Jump to content


 


Register a free account to unlock additional features at BleepingComputer.com
Welcome to BleepingComputer, a free community where people like yourself come together to discuss and learn how to use their computers. Using the site is easy and fun. As a guest, you can browse and view the various discussions in the forums, but can not create a new topic or reply to an existing one unless you are logged in. Other benefits of registering an account are subscribing to topics and forums, creating a blog, and having no ads shown anywhere on the site.


Click here to Register a free account now! or read our Welcome Guide to learn how to use this site.

Photo

Antivirus 2009 on Windows ME how do I remove it?


  • Please log in to reply
10 replies to this topic

#1 Laffnmule's Lode

Laffnmule's Lode

  • Members
  • 38 posts
  • OFFLINE
  •  
  • Local time:11:35 PM

Posted 12 January 2009 - 02:34 AM

1. I was doing a Google search for "elephant themed" craft or crafts.

2. On the second page I clicked on a search entry that I should not have, my bad.

3. Instead of opening a page on elephant themed crafts, I got a box that looked like it was from Microsoft Internet Explorer. It says,

ATTENTION If your computer is struck by the spyware, you could suffer data loss, unusual PC behaviour, PC freezes and crashes .Detect and remove viruses before they damage your computer!Antivirus 2009 will perform a 100% FREE and quick scan of your PC for Viruses, Spyware and Adware. Do you want to install Antivirus 2009 to scan your computer for malware now? (Recomended)

Below this message are two buttons OK on the left and Cancel on the right.

From rolling my curser over its button on my lower bar I see the following URL:
http ://best-anti-virus-scan.com/2009/1/en/freescan.php?id=880135 - Microsoft In
(I have disabled it here, by putting a space after the http, so that no one can inadvertantly click on it.)


4. Before I could click on the Cancel button (or do anything), my AVG Free Edition Resident Shield came up in a box that says,

Threat Detected! While opening file: C:\\WINDOWS\TEMPORARY INTERNET FILES\CONTENT.IE5\4DMVSPYJ\FREESCAN[1].HTM Virus found FakeAlert

Below the message the AVG box has these buttons from left to right: Ignore, Info, Heal, Move to Vault.

5. I clicked on the AVG Heal button, and got this message box: AVG Free Edition

Action failed. Error while handling file C:\\WINDOWS\TEMPORARY INTERNET FILES\CONTENT.IE5\4DMVSPYJ\FREESCAN[1].HTM

with an OK button below, which I clicked.

6. I clicked on the AVG Move to Vault button, and got this message box: AVG Free Edition

If a system file is removed from your disk, the operating system may cause an error and be unstable. Do you really want to move the file into the Virus Vault?

with Yes and No buttons below. For now, until I have more information, I clicked on the No button.

7. On a different computer we Googled Antivirus 2009. First I looked at a Yahoo! Answers Question. In the Best Answer was a link to BleepingComputer, but I had seen that a search result above the Yahoo! Answers one was for www.bleepingcomputer.com/malware-removal/uninstall-antivirus-2009, so I went back to Google and clicked from there. That computer has a printer (mine doesn't), so I was able to print out the instructions for using Malwarebytes' Anti-Malware.

8. On the infected computer, I opened a fresh browser, entered the URL in paragraph 7, and arrived at the How to Remove Antivirus 2009 (Uninstall Instructions). I clicked on the Malwarebytes' Anti-Malware Download Link, and got this message box: Error

This program requires Windows NT version 4.0 or later.

My operating system is Windows Milenium Edition.

9. I clicked on the questions link, registered, and came here. I am worried about what will happen when AVG does its morning virus scan and update. What do I do next?

Laffnmule's Lode

eMachines EZ1601-01; Intel Atom processor N270, speed ?; 1 GB RAM DDR2; 160 GB HDD; Built-in Graphics; Linksys Wireless Router, DSL modem; Windows XP Home Edition with SP3; mostly Google Chrome 16.0.912.77m, also IE 8.0.6001.18702; Yahoo Mail; Microsoft Security Essentials

BC AdBot (Login to Remove)

 


#2 buddy215

buddy215

  • Moderator
  • 13,501 posts
  • OFFLINE
  •  
  • Gender:Male
  • Location:West Tennessee
  • Local time:12:35 AM

Posted 12 January 2009 - 01:19 PM

You can use Super Antispyware. It works in ME. You may have to update it and run it again in a day or two. Security programs are always playing catchup with the constantly changing malware.

http://www.superantispyware.com/
Double-click SUPERAntiSypware.exe and use the default settings for installation. (OR the Renamed .EXE)
* An icon will be created on your desktop. Double-click that icon to launch the program.
* If asked to update the program definitions, click "Yes". If not, update the
definitions before scanning by selecting "Check for Updates".
* Under the "Configuration and Preferences", click the Preferences... button.
* Click the "General and Startup" tab, and under
Start-up Options, make sure "Start SUPERAntiSpyware when Windows starts" box is unchecked.
* Click the "Scanning Control" tab, and under Scanner
Options, make sure the following are checked (leave all others unchecked):
o Close browsers before scanning.
o Scan for tracking cookies.
o Terminate memory threats before quarantining.
* Click the "Close" button to leave the control center screen and exit the program.
Reboot your computer in "Safe Mode" using the F8 method. To do this, restart your computer and after hearing your computer beep once during startup (but before the Windows icon appears) press the F8 key repeatedly. A menu will appear with several options. Use the arrow keys to navigate and select the option to run Windows in "Safe Mode".

* Launch the program and back on the main screen, under "Scan for Harmful Software" click Scan your computer.
* On the left, make sure you check C:\Fixed Drive.
* On the right, under "Complete Scan", choose Perform Complete Scan and click "Next".
* After the scan is complete, a Scan Summary box will appear with potentially harmful items that were detected. Click "OK".
* Make sure everything has a checkmark next to it and click "Next".
* A notification will appear that "Quarantine and Removal is Complete". Click "OK" and then click the "Finish" button to return to the main menu.
* If asked if you want to reboot, click "Yes" and reboot normally.
* To retrieve the removal information after reboot, launch SUPERAntispyware again.
o Click Preferences, then click the Statistics/Logs tab.
o Under Scanner Logs, double-click SUPERAntiSpyware Scan Log.
o If there are several logs, click the current dated log and press View log. A text file will open in your default text editor.
o Please copy and paste the Scan Log results in your next reply.
* Click Close to exit the program.
“Every atom in your body came from a star that exploded and the atoms in your left hand probably came from a different star than your right hand. It really is the most poetic thing I know about physics...you are all stardust.”Lawrence M. Krauss
A 1792 U.S. penny, designed in part by Thomas Jefferson and George Washington, reads “Liberty Parent of Science & Industry.”

#3 Laffnmule's Lode

Laffnmule's Lode
  • Topic Starter

  • Members
  • 38 posts
  • OFFLINE
  •  
  • Local time:11:35 PM

Posted 12 January 2009 - 06:03 PM

OK I ran SAS (it pulled a whole bunch of cookies) here is the log:

SUPERAntiSpyware Scan Log
http://www.superantispyware.com

Generated 01/12/2009 at 02:16 PM

Application Version : 4.24.1004

Core Rules Database Version : 3706
Trace Rules Database Version: 1681

Scan type : Complete Scan
Total Scan Time : 01:53:57

Memory items scanned : 85
Memory threats detected : 0
Registry items scanned : 3736
Registry threats detected : 7
File items scanned : 105701
File threats detected : 831

Adware.Tracking Cookie
C:\WINDOWS\Cookies\anyuser@content.yieldmanager.edgesuite[1].txt
C:\WINDOWS\Cookies\anyuser@msnbc.112.2o7[1].txt
C:\WINDOWS\Cookies\anyuser@atwola[2].txt
C:\WINDOWS\Cookies\anyuser@ads.miricommunity[2].txt
C:\WINDOWS\Cookies\anyuser@specificclick[3].txt
C:\WINDOWS\Cookies\anyuser@revsci[5].txt
C:\WINDOWS\Cookies\anyuser@chitika[2].txt
C:\WINDOWS\Cookies\anyuser@yieldmanager[1].txt
C:\WINDOWS\Cookies\anyuser@content.yieldmanager[2].txt
C:\WINDOWS\Cookies\anyuser@apmebf[3].txt
C:\WINDOWS\Cookies\anyuser@tripod.lycos[1].txt
C:\WINDOWS\Cookies\anyuser@ads.bridgetrack[3].txt
C:\WINDOWS\Cookies\anyuser@microsoftwindows.112.2o7[1].txt
C:\WINDOWS\Cookies\anyuser@burstnet[4].txt
C:\WINDOWS\Cookies\anyuser@realmedia[3].txt
C:\WINDOWS\Cookies\anyuser@richmedia.yahoo[3].txt
C:\WINDOWS\Cookies\anyuser@onlinecounter2[1].txt
C:\WINDOWS\Cookies\anyuser@ads.pointroll[6].txt
C:\WINDOWS\Cookies\anyuser@at.atwola[2].txt
C:\WINDOWS\Cookies\anyuser@bs.serving-sys[1].txt
C:\WINDOWS\Cookies\anyuser@offers.animaladnetwork[3].txt
C:\WINDOWS\Cookies\anyuser@media6degrees[1].txt
C:\WINDOWS\Cookies\anyuser@tribalfusion[7].txt
C:\WINDOWS\Cookies\anyuser@247realmedia[1].txt
C:\WINDOWS\Cookies\anyuser@dynamic.media.adrevolver[3].txt
C:\WINDOWS\Cookies\anyuser@1041372295[1].txt
C:\WINDOWS\Cookies\anyuser@2o7[7].txt
C:\WINDOWS\Cookies\anyuser@ak[2].txt
C:\WINDOWS\Cookies\anyuser@adserver.adtechus[1].txt
C:\WINDOWS\Cookies\anyuser@adrevolver[11].txt
C:\WINDOWS\Cookies\anyuser@cgi-bin[3].txt
C:\WINDOWS\Cookies\anyuser@www.burstnet[3].txt
C:\WINDOWS\Cookies\anyuser@media.adrevolver[4].txt
C:\WINDOWS\Cookies\anyuser@adopt.specificclick[6].txt
C:\WINDOWS\Cookies\anyuser@dmtracker[1].txt
C:\WINDOWS\Cookies\anyuser@ad.associatedcontent[1].txt
C:\WINDOWS\Cookies\anyuser@tacoda[6].txt
C:\WINDOWS\Cookies\anyuser@overture[3].txt
C:\WINDOWS\Cookies\anyuser@adinterax[2].txt
C:\WINDOWS\Cookies\anyuser@kontera[4].txt
C:\WINDOWS\Cookies\anyuser@videoegg.adbureau[1].txt
C:\WINDOWS\Cookies\anyuser@zedo[8].txt
C:\WINDOWS\Cookies\anyuser@interclick[2].txt
C:\WINDOWS\Cookies\anyuser@insightexpressai[4].txt
C:\WINDOWS\Cookies\anyuser@questionmarket[7].txt
C:\WINDOWS\Cookies\anyuser@tripod[3].txt
C:\WINDOWS\Cookies\anyuser@msnportal.112.2o7[2].txt
C:\WINDOWS\Cookies\anyuser@serving-sys[5].txt
C:\WINDOWS\Cookies\anyuser@adopt.euroclick[5].txt
C:\WINDOWS\Cookies\anyuser@trafficmp[1].txt
C:\WINDOWS\Cookies\anyuser@www.burstbeacon[4].txt
C:\WINDOWS\Cookies\anyuser@ad.yieldmanager[8].txt
C:\WINDOWS\Cookies\anyuser@server.iad.liveperson[2].txt
C:\WINDOWS\Cookies\anyuser@specificmedia[3].txt
C:\WINDOWS\Cookies\anyuser@statcounter[6].txt
c:\WINDOWS\Cookies\default@click-safe[2].txt
c:\WINDOWS\Cookies\default@pennyweb[2].txt
c:\WINDOWS\Cookies\default@websponsors[1].txt
c:\WINDOWS\Cookies\default@adq.nextag[2].txt
c:\WINDOWS\Cookies\default@azjmp[2].txt
c:\WINDOWS\Cookies\default@a.websponsors[1].txt
c:\WINDOWS\Cookies\default@ad.yieldmanager[1].txt
c:\WINDOWS\Cookies\default@rightmedia[3].txt
c:\WINDOWS\Cookies\default@adprofile[1].txt
c:\WINDOWS\Cookies\default@www.launchitmedia[1].txt
c:\WINDOWS\Cookies\default@pathfinder[1].txt
c:\WINDOWS\Cookies\default@112.2o7[1].txt
c:\WINDOWS\Cookies\default@www.popuptraffic[1].txt
c:\WINDOWS\Cookies\default@www.epartmentfinder[1].txt
c:\WINDOWS\Cookies\default@db1.sitestats[2].txt
c:\WINDOWS\Cookies\default@bannerspace[1].txt
c:\WINDOWS\Cookies\default@gostats[2].txt
c:\WINDOWS\Cookies\default@indextools[4].txt
c:\WINDOWS\Cookies\default@1.primaryads[1].txt
c:\WINDOWS\Cookies\default@directtrack[1].txt
c:\WINDOWS\Cookies\default@belnk[2].txt
c:\WINDOWS\Cookies\default@adv.webmd[2].txt
c:\WINDOWS\Cookies\default@metareward[4].txt
c:\WINDOWS\Cookies\default@coolsavings[2].txt
c:\WINDOWS\Cookies\default@travelfinds.sidestep[2].txt
c:\WINDOWS\Cookies\default@secure.directtrack[2].txt
c:\WINDOWS\Cookies\default@hypertracker[2].txt
c:\WINDOWS\Cookies\default@metareward[1].txt
c:\WINDOWS\Cookies\default@trafficsystem[1].txt
c:\WINDOWS\Cookies\default@insightfirst[1].txt
c:\WINDOWS\Cookies\default@media[2].txt
c:\WINDOWS\Cookies\default@emarketmakers[2].txt
c:\WINDOWS\Cookies\default@www.metareward[1].txt
c:\WINDOWS\Cookies\default@nextag[3].txt
c:\WINDOWS\Cookies\default@www.nextag[1].txt
c:\WINDOWS\Cookies\default@etracking[1].txt
c:\WINDOWS\Cookies\default@hotbar[1].txt
c:\WINDOWS\Cookies\default@webfile[2].txt
c:\WINDOWS\Cookies\anyuser@msnportal.112.2o7[1].txt
c:\WINDOWS\Cookies\anyuser@tacoda[5].txt
c:\WINDOWS\Cookies\anyuser@media.adrevolver[3].txt
c:\WINDOWS\Cookies\anyuser@adrevolver[9].txt
c:\WINDOWS\Cookies\default@www.ticketsnow[2].txt
c:\WINDOWS\Cookies\default@superstats[1].txt
c:\WINDOWS\Cookies\default@dcsadxfd521e5huw2wrttnlc9_4f8h[1].txt
c:\WINDOWS\Cookies\default@adv.webmd[1].txt
c:\WINDOWS\Cookies\default@specificpop[2].txt
c:\WINDOWS\Cookies\default@insightfirst[2].txt
c:\WINDOWS\Cookies\default@ads.touregypt[1].txt
c:\WINDOWS\Cookies\default@www.stats4you[1].txt
c:\WINDOWS\Cookies\default@www.ticketsnow2[2].txt
c:\WINDOWS\Cookies\default@www.findserenitynow[1].txt
c:\WINDOWS\Cookies\default@ads.belointeractive[1].txt
c:\WINDOWS\Cookies\default@media[5].txt
c:\WINDOWS\Cookies\default@media[3].txt
c:\WINDOWS\Cookies\default@www.findonline[1].txt
c:\WINDOWS\Cookies\default@media[6].txt
c:\WINDOWS\Cookies\default@media[4].txt
c:\WINDOWS\Cookies\default@ads.specificclick[1].txt
c:\WINDOWS\Cookies\default@netfastmedia[1].txt
c:\WINDOWS\Cookies\default@ad.slygreetings[1].txt
c:\WINDOWS\Cookies\default@atwola[1].txt
c:\WINDOWS\Cookies\default@ads.as4x.tmcs[2].txt
c:\WINDOWS\Cookies\default@insightexpress[2].txt
c:\WINDOWS\Cookies\anyuser@dynamic.media.adrevolver[1].txt
c:\WINDOWS\Cookies\anyuser@2o7[6].txt
c:\WINDOWS\Cookies\anyuser@zedo[7].txt
c:\WINDOWS\Cookies\anyuser@collective-media[1].txt
c:\WINDOWS\Cookies\anyuser@tribalfusion[6].txt
c:\WINDOWS\Cookies\anyuser@specificmedia[1].txt
c:\WINDOWS\Cookies\anyuser@adopt.specificclick[5].txt
c:\WINDOWS\Cookies\anyuser@specificclick[5].txt
c:\WINDOWS\Cookies\anyuser@ad.yieldmanager[1].txt
c:\WINDOWS\Cookies\default@indextools[1].txt
c:\WINDOWS\Cookies\anyuser@nextag[3].txt
c:\WINDOWS\Cookies\anyuser@richmedia.yahoo[1].txt
c:\WINDOWS\Cookies\anyuser@questionmarket[5].txt
c:\WINDOWS\Cookies\default@dealtime[1].txt
c:\WINDOWS\Cookies\default@stat.dealtime[1].txt
c:\WINDOWS\Cookies\default@nextag[1].txt
c:\WINDOWS\Cookies\default@www.burstbeacon[2].txt
c:\WINDOWS\Cookies\default@insightexpress[3].txt
c:\WINDOWS\Cookies\default@insightfirst[3].txt
c:\WINDOWS\Cookies\default@atwola[3].txt
c:\WINDOWS\Cookies\default@find.intelius[2].txt
c:\WINDOWS\Cookies\default@y-1shz2prbmdj6wvny-1sez2pra2dj6wjlyenczklpwmdj6x9ny-1seq-2-2.stats.esomniture[2].txt
c:\WINDOWS\Cookies\default@indextools[2].txt
c:\WINDOWS\Cookies\default@metareward[2].txt
c:\WINDOWS\Cookies\default@focalex[2].txt
c:\WINDOWS\Cookies\default@comparediscounthotels[1].txt
c:\WINDOWS\Cookies\default@websponsors[2].txt
c:\WINDOWS\Cookies\default@rightmedia[2].txt
c:\WINDOWS\Cookies\default@webfile[3].txt
c:\WINDOWS\Cookies\default@clickability[1].txt
c:\WINDOWS\Cookies\default@stats[1].txt
c:\WINDOWS\Cookies\default@dealtime[2].txt
c:\WINDOWS\Cookies\default@tracking[1].txt
c:\WINDOWS\Cookies\default@banner[1].txt
c:\WINDOWS\Cookies\default@emarketmakers[1].txt
c:\WINDOWS\Cookies\default@ads.as4x.tmcs.ticketmaster[1].txt
c:\WINDOWS\Cookies\default@atwola[2].txt
c:\WINDOWS\Cookies\default@y-1shz2prbmdj6wvny-1sez2pra2dj6wjnyopcjweoqsdj6x9ny-1seq-2-2.stats.esomniture[2].txt
c:\WINDOWS\Cookies\default@y-1shz2prbmdj6wvny-1sez2pra2dj6wjlyenczklpwmdj6x9ny-1seq-2-2.stats.esomniture[3].txt
c:\WINDOWS\Cookies\default@adq.nextag[1].txt
c:\WINDOWS\Cookies\default@nextag[2].txt
c:\WINDOWS\Cookies\default@y-1shz2prbmdj6wvny-1sez2pra2dj6wjnywhdzikqqudj6x9ny-1seq-2-2.stats.esomniture[2].txt
c:\WINDOWS\Cookies\default@a-1shz2prbmdj6wvny-1sez2pra2dj6wjk4kmajwdpg-1dj6x9ny-1seq-2-2.stats.esomniture[2].txt
c:\WINDOWS\Cookies\default@a-1shz2prbmdj6wvny-1sez2pra2dj6wfkislajcfpw-1dj6x9ny-1seq-2-2.stats.esomniture[2].txt
c:\WINDOWS\Cookies\default@y-1shz2prbmdj6wvny-1sez2pra2dj6wjmiomcjmhoqidj6x9ny-1seq-2-2.stats.esomniture[2].txt
c:\WINDOWS\Cookies\default@y-1shz2prbmdj6wvny-1sez2pra2dj6wjl4spdzcdoasdj6x9ny-1seq-2-2.stats.esomniture[2].txt
c:\WINDOWS\Cookies\default@y-1shz2prbmdj6wvny-1sez2pra2dj6wjkyqkcpseoamdj6x9ny-1seq-2-2.stats.esomniture[2].txt
c:\WINDOWS\Cookies\default@y-1shz2prbmdj6wvny-1sez2pra2dj6wjliegdjelpgydj6x9ny-1seq-2-2.stats.esomniture[2].txt
c:\WINDOWS\Cookies\default@hypertracker[1].txt
c:\WINDOWS\Cookies\default@insightexpress[1].txt
c:\WINDOWS\Cookies\default@y-1shz2prbmdj6wvny-1sez2pra2dj6wjnycnajmhpqidj6x9ny-1seq-2-2.stats.esomniture[1].txt
c:\WINDOWS\Cookies\default@stat.dealtime[3].txt
c:\WINDOWS\Cookies\default@www.blowoutbanners[2].txt
c:\WINDOWS\Cookies\default@goto.trafficmultiplier[2].txt
c:\WINDOWS\Cookies\default@www.burstbeacon[3].txt
c:\WINDOWS\Cookies\default@y-1shz2prbmdj6wvny-1sez2pra2dj6wjkyoiczwgqqidj6x9ny-1seq-2-2.stats.esomniture[2].txt
c:\WINDOWS\Cookies\default@stats.manticoretechnology[1].txt
c:\WINDOWS\Cookies\default@-1shz2prbmdj6wvny-1sez2pra2dj6wjny-1mczoloaudj6x9ny-1seq-2-2.stats.esomniture[2].txt
c:\WINDOWS\Cookies\default@fcstats.bcentral[1].txt
c:\WINDOWS\Cookies\default@hotels-and-discounts[1].txt
c:\WINDOWS\Cookies\default@bizrate[2].txt
c:\WINDOWS\Cookies\default@realtytracker[1].txt
c:\WINDOWS\Cookies\default@y-1shz2prbmdj6wvny-1sez2pra2dj6wjliwmdjshowsdj6x9ny-1seq-2-2.stats.esomniture[1].txt
c:\WINDOWS\Cookies\default@y-1shz2prbmdj6wvny-1sez2pra2dj6wjliojcjcapw6dj6x9ny-1seq-2-2.stats.esomniture[1].txt
c:\WINDOWS\Cookies\default@find.intelius[3].txt
c:\WINDOWS\Cookies\default@insightfirst[4].txt
c:\WINDOWS\Cookies\default@adopt.specificclick[1].txt
c:\WINDOWS\Cookies\anyuser@belnk[2].txt
c:\WINDOWS\Cookies\anyuser@belnk[3].txt
c:\WINDOWS\Cookies\francine@msnportal.112.2o7[1].txt
c:\WINDOWS\Cookies\anyuser@statcounter[2].txt
c:\WINDOWS\Cookies\anyuser@www.burstbeacon[2].txt
c:\WINDOWS\Cookies\anyuser@adrevolver[1].txt
c:\WINDOWS\Cookies\anyuser@adrevolver[2].txt
c:\WINDOWS\Cookies\anyuser@2o7[2].txt
c:\WINDOWS\Cookies\anyuser@citi.bridgetrack[2].txt
c:\WINDOWS\Cookies\anyuser@burstnet[2].txt
c:\WINDOWS\Cookies\anyuser@adrevolver[6].txt
c:\WINDOWS\Cookies\anyuser@tribalfusion[1].txt
c:\WINDOWS\Cookies\anyuser@realmedia[2].txt
c:\WINDOWS\Cookies\anyuser@ads.pointroll[2].txt
c:\WINDOWS\Cookies\anyuser@ad.yieldmanager[2].txt
c:\WINDOWS\Cookies\anyuser@zedo[2].txt
c:\WINDOWS\Cookies\anyuser@ads.addynamix[1].txt
c:\WINDOWS\Cookies\anyuser@insightexpressai[2].txt
c:\WINDOWS\Cookies\anyuser@questionmarket[1].txt
c:\WINDOWS\Cookies\anyuser@data2.perf.overture[2].txt
c:\WINDOWS\Cookies\anyuser@tacoda[1].txt
c:\WINDOWS\Cookies\anyuser@serving-sys[2].txt
c:\WINDOWS\Cookies\anyuser@bs.serving-sys[2].txt
c:\WINDOWS\Cookies\anyuser@ads.addynamix[3].txt
c:\WINDOWS\Cookies\anyuser@z1.adserver[1].txt
c:\WINDOWS\Cookies\anyuser@bluestreak[2].txt
c:\WINDOWS\Cookies\anyuser@superstats[1].txt
c:\WINDOWS\Cookies\anyuser@tacoda[4].txt
c:\WINDOWS\Cookies\anyuser@nextag[2].txt
c:\WINDOWS\Cookies\anyuser@apmebf[2].txt
c:\WINDOWS\Cookies\anyuser@qksrv[2].txt
c:\WINDOWS\Cookies\anyuser@wpni.112.2o7[1].txt
c:\WINDOWS\Cookies\anyuser@anat.tacoda[1].txt
c:\WINDOWS\Cookies\anyuser@powellsbooks.122.2o7[1].txt
c:\WINDOWS\Cookies\anyuser@citi.bridgetrack[3].txt
c:\WINDOWS\Cookies\anyuser@adbrite[2].txt
c:\WINDOWS\Cookies\anyuser@bookfinder[1].txt
c:\WINDOWS\Cookies\anyuser@insightexpressai[3].txt
c:\WINDOWS\Cookies\anyuser@adopt.specificclick[2].txt
c:\WINDOWS\Cookies\anyuser@anad.tacoda[2].txt
c:\WINDOWS\Cookies\anyuser@www.burstbeacon[3].txt
c:\WINDOWS\Cookies\anyuser@redorbit[2].txt
c:\WINDOWS\Cookies\anyuser@cbs.112.2o7[1].txt
c:\WINDOWS\Cookies\anyuser@statcounter[1].txt
c:\WINDOWS\Cookies\anyuser@ads.cnn[2].txt
c:\WINDOWS\Cookies\anyuser@cnn.122.2o7[1].txt
c:\WINDOWS\Cookies\anyuser@members.tripod[2].txt
c:\WINDOWS\Cookies\anyuser@e-2dj6wjny-1sczek.stats.esomniture[2].txt
c:\WINDOWS\Cookies\anyuser@adopt.euroclick[1].txt
c:\WINDOWS\Cookies\anyuser@atwola[1].txt
c:\WINDOWS\Cookies\anyuser@bravenet[1].txt
c:\WINDOWS\Cookies\anyuser@ad.yieldmanager[3].txt
c:\WINDOWS\Cookies\anyuser@247realmedia[2].txt
c:\WINDOWS\Cookies\anyuser@e-2dj6whlocmc5aep.stats.esomniture[1].txt
c:\WINDOWS\Cookies\anyuser@tracker.wholinked[1].txt
c:\WINDOWS\Cookies\anyuser@2o7[1].txt
c:\WINDOWS\Cookies\anyuser@e-2dj6wjkoklazeap.stats.esomniture[2].txt
c:\WINDOWS\Cookies\anyuser@e-2dj6wflisjdzmgo.stats.esomniture[2].txt
c:\WINDOWS\Cookies\anyuser@e-2dj6wjnyokazagq.stats.esomniture[2].txt
c:\WINDOWS\Cookies\anyuser@e-2dj6whliopcpaeq.stats.esomniture[2].txt
c:\WINDOWS\Cookies\anyuser@e-2dj6wjkyqnazceo.stats.esomniture[2].txt
c:\WINDOWS\Cookies\anyuser@a.findarticles[1].txt
c:\WINDOWS\Cookies\anyuser@e-2dj6wakowgczsap.stats.esomniture[2].txt
c:\WINDOWS\Cookies\anyuser@rotator.adjuggler[1].txt
c:\WINDOWS\Cookies\anyuser@tribalfusion[2].txt
c:\WINDOWS\Cookies\anyuser@adrevolver[3].txt
c:\WINDOWS\Cookies\anyuser@adrevolver[4].txt
c:\WINDOWS\Cookies\anyuser@e-2dj6wjk4gjdjebp.stats.esomniture[1].txt
c:\WINDOWS\Cookies\anyuser@data2.perf.overture[1].txt
c:\WINDOWS\Cookies\anyuser@trafficmp[2].txt
c:\WINDOWS\Cookies\anyuser@burstnet[1].txt
c:\WINDOWS\Cookies\anyuser@zedo[1].txt
c:\WINDOWS\Cookies\anyuser@realmedia[1].txt
c:\WINDOWS\Cookies\anyuser@www.burstnet[1].txt
c:\WINDOWS\Cookies\anyuser@specificclick[1].txt
c:\WINDOWS\Cookies\anyuser@revsci[2].txt
c:\WINDOWS\Cookies\anyuser@e-2dj6wak4undpegp.stats.esomniture[2].txt
c:\WINDOWS\Cookies\anyuser@partner2profit[2].txt
c:\WINDOWS\Cookies\anyuser@questionmarket[3].txt
c:\WINDOWS\Cookies\anyuser@ads.pointroll[1].txt
c:\WINDOWS\Cookies\anyuser@zedo[4].txt
c:\WINDOWS\Cookies\anyuser@apmebf[1].txt
c:\WINDOWS\Cookies\anyuser@tacoda[2].txt
c:\WINDOWS\Cookies\anyuser@tripod[2].txt
c:\WINDOWS\Cookies\anyuser@adserver[1].txt
c:\WINDOWS\Cookies\anyuser@media.adrevolver[2].txt
c:\WINDOWS\Cookies\anyuser@2o7[3].txt
c:\WINDOWS\Cookies\anyuser@kontera[2].txt
c:\WINDOWS\Cookies\anyuser@adrevolver[7].txt
c:\WINDOWS\Cookies\anyuser@partner2profit[1].txt
c:\WINDOWS\Cookies\anyuser@sitestat.mayoclinic[1].txt
c:\WINDOWS\Cookies\anyuser@serving-sys[1].txt
c:\WINDOWS\Cookies\anyuser@statcounter[3].txt
c:\WINDOWS\Cookies\anyuser@ad.yieldmanager[4].txt
c:\WINDOWS\Cookies\anyuser@www.burstbeacon[1].txt
c:\WINDOWS\Cookies\anyuser@insightexpressai[1].txt
c:\WINDOWS\Cookies\anyuser@ad.yieldmanager[5].txt
c:\WINDOWS\Cookies\anyuser@specificclick[2].txt
c:\WINDOWS\Cookies\anyuser@revsci[3].txt
c:\WINDOWS\Cookies\anyuser@adopt.euroclick[3].txt
c:\WINDOWS\Cookies\anyuser@tacoda[3].txt
c:\WINDOWS\Cookies\anyuser@findarticles[2].txt
c:\WINDOWS\Cookies\anyuser@adopt.specificclick[3].txt
c:\WINDOWS\Cookies\anyuser@ads.pointroll[3].txt
c:\WINDOWS\Cookies\anyuser@offers.animaladnetwork[1].txt
c:\WINDOWS\Cookies\anyuser@questionmarket[4].txt
c:\WINDOWS\Cookies\anyuser@tribalfusion[3].txt
c:\WINDOWS\Cookies\anyuser@zedo[3].txt
c:\WINDOWS\Cookies\anyuser@adserver[2].txt
c:\WINDOWS\Cookies\anyuser@tripod[1].txt
c:\WINDOWS\Cookies\anyuser@kontera[1].txt
c:\WINDOWS\Cookies\anyuser@adrevolver[8].txt
c:\WINDOWS\Cookies\anyuser@sitestat.mayoclinic[2].txt
c:\WINDOWS\Cookies\anyuser@2o7[4].txt
c:\WINDOWS\Cookies\anyuser@revsci[4].txt
c:\WINDOWS\Cookies\anyuser@paypal.112.2o7[1].txt
c:\WINDOWS\Cookies\anyuser@serving-sys[3].txt
c:\WINDOWS\Cookies\anyuser@partner2profit[3].txt
c:\WINDOWS\Cookies\anyuser@adlegend[1].txt
c:\WINDOWS\Cookies\anyuser@ads.pointroll[4].txt
c:\WINDOWS\Cookies\anyuser@overture[2].txt
c:\WINDOWS\Cookies\anyuser@web4.realtracker[2].txt
c:\WINDOWS\Cookies\anyuser@insightexpressai[5].txt
c:\WINDOWS\Cookies\anyuser@newmediaexplorer[2].txt
c:\WINDOWS\Cookies\anyuser@cancertreatmentcenter.112.2o7[1].txt
c:\WINDOWS\Cookies\anyuser@media.zoominfo[1].txt
c:\WINDOWS\Cookies\anyuser@adserving[2].txt
c:\WINDOWS\Cookies\anyuser@apmebf[4].txt
c:\WINDOWS\Cookies\anyuser@revenue[2].txt
c:\WINDOWS\Cookies\anyuser@findarticles[1].txt
c:\WINDOWS\Cookies\anyuser@e-2dj6wjnycoczeep.stats.esomniture[2].txt
c:\WINDOWS\Cookies\anyuser@e-2dj6wflokkdjkkp.stats.esomniture[2].txt
c:\WINDOWS\Cookies\anyuser@e-2dj6wgk4qkczodq.stats.esomniture[2].txt
c:\WINDOWS\Cookies\anyuser@e-2dj6whkisiazwho.stats.esomniture[2].txt
c:\WINDOWS\Cookies\anyuser@e-2dj6wjlygpazigo.stats.esomniture[2].txt
c:\WINDOWS\Cookies\anyuser@tribalfusion[5].txt
c:\WINDOWS\Cookies\anyuser@media.adrevolver[1].txt
c:\WINDOWS\Cookies\anyuser@adopt.specificclick[1].txt
c:\WINDOWS\Cookies\anyuser@adopt.euroclick[4].txt
c:\WINDOWS\Cookies\anyuser@atlas.entrepreneur[2].txt
c:\WINDOWS\Cookies\anyuser@zedo[5].txt
c:\WINDOWS\Cookies\anyuser@offers.animaladnetwork[2].txt
c:\WINDOWS\Cookies\anyuser@timeinc.122.2o7[1].txt
c:\WINDOWS\Cookies\anyuser@ads.bridgetrack[1].txt
c:\WINDOWS\Cookies\anyuser@www.burstnet[2].txt
c:\WINDOWS\Cookies\anyuser@www.burstbeacon[5].txt
c:\WINDOWS\Cookies\anyuser@ascendmedia.112.2o7[1].txt
c:\WINDOWS\Cookies\anyuser@eyewonder[1].txt
c:\WINDOWS\Cookies\anyuser@statcounter[5].txt
c:\WINDOWS\Cookies\anyuser@AdDisplayTrackerServlet[1].txt
c:\WINDOWS\Cookies\anyuser@questionmarket[2].txt
c:\WINDOWS\Cookies\anyuser@adrevolver[5].txt
c:\WINDOWS\Cookies\anyuser@bp.specificclick[2].txt
c:\WINDOWS\Cookies\anyuser@e-2dj6wfkoskajifp.stats.esomniture[2].txt
c:\WINDOWS\Cookies\anyuser@ad.yieldmanager[6].txt
c:\WINDOWS\Cookies\anyuser@e-2dj6wjkokjazkgp.stats.esomniture[2].txt
c:\WINDOWS\Cookies\anyuser@specificclick[4].txt
c:\WINDOWS\Profiles\Robin\Cookies\default@click-safe[2].txt
c:\WINDOWS\Profiles\Robin\Cookies\default@pennyweb[2].txt
c:\WINDOWS\Profiles\Robin\Cookies\default@websponsors[1].txt
c:\WINDOWS\Profiles\Robin\Cookies\default@adq.nextag[2].txt
c:\WINDOWS\Profiles\Robin\Cookies\default@azjmp[2].txt
c:\WINDOWS\Profiles\Robin\Cookies\default@a.websponsors[1].txt
c:\WINDOWS\Profiles\Robin\Cookies\default@ad.yieldmanager[1].txt
c:\WINDOWS\Profiles\Robin\Cookies\default@rightmedia[3].txt
c:\WINDOWS\Profiles\Robin\Cookies\default@adprofile[1].txt
c:\WINDOWS\Profiles\Robin\Cookies\default@www.launchitmedia[1].txt
c:\WINDOWS\Profiles\Robin\Cookies\default@pathfinder[1].txt
c:\WINDOWS\Profiles\Robin\Cookies\default@112.2o7[1].txt
c:\WINDOWS\Profiles\Robin\Cookies\default@www.popuptraffic[1].txt
c:\WINDOWS\Profiles\Robin\Cookies\default@www.epartmentfinder[1].txt
c:\WINDOWS\Profiles\Robin\Cookies\default@db1.sitestats[2].txt
c:\WINDOWS\Profiles\Robin\Cookies\default@bannerspace[1].txt
c:\WINDOWS\Profiles\Robin\Cookies\default@gostats[2].txt
c:\WINDOWS\Profiles\Robin\Cookies\default@indextools[4].txt
c:\WINDOWS\Profiles\Robin\Cookies\default@1.primaryads[1].txt
c:\WINDOWS\Profiles\Robin\Cookies\default@directtrack[1].txt
c:\WINDOWS\Profiles\Robin\Cookies\default@belnk[2].txt
c:\WINDOWS\Profiles\Robin\Cookies\default@adv.webmd[2].txt
c:\WINDOWS\Profiles\Robin\Cookies\default@metareward[4].txt
c:\WINDOWS\Profiles\Robin\Cookies\default@coolsavings[2].txt
c:\WINDOWS\Profiles\Robin\Cookies\default@travelfinds.sidestep[2].txt
c:\WINDOWS\Profiles\Robin\Cookies\default@secure.directtrack[2].txt
c:\WINDOWS\Profiles\Robin\Cookies\default@hypertracker[2].txt
c:\WINDOWS\Profiles\Robin\Cookies\default@metareward[1].txt
c:\WINDOWS\Profiles\Robin\Cookies\default@trafficsystem[1].txt
c:\WINDOWS\Profiles\Robin\Cookies\default@insightfirst[1].txt
c:\WINDOWS\Profiles\Robin\Cookies\default@media[2].txt
c:\WINDOWS\Profiles\Robin\Cookies\default@emarketmakers[2].txt
c:\WINDOWS\Profiles\Robin\Cookies\default@www.metareward[1].txt
c:\WINDOWS\Profiles\Robin\Cookies\default@nextag[3].txt
c:\WINDOWS\Profiles\Robin\Cookies\default@www.nextag[1].txt
c:\WINDOWS\Profiles\Robin\Cookies\default@etracking[1].txt
c:\WINDOWS\Profiles\Robin\Cookies\default@hotbar[1].txt
c:\WINDOWS\Profiles\Robin\Cookies\default@webfile[2].txt
c:\WINDOWS\Profiles\Robin\Cookies\default@superstats[2].txt
c:\WINDOWS\Profiles\Robin\Cookies\default@adprofile[3].txt
c:\WINDOWS\Profiles\Robin\Cookies\default@www.ticketsnow[2].txt
c:\WINDOWS\Profiles\Robin\Cookies\default@superstats[1].txt
c:\WINDOWS\Profiles\Robin\Cookies\default@dcsadxfd521e5huw2wrttnlc9_4f8h[1].txt
c:\WINDOWS\Profiles\Robin\Cookies\default@adv.webmd[1].txt
c:\WINDOWS\Profiles\Robin\Cookies\default@specificpop[2].txt
c:\WINDOWS\Profiles\Robin\Cookies\default@insightfirst[2].txt
c:\WINDOWS\Profiles\Robin\Cookies\default@ads.touregypt[1].txt
c:\WINDOWS\Profiles\Robin\Cookies\default@www.stats4you[1].txt
c:\WINDOWS\Profiles\Robin\Cookies\default@www.ticketsnow2[2].txt
c:\WINDOWS\Profiles\Robin\Cookies\default@www.findserenitynow[1].txt
c:\WINDOWS\Profiles\Robin\Cookies\default@ads.belointeractive[1].txt
c:\WINDOWS\Profiles\Robin\Cookies\default@media[5].txt
c:\WINDOWS\Profiles\Robin\Cookies\default@media[3].txt
c:\WINDOWS\Profiles\Robin\Cookies\default@www.findonline[1].txt
c:\WINDOWS\Profiles\Robin\Cookies\default@media[6].txt
c:\WINDOWS\Profiles\Robin\Cookies\default@media[4].txt
c:\WINDOWS\Profiles\Robin\Cookies\default@ads.specificclick[1].txt
c:\WINDOWS\Profiles\Robin\Cookies\default@netfastmedia[1].txt
c:\WINDOWS\Profiles\Robin\Cookies\default@ad.slygreetings[1].txt
c:\WINDOWS\Profiles\Robin\Cookies\default@atwola[1].txt
c:\WINDOWS\Profiles\Robin\Cookies\default@ads.as4x.tmcs[2].txt
c:\WINDOWS\Profiles\Robin\Cookies\default@insightexpress[2].txt
c:\WINDOWS\Profiles\Robin\Cookies\default@www.rowise[1].txt
c:\WINDOWS\Profiles\Robin\Cookies\default@intellisrv[1].txt
c:\WINDOWS\Profiles\Robin\Cookies\default@trafficsecrets[1].txt
c:\WINDOWS\Profiles\Robin\Cookies\default@ads.jackpot[2].txt
c:\WINDOWS\Profiles\Robin\Cookies\default@1.primaryads[3].txt
c:\WINDOWS\Profiles\Robin\Cookies\default@ads.ussearch[1].txt
c:\WINDOWS\Profiles\Robin\Cookies\default@indextools[1].txt
c:\WINDOWS\Profiles\Robin\Cookies\default@publishers.clickbooth[1].txt
c:\WINDOWS\Profiles\Robin\Cookies\default@metareward[3].txt
c:\WINDOWS\Profiles\Robin\Cookies\default@azjmp[3].txt
c:\WINDOWS\Profiles\Robin\Cookies\default@dist.belnk[2].txt
c:\WINDOWS\Profiles\Robin\Cookies\default@insightfirst[5].txt
c:\WINDOWS\Profiles\Robin\Cookies\default@indextools[3].txt
c:\WINDOWS\Profiles\Robin\Cookies\default@adv.webmd[4].txt
c:\WINDOWS\Profiles\Robin\Cookies\default@login.tracking101[1].txt
c:\WINDOWS\Profiles\Robin\Cookies\default@dealtime[1].txt
c:\WINDOWS\Profiles\Robin\Cookies\default@stat.dealtime[1].txt
c:\WINDOWS\Profiles\Robin\Cookies\default@ad.yieldmanager[3].txt
c:\WINDOWS\Profiles\Robin\Cookies\default@icc.intellisrv[2].txt
c:\WINDOWS\Profiles\Robin\Cookies\default@nextag[4].txt
c:\WINDOWS\Profiles\Robin\Cookies\default@sfp.directtrack[1].txt
c:\WINDOWS\Profiles\Robin\Cookies\default@coolsavings[1].txt
c:\WINDOWS\Profiles\Robin\Cookies\default@nextag[1].txt
c:\WINDOWS\Profiles\Robin\Cookies\default@adknowledge[1].txt
c:\WINDOWS\Profiles\Robin\Cookies\default@directtrack[3].txt
c:\WINDOWS\Profiles\Robin\Cookies\default@burstnet[2].txt
c:\WINDOWS\Profiles\Robin\Cookies\default@www.burstbeacon[4].txt
c:\WINDOWS\Profiles\Robin\Cookies\default@offersquest.directtrack[2].txt
c:\WINDOWS\Profiles\Robin\Cookies\default@focalex[3].txt
c:\WINDOWS\Profiles\Robin\Cookies\default@www.emarketmakers[1].txt
c:\WINDOWS\Profiles\Robin\Cookies\default@www.burstbeacon[2].txt
c:\WINDOWS\Profiles\Robin\Cookies\default@insightexpress[3].txt
c:\WINDOWS\Profiles\Robin\Cookies\default@512media[1].txt
c:\WINDOWS\Profiles\Robin\Cookies\default@insightfirst[3].txt
c:\WINDOWS\Profiles\Robin\Cookies\default@atwola[3].txt
c:\WINDOWS\Profiles\Robin\Cookies\default@find.intelius[2].txt
c:\WINDOWS\Profiles\Robin\Cookies\default@y-1shz2prbmdj6wvny-1sez2pra2dj6wjlyenczklpwmdj6x9ny-1seq-2-2.stats.esomniture[2].txt
c:\WINDOWS\Profiles\Robin\Cookies\default@indextools[2].txt
c:\WINDOWS\Profiles\Robin\Cookies\default@metareward[2].txt
c:\WINDOWS\Profiles\Robin\Cookies\default@focalex[2].txt
c:\WINDOWS\Profiles\Robin\Cookies\default@comparediscounthotels[1].txt
c:\WINDOWS\Profiles\Robin\Cookies\default@websponsors[2].txt
c:\WINDOWS\Profiles\Robin\Cookies\default@rightmedia[2].txt
c:\WINDOWS\Profiles\Robin\Cookies\default@webfile[3].txt
c:\WINDOWS\Profiles\Robin\Cookies\default@clickability[1].txt
c:\WINDOWS\Profiles\Robin\Cookies\default@stats[1].txt
c:\WINDOWS\Profiles\Robin\Cookies\default@dealtime[2].txt
c:\WINDOWS\Profiles\Robin\Cookies\default@tracking[1].txt
c:\WINDOWS\Profiles\Robin\Cookies\default@banner[1].txt
c:\WINDOWS\Profiles\Robin\Cookies\default@emarketmakers[1].txt
c:\WINDOWS\Profiles\Robin\Cookies\default@ads.as4x.tmcs.ticketmaster[1].txt
c:\WINDOWS\Profiles\Robin\Cookies\default@atwola[2].txt
c:\WINDOWS\Profiles\Robin\Cookies\default@y-1shz2prbmdj6wvny-1sez2pra2dj6wjnyopcjweoqsdj6x9ny-1seq-2-2.stats.esomniture[2].txt
c:\WINDOWS\Profiles\Robin\Cookies\default@y-1shz2prbmdj6wvny-1sez2pra2dj6wjlyenczklpwmdj6x9ny-1seq-2-2.stats.esomniture[3].txt
c:\WINDOWS\Profiles\Robin\Cookies\default@adq.nextag[1].txt
c:\WINDOWS\Profiles\Robin\Cookies\default@nextag[2].txt
c:\WINDOWS\Profiles\Robin\Cookies\default@y-1shz2prbmdj6wvny-1sez2pra2dj6wjnywhdzikqqudj6x9ny-1seq-2-2.stats.esomniture[2].txt
c:\WINDOWS\Profiles\Robin\Cookies\default@a-1shz2prbmdj6wvny-1sez2pra2dj6wjk4kmajwdpg-1dj6x9ny-1seq-2-2.stats.esomniture[2].txt
c:\WINDOWS\Profiles\Robin\Cookies\default@a-1shz2prbmdj6wvny-1sez2pra2dj6wfkislajcfpw-1dj6x9ny-1seq-2-2.stats.esomniture[2].txt
c:\WINDOWS\Profiles\Robin\Cookies\default@y-1shz2prbmdj6wvny-1sez2pra2dj6wjmiomcjmhoqidj6x9ny-1seq-2-2.stats.esomniture[2].txt
c:\WINDOWS\Profiles\Robin\Cookies\default@y-1shz2prbmdj6wvny-1sez2pra2dj6wjl4spdzcdoasdj6x9ny-1seq-2-2.stats.esomniture[2].txt
c:\WINDOWS\Profiles\Robin\Cookies\default@y-1shz2prbmdj6wvny-1sez2pra2dj6wjkyqkcpseoamdj6x9ny-1seq-2-2.stats.esomniture[2].txt
c:\WINDOWS\Profiles\Robin\Cookies\default@y-1shz2prbmdj6wvny-1sez2pra2dj6wjliegdjelpgydj6x9ny-1seq-2-2.stats.esomniture[2].txt
c:\WINDOWS\Profiles\Robin\Cookies\default@hypertracker[1].txt
c:\WINDOWS\Profiles\Robin\Cookies\default@insightexpress[1].txt
c:\WINDOWS\Profiles\Robin\Cookies\default@y-1shz2prbmdj6wvny-1sez2pra2dj6wjnycnajmhpqidj6x9ny-1seq-2-2.stats.esomniture[1].txt
c:\WINDOWS\Profiles\Robin\Cookies\default@stat.dealtime[3].txt
c:\WINDOWS\Profiles\Robin\Cookies\default@www.blowoutbanners[2].txt
c:\WINDOWS\Profiles\Robin\Cookies\default@goto.trafficmultiplier[2].txt
c:\WINDOWS\Profiles\Robin\Cookies\default@www.burstbeacon[3].txt
c:\WINDOWS\Profiles\Robin\Cookies\default@y-1shz2prbmdj6wvny-1sez2pra2dj6wjkyoiczwgqqidj6x9ny-1seq-2-2.stats.esomniture[2].txt
c:\WINDOWS\Profiles\Robin\Cookies\default@stats.manticoretechnology[1].txt
c:\WINDOWS\Profiles\Robin\Cookies\default@-1shz2prbmdj6wvny-1sez2pra2dj6wjny-1mczoloaudj6x9ny-1seq-2-2.stats.esomniture[2].txt
c:\WINDOWS\Profiles\Robin\Cookies\default@fcstats.bcentral[1].txt
c:\WINDOWS\Profiles\Robin\Cookies\default@hotels-and-discounts[1].txt
c:\WINDOWS\Profiles\Robin\Cookies\default@bizrate[2].txt
c:\WINDOWS\Profiles\Robin\Cookies\default@realtytracker[1].txt
c:\WINDOWS\Profiles\Robin\Cookies\default@y-1shz2prbmdj6wvny-1sez2pra2dj6wjliwmdjshowsdj6x9ny-1seq-2-2.stats.esomniture[1].txt
c:\WINDOWS\Profiles\Robin\Cookies\default@y-1shz2prbmdj6wvny-1sez2pra2dj6wjliojcjcapw6dj6x9ny-1seq-2-2.stats.esomniture[1].txt
c:\WINDOWS\Profiles\Robin\Cookies\default@find.intelius[3].txt
c:\WINDOWS\Profiles\Robin\Cookies\default@insightfirst[4].txt
c:\WINDOWS\Profiles\Robin\Cookies\default@adopt.specificclick[1].txt
c:\WINDOWS\Profiles\Robin\Cookies\default@secure.directtrack[1].txt
c:\WINDOWS\Profiles\Robin\Cookies\default@a.websponsors[2].txt
c:\WINDOWS\Profiles\Robin\Cookies\default@windowsmedia[1].txt
c:\WINDOWS\Profiles\Robin\Cookies\default@clicks.jackpot[1].txt
c:\WINDOWS\Profiles\Robin\Cookies\default@www.metareward[3].txt
c:\WINDOWS\Profiles\Robin\Cookies\default@clicks.winsweepstakes[1].txt
c:\WINDOWS\Profiles\Robin\Cookies\default@lynxtrack[1].txt
c:\WINDOWS\Profiles\Robin\Cookies\default@itimenetwork.directtrack[2].txt
c:\WINDOWS\Profiles\Robin\Cookies\default@qnsr[2].txt
c:\WINDOWS\Profiles\Robin\Cookies\default@emarketmakers[3].txt
c:\WINDOWS\Profiles\Robin\Cookies\default@belnk[3].txt
c:\WINDOWS\Profiles\Robin\Cookies\anyuser@azjmp[2].txt
c:\WINDOWS\Profiles\Robin\Cookies\anyuser@adprofile[1].txt
c:\WINDOWS\Profiles\Robin\Cookies\anyuser@www.rowise[1].txt
c:\WINDOWS\Profiles\Robin\Cookies\anyuser@gozing.directtrack[2].txt
c:\WINDOWS\Profiles\Robin\Cookies\anyuser@indextools[1].txt
c:\WINDOWS\Profiles\Robin\Cookies\anyuser@sfp.directtrack[2].txt
c:\WINDOWS\Profiles\Robin\Cookies\anyuser@emarketmakers[1].txt
c:\WINDOWS\Profiles\Robin\Cookies\anyuser@directtrack[1].txt
c:\WINDOWS\Profiles\Robin\Cookies\anyuser@1.primaryads[1].txt
c:\WINDOWS\Profiles\Robin\Cookies\anyuser@itimenetwork.directtrack[2].txt
c:\WINDOWS\Profiles\Robin\Cookies\anyuser@searchforgreatdiscounts[1].txt
c:\WINDOWS\Profiles\Robin\Cookies\anyuser@www.findtherightschool[1].txt
c:\WINDOWS\Profiles\Robin\Cookies\anyuser@qnsr[2].txt
c:\WINDOWS\Profiles\Robin\Cookies\anyuser@clicks.searchforgreatdiscounts[1].txt
c:\WINDOWS\Profiles\Robin\Cookies\anyuser@www.cyberneticmedia[1].txt
c:\WINDOWS\Profiles\Robin\Cookies\anyuser@publishers.clickbooth[2].txt
c:\WINDOWS\Profiles\Robin\Cookies\anyuser@metareward[2].txt
c:\WINDOWS\Profiles\Robin\Cookies\anyuser@coolsavings[2].txt
c:\WINDOWS\Profiles\Robin\Cookies\anyuser@a.websponsors[1].txt
c:\WINDOWS\Profiles\Robin\Cookies\anyuser@login.tracking101[2].txt
c:\WINDOWS\Profiles\Robin\Cookies\anyuser@belnk[2].txt
c:\WINDOWS\Profiles\Robin\Cookies\anyuser@belnk[3].txt
c:\WINDOWS\Profiles\Robin\Cookies\francine@msnportal.112.2o7[1].txt
c:\WINDOWS\Profiles\Robin\Cookies\anyuser@burstnet[1].txt
c:\WINDOWS\Profiles\Robin\Cookies\anyuser@msnportal.112.2o7[1].txt
c:\WINDOWS\Profiles\Robin\Cookies\anyuser@belnk[1].txt
c:\WINDOWS\Profiles\Robin\Cookies\anyuser@insightexpressai[1].txt
c:\WINDOWS\Profiles\Robin\Cookies\anyuser@adknowledge[2].txt
c:\WINDOWS\Profiles\Robin\Cookies\anyuser@ads.glispa[2].txt
c:\WINDOWS\Profiles\Robin\Cookies\anyuser@www.burstbeacon[2].txt
c:\WINDOWS\Profiles\Robin\Cookies\anyuser@ad.yieldmanager[2].txt
c:\WINDOWS\Profiles\Robin\Cookies\robin@msnportal.112.2o7[1].txt
c:\WINDOWS\Profiles\Robin\Cookies\robin@xxxcounter[1].txt
c:\WINDOWS\Profiles\Robin\Cookies\robin@anad.tacoda[1].txt
c:\WINDOWS\Profiles\Robin\Cookies\robin@analytics.clickpathmedia[1].txt
c:\WINDOWS\Profiles\Robin\Cookies\robin@a.websponsors[2].txt
c:\WINDOWS\Profiles\Robin\Cookies\robin@bluestreak[1].txt
c:\WINDOWS\Profiles\Robin\Cookies\robin@zedo[5].txt
c:\WINDOWS\Profiles\Robin\Cookies\robin@serving-sys[1].txt
c:\WINDOWS\Profiles\Robin\Cookies\robin@ads.pointroll[1].txt
c:\WINDOWS\Profiles\Robin\Cookies\robin@clickbank[1].txt
c:\WINDOWS\Profiles\Robin\Cookies\robin@ad.yieldmanager[2].txt
c:\WINDOWS\Profiles\Robin\Cookies\robin@tacoda[2].txt
c:\WINDOWS\Profiles\Robin\Cookies\robin@e-2dj6wjkoqmcpcfp.stats.esomniture[1].txt
c:\WINDOWS\Profiles\Robin\Cookies\robin@e-2dj6wjnyanc5oco.stats.esomniture[2].txt
c:\WINDOWS\Profiles\Robin\Cookies\robin@nextag[1].txt
c:\WINDOWS\Profiles\Robin\Cookies\robin@specificclick[2].txt
c:\WINDOWS\Profiles\Robin\Cookies\robin@2o7[2].txt
c:\WINDOWS\Profiles\Robin\Cookies\robin@e-2dj6wjkyeoajmhp.stats.esomniture[1].txt
c:\WINDOWS\Profiles\Robin\Cookies\robin@bizrate[1].txt
c:\WINDOWS\Profiles\Robin\Cookies\robin@e-2dj6wblyemdpolo.stats.esomniture[2].txt
c:\WINDOWS\Profiles\Robin\Cookies\robin@e-2dj6wjnywnczkho.stats.esomniture[2].txt
c:\WINDOWS\Profiles\Robin\Cookies\robin@e-2dj6wjl4sjdpiep.stats.esomniture[2].txt
c:\WINDOWS\Profiles\Robin\Cookies\robin@e-2dj6wjmigpajolp.stats.esomniture[2].txt
c:\WINDOWS\Profiles\Robin\Cookies\robin@e-2dj6wgkyemczmao.stats.esomniture[2].txt
c:\WINDOWS\Profiles\Robin\Cookies\robin@e-2dj6wgkoamcpccp.stats.esomniture[2].txt
c:\WINDOWS\Profiles\Robin\Cookies\robin@e-2dj6wjlicicjglp.stats.esomniture[2].txt
c:\WINDOWS\Profiles\Robin\Cookies\robin@e-2dj6wjny-1sd5sg.stats.esomniture[2].txt
c:\WINDOWS\Profiles\Robin\Cookies\robin@e-2dj6wjnyeoczsko.stats.esomniture[2].txt
c:\WINDOWS\Profiles\Robin\Cookies\robin@e-2dj6wfligpczkhp.stats.esomniture[2].txt
c:\WINDOWS\Profiles\Robin\Cookies\robin@e-2dj6wgkoqnajaap.stats.esomniture[2].txt
c:\WINDOWS\Profiles\Robin\Cookies\robin@questionmarket[2].txt
c:\WINDOWS\Profiles\Robin\Cookies\robin@tribalfusion[2].txt
c:\WINDOWS\Profiles\Robin\Cookies\robin@server.iad.liveperson[2].txt
c:\WINDOWS\Profiles\Robin\Cookies\robin@medhelpinternational.112.2o7[1].txt
c:\WINDOWS\Profiles\Robin\Cookies\robin@zedo[2].txt
c:\WINDOWS\Profiles\Robin\Cookies\robin@zedo[3].txt
c:\WINDOWS\Profiles\Robin\Cookies\robin@specificclick[1].txt
c:\WINDOWS\Profiles\Robin\Cookies\robin@2o7[1].txt
c:\WINDOWS\Profiles\Robin\Cookies\robin@collective-media[2].txt
c:\WINDOWS\Profiles\Robin\Cookies\robin@questionmarket[3].txt
c:\WINDOWS\Profiles\Robin\Cookies\robin@server.iad.liveperson[3].txt
c:\WINDOWS\Profiles\Robin\Cookies\robin@cancertreatmentcenter.112.2o7[1].txt
c:\WINDOWS\Profiles\Robin\Cookies\robin@statcounter[2].txt
c:\WINDOWS\Profiles\Robin\Cookies\robin@perf.overture[1].txt
c:\WINDOWS\Profiles\Robin\Cookies\robin@apmebf[1].txt
c:\WINDOWS\Profiles\Robin\Cookies\robin@statcounter[3].txt
c:\WINDOWS\Profiles\Robin\Cookies\robin@adlegend[1].txt
c:\WINDOWS\Profiles\Robin\Cookies\robin@www.clickxchange[2].txt
c:\WINDOWS\Profiles\Robin\Cookies\robin@ad.yieldmanager[1].txt
c:\WINDOWS\Profiles\Robin\Cookies\robin@tribalfusion[1].txt
c:\WINDOWS\Profiles\Robin\Cookies\robin@adopt.specificclick[2].txt
c:\WINDOWS\Profiles\Robin\Cookies\robin@ads.bridgetrack[1].txt
c:\WINDOWS\Profiles\Robin\Cookies\robin@app.insightgrit[2].txt
c:\WINDOWS\Profiles\Robin\Cookies\robin@ads.pointroll[3].txt
c:\WINDOWS\Profiles\Robin\Cookies\robin@ads.pointroll[4].txt
c:\WINDOWS\Profiles\Robin\Cookies\robin@tacoda[3].txt
c:\WINDOWS\Profiles\Robin\Cookies\robin@adinterax[2].txt
c:\WINDOWS\Profiles\Robin\Cookies\robin@adserver[1].txt
c:\WINDOWS\Profiles\Robin\Cookies\robin@interclick[1].txt
c:\WINDOWS\Profiles\Robin\Cookies\robin@collective-media[1].txt
c:\WINDOWS\Profiles\Robin\Cookies\robin@apmebf[2].txt
c:\WINDOWS\Profiles\Robin\Cookies\robin@adrevolver[2].txt
c:\WINDOWS\Profiles\Robin\Cookies\robin@revsci[2].txt
c:\WINDOWS\Profiles\Robin\Cookies\robin@cmpmedica.112.2o7[1].txt
c:\WINDOWS\Profiles\Robin\Cookies\robin@adserver.dns-forums.co[2].txt
c:\WINDOWS\Profiles\Robin\Cookies\robin@zedo[1].txt
c:\WINDOWS\Profiles\Robin\Cookies\robin@msnbc.112.2o7[1].txt
c:\WINDOWS\Profiles\Robin\Cookies\robin@rotator.adjuggler[2].txt
c:\WINDOWS\Profiles\Robin\Cookies\robin@server.iad.liveperson[1].txt
c:\WINDOWS\Profiles\Robin\Cookies\robin@serving-sys[3].txt
c:\WINDOWS\Profiles\Robin\Cookies\robin@adrevolver[1].txt
c:\WINDOWS\Profiles\Robin\Cookies\robin@bs.serving-sys[1].txt
c:\WINDOWS\Profiles\Robin\Cookies\robin@2o7[4].txt
c:\WINDOWS\Profiles\Robin\Cookies\robin@specificclick[4].txt
c:\WINDOWS\Profiles\Robin\Cookies\robin@partner2profit[1].txt
c:\WINDOWS\Profiles\Robin\Cookies\robin@questionmarket[4].txt
c:\WINDOWS\Profiles\Robin\Cookies\robin@media.adrevolver[2].txt
c:\WINDOWS\Profiles\Robin\Cookies\robin@tacoda[1].txt
c:\WINDOWS\Profiles\Robin\Cookies\robin@adopt.specificclick[3].txt
c:\WINDOWS\Profiles\Robin\Cookies\robin@tribalfusion[4].txt
c:\WINDOWS\Profiles\Robin\Cookies\robin@highbeam.122.2o7[1].txt
c:\WINDOWS\Profiles\Robin\Cookies\robin@microsoftwindows.112.2o7[1].txt
c:\WINDOWS\Profiles\Robin\Cookies\robin@specificmedia[1].txt
c:\WINDOWS\Profiles\Robin\Cookies\robin@findarticles[1].txt
c:\WINDOWS\Profiles\Robin\Cookies\robin@dmtracker[1].txt
c:\WINDOWS\Profiles\Robin\Cookies\robin@ads.pointroll[5].txt
c:\WINDOWS\Profiles\Robin\Cookies\robin@trafficmp[2].txt
c:\WINDOWS\Profiles\Robin\Cookies\robin@insightexpressai[2].txt
c:\WINDOWS\Profiles\Robin\Cookies\robin@ad.yieldmanager[3].txt
c:\WINDOWS\Profiles\Robin\Cookies\robin@vitacost.122.2o7[1].txt
c:\WINDOWS\Profiles\Robin\Cookies\robin@tacoda[5].txt
c:\WINDOWS\Profiles\Robin\Cookies\robin@content.yieldmanager[1].txt
c:\WINDOWS\Profiles\Robin\Cookies\robin@content.yieldmanager.edgesuite[1].txt
c:\WINDOWS\Profiles\Robin\Cookies\robin@media.adrevolver[1].txt
c:\WINDOWS\Profiles\Robin\Cookies\robin@dynamic.media.adrevolver[1].txt
c:\WINDOWS\Profiles\Robin\Cookies\robin@www.burstnet[1].txt
c:\WINDOWS\Profiles\Robin\Cookies\robin@apmebf[4].txt
c:\WINDOWS\Profiles\Robin\Cookies\robin@2o7[3].txt
c:\WINDOWS\Profiles\Robin\Cookies\robin@kontera[2].txt
c:\WINDOWS\Profiles\Robin\Cookies\robin@tnswvisitnswdev.122.2o7[1].txt
c:\WINDOWS\Profiles\Robin\Cookies\robin@revsci[3].txt
c:\WINDOWS\Profiles\Robin\Cookies\robin@overture[1].txt
c:\WINDOWS\Profiles\Robin\Cookies\robin@burstnet[2].txt
c:\WINDOWS\Profiles\Robin\Cookies\robin@adrevolver[3].txt
c:\WINDOWS\Profiles\Robin\Cookies\robin@at.atwola[2].txt
c:\WINDOWS\Profiles\Robin\Cookies\robin@meetupcom.122.2o7[1].txt
c:\WINDOWS\Profiles\Robin\Cookies\robin@questionmarket[5].txt
c:\WINDOWS\Profiles\Robin\Cookies\robin@specificclick[5].txt
c:\WINDOWS\Profiles\Robin\Cookies\robin@112.2o7[2].txt
c:\WINDOWS\Profiles\Robin\Cookies\robin@interclick[2].txt
c:\WINDOWS\Profiles\Robin\Cookies\robin@statcounter[4].txt
c:\WINDOWS\Profiles\Robin\Cookies\robin@collective-media[4].txt
c:\WINDOWS\Profiles\Robin\Cookies\robin@tribalfusion[5].txt
c:\WINDOWS\Profiles\Robin\Cookies\robin@bonneville.112.2o7[1].txt
c:\WINDOWS\Profiles\Robin\Cookies\robin@realmedia[2].txt
c:\WINDOWS\Profiles\Robin\Cookies\robin@adopt.specificclick[4].txt
c:\WINDOWS\Profiles\Robin\Cookies\robin@adrevolver[4].txt
c:\WINDOWS\Profiles\Robin\Cookies\robin@richmedia.yahoo[2].txt
c:\WINDOWS\Profiles\Robin\Cookies\robin@ads.telegraph.co[1].txt
c:\WINDOWS\Profiles\Guest\Cookies\default@click-safe[2].txt
c:\WINDOWS\Profiles\Guest\Cookies\default@pennyweb[2].txt
c:\WINDOWS\Profiles\Guest\Cookies\default@websponsors[1].txt
c:\WINDOWS\Profiles\Guest\Cookies\default@adq.nextag[2].txt
c:\WINDOWS\Profiles\Guest\Cookies\default@azjmp[2].txt
c:\WINDOWS\Profiles\Guest\Cookies\default@a.websponsors[1].txt
c:\WINDOWS\Profiles\Guest\Cookies\default@ad.yieldmanager[1].txt
c:\WINDOWS\Profiles\Guest\Cookies\default@rightmedia[3].txt
c:\WINDOWS\Profiles\Guest\Cookies\default@adprofile[1].txt
c:\WINDOWS\Profiles\Guest\Cookies\default@www.launchitmedia[1].txt
c:\WINDOWS\Profiles\Guest\Cookies\default@pathfinder[1].txt
c:\WINDOWS\Profiles\Guest\Cookies\default@112.2o7[1].txt
c:\WINDOWS\Profiles\Guest\Cookies\default@www.popuptraffic[1].txt
c:\WINDOWS\Profiles\Guest\Cookies\default@www.epartmentfinder[1].txt
c:\WINDOWS\Profiles\Guest\Cookies\default@db1.sitestats[2].txt
c:\WINDOWS\Profiles\Guest\Cookies\default@bannerspace[1].txt
c:\WINDOWS\Profiles\Guest\Cookies\default@gostats[2].txt
c:\WINDOWS\Profiles\Guest\Cookies\default@indextools[4].txt
c:\WINDOWS\Profiles\Guest\Cookies\default@1.primaryads[1].txt
c:\WINDOWS\Profiles\Guest\Cookies\default@directtrack[1].txt
c:\WINDOWS\Profiles\Guest\Cookies\default@belnk[2].txt
c:\WINDOWS\Profiles\Guest\Cookies\default@adv.webmd[2].txt
c:\WINDOWS\Profiles\Guest\Cookies\default@metareward[4].txt
c:\WINDOWS\Profiles\Guest\Cookies\default@coolsavings[2].txt
c:\WINDOWS\Profiles\Guest\Cookies\default@travelfinds.sidestep[2].txt
c:\WINDOWS\Profiles\Guest\Cookies\default@secure.directtrack[2].txt
c:\WINDOWS\Profiles\Guest\Cookies\default@hypertracker[2].txt
c:\WINDOWS\Profiles\Guest\Cookies\default@metareward[1].txt
c:\WINDOWS\Profiles\Guest\Cookies\default@trafficsystem[1].txt
c:\WINDOWS\Profiles\Guest\Cookies\default@insightfirst[1].txt
c:\WINDOWS\Profiles\Guest\Cookies\default@media[2].txt
c:\WINDOWS\Profiles\Guest\Cookies\default@emarketmakers[2].txt
c:\WINDOWS\Profiles\Guest\Cookies\default@www.metareward[1].txt
c:\WINDOWS\Profiles\Guest\Cookies\default@nextag[3].txt
c:\WINDOWS\Profiles\Guest\Cookies\default@www.nextag[1].txt
c:\WINDOWS\Profiles\Guest\Cookies\default@etracking[1].txt
c:\WINDOWS\Profiles\Guest\Cookies\default@hotbar[1].txt
c:\WINDOWS\Profiles\Guest\Cookies\default@webfile[2].txt
c:\WINDOWS\Profiles\Guest\Cookies\default@superstats[2].txt
c:\WINDOWS\Profiles\Guest\Cookies\default@adprofile[3].txt
c:\WINDOWS\Profiles\Guest\Cookies\default@www.ticketsnow[2].txt
c:\WINDOWS\Profiles\Guest\Cookies\default@superstats[1].txt
c:\WINDOWS\Profiles\Guest\Cookies\default@dcsadxfd521e5huw2wrttnlc9_4f8h[1].txt
c:\WINDOWS\Profiles\Guest\Cookies\default@adv.webmd[1].txt
c:\WINDOWS\Profiles\Guest\Cookies\default@specificpop[2].txt
c:\WINDOWS\Profiles\Guest\Cookies\default@insightfirst[2].txt
c:\WINDOWS\Profiles\Guest\Cookies\default@ads.touregypt[1].txt
c:\WINDOWS\Profiles\Guest\Cookies\default@www.stats4you[1].txt
c:\WINDOWS\Profiles\Guest\Cookies\default@www.ticketsnow2[2].txt
c:\WINDOWS\Profiles\Guest\Cookies\default@www.findserenitynow[1].txt
c:\WINDOWS\Profiles\Guest\Cookies\default@ads.belointeractive[1].txt
c:\WINDOWS\Profiles\Guest\Cookies\default@media[5].txt
c:\WINDOWS\Profiles\Guest\Cookies\default@media[3].txt
c:\WINDOWS\Profiles\Guest\Cookies\default@www.findonline[1].txt
c:\WINDOWS\Profiles\Guest\Cookies\default@media[6].txt
c:\WINDOWS\Profiles\Guest\Cookies\default@media[4].txt
c:\WINDOWS\Profiles\Guest\Cookies\default@ads.specificclick[1].txt
c:\WINDOWS\Profiles\Guest\Cookies\default@netfastmedia[1].txt
c:\WINDOWS\Profiles\Guest\Cookies\default@ad.slygreetings[1].txt
c:\WINDOWS\Profiles\Guest\Cookies\default@2o7[3].txt
c:\WINDOWS\Profiles\Guest\Cookies\default@atwola[1].txt
c:\WINDOWS\Profiles\Guest\Cookies\default@ads.as4x.tmcs[2].txt
c:\WINDOWS\Profiles\Guest\Cookies\default@ehg-dig.hitbox[6].txt
c:\WINDOWS\Profiles\Guest\Cookies\default@insightexpress[2].txt
c:\WINDOWS\Profiles\Guest\Cookies\default@www.rowise[1].txt
c:\WINDOWS\Profiles\Guest\Cookies\default@intellisrv[1].txt
c:\WINDOWS\Profiles\Guest\Cookies\default@trafficsecrets[1].txt
c:\WINDOWS\Profiles\Guest\Cookies\default@ads.jackpot[2].txt
c:\WINDOWS\Profiles\Guest\Cookies\default@1.primaryads[3].txt
c:\WINDOWS\Profiles\Guest\Cookies\default@ads.ussearch[1].txt
c:\WINDOWS\Profiles\Guest\Cookies\default@indextools[1].txt
c:\WINDOWS\Profiles\Guest\Cookies\default@publishers.clickbooth[1].txt
c:\WINDOWS\Profiles\Guest\Cookies\default@metareward[3].txt
c:\WINDOWS\Profiles\Guest\Cookies\default@azjmp[3].txt
c:\WINDOWS\Profiles\Guest\Cookies\default@dist.belnk[2].txt
c:\WINDOWS\Profiles\Guest\Cookies\default@insightfirst[5].txt
c:\WINDOWS\Profiles\Guest\Cookies\default@indextools[3].txt
c:\WINDOWS\Profiles\Guest\Cookies\default@adv.webmd[4].txt
c:\WINDOWS\Profiles\Guest\Cookies\default@login.tracking101[1].txt
c:\WINDOWS\Profiles\Guest\Cookies\default@dealtime[1].txt
c:\WINDOWS\Profiles\Guest\Cookies\default@stat.dealtime[1].txt
c:\WINDOWS\Profiles\Guest\Cookies\default@ad.yieldmanager[3].txt
c:\WINDOWS\Profiles\Guest\Cookies\default@icc.intellisrv[2].txt
c:\WINDOWS\Profiles\Guest\Cookies\default@nextag[4].txt
c:\WINDOWS\Profiles\Guest\Cookies\default@sfp.directtrack[1].txt
c:\WINDOWS\Profiles\Guest\Cookies\default@coolsavings[1].txt
c:\WINDOWS\Profiles\Guest\Cookies\default@nextag[1].txt
c:\WINDOWS\Profiles\Guest\Cookies\default@adknowledge[1].txt
c:\WINDOWS\Profiles\Guest\Cookies\default@directtrack[3].txt
c:\WINDOWS\Profiles\Guest\Cookies\default@burstnet[2].txt
c:\WINDOWS\Profiles\Guest\Cookies\default@www.burstbeacon[4].txt
c:\WINDOWS\Profiles\Guest\Cookies\default@offersquest.directtrack[2].txt
c:\WINDOWS\Profiles\Guest\Cookies\default@focalex[3].txt
c:\WINDOWS\Profiles\Guest\Cookies\default@www.emarketmakers[1].txt
c:\WINDOWS\Profiles\Guest\Cookies\default@www.burstbeacon[2].txt
c:\WINDOWS\Profiles\Guest\Cookies\default@insightexpress[3].txt
c:\WINDOWS\Profiles\Guest\Cookies\default@512media[1].txt
c:\WINDOWS\Profiles\Guest\Cookies\default@insightfirst[3].txt
c:\WINDOWS\Profiles\Guest\Cookies\default@atwola[3].txt
c:\WINDOWS\Profiles\Guest\Cookies\default@find.intelius[2].txt
c:\WINDOWS\Profiles\Guest\Cookies\default@2o7[4].txt
c:\WINDOWS\Profiles\Guest\Cookies\default@y-1shz2prbmdj6wvny-1sez2pra2dj6wjlyenczklpwmdj6x9ny-1seq-2-2.stats.esomniture[2].txt
c:\WINDOWS\Profiles\Guest\Cookies\default@indextools[2].txt
c:\WINDOWS\Profiles\Guest\Cookies\default@metareward[2].txt
c:\WINDOWS\Profiles\Guest\Cookies\default@focalex[2].txt
c:\WINDOWS\Profiles\Guest\Cookies\default@comparediscounthotels[1].txt
c:\WINDOWS\Profiles\Guest\Cookies\default@websponsors[2].txt
c:\WINDOWS\Profiles\Guest\Cookies\default@rightmedia[2].txt
c:\WINDOWS\Profiles\Guest\Cookies\default@webfile[3].txt
c:\WINDOWS\Profiles\Guest\Cookies\default@clickability[1].txt
c:\WINDOWS\Profiles\Guest\Cookies\default@stats[1].txt
c:\WINDOWS\Profiles\Guest\Cookies\default@dealtime[2].txt
c:\WINDOWS\Profiles\Guest\Cookies\default@tracking[1].txt
c:\WINDOWS\Profiles\Guest\Cookies\default@banner[1].txt
c:\WINDOWS\Profiles\Guest\Cookies\default@emarketmakers[1].txt
c:\WINDOWS\Profiles\Guest\Cookies\default@ads.as4x.tmcs.ticketmaster[1].txt
c:\WINDOWS\Profiles\Guest\Cookies\default@atwola[2].txt
c:\WINDOWS\Profiles\Guest\Cookies\default@y-1shz2prbmdj6wvny-1sez2pra2dj6wjnyopcjweoqsdj6x9ny-1seq-2-2.stats.esomniture[2].txt
c:\WINDOWS\Profiles\Guest\Cookies\default@y-1shz2prbmdj6wvny-1sez2pra2dj6wjlyenczklpwmdj6x9ny-1seq-2-2.stats.esomniture[3].txt
c:\WINDOWS\Profiles\Guest\Cookies\default@adq.nextag[1].txt
c:\WINDOWS\Profiles\Guest\Cookies\default@nextag[2].txt
c:\WINDOWS\Profiles\Guest\Cookies\default@y-1shz2prbmdj6wvny-1sez2pra2dj6wjnywhdzikqqudj6x9ny-1seq-2-2.stats.esomniture[2].txt
c:\WINDOWS\Profiles\Guest\Cookies\default@a-1shz2prbmdj6wvny-1sez2pra2dj6wjk4kmajwdpg-1dj6x9ny-1seq-2-2.stats.esomniture[2].txt
c:\WINDOWS\Profiles\Guest\Cookies\default@a-1shz2prbmdj6wvny-1sez2pra2dj6wfkislajcfpw-1dj6x9ny-1seq-2-2.stats.esomniture[2].txt
c:\WINDOWS\Profiles\Guest\Cookies\default@y-1shz2prbmdj6wvny-1sez2pra2dj6wjmiomcjmhoqidj6x9ny-1seq-2-2.stats.esomniture[2].txt
c:\WINDOWS\Profiles\Guest\Cookies\default@y-1shz2prbmdj6wvny-1sez2pra2dj6wjl4spdzcdoasdj6x9ny-1seq-2-2.stats.esomniture[2].txt
c:\WINDOWS\Profiles\Guest\Cookies\default@y-1shz2prbmdj6wvny-1sez2pra2dj6wjkyqkcpseoamdj6x9ny-1seq-2-2.stats.esomniture[2].txt
c:\WINDOWS\Profiles\Guest\Cookies\default@y-1shz2prbmdj6wvny-1sez2pra2dj6wjliegdjelpgydj6x9ny-1seq-2-2.stats.esomniture[2].txt
c:\WINDOWS\Profiles\Guest\Cookies\default@hypertracker[1].txt
c:\WINDOWS\Profiles\Guest\Cookies\default@insightexpress[1].txt
c:\WINDOWS\Profiles\Guest\Cookies\default@y-1shz2prbmdj6wvny-1sez2pra2dj6wjnycnajmhpqidj6x9ny-1seq-2-2.stats.esomniture[1].txt
c:\WINDOWS\Profiles\Guest\Cookies\default@stat.dealtime[3].txt
c:\WINDOWS\Profiles\Guest\Cookies\default@www.blowoutbanners[2].txt
c:\WINDOWS\Profiles\Guest\Cookies\default@goto.trafficmultiplier[2].txt
c:\WINDOWS\Profiles\Guest\Cookies\default@www.burstbeacon[3].txt
c:\WINDOWS\Profiles\Guest\Cookies\default@y-1shz2prbmdj6wvny-1sez2pra2dj6wjkyoiczwgqqidj6x9ny-1seq-2-2.stats.esomniture[2].txt
c:\WINDOWS\Profiles\Guest\Cookies\default@stats.manticoretechnology[1].txt
c:\WINDOWS\Profiles\Guest\Cookies\default@-1shz2prbmdj6wvny-1sez2pra2dj6wjny-1mczoloaudj6x9ny-1seq-2-2.stats.esomniture[2].txt
c:\WINDOWS\Profiles\Guest\Cookies\default@fcstats.bcentral[1].txt
c:\WINDOWS\Profiles\Guest\Cookies\default@hotels-and-discounts[1].txt
c:\WINDOWS\Profiles\Guest\Cookies\default@bizrate[2].txt
c:\WINDOWS\Profiles\Guest\Cookies\default@realtytracker[1].txt
c:\WINDOWS\Profiles\Guest\Cookies\default@y-1shz2prbmdj6wvny-1sez2pra2dj6wjliwmdjshowsdj6x9ny-1seq-2-2.stats.esomniture[1].txt
c:\WINDOWS\Profiles\Guest\Cookies\default@y-1shz2prbmdj6wvny-1sez2pra2dj6wjliojcjcapw6dj6x9ny-1seq-2-2.stats.esomniture[1].txt
c:\WINDOWS\Profiles\Guest\Cookies\default@find.intelius[3].txt
c:\WINDOWS\Profiles\Guest\Cookies\default@insightfirst[4].txt
c:\WINDOWS\Profiles\Guest\Cookies\default@adopt.specificclick[1].txt
c:\WINDOWS\Profiles\Guest\Cookies\default@secure.directtrack[1].txt
c:\WINDOWS\Profiles\Guest\Cookies\default@a.websponsors[2].txt
c:\WINDOWS\Profiles\Guest\Cookies\default@windowsmedia[1].txt
c:\WINDOWS\Profiles\Guest\Cookies\default@clicks.jackpot[1].txt
c:\WINDOWS\Profiles\Guest\Cookies\default@www.metareward[3].txt
c:\WINDOWS\Profiles\Guest\Cookies\default@clicks.winsweepstakes[1].txt
c:\WINDOWS\Profiles\Guest\Cookies\default@lynxtrack[1].txt
c:\WINDOWS\Profiles\Guest\Cookies\default@itimenetwork.directtrack[2].txt
c:\WINDOWS\Profiles\Guest\Cookies\default@qnsr[2].txt
c:\WINDOWS\Profiles\Guest\Cookies\default@emarketmakers[3].txt
c:\WINDOWS\Profiles\Guest\Cookies\default@belnk[3].txt
c:\WINDOWS\Profiles\Guest\Cookies\anyuser@azjmp[2].txt
c:\WINDOWS\Profiles\Guest\Cookies\anyuser@adprofile[1].txt
c:\WINDOWS\Profiles\Guest\Cookies\anyuser@www.rowise[1].txt
c:\WINDOWS\Profiles\Guest\Cookies\anyuser@gozing.directtrack[2].txt
c:\WINDOWS\Profiles\Guest\Cookies\anyuser@indextools[1].txt
c:\WINDOWS\Profiles\Guest\Cookies\anyuser@ad.yieldmanager[2].txt
c:\WINDOWS\Profiles\Guest\Cookies\anyuser@sfp.directtrack[2].txt
c:\WINDOWS\Profiles\Guest\Cookies\anyuser@emarketmakers[1].txt
c:\WINDOWS\Profiles\Guest\Cookies\anyuser@directtrack[1].txt
c:\WINDOWS\Profiles\Guest\Cookies\anyuser@1.primaryads[1].txt
c:\WINDOWS\Profiles\Guest\Cookies\anyuser@itimenetwork.directtrack[2].txt
c:\WINDOWS\Profiles\Guest\Cookies\anyuser@searchforgreatdiscounts[1].txt
c:\WINDOWS\Profiles\Guest\Cookies\anyuser@www.findtherightschool[1].txt
c:\WINDOWS\Profiles\Guest\Cookies\anyuser@qnsr[2].txt
c:\WINDOWS\Profiles\Guest\Cookies\anyuser@clicks.searchforgreatdiscounts[1].txt
c:\WINDOWS\Profiles\Guest\Cookies\anyuser@dist.belnk[2].txt
c:\WINDOWS\Profiles\Guest\Cookies\anyuser@www.cyberneticmedia[1].txt
c:\WINDOWS\Profiles\Guest\Cookies\anyuser@publishers.clickbooth[2].txt
c:\WINDOWS\Profiles\Guest\Cookies\anyuser@metareward[2].txt
c:\WINDOWS\Profiles\Guest\Cookies\anyuser@coolsavings[2].txt
c:\WINDOWS\Profiles\Guest\Cookies\anyuser@a.websponsors[1].txt
c:\WINDOWS\Profiles\Guest\Cookies\anyuser@login.tracking101[2].txt
c:\WINDOWS\Profiles\Guest\Cookies\anyuser@belnk[2].txt
c:\WINDOWS\Profiles\Guest\Cookies\anyuser@belnk[3].txt
c:\WINDOWS\Profiles\Guest\Cookies\francine@msnportal.112.2o7[1].txt

Registry Cleaner Trial
HKCR\Install.Install
HKCR\Install.Install\CLSID
HKCR\Install.Install\CurVer
HKCR\Install.Install.1
HKCR\Install.Install.1\CLSID
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\ModuleUsage\C:/WINDOWS/Downloaded Program Files/Install.dll
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\SharedDLLs#C:\WINDOWS\Downloaded Program Files\Install.dll [  ]


During the scan I did not see the file that AVG Free had targeted as the infected one, nor is it in the files above. So, what is next?
Laffnmule's Lode

eMachines EZ1601-01; Intel Atom processor N270, speed ?; 1 GB RAM DDR2; 160 GB HDD; Built-in Graphics; Linksys Wireless Router, DSL modem; Windows XP Home Edition with SP3; mostly Google Chrome 16.0.912.77m, also IE 8.0.6001.18702; Yahoo Mail; Microsoft Security Essentials

#4 buddy215

buddy215

  • Moderator
  • 13,501 posts
  • OFFLINE
  •  
  • Gender:Male
  • Location:West Tennessee
  • Local time:12:35 AM

Posted 12 January 2009 - 06:35 PM

Not sure what cleanup tool works in ME. Try going to internet options and delete/remove temporary files.

You should run a scan daily with SAS for the next 3 days after updating it. The reason is that the malware you have constantly changes to hide from the security programs and they are always playing catchup.

You can block the Ad/ tracking cookies from ever installing on your computer by following the steps below.
This applies to Internet explorer browsers.
Click on tools
click on internet options
click on privacy tab
click on advanced button
put a check in the box next to override automatic cookie handling
put a check in the box next to first party accept
put a check in the box next to block third party cookies (those are the ad/ tracking cookies that AVG deletes)
Click OK to exit
Then just run another quick scan with SAS to remove the third party cookies that were installed before changing the settings.

Open up Sun Java and delete the cached files. If you have more than one version of Java in Add/Remove, remove all but the latest. I don't think the latest Java supports ME.
To remove temp files in Java cache: click on the Java icon, general tab, click on the settings button under "temporary internet files, click on "delete files"

Edited by buddy215, 12 January 2009 - 06:43 PM.

“Every atom in your body came from a star that exploded and the atoms in your left hand probably came from a different star than your right hand. It really is the most poetic thing I know about physics...you are all stardust.”Lawrence M. Krauss
A 1792 U.S. penny, designed in part by Thomas Jefferson and George Washington, reads “Liberty Parent of Science & Industry.”

#5 Laffnmule's Lode

Laffnmule's Lode
  • Topic Starter

  • Members
  • 38 posts
  • OFFLINE
  •  
  • Local time:11:35 PM

Posted 14 January 2009 - 12:04 AM

I have made the internet options setting changes you recomended.

I don't know where to go to open Sun Java, I have no idea where the Java icon is located (or what it looks like). It is not on my desktop. I tried clicking the start button, going to progams, and looking there; but could not find any Java. I did a File and Folders Search for *Java.* All that I found was:

MSJAVA.DLL In Folder C:\WINDOWS\SYSTEM 926kb Application Extension Modified 2/28/2003

msjava.cat In Folder C:\WINDOWS\SYSTEM\CatRoot\{... 14kb Security Catalog Modified 3/4/2003

JAVA.INF In Folder C:\WINDOWS\INF 45kb Setup Information Modified 2/28/2003

So I have not yet done anything with Java.

I updated and ran SAS again. Here is the new log:


SUPERAntiSpyware Scan Log
http://www.superantispyware.com

Generated 01/13/2009 at 07:24 PM

Application Version : 4.24.1004

Core Rules Database Version : 3708
Trace Rules Database Version: 1683

Scan type : Complete Scan
Total Scan Time : 01:50:01

Memory items scanned : 84
Memory threats detected : 0
Registry items scanned : 3736
Registry threats detected : 0
File items scanned : 106338
File threats detected : 19

Adware.Tracking Cookie
C:\WINDOWS\Cookies\anyuser@content.yieldmanager.edgesuite[1].txt
C:\WINDOWS\Cookies\anyuser@specificclick[1].txt
C:\WINDOWS\Cookies\anyuser@content.yieldmanager[2].txt
C:\WINDOWS\Cookies\anyuser@apmebf[1].txt
C:\WINDOWS\Cookies\anyuser@richmedia.yahoo[2].txt
C:\WINDOWS\Cookies\anyuser@ads.pointroll[1].txt
C:\WINDOWS\Cookies\anyuser@bs.serving-sys[2].txt
C:\WINDOWS\Cookies\anyuser@tribalfusion[2].txt
C:\WINDOWS\Cookies\anyuser@dynamic.media.adrevolver[1].txt
C:\WINDOWS\Cookies\anyuser@ak[2].txt
C:\WINDOWS\Cookies\anyuser@adrevolver[1].txt
C:\WINDOWS\Cookies\anyuser@media.adrevolver[1].txt
C:\WINDOWS\Cookies\anyuser@adopt.specificclick[1].txt
C:\WINDOWS\Cookies\anyuser@questionmarket[2].txt
C:\WINDOWS\Cookies\anyuser@msnportal.112.2o7[1].txt
C:\WINDOWS\Cookies\anyuser@serving-sys[1].txt
C:\WINDOWS\Cookies\anyuser@adopt.euroclick[2].txt
C:\WINDOWS\Cookies\anyuser@ad.yieldmanager[2].txt
C:\WINDOWS\Cookies\anyuser@specificmedia[1].txt
Laffnmule's Lode

eMachines EZ1601-01; Intel Atom processor N270, speed ?; 1 GB RAM DDR2; 160 GB HDD; Built-in Graphics; Linksys Wireless Router, DSL modem; Windows XP Home Edition with SP3; mostly Google Chrome 16.0.912.77m, also IE 8.0.6001.18702; Yahoo Mail; Microsoft Security Essentials

#6 buddy215

buddy215

  • Moderator
  • 13,501 posts
  • OFFLINE
  •  
  • Gender:Male
  • Location:West Tennessee
  • Local time:12:35 AM

Posted 14 January 2009 - 06:17 AM

Sun Java would have shown up in your program files. If you don't have it installed, nothing to delete.

Looks like you have removed the malware. I suggest you keep SAS and update it often so it is ready when needed.
Would be a good idea to run some scans in the next week to be sure the malware is gone.
“Every atom in your body came from a star that exploded and the atoms in your left hand probably came from a different star than your right hand. It really is the most poetic thing I know about physics...you are all stardust.”Lawrence M. Krauss
A 1792 U.S. penny, designed in part by Thomas Jefferson and George Washington, reads “Liberty Parent of Science & Industry.”

#7 Laffnmule's Lode

Laffnmule's Lode
  • Topic Starter

  • Members
  • 38 posts
  • OFFLINE
  •  
  • Local time:11:35 PM

Posted 15 January 2009 - 10:43 PM

I updated and ran SAS today. Here is the log:

SUPERAntiSpyware Scan Log
http://www.superantispyware.com

Generated 01/15/2009 at 06:48 PM

Application Version : 4.24.1004

Core Rules Database Version : 3712
Trace Rules Database Version: 1687

Scan type : Complete Scan
Total Scan Time : 01:49:31

Memory items scanned : 84
Memory threats detected : 0
Registry items scanned : 3736
Registry threats detected : 0
File items scanned : 105728
File threats detected : 0


The malware is still on my computer. Its file is located at:
C:\\WINDOWS\TEMPORARY INTERNET FILES\CONTENT.IE5\4DMVSPYJ\FREESCAN[1].HTM

EDIT: I have not yet deleted the Temporary Internet Files, because I am afraid that something essential will get deleted along with them, or else the malware itself might become activated.

Should I go ahead and put it in the AVG Free Virus Vault, despite the warning from AVG Free?

The warning reads, "If a system file is removed from your disk, the operating system may cause an error and may be unstable. Do you really want to move the file into the Virus Vault?"

What do I try next?

Edited by Laffnmule's Lode, 16 January 2009 - 12:23 AM.

Laffnmule's Lode

eMachines EZ1601-01; Intel Atom processor N270, speed ?; 1 GB RAM DDR2; 160 GB HDD; Built-in Graphics; Linksys Wireless Router, DSL modem; Windows XP Home Edition with SP3; mostly Google Chrome 16.0.912.77m, also IE 8.0.6001.18702; Yahoo Mail; Microsoft Security Essentials

#8 buddy215

buddy215

  • Moderator
  • 13,501 posts
  • OFFLINE
  •  
  • Gender:Male
  • Location:West Tennessee
  • Local time:12:35 AM

Posted 16 January 2009 - 08:20 AM

Your last scan says SAS found no malware. You can clean out the temporary files by following the directions below.

For Internet Explorer 5 and above, you can follow these directions to clear out temporary files and delete cookies.

1) Open Internet Explorer and click on Tools
2) Click on Internet Options
3) On the General Tab, in the middle of the screen, click on Delete Files
4) You may also want to check the box "Delete all offline content"
5) Click on OK and wait for the hourglass icon to stop after it deletes the temporary internet files
6) You can now click on Delete Cookies and click OK to delete cookies that websites have placed on your hard drive.

To clear the Internet History in IE:

1) Open Internet Explorer and click on Tools
2) Click on Internet Options
3) On the General Tab, in the middle of the screen, click on Clear History
4) Click OK

To clean up other temporary files on your computer in Windows 98 or higher:

1) Click Start, Programs (or All Programs), Accessories, System Tools, Disk Cleanup
2) Choose the correct drive usually C:\
3) Check the boxes in the list and delete the files
“Every atom in your body came from a star that exploded and the atoms in your left hand probably came from a different star than your right hand. It really is the most poetic thing I know about physics...you are all stardust.”Lawrence M. Krauss
A 1792 U.S. penny, designed in part by Thomas Jefferson and George Washington, reads “Liberty Parent of Science & Industry.”

#9 Laffnmule's Lode

Laffnmule's Lode
  • Topic Starter

  • Members
  • 38 posts
  • OFFLINE
  •  
  • Local time:11:35 PM

Posted 16 January 2009 - 09:06 PM

I deleted the Temporary Internet Files. Hopefully, the malware Antivirus 2009 is gone (I still need to confirm that by doing a complete scan with AVG Free).

Then I ran SAS again, here is the latest log:

SUPERAntiSpyware Scan Log
http://www.superantispyware.com

Generated 01/16/2009 at 02:09 PM

Application Version : 4.24.1004

Core Rules Database Version : 3713
Trace Rules Database Version: 1688

Scan type : Complete Scan
Total Scan Time : 01:06:16

Memory items scanned : 84
Memory threats detected : 0
Registry items scanned : 3736
Registry threats detected : 0
File items scanned : 48977
File threats detected : 1

Adware.Tracking Cookie
C:\WINDOWS\Cookies\anyuser@richmedia.yahoo[1].txt


I have not yet deleted all the other cookies, or the internet history.
Laffnmule's Lode

eMachines EZ1601-01; Intel Atom processor N270, speed ?; 1 GB RAM DDR2; 160 GB HDD; Built-in Graphics; Linksys Wireless Router, DSL modem; Windows XP Home Edition with SP3; mostly Google Chrome 16.0.912.77m, also IE 8.0.6001.18702; Yahoo Mail; Microsoft Security Essentials

#10 Laffnmule's Lode

Laffnmule's Lode
  • Topic Starter

  • Members
  • 38 posts
  • OFFLINE
  •  
  • Local time:11:35 PM

Posted 19 January 2009 - 01:38 AM

I deleted cookies and Temporary Internet Files. I cleared Internet History. I checked my AVG Free, and it has not detected any threats. I did a complete Scan Disk, then Disk Defragmenter. I updated, then ran SAS again; and came out clean, here is the latest log:

SUPERAntiSpyware Scan Log
http://www.superantispyware.com

Generated 01/18/2009 at 08:56 PM

Application Version : 4.24.1004

Core Rules Database Version : 3714
Trace Rules Database Version: 1689

Scan type : Complete Scan
Total Scan Time : 01:05:50

Memory items scanned : 84
Memory threats detected : 0
Registry items scanned : 3736
Registry threats detected : 0
File items scanned : 49701
File threats detected : 0


I still have yet to do the disk clean up.

I guess I might be clear of the Antivirus 2009 threat, for now; I sure hope so.
Thanks for your help Buddy215.
________

Laffnmule's Lode

Edited by Laffnmule's Lode, 19 January 2009 - 01:40 AM.

Laffnmule's Lode

eMachines EZ1601-01; Intel Atom processor N270, speed ?; 1 GB RAM DDR2; 160 GB HDD; Built-in Graphics; Linksys Wireless Router, DSL modem; Windows XP Home Edition with SP3; mostly Google Chrome 16.0.912.77m, also IE 8.0.6001.18702; Yahoo Mail; Microsoft Security Essentials

#11 buddy215

buddy215

  • Moderator
  • 13,501 posts
  • OFFLINE
  •  
  • Gender:Male
  • Location:West Tennessee
  • Local time:12:35 AM

Posted 19 January 2009 - 07:28 AM

Glad to of helped you.
Surf Safe

You should keep SAS around and update often so it will be ready if problems arise.
“Every atom in your body came from a star that exploded and the atoms in your left hand probably came from a different star than your right hand. It really is the most poetic thing I know about physics...you are all stardust.”Lawrence M. Krauss
A 1792 U.S. penny, designed in part by Thomas Jefferson and George Washington, reads “Liberty Parent of Science & Industry.”




0 user(s) are reading this topic

0 members, 0 guests, 0 anonymous users