Jump to content


 


Register a free account to unlock additional features at BleepingComputer.com
Welcome to BleepingComputer, a free community where people like yourself come together to discuss and learn how to use their computers. Using the site is easy and fun. As a guest, you can browse and view the various discussions in the forums, but can not create a new topic or reply to an existing one unless you are logged in. Other benefits of registering an account are subscribing to topics and forums, creating a blog, and having no ads shown anywhere on the site.


Click here to Register a free account now! or read our Welcome Guide to learn how to use this site.

Photo

Possibilty computer has a virus/ spyware or similar


  • This topic is locked This topic is locked
12 replies to this topic

#1 starmmb

starmmb

  • Members
  • 18 posts
  • OFFLINE
  •  
  • Local time:04:30 PM

Posted 21 December 2010 - 08:11 PM

Hi, I am using Windows xp home addition & AVG free edition (just updated). A week or 2 ago I had "Internet anti-virus 2011" installed on my computer and was frustrated at the reports that continuously appeared. As I could not find it listed in the uninstall programs list, I did a 'system restore' to a date prior to it being on my computer. I thought I was rid of it however I think it may be related to a newer problem that has emerged. For the past several days many of the search results that I click on through Google get redirected to an unrelated site. If I hit the back arrow enough times to the search results, usually on the second attempt I will be able to open the intended site. Now today when I open Google homepage it tells me the page does not exist but I get a smaller version of the search bar towards the top of the page. This may or may not be related but thought I would mention it. AVG runs an automatic scan every day. The last time it showed any problems was on December 14 (the day I installed the update). It said 15/15 infections were removed to the vault. I would appreciate any advice you can give me but please be very specific as I do not consider myself to be highly computer literate. Thanks in advance.

BC AdBot (Login to Remove)

 


#2 quietman7

quietman7

    Bleepin' Janitor


  • Global Moderator
  • 51,766 posts
  • OFFLINE
  •  
  • Gender:Male
  • Location:Virginia, USA
  • Local time:02:30 AM

Posted 21 December 2010 - 09:02 PM

Please follow these instructions: How to remove Google Redirects or the TDSS, TDL3, Alureon rootkit using TDSSKiller
  • Double-click on TDSSKiller.exe to run the tool for known TDSS variants.
    Vista/Windows 7 users right-click and select Run As Administrator.
  • When the program opens, click the Start Scan button.
  • If malicious objects are found, they will show in the Scan results - Select action for found objects and offer three options.
  • Ensure Cure is selected, then click Continue > Reboot now to finish the cleaning process. <- Important!!
    Note: If 'Suspicious' objects are detected, you will be given the option to Skip or Quarantine. Skip will be the default selection.
  • A log file named TDSSKiller_version_date_time_log.txt will be created and saved to the root directory (usually Local Disk C:).
  • Copy and paste the contents of that file in your next reply.
-- For any files detected as 'Suspicious' (except those identified as Forged to be cured after reboot) get a second opinion by submitting to Jotti's virusscan or VirusTotal. In the "File to upload & scan" box, browse to the location of the suspicious file and submit (upload) it for scanning/analysis.

Step 9 recommends that you scan your computer using Malwarebytes Anti-Malware to remove any traces that may still be present. If Malwarebytes encounters a file that is difficult to remove, you will be asked to reboot your computer so it can proceed with the disinfection process. If asked to restart the computer, please do so immediately. Failure to reboot normally will prevent Malwarebytes from removing all the malware. After performing that step, please post the complete results of your scan for review.


Please download SUPERAntiSpyware Free and follow these instructions for performing a scan.

  • Double-click SUPERAntiSypware.exe and use the default settings for installation.
  • Be sure to update the definitions before scanning by selecting "Check for Updates".
    If you encounter any problems while downloading the updates, manually download them from here.
  • To retrieve the removal information after reboot, launch SUPERAntispyware again.
    • Click Preferences, then click the Statistics/Logs tab.
    • Under Scanner Logs, double-click SUPERAntiSpyware Scan Log.
    • If there are several logs, click the current dated log and press View log. A text file will open in your default text editor.
  • Click Close to exit the program.
  • Please copy and paste the Scan Log results in your next reply.
-- Some types of malware will disable security tools. If SUPERAntiSpyware will not install, please refer to these instructions for using the SUPERAntiSpyware Installer. If SUPERAntiSpyware is already installed but will not run, then follow the instructions for using RUNSAS.EXE to launch the program.

-- Alternatively, you can try downloading and using the SUPERAntiSpyware Portable Scanner or performing the SUPERAntiSpyware Online Safe Scan (both listed under Popular Links) instead. Save the randomly named file (i.e. SAS_1710895.COM) to a usb drive or CD and transfer to the infected computer. Then double-click on it to launch and scan. The file is randomly named to help keep malware from blocking the scanner.
.
.
Windows Insider MVP 2017-2018
Microsoft MVP Reconnect 2016
Microsoft MVP Consumer Security 2007-2015 kO7xOZh.gif
Member of UNITE, Unified Network of Instructors and Trusted Eliminators

If I have been helpful & you'd like to consider a donation, click 38WxTfO.gif

#3 starmmb

starmmb
  • Topic Starter

  • Members
  • 18 posts
  • OFFLINE
  •  
  • Local time:04:30 PM

Posted 21 December 2010 - 11:40 PM

Hi, thank you for your prompt reply. When I ran the TDSSKiller scan it reported that no infections were found so I proceded to the SUPERAntiSpyware program as the information provided stated that Malwarebytes Anti-Malware was to remove any remaining traces. I now believe that perhaps I should not have skipped this step so I will post the results of the 2 scans I have completed then start the malware bytes scan & post them once it has finished. Thank you for your patience, understanding & assistance.

2010/12/22 12:14:10.0859 TDSS rootkit removing tool 2.4.12.0 Dec 16 2010 09:46:46
2010/12/22 12:14:10.0859 ================================================================================
2010/12/22 12:14:10.0859 SystemInfo:
2010/12/22 12:14:10.0859
2010/12/22 12:14:10.0859 OS Version: 5.1.2600 ServicePack: 3.0
2010/12/22 12:14:10.0875 Product type: Workstation
2010/12/22 12:14:10.0875 ComputerName: PCUSER-1E514038
2010/12/22 12:14:10.0890 UserName: Melane
2010/12/22 12:14:10.0890 Windows directory: C:\WINDOWS
2010/12/22 12:14:10.0890 System windows directory: C:\WINDOWS
2010/12/22 12:14:10.0890 Processor architecture: Intel x86
2010/12/22 12:14:10.0890 Number of processors: 2
2010/12/22 12:14:10.0890 Page size: 0x1000
2010/12/22 12:14:10.0890 Boot type: Normal boot
2010/12/22 12:14:10.0890 ================================================================================
2010/12/22 12:14:12.0015 Initialize success
2010/12/22 12:14:41.0546 ================================================================================
2010/12/22 12:14:41.0546 Scan started
2010/12/22 12:14:41.0546 Mode: Manual;
2010/12/22 12:14:41.0546 ================================================================================
2010/12/22 12:14:43.0156 ACPI (8fd99680a539792a30e97944fdaecf17) C:\WINDOWS\system32\DRIVERS\ACPI.sys
2010/12/22 12:14:43.0296 ACPIEC (9859c0f6936e723e4892d7141b1327d5) C:\WINDOWS\system32\drivers\ACPIEC.sys
2010/12/22 12:14:43.0562 aec (8bed39e3c35d6a489438b8141717a557) C:\WINDOWS\system32\drivers\aec.sys
2010/12/22 12:14:43.0765 AFD (7e775010ef291da96ad17ca4b17137d7) C:\WINDOWS\System32\drivers\afd.sys
2010/12/22 12:14:44.0328 AsyncMac (b153affac761e7f5fcfa822b9c4e97bc) C:\WINDOWS\system32\DRIVERS\asyncmac.sys
2010/12/22 12:14:44.0484 atapi (9f3a2f5aa6875c72bf062c712cfa2674) C:\WINDOWS\system32\DRIVERS\atapi.sys
2010/12/22 12:14:44.0671 ati2mtag (f48fe6d69f7a224a2157d052e3b1a0fc) C:\WINDOWS\system32\DRIVERS\ati2mtag.sys
2010/12/22 12:14:44.0875 Atmarpc (9916c1225104ba14794209cfa8012159) C:\WINDOWS\system32\DRIVERS\atmarpc.sys
2010/12/22 12:14:45.0062 audstub (d9f724aa26c010a217c97606b160ed68) C:\WINDOWS\system32\DRIVERS\audstub.sys
2010/12/22 12:14:45.0296 AVGIDSDriver (0c61f066f4d94bd67063dc6691935143) C:\WINDOWS\system32\DRIVERS\AVGIDSDriver.Sys
2010/12/22 12:14:45.0375 AVGIDSEH (84853f800cd69252c3c764fe50d0346f) C:\WINDOWS\system32\DRIVERS\AVGIDSEH.Sys
2010/12/22 12:14:45.0484 AVGIDSFilter (28d6adcd03e10f3838488b9b5d407dd4) C:\WINDOWS\system32\DRIVERS\AVGIDSFilter.Sys
2010/12/22 12:14:45.0656 AVGIDSShim (0eb16f4dbbb946360af30d2b13a52d1d) C:\WINDOWS\system32\DRIVERS\AVGIDSShim.Sys
2010/12/22 12:14:45.0828 Avgldx86 (1119e5bec6e749e0d292f0f84d48edba) C:\WINDOWS\system32\DRIVERS\avgldx86.sys
2010/12/22 12:14:46.0000 Avgmfx86 (54f1a9b4c9b540c2d8ac4baa171696b1) C:\WINDOWS\system32\DRIVERS\avgmfx86.sys
2010/12/22 12:14:46.0078 Avgrkx86 (8da3b77993c5f354cc2977b7ea06d03a) C:\WINDOWS\system32\DRIVERS\avgrkx86.sys
2010/12/22 12:14:46.0187 Avgtdix (354e0fec3bfdfa9c369e0f67ac362f9f) C:\WINDOWS\system32\DRIVERS\avgtdix.sys
2010/12/22 12:14:46.0343 Beep (da1f27d85e0d1525f6621372e7b685e9) C:\WINDOWS\system32\drivers\Beep.sys
2010/12/22 12:14:46.0359 Suspicious service (NoAccess): bxtjvesaf
2010/12/22 12:14:46.0468 cbidf2k (90a673fc8e12a79afbed2576f6a7aaf9) C:\WINDOWS\system32\drivers\cbidf2k.sys
2010/12/22 12:14:46.0656 CCDECODE (0be5aef125be881c4f854c554f2b025c) C:\WINDOWS\system32\DRIVERS\CCDECODE.sys
2010/12/22 12:14:46.0953 Cdaudio (c1b486a7658353d33a10cc15211a873b) C:\WINDOWS\system32\drivers\Cdaudio.sys
2010/12/22 12:14:47.0109 Cdfs (c885b02847f5d2fd45a24e219ed93b32) C:\WINDOWS\system32\drivers\Cdfs.sys
2010/12/22 12:14:47.0187 Cdrom (1f4260cc5b42272d71f79e570a27a4fe) C:\WINDOWS\system32\DRIVERS\cdrom.sys
2010/12/22 12:14:47.0562 Disk (044452051f3e02e7963599fc8f4f3e25) C:\WINDOWS\system32\DRIVERS\disk.sys
2010/12/22 12:14:47.0718 dmboot (d992fe1274bde0f84ad826acae022a41) C:\WINDOWS\system32\drivers\dmboot.sys
2010/12/22 12:14:47.0984 dmio (7c824cf7bbde77d95c08005717a95f6f) C:\WINDOWS\system32\drivers\dmio.sys
2010/12/22 12:14:48.0171 dmload (e9317282a63ca4d188c0df5e09c6ac5f) C:\WINDOWS\system32\drivers\dmload.sys
2010/12/22 12:14:48.0328 DMusic (8a208dfcf89792a484e76c40e5f50b45) C:\WINDOWS\system32\drivers\DMusic.sys
2010/12/22 12:14:48.0562 drmkaud (8f5fcff8e8848afac920905fbd9d33c8) C:\WINDOWS\system32\drivers\drmkaud.sys
2010/12/22 12:14:48.0703 Fastfat (38d332a6d56af32635675f132548343e) C:\WINDOWS\system32\drivers\Fastfat.sys
2010/12/22 12:14:48.0765 Fdc (92cdd60b6730b9f50f6a1a0c1f8cdc81) C:\WINDOWS\system32\DRIVERS\fdc.sys
2010/12/22 12:14:48.0906 FETNDIS (e9648254056bce81a85380c0c3647dc4) C:\WINDOWS\system32\DRIVERS\fetnd5.sys
2010/12/22 12:14:49.0062 Fips (d45926117eb9fa946a6af572fbe1caa3) C:\WINDOWS\system32\drivers\Fips.sys
2010/12/22 12:14:49.0218 Flpydisk (9d27e7b80bfcdf1cdd9b555862d5e7f0) C:\WINDOWS\system32\drivers\Flpydisk.sys
2010/12/22 12:14:49.0375 FltMgr (b2cf4b0786f8212cb92ed2b50c6db6b0) C:\WINDOWS\system32\drivers\fltmgr.sys
2010/12/22 12:14:49.0531 Fs_Rec (3e1e2bd4f39b0e2b7dc4f4d2bcc2779a) C:\WINDOWS\system32\drivers\Fs_Rec.sys
2010/12/22 12:14:49.0687 Ftdisk (6ac26732762483366c3969c9e4d2259d) C:\WINDOWS\system32\DRIVERS\ftdisk.sys
2010/12/22 12:14:49.0765 GEARAspiWDM (8182ff89c65e4d38b2de4bb0fb18564e) C:\WINDOWS\system32\DRIVERS\GEARAspiWDM.sys
2010/12/22 12:14:49.0781 Suspicious service (NoAccess): gmecig
2010/12/22 12:14:49.0875 Gpc (0a02c63c8b144bd8c86b103dee7c86a2) C:\WINDOWS\system32\DRIVERS\msgpc.sys
2010/12/22 12:14:50.0093 HPZid412 (d03d10f7ded688fecf50f8fbf1ea9b8a) C:\WINDOWS\system32\DRIVERS\HPZid412.sys
2010/12/22 12:14:50.0187 HPZipr12 (89f41658929393487b6b7d13c8528ce3) C:\WINDOWS\system32\DRIVERS\HPZipr12.sys
2010/12/22 12:14:50.0265 HPZius12 (abcb05ccdbf03000354b9553820e39f8) C:\WINDOWS\system32\DRIVERS\HPZius12.sys
2010/12/22 12:14:50.0359 HSFHWBS2 (970178e8e003eb1481293830069624b9) C:\WINDOWS\system32\DRIVERS\HSFBS2S2.sys
2010/12/22 12:14:50.0546 HSF_DP (ebb354438a4c5a3327fb97306260714a) C:\WINDOWS\system32\DRIVERS\HSFDPSP2.sys
2010/12/22 12:14:50.0750 HTTP (f80a415ef82cd06ffaf0d971528ead38) C:\WINDOWS\system32\Drivers\HTTP.sys
2010/12/22 12:14:51.0078 i8042prt (4a0b06aa8943c1e332520f7440c0aa30) C:\WINDOWS\system32\DRIVERS\i8042prt.sys
2010/12/22 12:14:51.0234 Imapi (083a052659f5310dd8b6a6cb05edcf8e) C:\WINDOWS\system32\DRIVERS\imapi.sys
2010/12/22 12:14:51.0312 Suspicious service (NoAccess): imdid
2010/12/22 12:14:51.0421 InCDfs (bb7b8b24d81de3cdfd5d91eb632ccbbe) C:\WINDOWS\system32\drivers\InCDfs.sys
2010/12/22 12:14:51.0578 InCDPass (abbb6a2ff6bfc531f482c19905dd7f6b) C:\WINDOWS\system32\DRIVERS\InCDPass.sys
2010/12/22 12:14:51.0875 InCDrec (4a8846c9db9d2070f604ebd60ce64816) C:\WINDOWS\system32\drivers\InCDrec.sys
2010/12/22 12:14:52.0031 incdrm (dcaa6a1d8188b594129f1633c9c4ef8b) C:\WINDOWS\system32\drivers\incdrm.sys
2010/12/22 12:14:52.0343 intelppm (8c953733d8f36eb2133f5bb58808b66b) C:\WINDOWS\system32\DRIVERS\intelppm.sys
2010/12/22 12:14:52.0453 Ip6Fw (3bb22519a194418d5fec05d800a19ad0) C:\WINDOWS\system32\drivers\ip6fw.sys
2010/12/22 12:14:52.0640 IpFilterDriver (731f22ba402ee4b62748adaf6363c182) C:\WINDOWS\system32\DRIVERS\ipfltdrv.sys
2010/12/22 12:14:52.0734 IpInIp (b87ab476dcf76e72010632b5550955f5) C:\WINDOWS\system32\DRIVERS\ipinip.sys
2010/12/22 12:14:52.0843 IpNat (cc748ea12c6effde940ee98098bf96bb) C:\WINDOWS\system32\DRIVERS\ipnat.sys
2010/12/22 12:14:53.0031 IPSec (23c74d75e36e7158768dd63d92789a91) C:\WINDOWS\system32\DRIVERS\ipsec.sys
2010/12/22 12:14:53.0203 IRENUM (c93c9ff7b04d772627a3646d89f7bf89) C:\WINDOWS\system32\DRIVERS\irenum.sys
2010/12/22 12:14:53.0390 isapnp (05a299ec56e52649b1cf2fc52d20f2d7) C:\WINDOWS\system32\DRIVERS\isapnp.sys
2010/12/22 12:14:53.0531 Kbdclass (463c1ec80cd17420a542b7f36a36f128) C:\WINDOWS\system32\DRIVERS\kbdclass.sys
2010/12/22 12:14:53.0718 kmixer (692bcf44383d056aed41b045a323d378) C:\WINDOWS\system32\drivers\kmixer.sys
2010/12/22 12:14:53.0812 KSecDD (b467646c54cc746128904e1654c750c1) C:\WINDOWS\system32\drivers\KSecDD.sys
2010/12/22 12:14:53.0968 mdmxsdk (195741aee20369980796b557358cd774) C:\WINDOWS\system32\DRIVERS\mdmxsdk.sys
2010/12/22 12:14:54.0125 mnmdd (4ae068242760a1fb6e1a44bf4e16afa6) C:\WINDOWS\system32\drivers\mnmdd.sys
2010/12/22 12:14:54.0281 Modem (dfcbad3cec1c5f964962ae10e0bcc8e1) C:\WINDOWS\system32\drivers\Modem.sys
2010/12/22 12:14:54.0453 Mouclass (35c9e97194c8cfb8430125f8dbc34d04) C:\WINDOWS\system32\DRIVERS\mouclass.sys
2010/12/22 12:14:54.0609 MountMgr (a80b9a0bad1b73637dbcbba7df72d3fd) C:\WINDOWS\system32\drivers\MountMgr.sys
2010/12/22 12:14:54.0734 MRxDAV (11d42bb6206f33fbb3ba0288d3ef81bd) C:\WINDOWS\system32\DRIVERS\mrxdav.sys
2010/12/22 12:14:54.0859 MRxSmb (f3aefb11abc521122b67095044169e98) C:\WINDOWS\system32\DRIVERS\mrxsmb.sys
2010/12/22 12:14:55.0031 Msfs (c941ea2454ba8350021d774daf0f1027) C:\WINDOWS\system32\drivers\Msfs.sys
2010/12/22 12:14:55.0078 MSKSSRV (d1575e71568f4d9e14ca56b7b0453bf1) C:\WINDOWS\system32\drivers\MSKSSRV.sys
2010/12/22 12:14:55.0187 MSPCLOCK (325bb26842fc7ccc1fcce2c457317f3e) C:\WINDOWS\system32\drivers\MSPCLOCK.sys
2010/12/22 12:14:55.0281 MSPQM (bad59648ba099da4a17680b39730cb3d) C:\WINDOWS\system32\drivers\MSPQM.sys
2010/12/22 12:14:55.0437 mssmbios (af5f4f3f14a8ea2c26de30f7a1e17136) C:\WINDOWS\system32\DRIVERS\mssmbios.sys
2010/12/22 12:14:55.0546 MSTEE (e53736a9e30c45fa9e7b5eac55056d1d) C:\WINDOWS\system32\drivers\MSTEE.sys
2010/12/22 12:14:55.0703 Mup (2f625d11385b1a94360bfc70aaefdee1) C:\WINDOWS\system32\drivers\Mup.sys
2010/12/22 12:14:55.0796 NABTSFEC (5b50f1b2a2ed47d560577b221da734db) C:\WINDOWS\system32\DRIVERS\NABTSFEC.sys
2010/12/22 12:14:55.0953 NDIS (1df7f42665c94b825322fae71721130d) C:\WINDOWS\system32\drivers\NDIS.sys
2010/12/22 12:14:56.0046 NdisIP (7ff1f1fd8609c149aa432f95a8163d97) C:\WINDOWS\system32\DRIVERS\NdisIP.sys
2010/12/22 12:14:56.0187 NdisTapi (1ab3d00c991ab086e69db84b6c0ed78f) C:\WINDOWS\system32\DRIVERS\ndistapi.sys
2010/12/22 12:14:56.0296 Ndisuio (f927a4434c5028758a842943ef1a3849) C:\WINDOWS\system32\DRIVERS\ndisuio.sys
2010/12/22 12:14:56.0453 NdisWan (edc1531a49c80614b2cfda43ca8659ab) C:\WINDOWS\system32\DRIVERS\ndiswan.sys
2010/12/22 12:14:56.0578 NDProxy (9282bd12dfb069d3889eb3fcc1000a9b) C:\WINDOWS\system32\drivers\NDProxy.sys
2010/12/22 12:14:56.0750 NetBIOS (5d81cf9a2f1a3a756b66cf684911cdf0) C:\WINDOWS\system32\DRIVERS\netbios.sys
2010/12/22 12:14:56.0859 NetBT (74b2b2f5bea5e9a3dc021d685551bd3d) C:\WINDOWS\system32\DRIVERS\netbt.sys
2010/12/22 12:14:57.0031 Npfs (3182d64ae053d6fb034f44b6def8034a) C:\WINDOWS\system32\drivers\Npfs.sys
2010/12/22 12:14:57.0093 Ntfs (78a08dd6a8d65e697c18e1db01c5cdca) C:\WINDOWS\system32\drivers\Ntfs.sys
2010/12/22 12:14:57.0250 Null (73c1e1f395918bc2c6dd67af7591a3ad) C:\WINDOWS\system32\drivers\Null.sys
2010/12/22 12:14:57.0375 NwlnkFlt (b305f3fad35083837ef46a0bbce2fc57) C:\WINDOWS\system32\DRIVERS\nwlnkflt.sys
2010/12/22 12:14:57.0531 NwlnkFwd (c99b3415198d1aab7227f2c88fd664b9) C:\WINDOWS\system32\DRIVERS\nwlnkfwd.sys
2010/12/22 12:14:57.0625 Parport (5575faf8f97ce5e713d108c2a58d7c7c) C:\WINDOWS\system32\DRIVERS\parport.sys
2010/12/22 12:14:57.0765 PartMgr (beb3ba25197665d82ec7065b724171c6) C:\WINDOWS\system32\drivers\PartMgr.sys
2010/12/22 12:14:57.0859 ParVdm (70e98b3fd8e963a6a46a2e6247e0bea1) C:\WINDOWS\system32\drivers\ParVdm.sys
2010/12/22 12:14:57.0984 PCI (a219903ccf74233761d92bef471a07b1) C:\WINDOWS\system32\DRIVERS\pci.sys
2010/12/22 12:14:58.0109 Pcmcia (9e89ef60e9ee05e3f2eef2da7397f1c1) C:\WINDOWS\system32\drivers\Pcmcia.sys
2010/12/22 12:14:58.0500 PptpMiniport (efeec01b1d3cf84f16ddd24d9d9d8f99) C:\WINDOWS\system32\DRIVERS\raspptp.sys
2010/12/22 12:14:58.0671 PSched (09298ec810b07e5d582cb3a3f9255424) C:\WINDOWS\system32\DRIVERS\psched.sys
2010/12/22 12:14:58.0843 Ptilink (80d317bd1c3dbc5d4fe7b1678c60cadd) C:\WINDOWS\system32\DRIVERS\ptilink.sys
2010/12/22 12:14:59.0187 RasAcd (fe0d99d6f31e4fad8159f690d68ded9c) C:\WINDOWS\system32\DRIVERS\rasacd.sys
2010/12/22 12:14:59.0328 Rasl2tp (11b4a627bc9614b885c4969bfa5ff8a6) C:\WINDOWS\system32\DRIVERS\rasl2tp.sys
2010/12/22 12:14:59.0437 RasPppoe (5bc962f2654137c9909c3d4603587dee) C:\WINDOWS\system32\DRIVERS\raspppoe.sys
2010/12/22 12:14:59.0625 Raspti (fdbb1d60066fcfbb7452fd8f9829b242) C:\WINDOWS\system32\DRIVERS\raspti.sys
2010/12/22 12:14:59.0734 Rdbss (7ad224ad1a1437fe28d89cf22b17780a) C:\WINDOWS\system32\DRIVERS\rdbss.sys
2010/12/22 12:14:59.0812 RDPCDD (4912d5b403614ce99c28420f75353332) C:\WINDOWS\system32\DRIVERS\RDPCDD.sys
2010/12/22 12:14:59.0921 RDPWD (6728e45b66f93c08f11de2e316fc70dd) C:\WINDOWS\system32\drivers\RDPWD.sys
2010/12/22 12:15:00.0109 redbook (f828dd7e1419b6653894a8f97a0094c5) C:\WINDOWS\system32\DRIVERS\redbook.sys
2010/12/22 12:15:00.0281 Secdrv (90a3935d05b494a5a39d37e71f09a677) C:\WINDOWS\system32\DRIVERS\secdrv.sys
2010/12/22 12:15:00.0453 serenum (0f29512ccd6bead730039fb4bd2c85ce) C:\WINDOWS\system32\DRIVERS\serenum.sys
2010/12/22 12:15:00.0593 Serial (cca207a8896d4c6a0c9ce29a4ae411a7) C:\WINDOWS\system32\DRIVERS\serial.sys
2010/12/22 12:15:00.0750 Sfloppy (8e6b8c671615d126fdc553d1e2de5562) C:\WINDOWS\system32\drivers\Sfloppy.sys
2010/12/22 12:15:00.0953 SLIP (866d538ebe33709a5c9f5c62b73b7d14) C:\WINDOWS\system32\DRIVERS\SLIP.sys
2010/12/22 12:15:01.0156 splitter (ab8b92451ecb048a4d1de7c3ffcb4a9f) C:\WINDOWS\system32\drivers\splitter.sys
2010/12/22 12:15:01.0328 sr (76bb022c2fb6902fd5bdd4f78fc13a5d) C:\WINDOWS\system32\DRIVERS\sr.sys
2010/12/22 12:15:01.0437 Srv (0f6aefad3641a657e18081f52d0c15af) C:\WINDOWS\system32\DRIVERS\srv.sys
2010/12/22 12:15:01.0625 streamip (77813007ba6265c4b6098187e6ed79d2) C:\WINDOWS\system32\DRIVERS\StreamIP.sys
2010/12/22 12:15:01.0796 swenum (3941d127aef12e93addf6fe6ee027e0f) C:\WINDOWS\system32\DRIVERS\swenum.sys
2010/12/22 12:15:01.0890 swmidi (8ce882bcc6cf8a62f2b2323d95cb3d01) C:\WINDOWS\system32\drivers\swmidi.sys
2010/12/22 12:15:02.0296 sysaudio (8b83f3ed0f1688b4958f77cd6d2bf290) C:\WINDOWS\system32\drivers\sysaudio.sys
2010/12/22 12:15:02.0500 Tcpip (9aefa14bd6b182d61e3119fa5f436d3d) C:\WINDOWS\system32\DRIVERS\tcpip.sys
2010/12/22 12:15:02.0687 TDPIPE (6471a66807f5e104e4885f5b67349397) C:\WINDOWS\system32\drivers\TDPIPE.sys
2010/12/22 12:15:02.0843 TDTCP (c56b6d0402371cf3700eb322ef3aaf61) C:\WINDOWS\system32\drivers\TDTCP.sys
2010/12/22 12:15:02.0890 TermDD (88155247177638048422893737429d9e) C:\WINDOWS\system32\DRIVERS\termdd.sys
2010/12/22 12:15:03.0109 uagp35 (d85938f272d1bcf3db3a31fc0a048928) C:\WINDOWS\system32\DRIVERS\uagp35.sys
2010/12/22 12:15:03.0234 Udfs (5787b80c2e3c5e2f56c2a233d91fa2c9) C:\WINDOWS\system32\drivers\Udfs.sys
2010/12/22 12:15:03.0437 Update (402ddc88356b1bac0ee3dd1580c76a31) C:\WINDOWS\system32\DRIVERS\update.sys
2010/12/22 12:15:03.0625 USBAAPL (1df89c499bf45d878b87ebd4421d462d) C:\WINDOWS\system32\Drivers\usbaapl.sys
2010/12/22 12:15:03.0750 usbccgp (173f317ce0db8e21322e71b7e60a27e8) C:\WINDOWS\system32\DRIVERS\usbccgp.sys
2010/12/22 12:15:03.0843 usbehci (65dcf09d0e37d4c6b11b5b0b76d470a7) C:\WINDOWS\system32\DRIVERS\usbehci.sys
2010/12/22 12:15:03.0984 usbhub (1ab3cdde553b6e064d2e754efe20285c) C:\WINDOWS\system32\DRIVERS\usbhub.sys
2010/12/22 12:15:04.0125 usbprint (a717c8721046828520c9edf31288fc00) C:\WINDOWS\system32\DRIVERS\usbprint.sys
2010/12/22 12:15:04.0343 usbscan (a0b8cf9deb1184fbdd20784a58fa75d4) C:\WINDOWS\system32\DRIVERS\usbscan.sys
2010/12/22 12:15:04.0656 USBSTOR (a32426d9b14a089eaa1d922e0c5801a9) C:\WINDOWS\system32\DRIVERS\USBSTOR.SYS
2010/12/22 12:15:05.0031 usbuhci (26496f9dee2d787fc3e61ad54821ffe6) C:\WINDOWS\system32\DRIVERS\usbuhci.sys
2010/12/22 12:15:05.0390 usbvideo (63bbfca7f390f4c49ed4b96bfb1633e0) C:\WINDOWS\system32\Drivers\usbvideo.sys
2010/12/22 12:15:05.0796 VgaSave (0d3a8fafceacd8b7625cd549757a7df1) C:\WINDOWS\System32\drivers\vga.sys
2010/12/22 12:15:06.0250 ViaIde (3b3efcda263b8ac14fdf9cbdd0791b2e) C:\WINDOWS\system32\DRIVERS\viaide.sys
2010/12/22 12:15:06.0656 viamraid (7dc3e1dc6e4f8be381c31bfea578412a) C:\WINDOWS\system32\DRIVERS\viamraid.sys
2010/12/22 12:15:07.0093 VIAudio (ec14fedcfc97f0af98215ce385afec23) C:\WINDOWS\system32\drivers\viaudios.sys
2010/12/22 12:15:07.0765 videX32 (f95c0fcfbcbda6d8f202d2df4052f88d) C:\WINDOWS\system32\DRIVERS\videX32.sys
2010/12/22 12:15:07.0906 VolSnap (4c8fcb5cc53aab716d810740fe59d025) C:\WINDOWS\system32\drivers\VolSnap.sys
2010/12/22 12:15:08.0000 Vsp (aaf94bc88ecdf0ae0586805dad1e59c4) C:\WINDOWS\system32\drivers\Vsp.sys
2010/12/22 12:15:08.0156 Wanarp (e20b95baedb550f32dd489265c1da1f6) C:\WINDOWS\system32\DRIVERS\wanarp.sys
2010/12/22 12:15:08.0375 wdmaud (6768acf64b18196494413695f0c3a00f) C:\WINDOWS\system32\drivers\wdmaud.sys
2010/12/22 12:15:08.0562 winachsf (1225ebea76aac3c84df6c54fe5e5d8be) C:\WINDOWS\system32\DRIVERS\HSFCXTS2.sys
2010/12/22 12:15:08.0796 WSTCODEC (c98b39829c2bbd34e454150633c62c78) C:\WINDOWS\system32\DRIVERS\WSTCODEC.SYS
2010/12/22 12:15:08.0953 WudfPf (f15feafffbb3644ccc80c5da584e6311) C:\WINDOWS\system32\DRIVERS\WudfPf.sys
2010/12/22 12:15:09.0109 WudfRd (28b524262bce6de1f7ef9f510ba3985b) C:\WINDOWS\system32\DRIVERS\wudfrd.sys
2010/12/22 12:15:09.0234 zgwhsdiag (f2c38cd7b6696566da0c3485a41b43dc) C:\WINDOWS\system32\DRIVERS\zgwhsdiag.sys
2010/12/22 12:15:09.0406 zgwhsmdm (f2c38cd7b6696566da0c3485a41b43dc) C:\WINDOWS\system32\DRIVERS\zgwhsmdm.sys
2010/12/22 12:15:09.0578 ================================================================================
2010/12/22 12:15:09.0578 Scan finished
2010/12/22 12:15:09.0578 ================================================================================
2010/12/22 12:17:46.0921 Deinitialize success



SUPERAntiSpyware Scan Log
http://www.superantispyware.com

Generated 12/22/2010 at 01:45 PM

Application Version : 4.47.1000

Core Rules Database Version : 6054
Trace Rules Database Version: 3866

Scan type : Complete Scan
Total Scan Time : 01:06:36

Memory items scanned : 494
Memory threats detected : 2
Registry items scanned : 7438
Registry threats detected : 796
File items scanned : 22827
File threats detected : 1146

Adware.MyWebSearch
C:\PROGRA~1\MYWEBS~1\BAR\1.BIN\MWSOESTB.DLL
C:\PROGRA~1\MYWEBS~1\BAR\1.BIN\MWSOESTB.DLL
C:\PROGRA~1\MYWEBS~1\BAR\1.BIN\MWSOEMON.EXE
C:\PROGRA~1\MYWEBS~1\BAR\1.BIN\MWSOEMON.EXE
[My Web Search Bar Search Scope Monitor] C:\PROGRA~1\MYWEBS~1\BAR\1.BIN\M3SRCHMN.EXE
C:\PROGRA~1\MYWEBS~1\BAR\1.BIN\M3SRCHMN.EXE
[MyWebSearch Email Plugin] C:\PROGRA~1\MYWEBS~1\BAR\1.BIN\MWSOEMON.EXE
[MyWebSearch Email Plugin] C:\PROGRA~1\MYWEBS~1\BAR\1.BIN\MWSOEMON.EXE
HKLM\Software\Classes\CLSID\{00A6FAF1-072E-44cf-8957-5838F569A31D}
HKCR\CLSID\{00A6FAF1-072E-44CF-8957-5838F569A31D}
HKCR\CLSID\{00A6FAF1-072E-44CF-8957-5838F569A31D}
HKCR\CLSID\{00A6FAF1-072E-44CF-8957-5838F569A31D}\InprocServer32
HKCR\CLSID\{00A6FAF1-072E-44CF-8957-5838F569A31D}\InprocServer32#ThreadingModel
HKCR\CLSID\{00A6FAF1-072E-44CF-8957-5838F569A31D}\Programmable
C:\PROGRAM FILES\MYWEBSEARCH\BAR\1.BIN\MWSSRCAS.DLL
HKLM\Software\Classes\CLSID\{00A6FAF6-072E-44cf-8957-5838F569A31D}
HKCR\CLSID\{00A6FAF6-072E-44CF-8957-5838F569A31D}
HKCR\CLSID\{00A6FAF6-072E-44CF-8957-5838F569A31D}
HKCR\CLSID\{00A6FAF6-072E-44CF-8957-5838F569A31D}\InprocServer32
HKCR\CLSID\{00A6FAF6-072E-44CF-8957-5838F569A31D}\InprocServer32#ThreadingModel
HKCR\CLSID\{00A6FAF6-072E-44CF-8957-5838F569A31D}\Programmable
HKLM\Software\Classes\CLSID\{07B18EA1-A523-4961-B6BB-170DE4475CCA}
HKCR\CLSID\{07B18EA1-A523-4961-B6BB-170DE4475CCA}
HKCR\CLSID\{07B18EA1-A523-4961-B6BB-170DE4475CCA}
HKCR\CLSID\{07B18EA1-A523-4961-B6BB-170DE4475CCA}\InprocServer32
HKCR\CLSID\{07B18EA1-A523-4961-B6BB-170DE4475CCA}\InprocServer32#ThreadingModel
C:\PROGRAM FILES\MYWEBSEARCH\BAR\1.BIN\MWSBAR.DLL
HKLM\Software\Classes\CLSID\{07B18EA9-A523-4961-B6BB-170DE4475CCA}
HKCR\CLSID\{07B18EA9-A523-4961-B6BB-170DE4475CCA}
HKCR\CLSID\{07B18EA9-A523-4961-B6BB-170DE4475CCA}
HKCR\CLSID\{07B18EA9-A523-4961-B6BB-170DE4475CCA}\InprocServer32
HKCR\CLSID\{07B18EA9-A523-4961-B6BB-170DE4475CCA}\InprocServer32#ThreadingModel
HKLM\Software\Classes\CLSID\{07B18EAB-A523-4961-B6BB-170DE4475CCA}
HKCR\CLSID\{07B18EAB-A523-4961-B6BB-170DE4475CCA}
HKCR\CLSID\{07B18EAB-A523-4961-B6BB-170DE4475CCA}
HKCR\CLSID\{07B18EAB-A523-4961-B6BB-170DE4475CCA}\Control
HKCR\CLSID\{07B18EAB-A523-4961-B6BB-170DE4475CCA}\InprocServer32
HKCR\CLSID\{07B18EAB-A523-4961-B6BB-170DE4475CCA}\InprocServer32#ThreadingModel
HKCR\CLSID\{07B18EAB-A523-4961-B6BB-170DE4475CCA}\MiscStatus
HKCR\CLSID\{07B18EAB-A523-4961-B6BB-170DE4475CCA}\MiscStatus\1
HKCR\CLSID\{07B18EAB-A523-4961-B6BB-170DE4475CCA}\ProgID
HKCR\CLSID\{07B18EAB-A523-4961-B6BB-170DE4475CCA}\Programmable
HKCR\CLSID\{07B18EAB-A523-4961-B6BB-170DE4475CCA}\TypeLib
HKCR\CLSID\{07B18EAB-A523-4961-B6BB-170DE4475CCA}\Version
HKCR\CLSID\{07B18EAB-A523-4961-B6BB-170DE4475CCA}\VersionIndependentProgID
HKCR\MyWebSearchToolBar.SettingsPlugin.1
HKCR\MyWebSearchToolBar.SettingsPlugin.1\CLSID
HKCR\MyWebSearchToolBar.SettingsPlugin
HKCR\MyWebSearchToolBar.SettingsPlugin\CLSID
HKCR\MyWebSearchToolBar.SettingsPlugin\CurVer
HKCR\TypeLib\{07B18EA0-A523-4961-B6BB-170DE4475CCA}
HKCR\TypeLib\{07B18EA0-A523-4961-B6BB-170DE4475CCA}\1.0
HKCR\TypeLib\{07B18EA0-A523-4961-B6BB-170DE4475CCA}\1.0\0
HKCR\TypeLib\{07B18EA0-A523-4961-B6BB-170DE4475CCA}\1.0\0\win32
HKCR\TypeLib\{07B18EA0-A523-4961-B6BB-170DE4475CCA}\1.0\FLAGS
HKCR\TypeLib\{07B18EA0-A523-4961-B6BB-170DE4475CCA}\1.0\HELPDIR
HKLM\Software\Classes\CLSID\{53CED2D0-5E9A-4761-9005-648404E6F7E5}
HKCR\CLSID\{53CED2D0-5E9A-4761-9005-648404E6F7E5}
HKCR\CLSID\{53CED2D0-5E9A-4761-9005-648404E6F7E5}
HKCR\CLSID\{53CED2D0-5E9A-4761-9005-648404E6F7E5}\InprocServer32
HKCR\CLSID\{53CED2D0-5E9A-4761-9005-648404E6F7E5}\InprocServer32#ThreadingModel
HKCR\CLSID\{53CED2D0-5E9A-4761-9005-648404E6F7E5}\ProgID
HKCR\CLSID\{53CED2D0-5E9A-4761-9005-648404E6F7E5}\Programmable
HKCR\CLSID\{53CED2D0-5E9A-4761-9005-648404E6F7E5}\TypeLib
HKCR\CLSID\{53CED2D0-5E9A-4761-9005-648404E6F7E5}\VersionIndependentProgID
HKCR\MyWebSearchToolBar.ToolbarPlugin.1
HKCR\MyWebSearchToolBar.ToolbarPlugin.1\CLSID
HKCR\MyWebSearchToolBar.ToolbarPlugin
HKCR\MyWebSearchToolBar.ToolbarPlugin\CLSID
HKCR\MyWebSearchToolBar.ToolbarPlugin\CurVer
HKLM\Software\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{00A6FAF1-072E-44cf-8957-5838F569A31D}
HKLM\Software\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{07B18EA1-A523-4961-B6BB-170DE4475CCA}
HKU\S-1-5-21-515967899-57989841-839522115-1004\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{00A6FAF1-072E-44CF-8957-5838F569A31D}
HKU\S-1-5-21-515967899-57989841-839522115-1004\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{00A6FAF6-072E-44CF-8957-5838F569A31D}
HKU\S-1-5-21-515967899-57989841-839522115-1004\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{07B18EA1-A523-4961-B6BB-170DE4475CCA}
HKU\S-1-5-21-515967899-57989841-839522115-1004\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{07B18EA9-A523-4961-B6BB-170DE4475CCA}
HKU\S-1-5-21-515967899-57989841-839522115-1004\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{07B18EAB-A523-4961-B6BB-170DE4475CCA}
HKLM\Software\Microsoft\Internet Explorer\Toolbar#{07B18EA9-A523-4961-B6BB-170DE4475CCA}
HKU\S-1-5-21-515967899-57989841-839522115-1004\Software\Microsoft\Internet Explorer\Toolbar\WebBrowser#{07B18EA9-A523-4961-B6BB-170DE4475CCA}
HKU\S-1-5-21-515967899-57989841-839522115-1004\Software\Microsoft\Internet Explorer\URLSearchHooks#{00A6FAF6-072E-44cf-8957-5838F569A31D}
HKLM\System\ControlSet001\Services\MyWebSearchService
C:\PROGRA~1\MYWEBS~1\BAR\1.BIN\MWSSVC.EXE
HKLM\System\ControlSet001\Enum\Root\LEGACY_MyWebSearchService
HKLM\System\ControlSet003\Services\MyWebSearchService
HKLM\System\ControlSet003\Enum\Root\LEGACY_MyWebSearchService
HKLM\System\CurrentControlSet\Services\MyWebSearchService
HKLM\System\CurrentControlSet\Enum\Root\LEGACY_MyWebSearchService
C:\WINDOWS\Prefetch\M3SRCHMN.EXE-214A5037.pf

Adware.MyWebSearch/FunWebProducts
HKLM\Software\Classes\CLSID\{938AA51A-996C-4884-98CE-80DD16A5C9DA}
HKCR\CLSID\{938AA51A-996C-4884-98CE-80DD16A5C9DA}
HKCR\CLSID\{938AA51A-996C-4884-98CE-80DD16A5C9DA}
HKCR\CLSID\{938AA51A-996C-4884-98CE-80DD16A5C9DA}\InprocServer32
HKCR\CLSID\{938AA51A-996C-4884-98CE-80DD16A5C9DA}\InprocServer32#ThreadingModel
C:\PROGRAM FILES\MYWEBSEARCH\BAR\1.BIN\F3SCRCTR.DLL
HKLM\Software\Classes\CLSID\{9FF05104-B030-46FC-94B8-81276E4E27DF}
HKCR\CLSID\{9FF05104-B030-46FC-94B8-81276E4E27DF}
HKCR\CLSID\{9FF05104-B030-46FC-94B8-81276E4E27DF}
HKCR\CLSID\{9FF05104-B030-46FC-94B8-81276E4E27DF}\InprocServer32
HKCR\CLSID\{9FF05104-B030-46FC-94B8-81276E4E27DF}\InprocServer32#ThreadingModel
HKCR\CLSID\{9FF05104-B030-46FC-94B8-81276E4E27DF}\MiscStatus
HKCR\CLSID\{9FF05104-B030-46FC-94B8-81276E4E27DF}\MiscStatus\1
HKCR\CLSID\{9FF05104-B030-46FC-94B8-81276E4E27DF}\ProgID
HKCR\CLSID\{9FF05104-B030-46FC-94B8-81276E4E27DF}\Programmable
HKCR\CLSID\{9FF05104-B030-46FC-94B8-81276E4E27DF}\TypeLib
HKCR\CLSID\{9FF05104-B030-46FC-94B8-81276E4E27DF}\Version
HKCR\CLSID\{9FF05104-B030-46FC-94B8-81276E4E27DF}\VersionIndependentProgID
HKCR\ScreenSaverControl.ScreenSaverInstaller.1
HKCR\ScreenSaverControl.ScreenSaverInstaller.1\CLSID
HKCR\ScreenSaverControl.ScreenSaverInstaller
HKCR\ScreenSaverControl.ScreenSaverInstaller\CLSID
HKCR\ScreenSaverControl.ScreenSaverInstaller\CurVer
HKCR\TypeLib\{29D67D3C-509A-4544-903F-C8C1B8236554}
HKCR\TypeLib\{29D67D3C-509A-4544-903F-C8C1B8236554}\1.0
HKCR\TypeLib\{29D67D3C-509A-4544-903F-C8C1B8236554}\1.0\0
HKCR\TypeLib\{29D67D3C-509A-4544-903F-C8C1B8236554}\1.0\0\win32
HKCR\TypeLib\{29D67D3C-509A-4544-903F-C8C1B8236554}\1.0\FLAGS
HKCR\TypeLib\{29D67D3C-509A-4544-903F-C8C1B8236554}\1.0\HELPDIR
HKU\S-1-5-21-515967899-57989841-839522115-1004\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{3DC201FB-E9C9-499C-A11F-23C360D7C3F8}
HKCR\CLSID\{3DC201FB-E9C9-499C-A11F-23C360D7C3F8}
HKCR\CLSID\{3DC201FB-E9C9-499C-A11F-23C360D7C3F8}
HKCR\CLSID\{3DC201FB-E9C9-499C-A11F-23C360D7C3F8}\InprocServer32
HKCR\CLSID\{3DC201FB-E9C9-499C-A11F-23C360D7C3F8}\InprocServer32#ThreadingModel
HKCR\CLSID\{3DC201FB-E9C9-499C-A11F-23C360D7C3F8}\ProgID
HKCR\CLSID\{3DC201FB-E9C9-499C-A11F-23C360D7C3F8}\VersionIndependentProgID
HKCR\FunWebProducts.HTMLMenu.2
HKCR\FunWebProducts.HTMLMenu.2\CLSID
HKCR\FunWebProducts.HTMLMenu
HKCR\FunWebProducts.HTMLMenu\CLSID
HKCR\FunWebProducts.HTMLMenu\CurVer
C:\PROGRAM FILES\MYWEBSEARCH\BAR\1.BIN\F3HTMLMU.DLL
HKU\S-1-5-21-515967899-57989841-839522115-1004\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{9FF05104-B030-46FC-94B8-81276E4E27DF}
HKLM\SOFTWARE\Fun Web Products
HKLM\SOFTWARE\Fun Web Products#JpegConversionLib
HKLM\SOFTWARE\Fun Web Products#CacheDir
HKLM\SOFTWARE\Fun Web Products\MSNMessenger
HKLM\SOFTWARE\Fun Web Products\MSNMessenger#DLLFile
HKLM\SOFTWARE\Fun Web Products\MSNMessenger#DLLDir
HKLM\SOFTWARE\Fun Web Products\ScreenSaver
HKLM\SOFTWARE\Fun Web Products\ScreenSaver#ImagesDir
HKLM\SOFTWARE\Fun Web Products\Settings
HKLM\SOFTWARE\Fun Web Products\Settings\CursorManiaBtn
HKLM\SOFTWARE\Fun Web Products\Settings\CursorManiaBtn#LastHTMLMenuURL
HKLM\SOFTWARE\Fun Web Products\Settings\CursorManiaBtn#HTMLMenuRevision
HKLM\SOFTWARE\Fun Web Products\Settings\CursorManiaBtn#ETag
HKLM\SOFTWARE\Fun Web Products\Settings\Promos
HKLM\SOFTWARE\Fun Web Products\Settings\Promos#BuddyTextNone.numActive
HKLM\SOFTWARE\Fun Web Products\Settings\Promos#BuddyTextNone.0
HKLM\SOFTWARE\Fun Web Products\Settings\Promos#BuddyFreqNone
HKLM\SOFTWARE\Fun Web Products\Settings\Promos#BuddyTextUninstalled.numActive
HKLM\SOFTWARE\Fun Web Products\Settings\Promos#BuddyTextUninstalled.0
HKLM\SOFTWARE\Fun Web Products\Settings\Promos#BuddyFreqUninstalled
HKLM\SOFTWARE\Fun Web Products\Settings\Promos#MSN.numActive
HKLM\SOFTWARE\Fun Web Products\Settings\Promos#MSN.numActive2
HKLM\SOFTWARE\Fun Web Products\Settings\Promos#MSN.1
HKLM\SOFTWARE\Fun Web Products\Settings\Promos#MSN.2
HKLM\SOFTWARE\Fun Web Products\Settings\Promos#MSN.3
HKLM\SOFTWARE\Fun Web Products\Settings\Promos#MSN.4
HKLM\SOFTWARE\Fun Web Products\Settings\Promos#MSN.5
HKLM\SOFTWARE\Fun Web Products\Settings\Promos#MSN.6
HKLM\SOFTWARE\Fun Web Products\Settings\Promos#MSN.7
HKLM\SOFTWARE\Fun Web Products\Settings\Promos#MSN.8
HKLM\SOFTWARE\Fun Web Products\Settings\SmileyCentralBtn
HKLM\SOFTWARE\Fun Web Products\Settings\SmileyCentralBtn#HTMLMenuPosDeleted
HKLM\SOFTWARE\Fun Web Products\Settings\SmileyCentralBtn#LastHTMLMenuURL
HKLM\SOFTWARE\Fun Web Products\Settings\SmileyCentralBtn#HTMLMenuRevision
HKLM\SOFTWARE\Fun Web Products\Settings\SmileyCentralBtn#ETag
HKLM\SOFTWARE\Fun Web Products\Settings\SmileyCentralBtn#msimn.exe.pos
HKLM\SOFTWARE\Fun Web Products\Settings\WebfettiBtn
HKLM\SOFTWARE\Fun Web Products\Settings\WebfettiBtn#LastHTMLMenuURL
HKLM\SOFTWARE\Fun Web Products\Settings\WebfettiBtn#HTMLMenuRevision
HKLM\SOFTWARE\Fun Web Products\Settings\WebfettiBtn#ETag
HKU\S-1-5-21-515967899-57989841-839522115-1004\SOFTWARE\FunWebProducts
HKU\S-1-5-21-515967899-57989841-839522115-1004\SOFTWARE\MyWebSearch
HKLM\SOFTWARE\MyWebSearch
HKLM\SOFTWARE\MyWebSearch\bar
HKLM\SOFTWARE\MyWebSearch\bar#Maximized
HKLM\SOFTWARE\MyWebSearch\bar#Visible
HKLM\SOFTWARE\MyWebSearch\bar#UseFWB
HKLM\SOFTWARE\MyWebSearch\bar#pid
HKLM\SOFTWARE\MyWebSearch\bar#fwp
HKLM\SOFTWARE\MyWebSearch\bar#tiec
HKLM\SOFTWARE\MyWebSearch\bar#Dir
HKLM\SOFTWARE\MyWebSearch\bar#UninstallString
HKLM\SOFTWARE\MyWebSearch\bar#PluginPath
HKLM\SOFTWARE\MyWebSearch\bar#RegHookPath
HKLM\SOFTWARE\MyWebSearch\bar#Id
HKLM\SOFTWARE\MyWebSearch\bar#CurInstall
HKLM\SOFTWARE\MyWebSearch\bar#SettingsDir
HKLM\SOFTWARE\MyWebSearch\bar#sr
HKLM\SOFTWARE\MyWebSearch\bar#pl
HKLM\SOFTWARE\MyWebSearch\bar#CacheDir
HKLM\SOFTWARE\MyWebSearch\bar#ConfigRevision
HKLM\SOFTWARE\MyWebSearch\bar#ConfigRevisionURL
HKLM\SOFTWARE\MyWebSearch\bar#ConfigDateStamp
HKLM\SOFTWARE\MyWebSearch\bar#HTMLMenuRevision
HKLM\SOFTWARE\MyWebSearch\bar#sscSet
HKLM\SOFTWARE\MyWebSearch\bar#sscLabel
HKLM\SOFTWARE\MyWebSearch\bar#sscURL
HKLM\SOFTWARE\MyWebSearch\bar#AlertCount
HKLM\SOFTWARE\MyWebSearch\bar#AlertPeriod
HKLM\SOFTWARE\MyWebSearch\bar#AlertPausePeriod
HKLM\SOFTWARE\MyWebSearch\bar#NoThrottleAlert
HKLM\SOFTWARE\MyWebSearch\bar#Flags
HKLM\SOFTWARE\MyWebSearch\bar#HistoryDir
HKLM\SOFTWARE\MyWebSearch\bar#ConfigCustomButtons
HKLM\SOFTWARE\MyWebSearch\bar#LastChange
HKLM\SOFTWARE\MyWebSearch\bar#NextConfigRequest
HKLM\SOFTWARE\MyWebSearch\bar#LastConfigRequest
HKLM\SOFTWARE\MyWebSearch\bar#AutocompleteURL
HKLM\SOFTWARE\MyWebSearch\bar\downloaded
HKLM\SOFTWARE\MyWebSearch\bar\downloaded#SetupsDir
HKLM\SOFTWARE\MyWebSearch\MWSOEMON
HKLM\SOFTWARE\MyWebSearch\MWSOEMON#Version
HKLM\SOFTWARE\MyWebSearch\MWSOEPLG
HKLM\SOFTWARE\MyWebSearch\MWSOEPLG#Version
HKLM\SOFTWARE\MyWebSearch\MWSOEPLG#Path
HKLM\SOFTWARE\MyWebSearch\MWSOEPLG#StandardSmileyDir.AIM
HKLM\SOFTWARE\MyWebSearch\MWSOEPLG\Promo
HKLM\SOFTWARE\MyWebSearch\MWSOEPLG\Promo#ICQT.numActive2
HKLM\SOFTWARE\MyWebSearch\MWSOEPLG\Promo#ICQT.0
HKLM\SOFTWARE\MyWebSearch\MWSOEPLG\Promo#ICQT.1
HKLM\SOFTWARE\MyWebSearch\MWSOEPLG\Promo#ICQT.2
HKLM\SOFTWARE\MyWebSearch\MWSOEPLG\Promo#ICQT.3
HKLM\SOFTWARE\MyWebSearch\MWSOEPLG\Promo#ICQT.4
HKLM\SOFTWARE\MyWebSearch\MWSOEPLG\Promo#ICQT.5
HKLM\SOFTWARE\MyWebSearch\MWSOEPLG\Promo#ICQT.6
HKLM\SOFTWARE\MyWebSearch\MWSOEPLG\Promo#ICQT.7
HKLM\SOFTWARE\MyWebSearch\MWSOEPLG\Promo#ICQT.8
HKLM\SOFTWARE\MyWebSearch\MWSOEPLG\Promo#ICQT.9
HKLM\SOFTWARE\MyWebSearch\MWSOEPLG\Promo#Yahoo.numActive
HKLM\SOFTWARE\MyWebSearch\MWSOEPLG\Promo#Yahoo.numActive2
HKLM\SOFTWARE\MyWebSearch\MWSOEPLG\Promo#Yahoo.0.old
HKLM\SOFTWARE\MyWebSearch\MWSOEPLG\Promo#Yahoo.1.old
HKLM\SOFTWARE\MyWebSearch\MWSOEPLG\Promo#Yahoo.2.old
HKLM\SOFTWARE\MyWebSearch\MWSOEPLG\Promo#Yahoo.3.old
HKLM\SOFTWARE\MyWebSearch\MWSOEPLG\Promo#Yahoo.4.old
HKLM\SOFTWARE\MyWebSearch\MWSOEPLG\Promo#Yahoo.5.old
HKLM\SOFTWARE\MyWebSearch\MWSOEPLG\Promo#Yahoo.6.old
HKLM\SOFTWARE\MyWebSearch\MWSOEPLG\Promo#Yahoo.7.old
HKLM\SOFTWARE\MyWebSearch\MWSOEPLG\Promo#Yahoo.8.old
HKLM\SOFTWARE\MyWebSearch\MWSOEPLG\Promo#Yahoo.9.old
HKLM\SOFTWARE\MyWebSearch\MWSOEPLG\Promo#Yahoo.10.old
HKLM\SOFTWARE\MyWebSearch\MWSOEPLG\Promo#Yahoo.11.old
HKLM\SOFTWARE\MyWebSearch\MWSOEPLG\Promo#Yahoo.12.old
HKLM\SOFTWARE\MyWebSearch\MWSOEPLG\Promo#Yahoo.13.old
HKLM\SOFTWARE\MyWebSearch\MWSOEPLG\Promo#AIM.numActive
HKLM\SOFTWARE\MyWebSearch\MWSOEPLG\Promo#AIM.numActive2
HKLM\SOFTWARE\MyWebSearch\MWSOEPLG\Promo#AIM.0.old
HKLM\SOFTWARE\MyWebSearch\MWSOEPLG\Promo#AIM.1.old
HKLM\SOFTWARE\MyWebSearch\MWSOEPLG\Promo#AIM.2.old
HKLM\SOFTWARE\MyWebSearch\MWSOEPLG\Promo#AIM.3.old
HKLM\SOFTWARE\MyWebSearch\MWSOEPLG\Promo#AIM.4.old
HKLM\SOFTWARE\MyWebSearch\MWSOEPLG\Promo#AIM.5.old
HKLM\SOFTWARE\MyWebSearch\MWSOEPLG\Promo#AIM.6.old
HKLM\SOFTWARE\MyWebSearch\MWSOEPLG\Promo#AIM.7.old
HKLM\SOFTWARE\MyWebSearch\MWSOEPLG\Promo#AIM.8
HKLM\SOFTWARE\MyWebSearch\MWSOEPLG\Promo#AIMT.numActive2
HKLM\SOFTWARE\MyWebSearch\MWSOEPLG\Promo#AIMT.0
HKLM\SOFTWARE\MyWebSearch\MWSOEPLG\Promo#AIMT.1
HKLM\SOFTWARE\MyWebSearch\MWSOEPLG\Promo#AIMT.2
HKLM\SOFTWARE\MyWebSearch\MWSOEPLG\Promo#AIMT.3
HKLM\SOFTWARE\MyWebSearch\MWSOEPLG\Promo#AIMT.4
HKLM\SOFTWARE\MyWebSearch\MWSOEPLG\Promo#AIMT.5
HKLM\SOFTWARE\MyWebSearch\MWSOEPLG\Promo#AIMT.6
HKLM\SOFTWARE\MyWebSearch\MWSOEPLG\Promo#AIMT.7
HKLM\SOFTWARE\MyWebSearch\MWSOEPLG\Promo#AIMT.8
HKLM\SOFTWARE\MyWebSearch\MWSOEPLG\Promo#AIMT.9
HKLM\SOFTWARE\MyWebSearch\MWSOEPLG\Promo#GoogleTalkHTML.numActive2
HKLM\SOFTWARE\MyWebSearch\MWSOEPLG\Promo#GoogleTalkHTML.0
HKLM\SOFTWARE\MyWebSearch\MWSOEPLG\Promo#GoogleTalkHTML.1
HKLM\SOFTWARE\MyWebSearch\MWSOEPLG\Promo#GoogleTalkHTML.2
HKLM\SOFTWARE\MyWebSearch\MWSOEPLG\Promo#GoogleTalkHTML.3
HKLM\SOFTWARE\MyWebSearch\MWSOEPLG\Promo#GoogleTalkHTML.4
HKLM\SOFTWARE\MyWebSearch\MWSOEPLG\Promo#GoogleTalkHTML.5
HKLM\SOFTWARE\MyWebSearch\MWSOEPLG\Promo#GoogleTalkHTML.6
HKLM\SOFTWARE\MyWebSearch\MWSOEPLG\Promo#GoogleTalkHTML.7
HKLM\SOFTWARE\MyWebSearch\MWSOEPLG\Promo#AIM.9
HKLM\SOFTWARE\MyWebSearch\MWSOEPLG\Promo#AIM.10
HKLM\SOFTWARE\MyWebSearch\MWSOEPLG\Promo#AIMT.10
HKLM\SOFTWARE\MyWebSearch\MWSOEPLG\Promo#AIMT.11
HKLM\SOFTWARE\MyWebSearch\OEHosts
HKLM\SOFTWARE\MyWebSearch\OEHosts#Windows11
HKLM\SOFTWARE\MyWebSearch\OEHosts#Windows2
HKLM\SOFTWARE\MyWebSearch\OEHosts#Windows3
HKLM\SOFTWARE\MyWebSearch\OEHosts#Windows4
HKLM\SOFTWARE\MyWebSearch\OEHosts#Windows5
HKLM\SOFTWARE\MyWebSearch\OEHosts#Windows6
HKLM\SOFTWARE\MyWebSearch\OEHosts#Windows7
HKLM\SOFTWARE\MyWebSearch\OEHosts#Windows8
HKLM\SOFTWARE\MyWebSearch\OEHosts#Windows9
HKLM\SOFTWARE\MyWebSearch\OEHosts#Windows10
HKLM\SOFTWARE\MyWebSearch\SearchAssistant
HKLM\SOFTWARE\MyWebSearch\SearchAssistant#pid
HKLM\SOFTWARE\MyWebSearch\SearchAssistant#fwp
HKLM\SOFTWARE\MyWebSearch\SearchAssistant#esh
HKLM\SOFTWARE\MyWebSearch\SearchAssistant#lsp
HKLM\SOFTWARE\MyWebSearch\SearchAssistant#LastRequest
HKLM\SOFTWARE\MyWebSearch\SearchAssistant#NextRequest
HKLM\SOFTWARE\MyWebSearch\SearchAssistant#ie8h
HKLM\SOFTWARE\MyWebSearch\SearchAssistant#ABS
HKLM\SOFTWARE\MyWebSearch\SearchAssistant#DES
HKLM\SOFTWARE\MyWebSearch\SkinTools
HKLM\SOFTWARE\MyWebSearch\SkinTools#PlayerPath
HKCR\FunWebProducts.DataControl
HKCR\FunWebProducts.DataControl\CLSID
HKCR\FunWebProducts.DataControl\CurVer
HKCR\FunWebProducts.DataControl.1
HKCR\FunWebProducts.DataControl.1\CLSID
HKCR\FunWebProducts.HistoryKillerScheduler
HKCR\FunWebProducts.HistoryKillerScheduler\CLSID
HKCR\FunWebProducts.HistoryKillerScheduler\CurVer
HKCR\FunWebProducts.HistoryKillerScheduler.1
HKCR\FunWebProducts.HistoryKillerScheduler.1\CLSID
HKCR\FunWebProducts.HistorySwatterControlBar
HKCR\FunWebProducts.HistorySwatterControlBar\CLSID
HKCR\FunWebProducts.HistorySwatterControlBar\CurVer
HKCR\FunWebProducts.HistorySwatterControlBar.1
HKCR\FunWebProducts.HistorySwatterControlBar.1\CLSID
HKCR\FunWebProducts.HTMLMenu.1
HKCR\FunWebProducts.HTMLMenu.1\CLSID
HKCR\FunWebProducts.IECookiesManager
HKCR\FunWebProducts.IECookiesManager\CLSID
HKCR\FunWebProducts.IECookiesManager\CurVer
HKCR\FunWebProducts.IECookiesManager.1
HKCR\FunWebProducts.IECookiesManager.1\CLSID
HKCR\FunWebProducts.KillerObjManager
HKCR\FunWebProducts.KillerObjManager\CLSID
HKCR\FunWebProducts.KillerObjManager\CurVer
HKCR\FunWebProducts.KillerObjManager.1
HKCR\FunWebProducts.KillerObjManager.1\CLSID
HKCR\FunWebProducts.PopSwatterBarButton
HKCR\FunWebProducts.PopSwatterBarButton\CLSID
HKCR\FunWebProducts.PopSwatterBarButton\CurVer
HKCR\FunWebProducts.PopSwatterBarButton.1
HKCR\FunWebProducts.PopSwatterBarButton.1\CLSID
HKCR\FunWebProducts.PopSwatterSettingsControl
HKCR\FunWebProducts.PopSwatterSettingsControl\CLSID
HKCR\FunWebProducts.PopSwatterSettingsControl\CurVer
HKCR\FunWebProducts.PopSwatterSettingsControl.1
HKCR\FunWebProducts.PopSwatterSettingsControl.1\CLSID
HKCR\MyWebSearch.ChatSessionPlugin
HKCR\MyWebSearch.ChatSessionPlugin\CLSID
HKCR\MyWebSearch.ChatSessionPlugin\CurVer
HKCR\MyWebSearch.ChatSessionPlugin.1
HKCR\MyWebSearch.ChatSessionPlugin.1\CLSID
HKCR\MyWebSearch.HTMLPanel
HKCR\MyWebSearch.HTMLPanel\CLSID
HKCR\MyWebSearch.HTMLPanel\CurVer
HKCR\MyWebSearch.HTMLPanel.1
HKCR\MyWebSearch.HTMLPanel.1\CLSID
HKCR\MyWebSearch.OutlookAddin
HKCR\MyWebSearch.OutlookAddin\CLSID
HKCR\MyWebSearch.OutlookAddin\CurVer
HKCR\MyWebSearch.OutlookAddin.1
HKCR\MyWebSearch.OutlookAddin.1\CLSID
HKCR\MyWebSearch.PseudoTransparentPlugin
HKCR\MyWebSearch.PseudoTransparentPlugin\CLSID
HKCR\MyWebSearch.PseudoTransparentPlugin\CurVer
HKCR\MyWebSearch.PseudoTransparentPlugin.1
HKCR\MyWebSearch.PseudoTransparentPlugin.1\CLSID
HKCR\CLSID\{0F8ECF4F-3646-4C3A-8881-8E138FFCAF70}
HKCR\CLSID\{0F8ECF4F-3646-4C3A-8881-8E138FFCAF70}\InprocServer32
HKCR\CLSID\{0F8ECF4F-3646-4C3A-8881-8E138FFCAF70}\InprocServer32#ThreadingModel
HKCR\CLSID\{0F8ECF4F-3646-4C3A-8881-8E138FFCAF70}\ProgID
HKCR\CLSID\{0F8ECF4F-3646-4C3A-8881-8E138FFCAF70}\Programmable
HKCR\CLSID\{0F8ECF4F-3646-4C3A-8881-8E138FFCAF70}\TypeLib
HKCR\CLSID\{0F8ECF4F-3646-4C3A-8881-8E138FFCAF70}\VersionIndependentProgID
HKCR\CLSID\{147A976F-EEE1-4377-8EA7-4716E4CDD239}
HKCR\CLSID\{147A976F-EEE1-4377-8EA7-4716E4CDD239}\TreatAs
HKCR\CLSID\{1E0DE227-5CE4-4ea3-AB0C-8B03E1AA76BC}
HKCR\CLSID\{1E0DE227-5CE4-4ea3-AB0C-8B03E1AA76BC}\Implemented Categories
HKCR\CLSID\{1E0DE227-5CE4-4ea3-AB0C-8B03E1AA76BC}\Implemented Categories\{00021493-0000-0000-C000-000000000046}
HKCR\CLSID\{1E0DE227-5CE4-4ea3-AB0C-8B03E1AA76BC}\InprocServer32
HKCR\CLSID\{1E0DE227-5CE4-4ea3-AB0C-8B03E1AA76BC}\InprocServer32#ThreadingModel
HKCR\CLSID\{1E0DE227-5CE4-4ea3-AB0C-8B03E1AA76BC}\Instance
HKCR\CLSID\{1E0DE227-5CE4-4ea3-AB0C-8B03E1AA76BC}\Instance#CLSID
HKCR\CLSID\{1E0DE227-5CE4-4ea3-AB0C-8B03E1AA76BC}\Instance\InitPropertyBag
HKCR\CLSID\{1E0DE227-5CE4-4ea3-AB0C-8B03E1AA76BC}\Instance\InitPropertyBag#Url
HKCR\CLSID\{25560540-9571-4D7B-9389-0F166788785A}
HKCR\CLSID\{25560540-9571-4D7B-9389-0F166788785A}\Control
HKCR\CLSID\{25560540-9571-4D7B-9389-0F166788785A}\InprocServer32
HKCR\CLSID\{25560540-9571-4D7B-9389-0F166788785A}\InprocServer32#ThreadingModel
HKCR\CLSID\{25560540-9571-4D7B-9389-0F166788785A}\MiscStatus
HKCR\CLSID\{25560540-9571-4D7B-9389-0F166788785A}\MiscStatus\1
HKCR\CLSID\{25560540-9571-4D7B-9389-0F166788785A}\ProgID
HKCR\CLSID\{25560540-9571-4D7B-9389-0F166788785A}\Programmable
HKCR\CLSID\{25560540-9571-4D7B-9389-0F166788785A}\TypeLib
HKCR\CLSID\{25560540-9571-4D7B-9389-0F166788785A}\Version
HKCR\CLSID\{25560540-9571-4D7B-9389-0F166788785A}\VersionIndependentProgID
HKCR\CLSID\{3E720452-B472-4954-B7AA-33069EB53906}
HKCR\CLSID\{3E720452-B472-4954-B7AA-33069EB53906}\Control
HKCR\CLSID\{3E720452-B472-4954-B7AA-33069EB53906}\InprocServer32
HKCR\CLSID\{3E720452-B472-4954-B7AA-33069EB53906}\InprocServer32#ThreadingModel
HKCR\CLSID\{3E720452-B472-4954-B7AA-33069EB53906}\MiscStatus
HKCR\CLSID\{3E720452-B472-4954-B7AA-33069EB53906}\MiscStatus\1
HKCR\CLSID\{3E720452-B472-4954-B7AA-33069EB53906}\ProgID
HKCR\CLSID\{3E720452-B472-4954-B7AA-33069EB53906}\Programmable
HKCR\CLSID\{3E720452-B472-4954-B7AA-33069EB53906}\TypeLib
HKCR\CLSID\{3E720452-B472-4954-B7AA-33069EB53906}\Version
HKCR\CLSID\{3E720452-B472-4954-B7AA-33069EB53906}\VersionIndependentProgID
HKCR\CLSID\{63D0ED2C-B45B-4458-8B3B-60C69BBBD83C}
HKCR\CLSID\{63D0ED2C-B45B-4458-8B3B-60C69BBBD83C}\InprocServer32
HKCR\CLSID\{63D0ED2C-B45B-4458-8B3B-60C69BBBD83C}\InprocServer32#ThreadingModel
HKCR\CLSID\{63D0ED2C-B45B-4458-8B3B-60C69BBBD83C}\ProgID
HKCR\CLSID\{63D0ED2C-B45B-4458-8B3B-60C69BBBD83C}\Programmable
HKCR\CLSID\{63D0ED2C-B45B-4458-8B3B-60C69BBBD83C}\TypeLib
HKCR\CLSID\{63D0ED2C-B45B-4458-8B3B-60C69BBBD83C}\VersionIndependentProgID
HKCR\CLSID\{7473D292-B7BB-4f24-AE82-7E2CE94BB6A9}
HKCR\CLSID\{7473D292-B7BB-4f24-AE82-7E2CE94BB6A9}\Control
HKCR\CLSID\{7473D292-B7BB-4f24-AE82-7E2CE94BB6A9}\InprocServer32
HKCR\CLSID\{7473D292-B7BB-4f24-AE82-7E2CE94BB6A9}\InprocServer32#ThreadingModel
HKCR\CLSID\{7473D292-B7BB-4f24-AE82-7E2CE94BB6A9}\MiscStatus
HKCR\CLSID\{7473D292-B7BB-4f24-AE82-7E2CE94BB6A9}\MiscStatus\1
HKCR\CLSID\{7473D292-B7BB-4f24-AE82-7E2CE94BB6A9}\Programmable
HKCR\CLSID\{7473D292-B7BB-4f24-AE82-7E2CE94BB6A9}\TypeLib
HKCR\CLSID\{7473D292-B7BB-4f24-AE82-7E2CE94BB6A9}\Version
HKCR\CLSID\{7473D294-B7BB-4f24-AE82-7E2CE94BB6A9}
HKCR\CLSID\{7473D294-B7BB-4f24-AE82-7E2CE94BB6A9}\Control
HKCR\CLSID\{7473D294-B7BB-4f24-AE82-7E2CE94BB6A9}\InprocServer32
HKCR\CLSID\{7473D294-B7BB-4f24-AE82-7E2CE94BB6A9}\InprocServer32#ThreadingModel
HKCR\CLSID\{7473D294-B7BB-4f24-AE82-7E2CE94BB6A9}\MiscStatus
HKCR\CLSID\{7473D294-B7BB-4f24-AE82-7E2CE94BB6A9}\MiscStatus\1
HKCR\CLSID\{7473D294-B7BB-4f24-AE82-7E2CE94BB6A9}\ProgID
HKCR\CLSID\{7473D294-B7BB-4f24-AE82-7E2CE94BB6A9}\Programmable
HKCR\CLSID\{7473D294-B7BB-4f24-AE82-7E2CE94BB6A9}\TypeLib
HKCR\CLSID\{7473D294-B7BB-4f24-AE82-7E2CE94BB6A9}\Version
HKCR\CLSID\{7473D294-B7BB-4f24-AE82-7E2CE94BB6A9}\VersionIndependentProgID
HKCR\CLSID\{7473D296-B7BB-4f24-AE82-7E2CE94BB6A9}
HKCR\CLSID\{7473D296-B7BB-4f24-AE82-7E2CE94BB6A9}\Control
HKCR\CLSID\{7473D296-B7BB-4f24-AE82-7E2CE94BB6A9}\InprocServer32
HKCR\CLSID\{7473D296-B7BB-4f24-AE82-7E2CE94BB6A9}\InprocServer32#ThreadingModel
HKCR\CLSID\{7473D296-B7BB-4f24-AE82-7E2CE94BB6A9}\MiscStatus
HKCR\CLSID\{7473D296-B7BB-4f24-AE82-7E2CE94BB6A9}\MiscStatus\1
HKCR\CLSID\{7473D296-B7BB-4f24-AE82-7E2CE94BB6A9}\Programmable
HKCR\CLSID\{7473D296-B7BB-4f24-AE82-7E2CE94BB6A9}\TypeLib
HKCR\CLSID\{7473D296-B7BB-4f24-AE82-7E2CE94BB6A9}\Version
HKCR\CLSID\{84DA4FDF-A1CF-4195-8688-3E961F505983}
HKCR\CLSID\{84DA4FDF-A1CF-4195-8688-3E961F505983}\InprocServer32
HKCR\CLSID\{84DA4FDF-A1CF-4195-8688-3E961F505983}\InprocServer32#ThreadingModel
HKCR\CLSID\{8E6F1832-9607-4440-8530-13BE7C4B1D14}
HKCR\CLSID\{8E6F1832-9607-4440-8530-13BE7C4B1D14}\InprocServer32
HKCR\CLSID\{8E6F1832-9607-4440-8530-13BE7C4B1D14}\InprocServer32#ThreadingModel
HKCR\CLSID\{8E6F1832-9607-4440-8530-13BE7C4B1D14}\ProgID
HKCR\CLSID\{8E6F1832-9607-4440-8530-13BE7C4B1D14}\Programmable
HKCR\CLSID\{8E6F1832-9607-4440-8530-13BE7C4B1D14}\TypeLib
HKCR\CLSID\{8E6F1832-9607-4440-8530-13BE7C4B1D14}\VersionIndependentProgID
HKCR\CLSID\{98D9753D-D73B-42D5-8C85-4469CDA897AB}
HKCR\CLSID\{98D9753D-D73B-42D5-8C85-4469CDA897AB}\InprocServer32
HKCR\CLSID\{98D9753D-D73B-42D5-8C85-4469CDA897AB}\InprocServer32#ThreadingModel
HKCR\CLSID\{98D9753D-D73B-42D5-8C85-4469CDA897AB}\ProgID
HKCR\CLSID\{98D9753D-D73B-42D5-8C85-4469CDA897AB}\VersionIndependentProgID
HKCR\CLSID\{A4730EBE-43A6-443e-9776-36915D323AD3}
HKCR\CLSID\{A4730EBE-43A6-443e-9776-36915D323AD3}\TreatAs
HKCR\CLSID\{A9571378-68A1-443d-B082-284F960C6D17}
HKCR\CLSID\{A9571378-68A1-443d-B082-284F960C6D17}\InprocServer32
HKCR\CLSID\{A9571378-68A1-443d-B082-284F960C6D17}\InprocServer32#ThreadingModel
HKCR\CLSID\{A9571378-68A1-443d-B082-284F960C6D17}\Programmable
HKCR\CLSID\{A9571378-68A1-443d-B082-284F960C6D17}\TypeLib
HKCR\CLSID\{ADB01E81-3C79-4272-A0F1-7B2BE7A782DC}
HKCR\CLSID\{ADB01E81-3C79-4272-A0F1-7B2BE7A782DC}\InprocServer32
HKCR\CLSID\{ADB01E81-3C79-4272-A0F1-7B2BE7A782DC}\InprocServer32#ThreadingModel
HKCR\CLSID\{ADB01E81-3C79-4272-A0F1-7B2BE7A782DC}\ProgID
HKCR\CLSID\{ADB01E81-3C79-4272-A0F1-7B2BE7A782DC}\Programmable
HKCR\CLSID\{ADB01E81-3C79-4272-A0F1-7B2BE7A782DC}\VersionIndependentProgID
HKCR\CLSID\{B813095C-81C0-4E40-AA14-67520372B987}
HKCR\CLSID\{B813095C-81C0-4E40-AA14-67520372B987}\InprocServer32
HKCR\CLSID\{B813095C-81C0-4E40-AA14-67520372B987}\InprocServer32#ThreadingModel
HKCR\CLSID\{B813095C-81C0-4E40-AA14-67520372B987}\MiscStatus
HKCR\CLSID\{B813095C-81C0-4E40-AA14-67520372B987}\MiscStatus\1
HKCR\CLSID\{B813095C-81C0-4E40-AA14-67520372B987}\ProgID
HKCR\CLSID\{B813095C-81C0-4E40-AA14-67520372B987}\Programmable
HKCR\CLSID\{B813095C-81C0-4E40-AA14-67520372B987}\TypeLib
HKCR\CLSID\{B813095C-81C0-4E40-AA14-67520372B987}\Version
HKCR\CLSID\{B813095C-81C0-4E40-AA14-67520372B987}\VersionIndependentProgID
HKCR\CLSID\{C9D7BE3E-141A-4C85-8CD6-32461F3DF2C7}
HKCR\CLSID\{C9D7BE3E-141A-4C85-8CD6-32461F3DF2C7}\InprocServer32
HKCR\CLSID\{C9D7BE3E-141A-4C85-8CD6-32461F3DF2C7}\InprocServer32#ThreadingModel
HKCR\CLSID\{C9D7BE3E-141A-4C85-8CD6-32461F3DF2C7}\MiscStatus
HKCR\CLSID\{C9D7BE3E-141A-4C85-8CD6-32461F3DF2C7}\MiscStatus\1
HKCR\CLSID\{C9D7BE3E-141A-4C85-8CD6-32461F3DF2C7}\ProgID
HKCR\CLSID\{C9D7BE3E-141A-4C85-8CD6-32461F3DF2C7}\Programmable
HKCR\CLSID\{C9D7BE3E-141A-4C85-8CD6-32461F3DF2C7}\TypeLib
HKCR\CLSID\{C9D7BE3E-141A-4C85-8CD6-32461F3DF2C7}\Version
HKCR\CLSID\{C9D7BE3E-141A-4C85-8CD6-32461F3DF2C7}\VersionIndependentProgID
HKCR\CLSID\{CFF4CE82-3AA2-451F-9B77-7165605FB835}
HKCR\CLSID\{CFF4CE82-3AA2-451F-9B77-7165605FB835}\InprocServer32
HKCR\CLSID\{CFF4CE82-3AA2-451F-9B77-7165605FB835}\InprocServer32#ThreadingModel
HKCR\CLSID\{CFF4CE82-3AA2-451F-9B77-7165605FB835}\ProgID
HKCR\CLSID\{CFF4CE82-3AA2-451F-9B77-7165605FB835}\Programmable
HKCR\CLSID\{CFF4CE82-3AA2-451F-9B77-7165605FB835}\TypeLib
HKCR\CLSID\{CFF4CE82-3AA2-451F-9B77-7165605FB835}\VersionIndependentProgID
HKCR\CLSID\{D9FFFB27-D62A-4D64-8CEC-1FF006528805}
HKCR\CLSID\{D9FFFB27-D62A-4D64-8CEC-1FF006528805}\InprocServer32
HKCR\CLSID\{D9FFFB27-D62A-4D64-8CEC-1FF006528805}\InprocServer32#ThreadingModel
HKCR\CLSID\{D9FFFB27-D62A-4D64-8CEC-1FF006528805}\Programmable
HKCR\CLSID\{D9FFFB27-D62A-4D64-8CEC-1FF006528805}\TypeLib
HKCR\CLSID\{E79DFBCA-5697-4fbd-94E5-5B2A9C7C1612}
HKCR\CLSID\{E79DFBCA-5697-4fbd-94E5-5B2A9C7C1612}\Control
HKCR\CLSID\{E79DFBCA-5697-4fbd-94E5-5B2A9C7C1612}\InprocServer32
HKCR\CLSID\{E79DFBCA-5697-4fbd-94E5-5B2A9C7C1612}\InprocServer32#ThreadingModel
HKCR\CLSID\{E79DFBCA-5697-4fbd-94E5-5B2A9C7C1612}\MiscStatus
HKCR\CLSID\{E79DFBCA-5697-4fbd-94E5-5B2A9C7C1612}\MiscStatus\1
HKCR\CLSID\{E79DFBCA-5697-4fbd-94E5-5B2A9C7C1612}\ProgID
HKCR\CLSID\{E79DFBCA-5697-4fbd-94E5-5B2A9C7C1612}\Programmable
HKCR\CLSID\{E79DFBCA-5697-4fbd-94E5-5B2A9C7C1612}\TypeLib
HKCR\CLSID\{E79DFBCA-5697-4fbd-94E5-5B2A9C7C1612}\Version
HKCR\CLSID\{E79DFBCA-5697-4fbd-94E5-5B2A9C7C1612}\VersionIndependentProgID
HKCR\TypeLib\{0D26BC71-A633-4E71-AD31-EADC3A1B6A3A}
HKCR\TypeLib\{0D26BC71-A633-4E71-AD31-EADC3A1B6A3A}\1.0
HKCR\TypeLib\{0D26BC71-A633-4E71-AD31-EADC3A1B6A3A}\1.0\0
HKCR\TypeLib\{0D26BC71-A633-4E71-AD31-EADC3A1B6A3A}\1.0\0\win32
HKCR\TypeLib\{0D26BC71-A633-4E71-AD31-EADC3A1B6A3A}\1.0\FLAGS
HKCR\TypeLib\{0D26BC71-A633-4E71-AD31-EADC3A1B6A3A}\1.0\HELPDIR
HKCR\TypeLib\{3E720450-B472-4954-B7AA-33069EB53906}
HKCR\TypeLib\{3E720450-B472-4954-B7AA-33069EB53906}\1.0
HKCR\TypeLib\{3E720450-B472-4954-B7AA-33069EB53906}\1.0\0
HKCR\TypeLib\{3E720450-B472-4954-B7AA-33069EB53906}\1.0\0\win32
HKCR\TypeLib\{3E720450-B472-4954-B7AA-33069EB53906}\1.0\FLAGS
HKCR\TypeLib\{3E720450-B472-4954-B7AA-33069EB53906}\1.0\HELPDIR
HKCR\TypeLib\{7473D290-B7BB-4F24-AE82-7E2CE94BB6A9}
HKCR\TypeLib\{7473D290-B7BB-4F24-AE82-7E2CE94BB6A9}\1.0
HKCR\TypeLib\{7473D290-B7BB-4F24-AE82-7E2CE94BB6A9}\1.0\0
HKCR\TypeLib\{7473D290-B7BB-4F24-AE82-7E2CE94BB6A9}\1.0\0\win32
HKCR\TypeLib\{7473D290-B7BB-4F24-AE82-7E2CE94BB6A9}\1.0\FLAGS
HKCR\TypeLib\{7473D290-B7BB-4F24-AE82-7E2CE94BB6A9}\1.0\HELPDIR
HKCR\TypeLib\{8CA01F0E-987C-49C3-B852-2F1AC4A7094C}
HKCR\TypeLib\{8CA01F0E-987C-49C3-B852-2F1AC4A7094C}\1.0
HKCR\TypeLib\{8CA01F0E-987C-49C3-B852-2F1AC4A7094C}\1.0\0
HKCR\TypeLib\{8CA01F0E-987C-49C3-B852-2F1AC4A7094C}\1.0\0\win32
HKCR\TypeLib\{8CA01F0E-987C-49C3-B852-2F1AC4A7094C}\1.0\FLAGS
HKCR\TypeLib\{8CA01F0E-987C-49C3-B852-2F1AC4A7094C}\1.0\HELPDIR
HKCR\TypeLib\{8E6F1830-9607-4440-8530-13BE7C4B1D14}
HKCR\TypeLib\{8E6F1830-9607-4440-8530-13BE7C4B1D14}\1.0
HKCR\TypeLib\{8E6F1830-9607-4440-8530-13BE7C4B1D14}\1.0\0
HKCR\TypeLib\{8E6F1830-9607-4440-8530-13BE7C4B1D14}\1.0\0\win32
HKCR\TypeLib\{8E6F1830-9607-4440-8530-13BE7C4B1D14}\1.0\FLAGS
HKCR\TypeLib\{8E6F1830-9607-4440-8530-13BE7C4B1D14}\1.0\HELPDIR
HKCR\TypeLib\{C8CECDE3-1AE1-4C4A-AD82-6D5B00212144}
HKCR\TypeLib\{C8CECDE3-1AE1-4C4A-AD82-6D5B00212144}\1.0
HKCR\TypeLib\{C8CECDE3-1AE1-4C4A-AD82-6D5B00212144}\1.0\0
HKCR\TypeLib\{C8CECDE3-1AE1-4C4A-AD82-6D5B00212144}\1.0\0\win32
HKCR\TypeLib\{C8CECDE3-1AE1-4C4A-AD82-6D5B00212144}\1.0\FLAGS
HKCR\TypeLib\{C8CECDE3-1AE1-4C4A-AD82-6D5B00212144}\1.0\HELPDIR
HKCR\TypeLib\{D518921A-4A03-425E-9873-B9A71756821E}
HKCR\TypeLib\{D518921A-4A03-425E-9873-B9A71756821E}\1.0
HKCR\TypeLib\{D518921A-4A03-425E-9873-B9A71756821E}\1.0\0
HKCR\TypeLib\{D518921A-4A03-425E-9873-B9A71756821E}\1.0\0\win32
HKCR\TypeLib\{D518921A-4A03-425E-9873-B9A71756821E}\1.0\FLAGS
HKCR\TypeLib\{D518921A-4A03-425E-9873-B9A71756821E}\1.0\HELPDIR
HKCR\TypeLib\{E47CAEE0-DEEA-464A-9326-3F2801535A4D}
HKCR\TypeLib\{E47CAEE0-DEEA-464A-9326-3F2801535A4D}\1.0
HKCR\TypeLib\{E47CAEE0-DEEA-464A-9326-3F2801535A4D}\1.0\0
HKCR\TypeLib\{E47CAEE0-DEEA-464A-9326-3F2801535A4D}\1.0\0\win32
HKCR\TypeLib\{E47CAEE0-DEEA-464A-9326-3F2801535A4D}\1.0\FLAGS
HKCR\TypeLib\{E47CAEE0-DEEA-464A-9326-3F2801535A4D}\1.0\HELPDIR
HKCR\TypeLib\{E79DFBC0-5697-4FBD-94E5-5B2A9C7C1612}
HKCR\TypeLib\{E79DFBC0-5697-4FBD-94E5-5B2A9C7C1612}\1.0
HKCR\TypeLib\{E79DFBC0-5697-4FBD-94E5-5B2A9C7C1612}\1.0\0
HKCR\TypeLib\{E79DFBC0-5697-4FBD-94E5-5B2A9C7C1612}\1.0\0\win32
HKCR\TypeLib\{E79DFBC0-5697-4FBD-94E5-5B2A9C7C1612}\1.0\FLAGS
HKCR\TypeLib\{E79DFBC0-5697-4FBD-94E5-5B2A9C7C1612}\1.0\HELPDIR
HKCR\TypeLib\{F42228FB-E84E-479E-B922-FBBD096E792C}
HKCR\TypeLib\{F42228FB-E84E-479E-B922-FBBD096E792C}\1.0
HKCR\TypeLib\{F42228FB-E84E-479E-B922-FBBD096E792C}\1.0\0
HKCR\TypeLib\{F42228FB-E84E-479E-B922-FBBD096E792C}\1.0\0\win32
HKCR\TypeLib\{F42228FB-E84E-479E-B922-FBBD096E792C}\1.0\FLAGS
HKCR\TypeLib\{F42228FB-E84E-479E-B922-FBBD096E792C}\1.0\HELPDIR
HKCR\Interface\{07B18EAA-A523-4961-B6BB-170DE4475CCA}
HKCR\Interface\{07B18EAA-A523-4961-B6BB-170DE4475CCA}\ProxyStubClsid
HKCR\Interface\{07B18EAA-A523-4961-B6BB-170DE4475CCA}\ProxyStubClsid32
HKCR\Interface\{07B18EAA-A523-4961-B6BB-170DE4475CCA}\TypeLib
HKCR\Interface\{07B18EAA-A523-4961-B6BB-170DE4475CCA}\TypeLib#Version
HKCR\Interface\{07B18EAC-A523-4961-B6BB-170DE4475CCA}
HKCR\Interface\{07B18EAC-A523-4961-B6BB-170DE4475CCA}\ProxyStubClsid
HKCR\Interface\{07B18EAC-A523-4961-B6BB-170DE4475CCA}\ProxyStubClsid32
HKCR\Interface\{07B18EAC-A523-4961-B6BB-170DE4475CCA}\TypeLib
HKCR\Interface\{07B18EAC-A523-4961-B6BB-170DE4475CCA}\TypeLib#Version
HKCR\Interface\{1093995A-BA37-41D2-836E-091067C4AD17}
HKCR\Interface\{1093995A-BA37-41D2-836E-091067C4AD17}\ProxyStubClsid
HKCR\Interface\{1093995A-BA37-41D2-836E-091067C4AD17}\ProxyStubClsid32
HKCR\Interface\{1093995A-BA37-41D2-836E-091067C4AD17}\TypeLib
HKCR\Interface\{1093995A-BA37-41D2-836E-091067C4AD17}\TypeLib#Version
HKCR\Interface\{120927BF-1700-43BC-810F-FAB92549B390}
HKCR\Interface\{120927BF-1700-43BC-810F-FAB92549B390}\ProxyStubClsid
HKCR\Interface\{120927BF-1700-43BC-810F-FAB92549B390}\ProxyStubClsid32
HKCR\Interface\{120927BF-1700-43BC-810F-FAB92549B390}\TypeLib
HKCR\Interface\{120927BF-1700-43BC-810F-FAB92549B390}\TypeLib#Version
HKCR\Interface\{17DE5E5E-BFE3-4E83-8E1F-8755795359EC}
HKCR\Interface\{17DE5E5E-BFE3-4E83-8E1F-8755795359EC}\ProxyStubClsid
HKCR\Interface\{17DE5E5E-BFE3-4E83-8E1F-8755795359EC}\ProxyStubClsid32
HKCR\Interface\{17DE5E5E-BFE3-4E83-8E1F-8755795359EC}\TypeLib
HKCR\Interface\{17DE5E5E-BFE3-4E83-8E1F-8755795359EC}\TypeLib#Version
HKCR\Interface\{1F52A5FA-A705-4415-B975-88503B291728}
HKCR\Interface\{1F52A5FA-A705-4415-B975-88503B291728}\ProxyStubClsid
HKCR\Interface\{1F52A5FA-A705-4415-B975-88503B291728}\ProxyStubClsid32
HKCR\Interface\{1F52A5FA-A705-4415-B975-88503B291728}\TypeLib
HKCR\Interface\{1F52A5FA-A705-4415-B975-88503B291728}\TypeLib#Version
HKCR\Interface\{247A115F-06C2-4FB3-967D-2D62D3CF4F0A}
HKCR\Interface\{247A115F-06C2-4FB3-967D-2D62D3CF4F0A}\ProxyStubClsid
HKCR\Interface\{247A115F-06C2-4FB3-967D-2D62D3CF4F0A}\ProxyStubClsid32
HKCR\Interface\{247A115F-06C2-4FB3-967D-2D62D3CF4F0A}\TypeLib
HKCR\Interface\{247A115F-06C2-4FB3-967D-2D62D3CF4F0A}\TypeLib#Version
HKCR\Interface\{2E3537FC-CF2F-4F56-AF54-5A6A3DD375CC}
HKCR\Interface\{2E3537FC-CF2F-4F56-AF54-5A6A3DD375CC}\ProxyStubClsid
HKCR\Interface\{2E3537FC-CF2F-4F56-AF54-5A6A3DD375CC}\ProxyStubClsid32
HKCR\Interface\{2E3537FC-CF2F-4F56-AF54-5A6A3DD375CC}\TypeLib
HKCR\Interface\{2E3537FC-CF2F-4F56-AF54-5A6A3DD375CC}\TypeLib#Version
HKCR\Interface\{2E9937FC-CF2F-4F56-AF54-5A6A3DD375CC}
HKCR\Interface\{2E9937FC-CF2F-4F56-AF54-5A6A3DD375CC}\ProxyStubClsid
HKCR\Interface\{2E9937FC-CF2F-4F56-AF54-5A6A3DD375CC}\ProxyStubClsid32
HKCR\Interface\{2E9937FC-CF2F-4F56-AF54-5A6A3DD375CC}\TypeLib
HKCR\Interface\{2E9937FC-CF2F-4F56-AF54-5A6A3DD375CC}\TypeLib#Version
HKCR\Interface\{3E1656ED-F60E-4597-B6AA-B6A58E171495}
HKCR\Interface\{3E1656ED-F60E-4597-B6AA-B6A58E171495}\ProxyStubClsid
HKCR\Interface\{3E1656ED-F60E-4597-B6AA-B6A58E171495}\ProxyStubClsid32
HKCR\Interface\{3E1656ED-F60E-4597-B6AA-B6A58E171495}\TypeLib
HKCR\Interface\{3E1656ED-F60E-4597-B6AA-B6A58E171495}\TypeLib#Version
HKCR\Interface\{3E53E2CB-86DB-4A4A-8BD9-FFEB7A64DF82}
HKCR\Interface\{3E53E2CB-86DB-4A4A-8BD9-FFEB7A64DF82}\ProxyStubClsid
HKCR\Interface\{3E53E2CB-86DB-4A4A-8BD9-FFEB7A64DF82}\ProxyStubClsid32
HKCR\Interface\{3E53E2CB-86DB-4A4A-8BD9-FFEB7A64DF82}\TypeLib
HKCR\Interface\{3E53E2CB-86DB-4A4A-8BD9-FFEB7A64DF82}\TypeLib#Version
HKCR\Interface\{3E720451-B472-4954-B7AA-33069EB53906}
HKCR\Interface\{3E720451-B472-4954-B7AA-33069EB53906}\ProxyStubClsid
HKCR\Interface\{3E720451-B472-4954-B7AA-33069EB53906}\ProxyStubClsid32
HKCR\Interface\{3E720451-B472-4954-B7AA-33069EB53906}\TypeLib
HKCR\Interface\{3E720451-B472-4954-B7AA-33069EB53906}\TypeLib#Version
HKCR\Interface\{3E720453-B472-4954-B7AA-33069EB53906}
HKCR\Interface\{3E720453-B472-4954-B7AA-33069EB53906}\ProxyStubClsid
HKCR\Interface\{3E720453-B472-4954-B7AA-33069EB53906}\ProxyStubClsid32
HKCR\Interface\{3E720453-B472-4954-B7AA-33069EB53906}\TypeLib
HKCR\Interface\{3E720453-B472-4954-B7AA-33069EB53906}\TypeLib#Version
HKCR\Interface\{63D0ED2B-B45B-4458-8B3B-60C69BBBD83C}
HKCR\Interface\{63D0ED2B-B45B-4458-8B3B-60C69BBBD83C}\ProxyStubClsid
HKCR\Interface\{63D0ED2B-B45B-4458-8B3B-60C69BBBD83C}\ProxyStubClsid32
HKCR\Interface\{63D0ED2B-B45B-4458-8B3B-60C69BBBD83C}\TypeLib
HKCR\Interface\{63D0ED2B-B45B-4458-8B3B-60C69BBBD83C}\TypeLib#Version
HKCR\Interface\{63D0ED2D-B45B-4458-8B3B-60C69BBBD83C}
HKCR\Interface\{63D0ED2D-B45B-4458-8B3B-60C69BBBD83C}\ProxyStubClsid
HKCR\Interface\{63D0ED2D-B45B-4458-8B3B-60C69BBBD83C}\ProxyStubClsid32
HKCR\Interface\{63D0ED2D-B45B-4458-8B3B-60C69BBBD83C}\TypeLib
HKCR\Interface\{63D0ED2D-B45B-4458-8B3B-60C69BBBD83C}\TypeLib#Version
HKCR\Interface\{6E74766C-4D93-4CC0-96D1-47B8E07FF9CA}
HKCR\Interface\{6E74766C-4D93-4CC0-96D1-47B8E07FF9CA}\ProxyStubClsid
HKCR\Interface\{6E74766C-4D93-4CC0-96D1-47B8E07FF9CA}\ProxyStubClsid32
HKCR\Interface\{6E74766C-4D93-4CC0-96D1-47B8E07FF9CA}\TypeLib
HKCR\Interface\{6E74766C-4D93-4CC0-96D1-47B8E07FF9CA}\TypeLib#Version
HKCR\Interface\{72EE7F04-15BD-4845-A005-D6711144D86A}
HKCR\Interface\{72EE7F04-15BD-4845-A005-D6711144D86A}\ProxyStubClsid
HKCR\Interface\{72EE7F04-15BD-4845-A005-D6711144D86A}\ProxyStubClsid32
HKCR\Interface\{72EE7F04-15BD-4845-A005-D6711144D86A}\TypeLib
HKCR\Interface\{72EE7F04-15BD-4845-A005-D6711144D86A}\TypeLib#Version
HKCR\Interface\{741DE825-A6F0-4497-9AA6-8023CF9B0FFF}
HKCR\Interface\{741DE825-A6F0-4497-9AA6-8023CF9B0FFF}\ProxyStubClsid
HKCR\Interface\{741DE825-A6F0-4497-9AA6-8023CF9B0FFF}\ProxyStubClsid32
HKCR\Interface\{741DE825-A6F0-4497-9AA6-8023CF9B0FFF}\TypeLib
HKCR\Interface\{741DE825-A6F0-4497-9AA6-8023CF9B0FFF}\TypeLib#Version
HKCR\Interface\{7473D291-B7BB-4F24-AE82-7E2CE94BB6A9}
HKCR\Interface\{7473D291-B7BB-4F24-AE82-7E2CE94BB6A9}\ProxyStubClsid
HKCR\Interface\{7473D291-B7BB-4F24-AE82-7E2CE94BB6A9}\ProxyStubClsid32
HKCR\Interface\{7473D291-B7BB-4F24-AE82-7E2CE94BB6A9}\TypeLib
HKCR\Interface\{7473D291-B7BB-4F24-AE82-7E2CE94BB6A9}\TypeLib#Version
HKCR\Interface\{7473D293-B7BB-4F24-AE82-7E2CE94BB6A9}
HKCR\Interface\{7473D293-B7BB-4F24-AE82-7E2CE94BB6A9}\ProxyStubClsid
HKCR\Interface\{7473D293-B7BB-4F24-AE82-7E2CE94BB6A9}\ProxyStubClsid32
HKCR\Interface\{7473D293-B7BB-4F24-AE82-7E2CE94BB6A9}\TypeLib
HKCR\Interface\{7473D293-B7BB-4F24-AE82-7E2CE94BB6A9}\TypeLib#Version
HKCR\Interface\{7473D295-B7BB-4F24-AE82-7E2CE94BB6A9}
HKCR\Interface\{7473D295-B7BB-4F24-AE82-7E2CE94BB6A9}\ProxyStubClsid
HKCR\Interface\{7473D295-B7BB-4F24-AE82-7E2CE94BB6A9}\ProxyStubClsid32
HKCR\Interface\{7473D295-B7BB-4F24-AE82-7E2CE94BB6A9}\TypeLib
HKCR\Interface\{7473D295-B7BB-4F24-AE82-7E2CE94BB6A9}\TypeLib#Version
HKCR\Interface\{7473D297-B7BB-4F24-AE82-7E2CE94BB6A9}
HKCR\Interface\{7473D297-B7BB-4F24-AE82-7E2CE94BB6A9}\ProxyStubClsid
HKCR\Interface\{7473D297-B7BB-4F24-AE82-7E2CE94BB6A9}\ProxyStubClsid32
HKCR\Interface\{7473D297-B7BB-4F24-AE82-7E2CE94BB6A9}\TypeLib
HKCR\Interface\{7473D297-B7BB-4F24-AE82-7E2CE94BB6A9}\TypeLib#Version
HKCR\Interface\{90449521-D834-4703-BB4E-D3AA44042FF8}
HKCR\Interface\{90449521-D834-4703-BB4E-D3AA44042FF8}\ProxyStubClsid
HKCR\Interface\{90449521-D834-4703-BB4E-D3AA44042FF8}\ProxyStubClsid32
HKCR\Interface\{90449521-D834-4703-BB4E-D3AA44042FF8}\TypeLib
HKCR\Interface\{90449521-D834-4703-BB4E-D3AA44042FF8}\TypeLib#Version
HKCR\Interface\{991AAC62-B100-47CE-8B75-253965244F69}
HKCR\Interface\{991AAC62-B100-47CE-8B75-253965244F69}\ProxyStubClsid
HKCR\Interface\{991AAC62-B100-47CE-8B75-253965244F69}\ProxyStubClsid32
HKCR\Interface\{991AAC62-B100-47CE-8B75-253965244F69}\TypeLib
HKCR\Interface\{991AAC62-B100-47CE-8B75-253965244F69}\TypeLib#Version
HKCR\Interface\{A626CDBD-3D13-4F78-B819-440A28D7E8FC}
HKCR\Interface\{A626CDBD-3D13-4F78-B819-440A28D7E8FC}\ProxyStubClsid
HKCR\Interface\{A626CDBD-3D13-4F78-B819-440A28D7E8FC}\ProxyStubClsid32
HKCR\Interface\{A626CDBD-3D13-4F78-B819-440A28D7E8FC}\TypeLib
HKCR\Interface\{A626CDBD-3D13-4F78-B819-440A28D7E8FC}\TypeLib#Version
HKCR\Interface\{BBABDC90-F3D5-4801-863A-EE6AE529862D}
HKCR\Interface\{BBABDC90-F3D5-4801-863A-EE6AE529862D}\ProxyStubClsid
HKCR\Interface\{BBABDC90-F3D5-4801-863A-EE6AE529862D}\ProxyStubClsid32
HKCR\Interface\{BBABDC90-F3D5-4801-863A-EE6AE529862D}\TypeLib
HKCR\Interface\{BBABDC90-F3D5-4801-863A-EE6AE529862D}\TypeLib#Version
HKCR\Interface\{CF54BE1C-9359-4395-8533-1657CF209CFE}
HKCR\Interface\{CF54BE1C-9359-4395-8533-1657CF209CFE}\ProxyStubClsid
HKCR\Interface\{CF54BE1C-9359-4395-8533-1657CF209CFE}\ProxyStubClsid32
HKCR\Interface\{CF54BE1C-9359-4395-8533-1657CF209CFE}\TypeLib
HKCR\Interface\{CF54BE1C-9359-4395-8533-1657CF209CFE}\TypeLib#Version
HKCR\Interface\{D6FF3684-AD3B-48EB-BBB4-B9E6C5A355C1}
HKCR\Interface\{D6FF3684-AD3B-48EB-BBB4-B9E6C5A355C1}\ProxyStubClsid
HKCR\Interface\{D6FF3684-AD3B-48EB-BBB4-B9E6C5A355C1}\ProxyStubClsid32
HKCR\Interface\{D6FF3684-AD3B-48EB-BBB4-B9E6C5A355C1}\TypeLib
HKCR\Interface\{D6FF3684-AD3B-48EB-BBB4-B9E6C5A355C1}\TypeLib#Version
HKCR\Interface\{DE38C398-B328-4F4C-A3AD-1B5E4ED93477}
HKCR\Interface\{DE38C398-B328-4F4C-A3AD-1B5E4ED93477}\ProxyStubClsid
HKCR\Interface\{DE38C398-B328-4F4C-A3AD-1B5E4ED93477}\ProxyStubClsid32
HKCR\Interface\{DE38C398-B328-4F4C-A3AD-1B5E4ED93477}\TypeLib
HKCR\Interface\{DE38C398-B328-4F4C-A3AD-1B5E4ED93477}\TypeLib#Version
HKCR\Interface\{E342AF55-B78A-4CD0-A2BB-DA7F52D9D25E}
HKCR\Interface\{E342AF55-B78A-4CD0-A2BB-DA7F52D9D25E}\ProxyStubClsid
HKCR\Interface\{E342AF55-B78A-4CD0-A2BB-DA7F52D9D25E}\ProxyStubClsid32
HKCR\Interface\{E342AF55-B78A-4CD0-A2BB-DA7F52D9D25E}\TypeLib
HKCR\Interface\{E342AF55-B78A-4CD0-A2BB-DA7F52D9D25E}\TypeLib#Version
HKCR\Interface\{E342AF55-B78A-4CD0-A2BB-DA7F52D9D25F}
HKCR\Interface\{E342AF55-B78A-4CD0-A2BB-DA7F52D9D25F}\ProxyStubClsid
HKCR\Interface\{E342AF55-B78A-4CD0-A2BB-DA7F52D9D25F}\ProxyStubClsid32
HKCR\Interface\{E342AF55-B78A-4CD0-A2BB-DA7F52D9D25F}\TypeLib
HKCR\Interface\{E342AF55-B78A-4CD0-A2BB-DA7F52D9D25F}\TypeLib#Version
HKCR\Interface\{E79DFBC9-5697-4FBD-94E5-5B2A9C7C1612}
HKCR\Interface\{E79DFBC9-5697-4FBD-94E5-5B2A9C7C1612}\ProxyStubClsid
HKCR\Interface\{E79DFBC9-5697-4FBD-94E5-5B2A9C7C1612}\ProxyStubClsid32
HKCR\Interface\{E79DFBC9-5697-4FBD-94E5-5B2A9C7C1612}\TypeLib
HKCR\Interface\{E79DFBC9-5697-4FBD-94E5-5B2A9C7C1612}\TypeLib#Version
HKCR\Interface\{E79DFBCB-5697-4FBD-94E5-5B2A9C7C1612}
HKCR\Interface\{E79DFBCB-5697-4FBD-94E5-5B2A9C7C1612}\ProxyStubClsid
HKCR\Interface\{E79DFBCB-5697-4FBD-94E5-5B2A9C7C1612}\ProxyStubClsid32
HKCR\Interface\{E79DFBCB-5697-4FBD-94E5-5B2A9C7C1612}\TypeLib
HKCR\Interface\{E79DFBCB-5697-4FBD-94E5-5B2A9C7C1612}\TypeLib#Version
HKCR\Interface\{EB9E5C1C-B1F9-4C2B-BE8A-27D6446FDAF8}
HKCR\Interface\{EB9E5C1C-B1F9-4C2B-BE8A-27D6446FDAF8}\ProxyStubClsid
HKCR\Interface\{EB9E5C1C-B1F9-4C2B-BE8A-27D6446FDAF8}\ProxyStubClsid32
HKCR\Interface\{EB9E5C1C-B1F9-4C2B-BE8A-27D6446FDAF8}\TypeLib
HKCR\Interface\{EB9E5C1C-B1F9-4C2B-BE8A-27D6446FDAF8}\TypeLib#Version
HKCR\Interface\{F87D7FB5-9DC5-4C8C-B998-D8DFE02E2978}
HKCR\Interface\{F87D7FB5-9DC5-4C8C-B998-D8DFE02E2978}\ProxyStubClsid
HKCR\Interface\{F87D7FB5-9DC5-4C8C-B998-D8DFE02E2978}\ProxyStubClsid32
HKCR\Interface\{F87D7FB5-9DC5-4C8C-B998-D8DFE02E2978}\TypeLib
HKCR\Interface\{F87D7FB5-9DC5-4C8C-B998-D8DFE02E2978}\TypeLib#Version
HKLM\Software\FocusInteractive
HKLM\Software\FocusInteractive\bar
HKLM\Software\FocusInteractive\bar\Switches
HKLM\Software\FocusInteractive\bar\Switches#incmail.exe
HKLM\Software\FocusInteractive\bar\Switches#msimn.exe
HKLM\Software\FocusInteractive\bar\Switches#msn.exe
HKLM\Software\FocusInteractive\bar\Switches#outlook.exe
HKLM\Software\FocusInteractive\bar\Switches#waol.exe
HKLM\Software\FocusInteractive\bar\Switches#aim.exe
HKLM\Software\FocusInteractive\bar\Switches#icq.exe
HKLM\Software\FocusInteractive\bar\Switches#icqlite.exe
HKLM\Software\FocusInteractive\bar\Switches#msmsgs.exe
HKLM\Software\FocusInteractive\bar\Switches#msnmsgr.exe
HKLM\Software\FocusInteractive\bar\Switches#ypager.exe
HKLM\Software\FocusInteractive\bar\Switches#ua
HKLM\Software\FocusInteractive\bar\Switches#au
HKLM\Software\FocusInteractive\bar\Switches#mwsSrcAs.dll
HKLM\Software\FocusInteractive\bar\Switches#ok
HKLM\Software\FocusInteractive\bar\Switches#od
HKLM\Software\FocusInteractive\bar\Switches#nk
HKLM\Software\FocusInteractive\bar\Switches#nd
HKLM\Software\FocusInteractive\Email-IM
HKLM\Software\FocusInteractive\Email-IM\0
HKLM\Software\FocusInteractive\Email-IM\0#Toolbar
HKLM\Software\FocusInteractive\Email-IM\0#AppName
HKLM\Software\FocusInteractive\Email-IM\0#Path
HKLM\Software\FocusInteractive\Outlook
HKLM\Software\FocusInteractive\Outlook#MyWebSearch.OutlookAddin
HKLM\SYSTEM\CurrentControlSet\Enum\Root\LEGACY_MYWEBSEARCHSERVICE#NextInstance
HKLM\SYSTEM\CurrentControlSet\Enum\Root\LEGACY_MYWEBSEARCHSERVICE\0000
HKLM\SYSTEM\CurrentControlSet\Enum\Root\LEGACY_MYWEBSEARCHSERVICE\0000#Service
HKLM\SYSTEM\CurrentControlSet\Enum\Root\LEGACY_MYWEBSEARCHSERVICE\0000#Legacy
HKLM\SYSTEM\CurrentControlSet\Enum\Root\LEGACY_MYWEBSEARCHSERVICE\0000#ConfigFlags
HKLM\SYSTEM\CurrentControlSet\Enum\Root\LEGACY_MYWEBSEARCHSERVICE\0000#Class
HKLM\SYSTEM\CurrentControlSet\Enum\Root\LEGACY_MYWEBSEARCHSERVICE\0000#ClassGUID
HKLM\SYSTEM\CurrentControlSet\Enum\Root\LEGACY_MYWEBSEARCHSERVICE\0000#DeviceDesc
HKLM\SYSTEM\CurrentControlSet\Enum\Root\LEGACY_MYWEBSEARCHSERVICE\0000\Control
HKLM\SYSTEM\CurrentControlSet\Enum\Root\LEGACY_MYWEBSEARCHSERVICE\0000\Control#ActiveService
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\MyWebSearch bar Uninstall
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\MyWebSearch bar Uninstall#DisplayName
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\MyWebSearch bar Uninstall#HelpLink
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\MyWebSearch bar Uninstall#Publisher
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\MyWebSearch bar Uninstall#UninstallString
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\MyWebSearch bar Uninstall#UrlInfoAbout
HKLM\SYSTEM\CurrentControlSet\Services\MyWebSearchService#Type
HKLM\SYSTEM\CurrentControlSet\Services\MyWebSearchService#Start
HKLM\SYSTEM\CurrentControlSet\Services\MyWebSearchService#ErrorControl
HKLM\SYSTEM\CurrentControlSet\Services\MyWebSearchService#ImagePath
HKLM\SYSTEM\CurrentControlSet\Services\MyWebSearchService#DisplayName
HKLM\SYSTEM\CurrentControlSet\Services\MyWebSearchService#ObjectName
HKLM\SYSTEM\CurrentControlSet\Services\MyWebSearchService\Security
HKLM\SYSTEM\CurrentControlSet\Services\MyWebSearchService\Security#Security
HKLM\SYSTEM\CurrentControlSet\Services\MyWebSearchService\Enum
HKLM\SYSTEM\CurrentControlSet\Services\MyWebSearchService\Enum#0
HKLM\SYSTEM\CurrentControlSet\Services\MyWebSearchService\Enum#Count
HKLM\SYSTEM\CurrentControlSet\Services\MyWebSearchService\Enum#NextInstance
C:\Program Files\MyWebSearch\bar\1.bin\chrome\M3FFXTBR.JAR
C:\Program Files\MyWebSearch\bar\1.bin\chrome
C:\Program Files\MyWebSearch\bar\1.bin\CHROME.MANIFEST
C:\Program Files\MyWebSearch\bar\1.bin\F3BKGERR.JPG
C:\Program Files\MyWebSearch\bar\1.bin\F3CJPEG.DLL
C:\Program Files\MyWebSearch\bar\1.bin\F3DTACTL.DLL
C:\Program Files\MyWebSearch\bar\1.bin\F3HISTSW.DLL
C:\Program Files\MyWebSearch\bar\1.bin\F3HKSTUB.DLL
C:\Program Files\MyWebSearch\bar\1.bin\F3HTTPCT.DLL
C:\Program Files\MyWebSearch\bar\1.bin\F3IMSTUB.DLL
C:\Program Files\MyWebSearch\bar\1.bin\F3POPSWT.DLL
C:\Program Files\MyWebSearch\bar\1.bin\F3PSSAVR.SCR
C:\Program Files\MyWebSearch\bar\1.bin\F3REGHK.DLL
C:\Program Files\MyWebSearch\bar\1.bin\F3REPROX.DLL
C:\Program Files\MyWebSearch\bar\1.bin\F3RESTUB.DLL
C:\Program Files\MyWebSearch\bar\1.bin\F3SCHMON.EXE
C:\Program Files\MyWebSearch\bar\1.bin\F3SPACER.WMV
C:\Program Files\MyWebSearch\bar\1.bin\F3WALLPP.DAT
C:\Program Files\MyWebSearch\bar\1.bin\F3WPHOOK.DLL
C:\Program Files\MyWebSearch\bar\1.bin\FWPBUDDY.PNG
C:\Program Files\MyWebSearch\bar\1.bin\INSTALL.RDF
C:\Program Files\MyWebSearch\bar\1.bin\M3AUXSTB.DLL
C:\Program Files\MyWebSearch\bar\1.bin\M3DLGHK.DLL
C:\Program Files\MyWebSearch\bar\1.bin\M3HIGHIN.EXE
C:\Program Files\MyWebSearch\bar\1.bin\M3HTML.DLL
C:\Program Files\MyWebSearch\bar\1.bin\M3IDLE.DLL
C:\Program Files\MyWebSearch\bar\1.bin\M3IMPIPE.EXE
C:\Program Files\MyWebSearch\bar\1.bin\M3MEDINT.EXE
C:\Program Files\MyWebSearch\bar\1.bin\M3MSG.DLL
C:\Program Files\MyWebSearch\bar\1.bin\M3OUTLCN.DLL
C:\Program Files\MyWebSearch\bar\1.bin\M3PATCH.DLL
C:\Program Files\MyWebSearch\bar\1.bin\M3PLUGIN.DLL
C:\Program Files\MyWebSearch\bar\1.bin\M3SKIN.DLL
C:\Program Files\MyWebSearch\bar\1.bin\M3SKPLAY.EXE
C:\Program Files\MyWebSearch\bar\1.bin\M3SLSRCH.EXE
C:\Program Files\MyWebSearch\bar\1.bin\M3SRCHMN.EXE
C:\Program Files\MyWebSearch\bar\1.bin\MWSMLBTN.DLL
C:\Program Files\MyWebSearch\bar\1.bin\MWSOEMON.EXE
C:\Program Files\MyWebSearch\bar\1.bin\MWSOEPLG.DLL
C:\Program Files\MyWebSearch\bar\1.bin\MWSOESTB.DLL
C:\Program Files\MyWebSearch\bar\1.bin\MWSSVC.EXE
C:\Program Files\MyWebSearch\bar\1.bin\MWSUABTN.DLL
C:\Program Files\MyWebSearch\bar\1.bin\NPMYWEBS.DLL
C:\Program Files\MyWebSearch\bar\1.bin
C:\Program Files\MyWebSearch\bar\Avatar\COMMON.F3S
C:\Program Files\MyWebSearch\bar\Avatar
C:\Program Files\MyWebSearch\bar\Cache\0009BBD2.bmp
C:\Program Files\MyWebSearch\bar\Cache\000C4D6A.bmp
C:\Program Files\MyWebSearch\bar\Cache\000EE606
C:\Program Files\MyWebSearch\bar\Cache\000EEA7B.bin
C:\Program Files\MyWebSearch\bar\Cache\000EEE82.bin
C:\Program Files\MyWebSearch\bar\Cache\000EF24B.bin
C:\Program Files\MyWebSearch\bar\Cache\000EF633.bin
C:\Program Files\MyWebSearch\bar\Cache\00119306
C:\Program Files\MyWebSearch\bar\Cache\0011A6FB
C:\Program Files\MyWebSearch\bar\Cache\0011BE0D
C:\Program Files\MyWebSearch\bar\Cache\00120C5C
C:\Program Files\MyWebSearch\bar\Cache\001770EA.bin
C:\Program Files\MyWebSearch\bar\Cache\001772FD.bin
C:\Program Files\MyWebSearch\bar\Cache\00A575F8.bmp
C:\Program Files\MyWebSearch\bar\Cache\files.ini
C:\Program Files\MyWebSearch\bar\Cache
C:\Program Files\MyWebSearch\bar\Game\CHECKERS.F3S
C:\Program Files\MyWebSearch\bar\Game\CHESS.F3S
C:\Program Files\MyWebSearch\bar\Game\REVERSI.F3S
C:\Program Files\MyWebSearch\bar\Game
C:\Program Files\MyWebSearch\bar\History\search3
C:\Program Files\MyWebSearch\bar\History
C:\Program Files\MyWebSearch\bar\icons\CM.ICO
C:\Program Files\MyWebSearch\bar\icons\MFC.ICO
C:\Program Files\MyWebSearch\bar\icons\PSS.ICO
C:\Program Files\MyWebSearch\bar\icons\SMILEY.ICO
C:\Program Files\MyWebSearch\bar\icons\WB.ICO
C:\Program Files\MyWebSearch\bar\icons\ZWINKY.ICO
C:\Program Files\MyWebSearch\bar\icons
C:\Program Files\MyWebSearch\bar\Message\COMMON.F3S
C:\Program Files\MyWebSearch\bar\Message
C:\Program Files\MyWebSearch\bar\Notifier\COMMON.F3S
C:\Program Files\MyWebSearch\bar\Notifier\DOG.F3S
C:\Program Files\MyWebSearch\bar\Notifier\FISH.F3S
C:\Program Files\MyWebSearch\bar\Notifier\KUNGFU.F3S
C:\Program Files\MyWebSearch\bar\Notifier\LIFEGARD.F3S
C:\Program Files\MyWebSearch\bar\Notifier\MAID.F3S
C:\Program Files\MyWebSearch\bar\Notifier\MAILBOX.F3S
C:\Program Files\MyWebSearch\bar\Notifier\OPERA.F3S
C:\Program Files\MyWebSearch\bar\Notifier\ROBOT.F3S
C:\Program Files\MyWebSearch\bar\Notifier\SEDUCT.F3S
C:\Program Files\MyWebSearch\bar\Notifier\SURFER.F3S
C:\Program Files\MyWebSearch\bar\Notifier
C:\Program Files\MyWebSearch\bar\Settings\prevcfg2.htm
C:\Program Files\MyWebSearch\bar\Settings\setting2.htm
C:\Program Files\MyWebSearch\bar\Settings\settings.dat
C:\Program Files\MyWebSearch\bar\Settings\s_pid.dat
C:\Program Files\MyWebSearch\bar\Settings
C:\Program Files\MyWebSearch\bar\setups
C:\Program Files\MyWebSearch\bar
C:\Program Files\MyWebSearch
C:\Program Files\FunWebProducts\Installr\1.bin\F3EZSETP.DLL
C:\Program Files\FunWebProducts\Installr\1.bin\F3PLUGIN.DLL
C:\Program Files\FunWebProducts\Installr\1.bin\NPFUNWEB.DLL
C:\Program Files\FunWebProducts\Installr\1.bin
C:\Program Files\FunWebProducts\Installr\Cache\000E3B4F.exe
C:\Program Files\FunWebProducts\Installr\Cache\files.ini
C:\Program Files\FunWebProducts\Installr\Cache
C:\Program Files\FunWebProducts\Installr\setups
C:\Program Files\FunWebProducts\Installr
C:\Program Files\FunWebProducts\ScreenSaver\Images
C:\Program Files\FunWebProducts\ScreenSaver
C:\Program Files\FunWebProducts\Shared\Cache\CursorManiaBtn.html
C:\Program Files\FunWebProducts\Shared\Cache\SmileyCentralBtn.html
C:\Program Files\FunWebProducts\Shared\Cache\WebfettiBtn.html
C:\Program Files\FunWebProducts\Shared\Cache
C:\Program Files\FunWebProducts\Shared
C:\Program Files\FunWebProducts
C:\WINDOWS\SYSTEM32\F3PSSAVR.SCR

Adware.HBHelper
HKU\S-1-5-21-515967899-57989841-839522115-1004\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{CA3EB689-8F09-4026-AA10-B9534C691CE0}
HKCR\CLSID\{CA3EB689-8F09-4026-AA10-B9534C691CE0}
HKU\S-1-5-21-515967899-57989841-839522115-1004\Software\Microsoft\Internet Explorer\URLSearchHooks#{CA3EB689-8F09-4026-AA10-B9534C691CE0}

Adware.Tracking Cookie
C:\Documents and Settings\Melane\Cookies\melane@dmtracker[5].txt
C:\Documents and Settings\Melane\Cookies\melane@associatedcontent.112.2o7[3].txt
C:\Documents and Settings\Melane\Cookies\melane@myroitracking[1].txt
C:\Documents and Settings\Melane\Cookies\melane@richmedia.yahoo[7].txt
C:\Documents and Settings\Melane\Cookies\melane@network.alluremedia.com[4].txt
C:\Documents and Settings\Melane\Cookies\melane@advertising.sheknows[2].txt
C:\Documents and Settings\Melane\Cookies\melane@msnservices.112.2o7[3].txt
C:\Documents and Settings\Melane\Cookies\melane@ads.associatedcontent[3].txt
C:\Documents and Settings\Melane\Cookies\melane@e-2dj6wgliclazwgo.stats.esomniture[2].txt
C:\Documents and Settings\Melane\Cookies\melane@dc.tremormedia[2].txt
C:\Documents and Settings\Melane\Cookies\melane@lfstmedia[4].txt
C:\Documents and Settings\Melane\Cookies\melane@ru4[4].txt
C:\Documents and Settings\Melane\Cookies\melane@CABYK65W.txt
C:\Documents and Settings\Melane\Cookies\melane@mywebsearch[9].txt
C:\Documents and Settings\Melane\Cookies\melane@adbrite[8].txt
C:\Documents and Settings\Melane\Cookies\melane@www6.addfreestats[2].txt
C:\Documents and Settings\Melane\Cookies\melane@overture[7].txt
C:\Documents and Settings\Melane\Cookies\melane@112.2o7[6].txt
C:\Documents and Settings\Melane\Cookies\melane@smileycentral[4].txt
C:\Documents and Settings\Melane\Cookies\melane@ads.apn.co[5].txt
C:\Documents and Settings\Melane\Cookies\melane@cattle-country-lifestyle[2].txt
C:\Documents and Settings\Melane\Cookies\melane@apmebf[6].txt
C:\Documents and Settings\Melane\Cookies\melane@ads.ad4game[5].txt
C:\Documents and Settings\Melane\Cookies\melane@CA695IQZ.txt
C:\Documents and Settings\Melane\Cookies\melane@msnportal.112.2o7[5].txt
C:\Documents and Settings\Melane\Cookies\melane@sensismediasmart.com[8].txt
C:\Documents and Settings\Melane\Cookies\melane@imrworldwide[6].txt
C:\Documents and Settings\Melane\Cookies\melane@snapfish.112.2o7[6].txt
C:\Documents and Settings\Melane\Cookies\melane@sales.liveperson[2].txt
C:\Documents and Settings\Melane\Cookies\melane@advertising[7].txt
C:\Documents and Settings\Melane\Cookies\melane@www.burstnet[6].txt
C:\Documents and Settings\Melane\Cookies\melane@media.sensis.com[11].txt
C:\Documents and Settings\Melane\Cookies\melane@examinercom.122.2o7[2].txt
C:\Documents and Settings\Melane\Cookies\melane@ads.bleepingcomputer[1].txt
C:\Documents and Settings\Melane\Cookies\melane@tacoda[4].txt
C:\Documents and Settings\Melane\Cookies\melane@questionmarket[5].txt
C:\Documents and Settings\Melane\Cookies\melane@adserver.adreactor[5].txt
C:\Documents and Settings\Melane\Cookies\melane@finda.com[5].txt
C:\Documents and Settings\Melane\Cookies\melane@burstnet[4].txt
C:\Documents and Settings\Melane\Cookies\melane@countrymusicchannel.com[1].txt
C:\Documents and Settings\Melane\Cookies\melane@atdmt[3].txt
C:\Documents and Settings\Melane\Cookies\melane@liveperson[8].txt
C:\Documents and Settings\Melane\Cookies\melane@zedo[6].txt
C:\Documents and Settings\Melane\Cookies\melane@ads.telegraph.co[3].txt
C:\Documents and Settings\Melane\Cookies\melane@clicksor[5].txt
C:\Documents and Settings\Melane\Cookies\melane@adservx.omg.com[5].txt
C:\Documents and Settings\Melane\Cookies\melane@statse.webtrendslive[3].txt
C:\Documents and Settings\Melane\Cookies\melane@adserver.adtechus[4].txt
C:\Documents and Settings\Melane\Cookies\melane@casalemedia[7].txt
C:\Documents and Settings\Melane\Cookies\melane@tribalfusion[10].txt
C:\Documents and Settings\Melane\Cookies\melane@readersdigest.122.2o7[2].txt
C:\Documents and Settings\Melane\Cookies\melane@CAIJGXV5.txt
C:\Documents and Settings\Melane\Cookies\melane@2o7[5].txt
C:\Documents and Settings\Melane\Cookies\melane@toplist[2].txt
C:\Documents and Settings\Melane\Cookies\melane@fastclick[10].txt
C:\Documents and Settings\Melane\Cookies\melane@network.realmedia[2].txt
C:\Documents and Settings\Melane\Cookies\melane@d.dmcpmtrack[1].txt
C:\Documents and Settings\Melane\Cookies\melane@CASO4DIQ.txt
C:\Documents and Settings\Melane\Cookies\melane@CAJEQ56Q.txt
C:\Documents and Settings\Melane\Cookies\melane@interclick[5].txt
C:\Documents and Settings\Melane\Cookies\melane@doubleclick[6].txt
C:\Documents and Settings\Melane\Cookies\melane@pro-market[3].txt
C:\Documents and Settings\Melane\Cookies\melane@adlegend[2].txt
C:\Documents and Settings\Melane\Cookies\melane@statcounter[10].txt
C:\Documents and Settings\Melane\Cookies\melane@CAJKHGA4.txt
C:\Documents and Settings\Melane\Cookies\melane@sbsaustralia.112.2o7[2].txt
C:\Documents and Settings\Melane\Cookies\melane@advertise[1].txt
C:\Documents and Settings\Melane\Cookies\melane@yieldmanager[6].txt
C:\Documents and Settings\Melane\Cookies\melane@ads.e-planning[1].txt
C:\Documents and Settings\Melane\Cookies\melane@realmedia[2].txt
C:\Documents and Settings\Melane\Cookies\melane@statse.webtrendslive[6].txt
C:\Documents and Settings\Melane\Cookies\melane@tradedoubler[2].txt
C:\Documents and Settings\Melane\Cookies\melane@f2network.112.2o7[6].txt
C:\Documents and Settings\Melane\Cookies\melane@ads.godlikeproductions[2].txt
C:\Documents and Settings\Melane\Cookies\melane@paypal.112.2o7[5].txt
C:\Documents and Settings\Melane\Cookies\melane@ads.pof[3].txt
C:\Documents and Settings\Melane\Cookies\melane@specificclick[7].txt
C:\Documents and Settings\Melane\Cookies\melane@collective-media[4].txt
C:\Documents and Settings\Melane\Cookies\melane@liveperson[11].txt
C:\Documents and Settings\Melane\Cookies\melane@server.cpmstar[1].txt
C:\Documents and Settings\Melane\Cookies\melane@chitika[8].txt
C:\Documents and Settings\Melane\Cookies\melane@CAMY3JU7.txt
C:\Documents and Settings\Melane\Cookies\melane@revsci[6].txt
C:\Documents and Settings\Melane\Cookies\melane@media6degrees[5].txt
C:\Documents and Settings\Melane\Cookies\melane@at.atwola[7].txt
C:\Documents and Settings\Melane\Cookies\melane@invitemedia[4].txt
C:\Documents and Settings\Melane\Cookies\melane@CA3EP465.txt
C:\Documents and Settings\Melane\Cookies\melane@CAXWSA59.txt
C:\Documents and Settings\Melane\Cookies\melane@in.getclicky[3].txt
C:\Documents and Settings\Melane\Cookies\melane@searsca.122.2o7[2].txt
C:\Documents and Settings\Melane\Cookies\melane@legolas-media[3].txt
C:\Documents and Settings\Melane\Cookies\melane@e-2dj6wgkisod5mbp.stats.esomniture[3].txt
C:\Documents and Settings\Melane\Cookies\melane@e-2dj6wfk4ckdjegp.stats.esomniture[1].txt
C:\Documents and Settings\Melane\Cookies\melane@go.ewatracking[1].txt
C:\Documents and Settings\Melane\Cookies\melane@user.lucidmedia[2].txt
C:\Documents and Settings\Melane\Cookies\melane@eventbrite.122.2o7[1].txt
C:\Documents and Settings\Melane\Cookies\melane@adxpose[2].txt
C:\Documents and Settings\Melane\Cookies\melane@urlad--sensismediasmart--com--au.rtrk.com[1].txt
C:\Documents and Settings\Melane\Cookies\melane@ads.updatecar[1].txt
C:\Documents and Settings\Melane\Cookies\melane@n-traffic[1].txt
C:\Documents and Settings\Melane\Cookies\melane@e-2dj6wgmywlcjwbq.stats.esomniture[1].txt
C:\Documents and Settings\Melane\Cookies\melane@tripod[3].txt
C:\Documents and Settings\Melane\Cookies\melane@clickboothlnk[1].txt
C:\Documents and Settings\Melane\Cookies\melane@nrma.122.2o7[1].txt
C:\Documents and Settings\Melane\Cookies\melane@stat.dealtime[9].txt
C:\Documents and Settings\Melane\Cookies\melane@e-2dj6wmmyciazieo.stats.esomniture[1].txt
C:\Documents and Settings\Melane\Cookies\melane@clickbank[3].txt
C:\Documents and Settings\Melane\Cookies\melane@fidelity.rotator.hadj7.adjuggler[1].txt
C:\Documents and Settings\Melane\Cookies\melane@e-2dj6wgkyqnczigq.stats.esomniture[2].txt
C:\Documents and Settings\Melane\Cookies\melane@bshg.122.2o7[1].txt
C:\Documents and Settings\Melane\Cookies\melane@www.tracklead[2].txt
C:\Documents and Settings\Melane\Cookies\melane@columbussearchd.122.2o7[2].txt
C:\Documents and Settings\Melane\Cookies\melane@ice.112.2o7[3].txt
C:\Documents and Settings\Melane\Cookies\melane@adtech[3].txt
C:\Documents and Settings\Melane\Cookies\melane@avgtechnologies.112.2o7[5].txt
C:\Documents and Settings\Melane\Cookies\melane@mediatraffic[2].txt
C:\Documents and Settings\Melane\Cookies\melane@click01.mivaadcenter[2].txt
C:\Documents and Settings\Melane\Cookies\melane@CAQZSA2V.txt
C:\Documents and Settings\Melane\Cookies\melane@ads.gamersmedia[1].txt
C:\Documents and Settings\Melane\Cookies\melane@tacoda.at.atwola[2].txt
C:\Documents and Settings\Melane\Cookies\melane@trafficmp[2].txt
C:\Documents and Settings\Melane\Cookies\melane@server.iad.liveperson[2].txt
C:\Documents and Settings\Melane\Cookies\melane@publishers.clickbooth[2].txt
C:\Documents and Settings\Melane\Cookies\melane@ads.foodbuzz[3].txt
C:\Documents and Settings\Melane\Cookies\melane@insightexpressai[6].txt
C:\Documents and Settings\Melane\Cookies\melane@www.clickiz[2].txt
C:\Documents and Settings\Melane\Cookies\melane@www.gotrackthis[2].txt
acvs.mediaonenetwork.net [ C:\Documents and Settings\Melane\Application Data\Macromedia\Flash Player\#SharedObjects\WG7BRD3U ]
cdn4.specificclick.net [ C:\Documents and Settings\Melane\Application Data\Macromedia\Flash Player\#SharedObjects\WG7BRD3U ]
cloud.video.unrulymedia.com [ C:\Documents and Settings\Melane\Application Data\Macromedia\Flash Player\#SharedObjects\WG7BRD3U ]
content.oddcast.com [ C:\Documents and Settings\Melane\Application Data\Macromedia\Flash Player\#SharedObjects\WG7BRD3U ]
core.insightexpressai.com [ C:\Documents and Settings\Melane\Application Data\Macromedia\Flash Player\#SharedObjects\WG7BRD3U ]
googleads.g.doubleclick.net [ C:\Documents and Settings\Melane\Application Data\Macromedia\Flash Player\#SharedObjects\WG7BRD3U ]
hs.interpolls.com [ C:\Documents and Settings\Melane\Application Data\Macromedia\Flash Player\#SharedObjects\WG7BRD3U ]
interclick.com [ C:\Documents and Settings\Melane\Application Data\Macromedia\Flash Player\#SharedObjects\WG7BRD3U ]
m1.2mdn.net [ C:\Documents and Settings\Melane\Application Data\Macromedia\Flash Player\#SharedObjects\WG7BRD3U ]
media.foxsports.com.au [ C:\Documents and Settings\Melane\Application Data\Macromedia\Flash Player\#SharedObjects\WG7BRD3U ]
media.mtvnservices.com [ C:\Documents and Settings\Melane\Application Data\Macromedia\Flash Player\#SharedObjects\WG7BRD3U ]
media.perthnow.com.au [ C:\Documents and Settings\Melane\Application Data\Macromedia\Flash Player\#SharedObjects\WG7BRD3U ]
media.resulthost.org [ C:\Documents and Settings\Melane\Application Data\Macromedia\Flash Player\#SharedObjects\WG7BRD3U ]
media.scanscout.com [ C:\Documents and Settings\Melane\Application Data\Macromedia\Flash Player\#SharedObjects\WG7BRD3U ]
media.tattomedia.com [ C:\Documents and Settings\Melane\Application Data\Macromedia\Flash Player\#SharedObjects\WG7BRD3U ]
media1.break.com [ C:\Documents and Settings\Melane\Application Data\Macromedia\Flash Player\#SharedObjects\WG7BRD3U ]
memecounter.com [ C:\Documents and Settings\Melane\Application Data\Macromedia\Flash Player\#SharedObjects\WG7BRD3U ]
msnbcmedia.msn.com [ C:\Documents and Settings\Melane\Application Data\Macromedia\Flash Player\#SharedObjects\WG7BRD3U ]
objects.tremormedia.com [ C:\Documents and Settings\Melane\Application Data\Macromedia\Flash Player\#SharedObjects\WG7BRD3U ]
rmd.atdmt.com [ C:\Documents and Settings\Melane\Application Data\Macromedia\Flash Player\#SharedObjects\WG7BRD3U ]
s0.2mdn.net [ C:\Documents and Settings\Melane\Application Data\Macromedia\Flash Player\#SharedObjects\WG7BRD3U ]
s3media.pleasetakemeto.com [ C:\Documents and Settings\Melane\Application Data\Macromedia\Flash Player\#SharedObjects\WG7BRD3U ]
secure-us.imrworldwide.com [ C:\Documents and Settings\Melane\Application Data\Macromedia\Flash Player\#SharedObjects\WG7BRD3U ]
stat.easydate.biz [ C:\Documents and Settings\Melane\Application Data\Macromedia\Flash Player\#SharedObjects\WG7BRD3U ]
sunshine-coast.finda.com.au [ C:\Documents and Settings\Melane\Application Data\Macromedia\Flash Player\#SharedObjects\WG7BRD3U ]
www.99counters.com [ C:\Documents and Settings\Melane\Application Data\Macromedia\Flash Player\#SharedObjects\WG7BRD3U ]
C:\Documents and Settings\Melane\Cookies\melane@www.ez-tracks[1].txt
C:\Documents and Settings\Melane\Cookies\melane@trvlnet.adbureau[3].txt
C:\Documents and Settings\Melane\Cookies\melane@e-2dj6wfloaodpcbo.stats.esomniture[3].txt
C:\Documents and Settings\Melane\Cookies\melane@content.yieldmanager[5].txt
C:\Documents and Settings\Melane\Cookies\melane@content.yieldmanager[9].txt
C:\Documents and Settings\Melane\Cookies\melane@e-2dj6wdlyskcjwkp.stats.esomniture[2].txt
C:\Documents and Settings\Melane\Cookies\melane@imrworldwide[2].txt
C:\Documents and Settings\Melane\Cookies\melane@content.yieldmanager[1].txt
C:\Documents and Settings\Melane\Cookies\melane@msnbc.112.2o7[2].txt
C:\Documents and Settings\Melane\Cookies\melane@e-2dj6wmkoend5wlo.stats.esomniture[2].txt
C:\Documents and Settings\Melane\Cookies\melane@ads.us.e-planning[1].txt
C:\Documents and Settings\Melane\Cookies\melane@link.mercent[1].txt
C:\Documents and Settings\Melane\Cookies\melane@e-2dj6wnkyehd5skp.stats.esomniture[2].txt
C:\Documents and Settings\Melane\Cookies\melane@content.yieldmanager[6].txt
C:\Documents and Settings\Melane\Cookies\melane@imrworldwide[3].txt
C:\Documents and Settings\Melane\Cookies\melane@content.yieldmanager[2].txt
C:\Documents and Settings\Melane\Cookies\melane@advertising.sheknows[1].txt
C:\Documents and Settings\Melane\Cookies\melane@bannerspace.com[2].txt
C:\Documents and Settings\Melane\Cookies\melane@virginmedia[1].txt
C:\Documents and Settings\Melane\Cookies\melane@ads.bleepingcomputer[2].txt
C:\Documents and Settings\Melane\Cookies\melane@ads.meridiangrouphk[2].txt
C:\Documents and Settings\Melane\Cookies\melane@e-2dj6wfloqhdjgho.stats.esomniture[2].txt
C:\Documents and Settings\Melane\Cookies\melane@e-2dj6wfloaodpcbo.stats.esomniture[1].txt
C:\Documents and Settings\Melane\Cookies\melane@content.yieldmanager[7].txt
C:\Documents and Settings\Melane\Cookies\melane@e-2dj6wak4qiajifp.stats.esomniture[2].txt
C:\Documents and Settings\Melane\Cookies\melane@imrworldwide[4].txt
C:\Documents and Settings\Melane\Cookies\melane@content.yieldmanager[3].txt
C:\Documents and Settings\Melane\Cookies\melane@hearstdigital.122.2o7[1].txt
C:\Documents and Settings\Melane\Cookies\melane@associatedcontent.112.2o7[2].txt
C:\Documents and Settings\Melane\Cookies\melane@associatedcontent.112.2o7[1].txt
C:\Documents and Settings\Melane\Cookies\melane@statsadv.dada[1].txt
C:\Documents and Settings\Melane\Cookies\melane@www8.addfreestats[1].txt
C:\Documents and Settings\Melane\Cookies\melane@www7.addfreestats[2].txt
C:\Documents and Settings\Melane\Cookies\melane@www7.addfreestats[1].txt
C:\Documents and Settings\Melane\Cookies\melane@advertising[3].txt
C:\Documents and Settings\Melane\Cookies\melane@advertising[2].txt
C:\Documents and Settings\Melane\Cookies\melane@advertising[1].txt
C:\Documents and Settings\Melane\Cookies\melane@trvlnet.adbureau[2].txt
C:\Documents and Settings\Melane\Cookies\melane@advertising[4].txt
C:\Documents and Settings\Melane\Cookies\melane@content.yieldmanager[8].txt
C:\Documents and Settings\Melane\Cookies\melane@brandsexclusive.com[2].txt
C:\Documents and Settings\Melane\Cookies\melane@ihg.db.advertising[1].txt
C:\Documents and Settings\Melane\Cookies\melane@tacoda.at.atwola[1].txt
C:\Documents and Settings\Melane\Cookies\melane@imrworldwide[1].txt
C:\Documents and Settings\Melane\Cookies\melane@imrworldwide[5].txt
C:\Documents and Settings\Melane\Cookies\melane@content.yieldmanager[4].txt
C:\Documents and Settings\Melane\Cookies\melane@ads.contactmusic[1].txt
C:\Documents and Settings\Melane\Cookies\melane@www.googleadservices[1].txt
C:\Documents and Settings\Melane\Cookies\melane@www.googleadservices[5].txt
C:\Documents and Settings\Melane\Cookies\melane@www.googleadservices[9].txt
C:\Documents and Settings\Melane\Cookies\melane@dealtime[2].txt
C:\Documents and Settings\Melane\Cookies\melane@e-2dj6wjligkazako.stats.esomniture[2].txt
C:\Documents and Settings\Melane\Cookies\melane@suncorp.122.2o7[1].txt
C:\Documents and Settings\Melane\Cookies\melane@yieldmanager[3].txt
C:\Documents and Settings\Melane\Cookies\melane@user.lucidmedia[1].txt
C:\Documents and Settings\Melane\Cookies\melane@videoegg.adbureau[4].txt
C:\Documents and Settings\Melane\Cookies\melane@videoegg.adbureau[3].txt
C:\Documents and Settings\Melane\Cookies\melane@videoegg.adbureau[2].txt
C:\Documents and Settings\Melane\Cookies\melane@CADXB4SO.txt
C:\Documents and Settings\Melane\Cookies\melane@yadro[2].txt
C:\Documents and Settings\Melane\Cookies\melane@ads.gmodules[1].txt
C:\Documents and Settings\Melane\Cookies\melane@doubleclick[1].txt
C:\Documents and Settings\Melane\Cookies\melane@doubleclick[3].txt
C:\Documents and Settings\Melane\Cookies\melane@doubleclick[2].txt
C:\Documents and Settings\Melane\Cookies\melane@www.googleadservices[2].txt
C:\Documents and Settings\Melane\Cookies\melane@www.googleadservices[6].txt
C:\Documents and Settings\Melane\Cookies\melane@d2.zedo[1].txt
C:\Documents and Settings\Melane\Cookies\melane@247realmedia[1].txt
C:\Documents and Settings\Melane\Cookies\melane@ads.gmodules[2].txt
C:\Documents and Settings\Melane\Cookies\melane@www.trackattack.com[2].txt
C:\Documents and Settings\Melane\Cookies\melane@www.trackattack.com[1].txt
C:\Documents and Settings\Melane\Cookies\melane@ad.yieldmanager[1].txt
C:\Documents and Settings\Melane\Cookies\melane@ad.yieldmanager[2].txt
C:\Documents and Settings\Melane\Cookies\melane@e-2dj6wbmisnd5kho.stats.esomniture[2].txt
C:\Documents and Settings\Melane\Cookies\melane@media.sensis.com[10].txt
C:\Documents and Settings\Melane\Cookies\melane@www.googleadservices[3].txt
C:\Documents and Settings\Melane\Cookies\melane@www.googleadservices[7].txt
C:\Documents and Settings\Melane\Cookies\melane@www.findapart.com[1].txt
C:\Documents and Settings\Melane\Cookies\melane@ads.movember[1].txt
C:\Documents and Settings\Melane\Cookies\melane@dc.tremormedia[1].txt
C:\Documents and Settings\Melane\Cookies\melane@abccountry.net[2].txt
C:\Documents and Settings\Melane\Cookies\melane@ehg-rodale.hitbox[1].txt
C:\Documents and Settings\Melane\Cookies\melane@lego.112.2o7[1].txt
C:\Documents and Settings\Melane\Cookies\melane@yieldmanager[1].txt
C:\Documents and Settings\Melane\Cookies\melane@yieldmanager[5].txt
C:\Documents and Settings\Melane\Cookies\melane@micron.112.2o7[1].txt
C:\Documents and Settings\Melane\Cookies\melane@mywebsearch[2].txt
C:\Documents and Settings\Melane\Cookies\melane@mywebsearch[3].txt
C:\Documents and Settings\Melane\Cookies\melane@mywebsearch[1].txt
C:\Documents and Settings\Melane\Cookies\melane@www.bizrate[2].txt
C:\Documents and Settings\Melane\Cookies\melane@pointroll[5].txt
C:\Documents and Settings\Melane\Cookies\melane@pointroll[4].txt
C:\Documents and Settings\Melane\Cookies\melane@pointroll[3].txt
C:\Documents and Settings\Melane\Cookies\melane@pointroll[2].txt
C:\Documents and Settings\Melane\Cookies\melane@ads.ad4game[3].txt
C:\Documents and Settings\Melane\Cookies\melane@ads.ad4game[2].txt
C:\Documents and Settings\Melane\Cookies\melane@ads.ad4game[1].txt
C:\Documents and Settings\Melane\Cookies\melane@pearson.122.2o7[1].txt
C:\Documents and Settings\Melane\Cookies\melane@e1.cdn.qnsr[2].txt
C:\Documents and Settings\Melane\Cookies\melane@www.googleadservices[4].txt
C:\Documents and Settings\Melane\Cookies\melane@www.googleadservices[8].txt
C:\Documents and Settings\Melane\Cookies\melane@dealtime[1].txt
C:\Documents and Settings\Melane\Cookies\melane@ads.weatherzone.com[2].txt
C:\Documents and Settings\Melane\Cookies\melane@e-2dj6wfkyeidjgao.stats.esomniture[2].txt
C:\Documents and Settings\Melane\Cookies\melane@e-2dj6wfk4ckdjegp.stats.esomniture[2].txt
C:\Documents and Settings\Melane\Cookies\melane@adverts.planbooktravel[1].txt
C:\Documents and Settings\Melane\Cookies\melane@yieldmanager[2].txt
C:\Documents and Settings\Melane\Cookies\melane@advertising[6].txt
C:\Documents and Settings\Melane\Cookies\melane@go.globaladsales[2].txt
C:\Documents and Settings\Melane\Cookies\melane@ads.pointroll[6].txt
C:\Documents and Settings\Melane\Cookies\melane@ads.pointroll[5].txt
C:\Documents and Settings\Melane\Cookies\melane@ads.gmodules[4].txt
C:\Documents and Settings\Melane\Cookies\melane@ads.pointroll[2].txt
C:\Documents and Settings\Melane\Cookies\melane@ads.pointroll[3].txt
C:\Documents and Settings\Melane\Cookies\melane@ads.pointroll[1].txt
C:\Documents and Settings\Melane\Cookies\melane@socialmedia[1].txt
C:\Documents and Settings\Melane\Cookies\melane@reagroup.122.2o7[2].txt
C:\Documents and Settings\Melane\Cookies\melane@ads.associatedcontent[1].txt
C:\Documents and Settings\Melane\Cookies\melane@doubleclick[5].txt
C:\Documents and Settings\Melane\Cookies\melane@columbussearchd.122.2o7[1].txt
C:\Documents and Settings\Melane\Cookies\melane@tourismnt.112.2o7[1].txt
C:\Documents and Settings\Melane\Cookies\melane@oasn04.247realmedia[1].txt
C:\Documents and Settings\Melane\Cookies\melane@smartadserver[1].txt
C:\Documents and Settings\Melane\Cookies\melane@content.yieldmanager[10].txt
C:\Documents and Settings\Melane\Cookies\melane@reagroup.122.2o7[3].txt
C:\Documents and Settings\Melane\Cookies\melane@e-2dj6wnlywhd5oeq.stats.esomniture[2].txt
C:\Documents and Settings\Melane\Cookies\melane@e-2dj6wjnywndpsbo.stats.esomniture[2].txt
C:\Documents and Settings\Melane\Cookies\melane@1.sharkadnetwork[2].txt
C:\Documents and Settings\Melane\Cookies\melane@oddcast[4].txt
C:\Documents and Settings\Melane\Cookies\melane@oddcast[3].txt
C:\Documents and Settings\Melane\Cookies\melane@oddcast[2].txt
C:\Documents and Settings\Melane\Cookies\melane@oddcast[1].txt
C:\Documents and Settings\Melane\Cookies\melane@e-2dj6wmkiamdzogq.stats.esomniture[2].txt
C:\Documents and Settings\Melane\Cookies\melane@myxer.adbureau[1].txt
C:\Documents and Settings\Melane\Cookies\melane@qksrv[2].txt
C:\Documents and Settings\Melane\Cookies\melane@ad.yieldmanager[9].txt
C:\Documents and Settings\Melane\Cookies\melane@ad.yieldmanager[8].txt
C:\Documents and Settings\Melane\Cookies\melane@ad.yieldmanager[7].txt
C:\Documents and Settings\Melane\Cookies\melane@ad.yieldmanager[6].txt
C:\Documents and Settings\Melane\Cookies\melane@ad.yieldmanager[5].txt
C:\Documents and Settings\Melane\Cookies\melane@ad.yieldmanager[4].txt
C:\Documents and Settings\Melane\Cookies\melane@ad.yieldmanager[3].txt
C:\Documents and Settings\Melane\Cookies\melane@e-2dj6wdl4qjc5adp.stats.esomniture[1].txt
C:\Documents and Settings\Melane\Cookies\melane@view.atdmt[2].txt
C:\Documents and Settings\Melane\Cookies\melane@www.burstbeacon[2].txt
C:\Documents and Settings\Melane\Cookies\melane@mywebsearch[8].txt
C:\Documents and Settings\Melane\Cookies\melane@mywebsearch[6].txt
C:\Documents and Settings\Melane\Cookies\melane@mywebsearch[7].txt
C:\Documents and Settings\Melane\Cookies\melane@mywebsearch[5].txt
C:\Documents and Settings\Melane\Cookies\melane@reagroup.122.2o7[1].txt
C:\Documents and Settings\Melane\Cookies\melane@2o7[4].txt
C:\Documents and Settings\Melane\Cookies\melane@2o7[1].txt
C:\Documents and Settings\Melane\Cookies\melane@2o7[2].txt
C:\Documents and Settings\Melane\Cookies\melane@ads.lycos[1].txt
C:\Documents and Settings\Melane\Cookies\melane@ads.lycos[2].txt
C:\Documents and Settings\Melane\Cookies\melane@zanox[2].txt
C:\Documents and Settings\Melane\Cookies\melane@ad1.adtitan[1].txt
C:\Documents and Settings\Melane\Cookies\melane@easyfindguide.com[4].txt
C:\Documents and Settings\Melane\Cookies\melane@easyfindguide.com[2].txt
C:\Documents and Settings\Melane\Cookies\melane@easyfindguide.com[1].txt
C:\Documents and Settings\Melane\Cookies\melane@smileycentral[2].txt
C:\Documents and Settings\Melane\Cookies\melane@smileycentral[1].txt
C:\Documents and Settings\Melane\Cookies\melane@stats.clicktracks[2].txt
C:\Documents and Settings\Melane\Cookies\melane@snapfish.112.2o7[3].txt
C:\Documents and Settings\Melane\Cookies\melane@ehg-bestwestern.hitbox[1].txt
C:\Documents and Settings\Melane\Cookies\melane@ads.networldmedia[1].txt
C:\Documents and Settings\Melane\Cookies\melane@edge.ru4[2].txt
C:\Documents and Settings\Melane\Cookies\melane@tacoda[1].txt
C:\Documents and Settings\Melane\Cookies\melane@tacoda[5].txt
C:\Documents and Settings\Melane\Cookies\melane@ads.associatedcontent[2].txt
C:\Documents and Settings\Melane\Cookies\melane@lucidmedia[1].txt
C:\Documents and Settings\Melane\Cookies\melane@statcounter[3].txt
C:\Documents and Settings\Melane\Cookies\melane@statcounter[4].txt
C:\Documents and Settings\Melane\Cookies\melane@statcounter[1].txt
C:\Documents and Settings\Melane\Cookies\melane@statcounter[2].txt
C:\Documents and Settings\Melane\Cookies\melane@content.yieldmanager[11].txt
C:\Documents and Settings\Melane\Cookies\melane@e-2dj6wjnyeoazwko.stats.esomniture[2].txt
C:\Documents and Settings\Melane\Cookies\melane@snapfish.112.2o7[4].txt
C:\Documents and Settings\Melane\Cookies\melane@s.clickability[2].txt
C:\Documents and Settings\Melane\Cookies\melane@commonsensemedia[1].txt
C:\Documents and Settings\Melane\Cookies\melane@ehg-bestbuy.hitbox[1].txt
C:\Documents and Settings\Melane\Cookies\melane@turnerapac.112.2o7[1].txt
C:\Documents and Settings\Melane\Cookies\melane@ads.basrv[2].txt
C:\Documents and Settings\Melane\Cookies\melane@ads.aussiev8.com[4].txt
C:\Documents and Settings\Melane\Cookies\melane@ibminteractive.122.2o7[1].txt
C:\Documents and Settings\Melane\Cookies\melane@tacoda[2].txt
C:\Documents and Settings\Melane\Cookies\melane@tacoda[6].txt
C:\Documents and Settings\Melane\Cookies\melane@adserv.emailjokes.co[2].txt
C:\Documents and Settings\Melane\Cookies\melane@server.iad.liveperson[5].txt
C:\Documents and Settings\Melane\Cookies\melane@server.iad.liveperson[4].txt
C:\Documents and Settings\Melane\Cookies\melane@server.iad.liveperson[3].txt
C:\Documents and Settings\Melane\Cookies\melane@server.iad.liveperson[1].txt
C:\Documents and Settings\Melane\Cookies\melane@eliteskills[2].txt
C:\Documents and Settings\Melane\Cookies\melane@ads.mediageeks[1].txt
C:\Documents and Settings\Melane\Cookies\melane@snapfish.112.2o7[1].txt
C:\Documents and Settings\Melane\Cookies\melane@snapfish.112.2o7[5].txt
C:\Documents and Settings\Melane\Cookies\melane@acpmagazines.112.2o7[1].txt
C:\Documents and Settings\Melane\Cookies\melane@ads.aussiev8.com[1].txt
C:\Documents and Settings\Melane\Cookies\melane@nursingcenter2.advertserve[1].txt
C:\Documents and Settings\Melane\Cookies\melane@tacoda[3].txt
C:\Documents and Settings\Melane\Cookies\melane@e-2dj6wakoqlc5ehq.stats.esomniture[2].txt
C:\Documents and Settings\Melane\Cookies\melane@e-2dj6wjmyqmcjafo.stats.esomniture[1].txt
C:\Documents and Settings\Melane\Cookies\melane@canoe.112.2o7[1].txt
C:\Documents and Settings\Melane\Cookies\melane@ehg-editorialpro.hitbox[1].txt
C:\Documents and Settings\Melane\Cookies\melane@snapfish.112.2o7[2].txt
C:\Documents and Settings\Melane\Cookies\melane@adserver.adtechus[2].txt
C:\Documents and Settings\Melane\Cookies\melane@ads.aussiev8.com[2].txt
C:\Documents and Settings\Melane\Cookies\melane@adserver.adtechus[3].txt
C:\Documents and Settings\Melane\Cookies\melane@adserver.adtechus[1].txt
C:\Documents and Settings\Melane\Cookies\melane@ads.lycos[4].txt
C:\Documents and Settings\Melane\Cookies\melane@edge.ru4[1].txt
C:\Documents and Settings\Melane\Cookies\melane@revsci[3].txt
C:\Documents and Settings\Melane\Cookies\melane@cantire.122.2o7[1].txt
C:\Documents and Settings\Melane\Cookies\melane@highbeam.122.2o7[4].txt
C:\Documents and Settings\Melane\Cookies\melane@web4.realtracker[1].txt
C:\Documents and Settings\Melane\Cookies\melane@bargainfinda.com[1].txt
C:\Documents and Settings\Melane\Cookies\melane@counter2.hitslink[1].txt
C:\Documents and Settings\Melane\Cookies\melane@statcounter[7].txt
C:\Documents and Settings\Melane\Cookies\melane@statcounter[8].txt
C:\Documents and Settings\Melane\Cookies\melane@statcounter[5].txt
C:\Documents and Settings\Melane\Cookies\melane@statcounter[6].txt
C:\Documents and Settings\Melane\Cookies\melane@usatourist.advertserve[1].txt
C:\Documents and Settings\Melane\Cookies\melane@ru4[3].txt
C:\Documents and Settings\Melane\Cookies\melane@ru4[2].txt
C:\Documents and Settings\Melane\Cookies\melane@hitcountry[1].txt
C:\Documents and Settings\Melane\Cookies\melane@revsci[4].txt
C:\Documents and Settings\Melane\Cookies\melane@wotifcom.112.2o7[1].txt
C:\Documents and Settings\Melane\Cookies\melane@bwired.122.2o7[1].txt
C:\Documents and Settings\Melane\Cookies\melane@e-2dj6wnmieoazohp.stats.esomniture[1].txt
C:\Documents and Settings\Melane\Cookies\melane@nextag[1].txt
C:\Documents and Settings\Melane\Cookies\melane@www.morrisonmedia.com[1].txt
C:\Documents and Settings\Melane\Cookies\melane@highbeam.122.2o7[1].txt
C:\Documents and Settings\Melane\Cookies\melane@e-2dj6wfliokdpido.stats.esomniture[1].txt
C:\Documents and Settings\Melane\Cookies\melane@ehg-artnetworldwide.hitbox[1].txt
C:\Documents and Settings\Melane\Cookies\melane@e-2dj6wjlywkdpgcp.stats.esomniture[2].txt
C:\Documents and Settings\Melane\Cookies\melane@adservx.omg.com[3].txt
C:\Documents and Settings\Melane\Cookies\melane@adservx.omg.com[2].txt
C:\Documents and Settings\Melane\Cookies\melane@adservx.omg.com[1].txt
C:\Documents and Settings\Melane\Cookies\melane@countrymusicchannel.com[2].txt
C:\Documents and Settings\Melane\Cookies\melane@msnportal.112.2o7[1].txt
C:\Documents and Settings\Melane\Cookies\melane@ad-mad.co[1].txt
C:\Documents and Settings\Melane\Cookies\melane@revsci[1].txt
C:\Documents and Settings\Melane\Cookies\melane@stat.dealtime[6].txt
C:\Documents and Settings\Melane\Cookies\melane@stat.dealtime[5].txt
C:\Documents and Settings\Melane\Cookies\melane@stat.dealtime[4].txt
C:\Documents and Settings\Melane\Cookies\melane@stat.dealtime[2].txt
C:\Documents and Settings\Melane\Cookies\melane@revsci[5].txt
C:\Documents and Settings\Melane\Cookies\melane@stat.dealtime[1].txt
C:\Documents and Settings\Melane\Cookies\melane@stat.dealtime[3].txt
C:\Documents and Settings\Melane\Cookies\melane@find.yuku[2].txt
C:\Documents and Settings\Melane\Cookies\melane@wotifcom.112.2o7[2].txt
C:\Documents and Settings\Melane\Cookies\melane@adserve.mizzenmedia[2].txt
C:\Documents and Settings\Melane\Cookies\melane@e-2dj6wcl4opdjefp.stats.esomniture[2].txt
C:\Documents and Settings\Melane\Cookies\melane@highbeam.122.2o7[2].txt
C:\Documents and Settings\Melane\Cookies\melane@network.alluremedia.com[2].txt
C:\Documents and Settings\Melane\Cookies\melane@network.alluremedia.com[1].txt
C:\Documents and Settings\Melane\Cookies\melane@click-fr[2].txt
C:\Documents and Settings\Melane\Cookies\melane@dmtracker[1].txt
C:\Documents and Settings\Melane\Cookies\melane@bravenet[2].txt
C:\Documents and Settings\Melane\Cookies\melane@www.countrymusicchannel.com[2].txt
C:\Documents and Settings\Melane\Cookies\melane@dmtracker[2].txt
C:\Documents and Settings\Melane\Cookies\melane@e-2dj6wjl4egazecp.stats.esomniture[2].txt
C:\Documents and Settings\Melane\Cookies\melane@hitbox[2].txt
C:\Documents and Settings\Melane\Cookies\melane@click.onlinepaysys[1].txt
C:\Documents and Settings\Melane\Cookies\melane@revsci[2].txt
C:\Documents and Settings\Melane\Cookies\melane@e-2dj6wjliuhazeao.stats.esomniture[2].txt
C:\Documents and Settings\Melane\Cookies\melane@msnaccountservices.112.2o7[2].txt
C:\Documents and Settings\Melane\Cookies\melane@highbeam.122.2o7[3].txt
C:\Documents and Settings\Melane\Cookies\melane@adserver[1].txt
C:\Documents and Settings\Melane\Cookies\melane@mediaonenetwork[1].txt
C:\Documents and Settings\Melane\Cookies\melane@acronymfinder[1].txt
C:\Documents and Settings\Melane\Cookies\melane@statse.webtrendslive[7].txt
C:\Documents and Settings\Melane\Cookies\melane@interclick[4].txt
C:\Documents and Settings\Melane\Cookies\melane@clicksor[2].txt
C:\Documents and Settings\Melane\Cookies\melane@plymedia[1].txt
C:\Documents and Settings\Melane\Cookies\melane@aotgroup.122.2o7[1].txt
C:\Documents and Settings\Melane\Cookies\melane@e-2dj6wjkooodpohq.stats.esomniture[2].txt
C:\Documents and Settings\Melane\Cookies\melane@perf.overture[1].txt
C:\Documents and Settings\Melane\Cookies\melane@overture[2].txt
C:\Documents and Settings\Melane\Cookies\melane@overture[6].txt
C:\Documents and Settings\Melane\Cookies\melane@eas.apm.emediate[2].txt
C:\Documents and Settings\Melane\Cookies\melane@searsca.122.2o7[1].txt
C:\Documents and Settings\Melane\Cookies\melane@statse.webtrendslive[4].txt
C:\Documents and Settings\Melane\Cookies\melane@clicksor[3].txt
C:\Documents and Settings\Melane\Cookies\melane@plymedia[2].txt
C:\Documents and Settings\Melane\Cookies\melane@e-2dj6wfmygjc5gdp.stats.esomniture[1].txt
C:\Documents and Settings\Melane\Cookies\melane@aotgroup.122.2o7[2].txt
C:\Documents and Settings\Melane\Cookies\melane@e-2dj6wfkyqkczkaq.stats.esomniture[2].txt
C:\Documents and Settings\Melane\Cookies\melane@e-2dj6wakiamcpidq.stats.esomniture[1].txt
C:\Documents and Settings\Melane\Cookies\melane@ads.clicksor[1].txt
C:\Documents and Settings\Melane\Cookies\melane@overture[3].txt
C:\Documents and Settings\Melane\Cookies\melane@eas.apm.emediate[3].txt
C:\Documents and Settings\Melane\Cookies\melane@media.photobucket[4].txt
C:\Documents and Settings\Melane\Cookies\melane@media.photobucket[2].txt
C:\Documents and Settings\Melane\Cookies\melane@media.photobucket[1].txt
C:\Documents and Settings\Melane\Cookies\melane@msnportal.112.2o7[4].txt
C:\Documents and Settings\Melane\Cookies\melane@msnportal.112.2o7[3].txt
C:\Documents and Settings\Melane\Cookies\melane@msnportal.112.2o7[2].txt
C:\Documents and Settings\Melane\Cookies\melane@e-2dj6wnkiohdpkco.stats.esomniture[2].txt
C:\Documents and Settings\Melane\Cookies\melane@www.adultjokes.co[1].txt
C:\Documents and Settings\Melane\Cookies\melane@stat.dealtime[8].txt
C:\Documents and Settings\Melane\Cookies\melane@statse.webtrendslive[1].txt
C:\Documents and Settings\Melane\Cookies\melane@statse.webtrendslive[5].txt
C:\Documents and Settings\Melane\Cookies\melane@interclick[2].txt
C:\Documents and Settings\Melane\Cookies\melane@clicksor[4].txt
C:\Documents and Settings\Melane\Cookies\melane@e-2dj6wjliqmczkhp.stats.esomniture[2].txt
C:\Documents and Settings\Melane\Cookies\melane@www.babynamescountry[1].txt
C:\Documents and Settings\Melane\Cookies\melane@e-2dj6wfk4ahdpcko.stats.esomniture[1].txt
C:\Documents and Settings\Melane\Cookies\melane@click.cashengines[2].txt
C:\Documents and Settings\Melane\Cookies\melane@overture[4].txt
C:\Documents and Settings\Melane\Cookies\melane@overture[8].txt
C:\Documents and Settings\Melane\Cookies\melane@e-2dj6wmkooidpahq.stats.esomniture[2].txt
C:\Documents and Settings\Melane\Cookies\melane@dmtracker[3].txt
C:\Documents and Settings\Melane\Cookies\melane@dmtracker[4].txt
C:\Documents and Settings\Melane\Cookies\melane@ads.ak.facebook[2].txt
C:\Documents and Settings\Melane\Cookies\melane@e-2dj6wfk4coczehp.stats.esomniture[2].txt
C:\Documents and Settings\Melane\Cookies\melane@specificmedia[2].txt
C:\Documents and Settings\Melane\Cookies\melane@specificmedia[1].txt
C:\Documents and Settings\Melane\Cookies\melane@e-2dj6wmk4glazico.stats.esomniture[2].txt
C:\Documents and Settings\Melane\Cookies\melane@traditionstainedglass.com[2].txt
C:\Documents and Settings\Melane\Cookies\melane@statse.webtrendslive[2].txt
C:\Documents and Settings\Melane\Cookies\melane@interclick[3].txt
C:\Documents and Settings\Melane\Cookies\melane@e-2dj6wmkiqocpghp.stats.esomniture[2].txt
C:\Documents and Settings\Melane\Cookies\melane@ad.sensismediasmart.com[1].txt
C:\Documents and Settings\Melane\Cookies\melane@stats.sitesuite[1].txt
C:\Documents and Settings\Melane\Cookies\melane@ad.sensismediasmart.com[2].txt
C:\Documents and Settings\Melane\Cookies\melane@overture[1].txt
C:\Documents and Settings\Melane\Cookies\melane@overture[5].txt
C:\Documents and Settings\Melane\Cookies\melane@mediaonenetwork[3].txt
C:\Documents and Settings\Melane\Cookies\melane@overture[9].txt
C:\Documents and Settings\Melane\Cookies\melane@kontera[5].txt
C:\Documents and Settings\Melane\Cookies\melane@kontera[3].txt
C:\Documents and Settings\Melane\Cookies\melane@kontera[4].txt
C:\Documents and Settings\Melane\Cookies\melane@kontera[1].txt
C:\Documents and Settings\Melane\Cookies\melane@kontera[2].txt
C:\Documents and Settings\Melane\Cookies\melane@serw.clicksor[1].txt
C:\Documents and Settings\Melane\Cookies\melane@mediaonenetwork[4].txt
C:\Documents and Settings\Melane\Cookies\melane@mediaonenetwork[2].txt
C:\Documents and Settings\Melane\Cookies\melane@e-2dj6wjnysnajwbp.stats.esomniture[1].txt
C:\Documents and Settings\Melane\Cookies\melane@d.mediaforceads[2].txt
C:\Documents and Settings\Melane\Cookies\melane@ads.alhgroup[1].txt
C:\Documents and Settings\Melane\Cookies\melane@gostats[2].txt
C:\Documents and Settings\Melane\Cookies\melane@gostats[1].txt
C:\Documents and Settings\Melane\Cookies\melane@optimize.indieclick[3].txt
C:\Documents and Settings\Melane\Cookies\melane@optimize.indieclick[4].txt
C:\Documents and Settings\Melane\Cookies\melane@optimize.indieclick[1].txt
C:\Documents and Settings\Melane\Cookies\melane@counter.hitslink[2].txt
C:\Documents and Settings\Melane\Cookies\melane@ez-tracks[1].txt
C:\Documents and Settings\Melane\Cookies\melane@hearstmagazines.112.2o7[2].txt
C:\Documents and Settings\Melane\Cookies\melane@hearstmagazines.112.2o7[1].txt
C:\Documents and Settings\Melane\Cookies\melane@adserver.craftbits[2].txt
C:\Documents and Settings\Melane\Cookies\melane@viacom.adbureau[3].txt
C:\Documents and Settings\Melane\Cookies\melane@viacom.adbureau[2].txt
C:\Documents and Settings\Melane\Cookies\melane@readersdigest.122.2o7[1].txt
C:\Documents and Settings\Melane\Cookies\melane@e-2dj6wal4wic5wko.stats.esomniture[2].txt
C:\Documents and Settings\Melane\Cookies\melane@www.finda.com[2].txt
C:\Documents and Settings\Melane\Cookies\melane@www.findstone[2].txt
C:\Documents and Settings\Melane\Cookies\melane@counter.hitslink[3].txt
C:\Documents and Settings\Melane\Cookies\melane@revenue[2].txt
C:\Documents and Settings\Melane\Cookies\melane@cracker.com[1].txt
C:\Documents and Settings\Melane\Cookies\melane@linksynergy[1].txt
C:\Documents and Settings\Melane\Cookies\melane@rotator.adjuggler[1].txt
C:\Documents and Settings\Melane\Cookies\melane@media6degrees[3].txt
C:\Documents and Settings\Melane\Cookies\melane@media6degrees[2].txt
C:\Documents and Settings\Melane\Cookies\melane@media6degrees[1].txt
C:\Documents and Settings\Melane\Cookies\melane@msnservices.112.2o7[2].txt
C:\Documents and Settings\Melane\Cookies\melane@msnservices.112.2o7[1].txt
C:\Documents and Settings\Melane\Cookies\melane@e-2dj6wjlogjc5gdo.stats.esomniture[2].txt
C:\Documents and Settings\Melane\Cookies\melane@media.medhelp[1].txt
C:\Documents and Settings\Melane\Cookies\melane@e-2dj6wnloeld5ebo.stats.esomniture[2].txt
C:\Documents and Settings\Melane\Cookies\melane@tracking.ecorner[1].txt
C:\Documents and Settings\Melane\Cookies\melane@e-2dj6wmlyolc5gdp.stats.esomniture[2].txt
C:\Documents and Settings\Melane\Cookies\melane@advert.spacequad[1].txt
C:\Documents and Settings\Melane\Cookies\melane@ad.sensismediasmart.com[5].txt
C:\Documents and Settings\Melane\Cookies\melane@ad.sensismediasmart.com[4].txt
C:\Documents and Settings\Melane\Cookies\melane@ad.sensismediasmart.com[3].txt
C:\Documents and Settings\Melane\Cookies\melane@invitemedia[3].txt
C:\Documents and Settings\Melane\Cookies\melane@invitemedia[1].txt
C:\Documents and Settings\Melane\Cookies\melane@invitemedia[2].txt
C:\Documents and Settings\Melane\Cookies\melane@counter.surfcounters[1].txt
C:\Documents and Settings\Melane\Cookies\melane@counter.hitslink[1].txt
C:\Documents and Settings\Melane\Cookies\melane@www.technologyquestions[1].txt
C:\Documents and Settings\Melane\Cookies\melane@e-2dj6wjl4chajwbo.stats.esomniture[1].txt
C:\Documents and Settings\Melane\Cookies\melane@paypal.112.2o7[2].txt
C:\Documents and Settings\Melane\Cookies\melane@microsoftwindows.112.2o7[2].txt
C:\Documents and Settings\Melane\Cookies\melane@gossipteen[1].txt
C:\Documents and Settings\Melane\Cookies\melane@femalefirst.co[2].txt
C:\Documents and Settings\Melane\Cookies\melane@csm.rotator.hadj7.adjuggler[1].txt
C:\Documents and Settings\Melane\Cookies\melane@ice.112.2o7[1].txt
C:\Documents and Settings\Melane\Cookies\melane@ice.112.2o7[2].txt
C:\Documents and Settings\Melane\Cookies\melane@roiservice[1].txt
C:\Documents and Settings\Melane\Cookies\melane@collective-media[1].txt
C:\Documents and Settings\Melane\Cookies\melane@collective-media[5].txt
C:\Documents and Settings\Melane\Cookies\melane@paypal.112.2o7[3].txt
C:\Documents and Settings\Melane\Cookies\melane@www.keepingitcountry[1].txt
C:\Documents and Settings\Melane\Cookies\melane@e-2dj6wamiehdpocp.stats.esomniture[2].txt
C:\Documents and Settings\Melane\Cookies\melane@e-2dj6wcliupd5clp.stats.esomniture[1].txt
C:\Documents and Settings\Melane\Cookies\melane@e-2dj6wfkyqld5ifq.stats.esomniture[2].txt
C:\Documents and Settings\Melane\Cookies\melane@e-2dj6wfmyokcjcfo.stats.esomniture[1].txt
C:\Documents and Settings\Melane\Cookies\melane@roiservice[2].txt
C:\Documents and Settings\Melane\Cookies\melane@examinercom.122.2o7[1].txt
C:\Documents and Settings\Melane\Cookies\melane@banners.onlineinnovations[2].txt
C:\Documents and Settings\Melane\Cookies\melane@collective-media[2].txt
C:\Documents and Settings\Melane\Cookies\melane@collective-media[6].txt
C:\Documents and Settings\Melane\Cookies\melane@112.2o7[3].txt
C:\Documents and Settings\Melane\Cookies\melane@112.2o7[2].txt
C:\Documents and Settings\Melane\Cookies\melane@112.2o7[1].txt
C:\Documents and Settings\Melane\Cookies\melane@paypal.112.2o7[4].txt
C:\Documents and Settings\Melane\Cookies\melane@rotator.adjuggler[4].txt
C:\Documents and Settings\Melane\Cookies\melane@rotator.adjuggler[2].txt
C:\Documents and Settings\Melane\Cookies\melane@e-2dj6whmygmcjekq.stats.esomniture[2].txt
C:\Documents and Settings\Melane\Cookies\melane@eb.adbureau[3].txt
C:\Documents and Settings\Melane\Cookies\melane@eb.adbureau[4].txt
C:\Documents and Settings\Melane\Cookies\melane@eb.adbureau[1].txt
C:\Documents and Settings\Melane\Cookies\melane@e-2dj6wbk4gld5efp.stats.esomniture[2].txt
C:\Documents and Settings\Melane\Cookies\melane@prettydisneyteens.wetpaint[2].txt
C:\Documents and Settings\Melane\Cookies\melane@collective-media[3].txt
C:\Documents and Settings\Melane\Cookies\melane@collective-media[7].txt
C:\Documents and Settings\Melane\Cookies\melane@wsclick.infospace[5].txt
C:\Documents and Settings\Melane\Cookies\melane@wsclick.infospace[4].txt
C:\Documents and Settings\Melane\Cookies\melane@wsclick.infospace[3].txt
C:\Documents and Settings\Melane\Cookies\melane@wsclick.infospace[2].txt
C:\Documents and Settings\Melane\Cookies\melane@wsclick.infospace[1].txt
C:\Documents and Settings\Melane\Cookies\melane@paypal.112.2o7[1].txt
C:\Documents and Settings\Melane\Cookies\melane@microsoftwindows.112.2o7[1].txt
C:\Documents and Settings\Melane\Cookies\melane@e-2dj6wfk4ojd5ico.stats.esomniture[2].txt
C:\Documents and Settings\Melane\Cookies\melane@ads.comparison.com[2].txt
C:\Documents and Settings\Melane\Cookies\melane@ads.torrentreactor[2].txt
C:\Documents and Settings\Melane\Cookies\melane@technologyquestions[1].txt
C:\Documents and Settings\Melane\Cookies\melane@freepornhosting[2].txt
C:\Documents and Settings\Melane\Cookies\melane@theadnetwork.com[1].txt
C:\Documents and Settings\Melane\Cookies\melane@www.digital-media.net[2].txt
C:\Documents and Settings\Melane\Cookies\melane@www.edhardydiscount[2].txt
C:\Documents and Settings\Melane\Cookies\melane@ehg-newsinteractive.hitbox[1].txt
C:\Documents and Settings\Melane\Cookies\melane@e-2dj6wjloskazibo.stats.esomniture[1].txt
C:\Documents and Settings\Melane\Cookies\melane@flightcentreltd.122.2o7[1].txt
C:\Documents and Settings\Melane\Cookies\melane@terra.112.2o7[1].txt
C:\Documents and Settings\Melane\Cookies\melane@e-2dj6wdlyskajiap.stats.esomniture[2].txt
C:\Documents and Settings\Melane\Cookies\melane@advertising.ctcproductions.com[1].txt
C:\Documents and Settings\Melane\Cookies\melane@e-2dj6wcl4oocjifo.stats.esomniture[1].txt
C:\Documents and Settings\Melane\Cookies\melane@112.2o7[4].txt
C:\Documents and Settings\Melane\Cookies\melane@ads.healthcare[1].txt
C:\Documents and Settings\Melane\Cookies\melane@helpfindmychild[1].txt
C:\Documents and Settings\Melane\Cookies\melane@e-2dj6whlyendpgap.stats.esomniture[2].txt
C:\Documents and Settings\Melane\Cookies\melane@e-2dj6whl4woczcdp.stats.esomniture[2].txt
C:\Documents and Settings\Melane\Cookies\melane@ehg-legonewyorkinc.hitbox[2].txt
C:\Documents and Settings\Melane\Cookies\melane@casalemedia[1].txt
C:\Documents and Settings\Melane\Cookies\melane@popularscreensavers[1].txt
C:\Documents and Settings\Melane\Cookies\melane@ad.epochtimes[2].txt
C:\Documents and Settings\Melane\Cookies\melane@alexanderinteractive.112.2o7[1].txt
C:\Documents and Settings\Melane\Cookies\melane@liveperson[10].txt
C:\Documents and Settings\Melane\Cookies\melane@www.free-counter.co[2].txt
C:\Documents and Settings\Melane\Cookies\melane@richmedia.yahoo[4].txt
C:\Documents and Settings\Melane\Cookies\melane@richmedia.yahoo[2].txt
C:\Documents and Settings\Melane\Cookies\melane@richmedia.yahoo[3].txt
C:\Documents and Settings\Melane\Cookies\melane@richmedia.yahoo[1].txt
C:\Documents and Settings\Melane\Cookies\melane@e-2dj6wjlikkajweo.stats.esomniture[1].txt
C:\Documents and Settings\Melane\Cookies\melane@www.socialtrack[2].txt
C:\Documents and Settings\Melane\Cookies\melane@clickaider[2].txt
C:\Documents and Settings\Melane\Cookies\melane@bs.serving-sys[1].txt
C:\Documents and Settings\Melane\Cookies\melane@bs.serving-sys[5].txt
C:\Documents and Settings\Melane\Cookies\melane@bs.serving-sys[9].txt
C:\Documents and Settings\Melane\Cookies\melane@stats.paypal[5].txt
C:\Documents and Settings\Melane\Cookies\melane@ads.pubmatic[1].txt
C:\Documents and Settings\Melane\Cookies\melane@sensismediasmart.com[1].txt
C:\Documents and Settings\Melane\Cookies\melane@thefind[1].txt
C:\Documents and Settings\Melane\Cookies\melane@sensismediasmart.com[5].txt
C:\Documents and Settings\Melane\Cookies\melane@in.getclicky[1].txt
C:\Documents and Settings\Melane\Cookies\melane@adecn[6].txt
C:\Documents and Settings\Melane\Cookies\melane@adecn[5].txt
C:\Documents and Settings\Melane\Cookies\melane@adecn[3].txt
C:\Documents and Settings\Melane\Cookies\melane@adecn[2].txt
C:\Documents and Settings\Melane\Cookies\melane@adecn[1].txt
C:\Documents and Settings\Melane\Cookies\melane@campingcountryaustralia.com[1].txt
C:\Documents and Settings\Melane\Cookies\melane@campingcountryaustralia.com[2].txt
C:\Documents and Settings\Melane\Cookies\melane@bs.serving-sys[2].txt
C:\Documents and Settings\Melane\Cookies\melane@bs.serving-sys[6].txt
C:\Documents and Settings\Melane\Cookies\melane@stats.paypal[2].txt
C:\Documents and Settings\Melane\Cookies\melane@ads.pof[1].txt
C:\Documents and Settings\Melane\Cookies\melane@chitika[5].txt
C:\Documents and Settings\Melane\Cookies\melane@atdmt[4].txt
C:\Documents and Settings\Melane\Cookies\melane@chitika[4].txt
C:\Documents and Settings\Melane\Cookies\melane@chitika[3].txt
C:\Documents and Settings\Melane\Cookies\melane@atdmt[2].txt
C:\Documents and Settings\Melane\Cookies\melane@chitika[6].txt
C:\Documents and Settings\Melane\Cookies\melane@atdmt[1].txt
C:\Documents and Settings\Melane\Cookies\melane@chitika[1].txt
C:\Documents and Settings\Melane\Cookies\melane@burstnet[1].txt
C:\Documents and Settings\Melane\Cookies\melane@chitika[2].txt
C:\Documents and Settings\Melane\Cookies\melane@atdmt[5].txt
C:\Documents and Settings\Melane\Cookies\melane@burstnet[5].txt
C:\Documents and Settings\Melane\Cookies\melane@kanoodle[1].txt
C:\Documents and Settings\Melane\Cookies\melane@sensismediasmart.com[2].txt
C:\Documents and Settings\Melane\Cookies\melane@sensismediasmart.com[6].txt
C:\Documents and Settings\Melane\Cookies\melane@in.getclicky[2].txt
C:\Documents and Settings\Melane\Cookies\melane@terra.112.2o7[2].txt
C:\Documents and Settings\Melane\Cookies\melane@e-2dj6wmmianc5kfq.stats.esomniture[2].txt
C:\Documents and Settings\Melane\Cookies\melane@bs.serving-sys[3].txt
C:\Documents and Settings\Melane\Cookies\melane@bs.serving-sys[7].txt
C:\Documents and Settings\Melane\Cookies\melane@e-2dj6wgkoqndpkdo.stats.esomniture[2].txt
C:\Documents and Settings\Melane\Cookies\melane@ads.ourstage[2].txt
C:\Documents and Settings\Melane\Cookies\melane@stats.paypal[3].txt
C:\Documents and Settings\Melane\Cookies\melane@ads.pubmatic[3].txt
C:\Documents and Settings\Melane\Cookies\melane@azjmp[4].txt
C:\Documents and Settings\Melane\Cookies\melane@azjmp[3].txt
C:\Documents and Settings\Melane\Cookies\melane@azjmp[2].txt
C:\Documents and Settings\Melane\Cookies\melane@imperium.adbureau[2].txt
C:\Documents and Settings\Melane\Cookies\melane@burstnet[2].txt
C:\Documents and Settings\Melane\Cookies\melane@kanoodle[2].txt
C:\Documents and Settings\Melane\Cookies\melane@e-2dj6wgmigmd5cgq.stats.esomniture[2].txt
C:\Documents and Settings\Melane\Cookies\melane@sensismediasmart.com[3].txt
C:\Documents and Settings\Melane\Cookies\melane@adxpose[1].txt
C:\Documents and Settings\Melane\Cookies\melane@legolas-media[2].txt
C:\Documents and Settings\Melane\Cookies\melane@casalemedia[6].txt
C:\Documents and Settings\Melane\Cookies\melane@casalemedia[5].txt
C:\Documents and Settings\Melane\Cookies\melane@casalemedia[3].txt
C:\Documents and Settings\Melane\Cookies\melane@casalemedia[2].txt
C:\Documents and Settings\Melane\Cookies\melane@adserver.racq.com[1].txt
C:\Documents and Settings\Melane\Cookies\melane@clickaider[1].txt
C:\Documents and Settings\Melane\Cookies\melane@www.qksrv[1].txt
C:\Documents and Settings\Melane\Cookies\melane@bs.serving-sys[4].txt
C:\Documents and Settings\Melane\Cookies\melane@bs.serving-sys[8].txt
C:\Documents and Settings\Melane\Cookies\melane@e-2dj6wnkisgcjcko.stats.esomniture[2].txt
C:\Documents and Settings\Melane\Cookies\melane@stats.paypal[4].txt
C:\Documents and Settings\Melane\Cookies\melane@www.qksrv[2].txt
C:\Documents and Settings\Melane\Cookies\melane@adbrite[4].txt
C:\Documents and Settings\Melane\Cookies\melane@adbrite[3].txt
C:\Documents and Settings\Melane\Cookies\melane@adbrite[2].txt
C:\Documents and Settings\Melane\Cookies\melane@adbrite[5].txt
C:\Documents and Settings\Melane\Cookies\melane@adbrite[1].txt
C:\Documents and Settings\Melane\Cookies\melane@richmedia.yahoo[6].txt
C:\Documents and Settings\Melane\Cookies\melane@burstnet[3].txt
C:\Documents and Settings\Melane\Cookies\melane@sensismediasmart.com[4].txt
C:\Documents and Settings\Melane\Cookies\melane@e-2dj6wfl4spd5sco.stats.esomniture[1].txt
C:\Documents and Settings\Melane\Cookies\melane@mediaplex[6].txt
C:\Documents and Settings\Melane\Cookies\melane@mediaplex[7].txt
C:\Documents and Settings\Melane\Cookies\melane@mediaplex[4].txt
C:\Documents and Settings\Melane\Cookies\melane@mediaplex[2].txt
C:\Documents and Settings\Melane\Cookies\melane@mediaplex[3].txt
C:\Documents and Settings\Melane\Cookies\melane@mediaplex[1].txt
C:\Documents and Settings\Melane\Cookies\melane@tracking.fastbooking[1].txt
C:\Documents and Settings\Melane\Cookies\melane@zedo[4].txt
C:\Documents and Settings\Melane\Cookies\melane@digital-media.net[1].txt
C:\Documents and Settings\Melane\Cookies\melane@xm.xtendmedia[3].txt
C:\Documents and Settings\Melane\Cookies\melane@xm.xtendmedia[1].txt
C:\Documents and Settings\Melane\Cookies\melane@cba.122.2o7[1].txt
C:\Documents and Settings\Melane\Cookies\melane@adserver.productreview.com[1].txt
C:\Documents and Settings\Melane\Cookies\melane@metroleap.rotator.hadj7.adjuggler[5].txt
C:\Documents and Settings\Melane\Cookies\melane@metroleap.rotator.hadj7.adjuggler[4].txt
C:\Documents and Settings\Melane\Cookies\melane@metroleap.rotator.hadj7.adjuggler[3].txt
C:\Documents and Settings\Melane\Cookies\melane@metroleap.rotator.hadj7.adjuggler[2].txt
C:\Documents and Settings\Melane\Cookies\melane@metroleap.rotator.hadj7.adjuggler[1].txt
C:\Documents and Settings\Melane\Cookies\melane@campingcountryaustralia.com[3].txt
C:\Documents and Settings\Melane\Cookies\melane@zedo[1].txt
C:\Documents and Settings\Melane\Cookies\melane@adtech.staticwhich.co[2].txt
C:\Documents and Settings\Melane\Cookies\melane@ads.cnn[2].txt
C:\Documents and Settings\Melane\Cookies\melane@ads.ibibo[2].txt
C:\Documents and Settings\Melane\Cookies\melane@sbsaustralia.112.2o7[1].txt
C:\Documents and Settings\Melane\Cookies\melane@adserver.productreview.com[2].txt
C:\Documents and Settings\Melane\Cookies\melane@myroitracking[4].txt
C:\Documents and Settings\Melane\Cookies\melane@myroitracking[3].txt
C:\Documents and Settings\Melane\Cookies\melane@myroitracking[2].txt
C:\Documents and Settings\Melane\Cookies\melane@urladserver3--mobileactive--com.rtrk.com[2].txt
C:\Documents and Settings\Melane\Cookies\melane@zedo[2].txt
C:\Documents and Settings\Melane\Cookies\melane@serving-sys[10].txt
C:\Documents and Settings\Melane\Cookies\melane@ads.foodbuzz[1].txt
C:\Documents and Settings\Melane\Cookies\melane@microsoftsto.112.2o7[1].txt
C:\Documents and Settings\Melane\Cookies\melane@m1.webstats.motigo[1].txt
C:\Documents and Settings\Melane\Cookies\melane@tattoofinder[1].txt
C:\Documents and Settings\Melane\Cookies\melane@zedo[3].txt
C:\Documents and Settings\Melane\Cookies\melane@www.qsstats[2].txt
C:\Documents and Settings\Melane\Cookies\melane@www.qsstats[1].txt
C:\Documents and Settings\Melane\Cookies\melane@serving-sys[11].txt
C:\Documents and Settings\Melane\Cookies\melane@adbrite[6].txt
C:\Documents and Settings\Melane\Cookies\melane@babynamescountry[2].txt
C:\Documents and Settings\Melane\Cookies\melane@tdstats[1].txt
C:\Documents and Settings\Melane\Cookies\melane@www.etracker.com[2].txt
C:\Documents and Settings\Melane\Cookies\melane@www.jiscdigitalmedia.ac[1].txt
C:\Documents and Settings\Melane\Cookies\melane@ads.undertone[3].txt
C:\Documents and Settings\Melane\Cookies\melane@ads.undertone[1].txt
C:\Documents and Settings\Melane\Cookies\melane@eharmony.112.2o7[1].txt
C:\Documents and Settings\Melane\Cookies\melane@www.smileycentral[1].txt
C:\Documents and Settings\Melane\Cookies\melane@adserver.productreview.com[4].txt
C:\Documents and Settings\Melane\Cookies\melane@jiscdigitalmedia.ac[1].txt
C:\Documents and Settings\Melane\Cookies\melane@hearstugo.112.2o7[1].txt
C:\Documents and Settings\Melane\Cookies\melane@hearstugo.112.2o7[2].txt
C:\Documents and Settings\Melane\Cookies\melane@ads.trutv[1].txt
C:\Documents and Settings\Melane\Cookies\melane@sixapart.adbureau[1].txt
C:\Documents and Settings\Melane\Cookies\melane@adserver.flossiemediagroup[2].txt
C:\Documents and Settings\Melane\Cookies\melane@xiti[2].txt
C:\Documents and Settings\Melane\Cookies\melane@pathfinder.bestwestern.com[1].txt
C:\Documents and Settings\Melane\Cookies\melane@timeinc.122.2o7[1].txt
C:\Documents and Settings\Melane\Cookies\melane@www.googleadservices[11].txt
C:\Documents and Settings\Melane\Cookies\melane@www.googleadservices[10].txt
C:\Documents and Settings\Melane\Cookies\melane@apmebf[3].txt
C:\Documents and Settings\Melane\Cookies\melane@apmebf[7].txt
C:\Documents and Settings\Melane\Cookies\melane@ads.gamesbannernet[3].txt
C:\Documents and Settings\Melane\Cookies\melane@e-2dj6wjmyugcjsho.stats.esomniture[2].txt
C:\Documents and Settings\Melane\Cookies\melane@www.backcountry[1].txt
C:\Documents and Settings\Melane\Cookies\melane@media.mtvnservices[2].txt
C:\Documents and Settings\Melane\Cookies\melane@xiti[3].txt
C:\Documents and Settings\Melane\Cookies\melane@keepingitcountry[1].txt
C:\Documents and Settings\Melane\Cookies\melane@ad.allvoices[1].txt
C:\Documents and Settings\Melane\Cookies\melane@ads.intergi[1].txt
C:\Documents and Settings\Melane\Cookies\melane@apmebf[4].txt
C:\Documents and Settings\Melane\Cookies\melane@viator.122.2o7[1].txt
C:\Documents and Settings\Melane\Cookies\melane@qnsr[2].txt
C:\Documents and Settings\Melane\Cookies\melane@e-2dj6whmiehczkcq.stats.esomniture[2].txt
C:\Documents and Settings\Melane\Cookies\melane@xiti[4].txt
C:\Documents and Settings\Melane\Cookies\melane@adtech[1].txt
C:\Documents and Settings\Melane\Cookies\melane@media.mtvnservices[3].txt
C:\Documents and Settings\Melane\Cookies\melane@tracker.adjump[1].txt
C:\Documents and Settings\Melane\Cookies\melane@e-2dj6wfmyspdjodp.stats.esomniture[1].txt
C:\Documents and Settings\Melane\Cookies\melane@e-2dj6wmmyemcpkco.stats.esomniture[2].txt
C:\Documents and Settings\Melane\Cookies\melane@e-2dj6wjk4ujd5olo.stats.esomniture[1].txt
C:\Documents and Settings\Melane\Cookies\melane@apmebf[1].txt
C:\Documents and Settings\Melane\Cookies\melane@apmebf[5].txt
C:\Documents and Settings\Melane\Cookies\melane@ads.gamesbannernet[1].txt
C:\Documents and Settings\Melane\Cookies\melane@e-2dj6wclokid5elp.stats.esomniture[2].txt
C:\Documents and Settings\Melane\Cookies\melane@adtech[2].txt
C:\Documents and Settings\Melane\Cookies\melane@e-2dj6wgkockd5igo.stats.esomniture[2].txt
C:\Documents and Settings\Melane\Cookies\melane@cnetaustralia.122.2o7[2].txt
C:\Documents and Settings\Melane\Cookies\melane@cnetaustralia.122.2o7[1].txt
C:\Documents and Settings\Melane\Cookies\melane@xiti[1].txt
C:\Documents and Settings\Melane\Cookies\melane@e-2dj6wjk4ujd5olo.stats.esomniture[2].txt
C:\Documents and Settings\Melane\Cookies\melane@e-2dj6wgkisod5mbp.stats.esomniture[2].txt
C:\Documents and Settings\Melane\Cookies\melane@e-2dj6wjmycjdjeho.stats.esomniture[2].txt
C:\Documents and Settings\Melane\Cookies\melane@apmebf[2].txt
C:\Documents and Settings\Melane\Cookies\melane@ads.undertone[4].txt
C:\Documents and Settings\Melane\Cookies\melane@backstageweb.122.2o7[1].txt
C:\Documents and Settings\Melane\Cookies\melane@media.theage.com[1].txt
C:\Documents and Settings\Melane\Cookies\melane@mediasite.eq.edu[1].txt
C:\Documents and Settings\Melane\Cookies\melane@atwola[2].txt
C:\Documents and Settings\Melane\Cookies\melane@liveperson[4].txt
C:\Documents and Settings\Melane\Cookies\melane@ads.telegraph.co[2].txt
C:\Documents and Settings\Melane\Cookies\melane@tribalfusion[2].txt
C:\Documents and Settings\Melane\Cookies\melane@tribalfusion[6].txt
C:\Documents and Settings\Melane\Cookies\melane@ads.adk2[1].txt
C:\Documents and Settings\Melane\Cookies\melane@www.burstnet[1].txt
C:\Documents and Settings\Melane\Cookies\melane@e-2dj6wnloqgazsdo.stats.esomniture[1].txt
C:\Documents and Settings\Melane\Cookies\melane@tripod[1].txt
C:\Documents and Settings\Melane\Cookies\melane@cdn1.trafficmp[2].txt
C:\Documents and Settings\Melane\Cookies\melane@mediatraffic[1].txt
C:\Documents and Settings\Melane\Cookies\melane@www.backcountry[2].txt
C:\Documents and Settings\Melane\Cookies\melane@e-2dj6wbloeocjakp.stats.esomniture[2].txt
C:\Documents and Settings\Melane\Cookies\melane@atwola[3].txt
C:\Documents and Settings\Melane\Cookies\melane@liveperson[1].txt
C:\Documents and Settings\Melane\Cookies\melane@liveperson[5].txt
C:\Documents and Settings\Melane\Cookies\melane@count.brat-online[1].txt
C:\Documents and Settings\Melane\Cookies\melane@liveperson[9].txt
C:\Documents and Settings\Melane\Cookies\melane@tribalfusion[3].txt
C:\Documents and Settings\Melane\Cookies\melane@serving-sys[4].txt
C:\Documents and Settings\Melane\Cookies\melane@serving-sys[5].txt
C:\Documents and Settings\Melane\Cookies\melane@serving-sys[2].txt
C:\Documents and Settings\Melane\Cookies\melane@serving-sys[3].txt
C:\Documents and Settings\Melane\Cookies\melane@tribalfusion[7].txt
C:\Documents and Settings\Melane\Cookies\melane@serving-sys[1].txt
C:\Documents and Settings\Melane\Cookies\melane@www.burstnet[2].txt
C:\Documents and Settings\Melane\Cookies\melane@tripod[2].txt
C:\Documents and Settings\Melane\Cookies\melane@adserver.mxtabs[2].txt
C:\Documents and Settings\Melane\Cookies\melane@www.timedial[2].txt
C:\Documents and Settings\Melane\Cookies\melane@stat.onestat[1].txt
C:\Documents and Settings\Melane\Cookies\melane@finda.com[2].txt
C:\Documents and Settings\Melane\Cookies\melane@e-2dj6wjnyckc5geo.stats.esomniture[1].txt
C:\Documents and Settings\Melane\Cookies\melane@finda.com[4].txt
C:\Documents and Settings\Melane\Cookies\melane@finda.com[1].txt
C:\Documents and Settings\Melane\Cookies\melane@premiumtv.122.2o7[2].txt
C:\Documents and Settings\Melane\Cookies\melane@premiumtv.122.2o7[1].txt
C:\Documents and Settings\Melane\Cookies\melane@liveperson[2].txt
C:\Documents and Settings\Melane\Cookies\melane@findstone[2].txt
C:\Documents and Settings\Melane\Cookies\melane@liveperson[6].txt
C:\Documents and Settings\Melane\Cookies\melane@marthastewart.122.2o7[1].txt
C:\Documents and Settings\Melane\Cookies\melane@tribalfusion[4].txt
C:\Documents and Settings\Melane\Cookies\melane@tribalfusion[8].txt
C:\Documents and Settings\Melane\Cookies\melane@ads.adk2[3].txt
C:\Documents and Settings\Melane\Cookies\melane@www.burstnet[3].txt
C:\Documents and Settings\Melane\Cookies\melane@e-2dj6wmlicjdjkkp.stats.esomniture[2].txt
C:\Documents and Settings\Melane\Cookies\melane@philips.112.2o7[1].txt
C:\Documents and Settings\Melane\Cookies\melane@e-2dj6wclyeocpcdp.stats.esomniture[1].txt
C:\Documents and Settings\Melane\Cookies\melane@stat.onestat[2].txt
C:\Documents and Settings\Melane\Cookies\melane@e-2dj6wdlocjdjgbo.stats.esomniture[2].txt
C:\Documents and Settings\Melane\Cookies\melane@atwola[1].txt
C:\Documents and Settings\Melane\Cookies\melane@e-2dj6wclykkdpgko.stats.esomniture[2].txt
C:\Documents and Settings\Melane\Cookies\melane@liveperson[3].txt
C:\Documents and Settings\Melane\Cookies\melane@ads.adap[1].txt
C:\Documents and Settings\Melane\Cookies\melane@liveperson[7].txt
C:\Documents and Settings\Melane\Cookies\melane@ads.telegraph.co[1].txt
C:\Documents and Settings\Melane\Cookies\melane@media.efarming.com[1].txt
C:\Documents and Settings\Melane\Cookies\melane@tribalfusion[1].txt
C:\Documents and Settings\Melane\Cookies\melane@tribalfusion[5].txt
C:\Documents and Settings\Melane\Cookies\melane@tribalfusion[9].txt
C:\Documents and Settings\Melane\Cookies\melane@e-2dj6wjlysldjwco.stats.esomniture[1].txt
C:\Documents and Settings\Melane\Cookies\melane@fastclick[4].txt
C:\Documents and Settings\Melane\Cookies\melane@fastclick[3].txt
C:\Documents and Settings\Melane\Cookies\melane@fastclick[2].txt
C:\Documents and Settings\Melane\Cookies\melane@www.burstnet[4].txt
C:\Documents and Settings\Melane\Cookies\melane@fastclick[5].txt
C:\Documents and Settings\Melane\Cookies\melane@tripod[4].txt
C:\Documents and Settings\Melane\Cookies\melane@ad.sbnation[2].txt
C:\Documents and Settings\Melane\Cookies\melane@a1.interclick[2].txt
C:\Documents and Settings\Melane\Cookies\melane@travelcomau.112.2o7[2].txt
C:\Documents and Settings\Melane\Cookies\melane@travelcomau.112.2o7[1].txt
C:\Documents and Settings\Melane\Cookies\melane@lfstmedia[2].txt
C:\Documents and Settings\Melane\Cookies\melane@server.cpmstar[2].txt
C:\Documents and Settings\Melane\Cookies\melane@ads.apn.co[3].txt
C:\Documents and Settings\Melane\Cookies\melane@media.adfrontiers[1].txt
C:\Documents and Settings\Melane\Cookies\melane@edhardydiscount[2].txt
C:\Documents and Settings\Melane\Cookies\melane@surveymonkey.122.2o7[2].txt
C:\Documents and Settings\Melane\Cookies\melane@sales.liveperson[4].txt
C:\Documents and Settings\Melane\Cookies\melane@e-2dj6wfkoehcpoao.stats.esomniture[1].txt
C:\Documents and Settings\Melane\Cookies\melane@questionmarket[1].txt
C:\Documents and Settings\Melane\Cookies\melane@f2network.112.2o7[3].txt
C:\Documents and Settings\Melane\Cookies\melane@f2network.112.2o7[4].txt
C:\Documents and Settings\Melane\Cookies\melane@f2network.112.2o7[1].txt
C:\Documents and Settings\Melane\Cookies\melane@f2network.112.2o7[2].txt
C:\Documents and Settings\Melane\Cookies\melane@server.cpmstar[3].txt
C:\Documents and Settings\Melane\Cookies\melane@e-2dj6wgkyumcjsbp.stats.esomniture[2].txt
C:\Documents and Settings\Melane\Cookies\melane@ads.apn.co[4].txt
C:\Documents and Settings\Melane\Cookies\melane@e-2dj6wgkokhdzido.stats.esomniture[1].txt
C:\Documents and Settings\Melane\Cookies\melane@viacomedycentralrl.112.2o7[1].txt
C:\Documents and Settings\Melane\Cookies\melane@serving-sys[8].txt
C:\Documents and Settings\Melane\Cookies\melane@serving-sys[9].txt
C:\Documents and Settings\Melane\Cookies\melane@serving-sys[6].txt
C:\Documents and Settings\Melane\Cookies\melane@serving-sys[7].txt
C:\Documents and Settings\Melane\Cookies\melane@e-2dj6wjkykndpsdo.stats.esomniture[2].txt
C:\Documents and Settings\Melane\Cookies\melane@surveymonkey.122.2o7[3].txt
C:\Documents and Settings\Melane\Cookies\melane@merrillcorp.112.2o7[1].txt
C:\Documents and Settings\Melane\Cookies\melane@sales.liveperson[1].txt
C:\Documents and Settings\Melane\Cookies\melane@sales.liveperson[5].txt
C:\Documents and Settings\Melane\Cookies\melane@e-2dj6wmlicmdpelp.stats.esomniture[1].txt
C:\Documents and Settings\Melane\Cookies\melane@questionmarket[2].txt
C:\Documents and Settings\Melane\Cookies\melane@questionmarket[6].txt
C:\Documents and Settings\Melane\Cookies\melane@indextools[2].txt
C:\Documents and Settings\Melane\Cookies\melane@ads.apn.co[1].txt
C:\Documents and Settings\Melane\Cookies\melane@at.atwola[2].txt
C:\Documents and Settings\Melane\Cookies\melane@at.atwola[1].txt
C:\Documents and Settings\Melane\Cookies\melane@www.3dstats[1].txt
C:\Documents and Settings\Melane\Cookies\melane@e-2dj6wnkiahazkep.stats.esomniture[2].txt
C:\Documents and Settings\Melane\Cookies\melane@adsrevenue[1].txt
C:\Documents and Settings\Melane\Cookies\melane@e-2dj6wbmyqld5mfp.stats.esomniture[1].txt
C:\Documents and Settings\Melane\Cookies\melane@specificclick[2].txt
C:\Documents and Settings\Melane\Cookies\melane@specificclick[1].txt
C:\Documents and Settings\Melane\Cookies\melane@specificclick[3].txt
C:\Documents and Settings\Melane\Cookies\melane@e-2dj6wjlyehcpilq.stats.esomniture[2].txt
C:\Documents and Settings\Melane\Cookies\melane@pro-market[1].txt
C:\Documents and Settings\Melane\Cookies\melane@sales.liveperson[6].txt
C:\Documents and Settings\Melane\Cookies\melane@e-2dj6wfkykhdzcap.stats.esomniture[2].txt
C:\Documents and Settings\Melane\Cookies\melane@questionmarket[3].txt
C:\Documents and Settings\Melane\Cookies\melane@questionmarket[7].txt
C:\Documents and Settings\Melane\Cookies\melane@nextag.com[2].txt
C:\Documents and Settings\Melane\Cookies\melane@ads.cartoonnetwork[1].txt
C:\Documents and Settings\Melane\Cookies\melane@ads.realtechnetwork[2].txt
C:\Documents and Settings\Melane\Cookies\melane@ads.apn.co[2].txt
C:\Documents and Settings\Melane\Cookies\melane@www.femalefirst.co[1].txt
C:\Documents and Settings\Melane\Cookies\melane@fastclick[9].txt
C:\Documents and Settings\Melane\Cookies\melane@fastclick[8].txt
C:\Documents and Settings\Melane\Cookies\melane@fastclick[7].txt
C:\Documents and Settings\Melane\Cookies\melane@fastclick[6].txt
C:\Documents and Settings\Melane\Cookies\melane@adviva[1].txt
C:\Documents and Settings\Melane\Cookies\melane@ads.veoh[1].txt
C:\Documents and Settings\Melane\Cookies\melane@surveymonkey.122.2o7[1].txt
C:\Documents and Settings\Melane\Cookies\melane@bizrate[3].txt
C:\Documents and Settings\Melane\Cookies\melane@bizrate[1].txt
C:\Documents and Settings\Melane\Cookies\melane@bizrate[2].txt
C:\Documents and Settings\Melane\Cookies\melane@e-2dj6wbmiclc5cgp.stats.esomniture[2].txt
C:\Documents and Settings\Melane\Cookies\melane@sales.liveperson[3].txt
C:\Documents and Settings\Melane\Cookies\melane@medhelpinternational.112.2o7[1].txt
C:\Documents and Settings\Melane\Cookies\melane@questionmarket[4].txt
C:\Documents and Settings\Melane\Cookies\melane@lfstmedia[3].txt
C:\Documents and Settings\Melane\Cookies\melane@members.tripod[1].txt
C:\Documents and Settings\Melane\Cookies\melane@clickbank[2].txt
C:\Documents and Settings\Melane\Cookies\melane@clickbank[1].txt
C:\Documents and Settings\Melane\Cookies\melane@www.hitcountry[1].txt
C:\Documents and Settings\Melane\Cookies\melane@adserver.adreactor[1].txt
C:\Documents and Settings\Melane\Cookies\melane@media.sensis.com[3].txt
C:\Documents and Settings\Melane\Cookies\melane@media.sensis.com[7].txt
C:\Documents and Settings\Melane\Cookies\melane@f2network.112.2o7[5].txt
C:\Documents and Settings\Melane\Cookies\melane@trafficmp[3].txt
C:\Documents and Settings\Melane\Cookies\melane@trafficmp[1].txt
C:\Documents and Settings\Melane\Cookies\melane@traveladvertising[1].txt
C:\Documents and Settings\Melane\Cookies\melane@findarticles[1].txt
C:\Documents and Settings\Melane\Cookies\melane@backcountry[1].txt
C:\Documents and Settings\Melane\Cookies\melane@adserver.adreactor[2].txt
C:\Documents and Settings\Melane\Cookies\melane@e-2dj6wblokhc5ihp.stats.esomniture[1].txt
C:\Documents and Settings\Melane\Cookies\melane@media.sensis.com[4].txt
C:\Documents and Settings\Melane\Cookies\melane@at.atwola[5].txt
C:\Documents and Settings\Melane\Cookies\melane@at.atwola[6].txt
C:\Documents and Settings\Melane\Cookies\melane@at.atwola[4].txt
C:\Documents and Settings\Melane\Cookies\melane@specificclick[6].txt
C:\Documents and Settings\Melane\Cookies\melane@specificclick[4].txt
C:\Documents and Settings\Melane\Cookies\melane@adserver.adreactor[3].txt
C:\Documents and Settings\Melane\Cookies\melane@ad1.clickhype[1].txt
C:\Documents and Settings\Melane\Cookies\melane@media.sensis.com[1].txt
C:\Documents and Settings\Melane\Cookies\melane@media.sensis.com[5].txt
C:\Documents and Settings\Melane\Cookies\melane@media.sensis.com[9].txt
C:\Documents and Settings\Melane\Cookies\melane@ads.anvato[1].txt
C:\Documents and Settings\Melane\Cookies\melane@randomhouse.122.2o7[1].txt
C:\Documents and Settings\Melane\Cookies\melane@phg.hitbox[1].txt
C:\Documents and Settings\Melane\Cookies\melane@cbsdigitalmedia.112.2o7[1].txt
C:\Documents and Settings\Melane\Cookies\melane@findarticles[3].txt
C:\Documents and Settings\Melane\Cookies\melane@adserver.adreactor[4].txt
C:\Documents and Settings\Melane\Cookies\melane@ads.admaxasia[1].txt
C:\Documents and Settings\Melane\Cookies\melane@bizrate[5].txt
C:\Documents and Settings\Melane\Cookies\melane@media.sensis.com[2].txt
C:\Documents and Settings\Melane\Cookies\melane@media.sensis.com[6].txt
C:\Documents and Settings\Melane\Cookies\melane@e-2dj6wgmychcpwhq.stats.esomniture[2].txt
C:\Documents and Settings\Melane\Cookies\melane@ads.fulldls[1].txt
C:\Documents and Settings\Melane\Cookies\melane@tripod.lycos[2].txt
C:\Documents and Settings\Melane\Cookies\melane@shopping.112.2o7[1].txt
C:\Documents and Settings\Melane\Cookies\melane@tns-counter[1].txt
C:\Documents and Settings\Melane\Cookies\melane@avgtechnologies.112.2o7[4].txt
C:\Documents and Settings\Melane\Cookies\melane@avgtechnologies.112.2o7[3].txt
C:\Documents and Settings\Melane\Cookies\melane@avgtechnologies.112.2o7[2].txt
C:\Documents and Settings\Melane\Cookies\melane@avgtechnologies.112.2o7[1].txt
C:\Documents and Settings\Melane\Cookies\melane@affiliates.hottopicmedia[2].txt
C:\Documents and Settings\Melane\Cookies\melane@insightexpressai[3].txt
C:\Documents and Settings\Melane\Cookies\melane@cdn5.specificclick[2].txt
C:\Documents and Settings\Melane\Cookies\melane@cdn4.specificclick[2].txt
C:\Documents and Settings\Melane\Cookies\melane@msnbc.112.2o7[1].txt
C:\Documents and Settings\Melane\Cookies\melane@adply.plymedia[3].txt
C:\Documents and Settings\Melane\Cookies\melane@ads.techguy[2].txt
C:\Documents and Settings\Melane\Cookies\melane@oztracktuning[1].txt
C:\Documents and Settings\Melane\Cookies\melane@agl.122.2o7[1].txt
C:\Documents and Settings\Melane\Cookies\melane@ads.addynamix[1].txt
C:\Documents and Settings\Melane\Cookies\melane@shopping.112.2o7[2].txt
C:\Documents and Settings\Melane\Cookies\melane@e-2dj6wgmycicjwlp.stats.esomniture[2].txt
C:\Documents and Settings\Melane\Cookies\melane@ads.songlyrics[1].txt
C:\Documents and Settings\Melane\Cookies\melane@inl.adbureau[1].txt
C:\Documents and Settings\Melane\Cookies\melane@trinitymirror.112.2o7[1].txt
C:\Documents and Settings\Melane\Cookies\melane@insightexpressai[4].txt
C:\Documents and Settings\Melane\Cookies\melane@tradedoubler[1].txt
C:\Documents and Settings\Melane\Cookies\melane@bannerspace.com[1].txt
C:\Documents and Settings\Melane\Cookies\melane@cdn4.specificclick[3].txt
C:\Documents and Settings\Melane\Cookies\melane@adply.plymedia[4].txt
C:\Documents and Settings\Melane\Cookies\melane@steelhousemedia[2].txt
C:\Documents and Settings\Melane\Cookies\melane@e-2dj6wjk4egc5igo.stats.esomniture[1].txt
C:\Documents and Settings\Melane\Cookies\melane@www.commonsensemedia[2].txt
C:\Documents and Settings\Melane\Cookies\melane@ads.cpxadroit[1].txt
C:\Documents and Settings\Melane\Cookies\melane@adultjokes.co[2].txt
C:\Documents and Settings\Melane\Cookies\melane@www.vertadnet[2].txt
C:\Documents and Settings\Melane\Cookies\melane@ads.songlyrics[2].txt
C:\Documents and Settings\Melane\Cookies\melane@trackalyzer[1].txt
C:\Documents and Settings\Melane\Cookies\melane@inl.adbureau[2].txt
C:\Documents and Settings\Melane\Cookies\melane@ad.yieldmanager[10].txt
C:\Documents and Settings\Melane\Cookies\melane@insightexpressai[1].txt
C:\Documents and Settings\Melane\Cookies\melane@bs.serving-sys[11].txt
C:\Documents and Settings\Melane\Cookies\melane@bs.serving-sys[10].txt
C:\Documents and Settings\Melane\Cookies\melane@find.myrecipes[1].txt
C:\Documents and Settings\Melane\Cookies\melane@adply.plymedia[5].txt
C:\Documents and Settings\Melane\Cookies\melane@e-2dj6wck4egc5gfo.stats.esomniture[2].txt
C:\Documents and Settings\Melane\Cookies\melane@ads.monster[2].txt
C:\Documents and Settings\Melane\Cookies\melane@ipcmedia.122.2o7[1].txt
C:\Documents and Settings\Melane\Cookies\melane@gotacha.rotator.hadj7.adjuggler[1].txt
C:\Documents and Settings\Melane\Cookies\melane@e-2dj6wbmychcjehq.stats.esomniture[2].txt
C:\Documents and Settings\Melane\Cookies\melane@www.speedmediamarketing[1].txt
C:\Documents and Settings\Melane\Cookies\melane@e-2dj6wjmiclcpekq.stats.esomniture[2].txt
C:\Documents and Settings\Melane\Cookies\melane@e-2dj6wjmyglajcgo.stats.esomniture[2].txt
C:\Documents and Settings\Melane\Cookies\melane@e-2dj6wfkogpc5cao.stats.esomniture[2].txt
C:\Documents and Settings\Melane\Cookies\melane@ad.yieldmanager[11].txt
C:\Documents and Settings\Melane\Cookies\melane@e-2dj6wdmyqgdpwfp.stats.esomniture[1].txt
C:\Documents and Settings\Melane\Cookies\melane@insightexpressai[2].txt
C:\Documents and Settings\Melane\Cookies\melane@traffictrack[1].txt
C:\Documents and Settings\Melane\Cookies\melane@e-2dj6wbkowmc5abo.stats.esomniture[2].txt
C:\Documents and Settings\Melane\Cookies\melane@cdn4.specificclick[1].txt
C:\Documents and Settings\Melane\Cookies\melane@adply.plymedia[2].txt
C:\Documents and Settings\Melane\Cookies\melane@australiapost.122.2o7[1].txt
C:\Documents and Settings\Melane\Cookies\melane@checkmystats.com[2].txt
C:\Documents and Settings\Melane\Cookies\melane@msnaccountservices.112.2o7[1].txt
C:\Documents and Settings\Melane\Cookies\melane@partypoker[1].txt

Browser Hijacker.Deskbar
HKCR\Interface\{4897BBA6-48D9-468C-8EFA-846275D7701B}
HKCR\Interface\{4897BBA6-48D9-468C-8EFA-846275D7701B}\ProxyStubClsid
HKCR\Interface\{4897BBA6-48D9-468C-8EFA-846275D7701B}\ProxyStubClsid32
HKCR\Interface\{4897BBA6-48D9-468C-8EFA-846275D7701B}\TypeLib
HKCR\Interface\{4897BBA6-48D9-468C-8EFA-846275D7701B}\TypeLib#Version

Disabled.FolderOption
HKLM\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\EXPLORER\ADVANCED\FOLDER\HIDDEN\SHOWALL#CHECKEDVALUE

#4 starmmb

starmmb
  • Topic Starter

  • Members
  • 18 posts
  • OFFLINE
  •  
  • Local time:04:30 PM

Posted 22 December 2010 - 12:22 AM

Hi I have made 3 attempts to run the Malwarebytes program. Each time it has frozen & I have had to end it as a nonresponsive program. The first time it stopped after 5min, 1sec. The 2nd time was 4min, 10sec & I noticed that the file it was scanning at the time was to do with flash player. The 3rd time it froze @ 4min, 9sec & I wrote down the full name of the file it was scanning-
c:/Documents and Settings/Application Data/Macromedia/Flash Player/#SharedObjects/WG7BRD3U/@._V1_.swf/IMDBTEST.sol
Each time the number of infected objects was 22 (they appeared in one hit about a minute into each scan).

I have now been able to successfully perform a quick scan (instead of a full scan). Here is the log
Malwarebytes' Anti-Malware 1.50
www.malwarebytes.org

Database version: 5375

Windows 5.1.2600 Service Pack 3
Internet Explorer 8.0.6001.18702

22/12/2010 4:28:26 PM
mbam-log-2010-12-22 (16-28-26).txt

Scan type: Quick scan
Objects scanned: 155548
Time elapsed: 19 minute(s), 7 second(s)

Memory Processes Infected: 0
Memory Modules Infected: 0
Registry Keys Infected: 30
Registry Values Infected: 3
Registry Data Items Infected: 0
Folders Infected: 0
Files Infected: 0

Memory Processes Infected:
(No malicious items detected)

Memory Modules Infected:
(No malicious items detected)

Registry Keys Infected:
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{56256A51-B582-467e-B8D4-7786EDA79AE0} (Trojan.Vundo) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{56256A51-B582-467e-B8D4-7786EDA79AE0} (Trojan.Vundo) -> Quarantined and deleted successfully.
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\Settings\{00A6FAF1-072E-44CF-8957-5838F569A31D} (Adware.MyWebSearch) -> Quarantined and deleted successfully.
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\Settings\{07B18EA1-A523-4961-B6BB-170DE4475CCA} (Adware.MyWebSearch) -> Quarantined and deleted successfully.
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\Settings\{07B18EA9-A523-4961-B6BB-170DE4475CCA} (Adware.MyWebSearch) -> Quarantined and deleted successfully.
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\Stats\{1D4DB7D2-6EC9-47A3-BD87-1E41684E07BB} (Adware.MyWebSearch) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{1D4DB7D2-6EC9-47A3-BD87-1E41684E07BB} (Adware.MyWebSearch) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{59C7FC09-1C83-4648-B3E6-003D2BBC7481} (Adware.MyWebSearch) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{68AF847F-6E91-45dd-9B68-D6A12C30E5D7} (Adware.MyWebSearch) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{9170B96C-28D4-4626-8358-27E6CAEEF907} (Adware.MyWebSearch) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{D1A71FA0-FF48-48dd-9B6D-7A13A3E42127} (Adware.MyWebSearch) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{DDB1968E-EAD6-40fd-8DAE-FF14757F60C7} (Adware.MyWebSearch) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{F138D901-86F0-4383-99B6-9CDD406036DA} (Adware.MyWebSearch) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{07B18EAB-A523-4961-B6BB-170DE4475CCA} (Adware.MyWebSearch) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{25560540-9571-4D7B-9389-0F166788785A} (Adware.MyWebSearch) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{3DC201FB-E9C9-499C-A11F-23C360D7C3F8} (Adware.MyWebSearch) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{3E720452-B472-4954-B7AA-33069EB53906} (Adware.MyWebSearch) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{63D0ED2C-B45B-4458-8B3B-60C69BBBD83C} (Adware.MyWebSearch) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{7473D294-B7BB-4f24-AE82-7E2CE94BB6A9} (Adware.MyWebSearch) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{98D9753D-D73B-42D5-8C85-4469CDA897AB} (Adware.MyWebSearch) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{9FF05104-B030-46FC-94B8-81276E4E27DF} (Adware.MyWebSearch) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{E79DFBCA-5697-4fbd-94E5-5B2A9C7C1612} (Adware.MyWebSearch) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\MyWebSearch.MultipleButton (Adware.MyWebSearch) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\MyWebSearch.MultipleButton.1 (Adware.MyWebSearch) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\MyWebSearch.UrlAlertButton (Adware.MyWebSearch) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\MyWebSearch.UrlAlertButton.1 (Adware.MyWebSearch) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Low Rights\RunDll32Policy\f3ScrCtr.dll (Adware.MyWebSearch) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Multimedia\WMPlayer\Schemes\f3pss (Adware.MyWebSearch) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Office\Outlook\Addins\MyWebSearch.OutlookAddin (Adware.MyWebSearch) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Office\Word\Addins\MyWebSearch.OutlookAddin (Adware.MyWebSearch) -> Quarantined and deleted successfully.

Registry Values Infected:
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Internet Explorer\MenuExt\&Search\(default) (Adware.Hotbar) -> Value: (default) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows Media\WMSDK\Sources\f3PopularScreensavers (Adware.MyWebSearch) -> Value: f3PopularScreensavers -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\User Agent\Post Platform\FunWebProducts (Adware.MyWebSearch) -> Value: FunWebProducts -> Quarantined and deleted successfully.

Registry Data Items Infected:
(No malicious items detected)

Folders Infected:
(No malicious items detected)

Files Infected:
(No malicious items detected)

Edited by starmmb, 22 December 2010 - 01:33 AM.


#5 quietman7

quietman7

    Bleepin' Janitor


  • Global Moderator
  • 51,766 posts
  • OFFLINE
  •  
  • Gender:Male
  • Location:Virginia, USA
  • Local time:02:30 AM

Posted 22 December 2010 - 08:01 AM

Now rescan again with Malwarebytes Anti-Malware, but this time perform a Full Scan in normal mode and and check all items found for removal. Don't forgot to check for database definition updates through the program's interface (preferable method) before scanning and to reboot afterwards. Failure to reboot normally will prevent Malwarebytes' from removing all the malware. When done, click the Logs tab and copy/paste the contents of the new report in your next reply.

Try doing an online scan to see if it finds anything else that the other scans may have missed.

Please perform a scan with Eset Online Anti-virus Scanner.
  • This scan requires Internet Explorer to work. If using a different browser, you will be given the option to download and use the ESET Smart Installer.
  • Vista/Windows 7 users need to run Internet Explorer as Administrator. To do this, right-click on the IE icon in the Start Menu or Quick Launch Bar on the Taskbar and select Run As Administrator from the context menu.
  • Click the green Posted Image button.
  • Read the End User License Agreement and check the box:
  • Check Posted Image.
  • Click the Posted Image button.
  • Accept any security warnings from your browser.
  • Check Posted Image
  • Check Remove found threats and Scan potentially unwanted applications. (If given the option, choose "Quarantine" instead of delete.)
  • Click the Start button.
  • ESET will then download updates for itself, install itself, and begin scanning your computer.
  • If offered the option to get information or buy software at any point, just close the window.
  • The scan will take a while so be patient and do NOT use the computer while the scan is running. Keep all other programs and windows closed.
  • When the scan completes, push Posted Image
  • Push Posted Image, and save the file to your desktop as ESETScan.txt.
  • Push the Posted Image button, then Finish.
  • Copy and paste the contents of ESETScan.txt in your next reply.
Note: A log.txt file will also be created and automatically saved in the C:\Program Files\EsetOnlineScanner\ folder.
If you did not save the ESETScan log, click Posted Image > Run..., then type or copy and paste everything in the code box below into the Open dialogue box:

C:\Program Files\ESET\EsetOnlineScanner\log.txt
  • Click Ok and the scan results will open in Notepad.
  • Copy and paste the contents of log.txt in your next reply.
-- Some online scanners will detect existing anti-virus software and refuse to cooperate. You may have to disable the real-time protection components of your existing anti-virus and try running the scan again. If you do this, remember to turn them back on after you are finished.
.
.
Windows Insider MVP 2017-2018
Microsoft MVP Reconnect 2016
Microsoft MVP Consumer Security 2007-2015 kO7xOZh.gif
Member of UNITE, Unified Network of Instructors and Trusted Eliminators

If I have been helpful & you'd like to consider a donation, click 38WxTfO.gif

#6 starmmb

starmmb
  • Topic Starter

  • Members
  • 18 posts
  • OFFLINE
  •  
  • Local time:04:30 PM

Posted 22 December 2010 - 07:49 PM

Hi Quietman7, here are the results of the malabytes full scan. I will do the online scan after posting this reply then add the log results as an edit. Just so you know I will not have access to my computer from tomorrow morning (my time - which is in about another 24 hours) until Monday or Tuesday (so for at least 3 full days). Anything you advise during that period I will get onto as soon as I am back at home. In the meantime thanks again for the support & Merry Christmas to you and yours :)

Malwarebytes' Anti-Malware 1.50
www.malwarebytes.org

Database version: 5375

Windows 5.1.2600 Service Pack 3
Internet Explorer 8.0.6001.18702

23/12/2010 10:14:31 AM
mbam-log-2010-12-23 (10-14-31).txt

Scan type: Full scan (C:\|)
Objects scanned: 216538
Time elapsed: 1 hour(s), 51 minute(s), 29 second(s)

Memory Processes Infected: 0
Memory Modules Infected: 0
Registry Keys Infected: 0
Registry Values Infected: 0
Registry Data Items Infected: 0
Folders Infected: 0
Files Infected: 40

Memory Processes Infected:
(No malicious items detected)

Memory Modules Infected:
(No malicious items detected)

Registry Keys Infected:
(No malicious items detected)

Registry Values Infected:
(No malicious items detected)

Registry Data Items Infected:
(No malicious items detected)

Folders Infected:
(No malicious items detected)

Files Infected:
c:\program files\search guard plus\searchguardplus.exe (PUP.Fbsearch) -> Quarantined and deleted successfully.
c:\system volume information\_restore{0cbef4e5-5cfa-47c2-a8a1-a518d92c0df2}\RP384\A0131387.EXE (Adware.MyWebSearch) -> Quarantined and deleted successfully.
c:\system volume information\_restore{0cbef4e5-5cfa-47c2-a8a1-a518d92c0df2}\RP384\A0131388.DLL (Adware.MyWebSearch) -> Quarantined and deleted successfully.
c:\system volume information\_restore{0cbef4e5-5cfa-47c2-a8a1-a518d92c0df2}\RP384\A0131405.EXE (PUP.FunWebProducts) -> Quarantined and deleted successfully.
c:\system volume information\_restore{0cbef4e5-5cfa-47c2-a8a1-a518d92c0df2}\RP384\A0131423.DLL (Adware.MyWebSearch) -> Quarantined and deleted successfully.
c:\system volume information\_restore{0cbef4e5-5cfa-47c2-a8a1-a518d92c0df2}\RP384\A0131389.DLL (Adware.MyWebSearch) -> Quarantined and deleted successfully.
c:\system volume information\_restore{0cbef4e5-5cfa-47c2-a8a1-a518d92c0df2}\RP384\A0131390.EXE (Adware.MyWebSearch) -> Quarantined and deleted successfully.
c:\system volume information\_restore{0cbef4e5-5cfa-47c2-a8a1-a518d92c0df2}\RP384\A0131391.DLL (PUP.FunWebProducts) -> Quarantined and deleted successfully.
c:\system volume information\_restore{0cbef4e5-5cfa-47c2-a8a1-a518d92c0df2}\RP384\A0131392.DLL (PUP.FunWebProducts) -> Quarantined and deleted successfully.
c:\system volume information\_restore{0cbef4e5-5cfa-47c2-a8a1-a518d92c0df2}\RP384\A0131394.DLL (PUP.FunWebProducts) -> Quarantined and deleted successfully.
c:\system volume information\_restore{0cbef4e5-5cfa-47c2-a8a1-a518d92c0df2}\RP384\A0131395.DLL (PUP.FunWebProducts) -> Quarantined and deleted successfully.
c:\system volume information\_restore{0cbef4e5-5cfa-47c2-a8a1-a518d92c0df2}\RP384\A0131396.DLL (PUP.FunWebProducts) -> Quarantined and deleted successfully.
c:\system volume information\_restore{0cbef4e5-5cfa-47c2-a8a1-a518d92c0df2}\RP384\A0131397.DLL (Adware.MyWebSearch) -> Quarantined and deleted successfully.
c:\system volume information\_restore{0cbef4e5-5cfa-47c2-a8a1-a518d92c0df2}\RP384\A0131398.DLL (PUP.FunWebProducts) -> Quarantined and deleted successfully.
c:\system volume information\_restore{0cbef4e5-5cfa-47c2-a8a1-a518d92c0df2}\RP384\A0131399.DLL (PUP.FunWebProducts) -> Quarantined and deleted successfully.
c:\system volume information\_restore{0cbef4e5-5cfa-47c2-a8a1-a518d92c0df2}\RP384\A0131400.DLL (PUP.FunWebProducts) -> Quarantined and deleted successfully.
c:\system volume information\_restore{0cbef4e5-5cfa-47c2-a8a1-a518d92c0df2}\RP384\A0131401.SCR (PUP.FunWebProducts) -> Quarantined and deleted successfully.
c:\system volume information\_restore{0cbef4e5-5cfa-47c2-a8a1-a518d92c0df2}\RP384\A0131402.DLL (Adware.MyWebSearch) -> Quarantined and deleted successfully.
c:\system volume information\_restore{0cbef4e5-5cfa-47c2-a8a1-a518d92c0df2}\RP384\A0131403.DLL (PUP.FunWebProducts) -> Quarantined and deleted successfully.
c:\system volume information\_restore{0cbef4e5-5cfa-47c2-a8a1-a518d92c0df2}\RP384\A0131404.DLL (PUP.FunWebProducts) -> Quarantined and deleted successfully.
c:\system volume information\_restore{0cbef4e5-5cfa-47c2-a8a1-a518d92c0df2}\RP384\A0131406.DLL (Adware.MyWebSearch) -> Quarantined and deleted successfully.
c:\system volume information\_restore{0cbef4e5-5cfa-47c2-a8a1-a518d92c0df2}\RP384\A0131407.DLL (Adware.MyWebSearch) -> Quarantined and deleted successfully.
c:\system volume information\_restore{0cbef4e5-5cfa-47c2-a8a1-a518d92c0df2}\RP384\A0131408.DLL (Adware.MyWebSearch) -> Quarantined and deleted successfully.
c:\system volume information\_restore{0cbef4e5-5cfa-47c2-a8a1-a518d92c0df2}\RP384\A0131409.EXE (Adware.MyWebSearch) -> Quarantined and deleted successfully.
c:\system volume information\_restore{0cbef4e5-5cfa-47c2-a8a1-a518d92c0df2}\RP384\A0131410.DLL (Adware.MyWebSearch) -> Quarantined and deleted successfully.
c:\system volume information\_restore{0cbef4e5-5cfa-47c2-a8a1-a518d92c0df2}\RP384\A0131411.DLL (Adware.MyWebSearch) -> Quarantined and deleted successfully.
c:\system volume information\_restore{0cbef4e5-5cfa-47c2-a8a1-a518d92c0df2}\RP384\A0131412.EXE (Adware.MyWebSearch) -> Quarantined and deleted successfully.
c:\system volume information\_restore{0cbef4e5-5cfa-47c2-a8a1-a518d92c0df2}\RP384\A0131413.EXE (Adware.MyWebSearch) -> Quarantined and deleted successfully.
c:\system volume information\_restore{0cbef4e5-5cfa-47c2-a8a1-a518d92c0df2}\RP384\A0131414.DLL (Adware.MyWebSearch) -> Quarantined and deleted successfully.
c:\system volume information\_restore{0cbef4e5-5cfa-47c2-a8a1-a518d92c0df2}\RP384\A0131415.DLL (Adware.MyWebSearch) -> Quarantined and deleted successfully.
c:\system volume information\_restore{0cbef4e5-5cfa-47c2-a8a1-a518d92c0df2}\RP384\A0131416.DLL (Adware.MyWebSearch) -> Quarantined and deleted successfully.
c:\system volume information\_restore{0cbef4e5-5cfa-47c2-a8a1-a518d92c0df2}\RP384\A0131417.DLL (Adware.MyWebSearch) -> Quarantined and deleted successfully.
c:\system volume information\_restore{0cbef4e5-5cfa-47c2-a8a1-a518d92c0df2}\RP384\A0131418.DLL (Adware.MyWebSearch) -> Quarantined and deleted successfully.
c:\system volume information\_restore{0cbef4e5-5cfa-47c2-a8a1-a518d92c0df2}\RP384\A0131419.EXE (Adware.MyWebSearch) -> Quarantined and deleted successfully.
c:\system volume information\_restore{0cbef4e5-5cfa-47c2-a8a1-a518d92c0df2}\RP384\A0131420.EXE (Adware.MyWebSearch) -> Quarantined and deleted successfully.
c:\system volume information\_restore{0cbef4e5-5cfa-47c2-a8a1-a518d92c0df2}\RP384\A0131421.DLL (Adware.MyWebSearch) -> Quarantined and deleted successfully.
c:\system volume information\_restore{0cbef4e5-5cfa-47c2-a8a1-a518d92c0df2}\RP384\A0131422.DLL (Adware.MyWebSearch) -> Quarantined and deleted successfully.
c:\system volume information\_restore{0cbef4e5-5cfa-47c2-a8a1-a518d92c0df2}\RP384\A0131424.DLL (Adware.MyWebSearch) -> Quarantined and deleted successfully.
c:\system volume information\_restore{0cbef4e5-5cfa-47c2-a8a1-a518d92c0df2}\RP384\A0131431.DLL (PUP.FunWebProducts) -> Quarantined and deleted successfully.
c:\system volume information\_restore{0cbef4e5-5cfa-47c2-a8a1-a518d92c0df2}\RP384\A0131436.scr (PUP.FunWebProducts) -> Quarantined and deleted successfully.


ESET Scanner results
C:\Documents and Settings\Melane\Application Data\Sun\Java\Deployment\cache\6.0\46\7f5814ee-35a92a4e multiple threats deleted - quarantined

FYI- the Google homepage has not yet returned to normal (Is that even virus-related???) Did a few searches this morning & none of the results I opened were redirected YAY. Fingers crossed

Grrrr - I spoke too soon. Just got another redirect then a pop-up from AVG - Threat was blocked! File name: pexunob.co.cc/?id+06abQDcx Threat name: Exploit Rogue Scanner (type 1349) When I clicked on 'Show details' it said Process name: C:/Program Files/Internet Explorer/iexplore.exe Process ID 2468 When I clicked in 'More info' to search their encyclopedia it said "We did not find any virus in the Virus Encyclopedia. Please try to use a more generic name at least 3 characters long." I tried both the File name & the threat name.

I will await further advice, cheers.

Edited by starmmb, 22 December 2010 - 10:40 PM.


#7 quietman7

quietman7

    Bleepin' Janitor


  • Global Moderator
  • 51,766 posts
  • OFFLINE
  •  
  • Gender:Male
  • Location:Virginia, USA
  • Local time:02:30 AM

Posted 23 December 2010 - 09:20 AM

Some infections are difficult to remove completely because of their morphing characteristics which allows the malware to regenerate itself or infect critical system files which cannot be cleaned. Sometimes there is an undetected hidden piece of malware such as a rootkit which protects malicious files and registry keys so they cannot be permanently deleted. Disinfection will probably require the use of more powerful tools than we recommend in this forum. Before that can be done you will need you to create and post a DDS log for further investigation.

Please read the pinned topic titled "Preparation Guide For Use Before Using Malware Removal Tools and Requesting Help". If you cannot complete a step, then skip it and continue with the next. In Step 7 there are instructions for downloading and running DDS which will create a Pseudo HJT Report as part of its log.

When you have done that, post your log in the Virus, Trojan, Spyware, and Malware Removal Logs forum, NOT here, for assistance by the Malware Response Team Experts. A member of the Team will walk you through, step by step, on how to clean your computer. If you post your log back in this thread, the response from the Malware Response Team will be delayed because your post will have to be moved. This means it will fall in line behind any others posted that same day.

Start a new topic, give it a relevant title and post your log along with a brief description of your problem, a summary of any anti-malware tools you have used and a summary of any steps that you have performed on your own. An expert will analyze your log and reply with instructions advising you what to fix. After doing this, we would appreciate if you post a link to your log back here so we know that your getting help from the Malware Response Team.

Please be patient. It may take a while to get a response because the Malware Response Team members are very busy working logs posted before yours. They are volunteers who will help you out as soon as possible. Once you have posted your log and are waiting, please DO NOT "bump" your post or make another reply until it has been responded to by a member of the Malware Response Team. Generally the staff checks the forum for postings that have 0 replies as this makes it easier for them to identify those who have not been helped. If you post another response there will be 1 reply. A team member, looking for a new log to work may assume another Malware Response Team member is already assisting you and not open the thread to respond.
.
.
Windows Insider MVP 2017-2018
Microsoft MVP Reconnect 2016
Microsoft MVP Consumer Security 2007-2015 kO7xOZh.gif
Member of UNITE, Unified Network of Instructors and Trusted Eliminators

If I have been helpful & you'd like to consider a donation, click 38WxTfO.gif

#8 starmmb

starmmb
  • Topic Starter

  • Members
  • 18 posts
  • OFFLINE
  •  
  • Local time:04:30 PM

Posted 23 December 2010 - 04:36 PM

Thanks quietman7 - I don't have the time to dedicate to this next stage of the process before I go away this morning so will attend to it on my return in a few days time. To tell the truth it is doing my head in, hats off to you and your colleagues who deal with this 24/7! All the best for the festive season.

#9 quietman7

quietman7

    Bleepin' Janitor


  • Global Moderator
  • 51,766 posts
  • OFFLINE
  •  
  • Gender:Male
  • Location:Virginia, USA
  • Local time:02:30 AM

Posted 23 December 2010 - 04:44 PM

I understand.

Have a safe trip and enjoy the holidays.
.
.
Windows Insider MVP 2017-2018
Microsoft MVP Reconnect 2016
Microsoft MVP Consumer Security 2007-2015 kO7xOZh.gif
Member of UNITE, Unified Network of Instructors and Trusted Eliminators

If I have been helpful & you'd like to consider a donation, click 38WxTfO.gif

#10 starmmb

starmmb
  • Topic Starter

  • Members
  • 18 posts
  • OFFLINE
  •  
  • Local time:04:30 PM

Posted 26 December 2010 - 04:45 PM

Hello quietman7, Last night I re-ran all the scans you had previously recommended & it seems that the problem may have been eliminated! I will post the results of each one & hope you will be kind enough to have a look (only SUPERAntiSpyware & ESET uncovered 'things', the other 2 scans came back clean)then let me know whether or not I should still proceed with the other forum section. Google homepage has returned to normal & various searches results I clicked went to the correct site straight away.......

2010/12/26 16:56:03.0359 TDSS rootkit removing tool 2.4.12.0 Dec 16 2010 09:46:46
2010/12/26 16:56:03.0359 ================================================================================
2010/12/26 16:56:03.0359 SystemInfo:
2010/12/26 16:56:03.0359
2010/12/26 16:56:03.0359 OS Version: 5.1.2600 ServicePack: 3.0
2010/12/26 16:56:03.0359 Product type: Workstation
2010/12/26 16:56:03.0359 ComputerName: PCUSER-1E514038
2010/12/26 16:56:03.0359 UserName: Melane
2010/12/26 16:56:03.0359 Windows directory: C:\WINDOWS
2010/12/26 16:56:03.0359 System windows directory: C:\WINDOWS
2010/12/26 16:56:03.0359 Processor architecture: Intel x86
2010/12/26 16:56:03.0359 Number of processors: 2
2010/12/26 16:56:03.0359 Page size: 0x1000
2010/12/26 16:56:03.0359 Boot type: Normal boot
2010/12/26 16:56:03.0359 ================================================================================
2010/12/26 16:56:04.0062 Initialize success
2010/12/26 16:56:53.0156 ================================================================================
2010/12/26 16:56:53.0156 Scan started
2010/12/26 16:56:53.0156 Mode: Manual;
2010/12/26 16:56:53.0156 ================================================================================
2010/12/26 16:56:55.0937 ACPI (8fd99680a539792a30e97944fdaecf17) C:\WINDOWS\system32\DRIVERS\ACPI.sys
2010/12/26 16:56:56.0406 ACPIEC (9859c0f6936e723e4892d7141b1327d5) C:\WINDOWS\system32\drivers\ACPIEC.sys
2010/12/26 16:56:56.0953 aec (8bed39e3c35d6a489438b8141717a557) C:\WINDOWS\system32\drivers\aec.sys
2010/12/26 16:56:57.0421 AFD (7e775010ef291da96ad17ca4b17137d7) C:\WINDOWS\System32\drivers\afd.sys
2010/12/26 16:57:00.0171 AsyncMac (b153affac761e7f5fcfa822b9c4e97bc) C:\WINDOWS\system32\DRIVERS\asyncmac.sys
2010/12/26 16:57:00.0703 atapi (9f3a2f5aa6875c72bf062c712cfa2674) C:\WINDOWS\system32\DRIVERS\atapi.sys
2010/12/26 16:57:01.0437 ati2mtag (f48fe6d69f7a224a2157d052e3b1a0fc) C:\WINDOWS\system32\DRIVERS\ati2mtag.sys
2010/12/26 16:57:02.0000 Atmarpc (9916c1225104ba14794209cfa8012159) C:\WINDOWS\system32\DRIVERS\atmarpc.sys
2010/12/26 16:57:02.0359 audstub (d9f724aa26c010a217c97606b160ed68) C:\WINDOWS\system32\DRIVERS\audstub.sys
2010/12/26 16:57:02.0718 AVGIDSDriver (0c61f066f4d94bd67063dc6691935143) C:\WINDOWS\system32\DRIVERS\AVGIDSDriver.Sys
2010/12/26 16:57:03.0046 AVGIDSEH (84853f800cd69252c3c764fe50d0346f) C:\WINDOWS\system32\DRIVERS\AVGIDSEH.Sys
2010/12/26 16:57:03.0343 AVGIDSFilter (28d6adcd03e10f3838488b9b5d407dd4) C:\WINDOWS\system32\DRIVERS\AVGIDSFilter.Sys
2010/12/26 16:57:03.0718 AVGIDSShim (0eb16f4dbbb946360af30d2b13a52d1d) C:\WINDOWS\system32\DRIVERS\AVGIDSShim.Sys
2010/12/26 16:57:04.0015 Avgldx86 (1119e5bec6e749e0d292f0f84d48edba) C:\WINDOWS\system32\DRIVERS\avgldx86.sys
2010/12/26 16:57:04.0468 Avgmfx86 (54f1a9b4c9b540c2d8ac4baa171696b1) C:\WINDOWS\system32\DRIVERS\avgmfx86.sys
2010/12/26 16:57:04.0812 Avgrkx86 (8da3b77993c5f354cc2977b7ea06d03a) C:\WINDOWS\system32\DRIVERS\avgrkx86.sys
2010/12/26 16:57:05.0203 Avgtdix (354e0fec3bfdfa9c369e0f67ac362f9f) C:\WINDOWS\system32\DRIVERS\avgtdix.sys
2010/12/26 16:57:05.0515 Beep (da1f27d85e0d1525f6621372e7b685e9) C:\WINDOWS\system32\drivers\Beep.sys
2010/12/26 16:57:05.0546 Suspicious service (NoAccess): bxtjvesaf
2010/12/26 16:57:05.0828 cbidf2k (90a673fc8e12a79afbed2576f6a7aaf9) C:\WINDOWS\system32\drivers\cbidf2k.sys
2010/12/26 16:57:06.0093 CCDECODE (0be5aef125be881c4f854c554f2b025c) C:\WINDOWS\system32\DRIVERS\CCDECODE.sys
2010/12/26 16:57:06.0484 Cdaudio (c1b486a7658353d33a10cc15211a873b) C:\WINDOWS\system32\drivers\Cdaudio.sys
2010/12/26 16:57:06.0718 Cdfs (c885b02847f5d2fd45a24e219ed93b32) C:\WINDOWS\system32\drivers\Cdfs.sys
2010/12/26 16:57:06.0984 Cdrom (1f4260cc5b42272d71f79e570a27a4fe) C:\WINDOWS\system32\DRIVERS\cdrom.sys
2010/12/26 16:57:08.0171 Disk (044452051f3e02e7963599fc8f4f3e25) C:\WINDOWS\system32\DRIVERS\disk.sys
2010/12/26 16:57:08.0578 dmboot (d992fe1274bde0f84ad826acae022a41) C:\WINDOWS\system32\drivers\dmboot.sys
2010/12/26 16:57:09.0187 dmio (7c824cf7bbde77d95c08005717a95f6f) C:\WINDOWS\system32\drivers\dmio.sys
2010/12/26 16:57:09.0515 dmload (e9317282a63ca4d188c0df5e09c6ac5f) C:\WINDOWS\system32\drivers\dmload.sys
2010/12/26 16:57:09.0875 DMusic (8a208dfcf89792a484e76c40e5f50b45) C:\WINDOWS\system32\drivers\DMusic.sys
2010/12/26 16:57:10.0250 drmkaud (8f5fcff8e8848afac920905fbd9d33c8) C:\WINDOWS\system32\drivers\drmkaud.sys
2010/12/26 16:57:10.0687 Fastfat (38d332a6d56af32635675f132548343e) C:\WINDOWS\system32\drivers\Fastfat.sys
2010/12/26 16:57:11.0078 Fdc (92cdd60b6730b9f50f6a1a0c1f8cdc81) C:\WINDOWS\system32\DRIVERS\fdc.sys
2010/12/26 16:57:11.0312 FETNDIS (e9648254056bce81a85380c0c3647dc4) C:\WINDOWS\system32\DRIVERS\fetnd5.sys
2010/12/26 16:57:11.0687 Fips (d45926117eb9fa946a6af572fbe1caa3) C:\WINDOWS\system32\drivers\Fips.sys
2010/12/26 16:57:11.0890 Flpydisk (9d27e7b80bfcdf1cdd9b555862d5e7f0) C:\WINDOWS\system32\drivers\Flpydisk.sys
2010/12/26 16:57:12.0218 FltMgr (b2cf4b0786f8212cb92ed2b50c6db6b0) C:\WINDOWS\system32\drivers\fltmgr.sys
2010/12/26 16:57:12.0343 Fs_Rec (3e1e2bd4f39b0e2b7dc4f4d2bcc2779a) C:\WINDOWS\system32\drivers\Fs_Rec.sys
2010/12/26 16:57:12.0781 Ftdisk (6ac26732762483366c3969c9e4d2259d) C:\WINDOWS\system32\DRIVERS\ftdisk.sys
2010/12/26 16:57:13.0203 GEARAspiWDM (8182ff89c65e4d38b2de4bb0fb18564e) C:\WINDOWS\system32\DRIVERS\GEARAspiWDM.sys
2010/12/26 16:57:13.0234 Suspicious service (NoAccess): gmecig
2010/12/26 16:57:13.0640 Gpc (0a02c63c8b144bd8c86b103dee7c86a2) C:\WINDOWS\system32\DRIVERS\msgpc.sys
2010/12/26 16:57:14.0078 HPZid412 (d03d10f7ded688fecf50f8fbf1ea9b8a) C:\WINDOWS\system32\DRIVERS\HPZid412.sys
2010/12/26 16:57:14.0343 HPZipr12 (89f41658929393487b6b7d13c8528ce3) C:\WINDOWS\system32\DRIVERS\HPZipr12.sys
2010/12/26 16:57:14.0656 HPZius12 (abcb05ccdbf03000354b9553820e39f8) C:\WINDOWS\system32\DRIVERS\HPZius12.sys
2010/12/26 16:57:14.0984 HSFHWBS2 (970178e8e003eb1481293830069624b9) C:\WINDOWS\system32\DRIVERS\HSFBS2S2.sys
2010/12/26 16:57:15.0609 HSF_DP (ebb354438a4c5a3327fb97306260714a) C:\WINDOWS\system32\DRIVERS\HSFDPSP2.sys
2010/12/26 16:57:16.0281 HTTP (f80a415ef82cd06ffaf0d971528ead38) C:\WINDOWS\system32\Drivers\HTTP.sys
2010/12/26 16:57:17.0000 i8042prt (4a0b06aa8943c1e332520f7440c0aa30) C:\WINDOWS\system32\DRIVERS\i8042prt.sys
2010/12/26 16:57:17.0265 Imapi (083a052659f5310dd8b6a6cb05edcf8e) C:\WINDOWS\system32\DRIVERS\imapi.sys
2010/12/26 16:57:17.0281 Suspicious service (NoAccess): imdid
2010/12/26 16:57:17.0468 InCDfs (bb7b8b24d81de3cdfd5d91eb632ccbbe) C:\WINDOWS\system32\drivers\InCDfs.sys
2010/12/26 16:57:17.0656 InCDPass (abbb6a2ff6bfc531f482c19905dd7f6b) C:\WINDOWS\system32\DRIVERS\InCDPass.sys
2010/12/26 16:57:17.0796 InCDrec (4a8846c9db9d2070f604ebd60ce64816) C:\WINDOWS\system32\drivers\InCDrec.sys
2010/12/26 16:57:18.0078 incdrm (dcaa6a1d8188b594129f1633c9c4ef8b) C:\WINDOWS\system32\drivers\incdrm.sys
2010/12/26 16:57:18.0875 intelppm (8c953733d8f36eb2133f5bb58808b66b) C:\WINDOWS\system32\DRIVERS\intelppm.sys
2010/12/26 16:57:19.0203 Ip6Fw (3bb22519a194418d5fec05d800a19ad0) C:\WINDOWS\system32\drivers\ip6fw.sys
2010/12/26 16:57:19.0484 IpFilterDriver (731f22ba402ee4b62748adaf6363c182) C:\WINDOWS\system32\DRIVERS\ipfltdrv.sys
2010/12/26 16:57:19.0906 IpInIp (b87ab476dcf76e72010632b5550955f5) C:\WINDOWS\system32\DRIVERS\ipinip.sys
2010/12/26 16:57:20.0203 IpNat (cc748ea12c6effde940ee98098bf96bb) C:\WINDOWS\system32\DRIVERS\ipnat.sys
2010/12/26 16:57:20.0625 IPSec (23c74d75e36e7158768dd63d92789a91) C:\WINDOWS\system32\DRIVERS\ipsec.sys
2010/12/26 16:57:20.0968 IRENUM (c93c9ff7b04d772627a3646d89f7bf89) C:\WINDOWS\system32\DRIVERS\irenum.sys
2010/12/26 16:57:21.0343 isapnp (05a299ec56e52649b1cf2fc52d20f2d7) C:\WINDOWS\system32\DRIVERS\isapnp.sys
2010/12/26 16:57:21.0765 Kbdclass (463c1ec80cd17420a542b7f36a36f128) C:\WINDOWS\system32\DRIVERS\kbdclass.sys
2010/12/26 16:57:22.0250 kmixer (692bcf44383d056aed41b045a323d378) C:\WINDOWS\system32\drivers\kmixer.sys
2010/12/26 16:57:22.0750 KSecDD (b467646c54cc746128904e1654c750c1) C:\WINDOWS\system32\drivers\KSecDD.sys
2010/12/26 16:57:23.0343 mdmxsdk (195741aee20369980796b557358cd774) C:\WINDOWS\system32\DRIVERS\mdmxsdk.sys
2010/12/26 16:57:23.0656 mnmdd (4ae068242760a1fb6e1a44bf4e16afa6) C:\WINDOWS\system32\drivers\mnmdd.sys
2010/12/26 16:57:24.0156 Modem (dfcbad3cec1c5f964962ae10e0bcc8e1) C:\WINDOWS\system32\drivers\Modem.sys
2010/12/26 16:57:24.0406 Mouclass (35c9e97194c8cfb8430125f8dbc34d04) C:\WINDOWS\system32\DRIVERS\mouclass.sys
2010/12/26 16:57:24.0750 MountMgr (a80b9a0bad1b73637dbcbba7df72d3fd) C:\WINDOWS\system32\drivers\MountMgr.sys
2010/12/26 16:57:25.0359 MRxDAV (11d42bb6206f33fbb3ba0288d3ef81bd) C:\WINDOWS\system32\DRIVERS\mrxdav.sys
2010/12/26 16:57:25.0984 MRxSmb (f3aefb11abc521122b67095044169e98) C:\WINDOWS\system32\DRIVERS\mrxsmb.sys
2010/12/26 16:57:26.0375 Msfs (c941ea2454ba8350021d774daf0f1027) C:\WINDOWS\system32\drivers\Msfs.sys
2010/12/26 16:57:26.0984 MSKSSRV (d1575e71568f4d9e14ca56b7b0453bf1) C:\WINDOWS\system32\drivers\MSKSSRV.sys
2010/12/26 16:57:34.0484 MSPCLOCK (325bb26842fc7ccc1fcce2c457317f3e) C:\WINDOWS\system32\drivers\MSPCLOCK.sys
2010/12/26 16:57:35.0046 MSPQM (bad59648ba099da4a17680b39730cb3d) C:\WINDOWS\system32\drivers\MSPQM.sys
2010/12/26 16:57:35.0984 mssmbios (af5f4f3f14a8ea2c26de30f7a1e17136) C:\WINDOWS\system32\DRIVERS\mssmbios.sys
2010/12/26 16:57:37.0546 MSTEE (e53736a9e30c45fa9e7b5eac55056d1d) C:\WINDOWS\system32\drivers\MSTEE.sys
2010/12/26 16:57:38.0765 Mup (2f625d11385b1a94360bfc70aaefdee1) C:\WINDOWS\system32\drivers\Mup.sys
2010/12/26 16:57:39.0421 NABTSFEC (5b50f1b2a2ed47d560577b221da734db) C:\WINDOWS\system32\DRIVERS\NABTSFEC.sys
2010/12/26 16:57:40.0515 NDIS (1df7f42665c94b825322fae71721130d) C:\WINDOWS\system32\drivers\NDIS.sys
2010/12/26 16:57:41.0828 NdisIP (7ff1f1fd8609c149aa432f95a8163d97) C:\WINDOWS\system32\DRIVERS\NdisIP.sys
2010/12/26 16:57:42.0656 NdisTapi (1ab3d00c991ab086e69db84b6c0ed78f) C:\WINDOWS\system32\DRIVERS\ndistapi.sys
2010/12/26 16:57:44.0500 Ndisuio (f927a4434c5028758a842943ef1a3849) C:\WINDOWS\system32\DRIVERS\ndisuio.sys
2010/12/26 16:57:45.0234 NdisWan (edc1531a49c80614b2cfda43ca8659ab) C:\WINDOWS\system32\DRIVERS\ndiswan.sys
2010/12/26 16:57:50.0062 NDProxy (9282bd12dfb069d3889eb3fcc1000a9b) C:\WINDOWS\system32\drivers\NDProxy.sys
2010/12/26 16:57:52.0078 NetBIOS (5d81cf9a2f1a3a756b66cf684911cdf0) C:\WINDOWS\system32\DRIVERS\netbios.sys
2010/12/26 16:57:53.0828 NetBT (74b2b2f5bea5e9a3dc021d685551bd3d) C:\WINDOWS\system32\DRIVERS\netbt.sys
2010/12/26 16:58:02.0578 Npfs (3182d64ae053d6fb034f44b6def8034a) C:\WINDOWS\system32\drivers\Npfs.sys
2010/12/26 16:58:04.0500 Ntfs (78a08dd6a8d65e697c18e1db01c5cdca) C:\WINDOWS\system32\drivers\Ntfs.sys
2010/12/26 16:58:06.0046 Null (73c1e1f395918bc2c6dd67af7591a3ad) C:\WINDOWS\system32\drivers\Null.sys
2010/12/26 16:58:07.0140 NwlnkFlt (b305f3fad35083837ef46a0bbce2fc57) C:\WINDOWS\system32\DRIVERS\nwlnkflt.sys
2010/12/26 16:58:08.0468 NwlnkFwd (c99b3415198d1aab7227f2c88fd664b9) C:\WINDOWS\system32\DRIVERS\nwlnkfwd.sys
2010/12/26 16:58:09.0125 Parport (5575faf8f97ce5e713d108c2a58d7c7c) C:\WINDOWS\system32\DRIVERS\parport.sys
2010/12/26 16:58:10.0718 PartMgr (beb3ba25197665d82ec7065b724171c6) C:\WINDOWS\system32\drivers\PartMgr.sys
2010/12/26 16:58:12.0031 ParVdm (70e98b3fd8e963a6a46a2e6247e0bea1) C:\WINDOWS\system32\drivers\ParVdm.sys
2010/12/26 16:58:13.0562 PCI (a219903ccf74233761d92bef471a07b1) C:\WINDOWS\system32\DRIVERS\pci.sys
2010/12/26 16:58:16.0250 Pcmcia (9e89ef60e9ee05e3f2eef2da7397f1c1) C:\WINDOWS\system32\drivers\Pcmcia.sys
2010/12/26 16:58:20.0468 PptpMiniport (efeec01b1d3cf84f16ddd24d9d9d8f99) C:\WINDOWS\system32\DRIVERS\raspptp.sys
2010/12/26 16:58:21.0625 PSched (09298ec810b07e5d582cb3a3f9255424) C:\WINDOWS\system32\DRIVERS\psched.sys
2010/12/26 16:58:22.0671 Ptilink (80d317bd1c3dbc5d4fe7b1678c60cadd) C:\WINDOWS\system32\DRIVERS\ptilink.sys
2010/12/26 16:58:28.0187 RasAcd (fe0d99d6f31e4fad8159f690d68ded9c) C:\WINDOWS\system32\DRIVERS\rasacd.sys
2010/12/26 16:58:29.0031 Rasl2tp (11b4a627bc9614b885c4969bfa5ff8a6) C:\WINDOWS\system32\DRIVERS\rasl2tp.sys
2010/12/26 16:58:29.0640 RasPppoe (5bc962f2654137c9909c3d4603587dee) C:\WINDOWS\system32\DRIVERS\raspppoe.sys
2010/12/26 16:58:30.0312 Raspti (fdbb1d60066fcfbb7452fd8f9829b242) C:\WINDOWS\system32\DRIVERS\raspti.sys
2010/12/26 16:58:31.0031 Rdbss (7ad224ad1a1437fe28d89cf22b17780a) C:\WINDOWS\system32\DRIVERS\rdbss.sys
2010/12/26 16:58:32.0296 RDPCDD (4912d5b403614ce99c28420f75353332) C:\WINDOWS\system32\DRIVERS\RDPCDD.sys
2010/12/26 16:58:33.0546 RDPWD (6728e45b66f93c08f11de2e316fc70dd) C:\WINDOWS\system32\drivers\RDPWD.sys
2010/12/26 16:58:35.0078 redbook (f828dd7e1419b6653894a8f97a0094c5) C:\WINDOWS\system32\DRIVERS\redbook.sys
2010/12/26 16:58:35.0562 SASDIFSV (a3281aec37e0720a2bc28034c2df2a56) C:\Program Files\SUPERAntiSpyware\SASDIFSV.SYS
2010/12/26 16:58:37.0687 SASKUTIL (61db0d0756a99506207fd724e3692b25) C:\Program Files\SUPERAntiSpyware\SASKUTIL.SYS
2010/12/26 16:58:39.0250 Secdrv (90a3935d05b494a5a39d37e71f09a677) C:\WINDOWS\system32\DRIVERS\secdrv.sys
2010/12/26 16:58:40.0640 serenum (0f29512ccd6bead730039fb4bd2c85ce) C:\WINDOWS\system32\DRIVERS\serenum.sys
2010/12/26 16:58:41.0625 Serial (cca207a8896d4c6a0c9ce29a4ae411a7) C:\WINDOWS\system32\DRIVERS\serial.sys
2010/12/26 16:58:42.0468 Sfloppy (8e6b8c671615d126fdc553d1e2de5562) C:\WINDOWS\system32\drivers\Sfloppy.sys
2010/12/26 16:58:44.0093 SLIP (866d538ebe33709a5c9f5c62b73b7d14) C:\WINDOWS\system32\DRIVERS\SLIP.sys
2010/12/26 16:58:45.0546 splitter (ab8b92451ecb048a4d1de7c3ffcb4a9f) C:\WINDOWS\system32\drivers\splitter.sys
2010/12/26 16:58:46.0078 sr (76bb022c2fb6902fd5bdd4f78fc13a5d) C:\WINDOWS\system32\DRIVERS\sr.sys
2010/12/26 16:58:46.0578 Srv (0f6aefad3641a657e18081f52d0c15af) C:\WINDOWS\system32\DRIVERS\srv.sys
2010/12/26 16:58:47.0468 streamip (77813007ba6265c4b6098187e6ed79d2) C:\WINDOWS\system32\DRIVERS\StreamIP.sys
2010/12/26 16:58:48.0625 swenum (3941d127aef12e93addf6fe6ee027e0f) C:\WINDOWS\system32\DRIVERS\swenum.sys
2010/12/26 16:58:50.0281 swmidi (8ce882bcc6cf8a62f2b2323d95cb3d01) C:\WINDOWS\system32\drivers\swmidi.sys
2010/12/26 16:58:55.0484 sysaudio (8b83f3ed0f1688b4958f77cd6d2bf290) C:\WINDOWS\system32\drivers\sysaudio.sys
2010/12/26 16:58:56.0468 Tcpip (9aefa14bd6b182d61e3119fa5f436d3d) C:\WINDOWS\system32\DRIVERS\tcpip.sys
2010/12/26 16:58:57.0625 TDPIPE (6471a66807f5e104e4885f5b67349397) C:\WINDOWS\system32\drivers\TDPIPE.sys
2010/12/26 16:58:58.0812 TDTCP (c56b6d0402371cf3700eb322ef3aaf61) C:\WINDOWS\system32\drivers\TDTCP.sys
2010/12/26 16:58:59.0953 TermDD (88155247177638048422893737429d9e) C:\WINDOWS\system32\DRIVERS\termdd.sys
2010/12/26 16:59:02.0250 uagp35 (d85938f272d1bcf3db3a31fc0a048928) C:\WINDOWS\system32\DRIVERS\uagp35.sys
2010/12/26 16:59:03.0375 Udfs (5787b80c2e3c5e2f56c2a233d91fa2c9) C:\WINDOWS\system32\drivers\Udfs.sys
2010/12/26 16:59:04.0593 Update (402ddc88356b1bac0ee3dd1580c76a31) C:\WINDOWS\system32\DRIVERS\update.sys
2010/12/26 16:59:05.0343 USBAAPL (1df89c499bf45d878b87ebd4421d462d) C:\WINDOWS\system32\Drivers\usbaapl.sys
2010/12/26 16:59:05.0687 usbccgp (173f317ce0db8e21322e71b7e60a27e8) C:\WINDOWS\system32\DRIVERS\usbccgp.sys
2010/12/26 16:59:06.0015 usbehci (65dcf09d0e37d4c6b11b5b0b76d470a7) C:\WINDOWS\system32\DRIVERS\usbehci.sys
2010/12/26 16:59:06.0281 usbhub (1ab3cdde553b6e064d2e754efe20285c) C:\WINDOWS\system32\DRIVERS\usbhub.sys
2010/12/26 16:59:06.0734 usbprint (a717c8721046828520c9edf31288fc00) C:\WINDOWS\system32\DRIVERS\usbprint.sys
2010/12/26 16:59:07.0078 usbscan (a0b8cf9deb1184fbdd20784a58fa75d4) C:\WINDOWS\system32\DRIVERS\usbscan.sys
2010/12/26 16:59:07.0796 USBSTOR (a32426d9b14a089eaa1d922e0c5801a9) C:\WINDOWS\system32\DRIVERS\USBSTOR.SYS
2010/12/26 16:59:08.0265 usbuhci (26496f9dee2d787fc3e61ad54821ffe6) C:\WINDOWS\system32\DRIVERS\usbuhci.sys
2010/12/26 16:59:09.0562 usbvideo (63bbfca7f390f4c49ed4b96bfb1633e0) C:\WINDOWS\system32\Drivers\usbvideo.sys
2010/12/26 16:59:10.0828 VgaSave (0d3a8fafceacd8b7625cd549757a7df1) C:\WINDOWS\System32\drivers\vga.sys
2010/12/26 16:59:12.0984 ViaIde (3b3efcda263b8ac14fdf9cbdd0791b2e) C:\WINDOWS\system32\DRIVERS\viaide.sys
2010/12/26 16:59:14.0609 viamraid (7dc3e1dc6e4f8be381c31bfea578412a) C:\WINDOWS\system32\DRIVERS\viamraid.sys
2010/12/26 16:59:16.0062 VIAudio (ec14fedcfc97f0af98215ce385afec23) C:\WINDOWS\system32\drivers\viaudios.sys
2010/12/26 16:59:17.0890 videX32 (f95c0fcfbcbda6d8f202d2df4052f88d) C:\WINDOWS\system32\DRIVERS\videX32.sys
2010/12/26 16:59:19.0781 VolSnap (4c8fcb5cc53aab716d810740fe59d025) C:\WINDOWS\system32\drivers\VolSnap.sys
2010/12/26 16:59:20.0765 Vsp (aaf94bc88ecdf0ae0586805dad1e59c4) C:\WINDOWS\system32\drivers\Vsp.sys
2010/12/26 16:59:21.0906 Wanarp (e20b95baedb550f32dd489265c1da1f6) C:\WINDOWS\system32\DRIVERS\wanarp.sys
2010/12/26 16:59:23.0187 wdmaud (6768acf64b18196494413695f0c3a00f) C:\WINDOWS\system32\drivers\wdmaud.sys
2010/12/26 16:59:24.0375 winachsf (1225ebea76aac3c84df6c54fe5e5d8be) C:\WINDOWS\system32\DRIVERS\HSFCXTS2.sys
2010/12/26 16:59:26.0375 WSTCODEC (c98b39829c2bbd34e454150633c62c78) C:\WINDOWS\system32\DRIVERS\WSTCODEC.SYS
2010/12/26 16:59:27.0203 WudfPf (f15feafffbb3644ccc80c5da584e6311) C:\WINDOWS\system32\DRIVERS\WudfPf.sys
2010/12/26 16:59:28.0140 WudfRd (28b524262bce6de1f7ef9f510ba3985b) C:\WINDOWS\system32\DRIVERS\wudfrd.sys
2010/12/26 16:59:29.0187 zgwhsdiag (f2c38cd7b6696566da0c3485a41b43dc) C:\WINDOWS\system32\DRIVERS\zgwhsdiag.sys
2010/12/26 16:59:30.0531 zgwhsmdm (f2c38cd7b6696566da0c3485a41b43dc) C:\WINDOWS\system32\DRIVERS\zgwhsmdm.sys
2010/12/26 17:01:17.0593 ================================================================================
2010/12/26 17:01:17.0671 Scan finished
2010/12/26 17:01:17.0671 ================================================================================
2010/12/26 17:03:30.0062 Deinitialize success


SUPERAntiSpyware Scan Log
http://www.superantispyware.com

Generated 12/26/2010 at 04:36 PM

Application Version : 4.47.1000

Core Rules Database Version : 6069
Trace Rules Database Version: 3881

Scan type : Complete Scan
Total Scan Time : 00:54:09

Memory items scanned : 489
Memory threats detected : 0
Registry items scanned : 7403
Registry threats detected : 0
File items scanned : 21943
File threats detected : 35

Adware.Tracking Cookie
C:\Documents and Settings\Melane\Cookies\melane@dmtracker[1].txt
C:\Documents and Settings\Melane\Cookies\melane@hitbox[2].txt
C:\Documents and Settings\Melane\Cookies\melane@serving-sys[1].txt
C:\Documents and Settings\Melane\Cookies\melane@w3counter[1].txt
C:\Documents and Settings\Melane\Cookies\melane@overture[2].txt
C:\Documents and Settings\Melane\Cookies\melane@click.mooter[1].txt
C:\Documents and Settings\Melane\Cookies\melane@ad.yieldmanager[1].txt
C:\Documents and Settings\Melane\Cookies\melane@imrworldwide[2].txt
C:\Documents and Settings\Melane\Cookies\melane@ads.bleepingcomputer[3].txt
C:\Documents and Settings\Melane\Cookies\melane@atdmt[1].txt
C:\Documents and Settings\Melane\Cookies\melane@xxxcupid[1].txt
C:\Documents and Settings\Melane\Cookies\melane@casalemedia[2].txt
C:\Documents and Settings\Melane\Cookies\melane@www.xxxcupid[2].txt
C:\Documents and Settings\Melane\Cookies\melane@CASO4DIQ.txt
C:\Documents and Settings\Melane\Cookies\melane@bs.serving-sys[1].txt
C:\Documents and Settings\Melane\Cookies\melane@eset.122.2o7[1].txt
C:\Documents and Settings\Melane\Cookies\melane@doubleclick[1].txt
C:\Documents and Settings\Melane\Cookies\melane@advertise[1].txt
C:\Documents and Settings\Melane\Cookies\melane@statse.webtrendslive[6].txt
C:\Documents and Settings\Melane\Cookies\melane@paypal.112.2o7[1].txt
C:\Documents and Settings\Melane\Cookies\melane@ehg-eset.hitbox[2].txt
C:\Documents and Settings\Melane\Cookies\melane@wt.xxxcupid[1].txt
C:\Documents and Settings\Melane\Cookies\melane@collective-media[2].txt
C:\Documents and Settings\Melane\Cookies\melane@CAMY3JU7.txt
C:\Documents and Settings\Melane\Cookies\melane@revsci[2].txt
C:\Documents and Settings\Melane\Cookies\melane@microsoftwindows.112.2o7[1].txt
C:\Documents and Settings\Melane\Cookies\melane@insightexpressai[2].txt
C:\Documents and Settings\Melane\Cookies\melane@content.yieldmanager[1].txt
C:\Documents and Settings\Melane\Cookies\melane@stats.paypal[2].txt
C:\Documents and Settings\Melane\Cookies\melane@avgtechnologies.112.2o7[1].txt
stat.easydate.biz [ C:\Documents and Settings\Melane\Application Data\Macromedia\Flash Player\#SharedObjects\WG7BRD3U ]
C:\Documents and Settings\Melane\Cookies\melane@CADXOSK8.txt
C:\Documents and Settings\Melane\Cookies\melane@ads.bleepingcomputer[1].txt
C:\Documents and Settings\Melane\Cookies\melane@ehg-eset.hitbox[1].txt

Trojan.Agent/Gen-Nullo[Short]
C:\SYSTEM VOLUME INFORMATION\_RESTORE{0CBEF4E5-5CFA-47C2-A8A1-A518D92C0DF2}\RP385\A0131490.EXE


Malwarebytes' Anti-Malware 1.50.1.1100
www.malwarebytes.org

Database version: 5363

Windows 5.1.2600 Service Pack 3
Internet Explorer 8.0.6001.18702

26/12/2010 6:59:35 PM
mbam-log-2010-12-26 (18-59-35).txt

Scan type: Full scan (C:\|E:\|)
Objects scanned: 215024
Time elapsed: 1 hour(s), 46 minute(s), 35 second(s)

Memory Processes Infected: 0
Memory Modules Infected: 0
Registry Keys Infected: 0
Registry Values Infected: 0
Registry Data Items Infected: 0
Folders Infected: 0
Files Infected: 0

Memory Processes Infected:
(No malicious items detected)

Memory Modules Infected:
(No malicious items detected)

Registry Keys Infected:
(No malicious items detected)

Registry Values Infected:
(No malicious items detected)

Registry Data Items Infected:
(No malicious items detected)

Folders Infected:
(No malicious items detected)

Files Infected:
(No malicious items detected)

ESET
C:\WINDOWS\system32\drivers\etc\hosts Win32/Qhost trojan cleaned by deleting (after the next restart) - quarantined

Thank you so much.

#11 quietman7

quietman7

    Bleepin' Janitor


  • Global Moderator
  • 51,766 posts
  • OFFLINE
  •  
  • Gender:Male
  • Location:Virginia, USA
  • Local time:02:30 AM

Posted 27 December 2010 - 07:21 AM

These entries should be investigated further:

2010/12/26 16:57:05.0546 Suspicious service (NoAccess): bxtjvesaf
2010/12/26 16:57:13.0234 Suspicious service (NoAccess): gmecig


Unless you recognize them, I still recommend you follow the instructions I provided in Post #7.
.
.
Windows Insider MVP 2017-2018
Microsoft MVP Reconnect 2016
Microsoft MVP Consumer Security 2007-2015 kO7xOZh.gif
Member of UNITE, Unified Network of Instructors and Trusted Eliminators

If I have been helpful & you'd like to consider a donation, click 38WxTfO.gif

#12 starmmb

starmmb
  • Topic Starter

  • Members
  • 18 posts
  • OFFLINE
  •  
  • Local time:04:30 PM

Posted 28 December 2010 - 07:42 PM

Hello again, I have just completed the new post on the other forum section. I will let you know once someone has made contact. Thank you once again for all your support. It is very much appreciated.

#13 Orange Blossom

Orange Blossom

    OBleepin Investigator


  • Moderator
  • 37,011 posts
  • OFFLINE
  •  
  • Gender:Not Telling
  • Location:Bloomington, IN
  • Local time:02:30 AM

Posted 28 December 2010 - 10:03 PM

Hello,

Now that you have posted a log here: http://www.bleepingcomputer.com/forums/topic369906.html you should NOT make further changes to your computer (install/uninstall programs, use special fix tools, delete files, edit the registry, etc) unless advised by a MRT Team member, nor should you ask for help elsewhere. Doing so can result in system changes which may not show in the log you already posted. Further, any modifications you make on your own may cause confusion for the helper assisting you and could complicate the malware removal process which would extend the time it takes to clean your computer.

From this point on the MRT Team should be the only members that you take advice from, until they have verified your log as clean.

Please be patient. It may take a while to get a response because the MRT Team members are EXTREMELY busy working logs posted before yours. They are volunteers who will help you out as soon as possible. Once you have made your post and are waiting, please DO NOT make another reply until it has been responded to by a member of the MRT Team. Generally the staff checks the forum for postings that have 0 replies as this makes it easier for them to identify those who have not been helped. If you post another response there will be 1 reply. A team member, looking for a new log to work may assume another MRT Team member is already assisting you and not open the thread to respond.

Please be patient. It may take several days to get a response but your log will be reviewed and answered as soon as possible. I advise checking your topic once a day for responses as the e-mail notification system is unreliable.

To avoid confusion, I am closing this topic. Good luck with your log.

Orange Blossom :cherry:
Help us help you. If HelpBot replies, you MUST follow step 1 in its reply so we know you need help.

Orange Blossom

An ounce of prevention is worth a pound of cure

SpywareBlaster, WinPatrol Plus, ESET Smart Security, Malwarebytes' Anti-Malware, NoScript Firefox ext., Norton noscript




0 user(s) are reading this topic

0 members, 0 guests, 0 anonymous users