Jump to content


 


Register a free account to unlock additional features at BleepingComputer.com
Welcome to BleepingComputer, a free community where people like yourself come together to discuss and learn how to use their computers. Using the site is easy and fun. As a guest, you can browse and view the various discussions in the forums, but can not create a new topic or reply to an existing one unless you are logged in. Other benefits of registering an account are subscribing to topics and forums, creating a blog, and having no ads shown anywhere on the site.


Click here to Register a free account now! or read our Welcome Guide to learn how to use this site.

Photo

Kids installed various adware/software on accident.


  • Please log in to reply
5 replies to this topic

#1 REIDS

REIDS

  • Members
  • 102 posts
  • OFFLINE
  •  
  • Local time:03:29 PM

Posted 11 September 2013 - 06:20 PM

I am running Windows 7 Home version and use the free version of the Microsoft anti-virus program (I forget what it is called...).

 

So I came home to find out that my 8 year old son got on the internet and was clicking on all the blinking/colorful advertisements and the computer was running very slow. I noticed immediately that my IE had multiple toolbars installed that were not there before. When asked, my son didn't know what he clicked on.

 

I immediately unplugged the internet and proceeded to the control panel to see what was recently installed. I ended up removing approximately 15-20 small programs ranging from toolbar add-ons to games and advertisement software.

 

I was able to remove all programs that had been installed that day (that showed up in the add/remove programs option under the control panel), however, I don't know if there are still any adware/spyware programs or any other types of viruses that may have been transmitted onto my computer. Can someone help me with an appropriate scan of my system to make sure I don't have any spyware/adware/viruses on the computer?



BC AdBot (Login to Remove)

 


#2 Condobloke

Condobloke

    Outback Aussie @ 54.2101 N, 0.2906 W


  • Members
  • 6,047 posts
  • OFFLINE
  •  
  • Gender:Male
  • Local time:09:29 AM

Posted 11 September 2013 - 06:33 PM

 
 
 
 
 
 

* Save it to your Desktop.
* Double-click SecurityCheck.exe
* Follow the onscreen instructions inside the black box.
* A Notepad document should open automatically called checkup.txt; please post the contents of that document.
Note: If any security program requests permission to access the Internet, allow it to do so.

 

------------------------------------------------------------------------------------------------------------------------------------------------------------------

 

Please download  AdwCleaner by Xplode and save to your Desktop.

    Double click on AdwCleaner.exe to run the tool. Vista/Windows 7/8 users right-click and select Run As Administrator

.

    Click on the Scan button.

    AdwCleaner will begin...be patient as the scan may take some time to complete.

    After the scan has finished, click on the Report button...a logfile (AdwCleaner[R0].txt) will open in Notepad for review.

    Copy and paste the contents of that logfile in your next reply.

    A copy of all logfiles are saved in the C:\AdwCleaner folder which was created when running the tool.

 

 

 

-----------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------

 

 

Please download Malwarebytes Anti-Malware Free (aka MBAM)
Do not install the Free Trial Version at this time .........
* Double-click MBAM -setup.exe and follow the prompts to install the program.
* At the end, be sure to Check for Updates to be so it is current
* If an update is found, it will download and install the latest version.
* Once the program has loaded, select Scan, then click Quick Scan.
* When the scan is complete, click OK, then Show Results to view the results.
* Be sure that everything is checked, and click Remove Selected.
* When completed, a log will open in Notepad.
* Post the log back here.
If you are not sure of any items, post the log and ask if it should be removed.
Be sure to reboot the computer after you post the log.

 

 

-----------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------

Download SUPERAntiSpyware Free (aka SAS)
* Double-click SAS -setup.exe and follow the prompts to install the program.
* At the end, be sure to Check for Updates to be so it is current
* If an update is found, it will download and install the latest version.
* Once the program has loaded, select Perform quick scan, then click Scan.
* When the scan is complete, click OK, then Show Results to view the results.
* Be sure that everything is checked, and click Remove Selected.
* When completed, a log will open in Notepad.
* Post the log back here.
Be sure to reboot the computer after you post the log.

 

-------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------
Scan your machine with ESET OnlineScan
1. Hold down Control and click HERE to open ESET OnlineScan in a new window.
2. Click the ESET Online Scanner button.
3. NOTE :.For alternate browsers only: (Microsoft Internet Explorer users can skip these steps)
--------------------------------------------------------------------------
- 1. Click on esetsmartinstaller_enu.exe to download the ESET Smart Installer. Save it to your desktop.
- 2. Double click on the ESET Online Scanner icon on your desktop.

4. Check "YES, I accept the Terms of Use."
5. Click the Start button.
6. Accept any security warnings from your browser.
7. Under scan settings, check "Scan Archives" and "Remove found threats"
8. Click Advanced settings and select the following:
Scan potentially unwanted applications
Scan for potentially unsafe applications
Enable Anti-Stealth technology

9. ESET will then download updates for itself, install itself, and begin scanning your computer. Please be patient as this will take some time to download the program for a first time, and then download updated data base (1 to 2  hours is not unusual)
10. When the scan completes, click List Threats
11. Click Export, and save the file to your desktop using a unique name, such as ESETScan.
- Include the contents of this report in your next reply.
12. Click the Back button.
13. Click the Finish button
Or you can find a report at  C:\Program Files\esetonlinescanner\log.txt.


Edited by Condobloke, 11 September 2013 - 07:07 PM.

Condobloke ...Outback Australian  fed up with Windows antics...??....LINUX IS THE ANSWER....I USE LINUX MINT 18.3  EXCLUSIVELY.

“A man travels the world in search of what he needs and returns home to find it."

It has been said that time heals all wounds. I don't agree. The wounds remain. Time - the mind, protecting its sanity - covers them with some scar tissue and the pain lessens, but it is never gone. Rose Kennedy

 GcnI1aH.jpg

 

 


#3 REIDS

REIDS
  • Topic Starter

  • Members
  • 102 posts
  • OFFLINE
  •  
  • Local time:03:29 PM

Posted 15 September 2013 - 03:50 PM

SecurityCheck Content:

 Results of screen317's Security Check version 0.99.73
 Windows 7 Service Pack 1 x64 (UAC is enabled)
 Internet Explorer 10
``````````````Antivirus/Firewall Check:``````````````
 Windows Security Center service is not running! This report may not be accurate!
 Windows Firewall Enabled!
Microsoft Security Essentials 
 Antivirus up to date!
`````````Anti-malware/Other Utilities Check:`````````
 Secunia PSI (2.0.0.4003) 
 Java 7 Update 25
 Adobe Reader 10.1.7 Adobe Reader out of Date!
````````Process Check: objlist.exe by Laurent````````
 Microsoft Security Essentials MSMpEng.exe
 Microsoft Security Essentials msseces.exe
`````````````````System Health check`````````````````
 Total Fragmentation on Drive C: 0%
````````````````````End of Log``````````````````````

I ran the AdwCleaner program and it came up with 3 adware programs that I decided to remove (using this program), which made me restart the computer, so I restarted and then ran the security check program again and posted the associated report above. The report below is the report after I removed the adware.

# AdwCleaner v3.003 - Report created 14/09/2013 at 16:02:11
# Updated 07/09/2013 by Xplode
# Operating System : Windows 7 Home Premium Service Pack 1 (64 bits)
# Username : rstadel - TGOE_DESKTOP
# Running from : C:\Users\rstadel\Desktop\AdwCleaner.exe
# Option : Clean

***** [ Services ] *****

Service Deleted : APNMCP
[#] Service Deleted : dealplylive
[#] Service Deleted : dealplylivem

***** [ Files / Folders ] *****

Folder Deleted : C:\ProgramData\apn
Folder Deleted : C:\ProgramData\AskPartnerNetwork
Folder Deleted : C:\ProgramData\boost_interprocess
Folder Deleted : C:\ProgramData\Conduit
Folder Deleted : C:\ProgramData\DealPlyLive
Folder Deleted : C:\ProgramData\WeCareReminder
Folder Deleted : C:\Program Files (x86)\1ClickDownload
Folder Deleted : C:\Program Files (x86)\AskPartnerNetwork
Folder Deleted : C:\Program Files (x86)\Conduit
Folder Deleted : C:\Program Files (x86)\DealPly
Folder Deleted : C:\Program Files (x86)\DealPlyLive
Folder Deleted : C:\Program Files (x86)\lucky leap
Folder Deleted : C:\Users\rstadel\AppData\Local\Conduit
Folder Deleted : C:\Users\rstadel\AppData\Local\DealPlyLive
Folder Deleted : C:\Users\rstadel\AppData\Local\Temp\apn
Folder Deleted : C:\Users\rstadel\AppData\Local\Temp\AskSearch
Folder Deleted : C:\Users\rstadel\AppData\Local\Temp\boost_interprocess
Folder Deleted : C:\Users\rstadel\AppData\Local\Temp\TempDir
Folder Deleted : C:\Users\rstadel\AppData\LocalLow\Conduit
Folder Deleted : C:\Users\rstadel\AppData\LocalLow\Minibar
Folder Deleted : C:\Users\rstadel\AppData\LocalLow\PriceGong
Folder Deleted : C:\Users\rstadel\AppData\Roaming\DealPly
Folder Deleted : C:\Users\rstadel\AppData\Roaming\OpenCandy
Folder Deleted : C:\Users\rstadel\AppData\Roaming\SearchProtect
File Deleted : C:\END
File Deleted : C:\Users\rstadel\AppData\Local\Temp\Uninstall.exe
File Deleted : C:\Users\rstadel\AppData\Roaming\Mozilla\Firefox\Profiles\extensions\user.js
File Deleted : C:\Windows\Tasks\Dealply.job
File Deleted : C:\Windows\System32\Tasks\Dealply
File Deleted : C:\Windows\Tasks\DealPlyLiveUpdateTaskMachineCore.job
File Deleted : C:\Windows\System32\Tasks\DealPlyLiveUpdateTaskMachineCore
File Deleted : C:\Windows\Tasks\DealPlyLiveUpdateTaskMachineUA.job
File Deleted : C:\Windows\System32\Tasks\DealPlyLiveUpdateTaskMachineUA

***** [ Shortcuts ] *****

***** [ Registry ] *****

Key Deleted : HKLM\SOFTWARE\Google\Chrome\Extensions\pmlghpafmmnmmkjdhacccolfgnkiboco
Key Deleted : HKLM\SOFTWARE\Classes\AppID\dealplylive.exe
Key Deleted : HKLM\SOFTWARE\Classes\AppID\DefaultTabBHO.DLL
Key Deleted : HKLM\SOFTWARE\Classes\DealPlyLive.OneClickCtrl.9
Key Deleted : HKLM\SOFTWARE\Classes\DealPlyLive.OneClickProcessLauncherMachine
Key Deleted : HKLM\SOFTWARE\Classes\DealPlyLive.OneClickProcessLauncherMachine.1.0
Key Deleted : HKLM\SOFTWARE\Classes\DealPlyLive.Update3WebControl.3
Key Deleted : HKLM\SOFTWARE\Classes\DealPlyLiveUpdate.CoCreateAsync
Key Deleted : HKLM\SOFTWARE\Classes\DealPlyLiveUpdate.CoCreateAsync.1.0
Key Deleted : HKLM\SOFTWARE\Classes\dealplyliveupdate.coreclass
Key Deleted : HKLM\SOFTWARE\Classes\DealPlyLiveUpdate.CoreClass.1
Key Deleted : HKLM\SOFTWARE\Classes\DealPlyLiveUpdate.CoreMachineClass
Key Deleted : HKLM\SOFTWARE\Classes\DealPlyLiveUpdate.CoreMachineClass.1
Key Deleted : HKLM\SOFTWARE\Classes\dealplyliveupdate.credentialdialogmachine
Key Deleted : HKLM\SOFTWARE\Classes\dealplyliveupdate.credentialdialogmachine.1.0
Key Deleted : HKLM\SOFTWARE\Classes\dealplyliveupdate.ondemandcomclassmachine
Key Deleted : HKLM\SOFTWARE\Classes\DealPlyLiveUpdate.OnDemandCOMClassMachine.1.0
Key Deleted : HKLM\SOFTWARE\Classes\dealplyliveupdate.ondemandcomclassmachinefallback
Key Deleted : HKLM\SOFTWARE\Classes\dealplyliveupdate.ondemandcomclassmachinefallback.1.0
Key Deleted : HKLM\SOFTWARE\Classes\DealPlyLiveUpdate.OnDemandCOMClassSvc
Key Deleted : HKLM\SOFTWARE\Classes\dealplyliveupdate.ondemandcomclasssvc.1.0
Key Deleted : HKLM\SOFTWARE\Classes\DealPlyLiveUpdate.ProcessLauncher
Key Deleted : HKLM\SOFTWARE\Classes\DealPlyLiveUpdate.ProcessLauncher.1.0
Key Deleted : HKLM\SOFTWARE\Classes\DealPlyLiveUpdate.Update3COMClassService
Key Deleted : HKLM\SOFTWARE\Classes\DealPlyLiveUpdate.Update3COMClassService.1.0
Key Deleted : HKLM\SOFTWARE\Classes\dealplyliveupdate.update3webmachine
Key Deleted : HKLM\SOFTWARE\Classes\dealplyliveupdate.update3webmachine.1.0
Key Deleted : HKLM\SOFTWARE\Classes\dealplyliveupdate.update3webmachinefallback
Key Deleted : HKLM\SOFTWARE\Classes\dealplyliveupdate.update3webmachinefallback.1.0
Key Deleted : HKLM\SOFTWARE\Classes\dealplyliveupdate.update3websvc
Key Deleted : HKLM\SOFTWARE\Classes\dealplyliveupdate.update3websvc.1.0
Key Deleted : HKLM\SOFTWARE\Classes\DefaultTabBHO.DefaultTabBrowser
Key Deleted : HKLM\SOFTWARE\Classes\DefaultTabBHO.DefaultTabBrowser.1
Key Deleted : HKLM\SOFTWARE\Classes\DefaultTabBHO.DefaultTabBrowserActiveX
Key Deleted : HKLM\SOFTWARE\Classes\DefaultTabBHO.DefaultTabBrowserActiveX.1
Key Deleted : HKLM\SOFTWARE\Microsoft\Tracing\apnstub_RASAPI32
Key Deleted : HKLM\SOFTWARE\Microsoft\Tracing\apnstub_RASMANCS
Key Deleted : HKLM\SOFTWARE\Microsoft\Tracing\askpartnercobrandingtool_RASAPI32
Key Deleted : HKLM\SOFTWARE\Microsoft\tracing\askpartnercobrandingtool_RASMANCS
Key Deleted : HKLM\SOFTWARE\Microsoft\Tracing\AskSLib_RASAPI32
Key Deleted : HKLM\SOFTWARE\Microsoft\Tracing\AskSLib_RASMANCS
Key Deleted : HKLM\SOFTWARE\Microsoft\Tracing\Iminent_RASAPI32
Key Deleted : HKLM\SOFTWARE\Microsoft\Tracing\Iminent_RASMANCS
Key Deleted : HKLM\SOFTWARE\Microsoft\Tracing\QuickShare_RASAPI32
Key Deleted : HKLM\SOFTWARE\Microsoft\Tracing\QuickShare_RASMANCS
Key Deleted : HKLM\SOFTWARE\Microsoft\Tracing\TaskScheduler_RASAPI32
Key Deleted : HKLM\SOFTWARE\Microsoft\Tracing\TaskScheduler_RASMANCS
Key Deleted : HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\dealplylive.exe
Value Deleted : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run [ApnTbMon]
Key Deleted : HKLM\SOFTWARE\MozillaPlugins\@tools.dpliveupdate.com/DealPlyLive Update;version=3
Key Deleted : HKLM\SOFTWARE\MozillaPlugins\@tools.dpliveupdate.com/DealPlyLive Update;version=9
Key Deleted : HKLM\SOFTWARE\Classes\Toolbar.CT3314199
Key Deleted : HKLM\SOFTWARE\Classes\AppID\{5B1881D1-D9C7-46DF-B041-1E593282C7D0}
Key Deleted : HKLM\SOFTWARE\Classes\AppID\{608D3067-77E8-463D-9084-908966806826}
Key Deleted : HKLM\SOFTWARE\Classes\AppID\{80FABB17-63AF-4655-9F07-B6509EE37AF2}
Key Deleted : HKLM\SOFTWARE\Classes\AppID\{BDB69379-802F-4EAF-B541-F8DE92DD98DB}
Key Deleted : HKLM\SOFTWARE\Classes\AppID\{EA28B360-05E0-4F93-8150-02891F1D8D3C}
Key Deleted : HKLM\SOFTWARE\Classes\AppID\{F48FC5B2-094A-44C7-B48C-289738C9582D}
Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{02054E11-5113-4BE3-8153-AA8DFB5D3761}
Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{0D89DE71-3D99-4288-84DC-F18F1047A7D8}
Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{1E0C9B2A-6447-452C-B012-2314A0C29412}
Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{34A8CEB6-89BB-49F1-B5E4-0D0D6C21F3B1}
Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{35B8892D-C3FB-4D88-990D-31DB2EBD72BD}
Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{3A4DBD3A-98CC-41CE-AD21-352D42B6F754}
Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{3C471948-F874-49F5-B338-4F214A2EE0B1}
Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{4F8A50F6-69DE-4BE3-A33A-A1079B9AC0DB}
Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{501CB57A-D4E2-4855-96AD-EDB0A9083395}
Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{6E993643-8FBC-44FE-BC85-D318495C4D96}
Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{6FF2C4DD-77A4-4BB5-BA4C-B42DEFBF9137}
Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{7F1796B2-BEC6-427B-B734-F9C75ED94A80}
Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{7F6AFBF1-E065-4627-A2FD-810366367D01}
Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{80FABB17-63AF-4655-9F07-B6509EE37AF2}
Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{83ABA270-8390-4CA6-AE48-FC089F55629E}
Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{8B218A5F-1A3D-4347-94EF-A79575EB8094}
Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{8C338DDB-19FC-4C1F-B74D-6931EE55F7A1}
Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{9BDB5E09-4BBA-4422-8C2B-529B281C32B8}
Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{AE07101B-46D4-4A98-AF68-0333EA26E113}
Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{C536F080-57B7-46D6-8894-C647553F2889}
Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{CA5D945F-E738-4D0B-A0B5-25AC51C64659}
Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{D824F0DE-3D60-4F57-9EB1-66033ECD8ABB}
Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{DE9028D0-5FFA-4E69-94E3-89EE8741F468}
Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{E7DF6BFF-55A5-4EB7-A673-4ED3E9456D39}
Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{F48FC5B2-094A-44C7-B48C-289738C9582D}
Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{F7698761-4ABA-45C2-A5BB-D2163922C725}
Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{FFCC53E6-2655-47FC-A89B-54E8D7F305D1}
Key Deleted : HKLM\SOFTWARE\Classes\Interface\{021B4049-F57D-4565-A693-FD3B04786BFA}
Key Deleted : HKLM\SOFTWARE\Classes\Interface\{0362AA09-808D-48E9-B360-FB51A8CBCE09}
Key Deleted : HKLM\SOFTWARE\Classes\Interface\{03E2A1F3-4402-4121-8B35-733216D61217}
Key Deleted : HKLM\SOFTWARE\Classes\Interface\{06844020-CD0B-3D3D-A7FE-371153013E49}
Key Deleted : HKLM\SOFTWARE\Classes\Interface\{0ADC01BB-303B-3F8E-93DA-12C140E85460}
Key Deleted : HKLM\SOFTWARE\Classes\Interface\{10D3722F-23E6-3901-B6C1-FF6567121920}
Key Deleted : HKLM\SOFTWARE\Classes\Interface\{1675E62B-F911-3B7B-A046-EB57261212F3}
Key Deleted : HKLM\SOFTWARE\Classes\Interface\{192929F2-9273-3894-91B0-F54671C4C861}
Key Deleted : HKLM\SOFTWARE\Classes\Interface\{2932897E-3036-43D9-8A64-B06447992065}
Key Deleted : HKLM\SOFTWARE\Classes\Interface\{2DE92D29-A042-3C37-BFF8-07C7D8893EFA}
Key Deleted : HKLM\SOFTWARE\Classes\Interface\{32B80AD6-1214-45F4-994E-78A5D482C000}
Key Deleted : HKLM\SOFTWARE\Classes\Interface\{3A8E103F-B2B7-3BEF-B3B0-88E29B2420E4}
Key Deleted : HKLM\SOFTWARE\Classes\Interface\{3F607E46-0D3C-4442-B1DE-DE7FA4768F5C}
Key Deleted : HKLM\SOFTWARE\Classes\Interface\{478CE5D3-D38E-3FFE-8DBE-8C4A0F1C4D8D}
Key Deleted : HKLM\SOFTWARE\Classes\Interface\{48B7DA4E-69ED-39E3-BAD5-3E3EFF22CFB0}
Key Deleted : HKLM\SOFTWARE\Classes\Interface\{5982F405-44E4-3BBB-BAC4-CF8141CBBC5C}
Key Deleted : HKLM\SOFTWARE\Classes\Interface\{5D8C3CC3-3C05-38A1-B244-924A23115FE9}
Key Deleted : HKLM\SOFTWARE\Classes\Interface\{641593AF-D9FD-30F7-B783-36E16F7A2E08}
Key Deleted : HKLM\SOFTWARE\Classes\Interface\{711FC48A-1356-3932-94D8-A8B733DBC7E4}
Key Deleted : HKLM\SOFTWARE\Classes\Interface\{72227B7F-1F02-3560-95F5-592E68BACC0C}
Key Deleted : HKLM\SOFTWARE\Classes\Interface\{7B5E8CE3-4722-4C0E-A236-A6FF731BEF37}
Key Deleted : HKLM\SOFTWARE\Classes\Interface\{890D4F59-5ED0-3CB4-8E0E-74A5A86E7ED0}
Key Deleted : HKLM\SOFTWARE\Classes\Interface\{8C68913C-AC3C-4494-8B9C-984D87C85003}
Key Deleted : HKLM\SOFTWARE\Classes\Interface\{8D019513-083F-4AA5-933F-7D43A6DA82C4}
Key Deleted : HKLM\SOFTWARE\Classes\Interface\{923F6FB8-A390-370E-A0D2-DD505432481D}
Key Deleted : HKLM\SOFTWARE\Classes\Interface\{9BBB26EF-B178-35D6-9D3D-B485F4279FE5}
Key Deleted : HKLM\SOFTWARE\Classes\Interface\{9E3B11F6-4179-4603-A71B-A55F4BCB0BEC}
Key Deleted : HKLM\SOFTWARE\Classes\Interface\{A62DDBE0-8D2A-339A-B089-8CBCC5CD322A}
Key Deleted : HKLM\SOFTWARE\Classes\Interface\{A82AD04D-0B8E-3A49-947B-6A69A8A9C96D}
Key Deleted : HKLM\SOFTWARE\Classes\Interface\{ADEB3CC9-A05D-4FCC-BD09-9025456AA3EA}
Key Deleted : HKLM\SOFTWARE\Classes\Interface\{B06D4521-D09C-3F41-8E39-9D784CCA2A75}
Key Deleted : HKLM\SOFTWARE\Classes\Interface\{C06DAD42-6F39-4CE1-83CC-9A8B9105E556}
Key Deleted : HKLM\SOFTWARE\Classes\Interface\{C2E799D0-43A5-3477-8A98-FC5F3677F35C}
Key Deleted : HKLM\SOFTWARE\Classes\Interface\{D16107CD-2AD5-46A8-BA59-303B7C32C500}
Key Deleted : HKLM\SOFTWARE\Classes\Interface\{D25B101F-8188-3B43-9D85-201F372BC205}
Key Deleted : HKLM\SOFTWARE\Classes\Interface\{D2BA7595-5E44-3F1E-880F-03B3139FA5ED}
Key Deleted : HKLM\SOFTWARE\Classes\Interface\{D35F5C81-17D9-3E1C-A1FC-4472542E1D25}
Key Deleted : HKLM\SOFTWARE\Classes\Interface\{D8FA96CA-B250-312C-AF34-4FF1DD72589D}
Key Deleted : HKLM\SOFTWARE\Classes\Interface\{DAFC1E63-3359-416D-9BC2-E7DCA6F7B0F3}
Key Deleted : HKLM\SOFTWARE\Classes\Interface\{DC5E5C44-80FD-3697-9E65-9F286D92F3E7}
Key Deleted : HKLM\SOFTWARE\Classes\Interface\{E1B4C9DE-D741-385F-981E-6745FACE6F01}
Key Deleted : HKLM\SOFTWARE\Classes\Interface\{E7B623F5-9715-3F9F-A671-D1485A39F8A2}
Key Deleted : HKLM\SOFTWARE\Classes\Interface\{ED916A7B-7C68-3198-B87D-2DABC30A5587}
Key Deleted : HKLM\SOFTWARE\Classes\Interface\{EFA1BDB2-BB3D-3D9A-8EB5-D0D22E0F64F4}
Key Deleted : HKLM\SOFTWARE\Classes\Interface\{F4CBF4DD-F8FE-35BA-BB7E-68304DAAB70B}
Key Deleted : HKLM\SOFTWARE\Classes\Interface\{FC32005D-E27C-32E0-ADFA-152F598B75E7}
Key Deleted : HKLM\SOFTWARE\Classes\Interface\{FE0273D1-99DF-4AC0-87D5-1371C6271785}
Key Deleted : HKLM\SOFTWARE\Classes\TypeLib\{2BF2028E-3F3C-4C05-AB45-B2F1DCFE0759}
Key Deleted : HKLM\SOFTWARE\Classes\TypeLib\{93E3D79C-0786-48FF-9329-93BC9F6DC2B3}
Key Deleted : HKLM\SOFTWARE\Classes\TypeLib\{9C049BA6-EA47-4AC3-AED6-A66D8DC9E1D8}
Key Deleted : HKLM\SOFTWARE\Classes\TypeLib\{DB538320-D3C5-433C-BCA9-C4081A054FCF}
Key Deleted : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{02478D38-C3F9-4EFB-9B51-7695ECA05670}
Key Deleted : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{7F6AFBF1-E065-4627-A2FD-810366367D01}
Key Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{02478D38-C3F9-4EFB-9B51-7695ECA05670}
Key Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{7F6AFBF1-E065-4627-A2FD-810366367D01}
Key Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{AE07101B-46D4-4A98-AF68-0333EA26E113}
Key Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{F25AF245-4A81-40DC-92F9-E9021F207706}
Key Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{7F6AFBF1-E065-4627-A2FD-810366367D01}
Key Deleted : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{02478D38-C3F9-4EFB-9B51-7695ECA05670}
Key Deleted : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{7F1796B2-BEC6-427B-B734-F9C75ED94A80}
Key Deleted : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{7F6AFBF1-E065-4627-A2FD-810366367D01}
Key Deleted : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{8C338DDB-19FC-4C1F-B74D-6931EE55F7A1}
Key Deleted : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{EF99BD32-C1FB-11D2-892F-0090271D4F88}
Key Deleted : HKLM\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{68B81CCD-A80C-4060-8947-5AE69ED01199}
Key Deleted : HKLM\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{7F1796B2-BEC6-427B-B734-F9C75ED94A80}
Key Deleted : HKLM\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{8C338DDB-19FC-4C1F-B74D-6931EE55F7A1}
Key Deleted : HKLM\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{C536F080-57B7-46D6-8894-C647553F2889}
Key Deleted : HKLM\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{E6B969FB-6D33-48D2-9061-8BBD4899EB08}
Key Deleted : HKCU\Software\Microsoft\Internet Explorer\SearchScopes\{014DB5FA-EAFB-4592-A95B-F44D3EE87FA9}
Key Deleted : HKCU\Software\Microsoft\Internet Explorer\SearchScopes\{2FA28606-DE77-4029-AF96-B231E3B8F827}
Key Deleted : HKCU\Software\Microsoft\Internet Explorer\SearchScopes\{B7FCA997-D0FB-4FE0-8AFD-255E89CF9671}
Key Deleted : HKCU\Software\Microsoft\Internet Explorer\SearchScopes\{D43B3890-80C7-4010-A95D-1E77B5924DC3}
Key Deleted : HKLM\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{2FA28606-DE77-4029-AF96-B231E3B8F827}
Key Deleted : HKLM\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{B7FCA997-D0FB-4FE0-8AFD-255E89CF9671}
Key Deleted : HKLM\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{D43B3890-80C7-4010-A95D-1E77B5924DC3}
Value Deleted : HKLM\SOFTWARE\Microsoft\Internet Explorer\Toolbar [{AE07101B-46D4-4A98-AF68-0333EA26E113}]
Value Deleted : HKCU\Software\Microsoft\Internet Explorer\Toolbar\WebBrowser [{E7DF6BFF-55A5-4EB7-A673-4ED3E9456D39}]
Key Deleted : [x64] HKLM\SOFTWARE\Classes\CLSID\{AE07101B-46D4-4A98-AF68-0333EA26E113}
Value Deleted : [x64] HKLM\SOFTWARE\Microsoft\Internet Explorer\Toolbar [{AE07101B-46D4-4A98-AF68-0333EA26E113}]
Key Deleted : [x64] HKLM\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{2FA28606-DE77-4029-AF96-B231E3B8F827}
Key Deleted : [x64] HKLM\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{B7FCA997-D0FB-4FE0-8AFD-255E89CF9671}
Key Deleted : [x64] HKLM\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{D43B3890-80C7-4010-A95D-1E77B5924DC3}
Key Deleted : HKCU\Software\1ClickDownload
Key Deleted : HKCU\Software\APN PIP
Key Deleted : HKCU\Software\AskPartnerNetwork
Key Deleted : HKCU\Software\dealplylive
Key Deleted : HKCU\Software\Iminent
Key Deleted : HKCU\Software\SmartBar
Key Deleted : HKCU\Software\Webplayer
Key Deleted : HKCU\Software\AppDataLow\Software\Conduit
Key Deleted : HKCU\Software\AppDataLow\Software\ConduitSearchScopes
Key Deleted : HKCU\Software\AppDataLow\Software\LyricsGet
Key Deleted : HKCU\Software\AppDataLow\Software\PriceGong
Key Deleted : HKCU\Software\AppDataLow\Software\SmartBar
Key Deleted : HKLM\Software\AskPartnerNetwork
Key Deleted : HKLM\Software\Conduit
Key Deleted : HKLM\Software\dealplylive
Key Deleted : HKLM\Software\Iminent
Key Deleted : HKLM\Software\PIP
Key Deleted : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\SearchTheWebARP

***** [ Browsers ] *****

-\\ Internet Explorer v10.0.9200.16686

-\\ Mozilla Firefox v

[ File : C:\Users\rstadel\AppData\Roaming\Mozilla\Firefox\Profiles\extensions\prefs.js ]

*************************

AdwCleaner[R0].txt - [18435 octets] - [14/09/2013 16:00:11]
AdwCleaner[S0].txt - [18070 octets] - [14/09/2013 16:02:11]

########## EOF - C:\AdwCleaner\AdwCleaner[S0].txt - [18131 octets] ##########

 

 

Malwarebytes Anti-Malware 1.75.0.1300
www.malwarebytes.org

Database version: v2013.09.14.10

Windows 7 Service Pack 1 x64 NTFS
Internet Explorer 10.0.9200.16686
rstadel :: TGOE_DESKTOP [administrator]

9/14/2013 4:18:32 PM
mbam-log-2013-09-14 (16-18-32).txt

Scan type: Quick scan
Scan options enabled: Memory | Startup | Registry | File System | Heuristics/Extra | Heuristics/Shuriken | PUP | PUM
Scan options disabled: P2P
Objects scanned: 260242
Time elapsed: 10 minute(s), 58 second(s)

Memory Processes Detected: 0
(No malicious items detected)

Memory Modules Detected: 0
(No malicious items detected)

Registry Keys Detected: 12
HKCR\AppID\{38495740-0035-4471-851E-F5BBB86AB085} (PUP.Optional.DefaultTab.A) -> Quarantined and deleted successfully.
HKCR\AppID\{72D89EBF-0C5D-4190-91FD-398E45F1D007} (PUP.Optional.DefaultTab.A) -> Quarantined and deleted successfully.
HKCR\CLSID\{1AA60054-57D9-4F99-9A55-D0FBFBE7ECD3} (PUP.Optional.BrowseFox.A) -> Quarantined and deleted successfully.
HKCR\CLSID\{A1E28287-1A31-4b0f-8D05-AA8C465D3C5A} (PUP.Optional.DefaultTab.A) -> Quarantined and deleted successfully.
HKCR\TypeLib\{FEB62B15-CC00-4736-AAEC-BA046C9DFF73} (PUP.Optional.DefaultTab.A) -> Quarantined and deleted successfully.
HKCR\Interface\{1F8EDE97-36D5-422A-B8F0-9406E2D87C60} (PUP.Optional.DefaultTab.A) -> Quarantined and deleted successfully.
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{A1E28287-1A31-4B0F-8D05-AA8C465D3C5A} (PUP.Optional.DefaultTab.A) -> Quarantined and deleted successfully.
HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{7F6AFBF1-E065-4627-A2FD-810366367D01} (PUP.Optional.DefaultTab) -> Quarantined and deleted successfully.
HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\Stats\{CF190686-9E72-403C-B99D-682ABDB63C5B} (PUP.Optional.TopArcadeHits.A) -> Quarantined and deleted successfully.
HKCR\TypeLib\{DCABB943-792E-44C4-9029-ECBEE6265AF9} (PUP.Optional.Smart) -> Quarantined and deleted successfully.
HKCR\Interface\{3408AC0D-510E-4808-8F7B-6B70B1F88534} (PUP.Optional.Smart) -> Quarantined and deleted successfully.
HKLM\SOFTWARE\SWEETIM (PUP.Optional.SweetIM.A) -> Quarantined and deleted successfully.

Registry Values Detected: 1
HKLM\Software\SweetIM|simapp_id (PUP.Optional.SweetIM.A) -> Data: 11111111 -> Quarantined and deleted successfully.

Registry Data Items Detected: 0
(No malicious items detected)

Folders Detected: 0
(No malicious items detected)

Files Detected: 31
C:\Users\rstadel\AppData\Local\Temp\DealPlyUpdateVer.exe (PUP.DealPly.A) -> Quarantined and deleted successfully.
C:\Users\rstadel\AppData\Local\Temp\DownloadManager.exe (PUP.Optional.Smart) -> Quarantined and deleted successfully.
C:\Users\rstadel\AppData\Local\Temp\LuckyLeap.exe (PUP.Optional.LuckyLeap.A) -> Quarantined and deleted successfully.
C:\Users\rstadel\AppData\Local\Temp\mconduitinstaller.exe (PUP.Optional.Conduit.A) -> Quarantined and deleted successfully.
C:\Users\rstadel\AppData\Local\Temp\SPIdentifier.exe (PUP.Optional.Conduit.A) -> Quarantined and deleted successfully.
C:\Users\rstadel\AppData\Local\Temp\SPStub.exe (PUP.Optional.Conduit.A) -> Quarantined and deleted successfully.
C:\Users\rstadel\AppData\Local\Temp\60377607-a0fb-49b0-adba-9c435df33687\winamp563_full_emusic-7plus_en-us.exe (PUP.Optional.OpenCandy) -> Quarantined and deleted successfully.
C:\Users\rstadel\AppData\Local\Temp\ct3314199\ctbe.exe (PUP.Optional.Conduit.A) -> Quarantined and deleted successfully.
C:\Users\rstadel\AppData\Local\Temp\ct3314199\ieLogic.exe (PUP.Optional.Conduit.A) -> Quarantined and deleted successfully.
C:\Users\rstadel\AppData\Local\Temp\ct3314199\statisticsStub.exe (PUP.Optional.Conduit.A) -> Quarantined and deleted successfully.
C:\Users\rstadel\AppData\Local\Temp\ct3314199\stub.exe (PUP.Optional.Conduit.A) -> Quarantined and deleted successfully.
C:\Users\rstadel\Local Settings\Temporary Internet Files\Content.IE5\0YO7L4HQ\iminent[1].msi (PUP.Optional.Iminent) -> Quarantined and deleted successfully.
C:\Users\rstadel\Local Settings\Temporary Internet Files\Content.IE5\0YO7L4HQ\SetupToparcadehits[1].exe (Adware.GameVance) -> Quarantined and deleted successfully.
C:\Users\rstadel\Local Settings\Temporary Internet Files\Content.IE5\2WLADZYB\checktbexist[1].exe (PUP.Optional.Conduit.A) -> Quarantined and deleted successfully.
C:\Users\rstadel\Local Settings\Temporary Internet Files\Content.IE5\73MXKXMC\MinibarChrome[1].exe (PUP.Optional.Iminent.A) -> Quarantined and deleted successfully.
C:\Users\rstadel\Local Settings\Temporary Internet Files\Content.IE5\73MXKXMC\Setup[1].exe (PUP.Optional.LuckyLeap.A) -> Quarantined and deleted successfully.
C:\Users\rstadel\Local Settings\Temporary Internet Files\Content.IE5\ERTDXWW4\IminentSetup[1].exe (PUP.Iminent.A) -> Quarantined and deleted successfully.
C:\Users\rstadel\Local Settings\Temporary Internet Files\Content.IE5\ERTDXWW4\LuckyLeap2[1].exe (PUP.Optional.LuckyLeap.A) -> Quarantined and deleted successfully.
C:\Users\rstadel\Local Settings\Temporary Internet Files\Content.IE5\ERTDXWW4\SPChecker[1].exe (PUP.Optional.Conduit.A) -> Quarantined and deleted successfully.
C:\Users\rstadel\Local Settings\Temporary Internet Files\Content.IE5\ERTDXWW4\statisticsstub[1].exe (PUP.Optional.Conduit.A) -> Quarantined and deleted successfully.
C:\Users\rstadel\Local Settings\Temporary Internet Files\Content.IE5\K8DOZQ6I\conduitinstaller[1].exe (PUP.Optional.Conduit.A) -> Quarantined and deleted successfully.
C:\Users\rstadel\Local Settings\Temporary Internet Files\Content.IE5\KOZ0HIIM\appshat-distribution[1].exe (PUP.Optional.Somoto.A) -> Quarantined and deleted successfully.
C:\Users\rstadel\Local Settings\Temporary Internet Files\Content.IE5\KOZ0HIIM\filesfrog-distribution[1].exe (PUP.Optional.Somoto.A) -> Quarantined and deleted successfully.
C:\Users\rstadel\Local Settings\Temporary Internet Files\Content.IE5\KOZ0HIIM\Installer[1].exe (PUP.Optional.SmartBar.A) -> Quarantined and deleted successfully.
C:\Users\rstadel\Local Settings\Temporary Internet Files\Content.IE5\PC4FXWW3\SweetPacks_A2[1].exe (PUP.Optional.Conduit.A) -> Quarantined and deleted successfully.
C:\Users\rstadel\Local Settings\Temporary Internet Files\Content.IE5\XM29U0A7\dp[1].exe (PUP.DealPly.A) -> Quarantined and deleted successfully.
C:\Users\rstadel\Local Settings\Temporary Internet Files\Content.IE5\XM29U0A7\Freegiez_MineCraft.exe (PUP.Optional.Smart) -> Quarantined and deleted successfully.
C:\Users\rstadel\Local Settings\Temporary Internet Files\Content.IE5\XM29U0A7\IminentMinibarIE[1].exe (PUP.Optional.Iminent.A) -> Quarantined and deleted successfully.
C:\Users\rstadel\Local Settings\Temporary Internet Files\Content.IE5\Y23P3687\minibar-core[1].exe (PUP.Optional.MiniBar.A) -> Quarantined and deleted successfully.
C:\Users\rstadel\Local Settings\Temporary Internet Files\Content.IE5\Y23P3687\MinibarFirefox[1].exe (PUP.Optional.Iminent.A) -> Quarantined and deleted successfully.
C:\Users\rstadel\Local Settings\Temporary Internet Files\Content.IE5\Y23P3687\SweetPacksCND_SMART[1].exe (PUP.Optional.Conduit.A) -> Quarantined and deleted successfully.

(end)

 

 

 

SUPERAntiSpyware Scan Log
http://www.superantispyware.com

Generated 09/14/2013 at 04:57 PM

Application Version : 5.6.1032

Core Rules Database Version : 10768
Trace Rules Database Version: 8580

Scan type       : Quick Scan
Total Scan Time : 00:14:00

Operating System Information
Windows 7 Home Premium 64-bit, Service Pack 1 (Build 6.01.7601)
UAC On - Limited User

Memory items scanned      : 624
Memory threats detected   : 0
Registry items scanned    : 60349
Registry threats detected : 0
File items scanned        : 13409
File threats detected     : 501

Adware.Tracking Cookie
 C:\Users\rstadel\AppData\Roaming\Microsoft\Windows\Cookies\ZEH8RX32.txt [ /ads.intergi.com ]
 C:\Users\rstadel\AppData\Roaming\Microsoft\Windows\Cookies\VW2MRZOC.txt [ /advertising.com ]
 C:\Users\rstadel\AppData\Roaming\Microsoft\Windows\Cookies\3DRDNE1P.txt [ /pointroll.com ]
 C:\Users\rstadel\AppData\Roaming\Microsoft\Windows\Cookies\C0CH312N.txt [ /mediaforge.com ]
 C:\Users\rstadel\AppData\Roaming\Microsoft\Windows\Cookies\IF4FV40C.txt [ /zedo.com ]
 C:\Users\rstadel\AppData\Roaming\Microsoft\Windows\Cookies\SXVXU4PL.txt [ /ads.p161.net ]
 C:\Users\rstadel\AppData\Roaming\Microsoft\Windows\Cookies\S6H60QPU.txt [ /clickfuse.com ]
 C:\Users\rstadel\AppData\Roaming\Microsoft\Windows\Cookies\TML9FGUA.txt [ /insightexpressai.com ]
 C:\Users\rstadel\AppData\Roaming\Microsoft\Windows\Cookies\Q0HMPBT9.txt [ /burstnet.com ]
 C:\Users\rstadel\AppData\Roaming\Microsoft\Windows\Cookies\IN8P8I8B.txt [ /2o7.net ]
 C:\Users\rstadel\AppData\Roaming\Microsoft\Windows\Cookies\1FC1Z1UK.txt [ /mediaplex.com ]
 C:\Users\rstadel\AppData\Roaming\Microsoft\Windows\Cookies\9VB2FBAP.txt [ /media6degrees.com ]
 C:\Users\rstadel\AppData\Roaming\Microsoft\Windows\Cookies\PNM3S7BZ.txt [ /www.nramedia.org ]
 C:\Users\rstadel\AppData\Roaming\Microsoft\Windows\Cookies\T1MKBT6D.txt [ /ads.creative-serving.com ]
 C:\Users\rstadel\AppData\Roaming\Microsoft\Windows\Cookies\A6ZEYNQ5.txt [ /ipcmedia.122.2o7.net ]
 C:\Users\rstadel\AppData\Roaming\Microsoft\Windows\Cookies\VOQ89RVM.txt [ /ads.undertone.com ]
 C:\Users\rstadel\AppData\Roaming\Microsoft\Windows\Cookies\13W3O01P.txt [ /serving-sys.com ]
 C:\Users\rstadel\AppData\Roaming\Microsoft\Windows\Cookies\WRU6IDO4.txt [ /ad.yieldmanager.com ]
 C:\Users\rstadel\AppData\Roaming\Microsoft\Windows\Cookies\JVE8Z14V.txt [ /oxmedia.srvoverlay.com ]
 C:\Users\rstadel\AppData\Roaming\Microsoft\Windows\Cookies\H2RH5Z6S.txt [ /accounts.google.com ]
 C:\Users\rstadel\AppData\Roaming\Microsoft\Windows\Cookies\MZRLJFDT.txt [ /server.cpmstar.com ]
 C:\Users\rstadel\AppData\Roaming\Microsoft\Windows\Cookies\75JTGEJQ.txt [ /thefind.com ]
 C:\Users\rstadel\AppData\Roaming\Microsoft\Windows\Cookies\A9GLUBAK.txt [ /bs.serving-sys.com ]
 C:\Users\rstadel\AppData\Roaming\Microsoft\Windows\Cookies\2JUNKN04.txt [ /adserver.adtechus.com ]
 C:\Users\rstadel\AppData\Roaming\Microsoft\Windows\Cookies\RY6BL2RE.txt [ /fastclick.net ]
 C:\Users\rstadel\AppData\Roaming\Microsoft\Windows\Cookies\CVW28CUS.txt [ /d.tracksrv.com ]
 C:\Users\rstadel\AppData\Roaming\Microsoft\Windows\Cookies\HSBOO020.txt [ /network.realmedia.com ]
 C:\Users\rstadel\AppData\Roaming\Microsoft\Windows\Cookies\KNX2WPBI.txt [ /trafficmp.com ]
 C:\Users\rstadel\AppData\Roaming\Microsoft\Windows\Cookies\7H3LQA9M.txt [ /revsci.net ]
 C:\Users\rstadel\AppData\Roaming\Microsoft\Windows\Cookies\5KLU27L1.txt [ /winzip.122.2o7.net ]
 C:\Users\rstadel\AppData\Roaming\Microsoft\Windows\Cookies\DKO88BKE.txt [ /a1.interclick.com ]
 C:\Users\rstadel\AppData\Roaming\Microsoft\Windows\Cookies\1OR60N9U.txt [ /ad.360yield.com ]
 C:\Users\rstadel\AppData\Roaming\Microsoft\Windows\Cookies\WRK8REC0.txt [ /247realmedia.com ]
 C:\Users\rstadel\AppData\Roaming\Microsoft\Windows\Cookies\6VJ8ORPN.txt [ /interclick.com ]
 C:\Users\rstadel\AppData\Roaming\Microsoft\Windows\Cookies\RM5X3X29.txt [ /ads.pointroll.com ]
 C:\Users\rstadel\AppData\Roaming\Microsoft\Windows\Cookies\NDT1F1B1.txt [ /track.adform.net ]
 C:\Users\rstadel\AppData\Roaming\Microsoft\Windows\Cookies\SE79K1RA.txt [ /questionmarket.com ]
 C:\Users\rstadel\AppData\Roaming\Microsoft\Windows\Cookies\OSOO427M.txt [ /ads.ad4game.com ]
 C:\Users\rstadel\AppData\Roaming\Microsoft\Windows\Cookies\XOXQON25.txt [ /invitemedia.com ]
 C:\Users\rstadel\AppData\Roaming\Microsoft\Windows\Cookies\Q13X6SWZ.txt [ /adtechus.com ]
 C:\Users\rstadel\AppData\Roaming\Microsoft\Windows\Cookies\M47ERJUW.txt [ /pro-market.net ]
 C:\Users\rstadel\AppData\Roaming\Microsoft\Windows\Cookies\WKBDN7G5.txt [ /t.pointroll.com ]
 C:\Users\rstadel\AppData\Roaming\Microsoft\Windows\Cookies\IVUXAQ4G.txt [ /atdmt.com ]
 C:\Users\rstadel\AppData\Roaming\Microsoft\Windows\Cookies\VJ5X0C97.txt [ /adxpose.com ]
 C:\Users\rstadel\AppData\Roaming\Microsoft\Windows\Cookies\NUJJHGZL.txt [ /oxmedia.iweb.cortica.com ]
 C:\Users\rstadel\AppData\Roaming\Microsoft\Windows\Cookies\RYJYNZ84.txt [ /ru4.com ]
 C:\Users\rstadel\AppData\Roaming\Microsoft\Windows\Cookies\ODNJDHD0.txt [ /legolas-media.com ]
 C:\Users\rstadel\AppData\Roaming\Microsoft\Windows\Cookies\XMP512YV.txt [ /intermundomedia.com ]
 C:\Users\rstadel\AppData\Roaming\Microsoft\Windows\Cookies\Z5YYT129.txt [ /collective-media.net ]
 C:\Users\rstadel\AppData\Roaming\Microsoft\Windows\Cookies\0X6H67NV.txt [ /adfarm1.adition.com ]
 C:\Users\rstadel\AppData\Roaming\Microsoft\Windows\Cookies\KESU0BO1.txt [ /adtech.de ]
 C:\Users\rstadel\AppData\Roaming\Microsoft\Windows\Cookies\1BATE6DI.txt [ /ad2.adfarm1.adition.com ]
 C:\Users\rstadel\AppData\Roaming\Microsoft\Windows\Cookies\3W1UY5EQ.txt [ /doubleclick.net ]
 C:\Users\rstadel\AppData\Roaming\Microsoft\Windows\Cookies\JUTKBOJB.txt [ /imrworldwide.com ]
 C:\Users\rstadel\AppData\Roaming\Microsoft\Windows\Cookies\H3VQCRH4.txt [ /casalemedia.com ]
 C:\Users\rstadel\AppData\Roaming\Microsoft\Windows\Cookies\28CB755T.txt [ /adbrite.com ]
 C:\Users\rstadel\AppData\Roaming\Microsoft\Windows\Cookies\4MR656MF.txt [ /mediaservices-d.openxenterprise.com ]
 C:\Users\rstadel\AppData\Roaming\Microsoft\Windows\Cookies\LEC31TAR.txt [ /ad.mlnadvertising.com ]
 C:\Users\rstadel\AppData\Roaming\Microsoft\Windows\Cookies\LHAUVD3E.txt [ /at.atwola.com ]
 C:\Users\rstadel\AppData\Roaming\Microsoft\Windows\Cookies\CSF9AL4W.txt [ /saymedia.com ]
 C:\Users\rstadel\AppData\Roaming\Microsoft\Windows\Cookies\243KUBBF.txt [ /tribalfusion.com ]
 C:\Users\rstadel\AppData\Roaming\Microsoft\Windows\Cookies\ANFIZGIB.txt [ /apmebf.com ]
 C:\Users\rstadel\AppData\Roaming\Microsoft\Windows\Cookies\I7NHWR40.txt [ /specificclick.net ]
 C:\Users\rstadel\AppData\Roaming\Microsoft\Windows\Cookies\YJ2VAP2I.txt [ /yieldmanager.net ]
 C:\Users\rstadel\AppData\Roaming\Microsoft\Windows\Cookies\XNIOOC0Q.txt [ /media.campaigner.com ]
 C:\Users\rstadel\AppData\Roaming\Microsoft\Windows\Cookies\ZNHRXZLD.txt [ /lucidmedia.com ]
 C:\Users\rstadel\AppData\Roaming\Microsoft\Windows\Cookies\PE7CI2Z7.txt [ /realmedia.com ]
 C:\Users\rstadel\AppData\Roaming\Microsoft\Windows\Cookies\6F9EW2SX.txt [ /ads.us.e-planning.net ]
 C:\Users\rstadel\AppData\Roaming\Microsoft\Windows\Cookies\Low\I63JDCH4.txt [ /csc.112.2o7.net ]
 C:\Users\rstadel\AppData\Roaming\Microsoft\Windows\Cookies\Low\KHCQLN97.txt [ /liveperson.net ]
 C:\Users\rstadel\AppData\Roaming\Microsoft\Windows\Cookies\Low\6U6GKOTG.txt [ /tracking.dsmmadvantage.com ]
 C:\Users\rstadel\AppData\Roaming\Microsoft\Windows\Cookies\Low\71MMA3T3.txt [ /clicksor.com ]
 C:\Users\rstadel\AppData\Roaming\Microsoft\Windows\Cookies\Low\QKIBZZ1H.txt [ /ads.intergi.com ]
 C:\Users\rstadel\AppData\Roaming\Microsoft\Windows\Cookies\Low\4DYKT4N6.txt [ /advertising.com ]
 C:\Users\rstadel\AppData\Roaming\Microsoft\Windows\Cookies\Low\QQ0DRH4I.txt [ /www.lacountyfair.com ]
 C:\Users\rstadel\AppData\Roaming\Microsoft\Windows\Cookies\Low\3OUGXG3W.txt [ /sftrack.searchforce.net ]
 C:\Users\rstadel\AppData\Roaming\Microsoft\Windows\Cookies\Low\TLU3YXPE.txt [ /www.traditionaloven.com ]
 C:\Users\rstadel\AppData\Roaming\Microsoft\Windows\Cookies\Low\TODPDLY0.txt [ /pointroll.com ]
 C:\Users\rstadel\AppData\Roaming\Microsoft\Windows\Cookies\Low\41XCKMLN.txt [ /andomedia.com ]
 C:\Users\rstadel\AppData\Roaming\Microsoft\Windows\Cookies\Low\FJ1ICBME.txt [ /media.adfrontiers.com ]
 C:\Users\rstadel\AppData\Roaming\Microsoft\Windows\Cookies\Low\TBILFFYX.txt [ /e-2dj6wjl4enc5obp.stats.esomniture.com ]
 C:\Users\rstadel\AppData\Roaming\Microsoft\Windows\Cookies\Low\CA2JPPHD.txt [ /zakmj.tripod.com ]
 C:\Users\rstadel\AppData\Roaming\Microsoft\Windows\Cookies\Low\U491KJXK.txt [ /e-2dj6wnliapc5efo.stats.esomniture.com ]
 C:\Users\rstadel\AppData\Roaming\Microsoft\Windows\Cookies\Low\NEP0UTBO.txt [ /frostclick.com ]
 C:\Users\rstadel\AppData\Roaming\Microsoft\Windows\Cookies\Low\X6SI51EH.txt [ /yadro.ru ]
 C:\Users\rstadel\AppData\Roaming\Microsoft\Windows\Cookies\Low\7QWBH0EC.txt [ /mediaforge.com ]
 C:\Users\rstadel\AppData\Roaming\Microsoft\Windows\Cookies\Low\P76KFVPZ.txt [ /zedo.com ]
 C:\Users\rstadel\AppData\Roaming\Microsoft\Windows\Cookies\Low\W7Z0TD2W.txt [ /liveperson.net ]
 C:\Users\rstadel\AppData\Roaming\Microsoft\Windows\Cookies\Low\5O9W4YKS.txt [ /ads.p161.net ]
 C:\Users\rstadel\AppData\Roaming\Microsoft\Windows\Cookies\Low\L56TTCQ4.txt [ /ict.infinity-tracking.net ]
 C:\Users\rstadel\AppData\Roaming\Microsoft\Windows\Cookies\Low\T9LMAP9Z.txt [ /ads.batpmturner.com ]
 C:\Users\rstadel\AppData\Roaming\Microsoft\Windows\Cookies\Low\02209MO0.txt [ /countryoutfitter.com ]
 C:\Users\rstadel\AppData\Roaming\Microsoft\Windows\Cookies\Low\TGVG1UJW.txt [ /www.3dstats.com ]
 C:\Users\rstadel\AppData\Roaming\Microsoft\Windows\Cookies\Low\79TIOEO9.txt [ /clickfuse.com ]
 C:\Users\rstadel\AppData\Roaming\Microsoft\Windows\Cookies\Low\ZMSZDRPB.txt [ /www.burstbeacon.com ]
 C:\Users\rstadel\AppData\Roaming\Microsoft\Windows\Cookies\Low\R5BOV5ET.txt [ /insightexpressai.com ]
 C:\Users\rstadel\AppData\Roaming\Microsoft\Windows\Cookies\Low\IIC9PS93.txt [ /media2.legacy.com ]
 C:\Users\rstadel\AppData\Roaming\Microsoft\Windows\Cookies\Low\SEW763XA.txt [ /lego.112.2o7.net ]
 C:\Users\rstadel\AppData\Roaming\Microsoft\Windows\Cookies\Low\U0HGTOP7.txt [ /azjmp.com ]
 C:\Users\rstadel\AppData\Roaming\Microsoft\Windows\Cookies\Low\1OFE8SBQ.txt [ /dc.tremormedia.com ]
 C:\Users\rstadel\AppData\Roaming\Microsoft\Windows\Cookies\Low\QBS2RLNY.txt [ /lfstmedia.com ]
 C:\Users\rstadel\AppData\Roaming\Microsoft\Windows\Cookies\Low\6JUYY9KI.txt [ /ads.syracuse.com ]
 C:\Users\rstadel\AppData\Roaming\Microsoft\Windows\Cookies\Low\TMQKP8NJ.txt [ /microsoftsto.112.2o7.net ]
 C:\Users\rstadel\AppData\Roaming\Microsoft\Windows\Cookies\Low\0ZX0G18O.txt [ /media.photobucket.com ]
 C:\Users\rstadel\AppData\Roaming\Microsoft\Windows\Cookies\Low\7BMAO6TI.txt [ /www.googleadservices.com ]
 C:\Users\rstadel\AppData\Roaming\Microsoft\Windows\Cookies\Low\JZN7QWV1.txt [ /www.googleadservices.com ]
 C:\Users\rstadel\AppData\Roaming\Microsoft\Windows\Cookies\Low\GIQC1JC2.txt [ /www.googleadservices.com ]
 C:\Users\rstadel\AppData\Roaming\Microsoft\Windows\Cookies\Low\BP4QD71D.txt [ /www.googleadservices.com ]
 C:\Users\rstadel\AppData\Roaming\Microsoft\Windows\Cookies\Low\K221C8CK.txt [ /www.googleadservices.com ]
 C:\Users\rstadel\AppData\Roaming\Microsoft\Windows\Cookies\Low\4WLO3GBD.txt [ /www.googleadservices.com ]
 C:\Users\rstadel\AppData\Roaming\Microsoft\Windows\Cookies\Low\U4OFZ11C.txt [ /www.googleadservices.com ]
 C:\Users\rstadel\AppData\Roaming\Microsoft\Windows\Cookies\Low\0K91LIL5.txt [ /www.googleadservices.com ]
 C:\Users\rstadel\AppData\Roaming\Microsoft\Windows\Cookies\Low\H7B0KWAY.txt [ /www.googleadservices.com ]
 C:\Users\rstadel\AppData\Roaming\Microsoft\Windows\Cookies\Low\C7SJ2W1U.txt [ /www.googleadservices.com ]
 C:\Users\rstadel\AppData\Roaming\Microsoft\Windows\Cookies\Low\DBCXSH9X.txt [ /www.googleadservices.com ]
 C:\Users\rstadel\AppData\Roaming\Microsoft\Windows\Cookies\Low\RR064Q4F.txt [ /www.googleadservices.com ]
 C:\Users\rstadel\AppData\Roaming\Microsoft\Windows\Cookies\Low\W2G7QH0E.txt [ /www.googleadservices.com ]
 C:\Users\rstadel\AppData\Roaming\Microsoft\Windows\Cookies\Low\IR4EHCAH.txt [ /www.googleadservices.com ]
 C:\Users\rstadel\AppData\Roaming\Microsoft\Windows\Cookies\Low\W0Y9069J.txt [ /www.googleadservices.com ]
 C:\Users\rstadel\AppData\Roaming\Microsoft\Windows\Cookies\Low\6318C8WX.txt [ /www.googleadservices.com ]
 C:\Users\rstadel\AppData\Roaming\Microsoft\Windows\Cookies\Low\GGR9593S.txt [ /www.googleadservices.com ]
 C:\Users\rstadel\AppData\Roaming\Microsoft\Windows\Cookies\Low\0V3M1OH3.txt [ /www.googleadservices.com ]
 C:\Users\rstadel\AppData\Roaming\Microsoft\Windows\Cookies\Low\8TKUJANR.txt [ /www.googleadservices.com ]
 C:\Users\rstadel\AppData\Roaming\Microsoft\Windows\Cookies\Low\ACIAU080.txt [ /www.googleadservices.com ]
 C:\Users\rstadel\AppData\Roaming\Microsoft\Windows\Cookies\Low\9JN5X6NU.txt [ /www.googleadservices.com ]
 C:\Users\rstadel\AppData\Roaming\Microsoft\Windows\Cookies\Low\BWO4NMOD.txt [ /www.googleadservices.com ]
 C:\Users\rstadel\AppData\Roaming\Microsoft\Windows\Cookies\Low\0HSEZD0G.txt [ /www.googleadservices.com ]
 C:\Users\rstadel\AppData\Roaming\Microsoft\Windows\Cookies\Low\HGLCHHPZ.txt [ /www.googleadservices.com ]
 C:\Users\rstadel\AppData\Roaming\Microsoft\Windows\Cookies\Low\VWAHX8G6.txt [ /www.googleadservices.com ]
 C:\Users\rstadel\AppData\Roaming\Microsoft\Windows\Cookies\Low\Y7CSXEEY.txt [ /www.googleadservices.com ]
 C:\Users\rstadel\AppData\Roaming\Microsoft\Windows\Cookies\Low\JJMPU2GJ.txt [ /www.googleadservices.com ]
 C:\Users\rstadel\AppData\Roaming\Microsoft\Windows\Cookies\Low\ZDH2LKZW.txt [ /www.googleadservices.com ]
 C:\Users\rstadel\AppData\Roaming\Microsoft\Windows\Cookies\Low\HHIA2ZLB.txt [ /www.googleadservices.com ]
 C:\Users\rstadel\AppData\Roaming\Microsoft\Windows\Cookies\Low\GAKVBS1O.txt [ /www.googleadservices.com ]
 C:\Users\rstadel\AppData\Roaming\Microsoft\Windows\Cookies\Low\9LDJ5SCF.txt [ /www.googleadservices.com ]
 C:\Users\rstadel\AppData\Roaming\Microsoft\Windows\Cookies\Low\XZM9J1UH.txt [ /www.googleadservices.com ]
 C:\Users\rstadel\AppData\Roaming\Microsoft\Windows\Cookies\Low\DCIT8R0Q.txt [ /www.googleadservices.com ]
 C:\Users\rstadel\AppData\Roaming\Microsoft\Windows\Cookies\Low\8WPGIVLD.txt [ /www.googleadservices.com ]
 C:\Users\rstadel\AppData\Roaming\Microsoft\Windows\Cookies\Low\N06BSFP6.txt [ /www.googleadservices.com ]
 C:\Users\rstadel\AppData\Roaming\Microsoft\Windows\Cookies\Low\OFK9174Y.txt [ /www.googleadservices.com ]
 C:\Users\rstadel\AppData\Roaming\Microsoft\Windows\Cookies\Low\5JL9TN3S.txt [ /www.googleadservices.com ]
 C:\Users\rstadel\AppData\Roaming\Microsoft\Windows\Cookies\Low\G93VH5KF.txt [ /www.googleadservices.com ]
 C:\Users\rstadel\AppData\Roaming\Microsoft\Windows\Cookies\Low\K1T30WOT.txt [ /www.googleadservices.com ]
 C:\Users\rstadel\AppData\Roaming\Microsoft\Windows\Cookies\Low\P0K9C1X6.txt [ /www.googleadservices.com ]
 C:\Users\rstadel\AppData\Roaming\Microsoft\Windows\Cookies\Low\SEZHPF2D.txt [ /www.googleadservices.com ]
 C:\Users\rstadel\AppData\Roaming\Microsoft\Windows\Cookies\Low\O3AT5ERE.txt [ /discount-hydro.com ]
 C:\Users\rstadel\AppData\Roaming\Microsoft\Windows\Cookies\Low\82VLNDYY.txt [ /pbteen.com ]
 C:\Users\rstadel\AppData\Roaming\Microsoft\Windows\Cookies\Low\LRM7WR22.txt [ /stanislavs.tripod.com ]
 C:\Users\rstadel\AppData\Roaming\Microsoft\Windows\Cookies\Low\AOFZ4YX6.txt [ /realfoodmedia.advertserve.com ]
 C:\Users\rstadel\AppData\Roaming\Microsoft\Windows\Cookies\Low\C3Y3LCZ7.txt [ /microsoftwindows.112.2o7.net ]
 C:\Users\rstadel\AppData\Roaming\Microsoft\Windows\Cookies\Low\GXY8PJ6W.txt [ /www.backcountry.com ]
 C:\Users\rstadel\AppData\Roaming\Microsoft\Windows\Cookies\Low\XCU20ZKE.txt [ /liveperson.net ]
 C:\Users\rstadel\AppData\Roaming\Microsoft\Windows\Cookies\Low\JL6FZD9E.txt [ /liveperson.net ]
 C:\Users\rstadel\AppData\Roaming\Microsoft\Windows\Cookies\Low\0JHSQB5V.txt [ /mycounter.tinycounter.com ]
 C:\Users\rstadel\AppData\Roaming\Microsoft\Windows\Cookies\Low\21FKYT33.txt [ /ehg-reed.hitbox.com ]
 C:\Users\rstadel\AppData\Roaming\Microsoft\Windows\Cookies\Low\RRY66LAT.txt [ /burstnet.com ]
 C:\Users\rstadel\AppData\Roaming\Microsoft\Windows\Cookies\Low\3X7X6YMX.txt [ /www.mediaite.com ]
 C:\Users\rstadel\AppData\Roaming\Microsoft\Windows\Cookies\Low\Z2E5L5NM.txt [ /2o7.net ]
 C:\Users\rstadel\AppData\Roaming\Microsoft\Windows\Cookies\Low\OW86YBG5.txt [ /ads.masslive.com ]
 C:\Users\rstadel\AppData\Roaming\Microsoft\Windows\Cookies\Low\NZEI17VY.txt [ /mediaplex.com ]
 C:\Users\rstadel\AppData\Roaming\Microsoft\Windows\Cookies\Low\PAD5495L.txt [ /media6degrees.com ]
 C:\Users\rstadel\AppData\Roaming\Microsoft\Windows\Cookies\Low\AHZOQZSO.txt [ /amazonservices.122.2o7.net ]
 C:\Users\rstadel\AppData\Roaming\Microsoft\Windows\Cookies\Low\0DBWXB5U.txt [ /www.webstatschecker.com ]
 C:\Users\rstadel\AppData\Roaming\Microsoft\Windows\Cookies\Low\JIQ9LRVP.txt [ /std-clinics.findthebest.com ]
 C:\Users\rstadel\AppData\Roaming\Microsoft\Windows\Cookies\Low\M1XN8PE1.txt [ /survey.g.doubleclick.net ]
 C:\Users\rstadel\AppData\Roaming\Microsoft\Windows\Cookies\Low\B2MKF3SF.txt [ /activenetwork.122.2o7.net ]
 C:\Users\rstadel\AppData\Roaming\Microsoft\Windows\Cookies\Low\3OIUYDWA.txt [ /ads.creative-serving.com ]
 C:\Users\rstadel\AppData\Roaming\Microsoft\Windows\Cookies\Low\MDZJVTMJ.txt [ /ev.ads.pointroll.com ]
 C:\Users\rstadel\AppData\Roaming\Microsoft\Windows\Cookies\Low\XGCEGM47.txt [ /stats.powersites.net ]
 C:\Users\rstadel\AppData\Roaming\Microsoft\Windows\Cookies\Low\CIUF96LV.txt [ /ipcmedia.122.2o7.net ]
 C:\Users\rstadel\AppData\Roaming\Microsoft\Windows\Cookies\Low\KUHM3SGI.txt [ /martiniadnetwork.com ]
 C:\Users\rstadel\AppData\Roaming\Microsoft\Windows\Cookies\Low\UK69RQTD.txt [ /skyscanner.net ]
 C:\Users\rstadel\AppData\Roaming\Microsoft\Windows\Cookies\Low\QRANR2U1.txt [ /freddiemac.122.2o7.net ]
 C:\Users\rstadel\AppData\Roaming\Microsoft\Windows\Cookies\Low\3HRU091J.txt [ /findlaw.com ]
 C:\Users\rstadel\AppData\Roaming\Microsoft\Windows\Cookies\Low\XY22WMIG.txt [ /liveperson.net ]
 C:\Users\rstadel\AppData\Roaming\Microsoft\Windows\Cookies\Low\API1QNZ9.txt [ /msnportal.112.2o7.net ]
 C:\Users\rstadel\AppData\Roaming\Microsoft\Windows\Cookies\Low\6WO5E5GX.txt [ /mmstat.com ]
 C:\Users\rstadel\AppData\Roaming\Microsoft\Windows\Cookies\Low\O3DYM2L2.txt [ /gmchevrolet.112.2o7.net ]
 C:\Users\rstadel\AppData\Roaming\Microsoft\Windows\Cookies\Low\OM9V76BR.txt [ /e-2dj6wjkywhdjkho.stats.esomniture.com ]
 C:\Users\rstadel\AppData\Roaming\Microsoft\Windows\Cookies\Low\PCA991ZT.txt [ /ads.undertone.com ]
 C:\Users\rstadel\AppData\Roaming\Microsoft\Windows\Cookies\Low\5LVRQRNF.txt [ /enhance.com ]
 C:\Users\rstadel\AppData\Roaming\Microsoft\Windows\Cookies\Low\S0FJFGLK.txt [ /media.net ]
 C:\Users\rstadel\AppData\Roaming\Microsoft\Windows\Cookies\Low\DHRPSAEY.txt [ /adserv.dreadlockssite.com ]
 C:\Users\rstadel\AppData\Roaming\Microsoft\Windows\Cookies\Low\1RCFEPTC.txt [ /serving-sys.com ]
 C:\Users\rstadel\AppData\Roaming\Microsoft\Windows\Cookies\Low\5IEIE08J.txt [ /ad.yieldmanager.com ]
 C:\Users\rstadel\AppData\Roaming\Microsoft\Windows\Cookies\Low\B2YMK2G3.txt [ /interchangecorporation.122.2o7.net ]
 C:\Users\rstadel\AppData\Roaming\Microsoft\Windows\Cookies\Low\BNCLAM6Y.txt [ /www.nextag.com ]
 C:\Users\rstadel\AppData\Roaming\Microsoft\Windows\Cookies\Low\XO7XNAWI.txt [ /www.growstorefinder.com ]
 C:\Users\rstadel\AppData\Roaming\Microsoft\Windows\Cookies\Low\M9J09ZUV.txt [ /countryvillageliving.com ]
 C:\Users\rstadel\AppData\Roaming\Microsoft\Windows\Cookies\Low\FACPFE1U.txt [ /e-2dj6afkiggajslq.stats.esomniture.com ]
 C:\Users\rstadel\AppData\Roaming\Microsoft\Windows\Cookies\Low\CBIQE18I.txt [ /a.iad.lpsnmedia.net ]
 C:\Users\rstadel\AppData\Roaming\Microsoft\Windows\Cookies\Low\WYOA4NQS.txt [ /192com.112.2o7.net ]
 C:\Users\rstadel\AppData\Roaming\Microsoft\Windows\Cookies\Low\EU7PDC7Z.txt [ /e-2dj6wjnywhcjelp.stats.esomniture.com ]
 C:\Users\rstadel\AppData\Roaming\Microsoft\Windows\Cookies\Low\F3HHKJ57.txt [ /media.gsimedia.net ]
 C:\Users\rstadel\AppData\Roaming\Microsoft\Windows\Cookies\Low\MWLX740S.txt [ /zulily.db.advertising.com ]
 C:\Users\rstadel\AppData\Roaming\Microsoft\Windows\Cookies\Low\6CKO3W1U.txt [ /kanoodle.com ]
 C:\Users\rstadel\AppData\Roaming\Microsoft\Windows\Cookies\Low\13LL1CKN.txt [ /ads.cartoonnetwork.com ]
 C:\Users\rstadel\AppData\Roaming\Microsoft\Windows\Cookies\Low\3731CMDB.txt [ /gid.inferclick.com ]
 C:\Users\rstadel\AppData\Roaming\Microsoft\Windows\Cookies\Low\BKDFWSYC.txt [ /lacountyfair.com ]
 C:\Users\rstadel\AppData\Roaming\Microsoft\Windows\Cookies\Low\BJO6OFSS.txt [ /liveperson.net ]
 C:\Users\rstadel\AppData\Roaming\Microsoft\Windows\Cookies\Low\TM2DI1TV.txt [ /amazon-adsystem.com ]
 C:\Users\rstadel\AppData\Roaming\Microsoft\Windows\Cookies\Low\UVUGEGBP.txt [ /liveperson.net ]
 C:\Users\rstadel\AppData\Roaming\Microsoft\Windows\Cookies\Low\73HL033F.txt [ /fieldandstream.com.122.2o7.net ]
 C:\Users\rstadel\AppData\Roaming\Microsoft\Windows\Cookies\Low\QRONA35G.txt [ /accounts.google.com ]
 C:\Users\rstadel\AppData\Roaming\Microsoft\Windows\Cookies\Low\B8Z3N9BR.txt [ /server.cpmstar.com ]
 C:\Users\rstadel\AppData\Roaming\Microsoft\Windows\Cookies\Low\C1EDV7ET.txt [ /liveperson.net ]
 C:\Users\rstadel\AppData\Roaming\Microsoft\Windows\Cookies\Low\3PPM4NP9.txt [ /statse.webtrendslive.com ]
 C:\Users\rstadel\AppData\Roaming\Microsoft\Windows\Cookies\Low\32CESJ0E.txt [ /thefind.com ]
 C:\Users\rstadel\AppData\Roaming\Microsoft\Windows\Cookies\Low\X0AA9C59.txt [ /testdata.coremetrics.com ]
 C:\Users\rstadel\AppData\Roaming\Microsoft\Windows\Cookies\Low\8I3X987O.txt [ /e-2dj6wjl4eic5sko.stats.esomniture.com ]
 C:\Users\rstadel\AppData\Roaming\Microsoft\Windows\Cookies\Low\XYIFPO7S.txt [ /f.blogads.com ]
 C:\Users\rstadel\AppData\Roaming\Microsoft\Windows\Cookies\Low\YP0RLAJ8.txt [ /1sadx.net ]
 C:\Users\rstadel\AppData\Roaming\Microsoft\Windows\Cookies\Low\0UBASQ4K.txt [ /california-sales-tax-rate.findthebest.com ]
 C:\Users\rstadel\AppData\Roaming\Microsoft\Windows\Cookies\Low\P60V2APT.txt [ /boostmobile.112.2o7.net ]
 C:\Users\rstadel\AppData\Roaming\Microsoft\Windows\Cookies\Low\1ECYEDEB.txt [ /hitbox.com ]
 C:\Users\rstadel\AppData\Roaming\Microsoft\Windows\Cookies\Low\JP35V7KY.txt [ /sexycostumes.com ]
 C:\Users\rstadel\AppData\Roaming\Microsoft\Windows\Cookies\Low\DD97YSBL.txt [ /bs.serving-sys.com ]
 C:\Users\rstadel\AppData\Roaming\Microsoft\Windows\Cookies\Low\SOA3ZBLQ.txt [ /ads.tunein.com ]
 C:\Users\rstadel\AppData\Roaming\Microsoft\Windows\Cookies\Low\2CHNHEWJ.txt [ /adserver.adtechus.com ]
 C:\Users\rstadel\AppData\Roaming\Microsoft\Windows\Cookies\Low\ES0XAFOB.txt [ /solutions.122.2o7.net ]
 C:\Users\rstadel\AppData\Roaming\Microsoft\Windows\Cookies\Low\JZH50L38.txt [ /a.intentmedia.net ]
 C:\Users\rstadel\AppData\Roaming\Microsoft\Windows\Cookies\Low\NXHRUBPO.txt [ /www.skyscanner.com ]
 C:\Users\rstadel\AppData\Roaming\Microsoft\Windows\Cookies\Low\XVY2KI12.txt [ /liveperson.net ]
 C:\Users\rstadel\AppData\Roaming\Microsoft\Windows\Cookies\Low\PSNK3GEJ.txt [ /findthebest.com ]
 C:\Users\rstadel\AppData\Roaming\Microsoft\Windows\Cookies\Low\3A1R6A2K.txt [ /emailfinder.com ]
 C:\Users\rstadel\AppData\Roaming\Microsoft\Windows\Cookies\Low\DR6ELJ4Y.txt [ /fastclick.net ]
 C:\Users\rstadel\AppData\Roaming\Microsoft\Windows\Cookies\Low\5D6M270B.txt [ /d.tracksrv.com ]
 C:\Users\rstadel\AppData\Roaming\Microsoft\Windows\Cookies\Low\DQUHN264.txt [ /steelhousemedia.com ]
 C:\Users\rstadel\AppData\Roaming\Microsoft\Windows\Cookies\Low\E5EC64TL.txt [ /network.realmedia.com ]
 C:\Users\rstadel\AppData\Roaming\Microsoft\Windows\Cookies\Low\AX7WTQ17.txt [ /www.arbookfind.com ]
 C:\Users\rstadel\AppData\Roaming\Microsoft\Windows\Cookies\Low\GGJXMLC3.txt [ /trafficmp.com ]
 C:\Users\rstadel\AppData\Roaming\Microsoft\Windows\Cookies\Low\25S7EQV7.txt [ /e-2dj6wgmiehdzsbp.stats.esomniture.com ]
 C:\Users\rstadel\AppData\Roaming\Microsoft\Windows\Cookies\Low\W1EZMDQL.txt [ /ads.verticalscope.com ]
 C:\Users\rstadel\AppData\Roaming\Microsoft\Windows\Cookies\Low\5XLPQW97.txt [ /microsoftwlsearchcrm.112.2o7.net ]
 C:\Users\rstadel\AppData\Roaming\Microsoft\Windows\Cookies\Low\4YO5C5S3.txt [ /ox-d.mmaadnet.com ]
 C:\Users\rstadel\AppData\Roaming\Microsoft\Windows\Cookies\Low\IGKPU37Q.txt [ /tracking.websitealive.com ]
 C:\Users\rstadel\AppData\Roaming\Microsoft\Windows\Cookies\Low\191W1V3I.txt [ /eset.122.2o7.net ]
 C:\Users\rstadel\AppData\Roaming\Microsoft\Windows\Cookies\Low\U25H9P3K.txt [ /estat.com ]
 C:\Users\rstadel\AppData\Roaming\Microsoft\Windows\Cookies\Low\0IC8STZP.txt [ /furryfriendsrescue.org ]
 C:\Users\rstadel\AppData\Roaming\Microsoft\Windows\Cookies\Low\W5MUIJI5.txt [ /revsci.net ]
 C:\Users\rstadel\AppData\Roaming\Microsoft\Windows\Cookies\Low\YZXPKU09.txt [ /weborama.fr ]
 C:\Users\rstadel\AppData\Roaming\Microsoft\Windows\Cookies\Low\IAUW8014.txt [ /winzip.122.2o7.net ]
 C:\Users\rstadel\AppData\Roaming\Microsoft\Windows\Cookies\Low\PP04OXO0.txt [ /citi.bridgetrack.com ]
 C:\Users\rstadel\AppData\Roaming\Microsoft\Windows\Cookies\Low\29BOY0R7.txt [ /a1.interclick.com ]
 C:\Users\rstadel\AppData\Roaming\Microsoft\Windows\Cookies\Low\51CGYKJU.txt [ /uk.sitestat.com ]
 C:\Users\rstadel\AppData\Roaming\Microsoft\Windows\Cookies\Low\XCDWHJC3.txt [ /delivery.bluefinmediaads.com ]
 C:\Users\rstadel\AppData\Roaming\Microsoft\Windows\Cookies\Low\BKSN1HU6.txt [ /e-2dj6wfkisoazshq.stats.esomniture.com ]
 C:\Users\rstadel\AppData\Roaming\Microsoft\Windows\Cookies\Low\7RU2X4ZN.txt [ /server.adformdsp.net ]
 C:\Users\rstadel\AppData\Roaming\Microsoft\Windows\Cookies\Low\RDIJP2LC.txt [ /statcounter.com ]
 C:\Users\rstadel\AppData\Roaming\Microsoft\Windows\Cookies\Low\KIDULOOI.txt [ /ad.360yield.com ]
 C:\Users\rstadel\AppData\Roaming\Microsoft\Windows\Cookies\Low\RUNMX7GF.txt [ /careers.peopleclick.com ]
 C:\Users\rstadel\AppData\Roaming\Microsoft\Windows\Cookies\Low\1O1KJ5PQ.txt [ /liveperson.net ]
 C:\Users\rstadel\AppData\Roaming\Microsoft\Windows\Cookies\Low\0IOJXKXA.txt [ /traffic.prod.cobaltgroup.com ]
 C:\Users\rstadel\AppData\Roaming\Microsoft\Windows\Cookies\Low\T4NSOJLY.txt [ /arbookfind.com ]
 C:\Users\rstadel\AppData\Roaming\Microsoft\Windows\Cookies\Low\PTRPMFV5.txt [ /e-2dj6wmkyqpazcfp.stats.esomniture.com ]
 C:\Users\rstadel\AppData\Roaming\Microsoft\Windows\Cookies\Low\HMT3AIH8.txt [ /ad.leadbolt.net ]
 C:\Users\rstadel\AppData\Roaming\Microsoft\Windows\Cookies\Low\TW695PI6.txt [ /findthedata.org ]
 C:\Users\rstadel\AppData\Roaming\Microsoft\Windows\Cookies\Low\8Q65GX83.txt [ /vancepublishing.112.2o7.net ]
 C:\Users\rstadel\AppData\Roaming\Microsoft\Windows\Cookies\Low\XJ8IU0D3.txt [ /ads.foodbuzz.com ]
 C:\Users\rstadel\AppData\Roaming\Microsoft\Windows\Cookies\Low\B8VB3BK1.txt [ /uac.advertising.com ]
 C:\Users\rstadel\AppData\Roaming\Microsoft\Windows\Cookies\Low\DBEII05E.txt [ /liveperson.net ]
 C:\Users\rstadel\AppData\Roaming\Microsoft\Windows\Cookies\Low\N7L42IOG.txt [ /tracking.feedperfect.com ]
 C:\Users\rstadel\AppData\Roaming\Microsoft\Windows\Cookies\Low\PEN8XLKM.txt [ /ads.imaging-resource.com ]
 C:\Users\rstadel\AppData\Roaming\Microsoft\Windows\Cookies\Low\5L2R6CU3.txt [ /www.countryoutfitter.com ]
 C:\Users\rstadel\AppData\Roaming\Microsoft\Windows\Cookies\Low\N8YMLDXM.txt [ /247realmedia.com ]
 C:\Users\rstadel\AppData\Roaming\Microsoft\Windows\Cookies\Low\E7VOS3TU.txt [ /interclick.com ]
 C:\Users\rstadel\AppData\Roaming\Microsoft\Windows\Cookies\Low\ZSR72MJS.txt [ /ad.auditude.com ]
 C:\Users\rstadel\AppData\Roaming\Microsoft\Windows\Cookies\Low\A1XSSTO4.txt [ /staradvertiser.com ]
 C:\Users\rstadel\AppData\Roaming\Microsoft\Windows\Cookies\Low\LIZ8EI7O.txt [ /ads.pointroll.com ]
 C:\Users\rstadel\AppData\Roaming\Microsoft\Windows\Cookies\Low\6US1WHG2.txt [ /ads.cleveland.com ]
 C:\Users\rstadel\AppData\Roaming\Microsoft\Windows\Cookies\Low\JMXUQ8UZ.txt [ /click.livesearchnow.com ]
 C:\Users\rstadel\AppData\Roaming\Microsoft\Windows\Cookies\Low\AXM6E2F6.txt [ /track.adform.net ]
 C:\Users\rstadel\AppData\Roaming\Microsoft\Windows\Cookies\Low\Q4X9OOJZ.txt [ /msnbc.112.2o7.net ]
 C:\Users\rstadel\AppData\Roaming\Microsoft\Windows\Cookies\Low\2PZAVQZR.txt [ /ihg2.db.advertising.com ]
 C:\Users\rstadel\AppData\Roaming\Microsoft\Windows\Cookies\Low\19XM2L51.txt [ /virginamerica.112.2o7.net ]
 C:\Users\rstadel\AppData\Roaming\Microsoft\Windows\Cookies\Low\P4BT8017.txt [ /ads.bleepingcomputer.com ]
 C:\Users\rstadel\AppData\Roaming\Microsoft\Windows\Cookies\Low\43DEISE4.txt [ /mediaite.com ]
 C:\Users\rstadel\AppData\Roaming\Microsoft\Windows\Cookies\Low\HKX12PTA.txt [ /questionmarket.com ]
 C:\Users\rstadel\AppData\Roaming\Microsoft\Windows\Cookies\Low\0BV4QYM8.txt [ /ads.asp.net ]
 C:\Users\rstadel\AppData\Roaming\Microsoft\Windows\Cookies\Low\ZL0MCKN4.txt [ /www.mediamath.me ]
 C:\Users\rstadel\AppData\Roaming\Microsoft\Windows\Cookies\Low\80HVU93X.txt [ /ads.ad4game.com ]
 C:\Users\rstadel\AppData\Roaming\Microsoft\Windows\Cookies\Low\SLEWLEI1.txt [ /liveperson.net ]
 C:\Users\rstadel\AppData\Roaming\Microsoft\Windows\Cookies\Low\HMBR1X32.txt [ /www.sexycostumes.com ]
 C:\Users\rstadel\AppData\Roaming\Microsoft\Windows\Cookies\Low\6JK144SG.txt [ /stats.exph.net ]
 C:\Users\rstadel\AppData\Roaming\Microsoft\Windows\Cookies\Low\3KIF7CN9.txt [ /invitemedia.com ]
 C:\Users\rstadel\AppData\Roaming\Microsoft\Windows\Cookies\Low\HSASO8VY.txt [ /findlocalweather.com ]
 C:\Users\rstadel\AppData\Roaming\Microsoft\Windows\Cookies\Low\Z1QXX7AJ.txt [ /adtechus.com ]
 C:\Users\rstadel\AppData\Roaming\Microsoft\Windows\Cookies\Low\13932BK3.txt [ /www.qsstats.com ]
 C:\Users\rstadel\AppData\Roaming\Microsoft\Windows\Cookies\Low\3A0ASXCX.txt [ /adserver.avalonsunsplash.com ]
 C:\Users\rstadel\AppData\Roaming\Microsoft\Windows\Cookies\Low\OHJ9GRBX.txt [ /skyscanner.com ]
 C:\Users\rstadel\AppData\Roaming\Microsoft\Windows\Cookies\Low\8NB1N6Y9.txt [ /warnerbros.112.2o7.net ]
 C:\Users\rstadel\AppData\Roaming\Microsoft\Windows\Cookies\Low\YE0AZTXJ.txt [ /ads.nj.com ]
 C:\Users\rstadel\AppData\Roaming\Microsoft\Windows\Cookies\Low\3NFKGZAE.txt [ /atwola.com ]
 C:\Users\rstadel\AppData\Roaming\Microsoft\Windows\Cookies\Low\I8L1YB8M.txt [ /thcfinder.com ]
 C:\Users\rstadel\AppData\Roaming\Microsoft\Windows\Cookies\Low\DCACYD1N.txt [ /leeenterprises.112.2o7.net ]
 C:\Users\rstadel\AppData\Roaming\Microsoft\Windows\Cookies\Low\88UL9UPK.txt [ /ads.vayama.com ]
 C:\Users\rstadel\AppData\Roaming\Microsoft\Windows\Cookies\Low\22M5WLEE.txt [ /amazonlocal.122.2o7.net ]
 C:\Users\rstadel\AppData\Roaming\Microsoft\Windows\Cookies\Low\JX7EZTUJ.txt [ /in.getclicky.com ]
 C:\Users\rstadel\AppData\Roaming\Microsoft\Windows\Cookies\Low\MQB3YCBV.txt [ /www.bizrate.com ]
 C:\Users\rstadel\AppData\Roaming\Microsoft\Windows\Cookies\Low\LBBGFVOV.txt [ /pro-market.net ]
 C:\Users\rstadel\AppData\Roaming\Microsoft\Windows\Cookies\Low\AGN76H5N.txt [ /brownshoe.112.2o7.net ]
 C:\Users\rstadel\AppData\Roaming\Microsoft\Windows\Cookies\Low\A15EXBRN.txt [ /marketlive.122.2o7.net ]
 C:\Users\rstadel\AppData\Roaming\Microsoft\Windows\Cookies\Low\YSVA7E2N.txt [ /t.pointroll.com ]
 C:\Users\rstadel\AppData\Roaming\Microsoft\Windows\Cookies\Low\S1CFLICK.txt [ /pacificdentalservices.112.2o7.net ]
 C:\Users\rstadel\AppData\Roaming\Microsoft\Windows\Cookies\Low\3N56CFTO.txt [ /evite.112.2o7.net ]
 C:\Users\rstadel\AppData\Roaming\Microsoft\Windows\Cookies\Low\1PHT5AF9.txt [ /onrampadvertising.com ]
 C:\Users\rstadel\AppData\Roaming\Microsoft\Windows\Cookies\Low\U0R60RCY.txt [ /ehg-verizon.hitbox.com ]
 C:\Users\rstadel\AppData\Roaming\Microsoft\Windows\Cookies\Low\CPOEB3UT.txt [ /static.freewebs.getclicky.com ]
 C:\Users\rstadel\AppData\Roaming\Microsoft\Windows\Cookies\Low\S720LSYS.txt [ /adv.dmv.org ]
 C:\Users\rstadel\AppData\Roaming\Microsoft\Windows\Cookies\Low\WW30L91X.txt [ /forums.govteen.com ]
 C:\Users\rstadel\AppData\Roaming\Microsoft\Windows\Cookies\Low\ZM7O7VN5.txt [ /ads.pennlive.com ]
 C:\Users\rstadel\AppData\Roaming\Microsoft\Windows\Cookies\Low\IQFQSJEH.txt [ /ad.propellerads.com ]
 C:\Users\rstadel\AppData\Roaming\Microsoft\Windows\Cookies\Low\E4LOFC85.txt [ /liveperson.net ]
 C:\Users\rstadel\AppData\Roaming\Microsoft\Windows\Cookies\Low\R3MPCLKS.txt [ /ads.pubmatic.com ]
 C:\Users\rstadel\AppData\Roaming\Microsoft\Windows\Cookies\Low\GVALZ0UN.txt [ /atdmt.com ]
 C:\Users\rstadel\AppData\Roaming\Microsoft\Windows\Cookies\Low\BBCTW36G.txt [ /e-2dj6wfkoghdzobq.stats.esomniture.com ]
 C:\Users\rstadel\AppData\Roaming\Microsoft\Windows\Cookies\Low\HZCWM5BX.txt [ /ads.netrition.com ]
 C:\Users\rstadel\AppData\Roaming\Microsoft\Windows\Cookies\Low\LY8P8SJ5.txt [ /ads.extremereach.com ]
 C:\Users\rstadel\AppData\Roaming\Microsoft\Windows\Cookies\Low\FQM85MYR.txt [ /ads.videohub.tv ]
 C:\Users\rstadel\AppData\Roaming\Microsoft\Windows\Cookies\Low\QUJKRNCE.txt [ /adxpose.com ]
 C:\Users\rstadel\AppData\Roaming\Microsoft\Windows\Cookies\Low\BNNXRXQQ.txt [ /ad.doubleclick.net ]
 C:\Users\rstadel\AppData\Roaming\Microsoft\Windows\Cookies\Low\BKEHHI7X.txt [ /ad.doubleclick.net ]
 C:\Users\rstadel\AppData\Roaming\Microsoft\Windows\Cookies\Low\IBGRBLER.txt [ /ad.doubleclick.net ]
 C:\Users\rstadel\AppData\Roaming\Microsoft\Windows\Cookies\Low\XMKTP0FS.txt [ /ad.doubleclick.net ]
 C:\Users\rstadel\AppData\Roaming\Microsoft\Windows\Cookies\Low\E1273VPB.txt [ /ad.doubleclick.net ]
 C:\Users\rstadel\AppData\Roaming\Microsoft\Windows\Cookies\Low\T6DSVO38.txt [ /mallimages.mallfinder.com ]
 C:\Users\rstadel\AppData\Roaming\Microsoft\Windows\Cookies\Low\R3D6JZJU.txt [ /link.mercent.com ]
 C:\Users\rstadel\AppData\Roaming\Microsoft\Windows\Cookies\Low\KRUF79TM.txt [ /onestopinternet.122.2o7.net ]
 C:\Users\rstadel\AppData\Roaming\Microsoft\Windows\Cookies\Low\C91M9VSZ.txt [ /findlocal-treeservice.com ]
 C:\Users\rstadel\AppData\Roaming\Microsoft\Windows\Cookies\Low\X4434TXF.txt [ /tracking.waterfrontmedia.com ]
 C:\Users\rstadel\AppData\Roaming\Microsoft\Windows\Cookies\Low\CKW2JAE2.txt [ /kontera.com ]
 C:\Users\rstadel\AppData\Roaming\Microsoft\Windows\Cookies\Low\J3A5IPY2.txt [ /pbteen.com ]
 C:\Users\rstadel\AppData\Roaming\Microsoft\Windows\Cookies\Low\1IFJHNB6.txt [ /px.steelhousemedia.com ]
 C:\Users\rstadel\AppData\Roaming\Microsoft\Windows\Cookies\Low\T2KWXRN1.txt [ /bizrate.com ]
 C:\Users\rstadel\AppData\Roaming\Microsoft\Windows\Cookies\Low\H5SWRMEA.txt [ /feed.validclick.com ]
 C:\Users\rstadel\AppData\Roaming\Microsoft\Windows\Cookies\Low\5NEEHH60.txt [ /admedia.com ]
 C:\Users\rstadel\AppData\Roaming\Microsoft\Windows\Cookies\Low\WV70P2NY.txt [ /clarkcountynv.gov ]
 C:\Users\rstadel\AppData\Roaming\Microsoft\Windows\Cookies\Low\NT4JD9CU.txt [ /ihg.db.advertising.com ]
 C:\Users\rstadel\AppData\Roaming\Microsoft\Windows\Cookies\Low\P376ZI9G.txt [ /ads.shopstyle.com ]
 C:\Users\rstadel\AppData\Roaming\Microsoft\Windows\Cookies\Low\R0BR81KT.txt [ /www.discountlocksmithco.com ]
 C:\Users\rstadel\AppData\Roaming\Microsoft\Windows\Cookies\Low\ZT4WSSMM.txt [ /clickbooth.com ]
 C:\Users\rstadel\AppData\Roaming\Microsoft\Windows\Cookies\Low\5YP5XQXO.txt [ /ru4.com ]
 C:\Users\rstadel\AppData\Roaming\Microsoft\Windows\Cookies\Low\E0UN4C9K.txt [ /adserving.autotrader.com ]
 C:\Users\rstadel\AppData\Roaming\Microsoft\Windows\Cookies\Low\N35367RF.txt [ /smartadserver.com ]
 C:\Users\rstadel\AppData\Roaming\Microsoft\Windows\Cookies\Low\NPEHDCWN.txt [ /legolas-media.com ]
 C:\Users\rstadel\AppData\Roaming\Microsoft\Windows\Cookies\Low\I9F1AUK5.txt [ /pulse-analytics-beacon.reutersmedia.net ]
 C:\Users\rstadel\AppData\Roaming\Microsoft\Windows\Cookies\Low\24ULLUYU.txt [ /additudemag.advertserve.com ]
 C:\Users\rstadel\AppData\Roaming\Microsoft\Windows\Cookies\Low\00Q0XZGM.txt [ /counter.hitslink.com ]
 C:\Users\rstadel\AppData\Roaming\Microsoft\Windows\Cookies\Low\VTQ8QG1D.txt [ /e-2dj6wjnysjcjcdp.stats.esomniture.com ]
 C:\Users\rstadel\AppData\Roaming\Microsoft\Windows\Cookies\Low\JYZ40N2U.txt [ /ad12.bannerbank.ru ]
 C:\Users\rstadel\AppData\Roaming\Microsoft\Windows\Cookies\Low\J5ZQKAQ4.txt [ /intermundomedia.com ]
 C:\Users\rstadel\AppData\Roaming\Microsoft\Windows\Cookies\Low\3W81KV7W.txt [ /ad.e-kolay.net ]
 C:\Users\rstadel\AppData\Roaming\Microsoft\Windows\Cookies\Low\4EMTNWUR.txt [ /collective-media.net ]
 C:\Users\rstadel\AppData\Roaming\Microsoft\Windows\Cookies\Low\GKY93RPL.txt [ /ox-d.mediaforge.com ]
 C:\Users\rstadel\AppData\Roaming\Microsoft\Windows\Cookies\Low\P3BRTU1E.txt [ /verizontelecom.112.2o7.net ]
 C:\Users\rstadel\AppData\Roaming\Microsoft\Windows\Cookies\Low\QYXQ1T5L.txt [ /googleads.g.doubleclick.net ]
 C:\Users\rstadel\AppData\Roaming\Microsoft\Windows\Cookies\Low\Y54VR9R7.txt [ /ads.nola.com ]
 C:\Users\rstadel\AppData\Roaming\Microsoft\Windows\Cookies\Low\9YE0ANTW.txt [ /hyundaimotoramerica.122.2o7.net ]
 C:\Users\rstadel\AppData\Roaming\Microsoft\Windows\Cookies\Low\X961P5BU.txt [ /discounttire.122.2o7.net ]
 C:\Users\rstadel\AppData\Roaming\Microsoft\Windows\Cookies\Low\UL1AOIDQ.txt [ /e-2dj6aekoejdjgbp.stats.esomniture.com ]
 C:\Users\rstadel\AppData\Roaming\Microsoft\Windows\Cookies\Low\DX1IU79Y.txt [ /medical-marijuana-dispensaries.findthebest.com ]
 C:\Users\rstadel\AppData\Roaming\Microsoft\Windows\Cookies\Low\C2ZBQMT5.txt [ /e-2dj6wjnywlczsap.stats.esomniture.com ]
 C:\Users\rstadel\AppData\Roaming\Microsoft\Windows\Cookies\Low\Z9VJD14H.txt [ /liveperson.net ]
 C:\Users\rstadel\AppData\Roaming\Microsoft\Windows\Cookies\Low\YOUXNFFY.txt [ /e-2dj6ael4godpclo.stats.esomniture.com ]
 C:\Users\rstadel\AppData\Roaming\Microsoft\Windows\Cookies\Low\OQ41PI87.txt [ /cn.clickable.net ]
 C:\Users\rstadel\AppData\Roaming\Microsoft\Windows\Cookies\Low\ZJ20X39F.txt [ /e-2dj6wbkowkdzslq.stats.esomniture.com ]
 C:\Users\rstadel\AppData\Roaming\Microsoft\Windows\Cookies\Low\S5U1HHK6.txt [ /delivery.adseekmedia.com ]
 C:\Users\rstadel\AppData\Roaming\Microsoft\Windows\Cookies\Low\ONOAMYI6.txt [ /accounts.youtube.com ]
 C:\Users\rstadel\AppData\Roaming\Microsoft\Windows\Cookies\Low\OHCUMM3L.txt [ /adform.net ]
 C:\Users\rstadel\AppData\Roaming\Microsoft\Windows\Cookies\Low\X7RK6UIP.txt [ /ewstv.112.2o7.net ]
 C:\Users\rstadel\AppData\Roaming\Microsoft\Windows\Cookies\Low\R657H4UQ.txt [ /adtech.de ]
 C:\Users\rstadel\AppData\Roaming\Microsoft\Windows\Cookies\Low\5D5R6Q01.txt [ /tripod.com ]
 C:\Users\rstadel\AppData\Roaming\Microsoft\Windows\Cookies\Low\S7D56KN6.txt [ /ads.as4x.tmcs.ticketmaster.com ]
 C:\Users\rstadel\AppData\Roaming\Microsoft\Windows\Cookies\Low\NIRQWED5.txt [ /verthealth.rotator.hadj1.adjuggler.net ]
 C:\Users\rstadel\AppData\Roaming\Microsoft\Windows\Cookies\Low\2U3945BK.txt [ /yellowpages.staradvertiser.com ]
 C:\Users\rstadel\AppData\Roaming\Microsoft\Windows\Cookies\Low\B13AWLCY.txt [ /c1.atdmt.com ]
 C:\Users\rstadel\AppData\Roaming\Microsoft\Windows\Cookies\Low\XGGHIO49.txt [ /e-2dj6wflikncjiep.stats.esomniture.com ]
 C:\Users\rstadel\AppData\Roaming\Microsoft\Windows\Cookies\Low\6N0G3XKB.txt [ /stats.townnews.com ]
 C:\Users\rstadel\AppData\Roaming\Microsoft\Windows\Cookies\Low\4PD3J4IT.txt [ /bookit.advertserve.com ]
 C:\Users\rstadel\AppData\Roaming\Microsoft\Windows\Cookies\Low\C2EX5RUF.txt [ /uk.sitestat.com ]
 C:\Users\rstadel\AppData\Roaming\Microsoft\Windows\Cookies\Low\VFXLF9RB.txt [ /blog.countryvillageliving.com ]
 C:\Users\rstadel\AppData\Roaming\Microsoft\Windows\Cookies\Low\XVLD4A1U.txt [ /i4commerce.112.2o7.net ]
 C:\Users\rstadel\AppData\Roaming\Microsoft\Windows\Cookies\Low\20553CK9.txt [ /stats.aatrk.com ]
 C:\Users\rstadel\AppData\Roaming\Microsoft\Windows\Cookies\Low\Z8RZQGZJ.txt [ /h.atdmt.com ]
 C:\Users\rstadel\AppData\Roaming\Microsoft\Windows\Cookies\Low\OCGRE73P.txt [ /stats.townnews.com ]
 C:\Users\rstadel\AppData\Roaming\Microsoft\Windows\Cookies\Low\3EW7513T.txt [ /networkcommunications2.112.2o7.net ]
 C:\Users\rstadel\AppData\Roaming\Microsoft\Windows\Cookies\Low\1E2ESEJM.txt [ /doubleclick.net ]
 C:\Users\rstadel\AppData\Roaming\Microsoft\Windows\Cookies\Low\VO9EHTSE.txt [ /e-2dj6wgkykgdzgcp.stats.esomniture.com ]
 C:\Users\rstadel\AppData\Roaming\Microsoft\Windows\Cookies\Low\XUPZ50UW.txt [ /ads.al.com ]
 C:\Users\rstadel\AppData\Roaming\Microsoft\Windows\Cookies\Low\KVRXSX8V.txt [ /stat.dealtime.com ]
 C:\Users\rstadel\AppData\Roaming\Microsoft\Windows\Cookies\Low\IYJ5TMDY.txt [ /tracking.adparlor.com ]
 C:\Users\rstadel\AppData\Roaming\Microsoft\Windows\Cookies\Low\JSYMCM66.txt [ /liveperson.net ]
 C:\Users\rstadel\AppData\Roaming\Microsoft\Windows\Cookies\Low\DN6WL0QB.txt [ /eaeacom.112.2o7.net ]
 C:\Users\rstadel\AppData\Roaming\Microsoft\Windows\Cookies\Low\K52LSOM7.txt [ /clickbank.net ]
 C:\Users\rstadel\AppData\Roaming\Microsoft\Windows\Cookies\Low\ZXTYUJZ8.txt [ /weedtracker.com ]
 C:\Users\rstadel\AppData\Roaming\Microsoft\Windows\Cookies\Low\XGKLJEHA.txt [ /paypal.112.2o7.net ]
 C:\Users\rstadel\AppData\Roaming\Microsoft\Windows\Cookies\Low\7C9BEYO6.txt [ /adtrack.voicestar.com ]
 C:\Users\rstadel\AppData\Roaming\Microsoft\Windows\Cookies\Low\8G9AB9YE.txt [ /timeinc.122.2o7.net ]
 C:\Users\rstadel\AppData\Roaming\Microsoft\Windows\Cookies\Low\W1QCCQ20.txt [ /adx.winners.us-west-1.rtb.adroll.com ]
 C:\Users\rstadel\AppData\Roaming\Microsoft\Windows\Cookies\Low\1P9FMBH7.txt [ /e-2dj6afliujdpwao.stats.esomniture.com ]
 C:\Users\rstadel\AppData\Roaming\Microsoft\Windows\Cookies\Low\1ARY0G8K.txt [ /liveperson.net ]
 C:\Users\rstadel\AppData\Roaming\Microsoft\Windows\Cookies\Low\GG9JDW6L.txt [ /nextag.com ]
 C:\Users\rstadel\AppData\Roaming\Microsoft\Windows\Cookies\Low\BBJ0I7VX.txt [ /ad.where.com ]
 C:\Users\rstadel\AppData\Roaming\Microsoft\Windows\Cookies\Low\WKLI0XDO.txt [ /tacoda.at.atwola.com ]
 C:\Users\rstadel\AppData\Roaming\Microsoft\Windows\Cookies\Low\9PYI77R3.txt [ /ad1.emediate.dk ]
 C:\Users\rstadel\AppData\Roaming\Microsoft\Windows\Cookies\Low\82DS61OB.txt [ /liveperson.net ]
 C:\Users\rstadel\AppData\Roaming\Microsoft\Windows\Cookies\Low\KC2Q6T0F.txt [ /advanceinternet.122.2o7.net ]
 C:\Users\rstadel\AppData\Roaming\Microsoft\Windows\Cookies\Low\9WE5MH4Y.txt [ /harborfreight.122.2o7.net ]
 C:\Users\rstadel\AppData\Roaming\Microsoft\Windows\Cookies\Low\O6QJ42Z6.txt [ /e-2dj6wjkogkczagq.stats.esomniture.com ]
 C:\Users\rstadel\AppData\Roaming\Microsoft\Windows\Cookies\Low\T22Y5SRI.txt [ /linksynergy.com ]
 C:\Users\rstadel\AppData\Roaming\Microsoft\Windows\Cookies\Low\BJ6LBIM8.txt [ /imrworldwide.com ]
 C:\Users\rstadel\AppData\Roaming\Microsoft\Windows\Cookies\Low\1I7496FP.txt [ /flagcounter.com ]
 C:\Users\rstadel\AppData\Roaming\Microsoft\Windows\Cookies\Low\ZSI7N9R4.txt [ /oasc12.247realmedia.com ]
 C:\Users\rstadel\AppData\Roaming\Microsoft\Windows\Cookies\Low\KHX908RO.txt [ /casalemedia.com ]
 C:\Users\rstadel\AppData\Roaming\Microsoft\Windows\Cookies\Low\IZUJH3YG.txt [ /enjoyfindingmedia.com ]
 C:\Users\rstadel\AppData\Roaming\Microsoft\Windows\Cookies\Low\6HVGQEU8.txt [ /adbrite.com ]
 C:\Users\rstadel\AppData\Roaming\Microsoft\Windows\Cookies\Low\0CE063CI.txt [ /atlanticmedia.122.2o7.net ]
 C:\Users\rstadel\AppData\Roaming\Microsoft\Windows\Cookies\Low\PJZLC3S5.txt [ /twci.112.2o7.net ]
 C:\Users\rstadel\AppData\Roaming\Microsoft\Windows\Cookies\Low\VFIDHLIB.txt [ /hearstmagazines.112.2o7.net ]
 C:\Users\rstadel\AppData\Roaming\Microsoft\Windows\Cookies\Low\GTCTD5ZA.txt [ /data.coremetrics.com ]
 C:\Users\rstadel\AppData\Roaming\Microsoft\Windows\Cookies\Low\96Y5K650.txt [ /mediaforceltd.go2jump.org ]
 C:\Users\rstadel\AppData\Roaming\Microsoft\Windows\Cookies\Low\AVWNN2MD.txt [ /mediaservices-d.openxenterprise.com ]
 C:\Users\rstadel\AppData\Roaming\Microsoft\Windows\Cookies\Low\1W9JCJSE.txt [ /ad.mlnadvertising.com ]
 C:\Users\rstadel\AppData\Roaming\Microsoft\Windows\Cookies\Low\A2N29KL0.txt [ /adinterax.com ]
 C:\Users\rstadel\AppData\Roaming\Microsoft\Windows\Cookies\Low\QXERF790.txt [ /testtaketraffic.com ]
 C:\Users\rstadel\AppData\Roaming\Microsoft\Windows\Cookies\Low\GF0P4M0V.txt [ /birth-control.findthedata.org ]
 C:\Users\rstadel\AppData\Roaming\Microsoft\Windows\Cookies\Low\IDTMG9DW.txt [ /ads.collegeconfidential.com ]
 C:\Users\rstadel\AppData\Roaming\Microsoft\Windows\Cookies\Low\SGT572X3.txt [ /accounts.google.com ]
 C:\Users\rstadel\AppData\Roaming\Microsoft\Windows\Cookies\Low\LB70M8LI.txt [ /at.atwola.com ]
 C:\Users\rstadel\AppData\Roaming\Microsoft\Windows\Cookies\Low\5POS95PL.txt [ /ads.bridgetrack.com ]
 C:\Users\rstadel\AppData\Roaming\Microsoft\Windows\Cookies\Low\MR92S1RJ.txt [ /phhmortgage.122.2o7.net ]
 C:\Users\rstadel\AppData\Roaming\Microsoft\Windows\Cookies\Low\43T6P9UJ.txt [ /adformdsp.net ]
 C:\Users\rstadel\AppData\Roaming\Microsoft\Windows\Cookies\Low\NRQUNG5N.txt [ /xiti.com ]
 C:\Users\rstadel\AppData\Roaming\Microsoft\Windows\Cookies\Low\GFN7XU06.txt [ /backcountry.com ]
 C:\Users\rstadel\AppData\Roaming\Microsoft\Windows\Cookies\Low\43T165LI.txt [ /webservices.evolvemediacorp.com ]
 C:\Users\rstadel\AppData\Roaming\Microsoft\Windows\Cookies\Low\1H56R7JX.txt [ /tribalfusion.com ]
 C:\Users\rstadel\AppData\Roaming\Microsoft\Windows\Cookies\Low\6PJIP3RH.txt [ /ads.mlive.com ]
 C:\Users\rstadel\AppData\Roaming\Microsoft\Windows\Cookies\Low\3IIOUY9O.txt [ /apmebf.com ]
 C:\Users\rstadel\AppData\Roaming\Microsoft\Windows\Cookies\Low\KQE4JYG3.txt [ /traditionaloven.com ]
 C:\Users\rstadel\AppData\Roaming\Microsoft\Windows\Cookies\Low\J9I9NVMW.txt [ /educationcom.112.2o7.net ]
 C:\Users\rstadel\AppData\Roaming\Microsoft\Windows\Cookies\Low\F9Y5OLWQ.txt [ /e-2dj6afk4kiczsbp.stats.esomniture.com ]
 C:\Users\rstadel\AppData\Roaming\Microsoft\Windows\Cookies\Low\1AB50W4T.txt [ /base.liveperson.net ]
 C:\Users\rstadel\AppData\Roaming\Microsoft\Windows\Cookies\Low\NKELSLXS.txt [ /tracking.affiliates.de ]
 C:\Users\rstadel\AppData\Roaming\Microsoft\Windows\Cookies\Low\ONRC0M7J.txt [ /specificclick.net ]
 C:\Users\rstadel\AppData\Roaming\Microsoft\Windows\Cookies\Low\927QV3LZ.txt [ /ads.okcimg.com ]
 C:\Users\rstadel\AppData\Roaming\Microsoft\Windows\Cookies\Low\SVWV9VQ2.txt [ /ad.doubleclick.net ]
 C:\Users\rstadel\AppData\Roaming\Microsoft\Windows\Cookies\Low\KIIXHCJP.txt [ /eyeviewads.com ]
 C:\Users\rstadel\AppData\Roaming\Microsoft\Windows\Cookies\Low\J7H8GJ9M.txt [ /ads.nba.com ]
 C:\Users\rstadel\AppData\Roaming\Microsoft\Windows\Cookies\Low\2BMQIEY3.txt [ /adserver.adreactor.com ]
 C:\Users\rstadel\AppData\Roaming\Microsoft\Windows\Cookies\Low\5TV99DCS.txt [ /e-2dj6wjl4gkc5ifp.stats.esomniture.com ]
 C:\Users\rstadel\AppData\Roaming\Microsoft\Windows\Cookies\Low\WOKNLFAP.txt [ /oracle.112.2o7.net ]
 C:\Users\rstadel\AppData\Roaming\Microsoft\Windows\Cookies\Low\Z4F7KMTZ.txt [ /eyewonder.com ]
 C:\Users\rstadel\AppData\Roaming\Microsoft\Windows\Cookies\Low\5YAVUO4Q.txt [ /findstuffforme.com ]
 C:\Users\rstadel\AppData\Roaming\Microsoft\Windows\Cookies\Low\BSILK8OF.txt [ /www.discount-hydro.com ]
 C:\Users\rstadel\AppData\Roaming\Microsoft\Windows\Cookies\Low\1437JU2P.txt [ /solvemedia.com ]
 C:\Users\rstadel\AppData\Roaming\Microsoft\Windows\Cookies\Low\QL0N6SA6.txt [ /growstorefinder.com ]
 C:\Users\rstadel\AppData\Roaming\Microsoft\Windows\Cookies\Low\NW4CKF5W.txt [ /statoil.solution.weborama.fr ]
 C:\Users\rstadel\AppData\Roaming\Microsoft\Windows\Cookies\Low\H39PS1AP.txt [ /knowledgeadventure.122.2o7.net ]
 C:\Users\rstadel\AppData\Roaming\Microsoft\Windows\Cookies\Low\L1YDOB62.txt [ /yieldmanager.net ]
 C:\Users\rstadel\AppData\Roaming\Microsoft\Windows\Cookies\Low\MS88GOR4.txt [ /imp.bid.ace.advertising.com ]
 C:\Users\rstadel\AppData\Roaming\Microsoft\Windows\Cookies\Low\P1WSXJB0.txt [ /liveperson.net ]
 C:\Users\rstadel\AppData\Roaming\Microsoft\Windows\Cookies\Low\8WHUZ2QG.txt [ /ads.lzjl.com ]
 C:\Users\rstadel\AppData\Roaming\Microsoft\Windows\Cookies\Low\CWS6OROH.txt [ /e-2dj6wgl4wgajifq.stats.esomniture.com ]
 C:\Users\rstadel\AppData\Roaming\Microsoft\Windows\Cookies\Low\4VYPUNTL.txt [ /s.clickability.com ]
 C:\Users\rstadel\AppData\Roaming\Microsoft\Windows\Cookies\Low\PNI6FJTY.txt [ /gostats.com ]
 C:\Users\rstadel\AppData\Roaming\Microsoft\Windows\Cookies\Low\6X87T6EP.txt [ /e-2dj6wjlyggcpsgo.stats.esomniture.com ]
 C:\Users\rstadel\AppData\Roaming\Microsoft\Windows\Cookies\Low\KGEEYTW9.txt [ /stats.paypal.com ]
 C:\Users\rstadel\AppData\Roaming\Microsoft\Windows\Cookies\Low\EUXFIKOU.txt [ /lucidmedia.com ]
 C:\Users\rstadel\AppData\Roaming\Microsoft\Windows\Cookies\Low\R2M2IHXC.txt [ /c.atdmt.com ]
 C:\Users\rstadel\AppData\Roaming\Microsoft\Windows\Cookies\Low\6LL5WEXE.txt [ /ar.atwola.com ]
 C:\Users\rstadel\AppData\Roaming\Microsoft\Windows\Cookies\Low\0L516AX1.txt [ /bestofelite.com ]
 C:\Users\rstadel\AppData\Roaming\Microsoft\Windows\Cookies\Low\5JV1WF1Y.txt [ /realmedia.com ]
 C:\Users\rstadel\AppData\Roaming\Microsoft\Windows\Cookies\Low\35KLDBTG.txt [ /thewrap.rotator.hadj7.adjuggler.net ]
 C:\Users\rstadel\AppData\Roaming\Microsoft\Windows\Cookies\Low\KMHT13C3.txt [ /isparkmedia.com ]
 C:\Users\rstadel\AppData\Roaming\Microsoft\Windows\Cookies\Low\BTXDR9UD.txt [ /usnews.122.2o7.net ]
 C:\Users\rstadel\AppData\Roaming\Microsoft\Windows\Cookies\Low\XDHNQUD5.txt [ /e-2dj6wdl4kgc5mgp.stats.esomniture.com ]
 C:\Users\rstadel\AppData\Roaming\Microsoft\Windows\Cookies\Low\9XDIRNEN.txt [ /mmotraffic.com ]
 C:\Users\rstadel\AppData\Roaming\Microsoft\Windows\Cookies\Low\DKK6S7RB.txt [ /adserver.twitpic.com ]
 C:\Users\rstadel\AppData\Roaming\Microsoft\Windows\Cookies\Low\H2MBOVZZ.txt [ /va.marketer.lpsnmedia.net ]
 C:\Users\rstadel\AppData\Roaming\Microsoft\Windows\Cookies\Low\0U9BP2X0.txt [ /e-2dj6wnliqhdjago.stats.esomniture.com ]
 C:\Users\rstadel\AppData\Roaming\Microsoft\Windows\Cookies\Low\BTR8NUVA.txt [ /e-2dj6wjnycpd5cfo.stats.esomniture.com ]
 C:\Users\rstadel\AppData\Roaming\Microsoft\Windows\Cookies\Low\K8ILT5XC.txt [ /liveperson.net ]
 C:\Users\rstadel\AppData\Roaming\Microsoft\Windows\Cookies\Low\TPQU152J.txt [ /overture.com ]
 C:\Users\rstadel\AppData\Roaming\Microsoft\Windows\Cookies\Low\LERDFY8N.txt [ /ads.oregonlive.com ]
 C:\Users\rstadel\AppData\Roaming\Microsoft\Windows\Cookies\Low\2D0C4EH8.txt [ /ww251.smartadserver.com ]
 C:\Users\rstadel\AppData\Roaming\Microsoft\Windows\Cookies\Low\PX0KTEIK.txt [ /e-2dj6wjnywpczagq.stats.esomniture.com ]
 C:\Users\rstadel\AppData\Roaming\Microsoft\Windows\Cookies\Low\UYCOUMLB.txt [ /histats.com ]
 C:\Users\rstadel\AppData\Roaming\Microsoft\Windows\Cookies\Low\T23HARX3.txt [ /ads.us.e-planning.net ]
 C:\Users\rstadel\AppData\Roaming\Microsoft\Windows\Cookies\Low\KNQJ28BL.txt [ /dmtracker.com ]
 C:\Users\rstadel\AppData\Roaming\Microsoft\Windows\Cookies\Low\O4VCHAET.txt [ /www.qsstats.com ]
 C:\Users\rstadel\AppData\Roaming\Microsoft\Windows\Cookies\Low\L61FSJGM.txt [ /puppyfind.com ]
 C:\Users\rstadel\AppData\Roaming\Microsoft\Windows\Cookies\Low\QXEWH5YV.txt [ /countercentral.com ]
 C:\Users\rstadel\AppData\Roaming\Microsoft\Windows\Cookies\Low\FJNCP1E1.txt [ /birth-control-pills.findthebest.com ]
 C:\Users\rstadel\AppData\Roaming\Microsoft\Windows\Cookies\Low\XZL9Q6EZ.txt [ /homestore.122.2o7.net ]
 C:\Users\rstadel\AppData\Roaming\Microsoft\Windows\Cookies\Low\8ZMLXPZQ.txt [ /webstatschecker.com ]
 C:\Users\rstadel\AppData\Roaming\Microsoft\Windows\Cookies\Low\7WB7I2DL.txt [ /journalregistercompany.122.2o7.net ]
 C:\Users\rstadel\AppData\Roaming\Microsoft\Windows\Cookies\Low\0NYV9NL3.txt [ /www.trackerguru.com ]
 C:\Users\rstadel\AppData\Roaming\Microsoft\Windows\Cookies\Low\AYDG5S9U.txt [ /rambler.ru ]
 C:\Users\rstadel\AppData\Roaming\Microsoft\Windows\Cookies\Low\A5XJ3JOG.txt [ /lion-den.tripod.com ]
 C:\Users\rstadel\AppData\Roaming\Microsoft\Windows\Cookies\Low\14WOC4HX.txt [ /auslieferung.commindo-media-ressourcen.de ]
 C:\Users\rstadel\AppData\Roaming\Microsoft\Windows\Cookies\Low\H33GXCRK.txt [ /traveladvertising.com ]

 

ESET Results

C:\AdwCleaner\Quarantine\C\Program Files (x86)\DealPly\DealPlyUpdateVer.exe.vir a variant of Win32/DealPly.F application cleaned by deleting - quarantined
C:\AdwCleaner\Quarantine\C\Program Files (x86)\lucky leap\updateluckyleap.exe.vir a variant of MSIL/BrowseFox.A application cleaned by deleting - quarantined
C:\AdwCleaner\Quarantine\C\Users\rstadel\AppData\Roaming\DealPly\UpdateProc\UpdateTask.exe.vir a variant of Win32/DealPly.F application cleaned by deleting - quarantined
C:\AdwCleaner\Quarantine\C\Users\rstadel\AppData\Roaming\OpenCandy\FE99D2351E7B43008050AA46586C54B7\OCBrowserHelper_1.0.3.85.dll.vir a variant of Win32/OpenCandy.A application cleaned by deleting - quarantined
C:\AdwCleaner\Quarantine\C\Users\rstadel\AppData\Roaming\SearchProtect\Res\SPSetup.exe.vir multiple threats cleaned by deleting - quarantined
C:\Program Files (x86)\FrostWire 5\frostwire-installer.exe multiple threats cleaned by deleting - quarantined
C:\Program Files (x86)\FrostWire 5\OCSetupHlp.dll Win32/OpenCandy application cleaned by deleting - quarantined
C:\Users\rstadel\.frostwire5\updates\frostwire-5.6.4.windows.exe multiple threats cleaned by deleting - quarantined
C:\Users\rstadel\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\K8DOZQ6I\SPSetup[1].exe multiple threats cleaned by deleting - quarantined
C:\Users\rstadel\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\XM29U0A7\DefaultTabSetup[1].exe a variant of Win32/Toolbar.DefaultTab.B application cleaned by deleting - quarantined
C:\Users\rstadel\AppData\Local\Temp\AskSLib.dll a variant of Win32/Bundled.Toolbar.Ask application cleaned by deleting - quarantined

 



#4 Condobloke

Condobloke

    Outback Aussie @ 54.2101 N, 0.2906 W


  • Members
  • 6,047 posts
  • OFFLINE
  •  
  • Gender:Male
  • Local time:09:29 AM

Posted 15 September 2013 - 04:08 PM

We need to update Adobe....

 

 

You can download Adobe from http://www.adobe.com/products/acrobat/readstep2.html
After installing the latest Adobe Reader,be sure to uninstall all previous versions (if present).
Note. If you already have Adobe Photoshop® Album Starter Edition installed or do not wish to have it installed UNcheck the box which says Also Download Adobe Photoshop® Album Starter Edition.

 

OR.....you may care to choose a 'lighter' alternative...uninstall Adobe reader completely and ::- Foxit PDF Reader from HERE.
It's a much smaller file to download and uses a lot less resources than Adobe Reader.
Note: When installing FoxitReader, make sure to UN-check any pre-checked toolbar, or any other garbage/rubbish bundled with it !

 

 

Lastly....run TFC
Please download TFC, or Temp File Cleaner from BleepingComputer downloads
Usage Instructions:

  • Download TFC from the download link above and save the file on your desktop.
  • Close ALL running applications as TFC will terminate them before attempting to clean up the temporary files.
  • Double-click on the TFC icon.
  • When the program opens, click on the Start button.  TFC will terminate the Explorer process and all running applications and then begin the process of cleaning out all of your temp folders.
  • When done, press OK to reboot your computer and finish the cleanup.

Note: Depending on how much data is currently stored in the Temp folders, this process can take quite a while to remove all of the files, so please be patient.

 

How is your PC running now  ??

 

Regards,

 

(edited to add adobe, foxit and tfc)


Edited by Condobloke, 15 September 2013 - 06:05 PM.

Condobloke ...Outback Australian  fed up with Windows antics...??....LINUX IS THE ANSWER....I USE LINUX MINT 18.3  EXCLUSIVELY.

“A man travels the world in search of what he needs and returns home to find it."

It has been said that time heals all wounds. I don't agree. The wounds remain. Time - the mind, protecting its sanity - covers them with some scar tissue and the pain lessens, but it is never gone. Rose Kennedy

 GcnI1aH.jpg

 

 


#5 REIDS

REIDS
  • Topic Starter

  • Members
  • 102 posts
  • OFFLINE
  •  
  • Local time:03:29 PM

Posted 15 September 2013 - 07:02 PM

It seems to be running much better now. Thanks for the help. I had over 12GB of temp files stored on the hard drive. That is crazy.



#6 Condobloke

Condobloke

    Outback Aussie @ 54.2101 N, 0.2906 W


  • Members
  • 6,047 posts
  • OFFLINE
  •  
  • Gender:Male
  • Local time:09:29 AM

Posted 15 September 2013 - 07:28 PM

It should just about lift off the ground all on its own now !!....much lighter !

 

Now....a little clean up and you are good to go.

 

1. Security Check....simply right click and delete.

 

2. AdwCleaner....double click ,then select uninstall.

 

3. MalwareBytes....this is a good program to keep. Be sure to update it before using it. Once a fortnight /week, is usually sufficient.

 

4.SuperantiSpyware...is also a good program to keep ....again....be sure  to update it before use.

 

Eset....you can choose to uninstall or keep....your choice....the update rule also applies here.

 

TFC is an excellent temp file cleaner......once a fortnight is usually sufficient.

 

 

Regards,


Condobloke ...Outback Australian  fed up with Windows antics...??....LINUX IS THE ANSWER....I USE LINUX MINT 18.3  EXCLUSIVELY.

“A man travels the world in search of what he needs and returns home to find it."

It has been said that time heals all wounds. I don't agree. The wounds remain. Time - the mind, protecting its sanity - covers them with some scar tissue and the pain lessens, but it is never gone. Rose Kennedy

 GcnI1aH.jpg

 

 





0 user(s) are reading this topic

0 members, 0 guests, 0 anonymous users