Jump to content


 


Register a free account to unlock additional features at BleepingComputer.com
Welcome to BleepingComputer, a free community where people like yourself come together to discuss and learn how to use their computers. Using the site is easy and fun. As a guest, you can browse and view the various discussions in the forums, but can not create a new topic or reply to an existing one unless you are logged in. Other benefits of registering an account are subscribing to topics and forums, creating a blog, and having no ads shown anywhere on the site.


Click here to Register a free account now! or read our Welcome Guide to learn how to use this site.

Photo

From: PlZ Help, PC restarts, I can't download, extremly slow/ Moved


  • This topic is locked This topic is locked
53 replies to this topic

#1 1bsymum

1bsymum

  • Members
  • 115 posts
  • OFFLINE
  •  
  • Local time:10:10 AM

Posted 03 March 2009 - 12:51 AM

I was able to open Hijackthis program here it is, can you tell me if I have a virus and how to get rid of it? Thank you.

Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 10:46:50 PM, on 3/2/2009
Platform: Windows Vista SP1 (WinNT 6.00.1905)
MSIE: Internet Explorer v7.00 (7.00.6001.18000)
Boot mode: Normal

Running processes:
C:\Windows\system32\taskeng.exe
C:\Windows\system32\Dwm.exe
C:\Windows\Explorer.EXE
C:\Program Files\Windows Defender\MSASCui.exe
C:\Program Files\Intel\IntelDH\CCU\CCU_TrayIcon.exe
C:\Program Files\Intel\Intel Matrix Storage Manager\IAAnotif.exe
C:\Program Files\Lexmark 4200 Series\LXBMmon.exe
C:\Program Files\Ulead Systems\Ulead Photo Express My Scrapbook 2.0\CalCheck.exe
C:\Windows\System32\wpcumi.exe
C:\Program Files\iTunes\iTunesHelper.exe
C:\Program Files\Avira\AntiVir PersonalEdition Classic\avgnt.exe
C:\Program Files\Intel\IntelDH\CCU\CCU_Engine.exe
C:\Windows\sttray.exe
C:\Windows\System32\rundll32.exe
C:\Windows\ehome\ehtray.exe
C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
C:\Program Files\Windows Media Player\wmpnscfg.exe
C:\Windows\System32\rundll32.exe
C:\Windows\ehome\ehmsas.exe
C:\Windows\system32\wbem\unsecapp.exe
C:\Program Files\Internet Explorer\ieuser.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\Common Files\Microsoft Shared\Works Shared\wkcalrem.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = http://g.msn.com/0SEENUS/SAOS01?FORM=TOOLBR
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://g.msn.com/0SEENUS/SAOS01?FORM=TOOLBR
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.yahoo.com/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.yahoo.com
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.yahoo.com
R1 - HKCU\Software\Microsoft\Internet Explorer\SearchURL,(Default) = http://g.msn.com/0SEENUS/SAOS01?FORM=TOOLBR
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
O1 - Hosts: ::1 localhost
O2 - BHO: &Yahoo! Toolbar Helper - {02478D38-C3F9-4efb-9B51-7695ECA05670} - C:\Program Files\Yahoo!\Companion\Installs\cpn0\yt.dll
O2 - BHO: AcroIEHelperStub - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll
O2 - BHO: Spybot-S&D IE Protection - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_01\bin\ssv.dll
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar1.dll
O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\5.0.926.3450\swg.dll
O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar1.dll
O3 - Toolbar: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn0\yt.dll
O3 - Toolbar: (no name) - {0BF43445-2F28-4351-9252-17FE6E806AA0} - (no file)
O4 - HKLM\..\Run: [Windows Defender] "C:\Program Files\Windows Defender\MSASCui.exe" -hide
O4 - HKLM\..\Run: [NMSSupport] "C:\Program Files\Common Files\Intel\IntelDH\NMS\Support\IntelHCTAgent.exe" /startup
O4 - HKLM\..\Run: [CCUTRAYICON] "C:\Program Files\Intel\IntelDH\CCU\CCU_TrayIcon.exe"
O4 - HKLM\..\Run: [IAAnotif] "C:\Program Files\Intel\Intel Matrix Storage Manager\Iaanotif.exe"
O4 - HKLM\..\Run: [Spare Backup] "C:\Program Files\Spare Backup\SpareBackup.exe" /silent
O4 - HKLM\..\Run: [BigFix] "c:\program files\Bigfix\bigfix.exe" /atstartup
O4 - HKLM\..\Run: [lxbmmon.exe] "C:\Program Files\Lexmark 4200 Series\lxbmmon.exe"
O4 - HKLM\..\Run: [Lexmark 4200 Series Fax Server] "C:\Program Files\Lexmark 4200 Series\fm3032.exe" /s
O4 - HKLM\..\Run: [Ulead Photo Express Calendar Checker] "C:\Program Files\Ulead Systems\Ulead Photo Express My Scrapbook 2.0\calcheck.exe"
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\QTTask.exe" -atboottime
O4 - HKLM\..\Run: [WPCUMI] C:\Windows\system32\WpcUmi.exe
O4 - HKLM\..\Run: [AppleSyncNotifier] C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleSyncNotifier.exe
O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
O4 - HKLM\..\Run: [avgnt] "C:\Program Files\Avira\AntiVir PersonalEdition Classic\avgnt.exe" /min
O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 9.0\Reader\Reader_sl.exe"
O4 - HKLM\..\Run: [SigmatelSysTrayApp] sttray.exe
O4 - HKLM\..\Run: [NvSvc] RUNDLL32.EXE C:\Windows\system32\nvsvc.dll,nvsvcStart
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\Windows\system32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\Windows\system32\NvMcTray.dll,NvTaskbarInit
O4 - HKLM\..\RunOnce: [Launcher] %WINDIR%\SMINST\launcher.exe
O4 - HKCU\..\Run: [ehTray.exe] C:\Windows\ehome\ehTray.exe
O4 - HKCU\..\Run: [SpybotSD TeaTimer] C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
O4 - HKCU\..\Run: [WMPNSCFG] C:\Program Files\Windows Media Player\WMPNSCFG.exe
O4 - HKUS\S-1-5-19\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /detectMem (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-19\..\Run: [WindowsWelcomeCenter] rundll32.exe oobefldr.dll,ShowWelcomeCenter (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-20\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /detectMem (User 'NETWORK SERVICE')
O4 - HKUS\S-1-5-21-3927571385-4176734311-2547241167-1000\..\Run: [Sidebar] "C:\Program Files\Windows Sidebar\Sidebar.exe" /detectMem (User 'IUSR_NMPR')
O4 - HKUS\S-1-5-21-3927571385-4176734311-2547241167-1002\..\Run: [Sidebar] C:\Program Files\Windows Sidebar\sidebar.exe /autoRun (User 'kids')
O4 - S-1-5-21-3927571385-4176734311-2547241167-1002 Startup: LimeWire On Startup.lnk = C:\Program Files\LimeWire\LimeWire.exe (User 'kids')
O4 - S-1-5-21-3927571385-4176734311-2547241167-1002 Startup: OneNote 2007 Screen Clipper and Launcher.lnk = C:\Program Files\Microsoft Office\Office12\ONENOTEM.EXE (User 'kids')
O4 - S-1-5-21-3927571385-4176734311-2547241167-1002 User Startup: LimeWire On Startup.lnk = C:\Program Files\LimeWire\LimeWire.exe (User 'kids')
O4 - S-1-5-21-3927571385-4176734311-2547241167-1002 User Startup: OneNote 2007 Screen Clipper and Launcher.lnk = C:\Program Files\Microsoft Office\Office12\ONENOTEM.EXE (User 'kids')
O4 - Startup: OneNote 2007 Screen Clipper and Launcher.lnk = C:\Program Files\Microsoft Office\Office12\ONENOTEM.EXE
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_01\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_01\bin\ssv.dll
O9 - Extra button: Send to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~2\Office12\ONBttnIE.dll
O9 - Extra 'Tools' menuitem: S&end to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~2\Office12\ONBttnIE.dll
O9 - Extra button: (no name) - {85d1f590-48f4-11d9-9669-0800200c9a66} - C:\Windows\bdoscandel.exe (file missing)
O9 - Extra 'Tools' menuitem: Uninstall BitDefender Online Scanner v8 - {85d1f590-48f4-11d9-9669-0800200c9a66} - C:\Windows\bdoscandel.exe (file missing)
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\Office12\REFIEBAR.DLL
O9 - Extra button: (no name) - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O9 - Extra 'Tools' menuitem: Spybot - Search & Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O10 - Unknown file in Winsock LSP: c:\windows\system32\wpclsp.dll
O10 - Unknown file in Winsock LSP: c:\windows\system32\wpclsp.dll
O10 - Unknown file in Winsock LSP: c:\windows\system32\wpclsp.dll
O10 - Unknown file in Winsock LSP: c:\windows\system32\wpclsp.dll
O10 - Unknown file in Winsock LSP: c:\windows\system32\wpclsp.dll
O10 - Unknown file in Winsock LSP: c:\windows\system32\wpclsp.dll
O10 - Unknown file in Winsock LSP: c:\windows\system32\wpclsp.dll
O10 - Unknown file in Winsock LSP: c:\windows\system32\wpclsp.dll
O10 - Unknown file in Winsock LSP: c:\windows\system32\wpclsp.dll
O16 - DPF: {0742B9EF-8C83-41CA-BFBA-830A59E23533} (Microsoft Data Collection Control) - https://support.microsoft.com/OAS/ActiveX/MSDcode.cab
O16 - DPF: {3860DD98-0549-4D50-AA72-5D17D200EE10} (Windows Live OneCare safety scanner control) - http://cdn.scan.onecare.live.com/resource/...s/wlscctrl2.cab
O23 - Service: Lavasoft Ad-Aware Service (aawservice) - Lavasoft - C:\Program Files\Lavasoft\Ad-Aware\aawservice.exe
O23 - Service: Agere Modem Call Progress Audio (AgereModemAudio) - Agere Systems - C:\Windows\system32\agrsmsvc.exe
O23 - Service: Intel® Alert Service (AlertService) - Intel® Corporation - C:\Program Files\Intel\IntelDH\CCU\AlertService.exe
O23 - Service: Avira AntiVir Personal - Free Antivirus Scheduler (AntiVirScheduler) - Avira GmbH - C:\Program Files\Avira\AntiVir PersonalEdition Classic\sched.exe
O23 - Service: Avira AntiVir Personal - Free Antivirus Guard (AntiVirService) - Avira GmbH - C:\Program Files\Avira\AntiVir PersonalEdition Classic\avguard.exe
O23 - Service: Apple Mobile Device - Apple Inc. - C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
O23 - Service: Bonjour Service - Apple Inc. - C:\Program Files\Bonjour\mDNSResponder.exe
O23 - Service: Intel® DHTrace Controller (DHTRACE) - Intel® Corporation - C:\Program Files\Common Files\Intel\IntelDH\bin\DHTraceController.exe
O23 - Service: DQLWinService - Unknown owner - C:\Program Files\Common Files\Intel\IntelDH\NMS\AdpPlugins\DQLWinService.exe
O23 - Service: GameConsoleService - WildTangent, Inc. - C:\Program Files\Gateway Games\Gateway Game Console\GameConsoleService.exe
O23 - Service: Google Update Service (gupdate1c9662e9aaf4c23) (gupdate1c9662e9aaf4c23) - Google Inc. - C:\Program Files\Google\Update\GoogleUpdate.exe
O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: Intel® Matrix Storage Event Monitor (IAANTMON) - Intel Corporation - C:\Program Files\Intel\Intel Matrix Storage Manager\Iaantmon.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: iPod Service - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: Intel® Software Services Manager (ISSM) - Intel® Corporation - C:\Program Files\Intel\IntelDH\Intel Media Server\Media Server\bin\ISSM.exe
O23 - Service: lxbm_device - - C:\Windows\system32\lxbmcoms.exe
O23 - Service: Intel® Viiv™ Media Server (M1 Server) - Unknown owner - C:\Program Files\Intel\IntelDH\Intel Media Server\Media Server\bin\mediaserver.exe
O23 - Service: Intel® Application Tracker (MCLServiceATL) - Intel® Corporation - C:\Program Files\Intel\IntelDH\Intel Media Server\Shells\MCLServiceATL.exe
O23 - Service: Intel® NMSCore (NMSCore) - Intel® Corporation - C:\Program Files\Common Files\Intel\IntelDH\NMS\NMSCore\NMSCore.exe
O23 - Service: PrismXL - New Boundary Technologies, Inc. - C:\Program Files\Common Files\New Boundary\PrismXL\PRISMXL.SYS
O23 - Service: Intel® Quality Manager (QualityManager) - Intel® Corporation - C:\Program Files\Intel\IntelDH\Intel Media Server\Media Server\bin\qualitymanager.exe
O23 - Service: Intel® Remoting Service (Remote UI Service) - Intel® Corporation - C:\Program Files\Intel\IntelDH\Intel Media Server\Shells\Remote UI Service.exe

--
End of file - 12112 bytes


StartupList report, 3/2/2009, 10:49:13 PM
StartupList version: 1.52.2
Started from : C:\Program Files\Trend Micro\HijackThis\HijackThis.EXE
Detected: Windows Vista SP1 (WinNT 6.00.1905)
Detected: Internet Explorer v7.00 (7.00.6001.18000)
* Using default options
==================================================

Running processes:

C:\Windows\system32\taskeng.exe
C:\Windows\system32\Dwm.exe
C:\Windows\Explorer.EXE
C:\Program Files\Windows Defender\MSASCui.exe
C:\Program Files\Intel\IntelDH\CCU\CCU_TrayIcon.exe
C:\Program Files\Intel\Intel Matrix Storage Manager\IAAnotif.exe
C:\Program Files\Lexmark 4200 Series\LXBMmon.exe
C:\Program Files\Ulead Systems\Ulead Photo Express My Scrapbook 2.0\CalCheck.exe
C:\Windows\System32\wpcumi.exe
C:\Program Files\iTunes\iTunesHelper.exe
C:\Program Files\Avira\AntiVir PersonalEdition Classic\avgnt.exe
C:\Program Files\Intel\IntelDH\CCU\CCU_Engine.exe
C:\Windows\sttray.exe
C:\Windows\System32\rundll32.exe
C:\Windows\ehome\ehtray.exe
C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
C:\Program Files\Windows Media Player\wmpnscfg.exe
C:\Windows\System32\rundll32.exe
C:\Windows\ehome\ehmsas.exe
C:\Windows\system32\wbem\unsecapp.exe
C:\Program Files\Internet Explorer\ieuser.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\Common Files\Microsoft Shared\Works Shared\wkcalrem.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe
C:\Windows\system32\SearchFilterHost.exe

--------------------------------------------------

Listing of startup folders:

Shell folders Startup:
[C:\Users\marquelle\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup]
OneNote 2007 Screen Clipper and Launcher.lnk = C:\Program Files\Microsoft Office\Office12\ONENOTEM.EXE

--------------------------------------------------

Checking Windows NT UserInit:

[HKLM\Software\Microsoft\Windows NT\CurrentVersion\Winlogon]
UserInit = C:\Windows\system32\userinit.exe,

--------------------------------------------------

Autorun entries from Registry:
HKLM\Software\Microsoft\Windows\CurrentVersion\Run

Windows Defender = "C:\Program Files\Windows Defender\MSASCui.exe" -hide
NMSSupport = "C:\Program Files\Common Files\Intel\IntelDH\NMS\Support\IntelHCTAgent.exe" /startup
CCUTRAYICON = "C:\Program Files\Intel\IntelDH\CCU\CCU_TrayIcon.exe"
IAAnotif = "C:\Program Files\Intel\Intel Matrix Storage Manager\Iaanotif.exe"
Spare Backup = "C:\Program Files\Spare Backup\SpareBackup.exe" /silent
BigFix = "c:\program files\Bigfix\bigfix.exe" /atstartup
lxbmmon.exe = "C:\Program Files\Lexmark 4200 Series\lxbmmon.exe"
Lexmark 4200 Series Fax Server = "C:\Program Files\Lexmark 4200 Series\fm3032.exe" /s
Ulead Photo Express Calendar Checker = "C:\Program Files\Ulead Systems\Ulead Photo Express My Scrapbook 2.0\calcheck.exe"
QuickTime Task = "C:\Program Files\QuickTime\QTTask.exe" -atboottime
WPCUMI = C:\Windows\system32\WpcUmi.exe
AppleSyncNotifier = C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleSyncNotifier.exe
iTunesHelper = "C:\Program Files\iTunes\iTunesHelper.exe"
avgnt = "C:\Program Files\Avira\AntiVir PersonalEdition Classic\avgnt.exe" /min
Adobe Reader Speed Launcher = "C:\Program Files\Adobe\Reader 9.0\Reader\Reader_sl.exe"
SigmatelSysTrayApp = sttray.exe
NvSvc = RUNDLL32.EXE C:\Windows\system32\nvsvc.dll,nvsvcStart
NvCplDaemon = RUNDLL32.EXE C:\Windows\system32\NvCpl.dll,NvStartup
NvMediaCenter = RUNDLL32.EXE C:\Windows\system32\NvMcTray.dll,NvTaskbarInit

--------------------------------------------------

Autorun entries from Registry:
HKCU\Software\Microsoft\Windows\CurrentVersion\Run

ehTray.exe = C:\Windows\ehome\ehTray.exe
SpybotSD TeaTimer = C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
WMPNSCFG = C:\Program Files\Windows Media Player\WMPNSCFG.exe

--------------------------------------------------

Autorun entries in Registry subkeys of:
HKLM\Software\Microsoft\Windows\CurrentVersion\Run

[OptionalComponents]
=

--------------------------------------------------

Shell & screensaver key from C:\Windows\SYSTEM.INI:

Shell=*INI section not found*
SCRNSAVE.EXE=*INI section not found*
drivers=*INI section not found*

Shell & screensaver key from Registry:

Shell=explorer.exe
SCRNSAVE.EXE=*Registry value not found*
drivers=*Registry value not found*

Policies Shell key:

HKCU\..\Policies: Shell=*Registry value not found*
HKLM\..\Policies: Shell=*Registry value not found*

--------------------------------------------------


Enumerating Browser Helper Objects:

(no name) - C:\Program Files\Yahoo!\Companion\Installs\cpn0\yt.dll - {02478D38-C3F9-4efb-9B51-7695ECA05670}
AcroIEHelperStub - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll - {18DF081C-E8AD-4283-A596-FA578C2EBDC3}
(no name) - C:\PROGRA~1\SPYBOT~1\SDHelper.dll - {53707962-6F74-2D53-2644-206D7942484F}
(no name) - C:\Program Files\Java\jre1.6.0_01\bin\ssv.dll - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43}
(no name) - c:\program files\google\googletoolbar1.dll - {AA58ED58-01DD-4d91-8333-CF10577473F7}
(no name) - C:\Program Files\Google\GoogleToolbarNotifier\5.0.926.3450\swg.dll - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D}

--------------------------------------------------

Enumerating Task Scheduler jobs:

GoogleUpdateTaskMachine.job
User_Feed_Synchronization-{7B6BEF21-AC1D-4E7A-B26C-55D5BB6B01CF}.job
User_Feed_Synchronization-{7C100F25-44AA-4C99-B678-BCE81F4310D7}.job

--------------------------------------------------

Enumerating Download Program Files:

[Microsoft Data Collection Control]
InProcServer32 = C:\Windows\Downloaded Program Files\MSDcode.dll
CODEBASE = https://support.microsoft.com/OAS/ActiveX/MSDcode.cab

[Windows Live OneCare safety scanner control]
InProcServer32 = %ProgramFiles%\Windows Live Safety Center\wlscCtrl2.dll
CODEBASE = http://cdn.scan.onecare.live.com/resource/...s/wlscctrl2.cab

--------------------------------------------------

Enumerating Winsock LSP files:

NameSpace #1: C:\Windows\system32\NLAapi.dll
NameSpace #2: C:\Windows\system32\napinsp.dll
NameSpace #3: C:\Windows\system32\pnrpnsp.dll
NameSpace #4: C:\Windows\system32\pnrpnsp.dll
NameSpace #5: C:\Program Files\Bonjour\mdnsNSP.dll
Protocol #1: C:\Windows\system32\wpclsp.dll
Protocol #2: C:\Windows\system32\wpclsp.dll
Protocol #3: C:\Windows\system32\wpclsp.dll
Protocol #4: C:\Windows\system32\wpclsp.dll
Protocol #5: C:\Windows\system32\wpclsp.dll
Protocol #6: C:\Windows\system32\wpclsp.dll
Protocol #7: C:\Windows\system32\wpclsp.dll
Protocol #8: C:\Windows\system32\wpclsp.dll
Protocol #19: C:\Windows\system32\wpclsp.dll

--------------------------------------------------

Enumerating ShellServiceObjectDelayLoad items:

WebCheck: C:\Windows\system32\webcheck.dll

--------------------------------------------------
End of report, 7,700 bytes
Report generated in 0.031 seconds

Command line options:
/verbose - to add additional info on each section
/complete - to include empty sections and unsuspicious data
/full - to include several rarely-important sections
/force9x - to include Win9x-only startups even if running on WinNT
/forcent - to include WinNT-only startups even if running on Win9x
/forceall - to include all Win9x and WinNT startups, regardless of platform
/history - to list version history only

BC AdBot (Login to Remove)

 


#2 Hoov

Hoov

  • Malware Response Team
  • 3,519 posts
  • OFFLINE
  •  
  • Location:Mikado Michigan
  • Local time:01:10 PM

Posted 12 March 2009 - 09:01 PM

Howdy, my name is Hoov, and I will be helping you with your dilemma. Appologies for taking so long in getting to you and your problem.

Please make sure you watch this thread for responses. If you click the options tab at the top of your first post, you can select to track this thread.

Here is what I am asking you to do during the repair of your computer

*Tell me everything that you have done, if anything, to try and fix this problem.

*Please only use 1 forum to help clear up your problem. Posting on more than 1 and following instructions from more than 1 forum will cause those helping you to pull out thier hair.

*Follow my instructions - If you can't for some reason, or if you don't understand something, please tell me. If you deviate from my instructions, tell me, it may make a difference on where we go. Don't install anything, even other programs that have nothing to do with security or malware, it could cause things to change, and I would never know it.

*Have faith. I will do all I can to get your computer working, and if I can't - someone else here will know something else to try.

*Stick with me to the end. My aim is to fix your problems, and give you the tools and knowledge to keep this from happening again.

Now onto trying to fix your computer.

If I am helping you and you don't hear from me for 24Hrs, send me a PM Please!

Do you have another computer or access to another computer that you can download programs to and burn them to a CD?

Please perform a BitDefender Online Virus and Malware Scan here:
http://www.bitdefender.com/scan8/ie.html
* Click on I Agree.
* An ActiveX warning box will appear, click on Install.
* Under Select What You Want To Check For Viruses.
* Please Check My Computer and Click Ok
* Now Click On Click Here To Scan
* Next, Click on Click here to export the scan report
* Save it to your Desktop.
* In your next reply, please include the BitDefender log
Visiting From SpywareHammer.com and DonHoover.net

Tilting at windmills hurts you more than the windmills.
-From the Notebooks of Lazarus Long
Senior of the Howard Families

Posted Image

#3 1bsymum

1bsymum
  • Topic Starter

  • Members
  • 115 posts
  • OFFLINE
  •  
  • Local time:10:10 AM

Posted 15 March 2009 - 02:37 PM

Hey, I was finally able to download Bitdefender. I had to get rid of my router, which seemed to be causing the downloading to cease. However; I have had no luck with the reports, the test results are good? I think Bitdefender is not running right, I cannot get anything to run as Administrator? I've been in and out of Control Panel, I have a window ask for permission but, it does not ask for my password (which it should do)? What else should I do? Thanks

#4 Hoov

Hoov

  • Malware Response Team
  • 3,519 posts
  • OFFLINE
  •  
  • Location:Mikado Michigan
  • Local time:01:10 PM

Posted 16 March 2009 - 04:01 PM

I am sorry to have left you hanging this weekend. I am having a cat5e cable problem. I have a real ugly fix right now so I can do some catch up and let people know I didn't abandon them intentionally. I won't be able to post again until March 17 at about 5PM East Coast USA time (UCT -4).

Sorry for any inconvenience.

Please download Malwarebytes Anti-Malware and save it to your desktop.
alternate download link 1
alternate download link 2
  • Make sure you are connected to the Internet.
  • Double-click on mbam-setup.exe to install the application.
  • When the installation begins, follow the prompts and do not make any changes to default settings.
  • When installation has finished, make sure you leave both of these checked:
    • Update Malwarebytes' Anti-Malware
    • Launch Malwarebytes' Anti-Malware
  • Then click Finish.
MBAM will automatically start and you will be asked to update the program before performing a scan.
  • If an update is found, the program will automatically update itself.
  • Press the OK button to close that box and continue.
  • If you encounter any problems while downloading the updates, manually download them from here and just double-click on mbam-rules.exe to install. Alternatively, you can update through MBAM's interface from a clean computer, copy the definitions (rules.ref) located in C:\Documents and Settings\All Users\Application Data\Malwarebytes\Malwarebytes' Anti-Malware from that system to a usb stick or CD and then copy it to the infected machine.
On the Scanner tab:
  • Make sure the "Perform Quick Scan" option is selected.
  • Then click on the Scan button.
  • If asked to select the drives to scan, leave all the drives selected and click on the Start Scan button.
  • The scan will begin and "Scan in progress" will show at the top. It may take some time to complete so please be patient.
  • When the scan is finished, a message box will say "The scan completed successfully. Click 'Show Results' to display all objects found".
  • Click OK to close the message box and continue with the removal process.
Back at the main Scanner screen:
  • Click on the Show Results button to see a list of any malware that was found.
  • Make sure that everything is checked, and click Remove Selected.
  • When removal is completed, a log report will open in Notepad.
  • The log is automatically saved and can be viewed by clicking the Logs tab in MBAM.
  • Copy and paste the contents of that report in your next reply and exit MBAM.
Note: If MBAM encounters a file that is difficult to remove, you may be asked to reboot your computer so it can proceed with the disinfection process. Regardless if prompted to restart the computer or not, please do so immediately. Failure to reboot normally (not into safe mode) will prevent MBAM from removing all the malware. MBAM may "make changes to your registry" as part of its disinfection routine. If using other security programs that detect registry changes (ie Spybot's Teatimer), they may interfere or alert you after scanning with MBAM. Please temporarily disable such programs or permit them to allow the changes.
Visiting From SpywareHammer.com and DonHoover.net

Tilting at windmills hurts you more than the windmills.
-From the Notebooks of Lazarus Long
Senior of the Howard Families

Posted Image

#5 1bsymum

1bsymum
  • Topic Starter

  • Members
  • 115 posts
  • OFFLINE
  •  
  • Local time:10:10 AM

Posted 19 March 2009 - 03:05 AM

Sorry to have not replied sooner myself, between kids springbreak and this pc, things are crazy! I cannot get Bitdefender to work either, I know my pc has something? I have been recently hit with something called TR/joke.vixenish, and even more recent something called 360? I'm worried one of my kids may have installed this on their user account but, not sure? I cannot run anything with Administrator rights, it will not ask for a password???? I decided tonight to try to run in safe mode with networking, upon hitting my start button, nothing happens? I hit it again, and had a Start up Repair window pop up, it scanned to try to repair, it asked to restart at an earlier starting point, to worried to do that? The results were to be sent back to MS, I copied them for you to look at, don't know if they mean anything? However; my other problem is in another window for System Recovery Options, my password would not work!! It said my account has been disabled??? What is going on with this thing?? Any ideas?

Problem Event Name: StartupRepairV2
Problem Signature 01: Autofailover
02: 6.0.6000.16386.6.0.6001.18000
03: 3
04: 65537
05: unknown
06: No Root Cause
07: 0
08: 2
09: WrpRepair
10: 2
OS Version : 6.0.6000.2.0.0.256.1
Locale ID : 10333

#6 1bsymum

1bsymum
  • Topic Starter

  • Members
  • 115 posts
  • OFFLINE
  •  
  • Local time:10:10 AM

Posted 19 March 2009 - 03:07 AM

Sorry post says Bitdefender and I meant Malware bytes.

#7 Hoov

Hoov

  • Malware Response Team
  • 3,519 posts
  • OFFLINE
  •  
  • Location:Mikado Michigan
  • Local time:01:10 PM

Posted 19 March 2009 - 08:03 AM

do you have your windows Vista installation disk?
Visiting From SpywareHammer.com and DonHoover.net

Tilting at windmills hurts you more than the windmills.
-From the Notebooks of Lazarus Long
Senior of the Howard Families

Posted Image

#8 1bsymum

1bsymum
  • Topic Starter

  • Members
  • 115 posts
  • OFFLINE
  •  
  • Local time:10:10 AM

Posted 19 March 2009 - 03:09 PM

I have The Gateway operating system disc, another disc called eztune (don't know what this is), and I think I previously made back up cds of my drives and applications. Do you think I need to wipe everything out the way it was when it was shipped from the factory or does it completely need wiped out? Which ever one, just to let you know, I don't know where to start with either of these things? So, if this is the case, please walk me through it!

#9 Hoov

Hoov

  • Malware Response Team
  • 3,519 posts
  • OFFLINE
  •  
  • Location:Mikado Michigan
  • Local time:01:10 PM

Posted 19 March 2009 - 04:44 PM

Not yet, I was hoping that we could do a repair. Here are the instructions I need you to follow. Let me know what happens.
Visiting From SpywareHammer.com and DonHoover.net

Tilting at windmills hurts you more than the windmills.
-From the Notebooks of Lazarus Long
Senior of the Howard Families

Posted Image

#10 1bsymum

1bsymum
  • Topic Starter

  • Members
  • 115 posts
  • OFFLINE
  •  
  • Local time:10:10 AM

Posted 24 March 2009 - 09:24 PM

O.k., sorry I'm a day late. I went through the instructions and ran the disc. No errors found? Now what?

#11 Hoov

Hoov

  • Malware Response Team
  • 3,519 posts
  • OFFLINE
  •  
  • Location:Mikado Michigan
  • Local time:01:10 PM

Posted 24 March 2009 - 11:06 PM

Reboot to safe mode and see if Malwarebytes' Anti-Malware will run. If it still will not run, Run comboFix.exe. Please visit this webpage for download links, and instructions for running the tool:

http://www.bleepingcomputer.com/combofix/how-to-use-combofix

* Ensure you have disabled all anti virus and anti malware programs so they do not interfere with the running of ComboFix. Also make sure you close all your browsers just before the instructions tell you to start the scanner.

Please include the C:\ComboFix.txt in your next reply for further review.

Note:
Do not mouseclick combofix's window while it's running. That may cause it to stall

If that won't run, rename combofix.exe to multifix.exe and reboot to safe mode and run it.
Visiting From SpywareHammer.com and DonHoover.net

Tilting at windmills hurts you more than the windmills.
-From the Notebooks of Lazarus Long
Senior of the Howard Families

Posted Image

#12 1bsymum

1bsymum
  • Topic Starter

  • Members
  • 115 posts
  • OFFLINE
  •  
  • Local time:10:10 AM

Posted 27 March 2009 - 12:24 AM

O.k. so I still can't run my pc in safemode? When it gets shut off, it still doesn't ask the four options to start in safe mode with networking, normally, etc. it just automatically starts? I had to hit the F8 key and than start it in safe mode, however; malware bytes would not start as administrator. I downloaded Combo fix, I went through the instructions and SHUT OFF, spybot, Anti Vir, windows defender and firewall. It came up that Avira was still on, I think something is screwy with my window security screen, it shows the same program listed twice? After Combo fix was done, I also had Spybot come on ask me to allow changes, I assumed this was due to combo fix so I allowed them? If I screwed this up, please let me know? Here are my logs. Much Thanks!!!

ComboFix 09-03-26.03 - marquelle 2009-03-26 21:57:45.3 - NTFSx86
Microsoft® Windows Vista™ Home Premium 6.0.6001.1.1252.1.1033.18.3053.2082 [GMT -7:00]
Running from: c:\users\marquelle\Desktop\ComboFix.exe
AV: Avira AntiVir PersonalEdition *On-access scanning enabled* (Updated)
* Created a new restore point
.

((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.

c:\windows\system32\dumphive.exe
c:\windows\system32\IEDFix.exe
c:\windows\system32\SrchSTS.exe
c:\windows\system32\tmp.reg
c:\windows\system32\VACFix.exe
c:\windows\system32\VCCLSID.exe
c:\windows\system32\WS2Fix.exe

.
((((((((((((((((((((((((( Files Created from 2009-02-27 to 2009-03-27 )))))))))))))))))))))))))))))))
.

2009-03-11 12:01 . 2009-02-08 20:10 2,033,152 --a------ c:\windows\System32\win32k.sys
2009-03-11 12:01 . 2008-11-26 21:43 268,288 --a------ c:\windows\System32\schannel.dll
2009-03-05 14:05 . 2009-03-05 14:05 <DIR> d-------- c:\users\marquelle\AppData\Roaming\Malwarebytes
2009-03-05 14:05 . 2009-03-05 14:05 <DIR> d-------- c:\users\All Users\Malwarebytes
2009-03-05 14:05 . 2009-03-05 14:05 <DIR> d-------- c:\programdata\Malwarebytes
2009-03-05 14:05 . 2009-03-05 14:05 <DIR> d-------- c:\program files\Malwarebytes' Anti-Malware
2009-03-05 14:05 . 2009-02-11 10:19 38,496 --a------ c:\windows\System32\drivers\mbamswissarmy.sys
2009-03-05 14:05 . 2009-02-11 10:19 15,504 --a------ c:\windows\System32\drivers\mbam.sys

.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2009-03-27 02:36 --------- d-----w c:\users\marquelle\AppData\Roaming\Spare Backup
2009-03-26 06:28 --------- d-----w c:\programdata\Google Updater
2009-03-24 20:53 --------- d-----w c:\users\kids\AppData\Roaming\Spare Backup
2009-03-22 20:52 --------- d-----w c:\users\kids\AppData\Roaming\LimeWire
2009-03-20 04:25 6,376 ----a-w c:\users\marquelle\AppData\Roaming\wklnhst.dat
2009-03-19 08:09 --------- d-----w c:\program files\Windows Live Safety Center
2009-03-14 03:28 --------- d-----w c:\users\marquelle\AppData\Roaming\LimeWire
2009-03-12 10:06 --------- d-----w c:\program files\Windows Mail
2009-02-28 17:24 --------- d-----w c:\program files\Microsoft Silverlight
2009-02-25 00:55 --------- d-----w c:\program files\LSI SoftModem
2009-02-21 00:00 --------- d-----w c:\programdata\WindowsSearch
2009-02-20 21:43 --------- d-----w c:\users\marquelle\AppData\Roaming\Apple Computer
2009-02-20 21:41 --------- d-----w c:\users\marquelle\AppData\Roaming\PeerNetworking
2009-02-20 21:06 206 ----a-w c:\users\kids\AppData\Roaming\wklnhst.dat
2009-02-11 04:17 --------- d-----w c:\program files\Google
2009-02-06 23:45 --------- d-----w c:\program files\Coupons
2009-01-15 06:11 827,392 ----a-w c:\windows\System32\wininet.dll
2008-10-14 00:59 174 --sha-w c:\program files\desktop.ini
2008-02-19 02:54 32 ----a-r c:\users\All Users\hash.dat
2008-02-19 02:54 32 ----a-r c:\programdata\hash.dat
2008-01-26 03:23 1,076,640 ----a-w c:\users\marquelle\WoW-2.0.0-enUS-Installer-downloader.exe
2008-01-14 21:32 262,144 ----a-w c:\programdata\ntuser.dat
2008-07-25 00:38 16,384 --sha-w c:\windows\ServiceProfiles\NetworkService\AppData\Local\Microsoft\Windows\History\History.IE5\index.dat
2008-07-29 21:47 32,768 --sha-w c:\windows\ServiceProfiles\NetworkService\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\index.dat
2008-07-29 21:47 16,384 --sha-w c:\windows\ServiceProfiles\NetworkService\AppData\Local\Temp\Cookies\index.dat
2008-07-29 21:47 16,384 --sha-w c:\windows\ServiceProfiles\NetworkService\AppData\Local\Temp\History\History.IE5\index.dat
2008-07-29 21:47 32,768 --sha-w c:\windows\ServiceProfiles\NetworkService\AppData\Local\Temp\Temporary Internet Files\Content.IE5\index.dat
2008-07-25 00:38 16,384 --sha-w c:\windows\ServiceProfiles\NetworkService\AppData\Roaming\Microsoft\Windows\Cookies\index.dat
.

((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ehTray.exe"="c:\windows\ehome\ehTray.exe" [2008-01-19 125952]
"WMPNSCFG"="c:\program files\Windows Media Player\WMPNSCFG.exe" [2008-01-19 202240]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"NMSSupport"="c:\program files\Common Files\Intel\IntelDH\NMS\Support\IntelHCTAgent.exe" [2007-04-06 439768]
"CCUTRAYICON"="c:\program files\Intel\IntelDH\CCU\CCU_TrayIcon.exe" [2007-04-06 215512]
"IAAnotif"="c:\program files\Intel\Intel Matrix Storage Manager\Iaanotif.exe" [2007-03-21 174872]
"Spare Backup"="c:\program files\Spare Backup\SpareBackup.exe" [2007-07-12 5252936]
"BigFix"="c:\program files\Bigfix\bigfix.exe" [2006-11-16 2348584]
"lxbmmon.exe"="c:\program files\Lexmark 4200 Series\lxbmmon.exe" [2007-01-30 230320]
"Lexmark 4200 Series Fax Server"="c:\program files\Lexmark 4200 Series\fm3032.exe" [2007-01-30 160688]
"QuickTime Task"="c:\program files\QuickTime\QTTask.exe" [2008-05-27 413696]
"WPCUMI"="c:\windows\system32\WpcUmi.exe" [2006-11-02 176128]
"AppleSyncNotifier"="c:\program files\Common Files\Apple\Mobile Device Support\bin\AppleSyncNotifier.exe" [2008-07-10 116040]
"iTunesHelper"="c:\program files\iTunes\iTunesHelper.exe" [2008-07-10 289064]
"avgnt"="c:\program files\Avira\AntiVir PersonalEdition Classic\avgnt.exe" [2008-06-12 266497]
"Adobe Reader Speed Launcher"="c:\program files\Adobe\Reader 9.0\Reader\Reader_sl.exe" [2008-06-12 34672]
"NvSvc"="c:\windows\system32\nvsvc.dll" [2007-12-05 86016]
"NvCplDaemon"="c:\windows\system32\NvCpl.dll" [2007-12-05 8530464]
"NvMediaCenter"="c:\windows\system32\NvMcTray.dll" [2007-12-05 81920]
"SigmatelSysTrayApp"="sttray.exe" [2007-02-28 c:\windows\sttray.exe]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\RunOnce]
"Launcher"="c:\windows\SMINST\launcher.exe" [2007-07-03 40072]

c:\users\kids\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\
LimeWire On Startup.lnk - c:\program files\LimeWire\LimeWire.exe [2008-02-08 147456]
OneNote 2007 Screen Clipper and Launcher.lnk - c:\program files\Microsoft Office\Office12\ONENOTEM.EXE [2007-12-07 101440]

c:\users\marquelle\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\
OneNote 2007 Screen Clipper and Launcher.lnk - c:\program files\Microsoft Office\Office12\ONENOTEM.EXE [2007-12-07 101440]

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"EnableUIADesktopToggle"= 0 (0x0)

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\drivers32]
"msacm.clmp3enc"= c:\progra~1\CYBERL~1\Power2Go\CLMP3Enc.ACM

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SpybotSD TeaTimer]
-rahs---- 2008-09-16 12:16 1833296 c:\program files\Spybot - Search & Destroy\TeaTimer.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Ulead Photo Express Calendar Checker]
--a------ 2003-09-19 20:23 69632 c:\program files\Ulead Systems\Ulead Photo Express My Scrapbook 2.0\CalCheck.exe

[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\McAfeeAntiSpyware]
"DisableMonitoring"=dword:00000001

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\DomainProfile]
"DefaultOutboundAction"= 0 (0x0)
"DefaultInboundAction"= 1 (0x1)

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\StandardProfile]
"EnableFirewall"= 0 (0x0)

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\StandardProfile\AuthorizedApplications\List]
"c:\\Program Files\\Yahoo!\\Yahoo! Music Jukebox\\YahooMusicEngine.exe"= c:\program files\Yahoo!\Yahoo! Music Jukebox\YahooMusicEngine.exe:*:Enabled:Yahoo! Music Jukebox

R2 DQLWinService;DQLWinService;c:\program files\Common Files\Intel\IntelDH\NMS\AdpPlugins\DQLWinService.exe [2007-02-12 208896]
R2 lxbm_device;lxbm_device;c:\windows\system32\lxbmcoms.exe -service --> c:\windows\system32\lxbmcoms.exe -service [?]
R2 NMSCore;Intel® NMSCore;c:\program files\Common Files\Intel\IntelDH\NMS\NMSCore\NMSCore.exe [2007-04-06 313816]
R2 nmsunidr;UniDriver for NMS;c:\windows\System32\drivers\nmsunidr.sys [2007-02-18 5376]
R2 QualityManager;Intel® Quality Manager;c:\program files\Intel\IntelDH\Intel Media Server\Media Server\bin\QualityManager.exe [2007-04-06 272856]
R3 IntelDH;IntelDH Driver;c:\windows\System32\drivers\IntelDH.sys [2006-08-25 5504]
S2 gupdate1c9662e9aaf4c23;Google Update Service (gupdate1c9662e9aaf4c23);c:\program files\Google\Update\GoogleUpdate.exe [2008-12-24 133104]
S3 DHTRACE;Intel® DHTrace Controller;c:\program files\Common Files\Intel\IntelDH\bin\DHTraceController.exe [2007-04-06 39896]
S3 NETw2v32;Intel® PRO/Wireless 2200BG Network Connection Driver for Windows Vista;c:\windows\System32\drivers\NETw2v32.sys [2006-11-02 2589184]
.
Contents of the 'Scheduled Tasks' folder

2009-03-27 c:\windows\Tasks\Google Software Updater.job
- c:\program files\Google\Common\Google Updater\GoogleUpdaterService.exe [2009-03-23 20:25]

2009-03-27 c:\windows\Tasks\GoogleUpdateTaskMachine.job
- c:\program files\Google\Update\GoogleUpdate.exe [2009-02-10 21:17]

2009-03-27 c:\windows\Tasks\User_Feed_Synchronization-{7B6BEF21-AC1D-4E7A-B26C-55D5BB6B01CF}.job
- c:\windows\system32\msfeedssync.exe [2008-01-19 00:33]

2009-03-27 c:\windows\Tasks\User_Feed_Synchronization-{7C100F25-44AA-4C99-B678-BCE81F4310D7}.job
- c:\windows\system32\msfeedssync.exe [2008-01-19 00:33]
.
.
------- Supplementary Scan -------
.
uStart Page = hxxp://www.yahoo.com/
mStart Page = hxxp://www.yahoo.com
LSP: c:\windows\system32\wpclsp.dll
.

**************************************************************************

catchme 0.3.1367 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2009-03-26 22:00:13
Windows 6.0.6001 Service Pack 1 NTFS

scanning hidden processes ...

scanning hidden autostart entries ...

scanning hidden files ...

scan completed successfully
hidden files: 0

**************************************************************************
.
Completion time: 2009-03-26 22:01:50
ComboFix-quarantined-files.txt 2009-03-27 05:01:49
ComboFix2.txt 2008-02-17 20:22:39
ComboFix3.txt 2008-02-17 04:58:46

Pre-Run: 354,105,925,632 bytes free
Post-Run: 354,130,976,768 bytes free

152 --- E O F --- 2009-03-26 14:15:56

#13 1bsymum

1bsymum
  • Topic Starter

  • Members
  • 115 posts
  • OFFLINE
  •  
  • Local time:10:10 AM

Posted 27 March 2009 - 12:27 AM

One more thing, I noticed in users account, there something listed as IUSR_NMPR, do you know what this is?

#14 Hoov

Hoov

  • Malware Response Team
  • 3,519 posts
  • OFFLINE
  •  
  • Location:Mikado Michigan
  • Local time:01:10 PM

Posted 27 March 2009 - 01:31 AM

Its created by the computer manufacturer when they installed the OS.

Please download and scan with SUPERAntiSpyware Free for Home Users
  • Double-click SUPERAntiSpyware.exe and use the default settings for installation.
  • An icon will be created on your desktop. Double-click that icon to launch the program.
  • If asked to update the program definitions, click "Yes". If not, update the definitions before scanning by selecting "Check for Updates". (If you encounter any problems while downloading the updates, manually download them from here. Double-click on the hyperlink for Download Installer and save SASDEFINITIONS.EXE to your desktop. Then double-click on SASDEFINITIONS.EXE to install the definitions.)
  • Under "Configuration and Preferences", click the Preferences button.
  • Click the Scanning Control tab.
  • Under Scanner Options make sure the following are checked (leave all others unchecked):
    • Close browsers before scanning.
    • Scan for tracking cookies.
    • Terminate memory threats before quarantining.
  • Click the "Close" button to leave the control center screen.
  • Back on the main screen, under "Scan for Harmful Software" click Scan your computer.
  • On the left, make sure you check C:\Fixed Drive.
  • On the right, under "Complete Scan", choose Perform Complete Scan.
  • Click "Next" to start the scan. Please be patient while it scans your computer.
  • After the scan is complete, a Scan Summary box will appear with potentially harmful items that were detected. Click "OK".
  • Make sure everything has a checkmark next to it and click "Next".
  • A notification will appear that "Quarantine and Removal is Complete". Click "OK" and then click the "Finish" button to return to the main menu.
  • If asked if you want to reboot, click "Yes".
  • To retrieve the removal information after reboot, launch SUPERAntispyware again.
    • Click Preferences, then click the Statistics/Logs tab.
    • Under Scanner Logs, double-click SUPERAntiSpyware Scan Log.
    • If there are several logs, click the current dated log and press View log. A text file will open in your default text editor.
    • Please copy and paste the Scan Log results in your next reply.
  • Click Close to exit the program.

Visiting From SpywareHammer.com and DonHoover.net

Tilting at windmills hurts you more than the windmills.
-From the Notebooks of Lazarus Long
Senior of the Howard Families

Posted Image

#15 1bsymum

1bsymum
  • Topic Starter

  • Members
  • 115 posts
  • OFFLINE
  •  
  • Local time:10:10 AM

Posted 28 March 2009 - 11:16 PM

Sorry I didn't get back till now, I was trying to get this posted last night, but six hours of waiting, 1am and I had to sleep. Just got back into town tonight so here it is, I see now why it took so long. I ran Superantispyware on normal mode, left other programs on, and not with adminstrator rights, again let me know if I need to redo. Also, I only selected C drive per the instructions, should D drive also be scanned? Thanks :thumbup2:

SUPERAntiSpyware Scan Log
http://www.superantispyware.com

Generated 03/28/2009 at 05:39 PM

Application Version : 4.26.1000

Core Rules Database Version : 3819
Trace Rules Database Version: 1773

Scan type : Complete Scan
Total Scan Time : 22:16:46

Memory items scanned : 742
Memory threats detected : 0
Registry items scanned : 6959
Registry threats detected : 0
File items scanned : 1579845
File threats detected : 980

Adware.Tracking Cookie
C:\Documents and Settings\kids\AppData\Roaming\Microsoft\Windows\Cookies\Low\kids@247realmedia[1].txt
C:\Documents and Settings\kids\AppData\Roaming\Microsoft\Windows\Cookies\Low\kids@2o7[1].txt
C:\Documents and Settings\kids\AppData\Roaming\Microsoft\Windows\Cookies\Low\kids@a1.interclick[2].txt
C:\Documents and Settings\kids\AppData\Roaming\Microsoft\Windows\Cookies\Low\kids@adbrite[1].txt
C:\Documents and Settings\kids\AppData\Roaming\Microsoft\Windows\Cookies\Low\kids@adinterax[2].txt
C:\Documents and Settings\kids\AppData\Roaming\Microsoft\Windows\Cookies\Low\kids@adlegend[2].txt
C:\Documents and Settings\kids\AppData\Roaming\Microsoft\Windows\Cookies\Low\kids@adrevolver[2].txt
C:\Documents and Settings\kids\AppData\Roaming\Microsoft\Windows\Cookies\Low\kids@ads.associatedcontent[2].txt
C:\Documents and Settings\kids\AppData\Roaming\Microsoft\Windows\Cookies\Low\kids@ads.bridgetrack[1].txt
C:\Documents and Settings\kids\AppData\Roaming\Microsoft\Windows\Cookies\Low\kids@ads.cartoonnetwork[2].txt
C:\Documents and Settings\kids\AppData\Roaming\Microsoft\Windows\Cookies\Low\kids@ads.cheatingdome[1].txt
C:\Documents and Settings\kids\AppData\Roaming\Microsoft\Windows\Cookies\Low\kids@ads.createreach[1].txt
C:\Documents and Settings\kids\AppData\Roaming\Microsoft\Windows\Cookies\Low\kids@ads.gamesbannernet[1].txt
C:\Documents and Settings\kids\AppData\Roaming\Microsoft\Windows\Cookies\Low\kids@ads.pointroll[2].txt
C:\Documents and Settings\kids\AppData\Roaming\Microsoft\Windows\Cookies\Low\kids@ads.pokegym[1].txt
C:\Documents and Settings\kids\AppData\Roaming\Microsoft\Windows\Cookies\Low\kids@adserver.adtechus[1].txt
C:\Documents and Settings\kids\AppData\Roaming\Microsoft\Windows\Cookies\Low\kids@adserver.easyad[1].txt
C:\Documents and Settings\kids\AppData\Roaming\Microsoft\Windows\Cookies\Low\kids@adtech[1].txt
C:\Documents and Settings\kids\AppData\Roaming\Microsoft\Windows\Cookies\Low\kids@advertising[1].txt
C:\Documents and Settings\kids\AppData\Roaming\Microsoft\Windows\Cookies\Low\kids@adviva[2].txt
C:\Documents and Settings\kids\AppData\Roaming\Microsoft\Windows\Cookies\Low\kids@affiliate.kitaramedia[2].txt
C:\Documents and Settings\kids\AppData\Roaming\Microsoft\Windows\Cookies\Low\kids@apmebf[2].txt
C:\Documents and Settings\kids\AppData\Roaming\Microsoft\Windows\Cookies\Low\kids@at.atwola[1].txt
C:\Documents and Settings\kids\AppData\Roaming\Microsoft\Windows\Cookies\Low\kids@atdmt[2].txt
C:\Documents and Settings\kids\AppData\Roaming\Microsoft\Windows\Cookies\Low\kids@atwola[2].txt
C:\Documents and Settings\kids\AppData\Roaming\Microsoft\Windows\Cookies\Low\kids@azjmp[1].txt
C:\Documents and Settings\kids\AppData\Roaming\Microsoft\Windows\Cookies\Low\kids@banners.battleon[1].txt
C:\Documents and Settings\kids\AppData\Roaming\Microsoft\Windows\Cookies\Low\kids@banners2.battleon[1].txt
C:\Documents and Settings\kids\AppData\Roaming\Microsoft\Windows\Cookies\Low\kids@bs.serving-sys[1].txt
C:\Documents and Settings\kids\AppData\Roaming\Microsoft\Windows\Cookies\Low\kids@burstnet[2].txt
C:\Documents and Settings\kids\AppData\Roaming\Microsoft\Windows\Cookies\Low\kids@c7.zedo[2].txt
C:\Documents and Settings\kids\AppData\Roaming\Microsoft\Windows\Cookies\Low\kids@cgm.adbureau[1].txt
C:\Documents and Settings\kids\AppData\Roaming\Microsoft\Windows\Cookies\Low\kids@chitika[2].txt
C:\Documents and Settings\kids\AppData\Roaming\Microsoft\Windows\Cookies\Low\kids@collective-media[1].txt
C:\Documents and Settings\kids\AppData\Roaming\Microsoft\Windows\Cookies\Low\kids@desertschools.112.2o7[1].txt
C:\Documents and Settings\kids\AppData\Roaming\Microsoft\Windows\Cookies\Low\kids@directtrack[1].txt
C:\Documents and Settings\kids\AppData\Roaming\Microsoft\Windows\Cookies\Low\kids@doubleclick[1].txt
C:\Documents and Settings\kids\AppData\Roaming\Microsoft\Windows\Cookies\Low\kids@dynamic.media.adrevolver[2].txt
C:\Documents and Settings\kids\AppData\Roaming\Microsoft\Windows\Cookies\Low\kids@e-2dj6wdliuidzcco.stats.esomniture[2].txt
C:\Documents and Settings\kids\AppData\Roaming\Microsoft\Windows\Cookies\Low\kids@e-2dj6wfk4ejdjilo.stats.esomniture[2].txt
C:\Documents and Settings\kids\AppData\Roaming\Microsoft\Windows\Cookies\Low\kids@e-2dj6wfkyoidpoco.stats.esomniture[2].txt
C:\Documents and Settings\kids\AppData\Roaming\Microsoft\Windows\Cookies\Low\kids@e-2dj6wfloemdzoep.stats.esomniture[1].txt
C:\Documents and Settings\kids\AppData\Roaming\Microsoft\Windows\Cookies\Low\kids@e-2dj6wjkownajwgo.stats.esomniture[1].txt
C:\Documents and Settings\kids\AppData\Roaming\Microsoft\Windows\Cookies\Low\kids@e-2dj6wjlychcjifp.stats.esomniture[2].txt
C:\Documents and Settings\kids\AppData\Roaming\Microsoft\Windows\Cookies\Low\kids@e-2dj6wjnycidzwhp.stats.esomniture[1].txt
C:\Documents and Settings\kids\AppData\Roaming\Microsoft\Windows\Cookies\Low\kids@e-2dj6wjnycmdjagq.stats.esomniture[2].txt
C:\Documents and Settings\kids\AppData\Roaming\Microsoft\Windows\Cookies\Low\kids@e-2dj6wjnyomcpmfo.stats.esomniture[2].txt
C:\Documents and Settings\kids\AppData\Roaming\Microsoft\Windows\Cookies\Low\kids@e-2dj6wjnysmc5kcp.stats.esomniture[1].txt
C:\Documents and Settings\kids\AppData\Roaming\Microsoft\Windows\Cookies\Low\kids@e-2dj6wjnysoazwlq.stats.esomniture[1].txt
C:\Documents and Settings\kids\AppData\Roaming\Microsoft\Windows\Cookies\Low\kids@ehg-corusentertainment.hitbox[1].txt
C:\Documents and Settings\kids\AppData\Roaming\Microsoft\Windows\Cookies\Low\kids@ehg-findlaw.hitbox[2].txt
C:\Documents and Settings\kids\AppData\Roaming\Microsoft\Windows\Cookies\Low\kids@ehg-idgentertainment.hitbox[2].txt
C:\Documents and Settings\kids\AppData\Roaming\Microsoft\Windows\Cookies\Low\kids@fastclick[1].txt
C:\Documents and Settings\kids\AppData\Roaming\Microsoft\Windows\Cookies\Low\kids@gjacket.adbureau[2].txt
C:\Documents and Settings\kids\AppData\Roaming\Microsoft\Windows\Cookies\Low\kids@hitbox[1].txt
C:\Documents and Settings\kids\AppData\Roaming\Microsoft\Windows\Cookies\Low\kids@insightexpressai[1].txt
C:\Documents and Settings\kids\AppData\Roaming\Microsoft\Windows\Cookies\Low\kids@interclick[2].txt
C:\Documents and Settings\kids\AppData\Roaming\Microsoft\Windows\Cookies\Low\kids@ipcmedia.122.2o7[1].txt
C:\Documents and Settings\kids\AppData\Roaming\Microsoft\Windows\Cookies\Low\kids@kontera[1].txt
C:\Documents and Settings\kids\AppData\Roaming\Microsoft\Windows\Cookies\Low\kids@landing.hitfarm[1].txt
C:\Documents and Settings\kids\AppData\Roaming\Microsoft\Windows\Cookies\Low\kids@login.tracking101[1].txt
C:\Documents and Settings\kids\AppData\Roaming\Microsoft\Windows\Cookies\Low\kids@mach.adbureau[1].txt
C:\Documents and Settings\kids\AppData\Roaming\Microsoft\Windows\Cookies\Low\kids@maxis.112.2o7[1].txt
C:\Documents and Settings\kids\AppData\Roaming\Microsoft\Windows\Cookies\Low\kids@media.adrevolver[1].txt
C:\Documents and Settings\kids\AppData\Roaming\Microsoft\Windows\Cookies\Low\kids@media.mtvnservices[2].txt
C:\Documents and Settings\kids\AppData\Roaming\Microsoft\Windows\Cookies\Low\kids@mediaplex[2].txt
C:\Documents and Settings\kids\AppData\Roaming\Microsoft\Windows\Cookies\Low\kids@msnbc.112.2o7[1].txt
C:\Documents and Settings\kids\AppData\Roaming\Microsoft\Windows\Cookies\Low\kids@msnportal.112.2o7[1].txt
C:\Documents and Settings\kids\AppData\Roaming\Microsoft\Windows\Cookies\Low\kids@myaccount.sparebackup[1].txt
C:\Documents and Settings\kids\AppData\Roaming\Microsoft\Windows\Cookies\Low\kids@network.realmedia[2].txt
C:\Documents and Settings\kids\AppData\Roaming\Microsoft\Windows\Cookies\Low\kids@nextag[1].txt
C:\Documents and Settings\kids\AppData\Roaming\Microsoft\Windows\Cookies\Low\kids@oasn04.247realmedia[1].txt
C:\Documents and Settings\kids\AppData\Roaming\Microsoft\Windows\Cookies\Low\kids@overture[1].txt
C:\Documents and Settings\kids\AppData\Roaming\Microsoft\Windows\Cookies\Low\kids@perf.overture[1].txt
C:\Documents and Settings\kids\AppData\Roaming\Microsoft\Windows\Cookies\Low\kids@popularscreensavers[1].txt
C:\Documents and Settings\kids\AppData\Roaming\Microsoft\Windows\Cookies\Low\kids@precisionclick[1].txt
C:\Documents and Settings\kids\AppData\Roaming\Microsoft\Windows\Cookies\Low\kids@pro-market[1].txt
C:\Documents and Settings\kids\AppData\Roaming\Microsoft\Windows\Cookies\Low\kids@questionmarket[2].txt
C:\Documents and Settings\kids\AppData\Roaming\Microsoft\Windows\Cookies\Low\kids@realmedia[2].txt
C:\Documents and Settings\kids\AppData\Roaming\Microsoft\Windows\Cookies\Low\kids@redirect.antracker[1].txt
C:\Documents and Settings\kids\AppData\Roaming\Microsoft\Windows\Cookies\Low\kids@redirect.antracker[2].txt
C:\Documents and Settings\kids\AppData\Roaming\Microsoft\Windows\Cookies\Low\kids@redirect.antracker[3].txt
C:\Documents and Settings\kids\AppData\Roaming\Microsoft\Windows\Cookies\Low\kids@revsci[2].txt
C:\Documents and Settings\kids\AppData\Roaming\Microsoft\Windows\Cookies\Low\kids@richmedia.yahoo[1].txt
C:\Documents and Settings\kids\AppData\Roaming\Microsoft\Windows\Cookies\Low\kids@roiservice[1].txt
C:\Documents and Settings\kids\AppData\Roaming\Microsoft\Windows\Cookies\Low\kids@server.cpmstar[2].txt
C:\Documents and Settings\kids\AppData\Roaming\Microsoft\Windows\Cookies\Low\kids@serving-sys[2].txt
C:\Documents and Settings\kids\AppData\Roaming\Microsoft\Windows\Cookies\Low\kids@sitestat.mayoclinic[1].txt
C:\Documents and Settings\kids\AppData\Roaming\Microsoft\Windows\Cookies\Low\kids@smartadserver[1].txt
C:\Documents and Settings\kids\AppData\Roaming\Microsoft\Windows\Cookies\Low\kids@specificclick[1].txt
C:\Documents and Settings\kids\AppData\Roaming\Microsoft\Windows\Cookies\Low\kids@statcounter[2].txt
C:\Documents and Settings\kids\AppData\Roaming\Microsoft\Windows\Cookies\Low\kids@stats.virtualreview[1].txt
C:\Documents and Settings\kids\AppData\Roaming\Microsoft\Windows\Cookies\Low\kids@stats3.mbmii[1].txt
C:\Documents and Settings\kids\AppData\Roaming\Microsoft\Windows\Cookies\Low\kids@statse.webtrendslive[2].txt
C:\Documents and Settings\kids\AppData\Roaming\Microsoft\Windows\Cookies\Low\kids@tacoda[2].txt
C:\Documents and Settings\kids\AppData\Roaming\Microsoft\Windows\Cookies\Low\kids@trafficmp[2].txt
C:\Documents and Settings\kids\AppData\Roaming\Microsoft\Windows\Cookies\Low\kids@tribalfusion[1].txt
C:\Documents and Settings\kids\AppData\Roaming\Microsoft\Windows\Cookies\Low\kids@viacom.adbureau[2].txt
C:\Documents and Settings\kids\AppData\Roaming\Microsoft\Windows\Cookies\Low\kids@videoegg.adbureau[2].txt
C:\Documents and Settings\kids\AppData\Roaming\Microsoft\Windows\Cookies\Low\kids@webventures.directtrack[2].txt
C:\Documents and Settings\kids\AppData\Roaming\Microsoft\Windows\Cookies\Low\kids@www.burstbeacon[1].txt
C:\Documents and Settings\kids\AppData\Roaming\Microsoft\Windows\Cookies\Low\kids@www.burstnet[1].txt
C:\Documents and Settings\kids\AppData\Roaming\Microsoft\Windows\Cookies\Low\kids@www.clickmanage[2].txt
C:\Documents and Settings\kids\AppData\Roaming\Microsoft\Windows\Cookies\Low\kids@www.googleadservices[1].txt
C:\Documents and Settings\kids\AppData\Roaming\Microsoft\Windows\Cookies\Low\kids@www.googleadservices[2].txt
C:\Documents and Settings\kids\AppData\Roaming\Microsoft\Windows\Cookies\Low\kids@www.googleadservices[4].txt
C:\Documents and Settings\kids\AppData\Roaming\Microsoft\Windows\Cookies\Low\kids@www.googleadservices[5].txt
C:\Documents and Settings\kids\AppData\Roaming\Microsoft\Windows\Cookies\Low\kids@www.mysitetraffic[2].txt
C:\Documents and Settings\kids\AppData\Roaming\Microsoft\Windows\Cookies\Low\kids@www.pixitrack[1].txt
C:\Documents and Settings\kids\AppData\Roaming\Microsoft\Windows\Cookies\Low\kids@www.popularscreensavers[1].txt
C:\Documents and Settings\kids\AppData\Roaming\Microsoft\Windows\Cookies\Low\kids@www.socialtrack[2].txt
C:\Documents and Settings\kids\AppData\Roaming\Microsoft\Windows\Cookies\Low\kids@www.w3counter[1].txt
C:\Documents and Settings\kids\AppData\Roaming\Microsoft\Windows\Cookies\Low\kids@www3.addfreestats[1].txt
C:\Documents and Settings\kids\AppData\Roaming\Microsoft\Windows\Cookies\Low\kids@xiti[1].txt
C:\Documents and Settings\kids\AppData\Roaming\Microsoft\Windows\Cookies\Low\kids@zedo[1].txt
C:\Documents and Settings\kids\Application Data\Microsoft\Windows\Cookies\Low\kids@247realmedia[1].txt
C:\Documents and Settings\kids\Application Data\Microsoft\Windows\Cookies\Low\kids@2o7[1].txt
C:\Documents and Settings\kids\Application Data\Microsoft\Windows\Cookies\Low\kids@a1.interclick[2].txt
C:\Documents and Settings\kids\Application Data\Microsoft\Windows\Cookies\Low\kids@adbrite[1].txt
C:\Documents and Settings\kids\Application Data\Microsoft\Windows\Cookies\Low\kids@adinterax[2].txt
C:\Documents and Settings\kids\Application Data\Microsoft\Windows\Cookies\Low\kids@adlegend[2].txt
C:\Documents and Settings\kids\Application Data\Microsoft\Windows\Cookies\Low\kids@adrevolver[2].txt
C:\Documents and Settings\kids\Application Data\Microsoft\Windows\Cookies\Low\kids@ads.associatedcontent[2].txt
C:\Documents and Settings\kids\Application Data\Microsoft\Windows\Cookies\Low\kids@ads.bridgetrack[1].txt
C:\Documents and Settings\kids\Application Data\Microsoft\Windows\Cookies\Low\kids@ads.cartoonnetwork[2].txt
C:\Documents and Settings\kids\Application Data\Microsoft\Windows\Cookies\Low\kids@ads.cheatingdome[1].txt
C:\Documents and Settings\kids\Application Data\Microsoft\Windows\Cookies\Low\kids@ads.createreach[1].txt
C:\Documents and Settings\kids\Application Data\Microsoft\Windows\Cookies\Low\kids@ads.gamesbannernet[1].txt
C:\Documents and Settings\kids\Application Data\Microsoft\Windows\Cookies\Low\kids@ads.pointroll[2].txt
C:\Documents and Settings\kids\Application Data\Microsoft\Windows\Cookies\Low\kids@ads.pokegym[1].txt
C:\Documents and Settings\kids\Application Data\Microsoft\Windows\Cookies\Low\kids@adserver.adtechus[1].txt
C:\Documents and Settings\kids\Application Data\Microsoft\Windows\Cookies\Low\kids@adserver.easyad[1].txt
C:\Documents and Settings\kids\Application Data\Microsoft\Windows\Cookies\Low\kids@adtech[1].txt
C:\Documents and Settings\kids\Application Data\Microsoft\Windows\Cookies\Low\kids@advertising[1].txt
C:\Documents and Settings\kids\Application Data\Microsoft\Windows\Cookies\Low\kids@adviva[2].txt
C:\Documents and Settings\kids\Application Data\Microsoft\Windows\Cookies\Low\kids@affiliate.kitaramedia[2].txt
C:\Documents and Settings\kids\Application Data\Microsoft\Windows\Cookies\Low\kids@apmebf[2].txt
C:\Documents and Settings\kids\Application Data\Microsoft\Windows\Cookies\Low\kids@at.atwola[1].txt
C:\Documents and Settings\kids\Application Data\Microsoft\Windows\Cookies\Low\kids@atdmt[2].txt
C:\Documents and Settings\kids\Application Data\Microsoft\Windows\Cookies\Low\kids@atwola[2].txt
C:\Documents and Settings\kids\Application Data\Microsoft\Windows\Cookies\Low\kids@azjmp[1].txt
C:\Documents and Settings\kids\Application Data\Microsoft\Windows\Cookies\Low\kids@banners.battleon[1].txt
C:\Documents and Settings\kids\Application Data\Microsoft\Windows\Cookies\Low\kids@banners2.battleon[1].txt
C:\Documents and Settings\kids\Application Data\Microsoft\Windows\Cookies\Low\kids@bs.serving-sys[1].txt
C:\Documents and Settings\kids\Application Data\Microsoft\Windows\Cookies\Low\kids@burstnet[2].txt
C:\Documents and Settings\kids\Application Data\Microsoft\Windows\Cookies\Low\kids@c7.zedo[2].txt
C:\Documents and Settings\kids\Application Data\Microsoft\Windows\Cookies\Low\kids@cgm.adbureau[1].txt
C:\Documents and Settings\kids\Application Data\Microsoft\Windows\Cookies\Low\kids@chitika[2].txt
C:\Documents and Settings\kids\Application Data\Microsoft\Windows\Cookies\Low\kids@collective-media[1].txt
C:\Documents and Settings\kids\Application Data\Microsoft\Windows\Cookies\Low\kids@desertschools.112.2o7[1].txt
C:\Documents and Settings\kids\Application Data\Microsoft\Windows\Cookies\Low\kids@directtrack[1].txt
C:\Documents and Settings\kids\Application Data\Microsoft\Windows\Cookies\Low\kids@doubleclick[1].txt
C:\Documents and Settings\kids\Application Data\Microsoft\Windows\Cookies\Low\kids@dynamic.media.adrevolver[2].txt
C:\Documents and Settings\kids\Application Data\Microsoft\Windows\Cookies\Low\kids@e-2dj6wdliuidzcco.stats.esomniture[2].txt
C:\Documents and Settings\kids\Application Data\Microsoft\Windows\Cookies\Low\kids@e-2dj6wfk4ejdjilo.stats.esomniture[2].txt
C:\Documents and Settings\kids\Application Data\Microsoft\Windows\Cookies\Low\kids@e-2dj6wfkyoidpoco.stats.esomniture[2].txt
C:\Documents and Settings\kids\Application Data\Microsoft\Windows\Cookies\Low\kids@e-2dj6wfloemdzoep.stats.esomniture[1].txt
C:\Documents and Settings\kids\Application Data\Microsoft\Windows\Cookies\Low\kids@e-2dj6wjkownajwgo.stats.esomniture[1].txt
C:\Documents and Settings\kids\Application Data\Microsoft\Windows\Cookies\Low\kids@e-2dj6wjlychcjifp.stats.esomniture[2].txt
C:\Documents and Settings\kids\Application Data\Microsoft\Windows\Cookies\Low\kids@e-2dj6wjnycidzwhp.stats.esomniture[1].txt
C:\Documents and Settings\kids\Application Data\Microsoft\Windows\Cookies\Low\kids@e-2dj6wjnycmdjagq.stats.esomniture[2].txt
C:\Documents and Settings\kids\Application Data\Microsoft\Windows\Cookies\Low\kids@e-2dj6wjnyomcpmfo.stats.esomniture[2].txt
C:\Documents and Settings\kids\Application Data\Microsoft\Windows\Cookies\Low\kids@e-2dj6wjnysmc5kcp.stats.esomniture[1].txt
C:\Documents and Settings\kids\Application Data\Microsoft\Windows\Cookies\Low\kids@e-2dj6wjnysoazwlq.stats.esomniture[1].txt
C:\Documents and Settings\kids\Application Data\Microsoft\Windows\Cookies\Low\kids@ehg-corusentertainment.hitbox[1].txt
C:\Documents and Settings\kids\Application Data\Microsoft\Windows\Cookies\Low\kids@ehg-findlaw.hitbox[2].txt
C:\Documents and Settings\kids\Application Data\Microsoft\Windows\Cookies\Low\kids@ehg-idgentertainment.hitbox[2].txt
C:\Documents and Settings\kids\Application Data\Microsoft\Windows\Cookies\Low\kids@fastclick[1].txt
C:\Documents and Settings\kids\Application Data\Microsoft\Windows\Cookies\Low\kids@gjacket.adbureau[2].txt
C:\Documents and Settings\kids\Application Data\Microsoft\Windows\Cookies\Low\kids@hitbox[1].txt
C:\Documents and Settings\kids\Application Data\Microsoft\Windows\Cookies\Low\kids@insightexpressai[1].txt
C:\Documents and Settings\kids\Application Data\Microsoft\Windows\Cookies\Low\kids@interclick[2].txt
C:\Documents and Settings\kids\Application Data\Microsoft\Windows\Cookies\Low\kids@ipcmedia.122.2o7[1].txt
C:\Documents and Settings\kids\Application Data\Microsoft\Windows\Cookies\Low\kids@kontera[1].txt
C:\Documents and Settings\kids\Application Data\Microsoft\Windows\Cookies\Low\kids@landing.hitfarm[1].txt
C:\Documents and Settings\kids\Application Data\Microsoft\Windows\Cookies\Low\kids@login.tracking101[1].txt
C:\Documents and Settings\kids\Application Data\Microsoft\Windows\Cookies\Low\kids@mach.adbureau[1].txt
C:\Documents and Settings\kids\Application Data\Microsoft\Windows\Cookies\Low\kids@maxis.112.2o7[1].txt
C:\Documents and Settings\kids\Application Data\Microsoft\Windows\Cookies\Low\kids@media.adrevolver[1].txt
C:\Documents and Settings\kids\Application Data\Microsoft\Windows\Cookies\Low\kids@media.mtvnservices[2].txt
C:\Documents and Settings\kids\Application Data\Microsoft\Windows\Cookies\Low\kids@mediaplex[2].txt
C:\Documents and Settings\kids\Application Data\Microsoft\Windows\Cookies\Low\kids@msnbc.112.2o7[1].txt
C:\Documents and Settings\kids\Application Data\Microsoft\Windows\Cookies\Low\kids@msnportal.112.2o7[1].txt
C:\Documents and Settings\kids\Application Data\Microsoft\Windows\Cookies\Low\kids@myaccount.sparebackup[1].txt
C:\Documents and Settings\kids\Application Data\Microsoft\Windows\Cookies\Low\kids@network.realmedia[2].txt
C:\Documents and Settings\kids\Application Data\Microsoft\Windows\Cookies\Low\kids@nextag[1].txt
C:\Documents and Settings\kids\Application Data\Microsoft\Windows\Cookies\Low\kids@oasn04.247realmedia[1].txt
C:\Documents and Settings\kids\Application Data\Microsoft\Windows\Cookies\Low\kids@overture[1].txt
C:\Documents and Settings\kids\Application Data\Microsoft\Windows\Cookies\Low\kids@perf.overture[1].txt
C:\Documents and Settings\kids\Application Data\Microsoft\Windows\Cookies\Low\kids@popularscreensavers[1].txt
C:\Documents and Settings\kids\Application Data\Microsoft\Windows\Cookies\Low\kids@precisionclick[1].txt
C:\Documents and Settings\kids\Application Data\Microsoft\Windows\Cookies\Low\kids@pro-market[1].txt
C:\Documents and Settings\kids\Application Data\Microsoft\Windows\Cookies\Low\kids@questionmarket[2].txt
C:\Documents and Settings\kids\Application Data\Microsoft\Windows\Cookies\Low\kids@realmedia[2].txt
C:\Documents and Settings\kids\Application Data\Microsoft\Windows\Cookies\Low\kids@redirect.antracker[1].txt
C:\Documents and Settings\kids\Application Data\Microsoft\Windows\Cookies\Low\kids@redirect.antracker[2].txt
C:\Documents and Settings\kids\Application Data\Microsoft\Windows\Cookies\Low\kids@redirect.antracker[3].txt
C:\Documents and Settings\kids\Application Data\Microsoft\Windows\Cookies\Low\kids@revsci[2].txt
C:\Documents and Settings\kids\Application Data\Microsoft\Windows\Cookies\Low\kids@richmedia.yahoo[1].txt
C:\Documents and Settings\kids\Application Data\Microsoft\Windows\Cookies\Low\kids@roiservice[1].txt
C:\Documents and Settings\kids\Application Data\Microsoft\Windows\Cookies\Low\kids@server.cpmstar[2].txt
C:\Documents and Settings\kids\Application Data\Microsoft\Windows\Cookies\Low\kids@serving-sys[2].txt
C:\Documents and Settings\kids\Application Data\Microsoft\Windows\Cookies\Low\kids@sitestat.mayoclinic[1].txt
C:\Documents and Settings\kids\Application Data\Microsoft\Windows\Cookies\Low\kids@smartadserver[1].txt
C:\Documents and Settings\kids\Application Data\Microsoft\Windows\Cookies\Low\kids@specificclick[1].txt
C:\Documents and Settings\kids\Application Data\Microsoft\Windows\Cookies\Low\kids@statcounter[2].txt
C:\Documents and Settings\kids\Application Data\Microsoft\Windows\Cookies\Low\kids@stats.virtualreview[1].txt
C:\Documents and Settings\kids\Application Data\Microsoft\Windows\Cookies\Low\kids@stats3.mbmii[1].txt
C:\Documents and Settings\kids\Application Data\Microsoft\Windows\Cookies\Low\kids@statse.webtrendslive[2].txt
C:\Documents and Settings\kids\Application Data\Microsoft\Windows\Cookies\Low\kids@tacoda[2].txt
C:\Documents and Settings\kids\Application Data\Microsoft\Windows\Cookies\Low\kids@trafficmp[2].txt
C:\Documents and Settings\kids\Application Data\Microsoft\Windows\Cookies\Low\kids@tribalfusion[1].txt
C:\Documents and Settings\kids\Application Data\Microsoft\Windows\Cookies\Low\kids@viacom.adbureau[2].txt
C:\Documents and Settings\kids\Application Data\Microsoft\Windows\Cookies\Low\kids@videoegg.adbureau[2].txt
C:\Documents and Settings\kids\Application Data\Microsoft\Windows\Cookies\Low\kids@webventures.directtrack[2].txt
C:\Documents and Settings\kids\Application Data\Microsoft\Windows\Cookies\Low\kids@www.burstbeacon[1].txt
C:\Documents and Settings\kids\Application Data\Microsoft\Windows\Cookies\Low\kids@www.burstnet[1].txt
C:\Documents and Settings\kids\Application Data\Microsoft\Windows\Cookies\Low\kids@www.clickmanage[2].txt
C:\Documents and Settings\kids\Application Data\Microsoft\Windows\Cookies\Low\kids@www.googleadservices[1].txt
C:\Documents and Settings\kids\Application Data\Microsoft\Windows\Cookies\Low\kids@www.googleadservices[2].txt
C:\Documents and Settings\kids\Application Data\Microsoft\Windows\Cookies\Low\kids@www.googleadservices[4].txt
C:\Documents and Settings\kids\Application Data\Microsoft\Windows\Cookies\Low\kids@www.googleadservices[5].txt
C:\Documents and Settings\kids\Application Data\Microsoft\Windows\Cookies\Low\kids@www.mysitetraffic[2].txt
C:\Documents and Settings\kids\Application Data\Microsoft\Windows\Cookies\Low\kids@www.pixitrack[1].txt
C:\Documents and Settings\kids\Application Data\Microsoft\Windows\Cookies\Low\kids@www.popularscreensavers[1].txt
C:\Documents and Settings\kids\Application Data\Microsoft\Windows\Cookies\Low\kids@www.socialtrack[2].txt
C:\Documents and Settings\kids\Application Data\Microsoft\Windows\Cookies\Low\kids@www.w3counter[1].txt
C:\Documents and Settings\kids\Application Data\Microsoft\Windows\Cookies\Low\kids@www3.addfreestats[1].txt
C:\Documents and Settings\kids\Application Data\Microsoft\Windows\Cookies\Low\kids@xiti[1].txt
C:\Documents and Settings\kids\Application Data\Microsoft\Windows\Cookies\Low\kids@zedo[1].txt
C:\Documents and Settings\kids\Cookies\Low\kids@247realmedia[1].txt
C:\Documents and Settings\kids\Cookies\Low\kids@2o7[1].txt
C:\Documents and Settings\kids\Cookies\Low\kids@a1.interclick[2].txt
C:\Documents and Settings\kids\Cookies\Low\kids@adbrite[1].txt
C:\Documents and Settings\kids\Cookies\Low\kids@adinterax[2].txt
C:\Documents and Settings\kids\Cookies\Low\kids@adlegend[2].txt
C:\Documents and Settings\kids\Cookies\Low\kids@adrevolver[2].txt
C:\Documents and Settings\kids\Cookies\Low\kids@ads.associatedcontent[2].txt
C:\Documents and Settings\kids\Cookies\Low\kids@ads.bridgetrack[1].txt
C:\Documents and Settings\kids\Cookies\Low\kids@ads.cartoonnetwork[2].txt
C:\Documents and Settings\kids\Cookies\Low\kids@ads.cheatingdome[1].txt
C:\Documents and Settings\kids\Cookies\Low\kids@ads.createreach[1].txt
C:\Documents and Settings\kids\Cookies\Low\kids@ads.gamesbannernet[1].txt
C:\Documents and Settings\kids\Cookies\Low\kids@ads.pointroll[2].txt
C:\Documents and Settings\kids\Cookies\Low\kids@ads.pokegym[1].txt
C:\Documents and Settings\kids\Cookies\Low\kids@adserver.adtechus[1].txt
C:\Documents and Settings\kids\Cookies\Low\kids@adserver.easyad[1].txt
C:\Documents and Settings\kids\Cookies\Low\kids@adtech[1].txt
C:\Documents and Settings\kids\Cookies\Low\kids@advertising[1].txt
C:\Documents and Settings\kids\Cookies\Low\kids@adviva[2].txt
C:\Documents and Settings\kids\Cookies\Low\kids@affiliate.kitaramedia[2].txt
C:\Documents and Settings\kids\Cookies\Low\kids@apmebf[2].txt
C:\Documents and Settings\kids\Cookies\Low\kids@at.atwola[1].txt
C:\Documents and Settings\kids\Cookies\Low\kids@atdmt[2].txt
C:\Documents and Settings\kids\Cookies\Low\kids@atwola[2].txt
C:\Documents and Settings\kids\Cookies\Low\kids@azjmp[1].txt
C:\Documents and Settings\kids\Cookies\Low\kids@banners.battleon[1].txt
C:\Documents and Settings\kids\Cookies\Low\kids@banners2.battleon[1].txt
C:\Documents and Settings\kids\Cookies\Low\kids@bs.serving-sys[1].txt
C:\Documents and Settings\kids\Cookies\Low\kids@burstnet[2].txt
C:\Documents and Settings\kids\Cookies\Low\kids@c7.zedo[2].txt
C:\Documents and Settings\kids\Cookies\Low\kids@cgm.adbureau[1].txt
C:\Documents and Settings\kids\Cookies\Low\kids@chitika[2].txt
C:\Documents and Settings\kids\Cookies\Low\kids@collective-media[1].txt
C:\Documents and Settings\kids\Cookies\Low\kids@desertschools.112.2o7[1].txt
C:\Documents and Settings\kids\Cookies\Low\kids@directtrack[1].txt
C:\Documents and Settings\kids\Cookies\Low\kids@doubleclick[1].txt
C:\Documents and Settings\kids\Cookies\Low\kids@dynamic.media.adrevolver[2].txt
C:\Documents and Settings\kids\Cookies\Low\kids@e-2dj6wdliuidzcco.stats.esomniture[2].txt
C:\Documents and Settings\kids\Cookies\Low\kids@e-2dj6wfk4ejdjilo.stats.esomniture[2].txt
C:\Documents and Settings\kids\Cookies\Low\kids@e-2dj6wfkyoidpoco.stats.esomniture[2].txt
C:\Documents and Settings\kids\Cookies\Low\kids@e-2dj6wfloemdzoep.stats.esomniture[1].txt
C:\Documents and Settings\kids\Cookies\Low\kids@e-2dj6wjkownajwgo.stats.esomniture[1].txt
C:\Documents and Settings\kids\Cookies\Low\kids@e-2dj6wjlychcjifp.stats.esomniture[2].txt
C:\Documents and Settings\kids\Cookies\Low\kids@e-2dj6wjnycidzwhp.stats.esomniture[1].txt
C:\Documents and Settings\kids\Cookies\Low\kids@e-2dj6wjnycmdjagq.stats.esomniture[2].txt
C:\Documents and Settings\kids\Cookies\Low\kids@e-2dj6wjnyomcpmfo.stats.esomniture[2].txt
C:\Documents and Settings\kids\Cookies\Low\kids@e-2dj6wjnysmc5kcp.stats.esomniture[1].txt
C:\Documents and Settings\kids\Cookies\Low\kids@e-2dj6wjnysoazwlq.stats.esomniture[1].txt
C:\Documents and Settings\kids\Cookies\Low\kids@ehg-corusentertainment.hitbox[1].txt
C:\Documents and Settings\kids\Cookies\Low\kids@ehg-findlaw.hitbox[2].txt
C:\Documents and Settings\kids\Cookies\Low\kids@ehg-idgentertainment.hitbox[2].txt
C:\Documents and Settings\kids\Cookies\Low\kids@fastclick[1].txt
C:\Documents and Settings\kids\Cookies\Low\kids@gjacket.adbureau[2].txt
C:\Documents and Settings\kids\Cookies\Low\kids@hitbox[1].txt
C:\Documents and Settings\kids\Cookies\Low\kids@insightexpressai[1].txt
C:\Documents and Settings\kids\Cookies\Low\kids@interclick[2].txt
C:\Documents and Settings\kids\Cookies\Low\kids@ipcmedia.122.2o7[1].txt
C:\Documents and Settings\kids\Cookies\Low\kids@kontera[1].txt
C:\Documents and Settings\kids\Cookies\Low\kids@landing.hitfarm[1].txt
C:\Documents and Settings\kids\Cookies\Low\kids@login.tracking101[1].txt
C:\Documents and Settings\kids\Cookies\Low\kids@mach.adbureau[1].txt
C:\Documents and Settings\kids\Cookies\Low\kids@maxis.112.2o7[1].txt
C:\Documents and Settings\kids\Cookies\Low\kids@media.adrevolver[1].txt
C:\Documents and Settings\kids\Cookies\Low\kids@media.mtvnservices[2].txt
C:\Documents and Settings\kids\Cookies\Low\kids@mediaplex[2].txt
C:\Documents and Settings\kids\Cookies\Low\kids@msnbc.112.2o7[1].txt
C:\Documents and Settings\kids\Cookies\Low\kids@msnportal.112.2o7[1].txt
C:\Documents and Settings\kids\Cookies\Low\kids@myaccount.sparebackup[1].txt
C:\Documents and Settings\kids\Cookies\Low\kids@network.realmedia[2].txt
C:\Documents and Settings\kids\Cookies\Low\kids@nextag[1].txt
C:\Documents and Settings\kids\Cookies\Low\kids@oasn04.247realmedia[1].txt
C:\Documents and Settings\kids\Cookies\Low\kids@overture[1].txt
C:\Documents and Settings\kids\Cookies\Low\kids@perf.overture[1].txt
C:\Documents and Settings\kids\Cookies\Low\kids@popularscreensavers[1].txt
C:\Documents and Settings\kids\Cookies\Low\kids@precisionclick[1].txt
C:\Documents and Settings\kids\Cookies\Low\kids@pro-market[1].txt
C:\Documents and Settings\kids\Cookies\Low\kids@questionmarket[2].txt
C:\Documents and Settings\kids\Cookies\Low\kids@realmedia[2].txt
C:\Documents and Settings\kids\Cookies\Low\kids@redirect.antracker[1].txt
C:\Documents and Settings\kids\Cookies\Low\kids@redirect.antracker[2].txt
C:\Documents and Settings\kids\Cookies\Low\kids@redirect.antracker[3].txt
C:\Documents and Settings\kids\Cookies\Low\kids@revsci[2].txt
C:\Documents and Settings\kids\Cookies\Low\kids@richmedia.yahoo[1].txt
C:\Documents and Settings\kids\Cookies\Low\kids@roiservice[1].txt
C:\Documents and Settings\kids\Cookies\Low\kids@server.cpmstar[2].txt
C:\Documents and Settings\kids\Cookies\Low\kids@serving-sys[2].txt
C:\Documents and Settings\kids\Cookies\Low\kids@sitestat.mayoclinic[1].txt
C:\Documents and Settings\kids\Cookies\Low\kids@smartadserver[1].txt
C:\Documents and Settings\kids\Cookies\Low\kids@specificclick[1].txt
C:\Documents and Settings\kids\Cookies\Low\kids@statcounter[2].txt
C:\Documents and Settings\kids\Cookies\Low\kids@stats.virtualreview[1].txt
C:\Documents and Settings\kids\Cookies\Low\kids@stats3.mbmii[1].txt
C:\Documents and Settings\kids\Cookies\Low\kids@statse.webtrendslive[2].txt
C:\Documents and Settings\kids\Cookies\Low\kids@tacoda[2].txt
C:\Documents and Settings\kids\Cookies\Low\kids@trafficmp[2].txt
C:\Documents and Settings\kids\Cookies\Low\kids@tribalfusion[1].txt
C:\Documents and Settings\kids\Cookies\Low\kids@viacom.adbureau[2].txt
C:\Documents and Settings\kids\Cookies\Low\kids@videoegg.adbureau[2].txt
C:\Documents and Settings\kids\Cookies\Low\kids@webventures.directtrack[2].txt
C:\Documents and Settings\kids\Cookies\Low\kids@www.burstbeacon[1].txt
C:\Documents and Settings\kids\Cookies\Low\kids@www.burstnet[1].txt
C:\Documents and Settings\kids\Cookies\Low\kids@www.clickmanage[2].txt
C:\Documents and Settings\kids\Cookies\Low\kids@www.googleadservices[1].txt
C:\Documents and Settings\kids\Cookies\Low\kids@www.googleadservices[2].txt
C:\Documents and Settings\kids\Cookies\Low\kids@www.googleadservices[4].txt
C:\Documents and Settings\kids\Cookies\Low\kids@www.googleadservices[5].txt
C:\Documents and Settings\kids\Cookies\Low\kids@www.mysitetraffic[2].txt
C:\Documents and Settings\kids\Cookies\Low\kids@www.pixitrack[1].txt
C:\Documents and Settings\kids\Cookies\Low\kids@www.popularscreensavers[1].txt
C:\Documents and Settings\kids\Cookies\Low\kids@www.socialtrack[2].txt
C:\Documents and Settings\kids\Cookies\Low\kids@www.w3counter[1].txt
C:\Documents and Settings\kids\Cookies\Low\kids@www3.addfreestats[1].txt
C:\Documents and Settings\kids\Cookies\Low\kids@xiti[1].txt
C:\Documents and Settings\kids\Cookies\Low\kids@zedo[1].txt
C:\Documents and Settings\marquelle\AppData\Roaming\Microsoft\Windows\Cookies\Low\marquelle@a1.interclick[1].txt
C:\Documents and Settings\marquelle\AppData\Roaming\Microsoft\Windows\Cookies\Low\marquelle@adopt.euroclick[2].txt
C:\Documents and Settings\marquelle\AppData\Roaming\Microsoft\Windows\Cookies\Low\marquelle@ads.allaboutvision[2].txt
C:\Documents and Settings\marquelle\AppData\Roaming\Microsoft\Windows\Cookies\Low\marquelle@ads.lucidmedia[1].txt
C:\Documents and Settings\marquelle\AppData\Roaming\Microsoft\Windows\Cookies\Low\marquelle@ads.monster[1].txt
C:\Documents and Settings\marquelle\AppData\Roaming\Microsoft\Windows\Cookies\Low\marquelle@cgm.adbureau[2].txt
C:\Documents and Settings\marquelle\AppData\Roaming\Microsoft\Windows\Cookies\Low\marquelle@chitika[1].txt
C:\Documents and Settings\marquelle\AppData\Roaming\Microsoft\Windows\Cookies\Low\marquelle@collective-media[1].txt
C:\Documents and Settings\marquelle\AppData\Roaming\Microsoft\Windows\Cookies\Low\marquelle@e-2dj6wfk4cjczglp.stats.esomniture[1].txt
C:\Documents and Settings\marquelle\AppData\Roaming\Microsoft\Windows\Cookies\Low\marquelle@e-2dj6wfk4qkdjifo.stats.esomniture[2].txt
C:\Documents and Settings\marquelle\AppData\Roaming\Microsoft\Windows\Cookies\Low\marquelle@e-2dj6wfk4uocpiko.stats.esomniture[2].txt
C:\Documents and Settings\marquelle\AppData\Roaming\Microsoft\Windows\Cookies\Low\marquelle@e-2dj6wfkyagc5elo.stats.esomniture[2].txt
C:\Documents and Settings\marquelle\AppData\Roaming\Microsoft\Windows\Cookies\Low\marquelle@e-2dj6wfloujcjaeq.stats.esomniture[1].txt
C:\Documents and Settings\marquelle\AppData\Roaming\Microsoft\Windows\Cookies\Low\marquelle@e-2dj6wgkyugczmlp.stats.esomniture[2].txt
C:\Documents and Settings\marquelle\AppData\Roaming\Microsoft\Windows\Cookies\Low\marquelle@e-2dj6wgl4upcjolp.stats.esomniture[1].txt
C:\Documents and Settings\marquelle\AppData\Roaming\Microsoft\Windows\Cookies\Low\marquelle@e-2dj6whk4qkcjiao.stats.esomniture[1].txt
C:\Documents and Settings\marquelle\AppData\Roaming\Microsoft\Windows\Cookies\Low\marquelle@e-2dj6wjkosidjelp.stats.esomniture[2].txt
C:\Documents and Settings\marquelle\AppData\Roaming\Microsoft\Windows\Cookies\Low\marquelle@e-2dj6wjkosjcjweo.stats.esomniture[2].txt
C:\Documents and Settings\marquelle\AppData\Roaming\Microsoft\Windows\Cookies\Low\marquelle@e-2dj6wjkyshdzwbp.stats.esomniture[1].txt
C:\Documents and Settings\marquelle\AppData\Roaming\Microsoft\Windows\Cookies\Low\marquelle@e-2dj6wjkyunczgeo.stats.esomniture[1].txt
C:\Documents and Settings\marquelle\AppData\Roaming\Microsoft\Windows\Cookies\Low\marquelle@e-2dj6wjligkdzkbo.stats.esomniture[2].txt
C:\Documents and Settings\marquelle\AppData\Roaming\Microsoft\Windows\Cookies\Low\marquelle@e-2dj6wjlysicjsgo.stats.esomniture[2].txt
C:\Documents and Settings\marquelle\AppData\Roaming\Microsoft\Windows\Cookies\Low\marquelle@e-2dj6wjmiaic5ofo.stats.esomniture[2].txt
C:\Documents and Settings\marquelle\AppData\Roaming\Microsoft\Windows\Cookies\Low\marquelle@e-2dj6wjny-1sczia.stats.esomniture[2].txt
C:\Documents and Settings\marquelle\AppData\Roaming\Microsoft\Windows\Cookies\Low\marquelle@e-2dj6wjnyagdzkko.stats.esomniture[1].txt
C:\Documents and Settings\marquelle\AppData\Roaming\Microsoft\Windows\Cookies\Low\marquelle@e-2dj6wjnyahc5olp.stats.esomniture[1].txt
C:\Documents and Settings\marquelle\AppData\Roaming\Microsoft\Windows\Cookies\Low\marquelle@e-2dj6wmmiwncjsfo.stats.esomniture[1].txt
C:\Documents and Settings\marquelle\AppData\Roaming\Microsoft\Windows\Cookies\Low\marquelle@insightexpressai[1].txt
C:\Documents and Settings\marquelle\AppData\Roaming\Microsoft\Windows\Cookies\Low\marquelle@interclick[1].txt
C:\Documents and Settings\marquelle\AppData\Roaming\Microsoft\Windows\Cookies\Low\marquelle@kontera[1].txt
C:\Documents and Settings\marquelle\AppData\Roaming\Microsoft\Windows\Cookies\Low\marquelle@media6degrees[2].txt
C:\Documents and Settings\marquelle\AppData\Roaming\Microsoft\Windows\Cookies\Low\marquelle@network.realmedia[1].txt
C:\Documents and Settings\marquelle\AppData\Roaming\Microsoft\Windows\Cookies\Low\marquelle@oddcast[1].txt
C:\Documents and Settings\marquelle\AppData\Roaming\Microsoft\Windows\Cookies\Low\marquelle@pinalcountyaz[1].txt
C:\Documents and Settings\marquelle\AppData\Roaming\Microsoft\Windows\Cookies\Low\marquelle@questionpro[2].txt
C:\Documents and Settings\marquelle\AppData\Roaming\Microsoft\Windows\Cookies\Low\marquelle@realmedia[1].txt
C:\Documents and Settings\marquelle\AppData\Roaming\Microsoft\Windows\Cookies\Low\marquelle@revsci[2].txt
C:\Documents and Settings\marquelle\AppData\Roaming\Microsoft\Windows\Cookies\Low\marquelle@richmedia.yahoo[2].txt
C:\Documents and Settings\marquelle\AppData\Roaming\Microsoft\Windows\Cookies\Low\marquelle@sales.liveperson[1].txt
C:\Documents and Settings\marquelle\AppData\Roaming\Microsoft\Windows\Cookies\Low\marquelle@sales.liveperson[2].txt
C:\Documents and Settings\marquelle\AppData\Roaming\Microsoft\Windows\Cookies\Low\marquelle@server.iad.liveperson[2].txt
C:\Documents and Settings\marquelle\AppData\Roaming\Microsoft\Windows\Cookies\Low\marquelle@statcounter[1].txt
C:\Documents and Settings\marquelle\AppData\Roaming\Microsoft\Windows\Cookies\Low\marquelle@stats.paypal[1].txt
C:\Documents and Settings\marquelle\AppData\Roaming\Microsoft\Windows\Cookies\Low\marquelle@tacoda[2].txt
C:\Documents and Settings\marquelle\AppData\Roaming\Microsoft\Windows\Cookies\Low\marquelle@www.googleadservices[1].txt
C:\Documents and Settings\marquelle\AppData\Roaming\Microsoft\Windows\Cookies\Low\marquelle@www.googleadservices[2].txt
C:\Documents and Settings\marquelle\Application Data\Microsoft\Windows\Cookies\Low\marquelle@a1.interclick[1].txt
C:\Documents and Settings\marquelle\Application Data\Microsoft\Windows\Cookies\Low\marquelle@adopt.euroclick[2].txt
C:\Documents and Settings\marquelle\Application Data\Microsoft\Windows\Cookies\Low\marquelle@ads.allaboutvision[2].txt
C:\Documents and Settings\marquelle\Application Data\Microsoft\Windows\Cookies\Low\marquelle@ads.lucidmedia[1].txt
C:\Documents and Settings\marquelle\Application Data\Microsoft\Windows\Cookies\Low\marquelle@ads.monster[1].txt
C:\Documents and Settings\marquelle\Application Data\Microsoft\Windows\Cookies\Low\marquelle@cgm.adbureau[2].txt
C:\Documents and Settings\marquelle\Application Data\Microsoft\Windows\Cookies\Low\marquelle@chitika[1].txt
C:\Documents and Settings\marquelle\Application Data\Microsoft\Windows\Cookies\Low\marquelle@collective-media[1].txt
C:\Documents and Settings\marquelle\Application Data\Microsoft\Windows\Cookies\Low\marquelle@e-2dj6wfk4cjczglp.stats.esomniture[1].txt
C:\Documents and Settings\marquelle\Application Data\Microsoft\Windows\Cookies\Low\marquelle@e-2dj6wfk4qkdjifo.stats.esomniture[2].txt
C:\Documents and Settings\marquelle\Application Data\Microsoft\Windows\Cookies\Low\marquelle@e-2dj6wfk4uocpiko.stats.esomniture[2].txt
C:\Documents and Settings\marquelle\Application Data\Microsoft\Windows\Cookies\Low\marquelle@e-2dj6wfkyagc5elo.stats.esomniture[2].txt
C:\Documents and Settings\marquelle\Application Data\Microsoft\Windows\Cookies\Low\marquelle@e-2dj6wfloujcjaeq.stats.esomniture[1].txt
C:\Documents and Settings\marquelle\Application Data\Microsoft\Windows\Cookies\Low\marquelle@e-2dj6wgkyugczmlp.stats.esomniture[2].txt
C:\Documents and Settings\marquelle\Application Data\Microsoft\Windows\Cookies\Low\marquelle@e-2dj6wgl4upcjolp.stats.esomniture[1].txt
C:\Documents and Settings\marquelle\Application Data\Microsoft\Windows\Cookies\Low\marquelle@e-2dj6whk4qkcjiao.stats.esomniture[1].txt
C:\Documents and Settings\marquelle\Application Data\Microsoft\Windows\Cookies\Low\marquelle@e-2dj6wjkosidjelp.stats.esomniture[2].txt
C:\Documents and Settings\marquelle\Application Data\Microsoft\Windows\Cookies\Low\marquelle@e-2dj6wjkosjcjweo.stats.esomniture[2].txt
C:\Documents and Settings\marquelle\Application Data\Microsoft\Windows\Cookies\Low\marquelle@e-2dj6wjkyshdzwbp.stats.esomniture[1].txt
C:\Documents and Settings\marquelle\Application Data\Microsoft\Windows\Cookies\Low\marquelle@e-2dj6wjkyunczgeo.stats.esomniture[1].txt
C:\Documents and Settings\marquelle\Application Data\Microsoft\Windows\Cookies\Low\marquelle@e-2dj6wjligkdzkbo.stats.esomniture[2].txt
C:\Documents and Settings\marquelle\Application Data\Microsoft\Windows\Cookies\Low\marquelle@e-2dj6wjlysicjsgo.stats.esomniture[2].txt
C:\Documents and Settings\marquelle\Application Data\Microsoft\Windows\Cookies\Low\marquelle@e-2dj6wjmiaic5ofo.stats.esomniture[2].txt
C:\Documents and Settings\marquelle\Application Data\Microsoft\Windows\Cookies\Low\marquelle@e-2dj6wjny-1sczia.stats.esomniture[2].txt
C:\Documents and Settings\marquelle\Application Data\Microsoft\Windows\Cookies\Low\marquelle@e-2dj6wjnyagdzkko.stats.esomniture[1].txt
C:\Documents and Settings\marquelle\Application Data\Microsoft\Windows\Cookies\Low\marquelle@e-2dj6wjnyahc5olp.stats.esomniture[1].txt
C:\Documents and Settings\marquelle\Application Data\Microsoft\Windows\Cookies\Low\marquelle@e-2dj6wmmiwncjsfo.stats.esomniture[1].txt
C:\Documents and Settings\marquelle\Application Data\Microsoft\Windows\Cookies\Low\marquelle@insightexpressai[1].txt
C:\Documents and Settings\marquelle\Application Data\Microsoft\Windows\Cookies\Low\marquelle@interclick[1].txt
C:\Documents and Settings\marquelle\Application Data\Microsoft\Windows\Cookies\Low\marquelle@kontera[1].txt
C:\Documents and Settings\marquelle\Application Data\Microsoft\Windows\Cookies\Low\marquelle@media6degrees[2].txt
C:\Documents and Settings\marquelle\Application Data\Microsoft\Windows\Cookies\Low\marquelle@network.realmedia[1].txt
C:\Documents and Settings\marquelle\Application Data\Microsoft\Windows\Cookies\Low\marquelle@oddcast[1].txt
C:\Documents and Settings\marquelle\Application Data\Microsoft\Windows\Cookies\Low\marquelle@pinalcountyaz[1].txt
C:\Documents and Settings\marquelle\Application Data\Microsoft\Windows\Cookies\Low\marquelle@questionpro[2].txt
C:\Documents and Settings\marquelle\Application Data\Microsoft\Windows\Cookies\Low\marquelle@realmedia[1].txt
C:\Documents and Settings\marquelle\Application Data\Microsoft\Windows\Cookies\Low\marquelle@revsci[2].txt
C:\Documents and Settings\marquelle\Application Data\Microsoft\Windows\Cookies\Low\marquelle@richmedia.yahoo[2].txt
C:\Documents and Settings\marquelle\Application Data\Microsoft\Windows\Cookies\Low\marquelle@sales.liveperson[1].txt
C:\Documents and Settings\marquelle\Application Data\Microsoft\Windows\Cookies\Low\marquelle@sales.liveperson[2].txt
C:\Documents and Settings\marquelle\Application Data\Microsoft\Windows\Cookies\Low\marquelle@server.iad.liveperson[2].txt
C:\Documents and Settings\marquelle\Application Data\Microsoft\Windows\Cookies\Low\marquelle@statcounter[1].txt
C:\Documents and Settings\marquelle\Application Data\Microsoft\Windows\Cookies\Low\marquelle@stats.paypal[1].txt
C:\Documents and Settings\marquelle\Application Data\Microsoft\Windows\Cookies\Low\marquelle@tacoda[2].txt
C:\Documents and Settings\marquelle\Application Data\Microsoft\Windows\Cookies\Low\marquelle@www.googleadservices[1].txt
C:\Documents and Settings\marquelle\Application Data\Microsoft\Windows\Cookies\Low\marquelle@www.googleadservices[2].txt
C:\Documents and Settings\marquelle\Cookies\Low\marquelle@a1.interclick[1].txt
C:\Documents and Settings\marquelle\Cookies\Low\marquelle@adopt.euroclick[2].txt
C:\Documents and Settings\marquelle\Cookies\Low\marquelle@ads.allaboutvision[2].txt
C:\Documents and Settings\marquelle\Cookies\Low\marquelle@ads.lucidmedia[1].txt
C:\Documents and Settings\marquelle\Cookies\Low\marquelle@ads.monster[1].txt
C:\Documents and Settings\marquelle\Cookies\Low\marquelle@cgm.adbureau[2].txt
C:\Documents and Settings\marquelle\Cookies\Low\marquelle@chitika[1].txt
C:\Documents and Settings\marquelle\Cookies\Low\marquelle@collective-media[1].txt
C:\Documents and Settings\marquelle\Cookies\Low\marquelle@e-2dj6wfk4cjczglp.stats.esomniture[1].txt
C:\Documents and Settings\marquelle\Cookies\Low\marquelle@e-2dj6wfk4qkdjifo.stats.esomniture[2].txt
C:\Documents and Settings\marquelle\Cookies\Low\marquelle@e-2dj6wfk4uocpiko.stats.esomniture[2].txt
C:\Documents and Settings\marquelle\Cookies\Low\marquelle@e-2dj6wfkyagc5elo.stats.esomniture[2].txt
C:\Documents and Settings\marquelle\Cookies\Low\marquelle@e-2dj6wfloujcjaeq.stats.esomniture[1].txt
C:\Documents and Settings\marquelle\Cookies\Low\marquelle@e-2dj6wgkyugczmlp.stats.esomniture[2].txt
C:\Documents and Settings\marquelle\Cookies\Low\marquelle@e-2dj6wgl4upcjolp.stats.esomniture[1].txt
C:\Documents and Settings\marquelle\Cookies\Low\marquelle@e-2dj6whk4qkcjiao.stats.esomniture[1].txt
C:\Documents and Settings\marquelle\Cookies\Low\marquelle@e-2dj6wjkosidjelp.stats.esomniture[2].txt
C:\Documents and Settings\marquelle\Cookies\Low\marquelle@e-2dj6wjkosjcjweo.stats.esomniture[2].txt
C:\Documents and Settings\marquelle\Cookies\Low\marquelle@e-2dj6wjkyshdzwbp.stats.esomniture[1].txt
C:\Documents and Settings\marquelle\Cookies\Low\marquelle@e-2dj6wjkyunczgeo.stats.esomniture[1].txt
C:\Documents and Settings\marquelle\Cookies\Low\marquelle@e-2dj6wjligkdzkbo.stats.esomniture[2].txt
C:\Documents and Settings\marquelle\Cookies\Low\marquelle@e-2dj6wjlysicjsgo.stats.esomniture[2].txt
C:\Documents and Settings\marquelle\Cookies\Low\marquelle@e-2dj6wjmiaic5ofo.stats.esomniture[2].txt
C:\Documents and Settings\marquelle\Cookies\Low\marquelle@e-2dj6wjny-1sczia.stats.esomniture[2].txt
C:\Documents and Settings\marquelle\Cookies\Low\marquelle@e-2dj6wjnyagdzkko.stats.esomniture[1].txt
C:\Documents and Settings\marquelle\Cookies\Low\marquelle@e-2dj6wjnyahc5olp.stats.esomniture[1].txt
C:\Documents and Settings\marquelle\Cookies\Low\marquelle@e-2dj6wmmiwncjsfo.stats.esomniture[1].txt
C:\Documents and Settings\marquelle\Cookies\Low\marquelle@insightexpressai[1].txt
C:\Documents and Settings\marquelle\Cookies\Low\marquelle@interclick[1].txt
C:\Documents and Settings\marquelle\Cookies\Low\marquelle@kontera[1].txt
C:\Documents and Settings\marquelle\Cookies\Low\marquelle@media6degrees[2].txt
C:\Documents and Settings\marquelle\Cookies\Low\marquelle@network.realmedia[1].txt
C:\Documents and Settings\marquelle\Cookies\Low\marquelle@oddcast[1].txt
C:\Documents and Settings\marquelle\Cookies\Low\marquelle@pinalcountyaz[1].txt
C:\Documents and Settings\marquelle\Cookies\Low\marquelle@questionpro[2].txt
C:\Documents and Settings\marquelle\Cookies\Low\marquelle@realmedia[1].txt
C:\Documents and Settings\marquelle\Cookies\Low\marquelle@revsci[2].txt
C:\Documents and Settings\marquelle\Cookies\Low\marquelle@richmedia.yahoo[2].txt
C:\Documents and Settings\marquelle\Cookies\Low\marquelle@sales.liveperson[1].txt
C:\Documents and Settings\marquelle\Cookies\Low\marquelle@sales.liveperson[2].txt
C:\Documents and Settings\marquelle\Cookies\Low\marquelle@server.iad.liveperson[2].txt
C:\Documents and Settings\marquelle\Cookies\Low\marquelle@statcounter[1].txt
C:\Documents and Settings\marquelle\Cookies\Low\marquelle@stats.paypal[1].txt
C:\Documents and Settings\marquelle\Cookies\Low\marquelle@tacoda[2].txt
C:\Documents and Settings\marquelle\Cookies\Low\marquelle@www.googleadservices[1].txt
C:\Documents and Settings\marquelle\Cookies\Low\marquelle@www.googleadservices[2].txt
C:\Users\kids\AppData\Roaming\Microsoft\Windows\Cookies\Low\kids@247realmedia[1].txt
C:\Users\kids\AppData\Roaming\Microsoft\Windows\Cookies\Low\kids@2o7[1].txt
C:\Users\kids\AppData\Roaming\Microsoft\Windows\Cookies\Low\kids@a1.interclick[2].txt
C:\Users\kids\AppData\Roaming\Microsoft\Windows\Cookies\Low\kids@adbrite[1].txt
C:\Users\kids\AppData\Roaming\Microsoft\Windows\Cookies\Low\kids@adinterax[2].txt
C:\Users\kids\AppData\Roaming\Microsoft\Windows\Cookies\Low\kids@adlegend[2].txt
C:\Users\kids\AppData\Roaming\Microsoft\Windows\Cookies\Low\kids@adrevolver[2].txt
C:\Users\kids\AppData\Roaming\Microsoft\Windows\Cookies\Low\kids@ads.associatedcontent[2].txt
C:\Users\kids\AppData\Roaming\Microsoft\Windows\Cookies\Low\kids@ads.bridgetrack[1].txt
C:\Users\kids\AppData\Roaming\Microsoft\Windows\Cookies\Low\kids@ads.cartoonnetwork[2].txt
C:\Users\kids\AppData\Roaming\Microsoft\Windows\Cookies\Low\kids@ads.cheatingdome[1].txt
C:\Users\kids\AppData\Roaming\Microsoft\Windows\Cookies\Low\kids@ads.createreach[1].txt
C:\Users\kids\AppData\Roaming\Microsoft\Windows\Cookies\Low\kids@ads.gamesbannernet[1].txt
C:\Users\kids\AppData\Roaming\Microsoft\Windows\Cookies\Low\kids@ads.pointroll[2].txt
C:\Users\kids\AppData\Roaming\Microsoft\Windows\Cookies\Low\kids@ads.pokegym[1].txt
C:\Users\kids\AppData\Roaming\Microsoft\Windows\Cookies\Low\kids@adserver.adtechus[1].txt
C:\Users\kids\AppData\Roaming\Microsoft\Windows\Cookies\Low\kids@adserver.easyad[1].txt
C:\Users\kids\AppData\Roaming\Microsoft\Windows\Cookies\Low\kids@adtech[1].txt
C:\Users\kids\AppData\Roaming\Microsoft\Windows\Cookies\Low\kids@advertising[1].txt
C:\Users\kids\AppData\Roaming\Microsoft\Windows\Cookies\Low\kids@adviva[2].txt
C:\Users\kids\AppData\Roaming\Microsoft\Windows\Cookies\Low\kids@affiliate.kitaramedia[2].txt
C:\Users\kids\AppData\Roaming\Microsoft\Windows\Cookies\Low\kids@apmebf[2].txt
C:\Users\kids\AppData\Roaming\Microsoft\Windows\Cookies\Low\kids@at.atwola[1].txt
C:\Users\kids\AppData\Roaming\Microsoft\Windows\Cookies\Low\kids@atdmt[2].txt
C:\Users\kids\AppData\Roaming\Microsoft\Windows\Cookies\Low\kids@atwola[2].txt
C:\Users\kids\AppData\Roaming\Microsoft\Windows\Cookies\Low\kids@azjmp[1].txt
C:\Users\kids\AppData\Roaming\Microsoft\Windows\Cookies\Low\kids@banners.battleon[1].txt
C:\Users\kids\AppData\Roaming\Microsoft\Windows\Cookies\Low\kids@banners2.battleon[1].txt
C:\Users\kids\AppData\Roaming\Microsoft\Windows\Cookies\Low\kids@bs.serving-sys[1].txt
C:\Users\kids\AppData\Roaming\Microsoft\Windows\Cookies\Low\kids@burstnet[2].txt
C:\Users\kids\AppData\Roaming\Microsoft\Windows\Cookies\Low\kids@c7.zedo[2].txt
C:\Users\kids\AppData\Roaming\Microsoft\Windows\Cookies\Low\kids@cgm.adbureau[1].txt
C:\Users\kids\AppData\Roaming\Microsoft\Windows\Cookies\Low\kids@chitika[2].txt
C:\Users\kids\AppData\Roaming\Microsoft\Windows\Cookies\Low\kids@collective-media[1].txt
C:\Users\kids\AppData\Roaming\Microsoft\Windows\Cookies\Low\kids@desertschools.112.2o7[1].txt
C:\Users\kids\AppData\Roaming\Microsoft\Windows\Cookies\Low\kids@directtrack[1].txt
C:\Users\kids\AppData\Roaming\Microsoft\Windows\Cookies\Low\kids@doubleclick[1].txt
C:\Users\kids\AppData\Roaming\Microsoft\Windows\Cookies\Low\kids@dynamic.media.adrevolver[2].txt
C:\Users\kids\AppData\Roaming\Microsoft\Windows\Cookies\Low\kids@e-2dj6wdliuidzcco.stats.esomniture[2].txt
C:\Users\kids\AppData\Roaming\Microsoft\Windows\Cookies\Low\kids@e-2dj6wfk4ejdjilo.stats.esomniture[2].txt
C:\Users\kids\AppData\Roaming\Microsoft\Windows\Cookies\Low\kids@e-2dj6wfkyoidpoco.stats.esomniture[2].txt
C:\Users\kids\AppData\Roaming\Microsoft\Windows\Cookies\Low\kids@e-2dj6wfloemdzoep.stats.esomniture[1].txt
C:\Users\kids\AppData\Roaming\Microsoft\Windows\Cookies\Low\kids@e-2dj6wjkownajwgo.stats.esomniture[1].txt
C:\Users\kids\AppData\Roaming\Microsoft\Windows\Cookies\Low\kids@e-2dj6wjlychcjifp.stats.esomniture[2].txt
C:\Users\kids\AppData\Roaming\Microsoft\Windows\Cookies\Low\kids@e-2dj6wjnycidzwhp.stats.esomniture[1].txt
C:\Users\kids\AppData\Roaming\Microsoft\Windows\Cookies\Low\kids@e-2dj6wjnycmdjagq.stats.esomniture[2].txt
C:\Users\kids\AppData\Roaming\Microsoft\Windows\Cookies\Low\kids@e-2dj6wjnyomcpmfo.stats.esomniture[2].txt
C:\Users\kids\AppData\Roaming\Microsoft\Windows\Cookies\Low\kids@e-2dj6wjnysmc5kcp.stats.esomniture[1].txt
C:\Users\kids\AppData\Roaming\Microsoft\Windows\Cookies\Low\kids@e-2dj6wjnysoazwlq.stats.esomniture[1].txt
C:\Users\kids\AppData\Roaming\Microsoft\Windows\Cookies\Low\kids@ehg-corusentertainment.hitbox[1].txt
C:\Users\kids\AppData\Roaming\Microsoft\Windows\Cookies\Low\kids@ehg-findlaw.hitbox[2].txt
C:\Users\kids\AppData\Roaming\Microsoft\Windows\Cookies\Low\kids@ehg-idgentertainment.hitbox[2].txt
C:\Users\kids\AppData\Roaming\Microsoft\Windows\Cookies\Low\kids@fastclick[1].txt
C:\Users\kids\AppData\Roaming\Microsoft\Windows\Cookies\Low\kids@gjacket.adbureau[2].txt
C:\Users\kids\AppData\Roaming\Microsoft\Windows\Cookies\Low\kids@hitbox[1].txt
C:\Users\kids\AppData\Roaming\Microsoft\Windows\Cookies\Low\kids@insightexpressai[1].txt
C:\Users\kids\AppData\Roaming\Microsoft\Windows\Cookies\Low\kids@interclick[2].txt
C:\Users\kids\AppData\Roaming\Microsoft\Windows\Cookies\Low\kids@ipcmedia.122.2o7[1].txt
C:\Users\kids\AppData\Roaming\Microsoft\Windows\Cookies\Low\kids@kontera[1].txt
C:\Users\kids\AppData\Roaming\Microsoft\Windows\Cookies\Low\kids@landing.hitfarm[1].txt
C:\Users\kids\AppData\Roaming\Microsoft\Windows\Cookies\Low\kids@login.tracking101[1].txt
C:\Users\kids\AppData\Roaming\Microsoft\Windows\Cookies\Low\kids@mach.adbureau[1].txt
C:\Users\kids\AppData\Roaming\Microsoft\Windows\Cookies\Low\kids@maxis.112.2o7[1].txt
C:\Users\kids\AppData\Roaming\Microsoft\Windows\Cookies\Low\kids@media.adrevolver[1].txt
C:\Users\kids\AppData\Roaming\Microsoft\Windows\Cookies\Low\kids@media.mtvnservices[2].txt
C:\Users\kids\AppData\Roaming\Microsoft\Windows\Cookies\Low\kids@mediaplex[2].txt
C:\Users\kids\AppData\Roaming\Microsoft\Windows\Cookies\Low\kids@msnbc.112.2o7[1].txt
C:\Users\kids\AppData\Roaming\Microsoft\Windows\Cookies\Low\kids@msnportal.112.2o7[1].txt
C:\Users\kids\AppData\Roaming\Microsoft\Windows\Cookies\Low\kids@myaccount.sparebackup[1].txt
C:\Users\kids\AppData\Roaming\Microsoft\Windows\Cookies\Low\kids@network.realmedia[2].txt
C:\Users\kids\AppData\Roaming\Microsoft\Windows\Cookies\Low\kids@nextag[1].txt
C:\Users\kids\AppData\Roaming\Microsoft\Windows\Cookies\Low\kids@oasn04.247realmedia[1].txt
C:\Users\kids\AppData\Roaming\Microsoft\Windows\Cookies\Low\kids@overture[1].txt
C:\Users\kids\AppData\Roaming\Microsoft\Windows\Cookies\Low\kids@perf.overture[1].txt
C:\Users\kids\AppData\Roaming\Microsoft\Windows\Cookies\Low\kids@popularscreensavers[1].txt
C:\Users\kids\AppData\Roaming\Microsoft\Windows\Cookies\Low\kids@precisionclick[1].txt
C:\Users\kids\AppData\Roaming\Microsoft\Windows\Cookies\Low\kids@pro-market[1].txt
C:\Users\kids\AppData\Roaming\Microsoft\Windows\Cookies\Low\kids@questionmarket[2].txt
C:\Users\kids\AppData\Roaming\Microsoft\Windows\Cookies\Low\kids@realmedia[2].txt
C:\Users\kids\AppData\Roaming\Microsoft\Windows\Cookies\Low\kids@redirect.antracker[1].txt
C:\Users\kids\AppData\Roaming\Microsoft\Windows\Cookies\Low\kids@redirect.antracker[2].txt
C:\Users\kids\AppData\Roaming\Microsoft\Windows\Cookies\Low\kids@redirect.antracker[3].txt
C:\Users\kids\AppData\Roaming\Microsoft\Windows\Cookies\Low\kids@revsci[2].txt
C:\Users\kids\AppData\Roaming\Microsoft\Windows\Cookies\Low\kids@richmedia.yahoo[1].txt
C:\Users\kids\AppData\Roaming\Microsoft\Windows\Cookies\Low\kids@roiservice[1].txt
C:\Users\kids\AppData\Roaming\Microsoft\Windows\Cookies\Low\kids@server.cpmstar[2].txt
C:\Users\kids\AppData\Roaming\Microsoft\Windows\Cookies\Low\kids@serving-sys[2].txt
C:\Users\kids\AppData\Roaming\Microsoft\Windows\Cookies\Low\kids@sitestat.mayoclinic[1].txt
C:\Users\kids\AppData\Roaming\Microsoft\Windows\Cookies\Low\kids@smartadserver[1].txt
C:\Users\kids\AppData\Roaming\Microsoft\Windows\Cookies\Low\kids@specificclick[1].txt
C:\Users\kids\AppData\Roaming\Microsoft\Windows\Cookies\Low\kids@statcounter[2].txt
C:\Users\kids\AppData\Roaming\Microsoft\Windows\Cookies\Low\kids@stats.virtualreview[1].txt
C:\Users\kids\AppData\Roaming\Microsoft\Windows\Cookies\Low\kids@stats3.mbmii[1].txt
C:\Users\kids\AppData\Roaming\Microsoft\Windows\Cookies\Low\kids@statse.webtrendslive[2].txt
C:\Users\kids\AppData\Roaming\Microsoft\Windows\Cookies\Low\kids@tacoda[2].txt
C:\Users\kids\AppData\Roaming\Microsoft\Windows\Cookies\Low\kids@trafficmp[2].txt
C:\Users\kids\AppData\Roaming\Microsoft\Windows\Cookies\Low\kids@tribalfusion[1].txt
C:\Users\kids\AppData\Roaming\Microsoft\Windows\Cookies\Low\kids@viacom.adbureau[2].txt
C:\Users\kids\AppData\Roaming\Microsoft\Windows\Cookies\Low\kids@videoegg.adbureau[2].txt
C:\Users\kids\AppData\Roaming\Microsoft\Windows\Cookies\Low\kids@webventures.directtrack[2].txt
C:\Users\kids\AppData\Roaming\Microsoft\Windows\Cookies\Low\kids@www.burstbeacon[1].txt
C:\Users\kids\AppData\Roaming\Microsoft\Windows\Cookies\Low\kids@www.burstnet[1].txt
C:\Users\kids\AppData\Roaming\Microsoft\Windows\Cookies\Low\kids@www.clickmanage[2].txt
C:\Users\kids\AppData\Roaming\Microsoft\Windows\Cookies\Low\kids@www.googleadservices[1].txt
C:\Users\kids\AppData\Roaming\Microsoft\Windows\Cookies\Low\kids@www.googleadservices[2].txt
C:\Users\kids\AppData\Roaming\Microsoft\Windows\Cookies\Low\kids@www.googleadservices[4].txt
C:\Users\kids\AppData\Roaming\Microsoft\Windows\Cookies\Low\kids@www.googleadservices[5].txt
C:\Users\kids\AppData\Roaming\Microsoft\Windows\Cookies\Low\kids@www.mysitetraffic[2].txt
C:\Users\kids\AppData\Roaming\Microsoft\Windows\Cookies\Low\kids@www.pixitrack[1].txt
C:\Users\kids\AppData\Roaming\Microsoft\Windows\Cookies\Low\kids@www.popularscreensavers[1].txt
C:\Users\kids\AppData\Roaming\Microsoft\Windows\Cookies\Low\kids@www.socialtrack[2].txt
C:\Users\kids\AppData\Roaming\Microsoft\Windows\Cookies\Low\kids@www.w3counter[1].txt
C:\Users\kids\AppData\Roaming\Microsoft\Windows\Cookies\Low\kids@www3.addfreestats[1].txt
C:\Users\kids\AppData\Roaming\Microsoft\Windows\Cookies\Low\kids@xiti[1].txt
C:\Users\kids\AppData\Roaming\Microsoft\Windows\Cookies\Low\kids@zedo[1].txt
C:\Users\kids\Application Data\Microsoft\Windows\Cookies\Low\kids@247realmedia[1].txt
C:\Users\kids\Application Data\Microsoft\Windows\Cookies\Low\kids@2o7[1].txt
C:\Users\kids\Application Data\Microsoft\Windows\Cookies\Low\kids@a1.interclick[2].txt
C:\Users\kids\Application Data\Microsoft\Windows\Cookies\Low\kids@adbrite[1].txt
C:\Users\kids\Application Data\Microsoft\Windows\Cookies\Low\kids@adinterax[2].txt
C:\Users\kids\Application Data\Microsoft\Windows\Cookies\Low\kids@adlegend[2].txt
C:\Users\kids\Application Data\Microsoft\Windows\Cookies\Low\kids@adrevolver[2].txt
C:\Users\kids\Application Data\Microsoft\Windows\Cookies\Low\kids@ads.associatedcontent[2].txt
C:\Users\kids\Application Data\Microsoft\Windows\Cookies\Low\kids@ads.bridgetrack[1].txt
C:\Users\kids\Application Data\Microsoft\Windows\Cookies\Low\kids@ads.cartoonnetwork[2].txt
C:\Users\kids\Application Data\Microsoft\Windows\Cookies\Low\kids@ads.cheatingdome[1].txt
C:\Users\kids\Application Data\Microsoft\Windows\Cookies\Low\kids@ads.createreach[1].txt
C:\Users\kids\Application Data\Microsoft\Windows\Cookies\Low\kids@ads.gamesbannernet[1].txt
C:\Users\kids\Application Data\Microsoft\Windows\Cookies\Low\kids@ads.pointroll[2].txt
C:\Users\kids\Application Data\Microsoft\Windows\Cookies\Low\kids@ads.pokegym[1].txt
C:\Users\kids\Application Data\Microsoft\Windows\Cookies\Low\kids@adserver.adtechus[1].txt
C:\Users\kids\Application Data\Microsoft\Windows\Cookies\Low\kids@adserver.easyad[1].txt
C:\Users\kids\Application Data\Microsoft\Windows\Cookies\Low\kids@adtech[1].txt
C:\Users\kids\Application Data\Microsoft\Windows\Cookies\Low\kids@advertising[1].txt
C:\Users\kids\Application Data\Microsoft\Windows\Cookies\Low\kids@adviva[2].txt
C:\Users\kids\Application Data\Microsoft\Windows\Cookies\Low\kids@affiliate.kitaramedia[2].txt
C:\Users\kids\Application Data\Microsoft\Windows\Cookies\Low\kids@apmebf[2].txt
C:\Users\kids\Application Data\Microsoft\Windows\Cookies\Low\kids@at.atwola[1].txt
C:\Users\kids\Application Data\Microsoft\Windows\Cookies\Low\kids@atdmt[2].txt
C:\Users\kids\Application Data\Microsoft\Windows\Cookies\Low\kids@atwola[2].txt
C:\Users\kids\Application Data\Microsoft\Windows\Cookies\Low\kids@azjmp[1].txt
C:\Users\kids\Application Data\Microsoft\Windows\Cookies\Low\kids@banners.battleon[1].txt
C:\Users\kids\Application Data\Microsoft\Windows\Cookies\Low\kids@banners2.battleon[1].txt
C:\Users\kids\Application Data\Microsoft\Windows\Cookies\Low\kids@bs.serving-sys[1].txt
C:\Users\kids\Application Data\Microsoft\Windows\Cookies\Low\kids@burstnet[2].txt
C:\Users\kids\Application Data\Microsoft\Windows\Cookies\Low\kids@c7.zedo[2].txt
C:\Users\kids\Application Data\Microsoft\Windows\Cookies\Low\kids@cgm.adbureau[1].txt
C:\Users\kids\Application Data\Microsoft\Windows\Cookies\Low\kids@chitika[2].txt
C:\Users\kids\Application Data\Microsoft\Windows\Cookies\Low\kids@collective-media[1].txt
C:\Users\kids\Application Data\Microsoft\Windows\Cookies\Low\kids@desertschools.112.2o7[1].txt
C:\Users\kids\Application Data\Microsoft\Windows\Cookies\Low\kids@directtrack[1].txt
C:\Users\kids\Application Data\Microsoft\Windows\Cookies\Low\kids@doubleclick[1].txt
C:\Users\kids\Application Data\Microsoft\Windows\Cookies\Low\kids@dynamic.media.adrevolver[2].txt
C:\Users\kids\Application Data\Microsoft\Windows\Cookies\Low\kids@e-2dj6wdliuidzcco.stats.esomniture[2].txt
C:\Users\kids\Application Data\Microsoft\Windows\Cookies\Low\kids@e-2dj6wfk4ejdjilo.stats.esomniture[2].txt
C:\Users\kids\Application Data\Microsoft\Windows\Cookies\Low\kids@e-2dj6wfkyoidpoco.stats.esomniture[2].txt
C:\Users\kids\Application Data\Microsoft\Windows\Cookies\Low\kids@e-2dj6wfloemdzoep.stats.esomniture[1].txt
C:\Users\kids\Application Data\Microsoft\Windows\Cookies\Low\kids@e-2dj6wjkownajwgo.stats.esomniture[1].txt
C:\Users\kids\Application Data\Microsoft\Windows\Cookies\Low\kids@e-2dj6wjlychcjifp.stats.esomniture[2].txt
C:\Users\kids\Application Data\Microsoft\Windows\Cookies\Low\kids@e-2dj6wjnycidzwhp.stats.esomniture[1].txt
C:\Users\kids\Application Data\Microsoft\Windows\Cookies\Low\kids@e-2dj6wjnycmdjagq.stats.esomniture[2].txt
C:\Users\kids\Application Data\Microsoft\Windows\Cookies\Low\kids@e-2dj6wjnyomcpmfo.stats.esomniture[2].txt
C:\Users\kids\Application Data\Microsoft\Windows\Cookies\Low\kids@e-2dj6wjnysmc5kcp.stats.esomniture[1].txt
C:\Users\kids\Application Data\Microsoft\Windows\Cookies\Low\kids@e-2dj6wjnysoazwlq.stats.esomniture[1].txt
C:\Users\kids\Application Data\Microsoft\Windows\Cookies\Low\kids@ehg-corusentertainment.hitbox[1].txt
C:\Users\kids\Application Data\Microsoft\Windows\Cookies\Low\kids@ehg-findlaw.hitbox[2].txt
C:\Users\kids\Application Data\Microsoft\Windows\Cookies\Low\kids@ehg-idgentertainment.hitbox[2].txt
C:\Users\kids\Application Data\Microsoft\Windows\Cookies\Low\kids@fastclick[1].txt
C:\Users\kids\Application Data\Microsoft\Windows\Cookies\Low\kids@gjacket.adbureau[2].txt
C:\Users\kids\Application Data\Microsoft\Windows\Cookies\Low\kids@hitbox[1].txt
C:\Users\kids\Application Data\Microsoft\Windows\Cookies\Low\kids@insightexpressai[1].txt
C:\Users\kids\Application Data\Microsoft\Windows\Cookies\Low\kids@interclick[2].txt
C:\Users\kids\Application Data\Microsoft\Windows\Cookies\Low\kids@ipcmedia.122.2o7[1].txt
C:\Users\kids\Application Data\Microsoft\Windows\Cookies\Low\kids@kontera[1].txt
C:\Users\kids\Application Data\Microsoft\Windows\Cookies\Low\kids@landing.hitfarm[1].txt
C:\Users\kids\Application Data\Microsoft\Windows\Cookies\Low\kids@login.tracking101[1].txt
C:\Users\kids\Application Data\Microsoft\Windows\Cookies\Low\kids@mach.adbureau[1].txt
C:\Users\kids\Application Data\Microsoft\Windows\Cookies\Low\kids@maxis.112.2o7[1].txt
C:\Users\kids\Application Data\Microsoft\Windows\Cookies\Low\kids@media.adrevolver[1].txt
C:\Users\kids\Application Data\Microsoft\Windows\Cookies\Low\kids@media.mtvnservices[2].txt
C:\Users\kids\Application Data\Microsoft\Windows\Cookies\Low\kids@mediaplex[2].txt
C:\Users\kids\Application Data\Microsoft\Windows\Cookies\Low\kids@msnbc.112.2o7[1].txt
C:\Users\kids\Application Data\Microsoft\Windows\Cookies\Low\kids@msnportal.112.2o7[1].txt
C:\Users\kids\Application Data\Microsoft\Windows\Cookies\Low\kids@myaccount.sparebackup[1].txt
C:\Users\kids\Application Data\Microsoft\Windows\Cookies\Low\kids@network.realmedia[2].txt
C:\Users\kids\Application Data\Microsoft\Windows\Cookies\Low\kids@nextag[1].txt
C:\Users\kids\Application Data\Microsoft\Windows\Cookies\Low\kids@oasn04.247realmedia[1].txt
C:\Users\kids\Application Data\Microsoft\Windows\Cookies\Low\kids@overture[1].txt
C:\Users\kids\Application Data\Microsoft\Windows\Cookies\Low\kids@perf.overture[1].txt
C:\Users\kids\Application Data\Microsoft\Windows\Cookies\Low\kids@popularscreensavers[1].txt
C:\Users\kids\Application Data\Microsoft\Windows\Cookies\Low\kids@precisionclick[1].txt
C:\Users\kids\Application Data\Microsoft\Windows\Cookies\Low\kids@pro-market[1].txt
C:\Users\kids\Application Data\Microsoft\Windows\Cookies\Low\kids@questionmarket[2].txt
C:\Users\kids\Application Data\Microsoft\Windows\Cookies\Low\kids@realmedia[2].txt
C:\Users\kids\Application Data\Microsoft\Windows\Cookies\Low\kids@redirect.antracker[1].txt
C:\Users\kids\Application Data\Microsoft\Windows\Cookies\Low\kids@redirect.antracker[2].txt
C:\Users\kids\Application Data\Microsoft\Windows\Cookies\Low\kids@redirect.antracker[3].txt
C:\Users\kids\Application Data\Microsoft\Windows\Cookies\Low\kids@revsci[2].txt
C:\Users\kids\Application Data\Microsoft\Windows\Cookies\Low\kids@richmedia.yahoo[1].txt
C:\Users\kids\Application Data\Microsoft\Windows\Cookies\Low\kids@roiservice[1].txt
C:\Users\kids\Application Data\Microsoft\Windows\Cookies\Low\kids@server.cpmstar[2].txt
C:\Users\kids\Application Data\Microsoft\Windows\Cookies\Low\kids@serving-sys[2].txt
C:\Users\kids\Application Data\Microsoft\Windows\Cookies\Low\kids@sitestat.mayoclinic[1].txt
C:\Users\kids\Application Data\Microsoft\Windows\Cookies\Low\kids@smartadserver[1].txt
C:\Users\kids\Application Data\Microsoft\Windows\Cookies\Low\kids@specificclick[1].txt
C:\Users\kids\Application Data\Microsoft\Windows\Cookies\Low\kids@statcounter[2].txt
C:\Users\kids\Application Data\Microsoft\Windows\Cookies\Low\kids@stats.virtualreview[1].txt
C:\Users\kids\Application Data\Microsoft\Windows\Cookies\Low\kids@stats3.mbmii[1].txt
C:\Users\kids\Application Data\Microsoft\Windows\Cookies\Low\kids@statse.webtrendslive[2].txt
C:\Users\kids\Application Data\Microsoft\Windows\Cookies\Low\kids@tacoda[2].txt
C:\Users\kids\Application Data\Microsoft\Windows\Cookies\Low\kids@trafficmp[2].txt
C:\Users\kids\Application Data\Microsoft\Windows\Cookies\Low\kids@tribalfusion[1].txt
C:\Users\kids\Application Data\Microsoft\Windows\Cookies\Low\kids@viacom.adbureau[2].txt
C:\Users\kids\Application Data\Microsoft\Windows\Cookies\Low\kids@videoegg.adbureau[2].txt
C:\Users\kids\Application Data\Microsoft\Windows\Cookies\Low\kids@webventures.directtrack[2].txt
C:\Users\kids\Application Data\Microsoft\Windows\Cookies\Low\kids@www.burstbeacon[1].txt
C:\Users\kids\Application Data\Microsoft\Windows\Cookies\Low\kids@www.burstnet[1].txt
C:\Users\kids\Application Data\Microsoft\Windows\Cookies\Low\kids@www.clickmanage[2].txt
C:\Users\kids\Application Data\Microsoft\Windows\Cookies\Low\kids@www.googleadservices[1].txt
C:\Users\kids\Application Data\Microsoft\Windows\Cookies\Low\kids@www.googleadservices[2].txt
C:\Users\kids\Application Data\Microsoft\Windows\Cookies\Low\kids@www.googleadservices[4].txt
C:\Users\kids\Application Data\Microsoft\Windows\Cookies\Low\kids@www.googleadservices[5].txt
C:\Users\kids\Application Data\Microsoft\Windows\Cookies\Low\kids@www.mysitetraffic[2].txt
C:\Users\kids\Application Data\Microsoft\Windows\Cookies\Low\kids@www.pixitrack[1].txt
C:\Users\kids\Application Data\Microsoft\Windows\Cookies\Low\kids@www.popularscreensavers[1].txt
C:\Users\kids\Application Data\Microsoft\Windows\Cookies\Low\kids@www.socialtrack[2].txt
C:\Users\kids\Application Data\Microsoft\Windows\Cookies\Low\kids@www.w3counter[1].txt
C:\Users\kids\Application Data\Microsoft\Windows\Cookies\Low\kids@www3.addfreestats[1].txt
C:\Users\kids\Application Data\Microsoft\Windows\Cookies\Low\kids@xiti[1].txt
C:\Users\kids\Application Data\Microsoft\Windows\Cookies\Low\kids@zedo[1].txt
C:\Users\kids\Cookies\Low\kids@247realmedia[1].txt
C:\Users\kids\Cookies\Low\kids@2o7[1].txt
C:\Users\kids\Cookies\Low\kids@a1.interclick[2].txt
C:\Users\kids\Cookies\Low\kids@adbrite[1].txt
C:\Users\kids\Cookies\Low\kids@adinterax[2].txt
C:\Users\kids\Cookies\Low\kids@adlegend[2].txt
C:\Users\kids\Cookies\Low\kids@adrevolver[2].txt
C:\Users\kids\Cookies\Low\kids@ads.associatedcontent[2].txt
C:\Users\kids\Cookies\Low\kids@ads.bridgetrack[1].txt
C:\Users\kids\Cookies\Low\kids@ads.cartoonnetwork[2].txt
C:\Users\kids\Cookies\Low\kids@ads.cheatingdome[1].txt
C:\Users\kids\Cookies\Low\kids@ads.createreach[1].txt
C:\Users\kids\Cookies\Low\kids@ads.gamesbannernet[1].txt
C:\Users\kids\Cookies\Low\kids@ads.pointroll[2].txt
C:\Users\kids\Cookies\Low\kids@ads.pokegym[1].txt
C:\Users\kids\Cookies\Low\kids@adserver.adtechus[1].txt
C:\Users\kids\Cookies\Low\kids@adserver.easyad[1].txt
C:\Users\kids\Cookies\Low\kids@adtech[1].txt
C:\Users\kids\Cookies\Low\kids@advertising[1].txt
C:\Users\kids\Cookies\Low\kids@adviva[2].txt
C:\Users\kids\Cookies\Low\kids@affiliate.kitaramedia[2].txt
C:\Users\kids\Cookies\Low\kids@apmebf[2].txt
C:\Users\kids\Cookies\Low\kids@at.atwola[1].txt
C:\Users\kids\Cookies\Low\kids@atdmt[2].txt
C:\Users\kids\Cookies\Low\kids@atwola[2].txt
C:\Users\kids\Cookies\Low\kids@azjmp[1].txt
C:\Users\kids\Cookies\Low\kids@banners.battleon[1].txt
C:\Users\kids\Cookies\Low\kids@banners2.battleon[1].txt
C:\Users\kids\Cookies\Low\kids@bs.serving-sys[1].txt
C:\Users\kids\Cookies\Low\kids@burstnet[2].txt
C:\Users\kids\Cookies\Low\kids@c7.zedo[2].txt
C:\Users\kids\Cookies\Low\kids@cgm.adbureau[1].txt
C:\Users\kids\Cookies\Low\kids@chitika[2].txt
C:\Users\kids\Cookies\Low\kids@collective-media[1].txt
C:\Users\kids\Cookies\Low\kids@desertschools.112.2o7[1].txt
C:\Users\kids\Cookies\Low\kids@directtrack[1].txt
C:\Users\kids\Cookies\Low\kids@doubleclick[1].txt
C:\Users\kids\Cookies\Low\kids@dynamic.media.adrevolver[2].txt
C:\Users\kids\Cookies\Low\kids@e-2dj6wdliuidzcco.stats.esomniture[2].txt
C:\Users\kids\Cookies\Low\kids@e-2dj6wfk4ejdjilo.stats.esomniture[2].txt
C:\Users\kids\Cookies\Low\kids@e-2dj6wfkyoidpoco.stats.esomniture[2].txt
C:\Users\kids\Cookies\Low\kids@e-2dj6wfloemdzoep.stats.esomniture[1].txt
C:\Users\kids\Cookies\Low\kids@e-2dj6wjkownajwgo.stats.esomniture[1].txt
C:\Users\kids\Cookies\Low\kids@e-2dj6wjlychcjifp.stats.esomniture[2].txt
C:\Users\kids\Cookies\Low\kids@e-2dj6wjnycidzwhp.stats.esomniture[1].txt
C:\Users\kids\Cookies\Low\kids@e-2dj6wjnycmdjagq.stats.esomniture[2].txt
C:\Users\kids\Cookies\Low\kids@e-2dj6wjnyomcpmfo.stats.esomniture[2].txt
C:\Users\kids\Cookies\Low\kids@e-2dj6wjnysmc5kcp.stats.esomniture[1].txt
C:\Users\kids\Cookies\Low\kids@e-2dj6wjnysoazwlq.stats.esomniture[1].txt
C:\Users\kids\Cookies\Low\kids@ehg-corusentertainment.hitbox[1].txt
C:\Users\kids\Cookies\Low\kids@ehg-findlaw.hitbox[2].txt
C:\Users\kids\Cookies\Low\kids@ehg-idgentertainment.hitbox[2].txt
C:\Users\kids\Cookies\Low\kids@fastclick[1].txt
C:\Users\kids\Cookies\Low\kids@gjacket.adbureau[2].txt
C:\Users\kids\Cookies\Low\kids@hitbox[1].txt
C:\Users\kids\Cookies\Low\kids@insightexpressai[1].txt
C:\Users\kids\Cookies\Low\kids@interclick[2].txt
C:\Users\kids\Cookies\Low\kids@ipcmedia.122.2o7[1].txt
C:\Users\kids\Cookies\Low\kids@kontera[1].txt
C:\Users\kids\Cookies\Low\kids@landing.hitfarm[1].txt
C:\Users\kids\Cookies\Low\kids@login.tracking101[1].txt
C:\Users\kids\Cookies\Low\kids@mach.adbureau[1].txt
C:\Users\kids\Cookies\Low\kids@maxis.112.2o7[1].txt
C:\Users\kids\Cookies\Low\kids@media.adrevolver[1].txt
C:\Users\kids\Cookies\Low\kids@media.mtvnservices[2].txt
C:\Users\kids\Cookies\Low\kids@mediaplex[2].txt
C:\Users\kids\Cookies\Low\kids@msnbc.112.2o7[1].txt
C:\Users\kids\Cookies\Low\kids@msnportal.112.2o7[1].txt
C:\Users\kids\Cookies\Low\kids@myaccount.sparebackup[1].txt
C:\Users\kids\Cookies\Low\kids@network.realmedia[2].txt
C:\Users\kids\Cookies\Low\kids@nextag[1].txt
C:\Users\kids\Cookies\Low\kids@oasn04.247realmedia[1].txt
C:\Users\kids\Cookies\Low\kids@overture[1].txt
C:\Users\kids\Cookies\Low\kids@perf.overture[1].txt
C:\Users\kids\Cookies\Low\kids@popularscreensavers[1].txt
C:\Users\kids\Cookies\Low\kids@precisionclick[1].txt
C:\Users\kids\Cookies\Low\kids@pro-market[1].txt
C:\Users\kids\Cookies\Low\kids@questionmarket[2].txt
C:\Users\kids\Cookies\Low\kids@realmedia[2].txt
C:\Users\kids\Cookies\Low\kids@redirect.antracker[1].txt
C:\Users\kids\Cookies\Low\kids@redirect.antracker[2].txt
C:\Users\kids\Cookies\Low\kids@redirect.antracker[3].txt
C:\Users\kids\Cookies\Low\kids@revsci[2].txt
C:\Users\kids\Cookies\Low\kids@richmedia.yahoo[1].txt
C:\Users\kids\Cookies\Low\kids@roiservice[1].txt
C:\Users\kids\Cookies\Low\kids@server.cpmstar[2].txt
C:\Users\kids\Cookies\Low\kids@serving-sys[2].txt
C:\Users\kids\Cookies\Low\kids@sitestat.mayoclinic[1].txt
C:\Users\kids\Cookies\Low\kids@smartadserver[1].txt
C:\Users\kids\Cookies\Low\kids@specificclick[1].txt
C:\Users\kids\Cookies\Low\kids@statcounter[2].txt
C:\Users\kids\Cookies\Low\kids@stats.virtualreview[1].txt
C:\Users\kids\Cookies\Low\kids@stats3.mbmii[1].txt
C:\Users\kids\Cookies\Low\kids@statse.webtrendslive[2].txt
C:\Users\kids\Cookies\Low\kids@tacoda[2].txt
C:\Users\kids\Cookies\Low\kids@trafficmp[2].txt
C:\Users\kids\Cookies\Low\kids@tribalfusion[1].txt
C:\Users\kids\Cookies\Low\kids@viacom.adbureau[2].txt
C:\Users\kids\Cookies\Low\kids@videoegg.adbureau[2].txt
C:\Users\kids\Cookies\Low\kids@webventures.directtrack[2].txt
C:\Users\kids\Cookies\Low\kids@www.burstbeacon[1].txt
C:\Users\kids\Cookies\Low\kids@www.burstnet[1].txt
C:\Users\kids\Cookies\Low\kids@www.clickmanage[2].txt
C:\Users\kids\Cookies\Low\kids@www.googleadservices[1].txt
C:\Users\kids\Cookies\Low\kids@www.googleadservices[2].txt
C:\Users\kids\Cookies\Low\kids@www.googleadservices[4].txt
C:\Users\kids\Cookies\Low\kids@www.googleadservices[5].txt
C:\Users\kids\Cookies\Low\kids@www.mysitetraffic[2].txt
C:\Users\kids\Cookies\Low\kids@www.pixitrack[1].txt
C:\Users\kids\Cookies\Low\kids@www.popularscreensavers[1].txt
C:\Users\kids\Cookies\Low\kids@www.socialtrack[2].txt
C:\Users\kids\Cookies\Low\kids@www.w3counter[1].txt
C:\Users\kids\Cookies\Low\kids@www3.addfreestats[1].txt
C:\Users\kids\Cookies\Low\kids@xiti[1].txt
C:\Users\kids\Cookies\Low\kids@zedo[1].txt
C:\Users\marquelle\AppData\Roaming\Microsoft\Windows\Cookies\Low\marquelle@a1.interclick[1].txt
C:\Users\marquelle\AppData\Roaming\Microsoft\Windows\Cookies\Low\marquelle@adopt.euroclick[2].txt
C:\Users\marquelle\AppData\Roaming\Microsoft\Windows\Cookies\Low\marquelle@ads.allaboutvision[2].txt
C:\Users\marquelle\AppData\Roaming\Microsoft\Windows\Cookies\Low\marquelle@ads.lucidmedia[1].txt
C:\Users\marquelle\AppData\Roaming\Microsoft\Windows\Cookies\Low\marquelle@ads.monster[1].txt
C:\Users\marquelle\AppData\Roaming\Microsoft\Windows\Cookies\Low\marquelle@cgm.adbureau[2].txt
C:\Users\marquelle\AppData\Roaming\Microsoft\Windows\Cookies\Low\marquelle@chitika[1].txt
C:\Users\marquelle\AppData\Roaming\Microsoft\Windows\Cookies\Low\marquelle@collective-media[1].txt
C:\Users\marquelle\AppData\Roaming\Microsoft\Windows\Cookies\Low\marquelle@e-2dj6wfk4cjczglp.stats.esomniture[1].txt
C:\Users\marquelle\AppData\Roaming\Microsoft\Windows\Cookies\Low\marquelle@e-2dj6wfk4qkdjifo.stats.esomniture[2].txt
C:\Users\marquelle\AppData\Roaming\Microsoft\Windows\Cookies\Low\marquelle@e-2dj6wfk4uocpiko.stats.esomniture[2].txt
C:\Users\marquelle\AppData\Roaming\Microsoft\Windows\Cookies\Low\marquelle@e-2dj6wfkyagc5elo.stats.esomniture[2].txt
C:\Users\marquelle\AppData\Roaming\Microsoft\Windows\Cookies\Low\marquelle@e-2dj6wfloujcjaeq.stats.esomniture[1].txt
C:\Users\marquelle\AppData\Roaming\Microsoft\Windows\Cookies\Low\marquelle@e-2dj6wgkyugczmlp.stats.esomniture[2].txt
C:\Users\marquelle\AppData\Roaming\Microsoft\Windows\Cookies\Low\marquelle@e-2dj6wgl4upcjolp.stats.esomniture[1].txt
C:\Users\marquelle\AppData\Roaming\Microsoft\Windows\Cookies\Low\marquelle@e-2dj6whk4qkcjiao.stats.esomniture[1].txt
C:\Users\marquelle\AppData\Roaming\Microsoft\Windows\Cookies\Low\marquelle@e-2dj6wjkosidjelp.stats.esomniture[2].txt
C:\Users\marquelle\AppData\Roaming\Microsoft\Windows\Cookies\Low\marquelle@e-2dj6wjkosjcjweo.stats.esomniture[2].txt
C:\Users\marquelle\AppData\Roaming\Microsoft\Windows\Cookies\Low\marquelle@e-2dj6wjkyshdzwbp.stats.esomniture[1].txt
C:\Users\marquelle\AppData\Roaming\Microsoft\Windows\Cookies\Low\marquelle@e-2dj6wjkyunczgeo.stats.esomniture[1].txt
C:\Users\marquelle\AppData\Roaming\Microsoft\Windows\Cookies\Low\marquelle@e-2dj6wjligkdzkbo.stats.esomniture[2].txt
C:\Users\marquelle\AppData\Roaming\Microsoft\Windows\Cookies\Low\marquelle@e-2dj6wjlysicjsgo.stats.esomniture[2].txt
C:\Users\marquelle\AppData\Roaming\Microsoft\Windows\Cookies\Low\marquelle@e-2dj6wjmiaic5ofo.stats.esomniture[2].txt
C:\Users\marquelle\AppData\Roaming\Microsoft\Windows\Cookies\Low\marquelle@e-2dj6wjny-1sczia.stats.esomniture[2].txt
C:\Users\marquelle\AppData\Roaming\Microsoft\Windows\Cookies\Low\marquelle@e-2dj6wjnyagdzkko.stats.esomniture[1].txt
C:\Users\marquelle\AppData\Roaming\Microsoft\Windows\Cookies\Low\marquelle@e-2dj6wjnyahc5olp.stats.esomniture[1].txt
C:\Users\marquelle\AppData\Roaming\Microsoft\Windows\Cookies\Low\marquelle@e-2dj6wmmiwncjsfo.stats.esomniture[1].txt
C:\Users\marquelle\AppData\Roaming\Microsoft\Windows\Cookies\Low\marquelle@insightexpressai[1].txt
C:\Users\marquelle\AppData\Roaming\Microsoft\Windows\Cookies\Low\marquelle@interclick[1].txt
C:\Users\marquelle\AppData\Roaming\Microsoft\Windows\Cookies\Low\marquelle@kontera[1].txt
C:\Users\marquelle\AppData\Roaming\Microsoft\Windows\Cookies\Low\marquelle@media6degrees[2].txt
C:\Users\marquelle\AppData\Roaming\Microsoft\Windows\Cookies\Low\marquelle@network.realmedia[1].txt
C:\Users\marquelle\AppData\Roaming\Microsoft\Windows\Cookies\Low\marquelle@oddcast[1].txt
C:\Users\marquelle\AppData\Roaming\Microsoft\Windows\Cookies\Low\marquelle@pinalcountyaz[1].txt
C:\Users\marquelle\AppData\Roaming\Microsoft\Windows\Cookies\Low\marquelle@questionpro[2].txt
C:\Users\marquelle\AppData\Roaming\Microsoft\Windows\Cookies\Low\marquelle@realmedia[1].txt
C:\Users\marquelle\AppData\Roaming\Microsoft\Windows\Cookies\Low\marquelle@revsci[2].txt
C:\Users\marquelle\AppData\Roaming\Microsoft\Windows\Cookies\Low\marquelle@richmedia.yahoo[2].txt
C:\Users\marquelle\AppData\Roaming\Microsoft\Windows\Cookies\Low\marquelle@sales.liveperson[1].txt
C:\Users\marquelle\AppData\Roaming\Microsoft\Windows\Cookies\Low\marquelle@sales.liveperson[2].txt
C:\Users\marquelle\AppData\Roaming\Microsoft\Windows\Cookies\Low\marquelle@server.iad.liveperson[2].txt
C:\Users\marquelle\AppData\Roaming\Microsoft\Windows\Cookies\Low\marquelle@statcounter[1].txt
C:\Users\marquelle\AppData\Roaming\Microsoft\Windows\Cookies\Low\marquelle@stats.paypal[1].txt
C:\Users\marquelle\AppData\Roaming\Microsoft\Windows\Cookies\Low\marquelle@tacoda[2].txt
C:\Users\marquelle\AppData\Roaming\Microsoft\Windows\Cookies\Low\marquelle@www.googleadservices[1].txt
C:\Users\marquelle\AppData\Roaming\Microsoft\Windows\Cookies\Low\marquelle@www.googleadservices[2].txt
C:\Users\marquelle\Application Data\Microsoft\Windows\Cookies\Low\marquelle@a1.interclick[1].txt
C:\Users\marquelle\Application Data\Microsoft\Windows\Cookies\Low\marquelle@adopt.euroclick[2].txt
C:\Users\marquelle\Application Data\Microsoft\Windows\Cookies\Low\marquelle@ads.allaboutvision[2].txt
C:\Users\marquelle\Application Data\Microsoft\Windows\Cookies\Low\marquelle@ads.lucidmedia[1].txt
C:\Users\marquelle\Application Data\Microsoft\Windows\Cookies\Low\marquelle@ads.monster[1].txt
C:\Users\marquelle\Application Data\Microsoft\Windows\Cookies\Low\marquelle@cgm.adbureau[2].txt
C:\Users\marquelle\Application Data\Microsoft\Windows\Cookies\Low\marquelle@chitika[1].txt
C:\Users\marquelle\Application Data\Microsoft\Windows\Cookies\Low\marquelle@collective-media[1].txt
C:\Users\marquelle\Application Data\Microsoft\Windows\Cookies\Low\marquelle@e-2dj6wfk4cjczglp.stats.esomniture[1].txt
C:\Users\marquelle\Application Data\Microsoft\Windows\Cookies\Low\marquelle@e-2dj6wfk4qkdjifo.stats.esomniture[2].txt
C:\Users\marquelle\Application Data\Microsoft\Windows\Cookies\Low\marquelle@e-2dj6wfk4uocpiko.stats.esomniture[2].txt
C:\Users\marquelle\Application Data\Microsoft\Windows\Cookies\Low\marquelle@e-2dj6wfkyagc5elo.stats.esomniture[2].txt
C:\Users\marquelle\Application Data\Microsoft\Windows\Cookies\Low\marquelle@e-2dj6wfloujcjaeq.stats.esomniture[1].txt
C:\Users\marquelle\Application Data\Microsoft\Windows\Cookies\Low\marquelle@e-2dj6wgkyugczmlp.stats.esomniture[2].txt
C:\Users\marquelle\Application Data\Microsoft\Windows\Cookies\Low\marquelle@e-2dj6wgl4upcjolp.stats.esomniture[1].txt
C:\Users\marquelle\Application Data\Microsoft\Windows\Cookies\Low\marquelle@e-2dj6whk4qkcjiao.stats.esomniture[1].txt
C:\Users\marquelle\Application Data\Microsoft\Windows\Cookies\Low\marquelle@e-2dj6wjkosidjelp.stats.esomniture[2].txt
C:\Users\marquelle\Application Data\Microsoft\Windows\Cookies\Low\marquelle@e-2dj6wjkosjcjweo.stats.esomniture[2].txt
C:\Users\marquelle\Application Data\Microsoft\Windows\Cookies\Low\marquelle@e-2dj6wjkyshdzwbp.stats.esomniture[1].txt
C:\Users\marquelle\Application Data\Microsoft\Windows\Cookies\Low\marquelle@e-2dj6wjkyunczgeo.stats.esomniture[1].txt
C:\Users\marquelle\Application Data\Microsoft\Windows\Cookies\Low\marquelle@e-2dj6wjligkdzkbo.stats.esomniture[2].txt
C:\Users\marquelle\Application Data\Microsoft\Windows\Cookies\Low\marquelle@e-2dj6wjlysicjsgo.stats.esomniture[2].txt
C:\Users\marquelle\Application Data\Microsoft\Windows\Cookies\Low\marquelle@e-2dj6wjmiaic5ofo.stats.esomniture[2].txt
C:\Users\marquelle\Application Data\Microsoft\Windows\Cookies\Low\marquelle@e-2dj6wjny-1sczia.stats.esomniture[2].txt
C:\Users\marquelle\Application Data\Microsoft\Windows\Cookies\Low\marquelle@e-2dj6wjnyagdzkko.stats.esomniture[1].txt
C:\Users\marquelle\Application Data\Microsoft\Windows\Cookies\Low\marquelle@e-2dj6wjnyahc5olp.stats.esomniture[1].txt
C:\Users\marquelle\Application Data\Microsoft\Windows\Cookies\Low\marquelle@e-2dj6wmmiwncjsfo.stats.esomniture[1].txt
C:\Users\marquelle\Application Data\Microsoft\Windows\Cookies\Low\marquelle@insightexpressai[1].txt
C:\Users\marquelle\Application Data\Microsoft\Windows\Cookies\Low\marquelle@interclick[1].txt
C:\Users\marquelle\Application Data\Microsoft\Windows\Cookies\Low\marquelle@kontera[1].txt
C:\Users\marquelle\Application Data\Microsoft\Windows\Cookies\Low\marquelle@media6degrees[2].txt
C:\Users\marquelle\Application Data\Microsoft\Windows\Cookies\Low\marquelle@network.realmedia[1].txt
C:\Users\marquelle\Application Data\Microsoft\Windows\Cookies\Low\marquelle@oddcast[1].txt
C:\Users\marquelle\Application Data\Microsoft\Windows\Cookies\Low\marquelle@pinalcountyaz[1].txt
C:\Users\marquelle\Application Data\Microsoft\Windows\Cookies\Low\marquelle@questionpro[2].txt
C:\Users\marquelle\Application Data\Microsoft\Windows\Cookies\Low\marquelle@realmedia[1].txt
C:\Users\marquelle\Application Data\Microsoft\Windows\Cookies\Low\marquelle@revsci[2].txt
C:\Users\marquelle\Application Data\Microsoft\Windows\Cookies\Low\marquelle@richmedia.yahoo[2].txt
C:\Users\marquelle\Application Data\Microsoft\Windows\Cookies\Low\marquelle@sales.liveperson[1].txt
C:\Users\marquelle\Application Data\Microsoft\Windows\Cookies\Low\marquelle@sales.liveperson[2].txt
C:\Users\marquelle\Application Data\Microsoft\Windows\Cookies\Low\marquelle@server.iad.liveperson[2].txt
C:\Users\marquelle\Application Data\Microsoft\Windows\Cookies\Low\marquelle@statcounter[1].txt
C:\Users\marquelle\Application Data\Microsoft\Windows\Cookies\Low\marquelle@stats.paypal[1].txt
C:\Users\marquelle\Application Data\Microsoft\Windows\Cookies\Low\marquelle@tacoda[2].txt
C:\Users\marquelle\Application Data\Microsoft\Windows\Cookies\Low\marquelle@www.googleadservices[1].txt
C:\Users\marquelle\Application Data\Microsoft\Windows\Cookies\Low\marquelle@www.googleadservices[2].txt
C:\Users\marquelle\Cookies\Low\marquelle@a1.interclick[1].txt
C:\Users\marquelle\Cookies\Low\marquelle@adopt.euroclick[2].txt
C:\Users\marquelle\Cookies\Low\marquelle@ads.allaboutvision[2].txt
C:\Users\marquelle\Cookies\Low\marquelle@ads.lucidmedia[1].txt
C:\Users\marquelle\Cookies\Low\marquelle@ads.monster[1].txt
C:\Users\marquelle\Cookies\Low\marquelle@cgm.adbureau[2].txt
C:\Users\marquelle\Cookies\Low\marquelle@chitika[1].txt
C:\Users\marquelle\Cookies\Low\marquelle@collective-media[1].txt
C:\Users\marquelle\Cookies\Low\marquelle@e-2dj6wfk4cjczglp.stats.esomniture[1].txt
C:\Users\marquelle\Cookies\Low\marquelle@e-2dj6wfk4qkdjifo.stats.esomniture[2].txt
C:\Users\marquelle\Cookies\Low\marquelle@e-2dj6wfk4uocpiko.stats.esomniture[2].txt
C:\Users\marquelle\Cookies\Low\marquelle@e-2dj6wfkyagc5elo.stats.esomniture[2].txt
C:\Users\marquelle\Cookies\Low\marquelle@e-2dj6wfloujcjaeq.stats.esomniture[1].txt
C:\Users\marquelle\Cookies\Low\marquelle@e-2dj6wgkyugczmlp.stats.esomniture[2].txt
C:\Users\marquelle\Cookies\Low\marquelle@e-2dj6wgl4upcjolp.stats.esomniture[1].txt
C:\Users\marquelle\Cookies\Low\marquelle@e-2dj6whk4qkcjiao.stats.esomniture[1].txt
C:\Users\marquelle\Cookies\Low\marquelle@e-2dj6wjkosidjelp.stats.esomniture[2].txt
C:\Users\marquelle\Cookies\Low\marquelle@e-2dj6wjkosjcjweo.stats.esomniture[2].txt
C:\Users\marquelle\Cookies\Low\marquelle@e-2dj6wjkyshdzwbp.stats.esomniture[1].txt
C:\Users\marquelle\Cookies\Low\marquelle@e-2dj6wjkyunczgeo.stats.esomniture[1].txt
C:\Users\marquelle\Cookies\Low\marquelle@e-2dj6wjligkdzkbo.stats.esomniture[2].txt
C:\Users\marquelle\Cookies\Low\marquelle@e-2dj6wjlysicjsgo.stats.esomniture[2].txt
C:\Users\marquelle\Cookies\Low\marquelle@e-2dj6wjmiaic5ofo.stats.esomniture[2].txt
C:\Users\marquelle\Cookies\Low\marquelle@e-2dj6wjny-1sczia.stats.esomniture[2].txt
C:\Users\marquelle\Cookies\Low\marquelle@e-2dj6wjnyagdzkko.stats.esomniture[1].txt
C:\Users\marquelle\Cookies\Low\marquelle@e-2dj6wjnyahc5olp.stats.esomniture[1].txt
C:\Users\marquelle\Cookies\Low\marquelle@e-2dj6wmmiwncjsfo.stats.esomniture[1].txt
C:\Users\marquelle\Cookies\Low\marquelle@insightexpressai[1].txt
C:\Users\marquelle\Cookies\Low\marquelle@interclick[1].txt
C:\Users\marquelle\Cookies\Low\marquelle@kontera[1].txt
C:\Users\marquelle\Cookies\Low\marquelle@media6degrees[2].txt
C:\Users\marquelle\Cookies\Low\marquelle@network.realmedia[1].txt
C:\Users\marquelle\Cookies\Low\marquelle@oddcast[1].txt
C:\Users\marquelle\Cookies\Low\marquelle@pinalcountyaz[1].txt
C:\Users\marquelle\Cookies\Low\marquelle@questionpro[2].txt
C:\Users\marquelle\Cookies\Low\marquelle@realmedia[1].txt
C:\Users\marquelle\Cookies\Low\marquelle@revsci[2].txt
C:\Users\marquelle\Cookies\Low\marquelle@richmedia.yahoo[2].txt
C:\Users\marquelle\Cookies\Low\marquelle@sales.liveperson[1].txt
C:\Users\marquelle\Cookies\Low\marquelle@sales.liveperson[2].txt
C:\Users\marquelle\Cookies\Low\marquelle@server.iad.liveperson[2].txt
C:\Users\marquelle\Cookies\Low\marquelle@statcounter[1].txt
C:\Users\marquelle\Cookies\Low\marquelle@stats.paypal[1].txt
C:\Users\marquelle\Cookies\Low\marquelle@tacoda[2].txt
C:\Users\marquelle\Cookies\Low\marquelle@www.googleadservices[1].txt
C:\Users\marquelle\Cookies\Low\marquelle@www.googleadservices[2].txt

Trojan.Dropper/Gen
C:\USERS\MARQUELLE\APPDATA\LOCAL\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\TEMPORARY INTERNET FILES\VIRTUALIZED\C\USERS\MARQUELLE\APPDATA\LOCAL\MICROSOFT\WINDOWS\BURN\BURN\GWSCAN.EXE
C:\USERS\MARQUELLE\APPDATA\LOCAL\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\TEMPORARY INTERNET FILES\VIRTUALIZED\C\USERS\MARQUELLE\APPDATA\LOCAL\MICROSOFT\WINDOWS\BURN\BURN\GWSCAN.EXE
C:\USERS\MARQUELLE\APPDATA\LOCAL\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\MICROSOFT\WINDOWS\TEMPORARY INTERNET FILES\VIRTUALIZED\C\USERS\MARQUELLE\APPDATA\LOCAL\MICROSOFT\WINDOWS\BURN\BURN\GWSCAN.EXE
C:\USERS\MARQUELLE\APPDATA\LOCAL\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\TEMPORARY INTERNET FILES\VIRTUALIZED\C\USERS\MARQUELLE\APPDATA\LOCAL\MICROSOFT\WINDOWS\BURN\BURN\GWSCAN.EXE
C:\USERS\MARQUELLE\APPDATA\LOCAL\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\MICROSOFT\WINDOWS\TEMPORARY INTERNET FILES\VIRTUALIZED\C\USERS\MARQUELLE\APPDATA\LOCAL\MICROSOFT\WINDOWS\BURN\BURN\GWSCAN.EXE
C:\USERS\MARQUELLE\APPDATA\LOCAL\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\TEMPORARY INTERNET FILES\VIRTUALIZED\C\USERS\MARQUELLE\APPDATA\LOCAL\MICROSOFT\WINDOWS\BURN\BURN\GWSCAN.EXE
C:\USERS\MARQUELLE\APPDATA\LOCAL\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\MICROSOFT\WINDOWS\TEMPORARY INTERNET FILES\VIRTUALIZED\C\USERS\MARQUELLE\APPDATA\LOCAL\MICROSOFT\WINDOWS\BURN\BURN\GWSCAN.EXE
C:\USERS\MARQUELLE\APPDATA\LOCAL\APPLICATION DATA\APPLICATION DATA\APPLICATION DATA\TEMPORARY INTERNET FILES\VIRTUALIZED\C\USERS\MARQUELLE\APPDATA\LOCAL\MICROSOFT\WINDOWS\BURN\BURN\GWSCAN.EXE
C:\USERS\MARQUELLE\APPDATA\LOCAL\APPLICATION DATA\APPLICATION DATA\MICROSOFT\WINDOWS\TEMPORARY INTERNET FILES\VIRTUALIZED\C\USERS\MARQUELLE\APPDATA\LOCAL\MICROSOFT\WINDOWS\BURN\BURN\GWSCAN.EXE
C:\USERS\MARQUELLE\APPDATA\LOCAL\APPLICATION DATA\APPLICATION DATA\TEMPORARY INTERNET FILES\VIRTUALIZED\C\USERS\MARQUELLE\APPDATA\LOCAL\MICROSOFT\WINDOWS\BURN\BURN\GWSCAN.EXE
C:\USERS\MARQUELLE\APPDATA\LOCAL\APPLICATION DATA\MICROSOFT\WINDOWS\TEMPORARY INTERNET FILES\VIRTUALIZED\C\USERS\MARQUELLE\APPDATA\LOCAL\MICROSOFT\WINDOWS\BURN\BURN\GWSCAN.EXE
C:\USERS\MARQUELLE\APPDATA\LOCAL\APPLICATION DATA\TEMPORARY INTERNET FILES\VIRTUALIZED\C\USERS\MARQUELLE\APPDATA\LOCAL\MICROSOFT\WINDOWS\BURN\BURN\GWSCAN.EXE
C:\USERS\MARQUELLE\APPDATA\LOCAL\MICROSOFT\WINDOWS\TEMPORARY INTERNET FILES\VIRTUALIZED\C\USERS\MARQUELLE\APPDATA\LOCAL\MICROSOFT\WINDOWS\BURN\BURN\GWSCAN.EXE
C:\USERS\MARQUELLE\APPDATA\LOCAL\TEMPORARY INTERNET FILES\VIRTUALIZED\C\USERS\MARQUELLE\APPDATA\LOCAL\MICROSOFT\WINDOWS\BURN\BURN\GWSCAN.EXE




0 user(s) are reading this topic

0 members, 0 guests, 0 anonymous users