We’d like to remind Forumites to please avoid political debate on the Forum.
This is to keep it a safe and useful space for MoneySaving discussions. Threads that are – or become – political in nature may be removed in line with the Forum’s rules. Thank you for your understanding.
📨 Have you signed up to the Forum's new Email Digest yet? Get a selection of trending threads sent straight to your inbox daily, weekly or monthly!
Possible virus - weird computer problem UPDATED with hijack results please help!
Comments
-
I won't but I would imagine that rik or one of ther others might ask for the malwarebytes log with the problems on it , it in the logs tab.
edit : Too Late the maestro beat me to it4.8kWp 12x400W Longhi 9.6 kWh battery Giv-hy 5.0 Inverter, WSW facing Essex . Aint no sunshine ☀️ Octopus gas fixed dec 24 @ 5.74 tracker again+ Octopus Intelligent Flux leccy0 -
Thank you for looking at it for me : ) This is the 1st log
(split over several posts as very long!)
Malwarebytes' Anti-Malware 1.50.1.1100
www.malwarebytes.org
Database version: 5560
Windows 6.1.7600
Internet Explorer 8.0.7600.16385
20/01/2011 17:26:41
mbam-log-2011-01-20 (17-26-41).txt
Scan type: Quick scan
Objects scanned: 158600
Time elapsed: 4 minute(s), 52 second(s)
Memory Processes Infected: 1
Memory Modules Infected: 1
Registry Keys Infected: 134
Registry Values Infected: 10
Registry Data Items Infected: 0
Folders Infected: 18
Files Infected: 76
Memory Processes Infected:
c:\program files (x86)\mywebsearch\bar\1.bin\MWSOEMON.EXE (Adware.MyWebSearch) -> 4828 -> Unloaded process successfully.
Memory Modules Infected:
c:\program files (x86)\mywebsearch\bar\1.bin\MWSOESTB.DLL (Adware.MyWebSearch) -> Delete on reboot.
Registry Keys Infected:
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\MyWebSearchService (Adware.MyWebSearch) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\CLSID\{00A6FAF1-072E-44cf-8957-5838F569A31D} (Adware.MyWebSearch) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{00A6FAF1-072E-44CF-8957-5838F569A31D} (Adware.MyWebSearch) -> Quarantined and deleted successfully.
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\Settings\{00A6FAF1-072E-44CF-8957-5838F569A31D} (Adware.MyWebSearch) -> Quarantined and deleted successfully.
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\Stats\{00A6FAF1-072E-44CF-8957-5838F569A31D} (Adware.MyWebSearch) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\CLSID\{07B18EA1-A523-4961-B6BB-170DE4475CCA} (Adware.MyWebSearch) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{07B18EA1-A523-4961-B6BB-170DE4475CCA} (Adware.MyWebSearch) -> Quarantined and deleted successfully.
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\Settings\{07B18EA1-A523-4961-B6BB-170DE4475CCA} (Adware.MyWebSearch) -> Quarantined and deleted successfully.
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\Stats\{07B18EA1-A523-4961-B6BB-170DE4475CCA} (Adware.MyWebSearch) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\TypeLib\{07B18EA0-A523-4961-B6BB-170DE4475CCA} (Adware.MyWebSearch) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\Interface\{07B18EAA-A523-4961-B6BB-170DE4475CCA} (Adware.MyWebSearch) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\MyWebSearch bar Uninstall (Adware.MyWebSearch) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\CLSID\{00A6FAF6-072E-44cf-8957-5838F569A31D} (Adware.MyWebSearch) -> Quarantined and deleted successfully.
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\Stats\{00A6FAF6-072E-44CF-8957-5838F569A31D} (Adware.MyWebSearch) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\CLSID\{07B18EA9-A523-4961-B6BB-170DE4475CCA} (Adware.MyWebSearch) -> Quarantined and deleted successfully.
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\Settings\{07B18EA9-A523-4961-B6BB-170DE4475CCA} (Adware.MyWebSearch) -> Quarantined and deleted successfully.
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\Stats\{07B18EA9-A523-4961-B6BB-170DE4475CCA} (Adware.MyWebSearch) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\CLSID\{07B18EAB-A523-4961-B6BB-170DE4475CCA} (Adware.MyWebSearch) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\MyWebSearchToolBar.SettingsPlugin.1 (Adware.MyWebSearch) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\MyWebSearchToolBar.SettingsPlugin (Adware.MyWebSearch) -> Quarantined and deleted successfully.
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\Stats\{07B18EAB-A523-4961-B6BB-170DE4475CCA} (Adware.MyWebSearch) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{07B18EAB-A523-4961-B6BB-170DE4475CCA} (Adware.MyWebSearch) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\CLSID\{0F8ECF4F-3646-4C3A-8881-8E138FFCAF70} (Adware.MyWebSearch) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\TypeLib\{8CA01F0E-987C-49C3-B852-2F1AC4A7094C} (Adware.MyWebSearch) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\Interface\{1093995A-BA37-41D2-836E-091067C4AD17} (Adware.MyWebSearch) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\FunWebProducts.IECookiesManager.1 (Adware.MyWebSearch) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\FunWebProducts.IECookiesManager (Adware.MyWebSearch) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\CLSID\{147A976F-EEE1-4377-8EA7-4716E4CDD239} (Adware.MyWebSearch) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\CLSID\{1E0DE227-5CE4-4ea3-AB0C-8B03E1AA76BC} (Adware.MyWebSearch) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\CLSID\{25560540-9571-4D7B-9389-0F166788785A} (Adware.MyWebSearch) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\TypeLib\{C8CECDE3-1AE1-4C4A-AD82-6D5B00212144} (Adware.MyWebSearch) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\Interface\{17DE5E5E-BFE3-4E83-8E1F-8755795359EC} (Adware.MyWebSearch) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\FunWebProducts.DataControl.1 (Adware.MyWebSearch) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\FunWebProducts.DataControl (Adware.MyWebSearch) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{25560540-9571-4D7B-9389-0F166788785A} (Adware.MyWebSearch) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\CLSID\{3DC201FB-E9C9-499C-A11F-23C360D7C3F8} (Adware.MyWebSearch) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\TypeLib\{E47CAEE0-DEEA-464A-9326-3F2801535A4D} (Adware.MyWebSearch) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\Interface\{3E1656ED-F60E-4597-B6AA-B6A58E171495} (Adware.MyWebSearch) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\FunWebProducts.HTMLMenu.2 (Adware.MyWebSearch) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\FunWebProducts.HTMLMenu (Adware.MyWebSearch) -> Quarantined and deleted successfully.
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\Stats\{3DC201FB-E9C9-499C-A11F-23C360D7C3F8} (Adware.MyWebSearch) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{3DC201FB-E9C9-499C-A11F-23C360D7C3F8} (Adware.MyWebSearch) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\CLSID\{3E720452-B472-4954-B7AA-33069EB53906} (Adware.MyWebSearch) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\TypeLib\{3E720450-B472-4954-B7AA-33069EB53906} (Adware.MyWebSearch) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\Interface\{3E720451-B472-4954-B7AA-33069EB53906} (Adware.MyWebSearch) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\MyWebSearch.HTMLPanel.1 (Adware.MyWebSearch) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\MyWebSearch.HTMLPanel (Adware.MyWebSearch) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{3E720452-B472-4954-B7AA-33069EB53906} (Adware.MyWebSearch) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\CLSID\{53CED2D0-5E9A-4761-9005-648404E6F7E5} (Adware.MyWebSearch) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\MyWebSearchToolBar.ToolbarPlugin.1 (Adware.MyWebSearch) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\MyWebSearchToolBar.ToolbarPlugin (Adware.MyWebSearch) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\CLSID\{63D0ED2C-B45B-4458-8B3B-60C69BBBD83C} (Adware.MyWebSearch) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\TypeLib\{8E6F1830-9607-4440-8530-13BE7C4B1D14} (Adware.MyWebSearch) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\Interface\{63D0ED2B-B45B-4458-8B3B-60C69BBBD83C} (Adware.MyWebSearch) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\FunWebProducts.PopSwatterSettingsControl.1 (Adware.MyWebSearch) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\FunWebProducts.PopSwatterSettingsControl (Adware.MyWebSearch) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{63D0ED2C-B45B-4458-8B3B-60C69BBBD83C} (Adware.MyWebSearch) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\CLSID\{7473D292-B7BB-4f24-AE82-7E2CE94BB6A9} (Adware.MyWebSearch) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\TypeLib\{7473D290-B7BB-4F24-AE82-7E2CE94BB6A9} (Adware.MyWebSearch) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\Interface\{7473D291-B7BB-4F24-AE82-7E2CE94BB6A9} (Adware.MyWebSearch) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\CLSID\{7473D294-B7BB-4f24-AE82-7E2CE94BB6A9} (Adware.MyWebSearch) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\MyWebSearch.PseudoTransparentPlugin.1 (Adware.MyWebSearch) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\MyWebSearch.PseudoTransparentPlugin (Adware.MyWebSearch) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{7473D294-B7BB-4F24-AE82-7E2CE94BB6A9} (Adware.MyWebSearch) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\CLSID\{7473D296-B7BB-4f24-AE82-7E2CE94BB6A9} (Adware.MyWebSearch) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\CLSID\{84DA4FDF-A1CF-4195-8688-3E961F505983} (Adware.MyWebSearch) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\CLSID\{8E6F1832-9607-4440-8530-13BE7C4B1D14} (Adware.MyWebSearch) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\FunWebProducts.PopSwatterBarButton.1 (Adware.MyWebSearch) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\FunWebProducts.PopSwatterBarButton (Adware.MyWebSearch) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\CLSID\{938AA51A-996C-4884-98CE-80DD16A5C9DA} (Adware.MyWebSearch) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\TypeLib\{29D67D3C-509A-4544-903F-C8C1B8236554} (Adware.MyWebSearch) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\Interface\{2E3537FC-CF2F-4F56-AF54-5A6A3DD375CC} (Adware.MyWebSearch) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\CLSID\{98D9753D-D73B-42D5-8C85-4469CDA897AB} (Adware.MyWebSearch) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\FunWebProducts.HTMLMenu.1 (Adware.MyWebSearch) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{98D9753D-D73B-42D5-8C85-4469CDA897AB} (Adware.MyWebSearch) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\CLSID\{9FF05104-B030-46FC-94B8-81276E4E27DF} (Adware.MyWebSearch) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\ScreenSaverControl.ScreenSaverInstaller.1 (Adware.MyWebSearch) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\ScreenSaverControl.ScreenSaverInstaller (Adware.MyWebSearch) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{9FF05104-B030-46FC-94B8-81276E4E27DF} (Adware.MyWebSearch) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\CLSID\{A4730EBE-43A6-443e-9776-36915D323AD3} (Adware.MyWebSearch) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\CLSID\{A9571378-68A1-443d-B082-284F960C6D17} (Adware.MyWebSearch) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\CLSID\{ADB01E81-3C79-4272-A0F1-7B2BE7A782DC} (Adware.MyWebSearch) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\MyWebSearch.OutlookAddin.1 (Adware.MyWebSearch) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\MyWebSearch.OutlookAddin (Adware.MyWebSearch) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\CLSID\{B813095C-81C0-4E40-AA14-67520372B987} (Adware.MyWebSearch) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\FunWebProducts.KillerObjManager.1 (Adware.MyWebSearch) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\FunWebProducts.KillerObjManager (Adware.MyWebSearch) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\CLSID\{C9D7BE3E-141A-4C85-8CD6-32461F3DF2C7} (Adware.MyWebSearch) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\FunWebProducts.HistoryKillerScheduler.1 (Adware.MyWebSearch) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\FunWebProducts.HistoryKillerScheduler (Adware.MyWebSearch) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\CLSID\{CFF4CE82-3AA2-451F-9B77-7165605FB835} (Adware.MyWebSearch) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\FunWebProducts.HistorySwatterControlBar.1 (Adware.MyWebSearch) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\FunWebProducts.HistorySwatterControlBar (Adware.MyWebSearch) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\CLSID\{D9FFFB27-D62A-4D64-8CEC-1FF006528805} (Adware.MyWebSearch) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\TypeLib\{0D26BC71-A633-4E71-AD31-EADC3A1B6A3A} (Adware.MyWebSearch) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\Interface\{E342AF55-B78A-4CD0-A2BB-DA7F52D9D25E} (Adware.MyWebSearch) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\CLSID\{E79DFBCA-5697-4fbd-94E5-5B2A9C7C1612} (Adware.MyWebSearch) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\TypeLib\{E79DFBC0-5697-4FBD-94E5-5B2A9C7C1612} (Adware.MyWebSearch) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\Interface\{72EE7F04-15BD-4845-A005-D6711144D86A} (Adware.MyWebSearch) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\MyWebSearch.ChatSessionPlugin.1 (Adware.MyWebSearch) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\MyWebSearch.ChatSessionPlugin (Adware.MyWebSearch) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{E79DFBCA-5697-4FBD-94E5-5B2A9C7C1612} (Adware.MyWebSearch) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\Typelib\{D518921A-4A03-425E-9873-B9A71756821E} (Adware.MyWebSearch) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\Interface\{CF54BE1C-9359-4395-8533-1657CF209CFE} (Adware.MyWebSearch) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\Typelib\{F42228FB-E84E-479E-B922-FBBD096E792C} (Adware.MyWebSearch) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\Interface\{6E74766C-4D93-4CC0-96D1-47B8E07FF9CA} (Adware.MyWebSearch) -> Quarantined and deleted successfully.
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{56256A51-B582-467e-B8D4-7786EDA79AE0} (Trojan.Vundo) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{56256A51-B582-467e-B8D4-7786EDA79AE0} (Trojan.Vundo) -> Quarantined and deleted successfully.
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\Settings\{1D4DB7D2-6EC9-47A3-BD87-1E41684E07BB} (Adware.MyWebSearch) -> Quarantined and deleted successfully.
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\Stats\{1D4DB7D2-6EC9-47A3-BD87-1E41684E07BB} (Adware.MyWebSearch) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{1D4DB7D2-6EC9-47A3-BD87-1E41684E07BB} (Adware.MyWebSearch) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{59C7FC09-1C83-4648-B3E6-003D2BBC7481} (Adware.MyWebSearch) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{68AF847F-6E91-45dd-9B68-D6A12C30E5D7} (Adware.MyWebSearch) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{9170B96C-28D4-4626-8358-27E6CAEEF907} (Adware.MyWebSearch) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{D1A71FA0-FF48-48dd-9B6D-7A13A3E42127} (Adware.MyWebSearch) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{DDB1968E-EAD6-40fd-8DAE-FF14757F60C7} (Adware.MyWebSearch) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{F138D901-86F0-4383-99B6-9CDD406036DA} (Adware.MyWebSearch) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\MyWebSearch.MultipleButton (Adware.MyWebSearch) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\MyWebSearch.MultipleButton.1 (Adware.MyWebSearch) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\MyWebSearch.UrlAlertButton (Adware.MyWebSearch) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\MyWebSearch.UrlAlertButton.1 (Adware.MyWebSearch) -> Quarantined and deleted successfully.
HKEY_CURRENT_USER\SOFTWARE\MyWebSearch (Adware.MyWebSearch) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\FocusInteractive (Adware.MyWebSearch) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Fun Web Products (Adware.MyWebSearch) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\MyWebSearch (Adware.MyWebSearch) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Low Rights\RunDll32Policy\f3ScrCtr.dll (Adware.MyWebSearch) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Multimedia\WMPlayer\Schemes\f3pss (Adware.MyWebSearch) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Office\Outlook\Addins\MyWebSearch.OutlookAddin (Adware.MyWebSearch) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Office\Word\Addins\MyWebSearch.OutlookAddin (Adware.MyWebSearch) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\CLSID\{819FFE22-35C7-4925-8CDA-4E0E2DB94302} (Adware.MyWebSearch) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\TypeLib\{819FFE20-35C7-4925-8CDA-4E0E2DB94302} (Adware.MyWebSearch) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\Interface\{819FFE21-35C7-4925-8CDA-4E0E2DB94302} (Adware.MyWebSearch) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\CLSID\{799391D3-EB86-4bac-9BD3-CBFEA58A0E15} (Adware.MyWebSearch) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\CLSID\{D858DAFC-9573-4811-B323-7011A3AA7E61} (Adware.MyWebSearch) -> Quarantined and deleted successfully0 -
Registry Values Infected:
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\MyWebSearch Email Plugin (Adware.MyWebSearch) -> Value: MyWebSearch Email Plugin -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\My Web Search Bar Search Scope Monitor (Adware.MyWebSearch) -> Value: My Web Search Bar Search Scope Monitor -> Quarantined and deleted successfully.
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Internet Explorer\URLSearchHooks\{00A6FAF6-072E-44CF-8957-5838F569A31D} (Adware.MyWebSearch) -> Value: {00A6FAF6-072E-44CF-8957-5838F569A31D} -> Quarantined and deleted successfully.
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Internet Explorer\Toolbar\WebBrowser\{07B18EA9-A523-4961-B6BB-170DE4475CCA} (Adware.MyWebSearch) -> Value: {07B18EA9-A523-4961-B6BB-170DE4475CCA} -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar\{07B18EA9-A523-4961-B6BB-170DE4475CCA} (Adware.MyWebSearch) -> Value: {07B18EA9-A523-4961-B6BB-170DE4475CCA} -> Quarantined and deleted successfully.
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Internet Explorer\Toolbar\WebBrowser\{07B18EA9-A523-4961-B6BB-170DE4475CCA} (Adware.MyWebSearch) -> Value: {07B18EA9-A523-4961-B6BB-170DE4475CCA} -> Quarantined and deleted successfully.
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Internet Explorer\URLSearchHooks\{00A6FAF6-072E-44cf-8957-5838F569A31D} (Adware.MyWebSearch) -> Value: {00A6FAF6-072E-44cf-8957-5838F569A31D} -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar\{07B18EA9-A523-4961-B6BB-170DE4475CCA} (Adware.MyWebSearch) -> Value: {07B18EA9-A523-4961-B6BB-170DE4475CCA} -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows Media\WMSDK\Sources\f3PopularScreensavers (Adware.MyWebSearch) -> Value: f3PopularScreensavers -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\User Agent\Post Platform\FunWebProducts (Adware.MyWebSearch) -> Value: FunWebProducts -> Quarantined and deleted successfully.
Registry Data Items Infected:
(No malicious items detected)
Folders Infected:
c:\program files (x86)\funwebproducts (Adware.MyWebSearch) -> Quarantined and deleted successfully.
c:\program files (x86)\funwebproducts\Installr (Adware.MyWebSearch) -> Quarantined and deleted successfully.
c:\program files (x86)\funwebproducts\Installr\1.bin (Adware.MyWebSearch) -> Quarantined and deleted successfully.
c:\program files (x86)\funwebproducts\Installr\setups (Adware.MyWebSearch) -> Quarantined and deleted successfully.
c:\program files (x86)\funwebproducts\screensaver (Adware.MyWebSearch) -> Quarantined and deleted successfully.
c:\program files (x86)\funwebproducts\screensaver\Images (Adware.MyWebSearch) -> Quarantined and deleted successfully.
c:\program files (x86)\mywebsearch (Adware.MyWebSearch) -> Delete on reboot.
c:\program files (x86)\mywebsearch\bar (Adware.MyWebSearch) -> Delete on reboot.
c:\program files (x86)\mywebsearch\bar\1.bin (Adware.MyWebSearch) -> Delete on reboot.
c:\program files (x86)\mywebsearch\bar\1.bin\chrome (Adware.MyWebSearch) -> Quarantined and deleted successfully.
c:\program files (x86)\mywebsearch\bar\Avatar (Adware.MyWebSearch) -> Quarantined and deleted successfully.
c:\program files (x86)\mywebsearch\bar\Game (Adware.MyWebSearch) -> Quarantined and deleted successfully.
c:\program files (x86)\mywebsearch\bar\History (Adware.MyWebSearch) -> Quarantined and deleted successfully.
c:\program files (x86)\mywebsearch\bar\icons (Adware.MyWebSearch) -> Quarantined and deleted successfully.
c:\program files (x86)\mywebsearch\bar\Message (Adware.MyWebSearch) -> Quarantined and deleted successfully.
c:\program files (x86)\mywebsearch\bar\Notifier (Adware.MyWebSearch) -> Quarantined and deleted successfully.
c:\program files (x86)\mywebsearch\bar\Overlay (Adware.MyWebSearch) -> Quarantined and deleted successfully.
c:\program files (x86)\mywebsearch\bar\Settings (Adware.MyWebSearch) -> Quarantined and deleted successfully.
Files Infected:
c:\Program Files (x86)\MyWebSearch\bar\1.bin\MWSSVC.EXE (Adware.MyWebSearch) -> Quarantined and deleted successfully.
c:\program files (x86)\mywebsearch\bar\1.bin\MWSOESTB.DLL (Adware.MyWebSearch) -> Quarantined and deleted successfully.
c:\program files (x86)\mywebsearch\bar\1.bin\MWSOEMON.EXE (Adware.MyWebSearch) -> Quarantined and deleted successfully.
c:\program files (x86)\mywebsearch\bar\1.bin\M3SRCHMN.EXE (Adware.MyWebSearch) -> Quarantined and deleted successfully.
c:\program files (x86)\mywebsearch\bar\1.bin\MWSSRCAS.DLL (Adware.MyWebSearch) -> Quarantined and deleted successfully.
c:\program files (x86)\mywebsearch\bar\1.bin\MWSBAR.DLL (Adware.MyWebSearch) -> Quarantined and deleted successfully.
c:\program files (x86)\mywebsearch\bar\1.bin\F3HISTSW.DLL (Adware.MyWebSearch) -> Quarantined and deleted successfully.
c:\program files (x86)\mywebsearch\bar\1.bin\F3DTACTL.DLL (Adware.MyWebSearch) -> Quarantined and deleted successfully.
c:\program files (x86)\mywebsearch\bar\1.bin\F3HTMLMU.DLL (Adware.MyWebSearch) -> Quarantined and deleted successfully.
c:\program files (x86)\mywebsearch\bar\1.bin\M3HTML.DLL (Adware.MyWebSearch) -> Quarantined and deleted successfully.
c:\program files (x86)\mywebsearch\bar\1.bin\F3POPSWT.DLL (Adware.MyWebSearch) -> Quarantined and deleted successfully.
c:\program files (x86)\mywebsearch\bar\1.bin\M3SKIN.DLL (Adware.MyWebSearch) -> Quarantined and deleted successfully.
c:\program files (x86)\mywebsearch\bar\1.bin\F3CJPEG.DLL (Adware.MyWebSearch) -> Quarantined and deleted successfully.
c:\program files (x86)\mywebsearch\bar\1.bin\F3SCRCTR.DLL (Adware.MyWebSearch) -> Quarantined and deleted successfully.
c:\program files (x86)\mywebsearch\bar\1.bin\M3OUTLCN.DLL (Adware.MyWebSearch) -> Quarantined and deleted successfully.
c:\program files (x86)\mywebsearch\bar\1.bin\F3HTTPCT.DLL (Adware.MyWebSearch) -> Quarantined and deleted successfully.
c:\program files (x86)\mywebsearch\bar\1.bin\M3MSG.DLL (Adware.MyWebSearch) -> Quarantined and deleted successfully.
c:\program files (x86)\mywebsearch\bar\1.bin\F3REPROX.DLL (Adware.MyWebSearch) -> Quarantined and deleted successfully.
c:\program files (x86)\mywebsearch\bar\1.bin\MWSOEPLG.DLL (Adware.MyWebSearch) -> Quarantined and deleted successfully.
c:\Windows\System32\f3PSSavr.scr (PUP.FunWebProducts) -> Not selected for removal.
c:\Windows\SysWOW64\f3PSSavr.scr (PUP.FunWebProducts) -> Not selected for removal.
c:\Users\lou\AppData\Local\Temp\78E9.tmp (Rootkit.TDSS) -> Quarantined and deleted successfully.
c:\Users\lou\myfuncards.exe (PUP.FunWebProducts) -> Not selected for removal.
c:\program files (x86)\funwebproducts\Installr\1.bin\F3EZSETP.DLL (Adware.MyWebSearch) -> Quarantined and deleted successfully.
c:\program files (x86)\funwebproducts\Installr\1.bin\F3PLUGIN.DLL (Adware.MyWebSearch) -> Quarantined and deleted successfully.
c:\program files (x86)\funwebproducts\Installr\1.bin\NPFUNWEB.DLL (Adware.MyWebSearch) -> Quarantined and deleted successfully.
c:\program files (x86)\mywebsearch\bar\1.bin\chrome.manifest (Adware.MyWebSearch) -> Quarantined and deleted successfully.
c:\program files (x86)\mywebsearch\bar\1.bin\F3BKGERR.JPG (Adware.MyWebSearch) -> Quarantined and deleted successfully.
c:\program files (x86)\mywebsearch\bar\1.bin\F3HKSTUB.DLL (Adware.MyWebSearch) -> Quarantined and deleted successfully.
c:\program files (x86)\mywebsearch\bar\1.bin\F3IMSTUB.DLL (Adware.MyWebSearch) -> Quarantined and deleted successfully.
c:\program files (x86)\mywebsearch\bar\1.bin\F3PSSAVR.SCR (Adware.MyWebSearch) -> Quarantined and deleted successfully.
c:\program files (x86)\mywebsearch\bar\1.bin\F3REGHK.DLL (Adware.MyWebSearch) -> Quarantined and deleted successfully.
c:\program files (x86)\mywebsearch\bar\1.bin\F3RESTUB.DLL (Adware.MyWebSearch) -> Quarantined and deleted successfully.
c:\program files (x86)\mywebsearch\bar\1.bin\F3SCHMON.EXE (Adware.MyWebSearch) -> Quarantined and deleted successfully.
c:\program files (x86)\mywebsearch\bar\1.bin\F3SPACER.WMV (Adware.MyWebSearch) -> Quarantined and deleted successfully.
c:\program files (x86)\mywebsearch\bar\1.bin\F3WALLPP.DAT (Adware.MyWebSearch) -> Quarantined and deleted successfully.
c:\program files (x86)\mywebsearch\bar\1.bin\F3WPHOOK.DLL (Adware.MyWebSearch) -> Quarantined and deleted successfully.
c:\program files (x86)\mywebsearch\bar\1.bin\FWPBUDDY.PNG (Adware.MyWebSearch) -> Quarantined and deleted successfully.
c:\program files (x86)\mywebsearch\bar\1.bin\INSTALL.RDF (Adware.MyWebSearch) -> Quarantined and deleted successfully.
c:\program files (x86)\mywebsearch\bar\1.bin\M3AUXSTB.DLL (Adware.MyWebSearch) -> Quarantined and deleted successfully.
c:\program files (x86)\mywebsearch\bar\1.bin\M3DLGHK.DLL (Adware.MyWebSearch) -> Quarantined and deleted successfully.
c:\program files (x86)\mywebsearch\bar\1.bin\M3HIGHIN.EXE (Adware.MyWebSearch) -> Quarantined and deleted successfully.
c:\program files (x86)\mywebsearch\bar\1.bin\M3IDLE.DLL (Adware.MyWebSearch) -> Quarantined and deleted successfully.
c:\program files (x86)\mywebsearch\bar\1.bin\M3IMPIPE.EXE (Adware.MyWebSearch) -> Quarantined and deleted successfully.
c:\program files (x86)\mywebsearch\bar\1.bin\M3MEDINT.EXE (Adware.MyWebSearch) -> Quarantined and deleted successfully.
c:\program files (x86)\mywebsearch\bar\1.bin\M3PLUGIN.DLL (Adware.MyWebSearch) -> Quarantined and deleted successfully.
c:\program files (x86)\mywebsearch\bar\1.bin\M3SKPLAY.EXE (Adware.MyWebSearch) -> Quarantined and deleted successfully.
c:\program files (x86)\mywebsearch\bar\1.bin\M3SLSRCH.EXE (Adware.MyWebSearch) -> Quarantined and deleted successfully.
c:\program files (x86)\mywebsearch\bar\1.bin\MWSMLBTN.DLL (Adware.MyWebSearch) -> Quarantined and deleted successfully.
c:\program files (x86)\mywebsearch\bar\1.bin\MWSUABTN.DLL (Adware.MyWebSearch) -> Quarantined and deleted successfully.
c:\program files (x86)\mywebsearch\bar\1.bin\NPMYWEBS.DLL (Adware.MyWebSearch) -> Quarantined and deleted successfully.
c:\program files (x86)\mywebsearch\bar\1.bin\chrome\M3FFXTBR.JAR (Adware.MyWebSearch) -> Quarantined and deleted successfully.
c:\program files (x86)\mywebsearch\bar\Avatar\COMMON.F3S (Adware.MyWebSearch) -> Quarantined and deleted successfully.
c:\program files (x86)\mywebsearch\bar\Game\CHECKERS.F3S (Adware.MyWebSearch) -> Quarantined and deleted successfully.
c:\program files (x86)\mywebsearch\bar\Game\CHESS.F3S (Adware.MyWebSearch) -> Quarantined and deleted successfully.
c:\program files (x86)\mywebsearch\bar\Game\REVERSI.F3S (Adware.MyWebSearch) -> Quarantined and deleted successfully.
c:\program files (x86)\mywebsearch\bar\icons\CM.ICO (Adware.MyWebSearch) -> Quarantined and deleted successfully.
c:\program files (x86)\mywebsearch\bar\icons\MFC.ICO (Adware.MyWebSearch) -> Quarantined and deleted successfully.
c:\program files (x86)\mywebsearch\bar\icons\PSS.ICO (Adware.MyWebSearch) -> Quarantined and deleted successfully.
c:\program files (x86)\mywebsearch\bar\icons\SMILEY.ICO (Adware.MyWebSearch) -> Quarantined and deleted successfully.
c:\program files (x86)\mywebsearch\bar\icons\WB.ICO (Adware.MyWebSearch) -> Quarantined and deleted successfully.
c:\program files (x86)\mywebsearch\bar\icons\ZWINKY.ICO (Adware.MyWebSearch) -> Quarantined and deleted successfully.
c:\program files (x86)\mywebsearch\bar\Message\COMMON.F3S (Adware.MyWebSearch) -> Quarantined and deleted successfully.
c:\program files (x86)\mywebsearch\bar\Notifier\COMMON.F3S (Adware.MyWebSearch) -> Quarantined and deleted successfully.
c:\program files (x86)\mywebsearch\bar\Notifier\DOG.F3S (Adware.MyWebSearch) -> Quarantined and deleted successfully.
c:\program files (x86)\mywebsearch\bar\Notifier\FISH.F3S (Adware.MyWebSearch) -> Quarantined and deleted successfully.
c:\program files (x86)\mywebsearch\bar\Notifier\KUNGFU.F3S (Adware.MyWebSearch) -> Quarantined and deleted successfully.
c:\program files (x86)\mywebsearch\bar\Notifier\LIFEGARD.F3S (Adware.MyWebSearch) -> Quarantined and deleted successfully.
c:\program files (x86)\mywebsearch\bar\Notifier\MAID.F3S (Adware.MyWebSearch) -> Quarantined and deleted successfully.
c:\program files (x86)\mywebsearch\bar\Notifier\MAILBOX.F3S (Adware.MyWebSearch) -> Quarantined and deleted successfully.
c:\program files (x86)\mywebsearch\bar\Notifier\OPERA.F3S (Adware.MyWebSearch) -> Quarantined and deleted successfully.
c:\program files (x86)\mywebsearch\bar\Notifier\ROBOT.F3S (Adware.MyWebSearch) -> Quarantined and deleted successfully.
c:\program files (x86)\mywebsearch\bar\Notifier\SEDUCT.F3S (Adware.MyWebSearch) -> Quarantined and deleted successfully.
c:\program files (x86)\mywebsearch\bar\Notifier\SURFER.F3S (Adware.MyWebSearch) -> Quarantined and deleted successfully.
c:\program files (x86)\mywebsearch\bar\Overlay\COMMON.F3S (Adware.MyWebSearch) -> Quarantined and deleted successfully.
c:\program files (x86)\mywebsearch\bar\Settings\s_pid.dat (Adware.MyWebSearch) -> Quarantined and deleted successfully.0 -
i then did another full scan and it produced the following results:
Malwarebytes' Anti-Malware 1.50.1.1100
www.malwarebytes.org
Database version: 5560
Windows 6.1.7600
Internet Explorer 8.0.7600.16385
20/01/2011 18:42:39
mbam-log-2011-01-20 (18-42-39).txt
Scan type: Full scan (C:\|D:\|)
Objects scanned: 339002
Time elapsed: 1 hour(s), 9 minute(s), 35 second(s)
Memory Processes Infected: 0
Memory Modules Infected: 0
Registry Keys Infected: 0
Registry Values Infected: 0
Registry Data Items Infected: 0
Folders Infected: 0
Files Infected: 5
Memory Processes Infected:
(No malicious items detected)
Memory Modules Infected:
(No malicious items detected)
Registry Keys Infected:
(No malicious items detected)
Registry Values Infected:
(No malicious items detected)
Registry Data Items Infected:
(No malicious items detected)
Folders Infected:
(No malicious items detected)
Files Infected:
c:\program files (x86)\windows live\messenger\msimg32.dll (PUP.FunWebProducts) -> Quarantined and deleted successfully.
c:\program files (x86)\windows live\messenger\riched20.dll (PUP.FunWebProducts) -> Quarantined and deleted successfully.
c:\Users\lou\myfuncards.exe (PUP.FunWebProducts) -> Quarantined and deleted successfully.
c:\Windows\System32\f3PSSavr.scr (PUP.FunWebProducts) -> Quarantined and deleted successfully.
c:\Windows\SysWOW64\f3PSSavr.scr (PUP.FunWebProducts) -> Quarantined and deleted successfully.
I then did the quick test again and the hijack this log which are in post #100 -
Download SUPERANTISPYWARE (Make sure you click 'DOWNLOAD LATEST VERSION')
http://www.filehippo.com/download_superantispyware/
UPDATE and PERFORM COMPLETE SCAN
(Then goto console and LOGS and post the log it created then untick it from STARTING UP WITH WINDOWS):idea:0 -
Also TICK and FIX these in hijack -
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant = http://start.facemoods.com/?a=snd&s={searchTerms}&f=4
R3 - URLSearchHook: SweetIM ToolbarURLSearchHook Class - {EEE6C35D-6118-11DC-9C72-001320C79847} - C:\Program Files (x86)\SweetIM\Toolbars\Internet Explorer\mgHelper.dll (file missing)
O2 - BHO: (no name) - {5C255C8A-E604-49b4-9D64-90988571CECB} - (no file)
O2 - BHO: facemoods Helper - {64182481-4F71-486b-A045-B233BD0DA8FC} - C:\Program Files (x86)\facemoods.com\facemoods\1.4.15.13\bh\facemoo ds.dll (file missing)
O2 - BHO: Ask Toolbar BHO - {D4027C7F-154A-4066-A1AD-4243D8127440} - C:\Program Files (x86)\Ask.com\GenericAskToolbar.dll (file missing)
O2 - BHO: SWEETIE - {EEE6C35C-6118-11DC-9C72-001320C79847} - C:\Program Files (x86)\SweetIM\Toolbars\Internet Explorer\mgToolbarIE.dll (file missing)
O3 - Toolbar: SweetIM Toolbar for Internet Explorer - {EEE6C35B-6118-11DC-9C72-001320C79847} - C:\Program Files (x86)\SweetIM\Toolbars\Internet Explorer\mgToolbarIE.dll (file missing)
O3 - Toolbar: facemoods Toolbar - {DB4E9724-F518-4dfd-9C7C-78B52103CAB9} - C:\Program Files (x86)\facemoods.com\facemoods\1.4.15.13\facemoodsT lbr.dll (file missing)
O3 - Toolbar: Ask Toolbar - {D4027C7F-154A-4066-A1AD-4243D8127440} - C:\Program Files (x86)\Ask.com\GenericAskToolbar.dll (file missing)
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files (x86)\QuickTime\QTTask.exe" -atboottime:idea:0 -
Here are the scan results from superantispyware
SUPERAntiSpyware Scan Log
http://www.superantispyware.com
Generated 01/20/2011 at 10:06 PM
Application Version : 4.48.1000
Core Rules Database Version : 6243
Trace Rules Database Version: 4055
Scan type : Complete Scan
Total Scan Time : 00:47:37
Memory items scanned : 780
Memory threats detected : 0
Registry items scanned : 13880
Registry threats detected : 141
File items scanned : 30949
File threats detected : 615
Adware.Tracking Cookie
C:\Users\lou\AppData\Roaming\Microsoft\Windows\Cookies\lou@www.westsussex.gov[1].txt
C:\Users\lou\AppData\Roaming\Microsoft\Windows\Cookies\lou@atdmt[2].txt
C:\Users\lou\AppData\Roaming\Microsoft\Windows\Cookies\lou@www.yourspacewestsussex.co[1].txt
C:\Users\lou\AppData\Roaming\Microsoft\Windows\Cookies\lou@doubleclick[1].txt
C:\Users\lou\AppData\Roaming\Microsoft\Windows\Cookies\lou@statse.webtrendslive[2].txt
C:\Users\lou\AppData\Roaming\Microsoft\Windows\Cookies\lou@eaeacom.112.2o7[1].txt
cdn5.specificclick.net [ C:\Users\lou\AppData\Roaming\Macromedia\Flash Player\#SharedObjects\LKN423QC ]
cloud.video.unrulymedia.com [ C:\Users\lou\AppData\Roaming\Macromedia\Flash Player\#SharedObjects\LKN423QC ]
content.oddcast.com [ C:\Users\lou\AppData\Roaming\Macromedia\Flash Player\#SharedObjects\LKN423QC ]
core.insightexpressai.com [ C:\Users\lou\AppData\Roaming\Macromedia\Flash Player\#SharedObjects\LKN423QC ]
ec.atdmt.com [ C:\Users\lou\AppData\Roaming\Macromedia\Flash Player\#SharedObjects\LKN423QC ]
files.youporn.com [ C:\Users\lou\AppData\Roaming\Macromedia\Flash Player\#SharedObjects\LKN423QC ]
gw.callingbanners.com [ C:\Users\lou\AppData\Roaming\Macromedia\Flash Player\#SharedObjects\LKN423QC ]
ia.media-imdb.com [ C:\Users\lou\AppData\Roaming\Macromedia\Flash Player\#SharedObjects\LKN423QC ]
ieadtrack.com [ C:\Users\lou\AppData\Roaming\Macromedia\Flash Player\#SharedObjects\LKN423QC ]
media.entertonement.com [ C:\Users\lou\AppData\Roaming\Macromedia\Flash Player\#SharedObjects\LKN423QC ]
media.mtvnservices.com [ C:\Users\lou\AppData\Roaming\Macromedia\Flash Player\#SharedObjects\LKN423QC ]
s0.2mdn.net [ C:\Users\lou\AppData\Roaming\Macromedia\Flash Player\#SharedObjects\LKN423QC ]
serving-sys.com [ C:\Users\lou\AppData\Roaming\Macromedia\Flash Player\#SharedObjects\LKN423QC ]
sexforums.com [ C:\Users\lou\AppData\Roaming\Macromedia\Flash Player\#SharedObjects\LKN423QC ]
spe.atdmt.com [ C:\Users\lou\AppData\Roaming\Macromedia\Flash Player\#SharedObjects\LKN423QC ]
track.webgains.com [ C:\Users\lou\AppData\Roaming\Macromedia\Flash Player\#SharedObjects\LKN423QC ]
tracking.onefeed.co.uk [ C:\Users\lou\AppData\Roaming\Macromedia\Flash Player\#SharedObjects\LKN423QC ]
www.sexforums.com [ C:\Users\lou\AppData\Roaming\Macromedia\Flash Player\#SharedObjects\LKN423QC ]
C:\Users\lou\AppData\Roaming\Microsoft\Windows\Cookies\lou@ad.yieldmanager[1].txt
C:\Users\lou\AppData\Roaming\Microsoft\Windows\Cookies\lou@mywebsearch[2].txt
C:\Users\lou\AppData\Roaming\Microsoft\Windows\Cookies\Low\lou@content.yieldmanager[8].txt
C:\Users\lou\AppData\Roaming\Microsoft\Windows\Cookies\Low\lou@questionmarket[6].txt
C:\Users\lou\AppData\Roaming\Microsoft\Windows\Cookies\Low\lou@mediaplex[2].txt
C:\Users\lou\AppData\Roaming\Microsoft\Windows\Cookies\Low\lou@care2.112.2o7[1].txt
C:\Users\lou\AppData\Roaming\Microsoft\Windows\Cookies\Low\lou@revsci[6].txt
C:\Users\lou\AppData\Roaming\Microsoft\Windows\Cookies\Low\lou@healthgrades.112.2o7[1].txt
C:\Users\lou\AppData\Roaming\Microsoft\Windows\Cookies\Low\lou@medhelpinternational.112.2o7[2].txt
C:\Users\lou\AppData\Roaming\Microsoft\Windows\Cookies\Low\lou@amznmothercare.122.2o7[1].txt
C:\Users\lou\AppData\Roaming\Microsoft\Windows\Cookies\Low\lou@specificclick[7].txt
C:\Users\lou\AppData\Roaming\Microsoft\Windows\Cookies\Low\lou@blackberrytrackball[2].txt
C:\Users\lou\AppData\Roaming\Microsoft\Windows\Cookies\Low\lou@ads.pointroll[1].txt
C:\Users\lou\AppData\Roaming\Microsoft\Windows\Cookies\Low\lou@media6degrees[9].txt
C:\Users\lou\AppData\Roaming\Microsoft\Windows\Cookies\Low\lou@ad.yieldmanager[5].txt
C:\Users\lou\AppData\Roaming\Microsoft\Windows\Cookies\Low\lou@medhelpinternational.112.2o7[3].txt
C:\Users\lou\AppData\Roaming\Microsoft\Windows\Cookies\Low\lou@adserver.interfacebs[2].txt
C:\Users\lou\AppData\Roaming\Microsoft\Windows\Cookies\Low\lou@eas.apm.emediate[2].txt
C:\Users\lou\AppData\Roaming\Microsoft\Windows\Cookies\Low\lou@mediaplex[1].txt
C:\Users\lou\AppData\Roaming\Microsoft\Windows\Cookies\Low\lou@ad.bodybuilding[2].txt
C:\Users\lou\AppData\Roaming\Microsoft\Windows\Cookies\Low\lou@www.questionhub[1].txt
C:\Users\lou\AppData\Roaming\Microsoft\Windows\Cookies\Low\lou@statcounter[2].txt
C:\Users\lou\AppData\Roaming\Microsoft\Windows\Cookies\Low\lou@counter.hitslink[2].txt
C:\Users\lou\AppData\Roaming\Microsoft\Windows\Cookies\Low\lou@hitbox[4].txt
C:\Users\lou\AppData\Roaming\Microsoft\Windows\Cookies\Low\lou@www.3dstats[1].txt
C:\Users\lou\AppData\Roaming\Microsoft\Windows\Cookies\Low\lou@liveperson[3].txt
C:\Users\lou\AppData\Roaming\Microsoft\Windows\Cookies\Low\lou@e-2dj6aekouodpwfo.stats.esomniture[1].txt
C:\Users\lou\AppData\Roaming\Microsoft\Windows\Cookies\Low\lou@tracking.dc-storm[4].txt
C:\Users\lou\AppData\Roaming\Microsoft\Windows\Cookies\Low\lou@tracking.hearthstoneonline[3].txt
C:\Users\lou\AppData\Roaming\Microsoft\Windows\Cookies\Low\lou@track.webgains[2].txt
C:\Users\lou\AppData\Roaming\Microsoft\Windows\Cookies\Low\lou@liveperson[4].txt
C:\Users\lou\AppData\Roaming\Microsoft\Windows\Cookies\Low\lou@liveperson[2].txt
C:\Users\lou\AppData\Roaming\Microsoft\Windows\Cookies\Low\lou@tradedoubler[1].txt
C:\Users\lou\AppData\Roaming\Microsoft\Windows\Cookies\Low\lou@tracking.dc-storm[3].txt
C:\Users\lou\AppData\Roaming\Microsoft\Windows\Cookies\Low\lou@legolas-media[1].txt
C:\Users\lou\AppData\Roaming\Microsoft\Windows\Cookies\Low\lou@harrenmedianetwork[1].txt
C:\Users\lou\AppData\Roaming\Microsoft\Windows\Cookies\Low\lou@fastclick[3].txt
C:\Users\lou\AppData\Roaming\Microsoft\Windows\Cookies\Low\lou@ads.crakmedia[2].txt
C:\Users\lou\AppData\Roaming\Microsoft\Windows\Cookies\Low\lou@mycounter.tinycounter[1].txt
C:\Users\lou\AppData\Roaming\Microsoft\Windows\Cookies\Low\lou@serving-sys[7].txt
C:\Users\lou\AppData\Roaming\Microsoft\Windows\Cookies\Low\lou@media.sensis.com[1].txt
C:\Users\lou\AppData\Roaming\Microsoft\Windows\Cookies\Low\lou@trafficmp[2].txt
C:\Users\lou\AppData\Roaming\Microsoft\Windows\Cookies\Low\lou@e-2dj6wakoaidpwhp.stats.esomniture[2].txt
C:\Users\lou\AppData\Roaming\Microsoft\Windows\Cookies\Low\lou@www.googleadservices[10].txt
C:\Users\lou\AppData\Roaming\Microsoft\Windows\Cookies\Low\lou@fastclick[2].txt
C:\Users\lou\AppData\Roaming\Microsoft\Windows\Cookies\Low\lou@legolas-media[2].txt
C:\Users\lou\AppData\Roaming\Microsoft\Windows\Cookies\Low\lou@adserver.adtechus[2].txt
C:\Users\lou\AppData\Roaming\Microsoft\Windows\Cookies\Low\lou@server.lon.liveperson[2].txt
C:\Users\lou\AppData\Roaming\Microsoft\Windows\Cookies\Low\lou@tradedoubler[2].txt
C:\Users\lou\AppData\Roaming\Microsoft\Windows\Cookies\Low\lou@essex.bookaisle[2].txt
C:\Users\lou\AppData\Roaming\Microsoft\Windows\Cookies\Low\lou@linksynergy[1].txt
C:\Users\lou\AppData\Roaming\Microsoft\Windows\Cookies\Low\lou@revsci[5].txt
C:\Users\lou\AppData\Roaming\Microsoft\Windows\Cookies\Low\lou@citi.bridgetrack[2].txt
C:\Users\lou\AppData\Roaming\Microsoft\Windows\Cookies\Low\lou@www.illicitencounters[2].txt
C:\Users\lou\AppData\Roaming\Microsoft\Windows\Cookies\Low\lou@mediaplex[3].txt
C:\Users\lou\AppData\Roaming\Microsoft\Windows\Cookies\Low\lou@www.sexforums[3].txt
C:\Users\lou\AppData\Roaming\Microsoft\Windows\Cookies\Low\lou@westsussex.gov[4].txt
C:\Users\lou\AppData\Roaming\Microsoft\Windows\Cookies\Low\lou@statse.webtrendslive[10].txt
C:\Users\lou\AppData\Roaming\Microsoft\Windows\Cookies\Low\lou@adserver1.mokono[1].txt
C:\Users\lou\AppData\Roaming\Microsoft\Windows\Cookies\Low\lou@statcounter[1].txt
C:\Users\lou\AppData\Roaming\Microsoft\Windows\Cookies\Low\lou@revsci[7].txt
C:\Users\lou\AppData\Roaming\Microsoft\Windows\Cookies\Low\lou@amazonms.122.2o7[3].txt
C:\Users\lou\AppData\Roaming\Microsoft\Windows\Cookies\Low\lou@adserver.weddingideasmag[1].txt
C:\Users\lou\AppData\Roaming\Microsoft\Windows\Cookies\Low\lou@questionmarket[4].txt
C:\Users\lou\AppData\Roaming\Microsoft\Windows\Cookies\Low\lou@serving-sys[1].txt
C:\Users\lou\AppData\Roaming\Microsoft\Windows\Cookies\Low\lou@e-2dj6aekosmcpobp.stats.esomniture[2].txt
C:\Users\lou\AppData\Roaming\Microsoft\Windows\Cookies\Low\lou@tribalfusion[5].txt
C:\Users\lou\AppData\Roaming\Microsoft\Windows\Cookies\Low\lou@eas.apm.emediate[3].txt
C:\Users\lou\AppData\Roaming\Microsoft\Windows\Cookies\Low\lou@e-2dj6wbkicpcjelo.stats.esomniture[2].txt
C:\Users\lou\AppData\Roaming\Microsoft\Windows\Cookies\Low\lou@ads.gmodules[1].txt
C:\Users\lou\AppData\Roaming\Microsoft\Windows\Cookies\Low\lou@doubleclick[2].txt
C:\Users\lou\AppData\Roaming\Microsoft\Windows\Cookies\Low\lou@ad.yieldmanager[6].txt
C:\Users\lou\AppData\Roaming\Microsoft\Windows\Cookies\Low\lou@media6degrees[7].txt
C:\Users\lou\AppData\Roaming\Microsoft\Windows\Cookies\Low\lou@invitemedia[1].txt
C:\Users\lou\AppData\Roaming\Microsoft\Windows\Cookies\Low\lou@videoegg.adbureau[3].txt
C:\Users\lou\AppData\Roaming\Microsoft\Windows\Cookies\Low\lou@specificclick[1].txt
C:\Users\lou\AppData\Roaming\Microsoft\Windows\Cookies\Low\lou@rotator.adjuggler[2].txt
C:\Users\lou\AppData\Roaming\Microsoft\Windows\Cookies\Low\lou@fastclick[5].txt
C:\Users\lou\AppData\Roaming\Microsoft\Windows\Cookies\Low\lou@microsoftmachinetranslation.112.2o7[2].txt
C:\Users\lou\AppData\Roaming\Microsoft\Windows\Cookies\Low\lou@adserver1.mokono[6].txt
C:\Users\lou\AppData\Roaming\Microsoft\Windows\Cookies\Low\lou@ads.basrv[1].txt
C:\Users\lou\AppData\Roaming\Microsoft\Windows\Cookies\Low\lou@ad1.emediate[2].txt
C:\Users\lou\AppData\Roaming\Microsoft\Windows\Cookies\Low\lou@e-2dj6wakowkd5eeo.stats.esomniture[1].txt
C:\Users\lou\AppData\Roaming\Microsoft\Windows\Cookies\Low\lou@statse.webtrendslive[7].txt
C:\Users\lou\AppData\Roaming\Microsoft\Windows\Cookies\Low\lou@content.yieldmanager[2].txt
C:\Users\lou\AppData\Roaming\Microsoft\Windows\Cookies\Low\lou@atdmt[3].txt
C:\Users\lou\AppData\Roaming\Microsoft\Windows\Cookies\Low\lou@eaeacom.112.2o7[2].txt
C:\Users\lou\AppData\Roaming\Microsoft\Windows\Cookies\Low\lou@im.banner.t-online[1].txt
C:\Users\lou\AppData\Roaming\Microsoft\Windows\Cookies\Low\lou@themis-media[1].txt
C:\Users\lou\AppData\Roaming\Microsoft\Windows\Cookies\Low\lou@e-2dj6aekikoczsao.stats.esomniture[2].txt
C:\Users\lou\AppData\Roaming\Microsoft\Windows\Cookies\Low\lou@ads.raasnet[1].txt
C:\Users\lou\AppData\Roaming\Microsoft\Windows\Cookies\Low\lou@track.adform[1].txt
C:\Users\lou\AppData\Roaming\Microsoft\Windows\Cookies\Low\lou@sussexpub.co[2].txt
C:\Users\lou\AppData\Roaming\Microsoft\Windows\Cookies\Low\lou@clickaider[2].txt
C:\Users\lou\AppData\Roaming\Microsoft\Windows\Cookies\Low\lou@bluestreak[1].txt
C:\Users\lou\AppData\Roaming\Microsoft\Windows\Cookies\Low\lou@www.yourspacewestsussex.co[1].txt
C:\Users\lou\AppData\Roaming\Microsoft\Windows\Cookies\Low\lou@apmebf[8].txt
C:\Users\lou\AppData\Roaming\Microsoft\Windows\Cookies\Low\lou@roadtrafficaccidents.co[1].txt
C:\Users\lou\AppData\Roaming\Microsoft\Windows\Cookies\Low\lou@apmebf[10].txt
C:\Users\lou\AppData\Roaming\Microsoft\Windows\Cookies\Low\lou@track.cpanuk[2].txt
C:\Users\lou\AppData\Roaming\Microsoft\Windows\Cookies\Low\lou@e-2dj6wjl4agczacp.stats.esomniture[2].txt
C:\Users\lou\AppData\Roaming\Microsoft\Windows\Cookies\Low\lou@revsci[9].txt
C:\Users\lou\AppData\Roaming\Microsoft\Windows\Cookies\Low\lou@ad.youporn.videobox[1].txt
C:\Users\lou\AppData\Roaming\Microsoft\Windows\Cookies\Low\lou@adserver.eco.co[1].txt
C:\Users\lou\AppData\Roaming\Microsoft\Windows\Cookies\Low\lou@ehg-totalsystemsservices.hitbox[2].txt
C:\Users\lou\AppData\Roaming\Microsoft\Windows\Cookies\Low\lou@www.googleadservices[9].txt
C:\Users\lou\AppData\Roaming\Microsoft\Windows\Cookies\Low\lou@ad.publicisdigital[2].txt
C:\Users\lou\AppData\Roaming\Microsoft\Windows\Cookies\Low\lou@invitemedia[2].txt
C:\Users\lou\AppData\Roaming\Microsoft\Windows\Cookies\Low\lou@mywebsearch[4].txt
C:\Users\lou\AppData\Roaming\Microsoft\Windows\Cookies\Low\lou@advertise[2].txt
C:\Users\lou\AppData\Roaming\Microsoft\Windows\Cookies\Low\lou@ad.yieldmanager[2].txt
C:\Users\lou\AppData\Roaming\Microsoft\Windows\Cookies\Low\lou@pointroll[3].txt
C:\Users\lou\AppData\Roaming\Microsoft\Windows\Cookies\Low\lou@e-2dj6wdlyuhdzgbo.stats.esomniture[2].txt
C:\Users\lou\AppData\Roaming\Microsoft\Windows\Cookies\Low\lou@adserver.craftbits[2].txt
C:\Users\lou\AppData\Roaming\Microsoft\Windows\Cookies\Low\lou@www8.addfreestats[1].txt
C:\Users\lou\AppData\Roaming\Microsoft\Windows\Cookies\Low\lou@pro-market[3].txt
C:\Users\lou\AppData\Roaming\Microsoft\Windows\Cookies\Low\lou@in.getclicky[2].txt
C:\Users\lou\AppData\Roaming\Microsoft\Windows\Cookies\Low\lou@apmebf[5].txt
C:\Users\lou\AppData\Roaming\Microsoft\Windows\Cookies\Low\lou@mediabrandsww[1].txt
C:\Users\lou\AppData\Roaming\Microsoft\Windows\Cookies\Low\lou@sussexlocaljobs.co[2].txt
C:\Users\lou\AppData\Roaming\Microsoft\Windows\Cookies\Low\lou@discountvouchers.co[2].txt
C:\Users\lou\AppData\Roaming\Microsoft\Windows\Cookies\Low\lou@adtech[1].txt
C:\Users\lou\AppData\Roaming\Microsoft\Windows\Cookies\Low\lou@ad.yieldmanager[8].txt
C:\Users\lou\AppData\Roaming\Microsoft\Windows\Cookies\Low\lou@media6degrees[5].txt
C:\Users\lou\AppData\Roaming\Microsoft\Windows\Cookies\Low\lou@debenhams.122.2o7[1].txt
C:\Users\lou\AppData\Roaming\Microsoft\Windows\Cookies\Low\lou@banners.addictiveinteractive[1].txt
C:\Users\lou\AppData\Roaming\Microsoft\Windows\Cookies\Low\lou@revsci[3].txt
C:\Users\lou\AppData\Roaming\Microsoft\Windows\Cookies\Low\lou@www.googleadservices[1].txt
C:\Users\lou\AppData\Roaming\Microsoft\Windows\Cookies\Low\lou@ads.timeout[2].txt
C:\Users\lou\AppData\Roaming\Microsoft\Windows\Cookies\Low\lou@www.webhostingcounter[1].txt
C:\Users\lou\AppData\Roaming\Microsoft\Windows\Cookies\Low\lou@doompalm.westsussex.gov[2].txt
C:\Users\lou\AppData\Roaming\Microsoft\Windows\Cookies\Low\lou@realmedia[1].txt
C:\Users\lou\AppData\Roaming\Microsoft\Windows\Cookies\Low\lou@ads.ctasnet[2].txt
C:\Users\lou\AppData\Roaming\Microsoft\Windows\Cookies\Low\lou@stat.onestat[2].txt
C:\Users\lou\AppData\Roaming\Microsoft\Windows\Cookies\Low\lou@youporn[2].txt
C:\Users\lou\AppData\Roaming\Microsoft\Windows\Cookies\Low\lou@stat.dealtime[2].txt
C:\Users\lou\AppData\Roaming\Microsoft\Windows\Cookies\Low\lou@questionmarket[3].txt
C:\Users\lou\AppData\Roaming\Microsoft\Windows\Cookies\Low\lou@ads.youporn[3].txt
C:\Users\lou\AppData\Roaming\Microsoft\Windows\Cookies\Low\lou@stats.adimpact[1].txt
C:\Users\lou\AppData\Roaming\Microsoft\Windows\Cookies\Low\lou@interclick[3].txt
C:\Users\lou\AppData\Roaming\Microsoft\Windows\Cookies\Low\lou@ehg-tfl.hitbox[3].txt
C:\Users\lou\AppData\Roaming\Microsoft\Windows\Cookies\Low\lou@revsci[2].txt
C:\Users\lou\AppData\Roaming\Microsoft\Windows\Cookies\Low\lou@server.cpmstar[2].txt
C:\Users\lou\AppData\Roaming\Microsoft\Windows\Cookies\Low\lou@media.medhelp[1].txt
C:\Users\lou\AppData\Roaming\Microsoft\Windows\Cookies\Low\lou@track.adform[3].txt
C:\Users\lou\AppData\Roaming\Microsoft\Windows\Cookies\Low\lou@adxpose[2].txt
C:\Users\lou\AppData\Roaming\Microsoft\Windows\Cookies\Low\lou@e-2dj6aekywod5afo.stats.esomniture[2].txt
C:\Users\lou\AppData\Roaming\Microsoft\Windows\Cookies\Low\lou@ru4[3].txt
C:\Users\lou\AppData\Roaming\Microsoft\Windows\Cookies\Low\lou@liveperson[7].txt
C:\Users\lou\AppData\Roaming\Microsoft\Windows\Cookies\Low\lou@imrworldwide[4].txt
C:\Users\lou\AppData\Roaming\Microsoft\Windows\Cookies\Low\lou@advertising[1].txt
C:\Users\lou\AppData\Roaming\Microsoft\Windows\Cookies\Low\lou@ad.wsod[2].txt
C:\Users\lou\AppData\Roaming\Microsoft\Windows\Cookies\Low\lou@apmebf[6].txt
C:\Users\lou\AppData\Roaming\Microsoft\Windows\Cookies\Low\lou@e-2dj6wmkoopc5ihp.stats.esomniture[2].txt
C:\Users\lou\AppData\Roaming\Microsoft\Windows\Cookies\Low\lou@adviva[4].txt
C:\Users\lou\AppData\Roaming\Microsoft\Windows\Cookies\Low\lou@tacoda.at.atwola[2].txt
C:\Users\lou\AppData\Roaming\Microsoft\Windows\Cookies\Low\lou@adinterax[2].txt
C:\Users\lou\AppData\Roaming\Microsoft\Windows\Cookies\Low\lou@pointroll[2].txt
C:\Users\lou\AppData\Roaming\Microsoft\Windows\Cookies\Low\lou@e-2dj6wnkocmcpeeo.stats.esomniture[1].txt
C:\Users\lou\AppData\Roaming\Microsoft\Windows\Cookies\Low\lou@e-2dj6wjkyenazgao.stats.esomniture[2].txt
C:\Users\lou\AppData\Roaming\Microsoft\Windows\Cookies\Low\lou@serving-sys[4].txt
C:\Users\lou\AppData\Roaming\Microsoft\Windows\Cookies\Low\lou@adecn[2].txt
C:\Users\lou\AppData\Roaming\Microsoft\Windows\Cookies\Low\lou@bevscountrycottage[2].txt
C:\Users\lou\AppData\Roaming\Microsoft\Windows\Cookies\Low\lou@handpickedmedia.co[3].txt
C:\Users\lou\AppData\Roaming\Microsoft\Windows\Cookies\Low\lou@adserver1.mokono[4].txt
C:\Users\lou\AppData\Roaming\Microsoft\Windows\Cookies\Low\lou@clickfuse[2].txt
C:\Users\lou\AppData\Roaming\Microsoft\Windows\Cookies\Low\lou@internettrafficbuilder[2].txt
C:\Users\lou\AppData\Roaming\Microsoft\Windows\Cookies\Low\lou@stat.dealtime[3].txt
C:\Users\lou\AppData\Roaming\Microsoft\Windows\Cookies\Low\lou@youporn[1].txt
C:\Users\lou\AppData\Roaming\Microsoft\Windows\Cookies\Low\lou@www.discountvouchers.co[3].txt
C:\Users\lou\AppData\Roaming\Microsoft\Windows\Cookies\Low\lou@himedia.individuad[3].txt
C:\Users\lou\AppData\Roaming\Microsoft\Windows\Cookies\Low\lou@realmedia[2].txt
C:\Users\lou\AppData\Roaming\Microsoft\Windows\Cookies\Low\lou@atdmt[5].txt
C:\Users\lou\AppData\Roaming\Microsoft\Windows\Cookies\Low\lou@westsussex.nhs[2].txt
C:\Users\lou\AppData\Roaming\Microsoft\Windows\Cookies\Low\lou@ehg-debenhams.hitbox[3].txt
C:\Users\lou\AppData\Roaming\Microsoft\Windows\Cookies\Low\lou@sexysims2[2].txt
C:\Users\lou\AppData\Roaming\Microsoft\Windows\Cookies\Low\lou@adtech[3].txt
C:\Users\lou\AppData\Roaming\Microsoft\Windows\Cookies\Low\lou@westsussex.gov[1].txt
C:\Users\lou\AppData\Roaming\Microsoft\Windows\Cookies\Low\lou@adserver1.backbeatmedia[1].txt
C:\Users\lou\AppData\Roaming\Microsoft\Windows\Cookies\Low\lou@e-2dj6whmygpdjkgp.stats.esomniture[2].txt
C:\Users\lou\AppData\Roaming\Microsoft\Windows\Cookies\Low\lou@ads.sexforums[2].txt
C:\Users\lou\AppData\Roaming\Microsoft\Windows\Cookies\Low\lou@men.122.2o7[2].txt
C:\Users\lou\AppData\Roaming\Microsoft\Windows\Cookies\Low\lou@www.sussex.police[1].txt
C:\Users\lou\AppData\Roaming\Microsoft\Windows\Cookies\Low\lou@content.yieldmanager[3].txt
C:\Users\lou\AppData\Roaming\Microsoft\Windows\Cookies\Low\lou@www.westsussex.gov[1].txt
C:\Users\lou\AppData\Roaming\Microsoft\Windows\Cookies\Low\lou@weddingfairssussex.co[2].txt
C:\Users\lou\AppData\Roaming\Microsoft\Windows\Cookies\Low\lou@statse.webtrendslive[6].txt
C:\Users\lou\AppData\Roaming\Microsoft\Windows\Cookies\Low\lou@specificclick[2].txt
C:\Users\lou\AppData\Roaming\Microsoft\Windows\Cookies\Low\lou@adviva[1].txt
C:\Users\lou\AppData\Roaming\Microsoft\Windows\Cookies\Low\lou@easyadverts.co[1].txt
C:\Users\lou\AppData\Roaming\Microsoft\Windows\Cookies\Low\lou@interclick[1].txt
C:\Users\lou\AppData\Roaming\Microsoft\Windows\Cookies\Low\lou@server.lon.liveperson[1].txt
C:\Users\lou\AppData\Roaming\Microsoft\Windows\Cookies\Low\lou@www.googleadservices[7].txt
C:\Users\lou\AppData\Roaming\Microsoft\Windows\Cookies\Low\lou@midsussex.gov[1].txt
C:\Users\lou\AppData\Roaming\Microsoft\Windows\Cookies\Low\lou@ero-advertising[1].txt
C:\Users\lou\AppData\Roaming\Microsoft\Windows\Cookies\Low\lou@invitemedia[4].txt
C:\Users\lou\AppData\Roaming\Microsoft\Windows\Cookies\Low\lou@kontera[3].txt
C:\Users\lou\AppData\Roaming\Microsoft\Windows\Cookies\Low\lou@tacoda[4].txt
C:\Users\lou\AppData\Roaming\Microsoft\Windows\Cookies\Low\lou@adbrite[5].txt
C:\Users\lou\AppData\Roaming\Microsoft\Windows\Cookies\Low\lou@invitemedia[9].txt
C:\Users\lou\AppData\Roaming\Microsoft\Windows\Cookies\Low\lou@clicksor[1].txt
C:\Users\lou\AppData\Roaming\Microsoft\Windows\Cookies\Low\lou@server.lon.liveperson[6].txt
C:\Users\lou\AppData\Roaming\Microsoft\Windows\Cookies\Low\lou@e-2dj6wfkoglajsep.stats.esomniture[2].txt
C:\Users\lou\AppData\Roaming\Microsoft\Windows\Cookies\Low\lou@chat.smileycentral[1].txt
C:\Users\lou\AppData\Roaming\Microsoft\Windows\Cookies\Low\lou@serving-sys[2].txt
C:\Users\lou\AppData\Roaming\Microsoft\Windows\Cookies\Low\lou@content.yieldmanager[5].txt
C:\Users\lou\AppData\Roaming\Microsoft\Windows\Cookies\Low\lou@conrad.122.2o7[1].txt
C:\Users\lou\AppData\Roaming\Microsoft\Windows\Cookies\Low\lou@atdmt[6].txt
C:\Users\lou\AppData\Roaming\Microsoft\Windows\Cookies\Low\lou@tribalfusion[3].txt
C:\Users\lou\AppData\Roaming\Microsoft\Windows\Cookies\Low\lou@at.atwola[2].txt
C:\Users\lou\AppData\Roaming\Microsoft\Windows\Cookies\Low\lou@weborama[1].txt
C:\Users\lou\AppData\Roaming\Microsoft\Windows\Cookies\Low\lou@amazonms.122.2o7[2].txt
C:\Users\lou\AppData\Roaming\Microsoft\Windows\Cookies\Low\lou@ads1.mumsnet[1].txt
C:\Users\lou\AppData\Roaming\Microsoft\Windows\Cookies\Low\lou@statse.webtrendslive[3].txt
C:\Users\lou\AppData\Roaming\Microsoft\Windows\Cookies\Low\lou@media6degrees[8].txt
C:\Users\lou\AppData\Roaming\Microsoft\Windows\Cookies\Low\lou@mediaplex[4].txt
C:\Users\lou\AppData\Roaming\Microsoft\Windows\Cookies\Low\lou@atdmt[7].txt
C:\Users\lou\AppData\Roaming\Microsoft\Windows\Cookies\Low\lou@answerstv.112.2o7[3].txt
C:\Users\lou\AppData\Roaming\Microsoft\Windows\Cookies\Low\lou@trinitymirror.112.2o7[2].txt
C:\Users\lou\AppData\Roaming\Microsoft\Windows\Cookies\Low\lou@sexforums[3].txt
C:\Users\lou\AppData\Roaming\Microsoft\Windows\Cookies\Low\lou@apmebf[2].txt
C:\Users\lou\AppData\Roaming\Microsoft\Windows\Cookies\Low\lou@server.iad.liveperson[1].txt
C:\Users\lou\AppData\Roaming\Microsoft\Windows\Cookies\Low\lou@tacoda.at.atwola[3].txt
C:\Users\lou\AppData\Roaming\Microsoft\Windows\Cookies\Low\lou@www.find-me-a-gift.co[3].txt
C:\Users\lou\AppData\Roaming\Microsoft\Windows\Cookies\Low\lou@mywebsearch[1].txt
C:\Users\lou\AppData\Roaming\Microsoft\Windows\Cookies\Low\lou@liveperson[9].txt
C:\Users\lou\AppData\Roaming\Microsoft\Windows\Cookies\Low\lou@billy4sex.blog.co[1].txt
C:\Users\lou\AppData\Roaming\Microsoft\Windows\Cookies\Low\lou@visitsussex[1].txt
C:\Users\lou\AppData\Roaming\Microsoft\Windows\Cookies\Low\lou@specificclick[4].txt
C:\Users\lou\AppData\Roaming\Microsoft\Windows\Cookies\Low\lou@amazonms.122.2o7[1].txt
C:\Users\lou\AppData\Roaming\Microsoft\Windows\Cookies\Low\lou@eas.apm.emediate[4].txt
C:\Users\lou\AppData\Roaming\Microsoft\Windows\Cookies\Low\lou@adviva[6].txt
C:\Users\lou\AppData\Roaming\Microsoft\Windows\Cookies\Low\lou@ehg-futurepub.hitbox[1].txt
C:\Users\lou\AppData\Roaming\Microsoft\Windows\Cookies\Low\lou@serving-sys[6].txt
C:\Users\lou\AppData\Roaming\Microsoft\Windows\Cookies\Low\lou@uk.at.atwola[1].txt
C:\Users\lou\AppData\Roaming\Microsoft\Windows\Cookies\Low\lou@yadro[3].txt
C:\Users\lou\AppData\Roaming\Microsoft\Windows\Cookies\Low\lou@womanandhome.ipcmediasecure[2].txt
C:\Users\lou\AppData\Roaming\Microsoft\Windows\Cookies\Low\lou@track.affilibid[1].txt
C:\Users\lou\AppData\Roaming\Microsoft\Windows\Cookies\Low\lou@ehg-fastweb.hitbox[2].txt
C:\Users\lou\AppData\Roaming\Microsoft\Windows\Cookies\Low\lou@www.googleadservices[5].txt
C:\Users\lou\AppData\Roaming\Microsoft\Windows\Cookies\Low\lou@server.lon.liveperson[3].txt
MORE TO FOLLOW0 -
C:\Users\lou\AppData\Roaming\Microsoft\Windows\Cookies\Low\lou@hitbox[2].txt
C:\Users\lou\AppData\Roaming\Microsoft\Windows\Cookies\Low\lou@youporn.videobox[1].txt
C:\Users\lou\AppData\Roaming\Microsoft\Windows\Cookies\Low\lou@jobs.westsussex.gov[2].txt
C:\Users\lou\AppData\Roaming\Microsoft\Windows\Cookies\Low\lou@e-2dj6wfkishd5sco.stats.esomniture[1].txt
C:\Users\lou\AppData\Roaming\Microsoft\Windows\Cookies\Low\lou@ads.pubmatic[2].txt
C:\Users\lou\AppData\Roaming\Microsoft\Windows\Cookies\Low\lou@www.babynamescountry[1].txt
C:\Users\lou\AppData\Roaming\Microsoft\Windows\Cookies\Low\lou@invitemedia[7].txt
C:\Users\lou\AppData\Roaming\Microsoft\Windows\Cookies\Low\lou@media6degrees[1].txt
C:\Users\lou\AppData\Roaming\Microsoft\Windows\Cookies\Low\lou@adtech[5].txt
C:\Users\lou\AppData\Roaming\Microsoft\Windows\Cookies\Low\lou@www.googleadservices[4].txt
C:\Users\lou\AppData\Roaming\Microsoft\Windows\Cookies\Low\lou@server.lon.liveperson[4].txt
C:\Users\lou\AppData\Roaming\Microsoft\Windows\Cookies\Low\lou@tacoda[6].txt
C:\Users\lou\AppData\Roaming\Microsoft\Windows\Cookies\Low\lou@uk.at.atwola[2].txt
C:\Users\lou\AppData\Roaming\Microsoft\Windows\Cookies\Low\lou@hitbox[3].txt
C:\Users\lou\AppData\Roaming\Microsoft\Windows\Cookies\Low\lou@essex.bookaisle[1].txt
C:\Users\lou\AppData\Roaming\Microsoft\Windows\Cookies\Low\lou@stats.matraxis[1].txt
C:\Users\lou\AppData\Roaming\Microsoft\Windows\Cookies\Low\lou@ads.cheapflights[1].txt
C:\Users\lou\AppData\Roaming\Microsoft\Windows\Cookies\Low\lou@fastclick[1].txt
C:\Users\lou\AppData\Roaming\Microsoft\Windows\Cookies\Low\lou@universalmusic.w00tmedia[2].txt
C:\Users\lou\AppData\Roaming\Microsoft\Windows\Cookies\Low\lou@www.ist-track[1].txt
C:\Users\lou\AppData\Roaming\Microsoft\Windows\Cookies\Low\lou@atdmt[9].txt
C:\Users\lou\AppData\Roaming\Microsoft\Windows\Cookies\Low\lou@apmebf[3].txt
C:\Users\lou\AppData\Roaming\Microsoft\Windows\Cookies\Low\lou@fidelity.rotator.hadj7.adjuggler[1].txt
C:\Users\lou\AppData\Roaming\Microsoft\Windows\Cookies\Low\lou@find-me-a-gift.co[2].txt
C:\Users\lou\AppData\Roaming\Microsoft\Windows\Cookies\Low\lou@apmebf[4].txt
C:\Users\lou\AppData\Roaming\Microsoft\Windows\Cookies\Low\lou@sexforums[2].txt
C:\Users\lou\AppData\Roaming\Microsoft\Windows\Cookies\Low\lou@trinitymirror.112.2o7[1].txt
C:\Users\lou\AppData\Roaming\Microsoft\Windows\Cookies\Low\lou@atdmt[8].txt
C:\Users\lou\AppData\Roaming\Microsoft\Windows\Cookies\Low\lou@ad.yieldmanager[4].txt
C:\Users\lou\AppData\Roaming\Microsoft\Windows\Cookies\Low\lou@statse.webtrendslive[2].txt
C:\Users\lou\AppData\Roaming\Microsoft\Windows\Cookies\Low\lou@bs.serving-sys[5].txt
C:\Users\lou\AppData\Roaming\Microsoft\Windows\Cookies\Low\lou@specificclick[6].txt
C:\Users\lou\AppData\Roaming\Microsoft\Windows\Cookies\Low\lou@collective-media[3].txt
C:\Users\lou\AppData\Roaming\Microsoft\Windows\Cookies\Low\lou@ads1.mumsnet[2].txt
C:\Users\lou\AppData\Roaming\Microsoft\Windows\Cookies\Low\lou@at.atwola[3].txt
C:\Users\lou\AppData\Roaming\Microsoft\Windows\Cookies\Low\lou@atdmt[10].txt
C:\Users\lou\AppData\Roaming\Microsoft\Windows\Cookies\Low\lou@surveymonkey.122.2o7[1].txt
C:\Users\lou\AppData\Roaming\Microsoft\Windows\Cookies\Low\lou@tribalfusion[4].txt
C:\Users\lou\AppData\Roaming\Microsoft\Windows\Cookies\Low\lou@ads.fling[1].txt
C:\Users\lou\AppData\Roaming\Microsoft\Windows\Cookies\Low\lou@galleries.tryteens[1].txt
C:\Users\lou\AppData\Roaming\Microsoft\Windows\Cookies\Low\lou@dealtime[2].txt
C:\Users\lou\AppData\Roaming\Microsoft\Windows\Cookies\Low\lou@content.yieldmanager[7].txt
C:\Users\lou\AppData\Roaming\Microsoft\Windows\Cookies\Low\lou@countrylife.co[2].txt
C:\Users\lou\AppData\Roaming\Microsoft\Windows\Cookies\Low\lou@at.atwola[4].txt
C:\Users\lou\AppData\Roaming\Microsoft\Windows\Cookies\Low\lou@yourspacewestsussex.co[2].txt
C:\Users\lou\AppData\Roaming\Microsoft\Windows\Cookies\Low\lou@specificclick[5].txt
C:\Users\lou\AppData\Roaming\Microsoft\Windows\Cookies\Low\lou@www.find-me-a-gift.co[2].txt
C:\Users\lou\AppData\Roaming\Microsoft\Windows\Cookies\Low\lou@statse.webtrendslive[1].txt
C:\Users\lou\AppData\Roaming\Microsoft\Windows\Cookies\Low\lou@advertising[5].txt
C:\Users\lou\AppData\Roaming\Microsoft\Windows\Cookies\Low\lou@www.googleadservices[6].txt
C:\Users\lou\AppData\Roaming\Microsoft\Windows\Cookies\Low\lou@traveladvertising[1].txt
C:\Users\lou\AppData\Roaming\Microsoft\Windows\Cookies\Low\lou@newlook.112.2o7[1].txt
C:\Users\lou\AppData\Roaming\Microsoft\Windows\Cookies\Low\lou@www.westsussex.gov[2].txt
C:\Users\lou\AppData\Roaming\Microsoft\Windows\Cookies\Low\lou@e-2dj6aekyqmcpwcp.stats.esomniture[1].txt
C:\Users\lou\AppData\Roaming\Microsoft\Windows\Cookies\Low\lou@stats.matraxis[2].txt
C:\Users\lou\AppData\Roaming\Microsoft\Windows\Cookies\Low\lou@ramadajarvis.112.2o7[1].txt
C:\Users\lou\AppData\Roaming\Microsoft\Windows\Cookies\Low\lou@adbrite[2].txt
C:\Users\lou\AppData\Roaming\Microsoft\Windows\Cookies\Low\lou@mediaforge[2].txt
C:\Users\lou\AppData\Roaming\Microsoft\Windows\Cookies\Low\lou@weddingmagazine.ipcmediasecure[1].txt
C:\Users\lou\AppData\Roaming\Microsoft\Windows\Cookies\Low\lou@mediaplex[7].txt
C:\Users\lou\AppData\Roaming\Microsoft\Windows\Cookies\Low\lou@sexysims2[1].txt
C:\Users\lou\AppData\Roaming\Microsoft\Windows\Cookies\Low\lou@uk.at.atwola[3].txt
C:\Users\lou\AppData\Roaming\Microsoft\Windows\Cookies\Low\lou@tacoda[7].txt
C:\Users\lou\AppData\Roaming\Microsoft\Windows\Cookies\Low\lou@adfarm1.adition[1].txt
C:\Users\lou\AppData\Roaming\Microsoft\Windows\Cookies\Low\lou@myroitracking[1].txt
C:\Users\lou\AppData\Roaming\Microsoft\Windows\Cookies\Low\lou@ehg-debenhams.hitbox[4].txt
C:\Users\lou\AppData\Roaming\Microsoft\Windows\Cookies\Low\lou@doubleclick[7].txt
C:\Users\lou\AppData\Roaming\Microsoft\Windows\Cookies\Low\lou@gogamer.advertserve[1].txt
C:\Users\lou\AppData\Roaming\Microsoft\Windows\Cookies\Low\lou@www.googleadservices[3].txt
C:\Users\lou\AppData\Roaming\Microsoft\Windows\Cookies\Low\lou@ads.pubmatic[1].txt
C:\Users\lou\AppData\Roaming\Microsoft\Windows\Cookies\Low\lou@adbrite[4].txt
C:\Users\lou\AppData\Roaming\Microsoft\Windows\Cookies\Low\lou@www.burstnet[1].txt
C:\Users\lou\AppData\Roaming\Microsoft\Windows\Cookies\Low\lou@tacoda[5].txt
C:\Users\lou\AppData\Roaming\Microsoft\Windows\Cookies\Low\lou@paypal.112.2o7[1].txt
C:\Users\lou\AppData\Roaming\Microsoft\Windows\Cookies\Low\lou@e-2dj6wdlywhajago.stats.esomniture[2].txt
C:\Users\lou\AppData\Roaming\Microsoft\Windows\Cookies\Low\lou@sussexbrides.co[1].txt
C:\Users\lou\AppData\Roaming\Microsoft\Windows\Cookies\Low\lou@youporn.videobox[2].txt
C:\Users\lou\AppData\Roaming\Microsoft\Windows\Cookies\Low\lou@adserver.mediarun[1].txt
C:\Users\lou\AppData\Roaming\Microsoft\Windows\Cookies\Low\lou@adbrite[1].txt
C:\Users\lou\AppData\Roaming\Microsoft\Windows\Cookies\Low\lou@invitemedia[5].txt
C:\Users\lou\AppData\Roaming\Microsoft\Windows\Cookies\Low\lou@media6degrees[3].txt
C:\Users\lou\AppData\Roaming\Microsoft\Windows\Cookies\Low\lou@theperfumeshop.122.2o7[1].txt
C:\Users\lou\AppData\Roaming\Microsoft\Windows\Cookies\Low\lou@statcounter[3].txt
C:\Users\lou\AppData\Roaming\Microsoft\Windows\Cookies\Low\lou@tribalfusion[2].txt
C:\Users\lou\AppData\Roaming\Microsoft\Windows\Cookies\Low\lou@ads.babymed[2].txt
C:\Users\lou\AppData\Roaming\Microsoft\Windows\Cookies\Low\lou@content.yieldmanager[4].txt
C:\Users\lou\AppData\Roaming\Microsoft\Windows\Cookies\Low\lou@adecn[1].txt
C:\Users\lou\AppData\Roaming\Microsoft\Windows\Cookies\Low\lou@serving-sys[3].txt
C:\Users\lou\AppData\Roaming\Microsoft\Windows\Cookies\Low\lou@lovefilm.db.advertising[1].txt
C:\Users\lou\AppData\Roaming\Microsoft\Windows\Cookies\Low\lou@thesimsquestions[1].txt
C:\Users\lou\AppData\Roaming\Microsoft\Windows\Cookies\Low\lou@find-dvd.co[1].txt
C:\Users\lou\AppData\Roaming\Microsoft\Windows\Cookies\Low\lou@www.sexforums[1].txt
C:\Users\lou\AppData\Roaming\Microsoft\Windows\Cookies\Low\lou@weborama[3].txt
C:\Users\lou\AppData\Roaming\Microsoft\Windows\Cookies\Low\lou@specificclick[3].txt
C:\Users\lou\AppData\Roaming\Microsoft\Windows\Cookies\Low\lou@doubleclick[4].txt
C:\Users\lou\AppData\Roaming\Microsoft\Windows\Cookies\Low\lou@liveperson[8].txt
C:\Users\lou\AppData\Roaming\Microsoft\Windows\Cookies\Low\lou@chitika[2].txt
C:\Users\lou\AppData\Roaming\Microsoft\Windows\Cookies\Low\lou@www.ist-track[3].txt
C:\Users\lou\AppData\Roaming\Microsoft\Windows\Cookies\Low\lou@mywebsearch[2].txt
C:\Users\lou\AppData\Roaming\Microsoft\Windows\Cookies\Low\lou@media.medhelp[2].txt
C:\Users\lou\AppData\Roaming\Microsoft\Windows\Cookies\Low\lou@handpickedmedia.co[1].txt
C:\Users\lou\AppData\Roaming\Microsoft\Windows\Cookies\Low\lou@apmebf[1].txt
C:\Users\lou\AppData\Roaming\Microsoft\Windows\Cookies\Low\lou@pro-market[1].txt
C:\Users\lou\AppData\Roaming\Microsoft\Windows\Cookies\Low\lou@surveymonkey.122.2o7[2].txt
C:\Users\lou\AppData\Roaming\Microsoft\Windows\Cookies\Low\lou@sonyeurope.112.2o7[2].txt
C:\Users\lou\AppData\Roaming\Microsoft\Windows\Cookies\Low\lou@answerstv.112.2o7[2].txt
C:\Users\lou\AppData\Roaming\Microsoft\Windows\Cookies\Low\lou@www.discountvouchers.co[2].txt
C:\Users\lou\AppData\Roaming\Microsoft\Windows\Cookies\Low\lou@ad.zanox[2].txt
C:\Users\lou\AppData\Roaming\Microsoft\Windows\Cookies\Low\lou@statse.webtrendslive[4].txt
C:\Users\lou\AppData\Roaming\Microsoft\Windows\Cookies\Low\lou@liveperson[11].txt
C:\Users\lou\AppData\Roaming\Microsoft\Windows\Cookies\Low\lou@www.findaproperty[1].txt
C:\Users\lou\AppData\Roaming\Microsoft\Windows\Cookies\Low\lou@bs.serving-sys[7].txt
C:\Users\lou\AppData\Roaming\Microsoft\Windows\Cookies\Low\lou@specificclick[8].txt
C:\Users\lou\AppData\Roaming\Microsoft\Windows\Cookies\Low\lou@adultwork[1].txt
C:\Users\lou\AppData\Roaming\Microsoft\Windows\Cookies\Low\lou@ads.sexforums[1].txt
C:\Users\lou\AppData\Roaming\Microsoft\Windows\Cookies\Low\lou@ads.us.e-planning[1].txt
C:\Users\lou\AppData\Roaming\Microsoft\Windows\Cookies\Low\lou@e-2dj6wfkyehcpelo.stats.esomniture[2].txt
C:\Users\lou\AppData\Roaming\Microsoft\Windows\Cookies\Low\lou@westsussex.gov[2].txt
C:\Users\lou\AppData\Roaming\Microsoft\Windows\Cookies\Low\lou@chitika[1].txt
C:\Users\lou\AppData\Roaming\Microsoft\Windows\Cookies\Low\lou@ehg-bskyb.hitbox[1].txt
C:\Users\lou\AppData\Roaming\Microsoft\Windows\Cookies\Low\lou@media6degrees[4].txt
C:\Users\lou\AppData\Roaming\Microsoft\Windows\Cookies\Low\lou@uk.at.atwola[5].txt
C:\Users\lou\AppData\Roaming\Microsoft\Windows\Cookies\Low\lou@westsussexweddingvenue.co[1].txt
C:\Users\lou\AppData\Roaming\Microsoft\Windows\Cookies\Low\lou@adtech[2].txt
C:\Users\lou\AppData\Roaming\Microsoft\Windows\Cookies\Low\lou@mediaplex[5].txt
C:\Users\lou\AppData\Roaming\Microsoft\Windows\Cookies\Low\lou@in.getclicky[1].txt
C:\Users\lou\AppData\Roaming\Microsoft\Windows\Cookies\Low\lou@doubleclick[5].txt
C:\Users\lou\AppData\Roaming\Microsoft\Windows\Cookies\Low\lou@sextoys.co[2].txt
C:\Users\lou\AppData\Roaming\Microsoft\Windows\Cookies\Low\lou@sexperienceuk.channel4[1].txt
C:\Users\lou\AppData\Roaming\Microsoft\Windows\Cookies\Low\lou@invitemedia[3].txt
C:\Users\lou\AppData\Roaming\Microsoft\Windows\Cookies\Low\lou@tacoda[3].txt
C:\Users\lou\AppData\Roaming\Microsoft\Windows\Cookies\Low\lou@ad.yieldmanager[1].txt
C:\Users\lou\AppData\Roaming\Microsoft\Windows\Cookies\Low\lou@mywebsearch[5].txt
C:\Users\lou\AppData\Roaming\Microsoft\Windows\Cookies\Low\lou@babynamescountry[1].txt
C:\Users\lou\AppData\Roaming\Microsoft\Windows\Cookies\Low\lou@questionmarket[1].txt
C:\Users\lou\AppData\Roaming\Microsoft\Windows\Cookies\Low\lou@www.googleadservices[8].txt
C:\Users\lou\AppData\Roaming\Microsoft\Windows\Cookies\Low\lou@eas.apm.emediate[5].txt
C:\Users\lou\AppData\Roaming\Microsoft\Windows\Cookies\Low\lou@tacoda[2].txt
C:\Users\lou\AppData\Roaming\Microsoft\Windows\Cookies\Low\lou@adviva[2].txt
C:\Users\lou\AppData\Roaming\Microsoft\Windows\Cookies\Low\lou@stats.matraxis[3].txt
C:\Users\lou\AppData\Roaming\Microsoft\Windows\Cookies\Low\lou@weddingfairssussex.co[1].txt
C:\Users\lou\AppData\Roaming\Microsoft\Windows\Cookies\Low\lou@questionmarket[2].txt
C:\Users\lou\AppData\Roaming\Microsoft\Windows\Cookies\Low\lou@hearstdigital.122.2o7[1].txt
C:\Users\lou\AppData\Roaming\Microsoft\Windows\Cookies\Low\lou@specificclick[10].txt
C:\Users\lou\AppData\Roaming\Microsoft\Windows\Cookies\Low\lou@advertising[2].txt
C:\Users\lou\AppData\Roaming\Microsoft\Windows\Cookies\Low\lou@tracking.dc-storm[1].txt
C:\Users\lou\AppData\Roaming\Microsoft\Windows\Cookies\Low\lou@www.adultwork[1].txt
C:\Users\lou\AppData\Roaming\Microsoft\Windows\Cookies\Low\lou@liveperson[6].txt
C:\Users\lou\AppData\Roaming\Microsoft\Windows\Cookies\Low\lou@adxpose[1].txt
C:\Users\lou\AppData\Roaming\Microsoft\Windows\Cookies\Low\lou@track.adform[2].txt
C:\Users\lou\AppData\Roaming\Microsoft\Windows\Cookies\Low\lou@e-2dj6wnmyshc5cbo.stats.esomniture[1].txt
C:\Users\lou\AppData\Roaming\Microsoft\Windows\Cookies\Low\lou@atdmt[4].txt
C:\Users\lou\AppData\Roaming\Microsoft\Windows\Cookies\Low\lou@media6degrees[10].txt
C:\Users\lou\AppData\Roaming\Microsoft\Windows\Cookies\Low\lou@ehg-dig.hitbox[2].txt
C:\Users\lou\AppData\Roaming\Microsoft\Windows\Cookies\Low\lou@ads.acevillepublications[2].txt
C:\Users\lou\AppData\Roaming\Microsoft\Windows\Cookies\Low\lou@adserver1.mokono[5].txt
C:\Users\lou\AppData\Roaming\Microsoft\Windows\Cookies\Low\lou@specificclick[11].txt
C:\Users\lou\AppData\Roaming\Microsoft\Windows\Cookies\Low\lou@goodtoknow.ipcmediasecure[3].txt
C:\Users\lou\AppData\Roaming\Microsoft\Windows\Cookies\Low\lou@serving-sys[5].txt
C:\Users\lou\AppData\Roaming\Microsoft\Windows\Cookies\Low\lou@tacoda.at.atwola[1].txt
C:\Users\lou\AppData\Roaming\Microsoft\Windows\Cookies\Low\lou@paypal.112.2o7[2].txt
C:\Users\lou\AppData\Roaming\Microsoft\Windows\Cookies\Low\lou@adviva[3].txt
C:\Users\lou\AppData\Roaming\Microsoft\Windows\Cookies\Low\lou@ads.bcserving[1].txt
C:\Users\lou\AppData\Roaming\Microsoft\Windows\Cookies\Low\lou@ads.traffikings[1].txt
C:\Users\lou\AppData\Roaming\Microsoft\Windows\Cookies\Low\lou@tacoda[1].txt
C:\Users\lou\AppData\Roaming\Microsoft\Windows\Cookies\Low\lou@apmebf[7].txt
C:\Users\lou\AppData\Roaming\Microsoft\Windows\Cookies\Low\lou@ads.undertone[2].txt
C:\Users\lou\AppData\Roaming\Microsoft\Windows\Cookies\Low\lou@ad.yieldmanager[3].txt
C:\Users\lou\AppData\Roaming\Microsoft\Windows\Cookies\Low\lou@mywebsearch[3].txt
C:\Users\lou\AppData\Roaming\Microsoft\Windows\Cookies\Low\lou@ad.youporn.videobox[2].txt
C:\Users\lou\AppData\Roaming\Microsoft\Windows\Cookies\Low\lou@ads.pointroll[3].txt
C:\Users\lou\AppData\Roaming\Microsoft\Windows\Cookies\Low\lou@adserver.eco.co[2].txt
C:\Users\lou\AppData\Roaming\Microsoft\Windows\Cookies\Low\lou@adserver1.mokono[2].txt
C:\Users\lou\AppData\Roaming\Microsoft\Windows\Cookies\Low\lou@server.cpmstar[1].txt
C:\Users\lou\AppData\Roaming\Microsoft\Windows\Cookies\Low\lou@ehg-tfl.hitbox[2].txt
C:\Users\lou\AppData\Roaming\Microsoft\Windows\Cookies\Low\lou@liveperson[10].txt
C:\Users\lou\AppData\Roaming\Microsoft\Windows\Cookies\Low\lou@ads.youporn[2].txt
C:\Users\lou\AppData\Roaming\Microsoft\Windows\Cookies\Low\lou@www6.addfreestats[1].txt
C:\Users\lou\AppData\Roaming\Microsoft\Windows\Cookies\Low\lou@ads.ctasnet[1].txt
C:\Users\lou\AppData\Roaming\Microsoft\Windows\Cookies\Low\lou@www.clickmanage[2].txt
C:\Users\lou\AppData\Roaming\Microsoft\Windows\Cookies\Low\lou@burstbeacon[1].txt
C:\Users\lou\AppData\Roaming\Microsoft\Windows\Cookies\Low\lou@stats.paypal[3].txt
C:\Users\lou\AppData\Roaming\Microsoft\Windows\Cookies\Low\lou@ads.audience2media[2].txt
C:\Users\lou\AppData\Roaming\Microsoft\Windows\Cookies\Low\lou@tribalfusion[1].txt
C:\Users\lou\AppData\Roaming\Microsoft\Windows\Cookies\Low\lou@statcounter[4].txt
C:\Users\lou\AppData\Roaming\Microsoft\Windows\Cookies\Low\lou@revsci[4].txt
C:\Users\lou\AppData\Roaming\Microsoft\Windows\Cookies\Low\lou@e-2dj6walyckdzoeo.stats.esomniture[2].txt
C:\Users\lou\AppData\Roaming\Microsoft\Windows\Cookies\Low\lou@ads.lzjl[2].txt
C:\Users\lou\AppData\Roaming\Microsoft\Windows\Cookies\Low\lou@videoegg.adbureau[2].txt
C:\Users\lou\AppData\Roaming\Microsoft\Windows\Cookies\Low\lou@sussexweddingfairs.co[2].txt
C:\Users\lou\AppData\Roaming\Microsoft\Windows\Cookies\Low\lou@statse.webtrendslive[5].txt
C:\Users\lou\AppData\Roaming\Microsoft\Windows\Cookies\Low\lou@media6degrees[6].txt
C:\Users\lou\AppData\Roaming\Microsoft\Windows\Cookies\Low\lou@ad.yieldmanager[7].txt
C:\Users\lou\AppData\Roaming\Microsoft\Windows\Cookies\Low\lou@doubleclick[3].txt
C:\Users\lou\AppData\Roaming\Microsoft\Windows\Cookies\Low\lou@ads.hairboutique[1].txt
C:\Users\lou\AppData\Roaming\Microsoft\Windows\Cookies\Low\lou@sonyeurope.112.2o7[1].txt
C:\Users\lou\AppData\Roaming\Microsoft\Windows\Cookies\Low\lou@clickshift[2].txt
C:\Users\lou\AppData\Roaming\Microsoft\Windows\Cookies\Low\lou@pro-market[2].txt
C:\Users\lou\AppData\Roaming\Microsoft\Windows\Cookies\Low\lou@ad1.adfarm1.adition[1].txt
C:\Users\lou\AppData\Roaming\Microsoft\Windows\Cookies\Low\lou@adserver.craftbits[3].txt
C:\Users\lou\AppData\Roaming\Microsoft\Windows\Cookies\Low\lou@www.yourspacewestsussex.co[2].txt
C:\Users\lou\AppData\Roaming\Microsoft\Windows\Cookies\Low\lou@serving-sys[9].txt
C:\Users\lou\AppData\Roaming\Microsoft\Windows\Cookies\Low\lou@imrworldwide[3].txt
C:\Users\lou\AppData\Roaming\Microsoft\Windows\Cookies\Low\lou@www.sextoys.co[2].txt
C:\Users\lou\AppData\Roaming\Microsoft\Windows\Cookies\Low\lou@adserver1.mokono[7].txt
C:\Users\lou\AppData\Roaming\Microsoft\Windows\Cookies\Low\lou@revsci[1].txt
C:\Users\lou\AppData\Roaming\Microsoft\Windows\Cookies\Low\lou@essex.gov[2].txt
C:\Users\lou\AppData\Roaming\Microsoft\Windows\Cookies\Low\lou@adform[2].txt
C:\Users\lou\AppData\Roaming\Microsoft\Windows\Cookies\Low\lou@fastclick[4].txt
C:\Users\lou\AppData\Roaming\Microsoft\Windows\Cookies\Low\lou@rotator.adjuggler[1].txt
C:\Users\lou\AppData\Roaming\Microsoft\Windows\Cookies\Low\lou@e-2dj6whlyokcpkkp.stats.esomniture[2].txt
C:\Users\lou\AppData\Roaming\Microsoft\Windows\Cookies\Low\lou@invitemedia[6].txt
C:\Users\lou\AppData\Roaming\Microsoft\Windows\Cookies\Low\lou@ads.geekswithblogs[1].txt
C:\Users\lou\AppData\Roaming\Microsoft\Windows\Cookies\Low\lou@www.burstbeacon[1].txt
C:\Users\lou\AppData\Roaming\Microsoft\Windows\Cookies\Low\lou@www.thesimsquestions[1].txt
C:\Users\lou\AppData\Roaming\Microsoft\Windows\Cookies\Low\lou@www.googleadservices[11].txt
C:\Users\lou\AppData\Roaming\Microsoft\Windows\Cookies\Low\lou@trafficmp[3].txt
C:\Users\lou\AppData\Roaming\Microsoft\Windows\Cookies\Low\lou@track.webgains[1].txt
C:\Users\lou\AppData\Roaming\Microsoft\Windows\Cookies\Low\lou@advertising[4].txt
C:\Users\lou\AppData\Roaming\Microsoft\Windows\Cookies\Low\lou@a.secureclicks[1].txt
C:\Users\lou\AppData\Roaming\Microsoft\Windows\Cookies\Low\lou@burstnet[2].txt
C:\Users\lou\AppData\Roaming\Microsoft\Windows\Cookies\Low\lou@adfarm1.adition[2].txt
C:\Users\lou\AppData\Roaming\Microsoft\Windows\Cookies\Low\lou@tradedoubler[3].txt
C:\Users\lou\AppData\Roaming\Microsoft\Windows\Cookies\Low\lou@ad.adnet[1].txt
C:\Users\lou\AppData\Roaming\Microsoft\Windows\Cookies\Low\lou@www.googleadservices[2].txt
C:\Users\lou\AppData\Roaming\Microsoft\Windows\Cookies\Low\lou@www.countrylife.co[1].txt
C:\Users\lou\AppData\Roaming\Microsoft\Windows\Cookies\Low\lou@e-2dj6wfkieodzmco.stats.esomniture[1].txt
C:\Users\lou\AppData\Roaming\Microsoft\Windows\Cookies\Low\lou@content.yieldmanager[1].txt
C:\Users\lou\AppData\Roaming\Microsoft\Windows\Cookies\Low\lou@statse.webtrendslive[8].txt
C:\Users\lou\AppData\Roaming\Microsoft\Windows\Cookies\Low\lou@192com.112.2o7[1].txt
C:\Users\lou\AppData\Roaming\Microsoft\Windows\Cookies\Low\lou@192com.112.2o7[2].txt
C:\Users\lou\AppData\Roaming\Microsoft\Windows\Cookies\Low\lou@247realmedia[2].txt
C:\Users\lou\AppData\Roaming\Microsoft\Windows\Cookies\Low\lou@247realmedia[1].txt
C:\Users\lou\AppData\Roaming\Microsoft\Windows\Cookies\Low\lou@247realmedia[3].txt
C:\Users\lou\AppData\Roaming\Microsoft\Windows\Cookies\Low\lou@247realmedia[4].txt
C:\Users\lou\AppData\Roaming\Microsoft\Windows\Cookies\Low\lou@2o7[2].txt
C:\Users\lou\AppData\Roaming\Microsoft\Windows\Cookies\Low\lou@77tracking[1].txt
C:\Users\lou\AppData\Roaming\Microsoft\Windows\Cookies\Low\lou@77tracking[2].txt
C:\Users\lou\AppData\Roaming\Microsoft\Windows\Cookies\Low\lou@acwestsussex[1].txt
C:\Users\lou\AppData\Roaming\Microsoft\Windows\Cookies\Low\lou@adbureau[1].txt
C:\Users\lou\AppData\Roaming\Microsoft\Windows\Cookies\Low\lou@adserver.adtechus[1].txt
C:\Users\lou\AppData\Roaming\Microsoft\Windows\Cookies\Low\lou@ads.telegraph.co[1].txt
C:\Users\lou\AppData\Roaming\Microsoft\Windows\Cookies\Low\lou@answerstv.112.2o7[1].txt
C:\Users\lou\AppData\Roaming\Microsoft\Windows\Cookies\Low\lou@atdmt[1].txt
C:\Users\lou\AppData\Roaming\Microsoft\Windows\Cookies\Low\lou@atdmt[2].txt
C:\Users\lou\AppData\Roaming\Microsoft\Windows\Cookies\Low\lou@bs.serving-sys[1].txt
C:\Users\lou\AppData\Roaming\Microsoft\Windows\Cookies\Low\lou@bs.serving-sys[2].txt
C:\Users\lou\AppData\Roaming\Microsoft\Windows\Cookies\Low\lou@bs.serving-sys[3].txt
C:\Users\lou\AppData\Roaming\Microsoft\Windows\Cookies\Low\lou@bs.serving-sys[4].txt
C:\Users\lou\AppData\Roaming\Microsoft\Windows\Cookies\Low\lou@burstnet[1].txt
C:\Users\lou\AppData\Roaming\Microsoft\Windows\Cookies\Low\lou@cb.adbureau[1].txt
C:\Users\lou\AppData\Roaming\Microsoft\Windows\Cookies\Low\lou@cdn4.specificclick[1].txt
C:\Users\lou\AppData\Roaming\Microsoft\Windows\Cookies\Low\lou@cdn5.specificclick[1].txt
C:\Users\lou\AppData\Roaming\Microsoft\Windows\Cookies\Low\lou@cgm.adbureau[1].txt
C:\Users\lou\AppData\Roaming\Microsoft\Windows\Cookies\Low\lou@clickshift[1].txt
C:\Users\lou\AppData\Roaming\Microsoft\Windows\Cookies\Low\lou@cltomedia[1].txt
C:\Users\lou\AppData\Roaming\Microsoft\Windows\Cookies\Low\lou@collective-media[2].txt
C:\Users\lou\AppData\Roaming\Microsoft\Windows\Cookies\Low\lou@ehg-bbc.hitbox[1].txt
C:\Users\lou\AppData\Roaming\Microsoft\Windows\Cookies\Low\lou@counter.hitslink[1].txt
C:\Users\lou\AppData\Roaming\Microsoft\Windows\Cookies\Low\lou@crackberry[2].txt
C:\Users\lou\AppData\Roaming\Microsoft\Windows\Cookies\Low\lou@d2.advertserve[1].txt
C:\Users\lou\AppData\Roaming\Microsoft\Windows\Cookies\Low\lou@d3.zedo[1].txt
C:\Users\lou\AppData\Roaming\Microsoft\Windows\Cookies\Low\lou@dealtime[1].txt
C:\Users\lou\AppData\Roaming\Microsoft\Windows\Cookies\Low\lou@dmtracker[2].txt
C:\Users\lou\AppData\Roaming\Microsoft\Windows\Cookies\Low\lou@dmtracker[1].txt
C:\Users\lou\AppData\Roaming\Microsoft\Windows\Cookies\Low\lou@doubleclick[1].txt
C:\Users\lou\AppData\Roaming\Microsoft\Windows\Cookies\Low\lou@e-2dj6wgmyqmcpigo.stats.esomniture[2].txt
C:\Users\lou\AppData\Roaming\Microsoft\Windows\Cookies\Low\lou@e-2dj6wcliwmczgfq.stats.esomniture[2].txt
C:\Users\lou\AppData\Roaming\Microsoft\Windows\Cookies\Low\lou@e-2dj6wfmycjdpalo.stats.esomniture[2].txt
C:\Users\lou\AppData\Roaming\Microsoft\Windows\Cookies\Low\lou@e-2dj6wjmyggdpwao.stats.esomniture[1].txt
C:\Users\lou\AppData\Roaming\Microsoft\Windows\Cookies\Low\lou@e.m.j.cltomedia[1].txt
C:\Users\lou\AppData\Roaming\Microsoft\Windows\Cookies\Low\lou@eaeacom.112.2o7[1].txt
C:\Users\lou\AppData\Roaming\Microsoft\Windows\Cookies\Low\lou@eas.apm.emediate[1].txt
C:\Users\lou\AppData\Roaming\Microsoft\Windows\Cookies\Low\lou@educationdynamics.122.2o7[1].txt
C:\Users\lou\AppData\Roaming\Microsoft\Windows\Cookies\Low\lou@ehg-debenhams.hitbox[1].txt
C:\Users\lou\AppData\Roaming\Microsoft\Windows\Cookies\Low\lou@emailworkz.globusmedia[2].txt
C:\Users\lou\AppData\Roaming\Microsoft\Windows\Cookies\Low\lou@eurostar.122.2o7[1].txt
C:\Users\lou\AppData\Roaming\Microsoft\Windows\Cookies\Low\lou@eyewonder[2].txt
C:\Users\lou\AppData\Roaming\Microsoft\Windows\Cookies\Low\lou@f2network.112.2o7[1].txt
C:\Users\lou\AppData\Roaming\Microsoft\Windows\Cookies\Low\lou@findacarehome[1].txt
C:\Users\lou\AppData\Roaming\Microsoft\Windows\Cookies\Low\lou@findaproperty[2].txt
C:\Users\lou\AppData\Roaming\Microsoft\Windows\Cookies\Low\lou@fl01.ct2.comclick[1].txt
AND MORE!!0 -
C:\Users\lou\AppData\Roaming\Microsoft\Windows\Cookies\Low\lou@forums.crackberry[2].txt
C:\Users\lou\AppData\Roaming\Microsoft\Windows\Cookies\Low\lou@harrahs.112.2o7[1].txt
C:\Users\lou\AppData\Roaming\Microsoft\Windows\Cookies\Low\lou@hg1.hitbox[1].txt
C:\Users\lou\AppData\Roaming\Microsoft\Windows\Cookies\Low\lou@himedia.individuad[1].txt
C:\Users\lou\AppData\Roaming\Microsoft\Windows\Cookies\Low\lou@hitbox[1].txt
C:\Users\lou\AppData\Roaming\Microsoft\Windows\Cookies\Low\lou@illicitencounters[2].txt
C:\Users\lou\AppData\Roaming\Microsoft\Windows\Cookies\Low\lou@imrworldwide[2].txt
C:\Users\lou\AppData\Roaming\Microsoft\Windows\Cookies\Low\lou@iwestsussex.co[2].txt
C:\Users\lou\AppData\Roaming\Microsoft\Windows\Cookies\Low\lou@iwestsussex.co[3].txt
C:\Users\lou\AppData\Roaming\Microsoft\Windows\Cookies\Low\lou@kontera[2].txt
C:\Users\lou\AppData\Roaming\Microsoft\Windows\Cookies\Low\lou@lfstmedia[1].txt
C:\Users\lou\AppData\Roaming\Microsoft\Windows\Cookies\Low\lou@liveperson[1].txt
C:\Users\lou\AppData\Roaming\Microsoft\Windows\Cookies\Low\lou@lucidmedia[1].txt
C:\Users\lou\AppData\Roaming\Microsoft\Windows\Cookies\Low\lou@marketingexperiments.122.2o7[1].txt
C:\Users\lou\AppData\Roaming\Microsoft\Windows\Cookies\Low\lou@mcafee.122.2o7[1].txt
C:\Users\lou\AppData\Roaming\Microsoft\Windows\Cookies\Low\lou@matalan.122.2o7[1].txt
C:\Users\lou\AppData\Roaming\Microsoft\Windows\Cookies\Low\lou@maxis.112.2o7[1].txt
C:\Users\lou\AppData\Roaming\Microsoft\Windows\Cookies\Low\lou@medhelpinternational.112.2o7[1].txt
C:\Users\lou\AppData\Roaming\Microsoft\Windows\Cookies\Low\lou@media.medhelp[3].txt
C:\Users\lou\AppData\Roaming\Microsoft\Windows\Cookies\Low\lou@men.122.2o7[1].txt
C:\Users\lou\AppData\Roaming\Microsoft\Windows\Cookies\Low\lou@microsoftmachinetranslation.112.2o7[1].txt
C:\Users\lou\AppData\Roaming\Microsoft\Windows\Cookies\Low\lou@msnaccountservices.112.2o7[1].txt
C:\Users\lou\AppData\Roaming\Microsoft\Windows\Cookies\Low\lou@newsquestdigitalmedia.122.2o7[1].txt
C:\Users\lou\AppData\Roaming\Microsoft\Windows\Cookies\Low\lou@nhhotelessa.112.2o7[1].txt
C:\Users\lou\AppData\Roaming\Microsoft\Windows\Cookies\Low\lou@nissaneurope.112.2o7[1].txt
C:\Users\lou\AppData\Roaming\Microsoft\Windows\Cookies\Low\lou@oddcast[1].txt
C:\Users\lou\AppData\Roaming\Microsoft\Windows\Cookies\Low\lou@onlineadtracker.co[2].txt
C:\Users\lou\AppData\Roaming\Microsoft\Windows\Cookies\Low\lou@overture[1].txt
C:\Users\lou\AppData\Roaming\Microsoft\Windows\Cookies\Low\lou@p162t1s1960137.kronos.bravenetmedia[2].txt
C:\Users\lou\AppData\Roaming\Microsoft\Windows\Cookies\Low\lou@photobox.112.2o7[1].txt
C:\Users\lou\AppData\Roaming\Microsoft\Windows\Cookies\Low\lou@pluckit.demandmedia[1].txt
C:\Users\lou\AppData\Roaming\Microsoft\Windows\Cookies\Low\lou@questionpro[1].txt
C:\Users\lou\AppData\Roaming\Microsoft\Windows\Cookies\Low\lou@roxburghshire.country-life.org[1].txt
C:\Users\lou\AppData\Roaming\Microsoft\Windows\Cookies\Low\lou@rrpartners.122.2o7[1].txt
C:\Users\lou\AppData\Roaming\Microsoft\Windows\Cookies\Low\lou@ru4[1].txt
C:\Users\lou\AppData\Roaming\Microsoft\Windows\Cookies\Low\lou@stats.paypal[1].txt
C:\Users\lou\AppData\Roaming\Microsoft\Windows\Cookies\Low\lou@statsadv.dada[1].txt
C:\Users\lou\AppData\Roaming\Microsoft\Windows\Cookies\Low\lou@sussex.police[2].txt
C:\Users\lou\AppData\Roaming\Microsoft\Windows\Cookies\Low\lou@test.coremetrics[1].txt
C:\Users\lou\AppData\Roaming\Microsoft\Windows\Cookies\Low\lou@timeoutcommunications.122.2o7[1].txt
C:\Users\lou\AppData\Roaming\Microsoft\Windows\Cookies\Low\lou@tracking.hearthstoneonline[1].txt
C:\Users\lou\AppData\Roaming\Microsoft\Windows\Cookies\Low\lou@tracking.onefeed.co[1].txt
C:\Users\lou\AppData\Roaming\Microsoft\Windows\Cookies\Low\lou@valueclick[1].txt
C:\Users\lou\AppData\Roaming\Microsoft\Windows\Cookies\Low\lou@user.lucidmedia[1].txt
C:\Users\lou\AppData\Roaming\Microsoft\Windows\Cookies\Low\lou@vdwp.solution.weborama[2].txt
C:\Users\lou\AppData\Roaming\Microsoft\Windows\Cookies\Low\lou@vdwp.solution.weborama[3].txt
C:\Users\lou\AppData\Roaming\Microsoft\Windows\Cookies\Low\lou@w00tpublishers.wootmedia[1].txt
C:\Users\lou\AppData\Roaming\Microsoft\Windows\Cookies\Low\lou@w00tpublishers.wootmedia[3].txt
C:\Users\lou\AppData\Roaming\Microsoft\Windows\Cookies\Low\lou@web4.realtracker[1].txt
C:\Users\lou\AppData\Roaming\Microsoft\Windows\Cookies\Low\lou@wmads2.widearea.co[1].txt
C:\Users\lou\AppData\Roaming\Microsoft\Windows\Cookies\Low\lou@wsclick.infospace[1].txt
C:\Users\lou\AppData\Roaming\Microsoft\Windows\Cookies\Low\lou@xiti[1].txt
C:\Users\lou\AppData\Roaming\Microsoft\Windows\Cookies\Low\lou@xiti[2].txt
C:\Users\lou\AppData\Roaming\Microsoft\Windows\Cookies\Low\lou@xiti[3].txt
C:\Users\lou\AppData\Roaming\Microsoft\Windows\Cookies\Low\lou@xm.xtendmedia[2].txt
C:\Users\lou\AppData\Roaming\Microsoft\Windows\Cookies\Low\lou@yadro[1].txt
C:\Users\lou\AppData\Roaming\Microsoft\Windows\Cookies\Low\lou@yieldmanager[2].txt
C:\Users\lou\AppData\Roaming\Microsoft\Windows\Cookies\Low\lou@yieldmanager[3].txt
C:\Users\lou\AppData\Roaming\Microsoft\Windows\Cookies\Low\lou@yourspacewestsussex.co[1].txt
C:\Users\lou\AppData\Roaming\Microsoft\Windows\Cookies\Low\lou@zedo[1].txt
C:\Users\lou\AppData\Roaming\Microsoft\Windows\Cookies\Low\lou@zedo[2].txt
Adware.MyWebSearch/FunWebProducts
(x86) HKU\S-1-5-21-3740435856-1450068620-2502515287-1000\SOFTWARE\FunWebProducts
(x86) HKCR\Interface\{07B18EAC-A523-4961-B6BB-170DE4475CCA}
(x86) HKCR\Interface\{07B18EAC-A523-4961-B6BB-170DE4475CCA}\ProxyStubClsid32
(x86) HKCR\Interface\{07B18EAC-A523-4961-B6BB-170DE4475CCA}\TypeLib
(x86) HKCR\Interface\{07B18EAC-A523-4961-B6BB-170DE4475CCA}\TypeLib#Version
(x86) HKCR\Interface\{120927BF-1700-43BC-810F-FAB92549B390}
(x86) HKCR\Interface\{120927BF-1700-43BC-810F-FAB92549B390}\ProxyStubClsid32
(x86) HKCR\Interface\{120927BF-1700-43BC-810F-FAB92549B390}\TypeLib
(x86) HKCR\Interface\{120927BF-1700-43BC-810F-FAB92549B390}\TypeLib#Version
(x86) HKCR\Interface\{1F52A5FA-A705-4415-B975-88503B291728}
(x86) HKCR\Interface\{1F52A5FA-A705-4415-B975-88503B291728}\ProxyStubClsid32
(x86) HKCR\Interface\{1F52A5FA-A705-4415-B975-88503B291728}\TypeLib
(x86) HKCR\Interface\{1F52A5FA-A705-4415-B975-88503B291728}\TypeLib#Version
(x86) HKCR\Interface\{247A115F-06C2-4FB3-967D-2D62D3CF4F0A}
(x86) HKCR\Interface\{247A115F-06C2-4FB3-967D-2D62D3CF4F0A}\ProxyStubClsid32
(x86) HKCR\Interface\{247A115F-06C2-4FB3-967D-2D62D3CF4F0A}\TypeLib
(x86) HKCR\Interface\{247A115F-06C2-4FB3-967D-2D62D3CF4F0A}\TypeLib#Version
(x86) HKCR\Interface\{2E9937FC-CF2F-4F56-AF54-5A6A3DD375CC}
(x86) HKCR\Interface\{2E9937FC-CF2F-4F56-AF54-5A6A3DD375CC}\ProxyStubClsid32
(x86) HKCR\Interface\{2E9937FC-CF2F-4F56-AF54-5A6A3DD375CC}\TypeLib
(x86) HKCR\Interface\{2E9937FC-CF2F-4F56-AF54-5A6A3DD375CC}\TypeLib#Version
(x86) HKCR\Interface\{3E53E2CB-86DB-4A4A-8BD9-FFEB7A64DF82}
(x86) HKCR\Interface\{3E53E2CB-86DB-4A4A-8BD9-FFEB7A64DF82}\ProxyStubClsid32
(x86) HKCR\Interface\{3E53E2CB-86DB-4A4A-8BD9-FFEB7A64DF82}\TypeLib
(x86) HKCR\Interface\{3E53E2CB-86DB-4A4A-8BD9-FFEB7A64DF82}\TypeLib#Version
(x86) HKCR\Interface\{3E720453-B472-4954-B7AA-33069EB53906}
(x86) HKCR\Interface\{3E720453-B472-4954-B7AA-33069EB53906}\ProxyStubClsid32
(x86) HKCR\Interface\{3E720453-B472-4954-B7AA-33069EB53906}\TypeLib
(x86) HKCR\Interface\{3E720453-B472-4954-B7AA-33069EB53906}\TypeLib#Version
(x86) HKCR\Interface\{63D0ED2D-B45B-4458-8B3B-60C69BBBD83C}
(x86) HKCR\Interface\{63D0ED2D-B45B-4458-8B3B-60C69BBBD83C}\ProxyStubClsid32
(x86) HKCR\Interface\{63D0ED2D-B45B-4458-8B3B-60C69BBBD83C}\TypeLib
(x86) HKCR\Interface\{63D0ED2D-B45B-4458-8B3B-60C69BBBD83C}\TypeLib#Version
(x86) HKCR\Interface\{741DE825-A6F0-4497-9AA6-8023CF9B0FFF}
(x86) HKCR\Interface\{741DE825-A6F0-4497-9AA6-8023CF9B0FFF}\ProxyStubClsid32
(x86) HKCR\Interface\{741DE825-A6F0-4497-9AA6-8023CF9B0FFF}\TypeLib
(x86) HKCR\Interface\{741DE825-A6F0-4497-9AA6-8023CF9B0FFF}\TypeLib#Version
(x86) HKCR\Interface\{7473D293-B7BB-4F24-AE82-7E2CE94BB6A9}
(x86) HKCR\Interface\{7473D293-B7BB-4F24-AE82-7E2CE94BB6A9}\ProxyStubClsid32
(x86) HKCR\Interface\{7473D293-B7BB-4F24-AE82-7E2CE94BB6A9}\TypeLib
(x86) HKCR\Interface\{7473D293-B7BB-4F24-AE82-7E2CE94BB6A9}\TypeLib#Version
(x86) HKCR\Interface\{7473D295-B7BB-4F24-AE82-7E2CE94BB6A9}
(x86) HKCR\Interface\{7473D295-B7BB-4F24-AE82-7E2CE94BB6A9}\ProxyStubClsid32
(x86) HKCR\Interface\{7473D295-B7BB-4F24-AE82-7E2CE94BB6A9}\TypeLib
(x86) HKCR\Interface\{7473D295-B7BB-4F24-AE82-7E2CE94BB6A9}\TypeLib#Version
(x86) HKCR\Interface\{7473D297-B7BB-4F24-AE82-7E2CE94BB6A9}
(x86) HKCR\Interface\{7473D297-B7BB-4F24-AE82-7E2CE94BB6A9}\ProxyStubClsid32
(x86) HKCR\Interface\{7473D297-B7BB-4F24-AE82-7E2CE94BB6A9}\TypeLib
(x86) HKCR\Interface\{7473D297-B7BB-4F24-AE82-7E2CE94BB6A9}\TypeLib#Version
(x86) HKCR\Interface\{90449521-D834-4703-BB4E-D3AA44042FF8}
(x86) HKCR\Interface\{90449521-D834-4703-BB4E-D3AA44042FF8}\ProxyStubClsid32
(x86) HKCR\Interface\{90449521-D834-4703-BB4E-D3AA44042FF8}\TypeLib
(x86) HKCR\Interface\{90449521-D834-4703-BB4E-D3AA44042FF8}\TypeLib#Version
(x86) HKCR\Interface\{991AAC62-B100-47CE-8B75-253965244F69}
(x86) HKCR\Interface\{991AAC62-B100-47CE-8B75-253965244F69}\ProxyStubClsid32
(x86) HKCR\Interface\{991AAC62-B100-47CE-8B75-253965244F69}\TypeLib
(x86) HKCR\Interface\{991AAC62-B100-47CE-8B75-253965244F69}\TypeLib#Version
(x86) HKCR\Interface\{A626CDBD-3D13-4F78-B819-440A28D7E8FC}
(x86) HKCR\Interface\{A626CDBD-3D13-4F78-B819-440A28D7E8FC}\ProxyStubClsid32
(x86) HKCR\Interface\{A626CDBD-3D13-4F78-B819-440A28D7E8FC}\TypeLib
(x86) HKCR\Interface\{A626CDBD-3D13-4F78-B819-440A28D7E8FC}\TypeLib#Version
(x86) HKCR\Interface\{BBABDC90-F3D5-4801-863A-EE6AE529862D}
(x86) HKCR\Interface\{BBABDC90-F3D5-4801-863A-EE6AE529862D}\ProxyStubClsid32
(x86) HKCR\Interface\{BBABDC90-F3D5-4801-863A-EE6AE529862D}\TypeLib
(x86) HKCR\Interface\{BBABDC90-F3D5-4801-863A-EE6AE529862D}\TypeLib#Version
(x86) HKCR\Interface\{D6FF3684-AD3B-48EB-BBB4-B9E6C5A355C1}
(x86) HKCR\Interface\{D6FF3684-AD3B-48EB-BBB4-B9E6C5A355C1}\ProxyStubClsid32
(x86) HKCR\Interface\{D6FF3684-AD3B-48EB-BBB4-B9E6C5A355C1}\TypeLib
(x86) HKCR\Interface\{D6FF3684-AD3B-48EB-BBB4-B9E6C5A355C1}\TypeLib#Version
(x86) HKCR\Interface\{DE38C398-B328-4F4C-A3AD-1B5E4ED93477}
(x86) HKCR\Interface\{DE38C398-B328-4F4C-A3AD-1B5E4ED93477}\ProxyStubClsid32
(x86) HKCR\Interface\{DE38C398-B328-4F4C-A3AD-1B5E4ED93477}\TypeLib
(x86) HKCR\Interface\{DE38C398-B328-4F4C-A3AD-1B5E4ED93477}\TypeLib#Version
(x86) HKCR\Interface\{E342AF55-B78A-4CD0-A2BB-DA7F52D9D25F}
(x86) HKCR\Interface\{E342AF55-B78A-4CD0-A2BB-DA7F52D9D25F}\ProxyStubClsid32
(x86) HKCR\Interface\{E342AF55-B78A-4CD0-A2BB-DA7F52D9D25F}\TypeLib
(x86) HKCR\Interface\{E342AF55-B78A-4CD0-A2BB-DA7F52D9D25F}\TypeLib#Version
(x86) HKCR\Interface\{E79DFBC9-5697-4FBD-94E5-5B2A9C7C1612}
(x86) HKCR\Interface\{E79DFBC9-5697-4FBD-94E5-5B2A9C7C1612}\ProxyStubClsid32
(x86) HKCR\Interface\{E79DFBC9-5697-4FBD-94E5-5B2A9C7C1612}\TypeLib
(x86) HKCR\Interface\{E79DFBC9-5697-4FBD-94E5-5B2A9C7C1612}\TypeLib#Version
(x86) HKCR\Interface\{E79DFBCB-5697-4FBD-94E5-5B2A9C7C1612}
(x86) HKCR\Interface\{E79DFBCB-5697-4FBD-94E5-5B2A9C7C1612}\ProxyStubClsid32
(x86) HKCR\Interface\{E79DFBCB-5697-4FBD-94E5-5B2A9C7C1612}\TypeLib
(x86) HKCR\Interface\{E79DFBCB-5697-4FBD-94E5-5B2A9C7C1612}\TypeLib#Version
(x86) HKCR\Interface\{EB9E5C1C-B1F9-4C2B-BE8A-27D6446FDAF8}
(x86) HKCR\Interface\{EB9E5C1C-B1F9-4C2B-BE8A-27D6446FDAF8}\ProxyStubClsid32
(x86) HKCR\Interface\{EB9E5C1C-B1F9-4C2B-BE8A-27D6446FDAF8}\TypeLib
(x86) HKCR\Interface\{EB9E5C1C-B1F9-4C2B-BE8A-27D6446FDAF8}\TypeLib#Version
(x86) HKCR\Interface\{F87D7FB5-9DC5-4C8C-B998-D8DFE02E2978}
(x86) HKCR\Interface\{F87D7FB5-9DC5-4C8C-B998-D8DFE02E2978}\ProxyStubClsid32
(x86) HKCR\Interface\{F87D7FB5-9DC5-4C8C-B998-D8DFE02E2978}\TypeLib
(x86) HKCR\Interface\{F87D7FB5-9DC5-4C8C-B998-D8DFE02E2978}\TypeLib#Version
(x64) HKCR\Interface\{07B18EAA-A523-4961-B6BB-170DE4475CCA}
(x64) HKCR\Interface\{07B18EAA-A523-4961-B6BB-170DE4475CCA}\ProxyStubClsid32
(x64) HKCR\Interface\{07B18EAA-A523-4961-B6BB-170DE4475CCA}\TypeLib
(x64) HKCR\Interface\{07B18EAA-A523-4961-B6BB-170DE4475CCA}\TypeLib#Version
(x64) HKCR\Interface\{1093995A-BA37-41D2-836E-091067C4AD17}
(x64) HKCR\Interface\{1093995A-BA37-41D2-836E-091067C4AD17}\ProxyStubClsid32
(x64) HKCR\Interface\{1093995A-BA37-41D2-836E-091067C4AD17}\TypeLib
(x64) HKCR\Interface\{1093995A-BA37-41D2-836E-091067C4AD17}\TypeLib#Version
(x64) HKCR\Interface\{17DE5E5E-BFE3-4E83-8E1F-8755795359EC}
(x64) HKCR\Interface\{17DE5E5E-BFE3-4E83-8E1F-8755795359EC}\ProxyStubClsid32
(x64) HKCR\Interface\{17DE5E5E-BFE3-4E83-8E1F-8755795359EC}\TypeLib
(x64) HKCR\Interface\{17DE5E5E-BFE3-4E83-8E1F-8755795359EC}\TypeLib#Version
(x64) HKCR\Interface\{2E3537FC-CF2F-4F56-AF54-5A6A3DD375CC}
(x64) HKCR\Interface\{2E3537FC-CF2F-4F56-AF54-5A6A3DD375CC}\ProxyStubClsid32
(x64) HKCR\Interface\{2E3537FC-CF2F-4F56-AF54-5A6A3DD375CC}\TypeLib
(x64) HKCR\Interface\{2E3537FC-CF2F-4F56-AF54-5A6A3DD375CC}\TypeLib#Version
(x64) HKCR\Interface\{3E1656ED-F60E-4597-B6AA-B6A58E171495}
(x64) HKCR\Interface\{3E1656ED-F60E-4597-B6AA-B6A58E171495}\ProxyStubClsid32
(x64) HKCR\Interface\{3E1656ED-F60E-4597-B6AA-B6A58E171495}\TypeLib
(x64) HKCR\Interface\{3E1656ED-F60E-4597-B6AA-B6A58E171495}\TypeLib#Version
(x64) HKCR\Interface\{3E720451-B472-4954-B7AA-33069EB53906}
(x64) HKCR\Interface\{3E720451-B472-4954-B7AA-33069EB53906}\ProxyStubClsid32
(x64) HKCR\Interface\{3E720451-B472-4954-B7AA-33069EB53906}\TypeLib
(x64) HKCR\Interface\{3E720451-B472-4954-B7AA-33069EB53906}\TypeLib#Version
(x64) HKCR\Interface\{63D0ED2B-B45B-4458-8B3B-60C69BBBD83C}
(x64) HKCR\Interface\{63D0ED2B-B45B-4458-8B3B-60C69BBBD83C}\ProxyStubClsid32
(x64) HKCR\Interface\{63D0ED2B-B45B-4458-8B3B-60C69BBBD83C}\TypeLib
(x64) HKCR\Interface\{63D0ED2B-B45B-4458-8B3B-60C69BBBD83C}\TypeLib#Version
(x64) HKCR\Interface\{6E74766C-4D93-4CC0-96D1-47B8E07FF9CA}
(x64) HKCR\Interface\{6E74766C-4D93-4CC0-96D1-47B8E07FF9CA}\ProxyStubClsid32
(x64) HKCR\Interface\{6E74766C-4D93-4CC0-96D1-47B8E07FF9CA}\TypeLib
(x64) HKCR\Interface\{6E74766C-4D93-4CC0-96D1-47B8E07FF9CA}\TypeLib#Version
(x64) HKCR\Interface\{72EE7F04-15BD-4845-A005-D6711144D86A}
(x64) HKCR\Interface\{72EE7F04-15BD-4845-A005-D6711144D86A}\ProxyStubClsid32
(x64) HKCR\Interface\{72EE7F04-15BD-4845-A005-D6711144D86A}\TypeLib
(x64) HKCR\Interface\{72EE7F04-15BD-4845-A005-D6711144D86A}\TypeLib#Version
(x64) HKCR\Interface\{7473D291-B7BB-4F24-AE82-7E2CE94BB6A9}
(x64) HKCR\Interface\{7473D291-B7BB-4F24-AE82-7E2CE94BB6A9}\ProxyStubClsid32
(x64) HKCR\Interface\{7473D291-B7BB-4F24-AE82-7E2CE94BB6A9}\TypeLib
(x64) HKCR\Interface\{7473D291-B7BB-4F24-AE82-7E2CE94BB6A9}\TypeLib#Version
(x64) HKCR\Interface\{CF54BE1C-9359-4395-8533-1657CF209CFE}
(x64) HKCR\Interface\{CF54BE1C-9359-4395-8533-1657CF209CFE}\ProxyStubClsid32
(x64) HKCR\Interface\{CF54BE1C-9359-4395-8533-1657CF209CFE}\TypeLib
(x64) HKCR\Interface\{CF54BE1C-9359-4395-8533-1657CF209CFE}\TypeLib#Version
(x64) HKCR\Interface\{E342AF55-B78A-4CD0-A2BB-DA7F52D9D25E}
(x64) HKCR\Interface\{E342AF55-B78A-4CD0-A2BB-DA7F52D9D25E}\ProxyStubClsid32
(x64) HKCR\Interface\{E342AF55-B78A-4CD0-A2BB-DA7F52D9D25E}\TypeLib
(x64) HKCR\Interface\{E342AF55-B78A-4CD0-A2BB-DA7F52D9D25E}\TypeLib#Version
Trojan.Agent/Gen-Koobface
C:\$RECYCLE.BIN\S-1-5-21-3740435856-1450068620-2502515287-1000\$R6GRDO0.COM\FACEMOODS\1.4.15.13\FACEMOODSAPP.DLL
Havent done the other thing you suggested yet (as scan only just finished for this one) am going to bed now, but will do that asap if you could please advise me what to do next0 -
Well the thing that concerns me is the only real nasty thats been found is 'mywebsearch'. Yet ive never known it do what you explained in the original post (that said, its 'always' being updated so maybe its now worse than before)
As youve a 64 bit system its a little difficult finding programs to run to check (Id normally ask for combfix to be run, but it wont run on 64 bit systems)
So id suggest running Dr Web next
Download and run the FREE version of DR WEB
http://www.freedrweb.com/download+cureit/gr/
Turn your anti virus OFF
It will auto QUICK scan
After that set to scan the WHOLE computer and press the 'play' icon
***DO NOT UPGRADE TO FULL VERSION***:idea:0
This discussion has been closed.
Confirm your email address to Create Threads and Reply

Categories
- All Categories
- 352K Banking & Borrowing
- 253.5K Reduce Debt & Boost Income
- 454.2K Spending & Discounts
- 245K Work, Benefits & Business
- 600.6K Mortgages, Homes & Bills
- 177.4K Life & Family
- 258.8K Travel & Transport
- 1.5M Hobbies & Leisure
- 16.2K Discuss & Feedback
- 37.6K Read-Only Boards