Jump to content


 


Register a free account to unlock additional features at BleepingComputer.com
Welcome to BleepingComputer, a free community where people like yourself come together to discuss and learn how to use their computers. Using the site is easy and fun. As a guest, you can browse and view the various discussions in the forums, but can not create a new topic or reply to an existing one unless you are logged in. Other benefits of registering an account are subscribing to topics and forums, creating a blog, and having no ads shown anywhere on the site.


Click here to Register a free account now! or read our Welcome Guide to learn how to use this site.

Photo

Steam store redirects to ads, Utrack.pw pop-up on desktop


  • This topic is locked This topic is locked
16 replies to this topic

#1 euanicorn

euanicorn

  • Members
  • 12 posts
  • OFFLINE
  •  
  • Local time:08:12 AM

Posted 13 December 2015 - 10:39 AM

Hi there, I was kindly receiving help in this thread and was advised to start a new topic.
 
http://www.bleepingcomputer.com/forums/t/598124/steam-store-pop-up-ads-and-redirecting/
 
My issue's that the store page on Valve's Steam redirects to advertisements and pop-ups, and now there's also a Utrack.pw pop-up on my desktop that is always on top of everything else, like my browser right now.
 
I've ran Farbar, here's the log. I'll put Addition.txt in the following post.
 
 
 
Scan result of Farbar Recovery Scan Tool (FRST) (x64) Version:12-12-2015 01
Ran by euan (administrator) on EUAN-PC (13-12-2015 15:29:38)
Running from C:\Users\euan\Downloads
Loaded Profiles: euan (Available Profiles: euan)
Platform: Windows 7 Home Premium Service Pack 1 (X64) Language: English (United States)
Internet Explorer Version 9 (Default browser: FF)
Boot Mode: Normal
Tutorial for Farbar Recovery Scan Tool: http://www.geekstogo.com/forum/topic/335081-frst-tutorial-how-to-use-farbar-recovery-scan-tool/

==================== Processes (Whitelisted) =================

(If an entry is included in the fixlist, the process will be closed. The file will not be moved.)

(AVG Technologies CZ, s.r.o.) C:\Program Files (x86)\AVG\Av\avgrsa.exe
(AVG Technologies CZ, s.r.o.) C:\Program Files (x86)\AVG\Av\avgcsrva.exe
(NVIDIA Corporation) C:\Windows\System32\nvvsvc.exe
(NVIDIA Corporation) C:\Program Files (x86)\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe
(NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\Display\NvXDSync.exe
(NVIDIA Corporation) C:\Windows\System32\nvvsvc.exe
(AVG Technologies CZ, s.r.o.) C:\Program Files (x86)\AVG\Av\avgidsagent.exe
(AVG Technologies CZ, s.r.o.) C:\Program Files (x86)\AVG\Framework\Common\avgsvca.exe
(AVG Technologies CZ, s.r.o.) C:\Program Files (x86)\AVG\Av\avgwdsvcx.exe
(SEIKO EPSON CORPORATION) C:\Program Files\Common Files\EPSON\EPW!3 SSRP\E_S50RPB.EXE
(NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\GeForce Experience Service\GfExperienceService.exe
(LogMeIn, Inc.) C:\Program Files (x86)\LogMeIn Hamachi\LMIGuardianSvc.exe
(Malwarebytes) C:\Program Files (x86)\Malwarebytes Anti-Malware\mbamscheduler.exe
(NVIDIA Corporation) C:\Program Files (x86)\NVIDIA Corporation\Update Core\NvBackend.exe
(Malwarebytes) C:\Program Files (x86)\Malwarebytes Anti-Malware\mbam.exe
(NVIDIA Corporation) C:\Program Files (x86)\NVIDIA Corporation\NetService\NvNetworkService.exe
(NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\NvStreamSrv\NvStreamService.exe
(Renesas Electronics Corporation) C:\Program Files (x86)\Renesas Electronics\USB 3.0 Host Controller Driver\Application\nusb3mon.exe
(AVG Technologies CZ, s.r.o.) C:\Program Files (x86)\AVG\Av\avgui.exe
(AVG Technologies CZ, s.r.o.) C:\Program Files (x86)\AVG\Framework\Common\avguix.exe
(Microsoft Corp.) C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE
(LogMeIn Inc.) C:\Program Files (x86)\LogMeIn Hamachi\hamachi-2.exe
(Microsoft Corp.) C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVCM.EXE
(NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\Display\nvtray.exe
(AVG Technologies CZ, s.r.o.) C:\Program Files (x86)\AVG\Framework\Common\avguix.exe
(NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\NvStreamSrv\NvStreamNetworkService.exe
(NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\NvStreamSrv\NvStreamUserAgent.exe
(Microsoft Corporation) C:\Windows\System32\dllhost.exe
(Mozilla Corporation) C:\Program Files (x86)\Mozilla Firefox\firefox.exe


==================== Registry (Whitelisted) ===========================

(If an entry is included in the fixlist, the registry item will be restored to default or removed. The file will not be moved.)

HKLM\...\Run: [VX3000] => C:\Windows\vVX3000.exe
HKLM\...\Run: [Logitech Download Assistant] => C:\Windows\system32\rundll32.exe C:\Windows\System32\LogiLDA.dll,LogiFetch
HKLM\...\Run: [NvBackend] => C:\Program Files (x86)\NVIDIA Corporation\Update Core\NvBackend.exe [2757424 2015-11-24] (NVIDIA Corporation)
HKLM\...\Run: [ShadowPlay] => "C:\Windows\system32\rundll32.exe" C:\Windows\system32\nvspcap64.dll,ShadowPlayOnSystemStart
HKLM\...\Run: [XboxStat] => C:\Program Files\Microsoft Xbox 360 Accessories\XboxStat.exe [825184 2009-10-01] (Microsoft Corporation)
HKLM\...\Run: [ProfilerU] => C:\Program Files\SmartTechnology\Software\ProfilerU.exe [454144 2013-04-16] (Saitek)
HKLM\...\Run: [SaiMfd] => C:\Program Files\SmartTechnology\Software\SaiMfd.exe [158208 2013-04-16] (Saitek)
HKLM-x32\...\Run: [NUSB3MON] => C:\Program Files (x86)\Renesas Electronics\USB 3.0 Host Controller Driver\Application\nusb3mon.exe [113288 2010-04-27] (Renesas Electronics Corporation)
HKLM-x32\...\Run: [AVG_UI] => C:\Program Files (x86)\AVG\Av\avgui.exe [3855272 2015-11-20] (AVG Technologies CZ, s.r.o.)
HKLM-x32\...\Run: [QuickTime Task] => C:\Program Files (x86)\QuickTime\QTTask.exe [421888 2013-05-01] (Apple Inc.)
HKLM-x32\...\Run: [DivXUpdate] => C:\Program Files (x86)\DivX\DivX Update\DivXUpdate.exe [1861968 2014-01-10] ()
HKLM-x32\...\Run: [LogMeIn Hamachi Ui] => C:\Program Files (x86)\LogMeIn Hamachi\hamachi-2-ui.exe [5565448 2015-11-12] (LogMeIn Inc.)
HKLM-x32\...\Run: [SunJavaUpdateSched] => C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe [596528 2015-11-09] (Oracle Corporation)
HKLM-x32\...\Run: [AvgUi] => C:\Program Files (x86)\AVG\Framework\Common\avguix.exe [1136552 2015-11-12] (AVG Technologies CZ, s.r.o.)
HKU\S-1-5-21-1126527562-1434389470-3061596616-1001\...\Run: [RGSC] => C:\Program Files (x86)\Rockstar Games\Rockstar Games Social Club\RGSCLauncher.exe /silent
HKU\S-1-5-21-1126527562-1434389470-3061596616-1001\...\Run: [EA Core] => "C:\Program Files (x86)\Electronic Arts\EADM\Core.exe" -silent
HKU\S-1-5-21-1126527562-1434389470-3061596616-1001\...\MountPoints2: {9e9b233d-579d-11e0-a149-bcaec5df35a0} - F:\AutoRunCD.exe
HKU\S-1-5-21-1126527562-1434389470-3061596616-1001\...\MountPoints2: {a15df326-6756-11e0-82db-bcaec5df35a0} - F:\Setup.exe
HKU\S-1-5-21-1126527562-1434389470-3061596616-1001\...\MountPoints2: {fb449286-a992-11e1-96d5-bcaec5df35a0} - F:\setup.exe

==================== Internet (Whitelisted) ====================

(If an item is included in the fixlist, if it is a registry item it will be removed or restored to default.)

Hosts: There are more than one entry in Hosts. See Hosts section of Addition.txt
Tcpip\Parameters: [DhcpNameServer] 192.168.2.1
Tcpip\..\Interfaces\{7E1F3EA3-0209-4920-B785-4CC8096B6F93}: [DhcpNameServer] 44.0.0.253 44.0.0.3 44.0.0.4 4.2.2.1
Tcpip\..\Interfaces\{A946E94C-70A9-4EC0-AF84-56E22E561C34}: [DhcpNameServer] 192.168.42.129
Tcpip\..\Interfaces\{E10BF0C0-47F1-4809-B3EA-D2EE243ECFE3}: [DhcpNameServer] 192.168.2.1

Internet Explorer:
==================
HKU\S-1-5-21-1126527562-1434389470-3061596616-1001\Software\Microsoft\Internet Explorer\Main,Start Page Redirect Cache = hxxp://uk.msn.com/?ocid=iehp
SearchScopes: HKU\.DEFAULT -> DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL =
SearchScopes: HKU\S-1-5-19 -> DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL =
SearchScopes: HKU\S-1-5-20 -> DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL =
SearchScopes: HKU\S-1-5-21-1126527562-1434389470-3061596616-1001 -> {012E1000-F331-11DB-8314-0800200C9A66} URL = hxxp://www.google.com/search?q={searchTerms}
BHO: Windows Live ID Sign-in Helper -> {9030D464-4C02-4ABF-8ECC-5164760863C6} -> C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll [2010-09-21] (Microsoft Corp.)
BHO: Office Document Cache Handler -> {B4F3A835-0E21-4959-BA22-42B3008E02FF} -> C:\Program Files\Microsoft Office\Office14\URLREDIR.DLL [2013-03-06] (Microsoft Corporation)
BHO-x32: Java™ Plug-In SSV Helper -> {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} -> C:\Program Files (x86)\Java\jre1.8.0_66\bin\ssv.dll [2015-12-01] (Oracle Corporation)
BHO-x32: Windows Live ID Sign-in Helper -> {9030D464-4C02-4ABF-8ECC-5164760863C6} -> C:\Program Files (x86)\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll [2010-09-21] (Microsoft Corp.)
BHO-x32: Skype Browser Helper -> {AE805869-2E5C-4ED4-8F7B-F1F7851A4497} -> C:\Program Files (x86)\Skype\Toolbars\Internet Explorer\skypeieplugin.dll [2011-10-10] (Skype Technologies S.A.)
BHO-x32: Office Document Cache Handler -> {B4F3A835-0E21-4959-BA22-42B3008E02FF} -> C:\Program Files (x86)\Microsoft Office\Office14\URLREDIR.DLL [2013-03-06] (Microsoft Corporation)
BHO-x32: Java™ Plug-In 2 SSV Helper -> {DBC80044-A445-435b-BC74-9C25C1C588A9} -> C:\Program Files (x86)\Java\jre1.8.0_66\bin\jp2ssv.dll [2015-12-01] (Oracle Corporation)
DPF: HKLM-x32 {20A60F0D-9AFA-4515-A0FD-83BD84642501} hxxp://messenger.zone.msn.com/binary/msgrchkr.cab56986.cab
DPF: HKLM-x32 {C3F79A2B-B9B4-4A66-B012-3EE46475B072} hxxp://messenger.zone.msn.com/binary/MessengerStatsPAClient.cab56907.cab
DPF: HKLM-x32 {D27CDB6E-AE6D-11CF-96B8-444553540000} hxxp://fpdownload2.macromedia.com/get/shockwave/cabs/flash/swflash.cab
Handler: linkscanner - {F274614C-63F8-47D5-A4D1-FBDDE494F8D1} - C:\Program Files (x86)\AVG\AVG2012\avgpp.dll No File
Handler-x32: skype-ie-addon-data - {91774881-D725-4E58-B298-07617B9B86A8} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer\skypeieplugin.dll [2011-10-10] (Skype Technologies S.A.)
Handler-x32: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\Program Files (x86)\Common Files\Skype\Skype4COM.dll [2014-05-02] (Skype Technologies)

FireFox:
========
FF ProfilePath: C:\Users\euan\AppData\Roaming\Mozilla\Firefox\Profiles\1luqk2cl.default
FF Homepage: www.google.com
FF Plugin: @adobe.com/FlashPlayer -> C:\Windows\system32\Macromed\Flash\NPSWF64_20_0_0_235.dll [2015-12-09] ()
FF Plugin: @microsoft.com/GENUINE -> disabled [No File]
FF Plugin: @microsoft.com/OfficeAuthz,version=14.0 -> C:\PROGRA~1\MICROS~3\Office14\NPAUTHZ.DLL [2010-01-09] (Microsoft Corporation)
FF Plugin-x32: @adobe.com/FlashPlayer -> C:\Windows\SysWOW64\Macromed\Flash\NPSWF32_20_0_0_235.dll [2015-12-09] ()
FF Plugin-x32: @divx.com/DivX VOD Helper,version=1.0.0 -> C:\Program Files (x86)\DivX\DivX OVS Helper\npovshelper.dll [2013-09-17] (DivX, LLC.)
FF Plugin-x32: @java.com/DTPlugin,version=11.66.2 -> C:\Program Files (x86)\Java\jre1.8.0_66\bin\dtplugin\npDeployJava1.dll [2015-12-01] (Oracle Corporation)
FF Plugin-x32: @java.com/JavaPlugin,version=11.66.2 -> C:\Program Files (x86)\Java\jre1.8.0_66\bin\plugin2\npjp2.dll [2015-12-01] (Oracle Corporation)
FF Plugin-x32: @microsoft.com/GENUINE -> disabled [No File]
FF Plugin-x32: @microsoft.com/OfficeAuthz,version=14.0 -> C:\PROGRA~2\MIF5BA~1\Office14\NPAUTHZ.DLL [2010-01-09] (Microsoft Corporation)
FF Plugin-x32: @microsoft.com/WLPG,version=15.4.3502.0922 -> C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll [2010-11-10] (Microsoft Corporation)
FF Plugin-x32: @microsoft.com/WLPG,version=15.4.3508.1109 -> C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll [2010-11-10] (Microsoft Corporation)
FF Plugin-x32: @nvidia.com/3DVision -> C:\Program Files (x86)\NVIDIA Corporation\3D Vision\npnv3dv.dll [2015-11-24] (NVIDIA Corporation)
FF Plugin-x32: @nvidia.com/3DVisionStreaming -> C:\Program Files (x86)\NVIDIA Corporation\3D Vision\npnv3dvstreaming.dll [2015-11-24] (NVIDIA Corporation)
FF Plugin-x32: @videolan.org/vlc,version=2.0.0 -> C:\Program Files (x86)\VideoLAN\VLC\npvlc.dll [2012-02-17] (VideoLAN)
FF Plugin-x32: Adobe Reader -> C:\Program Files (x86)\Adobe\Acrobat Reader DC\Reader\AIR\nppdf32.dll [2015-09-30] (Adobe Systems Inc.)
FF Plugin HKU\S-1-5-21-1126527562-1434389470-3061596616-1001: ubisoft.com/uplaypc -> C:\Program Files (x86)\Ubisoft\Ubisoft Game Launcher\npuplaypc.dll [2015-11-10] ()
FF Plugin ProgramFiles/Appdata: C:\Program Files (x86)\mozilla firefox\plugins\npBitCometAgent.dll [2012-01-12] (BitComet)
FF Plugin ProgramFiles/Appdata: C:\Program Files (x86)\mozilla firefox\plugins\nppdf32.dll [2015-09-30] (Adobe Systems Inc.)
FF Plugin ProgramFiles/Appdata: C:\Program Files (x86)\mozilla firefox\plugins\npqtplugin.dll [2013-09-25] (Apple Inc.)
FF Plugin ProgramFiles/Appdata: C:\Program Files (x86)\mozilla firefox\plugins\npqtplugin2.dll [2013-09-25] (Apple Inc.)
FF Plugin ProgramFiles/Appdata: C:\Program Files (x86)\mozilla firefox\plugins\npqtplugin3.dll [2013-09-25] (Apple Inc.)
FF Plugin ProgramFiles/Appdata: C:\Program Files (x86)\mozilla firefox\plugins\npqtplugin4.dll [2013-09-25] (Apple Inc.)
FF Plugin ProgramFiles/Appdata: C:\Program Files (x86)\mozilla firefox\plugins\npqtplugin5.dll [2013-09-25] (Apple Inc.)
FF Extension: NoScript - C:\Users\euan\AppData\Roaming\Mozilla\Firefox\Profiles\1luqk2cl.default\extensions\{73a6fe31-595d-460b-a920-fcc0f8843232}.xpi [2015-11-30]
FF Extension: Adblock Plus - C:\Users\euan\AppData\Roaming\Mozilla\Firefox\Profiles\1luqk2cl.default\Extensions\{d10d0bf8-f5b5-c8b4-a8b2-2b9879e08c5d}.xpi [2015-11-30]
FF Extension: Skype Click to Call - C:\Program Files (x86)\Mozilla Firefox\extensions\{82AF8DCA-6DE9-405D-BD5E-43525BDAD38A} [2015-11-30] [not signed]
FF Extension: Java Console - C:\Program Files (x86)\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0033-ABCDEFFEDCBA} [2015-11-30] [not signed]
FF Extension: Java Console - C:\Program Files (x86)\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0035-ABCDEFFEDCBA} [2015-11-30] [not signed]

==================== Services (Whitelisted) ========================

(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)

S3 AvgAMPS; C:\Program Files (x86)\AVG\Av\avgamps.exe [615584 2015-11-20] (AVG Technologies CZ, s.r.o.)
R2 AVGIDSAgent; C:\Program Files (x86)\AVG\Av\avgidsagent.exe [3857272 2015-11-20] (AVG Technologies CZ, s.r.o.)
R2 avgsvc; C:\Program Files (x86)\AVG\Framework\Common\avgsvca.exe [1046952 2015-11-12] (AVG Technologies CZ, s.r.o.)
R2 avgwd; C:\Program Files (x86)\AVG\Av\avgwdsvcx.exe [579776 2015-11-20] (AVG Technologies CZ, s.r.o.)
S3 BEService; C:\Program Files (x86)\Common Files\BattlEye\BEService.exe [1125888 2015-07-22] ()
S3 BITCOMET_HELPER_SERVICE; C:\Program Files\BitComet\tools\BitCometService.exe [1296728 2010-12-28] (www.BitComet.com)
S3 EvoSvc; C:\Program Files\Echobit\Evolve\EvoSvc.exe [1580416 2015-01-20] (Echobit LLC)
R2 GfExperienceService; C:\Program Files\NVIDIA Corporation\GeForce Experience Service\GfExperienceService.exe [1156400 2015-11-24] (NVIDIA Corporation)
R2 LMIGuardianSvc; C:\Program Files (x86)\LogMeIn Hamachi\LMIGuardianSvc.exe [417552 2015-11-12] (LogMeIn, Inc.)
R2 MBAMScheduler; C:\Program Files (x86)\Malwarebytes Anti-Malware\mbamscheduler.exe [1513784 2015-10-05] (Malwarebytes)
S2 MBAMService; C:\Program Files (x86)\Malwarebytes Anti-Malware\mbamservice.exe [1135416 2015-10-05] (Malwarebytes)
R2 NvNetworkService; C:\Program Files (x86)\NVIDIA Corporation\NetService\NvNetworkService.exe [1872688 2015-11-24] (NVIDIA Corporation)
R3 NvStreamNetworkSvc; C:\Program Files\NVIDIA Corporation\NvStreamSrv\NvStreamNetworkService.exe [8133424 2015-11-24] (NVIDIA Corporation)
R2 NvStreamSvc; C:\Program Files\NVIDIA Corporation\NvStreamSrv\NvStreamService.exe [5915440 2015-11-24] (NVIDIA Corporation)
S3 Origin Client Service; C:\Program Files (x86)\Origin\OriginClientService.exe [1903472 2015-01-11] (Electronic Arts)
S3 Steam Client Service; C:\Program Files (x86)\Common Files\Steam\SteamService.exe [836176 2015-12-10] (Valve Corporation) [File not signed]
S3 WinDefend; C:\Program Files\Windows Defender\mpsvc.dll [1011712 2013-05-27] (Microsoft Corporation)
S2 MSCamSvc; "C:\Program Files\Microsoft LifeCam\MSCamS64.exe" [X]

===================== Drivers (Whitelisted) ==========================

(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)

R2 atksgt; C:\Windows\System32\DRIVERS\atksgt.sys [314016 2011-03-28] ()
R1 Avgdiska; C:\Windows\System32\DRIVERS\avgdiska.sys [184240 2015-11-06] (AVG Technologies CZ, s.r.o.)
R1 AVGIDSDriver; C:\Windows\System32\DRIVERS\avgidsdrivera.sys [313776 2015-11-06] (AVG Technologies CZ, s.r.o.)
R0 AVGIDSHA; C:\Windows\System32\DRIVERS\avgidsha.sys [298416 2015-08-20] (AVG Technologies CZ, s.r.o.)
R1 Avgldx64; C:\Windows\System32\DRIVERS\avgldx64.sys [284080 2015-10-21] (AVG Technologies CZ, s.r.o.)
R0 Avgloga; C:\Windows\System32\DRIVERS\avgloga.sys [398256 2015-08-14] (AVG Technologies CZ, s.r.o.)
R0 Avgmfx64; C:\Windows\System32\DRIVERS\avgmfx64.sys [256432 2015-11-06] (AVG Technologies CZ, s.r.o.)
R0 Avgrkx64; C:\Windows\System32\DRIVERS\avgrkx64.sys [42416 2015-08-10] (AVG Technologies CZ, s.r.o.)
R1 dtsoftbus01; C:\Windows\System32\DRIVERS\dtsoftbus01.sys [283200 2012-05-29] (DT Soft Ltd)
S3 ebdrv; C:\Windows\system32\DRIVERS\evbda.sys [3286016 2009-06-10] (Broadcom Corporation)
R3 EvolveVirtualAdapter; C:\Windows\System32\DRIVERS\evolve.sys [21656 2014-05-06] (Echobit, LLC)
S3 HabuFltr; C:\Windows\System32\drivers\habu.sys [13696 2006-10-26] (Razer (Asia-Pacific) Pte Ltd)
R2 lirsgt; C:\Windows\System32\DRIVERS\lirsgt.sys [43680 2011-03-28] ()
R3 MBAMProtector; C:\Windows\system32\drivers\mbam.sys [25816 2015-10-05] (Malwarebytes)
R3 MBAMSwissArmy; C:\Windows\system32\drivers\MBAMSwissArmy.sys [192216 2015-12-13] (Malwarebytes)
S3 MBAMWebAccessControl; C:\Windows\system32\drivers\mwac.sys [63704 2015-10-05] (Malwarebytes Corporation)
R3 NvStreamKms; C:\Program Files\NVIDIA Corporation\NvStreamSrv\NvStreamKms.sys [19760 2015-11-24] (NVIDIA Corporation)
R3 nvvad_WaveExtensible; C:\Windows\System32\drivers\nvvad64v.sys [50472 2015-11-24] (NVIDIA Corporation)
S3 Razerlow; C:\Windows\System32\drivers\Razerlow.sys [21120 2005-11-07] (Razer (Asia-Pacific) Pte Ltd)
S3 Razerlow; C:\Windows\SysWOW64\drivers\Razerlow.sys [13225 2005-04-24] (Razer (Asia-Pacific) Pte Ltd) [File not signed]
S3 SaiH0464; C:\Windows\System32\DRIVERS\SaiH0464.sys [178432 2008-03-31] (Saitek)
R3 SaiMini; C:\Windows\System32\DRIVERS\SaiMini.sys [25120 2013-04-30] (Saitek)
R3 SaiNtBus; C:\Windows\System32\drivers\SaiBus.sys [52640 2013-04-30] (Saitek)
S3 tapSF0901; C:\Windows\System32\DRIVERS\tapSF0901.sys [39104 2014-09-30] (Spotflux, Inc.)
S3 USBAAPL64; C:\Windows\System32\Drivers\usbaapl64.sys [54784 2012-12-13] (Apple, Inc.) [File not signed]
U4 Avgtdia; system32\DRIVERS\avgtdia.sys [X]

==================== NetSvcs (Whitelisted) ===================

(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)


==================== One Month Created files and folders ========

(If an entry is included in the fixlist, the file/folder will be moved.)

2015-12-13 15:29 - 2015-12-13 15:30 - 00018212 _____ C:\Users\euan\Downloads\FRST.txt
2015-12-13 15:29 - 2015-12-13 15:29 - 02369536 _____ (Farbar) C:\Users\euan\Downloads\FRST64.exe
2015-12-13 15:29 - 2015-12-13 15:29 - 00000000 ____D C:\FRST
2015-12-10 23:03 - 2015-12-10 23:03 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Skype
2015-12-09 11:18 - 2015-12-09 11:18 - 09498816 _____ (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerInstaller.exe
2015-12-09 10:56 - 2015-11-20 18:54 - 03170304 _____ (Microsoft Corporation) C:\Windows\system32\wucltux.dll
2015-12-09 10:56 - 2015-11-20 18:54 - 02609152 _____ (Microsoft Corporation) C:\Windows\system32\wuaueng.dll
2015-12-09 10:56 - 2015-11-20 18:54 - 00709632 _____ (Microsoft Corporation) C:\Windows\system32\wuapi.dll
2015-12-09 10:56 - 2015-11-20 18:54 - 00192512 _____ (Microsoft Corporation) C:\Windows\system32\wuwebv.dll
2015-12-09 10:56 - 2015-11-20 18:54 - 00140288 _____ (Microsoft Corporation) C:\Windows\system32\wuauclt.exe
2015-12-09 10:56 - 2015-11-20 18:54 - 00098816 _____ (Microsoft Corporation) C:\Windows\system32\wudriver.dll
2015-12-09 10:56 - 2015-11-20 18:54 - 00091136 _____ (Microsoft Corporation) C:\Windows\system32\WinSetupUI.dll
2015-12-09 10:56 - 2015-11-20 18:54 - 00037888 _____ (Microsoft Corporation) C:\Windows\system32\wups2.dll
2015-12-09 10:56 - 2015-11-20 18:54 - 00037888 _____ (Microsoft Corporation) C:\Windows\system32\wuapp.exe
2015-12-09 10:56 - 2015-11-20 18:54 - 00036864 _____ (Microsoft Corporation) C:\Windows\system32\wups.dll
2015-12-09 10:56 - 2015-11-20 18:54 - 00012288 _____ (Microsoft Corporation) C:\Windows\system32\wu.upgrade.ps.dll
2015-12-09 10:56 - 2015-11-20 18:34 - 00573440 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wuapi.dll
2015-12-09 10:56 - 2015-11-20 18:34 - 00174080 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wuwebv.dll
2015-12-09 10:56 - 2015-11-20 18:34 - 00093696 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wudriver.dll
2015-12-09 10:56 - 2015-11-20 18:34 - 00030208 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wups.dll
2015-12-09 10:56 - 2015-11-20 18:33 - 00035328 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wuapp.exe
2015-12-09 10:56 - 2015-11-05 19:02 - 00002048 _____ (Microsoft Corporation) C:\Windows\system32\tzres.dll
2015-12-09 10:56 - 2015-11-05 19:00 - 00002048 _____ (Microsoft Corporation) C:\Windows\SysWOW64\tzres.dll
2015-12-09 10:56 - 2015-11-03 19:04 - 00802304 _____ (Microsoft Corporation) C:\Windows\system32\usp10.dll
2015-12-09 10:56 - 2015-11-03 18:56 - 00627712 _____ (Microsoft Corporation) C:\Windows\SysWOW64\usp10.dll
2015-12-09 10:55 - 2015-11-12 21:13 - 02350080 _____ (Microsoft Corporation) C:\Windows\system32\jscript9.dll
2015-12-09 10:55 - 2015-11-12 21:07 - 01392128 _____ (Microsoft Corporation) C:\Windows\system32\wininet.dll
2015-12-09 10:55 - 2015-11-12 21:06 - 02382848 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.tlb
2015-12-09 10:55 - 2015-11-12 21:06 - 00816128 _____ (Microsoft Corporation) C:\Windows\system32\jscript.dll
2015-12-09 10:55 - 2015-11-12 21:06 - 00579072 _____ (Microsoft Corporation) C:\Windows\system32\vbscript.dll
2015-12-09 10:55 - 2015-11-12 21:06 - 00453120 _____ (Microsoft Corporation) C:\Windows\system32\dxtmsft.dll
2015-12-09 10:55 - 2015-11-12 21:06 - 00282112 _____ (Microsoft Corporation) C:\Windows\system32\dxtrans.dll
2015-12-09 10:55 - 2015-11-12 21:06 - 00248320 _____ (Microsoft Corporation) C:\Windows\system32\ieui.dll
2015-12-09 10:55 - 2015-11-12 21:06 - 00096768 _____ (Microsoft Corporation) C:\Windows\system32\mshtmled.dll
2015-12-09 10:55 - 2015-11-12 21:06 - 00086016 _____ (Microsoft Corporation) C:\Windows\system32\jsproxy.dll
2015-12-09 10:55 - 2015-11-12 20:39 - 01814528 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jscript9.dll
2015-12-09 10:55 - 2015-11-12 20:37 - 12389376 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.dll
2015-12-09 10:55 - 2015-11-12 20:33 - 01129472 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wininet.dll
2015-12-09 10:55 - 2015-11-12 20:32 - 00718848 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jscript.dll
2015-12-09 10:55 - 2015-11-12 20:32 - 00424448 _____ (Microsoft Corporation) C:\Windows\SysWOW64\vbscript.dll
2015-12-09 10:55 - 2015-11-12 20:31 - 02382848 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.tlb
2015-12-09 10:55 - 2015-11-12 20:31 - 00353792 _____ (Microsoft Corporation) C:\Windows\SysWOW64\dxtmsft.dll
2015-12-09 10:55 - 2015-11-12 20:31 - 00223232 _____ (Microsoft Corporation) C:\Windows\SysWOW64\dxtrans.dll
2015-12-09 10:55 - 2015-11-12 20:31 - 00176640 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieui.dll
2015-12-09 10:55 - 2015-11-12 20:31 - 00073216 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtmled.dll
2015-12-09 10:55 - 2015-11-11 18:53 - 01735680 _____ (Microsoft Corporation) C:\Windows\system32\comsvcs.dll
2015-12-09 10:55 - 2015-11-11 18:53 - 00525312 _____ (Microsoft Corporation) C:\Windows\system32\catsrvut.dll
2015-12-09 10:55 - 2015-11-11 18:39 - 01242624 _____ (Microsoft Corporation) C:\Windows\SysWOW64\comsvcs.dll
2015-12-09 10:55 - 2015-11-11 18:39 - 00487936 _____ (Microsoft Corporation) C:\Windows\SysWOW64\catsrvut.dll
2015-12-09 10:55 - 2015-11-10 18:55 - 01550848 _____ (Microsoft Corporation) C:\Windows\system32\DWrite.dll
2015-12-09 10:55 - 2015-11-10 18:55 - 01148416 _____ (Microsoft Corporation) C:\Windows\system32\FntCache.dll
2015-12-09 10:55 - 2015-11-10 18:55 - 01008640 _____ (Microsoft Corporation) C:\Windows\system32\user32.dll
2015-12-09 10:55 - 2015-11-10 18:38 - 01081856 _____ (Microsoft Corporation) C:\Windows\SysWOW64\DWrite.dll
2015-12-09 10:55 - 2015-11-10 18:37 - 00833024 _____ (Microsoft Corporation) C:\Windows\SysWOW64\user32.dll
2015-12-09 10:55 - 2015-11-10 17:47 - 03211264 _____ (Microsoft Corporation) C:\Windows\system32\win32k.sys
2015-12-09 10:55 - 2015-11-05 19:05 - 00017408 _____ (Microsoft Corporation) C:\Windows\system32\wshrm.dll
2015-12-09 10:55 - 2015-11-05 19:02 - 00014848 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wshrm.dll
2015-12-09 10:55 - 2015-11-05 09:53 - 00146944 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\rmcast.sys
2015-12-09 10:55 - 2015-10-08 23:22 - 00069120 _____ (Microsoft Corporation) C:\Windows\system32\nlsbres.dll
2015-12-09 10:55 - 2015-10-08 23:18 - 00007168 _____ (Microsoft Corporation) C:\Windows\SysWOW64\KBDAZE.DLL
2015-12-09 10:55 - 2015-10-08 23:18 - 00007168 _____ (Microsoft Corporation) C:\Windows\system32\kbdgeoqw.dll
2015-12-09 10:55 - 2015-10-08 23:18 - 00007168 _____ (Microsoft Corporation) C:\Windows\system32\KBDAZEL.DLL
2015-12-09 10:55 - 2015-10-08 23:18 - 00007168 _____ (Microsoft Corporation) C:\Windows\system32\KBDAZE.DLL
2015-12-09 10:55 - 2015-10-08 23:18 - 00006656 _____ (Microsoft Corporation) C:\Windows\SysWOW64\kbdgeoqw.dll
2015-12-09 10:55 - 2015-10-08 23:18 - 00006656 _____ (Microsoft Corporation) C:\Windows\SysWOW64\KBDAZEL.DLL
2015-12-09 10:55 - 2015-10-08 23:17 - 00069120 _____ (Microsoft Corporation) C:\Windows\SysWOW64\nlsbres.dll
2015-12-09 10:55 - 2015-10-08 19:13 - 00419928 _____ C:\Windows\SysWOW64\locale.nls
2015-12-09 10:55 - 2015-10-08 18:52 - 00419928 _____ C:\Windows\system32\locale.nls
2015-12-09 10:54 - 2015-11-12 21:16 - 17892864 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.dll
2015-12-09 10:54 - 2015-11-12 21:09 - 10937856 _____ (Microsoft Corporation) C:\Windows\system32\ieframe.dll
2015-12-09 10:54 - 2015-11-12 21:08 - 01388032 _____ (Microsoft Corporation) C:\Windows\system32\urlmon.dll
2015-12-09 10:54 - 2015-11-12 21:08 - 00448512 _____ (Microsoft Corporation) C:\Windows\system32\html.iec
2015-12-09 10:54 - 2015-11-12 21:07 - 02158080 _____ (Microsoft Corporation) C:\Windows\system32\iertutil.dll
2015-12-09 10:54 - 2015-11-12 21:06 - 01494016 _____ (Microsoft Corporation) C:\Windows\system32\inetcpl.cpl
2015-12-09 10:54 - 2015-11-12 21:06 - 00729088 _____ (Microsoft Corporation) C:\Windows\system32\msfeeds.dll
2015-12-09 10:54 - 2015-11-12 21:06 - 00237056 _____ (Microsoft Corporation) C:\Windows\system32\url.dll
2015-12-09 10:54 - 2015-11-12 21:06 - 00173568 _____ (Microsoft Corporation) C:\Windows\system32\ieUnatt.exe
2015-12-09 10:54 - 2015-11-12 21:06 - 00055296 _____ (Microsoft Corporation) C:\Windows\system32\msfeedsbs.dll
2015-12-09 10:54 - 2015-11-12 21:06 - 00012800 _____ (Microsoft Corporation) C:\Windows\system32\mshta.exe
2015-12-09 10:54 - 2015-11-12 21:06 - 00011264 _____ (Microsoft Corporation) C:\Windows\system32\msfeedssync.exe
2015-12-09 10:54 - 2015-11-12 20:36 - 00367616 _____ (Microsoft Corporation) C:\Windows\SysWOW64\html.iec
2015-12-09 10:54 - 2015-11-12 20:34 - 09753088 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieframe.dll
2015-12-09 10:54 - 2015-11-12 20:34 - 01140224 _____ (Microsoft Corporation) C:\Windows\SysWOW64\urlmon.dll
2015-12-09 10:54 - 2015-11-12 20:32 - 01804288 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iertutil.dll
2015-12-09 10:54 - 2015-11-12 20:32 - 01427968 _____ (Microsoft Corporation) C:\Windows\SysWOW64\inetcpl.cpl
2015-12-09 10:54 - 2015-11-12 20:32 - 00607744 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msfeeds.dll
2015-12-09 10:54 - 2015-11-12 20:32 - 00231936 _____ (Microsoft Corporation) C:\Windows\SysWOW64\url.dll
2015-12-09 10:54 - 2015-11-12 20:32 - 00142848 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieUnatt.exe
2015-12-09 10:54 - 2015-11-12 20:32 - 00065536 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jsproxy.dll
2015-12-09 10:54 - 2015-11-12 20:32 - 00041472 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msfeedsbs.dll
2015-12-09 10:54 - 2015-11-12 20:32 - 00011776 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshta.exe
2015-12-09 10:54 - 2015-11-12 20:31 - 00010752 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msfeedssync.exe
2015-12-09 10:54 - 2015-11-03 19:04 - 00241664 _____ (Microsoft Corporation) C:\Windows\system32\els.dll
2015-12-09 10:54 - 2015-11-03 18:55 - 00179712 _____ (Microsoft Corporation) C:\Windows\SysWOW64\els.dll
2015-12-07 19:43 - 2015-12-07 19:44 - 00002441 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Acrobat Reader DC.lnk
2015-12-07 19:43 - 2015-12-07 19:43 - 00002047 _____ C:\Users\Public\Desktop\Acrobat Reader DC.lnk
2015-12-07 19:43 - 2015-12-07 19:43 - 00000000 ____D C:\Program Files (x86)\Adobe
2015-12-06 11:08 - 2015-12-06 11:08 - 00000000 ____D C:\Users\euan\AppData\Roaming\AVG
2015-12-06 10:57 - 2015-12-06 10:57 - 00000930 _____ C:\Users\Public\Desktop\AVG.lnk
2015-12-06 10:57 - 2015-12-06 10:57 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\AVG Zen
2015-12-06 10:54 - 2015-12-06 11:02 - 00000000 ____D C:\ProgramData\Avg
2015-12-06 10:33 - 2015-12-06 10:57 - 00000000 ____D C:\Users\euan\AppData\Local\AvgSetupLog
2015-12-03 08:48 - 2015-12-03 08:48 - 00000282 _____ C:\Users\euan\Desktop\esetscanner2.txt
2015-12-03 00:16 - 2015-12-03 00:16 - 00000763 _____ C:\Users\euan\Desktop\JRT.txt
2015-12-02 21:07 - 2015-12-02 21:07 - 00000127 _____ C:\ProgramData\Microsoft.SqlServer.Compact.400.32.bc
2015-12-02 21:06 - 2015-12-02 21:06 - 01599336 _____ (Malwarebytes) C:\Users\euan\Desktop\JRT.exe
2015-12-02 21:06 - 2015-12-02 21:06 - 00448512 _____ (OldTimer Tools) C:\Users\euan\Desktop\TFC.exe
2015-12-02 12:37 - 2015-11-24 23:10 - 00112712 _____ C:\Windows\system32\NvRtmpStreamer64.dll
2015-12-02 12:33 - 2015-11-24 18:29 - 00102704 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\nvStreaming.exe
2015-12-02 12:26 - 2015-11-24 23:10 - 42913912 _____ C:\Windows\system32\nvcompiler.dll
2015-12-02 12:26 - 2015-11-24 23:10 - 37882488 _____ C:\Windows\SysWOW64\nvcompiler.dll
2015-12-02 12:26 - 2015-11-24 23:10 - 22310008 _____ (NVIDIA Corporation) C:\Windows\system32\nvoglv64.dll
2015-12-02 12:26 - 2015-11-24 23:10 - 18363696 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\nvoglv32.dll
2015-12-02 12:26 - 2015-11-24 23:10 - 16553568 _____ (NVIDIA Corporation) C:\Windows\system32\nvopencl.dll
2015-12-02 12:26 - 2015-11-24 23:10 - 15717672 _____ (NVIDIA Corporation) C:\Windows\system32\nvd3dumx.dll
2015-12-02 12:26 - 2015-11-24 23:10 - 15122296 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\nvwgf2um.dll
2015-12-02 12:26 - 2015-11-24 23:10 - 14835872 _____ (NVIDIA Corporation) C:\Windows\system32\nvcuda.dll
2015-12-02 12:26 - 2015-11-24 23:10 - 13527248 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\nvopencl.dll
2015-12-02 12:26 - 2015-11-24 23:10 - 12770752 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\nvd3dum.dll
2015-12-02 12:26 - 2015-11-24 23:10 - 12034248 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\nvcuda.dll
2015-12-02 12:26 - 2015-11-24 23:10 - 11131184 _____ (NVIDIA Corporation) C:\Windows\system32\Drivers\nvlddmkm.sys
2015-12-02 12:26 - 2015-11-24 23:10 - 03159248 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\nvapi.dll
2015-12-02 12:26 - 2015-11-24 23:10 - 02870392 _____ (NVIDIA Corporation) C:\Windows\system32\nvcuvid.dll
2015-12-02 12:26 - 2015-11-24 23:10 - 02490488 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\nvcuvid.dll
2015-12-02 12:26 - 2015-11-24 23:10 - 01905272 _____ (NVIDIA Corporation) C:\Windows\system32\nvdispco6435906.dll
2015-12-02 12:26 - 2015-11-24 23:10 - 01564792 _____ (NVIDIA Corporation) C:\Windows\system32\nvdispgenco6435906.dll
2015-12-02 12:26 - 2015-11-24 23:10 - 00877360 _____ (NVIDIA Corporation) C:\Windows\system32\NvFBC64.dll
2015-12-02 12:26 - 2015-11-24 23:10 - 00861816 _____ (NVIDIA Corporation) C:\Windows\system32\NvIFR64.dll
2015-12-02 12:26 - 2015-11-24 23:10 - 00689272 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\NvFBC.dll
2015-12-02 12:26 - 2015-11-24 23:10 - 00673912 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\NvIFR.dll
2015-12-02 12:26 - 2015-11-24 23:10 - 00467912 _____ (NVIDIA Corporation) C:\Windows\system32\nvumdshimx.dll
2015-12-02 12:26 - 2015-11-24 23:10 - 00388024 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\nvumdshim.dll
2015-12-02 12:26 - 2015-11-24 23:10 - 00205456 _____ (NVIDIA Corporation) C:\Windows\system32\Drivers\nvhda64v.sys
2015-12-02 12:26 - 2015-11-24 23:10 - 00177600 _____ (NVIDIA Corporation) C:\Windows\system32\nvinitx.dll
2015-12-02 12:26 - 2015-11-24 23:10 - 00155792 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\nvinit.dll
2015-12-02 12:26 - 2015-11-24 23:10 - 00151184 _____ (NVIDIA Corporation) C:\Windows\system32\nvoglshim64.dll
2015-12-02 12:26 - 2015-11-24 23:10 - 00128696 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\nvoglshim32.dll
2015-12-02 12:26 - 2015-11-24 23:10 - 00069416 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\nvaudcap32v.dll
2015-12-02 12:26 - 2015-11-24 23:10 - 00050472 _____ (NVIDIA Corporation) C:\Windows\system32\Drivers\nvvad64v.sys
2015-12-02 12:26 - 2015-11-24 23:10 - 00039240 _____ (NVIDIA Corporation) C:\Windows\system32\nvhdap64.dll
2015-12-02 12:26 - 2015-11-24 23:10 - 00033607 _____ C:\Windows\system32\nvinfo.pb
2015-12-02 12:15 - 2015-12-02 12:23 - 316046904 _____ (NVIDIA Corporation) C:\Users\euan\Downloads\359.06-desktop-win8-win7-winvista-64bit-international-whql.exe
2015-12-02 11:44 - 2015-12-02 11:44 - 00000000 ____D C:\Users\euan\AppData\Local\Fallout4
2015-12-02 11:14 - 2015-12-02 11:14 - 00000000 __SHD C:\Windows\SysWOW64\AI_RecycleBin
2015-12-02 11:11 - 2015-12-02 11:11 - 00004934 _____ C:\Users\euan\Desktop\esetscanner.txt
2015-12-02 08:16 - 2015-12-02 08:16 - 00000938 _____ C:\Users\euan\Desktop\Games - Shortcut.lnk
2015-12-02 05:06 - 2015-12-02 05:06 - 00000000 ____D C:\Program Files (x86)\ESET
2015-12-02 05:03 - 2015-12-02 05:04 - 02870984 _____ (ESET) C:\Users\euan\Desktop\esetsmartinstaller_enu.exe
2015-12-02 05:02 - 2015-12-02 05:02 - 00039714 _____ C:\Users\euan\Desktop\MTB.txt
2015-12-02 04:59 - 2015-12-02 04:59 - 00891392 _____ (Farbar) C:\Users\euan\Desktop\MiniToolBox.exe
2015-12-01 23:36 - 2015-12-01 23:07 - 00024064 _____ C:\Windows\zoek-delete.exe
2015-12-01 23:07 - 2015-12-01 23:28 - 00000000 ____D C:\zoek_backup
2015-12-01 23:06 - 2015-12-01 23:06 - 01309184 _____ C:\Users\euan\Downloads\zoek.exe
2015-12-01 22:53 - 2015-12-01 23:22 - 46525608 _____ (Safer-Networking Ltd. ) C:\Users\euan\Downloads\spybot-2.4.exe
2015-12-01 17:25 - 2015-12-01 17:25 - 00000000 ____D C:\Program Files\Common Files\Lavasoft
2015-11-30 18:58 - 2015-11-30 19:06 - 00000000 ___SD C:\Windows\system32\GWX
2015-11-30 18:58 - 2015-11-30 18:58 - 00000000 ___SD C:\Windows\SysWOW64\GWX
2015-11-30 18:24 - 2015-11-30 18:24 - 00000834 _____ C:\Users\euan\.recently-used.xbel
2015-11-30 17:58 - 2015-12-01 07:40 - 00000000 ____D C:\Users\euan\Desktop\mbar
2015-11-30 17:26 - 2015-11-30 17:27 - 16563352 _____ (Malwarebytes Corp.) C:\Users\euan\Downloads\mbar-1.09.3.1001.exe
2015-11-30 16:55 - 2015-11-30 19:03 - 00000000 ____D C:\Program Files (x86)\Mozilla Firefox
2015-11-30 15:58 - 2015-08-06 18:04 - 14176768 _____ (Microsoft Corporation) C:\Windows\system32\shell32.dll
2015-11-30 15:58 - 2015-08-06 18:03 - 01866752 _____ (Microsoft Corporation) C:\Windows\system32\ExplorerFrame.dll
2015-11-30 15:58 - 2015-08-06 17:44 - 12875776 _____ (Microsoft Corporation) C:\Windows\SysWOW64\shell32.dll
2015-11-30 15:58 - 2015-08-06 17:44 - 01498624 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ExplorerFrame.dll
2015-11-30 15:58 - 2015-08-05 17:56 - 01110016 _____ (Microsoft Corporation) C:\Windows\system32\schedsvc.dll
2015-11-30 15:57 - 2015-10-01 18:06 - 00692672 _____ (Microsoft Corporation) C:\Windows\system32\winload.efi
2015-11-30 15:57 - 2015-10-01 18:04 - 00616360 _____ (Microsoft Corporation) C:\Windows\system32\winresume.efi
2015-11-30 15:57 - 2015-10-01 18:00 - 00147456 _____ (Microsoft Corporation) C:\Windows\system32\appidpolicyconverter.exe
2015-11-30 15:57 - 2015-10-01 18:00 - 00063488 _____ (Microsoft Corporation) C:\Windows\system32\setbcdlocale.dll
2015-11-30 15:57 - 2015-10-01 18:00 - 00059392 _____ (Microsoft Corporation) C:\Windows\system32\appidapi.dll
2015-11-30 15:57 - 2015-10-01 18:00 - 00032768 _____ (Microsoft Corporation) C:\Windows\system32\appidsvc.dll
2015-11-30 15:57 - 2015-10-01 18:00 - 00017920 _____ (Microsoft Corporation) C:\Windows\system32\appidcertstorecheck.exe
2015-11-30 15:57 - 2015-10-01 17:50 - 00050688 _____ (Microsoft Corporation) C:\Windows\SysWOW64\appidapi.dll
2015-11-30 15:57 - 2015-10-01 17:00 - 00061440 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\appid.sys
2015-11-30 15:57 - 2015-07-09 17:58 - 01632256 _____ (Microsoft Corporation) C:\Windows\system32\dwmcore.dll
2015-11-30 15:57 - 2015-07-09 17:58 - 00082944 _____ (Microsoft Corporation) C:\Windows\system32\dwmapi.dll
2015-11-30 15:57 - 2015-07-09 17:42 - 01372160 _____ (Microsoft Corporation) C:\Windows\SysWOW64\dwmcore.dll
2015-11-30 15:57 - 2015-07-09 17:42 - 00067584 _____ (Microsoft Corporation) C:\Windows\SysWOW64\dwmapi.dll
2015-11-30 15:55 - 2015-09-18 19:22 - 00025432 _____ (Microsoft Corporation) C:\Windows\system32\CompatTelRunner.exe
2015-11-30 15:55 - 2015-09-18 19:19 - 01291264 _____ (Microsoft Corporation) C:\Windows\system32\appraiser.dll
2015-11-30 15:55 - 2015-09-18 19:19 - 00766464 _____ (Microsoft Corporation) C:\Windows\system32\generaltel.dll
2015-11-30 15:55 - 2015-09-18 19:19 - 00700416 _____ (Microsoft Corporation) C:\Windows\system32\invagent.dll
2015-11-30 15:55 - 2015-09-18 19:19 - 00503808 _____ (Microsoft Corporation) C:\Windows\system32\devinv.dll
2015-11-30 15:55 - 2015-09-18 19:19 - 00073216 _____ (Microsoft Corporation) C:\Windows\system32\acmigration.dll
2015-11-30 15:55 - 2015-09-18 19:09 - 01163776 _____ (Microsoft Corporation) C:\Windows\system32\aeinv.dll
2015-11-30 15:45 - 2015-10-20 01:12 - 05570496 _____ (Microsoft Corporation) C:\Windows\system32\ntoskrnl.exe
2015-11-30 15:45 - 2015-10-20 01:12 - 00154560 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\ksecpkg.sys
2015-11-30 15:45 - 2015-10-20 01:12 - 00095680 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\ksecdd.sys
2015-11-30 15:45 - 2015-10-20 01:09 - 01730496 _____ (Microsoft Corporation) C:\Windows\system32\ntdll.dll
2015-11-30 15:45 - 2015-10-20 01:06 - 00362496 _____ (Microsoft Corporation) C:\Windows\system32\wow64win.dll
2015-11-30 15:45 - 2015-10-20 01:06 - 00243712 _____ (Microsoft Corporation) C:\Windows\system32\wow64.dll
2015-11-30 15:45 - 2015-10-20 01:06 - 00215040 _____ (Microsoft Corporation) C:\Windows\system32\winsrv.dll
2015-11-30 15:45 - 2015-10-20 01:06 - 00013312 _____ (Microsoft Corporation) C:\Windows\system32\wow64cpu.dll
2015-11-30 15:45 - 2015-10-20 01:05 - 01461760 _____ (Microsoft Corporation) C:\Windows\system32\lsasrv.dll
2015-11-30 15:45 - 2015-10-20 01:05 - 01216512 _____ (Microsoft Corporation) C:\Windows\system32\rpcrt4.dll
2015-11-30 15:45 - 2015-10-20 01:05 - 01164800 _____ (Microsoft Corporation) C:\Windows\system32\kernel32.dll
2015-11-30 15:45 - 2015-10-20 01:05 - 00729600 _____ (Microsoft Corporation) C:\Windows\system32\kerberos.dll
2015-11-30 15:45 - 2015-10-20 01:05 - 00503808 _____ (Microsoft Corporation) C:\Windows\system32\srcore.dll
2015-11-30 15:45 - 2015-10-20 01:05 - 00424960 _____ (Microsoft Corporation) C:\Windows\system32\KernelBase.dll
2015-11-30 15:45 - 2015-10-20 01:05 - 00344064 _____ (Microsoft Corporation) C:\Windows\system32\schannel.dll
2015-11-30 15:45 - 2015-10-20 01:05 - 00315392 _____ (Microsoft Corporation) C:\Windows\system32\msv1_0.dll
2015-11-30 15:45 - 2015-10-20 01:05 - 00312320 _____ (Microsoft Corporation) C:\Windows\system32\ncrypt.dll
2015-11-30 15:45 - 2015-10-20 01:05 - 00296960 _____ (Microsoft Corporation) C:\Windows\system32\rstrui.exe
2015-11-30 15:45 - 2015-10-20 01:05 - 00210944 _____ (Microsoft Corporation) C:\Windows\system32\wdigest.dll
2015-11-30 15:45 - 2015-10-20 01:05 - 00136192 _____ (Microsoft Corporation) C:\Windows\system32\sspicli.dll
2015-11-30 15:45 - 2015-10-20 01:05 - 00112640 _____ (Microsoft Corporation) C:\Windows\system32\smss.exe
2015-11-30 15:45 - 2015-10-20 01:05 - 00086528 _____ (Microsoft Corporation) C:\Windows\system32\TSpkg.dll
2015-11-30 15:45 - 2015-10-20 01:05 - 00050176 _____ (Microsoft Corporation) C:\Windows\system32\srclient.dll
2015-11-30 15:45 - 2015-10-20 01:05 - 00044032 _____ (Microsoft Corporation) C:\Windows\system32\cryptbase.dll
2015-11-30 15:45 - 2015-10-20 01:05 - 00043520 _____ (Microsoft Corporation) C:\Windows\system32\csrsrv.dll
2015-11-30 15:45 - 2015-10-20 01:05 - 00029184 _____ (Microsoft Corporation) C:\Windows\system32\sspisrv.dll
2015-11-30 15:45 - 2015-10-20 01:05 - 00028160 _____ (Microsoft Corporation) C:\Windows\system32\secur32.dll
2015-11-30 15:45 - 2015-10-20 01:05 - 00022016 _____ (Microsoft Corporation) C:\Windows\system32\credssp.dll
2015-11-30 15:45 - 2015-10-20 01:05 - 00016384 _____ (Microsoft Corporation) C:\Windows\system32\ntvdm64.dll
2015-11-30 15:45 - 2015-10-20 01:04 - 00338432 _____ (Microsoft Corporation) C:\Windows\system32\conhost.exe
2015-11-30 15:45 - 2015-10-20 01:04 - 00064000 _____ (Microsoft Corporation) C:\Windows\system32\auditpol.exe
2015-11-30 15:45 - 2015-10-20 01:04 - 00031232 _____ (Microsoft Corporation) C:\Windows\system32\lsass.exe
2015-11-30 15:45 - 2015-10-20 01:00 - 00060416 _____ (Microsoft Corporation) C:\Windows\system32\msobjs.dll
2015-11-30 15:45 - 2015-10-20 00:59 - 00146432 _____ (Microsoft Corporation) C:\Windows\system32\msaudite.dll
2015-11-30 15:45 - 2015-10-20 00:53 - 00686080 _____ (Microsoft Corporation) C:\Windows\system32\adtschema.dll
2015-11-30 15:45 - 2015-10-20 00:53 - 00006656 _____ (Microsoft Corporation) C:\Windows\system32\apisetschema.dll
2015-11-30 15:45 - 2015-10-20 00:53 - 00006144 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-security-base-l1-1-0.dll
2015-11-30 15:45 - 2015-10-20 00:53 - 00005120 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-file-l1-1-0.dll
2015-11-30 15:45 - 2015-10-20 00:53 - 00004608 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-threadpool-l1-1-0.dll
2015-11-30 15:45 - 2015-10-20 00:53 - 00004608 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-processthreads-l1-1-0.dll
2015-11-30 15:45 - 2015-10-20 00:53 - 00004096 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-sysinfo-l1-1-0.dll
2015-11-30 15:45 - 2015-10-20 00:53 - 00004096 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-synch-l1-1-0.dll
2015-11-30 15:45 - 2015-10-20 00:53 - 00004096 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-localregistry-l1-1-0.dll
2015-11-30 15:45 - 2015-10-20 00:53 - 00004096 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-localization-l1-1-0.dll
2015-11-30 15:45 - 2015-10-20 00:53 - 00003584 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-rtlsupport-l1-1-0.dll
2015-11-30 15:45 - 2015-10-20 00:53 - 00003584 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-processenvironment-l1-1-0.dll
2015-11-30 15:45 - 2015-10-20 00:53 - 00003584 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-namedpipe-l1-1-0.dll
2015-11-30 15:45 - 2015-10-20 00:53 - 00003584 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-misc-l1-1-0.dll
2015-11-30 15:45 - 2015-10-20 00:53 - 00003584 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-memory-l1-1-0.dll
2015-11-30 15:45 - 2015-10-20 00:53 - 00003584 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-libraryloader-l1-1-0.dll
2015-11-30 15:45 - 2015-10-20 00:53 - 00003584 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-heap-l1-1-0.dll
2015-11-30 15:45 - 2015-10-20 00:53 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-xstate-l1-1-0.dll
2015-11-30 15:45 - 2015-10-20 00:53 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-util-l1-1-0.dll
2015-11-30 15:45 - 2015-10-20 00:53 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-string-l1-1-0.dll
2015-11-30 15:45 - 2015-10-20 00:53 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-profile-l1-1-0.dll
2015-11-30 15:45 - 2015-10-20 00:53 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-io-l1-1-0.dll
2015-11-30 15:45 - 2015-10-20 00:53 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-interlocked-l1-1-0.dll
2015-11-30 15:45 - 2015-10-20 00:53 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-handle-l1-1-0.dll
2015-11-30 15:45 - 2015-10-20 00:53 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-fibers-l1-1-0.dll
2015-11-30 15:45 - 2015-10-20 00:53 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-errorhandling-l1-1-0.dll
2015-11-30 15:45 - 2015-10-20 00:53 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-delayload-l1-1-0.dll
2015-11-30 15:45 - 2015-10-20 00:53 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-debug-l1-1-0.dll
2015-11-30 15:45 - 2015-10-20 00:53 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-datetime-l1-1-0.dll
2015-11-30 15:45 - 2015-10-20 00:53 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-console-l1-1-0.dll
2015-11-30 15:45 - 2015-10-20 00:52 - 03991488 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ntkrnlpa.exe
2015-11-30 15:45 - 2015-10-20 00:52 - 03935680 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ntoskrnl.exe
2015-11-30 15:45 - 2015-10-20 00:48 - 01311768 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ntdll.dll
2015-11-30 15:45 - 2015-10-20 00:45 - 00552960 _____ (Microsoft Corporation) C:\Windows\SysWOW64\kerberos.dll
2015-11-30 15:45 - 2015-10-20 00:45 - 00259584 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msv1_0.dll
2015-11-30 15:45 - 2015-10-20 00:45 - 00251392 _____ (Microsoft Corporation) C:\Windows\SysWOW64\schannel.dll
2015-11-30 15:45 - 2015-10-20 00:45 - 00223232 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ncrypt.dll
2015-11-30 15:45 - 2015-10-20 00:45 - 00172032 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wdigest.dll
2015-11-30 15:45 - 2015-10-20 00:45 - 00065536 _____ (Microsoft Corporation) C:\Windows\SysWOW64\TSpkg.dll
2015-11-30 15:45 - 2015-10-20 00:45 - 00043008 _____ (Microsoft Corporation) C:\Windows\SysWOW64\srclient.dll
2015-11-30 15:45 - 2015-10-20 00:45 - 00036864 _____ (Microsoft Corporation) C:\Windows\SysWOW64\cryptbase.dll
2015-11-30 15:45 - 2015-10-20 00:45 - 00025600 _____ (Microsoft Corporation) C:\Windows\SysWOW64\setup16.exe
2015-11-30 15:45 - 2015-10-20 00:45 - 00022016 _____ (Microsoft Corporation) C:\Windows\SysWOW64\secur32.dll
2015-11-30 15:45 - 2015-10-20 00:45 - 00017408 _____ (Microsoft Corporation) C:\Windows\SysWOW64\credssp.dll
2015-11-30 15:45 - 2015-10-20 00:45 - 00014336 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ntvdm64.dll
2015-11-30 15:45 - 2015-10-20 00:44 - 01114112 _____ (Microsoft Corporation) C:\Windows\SysWOW64\kernel32.dll
2015-11-30 15:45 - 2015-10-20 00:44 - 00665088 _____ (Microsoft Corporation) C:\Windows\SysWOW64\rpcrt4.dll
2015-11-30 15:45 - 2015-10-20 00:44 - 00274944 _____ (Microsoft Corporation) C:\Windows\SysWOW64\KernelBase.dll
2015-11-30 15:45 - 2015-10-20 00:44 - 00096768 _____ (Microsoft Corporation) C:\Windows\SysWOW64\sspicli.dll
2015-11-30 15:45 - 2015-10-20 00:44 - 00050176 _____ (Microsoft Corporation) C:\Windows\SysWOW64\auditpol.exe
2015-11-30 15:45 - 2015-10-20 00:44 - 00005120 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wow32.dll
2015-11-30 15:45 - 2015-10-20 00:39 - 00146432 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msaudite.dll
2015-11-30 15:45 - 2015-10-20 00:39 - 00060416 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msobjs.dll
2015-11-30 15:45 - 2015-10-20 00:35 - 00686080 _____ (Microsoft Corporation) C:\Windows\SysWOW64\adtschema.dll
2015-11-30 15:45 - 2015-10-20 00:35 - 00006656 _____ (Microsoft Corporation) C:\Windows\SysWOW64\apisetschema.dll
2015-11-30 15:45 - 2015-10-20 00:35 - 00005120 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-file-l1-1-0.dll
2015-11-30 15:45 - 2015-10-20 00:35 - 00004608 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-processthreads-l1-1-0.dll
2015-11-30 15:45 - 2015-10-20 00:35 - 00004096 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-sysinfo-l1-1-0.dll
2015-11-30 15:45 - 2015-10-20 00:35 - 00004096 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-synch-l1-1-0.dll
2015-11-30 15:45 - 2015-10-20 00:35 - 00004096 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-misc-l1-1-0.dll
2015-11-30 15:45 - 2015-10-20 00:35 - 00004096 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-localregistry-l1-1-0.dll
2015-11-30 15:45 - 2015-10-20 00:35 - 00004096 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-localization-l1-1-0.dll
2015-11-30 15:45 - 2015-10-20 00:35 - 00003584 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-processenvironment-l1-1-0.dll
2015-11-30 15:45 - 2015-10-20 00:35 - 00003584 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-namedpipe-l1-1-0.dll
2015-11-30 15:45 - 2015-10-20 00:35 - 00003584 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-memory-l1-1-0.dll
2015-11-30 15:45 - 2015-10-20 00:35 - 00003584 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-libraryloader-l1-1-0.dll
2015-11-30 15:45 - 2015-10-20 00:35 - 00003584 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-interlocked-l1-1-0.dll
2015-11-30 15:45 - 2015-10-20 00:35 - 00003584 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-heap-l1-1-0.dll
2015-11-30 15:45 - 2015-10-20 00:35 - 00003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-string-l1-1-0.dll
2015-11-30 15:45 - 2015-10-20 00:35 - 00003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-rtlsupport-l1-1-0.dll
2015-11-30 15:45 - 2015-10-20 00:35 - 00003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-profile-l1-1-0.dll
2015-11-30 15:45 - 2015-10-20 00:35 - 00003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-io-l1-1-0.dll
2015-11-30 15:45 - 2015-10-20 00:35 - 00003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-handle-l1-1-0.dll
2015-11-30 15:45 - 2015-10-20 00:35 - 00003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-fibers-l1-1-0.dll
2015-11-30 15:45 - 2015-10-20 00:35 - 00003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-errorhandling-l1-1-0.dll
2015-11-30 15:45 - 2015-10-20 00:35 - 00003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-delayload-l1-1-0.dll
2015-11-30 15:45 - 2015-10-20 00:35 - 00003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-debug-l1-1-0.dll
2015-11-30 15:45 - 2015-10-20 00:35 - 00003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-datetime-l1-1-0.dll
2015-11-30 15:45 - 2015-10-20 00:35 - 00003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-console-l1-1-0.dll
2015-11-30 15:45 - 2015-10-19 23:41 - 00159232 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\mrxsmb.sys
2015-11-30 15:45 - 2015-10-19 23:40 - 00290816 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\mrxsmb10.sys
2015-11-30 15:45 - 2015-10-19 23:40 - 00129024 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\mrxsmb20.sys
2015-11-30 15:45 - 2015-10-19 23:29 - 00007680 _____ (Microsoft Corporation) C:\Windows\SysWOW64\instnm.exe
2015-11-30 15:45 - 2015-10-19 23:29 - 00002048 _____ (Microsoft Corporation) C:\Windows\SysWOW64\user.exe
2015-11-30 15:45 - 2015-10-19 23:27 - 00006144 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-security-base-l1-1-0.dll
2015-11-30 15:45 - 2015-10-19 23:27 - 00004608 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-threadpool-l1-1-0.dll
2015-11-30 15:45 - 2015-10-19 23:27 - 00003584 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-xstate-l1-1-0.dll
2015-11-30 15:45 - 2015-10-19 23:27 - 00003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-util-l1-1-0.dll
2015-11-30 15:45 - 2015-09-23 13:15 - 00460776 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\cng.sys
2015-11-30 15:45 - 2015-09-23 13:15 - 00299632 _____ (Microsoft Corporation) C:\Windows\system32\bcryptprimitives.dll
2015-11-30 15:45 - 2015-09-23 13:09 - 00251000 _____ (Microsoft Corporation) C:\Windows\SysWOW64\bcryptprimitives.dll
2015-11-30 15:43 - 2015-10-29 17:50 - 00342016 _____ (Microsoft Corporation) C:\Windows\system32\apphelp.dll
2015-11-30 15:43 - 2015-10-29 17:50 - 00072192 _____ (Microsoft Corporation) C:\Windows\system32\aelupsvc.dll
2015-11-30 15:43 - 2015-10-29 17:50 - 00023552 _____ (Microsoft Corporation) C:\Windows\system32\sdbinst.exe
2015-11-30 15:43 - 2015-10-29 17:50 - 00006656 _____ (Microsoft Corporation) C:\Windows\system32\shimeng.dll
2015-11-30 15:43 - 2015-10-29 17:50 - 00005120 _____ (Microsoft Corporation) C:\Windows\SysWOW64\shimeng.dll
2015-11-30 15:43 - 2015-10-29 17:49 - 00295936 _____ (Microsoft Corporation) C:\Windows\SysWOW64\apphelp.dll
2015-11-30 15:43 - 2015-10-29 17:49 - 00020992 _____ (Microsoft Corporation) C:\Windows\SysWOW64\sdbinst.exe
2015-11-30 15:43 - 2015-07-23 00:02 - 01390592 _____ (Microsoft Corporation) C:\Windows\system32\diagtrack.dll
2015-11-30 15:43 - 2015-07-23 00:02 - 00879104 _____ (Microsoft Corporation) C:\Windows\system32\tdh.dll
2015-11-30 15:43 - 2015-07-23 00:02 - 00879104 _____ (Microsoft Corporation) C:\Windows\system32\advapi32.dll
2015-11-30 15:43 - 2015-07-22 17:53 - 00641536 _____ (Microsoft Corporation) C:\Windows\SysWOW64\advapi32.dll
2015-11-30 15:43 - 2015-07-22 17:53 - 00635392 _____ (Microsoft Corporation) C:\Windows\SysWOW64\tdh.dll
2015-11-30 15:43 - 2015-07-22 16:48 - 00041984 _____ (Microsoft Corporation) C:\Windows\system32\UtcResources.dll
2015-11-30 15:43 - 2015-07-18 13:08 - 00984448 _____ (Microsoft Corporation) C:\Windows\system32\ucrtbase.dll
2015-11-30 15:43 - 2015-07-18 13:08 - 00901264 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ucrtbase.dll
2015-11-30 15:43 - 2015-07-18 13:08 - 00066400 _____ (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-crt-private-l1-1-0.dll
2015-11-30 15:43 - 2015-07-18 13:08 - 00063840 _____ (Microsoft Corporation) C:\Windows\system32\api-ms-win-crt-private-l1-1-0.dll
2015-11-30 15:43 - 2015-07-18 13:08 - 00022368 _____ (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-crt-math-l1-1-0.dll
2015-11-30 15:43 - 2015-07-18 13:08 - 00020832 _____ (Microsoft Corporation) C:\Windows\system32\api-ms-win-crt-math-l1-1-0.dll
2015-11-30 15:43 - 2015-07-18 13:08 - 00019808 _____ (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-crt-multibyte-l1-1-0.dll
2015-11-30 15:43 - 2015-07-18 13:08 - 00019808 _____ (Microsoft Corporation) C:\Windows\system32\api-ms-win-crt-multibyte-l1-1-0.dll
2015-11-30 15:43 - 2015-07-18 13:08 - 00017760 _____ (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-crt-string-l1-1-0.dll
2015-11-30 15:43 - 2015-07-18 13:08 - 00017760 _____ (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-crt-stdio-l1-1-0.dll
2015-11-30 15:43 - 2015-07-18 13:08 - 00017760 _____ (Microsoft Corporation) C:\Windows\system32\api-ms-win-crt-string-l1-1-0.dll
2015-11-30 15:43 - 2015-07-18 13:08 - 00017760 _____ (Microsoft Corporation) C:\Windows\system32\api-ms-win-crt-stdio-l1-1-0.dll
2015-11-30 15:43 - 2015-07-18 13:08 - 00016224 _____ (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-crt-runtime-l1-1-0.dll
2015-11-30 15:43 - 2015-07-18 13:08 - 00016224 _____ (Microsoft Corporation) C:\Windows\system32\api-ms-win-crt-runtime-l1-1-0.dll
2015-11-30 15:43 - 2015-07-18 13:08 - 00015712 _____ (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-crt-convert-l1-1-0.dll
2015-11-30 15:43 - 2015-07-18 13:08 - 00015712 _____ (Microsoft Corporation) C:\Windows\system32\api-ms-win-crt-convert-l1-1-0.dll
2015-11-30 15:43 - 2015-07-18 13:08 - 00014176 _____ (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-crt-time-l1-1-0.dll
2015-11-30 15:43 - 2015-07-18 13:08 - 00014176 _____ (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-localization-l1-2-0.dll
2015-11-30 15:43 - 2015-07-18 13:08 - 00014176 _____ (Microsoft Corporation) C:\Windows\system32\api-ms-win-crt-time-l1-1-0.dll
2015-11-30 15:43 - 2015-07-18 13:08 - 00014176 _____ (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-localization-l1-2-0.dll
2015-11-30 15:43 - 2015-07-18 13:08 - 00013664 _____ (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-crt-filesystem-l1-1-0.dll
2015-11-30 15:43 - 2015-07-18 13:08 - 00013664 _____ (Microsoft Corporation) C:\Windows\system32\api-ms-win-crt-filesystem-l1-1-0.dll
2015-11-30 15:43 - 2015-07-18 13:08 - 00012640 _____ (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-crt-process-l1-1-0.dll
2015-11-30 15:43 - 2015-07-18 13:08 - 00012640 _____ (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-crt-heap-l1-1-0.dll
2015-11-30 15:43 - 2015-07-18 13:08 - 00012640 _____ (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-crt-conio-l1-1-0.dll
2015-11-30 15:43 - 2015-07-18 13:08 - 00012640 _____ (Microsoft Corporation) C:\Windows\system32\api-ms-win-crt-process-l1-1-0.dll
2015-11-30 15:43 - 2015-07-18 13:08 - 00012640 _____ (Microsoft Corporation) C:\Windows\system32\api-ms-win-crt-heap-l1-1-0.dll
2015-11-30 15:43 - 2015-07-18 13:08 - 00012640 _____ (Microsoft Corporation) C:\Windows\system32\api-ms-win-crt-conio-l1-1-0.dll
2015-11-30 15:43 - 2015-07-18 13:08 - 00012128 _____ (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-crt-utility-l1-1-0.dll
2015-11-30 15:43 - 2015-07-18 13:08 - 00012128 _____ (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-crt-locale-l1-1-0.dll
2015-11-30 15:43 - 2015-07-18 13:08 - 00012128 _____ (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-crt-environment-l1-1-0.dll
2015-11-30 15:43 - 2015-07-18 13:08 - 00012128 _____ (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-synch-l1-2-0.dll
2015-11-30 15:43 - 2015-07-18 13:08 - 00012128 _____ (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-processthreads-l1-1-1.dll
2015-11-30 15:43 - 2015-07-18 13:08 - 00012128 _____ (Microsoft Corporation) C:\Windows\system32\api-ms-win-crt-utility-l1-1-0.dll
2015-11-30 15:43 - 2015-07-18 13:08 - 00012128 _____ (Microsoft Corporation) C:\Windows\system32\api-ms-win-crt-locale-l1-1-0.dll
2015-11-30 15:43 - 2015-07-18 13:08 - 00012128 _____ (Microsoft Corporation) C:\Windows\system32\api-ms-win-crt-environment-l1-1-0.dll
2015-11-30 15:43 - 2015-07-18 13:08 - 00012128 _____ (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-synch-l1-2-0.dll
2015-11-30 15:43 - 2015-07-18 13:08 - 00012128 _____ (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-processthreads-l1-1-1.dll
2015-11-30 15:43 - 2015-07-18 13:08 - 00011616 _____ (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-eventing-provider-l1-1-0.dll
2015-11-30 15:43 - 2015-07-18 13:08 - 00011616 _____ (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-xstate-l2-1-0.dll
2015-11-30 15:43 - 2015-07-18 13:08 - 00011616 _____ (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-timezone-l1-1-0.dll
2015-11-30 15:43 - 2015-07-18 13:08 - 00011616 _____ (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-file-l2-1-0.dll
2015-11-30 15:43 - 2015-07-18 13:08 - 00011616 _____ (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-file-l1-2-0.dll
2015-11-30 15:43 - 2015-07-18 13:08 - 00011616 _____ (Microsoft Corporation) C:\Windows\system32\api-ms-win-eventing-provider-l1-1-0.dll
2015-11-30 15:43 - 2015-07-18 13:08 - 00011616 _____ (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-xstate-l2-1-0.dll
2015-11-30 15:43 - 2015-07-18 13:08 - 00011616 _____ (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-timezone-l1-1-0.dll
2015-11-30 15:43 - 2015-07-18 13:08 - 00011616 _____ (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-file-l2-1-0.dll
2015-11-30 15:43 - 2015-07-18 13:08 - 00011616 _____ (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-file-l1-2-0.dll
2015-11-30 15:41 - 2015-10-01 18:00 - 00275456 _____ (Microsoft Corporation) C:\Windows\system32\InkEd.dll
2015-11-30 15:41 - 2015-10-01 18:00 - 00024576 _____ (Microsoft Corporation) C:\Windows\system32\jnwmon.dll
2015-11-30 15:41 - 2015-10-01 17:50 - 00216064 _____ (Microsoft Corporation) C:\Windows\SysWOW64\InkEd.dll
2015-11-30 15:41 - 2015-08-27 18:18 - 02004480 _____ (Microsoft Corporation) C:\Windows\system32\msxml6.dll
2015-11-30 15:41 - 2015-08-27 18:18 - 01887232 _____ (Microsoft Corporation) C:\Windows\system32\msxml3.dll
2015-11-30 15:41 - 2015-08-27 18:13 - 00002048 _____ (Microsoft Corporation) C:\Windows\system32\msxml6r.dll
2015-11-30 15:41 - 2015-08-27 18:13 - 00002048 _____ (Microsoft Corporation) C:\Windows\system32\msxml3r.dll
2015-11-30 15:41 - 2015-08-27 17:58 - 01391104 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msxml6.dll
2015-11-30 15:41 - 2015-08-27 17:58 - 01241088 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msxml3.dll
2015-11-30 15:41 - 2015-08-27 17:51 - 00002048 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msxml6r.dll
2015-11-30 15:41 - 2015-08-27 17:51 - 00002048 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msxml3r.dll
2015-11-30 15:41 - 2015-06-25 10:06 - 00115136 _____ (Microsoft Corporation) C:\Windows\system32\consent.exe
2015-11-30 15:41 - 2015-06-25 10:01 - 01941504 _____ (Microsoft Corporation) C:\Windows\system32\authui.dll
2015-11-30 15:41 - 2015-06-25 10:01 - 00070656 _____ (Microsoft Corporation) C:\Windows\system32\appinfo.dll
2015-11-30 15:41 - 2015-06-25 09:44 - 01805824 _____ (Microsoft Corporation) C:\Windows\SysWOW64\authui.dll
2015-11-30 15:40 - 2015-10-13 16:41 - 00497664 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\afd.sys
2015-11-30 15:40 - 2015-10-13 16:40 - 00118272 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\tdx.sys
2015-11-30 15:34 - 2015-10-13 04:57 - 00950720 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\ndis.sys
2015-11-30 15:34 - 2015-09-02 03:04 - 00100864 _____ (Microsoft Corporation) C:\Windows\system32\fontsub.dll
2015-11-30 15:34 - 2015-09-02 03:04 - 00046080 _____ (Adobe Systems) C:\Windows\system32\atmlib.dll
2015-11-30 15:34 - 2015-09-02 03:04 - 00041984 _____ (Microsoft Corporation) C:\Windows\system32\lpk.dll
2015-11-30 15:34 - 2015-09-02 03:04 - 00014336 _____ (Microsoft Corporation) C:\Windows\system32\dciman32.dll
2015-11-30 15:34 - 2015-09-02 02:48 - 00070656 _____ (Microsoft Corporation) C:\Windows\SysWOW64\fontsub.dll
2015-11-30 15:34 - 2015-09-02 02:48 - 00034304 _____ (Adobe Systems) C:\Windows\SysWOW64\atmlib.dll
2015-11-30 15:34 - 2015-09-02 02:48 - 00010240 _____ (Microsoft Corporation) C:\Windows\SysWOW64\dciman32.dll
2015-11-30 15:34 - 2015-09-02 02:47 - 00025600 _____ (Microsoft Corporation) C:\Windows\SysWOW64\lpk.dll
2015-11-30 15:34 - 2015-09-02 01:47 - 00372736 _____ (Adobe Systems Incorporated) C:\Windows\system32\atmfd.dll
2015-11-30 15:34 - 2015-09-02 01:33 - 00299520 _____ (Adobe Systems Incorporated) C:\Windows\SysWOW64\atmfd.dll
2015-11-30 14:16 - 2015-11-30 14:16 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\LogMeIn Hamachi
2015-11-30 14:16 - 2015-11-30 14:16 - 00000000 ____D C:\Program Files (x86)\LogMeIn Hamachi

==================== One Month Modified files and folders ========

(If an entry is included in the fixlist, the file/folder will be moved.)

2015-12-13 15:29 - 2009-07-14 03:20 - 00000000 ____D C:\Windows
2015-12-13 15:18 - 2012-05-03 12:04 - 00000830 _____ C:\Windows\Tasks\Adobe Flash Player Updater.job
2015-12-13 15:00 - 2015-08-12 20:55 - 00192216 _____ (Malwarebytes) C:\Windows\system32\Drivers\MBAMSwissArmy.sys
2015-12-13 12:24 - 2009-07-14 04:45 - 00023376 ____H C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
2015-12-13 12:24 - 2009-07-14 04:45 - 00023376 ____H C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
2015-12-13 12:17 - 2011-03-24 21:44 - 00000000 ____D C:\ProgramData\MFAData
2015-12-13 12:15 - 2011-04-12 22:51 - 00000000 ____D C:\Users\euan\AppData\Local\LogMeIn Hamachi
2015-12-13 12:14 - 2011-03-24 21:06 - 00000000 ____D C:\ProgramData\NVIDIA
2015-12-13 12:14 - 2009-07-14 05:08 - 00000006 ____H C:\Windows\Tasks\SA.DAT
2015-12-12 01:48 - 2011-06-20 11:57 - 00000000 ____D C:\Users\euan\AppData\Roaming\BitComet
2015-12-12 00:10 - 2009-07-14 03:20 - 00000000 ____D C:\Windows\rescache
2015-12-11 14:56 - 2011-04-28 21:54 - 00000000 ____D C:\Users\euan\AppData\Roaming\Skype
2015-12-10 23:04 - 2011-04-28 21:53 - 00000000 ____D C:\ProgramData\Skype
2015-12-10 23:03 - 2014-03-12 21:53 - 00000000 ____D C:\Users\euan\AppData\Local\Skype
2015-12-10 23:03 - 2011-12-02 14:36 - 00002697 _____ C:\Users\Public\Desktop\Skype.lnk
2015-12-10 23:03 - 2011-04-28 21:53 - 00000000 ___RD C:\Program Files (x86)\Skype
2015-12-10 11:18 - 2009-07-14 04:45 - 00280824 _____ C:\Windows\system32\FNTCACHE.DAT
2015-12-10 11:15 - 2009-07-14 03:20 - 00000000 ____D C:\Windows\inf
2015-12-10 01:26 - 2012-07-04 19:12 - 00000000 ____D C:\ProgramData\Microsoft Help
2015-12-10 01:23 - 2013-08-14 17:35 - 00000000 ____D C:\Windows\system32\MRT
2015-12-10 01:18 - 2011-03-25 15:04 - 140158008 _____ (Microsoft Corporation) C:\Windows\system32\MRT.exe
2015-12-09 17:59 - 2009-07-14 05:13 - 00782470 _____ C:\Windows\system32\PerfStringBackup.INI
2015-12-09 11:18 - 2012-05-03 12:04 - 00796864 _____ (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerApp.exe
2015-12-09 11:18 - 2012-05-03 12:04 - 00003768 _____ C:\Windows\System32\Tasks\Adobe Flash Player Updater
2015-12-09 11:18 - 2011-05-19 11:38 - 00142528 _____ (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerCPLApp.cpl
2015-12-07 19:44 - 2015-07-15 14:08 - 00003886 _____ C:\Windows\System32\Tasks\Adobe Acrobat Update Task
2015-12-07 19:42 - 2011-06-08 14:53 - 00000000 ____D C:\ProgramData\Adobe
2015-12-07 08:27 - 2014-10-21 10:03 - 00000000 ____D C:\ProgramData\AVG2015
2015-12-07 08:27 - 2011-03-24 21:53 - 00000000 ____D C:\Program Files (x86)\AVG
2015-12-06 11:09 - 2015-07-16 07:56 - 00000000 ____D C:\Users\euan\AppData\Local\Avg
2015-12-06 11:08 - 2011-02-26 19:09 - 00000000 ___HD C:\$AVG
2015-12-06 11:07 - 2014-03-31 09:31 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\AVG
2015-12-06 11:06 - 2015-07-16 07:59 - 00000000 ____D C:\Program Files\Common Files\AV
2015-12-03 00:10 - 2014-11-03 23:06 - 00000000 ____D C:\Program Files (x86)\Crusader Kings II
2015-12-02 21:07 - 2012-06-15 16:58 - 00000000 ____D C:\Users\euan\AppData\Roaming\Fatshark
2015-12-02 12:36 - 2014-02-18 20:19 - 00000000 ____D C:\Users\euan\AppData\Local\NVIDIA Corporation
2015-12-02 12:34 - 2014-02-18 20:16 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\NVIDIA Corporation
2015-12-02 12:34 - 2011-03-24 20:58 - 00000000 ____D C:\ProgramData\NVIDIA Corporation
2015-12-02 11:44 - 2011-03-24 15:57 - 00000000 ____D C:\Users\euan\Documents\My Games
2015-12-02 11:14 - 2012-10-09 22:11 - 00000000 ____D C:\Users\euan\AppData\Roaming\.spotflux
2015-12-02 08:20 - 2012-09-21 18:29 - 00000000 ____D C:\Users\euan\Games
2015-12-02 08:19 - 2011-03-24 20:47 - 00000000 ____D C:\Users\euan
2015-12-02 08:16 - 2011-05-19 21:05 - 00155648 ___SH C:\Users\euan\Thumbs.db
2015-12-02 08:08 - 2011-07-05 15:44 - 00000000 ____D C:\Users\euan\TV & Movies
2015-12-01 22:49 - 2015-08-11 22:48 - 00000000 ____D C:\AdwCleaner
2015-12-01 16:06 - 2013-10-26 14:26 - 00000000 ____D C:\ProgramData\Oracle
2015-12-01 16:05 - 2013-10-26 14:23 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Java
2015-12-01 16:05 - 2011-03-26 18:52 - 00000000 ____D C:\Program Files (x86)\Java
2015-12-01 16:02 - 2015-08-27 11:48 - 00000000 ____D C:\Users\euan\.oracle_jre_usage
2015-12-01 16:01 - 2014-10-20 12:57 - 00097888 _____ (Oracle Corporation) C:\Windows\SysWOW64\WindowsAccessBridge-32.dll
2015-12-01 15:19 - 2011-07-15 23:33 - 00425884 _____ C:\Windows\ntbtlog.txt
2015-12-01 07:20 - 2015-08-12 20:55 - 00109272 _____ (Malwarebytes) C:\Windows\system32\Drivers\mbamchameleon.sys
2015-11-30 19:03 - 2012-05-18 11:32 - 00000000 ____D C:\Program Files (x86)\Mozilla Maintenance Service
2015-11-30 19:02 - 2009-07-14 03:20 - 00000000 ____D C:\Windows\LiveKernelReports
2015-11-30 18:58 - 2014-12-10 09:51 - 00000000 ____D C:\Windows\system32\appraiser
2015-11-30 18:58 - 2014-05-06 17:05 - 00000000 ___SD C:\Windows\system32\CompatTel
2015-11-30 18:58 - 2009-07-14 07:45 - 00000000 ____D C:\Program Files\Windows Journal
2015-11-30 18:22 - 2011-05-28 13:45 - 00000000 ____D C:\Users\euan\.gimp-2.6
2015-11-30 16:24 - 2011-04-30 15:07 - 00766336 _____ C:\Windows\SysWOW64\PerfStringBackup.INI
2015-11-30 16:03 - 2015-08-12 20:55 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Malwarebytes Anti-Malware
2015-11-30 16:03 - 2015-08-12 20:55 - 00000000 ____D C:\Program Files (x86)\Malwarebytes Anti-Malware
2015-11-30 15:00 - 2012-06-22 22:20 - 00000000 ____D C:\ProgramData\Rockstar Games
2015-11-30 15:00 - 2011-04-12 11:41 - 00000000 ___HD C:\Program Files (x86)\InstallShield Installation Information
2015-11-30 14:53 - 2009-07-14 05:32 - 00000000 ___RD C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Games
2015-11-24 23:10 - 2014-11-18 10:27 - 01756424 _____ (NVIDIA Corporation) C:\Windows\system32\nvspbridge64.dll
2015-11-24 23:10 - 2014-11-18 10:27 - 01316000 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\nvspbridge.dll
2015-11-24 23:10 - 2014-02-18 20:17 - 01828160 _____ (NVIDIA Corporation) C:\Windows\system32\nvspcap64.dll
2015-11-24 23:10 - 2014-02-18 20:17 - 01509824 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\nvspcap.dll
2015-11-24 23:10 - 2014-02-18 20:10 - 00072504 _____ (NVIDIA Corporation) C:\Windows\system32\nvaudcap64v.dll
2015-11-24 23:10 - 2013-02-25 23:32 - 17516040 _____ (NVIDIA Corporation) C:\Windows\system32\nvwgf2umx.dll
2015-11-24 23:10 - 2013-02-25 23:32 - 03579696 _____ (NVIDIA Corporation) C:\Windows\system32\nvapi64.dll
2015-11-24 23:10 - 2012-08-19 00:05 - 01572496 _____ (NVIDIA Corporation) C:\Windows\system32\nvhdagenco6420103.dll
2015-11-24 18:40 - 2011-01-07 20:50 - 06358648 _____ (NVIDIA Corporation) C:\Windows\system32\nvcpl.dll
2015-11-24 18:40 - 2011-01-07 20:49 - 02983032 _____ (NVIDIA Corporation) C:\Windows\system32\nvsvc64.dll
2015-11-24 18:40 - 2011-01-07 20:49 - 02554488 _____ (NVIDIA Corporation) C:\Windows\system32\nvsvcr.dll
2015-11-24 18:40 - 2011-01-07 20:49 - 00938616 _____ (NVIDIA Corporation) C:\Windows\system32\nvvsvc.exe
2015-11-24 18:40 - 2011-01-07 20:49 - 00385144 _____ (NVIDIA Corporation) C:\Windows\system32\nvmctray.dll
2015-11-24 18:40 - 2010-07-09 16:27 - 00062584 _____ (NVIDIA Corporation) C:\Windows\system32\nvshext.dll
2015-11-23 10:38 - 2012-08-19 00:07 - 06049858 _____ C:\Windows\system32\nvcoproc.bin

==================== Files in the root of some directories =======

2012-11-19 23:02 - 2012-12-08 13:22 - 0581642 _____ () C:\Users\euan\AppData\Roaming\technic-launcher.jar
2012-11-19 23:02 - 2012-12-04 20:47 - 0581168 _____ () C:\Users\euan\AppData\Roaming\technic-launcher.jar.bak
2011-08-04 17:13 - 2014-04-08 13:34 - 0010752 _____ () C:\Users\euan\AppData\Local\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
2013-06-20 13:23 - 2013-06-20 13:23 - 0000017 _____ () C:\Users\euan\AppData\Local\resmon.resmoncfg
2011-04-28 21:55 - 2011-04-28 21:55 - 0000056 ____H () C:\ProgramData\ezsidmv.dat
2015-12-02 21:07 - 2015-12-02 21:07 - 0000127 _____ () C:\ProgramData\Microsoft.SqlServer.Compact.400.32.bc

==================== Bamital & volsnap =================

(There is no automatic fix for files that do not pass verification.)

C:\Windows\system32\winlogon.exe => File is digitally signed
C:\Windows\system32\wininit.exe => File is digitally signed
C:\Windows\SysWOW64\wininit.exe => File is digitally signed
C:\Windows\explorer.exe => File is digitally signed
C:\Windows\SysWOW64\explorer.exe => File is digitally signed
C:\Windows\system32\svchost.exe => File is digitally signed
C:\Windows\SysWOW64\svchost.exe => File is digitally signed
C:\Windows\system32\services.exe => File is digitally signed
C:\Windows\system32\User32.dll => File is digitally signed
C:\Windows\SysWOW64\User32.dll => File is digitally signed
C:\Windows\system32\userinit.exe => File is digitally signed
C:\Windows\SysWOW64\userinit.exe => File is digitally signed
C:\Windows\system32\rpcss.dll => File is digitally signed
C:\Windows\system32\dnsapi.dll => File is digitally signed
C:\Windows\SysWOW64\dnsapi.dll => File is digitally signed
C:\Windows\system32\Drivers\volsnap.sys => File is digitally signed


LastRegBack: 2015-12-10 12:56

==================== End of FRST.txt ============================

Edited by Queen-Evie, 13 December 2015 - 02:51 PM.
moved from Am I Infected to Malware Removal Logs. FRST logs are allowed only in MRL forum.


BC AdBot (Login to Remove)

 


#2 euanicorn

euanicorn
  • Topic Starter

  • Members
  • 12 posts
  • OFFLINE
  •  
  • Local time:08:12 AM

Posted 13 December 2015 - 10:41 AM

And Addition.txt
 
Additional scan result of Farbar Recovery Scan Tool (x64) Version:12-12-2015 01
Ran by euan (2015-12-13 15:30:44)
Running from C:\Users\euan\Downloads
Windows 7 Home Premium Service Pack 1 (X64) (2011-03-24 20:47:13)
Boot Mode: Normal
==========================================================


==================== Accounts: =============================

Administrator (S-1-5-21-1126527562-1434389470-3061596616-500 - Administrator - Disabled)
euan (S-1-5-21-1126527562-1434389470-3061596616-1001 - Administrator - Enabled) => C:\Users\euan
Guest (S-1-5-21-1126527562-1434389470-3061596616-501 - Limited - Enabled)
HomeGroupUser$ (S-1-5-21-1126527562-1434389470-3061596616-1002 - Limited - Enabled)

==================== Security Center ========================

(If an entry is included in the fixlist, it will be removed.)

AV: AVG AntiVirus Free Edition (Enabled - Up to date) {4D41356F-32AD-7C42-C820-63775EE4F413}
AS: Windows Defender (Disabled - Up to date) {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
AS: AVG AntiVirus Free Edition (Enabled - Up to date) {F620D48B-1497-73CC-F290-58052563BEAE}

==================== Installed Programs ======================

(Only the adware programs with "Hidden" flag could be added to the fixlist to unhide them. The adware programs should be uninstalled manually.)

7-Zip 9.20 (HKLM-x32\...\7-Zip) (Version:  - )
Ad-Aware Antivirus (HKLM\...\{30B9595A-D4B5-4198-8F3C-2219C78590C9}_AdAwareUpdater) (Version: 11.9.662.8718 - Lavasoft)
Adobe Acrobat Reader DC (HKLM-x32\...\{AC76BA86-7AD7-1033-7B44-AC0F074E4100}) (Version: 15.009.20069 - Adobe Systems Incorporated)
Adobe Flash Player 20 ActiveX (HKLM-x32\...\Adobe Flash Player ActiveX) (Version: 20.0.0.228 - Adobe Systems Incorporated)
Adobe Flash Player 20 NPAPI (HKLM-x32\...\Adobe Flash Player NPAPI) (Version: 20.0.0.235 - Adobe Systems Incorporated)
Age of Wonders 3 (HKLM-x32\...\Age of Wonders 3_R.G. Mechanics_is1) (Version:  - R.G. Mechanics, markfiter)
Arma 3 Alpha (HKLM-x32\...\Steam App 107410) (Version:  - Bohemia Interactive)
AVG (HKLM\...\AvgZen) (Version: 1.22.1.40089 - AVG Technologies)
AVG (Version: 16.12.7294 - AVG Technologies) Hidden
AVG 2016 (Version: 16.0.4483 - AVG Technologies) Hidden
AVG Protection (HKLM\...\AVG) (Version: 2016.12.7294 - AVG Technologies)
AVG Zen (Version: 1.22.1 - AVG Technologies) Hidden
BitComet 1.27 (HKLM-x32\...\BitComet) (Version: 1.27 - CometNetwork)
BitComet 1.35 64-bit (HKLM-x32\...\BitComet_x64) (Version: 1.35 - CometNetwork)
CDBurnerXP (HKLM\...\{7E265513-8CDA-4631-B696-F40D983F3B07}_is1) (Version: 4.3.8.2568 - CDBurnerXP)
Chivalry: Medieval Warfare (HKLM-x32\...\Steam App 219640) (Version:  - )
Counter-Strike: Global Offensive - SDK (HKLM-x32\...\Steam App 745) (Version:  - )
CSI New York (HKLM-x32\...\CSI New York1.0) (Version: 1.0 - Your Company)
D3DX10 (x32 Version: 15.4.2368.0902 - Microsoft) Hidden
DAEMON Tools Lite (HKLM-x32\...\DAEMON Tools Lite) (Version: 4.45.4.0315 - DT Soft Ltd)
DARK SOULS™ II (HKLM-x32\...\Steam App 236430) (Version:  - FromSoftware, Inc)
Dead Rising 3 v.1.0 (HKLM-x32\...\Dead Rising 3_is1) (Version:  - )
Dishonored (HKLM-x32\...\Steam App 205100) (Version: 1.0 - Bethesda Softworks)
Distant Worlds (HKLM-x32\...\Distant Worlds1.00) (Version: 1.00 - Matrix Games)
DivX Setup (HKLM-x32\...\DivX Setup) (Version: 2.6.1.100 - DivX, LLC)
Dominions 4 (HKLM-x32\...\Steam App 259060) (Version:  - Illwinter Game Design)
Don't Starve (HKLM-x32\...\Steam App 219740) (Version:  - )
DVD Flick 1.3.0.7 (HKLM-x32\...\DVD Flick_is1) (Version: 1.3.0.7 - Dennis Meuwissen)
Dying Light (HKLM-x32\...\Dying Light_R.G. Mechanics_is1) (Version:  - R.G. Mechanics, ProZorg_tm)
Eastern Front (HKLM-x32\...\Eastern Front) (Version: 1.5.1.0 - )
Elite Dangerous Launcher version 0.4.2854.0 (HKLM-x32\...\{696F8871-C91D-4CB1-825D-36BE18065575}_is1) (Version: 0.4.2854.0 - Frontier Developments)
EPSON SX235 Series Printer Uninstall (HKLM\...\EPSON SX235 Series) (Version:  - SEIKO EPSON Corporation)
ESET Online Scanner v3 (HKLM-x32\...\ESET Online Scanner) (Version:  - )
Evil Genius (HKLM-x32\...\Steam App 3720) (Version:  - Elixir Studios)
Evolve (HKLM\...\{670B1B49-9FD3-4827-9B41-471EFF580AA8}) (Version: 1.8.10 - Echobit, LLC)
Fallout 4 (HKLM-x32\...\Steam App 377160) (Version:  - Bethesda Game Studios)
Fallout Mod Manager 0.13.21 (HKLM-x32\...\Generic Mod Manager_is1) (Version:  - Q, Timeslip)
Far Cry 4 (HKLM-x32\...\Uplay Install 420) (Version:  - Ubisoft)
Faster Than Light (HKLM-x32\...\Faster Than Light_is1) (Version:  - GOG.com)
Five Nights at Freddy's (HKLM-x32\...\Steam App 319510) (Version:  - Scott Cawthon)
FMW 1 (Version: 1.32.2 - AVG Technologies) Hidden
FTL: Faster Than Light (HKLM-x32\...\Steam App 212680) (Version:  - Subset Games)
GIMP 2.6.11 (HKLM-x32\...\WinGimp-2.0_is1) (Version: 2.6.11 - The GIMP Team)
Grand Theft Auto V (HKLM-x32\...\Steam App 271590) (Version:  - Rockstar North)
Hitman: Absolution (HKLM-x32\...\Steam App 203140) (Version:  - Square Enix)
Hotline Miami (HKLM-x32\...\Steam App 219150) (Version:  - )
Impulse (HKLM-x32\...\Impulse) (Version:  - Stardock)
Impulse (x32 Version: 1.0 - Stardock Corporation) Hidden
Injustice: Gods Among Us Ultimate Edition (HKLM-x32\...\SW5qdXN0aWNlR29kc0Ftb25nVXNVbHRpbWF0ZUVkaXRpb24=_is1) (Version: 1 - )
Java 8 Update 66 (HKLM-x32\...\{26A24AE4-039D-4CA4-87B4-2F83218066F0}) (Version: 8.0.660.18 - Oracle Corporation)
Kerbal Space Program (HKLM-x32\...\Steam App 220200) (Version:  - Squad)
Lichdom: Battlemage (HKLM-x32\...\Steam App 261760) (Version:  - Xaviant)
LogMeIn Hamachi (HKLM-x32\...\LogMeIn Hamachi) (Version: 2.2.0.410 - LogMeIn, Inc.)
LogMeIn Hamachi (x32 Version: 2.2.0.410 - LogMeIn, Inc.) Hidden
LOOT version 0.8.0 (HKLM-x32\...\{BF634210-A0D4-443F-A657-0DCE38040374}_is1) (Version: 0.8.0 - LOOT Team)
Magic ISO Maker v5.5 (build 0281) (HKLM-x32\...\Magic ISO Maker v5.5 (build 0281)) (Version:  - )
Malwarebytes Anti-Malware version 2.2.0.1024 (HKLM-x32\...\Malwarebytes Anti-Malware_is1) (Version: 2.2.0.1024 - Malwarebytes)
Microsoft .NET Framework 4.5.2 (HKLM\...\{92FB6C44-E685-45AD-9B20-CADF4CABA132} - 1033) (Version: 4.5.51209 - Microsoft Corporation)
Microsoft ASP.NET MVC 4 Runtime (HKLM-x32\...\{3FE312D5-B862-40CE-8E4E-A6D8ABF62736}) (Version: 4.0.40804.0 - Microsoft Corporation)
Microsoft Chart Controls for Microsoft .NET Framework 3.5 (HKLM-x32\...\{41785C66-90F2-40CE-8CB5-1C94BFC97280}) (Version: 3.5.30730.0 - Microsoft Corporation)
Microsoft Games for Windows - LIVE Redistributable (HKLM-x32\...\{832D9DE0-8AFC-4689-9819-4DBBDEBD3E4F}) (Version: 3.5.92.0 - Microsoft Corporation)
Microsoft Games for Windows Marketplace (HKLM-x32\...\{4CB0307C-565E-4441-86BE-0DF2E4FB828C}) (Version: 3.5.50.0 - Microsoft Corporation)
Microsoft Office Home and Student 2010 (HKLM-x32\...\Office14.SingleImage) (Version: 14.0.7015.1000 - Microsoft Corporation)
Microsoft SQL Server 2005 Compact Edition [ENU] (HKLM-x32\...\{F0B430D1-B6AA-473D-9B06-AA3DD01FD0B8}) (Version: 3.1.0000 - Microsoft Corporation)
Microsoft Visual C++ 2005 Redistributable (HKLM-x32\...\{710f4c1c-cc18-4c49-8cbf-51240c89a1a2}) (Version: 8.0.61001 - Microsoft Corporation)
Microsoft Visual C++ 2005 Redistributable (HKLM-x32\...\{7299052b-02a4-4627-81f2-1818da5d550d}) (Version: 8.0.56336 - Microsoft Corporation)
Microsoft Visual C++ 2005 Redistributable (HKLM-x32\...\{837b34e3-7c30-493c-8f6a-2b0f04e2912c}) (Version: 8.0.59193 - Microsoft Corporation)
Microsoft Visual C++ 2005 Redistributable (HKLM-x32\...\{A49F249F-0C91-497F-86DF-B2585E8E76B7}) (Version: 8.0.50727.42 - Microsoft Corporation)
Microsoft Visual C++ 2005 Redistributable (x64) (HKLM\...\{ad8a2fa1-06e7-4b0d-927d-6e54b3d31028}) (Version: 8.0.61000 - Microsoft Corporation)
Microsoft Visual C++ 2008 ATL Update kb973924 - x64 9.0.30729.4148 (HKLM\...\{EE936C7A-EA40-31D5-9B65-8E3E089C3828}) (Version: 9.0.30729.4148 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - KB2467174 - x64 9.0.30729.5570 (HKLM\...\{8338783A-0968-3B85-AFC7-BAAE0A63DC50}) (Version: 9.0.30729.5570 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - KB2467174 - x86 9.0.30729.5570 (HKLM-x32\...\{86CE85E6-DBAC-3FFD-B977-E4B79F83C909}) (Version: 9.0.30729.5570 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x64 9.0.21022 (HKLM\...\{350AA351-21FA-3270-8B7A-835434E766AD}) (Version: 9.0.21022 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.4148 (HKLM\...\{4B6C7001-C7D6-3710-913E-5BC23FCE91E6}) (Version: 9.0.30729.4148 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.6161 (HKLM\...\{5FCE6D76-F5DC-37AB-B2B8-22AB8CEDB1D4}) (Version: 9.0.30729.6161 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x86 9.0.21022 (HKLM-x32\...\{FF66E9F6-83E7-3A3E-AF14-8DE9A809A6A4}) (Version: 9.0.21022 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x86 9.0.21022.218 (HKLM-x32\...\{E503B4BF-F7BB-3D5F-8BC8-F694B1CFF942}) (Version: 9.0.21022.218 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17 (HKLM-x32\...\{9A25302D-30C0-39D9-BD6F-21E6EC160475}) (Version: 9.0.30729 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.4148 (HKLM-x32\...\{1F1C2DFC-2D24-3E06-BCB8-725134ADF989}) (Version: 9.0.30729.4148 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.6161 (HKLM-x32\...\{9BE518E6-ECC6-35A9-88E4-87755C07200F}) (Version: 9.0.30729.6161 - Microsoft Corporation)
Microsoft Visual C++ 2010 Redistributable - x64 10.0.40219 (HKLM\...\{1D8E6291-B0D5-35EC-8441-6616F567A0F7}) (Version: 10.0.40219 - Microsoft Corporation)
Microsoft Visual C++ 2010 Redistributable - x86 10.0.40219 (HKLM-x32\...\{F0C3E5D1-1ADE-321E-8167-68EF0DE699A5}) (Version: 10.0.40219 - Microsoft Corporation)
Microsoft Visual C++ 2012 Redistributable (x64) - 11.0.61030 (HKLM-x32\...\{ca67548a-5ebe-413a-b50c-4b9ceb6d66c6}) (Version: 11.0.61030.0 - Microsoft Corporation)
Microsoft Visual C++ 2012 Redistributable (x86) - 11.0.61030 (HKLM-x32\...\{33d1fd90-4274-48a1-9bc1-97e33d9c2d6f}) (Version: 11.0.61030.0 - Microsoft Corporation)
Microsoft Visual C++ 2013 Redistributable (x64) - 12.0.30501 (HKLM-x32\...\{050d4fc8-5d48-4b8f-8972-47c82c46020f}) (Version: 12.0.30501.0 - Microsoft Corporation)
Microsoft Visual C++ 2013 Redistributable (x86) - 12.0.30501 (HKLM-x32\...\{f65db027-aff3-4070-886a-0d87064aabb1}) (Version: 12.0.30501.0 - Microsoft Corporation)
Microsoft Visual Studio 2010 Tools for Office Runtime (x64) (HKLM\...\Microsoft Visual Studio 2010 Tools for Office Runtime (x64)) (Version: 10.0.50903 - Microsoft Corporation)
Microsoft WSE 3.0 Runtime (HKLM-x32\...\{E3E71D07-CD27-46CB-8448-16D4FB29AA13}) (Version: 3.0.5305.0 - Microsoft Corp.)
Microsoft Xbox 360 Accessories 1.2 (HKLM\...\{D9C50188-12D5-4D3E-8F00-682346C2AA5F}) (Version: 1.20.146.0 - Microsoft)
Microsoft XNA Framework Redistributable 3.1 (HKLM-x32\...\{19BFDA5D-1FE2-4F25-97F9-1A79DD04EE20}) (Version: 3.1.10527.0 - Microsoft Corporation)
Microsoft XNA Framework Redistributable 4.0 Refresh (HKLM-x32\...\{D69C8EDE-BBC5-436B-8E0E-C5A6D311CF4F}) (Version: 4.0.30901.0 - Microsoft Corporation)
Mozilla Firefox 42.0 (x86 en-GB) (HKLM-x32\...\Mozilla Firefox 42.0 (x86 en-GB)) (Version: 42.0 - Mozilla)
Mozilla Maintenance Service (HKLM-x32\...\MozillaMaintenanceService) (Version: 42.0.0.5780 - Mozilla)
Mumble 1.2.3 (HKLM-x32\...\{B4E343DD-BAAB-4D59-AD9C-DEA0AFE09DF1}) (Version: 1.2.3 - Thorvald Natvig)
Nidhogg (HKLM-x32\...\Steam App 94400) (Version:  - Messhof)
Nokia Connectivity Cable Driver (HKLM\...\{BC4AE628-81A4-4FC6-863A-7A9BA2E2531F}) (Version: 7.1.32.64 - )
NVIDIA 3D Vision Controller Driver 352.65 (HKLM\...\{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.NVIRUSB) (Version: 352.65 - NVIDIA Corporation)
NVIDIA 3D Vision Driver 359.06 (HKLM\...\{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.3DVision) (Version: 359.06 - NVIDIA Corporation)
NVIDIA GeForce Experience 2.7.4.10 (HKLM\...\{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.GFExperience) (Version: 2.7.4.10 - NVIDIA Corporation)
NVIDIA Graphics Driver 359.06 (HKLM\...\{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.Driver) (Version: 359.06 - NVIDIA Corporation)
NVIDIA HD Audio Driver 1.3.34.4 (HKLM\...\{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_HDAudio.Driver) (Version: 1.3.34.4 - NVIDIA Corporation)
NVIDIA PhysX System Software 9.15.0428 (HKLM\...\{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.PhysX) (Version: 9.15.0428 - NVIDIA Corporation)
OpenAL (HKLM-x32\...\OpenAL) (Version:  - )
OpenVPN Tap Adapter 9.0.0.8 (HKLM-x32\...\OpenVPN Tap Adapter) (Version:  - )
Orcs Must Die! 2 (HKLM-x32\...\Steam App 201790) (Version:  - )
Origin (HKLM-x32\...\Origin) (Version: 9.4.20.386 - Electronic Arts, Inc.)
Papers, Please (HKLM-x32\...\Steam App 239030) (Version:  - 3909)
Project Zomboid (remove only) (HKLM-x32\...\ProjectZomboid) (Version:  - )
PVSonyDll (Version: 1.00.0001 - NVIDIA Corporation) Hidden
QuickTime (HKLM-x32\...\{B67BAFBA-4C9F-48FA-9496-933E3B255044}) (Version: 7.74.80.86 - Apple Inc.)
Rayman Legends (HKLM-x32\...\Steam App 242550) (Version:  - )
Renesas Electronics USB 3.0 Host Controller Driver (HKLM-x32\...\InstallShield_{5442DAB8-7177-49E1-8B22-09A049EA5996}) (Version: 2.0.4.0 - Renesas Electronics Corporation)
Renesas Electronics USB 3.0 Host Controller Driver (x32 Version: 2.0.4.0 - Renesas Electronics Corporation) Hidden
Rockstar Games Social Club (HKLM-x32\...\Rockstar Games Social Club) (Version: 1.1.6.1 - Rockstar Games)
S.T.A.L.K.E.R.: Call of Pripyat (HKLM-x32\...\Steam App 41700) (Version:  - GSC Game World)
Scribblenauts Unlimited (HKLM-x32\...\Scribblenauts Unlimited_is1) (Version:  - )
Service Pack 2 for Microsoft Office 2010 (KB2687455) 32-Bit Edition (HKLM-x32\...\{90140000-003D-0000-0000-0000000FF1CE}_Office14.SingleImage_{DE28B448-32E8-4E8F-84F0-A52B21A49B5B}) (Version:  - Microsoft)
SHIELD Streaming (Version: 4.1.0240 - NVIDIA Corporation) Hidden
SHIELD Wireless Controller Driver (Version: 2.7.4.10 - NVIDIA Corporation) Hidden
Sid Meier's Civilization V (HKLM-x32\...\Steam App 8930) (Version:  - 2K Games, Inc.)
SimCity 4 Deluxe (HKLM-x32\...\Steam App 24780) (Version:  - EA - Maxis)
Sir, You Are Being Hunted (HKLM-x32\...\Steam App 242880) (Version:  - )
Skype Click to Call (HKLM-x32\...\{B6CF2967-C81E-40C0-9815-C05774FEF120}) (Version: 5.6.8442 - Skype Technologies S.A.)
Skype™ 7.16 (HKLM-x32\...\{FC965A47-4839-40CA-B618-18F486F042C6}) (Version: 7.16.102 - Skype Technologies S.A.)
Skyrim Script Extender (SKSE) (HKLM-x32\...\Steam App 365720) (Version:  - The SKSE Team)
Smart Technology Programming Software 7.0.27.13 (HKLM\...\{BD90BC1C-115D-47E1-B85C-07AE182C3AB8}) (Version: 7.0.27.13 - Mad Catz)
Space Engineers (HKLM-x32\...\Steam App 244850) (Version:  - )
Spelunky (HKLM-x32\...\Steam App 239350) (Version:  - )
Starbound (HKLM-x32\...\Steam App 211820) (Version:  - )
State of Decay (HKLM-x32\...\Steam App 241540) (Version:  - )
The Elder Scrolls V: Skyrim (HKLM-x32\...\Steam App 72850) (Version:  - Bethesda Game Studios)
The Forest (HKLM-x32\...\Steam App 242760) (Version:  - Endnight Games Ltd)
Tomb Raider (HKLM-x32\...\Steam App 203160) (Version:  - Crystal Dynamics)
Total War: ATTILA (HKLM-x32\...\Steam App 325610) (Version:  - Creative Assembly)
Trials Evolution Gold Edition (HKLM-x32\...\Steam App 220160) (Version:  - RedLynx and Ubisoft Shanghai)
Trials Fusion (HKLM-x32\...\Steam App 245490) (Version:  - RedLynx, in collaboration with  Ubisoft Shanghai, Ubisoft Kiev)
Ubisoft Game Launcher (HKLM-x32\...\{888F1505-C2B3-4FDE-835D-36353EBD4754}) (Version: 1.0.0.0 - UBISOFT)
Uplay (HKLM-x32\...\Uplay) (Version: 4.3 - Ubisoft)
VC80CRTRedist - 8.0.50727.6195 (x32 Version: 1.2.0 - DivX, Inc) Hidden
Ventrilo Client for Windows x64 (HKLM\...\{EEB3F6BB-318D-4CE5-989F-8191FCBFB578}) (Version: 3.0.8.0 - Flagship Industries, Inc.)
Visual Studio 2008 x64 Redistributables (HKLM-x32\...\{FCDBEA60-79F0-4FAE-BBA8-55A26C609A49}) (Version: 10.0.0.2 - AVG Technologies)
Visual Studio 2010 x64 Redistributables (HKLM\...\{21B133D6-5979-47F0-BE1C-F6A6B304693F}) (Version: 13.0.0.1 - AVG Technologies)
Visual Studio 2012 x64 Redistributables (HKLM\...\{8C775E70-A791-4DA8-BCC3-6AB7136F4484}) (Version: 14.0.0.1 - AVG Technologies)
Visual Studio 2012 x86 Redistributables (HKLM-x32\...\{98EFF19A-30AB-4E4B-B943-F06B1C63EBF8}) (Version: 14.0.0.1 - AVG Technologies CZ, s.r.o.)
VLC media player 2.0.0 (HKLM-x32\...\VLC media player) (Version: 2.0.0 - VideoLAN)
Warhammer: End Times - Vermintide (HKLM-x32\...\Steam App 235540) (Version:  - Fatshark)
Winamp (HKLM-x32\...\Winamp) (Version: 5.666  - Nullsoft, Inc)
Windows Live Essentials (HKLM-x32\...\WinLiveSuite) (Version: 15.4.3508.1109 - Microsoft Corporation)
Wings of Prey 1.0.4.1 (HKLM-x32\...\{bd8defa4-19fa-4964-9692-f1112d8a62d9}}_is1) (Version: 1.0.4.1 - Gaijin Entertainment, Corp.)
WinRAR 4.00 (64-bit) (HKLM\...\WinRAR archiver) (Version: 4.00.0 - win.rar GmbH)
Worms Revolution (HKLM-x32\...\Steam App 200170) (Version:  - )
XCom Long War EW Mod version Beta 15f (HKLM-x32\...\{860C3266-65B9-4BF2-937A-1778483046B5}_is1) (Version: Beta 15f - JohnnyLump)
XCOM: Enemy Unknown (HKLM-x32\...\Steam App 200510) (Version:  - Firaxis Games)
Zafehouse Diaries (HKLM-x32\...\GOGPACKZAFEHOUSEDIARIES_is1) (Version: 2.0.0.3 - GOG.com)

==================== Custom CLSID (Whitelisted): ==========================

(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)


==================== Restore Points =========================

03-12-2015 09:00:45 AA11
06-12-2015 11:01:06 Installed AVG 2016
06-12-2015 11:02:20 Installed AVG
10-12-2015 01:12:49 Windows Update

==================== Hosts content: ==========================

(If needed Hosts: directive could be included in the fixlist to reset Hosts.)

2009-07-14 02:34 - 2015-08-08 07:41 - 00002291 ____A C:\Windows\system32\Drivers\etc\hosts

127.0.0.1 0.0.0.0.0
127.0.0.1 0.0.0.0.0
127.0.0.1 0.0.0.0.0
127.0.0.1 0.0.0.0.0
127.0.0.1 0.0.0.0.0
127.0.0.1 0.0.0.0.0
127.0.0.1 0.0.0.0.0
127.0.0.1 0.0.0.0.0
127.0.0.1 0.0.0.0.0
127.0.0.1 m.fr.a2dfp.net
127.0.0.1 mfr.a2dfp.net
127.0.0.1 ad.a8.net
127.0.0.1 asy.a8ww.net
127.0.0.1 static.a-ads.com
127.0.0.1 atlas.aamedia.ro
127.0.0.1 abcstats.com
127.0.0.1 ad4.abradio.cz
127.0.0.1 a.abv.bg
127.0.0.1 adserver.abv.bg
127.0.0.1 adv.abv.bg
127.0.0.1 bimg.abv.bg
127.0.0.1 ca.abv.bg
127.0.0.1 www2.a-counter.kiev.ua
127.0.0.1 track.acclaimnetwork.com
127.0.0.1 accuserveadsystem.com
127.0.0.1 www.accuserveadsystem.com
127.0.0.1 achmedia.com
127.0.0.1 csh.actiondesk.com
127.0.0.1 ads.activepower.net
127.0.0.1 app.activetrail.com

There are 48 more lines.


==================== Scheduled Tasks (Whitelisted) =============

(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)

Task: {025A3BAF-6395-4EAF-B3AC-B93475C62D21} - System32\Tasks\{19AC4625-53F6-4DC4-861D-A61CE3E45365} => pcalua.exe -a C:\Users\euan\Downloads\jxpiinstall.exe -d C:\Users\euan\Downloads
Task: {0C018E8F-A422-4BC4-BCF6-36BB3281C6E4} - System32\Tasks\{0AFF271A-5ADA-44AB-A589-49FE21D9ED72} => pcalua.exe -a "D:\Arma 2\Bohemia Interactive\uninstall.exe" -d "D:\Arma 2\Bohemia Interactive"
Task: {0F1356CE-5FDC-4BBF-92B3-6090D92C9F7C} - System32\Tasks\{0612C04D-1622-4198-9DEE-6B343C7C82D1} => pcalua.exe -a C:\Users\euan\Downloads\Saitek_Cyborg_Evo_SD6_64.exe -d C:\Users\euan\Downloads
Task: {3599726E-3778-4ABE-BD66-B07C74A18FE0} - System32\Tasks\{971BB27B-2149-4E59-B744-2DEC1C2AF979} => pcalua.exe -a F:\SETUP.EXE -d F:\
Task: {574D6A07-DE52-4EA3-8FE9-E335C03639AF} - System32\Tasks\Adobe Flash Player Updater => C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe [2015-12-09] (Adobe Systems Incorporated)
Task: {90D510F7-2131-48AA-BB17-1D7EF3DCA1A2} - System32\Tasks\{2B469A94-5495-49C2-B6B8-9B6BEB4AF2AF} => C:\Program Files (x86)\Skype\\Phone\Skype.exe [2015-12-08] (Skype Technologies S.A.)
Task: {9CDDEC9B-A871-4B8F-A532-3573B1AF2605} - System32\Tasks\{21CBD1CC-542D-4E27-8993-C473F2C81696} => pcalua.exe -a "C:\Windows\CSI New York\uninstall.exe" -c "/U:C:\Program Files (x86)\CSI New York\Uninstall\uninstall.xml"
Task: {B114404E-E6B1-4914-AC45-5D452A2EACA2} - System32\Tasks\{E068DCF6-30B7-410F-954D-BB8822E93197} => pcalua.exe -a "C:\Downloads\World Of Goo game [ENG] [PC]\WorldOfGooSetup.exe" -d "C:\Downloads\World Of Goo game [ENG] [PC]"
Task: {C31E27F4-8117-4EBC-B199-B74D7FAA988A} - System32\Tasks\Adobe Acrobat Update Task => C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe [2015-10-28] (Adobe Systems Incorporated)

(If an entry is included in the fixlist, the task (.job) file will be moved. The file which is running by the task will not be moved.)

Task: C:\Windows\Tasks\Adobe Flash Player Updater.job => C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe

==================== Shortcuts =============================

(The entries could be listed to be restored or removed.)

==================== Loaded Modules (Whitelisted) ==============

2012-08-19 00:07 - 2015-11-24 18:40 - 00116344 _____ () C:\Program Files\NVIDIA Corporation\Display\NvSmartMax64.dll
2015-07-16 08:50 - 2015-11-24 23:10 - 00012080 _____ () C:\Program Files (x86)\NVIDIA Corporation\Update Core\detoured.dll
2015-12-06 10:54 - 2015-12-06 10:34 - 40500224 _____ () C:\Program Files (x86)\AVG\UiDll\2171\libcef.dll

==================== Alternate Data Streams (Whitelisted) =========

(If an entry is included in the fixlist, only the ADS will be removed.)


==================== Safe Mode (Whitelisted) ===================

(If an entry is included in the fixlist, it will be removed from the registry. The "AlternateShell" will be restored.)

HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\Hamachi2Svc => ""="Service"

==================== EXE Association (Whitelisted) ===============

(If an entry is included in the fixlist, the registry item will be restored to default or removed.)


==================== Internet Explorer trusted/restricted ===============

(If an entry is included in the fixlist, it will be removed from the registry.)

IE trusted site: HKU\S-1-5-21-1126527562-1434389470-3061596616-1001\...\clonewarsadventures.com -> clonewarsadventures.com
IE trusted site: HKU\S-1-5-21-1126527562-1434389470-3061596616-1001\...\freerealms.com -> freerealms.com
IE trusted site: HKU\S-1-5-21-1126527562-1434389470-3061596616-1001\...\soe.com -> soe.com
IE trusted site: HKU\S-1-5-21-1126527562-1434389470-3061596616-1001\...\sony.com -> sony.com

==================== Other Areas ============================

(Currently there is no automatic fix for this section.)

HKU\S-1-5-21-1126527562-1434389470-3061596616-1001\Control Panel\Desktop\\Wallpaper -> C:\Users\euan\AppData\Roaming\Microsoft\Windows\Themes\TranscodedWallpaper.jpg
DNS Servers: 192.168.2.1
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\System => (ConsentPromptBehaviorAdmin: 5) (ConsentPromptBehaviorUser: 3) (EnableLUA: 1)
Windows Firewall is enabled.

==================== MSCONFIG/TASK MANAGER disabled items ==

(Currently there is no automatic fix for this section.)


==================== FirewallRules (Whitelisted) ===============

(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)

FirewallRules: [{7CB0DADC-1F4D-41D8-8F40-5FFE10A11051}] => (Allow) D:\Valve\Steam\Steam.exe
FirewallRules: [{E3473162-F0EE-4012-A6D4-995AE0D929F7}] => (Allow) D:\Valve\Steam\Steam.exe
FirewallRules: [TCP Query User{2410BBD1-EA21-495D-BDD3-B9F4ECF3B0AD}C:\program files (x86)\xfire\xfire.exe] => (Allow) C:\program files (x86)\xfire\xfire.exe
FirewallRules: [UDP Query User{4694F0C4-D9E1-43DA-897F-01FFDB5424F6}C:\program files (x86)\xfire\xfire.exe] => (Allow) C:\program files (x86)\xfire\xfire.exe
FirewallRules: [{F1F8F754-C1DB-4F28-A1CC-3CA06869FE8D}] => (Allow) C:\Program Files\Ventrilo\Ventrilo.exe
FirewallRules: [{7254A309-A235-44F3-A807-56D062D8635F}] => (Allow) C:\Program Files\Ventrilo\Ventrilo.exe
FirewallRules: [TCP Query User{551B093F-D64F-4FFC-BDC1-CA3C2F238397}D:\valve\steam\steamapps\common\red faction guerrilla\rfg.exe] => (Allow) D:\valve\steam\steamapps\common\red faction guerrilla\rfg.exe
FirewallRules: [UDP Query User{33EC5EDB-4A1B-4418-85A7-5E8DCCBA8759}D:\valve\steam\steamapps\common\red faction guerrilla\rfg.exe] => (Allow) D:\valve\steam\steamapps\common\red faction guerrilla\rfg.exe
FirewallRules: [TCP Query User{6AFF74C4-1196-4157-8699-E2C4EE1ABC06}D:\valve\steam\steamapps\common\company of heroes\relicdownloader\relicdownloader.exe] => (Allow) D:\valve\steam\steamapps\common\company of heroes\relicdownloader\relicdownloader.exe
FirewallRules: [UDP Query User{BEA6247D-B3C4-4432-85E5-E875A350FF7C}D:\valve\steam\steamapps\common\company of heroes\relicdownloader\relicdownloader.exe] => (Allow) D:\valve\steam\steamapps\common\company of heroes\relicdownloader\relicdownloader.exe
FirewallRules: [TCP Query User{288BF365-3483-4EC6-8C1D-A2B6D438D0B7}D:\valve\steam\steamapps\zim_zum\team fortress 2\hl2.exe] => (Allow) D:\valve\steam\steamapps\zim_zum\team fortress 2\hl2.exe
FirewallRules: [UDP Query User{09473F32-7888-4DFA-80AF-F1458FFBDFA4}D:\valve\steam\steamapps\zim_zum\team fortress 2\hl2.exe] => (Allow) D:\valve\steam\steamapps\zim_zum\team fortress 2\hl2.exe
FirewallRules: [TCP Query User{D7CB32B2-2A80-4F80-98B6-9AB26C4806FC}D:\valve\steam\steamapps\common\grand theft auto iv episodes from liberty city\eflc\eflc.exe] => (Allow) D:\valve\steam\steamapps\common\grand theft auto iv episodes from liberty city\eflc\eflc.exe
FirewallRules: [UDP Query User{655EE5BD-D425-4EEA-BB4F-6F6967DB90B3}D:\valve\steam\steamapps\common\grand theft auto iv episodes from liberty city\eflc\eflc.exe] => (Allow) D:\valve\steam\steamapps\common\grand theft auto iv episodes from liberty city\eflc\eflc.exe
FirewallRules: [{CA249695-7A15-41AA-B3EE-9AD73B19C6FA}] => (Allow) C:\Program Files (x86)\Windows Live\Contacts\wlcomm.exe
FirewallRules: [{42C0E000-6801-4854-ABC0-169187605549}] => (Allow) LPort=2869
FirewallRules: [{701D546B-6F84-4CBC-8D5E-CCA242E56B99}] => (Allow) LPort=1900
FirewallRules: [{35F00171-BFE4-4637-9FB1-A7A20E25E924}] => (Allow) C:\Program Files (x86)\Windows Live\Messenger\msnmsgr.exe
FirewallRules: [{36AC5ED2-C04D-48C4-A281-D60985B115E9}] => (Allow) C:\Program Files (x86)\Microsoft LifeCam\LifeCam.exe
FirewallRules: [{5F803B37-1B14-41A4-AA30-0164073CD74A}] => (Allow) C:\Program Files (x86)\Microsoft LifeCam\LifeCam.exe
FirewallRules: [{5505E43E-3522-402A-A3D2-76D256C0217B}] => (Allow) C:\Program Files (x86)\Microsoft LifeCam\LifeEnC2.exe
FirewallRules: [{C348857C-8129-4D3C-9642-F2B725DF8548}] => (Allow) C:\Program Files (x86)\Microsoft LifeCam\LifeEnC2.exe
FirewallRules: [{C934EE71-8BD4-4B7E-94E6-6DFC35BDACB9}] => (Allow) C:\Program Files (x86)\Microsoft LifeCam\LifeExp.exe
FirewallRules: [{A3677D03-E4B3-4FE2-8C9B-1B8DD88128A1}] => (Allow) C:\Program Files (x86)\Microsoft LifeCam\LifeExp.exe
FirewallRules: [{C0143A55-57D5-4ABB-8092-3CA27612EDF6}] => (Allow) C:\Program Files (x86)\Microsoft LifeCam\LifeTray.exe
FirewallRules: [{93D1B3EA-8522-44B0-9721-E7ADCBEB0C4A}] => (Allow) C:\Program Files (x86)\Microsoft LifeCam\LifeTray.exe
FirewallRules: [{FB24E625-3AF8-4F29-88BB-DC2C87EB43EB}] => (Allow) C:\Program Files (x86)\bitComposer Games\S.T.A.L.K.E.R. - Call of Pripyat\bin\xrEngine.exe
FirewallRules: [{BAC6F4D6-D5FD-4F5A-BF31-435308560A7B}] => (Allow) C:\Program Files (x86)\bitComposer Games\S.T.A.L.K.E.R. - Call of Pripyat\bin\xrEngine.exe
FirewallRules: [{8887BFEE-262F-46F3-B10F-7D18449851C9}] => (Allow) C:\Program Files (x86)\bitComposer Games\S.T.A.L.K.E.R. - Call of Pripyat\bin\dedicated\xrEngine.exe
FirewallRules: [{ECF3F0F1-6F46-4ED5-A093-859657DDCCD2}] => (Allow) C:\Program Files (x86)\bitComposer Games\S.T.A.L.K.E.R. - Call of Pripyat\bin\dedicated\xrEngine.exe
FirewallRules: [TCP Query User{0F8CEA6A-19F9-437B-8F64-A9DFC81F72BE}D:\valve\steam\steamapps\common\wings of prey\acess.exe] => (Allow) D:\valve\steam\steamapps\common\wings of prey\acess.exe
FirewallRules: [UDP Query User{16A3D2E9-FD3F-40DE-9ECA-DD400FD80AFA}D:\valve\steam\steamapps\common\wings of prey\acess.exe] => (Allow) D:\valve\steam\steamapps\common\wings of prey\acess.exe
FirewallRules: [TCP Query User{5D548390-EEDF-46E1-BC49-6F80467430A8}C:\users\euan\downloads\wings_of_prey_update_1_0_3_8_beta.exe] => (Allow) C:\users\euan\downloads\wings_of_prey_update_1_0_3_8_beta.exe
FirewallRules: [UDP Query User{EBB8851E-90D1-4FF6-8DCE-060A3EFC675F}C:\users\euan\downloads\wings_of_prey_update_1_0_3_8_beta.exe] => (Allow) C:\users\euan\downloads\wings_of_prey_update_1_0_3_8_beta.exe
FirewallRules: [{E8FD2710-4602-4CF5-94A6-6A848A1D8F84}] => (Allow) C:\Program Files (x86)\Skype\Phone\Skype.exe
FirewallRules: [{F3AC6AF5-0C05-4363-8230-06B4646AD848}] => (Allow) C:\Program Files (x86)\AVG\AVG10\avgmfapx.exe
FirewallRules: [{D0263052-4185-4392-A312-7E0F6414095C}] => (Allow) C:\Program Files (x86)\AVG\AVG10\avgmfapx.exe
FirewallRules: [TCP Query User{824E7232-5643-44FC-BAB8-7036DA8D742B}C:\users\euan\downloads\wings_of_prey_update_to_1_0_3_9_beta.exe] => (Allow) C:\users\euan\downloads\wings_of_prey_update_to_1_0_3_9_beta.exe
FirewallRules: [UDP Query User{0DFF2C9B-9CA8-4FD9-A96B-DCDB509962DC}C:\users\euan\downloads\wings_of_prey_update_to_1_0_3_9_beta.exe] => (Allow) C:\users\euan\downloads\wings_of_prey_update_to_1_0_3_9_beta.exe
FirewallRules: [TCP Query User{72C18C2B-4FDE-40E1-BCE6-58ABC5B9CE30}D:\valve\steam\steamapps\common\sid meier's civilization v\civilizationv_dx11.exe] => (Allow) D:\valve\steam\steamapps\common\sid meier's civilization v\civilizationv_dx11.exe
FirewallRules: [UDP Query User{8EC191C1-A70C-438E-AEF3-F8CD33AFE8AB}D:\valve\steam\steamapps\common\sid meier's civilization v\civilizationv_dx11.exe] => (Allow) D:\valve\steam\steamapps\common\sid meier's civilization v\civilizationv_dx11.exe
FirewallRules: [TCP Query User{DEECE4E6-2921-48A8-AC0C-D7AFA36ADCC9}D:\valve\steam\steamapps\common\terraria\terrariaserver.exe] => (Allow) D:\valve\steam\steamapps\common\terraria\terrariaserver.exe
FirewallRules: [UDP Query User{C79A3A51-E545-438E-A673-2BE0568264B2}D:\valve\steam\steamapps\common\terraria\terrariaserver.exe] => (Allow) D:\valve\steam\steamapps\common\terraria\terrariaserver.exe
FirewallRules: [{3FD9FD2D-28E9-4FA1-8BD0-ED94D2D288D9}] => (Allow) C:\Program Files (x86)\BitComet\BitComet.exe
FirewallRules: [{F87E55CD-0E4A-4C9C-9555-BCEF3C1716A3}] => (Allow) C:\Program Files (x86)\BitComet\BitComet.exe
FirewallRules: [TCP Query User{F68956F3-5A31-43AF-BC6E-ABFAFC3EC448}C:\users\euan\downloads\wings_of_prey_update_to_1_0_4_0_beta.exe] => (Allow) C:\users\euan\downloads\wings_of_prey_update_to_1_0_4_0_beta.exe
FirewallRules: [UDP Query User{2D382935-E814-4A36-BB3C-BD5D3B2C7376}C:\users\euan\downloads\wings_of_prey_update_to_1_0_4_0_beta.exe] => (Allow) C:\users\euan\downloads\wings_of_prey_update_to_1_0_4_0_beta.exe
FirewallRules: [TCP Query User{70C35C53-E994-404A-9449-59727E8AC424}C:\users\euan\downloads\wings_of_prey_update_from_1_0_3_6_to_1_0_4_1.exe] => (Allow) C:\users\euan\downloads\wings_of_prey_update_from_1_0_3_6_to_1_0_4_1.exe
FirewallRules: [UDP Query User{B75B1186-00F9-43BF-BD53-B61DE56B97C8}C:\users\euan\downloads\wings_of_prey_update_from_1_0_3_6_to_1_0_4_1.exe] => (Allow) C:\users\euan\downloads\wings_of_prey_update_from_1_0_3_6_to_1_0_4_1.exe
FirewallRules: [TCP Query User{767F4C05-3BD0-4FBA-B99B-77DF916E850B}D:\valve\steam\steamapps\common\shattered_horizon\server_exe\sh_server.exe] => (Allow) D:\valve\steam\steamapps\common\shattered_horizon\server_exe\sh_server.exe
FirewallRules: [UDP Query User{542341D4-7AF4-4FFB-9F3C-A39DF61E64A1}D:\valve\steam\steamapps\common\shattered_horizon\server_exe\sh_server.exe] => (Allow) D:\valve\steam\steamapps\common\shattered_horizon\server_exe\sh_server.exe
FirewallRules: [{26C0B208-5D9B-46FE-8598-5F11B4F30A38}] => (Allow) C:\Windows\SysWOW64\PnkBstrA.exe
FirewallRules: [{EE04E385-2FE2-4E81-AC95-E5A45AD36C39}] => (Allow) C:\Windows\SysWOW64\PnkBstrA.exe
FirewallRules: [{C5BCCFC0-F67D-4DD2-B371-3136F8E4A359}] => (Allow) C:\Windows\SysWOW64\PnkBstrB.exe
FirewallRules: [{65E5413F-FB39-45E2-8B6E-C74D9C171C60}] => (Allow) C:\Windows\SysWOW64\PnkBstrB.exe
FirewallRules: [{465486FF-8C2B-4AAD-80EB-916CC6FE1FD6}] => (Allow) C:\Program Files\BitComet\BitComet.exe
FirewallRules: [{54106B49-C597-44B2-BC7B-B47291BF5249}] => (Allow) C:\Program Files\BitComet\BitComet.exe
FirewallRules: [{4B5EB306-92E4-4D1B-9D85-F46F240935EC}] => (Allow) D:\Valve\Steam\SteamApps\common\peggle deluxe\Peggle.exe
FirewallRules: [{64FDCC1E-1C0C-4516-B180-2170F59DB7B3}] => (Allow) D:\Valve\Steam\SteamApps\common\peggle deluxe\Peggle.exe
FirewallRules: [{E5340E22-5976-49E5-8791-4C2723AD0A70}] => (Allow) D:\Valve\Steam\SteamApps\common\peggle extreme\PeggleExtreme.exe
FirewallRules: [{2963551F-F59E-403B-981A-033DA67AC19D}] => (Allow) D:\Valve\Steam\SteamApps\common\peggle extreme\PeggleExtreme.exe
FirewallRules: [{AFE11FF2-7D0D-449B-8904-EB89368AA3F3}] => (Allow) D:\Valve\Steam\SteamApps\common\sid meier's civilization iv\Civilization4.exe
FirewallRules: [{65974C13-761D-4383-9B5E-CC8C510F549B}] => (Allow) D:\Valve\Steam\SteamApps\common\sid meier's civilization iv\Civilization4.exe
FirewallRules: [{73B8D33C-9D91-4053-8F35-50887840353D}] => (Allow) D:\Valve\Steam\SteamApps\common\titan quest\help.htm
FirewallRules: [{7D3607DE-3384-4647-ACB0-90A42118B32E}] => (Allow) D:\Valve\Steam\SteamApps\common\titan quest\help.htm
FirewallRules: [{01E733A4-BDE5-422A-B949-0A5FCBFCCF4E}] => (Allow) D:\Valve\Steam\SteamApps\common\titan quest immortal throne\help.htm
FirewallRules: [{0D92E4A8-2DF7-435C-8B7A-065A85F85CAE}] => (Allow) D:\Valve\Steam\SteamApps\common\titan quest immortal throne\help.htm
FirewallRules: [{298FA977-BA7B-49A4-93FD-1DF8D268A32C}] => (Allow) D:\Valve\Steam\SteamApps\common\thief deadly shadows\System\runme.exe
FirewallRules: [{508A99B2-2FFC-4F92-913A-BFA7AD43D390}] => (Allow) D:\Valve\Steam\SteamApps\common\thief deadly shadows\System\runme.exe
FirewallRules: [{BC8B93AF-6D48-42E0-B591-71471C9A90E8}] => (Allow) D:\Valve\Steam\SteamApps\common\x-com terror from the deep\runme.exe
FirewallRules: [{9E5CACC9-AABE-48B8-8649-AF2B3F74E3B6}] => (Allow) D:\Valve\Steam\SteamApps\common\x-com terror from the deep\runme.exe
FirewallRules: [{3DE5CF12-F48B-43DE-9200-7CACBF1601E9}] => (Allow) D:\Valve\Steam\SteamApps\common\xcom apocalypse\dosbox.exe
FirewallRules: [{94AF4A0C-F781-42CB-896F-2A36BCF604F2}] => (Allow) D:\Valve\Steam\SteamApps\common\xcom apocalypse\dosbox.exe
FirewallRules: [{1A7A28D3-4115-49B6-A35E-B8A45A464C89}] => (Allow) D:\Valve\Steam\SteamApps\common\xcom ufo defense\dosbox.exe
FirewallRules: [{FABC1AFC-EA00-41BA-A761-D184BEE4352A}] => (Allow) D:\Valve\Steam\SteamApps\common\xcom ufo defense\dosbox.exe
FirewallRules: [{132181C0-B6F2-4B8B-94F3-CF7D2BB463E5}] => (Allow) D:\Valve\Steam\SteamApps\common\sid meier's civilization iv beyond the sword\Beyond the Sword\Civ4BeyondSword.exe
FirewallRules: [{2B62C009-D43F-46F2-B914-4BC6CCE28B5B}] => (Allow) D:\Valve\Steam\SteamApps\common\sid meier's civilization iv beyond the sword\Beyond the Sword\Civ4BeyondSword.exe
FirewallRules: [{ED8F1F32-B59A-4777-9D01-5D0A7AFC8363}] => (Allow) D:\Valve\Steam\SteamApps\common\freedom force\fforce.exe
FirewallRules: [{97607FDA-8853-4103-B337-9A24C5085154}] => (Allow) D:\Valve\Steam\SteamApps\common\freedom force\fforce.exe
FirewallRules: [{6A5ADDEB-60BC-4D29-91CB-F6AFAE3A61DB}] => (Allow) D:\Valve\Steam\SteamApps\common\freedom force vs. the 3rd reich\ffvt3r.exe
FirewallRules: [{67A221B6-E2A7-44C0-BFDD-AC124F14B317}] => (Allow) D:\Valve\Steam\SteamApps\common\freedom force vs. the 3rd reich\ffvt3r.exe
FirewallRules: [{192A8AE7-A7E8-422F-A093-EFE082B1F399}] => (Allow) D:\Valve\Steam\SteamApps\common\unreal tournament 3\Binaries\UT3.exe
FirewallRules: [{09BC92D6-5C9E-4413-A971-7EA5E5FFB274}] => (Allow) D:\Valve\Steam\SteamApps\common\unreal tournament 3\Binaries\UT3.exe
FirewallRules: [{D433F7EC-B987-4E92-BCBF-90FB84C56084}] => (Allow) D:\Valve\Steam\SteamApps\common\spore\runme.exe
FirewallRules: [{BEDADE33-E292-4B99-90D2-80F11BC53CCD}] => (Allow) D:\Valve\Steam\SteamApps\common\spore\runme.exe
FirewallRules: [{4624F67A-E8F1-43BF-BC47-E6F35B75737D}] => (Allow) D:\Valve\Steam\SteamApps\common\spore\Support\EA Help\Electronic_Arts_Technical_Support.htm
FirewallRules: [{DBC05A9A-8882-4EB2-8F67-6DD95F5380A9}] => (Allow) D:\Valve\Steam\SteamApps\common\spore\Support\EA Help\Electronic_Arts_Technical_Support.htm
FirewallRules: [{CFF9A1AC-BC34-4AF8-BF38-F6B05B2C6E70}] => (Allow) D:\Valve\Steam\SteamApps\common\shattered_horizon\client_exe\shattered_horizon.exe
FirewallRules: [{1E8FBBF1-F399-4E4D-9DFC-C209FDB0CD7C}] => (Allow) D:\Valve\Steam\SteamApps\common\shattered_horizon\client_exe\shattered_horizon.exe
FirewallRules: [{FF034307-5653-41B1-9A4D-07B493D56836}] => (Allow) D:\Valve\Steam\SteamApps\common\far cry 2\bin\FarCry2.exe
FirewallRules: [{A409D6BB-E6B4-4461-8311-A21F5F021C20}] => (Allow) D:\Valve\Steam\SteamApps\common\far cry 2\bin\FarCry2.exe
FirewallRules: [{A0094A60-8E85-4B29-B40C-834C0E415332}] => (Allow) D:\Valve\Steam\SteamApps\common\far cry 2\bin\FC2Editor.exe
FirewallRules: [{A964A146-3F1E-4C08-A4D6-35F55EDD0AD6}] => (Allow) D:\Valve\Steam\SteamApps\common\far cry 2\bin\FC2Editor.exe
FirewallRules: [{7EA14A1A-C286-47CE-B28C-1F2B0D92B4A4}] => (Allow) D:\Valve\Steam\SteamApps\common\far cry 2\bin\FC2BenchmarkTool.exe
FirewallRules: [{B7E7B7A5-7218-4486-A18E-B866FF248852}] => (Allow) D:\Valve\Steam\SteamApps\common\far cry 2\bin\FC2BenchmarkTool.exe
FirewallRules: [{10FDDA34-DAB3-4EE4-8C79-B57460446577}] => (Allow) D:\Valve\Steam\SteamApps\common\far cry 2\bin\FC2ServerLauncher.exe
FirewallRules: [{F5065462-D355-4202-86C5-81426D2AAE33}] => (Allow) D:\Valve\Steam\SteamApps\common\far cry 2\bin\FC2ServerLauncher.exe
FirewallRules: [{03E7C349-E110-4FAE-88F3-85A7EA60EFB7}] => (Allow) D:\Valve\Steam\SteamApps\common\company of heroes\RelicCOH.exe
FirewallRules: [{124758A8-BAE9-470F-99A6-4D3FE6BA8927}] => (Allow) D:\Valve\Steam\SteamApps\common\company of heroes\RelicCOH.exe
FirewallRules: [{E60471A2-62DC-492C-B679-EEB07BBFF2DB}] => (Allow) D:\Valve\Steam\SteamApps\common\dawn of war 2\DOW2.exe
FirewallRules: [{C259F97E-DB07-4FF5-A148-7EFF389CAA0C}] => (Allow) D:\Valve\Steam\SteamApps\common\dawn of war 2\DOW2.exe
FirewallRules: [{79872562-BF4D-4730-969F-E5514676A1E4}] => (Allow) D:\Valve\Steam\SteamApps\common\battlefield bad company 2\BFBC2Game.exe
FirewallRules: [{A9AAEE28-15F5-4011-96A7-D2DF2F40FFA8}] => (Allow) D:\Valve\Steam\SteamApps\common\battlefield bad company 2\BFBC2Game.exe
FirewallRules: [{A78E509C-1E6F-454F-9E45-C099E8E8B668}] => (Allow) D:\Valve\Steam\SteamApps\common\battlefield bad company 2\Support\EA Help\Electronic_Arts_Technical_Support.htm
FirewallRules: [{443BC0EC-8037-42DE-B755-3E7D25CDA439}] => (Allow) D:\Valve\Steam\SteamApps\common\battlefield bad company 2\Support\EA Help\Electronic_Arts_Technical_Support.htm
FirewallRules: [{D252DB97-F5CE-4162-9A3A-2E358EDF0EE8}] => (Allow) D:\Valve\Steam\SteamApps\common\batman arkham asylum\Binaries\BmLauncher.exe
FirewallRules: [{E6473E53-D881-4FB6-B938-8198D8A6A022}] => (Allow) D:\Valve\Steam\SteamApps\common\batman arkham asylum\Binaries\BmLauncher.exe
FirewallRules: [{6A3E6DBE-F725-43C1-9A85-28F8F3B22AF2}] => (Allow) D:\Valve\Steam\SteamApps\common\ufo extraterrestrials gold\UFO_ET.exe
FirewallRules: [{5AEF7D70-662F-440B-9DA4-E4C84C10F2C8}] => (Allow) D:\Valve\Steam\SteamApps\common\ufo extraterrestrials gold\UFO_ET.exe
FirewallRules: [{69A83AE5-4914-4CAB-8990-3CEC1116EF22}] => (Allow) D:\Valve\Steam\SteamApps\common\amnesia the dark descent\Launcher.exe
FirewallRules: [{F49CA083-48D0-447D-BF4C-510C2E121AA3}] => (Allow) D:\Valve\Steam\SteamApps\common\amnesia the dark descent\Launcher.exe
FirewallRules: [{4FAE34D0-093F-4D94-A19E-7FFF1841B8F5}] => (Allow) D:\Valve\Steam\SteamApps\common\tropico 3\Tropico3.exe
FirewallRules: [{995189CD-6009-417E-95A3-201B48D6DD9C}] => (Allow) D:\Valve\Steam\SteamApps\common\tropico 3\Tropico3.exe
FirewallRules: [{7DFE9329-B09D-4CC3-8FF6-DDDDAB2D527C}] => (Allow) D:\Valve\Steam\SteamApps\common\age of wonders shadow magic\Readme.html
FirewallRules: [{EA209068-75A6-4CAA-9FCE-8D7F6CFDFC98}] => (Allow) D:\Valve\Steam\SteamApps\common\age of wonders shadow magic\Readme.html
FirewallRules: [{1828FB76-2432-429F-B274-8957D6CCB51B}] => (Allow) D:\Valve\Steam\SteamApps\common\age of wonders shadow magic\QuickStart.pdf
FirewallRules: [{230CF9A2-F58E-4F97-9610-8326B5D664B6}] => (Allow) D:\Valve\Steam\SteamApps\common\age of wonders shadow magic\QuickStart.pdf
FirewallRules: [{5D842F53-D24C-4DD8-AEE1-5FC828FBAA04}] => (Allow) D:\Valve\Steam\SteamApps\common\saints row the third\saintsrowthethird.exe
FirewallRules: [{D9AA5A24-1285-46B9-AEED-07AF784002B7}] => (Allow) D:\Valve\Steam\SteamApps\common\saints row the third\saintsrowthethird.exe
FirewallRules: [{E260154D-DB60-456D-9499-CCC7EABCB30B}] => (Allow) D:\Valve\Steam\SteamApps\common\saints row the third\saintsrowthethird_dx11.exe
FirewallRules: [{B1D5863D-BC99-4110-91D2-9602F19015E9}] => (Allow) D:\Valve\Steam\SteamApps\common\saints row the third\saintsrowthethird_dx11.exe
FirewallRules: [{30F74B31-CB29-4AE9-B87B-C2F89AB4D06F}] => (Allow) D:\Valve\Steam\SteamApps\common\universe sandbox\Universe Sandbox.exe
FirewallRules: [{0FEDC5D2-D756-409A-B3EB-EEFC7BE4519B}] => (Allow) D:\Valve\Steam\SteamApps\common\universe sandbox\Universe Sandbox.exe
FirewallRules: [{59CE6C18-DB9B-4A8E-B0E5-21BF64C4A03E}] => (Allow) D:\Valve\Steam\SteamApps\common\arma 2 operation arrowhead\DLCsetup\BAF\datacachepreprocessor.exe
FirewallRules: [{C223E3B1-6FF6-441A-A2C0-AB89C59A7413}] => (Allow) D:\Valve\Steam\SteamApps\common\arma 2 operation arrowhead\DLCsetup\BAF\datacachepreprocessor.exe
FirewallRules: [{DD93E3E1-B603-40C8-8EDF-CC86F293693D}] => (Allow) D:\Valve\Steam\SteamApps\common\warhammer 40,000 space marine\SpaceMarine.exe
FirewallRules: [{3BFF9118-3947-45E0-9209-7E8E4DEDADA6}] => (Allow) D:\Valve\Steam\SteamApps\common\warhammer 40,000 space marine\SpaceMarine.exe
FirewallRules: [TCP Query User{96ADD1C7-D73C-4B5A-B009-1E27F4F39578}C:\program files (x86)\electronic arts\eadm\core.exe] => (Allow) C:\program files (x86)\electronic arts\eadm\core.exe
FirewallRules: [UDP Query User{9F542583-51A2-4B5D-9A5B-06A9C615A0CD}C:\program files (x86)\electronic arts\eadm\core.exe] => (Allow) C:\program files (x86)\electronic arts\eadm\core.exe
FirewallRules: [TCP Query User{A2F96CC4-6AF7-4D3A-9E94-AFDD75631A32}C:\program files (x86)\electronic arts\eadm\core.exe] => (Allow) C:\program files (x86)\electronic arts\eadm\core.exe
FirewallRules: [UDP Query User{A778DF2E-9C25-4343-A6D5-30D0842DC352}C:\program files (x86)\electronic arts\eadm\core.exe] => (Allow) C:\program files (x86)\electronic arts\eadm\core.exe
FirewallRules: [TCP Query User{D0B6D820-1752-4565-A2D1-0CCEFA123CA6}D:\dead space\dead space.exe] => (Allow) D:\dead space\dead space.exe
FirewallRules: [UDP Query User{28E3C930-3FE0-4311-BA20-1FAC633E4F07}D:\dead space\dead space.exe] => (Allow) D:\dead space\dead space.exe
FirewallRules: [{7EDC2F12-5D4B-4F37-A829-C5E43E7D6A47}] => (Allow) D:\Valve\Steam\SteamApps\common\blood bowl legendary edition\BB_LE.exe
FirewallRules: [{1CD9DBBB-1568-44DF-8F8A-DE6E965AE8EC}] => (Allow) D:\Valve\Steam\SteamApps\common\blood bowl legendary edition\BB_LE.exe
FirewallRules: [{B704AE76-4A63-494D-BD67-DE322C6B71AD}] => (Allow) D:\Valve\Steam\SteamApps\common\sid meier's pirates!\Pirates!.exe
FirewallRules: [{385DC76B-6726-4E8D-AD4E-212628F8C603}] => (Allow) D:\Valve\Steam\SteamApps\common\sid meier's pirates!\Pirates!.exe
FirewallRules: [{44947184-8F31-4A45-8662-FEC3655AE93F}] => (Allow) D:\Valve\Steam\SteamApps\common\alien swarm\srcds.exe
FirewallRules: [{40FA80A1-2BA3-4736-81CA-C26B043820FE}] => (Allow) D:\Valve\Steam\SteamApps\common\alien swarm\srcds.exe
FirewallRules: [TCP Query User{B4772E6B-ECE8-4ABC-B972-A63DE961BCBC}D:\dragon age origins\dragon age\bin_ship\daorigins.exe] => (Allow) D:\dragon age origins\dragon age\bin_ship\daorigins.exe
FirewallRules: [UDP Query User{CDC9E1F3-4509-4C7C-9059-F3EACAA8E754}D:\dragon age origins\dragon age\bin_ship\daorigins.exe] => (Allow) D:\dragon age origins\dragon age\bin_ship\daorigins.exe
FirewallRules: [{B215F547-E111-4F1E-9A50-89353A085CD0}] => (Allow) D:\Valve\Steam\SteamApps\common\jabia\JaggedAllianceBIA.exe
FirewallRules: [{CC7011CA-1706-44DD-929A-D5407762AF71}] => (Allow) D:\Valve\Steam\SteamApps\common\jabia\JaggedAllianceBIA.exe
FirewallRules: [{D344E8F3-9CA1-4D45-9B95-FBC97C8A7F54}] => (Allow) C:\Program Files (x86)\AVG\AVG2012\avgmfapx.exe
FirewallRules: [{8CA95400-1AC6-4072-B5E1-4EF26D420572}] => (Allow) C:\Program Files (x86)\AVG\AVG2012\avgmfapx.exe
FirewallRules: [{B0B8E580-3CB7-46E2-920D-D9326BD18753}] => (Allow) D:\Valve\Steam\SteamApps\common\from dust\From_Dust.exe
FirewallRules: [{B476EA4D-9DE5-4C12-A130-5B93348EBD3E}] => (Allow) D:\Valve\Steam\SteamApps\common\from dust\From_Dust.exe
FirewallRules: [{E9E8F9C5-0488-46A0-8215-654D14FDED75}] => (Allow) C:\Program Files (x86)\Ubisoft\Ubisoft Game Launcher\UbisoftGameLauncher.exe
FirewallRules: [{1C7B42C4-4FC3-4F8E-A4EC-4C81F776C301}] => (Allow) C:\Program Files (x86)\Ubisoft\Ubisoft Game Launcher\UbisoftGameLauncher.exe
FirewallRules: [{97E706F2-1949-41FF-8174-1A27FFE889BA}] => (Allow) D:\Valve\Steam\SteamApps\common\dead island\DeadIslandGame.exe
FirewallRules: [{8CA843B1-6370-4B76-B9F6-80822CE2C0D1}] => (Allow) D:\Valve\Steam\SteamApps\common\dead island\DeadIslandGame.exe
FirewallRules: [{59A94C4F-DC63-4B42-865C-B305D17D276F}] => (Allow) D:\Valve\Steam\SteamApps\common\tradewinds classic\TradewindsClassic.exe
FirewallRules: [{6AE815A1-8048-45C1-B8D0-397893111634}] => (Allow) D:\Valve\Steam\SteamApps\common\tradewinds classic\TradewindsClassic.exe
FirewallRules: [{FB3B97CB-8CAA-443E-B69E-65823A590F8E}] => (Allow) D:\Valve\Steam\SteamApps\common\tradewinds 2\Tradewinds2.exe
FirewallRules: [{8D0CC826-B640-4F0D-A4D0-87C7F3778447}] => (Allow) D:\Valve\Steam\SteamApps\common\tradewinds 2\Tradewinds2.exe
FirewallRules: [{A4EA5C85-26DE-44B4-B9CB-CADD7238E806}] => (Allow) D:\Valve\Steam\SteamApps\common\tradewinds legends\TradewindsLegends.exe
FirewallRules: [{68A70FA8-ABF8-46EA-9829-CC5CD858AA36}] => (Allow) D:\Valve\Steam\SteamApps\common\tradewinds legends\TradewindsLegends.exe
FirewallRules: [{24F1BA66-903E-4D95-9D9C-A960F878D322}] => (Allow) D:\Valve\Steam\SteamApps\common\dawn of war soulstorm\soulstorm.exe
FirewallRules: [{16F85128-6A18-4E7F-8ADF-F1CBBE5BA4E7}] => (Allow) D:\Valve\Steam\SteamApps\common\dawn of war soulstorm\soulstorm.exe
FirewallRules: [TCP Query User{497BDABF-62BB-44DD-AA87-35DF80DB995F}C:\program files (x86)\firefly studios\stronghold 3\bin\win32_release\stronghold3.exe] => (Allow) C:\program files (x86)\firefly studios\stronghold 3\bin\win32_release\stronghold3.exe
FirewallRules: [UDP Query User{FAAB4092-74F1-4757-99D9-23A07CC68351}C:\program files (x86)\firefly studios\stronghold 3\bin\win32_release\stronghold3.exe] => (Allow) C:\program files (x86)\firefly studios\stronghold 3\bin\win32_release\stronghold3.exe
FirewallRules: [{8C3A3AFC-EBD3-4C0B-97C8-1726308E2ACC}] => (Allow) D:\Valve\Steam\SteamApps\common\saints row the third\game_launcher.exe
FirewallRules: [{2011184C-D0F8-4169-9A52-E5E42BC9EB3C}] => (Allow) D:\Valve\Steam\SteamApps\common\saints row the third\game_launcher.exe
FirewallRules: [TCP Query User{AC62D518-BE48-4191-A96F-099B42EB65DD}C:\program files (x86)\warlock - master of the arcane\game.exe] => (Allow) C:\program files (x86)\warlock - master of the arcane\game.exe
FirewallRules: [UDP Query User{44D698DD-C9E7-45AB-A2D3-B03C8626ECEB}C:\program files (x86)\warlock - master of the arcane\game.exe] => (Allow) C:\program files (x86)\warlock - master of the arcane\game.exe
FirewallRules: [TCP Query User{9307508B-B9AB-4694-ABA2-C62468845416}C:\program files (x86)\bitcomet\bitcomet_x64.exe] => (Allow) C:\program files (x86)\bitcomet\bitcomet_x64.exe
FirewallRules: [UDP Query User{8923594E-7A9B-4D76-AE37-DC222ADA9B2D}C:\program files (x86)\bitcomet\bitcomet_x64.exe] => (Allow) C:\program files (x86)\bitcomet\bitcomet_x64.exe
FirewallRules: [TCP Query User{93F550C2-E280-4FCF-BB11-6048CA9C085E}C:\program files (x86)\fatshark\krater\krater.exe] => (Allow) C:\program files (x86)\fatshark\krater\krater.exe
FirewallRules: [UDP Query User{D39E4958-26BA-42AE-AA79-957191CF39BB}C:\program files (x86)\fatshark\krater\krater.exe] => (Allow) C:\program files (x86)\fatshark\krater\krater.exe
FirewallRules: [TCP Query User{C536E461-B958-49D1-9817-5B18EFE8BC3E}D:\games\mass effect 3\binaries\win32\masseffect3.exe] => (Allow) D:\games\mass effect 3\binaries\win32\masseffect3.exe
FirewallRules: [UDP Query User{E203829B-3A79-4803-B652-B2BC9B94A83E}D:\games\mass effect 3\binaries\win32\masseffect3.exe] => (Allow) D:\games\mass effect 3\binaries\win32\masseffect3.exe
FirewallRules: [TCP Query User{D06FDB74-C1A9-4A41-A2FD-643AD7095F4B}C:\program files (x86)\gog.com\the witcher 2 enhanced edition\bin\witcher2.exe] => (Allow) C:\program files (x86)\gog.com\the witcher 2 enhanced edition\bin\witcher2.exe
FirewallRules: [UDP Query User{53A174D1-F35C-42FC-8EF0-DE34877A3A85}C:\program files (x86)\gog.com\the witcher 2 enhanced edition\bin\witcher2.exe] => (Allow) C:\program files (x86)\gog.com\the witcher 2 enhanced edition\bin\witcher2.exe
FirewallRules: [{9B54B0F1-A038-45B5-9CAB-07F0B4C606EC}] => (Allow) C:\Program Files (x86)\Rockstar Games\Max Payne 3\PlayMaxPayne3.exe
FirewallRules: [{A73EDF21-451B-43C3-B72E-A34728A91E52}] => (Allow) C:\Program Files (x86)\Rockstar Games\Max Payne 3\PlayMaxPayne3.exe
FirewallRules: [{597AA76E-1AA6-4DDD-B34D-3DB06F149FD1}] => (Allow) C:\Program Files (x86)\Rockstar Games\Social Club\renderer.exe
FirewallRules: [{90798577-C574-4426-A030-411312A6839C}] => (Allow) C:\Program Files (x86)\Rockstar Games\Social Club\renderer.exe
FirewallRules: [{19887208-FC3E-44D6-95F2-D0CA31643345}] => (Allow) C:\Program Files (x86)\Rockstar Games\Social Club\renderer.exe
FirewallRules: [{B77FC5A0-EE47-44C9-B0C2-37A564A0FE77}] => (Allow) C:\Program Files (x86)\Rockstar Games\Social Club\renderer.exe
FirewallRules: [{8179FD7E-FB39-4E59-936B-EB0893F524BB}] => (Allow) C:\Program Files (x86)\Rockstar Games\Max Payne 3\MaxPayne3.exe
FirewallRules: [{64319ACB-052D-482C-A861-06789EA374AE}] => (Allow) C:\Program Files (x86)\Rockstar Games\Max Payne 3\MaxPayne3.exe
FirewallRules: [{83BE34A8-1DA1-416C-AF9C-9117E97312ED}] => (Allow) C:\Program Files (x86)\Rockstar Games\Max Payne 3\MaxPayne3.exe
FirewallRules: [{D120ADC8-4B1F-4A73-8E6C-E4E6D13E4B87}] => (Allow) C:\Program Files (x86)\Rockstar Games\Max Payne 3\MaxPayne3.exe
FirewallRules: [{40E773A8-7B20-4E6C-90F9-8C8BEAEE049C}] => (Allow) C:\Program Files (x86)\Capcom\Dead Rising 2 Off The Record\deadrising2otr.exe
FirewallRules: [{DEC3D120-D672-4C70-86F4-98590A77C24B}] => (Allow) C:\Program Files (x86)\Capcom\Dead Rising 2 Off The Record\deadrising2otr.exe
FirewallRules: [{DE200FB5-49FC-4DEF-B8ED-D9E2EA4D8CE6}] => (Allow) C:\Program Files (x86)\Ubisoft\Might & Magic Heroes VI\Might & Magic Heroes VI.exe
FirewallRules: [{F979DEF3-D554-41EB-B1CB-0E86E5BACCF7}] => (Allow) C:\Program Files (x86)\Ubisoft\Might & Magic Heroes VI\Might & Magic Heroes VI.exe
FirewallRules: [{1EE416EB-B0EC-44A4-BB02-3B2659A4281A}] => (Allow) D:\Valve\Steam\SteamApps\common\napoleon total war\Napoleon.exe
FirewallRules: [{C2B0D0E4-EB00-41B4-B204-9AB1D17752F8}] => (Allow) D:\Valve\Steam\SteamApps\common\napoleon total war\Napoleon.exe
FirewallRules: [TCP Query User{F40F20B8-8AA5-41C4-92EC-21324E0CF907}C:\program files (x86)\rock of ages\binaries\win32\roa.exe] => (Block) C:\program files (x86)\rock of ages\binaries\win32\roa.exe
FirewallRules: [UDP Query User{8E4BB069-05DB-49FE-AB69-3A6E82CD3F7D}C:\program files (x86)\rock of ages\binaries\win32\roa.exe] => (Block) C:\program files (x86)\rock of ages\binaries\win32\roa.exe
FirewallRules: [{8A56B1D2-F614-4137-8B55-E71C552D0733}] => (Allow) C:\Program Files (x86)\Kalypso Media\Dungeons - The Dark Lord\dungeons-server.exe
FirewallRules: [{093D46BB-4D3A-4EB1-9C3C-66CE5321CF98}] => (Allow) C:\Program Files (x86)\Kalypso Media\Dungeons - The Dark Lord\dungeons-server.exe
FirewallRules: [TCP Query User{78BD07C3-B725-4484-A9FA-AA7DD541BAF7}C:\program files (x86)\all orcs must die\build\release\orcsmustdie.exe] => (Block) C:\program files (x86)\all orcs must die\build\release\orcsmustdie.exe
FirewallRules: [UDP Query User{99E48EE5-37FF-48CA-9EE5-30D7DB1D3EDD}C:\program files (x86)\all orcs must die\build\release\orcsmustdie.exe] => (Block) C:\program files (x86)\all orcs must die\build\release\orcsmustdie.exe
FirewallRules: [{6C2030F4-539E-4B6D-B4E6-4910D74025BA}] => (Allow) C:\Program Files (x86)\Ubisoft\Driver San Francisco\Driver.exe
FirewallRules: [{89B47788-1B48-446C-ADF1-2796EED03D9F}] => (Allow) C:\Program Files (x86)\Ubisoft\Driver San Francisco\Driver.exe
FirewallRules: [TCP Query User{0266CDAC-8142-4D79-A7C0-D83EACA24636}C:\program files (x86)\alice madness returnss\alice madness returns the complete collection\game\alice2\binaries\win32\alicemadnessreturns.exe] => (Block) C:\program files (x86)\alice madness returnss\alice madness returns the complete collection\game\alice2\binaries\win32\alicemadnessreturns.exe
FirewallRules: [UDP Query User{B7BBA9E1-DBBD-4858-A11F-3CAF676A605C}C:\program files (x86)\alice madness returnss\alice madness returns the complete collection\game\alice2\binaries\win32\alicemadnessreturns.exe] => (Block) C:\program files (x86)\alice madness returnss\alice madness returns the complete collection\game\alice2\binaries\win32\alicemadnessreturns.exe
FirewallRules: [{3EDD8518-58EC-4C05-9237-4F14F5CDEFE2}] => (Allow) D:\Valve\Steam\SteamApps\common\wormsxhd\Launcher.exe
FirewallRules: [{39F68258-D12D-4C8E-A35D-E461D922E7FE}] => (Allow) D:\Valve\Steam\SteamApps\common\wormsxhd\Launcher.exe
FirewallRules: [{903D9000-80A4-43E3-A166-88543272F065}] => (Allow) D:\Valve\Steam\SteamApps\common\alien swarm\swarm.exe
FirewallRules: [{1E714BFA-1BF1-44FD-A666-1784D4E0901C}] => (Allow) D:\Valve\Steam\SteamApps\common\alien swarm\swarm.exe
FirewallRules: [{29C154DE-7856-48C9-B005-432C9245D44B}] => (Allow) D:\Valve\Steam\SteamApps\common\ironfront\ironfront.exe
FirewallRules: [{C0CE7763-7DCF-46F4-9CC6-A772E1F9179E}] => (Allow) D:\Valve\Steam\SteamApps\common\ironfront\ironfront.exe
FirewallRules: [{202AB760-8C67-4BAB-AC3A-B6A48D7AC614}] => (Allow) C:\Users\euan\AppData\Local\DirectDownloader\directdownloader.exe
FirewallRules: [{8814F6DE-0451-472F-90AC-70C4956FE461}] => (Allow) C:\Users\euan\AppData\Local\DirectDownloader\directdownloader.exe
FirewallRules: [{BEF1D83F-EFA5-4D26-95AC-E51F133E928E}] => (Allow) D:\Valve\Steam\SteamApps\common\eye\EYE.exe
FirewallRules: [{41DD035B-150B-40CC-89FB-83B8123D44F5}] => (Allow) D:\Valve\Steam\SteamApps\common\eye\EYE.exe
FirewallRules: [{02410B2E-8631-4B4F-BE87-36243F62854E}] => (Allow) C:\Program Files (x86)\NVIDIA Corporation\NVIDIA Update Core\daemonu.exe
FirewallRules: [{88A6B39C-3904-4D5B-B30D-20BD58C88A10}] => (Allow) C:\Program Files (x86)\NVIDIA Corporation\NVIDIA Update Core\daemonu.exe
FirewallRules: [{E319C7B7-0E16-4D8D-B447-B48D67994611}] => (Allow) D:\Valve\Steam\SteamApps\common\arma 2 operation arrowhead\BEsetup\Setup_BattlEyeARMA2OA.exe
FirewallRules: [{A476489B-0ABD-47AF-A321-F322841EDDC5}] => (Allow) D:\Valve\Steam\SteamApps\common\arma 2 operation arrowhead\BEsetup\Setup_BattlEyeARMA2OA.exe
FirewallRules: [{51D48DE3-B95C-4E51-B76A-6E33CAACF0D7}] => (Allow) D:\Valve\Steam\SteamApps\common\arma 2 operation arrowhead\_runA2CO.cmd
FirewallRules: [{F501E6B7-30E9-427E-AE12-913AA5A6CFD3}] => (Allow) D:\Valve\Steam\SteamApps\common\arma 2 operation arrowhead\_runA2CO.cmd
FirewallRules: [{3251EFC9-27BA-441F-945A-4EA9BFEC14EA}] => (Allow) C:\Program Files (x86)\AVG\AVG2012\avgnsa.exe
FirewallRules: [{938A0D5C-E9D9-4105-BC8A-3D7F3A6E2319}] => (Allow) C:\Program Files (x86)\AVG\AVG2012\avgnsa.exe
FirewallRules: [{CF31C567-2FDF-428F-BA15-0249C246B7B8}] => (Allow) C:\Program Files (x86)\AVG\AVG2012\avgdiagex.exe
FirewallRules: [{E1C2E04B-E8D9-4B0A-BD55-1F80E1DF0990}] => (Allow) C:\Program Files (x86)\AVG\AVG2012\avgdiagex.exe
FirewallRules: [{7ACDB05F-84F0-46A2-A078-F50F908C6F02}] => (Allow) C:\Program Files (x86)\AVG\AVG2012\avgemca.exe
FirewallRules: [{5A8B6B48-390D-4A71-8AA3-BD5E9CEB3F2E}] => (Allow) C:\Program Files (x86)\AVG\AVG2012\avgemca.exe
FirewallRules: [TCP Query User{95A38350-D61D-4A06-ACAC-F6038A336BFF}C:\program files (x86)\2k games\borderlands 2\binaries\win32\borderlands2.exe] => (Block) C:\program files (x86)\2k games\borderlands 2\binaries\win32\borderlands2.exe
FirewallRules: [UDP Query User{4796DC0E-76CF-480F-A2C2-07871FE905EB}C:\program files (x86)\2k games\borderlands 2\binaries\win32\borderlands2.exe] => (Block) C:\program files (x86)\2k games\borderlands 2\binaries\win32\borderlands2.exe
FirewallRules: [{1132473B-3DC5-4C07-AA4E-B76ACCAAC72A}] => (Allow) D:\Valve\Steam\SteamApps\common\Counter-Strike Global Offensive\bin\SDKLauncher.exe
FirewallRules: [{676C8ED4-DC4F-4C83-A6ED-E09E3F5329D2}] => (Allow) D:\Valve\Steam\SteamApps\common\Counter-Strike Global Offensive\bin\SDKLauncher.exe
FirewallRules: [TCP Query User{C6B8ACAB-C85E-4D2F-8253-8A978DF1E3B5}C:\program files (x86)\java\jre6\bin\javaw.exe] => (Allow) C:\program files (x86)\java\jre6\bin\javaw.exe
FirewallRules: [UDP Query User{279F9FB9-E396-47BF-9992-2A509BD421EE}C:\program files (x86)\java\jre6\bin\javaw.exe] => (Allow) C:\program files (x86)\java\jre6\bin\javaw.exe
FirewallRules: [{5800F8D9-C32F-48CA-9CD5-D7F78609563F}] => (Allow) D:\Valve\Steam\SteamApps\common\total war shogun 2\data\encyclopedia\how_to_play.html
FirewallRules: [{9CC457A7-A606-4CA0-82AC-FBEE8A7B41C9}] => (Allow) D:\Valve\Steam\SteamApps\common\total war shogun 2\data\encyclopedia\how_to_play.html
FirewallRules: [{895ED40C-7A6E-44D5-AE0B-493D2B9F9089}] => (Allow) D:\Valve\Steam\SteamApps\common\total war shogun 2\benchmarks\benchmark_current_settings.bat
FirewallRules: [{E7496E64-71D3-4A62-AFE4-48807FADC9F9}] => (Allow) D:\Valve\Steam\SteamApps\common\total war shogun 2\benchmarks\benchmark_current_settings.bat
FirewallRules: [{6269D0C9-0F8C-4399-BD09-56BF052FC2DA}] => (Allow) D:\Valve\Steam\SteamApps\common\total war shogun 2\benchmarks\benchmark_specify_properties.bat
FirewallRules: [{D388BBDB-BA91-4232-9FAB-9610FC144825}] => (Allow) D:\Valve\Steam\SteamApps\common\total war shogun 2\benchmarks\benchmark_specify_properties.bat
FirewallRules: [TCP Query User{563F2856-E004-4E8E-A657-CB563D94223F}C:\program files (x86)\bethesda softworks\dishonored\binaries\win32\dishonored.exe] => (Block) C:\program files (x86)\bethesda softworks\dishonored\binaries\win32\dishonored.exe
FirewallRules: [UDP Query User{6586E0D7-42F9-4907-877A-6ECEC3DEFD3E}C:\program files (x86)\bethesda softworks\dishonored\binaries\win32\dishonored.exe] => (Block) C:\program files (x86)\bethesda softworks\dishonored\binaries\win32\dishonored.exe
FirewallRules: [{52331AC4-4EBC-4425-BAB1-3D1539B8A2DF}] => (Allow) D:\Valve\Steam\SteamApps\common\Counter-Strike Global Offensive\csgo.exe
FirewallRules: [{6C9112BB-56F7-4984-A329-72EB6AF3EF14}] => (Allow) D:\Valve\Steam\SteamApps\common\Counter-Strike Global Offensive\csgo.exe
FirewallRules: [{28AC7824-460D-4BBC-88ED-B998707F6B09}] => (Allow) D:\Valve\Steam\SteamApps\common\sid meier's civilization v\Launcher.exe
FirewallRules: [{C7B70EB2-0D54-4EC0-A16E-AFB53EBF3DC0}] => (Allow) D:\Valve\Steam\SteamApps\common\sid meier's civilization v\Launcher.exe
FirewallRules: [{64A3ECB3-41CF-458E-B777-FCB1C94ED602}] => (Allow) D:\Valve\Steam\SteamApps\common\Dark Souls Prepare to Die Edition\DATA\DARKSOULS.exe
FirewallRules: [{FC8C94AC-6C2C-4BBA-8FBF-FEB2C9540AA5}] => (Allow) D:\Valve\Steam\SteamApps\common\Dark Souls Prepare to Die Edition\DATA\DARKSOULS.exe
FirewallRules: [TCP Query User{1D33884A-1899-494A-9047-4578B323CF8F}D:\valve\steam\steamapps\common\dark souls prepare to die edition\data\data.exe] => (Allow) D:\valve\steam\steamapps\common\dark souls prepare to die edition\data\data.exe
FirewallRules: [UDP Query User{C6837674-13D6-4551-B3FB-2897629C29D9}D:\valve\steam\steamapps\common\dark souls prepare to die edition\data\data.exe] => (Allow) D:\valve\steam\steamapps\common\dark souls prepare to die edition\data\data.exe
FirewallRules: [TCP Query User{D66FACAD-35D4-44D1-924E-D7150EA23932}D:\valve\steam\steamapps\common\planetside 2\planetside2.exe] => (Allow) D:\valve\steam\steamapps\common\planetside 2\planetside2.exe
FirewallRules: [UDP Query User{5EE05FE5-921B-48E6-B1AA-B26BDC4976BE}D:\valve\steam\steamapps\common\planetside 2\planetside2.exe] => (Allow) D:\valve\steam\steamapps\common\planetside 2\planetside2.exe
FirewallRules: [{327AD4B8-552F-4BB4-BEDA-FDC5644CB70A}] => (Block) D:\valve\steam\steamapps\common\planetside 2\planetside2.exe
FirewallRules: [{3A957847-ACB2-44CD-A849-140846449725}] => (Block) D:\valve\steam\steamapps\common\planetside 2\planetside2.exe
FirewallRules: [TCP Query User{38A28580-78CF-4C77-9365-B34B1438A8D7}D:\thq\dark crusade\dawn of war - dark crusade\darkcrusade.exe] => (Allow) D:\thq\dark crusade\dawn of war - dark crusade\darkcrusade.exe
FirewallRules: [UDP Query User{1E34533B-EE3D-47CE-9B7E-E0D7423DDE97}D:\thq\dark crusade\dawn of war - dark crusade\darkcrusade.exe] => (Allow) D:\thq\dark crusade\dawn of war - dark crusade\darkcrusade.exe
FirewallRules: [{F59BAFED-304B-43C0-9CE4-F4B836B447E0}] => (Block) D:\thq\dark crusade\dawn of war - dark crusade\darkcrusade.exe
FirewallRules: [{CBAC4C37-E3E8-4306-87D2-F1DC4A445EDA}] => (Block) D:\thq\dark crusade\dawn of war - dark crusade\darkcrusade.exe
FirewallRules: [{664EBF9F-34F7-41E5-8FBA-6D51B53C8B8C}] => (Allow) D:\Valve\Steam\SteamApps\common\Torchlight II\Torchlight2.exe
FirewallRules: [{06C87865-EAD3-4615-850A-0424F993A37F}] => (Allow) D:\Valve\Steam\SteamApps\common\Torchlight II\Torchlight2.exe
FirewallRules: [{A84E947D-E361-448C-A9FD-6CDC3E8AF8F2}] => (Allow) C:\Program Files (x86)\AVG\AVG2013\avgmfapx.exe
FirewallRules: [{AD7BDB89-AF12-453B-8731-3574160C31EC}] => (Allow) C:\Program Files (x86)\AVG\AVG2013\avgmfapx.exe
FirewallRules: [{E6924CF0-E4AF-4071-8C6F-64B216CDFD92}] => (Allow) D:\Valve\Steam\SteamApps\common\eye\EYE.exe
FirewallRules: [{A23B2E05-8CBF-4EEA-94E8-BF63F0FB3A52}] => (Allow) D:\Valve\Steam\SteamApps\common\eye\EYE.exe
FirewallRules: [{81C793E3-49BE-42C9-AB8D-20873E7D8795}] => (Allow) D:\Valve\Steam\SteamApps\common\Hitman Absolution\HMA.exe
FirewallRules: [{DF8DBE1F-E457-4D56-A21A-089959A15AF8}] => (Allow) D:\Valve\Steam\SteamApps\common\Hitman Absolution\HMA.exe
FirewallRules: [{1478BF36-9E21-43FB-BE6B-0661038DCACD}] => (Allow) D:\Valve\Steam\SteamApps\common\Far Cry 3 Blood Dragon\bin\FC3BDUpdaterSteam.exe
FirewallRules: [{31D3997F-9970-4AD4-A937-DE2325032054}] => (Allow) D:\Valve\Steam\SteamApps\common\Far Cry 3 Blood Dragon\bin\FC3BDUpdaterSteam.exe
FirewallRules: [{A3AE9BA5-21D4-4155-836F-4FA2F586FE31}] => (Allow) D:\Valve\Steam\SteamApps\common\WormsRevolution\WormsRevolution.exe
FirewallRules: [{CA3B5235-E050-4090-A60C-2EAA9E963BBD}] => (Allow) D:\Valve\Steam\SteamApps\common\WormsRevolution\WormsRevolution.exe
FirewallRules: [TCP Query User{4763596B-7214-49BE-97B1-4114674A76C1}C:\program files (x86)\saints row iv\saintsrowiv.exe] => (Block) C:\program files (x86)\saints row iv\saintsrowiv.exe
FirewallRules: [UDP Query User{C81E483D-6855-490E-A00D-0AA6AB3001BB}C:\program files (x86)\saints row iv\saintsrowiv.exe] => (Block) C:\program files (x86)\saints row iv\saintsrowiv.exe
FirewallRules: [TCP Query User{A56AEA23-8751-4427-80EC-1AAE4336846E}D:\valve\steam\steamapps\common\total war rome ii\rome2.exe] => (Allow) D:\valve\steam\steamapps\common\total war rome ii\rome2.exe
FirewallRules: [UDP Query User{FFDC9349-DE58-420C-A9F8-4B929A723452}D:\valve\steam\steamapps\common\total war rome ii\rome2.exe] => (Allow) D:\valve\steam\steamapps\common\total war rome ii\rome2.exe
FirewallRules: [{1023F0F5-DD6C-41B8-A78F-41F827D76C98}] => (Block) D:\valve\steam\steamapps\common\total war rome ii\rome2.exe
FirewallRules: [{CC9DC4BA-49E4-4E6A-A815-C6F888C5C176}] => (Block) D:\valve\steam\steamapps\common\total war rome ii\rome2.exe
FirewallRules: [{83A0FB0A-F20F-44FA-BD47-5E1A8C06A4EF}] => (Allow) D:\Valve\Steam\SteamApps\common\Dark Souls Prepare to Die Edition\DATA\DARKSOULS.exe
FirewallRules: [{251E6F2B-EA55-4CF9-97A6-C8D738B46F53}] => (Allow) D:\Valve\Steam\SteamApps\common\Dark Souls Prepare to Die Edition\DATA\DARKSOULS.exe
FirewallRules: [{DC3554F9-E6DB-47C6-AD4D-321FAAF7C1D4}] => (Allow) D:\Valve\Steam\SteamApps\common\hotline_miami\HotlineMiami.exe
FirewallRules: [{121860EA-5C6A-465E-B10A-725CDE811613}] => (Allow) D:\Valve\Steam\SteamApps\common\hotline_miami\HotlineMiami.exe
FirewallRules: [{0B88B7CC-D5A0-46E1-9411-EB2D5FCFF7EA}] => (Allow) D:\Valve\Steam\SteamApps\common\chivalrymedievalwarfare\Binaries\Win32\UDK.exe
FirewallRules: [{0155AB76-FC4C-414D-9775-676F070904A9}] => (Allow) D:\Valve\Steam\SteamApps\common\chivalrymedievalwarfare\Binaries\Win32\UDK.exe
FirewallRules: [{AAFF3B45-9AAF-4D76-BE3A-05F482FB0AA3}] => (Allow) D:\Valve\Steam\SteamApps\common\sid meier's civilization v\Launcher.exe
FirewallRules: [{72B87D0C-9FEE-4685-8856-B6B79485C9A5}] => (Allow) D:\Valve\Steam\SteamApps\common\sid meier's civilization v\Launcher.exe
FirewallRules: [TCP Query User{7BFC2D6B-9024-48FE-B957-3FA032D721CA}D:\valve\steam\steamapps\common\orcs must die 2\build\game\orcsmustdie2.exe] => (Allow) D:\valve\steam\steamapps\common\orcs must die 2\build\game\orcsmustdie2.exe
FirewallRules: [UDP Query User{627939F7-4DC6-4868-921E-2B928CFF5E60}D:\valve\steam\steamapps\common\orcs must die 2\build\game\orcsmustdie2.exe] => (Allow) D:\valve\steam\steamapps\common\orcs must die 2\build\game\orcsmustdie2.exe
FirewallRules: [{78984C4E-11F8-4B82-AE2C-39CDD6EFAD7D}] => (Block) D:\valve\steam\steamapps\common\orcs must die 2\build\game\orcsmustdie2.exe
FirewallRules: [{4057274D-F713-4955-BAD3-2D4B766043E0}] => (Block) D:\valve\steam\steamapps\common\orcs must die 2\build\game\orcsmustdie2.exe
FirewallRules: [{DE13955A-C43F-436E-B825-4BD4FD12ED95}] => (Allow) D:\Valve\Steam\SteamApps\common\Orcs Must Die 2\build\release\OrcsMustDie2.exe
FirewallRules: [{BCE2E445-A3D4-4A76-BC6F-892BFB0C5FAF}] => (Allow) D:\Valve\Steam\SteamApps\common\Orcs Must Die 2\build\release\OrcsMustDie2.exe
FirewallRules: [TCP Query User{6F428C81-505A-4EEA-A335-DC9CD99E1DDF}D:\valve\steam\steamapps\common\xcom-enemy-unknown\xew\binaries\win32\xcomew.exe] => (Allow) D:\valve\steam\steamapps\common\xcom-enemy-unknown\xew\binaries\win32\xcomew.exe
FirewallRules: [UDP Query User{2D516729-FC3A-466D-A6FC-A4FFDEB9F610}D:\valve\steam\steamapps\common\xcom-enemy-unknown\xew\binaries\win32\xcomew.exe] => (Allow) D:\valve\steam\steamapps\common\xcom-enemy-unknown\xew\binaries\win32\xcomew.exe
FirewallRules: [{9AAC71A1-C82D-4557-BBBD-D51C60810D91}] => (Block) D:\valve\steam\steamapps\common\xcom-enemy-unknown\xew\binaries\win32\xcomew.exe
FirewallRules: [{73B7C6F7-6C9A-4095-A856-9FF538901E81}] => (Block) D:\valve\steam\steamapps\common\xcom-enemy-unknown\xew\binaries\win32\xcomew.exe
FirewallRules: [{8966F1A4-3D4F-4391-8CCE-5930B6197F75}] => (Allow) C:\Windows\SysWOW64\PnkBstrA.exe
FirewallRules: [{D8C2C27C-B0E7-4FC2-B109-6DC32D89F345}] => (Allow) C:\Windows\SysWOW64\PnkBstrA.exe
FirewallRules: [{234F2943-E3EE-4637-A175-859EDEE9FA5D}] => (Allow) C:\Windows\SysWOW64\PnkBstrB.exe
FirewallRules: [{C01CB212-E8F2-4CFA-9434-3D5E2E095693}] => (Allow) C:\Windows\SysWOW64\PnkBstrB.exe
FirewallRules: [{DFA1C5E8-EEB5-4C0B-A0FD-B17212AEA84A}] => (Allow) D:\Valve\Steam\SteamApps\common\FTL Faster Than Light\FTLGame.exe
FirewallRules: [{3748FB3B-E40A-4FEB-907D-8427F91FE582}] => (Allow) D:\Valve\Steam\SteamApps\common\FTL Faster Than Light\FTLGame.exe
FirewallRules: [{F672B578-CAAA-492A-9DEB-BACCADA8B002}] => (Allow) D:\Valve\Steam\SteamApps\common\SpaceEngineers\SpaceEngineers.exe
FirewallRules: [{4B2CC312-068C-419B-97A5-45DAD6E387A6}] => (Allow) D:\Valve\Steam\SteamApps\common\SpaceEngineers\SpaceEngineers.exe
FirewallRules: [{CB9D8218-AB08-421E-A53B-F50F17D4C7A9}] => (Allow) D:\Valve\Steam\SteamApps\common\Dishonored\Binaries\Win32\Dishonored.exe
FirewallRules: [{14B5DDE3-F8C5-4A60-8145-B8D9E86946E9}] => (Allow) D:\Valve\Steam\SteamApps\common\Dishonored\Binaries\Win32\Dishonored.exe
FirewallRules: [{646B5B2C-318A-4F46-9097-089E879089FB}] => (Allow) D:\Valve\Steam\SteamApps\common\Tomb Raider\TombRaider.exe
FirewallRules: [{7F45B249-977D-49B6-A468-F582789665C4}] => (Allow) D:\Valve\Steam\SteamApps\common\Tomb Raider\TombRaider.exe
FirewallRules: [{B6D32FE8-B3C0-47AA-B173-F45B18EFD27B}] => (Allow) D:\Valve\Steam\SteamApps\common\Arma 3\arma3.exe
FirewallRules: [{70D1A856-0E89-4B12-BB25-303A8F50ED5D}] => (Allow) D:\Valve\Steam\SteamApps\common\Arma 3\arma3.exe
FirewallRules: [{AE9D50B6-1EE1-4EA9-8E19-4F06A9FF7595}] => (Allow) D:\Valve\Steam\SteamApps\common\Arma 3\arma3.exe
FirewallRules: [{B917CA2D-B0A4-4401-B9E3-CAE3386BA39C}] => (Allow) D:\Valve\Steam\SteamApps\common\Arma 3\arma3.exe
FirewallRules: [{82C28301-996C-4901-B26E-AB808B00C3A5}] => (Allow) D:\Valve\Steam\SteamApps\common\Arma 3\arma3.exe
FirewallRules: [{E309A8D3-64CF-4005-B17F-2E2118EB987F}] => (Allow) D:\Valve\Steam\SteamApps\common\Arma 3\arma3.exe
FirewallRules: [{B103B316-4281-40DF-A3CE-64F1B0E92B95}] => (Allow) D:\Valve\Steam\SteamApps\common\Arma 3\arma3.exe
FirewallRules: [{15D34AEF-18A0-4ED1-8885-2FC40EEFB963}] => (Allow) D:\Valve\Steam\SteamApps\common\Arma 3\arma3.exe
FirewallRules: [{57E0D1A5-D1CC-4736-94F1-CF7F7DFB131A}] => (Allow) D:\Valve\Steam\SteamApps\common\Tomb Raider\TombRaider.exe
FirewallRules: [{F7C87FE5-0FC2-4554-BB3F-BACF97DE485D}] => (Allow) D:\Valve\Steam\SteamApps\common\Tomb Raider\TombRaider.exe
FirewallRules: [{9DD849F8-2179-499C-B1F0-CC818429C416}] => (Allow) D:\Valve\Steam\SteamApps\common\total war shogun 2\data\encyclopedia\how_to_play.html
FirewallRules: [{846C43AD-BCF1-4141-BEAB-04767B4EC2DB}] => (Allow) D:\Valve\Steam\SteamApps\common\total war shogun 2\data\encyclopedia\how_to_play.html
FirewallRules: [{19DCEB71-C9AF-4C3D-89DA-948C693A860F}] => (Allow) D:\Valve\Steam\SteamApps\common\total war shogun 2\benchmarks\benchmark_specify_properties.bat
FirewallRules: [{5F3DB9D5-0F15-43CD-A214-22A2482D5B59}] => (Allow) D:\Valve\Steam\SteamApps\common\total war shogun 2\benchmarks\benchmark_specify_properties.bat
FirewallRules: [{41346B78-20E9-4FDD-B2AE-003B0CC8DDDF}] => (Allow) D:\Valve\Steam\SteamApps\common\total war shogun 2\benchmarks\benchmark_specify_properties.bat
FirewallRules: [{8C930D16-93D2-4F77-8571-4F77E6527771}] => (Allow) D:\Valve\Steam\SteamApps\common\total war shogun 2\benchmarks\benchmark_specify_properties.bat
FirewallRules: [{A5F71B60-23ED-4D42-B984-6077C30AFFA2}] => (Allow) D:\Valve\Steam\SteamApps\common\total war shogun 2\benchmarks\benchmark_current_settings.bat
FirewallRules: [{DED433C3-934D-4A0D-8454-701A5C9B95D9}] => (Allow) D:\Valve\Steam\SteamApps\common\total war shogun 2\benchmarks\benchmark_current_settings.bat
FirewallRules: [{90A3C7A5-48A6-41AC-992C-9B47A298B161}] => (Allow) D:\Valve\Steam\SteamApps\common\total war shogun 2\benchmarks\benchmark_specify_properties.bat
FirewallRules: [{A3F8AD5C-602E-4121-89A7-76DAE29924A0}] => (Allow) D:\Valve\Steam\SteamApps\common\total war shogun 2\benchmarks\benchmark_specify_properties.bat
FirewallRules: [{1F06D282-EE6F-4E71-8D52-2DFCA28925FE}] => (Allow) D:\Valve\Steam\SteamApps\common\total war shogun 2\benchmarks\benchmark_specify_properties.bat
FirewallRules: [{36D595E8-6992-4F71-ADAD-0CA6DFEA7AA9}] => (Allow) D:\Valve\Steam\SteamApps\common\total war shogun 2\benchmarks\benchmark_specify_properties.bat
FirewallRules: [{53C71E8E-78B4-4D0B-BC55-2484E7DD44E3}] => (Allow) D:\Valve\Steam\SteamApps\common\Arma 3\arma3.exe
FirewallRules: [{73EBA36C-ACA2-421E-BE5C-95E0A413845C}] => (Allow) D:\Valve\Steam\SteamApps\common\Arma 3\arma3.exe
FirewallRules: [{6765D150-E28A-4816-B685-EEDAD26BACD1}] => (Allow) D:\Valve\Steam\SteamApps\common\Arma 3\arma3.exe
FirewallRules: [{AEAFE02E-BB32-497D-A097-94D0FB06B772}] => (Allow) D:\Valve\Steam\SteamApps\common\Arma 3\arma3.exe
FirewallRules: [{E04927F6-DA8E-42B9-8603-7BAC18052B56}] => (Allow) D:\Valve\Steam\SteamApps\common\State of Decay\StateOfDecay.exe
FirewallRules: [{144946DE-6051-4173-AF5C-FD6A8510E586}] => (Allow) D:\Valve\Steam\SteamApps\common\State of Decay\StateOfDecay.exe
FirewallRules: [{6BDC7953-A3B4-4056-8D76-B290965D82B0}] => (Allow) D:\Valve\Steam\SteamApps\common\Arma 3\arma3.exe
FirewallRules: [{227B9313-3149-45E2-8B60-C209DC5466B0}] => (Allow) D:\Valve\Steam\SteamApps\common\Arma 3\arma3.exe
FirewallRules: [{3573BDE9-0455-4AF2-B355-0D18F04B9CD1}] => (Allow) D:\Valve\Steam\SteamApps\common\Arma 3\arma3.exe
FirewallRules: [{7B037C54-F19C-4F8D-9674-73429C1C3234}] => (Allow) D:\Valve\Steam\SteamApps\common\Arma 3\arma3.exe
FirewallRules: [{8532096F-EEEE-4AA2-B026-491962B80E94}] => (Allow) D:\Valve\Steam\SteamApps\common\Arma 3\arma3.exe
FirewallRules: [{65C7FDAF-38B2-4254-92E0-DECB69EB982D}] => (Allow) D:\Valve\Steam\SteamApps\common\Arma 3\arma3.exe
FirewallRules: [{2D1C0C7B-D607-4E55-BAAF-D6D3A0FDD418}] => (Allow) D:\Valve\Steam\SteamApps\common\Arma 3\arma3.exe
FirewallRules: [{B28B89E3-877B-4638-AAAD-BB5FEA06182F}] => (Allow) D:\Valve\Steam\SteamApps\common\Arma 3\arma3.exe
FirewallRules: [{B50091DB-8B36-48FC-8011-07E463B68DEF}] => (Allow) D:\Valve\Steam\SteamApps\common\Arma 3\arma3.exe
FirewallRules: [{E6305C24-DCA7-4C03-9BD9-48BE4D52E45A}] => (Allow) D:\Valve\Steam\SteamApps\common\Arma 3\arma3.exe
FirewallRules: [{9042331D-5743-4E8A-BC13-440C5E75585B}] => (Allow) D:\Valve\Steam\SteamApps\common\Arma 3\arma3.exe
FirewallRules: [{B8E4CF7D-2B94-4BE5-8B1B-8875B8F4CDA1}] => (Allow) D:\Valve\Steam\SteamApps\common\Arma 3\arma3.exe
FirewallRules: [{8DFD17BE-80AD-480C-B55F-C8011F3ABD38}] => (Allow) D:\Valve\Steam\SteamApps\common\chivalrymedievalwarfare\ChivLauncher.exe
FirewallRules: [{84CE9E55-39C1-40C0-9F86-125C13AABDC3}] => (Allow) D:\Valve\Steam\SteamApps\common\chivalrymedievalwarfare\ChivLauncher.exe
FirewallRules: [{AF97DB22-2317-4FAF-8B8D-FDF0A0E0B170}] => (Allow) D:\Valve\Steam\SteamApps\common\Arma 3\arma3.exe
FirewallRules: [{F75713E3-4605-4D4E-859D-ED5A796B7C25}] => (Allow) D:\Valve\Steam\SteamApps\common\Arma 3\arma3.exe
FirewallRules: [{257B55C7-333F-4DFC-AB9D-F9F9E7D3D275}] => (Allow) D:\Valve\Steam\SteamApps\common\Arma 3\arma3.exe
FirewallRules: [{D2716ED6-4ABD-48F5-8381-2829BC89423D}] => (Allow) D:\Valve\Steam\SteamApps\common\Arma 3\arma3.exe
FirewallRules: [{F0854800-03F7-4F55-AE06-4CD6EEF86184}] => (Allow) D:\Valve\Steam\SteamApps\common\Arma 3\arma3.exe
FirewallRules: [{74AE78B0-BBA0-4B1A-855F-EA4ACC57EE7E}] => (Allow) D:\Valve\Steam\SteamApps\common\Arma 3\arma3.exe
FirewallRules: [{65E8719A-DF01-443B-AA8E-1BEFBE66A23D}] => (Allow) D:\Valve\Steam\SteamApps\common\Arma 3\arma3.exe
FirewallRules: [{64633698-34EC-4019-BD70-86757EA8ACBA}] => (Allow) D:\Valve\Steam\SteamApps\common\Arma 3\arma3.exe
FirewallRules: [{E2D6341F-3FCF-4AE0-94DC-D62EEBE5D992}] => (Allow) D:\Valve\Steam\SteamApps\common\State of Decay\StateOfDecay.exe
FirewallRules: [{5B9DA454-5C46-4A4A-872B-AED71FA5389D}] => (Allow) D:\Valve\Steam\SteamApps\common\State of Decay\StateOfDecay.exe
FirewallRules: [{427AD84B-A1E6-496E-A7CB-2127553E8330}] => (Allow) D:\Valve\Steam\SteamApps\common\Kerbal Space Program\KSP.exe
FirewallRules: [{21B8555E-DD9E-4B93-A1AA-1385CF4FFAC4}] => (Allow) D:\Valve\Steam\SteamApps\common\Kerbal Space Program\KSP.exe
FirewallRules: [TCP Query User{1D29B7A7-BAC3-47B8-8F3A-E1593E69E8BE}D:\valve\steam\steam.exe] => (Allow) D:\valve\steam\steam.exe
FirewallRules: [UDP Query User{7656B92D-AFDC-49D6-8E1A-7E1C99AFED1C}D:\valve\steam\steam.exe] => (Allow) D:\valve\steam\steam.exe
FirewallRules: [{53A28D42-2F9C-4DC4-B110-1D4C2C41FFEE}] => (Allow) D:\Valve\Steam\SteamApps\common\chivalrymedievalwarfare\ChivLauncher.exe
FirewallRules: [{67A55E7D-04D7-48DF-8196-C3B7E263703C}] => (Allow) D:\Valve\Steam\SteamApps\common\chivalrymedievalwarfare\ChivLauncher.exe
FirewallRules: [{1D7C79B2-A2AC-4F09-A37E-A7526FC7ED95}] => (Allow) D:\Valve\Steam\SteamApps\common\total war shogun 2\data\encyclopedia\how_to_play.html
FirewallRules: [{BDF76641-2B71-428E-90C6-1CA8FE4B269F}] => (Allow) D:\Valve\Steam\SteamApps\common\total war shogun 2\data\encyclopedia\how_to_play.html
FirewallRules: [{3606C26C-35F8-4918-98BE-4B0AC61D567C}] => (Allow) D:\Valve\Steam\SteamApps\common\total war shogun 2\benchmarks\benchmark_specify_properties.bat
FirewallRules: [{5CAA96F2-B58A-481F-896F-31C863E6F9D4}] => (Allow) D:\Valve\Steam\SteamApps\common\total war shogun 2\benchmarks\benchmark_specify_properties.bat
FirewallRules: [{93DD4F91-183B-45FB-B42D-C4F3354E7487}] => (Allow) D:\Valve\Steam\SteamApps\common\total war shogun 2\benchmarks\benchmark_specify_properties.bat
FirewallRules: [{A04EA7A9-92F5-4CCE-AAF0-F430898B84C1}] => (Allow) D:\Valve\Steam\SteamApps\common\total war shogun 2\benchmarks\benchmark_specify_properties.bat
FirewallRules: [{70FF4AC2-F95D-4829-AE6D-E8CAE1B286D9}] => (Allow) D:\Valve\Steam\SteamApps\common\total war shogun 2\benchmarks\benchmark_current_settings.bat
FirewallRules: [{C257D18C-7898-4BCE-9804-B8593FCAF51D}] => (Allow) D:\Valve\Steam\SteamApps\common\total war shogun 2\benchmarks\benchmark_current_settings.bat
FirewallRules: [{28C1AFA1-F214-446F-B717-7CF5093CDFC2}] => (Allow) D:\Valve\Steam\SteamApps\common\total war shogun 2\benchmarks\benchmark_specify_properties.bat
FirewallRules: [{B39E7015-391E-4809-B280-553F271554A7}] => (Allow) D:\Valve\Steam\SteamApps\common\total war shogun 2\benchmarks\benchmark_specify_properties.bat
FirewallRules: [{D8C9F279-DA78-4CBF-8E21-B735E40FC5BA}] => (Allow) D:\Valve\Steam\SteamApps\common\total war shogun 2\benchmarks\benchmark_specify_properties.bat
FirewallRules: [{A04280F9-29E0-4256-8100-23F7DF4C3CE4}] => (Allow) D:\Valve\Steam\SteamApps\common\total war shogun 2\benchmarks\benchmark_specify_properties.bat
FirewallRules: [{6E6EDE51-46EA-4AD6-A04E-B8D709430FBA}] => (Allow) D:\Valve\Steam\SteamApps\common\Kerbal Space Program\KSP.exe
FirewallRules: [{7D753208-0847-4C23-958D-E9897B8A2216}] => (Allow) D:\Valve\Steam\SteamApps\common\Kerbal Space Program\KSP.exe
FirewallRules: [{CD6E040E-55F3-4CC5-9242-EAE8A2A8AFAF}] => (Allow) D:\Valve\Steam\SteamApps\common\chivalrymedievalwarfare\ChivLauncher.exe
FirewallRules: [{4EDC686D-434D-4B1B-8046-3A2B0A65E254}] => (Allow) D:\Valve\Steam\SteamApps\common\chivalrymedievalwarfare\ChivLauncher.exe
FirewallRules: [{73816AB5-98CB-4764-BA7D-E48EFA5E6537}] => (Allow) D:\Valve\Steam\SteamApps\common\chivalrymedievalwarfare\ChivLauncher.exe
FirewallRules: [{853D4C9A-BD52-40BA-8858-085237A3FF11}] => (Allow) D:\Valve\Steam\SteamApps\common\chivalrymedievalwarfare\ChivLauncher.exe
FirewallRules: [{4EA1F0C9-D852-4261-B64B-DA874F5514E9}] => (Allow) D:\Valve\Steam\SteamApps\common\State of Decay\StateOfDecay.exe
FirewallRules: [{2CF0818E-36C0-492B-8D43-67E4DE4B022B}] => (Allow) D:\Valve\Steam\SteamApps\common\State of Decay\StateOfDecay.exe
FirewallRules: [{80D1F9EB-5B3D-41D7-9EAD-6AC94B343C4F}] => (Allow) D:\Valve\Steam\SteamApps\common\State of Decay\StateOfDecay.exe
FirewallRules: [{4F5292E8-9662-46A3-9CB8-17267805BC55}] => (Allow) D:\Valve\Steam\SteamApps\common\State of Decay\StateOfDecay.exe
FirewallRules: [{BF63E85F-AE23-45CE-8FD0-89EBB8D4E40C}] => (Allow) D:\Valve\Steam\SteamApps\common\Warlock - Master of the Arcane\support\game.url
FirewallRules: [{D7449100-1A6F-46C7-B916-E41F5597E9EA}] => (Allow) D:\Valve\Steam\SteamApps\common\Warlock - Master of the Arcane\support\game.url
FirewallRules: [{56F6D45E-8D5C-4EDE-AC9A-F5C8B035032A}] => (Allow) D:\Valve\Steam\SteamApps\common\Warlock - Master of the Arcane\support\paradox.url
FirewallRules: [{D0DE103B-E7FB-4B6B-8CEC-DB1515E612DF}] => (Allow) D:\Valve\Steam\SteamApps\common\Warlock - Master of the Arcane\support\paradox.url
FirewallRules: [{7C886907-A464-4C4D-841B-58722C24CCDF}] => (Allow) D:\Valve\Steam\SteamApps\common\Warlock - Master of the Arcane\support\ino_co_com.url
FirewallRules: [{42B4274B-72F3-4998-852A-B3A5C74C8C0C}] => (Allow) D:\Valve\Steam\SteamApps\common\Warlock - Master of the Arcane\support\ino_co_com.url
FirewallRules: [{AA00CAFC-4EEB-4325-AC66-45291311864E}] => (Allow) D:\Valve\Steam\SteamApps\common\Spelunky\Spelunky.exe
FirewallRules: [{BA22AAD9-095F-4281-AF92-D0254F9FFB69}] => (Allow) D:\Valve\Steam\SteamApps\common\Spelunky\Spelunky.exe
FirewallRules: [{65135779-5C13-42DE-A40A-DB300FA798DB}] => (Allow) D:\Valve\Steam\SteamApps\common\chivalrymedievalwarfare\ChivLauncher.exe
FirewallRules: [{738A1277-1A8D-4D26-B5F6-0966BC0EE83F}] => (Allow) D:\Valve\Steam\SteamApps\common\chivalrymedievalwarfare\ChivLauncher.exe
FirewallRules: [{B6B8650D-CFFC-439D-A6BE-A1C95E52C37F}] => (Allow) D:\Valve\Steam\SteamApps\common\Arma 3\arma3.exe
FirewallRules: [{7E5A2E15-5B80-4A9E-B509-AB9190DD9B8F}] => (Allow) D:\Valve\Steam\SteamApps\common\Arma 3\arma3.exe
FirewallRules: [{A6E86F3E-B3A8-4449-9D71-8E0F46686347}] => (Allow) D:\Valve\Steam\SteamApps\common\Arma 3\arma3.exe
FirewallRules: [{549E655D-2BB1-468A-A820-46EFCE14B932}] => (Allow) D:\Valve\Steam\SteamApps\common\Arma 3\arma3.exe
FirewallRules: [{6AC5581F-EAD4-4182-AA22-70A20CAE0C2E}] => (Allow) D:\Valve\Steam\SteamApps\common\chivalrymedievalwarfare\ChivLauncher.exe
FirewallRules: [{42817601-B8B3-4136-9FF8-FD8A212E6E81}] => (Allow) D:\Valve\Steam\SteamApps\common\chivalrymedievalwarfare\ChivLauncher.exe
FirewallRules: [{84A7647E-9A4E-4765-9EFF-B914EF84F3B1}] => (Allow) D:\Valve\Steam\SteamApps\common\chivalrymedievalwarfare\ChivLauncher.exe
FirewallRules: [{7564FB5E-FF8C-437C-9E5D-480EDFF1DA30}] => (Allow) D:\Valve\Steam\SteamApps\common\chivalrymedievalwarfare\ChivLauncher.exe
FirewallRules: [{F0019473-7F68-4679-B90E-BE3E8DD62E95}] => (Allow) D:\Valve\Steam\SteamApps\common\chivalrymedievalwarfare\ChivLauncher.exe
FirewallRules: [{EE54EF6F-3D0B-4D56-BE6E-F30C1AE06644}] => (Allow) D:\Valve\Steam\SteamApps\common\chivalrymedievalwarfare\ChivLauncher.exe
FirewallRules: [{D9B846E2-B327-4898-8FCB-83750E47B9A9}] => (Allow) C:\Program Files (x86)\Winamp\winamp.exe
FirewallRules: [{21E0CC47-C615-47F8-95A5-B3C2E0BCE8E2}] => (Allow) C:\Program Files (x86)\Winamp\winamp.exe
FirewallRules: [{151CB3AE-3F18-45A0-BF28-E87593D74672}] => (Allow) D:\Valve\Steam\SteamApps\common\Deadlight\Binaries\Win32\LOTDGame.exe
FirewallRules: [{5C7712CA-9C89-4AA0-936E-326CF21A10C9}] => (Allow) D:\Valve\Steam\SteamApps\common\Deadlight\Binaries\Win32\LOTDGame.exe
FirewallRules: [{6CE0970C-2B9B-4009-9E69-5DECD2E061BA}] => (Allow) D:\Valve\Steam\SteamApps\common\Nidhogg\Nidhogg.exe
FirewallRules: [{B6D1097C-4666-4B7C-A59B-08F91D9CD4C3}] => (Allow) D:\Valve\Steam\SteamApps\common\Nidhogg\Nidhogg.exe
FirewallRules: [{F2666FEE-A1A1-4F6F-A321-ABF4881B73AD}] => (Allow) D:\Valve\Steam\SteamApps\common\SimCity 4 Deluxe\Apps\SimCity 4.exe
FirewallRules: [{094285B1-400E-484B-AB4C-0FA52BC4C4FB}] => (Allow) D:\Valve\Steam\SteamApps\common\SimCity 4 Deluxe\Apps\SimCity 4.exe
FirewallRules: [{5B69E985-C6DA-4171-B144-D77E34FB097A}] => (Allow) C:\Program Files\BitComet\BitComet.exe
FirewallRules: [{31456C3E-6E52-4D07-88F5-847EC7D702FB}] => (Allow) C:\Program Files\BitComet\BitComet.exe
FirewallRules: [{31D7AF05-6409-4F6E-8D07-163B26B794DB}] => (Allow) D:\Valve\Steam\SteamApps\common\TrialsPC\datapack\trialsFMX.exe
FirewallRules: [{C97A0C2D-5FF0-41BC-8CC3-4CB5D2184B27}] => (Allow) D:\Valve\Steam\SteamApps\common\TrialsPC\datapack\trialsFMX.exe
FirewallRules: [{3E59115C-7B46-4F64-919F-F3FB8F9FCFC5}] => (Allow) C:\Program Files (x86)\NVIDIA Corporation\NetService\NvNetworkService.exe
FirewallRules: [{1D851611-F1FB-415E-99B3-15A92EE69C3C}] => (Allow) C:\Program Files (x86)\NVIDIA Corporation\NetService\NvNetworkService.exe
FirewallRules: [{F544CEE7-5364-4CF5-A6F2-AC1738818590}] => (Allow) C:\Program Files\NVIDIA Corporation\NvStreamSrv\nvstreamsvc.exe
FirewallRules: [{86F56304-0657-4438-85F5-3847988656A8}] => (Allow) C:\Program Files\NVIDIA Corporation\NvStreamSrv\nvstreamer.exe
FirewallRules: [{5279F556-3D17-4C77-BA62-153587864AAB}] => (Allow) C:\Program Files\NVIDIA Corporation\NvStreamSrv\nvstreamer.exe
FirewallRules: [{C6284366-8F8E-4E92-B881-8AEDF136F9D9}] => (Allow) D:\Valve\Steam\SteamApps\common\Rayman Legends\Rayman Legends.exe
FirewallRules: [{07BC2D11-F2A4-433B-B75C-019DD06D94AB}] => (Allow) D:\Valve\Steam\SteamApps\common\Rayman Legends\Rayman Legends.exe
FirewallRules: [TCP Query User{B01A17D4-95B7-44DF-8F33-E00173A79B94}D:\valve\steam\steamapps\common\chivalrymedievalwarfare\binaries\win64\cmw.exe] => (Allow) D:\valve\steam\steamapps\common\chivalrymedievalwarfare\binaries\win64\cmw.exe
FirewallRules: [UDP Query User{F412032C-CF55-4BF5-85FB-DFBAD0185878}D:\valve\steam\steamapps\common\chivalrymedievalwarfare\binaries\win64\cmw.exe] => (Allow) D:\valve\steam\steamapps\common\chivalrymedievalwarfare\binaries\win64\cmw.exe
FirewallRules: [{45104EDD-844F-4325-BE2A-761839E36F55}] => (Allow) D:\Valve\Steam\SteamApps\common\Planetary Annihilation\PA.exe
FirewallRules: [{948018E5-0B1C-457F-9825-36D04F3DF599}] => (Allow) D:\Valve\Steam\SteamApps\common\Planetary Annihilation\PA.exe
FirewallRules: [{01631AE9-A9DD-413D-AB29-89F3968ECC8E}] => (Allow) C:\Program Files (x86)\NVIDIA Corporation\NetService\NvNetworkService.exe
FirewallRules: [{60BF717D-AC4A-4F98-BAE9-F97100C6F5E7}] => (Allow) C:\Program Files (x86)\NVIDIA Corporation\NetService\NvNetworkService.exe
FirewallRules: [{B018DEEE-FACA-4EA0-B1A6-A78DFDA294C0}] => (Allow) D:\Valve\Steam\SteamApps\common\SirYouAreBeingHunted\x64\sir_alpha.exe
FirewallRules: [{1805138B-0302-41AB-A6B5-F2480F8EF8A5}] => (Allow) D:\Valve\Steam\SteamApps\common\SirYouAreBeingHunted\x64\sir_alpha.exe
FirewallRules: [{5E0F5FF6-8CAD-4E8D-B674-F9F89CEBEBD5}] => (Allow) D:\Valve\Steam\SteamApps\common\SirYouAreBeingHunted\x86\sir_alpha.exe
FirewallRules: [{5BE1E380-FE85-463B-A276-71E678E46923}] => (Allow) D:\Valve\Steam\SteamApps\common\SirYouAreBeingHunted\x86\sir_alpha.exe
FirewallRules: [TCP Query User{E48E287A-581C-4CE8-A21E-8C63D0C0B8C7}C:\program files (x86)\age of wonders iii\aow3.exe] => (Block) C:\program files (x86)\age of wonders iii\aow3.exe
FirewallRules: [UDP Query User{38047159-62BA-4CEF-87B7-2165ADC39D13}C:\program files (x86)\age of wonders iii\aow3.exe] => (Block) C:\program files (x86)\age of wonders iii\aow3.exe
FirewallRules: [{3DAEFFE7-235B-41CF-B706-785DB50C0DBA}] => (Allow) D:\Valve\Steam\SteamApps\common\SpaceEngineers\Bin64\SpaceEngineers.exe
FirewallRules: [{EB5DE751-A38E-4D05-954E-0384CFC11703}] => (Allow) D:\Valve\Steam\SteamApps\common\SpaceEngineers\Bin64\SpaceEngineers.exe
FirewallRules: [{BD2188DA-3768-48D1-8C2A-0F7706AF8018}] => (Allow) D:\Valve\Steam\SteamApps\common\SirYouAreBeingHunted\x64\sir_beta.exe
FirewallRules: [{BB677A70-1DC6-443D-8E85-DD6D044D8E2D}] => (Allow) D:\Valve\Steam\SteamApps\common\SirYouAreBeingHunted\x64\sir_beta.exe
FirewallRules: [{75509373-DBE2-46D9-8ECF-7543601B2252}] => (Allow) D:\Valve\Steam\SteamApps\common\SirYouAreBeingHunted\x86\sir_beta.exe
FirewallRules: [{2857FC1C-8C8B-44D9-BC7B-68D1448E4C95}] => (Allow) D:\Valve\Steam\SteamApps\common\SirYouAreBeingHunted\x86\sir_beta.exe
FirewallRules: [{C63E0574-9B74-43C2-982F-22B2AE58F931}] => (Allow) D:\Valve\Steam\SteamApps\common\Trials Fusion\datapack\trials_fusion.exe
FirewallRules: [{A1CBB836-06AD-4B13-A592-948E0D094023}] => (Allow) D:\Valve\Steam\SteamApps\common\Trials Fusion\datapack\trials_fusion.exe
FirewallRules: [{48E39AE7-3939-40D7-B920-F8819F848009}] => (Allow) D:\Valve\Steam\SteamApps\common\Trials Fusion\datapack\trials_fusion.exe
FirewallRules: [{99B42BCF-2AE7-4B46-B348-50C7B1030282}] => (Allow) D:\Valve\Steam\SteamApps\common\Trials Fusion\datapack\trials_fusion.exe
FirewallRules: [{2AE72BF1-5572-4E1F-953B-BBED432537CB}] => (Allow) D:\Valve\Steam\SteamApps\common\Trials Fusion\datapack\trials_fusion.exe
FirewallRules: [{C013939C-6DCA-4BB0-B55A-88C69B64ED1C}] => (Allow) D:\Valve\Steam\SteamApps\common\Trials Fusion\datapack\trials_fusion.exe
FirewallRules: [TCP Query User{F80F63B9-4196-4245-8486-4D6A7C81AC16}C:\program files (x86)\java\jre7\bin\javaw.exe] => (Allow) C:\program files (x86)\java\jre7\bin\javaw.exe
FirewallRules: [UDP Query User{2507BBF4-D2B0-4DA0-A436-51FD6252237A}C:\program files (x86)\java\jre7\bin\javaw.exe] => (Allow) C:\program files (x86)\java\jre7\bin\javaw.exe
FirewallRules: [{73617909-7156-45B6-8E54-8221F7576BAB}] => (Block) C:\program files (x86)\java\jre7\bin\javaw.exe
FirewallRules: [{9BED0ED6-ABBF-4A48-A771-ABEC339B83DE}] => (Block) C:\program files (x86)\java\jre7\bin\javaw.exe
FirewallRules: [{76445400-E419-4525-9591-C348CED23684}] => (Allow) C:\Program Files\Echobit\Evolve\EvoSvc.exe
FirewallRules: [{0222067C-88BF-4308-AEC4-9113DF87BA0A}] => (Allow) C:\Program Files\Echobit\Evolve\EvolveClient.exe
FirewallRules: [{230C0A69-9C86-4673-B3B4-4A2BE04BCE64}] => (Allow) LPort=16355
FirewallRules: [{E0BB555C-E4A8-41EF-9CF5-3BF749B09D75}] => (Allow) LPort=16355
FirewallRules: [{A0FAA5FE-D80B-469C-8DD2-4CC5AAD81991}] => (Allow) D:\Valve\Steam\SteamApps\common\PapersPlease\PapersPlease.exe
FirewallRules: [{A092842E-A45D-478B-8472-E44C4733CF84}] => (Allow) D:\Valve\Steam\SteamApps\common\PapersPlease\PapersPlease.exe
FirewallRules: [TCP Query User{0D83E281-48FB-43FF-9B2B-594D09A2EC74}D:\valve\steam\steamapps\common\lichdom battlemage\bin32\lichdombattlemage.exe] => (Allow) D:\valve\steam\steamapps\common\lichdom battlemage\bin32\lichdombattlemage.exe
FirewallRules: [UDP Query User{34183E52-E94F-4306-92F2-07C47FE06AD1}D:\valve\steam\steamapps\common\lichdom battlemage\bin32\lichdombattlemage.exe] => (Allow) D:\valve\steam\steamapps\common\lichdom battlemage\bin32\lichdombattlemage.exe
FirewallRules: [{1319A966-E36F-4C9A-9735-8BECC7ED3E40}] => (Block) D:\valve\steam\steamapps\common\lichdom battlemage\bin32\lichdombattlemage.exe
FirewallRules: [{9B1C1011-3223-4EE1-826C-B076E0A6D169}] => (Block) D:\valve\steam\steamapps\common\lichdom battlemage\bin32\lichdombattlemage.exe
FirewallRules: [{79B20F94-34EF-4597-A11B-E9D5E4F4B40A}] => (Allow) D:\Valve\Steam\SteamApps\common\The Forest\TheForest.exe
FirewallRules: [{302EF04E-E884-4823-819A-FFF039835F43}] => (Allow) D:\Valve\Steam\SteamApps\common\The Forest\TheForest.exe
FirewallRules: [{ABB42577-9E1C-4046-9361-6E9B8695228E}] => (Allow) D:\Valve\Steam\SteamApps\common\Arma 3\arma3launcher.exe
FirewallRules: [{535B5F2A-C969-4680-882A-AD4EDE1993AA}] => (Allow) D:\Valve\Steam\SteamApps\common\Arma 3\arma3launcher.exe
FirewallRules: [{D1E9D231-FE17-49D5-B605-2146DF3CE991}] => (Allow) D:\Valve\Steam\SteamApps\common\atomzombiesmasher\data\atomzombiesmasher.exe
FirewallRules: [{875AB6F1-AA82-4A2B-9952-A784BF03F3B9}] => (Allow) D:\Valve\Steam\SteamApps\common\atomzombiesmasher\data\atomzombiesmasher.exe
FirewallRules: [TCP Query User{F9FFDC31-508A-4A08-B13E-2CF86F9669AD}C:\program files (x86)\mortal kombat complete edition\mkke.exe] => (Block) C:\program files (x86)\mortal kombat complete edition\mkke.exe
FirewallRules: [UDP Query User{EA103422-D36C-4D5C-A5AD-9DAD430F269A}C:\program files (x86)\mortal kombat complete edition\mkke.exe] => (Block) C:\program files (x86)\mortal kombat complete edition\mkke.exe
FirewallRules: [{C0C4156D-20CB-4481-AA3B-B2E5046F8DB9}] => (Allow) C:\Program Files (x86)\AVG\AVG2014\avgmfapx.exe
FirewallRules: [{BB762B86-F5B0-4AD4-8C18-C2667AE54560}] => (Allow) C:\Program Files (x86)\AVG\AVG2014\avgmfapx.exe
FirewallRules: [{433706C2-A605-42F3-B06B-5D2A436280E2}] => (Allow) D:\Valve\Steam\SteamApps\common\mark_of_the_ninja\bin\game.exe
FirewallRules: [{AF3462E9-6170-49AC-8C31-7B8443BEC54F}] => (Allow) D:\Valve\Steam\SteamApps\common\mark_of_the_ninja\bin\game.exe
FirewallRules: [{57E7B0DA-C2A9-4356-9FFA-ED65831F602E}] => (Allow) D:\Valve\Steam\bin\steamwebhelper.exe
FirewallRules: [{F7EB239B-B869-47A0-89BD-966C0CB60BB1}] => (Allow) D:\Valve\Steam\bin\steamwebhelper.exe
FirewallRules: [{E35A9B29-E75D-4D66-B904-8FCD7432E05A}] => (Allow) D:\Valve\Steam\SteamApps\common\Five Nights at Freddy's\FiveNightsatFreddys.exe
FirewallRules: [{73589165-5F6F-427F-B7B0-479F8717C298}] => (Allow) D:\Valve\Steam\SteamApps\common\Five Nights at Freddy's\FiveNightsatFreddys.exe
FirewallRules: [TCP Query User{F6A77EA4-4782-4F77-AFA2-891FC9EBD8BE}C:\program files (x86)\age of wonders iii golden realms\aow3.exe] => (Block) C:\program files (x86)\age of wonders iii golden realms\aow3.exe
FirewallRules: [UDP Query User{5F704B1A-9A89-4E55-A831-6B3ECCB4C835}C:\program files (x86)\age of wonders iii golden realms\aow3.exe] => (Block) C:\program files (x86)\age of wonders iii golden realms\aow3.exe
FirewallRules: [{2791DCF1-6AB9-4646-B71D-36CABBA3DEB2}] => (Allow) D:\Valve\Steam\SteamApps\common\Evil Genius\EvilGeniusLauncher.exe
FirewallRules: [{157579DA-5FDC-4740-9CA8-07E5E0458835}] => (Allow) D:\Valve\Steam\SteamApps\common\Evil Genius\EvilGeniusLauncher.exe
FirewallRules: [TCP Query User{3DA9109C-985F-4520-A63D-1132D287EDB8}D:\valve\steam\steamapps\common\borderlandspresequel\binaries\win32\borderlandspresequel.exe] => (Allow) D:\valve\steam\steamapps\common\borderlandspresequel\binaries\win32\borderlandspresequel.exe
FirewallRules: [UDP Query User{765C68DA-6A52-43DF-8F09-A46428BC1FDF}D:\valve\steam\steamapps\common\borderlandspresequel\binaries\win32\borderlandspresequel.exe] => (Allow) D:\valve\steam\steamapps\common\borderlandspresequel\binaries\win32\borderlandspresequel.exe
FirewallRules: [TCP Query User{BA4A5D57-3D4C-4A82-9D3F-284B3D23643A}D:\valve\steam\steamapps\common\chivalrymedievalwarfare\cdw\binaries\win64\cdw.exe] => (Allow) D:\valve\steam\steamapps\common\chivalrymedievalwarfare\cdw\binaries\win64\cdw.exe
FirewallRules: [UDP Query User{8FD828DA-EF4B-4C48-84E5-C78522FFCA07}D:\valve\steam\steamapps\common\chivalrymedievalwarfare\cdw\binaries\win64\cdw.exe] => (Allow) D:\valve\steam\steamapps\common\chivalrymedievalwarfare\cdw\binaries\win64\cdw.exe
FirewallRules: [{F9D80753-21BF-4938-AA27-D346E71CB574}] => (Allow) D:\Valve\Steam\SteamApps\common\SirYouAreBeingHunted\x64\sir.exe
FirewallRules: [{0F2B2103-3CD7-4B1D-8FEC-A84AE681E93C}] => (Allow) D:\Valve\Steam\SteamApps\common\SirYouAreBeingHunted\x64\sir.exe
FirewallRules: [{96E42C37-C4D0-41C2-BFF8-8A7801D32E2E}] => (Allow) D:\Valve\Steam\SteamApps\common\SirYouAreBeingHunted\x86\sir.exe
FirewallRules: [{E12393AA-DD25-4C4E-A827-3C1E9A94FBDD}] => (Allow) D:\Valve\Steam\SteamApps\common\SirYouAreBeingHunted\x86\sir.exe
FirewallRules: [{3398D89A-520E-4AAD-8657-D5C825103BDF}] => (Allow) D:\Valve\Steam\SteamApps\common\chivalrymedievalwarfare\Binaries\Win64\CMW.exe
FirewallRules: [{EAC59AE5-8A45-4050-8C4E-805283D7DC13}] => (Allow) D:\Valve\Steam\SteamApps\common\chivalrymedievalwarfare\Binaries\Win64\CMW.exe
FirewallRules: [{9359922C-E889-4F11-BE69-80A468904131}] => (Allow) D:\Valve\Steam\SteamApps\common\chivalrymedievalwarfare\CDW\Binaries\Win64\CDW.exe
FirewallRules: [{E09C7A0B-E225-494A-B9FA-2B1E707DAF24}] => (Allow) D:\Valve\Steam\SteamApps\common\chivalrymedievalwarfare\CDW\Binaries\Win64\CDW.exe
FirewallRules: [{0FEE3CDF-AE7D-4F28-A12B-8E2FBF2D95C6}] => (Allow) D:\Valve\Steam\SteamApps\common\chivalrymedievalwarfare\Binaries\Win32\CMW.exe
FirewallRules: [{9FFFC25A-241E-4583-A67D-BB89A80C3FA4}] => (Allow) D:\Valve\Steam\SteamApps\common\chivalrymedievalwarfare\Binaries\Win32\CMW.exe
FirewallRules: [{9ED4D24E-1632-42F6-B407-803BB5D3A4A5}] => (Allow) D:\Valve\Steam\SteamApps\common\chivalrymedievalwarfare\CDW\Binaries\Win32\CDW.exe
FirewallRules: [{DA6EDA1A-E1DB-46B8-ACB3-A01B7153638E}] => (Allow) D:\Valve\Steam\SteamApps\common\chivalrymedievalwarfare\CDW\Binaries\Win32\CDW.exe
FirewallRules: [{6DED95FA-294A-40A8-BAC8-43D3681CE1C5}] => (Allow) C:\Program Files (x86)\Ubisoft\Ubisoft Game Launcher\games\Far Cry 4\bin\FarCry4.exe
FirewallRules: [{C3DC9F68-2FBD-4A71-A6DA-5812DE9C1222}] => (Allow) C:\Program Files (x86)\Ubisoft\Ubisoft Game Launcher\games\Far Cry 4\bin\FarCry4.exe
FirewallRules: [{F78D5EBF-C486-4FAA-B8C7-54976AF4CC79}] => (Allow) C:\Program Files (x86)\Ubisoft\Ubisoft Game Launcher\games\Far Cry 4\bin\FarCry4.exe
FirewallRules: [{2694E0CA-A479-42BC-8D10-E2E43713C589}] => (Allow) C:\Program Files (x86)\Ubisoft\Ubisoft Game Launcher\games\Far Cry 4\bin\FarCry4.exe
FirewallRules: [{14168E12-F78D-4E9E-ABD4-6B4F0C076F80}] => (Allow) C:\Program Files (x86)\Ubisoft\Ubisoft Game Launcher\games\Far Cry 4\bin\IGE_WPF64.exe
FirewallRules: [{C95A7BAE-7508-47D7-97C4-CB43D959DED5}] => (Allow) C:\Program Files (x86)\Ubisoft\Ubisoft Game Launcher\games\Far Cry 4\bin\IGE_WPF64.exe
FirewallRules: [{BDDF2334-9494-4002-9D83-4A5DD643F2F4}] => (Allow) C:\Program Files (x86)\Ubisoft\Ubisoft Game Launcher\games\Far Cry 4\bin\IGE_WPF64.exe
FirewallRules: [{4AE16104-0C50-4BD0-BD3F-93D77A5D8590}] => (Allow) C:\Program Files (x86)\Ubisoft\Ubisoft Game Launcher\games\Far Cry 4\bin\IGE_WPF64.exe
FirewallRules: [{0F8895D3-B32B-4CAE-8910-235E0FB0FB4D}] => (Allow) C:\Program Files (x86)\Mozilla Firefox\firefox.exe
FirewallRules: [{5FB606A3-AF3A-4D59-9BA8-02B9548E9F4C}] => (Allow) C:\Program Files (x86)\Mozilla Firefox\firefox.exe
FirewallRules: [TCP Query User{AAE22DD9-71C6-4F1E-A36A-A618F6C93048}C:\program files (x86)\r.g. mechanics\dying light\dyinglightgame.exe] => (Block) C:\program files (x86)\r.g. mechanics\dying light\dyinglightgame.exe
FirewallRules: [UDP Query User{2A661C70-CF80-4F25-82B9-A44C02938E47}C:\program files (x86)\r.g. mechanics\dying light\dyinglightgame.exe] => (Block) C:\program files (x86)\r.g. mechanics\dying light\dyinglightgame.exe
FirewallRules: [{53C32C10-EF62-400E-87D6-80BE442EB26B}] => (Allow) D:\Valve\Steam\SteamApps\common\Lichdom Battlemage\Bin64\LichdomBattlemage.exe
FirewallRules: [{8043C675-57CF-4D15-BF06-96A217342071}] => (Allow) D:\Valve\Steam\SteamApps\common\Lichdom Battlemage\Bin64\LichdomBattlemage.exe
FirewallRules: [TCP Query User{BD4120DA-0A46-4D88-AFA9-ADC6A4BD8C92}D:\valve\steam\steamapps\common\total war attila\attila.exe] => (Allow) D:\valve\steam\steamapps\common\total war attila\attila.exe
FirewallRules: [UDP Query User{C7E3C49B-776A-4EE3-8066-84D8AD0351D1}D:\valve\steam\steamapps\common\total war attila\attila.exe] => (Allow) D:\valve\steam\steamapps\common\total war attila\attila.exe
FirewallRules: [{C062383D-F88B-46BC-A914-0AA8F35F7EBD}] => (Block) D:\valve\steam\steamapps\common\total war attila\attila.exe
FirewallRules: [{2EAF0D7B-BA44-44BF-A39B-73EBB58D76E9}] => (Block) D:\valve\steam\steamapps\common\total war attila\attila.exe
FirewallRules: [{53C73200-05AE-4FA9-A4E5-E14D74D8E6A2}] => (Allow) D:\Valve\Steam\SteamApps\common\Dark Souls II\Game\DarkSoulsII.exe
FirewallRules: [{17875CE4-4E54-4CE4-B094-3F99C70CC077}] => (Allow) D:\Valve\Steam\SteamApps\common\Dark Souls II\Game\DarkSoulsII.exe
FirewallRules: [{0B9B70AF-531E-4B89-A053-E51970F0D8DD}] => (Allow) D:\Valve\Steam\SteamApps\common\ShadowOfMordor\x64\ShadowOfMordor.exe
FirewallRules: [{F21FB8FD-E91C-4177-B057-559FE6F9EE13}] => (Allow) D:\Valve\Steam\SteamApps\common\ShadowOfMordor\x64\ShadowOfMordor.exe
FirewallRules: [TCP Query User{B9285835-3C78-4050-9540-96061BD60278}C:\program files (x86)\r.g. mechanics\age of wonders 3\aow3.exe] => (Block) C:\program files (x86)\r.g. mechanics\age of wonders 3\aow3.exe
FirewallRules: [UDP Query User{02204D81-A223-4068-A82D-3D8AE92F2AAF}C:\program files (x86)\r.g. mechanics\age of wonders 3\aow3.exe] => (Block) C:\program files (x86)\r.g. mechanics\age of wonders 3\aow3.exe
FirewallRules: [{3CC69B85-A865-418D-8D0C-7253F779F225}] => (Allow) D:\Valve\Steam\SteamApps\common\Grand Theft Auto V\GTAVLauncher.exe
FirewallRules: [{4CF704C8-6D2A-42F2-AE39-C6E0C53215D2}] => (Allow) D:\Valve\Steam\SteamApps\common\Grand Theft Auto V\GTAVLauncher.exe
FirewallRules: [TCP Query User{34382CD1-68F9-42DA-9B40-D89746EFE3E5}D:\valve\steam\steamapps\common\grand theft auto v\gta5.exe] => (Allow) D:\valve\steam\steamapps\common\grand theft auto v\gta5.exe
FirewallRules: [UDP Query User{0313A8EE-522B-438D-AF5C-DF50E686CD5D}D:\valve\steam\steamapps\common\grand theft auto v\gta5.exe] => (Allow) D:\valve\steam\steamapps\common\grand theft auto v\gta5.exe
FirewallRules: [{E9A46CC0-7B5A-4846-AEDB-C43106291909}] => (Block) D:\valve\steam\steamapps\common\grand theft auto v\gta5.exe
FirewallRules: [{F2BA203C-01D8-4101-B58C-0E74A44717C9}] => (Block) D:\valve\steam\steamapps\common\grand theft auto v\gta5.exe
FirewallRules: [{10055702-F47A-4D12-A185-EBD097BFB3F9}] => (Allow) D:\Valve\Steam\SteamApps\common\XCom-Enemy-Unknown\Binaries\Win32\XComGame.exe
FirewallRules: [{DD4C3D55-E033-489D-833F-C915D1EB286F}] => (Allow) D:\Valve\Steam\SteamApps\common\XCom-Enemy-Unknown\Binaries\Win32\XComGame.exe
FirewallRules: [{82778705-1185-450F-B098-BC34200EB91B}] => (Allow) C:\Program Files (x86)\AVG\AVG2015\avgmfapx.exe
FirewallRules: [{800C0F21-FA47-4902-AA22-E18B598C28B4}] => (Allow) C:\Program Files (x86)\AVG\AVG2015\avgmfapx.exe
FirewallRules: [{3910713F-C842-4FC7-A79C-5A96C2AD900D}] => (Allow) D:\Valve\Steam\SteamApps\common\Skyrim\SkyrimLauncher.exe
FirewallRules: [{99B40DC1-64A5-467A-A7A0-12CBCC557A30}] => (Allow) D:\Valve\Steam\SteamApps\common\Skyrim\SkyrimLauncher.exe
FirewallRules: [{D19F5C37-1D38-4EAC-8968-7B392F2DF758}] => (Allow) D:\Valve\Steam\SteamApps\common\Skyrim\skse_steam_boot.exe
FirewallRules: [{8068B91C-0D7C-4E2D-9C9A-B60E726CC111}] => (Allow) D:\Valve\Steam\SteamApps\common\Skyrim\skse_steam_boot.exe
FirewallRules: [{27AEE00E-A5CB-4836-A3E8-80BAB1B86C1C}] => (Allow) D:\Valve\Steam\SteamApps\common\Stalker Call of Pripyat\bin\xrEngine.exe
FirewallRules: [{2F72C4E0-27E1-4A2D-83BD-99DBBB9BA232}] => (Allow) D:\Valve\Steam\SteamApps\common\Stalker Call of Pripyat\bin\xrEngine.exe
FirewallRules: [{343E9BA8-29FD-4AAF-B0F6-70DAE48077BF}] => (Allow) D:\Valve\Steam\SteamApps\common\Total War Rome II\launcher\launcher.exe
FirewallRules: [{0D7E24A4-F87B-4703-9809-3455530B6527}] => (Allow) D:\Valve\Steam\SteamApps\common\Total War Rome II\launcher\launcher.exe
FirewallRules: [{479D7697-17CE-4449-AC3D-8C7D8D2904A7}] => (Allow) C:\Program Files (x86)\Mozilla Firefox\firefox.exe
FirewallRules: [{0F048C96-DCA3-482B-A519-C488B33FE6BE}] => (Allow) C:\Program Files (x86)\Mozilla Firefox\firefox.exe
FirewallRules: [{6D88F505-DDA0-4B7C-8AE7-9AFD8B9669A0}] => (Allow) D:\Valve\Steam\SteamApps\common\Fallout 4\Fallout4Launcher.exe
FirewallRules: [{875AFFA1-80EF-47E1-B700-1F4585AF080A}] => (Allow) D:\Valve\Steam\SteamApps\common\Fallout 4\Fallout4Launcher.exe
FirewallRules: [{ED5888AD-EA73-4EE8-A1C5-58CF7C620B83}] => (Allow) C:\Program Files\NVIDIA Corporation\NvStreamSrv\NvStreamNetworkService.exe
FirewallRules: [{878D8ABD-3713-4FF8-86AD-C263E790FAC0}] => (Allow) C:\Program Files\NVIDIA Corporation\NvStreamSrv\NvStreamNetworkService.exe
FirewallRules: [{AFA755EA-70ED-4F61-9743-859837724623}] => (Allow) C:\Program Files\NVIDIA Corporation\NvStreamSrv\NvStreamUserAgent.exe
FirewallRules: [{FBA416E5-FAD5-46A9-8AF8-6C4666363827}] => (Allow) C:\Program Files\NVIDIA Corporation\NvStreamSrv\nvstreamer.exe
FirewallRules: [{5A7DCB04-9574-439C-9770-294455FB1D0E}] => (Allow) C:\Program Files\NVIDIA Corporation\NvStreamSrv\nvstreamer.exe
FirewallRules: [{CA32BEB6-EAAA-40D7-9341-ADADA73D7785}] => (Allow) D:\Valve\Steam\SteamApps\common\Warhammer End Times Vermintide\launcher\launcher.exe
FirewallRules: [{0426259E-7FB6-4703-9494-32E6E527F951}] => (Allow) D:\Valve\Steam\SteamApps\common\Warhammer End Times Vermintide\launcher\launcher.exe
FirewallRules: [{7C61FC15-8C5B-4444-8F49-7FAD6DC26EE3}] => (Allow) D:\Valve\Steam\SteamApps\common\Warhammer End Times Vermintide\binaries\vermintide.exe
FirewallRules: [{3B4F5E4C-1B23-4279-9FE8-2EADA3041E17}] => (Allow) D:\Valve\Steam\SteamApps\common\Warhammer End Times Vermintide\binaries\vermintide.exe
FirewallRules: [{BD48B375-13CF-4B7F-AD46-8DE01F14267D}] => (Allow) D:\Valve\Steam\SteamApps\common\SirYouAreBeingHunted\launcher\sir.exe
FirewallRules: [{6C354BA0-AB5B-445F-B255-1599BE5CEB1B}] => (Allow) D:\Valve\Steam\SteamApps\common\SirYouAreBeingHunted\launcher\sir.exe
FirewallRules: [{C4A914CA-DF51-4072-B4DD-9C02EF774D7F}] => (Allow) D:\Valve\Steam\SteamApps\common\dont_starve\bin\dontstarve_steam.exe
FirewallRules: [{0DD1F006-A6C5-45C5-BCE3-10EDB00FA5F1}] => (Allow) D:\Valve\Steam\SteamApps\common\dont_starve\bin\dontstarve_steam.exe
FirewallRules: [{9915F2D0-7DEE-47C9-BDD6-25AAAC2CD687}] => (Allow) C:\Program Files (x86)\AVG\Av\avgdiagex.exe
FirewallRules: [{97E08EB4-DF61-4020-AE3B-7480CA74414E}] => (Allow) C:\Program Files (x86)\AVG\Av\avgdiagex.exe
FirewallRules: [{E2139C6F-EA83-460F-B5FA-FDA5CCBD9687}] => (Allow) C:\Program Files (x86)\AVG\Av\avgmfapx.exe
FirewallRules: [{84B4F00C-DBF8-4BB7-B65E-7679E105F552}] => (Allow) C:\Program Files (x86)\AVG\Av\avgmfapx.exe
FirewallRules: [{0F067B12-D2CB-46E6-8917-D513C90DFD3A}] => (Allow) D:\Valve\Steam\SteamApps\common\Counter-Strike Global Offensive\bin\SDKLauncher.exe
FirewallRules: [{DB06EE9E-9028-443E-AB2E-F2F97AFFFF1E}] => (Allow) D:\Valve\Steam\SteamApps\common\Counter-Strike Global Offensive\bin\SDKLauncher.exe
FirewallRules: [{9A54543E-6A1F-4E5D-A4F5-7A16061AF7AE}] => (Allow) D:\Valve\Steam\SteamApps\common\Total War Attila\launcher\launcher.exe
FirewallRules: [{F31A3CC9-6DC8-4B98-BCC6-E15DE1332536}] => (Allow) D:\Valve\Steam\SteamApps\common\Total War Attila\launcher\launcher.exe

==================== Faulty Device Manager Devices =============

Name: Teredo Tunneling Pseudo-Interface
Description: Microsoft Teredo Tunneling Adapter
Class Guid: {4d36e972-e325-11ce-bfc1-08002be10318}
Manufacturer: Microsoft
Service: tunnel
Problem: : This device cannot start. (Code10)
Resolution: Device failed to start. Click "Update Driver" to update the drivers for this device.
On the "General Properties" tab of the device, click "Troubleshoot" to start the troubleshooting wizard.


==================== Event log errors: =========================

Application errors:
==================
Error: (12/09/2015 10:44:47 AM) (Source: Application Error) (EventID: 1000) (User: )
Description: Faulting application name: mbamscheduler.exe, version: 3.1.6.0, time stamp: 0x55e84890
Faulting module name: unknown, version: 0.0.0.0, time stamp: 0x00000000
Exception code: 0xc0000005
Fault offset: 0x00000000
Faulting process id: 0x920
Faulting application start time: 0xmbamscheduler.exe0
Faulting application path: mbamscheduler.exe1
Faulting module path: mbamscheduler.exe2
Report Id: mbamscheduler.exe3

Error: (12/07/2015 03:15:51 PM) (Source: Application Hang) (EventID: 1002) (User: )
Description: The program Fallout4.exe version 1.1.30.0 stopped interacting with Windows and was closed. To see if more information about the problem is available, check the problem history in the Action Center control panel.

Process ID: 1704

Start Time: 01d13101e55d39dc

Termination Time: 275

Application Path: D:\Valve\Steam\steamapps\common\Fallout 4\Fallout4.exe

Report Id:

Error: (12/07/2015 10:07:55 AM) (Source: Application Hang) (EventID: 1002) (User: )
Description: The program Fallout4.exe version 1.1.30.0 stopped interacting with Windows and was closed. To see if more information about the problem is available, check the problem history in the Action Center control panel.

Process ID: 314

Start Time: 01d130d6d3e95461

Termination Time: 261

Application Path: D:\Valve\Steam\steamapps\common\Fallout 4\Fallout4.exe

Report Id:

Error: (12/07/2015 10:05:30 AM) (Source: Application Hang) (EventID: 1002) (User: )
Description: The program Fallout4.exe version 1.1.30.0 stopped interacting with Windows and was closed. To see if more information about the problem is available, check the problem history in the Action Center control panel.

Process ID: 1078

Start Time: 01d130d6a0493958

Termination Time: 204

Application Path: D:\Valve\Steam\steamapps\common\Fallout 4\Fallout4.exe

Report Id:

Error: (12/07/2015 10:03:39 AM) (Source: Application Hang) (EventID: 1002) (User: )
Description: The program Fallout4.exe version 1.1.30.0 stopped interacting with Windows and was closed. To see if more information about the problem is available, check the problem history in the Action Center control panel.

Process ID: 11ac

Start Time: 01d130d65599d1f4

Termination Time: 241

Application Path: D:\Valve\Steam\steamapps\common\Fallout 4\Fallout4.exe

Report Id:

Error: (12/07/2015 10:01:10 AM) (Source: Application Hang) (EventID: 1002) (User: )
Description: The program Fallout4.exe version 1.1.30.0 stopped interacting with Windows and was closed. To see if more information about the problem is available, check the problem history in the Action Center control panel.

Process ID: f80

Start Time: 01d130d61853c87c

Termination Time: 211

Application Path: D:\Valve\Steam\steamapps\common\Fallout 4\Fallout4.exe

Report Id:

Error: (12/05/2015 08:25:52 PM) (Source: Application Hang) (EventID: 1002) (User: )
Description: The program Fallout4.exe version 1.1.30.0 stopped interacting with Windows and was closed. To see if more information about the problem is available, check the problem history in the Action Center control panel.

Process ID: 1770

Start Time: 01d12f9b0d3c8faa

Termination Time: 273

Application Path: D:\Valve\Steam\steamapps\common\Fallout 4\Fallout4.exe

Report Id:

Error: (12/05/2015 08:25:11 PM) (Source: Application Hang) (EventID: 1002) (User: )
Description: The program Fallout4.exe version 1.1.30.0 stopped interacting with Windows and was closed. To see if more information about the problem is available, check the problem history in the Action Center control panel.

Process ID: 12f0

Start Time: 01d12f9aee7dca21

Termination Time: 236

Application Path: D:\Valve\Steam\steamapps\common\Fallout 4\Fallout4.exe

Report Id:

Error: (12/05/2015 09:31:34 AM) (Source: Application Hang) (EventID: 1002) (User: )
Description: The program Fallout4.exe version 1.1.30.0 stopped interacting with Windows and was closed. To see if more information about the problem is available, check the problem history in the Action Center control panel.

Process ID: 170c

Start Time: 01d12f3f4b43aa83

Termination Time: 279

Application Path: D:\Valve\Steam\steamapps\common\Fallout 4\Fallout4.exe

Report Id:

Error: (12/03/2015 04:09:48 PM) (Source: Application Hang) (EventID: 1002) (User: )
Description: The program Fallout4.exe version 1.1.30.0 stopped interacting with Windows and was closed. To see if more information about the problem is available, check the problem history in the Action Center control panel.

Process ID: 110c

Start Time: 01d12de4afdbd2d9

Termination Time: 201

Application Path: D:\Valve\Steam\steamapps\common\Fallout 4\Fallout4.exe

Report Id:


System errors:
=============
Error: (12/13/2015 12:14:32 PM) (Source: Service Control Manager) (EventID: 7000) (User: )
Description: The MSCamSvc service failed to start due to the following error:
%%2

Error: (12/12/2015 01:09:45 PM) (Source: Service Control Manager) (EventID: 7000) (User: )
Description: The MSCamSvc service failed to start due to the following error:
%%2

Error: (12/11/2015 04:08:20 PM) (Source: Service Control Manager) (EventID: 7000) (User: )
Description: The MSCamSvc service failed to start due to the following error:
%%2

Error: (12/11/2015 02:45:19 PM) (Source: Schannel) (EventID: 4120) (User: NT AUTHORITY)
Description: The following fatal alert was generated: 10. The internal error state is 10.

Error: (12/11/2015 02:45:19 PM) (Source: Schannel) (EventID: 4120) (User: NT AUTHORITY)
Description: The following fatal alert was generated: 10. The internal error state is 10.

Error: (12/11/2015 02:45:18 PM) (Source: Schannel) (EventID: 4120) (User: NT AUTHORITY)
Description: The following fatal alert was generated: 10. The internal error state is 10.

Error: (12/11/2015 02:35:07 PM) (Source: Schannel) (EventID: 4120) (User: NT AUTHORITY)
Description: The following fatal alert was generated: 10. The internal error state is 10.

Error: (12/11/2015 02:35:07 PM) (Source: Schannel) (EventID: 4120) (User: NT AUTHORITY)
Description: The following fatal alert was generated: 10. The internal error state is 10.

Error: (12/11/2015 02:35:07 PM) (Source: Schannel) (EventID: 4120) (User: NT AUTHORITY)
Description: The following fatal alert was generated: 10. The internal error state is 10.

Error: (12/11/2015 02:14:35 PM) (Source: Schannel) (EventID: 4120) (User: NT AUTHORITY)
Description: The following fatal alert was generated: 10. The internal error state is 10.


==================== Memory info ===========================

Processor: Intel® Core™ i5-2400 CPU @ 3.10GHz
Percentage of memory in use: 65%
Total physical RAM: 4077.25 MB
Available physical RAM: 1409.85 MB
Total Virtual: 8152.71 MB
Available Virtual: 5933.61 MB

==================== Drives ================================

Drive c: () (Fixed) (Total:931.5 GB) (Free:413.51 GB) NTFS ==>[drive with boot components (obtained from BCD)]
Drive d: () (Fixed) (Total:465.76 GB) (Free:45.31 GB) NTFS

==================== MBR & Partition Table ==================

========================================================
Disk: 0 (MBR Code: Windows XP) (Size: 465.8 GB) (Disk ID: 4FEEEC35)
Partition 1: (Active) - (Size=465.8 GB) - (Type=07 NTFS)

========================================================
Disk: 1 (MBR Code: Windows 7 or 8) (Size: 931.5 GB) (Disk ID: 20812080)
Partition 1: (Active) - (Size=931.5 GB) - (Type=07 NTFS)

==================== End of Addition.txt ============================

Edited by Queen-Evie, 13 December 2015 - 02:50 PM.


#3 Oh My!

Oh My!

    Adware and Spyware and Malware.....


  • Malware Response Instructor
  • 37,972 posts
  • OFFLINE
  •  
  • Gender:Male
  • Location:California
  • Local time:12:12 AM

Posted 16 December 2015 - 08:58 PM

Greetings euanicorn and :welcome: to BleepingComputer's Virus/Trojan/Spyware/Malware Removal forum.

My name is Oh My! and I am here to help you! Now that we are "friends" please call me Gary.

If you would allow me to call you by your first name I would prefer to do that.

===================================================

Ground Rules:
  • First, I would like to inform you that most of us here at Bleeping Computer offer our expert assistance out of the goodness of our hearts. Please try to match our commitment to you with your patience toward us. If this was easy we would never have met.
  • Please do not run any tools or take any steps other than those I will provide for you while we work on your computer together. I need to be certain about the state of your computer in order to provide appropriate and effective steps for you to take. Most often "well intentioned" (and usually panic driven!) independent efforts can make things much worse for both of us. If at any point you would prefer to take your own steps please let me know, I will not be offended. I would be happy to focus on the many others who are waiting in line for assistance.
  • Please perform all steps in the order they are listed in each set of instructions. Some steps may be a bit complicated. If things are not clear, be sure to stop and let me know. We need to work on this together with confidence.
  • Please copy and paste all logs into your post unless directed otherwise. Please do not re-run any programs I suggest. If you encounter problems simply stop and tell me.
  • When you post your reply, use the Replytopic.jpg button instead.
  • In the upper right hand corner of the topic you will see the Followtopic.jpg button. Click on this then choose Immediate E-Mail notification and then Proceed and you will be sent an email once I have posted a response.
  • If you do not reply to your topic after 5 days we assume it has been abandoned and I will close it.
  • When your computer is clean I will alert you of such. I will also provide for you detailed information about how you can combat future infections.
  • I would like to remind you to make no further changes to your computer unless I direct you to do so.
  • Now let's get started
===================================================

Now that I am assisting you, you can expect that I will be very responsive to your situation. If you are able, I would request you check this thread at least once per day so that we can try to resolve your issues effectively and efficiently. If you are going to be delayed please be considerate and post that information so that I know you are still with me. Unfortunately, there are many people waiting to be assisted and not enough of us at BleepingComputer to go around. I appreciate your understanding and diligence.

Thank you for your patience thus far.

Do you know what this is?

C:\Windows\CSI New York\uninstall.exe

Please do this.

===================================================

Farbar's Recovery Scan Tool - Run Fix in Normal or Safe Mode

--------------------
  • Press the Windows key Windows_Logo_key.gif + r on your keyboard at the same time. Type in notepad and press Enter
  • Please copy and paste the contents of the below code box into the open notepad and save it to your desktop (<<<Important) as fixlist.txt
HKU\S-1-5-21-1126527562-1434389470-3061596616-1001\...\MountPoints2: {9e9b233d-579d-11e0-a149-bcaec5df35a0} - F:\AutoRunCD.exe
HKU\S-1-5-21-1126527562-1434389470-3061596616-1001\...\MountPoints2: {a15df326-6756-11e0-82db-bcaec5df35a0} - F:\Setup.exe
HKU\S-1-5-21-1126527562-1434389470-3061596616-1001\...\MountPoints2: {fb449286-a992-11e1-96d5-bcaec5df35a0} - F:\setup.exe
SearchScopes: HKU\.DEFAULT -> DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL =
SearchScopes: HKU\S-1-5-19 -> DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL =
SearchScopes: HKU\S-1-5-20 -> DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL =
Handler: linkscanner - {F274614C-63F8-47D5-A4D1-FBDDE494F8D1} - C:\Program Files (x86)\AVG\AVG2012\avgpp.dll No File
S2 MSCamSvc; "C:\Program Files\Microsoft LifeCam\MSCamS64.exe" [X]
U4 Avgtdia; system32\DRIVERS\avgtdia.sys [X]
Task: {3599726E-3778-4ABE-BD66-B07C74A18FE0} - System32\Tasks\{971BB27B-2149-4E59-B744-2DEC1C2AF979} => pcalua.exe -a F:\SETUP.EXE -d F:\
File: C:\Windows\CSI New York\uninstall.exe
  • Launch FRST and press the Fix button just once and wait, the program will automatically launch fixlist.txt.
  • The tool will create a log on the desktop called Fixlog.txt. Please copy and paste the contents of the file in your reply.
===================================================

RogueKiller by Tigzy

--------------------
  • Download RogueKiller and save it to your desktop
  • Close all running programs
  • Right click on the icon and select Run as Administrator
  • For Windows XP simply double click on the icon
  • The program will conduct a prescan and when finished you wlll see Prescan Finished. Please hit the scan button
  • Click Scan
  • If, during the scan, you receive a request to upload a file to Virustotal please click Yes
  • A report should open and a copy of the report will be placed on your desktop. If not, hit the Report button.
  • If RogueKiller has been blocked, do not hesitate to try a few times more. If it really won't run, rename it winlogon.exe (or winlogon.com) and try again
  • Copy and paste the contents of the report in your reply
===================================================

aswMBR

--------------------
  • Download aswMBR and save it to your desktop.
  • Please disable your real time protection of any Antivirus, Antispyware or Antimalware programs temporarily. They will interfere and may cause unexpected results.
  • If you need help to disable your protection programs see here and here.
  • Double click the aswMBR.exe file to run it. Please allow when you are asked to download AVAST antivirus engine defs.
  • Wait until the AV update is done, then click on the Scan button to start. The program will launch a scan.

aswMBR1.png

  • When done, you will see Scan finished successfully. Please click on Save log and save the file to your desktop.

aswMBR2.png

  • Please post the contents of the log in your next reply.
NOTE: aswMBR will create MBR.dat file on your desktop. This is a copy of your MBR. Do NOT delete it.

===================================================

System Summary Information

--------------------
  • Press the windows key Windows_Logo_key.gif + r on your keyboard at the same time
  • Type msinfo32 and press Enter
  • Left click on System Summary
  • Click File, Save, and name the file Summary
  • Zip and attach the file to your reply
===================================================

Things I would like to see in your next reply. Please be sure to copy and paste any requested log information unless you are asked to attach it. :thumbsup2:
  • Do you recognize the entry?
  • Fixlog
  • RogueKiller log
  • aswMBR log
  • System Summary Information

Gary
 
If I do not reply within 24 hours please send me a Personal Message.

"Lord, to whom would we go? You have the words that give eternal life. We believe, and we know you are the Holy One of God."

#4 euanicorn

euanicorn
  • Topic Starter

  • Members
  • 12 posts
  • OFFLINE
  •  
  • Local time:08:12 AM

Posted 17 December 2015 - 09:40 AM

Hey Gary, thanks for taking the time to help me out. It's greatly appreciated, you can call me Euan.

 

If I'm not wrong the CSI.exe is probably from when I shared this computer with a girlfriend from a few years back, I think it's a game of the show. I checked the file location but there doesn't appear to be anything there but a dead shortcut and Uninstall.exe.

 

Here's Fixlog:

 

Fix result of Farbar Recovery Scan Tool (x64) Version:17-12-2015
Ran by euan (2015-12-17 13:14:13) Run:1
Running from C:\Users\euan\Desktop
Loaded Profiles: euan (Available Profiles: euan)
Boot Mode: Normal
==============================================

fixlist content:
*****************
HKU\S-1-5-21-1126527562-1434389470-3061596616-1001\...\MountPoints2: {9e9b233d-579d-11e0-a149-bcaec5df35a0} - F:\AutoRunCD.exe
HKU\S-1-5-21-1126527562-1434389470-3061596616-1001\...\MountPoints2: {a15df326-6756-11e0-82db-bcaec5df35a0} - F:\Setup.exe
HKU\S-1-5-21-1126527562-1434389470-3061596616-1001\...\MountPoints2: {fb449286-a992-11e1-96d5-bcaec5df35a0} - F:\setup.exe
SearchScopes: HKU\.DEFAULT -> DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL =
SearchScopes: HKU\S-1-5-19 -> DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL =
SearchScopes: HKU\S-1-5-20 -> DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL =
Handler: linkscanner - {F274614C-63F8-47D5-A4D1-FBDDE494F8D1} - C:\Program Files (x86)\AVG\AVG2012\avgpp.dll No File
S2 MSCamSvc; "C:\Program Files\Microsoft LifeCam\MSCamS64.exe" [X]
U4 Avgtdia; system32\DRIVERS\avgtdia.sys [X]
Task: {3599726E-3778-4ABE-BD66-B07C74A18FE0} - System32\Tasks\{971BB27B-2149-4E59-B744-2DEC1C2AF979} => pcalua.exe -a F:\SETUP.EXE -d F:\
File: C:\Windows\CSI New York\uninstall.exe
*****************

"HKU\S-1-5-21-1126527562-1434389470-3061596616-1001\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{9e9b233d-579d-11e0-a149-bcaec5df35a0}" => key removed successfully
HKCR\CLSID\{9e9b233d-579d-11e0-a149-bcaec5df35a0} => key not found.
"HKU\S-1-5-21-1126527562-1434389470-3061596616-1001\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{a15df326-6756-11e0-82db-bcaec5df35a0}" => key removed successfully
HKCR\CLSID\{a15df326-6756-11e0-82db-bcaec5df35a0} => key not found.
"HKU\S-1-5-21-1126527562-1434389470-3061596616-1001\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{fb449286-a992-11e1-96d5-bcaec5df35a0}" => key removed successfully
HKCR\CLSID\{fb449286-a992-11e1-96d5-bcaec5df35a0} => key not found.
HKU\.DEFAULT\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\\DefaultScope => value removed successfully
HKU\S-1-5-19\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\\DefaultScope => value removed successfully
HKU\S-1-5-20\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\\DefaultScope => value removed successfully
"HKCR\PROTOCOLS\Handler\linkscanner" => key removed successfully
"HKCR\CLSID\{F274614C-63F8-47D5-A4D1-FBDDE494F8D1}" => key removed successfully
MSCamSvc => service removed successfully
Avgtdia => service not found.
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain\{3599726E-3778-4ABE-BD66-B07C74A18FE0}" => key removed successfully
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{3599726E-3778-4ABE-BD66-B07C74A18FE0}" => key removed successfully
C:\Windows\System32\Tasks\{971BB27B-2149-4E59-B744-2DEC1C2AF979} => moved successfully
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\{971BB27B-2149-4E59-B744-2DEC1C2AF979}" => key removed successfully

========================= File: C:\Windows\CSI New York\uninstall.exe ========================

File not signed
MD5: 76DA2C7C124183ACF74251DB2A336A79
Creation and modification date: 2012-06-27 17:35 - 2012-06-27 17:35
Size: 0577024
Attributes: ----A
Company Name:
Internal Name: suf80_rt
Original Name: suf80_rt.exe
Product: Setup Factory 8.0 Runtime
Description: Setup Application
File Version: 8.1.1006.0
Product Version: 8.1.1006.0
Copyright: Runtime Engine Copyright © 2008 Indigo Rose Corporation (www.indigorose.com)

====== End of File: ======


==== End of Fixlog 13:14:13 ====

 

 

 

Here's Roguekiller:

 

RogueKiller V11.0.3.0 [Dec 14 2015] (Free) by Adlice Software
mail : http://www.adlice.com/contact/
Feedback : http://forum.adlice.com
Website : http://www.adlice.com/software/roguekiller/
Blog : http://www.adlice.com

Operating System : Windows 7 (6.1.7601 Service Pack 1) 64 bits version
Started in : Normal mode
User : euan [Administrator]
Started from : C:\Users\euan\Desktop\RogueKiller.exe
Mode : Scan -- Date : 12/17/2015 13:38:49

¤¤¤ Processes : 0 ¤¤¤

¤¤¤ Registry : 3 ¤¤¤
[PUM.Dns] (X64) HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\Tcpip\Parameters\Interfaces\{7E1F3EA3-0209-4920-B785-4CC8096B6F93} | DhcpNameServer : 44.0.0.253 44.0.0.3 44.0.0.4 4.2.2.1 ([X][X][UNITED STATES (US)][-])  -> Found
[PUM.Dns] (X64) HKEY_LOCAL_MACHINE\System\ControlSet001\Services\Tcpip\Parameters\Interfaces\{7E1F3EA3-0209-4920-B785-4CC8096B6F93} | DhcpNameServer : 44.0.0.253 44.0.0.3 44.0.0.4 4.2.2.1 ([UNITED STATES (US)][UNITED STATES (US)][UNITED STATES (US)][-])  -> Found
[PUM.Dns] (X64) HKEY_LOCAL_MACHINE\System\ControlSet002\Services\Tcpip\Parameters\Interfaces\{7E1F3EA3-0209-4920-B785-4CC8096B6F93} | DhcpNameServer : 44.0.0.253 44.0.0.3 44.0.0.4 4.2.2.1 ([UNITED STATES (US)][UNITED STATES (US)][UNITED STATES (US)][-])  -> Found

¤¤¤ Tasks : 0 ¤¤¤

¤¤¤ Files : 0 ¤¤¤

¤¤¤ Hosts File : 79 ¤¤¤
[C:\Windows\System32\drivers\etc\hosts] 127.0.0.1 0.0.0.0.0
[C:\Windows\System32\drivers\etc\hosts] 127.0.0.1 0.0.0.0.0
[C:\Windows\System32\drivers\etc\hosts] 127.0.0.1 0.0.0.0.0
[C:\Windows\System32\drivers\etc\hosts] 127.0.0.1 0.0.0.0.0
[C:\Windows\System32\drivers\etc\hosts] 127.0.0.1 0.0.0.0.0
[C:\Windows\System32\drivers\etc\hosts] 127.0.0.1 0.0.0.0.0
[C:\Windows\System32\drivers\etc\hosts] 127.0.0.1 0.0.0.0.0
[C:\Windows\System32\drivers\etc\hosts] 127.0.0.1 0.0.0.0.0
[C:\Windows\System32\drivers\etc\hosts] 127.0.0.1 0.0.0.0.0
[C:\Windows\System32\drivers\etc\hosts] 127.0.0.1 m.fr.a2dfp.net
[C:\Windows\System32\drivers\etc\hosts] 127.0.0.1 mfr.a2dfp.net
[C:\Windows\System32\drivers\etc\hosts] 127.0.0.1 ad.a8.net
[C:\Windows\System32\drivers\etc\hosts] 127.0.0.1 asy.a8ww.net
[C:\Windows\System32\drivers\etc\hosts] 127.0.0.1 static.a-ads.com
[C:\Windows\System32\drivers\etc\hosts] 127.0.0.1 atlas.aamedia.ro
[C:\Windows\System32\drivers\etc\hosts] 127.0.0.1 abcstats.com
[C:\Windows\System32\drivers\etc\hosts] 127.0.0.1 ad4.abradio.cz
[C:\Windows\System32\drivers\etc\hosts] 127.0.0.1 a.abv.bg
[C:\Windows\System32\drivers\etc\hosts] 127.0.0.1 adserver.abv.bg
[C:\Windows\System32\drivers\etc\hosts] 127.0.0.1 adv.abv.bg
[C:\Windows\System32\drivers\etc\hosts] 127.0.0.1 bimg.abv.bg
[C:\Windows\System32\drivers\etc\hosts] 127.0.0.1 ca.abv.bg
[C:\Windows\System32\drivers\etc\hosts] 127.0.0.1 www2.a-counter.kiev.ua
[C:\Windows\System32\drivers\etc\hosts] 127.0.0.1 track.acclaimnetwork.com
[C:\Windows\System32\drivers\etc\hosts] 127.0.0.1 accuserveadsystem.com
[C:\Windows\System32\drivers\etc\hosts] 127.0.0.1 www.accuserveadsystem.com
[C:\Windows\System32\drivers\etc\hosts] 127.0.0.1 achmedia.com
[C:\Windows\System32\drivers\etc\hosts] 127.0.0.1 csh.actiondesk.com
[C:\Windows\System32\drivers\etc\hosts] 127.0.0.1 ads.activepower.net
[C:\Windows\System32\drivers\etc\hosts] 127.0.0.1 app.activetrail.com
[C:\Windows\System32\drivers\etc\hosts] 127.0.0.1 stat.active24stats.nl #[Tracking.Cookie]
[C:\Windows\System32\drivers\etc\hosts] 127.0.0.1 traffic.acwebconnecting.com
[C:\Windows\System32\drivers\etc\hosts] 127.0.0.1 office.ad1.ru
[C:\Windows\System32\drivers\etc\hosts] 127.0.0.1 cms.ad2click.nl
[C:\Windows\System32\drivers\etc\hosts] 127.0.0.1 ad2games.com
[C:\Windows\System32\drivers\etc\hosts] 127.0.0.1 ads.ad2games.com
[C:\Windows\System32\drivers\etc\hosts] 127.0.0.1 content.ad20.net
[C:\Windows\System32\drivers\etc\hosts] 127.0.0.1 core.ad20.net
[C:\Windows\System32\drivers\etc\hosts] 127.0.0.1 banner.ad.nu
[C:\Windows\System32\drivers\etc\hosts] 127.0.0.1 cl21.v4.adaction.se
[C:\Windows\System32\drivers\etc\hosts] 127.0.0.1 adadvisor.net
[C:\Windows\System32\drivers\etc\hosts] 127.0.0.1 tag1.adaptiveads.com
[C:\Windows\System32\drivers\etc\hosts] 127.0.0.1 www.adbanner.ro
[C:\Windows\System32\drivers\etc\hosts] 127.0.0.1 wad.adbasket.net
[C:\Windows\System32\drivers\etc\hosts] 127.0.0.1 ad.pop1.adbn.ru
[C:\Windows\System32\drivers\etc\hosts] 127.0.0.1 ad.top1.adbn.ru
[C:\Windows\System32\drivers\etc\hosts] 127.0.0.1 ad.rich1.adbn.ru
[C:\Windows\System32\drivers\etc\hosts] 127.0.0.1 james.adbutler.de #[Tracking.Cookie]
[C:\Windows\System32\drivers\etc\hosts] 127.0.0.1 www.adbutler.de
[C:\Windows\System32\drivers\etc\hosts] 127.0.0.1 www.adchimp.com
[C:\Windows\System32\drivers\etc\hosts] 127.0.0.1 static.adclick.lt
[C:\Windows\System32\drivers\etc\hosts] 127.0.0.1 engine.adclick.lv
[C:\Windows\System32\drivers\etc\hosts] 127.0.0.1 show.adclick.lv
[C:\Windows\System32\drivers\etc\hosts] 127.0.0.1 static.adclick.lv
[C:\Windows\System32\drivers\etc\hosts] 127.0.0.1 www.adclick.lv
[C:\Windows\System32\drivers\etc\hosts] 127.0.0.1 ad-clix.com
[C:\Windows\System32\drivers\etc\hosts] 127.0.0.1 www.ad-clix.com
[C:\Windows\System32\drivers\etc\hosts] 127.0.0.1 servedby.adcombination.com
[C:\Windows\System32\drivers\etc\hosts] 127.0.0.1 adcomplete.com
[C:\Windows\System32\drivers\etc\hosts] 127.0.0.1 www.adcomplete.com
[C:\Windows\System32\drivers\etc\hosts] 127.0.0.1 adhall.com
[C:\Windows\System32\drivers\etc\hosts] 127.0.0.1 pool.adhese.be
[C:\Windows\System32\drivers\etc\hosts] 127.0.0.1 adhitzads.com
[C:\Windows\System32\drivers\etc\hosts] 127.0.0.1 ads.static.adhood.com
[C:\Windows\System32\drivers\etc\hosts] 127.0.0.1 app.pubserver.adhood.com
[C:\Windows\System32\drivers\etc\hosts] 127.0.0.1 app.winwords.adhood.com
[C:\Windows\System32\drivers\etc\hosts] 127.0.0.1 ssl3.adhost.com
[C:\Windows\System32\drivers\etc\hosts] 127.0.0.1 www2.adhost.com
[C:\Windows\System32\drivers\etc\hosts] 127.0.0.1 adfarm1.adition.com
[C:\Windows\System32\drivers\etc\hosts] 127.0.0.1 imagesrv.adition.com
[C:\Windows\System32\drivers\etc\hosts] 127.0.0.1 adblockplus.org
[C:\Windows\System32\drivers\etc\hosts] 127.0.0.1 easylist.adblockplus.org
[C:\Windows\System32\drivers\etc\hosts] 158.255.238.129 google-analytics.com
[C:\Windows\System32\drivers\etc\hosts] 158.255.238.129 www.google-analytics.com
[C:\Windows\System32\drivers\etc\hosts] 127.0.0.1 adk2cdn.cpmrocket.com
[C:\Windows\System32\drivers\etc\hosts] 127.0.0.1 c1.popads.net
[C:\Windows\System32\drivers\etc\hosts] 127.0.0.1 yieldmanager.adbooth.com
[C:\Windows\System32\drivers\etc\hosts] 127.0.0.1 www.adcash.com
[C:\Windows\System32\drivers\etc\hosts] 127.0.0.1 ads.adjalauto.com

¤¤¤ Antirootkit : 0 (Driver: Not loaded [0xc000036b]) ¤¤¤

¤¤¤ Web browsers : 0 ¤¤¤

¤¤¤ MBR Check : ¤¤¤
+++++ PhysicalDrive0: WDC WD10EARS-00Y5B1 ATA Device +++++
--- User ---
[MBR] f5d8d563f41122c3b61a278ce247b1ff
[BSP] c301fd0bac962df797a2a2d1f0fbb156 : Windows Vista/7/8|VT.Unknown MBR Code
Partition table:
0 - [ACTIVE] NTFS (0x7) [VISIBLE] Offset (sectors): 63 | Size: 953859 MB [Windows Vista/7/8 Bootstrap | Windows Vista/7/8 Bootloader]
User = LL1 ... OK
User = LL2 ... OK

+++++ PhysicalDrive1: WDC WD5000AAKS-22YGA0 ATA Device +++++
--- User ---
[MBR] ca9d96382074c9fa0f48cde619281c66
[BSP] 8d453807a0537ca50a0aa73d5f65e274 : Windows XP|VT.Unknown MBR Code
Partition table:
0 - [ACTIVE] NTFS (0x7) [VISIBLE] Offset (sectors): 63 | Size: 476939 MB [Windows XP Bootstrap | Windows XP Bootloader]
User = LL1 ... OK
User = LL2 ... OK
 

 

 

Here's aswMBR:

 

aswMBR version 1.0.1.2252 Copyright© 2014 AVAST Software
Run date: 2015-12-17 13:42:46
-----------------------------
13:42:46.837    OS Version: Windows x64 6.1.7601 Service Pack 1
13:42:46.837    Number of processors: 4 586 0x2A07
13:42:46.837    ComputerName: EUAN-PC  UserName: euan
13:42:49.468    Initialize success
13:42:49.507    VM: initialized successfully
13:42:49.508    VM: Intel CPU BiosDisabled
13:48:13.861    AVAST engine defs: 15121700
13:48:22.515    Disk 0 (boot) \Device\Harddisk0\DR0 -> \Device\Ide\IdeDeviceP2T0L0-2
13:48:22.530    Disk 0 Vendor: WDC_WD10EARS-00Y5B1 80.00A80 Size: 953869MB BusType: 3
13:48:22.530    Disk 1  \Device\Harddisk1\DR1 -> \Device\Ide\IdeDeviceP3T0L0-3
13:48:22.530    Disk 1 Vendor: WDC_WD5000AAKS-22YGA0 12.01C02 Size: 476940MB BusType: 3
13:48:22.671    Disk 0 MBR read successfully
13:48:22.671    Disk 0 MBR scan
13:48:22.671    Disk 0 Windows 7 default MBR code
13:48:22.671    Disk 0 Partition 1 80 (A) 07    HPFS/NTFS NTFS       953859 MB offset 63
13:48:22.686    Disk 0 default boot code
13:48:22.717    Disk 0 scanning C:\Windows\system32\drivers
13:48:33.669    Service scanning
13:48:55.743    Modules scanning
13:48:55.743    Disk 0 trace - called modules:
13:48:55.774    ntoskrnl.exe CLASSPNP.SYS disk.sys ACPI.sys ataport.SYS pciide.sys PCIIDEX.SYS hal.dll atapi.sys
13:48:55.774    1 nt!IofCallDriver -> \Device\Harddisk0\DR0[0xfffffa80047aa060]
13:48:55.789    3 CLASSPNP.SYS[fffff880018bc43f] -> nt!IofCallDriver -> [0xfffffa80044f3520]
13:48:55.789    5 ACPI.sys[fffff88000e0b7a1] -> nt!IofCallDriver -> \Device\Ide\IdeDeviceP2T0L0-2[0xfffffa80041bf680]
13:48:58.925    AVAST engine scan C:\Windows
13:49:02.029    AVAST engine scan C:\Windows\system32
13:52:04.831    AVAST engine scan C:\Windows\system32\drivers
13:52:16.390    AVAST engine scan C:\Users\euan
14:15:59.362    AVAST engine scan C:\ProgramData
14:19:40.040    Disk 0 statistics 5697214/0/0 @ 1.83 MB/s
14:19:40.056    Scan finished successfully
14:20:21.692    Disk 0 MBR has been saved successfully to "C:\Users\euan\Desktop\MBR.dat"
14:20:21.692    The log file has been saved successfully to "C:\Users\euan\Desktop\aswMBR.txt"

 

I've also attached Summary.nfo. I don't know if it's relevant, but the Utrack pop up was present during all of these steps. Thanks again for your time.

Attached Files



#5 Oh My!

Oh My!

    Adware and Spyware and Malware.....


  • Malware Response Instructor
  • 37,972 posts
  • OFFLINE
  •  
  • Gender:Male
  • Location:California
  • Local time:12:12 AM

Posted 17 December 2015 - 11:26 AM

Greetings Euan,

 

Can you tell me if you are currently attending a University in Southern California? Also, do you have the same issue after booting into Safe Mode with Networking?


Edited by Oh My!, 17 December 2015 - 11:29 AM.

Gary
 
If I do not reply within 24 hours please send me a Personal Message.

"Lord, to whom would we go? You have the words that give eternal life. We believe, and we know you are the Holy One of God."

#6 euanicorn

euanicorn
  • Topic Starter

  • Members
  • 12 posts
  • OFFLINE
  •  
  • Local time:08:12 AM

Posted 17 December 2015 - 05:15 PM

Hey Gary, I'm not - I'm actually in the UK. I didn't have the issue in Safe Mode, but that said the pop-up does not always appear even when booting normally.



#7 Oh My!

Oh My!

    Adware and Spyware and Malware.....


  • Malware Response Instructor
  • 37,972 posts
  • OFFLINE
  •  
  • Gender:Male
  • Location:California
  • Local time:12:12 AM

Posted 17 December 2015 - 08:16 PM

There are 2 entries in your logs that show IP addresses in California. We will remove those.

Which browser(s) are you using when you get pop ups?

Please do the following.

===================================================

Farbar's Recovery Scan Tool - Run Fix in Normal or Safe Mode

--------------------
  • Press the Windows key Windows_Logo_key.gif + r on your keyboard at the same time. Type in notepad and press Enter
  • Please copy and paste the contents of the below code box into the open notepad and save it to your desktop (<<<Important) as fixlist.txt
CreateRestorePoint:
CloseProcesses:
Tcpip\..\Interfaces\{7E1F3EA3-0209-4920-B785-4CC8096B6F93}: [DhcpNameServer] 44.0.0.253 44.0.0.3 44.0.0.4 4.2.2.1
emptytemp:
  • Launch FRST and press the Fix button just once and wait, the program will automatically launch fixlist.txt.
  • The tool will create a log on the desktop called Fixlog.txt. Please copy and paste the contents of the file in your reply.
===================================================

SUPERAntiSpyware

--------------------
  • Download SUPERAntiSpyware and save it to your Desktop
  • Double click the icon and select Next
  • Click I Agree, then Next three times
  • Click Finish
  • Click Decline to decline the Free Trial
  • Allow the program to update
  • Click Scan This Computer
  • Leave all the default setting to the left then click Complete Scan
  • Once the scan is complete click Continue
  • Uncheck Potentionally Unwanted Programs/Settings
  • Check Tracking Objects
  • Click Continue then click Continue on any warning screen
  • When completed click Continue
  • Click System Tools
  • Click Scan Logs
  • Click the magnifying glass to the right of the report dated today
  • Copy and paste the contents of the report in your reply
===================================================

Things I would like to see in your next reply. Please be sure to copy and paste any requested log information unless you are asked to attach it. :thumbsup2:
  • Browsers?
  • Fixlog
  • SUPERAntiSpyware report
  • Update on computer behavior

Gary
 
If I do not reply within 24 hours please send me a Personal Message.

"Lord, to whom would we go? You have the words that give eternal life. We believe, and we know you are the Holy One of God."

#8 euanicorn

euanicorn
  • Topic Starter

  • Members
  • 12 posts
  • OFFLINE
  •  
  • Local time:08:12 AM

Posted 18 December 2015 - 08:07 AM

Hey Gary, I use Firefox but that's actually fine at this moment. I get redirects and pop-ups to advertisements when using Steam on the store page, sorry but after a google I'm still unsure what browser that uses. The Utrack.pw pop-up actually occurs on computer start up, before any browser is even running - it's a large borderless window on the bottom right of my screen, that's always on top of what I'm doing with no way to close it. I've checked the task manager when it's there but can't see anything unusual, however I'm not sure what I'm looking for.

 

If it's relevant there's a historical note - the first problems I noticed were redirects in Firefox to advertisements, but that was literally the day before a year abroad and having come back Firefox is now fine.

 

Here's Fixlog:

 

Fix result of Farbar Recovery Scan Tool (x64) Version:17-12-2015
Ran by euan (2015-12-18 11:33:16) Run:2
Running from C:\Users\euan\Desktop
Loaded Profiles: euan (Available Profiles: euan)
Boot Mode: Normal
==============================================

fixlist content:
*****************
CreateRestorePoint:
CloseProcesses:
Tcpip\..\Interfaces\{7E1F3EA3-0209-4920-B785-4CC8096B6F93}: [DhcpNameServer] 44.0.0.253 44.0.0.3 44.0.0.4 4.2.2.1
emptytemp:
*****************

Restore point was successfully created.
Processes closed successfully.
HKLM\System\CurrentControlSet\Services\Tcpip\Parameters\Interfaces\{7E1F3EA3-0209-4920-B785-4CC8096B6F93}\\DhcpNameServer => value removed successfully
EmptyTemp: => 665.2 MB temporary data Removed.


The system needed a reboot.

==== End of Fixlog 11:34:47 ====

 

 

 

 

Here's SuperAntiSpyware:

 

SUPERAntiSpyware Scan Log
http://www.superantispyware.com

Generated 12/18/2015 at 12:48 PM

Application Version : 6.0.1210
Database Version : 12264

Scan type       : Complete Scan
Total Scan Time : 01:04:49

Operating System Information
Windows 7 Home Premium 64-bit, Service Pack 1 (Build 6.01.7601)
UAC On - Limited User

Memory items scanned      : 562
Memory threats detected   : 0
Registry items scanned    : 65332
Registry threats detected : 0
File items scanned        : 52756
File threats detected     : 676

Adware.Tracking Cookie
    cdn.adexcite.com [ C:\WINDOWS.OLD\DOCUMENTS AND SETTINGS\NUNAN\APPLICATION DATA\MACROMEDIA\FLASH PLAYER\#SHAREDOBJECTS\7RPDU2JP ]
    cdn.flashtalking.com [ C:\WINDOWS.OLD\DOCUMENTS AND SETTINGS\NUNAN\APPLICATION DATA\MACROMEDIA\FLASH PLAYER\#SHAREDOBJECTS\7RPDU2JP ]
    cdn.gigya.com [ C:\WINDOWS.OLD\DOCUMENTS AND SETTINGS\NUNAN\APPLICATION DATA\MACROMEDIA\FLASH PLAYER\#SHAREDOBJECTS\7RPDU2JP ]
    cdn.visiblemeasures.com [ C:\WINDOWS.OLD\DOCUMENTS AND SETTINGS\NUNAN\APPLICATION DATA\MACROMEDIA\FLASH PLAYER\#SHAREDOBJECTS\7RPDU2JP ]
    cdn1.telemetryverification.net [ C:\WINDOWS.OLD\DOCUMENTS AND SETTINGS\NUNAN\APPLICATION DATA\MACROMEDIA\FLASH PLAYER\#SHAREDOBJECTS\7RPDU2JP ]
    cdn2.telemetryverification.net [ C:\WINDOWS.OLD\DOCUMENTS AND SETTINGS\NUNAN\APPLICATION DATA\MACROMEDIA\FLASH PLAYER\#SHAREDOBJECTS\7RPDU2JP ]
    chibis.adotube.com [ C:\WINDOWS.OLD\DOCUMENTS AND SETTINGS\NUNAN\APPLICATION DATA\MACROMEDIA\FLASH PLAYER\#SHAREDOBJECTS\7RPDU2JP ]
    cloud.video.unrulymedia.com [ C:\WINDOWS.OLD\DOCUMENTS AND SETTINGS\NUNAN\APPLICATION DATA\MACROMEDIA\FLASH PLAYER\#SHAREDOBJECTS\7RPDU2JP ]
    ec.atdmt.com [ C:\WINDOWS.OLD\DOCUMENTS AND SETTINGS\NUNAN\APPLICATION DATA\MACROMEDIA\FLASH PLAYER\#SHAREDOBJECTS\7RPDU2JP ]
    gw.callingbanners.com [ C:\WINDOWS.OLD\DOCUMENTS AND SETTINGS\NUNAN\APPLICATION DATA\MACROMEDIA\FLASH PLAYER\#SHAREDOBJECTS\7RPDU2JP ]
    lookup.bluecava.com [ C:\WINDOWS.OLD\DOCUMENTS AND SETTINGS\NUNAN\APPLICATION DATA\MACROMEDIA\FLASH PLAYER\#SHAREDOBJECTS\7RPDU2JP ]
    s0.2mdn.net [ C:\WINDOWS.OLD\DOCUMENTS AND SETTINGS\NUNAN\APPLICATION DATA\MACROMEDIA\FLASH PLAYER\#SHAREDOBJECTS\7RPDU2JP ]
    secure-us.imrworldwide.com [ C:\WINDOWS.OLD\DOCUMENTS AND SETTINGS\NUNAN\APPLICATION DATA\MACROMEDIA\FLASH PLAYER\#SHAREDOBJECTS\7RPDU2JP ]
    serving-sys.com [ C:\WINDOWS.OLD\DOCUMENTS AND SETTINGS\NUNAN\APPLICATION DATA\MACROMEDIA\FLASH PLAYER\#SHAREDOBJECTS\7RPDU2JP ]
    spe.atdmt.com [ C:\WINDOWS.OLD\DOCUMENTS AND SETTINGS\NUNAN\APPLICATION DATA\MACROMEDIA\FLASH PLAYER\#SHAREDOBJECTS\7RPDU2JP ]
    video.flashtalking.com [ C:\WINDOWS.OLD\DOCUMENTS AND SETTINGS\NUNAN\APPLICATION DATA\MACROMEDIA\FLASH PLAYER\#SHAREDOBJECTS\7RPDU2JP ]
    vizu.com [ C:\WINDOWS.OLD\DOCUMENTS AND SETTINGS\NUNAN\APPLICATION DATA\MACROMEDIA\FLASH PLAYER\#SHAREDOBJECTS\7RPDU2JP ]
    vox-static.liverail.com [ C:\WINDOWS.OLD\DOCUMENTS AND SETTINGS\NUNAN\APPLICATION DATA\MACROMEDIA\FLASH PLAYER\#SHAREDOBJECTS\7RPDU2JP ]
    www.naiadsystems.com [ C:\WINDOWS.OLD\DOCUMENTS AND SETTINGS\NUNAN\APPLICATION DATA\MACROMEDIA\FLASH PLAYER\#SHAREDOBJECTS\7RPDU2JP ]
    www.pornhub.com [ C:\WINDOWS.OLD\DOCUMENTS AND SETTINGS\NUNAN\APPLICATION DATA\MACROMEDIA\FLASH PLAYER\#SHAREDOBJECTS\7RPDU2JP ]
    www.porntube.com [ C:\WINDOWS.OLD\DOCUMENTS AND SETTINGS\NUNAN\APPLICATION DATA\MACROMEDIA\FLASH PLAYER\#SHAREDOBJECTS\7RPDU2JP ]
    .addthis.com [ C:\WINDOWS.OLD\DOCUMENTS AND SETTINGS\NUNAN\APPLICATION DATA\MOZILLA\FIREFOX\PROFILES\EO4JXJ9N.DEFAULT\COOKIES.SQLITE ]
    .addthis.com [ C:\WINDOWS.OLD\DOCUMENTS AND SETTINGS\NUNAN\APPLICATION DATA\MOZILLA\FIREFOX\PROFILES\EO4JXJ9N.DEFAULT\COOKIES.SQLITE ]
    .atdmt.com [ C:\WINDOWS.OLD\DOCUMENTS AND SETTINGS\NUNAN\APPLICATION DATA\MOZILLA\FIREFOX\PROFILES\EO4JXJ9N.DEFAULT\COOKIES.SQLITE ]
    .atdmt.com [ C:\WINDOWS.OLD\DOCUMENTS AND SETTINGS\NUNAN\APPLICATION DATA\MOZILLA\FIREFOX\PROFILES\EO4JXJ9N.DEFAULT\COOKIES.SQLITE ]
    .doubleclick.net [ C:\WINDOWS.OLD\DOCUMENTS AND SETTINGS\NUNAN\APPLICATION DATA\MOZILLA\FIREFOX\PROFILES\EO4JXJ9N.DEFAULT\COOKIES.SQLITE ]
    .crwdcntrl.net [ C:\WINDOWS.OLD\DOCUMENTS AND SETTINGS\NUNAN\APPLICATION DATA\MOZILLA\FIREFOX\PROFILES\EO4JXJ9N.DEFAULT\COOKIES.SQLITE ]
    .crwdcntrl.net [ C:\WINDOWS.OLD\DOCUMENTS AND SETTINGS\NUNAN\APPLICATION DATA\MOZILLA\FIREFOX\PROFILES\EO4JXJ9N.DEFAULT\COOKIES.SQLITE ]
    .bluekai.com [ C:\WINDOWS.OLD\DOCUMENTS AND SETTINGS\NUNAN\APPLICATION DATA\MOZILLA\FIREFOX\PROFILES\EO4JXJ9N.DEFAULT\COOKIES.SQLITE ]
    .bluekai.com [ C:\WINDOWS.OLD\DOCUMENTS AND SETTINGS\NUNAN\APPLICATION DATA\MOZILLA\FIREFOX\PROFILES\EO4JXJ9N.DEFAULT\COOKIES.SQLITE ]
    .bluekai.com [ C:\WINDOWS.OLD\DOCUMENTS AND SETTINGS\NUNAN\APPLICATION DATA\MOZILLA\FIREFOX\PROFILES\EO4JXJ9N.DEFAULT\COOKIES.SQLITE ]
    .pubmatic.com [ C:\WINDOWS.OLD\DOCUMENTS AND SETTINGS\NUNAN\APPLICATION DATA\MOZILLA\FIREFOX\PROFILES\EO4JXJ9N.DEFAULT\COOKIES.SQLITE ]
    .pubmatic.com [ C:\WINDOWS.OLD\DOCUMENTS AND SETTINGS\NUNAN\APPLICATION DATA\MOZILLA\FIREFOX\PROFILES\EO4JXJ9N.DEFAULT\COOKIES.SQLITE ]
    d.tradex.openx.com [ C:\WINDOWS.OLD\DOCUMENTS AND SETTINGS\NUNAN\APPLICATION DATA\MOZILLA\FIREFOX\PROFILES\EO4JXJ9N.DEFAULT\COOKIES.SQLITE ]
    .openx.com [ C:\WINDOWS.OLD\DOCUMENTS AND SETTINGS\NUNAN\APPLICATION DATA\MOZILLA\FIREFOX\PROFILES\EO4JXJ9N.DEFAULT\COOKIES.SQLITE ]
    .revsci.net [ C:\WINDOWS.OLD\DOCUMENTS AND SETTINGS\NUNAN\APPLICATION DATA\MOZILLA\FIREFOX\PROFILES\EO4JXJ9N.DEFAULT\COOKIES.SQLITE ]
    ad.yieldmanager.com [ C:\WINDOWS.OLD\DOCUMENTS AND SETTINGS\NUNAN\APPLICATION DATA\MOZILLA\FIREFOX\PROFILES\EO4JXJ9N.DEFAULT\COOKIES.SQLITE ]
    ad.yieldmanager.com [ C:\WINDOWS.OLD\DOCUMENTS AND SETTINGS\NUNAN\APPLICATION DATA\MOZILLA\FIREFOX\PROFILES\EO4JXJ9N.DEFAULT\COOKIES.SQLITE ]
    ad.yieldmanager.com [ C:\WINDOWS.OLD\DOCUMENTS AND SETTINGS\NUNAN\APPLICATION DATA\MOZILLA\FIREFOX\PROFILES\EO4JXJ9N.DEFAULT\COOKIES.SQLITE ]
    ad.yieldmanager.com [ C:\WINDOWS.OLD\DOCUMENTS AND SETTINGS\NUNAN\APPLICATION DATA\MOZILLA\FIREFOX\PROFILES\EO4JXJ9N.DEFAULT\COOKIES.SQLITE ]
    .mathtag.com [ C:\WINDOWS.OLD\DOCUMENTS AND SETTINGS\NUNAN\APPLICATION DATA\MOZILLA\FIREFOX\PROFILES\EO4JXJ9N.DEFAULT\COOKIES.SQLITE ]
    pfa.levexis.com [ C:\WINDOWS.OLD\DOCUMENTS AND SETTINGS\NUNAN\APPLICATION DATA\MOZILLA\FIREFOX\PROFILES\EO4JXJ9N.DEFAULT\COOKIES.SQLITE ]
    .flashtalking.com [ C:\WINDOWS.OLD\DOCUMENTS AND SETTINGS\NUNAN\APPLICATION DATA\MOZILLA\FIREFOX\PROFILES\EO4JXJ9N.DEFAULT\COOKIES.SQLITE ]
    .scorecardresearch.com [ C:\WINDOWS.OLD\DOCUMENTS AND SETTINGS\NUNAN\APPLICATION DATA\MOZILLA\FIREFOX\PROFILES\EO4JXJ9N.DEFAULT\COOKIES.SQLITE ]
    .amgdgt.com [ C:\WINDOWS.OLD\DOCUMENTS AND SETTINGS\NUNAN\APPLICATION DATA\MOZILLA\FIREFOX\PROFILES\EO4JXJ9N.DEFAULT\COOKIES.SQLITE ]
    .adbrite.com [ C:\WINDOWS.OLD\DOCUMENTS AND SETTINGS\NUNAN\APPLICATION DATA\MOZILLA\FIREFOX\PROFILES\EO4JXJ9N.DEFAULT\COOKIES.SQLITE ]
    .triggit.com [ C:\WINDOWS.OLD\DOCUMENTS AND SETTINGS\NUNAN\APPLICATION DATA\MOZILLA\FIREFOX\PROFILES\EO4JXJ9N.DEFAULT\COOKIES.SQLITE ]
    .openx.net [ C:\WINDOWS.OLD\DOCUMENTS AND SETTINGS\NUNAN\APPLICATION DATA\MOZILLA\FIREFOX\PROFILES\EO4JXJ9N.DEFAULT\COOKIES.SQLITE ]
    .bs.serving-sys.com [ C:\WINDOWS.OLD\DOCUMENTS AND SETTINGS\NUNAN\APPLICATION DATA\MOZILLA\FIREFOX\PROFILES\EO4JXJ9N.DEFAULT\COOKIES.SQLITE ]
    .serving-sys.com [ C:\WINDOWS.OLD\DOCUMENTS AND SETTINGS\NUNAN\APPLICATION DATA\MOZILLA\FIREFOX\PROFILES\EO4JXJ9N.DEFAULT\COOKIES.SQLITE ]
    .serving-sys.com [ C:\WINDOWS.OLD\DOCUMENTS AND SETTINGS\NUNAN\APPLICATION DATA\MOZILLA\FIREFOX\PROFILES\EO4JXJ9N.DEFAULT\COOKIES.SQLITE ]
    .advertising.com [ C:\WINDOWS.OLD\DOCUMENTS AND SETTINGS\NUNAN\APPLICATION DATA\MOZILLA\FIREFOX\PROFILES\EO4JXJ9N.DEFAULT\COOKIES.SQLITE ]
    .advertising.com [ C:\WINDOWS.OLD\DOCUMENTS AND SETTINGS\NUNAN\APPLICATION DATA\MOZILLA\FIREFOX\PROFILES\EO4JXJ9N.DEFAULT\COOKIES.SQLITE ]
    .advertising.com [ C:\WINDOWS.OLD\DOCUMENTS AND SETTINGS\NUNAN\APPLICATION DATA\MOZILLA\FIREFOX\PROFILES\EO4JXJ9N.DEFAULT\COOKIES.SQLITE ]
    .advertising.com [ C:\WINDOWS.OLD\DOCUMENTS AND SETTINGS\NUNAN\APPLICATION DATA\MOZILLA\FIREFOX\PROFILES\EO4JXJ9N.DEFAULT\COOKIES.SQLITE ]
    .yieldmanager.net [ C:\WINDOWS.OLD\DOCUMENTS AND SETTINGS\NUNAN\APPLICATION DATA\MOZILLA\FIREFOX\PROFILES\EO4JXJ9N.DEFAULT\COOKIES.SQLITE ]
    .adtech.de [ C:\WINDOWS.OLD\DOCUMENTS AND SETTINGS\NUNAN\APPLICATION DATA\MOZILLA\FIREFOX\PROFILES\EO4JXJ9N.DEFAULT\COOKIES.SQLITE ]
    .adbrite.com [ C:\WINDOWS.OLD\DOCUMENTS AND SETTINGS\NUNAN\APPLICATION DATA\MOZILLA\FIREFOX\PROFILES\EO4JXJ9N.DEFAULT\COOKIES.SQLITE ]
    .adbrite.com [ C:\WINDOWS.OLD\DOCUMENTS AND SETTINGS\NUNAN\APPLICATION DATA\MOZILLA\FIREFOX\PROFILES\EO4JXJ9N.DEFAULT\COOKIES.SQLITE ]
    optimize.indieclick.com [ C:\WINDOWS.OLD\DOCUMENTS AND SETTINGS\NUNAN\APPLICATION DATA\MOZILLA\FIREFOX\PROFILES\EO4JXJ9N.DEFAULT\COOKIES.SQLITE ]
    .pubmatic.com [ C:\WINDOWS.OLD\DOCUMENTS AND SETTINGS\NUNAN\APPLICATION DATA\MOZILLA\FIREFOX\PROFILES\EO4JXJ9N.DEFAULT\COOKIES.SQLITE ]
    .imrworldwide.com [ C:\WINDOWS.OLD\DOCUMENTS AND SETTINGS\NUNAN\APPLICATION DATA\MOZILLA\FIREFOX\PROFILES\EO4JXJ9N.DEFAULT\COOKIES.SQLITE ]
    .imrworldwide.com [ C:\WINDOWS.OLD\DOCUMENTS AND SETTINGS\NUNAN\APPLICATION DATA\MOZILLA\FIREFOX\PROFILES\EO4JXJ9N.DEFAULT\COOKIES.SQLITE ]
    .mookie1.com [ C:\WINDOWS.OLD\DOCUMENTS AND SETTINGS\NUNAN\APPLICATION DATA\MOZILLA\FIREFOX\PROFILES\EO4JXJ9N.DEFAULT\COOKIES.SQLITE ]
    .mookie1.com [ C:\WINDOWS.OLD\DOCUMENTS AND SETTINGS\NUNAN\APPLICATION DATA\MOZILLA\FIREFOX\PROFILES\EO4JXJ9N.DEFAULT\COOKIES.SQLITE ]
    .nexac.com [ C:\WINDOWS.OLD\DOCUMENTS AND SETTINGS\NUNAN\APPLICATION DATA\MOZILLA\FIREFOX\PROFILES\EO4JXJ9N.DEFAULT\COOKIES.SQLITE ]
    .questionablecontent.net [ C:\WINDOWS.OLD\DOCUMENTS AND SETTINGS\NUNAN\APPLICATION DATA\MOZILLA\FIREFOX\PROFILES\EO4JXJ9N.DEFAULT\COOKIES.SQLITE ]
    .apmebf.com [ C:\WINDOWS.OLD\DOCUMENTS AND SETTINGS\NUNAN\APPLICATION DATA\MOZILLA\FIREFOX\PROFILES\EO4JXJ9N.DEFAULT\COOKIES.SQLITE ]
    .mediaplex.com [ C:\WINDOWS.OLD\DOCUMENTS AND SETTINGS\NUNAN\APPLICATION DATA\MOZILLA\FIREFOX\PROFILES\EO4JXJ9N.DEFAULT\COOKIES.SQLITE ]
    .mediaplex.com [ C:\WINDOWS.OLD\DOCUMENTS AND SETTINGS\NUNAN\APPLICATION DATA\MOZILLA\FIREFOX\PROFILES\EO4JXJ9N.DEFAULT\COOKIES.SQLITE ]
    .questionablecontent.net [ C:\WINDOWS.OLD\DOCUMENTS AND SETTINGS\NUNAN\APPLICATION DATA\MOZILLA\FIREFOX\PROFILES\EO4JXJ9N.DEFAULT\COOKIES.SQLITE ]
    .media6degrees.com [ C:\WINDOWS.OLD\DOCUMENTS AND SETTINGS\NUNAN\APPLICATION DATA\MOZILLA\FIREFOX\PROFILES\EO4JXJ9N.DEFAULT\COOKIES.SQLITE ]
    .media6degrees.com [ C:\WINDOWS.OLD\DOCUMENTS AND SETTINGS\NUNAN\APPLICATION DATA\MOZILLA\FIREFOX\PROFILES\EO4JXJ9N.DEFAULT\COOKIES.SQLITE ]
    .adxpose.com [ C:\WINDOWS.OLD\DOCUMENTS AND SETTINGS\NUNAN\APPLICATION DATA\MOZILLA\FIREFOX\PROFILES\EO4JXJ9N.DEFAULT\COOKIES.SQLITE ]
    .b3-uk.mookie1.com [ C:\WINDOWS.OLD\DOCUMENTS AND SETTINGS\NUNAN\APPLICATION DATA\MOZILLA\FIREFOX\PROFILES\EO4JXJ9N.DEFAULT\COOKIES.SQLITE ]
    .abmr.net [ C:\WINDOWS.OLD\DOCUMENTS AND SETTINGS\NUNAN\APPLICATION DATA\MOZILLA\FIREFOX\PROFILES\EO4JXJ9N.DEFAULT\COOKIES.SQLITE ]
    w55c.net [ C:\WINDOWS.OLD\DOCUMENTS AND SETTINGS\NUNAN\APPLICATION DATA\MOZILLA\FIREFOX\PROFILES\EO4JXJ9N.DEFAULT\COOKIES.SQLITE ]
    .rubiconproject.com [ C:\WINDOWS.OLD\DOCUMENTS AND SETTINGS\NUNAN\APPLICATION DATA\MOZILLA\FIREFOX\PROFILES\EO4JXJ9N.DEFAULT\COOKIES.SQLITE ]
    .rubiconproject.com [ C:\WINDOWS.OLD\DOCUMENTS AND SETTINGS\NUNAN\APPLICATION DATA\MOZILLA\FIREFOX\PROFILES\EO4JXJ9N.DEFAULT\COOKIES.SQLITE ]
    tap.rubiconproject.com [ C:\WINDOWS.OLD\DOCUMENTS AND SETTINGS\NUNAN\APPLICATION DATA\MOZILLA\FIREFOX\PROFILES\EO4JXJ9N.DEFAULT\COOKIES.SQLITE ]
    .bluekai.com [ C:\WINDOWS.OLD\DOCUMENTS AND SETTINGS\NUNAN\APPLICATION DATA\MOZILLA\FIREFOX\PROFILES\EO4JXJ9N.DEFAULT\COOKIES.SQLITE ]
    .pubmatic.com [ C:\WINDOWS.OLD\DOCUMENTS AND SETTINGS\NUNAN\APPLICATION DATA\MOZILLA\FIREFOX\PROFILES\EO4JXJ9N.DEFAULT\COOKIES.SQLITE ]
    .ru4.com [ C:\WINDOWS.OLD\DOCUMENTS AND SETTINGS\NUNAN\APPLICATION DATA\MOZILLA\FIREFOX\PROFILES\EO4JXJ9N.DEFAULT\COOKIES.SQLITE ]
    .ru4.com [ C:\WINDOWS.OLD\DOCUMENTS AND SETTINGS\NUNAN\APPLICATION DATA\MOZILLA\FIREFOX\PROFILES\EO4JXJ9N.DEFAULT\COOKIES.SQLITE ]
    .pubmatic.com [ C:\WINDOWS.OLD\DOCUMENTS AND SETTINGS\NUNAN\APPLICATION DATA\MOZILLA\FIREFOX\PROFILES\EO4JXJ9N.DEFAULT\COOKIES.SQLITE ]
    .interclick.com [ C:\WINDOWS.OLD\DOCUMENTS AND SETTINGS\NUNAN\APPLICATION DATA\MOZILLA\FIREFOX\PROFILES\EO4JXJ9N.DEFAULT\COOKIES.SQLITE ]
    .interclick.com [ C:\WINDOWS.OLD\DOCUMENTS AND SETTINGS\NUNAN\APPLICATION DATA\MOZILLA\FIREFOX\PROFILES\EO4JXJ9N.DEFAULT\COOKIES.SQLITE ]
    breakmedia.checkm8.com [ C:\WINDOWS.OLD\DOCUMENTS AND SETTINGS\NUNAN\APPLICATION DATA\MOZILLA\FIREFOX\PROFILES\EO4JXJ9N.DEFAULT\COOKIES.SQLITE ]
    breakmedia.checkm8.com [ C:\WINDOWS.OLD\DOCUMENTS AND SETTINGS\NUNAN\APPLICATION DATA\MOZILLA\FIREFOX\PROFILES\EO4JXJ9N.DEFAULT\COOKIES.SQLITE ]
    breakmedia.checkm8.com [ C:\WINDOWS.OLD\DOCUMENTS AND SETTINGS\NUNAN\APPLICATION DATA\MOZILLA\FIREFOX\PROFILES\EO4JXJ9N.DEFAULT\COOKIES.SQLITE ]
    .specificclick.net [ C:\WINDOWS.OLD\DOCUMENTS AND SETTINGS\NUNAN\APPLICATION DATA\MOZILLA\FIREFOX\PROFILES\EO4JXJ9N.DEFAULT\COOKIES.SQLITE ]
    .specificclick.net [ C:\WINDOWS.OLD\DOCUMENTS AND SETTINGS\NUNAN\APPLICATION DATA\MOZILLA\FIREFOX\PROFILES\EO4JXJ9N.DEFAULT\COOKIES.SQLITE ]
    .specificclick.net [ C:\WINDOWS.OLD\DOCUMENTS AND SETTINGS\NUNAN\APPLICATION DATA\MOZILLA\FIREFOX\PROFILES\EO4JXJ9N.DEFAULT\COOKIES.SQLITE ]
    .specificclick.net [ C:\WINDOWS.OLD\DOCUMENTS AND SETTINGS\NUNAN\APPLICATION DATA\MOZILLA\FIREFOX\PROFILES\EO4JXJ9N.DEFAULT\COOKIES.SQLITE ]
    .weborama.fr [ C:\WINDOWS.OLD\DOCUMENTS AND SETTINGS\NUNAN\APPLICATION DATA\MOZILLA\FIREFOX\PROFILES\EO4JXJ9N.DEFAULT\COOKIES.SQLITE ]
    .casalemedia.com [ C:\WINDOWS.OLD\DOCUMENTS AND SETTINGS\NUNAN\APPLICATION DATA\MOZILLA\FIREFOX\PROFILES\EO4JXJ9N.DEFAULT\COOKIES.SQLITE ]
    .zedo.com [ C:\WINDOWS.OLD\DOCUMENTS AND SETTINGS\NUNAN\APPLICATION DATA\MOZILLA\FIREFOX\PROFILES\EO4JXJ9N.DEFAULT\COOKIES.SQLITE ]
    .w55c.net [ C:\WINDOWS.OLD\DOCUMENTS AND SETTINGS\NUNAN\APPLICATION DATA\MOZILLA\FIREFOX\PROFILES\EO4JXJ9N.DEFAULT\COOKIES.SQLITE ]
    .voicefive.com [ C:\WINDOWS.OLD\DOCUMENTS AND SETTINGS\NUNAN\APPLICATION DATA\MOZILLA\FIREFOX\PROFILES\EO4JXJ9N.DEFAULT\COOKIES.SQLITE ]
    .collective-media.net [ C:\WINDOWS.OLD\DOCUMENTS AND SETTINGS\NUNAN\APPLICATION DATA\MOZILLA\FIREFOX\PROFILES\EO4JXJ9N.DEFAULT\COOKIES.SQLITE ]
    .adviva.net [ C:\WINDOWS.OLD\DOCUMENTS AND SETTINGS\NUNAN\APPLICATION DATA\MOZILLA\FIREFOX\PROFILES\EO4JXJ9N.DEFAULT\COOKIES.SQLITE ]
    .adviva.net [ C:\WINDOWS.OLD\DOCUMENTS AND SETTINGS\NUNAN\APPLICATION DATA\MOZILLA\FIREFOX\PROFILES\EO4JXJ9N.DEFAULT\COOKIES.SQLITE ]
    .advertising.com [ C:\WINDOWS.OLD\DOCUMENTS AND SETTINGS\NUNAN\APPLICATION DATA\MOZILLA\FIREFOX\PROFILES\EO4JXJ9N.DEFAULT\COOKIES.SQLITE ]
    .fastclick.net [ C:\WINDOWS.OLD\DOCUMENTS AND SETTINGS\NUNAN\APPLICATION DATA\MOZILLA\FIREFOX\PROFILES\EO4JXJ9N.DEFAULT\COOKIES.SQLITE ]
    .fastclick.net [ C:\WINDOWS.OLD\DOCUMENTS AND SETTINGS\NUNAN\APPLICATION DATA\MOZILLA\FIREFOX\PROFILES\EO4JXJ9N.DEFAULT\COOKIES.SQLITE ]
    .adotube.com [ C:\WINDOWS.OLD\DOCUMENTS AND SETTINGS\NUNAN\APPLICATION DATA\MOZILLA\FIREFOX\PROFILES\EO4JXJ9N.DEFAULT\COOKIES.SQLITE ]
    m.webtrends.com [ C:\WINDOWS.OLD\DOCUMENTS AND SETTINGS\NUNAN\APPLICATION DATA\MOZILLA\FIREFOX\PROFILES\EO4JXJ9N.DEFAULT\COOKIES.SQLITE ]
    .simpli.fi [ C:\WINDOWS.OLD\DOCUMENTS AND SETTINGS\NUNAN\APPLICATION DATA\MOZILLA\FIREFOX\PROFILES\EO4JXJ9N.DEFAULT\COOKIES.SQLITE ]
    .turn.com [ C:\WINDOWS.OLD\DOCUMENTS AND SETTINGS\NUNAN\APPLICATION DATA\MOZILLA\FIREFOX\PROFILES\EO4JXJ9N.DEFAULT\COOKIES.SQLITE ]
    .turn.com [ C:\WINDOWS.OLD\DOCUMENTS AND SETTINGS\NUNAN\APPLICATION DATA\MOZILLA\FIREFOX\PROFILES\EO4JXJ9N.DEFAULT\COOKIES.SQLITE ]
    .turn.com [ C:\WINDOWS.OLD\DOCUMENTS AND SETTINGS\NUNAN\APPLICATION DATA\MOZILLA\FIREFOX\PROFILES\EO4JXJ9N.DEFAULT\COOKIES.SQLITE ]
    .turn.com [ C:\WINDOWS.OLD\DOCUMENTS AND SETTINGS\NUNAN\APPLICATION DATA\MOZILLA\FIREFOX\PROFILES\EO4JXJ9N.DEFAULT\COOKIES.SQLITE ]
    .pubmatic.com [ C:\WINDOWS.OLD\DOCUMENTS AND SETTINGS\NUNAN\APPLICATION DATA\MOZILLA\FIREFOX\PROFILES\EO4JXJ9N.DEFAULT\COOKIES.SQLITE ]
    .pubmatic.com [ C:\WINDOWS.OLD\DOCUMENTS AND SETTINGS\NUNAN\APPLICATION DATA\MOZILLA\FIREFOX\PROFILES\EO4JXJ9N.DEFAULT\COOKIES.SQLITE ]
    .adecn.com [ C:\WINDOWS.OLD\DOCUMENTS AND SETTINGS\NUNAN\APPLICATION DATA\MOZILLA\FIREFOX\PROFILES\EO4JXJ9N.DEFAULT\COOKIES.SQLITE ]
    .contextweb.com [ C:\WINDOWS.OLD\DOCUMENTS AND SETTINGS\NUNAN\APPLICATION DATA\MOZILLA\FIREFOX\PROFILES\EO4JXJ9N.DEFAULT\COOKIES.SQLITE ]
    .msnportal.112.2o7.net [ C:\WINDOWS.OLD\DOCUMENTS AND SETTINGS\NUNAN\APPLICATION DATA\MOZILLA\FIREFOX\PROFILES\EO4JXJ9N.DEFAULT\COOKIES.SQLITE ]
    .fastclick.net [ C:\WINDOWS.OLD\DOCUMENTS AND SETTINGS\NUNAN\APPLICATION DATA\MOZILLA\FIREFOX\PROFILES\EO4JXJ9N.DEFAULT\COOKIES.SQLITE ]
    .specificclick.net [ C:\WINDOWS.OLD\DOCUMENTS AND SETTINGS\NUNAN\APPLICATION DATA\MOZILLA\FIREFOX\PROFILES\EO4JXJ9N.DEFAULT\COOKIES.SQLITE ]
    .specificclick.net [ C:\WINDOWS.OLD\DOCUMENTS AND SETTINGS\NUNAN\APPLICATION DATA\MOZILLA\FIREFOX\PROFILES\EO4JXJ9N.DEFAULT\COOKIES.SQLITE ]
    .specificclick.net [ C:\WINDOWS.OLD\DOCUMENTS AND SETTINGS\NUNAN\APPLICATION DATA\MOZILLA\FIREFOX\PROFILES\EO4JXJ9N.DEFAULT\COOKIES.SQLITE ]
    .specificclick.net [ C:\WINDOWS.OLD\DOCUMENTS AND SETTINGS\NUNAN\APPLICATION DATA\MOZILLA\FIREFOX\PROFILES\EO4JXJ9N.DEFAULT\COOKIES.SQLITE ]
    api.choicestream.com [ C:\WINDOWS.OLD\DOCUMENTS AND SETTINGS\NUNAN\APPLICATION DATA\MOZILLA\FIREFOX\PROFILES\EO4JXJ9N.DEFAULT\COOKIES.SQLITE ]
    .2o7.net [ C:\WINDOWS.OLD\DOCUMENTS AND SETTINGS\NUNAN\APPLICATION DATA\MOZILLA\FIREFOX\PROFILES\EO4JXJ9N.DEFAULT\COOKIES.SQLITE ]
    .viacom.adbureau.net [ C:\WINDOWS.OLD\DOCUMENTS AND SETTINGS\NUNAN\APPLICATION DATA\MOZILLA\FIREFOX\PROFILES\EO4JXJ9N.DEFAULT\COOKIES.SQLITE ]
    .ads.pointroll.com [ C:\WINDOWS.OLD\DOCUMENTS AND SETTINGS\NUNAN\APPLICATION DATA\MOZILLA\FIREFOX\PROFILES\EO4JXJ9N.DEFAULT\COOKIES.SQLITE ]
    .pointroll.com [ C:\WINDOWS.OLD\DOCUMENTS AND SETTINGS\NUNAN\APPLICATION DATA\MOZILLA\FIREFOX\PROFILES\EO4JXJ9N.DEFAULT\COOKIES.SQLITE ]
    .pointroll.com [ C:\WINDOWS.OLD\DOCUMENTS AND SETTINGS\NUNAN\APPLICATION DATA\MOZILLA\FIREFOX\PROFILES\EO4JXJ9N.DEFAULT\COOKIES.SQLITE ]
    .ads.pointroll.com [ C:\WINDOWS.OLD\DOCUMENTS AND SETTINGS\NUNAN\APPLICATION DATA\MOZILLA\FIREFOX\PROFILES\EO4JXJ9N.DEFAULT\COOKIES.SQLITE ]
    .ads.pointroll.com [ C:\WINDOWS.OLD\DOCUMENTS AND SETTINGS\NUNAN\APPLICATION DATA\MOZILLA\FIREFOX\PROFILES\EO4JXJ9N.DEFAULT\COOKIES.SQLITE ]
    .ads.pointroll.com [ C:\WINDOWS.OLD\DOCUMENTS AND SETTINGS\NUNAN\APPLICATION DATA\MOZILLA\FIREFOX\PROFILES\EO4JXJ9N.DEFAULT\COOKIES.SQLITE ]
    .ads.pointroll.com [ C:\WINDOWS.OLD\DOCUMENTS AND SETTINGS\NUNAN\APPLICATION DATA\MOZILLA\FIREFOX\PROFILES\EO4JXJ9N.DEFAULT\COOKIES.SQLITE ]
    .ads.pointroll.com [ C:\WINDOWS.OLD\DOCUMENTS AND SETTINGS\NUNAN\APPLICATION DATA\MOZILLA\FIREFOX\PROFILES\EO4JXJ9N.DEFAULT\COOKIES.SQLITE ]
    .ads.pointroll.com [ C:\WINDOWS.OLD\DOCUMENTS AND SETTINGS\NUNAN\APPLICATION DATA\MOZILLA\FIREFOX\PROFILES\EO4JXJ9N.DEFAULT\COOKIES.SQLITE ]
    .2o7.net [ C:\WINDOWS.OLD\DOCUMENTS AND SETTINGS\NUNAN\APPLICATION DATA\MOZILLA\FIREFOX\PROFILES\EO4JXJ9N.DEFAULT\COOKIES.SQLITE ]
    display.provenpixel.com [ C:\WINDOWS.OLD\DOCUMENTS AND SETTINGS\NUNAN\APPLICATION DATA\MOZILLA\FIREFOX\PROFILES\EO4JXJ9N.DEFAULT\COOKIES.SQLITE ]
    .openx.net [ C:\WINDOWS.OLD\DOCUMENTS AND SETTINGS\NUNAN\APPLICATION DATA\MOZILLA\FIREFOX\PROFILES\EO4JXJ9N.DEFAULT\COOKIES.SQLITE ]
    .tradedoubler.com [ C:\WINDOWS.OLD\DOCUMENTS AND SETTINGS\NUNAN\APPLICATION DATA\MOZILLA\FIREFOX\PROFILES\EO4JXJ9N.DEFAULT\COOKIES.SQLITE ]
    .tradedoubler.com [ C:\WINDOWS.OLD\DOCUMENTS AND SETTINGS\NUNAN\APPLICATION DATA\MOZILLA\FIREFOX\PROFILES\EO4JXJ9N.DEFAULT\COOKIES.SQLITE ]
    .tradedoubler.com [ C:\WINDOWS.OLD\DOCUMENTS AND SETTINGS\NUNAN\APPLICATION DATA\MOZILLA\FIREFOX\PROFILES\EO4JXJ9N.DEFAULT\COOKIES.SQLITE ]
    display.provenpixel.com [ C:\WINDOWS.OLD\DOCUMENTS AND SETTINGS\NUNAN\APPLICATION DATA\MOZILLA\FIREFOX\PROFILES\EO4JXJ9N.DEFAULT\COOKIES.SQLITE ]
    .zedo.com [ C:\WINDOWS.OLD\DOCUMENTS AND SETTINGS\NUNAN\APPLICATION DATA\MOZILLA\FIREFOX\PROFILES\EO4JXJ9N.DEFAULT\COOKIES.SQLITE ]
    .crwdcntrl.net [ C:\WINDOWS.OLD\DOCUMENTS AND SETTINGS\NUNAN\APPLICATION DATA\MOZILLA\FIREFOX\PROFILES\EO4JXJ9N.DEFAULT\COOKIES.SQLITE ]
    .crwdcntrl.net [ C:\WINDOWS.OLD\DOCUMENTS AND SETTINGS\NUNAN\APPLICATION DATA\MOZILLA\FIREFOX\PROFILES\EO4JXJ9N.DEFAULT\COOKIES.SQLITE ]
    .avgtechnologies.112.2o7.net [ C:\WINDOWS.OLD\DOCUMENTS AND SETTINGS\NUNAN\APPLICATION DATA\MOZILLA\FIREFOX\PROFILES\EO4JXJ9N.DEFAULT\COOKIES.SQLITE ]
    .trafficmp.com [ C:\WINDOWS.OLD\DOCUMENTS AND SETTINGS\NUNAN\APPLICATION DATA\MOZILLA\FIREFOX\PROFILES\EO4JXJ9N.DEFAULT\COOKIES.SQLITE ]
    .trafficmp.com [ C:\WINDOWS.OLD\DOCUMENTS AND SETTINGS\NUNAN\APPLICATION DATA\MOZILLA\FIREFOX\PROFILES\EO4JXJ9N.DEFAULT\COOKIES.SQLITE ]
    .tracking.foxnews.com [ C:\WINDOWS.OLD\DOCUMENTS AND SETTINGS\NUNAN\APPLICATION DATA\MOZILLA\FIREFOX\PROFILES\EO4JXJ9N.DEFAULT\COOKIES.SQLITE ]
    .tracking.foxnews.com [ C:\WINDOWS.OLD\DOCUMENTS AND SETTINGS\NUNAN\APPLICATION DATA\MOZILLA\FIREFOX\PROFILES\EO4JXJ9N.DEFAULT\COOKIES.SQLITE ]
    .kontera.com [ C:\WINDOWS.OLD\DOCUMENTS AND SETTINGS\NUNAN\APPLICATION DATA\MOZILLA\FIREFOX\PROFILES\EO4JXJ9N.DEFAULT\COOKIES.SQLITE ]
    .videoegg.adbureau.net [ C:\WINDOWS.OLD\DOCUMENTS AND SETTINGS\NUNAN\APPLICATION DATA\MOZILLA\FIREFOX\PROFILES\EO4JXJ9N.DEFAULT\COOKIES.SQLITE ]
    .adfarm1.adition.com [ C:\WINDOWS.OLD\DOCUMENTS AND SETTINGS\NUNAN\APPLICATION DATA\MOZILLA\FIREFOX\PROFILES\EO4JXJ9N.DEFAULT\COOKIES.SQLITE ]
    ad.zanox.com [ C:\WINDOWS.OLD\DOCUMENTS AND SETTINGS\NUNAN\APPLICATION DATA\MOZILLA\FIREFOX\PROFILES\EO4JXJ9N.DEFAULT\COOKIES.SQLITE ]
    .fwmrm.net [ C:\WINDOWS.OLD\DOCUMENTS AND SETTINGS\NUNAN\APPLICATION DATA\MOZILLA\FIREFOX\PROFILES\EO4JXJ9N.DEFAULT\COOKIES.SQLITE ]
    clickbangpop.com [ C:\WINDOWS.OLD\DOCUMENTS AND SETTINGS\NUNAN\APPLICATION DATA\MOZILLA\FIREFOX\PROFILES\EO4JXJ9N.DEFAULT\COOKIES.SQLITE ]
    .crwdcntrl.net [ C:\WINDOWS.OLD\DOCUMENTS AND SETTINGS\NUNAN\APPLICATION DATA\MOZILLA\FIREFOX\PROFILES\EO4JXJ9N.DEFAULT\COOKIES.SQLITE ]
    .media6degrees.com [ C:\WINDOWS.OLD\DOCUMENTS AND SETTINGS\NUNAN\APPLICATION DATA\MOZILLA\FIREFOX\PROFILES\EO4JXJ9N.DEFAULT\COOKIES.SQLITE ]
    .gigya.com [ C:\WINDOWS.OLD\DOCUMENTS AND SETTINGS\NUNAN\APPLICATION DATA\MOZILLA\FIREFOX\PROFILES\EO4JXJ9N.DEFAULT\COOKIES.SQLITE ]
    ads.ad4game.com [ C:\WINDOWS.OLD\DOCUMENTS AND SETTINGS\NUNAN\APPLICATION DATA\MOZILLA\FIREFOX\PROFILES\EO4JXJ9N.DEFAULT\COOKIES.SQLITE ]
    .adserver.adtechus.com [ C:\WINDOWS.OLD\DOCUMENTS AND SETTINGS\NUNAN\APPLICATION DATA\MOZILLA\FIREFOX\PROFILES\EO4JXJ9N.DEFAULT\COOKIES.SQLITE ]
    .statcounter.com [ C:\WINDOWS.OLD\DOCUMENTS AND SETTINGS\NUNAN\APPLICATION DATA\MOZILLA\FIREFOX\PROFILES\EO4JXJ9N.DEFAULT\COOKIES.SQLITE ]
    .yadro.ru [ C:\WINDOWS.OLD\DOCUMENTS AND SETTINGS\NUNAN\APPLICATION DATA\MOZILLA\FIREFOX\PROFILES\EO4JXJ9N.DEFAULT\COOKIES.SQLITE ]
    .sensic.net [ C:\WINDOWS.OLD\DOCUMENTS AND SETTINGS\NUNAN\APPLICATION DATA\MOZILLA\FIREFOX\PROFILES\EO4JXJ9N.DEFAULT\COOKIES.SQLITE ]
    .tracking.agenzy.com [ C:\WINDOWS.OLD\DOCUMENTS AND SETTINGS\NUNAN\APPLICATION DATA\MOZILLA\FIREFOX\PROFILES\EO4JXJ9N.DEFAULT\COOKIES.SQLITE ]
    .questionmarket.com [ C:\WINDOWS.OLD\DOCUMENTS AND SETTINGS\NUNAN\APPLICATION DATA\MOZILLA\FIREFOX\PROFILES\EO4JXJ9N.DEFAULT\COOKIES.SQLITE ]
    .media6degrees.com [ C:\WINDOWS.OLD\DOCUMENTS AND SETTINGS\NUNAN\APPLICATION DATA\MOZILLA\FIREFOX\PROFILES\EO4JXJ9N.DEFAULT\COOKIES.SQLITE ]
    .media6degrees.com [ C:\WINDOWS.OLD\DOCUMENTS AND SETTINGS\NUNAN\APPLICATION DATA\MOZILLA\FIREFOX\PROFILES\EO4JXJ9N.DEFAULT\COOKIES.SQLITE ]
    .openx.net [ C:\WINDOWS.OLD\DOCUMENTS AND SETTINGS\NUNAN\APPLICATION DATA\MOZILLA\FIREFOX\PROFILES\EO4JXJ9N.DEFAULT\COOKIES.SQLITE ]
    .media6degrees.com [ C:\WINDOWS.OLD\DOCUMENTS AND SETTINGS\NUNAN\APPLICATION DATA\MOZILLA\FIREFOX\PROFILES\EO4JXJ9N.DEFAULT\COOKIES.SQLITE ]
    adserver3.openadex.dk [ C:\WINDOWS.OLD\DOCUMENTS AND SETTINGS\NUNAN\APPLICATION DATA\MOZILLA\FIREFOX\PROFILES\EO4JXJ9N.DEFAULT\COOKIES.SQLITE ]
    .adsby.webtraffic.se [ C:\WINDOWS.OLD\DOCUMENTS AND SETTINGS\NUNAN\APPLICATION DATA\MOZILLA\FIREFOX\PROFILES\EO4JXJ9N.DEFAULT\COOKIES.SQLITE ]
    .vindicosuite.com [ C:\WINDOWS.OLD\DOCUMENTS AND SETTINGS\NUNAN\APPLICATION DATA\MOZILLA\FIREFOX\PROFILES\EO4JXJ9N.DEFAULT\COOKIES.SQLITE ]
    .vindicosuite.com [ C:\WINDOWS.OLD\DOCUMENTS AND SETTINGS\NUNAN\APPLICATION DATA\MOZILLA\FIREFOX\PROFILES\EO4JXJ9N.DEFAULT\COOKIES.SQLITE ]
    .mookie1.com [ C:\WINDOWS.OLD\DOCUMENTS AND SETTINGS\NUNAN\APPLICATION DATA\MOZILLA\FIREFOX\PROFILES\EO4JXJ9N.DEFAULT\COOKIES.SQLITE ]
    .tidaltv.com [ C:\WINDOWS.OLD\DOCUMENTS AND SETTINGS\NUNAN\APPLICATION DATA\MOZILLA\FIREFOX\PROFILES\EO4JXJ9N.DEFAULT\COOKIES.SQLITE ]
    .contextweb.com [ C:\WINDOWS.OLD\DOCUMENTS AND SETTINGS\NUNAN\APPLICATION DATA\MOZILLA\FIREFOX\PROFILES\EO4JXJ9N.DEFAULT\COOKIES.SQLITE ]
    .game-advertising-online.com [ C:\WINDOWS.OLD\DOCUMENTS AND SETTINGS\NUNAN\APPLICATION DATA\MOZILLA\FIREFOX\PROFILES\EO4JXJ9N.DEFAULT\COOKIES.SQLITE ]
    .mookie1.com [ C:\WINDOWS.OLD\DOCUMENTS AND SETTINGS\NUNAN\APPLICATION DATA\MOZILLA\FIREFOX\PROFILES\EO4JXJ9N.DEFAULT\COOKIES.SQLITE ]
    .sensic.net [ C:\WINDOWS.OLD\DOCUMENTS AND SETTINGS\NUNAN\APPLICATION DATA\MOZILLA\FIREFOX\PROFILES\EO4JXJ9N.DEFAULT\COOKIES.SQLITE ]
    .media6degrees.com [ C:\WINDOWS.OLD\DOCUMENTS AND SETTINGS\NUNAN\APPLICATION DATA\MOZILLA\FIREFOX\PROFILES\EO4JXJ9N.DEFAULT\COOKIES.SQLITE ]
    .rfihub.com [ C:\WINDOWS.OLD\DOCUMENTS AND SETTINGS\NUNAN\APPLICATION DATA\MOZILLA\FIREFOX\PROFILES\EO4JXJ9N.DEFAULT\COOKIES.SQLITE ]
    .rfihub.com [ C:\WINDOWS.OLD\DOCUMENTS AND SETTINGS\NUNAN\APPLICATION DATA\MOZILLA\FIREFOX\PROFILES\EO4JXJ9N.DEFAULT\COOKIES.SQLITE ]
    .rfihub.com [ C:\WINDOWS.OLD\DOCUMENTS AND SETTINGS\NUNAN\APPLICATION DATA\MOZILLA\FIREFOX\PROFILES\EO4JXJ9N.DEFAULT\COOKIES.SQLITE ]
    .rfihub.com [ C:\WINDOWS.OLD\DOCUMENTS AND SETTINGS\NUNAN\APPLICATION DATA\MOZILLA\FIREFOX\PROFILES\EO4JXJ9N.DEFAULT\COOKIES.SQLITE ]
    .rfihub.com [ C:\WINDOWS.OLD\DOCUMENTS AND SETTINGS\NUNAN\APPLICATION DATA\MOZILLA\FIREFOX\PROFILES\EO4JXJ9N.DEFAULT\COOKIES.SQLITE ]
    .rfihub.com [ C:\WINDOWS.OLD\DOCUMENTS AND SETTINGS\NUNAN\APPLICATION DATA\MOZILLA\FIREFOX\PROFILES\EO4JXJ9N.DEFAULT\COOKIES.SQLITE ]
    .rfihub.com [ C:\WINDOWS.OLD\DOCUMENTS AND SETTINGS\NUNAN\APPLICATION DATA\MOZILLA\FIREFOX\PROFILES\EO4JXJ9N.DEFAULT\COOKIES.SQLITE ]
    .rfihub.com [ C:\WINDOWS.OLD\DOCUMENTS AND SETTINGS\NUNAN\APPLICATION DATA\MOZILLA\FIREFOX\PROFILES\EO4JXJ9N.DEFAULT\COOKIES.SQLITE ]
    .sensic.net [ C:\WINDOWS.OLD\DOCUMENTS AND SETTINGS\NUNAN\APPLICATION DATA\MOZILLA\FIREFOX\PROFILES\EO4JXJ9N.DEFAULT\COOKIES.SQLITE ]
    .everesttech.net [ C:\WINDOWS.OLD\DOCUMENTS AND SETTINGS\NUNAN\APPLICATION DATA\MOZILLA\FIREFOX\PROFILES\EO4JXJ9N.DEFAULT\COOKIES.SQLITE ]
    .pixel1725.everesttech.net [ C:\WINDOWS.OLD\DOCUMENTS AND SETTINGS\NUNAN\APPLICATION DATA\MOZILLA\FIREFOX\PROFILES\EO4JXJ9N.DEFAULT\COOKIES.SQLITE ]
    .pixel1725.everesttech.net [ C:\WINDOWS.OLD\DOCUMENTS AND SETTINGS\NUNAN\APPLICATION DATA\MOZILLA\FIREFOX\PROFILES\EO4JXJ9N.DEFAULT\COOKIES.SQLITE ]
    .pixel2368.everesttech.net [ C:\WINDOWS.OLD\DOCUMENTS AND SETTINGS\NUNAN\APPLICATION DATA\MOZILLA\FIREFOX\PROFILES\EO4JXJ9N.DEFAULT\COOKIES.SQLITE ]
    .and.co.uk [ C:\WINDOWS.OLD\DOCUMENTS AND SETTINGS\NUNAN\APPLICATION DATA\MOZILLA\FIREFOX\PROFILES\EO4JXJ9N.DEFAULT\COOKIES.SQLITE ]
    .tynt.com [ C:\WINDOWS.OLD\DOCUMENTS AND SETTINGS\NUNAN\APPLICATION DATA\MOZILLA\FIREFOX\PROFILES\EO4JXJ9N.DEFAULT\COOKIES.SQLITE ]
    pfa.levexis.com [ C:\WINDOWS.OLD\DOCUMENTS AND SETTINGS\NUNAN\APPLICATION DATA\MOZILLA\FIREFOX\PROFILES\EO4JXJ9N.DEFAULT\COOKIES.SQLITE ]
    .ad.yieldmanager.com [ C:\WINDOWS.OLD\DOCUMENTS AND SETTINGS\NUNAN\APPLICATION DATA\MOZILLA\FIREFOX\PROFILES\EO4JXJ9N.DEFAULT\COOKIES.SQLITE ]
    d.psa-ads.openx.com [ C:\WINDOWS.OLD\DOCUMENTS AND SETTINGS\NUNAN\APPLICATION DATA\MOZILLA\FIREFOX\PROFILES\EO4JXJ9N.DEFAULT\COOKIES.SQLITE ]
    banner.civfanatics.com [ C:\WINDOWS.OLD\DOCUMENTS AND SETTINGS\NUNAN\APPLICATION DATA\MOZILLA\FIREFOX\PROFILES\EO4JXJ9N.DEFAULT\COOKIES.SQLITE ]
    .adbrite.com [ C:\WINDOWS.OLD\DOCUMENTS AND SETTINGS\NUNAN\APPLICATION DATA\MOZILLA\FIREFOX\PROFILES\EO4JXJ9N.DEFAULT\COOKIES.SQLITE ]
    adfarm1.adition.com [ C:\WINDOWS.OLD\DOCUMENTS AND SETTINGS\NUNAN\APPLICATION DATA\MOZILLA\FIREFOX\PROFILES\EO4JXJ9N.DEFAULT\COOKIES.SQLITE ]
    .atdmt.com [ C:\WINDOWS.OLD\DOCUMENTS AND SETTINGS\NUNAN\APPLICATION DATA\MOZILLA\FIREFOX\PROFILES\EO4JXJ9N.DEFAULT\COOKIES.SQLITE ]
    .atdmt.com [ C:\WINDOWS.OLD\DOCUMENTS AND SETTINGS\NUNAN\APPLICATION DATA\MOZILLA\FIREFOX\PROFILES\EO4JXJ9N.DEFAULT\COOKIES.SQLITE ]
    .tradedoubler.com [ C:\WINDOWS.OLD\DOCUMENTS AND SETTINGS\NUNAN\APPLICATION DATA\MOZILLA\FIREFOX\PROFILES\EO4JXJ9N.DEFAULT\COOKIES.SQLITE ]
    .tradedoubler.com [ C:\WINDOWS.OLD\DOCUMENTS AND SETTINGS\NUNAN\APPLICATION DATA\MOZILLA\FIREFOX\PROFILES\EO4JXJ9N.DEFAULT\COOKIES.SQLITE ]
    .server.cpmstar.com [ C:\WINDOWS.OLD\DOCUMENTS AND SETTINGS\NUNAN\APPLICATION DATA\MOZILLA\FIREFOX\PROFILES\EO4JXJ9N.DEFAULT\COOKIES.SQLITE ]
    .trafficpeople.co.uk [ C:\WINDOWS.OLD\DOCUMENTS AND SETTINGS\NUNAN\APPLICATION DATA\MOZILLA\FIREFOX\PROFILES\EO4JXJ9N.DEFAULT\COOKIES.SQLITE ]
    .trafficpeople.co.uk [ C:\WINDOWS.OLD\DOCUMENTS AND SETTINGS\NUNAN\APPLICATION DATA\MOZILLA\FIREFOX\PROFILES\EO4JXJ9N.DEFAULT\COOKIES.SQLITE ]
    .burstnet.com [ C:\WINDOWS.OLD\DOCUMENTS AND SETTINGS\NUNAN\APPLICATION DATA\MOZILLA\FIREFOX\PROFILES\EO4JXJ9N.DEFAULT\COOKIES.SQLITE ]
    .partypoker.com [ C:\WINDOWS.OLD\DOCUMENTS AND SETTINGS\NUNAN\APPLICATION DATA\MOZILLA\FIREFOX\PROFILES\EO4JXJ9N.DEFAULT\COOKIES.SQLITE ]
    .partypoker.com [ C:\WINDOWS.OLD\DOCUMENTS AND SETTINGS\NUNAN\APPLICATION DATA\MOZILLA\FIREFOX\PROFILES\EO4JXJ9N.DEFAULT\COOKIES.SQLITE ]
    .partypoker.com [ C:\WINDOWS.OLD\DOCUMENTS AND SETTINGS\NUNAN\APPLICATION DATA\MOZILLA\FIREFOX\PROFILES\EO4JXJ9N.DEFAULT\COOKIES.SQLITE ]
    .partypoker.com [ C:\WINDOWS.OLD\DOCUMENTS AND SETTINGS\NUNAN\APPLICATION DATA\MOZILLA\FIREFOX\PROFILES\EO4JXJ9N.DEFAULT\COOKIES.SQLITE ]
    .partypoker.com [ C:\WINDOWS.OLD\DOCUMENTS AND SETTINGS\NUNAN\APPLICATION DATA\MOZILLA\FIREFOX\PROFILES\EO4JXJ9N.DEFAULT\COOKIES.SQLITE ]
    .2o7.net [ C:\WINDOWS.OLD\DOCUMENTS AND SETTINGS\NUNAN\APPLICATION DATA\MOZILLA\FIREFOX\PROFILES\EO4JXJ9N.DEFAULT\COOKIES.SQLITE ]
    .sixapart.adbureau.net [ C:\WINDOWS.OLD\DOCUMENTS AND SETTINGS\NUNAN\APPLICATION DATA\MOZILLA\FIREFOX\PROFILES\EO4JXJ9N.DEFAULT\COOKIES.SQLITE ]
    tag.contextweb.com [ C:\WINDOWS.OLD\DOCUMENTS AND SETTINGS\NUNAN\APPLICATION DATA\MOZILLA\FIREFOX\PROFILES\EO4JXJ9N.DEFAULT\COOKIES.SQLITE ]
    d.tradex.openx.com [ C:\WINDOWS.OLD\DOCUMENTS AND SETTINGS\NUNAN\APPLICATION DATA\MOZILLA\FIREFOX\PROFILES\EO4JXJ9N.DEFAULT\COOKIES.SQLITE ]
    .mathtag.com [ C:\WINDOWS.OLD\DOCUMENTS AND SETTINGS\NUNAN\APPLICATION DATA\MOZILLA\FIREFOX\PROFILES\EO4JXJ9N.DEFAULT\COOKIES.SQLITE ]
    cas.criteo.com [ C:\WINDOWS.OLD\DOCUMENTS AND SETTINGS\NUNAN\APPLICATION DATA\MOZILLA\FIREFOX\PROFILES\EO4JXJ9N.DEFAULT\COOKIES.SQLITE ]
    .legolas-media.com [ C:\WINDOWS.OLD\DOCUMENTS AND SETTINGS\NUNAN\APPLICATION DATA\MOZILLA\FIREFOX\PROFILES\EO4JXJ9N.DEFAULT\COOKIES.SQLITE ]
    .viglink.com [ C:\WINDOWS.OLD\DOCUMENTS AND SETTINGS\NUNAN\APPLICATION DATA\MOZILLA\FIREFOX\PROFILES\EO4JXJ9N.DEFAULT\COOKIES.SQLITE ]
    .pubmatic.com [ C:\WINDOWS.OLD\DOCUMENTS AND SETTINGS\NUNAN\APPLICATION DATA\MOZILLA\FIREFOX\PROFILES\EO4JXJ9N.DEFAULT\COOKIES.SQLITE ]
    .pubmatic.com [ C:\WINDOWS.OLD\DOCUMENTS AND SETTINGS\NUNAN\APPLICATION DATA\MOZILLA\FIREFOX\PROFILES\EO4JXJ9N.DEFAULT\COOKIES.SQLITE ]
    .view.atdmt.com [ C:\WINDOWS.OLD\DOCUMENTS AND SETTINGS\NUNAN\APPLICATION DATA\MOZILLA\FIREFOX\PROFILES\EO4JXJ9N.DEFAULT\COOKIES.SQLITE ]
    .adtechus.com [ C:\WINDOWS.OLD\DOCUMENTS AND SETTINGS\NUNAN\APPLICATION DATA\MOZILLA\FIREFOX\PROFILES\EO4JXJ9N.DEFAULT\COOKIES.SQLITE ]
    .telemetryverification.net [ C:\WINDOWS.OLD\DOCUMENTS AND SETTINGS\NUNAN\APPLICATION DATA\MOZILLA\FIREFOX\PROFILES\EO4JXJ9N.DEFAULT\COOKIES.SQLITE ]
    .2o7.net [ C:\WINDOWS.OLD\DOCUMENTS AND SETTINGS\NUNAN\APPLICATION DATA\MOZILLA\FIREFOX\PROFILES\EO4JXJ9N.DEFAULT\COOKIES.SQLITE ]
    .chitika.net [ C:\WINDOWS.OLD\DOCUMENTS AND SETTINGS\NUNAN\APPLICATION DATA\MOZILLA\FIREFOX\PROFILES\EO4JXJ9N.DEFAULT\COOKIES.SQLITE ]
    .tribalfusion.com [ C:\WINDOWS.OLD\DOCUMENTS AND SETTINGS\NUNAN\APPLICATION DATA\MOZILLA\FIREFOX\PROFILES\EO4JXJ9N.DEFAULT\COOKIES.SQLITE ]
    .tribalfusion.com [ C:\WINDOWS.OLD\DOCUMENTS AND SETTINGS\NUNAN\APPLICATION DATA\MOZILLA\FIREFOX\PROFILES\EO4JXJ9N.DEFAULT\COOKIES.SQLITE ]
    .tribalfusion.com [ C:\WINDOWS.OLD\DOCUMENTS AND SETTINGS\NUNAN\APPLICATION DATA\MOZILLA\FIREFOX\PROFILES\EO4JXJ9N.DEFAULT\COOKIES.SQLITE ]
    .tribalfusion.com [ C:\WINDOWS.OLD\DOCUMENTS AND SETTINGS\NUNAN\APPLICATION DATA\MOZILLA\FIREFOX\PROFILES\EO4JXJ9N.DEFAULT\COOKIES.SQLITE ]
    .tribalfusion.com [ C:\WINDOWS.OLD\DOCUMENTS AND SETTINGS\NUNAN\APPLICATION DATA\MOZILLA\FIREFOX\PROFILES\EO4JXJ9N.DEFAULT\COOKIES.SQLITE ]
    .ib.adnxs.com [ C:\WINDOWS.OLD\DOCUMENTS AND SETTINGS\NUNAN\APPLICATION DATA\MOZILLA\FIREFOX\PROFILES\EO4JXJ9N.DEFAULT\COOKIES.SQLITE ]
    .s2d6.com [ C:\WINDOWS.OLD\DOCUMENTS AND SETTINGS\NUNAN\APPLICATION DATA\MOZILLA\FIREFOX\PROFILES\EO4JXJ9N.DEFAULT\COOKIES.SQLITE ]
    .rubiconproject.com [ C:\WINDOWS.OLD\DOCUMENTS AND SETTINGS\NUNAN\APPLICATION DATA\MOZILLA\FIREFOX\PROFILES\EO4JXJ9N.DEFAULT\COOKIES.SQLITE ]
    .udmserve.net [ C:\WINDOWS.OLD\DOCUMENTS AND SETTINGS\NUNAN\APPLICATION DATA\MOZILLA\FIREFOX\PROFILES\EO4JXJ9N.DEFAULT\COOKIES.SQLITE ]
    .udmserve.net [ C:\WINDOWS.OLD\DOCUMENTS AND SETTINGS\NUNAN\APPLICATION DATA\MOZILLA\FIREFOX\PROFILES\EO4JXJ9N.DEFAULT\COOKIES.SQLITE ]
    .rubiconproject.com [ C:\WINDOWS.OLD\DOCUMENTS AND SETTINGS\NUNAN\APPLICATION DATA\MOZILLA\FIREFOX\PROFILES\EO4JXJ9N.DEFAULT\COOKIES.SQLITE ]
    .tidaltv.com [ C:\WINDOWS.OLD\DOCUMENTS AND SETTINGS\NUNAN\APPLICATION DATA\MOZILLA\FIREFOX\PROFILES\EO4JXJ9N.DEFAULT\COOKIES.SQLITE ]
    .tidaltv.com [ C:\WINDOWS.OLD\DOCUMENTS AND SETTINGS\NUNAN\APPLICATION DATA\MOZILLA\FIREFOX\PROFILES\EO4JXJ9N.DEFAULT\COOKIES.SQLITE ]
    .tidaltv.com [ C:\WINDOWS.OLD\DOCUMENTS AND SETTINGS\NUNAN\APPLICATION DATA\MOZILLA\FIREFOX\PROFILES\EO4JXJ9N.DEFAULT\COOKIES.SQLITE ]
    .roiservice.com [ C:\WINDOWS.OLD\DOCUMENTS AND SETTINGS\NUNAN\APPLICATION DATA\MOZILLA\FIREFOX\PROFILES\EO4JXJ9N.DEFAULT\COOKIES.SQLITE ]
    .brandreachsys.com [ C:\WINDOWS.OLD\DOCUMENTS AND SETTINGS\NUNAN\APPLICATION DATA\MOZILLA\FIREFOX\PROFILES\EO4JXJ9N.DEFAULT\COOKIES.SQLITE ]
    .fe.brandreachsys.com [ C:\WINDOWS.OLD\DOCUMENTS AND SETTINGS\NUNAN\APPLICATION DATA\MOZILLA\FIREFOX\PROFILES\EO4JXJ9N.DEFAULT\COOKIES.SQLITE ]
    tag.contextweb.com [ C:\WINDOWS.OLD\DOCUMENTS AND SETTINGS\NUNAN\APPLICATION DATA\MOZILLA\FIREFOX\PROFILES\EO4JXJ9N.DEFAULT\COOKIES.SQLITE ]
    .mathtag.com [ C:\WINDOWS.OLD\DOCUMENTS AND SETTINGS\NUNAN\APPLICATION DATA\MOZILLA\FIREFOX\PROFILES\EO4JXJ9N.DEFAULT\COOKIES.SQLITE ]
    e2.emediate.se [ C:\WINDOWS.OLD\DOCUMENTS AND SETTINGS\NUNAN\APPLICATION DATA\MOZILLA\FIREFOX\PROFILES\EO4JXJ9N.DEFAULT\COOKIES.SQLITE ]
    .viasatsatelliteservices.112.2o7.net [ C:\WINDOWS.OLD\DOCUMENTS AND SETTINGS\NUNAN\APPLICATION DATA\MOZILLA\FIREFOX\PROFILES\EO4JXJ9N.DEFAULT\COOKIES.SQLITE ]
    .outbrain.com [ C:\WINDOWS.OLD\DOCUMENTS AND SETTINGS\NUNAN\APPLICATION DATA\MOZILLA\FIREFOX\PROFILES\EO4JXJ9N.DEFAULT\COOKIES.SQLITE ]
    tenzing.fmpub.net [ C:\WINDOWS.OLD\DOCUMENTS AND SETTINGS\NUNAN\APPLICATION DATA\MOZILLA\FIREFOX\PROFILES\EO4JXJ9N.DEFAULT\COOKIES.SQLITE ]
    tenzing.fmpub.net [ C:\WINDOWS.OLD\DOCUMENTS AND SETTINGS\NUNAN\APPLICATION DATA\MOZILLA\FIREFOX\PROFILES\EO4JXJ9N.DEFAULT\COOKIES.SQLITE ]
    .outbrain.com [ C:\WINDOWS.OLD\DOCUMENTS AND SETTINGS\NUNAN\APPLICATION DATA\MOZILLA\FIREFOX\PROFILES\EO4JXJ9N.DEFAULT\COOKIES.SQLITE ]
    .outbrain.com [ C:\WINDOWS.OLD\DOCUMENTS AND SETTINGS\NUNAN\APPLICATION DATA\MOZILLA\FIREFOX\PROFILES\EO4JXJ9N.DEFAULT\COOKIES.SQLITE ]
    .tacoda.net [ C:\WINDOWS.OLD\DOCUMENTS AND SETTINGS\NUNAN\APPLICATION DATA\MOZILLA\FIREFOX\PROFILES\EO4JXJ9N.DEFAULT\COOKIES.SQLITE ]
    .tacoda.net [ C:\WINDOWS.OLD\DOCUMENTS AND SETTINGS\NUNAN\APPLICATION DATA\MOZILLA\FIREFOX\PROFILES\EO4JXJ9N.DEFAULT\COOKIES.SQLITE ]
    .tacoda.net [ C:\WINDOWS.OLD\DOCUMENTS AND SETTINGS\NUNAN\APPLICATION DATA\MOZILLA\FIREFOX\PROFILES\EO4JXJ9N.DEFAULT\COOKIES.SQLITE ]
    .sensic.net [ C:\WINDOWS.OLD\DOCUMENTS AND SETTINGS\NUNAN\APPLICATION DATA\MOZILLA\FIREFOX\PROFILES\EO4JXJ9N.DEFAULT\COOKIES.SQLITE ]
    .criteo.com [ C:\WINDOWS.OLD\DOCUMENTS AND SETTINGS\NUNAN\APPLICATION DATA\MOZILLA\FIREFOX\PROFILES\EO4JXJ9N.DEFAULT\COOKIES.SQLITE ]
    .criteo.com [ C:\WINDOWS.OLD\DOCUMENTS AND SETTINGS\NUNAN\APPLICATION DATA\MOZILLA\FIREFOX\PROFILES\EO4JXJ9N.DEFAULT\COOKIES.SQLITE ]
    .criteo.com [ C:\WINDOWS.OLD\DOCUMENTS AND SETTINGS\NUNAN\APPLICATION DATA\MOZILLA\FIREFOX\PROFILES\EO4JXJ9N.DEFAULT\COOKIES.SQLITE ]
    .criteo.com [ C:\WINDOWS.OLD\DOCUMENTS AND SETTINGS\NUNAN\APPLICATION DATA\MOZILLA\FIREFOX\PROFILES\EO4JXJ9N.DEFAULT\COOKIES.SQLITE ]
    .criteo.com [ C:\WINDOWS.OLD\DOCUMENTS AND SETTINGS\NUNAN\APPLICATION DATA\MOZILLA\FIREFOX\PROFILES\EO4JXJ9N.DEFAULT\COOKIES.SQLITE ]
    .criteo.com [ C:\WINDOWS.OLD\DOCUMENTS AND SETTINGS\NUNAN\APPLICATION DATA\MOZILLA\FIREFOX\PROFILES\EO4JXJ9N.DEFAULT\COOKIES.SQLITE ]
    .criteo.com [ C:\WINDOWS.OLD\DOCUMENTS AND SETTINGS\NUNAN\APPLICATION DATA\MOZILLA\FIREFOX\PROFILES\EO4JXJ9N.DEFAULT\COOKIES.SQLITE ]
    .criteo.com [ C:\WINDOWS.OLD\DOCUMENTS AND SETTINGS\NUNAN\APPLICATION DATA\MOZILLA\FIREFOX\PROFILES\EO4JXJ9N.DEFAULT\COOKIES.SQLITE ]
    tag.contextweb.com [ C:\WINDOWS.OLD\DOCUMENTS AND SETTINGS\NUNAN\APPLICATION DATA\MOZILLA\FIREFOX\PROFILES\EO4JXJ9N.DEFAULT\COOKIES.SQLITE ]
    stats.renault.co.uk [ C:\WINDOWS.OLD\DOCUMENTS AND SETTINGS\NUNAN\APPLICATION DATA\MOZILLA\FIREFOX\PROFILES\EO4JXJ9N.DEFAULT\COOKIES.SQLITE ]
    .adap.tv [ C:\WINDOWS.OLD\DOCUMENTS AND SETTINGS\NUNAN\APPLICATION DATA\MOZILLA\FIREFOX\PROFILES\EO4JXJ9N.DEFAULT\COOKIES.SQLITE ]
    pfa.levexis.com [ C:\WINDOWS.OLD\DOCUMENTS AND SETTINGS\NUNAN\APPLICATION DATA\MOZILLA\FIREFOX\PROFILES\EO4JXJ9N.DEFAULT\COOKIES.SQLITE ]
    pfa.levexis.com [ C:\WINDOWS.OLD\DOCUMENTS AND SETTINGS\NUNAN\APPLICATION DATA\MOZILLA\FIREFOX\PROFILES\EO4JXJ9N.DEFAULT\COOKIES.SQLITE ]
    .googleads.g.doubleclick.net [ C:\WINDOWS.OLD\DOCUMENTS AND SETTINGS\NUNAN\APPLICATION DATA\MOZILLA\FIREFOX\PROFILES\EO4JXJ9N.DEFAULT\COOKIES.SQLITE ]
    .btrll.com [ C:\WINDOWS.OLD\DOCUMENTS AND SETTINGS\NUNAN\APPLICATION DATA\MOZILLA\FIREFOX\PROFILES\EO4JXJ9N.DEFAULT\COOKIES.SQLITE ]
    .roiservice.com [ C:\WINDOWS.OLD\DOCUMENTS AND SETTINGS\NUNAN\APPLICATION DATA\MOZILLA\FIREFOX\PROFILES\EO4JXJ9N.DEFAULT\COOKIES.SQLITE ]
    statse.webtrendslive.com [ C:\WINDOWS.OLD\DOCUMENTS AND SETTINGS\NUNAN\APPLICATION DATA\MOZILLA\FIREFOX\PROFILES\EO4JXJ9N.DEFAULT\COOKIES.SQLITE ]
    .sensic.net [ C:\WINDOWS.OLD\DOCUMENTS AND SETTINGS\NUNAN\APPLICATION DATA\MOZILLA\FIREFOX\PROFILES\EO4JXJ9N.DEFAULT\COOKIES.SQLITE ]
    .go.lotech.bbelements.com [ C:\WINDOWS.OLD\DOCUMENTS AND SETTINGS\NUNAN\APPLICATION DATA\MOZILLA\FIREFOX\PROFILES\EO4JXJ9N.DEFAULT\COOKIES.SQLITE ]
    ad.yieldmanager.com [ C:\WINDOWS.OLD\DOCUMENTS AND SETTINGS\NUNAN\APPLICATION DATA\MOZILLA\FIREFOX\PROFILES\EO4JXJ9N.DEFAULT\COOKIES.SQLITE ]
    ad.yieldmanager.com [ C:\WINDOWS.OLD\DOCUMENTS AND SETTINGS\NUNAN\APPLICATION DATA\MOZILLA\FIREFOX\PROFILES\EO4JXJ9N.DEFAULT\COOKIES.SQLITE ]
    pfa.levexis.com [ C:\WINDOWS.OLD\DOCUMENTS AND SETTINGS\NUNAN\APPLICATION DATA\MOZILLA\FIREFOX\PROFILES\EO4JXJ9N.DEFAULT\COOKIES.SQLITE ]
    .pro-market.net [ C:\WINDOWS.OLD\DOCUMENTS AND SETTINGS\NUNAN\APPLICATION DATA\MOZILLA\FIREFOX\PROFILES\EO4JXJ9N.DEFAULT\COOKIES.SQLITE ]
    pfa.levexis.com [ C:\WINDOWS.OLD\DOCUMENTS AND SETTINGS\NUNAN\APPLICATION DATA\MOZILLA\FIREFOX\PROFILES\EO4JXJ9N.DEFAULT\COOKIES.SQLITE ]
    .channelintelligence.com [ C:\WINDOWS.OLD\DOCUMENTS AND SETTINGS\NUNAN\APPLICATION DATA\MOZILLA\FIREFOX\PROFILES\EO4JXJ9N.DEFAULT\COOKIES.SQLITE ]
    .clicksor.com [ C:\WINDOWS.OLD\DOCUMENTS AND SETTINGS\NUNAN\APPLICATION DATA\MOZILLA\FIREFOX\PROFILES\EO4JXJ9N.DEFAULT\COOKIES.SQLITE ]
    .clicksor.com [ C:\WINDOWS.OLD\DOCUMENTS AND SETTINGS\NUNAN\APPLICATION DATA\MOZILLA\FIREFOX\PROFILES\EO4JXJ9N.DEFAULT\COOKIES.SQLITE ]
    .clicksor.com [ C:\WINDOWS.OLD\DOCUMENTS AND SETTINGS\NUNAN\APPLICATION DATA\MOZILLA\FIREFOX\PROFILES\EO4JXJ9N.DEFAULT\COOKIES.SQLITE ]
    .wtp101.com [ C:\WINDOWS.OLD\DOCUMENTS AND SETTINGS\NUNAN\APPLICATION DATA\MOZILLA\FIREFOX\PROFILES\EO4JXJ9N.DEFAULT\COOKIES.SQLITE ]
    .zedo.com [ C:\WINDOWS.OLD\DOCUMENTS AND SETTINGS\NUNAN\APPLICATION DATA\MOZILLA\FIREFOX\PROFILES\EO4JXJ9N.DEFAULT\COOKIES.SQLITE ]
    .ad-emea.doubleclick.net [ C:\WINDOWS.OLD\DOCUMENTS AND SETTINGS\NUNAN\APPLICATION DATA\MOZILLA\FIREFOX\PROFILES\EO4JXJ9N.DEFAULT\COOKIES.SQLITE ]
    .rubiconproject.com [ C:\WINDOWS.OLD\DOCUMENTS AND SETTINGS\NUNAN\APPLICATION DATA\MOZILLA\FIREFOX\PROFILES\EO4JXJ9N.DEFAULT\COOKIES.SQLITE ]
    pfa.levexis.com [ C:\WINDOWS.OLD\DOCUMENTS AND SETTINGS\NUNAN\APPLICATION DATA\MOZILLA\FIREFOX\PROFILES\EO4JXJ9N.DEFAULT\COOKIES.SQLITE ]
    .dmtracker.com [ C:\WINDOWS.OLD\DOCUMENTS AND SETTINGS\NUNAN\APPLICATION DATA\MOZILLA\FIREFOX\PROFILES\EO4JXJ9N.DEFAULT\COOKIES.SQLITE ]
    .microsoftconsumermarketing.112.2o7.net [ C:\WINDOWS.OLD\DOCUMENTS AND SETTINGS\NUNAN\APPLICATION DATA\MOZILLA\FIREFOX\PROFILES\EO4JXJ9N.DEFAULT\COOKIES.SQLITE ]
    .turn.com [ C:\WINDOWS.OLD\DOCUMENTS AND SETTINGS\NUNAN\APPLICATION DATA\MOZILLA\FIREFOX\PROFILES\EO4JXJ9N.DEFAULT\COOKIES.SQLITE ]
    .adbrite.com [ C:\WINDOWS.OLD\DOCUMENTS AND SETTINGS\NUNAN\APPLICATION DATA\MOZILLA\FIREFOX\PROFILES\EO4JXJ9N.DEFAULT\COOKIES.SQLITE ]
    .statcounter.com [ C:\WINDOWS.OLD\DOCUMENTS AND SETTINGS\NUNAN\APPLICATION DATA\MOZILLA\FIREFOX\PROFILES\EO4JXJ9N.DEFAULT\COOKIES.SQLITE ]
    .statcounter.com [ C:\WINDOWS.OLD\DOCUMENTS AND SETTINGS\NUNAN\APPLICATION DATA\MOZILLA\FIREFOX\PROFILES\EO4JXJ9N.DEFAULT\COOKIES.SQLITE ]
    .crwdcntrl.net [ C:\WINDOWS.OLD\DOCUMENTS AND SETTINGS\NUNAN\APPLICATION DATA\MOZILLA\FIREFOX\PROFILES\EO4JXJ9N.DEFAULT\COOKIES.SQLITE ]
    .crwdcntrl.net [ C:\WINDOWS.OLD\DOCUMENTS AND SETTINGS\NUNAN\APPLICATION DATA\MOZILLA\FIREFOX\PROFILES\EO4JXJ9N.DEFAULT\COOKIES.SQLITE ]
    .crwdcntrl.net [ C:\WINDOWS.OLD\DOCUMENTS AND SETTINGS\NUNAN\APPLICATION DATA\MOZILLA\FIREFOX\PROFILES\EO4JXJ9N.DEFAULT\COOKIES.SQLITE ]
    .crwdcntrl.net [ C:\WINDOWS.OLD\DOCUMENTS AND SETTINGS\NUNAN\APPLICATION DATA\MOZILLA\FIREFOX\PROFILES\EO4JXJ9N.DEFAULT\COOKIES.SQLITE ]
    .crwdcntrl.net [ C:\WINDOWS.OLD\DOCUMENTS AND SETTINGS\NUNAN\APPLICATION DATA\MOZILLA\FIREFOX\PROFILES\EO4JXJ9N.DEFAULT\COOKIES.SQLITE ]
    .turn.com [ C:\WINDOWS.OLD\DOCUMENTS AND SETTINGS\NUNAN\APPLICATION DATA\MOZILLA\FIREFOX\PROFILES\EO4JXJ9N.DEFAULT\COOKIES.SQLITE ]
    .turn.com [ C:\WINDOWS.OLD\DOCUMENTS AND SETTINGS\NUNAN\APPLICATION DATA\MOZILLA\FIREFOX\PROFILES\EO4JXJ9N.DEFAULT\COOKIES.SQLITE ]
    .soundtrack.net [ C:\WINDOWS.OLD\DOCUMENTS AND SETTINGS\NUNAN\APPLICATION DATA\MOZILLA\FIREFOX\PROFILES\EO4JXJ9N.DEFAULT\COOKIES.SQLITE ]
    .soundtrack.net [ C:\WINDOWS.OLD\DOCUMENTS AND SETTINGS\NUNAN\APPLICATION DATA\MOZILLA\FIREFOX\PROFILES\EO4JXJ9N.DEFAULT\COOKIES.SQLITE ]
    www.soundtrack.net [ C:\WINDOWS.OLD\DOCUMENTS AND SETTINGS\NUNAN\APPLICATION DATA\MOZILLA\FIREFOX\PROFILES\EO4JXJ9N.DEFAULT\COOKIES.SQLITE ]
    .soundtrack.net [ C:\WINDOWS.OLD\DOCUMENTS AND SETTINGS\NUNAN\APPLICATION DATA\MOZILLA\FIREFOX\PROFILES\EO4JXJ9N.DEFAULT\COOKIES.SQLITE ]
    .kontera.com [ C:\WINDOWS.OLD\DOCUMENTS AND SETTINGS\NUNAN\APPLICATION DATA\MOZILLA\FIREFOX\PROFILES\EO4JXJ9N.DEFAULT\COOKIES.SQLITE ]
    .kontera.com [ C:\WINDOWS.OLD\DOCUMENTS AND SETTINGS\NUNAN\APPLICATION DATA\MOZILLA\FIREFOX\PROFILES\EO4JXJ9N.DEFAULT\COOKIES.SQLITE ]
    .kontera.com [ C:\WINDOWS.OLD\DOCUMENTS AND SETTINGS\NUNAN\APPLICATION DATA\MOZILLA\FIREFOX\PROFILES\EO4JXJ9N.DEFAULT\COOKIES.SQLITE ]
    .pornhub.com [ C:\WINDOWS.OLD\DOCUMENTS AND SETTINGS\NUNAN\APPLICATION DATA\MOZILLA\FIREFOX\PROFILES\EO4JXJ9N.DEFAULT\COOKIES.SQLITE ]
    .pornhub.com [ C:\WINDOWS.OLD\DOCUMENTS AND SETTINGS\NUNAN\APPLICATION DATA\MOZILLA\FIREFOX\PROFILES\EO4JXJ9N.DEFAULT\COOKIES.SQLITE ]
    .adultfriendfinder.com [ C:\WINDOWS.OLD\DOCUMENTS AND SETTINGS\NUNAN\APPLICATION DATA\MOZILLA\FIREFOX\PROFILES\EO4JXJ9N.DEFAULT\COOKIES.SQLITE ]
    .adultfriendfinder.com [ C:\WINDOWS.OLD\DOCUMENTS AND SETTINGS\NUNAN\APPLICATION DATA\MOZILLA\FIREFOX\PROFILES\EO4JXJ9N.DEFAULT\COOKIES.SQLITE ]
    eas.apm.emediate.eu [ C:\WINDOWS.OLD\DOCUMENTS AND SETTINGS\NUNAN\APPLICATION DATA\MOZILLA\FIREFOX\PROFILES\EO4JXJ9N.DEFAULT\COOKIES.SQLITE ]
    eas.apm.emediate.eu [ C:\WINDOWS.OLD\DOCUMENTS AND SETTINGS\NUNAN\APPLICATION DATA\MOZILLA\FIREFOX\PROFILES\EO4JXJ9N.DEFAULT\COOKIES.SQLITE ]
    eas.apm.emediate.eu [ C:\WINDOWS.OLD\DOCUMENTS AND SETTINGS\NUNAN\APPLICATION DATA\MOZILLA\FIREFOX\PROFILES\EO4JXJ9N.DEFAULT\COOKIES.SQLITE ]
    .sensic.net [ C:\WINDOWS.OLD\DOCUMENTS AND SETTINGS\NUNAN\APPLICATION DATA\MOZILLA\FIREFOX\PROFILES\EO4JXJ9N.DEFAULT\COOKIES.SQLITE ]
    .insightexpressai.com [ C:\WINDOWS.OLD\DOCUMENTS AND SETTINGS\NUNAN\APPLICATION DATA\MOZILLA\FIREFOX\PROFILES\EO4JXJ9N.DEFAULT\COOKIES.SQLITE ]
    .insightexpressai.com [ C:\WINDOWS.OLD\DOCUMENTS AND SETTINGS\NUNAN\APPLICATION DATA\MOZILLA\FIREFOX\PROFILES\EO4JXJ9N.DEFAULT\COOKIES.SQLITE ]
    .insightexpressai.com [ C:\WINDOWS.OLD\DOCUMENTS AND SETTINGS\NUNAN\APPLICATION DATA\MOZILLA\FIREFOX\PROFILES\EO4JXJ9N.DEFAULT\COOKIES.SQLITE ]
    .insightexpressai.com [ C:\WINDOWS.OLD\DOCUMENTS AND SETTINGS\NUNAN\APPLICATION DATA\MOZILLA\FIREFOX\PROFILES\EO4JXJ9N.DEFAULT\COOKIES.SQLITE ]
    .insightexpressai.com [ C:\WINDOWS.OLD\DOCUMENTS AND SETTINGS\NUNAN\APPLICATION DATA\MOZILLA\FIREFOX\PROFILES\EO4JXJ9N.DEFAULT\COOKIES.SQLITE ]
    .insightexpressai.com [ C:\WINDOWS.OLD\DOCUMENTS AND SETTINGS\NUNAN\APPLICATION DATA\MOZILLA\FIREFOX\PROFILES\EO4JXJ9N.DEFAULT\COOKIES.SQLITE ]
    .insightexpressai.com [ C:\WINDOWS.OLD\DOCUMENTS AND SETTINGS\NUNAN\APPLICATION DATA\MOZILLA\FIREFOX\PROFILES\EO4JXJ9N.DEFAULT\COOKIES.SQLITE ]
    .trafficmp.com [ C:\WINDOWS.OLD\DOCUMENTS AND SETTINGS\NUNAN\APPLICATION DATA\MOZILLA\FIREFOX\PROFILES\EO4JXJ9N.DEFAULT\COOKIES.SQLITE ]
    .trafficmp.com [ C:\WINDOWS.OLD\DOCUMENTS AND SETTINGS\NUNAN\APPLICATION DATA\MOZILLA\FIREFOX\PROFILES\EO4JXJ9N.DEFAULT\COOKIES.SQLITE ]
    .trafficmp.com [ C:\WINDOWS.OLD\DOCUMENTS AND SETTINGS\NUNAN\APPLICATION DATA\MOZILLA\FIREFOX\PROFILES\EO4JXJ9N.DEFAULT\COOKIES.SQLITE ]
    breakmedia.checkm8.com [ C:\WINDOWS.OLD\DOCUMENTS AND SETTINGS\NUNAN\APPLICATION DATA\MOZILLA\FIREFOX\PROFILES\EO4JXJ9N.DEFAULT\COOKIES.SQLITE ]
    pfa.levexis.com [ C:\WINDOWS.OLD\DOCUMENTS AND SETTINGS\NUNAN\APPLICATION DATA\MOZILLA\FIREFOX\PROFILES\EO4JXJ9N.DEFAULT\COOKIES.SQLITE ]
    .sensic.net [ C:\WINDOWS.OLD\DOCUMENTS AND SETTINGS\NUNAN\APPLICATION DATA\MOZILLA\FIREFOX\PROFILES\EO4JXJ9N.DEFAULT\COOKIES.SQLITE ]
    .uk.at.atwola.com [ C:\WINDOWS.OLD\DOCUMENTS AND SETTINGS\NUNAN\APPLICATION DATA\MOZILLA\FIREFOX\PROFILES\EO4JXJ9N.DEFAULT\COOKIES.SQLITE ]
    .yumenetworks.com [ C:\WINDOWS.OLD\DOCUMENTS AND SETTINGS\NUNAN\APPLICATION DATA\MOZILLA\FIREFOX\PROFILES\EO4JXJ9N.DEFAULT\COOKIES.SQLITE ]
    .doubleclick.net [ C:\WINDOWS.OLD\DOCUMENTS AND SETTINGS\NUNAN\APPLICATION DATA\MOZILLA\FIREFOX\PROFILES\EO4JXJ9N.DEFAULT\COOKIES.SQLITE ]
    .sensic.net [ C:\WINDOWS.OLD\DOCUMENTS AND SETTINGS\NUNAN\APPLICATION DATA\MOZILLA\FIREFOX\PROFILES\EO4JXJ9N.DEFAULT\COOKIES.SQLITE ]
    .adserver.adtechus.com [ C:\WINDOWS.OLD\DOCUMENTS AND SETTINGS\NUNAN\APPLICATION DATA\MOZILLA\FIREFOX\PROFILES\EO4JXJ9N.DEFAULT\COOKIES.SQLITE ]
    .eyewonder.com [ C:\WINDOWS.OLD\DOCUMENTS AND SETTINGS\NUNAN\APPLICATION DATA\MOZILLA\FIREFOX\PROFILES\EO4JXJ9N.DEFAULT\COOKIES.SQLITE ]
    .eyewonder.com [ C:\WINDOWS.OLD\DOCUMENTS AND SETTINGS\NUNAN\APPLICATION DATA\MOZILLA\FIREFOX\PROFILES\EO4JXJ9N.DEFAULT\COOKIES.SQLITE ]
    .serving-sys.com [ C:\WINDOWS.OLD\DOCUMENTS AND SETTINGS\NUNAN\APPLICATION DATA\MOZILLA\FIREFOX\PROFILES\EO4JXJ9N.DEFAULT\COOKIES.SQLITE ]
    .serving-sys.com [ C:\WINDOWS.OLD\DOCUMENTS AND SETTINGS\NUNAN\APPLICATION DATA\MOZILLA\FIREFOX\PROFILES\EO4JXJ9N.DEFAULT\COOKIES.SQLITE ]
    .adnxs.com [ C:\WINDOWS.OLD\DOCUMENTS AND SETTINGS\NUNAN\APPLICATION DATA\MOZILLA\FIREFOX\PROFILES\EO4JXJ9N.DEFAULT\COOKIES.SQLITE ]
    .adnxs.com [ C:\WINDOWS.OLD\DOCUMENTS AND SETTINGS\NUNAN\APPLICATION DATA\MOZILLA\FIREFOX\PROFILES\EO4JXJ9N.DEFAULT\COOKIES.SQLITE ]
    ad.yieldmanager.com [ C:\WINDOWS.OLD\DOCUMENTS AND SETTINGS\NUNAN\APPLICATION DATA\MOZILLA\FIREFOX\PROFILES\EO4JXJ9N.DEFAULT\COOKIES.SQLITE ]
    .content.yieldmanager.com [ C:\WINDOWS.OLD\DOCUMENTS AND SETTINGS\NUNAN\APPLICATION DATA\MOZILLA\FIREFOX\PROFILES\EO4JXJ9N.DEFAULT\COOKIES.SQLITE ]
    .addthis.com [ C:\WINDOWS.OLD\DOCUMENTS AND SETTINGS\NUNAN\APPLICATION DATA\MOZILLA\FIREFOX\PROFILES\EO4JXJ9N.DEFAULT\COOKIES.SQLITE ]
    .addthis.com [ C:\WINDOWS.OLD\DOCUMENTS AND SETTINGS\NUNAN\APPLICATION DATA\MOZILLA\FIREFOX\PROFILES\EO4JXJ9N.DEFAULT\COOKIES.SQLITE ]
    .eaeacom.112.2o7.net [ C:\WINDOWS.OLD\DOCUMENTS AND SETTINGS\NUNAN\APPLICATION DATA\MOZILLA\FIREFOX\PROFILES\EO4JXJ9N.DEFAULT\COOKIES.SQLITE ]
    .server.cpmstar.com [ C:\WINDOWS.OLD\DOCUMENTS AND SETTINGS\NUNAN\APPLICATION DATA\MOZILLA\FIREFOX\PROFILES\EO4JXJ9N.DEFAULT\COOKIES.SQLITE ]
    in.getclicky.com [ C:\WINDOWS.OLD\DOCUMENTS AND SETTINGS\NUNAN\APPLICATION DATA\MOZILLA\FIREFOX\PROFILES\EO4JXJ9N.DEFAULT\COOKIES.SQLITE ]
    .bluekai.com [ C:\WINDOWS.OLD\DOCUMENTS AND SETTINGS\NUNAN\APPLICATION DATA\MOZILLA\FIREFOX\PROFILES\EO4JXJ9N.DEFAULT\COOKIES.SQLITE ]
    .bluekai.com [ C:\WINDOWS.OLD\DOCUMENTS AND SETTINGS\NUNAN\APPLICATION DATA\MOZILLA\FIREFOX\PROFILES\EO4JXJ9N.DEFAULT\COOKIES.SQLITE ]
    .bluekai.com [ C:\WINDOWS.OLD\DOCUMENTS AND SETTINGS\NUNAN\APPLICATION DATA\MOZILLA\FIREFOX\PROFILES\EO4JXJ9N.DEFAULT\COOKIES.SQLITE ]
    .rubiconproject.com [ C:\WINDOWS.OLD\DOCUMENTS AND SETTINGS\NUNAN\APPLICATION DATA\MOZILLA\FIREFOX\PROFILES\EO4JXJ9N.DEFAULT\COOKIES.SQLITE ]
    .rubiconproject.com [ C:\WINDOWS.OLD\DOCUMENTS AND SETTINGS\NUNAN\APPLICATION DATA\MOZILLA\FIREFOX\PROFILES\EO4JXJ9N.DEFAULT\COOKIES.SQLITE ]
    .pixel.rubiconproject.com [ C:\WINDOWS.OLD\DOCUMENTS AND SETTINGS\NUNAN\APPLICATION DATA\MOZILLA\FIREFOX\PROFILES\EO4JXJ9N.DEFAULT\COOKIES.SQLITE ]
    .serving-sys.com [ C:\WINDOWS.OLD\DOCUMENTS AND SETTINGS\NUNAN\APPLICATION DATA\MOZILLA\FIREFOX\PROFILES\EO4JXJ9N.DEFAULT\COOKIES.SQLITE ]
    .intellitxt.com [ C:\WINDOWS.OLD\DOCUMENTS AND SETTINGS\NUNAN\APPLICATION DATA\MOZILLA\FIREFOX\PROFILES\EO4JXJ9N.DEFAULT\COOKIES.SQLITE ]
    .revsci.net [ C:\WINDOWS.OLD\DOCUMENTS AND SETTINGS\NUNAN\APPLICATION DATA\MOZILLA\FIREFOX\PROFILES\EO4JXJ9N.DEFAULT\COOKIES.SQLITE ]
    us.sitestat.com [ C:\WINDOWS.OLD\DOCUMENTS AND SETTINGS\NUNAN\APPLICATION DATA\MOZILLA\FIREFOX\PROFILES\EO4JXJ9N.DEFAULT\COOKIES.SQLITE ]
    us.sitestat.com [ C:\WINDOWS.OLD\DOCUMENTS AND SETTINGS\NUNAN\APPLICATION DATA\MOZILLA\FIREFOX\PROFILES\EO4JXJ9N.DEFAULT\COOKIES.SQLITE ]
    .bnmla.com [ C:\WINDOWS.OLD\DOCUMENTS AND SETTINGS\NUNAN\APPLICATION DATA\MOZILLA\FIREFOX\PROFILES\EO4JXJ9N.DEFAULT\COOKIES.SQLITE ]
    .bnmla.com [ C:\WINDOWS.OLD\DOCUMENTS AND SETTINGS\NUNAN\APPLICATION DATA\MOZILLA\FIREFOX\PROFILES\EO4JXJ9N.DEFAULT\COOKIES.SQLITE ]
    .contextweb.com [ C:\WINDOWS.OLD\DOCUMENTS AND SETTINGS\NUNAN\APPLICATION DATA\MOZILLA\FIREFOX\PROFILES\EO4JXJ9N.DEFAULT\COOKIES.SQLITE ]
    .adnxs.com [ C:\WINDOWS.OLD\DOCUMENTS AND SETTINGS\NUNAN\APPLICATION DATA\MOZILLA\FIREFOX\PROFILES\EO4JXJ9N.DEFAULT\COOKIES.SQLITE ]
    .bluekai.com [ C:\WINDOWS.OLD\DOCUMENTS AND SETTINGS\NUNAN\APPLICATION DATA\MOZILLA\FIREFOX\PROFILES\EO4JXJ9N.DEFAULT\COOKIES.SQLITE ]
    .wtp101.com [ C:\WINDOWS.OLD\DOCUMENTS AND SETTINGS\NUNAN\APPLICATION DATA\MOZILLA\FIREFOX\PROFILES\EO4JXJ9N.DEFAULT\COOKIES.SQLITE ]
    .zedo.com [ C:\WINDOWS.OLD\DOCUMENTS AND SETTINGS\NUNAN\APPLICATION DATA\MOZILLA\FIREFOX\PROFILES\EO4JXJ9N.DEFAULT\COOKIES.SQLITE ]
    .zedo.com [ C:\WINDOWS.OLD\DOCUMENTS AND SETTINGS\NUNAN\APPLICATION DATA\MOZILLA\FIREFOX\PROFILES\EO4JXJ9N.DEFAULT\COOKIES.SQLITE ]
    .zedo.com [ C:\WINDOWS.OLD\DOCUMENTS AND SETTINGS\NUNAN\APPLICATION DATA\MOZILLA\FIREFOX\PROFILES\EO4JXJ9N.DEFAULT\COOKIES.SQLITE ]
    .advertising.com [ C:\WINDOWS.OLD\DOCUMENTS AND SETTINGS\NUNAN\APPLICATION DATA\MOZILLA\FIREFOX\PROFILES\EO4JXJ9N.DEFAULT\COOKIES.SQLITE ]
    .rubiconproject.com [ C:\WINDOWS.OLD\DOCUMENTS AND SETTINGS\NUNAN\APPLICATION DATA\MOZILLA\FIREFOX\PROFILES\EO4JXJ9N.DEFAULT\COOKIES.SQLITE ]
    pfa.levexis.com [ C:\WINDOWS.OLD\DOCUMENTS AND SETTINGS\NUNAN\APPLICATION DATA\MOZILLA\FIREFOX\PROFILES\EO4JXJ9N.DEFAULT\COOKIES.SQLITE ]
    .protectyourbubblecom.solution.weborama.fr [ C:\WINDOWS.OLD\DOCUMENTS AND SETTINGS\NUNAN\APPLICATION DATA\MOZILLA\FIREFOX\PROFILES\EO4JXJ9N.DEFAULT\COOKIES.SQLITE ]
    .protectyourbubblecom.solution.weborama.fr [ C:\WINDOWS.OLD\DOCUMENTS AND SETTINGS\NUNAN\APPLICATION DATA\MOZILLA\FIREFOX\PROFILES\EO4JXJ9N.DEFAULT\COOKIES.SQLITE ]
    .protectyourbubblecom.solution.weborama.fr [ C:\WINDOWS.OLD\DOCUMENTS AND SETTINGS\NUNAN\APPLICATION DATA\MOZILLA\FIREFOX\PROFILES\EO4JXJ9N.DEFAULT\COOKIES.SQLITE ]
    .protectyourbubblecom.solution.weborama.fr [ C:\WINDOWS.OLD\DOCUMENTS AND SETTINGS\NUNAN\APPLICATION DATA\MOZILLA\FIREFOX\PROFILES\EO4JXJ9N.DEFAULT\COOKIES.SQLITE ]
    .yumenetworks.com [ C:\WINDOWS.OLD\DOCUMENTS AND SETTINGS\NUNAN\APPLICATION DATA\MOZILLA\FIREFOX\PROFILES\EO4JXJ9N.DEFAULT\COOKIES.SQLITE ]
    .yumenetworks.com [ C:\WINDOWS.OLD\DOCUMENTS AND SETTINGS\NUNAN\APPLICATION DATA\MOZILLA\FIREFOX\PROFILES\EO4JXJ9N.DEFAULT\COOKIES.SQLITE ]
    .msnbc.112.2o7.net [ C:\WINDOWS.OLD\DOCUMENTS AND SETTINGS\NUNAN\APPLICATION DATA\MOZILLA\FIREFOX\PROFILES\EO4JXJ9N.DEFAULT\COOKIES.SQLITE ]
    .tubemogul.com [ C:\WINDOWS.OLD\DOCUMENTS AND SETTINGS\NUNAN\APPLICATION DATA\MOZILLA\FIREFOX\PROFILES\EO4JXJ9N.DEFAULT\COOKIES.SQLITE ]
    .tubemogul.com [ C:\WINDOWS.OLD\DOCUMENTS AND SETTINGS\NUNAN\APPLICATION DATA\MOZILLA\FIREFOX\PROFILES\EO4JXJ9N.DEFAULT\COOKIES.SQLITE ]
    .tubemogul.com [ C:\WINDOWS.OLD\DOCUMENTS AND SETTINGS\NUNAN\APPLICATION DATA\MOZILLA\FIREFOX\PROFILES\EO4JXJ9N.DEFAULT\COOKIES.SQLITE ]
    .rubiconproject.com [ C:\WINDOWS.OLD\DOCUMENTS AND SETTINGS\NUNAN\APPLICATION DATA\MOZILLA\FIREFOX\PROFILES\EO4JXJ9N.DEFAULT\COOKIES.SQLITE ]
    .rubiconproject.com [ C:\WINDOWS.OLD\DOCUMENTS AND SETTINGS\NUNAN\APPLICATION DATA\MOZILLA\FIREFOX\PROFILES\EO4JXJ9N.DEFAULT\COOKIES.SQLITE ]
    .rubiconproject.com [ C:\WINDOWS.OLD\DOCUMENTS AND SETTINGS\NUNAN\APPLICATION DATA\MOZILLA\FIREFOX\PROFILES\EO4JXJ9N.DEFAULT\COOKIES.SQLITE ]
    .realmedia.com [ C:\WINDOWS.OLD\DOCUMENTS AND SETTINGS\NUNAN\APPLICATION DATA\MOZILLA\FIREFOX\PROFILES\EO4JXJ9N.DEFAULT\COOKIES.SQLITE ]
    .afy11.net [ C:\WINDOWS.OLD\DOCUMENTS AND SETTINGS\NUNAN\APPLICATION DATA\MOZILLA\FIREFOX\PROFILES\EO4JXJ9N.DEFAULT\COOKIES.SQLITE ]
    .afy11.net [ C:\WINDOWS.OLD\DOCUMENTS AND SETTINGS\NUNAN\APPLICATION DATA\MOZILLA\FIREFOX\PROFILES\EO4JXJ9N.DEFAULT\COOKIES.SQLITE ]
    .afy11.net [ C:\WINDOWS.OLD\DOCUMENTS AND SETTINGS\NUNAN\APPLICATION DATA\MOZILLA\FIREFOX\PROFILES\EO4JXJ9N.DEFAULT\COOKIES.SQLITE ]
    .casalemedia.com [ C:\WINDOWS.OLD\DOCUMENTS AND SETTINGS\NUNAN\APPLICATION DATA\MOZILLA\FIREFOX\PROFILES\EO4JXJ9N.DEFAULT\COOKIES.SQLITE ]
    .casalemedia.com [ C:\WINDOWS.OLD\DOCUMENTS AND SETTINGS\NUNAN\APPLICATION DATA\MOZILLA\FIREFOX\PROFILES\EO4JXJ9N.DEFAULT\COOKIES.SQLITE ]
    .casalemedia.com [ C:\WINDOWS.OLD\DOCUMENTS AND SETTINGS\NUNAN\APPLICATION DATA\MOZILLA\FIREFOX\PROFILES\EO4JXJ9N.DEFAULT\COOKIES.SQLITE ]
    .afy11.net [ C:\WINDOWS.OLD\DOCUMENTS AND SETTINGS\NUNAN\APPLICATION DATA\MOZILLA\FIREFOX\PROFILES\EO4JXJ9N.DEFAULT\COOKIES.SQLITE ]
    .rubiconproject.com [ C:\WINDOWS.OLD\DOCUMENTS AND SETTINGS\NUNAN\APPLICATION DATA\MOZILLA\FIREFOX\PROFILES\EO4JXJ9N.DEFAULT\COOKIES.SQLITE ]
    .rubiconproject.com [ C:\WINDOWS.OLD\DOCUMENTS AND SETTINGS\NUNAN\APPLICATION DATA\MOZILLA\FIREFOX\PROFILES\EO4JXJ9N.DEFAULT\COOKIES.SQLITE ]
    .rubiconproject.com [ C:\WINDOWS.OLD\DOCUMENTS AND SETTINGS\NUNAN\APPLICATION DATA\MOZILLA\FIREFOX\PROFILES\EO4JXJ9N.DEFAULT\COOKIES.SQLITE ]
    .netseer.com [ C:\WINDOWS.OLD\DOCUMENTS AND SETTINGS\NUNAN\APPLICATION DATA\MOZILLA\FIREFOX\PROFILES\EO4JXJ9N.DEFAULT\COOKIES.SQLITE ]
    .rubiconproject.com [ C:\WINDOWS.OLD\DOCUMENTS AND SETTINGS\NUNAN\APPLICATION DATA\MOZILLA\FIREFOX\PROFILES\EO4JXJ9N.DEFAULT\COOKIES.SQLITE ]
    fidelity.rotator.hadj7.adjuggler.net [ C:\WINDOWS.OLD\DOCUMENTS AND SETTINGS\NUNAN\APPLICATION DATA\MOZILLA\FIREFOX\PROFILES\EO4JXJ9N.DEFAULT\COOKIES.SQLITE ]
    fidelity.rotator.hadj7.adjuggler.net [ C:\WINDOWS.OLD\DOCUMENTS AND SETTINGS\NUNAN\APPLICATION DATA\MOZILLA\FIREFOX\PROFILES\EO4JXJ9N.DEFAULT\COOKIES.SQLITE ]
    .rubiconproject.com [ C:\WINDOWS.OLD\DOCUMENTS AND SETTINGS\NUNAN\APPLICATION DATA\MOZILLA\FIREFOX\PROFILES\EO4JXJ9N.DEFAULT\COOKIES.SQLITE ]
    .casalemedia.com [ C:\WINDOWS.OLD\DOCUMENTS AND SETTINGS\NUNAN\APPLICATION DATA\MOZILLA\FIREFOX\PROFILES\EO4JXJ9N.DEFAULT\COOKIES.SQLITE ]
    .casalemedia.com [ C:\WINDOWS.OLD\DOCUMENTS AND SETTINGS\NUNAN\APPLICATION DATA\MOZILLA\FIREFOX\PROFILES\EO4JXJ9N.DEFAULT\COOKIES.SQLITE ]
    .rubiconproject.com [ C:\WINDOWS.OLD\DOCUMENTS AND SETTINGS\NUNAN\APPLICATION DATA\MOZILLA\FIREFOX\PROFILES\EO4JXJ9N.DEFAULT\COOKIES.SQLITE ]
    .rubiconproject.com [ C:\WINDOWS.OLD\DOCUMENTS AND SETTINGS\NUNAN\APPLICATION DATA\MOZILLA\FIREFOX\PROFILES\EO4JXJ9N.DEFAULT\COOKIES.SQLITE ]
    .adbrite.com [ C:\WINDOWS.OLD\DOCUMENTS AND SETTINGS\NUNAN\APPLICATION DATA\MOZILLA\FIREFOX\PROFILES\EO4JXJ9N.DEFAULT\COOKIES.SQLITE ]
    .audienceiq.com [ C:\WINDOWS.OLD\DOCUMENTS AND SETTINGS\NUNAN\APPLICATION DATA\MOZILLA\FIREFOX\PROFILES\EO4JXJ9N.DEFAULT\COOKIES.SQLITE ]
    .zedo.com [ C:\WINDOWS.OLD\DOCUMENTS AND SETTINGS\NUNAN\APPLICATION DATA\MOZILLA\FIREFOX\PROFILES\EO4JXJ9N.DEFAULT\COOKIES.SQLITE ]
    .tribalfusion.com [ C:\WINDOWS.OLD\DOCUMENTS AND SETTINGS\NUNAN\APPLICATION DATA\MOZILLA\FIREFOX\PROFILES\EO4JXJ9N.DEFAULT\COOKIES.SQLITE ]
    .adtech.de [ C:\WINDOWS.OLD\DOCUMENTS AND SETTINGS\NUNAN\APPLICATION DATA\MOZILLA\FIREFOX\PROFILES\EO4JXJ9N.DEFAULT\COOKIES.SQLITE ]
    fl01.ct2.comclick.com [ C:\WINDOWS.OLD\DOCUMENTS AND SETTINGS\NUNAN\APPLICATION DATA\MOZILLA\FIREFOX\PROFILES\EO4JXJ9N.DEFAULT\COOKIES.SQLITE ]
    fl01.ct2.comclick.com [ C:\WINDOWS.OLD\DOCUMENTS AND SETTINGS\NUNAN\APPLICATION DATA\MOZILLA\FIREFOX\PROFILES\EO4JXJ9N.DEFAULT\COOKIES.SQLITE ]
    fl01.ct2.comclick.com [ C:\WINDOWS.OLD\DOCUMENTS AND SETTINGS\NUNAN\APPLICATION DATA\MOZILLA\FIREFOX\PROFILES\EO4JXJ9N.DEFAULT\COOKIES.SQLITE ]
    .habitat.solution.weborama.fr [ C:\WINDOWS.OLD\DOCUMENTS AND SETTINGS\NUNAN\APPLICATION DATA\MOZILLA\FIREFOX\PROFILES\EO4JXJ9N.DEFAULT\COOKIES.SQLITE ]
    .habitat.solution.weborama.fr [ C:\WINDOWS.OLD\DOCUMENTS AND SETTINGS\NUNAN\APPLICATION DATA\MOZILLA\FIREFOX\PROFILES\EO4JXJ9N.DEFAULT\COOKIES.SQLITE ]
    .habitat.solution.weborama.fr [ C:\WINDOWS.OLD\DOCUMENTS AND SETTINGS\NUNAN\APPLICATION DATA\MOZILLA\FIREFOX\PROFILES\EO4JXJ9N.DEFAULT\COOKIES.SQLITE ]
    .habitat.solution.weborama.fr [ C:\WINDOWS.OLD\DOCUMENTS AND SETTINGS\NUNAN\APPLICATION DATA\MOZILLA\FIREFOX\PROFILES\EO4JXJ9N.DEFAULT\COOKIES.SQLITE ]
    .rubiconproject.com [ C:\WINDOWS.OLD\DOCUMENTS AND SETTINGS\NUNAN\APPLICATION DATA\MOZILLA\FIREFOX\PROFILES\EO4JXJ9N.DEFAULT\COOKIES.SQLITE ]
    .fastclick.net [ C:\WINDOWS.OLD\DOCUMENTS AND SETTINGS\NUNAN\APPLICATION DATA\MOZILLA\FIREFOX\PROFILES\EO4JXJ9N.DEFAULT\COOKIES.SQLITE ]
    .ru4.com [ C:\WINDOWS.OLD\DOCUMENTS AND SETTINGS\NUNAN\APPLICATION DATA\MOZILLA\FIREFOX\PROFILES\EO4JXJ9N.DEFAULT\COOKIES.SQLITE ]
    .wtp101.com [ C:\WINDOWS.OLD\DOCUMENTS AND SETTINGS\NUNAN\APPLICATION DATA\MOZILLA\FIREFOX\PROFILES\EO4JXJ9N.DEFAULT\COOKIES.SQLITE ]
    .wtp101.com [ C:\WINDOWS.OLD\DOCUMENTS AND SETTINGS\NUNAN\APPLICATION DATA\MOZILLA\FIREFOX\PROFILES\EO4JXJ9N.DEFAULT\COOKIES.SQLITE ]
    .azjmp.com [ C:\WINDOWS.OLD\DOCUMENTS AND SETTINGS\NUNAN\APPLICATION DATA\MOZILLA\FIREFOX\PROFILES\EO4JXJ9N.DEFAULT\COOKIES.SQLITE ]
    .azjmp.com [ C:\WINDOWS.OLD\DOCUMENTS AND SETTINGS\NUNAN\APPLICATION DATA\MOZILLA\FIREFOX\PROFILES\EO4JXJ9N.DEFAULT\COOKIES.SQLITE ]
    .mediaplex.com [ C:\WINDOWS.OLD\DOCUMENTS AND SETTINGS\NUNAN\APPLICATION DATA\MOZILLA\FIREFOX\PROFILES\EO4JXJ9N.DEFAULT\COOKIES.SQLITE ]
    .rambler.ru [ C:\WINDOWS.OLD\DOCUMENTS AND SETTINGS\NUNAN\APPLICATION DATA\MOZILLA\FIREFOX\PROFILES\EO4JXJ9N.DEFAULT\COOKIES.SQLITE ]
    .questionablecontent.net [ C:\WINDOWS.OLD\DOCUMENTS AND SETTINGS\NUNAN\APPLICATION DATA\MOZILLA\FIREFOX\PROFILES\EO4JXJ9N.DEFAULT\COOKIES.SQLITE ]
    .wtp101.com [ C:\WINDOWS.OLD\DOCUMENTS AND SETTINGS\NUNAN\APPLICATION DATA\MOZILLA\FIREFOX\PROFILES\EO4JXJ9N.DEFAULT\COOKIES.SQLITE ]
    .questionmarket.com [ C:\WINDOWS.OLD\DOCUMENTS AND SETTINGS\NUNAN\APPLICATION DATA\MOZILLA\FIREFOX\PROFILES\EO4JXJ9N.DEFAULT\COOKIES.SQLITE ]
    track.adform.net [ C:\WINDOWS.OLD\DOCUMENTS AND SETTINGS\NUNAN\APPLICATION DATA\MOZILLA\FIREFOX\PROFILES\EO4JXJ9N.DEFAULT\COOKIES.SQLITE ]
    track.adform.net [ C:\WINDOWS.OLD\DOCUMENTS AND SETTINGS\NUNAN\APPLICATION DATA\MOZILLA\FIREFOX\PROFILES\EO4JXJ9N.DEFAULT\COOKIES.SQLITE ]
    .adform.net [ C:\WINDOWS.OLD\DOCUMENTS AND SETTINGS\NUNAN\APPLICATION DATA\MOZILLA\FIREFOX\PROFILES\EO4JXJ9N.DEFAULT\COOKIES.SQLITE ]
    .server.cpmstar.com [ C:\WINDOWS.OLD\DOCUMENTS AND SETTINGS\NUNAN\APPLICATION DATA\MOZILLA\FIREFOX\PROFILES\EO4JXJ9N.DEFAULT\COOKIES.SQLITE ]
    .server.cpmstar.com [ C:\WINDOWS.OLD\DOCUMENTS AND SETTINGS\NUNAN\APPLICATION DATA\MOZILLA\FIREFOX\PROFILES\EO4JXJ9N.DEFAULT\COOKIES.SQLITE ]
    .server.cpmstar.com [ C:\WINDOWS.OLD\DOCUMENTS AND SETTINGS\NUNAN\APPLICATION DATA\MOZILLA\FIREFOX\PROFILES\EO4JXJ9N.DEFAULT\COOKIES.SQLITE ]
    .exelator.com [ C:\WINDOWS.OLD\DOCUMENTS AND SETTINGS\NUNAN\APPLICATION DATA\MOZILLA\FIREFOX\PROFILES\EO4JXJ9N.DEFAULT\COOKIES.SQLITE ]
    .exelator.com [ C:\WINDOWS.OLD\DOCUMENTS AND SETTINGS\NUNAN\APPLICATION DATA\MOZILLA\FIREFOX\PROFILES\EO4JXJ9N.DEFAULT\COOKIES.SQLITE ]
    .exelator.com [ C:\WINDOWS.OLD\DOCUMENTS AND SETTINGS\NUNAN\APPLICATION DATA\MOZILLA\FIREFOX\PROFILES\EO4JXJ9N.DEFAULT\COOKIES.SQLITE ]
    .exelator.com [ C:\WINDOWS.OLD\DOCUMENTS AND SETTINGS\NUNAN\APPLICATION DATA\MOZILLA\FIREFOX\PROFILES\EO4JXJ9N.DEFAULT\COOKIES.SQLITE ]
    .liverail.com [ C:\WINDOWS.OLD\DOCUMENTS AND SETTINGS\NUNAN\APPLICATION DATA\MOZILLA\FIREFOX\PROFILES\EO4JXJ9N.DEFAULT\COOKIES.SQLITE ]
    .adap.tv [ C:\WINDOWS.OLD\DOCUMENTS AND SETTINGS\NUNAN\APPLICATION DATA\MOZILLA\FIREFOX\PROFILES\EO4JXJ9N.DEFAULT\COOKIES.SQLITE ]
    .telemetryverification.net [ C:\WINDOWS.OLD\DOCUMENTS AND SETTINGS\NUNAN\APPLICATION DATA\MOZILLA\FIREFOX\PROFILES\EO4JXJ9N.DEFAULT\COOKIES.SQLITE ]
    .telemetryverification.net [ C:\WINDOWS.OLD\DOCUMENTS AND SETTINGS\NUNAN\APPLICATION DATA\MOZILLA\FIREFOX\PROFILES\EO4JXJ9N.DEFAULT\COOKIES.SQLITE ]
    .vdwp.solution.weborama.fr [ C:\WINDOWS.OLD\DOCUMENTS AND SETTINGS\NUNAN\APPLICATION DATA\MOZILLA\FIREFOX\PROFILES\EO4JXJ9N.DEFAULT\COOKIES.SQLITE ]
    .vdwp.solution.weborama.fr [ C:\WINDOWS.OLD\DOCUMENTS AND SETTINGS\NUNAN\APPLICATION DATA\MOZILLA\FIREFOX\PROFILES\EO4JXJ9N.DEFAULT\COOKIES.SQLITE ]
    .vdwp.solution.weborama.fr [ C:\WINDOWS.OLD\DOCUMENTS AND SETTINGS\NUNAN\APPLICATION DATA\MOZILLA\FIREFOX\PROFILES\EO4JXJ9N.DEFAULT\COOKIES.SQLITE ]
    .vdwp.solution.weborama.fr [ C:\WINDOWS.OLD\DOCUMENTS AND SETTINGS\NUNAN\APPLICATION DATA\MOZILLA\FIREFOX\PROFILES\EO4JXJ9N.DEFAULT\COOKIES.SQLITE ]
    .contextweb.com [ C:\WINDOWS.OLD\DOCUMENTS AND SETTINGS\NUNAN\APPLICATION DATA\MOZILLA\FIREFOX\PROFILES\EO4JXJ9N.DEFAULT\COOKIES.SQLITE ]
    .contextweb.com [ C:\WINDOWS.OLD\DOCUMENTS AND SETTINGS\NUNAN\APPLICATION DATA\MOZILLA\FIREFOX\PROFILES\EO4JXJ9N.DEFAULT\COOKIES.SQLITE ]
    .pro-market.net [ C:\WINDOWS.OLD\DOCUMENTS AND SETTINGS\NUNAN\APPLICATION DATA\MOZILLA\FIREFOX\PROFILES\EO4JXJ9N.DEFAULT\COOKIES.SQLITE ]
    .demdex.net [ C:\WINDOWS.OLD\DOCUMENTS AND SETTINGS\NUNAN\APPLICATION DATA\MOZILLA\FIREFOX\PROFILES\EO4JXJ9N.DEFAULT\COOKIES.SQLITE ]
    .at.atwola.com [ C:\WINDOWS.OLD\DOCUMENTS AND SETTINGS\NUNAN\APPLICATION DATA\MOZILLA\FIREFOX\PROFILES\EO4JXJ9N.DEFAULT\COOKIES.SQLITE ]
    .tacoda.at.atwola.com [ C:\WINDOWS.OLD\DOCUMENTS AND SETTINGS\NUNAN\APPLICATION DATA\MOZILLA\FIREFOX\PROFILES\EO4JXJ9N.DEFAULT\COOKIES.SQLITE ]
    .tacoda.at.atwola.com [ C:\WINDOWS.OLD\DOCUMENTS AND SETTINGS\NUNAN\APPLICATION DATA\MOZILLA\FIREFOX\PROFILES\EO4JXJ9N.DEFAULT\COOKIES.SQLITE ]
    .at.atwola.com [ C:\WINDOWS.OLD\DOCUMENTS AND SETTINGS\NUNAN\APPLICATION DATA\MOZILLA\FIREFOX\PROFILES\EO4JXJ9N.DEFAULT\COOKIES.SQLITE ]
    .tacoda.at.atwola.com [ C:\WINDOWS.OLD\DOCUMENTS AND SETTINGS\NUNAN\APPLICATION DATA\MOZILLA\FIREFOX\PROFILES\EO4JXJ9N.DEFAULT\COOKIES.SQLITE ]
    .pro-market.net [ C:\WINDOWS.OLD\DOCUMENTS AND SETTINGS\NUNAN\APPLICATION DATA\MOZILLA\FIREFOX\PROFILES\EO4JXJ9N.DEFAULT\COOKIES.SQLITE ]
    .advertising.com [ C:\WINDOWS.OLD\DOCUMENTS AND SETTINGS\NUNAN\APPLICATION DATA\MOZILLA\FIREFOX\PROFILES\EO4JXJ9N.DEFAULT\COOKIES.SQLITE ]
    .demdex.net [ C:\WINDOWS.OLD\DOCUMENTS AND SETTINGS\NUNAN\APPLICATION DATA\MOZILLA\FIREFOX\PROFILES\EO4JXJ9N.DEFAULT\COOKIES.SQLITE ]
    .dpm.demdex.net [ C:\WINDOWS.OLD\DOCUMENTS AND SETTINGS\NUNAN\APPLICATION DATA\MOZILLA\FIREFOX\PROFILES\EO4JXJ9N.DEFAULT\COOKIES.SQLITE ]
    .dpm.demdex.net [ C:\WINDOWS.OLD\DOCUMENTS AND SETTINGS\NUNAN\APPLICATION DATA\MOZILLA\FIREFOX\PROFILES\EO4JXJ9N.DEFAULT\COOKIES.SQLITE ]
    gourmandia.app4.hubspot.com [ C:\WINDOWS.OLD\DOCUMENTS AND SETTINGS\NUNAN\APPLICATION DATA\MOZILLA\FIREFOX\PROFILES\EO4JXJ9N.DEFAULT\COOKIES.SQLITE ]
    .gourmandia.app4.hubspot.com [ C:\WINDOWS.OLD\DOCUMENTS AND SETTINGS\NUNAN\APPLICATION DATA\MOZILLA\FIREFOX\PROFILES\EO4JXJ9N.DEFAULT\COOKIES.SQLITE ]
    .wtp101.com [ C:\WINDOWS.OLD\DOCUMENTS AND SETTINGS\NUNAN\APPLICATION DATA\MOZILLA\FIREFOX\PROFILES\EO4JXJ9N.DEFAULT\COOKIES.SQLITE ]
    .247realmedia.com [ C:\WINDOWS.OLD\DOCUMENTS AND SETTINGS\NUNAN\APPLICATION DATA\MOZILLA\FIREFOX\PROFILES\EO4JXJ9N.DEFAULT\COOKIES.SQLITE ]
    .fwmrm.net [ C:\WINDOWS.OLD\DOCUMENTS AND SETTINGS\NUNAN\APPLICATION DATA\MOZILLA\FIREFOX\PROFILES\EO4JXJ9N.DEFAULT\COOKIES.SQLITE ]
    .fwmrm.net [ C:\WINDOWS.OLD\DOCUMENTS AND SETTINGS\NUNAN\APPLICATION DATA\MOZILLA\FIREFOX\PROFILES\EO4JXJ9N.DEFAULT\COOKIES.SQLITE ]
    .fwmrm.net [ C:\WINDOWS.OLD\DOCUMENTS AND SETTINGS\NUNAN\APPLICATION DATA\MOZILLA\FIREFOX\PROFILES\EO4JXJ9N.DEFAULT\COOKIES.SQLITE ]
    .fwmrm.net [ C:\WINDOWS.OLD\DOCUMENTS AND SETTINGS\NUNAN\APPLICATION DATA\MOZILLA\FIREFOX\PROFILES\EO4JXJ9N.DEFAULT\COOKIES.SQLITE ]
    .pro-market.net [ C:\WINDOWS.OLD\DOCUMENTS AND SETTINGS\NUNAN\APPLICATION DATA\MOZILLA\FIREFOX\PROFILES\EO4JXJ9N.DEFAULT\COOKIES.SQLITE ]
    .spotxchange.com [ C:\WINDOWS.OLD\DOCUMENTS AND SETTINGS\NUNAN\APPLICATION DATA\MOZILLA\FIREFOX\PROFILES\EO4JXJ9N.DEFAULT\COOKIES.SQLITE ]
    .amgdgt.com [ C:\WINDOWS.OLD\DOCUMENTS AND SETTINGS\NUNAN\APPLICATION DATA\MOZILLA\FIREFOX\PROFILES\EO4JXJ9N.DEFAULT\COOKIES.SQLITE ]
    .amgdgt.com [ C:\WINDOWS.OLD\DOCUMENTS AND SETTINGS\NUNAN\APPLICATION DATA\MOZILLA\FIREFOX\PROFILES\EO4JXJ9N.DEFAULT\COOKIES.SQLITE ]
    .adbrite.com [ C:\WINDOWS.OLD\DOCUMENTS AND SETTINGS\NUNAN\APPLICATION DATA\MOZILLA\FIREFOX\PROFILES\EO4JXJ9N.DEFAULT\COOKIES.SQLITE ]
    .xiti.com [ C:\WINDOWS.OLD\DOCUMENTS AND SETTINGS\NUNAN\APPLICATION DATA\MOZILLA\FIREFOX\PROFILES\EO4JXJ9N.DEFAULT\COOKIES.SQLITE ]
    optimize.indieclick.com [ C:\WINDOWS.OLD\DOCUMENTS AND SETTINGS\NUNAN\APPLICATION DATA\MOZILLA\FIREFOX\PROFILES\EO4JXJ9N.DEFAULT\COOKIES.SQLITE ]
    optimize.indieclick.com [ C:\WINDOWS.OLD\DOCUMENTS AND SETTINGS\NUNAN\APPLICATION DATA\MOZILLA\FIREFOX\PROFILES\EO4JXJ9N.DEFAULT\COOKIES.SQLITE ]
    display.provenpixel.com [ C:\WINDOWS.OLD\DOCUMENTS AND SETTINGS\NUNAN\APPLICATION DATA\MOZILLA\FIREFOX\PROFILES\EO4JXJ9N.DEFAULT\COOKIES.SQLITE ]
    display.provenpixel.com [ C:\WINDOWS.OLD\DOCUMENTS AND SETTINGS\NUNAN\APPLICATION DATA\MOZILLA\FIREFOX\PROFILES\EO4JXJ9N.DEFAULT\COOKIES.SQLITE ]
    pfa.levexis.com [ C:\WINDOWS.OLD\DOCUMENTS AND SETTINGS\NUNAN\APPLICATION DATA\MOZILLA\FIREFOX\PROFILES\EO4JXJ9N.DEFAULT\COOKIES.SQLITE ]
    rts.lj.doublepimp.com [ C:\WINDOWS.OLD\DOCUMENTS AND SETTINGS\NUNAN\APPLICATION DATA\MOZILLA\FIREFOX\PROFILES\EO4JXJ9N.DEFAULT\COOKIES.SQLITE ]
    rts.lj.doublepimp.com [ C:\WINDOWS.OLD\DOCUMENTS AND SETTINGS\NUNAN\APPLICATION DATA\MOZILLA\FIREFOX\PROFILES\EO4JXJ9N.DEFAULT\COOKIES.SQLITE ]
    rts.lj.doublepimp.com [ C:\WINDOWS.OLD\DOCUMENTS AND SETTINGS\NUNAN\APPLICATION DATA\MOZILLA\FIREFOX\PROFILES\EO4JXJ9N.DEFAULT\COOKIES.SQLITE ]
    roia.biz [ C:\WINDOWS.OLD\DOCUMENTS AND SETTINGS\NUNAN\APPLICATION DATA\MOZILLA\FIREFOX\PROFILES\EO4JXJ9N.DEFAULT\COOKIES.SQLITE ]
    roia.biz [ C:\WINDOWS.OLD\DOCUMENTS AND SETTINGS\NUNAN\APPLICATION DATA\MOZILLA\FIREFOX\PROFILES\EO4JXJ9N.DEFAULT\COOKIES.SQLITE ]
    .247realmedia.com [ C:\WINDOWS.OLD\DOCUMENTS AND SETTINGS\NUNAN\APPLICATION DATA\MOZILLA\FIREFOX\PROFILES\EO4JXJ9N.DEFAULT\COOKIES.SQLITE ]
    .247realmedia.com [ C:\WINDOWS.OLD\DOCUMENTS AND SETTINGS\NUNAN\APPLICATION DATA\MOZILLA\FIREFOX\PROFILES\EO4JXJ9N.DEFAULT\COOKIES.SQLITE ]
    .247realmedia.com [ C:\WINDOWS.OLD\DOCUMENTS AND SETTINGS\NUNAN\APPLICATION DATA\MOZILLA\FIREFOX\PROFILES\EO4JXJ9N.DEFAULT\COOKIES.SQLITE ]
    .pubmatic.com [ C:\WINDOWS.OLD\DOCUMENTS AND SETTINGS\NUNAN\APPLICATION DATA\MOZILLA\FIREFOX\PROFILES\EO4JXJ9N.DEFAULT\COOKIES.SQLITE ]
    .adap.tv [ C:\WINDOWS.OLD\DOCUMENTS AND SETTINGS\NUNAN\APPLICATION DATA\MOZILLA\FIREFOX\PROFILES\EO4JXJ9N.DEFAULT\COOKIES.SQLITE ]
    .pubmatic.com [ C:\WINDOWS.OLD\DOCUMENTS AND SETTINGS\NUNAN\APPLICATION DATA\MOZILLA\FIREFOX\PROFILES\EO4JXJ9N.DEFAULT\COOKIES.SQLITE ]
    .adap.tv [ C:\WINDOWS.OLD\DOCUMENTS AND SETTINGS\NUNAN\APPLICATION DATA\MOZILLA\FIREFOX\PROFILES\EO4JXJ9N.DEFAULT\COOKIES.SQLITE ]
    .skimresources.com [ C:\WINDOWS.OLD\DOCUMENTS AND SETTINGS\NUNAN\APPLICATION DATA\MOZILLA\FIREFOX\PROFILES\EO4JXJ9N.DEFAULT\COOKIES.SQLITE ]
    .rubiconproject.com [ C:\WINDOWS.OLD\DOCUMENTS AND SETTINGS\NUNAN\APPLICATION DATA\MOZILLA\FIREFOX\PROFILES\EO4JXJ9N.DEFAULT\COOKIES.SQLITE ]
    .mookie1.com [ C:\WINDOWS.OLD\DOCUMENTS AND SETTINGS\NUNAN\APPLICATION DATA\MOZILLA\FIREFOX\PROFILES\EO4JXJ9N.DEFAULT\COOKIES.SQLITE ]
    .rubiconproject.com [ C:\WINDOWS.OLD\DOCUMENTS AND SETTINGS\NUNAN\APPLICATION DATA\MOZILLA\FIREFOX\PROFILES\EO4JXJ9N.DEFAULT\COOKIES.SQLITE ]
    .tradedoubler.com [ C:\WINDOWS.OLD\DOCUMENTS AND SETTINGS\NUNAN\APPLICATION DATA\MOZILLA\FIREFOX\PROFILES\EO4JXJ9N.DEFAULT\COOKIES.SQLITE ]
    .tidaltv.com [ C:\WINDOWS.OLD\DOCUMENTS AND SETTINGS\NUNAN\APPLICATION DATA\MOZILLA\FIREFOX\PROFILES\EO4JXJ9N.DEFAULT\COOKIES.SQLITE ]
    .unfoundation.122.2o7.net [ C:\WINDOWS.OLD\DOCUMENTS AND SETTINGS\NUNAN\APPLICATION DATA\MOZILLA\FIREFOX\PROFILES\EO4JXJ9N.DEFAULT\COOKIES.SQLITE ]
    .rubiconproject.com [ C:\WINDOWS.OLD\DOCUMENTS AND SETTINGS\NUNAN\APPLICATION DATA\MOZILLA\FIREFOX\PROFILES\EO4JXJ9N.DEFAULT\COOKIES.SQLITE ]
    .d.tradex.openx.com [ C:\WINDOWS.OLD\DOCUMENTS AND SETTINGS\NUNAN\APPLICATION DATA\MOZILLA\FIREFOX\PROFILES\EO4JXJ9N.DEFAULT\COOKIES.SQLITE ]
    de.sitestat.com [ C:\WINDOWS.OLD\DOCUMENTS AND SETTINGS\NUNAN\APPLICATION DATA\MOZILLA\FIREFOX\PROFILES\EO4JXJ9N.DEFAULT\COOKIES.SQLITE ]
    .nuggad.net [ C:\WINDOWS.OLD\DOCUMENTS AND SETTINGS\NUNAN\APPLICATION DATA\MOZILLA\FIREFOX\PROFILES\EO4JXJ9N.DEFAULT\COOKIES.SQLITE ]
    ad.zanox.com [ C:\WINDOWS.OLD\DOCUMENTS AND SETTINGS\NUNAN\APPLICATION DATA\MOZILLA\FIREFOX\PROFILES\EO4JXJ9N.DEFAULT\COOKIES.SQLITE ]
    .zanox.com [ C:\WINDOWS.OLD\DOCUMENTS AND SETTINGS\NUNAN\APPLICATION DATA\MOZILLA\FIREFOX\PROFILES\EO4JXJ9N.DEFAULT\COOKIES.SQLITE ]
    .traffictrack.de [ C:\WINDOWS.OLD\DOCUMENTS AND SETTINGS\NUNAN\APPLICATION DATA\MOZILLA\FIREFOX\PROFILES\EO4JXJ9N.DEFAULT\COOKIES.SQLITE ]
    .webmasterplan.com [ C:\WINDOWS.OLD\DOCUMENTS AND SETTINGS\NUNAN\APPLICATION DATA\MOZILLA\FIREFOX\PROFILES\EO4JXJ9N.DEFAULT\COOKIES.SQLITE ]
    .webmasterplan.com [ C:\WINDOWS.OLD\DOCUMENTS AND SETTINGS\NUNAN\APPLICATION DATA\MOZILLA\FIREFOX\PROFILES\EO4JXJ9N.DEFAULT\COOKIES.SQLITE ]
    .traffictrack.de [ C:\WINDOWS.OLD\DOCUMENTS AND SETTINGS\NUNAN\APPLICATION DATA\MOZILLA\FIREFOX\PROFILES\EO4JXJ9N.DEFAULT\COOKIES.SQLITE ]
    .traffictrack.de [ C:\WINDOWS.OLD\DOCUMENTS AND SETTINGS\NUNAN\APPLICATION DATA\MOZILLA\FIREFOX\PROFILES\EO4JXJ9N.DEFAULT\COOKIES.SQLITE ]
    .fwmrm.net [ C:\WINDOWS.OLD\DOCUMENTS AND SETTINGS\NUNAN\APPLICATION DATA\MOZILLA\FIREFOX\PROFILES\EO4JXJ9N.DEFAULT\COOKIES.SQLITE ]
    .fwmrm.net [ C:\WINDOWS.OLD\DOCUMENTS AND SETTINGS\NUNAN\APPLICATION DATA\MOZILLA\FIREFOX\PROFILES\EO4JXJ9N.DEFAULT\COOKIES.SQLITE ]
    .revsci.net [ C:\WINDOWS.OLD\DOCUMENTS AND SETTINGS\NUNAN\APPLICATION DATA\MOZILLA\FIREFOX\PROFILES\EO4JXJ9N.DEFAULT\COOKIES.SQLITE ]
    .sensic.net [ C:\WINDOWS.OLD\DOCUMENTS AND SETTINGS\NUNAN\APPLICATION DATA\MOZILLA\FIREFOX\PROFILES\EO4JXJ9N.DEFAULT\COOKIES.SQLITE ]
    .burstnet.com [ C:\WINDOWS.OLD\DOCUMENTS AND SETTINGS\NUNAN\APPLICATION DATA\MOZILLA\FIREFOX\PROFILES\EO4JXJ9N.DEFAULT\COOKIES.SQLITE ]
    gr.burstnet.com [ C:\WINDOWS.OLD\DOCUMENTS AND SETTINGS\NUNAN\APPLICATION DATA\MOZILLA\FIREFOX\PROFILES\EO4JXJ9N.DEFAULT\COOKIES.SQLITE ]
    ad2.adfarm1.adition.com [ C:\WINDOWS.OLD\DOCUMENTS AND SETTINGS\NUNAN\APPLICATION DATA\MOZILLA\FIREFOX\PROFILES\EO4JXJ9N.DEFAULT\COOKIES.SQLITE ]
    d.pubgears.com [ C:\WINDOWS.OLD\DOCUMENTS AND SETTINGS\NUNAN\APPLICATION DATA\MOZILLA\FIREFOX\PROFILES\EO4JXJ9N.DEFAULT\COOKIES.SQLITE ]
    trafficking.nabbr.com [ C:\WINDOWS.OLD\DOCUMENTS AND SETTINGS\NUNAN\APPLICATION DATA\MOZILLA\FIREFOX\PROFILES\EO4JXJ9N.DEFAULT\COOKIES.SQLITE ]
    profiles.hitslink.com [ C:\WINDOWS.OLD\DOCUMENTS AND SETTINGS\NUNAN\APPLICATION DATA\MOZILLA\FIREFOX\PROFILES\EO4JXJ9N.DEFAULT\COOKIES.SQLITE ]
    .hotlog.ru [ C:\WINDOWS.OLD\DOCUMENTS AND SETTINGS\NUNAN\APPLICATION DATA\MOZILLA\FIREFOX\PROFILES\EO4JXJ9N.DEFAULT\COOKIES.SQLITE ]
    uk.sitestat.com [ C:\WINDOWS.OLD\DOCUMENTS AND SETTINGS\NUNAN\APPLICATION DATA\MOZILLA\FIREFOX\PROFILES\EO4JXJ9N.DEFAULT\COOKIES.SQLITE ]
    uk.sitestat.com [ C:\WINDOWS.OLD\DOCUMENTS AND SETTINGS\NUNAN\APPLICATION DATA\MOZILLA\FIREFOX\PROFILES\EO4JXJ9N.DEFAULT\COOKIES.SQLITE ]
    .adsrvr.org [ C:\WINDOWS.OLD\DOCUMENTS AND SETTINGS\NUNAN\APPLICATION DATA\MOZILLA\FIREFOX\PROFILES\EO4JXJ9N.DEFAULT\COOKIES.SQLITE ]
    .collective-media.net [ C:\WINDOWS.OLD\DOCUMENTS AND SETTINGS\NUNAN\APPLICATION DATA\MOZILLA\FIREFOX\PROFILES\EO4JXJ9N.DEFAULT\COOKIES.SQLITE ]
    .collective-media.net [ C:\WINDOWS.OLD\DOCUMENTS AND SETTINGS\NUNAN\APPLICATION DATA\MOZILLA\FIREFOX\PROFILES\EO4JXJ9N.DEFAULT\COOKIES.SQLITE ]
    .azjmp.com [ C:\WINDOWS.OLD\DOCUMENTS AND SETTINGS\NUNAN\APPLICATION DATA\MOZILLA\FIREFOX\PROFILES\EO4JXJ9N.DEFAULT\COOKIES.SQLITE ]
    .mediaplex.com [ C:\WINDOWS.OLD\DOCUMENTS AND SETTINGS\NUNAN\APPLICATION DATA\MOZILLA\FIREFOX\PROFILES\EO4JXJ9N.DEFAULT\COOKIES.SQLITE ]
    ad.yieldmanager.com [ C:\WINDOWS.OLD\DOCUMENTS AND SETTINGS\NUNAN\APPLICATION DATA\MOZILLA\FIREFOX\PROFILES\EO4JXJ9N.DEFAULT\COOKIES.SQLITE ]
    .network.adsmarket.com [ C:\WINDOWS.OLD\DOCUMENTS AND SETTINGS\NUNAN\APPLICATION DATA\MOZILLA\FIREFOX\PROFILES\EO4JXJ9N.DEFAULT\COOKIES.SQLITE ]
    .rubiconproject.com [ C:\WINDOWS.OLD\DOCUMENTS AND SETTINGS\NUNAN\APPLICATION DATA\MOZILLA\FIREFOX\PROFILES\EO4JXJ9N.DEFAULT\COOKIES.SQLITE ]
    .adjuggler.net [ C:\WINDOWS.OLD\DOCUMENTS AND SETTINGS\NUNAN\APPLICATION DATA\MOZILLA\FIREFOX\PROFILES\EO4JXJ9N.DEFAULT\COOKIES.SQLITE ]
    .thumb.brandreachsys.com [ C:\WINDOWS.OLD\DOCUMENTS AND SETTINGS\NUNAN\APPLICATION DATA\MOZILLA\FIREFOX\PROFILES\EO4JXJ9N.DEFAULT\COOKIES.SQLITE ]
    assets.rubiconproject.com [ C:\WINDOWS.OLD\DOCUMENTS AND SETTINGS\NUNAN\APPLICATION DATA\MOZILLA\FIREFOX\PROFILES\EO4JXJ9N.DEFAULT\COOKIES.SQLITE ]
    .rfihub.com [ C:\WINDOWS.OLD\DOCUMENTS AND SETTINGS\NUNAN\APPLICATION DATA\MOZILLA\FIREFOX\PROFILES\EO4JXJ9N.DEFAULT\COOKIES.SQLITE ]
    .rfihub.com [ C:\WINDOWS.OLD\DOCUMENTS AND SETTINGS\NUNAN\APPLICATION DATA\MOZILLA\FIREFOX\PROFILES\EO4JXJ9N.DEFAULT\COOKIES.SQLITE ]
    .rfihub.com [ C:\WINDOWS.OLD\DOCUMENTS AND SETTINGS\NUNAN\APPLICATION DATA\MOZILLA\FIREFOX\PROFILES\EO4JXJ9N.DEFAULT\COOKIES.SQLITE ]
    .rfihub.com [ C:\WINDOWS.OLD\DOCUMENTS AND SETTINGS\NUNAN\APPLICATION DATA\MOZILLA\FIREFOX\PROFILES\EO4JXJ9N.DEFAULT\COOKIES.SQLITE ]
    .rfihub.com [ C:\WINDOWS.OLD\DOCUMENTS AND SETTINGS\NUNAN\APPLICATION DATA\MOZILLA\FIREFOX\PROFILES\EO4JXJ9N.DEFAULT\COOKIES.SQLITE ]
    .rfihub.com [ C:\WINDOWS.OLD\DOCUMENTS AND SETTINGS\NUNAN\APPLICATION DATA\MOZILLA\FIREFOX\PROFILES\EO4JXJ9N.DEFAULT\COOKIES.SQLITE ]
    .rfihub.com [ C:\WINDOWS.OLD\DOCUMENTS AND SETTINGS\NUNAN\APPLICATION DATA\MOZILLA\FIREFOX\PROFILES\EO4JXJ9N.DEFAULT\COOKIES.SQLITE ]
    .revsci.net [ C:\WINDOWS.OLD\DOCUMENTS AND SETTINGS\NUNAN\APPLICATION DATA\MOZILLA\FIREFOX\PROFILES\EO4JXJ9N.DEFAULT\COOKIES.SQLITE ]
    .revsci.net [ C:\WINDOWS.OLD\DOCUMENTS AND SETTINGS\NUNAN\APPLICATION DATA\MOZILLA\FIREFOX\PROFILES\EO4JXJ9N.DEFAULT\COOKIES.SQLITE ]
    .chango.com [ C:\WINDOWS.OLD\DOCUMENTS AND SETTINGS\NUNAN\APPLICATION DATA\MOZILLA\FIREFOX\PROFILES\EO4JXJ9N.DEFAULT\COOKIES.SQLITE ]
    .chango.com [ C:\WINDOWS.OLD\DOCUMENTS AND SETTINGS\NUNAN\APPLICATION DATA\MOZILLA\FIREFOX\PROFILES\EO4JXJ9N.DEFAULT\COOKIES.SQLITE ]
    .fwmrm.net [ C:\WINDOWS.OLD\DOCUMENTS AND SETTINGS\NUNAN\APPLICATION DATA\MOZILLA\FIREFOX\PROFILES\EO4JXJ9N.DEFAULT\COOKIES.SQLITE ]
    assets.rubiconproject.com [ C:\WINDOWS.OLD\DOCUMENTS AND SETTINGS\NUNAN\APPLICATION DATA\MOZILLA\FIREFOX\PROFILES\EO4JXJ9N.DEFAULT\COOKIES.SQLITE ]
    .trafficmp.com [ C:\WINDOWS.OLD\DOCUMENTS AND SETTINGS\NUNAN\APPLICATION DATA\MOZILLA\FIREFOX\PROFILES\EO4JXJ9N.DEFAULT\COOKIES.SQLITE ]
    assets.rubiconproject.com [ C:\WINDOWS.OLD\DOCUMENTS AND SETTINGS\NUNAN\APPLICATION DATA\MOZILLA\FIREFOX\PROFILES\EO4JXJ9N.DEFAULT\COOKIES.SQLITE ]
    .sexintheuk.com [ C:\WINDOWS.OLD\DOCUMENTS AND SETTINGS\NUNAN\APPLICATION DATA\MOZILLA\FIREFOX\PROFILES\EO4JXJ9N.DEFAULT\COOKIES.SQLITE ]
    .sexintheuk.com [ C:\WINDOWS.OLD\DOCUMENTS AND SETTINGS\NUNAN\APPLICATION DATA\MOZILLA\FIREFOX\PROFILES\EO4JXJ9N.DEFAULT\COOKIES.SQLITE ]
    .sexintheuk.com [ C:\WINDOWS.OLD\DOCUMENTS AND SETTINGS\NUNAN\APPLICATION DATA\MOZILLA\FIREFOX\PROFILES\EO4JXJ9N.DEFAULT\COOKIES.SQLITE ]
    assets.rubiconproject.com [ C:\WINDOWS.OLD\DOCUMENTS AND SETTINGS\NUNAN\APPLICATION DATA\MOZILLA\FIREFOX\PROFILES\EO4JXJ9N.DEFAULT\COOKIES.SQLITE ]
    .s.clickability.com [ C:\WINDOWS.OLD\DOCUMENTS AND SETTINGS\NUNAN\APPLICATION DATA\MOZILLA\FIREFOX\PROFILES\EO4JXJ9N.DEFAULT\COOKIES.SQLITE ]
    .s.clickability.com [ C:\WINDOWS.OLD\DOCUMENTS AND SETTINGS\NUNAN\APPLICATION DATA\MOZILLA\FIREFOX\PROFILES\EO4JXJ9N.DEFAULT\COOKIES.SQLITE ]
    .revsci.net [ C:\WINDOWS.OLD\DOCUMENTS AND SETTINGS\NUNAN\APPLICATION DATA\MOZILLA\FIREFOX\PROFILES\EO4JXJ9N.DEFAULT\COOKIES.SQLITE ]
    .pubmatic.com [ C:\WINDOWS.OLD\DOCUMENTS AND SETTINGS\NUNAN\APPLICATION DATA\MOZILLA\FIREFOX\PROFILES\EO4JXJ9N.DEFAULT\COOKIES.SQLITE ]
    .revsci.net [ C:\WINDOWS.OLD\DOCUMENTS AND SETTINGS\NUNAN\APPLICATION DATA\MOZILLA\FIREFOX\PROFILES\EO4JXJ9N.DEFAULT\COOKIES.SQLITE ]
    assets.rubiconproject.com [ C:\WINDOWS.OLD\DOCUMENTS AND SETTINGS\NUNAN\APPLICATION DATA\MOZILLA\FIREFOX\PROFILES\EO4JXJ9N.DEFAULT\COOKIES.SQLITE ]
    assets.rubiconproject.com [ C:\WINDOWS.OLD\DOCUMENTS AND SETTINGS\NUNAN\APPLICATION DATA\MOZILLA\FIREFOX\PROFILES\EO4JXJ9N.DEFAULT\COOKIES.SQLITE ]
    .showadsak.pubmatic.com [ C:\WINDOWS.OLD\DOCUMENTS AND SETTINGS\NUNAN\APPLICATION DATA\MOZILLA\FIREFOX\PROFILES\EO4JXJ9N.DEFAULT\COOKIES.SQLITE ]
    .pubmatic.com [ C:\WINDOWS.OLD\DOCUMENTS AND SETTINGS\NUNAN\APPLICATION DATA\MOZILLA\FIREFOX\PROFILES\EO4JXJ9N.DEFAULT\COOKIES.SQLITE ]
    pfa.levexis.com [ C:\WINDOWS.OLD\DOCUMENTS AND SETTINGS\NUNAN\APPLICATION DATA\MOZILLA\FIREFOX\PROFILES\EO4JXJ9N.DEFAULT\COOKIES.SQLITE ]
    assets.rubiconproject.com [ C:\WINDOWS.OLD\DOCUMENTS AND SETTINGS\NUNAN\APPLICATION DATA\MOZILLA\FIREFOX\PROFILES\EO4JXJ9N.DEFAULT\COOKIES.SQLITE ]
    .adbrite.com [ C:\WINDOWS.OLD\DOCUMENTS AND SETTINGS\NUNAN\APPLICATION DATA\MOZILLA\FIREFOX\PROFILES\EO4JXJ9N.DEFAULT\COOKIES.SQLITE ]
    assets.rubiconproject.com [ C:\WINDOWS.OLD\DOCUMENTS AND SETTINGS\NUNAN\APPLICATION DATA\MOZILLA\FIREFOX\PROFILES\EO4JXJ9N.DEFAULT\COOKIES.SQLITE ]
    assets.rubiconproject.com [ C:\WINDOWS.OLD\DOCUMENTS AND SETTINGS\NUNAN\APPLICATION DATA\MOZILLA\FIREFOX\PROFILES\EO4JXJ9N.DEFAULT\COOKIES.SQLITE ]
    assets.rubiconproject.com [ C:\WINDOWS.OLD\DOCUMENTS AND SETTINGS\NUNAN\APPLICATION DATA\MOZILLA\FIREFOX\PROFILES\EO4JXJ9N.DEFAULT\COOKIES.SQLITE ]
    .rubiconproject.com [ C:\WINDOWS.OLD\DOCUMENTS AND SETTINGS\NUNAN\APPLICATION DATA\MOZILLA\FIREFOX\PROFILES\EO4JXJ9N.DEFAULT\COOKIES.SQLITE ]
    .vizu.com [ C:\WINDOWS.OLD\DOCUMENTS AND SETTINGS\NUNAN\APPLICATION DATA\MOZILLA\FIREFOX\PROFILES\EO4JXJ9N.DEFAULT\COOKIES.SQLITE ]
    assets.rubiconproject.com [ C:\WINDOWS.OLD\DOCUMENTS AND SETTINGS\NUNAN\APPLICATION DATA\MOZILLA\FIREFOX\PROFILES\EO4JXJ9N.DEFAULT\COOKIES.SQLITE ]
    assets.rubiconproject.com [ C:\WINDOWS.OLD\DOCUMENTS AND SETTINGS\NUNAN\APPLICATION DATA\MOZILLA\FIREFOX\PROFILES\EO4JXJ9N.DEFAULT\COOKIES.SQLITE ]
    assets.rubiconproject.com [ C:\WINDOWS.OLD\DOCUMENTS AND SETTINGS\NUNAN\APPLICATION DATA\MOZILLA\FIREFOX\PROFILES\EO4JXJ9N.DEFAULT\COOKIES.SQLITE ]
    assets.rubiconproject.com [ C:\WINDOWS.OLD\DOCUMENTS AND SETTINGS\NUNAN\APPLICATION DATA\MOZILLA\FIREFOX\PROFILES\EO4JXJ9N.DEFAULT\COOKIES.SQLITE ]
    assets.rubiconproject.com [ C:\WINDOWS.OLD\DOCUMENTS AND SETTINGS\NUNAN\APPLICATION DATA\MOZILLA\FIREFOX\PROFILES\EO4JXJ9N.DEFAULT\COOKIES.SQLITE ]
    assets.rubiconproject.com [ C:\WINDOWS.OLD\DOCUMENTS AND SETTINGS\NUNAN\APPLICATION DATA\MOZILLA\FIREFOX\PROFILES\EO4JXJ9N.DEFAULT\COOKIES.SQLITE ]
    pfa.levexis.com [ C:\WINDOWS.OLD\DOCUMENTS AND SETTINGS\NUNAN\APPLICATION DATA\MOZILLA\FIREFOX\PROFILES\EO4JXJ9N.DEFAULT\COOKIES.SQLITE ]
    .porntube.com [ C:\WINDOWS.OLD\DOCUMENTS AND SETTINGS\NUNAN\APPLICATION DATA\MOZILLA\FIREFOX\PROFILES\EO4JXJ9N.DEFAULT\COOKIES.SQLITE ]
    .porntube.com [ C:\WINDOWS.OLD\DOCUMENTS AND SETTINGS\NUNAN\APPLICATION DATA\MOZILLA\FIREFOX\PROFILES\EO4JXJ9N.DEFAULT\COOKIES.SQLITE ]
    .bnmla.com [ C:\WINDOWS.OLD\DOCUMENTS AND SETTINGS\NUNAN\APPLICATION DATA\MOZILLA\FIREFOX\PROFILES\EO4JXJ9N.DEFAULT\COOKIES.SQLITE ]
    .porntubemate.com [ C:\WINDOWS.OLD\DOCUMENTS AND SETTINGS\NUNAN\APPLICATION DATA\MOZILLA\FIREFOX\PROFILES\EO4JXJ9N.DEFAULT\COOKIES.SQLITE ]
    ad.yieldmanager.com [ C:\WINDOWS.OLD\DOCUMENTS AND SETTINGS\NUNAN\APPLICATION DATA\MOZILLA\FIREFOX\PROFILES\EO4JXJ9N.DEFAULT\COOKIES.SQLITE ]
    streamate.doublepimp.com [ C:\WINDOWS.OLD\DOCUMENTS AND SETTINGS\NUNAN\APPLICATION DATA\MOZILLA\FIREFOX\PROFILES\EO4JXJ9N.DEFAULT\COOKIES.SQLITE ]
    streamate.doublepimp.com [ C:\WINDOWS.OLD\DOCUMENTS AND SETTINGS\NUNAN\APPLICATION DATA\MOZILLA\FIREFOX\PROFILES\EO4JXJ9N.DEFAULT\COOKIES.SQLITE ]
    streamate.doublepimp.com [ C:\WINDOWS.OLD\DOCUMENTS AND SETTINGS\NUNAN\APPLICATION DATA\MOZILLA\FIREFOX\PROFILES\EO4JXJ9N.DEFAULT\COOKIES.SQLITE ]
    porntubemate.com [ C:\WINDOWS.OLD\DOCUMENTS AND SETTINGS\NUNAN\APPLICATION DATA\MOZILLA\FIREFOX\PROFILES\EO4JXJ9N.DEFAULT\COOKIES.SQLITE ]
    .porntubemate.com [ C:\WINDOWS.OLD\DOCUMENTS AND SETTINGS\NUNAN\APPLICATION DATA\MOZILLA\FIREFOX\PROFILES\EO4JXJ9N.DEFAULT\COOKIES.SQLITE ]
    .adxpansion.com [ C:\WINDOWS.OLD\DOCUMENTS AND SETTINGS\NUNAN\APPLICATION DATA\MOZILLA\FIREFOX\PROFILES\EO4JXJ9N.DEFAULT\COOKIES.SQLITE ]
    .adultfriendfinder.com [ C:\WINDOWS.OLD\DOCUMENTS AND SETTINGS\NUNAN\APPLICATION DATA\MOZILLA\FIREFOX\PROFILES\EO4JXJ9N.DEFAULT\COOKIES.SQLITE ]
    .adultfriendfinder.com [ C:\WINDOWS.OLD\DOCUMENTS AND SETTINGS\NUNAN\APPLICATION DATA\MOZILLA\FIREFOX\PROFILES\EO4JXJ9N.DEFAULT\COOKIES.SQLITE ]
    .adultfriendfinder.com [ C:\WINDOWS.OLD\DOCUMENTS AND SETTINGS\NUNAN\APPLICATION DATA\MOZILLA\FIREFOX\PROFILES\EO4JXJ9N.DEFAULT\COOKIES.SQLITE ]
    .adultfriendfinder.com [ C:\WINDOWS.OLD\DOCUMENTS AND SETTINGS\NUNAN\APPLICATION DATA\MOZILLA\FIREFOX\PROFILES\EO4JXJ9N.DEFAULT\COOKIES.SQLITE ]
    .adultfriendfinder.com [ C:\WINDOWS.OLD\DOCUMENTS AND SETTINGS\NUNAN\APPLICATION DATA\MOZILLA\FIREFOX\PROFILES\EO4JXJ9N.DEFAULT\COOKIES.SQLITE ]
    rts.phn.doublepimp.com [ C:\WINDOWS.OLD\DOCUMENTS AND SETTINGS\NUNAN\APPLICATION DATA\MOZILLA\FIREFOX\PROFILES\EO4JXJ9N.DEFAULT\COOKIES.SQLITE ]
    rts.phn.doublepimp.com [ C:\WINDOWS.OLD\DOCUMENTS AND SETTINGS\NUNAN\APPLICATION DATA\MOZILLA\FIREFOX\PROFILES\EO4JXJ9N.DEFAULT\COOKIES.SQLITE ]
    rts.phn.doublepimp.com [ C:\WINDOWS.OLD\DOCUMENTS AND SETTINGS\NUNAN\APPLICATION DATA\MOZILLA\FIREFOX\PROFILES\EO4JXJ9N.DEFAULT\COOKIES.SQLITE ]
    .partypoker.com [ C:\WINDOWS.OLD\DOCUMENTS AND SETTINGS\NUNAN\APPLICATION DATA\MOZILLA\FIREFOX\PROFILES\EO4JXJ9N.DEFAULT\COOKIES.SQLITE ]
    display.provenpixel.com [ C:\WINDOWS.OLD\DOCUMENTS AND SETTINGS\NUNAN\APPLICATION DATA\MOZILLA\FIREFOX\PROFILES\EO4JXJ9N.DEFAULT\COOKIES.SQLITE ]
    display.provenpixel.com [ C:\WINDOWS.OLD\DOCUMENTS AND SETTINGS\NUNAN\APPLICATION DATA\MOZILLA\FIREFOX\PROFILES\EO4JXJ9N.DEFAULT\COOKIES.SQLITE ]
    display.provenpixel.com [ C:\WINDOWS.OLD\DOCUMENTS AND SETTINGS\NUNAN\APPLICATION DATA\MOZILLA\FIREFOX\PROFILES\EO4JXJ9N.DEFAULT\COOKIES.SQLITE ]
    display.provenpixel.com [ C:\WINDOWS.OLD\DOCUMENTS AND SETTINGS\NUNAN\APPLICATION DATA\MOZILLA\FIREFOX\PROFILES\EO4JXJ9N.DEFAULT\COOKIES.SQLITE ]
    assets.rubiconproject.com [ C:\WINDOWS.OLD\DOCUMENTS AND SETTINGS\NUNAN\APPLICATION DATA\MOZILLA\FIREFOX\PROFILES\EO4JXJ9N.DEFAULT\COOKIES.SQLITE ]
    .adbrite.com [ C:\WINDOWS.OLD\DOCUMENTS AND SETTINGS\NUNAN\APPLICATION DATA\MOZILLA\FIREFOX\PROFILES\EO4JXJ9N.DEFAULT\COOKIES.SQLITE ]
    tap.rubiconproject.com [ C:\WINDOWS.OLD\DOCUMENTS AND SETTINGS\NUNAN\APPLICATION DATA\MOZILLA\FIREFOX\PROFILES\EO4JXJ9N.DEFAULT\COOKIES.SQLITE ]
    .revsci.net [ C:\WINDOWS.OLD\DOCUMENTS AND SETTINGS\NUNAN\APPLICATION DATA\MOZILLA\FIREFOX\PROFILES\EO4JXJ9N.DEFAULT\COOKIES.SQLITE ]
    .revsci.net [ C:\WINDOWS.OLD\DOCUMENTS AND SETTINGS\NUNAN\APPLICATION DATA\MOZILLA\FIREFOX\PROFILES\EO4JXJ9N.DEFAULT\COOKIES.SQLITE ]
    uk.sitestat.com [ C:\WINDOWS.OLD\DOCUMENTS AND SETTINGS\NUNAN\APPLICATION DATA\MOZILLA\FIREFOX\PROFILES\EO4JXJ9N.DEFAULT\COOKIES.SQLITE ]
    uk.sitestat.com [ C:\WINDOWS.OLD\DOCUMENTS AND SETTINGS\NUNAN\APPLICATION DATA\MOZILLA\FIREFOX\PROFILES\EO4JXJ9N.DEFAULT\COOKIES.SQLITE ]
    .adnxs.com [ C:\WINDOWS.OLD\DOCUMENTS AND SETTINGS\NUNAN\APPLICATION DATA\MOZILLA\FIREFOX\PROFILES\EO4JXJ9N.DEFAULT\COOKIES.SQLITE ]
    .adbrite.com [ C:\WINDOWS.OLD\DOCUMENTS AND SETTINGS\NUNAN\APPLICATION DATA\MOZILLA\FIREFOX\PROFILES\EO4JXJ9N.DEFAULT\COOKIES.SQLITE ]
    .sexintheuk.com [ C:\WINDOWS.OLD\DOCUMENTS AND SETTINGS\NUNAN\APPLICATION DATA\MOZILLA\FIREFOX\PROFILES\EO4JXJ9N.DEFAULT\COOKIES.SQLITE ]
    tap2-cdn.rubiconproject.com [ C:\WINDOWS.OLD\DOCUMENTS AND SETTINGS\NUNAN\APPLICATION DATA\MOZILLA\FIREFOX\PROFILES\EO4JXJ9N.DEFAULT\COOKIES.SQLITE ]
    .collective-media.net [ C:\WINDOWS.OLD\DOCUMENTS AND SETTINGS\NUNAN\APPLICATION DATA\MOZILLA\FIREFOX\PROFILES\EO4JXJ9N.DEFAULT\COOKIES.SQLITE ]
    .bluekai.com [ C:\WINDOWS.OLD\DOCUMENTS AND SETTINGS\NUNAN\APPLICATION DATA\MOZILLA\FIREFOX\PROFILES\EO4JXJ9N.DEFAULT\COOKIES.SQLITE ]
    .collective-media.net [ C:\WINDOWS.OLD\DOCUMENTS AND SETTINGS\NUNAN\APPLICATION DATA\MOZILLA\FIREFOX\PROFILES\EO4JXJ9N.DEFAULT\COOKIES.SQLITE ]
    ads.pubmatic.com [ C:\WINDOWS.OLD\DOCUMENTS AND SETTINGS\NUNAN\APPLICATION DATA\MOZILLA\FIREFOX\PROFILES\EO4JXJ9N.DEFAULT\COOKIES.SQLITE ]
    tap2-cdn.rubiconproject.com [ C:\WINDOWS.OLD\DOCUMENTS AND SETTINGS\NUNAN\APPLICATION DATA\MOZILLA\FIREFOX\PROFILES\EO4JXJ9N.DEFAULT\COOKIES.SQLITE ]
    .pubmatic.com [ C:\WINDOWS.OLD\DOCUMENTS AND SETTINGS\NUNAN\APPLICATION DATA\MOZILLA\FIREFOX\PROFILES\EO4JXJ9N.DEFAULT\COOKIES.SQLITE ]
    tap2-cdn.rubiconproject.com [ C:\WINDOWS.OLD\DOCUMENTS AND SETTINGS\NUNAN\APPLICATION DATA\MOZILLA\FIREFOX\PROFILES\EO4JXJ9N.DEFAULT\COOKIES.SQLITE ]
    tap2-cdn.rubiconproject.com [ C:\WINDOWS.OLD\DOCUMENTS AND SETTINGS\NUNAN\APPLICATION DATA\MOZILLA\FIREFOX\PROFILES\EO4JXJ9N.DEFAULT\COOKIES.SQLITE ]
    tap2-cdn.rubiconproject.com [ C:\WINDOWS.OLD\DOCUMENTS AND SETTINGS\NUNAN\APPLICATION DATA\MOZILLA\FIREFOX\PROFILES\EO4JXJ9N.DEFAULT\COOKIES.SQLITE ]
    tap2-cdn.rubiconproject.com [ C:\WINDOWS.OLD\DOCUMENTS AND SETTINGS\NUNAN\APPLICATION DATA\MOZILLA\FIREFOX\PROFILES\EO4JXJ9N.DEFAULT\COOKIES.SQLITE ]
    tap2-cdn.rubiconproject.com [ C:\WINDOWS.OLD\DOCUMENTS AND SETTINGS\NUNAN\APPLICATION DATA\MOZILLA\FIREFOX\PROFILES\EO4JXJ9N.DEFAULT\COOKIES.SQLITE ]
    .rubiconproject.com [ C:\WINDOWS.OLD\DOCUMENTS AND SETTINGS\NUNAN\APPLICATION DATA\MOZILLA\FIREFOX\PROFILES\EO4JXJ9N.DEFAULT\COOKIES.SQLITE ]
    tap2-cdn.rubiconproject.com [ C:\WINDOWS.OLD\DOCUMENTS AND SETTINGS\NUNAN\APPLICATION DATA\MOZILLA\FIREFOX\PROFILES\EO4JXJ9N.DEFAULT\COOKIES.SQLITE ]
    tap2-cdn.rubiconproject.com [ C:\WINDOWS.OLD\DOCUMENTS AND SETTINGS\NUNAN\APPLICATION DATA\MOZILLA\FIREFOX\PROFILES\EO4JXJ9N.DEFAULT\COOKIES.SQLITE ]
    tap2-cdn.rubiconproject.com [ C:\WINDOWS.OLD\DOCUMENTS AND SETTINGS\NUNAN\APPLICATION DATA\MOZILLA\FIREFOX\PROFILES\EO4JXJ9N.DEFAULT\COOKIES.SQLITE ]
    tap2-cdn.rubiconproject.com [ C:\WINDOWS.OLD\DOCUMENTS AND SETTINGS\NUNAN\APPLICATION DATA\MOZILLA\FIREFOX\PROFILES\EO4JXJ9N.DEFAULT\COOKIES.SQLITE ]
    .segainc.112.2o7.net [ C:\WINDOWS.OLD\DOCUMENTS AND SETTINGS\NUNAN\APPLICATION DATA\MOZILLA\FIREFOX\PROFILES\EO4JXJ9N.DEFAULT\COOKIES.SQLITE ]
    tap2-cdn.rubiconproject.com [ C:\WINDOWS.OLD\DOCUMENTS AND SETTINGS\NUNAN\APPLICATION DATA\MOZILLA\FIREFOX\PROFILES\EO4JXJ9N.DEFAULT\COOKIES.SQLITE ]
    tap2-cdn.rubiconproject.com [ C:\WINDOWS.OLD\DOCUMENTS AND SETTINGS\NUNAN\APPLICATION DATA\MOZILLA\FIREFOX\PROFILES\EO4JXJ9N.DEFAULT\COOKIES.SQLITE ]
    .fastclick.net [ C:\WINDOWS.OLD\DOCUMENTS AND SETTINGS\NUNAN\APPLICATION DATA\MOZILLA\FIREFOX\PROFILES\EO4JXJ9N.DEFAULT\COOKIES.SQLITE ]
    tap2-cdn.rubiconproject.com [ C:\WINDOWS.OLD\DOCUMENTS AND SETTINGS\NUNAN\APPLICATION DATA\MOZILLA\FIREFOX\PROFILES\EO4JXJ9N.DEFAULT\COOKIES.SQLITE ]
    tap2-cdn.rubiconproject.com [ C:\WINDOWS.OLD\DOCUMENTS AND SETTINGS\NUNAN\APPLICATION DATA\MOZILLA\FIREFOX\PROFILES\EO4JXJ9N.DEFAULT\COOKIES.SQLITE ]
    tap2-cdn.rubiconproject.com [ C:\WINDOWS.OLD\DOCUMENTS AND SETTINGS\NUNAN\APPLICATION DATA\MOZILLA\FIREFOX\PROFILES\EO4JXJ9N.DEFAULT\COOKIES.SQLITE ]
    tap2-cdn.rubiconproject.com [ C:\WINDOWS.OLD\DOCUMENTS AND SETTINGS\NUNAN\APPLICATION DATA\MOZILLA\FIREFOX\PROFILES\EO4JXJ9N.DEFAULT\COOKIES.SQLITE ]
    .tradedoubler.com [ C:\WINDOWS.OLD\DOCUMENTS AND SETTINGS\NUNAN\APPLICATION DATA\MOZILLA\FIREFOX\PROFILES\EO4JXJ9N.DEFAULT\COOKIES.SQLITE ]
    cas.criteo.com [ C:\WINDOWS.OLD\DOCUMENTS AND SETTINGS\NUNAN\APPLICATION DATA\MOZILLA\FIREFOX\PROFILES\EO4JXJ9N.DEFAULT\COOKIES.SQLITE ]
    cas.criteo.com [ C:\WINDOWS.OLD\DOCUMENTS AND SETTINGS\NUNAN\APPLICATION DATA\MOZILLA\FIREFOX\PROFILES\EO4JXJ9N.DEFAULT\COOKIES.SQLITE ]
    .criteo.com [ C:\WINDOWS.OLD\DOCUMENTS AND SETTINGS\NUNAN\APPLICATION DATA\MOZILLA\FIREFOX\PROFILES\EO4JXJ9N.DEFAULT\COOKIES.SQLITE ]
    .revsci.net [ C:\WINDOWS.OLD\DOCUMENTS AND SETTINGS\NUNAN\APPLICATION DATA\MOZILLA\FIREFOX\PROFILES\EO4JXJ9N.DEFAULT\COOKIES.SQLITE ]
    .partypoker.com [ C:\WINDOWS.OLD\DOCUMENTS AND SETTINGS\NUNAN\APPLICATION DATA\MOZILLA\FIREFOX\PROFILES\EO4JXJ9N.DEFAULT\COOKIES.SQLITE ]
    www.star-advertising.com [ C:\WINDOWS.OLD\DOCUMENTS AND SETTINGS\NUNAN\APPLICATION DATA\MOZILLA\FIREFOX\PROFILES\EO4JXJ9N.DEFAULT\COOKIES.SQLITE ]
    www.star-advertising.com [ C:\WINDOWS.OLD\DOCUMENTS AND SETTINGS\NUNAN\APPLICATION DATA\MOZILLA\FIREFOX\PROFILES\EO4JXJ9N.DEFAULT\COOKIES.SQLITE ]
    .addthis.com [ C:\WINDOWS.OLD\DOCUMENTS AND SETTINGS\NUNAN\APPLICATION DATA\MOZILLA\FIREFOX\PROFILES\EO4JXJ9N.DEFAULT\COOKIES.SQLITE ]
    .bizrate.com [ C:\WINDOWS.OLD\DOCUMENTS AND SETTINGS\NUNAN\APPLICATION DATA\MOZILLA\FIREFOX\PROFILES\EO4JXJ9N.DEFAULT\COOKIES.SQLITE ]
    ace.adoftheyear.com [ C:\WINDOWS.OLD\DOCUMENTS AND SETTINGS\NUNAN\APPLICATION DATA\MOZILLA\FIREFOX\PROFILES\EO4JXJ9N.DEFAULT\COOKIES.SQLITE ]
    .rubiconproject.com [ C:\WINDOWS.OLD\DOCUMENTS AND SETTINGS\NUNAN\APPLICATION DATA\MOZILLA\FIREFOX\PROFILES\EO4JXJ9N.DEFAULT\COOKIES.SQLITE ]
    .rubiconproject.com [ C:\WINDOWS.OLD\DOCUMENTS AND SETTINGS\NUNAN\APPLICATION DATA\MOZILLA\FIREFOX\PROFILES\EO4JXJ9N.DEFAULT\COOKIES.SQLITE ]
    .rubiconproject.com [ C:\WINDOWS.OLD\DOCUMENTS AND SETTINGS\NUNAN\APPLICATION DATA\MOZILLA\FIREFOX\PROFILES\EO4JXJ9N.DEFAULT\COOKIES.SQLITE ]
    .rubiconproject.com [ C:\WINDOWS.OLD\DOCUMENTS AND SETTINGS\NUNAN\APPLICATION DATA\MOZILLA\FIREFOX\PROFILES\EO4JXJ9N.DEFAULT\COOKIES.SQLITE ]
    .rubiconproject.com [ C:\WINDOWS.OLD\DOCUMENTS AND SETTINGS\NUNAN\APPLICATION DATA\MOZILLA\FIREFOX\PROFILES\EO4JXJ9N.DEFAULT\COOKIES.SQLITE ]
    .rubiconproject.com [ C:\WINDOWS.OLD\DOCUMENTS AND SETTINGS\NUNAN\APPLICATION DATA\MOZILLA\FIREFOX\PROFILES\EO4JXJ9N.DEFAULT\COOKIES.SQLITE ]
    .rubiconproject.com [ C:\WINDOWS.OLD\DOCUMENTS AND SETTINGS\NUNAN\APPLICATION DATA\MOZILLA\FIREFOX\PROFILES\EO4JXJ9N.DEFAULT\COOKIES.SQLITE ]
    .bluekai.com [ C:\WINDOWS.OLD\DOCUMENTS AND SETTINGS\NUNAN\APPLICATION DATA\MOZILLA\FIREFOX\PROFILES\EO4JXJ9N.DEFAULT\COOKIES.SQLITE ]
    .tacoda.at.atwola.com [ C:\WINDOWS.OLD\DOCUMENTS AND SETTINGS\NUNAN\APPLICATION DATA\MOZILLA\FIREFOX\PROFILES\EO4JXJ9N.DEFAULT\COOKIES.SQLITE ]
    .tacoda.at.atwola.com [ C:\WINDOWS.OLD\DOCUMENTS AND SETTINGS\NUNAN\APPLICATION DATA\MOZILLA\FIREFOX\PROFILES\EO4JXJ9N.DEFAULT\COOKIES.SQLITE ]
    .bluekai.com [ C:\WINDOWS.OLD\DOCUMENTS AND SETTINGS\NUNAN\APPLICATION DATA\MOZILLA\FIREFOX\PROFILES\EO4JXJ9N.DEFAULT\COOKIES.SQLITE ]
    .rubiconproject.com [ C:\WINDOWS.OLD\DOCUMENTS AND SETTINGS\NUNAN\APPLICATION DATA\MOZILLA\FIREFOX\PROFILES\EO4JXJ9N.DEFAULT\COOKIES.SQLITE ]
    .rubiconproject.com [ C:\WINDOWS.OLD\DOCUMENTS AND SETTINGS\NUNAN\APPLICATION DATA\MOZILLA\FIREFOX\PROFILES\EO4JXJ9N.DEFAULT\COOKIES.SQLITE ]
    .content.yieldmanager.com [ C:\WINDOWS.OLD\DOCUMENTS AND SETTINGS\NUNAN\APPLICATION DATA\MOZILLA\FIREFOX\PROFILES\EO4JXJ9N.DEFAULT\COOKIES.SQLITE ]
    ad.yieldmanager.com [ C:\WINDOWS.OLD\DOCUMENTS AND SETTINGS\NUNAN\APPLICATION DATA\MOZILLA\FIREFOX\PROFILES\EO4JXJ9N.DEFAULT\COOKIES.SQLITE ]
    ad.yieldmanager.com [ C:\WINDOWS.OLD\DOCUMENTS AND SETTINGS\NUNAN\APPLICATION DATA\MOZILLA\FIREFOX\PROFILES\EO4JXJ9N.DEFAULT\COOKIES.SQLITE ]
    .rubiconproject.com [ C:\WINDOWS.OLD\DOCUMENTS AND SETTINGS\NUNAN\APPLICATION DATA\MOZILLA\FIREFOX\PROFILES\EO4JXJ9N.DEFAULT\COOKIES.SQLITE ]
    .rubiconproject.com [ C:\WINDOWS.OLD\DOCUMENTS AND SETTINGS\NUNAN\APPLICATION DATA\MOZILLA\FIREFOX\PROFILES\EO4JXJ9N.DEFAULT\COOKIES.SQLITE ]
    eas.apm.emediate.eu [ C:\WINDOWS.OLD\DOCUMENTS AND SETTINGS\NUNAN\APPLICATION DATA\MOZILLA\FIREFOX\PROFILES\EO4JXJ9N.DEFAULT\COOKIES.SQLITE ]
    C:\WINDOWS.OLD\DOCUMENTS AND SETTINGS\NUNAN\COOKIES\NUNAN@APMEBF[1].TXTC:\WINDOWS.OLD\DOCUMENTS AND SETTINGS\NUNAN\COOKIES\NUNAN@APMEBF[1].TXT [ /APMEBF ]
    C:\WINDOWS.OLD\DOCUMENTS AND SETTINGS\NUNAN\COOKIES\NUNAN@MSNPORTAL.112.2O7[1].TXTC:\WINDOWS.OLD\DOCUMENTS AND SETTINGS\NUNAN\COOKIES\NUNAN@MSNPORTAL.112.2O7[1].TXT [ /MSNPORTAL.112.2O7 ]

HackTool/Gen-GameHack.Process
    D:\SYSTEM VOLUME INFORMATION\_RESTORE{A1716103-BD5E-438B-8E15-F63A79DA3CCA}\RP11\A0000671.EXE

HackTool/Gen-GameHack.Process-1
    D:\SYSTEM VOLUME INFORMATION\_RESTORE{A1716103-BD5E-438B-8E15-F63A79DA3CCA}\RP11\A0001861.EXE

Trojan.Agent/Gen-Qhost
    D:\VALVE\STEAM\STEAMAPPS\COMMON\TRIALS FUSION\SUPPORT\SOFTWARE\KB971512\KB971512-X64.EXE
    D:\VALVE\STEAM\STEAMAPPS\COMMON\TRIALS FUSION\SUPPORT\SOFTWARE\KB971512\KB971512-X86.EXE
    D:\VALVE\STEAM\STEAMAPPS\COMMON\TRIALS FUSION - CLOSED BETA\SUPPORT\SOFTWARE\KB971512\KB971512-X64.EXE
    D:\VALVE\STEAM\STEAMAPPS\COMMON\TRIALS FUSION - CLOSED BETA\SUPPORT\SOFTWARE\KB971512\KB971512-X86.EXE

============
 End of Log
============
 

If I didn't say before, the Utrack.pw pop-up is not always there, sometimes it occurs and sometimes not. When it does occur, it's always on starting my computer. The Steam store issues are always there, clicking anywhere on the store will cause the redirection and pop-ups. Thanks.



#9 Oh My!

Oh My!

    Adware and Spyware and Malware.....


  • Malware Response Instructor
  • 37,972 posts
  • OFFLINE
  •  
  • Gender:Male
  • Location:California
  • Local time:12:12 AM

Posted 18 December 2015 - 10:10 AM

Thank you for the informtion. Please do this.

===================================================

Farbar's Recovery Scan Tool - Run Fix in Normal or Safe Mode

--------------------
  • Press the Windows key Windows_Logo_key.gif + r on your keyboard at the same time. Type in notepad and press Enter
  • Please copy and paste the contents of the below code box into the open notepad and save it to your desktop (<<<Important) as fixlist.txt
CloseProcesses:
CMD: ipconfig /flushdns
CMD: netsh winsock reset
CMD: ipconfig /release
CMD: ipconfig /renew
  • Launch FRST and press the Fix button just once and wait, the program will automatically launch fixlist.txt.
  • The tool will create a log on the desktop called Fixlog.txt. Please copy and paste the contents of the file in your reply.
  • Reboot and check your Internet
===================================================

Things I would like to see in your next reply. Please be sure to copy and paste any requested log information unless you are asked to attach it. :thumbsup2:
  • Fixlog
  • How is your computer behaving?

Gary
 
If I do not reply within 24 hours please send me a Personal Message.

"Lord, to whom would we go? You have the words that give eternal life. We believe, and we know you are the Holy One of God."

#10 euanicorn

euanicorn
  • Topic Starter

  • Members
  • 12 posts
  • OFFLINE
  •  
  • Local time:08:12 AM

Posted 18 December 2015 - 11:27 AM

Fix result of Farbar Recovery Scan Tool (x64) Version:17-12-2015
Ran by euan (2015-12-18 15:54:44) Run:3
Running from C:\Users\euan\Desktop
Loaded Profiles: euan (Available Profiles: euan)
Boot Mode: Normal
==============================================

fixlist content:
*****************
CloseProcesses:
CMD: ipconfig /flushdns
CMD: netsh winsock reset
CMD: ipconfig /release
CMD: ipconfig /renew
*****************

Processes closed successfully.

=========  ipconfig /flushdns =========


Windows IP Configuration

Successfully flushed the DNS Resolver Cache.

========= End of CMD: =========


=========  netsh winsock reset =========


Sucessfully reset the Winsock Catalog.
You must restart the computer in order to complete the reset.


========= End of CMD: =========


=========  ipconfig /release =========


Windows IP Configuration

No operation can be performed on Evolve Gaming Connection while it has its media disconnected.
No operation can be performed on Local Area Connection 3 while it has its media disconnected.
No operation can be performed on Local Area Connection 2 while it has its media disconnected.

Ethernet adapter Evolve Gaming Connection:

   Media State . . . . . . . . . . . : Media disconnected
   Connection-specific DNS Suffix  . :

Ethernet adapter Local Area Connection 3:

   Media State . . . . . . . . . . . : Media disconnected
   Connection-specific DNS Suffix  . :

Ethernet adapter Local Area Connection 2:

   Media State . . . . . . . . . . . : Media disconnected
   Connection-specific DNS Suffix  . :

Ethernet adapter Local Area Connection:

   Connection-specific DNS Suffix  . :
   Link-local IPv6 Address . . . . . : fe80::c168:b904:91cf:7a83%10
   Default Gateway . . . . . . . . . :

Ethernet adapter Local Area Connection 2:

   Connection-specific DNS Suffix  . :
   IPv6 Address. . . . . . . . . . . : 2620:9b::1964:1cf6
   Link-local IPv6 Address . . . . . : fe80::dd58:2aa9:e11d:d105%13
   Default Gateway . . . . . . . . . : 2620:9b::1900:1
                                       25.0.0.1

========= End of CMD: =========


=========  ipconfig /renew =========


Windows IP Configuration

No operation can be performed on Evolve Gaming Connection while it has its media disconnected.
No operation can be performed on Local Area Connection 3 while it has its media disconnected.
No operation can be performed on Local Area Connection 2 while it has its media disconnected.

Ethernet adapter Evolve Gaming Connection:

   Media State . . . . . . . . . . . : Media disconnected
   Connection-specific DNS Suffix  . :

Ethernet adapter Local Area Connection 3:

   Media State . . . . . . . . . . . : Media disconnected
   Connection-specific DNS Suffix  . :

Ethernet adapter Local Area Connection 2:

   Media State . . . . . . . . . . . : Media disconnected
   Connection-specific DNS Suffix  . :

Ethernet adapter Local Area Connection:

   Connection-specific DNS Suffix  . : Belkin
   Link-local IPv6 Address . . . . . : fe80::c168:b904:91cf:7a83%10
   IPv4 Address. . . . . . . . . . . : 192.168.2.5
   Subnet Mask . . . . . . . . . . . : 255.255.255.0
   Default Gateway . . . . . . . . . : 192.168.2.1

Ethernet adapter Local Area Connection 2:

   Connection-specific DNS Suffix  . :
   IPv6 Address. . . . . . . . . . . : 2620:9b::1964:1cf6
   Link-local IPv6 Address . . . . . : fe80::dd58:2aa9:e11d:d105%13
   IPv4 Address. . . . . . . . . . . : 25.100.28.246
   Subnet Mask . . . . . . . . . . . : 255.0.0.0
   Default Gateway . . . . . . . . . : 2620:9b::1900:1
                                       25.0.0.1

========= End of CMD: =========



The system needed a reboot.

==== End of Fixlog 15:54:55 ====

 

 

I just checked Steam and it's still going to ads, no Utrack thing just now but that appears irregularly so I'll have to let you know with that.

 

e; I'm not noticing any unusual behaviour outside of these issues.


Edited by euanicorn, 18 December 2015 - 01:43 PM.


#11 Oh My!

Oh My!

    Adware and Spyware and Malware.....


  • Malware Response Instructor
  • 37,972 posts
  • OFFLINE
  •  
  • Gender:Male
  • Location:California
  • Local time:12:12 AM

Posted 18 December 2015 - 02:30 PM

OK use it a bit and let me know if it is only related to Steam.
Gary
 
If I do not reply within 24 hours please send me a Personal Message.

"Lord, to whom would we go? You have the words that give eternal life. We believe, and we know you are the Holy One of God."

#12 Oh My!

Oh My!

    Adware and Spyware and Malware.....


  • Malware Response Instructor
  • 37,972 posts
  • OFFLINE
  •  
  • Gender:Male
  • Location:California
  • Local time:12:12 AM

Posted 20 December 2015 - 10:09 PM

How are we doing?
Gary
 
If I do not reply within 24 hours please send me a Personal Message.

"Lord, to whom would we go? You have the words that give eternal life. We believe, and we know you are the Holy One of God."

#13 Oh My!

Oh My!

    Adware and Spyware and Malware.....


  • Malware Response Instructor
  • 37,972 posts
  • OFFLINE
  •  
  • Gender:Male
  • Location:California
  • Local time:12:12 AM

Posted 22 December 2015 - 11:13 AM

Greetings,

===================================================

3 Day Bump

It has been more than 3 days since my last post.
  • Do you still need help with this?
  • If after 48hrs you have not replied to this thread then it will have to be closed.

Gary
 
If I do not reply within 24 hours please send me a Personal Message.

"Lord, to whom would we go? You have the words that give eternal life. We believe, and we know you are the Holy One of God."

#14 euanicorn

euanicorn
  • Topic Starter

  • Members
  • 12 posts
  • OFFLINE
  •  
  • Local time:08:12 AM

Posted 23 December 2015 - 07:22 AM

Hi Gary, sincere apologies for the late response! I haven't had the Utrack pop up since your help, from my experience before I'd have expected to have it by now. The only unusual behaviour with my PC now is the Steam store issue with the ads.


Edited by euanicorn, 23 December 2015 - 07:23 AM.


#15 Oh My!

Oh My!

    Adware and Spyware and Malware.....


  • Malware Response Instructor
  • 37,972 posts
  • OFFLINE
  •  
  • Gender:Male
  • Location:California
  • Local time:12:12 AM

Posted 23 December 2015 - 11:06 AM

Thanks for touching base. I am not familiar with Steam and how easy it would be to uninstall and reinstall it. Not quite ready to go there yet but could you tell me if that is a reasonable possibility?

Please do this.

===================================================

Run Combofix in Vista/7

--------------------

Combofix is a very powerful tool and special attention must be taken to allow it to work properly. Please pay careful attention to the following instructions.
  • Please download ComboFix from one of these locations:

BleepingComputer
ForoSpyware

  • Save Combofix.exe to your Desktop <-- Important!!!
  • Disable your AntiVirus and AntiSpyware applications, usually via a right click on the System Tray icon. They may otherwise interfere with our tools. (Click on this link to see a list of programs that should be disabled. The list is not all inclusive.)
  • Note: If after disabling Combofix warns you an Antivirus program is still running ignore the warning and run Combofix.
  • Double click on Combofix.exe and follow the prompts. It is important you do not mouseclick while the program is running or it may stall.
Note #1: Often times it may appear as if ComboFix has stopped working. To verify it is still running please do one of the following below. If, based on the below, you have concluded ComboFix has stopped running please stop and advise me.
  • Check your computer clock. If it is still running then so is ComboFix
  • Open Task Manager and select the Applications Tab. If the status of AutoScan is Running, then ComboFix is running
  • Open Task Manager and select the Processes Tab. Under Image Name look for files ending in .3xe. If there are fluctuating numbers under CPU and Mem Usage then ComboFix is running
Note #2: If you receive the following error "Illegal operation attempted on a registery key that has been marked for deletion" please just restart your computer to resolve this issue

If Combofix fails to run properly using the above instructions please attempt the following:
  • Right click on the Combofix icon on your desktop and select Delete
  • Download a new copy but rename it to freshcopy.exe first, then save it to your desktop
  • Now download RKill.exe (or RKill renamed as iExplore.exe if the first one doesn't work properly) and save it to your desktop
  • Restart your computer in Safe Mode
  • Right click on RKill (or iExplore) and select Run as Administrator. If you are using Windows XP simply double click the icon
  • A black DOS screen should flash and disappear. If not, try to launch the program with the second file. If neither works please stop and let me know
  • When RKill is finished running you will be presented with a text file and a copy will be saved on your desktop. Copy and paste the contents of this report in your reply
  • Do not reboot your computer
  • Double click the freshcopy.exe icon (renamed Combofix file)
  • When finished, it will produce a log. Please copy and paste the C:\Combofix.txt log information in your next reply
  • If you disabled your antivirus please enable it again. If you uninstalled it please wait for instructions to reinstall it
===================================================

Run TDSSKiller by Kaspersky

--------------------
  • Please download Kaspersky's TDSSKiller and save it to your Desktop. <-Important!!!
  • Right-click on TDSSKiller.exe and select Run As Administrator.
  • When the program opens, click the Start Scan button.

tdss1.png

  • Do not use the computer during the scan
  • If the scan completes with nothing found, click Close to exit.
  • Any objects found will show in the Scan results - Select action for found objects and offer three options.
  • If an infected file is detected, the default action will be Cure...do not change it.

tdss2.png

  • Click Continue > Reboot now to finish the cleaning process.<- Important!!

tdss4.png

  • If 'Suspicious' objects are detected, you will be given the option to Skip or Quarantine. Skip will be the default selection. Leave it as such for now.
  • A log file named TDSSKiller_version_date_time_log.txt will be created and saved to the root directory (usually Local Disk C:).
  • Copy and paste the contents of that file in your next reply even if no threats are found.
-- If TDSSKiller does not run, try renaming it. To do this, right-click on TDSSKiller.exe, select Rename and give it a random name with the .com file extension (i.e. 123abc.com). If you do not see the file extension, please refer to these instructions. In some cases it may be necessary to redownload TDSSKiller and randomly rename it before downloading and saving to the computer or to perform the scan in "safe mode".
===================================================

Things I would like to see in your next reply. Please be sure to copy and paste any requested log information unless you are asked to attach it. :thumbsup2:
  • Combofix log
  • TDSKiller log

Gary
 
If I do not reply within 24 hours please send me a Personal Message.

"Lord, to whom would we go? You have the words that give eternal life. We believe, and we know you are the Holy One of God."




0 user(s) are reading this topic

0 members, 0 guests, 0 anonymous users