Jump to content


 


Register a free account to unlock additional features at BleepingComputer.com
Welcome to BleepingComputer, a free community where people like yourself come together to discuss and learn how to use their computers. Using the site is easy and fun. As a guest, you can browse and view the various discussions in the forums, but can not create a new topic or reply to an existing one unless you are logged in. Other benefits of registering an account are subscribing to topics and forums, creating a blog, and having no ads shown anywhere on the site.


Click here to Register a free account now! or read our Welcome Guide to learn how to use this site.

Photo

Adware Pro


  • Please log in to reply
15 replies to this topic

#1 dto

dto

  • Members
  • 19 posts
  • OFFLINE
  •  
  • Local time:12:35 AM

Posted 22 December 2009 - 10:28 PM

Hi Bleeping Computer. You guys helped my tackle down the antivirus 360 last year and now this year I'm not sure if I have a problem or not. My dad recently downloaded "Adware Pro", made by Voltron. I was suspicious because I have never heard of it. He said he got it from updating Ad-Aware. Now I removed it using the control panel but, is uncertain if I got all of it. My computer is running normal but, I just want to take some precautions. Thanks - Dustin

BC AdBot (Login to Remove)

 


#2 Computer Pro

Computer Pro

  • Members
  • 2,448 posts
  • OFFLINE
  •  
  • Gender:Male
  • Local time:12:35 AM

Posted 22 December 2009 - 10:31 PM

Hello and welcome to Bleeping Computer. My name is Computer Pro and I will be helping you with your issues.

Please subscribe to your topic so that you will be notified as soon as I post a reply, instead of you having to check the topic all of the time. This will allow you to get an email notification when I reply.

To subscribe, go to your topic, and at the top right hand corner by your first post, click the Options button and then click Track this topic. Then bullet the immediate notification bubble. Finally, press submit.


I did some research and Adware Pro is a rogue (fake) application. Let's run Malwarebytes to make sure that you got it all.

Lets take a look with Malwarebytes

Please download Malwarebytes' Anti-Malware from here:
Malwarebytes
Please rename the file BEFORE downloading to zztoy.exe instead of mbam-setup.exe

MBAM may "make changes to your registry" as part of its disinfection routine. If using other security programs that detect registry changes (ie Spybot's Teatimer), they may interfere or alert you. Temporarily disable such programs or permit them to allow the changes.

Double Click zztoy.exe to install the application.
* Make sure a checkmark is placed next to Update Malwarebytes' Anti-Malware and Launch Malwarebytes' Anti-Malware, then click Finish.
* If an update is found, it will download and install the latest version.
* Once the program has loaded, select "Perform Full Scan", then click Scan.
* The scan may take some time to finish,so please be patient.
* When the scan is complete, click OK, then Show Results to view the results.
* Make sure that everything is checked, and click Remove Selected.
* When disinfection is completed, a log will open in Notepad and you may be prompted to Restart.(See Extra Note)
* The log is automatically saved by MBAM and can be viewed by clicking the Logs tab in MBAM.
* Copy&Paste the entire MBAM report (even if it does not find anything) in your next reply

Extra Note:
If MBAM encounters a file that is difficult to remove,you will be presented with 1 of 2 prompts,click OK to either and let MBAM proceed with the disinfection process, if asked to restart the computer, please do so immediately.


If Malwarebytes won't install or run

Some types of malware will disable MBAM and other security tools. If MBAM will not install, try renaming it. Right-click on the mbam-setup.exe file and change the .exe extension to .bat, .com, .pif, or .scr and then double-click on it to run.

If after installation, MBAM will not run, open the Malwarebytes' Anti-Malware folder in Program Files, right-click on mbam.exe and change the .exe as noted above. Then double-click on it to run.
Computer Pro

#3 dto

dto
  • Topic Starter

  • Members
  • 19 posts
  • OFFLINE
  •  
  • Local time:12:35 AM

Posted 23 December 2009 - 02:27 PM

Alright, thanks for the help. Here is my log:

Malwarebytes' Anti-Malware 1.42
Database version: 3415
Windows 6.0.6000
Internet Explorer 7.0.6000.16945

12/23/2009 2:10:56 PM
mbam-log-2009-12-23 (14-10-56).txt

Scan type: Full Scan (C:\|D:\|E:\|F:\|G:\|H:\|I:\|)
Objects scanned: 292889
Time elapsed: 2 hour(s), 58 minute(s), 19 second(s)

Memory Processes Infected: 0
Memory Modules Infected: 0
Registry Keys Infected: 3
Registry Values Infected: 3
Registry Data Items Infected: 0
Folders Infected: 0
Files Infected: 2

Memory Processes Infected:
(No malicious items detected)

Memory Modules Infected:
(No malicious items detected)

Registry Keys Infected:
HKEY_CLASSES_ROOT\CLSID\{7473d292-b7bb-4f24-ae82-7e2ce94bb6a9} (Adware.MyWebSearch) -> Quarantined and deleted successfully.
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\Stats\{07b18ea9-a523-4961-b6bb-170de4475cca} (Adware.MyWebSearch) -> Quarantined and deleted successfully.
HKEY_CURRENT_USER\SOFTWARE\Adware_ProNE (Malware.Trace) -> Quarantined and deleted successfully.

Registry Values Infected:
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar\{07b18ea9-a523-4961-b6bb-170de4475cca} (Adware.MyWebSearch) -> Quarantined and deleted successfully.
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Internet Explorer\MenuExt\&Search\(default) (Adware.Hotbar) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\my web search bar search scope monitor (Adware.MyWebSearch) -> Quarantined and deleted successfully.

Registry Data Items Infected:
(No malicious items detected)

Folders Infected:
(No malicious items detected)

Files Infected:
C:\Users\Lily Nguyen\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\KM1KIODY\downloadadwarepro[1].exe (Rogue.Installer) -> Quarantined and deleted successfully.
C:\Windows\System32\f3PSSavr.scr (Adware.MyWebSearch) -> Quarantined and deleted successfully.

#4 Computer Pro

Computer Pro

  • Members
  • 2,448 posts
  • OFFLINE
  •  
  • Gender:Male
  • Local time:12:35 AM

Posted 23 December 2009 - 02:30 PM

Now run SAS:

Please run ATF and SAS:

Note.. SAS doesn't open the registry hives for other user accounts on the system, so scans should be done from each user account.

Note 2: On Vista, "Windows Temp" is disabled. To empty "Windows Temp" ATF-Cleaner must be "Run as an Administrator".

From your regular user account..
Download Attribune's ATF Cleaner and then SUPERAntiSpyware, Free Home Edition

Save both to desktop ..
DO NOT run yet.
Open SUPER from icon and install and Update it
Under Scanner Options make sure the following are checked (leave all others unchecked):
Close browsers before scanning.
Scan for tracking cookies.
Terminate memory threats before quarantining.
Click the "Close" button to leave the control center screen and exit the program. DO NOT run yet.



Double-click ATF-Cleaner.exe to run the program.
Under Main "Select Files to Delete" choose: Select All.
Click the Empty Selected button.

If you use Firefox or Opera browser click that browser at the top and choose: Select All
Click the Empty Selected button.
If you would like to keep your saved passwords, please click No at the prompt.
Click Exit on the Main menu to close the program.

NOW Scan with SUPER
Open from the desktop icon or the program Files list
On the left, make sure you check C:\Fixed Drive.
Perform a Complete scan. After scan,Verify they are all checked.
Click OK on the summary screen to quarantine all found items.
If asked if you want to reboot, click "Yes" and reboot normally.

To retrieve the removal information after reboot, launch SUPERAntispyware again.
Click Preferences, then click the Statistics/Logs tab.
Under Scanner Logs, double-click SUPERAntiSpyware Scan Log.
If there are several logs, click the current dated log and press View log.
A text file will open in your default text editor.
Please copy and paste the Scan Log results in your next reply.
Click Close to exit the program.
Computer Pro

#5 dto

dto
  • Topic Starter

  • Members
  • 19 posts
  • OFFLINE
  •  
  • Local time:12:35 AM

Posted 23 December 2009 - 06:27 PM

Thanks for the help. Alright here is the log with Super:

SUPERAntiSpyware Scan Log
http://www.superantispyware.com

Generated 12/23/2009 at 06:13 PM

Application Version : 4.32.1000

Core Rules Database Version : 4406
Trace Rules Database Version: 2239

Scan type : Complete Scan
Total Scan Time : 03:05:21

Memory items scanned : 479
Memory threats detected : 0
Registry items scanned : 6969
Registry threats detected : 14
File items scanned : 172857
File threats detected : 207

Trojan.Agent/Gen-Nullo[Short]
HKLM\Software\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{F0D4B231-DA4B-4daf-81E4-DFEE4931A4AA}
HKCR\CLSID\{F0D4B231-DA4B-4DAF-81E4-DFEE4931A4AA}
HKCR\CLSID\{F0D4B231-DA4B-4DAF-81E4-DFEE4931A4AA}
HKCR\CLSID\{F0D4B231-DA4B-4DAF-81E4-DFEE4931A4AA}\InprocServer32
HKCR\CLSID\{F0D4B231-DA4B-4DAF-81E4-DFEE4931A4AA}\InprocServer32#ThreadingModel
C:\PROGRAM FILES\ASKSBAR\BAR\1.BIN\ASKSBAR.DLL
HKU\S-1-5-21-1035340872-3086985717-1729840511-1000\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{F0D4B231-DA4B-4DAF-81E4-DFEE4931A4AA}
HKU\S-1-5-21-1035340872-3086985717-1729840511-1000\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{F0D4B239-DA4B-4DAF-81E4-DFEE4931A4AA}
HKCR\CLSID\{F0D4B239-DA4B-4DAF-81E4-DFEE4931A4AA}
HKCR\CLSID\{F0D4B239-DA4B-4DAF-81E4-DFEE4931A4AA}
HKCR\CLSID\{F0D4B239-DA4B-4DAF-81E4-DFEE4931A4AA}\InprocServer32
HKCR\CLSID\{F0D4B239-DA4B-4DAF-81E4-DFEE4931A4AA}\InprocServer32#ThreadingModel
HKLM\Software\Microsoft\Internet Explorer\Toolbar#{F0D4B239-DA4B-4daf-81E4-DFEE4931A4AA}
HKU\S-1-5-21-1035340872-3086985717-1729840511-1000\Software\Microsoft\Internet Explorer\Toolbar\WebBrowser#{F0D4B239-DA4B-4DAF-81E4-DFEE4931A4AA}
C:\PROGRAM FILES\INTERNET EXPLORER\MSIMG32.DLL

Adware.MyWebSearch/FunWebProducts
HKU\S-1-5-21-1035340872-3086985717-1729840511-1000\SOFTWARE\FunWebProducts

Adware.Tracking Cookie
C:\Users\Lily Nguyen\AppData\Roaming\Microsoft\Windows\Cookies\Low\lily_nguyen@18eighteen[2].txt
C:\Users\Lily Nguyen\AppData\Roaming\Microsoft\Windows\Cookies\Low\lily_nguyen@2o7[1].txt
C:\Users\Lily Nguyen\AppData\Roaming\Microsoft\Windows\Cookies\Low\lily_nguyen@a1.interclick[1].txt
C:\Users\Lily Nguyen\AppData\Roaming\Microsoft\Windows\Cookies\Low\lily_nguyen@ad.flux[1].txt
C:\Users\Lily Nguyen\AppData\Roaming\Microsoft\Windows\Cookies\Low\lily_nguyen@ad.wsod[1].txt
C:\Users\Lily Nguyen\AppData\Roaming\Microsoft\Windows\Cookies\Low\lily_nguyen@ad.yieldmanager[2].txt
C:\Users\Lily Nguyen\AppData\Roaming\Microsoft\Windows\Cookies\Low\lily_nguyen@ad1.clickhype[1].txt
C:\Users\Lily Nguyen\AppData\Roaming\Microsoft\Windows\Cookies\Low\lily_nguyen@adcentriconline[1].txt
C:\Users\Lily Nguyen\AppData\Roaming\Microsoft\Windows\Cookies\Low\lily_nguyen@adecn.adnxs[1].txt
C:\Users\Lily Nguyen\AppData\Roaming\Microsoft\Windows\Cookies\Low\lily_nguyen@adinterax[1].txt
C:\Users\Lily Nguyen\AppData\Roaming\Microsoft\Windows\Cookies\Low\lily_nguyen@ads.adgoto[2].txt
C:\Users\Lily Nguyen\AppData\Roaming\Microsoft\Windows\Cookies\Low\lily_nguyen@ads.apn.co[2].txt
C:\Users\Lily Nguyen\AppData\Roaming\Microsoft\Windows\Cookies\Low\lily_nguyen@ads.beasleyinteractive[1].txt
C:\Users\Lily Nguyen\AppData\Roaming\Microsoft\Windows\Cookies\Low\lily_nguyen@ads.bittorrent[1].txt
C:\Users\Lily Nguyen\AppData\Roaming\Microsoft\Windows\Cookies\Low\lily_nguyen@ads.bleepingcomputer[2].txt
C:\Users\Lily Nguyen\AppData\Roaming\Microsoft\Windows\Cookies\Low\lily_nguyen@ads.cnn[1].txt
C:\Users\Lily Nguyen\AppData\Roaming\Microsoft\Windows\Cookies\Low\lily_nguyen@ads.financialcontent[1].txt
C:\Users\Lily Nguyen\AppData\Roaming\Microsoft\Windows\Cookies\Low\lily_nguyen@ads.foodbuzz[2].txt
C:\Users\Lily Nguyen\AppData\Roaming\Microsoft\Windows\Cookies\Low\lily_nguyen@ads.lucidmedia[1].txt
C:\Users\Lily Nguyen\AppData\Roaming\Microsoft\Windows\Cookies\Low\lily_nguyen@ads.lucidmedia[2].txt
C:\Users\Lily Nguyen\AppData\Roaming\Microsoft\Windows\Cookies\Low\lily_nguyen@ads.meredithads[1].txt
C:\Users\Lily Nguyen\AppData\Roaming\Microsoft\Windows\Cookies\Low\lily_nguyen@ads.nascar[1].txt
C:\Users\Lily Nguyen\AppData\Roaming\Microsoft\Windows\Cookies\Low\lily_nguyen@ads.nba[1].txt
C:\Users\Lily Nguyen\AppData\Roaming\Microsoft\Windows\Cookies\Low\lily_nguyen@ads.onlinephim[2].txt
C:\Users\Lily Nguyen\AppData\Roaming\Microsoft\Windows\Cookies\Low\lily_nguyen@ads.pgatour[1].txt
C:\Users\Lily Nguyen\AppData\Roaming\Microsoft\Windows\Cookies\Low\lily_nguyen@ads.pointroll[1].txt
C:\Users\Lily Nguyen\AppData\Roaming\Microsoft\Windows\Cookies\Low\lily_nguyen@ads.shorttail[1].txt
C:\Users\Lily Nguyen\AppData\Roaming\Microsoft\Windows\Cookies\Low\lily_nguyen@ads.tangowire[2].txt
C:\Users\Lily Nguyen\AppData\Roaming\Microsoft\Windows\Cookies\Low\lily_nguyen@ads.undertone[1].txt
C:\Users\Lily Nguyen\AppData\Roaming\Microsoft\Windows\Cookies\Low\lily_nguyen@ads.xapads[2].txt
C:\Users\Lily Nguyen\AppData\Roaming\Microsoft\Windows\Cookies\Low\lily_nguyen@adultadworld[2].txt
C:\Users\Lily Nguyen\AppData\Roaming\Microsoft\Windows\Cookies\Low\lily_nguyen@adultdatingpages[1].txt
C:\Users\Lily Nguyen\AppData\Roaming\Microsoft\Windows\Cookies\Low\lily_nguyen@advertising[2].txt
C:\Users\Lily Nguyen\AppData\Roaming\Microsoft\Windows\Cookies\Low\lily_nguyen@adxpose[1].txt
C:\Users\Lily Nguyen\AppData\Roaming\Microsoft\Windows\Cookies\Low\lily_nguyen@analteenangels[2].txt
C:\Users\Lily Nguyen\AppData\Roaming\Microsoft\Windows\Cookies\Low\lily_nguyen@assteenmouth[1].txt
C:\Users\Lily Nguyen\AppData\Roaming\Microsoft\Windows\Cookies\Low\lily_nguyen@atdmt[1].txt
C:\Users\Lily Nguyen\AppData\Roaming\Microsoft\Windows\Cookies\Low\lily_nguyen@beacon.dmsinsights[1].txt
C:\Users\Lily Nguyen\AppData\Roaming\Microsoft\Windows\Cookies\Low\lily_nguyen@bettersex[1].txt
C:\Users\Lily Nguyen\AppData\Roaming\Microsoft\Windows\Cookies\Low\lily_nguyen@bluestreak[1].txt
C:\Users\Lily Nguyen\AppData\Roaming\Microsoft\Windows\Cookies\Low\lily_nguyen@campusexplorer[1].txt
C:\Users\Lily Nguyen\AppData\Roaming\Microsoft\Windows\Cookies\Low\lily_nguyen@cdn4.specificclick[2].txt
C:\Users\Lily Nguyen\AppData\Roaming\Microsoft\Windows\Cookies\Low\lily_nguyen@cf-db01.clickfacts[1].txt
C:\Users\Lily Nguyen\AppData\Roaming\Microsoft\Windows\Cookies\Low\lily_nguyen@chitika[1].txt
C:\Users\Lily Nguyen\AppData\Roaming\Microsoft\Windows\Cookies\Low\lily_nguyen@click.email.hotels[1].txt
C:\Users\Lily Nguyen\AppData\Roaming\Microsoft\Windows\Cookies\Low\lily_nguyen@click.orgycash[1].txt
C:\Users\Lily Nguyen\AppData\Roaming\Microsoft\Windows\Cookies\Low\lily_nguyen@click.revsharecash[1].txt
C:\Users\Lily Nguyen\AppData\Roaming\Microsoft\Windows\Cookies\Low\lily_nguyen@click.tmfmoney[2].txt
C:\Users\Lily Nguyen\AppData\Roaming\Microsoft\Windows\Cookies\Low\lily_nguyen@clickintext[1].txt
C:\Users\Lily Nguyen\AppData\Roaming\Microsoft\Windows\Cookies\Low\lily_nguyen@clicktorrent[1].txt
C:\Users\Lily Nguyen\AppData\Roaming\Microsoft\Windows\Cookies\Low\lily_nguyen@cmss.bettersex[2].txt
C:\Users\Lily Nguyen\AppData\Roaming\Microsoft\Windows\Cookies\Low\lily_nguyen@collective-media[2].txt
C:\Users\Lily Nguyen\AppData\Roaming\Microsoft\Windows\Cookies\Low\lily_nguyen@content.yieldmanager[1].txt
C:\Users\Lily Nguyen\AppData\Roaming\Microsoft\Windows\Cookies\Low\lily_nguyen@content.yieldmanager[3].txt
C:\Users\Lily Nguyen\AppData\Roaming\Microsoft\Windows\Cookies\Low\lily_nguyen@convert.convert2media[2].txt
C:\Users\Lily Nguyen\AppData\Roaming\Microsoft\Windows\Cookies\Low\lily_nguyen@countryclubreceptions[1].txt
C:\Users\Lily Nguyen\AppData\Roaming\Microsoft\Windows\Cookies\Low\lily_nguyen@crackle[1].txt
C:\Users\Lily Nguyen\AppData\Roaming\Microsoft\Windows\Cookies\Low\lily_nguyen@criminal.findlaw[1].txt
C:\Users\Lily Nguyen\AppData\Roaming\Microsoft\Windows\Cookies\Low\lily_nguyen@cuteteenvideo[2].txt
C:\Users\Lily Nguyen\AppData\Roaming\Microsoft\Windows\Cookies\Low\lily_nguyen@dc.tremormedia[1].txt
C:\Users\Lily Nguyen\AppData\Roaming\Microsoft\Windows\Cookies\Low\lily_nguyen@deutsche-teens[2].txt
C:\Users\Lily Nguyen\AppData\Roaming\Microsoft\Windows\Cookies\Low\lily_nguyen@dmtracker[1].txt
C:\Users\Lily Nguyen\AppData\Roaming\Microsoft\Windows\Cookies\Low\lily_nguyen@doubleclick[1].txt
C:\Users\Lily Nguyen\AppData\Roaming\Microsoft\Windows\Cookies\Low\lily_nguyen@dumbandhorny[2].txt
C:\Users\Lily Nguyen\AppData\Roaming\Microsoft\Windows\Cookies\Low\lily_nguyen@dyn.adknowledgeimager3[1].txt
C:\Users\Lily Nguyen\AppData\Roaming\Microsoft\Windows\Cookies\Low\lily_nguyen@dyn.adknowledgeimages[1].txt
C:\Users\Lily Nguyen\AppData\Roaming\Microsoft\Windows\Cookies\Low\lily_nguyen@dyn.akmediapartners-img[1].txt
C:\Users\Lily Nguyen\AppData\Roaming\Microsoft\Windows\Cookies\Low\lily_nguyen@dyn.mediapartners-img[1].txt
C:\Users\Lily Nguyen\AppData\Roaming\Microsoft\Windows\Cookies\Low\lily_nguyen@eas.apm.emediate[1].txt
C:\Users\Lily Nguyen\AppData\Roaming\Microsoft\Windows\Cookies\Low\lily_nguyen@epochstats[1].txt
C:\Users\Lily Nguyen\AppData\Roaming\Microsoft\Windows\Cookies\Low\lily_nguyen@euroclick[2].txt
C:\Users\Lily Nguyen\AppData\Roaming\Microsoft\Windows\Cookies\Low\lily_nguyen@exploitedblackteens[2].txt
C:\Users\Lily Nguyen\AppData\Roaming\Microsoft\Windows\Cookies\Low\lily_nguyen@eyewonder[1].txt
C:\Users\Lily Nguyen\AppData\Roaming\Microsoft\Windows\Cookies\Low\lily_nguyen@fhg.cuteteencheaters[1].txt
C:\Users\Lily Nguyen\AppData\Roaming\Microsoft\Windows\Cookies\Low\lily_nguyen@find.galegroup[2].txt
C:\Users\Lily Nguyen\AppData\Roaming\Microsoft\Windows\Cookies\Low\lily_nguyen@findlaw[1].txt
C:\Users\Lily Nguyen\AppData\Roaming\Microsoft\Windows\Cookies\Low\lily_nguyen@findsouthwestfloridahomes[2].txt
C:\Users\Lily Nguyen\AppData\Roaming\Microsoft\Windows\Cookies\Low\lily_nguyen@findstuff[2].txt
C:\Users\Lily Nguyen\AppData\Roaming\Microsoft\Windows\Cookies\Low\lily_nguyen@floridahealthfinder[2].txt
C:\Users\Lily Nguyen\AppData\Roaming\Microsoft\Windows\Cookies\Low\lily_nguyen@freeporngiants[1].txt
C:\Users\Lily Nguyen\AppData\Roaming\Microsoft\Windows\Cookies\Low\lily_nguyen@bleeparoo[2].txt
C:\Users\Lily Nguyen\AppData\Roaming\Microsoft\Windows\Cookies\Low\lily_nguyen@fullporn[2].txt
C:\Users\Lily Nguyen\AppData\Roaming\Microsoft\Windows\Cookies\Low\lily_nguyen@gallery.teenpinkvideos[1].txt
C:\Users\Lily Nguyen\AppData\Roaming\Microsoft\Windows\Cookies\Low\lily_nguyen@himedia.individuad[2].txt
C:\Users\Lily Nguyen\AppData\Roaming\Microsoft\Windows\Cookies\Low\lily_nguyen@homemadeporn[2].txt
C:\Users\Lily Nguyen\AppData\Roaming\Microsoft\Windows\Cookies\Low\lily_nguyen@imrworldwide[2].txt
C:\Users\Lily Nguyen\AppData\Roaming\Microsoft\Windows\Cookies\Low\lily_nguyen@insightexpressai[2].txt
C:\Users\Lily Nguyen\AppData\Roaming\Microsoft\Windows\Cookies\Low\lily_nguyen@interclick[2].txt
C:\Users\Lily Nguyen\AppData\Roaming\Microsoft\Windows\Cookies\Low\lily_nguyen@intermundomedia[2].txt
C:\Users\Lily Nguyen\AppData\Roaming\Microsoft\Windows\Cookies\Low\lily_nguyen@invitemedia[1].txt
C:\Users\Lily Nguyen\AppData\Roaming\Microsoft\Windows\Cookies\Low\lily_nguyen@join.momsteachingteens[2].txt
C:\Users\Lily Nguyen\AppData\Roaming\Microsoft\Windows\Cookies\Low\lily_nguyen@l1.qsstats[1].txt
C:\Users\Lily Nguyen\AppData\Roaming\Microsoft\Windows\Cookies\Low\lily_nguyen@landing.trafficz[1].txt
C:\Users\Lily Nguyen\AppData\Roaming\Microsoft\Windows\Cookies\Low\lily_nguyen@lfstmedia[2].txt
C:\Users\Lily Nguyen\AppData\Roaming\Microsoft\Windows\Cookies\Low\lily_nguyen@loadxl.exelator[2].txt
C:\Users\Lily Nguyen\AppData\Roaming\Microsoft\Windows\Cookies\Low\lily_nguyen@login.tracking101[1].txt
C:\Users\Lily Nguyen\AppData\Roaming\Microsoft\Windows\Cookies\Low\lily_nguyen@lucidmedia[1].txt
C:\Users\Lily Nguyen\AppData\Roaming\Microsoft\Windows\Cookies\Low\lily_nguyen@maturevideoshunter.alexxxxpages[1].txt
C:\Users\Lily Nguyen\AppData\Roaming\Microsoft\Windows\Cookies\Low\lily_nguyen@media.expedia[2].txt
C:\Users\Lily Nguyen\AppData\Roaming\Microsoft\Windows\Cookies\Low\lily_nguyen@media.photobucket[1].txt
C:\Users\Lily Nguyen\AppData\Roaming\Microsoft\Windows\Cookies\Low\lily_nguyen@media6degrees[1].txt
C:\Users\Lily Nguyen\AppData\Roaming\Microsoft\Windows\Cookies\Low\lily_nguyen@mediaonenetwork[1].txt
C:\Users\Lily Nguyen\AppData\Roaming\Microsoft\Windows\Cookies\Low\lily_nguyen@mediapartners-img[1].txt
C:\Users\Lily Nguyen\AppData\Roaming\Microsoft\Windows\Cookies\Low\lily_nguyen@minnesotademocratsexposed[2].txt
C:\Users\Lily Nguyen\AppData\Roaming\Microsoft\Windows\Cookies\Low\lily_nguyen@momsteachingteens[1].txt
C:\Users\Lily Nguyen\AppData\Roaming\Microsoft\Windows\Cookies\Low\lily_nguyen@my18teens[2].txt
C:\Users\Lily Nguyen\AppData\Roaming\Microsoft\Windows\Cookies\Low\lily_nguyen@mybleepinwife[1].txt
C:\Users\Lily Nguyen\AppData\Roaming\Microsoft\Windows\Cookies\Low\lily_nguyen@myroitracking[2].txt
C:\Users\Lily Nguyen\AppData\Roaming\Microsoft\Windows\Cookies\Low\lily_nguyen@openxxx.viragemedia[1].txt
C:\Users\Lily Nguyen\AppData\Roaming\Microsoft\Windows\Cookies\Low\lily_nguyen@optimost[2].txt
C:\Users\Lily Nguyen\AppData\Roaming\Microsoft\Windows\Cookies\Low\lily_nguyen@overture[1].txt
C:\Users\Lily Nguyen\AppData\Roaming\Microsoft\Windows\Cookies\Low\lily_nguyen@pointroll[2].txt
C:\Users\Lily Nguyen\AppData\Roaming\Microsoft\Windows\Cookies\Low\lily_nguyen@pornhub[2].txt
C:\Users\Lily Nguyen\AppData\Roaming\Microsoft\Windows\Cookies\Low\lily_nguyen@pornopillow[1].txt
C:\Users\Lily Nguyen\AppData\Roaming\Microsoft\Windows\Cookies\Low\lily_nguyen@pornpussyclips[2].txt
C:\Users\Lily Nguyen\AppData\Roaming\Microsoft\Windows\Cookies\Low\lily_nguyen@porn[1].txt
C:\Users\Lily Nguyen\AppData\Roaming\Microsoft\Windows\Cookies\Low\lily_nguyen@privateteenvideo[1].txt
C:\Users\Lily Nguyen\AppData\Roaming\Microsoft\Windows\Cookies\Low\lily_nguyen@publishers.clickbooth[2].txt
C:\Users\Lily Nguyen\AppData\Roaming\Microsoft\Windows\Cookies\Low\lily_nguyen@pvw.drunksexorgy[2].txt
C:\Users\Lily Nguyen\AppData\Roaming\Microsoft\Windows\Cookies\Low\lily_nguyen@qnsr[2].txt
C:\Users\Lily Nguyen\AppData\Roaming\Microsoft\Windows\Cookies\Low\lily_nguyen@qualityadultblogs[2].txt
C:\Users\Lily Nguyen\AppData\Roaming\Microsoft\Windows\Cookies\Low\lily_nguyen@questionmarket[1].txt
C:\Users\Lily Nguyen\AppData\Roaming\Microsoft\Windows\Cookies\Low\lily_nguyen@realmedia[2].txt
C:\Users\Lily Nguyen\AppData\Roaming\Microsoft\Windows\Cookies\Low\lily_nguyen@revsci[2].txt
C:\Users\Lily Nguyen\AppData\Roaming\Microsoft\Windows\Cookies\Low\lily_nguyen@reztrack[1].txt
C:\Users\Lily Nguyen\AppData\Roaming\Microsoft\Windows\Cookies\Low\lily_nguyen@richmedia.yahoo[2].txt
C:\Users\Lily Nguyen\AppData\Roaming\Microsoft\Windows\Cookies\Low\lily_nguyen@roadandtrack[2].txt
C:\Users\Lily Nguyen\AppData\Roaming\Microsoft\Windows\Cookies\Low\lily_nguyen@sales.liveperson[10].txt
C:\Users\Lily Nguyen\AppData\Roaming\Microsoft\Windows\Cookies\Low\lily_nguyen@sales.liveperson[11].txt
C:\Users\Lily Nguyen\AppData\Roaming\Microsoft\Windows\Cookies\Low\lily_nguyen@sales.liveperson[1].txt
C:\Users\Lily Nguyen\AppData\Roaming\Microsoft\Windows\Cookies\Low\lily_nguyen@sales.liveperson[2].txt
C:\Users\Lily Nguyen\AppData\Roaming\Microsoft\Windows\Cookies\Low\lily_nguyen@sales.liveperson[3].txt
C:\Users\Lily Nguyen\AppData\Roaming\Microsoft\Windows\Cookies\Low\lily_nguyen@sales.liveperson[4].txt
C:\Users\Lily Nguyen\AppData\Roaming\Microsoft\Windows\Cookies\Low\lily_nguyen@sales.liveperson[5].txt
C:\Users\Lily Nguyen\AppData\Roaming\Microsoft\Windows\Cookies\Low\lily_nguyen@sales.liveperson[7].txt
C:\Users\Lily Nguyen\AppData\Roaming\Microsoft\Windows\Cookies\Low\lily_nguyen@sales.liveperson[8].txt
C:\Users\Lily Nguyen\AppData\Roaming\Microsoft\Windows\Cookies\Low\lily_nguyen@sales.liveperson[9].txt
C:\Users\Lily Nguyen\AppData\Roaming\Microsoft\Windows\Cookies\Low\lily_nguyen@sdpublic.sdcounty.ca[2].txt
C:\Users\Lily Nguyen\AppData\Roaming\Microsoft\Windows\Cookies\Low\lily_nguyen@secret.fullporn[2].txt
C:\Users\Lily Nguyen\AppData\Roaming\Microsoft\Windows\Cookies\Low\lily_nguyen@serw.clicksor[1].txt
C:\Users\Lily Nguyen\AppData\Roaming\Microsoft\Windows\Cookies\Low\lily_nguyen@sexmedo[1].txt
C:\Users\Lily Nguyen\AppData\Roaming\Microsoft\Windows\Cookies\Low\lily_nguyen@sexmovie[2].txt
C:\Users\Lily Nguyen\AppData\Roaming\Microsoft\Windows\Cookies\Low\lily_nguyen@sexoteric[1].txt
C:\Users\Lily Nguyen\AppData\Roaming\Microsoft\Windows\Cookies\Low\lily_nguyen@sexproadventures[1].txt
C:\Users\Lily Nguyen\AppData\Roaming\Microsoft\Windows\Cookies\Low\lily_nguyen@snip.www.findstuff[2].txt
C:\Users\Lily Nguyen\AppData\Roaming\Microsoft\Windows\Cookies\Low\lily_nguyen@socialmedia[1].txt
C:\Users\Lily Nguyen\AppData\Roaming\Microsoft\Windows\Cookies\Low\lily_nguyen@specificclick[1].txt
C:\Users\Lily Nguyen\AppData\Roaming\Microsoft\Windows\Cookies\Low\lily_nguyen@specificmedia[2].txt
C:\Users\Lily Nguyen\AppData\Roaming\Microsoft\Windows\Cookies\Low\lily_nguyen@stats.townnews[2].txt
C:\Users\Lily Nguyen\AppData\Roaming\Microsoft\Windows\Cookies\Low\lily_nguyen@t.lynxtrack[1].txt
C:\Users\Lily Nguyen\AppData\Roaming\Microsoft\Windows\Cookies\Low\lily_nguyen@teenagedelinquents[2].txt
C:\Users\Lily Nguyen\AppData\Roaming\Microsoft\Windows\Cookies\Low\lily_nguyen@teenagewhores[2].txt
C:\Users\Lily Nguyen\AppData\Roaming\Microsoft\Windows\Cookies\Low\lily_nguyen@teeniesxs[1].txt
C:\Users\Lily Nguyen\AppData\Roaming\Microsoft\Windows\Cookies\Low\lily_nguyen@teenmodels[2].txt
C:\Users\Lily Nguyen\AppData\Roaming\Microsoft\Windows\Cookies\Low\lily_nguyen@teenpinkvideos[1].txt
C:\Users\Lily Nguyen\AppData\Roaming\Microsoft\Windows\Cookies\Low\lily_nguyen@tour.sexproadventures[1].txt
C:\Users\Lily Nguyen\AppData\Roaming\Microsoft\Windows\Cookies\Low\lily_nguyen@tour.teenpinkvideos[2].txt
C:\Users\Lily Nguyen\AppData\Roaming\Microsoft\Windows\Cookies\Low\lily_nguyen@track.bestbuy[2].txt
C:\Users\Lily Nguyen\AppData\Roaming\Microsoft\Windows\Cookies\Low\lily_nguyen@track.bigbrandpromotions[2].txt
C:\Users\Lily Nguyen\AppData\Roaming\Microsoft\Windows\Cookies\Low\lily_nguyen@track.wachoviadealer[1].txt
C:\Users\Lily Nguyen\AppData\Roaming\Microsoft\Windows\Cookies\Low\lily_nguyen@trackalyzer[1].txt
C:\Users\Lily Nguyen\AppData\Roaming\Microsoft\Windows\Cookies\Low\lily_nguyen@tracking.foundry42[1].txt
C:\Users\Lily Nguyen\AppData\Roaming\Microsoft\Windows\Cookies\Low\lily_nguyen@tracking.foundry42[2].txt
C:\Users\Lily Nguyen\AppData\Roaming\Microsoft\Windows\Cookies\Low\lily_nguyen@tracking.gajmp[1].txt
C:\Users\Lily Nguyen\AppData\Roaming\Microsoft\Windows\Cookies\Low\lily_nguyen@tracking.lsfinteractive[1].txt
C:\Users\Lily Nguyen\AppData\Roaming\Microsoft\Windows\Cookies\Low\lily_nguyen@traffic.prod.cobaltgroup[1].txt
C:\Users\Lily Nguyen\AppData\Roaming\Microsoft\Windows\Cookies\Low\lily_nguyen@vintagevagina[1].txt
C:\Users\Lily Nguyen\AppData\Roaming\Microsoft\Windows\Cookies\Low\lily_nguyen@ww2.teenagewhores[1].txt
C:\Users\Lily Nguyen\AppData\Roaming\Microsoft\Windows\Cookies\Low\lily_nguyen@www.101teengirls[2].txt
C:\Users\Lily Nguyen\AppData\Roaming\Microsoft\Windows\Cookies\Low\lily_nguyen@www.bettersex[2].txt
C:\Users\Lily Nguyen\AppData\Roaming\Microsoft\Windows\Cookies\Low\lily_nguyen@www.campusexplorer[2].txt
C:\Users\Lily Nguyen\AppData\Roaming\Microsoft\Windows\Cookies\Low\lily_nguyen@www.castingcouchteens[1].txt
C:\Users\Lily Nguyen\AppData\Roaming\Microsoft\Windows\Cookies\Low\lily_nguyen@www.clickmanage[2].txt
C:\Users\Lily Nguyen\AppData\Roaming\Microsoft\Windows\Cookies\Low\lily_nguyen@www.countryclubreceptions[2].txt
C:\Users\Lily Nguyen\AppData\Roaming\Microsoft\Windows\Cookies\Low\lily_nguyen@www.deutsche-teens[1].txt
C:\Users\Lily Nguyen\AppData\Roaming\Microsoft\Windows\Cookies\Low\lily_nguyen@www.findstuff[2].txt
C:\Users\Lily Nguyen\AppData\Roaming\Microsoft\Windows\Cookies\Low\lily_nguyen@www.frank-teens[1].txt
C:\Users\Lily Nguyen\AppData\Roaming\Microsoft\Windows\Cookies\Low\lily_nguyen@www.bleeparoo[1].txt
C:\Users\Lily Nguyen\AppData\Roaming\Microsoft\Windows\Cookies\Low\lily_nguyen@www.fullporn[2].txt
C:\Users\Lily Nguyen\AppData\Roaming\Microsoft\Windows\Cookies\Low\lily_nguyen@www.homemadeporn[1].txt
C:\Users\Lily Nguyen\AppData\Roaming\Microsoft\Windows\Cookies\Low\lily_nguyen@www.ijapanesesex[1].txt
C:\Users\Lily Nguyen\AppData\Roaming\Microsoft\Windows\Cookies\Low\lily_nguyen@www.maturesex4free[1].txt
C:\Users\Lily Nguyen\AppData\Roaming\Microsoft\Windows\Cookies\Low\lily_nguyen@www.maturexxxarchive[1].txt
C:\Users\Lily Nguyen\AppData\Roaming\Microsoft\Windows\Cookies\Low\lily_nguyen@www.milfxxxtube4free[1].txt
C:\Users\Lily Nguyen\AppData\Roaming\Microsoft\Windows\Cookies\Low\lily_nguyen@www.mybleepinwife[2].txt
C:\Users\Lily Nguyen\AppData\Roaming\Microsoft\Windows\Cookies\Low\lily_nguyen@www.mybleepinwife[3].txt
C:\Users\Lily Nguyen\AppData\Roaming\Microsoft\Windows\Cookies\Low\lily_nguyen@www.porn-hotworld[2].txt
C:\Users\Lily Nguyen\AppData\Roaming\Microsoft\Windows\Cookies\Low\lily_nguyen@www.pornhub[2].txt
C:\Users\Lily Nguyen\AppData\Roaming\Microsoft\Windows\Cookies\Low\lily_nguyen@www.pornpussyclips[1].txt
C:\Users\Lily Nguyen\AppData\Roaming\Microsoft\Windows\Cookies\Low\lily_nguyen@www.porn[1].txt
C:\Users\Lily Nguyen\AppData\Roaming\Microsoft\Windows\Cookies\Low\lily_nguyen@www.porn[2].txt
C:\Users\Lily Nguyen\AppData\Roaming\Microsoft\Windows\Cookies\Low\lily_nguyen@www.sexhungrymoms[2].txt
C:\Users\Lily Nguyen\AppData\Roaming\Microsoft\Windows\Cookies\Low\lily_nguyen@www.sexmovieproject[2].txt
C:\Users\Lily Nguyen\AppData\Roaming\Microsoft\Windows\Cookies\Low\lily_nguyen@www.sexoteric[2].txt
C:\Users\Lily Nguyen\AppData\Roaming\Microsoft\Windows\Cookies\Low\lily_nguyen@www.sexvideo[1].txt
C:\Users\Lily Nguyen\AppData\Roaming\Microsoft\Windows\Cookies\Low\lily_nguyen@www.teeniesxs[1].txt
C:\Users\Lily Nguyen\AppData\Roaming\Microsoft\Windows\Cookies\Low\lily_nguyen@www.teenmodels[2].txt
C:\Users\Lily Nguyen\AppData\Roaming\Microsoft\Windows\Cookies\Low\lily_nguyen@www.theonlybleep[2].txt
C:\Users\Lily Nguyen\AppData\Roaming\Microsoft\Windows\Cookies\Low\lily_nguyen@www.tmptrack[1].txt
C:\Users\Lily Nguyen\AppData\Roaming\Microsoft\Windows\Cookies\Low\lily_nguyen@www.tracktrust[2].txt
C:\Users\Lily Nguyen\AppData\Roaming\Microsoft\Windows\Cookies\Low\lily_nguyen@www.trafficstrategies[1].txt
C:\Users\Lily Nguyen\AppData\Roaming\Microsoft\Windows\Cookies\Low\lily_nguyen@www.x3track[1].txt
C:\Users\Lily Nguyen\AppData\Roaming\Microsoft\Windows\Cookies\Low\lily_nguyen@yieldmanager[1].txt
C:\Users\Lily Nguyen\AppData\Roaming\Microsoft\Windows\Cookies\Low\lily_nguyen@youngsexparties[1].txt
C:\Users\Lily Nguyen\AppData\Roaming\Microsoft\Windows\Cookies\Low\lily_nguyen@yourmedia[1].txt

geez, all from porno sites..

#6 dto

dto
  • Topic Starter

  • Members
  • 19 posts
  • OFFLINE
  •  
  • Local time:12:35 AM

Posted 23 December 2009 - 06:31 PM

One more thing i forgot to ask, I have an out-to-date virus program called "Trend Micro Antivirus 2007" and now theres a pop up that asks me to update for free. I know its a fakeadware because my spy sweeper catches it everyday. I try to get rid of it everyday, but it still comes up. I was wondering if I should just delete the old Trend Micro because i never use it and plus it keeps poping up a false update.

#7 Computer Pro

Computer Pro

  • Members
  • 2,448 posts
  • OFFLINE
  •  
  • Gender:Male
  • Local time:12:35 AM

Posted 23 December 2009 - 06:32 PM

Ahh well, what can you say.

How are things running now?
Computer Pro

#8 dto

dto
  • Topic Starter

  • Members
  • 19 posts
  • OFFLINE
  •  
  • Local time:12:35 AM

Posted 23 December 2009 - 06:32 PM

Woops one more thing, what should I do with the three programs i downloaded? Thanks - Dustin

#9 dto

dto
  • Topic Starter

  • Members
  • 19 posts
  • OFFLINE
  •  
  • Local time:12:35 AM

Posted 23 December 2009 - 06:34 PM

Things are running quite well, Thank you. Just the Trend Micro keeps poping up the false free up-date.

#10 Computer Pro

Computer Pro

  • Members
  • 2,448 posts
  • OFFLINE
  •  
  • Gender:Male
  • Local time:12:35 AM

Posted 23 December 2009 - 07:31 PM

I would keep Malwarebytes and SAS and run scans with them atleast once a week.

Before you delete the Trend Micro, would you be willing to pay for an anti-virus, or would you want a free. Keep in mind, at least in my opinion, you get what you pay for.
Computer Pro

#11 dto

dto
  • Topic Starter

  • Members
  • 19 posts
  • OFFLINE
  •  
  • Local time:12:35 AM

Posted 23 December 2009 - 09:27 PM

Thanks for the tips, how about the ATF? About the Trend Micro, its been out-of-date since 2007, now i think possibly there is a fake program that hacked the Trend Micro. Sorry if im not making since but, my Spy Sweeper had found an adware called "fakealert.gen" and i think its the pop-up that keeps poping up about a free update of Trend Mirco.

#12 Computer Pro

Computer Pro

  • Members
  • 2,448 posts
  • OFFLINE
  •  
  • Gender:Male
  • Local time:12:35 AM

Posted 23 December 2009 - 10:10 PM

You can get rid of ATF. I would go ahead and replace the Trend Micro. Some of the free options are Avira, Avast, or Microsoft Security Essentials. Or you could go with paid. For paid, I recommend Kaspersky. Let me know what you select.
Computer Pro

#13 dto

dto
  • Topic Starter

  • Members
  • 19 posts
  • OFFLINE
  •  
  • Local time:12:35 AM

Posted 23 December 2009 - 11:11 PM

I will let you know when I made my choice. Thanks for all the help! How about the two that i used earlyer, can i use those two?

#14 Computer Pro

Computer Pro

  • Members
  • 2,448 posts
  • OFFLINE
  •  
  • Gender:Male
  • Local time:12:35 AM

Posted 23 December 2009 - 11:12 PM

Those are anti-malware solutions. They do not provide real-time protection, which is needed. Please let me know on your choice of real-time protection.
Computer Pro

#15 dto

dto
  • Topic Starter

  • Members
  • 19 posts
  • OFFLINE
  •  
  • Local time:12:35 AM

Posted 28 December 2009 - 07:00 PM

sorry I've been gone for the holidays, ill let you know when I i decide. Thanks for the advice.




0 user(s) are reading this topic

0 members, 0 guests, 0 anonymous users