TechSpot

Windows security Centre can't start and pops ups

By Gefstar
Aug 13, 2011
  1. Edit: Adding the text from duplicate post which has been deleted:
    Please see reports below

    GMER 1.0.15.15641 - http://www.gmer.net
    Rootkit scan 2011-08-13 23:21:11
    Windows 6.1.7601 Service Pack 1
    Running: gmer.exe


    ---- Registry - GMER 1.0.15 ----

    Reg HKLM\SYSTEM\CurrentControlSet\services\sptd\Cfg@s1 771343423
    Reg HKLM\SYSTEM\CurrentControlSet\services\sptd\Cfg@s2 285507792
    Reg HKLM\SYSTEM\CurrentControlSet\services\sptd\Cfg@h0 1
    Reg HKLM\SYSTEM\CurrentControlSet\services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC
    Reg HKLM\SYSTEM\CurrentControlSet\services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC@p0 C:\Program Files (x86)\DAEMON Tools Lite\
    Reg HKLM\SYSTEM\CurrentControlSet\services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC@u0 0x00 0x00 0x00 0x00 ...
    Reg HKLM\SYSTEM\CurrentControlSet\services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC@h0 0
    Reg HKLM\SYSTEM\CurrentControlSet\services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC@hdf12 0x60 0x7F 0xC2 0x15 ...
    Reg HKLM\SYSTEM\CurrentControlSet\services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC\00000001
    Reg HKLM\SYSTEM\CurrentControlSet\services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC\00000001@a0 0x20 0x01 0x00 0x00 ...
    Reg HKLM\SYSTEM\CurrentControlSet\services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC\00000001@hdf12 0xE0 0x55 0x4F 0x0E ...
    Reg HKLM\SYSTEM\CurrentControlSet\services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC\00000001\gdq0
    Reg HKLM\SYSTEM\CurrentControlSet\services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC\00000001\gdq0@hdf12 0x73 0x0E 0xB1 0x4C ...
    Reg HKLM\SYSTEM\ControlSet002\services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC (not active ControlSet)
    Reg HKLM\SYSTEM\ControlSet002\services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC@p0 C:\Program Files (x86)\DAEMON Tools Lite\
    Reg HKLM\SYSTEM\ControlSet002\services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC@u0 0x00 0x00 0x00 0x00 ...
    Reg HKLM\SYSTEM\ControlSet002\services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC@h0 0
    Reg HKLM\SYSTEM\ControlSet002\services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC@hdf12 0x60 0x7F 0xC2 0x15 ...
    Reg HKLM\SYSTEM\ControlSet002\services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC\00000001 (not active ControlSet)
    Reg HKLM\SYSTEM\ControlSet002\services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC\00000001@a0 0x20 0x01 0x00 0x00 ...
    Reg HKLM\SYSTEM\ControlSet002\services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC\00000001@hdf12 0xE0 0x55 0x4F 0x0E ...
    Reg HKLM\SYSTEM\ControlSet002\services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC\00000001\gdq0 (not active ControlSet)
    Reg HKLM\SYSTEM\ControlSet002\services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC\00000001\gdq0@hdf12 0x73 0x0E 0xB1 0x4C ...

    ---- Files - GMER 1.0.15 ----

    File C:\Users\ChrisKelly\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\7MVLD1Y4\down[2] 0 bytes
    File C:\Users\ChrisKelly\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\7MVLD1Y4\errorPageStrings[1] 0 bytes
    File C:\Users\ChrisKelly\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\7MVLD1Y4\bullet[1] 0 bytes
    File C:\Users\ChrisKelly\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\8I83OUC0\httpErrorPagesScripts[1] 0 bytes

    ---- EOF - GMER 1.0.15 ----


    .
    DDS (Ver_2011-06-23.01) - NTFSAMD64
    Internet Explorer: 8.0.7601.17514
    Run by ChrisKelly at 23:24:30 on 2011-08-13
    Microsoft Windows 7 Home Premium 6.1.7601.1.1252.44.1033.18.3828.1437 [GMT 1:00]
    .
    AV: McAfee Anti-Virus and Anti-Spyware *Disabled/Updated* {86355677-4064-3EA7-ABB3-1B136EB04637}
    SP: Windows Defender *Disabled/Updated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
    SP: McAfee Anti-Virus and Anti-Spyware *Disabled/Updated* {3D54B793-665E-3129-9103-206115370C8A}
    FW: McAfee Firewall *Disabled* {BE0ED752-0A0B-3FFF-80EC-B2269063014C}
    .
    ============== Running Processes ===============
    .
    C:\Windows\system32\wininit.exe
    C:\Windows\system32\lsm.exe
    C:\Windows\system32\svchost.exe -k DcomLaunch
    C:\Windows\system32\nvvsvc.exe
    C:\Program Files (x86)\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe
    C:\Windows\system32\svchost.exe -k RPCSS
    C:\Windows\System32\svchost.exe -k LocalServiceNetworkRestricted
    C:\Windows\System32\svchost.exe -k LocalSystemNetworkRestricted
    C:\Windows\system32\svchost.exe -k netsvcs
    C:\Windows\system32\svchost.exe -k LocalService
    C:\Program Files\Dell\DellDock\DockLogin.exe
    C:\Windows\system32\svchost.exe -k NetworkService
    C:\Program Files\AVAST Software\Avast\AvastSvc.exe
    C:\Windows\system32\WLANExt.exe
    C:\Windows\system32\conhost.exe
    C:\Program Files\NVIDIA Corporation\Display\nvxdsync.exe
    C:\Windows\system32\nvvsvc.exe
    C:\Windows\system32\taskeng.exe
    C:\Windows\System32\spoolsv.exe
    C:\Windows\system32\svchost.exe -k LocalServiceNoNetwork
    C:\Windows\system32\rundll32.exe
    C:\Windows\SysWOW64\rundll32.exe
    c:\Program Files (x86)\Adobe\Elements Organizer 8.0\PhotoshopElementsFileAgent.exe
    C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe
    C:\Program Files\Realtek\Audio\HDA\AERTSr64.exe
    C:\Windows\SysWOW64\svchost.exe -k Akamai
    C:\Program Files (x86)\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe
    C:\Windows\system32\taskhost.exe
    C:\Windows\system32\Dwm.exe
    C:\Windows\Explorer.EXE
    C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
    C:\Windows\System32\igfxtray.exe
    C:\Windows\System32\hkcmd.exe
    C:\Windows\System32\igfxpers.exe
    C:\Program Files\Common Files\Intel\WirelessCommon\iFrmewrk.exe
    C:\Windows\system32\svchost.exe -k LocalServiceAndNoImpersonation
    C:\Program Files\NVIDIA Corporation\Display\nvtray.exe
    C:\Program Files\Common Files\McAfee\SystemCore\mfevtps.exe
    C:\Program Files\Dell\QuickSet\quickset.exe
    C:\Program Files (x86)\STMicroelectronics\AccelerometerP11\FF_Protection.exe
    C:\Program Files\Common Files\Intel\WirelessCommon\RegSrvc.exe
    C:\Program Files (x86)\Dell DataSafe Local Backup\sftservice.EXE
    C:\Program Files\Realtek\Audio\HDA\RtkNGUI64.exe
    C:\Windows\system32\svchost.exe -k imgsvc
    C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE
    C:\Program Files\Realtek\Audio\HDA\RAVBg64.exe
    C:\Program Files\Intel\WiFi\bin\EvtEng.exe
    C:\Program Files (x86)\Dell DataSafe Local Backup\COMPONENTS\SCHEDULER\STSERVICE.EXE
    C:\Program Files (x86)\Dell DataSafe Local Backup\Components\DSUpdate\DSUpd.exe
    C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSvcM.exe
    C:\Windows\system32\wbem\wmiprvse.exe
    C:\Program Files (x86)\Nokia\Nokia PC Suite 7\PCSuite.exe
    C:\Windows\system32\wbem\unsecapp.exe
    C:\Program Files\Microsoft Office\Office14\MSOSYNC.EXE
    C:\Windows\system32\wbem\unsecapp.exe
    C:\Program Files\Common Files\McAfee\SystemCore\mcshield.exe
    C:\Program Files\Common Files\McAfee\SystemCore\mfefire.exe
    C:\Program Files\Common Files\McAfee\McSvcHost\McSvHost.exe
    C:\Program Files (x86)\DAEMON Tools Lite\DTLite.exe
    C:\Program Files\Windows Sidebar\sidebar.exe
    C:\Program Files (x86)\Dell DataSafe Local Backup\Toaster.exe
    C:\Program Files\Dell\DellDock\DellDock.exe
    C:\Program Files (x86)\Renesas Electronics\USB 3.0 Host Controller Driver\Application\nusb3mon.exe
    C:\Program Files (x86)\Dell DataSafe Online\DataSafeOnline.exe
    C:\Program Files (x86)\Dell Webcam\Dell Webcam Central\WebcamDell2.exe
    C:\Program Files (x86)\CyberLink\PowerDVD9\PDVD9Serv.exe
    C:\Program Files (x86)\CyberLink\Shared files\brs.exe
    C:\Program Files (x86)\Roxio\OEM\Roxio Burn\RoxioBurnLauncher.exe
    C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe
    C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamgui.exe
    C:\Program Files\AVAST Software\Avast\AvastUI.exe
    C:\Program Files (x86)\PC Connectivity Solution\ServiceLayer.exe
    C:\Windows\system32\SearchIndexer.exe
    C:\Program Files (x86)\PC Connectivity Solution\Transports\NclUSBSrv64.exe
    C:\Program Files\Synaptics\SynTP\SynTPHelper.exe
    C:\Program Files\Intel\WiFi\bin\PanDhcpDns.exe
    C:\Windows\system32\svchost.exe -k NetworkServiceNetworkRestricted
    C:\Program Files (x86)\PC Connectivity Solution\Transports\NclRSSrv.exe
    C:\Program Files\Windows Media Player\wmpnetwk.exe
    C:\Windows\System32\svchost.exe -k LocalServicePeerNet
    C:\Program Files (x86)\The Geek\AGT Pro\AGT Pro.exe
    C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\LMS\LMS.exe
    C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamservice.exe
    C:\Program Files (x86)\NVIDIA Corporation\NVIDIA Updatus\daemonu.exe
    C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\UNS\UNS.exe
    C:\Program Files (x86)\Adobe\Reader 10.0\Reader\AcroRd32.exe
    C:\Program Files (x86)\Adobe\Reader 10.0\Reader\AcroRd32.exe
    C:\Users\ChrisKelly\Desktop\gmer.exe
    C:\Program Files\mcafee.com\agent\mcagent.exe
    C:\Users\ChrisKelly\Desktop\gmer.exe
    C:\Users\ChrisKelly\AppData\Local\Google\Chrome\Application\chrome.exe
    C:\Users\ChrisKelly\AppData\Local\Google\Chrome\Application\chrome.exe
    C:\Users\ChrisKelly\AppData\Local\Google\Chrome\Application\chrome.exe
    C:\Users\ChrisKelly\AppData\Local\Google\Chrome\Application\chrome.exe
    C:\Users\ChrisKelly\AppData\Local\Google\Chrome\Application\chrome.exe
    C:\Users\ChrisKelly\AppData\Local\Google\Chrome\Application\chrome.exe
    C:\Users\ChrisKelly\AppData\Local\Google\Chrome\Application\chrome.exe
    C:\Users\ChrisKelly\AppData\Local\Google\Chrome\Application\chrome.exe
    C:\Users\ChrisKelly\AppData\Local\Google\Chrome\Application\chrome.exe
    C:\Users\ChrisKelly\AppData\Local\Google\Chrome\Application\chrome.exe
    C:\Users\ChrisKelly\AppData\Local\Google\Chrome\Application\chrome.exe
    C:\Users\ChrisKelly\AppData\Local\Google\Chrome\Application\chrome.exe
    C:\Users\ChrisKelly\AppData\Local\Google\Chrome\Application\chrome.exe
    C:\Windows\SysWOW64\rundll32.exe
    C:\Users\ChrisKelly\AppData\Local\Google\Chrome\Application\chrome.exe
    C:\Windows\system32\SearchProtocolHost.exe
    C:\Windows\system32\SearchFilterHost.exe
    C:\Windows\system32\DllHost.exe
    C:\Windows\system32\DllHost.exe
    C:\Windows\SysWOW64\cmd.exe
    C:\Windows\system32\conhost.exe
    C:\Windows\SysWOW64\cscript.exe
    C:\Windows\system32\wbem\wmiprvse.exe
    .
    ============== Pseudo HJT Report ===============
    .
    uSearch Page = hxxp://www.google.com
    uSearch Bar = hxxp://www.google.com/ie
    uDefault_Search_URL = hxxp://www.google.com/ie
    uSearchAssistant = hxxp://www.google.com/ie
    uSearchURL,(Default) = hxxp://www.google.com/search?q=%s
    uURLSearchHooks: H - No File
    uURLSearchHooks: H - No File
    BHO: Adobe PDF Link Helper: {18df081c-e8ad-4283-a596-fa578c2ebdc3} - C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll
    BHO: McAfee Phishing Filter: {27b4851a-3207-45a2-b947-be8afe6163ab} - c:\progra~1\mcafee\msk\mskapbho.dll
    BHO: Conduit Engine: {30f9b915-b755-4826-820b-08fba6bd249d} - C:\Program Files (x86)\ConduitEngine\ConduitEngine.dll
    BHO: Groove GFS Browser Helper: {72853161-30c5-4d22-b7f9-0bbc1d38a37e} - C:\PROGRA~2\MICROS~1\Office14\GROOVEEX.DLL
    BHO: scriptproxy: {7db2d5a0-7241-4e79-b68d-6309f01c5231} - C:\Program Files (x86)\Common Files\McAfee\SystemCore\ScriptSn.20110509193654.dll
    BHO: avast! WebRep: {8e5e2654-ad2d-48bf-ac2d-d17f00898d06} - C:\Program Files\AVAST Software\Avast\aswWebRepIE.dll
    BHO: Windows Live ID Sign-in Helper: {9030d464-4c02-4abf-8ecc-5164760863c6} - C:\Program Files (x86)\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
    BHO: Windows Live Messenger Companion Helper: {9fdde16b-836f-4806-ab1f-1455cbeff289} - C:\Program Files (x86)\Windows Live\Companion\companioncore.dll
    BHO: Skype add-on for Internet Explorer: {ae805869-2e5c-4ed4-8f7b-f1f7851a4497} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer\skypeieplugin.dll
    BHO: Office Document Cache Handler: {b4f3a835-0e21-4959-ba22-42b3008e02ff} - C:\PROGRA~2\MICROS~1\Office14\URLREDIR.DLL
    BHO: Java(tm) Plug-In 2 SSV Helper: {dbc80044-a445-435b-bc74-9c25c1c588a9} - C:\Program Files (x86)\Java\jre6\bin\jp2ssv.dll
    TB: Conduit Engine: {30f9b915-b755-4826-820b-08fba6bd249d} - C:\Program Files (x86)\ConduitEngine\ConduitEngine.dll
    TB: avast! WebRep: {8e5e2654-ad2d-48bf-ac2d-d17f00898d06} - C:\Program Files\AVAST Software\Avast\aswWebRepIE.dll
    TB: {88C7F2AA-F93F-432C-8F0E-B7D85967A527} - No File
    TB: {32099AAC-C132-4136-9E9A-4E364A424E17} - No File
    uRun: [msnmsgr] "C:\Program Files (x86)\Windows Live\Messenger\msnmsgr.exe" /background
    uRun: [AdobeBridge] "C:\Program Files (x86)\Adobe\Adobe Bridge CS5\Bridge.exe" -stealth
    uRun: [Google Update] "C:\Users\ChrisKelly\AppData\Local\Google\Update\GoogleUpdate.exe" /c
    uRun: [PC Suite Tray] "C:\Program Files (x86)\Nokia\Nokia PC Suite 7\PCSuite.exe" -onlytray
    uRun: [OfficeSyncProcess] "C:\Program Files\Microsoft Office\Office14\MSOSYNC.EXE"
    uRun: [DAEMON Tools Lite] "C:\Program Files (x86)\DAEMON Tools Lite\DTLite.exe" -autorun
    uRun: [Sidebar] C:\Program Files\Windows Sidebar\sidebar.exe /autoRun
    mRun: [NUSB3MON] "c:\Program Files (x86)\Renesas Electronics\USB 3.0 Host Controller Driver\Application\nusb3mon.exe"
    mRun: [Dell DataSafe Online] "C:\Program Files (x86)\Dell DataSafe Online\DataSafeOnline.exe" /m
    mRun: [mcui_exe] "C:\Program Files\McAfee.com\Agent\mcagent.exe" /runkey
    mRun: [Dell Webcam Central] "C:\Program Files (x86)\Dell Webcam\Dell Webcam Central\WebcamDell2.exe" /mode2
    mRun: [RemoteControl9] "c:\Program Files (x86)\CyberLink\PowerDVD9\PDVD9Serv.exe"
    mRun: [PDVD9LanguageShortcut] "c:\Program Files (x86)\CyberLink\PowerDVD9\Language\Language.exe"
    mRun: [BDRegion] c:\Program Files (x86)\Cyberlink\Shared Files\brs.exe
    mRun: [<NO NAME>]
    mRun: [RoxWatchTray] "C:\Program Files (x86)\Common Files\Roxio Shared\OEM\12.0\SharedCOM\RoxWatchTray12OEM.exe"
    mRun: [DellSupportCenter] "C:\Program Files (x86)\Dell Support Center\bin\sprtcmd.exe" /P DellSupportCenter
    mRun: [Desktop Disc Tool] "C:\Program Files (x86)\Roxio\oem\Roxio Burn\RoxioBurnLauncher.exe"
    mRun: [SunJavaUpdateSched] "C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe"
    mRun: [AppleSyncNotifier] C:\Program Files (x86)\Common Files\Apple\Mobile Device Support\AppleSyncNotifier.exe
    mRun: [Adobe ARM] "C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe"
    mRun: [Malwarebytes' Anti-Malware] "C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamgui.exe" /starttray
    mRun: [avast] "C:\Program Files\AVAST Software\Avast\avastUI.exe" /nogui
    StartupFolder: C:\Users\CHRISK~1\AppData\Roaming\MICROS~1\Windows\STARTM~1\Programs\Startup\DELLDO~1.LNK - C:\Program Files (x86)\Dell\DellDock\DellDock.exe
    mPolicies-explorer: NoActiveDesktop = 1 (0x1)
    mPolicies-system: ConsentPromptBehaviorAdmin = 5 (0x5)
    mPolicies-system: ConsentPromptBehaviorUser = 3 (0x3)
    mPolicies-system: EnableUIADesktopToggle = 0 (0x0)
    IE: Add to Google Photos Screensa&ver - C:\Windows\system32\GPhotos.scr/200
    IE: E&xport to Microsoft Excel - C:\PROGRA~1\MICROS~2\Office14\EXCEL.EXE/3000
    IE: Se&nd to OneNote - C:\PROGRA~1\MICROS~2\Office14\ONBttnIE.dll/105
    IE: {0000036B-C524-4050-81A0-243669A86B9F} - {B63DBA5F-523F-4B9C-A43D-65DF1977EAD3} - C:\Program Files (x86)\Windows Live\Companion\companioncore.dll
    IE: {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - {5F7B1267-94A9-47F5-98DB-E99415F33AEC} - C:\Program Files (x86)\Windows Live\Writer\WriterBrowserExtension.dll
    IE: {2670000A-7350-4f3c-8081-5663EE0C6C49} - {48E73304-E1D6-4330-914C-F5F514E3486C} - C:\Program Files (x86)\Microsoft Office\Office14\ONBttnIE.dll
    IE: {789FE86F-6FC4-46A1-9849-EDE0DB0C95CA} - {FFFDC614-B694-4AE6-AB38-5D6374584B52} - C:\Program Files (x86)\Microsoft Office\Office14\ONBttnIELinkedNotes.dll
    IE: {898EA8C8-E7FF-479B-8935-AEC46303B9E5} - {898EA8C8-E7FF-479B-8935-AEC46303B9E5} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer\skypeieplugin.dll
    DPF: {1E54D648-B804-468d-BC78-4AFFED8E262F} - hxxp://www.nvidia.com/content/DriverDownload/srl/3.0.0.4/srl_bin/sysreqlab_nvd.cab
    DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_24-windows-i586.cab
    DPF: {CAFEEFAC-0016-0000-0024-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_24-windows-i586.cab
    DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_24-windows-i586.cab
    TCP: DhcpNameServer = 192.168.1.254
    TCP: Interfaces\{234F1633-2877-42EC-819B-2D5A3BF1A546} : NameServer = 0.0.0.0
    TCP: Interfaces\{55BC3730-3C7B-4ED4-9FE1-DB7438253DC9} : DhcpNameServer = 192.168.1.254
    TCP: Interfaces\{55BC3730-3C7B-4ED4-9FE1-DB7438253DC9}\35B4952303031343 : DhcpNameServer = 192.168.0.1
    TCP: Interfaces\{B1321B63-E1DE-49CD-9F0C-C96DD716ECF2} : DhcpNameServer = 192.168.1.254
    Filter: text/xml - {807573E5-5146-11D5-A672-00B0D022E945} - C:\Program Files (x86)\Common Files\microsoft shared\OFFICE14\MSOXMLMF.DLL
    Handler: skype-ie-addon-data - {91774881-D725-4E58-B298-07617B9B86A8} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer\skypeieplugin.dll
    Handler: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~2\COMMON~1\Skype\SKYPE4~1.DLL
    Handler: wlpg - {E43EF6CD-A37A-4A9B-9E6F-83F89B8E6324} - C:\Program Files (x86)\Windows Live\Photo Gallery\AlbumDownloadProtocolHandler.dll
    AppInit_DLLs: C:\Windows\SysWOW64\nvinit.dll
    SEH: Groove GFS Stub Execution Hook: {b5a7f190-dda6-4420-b3ba-52453494e6cd} - C:\PROGRA~2\MICROS~1\Office14\GROOVEEX.DLL
    BHO-X64: Adobe PDF Link Helper: {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll
    BHO-X64: AcroIEHelperStub - No File
    BHO-X64: McAfee Phishing Filter: {27B4851A-3207-45A2-B947-BE8AFE6163AB} - c:\progra~1\mcafee\msk\mskapbho.dll
    BHO-X64: McAfee Phishing Filter - No File
    BHO-X64: Conduit Engine: {30F9B915-B755-4826-820B-08FBA6BD249D} - C:\Program Files (x86)\ConduitEngine\ConduitEngine.dll
    BHO-X64: Groove GFS Browser Helper: {72853161-30C5-4D22-B7F9-0BBC1D38A37E} - C:\PROGRA~2\MICROS~1\Office14\GROOVEEX.DLL
    BHO-X64: scriptproxy: {7DB2D5A0-7241-4E79-B68D-6309F01C5231} - C:\Program Files (x86)\Common Files\McAfee\SystemCore\ScriptSn.20110509193654.dll
    BHO-X64: scriptproxy - No File
    BHO-X64: avast! WebRep: {8E5E2654-AD2D-48bf-AC2D-D17F00898D06} - C:\Program Files\AVAST Software\Avast\aswWebRepIE.dll
    BHO-X64: Windows Live ID Sign-in Helper: {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files (x86)\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
    BHO-X64: Windows Live Messenger Companion Helper: {9FDDE16B-836F-4806-AB1F-1455CBEFF289} - C:\Program Files (x86)\Windows Live\Companion\companioncore.dll
    BHO-X64: Skype add-on for Internet Explorer: {AE805869-2E5C-4ED4-8F7B-F1F7851A4497} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer\skypeieplugin.dll
    BHO-X64: SkypeIEPluginBHO - No File
    BHO-X64: Office Document Cache Handler: {B4F3A835-0E21-4959-BA22-42B3008E02FF} - C:\PROGRA~2\MICROS~1\Office14\URLREDIR.DLL
    BHO-X64: URLRedirectionBHO - No File
    BHO-X64: Java(tm) Plug-In 2 SSV Helper: {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files (x86)\Java\jre6\bin\jp2ssv.dll
    TB-X64: Conduit Engine: {30F9B915-B755-4826-820B-08FBA6BD249D} - C:\Program Files (x86)\ConduitEngine\ConduitEngine.dll
    TB-X64: avast! WebRep: {8E5E2654-AD2D-48bf-AC2D-D17F00898D06} - C:\Program Files\AVAST Software\Avast\aswWebRepIE.dll
    TB-X64: {88C7F2AA-F93F-432C-8F0E-B7D85967A527} - No File
    TB-X64: {32099AAC-C132-4136-9E9A-4E364A424E17} - No File
    mRun-x64: [NUSB3MON] "c:\Program Files (x86)\Renesas Electronics\USB 3.0 Host Controller Driver\Application\nusb3mon.exe"
    mRun-x64: [Dell DataSafe Online] "C:\Program Files (x86)\Dell DataSafe Online\DataSafeOnline.exe" /m
    mRun-x64: [mcui_exe] "C:\Program Files\McAfee.com\Agent\mcagent.exe" /runkey
    mRun-x64: [Dell Webcam Central] "C:\Program Files (x86)\Dell Webcam\Dell Webcam Central\WebcamDell2.exe" /mode2
    mRun-x64: [RemoteControl9] "c:\Program Files (x86)\CyberLink\PowerDVD9\PDVD9Serv.exe"
    mRun-x64: [PDVD9LanguageShortcut] "c:\Program Files (x86)\CyberLink\PowerDVD9\Language\Language.exe"
    mRun-x64: [BDRegion] c:\Program Files (x86)\Cyberlink\Shared Files\brs.exe
    mRun-x64: [(Default)]
    mRun-x64: [RoxWatchTray] "C:\Program Files (x86)\Common Files\Roxio Shared\OEM\12.0\SharedCOM\RoxWatchTray12OEM.exe"
    mRun-x64: [DellSupportCenter] "C:\Program Files (x86)\Dell Support Center\bin\sprtcmd.exe" /P DellSupportCenter
    mRun-x64: [Desktop Disc Tool] "C:\Program Files (x86)\Roxio\oem\Roxio Burn\RoxioBurnLauncher.exe"
    mRun-x64: [SunJavaUpdateSched] "C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe"
    mRun-x64: [AppleSyncNotifier] C:\Program Files (x86)\Common Files\Apple\Mobile Device Support\AppleSyncNotifier.exe
    mRun-x64: [Adobe ARM] "C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe"
    mRun-x64: [Malwarebytes' Anti-Malware] "C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamgui.exe" /starttray
    mRun-x64: [avast] "C:\Program Files\AVAST Software\Avast\avastUI.exe" /nogui
    AppInit_DLLs-X64: C:\Windows\SysWOW64\nvinit.dll
    SEH-X64: Groove GFS Stub Execution Hook: {B5A7F190-DDA6-4420-B3BA-52453494E6CD} - C:\PROGRA~2\MICROS~1\Office14\GROOVEEX.DLL
    .
    ============= SERVICES / DRIVERS ===============
    .
    R0 mfehidk;McAfee Inc. mfehidk;C:\Windows\system32\drivers\mfehidk.sys --> C:\Windows\system32\drivers\mfehidk.sys [?]
    R0 mfewfpk;McAfee Inc. mfewfpk;C:\Windows\system32\drivers\mfewfpk.sys --> C:\Windows\system32\drivers\mfewfpk.sys [?]
    R0 nvpciflt;nvpciflt;C:\Windows\system32\DRIVERS\nvpciflt.sys --> C:\Windows\system32\DRIVERS\nvpciflt.sys [?]
    R0 PxHlpa64;PxHlpa64;C:\Windows\system32\Drivers\PxHlpa64.sys --> C:\Windows\system32\Drivers\PxHlpa64.sys [?]
    R0 stdcfltn;Disk Class Filter Driver for Accelerometer;C:\Windows\system32\DRIVERS\stdcfltn.sys --> C:\Windows\system32\DRIVERS\stdcfltn.sys [?]
    R1 aswSnx;aswSnx;C:\Windows\system32\drivers\aswSnx.sys --> C:\Windows\system32\drivers\aswSnx.sys [?]
    R1 aswSP;aswSP;C:\Windows\system32\drivers\aswSP.sys --> C:\Windows\system32\drivers\aswSP.sys [?]
    R1 mfenlfk;McAfee NDIS Light Filter;C:\Windows\system32\DRIVERS\mfenlfk.sys --> C:\Windows\system32\DRIVERS\mfenlfk.sys [?]
    R1 MpFilter;Microsoft Malware Protection Driver;C:\Windows\system32\DRIVERS\MpFilter.sys --> C:\Windows\system32\DRIVERS\MpFilter.sys [?]
    R1 vwififlt;Virtual WiFi Filter Driver;C:\Windows\system32\DRIVERS\vwififlt.sys --> C:\Windows\system32\DRIVERS\vwififlt.sys [?]
    R2 AdobeActiveFileMonitor8.0;Adobe Active File Monitor V8;C:\Program Files (x86)\Adobe\Elements Organizer 8.0\PhotoshopElementsFileAgent.exe [2009-9-18 169312]
    R2 AdobeARMservice;Adobe Acrobat Update Service;C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe [2011-6-6 64952]
    R2 AERTFilters;Andrea RT Filters Service;C:\Program Files\Realtek\Audio\HDA\AERTSr64.exe [2011-7-24 98208]
    R2 Akamai;Akamai NetSession Interface;C:\Windows\System32\svchost.exe -k Akamai [2009-7-14 20992]
    R2 aswFsBlk;aswFsBlk;C:\Windows\system32\drivers\aswFsBlk.sys --> C:\Windows\system32\drivers\aswFsBlk.sys [?]
    R2 aswMonFlt;aswMonFlt;\??\C:\Windows\system32\drivers\aswMonFlt.sys --> C:\Windows\system32\drivers\aswMonFlt.sys [?]
    R2 avast! Antivirus;avast! Antivirus;C:\Program Files\AVAST Software\Avast\AvastSvc.exe [2011-8-11 42184]
    R2 DockLoginService;Dock Login Service;C:\Program Files\Dell\DellDock\DockLogin.exe [2009-6-9 155648]
    R2 MBAMService;MBAMService;C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamservice.exe [2011-8-11 366640]
    R2 McMPFSvc;McAfee Personal Firewall Service;C:\Program Files\Common Files\mcafee\mcsvchost\McSvHost.exe [2011-1-6 355440]
    R2 McNaiAnn;McAfee VirusScan Announcer;C:\Program Files\Common Files\mcafee\mcsvchost\McSvHost.exe [2011-1-6 355440]
    R2 McProxy;McAfee Proxy Service;C:\Program Files\Common Files\mcafee\mcsvchost\McSvHost.exe [2011-1-6 355440]
    R2 McShield;McShield;C:\Program Files\Common Files\mcafee\systemcore\mcshield.exe [2011-1-3 200056]
    R2 mfefire;McAfee Firewall Core Service;C:\Program Files\Common Files\mcafee\systemcore\mfefire.exe [2011-1-3 245352]
    R2 mfevtp;McAfee Validation Trust Protection Service;C:\Program Files\Common Files\mcafee\systemcore\mfevtps.exe [2011-1-3 149032]
    R2 MyWiFiDHCPDNS;Wireless PAN DHCP Server;C:\Program Files\Intel\WiFi\bin\PanDhcpDns.exe [2010-3-5 340240]
    R2 nvUpdatusService;NVIDIA Update Service Daemon;C:\Program Files (x86)\NVIDIA Corporation\NVIDIA Updatus\daemonu.exe [2011-1-3 2214504]
    R2 SftService;SoftThinks Agent Service;C:\Program Files (x86)\Dell DataSafe Local Backup\SftService.exe [2011-1-3 705856]
    R2 Stereo Service;NVIDIA Stereoscopic 3D Driver Service;C:\Program Files (x86)\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe [2011-5-20 378472]
    R2 TurboB;Turbo Boost UI Monitor driver;C:\Windows\system32\DRIVERS\TurboB.sys --> C:\Windows\system32\DRIVERS\TurboB.sys [?]
    R2 UNS;Intel(R) Management & Security Application User Notification Service;C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\UNS\UNS.exe [2011-1-3 2533400]
    R3 Acceler;Accelerometer Service;C:\Windows\system32\DRIVERS\Accelern.sys --> C:\Windows\system32\DRIVERS\Accelern.sys [?]
    R3 cfwids;McAfee Inc. cfwids;C:\Windows\system32\drivers\cfwids.sys --> C:\Windows\system32\drivers\cfwids.sys [?]
    R3 CtClsFlt;Creative Camera Class Upper Filter Driver;C:\Windows\system32\DRIVERS\CtClsFlt.sys --> C:\Windows\system32\DRIVERS\CtClsFlt.sys [?]
    R3 HECIx64;Intel(R) Management Engine Interface;C:\Windows\system32\DRIVERS\HECIx64.sys --> C:\Windows\system32\DRIVERS\HECIx64.sys [?]
    R3 Impcd;Impcd;C:\Windows\system32\DRIVERS\Impcd.sys --> C:\Windows\system32\DRIVERS\Impcd.sys [?]
    R3 IntcDAud;Intel(R) Display Audio;C:\Windows\system32\DRIVERS\IntcDAud.sys --> C:\Windows\system32\DRIVERS\IntcDAud.sys [?]
    R3 MBAMProtector;MBAMProtector;\??\C:\Windows\system32\drivers\mbam.sys --> C:\Windows\system32\drivers\mbam.sys [?]
    R3 mfeavfk;McAfee Inc. mfeavfk;C:\Windows\system32\drivers\mfeavfk.sys --> C:\Windows\system32\drivers\mfeavfk.sys [?]
    R3 mfefirek;McAfee Inc. mfefirek;C:\Windows\system32\drivers\mfefirek.sys --> C:\Windows\system32\drivers\mfefirek.sys [?]
    R3 NETw5s64;Intel(R) Wireless WiFi Link 5000 Series Adapter Driver for Windows 7 - 64 Bit;C:\Windows\system32\DRIVERS\NETw5s64.sys --> C:\Windows\system32\DRIVERS\NETw5s64.sys [?]
    R3 nusb3hub;Renesas Electronics USB 3.0 Hub Driver;C:\Windows\system32\DRIVERS\nusb3hub.sys --> C:\Windows\system32\DRIVERS\nusb3hub.sys [?]
    R3 nusb3xhc;Renesas Electronics USB 3.0 Host Controller Driver;C:\Windows\system32\DRIVERS\nusb3xhc.sys --> C:\Windows\system32\DRIVERS\nusb3xhc.sys [?]
    R3 qicflt;upper Device Filter Driver;C:\Windows\system32\DRIVERS\qicflt.sys --> C:\Windows\system32\DRIVERS\qicflt.sys [?]
    R3 RTL8167;Realtek 8167 NT Driver;C:\Windows\system32\DRIVERS\Rt64win7.sys --> C:\Windows\system32\DRIVERS\Rt64win7.sys [?]
    R3 vwifimp;Microsoft Virtual WiFi Miniport Service;C:\Windows\system32\DRIVERS\vwifimp.sys --> C:\Windows\system32\DRIVERS\vwifimp.sys [?]
    R3 wdkmd;Intel WiDi KMD;C:\Windows\system32\DRIVERS\WDKMD.sys --> C:\Windows\system32\DRIVERS\WDKMD.sys [?]
    S2 CLKMSVC10_9EC60124;CyberLink Product - 2011/01/03 15:47:59;C:\Program Files (x86)\CyberLink\PowerDVD9\NavFilter\kmsvc.exe [2010-9-29 254448]
    S2 clr_optimization_v4.0.30319_32;Microsoft .NET Framework NGEN v4.0.30319_X86;C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe [2010-3-18 130384]
    S2 clr_optimization_v4.0.30319_64;Microsoft .NET Framework NGEN v4.0.30319_X64;C:\Windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe [2010-3-18 138576]
    S2 gupdate;Google Update Service (gupdate);C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2011-3-12 136176]
    S2 RoxWatch12;Roxio Hard Drive Watcher 12;C:\Program Files (x86)\Common Files\Roxio Shared\OEM\12.0\SharedCOM\RoxWatch12OEM.exe [2010-9-4 219632]
    S3 AllShare;SAMSUNG AllShare Service;C:\Program Files (x86)\Samsung\SAMSUNG PC Share Manager\WiselinkPro.exe [2010-7-16 6638080]
    S3 fssfltr;fssfltr;C:\Windows\system32\DRIVERS\fssfltr.sys --> C:\Windows\system32\DRIVERS\fssfltr.sys [?]
    S3 fsssvc;Windows Live Family Safety Service;C:\Program Files (x86)\Windows Live\Family Safety\fsssvc.exe [2011-5-13 1492840]
    S3 gupdatem;Google Update Service (gupdatem);C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2011-3-12 136176]
    S3 JMCR;JMCR;C:\Windows\system32\DRIVERS\jmcr.sys --> C:\Windows\system32\DRIVERS\jmcr.sys [?]
    S3 mferkdet;McAfee Inc. mferkdet;C:\Windows\system32\drivers\mferkdet.sys --> C:\Windows\system32\drivers\mferkdet.sys [?]
    S3 Microsoft SharePoint Workspace Audit Service;Microsoft SharePoint Workspace Audit Service;C:\Program Files\Microsoft Office\Office14\GROOVE.EXE [2010-3-25 51456888]
    S3 MpNWMon;Microsoft Malware Protection Network Driver;C:\Windows\system32\DRIVERS\MpNWMon.sys --> C:\Windows\system32\DRIVERS\MpNWMon.sys [?]
    S3 NisDrv;Microsoft Network Inspection System;C:\Windows\system32\DRIVERS\NisDrvWFP.sys --> C:\Windows\system32\DRIVERS\NisDrvWFP.sys [?]
    S3 NisSrv;Microsoft Network Inspection;C:\Program Files\Microsoft Security Client\Antimalware\NisSrv.exe [2011-4-27 288272]
    S3 nmwcdnsucx64;Nokia USB Flashing Generic;C:\Windows\system32\drivers\nmwcdnsucx64.sys --> C:\Windows\system32\drivers\nmwcdnsucx64.sys [?]
    S3 nmwcdnsux64;Nokia USB Flashing Phone Parent;C:\Windows\system32\drivers\nmwcdnsux64.sys --> C:\Windows\system32\drivers\nmwcdnsux64.sys [?]
    S3 NVHDA;Service for NVIDIA High Definition Audio Driver;C:\Windows\system32\drivers\nvhda64v.sys --> C:\Windows\system32\drivers\nvhda64v.sys [?]
    S3 ose64;Office 64 Source Engine;C:\Program Files\Common Files\Microsoft Shared\Source Engine\OSE.EXE [2010-1-9 174440]
    S3 osppsvc;Office Software Protection Platform;C:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPSVC.EXE [2010-1-9 4925184]
    S3 RoxMediaDB12OEM;RoxMediaDB12OEM;C:\Program Files (x86)\Common Files\Roxio Shared\OEM\12.0\SharedCOM\RoxMediaDB12OEM.exe [2010-9-4 1116656]
    S3 TsUsbFlt;TsUsbFlt;C:\Windows\system32\drivers\tsusbflt.sys --> C:\Windows\system32\drivers\tsusbflt.sys [?]
    S3 TurboBoost;TurboBoost;C:\Program Files\Intel\TurboBoost\TurboBoost.exe [2009-11-2 126352]
    S3 USBAAPL64;Apple Mobile USB Driver;C:\Windows\system32\Drivers\usbaapl64.sys --> C:\Windows\system32\Drivers\usbaapl64.sys [?]
    S3 WatAdminSvc;Windows Activation Technologies Service;C:\Windows\system32\Wat\WatAdminSvc.exe --> C:\Windows\system32\Wat\WatAdminSvc.exe [?]
    S4 McOobeSv;McAfee OOBE Service;C:\Program Files\Common Files\mcafee\mcsvchost\McSvHost.exe [2011-1-6 355440]
    S4 wlcrasvc;Windows Live Mesh remote connections service;C:\Program Files\Windows Live\Mesh\wlcrasvc.exe [2010-9-23 57184]
    .
    =============== Created Last 30 ================
    .
    2011-08-13 17:45:41 -------- d-----w- C:\Program Files (x86)\ESET
    2011-08-13 17:17:19 -------- d-----w- C:\_OTL
    2011-08-13 16:22:43 98816 ----a-w- C:\Windows\sed.exe
    2011-08-13 16:22:43 518144 ----a-w- C:\Windows\SWREG.exe
    2011-08-13 16:22:43 256000 ----a-w- C:\Windows\PEV.exe
    2011-08-13 16:22:43 208896 ----a-w- C:\Windows\MBR.exe
    2011-08-13 16:22:31 -------- d-s---w- C:\ComboFix
    2011-08-13 14:15:28 -------- d-----w- C:\Windows\SysWow64\syncdb
    2011-08-13 13:29:53 -------- d-----w- C:\Users\ChrisKelly\AppData\Roaming\com.adobe.bridge.PublishPanel
    2011-08-13 11:02:22 -------- d-----w- C:\Users\ChrisKelly\AppData\Local\{A15869AB-370D-45E9-9BA4-830D0B60C46A}
    2011-08-13 11:01:54 -------- d-----w- C:\Users\ChrisKelly\AppData\Local\{C3E3490B-45B7-44E4-8523-039C76E87E5F}
    2011-08-12 23:01:34 -------- d-----w- C:\Users\ChrisKelly\AppData\Local\{11AF0D52-8B02-4665-A5FB-8DA6FEA8B457}
    2011-08-12 23:01:05 -------- d-----w- C:\Users\ChrisKelly\AppData\Local\{BA96ADF2-2922-4FB1-B019-F0ED7CE519C7}
    2011-08-12 11:34:56 -------- d-----w- C:\Users\ChrisKelly\AppData\Local\CrashDumps
    2011-08-12 11:00:22 -------- d-----w- C:\Users\ChrisKelly\AppData\Local\{F50A37C0-2B14-4A35-BC3D-184EE96DAAF8}
    2011-08-12 11:00:08 -------- d-----w- C:\Users\ChrisKelly\AppData\Local\{058775DA-A44D-414E-A1C8-F657BAD5EA0F}
    2011-08-12 10:14:19 -------- d-----w- C:\Users\ChrisKelly\AppData\Local\{8DF63ECE-A14E-42F3-BE4B-491C1940DC54}
    2011-08-12 07:09:30 834544 ----a-w- C:\Windows\System32\drivers\sptd.sys
    2011-08-12 07:08:12 -------- d-----w- C:\Program Files (x86)\DAEMON Tools Lite
    2011-08-12 07:07:44 -------- d-----w- C:\Users\ChrisKelly\AppData\Roaming\DAEMON Tools Lite
    2011-08-12 07:07:38 -------- d-----w- C:\ProgramData\DAEMON Tools Lite
    2011-08-11 22:02:09 600920 ----a-w- C:\Windows\System32\drivers\aswSnx.sys
    2011-08-11 22:02:06 64856 ----a-w- C:\Windows\System32\drivers\aswMonFlt.sys
    2011-08-11 22:01:39 40112 ----a-w- C:\Windows\avastSS.scr
    2011-08-11 22:01:30 -------- d-----w- C:\ProgramData\AVAST Software
    2011-08-11 22:01:30 -------- d-----w- C:\Program Files\AVAST Software
    2011-08-11 21:54:33 -------- d-----w- C:\Program Files (x86)\Microsoft Security Client
    2011-08-11 21:51:18 -------- d-----w- C:\Users\ChrisKelly\AppData\Roaming\Malwarebytes
    2011-08-11 21:51:11 41272 ----a-w- C:\Windows\SysWow64\drivers\mbamswissarmy.sys
    2011-08-11 21:51:11 -------- d-----w- C:\ProgramData\Malwarebytes
    2011-08-11 21:51:08 25912 ----a-w- C:\Windows\System32\drivers\mbam.sys
    2011-08-11 21:51:08 -------- d-----w- C:\Program Files (x86)\Malwarebytes' Anti-Malware
    2011-08-11 21:19:07 -------- d-----w- C:\Users\ChrisKelly\AppData\Local\NPE
    2011-08-11 20:38:29 -------- d-----w- C:\ProgramData\STOPzilla!
    2011-08-11 20:27:29 270720 ------w- C:\Windows\System32\MpSigStub.exe
    2011-08-11 20:26:05 -------- d-----w- C:\Users\ChrisKelly\AppData\Local\{DCD268D2-D23B-4A1E-BF71-D61EEC627B53}
    2011-08-11 20:25:54 -------- d-----w- C:\Users\ChrisKelly\AppData\Local\{C06AE9F9-51D0-4FBF-8F8C-415D2353D409}
    2011-08-11 20:18:24 222080 ------w- C:\Windows\SysWow64\MpSigStub.exe
    2011-08-11 20:06:05 -------- d-----w- C:\Windows\en
    2011-08-11 19:59:28 15712 ----a-w- C:\Program Files (x86)\Common Files\Windows Live\.cache\2d6cb0f01cc586101\MeshBetaRemover.exe
    2011-08-11 19:54:40 -------- d-----w- C:\Users\ChrisKelly\AppData\Local\{1CB8A32A-BE99-4F16-8BF2-DF49E94476EB}
    2011-08-11 18:22:15 -------- d-----w- C:\Users\ChrisKelly\AppData\Local\{95A6671A-0076-445F-B877-B0AD61E0A68D}
    2011-08-11 18:11:51 -------- d-----w- C:\Program Files\Microsoft Security Client
    2011-08-11 17:16:55 -------- d-----w- C:\Users\ChrisKelly\AppData\Local\{2B3089BA-37B7-4CCF-823D-2451BED4B9D5}
    2011-08-10 22:14:44 -------- d-----w- C:\Users\ChrisKelly\AppData\Local\{2910535B-769F-4983-A106-720C6BF7CA8D}
    2011-08-10 21:49:12 -------- d-----w- C:\Users\ChrisKelly\AppData\Local\{8F69AA20-3514-4C6A-82A3-6DC00B9B1D67}
    2011-08-10 21:49:00 -------- d-----w- C:\Users\ChrisKelly\AppData\Local\{FC11D363-41B4-451A-85D2-5F2DC55BE50E}
    2011-08-10 21:08:54 -------- d-----w- C:\Users\ChrisKelly\AppData\Local\{F3572E0C-3C18-4DF1-BF65-A7E75D661DCE}
    2011-08-10 20:46:20 -------- d-----w- C:\Users\ChrisKelly\AppData\Local\{BDE58863-A108-497F-ADE5-F53D54DF4519}
    2011-08-10 17:10:52 -------- d-----w- C:\Users\ChrisKelly\AppData\Local\ElevatedDiagnostics
    2011-08-09 21:39:06 107520 --sha-r- C:\Windows\SysWow64\usbperfv.dll
    2011-08-09 21:19:52 -------- d-----w- C:\Users\ChrisKelly\AppData\Local\{8260C918-81F5-466D-93AC-EC0B27AFC3C0}
    2011-08-09 20:26:47 -------- d-----w- C:\Program Files (x86)\My Company Name
    2011-08-09 19:12:11 -------- d-----w- C:\Users\ChrisKelly\AppData\Local\{031997CF-4C8C-468C-8B1A-3535D1A560E3}
    2011-08-08 18:36:54 -------- d-----w- C:\Users\ChrisKelly\AppData\Local\{F4762BC0-C24E-4EC6-BA6E-662101B2EFA3}
    2011-08-07 10:12:29 -------- d-----w- C:\Users\ChrisKelly\AppData\Roaming\inkscape
    2011-08-07 07:55:43 -------- d-----w- C:\Program Files (x86)\Inkscape
    2011-08-05 21:03:56 2301208 ----a-w- C:\ProgramData\Microsoft\eHome\Packages\MCEClientUX\UpdateableMarkup-2\markup.dll
    2011-08-05 21:03:37 42776 ----a-w- C:\ProgramData\Microsoft\eHome\Packages\MCEClientUX\dSM-2\StartResources.dll
    2011-08-05 21:03:34 710976 ----a-w- C:\ProgramData\Microsoft\eHome\Packages\MCESpotlight\MCESpotlight-2\SpotlightResources.dll
    2011-08-05 20:43:10 -------- d-----w- C:\Users\ChrisKelly\AppData\Local\{EC40DF01-6233-467F-81A3-64EF206BAE80}
    2011-08-05 16:44:01 -------- d-----w- C:\Users\ChrisKelly\AppData\Local\{573D09D3-573F-45EC-8E17-A54572E714AA}
    2011-08-04 18:07:41 -------- d-----w- C:\Users\ChrisKelly\AppData\Local\{3867CFF6-1BDB-4C22-9956-3A8067342375}
    2011-08-03 20:54:14 -------- d-----w- C:\Users\ChrisKelly\AppData\Local\{9B7ABB8D-A7F6-44D8-8774-55F7004D701B}
    2011-08-02 19:32:43 -------- d-----w- C:\Users\ChrisKelly\AppData\Local\{9CC13EE6-8B85-4D04-9056-0150E62BD62B}
    2011-08-01 19:13:48 -------- d-----w- C:\Users\ChrisKelly\AppData\Local\{3BBC427C-0506-4E80-ADC9-884A8D63FA6A}
    2011-07-31 09:30:58 -------- d-----w- C:\Users\ChrisKelly\AppData\Local\{21DCF44D-3906-4B72-9C41-7683DBBD14C6}
    2011-07-30 20:00:22 -------- d-----w- C:\Users\ChrisKelly\AppData\Local\{190BA493-66CB-4D76-925C-B8E8E879DB28}
    2011-07-30 06:26:57 -------- d-----w- C:\Users\ChrisKelly\AppData\Local\{EE159C3B-EE23-4288-B2E0-921D80FC5036}
    2011-07-29 16:18:35 -------- d-----w- C:\Users\ChrisKelly\AppData\Local\{4596549E-028A-428C-B49C-7A62000B3DF3}
    2011-07-28 17:30:37 -------- d-----w- C:\Users\ChrisKelly\AppData\Local\{1DD7E945-F00F-4BA5-AC59-F165C048340F}
    2011-07-27 17:52:11 -------- d-----w- C:\Users\ChrisKelly\AppData\Local\{BC5D1014-1E7C-452B-892F-4A967DDD5CB3}
    2011-07-26 18:51:31 -------- d-----w- C:\Users\ChrisKelly\AppData\Local\{55ACB40A-7B70-4E44-BAA1-F6A567B1FC04}
    2011-07-25 05:51:35 -------- d-----w- C:\Users\ChrisKelly\AppData\Local\{440542D5-4BA3-4EA0-A62C-CA5397A369EE}
    2011-07-24 18:21:46 -------- d-----w- C:\Windows\System32\SRSLabs
    2011-07-24 18:21:40 -------- d-----w- C:\Windows\SysWow64\RTCOM
    2011-07-24 18:20:13 2604376 ----a-w- C:\Windows\System32\WavesGUILib.dll
    2011-07-24 18:20:09 155888 ----a-w- C:\Windows\System32\SRSWOW64.dll
    2011-07-24 18:20:08 518896 ----a-w- C:\Windows\System32\SRSTSX64.dll
    2011-07-24 18:20:08 211184 ----a-w- C:\Windows\System32\SRSTSH64.dll
    2011-07-24 18:20:06 198896 ----a-w- C:\Windows\System32\SRSHP64.dll
    2011-07-24 18:20:00 2432104 ----a-w- C:\Windows\System32\RtPgEx64.dll
    2011-07-24 18:20:00 1560168 ----a-w- C:\Windows\System32\RTSnMg64.cpl
    2011-07-24 18:18:21 5632 ----a-w- C:\Program Files (x86)\Common Files\InstallShield\Professional\RunTime\11\50\Intel32\DotNetInstaller.exe
    2011-07-24 18:15:40 -------- d-----w- C:\Program Files (x86)\Realtek
    2011-07-24 17:30:06 404640 ----a-w- C:\Windows\SysWow64\FlashPlayerCPLApp.cpl
    2011-07-24 17:21:08 29288 ----a-w- C:\Windows\System32\nvhdap64.dll
    2011-07-24 17:21:08 174184 ----a-w- C:\Windows\System32\drivers\nvhda64v.sys
    2011-07-24 17:21:08 1426536 ----a-w- C:\Windows\System32\nvhdagenco642040.dll
    2011-07-24 17:21:01 8863336 ----a-w- C:\Windows\System32\nvwgf2umx.dll
    2011-07-24 17:21:01 833640 ----a-w- C:\Windows\System32\nvumdshimx.dll
    2011-07-24 17:21:01 67176 ----a-w- C:\Windows\System32\OpenCL.dll
    2011-07-24 17:21:01 6555240 ----a-w- C:\Windows\SysWow64\nvwgf2um.dll
    2011-07-24 17:21:01 57960 ----a-w- C:\Windows\SysWow64\OpenCL.dll
    2011-07-24 17:21:01 366696 ----a-w- C:\Windows\System32\nvoptimusmft.dll
    2011-07-24 17:21:01 326248 ----a-w- C:\Windows\SysWow64\nvoptimusmft.dll
    2011-07-24 17:21:01 27240 ----a-w- C:\Windows\System32\drivers\nvpciflt.sys
    2011-07-24 17:21:00 22286952 ----a-w- C:\Windows\System32\nvoglv64.dll
    2011-07-24 17:14:04 -------- d-----w- C:\NVIDIA
    2011-07-24 17:10:34 -------- d-----w- C:\Program Files (x86)\SystemRequirementsLab
    2011-07-24 10:05:00 -------- d-----w- C:\Users\ChrisKelly\AppData\Local\{70EA3986-9B04-48ED-8AD8-8488D76A5D88}
    2011-07-23 21:05:34 -------- d-----w- C:\Users\ChrisKelly\AppData\Local\{17C85D2B-FDFE-4DBF-8790-8128FA145E95}
    2011-07-23 07:31:27 -------- d-----w- C:\Users\ChrisKelly\AppData\Local\{44B74C2B-C780-437E-A6D6-DD9198DFD3DE}
    2011-07-21 18:25:43 -------- d-----w- C:\Users\ChrisKelly\AppData\Local\{D9511B11-DCF6-4CC1-917F-ECDA45BA0341}
    2011-07-20 17:13:47 -------- d-----w- C:\Users\ChrisKelly\AppData\Local\{8B35CB5F-281F-44AC-A83E-46426D124D60}
    2011-07-18 18:22:10 -------- d-----w- C:\Users\ChrisKelly\AppData\Local\{5FA9C6BA-B19D-48CE-886C-B529079FA8AD}
    2011-07-16 09:12:31 -------- d-----w- C:\Users\ChrisKelly\AppData\Local\{11C59351-71B3-4004-82A8-D4315162E730}
    2011-07-15 14:38:29 -------- d-----w- C:\ProgramData\Nokia
    2011-07-15 14:26:44 -------- d-----w- C:\Program Files (x86)\Common Files\PCSuite
    2011-07-15 14:26:40 -------- d-----w- C:\Program Files (x86)\Common Files\Nokia
    2011-07-15 14:26:15 25600 ----a-w- C:\Windows\System32\drivers\pccsmcfdx64.sys
    2011-07-15 14:26:02 -------- d-----w- C:\Program Files (x86)\PC Connectivity Solution
    2011-07-15 14:25:48 57856 ----a-w- C:\Windows\System32\nmwcdclsX64.dll
    2011-07-15 14:25:48 -------- d-----w- C:\Program Files (x86)\Nokia
    2011-07-15 06:11:20 -------- d-----w- C:\Users\ChrisKelly\AppData\Local\{14A73E04-A792-4A07-81C7-C8133B46FBB1}
    .
    ==================== Find3M ====================
    .
    2011-07-22 05:22:26 1638912 ----a-w- C:\Windows\System32\mshtml.tlb
    2011-07-22 04:54:18 1638912 ----a-w- C:\Windows\SysWow64\mshtml.tlb
    2011-07-16 05:41:50 362496 ----a-w- C:\Windows\System32\wow64win.dll
    2011-07-16 05:41:49 243200 ----a-w- C:\Windows\System32\wow64.dll
    2011-07-16 05:41:49 13312 ----a-w- C:\Windows\System32\wow64cpu.dll
    2011-07-16 05:39:10 16384 ----a-w- C:\Windows\System32\ntvdm64.dll
    2011-07-16 05:37:12 421888 ----a-w- C:\Windows\System32\KernelBase.dll
    2011-07-16 04:29:19 14336 ----a-w- C:\Windows\SysWow64\ntvdm64.dll
    2011-07-16 04:26:00 44032 ----a-w- C:\Windows\apppatch\acwow64.dll
    2011-07-16 04:25:37 25600 ----a-w- C:\Windows\SysWow64\setup16.exe
    2011-07-16 04:24:23 5120 ----a-w- C:\Windows\SysWow64\wow32.dll
    2011-07-16 04:24:22 272384 ----a-w- C:\Windows\SysWow64\KernelBase.dll
    2011-07-16 02:21:44 7680 ----a-w- C:\Windows\SysWow64\instnm.exe
    2011-07-16 02:21:41 2048 ----a-w- C:\Windows\SysWow64\user.exe
    2011-07-16 02:17:19 6144 ---ha-w- C:\Windows\SysWow64\api-ms-win-security-base-l1-1-0.dll
    2011-07-16 02:17:19 4608 ---ha-w- C:\Windows\SysWow64\api-ms-win-core-threadpool-l1-1-0.dll
    2011-07-16 02:17:19 3584 ---ha-w- C:\Windows\SysWow64\api-ms-win-core-xstate-l1-1-0.dll
    2011-07-16 02:17:19 3072 ---ha-w- C:\Windows\SysWow64\api-ms-win-core-util-l1-1-0.dll
    2011-07-11 13:17:00 1698408 ----a-w- C:\Windows\RtlExUpd.dll
    2011-07-09 02:46:28 288768 ----a-w- C:\Windows\System32\drivers\mrxsmb10.sys
    2011-07-07 16:39:06 2914408 ----a-w- C:\Windows\System32\drivers\RTKVHD64.sys
    2011-07-07 14:50:08 1483264 ----a-w- C:\Windows\System32\RCORES64.dat
    2011-07-06 20:42:46 3148904 ----a-w- C:\Windows\System32\RtkAPO64.dll
    2011-07-06 12:27:00 92264 ----a-w- C:\Windows\System32\RCoInst64.dll
    2011-07-01 13:27:46 152576 ----a-w- C:\Windows\SysWow64\msclmd.dll
    2011-07-01 13:27:45 175616 ----a-w- C:\Windows\System32\msclmd.dll
    2011-07-01 13:05:42 1822824 ----a-w- C:\Windows\System32\RtkApi64.dll
    2011-06-27 13:45:00 3768152 ----a-w- C:\Windows\System32\MaxxAudioRealtek.dll
    2011-06-24 05:34:53 214528 ----a-w- C:\Windows\System32\winsrv.dll
    2011-06-24 05:25:49 338432 ----a-w- C:\Windows\System32\conhost.exe
    2011-06-23 05:43:12 5561216 ----a-w- C:\Windows\System32\ntoskrnl.exe
    2011-06-23 04:33:57 3967872 ----a-w- C:\Windows\SysWow64\ntkrnlpa.exe
    2011-06-23 04:33:57 3912576 ----a-w- C:\Windows\SysWow64\ntoskrnl.exe
    2011-06-21 06:34:00 1923968 ----a-w- C:\Windows\System32\drivers\tcpip.sys
    2011-06-21 06:20:53 1188864 ----a-w- C:\Windows\System32\wininet.dll
    2011-06-21 05:28:33 981504 ----a-w- C:\Windows\SysWow64\wininet.dll
    2011-06-15 10:02:23 212992 ----a-w- C:\Windows\System32\odbctrac.dll
    2011-06-15 10:02:23 163840 ----a-w- C:\Windows\System32\odbccp32.dll
    2011-06-15 10:02:23 106496 ----a-w- C:\Windows\System32\odbccu32.dll
    2011-06-15 10:02:23 106496 ----a-w- C:\Windows\System32\odbccr32.dll
    2011-06-15 08:55:19 86016 ----a-w- C:\Windows\SysWow64\odbccu32.dll
    2011-06-15 08:55:19 81920 ----a-w- C:\Windows\SysWow64\odbccr32.dll
    2011-06-15 08:55:19 319488 ----a-w- C:\Windows\SysWow64\odbcjt32.dll
    2011-06-15 08:55:19 163840 ----a-w- C:\Windows\SysWow64\odbctrac.dll
    2011-06-15 08:55:19 122880 ----a-w- C:\Windows\SysWow64\odbccp32.dll
    2011-06-14 19:35:32 625752 ----a-w- C:\Windows\System32\MBTHX64.dll
    2011-06-14 19:35:16 561240 ----a-w- C:\Windows\SysWow64\MBTHX32.dll
    2011-06-11 03:07:25 3137536 ----a-w- C:\Windows\System32\win32k.sys
    2011-05-31 08:42:06 728680 ----a-w- C:\Windows\System32\DTSBassEnhancementDLL64.dll
    2011-05-31 08:42:06 712296 ----a-w- C:\Windows\System32\DTSSymmetryDLL64.dll
    2011-05-31 08:42:06 693352 ----a-w- C:\Windows\System32\DTSVoiceClarityDLL64.dll
    2011-05-31 08:42:06 491112 ----a-w- C:\Windows\System32\DTSNeoPCDLL64.dll
    2011-05-31 08:42:06 432744 ----a-w- C:\Windows\System32\DTSLimiterDLL64.dll
    2011-05-31 08:42:06 428648 ----a-w- C:\Windows\System32\DTSGainCompensatorDLL64.dll
    2011-05-31 08:42:06 242792 ----a-w- C:\Windows\System32\DTSLFXAPO64.dll
    2011-05-31 08:42:06 242792 ----a-w- C:\Windows\System32\DTSGFXAPO64.dll
    2011-05-31 08:42:06 241768 ----a-w- C:\Windows\System32\DTSGFXAPONS64.dll
    2011-05-31 08:42:06 1756264 ----a-w- C:\Windows\System32\DTSS2SpeakerDLL64.dll
    2011-05-31 08:42:06 1568360 ----a-w- C:\Windows\System32\DTSS2HeadphoneDLL64.dll
    2011-05-31 08:42:06 1486952 ----a-w- C:\Windows\System32\DTSBoostDLL64.dll
    2011-05-24 11:42:55 404480 ----a-w- C:\Windows\System32\umpnpmgr.dll
    2011-05-24 10:40:05 64512 ----a-w- C:\Windows\SysWow64\devobj.dll
    2011-05-24 10:40:05 44544 ----a-w- C:\Windows\SysWow64\devrtl.dll
    2011-05-24 10:39:38 145920 ----a-w- C:\Windows\SysWow64\cfgmgr32.dll
    2011-05-24 10:37:54 252928 ----a-w- C:\Windows\SysWow64\drvinst.exe
    2011-05-23 16:12:36 1245288 ----a-w- C:\Windows\System32\RTCOM64.dll
    2011-05-20 21:35:28 304744 ----a-w- C:\Windows\SysWow64\nvStreaming.exe
    2011-05-18 09:15:26 166912 ----a-w- C:\Windows\System32\ccdcmbwux64.dll
    2011-05-18 09:15:16 640000 ----a-w- C:\Windows\System32\nmwcdcoclsx64.dll
    2011-05-18 09:14:22 9216 ----a-w- C:\Windows\System32\drivers\usbser_lowerfltjx64.sys
    2011-05-18 09:14:20 9216 ----a-w- C:\Windows\System32\drivers\usbser_lowerfltx64.sys
    2011-05-18 09:14:16 27136 ----a-w- C:\Windows\System32\drivers\ccdcmbox64.sys
    2011-05-18 09:14:12 19968 ----a-w- C:\Windows\System32\drivers\ccdcmbx64.sys
    2011-05-18 09:09:48 171008 ----a-w- C:\Windows\System32\drivers\nmwcdnsux64.sys
    2011-05-18 09:09:48 12800 ----a-w- C:\Windows\System32\drivers\nmwcdnsucx64.sys
    .
    ============= FINISH: 23:25:16.22 ===============


    .
     
  2. Gefstar

    Gefstar TS Rookie Topic Starter

    Cont'd

    UNLESS SPECIFICALLY INSTRUCTED, DO NOT POST THIS LOG.
    IF REQUESTED, ZIP IT UP & ATTACH IT
    .
    DDS (Ver_2011-06-23.01)
    .
    Microsoft Windows 7 Home Premium
    Boot Device: \Device\HarddiskVolume2
    Install Date: 06/01/2011 18:06:17
    System Uptime: 13/08/2011 18:28:47 (5 hours ago)
    .
    Motherboard: Dell Inc. | | 0V2WG4
    Processor: Intel(R) Core(TM) i5 CPU M 560 @ 2.67GHz | U2E1 | 1306/133mhz
    .
    ==== Disk Partitions =========================
    .
    C: is FIXED (NTFS) - 451 GiB total, 166.086 GiB free.
    D: is FIXED (NTFS) - 466 GiB total, 458.307 GiB free.
    E: is CDROM ()
    H: is CDROM ()
    .
    ==== Disabled Device Manager Items =============
    .
    Class GUID: {4d36e972-e325-11ce-bfc1-08002be10318}
    Description: Microsoft 6to4 Adapter
    Device ID: ROOT\*6TO4MP\0000
    Manufacturer: Microsoft
    Name: Microsoft 6to4 Adapter
    PNP Device ID: ROOT\*6TO4MP\0000
    Service: tunnel
    .
    Class GUID: {4d36e972-e325-11ce-bfc1-08002be10318}
    Description: Microsoft ISATAP Adapter
    Device ID: ROOT\*ISATAP\0000
    Manufacturer: Microsoft
    Name: Microsoft ISATAP Adapter #2
    PNP Device ID: ROOT\*ISATAP\0000
    Service: tunnel
    .
    Class GUID: {4d36e972-e325-11ce-bfc1-08002be10318}
    Description: Microsoft ISATAP Adapter
    Device ID: ROOT\*ISATAP\0001
    Manufacturer: Microsoft
    Name: Microsoft ISATAP Adapter
    PNP Device ID: ROOT\*ISATAP\0001
    Service: tunnel
    .
    Class GUID: {4d36e972-e325-11ce-bfc1-08002be10318}
    Description: Microsoft ISATAP Adapter
    Device ID: ROOT\*ISATAP\0002
    Manufacturer: Microsoft
    Name: Microsoft ISATAP Adapter #3
    PNP Device ID: ROOT\*ISATAP\0002
    Service: tunnel
    .
    Class GUID: {4d36e972-e325-11ce-bfc1-08002be10318}
    Description: Microsoft ISATAP Adapter
    Device ID: ROOT\*ISATAP\0003
    Manufacturer: Microsoft
    Name: Microsoft ISATAP Adapter #4
    PNP Device ID: ROOT\*ISATAP\0003
    Service: tunnel
    .
    Class GUID: {4d36e972-e325-11ce-bfc1-08002be10318}
    Description: Microsoft Teredo Tunneling Adapter
    Device ID: ROOT\*TEREDO\0001
    Manufacturer: Microsoft
    Name: Teredo Tunneling Pseudo-Interface
    PNP Device ID: ROOT\*TEREDO\0001
    Service: tunnel
    .
    ==== System Restore Points ===================
    .
    RP107: 11/08/2011 20:58:46 - CheckIfInstallerIsBusy
    RP108: 11/08/2011 20:59:26 - Windows Live Essentials
    RP109: 11/08/2011 21:01:12 - Installed DirectX
    RP110: 11/08/2011 21:01:30 - Installed DirectX
    RP111: 11/08/2011 21:02:37 - WLSetup
    RP112: 11/08/2011 21:11:49 - Windows Update
    RP113: 11/08/2011 21:37:11 - Installed STOPzilla. Available with Windows Installer version 1.2 and later.
    RP115: 11/08/2011 22:27:58 - Norton_Power_Eraser_20110811222753133
    RP116: 11/08/2011 23:00:39 - avast! Free Antivirus Setup
    RP118: 12/08/2011 08:08:47 - SPTD setup V1.62
    RP119: 12/08/2011 08:17:16 - Removed STOPzilla. Available with Windows Installer version 1.2 and later.
    RP120: 13/08/2011 15:08:05 - Removed Adobe Photoshop Elements 9.
    RP121: 13/08/2011 15:29:01 - Removed Bonjour
    RP122: 13/08/2011 15:29:38 - Removed Rosetta Stone Version 3
    RP123: 13/08/2011 17:59:22 - OTL Restore Point - 8/13/2011 5:59:15 PM
    .
    ==== Installed Programs ======================
    .
    AccelerometerP11
    Adobe Community Help
    Adobe Flash Player 10 ActiveX
    Adobe Flash Player 10 Plugin
    Adobe Media Player
    Adobe Photoshop Elements 8.0
    Adobe Reader X (10.1.0)
    Advanced Audio FX Engine
    AGT Pro
    Akamai NetSession Interface
    Amazon MP3 Downloader 1.0.9
    Apple Application Support
    Apple Software Update
    avast! Free Antivirus
    CANON iMAGE GATEWAY MyCamera Download Plugin
    CANON iMAGE GATEWAY Task for ZoomBrowser EX
    Canon Internet Library for ZoomBrowser EX
    Canon MOV Decoder
    Canon MOV Encoder
    Canon MovieEdit Task for ZoomBrowser EX
    Canon Utilities Digital Photo Professional 3.9
    Canon Utilities EOS Utility
    Canon Utilities PhotoStitch
    Canon Utilities Picture Style Editor
    Canon Utilities WFT Utility
    Canon Utilities ZoomBrowser EX
    Canon ZoomBrowser EX Memory Card Utility
    Conduit Engine
    CyberLink PowerDVD 9.6
    D3DX10
    Dell DataSafe Local Backup
    Dell DataSafe Local Backup - Support Software
    Dell DataSafe Online
    Dell Dock
    Dell Getting Started Guide
    Dell Webcam Central
    DirectX 9 Runtime
    ESET Online Scanner v3
    Google Chrome
    Google Earth
    Google Update Helper
    Inkscape 0.48.1
    Intel(R) Graphics Media Accelerator Driver
    Intel(R) Management Engine Components
    Internet TV for Windows Media Center
    Java Auto Updater
    Java(TM) 6 Update 24
    JMicron Flash Media Controller Driver
    Junk Mail filter update
    LiveUpload to Facebook
    LoJack Factory Installer
    Malwarebytes' Anti-Malware version 1.51.1.1800
    McAfee Security Center
    Mesh Runtime
    Messenger Companion
    Microsoft Office 2010
    Microsoft Research AutoCollage 2008 version 1.1
    Microsoft Silverlight
    Microsoft SQL Server 2005 Compact Edition [ENU]
    Microsoft Visual C++ 2005 ATL Update kb973923 - x86 8.0.50727.4053
    Microsoft Visual C++ 2005 Redistributable
    Microsoft Visual C++ 2008 ATL Update kb973924 - x86 9.0.30729.4148
    Microsoft Visual C++ 2008 Redistributable - KB2467174 - x86 9.0.30729.5570
    Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17
    Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.4148
    Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.6161
    Microsoft_VC80_ATL_x86
    Microsoft_VC80_CRT_x86
    Microsoft_VC80_MFC_x86
    Microsoft_VC80_MFCLOC_x86
    Microsoft_VC90_ATL_x86
    Microsoft_VC90_CRT_x86
    Microsoft_VC90_MFC_x86
    MSVC90_x86
    MSVCRT
    MSVCRT_amd64
    MSXML 4.0 SP2 (KB954430)
    MSXML 4.0 SP2 (KB973688)
    Nokia Connectivity Cable Driver
    Nokia PC Suite
    Nokia Software Updater
    NVIDIA 3D Vision Controller Driver
    NVIDIA PhysX
    NVIDIA Stereoscopic 3D Driver
    NVIDIA Updatus
    PC Connectivity Solution
    PhotoShowExpress
    Picasa 3
    Publish to Twitpic (Windows Live Photo Gallery Plug-in)
    PxMergeModule
    QuickTime
    Realtek High Definition Audio Driver
    Renesas Electronics USB 3.0 Host Controller Driver
    Roxio Activation Module
    Roxio BackOnTrack
    Roxio Burn
    Roxio Creator Starter
    Roxio Express Labeler 3
    Safari
    SAMSUNG PC Share Manager
    Security Update for CAPICOM (KB931906)
    Security Update for Microsoft .NET Framework 4 Client Profile (KB2160841)
    Security Update for Microsoft .NET Framework 4 Client Profile (KB2446708)
    Security Update for Microsoft .NET Framework 4 Client Profile (KB2478663)
    Security Update for Microsoft .NET Framework 4 Client Profile (KB2518870)
    Security Update for Microsoft .NET Framework 4 Client Profile (KB2539636)
    Skype Toolbars
    Skype™ 5.2
    SkyPlayer for Windows Media Center
    Sonic CinePlayer Decoder Pack
    Spelling Dictionaries Support For Adobe Reader 9
    System Requirements Lab
    TweetDeck
    Update for Microsoft .NET Framework 4 Client Profile (KB2468871)
    Update for Microsoft .NET Framework 4 Client Profile (KB2473228)
    Update for Microsoft .NET Framework 4 Client Profile (KB2533523)
    VLC media player 1.1.11
    Windows Live Communications Platform
    Windows Live Essentials
    Windows Live Installer
    Windows Live Mail
    Windows Live Mesh
    Windows Live Mesh ActiveX Control for Remote Connections
    Windows Live Messenger
    Windows Live Messenger Companion Core
    Windows Live Movie Maker
    Windows Live Photo Common
    Windows Live Photo Gallery
    Windows Live PIMT Platform
    Windows Live SOXE
    Windows Live SOXE Definitions
    Windows Live UX Platform
    Windows Live UX Platform Language Pack
    Windows Live Writer
    Windows Live Writer Resources
    Windows Media Center Add-in for Silverlight
    Windows Media Player Firefox Plugin
    .
    ==== Event Viewer Messages From Past Week ========
    .
    13/08/2011 23:25:22, Error: Microsoft-Windows-DNS-Client [1012] - There was an error while attempting to read the local hosts file.
    13/08/2011 18:30:39, Error: VDS Basic Provider [1] - Unexpected failure. Error code: 490@01010004
    13/08/2011 18:30:27, Error: Service Control Manager [7034] - The Wireless PAN DHCP Server service terminated unexpectedly. It has done this 1 time(s).
    13/08/2011 18:30:27, Error: Service Control Manager [7026] - The following boot-start or system-start driver(s) failed to load: is3srv szkg5
    13/08/2011 18:27:45, Error: Service Control Manager [7034] - The NVIDIA Stereoscopic 3D Driver Service service terminated unexpectedly. It has done this 1 time(s).
    13/08/2011 17:44:22, Error: Service Control Manager [7009] - A timeout was reached (30000 milliseconds) while waiting for the Adobe Active File Monitor V8 service to connect.
    13/08/2011 17:36:37, Error: Application Popup [1060] - \??\C:\ComboFix\catchme.sys has been blocked from loading due to incompatibility with this system. Please contact your software vendor for a compatible version of the driver.
    13/08/2011 17:30:30, Error: Service Control Manager [7030] - The PEVSystemStart service is marked as an interactive service. However, the system is configured to not allow interactive services. This service may not function properly.
    13/08/2011 17:27:18, Error: Service Control Manager [7011] - A timeout (30000 milliseconds) was reached while waiting for a transaction response from the McNASvc service.
    13/08/2011 17:26:48, Error: Service Control Manager [7011] - A timeout (30000 milliseconds) was reached while waiting for a transaction response from the McNaiAnn service.
    13/08/2011 17:26:18, Error: Service Control Manager [7011] - A timeout (30000 milliseconds) was reached while waiting for a transaction response from the mcmscsvc service.
    13/08/2011 17:25:48, Error: Service Control Manager [7011] - A timeout (30000 milliseconds) was reached while waiting for a transaction response from the McMPFSvc service.
    13/08/2011 17:22:26, Error: Service Control Manager [7031] - The Akamai NetSession Interface service terminated unexpectedly. It has done this 1 time(s). The following corrective action will be taken in 1000 milliseconds: Restart the service.
    13/08/2011 16:53:06, Error: Service Control Manager [7000] - The Security Center service failed to start due to the following error: The account specified for this service is different from the account specified for other services running in the same process.
    12/08/2011 08:12:38, Error: Service Control Manager [7026] - The following boot-start or system-start driver(s) failed to load: is3srv
    12/08/2011 08:02:11, Error: Microsoft-Windows-WLAN-AutoConfig [10000] - WLAN Extensibility Module has failed to start. Module Path: C:\Windows\System32\IWMSSvc.dll Error Code: 87
    12/08/2011 08:00:25, Error: Service Control Manager [7034] - The McAfee Scanner service terminated unexpectedly. It has done this 1 time(s).
    12/08/2011 01:15:00, Error: Service Control Manager [7031] - The McShield service terminated unexpectedly. It has done this 1 time(s). The following corrective action will be taken in 5000 milliseconds: Restart the service.
    11/08/2011 23:07:53, Error: Microsoft-Windows-WLAN-AutoConfig [10003] - WLAN Extensibility Module has stopped unexpectedly. Module Path: C:\Windows\System32\IWMSSvc.dll
    11/08/2011 13:51:24, Error: Disk [15] - The device, \Device\Harddisk2\DR2, is not ready for access yet.
    10/08/2011 23:20:02, Error: Service Control Manager [7034] - The NVIDIA Update Service Daemon service terminated unexpectedly. It has done this 1 time(s).
    10/08/2011 23:19:54, Error: Service Control Manager [7022] - The Windows Update service hung on starting.
    10/08/2011 22:33:27, Error: Service Control Manager [7024] - The HomeGroup Listener service terminated with service-specific error %%-2147023143.
    10/08/2011 22:32:49, Error: Service Control Manager [7034] - The Wireless PAN DHCP Server service terminated unexpectedly. It has done this 2 time(s).
    10/08/2011 22:30:57, Error: Service Control Manager [7024] - The Windows Firewall service terminated with service-specific error Access is denied..
    10/08/2011 00:37:48, Error: Schannel [36888] - The following fatal alert was generated: 10. The internal error state is 10.
    09/08/2011 12:32:25, Error: volsnap [36] - The shadow copies of volume C: were aborted because the shadow copy storage could not grow due to a user imposed limit.
    .
    ==== End Of File ===========================

    Thanks
     
  3. Bobbye

    Bobbye Helper on the Fringe Posts: 16,335   +36

    Welcome to TechSpot! I'll help you find what's closing the Security Center.

    I have combined your threads. Sometimes it takes a few minutes for a post to go through. We will keep everything for this problem on this thread. I have deleted the first one and added the content here. Am I correct in assuming that the popups are telling you the Security Center isn't running? If not, please give me the message.

    If the McAfee is current, you shouldn't be running Avast. Please uninstall Avast while I finish checking these logs: Avast Removal

    Please reboot the computer when finished.
    ================================================
    My Guidelines: please read and follow:
    • Be patient. Malware cleaning takes time and I am also working with other members while I am helping you.
    • Read my instructions carefully. If you don't understand or have a problem, ask me.
    • If you have questions, or if a program doesn't work, stop and tell me about it. Don't try to get around it yourself.
    • Follow the order of the tasks I give you. Order is crucial in cleaning process.
    • File sharing programs should be uninstalled or disabled during the cleaning process..
    • Observe these:
      [o] Don't use any other cleaning programs or scans while I'm helping you.
      [o] Don't use a Registry cleaner or make any changes in the Registry.
      [o] Don't download and install new programs- except those I give you.
    • Please let me know if there is any change in the system.

    If I don't get a reply from you in 5 days, the thread will be closed. If your problem persist, you can send a PM to reopen it.
    =====================================
    I will return with instructions shortly.
     
  4. Bobbye

    Bobbye Helper on the Fringe Posts: 16,335   +36

    Okay, I'm back. First with questions:

    Have you been getting help elsewhere? Or did you decide to gather random programs to try and fix the problem:

    I seen these on the system:

    These are not scans you should be doing yourself:
    RP123: 13/08/2011 17:59:22 - OTL Restore Point - 8/13/2011 5:59:15 PM
    2011-08-13 17:17:19 > C:\_OTL
    2011-08-13 16:22:31 > C:\ComboFix

    More security?
    2011-08-11 21:54:33> C:\Program Files (x86)\Microsoft Security Client > usually part of Microsoft Security Essentials


    Before I go on with you, I'd like to know about the scans above.

    Edit: Did you run Malwarebytes? Log?
     
  5. Gefstar

    Gefstar TS Rookie Topic Starter

    Reply1

    Hi, and thanks for taking your time to help someone who has got themselves in a mess!!

    Q1, I have been using BitTorrent lately and downloaded an adobe master cs5 file and tried to get the keygen to work using a Team Black keygen. I was warned by my McAfee programme that it may contaon a trojan (I continued!) Sorry. Since then the flag iin the taskbar has appeared with the white cross in a red circle, prompting me to turn on windows security centre. Upon pressing a pop up box shows, saying, Windows security centre can't be started. I have tried going into services.msc and changing the security centre profile but it keeps reverting to "disabled".

    Q2, Regarding the current state of cleaning programmes. - Sorry to say and to be totally honest, I followed somebody elses fix. I then read the forum rules about "NOT USING OTHER PEOPLES FIXES" - Once again I apologise.

    Q3. I searched the internet looking for fixes before landing here and got various methods of cleaning. All to no avail. Hence the multiple cleaning, virus removal programmes.

    Q4. Malware report - I did but I will run it again and paste it here.....

    Malwarebytes' Anti-Malware 1.51.1.1800
    www.malwarebytes.org

    Database version: 7454

    Windows 6.1.7601 Service Pack 1
    Internet Explorer 8.0.7601.17514

    14/08/2011 10:28:04
    mbam-log-2011-08-14 (10-28-04).txt

    Scan type: Quick scan
    Objects scanned: 233474
    Time elapsed: 5 minute(s), 25 second(s)

    Memory Processes Infected: 0
    Memory Modules Infected: 0
    Registry Keys Infected: 0
    Registry Values Infected: 0
    Registry Data Items Infected: 0
    Folders Infected: 0
    Files Infected: 0

    Memory Processes Infected:
    (No malicious items detected)

    Memory Modules Infected:
    (No malicious items detected)

    Registry Keys Infected:
    (No malicious items detected)

    Registry Values Infected:
    (No malicious items detected)

    Registry Data Items Infected:
    (No malicious items detected)

    Folders Infected:
    (No malicious items detected)

    Files Infected:
    (No malicious items detected)
     
  6. Gefstar

    Gefstar TS Rookie Topic Starter

    Cont'd

    Also, I am having problems with an Explorer window opening with random content. from Youtube videos for Lucozade adverts to Porn. Not good when my 4 year old daughter uses the laptop. The thing is I don't use Explorer, I use Chrome.

    Thanks
     
  7. Bobbye

    Bobbye Helper on the Fringe Posts: 16,335   +36

    You threw security out the Window when you did this:
    Using Bit Torrent at all or any other file sharing program puts the system at risk
    -------------------------------
    Pirating a program or app not only increases that risk, but is illegal.
    .
    ----------------------------
    As for the following, I suggest you keep her off the computer until it's clean and/or set up Parental Controls for very limited access:
    ===================================
    Please uninstall all previous programs you installed from someone else's help and from the internet. Once that has been done, use Windows Explorer to delete the program folders for or them.
    A note: Although we may run some of the same programs in the threads, the order we run them and what we do with the results of the scans are specific to the person who started the thread.

    To uninstall Combofix:
    • Click START> then RUN
    • Now type Combofix /Uninstall in the runbox and click OK. Note the space between the X and the U, it needs to be there.

    Reboot the computer when finished with the uninstalled
    --------------------------------------
    Download Combofix from HERE or HERE and save to the desktop
    • Double click combofix.exe & follow the prompts.
    • ComboFix will check to see if the Microsoft Windows Recovery Console is installed. It is recommended to have this pre-installed on your machine before doing any malware removal. It will allow you to boot up into a special recovery/repair mode if needed.
      **Please note: If the Microsoft Windows Recovery Console is already installed, ComboFix will continue it's malware removal procedures.
    • Follow the prompts to allow ComboFix to download and install the Microsoft Windows Recovery Console, and when prompted, agree to the End-User License Agreement to install the Microsoft Windows Recovery Console.
    • Once installed, you should see a blue screen prompt that says:
      The Recovery Console was successfully installed.
    • .Click on Yes, to continue scanning for malware
    • .If Combofix asks you to update the program, allow
    • .Close/disable all anti virus and anti malware programs so they do not interfere with the running of ComboFix.
    • .Close any open browsers.
    • .Double click combofix.exe[​IMG] & follow the prompts to run.
    • When the scan completes , a report will be generated-it will open a text window. Please paste the C:\ComboFix.txt in next reply..
    Re-enable your Antivirus software.

    Note 1:Do not mouse-click Combofix's window while it is running. That may cause it to stall.
    Note 2: ComboFix may reset a number of Internet Explorer's settings, including making I-E the default browser.
    Note 3: Combofix prevents autorun of ALL CD, floppy and USB devices to assist with malware removal & increase security. If this is an issue or makes it difficult for you -- please tell your helper.
    Note 4: CF disconnects your machine from the internet. The connection is automatically restored before CF completes its run. If CF runs into difficulty and terminates prematurely, the connection can be manually restored by restarting your machine.
    Note 5: If you receive an error "Illegal operation attempted on a registry key that has been marked for deletion", restart computer to fix the issue.
    ==========================================
    • Hold down Control and click on the following link to open ESET OnlineScan in a new window.
      ESETOnlineScan
    • For alternate browsers only: (Microsoft Internet Explorer users can skip these steps)
      [o] Click on Posted Image to download the ESET Smart Installer. Save it to your desktop.
      [o] Double click on the [​IMG]on your desktop.
    • Check 'Yes I accept terms of use.'
    • Click Start button
    • Accept any security warnings from your browser.
      [​IMG]
    • Uncheck 'Remove found threats'
    • Check 'Scan archives/
    • Leave remaining settings as is.
    • Press the Start button.
    • ESET will then download updates for itself, install itself, and begin scanning your computer. Please wait for the scan to finish.
    • When the scan completes, press List of found threats
    • Push Export of text file and save the file to your desktop using a unique name, such as ESETScan. Paste this log in your next reply.
    • Push the Back button
    • Push Finish

    NOTE: If no malware is found then no log will be produced. Let me know if this is the case.
    ======================================
    Download CKScanner and save to your desktop.
    • Doubleclick CKScanner.exe and click Search For Files.
    • When the cursor hourglass disappears, click Save List To File.
    • A message box will verify that the file is saved.
    • Double-click the CKFiles.txt icon on your desktop and copy/paste the contents
      in your next reply.

    All logs in next reply please.
     
  8. Gefstar

    Gefstar TS Rookie Topic Starter

    Reply

    ComboFix 11-08-16.02 - ChrisKelly 16/08/2011 20:18:32.2.4 - x64
    Microsoft Windows 7 Home Premium 6.1.7601.1.1252.44.1033.18.3828.1910 [GMT 1:00]
    Running from: c:\users\ChrisKelly\Downloads\ComboFix.exe
    AV: McAfee Anti-Virus and Anti-Spyware *Disabled/Updated* {86355677-4064-3EA7-ABB3-1B136EB04637}
    FW: McAfee Firewall *Disabled* {BE0ED752-0A0B-3FFF-80EC-B2269063014C}
    SP: McAfee Anti-Virus and Anti-Spyware *Disabled/Updated* {3D54B793-665E-3129-9103-206115370C8A}
    SP: Windows Defender *Disabled/Updated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
    * Created a new restore point
    * Resident AV is active
    .
    .
    .
    ((((((((((((((((((((((((( Files Created from 2011-07-16 to 2011-08-16 )))))))))))))))))))))))))))))))
    .
    .
    2011-08-16 19:29 . 2011-08-16 19:29 -------- d-----w- c:\users\Default\AppData\Local\temp
    2011-08-16 19:29 . 2011-08-16 19:29 -------- d-----w- c:\users\UpdatusUser\AppData\Local\temp
    2011-08-16 19:29 . 2011-08-16 19:29 -------- d-----w- c:\users\Mcx1-CHRISKELLY-PC\AppData\Local\temp
    2011-08-13 17:17 . 2011-08-13 17:17 -------- d-----w- C:\_OTL
    2011-08-13 14:15 . 2011-08-13 14:15 -------- d-----w- c:\windows\SysWow64\syncdb
    2011-08-13 13:29 . 2011-08-13 13:29 -------- d-----w- c:\users\ChrisKelly\AppData\Roaming\com.adobe.bridge.PublishPanel
    2011-08-12 11:34 . 2011-08-13 14:10 -------- d-----w- c:\users\ChrisKelly\AppData\Local\CrashDumps
    2011-08-12 10:44 . 2011-08-12 10:45 -------- d-----w- c:\users\Administrator
    2011-08-12 10:23 . 2011-08-12 10:24 -------- d-----w- c:\users\Administrator 1
    2011-08-12 07:09 . 2011-08-12 07:09 834544 ----a-w- c:\windows\system32\drivers\sptd.sys
    2011-08-12 07:07 . 2011-08-13 16:21 -------- d-----w- c:\users\ChrisKelly\AppData\Roaming\DAEMON Tools Lite
    2011-08-12 07:07 . 2011-08-12 07:07 -------- d-----w- c:\programdata\DAEMON Tools Lite
    2011-08-11 22:01 . 2011-07-04 11:43 40112 ----a-w- c:\windows\avastSS.scr
    2011-08-11 22:01 . 2011-07-04 11:43 199304 ----a-w- c:\windows\SysWow64\aswBoot.exe
    2011-08-11 22:01 . 2011-08-11 22:01 -------- d-----w- c:\programdata\AVAST Software
    2011-08-11 21:51 . 2011-08-11 21:51 -------- d-----w- c:\users\ChrisKelly\AppData\Roaming\Malwarebytes
    2011-08-11 21:51 . 2011-08-11 21:51 -------- d-----w- c:\programdata\Malwarebytes
    2011-08-11 21:51 . 2011-07-06 18:52 41272 ----a-w- c:\windows\SysWow64\drivers\mbamswissarmy.sys
    2011-08-11 21:51 . 2011-08-11 21:51 -------- d-----w- c:\program files (x86)\Malwarebytes' Anti-Malware
    2011-08-11 21:51 . 2011-07-06 18:52 25912 ----a-w- c:\windows\system32\drivers\mbam.sys
    2011-08-11 21:19 . 2011-08-11 21:38 -------- d-----w- c:\users\ChrisKelly\AppData\Local\NPE
    2011-08-11 20:38 . 2011-08-12 07:19 -------- d-----w- c:\programdata\STOPzilla!
    2011-08-11 20:27 . 2011-05-24 18:14 270720 ------w- c:\windows\system32\MpSigStub.exe
    2011-08-11 20:18 . 2010-10-19 10:33 222080 ------w- c:\windows\SysWow64\MpSigStub.exe
    2011-08-11 20:06 . 2011-08-11 20:06 -------- d-----w- c:\windows\en
    2011-08-11 19:59 . 2011-08-11 19:59 15712 ----a-w- c:\program files (x86)\Common Files\Windows Live\.cache\2d6cb0f01cc586101\MeshBetaRemover.exe
    2011-08-10 17:10 . 2011-08-10 17:12 -------- d-----w- c:\users\ChrisKelly\AppData\Local\ElevatedDiagnostics
    2011-08-09 21:39 . 2011-08-09 21:39 107520 --sha-r- c:\windows\SysWow64\usbperfv.dll
    2011-08-09 20:26 . 2011-08-09 20:26 -------- d-----w- c:\program files (x86)\My Company Name
    2011-08-07 10:12 . 2011-08-07 10:12 -------- d-----w- c:\users\ChrisKelly\AppData\Roaming\inkscape
    2011-08-07 07:55 . 2011-08-07 07:59 -------- d-----w- c:\program files (x86)\Inkscape
    2011-08-05 21:03 . 2011-08-05 21:03 2301208 ----a-w- c:\programdata\Microsoft\eHome\Packages\MCEClientUX\UpdateableMarkup-2\markup.dll
    2011-08-05 21:03 . 2011-08-05 21:03 42776 ----a-w- c:\programdata\Microsoft\eHome\Packages\MCEClientUX\dSM-2\StartResources.dll
    2011-08-05 21:03 . 2011-08-05 21:03 710976 ----a-w- c:\programdata\Microsoft\eHome\Packages\MCESpotlight\MCESpotlight-2\SpotlightResources.dll
    2011-07-24 18:21 . 2011-07-24 18:21 -------- d-----w- c:\windows\system32\SRSLabs
    2011-07-24 18:21 . 2011-07-24 18:21 -------- d-----w- c:\windows\SysWow64\RTCOM
    2011-07-24 18:20 . 2011-06-27 13:44 2604376 ----a-w- c:\windows\system32\WavesGUILib.dll
    2011-07-24 18:20 . 2009-11-24 08:55 155888 ----a-w- c:\windows\system32\SRSWOW64.dll
    2011-07-24 18:20 . 2009-11-24 08:55 518896 ----a-w- c:\windows\system32\SRSTSX64.dll
    2011-07-24 18:20 . 2009-11-24 08:55 211184 ----a-w- c:\windows\system32\SRSTSH64.dll
    2011-07-24 18:20 . 2009-11-24 08:55 198896 ----a-w- c:\windows\system32\SRSHP64.dll
    2011-07-24 18:20 . 2011-07-07 18:46 2432104 ----a-w- c:\windows\system32\RtPgEx64.dll
    2011-07-24 18:20 . 2011-06-30 15:14 1560168 ----a-w- c:\windows\system32\RTSnMg64.cpl
    2011-07-24 18:18 . 2005-11-13 22:19 5632 ----a-w- c:\program files (x86)\Common Files\InstallShield\Professional\RunTime\11\50\Intel32\DotNetInstaller.exe
    2011-07-24 18:15 . 2011-07-24 18:15 -------- d-----w- c:\program files (x86)\Realtek
    2011-07-24 17:30 . 2011-08-10 20:45 404640 ----a-w- c:\windows\SysWow64\FlashPlayerCPLApp.cpl
    2011-07-24 17:21 . 2011-05-10 09:41 29288 ----a-w- c:\windows\system32\nvhdap64.dll
    2011-07-24 17:21 . 2011-05-10 09:41 174184 ----a-w- c:\windows\system32\drivers\nvhda64v.sys
    2011-07-24 17:21 . 2011-05-10 09:41 1426536 ----a-w- c:\windows\system32\nvhdagenco642040.dll
    2011-07-24 17:21 . 2011-05-21 06:01 8863336 ----a-w- c:\windows\system32\nvwgf2umx.dll
    2011-07-24 17:21 . 2011-05-21 06:01 833640 ----a-w- c:\windows\system32\nvumdshimx.dll
    2011-07-24 17:21 . 2011-05-21 06:01 67176 ----a-w- c:\windows\system32\OpenCL.dll
    2011-07-24 17:21 . 2011-05-21 06:01 6555240 ----a-w- c:\windows\SysWow64\nvwgf2um.dll
    2011-07-24 17:21 . 2011-05-21 06:01 57960 ----a-w- c:\windows\SysWow64\OpenCL.dll
    2011-07-24 17:21 . 2011-05-21 06:01 366696 ----a-w- c:\windows\system32\nvoptimusmft.dll
    2011-07-24 17:21 . 2011-05-21 06:01 326248 ----a-w- c:\windows\SysWow64\nvoptimusmft.dll
    2011-07-24 17:21 . 2011-05-21 06:01 27240 ----a-w- c:\windows\system32\drivers\nvpciflt.sys
    2011-07-24 17:21 . 2011-05-21 06:01 22286952 ----a-w- c:\windows\system32\nvoglv64.dll
    2011-07-24 17:14 . 2011-07-24 17:14 -------- d-----w- C:\NVIDIA
    2011-07-24 17:10 . 2011-07-24 17:10 -------- d-----w- c:\program files (x86)\SystemRequirementsLab
    .
    .
    .
    (((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
    .
    2011-08-16 18:40 . 2011-01-06 23:34 2301208 ----a-w- c:\programdata\Microsoft\eHome\Packages\MCEClientUX\UpdateableMarkup\markup.dll
    2011-08-16 18:40 . 2011-01-06 23:33 42776 ----a-w- c:\programdata\Microsoft\eHome\Packages\MCEClientUX\dSM\StartResources.dll
    2011-08-11 20:02 . 2010-06-24 17:33 18328 ----a-w- c:\programdata\Microsoft\IdentityCRL\production\ppcrlconfig600.dll
    2011-07-16 04:26 . 2011-08-10 20:55 44032 ----a-w- c:\windows\apppatch\acwow64.dll
    2011-07-11 13:17 . 2011-01-03 21:21 1698408 ----a-w- c:\windows\RtlExUpd.dll
    2011-07-01 13:27 . 2009-07-14 02:36 152576 ----a-w- c:\windows\SysWow64\msclmd.dll
    2011-07-01 13:27 . 2009-07-14 02:36 175616 ----a-w- c:\windows\system32\msclmd.dll
    2011-06-11 03:07 . 2011-07-12 22:28 3137536 ----a-w- c:\windows\system32\win32k.sys
    2011-05-24 11:42 . 2011-07-01 12:59 404480 ----a-w- c:\windows\system32\umpnpmgr.dll
    2011-05-24 10:40 . 2011-07-01 12:59 64512 ----a-w- c:\windows\SysWow64\devobj.dll
    2011-05-24 10:40 . 2011-07-01 12:59 44544 ----a-w- c:\windows\SysWow64\devrtl.dll
    2011-05-24 10:39 . 2011-07-01 12:59 145920 ----a-w- c:\windows\SysWow64\cfgmgr32.dll
    2011-05-24 10:37 . 2011-07-01 12:59 252928 ----a-w- c:\windows\SysWow64\drvinst.exe
    2011-05-21 06:01 . 2010-11-24 17:34 694888 ----a-w- c:\windows\SysWow64\nvumdshim.dll
    2011-05-21 06:01 . 2010-11-24 17:34 239720 ----a-w- c:\windows\system32\nvinitx.dll
    2011-05-21 06:01 . 2010-11-24 17:34 200808 ----a-w- c:\windows\SysWow64\nvinit.dll
    2011-05-21 06:01 . 2010-11-24 17:34 11992680 ----a-w- c:\windows\SysWow64\nvd3dum.dll
    2011-05-21 06:01 . 2010-11-24 17:34 2644584 ----a-w- c:\windows\system32\nvapi64.dll
    2011-05-21 06:01 . 2010-11-24 17:34 2335848 ----a-w- c:\windows\SysWow64\nvapi.dll
    2011-05-21 06:01 . 2010-08-12 21:19 61544 ----a-w- c:\windows\system32\nvshext.dll
    2011-05-21 06:01 . 2010-08-12 21:19 1283212 ----a-w- c:\windows\system32\nvcoproc.bin
    2011-05-21 06:01 . 2010-08-12 19:19 6300776 ----a-w- c:\windows\system32\nvcpl.dll
    2011-05-21 06:01 . 2010-08-12 19:19 117864 ----a-w- c:\windows\system32\nvmctray.dll
    2011-05-21 06:01 . 2010-08-12 19:19 807528 ----a-w- c:\windows\system32\nv3dappshext.dll
    2011-05-21 06:01 . 2010-08-12 19:19 53864 ----a-w- c:\windows\system32\nv3dappshextr.dll
    2011-05-21 06:01 . 2010-08-12 19:19 326760 ----a-w- c:\windows\system32\nvhotkey.dll
    2011-05-21 06:01 . 2010-08-12 19:19 3040872 ----a-w- c:\windows\system32\nvsvc64.dll
    2011-05-21 06:01 . 2010-08-12 19:19 2560616 ----a-w- c:\windows\system32\nvsvcr.dll
    2011-05-21 06:01 . 2010-08-12 19:19 1016936 ----a-w- c:\windows\system32\nvvsvc.exe
    2011-05-21 06:01 . 2010-08-12 19:19 739432 ----a-w- c:\windows\system32\easyUpdatusAPIU64.dll
    2011-05-20 21:35 . 2011-05-20 21:35 304744 ----a-w- c:\windows\SysWow64\nvStreaming.exe
    .
    .
    ((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
    .
    .
    *Note* empty entries & legit default entries are not shown
    REGEDIT4
    .
    [HKEY_LOCAL_MACHINE\Wow6432Node\~\Browser Helper Objects\{30F9B915-B755-4826-820B-08FBA6BD249D}]
    2010-12-09 12:51 3911776 ----a-w- c:\program files (x86)\ConduitEngine\ConduitEngine.dll
    .
    [HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Toolbar]
    "{30F9B915-B755-4826-820B-08FBA6BD249D}"= "c:\program files (x86)\ConduitEngine\ConduitEngine.dll" [2010-12-09 3911776]
    .
    [HKEY_CLASSES_ROOT\clsid\{30f9b915-b755-4826-820b-08fba6bd249d}]
    .
    [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
    "msnmsgr"="c:\program files (x86)\Windows Live\Messenger\msnmsgr.exe" [2011-05-13 4283256]
    "PC Suite Tray"="c:\program files (x86)\Nokia\Nokia PC Suite 7\PCSuite.exe" [2011-06-16 1500160]
    "OfficeSyncProcess"="c:\program files\Microsoft Office\Office14\MSOSYNC.EXE" [2010-03-16 908160]
    .
    [HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Run]
    "NUSB3MON"="c:\program files (x86)\Renesas Electronics\USB 3.0 Host Controller Driver\Application\nusb3mon.exe" [2010-04-27 113288]
    "Dell DataSafe Online"="c:\program files (x86)\Dell DataSafe Online\DataSafeOnline.exe" [2010-02-09 1807680]
    "mcui_exe"="c:\program files\McAfee.com\Agent\mcagent.exe" [2011-06-28 1486392]
    "Dell Webcam Central"="c:\program files (x86)\Dell Webcam\Dell Webcam Central\WebcamDell2.exe" [2010-08-20 487562]
    "RemoteControl9"="c:\program files (x86)\CyberLink\PowerDVD9\PDVD9Serv.exe" [2009-07-06 87336]
    "PDVD9LanguageShortcut"="c:\program files (x86)\CyberLink\PowerDVD9\Language\Language.exe" [2010-09-18 50472]
    "BDRegion"="c:\program files (x86)\Cyberlink\Shared Files\brs.exe" [2010-09-28 75048]
    "RoxWatchTray"="c:\program files (x86)\Common Files\Roxio Shared\OEM\12.0\SharedCOM\RoxWatchTray12OEM.exe" [2010-09-04 240112]
    "Desktop Disc Tool"="c:\program files (x86)\Roxio\oem\Roxio Burn\RoxioBurnLauncher.exe" [2010-11-01 522736]
    "SunJavaUpdateSched"="c:\program files (x86)\Common Files\Java\Java Update\jusched.exe" [2010-10-29 249064]
    "AppleSyncNotifier"="c:\program files (x86)\Common Files\Apple\Mobile Device Support\AppleSyncNotifier.exe" [2010-12-14 47904]
    "Adobe ARM"="c:\program files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe" [2011-06-06 937920]
    "Malwarebytes' Anti-Malware"="c:\program files (x86)\Malwarebytes' Anti-Malware\mbamgui.exe" [2011-07-06 449584]
    .
    c:\users\Administrator\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\
    Dell Dock.lnk - c:\program files\Dell\DellDock\DellDock.exe [2010-5-28 1324384]
    .
    c:\users\Administrator 1\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\
    Dell Dock.lnk - c:\program files\Dell\DellDock\DellDock.exe [2010-5-28 1324384]
    .
    c:\users\Mcx1-CHRISKELLY-PC\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\
    Dell Dock First Run.lnk - c:\program files\Dell\DellDock\DellDock.exe [2010-5-28 1324384]
    .
    c:\users\ChrisKelly\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\
    Dell Dock.lnk - c:\program files\Dell\DellDock\DellDock.exe [2010-5-28 1324384]
    .
    c:\users\Default User\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\
    Dell Dock First Run.lnk - c:\program files\Dell\DellDock\DellDock.exe [2010-5-28 1324384]
    .
    [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
    "ConsentPromptBehaviorAdmin"= 5 (0x5)
    "ConsentPromptBehaviorUser"= 3 (0x3)
    "EnableUIADesktopToggle"= 0 (0x0)
    .
    [HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\windows nt\currentversion\windows]
    "AppInit_DLLs"=c:\windows\SysWOW64\nvinit.dll
    .
    [HKEY_LOCAL_MACHINE\system\currentcontrolset\control\lsa]
    Security Packages REG_MULTI_SZ kerberos msv1_0 schannel wdigest tspkg pku2u livessp
    .
    [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\mcmscsvc]
    @=""
    .
    [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\MCODS]
    @=""
    .
    R0 is3srv;is3srv;c:\windows\SySWOW64\drivers\is3srv64.sys [x]
    R0 szkg5;szkg5;c:\windows\SySWOW64\DRIVERS\szkg64.sys [x]
    R2 CLKMSVC10_9EC60124;CyberLink Product - 2011/01/03 15:47;c:\program files (x86)\CyberLink\PowerDVD9\NavFilter\kmsvc.exe [2010-09-28 254448]
    R2 clr_optimization_v4.0.30319_32;Microsoft .NET Framework NGEN v4.0.30319_X86;c:\windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe [2010-03-18 130384]
    R2 clr_optimization_v4.0.30319_64;Microsoft .NET Framework NGEN v4.0.30319_X64;c:\windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe [2010-03-18 138576]
    R2 gupdate;Google Update Service (gupdate);c:\program files (x86)\Google\Update\GoogleUpdate.exe [2011-03-12 136176]
    R2 RoxWatch12;Roxio Hard Drive Watcher 12;c:\program files (x86)\Common Files\Roxio Shared\OEM\12.0\SharedCOM\RoxWatch12OEM.exe [2010-09-04 219632]
    R3 AllShare;SAMSUNG AllShare Service;c:\program files (x86)\Samsung\SAMSUNG PC Share Manager\WiselinkPro.exe [2010-07-16 6638080]
    R3 gupdatem;Google Update Service (gupdatem);c:\program files (x86)\Google\Update\GoogleUpdate.exe [2011-03-12 136176]
    R3 JMCR;JMCR;c:\windows\system32\DRIVERS\jmcr.sys [x]
    R3 mferkdet;McAfee Inc. mferkdet;c:\windows\system32\drivers\mferkdet.sys [x]
    R3 Microsoft SharePoint Workspace Audit Service;Microsoft SharePoint Workspace Audit Service;c:\program files\Microsoft Office\Office14\GROOVE.EXE [2010-03-25 51456888]
    R3 nmwcdnsucx64;Nokia USB Flashing Generic;c:\windows\system32\drivers\nmwcdnsucx64.sys [x]
    R3 nmwcdnsux64;Nokia USB Flashing Phone Parent;c:\windows\system32\drivers\nmwcdnsux64.sys [x]
    R3 NVHDA;Service for NVIDIA High Definition Audio Driver;c:\windows\system32\drivers\nvhda64v.sys [x]
    R3 PCDSRVC{1E208CE0-FB7451FF-06020101}_0;PCDSRVC{1E208CE0-FB7451FF-06020101}_0 - PCDR Kernel Mode Service Helper Driver;c:\program files\dell support center\pcdsrvc_x64.pkms [2011-05-12 25072]
    R3 RoxMediaDB12OEM;RoxMediaDB12OEM;c:\program files (x86)\Common Files\Roxio Shared\OEM\12.0\SharedCOM\RoxMediaDB12OEM.exe [2010-09-04 1116656]
    R3 TsUsbFlt;TsUsbFlt;c:\windows\system32\drivers\tsusbflt.sys [x]
    R3 TurboBoost;TurboBoost;c:\program files\Intel\TurboBoost\TurboBoost.exe [2009-11-02 126352]
    R3 USBAAPL64;Apple Mobile USB Driver;c:\windows\system32\Drivers\usbaapl64.sys [x]
    R3 WatAdminSvc;Windows Activation Technologies Service;c:\windows\system32\Wat\WatAdminSvc.exe [x]
    R4 McOobeSv;McAfee OOBE Service;c:\program files\Common Files\mcafee\McSvcHost\McSvHost.exe [2010-03-10 355440]
    R4 wlcrasvc;Windows Live Mesh remote connections service;c:\program files\Windows Live\Mesh\wlcrasvc.exe [2010-09-23 57184]
    S0 mfewfpk;McAfee Inc. mfewfpk;c:\windows\system32\drivers\mfewfpk.sys [x]
    S0 nvpciflt;nvpciflt;c:\windows\system32\DRIVERS\nvpciflt.sys [x]
    S0 PxHlpa64;PxHlpa64;c:\windows\System32\Drivers\PxHlpa64.sys [x]
    S0 sptd;sptd;c:\windows\System32\Drivers\sptd.sys [x]
    S0 stdcfltn;Disk Class Filter Driver for Accelerometer;c:\windows\system32\DRIVERS\stdcfltn.sys [x]
    S1 mfenlfk;McAfee NDIS Light Filter;c:\windows\system32\DRIVERS\mfenlfk.sys [x]
    S1 vwififlt;Virtual WiFi Filter Driver;c:\windows\system32\DRIVERS\vwififlt.sys [x]
    S2 AdobeActiveFileMonitor8.0;Adobe Active File Monitor V8;c:\program files (x86)\Adobe\Elements Organizer 8.0\PhotoshopElementsFileAgent.exe [2009-09-18 169312]
    S2 AdobeARMservice;Adobe Acrobat Update Service;c:\program files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe [2011-06-06 64952]
    S2 AERTFilters;Andrea RT Filters Service;c:\program files\Realtek\Audio\HDA\AERTSr64.exe [2009-11-17 98208]
    S2 Akamai;Akamai NetSession Interface;c:\windows\System32\svchost.exe [2009-07-14 27136]
    S2 DockLoginService;Dock Login Service;c:\program files\Dell\DellDock\DockLogin.exe [2009-06-09 155648]
    S2 MBAMService;MBAMService;c:\program files (x86)\Malwarebytes' Anti-Malware\mbamservice.exe [2011-07-06 366640]
    S2 McMPFSvc;McAfee Personal Firewall Service;c:\program files\Common Files\McAfee\McSvcHost\McSvHost.exe [2010-03-10 355440]
    S2 McNaiAnn;McAfee VirusScan Announcer;c:\program files\Common Files\mcafee\McSvcHost\McSvHost.exe [2010-03-10 355440]
    S2 mfefire;McAfee Firewall Core Service;c:\program files\Common Files\McAfee\SystemCore\\mfefire.exe [2011-04-14 245352]
    S2 mfevtp;McAfee Validation Trust Protection Service;c:\program files\Common Files\McAfee\SystemCore\mfevtps.exe [2011-04-14 149032]
    S2 MyWiFiDHCPDNS;Wireless PAN DHCP Server;c:\program files\Intel\WiFi\bin\PanDhcpDns.exe [2010-03-05 340240]
    S2 nvUpdatusService;NVIDIA Update Service Daemon;c:\program files (x86)\NVIDIA Corporation\NVIDIA Updatus\daemonu.exe [2011-05-21 2214504]
    S2 SftService;SoftThinks Agent Service;c:\program files (x86)\Dell DataSafe Local Backup\sftservice.EXE [2011-01-13 705856]
    S2 Stereo Service;NVIDIA Stereoscopic 3D Driver Service;c:\program files (x86)\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe [2011-05-20 378472]
    S2 TurboB;Turbo Boost UI Monitor driver;c:\windows\system32\DRIVERS\TurboB.sys [x]
    S2 UNS;Intel(R) Management & Security Application User Notification Service;c:\program files (x86)\Intel\Intel(R) Management Engine Components\UNS\UNS.exe [2010-06-30 2533400]
    S3 Acceler;Accelerometer Service;c:\windows\system32\DRIVERS\Accelern.sys [x]
    S3 cfwids;McAfee Inc. cfwids;c:\windows\system32\drivers\cfwids.sys [x]
    S3 CtClsFlt;Creative Camera Class Upper Filter Driver;c:\windows\system32\DRIVERS\CtClsFlt.sys [x]
    S3 HECIx64;Intel(R) Management Engine Interface;c:\windows\system32\DRIVERS\HECIx64.sys [x]
    S3 Impcd;Impcd;c:\windows\system32\DRIVERS\Impcd.sys [x]
    S3 IntcDAud;Intel(R) Display Audio;c:\windows\system32\DRIVERS\IntcDAud.sys [x]
    S3 MBAMProtector;MBAMProtector;c:\windows\system32\drivers\mbam.sys [x]
    S3 mfefirek;McAfee Inc. mfefirek;c:\windows\system32\drivers\mfefirek.sys [x]
    S3 NETw5s64;Intel(R) Wireless WiFi Link 5000 Series Adapter Driver for Windows 7 - 64 Bit;c:\windows\system32\DRIVERS\NETw5s64.sys [x]
    S3 nusb3hub;Renesas Electronics USB 3.0 Hub Driver;c:\windows\system32\DRIVERS\nusb3hub.sys [x]
    S3 nusb3xhc;Renesas Electronics USB 3.0 Host Controller Driver;c:\windows\system32\DRIVERS\nusb3xhc.sys [x]
    S3 ose64;Office 64 Source Engine;c:\program files\Common Files\Microsoft Shared\Source Engine\OSE.EXE [2010-01-09 174440]
    S3 osppsvc;Office Software Protection Platform;c:\program files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPSVC.EXE [2010-01-09 4925184]
    S3 qicflt;upper Device Filter Driver;c:\windows\system32\DRIVERS\qicflt.sys [x]
    S3 RTL8167;Realtek 8167 NT Driver;c:\windows\system32\DRIVERS\Rt64win7.sys [x]
    S3 vwifimp;Microsoft Virtual WiFi Miniport Service;c:\windows\system32\DRIVERS\vwifimp.sys [x]
    S3 wdkmd;Intel WiDi KMD;c:\windows\system32\DRIVERS\WDKMD.sys [x]
    .
    .
    --- Other Services/Drivers In Memory ---
    .
    *Deregistered* - CLKMDRV10_9EC60124
    *Deregistered* - mfeavfk01
    .
    [HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\windows nt\currentversion\svchost]
    Akamai REG_MULTI_SZ Akamai
    .
    Contents of the 'Scheduled Tasks' folder
    .
    2011-08-16 c:\windows\Tasks\GoogleUpdateTaskMachineCore.job
    - c:\program files (x86)\Google\Update\GoogleUpdate.exe [2011-03-12 22:44]
    .
    2011-08-16 c:\windows\Tasks\GoogleUpdateTaskMachineUA.job
    - c:\program files (x86)\Google\Update\GoogleUpdate.exe [2011-03-12 22:44]
    .
    2011-08-16 c:\windows\Tasks\GoogleUpdateTaskUserS-1-5-21-2234497932-2908678672-3065977124-1002Core.job
    - c:\users\ChrisKelly\AppData\Local\Google\Update\GoogleUpdate.exe [2011-01-06 18:32]
    .
    2011-08-16 c:\windows\Tasks\GoogleUpdateTaskUserS-1-5-21-2234497932-2908678672-3065977124-1002UA.job
    - c:\users\ChrisKelly\AppData\Local\Google\Update\GoogleUpdate.exe [2011-01-06 18:32]
    .
    2011-07-29 c:\windows\Tasks\PCDoctorBackgroundMonitorTask.job
    - c:\program files\Dell Support Center\uaclauncher.exe [2011-06-21 18:09]
    .
    2011-08-16 c:\windows\Tasks\SystemToolsDailyTest.job
    - c:\program files\Dell Support Center\uaclauncher.exe [2011-06-21 18:09]
    .
    .
    --------- x86-64 -----------
    .
    .
    [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
    "IgfxTray"="c:\windows\system32\igfxtray.exe" [2010-09-02 161304]
    "HotKeysCmds"="c:\windows\system32\hkcmd.exe" [2010-09-02 386584]
    "Persistence"="c:\windows\system32\igfxpers.exe" [2010-09-02 415256]
    "IntelWireless"="c:\program files\Common Files\Intel\WirelessCommon\iFrmewrk.exe" [2010-03-05 1928976]
    "QuickSet"="c:\program files\Dell\QuickSet\QuickSet.exe" [2010-08-04 3206816]
    "FreeFallProtection"="c:\program files (x86)\STMicroelectronics\AccelerometerP11\FF_Protection.exe" [2010-09-24 727664]
    "BCSSync"="c:\program files\Microsoft Office\Office14\BCSSync.exe" [2010-03-13 112512]
    "NVHotkey"="c:\windows\system32\nvHotkey.dll" [2011-05-21 326760]
    "RTHDVCPL"="c:\program files\Realtek\Audio\HDA\RtkNGUI64.exe" [2011-07-06 7233640]
    "RtHDVBg"="c:\program files\Realtek\Audio\HDA\RAVBg64.exe" [2011-06-03 2226280]
    .
    [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows]
    "LoadAppInit_DLLs"=0x1
    "AppInit_DLLs"=c:\windows\System32\nvinitx.dll
    .
    ------- Supplementary Scan -------
    .
    uLocal Page = c:\windows\system32\blank.htm
    uDefault_Search_URL = hxxp://www.google.com/ie
    mLocal Page = c:\windows\SysWOW64\blank.htm
    uSearchAssistant = hxxp://www.google.com/ie
    uSearchURL,(Default) = hxxp://www.google.com/search?q=%s
    IE: Add to Google Photos Screensa&ver - c:\windows\system32\GPhotos.scr/200
    IE: E&xport to Microsoft Excel - c:\progra~1\MICROS~2\Office14\EXCEL.EXE/3000
    IE: Se&nd to OneNote - c:\progra~1\MICROS~2\Office14\ONBttnIE.dll/105
    TCP: DhcpNameServer = 192.168.1.254
    TCP: Interfaces\{234F1633-2877-42EC-819B-2D5A3BF1A546}: NameServer = 0.0.0.0
    .
    - - - - ORPHANS REMOVED - - - -
    .
    URLSearchHooks-{88c7f2aa-f93f-432c-8f0e-b7d85967a527} - (no file)
    URLSearchHooks-{ba14329e-9550-4989-b3f2-9732e92d17cc} - (no file)
    Toolbar-Locked - (no file)
    Wow6432Node-HKCU-Run-AdobeBridge - c:\program files (x86)\Adobe\Adobe Bridge CS5\Bridge.exe
    Wow6432Node-HKCU-Run-DAEMON Tools Lite - c:\program files (x86)\DAEMON Tools Lite\DTLite.exe
    Wow6432Node-HKLM-Run-DellSupportCenter - c:\program files (x86)\Dell Support Center\bin\sprtcmd.exe
    Toolbar-Locked - (no file)
    WebBrowser-{88C7F2AA-F93F-432C-8F0E-B7D85967A527} - (no file)
    ShellIconOverlayIdentifiers-{472083B0-C522-11CF-8763-00608CC02F24} - (no file)
    HKLM-Run-SynTPEnh - c:\program files (x86)\Synaptics\SynTP\SynTPEnh.exe
    HKLM-Run-RewardsWidget - c:\program files (x86)\Rewards4Golf\Rewards4Golf Widget\RewardsWidget.exe
    .
    .
    .
    [HKEY_LOCAL_MACHINE\system\ControlSet001\services\PCDSRVC{1E208CE0-FB7451FF-06020101}_0]
    "ImagePath"="\??\c:\program files\dell support center\pcdsrvc_x64.pkms"
    .
    --------------------- LOCKED REGISTRY KEYS ---------------------
    .
    [HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}]
    @Denied: (A 2) (Everyone)
    @="FlashBroker"
    "LocalizedString"="@c:\\Windows\\SysWOW64\\Macromed\\Flash\\FlashUtil10v_ActiveX.exe,-101"
    .
    [HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}\Elevation]
    "Enabled"=dword:00000001
    .
    [HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}\LocalServer32]
    @="c:\\Windows\\SysWOW64\\Macromed\\Flash\\FlashUtil10v_ActiveX.exe"
    .
    [HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}\TypeLib]
    @="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"
    .
    [HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}]
    @Denied: (A 2) (Everyone)
    @="Shockwave Flash Object"
    .
    [HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\InprocServer32]
    @="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash10v.ocx"
    "ThreadingModel"="Apartment"
    .
    [HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\MiscStatus]
    @="0"
    .
    [HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\ProgID]
    @="ShockwaveFlash.ShockwaveFlash.10"
    .
    [HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\ToolboxBitmap32]
    @="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash10v.ocx, 1"
    .
    [HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\TypeLib]
    @="{D27CDB6B-AE6D-11cf-96B8-444553540000}"
    .
    [HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\Version]
    @="1.0"
    .
    [HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\VersionIndependentProgID]
    @="ShockwaveFlash.ShockwaveFlash"
    .
    [HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}]
    @Denied: (A 2) (Everyone)
    @="Macromedia Flash Factory Object"
    .
    [HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\InprocServer32]
    @="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash10v.ocx"
    "ThreadingModel"="Apartment"
    .
    [HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\ProgID]
    @="FlashFactory.FlashFactory.1"
    .
    [HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\ToolboxBitmap32]
    @="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash10v.ocx, 1"
    .
    [HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\TypeLib]
    @="{D27CDB6B-AE6D-11cf-96B8-444553540000}"
    .
    [HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\Version]
    @="1.0"
    .
    [HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\VersionIndependentProgID]
    @="FlashFactory.FlashFactory"
    .
    [HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\Interface\{E3F2C3CB-5EB8-4A04-B22C-7E3B4B6AF30F}]
    @Denied: (A 2) (Everyone)
    @="IFlashBroker4"
    .
    [HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\Interface\{E3F2C3CB-5EB8-4A04-B22C-7E3B4B6AF30F}\ProxyStubClsid32]
    @="{00020424-0000-0000-C000-000000000046}"
    .
    [HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\Interface\{E3F2C3CB-5EB8-4A04-B22C-7E3B4B6AF30F}\TypeLib]
    @="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"
    "Version"="1.0"
    .
    [HKEY_LOCAL_MACHINE\software\McAfee]
    "SymbolicLinkValue"=hex(6):5c,00,72,00,65,00,67,00,69,00,73,00,74,00,72,00,79,
    00,5c,00,6d,00,61,00,63,00,68,00,69,00,6e,00,65,00,5c,00,53,00,6f,00,66,00,\
    .
    [HKEY_LOCAL_MACHINE\system\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0000\AllUserSettings]
    @Denied: (A) (Users)
    @Denied: (A) (Everyone)
    @Allowed: (B 1 2 3 4 5) (S-1-5-20)
    "BlindDial"=dword:00000000
    .
    [HKEY_LOCAL_MACHINE\system\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0001\AllUserSettings]
    @Denied: (A) (Users)
    @Denied: (A) (Everyone)
    @Allowed: (B 1 2 3 4 5) (S-1-5-20)
    "BlindDial"=dword:00000000
    .
    [HKEY_LOCAL_MACHINE\system\ControlSet001\Control\PCW\Security]
    @Denied: (Full) (Everyone)
    .
    Completion time: 2011-08-16 20:32:56
    ComboFix-quarantined-files.txt 2011-08-16 19:32
    .
    Pre-Run: 378,528,997,376 bytes free
    Post-Run: 378,410,590,208 bytes free
    .
    - - End Of File - - A65AF483C2157E82E7FF5E5426E49846

    No log produced on the eset scan

    CKScanner - Additional Security Risks - These are not necessarily bad
    c:\program files (x86)\inkscape\python\lib\site-packages\numpy\f2py\crackfortran.py
    scanner sequence 3.NA.11.XKAPDR
    ----- EOF -----

    Thanks
     
  9. Bobbye

    Bobbye Helper on the Fringe Posts: 16,335   +36

    I'm not seeing any Registry Entries disabling the Security Center. Have you tried restarting it again?

    Please run this Custom CFScript:

    • [1]. Close any open browsers.
      [2]. Close/disable all anti virus and anti malware programs so they do not interfere with the running of ComboFix.
      [3]. Open notepad> click on Format> Uncheck 'Word Wrap'> and copy/paste the text in the code below into it:Be sure to scroll down to include ALL lines.
    Code:
    File::
    
    DDS::
    uURLSearchHooks: H - No File
    uURLSearchHooks: H - No File
    BHO: Conduit Engine: {30f9b915-b755-4826-820b-08fba6bd249d} - C:\Program Files (x86)\ConduitEngine\ConduitEngine.dll
    BHO: avast! WebRep: {8e5e2654-ad2d-48bf-ac2d-d17f00898d06} - C:\Program Files\AVAST Software\Avast\aswWebRepIE.dll
    TB: Conduit Engine: {30f9b915-b755-4826-820b-08fba6bd249d} - C:\Program Files (x86)\ConduitEngine\ConduitEngine.dll
    TB: {88C7F2AA-F93F-432C-8F0E-B7D85967A527} - No File
    TB: {32099AAC-C132-4136-9E9A-4E364A424E17} - No File
    DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_24-windows-i586.cab
    DPF: {CAFEEFAC-0016-0000-0024-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_24-windows-i586.cab
    DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_24-windows-i586.cab
    TCP: Interfaces\{234F1633-2877-42EC-819B-2D5A3BF1A546} : NameServer = 0.0.0.0
    BHO-X64: Conduit Engine: {30F9B915-B755-4826-820B-08FBA6BD249D} - C:\Program Files (x86)\ConduitEngine\ConduitEngine.dll
    BHO-X64: scriptproxy - No File
    BHO-X64: SkypeIEPluginBHO - No File
    BHO-X64: URLRedirectionBHO - No File
    BHO-X64: Java(tm) Plug-In 2 SSV Helper: {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files (x86)\Java\jre6\bin\jp2ssv.dll
    TB-X64: Conduit Engine: {30F9B915-B755-4826-820B-08FBA6BD249D} - C:\Program Files (x86)\ConduitEngine\ConduitEngine.dll
    TB-X64: {88C7F2AA-F93F-432C-8F0E-B7D85967A527} - No File
    TB-X64: {32099AAC-C132-4136-9E9A-4E364A424E17} - No File
    Registry::
    [HKEY_LOCAL_MACHINE\Wow6432Node\~\Browser Helper Objects\{30F9B915-B755-4826-820B-08FBA6BD249D}]
    [HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Toolbar]
    "{30F9B915-B755-4826-820B-08FBA6BD249D}"=-
    [HKEY_CLASSES_ROOT\clsid\{30f9b915-b755-4826-820b-08fba6bd249d}]
    
    
    Save this as CFScript.txt, in the same location as ComboFix.exe
    [​IMG]

    Referring to the picture above, drag CFScript into ComboFix.exe

    When finished, it will produce a log for you at C:\ComboFix.txt . Please paste in your next reply.
    ========================================
    Are you still having some kind of popups? Describe them please.
    ========================================
    I'd like you to run the following. It will help to pin down why you are getting ads or popups of the kind you mentioned:
    [​IMG]
    SuperAntiSpyware Home Edition Free Version
    • Please download SuperAntiSpyware from HERE
    • Launch SuperAntiSpyware and click on 'Check for updates'.
    • Wait for the updates to be installed
    • On the main screen click on 'Scan your computer'.
    • Check: 'Perform Complete Scan then Click 'Next' to start the scan.
    • Superantispyware will now scan your computer,when it's finished it will list all/any infections found.
    • Make sure everything found has a checkmark next to it,then press 'Next'.
    • Click on 'Finish' when you've done.
    It's possible that the program will ask you to reboot in order to delete some files.

    Obtain the SuperAntiSpyware log as follows:
    • Click on 'Preferences'.
    • Click on the 'Statistics/Logs' tab.
    • Under 'Scanner Logs' double click on 'SuperAntiSpyware Scan Log'.
    It will then open in your default text editor,such as Notepad. Paste the notepad file here on your reply
     
  10. Gefstar

    Gefstar TS Rookie Topic Starter

    ComboFix 11-08-18.03 - ChrisKelly 19/08/2011 17:52:26.3.4 - x64
    Microsoft Windows 7 Home Premium 6.1.7601.1.1252.44.1033.18.3828.1728 [GMT 1:00]
    Running from: c:\users\ChrisKelly\Downloads\ComboFix.exe
    Command switches used :: c:\users\ChrisKelly\Desktop\CFScript.txt
    AV: McAfee Anti-Virus and Anti-Spyware *Disabled/Updated* {86355677-4064-3EA7-ABB3-1B136EB04637}
    FW: McAfee Firewall *Disabled* {BE0ED752-0A0B-3FFF-80EC-B2269063014C}
    SP: McAfee Anti-Virus and Anti-Spyware *Disabled/Updated* {3D54B793-665E-3129-9103-206115370C8A}
    SP: Windows Defender *Disabled/Updated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
    * Created a new restore point
    .
    .
    ((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
    .
    .
    c:\program files (x86)\ConduitEngine\ConduitEngine.dll
    .
    .
    ((((((((((((((((((((((((( Files Created from 2011-07-19 to 2011-08-19 )))))))))))))))))))))))))))))))
    .
    .
    2011-08-19 16:59 . 2011-08-19 16:59 -------- d-----w- c:\users\UpdatusUser\AppData\Local\temp
    2011-08-19 16:59 . 2011-08-19 16:59 -------- d-----w- c:\users\Mcx1-CHRISKELLY-PC\AppData\Local\temp
    2011-08-19 16:59 . 2011-08-19 16:59 -------- d-----w- c:\users\Default\AppData\Local\temp
    2011-08-16 19:38 . 2011-08-16 19:38 -------- d-----w- c:\program files (x86)\ESET
    2011-08-13 17:17 . 2011-08-13 17:17 -------- d-----w- C:\_OTL
    2011-08-13 14:15 . 2011-08-13 14:15 -------- d-----w- c:\windows\SysWow64\syncdb
    2011-08-13 13:29 . 2011-08-13 13:29 -------- d-----w- c:\users\ChrisKelly\AppData\Roaming\com.adobe.bridge.PublishPanel
    2011-08-12 11:34 . 2011-08-13 14:10 -------- d-----w- c:\users\ChrisKelly\AppData\Local\CrashDumps
    2011-08-12 10:44 . 2011-08-12 10:45 -------- d-----w- c:\users\Administrator
    2011-08-12 10:23 . 2011-08-12 10:24 -------- d-----w- c:\users\Administrator 1
    2011-08-12 07:09 . 2011-08-12 07:09 834544 ----a-w- c:\windows\system32\drivers\sptd.sys
    2011-08-12 07:07 . 2011-08-13 16:21 -------- d-----w- c:\users\ChrisKelly\AppData\Roaming\DAEMON Tools Lite
    2011-08-12 07:07 . 2011-08-12 07:07 -------- d-----w- c:\programdata\DAEMON Tools Lite
    2011-08-11 22:01 . 2011-07-04 11:43 40112 ----a-w- c:\windows\avastSS.scr
    2011-08-11 22:01 . 2011-07-04 11:43 199304 ----a-w- c:\windows\SysWow64\aswBoot.exe
    2011-08-11 22:01 . 2011-08-11 22:01 -------- d-----w- c:\programdata\AVAST Software
    2011-08-11 21:51 . 2011-08-11 21:51 -------- d-----w- c:\users\ChrisKelly\AppData\Roaming\Malwarebytes
    2011-08-11 21:51 . 2011-08-11 21:51 -------- d-----w- c:\programdata\Malwarebytes
    2011-08-11 21:51 . 2011-07-06 18:52 41272 ----a-w- c:\windows\SysWow64\drivers\mbamswissarmy.sys
    2011-08-11 21:51 . 2011-08-11 21:51 -------- d-----w- c:\program files (x86)\Malwarebytes' Anti-Malware
    2011-08-11 21:51 . 2011-07-06 18:52 25912 ----a-w- c:\windows\system32\drivers\mbam.sys
    2011-08-11 21:19 . 2011-08-11 21:38 -------- d-----w- c:\users\ChrisKelly\AppData\Local\NPE
    2011-08-11 20:38 . 2011-08-12 07:19 -------- d-----w- c:\programdata\STOPzilla!
    2011-08-11 20:27 . 2011-05-24 18:14 270720 ------w- c:\windows\system32\MpSigStub.exe
    2011-08-11 20:18 . 2010-10-19 10:33 222080 ------w- c:\windows\SysWow64\MpSigStub.exe
    2011-08-11 20:06 . 2011-08-11 20:06 -------- d-----w- c:\windows\en
    2011-08-11 19:59 . 2011-08-11 19:59 15712 ----a-w- c:\program files (x86)\Common Files\Windows Live\.cache\2d6cb0f01cc586101\MeshBetaRemover.exe
    2011-08-10 17:10 . 2011-08-10 17:12 -------- d-----w- c:\users\ChrisKelly\AppData\Local\ElevatedDiagnostics
    2011-08-09 21:39 . 2011-08-09 21:39 107520 --sha-r- c:\windows\SysWow64\usbperfv.dll
    2011-08-09 20:26 . 2011-08-09 20:26 -------- d-----w- c:\program files (x86)\My Company Name
    2011-08-07 10:12 . 2011-08-07 10:12 -------- d-----w- c:\users\ChrisKelly\AppData\Roaming\inkscape
    2011-08-07 07:55 . 2011-08-07 07:59 -------- d-----w- c:\program files (x86)\Inkscape
    2011-08-05 21:03 . 2011-08-05 21:03 2301208 ----a-w- c:\programdata\Microsoft\eHome\Packages\MCEClientUX\UpdateableMarkup-2\markup.dll
    2011-08-05 21:03 . 2011-08-05 21:03 42776 ----a-w- c:\programdata\Microsoft\eHome\Packages\MCEClientUX\dSM-2\StartResources.dll
    2011-08-05 21:03 . 2011-08-05 21:03 710976 ----a-w- c:\programdata\Microsoft\eHome\Packages\MCESpotlight\MCESpotlight-2\SpotlightResources.dll
    2011-07-24 18:21 . 2011-07-24 18:21 -------- d-----w- c:\windows\system32\SRSLabs
    2011-07-24 18:21 . 2011-07-24 18:21 -------- d-----w- c:\windows\SysWow64\RTCOM
    2011-07-24 18:20 . 2011-06-27 13:44 2604376 ----a-w- c:\windows\system32\WavesGUILib.dll
    2011-07-24 18:20 . 2009-11-24 08:55 155888 ----a-w- c:\windows\system32\SRSWOW64.dll
    2011-07-24 18:20 . 2009-11-24 08:55 518896 ----a-w- c:\windows\system32\SRSTSX64.dll
    2011-07-24 18:20 . 2009-11-24 08:55 211184 ----a-w- c:\windows\system32\SRSTSH64.dll
    2011-07-24 18:20 . 2009-11-24 08:55 198896 ----a-w- c:\windows\system32\SRSHP64.dll
    2011-07-24 18:20 . 2011-07-07 18:46 2432104 ----a-w- c:\windows\system32\RtPgEx64.dll
    2011-07-24 18:20 . 2011-06-30 15:14 1560168 ----a-w- c:\windows\system32\RTSnMg64.cpl
    2011-07-24 18:18 . 2005-11-13 22:19 5632 ----a-w- c:\program files (x86)\Common Files\InstallShield\Professional\RunTime\11\50\Intel32\DotNetInstaller.exe
    2011-07-24 18:15 . 2011-07-24 18:15 -------- d-----w- c:\program files (x86)\Realtek
    2011-07-24 17:30 . 2011-08-10 20:45 404640 ----a-w- c:\windows\SysWow64\FlashPlayerCPLApp.cpl
    2011-07-24 17:21 . 2011-05-10 09:41 29288 ----a-w- c:\windows\system32\nvhdap64.dll
    2011-07-24 17:21 . 2011-05-10 09:41 174184 ----a-w- c:\windows\system32\drivers\nvhda64v.sys
    2011-07-24 17:21 . 2011-05-10 09:41 1426536 ----a-w- c:\windows\system32\nvhdagenco642040.dll
    2011-07-24 17:21 . 2011-05-21 06:01 8863336 ----a-w- c:\windows\system32\nvwgf2umx.dll
    2011-07-24 17:21 . 2011-05-21 06:01 833640 ----a-w- c:\windows\system32\nvumdshimx.dll
    2011-07-24 17:21 . 2011-05-21 06:01 67176 ----a-w- c:\windows\system32\OpenCL.dll
    2011-07-24 17:21 . 2011-05-21 06:01 6555240 ----a-w- c:\windows\SysWow64\nvwgf2um.dll
    2011-07-24 17:21 . 2011-05-21 06:01 57960 ----a-w- c:\windows\SysWow64\OpenCL.dll
    2011-07-24 17:21 . 2011-05-21 06:01 366696 ----a-w- c:\windows\system32\nvoptimusmft.dll
    2011-07-24 17:21 . 2011-05-21 06:01 326248 ----a-w- c:\windows\SysWow64\nvoptimusmft.dll
    2011-07-24 17:21 . 2011-05-21 06:01 27240 ----a-w- c:\windows\system32\drivers\nvpciflt.sys
    2011-07-24 17:21 . 2011-05-21 06:01 22286952 ----a-w- c:\windows\system32\nvoglv64.dll
    2011-07-24 17:14 . 2011-07-24 17:14 -------- d-----w- C:\NVIDIA
    2011-07-24 17:10 . 2011-07-24 17:10 -------- d-----w- c:\program files (x86)\SystemRequirementsLab
    .
    .
    .
    (((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
    .
    2011-08-16 18:40 . 2011-01-06 23:34 2301208 ----a-w- c:\programdata\Microsoft\eHome\Packages\MCEClientUX\UpdateableMarkup\markup.dll
    2011-08-16 18:40 . 2011-01-06 23:33 42776 ----a-w- c:\programdata\Microsoft\eHome\Packages\MCEClientUX\dSM\StartResources.dll
    2011-08-11 20:02 . 2010-06-24 17:33 18328 ----a-w- c:\programdata\Microsoft\IdentityCRL\production\ppcrlconfig600.dll
    2011-07-16 04:26 . 2011-08-10 20:55 44032 ----a-w- c:\windows\apppatch\acwow64.dll
    2011-07-11 13:17 . 2011-01-03 21:21 1698408 ----a-w- c:\windows\RtlExUpd.dll
    2011-07-01 13:27 . 2009-07-14 02:36 152576 ----a-w- c:\windows\SysWow64\msclmd.dll
    2011-07-01 13:27 . 2009-07-14 02:36 175616 ----a-w- c:\windows\system32\msclmd.dll
    2011-06-11 03:07 . 2011-07-12 22:28 3137536 ----a-w- c:\windows\system32\win32k.sys
    2011-05-24 11:42 . 2011-07-01 12:59 404480 ----a-w- c:\windows\system32\umpnpmgr.dll
    2011-05-24 10:40 . 2011-07-01 12:59 64512 ----a-w- c:\windows\SysWow64\devobj.dll
    2011-05-24 10:40 . 2011-07-01 12:59 44544 ----a-w- c:\windows\SysWow64\devrtl.dll
    2011-05-24 10:39 . 2011-07-01 12:59 145920 ----a-w- c:\windows\SysWow64\cfgmgr32.dll
    2011-05-24 10:37 . 2011-07-01 12:59 252928 ----a-w- c:\windows\SysWow64\drvinst.exe
    .
    .
    ((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
    .
    .
    *Note* empty entries & legit default entries are not shown
    REGEDIT4
    .
    [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
    "msnmsgr"="c:\program files (x86)\Windows Live\Messenger\msnmsgr.exe" [2011-05-13 4283256]
    "PC Suite Tray"="c:\program files (x86)\Nokia\Nokia PC Suite 7\PCSuite.exe" [2011-06-16 1500160]
    "OfficeSyncProcess"="c:\program files\Microsoft Office\Office14\MSOSYNC.EXE" [2010-03-16 908160]
    .
    [HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Run]
    "NUSB3MON"="c:\program files (x86)\Renesas Electronics\USB 3.0 Host Controller Driver\Application\nusb3mon.exe" [2010-04-27 113288]
    "Dell DataSafe Online"="c:\program files (x86)\Dell DataSafe Online\DataSafeOnline.exe" [2010-02-09 1807680]
    "mcui_exe"="c:\program files\McAfee.com\Agent\mcagent.exe" [2011-06-28 1486392]
    "Dell Webcam Central"="c:\program files (x86)\Dell Webcam\Dell Webcam Central\WebcamDell2.exe" [2010-08-20 487562]
    "RemoteControl9"="c:\program files (x86)\CyberLink\PowerDVD9\PDVD9Serv.exe" [2009-07-06 87336]
    "PDVD9LanguageShortcut"="c:\program files (x86)\CyberLink\PowerDVD9\Language\Language.exe" [2010-09-18 50472]
    "BDRegion"="c:\program files (x86)\Cyberlink\Shared Files\brs.exe" [2010-09-28 75048]
    "RoxWatchTray"="c:\program files (x86)\Common Files\Roxio Shared\OEM\12.0\SharedCOM\RoxWatchTray12OEM.exe" [2010-09-04 240112]
    "Desktop Disc Tool"="c:\program files (x86)\Roxio\oem\Roxio Burn\RoxioBurnLauncher.exe" [2010-11-01 522736]
    "SunJavaUpdateSched"="c:\program files (x86)\Common Files\Java\Java Update\jusched.exe" [2010-10-29 249064]
    "AppleSyncNotifier"="c:\program files (x86)\Common Files\Apple\Mobile Device Support\AppleSyncNotifier.exe" [2010-12-14 47904]
    "Adobe ARM"="c:\program files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe" [2011-06-06 937920]
    "Malwarebytes' Anti-Malware"="c:\program files (x86)\Malwarebytes' Anti-Malware\mbamgui.exe" [2011-07-06 449584]
    .
    c:\users\Administrator\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\
    Dell Dock.lnk - c:\program files\Dell\DellDock\DellDock.exe [2010-5-28 1324384]
    .
    c:\users\Administrator 1\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\
    Dell Dock.lnk - c:\program files\Dell\DellDock\DellDock.exe [2010-5-28 1324384]
    .
    c:\users\Mcx1-CHRISKELLY-PC\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\
    Dell Dock First Run.lnk - c:\program files\Dell\DellDock\DellDock.exe [2010-5-28 1324384]
    .
    c:\users\ChrisKelly\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\
    Dell Dock.lnk - c:\program files\Dell\DellDock\DellDock.exe [2010-5-28 1324384]
    .
    c:\users\Default User\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\
    Dell Dock First Run.lnk - c:\program files\Dell\DellDock\DellDock.exe [2010-5-28 1324384]
    .
    [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
    "ConsentPromptBehaviorAdmin"= 5 (0x5)
    "ConsentPromptBehaviorUser"= 3 (0x3)
    "EnableUIADesktopToggle"= 0 (0x0)
    .
    [HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\windows nt\currentversion\windows]
    "AppInit_DLLs"=c:\windows\SysWOW64\nvinit.dll
    .
    [HKEY_LOCAL_MACHINE\system\currentcontrolset\control\lsa]
    Security Packages REG_MULTI_SZ kerberos msv1_0 schannel wdigest tspkg pku2u livessp
    .
    [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\mcmscsvc]
    @=""
    .
    [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\MCODS]
    @=""
    .
    R0 is3srv;is3srv;c:\windows\SySWOW64\drivers\is3srv64.sys [x]
    R0 szkg5;szkg5;c:\windows\SySWOW64\DRIVERS\szkg64.sys [x]
    R2 CLKMSVC10_9EC60124;CyberLink Product - 2011/01/03 15:47;c:\program files (x86)\CyberLink\PowerDVD9\NavFilter\kmsvc.exe [2010-09-28 254448]
    R2 clr_optimization_v4.0.30319_32;Microsoft .NET Framework NGEN v4.0.30319_X86;c:\windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe [2010-03-18 130384]
    R2 clr_optimization_v4.0.30319_64;Microsoft .NET Framework NGEN v4.0.30319_X64;c:\windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe [2010-03-18 138576]
    R2 gupdate;Google Update Service (gupdate);c:\program files (x86)\Google\Update\GoogleUpdate.exe [2011-03-12 136176]
    R2 MyWiFiDHCPDNS;Wireless PAN DHCP Server;c:\program files\Intel\WiFi\bin\PanDhcpDns.exe [2010-03-05 340240]
    R2 RoxWatch12;Roxio Hard Drive Watcher 12;c:\program files (x86)\Common Files\Roxio Shared\OEM\12.0\SharedCOM\RoxWatch12OEM.exe [2010-09-04 219632]
    R3 AllShare;SAMSUNG AllShare Service;c:\program files (x86)\Samsung\SAMSUNG PC Share Manager\WiselinkPro.exe [2010-07-16 6638080]
    R3 gupdatem;Google Update Service (gupdatem);c:\program files (x86)\Google\Update\GoogleUpdate.exe [2011-03-12 136176]
    R3 JMCR;JMCR;c:\windows\system32\DRIVERS\jmcr.sys [x]
    R3 mferkdet;McAfee Inc. mferkdet;c:\windows\system32\drivers\mferkdet.sys [x]
    R3 Microsoft SharePoint Workspace Audit Service;Microsoft SharePoint Workspace Audit Service;c:\program files\Microsoft Office\Office14\GROOVE.EXE [2010-03-25 51456888]
    R3 nmwcdnsucx64;Nokia USB Flashing Generic;c:\windows\system32\drivers\nmwcdnsucx64.sys [x]
    R3 nmwcdnsux64;Nokia USB Flashing Phone Parent;c:\windows\system32\drivers\nmwcdnsux64.sys [x]
    R3 NVHDA;Service for NVIDIA High Definition Audio Driver;c:\windows\system32\drivers\nvhda64v.sys [x]
    R3 ose64;Office 64 Source Engine;c:\program files\Common Files\Microsoft Shared\Source Engine\OSE.EXE [2010-01-09 174440]
    R3 osppsvc;Office Software Protection Platform;c:\program files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPSVC.EXE [2010-01-09 4925184]
    R3 RoxMediaDB12OEM;RoxMediaDB12OEM;c:\program files (x86)\Common Files\Roxio Shared\OEM\12.0\SharedCOM\RoxMediaDB12OEM.exe [2010-09-04 1116656]
    R3 TsUsbFlt;TsUsbFlt;c:\windows\system32\drivers\tsusbflt.sys [x]
    R3 TurboBoost;TurboBoost;c:\program files\Intel\TurboBoost\TurboBoost.exe [2009-11-02 126352]
    R3 USBAAPL64;Apple Mobile USB Driver;c:\windows\system32\Drivers\usbaapl64.sys [x]
    R3 WatAdminSvc;Windows Activation Technologies Service;c:\windows\system32\Wat\WatAdminSvc.exe [x]
    R4 McOobeSv;McAfee OOBE Service;c:\program files\Common Files\mcafee\McSvcHost\McSvHost.exe [2010-03-10 355440]
    R4 wlcrasvc;Windows Live Mesh remote connections service;c:\program files\Windows Live\Mesh\wlcrasvc.exe [2010-09-23 57184]
    S0 mfewfpk;McAfee Inc. mfewfpk;c:\windows\system32\drivers\mfewfpk.sys [x]
    S0 nvpciflt;nvpciflt;c:\windows\system32\DRIVERS\nvpciflt.sys [x]
    S0 PxHlpa64;PxHlpa64;c:\windows\System32\Drivers\PxHlpa64.sys [x]
    S0 sptd;sptd;c:\windows\System32\Drivers\sptd.sys [x]
    S0 stdcfltn;Disk Class Filter Driver for Accelerometer;c:\windows\system32\DRIVERS\stdcfltn.sys [x]
    S1 mfenlfk;McAfee NDIS Light Filter;c:\windows\system32\DRIVERS\mfenlfk.sys [x]
    S1 vwififlt;Virtual WiFi Filter Driver;c:\windows\system32\DRIVERS\vwififlt.sys [x]
    S2 AdobeActiveFileMonitor8.0;Adobe Active File Monitor V8;c:\program files (x86)\Adobe\Elements Organizer 8.0\PhotoshopElementsFileAgent.exe [2009-09-18 169312]
    S2 AdobeARMservice;Adobe Acrobat Update Service;c:\program files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe [2011-06-06 64952]
    S2 AERTFilters;Andrea RT Filters Service;c:\program files\Realtek\Audio\HDA\AERTSr64.exe [2009-11-17 98208]
    S2 Akamai;Akamai NetSession Interface;c:\windows\System32\svchost.exe [2009-07-14 27136]
    S2 DockLoginService;Dock Login Service;c:\program files\Dell\DellDock\DockLogin.exe [2009-06-09 155648]
    S2 MBAMService;MBAMService;c:\program files (x86)\Malwarebytes' Anti-Malware\mbamservice.exe [2011-07-06 366640]
    S2 McMPFSvc;McAfee Personal Firewall Service;c:\program files\Common Files\McAfee\McSvcHost\McSvHost.exe [2010-03-10 355440]
    S2 McNaiAnn;McAfee VirusScan Announcer;c:\program files\Common Files\mcafee\McSvcHost\McSvHost.exe [2010-03-10 355440]
    S2 mfefire;McAfee Firewall Core Service;c:\program files\Common Files\McAfee\SystemCore\\mfefire.exe [2011-04-14 245352]
    S2 mfevtp;McAfee Validation Trust Protection Service;c:\program files\Common Files\McAfee\SystemCore\mfevtps.exe [2011-04-14 149032]
    S2 nvUpdatusService;NVIDIA Update Service Daemon;c:\program files (x86)\NVIDIA Corporation\NVIDIA Updatus\daemonu.exe [2011-05-21 2214504]
    S2 SftService;SoftThinks Agent Service;c:\program files (x86)\Dell DataSafe Local Backup\sftservice.EXE [2011-01-13 705856]
    S2 Stereo Service;NVIDIA Stereoscopic 3D Driver Service;c:\program files (x86)\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe [2011-05-20 378472]
    S2 TurboB;Turbo Boost UI Monitor driver;c:\windows\system32\DRIVERS\TurboB.sys [x]
    S2 UNS;Intel(R) Management & Security Application User Notification Service;c:\program files (x86)\Intel\Intel(R) Management Engine Components\UNS\UNS.exe [2010-06-30 2533400]
    S3 Acceler;Accelerometer Service;c:\windows\system32\DRIVERS\Accelern.sys [x]
    S3 cfwids;McAfee Inc. cfwids;c:\windows\system32\drivers\cfwids.sys [x]
    S3 CtClsFlt;Creative Camera Class Upper Filter Driver;c:\windows\system32\DRIVERS\CtClsFlt.sys [x]
    S3 HECIx64;Intel(R) Management Engine Interface;c:\windows\system32\DRIVERS\HECIx64.sys [x]
    S3 Impcd;Impcd;c:\windows\system32\DRIVERS\Impcd.sys [x]
    S3 IntcDAud;Intel(R) Display Audio;c:\windows\system32\DRIVERS\IntcDAud.sys [x]
    S3 MBAMProtector;MBAMProtector;c:\windows\system32\drivers\mbam.sys [x]
    S3 mfefirek;McAfee Inc. mfefirek;c:\windows\system32\drivers\mfefirek.sys [x]
    S3 NETw5s64;Intel(R) Wireless WiFi Link 5000 Series Adapter Driver for Windows 7 - 64 Bit;c:\windows\system32\DRIVERS\NETw5s64.sys [x]
    S3 nusb3hub;Renesas Electronics USB 3.0 Hub Driver;c:\windows\system32\DRIVERS\nusb3hub.sys [x]
    S3 nusb3xhc;Renesas Electronics USB 3.0 Host Controller Driver;c:\windows\system32\DRIVERS\nusb3xhc.sys [x]
    S3 qicflt;upper Device Filter Driver;c:\windows\system32\DRIVERS\qicflt.sys [x]
    S3 RTL8167;Realtek 8167 NT Driver;c:\windows\system32\DRIVERS\Rt64win7.sys [x]
    S3 vwifimp;Microsoft Virtual WiFi Miniport Service;c:\windows\system32\DRIVERS\vwifimp.sys [x]
    S3 wdkmd;Intel WiDi KMD;c:\windows\system32\DRIVERS\WDKMD.sys [x]
    .
    .
    --- Other Services/Drivers In Memory ---
    .
    *Deregistered* - CLKMDRV10_9EC60124
    *Deregistered* - mfeavfk01
    .
    [HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\windows nt\currentversion\svchost]
    Akamai REG_MULTI_SZ Akamai
    .
    Contents of the 'Scheduled Tasks' folder
    .
    2011-08-19 c:\windows\Tasks\GoogleUpdateTaskMachineCore.job
    - c:\program files (x86)\Google\Update\GoogleUpdate.exe [2011-03-12 22:44]
    .
    2011-08-19 c:\windows\Tasks\GoogleUpdateTaskMachineUA.job
    - c:\program files (x86)\Google\Update\GoogleUpdate.exe [2011-03-12 22:44]
    .
    2011-08-19 c:\windows\Tasks\GoogleUpdateTaskUserS-1-5-21-2234497932-2908678672-3065977124-1002Core.job
    - c:\users\ChrisKelly\AppData\Local\Google\Update\GoogleUpdate.exe [2011-01-06 18:32]
    .
    2011-08-19 c:\windows\Tasks\GoogleUpdateTaskUserS-1-5-21-2234497932-2908678672-3065977124-1002UA.job
    - c:\users\ChrisKelly\AppData\Local\Google\Update\GoogleUpdate.exe [2011-01-06 18:32]
    .
    2011-07-29 c:\windows\Tasks\PCDoctorBackgroundMonitorTask.job
    - c:\program files\Dell Support Center\uaclauncher.exe [2011-06-21 18:09]
    .
    2011-08-19 c:\windows\Tasks\SystemToolsDailyTest.job
    - c:\program files\Dell Support Center\uaclauncher.exe [2011-06-21 18:09]
    .
    .
    --------- x86-64 -----------
    .
    .
    [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
    "SynTPEnh"="c:\program files (x86)\Synaptics\SynTP\SynTPEnh.exe" [BU]
    "IgfxTray"="c:\windows\system32\igfxtray.exe" [2010-09-02 161304]
    "HotKeysCmds"="c:\windows\system32\hkcmd.exe" [2010-09-02 386584]
    "Persistence"="c:\windows\system32\igfxpers.exe" [2010-09-02 415256]
    "IntelWireless"="c:\program files\Common Files\Intel\WirelessCommon\iFrmewrk.exe" [2010-03-05 1928976]
    "FreeFallProtection"="c:\program files (x86)\STMicroelectronics\AccelerometerP11\FF_Protection.exe" [2010-09-24 727664]
    "RewardsWidget"="c:\program files (x86)\Rewards4Golf\Rewards4Golf Widget\RewardsWidget.exe" [BU]
    "BCSSync"="c:\program files\Microsoft Office\Office14\BCSSync.exe" [2010-03-13 112512]
    "NVHotkey"="c:\windows\system32\nvHotkey.dll" [2011-05-21 326760]
    "RTHDVCPL"="c:\program files\Realtek\Audio\HDA\RtkNGUI64.exe" [2011-07-06 7233640]
    "RtHDVBg"="c:\program files\Realtek\Audio\HDA\RAVBg64.exe" [2011-06-03 2226280]
    .
    [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows]
    "AppInit_DLLs"=c:\windows\System32\nvinitx.dll
    .
    ------- Supplementary Scan -------
    .
    uLocal Page = c:\windows\system32\blank.htm
    uDefault_Search_URL = hxxp://www.google.com/ie
    mLocal Page = c:\windows\SysWOW64\blank.htm
    uSearchAssistant = hxxp://www.google.com/ie
    uSearchURL,(Default) = hxxp://www.google.com/search?q=%s
    IE: Add to Google Photos Screensa&ver - c:\windows\system32\GPhotos.scr/200
    IE: E&xport to Microsoft Excel - c:\progra~1\MICROS~2\Office14\EXCEL.EXE/3000
    IE: Se&nd to OneNote - c:\progra~1\MICROS~2\Office14\ONBttnIE.dll/105
    TCP: DhcpNameServer = 192.168.1.254
    TCP: Interfaces\{234F1633-2877-42EC-819B-2D5A3BF1A546}: NameServer = 0.0.0.0
    .
    - - - - ORPHANS REMOVED - - - -
    .
    Toolbar-Locked - (no file)
    ShellIconOverlayIdentifiers-{472083B0-C522-11CF-8763-00608CC02F24} - (no file)
    AddRemove-ESET Online Scanner - c:\program files (x86)\ESET\ESET Online Scanner\OnlineScannerUninstaller.exe
    .
    .
    .
    --------------------- LOCKED REGISTRY KEYS ---------------------
    .
    [HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}]
    @Denied: (A 2) (Everyone)
    @="FlashBroker"
    "LocalizedString"="@c:\\Windows\\SysWOW64\\Macromed\\Flash\\FlashUtil10v_ActiveX.exe,-101"
    .
    [HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}\Elevation]
    "Enabled"=dword:00000001
    .
    [HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}\LocalServer32]
    @="c:\\Windows\\SysWOW64\\Macromed\\Flash\\FlashUtil10v_ActiveX.exe"
    .
    [HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}\TypeLib]
    @="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"
    .
    [HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}]
    @Denied: (A 2) (Everyone)
    @="Shockwave Flash Object"
    .
    [HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\InprocServer32]
    @="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash10v.ocx"
    "ThreadingModel"="Apartment"
    .
    [HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\MiscStatus]
    @="0"
    .
    [HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\ProgID]
    @="ShockwaveFlash.ShockwaveFlash.10"
    .
    [HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\ToolboxBitmap32]
    @="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash10v.ocx, 1"
    .
    [HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\TypeLib]
    @="{D27CDB6B-AE6D-11cf-96B8-444553540000}"
    .
    [HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\Version]
    @="1.0"
    .
    [HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\VersionIndependentProgID]
    @="ShockwaveFlash.ShockwaveFlash"
    .
    [HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}]
    @Denied: (A 2) (Everyone)
    @="Macromedia Flash Factory Object"
    .
    [HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\InprocServer32]
    @="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash10v.ocx"
    "ThreadingModel"="Apartment"
    .
    [HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\ProgID]
    @="FlashFactory.FlashFactory.1"
    .
    [HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\ToolboxBitmap32]
    @="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash10v.ocx, 1"
    .
    [HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\TypeLib]
    @="{D27CDB6B-AE6D-11cf-96B8-444553540000}"
    .
    [HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\Version]
    @="1.0"
    .
    [HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\VersionIndependentProgID]
    @="FlashFactory.FlashFactory"
    .
    [HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\Interface\{E3F2C3CB-5EB8-4A04-B22C-7E3B4B6AF30F}]
    @Denied: (A 2) (Everyone)
    @="IFlashBroker4"
    .
    [HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\Interface\{E3F2C3CB-5EB8-4A04-B22C-7E3B4B6AF30F}\ProxyStubClsid32]
    @="{00020424-0000-0000-C000-000000000046}"
    .
    [HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\Interface\{E3F2C3CB-5EB8-4A04-B22C-7E3B4B6AF30F}\TypeLib]
    @="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"
    "Version"="1.0"
    .
    [HKEY_LOCAL_MACHINE\software\McAfee]
    "SymbolicLinkValue"=hex(6):5c,00,72,00,65,00,67,00,69,00,73,00,74,00,72,00,79,
    00,5c,00,6d,00,61,00,63,00,68,00,69,00,6e,00,65,00,5c,00,53,00,6f,00,66,00,\
    .
    [HKEY_LOCAL_MACHINE\system\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0000\AllUserSettings]
    @Denied: (A) (Users)
    @Denied: (A) (Everyone)
    @Allowed: (B 1 2 3 4 5) (S-1-5-20)
    "BlindDial"=dword:00000000
    .
    [HKEY_LOCAL_MACHINE\system\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0001\AllUserSettings]
    @Denied: (A) (Users)
    @Denied: (A) (Everyone)
    @Allowed: (B 1 2 3 4 5) (S-1-5-20)
    "BlindDial"=dword:00000000
    .
    [HKEY_LOCAL_MACHINE\system\ControlSet001\Control\PCW\Security]
    @Denied: (Full) (Everyone)
    .
    ------------------------ Other Running Processes ------------------------
    .
    c:\program files (x86)\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe
    c:\program files (x86)\Dell DataSafe Local Backup\COMPONENTS\SCHEDULER\STSERVICE.EXE
    c:\program files (x86)\Dell DataSafe Local Backup\Components\DSUpdate\DSUpd.exe
    c:\program files (x86)\Dell DataSafe Local Backup\Toaster.exe
    c:\program files (x86)\Intel\Intel(R) Management Engine Components\LMS\LMS.exe
    .
    **************************************************************************
    .
    Completion time: 2011-08-19 18:06:43 - machine was rebooted
    ComboFix-quarantined-files.txt 2011-08-19 17:06
    ComboFix2.txt 2011-08-16 19:32
    .
    Pre-Run: 374,588,698,624 bytes free
    Post-Run: 374,404,382,720 bytes free
    .
    - - End Of File - - 8508D62B467A3CE37D5D3B062597A521
     
  11. Gefstar

    Gefstar TS Rookie Topic Starter

    ..

    Hi,

    The Windows Security Centre is back up and running... Thank You.

    :D
     
  12. Gefstar

    Gefstar TS Rookie Topic Starter

    ...

    SUPERAntiSpyware Scan Log
    http://www.superantispyware.com

    Generated 08/19/2011 at 05:35 PM

    Application Version : 5.0.1118

    Core Rules Database Version : 7579
    Trace Rules Database Version: 5391

    Scan type : Quick Scan
    Total Scan Time : 20551:21327:00

    Operating System Information
    Windows 7 Home Premium 64-bit, Service Pack 1 (Build 6.01.7601)
    UAC On - Limited User

    Memory items scanned : 764
    Memory threats detected : 0
    Registry items scanned : 64475
    Registry threats detected : 1
    File items scanned : 11064
    File threats detected : 782

    Malware.Trace
    (x86) HKU\S-1-5-21-2234497932-2908678672-3065977124-1000\Software\NtWqIVLZEWZU

    Adware.Tracking Cookie
    C:\Users\ChrisKelly\AppData\Roaming\Microsoft\Windows\Cookies\chriskelly@accountservices.betfair[1].txt
    C:\Users\ChrisKelly\AppData\Roaming\Microsoft\Windows\Cookies\chriskelly@accountservices.betfair[2].txt
    C:\Users\ChrisKelly\AppData\Roaming\Microsoft\Windows\Cookies\chriskelly@ad.yieldmanager[2].txt
    C:\Users\ChrisKelly\AppData\Roaming\Microsoft\Windows\Cookies\chriskelly@adjuggler[1].txt
    C:\Users\ChrisKelly\AppData\Roaming\Microsoft\Windows\Cookies\chriskelly@ads.e-planning[1].txt
    C:\Users\ChrisKelly\AppData\Roaming\Microsoft\Windows\Cookies\chriskelly@ads.glispa[2].txt
    C:\Users\ChrisKelly\AppData\Roaming\Microsoft\Windows\Cookies\chriskelly@ads.inextmedia[2].txt
    C:\Users\ChrisKelly\AppData\Roaming\Microsoft\Windows\Cookies\chriskelly@ads.intergi[1].txt
    C:\Users\ChrisKelly\AppData\Roaming\Microsoft\Windows\Cookies\chriskelly@ads.nettravel[1].txt
    C:\Users\ChrisKelly\AppData\Roaming\Microsoft\Windows\Cookies\chriskelly@ads.pointroll[2].txt
    C:\Users\ChrisKelly\AppData\Roaming\Microsoft\Windows\Cookies\chriskelly@ads.pubmatic[1].txt
    C:\Users\ChrisKelly\AppData\Roaming\Microsoft\Windows\Cookies\chriskelly@adserver.adtechus[1].txt
    C:\Users\ChrisKelly\AppData\Roaming\Microsoft\Windows\Cookies\chriskelly@adtechus[1].txt
    C:\Users\ChrisKelly\AppData\Roaming\Microsoft\Windows\Cookies\chriskelly@advertising[2].txt
    C:\Users\ChrisKelly\AppData\Roaming\Microsoft\Windows\Cookies\chriskelly@adxpose[1].txt
    C:\Users\ChrisKelly\AppData\Roaming\Microsoft\Windows\Cookies\chriskelly@apmebf[2].txt
    C:\Users\ChrisKelly\AppData\Roaming\Microsoft\Windows\Cookies\chriskelly@apmebf[3].txt
    C:\Users\ChrisKelly\AppData\Roaming\Microsoft\Windows\Cookies\chriskelly@atdmt[1].txt
    C:\Users\ChrisKelly\AppData\Roaming\Microsoft\Windows\Cookies\chriskelly@atdmt[2].txt
    C:\Users\ChrisKelly\AppData\Roaming\Microsoft\Windows\Cookies\chriskelly@atdmt[4].txt
    C:\Users\ChrisKelly\AppData\Roaming\Microsoft\Windows\Cookies\chriskelly@atdmt[5].txt
    C:\Users\ChrisKelly\AppData\Roaming\Microsoft\Windows\Cookies\chriskelly@bs.serving-sys[2].txt
    C:\Users\ChrisKelly\AppData\Roaming\Microsoft\Windows\Cookies\chriskelly@content.yieldmanager[3].txt
    C:\Users\ChrisKelly\AppData\Roaming\Microsoft\Windows\Cookies\chriskelly@delivery.ads-littlestarmedia.co[1].txt
    C:\Users\ChrisKelly\AppData\Roaming\Microsoft\Windows\Cookies\chriskelly@directtrack[2].txt
    C:\Users\ChrisKelly\AppData\Roaming\Microsoft\Windows\Cookies\chriskelly@doubleclick[1].txt
    C:\Users\ChrisKelly\AppData\Roaming\Microsoft\Windows\Cookies\chriskelly@doubleclick[2].txt
    C:\Users\ChrisKelly\AppData\Roaming\Microsoft\Windows\Cookies\chriskelly@ehg-tfl.hitbox[2].txt
    C:\Users\ChrisKelly\AppData\Roaming\Microsoft\Windows\Cookies\chriskelly@eyeviewads[2].txt
    C:\Users\ChrisKelly\AppData\Roaming\Microsoft\Windows\Cookies\chriskelly@harrenmedianetwork[1].txt
    C:\Users\ChrisKelly\AppData\Roaming\Microsoft\Windows\Cookies\chriskelly@hitbox[1].txt
    C:\Users\ChrisKelly\AppData\Roaming\Microsoft\Windows\Cookies\chriskelly@httptrack[1].txt
    C:\Users\ChrisKelly\AppData\Roaming\Microsoft\Windows\Cookies\chriskelly@in.getclicky[1].txt
    C:\Users\ChrisKelly\AppData\Roaming\Microsoft\Windows\Cookies\chriskelly@indoormedia.co[1].txt
    C:\Users\ChrisKelly\AppData\Roaming\Microsoft\Windows\Cookies\chriskelly@lg2.solution.weborama[2].txt
    C:\Users\ChrisKelly\AppData\Roaming\Microsoft\Windows\Cookies\chriskelly@lsmnetwork.directtrack[1].txt
    C:\Users\ChrisKelly\AppData\Roaming\Microsoft\Windows\Cookies\chriskelly@matrix-media[1].txt
    C:\Users\ChrisKelly\AppData\Roaming\Microsoft\Windows\Cookies\chriskelly@mediabrandsww[1].txt
    C:\Users\ChrisKelly\AppData\Roaming\Microsoft\Windows\Cookies\chriskelly@mediaplex[1].txt
    C:\Users\ChrisKelly\AppData\Roaming\Microsoft\Windows\Cookies\chriskelly@mediaplex[2].txt
    C:\Users\ChrisKelly\AppData\Roaming\Microsoft\Windows\Cookies\chriskelly@microsoftwllivemkt.112.2o7[1].txt
    C:\Users\ChrisKelly\AppData\Roaming\Microsoft\Windows\Cookies\chriskelly@microsoftxbox.112.2o7[1].txt
    C:\Users\ChrisKelly\AppData\Roaming\Microsoft\Windows\Cookies\chriskelly@opti.inextmedia[2].txt
    C:\Users\ChrisKelly\AppData\Roaming\Microsoft\Windows\Cookies\chriskelly@pointroll[2].txt
    C:\Users\ChrisKelly\AppData\Roaming\Microsoft\Windows\Cookies\chriskelly@r1-ads.ace.advertising[2].txt
    C:\Users\ChrisKelly\AppData\Roaming\Microsoft\Windows\Cookies\chriskelly@rotator.adjuggler[1].txt
    C:\Users\ChrisKelly\AppData\Roaming\Microsoft\Windows\Cookies\chriskelly@ru4[2].txt
    C:\Users\ChrisKelly\AppData\Roaming\Microsoft\Windows\Cookies\chriskelly@rudefinder[2].txt
    C:\Users\ChrisKelly\AppData\Roaming\Microsoft\Windows\Cookies\chriskelly@server.cpmstar[2].txt
    C:\Users\ChrisKelly\AppData\Roaming\Microsoft\Windows\Cookies\chriskelly@serving-sys[1].txt
    C:\Users\ChrisKelly\AppData\Roaming\Microsoft\Windows\Cookies\chriskelly@track.webgains[1].txt
    C:\Users\ChrisKelly\AppData\Roaming\Microsoft\Windows\Cookies\chriskelly@trafficking.nabbr[2].txt
    C:\Users\ChrisKelly\AppData\Roaming\Microsoft\Windows\Cookies\chriskelly@vdwp.solution.weborama[1].txt
    C:\Users\ChrisKelly\AppData\Roaming\Microsoft\Windows\Cookies\chriskelly@vidasco.rotator.hadj7.adjuggler[2].txt
    C:\Users\ChrisKelly\AppData\Roaming\Microsoft\Windows\Cookies\chriskelly@weborama[1].txt
    C:\Users\ChrisKelly\AppData\Roaming\Microsoft\Windows\Cookies\chriskelly@www.rudefinder[1].txt
    C:\Users\ChrisKelly\AppData\Roaming\Microsoft\Windows\Cookies\chriskelly@xiti[1].txt
    C:\Users\ChrisKelly\AppData\Roaming\Microsoft\Windows\Cookies\chriskelly@yieldmanager[1].txt
    C:\Users\ChrisKelly\AppData\Roaming\Microsoft\Windows\Cookies\ZMYSY1E8.txt
    C:\Users\ChrisKelly\AppData\Roaming\Microsoft\Windows\Cookies\MUY42SRI.txt
    C:\Users\ChrisKelly\AppData\Roaming\Microsoft\Windows\Cookies\X0YBO6QM.txt
    C:\Users\ChrisKelly\AppData\Roaming\Microsoft\Windows\Cookies\D93MBNT8.txt
    C:\Users\ChrisKelly\AppData\Roaming\Microsoft\Windows\Cookies\RZ23OP7N.txt
    C:\Users\ChrisKelly\AppData\Roaming\Microsoft\Windows\Cookies\0VB4DQ8R.txt
    C:\Users\ChrisKelly\AppData\Roaming\Microsoft\Windows\Cookies\2YC4FI7P.txt
    C:\Users\ChrisKelly\AppData\Roaming\Microsoft\Windows\Cookies\V7G2A2E5.txt
    C:\Users\ChrisKelly\AppData\Roaming\Microsoft\Windows\Cookies\2DM2JL55.txt
    C:\Users\ChrisKelly\AppData\Roaming\Microsoft\Windows\Cookies\W5S6B7JG.txt
    C:\Users\ChrisKelly\AppData\Roaming\Microsoft\Windows\Cookies\XRFK8XKU.txt
    C:\Users\ChrisKelly\AppData\Roaming\Microsoft\Windows\Cookies\QMUOTV2W.txt
    C:\Users\ChrisKelly\AppData\Roaming\Microsoft\Windows\Cookies\1XXQEHWH.txt
    C:\Users\ChrisKelly\AppData\Roaming\Microsoft\Windows\Cookies\614PF46B.txt
    C:\Users\ChrisKelly\AppData\Roaming\Microsoft\Windows\Cookies\EC8Q3NH2.txt
    C:\Users\ChrisKelly\AppData\Roaming\Microsoft\Windows\Cookies\Q0W2FNLM.txt
    C:\Users\ChrisKelly\AppData\Roaming\Microsoft\Windows\Cookies\QY6U4FO4.txt
    C:\Users\ChrisKelly\AppData\Roaming\Microsoft\Windows\Cookies\3DBIAXJ4.txt
    C:\Users\ChrisKelly\AppData\Roaming\Microsoft\Windows\Cookies\DMS7L157.txt
    C:\Users\ChrisKelly\AppData\Roaming\Microsoft\Windows\Cookies\174DA096.txt
    C:\Users\ChrisKelly\AppData\Roaming\Microsoft\Windows\Cookies\H1SW2CS6.txt
    C:\Users\ChrisKelly\AppData\Roaming\Microsoft\Windows\Cookies\XF8P2ZF3.txt
    C:\Users\ChrisKelly\AppData\Roaming\Microsoft\Windows\Cookies\SBLGUB60.txt
    C:\Users\ChrisKelly\AppData\Roaming\Microsoft\Windows\Cookies\ZKMQYLUQ.txt
    C:\Users\ChrisKelly\AppData\Roaming\Microsoft\Windows\Cookies\U18LSH0G.txt
    C:\Users\ChrisKelly\AppData\Roaming\Microsoft\Windows\Cookies\1FJ5KIPR.txt
    C:\Users\ChrisKelly\AppData\Roaming\Microsoft\Windows\Cookies\38KAE10V.txt
    C:\Users\ChrisKelly\AppData\Roaming\Microsoft\Windows\Cookies\V939QDT1.txt
    C:\Users\ChrisKelly\AppData\Roaming\Microsoft\Windows\Cookies\ODVCAC2H.txt
    C:\Users\ChrisKelly\AppData\Roaming\Microsoft\Windows\Cookies\QIHY4BTC.txt
    C:\Users\ChrisKelly\AppData\Roaming\Microsoft\Windows\Cookies\38M302XY.txt
    C:\Users\ChrisKelly\AppData\Roaming\Microsoft\Windows\Cookies\GBNBMU2Q.txt
    C:\Users\ChrisKelly\AppData\Roaming\Microsoft\Windows\Cookies\0XNHLXFV.txt
    C:\Users\ChrisKelly\AppData\Roaming\Microsoft\Windows\Cookies\57KTVY7U.txt
    C:\Users\ChrisKelly\AppData\Roaming\Microsoft\Windows\Cookies\L8YK1LQ0.txt
    C:\Users\ChrisKelly\AppData\Roaming\Microsoft\Windows\Cookies\8Z0NN9ME.txt
    C:\Users\ChrisKelly\AppData\Roaming\Microsoft\Windows\Cookies\W0NO13K3.txt
    C:\Users\ChrisKelly\AppData\Roaming\Microsoft\Windows\Cookies\7JBDCZ0Q.txt
    C:\Users\ChrisKelly\AppData\Roaming\Microsoft\Windows\Cookies\KD2B0GUO.txt
    C:\Users\ChrisKelly\AppData\Roaming\Microsoft\Windows\Cookies\C33CC9U3.txt
    C:\Users\ChrisKelly\AppData\Roaming\Microsoft\Windows\Cookies\G4C2DOJY.txt
    C:\Users\ChrisKelly\AppData\Roaming\Microsoft\Windows\Cookies\I3C6VFL6.txt
    C:\Users\ChrisKelly\AppData\Roaming\Microsoft\Windows\Cookies\8YPPABZJ.txt
    C:\Users\ChrisKelly\AppData\Roaming\Microsoft\Windows\Cookies\SFDG1USX.txt
    C:\Users\ChrisKelly\AppData\Roaming\Microsoft\Windows\Cookies\70PH0L42.txt
    C:\Users\ChrisKelly\AppData\Roaming\Microsoft\Windows\Cookies\ZP1K502E.txt
    C:\Users\ChrisKelly\AppData\Roaming\Microsoft\Windows\Cookies\VHRUIZ0Z.txt
    C:\Users\ChrisKelly\AppData\Roaming\Microsoft\Windows\Cookies\GJ0AHKPX.txt
    C:\Users\ChrisKelly\AppData\Roaming\Microsoft\Windows\Cookies\7WN4I6UP.txt
    C:\Users\ChrisKelly\AppData\Roaming\Microsoft\Windows\Cookies\DIN2YAHS.txt
    C:\Users\ChrisKelly\AppData\Roaming\Microsoft\Windows\Cookies\2KU2S7FO.txt
    C:\Users\ChrisKelly\AppData\Roaming\Microsoft\Windows\Cookies\GDW750RY.txt
    C:\Users\ChrisKelly\AppData\Roaming\Microsoft\Windows\Cookies\T0AQNFUF.txt
    C:\Users\ChrisKelly\AppData\Roaming\Microsoft\Windows\Cookies\KPFBWQCF.txt
    C:\Users\ChrisKelly\AppData\Roaming\Microsoft\Windows\Cookies\7AI09F5A.txt
    C:\Users\ChrisKelly\AppData\Roaming\Microsoft\Windows\Cookies\SNDYO5VX.txt
    C:\Users\ChrisKelly\AppData\Roaming\Microsoft\Windows\Cookies\5UDET75A.txt
    C:\Users\ChrisKelly\AppData\Roaming\Microsoft\Windows\Cookies\1DG3PZ5C.txt
    C:\Users\ChrisKelly\AppData\Roaming\Microsoft\Windows\Cookies\VD8UP18S.txt
    C:\Users\ChrisKelly\AppData\Roaming\Microsoft\Windows\Cookies\DQU607MC.txt
    C:\Users\ChrisKelly\AppData\Roaming\Microsoft\Windows\Cookies\X3EA7066.txt
    C:\Users\ChrisKelly\AppData\Roaming\Microsoft\Windows\Cookies\TDJJ881V.txt
    C:\Users\ChrisKelly\AppData\Roaming\Microsoft\Windows\Cookies\7CNB5JFT.txt
    C:\Users\ChrisKelly\AppData\Roaming\Microsoft\Windows\Cookies\OYXUUNV2.txt
    C:\Users\ChrisKelly\AppData\Roaming\Microsoft\Windows\Cookies\3ZJZW2G3.txt
    C:\Users\ChrisKelly\AppData\Roaming\Microsoft\Windows\Cookies\GGII40EI.txt
    C:\Users\ChrisKelly\AppData\Roaming\Microsoft\Windows\Cookies\VV6ZI33B.txt
    C:\Users\ChrisKelly\AppData\Roaming\Microsoft\Windows\Cookies\V6QDWYZI.txt
    C:\Users\ChrisKelly\AppData\Roaming\Microsoft\Windows\Cookies\061ZZP22.txt
    C:\Users\ChrisKelly\AppData\Roaming\Microsoft\Windows\Cookies\TYSUNSUU.txt
    C:\Users\ChrisKelly\AppData\Roaming\Microsoft\Windows\Cookies\DHW96TR4.txt
    C:\Users\ChrisKelly\AppData\Roaming\Microsoft\Windows\Cookies\0F7OZAA9.txt
    C:\Users\ChrisKelly\AppData\Roaming\Microsoft\Windows\Cookies\WDDHYZC7.txt
    C:\Users\ChrisKelly\AppData\Roaming\Microsoft\Windows\Cookies\D86Y71V0.txt
    C:\Users\ChrisKelly\AppData\Roaming\Microsoft\Windows\Cookies\RHADATK2.txt
    C:\Users\ChrisKelly\AppData\Roaming\Microsoft\Windows\Cookies\GTIMCRM6.txt
    C:\Users\ChrisKelly\AppData\Roaming\Microsoft\Windows\Cookies\NJBYPUGW.txt
    C:\Users\ChrisKelly\AppData\Roaming\Microsoft\Windows\Cookies\R3X96XOL.txt
    C:\Users\ChrisKelly\AppData\Roaming\Microsoft\Windows\Cookies\0EXQLELG.txt
    C:\Users\ChrisKelly\AppData\Roaming\Microsoft\Windows\Cookies\T94ND1ZC.txt
    C:\Users\ChrisKelly\AppData\Roaming\Microsoft\Windows\Cookies\JI6C4AEU.txt
    C:\Users\ChrisKelly\AppData\Roaming\Microsoft\Windows\Cookies\0BPDNB5C.txt
    C:\Users\ChrisKelly\AppData\Roaming\Microsoft\Windows\Cookies\Y3R18UO9.txt
    C:\Users\ChrisKelly\AppData\Roaming\Microsoft\Windows\Cookies\5G1R7H8K.txt
    C:\Users\ChrisKelly\AppData\Roaming\Microsoft\Windows\Cookies\Q858ZJK6.txt
    C:\Users\ChrisKelly\AppData\Roaming\Microsoft\Windows\Cookies\6MQZQLLG.txt
    C:\Users\ChrisKelly\AppData\Roaming\Microsoft\Windows\Cookies\HT147R8F.txt
    C:\Users\ChrisKelly\AppData\Roaming\Microsoft\Windows\Cookies\41UKF4K1.txt
    C:\Users\ChrisKelly\AppData\Roaming\Microsoft\Windows\Cookies\O4F1YTT1.txt
    C:\Users\ChrisKelly\AppData\Roaming\Microsoft\Windows\Cookies\82O0QSLC.txt
    C:\Users\ChrisKelly\AppData\Roaming\Microsoft\Windows\Cookies\GL1NG9C2.txt
    C:\Users\ChrisKelly\AppData\Roaming\Microsoft\Windows\Cookies\6DWNW05C.txt
    C:\Users\ChrisKelly\AppData\Roaming\Microsoft\Windows\Cookies\67QZIZZ1.txt
    C:\Users\ChrisKelly\AppData\Roaming\Microsoft\Windows\Cookies\U0SHW6O9.txt
    C:\Users\ChrisKelly\AppData\Roaming\Microsoft\Windows\Cookies\4ALTAUJE.txt
    C:\Users\ChrisKelly\AppData\Roaming\Microsoft\Windows\Cookies\462UUSSN.txt
    C:\Users\ChrisKelly\AppData\Roaming\Microsoft\Windows\Cookies\UYRN2JUD.txt
    .revsci.net [ C:\USERS\CHRISKELLY\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
    .advertising.com [ C:\USERS\CHRISKELLY\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
    .mediaplex.com [ C:\USERS\CHRISKELLY\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
    .adtech.de [ C:\USERS\CHRISKELLY\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
    .atdmt.com [ C:\USERS\CHRISKELLY\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
    .imrworldwide.com [ C:\USERS\CHRISKELLY\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
    .imrworldwide.com [ C:\USERS\CHRISKELLY\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
    .2o7.net [ C:\USERS\CHRISKELLY\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
    .collective-media.net [ C:\USERS\CHRISKELLY\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
    .kontera.com [ C:\USERS\CHRISKELLY\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
    .orionmedia.com [ C:\USERS\CHRISKELLY\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
    .ru4.com [ C:\USERS\CHRISKELLY\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
    .ru4.com [ C:\USERS\CHRISKELLY\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
    .overture.com [ C:\USERS\CHRISKELLY\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
    C:\Users\ChrisKelly\AppData\Roaming\Microsoft\Windows\Cookies\SEFPFEYA.txt
    .zedo.com [ C:\USERS\CHRISKELLY\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
    C:\Users\ChrisKelly\AppData\Roaming\Microsoft\Windows\Cookies\V67FRHDK.txt
    .adbrite.com [ C:\USERS\CHRISKELLY\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
    C:\Users\ChrisKelly\AppData\Roaming\Microsoft\Windows\Cookies\UX096RNF.txt
    .invitemedia.com [ C:\USERS\CHRISKELLY\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
    C:\Users\ChrisKelly\AppData\Roaming\Microsoft\Windows\Cookies\VT2B2PE3.txt
    .adserver.adtechus.com [ C:\USERS\CHRISKELLY\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
    C:\Users\ChrisKelly\AppData\Roaming\Microsoft\Windows\Cookies\2EQLOE9Y.txt
    .msnportal.112.2o7.net [ C:\USERS\CHRISKELLY\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
    .liveperson.net [ C:\USERS\CHRISKELLY\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
    C:\Users\ChrisKelly\AppData\Roaming\Microsoft\Windows\Cookies\RVW5DI55.txt
    .amznmothercare.122.2o7.net [ C:\USERS\CHRISKELLY\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
    .2o7.net [ C:\USERS\CHRISKELLY\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
    .smartadserver.com [ C:\USERS\CHRISKELLY\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
    .serving-sys.com [ C:\USERS\CHRISKELLY\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
    C:\Users\ChrisKelly\AppData\Roaming\Microsoft\Windows\Cookies\2BNDGZRU.txt
    .ru4.com [ C:\USERS\CHRISKELLY\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
    .ru4.com [ C:\USERS\CHRISKELLY\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
    .ad.doubleclick.net [ C:\USERS\CHRISKELLY\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
    .2o7.net [ C:\USERS\CHRISKELLY\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
    .premiumtv.122.2o7.net [ C:\USERS\CHRISKELLY\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
    C:\Users\ChrisKelly\AppData\Roaming\Microsoft\Windows\Cookies\H2SAJ4RY.txt
    .uk.at.atwola.com [ C:\USERS\CHRISKELLY\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
    .at.atwola.com [ C:\USERS\CHRISKELLY\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
    C:\Users\ChrisKelly\AppData\Roaming\Microsoft\Windows\Cookies\5EOBFL0W.txt
    C:\Users\ChrisKelly\AppData\Roaming\Microsoft\Windows\Cookies\A1T83GB7.txt
    .newlook.112.2o7.net [ C:\USERS\CHRISKELLY\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
    C:\Users\ChrisKelly\AppData\Roaming\Microsoft\Windows\Cookies\CVMGLSBL.txt
    ad.yieldmanager.com [ C:\USERS\CHRISKELLY\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
    .2o7.net [ C:\USERS\CHRISKELLY\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
    C:\Users\ChrisKelly\AppData\Roaming\Microsoft\Windows\Cookies\DFEZ6A0I.txt
    .122.2o7.net [ C:\USERS\CHRISKELLY\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
    .2o7.net [ C:\USERS\CHRISKELLY\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
    .2o7.net [ C:\USERS\CHRISKELLY\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
    .sports-tracker.com [ C:\USERS\CHRISKELLY\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
    C:\Users\ChrisKelly\AppData\Roaming\Microsoft\Windows\Cookies\U0VVJUU4.txt
    .sports-tracker.com [ C:\USERS\CHRISKELLY\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
    .2o7.net [ C:\USERS\CHRISKELLY\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
    .2o7.net [ C:\USERS\CHRISKELLY\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
    .2o7.net [ C:\USERS\CHRISKELLY\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
    .2o7.net [ C:\USERS\CHRISKELLY\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
    .247realmedia.com [ C:\USERS\CHRISKELLY\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
    C:\Users\ChrisKelly\AppData\Roaming\Microsoft\Windows\Cookies\4HSXYXNR.txt
    .2o7.net [ C:\USERS\CHRISKELLY\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
    C:\Users\ChrisKelly\AppData\Roaming\Microsoft\Windows\Cookies\06093NA0.txt
    .kontera.com [ C:\USERS\CHRISKELLY\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
    .kontera.com [ C:\USERS\CHRISKELLY\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
    .2o7.net [ C:\USERS\CHRISKELLY\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
    .2o7.net [ C:\USERS\CHRISKELLY\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
    C:\Users\ChrisKelly\AppData\Roaming\Microsoft\Windows\Cookies\6Q1WTTLK.txt
    .xiti.com [ C:\USERS\CHRISKELLY\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
    tracking.dc-storm.com [ C:\USERS\CHRISKELLY\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
    C:\Users\ChrisKelly\AppData\Roaming\Microsoft\Windows\Cookies\4GQ7ZLEV.txt
    tracking.dc-storm.com [ C:\USERS\CHRISKELLY\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
    .2o7.net [ C:\USERS\CHRISKELLY\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
    .2o7.net [ C:\USERS\CHRISKELLY\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
    .2o7.net [ C:\USERS\CHRISKELLY\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
    .112.2o7.net [ C:\USERS\CHRISKELLY\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
    C:\Users\ChrisKelly\AppData\Roaming\Microsoft\Windows\Cookies\N0PTGTOP.txt
    .debenhams.122.2o7.net [ C:\USERS\CHRISKELLY\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
    .adbrite.com [ C:\USERS\CHRISKELLY\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
    .2o7.net [ C:\USERS\CHRISKELLY\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
    .122.2o7.net [ C:\USERS\CHRISKELLY\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
    tracking.dc-storm.com [ C:\USERS\CHRISKELLY\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
    C:\Users\ChrisKelly\AppData\Roaming\Microsoft\Windows\Cookies\VNNVV9GG.txt
    .invitemedia.com [ C:\USERS\CHRISKELLY\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
    .zedo.com [ C:\USERS\CHRISKELLY\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
    .2o7.net [ C:\USERS\CHRISKELLY\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
    C:\Users\ChrisKelly\AppData\Roaming\Microsoft\Windows\Cookies\Y3QTMM5G.txt
    .112.2o7.net [ C:\USERS\CHRISKELLY\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
    .2o7.net [ C:\USERS\CHRISKELLY\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
    .112.2o7.net [ C:\USERS\CHRISKELLY\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
    .112.2o7.net [ C:\USERS\CHRISKELLY\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
    C:\Users\ChrisKelly\AppData\Roaming\Microsoft\Windows\Cookies\RWWK31KF.txt
    .2o7.net [ C:\USERS\CHRISKELLY\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
    .2o7.net [ C:\USERS\CHRISKELLY\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
    .smartadserver.com [ C:\USERS\CHRISKELLY\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
    .ad.yieldmanager.com [ C:\USERS\CHRISKELLY\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
    .ad.yieldmanager.com [ C:\USERS\CHRISKELLY\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
    C:\Users\ChrisKelly\AppData\Roaming\Microsoft\Windows\Cookies\G2CO92A8.txt
    C:\Users\ChrisKelly\AppData\Roaming\Microsoft\Windows\Cookies\5A5MR2J0.txt
    .2o7.net [ C:\USERS\CHRISKELLY\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
    .2o7.net [ C:\USERS\CHRISKELLY\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
    media.mtvnservices.com [ C:\USERS\CHRISKELLY\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
    media.mtvnservices.com [ C:\USERS\CHRISKELLY\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
    C:\Users\ChrisKelly\AppData\Roaming\Microsoft\Windows\Cookies\WVAJBXMF.txt
    .2o7.net [ C:\USERS\CHRISKELLY\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
    .122.2o7.net [ C:\USERS\CHRISKELLY\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
    .2o7.net [ C:\USERS\CHRISKELLY\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
    .2o7.net [ C:\USERS\CHRISKELLY\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
    .2o7.net [ C:\USERS\CHRISKELLY\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
    C:\Users\ChrisKelly\AppData\Roaming\Microsoft\Windows\Cookies\ATJS5B4X.txt
    .trinitymirror.112.2o7.net [ C:\USERS\CHRISKELLY\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
    .2o7.net [ C:\USERS\CHRISKELLY\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
    .247realmedia.com [ C:\USERS\CHRISKELLY\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
    C:\Users\ChrisKelly\AppData\Roaming\Microsoft\Windows\Cookies\8ZRWBXO7.txt
    .adviva.net [ C:\USERS\CHRISKELLY\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
    .linksynergy.com [ C:\USERS\CHRISKELLY\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
    .linksynergy.com [ C:\USERS\CHRISKELLY\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
    .linksynergy.com [ C:\USERS\CHRISKELLY\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
    .2o7.net [ C:\USERS\CHRISKELLY\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
    .122.2o7.net [ C:\USERS\CHRISKELLY\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
    C:\Users\ChrisKelly\AppData\Roaming\Microsoft\Windows\Cookies\24HX6QE9.txt
    .matalan.122.2o7.net [ C:\USERS\CHRISKELLY\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
    C:\Users\ChrisKelly\AppData\Roaming\Microsoft\Windows\Cookies\IBLACNRK.txt
    .2o7.net [ C:\USERS\CHRISKELLY\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
    .112.2o7.net [ C:\USERS\CHRISKELLY\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
    .2o7.net [ C:\USERS\CHRISKELLY\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
    C:\Users\ChrisKelly\AppData\Roaming\Microsoft\Windows\Cookies\0SM3I9JY.txt
    .adxpose.com [ C:\USERS\CHRISKELLY\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
    .serving-sys.com [ C:\USERS\CHRISKELLY\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
    C:\Users\ChrisKelly\AppData\Roaming\Microsoft\Windows\Cookies\SFYTO567.txt
    .fastclick.net [ C:\USERS\CHRISKELLY\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
    .fastclick.net [ C:\USERS\CHRISKELLY\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
    C:\Users\ChrisKelly\AppData\Roaming\Microsoft\Windows\Cookies\R2GFC390.txt
    .122.2o7.net [ C:\USERS\CHRISKELLY\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
    ad.uk.doubleclick.net [ C:\USERS\CHRISKELLY\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
    ad.uk.doubleclick.net [ C:\USERS\CHRISKELLY\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
    accountservices.betfair.com [ C:\USERS\CHRISKELLY\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
    .afe2.specificclick.net [ C:\USERS\CHRISKELLY\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
    C:\Users\ChrisKelly\AppData\Roaming\Microsoft\Windows\Cookies\E5IJPDAV.txt
    .adviva.net [ C:\USERS\CHRISKELLY\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
    .2o7.net [ C:\USERS\CHRISKELLY\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
    .specificclick.net [ C:\USERS\CHRISKELLY\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
    C:\Users\ChrisKelly\AppData\Roaming\Microsoft\Windows\Cookies\11BG42YG.txt
    .specificclick.net [ C:\USERS\CHRISKELLY\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
    .specificclick.net [ C:\USERS\CHRISKELLY\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
    .specificclick.net [ C:\USERS\CHRISKELLY\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
    .specificclick.net [ C:\USERS\CHRISKELLY\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
    .specificclick.net [ C:\USERS\CHRISKELLY\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
    .specificclick.net [ C:\USERS\CHRISKELLY\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
    .specificclick.net [ C:\USERS\CHRISKELLY\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
    in.getclicky.com [ C:\USERS\CHRISKELLY\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
    .2o7.net [ C:\USERS\CHRISKELLY\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
    C:\Users\ChrisKelly\AppData\Roaming\Microsoft\Windows\Cookies\7HWNTUMU.txt
    .2o7.net [ C:\USERS\CHRISKELLY\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
    .legolas-media.com [ C:\USERS\CHRISKELLY\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
    C:\Users\ChrisKelly\AppData\Roaming\Microsoft\Windows\Cookies\E6QQVR5I.txt
    .bs.serving-sys.com [ C:\USERS\CHRISKELLY\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
    C:\Users\ChrisKelly\AppData\Roaming\Microsoft\Windows\Cookies\ESQ3EHXT.txt
    .adtech.de [ C:\USERS\CHRISKELLY\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
    .2o7.net [ C:\USERS\CHRISKELLY\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
    .122.2o7.net [ C:\USERS\CHRISKELLY\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
    .122.2o7.net [ C:\USERS\CHRISKELLY\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
    .partypoker.com [ C:\USERS\CHRISKELLY\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
    .2o7.net [ C:\USERS\CHRISKELLY\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
    C:\Users\ChrisKelly\AppData\Roaming\Microsoft\Windows\Cookies\QVX7GS02.txt
    C:\Users\ChrisKelly\AppData\Roaming\Microsoft\Windows\Cookies\7K1OGZO8.txt
    track.adform.net [ C:\USERS\CHRISKELLY\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
    C:\Users\ChrisKelly\AppData\Roaming\Microsoft\Windows\Cookies\289B0YEH.txt
    .invitemedia.com [ C:\USERS\CHRISKELLY\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
    C:\Users\ChrisKelly\AppData\Roaming\Microsoft\Windows\Cookies\CAWQTPJ9.txt
    .overture.com [ C:\USERS\CHRISKELLY\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
    .122.2o7.net [ C:\USERS\CHRISKELLY\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
    C:\Users\ChrisKelly\AppData\Roaming\Microsoft\Windows\Cookies\LL2PGL6J.txt
    tracker.roitesting.com [ C:\USERS\CHRISKELLY\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
    .bizrate.com [ C:\USERS\CHRISKELLY\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
    .apmebf.com [ C:\USERS\CHRISKELLY\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
    C:\Users\ChrisKelly\AppData\Roaming\Microsoft\Windows\Cookies\EGFX64AV.txt
    tracking.dc-storm.com [ C:\USERS\CHRISKELLY\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
    tracking.dc-storm.com [ C:\USERS\CHRISKELLY\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
    .burstnet.com [ C:\USERS\CHRISKELLY\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
    C:\Users\ChrisKelly\AppData\Roaming\Microsoft\Windows\Cookies\8E6AGONT.txt
    C:\Users\ChrisKelly\AppData\Roaming\Microsoft\Windows\Cookies\2M520SRH.txt
    .serving-sys.com [ C:\USERS\CHRISKELLY\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
    C:\Users\ChrisKelly\AppData\Roaming\Microsoft\Windows\Cookies\2N9LGF97.txt
    adserver.twitpic.com [ C:\USERS\CHRISKELLY\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
    .mediaplex.com [ C:\USERS\CHRISKELLY\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
    .overture.com [ C:\USERS\CHRISKELLY\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
    .2o7.net [ C:\USERS\CHRISKELLY\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
    C:\Users\ChrisKelly\AppData\Roaming\Microsoft\Windows\Cookies\JBSQDF2H.txt
    C:\Users\ChrisKelly\AppData\Roaming\Microsoft\Windows\Cookies\ABAG1196.txt
    C:\Users\ChrisKelly\AppData\Roaming\Microsoft\Windows\Cookies\EO1HRDUC.txt
    C:\Users\ChrisKelly\AppData\Roaming\Microsoft\Windows\Cookies\TF1P2SX0.txt
    C:\Users\ChrisKelly\AppData\Roaming\Microsoft\Windows\Cookies\2B5QZS4H.txt
    .classiccarpartfinder.co.uk [ C:\USERS\CHRISKELLY\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
    .classiccarpartfinder.co.uk [ C:\USERS\CHRISKELLY\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
    C:\Users\ChrisKelly\AppData\Roaming\Microsoft\Windows\Cookies\1JWMC2O8.txt
    banners.motorbase.com [ C:\USERS\CHRISKELLY\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
    banners.motorbase.com [ C:\USERS\CHRISKELLY\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
    banners.motorbase.com [ C:\USERS\CHRISKELLY\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
    C:\Users\ChrisKelly\AppData\Roaming\Microsoft\Windows\Cookies\6LJP65LO.txt
    .zedo.com [ C:\USERS\CHRISKELLY\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
    C:\Users\ChrisKelly\AppData\Roaming\Microsoft\Windows\Cookies\Q9UK6TCV.txt
    www.googleadservices.com [ C:\USERS\CHRISKELLY\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
    C:\Users\ChrisKelly\AppData\Roaming\Microsoft\Windows\Cookies\0N65MPUK.txt
    C:\Users\ChrisKelly\AppData\Roaming\Microsoft\Windows\Cookies\31B9EWAZ.txt
    .offersclick.co.uk [ C:\USERS\CHRISKELLY\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
    .offersclick.co.uk [ C:\USERS\CHRISKELLY\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
    .ehg-totalsystemsservices.hitbox.com [ C:\USERS\CHRISKELLY\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
    .hitbox.com [ C:\USERS\CHRISKELLY\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
    .ehg-totalsystemsservices.hitbox.com [ C:\USERS\CHRISKELLY\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
    www.googleadservices.com [ C:\USERS\CHRISKELLY\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
    .teletext.112.2o7.net [ C:\USERS\CHRISKELLY\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
    C:\Users\ChrisKelly\AppData\Roaming\Microsoft\Windows\Cookies\SREX63DN.txt
    C:\Users\ChrisKelly\AppData\Roaming\Microsoft\Windows\Cookies\TYJPKQ5Y.txt
    C:\Users\ChrisKelly\AppData\Roaming\Microsoft\Windows\Cookies\1ZUBDRXY.txt
    myaccount.creation.co.uk [ C:\USERS\CHRISKELLY\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
    C:\Users\ChrisKelly\AppData\Roaming\Microsoft\Windows\Cookies\Y90UVXA1.txt
    .kantarmedia.com [ C:\USERS\CHRISKELLY\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
    www.pcmediacenter.com.au [ C:\USERS\CHRISKELLY\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
    .pcmediacenter.com.au [ C:\USERS\CHRISKELLY\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
    .pcmediacenter.com.au [ C:\USERS\CHRISKELLY\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
    counter.hitslink.com [ C:\USERS\CHRISKELLY\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
    C:\Users\ChrisKelly\AppData\Roaming\Microsoft\Windows\Cookies\GXEM9KY4.txt
    .pro-market.net [ C:\USERS\CHRISKELLY\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
    C:\Users\ChrisKelly\AppData\Roaming\Microsoft\Windows\Cookies\HVPI692C.txt
    .adinterax.com [ C:\USERS\CHRISKELLY\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
    .adinterax.com [ C:\USERS\CHRISKELLY\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
    C:\Users\ChrisKelly\AppData\Roaming\Microsoft\Windows\Cookies\OEIN6VRA.txt
    track.adform.net [ C:\USERS\CHRISKELLY\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
    C:\Users\ChrisKelly\AppData\Roaming\Microsoft\Windows\Cookies\D88IG8B6.txt
    .adform.net [ C:\USERS\CHRISKELLY\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
    .revsci.net [ C:\USERS\CHRISKELLY\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
    C:\Users\ChrisKelly\AppData\Roaming\Microsoft\Windows\Cookies\4Z6MMOZU.txt
    C:\Users\ChrisKelly\AppData\Roaming\Microsoft\Windows\Cookies\IXYE5IX5.txt
    www.googleadservices.com [ C:\USERS\CHRISKELLY\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
    C:\Users\ChrisKelly\AppData\Roaming\Microsoft\Windows\Cookies\QQAQ4WB6.txt
    www.googleadservices.com [ C:\USERS\CHRISKELLY\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
    C:\Users\ChrisKelly\AppData\Roaming\Microsoft\Windows\Cookies\SGB43IQQ.txt
    www.googleadservices.com [ C:\USERS\CHRISKELLY\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
    C:\Users\ChrisKelly\AppData\Roaming\Microsoft\Windows\Cookies\9J7BMWL5.txt
    www.googleadservices.com [ C:\USERS\CHRISKELLY\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
    C:\Users\ChrisKelly\AppData\Roaming\Microsoft\Windows\Cookies\35KUHEG8.txt
    .liveperson.net [ C:\USERS\CHRISKELLY\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
    .traveladvertising.com [ C:\USERS\CHRISKELLY\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
    C:\Users\ChrisKelly\AppData\Roaming\Microsoft\Windows\Cookies\J8ZGOLM8.txt
    C:\Users\ChrisKelly\AppData\Roaming\Microsoft\Windows\Cookies\F5ZCZHHR.txt
    www.googleadservices.com [ C:\USERS\CHRISKELLY\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
    .tui.db.advertising.com [ C:\USERS\CHRISKELLY\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
    .firstchoice.db.advertising.com [ C:\USERS\CHRISKELLY\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
    .serving-sys.com [ C:\USERS\CHRISKELLY\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
    www.googleadservices.com [ C:\USERS\CHRISKELLY\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
    C:\Users\ChrisKelly\AppData\Roaming\Microsoft\Windows\Cookies\LJF98VZ2.txt
    .revsci.net [ C:\USERS\CHRISKELLY\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
    C:\Users\ChrisKelly\AppData\Roaming\Microsoft\Windows\Cookies\YIMI0R0L.txt
    .uk.at.atwola.com [ C:\USERS\CHRISKELLY\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
    .adtech.de [
     
  13. Gefstar

    Gefstar TS Rookie Topic Starter

    : cont'd

    C:\USERS\CHRISKELLY\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
    C:\Users\ChrisKelly\AppData\Roaming\Microsoft\Windows\Cookies\HRV6YY3A.txt
    C:\Users\ChrisKelly\AppData\Roaming\Microsoft\Windows\Cookies\SGT89M2X.txt
    .fastclick.net [ C:\USERS\CHRISKELLY\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
    C:\Users\ChrisKelly\AppData\Roaming\Microsoft\Windows\Cookies\SHFY2S5B.txt
    .adtech.de [ C:\USERS\CHRISKELLY\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
    www.skyscanner.net [ C:\USERS\CHRISKELLY\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
    www.skyscanner.net [ C:\USERS\CHRISKELLY\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
    .skyscanner.net [ C:\USERS\CHRISKELLY\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
    .skyscanner.net [ C:\USERS\CHRISKELLY\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
    C:\Users\ChrisKelly\AppData\Roaming\Microsoft\Windows\Cookies\S94CY89Z.txt
    www.skyscanner.net [ C:\USERS\CHRISKELLY\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
    .skyscanner.net [ C:\USERS\CHRISKELLY\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
    .skyscanner.net [ C:\USERS\CHRISKELLY\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
    .traveladvertising.com [ C:\USERS\CHRISKELLY\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
    .traveladvertising.com [ C:\USERS\CHRISKELLY\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
    .traveladvertising.com [ C:\USERS\CHRISKELLY\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
    .traveladvertising.com [ C:\USERS\CHRISKELLY\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
    tracking.dc-storm.com [ C:\USERS\CHRISKELLY\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
    .r1-ads.ace.advertising.com [ C:\USERS\CHRISKELLY\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
    .fastclick.net [ C:\USERS\CHRISKELLY\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
    C:\Users\ChrisKelly\AppData\Roaming\Microsoft\Windows\Cookies\O9KK1SIH.txt
    C:\Users\ChrisKelly\AppData\Roaming\Microsoft\Windows\Cookies\2YS4B0JM.txt
    C:\Users\ChrisKelly\AppData\Roaming\Microsoft\Windows\Cookies\VTBI34JJ.txt
    www.googleadservices.com [ C:\USERS\CHRISKELLY\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
    C:\Users\ChrisKelly\AppData\Roaming\Microsoft\Windows\Cookies\XPORVJAN.txt
    www.googleadservices.com [ C:\USERS\CHRISKELLY\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
    www.googleadservices.com [ C:\USERS\CHRISKELLY\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
    tracking.dc-storm.com [ C:\USERS\CHRISKELLY\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
    C:\Users\ChrisKelly\AppData\Roaming\Microsoft\Windows\Cookies\AYG9JTOM.txt
    www.googleadservices.com [ C:\USERS\CHRISKELLY\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
    www.googleadservices.com [ C:\USERS\CHRISKELLY\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
    C:\Users\ChrisKelly\AppData\Roaming\Microsoft\Windows\Cookies\DGZOFO2X.txt
    .liveperson.net [ C:\USERS\CHRISKELLY\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
    C:\Users\ChrisKelly\AppData\Roaming\Microsoft\Windows\Cookies\XBOG6V9G.txt
    www.googleadservices.com [ C:\USERS\CHRISKELLY\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
    C:\Users\ChrisKelly\AppData\Roaming\Microsoft\Windows\Cookies\GJS5NY6O.txt
    www.googleadservices.com [ C:\USERS\CHRISKELLY\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
    C:\Users\ChrisKelly\AppData\Roaming\Microsoft\Windows\Cookies\9FJ96X5T.txt
    C:\Users\ChrisKelly\AppData\Roaming\Microsoft\Windows\Cookies\LDVH93CF.txt
    www.sherwoodcountryclub.com [ C:\USERS\CHRISKELLY\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
    .sherwoodcountryclub.com [ C:\USERS\CHRISKELLY\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
    .sherwoodcountryclub.com [ C:\USERS\CHRISKELLY\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
    C:\Users\ChrisKelly\AppData\Roaming\Microsoft\Windows\Cookies\4WF0804C.txt
    .collective-media.net [ C:\USERS\CHRISKELLY\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
    .interclick.com [ C:\USERS\CHRISKELLY\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
    .interclick.com [ C:\USERS\CHRISKELLY\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
    .a1.interclick.com [ C:\USERS\CHRISKELLY\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
    .interclick.com [ C:\USERS\CHRISKELLY\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
    .a1.interclick.com [ C:\USERS\CHRISKELLY\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
    C:\Users\ChrisKelly\AppData\Roaming\Microsoft\Windows\Cookies\QWQIIK60.txt
    .interclick.com [ C:\USERS\CHRISKELLY\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
    C:\Users\ChrisKelly\AppData\Roaming\Microsoft\Windows\Cookies\FAIY93SK.txt
    www2.addfreestats.com [ C:\USERS\CHRISKELLY\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
    C:\Users\ChrisKelly\AppData\Roaming\Microsoft\Windows\Cookies\KXGC4JYX.txt
    .content.yieldmanager.com [ C:\USERS\CHRISKELLY\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
    C:\Users\ChrisKelly\AppData\Roaming\Microsoft\Windows\Cookies\HAC651I2.txt
    .media6degrees.com [ C:\USERS\CHRISKELLY\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
    C:\Users\ChrisKelly\AppData\Roaming\Microsoft\Windows\Cookies\3OBOYPYZ.txt
    C:\Users\ChrisKelly\AppData\Roaming\Microsoft\Windows\Cookies\BX9E42KG.txt
    wyestatsemea.com [ C:\USERS\CHRISKELLY\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
    wyestatsemea.com [ C:\USERS\CHRISKELLY\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
    C:\Users\ChrisKelly\AppData\Roaming\Microsoft\Windows\Cookies\4EUW5MRP.txt
    s08.flagcounter.com [ C:\USERS\CHRISKELLY\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
    C:\Users\ChrisKelly\AppData\Roaming\Microsoft\Windows\Cookies\H903T60J.txt
    .casalemedia.com [ C:\USERS\CHRISKELLY\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
    .casalemedia.com [ C:\USERS\CHRISKELLY\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
    .casalemedia.com [ C:\USERS\CHRISKELLY\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
    .casalemedia.com [ C:\USERS\CHRISKELLY\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
    .casalemedia.com [ C:\USERS\CHRISKELLY\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
    .e-2dj6wdkyagcjclp.stats.esomniture.com [ C:\USERS\CHRISKELLY\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
    C:\Users\ChrisKelly\AppData\Roaming\Microsoft\Windows\Cookies\8V34737L.txt
    www.googleadservices.com [ C:\USERS\CHRISKELLY\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
    uk.sitestat.com [ C:\USERS\CHRISKELLY\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
    www.googleadservices.com [ C:\USERS\CHRISKELLY\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
    .zedo.com [ C:\USERS\CHRISKELLY\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
    .cricket.widgets.stats.com [ C:\USERS\CHRISKELLY\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
    .cricket.widgets.stats.com [ C:\USERS\CHRISKELLY\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
    network.alluremedia.com.au [ C:\USERS\CHRISKELLY\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
    wstat.wibiya.com [ C:\USERS\CHRISKELLY\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
    ad.yieldmanager.com [ C:\USERS\CHRISKELLY\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
    .getclicky.com [ C:\USERS\CHRISKELLY\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
    .static.getclicky.com [ C:\USERS\CHRISKELLY\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
    www.googleadservices.com [ C:\USERS\CHRISKELLY\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
    www.googleadservices.com [ C:\USERS\CHRISKELLY\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
    www.googleadservices.com [ C:\USERS\CHRISKELLY\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
    .liveperson.net [ C:\USERS\CHRISKELLY\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
    www.finishedproductsexpo.com [ C:\USERS\CHRISKELLY\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
    www.googleadservices.com [ C:\USERS\CHRISKELLY\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
    .dmtracker.com [ C:\USERS\CHRISKELLY\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
    .revsci.net [ C:\USERS\CHRISKELLY\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
    .liveperson.net [ C:\USERS\CHRISKELLY\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
    www.googleadservices.com [ C:\USERS\CHRISKELLY\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
    .questionmarket.com [ C:\USERS\CHRISKELLY\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
    .questionmarket.com [ C:\USERS\CHRISKELLY\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
    .247realmedia.com [ C:\USERS\CHRISKELLY\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
    .www.burstnet.com [ C:\USERS\CHRISKELLY\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
    .revsci.net [ C:\USERS\CHRISKELLY\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
    tracking.dc-storm.com [ C:\USERS\CHRISKELLY\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
    www.googleadservices.com [ C:\USERS\CHRISKELLY\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
    .zedo.com [ C:\USERS\CHRISKELLY\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
    .liveperson.net [ C:\USERS\CHRISKELLY\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
    .bravenet.com [ C:\USERS\CHRISKELLY\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
    www.googleadservices.com [ C:\USERS\CHRISKELLY\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
    .insightexpressai.com [ C:\USERS\CHRISKELLY\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
    .insightexpressai.com [ C:\USERS\CHRISKELLY\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
    .insightexpressai.com [ C:\USERS\CHRISKELLY\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
    .insightexpressai.com [ C:\USERS\CHRISKELLY\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
    .insightexpressai.com [ C:\USERS\CHRISKELLY\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
    .insightexpressai.com [ C:\USERS\CHRISKELLY\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
    .insightexpressai.com [ C:\USERS\CHRISKELLY\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
    stats.eonenergy.com [ C:\USERS\CHRISKELLY\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
    .weborama.fr [ C:\USERS\CHRISKELLY\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
    .weborama.fr [ C:\USERS\CHRISKELLY\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
    .weboramapublishertrackinguk.solution.weborama.fr [ C:\USERS\CHRISKELLY\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
    .weboramapublishertrackinguk.solution.weborama.fr [ C:\USERS\CHRISKELLY\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
    .twittercounter.com [ C:\USERS\CHRISKELLY\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
    .twittercounter.com [ C:\USERS\CHRISKELLY\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
    .twittercounter.com [ C:\USERS\CHRISKELLY\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
    .media.twitter.com [ C:\USERS\CHRISKELLY\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
    .media.twitter.com [ C:\USERS\CHRISKELLY\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
    media.twitter.com [ C:\USERS\CHRISKELLY\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
    .247realmedia.com [ C:\USERS\CHRISKELLY\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
    dreamweaverserials.com [ C:\USERS\CHRISKELLY\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
    dreamweaverserials.com [ C:\USERS\CHRISKELLY\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
    .adbrite.com [ C:\USERS\CHRISKELLY\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
    .adbrite.com [ C:\USERS\CHRISKELLY\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
    .server.cpmstar.com [ C:\USERS\CHRISKELLY\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
    .server.cpmstar.com [ C:\USERS\CHRISKELLY\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
    .server.cpmstar.com [ C:\USERS\CHRISKELLY\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
    .server.cpmstar.com [ C:\USERS\CHRISKELLY\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
    .clicksor.com [ C:\USERS\CHRISKELLY\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
    .clicksor.com [ C:\USERS\CHRISKELLY\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
    .keygenguru.com [ C:\USERS\CHRISKELLY\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
    .keygenguru.com [ C:\USERS\CHRISKELLY\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
    .crackzone.net [ C:\USERS\CHRISKELLY\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
    .crackzone.net [ C:\USERS\CHRISKELLY\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
    .partypoker.com [ C:\USERS\CHRISKELLY\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
    .partypoker.com [ C:\USERS\CHRISKELLY\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
    .www.partypoker.com [ C:\USERS\CHRISKELLY\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
    .w3counter.com [ C:\USERS\CHRISKELLY\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
    .youserials.com [ C:\USERS\CHRISKELLY\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
    .youserials.com [ C:\USERS\CHRISKELLY\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
    .w3counter.com [ C:\USERS\CHRISKELLY\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
    .revsci.net [ C:\USERS\CHRISKELLY\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
    ad.yieldmanager.com [ C:\USERS\CHRISKELLY\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
    www.googleadservices.com [ C:\USERS\CHRISKELLY\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
    illustratorcs5serial.com [ C:\USERS\CHRISKELLY\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
    illustratorcs5serial.com [ C:\USERS\CHRISKELLY\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
    tracking.kinetiv.com [ C:\USERS\CHRISKELLY\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
    .zedo.com [ C:\USERS\CHRISKELLY\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
    .nickelodeonuk.112.2o7.net [ C:\USERS\CHRISKELLY\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
    .2o7.net [ C:\USERS\CHRISKELLY\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
    .2o7.net [ C:\USERS\CHRISKELLY\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
    .2o7.net [ C:\USERS\CHRISKELLY\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
    .smartadserver.com [ C:\USERS\CHRISKELLY\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
    .adtech.de [ C:\USERS\CHRISKELLY\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
    .2o7.net [ C:\USERS\CHRISKELLY\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
    auslieferung.commindo-media-ressourcen.de [ C:\USERS\CHRISKELLY\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
    www.googleadservices.com [ C:\USERS\CHRISKELLY\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
    tracking.dc-storm.com [ C:\USERS\CHRISKELLY\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
    www.googleadservices.com [ C:\USERS\CHRISKELLY\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
    www.googleadservices.com [ C:\USERS\CHRISKELLY\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
    eas.apm.emediate.eu [ C:\USERS\CHRISKELLY\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
    www.googleadservices.com [ C:\USERS\CHRISKELLY\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
    .adserver.simplysalesandmarketing.co.uk [ C:\USERS\CHRISKELLY\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
    .adserver.simplysalesandmarketing.co.uk [ C:\USERS\CHRISKELLY\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
    www.googleadservices.com [ C:\USERS\CHRISKELLY\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
    .yieldmanager.net [ C:\USERS\CHRISKELLY\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
    .advertising.com [ C:\USERS\CHRISKELLY\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
    .smartadserver.com [ C:\USERS\CHRISKELLY\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
    www.googleadservices.com [ C:\USERS\CHRISKELLY\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
    .revsci.net [ C:\USERS\CHRISKELLY\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
    .mm.chitika.net [ C:\USERS\CHRISKELLY\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
    .backtrack-linux.org [ C:\USERS\CHRISKELLY\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
    .www.backtrack-linux.org [ C:\USERS\CHRISKELLY\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
    .keygen.cc [ C:\USERS\CHRISKELLY\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
    .keygen.cc [ C:\USERS\CHRISKELLY\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
    .keygens.nl [ C:\USERS\CHRISKELLY\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
    .keygens.nl [ C:\USERS\CHRISKELLY\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
    .statcounter.com [ C:\USERS\CHRISKELLY\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
    .revsci.net [ C:\USERS\CHRISKELLY\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
    .traveladvertising.com [ C:\USERS\CHRISKELLY\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
    .traveladvertising.com [ C:\USERS\CHRISKELLY\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
    .findology.com [ C:\USERS\CHRISKELLY\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
    .trafficmp.com [ C:\USERS\CHRISKELLY\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
    .invitemedia.com [ C:\USERS\CHRISKELLY\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
    web4.realtracker.com [ C:\USERS\CHRISKELLY\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
    .legolas-media.com [ C:\USERS\CHRISKELLY\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
    www.sexscanner.com [ C:\USERS\CHRISKELLY\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
    www.sexscanner.com [ C:\USERS\CHRISKELLY\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
    .sexscanner.com [ C:\USERS\CHRISKELLY\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
    .sexscanner.com [ C:\USERS\CHRISKELLY\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
    .advertise.com [ C:\USERS\CHRISKELLY\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
    .casalemedia.com [ C:\USERS\CHRISKELLY\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
    .casalemedia.com [ C:\USERS\CHRISKELLY\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
    .casalemedia.com [ C:\USERS\CHRISKELLY\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
    .myroitracking.com [ C:\USERS\CHRISKELLY\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
    .clicksor.com [ C:\USERS\CHRISKELLY\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
    .clicksor.com [ C:\USERS\CHRISKELLY\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
    .stopzilla.com [ C:\USERS\CHRISKELLY\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
    .stopzilla.com [ C:\USERS\CHRISKELLY\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
    .stopzilla.com [ C:\USERS\CHRISKELLY\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
    www.stopzilla.com [ C:\USERS\CHRISKELLY\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
    rts.pgmediaserve.com [ C:\USERS\CHRISKELLY\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
    rts.pgmediaserve.com [ C:\USERS\CHRISKELLY\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
    rts.pgmediaserve.com [ C:\USERS\CHRISKELLY\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
    .partypoker.com [ C:\USERS\CHRISKELLY\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
    .partypoker.com [ C:\USERS\CHRISKELLY\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
    .partypoker.com [ C:\USERS\CHRISKELLY\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
    .partypoker.com [ C:\USERS\CHRISKELLY\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
    .partypoker.com [ C:\USERS\CHRISKELLY\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
    .partypoker.com [ C:\USERS\CHRISKELLY\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
    .zedo.com [ C:\USERS\CHRISKELLY\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
    .trafficmp.com [ C:\USERS\CHRISKELLY\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
    .trafficmp.com [ C:\USERS\CHRISKELLY\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
    .internet-security-serial.blogspot.com [ C:\USERS\CHRISKELLY\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
    .internet-security-serial.blogspot.com [ C:\USERS\CHRISKELLY\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
    .mediafire.com [ C:\USERS\CHRISKELLY\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
    .mediafire.com [ C:\USERS\CHRISKELLY\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
    .mediafire.com [ C:\USERS\CHRISKELLY\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
    fidelity.rotator.hadj7.adjuggler.net [ C:\USERS\CHRISKELLY\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
    fidelity.rotator.hadj7.adjuggler.net [ C:\USERS\CHRISKELLY\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
    .collective-media.net [ C:\USERS\CHRISKELLY\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
    .collective-media.net [ C:\USERS\CHRISKELLY\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
    .collective-media.net [ C:\USERS\CHRISKELLY\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
    .collective-media.net [ C:\USERS\CHRISKELLY\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
    .revsci.net [ C:\USERS\CHRISKELLY\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
    .invitemedia.com [ C:\USERS\CHRISKELLY\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
    .findology.com [ C:\USERS\CHRISKELLY\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
    .lg2.solution.weborama.fr [ C:\USERS\CHRISKELLY\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
    .lg2.solution.weborama.fr [ C:\USERS\CHRISKELLY\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
    .lg2.solution.weborama.fr [ C:\USERS\CHRISKELLY\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
    .lg2.solution.weborama.fr [ C:\USERS\CHRISKELLY\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
    ad.yieldmanager.com [ C:\USERS\CHRISKELLY\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
    dc.tremormedia.com [ C:\USERS\CHRISKELLY\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
    www4.smartadserver.com [ C:\USERS\CHRISKELLY\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
    .ad-emea.doubleclick.net [ C:\USERS\CHRISKELLY\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
    .ad-emea.doubleclick.net [ C:\USERS\CHRISKELLY\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
    .ad-emea.doubleclick.net [ C:\USERS\CHRISKELLY\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
    ad-emea.doubleclick.net [ C:\USERS\CHRISKELLY\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
    ad-emea.doubleclick.net [ C:\USERS\CHRISKELLY\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
    .ar.atwola.com [ C:\USERS\CHRISKELLY\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
    .tradedoubler.com [ C:\USERS\CHRISKELLY\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
    .tradedoubler.com [ C:\USERS\CHRISKELLY\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
    .banners.victor.com [ C:\USERS\CHRISKELLY\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
    .mediaplex.com [ C:\USERS\CHRISKELLY\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
    .traffic-update.co.uk [ C:\USERS\CHRISKELLY\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
    .traffic-update.co.uk [ C:\USERS\CHRISKELLY\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
    .traffic-update.co.uk [ C:\USERS\CHRISKELLY\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
    .collective-media.net [ C:\USERS\CHRISKELLY\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
    .revsci.net [ C:\USERS\CHRISKELLY\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
    .lucidmedia.com [ C:\USERS\CHRISKELLY\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
    .adbrite.com [ C:\USERS\CHRISKELLY\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
    www.googleadservices.com [ C:\USERS\CHRISKELLY\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
    .atdmt.com [ C:\USERS\CHRISKELLY\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
    .atdmt.com [ C:\USERS\CHRISKELLY\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
    .adviva.net [ C:\USERS\CHRISKELLY\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
    .pro-market.net [ C:\USERS\CHRISKELLY\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
    .pro-market.net [ C:\USERS\CHRISKELLY\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
    www.googleadservices.com [ C:\USERS\CHRISKELLY\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
    .adtech.de [ C:\USERS\CHRISKELLY\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
    .adtech.de [ C:\USERS\CHRISKELLY\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
    www.googleadservices.com [ C:\USERS\CHRISKELLY\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
    www.hxtrack.com [ C:\USERS\CHRISKELLY\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
    www.googleadservices.com [ C:\USERS\CHRISKELLY\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
    .ihg.db.advertising.com [ C:\USERS\CHRISKELLY\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
    www.googleadservices.com [ C:\USERS\CHRISKELLY\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
    www.googleadservices.com [ C:\USERS\CHRISKELLY\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
    statse.webtrendslive.com [ C:\USERS\CHRISKELLY\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
    www.googleadservices.com [ C:\USERS\CHRISKELLY\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
    www.googleadservices.com [ C:\USERS\CHRISKELLY\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
    .doubleclick.net [ C:\USERS\CHRISKELLY\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
    www.googleadservices.com [ C:\USERS\CHRISKELLY\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
    .microsoftsto.112.2o7.net [ C:\USERS\CHRISKELLY\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
    .apmebf.com [ C:\USERS\CHRISKELLY\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
    .247realmedia.com [ C:\USERS\CHRISKELLY\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
    .uk.at.atwola.com [ C:\USERS\CHRISKELLY\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
    .adtech.de [ C:\USERS\CHRISKELLY\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
    .adtech.de [ C:\USERS\CHRISKELLY\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
    .ipcmedia.122.2o7.net [ C:\USERS\CHRISKELLY\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
    .revsci.net [ C:\USERS\CHRISKELLY\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
    .invitemedia.com [ C:\USERS\CHRISKELLY\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
    .bs.serving-sys.com [ C:\USERS\CHRISKELLY\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
    .adtech.de [ C:\USERS\CHRISKELLY\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
    .adtech.de [ C:\USERS\CHRISKELLY\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
    .aimfar.solution.weborama.fr [ C:\USERS\CHRISKELLY\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
    .myaccount.creation.co.uk [ C:\USERS\CHRISKELLY\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
    .myaccount.creation.co.uk [ C:\USERS\CHRISKELLY\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
    .burstnet.com [ C:\USERS\CHRISKELLY\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
    .adtech.de [ C:\USERS\CHRISKELLY\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
    .adtech.de [ C:\USERS\CHRISKELLY\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
    .adtech.de [ C:\USERS\CHRISKELLY\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
    .adtech.de [ C:\USERS\CHRISKELLY\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
    .adtech.de [ C:\USERS\CHRISKELLY\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
    .revsci.net [ C:\USERS\CHRISKELLY\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
    .media6degrees.com [ C:\USERS\CHRISKELLY\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
    .revsci.net [ C:\USERS\CHRISKELLY\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
    uk.sitestat.com [ C:\USERS\CHRISKELLY\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
    uk.sitestat.com [ C:\USERS\CHRISKELLY\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
    .adtech.de [ C:\USERS\CHRISKELLY\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
    .uk.at.atwola.com [ C:\USERS\CHRISKELLY\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
    .adtech.de [ C:\USERS\CHRISKELLY\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
    .adtech.de [ C:\USERS\CHRISKELLY\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
    .uk.at.atwola.com [ C:\USERS\CHRISKELLY\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
    .uk.at.atwola.com [ C:\USERS\CHRISKELLY\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
    .clickfuse.com [ C:\USERS\CHRISKELLY\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
    .adtech.de [ C:\USERS\CHRISKELLY\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
    .adtech.de [ C:\USERS\CHRISKELLY\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
    .revsci.net [ C:\USERS\CHRISKELLY\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
    .adtech.de [ C:\USERS\CHRISKELLY\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
    .revsci.net [ C:\USERS\CHRISKELLY\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
    .invitemedia.com [ C:\USERS\CHRISKELLY\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
    .adtech.de [ C:\USERS\CHRISKELLY\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
    .adtech.de [ C:\USERS\CHRISKELLY\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
    .adtech.de [ C:\USERS\CHRISKELLY\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
    .tacoda.at.atwola.com [ C:\USERS\CHRISKELLY\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
    .serving-sys.com [ C:\USERS\CHRISKELLY\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
    .adtech.de [ C:\USERS\CHRISKELLY\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
    .atdmt.com [ C:\USERS\CHRISKELLY\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
    .atdmt.com [ C:\USERS\CHRISKELLY\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
    .atdmt.com [ C:\USERS\CHRISKELLY\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
    .adbrite.com [ C:\USERS\CHRISKELLY\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
    .adbrite.com [ C:\USERS\CHRISKELLY\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
    .adbrite.com [ C:\USERS\CHRISKELLY\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
    .adbrite.com [ C:\USERS\CHRISKELLY\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
    .mediabrandsww.com [ C:\USERS\CHRISKELLY\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
    ad.yieldmanager.com [ C:\USERS\CHRISKELLY\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
    .fastclick.net [ C:\USERS\CHRISKELLY\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
    .statcounter.com [ C:\USERS\CHRISKELLY\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
    .revsci.net [ C:\USERS\CHRISKELLY\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
    ad.yieldmanager.com [ C:\USERS\CHRISKELLY\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
    ad.yieldmanager.com [ C:\USERS\CHRISKELLY\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
    www.googleadservices.com [ C:\USERS\CHRISKELLY\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
    .revsci.net [ C:\USERS\CHRISKELLY\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
    .revsci.net [ C:\USERS\CHRISKELLY\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
    .revsci.net [ C:\USERS\CHRISKELLY\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
    .revsci.net [ C:\USERS\CHRISKELLY\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
    .revsci.net [ C:\USERS\CHRISKELLY\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
    .revsci.net [ C:\USERS\CHRISKELLY\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
    .revsci.net [ C:\USERS\CHRISKELLY\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
    .revsci.net [ C:\USERS\CHRISKELLY\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
    .revsci.net [ C:\USERS\CHRISKELLY\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
    .revsci.net [ C:\USERS\CHRISKELLY\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
    .collective-media.net [ C:\USERS\CHRISKELLY\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
    .collective-media.net [ C:\USERS\CHRISKELLY\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
    .collective-media.net [ C:\USERS\CHRISKELLY\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
    .mediaplex.com [ C:\USERS\CHRISKELLY\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
    .media6degrees.com [ C:\USERS\CHRISKELLY\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
    .media6degrees.com [ C:\USERS\CHRISKELLY\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
    .media6degrees.com [ C:\USERS\CHRISKELLY\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
    .media6degrees.com [ C:\USERS\CHRISKELLY\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
    .media6degrees.com [ C:\USERS\CHRISKELLY\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
    .media6degrees.com [ C:\USERS\CHRISKELLY\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
    .doubleclick.net [ C:\USERS\CHRISKELLY\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
    .invitemedia.com [ C:\USERS\CHRISKELLY\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
    .invitemedia.com [ C:\USERS\CHRISKELLY\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
    .invitemedia.com [ C:\USERS\CHRISKELLY\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
    .invitemedia.com [ C:\USERS\CHRISKELLY\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
    .advertising.com [ C:\USERS\CHRISKELLY\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
    .advertising.com [ C:\USERS\CHRISKELLY\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
    .advertising.com [ C:\USERS\CHRISKELLY\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
    ad.yieldmanager.com [ C:\USERS\CHRISKELLY\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
    .tribalfusion.com [ C:\USERS\CHRISKELLY\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
    .collective-media.net [ C:\USERS\CHRISKELLY\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
    .serving-sys.com [ C:\USERS\CHRISKELLY\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
    .serving-sys.com [ C:\USERS\CHRISKELLY\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
    .at.atwola.com [ C:\USERS\CHRISKELLY\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
    .tacoda.at.atwola.com [ C:\USERS\CHRISKELLY\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
    .tacoda.at.atwola.com [ C:\USERS\CHRISKELLY\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
    .tacoda.at.atwola.com [ C:\USERS\CHRISKELLY\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
    .at.atwola.com [ C:\USERS\CHRISKELLY\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
    .tacoda.net [ C:\USERS\CHRISKELLY\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
    .advertising.com [ C:\USERS\CHRISKELLY\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
    .advertising.com [ C:\USERS\CHRISKELLY\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
     
  14. Gefstar

    Gefstar TS Rookie Topic Starter

    In response to your question regarding the pop ups - The answer is NO, I have not had a problem with them or being diverted from searches to viral adverts
     
  15. Bobbye

    Bobbye Helper on the Fringe Posts: 16,335   +36

    About the Tracking Cookies:
    The only account name showing is Chris Kelley. So that user had thousands of Tracking Cookies. It appears that these have never been cleaned or that there is no ad or Cookie control.

    Reset Cookies

    For Internet Explorer: Internet Options (through Tools or Control Panel) Privacy tab> Advanced button> CHECK 'override automatic Cookie handling'> CHECK 'accept first party Cookies'> CHECK 'Block third party Cookies'> CHECK 'allow per session Cookies'> Apply> OK.

    For Firefox: Tools> Options> Privacy> Cookies> CHECK ‘accept Cookies from Sites’> UNCHECK 'accept third party Cookies'> Set Keep until 'they expire'. This will allow you to keep Cookies for registered sites and prevent or remove others. (Note: for Firefox v3.5, after Privacy click on 'use custom settings for History.')

    I suggest using the following two add-on for Firefox. They will prevent the Tracking Cookies that come from ads and banners and other sources:
    AdBlock Plus
    Easy List

    For Chrome: Tools> Options> Under The Hood> Privacy Section> CHECK 'Restrict how third party Cookies can be used'> Close.
    (First-party and third-party cookies can be set by the website you're visiting and websites that have items embedded in the website you're visiting. But when you next visit the website, only first-party cookie information is sent to the website. Third-party cookie information isn't sent back to the websites that originally set the third-party cookies.)

    Most of the Cookies were the usual internet junk.
    But some were specific and if these sites are being visited, this account is pirating software, visiting sites with porn:
    =============================================

    TFC (Temp File Cleaner)

    Download TFC to your desktop
    • Open the file and close any other windows.
    • It will close all programs itself when run, make sure to let it run uninterrupted.
    • Click the Start button to begin the process. The program should not take long to finish its job
    • Once its finished it should reboot your machine, if not, do this yourself to ensure a complete clean

    TFC only cleans temp folders. TFC will not clean URL history, prefetch, or cookies. Depending on how often someone cleans their temp folders, their system hardware, and how many accounts are present, it can take anywhere from a few seconds to a minute or more. TFC will completely clear all temp files where other temp file cleaners may fail. TFC requires a reboot immediately after running. Be sure to save any unsaved work before running TFC.

    TFC (Temp File Cleaner) will clear out all temp folders for all user accounts (temp, IE temp, java, FF, Opera, Chrome, Safari), including Administrator, All Users, LocalService, NetworkService, and any other accounts in the user folder.
    ===========================================
    Since so many crack, serial and keygens sites have been accessed, it is likely that there are pirated files, programs, apps, etc. on the system.
    Since the initial problems have been resolved:
    Removing all of the tools we used and the files and folders they created
    • Uninstall ComboFix and all Backups of the files it deleted
    • Click START> then RUN
    • Now type Combofix /Uninstall in the runbox and click OK. Note the space between the X and the U, it needs to be there.
      [​IMG]
    • Download OTCleanIt by OldTimer and save it to your Desktop.
    • Double click OTCleanIt.exe.
    • Click the CleanUp! button.
    • Select Yes when the "Begin cleanup Process?" prompt appears.
    • If you are prompted to Reboot during the cleanup, select Yes.
    • The tool will delete itself once it finishes.
    -----
    Note: If you receive a warning from your firewall or other security programs regarding OTC attempting to contact the internet, please allow it to do so.

    Note: If any tool, file or folder (belonging to the program we have used) hasn't been deleted, please delete it manually.
    ------------------------------------------
    • You should now set a new Restore Point and remove the old restore points to prevent infection from any previous Restore Points.
    • Go to Start > All Programs > Accessories > System Tools
    • Click "System Restore".
    • Choose "Create a Restore Point" on the first screen then click "Next".
    • Give the Restore Point a name> click "Create".
    • Go back and follow the path to > System Tools.
      [*]Choose Disc Cleanup
      [*]Click "OK" to select the partition or drive you want.
      [*]Click the "More Options" Tab.
      [*]Click "Clean Up" in the System Restore section to remove all previous Restore Points except the newly created one.


    Empty the Recycle Bin
     
Topic Status:
Not open for further replies.

Similar Topics

Add New Comment

You need to be a member to leave a comment. Join thousands of tech enthusiasts and participate.
TechSpot Account You may also...