Jump to content


 


Register a free account to unlock additional features at BleepingComputer.com
Welcome to BleepingComputer, a free community where people like yourself come together to discuss and learn how to use their computers. Using the site is easy and fun. As a guest, you can browse and view the various discussions in the forums, but can not create a new topic or reply to an existing one unless you are logged in. Other benefits of registering an account are subscribing to topics and forums, creating a blog, and having no ads shown anywhere on the site.


Click here to Register a free account now! or read our Welcome Guide to learn how to use this site.

Photo

Several programs will not run.


  • Please log in to reply
6 replies to this topic

#1 dodgechargerfan

dodgechargerfan

  • Members
  • 74 posts
  • OFFLINE
  •  
  • Gender:Male
  • Local time:03:17 AM

Posted 25 April 2009 - 09:44 AM

My Vista PC will not run several programs since booting up this morning.

Programs that will not run:
firefox - it shows up in Process Explorer, but never launches. Trying to launch it again results in another process entry, but still no launch
F-Secure Anti-virus scan - the user interface for the suite works, but trying to launch a scan results in a process starting and then stopping. I am using Process Explorer to view processes.
Intel Desktop Utilities tray ion allows me to try to launch the Desktop utility app, but that app just results in a process starting, but no actual launch - same results as firefox (I was just trying to launch this tool to see if it would or not.)
Windows SecurityCenter will not launch - I get rundll32 errors
Safari will open up but does not connect at all

Right now, I am accessing the Internet via my work PC (on another network).

I was able to download the latest mbam and run it on my home PC. I burned the file and the rules update to a CD.

A quick scan showed two Regisrty Data Items Infected:
HKEY_CLASSES_ROOT\srcfile\shell\open\command\ (broken.OpenCommand) -> Bad: (NOTEPAD.EXE %1) Good: ("%1" /S) -> No action taken.
HKEY_CLASSES_ROOT\regfile\shell\open\command\ (broken.OpenCommand) -> Bad: (NOTEPAD.EXE %1) Good: (regedit.exe "%1") -> No action taken.

From what I understand, this is more of a "glitch" in MalwareBytes than it is an infection. I let Malwarebytes fix it by clicking Remove.
http://www.malwarebytes.org/forums/index.php?showtopic=6195

I'm rebooting right now.

Edited by dodgechargerfan, 25 April 2009 - 09:52 AM.


BC AdBot (Login to Remove)

 


#2 DaChew

DaChew

    Visiting Alien


  • BC Advisor
  • 10,317 posts
  • OFFLINE
  •  
  • Gender:Male
  • Location:millenium falcon and rockytop
  • Local time:03:17 AM

Posted 25 April 2009 - 10:21 AM

From what I understand, this is more of a "glitch" in MalwareBytes than it is an infection. I let Malwarebytes fix it by clicking Remove.
http://www.malwarebytes.org/forums/index.php?showtopic=6195


I had none of your symptoms when I started that thread

Post the entire MBAM log please

How are you bringing back the

HKEY_CLASSES_ROOT\srcfile\shell\open\command\ (broken.OpenCommand) -> Bad: (NOTEPAD.EXE %1) Good: ("%1" /S) -> No action taken.
HKEY_CLASSES_ROOT\regfile\shell\open\command\ (broken.OpenCommand) -> Bad: (NOTEPAD.EXE %1) Good: (regedit.exe "%1") -> No action taken.


from the infected computer?
Chewy

No. Try not. Do... or do not. There is no try.

#3 dodgechargerfan

dodgechargerfan
  • Topic Starter

  • Members
  • 74 posts
  • OFFLINE
  •  
  • Gender:Male
  • Local time:03:17 AM

Posted 25 April 2009 - 10:30 AM

Understood regarding the symptoms. I just searched on the message given in the report to understand what the message meant.

I didn't post the whole log, because it is on the infected PC and I am reluctant to plug in a flash drive or burn from that machine at this point.
I typed those messages in manually.

#4 dodgechargerfan

dodgechargerfan
  • Topic Starter

  • Members
  • 74 posts
  • OFFLINE
  •  
  • Gender:Male
  • Local time:03:17 AM

Posted 25 April 2009 - 10:38 AM

Seems the reboot cleared the symptoms up, but I still want to be sure the system is clean.

to start: I'm gong to run a full scan in mbam.

#5 DaChew

DaChew

    Visiting Alien


  • BC Advisor
  • 10,317 posts
  • OFFLINE
  •  
  • Gender:Male
  • Location:millenium falcon and rockytop
  • Local time:03:17 AM

Posted 25 April 2009 - 10:41 AM

I am reluctant to plug in a flash drive or burn from that machine at this point.
I typed those messages in manually.


That's very good

Let's apply a safeguard to the clean computer and a usb drive

This will not prevent an infection from infected files on the usb drive but will prevent any autorun/autoplay from infecting the clean computer when accessing txt logs from the infected one.

As a matter of fact the thread you found was a remnant of an infection I got last summer opening a log file I was moving from an infected computer to mine so I could post online

Please download Flash_Disinfector.exe by sUBs and save it to your desktop.
  • Double-click Flash_Disinfector.exe to run it and follow any prompts that may appear.
  • The utility may ask you to insert your flash drive and/or other removable drives. Please do so and allow the utility to clean up those drives as well.
  • Hold down the Shift key when inserting the drive until Windows detects it to keep autorun.inf from executing if it is present.
  • Wait until it has finished scanning and then exit the program.
  • Reboot your computer when done.
Note: As part of its routine, Flash_Disinfector will create a hidden folder named autorun.inf in each partition and every USB drive that was plugged in when you ran it. Do not delete this folder...it will help protect your drives from future infection by keeping the autorun file from being installed on the root drive and running other malicious files.
Chewy

No. Try not. Do... or do not. There is no try.

#6 DaChew

DaChew

    Visiting Alien


  • BC Advisor
  • 10,317 posts
  • OFFLINE
  •  
  • Gender:Male
  • Location:millenium falcon and rockytop
  • Local time:03:17 AM

Posted 25 April 2009 - 10:52 AM

Please download ATF Cleaner by Atribune & save it to your desktop.
  • Double-click ATF-Cleaner.exe to run the program.
  • Under Main "Select Files to Delete" choose: Select All.
  • Click the Empty Selected button.
  • If you use Firefox browser click Firefox at the top and choose: Select All
  • Click the Empty Selected button.
    If you would like to keep your saved passwords, please click No at the prompt.
  • If you use Opera browser click Opera at the top and choose: Select All
  • Click the Empty Selected button.
    If you would like to keep your saved passwords, please click No at the prompt.
  • Click Exit on the Main menu to close the program.
Note: On Vista, "Windows Temp" is disabled. To empty "Windows Temp" ATF-Cleaner must be "Run as an Administrator".


Please download and scan with SUPERAntiSpyware Free
  • Double-click SUPERAntiSypware.exe and use the default settings for installation.
  • An icon will be created on your desktop. Double-click that icon to launch the program.
  • If asked to update the program definitions, click "Yes". If not, update the definitions before scanning by selecting "Check for Updates". (If you encounter any problems while downloading the updates, manually download them from here. Double-click on the hyperlink for Download Installer and save SASDEFINITIONS.EXE to your desktop. Then double-click on SASDEFINITIONS.EXE to install the definitions.)
  • In the Main Menu, click the Preferences... button.
  • Click the "General and Startup" tab, and under Start-up Options, make sure "Start SUPERAntiSpyware when Windows starts" box is unchecked.
  • Click the "Scanning Control" tab, and under Scanner Options, make sure the following are checked (leave all others unchecked):
    • Close browsers before scanning.
    • Scan for tracking cookies.
    • Terminate memory threats before quarantining.
  • Click the "Close" button to leave the control center screen and exit the program.
  • Do not run a scan just yet.
Reboot your computer in "Safe Mode" using the F8 method. To do this, restart your computer and after hearing your computer beep once during startup (but before the Windows icon appears) press the F8 key repeatedly. A menu will appear with several options. Use the arrow keys to navigate and select the option to run Windows in "Safe Mode".

Scan with SUPERAntiSpyware as follows:
  • Launch the program and back on the main screen, under "Scan for Harmful Software" click Scan your computer.
  • On the left, make sure you check C:\Fixed Drive.
  • On the right, under "Complete Scan", choose Perform Complete Scan and click "Next".
  • After the scan is complete, a Scan Summary box will appear with potentially harmful items that were detected. Click "OK".
  • Make sure everything has a checkmark next to it and click "Next".
  • A notification will appear that "Quarantine and Removal is Complete". Click "OK" and then click the "Finish" button to return to the main menu.
  • If asked if you want to reboot, click "Yes" and reboot normally.
  • To retrieve the removal information after reboot, launch SUPERAntispyware again.
    • Click Preferences, then click the Statistics/Logs tab.
    • Under Scanner Logs, double-click SUPERAntiSpyware Scan Log.
    • If there are several logs, click the current dated log and press View log. A text file will open in your default text editor.
    • Please copy and paste the Scan Log results in your next reply.
  • Click Close to exit the program.

Chewy

No. Try not. Do... or do not. There is no try.

#7 dodgechargerfan

dodgechargerfan
  • Topic Starter

  • Members
  • 74 posts
  • OFFLINE
  •  
  • Gender:Male
  • Local time:03:17 AM

Posted 25 April 2009 - 06:54 PM

Done!

Just tracking cookies were found.

As mentioned before, the symptoms with certain programs not running are cleared up now.

but here's the SAS log .

SUPERAntiSpyware Scan Log
http://www.superantispyware.com

Generated 04/25/2009 at 06:38 PM

Application Version : 4.26.1000

Core Rules Database Version : 3843
Trace Rules Database Version: 1798

Scan type : Complete Scan
Total Scan Time : 04:39:58

Memory items scanned : 293
Memory threats detected : 0
Registry items scanned : 9803
Registry threats detected : 0
File items scanned : 488488
File threats detected : 137

Adware.Tracking Cookie
C:\Users\Dave\AppData\Roaming\Microsoft\Windows\Cookies\dave@atdmt[1].txt
C:\Users\Dave\AppData\Roaming\Microsoft\Windows\Cookies\dave@2o7[2].txt
C:\Users\Dave\AppData\Roaming\Microsoft\Windows\Cookies\Low\dave@3.adbrite[1].txt
C:\Users\Dave\AppData\Roaming\Microsoft\Windows\Cookies\Low\dave@adcache.collectorcartraderonline[2].txt
C:\Users\Dave\AppData\Roaming\Microsoft\Windows\Cookies\Low\dave@adcentriconline[1].txt
C:\Users\Dave\AppData\Roaming\Microsoft\Windows\Cookies\Low\dave@adecn[1].txt
C:\Users\Dave\AppData\Roaming\Microsoft\Windows\Cookies\Low\dave@adlegend[2].txt
C:\Users\Dave\AppData\Roaming\Microsoft\Windows\Cookies\Low\dave@adopt.euroclick[2].txt
C:\Users\Dave\AppData\Roaming\Microsoft\Windows\Cookies\Low\dave@adopt.specificclick[1].txt
C:\Users\Dave\AppData\Roaming\Microsoft\Windows\Cookies\Low\dave@adrevolver[1].txt
C:\Users\Dave\AppData\Roaming\Microsoft\Windows\Cookies\Low\dave@ads.adbrite[2].txt
C:\Users\Dave\AppData\Roaming\Microsoft\Windows\Cookies\Low\dave@ads.ak.facebook[1].txt
C:\Users\Dave\AppData\Roaming\Microsoft\Windows\Cookies\Low\dave@ads.as4x.tmcs.ticketmaster[2].txt
C:\Users\Dave\AppData\Roaming\Microsoft\Windows\Cookies\Low\dave@ads.as4x.tmcs[1].txt
C:\Users\Dave\AppData\Roaming\Microsoft\Windows\Cookies\Low\dave@ads.associatedcontent[1].txt
C:\Users\Dave\AppData\Roaming\Microsoft\Windows\Cookies\Low\dave@ads.auctionads[1].txt
C:\Users\Dave\AppData\Roaming\Microsoft\Windows\Cookies\Low\dave@ads.cnn[2].txt
C:\Users\Dave\AppData\Roaming\Microsoft\Windows\Cookies\Low\dave@ads.jpgmag[1].txt
C:\Users\Dave\AppData\Roaming\Microsoft\Windows\Cookies\Low\dave@ads.labpixies[1].txt
C:\Users\Dave\AppData\Roaming\Microsoft\Windows\Cookies\Low\dave@ads.mediamayhemcorp[1].txt
C:\Users\Dave\AppData\Roaming\Microsoft\Windows\Cookies\Low\dave@ads.movieweb[2].txt
C:\Users\Dave\AppData\Roaming\Microsoft\Windows\Cookies\Low\dave@ads.onemedianetwork[1].txt
C:\Users\Dave\AppData\Roaming\Microsoft\Windows\Cookies\Low\dave@ads.planetactive[1].txt
C:\Users\Dave\AppData\Roaming\Microsoft\Windows\Cookies\Low\dave@ads.pointroll[2].txt
C:\Users\Dave\AppData\Roaming\Microsoft\Windows\Cookies\Low\dave@ads.revsci[1].txt
C:\Users\Dave\AppData\Roaming\Microsoft\Windows\Cookies\Low\dave@ads.sun[1].txt
C:\Users\Dave\AppData\Roaming\Microsoft\Windows\Cookies\Low\dave@ads.techguy[1].txt
C:\Users\Dave\AppData\Roaming\Microsoft\Windows\Cookies\Low\dave@ads.travelonly[2].txt
C:\Users\Dave\AppData\Roaming\Microsoft\Windows\Cookies\Low\dave@adv.surinter[2].txt
C:\Users\Dave\AppData\Roaming\Microsoft\Windows\Cookies\Low\dave@advertising[2].txt
C:\Users\Dave\AppData\Roaming\Microsoft\Windows\Cookies\Low\dave@affiliate.wordtracker[2].txt
C:\Users\Dave\AppData\Roaming\Microsoft\Windows\Cookies\Low\dave@alamo-push.worldmedia[1].txt
C:\Users\Dave\AppData\Roaming\Microsoft\Windows\Cookies\Low\dave@alamocanusa-push.worldmedia[1].txt
C:\Users\Dave\AppData\Roaming\Microsoft\Windows\Cookies\Low\dave@anad.tacoda[2].txt
C:\Users\Dave\AppData\Roaming\Microsoft\Windows\Cookies\Low\dave@apmebf[2].txt
C:\Users\Dave\AppData\Roaming\Microsoft\Windows\Cookies\Low\dave@app.insightgrit[1].txt
C:\Users\Dave\AppData\Roaming\Microsoft\Windows\Cookies\Low\dave@atwola[1].txt
C:\Users\Dave\AppData\Roaming\Microsoft\Windows\Cookies\Low\dave@audit.median[1].txt
C:\Users\Dave\AppData\Roaming\Microsoft\Windows\Cookies\Low\dave@banners.nbcupromotes[1].txt
C:\Users\Dave\AppData\Roaming\Microsoft\Windows\Cookies\Low\dave@burstnet[2].txt
C:\Users\Dave\AppData\Roaming\Microsoft\Windows\Cookies\Low\dave@CAIHTEKQ.txt
C:\Users\Dave\AppData\Roaming\Microsoft\Windows\Cookies\Low\dave@canadiansponsors.directtrack[2].txt
C:\Users\Dave\AppData\Roaming\Microsoft\Windows\Cookies\Low\dave@centralmediaserver[1].txt
C:\Users\Dave\AppData\Roaming\Microsoft\Windows\Cookies\Low\dave@cioinsight[1].txt
C:\Users\Dave\AppData\Roaming\Microsoft\Windows\Cookies\Low\dave@clickaider[1].txt
C:\Users\Dave\AppData\Roaming\Microsoft\Windows\Cookies\Low\dave@clicklab.pctools[1].txt
C:\Users\Dave\AppData\Roaming\Microsoft\Windows\Cookies\Low\dave@collective-media[2].txt
C:\Users\Dave\AppData\Roaming\Microsoft\Windows\Cookies\Low\dave@counter.surfcounters[1].txt
C:\Users\Dave\AppData\Roaming\Microsoft\Windows\Cookies\Low\dave@cpvfeed[2].txt
C:\Users\Dave\AppData\Roaming\Microsoft\Windows\Cookies\Low\dave@crackedeggstudios[2].txt
C:\Users\Dave\AppData\Roaming\Microsoft\Windows\Cookies\Low\dave@ct.enews.cioinsight[1].txt
C:\Users\Dave\AppData\Roaming\Microsoft\Windows\Cookies\Low\dave@discountedorfree[1].txt
C:\Users\Dave\AppData\Roaming\Microsoft\Windows\Cookies\Low\dave@e-2dj6wjmykndjggo.stats.esomniture[2].txt
C:\Users\Dave\AppData\Roaming\Microsoft\Windows\Cookies\Low\dave@easytimetracking[2].txt
C:\Users\Dave\AppData\Roaming\Microsoft\Windows\Cookies\Low\dave@ehg-nfusiongroup.hitbox[2].txt
C:\Users\Dave\AppData\Roaming\Microsoft\Windows\Cookies\Low\dave@ehg-oreilly.hitbox[2].txt
C:\Users\Dave\AppData\Roaming\Microsoft\Windows\Cookies\Low\dave@ehg-researchinmotion.hitbox[2].txt
C:\Users\Dave\AppData\Roaming\Microsoft\Windows\Cookies\Low\dave@ehg-uniontrib.hitbox[2].txt
C:\Users\Dave\AppData\Roaming\Microsoft\Windows\Cookies\Low\dave@ehg-valueclickmedia.hitbox[1].txt
C:\Users\Dave\AppData\Roaming\Microsoft\Windows\Cookies\Low\dave@ehg.hitbox[2].txt
C:\Users\Dave\AppData\Roaming\Microsoft\Windows\Cookies\Low\dave@fastclick[1].txt
C:\Users\Dave\AppData\Roaming\Microsoft\Windows\Cookies\Low\dave@findaperson.canada-411[1].txt
C:\Users\Dave\AppData\Roaming\Microsoft\Windows\Cookies\Low\dave@findaperson.canada411[1].txt
C:\Users\Dave\AppData\Roaming\Microsoft\Windows\Cookies\Low\dave@ford.112.2o7[1].txt
C:\Users\Dave\AppData\Roaming\Microsoft\Windows\Cookies\Low\dave@h.starware[1].txt
C:\Users\Dave\AppData\Roaming\Microsoft\Windows\Cookies\Low\dave@holidayinsights[1].txt
C:\Users\Dave\AppData\Roaming\Microsoft\Windows\Cookies\Low\dave@homestore.122.2o7[1].txt
C:\Users\Dave\AppData\Roaming\Microsoft\Windows\Cookies\Low\dave@hypertracker[1].txt
C:\Users\Dave\AppData\Roaming\Microsoft\Windows\Cookies\Low\dave@iad.liveperson[1].txt
C:\Users\Dave\AppData\Roaming\Microsoft\Windows\Cookies\Low\dave@imrworldwide[2].txt
C:\Users\Dave\AppData\Roaming\Microsoft\Windows\Cookies\Low\dave@indexstats[2].txt
C:\Users\Dave\AppData\Roaming\Microsoft\Windows\Cookies\Low\dave@insightexpressai[1].txt
C:\Users\Dave\AppData\Roaming\Microsoft\Windows\Cookies\Low\dave@interclick[2].txt
C:\Users\Dave\AppData\Roaming\Microsoft\Windows\Cookies\Low\dave@itxt.vibrantmedia[1].txt
C:\Users\Dave\AppData\Roaming\Microsoft\Windows\Cookies\Low\dave@iview-multimedia[1].txt
C:\Users\Dave\AppData\Roaming\Microsoft\Windows\Cookies\Low\dave@kmpads[1].txt
C:\Users\Dave\AppData\Roaming\Microsoft\Windows\Cookies\Low\dave@livedealcom.112.2o7[1].txt
C:\Users\Dave\AppData\Roaming\Microsoft\Windows\Cookies\Low\dave@media-partners[1].txt
C:\Users\Dave\AppData\Roaming\Microsoft\Windows\Cookies\Low\dave@media.cardomain[1].txt
C:\Users\Dave\AppData\Roaming\Microsoft\Windows\Cookies\Low\dave@media6.sitebrand[2].txt
C:\Users\Dave\AppData\Roaming\Microsoft\Windows\Cookies\Low\dave@medialearner.directtrack[1].txt
C:\Users\Dave\AppData\Roaming\Microsoft\Windows\Cookies\Low\dave@medialearner[1].txt
C:\Users\Dave\AppData\Roaming\Microsoft\Windows\Cookies\Low\dave@metareward[1].txt
C:\Users\Dave\AppData\Roaming\Microsoft\Windows\Cookies\Low\dave@microsoftuk.122.2o7[1].txt
C:\Users\Dave\AppData\Roaming\Microsoft\Windows\Cookies\Low\dave@mycounter.tinycounter[2].txt
C:\Users\Dave\AppData\Roaming\Microsoft\Windows\Cookies\Low\dave@mystat.synch[1].txt
C:\Users\Dave\AppData\Roaming\Microsoft\Windows\Cookies\Low\dave@nextag[2].txt
C:\Users\Dave\AppData\Roaming\Microsoft\Windows\Cookies\Low\dave@oasc04.247realmedia[1].txt
C:\Users\Dave\AppData\Roaming\Microsoft\Windows\Cookies\Low\dave@oddcast[2].txt
C:\Users\Dave\AppData\Roaming\Microsoft\Windows\Cookies\Low\dave@primedia.us.intellitxt[1].txt
C:\Users\Dave\AppData\Roaming\Microsoft\Windows\Cookies\Low\dave@puretracks[1].txt
C:\Users\Dave\AppData\Roaming\Microsoft\Windows\Cookies\Low\dave@questionpro[1].txt
C:\Users\Dave\AppData\Roaming\Microsoft\Windows\Cookies\Low\dave@questionpro[2].txt
C:\Users\Dave\AppData\Roaming\Microsoft\Windows\Cookies\Low\dave@richmedia.yahoo[1].txt
C:\Users\Dave\AppData\Roaming\Microsoft\Windows\Cookies\Low\dave@sales.liveperson[1].txt
C:\Users\Dave\AppData\Roaming\Microsoft\Windows\Cookies\Low\dave@sales.liveperson[2].txt
C:\Users\Dave\AppData\Roaming\Microsoft\Windows\Cookies\Low\dave@sales.liveperson[4].txt
C:\Users\Dave\AppData\Roaming\Microsoft\Windows\Cookies\Low\dave@sales.liveperson[5].txt
C:\Users\Dave\AppData\Roaming\Microsoft\Windows\Cookies\Low\dave@saletrack.co[1].txt
C:\Users\Dave\AppData\Roaming\Microsoft\Windows\Cookies\Low\dave@sdc.krollontrack[2].txt
C:\Users\Dave\AppData\Roaming\Microsoft\Windows\Cookies\Low\dave@server.cpmstar[2].txt
C:\Users\Dave\AppData\Roaming\Microsoft\Windows\Cookies\Low\dave@serving-sys[1].txt
C:\Users\Dave\AppData\Roaming\Microsoft\Windows\Cookies\Low\dave@sexpistols[1].txt
C:\Users\Dave\AppData\Roaming\Microsoft\Windows\Cookies\Low\dave@sleepcountry[2].txt
C:\Users\Dave\AppData\Roaming\Microsoft\Windows\Cookies\Low\dave@software.visicommedia[2].txt
C:\Users\Dave\AppData\Roaming\Microsoft\Windows\Cookies\Low\dave@soundclick[1].txt
C:\Users\Dave\AppData\Roaming\Microsoft\Windows\Cookies\Low\dave@stats.chooseyouritem[2].txt
C:\Users\Dave\AppData\Roaming\Microsoft\Windows\Cookies\Low\dave@stats.manticoretechnology[1].txt
C:\Users\Dave\AppData\Roaming\Microsoft\Windows\Cookies\Low\dave@t3.trackalyzer[1].txt
C:\Users\Dave\AppData\Roaming\Microsoft\Windows\Cookies\Low\dave@tabletquestions[1].txt
C:\Users\Dave\AppData\Roaming\Microsoft\Windows\Cookies\Low\dave@track.bestbuy[2].txt
C:\Users\Dave\AppData\Roaming\Microsoft\Windows\Cookies\Low\dave@tracking.foxnews[2].txt
C:\Users\Dave\AppData\Roaming\Microsoft\Windows\Cookies\Low\dave@try.starware[2].txt
C:\Users\Dave\AppData\Roaming\Microsoft\Windows\Cookies\Low\dave@vhost.oddcast[2].txt
C:\Users\Dave\AppData\Roaming\Microsoft\Windows\Cookies\Low\dave@www.3dstats[1].txt
C:\Users\Dave\AppData\Roaming\Microsoft\Windows\Cookies\Low\dave@www.addfreestats[1].txt
C:\Users\Dave\AppData\Roaming\Microsoft\Windows\Cookies\Low\dave@www.burstbeacon[2].txt
C:\Users\Dave\AppData\Roaming\Microsoft\Windows\Cookies\Low\dave@www.charger01foster.tripod[1].txt
C:\Users\Dave\AppData\Roaming\Microsoft\Windows\Cookies\Low\dave@www.cioinsight[1].txt
C:\Users\Dave\AppData\Roaming\Microsoft\Windows\Cookies\Low\dave@www.county.oxford.on[2].txt
C:\Users\Dave\AppData\Roaming\Microsoft\Windows\Cookies\Low\dave@www.discountcasinogear[2].txt
C:\Users\Dave\AppData\Roaming\Microsoft\Windows\Cookies\Low\dave@www.discountedwheelwarehouse[2].txt
C:\Users\Dave\AppData\Roaming\Microsoft\Windows\Cookies\Low\dave@www.elite-auto[1].txt
C:\Users\Dave\AppData\Roaming\Microsoft\Windows\Cookies\Low\dave@www.findcars[1].txt
C:\Users\Dave\AppData\Roaming\Microsoft\Windows\Cookies\Low\dave@www.googleadservices[1].txt
C:\Users\Dave\AppData\Roaming\Microsoft\Windows\Cookies\Low\dave@www.googleadservices[2].txt
C:\Users\Dave\AppData\Roaming\Microsoft\Windows\Cookies\Low\dave@www.googleadservices[4].txt
C:\Users\Dave\AppData\Roaming\Microsoft\Windows\Cookies\Low\dave@www.googleadservices[5].txt
C:\Users\Dave\AppData\Roaming\Microsoft\Windows\Cookies\Low\dave@www.googleadservices[6].txt
C:\Users\Dave\AppData\Roaming\Microsoft\Windows\Cookies\Low\dave@www.googleadservices[9].txt
C:\Users\Dave\AppData\Roaming\Microsoft\Windows\Cookies\Low\dave@www.media-partners[1].txt
C:\Users\Dave\AppData\Roaming\Microsoft\Windows\Cookies\Low\dave@www.puretracks[1].txt
C:\Users\Dave\AppData\Roaming\Microsoft\Windows\Cookies\Low\dave@www.tabletquestions[2].txt
C:\Users\Dave\AppData\Roaming\Microsoft\Windows\Cookies\Low\dave@www2.addfreestats[1].txt
C:\Users\Dave\AppData\Roaming\Microsoft\Windows\Cookies\Low\dave@www8.addfreestats[1].txt
C:\Users\Dave\AppData\Roaming\Microsoft\Windows\Cookies\Low\dave@xiti[1].txt
C:\Users\Dave\AppData\Roaming\Microsoft\Windows\Cookies\Low\dave@yadro[1].txt




0 user(s) are reading this topic

0 members, 0 guests, 0 anonymous users