Jump to content


 


Register a free account to unlock additional features at BleepingComputer.com
Welcome to BleepingComputer, a free community where people like yourself come together to discuss and learn how to use their computers. Using the site is easy and fun. As a guest, you can browse and view the various discussions in the forums, but can not create a new topic or reply to an existing one unless you are logged in. Other benefits of registering an account are subscribing to topics and forums, creating a blog, and having no ads shown anywhere on the site.


Click here to Register a free account now! or read our Welcome Guide to learn how to use this site.

Photo

Infected by Win32/Patched


  • This topic is locked This topic is locked
7 replies to this topic

#1 Army_Chef

Army_Chef

  • Members
  • 7 posts
  • OFFLINE
  •  
  • Local time:04:14 PM

Posted 09 November 2010 - 04:38 PM

Hi guys, I've been infected with the Win32/Patched trojsn and I have Googled intensively to see what I can do to resolve the issue. I am not very techie minded and find trying to follow most of the suggested remedies very difficult. I would appreciate a little instruction and step by step guidance as I try to fi this problem. I have read some of the other replies to similar posts here and the first thing I seem to understand is that this should not be done without expert help. So here goes.

I run Windows Vista Home Premium 32 bit, SP2 and I have experienced a Win32/Patch infection which was alerted to me by Windows Defender. I also run AVG anti-virus.

Any help would be greatly appreciated and I ask anyone brave enough to help me out to be a little patient and understanding at my lack of techie knowledge!

Chers,

Army Chef

BC AdBot (Login to Remove)

 


#2 cryptodan

cryptodan

    Bleepin Madman


  • Members
  • 21,868 posts
  • OFFLINE
  •  
  • Gender:Male
  • Location:Catonsville, Md
  • Local time:04:14 PM

Posted 09 November 2010 - 04:41 PM

Hello,

And welcome to BleepingComputer.com, before we can assist you with your question of: Am I infected? You will need to perform the following tasks and post the logs of each if you can.

Malwarebytes Anti-Malware

Please download Malwarebytes Anti-Malware and save it to your desktop.
Download Link 1
Download Link 2MBAM may "make changes to your registry" as part of its disinfection routine. If using other security programs that detect registry changes (ie Spybot's Teatimer), they may interfere or alert you. Temporarily disable such programs or permit them to allow the changes.

  • Make sure you are connected to the Internet.
  • Double-click on mbam-setup.exe to install the application.
    For instructions with screenshots, please refer to the How to use Malwarebytes' Anti-Malware Guide.
  • When the installation begins, follow the prompts and do not make any changes to default settings.
  • When installation has finished, make sure you leave both of these checked:
    • Update Malwarebytes' Anti-Malware
    • Launch Malwarebytes' Anti-Malware
  • Then click Finish.
MBAM will automatically start and you will be asked to update the program before performing a scan.
  • If an update is found, the program will automatically update itself. Press the OK button to close that box and continue.
  • If you encounter any problems while downloading the definition updates, manually download them from here and just double-click on mbam-rules.exe to install.
On the Scanner tab:
  • Make sure the "Perform Full Scan" option is selected.
  • Then click on the Scan button.
  • If asked to select the drives to scan, leave all the drives selected and click on the Start Scan button.
  • The scan will begin and "Scan in progress" will show at the top. It may take some time to complete so please be patient.
  • When the scan is finished, a message box will say "The scan completed successfully. Click 'Show Results' to display all objects found".
  • Click OK to close the message box and continue with the removal process.
Back at the main Scanner screen:
  • Click on the Show Results button to see a list of any malware that was found.
  • Make sure that everything is checked, and click Remove Selected.
  • When removal is completed, a log report will open in Notepad.
  • The log is automatically saved and can be viewed by clicking the Logs tab in MBAM.
  • Copy and paste the contents of that report in your next reply. Be sure to post the complete log to include the top portion which shows MBAM's database version and your operating system.
  • Exit MBAM when done.
Note: If MBAM encounters a file that is difficult to remove, you will be asked to reboot your computer so MBAM can proceed with the disinfection process. If asked to restart the computer, please do so immediately. Failure to reboot normally (not into safe mode) will prevent MBAM from removing all the malware.


SUPERAntiSpyware:

Please download and scan with SUPERAntiSpyware Free

  • Double-click SUPERAntiSypware.exe and use the default settings for installation.
  • An icon will be created on your desktop. Double-click that icon to launch the program.
  • If it will not start, go to Start > All Prgrams > SUPERAntiSpyware and click on Alternate Start.
  • If asked to update the program definitions, click "Yes". If not, update the definitions before scanning by selecting "Check for Updates". (If you encounter any problems while downloading the updates, manually download them from here. Double-click on the hyperlink for Download Installer and save SASDEFINITIONS.EXE to your desktop. Then double-click on SASDEFINITIONS.EXE to install the definitions.)
  • In the Main Menu, click the Preferences... button.
  • Click the "General and Startup" tab, and under Start-up Options, make sure "Start SUPERAntiSpyware when Windows starts" box is unchecked.
  • Click the "Scanning Control" tab, and under Scanner Options, make sure the following are checked (leave all others unchecked):
    • Close browsers before scanning.
    • Scan for tracking cookies.
    • Terminate memory threats before quarantining.
  • Click the "Close" button to leave the control center screen and exit the program.
  • Do not run a scan just yet.
Reboot your computer in "Safe Mode" using the F8 method. To do this, restart your computer and after hearing your computer beep once during startup (but before the Windows icon appears) press the F8 key repeatedly. A menu will appear with several options. Use the arrow keys to navigate and select the option to run Windows in "Safe Mode".

Scan with SUPERAntiSpyware as follows:
  • Launch the program and back on the main screen, under "Scan for Harmful Software" click Scan your computer.
  • On the left, make sure you check C:\Fixed Drive.
  • On the right, under "Complete Scan", choose Perform Complete Scan and click "Next".
  • After the scan is complete, a Scan Summary box will appear with potentially harmful items that were detected. Click "OK".
  • Make sure everything has a checkmark next to it and click "Next".
  • A notification will appear that "Quarantine and Removal is Complete". Click "OK" and then click the "Finish" button to return to the main menu.
  • If asked if you want to reboot, click "Yes" and reboot normally.
  • To retrieve the removal information after reboot, launch SUPERAntispyware again.
    • Click Preferences, then click the Statistics/Logs tab.
    • Under Scanner Logs, double-click SUPERAntiSpyware Scan Log.
    • If there are several logs, click the current dated log and press View log. A text file will open in your default text editor.
    • Please copy and paste the Scan Log results in your next reply.
  • Click Close to exit the program.
If you have a problem downloading, installing or getting SAS to run, try downloading and using the SUPERAntiSpyware Portable Scanner instead. Save the randomly named file (i.e. SAS_1710895.COM) to a usb drive or CD and transfer to the infected computer. Then double-click on it to launch and scan. The file is randomly named to help keep malware from blocking the scanner.

Instructions:

Download and scan with SUPERAntiSpyware Free for Home Users
  • Double-click SUPERAntiSpyware.exe and use the default settings for installation.
  • An icon will be created on your desktop. Double-click that icon to launch the program.
  • If asked to update the program definitions, click "Yes". If not, update the definitions before scanning by selecting "Check for Updates". (If you encounter any problems while downloading the updates, manually download them from here. Double-click on the hyperlink for Download Installer and save SASDEFINITIONS.EXE to your desktop. Then double-click on SASDEFINITIONS.EXE to install the definitions.)
  • In the Main Menu, click the Preferences... button.
  • Click the Scanning Control tab.
  • Under Scanner Options make sure the following are checked (leave all others unchecked):
    • Close browsers before scanning.
    • Scan for tracking cookies.
    • Terminate memory threats before quarantining.
  • Click the "Close" button to leave the control center screen.
  • Back on the main screen, under "Scan for Harmful Software" click Scan your computer.
  • On the left, make sure you check C:\Fixed Drive.
  • On the right, under "Complete Scan", choose Perform Complete Scan.
  • Click "Next" to start the scan. Please be patient while it scans your computer.
  • After the scan is complete, a Scan Summary box will appear with potentially harmful items that were detected. Click "OK".
  • Make sure everything has a checkmark next to it and click "Next".
  • A notification will appear that "Quarantine and Removal is Complete". Click "OK" and then click the "Finish" button to return to the main menu.
  • If asked if you want to reboot, click "Yes".
  • To retrieve the removal information after reboot, launch SUPERAntispyware again.
    • Click Preferences, then click the Statistics/Logs tab.
    • Under Scanner Logs, double-click SUPERAntiSpyware Scan Log.
    • If there are several logs, click the current dated log and press View log. A text file will open in your default text editor.
    • Please copy and paste the Scan Log results in your next reply.
  • Click Close to exit the program.
If you have a problem downloading, installing or getting SAS to run, try downloading and using the SUPERAntiSpyware Portable Scanner instead. Save the randomly named file (i.e. SAS_1710895.COM) to a usb drive or CD and transfer to the infected computer. Then double-click on it to launch and scan. The file is randomly named to help keep malware from blocking the scanner.


Now GMER

GMER does not work in 64bit Mode!!!!!!

Please download GMER from one of the following locations and save it to your desktop:

  • Main Mirror
    This version will download a randomly named file (Recommended)
  • Zipped Mirror
    This version will download a zip file you will need to extract first. If you use this mirror, please extract the zip file to your desktop.
  • Disconnect from the Internet and close all running programs.
  • Temporarily disable any real-time active protection so your security programs will not conflict with gmer's driver.
  • Double-click on the randomly named GMER file (i.e. n7gmo46c.exe) and allow the gmer.sys driver to load if asked.
  • Note: If you downloaded the zipped version, extract the file to its own folder such as C:\gmer and then double-click on gmer.exe.

    Posted Image
  • GMER will open to the Rootkit/Malware tab and perform an automatic Full Scan when first run. (do not use the computer while the scan is in progress)
  • If you receive a WARNING!!! about rootkit activity and are asked to fully scan your system...click NO.
  • Now click the Scan button. If you see a rootkit warning window, click OK.
  • When the scan is finished, click the Save... button to save the scan results to your Desktop. Save the file as gmer.log.
  • Click the Copy button and paste the results into your next reply.
  • Exit GMER and be sure to re-enable your anti-virus, Firewall and any other security programs you had disabled.
-- If you encounter any problems, try running GMER in safe mode.
-- If GMER crashes or keeps resulting in a BSODs, uncheck Devices on the right side before scanning
.



#3 Army_Chef

Army_Chef
  • Topic Starter

  • Members
  • 7 posts
  • OFFLINE
  •  
  • Local time:04:14 PM

Posted 09 November 2010 - 05:41 PM

Cryptodan, many thanks. I'm running the scans now and I'm guessing it will take some time. I'll be back asap with results.

Cheers,

Chef

#4 quietman7

quietman7

    Bleepin' Janitor


  • Global Moderator
  • 51,399 posts
  • OFFLINE
  •  
  • Gender:Male
  • Location:Virginia, USA
  • Local time:12:14 PM

Posted 10 November 2010 - 10:36 AM

It would also be helpful if you can advise the specific file(s) name associated with the malware threat(s) detection and if so, where is it located (full file path) at on your system.

Each security vendor uses their own naming conventions to identify various types of malware so it's difficult to determine exactly what has been detected or the nature of the infection without knowing more information about the actually file(s) involved. See Understanding virus names.

In some cases a Win32.Patched threat detection can be indicative of a dangerous polymorphic file infector with IRCBot functionality such as Virut or Win32/Ramnit.A. This type of malware typically typically infects .exe, .scr files, compressed files (.zip, .cab, .rar), and script files (.php, .asp, .htm, .html, .xml) and opens a back door that compromises your computer. Using this backdoor, a remote attacker can access and instruct the infected computer to download and execute more malicious files.

As such more information is required.
.
.
Windows Insider MVP 2017-2018
Microsoft MVP Reconnect 2016
Microsoft MVP Consumer Security 2007-2015 kO7xOZh.gif
Member of UNITE, Unified Network of Instructors and Trusted Eliminators

If I have been helpful & you'd like to consider a donation, click 38WxTfO.gif

#5 Army_Chef

Army_Chef
  • Topic Starter

  • Members
  • 7 posts
  • OFFLINE
  •  
  • Local time:04:14 PM

Posted 10 November 2010 - 01:41 PM

Cryptodan and quietman7, there now appear to be 2 affected files and they are as follows;

1. c:\Windows\System32\wininit.exe
2. c:\Windows\explorer.exe

I hope the above is a little more helpful.

The three scan logs will now be posted seperatley.

1. Mbam

Malwarebytes' Anti-Malware 1.46
www.malwarebytes.org

Database version: 5084

Windows 6.0.6002 Service Pack 2
Internet Explorer 8.0.6001.18975

10/11/2010 07:21:34
mbam-log-2010-11-10 (07-21-34).txt

Scan type: Full scan (C:\|S:\|)
Objects scanned: 386179
Time elapsed: 2 hour(s), 27 minute(s), 16 second(s)

Memory Processes Infected: 0
Memory Modules Infected: 0
Registry Keys Infected: 8
Registry Values Infected: 0
Registry Data Items Infected: 0
Folders Infected: 2
Files Infected: 18

Memory Processes Infected:
(No malicious items detected)

Memory Modules Infected:
(No malicious items detected)

Registry Keys Infected:
HKEY_CURRENT_USER\SOFTWARE\ShoppingReport (Adware.ShopperReports) -> Quarantined and deleted successfully.
HKEY_CURRENT_USER\SOFTWARE\zangosa (Adware.Zango) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Low Rights\RunDll32Policy\f3ScrCtr.dll (Adware.MyWebSearch) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Multimedia\WMPlayer\Schemes\f3pss (Adware.MyWebSearch) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Office\Outlook\Addins\HostOL.MailAnim (Adware.Hotbar) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Office\Word\Addins\HostOL.MailAnim (Adware.Hotbar) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\RelatedPageInstall (Adware.Mirar) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\ShoppingReport (Adware.ShopperReports) -> Quarantined and deleted successfully.

Registry Values Infected:
(No malicious items detected)

Registry Data Items Infected:
(No malicious items detected)

Folders Infected:
C:\Users\Leslie Ball\AppData\Roaming\Zango (Adware.Zango) -> Delete on reboot.
C:\ProgramData\ZangoSA (Adware.Zango) -> Quarantined and deleted successfully.

Files Infected:
C:\Program Files\Windows Live\Messenger\msimg32.dll (Adware.MyWebSearch) -> Quarantined and deleted successfully.
C:\Program Files\Windows Live\Messenger\riched20.dll (Adware.MyWebSearch) -> Quarantined and deleted successfully.
C:\Program Files\Microsoft\WaterMark.exe (Spyware.Passwords.XGen) -> Quarantined and deleted successfully.
C:\Program Files\Platinum Hide IP\Patch\PATCH.exe (RiskWare.Tool.CK) -> Quarantined and deleted successfully.
C:\Users\Leslie Ball\AppData\Roaming\Save\SaveUninst.exe (Trojan.Agent) -> Quarantined and deleted successfully.
C:\Windows\Temp\~TM4940.tmp (Spyware.Passwords.XGen) -> Quarantined and deleted successfully.
C:\ProgramData\ZangoSA\ZangoSA.dat (Adware.Zango) -> Quarantined and deleted successfully.
C:\ProgramData\ZangoSA\ZangoSAAbout.mht (Adware.Zango) -> Quarantined and deleted successfully.
C:\ProgramData\ZangoSA\ZangoSAau.dat (Adware.Zango) -> Quarantined and deleted successfully.
C:\ProgramData\ZangoSA\ZangoSAEula.mht (Adware.Zango) -> Quarantined and deleted successfully.
C:\ProgramData\ZangoSA\ZangoSA_kyf.dat (Adware.Zango) -> Quarantined and deleted successfully.
C:\Users\Leslie Ball\AppData\Roaming\02000000fc790c5c670C.manifest (Malware.Trace) -> Quarantined and deleted successfully.
C:\Users\Leslie Ball\AppData\Roaming\02000000fc790c5c670O.manifest (Malware.Trace) -> Quarantined and deleted successfully.
C:\Users\Leslie Ball\AppData\Roaming\02000000fc790c5c670P.manifest (Malware.Trace) -> Quarantined and deleted successfully.
C:\Users\Leslie Ball\AppData\Roaming\02000000fc790c5c670S.manifest (Malware.Trace) -> Quarantined and deleted successfully.
C:\Users\Public\Documents\Server\admin.txt (Malware.Trace) -> Quarantined and deleted successfully.
C:\Users\Public\Documents\Server\server.dat (Malware.Trace) -> Quarantined and deleted successfully.
C:\Windows\Tasks\{22116563-108C-42c0-A7CE-60161B75E508}.job (Trojan.Downloader) -> Quarantined and deleted successfully.

#6 Army_Chef

Army_Chef
  • Topic Starter

  • Members
  • 7 posts
  • OFFLINE
  •  
  • Local time:04:14 PM

Posted 10 November 2010 - 01:44 PM

2. SuperAntiSpyware

SUPERAntiSpyware Scan Log
http://www.superantispyware.com

Generated 11/10/2010 at 10:17 AM

Application Version : 4.45.1000

Core Rules Database Version : 5838
Trace Rules Database Version: 3650

Scan type : Complete Scan
Total Scan Time : 02:19:03

Memory items scanned : 273
Memory threats detected : 0
Registry items scanned : 9955
Registry threats detected : 2
File items scanned : 235992
File threats detected : 728

Adware.Tracking Cookie
C:\Users\Leslie Ball\AppData\Roaming\Microsoft\Windows\Cookies\leslie_ball@serving-sys[2].txt
C:\Users\Leslie Ball\AppData\Roaming\Microsoft\Windows\Cookies\leslie_ball@atdmt[2].txt
C:\Users\Leslie Ball\AppData\Roaming\Microsoft\Windows\Cookies\leslie_ball@adbrite[1].txt
C:\Users\Leslie Ball\AppData\Roaming\Microsoft\Windows\Cookies\leslie_ball@bs.serving-sys[1].txt
C:\Users\Leslie Ball\AppData\Roaming\Microsoft\Windows\Cookies\leslie_ball@doubleclick[3].txt
adserver.com.br [ C:\Users\Leslie Ball\AppData\Local\Microsoft\Windows\Temporary Internet Files\Virtualized\C\Users\Leslie Ball\AppData\Roaming\Macromedia\Flash Player\#SharedObjects\YWL8DEKD ]
atdmt.com [ C:\Users\Leslie Ball\AppData\Local\Microsoft\Windows\Temporary Internet Files\Virtualized\C\Users\Leslie Ball\AppData\Roaming\Macromedia\Flash Player\#SharedObjects\YWL8DEKD ]
dmcupdate.trackitdown.net [ C:\Users\Leslie Ball\AppData\Local\Microsoft\Windows\Temporary Internet Files\Virtualized\C\Users\Leslie Ball\AppData\Roaming\Macromedia\Flash Player\#SharedObjects\YWL8DEKD ]
enterotracker.de [ C:\Users\Leslie Ball\AppData\Local\Microsoft\Windows\Temporary Internet Files\Virtualized\C\Users\Leslie Ball\AppData\Roaming\Macromedia\Flash Player\#SharedObjects\YWL8DEKD ]
googleads.g.doubleclick.net [ C:\Users\Leslie Ball\AppData\Local\Microsoft\Windows\Temporary Internet Files\Virtualized\C\Users\Leslie Ball\AppData\Roaming\Macromedia\Flash Player\#SharedObjects\YWL8DEKD ]
img-cdn.mediaplex.com [ C:\Users\Leslie Ball\AppData\Local\Microsoft\Windows\Temporary Internet Files\Virtualized\C\Users\Leslie Ball\AppData\Roaming\Macromedia\Flash Player\#SharedObjects\YWL8DEKD ]
m.uk.2mdn.net [ C:\Users\Leslie Ball\AppData\Local\Microsoft\Windows\Temporary Internet Files\Virtualized\C\Users\Leslie Ball\AppData\Roaming\Macromedia\Flash Player\#SharedObjects\YWL8DEKD ]
m1.2mdn.net [ C:\Users\Leslie Ball\AppData\Local\Microsoft\Windows\Temporary Internet Files\Virtualized\C\Users\Leslie Ball\AppData\Roaming\Macromedia\Flash Player\#SharedObjects\YWL8DEKD ]
m1.emea.2mdn.net [ C:\Users\Leslie Ball\AppData\Local\Microsoft\Windows\Temporary Internet Files\Virtualized\C\Users\Leslie Ball\AppData\Roaming\Macromedia\Flash Player\#SharedObjects\YWL8DEKD ]
media.tattomedia.com [ C:\Users\Leslie Ball\AppData\Local\Microsoft\Windows\Temporary Internet Files\Virtualized\C\Users\Leslie Ball\AppData\Roaming\Macromedia\Flash Player\#SharedObjects\YWL8DEKD ]
paulvelocity.trackitdown.net [ C:\Users\Leslie Ball\AppData\Local\Microsoft\Windows\Temporary Internet Files\Virtualized\C\Users\Leslie Ball\AppData\Roaming\Macromedia\Flash Player\#SharedObjects\YWL8DEKD ]
uk.2mdn.net [ C:\Users\Leslie Ball\AppData\Local\Microsoft\Windows\Temporary Internet Files\Virtualized\C\Users\Leslie Ball\AppData\Roaming\Macromedia\Flash Player\#SharedObjects\YWL8DEKD ]
uktrancealliance.trackitdown.net [ C:\Users\Leslie Ball\AppData\Local\Microsoft\Windows\Temporary Internet Files\Virtualized\C\Users\Leslie Ball\AppData\Roaming\Macromedia\Flash Player\#SharedObjects\YWL8DEKD ]
www.pornhub.com [ C:\Users\Leslie Ball\AppData\Local\Microsoft\Windows\Temporary Internet Files\Virtualized\C\Users\Leslie Ball\AppData\Roaming\Macromedia\Flash Player\#SharedObjects\YWL8DEKD ]
www.trackitdown.net [ C:\Users\Leslie Ball\AppData\Local\Microsoft\Windows\Temporary Internet Files\Virtualized\C\Users\Leslie Ball\AppData\Roaming\Macromedia\Flash Player\#SharedObjects\YWL8DEKD ]
2mdn.net [ C:\Users\Leslie Ball\AppData\Roaming\Macromedia\Flash Player\#SharedObjects\YWL8DEKD ]
acvs.mediaonenetwork.net [ C:\Users\Leslie Ball\AppData\Roaming\Macromedia\Flash Player\#SharedObjects\YWL8DEKD ]
ads1.msn.com [ C:\Users\Leslie Ball\AppData\Roaming\Macromedia\Flash Player\#SharedObjects\YWL8DEKD ]
appsmedia.threerings.net [ C:\Users\Leslie Ball\AppData\Roaming\Macromedia\Flash Player\#SharedObjects\YWL8DEKD ]
atdmt.com [ C:\Users\Leslie Ball\AppData\Roaming\Macromedia\Flash Player\#SharedObjects\YWL8DEKD ]
bc.youporn.com [ C:\Users\Leslie Ball\AppData\Roaming\Macromedia\Flash Player\#SharedObjects\YWL8DEKD ]
broadcast.piximedia.fr [ C:\Users\Leslie Ball\AppData\Roaming\Macromedia\Flash Player\#SharedObjects\YWL8DEKD ]
cdn-www.pornhub.com [ C:\Users\Leslie Ball\AppData\Roaming\Macromedia\Flash Player\#SharedObjects\YWL8DEKD ]
cdn4.specificclick.net [ C:\Users\Leslie Ball\AppData\Roaming\Macromedia\Flash Player\#SharedObjects\YWL8DEKD ]
cdn5.specificclick.net [ C:\Users\Leslie Ball\AppData\Roaming\Macromedia\Flash Player\#SharedObjects\YWL8DEKD ]
cloud.video.unrulymedia.com [ C:\Users\Leslie Ball\AppData\Roaming\Macromedia\Flash Player\#SharedObjects\YWL8DEKD ]
content.oddcast.com [ C:\Users\Leslie Ball\AppData\Roaming\Macromedia\Flash Player\#SharedObjects\YWL8DEKD ]
core.insightexpressai.com [ C:\Users\Leslie Ball\AppData\Roaming\Macromedia\Flash Player\#SharedObjects\YWL8DEKD ]
crackle.com [ C:\Users\Leslie Ball\AppData\Roaming\Macromedia\Flash Player\#SharedObjects\YWL8DEKD ]
dmcupdate.trackitdown.net [ C:\Users\Leslie Ball\AppData\Roaming\Macromedia\Flash Player\#SharedObjects\YWL8DEKD ]
ds.serving-sys.com [ C:\Users\Leslie Ball\AppData\Roaming\Macromedia\Flash Player\#SharedObjects\YWL8DEKD ]
ec.atdmt.com [ C:\Users\Leslie Ball\AppData\Roaming\Macromedia\Flash Player\#SharedObjects\YWL8DEKD ]
files.youporn.com [ C:\Users\Leslie Ball\AppData\Roaming\Macromedia\Flash Player\#SharedObjects\YWL8DEKD ]
googleads.g.doubleclick.net [ C:\Users\Leslie Ball\AppData\Roaming\Macromedia\Flash Player\#SharedObjects\YWL8DEKD ]
gw.callingbanners.com [ C:\Users\Leslie Ball\AppData\Roaming\Macromedia\Flash Player\#SharedObjects\YWL8DEKD ]
hottraffic.nl [ C:\Users\Leslie Ball\AppData\Roaming\Macromedia\Flash Player\#SharedObjects\YWL8DEKD ]
ia.media-imdb.com [ C:\Users\Leslie Ball\AppData\Roaming\Macromedia\Flash Player\#SharedObjects\YWL8DEKD ]
img-cdn.mediaplex.com [ C:\Users\Leslie Ball\AppData\Roaming\Macromedia\Flash Player\#SharedObjects\YWL8DEKD ]
m.uk.2mdn.net [ C:\Users\Leslie Ball\AppData\Roaming\Macromedia\Flash Player\#SharedObjects\YWL8DEKD ]
m1.2mdn.net [ C:\Users\Leslie Ball\AppData\Roaming\Macromedia\Flash Player\#SharedObjects\YWL8DEKD ]
m1.emea.2mdn.net [ C:\Users\Leslie Ball\AppData\Roaming\Macromedia\Flash Player\#SharedObjects\YWL8DEKD ]
media.heavy.com [ C:\Users\Leslie Ball\AppData\Roaming\Macromedia\Flash Player\#SharedObjects\YWL8DEKD ]
media.kyte.tv [ C:\Users\Leslie Ball\AppData\Roaming\Macromedia\Flash Player\#SharedObjects\YWL8DEKD ]
media.scanscout.com [ C:\Users\Leslie Ball\AppData\Roaming\Macromedia\Flash Player\#SharedObjects\YWL8DEKD ]
media.tattomedia.com [ C:\Users\Leslie Ball\AppData\Roaming\Macromedia\Flash Player\#SharedObjects\YWL8DEKD ]
media1.break.com [ C:\Users\Leslie Ball\AppData\Roaming\Macromedia\Flash Player\#SharedObjects\YWL8DEKD ]
msntest.serving-sys.com [ C:\Users\Leslie Ball\AppData\Roaming\Macromedia\Flash Player\#SharedObjects\YWL8DEKD ]
naiadsystems.com [ C:\Users\Leslie Ball\AppData\Roaming\Macromedia\Flash Player\#SharedObjects\YWL8DEKD ]
objects.tremormedia.com [ C:\Users\Leslie Ball\AppData\Roaming\Macromedia\Flash Player\#SharedObjects\YWL8DEKD ]
s0.2mdn.net [ C:\Users\Leslie Ball\AppData\Roaming\Macromedia\Flash Player\#SharedObjects\YWL8DEKD ]
secure-uk.imrworldwide.com [ C:\Users\Leslie Ball\AppData\Roaming\Macromedia\Flash Player\#SharedObjects\YWL8DEKD ]
secure-us.imrworldwide.com [ C:\Users\Leslie Ball\AppData\Roaming\Macromedia\Flash Player\#SharedObjects\YWL8DEKD ]
serving-sys.com [ C:\Users\Leslie Ball\AppData\Roaming\Macromedia\Flash Player\#SharedObjects\YWL8DEKD ]
spe.atdmt.com [ C:\Users\Leslie Ball\AppData\Roaming\Macromedia\Flash Player\#SharedObjects\YWL8DEKD ]
static.2mdn.net [ C:\Users\Leslie Ball\AppData\Roaming\Macromedia\Flash Player\#SharedObjects\YWL8DEKD ]
static.youporn.com [ C:\Users\Leslie Ball\AppData\Roaming\Macromedia\Flash Player\#SharedObjects\YWL8DEKD ]
track.webgains.com [ C:\Users\Leslie Ball\AppData\Roaming\Macromedia\Flash Player\#SharedObjects\YWL8DEKD ]
trinity-adserver-003.co.uk [ C:\Users\Leslie Ball\AppData\Roaming\Macromedia\Flash Player\#SharedObjects\YWL8DEKD ]
uk.2mdn.net [ C:\Users\Leslie Ball\AppData\Roaming\Macromedia\Flash Player\#SharedObjects\YWL8DEKD ]
uktrancealliance.trackitdown.net [ C:\Users\Leslie Ball\AppData\Roaming\Macromedia\Flash Player\#SharedObjects\YWL8DEKD ]
video.redorbit.com [ C:\Users\Leslie Ball\AppData\Roaming\Macromedia\Flash Player\#SharedObjects\YWL8DEKD ]
www.99counters.com [ C:\Users\Leslie Ball\AppData\Roaming\Macromedia\Flash Player\#SharedObjects\YWL8DEKD ]
www.naiadsystems.com [ C:\Users\Leslie Ball\AppData\Roaming\Macromedia\Flash Player\#SharedObjects\YWL8DEKD ]
www.pornhub.com [ C:\Users\Leslie Ball\AppData\Roaming\Macromedia\Flash Player\#SharedObjects\YWL8DEKD ]
www.trackitdown.net [ C:\Users\Leslie Ball\AppData\Roaming\Macromedia\Flash Player\#SharedObjects\YWL8DEKD ]
www.uporn.com [ C:\Users\Leslie Ball\AppData\Roaming\Macromedia\Flash Player\#SharedObjects\YWL8DEKD ]
C:\Users\Leslie Ball\AppData\Roaming\Microsoft\Windows\Cookies\leslie_ball@atdmt[1].txt
C:\Users\Leslie Ball\AppData\Roaming\Microsoft\Windows\Cookies\leslie_ball@doubleclick[2].txt
C:\Users\Leslie Ball\AppData\Roaming\Microsoft\Windows\Cookies\Low\leslie_ball@0.e.r.cltomedia[2].txt
C:\Users\Leslie Ball\AppData\Roaming\Microsoft\Windows\Cookies\Low\leslie_ball@1.i.r.cltomedia[1].txt
C:\Users\Leslie Ball\AppData\Roaming\Microsoft\Windows\Cookies\Low\leslie_ball@112.2o7[1].txt
C:\Users\Leslie Ball\AppData\Roaming\Microsoft\Windows\Cookies\Low\leslie_ball@247realmedia[1].txt
C:\Users\Leslie Ball\AppData\Roaming\Microsoft\Windows\Cookies\Low\leslie_ball@247realmedia[2].txt
C:\Users\Leslie Ball\AppData\Roaming\Microsoft\Windows\Cookies\Low\leslie_ball@2o7[1].txt
C:\Users\Leslie Ball\AppData\Roaming\Microsoft\Windows\Cookies\Low\leslie_ball@2o7[3].txt
C:\Users\Leslie Ball\AppData\Roaming\Microsoft\Windows\Cookies\Low\leslie_ball@3.g.e.cltomedia[1].txt
C:\Users\Leslie Ball\AppData\Roaming\Microsoft\Windows\Cookies\Low\leslie_ball@3.n.e.cltomedia[2].txt
C:\Users\Leslie Ball\AppData\Roaming\Microsoft\Windows\Cookies\Low\leslie_ball@3.q.d.cltomedia[2].txt
C:\Users\Leslie Ball\AppData\Roaming\Microsoft\Windows\Cookies\Low\leslie_ball@77tracking[1].txt
C:\Users\Leslie Ball\AppData\Roaming\Microsoft\Windows\Cookies\Low\leslie_ball@a1.interclick[2].txt
C:\Users\Leslie Ball\AppData\Roaming\Microsoft\Windows\Cookies\Low\leslie_ball@ad.ad-srv[2].txt
C:\Users\Leslie Ball\AppData\Roaming\Microsoft\Windows\Cookies\Low\leslie_ball@ad.adnet[2].txt
C:\Users\Leslie Ball\AppData\Roaming\Microsoft\Windows\Cookies\Low\leslie_ball@ad.adnet[3].txt
C:\Users\Leslie Ball\AppData\Roaming\Microsoft\Windows\Cookies\Low\leslie_ball@ad.adocean[2].txt
C:\Users\Leslie Ball\AppData\Roaming\Microsoft\Windows\Cookies\Low\leslie_ball@ad.adocean[3].txt
C:\Users\Leslie Ball\AppData\Roaming\Microsoft\Windows\Cookies\Low\leslie_ball@ad.reklamport[2].txt
C:\Users\Leslie Ball\AppData\Roaming\Microsoft\Windows\Cookies\Low\leslie_ball@ad.yieldmanager[10].txt
C:\Users\Leslie Ball\AppData\Roaming\Microsoft\Windows\Cookies\Low\leslie_ball@ad.yieldmanager[11].txt
C:\Users\Leslie Ball\AppData\Roaming\Microsoft\Windows\Cookies\Low\leslie_ball@ad.yieldmanager[1].txt
C:\Users\Leslie Ball\AppData\Roaming\Microsoft\Windows\Cookies\Low\leslie_ball@ad.yieldmanager[2].txt
C:\Users\Leslie Ball\AppData\Roaming\Microsoft\Windows\Cookies\Low\leslie_ball@ad.yieldmanager[3].txt
C:\Users\Leslie Ball\AppData\Roaming\Microsoft\Windows\Cookies\Low\leslie_ball@ad.yieldmanager[4].txt
C:\Users\Leslie Ball\AppData\Roaming\Microsoft\Windows\Cookies\Low\leslie_ball@ad.yieldmanager[5].txt
C:\Users\Leslie Ball\AppData\Roaming\Microsoft\Windows\Cookies\Low\leslie_ball@ad.yieldmanager[6].txt
C:\Users\Leslie Ball\AppData\Roaming\Microsoft\Windows\Cookies\Low\leslie_ball@ad.yieldmanager[7].txt
C:\Users\Leslie Ball\AppData\Roaming\Microsoft\Windows\Cookies\Low\leslie_ball@ad.yieldmanager[8].txt
C:\Users\Leslie Ball\AppData\Roaming\Microsoft\Windows\Cookies\Low\leslie_ball@ad.yieldmanager[9].txt
C:\Users\Leslie Ball\AppData\Roaming\Microsoft\Windows\Cookies\Low\leslie_ball@ad.zanox[2].txt
C:\Users\Leslie Ball\AppData\Roaming\Microsoft\Windows\Cookies\Low\leslie_ball@ad1.advmaker[1].txt
C:\Users\Leslie Ball\AppData\Roaming\Microsoft\Windows\Cookies\Low\leslie_ball@ad2.doublepimp[1].txt
C:\Users\Leslie Ball\AppData\Roaming\Microsoft\Windows\Cookies\Low\leslie_ball@adbrite[1].txt
C:\Users\Leslie Ball\AppData\Roaming\Microsoft\Windows\Cookies\Low\leslie_ball@adbrite[2].txt
C:\Users\Leslie Ball\AppData\Roaming\Microsoft\Windows\Cookies\Low\leslie_ball@adbrite[4].txt
C:\Users\Leslie Ball\AppData\Roaming\Microsoft\Windows\Cookies\Low\leslie_ball@adbrite[5].txt
C:\Users\Leslie Ball\AppData\Roaming\Microsoft\Windows\Cookies\Low\leslie_ball@adecn[2].txt
C:\Users\Leslie Ball\AppData\Roaming\Microsoft\Windows\Cookies\Low\leslie_ball@adecn[3].txt
C:\Users\Leslie Ball\AppData\Roaming\Microsoft\Windows\Cookies\Low\leslie_ball@adfarm1.adition[1].txt
C:\Users\Leslie Ball\AppData\Roaming\Microsoft\Windows\Cookies\Low\leslie_ball@adinterax[2].txt
C:\Users\Leslie Ball\AppData\Roaming\Microsoft\Windows\Cookies\Low\leslie_ball@ads.4shared[1].txt
C:\Users\Leslie Ball\AppData\Roaming\Microsoft\Windows\Cookies\Low\leslie_ball@ads.ad4game[2].txt
C:\Users\Leslie Ball\AppData\Roaming\Microsoft\Windows\Cookies\Low\leslie_ball@ads.addynamix[1].txt
C:\Users\Leslie Ball\AppData\Roaming\Microsoft\Windows\Cookies\Low\leslie_ball@ads.adultadvertising[1].txt
C:\Users\Leslie Ball\AppData\Roaming\Microsoft\Windows\Cookies\Low\leslie_ball@ads.aol.co[1].txt
C:\Users\Leslie Ball\AppData\Roaming\Microsoft\Windows\Cookies\Low\leslie_ball@ads.apn.co[1].txt
C:\Users\Leslie Ball\AppData\Roaming\Microsoft\Windows\Cookies\Low\leslie_ball@ads.associatedcontent[2].txt
C:\Users\Leslie Ball\AppData\Roaming\Microsoft\Windows\Cookies\Low\leslie_ball@ads.audience2media[1].txt
C:\Users\Leslie Ball\AppData\Roaming\Microsoft\Windows\Cookies\Low\leslie_ball@ads.audience2media[2].txt
C:\Users\Leslie Ball\AppData\Roaming\Microsoft\Windows\Cookies\Low\leslie_ball@ads.audxch[1].txt
C:\Users\Leslie Ball\AppData\Roaming\Microsoft\Windows\Cookies\Low\leslie_ball@ads.bcserving[2].txt
C:\Users\Leslie Ball\AppData\Roaming\Microsoft\Windows\Cookies\Low\leslie_ball@ads.bleepingcomputer[1].txt
C:\Users\Leslie Ball\AppData\Roaming\Microsoft\Windows\Cookies\Low\leslie_ball@ads.bootcampmedia[2].txt
C:\Users\Leslie Ball\AppData\Roaming\Microsoft\Windows\Cookies\Low\leslie_ball@ads.bridgetrack[2].txt
C:\Users\Leslie Ball\AppData\Roaming\Microsoft\Windows\Cookies\Low\leslie_ball@ads.creafi[2].txt
C:\Users\Leslie Ball\AppData\Roaming\Microsoft\Windows\Cookies\Low\leslie_ball@ads.ctasnet[1].txt
C:\Users\Leslie Ball\AppData\Roaming\Microsoft\Windows\Cookies\Low\leslie_ball@ads.ctasnet[2].txt
C:\Users\Leslie Ball\AppData\Roaming\Microsoft\Windows\Cookies\Low\leslie_ball@ads.easyad[1].txt
C:\Users\Leslie Ball\AppData\Roaming\Microsoft\Windows\Cookies\Low\leslie_ball@ads.elevanet[1].txt
C:\Users\Leslie Ball\AppData\Roaming\Microsoft\Windows\Cookies\Low\leslie_ball@ads.eyecuedigital[1].txt
C:\Users\Leslie Ball\AppData\Roaming\Microsoft\Windows\Cookies\Low\leslie_ball@ads.ft[2].txt
C:\Users\Leslie Ball\AppData\Roaming\Microsoft\Windows\Cookies\Low\leslie_ball@ads.fulldls[2].txt
C:\Users\Leslie Ball\AppData\Roaming\Microsoft\Windows\Cookies\Low\leslie_ball@ads.fulldls[3].txt
C:\Users\Leslie Ball\AppData\Roaming\Microsoft\Windows\Cookies\Low\leslie_ball@ads.gmodules[1].txt
C:\Users\Leslie Ball\AppData\Roaming\Microsoft\Windows\Cookies\Low\leslie_ball@ads.mefeedia[1].txt
C:\Users\Leslie Ball\AppData\Roaming\Microsoft\Windows\Cookies\Low\leslie_ball@ads.neudesicmediagroup[1].txt
C:\Users\Leslie Ball\AppData\Roaming\Microsoft\Windows\Cookies\Low\leslie_ball@ads.ookla[2].txt
C:\Users\Leslie Ball\AppData\Roaming\Microsoft\Windows\Cookies\Low\leslie_ball@ads.pointroll[1].txt
C:\Users\Leslie Ball\AppData\Roaming\Microsoft\Windows\Cookies\Low\leslie_ball@ads.pubmatic[1].txt
C:\Users\Leslie Ball\AppData\Roaming\Microsoft\Windows\Cookies\Low\leslie_ball@ads.pubmatic[2].txt
C:\Users\Leslie Ball\AppData\Roaming\Microsoft\Windows\Cookies\Low\leslie_ball@ads.pubmatic[3].txt
C:\Users\Leslie Ball\AppData\Roaming\Microsoft\Windows\Cookies\Low\leslie_ball@ads.pubmatic[5].txt
C:\Users\Leslie Ball\AppData\Roaming\Microsoft\Windows\Cookies\Low\leslie_ball@ads.raasnet[2].txt
C:\Users\Leslie Ball\AppData\Roaming\Microsoft\Windows\Cookies\Low\leslie_ball@ads.techno4ever[1].txt
C:\Users\Leslie Ball\AppData\Roaming\Microsoft\Windows\Cookies\Low\leslie_ball@ads.telegraph.co[2].txt
C:\Users\Leslie Ball\AppData\Roaming\Microsoft\Windows\Cookies\Low\leslie_ball@ads.trackitdown[1].txt
C:\Users\Leslie Ball\AppData\Roaming\Microsoft\Windows\Cookies\Low\leslie_ball@ads.trackitdown[2].txt
C:\Users\Leslie Ball\AppData\Roaming\Microsoft\Windows\Cookies\Low\leslie_ball@ads.undertone[2].txt
C:\Users\Leslie Ball\AppData\Roaming\Microsoft\Windows\Cookies\Low\leslie_ball@ads.vertor[2].txt
C:\Users\Leslie Ball\AppData\Roaming\Microsoft\Windows\Cookies\Low\leslie_ball@ads.webstacja[2].txt
C:\Users\Leslie Ball\AppData\Roaming\Microsoft\Windows\Cookies\Low\leslie_ball@adserv.crossrhythms.co[1].txt
C:\Users\Leslie Ball\AppData\Roaming\Microsoft\Windows\Cookies\Low\leslie_ball@adserv.getyourglamtone[1].txt
C:\Users\Leslie Ball\AppData\Roaming\Microsoft\Windows\Cookies\Low\leslie_ball@adserver.adreactor[1].txt
C:\Users\Leslie Ball\AppData\Roaming\Microsoft\Windows\Cookies\Low\leslie_ball@adserver.adreactor[2].txt
C:\Users\Leslie Ball\AppData\Roaming\Microsoft\Windows\Cookies\Low\leslie_ball@adserver.adtechus[1].txt
C:\Users\Leslie Ball\AppData\Roaming\Microsoft\Windows\Cookies\Low\leslie_ball@adserver.adtechus[2].txt
C:\Users\Leslie Ball\AppData\Roaming\Microsoft\Windows\Cookies\Low\leslie_ball@adserver.seedpeer[1].txt
C:\Users\Leslie Ball\AppData\Roaming\Microsoft\Windows\Cookies\Low\leslie_ball@adserver.socialspark[1].txt
C:\Users\Leslie Ball\AppData\Roaming\Microsoft\Windows\Cookies\Low\leslie_ball@adserving.aedgency[2].txt
C:\Users\Leslie Ball\AppData\Roaming\Microsoft\Windows\Cookies\Low\leslie_ball@adserving.ezanga[2].txt
C:\Users\Leslie Ball\AppData\Roaming\Microsoft\Windows\Cookies\Low\leslie_ball@adsrv.clickvol[1].txt
C:\Users\Leslie Ball\AppData\Roaming\Microsoft\Windows\Cookies\Low\leslie_ball@adtech.staticwhich.co[2].txt
C:\Users\Leslie Ball\AppData\Roaming\Microsoft\Windows\Cookies\Low\leslie_ball@adtech[1].txt
C:\Users\Leslie Ball\AppData\Roaming\Microsoft\Windows\Cookies\Low\leslie_ball@adtech[2].txt
C:\Users\Leslie Ball\AppData\Roaming\Microsoft\Windows\Cookies\Low\leslie_ball@adtech[3].txt
C:\Users\Leslie Ball\AppData\Roaming\Microsoft\Windows\Cookies\Low\leslie_ball@adtech[4].txt
C:\Users\Leslie Ball\AppData\Roaming\Microsoft\Windows\Cookies\Low\leslie_ball@adultfriendfinder[1].txt
C:\Users\Leslie Ball\AppData\Roaming\Microsoft\Windows\Cookies\Low\leslie_ball@adultfriendfinder[2].txt
C:\Users\Leslie Ball\AppData\Roaming\Microsoft\Windows\Cookies\Low\leslie_ball@adultfriendfinder[3].txt
C:\Users\Leslie Ball\AppData\Roaming\Microsoft\Windows\Cookies\Low\leslie_ball@adultfriendfinder[4].txt
C:\Users\Leslie Ball\AppData\Roaming\Microsoft\Windows\Cookies\Low\leslie_ball@adultfriendfinder[5].txt
C:\Users\Leslie Ball\AppData\Roaming\Microsoft\Windows\Cookies\Low\leslie_ball@adv.advmaker[1].txt
C:\Users\Leslie Ball\AppData\Roaming\Microsoft\Windows\Cookies\Low\leslie_ball@adv.bewebmedia[1].txt
C:\Users\Leslie Ball\AppData\Roaming\Microsoft\Windows\Cookies\Low\leslie_ball@adverticum[2].txt
C:\Users\Leslie Ball\AppData\Roaming\Microsoft\Windows\Cookies\Low\leslie_ball@advertising[1].txt
C:\Users\Leslie Ball\AppData\Roaming\Microsoft\Windows\Cookies\Low\leslie_ball@advertising[2].txt
C:\Users\Leslie Ball\AppData\Roaming\Microsoft\Windows\Cookies\Low\leslie_ball@advertising[3].txt
C:\Users\Leslie Ball\AppData\Roaming\Microsoft\Windows\Cookies\Low\leslie_ball@advertising[4].txt
C:\Users\Leslie Ball\AppData\Roaming\Microsoft\Windows\Cookies\Low\leslie_ball@advertising[6].txt
C:\Users\Leslie Ball\AppData\Roaming\Microsoft\Windows\Cookies\Low\leslie_ball@adverts.forargyll[2].txt
C:\Users\Leslie Ball\AppData\Roaming\Microsoft\Windows\Cookies\Low\leslie_ball@adviva[1].txt
C:\Users\Leslie Ball\AppData\Roaming\Microsoft\Windows\Cookies\Low\leslie_ball@adviva[2].txt
C:\Users\Leslie Ball\AppData\Roaming\Microsoft\Windows\Cookies\Low\leslie_ball@adviva[3].txt
C:\Users\Leslie Ball\AppData\Roaming\Microsoft\Windows\Cookies\Low\leslie_ball@adviva[5].txt
C:\Users\Leslie Ball\AppData\Roaming\Microsoft\Windows\Cookies\Low\leslie_ball@adviva[6].txt
C:\Users\Leslie Ball\AppData\Roaming\Microsoft\Windows\Cookies\Low\leslie_ball@adxpose[1].txt
C:\Users\Leslie Ball\AppData\Roaming\Microsoft\Windows\Cookies\Low\leslie_ball@adxpose[2].txt
C:\Users\Leslie Ball\AppData\Roaming\Microsoft\Windows\Cookies\Low\leslie_ball@aimfar.solution.weborama[1].txt
C:\Users\Leslie Ball\AppData\Roaming\Microsoft\Windows\Cookies\Low\leslie_ball@answerstv.112.2o7[1].txt
C:\Users\Leslie Ball\AppData\Roaming\Microsoft\Windows\Cookies\Low\leslie_ball@apmebf[1].txt
C:\Users\Leslie Ball\AppData\Roaming\Microsoft\Windows\Cookies\Low\leslie_ball@apmebf[2].txt
C:\Users\Leslie Ball\AppData\Roaming\Microsoft\Windows\Cookies\Low\leslie_ball@apmebf[3].txt
C:\Users\Leslie Ball\AppData\Roaming\Microsoft\Windows\Cookies\Low\leslie_ball@apnonline.112.2o7[1].txt
C:\Users\Leslie Ball\AppData\Roaming\Microsoft\Windows\Cookies\Low\leslie_ball@associatedcontent.112.2o7[1].txt
C:\Users\Leslie Ball\AppData\Roaming\Microsoft\Windows\Cookies\Low\leslie_ball@at.atwola[1].txt
C:\Users\Leslie Ball\AppData\Roaming\Microsoft\Windows\Cookies\Low\leslie_ball@at.atwola[2].txt
C:\Users\Leslie Ball\AppData\Roaming\Microsoft\Windows\Cookies\Low\leslie_ball@atdmt[1].txt
C:\Users\Leslie Ball\AppData\Roaming\Microsoft\Windows\Cookies\Low\leslie_ball@atdmt[2].txt
C:\Users\Leslie Ball\AppData\Roaming\Microsoft\Windows\Cookies\Low\leslie_ball@atlas.entrepreneur[1].txt
C:\Users\Leslie Ball\AppData\Roaming\Microsoft\Windows\Cookies\Low\leslie_ball@audience2media[1].txt
C:\Users\Leslie Ball\AppData\Roaming\Microsoft\Windows\Cookies\Low\leslie_ball@audience2media[2].txt
C:\Users\Leslie Ball\AppData\Roaming\Microsoft\Windows\Cookies\Low\leslie_ball@audience2media[3].txt
C:\Users\Leslie Ball\AppData\Roaming\Microsoft\Windows\Cookies\Low\leslie_ball@audience2media[4].txt
C:\Users\Leslie Ball\AppData\Roaming\Microsoft\Windows\Cookies\Low\leslie_ball@audit.median[1].txt
C:\Users\Leslie Ball\AppData\Roaming\Microsoft\Windows\Cookies\Low\leslie_ball@avgtechnologies.112.2o7[1].txt
C:\Users\Leslie Ball\AppData\Roaming\Microsoft\Windows\Cookies\Low\leslie_ball@avgtechnologies.112.2o7[2].txt
C:\Users\Leslie Ball\AppData\Roaming\Microsoft\Windows\Cookies\Low\leslie_ball@avivauk.122.2o7[1].txt
C:\Users\Leslie Ball\AppData\Roaming\Microsoft\Windows\Cookies\Low\leslie_ball@azjmp[1].txt
C:\Users\Leslie Ball\AppData\Roaming\Microsoft\Windows\Cookies\Low\leslie_ball@b.n.d.cltomedia[2].txt
C:\Users\Leslie Ball\AppData\Roaming\Microsoft\Windows\Cookies\Low\leslie_ball@b.s.d.cltomedia[2].txt
C:\Users\Leslie Ball\AppData\Roaming\Microsoft\Windows\Cookies\Low\leslie_ball@banners.facebookofsex[2].txt
C:\Users\Leslie Ball\AppData\Roaming\Microsoft\Windows\Cookies\Low\leslie_ball@bannertgt[1].txt
C:\Users\Leslie Ball\AppData\Roaming\Microsoft\Windows\Cookies\Low\leslie_ball@beacon.dmsinsights[2].txt
C:\Users\Leslie Ball\AppData\Roaming\Microsoft\Windows\Cookies\Low\leslie_ball@bhdmedia.go2jump[1].txt
C:\Users\Leslie Ball\AppData\Roaming\Microsoft\Windows\Cookies\Low\leslie_ball@bicesteradvertiser[1].txt
C:\Users\Leslie Ball\AppData\Roaming\Microsoft\Windows\Cookies\Low\leslie_ball@bluemango.solution.weborama[2].txt
C:\Users\Leslie Ball\AppData\Roaming\Microsoft\Windows\Cookies\Low\leslie_ball@bluestreak[1].txt
C:\Users\Leslie Ball\AppData\Roaming\Microsoft\Windows\Cookies\Low\leslie_ball@bouyguestelecom.solution.weborama[2].txt
C:\Users\Leslie Ball\AppData\Roaming\Microsoft\Windows\Cookies\Low\leslie_ball@bravenet[2].txt
C:\Users\Leslie Ball\AppData\Roaming\Microsoft\Windows\Cookies\Low\leslie_ball@breakmedia.checkm8[1].txt
C:\Users\Leslie Ball\AppData\Roaming\Microsoft\Windows\Cookies\Low\leslie_ball@bridge1.admarketplace[1].txt
C:\Users\Leslie Ball\AppData\Roaming\Microsoft\Windows\Cookies\Low\leslie_ball@bs.serving-sys[1].txt
C:\Users\Leslie Ball\AppData\Roaming\Microsoft\Windows\Cookies\Low\leslie_ball@bs.serving-sys[2].txt
C:\Users\Leslie Ball\AppData\Roaming\Microsoft\Windows\Cookies\Low\leslie_ball@bs.serving-sys[3].txt
C:\Users\Leslie Ball\AppData\Roaming\Microsoft\Windows\Cookies\Low\leslie_ball@bs.serving-sys[5].txt
C:\Users\Leslie Ball\AppData\Roaming\Microsoft\Windows\Cookies\Low\leslie_ball@bs.serving-sys[6].txt
C:\Users\Leslie Ball\AppData\Roaming\Microsoft\Windows\Cookies\Low\leslie_ball@bucksbanner961[1].txt
C:\Users\Leslie Ball\AppData\Roaming\Microsoft\Windows\Cookies\Low\leslie_ball@burstbeacon[2].txt
C:\Users\Leslie Ball\AppData\Roaming\Microsoft\Windows\Cookies\Low\leslie_ball@burstnet[2].txt
C:\Users\Leslie Ball\AppData\Roaming\Microsoft\Windows\Cookies\Low\leslie_ball@burstnet[3].txt
C:\Users\Leslie Ball\AppData\Roaming\Microsoft\Windows\Cookies\Low\leslie_ball@c.r.d.cltomedia[2].txt
C:\Users\Leslie Ball\AppData\Roaming\Microsoft\Windows\Cookies\Low\leslie_ball@cache.trafficmp[1].txt
C:\Users\Leslie Ball\AppData\Roaming\Microsoft\Windows\Cookies\Low\leslie_ball@cadburyschweppesplc.112.2o7[1].txt
C:\Users\Leslie Ball\AppData\Roaming\Microsoft\Windows\Cookies\Low\leslie_ball@casalemedia[1].txt
C:\Users\Leslie Ball\AppData\Roaming\Microsoft\Windows\Cookies\Low\leslie_ball@cdn4.specificclick[1].txt
C:\Users\Leslie Ball\AppData\Roaming\Microsoft\Windows\Cookies\Low\leslie_ball@cdn5.specificclick[1].txt
C:\Users\Leslie Ball\AppData\Roaming\Microsoft\Windows\Cookies\Low\leslie_ball@cdn5.specificclick[2].txt
C:\Users\Leslie Ball\AppData\Roaming\Microsoft\Windows\Cookies\Low\leslie_ball@cgm.adbureau[2].txt
C:\Users\Leslie Ball\AppData\Roaming\Microsoft\Windows\Cookies\Low\leslie_ball@chcmedia[1].txt
C:\Users\Leslie Ball\AppData\Roaming\Microsoft\Windows\Cookies\Low\leslie_ball@chitika[1].txt
C:\Users\Leslie Ball\AppData\Roaming\Microsoft\Windows\Cookies\Low\leslie_ball@chitika[3].txt
C:\Users\Leslie Ball\AppData\Roaming\Microsoft\Windows\Cookies\Low\leslie_ball@click.superpaysys[1].txt
C:\Users\Leslie Ball\AppData\Roaming\Microsoft\Windows\Cookies\Low\leslie_ball@click.yottacash[1].txt
C:\Users\Leslie Ball\AppData\Roaming\Microsoft\Windows\Cookies\Low\leslie_ball@clickarrows[1].txt
C:\Users\Leslie Ball\AppData\Roaming\Microsoft\Windows\Cookies\Low\leslie_ball@clickbank[1].txt
C:\Users\Leslie Ball\AppData\Roaming\Microsoft\Windows\Cookies\Low\leslie_ball@clickshift[1].txt
C:\Users\Leslie Ball\AppData\Roaming\Microsoft\Windows\Cookies\Low\leslie_ball@clicksor[1].txt
C:\Users\Leslie Ball\AppData\Roaming\Microsoft\Windows\Cookies\Low\leslie_ball@clicksor[2].txt
C:\Users\Leslie Ball\AppData\Roaming\Microsoft\Windows\Cookies\Low\leslie_ball@cltomedia[2].txt
C:\Users\Leslie Ball\AppData\Roaming\Microsoft\Windows\Cookies\Low\leslie_ball@cltomedia[3].txt
C:\Users\Leslie Ball\AppData\Roaming\Microsoft\Windows\Cookies\Low\leslie_ball@cn.clickable[1].txt
C:\Users\Leslie Ball\AppData\Roaming\Microsoft\Windows\Cookies\Low\leslie_ball@cnam.solution.weborama[2].txt
C:\Users\Leslie Ball\AppData\Roaming\Microsoft\Windows\Cookies\Low\leslie_ball@collective-media[1].txt
C:\Users\Leslie Ball\AppData\Roaming\Microsoft\Windows\Cookies\Low\leslie_ball@collective-media[2].txt
C:\Users\Leslie Ball\AppData\Roaming\Microsoft\Windows\Cookies\Low\leslie_ball@content.yieldmanager[10].txt
C:\Users\Leslie Ball\AppData\Roaming\Microsoft\Windows\Cookies\Low\leslie_ball@content.yieldmanager[11].txt
C:\Users\Leslie Ball\AppData\Roaming\Microsoft\Windows\Cookies\Low\leslie_ball@content.yieldmanager[1].txt
C:\Users\Leslie Ball\AppData\Roaming\Microsoft\Windows\Cookies\Low\leslie_ball@content.yieldmanager[2].txt
C:\Users\Leslie Ball\AppData\Roaming\Microsoft\Windows\Cookies\Low\leslie_ball@content.yieldmanager[3].txt
C:\Users\Leslie Ball\AppData\Roaming\Microsoft\Windows\Cookies\Low\leslie_ball@content.yieldmanager[4].txt
C:\Users\Leslie Ball\AppData\Roaming\Microsoft\Windows\Cookies\Low\leslie_ball@content.yieldmanager[5].txt
C:\Users\Leslie Ball\AppData\Roaming\Microsoft\Windows\Cookies\Low\leslie_ball@content.yieldmanager[6].txt
C:\Users\Leslie Ball\AppData\Roaming\Microsoft\Windows\Cookies\Low\leslie_ball@content.yieldmanager[7].txt
C:\Users\Leslie Ball\AppData\Roaming\Microsoft\Windows\Cookies\Low\leslie_ball@content.yieldmanager[8].txt
C:\Users\Leslie Ball\AppData\Roaming\Microsoft\Windows\Cookies\Low\leslie_ball@content.yieldmanager[9].txt
C:\Users\Leslie Ball\AppData\Roaming\Microsoft\Windows\Cookies\Low\leslie_ball@counter.hitslink[1].txt
C:\Users\Leslie Ball\AppData\Roaming\Microsoft\Windows\Cookies\Low\leslie_ball@countrymusic.about[1].txt
C:\Users\Leslie Ball\AppData\Roaming\Microsoft\Windows\Cookies\Low\leslie_ball@crackle[2].txt
C:\Users\Leslie Ball\AppData\Roaming\Microsoft\Windows\Cookies\Low\leslie_ball@cz6.clickzs[2].txt
C:\Users\Leslie Ball\AppData\Roaming\Microsoft\Windows\Cookies\Low\leslie_ball@data.coremetrics[1].txt
C:\Users\Leslie Ball\AppData\Roaming\Microsoft\Windows\Cookies\Low\leslie_ball@dc.tremormedia[2].txt
C:\Users\Leslie Ball\AppData\Roaming\Microsoft\Windows\Cookies\Low\leslie_ball@dc.tremormedia[3].txt
C:\Users\Leslie Ball\AppData\Roaming\Microsoft\Windows\Cookies\Low\leslie_ball@dealclick.co[2].txt
C:\Users\Leslie Ball\AppData\Roaming\Microsoft\Windows\Cookies\Low\leslie_ball@delivery.trafficjunky[1].txt
C:\Users\Leslie Ball\AppData\Roaming\Microsoft\Windows\Cookies\Low\leslie_ball@djdownload.directtrack[2].txt
C:\Users\Leslie Ball\AppData\Roaming\Microsoft\Windows\Cookies\Low\leslie_ball@dmcupdate.trackitdown[1].txt
C:\Users\Leslie Ball\AppData\Roaming\Microsoft\Windows\Cookies\Low\leslie_ball@dmtracker[1].txt
C:\Users\Leslie Ball\AppData\Roaming\Microsoft\Windows\Cookies\Low\leslie_ball@doubleclick[2].txt
C:\Users\Leslie Ball\AppData\Roaming\Microsoft\Windows\Cookies\Low\leslie_ball@doubleclick[3].txt
C:\Users\Leslie Ball\AppData\Roaming\Microsoft\Windows\Cookies\Low\leslie_ball@doubleclick[4].txt
C:\Users\Leslie Ball\AppData\Roaming\Microsoft\Windows\Cookies\Low\leslie_ball@dynamic.media.adrevolver[2].txt
C:\Users\Leslie Ball\AppData\Roaming\Microsoft\Windows\Cookies\Low\leslie_ball@e-2dj6wakoggd5skp.stats.esomniture[2].txt
C:\Users\Leslie Ball\AppData\Roaming\Microsoft\Windows\Cookies\Low\leslie_ball@e-2dj6wal4ckdpeco.stats.esomniture[2].txt
C:\Users\Leslie Ball\AppData\Roaming\Microsoft\Windows\Cookies\Low\leslie_ball@e-2dj6wbkiuodzcep.stats.esomniture[2].txt
C:\Users\Leslie Ball\AppData\Roaming\Microsoft\Windows\Cookies\Low\leslie_ball@e-2dj6wdmiglazeeo.stats.esomniture[2].txt
C:\Users\Leslie Ball\AppData\Roaming\Microsoft\Windows\Cookies\Low\leslie_ball@e-2dj6wfk4ahdpgdq.stats.esomniture[2].txt
C:\Users\Leslie Ball\AppData\Roaming\Microsoft\Windows\Cookies\Low\leslie_ball@e-2dj6wfkycgcpicp.stats.esomniture[2].txt
C:\Users\Leslie Ball\AppData\Roaming\Microsoft\Windows\Cookies\Low\leslie_ball@e-2dj6wfl4sodjiao.stats.esomniture[2].txt
C:\Users\Leslie Ball\AppData\Roaming\Microsoft\Windows\Cookies\Low\leslie_ball@e-2dj6wflield5eeo.stats.esomniture[2].txt
C:\Users\Leslie Ball\AppData\Roaming\Microsoft\Windows\Cookies\Low\leslie_ball@e-2dj6wfloegcjofo.stats.esomniture[1].txt
C:\Users\Leslie Ball\AppData\Roaming\Microsoft\Windows\Cookies\Low\leslie_ball@e-2dj6wgk4kjdpkco.stats.esomniture[2].txt
C:\Users\Leslie Ball\AppData\Roaming\Microsoft\Windows\Cookies\Low\leslie_ball@e-2dj6wgkikkdzahp.stats.esomniture[2].txt
C:\Users\Leslie Ball\AppData\Roaming\Microsoft\Windows\Cookies\Low\leslie_ball@e-2dj6wgkykic5gbo.stats.esomniture[2].txt
C:\Users\Leslie Ball\AppData\Roaming\Microsoft\Windows\Cookies\Low\leslie_ball@e-2dj6wgl4gkdpcgo.stats.esomniture[2].txt
C:\Users\Leslie Ball\AppData\Roaming\Microsoft\Windows\Cookies\Low\leslie_ball@e-2dj6wjkyupczikq.stats.esomniture[1].txt
C:\Users\Leslie Ball\AppData\Roaming\Microsoft\Windows\Cookies\Low\leslie_ball@e-2dj6wjkyupczikq.stats.esomniture[2].txt
C:\Users\Leslie Ball\AppData\Roaming\Microsoft\Windows\Cookies\Low\leslie_ball@e-2dj6wjl4wicpmco.stats.esomniture[2].txt
C:\Users\Leslie Ball\AppData\Roaming\Microsoft\Windows\Cookies\Low\leslie_ball@e-2dj6wjmianc5wgp.stats.esomniture[1].txt
C:\Users\Leslie Ball\AppData\Roaming\Microsoft\Windows\Cookies\Low\leslie_ball@e-2dj6wjmiomczmep.stats.esomniture[2].txt
C:\Users\Leslie Ball\AppData\Roaming\Microsoft\Windows\Cookies\Low\leslie_ball@e-2dj6wjmioodzodo.stats.esomniture[1].txt
C:\Users\Leslie Ball\AppData\Roaming\Microsoft\Windows\Cookies\Low\leslie_ball@e-2dj6wjmyapajelp.stats.esomniture[2].txt
C:\Users\Leslie Ball\AppData\Roaming\Microsoft\Windows\Cookies\Low\leslie_ball@e-2dj6wnmyuhc5cco.stats.esomniture[2].txt
C:\Users\Leslie Ball\AppData\Roaming\Microsoft\Windows\Cookies\Low\leslie_ball@e.m.r.cltomedia[2].txt
C:\Users\Leslie Ball\AppData\Roaming\Microsoft\Windows\Cookies\Low\leslie_ball@eas.apm.emediate[1].txt
C:\Users\Leslie Ball\AppData\Roaming\Microsoft\Windows\Cookies\Low\leslie_ball@eas.apm.emediate[2].txt
C:\Users\Leslie Ball\AppData\Roaming\Microsoft\Windows\Cookies\Low\leslie_ball@eas.apm.emediate[3].txt
C:\Users\Leslie Ball\AppData\Roaming\Microsoft\Windows\Cookies\Low\leslie_ball@eas.apm.emediate[4].txt
C:\Users\Leslie Ball\AppData\Roaming\Microsoft\Windows\Cookies\Low\leslie_ball@eas.apm.emediate[5].txt
C:\Users\Leslie Ball\AppData\Roaming\Microsoft\Windows\Cookies\Low\leslie_ball@eb.adbureau[2].txt
C:\Users\Leslie Ball\AppData\Roaming\Microsoft\Windows\Cookies\Low\leslie_ball@ehg-codecomputerlove.hitbox[1].txt
C:\Users\Leslie Ball\AppData\Roaming\Microsoft\Windows\Cookies\Low\leslie_ball@ehg-deltatre.hitbox[2].txt
C:\Users\Leslie Ball\AppData\Roaming\Microsoft\Windows\Cookies\Low\leslie_ball@ehg-fifa.hitbox[2].txt
C:\Users\Leslie Ball\AppData\Roaming\Microsoft\Windows\Cookies\Low\leslie_ball@ehg-tfl.hitbox[2].txt
C:\Users\Leslie Ball\AppData\Roaming\Microsoft\Windows\Cookies\Low\leslie_ball@enter.pornhubpremium[2].txt
C:\Users\Leslie Ball\AppData\Roaming\Microsoft\Windows\Cookies\Low\leslie_ball@entrepreneur.122.2o7[2].txt
C:\Users\Leslie Ball\AppData\Roaming\Microsoft\Windows\Cookies\Low\leslie_ball@ext.trackingwiz[2].txt
C:\Users\Leslie Ball\AppData\Roaming\Microsoft\Windows\Cookies\Low\leslie_ball@eyewonder[1].txt
C:\Users\Leslie Ball\AppData\Roaming\Microsoft\Windows\Cookies\Low\leslie_ball@ez-tracks[2].txt
C:\Users\Leslie Ball\AppData\Roaming\Microsoft\Windows\Cookies\Low\leslie_ball@fastclick[1].txt
C:\Users\Leslie Ball\AppData\Roaming\Microsoft\Windows\Cookies\Low\leslie_ball@fastclick[2].txt
C:\Users\Leslie Ball\AppData\Roaming\Microsoft\Windows\Cookies\Low\leslie_ball@floraheartsgroup.solution.weborama[2].txt
C:\Users\Leslie Ball\AppData\Roaming\Microsoft\Windows\Cookies\Low\leslie_ball@gostats[2].txt
C:\Users\Leslie Ball\AppData\Roaming\Microsoft\Windows\Cookies\Low\leslie_ball@himedia.individuad[2].txt
C:\Users\Leslie Ball\AppData\Roaming\Microsoft\Windows\Cookies\Low\leslie_ball@hippocounter[1].txt
C:\Users\Leslie Ball\AppData\Roaming\Microsoft\Windows\Cookies\Low\leslie_ball@hornymatches[1].txt
C:\Users\Leslie Ball\AppData\Roaming\Microsoft\Windows\Cookies\Low\leslie_ball@hotlog[1].txt
C:\Users\Leslie Ball\AppData\Roaming\Microsoft\Windows\Cookies\Low\leslie_ball@iacas.adbureau[1].txt
C:\Users\Leslie Ball\AppData\Roaming\Microsoft\Windows\Cookies\Low\leslie_ball@ice.112.2o7[1].txt
C:\Users\Leslie Ball\AppData\Roaming\Microsoft\Windows\Cookies\Low\leslie_ball@ie-stat.bmmetrix[2].txt
C:\Users\Leslie Ball\AppData\Roaming\Microsoft\Windows\Cookies\Low\leslie_ball@ie-stat.bmmetrix[3].txt
C:\Users\Leslie Ball\AppData\Roaming\Microsoft\Windows\Cookies\Low\leslie_ball@imrworldwide[2].txt
C:\Users\Leslie Ball\AppData\Roaming\Microsoft\Windows\Cookies\Low\leslie_ball@imrworldwide[3].txt
C:\Users\Leslie Ball\AppData\Roaming\Microsoft\Windows\Cookies\Low\leslie_ball@in.getclicky[1].txt
C:\Users\Leslie Ball\AppData\Roaming\Microsoft\Windows\Cookies\Low\leslie_ball@incentaclick[2].txt
C:\Users\Leslie Ball\AppData\Roaming\Microsoft\Windows\Cookies\Low\leslie_ball@indoormedia.co[1].txt
C:\Users\Leslie Ball\AppData\Roaming\Microsoft\Windows\Cookies\Low\leslie_ball@insightexpressai[1].txt
C:\Users\Leslie Ball\AppData\Roaming\Microsoft\Windows\Cookies\Low\leslie_ball@interclick[2].txt
C:\Users\Leslie Ball\AppData\Roaming\Microsoft\Windows\Cookies\Low\leslie_ball@interclick[3].txt
C:\Users\Leslie Ball\AppData\Roaming\Microsoft\Windows\Cookies\Low\leslie_ball@invitemedia[1].txt
C:\Users\Leslie Ball\AppData\Roaming\Microsoft\Windows\Cookies\Low\leslie_ball@invitemedia[2].txt
C:\Users\Leslie Ball\AppData\Roaming\Microsoft\Windows\Cookies\Low\leslie_ball@invitemedia[3].txt
C:\Users\Leslie Ball\AppData\Roaming\Microsoft\Windows\Cookies\Low\leslie_ball@invitemedia[4].txt
C:\Users\Leslie Ball\AppData\Roaming\Microsoft\Windows\Cookies\Low\leslie_ball@ipcmedia.122.2o7[1].txt
C:\Users\Leslie Ball\AppData\Roaming\Microsoft\Windows\Cookies\Low\leslie_ball@irishtimesgroup.112.2o7[1].txt
C:\Users\Leslie Ball\AppData\Roaming\Microsoft\Windows\Cookies\Low\leslie_ball@irishtimesgroup.112.2o7[2].txt
C:\Users\Leslie Ball\AppData\Roaming\Microsoft\Windows\Cookies\Low\leslie_ball@kanoodle[1].txt
C:\Users\Leslie Ball\AppData\Roaming\Microsoft\Windows\Cookies\Low\leslie_ball@kaspersky.122.2o7[1].txt
C:\Users\Leslie Ball\AppData\Roaming\Microsoft\Windows\Cookies\Low\leslie_ball@kontera[2].txt
C:\Users\Leslie Ball\AppData\Roaming\Microsoft\Windows\Cookies\Low\leslie_ball@kontera[3].txt
C:\Users\Leslie Ball\AppData\Roaming\Microsoft\Windows\Cookies\Low\leslie_ball@kronos.bravenet[1].txt
C:\Users\Leslie Ball\AppData\Roaming\Microsoft\Windows\Cookies\Low\leslie_ball@kronosevents.bravenet[1].txt
C:\Users\Leslie Ball\AppData\Roaming\Microsoft\Windows\Cookies\Low\leslie_ball@legolas-media[1].txt
C:\Users\Leslie Ball\AppData\Roaming\Microsoft\Windows\Cookies\Low\leslie_ball@lfstmedia[1].txt
C:\Users\Leslie Ball\AppData\Roaming\Microsoft\Windows\Cookies\Low\leslie_ball@lib.s1.madbanner[1].txt
C:\Users\Leslie Ball\AppData\Roaming\Microsoft\Windows\Cookies\Low\leslie_ball@liveperson[1].txt
C:\Users\Leslie Ball\AppData\Roaming\Microsoft\Windows\Cookies\Low\leslie_ball@lucidmedia[2].txt
C:\Users\Leslie Ball\AppData\Roaming\Microsoft\Windows\Cookies\Low\leslie_ball@media.causes[1].txt
C:\Users\Leslie Ball\AppData\Roaming\Microsoft\Windows\Cookies\Low\leslie_ball@media.mtvnservices[2].txt
C:\Users\Leslie Ball\AppData\Roaming\Microsoft\Windows\Cookies\Low\leslie_ball@media6degrees[1].txt
C:\Users\Leslie Ball\AppData\Roaming\Microsoft\Windows\Cookies\Low\leslie_ball@media6degrees[2].txt
C:\Users\Leslie Ball\AppData\Roaming\Microsoft\Windows\Cookies\Low\leslie_ball@media6degrees[3].txt
C:\Users\Leslie Ball\AppData\Roaming\Microsoft\Windows\Cookies\Low\leslie_ball@media6degrees[4].txt
C:\Users\Leslie Ball\AppData\Roaming\Microsoft\Windows\Cookies\Low\leslie_ball@media6degrees[5].txt
C:\Users\Leslie Ball\AppData\Roaming\Microsoft\Windows\Cookies\Low\leslie_ball@media6degrees[6].txt
C:\Users\Leslie Ball\AppData\Roaming\Microsoft\Windows\Cookies\Low\leslie_ball@media6degrees[7].txt
C:\Users\Leslie Ball\AppData\Roaming\Microsoft\Windows\Cookies\Low\leslie_ball@media6degrees[8].txt
C:\Users\Leslie Ball\AppData\Roaming\Microsoft\Windows\Cookies\Low\leslie_ball@mediafire[1].txt
C:\Users\Leslie Ball\AppData\Roaming\Microsoft\Windows\Cookies\Low\leslie_ball@mediaonenetwork[1].txt
C:\Users\Leslie Ball\AppData\Roaming\Microsoft\Windows\Cookies\Low\leslie_ball@mediaplex[10].txt
C:\Users\Leslie Ball\AppData\Roaming\Microsoft\Windows\Cookies\Low\leslie_ball@mediaplex[1].txt
C:\Users\Leslie Ball\AppData\Roaming\Microsoft\Windows\Cookies\Low\leslie_ball@mediaplex[2].txt
C:\Users\Leslie Ball\AppData\Roaming\Microsoft\Windows\Cookies\Low\leslie_ball@mediaplex[3].txt
C:\Users\Leslie Ball\AppData\Roaming\Microsoft\Windows\Cookies\Low\leslie_ball@mediaplex[4].txt
C:\Users\Leslie Ball\AppData\Roaming\Microsoft\Windows\Cookies\Low\leslie_ball@mediaplex[5].txt
C:\Users\Leslie Ball\AppData\Roaming\Microsoft\Windows\Cookies\Low\leslie_ball@mediaplex[6].txt
C:\Users\Leslie Ball\AppData\Roaming\Microsoft\Windows\Cookies\Low\leslie_ball@mediaplex[7].txt
C:\Users\Leslie Ball\AppData\Roaming\Microsoft\Windows\Cookies\Low\leslie_ball@mediaplex[8].txt
C:\Users\Leslie Ball\AppData\Roaming\Microsoft\Windows\Cookies\Low\leslie_ball@mediaplex[9].txt
C:\Users\Leslie Ball\AppData\Roaming\Microsoft\Windows\Cookies\Low\leslie_ball@mediatraffic[2].txt
C:\Users\Leslie Ball\AppData\Roaming\Microsoft\Windows\Cookies\Low\leslie_ball@mediaweired[1].txt
C:\Users\Leslie Ball\AppData\Roaming\Microsoft\Windows\Cookies\Low\leslie_ball@microsoftinternetexplorer.112.2o7[1].txt
C:\Users\Leslie Ball\AppData\Roaming\Microsoft\Windows\Cookies\Low\leslie_ball@microsoftsto.112.2o7[1].txt
C:\Users\Leslie Ball\AppData\Roaming\Microsoft\Windows\Cookies\Low\leslie_ball@microsoftwindows.112.2o7[1].txt
C:\Users\Leslie Ball\AppData\Roaming\Microsoft\Windows\Cookies\Low\leslie_ball@mmedia.t134[1].txt
C:\Users\Leslie Ball\AppData\Roaming\Microsoft\Windows\Cookies\Low\leslie_ball@msnaccountservices.112.2o7[1].txt
C:\Users\Leslie Ball\AppData\Roaming\Microsoft\Windows\Cookies\Low\leslie_ball@msnbc.112.2o7[1].txt
C:\Users\Leslie Ball\AppData\Roaming\Microsoft\Windows\Cookies\Low\leslie_ball@msnportal.112.2o7[1].txt
C:\Users\Leslie Ball\AppData\Roaming\Microsoft\Windows\Cookies\Low\leslie_ball@msnportal.112.2o7[2].txt
C:\Users\Leslie Ball\AppData\Roaming\Microsoft\Windows\Cookies\Low\leslie_ball@msnportal.112.2o7[3].txt
C:\Users\Leslie Ball\AppData\Roaming\Microsoft\Windows\Cookies\Low\leslie_ball@myaccount.sparebackup[2].txt
C:\Users\Leslie Ball\AppData\Roaming\Microsoft\Windows\Cookies\Low\leslie_ball@myhammer.122.2o7[1].txt
C:\Users\Leslie Ball\AppData\Roaming\Microsoft\Windows\Cookies\Low\leslie_ball@myroitracking[1].txt
C:\Users\Leslie Ball\AppData\Roaming\Microsoft\Windows\Cookies\Low\leslie_ball@myroitracking[2].txt
C:\Users\Leslie Ball\AppData\Roaming\Microsoft\Windows\Cookies\Low\leslie_ball@n-traffic[1].txt
C:\Users\Leslie Ball\AppData\Roaming\Microsoft\Windows\Cookies\Low\leslie_ball@n.f.e.cltomedia[1].txt
C:\Users\Leslie Ball\AppData\Roaming\Microsoft\Windows\Cookies\Low\leslie_ball@network.realmedia[2].txt
C:\Users\Leslie Ball\AppData\Roaming\Microsoft\Windows\Cookies\Low\leslie_ball@newsquestdigitalmedia.122.2o7[1].txt
C:\Users\Leslie Ball\AppData\Roaming\Microsoft\Windows\Cookies\Low\leslie_ball@nextag.co[1].txt
C:\Users\Leslie Ball\AppData\Roaming\Microsoft\Windows\Cookies\Low\leslie_ball@oasn04.247realmedia[1].txt
C:\Users\Leslie Ball\AppData\Roaming\Microsoft\Windows\Cookies\Low\leslie_ball@onlineadtracker1.co[2].txt
C:\Users\Leslie Ball\AppData\Roaming\Microsoft\Windows\Cookies\Low\leslie_ball@openx.itmgmedia[1].txt
C:\Users\Leslie Ball\AppData\Roaming\Microsoft\Windows\Cookies\Low\leslie_ball@optimize.indieclick[2].txt
C:\Users\Leslie Ball\AppData\Roaming\Microsoft\Windows\Cookies\Low\leslie_ball@overture[2].txt
C:\Users\Leslie Ball\AppData\Roaming\Microsoft\Windows\Cookies\Low\leslie_ball@overture[3].txt
C:\Users\Leslie Ball\AppData\Roaming\Microsoft\Windows\Cookies\Low\leslie_ball@parship.122.2o7[1].txt
C:\Users\Leslie Ball\AppData\Roaming\Microsoft\Windows\Cookies\Low\leslie_ball@partyaccount[2].txt
C:\Users\Leslie Ball\AppData\Roaming\Microsoft\Windows\Cookies\Low\leslie_ball@partypoker[2].txt
C:\Users\Leslie Ball\AppData\Roaming\Microsoft\Windows\Cookies\Low\leslie_ball@partypoker[3].txt
C:\Users\Leslie Ball\AppData\Roaming\Microsoft\Windows\Cookies\Low\leslie_ball@patsbanner443[1].txt
C:\Users\Leslie Ball\AppData\Roaming\Microsoft\Windows\Cookies\Low\leslie_ball@paypal.112.2o7[1].txt
C:\Users\Leslie Ball\AppData\Roaming\Microsoft\Windows\Cookies\Low\leslie_ball@paypal.112.2o7[2].txt
C:\Users\Leslie Ball\AppData\Roaming\Microsoft\Windows\Cookies\Low\leslie_ball@pointroll[2].txt
C:\Users\Leslie Ball\AppData\Roaming\Microsoft\Windows\Cookies\Low\leslie_ball@popcapgames.122.2o7[1].txt
C:\Users\Leslie Ball\AppData\Roaming\Microsoft\Windows\Cookies\Low\leslie_ball@pornhubpremium[2].txt
C:\Users\Leslie Ball\AppData\Roaming\Microsoft\Windows\Cookies\Low\leslie_ball@pornhub[1].txt
C:\Users\Leslie Ball\AppData\Roaming\Microsoft\Windows\Cookies\Low\leslie_ball@pornhub[2].txt
C:\Users\Leslie Ball\AppData\Roaming\Microsoft\Windows\Cookies\Low\leslie_ball@pornhub[3].txt
C:\Users\Leslie Ball\AppData\Roaming\Microsoft\Windows\Cookies\Low\leslie_ball@pornhub[4].txt
C:\Users\Leslie Ball\AppData\Roaming\Microsoft\Windows\Cookies\Low\leslie_ball@pornhub[5].txt
C:\Users\Leslie Ball\AppData\Roaming\Microsoft\Windows\Cookies\Low\leslie_ball@pornhub[6].txt
C:\Users\Leslie Ball\AppData\Roaming\Microsoft\Windows\Cookies\Low\leslie_ball@pornsecretsrevealed[2].txt
C:\Users\Leslie Ball\AppData\Roaming\Microsoft\Windows\Cookies\Low\leslie_ball@premiumtv.122.2o7[1].txt
C:\Users\Leslie Ball\AppData\Roaming\Microsoft\Windows\Cookies\Low\leslie_ball@pro-market[1].txt
C:\Users\Leslie Ball\AppData\Roaming\Microsoft\Windows\Cookies\Low\leslie_ball@pro-market[2].txt
C:\Users\Leslie Ball\AppData\Roaming\Microsoft\Windows\Cookies\Low\leslie_ball@questionmarket[2].txt
C:\Users\Leslie Ball\AppData\Roaming\Microsoft\Windows\Cookies\Low\leslie_ball@questionmarket[3].txt
C:\Users\Leslie Ball\AppData\Roaming\Microsoft\Windows\Cookies\Low\leslie_ball@questionmarket[4].txt
C:\Users\Leslie Ball\AppData\Roaming\Microsoft\Windows\Cookies\Low\leslie_ball@questionmarket[5].txt
C:\Users\Leslie Ball\AppData\Roaming\Microsoft\Windows\Cookies\Low\leslie_ball@quoteonclick.co[1].txt
C:\Users\Leslie Ball\AppData\Roaming\Microsoft\Windows\Cookies\Low\leslie_ball@readersdigest.122.2o7[1].txt
C:\Users\Leslie Ball\AppData\Roaming\Microsoft\Windows\Cookies\Low\leslie_ball@realmedia[1].txt
C:\Users\Leslie Ball\AppData\Roaming\Microsoft\Windows\Cookies\Low\leslie_ball@reduxads.valuead[1].txt
C:\Users\Leslie Ball\AppData\Roaming\Microsoft\Windows\Cookies\Low\leslie_ball@revsci[10].txt
C:\Users\Leslie Ball\AppData\Roaming\Microsoft\Windows\Cookies\Low\leslie_ball@revsci[11].txt
C:\Users\Leslie Ball\AppData\Roaming\Microsoft\Windows\Cookies\Low\leslie_ball@revsci[1].txt
C:\Users\Leslie Ball\AppData\Roaming\Microsoft\Windows\Cookies\Low\leslie_ball@revsci[2].txt
C:\Users\Leslie Ball\AppData\Roaming\Microsoft\Windows\Cookies\Low\leslie_ball@revsci[3].txt
C:\Users\Leslie Ball\AppData\Roaming\Microsoft\Windows\Cookies\Low\leslie_ball@revsci[4].txt
C:\Users\Leslie Ball\AppData\Roaming\Microsoft\Windows\Cookies\Low\leslie_ball@revsci[5].txt
C:\Users\Leslie Ball\AppData\Roaming\Microsoft\Windows\Cookies\Low\leslie_ball@revsci[6].txt
C:\Users\Leslie Ball\AppData\Roaming\Microsoft\Windows\Cookies\Low\leslie_ball@revsci[7].txt
C:\Users\Leslie Ball\AppData\Roaming\Microsoft\Windows\Cookies\Low\leslie_ball@revsci[8].txt
C:\Users\Leslie Ball\AppData\Roaming\Microsoft\Windows\Cookies\Low\leslie_ball@richmedia.yahoo[1].txt
C:\Users\Leslie Ball\AppData\Roaming\Microsoft\Windows\Cookies\Low\leslie_ball@richmedia.yahoo[3].txt
C:\Users\Leslie Ball\AppData\Roaming\Microsoft\Windows\Cookies\Low\leslie_ball@rm.yieldmanager[2].txt
C:\Users\Leslie Ball\AppData\Roaming\Microsoft\Windows\Cookies\Low\leslie_ball@rotator.adjuggler[2].txt
C:\Users\Leslie Ball\AppData\Roaming\Microsoft\Windows\Cookies\Low\leslie_ball@rotator.adjuggler[3].txt
C:\Users\Leslie Ball\AppData\Roaming\Microsoft\Windows\Cookies\Low\leslie_ball@rts.pgmediaserve[1].txt
C:\Users\Leslie Ball\AppData\Roaming\Microsoft\Windows\Cookies\Low\leslie_ball@rts.pgmediaserve[2].txt
C:\Users\Leslie Ball\AppData\Roaming\Microsoft\Windows\Cookies\Low\leslie_ball@rts.pgmediaserve[3].txt
C:\Users\Leslie Ball\AppData\Roaming\Microsoft\Windows\Cookies\Low\leslie_ball@rts.pgmediaserve[4].txt
C:\Users\Leslie Ball\AppData\Roaming\Microsoft\Windows\Cookies\Low\leslie_ball@rts.pgmediaserve[5].txt
C:\Users\Leslie Ball\AppData\Roaming\Microsoft\Windows\Cookies\Low\leslie_ball@ru4[1].txt
C:\Users\Leslie Ball\AppData\Roaming\Microsoft\Windows\Cookies\Low\leslie_ball@ru4[3].txt
C:\Users\Leslie Ball\AppData\Roaming\Microsoft\Windows\Cookies\Low\leslie_ball@ru4[4].txt
C:\Users\Leslie Ball\AppData\Roaming\Microsoft\Windows\Cookies\Low\leslie_ball@s.clickability[2].txt
C:\Users\Leslie Ball\AppData\Roaming\Microsoft\Windows\Cookies\Low\leslie_ball@s.p.r.cltomedia[1].txt
C:\Users\Leslie Ball\AppData\Roaming\Microsoft\Windows\Cookies\Low\leslie_ball@secure.partyaccount[2].txt
C:\Users\Leslie Ball\AppData\Roaming\Microsoft\Windows\Cookies\Low\leslie_ball@servedby.adxpower[1].txt
C:\Users\Leslie Ball\AppData\Roaming\Microsoft\Windows\Cookies\Low\leslie_ball@server.cpmstar[2].txt
C:\Users\Leslie Ball\AppData\Roaming\Microsoft\Windows\Cookies\Low\leslie_ball@server.iad.liveperson[1].txt
C:\Users\Leslie Ball\AppData\Roaming\Microsoft\Windows\Cookies\Low\leslie_ball@server.iad.liveperson[3].txt
C:\Users\Leslie Ball\AppData\Roaming\Microsoft\Windows\Cookies\Low\leslie_ball@server.iad.liveperson[4].txt
C:\Users\Leslie Ball\AppData\Roaming\Microsoft\Windows\Cookies\Low\leslie_ball@server.iad.liveperson[5].txt
C:\Users\Leslie Ball\AppData\Roaming\Microsoft\Windows\Cookies\Low\leslie_ball@server.iad.liveperson[6].txt
C:\Users\Leslie Ball\AppData\Roaming\Microsoft\Windows\Cookies\Low\leslie_ball@server.lon.liveperson[1].txt
C:\Users\Leslie Ball\AppData\Roaming\Microsoft\Windows\Cookies\Low\leslie_ball@server.lon.liveperson[2].txt
C:\Users\Leslie Ball\AppData\Roaming\Microsoft\Windows\Cookies\Low\leslie_ball@server.lon.liveperson[3].txt
C:\Users\Leslie Ball\AppData\Roaming\Microsoft\Windows\Cookies\Low\leslie_ball@server.lon.liveperson[4].txt
C:\Users\Leslie Ball\AppData\Roaming\Microsoft\Windows\Cookies\Low\leslie_ball@server.lon.liveperson[5].txt
C:\Users\Leslie Ball\AppData\Roaming\Microsoft\Windows\Cookies\Low\leslie_ball@server.lon.liveperson[6].txt
C:\Users\Leslie Ball\AppData\Roaming\Microsoft\Windows\Cookies\Low\leslie_ball@server.lon.liveperson[7].txt
C:\Users\Leslie Ball\AppData\Roaming\Microsoft\Windows\Cookies\Low\leslie_ball@server.lon.liveperson[9].txt
C:\Users\Leslie Ball\AppData\Roaming\Microsoft\Windows\Cookies\Low\leslie_ball@serving-sys[1].txt
C:\Users\Leslie Ball\AppData\Roaming\Microsoft\Windows\Cookies\Low\leslie_ball@serving-sys[2].txt
C:\Users\Leslie Ball\AppData\Roaming\Microsoft\Windows\Cookies\Low\leslie_ball@serving-sys[3].txt
C:\Users\Leslie Ball\AppData\Roaming\Microsoft\Windows\Cookies\Low\leslie_ball@serving-sys[4].txt
C:\Users\Leslie Ball\AppData\Roaming\Microsoft\Windows\Cookies\Low\leslie_ball@serving-sys[5].txt
C:\Users\Leslie Ball\AppData\Roaming\Microsoft\Windows\Cookies\Low\leslie_ball@serving-sys[6].txt
C:\Users\Leslie Ball\AppData\Roaming\Microsoft\Windows\Cookies\Low\leslie_ball@serving-sys[8].txt
C:\Users\Leslie Ball\AppData\Roaming\Microsoft\Windows\Cookies\Low\leslie_ball@serving.adsrevenue.clicksor[2].txt
C:\Users\Leslie Ball\AppData\Roaming\Microsoft\Windows\Cookies\Low\leslie_ball@signup.ez-tracks[2].txt
C:\Users\Leslie Ball\AppData\Roaming\Microsoft\Windows\Cookies\Low\leslie_ball@simyo.122.2o7[1].txt
C:\Users\Leslie Ball\AppData\Roaming\Microsoft\Windows\Cookies\Low\leslie_ball@slaysbanner691[1].txt
C:\Users\Leslie Ball\AppData\Roaming\Microsoft\Windows\Cookies\Low\leslie_ball@smartadserver[2].txt
C:\Users\Leslie Ball\AppData\Roaming\Microsoft\Windows\Cookies\Low\leslie_ball@smartadserver[3].txt
C:\Users\Leslie Ball\AppData\Roaming\Microsoft\Windows\Cookies\Low\leslie_ball@socialmedia[1].txt
C:\Users\Leslie Ball\AppData\Roaming\Microsoft\Windows\Cookies\Low\leslie_ball@soundtrackcollector[1].txt
C:\Users\Leslie Ball\AppData\Roaming\Microsoft\Windows\Cookies\Low\leslie_ball@specificclick[1].txt
C:\Users\Leslie Ball\AppData\Roaming\Microsoft\Windows\Cookies\Low\leslie_ball@specificclick[2].txt
C:\Users\Leslie Ball\AppData\Roaming\Microsoft\Windows\Cookies\Low\leslie_ball@specificclick[3].txt
C:\Users\Leslie Ball\AppData\Roaming\Microsoft\Windows\Cookies\Low\leslie_ball@specificclick[4].txt
C:\Users\Leslie Ball\AppData\Roaming\Microsoft\Windows\Cookies\Low\leslie_ball@specificclick[5].txt
C:\Users\Leslie Ball\AppData\Roaming\Microsoft\Windows\Cookies\Low\leslie_ball@specificclick[6].txt
C:\Users\Leslie Ball\AppData\Roaming\Microsoft\Windows\Cookies\Low\leslie_ball@specificclick[7].txt
C:\Users\Leslie Ball\AppData\Roaming\Microsoft\Windows\Cookies\Low\leslie_ball@specificmedia[2].txt
C:\Users\Leslie Ball\AppData\Roaming\Microsoft\Windows\Cookies\Low\leslie_ball@stat.4u[1].txt
C:\Users\Leslie Ball\AppData\Roaming\Microsoft\Windows\Cookies\Low\leslie_ball@stat.easydate[1].txt
C:\Users\Leslie Ball\AppData\Roaming\Microsoft\Windows\Cookies\Low\leslie_ball@stat.onestat[2].txt
C:\Users\Leslie Ball\AppData\Roaming\Microsoft\Windows\Cookies\Low\leslie_ball@statcounter[1].txt
C:\Users\Leslie Ball\AppData\Roaming\Microsoft\Windows\Cookies\Low\leslie_ball@statcounter[2].txt
C:\Users\Leslie Ball\AppData\Roaming\Microsoft\Windows\Cookies\Low\leslie_ball@stats.adbrite[1].txt
C:\Users\Leslie Ball\AppData\Roaming\Microsoft\Windows\Cookies\Low\leslie_ball@stats.goomradio[1].txt
C:\Users\Leslie Ball\AppData\Roaming\Microsoft\Windows\Cookies\Low\leslie_ball@stats.matraxis[2].txt
C:\Users\Leslie Ball\AppData\Roaming\Microsoft\Windows\Cookies\Low\leslie_ball@stats.paypal[1].txt
C:\Users\Leslie Ball\AppData\Roaming\Microsoft\Windows\Cookies\Low\leslie_ball@stats.paypal[2].txt
C:\Users\Leslie Ball\AppData\Roaming\Microsoft\Windows\Cookies\Low\leslie_ball@statse.webtrendslive[1].txt
C:\Users\Leslie Ball\AppData\Roaming\Microsoft\Windows\Cookies\Low\leslie_ball@statse.webtrendslive[2].txt
C:\Users\Leslie Ball\AppData\Roaming\Microsoft\Windows\Cookies\Low\leslie_ball@statse.webtrendslive[4].txt
C:\Users\Leslie Ball\AppData\Roaming\Microsoft\Windows\Cookies\Low\leslie_ball@statse.webtrendslive[5].txt
C:\Users\Leslie Ball\AppData\Roaming\Microsoft\Windows\Cookies\Low\leslie_ball@statse.webtrendslive[6].txt
C:\Users\Leslie Ball\AppData\Roaming\Microsoft\Windows\Cookies\Low\leslie_ball@support.mediafire[2].txt
C:\Users\Leslie Ball\AppData\Roaming\Microsoft\Windows\Cookies\Low\leslie_ball@tacoda[1].txt
C:\Users\Leslie Ball\AppData\Roaming\Microsoft\Windows\Cookies\Low\leslie_ball@tacoda[2].txt
C:\Users\Leslie Ball\AppData\Roaming\Microsoft\Windows\Cookies\Low\leslie_ball@tdstats[1].txt
C:\Users\Leslie Ball\AppData\Roaming\Microsoft\Windows\Cookies\Low\leslie_ball@tns-counter[1].txt
C:\Users\Leslie Ball\AppData\Roaming\Microsoft\Windows\Cookies\Low\leslie_ball@tns-counter[2].txt
C:\Users\Leslie Ball\AppData\Roaming\Microsoft\Windows\Cookies\Low\leslie_ball@toplist[1].txt
C:\Users\Leslie Ball\AppData\Roaming\Microsoft\Windows\Cookies\Low\leslie_ball@track.adform[1].txt
C:\Users\Leslie Ball\AppData\Roaming\Microsoft\Windows\Cookies\Low\leslie_ball@trackalyzer[1].txt
C:\Users\Leslie Ball\AppData\Roaming\Microsoft\Windows\Cookies\Low\leslie_ball@tracker.roitesting[1].txt
C:\Users\Leslie Ball\AppData\Roaming\Microsoft\Windows\Cookies\Low\leslie_ball@trackers.1st-affiliation[2].txt
C:\Users\Leslie Ball\AppData\Roaming\Microsoft\Windows\Cookies\Low\leslie_ball@tracking.dc-storm[1].txt
C:\Users\Leslie Ball\AppData\Roaming\Microsoft\Windows\Cookies\Low\leslie_ball@tracking.dc-storm[3].txt
C:\Users\Leslie Ball\AppData\Roaming\Microsoft\Windows\Cookies\Low\leslie_ball@tracking.novem[2].txt
C:\Users\Leslie Ball\AppData\Roaming\Microsoft\Windows\Cookies\Low\leslie_ball@trackitdown[1].txt
C:\Users\Leslie Ball\AppData\Roaming\Microsoft\Windows\Cookies\Low\leslie_ball@tradedoubler[1].txt
C:\Users\Leslie Ball\AppData\Roaming\Microsoft\Windows\Cookies\Low\leslie_ball@tradedoubler[2].txt
C:\Users\Leslie Ball\AppData\Roaming\Microsoft\Windows\Cookies\Low\leslie_ball@tradedoubler[3].txt
C:\Users\Leslie Ball\AppData\Roaming\Microsoft\Windows\Cookies\Low\leslie_ball@tradedoubler[4].txt
C:\Users\Leslie Ball\AppData\Roaming\Microsoft\Windows\Cookies\Low\leslie_ball@traffic.uusee[1].txt
C:\Users\Leslie Ball\AppData\Roaming\Microsoft\Windows\Cookies\Low\leslie_ball@trafficalerts.tfl.gov[1].txt
C:\Users\Leslie Ball\AppData\Roaming\Microsoft\Windows\Cookies\Low\leslie_ball@trafficking.nabbr[1].txt
C:\Users\Leslie Ball\AppData\Roaming\Microsoft\Windows\Cookies\Low\leslie_ball@trafficking.nabbr[2].txt
C:\Users\Leslie Ball\AppData\Roaming\Microsoft\Windows\Cookies\Low\leslie_ball@trafficmp[1].txt
C:\Users\Leslie Ball\AppData\Roaming\Microsoft\Windows\Cookies\Low\leslie_ball@trafficmp[2].txt
C:\Users\Leslie Ball\AppData\Roaming\Microsoft\Windows\Cookies\Low\leslie_ball@traffictrack[1].txt
C:\Users\Leslie Ball\AppData\Roaming\Microsoft\Windows\Cookies\Low\leslie_ball@traveladvertising[2].txt
C:\Users\Leslie Ball\AppData\Roaming\Microsoft\Windows\Cookies\Low\leslie_ball@tribalfusion[1].txt
C:\Users\Leslie Ball\AppData\Roaming\Microsoft\Windows\Cookies\Low\leslie_ball@tribalfusion[2].txt
C:\Users\Leslie Ball\AppData\Roaming\Microsoft\Windows\Cookies\Low\leslie_ball@tribalfusion[3].txt
C:\Users\Leslie Ball\AppData\Roaming\Microsoft\Windows\Cookies\Low\leslie_ball@tribalfusion[4].txt
C:\Users\Leslie Ball\AppData\Roaming\Microsoft\Windows\Cookies\Low\leslie_ball@tribalfusion[5].txt
C:\Users\Leslie Ball\AppData\Roaming\Microsoft\Windows\Cookies\Low\leslie_ball@trinitymirror.112.2o7[1].txt
C:\Users\Leslie Ball\AppData\Roaming\Microsoft\Windows\Cookies\Low\leslie_ball@trinitymirror.112.2o7[2].txt
C:\Users\Leslie Ball\AppData\Roaming\Microsoft\Windows\Cookies\Low\leslie_ball@tripod[2].txt
C:\Users\Leslie Ball\AppData\Roaming\Microsoft\Windows\Cookies\Low\leslie_ball@trvlnet.adbureau[1].txt
C:\Users\Leslie Ball\AppData\Roaming\Microsoft\Windows\Cookies\Low\leslie_ball@tto2.traffictrack[1].txt
C:\Users\Leslie Ball\AppData\Roaming\Microsoft\Windows\Cookies\Low\leslie_ball@ufindus[1].txt
C:\Users\Leslie Ball\AppData\Roaming\Microsoft\Windows\Cookies\Low\leslie_ball@ufindus[2].txt
C:\Users\Leslie Ball\AppData\Roaming\Microsoft\Windows\Cookies\Low\leslie_ball@uk.at.atwola[1].txt
C:\Users\Leslie Ball\AppData\Roaming\Microsoft\Windows\Cookies\Low\leslie_ball@uk.at.atwola[3].txt
C:\Users\Leslie Ball\AppData\Roaming\Microsoft\Windows\Cookies\Low\leslie_ball@uktrancealliance.trackitdown[1].txt
C:\Users\Leslie Ball\AppData\Roaming\Microsoft\Windows\Cookies\Low\leslie_ball@uktrancealliance.trackitdown[3].txt
C:\Users\Leslie Ball\AppData\Roaming\Microsoft\Windows\Cookies\Low\leslie_ball@user.lucidmedia[1].txt
C:\Users\Leslie Ball\AppData\Roaming\Microsoft\Windows\Cookies\Low\leslie_ball@vdwp.solution.weborama[2].txt
C:\Users\Leslie Ball\AppData\Roaming\Microsoft\Windows\Cookies\Low\leslie_ball@viacom.adbureau[1].txt
C:\Users\Leslie Ball\AppData\Roaming\Microsoft\Windows\Cookies\Low\leslie_ball@videoegg.adbureau[2].txt
C:\Users\Leslie Ball\AppData\Roaming\Microsoft\Windows\Cookies\Low\leslie_ball@vimby.adbureau[2].txt
C:\Users\Leslie Ball\AppData\Roaming\Microsoft\Windows\Cookies\Low\leslie_ball@w00tpublishers.wootmedia[1].txt
C:\Users\Leslie Ball\AppData\Roaming\Microsoft\Windows\Cookies\Low\leslie_ball@warnerbros.112.2o7[1].txt
C:\Users\Leslie Ball\AppData\Roaming\Microsoft\Windows\Cookies\Low\leslie_ball@warnerbrosads.112.2o7[1].txt
C:\Users\Leslie Ball\AppData\Roaming\Microsoft\Windows\Cookies\Low\leslie_ball@we7.adbureau[1].txt
C:\Users\Leslie Ball\AppData\Roaming\Microsoft\Windows\Cookies\Low\leslie_ball@web4.realtracker[1].txt
C:\Users\Leslie Ball\AppData\Roaming\Microsoft\Windows\Cookies\Low\leslie_ball@webmasterplan[1].txt
C:\Users\Leslie Ball\AppData\Roaming\Microsoft\Windows\Cookies\Low\leslie_ball@weborama[1].txt
C:\Users\Leslie Ball\AppData\Roaming\Microsoft\Windows\Cookies\Low\leslie_ball@weborama[2].txt
C:\Users\Leslie Ball\AppData\Roaming\Microsoft\Windows\Cookies\Low\leslie_ball@winzip.122.2o7[1].txt
C:\Users\Leslie Ball\AppData\Roaming\Microsoft\Windows\Cookies\Low\leslie_ball@www.3pintracking[1].txt
C:\Users\Leslie Ball\AppData\Roaming\Microsoft\Windows\Cookies\Low\leslie_ball@www.adultadvertising[1].txt
C:\Users\Leslie Ball\AppData\Roaming\Microsoft\Windows\Cookies\Low\leslie_ball@www.bicesteradvertiser[1].txt
C:\Users\Leslie Ball\AppData\Roaming\Microsoft\Windows\Cookies\Low\leslie_ball@www.burstbeacon[1].txt
C:\Users\Leslie Ball\AppData\Roaming\Microsoft\Windows\Cookies\Low\leslie_ball@www.burstnet[1].txt
C:\Users\Leslie Ball\AppData\Roaming\Microsoft\Windows\Cookies\Low\leslie_ball@www.burstnet[2].txt
C:\Users\Leslie Ball\AppData\Roaming\Microsoft\Windows\Cookies\Low\leslie_ball@www.clash-media[2].txt
C:\Users\Leslie Ball\AppData\Roaming\Microsoft\Windows\Cookies\Low\leslie_ball@www.crackserialcodes[2].txt
C:\Users\Leslie Ball\AppData\Roaming\Microsoft\Windows\Cookies\Low\leslie_ball@www.dealclick.co[2].txt
C:\Users\Leslie Ball\AppData\Roaming\Microsoft\Windows\Cookies\Low\leslie_ball@www.downloadserialcrack[2].txt
C:\Users\Leslie Ball\AppData\Roaming\Microsoft\Windows\Cookies\Low\leslie_ball@www.etracker[1].txt
C:\Users\Leslie Ball\AppData\Roaming\Microsoft\Windows\Cookies\Low\leslie_ball@www.exgfsextapes[1].txt
C:\Users\Leslie Ball\AppData\Roaming\Microsoft\Windows\Cookies\Low\leslie_ball@www.ez-tracks[1].txt
C:\Users\Leslie Ball\AppData\Roaming\Microsoft\Windows\Cookies\Low\leslie_ball@www.focalmedia[1].txt
C:\Users\Leslie Ball\AppData\Roaming\Microsoft\Windows\Cookies\Low\leslie_ball@www.focalmedia[2].txt
C:\Users\Leslie Ball\AppData\Roaming\Microsoft\Windows\Cookies\Low\leslie_ball@www.googleadservices[10].txt
C:\Users\Leslie Ball\AppData\Roaming\Microsoft\Windows\Cookies\Low\leslie_ball@www.googleadservices[11].txt
C:\Users\Leslie Ball\AppData\Roaming\Microsoft\Windows\Cookies\Low\leslie_ball@www.googleadservices[1].txt
C:\Users\Leslie Ball\AppData\Roaming\Microsoft\Windows\Cookies\Low\leslie_ball@www.googleadservices[2].txt
C:\Users\Leslie Ball\AppData\Roaming\Microsoft\Windows\Cookies\Low\leslie_ball@www.googleadservices[3].txt
C:\Users\Leslie Ball\AppData\Roaming\Microsoft\Windows\Cookies\Low\leslie_ball@www.googleadservices[4].txt
C:\Users\Leslie Ball\AppData\Roaming\Microsoft\Windows\Cookies\Low\leslie_ball@www.googleadservices[5].txt
C:\Users\Leslie Ball\AppData\Roaming\Microsoft\Windows\Cookies\Low\leslie_ball@www.googleadservices[6].txt
C:\Users\Leslie Ball\AppData\Roaming\Microsoft\Windows\Cookies\Low\leslie_ball@www.googleadservices[7].txt
C:\Users\Leslie Ball\AppData\Roaming\Microsoft\Windows\Cookies\Low\leslie_ball@www.googleadservices[8].txt
C:\Users\Leslie Ball\AppData\Roaming\Microsoft\Windows\Cookies\Low\leslie_ball@www.googleadservices[9].txt
C:\Users\Leslie Ball\AppData\Roaming\Microsoft\Windows\Cookies\Low\leslie_ball@www.icityfind[1].txt
C:\Users\Leslie Ball\AppData\Roaming\Microsoft\Windows\Cookies\Low\leslie_ball@www.incentaclick[2].txt
C:\Users\Leslie Ball\AppData\Roaming\Microsoft\Windows\Cookies\Low\leslie_ball@www.inteletrack[1].txt
C:\Users\Leslie Ball\AppData\Roaming\Microsoft\Windows\Cookies\Low\leslie_ball@www.mylostaccount.org[1].txt
C:\Users\Leslie Ball\AppData\Roaming\Microsoft\Windows\Cookies\Low\leslie_ball@www.onlineadtracker.co[2].txt
C:\Users\Leslie Ball\AppData\Roaming\Microsoft\Windows\Cookies\Low\leslie_ball@www.partypoker[1].txt
C:\Users\Leslie Ball\AppData\Roaming\Microsoft\Windows\Cookies\Low\leslie_ball@www.perthshireadvertiser.co[1].txt
C:\Users\Leslie Ball\AppData\Roaming\Microsoft\Windows\Cookies\Low\leslie_ball@www.pornhub[1].txt
C:\Users\Leslie Ball\AppData\Roaming\Microsoft\Windows\Cookies\Low\leslie_ball@www.pornhub[2].txt
C:\Users\Leslie Ball\AppData\Roaming\Microsoft\Windows\Cookies\Low\leslie_ball@www.pornhub[3].txt
C:\Users\Leslie Ball\AppData\Roaming\Microsoft\Windows\Cookies\Low\leslie_ball@www.pornhub[4].txt
C:\Users\Leslie Ball\AppData\Roaming\Microsoft\Windows\Cookies\Low\leslie_ball@www.pxtrack[1].txt
C:\Users\Leslie Ball\AppData\Roaming\Microsoft\Windows\Cookies\Low\leslie_ball@www.qksrv[1].txt
C:\Users\Leslie Ball\AppData\Roaming\Microsoft\Windows\Cookies\Low\leslie_ball@www.quoteonclick.co[1].txt
C:\Users\Leslie Ball\AppData\Roaming\Microsoft\Windows\Cookies\Low\leslie_ball@www.smartadserver[1].txt
C:\Users\Leslie Ball\AppData\Roaming\Microsoft\Windows\Cookies\Low\leslie_ball@www.smartadserver[3].txt
C:\Users\Leslie Ball\AppData\Roaming\Microsoft\Windows\Cookies\Low\leslie_ball@www.soundtrackcollector[1].txt
C:\Users\Leslie Ball\AppData\Roaming\Microsoft\Windows\Cookies\Low\leslie_ball@www.track606[1].txt
C:\Users\Leslie Ball\AppData\Roaming\Microsoft\Windows\Cookies\Low\leslie_ball@www.trackitdown[1].txt
C:\Users\Leslie Ball\AppData\Roaming\Microsoft\Windows\Cookies\Low\leslie_ball@www.ufindus[1].txt
C:\Users\Leslie Ball\AppData\Roaming\Microsoft\Windows\Cookies\Low\leslie_ball@www.ufindus[2].txt
C:\Users\Leslie Ball\AppData\Roaming\Microsoft\Windows\Cookies\Low\leslie_ball@www.usenext[1].txt
C:\Users\Leslie Ball\AppData\Roaming\Microsoft\Windows\Cookies\Low\leslie_ball@www.youserials[2].txt
C:\Users\Leslie Ball\AppData\Roaming\Microsoft\Windows\Cookies\Low\leslie_ball@www3.addfreestats[1].txt
C:\Users\Leslie Ball\AppData\Roaming\Microsoft\Windows\Cookies\Low\leslie_ball@www6.addfreestats[1].txt
C:\Users\Leslie Ball\AppData\Roaming\Microsoft\Windows\Cookies\Low\leslie_ball@www7.addfreestats[1].txt
C:\Users\Leslie Ball\AppData\Roaming\Microsoft\Windows\Cookies\Low\leslie_ball@www9.addfreestats[1].txt
C:\Users\Leslie Ball\AppData\Roaming\Microsoft\Windows\Cookies\Low\leslie_ball@xiti[1].txt
C:\Users\Leslie Ball\AppData\Roaming\Microsoft\Windows\Cookies\Low\leslie_ball@xiti[2].txt
C:\Users\Leslie Ball\AppData\Roaming\Microsoft\Windows\Cookies\Low\leslie_ball@xm.xtendmedia[2].txt
C:\Users\Leslie Ball\AppData\Roaming\Microsoft\Windows\Cookies\Low\leslie_ball@xm.xtendmedia[3].txt
C:\Users\Leslie Ball\AppData\Roaming\Microsoft\Windows\Cookies\Low\leslie_ball@yadro[1].txt
C:\Users\Leslie Ball\AppData\Roaming\Microsoft\Windows\Cookies\Low\leslie_ball@yadro[2].txt
C:\Users\Leslie Ball\AppData\Roaming\Microsoft\Windows\Cookies\Low\leslie_ball@yieldmanager[1].txt
C:\Users\Leslie Ball\AppData\Roaming\Microsoft\Windows\Cookies\Low\leslie_ball@yieldmanager[3].txt
C:\Users\Leslie Ball\AppData\Roaming\Microsoft\Windows\Cookies\Low\leslie_ball@yieldmanager[4].txt
C:\Users\Leslie Ball\AppData\Roaming\Microsoft\Windows\Cookies\Low\leslie_ball@yourcounty.co[2].txt
C:\Users\Leslie Ball\AppData\Roaming\Microsoft\Windows\Cookies\Low\leslie_ball@youserials[2].txt
C:\Users\Leslie Ball\AppData\Roaming\Microsoft\Windows\Cookies\Low\leslie_ball@zanox-affiliate[2].txt
C:\Users\Leslie Ball\AppData\Roaming\Microsoft\Windows\Cookies\Low\leslie_ball@zanox[1].txt
C:\Users\Leslie Ball\AppData\Roaming\Microsoft\Windows\Cookies\Low\leslie_ball@zedo[1].txt
C:\Users\Leslie Ball\AppData\Roaming\Microsoft\Windows\Cookies\Low\leslie_ball@zedo[3].txt
indieclick.3janecdn.com [ C:\Windows\System32\config\systemprofile\AppData\Roaming\Macromedia\Flash Player\#SharedObjects\KVA2N532 ]
media.mtvnservices.com [ C:\Windows\System32\config\systemprofile\AppData\Roaming\Macromedia\Flash Player\#SharedObjects\KVA2N532 ]
media1.break.com [ C:\Windows\System32\config\systemprofile\AppData\Roaming\Macromedia\Flash Player\#SharedObjects\KVA2N532 ]
s0.2mdn.net [ C:\Windows\System32\config\systemprofile\AppData\Roaming\Macromedia\Flash Player\#SharedObjects\KVA2N532 ]
secure-us.imrworldwide.com [ C:\Windows\System32\config\systemprofile\AppData\Roaming\Macromedia\Flash Player\#SharedObjects\KVA2N532 ]
spe.atdmt.com [ C:\Windows\System32\config\systemprofile\AppData\Roaming\Macromedia\Flash Player\#SharedObjects\KVA2N532 ]
stat.easydate.biz [ C:\Windows\System32\config\systemprofile\AppData\Roaming\Macromedia\Flash Player\#SharedObjects\KVA2N532 ]
C:\Windows\System32\config\systemprofile\AppData\Roaming\Microsoft\Windows\Cookies\system@247realmedia[1].txt
C:\Windows\System32\config\systemprofile\AppData\Roaming\Microsoft\Windows\Cookies\system@ad.harrenmedianetwork[2].txt
C:\Windows\System32\config\systemprofile\AppData\Roaming\Microsoft\Windows\Cookies\system@ad.yieldmanager[1].txt
C:\Windows\System32\config\systemprofile\AppData\Roaming\Microsoft\Windows\Cookies\system@ad.yieldmanager[2].txt
C:\Windows\System32\config\systemprofile\AppData\Roaming\Microsoft\Windows\Cookies\system@ad.yieldmanager[3].txt
C:\Windows\System32\config\systemprofile\AppData\Roaming\Microsoft\Windows\Cookies\system@adbrite[2].txt
C:\Windows\System32\config\systemprofile\AppData\Roaming\Microsoft\Windows\Cookies\system@adbrite[3].txt
C:\Windows\System32\config\systemprofile\AppData\Roaming\Microsoft\Windows\Cookies\system@adecn[1].txt
C:\Windows\System32\config\systemprofile\AppData\Roaming\Microsoft\Windows\Cookies\system@adecn[2].txt
C:\Windows\System32\config\systemprofile\AppData\Roaming\Microsoft\Windows\Cookies\system@ads.associatedcontent[1].txt
C:\Windows\System32\config\systemprofile\AppData\Roaming\Microsoft\Windows\Cookies\system@ads.bighealthtree[1].txt
C:\Windows\System32\config\systemprofile\AppData\Roaming\Microsoft\Windows\Cookies\system@ads.myadplatform[1].txt
C:\Windows\System32\config\systemprofile\AppData\Roaming\Microsoft\Windows\Cookies\system@ads.pubmatic[1].txt
C:\Windows\System32\config\systemprofile\AppData\Roaming\Microsoft\Windows\Cookies\system@ads.pubmatic[2].txt
C:\Windows\System32\config\systemprofile\AppData\Roaming\Microsoft\Windows\Cookies\system@ads.pubmatic[3].txt
C:\Windows\System32\config\systemprofile\AppData\Roaming\Microsoft\Windows\Cookies\system@ads.raasnet[1].txt
C:\Windows\System32\config\systemprofile\AppData\Roaming\Microsoft\Windows\Cookies\system@ads.smartadx[1].txt
C:\Windows\System32\config\systemprofile\AppData\Roaming\Microsoft\Windows\Cookies\system@ads.telegraph.co[2].txt
C:\Windows\System32\config\systemprofile\AppData\Roaming\Microsoft\Windows\Cookies\system@adserver.adtechus[1].txt
C:\Windows\System32\config\systemprofile\AppData\Roaming\Microsoft\Windows\Cookies\system@adtech[1].txt
C:\Windows\System32\config\systemprofile\AppData\Roaming\Microsoft\Windows\Cookies\system@advertise[1].txt
C:\Windows\System32\config\systemprofile\AppData\Roaming\Microsoft\Windows\Cookies\system@advertise[2].txt
C:\Windows\System32\config\systemprofile\AppData\Roaming\Microsoft\Windows\Cookies\system@advertise[3].txt
C:\Windows\System32\config\systemprofile\AppData\Roaming\Microsoft\Windows\Cookies\system@advertise[4].txt
C:\Windows\System32\config\systemprofile\AppData\Roaming\Microsoft\Windows\Cookies\system@advertise[5].txt
C:\Windows\System32\config\systemprofile\AppData\Roaming\Microsoft\Windows\Cookies\system@advertise[6].txt
C:\Windows\System32\config\systemprofile\AppData\Roaming\Microsoft\Windows\Cookies\system@advertise[7].txt
C:\Windows\System32\config\systemprofile\AppData\Roaming\Microsoft\Windows\Cookies\system@advertise[8].txt
C:\Windows\System32\config\systemprofile\AppData\Roaming\Microsoft\Windows\Cookies\system@advertising[2].txt
C:\Windows\System32\config\systemprofile\AppData\Roaming\Microsoft\Windows\Cookies\system@advertising[3].txt
C:\Windows\System32\config\systemprofile\AppData\Roaming\Microsoft\Windows\Cookies\system@adviva[1].txt
C:\Windows\System32\config\systemprofile\AppData\Roaming\Microsoft\Windows\Cookies\system@adxpose[1].txt
C:\Windows\System32\config\systemprofile\AppData\Roaming\Microsoft\Windows\Cookies\system@apmebf[1].txt
C:\Windows\System32\config\systemprofile\AppData\Roaming\Microsoft\Windows\Cookies\system@associatedcontent.112.2o7[1].txt
C:\Windows\System32\config\systemprofile\AppData\Roaming\Microsoft\Windows\Cookies\system@atdmt[1].txt
C:\Windows\System32\config\systemprofile\AppData\Roaming\Microsoft\Windows\Cookies\system@atdmt[2].txt
C:\Windows\System32\config\systemprofile\AppData\Roaming\Microsoft\Windows\Cookies\system@atdmt[3].txt
C:\Windows\System32\config\systemprofile\AppData\Roaming\Microsoft\Windows\Cookies\system@bizzclick[1].txt
C:\Windows\System32\config\systemprofile\AppData\Roaming\Microsoft\Windows\Cookies\system@click.fastpartner[1].txt
C:\Windows\System32\config\systemprofile\AppData\Roaming\Microsoft\Windows\Cookies\system@click.searchnation[2].txt
C:\Windows\System32\config\systemprofile\AppData\Roaming\Microsoft\Windows\Cookies\system@click.searchnation[3].txt
C:\Windows\System32\config\systemprofile\AppData\Roaming\Microsoft\Windows\Cookies\system@clickpayz10.91462.information-seeking[1].txt
C:\Windows\System32\config\systemprofile\AppData\Roaming\Microsoft\Windows\Cookies\system@clickpayz10.91491.information-seeking[1].txt
C:\Windows\System32\config\systemprofile\AppData\Roaming\Microsoft\Windows\Cookies\system@clickpayz9.91462.information-seeking[1].txt
C:\Windows\System32\config\systemprofile\AppData\Roaming\Microsoft\Windows\Cookies\system@clicks.mysearchfare[1].txt
C:\Windows\System32\config\systemprofile\AppData\Roaming\Microsoft\Windows\Cookies\system@content.yieldmanager[1].txt
C:\Windows\System32\config\systemprofile\AppData\Roaming\Microsoft\Windows\Cookies\system@content.yieldmanager[2].txt
C:\Windows\System32\config\systemprofile\AppData\Roaming\Microsoft\Windows\Cookies\system@content.yieldmanager[3].txt
C:\Windows\System32\config\systemprofile\AppData\Roaming\Microsoft\Windows\Cookies\system@content.yieldmanager[4].txt
C:\Windows\System32\config\systemprofile\AppData\Roaming\Microsoft\Windows\Cookies\system@content.yieldmanager[7].txt
C:\Windows\System32\config\systemprofile\AppData\Roaming\Microsoft\Windows\Cookies\system@digitalentertainment.122.2o7[1].txt
C:\Windows\System32\config\systemprofile\AppData\Roaming\Microsoft\Windows\Cookies\system@doubleclick[1].txt
C:\Windows\System32\config\systemprofile\AppData\Roaming\Microsoft\Windows\Cookies\system@doubleclick[2].txt
C:\Windows\System32\config\systemprofile\AppData\Roaming\Microsoft\Windows\Cookies\system@doubleclick[3].txt
C:\Windows\System32\config\systemprofile\AppData\Roaming\Microsoft\Windows\Cookies\system@doubleclick[4].txt
C:\Windows\System32\config\systemprofile\AppData\Roaming\Microsoft\Windows\Cookies\system@doubleclick[6].txt
C:\Windows\System32\config\systemprofile\AppData\Roaming\Microsoft\Windows\Cookies\system@eas.apm.emediate[2].txt
C:\Windows\System32\config\systemprofile\AppData\Roaming\Microsoft\Windows\Cookies\system@fastclick[1].txt
C:\Windows\System32\config\systemprofile\AppData\Roaming\Microsoft\Windows\Cookies\system@imrworldwide[2].txt
C:\Windows\System32\config\systemprofile\AppData\Roaming\Microsoft\Windows\Cookies\system@interclick[1].txt
C:\Windows\System32\config\systemprofile\AppData\Roaming\Microsoft\Windows\Cookies\system@invitemedia[1].txt
C:\Windows\System32\config\systemprofile\AppData\Roaming\Microsoft\Windows\Cookies\system@invitemedia[2].txt
C:\Windows\System32\config\systemprofile\AppData\Roaming\Microsoft\Windows\Cookies\system@kontera[1].txt
C:\Windows\System32\config\systemprofile\AppData\Roaming\Microsoft\Windows\Cookies\system@legolas-media[2].txt
C:\Windows\System32\config\systemprofile\AppData\Roaming\Microsoft\Windows\Cookies\system@media6degrees[1].txt
C:\Windows\System32\config\systemprofile\AppData\Roaming\Microsoft\Windows\Cookies\system@mediaplex[1].txt
C:\Windows\System32\config\systemprofile\AppData\Roaming\Microsoft\Windows\Cookies\system@mediaplex[2].txt
C:\Windows\System32\config\systemprofile\AppData\Roaming\Microsoft\Windows\Cookies\system@msnportal.112.2o7[1].txt
C:\Windows\System32\config\systemprofile\AppData\Roaming\Microsoft\Windows\Cookies\system@revsci[1].txt
C:\Windows\System32\config\systemprofile\AppData\Roaming\Microsoft\Windows\Cookies\system@roiservice[1].txt
C:\Windows\System32\config\systemprofile\AppData\Roaming\Microsoft\Windows\Cookies\system@ru4[2].txt
C:\Windows\System32\config\systemprofile\AppData\Roaming\Microsoft\Windows\Cookies\system@serving-sys[1].txt
C:\Windows\System32\config\systemprofile\AppData\Roaming\Microsoft\Windows\Cookies\system@specificclick[1].txt
C:\Windows\System32\config\systemprofile\AppData\Roaming\Microsoft\Windows\Cookies\system@statse.webtrendslive[1].txt
C:\Windows\System32\config\systemprofile\AppData\Roaming\Microsoft\Windows\Cookies\system@trafficengine[2].txt
C:\Windows\System32\config\systemprofile\AppData\Roaming\Microsoft\Windows\Cookies\system@user.lucidmedia[1].txt
C:\Windows\System32\config\systemprofile\AppData\Roaming\Microsoft\Windows\Cookies\system@user.lucidmedia[2].txt
C:\Windows\System32\config\systemprofile\AppData\Roaming\Microsoft\Windows\Cookies\system@vdwp.solution.weborama[2].txt
C:\Windows\System32\config\systemprofile\AppData\Roaming\Microsoft\Windows\Cookies\system@weborama[1].txt
C:\Windows\System32\config\systemprofile\AppData\Roaming\Microsoft\Windows\Cookies\system@www.googleadservices[1].txt
C:\Windows\System32\config\systemprofile\AppData\Roaming\Microsoft\Windows\Cookies\system@yieldmanager[1].txt

Malware.Trace
HKU\.DEFAULT\SOFTWARE\XML
HKU\S-1-5-18\SOFTWARE\XML

Trojan.Agent/Gen-HackPatch
C:\$RECYCLE.BIN\S-1-5-21-779687313-344747744-421721146-1000\$RBLTFQO.PATCH-LZ0\LZ0\PATCH.EXE


Army Chef

3. gmer

GMER 1.0.15.15530 - http://www.gmer.net
Rootkit scan 2010-11-10 18:22:48
Windows 6.0.6002 Service Pack 2 Harddisk0\DR0 -> \Device\Ide\IdeDeviceP2T0L0-2 WDC_WD1200BEVS-22UST0 rev.01.01A01
Running: gmer.exe; Driver: C:\Users\LESLIE~1\AppData\Local\Temp\fxtyypog.sys


---- System - GMER 1.0.15 ----

SSDT \??\C:\Program Files\Trusteer\Rapport\bin\RapportPG.sys ZwAssignProcessToJobObject [0x8DE4BFE4]
SSDT \??\C:\Program Files\Trusteer\Rapport\bin\RapportPG.sys ZwCreateFile [0x8DE4C996]
SSDT \??\C:\ProgramData\Trusteer\Rapport\store\exts\RapportCerberus\19417\RapportCerberus_19417.sys ZwCreateThread [0x8DE77864]
SSDT \??\C:\Program Files\Trusteer\Rapport\bin\RapportPG.sys ZwDeleteFile [0x8DE4CAF6]
SSDT \??\C:\Program Files\Trusteer\Rapport\bin\RapportPG.sys ZwDeleteKey [0x8DE5036C]
SSDT \??\C:\Program Files\Trusteer\Rapport\bin\RapportPG.sys ZwDeleteValueKey [0x8DE5039E]
SSDT \??\C:\Program Files\Trusteer\Rapport\bin\RapportPG.sys ZwLoadKey [0x8DE50500]
SSDT \??\C:\Program Files\Trusteer\Rapport\bin\RapportPG.sys ZwOpenFile [0x8DE4CA5A]
SSDT \??\C:\Program Files\Trusteer\Rapport\bin\RapportPG.sys ZwOpenProcess [0x8DE4C128]
SSDT \??\C:\Program Files\Trusteer\Rapport\bin\RapportPG.sys ZwOpenThread [0x8DE4C31A]
SSDT \??\C:\Program Files\Trusteer\Rapport\bin\RapportPG.sys ZwProtectVirtualMemory [0x8DE4C44C]
SSDT \??\C:\Program Files\Trusteer\Rapport\bin\RapportPG.sys ZwQueryValueKey [0x8DE50476]
SSDT \??\C:\Program Files\Trusteer\Rapport\bin\RapportPG.sys ZwRenameKey [0x8DE503E0]
SSDT \??\C:\Program Files\Trusteer\Rapport\bin\RapportPG.sys ZwReplaceKey [0x8DE50412]
SSDT \??\C:\Program Files\Trusteer\Rapport\bin\RapportPG.sys ZwRestoreKey [0x8DE50444]
SSDT \??\C:\Program Files\Trusteer\Rapport\bin\RapportPG.sys ZwSetContextThread [0x8DE4BF8A]
SSDT \??\C:\Program Files\Trusteer\Rapport\bin\RapportPG.sys ZwSetInformationFile [0x8DE4CB56]
SSDT \??\C:\ProgramData\Trusteer\Rapport\store\exts\RapportCerberus\19417\RapportCerberus_19417.sys ZwSetValueKey [0x8DE7782E]
SSDT \??\C:\Program Files\Trusteer\Rapport\bin\RapportPG.sys ZwSuspendThread [0x8DE4BF26]
SSDT \??\C:\Program Files\SUPERAntiSpyware\SASKUTIL.SYS ZwTerminateProcess [0x8CDA7620]
SSDT \??\C:\Program Files\Trusteer\Rapport\bin\RapportPG.sys ZwTerminateThread [0x8DE4BEC2]
SSDT \??\C:\ProgramData\Trusteer\Rapport\store\exts\RapportCerberus\19417\RapportCerberus_19417.sys ZwCreateThreadEx [0x8DE778DC]

---- Kernel code sections - GMER 1.0.15 ----

.text ntkrnlpa.exe!KeSetEvent + 191 826BC8F4 4 Bytes [E4, BF, E4, 8D] {IN AL, 0xbf; IN AL, 0x8d}
.text ntkrnlpa.exe!KeSetEvent + 1D9 826BC93C 4 Bytes [96, C9, E4, 8D] {XCHG ESI, EAX; LEAVE ; IN AL, 0x8d}
.text ntkrnlpa.exe!KeSetEvent + 221 826BC984 4 Bytes [64, 78, E7, 8D]
.text ntkrnlpa.exe!KeSetEvent + 2D1 826BCA34 8 Bytes [F6, CA, E4, 8D, 6C, 03, E5, ...]
.text ntkrnlpa.exe!KeSetEvent + 2E1 826BCA44 4 Bytes [9E, 03, E5, 8D]
.text ...

---- User code sections - GMER 1.0.15 ----

.text C:\Program Files\Internet Explorer\iexplore.exe[2000] kernel32.dll!CreateProcessInternalW 771353DF 5 Bytes JMP 0004767D
.text C:\Program Files\Internet Explorer\iexplore.exe[2000] USER32.dll!CreateDialogParamW 772A72A2 5 Bytes JMP 100EC20C C:\Program Files\Radio_Bar_1\tbRad1.dll (Conduit Toolbar/Conduit Ltd.)
.text C:\Program Files\Internet Explorer\iexplore.exe[2000] USER32.dll!GetAsyncKeyState 772A863C 5 Bytes JMP 6EBB8F0F C:\Windows\system32\IEFRAME.dll (Internet Explorer/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\iexplore.exe[2000] USER32.dll!SetWindowsHookExW 772A87AD 5 Bytes JMP 6EC99AED C:\Windows\system32\IEFRAME.dll (Internet Explorer/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\iexplore.exe[2000] USER32.dll!CallNextHookEx 772A8E3B 5 Bytes JMP 6EC8D14D C:\Windows\system32\IEFRAME.dll (Internet Explorer/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\iexplore.exe[2000] USER32.dll!UnhookWindowsHookEx 772A98DB 5 Bytes JMP 6EC04686 C:\Windows\system32\IEFRAME.dll (Internet Explorer/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\iexplore.exe[2000] USER32.dll!EnableWindow 772ACD8B 5 Bytes JMP 6EC9DD5D C:\Windows\system32\IEFRAME.dll (Internet Explorer/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\iexplore.exe[2000] USER32.dll!CreateWindowExW 772B1305 5 Bytes JMP 6EC9DB44 C:\Windows\system32\IEFRAME.dll (Internet Explorer/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\iexplore.exe[2000] USER32.dll!GetKeyState 772B8CB1 5 Bytes JMP 6EC9D30B C:\Windows\system32\IEFRAME.dll (Internet Explorer/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\iexplore.exe[2000] USER32.dll!IsDialogMessageW 772C0745 5 Bytes JMP 6EBC5A07 C:\Windows\system32\IEFRAME.dll (Internet Explorer/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\iexplore.exe[2000] USER32.dll!CreateDialogParamA 772C17AA 5 Bytes JMP 6ED95C93 C:\Windows\system32\IEFRAME.dll (Internet Explorer/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\iexplore.exe[2000] USER32.dll!IsDialogMessage 772C1847 5 Bytes JMP 6ED9552F C:\Windows\system32\IEFRAME.dll (Internet Explorer/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\iexplore.exe[2000] USER32.dll!CreateDialogIndirectParamA 772C26F1 5 Bytes JMP 6ED95CCA C:\Windows\system32\IEFRAME.dll (Internet Explorer/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\iexplore.exe[2000] USER32.dll!CreateDialogIndirectParamW 772C9A62 5 Bytes JMP 6ED95D01 C:\Windows\system32\IEFRAME.dll (Internet Explorer/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\iexplore.exe[2000] USER32.dll!SetKeyboardState 772D0987 5 Bytes JMP 6ED9589E C:\Windows\system32\IEFRAME.dll (Internet Explorer/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\iexplore.exe[2000] USER32.dll!DialogBoxParamW 772D10B0 5 Bytes JMP 100EC3DC C:\Program Files\Radio_Bar_1\tbRad1.dll (Conduit Toolbar/Conduit Ltd.)
.text C:\Program Files\Internet Explorer\iexplore.exe[2000] USER32.dll!DialogBoxIndirectParamW 772D2EF5 5 Bytes JMP 6ED95027 C:\Windows\system32\IEFRAME.dll (Internet Explorer/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\iexplore.exe[2000] USER32.dll!SendInput 772D2F75 5 Bytes JMP 6ED9645B C:\Windows\system32\IEFRAME.dll (Internet Explorer/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\iexplore.exe[2000] USER32.dll!EndDialog 772D326E 5 Bytes JMP 6EBC7EAE C:\Windows\system32\IEFRAME.dll (Internet Explorer/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\iexplore.exe[2000] USER32.dll!SetCursorPos 772E6FB2 5 Bytes JMP 6ED964AF C:\Windows\system32\IEFRAME.dll (Internet Explorer/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\iexplore.exe[2000] USER32.dll!DialogBoxParamA 772E8152 5 Bytes JMP 6ED94FC4 C:\Windows\system32\IEFRAME.dll (Internet Explorer/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\iexplore.exe[2000] USER32.dll!DialogBoxIndirectParamA 772E847D 5 Bytes JMP 6ED9508A C:\Windows\system32\IEFRAME.dll (Internet Explorer/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\iexplore.exe[2000] USER32.dll!MessageBoxIndirectA 772FD4D9 5 Bytes JMP 6ED94F59 C:\Windows\system32\IEFRAME.dll (Internet Explorer/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\iexplore.exe[2000] USER32.dll!MessageBoxIndirectW 772FD5D3 5 Bytes JMP 6ED94EEE C:\Windows\system32\IEFRAME.dll (Internet Explorer/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\iexplore.exe[2000] USER32.dll!MessageBoxExA 772FD639 5 Bytes JMP 6ED94E8C C:\Windows\system32\IEFRAME.dll (Internet Explorer/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\iexplore.exe[2000] USER32.dll!MessageBoxExW 772FD65D 5 Bytes JMP 6ED94E2A C:\Windows\system32\IEFRAME.dll (Internet Explorer/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\iexplore.exe[2000] USER32.dll!keybd_event 772FD972 5 Bytes JMP 6ED967DF C:\Windows\system32\IEFRAME.dll (Internet Explorer/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\iexplore.exe[2000] SHELL32.dll!SHRestricted + D95 762F89A8 4 Bytes [4D, 30, 64, 67]
.text C:\Program Files\Internet Explorer\iexplore.exe[2000] SHELL32.dll!SHRestricted + D9D 762F89B0 8 Bytes [57, 2F, 64, 67, 9C, 5B, 63, ...]
.text C:\Program Files\Internet Explorer\iexplore.exe[2000] ole32.dll!OleLoadFromStream 76071E80 5 Bytes JMP 6ED9538F C:\Windows\system32\IEFRAME.dll (Internet Explorer/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\iexplore.exe[2000] ole32.dll!CoCreateInstance 760A9F3E 5 Bytes JMP 6EC9DBA0 C:\Windows\system32\IEFRAME.dll (Internet Explorer/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\iexplore.exe[2000] ws2_32.dll!closesocket 76EE330C 5 Bytes JMP 000463C3
.text C:\Program Files\Internet Explorer\iexplore.exe[2000] ws2_32.dll!recv 76EE343A 5 Bytes JMP 0004600A
.text C:\Program Files\Internet Explorer\iexplore.exe[2000] ws2_32.dll!WSASend 76EE4496 5 Bytes JMP 000460E5
.text C:\Program Files\Internet Explorer\iexplore.exe[2000] ws2_32.dll!send 76EE659B 5 Bytes JMP 00045F97
.text C:\Program Files\Internet Explorer\iexplore.exe[2000] ws2_32.dll!WSARecv 76EE8400 5 Bytes JMP 00046194
.text C:\Windows\Explorer.EXE[3752] kernel32.dll!CreateProcessInternalW 771353DF 5 Bytes JMP 0167866A
.text C:\Program Files\Internet Explorer\iexplore.exe[5220] kernel32.dll!CreateProcessInternalW 771353DF 5 Bytes JMP 0004767D
.text C:\Program Files\Internet Explorer\iexplore.exe[5220] USER32.dll!CreateDialogParamW 772A72A2 5 Bytes JMP 100EC20C C:\Program Files\Radio_Bar_1\tbRad1.dll (Conduit Toolbar/Conduit Ltd.)
.text C:\Program Files\Internet Explorer\iexplore.exe[5220] USER32.dll!CreateWindowExW 772B1305 5 Bytes JMP 6EC9DB44 C:\Windows\system32\IEFRAME.dll (Internet Explorer/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\iexplore.exe[5220] USER32.dll!DialogBoxParamW 772D10B0 5 Bytes JMP 100EC3DC C:\Program Files\Radio_Bar_1\tbRad1.dll (Conduit Toolbar/Conduit Ltd.)
.text C:\Program Files\Internet Explorer\iexplore.exe[5220] USER32.dll!DialogBoxIndirectParamW 772D2EF5 5 Bytes JMP 6ED95027 C:\Windows\system32\IEFRAME.dll (Internet Explorer/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\iexplore.exe[5220] USER32.dll!DialogBoxParamA 772E8152 5 Bytes JMP 6ED94FC4 C:\Windows\system32\IEFRAME.dll (Internet Explorer/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\iexplore.exe[5220] USER32.dll!DialogBoxIndirectParamA 772E847D 5 Bytes JMP 6ED9508A C:\Windows\system32\IEFRAME.dll (Internet Explorer/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\iexplore.exe[5220] USER32.dll!MessageBoxIndirectA 772FD4D9 5 Bytes JMP 6ED94F59 C:\Windows\system32\IEFRAME.dll (Internet Explorer/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\iexplore.exe[5220] USER32.dll!MessageBoxIndirectW 772FD5D3 5 Bytes JMP 6ED94EEE C:\Windows\system32\IEFRAME.dll (Internet Explorer/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\iexplore.exe[5220] USER32.dll!MessageBoxExA 772FD639 5 Bytes JMP 6ED94E8C C:\Windows\system32\IEFRAME.dll (Internet Explorer/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\iexplore.exe[5220] USER32.dll!MessageBoxExW 772FD65D 5 Bytes JMP 6ED94E2A C:\Windows\system32\IEFRAME.dll (Internet Explorer/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\iexplore.exe[5220] ws2_32.dll!closesocket 76EE330C 5 Bytes JMP 000463C3
.text C:\Program Files\Internet Explorer\iexplore.exe[5220] ws2_32.dll!recv 76EE343A 5 Bytes JMP 0004600A
.text C:\Program Files\Internet Explorer\iexplore.exe[5220] ws2_32.dll!WSASend 76EE4496 5 Bytes JMP 000460E5
.text C:\Program Files\Internet Explorer\iexplore.exe[5220] ws2_32.dll!send 76EE659B 5 Bytes JMP 00045F97
.text C:\Program Files\Internet Explorer\iexplore.exe[5220] ws2_32.dll!WSARecv 76EE8400 5 Bytes JMP 00046194

---- User IAT/EAT - GMER 1.0.15 ----

IAT C:\Windows\RtHDVCpl.exe[348] @ C:\Windows\system32\kernel32.dll [ntdll.dll!NtCreateFile] [003C2F30] C:\Windows\TEMP\logishrd\LVPrcInj22.dll (Camera Helper Library./Logitech Inc.)
IAT C:\Windows\RtHDVCpl.exe[348] @ C:\Windows\system32\kernel32.dll [ntdll.dll!NtClose] [003C2D00] C:\Windows\TEMP\logishrd\LVPrcInj22.dll (Camera Helper Library./Logitech Inc.)
IAT C:\Windows\RtHDVCpl.exe[348] @ C:\Windows\system32\kernel32.dll [ntdll.dll!NtDeviceIoControlFile] [003C2CA0] C:\Windows\TEMP\logishrd\LVPrcInj22.dll (Camera Helper Library./Logitech Inc.)
IAT C:\Windows\RtHDVCpl.exe[348] @ C:\Windows\system32\kernel32.dll [ntdll.dll!NtDuplicateObject] [003C2CD0] C:\Windows\TEMP\logishrd\LVPrcInj22.dll (Camera Helper Library./Logitech Inc.)
IAT C:\Program Files\AVG\AVG9\avgui.exe[1048] @ C:\Windows\system32\kernel32.dll [ntdll.dll!NtCreateFile] [003D2F30] C:\Windows\TEMP\logishrd\LVPrcInj22.dll (Camera Helper Library./Logitech Inc.)
IAT C:\Program Files\AVG\AVG9\avgui.exe[1048] @ C:\Windows\system32\kernel32.dll [ntdll.dll!NtClose] [003D2D00] C:\Windows\TEMP\logishrd\LVPrcInj22.dll (Camera Helper Library./Logitech Inc.)
IAT C:\Program Files\AVG\AVG9\avgui.exe[1048] @ C:\Windows\system32\kernel32.dll [ntdll.dll!NtDeviceIoControlFile] [003D2CA0] C:\Windows\TEMP\logishrd\LVPrcInj22.dll (Camera Helper Library./Logitech Inc.)
IAT C:\Program Files\AVG\AVG9\avgui.exe[1048] @ C:\Windows\system32\kernel32.dll [ntdll.dll!NtDuplicateObject] [003D2CD0] C:\Windows\TEMP\logishrd\LVPrcInj22.dll (Camera Helper Library./Logitech Inc.)
IAT C:\Program Files\Common Files\Real\Update_OB\realsched.exe[1484] @ C:\Windows\system32\kernel32.dll [ntdll.dll!NtCreateFile] [003B2F30] C:\Windows\TEMP\logishrd\LVPrcInj22.dll (Camera Helper Library./Logitech Inc.)
IAT C:\Program Files\Common Files\Real\Update_OB\realsched.exe[1484] @ C:\Windows\system32\kernel32.dll [ntdll.dll!NtClose] [003B2D00] C:\Windows\TEMP\logishrd\LVPrcInj22.dll (Camera Helper Library./Logitech Inc.)
IAT C:\Program Files\Common Files\Real\Update_OB\realsched.exe[1484] @ C:\Windows\system32\kernel32.dll [ntdll.dll!NtDeviceIoControlFile] [003B2CA0] C:\Windows\TEMP\logishrd\LVPrcInj22.dll (Camera Helper Library./Logitech Inc.)
IAT C:\Program Files\Common Files\Real\Update_OB\realsched.exe[1484] @ C:\Windows\system32\kernel32.dll [ntdll.dll!NtDuplicateObject] [003B2CD0] C:\Windows\TEMP\logishrd\LVPrcInj22.dll (Camera Helper Library./Logitech Inc.)
IAT C:\Program Files\Spare Messaging\MessagingApp.exe[1648] @ C:\Windows\system32\KERNEL32.dll [ntdll.dll!NtCreateFile] [00152F30] C:\Windows\TEMP\logishrd\LVPrcInj22.dll (Camera Helper Library./Logitech Inc.)
IAT C:\Program Files\Spare Messaging\MessagingApp.exe[1648] @ C:\Windows\system32\KERNEL32.dll [ntdll.dll!NtClose] [00152D00] C:\Windows\TEMP\logishrd\LVPrcInj22.dll (Camera Helper Library./Logitech Inc.)
IAT C:\Program Files\Spare Messaging\MessagingApp.exe[1648] @ C:\Windows\system32\KERNEL32.dll [ntdll.dll!NtDeviceIoControlFile] [00152CA0] C:\Windows\TEMP\logishrd\LVPrcInj22.dll (Camera Helper Library./Logitech Inc.)
IAT C:\Program Files\Spare Messaging\MessagingApp.exe[1648] @ C:\Windows\system32\KERNEL32.dll [ntdll.dll!NtDuplicateObject] [00152CD0] C:\Windows\TEMP\logishrd\LVPrcInj22.dll (Camera Helper Library./Logitech Inc.)
IAT C:\Program Files\Internet Explorer\iexplore.exe[2000] @ C:\Windows\system32\kernel32.dll [ntdll.dll!NtCreateFile] [00802F30] C:\Windows\TEMP\logishrd\LVPrcInj22.dll (Camera Helper Library./Logitech Inc.)
IAT C:\Program Files\Internet Explorer\iexplore.exe[2000] @ C:\Windows\system32\kernel32.dll [ntdll.dll!NtClose] [00802D00] C:\Windows\TEMP\logishrd\LVPrcInj22.dll (Camera Helper Library./Logitech Inc.)
IAT C:\Program Files\Internet Explorer\iexplore.exe[2000] @ C:\Windows\system32\kernel32.dll [ntdll.dll!NtDeviceIoControlFile] [00802CA0] C:\Windows\TEMP\logishrd\LVPrcInj22.dll (Camera Helper Library./Logitech Inc.)
IAT C:\Program Files\Internet Explorer\iexplore.exe[2000] @ C:\Windows\system32\kernel32.dll [ntdll.dll!NtDuplicateObject] [00802CD0] C:\Windows\TEMP\logishrd\LVPrcInj22.dll (Camera Helper Library./Logitech Inc.)
IAT C:\Program Files\Internet Explorer\iexplore.exe[2000] @ C:\Windows\system32\ADVAPI32.dll [KERNEL32.dll!GetProcAddress] [676282F6] C:\Program Files\Internet Explorer\IEShims.dll (Internet Explorer Compatibility Shims/Microsoft Corporation)
IAT C:\Program Files\Internet Explorer\iexplore.exe[2000] @ C:\Windows\system32\RPCRT4.dll [KERNEL32.dll!GetProcAddress] [676282F6] C:\Program Files\Internet Explorer\IEShims.dll (Internet Explorer Compatibility Shims/Microsoft Corporation)
IAT C:\Program Files\Internet Explorer\iexplore.exe[2000] @ C:\Windows\system32\USER32.dll [KERNEL32.dll!SearchPathW] [67631AEC] C:\Program Files\Internet Explorer\IEShims.dll (Internet Explorer Compatibility Shims/Microsoft Corporation)
IAT C:\Program Files\Internet Explorer\iexplore.exe[2000] @ C:\Windows\system32\USER32.dll [KERNEL32.dll!LoadLibraryExW] [6763007C] C:\Program Files\Internet Explorer\IEShims.dll (Internet Explorer Compatibility Shims/Microsoft Corporation)
IAT C:\Program Files\Internet Explorer\iexplore.exe[2000] @ C:\Windows\system32\USER32.dll [KERNEL32.dll!CopyFileW] [6762E1E9] C:\Program Files\Internet Explorer\IEShims.dll (Internet Explorer Compatibility Shims/Microsoft Corporation)
IAT C:\Program Files\Internet Explorer\iexplore.exe[2000] @ C:\Windows\system32\USER32.dll [KERNEL32.dll!MoveFileW] [67630994] C:\Program Files\Internet Explorer\IEShims.dll (Internet Explorer Compatibility Shims/Microsoft Corporation)
IAT C:\Program Files\Internet Explorer\iexplore.exe[2000] @ C:\Windows\system32\USER32.dll [KERNEL32.dll!DeleteFileW] [6762EE46] C:\Program Files\Internet Explorer\IEShims.dll (Internet Explorer Compatibility Shims/Microsoft Corporation)
IAT C:\Program Files\Internet Explorer\iexplore.exe[2000] @ C:\Windows\system32\USER32.dll [KERNEL32.dll!CreateProcessW] [6762A3FB] C:\Program Files\Internet Explorer\IEShims.dll (Internet Explorer Compatibility Shims/Microsoft Corporation)
IAT C:\Program Files\Internet Explorer\iexplore.exe[2000] @ C:\Windows\system32\USER32.dll [KERNEL32.dll!SetCurrentDirectoryW] [67631D56] C:\Program Files\Internet Explorer\IEShims.dll (Internet Explorer Compatibility Shims/Microsoft Corporation)
IAT C:\Program Files\Internet Explorer\iexplore.exe[2000] @ C:\Windows\system32\USER32.dll [KERNEL32.dll!FindClose] [67633ADC] C:\Program Files\Internet Explorer\IEShims.dll (Internet Explorer Compatibility Shims/Microsoft Corporation)
IAT C:\Program Files\Internet Explorer\iexplore.exe[2000] @ C:\Windows\system32\USER32.dll [KERNEL32.dll!FindNextFileW] [67632999] C:\Program Files\Internet Explorer\IEShims.dll (Internet Explorer Compatibility Shims/Microsoft Corporation)
IAT C:\Program Files\Internet Explorer\iexplore.exe[2000] @ C:\Windows\system32\USER32.dll [KERNEL32.dll!FindFirstFileW] [67633035] C:\Program Files\Internet Explorer\IEShims.dll (Internet Explorer Compatibility Shims/Microsoft Corporation)
IAT C:\Program Files\Internet Explorer\iexplore.exe[2000] @ C:\Windows\system32\USER32.dll [KERNEL32.dll!LoadLibraryA] [6762FBE1] C:\Program Files\Internet Explorer\IEShims.dll (Internet Explorer Compatibility Shims/Microsoft Corporation)
IAT C:\Program Files\Internet Explorer\iexplore.exe[2000] @ C:\Windows\system32\USER32.dll [KERNEL32.dll!CreateFileW] [6762E860] C:\Program Files\Internet Explorer\IEShims.dll (Internet Explorer Compatibility Shims/Microsoft Corporation)
IAT C:\Program Files\Internet Explorer\iexplore.exe[2000] @ C:\Windows\system32\USER32.dll [KERNEL32.dll!WritePrivateProfileStringW] [6762DC5C] C:\Program Files\Internet Explorer\IEShims.dll (Internet Explorer Compatibility Shims/Microsoft Corporation)
IAT C:\Program Files\Internet Explorer\iexplore.exe[2000] @ C:\Windows\system32\USER32.dll [KERNEL32.dll!LoadLibraryW] [6762FD66] C:\Program Files\Internet Explorer\IEShims.dll (Internet Explorer Compatibility Shims/Microsoft Corporation)
IAT C:\Program Files\Internet Explorer\iexplore.exe[2000] @ C:\Windows\system32\USER32.dll [KERNEL32.dll!GetProcAddress] [676282F6] C:\Program Files\Internet Explorer\IEShims.dll (Internet Explorer Compatibility Shims/Microsoft Corporation)
IAT C:\Program Files\Internet Explorer\iexplore.exe[2000] @ C:\Windows\system32\USER32.dll [KERNEL32.dll!GetPrivateProfileStringW] [6762D4B8] C:\Program Files\Internet Explorer\IEShims.dll (Internet Explorer Compatibility Shims/Microsoft Corporation)
IAT C:\Program Files\Internet Explorer\iexplore.exe[2000] @ C:\Windows\system32\USER32.dll [ADVAPI32.dll!RegQueryInfoKeyW] [6763FBB3] C:\Program Files\Internet Explorer\IEShims.dll (Internet Explorer Compatibility Shims/Microsoft Corporation)
IAT C:\Program Files\Internet Explorer\iexplore.exe[2000] @ C:\Windows\system32\USER32.dll [ADVAPI32.dll!RegEnumValueW] [6764051D] C:\Program Files\Internet Explorer\IEShims.dll (Internet Explorer Compatibility Shims/Microsoft Corporation)
IAT C:\Program Files\Internet Explorer\iexplore.exe[2000] @ C:\Windows\system32\USER32.dll [ADVAPI32.dll!RegOpenKeyExW] [6763EB3D] C:\Program Files\Internet Explorer\IEShims.dll (Internet Explorer Compatibility Shims/Microsoft Corporation)
IAT C:\Program Files\Internet Explorer\iexplore.exe[2000] @ C:\Windows\system32\USER32.dll [ADVAPI32.dll!RegQueryValueExW] [6763F817] C:\Program Files\Internet Explorer\IEShims.dll (Internet Explorer Compatibility Shims/Microsoft Corporation)
IAT C:\Program Files\Internet Explorer\iexplore.exe[2000] @ C:\Windows\system32\USER32.dll [ADVAPI32.dll!RegDeleteKeyW] [6763EF31] C:\Program Files\Internet Explorer\IEShims.dll (Internet Explorer Compatibility Shims/Microsoft Corporation)
IAT C:\Program Files\Internet Explorer\iexplore.exe[2000] @ C:\Windows\system32\USER32.dll [ADVAPI32.dll!RegCreateKeyExW] [6763E5C5] C:\Program Files\Internet Explorer\IEShims.dll (Internet Explorer Compatibility Shims/Microsoft Corporation)
IAT C:\Program Files\Internet Explorer\iexplore.exe[2000] @ C:\Windows\system32\USER32.dll [ADVAPI32.dll!RegCloseKey] [6763ED95] C:\Program Files\Internet Explorer\IEShims.dll (Internet Explorer Compatibility Shims/Microsoft Corporation)
IAT C:\Program Files\Internet Explorer\iexplore.exe[2000] @ C:\Windows\system32\GDI32.dll [KERNEL32.dll!LoadLibraryExW] [6763007C] C:\Program Files\Internet Explorer\IEShims.dll (Internet Explorer Compatibility Shims/Microsoft Corporation)
IAT C:\Program Files\Internet Explorer\iexplore.exe[2000] @ C:\Windows\system32\GDI32.dll [KERNEL32.dll!LoadLibraryA] [6762FBE1] C:\Program Files\Internet Explorer\IEShims.dll (Internet Explorer Compatibility Shims/Microsoft Corporation)
IAT C:\Program Files\Internet Explorer\iexplore.exe[2000] @ C:\Windows\system32\GDI32.dll [KERNEL32.dll!CopyFileW] [6762E1E9] C:\Program Files\Internet Explorer\IEShims.dll (Internet Explorer Compatibility Shims/Microsoft Corporation)
IAT C:\Program Files\Internet Explorer\iexplore.exe[2000] @ C:\Windows\system32\GDI32.dll [KERNEL32.dll!GetProcAddress] [676282F6] C:\Program Files\Internet Explorer\IEShims.dll (Internet Explorer Compatibility Shims/Microsoft Corporation)
IAT C:\Program Files\Internet Explorer\iexplore.exe[2000] @ C:\Windows\system32\GDI32.dll [KERNEL32.dll!LoadLibraryW] [6762FD66] C:\Program Files\Internet Explorer\IEShims.dll (Internet Explorer Compatibility Shims/Microsoft Corporation)
IAT C:\Program Files\Internet Explorer\iexplore.exe[2000] @ C:\Windows\system32\GDI32.dll [KERNEL32.dll!CreateFileW] [6762E860] C:\Program Files\Internet Explorer\IEShims.dll (Internet Explorer Compatibility Shims/Microsoft Corporation)
IAT C:\Program Files\Internet Explorer\iexplore.exe[2000] @ C:\Windows\system32\GDI32.dll [KERNEL32.dll!SearchPathW] [67631AEC] C:\Program Files\Internet Explorer\IEShims.dll (Internet Explorer Compatibility Shims/Microsoft Corporation)
IAT C:\Program Files\Internet Explorer\iexplore.exe[2000] @ C:\Windows\system32\GDI32.dll [KERNEL32.dll!DeleteFileW] [6762EE46] C:\Program Files\Internet Explorer\IEShims.dll (Internet Explorer Compatibility Shims/Microsoft Corporation)
IAT C:\Program Files\Internet Explorer\iexplore.exe[2000] @ C:\Windows\system32\msvcrt.dll [KERNEL32.dll!FindClose] [67633ADC] C:\Program Files\Internet Explorer\IEShims.dll (Internet Explorer Compatibility Shims/Microsoft Corporation)
IAT C:\Program Files\Internet Explorer\iexplore.exe[2000] @ C:\Windows\system32\msvcrt.dll [KERNEL32.dll!FindFirstFileA] [67632CD2] C:\Program Files\Internet Explorer\IEShims.dll (Internet Explorer Compatibility Shims/Microsoft Corporation)
IAT C:\Program Files\Internet Explorer\iexplore.exe[2000] @ C:\Windows\system32\msvcrt.dll [KERNEL32.dll!FindNextFileA] [67632926] C:\Program Files\Internet Explorer\IEShims.dll (Internet Explorer Compatibility Shims/Microsoft Corporation)
IAT C:\Program Files\Internet Explorer\iexplore.exe[2000] @ C:\Windows\system32\msvcrt.dll [KERNEL32.dll!FindFirstFileW] [67633035] C:\Program Files\Internet Explorer\IEShims.dll (Internet Explorer Compatibility Shims/Microsoft Corporation)
IAT C:\Program Files\Internet Explorer\iexplore.exe[2000] @ C:\Windows\system32\msvcrt.dll [KERNEL32.dll!FindNextFileW] [67632999] C:\Program Files\Internet Explorer\IEShims.dll (Internet Explorer Compatibility Shims/Microsoft Corporation)
IAT C:\Program Files\Internet Explorer\iexplore.exe[2000] @ C:\Windows\system32\msvcrt.dll [KERNEL32.dll!GetFileAttributesA] [6762BD77] C:\Program Files\Internet Explorer\IEShims.dll (Internet Explorer Compatibility Shims/Microsoft Corporation)
IAT C:\Program Files\Internet Explorer\iexplore.exe[2000] @ C:\Windows\system32\msvcrt.dll [KERNEL32.dll!SetCurrentDirectoryA] [6763173F] C:\Program Files\Internet Explorer\IEShims.dll (Internet Explorer Compatibility Shims/Microsoft Corporation)
IAT C:\Program Files\Internet Explorer\iexplore.exe[2000] @ C:\Windows\system32\msvcrt.dll [KERNEL32.dll!SetFileAttributesA] [6762BFCD] C:\Program Files\Internet Explorer\IEShims.dll (Internet Explorer Compatibility Shims/Microsoft Corporation)
IAT C:\Program Files\Internet Explorer\iexplore.exe[2000] @ C:\Windows\system32\msvcrt.dll [KERNEL32.dll!CreateDirectoryA] [67630F0F] C:\Program Files\Internet Explorer\IEShims.dll (Internet Explorer Compatibility Shims/Microsoft Corporation)
IAT C:\Program Files\Internet Explorer\iexplore.exe[2000] @ C:\Windows\system32\msvcrt.dll [KERNEL32.dll!RemoveDirectoryA] [676314E9] C:\Program Files\Internet Explorer\IEShims.dll (Internet Explorer Compatibility Shims/Microsoft Corporation)
IAT C:\Program Files\Internet Explorer\iexplore.exe[2000] @ C:\Windows\system32\msvcrt.dll [KERNEL32.dll!DeleteFileA] [6762ED1B] C:\Program Files\Internet Explorer\IEShims.dll (Internet Explorer Compatibility Shims/Microsoft Corporation)
IAT C:\Program Files\Internet Explorer\iexplore.exe[2000] @ C:\Windows\system32\msvcrt.dll [KERNEL32.dll!GetFileAttributesW] [6762BEA2] C:\Program Files\Internet Explorer\IEShims.dll (Internet Explorer Compatibility Shims/Microsoft Corporation)
IAT C:\Program Files\Internet Explorer\iexplore.exe[2000] @ C:\Windows\system32\msvcrt.dll [KERNEL32.dll!SetCurrentDirectoryW] [67631D56] C:\Program Files\Internet Explorer\IEShims.dll (Internet Explorer Compatibility Shims/Microsoft Corporation)
IAT C:\Program Files\Internet Explorer\iexplore.exe[2000] @ C:\Windows\system32\msvcrt.dll [KERNEL32.dll!SetFileAttributesW] [6762C0FB] C:\Program Files\Internet Explorer\IEShims.dll (Internet Explorer Compatibility Shims/Microsoft Corporation)
IAT C:\Program Files\Internet Explorer\iexplore.exe[2000] @ C:\Windows\system32\msvcrt.dll [KERNEL32.dll!CreateDirectoryW] [6763103D] C:\Program Files\Internet Explorer\IEShims.dll (Internet Explorer Compatibility Shims/Microsoft Corporation)
IAT C:\Program Files\Internet Explorer\iexplore.exe[2000] @ C:\Windows\system32\msvcrt.dll [KERNEL32.dll!DeleteFileW] [6762EE46] C:\Program Files\Internet Explorer\IEShims.dll (Internet Explorer Compatibility Shims/Microsoft Corporation)
IAT C:\Program Files\Internet Explorer\iexplore.exe[2000] @ C:\Windows\system32\msvcrt.dll [KERNEL32.dll!MoveFileW] [67630994] C:\Program Files\Internet Explorer\IEShims.dll (Internet Explorer Compatibility Shims/Microsoft Corporation)
IAT C:\Program Files\Internet Explorer\iexplore.exe[2000] @ C:\Windows\system32\msvcrt.dll [KERNEL32.dll!RemoveDirectoryW] [67631614] C:\Program Files\Internet Explorer\IEShims.dll (Internet Explorer Compatibility Shims/Microsoft Corporation)
IAT C:\Program Files\Internet Explorer\iexplore.exe[2000] @ C:\Windows\system32\msvcrt.dll [KERNEL32.dll!MoveFileA] [67630921] C:\Program Files\Internet Explorer\IEShims.dll (Internet Explorer Compatibility Shims/Microsoft Corporation)
IAT C:\Program Files\Internet Explorer\iexplore.exe[2000] @ C:\Windows\system32\msvcrt.dll [KERNEL32.dll!GetProcAddress] [676282F6] C:\Program Files\Internet Explorer\IEShims.dll (Internet Explorer Compatibility Shims/Microsoft Corporation)
IAT C:\Program Files\Internet Explorer\iexplore.exe[2000] @ C:\Windows\system32\msvcrt.dll [KERNEL32.dll!LoadLibraryA] [6762FBE1] C:\Program Files\Internet Explorer\IEShims.dll (Internet Explorer Compatibility Shims/Microsoft Corporation)
IAT C:\Program Files\Internet Explorer\iexplore.exe[2000] @ C:\Windows\system32\msvcrt.dll [KERNEL32.dll!CreateProcessA] [6762A073] C:\Program Files\Internet Explorer\IEShims.dll (Internet Explorer Compatibility Shims/Microsoft Corporation)
IAT C:\Program Files\Internet Explorer\iexplore.exe[2000] @ C:\Windows\system32\msvcrt.dll [KERNEL32.dll!CreateProcessW] [6762A3FB] C:\Program Files\Internet Explorer\IEShims.dll (Internet Explorer Compatibility Shims/Microsoft Corporation)
IAT C:\Program Files\Internet Explorer\iexplore.exe[2000] @ C:\Windows\system32\msvcrt.dll [KERNEL32.dll!CreateFileA] [6762E717] C:\Program Files\Internet Explorer\IEShims.dll (Internet Explorer Compatibility Shims/Microsoft Corporation)
IAT C:\Program Files\Internet Explorer\iexplore.exe[2000] @ C:\Windows\system32\msvcrt.dll [KERNEL32.dll!CreateFileW] [6762E860] C:\Program Files\Internet Explorer\IEShims.dll (Internet Explorer Compatibility Shims/Microsoft Corporation)
IAT C:\Program Files\Internet Explorer\iexplore.exe[2000] @ C:\Windows\system32\msvcrt.dll [KERNEL32.dll!LoadLibraryW] [6762FD66] C:\Program Files\Internet Explorer\IEShims.dll (Internet Explorer Compatibility Shims/Microsoft Corporation)
IAT C:\Program Files\Internet Explorer\iexplore.exe[2000] @ C:\Windows\system32\SHLWAPI.dll [KERNEL32.dll!LoadLibraryW] [6762FD66] C:\Program Files\Internet Explorer\IEShims.dll (Internet Explorer Compatibility Shims/Microsoft Corporation)
IAT C:\Program Files\Internet Explorer\iexplore.exe[2000] @ C:\Windows\system32\SHLWAPI.dll [KERNEL32.dll!ReplaceFileW] [67630C95] C:\Program Files\Internet Explorer\IEShims.dll (Internet Explorer Compatibility Shims/Microsoft Corporation)
IAT C:\Program Files\Internet Explorer\iexplore.exe[2000] @ C:\Windows\system32\SHLWAPI.dll [KERNEL32.dll!WritePrivateProfileStringW] [6762DC5C] C:\Program Files\Internet Explorer\IEShims.dll (Internet Explorer Compatibility Shims/Microsoft Corporation)
IAT C:\Program Files\Internet Explorer\iexplore.exe[2000] @ C:\Windows\system32\SHLWAPI.dll [KERNEL32.dll!GetPrivateProfileStringW] [6762D4B8] C:\Program Files\Internet Explorer\IEShims.dll (Internet Explorer Compatibility Shims/Microsoft Corporation)
IAT C:\Program Files\Internet Explorer\iexplore.exe[2000] @ C:\Windows\system32\SHLWAPI.dll [KERNEL32.dll!GetPrivateProfileStringA] [6762D361] C:\Program Files\Internet Explorer\IEShims.dll (Internet Explorer Compatibility Shims/Microsoft Corporation)
IAT C:\Program Files\Internet Explorer\iexplore.exe[2000] @ C:\Windows\system32\SHLWAPI.dll [KERNEL32.dll!DeleteFileW] [6762EE46] C:\Program Files\Internet Explorer\IEShims.dll (Internet Explorer Compatibility Shims/Microsoft Corporation)
IAT C:\Program Files\Internet Explorer\iexplore.exe[2000] @ C:\Windows\system32\SHLWAPI.dll [KERNEL32.dll!LoadLibraryExW] [6763007C] C:\Program Files\Internet Explorer\IEShims.dll (Internet Explorer Compatibility Shims/Microsoft Corporation)
IAT C:\Program Files\Internet Explorer\iexplore.exe[2000] @ C:\Windows\system32\SHLWAPI.dll [KERNEL32.dll!SetFileAttributesW] [6762C0FB] C:\Program Files\Internet Explorer\IEShims.dll (Internet Explorer Compatibility Shims/Microsoft Corporation)
IAT C:\Program Files\Internet Explorer\iexplore.exe[2000] @ C:\Windows\system32\SHLWAPI.dll [KERNEL32.dll!CreateFileW] [6762E860] C:\Program Files\Internet Explorer\IEShims.dll (Internet Explorer Compatibility Shims/Microsoft Corporation)
IAT C:\Program Files\Internet Explorer\iexplore.exe[2000] @ C:\Windows\system32\SHLWAPI.dll [KERNEL32.dll!FindFirstFileW] [67633035] C:\Program Files\Internet Explorer\IEShims.dll (Internet Explorer Compatibility Shims/Microsoft Corporation)
IAT C:\Program Files\Internet Explorer\iexplore.exe[2000] @ C:\Windows\system32\SHLWAPI.dll [KERNEL32.dll!FindNextFileW] [67632999] C:\Program Files\Internet Explorer\IEShims.dll (Internet Explorer Compatibility Shims/Microsoft Corporation)
IAT C:\Program Files\Internet Explorer\iexplore.exe[2000] @ C:\Windows\system32\SHLWAPI.dll [KERNEL32.dll!SearchPathW] [67631AEC] C:\Program Files\Internet Explorer\IEShims.dll (Internet Explorer Compatibility Shims/Microsoft Corporation)
IAT C:\Program Files\Internet Explorer\iexplore.exe[2000] @ C:\Windows\system32\SHLWAPI.dll [KERNEL32.dll!GetFileAttributesW] [6762BEA2] C:\Program Files\Internet Explorer\IEShims.dll (Internet Explorer Compatibility Shims/Microsoft Corporation)
IAT C:\Program Files\Internet Explorer\iexplore.exe[2000] @ C:\Windows\system32\SHLWAPI.dll [KERNEL32.dll!SetFileAttributesA] [6762BFCD] C:\Program Files\Internet Explorer\IEShims.dll (Internet Explorer Compatibility Shims/Microsoft Corporation)
IAT C:\Program Files\Internet Explorer\iexplore.exe[2000] @ C:\Windows\system32\SHLWAPI.dll [KERNEL32.dll!CreateFileA] [6762E717] C:\Program Files\Internet Explorer\IEShims.dll (Internet Explorer Compatibility Shims/Microsoft Corporation)
IAT C:\Program Files\Internet Explorer\iexplore.exe[2000] @ C:\Windows\system32\SHLWAPI.dll [KERNEL32.dll!FindFirstFileA] [67632CD2] C:\Program Files\Internet Explorer\IEShims.dll (Internet Explorer Compatibility Shims/Microsoft Corporation)
IAT C:\Program Files\Internet Explorer\iexplore.exe[2000] @ C:\Windows\system32\SHLWAPI.dll [KERNEL32.dll!FindNextFileA] [67632926] C:\Program Files\Internet Explorer\IEShims.dll (Internet Explorer Compatibility Shims/Microsoft Corporation)
IAT C:\Program Files\Internet Explorer\iexplore.exe[2000] @ C:\Windows\system32\SHLWAPI.dll [KERNEL32.dll!FindClose] [67633ADC] C:\Program Files\Internet Explorer\IEShims.dll (Internet Explorer Compatibility Shims/Microsoft Corporation)
IAT C:\Program Files\Internet Explorer\iexplore.exe[2000] @ C:\Windows\system32\SHLWAPI.dll [KERNEL32.dll!SearchPathA] [676323A5] C:\Program Files\Internet Explorer\IEShims.dll (Internet Explorer Compatibility Shims/Microsoft Corporation)
IAT C:\Program Files\Internet Explorer\iexplore.exe[2000] @ C:\Windows\system32\SHLWAPI.dll [KERNEL32.dll!GetFileAttributesA] [6762BD77] C:\Program Files\Internet Explorer\IEShims.dll (Internet Explorer Compatibility Shims/Microsoft Corporation)
IAT C:\Program Files\Internet Explorer\iexplore.exe[2000] @ C:\Windows\system32\SHLWAPI.dll [KERNEL32.dll!LoadLibraryA] [6762FBE1] C:\Program Files\Internet Explorer\IEShims.dll (Internet Explorer Compatibility Shims/Microsoft Corporation)
IAT C:\Program Files\Internet Explorer\iexplore.exe[2000] @ C:\Windows\system32\SHLWAPI.dll [KERNEL32.dll!GetProcAddress] [676282F6] C:\Program Files\Internet Explorer\IEShims.dll (Internet Explorer Compatibility Shims/Microsoft Corporation)
IAT C:\Program Files\Internet Explorer\iexplore.exe[2000] @ C:\Windows\system32\SHLWAPI.dll [USER32.dll!WinHelpW] [6762FAAA] C:\Program Files\Internet Explorer\IEShims.dll (Internet Explorer Compatibility Shims/Microsoft Corporation)
IAT C:\Program Files\Internet Explorer\iexplore.exe[2000] @ C:\Windows\system32\SHLWAPI.dll [USER32.dll!WinHelpA] [6762F973] C:\Program Files\Internet Explorer\IEShims.dll (Internet Explorer Compatibility Shims/Microsoft Corporation)
IAT C:\Program Files\Internet Explorer\iexplore.exe[2000] @ C:\Windows\system32\SHLWAPI.dll [ADVAPI32.dll!RegCloseKey] [6763ED95] C:\Program Files\Internet Explorer\IEShims.dll (Internet Explorer Compatibility Shims/Microsoft Corporation)
IAT C:\Program Files\Internet Explorer\iexplore.exe[2000] @ C:\Windows\system32\SHLWAPI.dll [ADVAPI32.dll!RegCreateKeyExA] [6763E43D] C:\Program Files\Internet Explorer\IEShims.dll (Internet Explorer Compatibility Shims/Microsoft Corporation)
IAT C:\Program Files\Internet Explorer\iexplore.exe[2000] @ C:\Windows\system32\SHLWAPI.dll [ADVAPI32.dll!RegDeleteKeyA] [6763EDE8] C:\Program Files\Internet Explorer\IEShims.dll (Internet Explorer Compatibility Shims/Microsoft Corporation)
IAT C:\Program Files\Internet Explorer\iexplore.exe[2000] @ C:\Windows\system32\SHLWAPI.dll [ADVAPI32.dll!RegQueryInfoKeyA] [6763F9B7] C:\Program Files\Internet Explorer\IEShims.dll (Internet Explorer Compatibility Shims/Microsoft Corporation)
IAT C:\Program Files\Internet Explorer\iexplore.exe[2000] @ C:\Windows\system32\SHLWAPI.dll [ADVAPI32.dll!RegOpenKeyExA] [6763E9C5] C:\Program Files\Internet Explorer\IEShims.dll (Internet Explorer Compatibility Shims/Microsoft Corporation)
IAT C:\Program Files\Internet Explorer\iexplore.exe[2000] @ C:\Windows\system32\SHLWAPI.dll [ADVAPI32.dll!RegCreateKeyExW] [6763E5C5] C:\Program Files\Internet Explorer\IEShims.dll (Internet Explorer Compatibility Shims/Microsoft Corporation)
IAT C:\Program Files\Internet Explorer\iexplore.exe[2000] @ C:\Windows\system32\SHLWAPI.dll [ADVAPI32.dll!RegOpenKeyExW] [6763EB3D] C:\Program Files\Internet Explorer\IEShims.dll (Internet Explorer Compatibility Shims/Microsoft Corporation)
IAT C:\Program Files\Internet Explorer\iexplore.exe[2000] @ C:\Windows\system32\SHLWAPI.dll [ADVAPI32.dll!RegEnumKeyExW] [6764020D] C:\Program Files\Internet Explorer\IEShims.dll (Internet Explorer Compatibility Shims/Microsoft Corporation)
IAT C:\Program Files\Internet Explorer\iexplore.exe[2000] @ C:\Windows\system32\SHLWAPI.dll [ADVAPI32.dll!RegQueryValueW] [6763F4DB] C:\Program Files\Internet Explorer\IEShims.dll (Internet Explorer Compatibility Shims/Microsoft Corporation)
IAT C:\Program Files\Internet Explorer\iexplore.exe[2000] @ C:\Windows\system32\SHLWAPI.dll [ADVAPI32.dll!RegDeleteKeyW] [6763EF31] C:\Program Files\Internet Explorer\IEShims.dll (Internet Explorer Compatibility Shims/Microsoft Corporation)
IAT C:\Program Files\Internet Explorer\iexplore.exe[2000] @ C:\Windows\system32\SHLWAPI.dll [ADVAPI32.dll!RegQueryInfoKeyW] [6763FBB3] C:\Program Files\Internet Explorer\IEShims.dll (Internet Explorer Compatibility Shims/Microsoft Corporation)
IAT C:\Program Files\Internet Explorer\iexplore.exe[2000] @ C:\Windows\system32\SHLWAPI.dll [ADVAPI32.dll!RegQueryValueExW] [6763F817] C:\Program Files\Internet Explorer\IEShims.dll (Internet Explorer Compatibility Shims/Microsoft Corporation)
IAT C:\Program Files\Internet Explorer\iexplore.exe[2000] @ C:\Windows\system32\SHLWAPI.dll [ADVAPI32.dll!RegEnumValueW] [6764051D] C:\Program Files\Internet Explorer\IEShims.dll (Internet Explorer Compatibility Shims/Microsoft Corporation)
IAT C:\Program Files\Internet Explorer\iexplore.exe[2000] @ C:\Windows\system32\SHLWAPI.dll [ADVAPI32.dll!RegEnumKeyW] [6763FF19] C:\Program Files\Internet Explorer\IEShims.dll (Internet Explorer Compatibility Shims/Microsoft Corporation)
IAT C:\Program Files\Internet Explorer\iexplore.exe[2000] @ C:\Windows\system32\SHLWAPI.dll [ADVAPI32.dll!RegEnumKeyExA] [67640085] C:\Program Files\Internet Explorer\IEShims.dll (Internet Explorer Compatibility Shims/Microsoft Corporation)
IAT C:\Program Files\Internet Explorer\iexplore.exe[2000] @ C:\Windows\system32\SHLWAPI.dll [ADVAPI32.dll!RegEnumValueA] [67640395] C:\Program Files\Internet Explorer\IEShims.dll (Internet Explorer Compatibility Shims/Microsoft Corporation)
IAT C:\Program Files\Internet Explorer\iexplore.exe[2000] @ C:\Windows\system32\SHLWAPI.dll [ADVAPI32.dll!RegEnumKeyA] [6763FDAF] C:\Program Files\Internet Explorer\IEShims.dll (Internet Explorer Compatibility Shims/Microsoft Corporation)
IAT C:\Program Files\Internet Explorer\iexplore.exe[2000] @ C:\Windows\system32\SHLWAPI.dll [ADVAPI32.dll!RegQueryValueExA] [6763F677] C:\Program Files\Internet Explorer\IEShims.dll (Internet Explorer Compatibility Shims/Microsoft Corporation)
IAT C:\Program Files\Internet Explorer\iexplore.exe[2000] @ C:\Windows\system32\SHELL32.dll [KERNEL32.dll!GetPrivateProfileSectionW] [6762CFA8] C:\Program Files\Internet Explorer\IEShims.dll (Internet Explorer Compatibility Shims/Microsoft Corporation)
IAT C:\Program Files\Internet Explorer\iexplore.exe[2000] @ C:\Windows\system32\SHELL32.dll [KERNEL32.dll!FindNextFileW] [67632999] C:\Program Files\Internet Explorer\IEShims.dll (Internet Explorer Compatibility Shims/Microsoft Corporation)
IAT C:\Program Files\Internet Explorer\iexplore.exe[2000] @ C:\Windows\system32\SHELL32.dll [KERNEL32.dll!ReplaceFileW] [67630C95] C:\Program Files\Internet Explorer\IEShims.dll (Internet Explorer Compatibility Shims/Microsoft Corporation)
IAT C:\Program Files\Internet Explorer\iexplore.exe[2000] @ C:\Windows\system32\SHELL32.dll [KERNEL32.dll!GetPrivateProfileSectionNamesW] [6762D22A] C:\Program Files\Internet Explorer\IEShims.dll (Internet Explorer Compatibility Shims/Microsoft Corporation)
IAT C:\Program Files\Internet Explorer\iexplore.exe[2000] @ C:\Windows\system32\SHELL32.dll [KERNEL32.dll!WritePrivateProfileSectionW] [6762D9DA] C:\Program Files\Internet Explorer\IEShims.dll (Internet Explorer Compatibility Shims/Microsoft Corporation)
IAT C:\Program Files\Internet Explorer\iexplore.exe[2000] @ C:\Windows\system32\SHELL32.dll [KERNEL32.dll!WritePrivateProfileStringW] [6762DC5C] C:\Program Files\Internet Explorer\IEShims.dll (Internet Explorer Compatibility Shims/Microsoft Corporation)
IAT C:\Program Files\Internet Explorer\iexplore.exe[2000] @ C:\Windows\system32\SHELL32.dll [KERNEL32.dll!CreateHardLinkW] [6762EB68] C:\Program Files\Internet Explorer\IEShims.dll (Internet Explorer Compatibility Shims/Microsoft Corporation)
IAT C:\Program Files\Internet Explorer\iexplore.exe[2000] @ C:\Windows\system32\SHELL32.dll [KERNEL32.dll!SetCurrentDirectoryW] [67631D56] C:\Program Files\Internet Explorer\IEShims.dll (Internet Explorer Compatibility Shims/Microsoft Corporation)
IAT C:\Program Files\Internet Explorer\iexplore.exe[2000] @ C:\Windows\system32\SHELL32.dll [KERNEL32.dll!CopyFileW] [6762E1E9] C:\Program Files\Internet Explorer\IEShims.dll (Internet Explorer Compatibility Shims/Microsoft Corporation)
IAT C:\Program Files\Internet Explorer\iexplore.exe[2000] @ C:\Windows\system32\SHELL32.dll [KERNEL32.dll!GetBinaryTypeW] [6762CAA7] C:\Program Files\Internet Explorer\IEShims.dll (Internet Explorer Compatibility Shims/Microsoft Corporation)
IAT C:\Program Files\Internet Explorer\iexplore.exe[2000] @ C:\Windows\system32\SHELL32.dll [KERNEL32.dll!LoadLibraryExW] [6763007C] C:\Program Files\Internet Explorer\IEShims.dll (Internet Explorer Compatibility Shims/Microsoft Corporation)
IAT C:\Program Files\Internet Explorer\iexplore.exe[2000] @ C:\Windows\system32\SHELL32.dll [KERNEL32.dll!CreateProcessW] [6762A3FB] C:\Program Files\Internet Explorer\IEShims.dll (Internet Explorer Compatibility Shims/Microsoft Corporation)
IAT C:\Program Files\Internet Explorer\iexplore.exe[2000] @ C:\Windows\system32\SHELL32.dll [KERNEL32.dll!MoveFileW] [67630994] C:\Program Files\Internet Explorer\IEShims.dll (Internet Explorer Compatibility Shims/Microsoft Corporation)
IAT C:\Program Files\Internet Explorer\iexplore.exe[2000] @ C:\Windows\system32\SHELL32.dll [KERNEL32.dll!FindFirstFileW] [67633035] C:\Program Files\Internet Explorer\IEShims.dll (Internet Explorer Compatibility Shims/Microsoft Corporation)
IAT C:\Program Files\Internet Explorer\iexplore.exe[2000] @ C:\Windows\system32\SHELL32.dll [KERNEL32.dll!FindClose] [67633ADC] C:\Program Files\Internet Explorer\IEShims.dll (Internet Explorer Compatibility Shims/Microsoft Corporation)
IAT C:\Program Files\Internet Explorer\iexplore.exe[2000] @ C:\Windows\system32\SHELL32.dll [KERNEL32.dll!GetShortPathNameA] [6762C709] C:\Program Files\Internet Explorer\IEShims.dll (Internet Explorer Compatibility Shims/Microsoft Corporation)
IAT C:\Program Files\Internet Explorer\iexplore.exe[2000] @ C:\Windows\system32\SHELL32.dll [KERNEL32.dll!GetFileAttributesA] [6762BD77] C:\Program Files\Internet Explorer\IEShims.dll (Internet Explorer Compatibility Shims/Microsoft Corporation)
IAT C:\Program Files\Internet Explorer\iexplore.exe[2000] @ C:\Windows\system32\SHELL32.dll [KERNEL32.dll!SearchPathW] [67631AEC] C:\Program Files\Internet Explorer\IEShims.dll (Internet Explorer Compatibility Shims/Microsoft Corporation)
IAT C:\Program Files\Internet Explorer\iexplore.exe[2000] @ C:\Windows\system32\SHELL32.dll [KERNEL32.dll!GetPrivateProfileIntW] [6762CD20] C:\Program Files\Internet Explorer\IEShims.dll (Internet Explorer Compatibility Shims/Microsoft Corporation)
IAT C:\Program Files\Internet Explorer\iexplore.exe[2000] @ C:\Windows\system32\SHELL32.dll [KERNEL32.dll!GetPrivateProfileStringW] [6762D4B8] C:\Program Files\Internet Explorer\IEShims.dll (Internet Explorer Compatibility Shims/Microsoft Corporation)
IAT C:\Program Files\Internet Explorer\iexplore.exe[2000] @ C:\Windows\system32\SHELL32.dll [KERNEL32.dll!RemoveDirectoryW] [67631614] C:\Program Files\Internet Explorer\IEShims.dll (Internet Explorer Compatibility Shims/Microsoft Corporation)
IAT C:\Program Files\Internet Explorer\iexplore.exe[2000] @ C:\Windows\system32\SHELL32.dll [KERNEL32.dll!CreateDirectoryW] [6763103D] C:\Program Files\Internet Explorer\IEShims.dll (Internet Explorer Compatibility Shims/Microsoft Corporation)
IAT C:\Program Files\Internet Explorer\iexplore.exe[2000] @ C:\Windows\system32\SHELL32.dll [KERNEL32.dll!DeleteFileW] [6762EE46] C:\Program Files\Internet Explorer\IEShims.dll (Internet Explorer Compatibility Shims/Microsoft Corporation)
IAT C:\Program Files\Internet Explorer\iexplore.exe[2000] @ C:\Windows\system32\SHELL32.dll [KERNEL32.dll!SetFileAttributesW] [6762C0FB] C:\Program Files\Internet Explorer\IEShims.dll (Internet Explorer Compatibility Shims/Microsoft Corporation)
IAT C:\Program Files\Internet Explorer\iexplore.exe[2000] @ C:\Windows\system32\SHELL32.dll [KERNEL32.dll!GetFileAttributesW] [6762BEA2] C:\Program Files\Internet Explorer\IEShims.dll (Internet Explorer Compatibility Shims/Microsoft Corporation)
IAT C:\Program Files\Internet Explorer\iexplore.exe[2000] @ C:\Windows\system32\SHELL32.dll [KERNEL32.dll!MoveFileExW] [676309B9] C:\Program Files\Internet Explorer\IEShims.dll (Internet Explorer Compatibility Shims/Microsoft Corporation)
IAT C:\Program Files\Internet Explorer\iexplore.exe[2000] @ C:\Windows\system32\SHELL32.dll [KERNEL32.dll!GetShortPathNameW] [6762C848] C:\Program Files\Internet Explorer\IEShims.dll (Internet Explorer Compatibility Shims/Microsoft Corporation)
IAT C:\Program Files\Internet Explorer\iexplore.exe[2000] @ C:\Windows\system32\SHELL32.dll [KERNEL32.dll!LoadLibraryW] [6762FD66] C:\Program Files\Internet Explorer\IEShims.dll (Internet Explorer Compatibility Shims/Microsoft Corporation)
IAT C:\Program Files\Internet Explorer\iexplore.exe[2000] @ C:\Windows\system32\SHELL32.dll [KERNEL32.dll!CreateFileW] [6762E860] C:\Program Files\Internet Explorer\IEShims.dll (Internet Explorer Compatibility Shims/Microsoft Corporation)
IAT C:\Program Files\Internet Explorer\iexplore.exe[2000] @ C:\Windows\system32\SHELL32.dll [KERNEL32.dll!GetFileAttributesExW] [6762C368] C:\Program Files\Internet Explorer\IEShims.dll (Internet Explorer Compatibility Shims/Microsoft Corporation)
IAT C:\Program Files\Internet Explorer\iexplore.exe[2000] @ C:\Windows\system32\SHELL32.dll [KERNEL32.dll!LoadLibraryA] [6762FBE1] C:\Program Files\Internet Explorer\IEShims.dll (Internet Explorer Compatibility Shims/Microsoft Corporation)
IAT C:\Program Files\Internet Explorer\iexplore.exe[2000] @ C:\Windows\system32\SHELL32.dll [KERNEL32.dll!GetLongPathNameW] [6762C5D8] C:\Program Files\Internet Explorer\IEShims.dll (Internet Explorer Compatibility Shims/Microsoft Corporation)
IAT C:\Program Files\Internet Explorer\iexplore.exe[2000] @ C:\Windows\system32\SHELL32.dll [USER32.dll!LoadImageW] [6762F0D0] C:\Program Files\Internet Explorer\IEShims.dll (Internet Explorer Compatibility Shims/Microsoft Corporation)
IAT C:\Program Files\Internet Explorer\iexplore.exe[2000] @ C:\Windows\system32\SHELL32.dll [USER32.dll!WinHelpW] [6762FAAA] C:\Program Files\Internet Explorer\IEShims.dll (Internet Explorer Compatibility Shims/Microsoft Corporation)
IAT C:\Program Files\Internet Explorer\iexplore.exe[2000] @ C:\Windows\system32\SHELL32.dll [USER32.dll!PrivateExtractIconsW] [6762F5C5] C:\Program Files\Internet Explorer\IEShims.dll (Internet Explorer Compatibility Shims/Microsoft Corporation)
IAT C:\Program Files\Internet Explorer\iexplore.exe[2000] @ C:\Windows\system32\SHELL32.dll [SHLWAPI.dll!AssocQueryStringByKeyW] [6763620B] C:\Program Files\Internet Explorer\IEShims.dll (Internet Explorer Compatibility Shims/Microsoft Corporation)
IAT C:\Program Files\Internet Explorer\iexplore.exe[2000] @ C:\Windows\system32\SHELL32.dll [SHLWAPI.dll!SHCreateStreamOnFileW] [67637595] C:\Program Files\Internet Explorer\IEShims.dll (Internet Explorer Compatibility Shims/Microsoft Corporation)
IAT C:\Program Files\Internet Explorer\iexplore.exe[2000] @ C:\Windows\system32\SHELL32.dll [SHLWAPI.dll!AssocQueryKeyW] [676360AE] C:\Program Files\Internet Explorer\IEShims.dll (Internet Explorer Compatibility Shims/Microsoft Corporation)
IAT C:\Program Files\Internet Explorer\iexplore.exe[2000] @ C:\Windows\system32\SHELL32.dll [SHLWAPI.dll!AssocQueryStringW] [6763615B] C:\Program Files\Internet Explorer\IEShims.dll (Internet Explorer Compatibility Shims/Microsoft Corporation)
IAT C:\Program Files\Internet Explorer\iexplore.exe[2000] @ C:\Windows\system32\SHELL32.dll [SHLWAPI.dll!SHDeleteKeyA] [676375E7] C:\Program Files\Internet Explorer\IEShims.dll (Internet Explorer Compatibility Shims/Microsoft Corporation)
IAT C:\Program Files\Internet Explorer\iexplore.exe[2000] @ C:\Windows\system32\SHELL32.dll [SHLWAPI.dll!PathCombineW] [67636533] C:\Program Files\Internet Explorer\IEShims.dll (Internet Explorer Compatibility Shims/Microsoft Corporation)
IAT C:\Program Files\Internet Explorer\iexplore.exe[2000] @ C:\Windows\system32\SHELL32.dll [SHLWAPI.dll!SHOpenRegStream2W] [6763799A] C:\Program Files\Internet Explorer\IEShims.dll (Internet Explorer Compatibility Shims/Microsoft Corporation)
IAT C:\Program Files\Internet Explorer\iexplore.exe[2000] @ C:\Windows\system32\SHELL32.dll [SHLWAPI.dll!PathIsDirectoryW] [6763684F] C:\Program Files\Internet Explorer\IEShims.dll (Internet Explorer Compatibility Shims/Microsoft Corporation)
IAT C:\Program Files\Internet Explorer\iexplore.exe[2000] @ C:\Windows\system32\SHELL32.dll [SHLWAPI.dll!PathIsURLW] [67636E45] C:\Program Files\Internet Explorer\IEShims.dll (Internet Explorer Compatibility Shims/Microsoft Corporation)
IAT C:\Program Files\Internet Explorer\iexplore.exe[2000] @ C:\Windows\system32\SHELL32.dll [SHLWAPI.dll!PathIsRootA] [67636AFB] C:\Program Files\Internet Explorer\IEShims.dll (Internet Explorer Compatibility Shims/Microsoft Corporation)
IAT C:\Program Files\Internet Explorer\iexplore.exe[2000] @ C:\Windows\system32\SHELL32.dll [SHLWAPI.dll!PathIsRootW] [67636B47] C:\Program Files\Internet Explorer\IEShims.dll (Internet Explorer Compatibility Shims/Microsoft Corporation)
IAT C:\Program Files\Internet Explorer\iexplore.exe[2000] @ C:\Windows\system32\SHELL32.dll [SHLWAPI.dll!PathStripToRootW] [67637281] C:\Program Files\Internet Explorer\IEShims.dll (Internet Explorer Compatibility Shims/Microsoft Corporation)
IAT C:\Program Files\Internet Explorer\iexplore.exe[2000] @ C:\Windows\system32\SHELL32.dll [SHLWAPI.dll!PathFindOnPathW] [67636716] C:\Program Files\Internet Explorer\IEShims.dll (Internet Explorer Compatibility Shims/Microsoft Corporation)
IAT C:\Program Files\Internet Explorer\iexplore.exe[2000] @ C:\Windows\system32\SHELL32.dll [SHLWAPI.dll!PathStripPathW] [676371ED] C:\Program Files\Internet Explorer\IEShims.dll (Internet Explorer Compatibility Shims/Microsoft Corporation)
IAT C:\Program Files\Internet Explorer\iexplore.exe[2000] @ C:\Windows\system32\SHELL32.dll [SHLWAPI.dll!PathRemoveArgsW] [67637021] C:\Program Files\Internet Explorer\IEShims.dll (Internet Explorer Compatibility Shims/Microsoft Corporation)
IAT C:\Program Files\Internet Explorer\iexplore.exe[2000] @ C:\Windows\system32\SHELL32.dll [SHLWAPI.dll!SHRegGetBoolUSValueW] [67637FBE] C:\Program Files\Internet Explorer\IEShims.dll (Internet Explorer Compatibility Shims/Microsoft Corporation)
IAT C:\Program Files\Internet Explorer\iexplore.exe[2000] @ C:\Windows\system32\SHELL32.dll [SHLWAPI.dll!PathSkipRootW] [67637159] C:\Program Files\Internet Explorer\IEShims.dll (Internet Explorer Compatibility Shims/Microsoft Corporation)
IAT C:\Program Files\Internet Explorer\iexplore.exe[2000] @ C:\Windows\system32\SHELL32.dll [SHLWAPI.dll!PathIsDirectoryEmptyW] [676368E7] C:\Program Files\Internet Explorer\IEShims.dll (Internet Explorer Compatibility Shims/Microsoft Corporation)
IAT C:\Program Files\Internet Explorer\iexplore.exe[2000] @ C:\Windows\system32\SHELL32.dll [SHLWAPI.dll!PathIsSystemFolderW] [67636BE2] C:\Program Files\Internet Explorer\IEShims.dll (Internet Explorer Compatibility Shims/Microsoft Corporation)
IAT C:\Program Files\Internet Explorer\iexplore.exe[2000] @ C:\Windows\system32\SHELL32.dll [SHLWAPI.dll!PathIsDirectoryA] [67636803] C:\Program Files\Internet Explorer\IEShims.dll (Internet Explorer Compatibility Shims/Microsoft Corporation)
IAT C:\Program Files\Internet Explorer\iexplore.exe[2000] @ C:\Windows\system32\SHELL32.dll [SHLWAPI.dll!PathRelativePathToW] [67636F81] C:\Program Files\Internet Explorer\IEShims.dll (Internet Explorer Compatibility Shims/Microsoft Corporation)
IAT C:\Program Files\Internet Explorer\iexplore.exe[2000] @ C:\Windows\system32\SHELL32.dll [SHLWAPI.dll!PathBuildRootA] [676363A5] C:\Program Files\Internet Explorer\IEShims.dll (Internet Explorer Compatibility Shims/Microsoft Corporation)
IAT C:\Program Files\Internet Explorer\iexplore.exe[2000] @ C:\Windows\system32\SHELL32.dll [SHLWAPI.dll!SHRegGetPathW] [676380BD] C:\Program Files\Internet Explorer\IEShims.dll (Internet Explorer Compatibility Shims/Microsoft Corporation)
IAT C:\Program Files\Internet Explorer\iexplore.exe[2000] @ C:\Windows\system32\SHELL32.dll [SHLWAPI.dll!SHRegSetPathW] [67638513] C:\Program Files\Internet Explorer\IEShims.dll (Internet Explorer Compatibility Shims/Microsoft Corporation)
IAT C:\Program Files\Internet Explorer\iexplore.exe[2000] @ C:\Windows\system32\SHELL32.dll [SHLWAPI.dll!SHRegGetUSValueW] [67638176] C:\Program Files\Internet Explorer\IEShims.dll (Internet Explorer Compatibility Shims/Microsoft Corporation)
IAT C:\Program Files\Internet Explorer\iexplore.exe[2000] @ C:\Windows\system32\SHELL32.dll [SHLWAPI.dll!PathCreateFromUrlW] [676365DA] C:\Program Files\Internet Explorer\IEShims.dll (Internet Explorer Compatibility Shims/Microsoft Corporation)
IAT C:\Program Files\Internet Explorer\iexplore.exe[2000] @ C:\Windows\system32\SHELL32.dll [SHLWAPI.dll!SHQueryValueExW] [67637BA4] C:\Program Files\Internet Explorer\IEShims.dll (Internet Explorer Compatibility Shims/Microsoft Corporation)
IAT C:\Program Files\Internet Explorer\iexplore.exe[2000] @ C:\Windows\system32\SHELL32.dll [SHLWAPI.dll!SHRegGetValueW] [67638235] C:\Program Files\Internet Explorer\IEShims.dll (Internet Explorer Compatibility Shims/Microsoft Corporation)
IAT C:\Program Files\Internet Explorer\iexplore.exe[2000] @ C:\Windows\system32\SHELL32.dll [SHLWAPI.dll!PathIsNetworkPathW] [6763697F] C:\Program Files\Internet Explorer\IEShims.dll (Internet Explorer Compatibility Shims/Microsoft Corporation)
IAT C:\Program Files\Internet Explorer\iexplore.exe[2000] @ C:\Windows\system32\SHELL32.dll [SHLWAPI.dll!PathIsUNCServerShareW] [67636DAD] C:\Program Files\Internet Explorer\IEShims.dll (Internet Explorer Compatibility Shims/Microsoft Corporation)
IAT C:\Program Files\Internet Explorer\iexplore.exe[2000] @ C:\Windows\system32\SHELL32.dll [SHLWAPI.dll!PathIsUNCServerW] [67636D15] C:\Program Files\Internet Explorer\IEShims.dll (Internet Explorer Compatibility Shims/Microsoft Corporation)
IAT C:\Program Files\Internet Explorer\iexplore.exe[2000] @ C:\Windows\system32\SHELL32.dll [SHLWAPI.dll!PathUnExpandEnvStringsW] [6763731F] C:\Program Files\Internet Explorer\IEShims.dll (Internet Explorer Compatibility Shims/Microsoft Corporation)
IAT C:\Program Files\Internet Explorer\iexplore.exe[2000] @ C:\Windows\system32\SHELL32.dll [SHLWAPI.dll!PathMakeSystemFolderW] [67636EDD] C:\Program Files\Internet Explorer\IEShims.dll (Internet Explorer Compatibility Shims/Microsoft Corporation)
IAT C:\Program Files\Internet Explorer\iexplore.exe[2000] @ C:\Windows\system32\SHELL32.dll [SHLWAPI.dll!PathIsUNCW] [67636C7D] C:\Program Files\Internet Explorer\IEShims.dll (Internet Explorer Compatibility Shims/Microsoft Corporation)
IAT C:\Program Files\Internet Explorer\iexplore.exe[2000] @ C:\Windows\system32\SHELL32.dll [SHLWAPI.dll!PathIsRelativeW] [67636AAF] C:\Program Files\Internet Explorer\IEShims.dll (Internet Explorer Compatibility Shims/Microsoft Corporation)
IAT C:\Program Files\Internet Explorer\iexplore.exe[2000] @ C:\Windows\system32\SHELL32.dll [SHLWAPI.dll!SHGetValueW] [676378EA] C:\Program Files\Internet Explorer\IEShims.dll (Internet Explorer Compatibility Shims/Microsoft Corporation)
IAT C:\Program Files\Internet Explorer\iexplore.exe[2000] @ C:\Windows\system32\SHELL32.dll [SHLWAPI.dll!PathBuildRootW] [676363F4] C:\Program Files\Internet Explorer\IEShims.dll (Internet Explorer Compatibility Shims/Microsoft Corporation)
IAT C:\Program Files\Internet Explorer\iexplore.exe[2000] @ C:\Windows\system32\SHELL32.dll [SHLWAPI.dll!SHDeleteValueW] [676376D7] C:\Program Files\Internet Explorer\IEShims.dll (Internet Explorer Compatibility Shims/Microsoft Corporation)
IAT C:\Program Files\Internet Explorer\iexplore.exe[2000] @ C:\Windows\system32\SHELL32.dll [SHLWAPI.dll!SHSetValueW] [67638732] C:\Program Files\Internet Explorer\IEShims.dll (Internet Explorer Compatibility Shims/Microsoft Corporation)
IAT C:\Program Files\Internet Explorer\iexplore.exe[2000] @ C:\Windows\system32\SHELL32.dll [SHLWAPI.dll!SHEnumKeyExW] [6763777E] C:\Program Files\Internet Explorer\IEShims.dll (Internet Explorer Compatibility Shims/Microsoft Corporation)
IAT C:\Program Files\Internet Explorer\iexplore.exe[2000] @ C:\Windows\system32\SHELL32.dll [SHLWAPI.dll!SHEnumValueW] [67637831] C:\Program Files\Internet Explorer\IEShims.dll (Internet Explorer Compatibility Shims/Microsoft Corporation)
IAT C:\Program Files\Internet Explorer\iexplore.exe[2000] @ C:\Windows\system32\SHELL32.dll [SHLWAPI.dll!PathFileExistsW] [6763667B] C:\Program Files\Internet Explorer\IEShims.dll (Internet Explorer Compatibility Shims/Microsoft Corporation)
IAT C:\Program Files\Internet Explorer\iexplore.exe[2000] @ C:\Windows\system32\SHELL32.dll [SHLWAPI.dll!SHDeleteKeyW] [67637636] C:\Program Files\Internet Explorer\IEShims.dll (Internet Explorer Compatibility Shims/Microsoft Corporation)
IAT C:\Program Files\Internet Explorer\iexplore.exe[2000] @ C:\Windows\system32\SHELL32.dll [ntdll.dll!NtQueryDirectoryFile] [6762BB38] C:\Program Files\Internet Explorer\IEShims.dll (Internet Explorer Compatibility Shims/Microsoft Corporation)
IAT C:\Program Files\Internet Explorer\iexplore.exe[2000] @ C:\Windows\system32\ole32.dll [KERNEL32.dll!FindClose] [67633ADC] C:\Program Files\Internet Explorer\IEShims.dll (Internet Explorer Compatibility Shims/Microsoft Corporation)
IAT C:\Program Files\Internet Explorer\iexplore.exe[2000] @ C:\Windows\system32\ole32.dll [KERNEL32.dll!FindFirstFileW] [67633035] C:\Program Files\Internet Explorer\IEShims.dll (Internet Explorer Compatibility Shims/Microsoft Corporation)
IAT C:\Program Files\Internet Explorer\iexplore.exe[2000] @ C:\Windows\system32\ole32.dll [KERNEL32.dll!LoadLibraryExW] [6763007C] C:\Program Files\Internet Explorer\IEShims.dll (Internet Explorer Compatibility Shims/Microsoft Corporation)
IAT C:\Program Files\Internet Explorer\iexplore.exe[2000] @ C:\Windows\system32\ole32.dll [KERNEL32.dll!SearchPathW] [67631AEC] C:\Program Files\Internet Explorer\IEShims.dll (Internet Explorer Compatibility Shims/Microsoft Corporation)
IAT C:\Program Files\Internet Explorer\iexplore.exe[2000] @ C:\Windows\system32\ole32.dll [KERNEL32.dll!CreateProcessW] [6762A3FB] C:\Program Files\Internet Explorer\IEShims.dll (Internet Explorer Compatibility Shims/Microsoft Corporation)
IAT C:\Program Files\Internet Explorer\iexplore.exe[2000] @ C:\Windows\system32\ole32.dll [KERNEL32.dll!DeleteFileW] [6762EE46] C:\Program Files\Internet Explorer\IEShims.dll (Internet Explorer Compatibility Shims/Microsoft Corporation)
IAT C:\Program Files\Internet Explorer\iexplore.exe[2000] @ C:\Windows\system32\ole32.dll [KERNEL32.dll!GetShortPathNameW] [6762C848] C:\Program Files\Internet Explorer\IEShims.dll (Internet Explorer Compatibility Shims/Microsoft Corporation)
IAT C:\Program Files\Internet Explorer\iexplore.exe[2000] @ C:\Windows\system32\ole32.dll [KERNEL32.dll!GetFileAttributesExW] [6762C368] C:\Program Files\Internet Explorer\IEShims.dll (Internet Explorer Compatibility Shims/Microsoft Corporation)
IAT C:\Program Files\Internet Explorer\iexplore.exe[2000] @ C:\Windows\system32\ole32.dll [KERNEL32.dll!CreateFileW] [6762E860] C:\Program Files\Internet Explorer\IEShims.dll (Internet Explorer Compatibility Shims/Microsoft Corporation)
IAT C:\Program Files\Internet Explorer\iexplore.exe[2000] @ C:\Windows\system32\ole32.dll [KERNEL32.dll!LoadLibraryW] [6762FD66] C:\Program Files\Internet Explorer\IEShims.dll (Internet Explorer Compatibility Shims/Microsoft Corporation)
IAT C:\Program Files\Internet Explorer\iexplore.exe[2000] @ C:\Windows\system32\ole32.dll [KERNEL32.dll!GetFileAttributesW] [6762BEA2] C:\Program Files\Internet Explorer\IEShims.dll (Internet Explorer Compatibility Shims/Microsoft Corporation)
IAT C:\Program Files\Internet Explorer\iexplore.exe[2000] @ C:\Windows\system32\ole32.dll [KERNEL32.dll!LoadLibraryA] [6762FBE1] C:\Program Files\Internet Explorer\IEShims.dll (Internet Explorer Compatibility Shims/Microsoft Corporation)
IAT C:\Program Files\Internet Explorer\iexplore.exe[2000] @ C:\Windows\system32\ws2_32.dll [KERNEL32.dll!GetProcAddress] [676282F6] C:\Program Files\Internet Explorer\IEShims.dll (Internet Explorer Compatibility Shims/Microsoft Corporation)
IAT C:\Program Files\Internet Explorer\iexplore.exe[2000] @ C:\Windows\system32\USERENV.dll [KERNEL32.dll!GetProcAddress] [676282F6] C:\Program Files\Internet Explorer\IEShims.dll (Internet Explorer Compatibility Shims/Microsoft Corporation)
IAT C:\Program Files\Internet Explorer\iexplore.exe[2000] @ C:\Windows\system32\Secur32.dll [KERNEL32.dll!GetProcAddress] [676282F6] C:\Program Files\Internet Explorer\IEShims.dll (Internet Explorer Compatibility Shims/Microsoft Corporation)
IAT C:\Program Files\Internet Explorer\iexplore.exe[2000] @ C:\Windows\system32\WININET.dll [SHLWAPI.dll!SHRegGetValueW] [67638235] C:\Program Files\Internet Explorer\IEShims.dll (Internet Explorer Compatibility Shims/Microsoft Corporation)
IAT C:\Program Files\Internet Explorer\iexplore.exe[2000] @ C:\Windows\system32\WININET.dll [SHLWAPI.dll!SHRegGetValueA] [676381D7] C:\Program Files\Internet Explorer\IEShims.dll (Internet Explorer Compatibility Shims/Microsoft Corporation)
IAT C:\Program Files\Internet Explorer\iexplore.exe[2000] @ C:\Windows\system32\WININET.dll [SHLWAPI.dll!PathUnExpandEnvStringsA] [676372CD] C:\Program Files\Internet Explorer\IEShims.dll (Internet Explorer Compatibility Shims/Microsoft Corporation)
IAT C:\Program Files\Internet Explorer\iexplore.exe[2000] @ C:\Windows\system32\WININET.dll [SHLWAPI.dll!SHDeleteKeyA] [676375E7] C:\Program Files\Internet Explorer\IEShims.dll (Internet Explorer Compatibility Shims/Microsoft Corporation)
IAT C:\Program Files\Internet Explorer\iexplore.exe[2000] @ C:\Windows\system32\WININET.dll [SHLWAPI.dll!SHDeleteValueW] [676376D7] C:\Program Files\Internet Explorer\IEShims.dll (Internet Explorer Compatibility Shims/Microsoft Corporation)
IAT C:\Program Files\Internet Explorer\iexplore.exe[2000] @ C:\Windows\system32\WININET.dll [SHLWAPI.dll!PathCreateFromUrlW] [676365DA] C:\Program Files\Internet Explorer\IEShims.dll (Internet Explorer Compatibility Shims/Microsoft Corporation)
IAT C:\Program Files\Internet Explorer\iexplore.exe[2000] @ C:\Windows\system32\WININET.dll [SHLWAPI.dll!SHGetValueA] [6763788F] C:\Program Files\Internet Explorer\IEShims.dll (Internet Explorer Compatibility Shims/Microsoft Corporation)
IAT C:\Program Files\Internet Explorer\iexplore.exe[2000] @ C:\Windows\system32\WININET.dll [SHLWAPI.dll!SHSetValueA] [676386D7] C:\Program Files\Internet Explorer\IEShims.dll (Internet Explorer Compatibility Shims/Microsoft Corporation)
IAT C:\Program Files\Internet Explorer\iexplore.exe[2000] @ C:\Windows\system32\WININET.dll [SHLWAPI.dll!SHGetValueW] [676378EA] C:\Program Files\Internet Explorer\IEShims.dll (Internet Explorer Compatibility Shims/Microsoft Corporation)
IAT C:\Program Files\Internet Explorer\iexplore.exe[2000] @ C:\Windows\system32\WININET.dll [SHLWAPI.dll!SHSetValueW] [67638732] C:\Program Files\Internet Explorer\IEShims.dll (Internet Explorer Compatibility Shims/Microsoft Corporation)
IAT C:\Program Files\Internet Explorer\iexplore.exe[2000] @ C:\Windows\system32\WININET.dll [SHLWAPI.dll!PathCombineW] [67636533] C:\Program Files\Internet Explorer\IEShims.dll (Internet Explorer Compatibility Shims/Microsoft Corporation)
IAT C:\Program Files\Internet Explorer\iexplore.exe[2000] @ C:\Windows\system32\WININET.dll [KERNEL32.dll!GetProcAddress] [676282F6] C:\Program Files\Internet Explorer\IEShims.dll (Internet Explorer Compatibility Shims/Microsoft Corporation)
IAT C:\Program Files\Internet Explorer\iexplore.exe[2000] @ C:\Windows\system32\SAMLIB.dll [KERNEL32.dll!GetProcAddress] [676282F6] C:\Program Files\Internet Explorer\IEShims.dll (Internet Explorer Compatibility Shims/Microsoft Corporation)
IAT C:\Program Files\Internet Explorer\iexplore.exe[2000] @ C:\Windows\system32\NETAPI32.dll [KERNEL32.dll!GetProcAddress] [676282F6] C:\Program Files\Internet Explorer\IEShims.dll (Internet Explorer Compatibility Shims/Microsoft Corporation)
IAT C:\Program Files\Internet Explorer\iexplore.exe[2000] @ C:\Windows\system32\CRYPT32.dll [KERNEL32.dll!GetProcAddress] [676282F6] C:\Program Files\Internet Explorer\IEShims.dll (Internet Explorer Compatibility Shims/Microsoft Corporation)
IAT C:\Program Files\Internet Explorer\iexplore.exe[2000] @ C:\Windows\system32\IPHLPAPI.DLL [KERNEL32.dll!GetProcAddress] [676282F6] C:\Program Files\Internet Explorer\IEShims.dll (Internet Explorer Compatibility Shims/Microsoft Corporation)
IAT C:\Program Files\AVG\AVG9\avgtray.exe[2064] @ C:\Windows\system32\kernel32.dll [ntdll.dll!NtCreateFile] [003B2F30] C:\Windows\TEMP\logishrd\LVPrcInj22.dll (Camera Helper Library./Logitech Inc.)
IAT C:\Program Files\AVG\AVG9\avgtray.exe[2064] @ C:\Windows\system32\kernel32.dll [ntdll.dll!NtClose] [003B2D00] C:\Windows\TEMP\logishrd\LVPrcInj22.dll (Camera Helper Library./Logitech Inc.)
IAT C:\Program Files\AVG\AVG9\avgtray.exe[2064] @ C:\Windows\system32\kernel32.dll [ntdll.dll!NtDeviceIoControlFile] [003B2CA0] C:\Windows\TEMP\logishrd\LVPrcInj22.dll (Camera Helper Library./Logitech Inc.)
IAT C:\Program Files\AVG\AVG9\avgtray.exe[2064] @ C:\Windows\system32\kernel32.dll [ntdll.dll!NtDuplicateObject] [003B2CD0] C:\Windows\TEMP\logishrd\LVPrcInj22.dll (Camera Helper Library./Logitech Inc.)
IAT C:\Windows\System32\hkcmd.exe[2212] @ C:\Windows\system32\kernel32.dll [ntdll.dll!NtCreateFile] [01842F30] C:\Windows\TEMP\logishrd\LVPrcInj22.dll (Camera Helper Library./Logitech Inc.)
IAT C:\Windows\System32\hkcmd.exe[2212] @ C:\Windows\system32\kernel32.dll [ntdll.dll!NtClose] [01842D00] C:\Windows\TEMP\logishrd\LVPrcInj22.dll (Camera Helper Library./Logitech Inc.)
IAT C:\Windows\System32\hkcmd.exe[2212] @ C:\Windows\system32\kernel32.dll [ntdll.dll!NtDeviceIoControlFile] [01842CA0] C:\Windows\TEMP\logishrd\LVPrcInj22.dll (Camera Helper Library./Logitech Inc.)
IAT C:\Windows\System32\hkcmd.exe[2212] @ C:\Windows\system32\kernel32.dll [ntdll.dll!NtDuplicateObject] [01842CD0] C:\Windows\TEMP\logishrd\LVPrcInj22.dll (Camera Helper Library./Logitech Inc.)
IAT C:\Windows\system32\rundll32.exe[2476] @ C:\Windows\system32\kernel32.dll [ntdll.dll!NtCreateFile] [00992F30] C:\Windows\TEMP\logishrd\LVPrcInj22.dll (Camera Helper Library./Logitech Inc.)
IAT C:\Windows\system32\rundll32.exe[2476] @ C:\Windows\system32\kernel32.dll [ntdll.dll!NtClose] [00992D00] C:\Windows\TEMP\logishrd\LVPrcInj22.dll (Camera Helper Library./Logitech Inc.)
IAT C:\Windows\system32\rundll32.exe[2476] @ C:\Windows\system32\kernel32.dll [ntdll.dll!NtDeviceIoControlFile] [00992CA0] C:\Windows\TEMP\logishrd\LVPrcInj22.dll (Camera Helper Library./Logitech Inc.)
IAT C:\Windows\system32\rundll32.exe[2476] @ C:\Windows\system32\kernel32.dll [ntdll.dll!NtDuplicateObject] [00992CD0] C:\Windows\TEMP\logishrd\LVPrcInj22.dll (Camera Helper Library./Logitech Inc.)
IAT C:\Program Files\Windows Sidebar\sidebar.exe[2492] @ C:\Windows\system32\kernel32.dll [ntdll.dll!NtCreateFile] [00252F30] C:\Windows\TEMP\logishrd\LVPrcInj22.dll (Camera Helper Library./Logitech Inc.)
IAT C:\Program Files\Windows Sidebar\sidebar.exe[2492] @ C:\Windows\system32\kernel32.dll [ntdll.dll!NtClose] [00252D00] C:\Windows\TEMP\logishrd\LVPrcInj22.dll (Camera Helper Library./Logitech Inc.)
IAT C:\Program Files\Windows Sidebar\sidebar.exe[2492] @ C:\Windows\system32\kernel32.dll [ntdll.dll!NtDeviceIoControlFile] [00252CA0] C:\Windows\TEMP\logishrd\LVPrcInj22.dll (Camera Helper Library./Logitech Inc.)
IAT C:\Program Files\Windows Sidebar\sidebar.exe[2492] @ C:\Windows\system32\kernel32.dll [ntdll.dll!NtDuplicateObject] [00252CD0] C:\Windows\TEMP\logishrd\LVPrcInj22.dll (Camera Helper Library./Logitech Inc.)
IAT C:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe[2556] @ C:\Windows\system32\kernel32.dll [ntdll.dll!NtCreateFile] [001D2F30] C:\Windows\TEMP\logishrd\LVPrcInj22.dll (Camera Helper Library./Logitech Inc.)
IAT C:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe[2556] @ C:\Windows\system32\kernel32.dll [ntdll.dll!NtClose] [001D2D00] C:\Windows\TEMP\logishrd\LVPrcInj22.dll (Camera Helper Library./Logitech Inc.)
IAT C:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe[2556] @ C:\Windows\system32\kernel32.dll [ntdll.dll!NtDeviceIoControlFile] [001D2CA0] C:\Windows\TEMP\logishrd\LVPrcInj22.dll (Camera Helper Library./Logitech Inc.)
IAT C:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe[2556] @ C:\Windows\system32\kernel32.dll [ntdll.dll!NtDuplicateObject] [001D2CD0] C:\Windows\TEMP\logishrd\LVPrcInj22.dll (Camera Helper Library./Logitech Inc.)
IAT C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe[2684] @ C:\Windows\system32\kernel32.dll [ntdll.dll!NtCreateFile] [00802F30] C:\Windows\TEMP\logishrd\LVPrcInj22.dll (Camera Helper Library./Logitech Inc.)
IAT C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe[2684] @ C:\Windows\system32\kernel32.dll [ntdll.dll!NtClose] [00802D00] C:\Windows\TEMP\logishrd\LVPrcInj22.dll (Camera Helper Library./Logitech Inc.)
IAT C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe[2684] @ C:\Windows\system32\kernel32.dll [ntdll.dll!NtDeviceIoControlFile] [00802CA0] C:\Windows\TEMP\logishrd\LVPrcInj22.dll (Camera Helper Library./Logitech Inc.)
IAT C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe[2684] @ C:\Windows\system32\kernel32.dll [ntdll.dll!NtDuplicateObject] [00802CD0] C:\Windows\TEMP\logishrd\LVPrcInj22.dll (Camera Helper Library./Logitech Inc.)
IAT C:\Program Files\Kontiki\KHost.exe[2716] @ C:\Windows\system32\kernel32.dll [ntdll.dll!NtCreateFile] [003C2F30] C:\Windows\TEMP\logishrd\LVPrcInj22.dll (Camera Helper Library./Logitech Inc.)
IAT C:\Program Files\Kontiki\KHost.exe[2716] @ C:\Windows\system32\kernel32.dll [ntdll.dll!NtClose] [003C2D00] C:\Windows\TEMP\logishrd\LVPrcInj22.dll (Camera Helper Library./Logitech Inc.)
IAT C:\Program Files\Kontiki\KHost.exe[2716] @ C:\Windows\system32\kernel32.dll [ntdll.dll!NtDeviceIoControlFile] [003C2CA0] C:\Windows\TEMP\logishrd\LVPrcInj22.dll (Camera Helper Library./Logitech Inc.)
IAT C:\Program Files\Kontiki\KHost.exe[2716] @ C:\Windows\system32\kernel32.dll [ntdll.dll!NtDuplicateObject] [003C2CD0] C:\Windows\TEMP\logishrd\LVPrcInj22.dll (Camera Helper Library./Logitech Inc.)
IAT C:\Windows\System32\igfxpers.exe[3364] @ C:\Windows\system32\kernel32.dll [ntdll.dll!NtCreateFile] [003C2F30] C:\Windows\TEMP\logishrd\LVPrcInj22.dll (Camera Helper Library./Logitech Inc.)
IAT C:\Windows\System32\igfxpers.exe[3364] @ C:\Windows\system32\kernel32.dll [ntdll.dll!NtClose] [003C2D00] C:\Windows\TEMP\logishrd\LVPrcInj22.dll (Camera Helper Library./Logitech Inc.)
IAT C:\Windows\System32\igfxpers.exe[3364] @ C:\Windows\system32\kernel32.dll [ntdll.dll!NtDeviceIoControlFile] [003C2CA0] C:\Windows\TEMP\logishrd\LVPrcInj22.dll (Camera Helper Library./Logitech Inc.)
IAT C:\Windows\System32\igfxpers.exe[3364] @ C:\Windows\system32\kernel32.dll [ntdll.dll!NtDuplicateObject] [003C2CD0] C:\Windows\TEMP\logishrd\LVPrcInj22.dll (Camera Helper Library./Logitech Inc.)
IAT C:\Program Files\Common Files\LogiShrd\LVCOMSER\LVComSer.exe[3452] @ C:\Windows\system32\kernel32.dll [ntdll.dll!NtCreateFile] [001F2F30] C:\Windows\TEMP\logishrd\LVPrcInj22.dll (Camera Helper Library./Logitech Inc.)
IAT C:\Program Files\Common Files\LogiShrd\LVCOMSER\LVComSer.exe[3452] @ C:\Windows\system32\kernel32.dll [ntdll.dll!NtClose] [001F2D00] C:\Windows\TEMP\logishrd\LVPrcInj22.dll (Camera Helper Library./Logitech Inc.)
IAT C:\Program Files\Common Files\LogiShrd\LVCOMSER\LVComSer.exe[3452] @ C:\Windows\system32\kernel32.dll [ntdll.dll!NtDeviceIoControlFile] [001F2CA0] C:\Windows\TEMP\logishrd\LVPrcInj22.dll (Camera Helper Library./Logitech Inc.)
IAT C:\Program Files\Common Files\LogiShrd\LVCOMSER\LVComSer.exe[3452] @ C:\Windows\system32\kernel32.dll [ntdll.dll!NtDuplicateObject] [001F2CD0] C:\Windows\TEMP\logishrd\LVPrcInj22.dll (Camera Helper Library./Logitech Inc.)
IAT C:\Windows\system32\taskeng.exe[3528] @ C:\Windows\system32\kernel32.dll [ntdll.dll!NtCreateFile] [003E2F30] C:\Windows\TEMP\logishrd\LVPrcInj22.dll (Camera Helper Library./Logitech Inc.)
IAT C:\Windows\system32\taskeng.exe[3528] @ C:\Windows\system32\kernel32.dll [ntdll.dll!NtClose] [003E2D00] C:\Windows\TEMP\logishrd\LVPrcInj22.dll (Camera Helper Library./Logitech Inc.)
IAT C:\Windows\system32\taskeng.exe[3528] @ C:\Windows\system32\kernel32.dll [ntdll.dll!NtDeviceIoControlFile] [003E2CA0] C:\Windows\TEMP\logishrd\LVPrcInj22.dll (Camera Helper Library./Logitech Inc.)
IAT C:\Windows\system32\taskeng.exe[3528] @ C:\Windows\system32\kernel32.dll [ntdll.dll!NtDuplicateObject] [003E2CD0] C:\Windows\TEMP\logishrd\LVPrcInj22.dll (Camera Helper Library./Logitech Inc.)
IAT C:\Windows\system32\Dwm.exe[3644] @ C:\Windows\system32\kernel32.dll [ntdll.dll!NtCreateFile] [001A2F30] C:\Windows\TEMP\logishrd\LVPrcInj22.dll (Camera Helper Library./Logitech Inc.)
IAT C:\Windows\system32\Dwm.exe[3644] @ C:\Windows\system32\kernel32.dll [ntdll.dll!NtClose] [001A2D00] C:\Windows\TEMP\logishrd\LVPrcInj22.dll (Camera Helper Library./Logitech Inc.)
IAT C:\Windows\system32\Dwm.exe[3644] @ C:\Windows\system32\kernel32.dll [ntdll.dll!NtDeviceIoControlFile] [001A2CA0] C:\Windows\TEMP\logishrd\LVPrcInj22.dll (Camera Helper Library./Logitech Inc.)
IAT C:\Windows\system32\Dwm.exe[3644] @ C:\Windows\system32\kernel32.dll [ntdll.dll!NtDuplicateObject] [001A2CD0] C:\Windows\TEMP\logishrd\LVPrcInj22.dll (Camera Helper Library./Logitech Inc.)
IAT C:\Windows\WindowsMobile\wmdcBase.exe[3696] @ C:\Windows\system32\kernel32.dll [ntdll.dll!NtCreateFile] [000E2F30] C:\Windows\TEMP\logishrd\LVPrcInj22.dll (Camera Helper Library./Logitech Inc.)
IAT C:\Windows\WindowsMobile\wmdcBase.exe[3696] @ C:\Windows\system32\kernel32.dll [ntdll.dll!NtClose] [000E2D00] C:\Windows\TEMP\logishrd\LVPrcInj22.dll (Camera Helper Library./Logitech Inc.)
IAT C:\Windows\WindowsMobile\wmdcBase.exe[3696] @ C:\Windows\system32\kernel32.dll [ntdll.dll!NtDeviceIoControlFile] [000E2CA0] C:\Windows\TEMP\logishrd\LVPrcInj22.dll (Camera Helper Library./Logitech Inc.)
IAT C:\Windows\WindowsMobile\wmdcBase.exe[3696] @ C:\Windows\system32\kernel32.dll [ntdll.dll!NtDuplicateObject] [000E2CD0] C:\Windows\TEMP\logishrd\LVPrcInj22.dll (Camera Helper Library./Logitech Inc.)
IAT C:\Program Files\Common Files\Java\Java Update\jusched.exe[3728] @ C:\Windows\system32\kernel32.dll [ntdll.dll!NtCreateFile] [003D2F30] C:\Windows\TEMP\logishrd\LVPrcInj22.dll (Camera Helper Library./Logitech Inc.)
IAT C:\Program Files\Common Files\Java\Java Update\jusched.exe[3728] @ C:\Windows\system32\kernel32.dll [ntdll.dll!NtClose] [003D2D00] C:\Windows\TEMP\logishrd\LVPrcInj22.dll (Camera Helper Library./Logitech Inc.)
IAT C:\Program Files\Common Files\Java\Java Update\jusched.exe[3728] @ C:\Windows\system32\kernel32.dll [ntdll.dll!NtDeviceIoControlFile] [003D2CA0] C:\Windows\TEMP\logishrd\LVPrcInj22.dll (Camera Helper Library./Logitech Inc.)
IAT C:\Program Files\Common Files\Java\Java Update\jusched.exe[3728] @ C:\Windows\system32\kernel32.dll [ntdll.dll!NtDuplicateObject] [003D2CD0] C:\Windows\TEMP\logishrd\LVPrcInj22.dll (Camera Helper Library./Logitech Inc.)
IAT C:\Windows\Explorer.EXE[3752] @ C:\Windows\Explorer.EXE [gdiplus.dll!GdiplusShutdown] [74917817] C:\Windows\WinSxS\x86_microsoft.windows.gdiplus_6595b64144ccf1df_1.0.6002.18005_none_9e50b396ca17ae07\gdiplus.dll (Microsoft GDI+/Microsoft Corporation)
IAT C:\Windows\Explorer.EXE[3752] @ C:\Windows\Explorer.EXE [gdiplus.dll!GdipCloneImage] [7496A86D] C:\Windows\WinSxS\x86_microsoft.windows.gdiplus_6595b64144ccf1df_1.0.6002.18005_none_9e50b396ca17ae07\gdiplus.dll (Microsoft GDI+/Microsoft Corporation)
IAT C:\Windows\Explorer.EXE[3752] @ C:\Windows\Explorer.EXE [gdiplus.dll!GdipDrawImageRectI] [7491BB22] C:\Windows\WinSxS\x86_microsoft.windows.gdiplus_6595b64144ccf1df_1.0.6002.18005_none_9e50b396ca17ae07\gdiplus.dll (Microsoft GDI+/Microsoft Corporation)
IAT C:\Windows\Explorer.EXE[3752] @ C:\Windows\Explorer.EXE [gdiplus.dll!GdipSetInterpolationMode] [7490F695] C:\Windows\WinSxS\x86_microsoft.windows.gdiplus_6595b64144ccf1df_1.0.6002.18005_none_9e50b396ca17ae07\gdiplus.dll (Microsoft GDI+/Microsoft Corporation)
IAT C:\Windows\Explorer.EXE[3752] @ C:\Windows\Explorer.EXE [gdiplus.dll!GdiplusStartup] [749175E9] C:\Windows\WinSxS\x86_microsoft.windows.gdiplus_6595b64144ccf1df_1.0.6002.18005_none_9e50b396ca17ae07\gdiplus.dll (Microsoft GDI+/Microsoft Corporation)
IAT C:\Windows\Explorer.EXE[3752] @ C:\Windows\Explorer.EXE [gdiplus.dll!GdipCreateFromHDC] [7490E7CA] C:\Windows\WinSxS\x86_microsoft.windows.gdiplus_6595b64144ccf1df_1.0.6002.18005_none_9e50b396ca17ae07\gdiplus.dll (Microsoft GDI+/Microsoft Corporation)
IAT C:\Windows\Explorer.EXE[3752] @ C:\Windows\Explorer.EXE [gdiplus.dll!GdipCreateBitmapFromStreamICM] [74948395] C:\Windows\WinSxS\x86_microsoft.windows.gdiplus_6595b64144ccf1df_1.0.6002.18005_none_9e50b396ca17ae07\gdiplus.dll (Microsoft GDI+/Microsoft Corporation)
IAT C:\Windows\Explorer.EXE[3752] @ C:\Windows\Explorer.EXE [gdiplus.dll!GdipCreateBitmapFromStream] [7491DA60] C:\Windows\WinSxS\x86_microsoft.windows.gdiplus_6595b64144ccf1df_1.0.6002.18005_none_9e50b396ca17ae07\gdiplus.dll (Microsoft GDI+/Microsoft Corporation)
IAT C:\Windows\Explorer.EXE[3752] @ C:\Windows\Explorer.EXE [gdiplus.dll!GdipGetImageHeight] [7490FFFA] C:\Windows\WinSxS\x86_microsoft.windows.gdiplus_6595b64144ccf1df_1.0.6002.18005_none_9e50b396ca17ae07\gdiplus.dll (Microsoft GDI+/Microsoft Corporation)
IAT C:\Windows\Explorer.EXE[3752] @ C:\Windows\Explorer.EXE [gdiplus.dll!GdipGetImageWidth] [7490FF61] C:\Windows\WinSxS\x86_microsoft.windows.gdiplus_6595b64144ccf1df_1.0.6002.18005_none_9e50b396ca17ae07\gdiplus.dll (Microsoft GDI+/Microsoft Corporation)
IAT C:\Windows\Explorer.EXE[3752] @ C:\Windows\Explorer.EXE [gdiplus.dll!GdipDisposeImage] [749071CF] C:\Windows\WinSxS\x86_microsoft.windows.gdiplus_6595b64144ccf1df_1.0.6002.18005_none_9e50b396ca17ae07\gdiplus.dll (Microsoft GDI+/Microsoft Corporation)
IAT C:\Windows\Explorer.EXE[3752] @ C:\Windows\Explorer.EXE [gdiplus.dll!GdipLoadImageFromFileICM] [7499CAE2] C:\Windows\WinSxS\x86_microsoft.windows.gdiplus_6595b64144ccf1df_1.0.6002.18005_none_9e50b396ca17ae07\gdiplus.dll (Microsoft GDI+/Microsoft Corporation)
IAT C:\Windows\Explorer.EXE[3752] @ C:\Windows\Explorer.EXE [gdiplus.dll!GdipLoadImageFromFile] [7493C8D8] C:\Windows\WinSxS\x86_microsoft.windows.gdiplus_6595b64144ccf1df_1.0.6002.18005_none_9e50b396ca17ae07\gdiplus.dll (Microsoft GDI+/Microsoft Corporation)
IAT C:\Windows\Explorer.EXE[3752] @ C:\Windows\Explorer.EXE [gdiplus.dll!GdipDeleteGraphics] [7490D968] C:\Windows\WinSxS\x86_microsoft.windows.gdiplus_6595b64144ccf1df_1.0.6002.18005_none_9e50b396ca17ae07\gdiplus.dll (Microsoft GDI+/Microsoft Corporation)
IAT C:\Windows\Explorer.EXE[3752] @ C:\Windows\Explorer.EXE [gdiplus.dll!GdipFree] [74906853] C:\Windows\WinSxS\x86_microsoft.windows.gdiplus_6595b64144ccf1df_1.0.6002.18005_none_9e50b396ca17ae07\gdiplus.dll (Microsoft GDI+/Microsoft Corporation)
IAT C:\Windows\Explorer.EXE[3752] @ C:\Windows\Explorer.EXE [gdiplus.dll!GdipAlloc] [7490687E] C:\Windows\WinSxS\x86_microsoft.windows.gdiplus_6595b64144ccf1df_1.0.6002.18005_none_9e50b396ca17ae07\gdiplus.dll (Microsoft GDI+/Microsoft Corporation)
IAT C:\Windows\Explorer.EXE[3752] @ C:\Windows\Explorer.EXE [gdiplus.dll!GdipSetCompositingMode] [74912AD1] C:\Windows\WinSxS\x86_microsoft.windows.gdiplus_6595b64144ccf1df_1.0.6002.18005_none_9e50b396ca17ae07\gdiplus.dll (Microsoft GDI+/Microsoft Corporation)
IAT C:\Windows\Explorer.EXE[3752] @ C:\Windows\system32\kernel32.dll [ntdll.dll!NtCreateFile] [01692F30] C:\Windows\TEMP\logishrd\LVPrcInj22.dll (Camera Helper Library./Logitech Inc.)
IAT C:\Windows\Explorer.EXE[3752] @ C:\Windows\system32\kernel32.dll [ntdll.dll!NtClose] [01692D00] C:\Windows\TEMP\logishrd\LVPrcInj22.dll (Camera Helper Library./Logitech Inc.)
IAT C:\Windows\Explorer.EXE[3752] @ C:\Windows\system32\kernel32.dll [ntdll.dll!NtDeviceIoControlFile] [01692CA0] C:\Windows\TEMP\logishrd\LVPrcInj22.dll (Camera Helper Library./Logitech Inc.)
IAT C:\Windows\Explorer.EXE[3752] @ C:\Windows\system32\kernel32.dll [ntdll.dll!NtDuplicateObject] [01692CD0] C:\Windows\TEMP\logishrd\LVPrcInj22.dll (Camera Helper Library./Logitech Inc.)
IAT C:\Windows\system32\igfxsrvc.exe[3776] @ C:\Windows\system32\kernel32.dll [ntdll.dll!NtCreateFile] [00192F30] C:\Windows\TEMP\logishrd\LVPrcInj22.dll (Camera Helper Library./Logitech Inc.)
IAT C:\Windows\system32\igfxsrvc.exe[3776] @ C:\Windows\system32\kernel32.dll [ntdll.dll!NtClose] [00192D00] C:\Windows\TEMP\logishrd\LVPrcInj22.dll (Camera Helper Library./Logitech Inc.)
IAT C:\Windows\system32\igfxsrvc.exe[3776] @ C:\Windows\system32\kernel32.dll [ntdll.dll!NtDeviceIoControlFile] [00192CA0] C:\Windows\TEMP\logishrd\LVPrcInj22.dll (Camera Helper Library./Logitech Inc.)
IAT C:\Windows\system32\igfxsrvc.exe[3776] @ C:\Windows\system32\kernel32.dll [ntdll.dll!NtDuplicateObject] [00192CD0] C:\Windows\TEMP\logishrd\LVPrcInj22.dll (Camera Helper Library./Logitech Inc.)
IAT C:\Program Files\iTunes\iTunesHelper.exe[4036] @ C:\Windows\system32\kernel32.dll [ntdll.dll!NtCreateFile] [00312F30] C:\Windows\TEMP\logishrd\LVPrcInj22.dll (Camera Helper Library./Logitech Inc.)
IAT C:\Program Files\iTunes\iTunesHelper.exe[4036] @ C:\Windows\system32\kernel32.dll [ntdll.dll!NtClose] [00312D00] C:\Windows\TEMP\logishrd\LVPrcInj22.dll (Camera Helper Library./Logitech Inc.)
IAT C:\Program Files\iTunes\iTunesHelper.exe[4036] @ C:\Windows\system32\kernel32.dll [ntdll.dll!NtDeviceIoControlFile] [00312CA0] C:\Windows\TEMP\logishrd\LVPrcInj22.dll (Camera Helper Library./Logitech Inc.)
IAT C:\Program Files\iTunes\iTunesHelper.exe[4036] @ C:\Windows\system32\kernel32.dll [ntdll.dll!NtDuplicateObject] [00312CD0] C:\Windows\TEMP\logishrd\LVPrcInj22.dll (Camera Helper Library./Logitech Inc.)
IAT C:\Windows\ehome\ehtray.exe[4100] @ C:\Windows\system32\kernel32.dll [ntdll.dll!NtCreateFile] [00802F30] C:\Windows\TEMP\logishrd\LVPrcInj22.dll (Camera Helper Library./Logitech Inc.)
IAT C:\Windows\ehome\ehtray.exe[4100] @ C:\Windows\system32\kernel32.dll [ntdll.dll!NtClose] [00802D00] C:\Windows\TEMP\logishrd\LVPrcInj22.dll (Camera Helper Library./Logitech Inc.)
IAT C:\Windows\ehome\ehtray.exe[4100] @ C:\Windows\system32\kernel32.dll [ntdll.dll!NtDeviceIoControlFile] [00802CA0] C:\Windows\TEMP\logishrd\LVPrcInj22.dll (Camera Helper Library./Logitech Inc.)
IAT C:\Windows\ehome\ehtray.exe[4100] @ C:\Windows\system32\kernel32.dll [ntdll.dll!NtDuplicateObject] [00802CD0] C:\Windows\TEMP\logishrd\LVPrcInj22.dll (Camera Helper Library./Logitech Inc.)
IAT C:\Users\Leslie Ball\AppData\Roaming\SanDisk\Sansa Updater\SansaDispatch.exe[4176] @ C:\Windows\system32\kernel32.dll [ntdll.dll!NtCreateFile] [003A2F30] C:\Windows\TEMP\logishrd\LVPrcInj22.dll (Camera Helper Library./Logitech Inc.)
IAT C:\Users\Leslie Ball\AppData\Roaming\SanDisk\Sansa Updater\SansaDispatch.exe[4176] @ C:\Windows\system32\kernel32.dll [ntdll.dll!NtClose] [003A2D00] C:\Windows\TEMP\logishrd\LVPrcInj22.dll (Camera Helper Library./Logitech Inc.)
IAT C:\Users\Leslie Ball\AppData\Roaming\SanDisk\Sansa Updater\SansaDispatch.exe[4176] @ C:\Windows\system32\kernel32.dll [ntdll.dll!NtDeviceIoControlFile] [003A2CA0] C:\Windows\TEMP\logishrd\LVPrcInj22.dll (Camera Helper Library./Logitech Inc.)
IAT C:\Users\Leslie Ball\AppData\Roaming\SanDisk\Sansa Updater\SansaDispatch.exe[4176] @ C:\Windows\system32\kernel32.dll [ntdll.dll!NtDuplicateObject] [003A2CD0] C:\Windows\TEMP\logishrd\LVPrcInj22.dll (Camera Helper Library./Logitech Inc.)
IAT C:\Windows\system32\FirewallControlPanel.exe[4348] @ C:\Windows\system32\kernel32.dll [ntdll.dll!NtCreateFile] [001E2F30] C:\Windows\TEMP\logishrd\LVPrcInj22.dll (Camera Helper Library./Logitech Inc.)
IAT C:\Windows\system32\FirewallControlPanel.exe[4348] @ C:\Windows\system32\kernel32.dll [ntdll.dll!NtClose] [001E2D00] C:\Windows\TEMP\logishrd\LVPrcInj22.dll (Camera Helper Library./Logitech Inc.)
IAT C:\Windows\system32\FirewallControlPanel.exe[4348] @ C:\Windows\system32\kernel32.dll [ntdll.dll!NtDeviceIoControlFile] [001E2CA0] C:\Windows\TEMP\logishrd\LVPrcInj22.dll (Camera Helper Library./Logitech Inc.)
IAT C:\Windows\system32\FirewallControlPanel.exe[4348] @ C:\Windows\system32\kernel32.dll [ntdll.dll!NtDuplicateObject] [001E2CD0] C:\Windows\TEMP\logishrd\LVPrcInj22.dll (Camera Helper Library./Logitech Inc.)
IAT C:\Program Files\RALINK\Common\RaUI.exe[4392] @ C:\Windows\system32\kernel32.dll [ntdll.dll!NtCreateFile] [00952F30] C:\Windows\TEMP\logishrd\LVPrcInj22.dll (Camera Helper Library./Logitech Inc.)
IAT C:\Program Files\RALINK\Common\RaUI.exe[4392] @ C:\Windows\system32\kernel32.dll [ntdll.dll!NtClose] [00952D00] C:\Windows\TEMP\logishrd\LVPrcInj22.dll (Camera Helper Library./Logitech Inc.)
IAT C:\Program Files\RALINK\Common\RaUI.exe[4392] @ C:\Windows\system32\kernel32.dll [ntdll.dll!NtDeviceIoControlFile] [00952CA0] C:\Windows\TEMP\logishrd\LVPrcInj22.dll (Camera Helper Library./Logitech Inc.)
IAT C:\Program Files\RALINK\Common\RaUI.exe[4392] @ C:\Windows\system32\kernel32.dll [ntdll.dll!NtDuplicateObject] [00952CD0] C:\Windows\TEMP\logishrd\LVPrcInj22.dll (Camera Helper Library./Logitech Inc.)
IAT C:\Program Files\Windows Media Player\wmpnscfg.exe[4492] @ C:\Windows\system32\kernel32.dll [ntdll.dll!NtCreateFile] [001C2F30] C:\Windows\TEMP\logishrd\LVPrcInj22.dll (Camera Helper Library./Logitech Inc.)
IAT C:\Program Files\Windows Media Player\wmpnscfg.exe[4492] @ C:\Windows\system32\kernel32.dll [ntdll.dll!NtClose] [001C2D00] C:\Windows\TEMP\logishrd\LVPrcInj22.dll (Camera Helper Library./Logitech Inc.)
IAT C:\Program Files\Windows Media Player\wmpnscfg.exe[4492] @ C:\Windows\system32\kernel32.dll [ntdll.dll!NtDeviceIoControlFile] [001C2CA0] C:\Windows\TEMP\logishrd\LVPrcInj22.dll (Camera Helper Library./Logitech Inc.)
IAT C:\Program Files\Windows Media Player\wmpnscfg.exe[4492] @ C:\Windows\system32\kernel32.dll [ntdll.dll!NtDuplicateObject] [001C2CD0] C:\Windows\TEMP\logishrd\LVPrcInj22.dll (Camera Helper Library./Logitech Inc.)
IAT C:\Windows\ehome\ehmsas.exe[4564] @ C:\Windows\system32\kernel32.dll [ntdll.dll!NtCreateFile] [00072F30] C:\Windows\TEMP\logishrd\LVPrcInj22.dll (Camera Helper Library./Logitech Inc.)
IAT C:\Windows\ehome\ehmsas.exe[4564] @ C:\Windows\system32\kernel32.dll [ntdll.dll!NtClose] [00072D00] C:\Windows\TEMP\logishrd\LVPrcInj22.dll (Camera Helper Library./Logitech Inc.)
IAT C:\Windows\ehome\ehmsas.exe[4564] @ C:\Windows\system32\kernel32.dll [ntdll.dll!NtDeviceIoControlFile] [00072CA0] C:\Windows\TEMP\logishrd\LVPrcInj22.dll (Camera Helper Library./Logitech Inc.)
IAT C:\Windows\ehome\ehmsas.exe[4564] @ C:\Windows\system32\kernel32.dll [ntdll.dll!NtDuplicateObject] [00072CD0] C:\Windows\TEMP\logishrd\LVPrcInj22.dll (Camera Helper Library./Logitech Inc.)
IAT C:\Users\Leslie Ball\Desktop\gmer.exe[4688] @ C:\Windows\system32\kernel32.dll [ntdll.dll!NtCreateFile] [00182F30] C:\Windows\TEMP\logishrd\LVPrcInj22.dll (Camera Helper Library./Logitech Inc.)
IAT C:\Users\Leslie Ball\Desktop\gmer.exe[4688] @ C:\Windows\system32\kernel32.dll [ntdll.dll!NtClose] [00182D00] C:\Windows\TEMP\logishrd\LVPrcInj22.dll (Camera Helper Library./Logitech Inc.)
IAT C:\Users\Leslie Ball\Desktop\gmer.exe[4688] @ C:\Windows\system32\kernel32.dll [ntdll.dll!NtDeviceIoControlFile] [00182CA0] C:\Windows\TEMP\logishrd\LVPrcInj22.dll (Camera Helper Library./Logitech Inc.)
IAT C:\Users\Leslie Ball\Desktop\gmer.exe[4688] @ C:\Windows\system32\kernel32.dll [ntdll.dll!NtDuplicateObject] [00182CD0] C:\Windows\TEMP\logishrd\LVPrcInj22.dll (Camera Helper Library./Logitech Inc.)
IAT C:\Windows\System32\notepad.exe[4920] @ C:\Windows\system32\kernel32.dll [ntdll.dll!NtCreateFile] [001D2F30] C:\Windows\TEMP\logishrd\LVPrcInj22.dll (Camera Helper Library./Logitech Inc.)
IAT C:\Windows\System32\notepad.exe[4920] @ C:\Windows\system32\kernel32.dll [ntdll.dll!NtClose] [001D2D00] C:\Windows\TEMP\logishrd\LVPrcInj22.dll (Camera Helper Library./Logitech Inc.)
IAT C:\Windows\System32\notepad.exe[4920] @ C:\Windows\system32\kernel32.dll [ntdll.dll!NtDeviceIoControlFile] [001D2CA0] C:\Windows\TEMP\logishrd\LVPrcInj22.dll (Camera Helper Library./Logitech Inc.)
IAT C:\Windows\System32\notepad.exe[4920] @ C:\Windows\system32\kernel32.dll [ntdll.dll!NtDuplicateObject] [001D2CD0] C:\Windows\TEMP\logishrd\LVPrcInj22.dll (Camera Helper Library./Logitech Inc.)
IAT C:\Program Files\Internet Explorer\iexplore.exe[5220] @ C:\Windows\system32\kernel32.dll [ntdll.dll!NtCreateFile] [00802F30] C:\Windows\TEMP\logishrd\LVPrcInj22.dll (Camera Helper Library./Logitech Inc.)
IAT C:\Program Files\Internet Explorer\iexplore.exe[5220] @ C:\Windows\system32\kernel32.dll [ntdll.dll!NtClose] [00802D00] C:\Windows\TEMP\logishrd\LVPrcInj22.dll (Camera Helper Library./Logitech Inc.)
IAT C:\Program Files\Internet Explorer\iexplore.exe[5220] @ C:\Windows\system32\kernel32.dll [ntdll.dll!NtDeviceIoControlFile] [00802CA0] C:\Windows\TEMP\logishrd\LVPrcInj22.dll (Camera Helper Library./Logitech Inc.)
IAT C:\Program Files\Internet Explorer\iexplore.exe[5220] @ C:\Windows\system32\kernel32.dll [ntdll.dll!NtDuplicateObject] [00802CD0] C:\Windows\TEMP\logishrd\LVPrcInj22.dll (Camera Helper Library./Logitech Inc.)
IAT C:\Program Files\AVG\AVG9\avgcfgex.exe[5856] @ C:\Windows\system32\kernel32.dll [ntdll.dll!NtCreateFile] [003D2F30] C:\Windows\TEMP\logishrd\LVPrcInj22.dll (Camera Helper Library./Logitech Inc.)
IAT C:\Program Files\AVG\AVG9\avgcfgex.exe[5856] @ C:\Windows\system32\kernel32.dll [ntdll.dll!NtClose] [003D2D00] C:\Windows\TEMP\logishrd\LVPrcInj22.dll (Camera Helper Library./Logitech Inc.)
IAT C:\Program Files\AVG\AVG9\avgcfgex.exe[5856] @ C:\Windows\system32\kernel32.dll [ntdll.dll!NtDeviceIoControlFile] [003D2CA0] C:\Windows\TEMP\logishrd\LVPrcInj22.dll (Camera Helper Library./Logitech Inc.)
IAT C:\Program Files\AVG\AVG9\avgcfgex.exe[5856] @ C:\Windows\system32\kernel32.dll [ntdll.dll!NtDuplicateObject] [003D2CD0] C:\Windows\TEMP\logishrd\LVPrcInj22.dll (Camera Helper Library./Logitech Inc.)
IAT C:\Windows\system32\Macromed\Flash\FlashUtil10j_ActiveX.exe[6112] @ C:\Windows\system32\kernel32.dll [ntdll.dll!NtCreateFile] [00BF2F30] C:\Windows\TEMP\logishrd\LVPrcInj22.dll (Camera Helper Library./Logitech Inc.)
IAT C:\Windows\system32\Macromed\Flash\FlashUtil10j_ActiveX.exe[6112] @ C:\Windows\system32\kernel32.dll [ntdll.dll!NtClose] [00BF2D00] C:\Windows\TEMP\logishrd\LVPrcInj22.dll (Camera Helper Library./Logitech Inc.)
IAT C:\Windows\system32\Macromed\Flash\FlashUtil10j_ActiveX.exe[6112] @ C:\Windows\system32\kernel32.dll [ntdll.dll!NtDeviceIoControlFile] [00BF2CA0] C:\Windows\TEMP\logishrd\LVPrcInj22.dll (Camera Helper Library./Logitech Inc.)
IAT C:\Windows\system32\Macromed\Flash\FlashUtil10j_ActiveX.exe[6112] @ C:\Windows\system32\kernel32.dll [ntdll.dll!NtDuplicateObject] [00BF2CD0] C:\Windows\TEMP\logishrd\LVPrcInj22.dll (Camera Helper Library./Logitech Inc.)

---- Devices - GMER 1.0.15 ----

AttachedDevice \Driver\tdx \Device\Tcp avgtdix.sys (AVG Network connection watcher/AVG Technologies CZ, s.r.o.)
AttachedDevice \Driver\tdx \Device\Udp avgtdix.sys (AVG Network connection watcher/AVG Technologies CZ, s.r.o.)
AttachedDevice \Driver\tdx \Device\RawIp avgtdix.sys (AVG Network connection watcher/AVG Technologies CZ, s.r.o.)

---- Registry - GMER 1.0.15 ----

Reg HKLM\SYSTEM\CurrentControlSet\Services\BTHPORT\Parameters\Keys\111111111111
Reg HKLM\SYSTEM\ControlSet002\Services\BTHPORT\Parameters\Keys\111111111111 (not active ControlSet)
Reg HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\CompatibilityAdapter\Signatures@User_Feed_Synchronization-{D855F070-0CE0-45AC-BA3A-BEA40F4409B7}.job.fp -1392796579
Reg HKLM\SOFTWARE\Microsoft\Windows Search\Gather\Windows\SystemIndex@LogName C:\ProgramData\Microsoft\Search\Data\Applications\Windows\Projects\SystemIndex\SystemIndex.Ntfy3188.gthr

---- EOF - GMER 1.0.15 ----

Army Chef

#7 quietman7

quietman7

    Bleepin' Janitor


  • Global Moderator
  • 51,399 posts
  • OFFLINE
  •  
  • Gender:Male
  • Location:Virginia, USA
  • Local time:12:14 PM

Posted 10 November 2010 - 02:28 PM

there now appear to be 2 affected files and they are as follows;

1. c:\Windows\System32\wininit.exe
2. c:\Windows\explorer.exe

Yes, that's related to a nasty infection making the rounds.

Some infections are difficult to remove completely because of their morphing characteristics which allows the malware to regenerate itself or infect critical system files which cannot be cleaned. Sometimes there is an undetected hidden piece of malware (rootkit) which protects malicious files and registry keys so they cannot be permanently deleted. Other types of malware can even terminate your security tools by changing the permissions on targeted programs so that they cannot run or complete scans. Infections will vary and some will cause more harm to your system then others as backdoor Trojans not only compromise your system, they have the ability to download more malicious files. Disinfection will probably require the use of more powerful tools than we recommend in this forum. Before that can be done you will need you to create and post a DDS log for further investigation.

Please read the pinned topic titled "Preparation Guide For Use Before Using Malware Removal Tools and Requesting Help". If you cannot complete a step, then skip it and continue with the next. In Step 7 there are instructions for downloading and running DDS which will create a Pseudo HJT Report as part of its log.

When you have done that, post your log in the Virus, Trojan, Spyware, and Malware Removal Logs forum, NOT here, for assistance by the Malware Response Team Experts. A member of the Team will walk you through, step by step, on how to clean your computer. If you post your log back in this thread, the response from the Malware Response Team will be delayed because your post will have to be moved. This means it will fall in line behind any others posted that same day.

Start a new topic, give it a relevant title and post your log along with a brief description of your problem, a summary of any anti-malware tools you have used and a summary of any steps that you have performed on your own. An expert will analyze your log and reply with instructions advising you what to fix. After doing this, we would appreciate if you post a link to your log back here so we know that your getting help from the Malware Response Team.

Please be patient. It may take a while to get a response because the Malware Response Team members are very busy working logs posted before yours. They are volunteers who will help you out as soon as possible. Once you have posted your log and are waiting, please DO NOT "bump" your post or make another reply until it has been responded to by a member of the Malware Response Team. Generally the staff checks the forum for postings that have 0 replies as this makes it easier for them to identify those who have not been helped. If you post another response there will be 1 reply. A team member, looking for a new log to work may assume another Malware Response Team member is already assisting you and not open the thread to respond.
.
.
Windows Insider MVP 2017-2018
Microsoft MVP Reconnect 2016
Microsoft MVP Consumer Security 2007-2015 kO7xOZh.gif
Member of UNITE, Unified Network of Instructors and Trusted Eliminators

If I have been helpful & you'd like to consider a donation, click 38WxTfO.gif

#8 Orange Blossom

Orange Blossom

    OBleepin Investigator


  • Moderator
  • 36,949 posts
  • ONLINE
  •  
  • Gender:Not Telling
  • Location:Bloomington, IN
  • Local time:12:14 PM

Posted 11 November 2010 - 11:05 PM

Hello,

Now that you have posted a log here: http://www.bleepingcomputer.com/forums/topic359706.html you should NOT make further changes to your computer (install/uninstall programs, use special fix tools, delete files, edit the registry, etc) unless advised by a MRT Team member, nor should you ask for help elsewhere. Doing so can result in system changes which may not show in the log you already posted. Further, any modifications you make on your own may cause confusion for the helper assisting you and could complicate the malware removal process which would extend the time it takes to clean your computer.

From this point on the MRT Team should be the only members that you take advice from, until they have verified your log as clean.

Please be patient. It may take a while to get a response because the MRT Team members are EXTREMELY busy working logs posted before yours. They are volunteers who will help you out as soon as possible. Once you have made your post and are waiting, please DO NOT make another reply until it has been responded to by a member of the MRT Team. Generally the staff checks the forum for postings that have 0 replies as this makes it easier for them to identify those who have not been helped. If you post another response there will be 1 reply. A team member, looking for a new log to work may assume another MRT Team member is already assisting you and not open the thread to respond.

Please be patient. It may take several days to get a response but your log will be reviewed and answered as soon as possible. I advise checking your topic once a day for responses as the e-mail notification system is unreliable.

To avoid confusion, I am closing this topic. Good luck with your log.

Orange Blossom :cherry:
Help us help you. If HelpBot replies, you MUST follow step 1 in its reply so we know you need help.

Orange Blossom

An ounce of prevention is worth a pound of cure

SpywareBlaster, WinPatrol Plus, ESET Smart Security, Malwarebytes' Anti-Malware, NoScript Firefox ext., Norton noscript




0 user(s) are reading this topic

0 members, 0 guests, 0 anonymous users