1. Computer problem? Tech Support Guy is completely free -- paid for by advertisers and donations. Click here to join today! If you're new to Tech Support Guy, we highly recommend that you visit our Guide for New Members.

possible malware

Discussion in 'Virus & Other Malware Removal' started by richardriley25, Sep 7, 2012.

Thread Status:
Not open for further replies.
Advertisement
  1. richardriley25

    richardriley25 Thread Starter

    Joined:
    Sep 7, 2012
    Messages:
    6
    When i log onto online banking or facebook i log in as normal and then another page comes up asking for more indepth personal details. When my wife phoned the bank and asked about this page they said it was neferious, however it appears to be still on the bank page and doesn't like a lot of other identity theft issues transfer to another site, i have run my mcafee, and it says theres no threats iv tried a system restore to get a gauge of when it was picked up and i am now wondering wether it is my pc or the sites. Any help on irradicating the problem would be appreciated.
     
  2. eddie5659

    eddie5659 Moderator Malware Specialist

    Joined:
    Mar 19, 2001
    Messages:
    34,343
    Hiya and welcome to Tech Support Guy :)

    Are you still having this problem? If so, I would advise you to log onto a different computer and change any passwords relating to FaceBook/banking. Also, try not to use this computer until the infection (if there) is removed.

    Can you now do the following for me:

    Download Security Check from here.
    • Save it to your Desktop.
    • Double click SecurityCheck.exe and follow the onscreen instructions inside of the black box.
    • A Notepad document should open automatically called checkup.txt; please post the contents of that document.





    Please download Malwarebytes' Anti-Malware from Here

    Double Click mbam-setup.exe to install the application.
    • Make sure a checkmark is placed next to Update Malwarebytes' Anti-Malware and Launch Malwarebytes' Anti-Malware, then click Finish.
    • If an update is found, it will download and install the latest version.
    • Once the program has loaded, select "Perform Quick Scan", then click Scan.
    • The scan may take some time to finish, so please be patient.
    • When the scan is complete, click OK, then Show Results to view the results.
    • Make sure that everything is checked, and click Remove Selected.
    • When disinfection is completed, a log will open in Notepad and you may be prompted to Restart.(See Extra Note)
    • The log is automatically saved by MBAM and can be viewed by clicking the Logs tab in MBAM.
    • Copy&Paste the entire report in your next reply.
    Extra Note:
    If MBAM encounters a file that is difficult to remove, you will be presented with 1 of 2 prompts, click OK to either and let MBAM proceed with the disinfection process, if asked to restart the computer, please do so immediatly.






    Download and scan with SUPERAntiSpyware Free Edition for Home Users
    • Double-click SUPERAntiSpyware.exe and use the default settings for installation.
    • An icon will be created on your desktop. Double-click that icon to launch the program.
    • If asked to update the program definitions, click "Yes". If not, update the definitions before scanning by selecting "Check for Updates". (If you encounter any problems while downloading the updates, manually download and unzip them from here.)
    • Under "Configuration and Preferences", click the Preferences button.
    • Click the Scanning Control tab.
    • Under Scanner Options make sure the following are checked (leave all others unchecked):
      • Close browsers before scanning.
      • Scan for tracking cookies.
      • Terminate memory threats before quarantining.
    • Click the "Home" button to leave the control center screen.
    • On the right, under "Complete Scan", choose Perform Complete Scan.
    • Click Scan your computer.
    • On the left, select all fixed drives.
    • Click "Start Complete Scan" to start the scan. Please be patient while it scans your computer.
    • After the scan is complete, a Scan Summary box will appear with potentially harmful items that were detected. Click "Continue".
    • Make sure everything has a checkmark next to it and click "Next".
    • A notification will appear that "Quarantine and Removal is Complete". Click "Remove Threats" and then click the "Finish" button to return to the main menu.
    • If asked if you want to reboot, click "Yes".
    • To retrieve the removal information after reboot, launch SUPERAntispyware again.
      • Click View Scan Logs.
        [*]Under Scanner Logs, double-click SUPERAntiSpyware Scan Log.
        [*]If there are several logs, click the current dated log and press View log. A text file will open in your default text editor.
        [*]Please copy and paste the Scan Log results in your next reply.
      [*]Click Close to exit the program.


    Please include the MBAM log, SUPERAntiSpyware Scan Log and checkup.txt in your next reply

    eddie
     
  3. richardriley25

    richardriley25 Thread Starter

    Joined:
    Sep 7, 2012
    Messages:
    6
    Results of screen317's Security Check version 0.99.50
    Windows Vista Service Pack 2 x86 (UAC is disabled!)
    Internet Explorer 9
    ``````````````Antivirus/Firewall Check:``````````````
    Windows Security Center service is not running! This report may not be accurate!
    AVG Internet Security 2012
    Antivirus up to date!
    `````````Anti-malware/Other Utilities Check:`````````
    Java(TM) 6 Update 11
    Java version out of Date!
    Adobe Flash Player 11.4.402.265
    Mozilla Firefox (14.0.1)
    Google Chrome 20.0.1132.57
    Google Chrome 21.0.1180.89
    ````````Process Check: objlist.exe by Laurent````````
    `````````````````System Health check`````````````````
    Total Fragmentation on Drive C: 0 %
    ````````````````````End of Log``````````````````````
     
  4. richardriley25

    richardriley25 Thread Starter

    Joined:
    Sep 7, 2012
    Messages:
    6
    first part done just doing second part (malwarebytes) now.
     
  5. richardriley25

    richardriley25 Thread Starter

    Joined:
    Sep 7, 2012
    Messages:
    6
    ok couple of problems when i try downloading malwarebytes anti-malware it redirects with error 404, so i tried the super antispyware and that just redirected to google.
     
  6. richardriley25

    richardriley25 Thread Starter

    Joined:
    Sep 7, 2012
    Messages:
    6
    Database version: v2012.09.16.11
    Windows Vista Service Pack 2 x86 NTFS
    Internet Explorer 9.0.8112.16421
    mum and dad :: MUMANDDAD-PC [administrator]
    Protection: Enabled
    16/09/2012 20:39:08
    mbam-log-2012-09-16 (20-39-08).txt
    Scan type: Quick scan
    Scan options enabled: Memory | Startup | Registry | File System | Heuristics/Extra | Heuristics/Shuriken | PUP | PUM
    Scan options disabled: P2P
    Objects scanned: 405130
    Time elapsed: 8 minute(s), 38 second(s)
    Memory Processes Detected: 0
    (No malicious items detected)
    Memory Modules Detected: 0
    (No malicious items detected)
    Registry Keys Detected: 2
    HKCU\SOFTWARE\CLASSES\CLSID\{42AEDC87-2188-41FD-B9A3-0C966FEABEC1}\INPROCSERVER32 (Trojan.Zaccess) -> Quarantined and deleted successfully.
    HKLM\SYSTEM\CurrentControlSet\Services\Micorsoft Windows Service (Trojan.Agent) -> Quarantined and deleted successfully.
    Registry Values Detected: 3
    HKCU\Environment|AVAPP (Rogue.PersonalAntiVirus) -> Data: C:\Program Files\PersonalAV -> Quarantined and deleted successfully.
    HKCU\Environment|AVUNINST (Rogue.PersonalAntiVirus) -> Data: C:\Program Files\Common Files\Uninstall\PersonalAV\Uninstall.lnk -> Quarantined and deleted successfully.
    HKCU\SOFTWARE\CLASSES\CLSID\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InprocServer32| (Trojan.Zaccess) -> Data: C:\Users\mum and dad\AppData\Local\{3ffd7c43-b9cf-b37d-f238-706fa90aab75}\n. -> Quarantined and deleted successfully.
    Registry Data Items Detected: 0
    (No malicious items detected)
    Folders Detected: 3
    C:\Program Files\Common Files\Uninstall\PersonalAV (Rogue.PersonalAntiVirus) -> Quarantined and deleted successfully.
    C:\Program Files\PersonalAV (Rogue.PersonalAntiVirus) -> Quarantined and deleted successfully.
    C:\ProgramData\Microsoft\Windows\Start Menu\PersonalAV (Rogue.PersonalAntiVirus) -> Quarantined and deleted successfully.
    Files Detected: 13
    C:\Users\mum and dad\AppData\Roaming\Waimwa\agizu.exe (Spyware.Zbot.DGen) -> Quarantined and deleted successfully.
    C:\Users\mum and dad\AppData\Local\Temp\0.20601714958342232c.exe (Trojan.Happili) -> Quarantined and deleted successfully.
    C:\Users\mum and dad\AppData\Local\Temp\tmp06a1af10\citadelbuild.exe (Trojan.Inject) -> Quarantined and deleted successfully.
    C:\Users\mum and dad\AppData\Local\Temp\tmp0d4aebec\citadelbuild.exe (Spyware.Password) -> Quarantined and deleted successfully.
    C:\Users\mum and dad\AppData\Local\Temp\tmp1ed8c334\citadelbuild.exe (Spyware.Password) -> Quarantined and deleted successfully.
    C:\Users\mum and dad\AppData\Local\Temp\tmp24223e93\citadelbuild.exe (Spyware.Password) -> Quarantined and deleted successfully.
    C:\Users\mum and dad\AppData\Local\Temp\tmp3b1f8083\citadelbuild.exe (Trojan.Inject) -> Quarantined and deleted successfully.
    C:\Users\mum and dad\AppData\Local\Temp\tmpbd7d8c81\citadelbuild.exe (Spyware.Password) -> Quarantined and deleted successfully.
    C:\Users\mum and dad\AppData\Local\Temp\tmpe0b4781f\citadelbuild.exe (Spyware.Password) -> Quarantined and deleted successfully.
    C:\Users\mum and dad\AppData\Local\Temp\tmpe3c115a8\citadelbuild.exe (Spyware.Password) -> Quarantined and deleted successfully.
    C:\Users\mum and dad\AppData\Local\Temp\tmp57985384\citadelbuild.exe (Spyware.Password) -> Quarantined and deleted successfully.
    C:\Users\mum and dad\AppData\Local\Temp\tmp8eaf1b50\citadelbuild.exe (Spyware.Password) -> Quarantined and deleted successfully.
    C:\Users\mum and dad\AppData\Local\Temp\tmpa02b02e7\citadelbuild.exe (Trojan.Inject) -> Quarantined and deleted successfully.
    (end)


    went through a different site to get mbam
     
  7. richardriley25

    richardriley25 Thread Starter

    Joined:
    Sep 7, 2012
    Messages:
    6
    SUPERAntiSpyware Scan Log
    http://www.superantispyware.com
    Generated 09/16/2012 at 10:40 PM
    Application Version : 5.5.1016
    Core Rules Database Version : 9236
    Trace Rules Database Version: 7048
    Scan type : Complete Scan
    Total Scan Time : 01:22:44
    Operating System Information
    Windows Vista Home Premium 32-bit, Service Pack 2 (Build 6.00.6002)
    UAC Off - Administrator
    Memory items scanned : 691
    Memory threats detected : 0
    Registry items scanned : 35351
    Registry threats detected : 0
    File items scanned : 205990
    File threats detected : 330
    Rogue.PersonalAntiVirus
    C:\Windows\Tasks\PersonalAV.job
    Adware.Tracking Cookie
    C:\Users\mum and dad\AppData\Roaming\Microsoft\Windows\Cookies\74A4SSTO.txt [ /atdmt.combing.com ]
    C:\Users\mum and dad\AppData\Roaming\Microsoft\Windows\Cookies\AN7UXFM5.txt [ /delivery.adserver.manutd.com ]
    C:\Users\mum and dad\AppData\Roaming\Microsoft\Windows\Cookies\DJ258651.txt [ /xiti.com ]
    C:\Users\mum and dad\AppData\Roaming\Microsoft\Windows\Cookies\B0EDYB7W.txt [ /liveperson.net ]
    C:\Users\mum and dad\AppData\Roaming\Microsoft\Windows\Cookies\4JAYMQML.txt [ /www.qsstats.com ]
    C:\Users\mum and dad\AppData\Roaming\Microsoft\Windows\Cookies\61CQNLC8.txt [ /at.atwola.com ]
    C:\Users\mum and dad\AppData\Roaming\Microsoft\Windows\Cookies\A50OCT55.txt [ /ar.atwola.com ]
    C:\Users\mum and dad\AppData\Roaming\Microsoft\Windows\Cookies\HT5J55RP.txt [ /traveladvertising.com ]
    C:\Users\mum and dad\AppData\Roaming\Microsoft\Windows\Cookies\4NF585TS.txt [ /kontera.com ]
    C:\Users\mum and dad\AppData\Roaming\Microsoft\Windows\Cookies\6KSC2PEI.txt [ /www.googleadservices.com ]
    C:\Users\mum and dad\AppData\Roaming\Microsoft\Windows\Cookies\6UIZMCVF.txt [ /media6degrees.com ]
    C:\Users\mum and dad\AppData\Roaming\Microsoft\Windows\Cookies\4EMYYVLP.txt [ /ww251.smartadserver.com ]
    C:\Users\mum and dad\AppData\Roaming\Microsoft\Windows\Cookies\QHU7ZO1Y.txt [ /tacoda.at.atwola.com ]
    C:\Users\mum and dad\AppData\Roaming\Microsoft\Windows\Cookies\CTDQ3VKB.txt [ /statse.webtrendslive.com ]
    C:\Users\mum and dad\AppData\Roaming\Microsoft\Windows\Cookies\NI0C8ROU.txt [ /www.googleadservices.com ]
    C:\Users\mum and dad\AppData\Roaming\Microsoft\Windows\Cookies\MSUYXP2A.txt [ /www4.smartadserver.com ]
    C:\Users\mum and dad\AppData\Roaming\Microsoft\Windows\Cookies\7GJ2EUGU.txt [ /liveperson.net ]
    C:\Users\mum and dad\AppData\Roaming\Microsoft\Windows\Cookies\GAR0GLQ4.txt [ /liveperson.net ]
    C:\Users\mum and dad\AppData\Roaming\Microsoft\Windows\Cookies\AGILB6BQ.txt [ /mediaplex.com ]
    C:\Users\mum and dad\AppData\Roaming\Microsoft\Windows\Cookies\BXAH0A7L.txt [ /www.grapeshot-media.net ]
    C:\Users\mum and dad\AppData\Roaming\Microsoft\Windows\Cookies\6FQAQGYY.txt [ /tracking.dc-storm.com ]
    C:\Users\mum and dad\AppData\Roaming\Microsoft\Windows\Cookies\NHCTKVFA.txt [ /server.lon.liveperson.net ]
    C:\Users\mum and dad\AppData\Roaming\Microsoft\Windows\Cookies\R2KMTZKI.txt [ /tribalfusion.com ]
    C:\Users\mum and dad\AppData\Roaming\Microsoft\Windows\Cookies\0X6UAQB5.txt [ /imrworldwide.com ]
    C:\Users\mum and dad\AppData\Roaming\Microsoft\Windows\Cookies\NCEGTC1U.txt [ /ad.yieldmanager.com ]
    C:\Users\mum and dad\AppData\Roaming\Microsoft\Windows\Cookies\YN1SSW1W.txt [ /adviva.net ]
    C:\Users\mum and dad\AppData\Roaming\Microsoft\Windows\Cookies\PAX2HC1U.txt [ /liveperson.net ]
    C:\Users\mum and dad\AppData\Roaming\Microsoft\Windows\Cookies\SCWV9ZKH.txt [ /revsci.net ]
    C:\Users\mum and dad\AppData\Roaming\Microsoft\Windows\Cookies\9FHXLNNC.txt [ /fastclick.net ]
    C:\Users\mum and dad\AppData\Roaming\Microsoft\Windows\Cookies\LY7Y5QEZ.txt [ /ad.360yield.com ]
    C:\Users\mum and dad\AppData\Roaming\Microsoft\Windows\Cookies\3ZAC66CY.txt [ /atdmt.com ]
    C:\Users\mum and dad\AppData\Roaming\Microsoft\Windows\Cookies\K1JZOQ6D.txt [ /clickfuse.com ]
    C:\Users\mum and dad\AppData\Roaming\Microsoft\Windows\Cookies\QR1OLH0L.txt [ /www.ist-track.com ]
    C:\Users\mum and dad\AppData\Roaming\Microsoft\Windows\Cookies\867742WV.txt [ /2o7.net ]
    C:\Users\mum and dad\AppData\Roaming\Microsoft\Windows\Cookies\0S8X79S2.txt [ /track.adform.net ]
    C:\Users\mum and dad\AppData\Roaming\Microsoft\Windows\Cookies\2TPM34ZS.txt [ /tacoda.net ]
    C:\Users\mum and dad\AppData\Roaming\Microsoft\Windows\Cookies\KHBLHN0W.txt [ /www.skyscanner.net ]
    C:\Users\mum and dad\AppData\Roaming\Microsoft\Windows\Cookies\ZGO7LJCQ.txt [ /audience2media.com ]
    C:\Users\mum and dad\AppData\Roaming\Microsoft\Windows\Cookies\2GP7ZMPZ.txt [ /www.googleadservices.com ]
    C:\Users\mum and dad\AppData\Roaming\Microsoft\Windows\Cookies\24E73LXR.txt [ /dmtracker.com ]
    C:\Users\mum and dad\AppData\Roaming\Microsoft\Windows\Cookies\NTO455N1.txt [ /exoclick.com ]
    C:\Users\mum and dad\AppData\Roaming\Microsoft\Windows\Cookies\2LZB69K4.txt [ /www.googleadservices.com ]
    C:\Users\mum and dad\AppData\Roaming\Microsoft\Windows\Cookies\OHH4FHKA.txt [ /adultfriendfinder.com ]
    C:\Users\mum and dad\AppData\Roaming\Microsoft\Windows\Cookies\WZM4P4EE.txt [ /o1.qnsr.com ]
    C:\Users\mum and dad\AppData\Roaming\Microsoft\Windows\Cookies\SHS53W4K.txt [ /serving-sys.com ]
    C:\Users\mum and dad\AppData\Roaming\Microsoft\Windows\Cookies\1SR3IIRF.txt [ /estat.com ]
    C:\Users\mum and dad\AppData\Roaming\Microsoft\Windows\Cookies\QA5AL2J6.txt [ /histats.com ]
    C:\Users\mum and dad\AppData\Roaming\Microsoft\Windows\Cookies\9EX5I2PB.txt [ /h.atdmt.com ]
    C:\Users\mum and dad\AppData\Roaming\Microsoft\Windows\Cookies\QBMMRGDC.txt [ /myaccount.sky.com ]
    C:\Users\mum and dad\AppData\Roaming\Microsoft\Windows\Cookies\D4OECH0N.txt [ /qnsr.com ]
    C:\Users\mum and dad\AppData\Roaming\Microsoft\Windows\Cookies\GO0GKTK0.txt [ /uk.sitestat.com ]
    C:\Users\mum and dad\AppData\Roaming\Microsoft\Windows\Cookies\FDVGGSOZ.txt [ /uk.sitestat.com ]
    C:\Users\mum and dad\AppData\Roaming\Microsoft\Windows\Cookies\CYEQSBWZ.txt [ /ads.pubmatic.com ]
    C:\Users\mum and dad\AppData\Roaming\Microsoft\Windows\Cookies\M8IBXCG1.txt [ /c.atdmt.com ]
    C:\Users\mum and dad\AppData\Roaming\Microsoft\Windows\Cookies\SPOYQ75Q.txt [ /adform.net ]
    C:\Users\mum and dad\AppData\Roaming\Microsoft\Windows\Cookies\VE24J3I3.txt [ /advertising.com ]
    C:\Users\mum and dad\AppData\Roaming\Microsoft\Windows\Cookies\JRR16C65.txt [ /www.qsstats.com ]
    C:\Users\mum and dad\AppData\Roaming\Microsoft\Windows\Cookies\SZ9LJ46O.txt [ /specificclick.net ]
    C:\Users\mum and dad\AppData\Roaming\Microsoft\Windows\Cookies\4723TRNA.txt [ /yieldmanager.net ]
    C:\Users\mum and dad\AppData\Roaming\Microsoft\Windows\Cookies\8SV0SHFH.txt [ /adserver.adtechus.com ]
    C:\Users\mum and dad\AppData\Roaming\Microsoft\Windows\Cookies\5FFHO2K5.txt [ /adtech.de ]
    C:\Users\mum and dad\AppData\Roaming\Microsoft\Windows\Cookies\OCQLY4SG.txt [ /bs.serving-sys.com ]
    C:\Users\mum and dad\AppData\Roaming\Microsoft\Windows\Cookies\7785OIX0.txt [ /lucidmedia.com ]
    C:\Users\mum and dad\AppData\Roaming\Microsoft\Windows\Cookies\9ZAEE85L.txt [ /invitemedia.com ]
    C:\Users\mum and dad\AppData\Roaming\Microsoft\Windows\Cookies\ZI6HESLJ.txt [ /uk.at.atwola.com ]
    C:\Users\mum and dad\AppData\Roaming\Microsoft\Windows\Cookies\0A7Y60CK.txt [ /ads.audience2media.com ]
    C:\Users\mum and dad\AppData\Roaming\Microsoft\Windows\Cookies\UTZXERID.txt [ /doubleclick.net ]
    C:\Users\mum and dad\AppData\Roaming\Microsoft\Windows\Cookies\ICQV5B85.txt [ /mm.chitika.net ]
    C:\Users\mum and dad\AppData\Roaming\Microsoft\Windows\Cookies\4ZXBFX1N.txt [ /www.googleadservices.com ]
    C:\Users\mum and dad\AppData\Roaming\Microsoft\Windows\Cookies\T69JQG44.txt [ /adbrite.com ]
    C:\Users\mum and dad\AppData\Roaming\Microsoft\Windows\Cookies\0WWF85QH.txt [ /www.googleadservices.com ]
    C:\Users\mum and dad\AppData\Roaming\Microsoft\Windows\Cookies\UUL8M7HG.txt [ /apmebf.com ]
    C:\Users\mum and dad\AppData\Roaming\Microsoft\Windows\Cookies\0I77YHIL.txt [ /collective-media.net ]
    C:\Users\mum and dad\AppData\Roaming\Microsoft\Windows\Cookies\N39DOKZI.txt [ /ads.footballmedia.com ]
    C:\Users\mum and dad\AppData\Roaming\Microsoft\Windows\Cookies\RSNFPOBW.txt [ /in.getclicky.com ]
    C:\Users\mum and dad\AppData\Roaming\Microsoft\Windows\Cookies\7Y2PE6G9.txt [ /statcounter.com ]
    C:\Users\mum and dad\AppData\Roaming\Microsoft\Windows\Cookies\NQ9039IK.txt [ /ru4.com ]
    C:\Users\mum and dad\AppData\Roaming\Microsoft\Windows\Cookies\N39Y8SC0.txt [ /atwola.com ]
    C:\Users\mum and dad\AppData\Roaming\Microsoft\Windows\Cookies\UG86R0Y1.txt [ /amazon-adsystem.com ]
    C:\Users\mum and dad\AppData\Roaming\Microsoft\Windows\Cookies\E7UXMMN6.txt [ /skyscanner.net ]
    C:\Users\mum and dad\AppData\Roaming\Microsoft\Windows\Cookies\IBTDTLJ8.txt [ /kaspersky.122.2o7.net ]
    C:\Users\mum and dad\AppData\Roaming\Microsoft\Windows\Cookies\QGRG60ZE.txt [ /smartadserver.com ]
    C:\Users\mum and dad\AppData\Roaming\Microsoft\Windows\Cookies\BQY0NZ1U.txt [ /zedo.com ]
    C:\Users\mum and dad\AppData\Roaming\Microsoft\Windows\Cookies\OZ3AMRYB.txt [ /www.googleadservices.com ]
    C:\Users\mum and dad\AppData\Roaming\Microsoft\Windows\Cookies\TBKPGF4W.txt [ /casalemedia.com ]
    C:\Users\mum and dad\AppData\Roaming\Microsoft\Windows\Cookies\FC3B1WV9.txt [ /virginmedia.com ]
    C:\Users\mum and dad\AppData\Roaming\Microsoft\Windows\Cookies\1D8A093D.txt [ /pro-market.net ]
    C:\Users\mum and dad\AppData\Roaming\Microsoft\Windows\Cookies\SO29W8D0.txt [ /www.googleadservices.com ]
    C:\Users\mum and dad\AppData\Roaming\Microsoft\Windows\Cookies\7YRMJTMX.txt [ /www.amateursex.com ]
    C:\Users\mum and dad\AppData\Roaming\Microsoft\Windows\Cookies\MGOK7IPZ.txt [ /insightexpressai.com ]
    C:\Users\mum and dad\AppData\Roaming\Microsoft\Windows\Cookies\U336ZM40.txt [ /www.googleadservices.com ]
    C:\Users\mum and dad\AppData\Roaming\Microsoft\Windows\Cookies\BYU1D45E.txt [ /amateursex.com ]
    C:\USERS\ALEX AND JAMES\AppData\Roaming\Microsoft\Windows\Cookies\H9P0CGX3.txt [ Cookie:alex and [email protected]/ ]
    C:\USERS\ALEX AND JAMES\AppData\Roaming\Microsoft\Windows\Cookies\0K921ZQ5.txt [ Cookie:alex and [email protected]/ ]
    C:\USERS\ALEX AND JAMES\AppData\Roaming\Microsoft\Windows\Cookies\NC2PK2A9.txt [ Cookie:alex and [email protected]/ ]
    C:\USERS\ALEX AND JAMES\AppData\Roaming\Microsoft\Windows\Cookies\ECMOLP5L.txt [ Cookie:alex and [email protected]/ ]
    C:\USERS\ALEX AND JAMES\AppData\Roaming\Microsoft\Windows\Cookies\TJR7SDLZ.txt [ Cookie:alex and [email protected]/ ]
    C:\USERS\ALEX AND JAMES\AppData\Roaming\Microsoft\Windows\Cookies\SC7XYF6A.txt [ Cookie:alex and [email protected]/ ]
    C:\USERS\ALEX AND JAMES\AppData\Roaming\Microsoft\Windows\Cookies\DGEWGLHC.txt [ Cookie:alex and [email protected]/ ]
    C:\USERS\ALEX AND JAMES\AppData\Roaming\Microsoft\Windows\Cookies\DYLDLJVO.txt [ Cookie:alex and [email protected]/ ]
    C:\USERS\ALEX AND JAMES\AppData\Roaming\Microsoft\Windows\Cookies\568AF6JP.txt [ Cookie:alex and [email protected]/ ]
    C:\USERS\ALEX AND JAMES\AppData\Roaming\Microsoft\Windows\Cookies\DAX73EPU.txt [ Cookie:alex and [email protected]/ ]
    C:\USERS\ALEX AND JAMES\AppData\Roaming\Microsoft\Windows\Cookies\SJLF09YV.txt [ Cookie:alex and [email protected]/ ]
    C:\USERS\ALEX AND JAMES\AppData\Roaming\Microsoft\Windows\Cookies\KD5P0AL1.txt [ Cookie:alex and [email protected]/ ]
    C:\USERS\ALEX AND JAMES\AppData\Roaming\Microsoft\Windows\Cookies\8BOKC98R.txt [ Cookie:alex and [email protected]/ ]
    C:\USERS\ALEX AND JAMES\AppData\Roaming\Microsoft\Windows\Cookies\ZUDJY4U1.txt [ Cookie:alex and [email protected]/ ]
    C:\USERS\ALEX AND JAMES\AppData\Roaming\Microsoft\Windows\Cookies\AEF099Z1.txt [ Cookie:alex and [email protected]/ ]
    C:\USERS\ALEX AND JAMES\AppData\Roaming\Microsoft\Windows\Cookies\Q9VNT3TW.txt [ Cookie:alex and [email protected]/cgi-bin ]
    C:\USERS\ALEX AND JAMES\AppData\Roaming\Microsoft\Windows\Cookies\2CUNBRND.txt [ Cookie:alex and [email protected]/ ]
    C:\USERS\ALEX AND JAMES\AppData\Roaming\Microsoft\Windows\Cookies\4BFMBP1R.txt [ Cookie:alex and [email protected]/ ]
    C:\USERS\ALEX AND JAMES\AppData\Roaming\Microsoft\Windows\Cookies\Y7HR2T9F.txt [ Cookie:alex and [email protected]/ ]
    C:\USERS\ALEX AND JAMES\AppData\Roaming\Microsoft\Windows\Cookies\VAKQZI5N.txt [ Cookie:alex and [email protected]/pagead/conversion/1071224783/ ]
    C:\USERS\ALEX AND JAMES\AppData\Roaming\Microsoft\Windows\Cookies\3V9OQFV2.txt [ Cookie:alex and [email protected]/ ]
    C:\USERS\ALEX AND JAMES\AppData\Roaming\Microsoft\Windows\Cookies\AP7DUEE3.txt [ Cookie:alex and [email protected]/ ]
    C:\USERS\ALEX AND JAMES\AppData\Roaming\Microsoft\Windows\Cookies\A1286QCJ.txt [ Cookie:alex and [email protected]/ ]
    C:\USERS\ALEX AND JAMES\AppData\Roaming\Microsoft\Windows\Cookies\J3865LE2.txt [ Cookie:alex and [email protected]/ ]
    C:\USERS\ALEX AND JAMES\Cookies\H9P0CGX3.txt [ Cookie:alex and [email protected]/ ]
    C:\USERS\ALEX AND JAMES\Cookies\0K921ZQ5.txt [ Cookie:alex and [email protected]/ ]
    C:\USERS\ALEX AND JAMES\Cookies\NC2PK2A9.txt [ Cookie:alex and [email protected]/ ]
    C:\USERS\ALEX AND JAMES\Cookies\ECMOLP5L.txt [ Cookie:alex and [email protected]/ ]
    C:\USERS\ALEX AND JAMES\Cookies\TJR7SDLZ.txt [ Cookie:alex and [email protected]/ ]
    C:\USERS\ALEX AND JAMES\Cookies\SC7XYF6A.txt [ Cookie:alex and [email protected]/ ]
    C:\USERS\ALEX AND JAMES\Cookies\DGEWGLHC.txt [ Cookie:alex and [email protected]/ ]
    C:\USERS\ALEX AND JAMES\Cookies\DYLDLJVO.txt [ Cookie:alex and [email protected]/ ]
    C:\USERS\ALEX AND JAMES\Cookies\568AF6JP.txt [ Cookie:alex and [email protected]/ ]
    C:\USERS\ALEX AND JAMES\Cookies\DAX73EPU.txt [ Cookie:alex and [email protected]/ ]
    C:\USERS\ALEX AND JAMES\Cookies\SJLF09YV.txt [ Cookie:alex and [email protected]/ ]
    C:\USERS\ALEX AND JAMES\Cookies\KD5P0AL1.txt [ Cookie:alex and [email protected]/ ]
    C:\USERS\ALEX AND JAMES\Cookies\8BOKC98R.txt [ Cookie:alex and [email protected]/ ]
    C:\USERS\ALEX AND JAMES\Cookies\ZUDJY4U1.txt [ Cookie:alex and [email protected]/ ]
    C:\USERS\ALEX AND JAMES\Cookies\AEF099Z1.txt [ Cookie:alex and [email protected]/ ]
    C:\USERS\ALEX AND JAMES\Cookies\Q9VNT3TW.txt [ Cookie:alex and [email protected]/cgi-bin ]
    C:\USERS\ALEX AND JAMES\Cookies\2CUNBRND.txt [ Cookie:alex and [email protected]/ ]
    C:\USERS\ALEX AND JAMES\Cookies\4BFMBP1R.txt [ Cookie:alex and [email protected]/ ]
    C:\USERS\ALEX AND JAMES\Cookies\Y7HR2T9F.txt [ Cookie:alex and [email protected]/ ]
    C:\USERS\ALEX AND JAMES\Cookies\VAKQZI5N.txt [ Cookie:alex and [email protected]/pagead/conversion/1071224783/ ]
    C:\USERS\ALEX AND JAMES\Cookies\3V9OQFV2.txt [ Cookie:alex and [email protected]/ ]
    C:\USERS\ALEX AND JAMES\Cookies\AP7DUEE3.txt [ Cookie:alex and [email protected]/ ]
    C:\USERS\ALEX AND JAMES\Cookies\A1286QCJ.txt [ Cookie:alex and [email protected]/ ]
    C:\USERS\ALEX AND JAMES\Cookies\J3865LE2.txt [ Cookie:alex and [email protected]/ ]
    C:\USERS\JAMES AND ALEX\AppData\Roaming\Microsoft\Windows\Cookies\Low\[email protected][1].txt [ Cookie:james and [email protected]/ ]
    C:\USERS\JAMES AND ALEX\AppData\Roaming\Microsoft\Windows\Cookies\Low\[email protected][2].txt [ Cookie:james and [email protected]/ ]
    C:\USERS\JAMES AND ALEX\AppData\Roaming\Microsoft\Windows\Cookies\Low\[email protected][1].txt [ Cookie:james and [email protected]/ ]
    C:\USERS\JAMES AND ALEX\AppData\Roaming\Microsoft\Windows\Cookies\Low\[email protected][2].txt [ Cookie:james and [email protected]/ ]
    C:\USERS\JAMES AND ALEX\AppData\Roaming\Microsoft\Windows\Cookies\Low\[email protected][1].txt [ Cookie:james and [email protected]/ ]
    C:\USERS\JAMES AND ALEX\AppData\Roaming\Microsoft\Windows\Cookies\Low\[email protected][1].txt [ Cookie:james and [email protected]/ ]
    C:\USERS\JAMES AND ALEX\AppData\Roaming\Microsoft\Windows\Cookies\Low\[email protected][1].txt [ Cookie:james and [email protected]/ ]
    C:\USERS\JAMES AND ALEX\AppData\Roaming\Microsoft\Windows\Cookies\Low\[email protected][2].txt [ Cookie:james and [email protected]/ ]
    C:\USERS\JAMES AND ALEX\AppData\Roaming\Microsoft\Windows\Cookies\Low\[email protected][2].txt [ Cookie:james and [email protected]/ ]
    C:\USERS\JAMES AND ALEX\AppData\Roaming\Microsoft\Windows\Cookies\Low\[email protected][2].txt [ Cookie:james and [email protected]/ ]
    C:\USERS\JAMES AND ALEX\AppData\Roaming\Microsoft\Windows\Cookies\Low\[email protected][1].txt [ Cookie:james and [email protected]/pagead/conversion/1071896469/ ]
    C:\USERS\JAMES AND ALEX\AppData\Roaming\Microsoft\Windows\Cookies\Low\[email protected][2].txt [ Cookie:james and [email protected]/ ]
    C:\USERS\JAMES AND ALEX\AppData\Roaming\Microsoft\Windows\Cookies\Low\[email protected][1].txt [ Cookie:james and [email protected]/ ]
    C:\USERS\JAMES AND ALEX\AppData\Roaming\Microsoft\Windows\Cookies\Low\[email protected][1].txt [ Cookie:james and [email protected]/ ]
    C:\USERS\JAMES AND ALEX\AppData\Roaming\Microsoft\Windows\Cookies\Low\[email protected][1].txt [ Cookie:james and [email protected]/ ]
    C:\USERS\JAMES AND ALEX\AppData\Roaming\Microsoft\Windows\Cookies\Low\[email protected][1].txt [ Cookie:james and [email protected]/ ]
    C:\USERS\JAMES AND ALEX\AppData\Roaming\Microsoft\Windows\Cookies\Low\[email protected][2].txt [ Cookie:james and [email protected]icksafe.direct.gov.uk/ ]
    C:\USERS\JAMES AND ALEX\AppData\Roaming\Microsoft\Windows\Cookies\Low\[email protected][1].txt [ Cookie:james and [email protected]/ ]
    C:\USERS\JAMES AND ALEX\AppData\Roaming\Microsoft\Windows\Cookies\Low\[email protected][1].txt [ Cookie:james and [email protected]/ ]
    C:\USERS\JAMES AND ALEX\AppData\Roaming\Microsoft\Windows\Cookies\Low\[email protected][2].txt [ Cookie:james and [email protected]/ ]
    C:\USERS\JAMES AND ALEX\AppData\Roaming\Microsoft\Windows\Cookies\Low\[email protected][1].txt [ Cookie:james and [email protected]/ ]
    C:\USERS\JAMES AND ALEX\AppData\Roaming\Microsoft\Windows\Cookies\Low\[email protected][1].txt [ Cookie:james and [email protected]/ ]
    C:\USERS\JAMES AND ALEX\AppData\Roaming\Microsoft\Windows\Cookies\Low\[email protected][2].txt [ Cookie:james and [email protected]/ ]
    C:\USERS\JAMES AND ALEX\AppData\Roaming\Microsoft\Windows\Cookies\Low\[email protected][1].txt [ Cookie:james and [email protected]/ ]
    C:\USERS\JAMES AND ALEX\AppData\Roaming\Microsoft\Windows\Cookies\Low\[email protected][1].txt [ Cookie:james and [email protected]/ ]
    C:\USERS\JAMES AND ALEX\AppData\Roaming\Microsoft\Windows\Cookies\Low\[email protected][2].txt [ Cookie:james and [email protected]/ ]
    C:\USERS\JAMES AND ALEX\AppData\Roaming\Microsoft\Windows\Cookies\Low\[email protected][1].txt [ Cookie:james and [email protected]/ ]
    C:\USERS\JAMES AND ALEX\AppData\Roaming\Microsoft\Windows\Cookies\Low\[email protected][1].txt [ Cookie:james and [email protected]/ ]
    C:\USERS\JAMES AND ALEX\AppData\Roaming\Microsoft\Windows\Cookies\Low\[email protected][1].txt [ Cookie:james and [email protected]/ ]
    C:\USERS\JAMES AND ALEX\AppData\Roaming\Microsoft\Windows\Cookies\Low\[email protected][2].txt [ Cookie:james and [email protected]/cgi-bin ]
    C:\USERS\JAMES AND ALEX\AppData\Roaming\Microsoft\Windows\Cookies\Low\[email protected][2].txt [ Cookie:james and [email protected]/ ]
    C:\USERS\JAMES AND ALEX\AppData\Roaming\Microsoft\Windows\Cookies\Low\[email protected][1].txt [ Cookie:james and [email protected]/ ]
    C:\USERS\JAMES AND ALEX\AppData\Roaming\Microsoft\Windows\Cookies\Low\[email protected][1].txt [ Cookie:james and [email protected]/ ]
    C:\USERS\JAMES AND ALEX\AppData\Roaming\Microsoft\Windows\Cookies\Low\[email protected][1].txt [ Cookie:james and [email protected]/ ]
    C:\USERS\JAMES AND ALEX\AppData\Roaming\Microsoft\Windows\Cookies\Low\[email protected][2].txt [ Cookie:james and [email protected]/ ]
    C:\USERS\JAMES AND ALEX\AppData\Roaming\Microsoft\Windows\Cookies\Low\[email protected][1].txt [ Cookie:james and [email protected]/ ]
    C:\USERS\JAMES AND ALEX\AppData\Roaming\Microsoft\Windows\Cookies\Low\[email protected][1].txt [ Cookie:james and [email protected]/ ]
    C:\USERS\JAMES AND ALEX\AppData\Roaming\Microsoft\Windows\Cookies\Low\[email protected][2].txt [ Cookie:james and [email protected]/ ]
    C:\USERS\JAMES AND ALEX\AppData\Roaming\Microsoft\Windows\Cookies\Low\[email protected][2].txt [ Cookie:james and [email protected]/ ]
    C:\USERS\MUM AND DAD\AppData\Roaming\Microsoft\Windows\Cookies\QFTZTH4F.txt [ Cookie:mum and [email protected]/intl/en/ads/ ]
    C:\USERS\MUM AND DAD\AppData\Roaming\Microsoft\Windows\Cookies\Low\[email protected][2].txt [ Cookie:mum and [email protected]/ ]
    C:\USERS\MUM AND DAD\AppData\Roaming\Microsoft\Windows\Cookies\Low\[email protected][1].txt [ Cookie:mum and [email protected]/ ]
    C:\USERS\MUM AND DAD\AppData\Roaming\Microsoft\Windows\Cookies\Low\[email protected][2].txt [ Cookie:mum and [email protected]/ ]
    C:\USERS\MUM AND DAD\AppData\Roaming\Microsoft\Windows\Cookies\Low\[email protected][3].txt [ Cookie:mum and [email protected]/ ]
    C:\USERS\MUM AND DAD\Cookies\74A4SSTO.txt [ Cookie:mum and [email protected]/ ]
    C:\USERS\MUM AND DAD\Cookies\DJ258651.txt [ Cookie:mum and [email protected]/ ]
    C:\USERS\MUM AND DAD\Cookies\B0EDYB7W.txt [ Cookie:mum and [email protected]/hc/53115291 ]
    C:\USERS\MUM AND DAD\Cookies\4JAYMQML.txt [ Cookie:mum and [email protected]/dcsq641a610000slzjl40w5wa_8j4e ]
    C:\USERS\MUM AND DAD\Cookies\61CQNLC8.txt [ Cookie:mum and [email protected]/ ]
    C:\USERS\MUM AND DAD\Cookies\4NF585TS.txt [ Cookie:mum and [email protected]/ ]
    C:\USERS\MUM AND DAD\Cookies\6UIZMCVF.txt [ Cookie:mum and [email protected]/ ]
    C:\USERS\MUM AND DAD\Cookies\4EMYYVLP.txt [ Cookie:mum and [email protected]/ ]
    C:\USERS\MUM AND DAD\Cookies\QFTZTH4F.txt [ Cookie:mum and [email protected]/intl/en/ads/ ]
    C:\USERS\MUM AND DAD\Cookies\CTDQ3VKB.txt [ Cookie:mum and [email protected]/ ]
    C:\USERS\MUM AND DAD\Cookies\NI0C8ROU.txt [ Cookie:mum and [email protected]/pagead/conversion/1054035038/ ]
    C:\USERS\MUM AND DAD\Cookies\MSUYXP2A.txt [ Cookie:mum and [email protected]/ ]
    C:\USERS\MUM AND DAD\Cookies\7GJ2EUGU.txt [ Cookie:mum and [email protected]/hc/48759847 ]
    C:\USERS\MUM AND DAD\Cookies\GAR0GLQ4.txt [ Cookie:mum and [email protected]/hc/63960994 ]
    C:\USERS\MUM AND DAD\Cookies\AGILB6BQ.txt [ Cookie:mum and [email protected]/ ]
    C:\USERS\MUM AND DAD\Cookies\BXAH0A7L.txt [ Cookie:mum and [email protected]/ ]
    C:\USERS\MUM AND DAD\Cookies\6FQAQGYY.txt [ Cookie:mum and [email protected]/ ]
    C:\USERS\MUM AND DAD\Cookies\NHCTKVFA.txt [ Cookie:mum and [email protected]/ ]
    C:\USERS\MUM AND DAD\Cookies\R2KMTZKI.txt [ Cookie:mum and [email protected]/ ]
    C:\USERS\MUM AND DAD\Cookies\0X6UAQB5.txt [ Cookie:mum and [email protected]/cgi-bin ]
    C:\USERS\MUM AND DAD\Cookies\NCEGTC1U.txt [ Cookie:mum and [email protected]/ ]
    C:\USERS\MUM AND DAD\Cookies\YN1SSW1W.txt [ Cookie:mum and [email protected]/ ]
    C:\USERS\MUM AND DAD\Cookies\PAX2HC1U.txt [ Cookie:mum and [email protected]/ ]
    C:\USERS\MUM AND DAD\Cookies\SCWV9ZKH.txt [ Cookie:mum and [email protected]/ ]
    C:\USERS\MUM AND DAD\Cookies\9FHXLNNC.txt [ Cookie:mum and [email protected]/ ]
    C:\USERS\MUM AND DAD\Cookies\0S8X79S2.txt [ Cookie:mum and [email protected]/ ]
    C:\USERS\MUM AND DAD\Cookies\2GP7ZMPZ.txt [ Cookie:mum and [email protected]/pagead/conversion/1036980325/ ]
    C:\USERS\MUM AND DAD\Cookies\24E73LXR.txt [ Cookie:mum and [email protected]/ ]
    C:\USERS\MUM AND DAD\Cookies\NTO455N1.txt [ Cookie:mum and [email protected]/ ]
    C:\USERS\MUM AND DAD\Cookies\2LZB69K4.txt [ Cookie:mum and [email protected]/pagead/conversion/984403512/ ]
    C:\USERS\MUM AND DAD\Cookies\OHH4FHKA.txt [ Cookie:mum and [email protected]/ ]
    C:\USERS\MUM AND DAD\Cookies\WZM4P4EE.txt [ Cookie:mum and [email protected]/ ]
    C:\USERS\MUM AND DAD\Cookies\SHS53W4K.txt [ Cookie:mum and [email protected]/ ]
    C:\USERS\MUM AND DAD\Cookies\1SR3IIRF.txt [ Cookie:mum and [email protected]/ ]
    C:\USERS\MUM AND DAD\Cookies\QA5AL2J6.txt [ Cookie:mum and [email protected]/ ]
    C:\USERS\MUM AND DAD\Cookies\9EX5I2PB.txt [ Cookie:mum and [email protected]/ ]
    C:\USERS\MUM AND DAD\Cookies\QBMMRGDC.txt [ Cookie:mum and [email protected]/ ]
    C:\USERS\MUM AND DAD\Cookies\D4OECH0N.txt [ Cookie:mum and [email protected]/ ]
    C:\USERS\MUM AND DAD\Cookies\GO0GKTK0.txt [ Cookie:mum and [email protected]/future/ ]
    C:\USERS\MUM AND DAD\Cookies\FDVGGSOZ.txt [ Cookie:mum and [email protected]/future/pcgamer/ ]
    C:\USERS\MUM AND DAD\Cookies\M8IBXCG1.txt [ Cookie:mum and [email protected]/ ]
    C:\USERS\MUM AND DAD\Cookies\SPOYQ75Q.txt [ Cookie:mum and [email protected]/ ]
    C:\USERS\MUM AND DAD\Cookies\VE24J3I3.txt [ Cookie:mum and [email protected]/ ]
    C:\USERS\MUM AND DAD\Cookies\SZ9LJ46O.txt [ Cookie:mum and [email protected]/ ]
    C:\USERS\MUM AND DAD\Cookies\4723TRNA.txt [ Cookie:mum and [email protected]/ ]
    C:\USERS\MUM AND DAD\Cookies\8SV0SHFH.txt [ Cookie:mum and [email protected]/ ]
    C:\USERS\MUM AND DAD\Cookies\5FFHO2K5.txt [ Cookie:mum and [email protected]/ ]
    C:\USERS\MUM AND DAD\Cookies\OCQLY4SG.txt [ Cookie:mum and [email protected]/ ]
    C:\USERS\MUM AND DAD\Cookies\7785OIX0.txt [ Cookie:mum and [email protected]/ ]
    C:\USERS\MUM AND DAD\Cookies\9ZAEE85L.txt [ Cookie:mum and [email protected]/ ]
    C:\USERS\MUM AND DAD\Cookies\0A7Y60CK.txt [ Cookie:mum and [email protected]/ ]
    C:\USERS\MUM AND DAD\Cookies\UTZXERID.txt [ Cookie:mum and [email protected]/ ]
    C:\USERS\MUM AND DAD\Cookies\ICQV5B85.txt [ Cookie:mum and [email protected]/ ]
    C:\USERS\MUM AND DAD\Cookies\4ZXBFX1N.txt [ Cookie:mum and [email protected]/pagead/conversion/996397746/ ]
    C:\USERS\MUM AND DAD\Cookies\T69JQG44.txt [ Cookie:mum and [email protected]/ ]
    C:\USERS\MUM AND DAD\Cookies\0WWF85QH.txt [ Cookie:mum and [email protected]/pagead/conversion/1069431180/ ]
    C:\USERS\MUM AND DAD\Cookies\0I77YHIL.txt [ Cookie:mum and [email protected]/ ]
    C:\USERS\MUM AND DAD\Cookies\N39DOKZI.txt [ Cookie:mum and [email protected]/ ]
    C:\USERS\MUM AND DAD\Cookies\RSNFPOBW.txt [ Cookie:mum and [email protected]/ ]
    C:\USERS\MUM AND DAD\Cookies\7Y2PE6G9.txt [ Cookie:mum and [email protected]/ ]
    C:\USERS\MUM AND DAD\Cookies\NQ9039IK.txt [ Cookie:mum and [email protected]/ ]
    C:\USERS\MUM AND DAD\Cookies\N39Y8SC0.txt [ Cookie:mum and [email protected]/ ]
    C:\USERS\MUM AND DAD\Cookies\E7UXMMN6.txt [ Cookie:mum and [email protected]/ ]
    C:\USERS\MUM AND DAD\Cookies\IBTDTLJ8.txt [ Cookie:mum and [email protected]/ ]
    C:\USERS\MUM AND DAD\Cookies\QGRG60ZE.txt [ Cookie:mum and [email protected]/ ]
    C:\USERS\MUM AND DAD\Cookies\BQY0NZ1U.txt [ Cookie:mum and [email protected]/ ]
    C:\USERS\MUM AND DAD\Cookies\TBKPGF4W.txt [ Cookie:mum and [email protected]/ ]
    C:\USERS\MUM AND DAD\Cookies\SO29W8D0.txt [ Cookie:mum and [email protected]/pagead/conversion/1070564663/ ]
    C:\USERS\MUM AND DAD\Cookies\7YRMJTMX.txt [ Cookie:mum and [email protected]/ ]
    C:\USERS\MUM AND DAD\Cookies\MGOK7IPZ.txt [ Cookie:mum and [email protected]/ ]
    C:\USERS\MUM AND DAD\Cookies\U336ZM40.txt [ Cookie:mum and [email protected]/pagead/conversion/1071809882/ ]
    core.saymedia.com [ C:\USERS\ALEX AND JAMES\APPDATA\ROAMING\MACROMEDIA\FLASH PLAYER\#SHAREDOBJECTS\GVP00001 ]
    cdn4.specificclick.net [ C:\USERS\JAMES AND ALEX\APPDATA\ROAMING\MACROMEDIA\FLASH PLAYER\#SHAREDOBJECTS\GVP00001 ]
    memecounter.com [ C:\USERS\JAMES AND ALEX\APPDATA\ROAMING\MACROMEDIA\FLASH PLAYER\#SHAREDOBJECTS\GVP00001 ]
    s0.2mdn.net [ C:\USERS\JAMES AND ALEX\APPDATA\ROAMING\MACROMEDIA\FLASH PLAYER\#SHAREDOBJECTS\GVP00001 ]
    C:\USERS\JAMES AND ALEX\APPDATA\ROAMING\MICROSOFT\WINDOWS\COOKIES\LOW\[email protected][1].TXT [ /112.2O7 ]
    C:\USERS\JAMES AND ALEX\APPDATA\ROAMING\MICROSOFT\WINDOWS\COOKIES\LOW\[email protected][1].TXT [ /AD.YIELDMANAGER ]
    C:\USERS\JAMES AND ALEX\APPDATA\ROAMING\MICROSOFT\WINDOWS\COOKIES\LOW\[email protected][2].TXT [ /AD1.POPCAP ]
    C:\USERS\JAMES AND ALEX\APPDATA\ROAMING\MICROSOFT\WINDOWS\COOKIES\LOW\[email protected][1].TXT [ /ADECN ]
    C:\USERS\JAMES AND ALEX\APPDATA\ROAMING\MICROSOFT\WINDOWS\COOKIES\LOW\[email protected][1].TXT [ /ADS.AD4GAME ]
    C:\USERS\JAMES AND ALEX\APPDATA\ROAMING\MICROSOFT\WINDOWS\COOKIES\LOW\[email protected][1].TXT [ /ADS.BUDDYPIC ]
    C:\USERS\JAMES AND ALEX\APPDATA\ROAMING\MICROSOFT\WINDOWS\COOKIES\LOW\[email protected][1].TXT [ /AOTRACKER ]
    C:\USERS\JAMES AND ALEX\APPDATA\ROAMING\MICROSOFT\WINDOWS\COOKIES\LOW\[email protected][1].TXT [ /CDN4.SPECIFICCLICK ]
    C:\USERS\JAMES AND ALEX\APPDATA\ROAMING\MICROSOFT\WINDOWS\COOKIES\LOW\[email protected][2].TXT [ /CONTENT.YIELDMANAGER ]
    C:\USERS\JAMES AND ALEX\APPDATA\ROAMING\MICROSOFT\WINDOWS\COOKIES\LOW\[email protected][3].TXT [ /CONTENT.YIELDMANAGER ]
    C:\USERS\JAMES AND ALEX\APPDATA\ROAMING\MICROSOFT\WINDOWS\COOKIES\LOW\[email protected][1].TXT [ /FASTCLICK ]
    C:\USERS\JAMES AND ALEX\APPDATA\ROAMING\MICROSOFT\WINDOWS\COOKIES\LOW\[email protected][1].TXT [ /MSNPORTAL.112.2O7 ]
    C:\USERS\JAMES AND ALEX\APPDATA\ROAMING\MICROSOFT\WINDOWS\COOKIES\LOW\[email protected][1].TXT [ /REVSCI ]
    C:\USERS\JAMES AND ALEX\APPDATA\ROAMING\MICROSOFT\WINDOWS\COOKIES\LOW\[email protected][1].TXT [ /SERVER.IAD.LIVEPERSON ]
    C:\USERS\JAMES AND ALEX\APPDATA\ROAMING\MICROSOFT\WINDOWS\COOKIES\LOW\[email protected][2].TXT [ /SERVER.IAD.LIVEPERSON ]
    core.saymedia.com [ C:\USERS\MUM AND DAD\APPDATA\ROAMING\MACROMEDIA\FLASH PLAYER\#SHAREDOBJECTS\GNCDXA89 ]
    media-cdn.tripadvisor.com [ C:\USERS\MUM AND DAD\APPDATA\ROAMING\MACROMEDIA\FLASH PLAYER\#SHAREDOBJECTS\GNCDXA89 ]
    media1.break.com [ C:\USERS\MUM AND DAD\APPDATA\ROAMING\MACROMEDIA\FLASH PLAYER\#SHAREDOBJECTS\GNCDXA89 ]
    secure-uk.imrworldwide.com [ C:\USERS\MUM AND DAD\APPDATA\ROAMING\MACROMEDIA\FLASH PLAYER\#SHAREDOBJECTS\GNCDXA89 ]
    secure-us.imrworldwide.com [ C:\USERS\MUM AND DAD\APPDATA\ROAMING\MACROMEDIA\FLASH PLAYER\#SHAREDOBJECTS\GNCDXA89 ]
    C:\USERS\MUM AND DAD\APPDATA\ROAMING\MICROSOFT\WINDOWS\COOKIES\LOW\[email protected][1].TXT [ /247REALMEDIA ]
    C:\USERS\MUM AND DAD\APPDATA\ROAMING\MICROSOFT\WINDOWS\COOKIES\LOW\[email protected][1].TXT [ /AD.YIELDMANAGER ]
    C:\USERS\MUM AND DAD\APPDATA\ROAMING\MICROSOFT\WINDOWS\COOKIES\LOW\[email protected][4].TXT [ /AD.YIELDMANAGER ]
    C:\USERS\MUM AND DAD\APPDATA\ROAMING\MICROSOFT\WINDOWS\COOKIES\LOW\[email protected][2].TXT [ /AD2.POPCAP ]
    C:\USERS\MUM AND DAD\APPDATA\ROAMING\MICROSOFT\WINDOWS\COOKIES\LOW\[email protected][3].TXT [ /AD2.POPCAP ]
    C:\USERS\MUM AND DAD\APPDATA\ROAMING\MICROSOFT\WINDOWS\COOKIES\LOW\[email protected][1].TXT [ /ADBRITE ]
    C:\USERS\MUM AND DAD\APPDATA\ROAMING\MICROSOFT\WINDOWS\COOKIES\LOW\[email protected][2].TXT [ /ADS.PUBMATIC ]
    C:\USERS\MUM AND DAD\APPDATA\ROAMING\MICROSOFT\WINDOWS\COOKIES\LOW\[email protected][2].TXT [ /ADTECH ]
    C:\USERS\MUM AND DAD\APPDATA\ROAMING\MICROSOFT\WINDOWS\COOKIES\LOW\[email protected][3].TXT [ /ADTECH ]
    C:\USERS\MUM AND DAD\APPDATA\ROAMING\MICROSOFT\WINDOWS\COOKIES\LOW\[email protected][1].TXT [ /ADVERTISING ]
    C:\USERS\MUM AND DAD\APPDATA\ROAMING\MICROSOFT\WINDOWS\COOKIES\LOW\[email protected][2].TXT [ /ADVERTISING ]
    C:\USERS\MUM AND DAD\APPDATA\ROAMING\MICROSOFT\WINDOWS\COOKIES\LOW\[email protected][3].TXT [ /ADVERTISING ]
    C:\USERS\MUM AND DAD\APPDATA\ROAMING\MICROSOFT\WINDOWS\COOKIES\LOW\[email protected][4].TXT [ /ADVERTISING ]
    C:\USERS\MUM AND DAD\APPDATA\ROAMING\MICROSOFT\WINDOWS\COOKIES\LOW\[email protected][1].TXT [ /ADVIVA ]
    C:\USERS\MUM AND DAD\APPDATA\ROAMING\MICROSOFT\WINDOWS\COOKIES\LOW\[email protected][2].TXT [ /ADVIVA ]
    C:\USERS\MUM AND DAD\APPDATA\ROAMING\MICROSOFT\WINDOWS\COOKIES\LOW\[email protected][2].TXT [ /ATDMT ]
    C:\USERS\MUM AND DAD\APPDATA\ROAMING\MICROSOFT\WINDOWS\COOKIES\LOW\[email protected][1].TXT [ /BS.SERVING-SYS ]
    C:\USERS\MUM AND DAD\APPDATA\ROAMING\MICROSOFT\WINDOWS\COOKIES\LOW\[email protected][2].TXT [ /CONTENT.YIELDMANAGER ]
    C:\USERS\MUM AND DAD\APPDATA\ROAMING\MICROSOFT\WINDOWS\COOKIES\LOW\[email protected][4].TXT [ /CONTENT.YIELDMANAGER ]
    C:\USERS\MUM AND DAD\APPDATA\ROAMING\MICROSOFT\WINDOWS\COOKIES\LOW\[email protected][6].TXT [ /CONTENT.YIELDMANAGER ]
    C:\USERS\MUM AND DAD\APPDATA\ROAMING\MICROSOFT\WINDOWS\COOKIES\LOW\[email protected][1].TXT [ /EAS.APM.EMEDIATE ]
    C:\USERS\MUM AND DAD\APPDATA\ROAMING\MICROSOFT\WINDOWS\COOKIES\LOW\[email protected][2].TXT [ /GAMECENTER.OBERON-MEDIA ]
    C:\USERS\MUM AND DAD\APPDATA\ROAMING\MICROSOFT\WINDOWS\COOKIES\LOW\[email protected][2].TXT [ /INVITEMEDIA ]
    C:\USERS\MUM AND DAD\APPDATA\ROAMING\MICROSOFT\WINDOWS\COOKIES\LOW\[email protected][2].TXT [ /LFSTMEDIA ]
    C:\USERS\MUM AND DAD\APPDATA\ROAMING\MICROSOFT\WINDOWS\COOKIES\LOW\[email protected][1].TXT [ /MEDIA6DEGREES ]
    C:\USERS\MUM AND DAD\APPDATA\ROAMING\MICROSOFT\WINDOWS\COOKIES\LOW\[email protected][2].TXT [ /MEDIA6DEGREES ]
    C:\USERS\MUM AND DAD\APPDATA\ROAMING\MICROSOFT\WINDOWS\COOKIES\LOW\[email protected][2].TXT [ /MEDIAPLEX ]
    C:\USERS\MUM AND DAD\APPDATA\ROAMING\MICROSOFT\WINDOWS\COOKIES\LOW\[email protected][3].TXT [ /MEDIAPLEX ]
    C:\USERS\MUM AND DAD\APPDATA\ROAMING\MICROSOFT\WINDOWS\COOKIES\LOW\[email protected][1].TXT [ /NEWMOONTHESOUNDTRACK ]
    C:\USERS\MUM AND DAD\APPDATA\ROAMING\MICROSOFT\WINDOWS\COOKIES\LOW\[email protected][2].TXT [ /REVSCI ]
    C:\USERS\MUM AND DAD\APPDATA\ROAMING\MICROSOFT\WINDOWS\COOKIES\LOW\[email protected][1].TXT [ /SERVER.CPMSTAR ]
    C:\USERS\MUM AND DAD\APPDATA\ROAMING\MICROSOFT\WINDOWS\COOKIES\LOW\[email protected][5].TXT [ /SERVER.LON.LIVEPERSON ]
    C:\USERS\MUM AND DAD\APPDATA\ROAMING\MICROSOFT\WINDOWS\COOKIES\LOW\[email protected][6].TXT [ /SERVER.LON.LIVEPERSON ]
    C:\USERS\MUM AND DAD\APPDATA\ROAMING\MICROSOFT\WINDOWS\COOKIES\LOW\[email protected][1].TXT [ /SERVING-SYS ]
    C:\USERS\MUM AND DAD\APPDATA\ROAMING\MICROSOFT\WINDOWS\COOKIES\LOW\[email protected][3].TXT [ /SERVING-SYS ]
    C:\USERS\MUM AND DAD\APPDATA\ROAMING\MICROSOFT\WINDOWS\COOKIES\LOW\[email protected][4].TXT [ /SERVING-SYS ]
    C:\USERS\MUM AND DAD\APPDATA\ROAMING\MICROSOFT\WINDOWS\COOKIES\LOW\[email protected][6].TXT [ /SERVING-SYS ]
    C:\USERS\MUM AND DAD\APPDATA\ROAMING\MICROSOFT\WINDOWS\COOKIES\LOW\[email protected][1].TXT [ /SPECIFICCLICK ]
    C:\USERS\MUM AND DAD\APPDATA\ROAMING\MICROSOFT\WINDOWS\COOKIES\LOW\[email protected][2].TXT [ /SPECIFICCLICK ]
    C:\USERS\MUM AND DAD\APPDATA\ROAMING\MICROSOFT\WINDOWS\COOKIES\LOW\[email protected][1].TXT [ /TRADEDOUBLER ]
    C:\USERS\MUM AND DAD\APPDATA\ROAMING\MICROSOFT\WINDOWS\COOKIES\LOW\[email protected][2].TXT [ /TRIBALFUSION ]
    C:\USERS\MUM AND DAD\APPDATA\ROAMING\MICROSOFT\WINDOWS\COOKIES\LOW\[email protected][3].TXT [ /TRIBALFUSION ]
    C:\USERS\MUM AND DAD\APPDATA\ROAMING\MICROSOFT\WINDOWS\COOKIES\LOW\[email protected][1].TXT [ /UK.AT.ATWOLA ]
    C:\USERS\MUM AND DAD\APPDATA\ROAMING\MICROSOFT\WINDOWS\COOKIES\LOW\[email protected][4].TXT [ /WWW.GOOGLEADSERVICES ]
    C:\USERS\MUM AND DAD\APPDATA\ROAMING\MICROSOFT\WINDOWS\COOKIES\LOW\[email protected][2].TXT [ /WWW.NEWMOONTHESOUNDTRACK ]
    cdn2.baronsmedia.com [ C:\WINDOWS\SYSTEM32\CONFIG\SYSTEMPROFILE\APPDATA\ROAMING\MACROMEDIA\FLASH PLAYER\#SHAREDOBJECTS\43YPMFTH ]
    core.saymedia.com [ C:\WINDOWS\SYSTEM32\CONFIG\SYSTEMPROFILE\APPDATA\ROAMING\MACROMEDIA\FLASH PLAYER\#SHAREDOBJECTS\43YPMFTH ]
    ictv-ic-ec.indieclicktv.com [ C:\WINDOWS\SYSTEM32\CONFIG\SYSTEMPROFILE\APPDATA\ROAMING\MACROMEDIA\FLASH PLAYER\#SHAREDOBJECTS\43YPMFTH ]
    secure-uk.imrworldwide.com [ C:\WINDOWS\SYSTEM32\CONFIG\SYSTEMPROFILE\APPDATA\ROAMING\MACROMEDIA\FLASH PLAYER\#SHAREDOBJECTS\43YPMFTH ]
    Trojan.Agent/Gen-Downloader
    C:\USERS\MUM AND DAD\APPDATA\LOCAL\ZYLOM GAMES\ZUMA DELUXE\ZUMA.EXE
     
  8. eddie5659

    eddie5659 Moderator Malware Specialist

    Joined:
    Mar 19, 2001
    Messages:
    34,343
    MBAM removed this:

    (Spyware.Password)

    So, I would make sure your passwords are changed, on another computer and don't use this one for banking until the infection is all gone.

    --

    Your Java is out of date, so lets do that next:

    Upgrade Java : (32 bits)
    • Download the latest version of Java SE Runtime Environment (JRE) JRE 7 Update 7 .
    • Under the JAVA Platform Standard Edition, click the "Download JRE" button to the right.
    • Accept License Agreement.[/b]".
    • Click on the link to download Windows Offline Installation 32 bit ( jre-7u5-windows-i586.exe) and save it to your desktop. Do NOT use the Sun Download Manager..
    • Close any programs you may have running - especially your web browser.
    • Go to Start > Control Panel, double-click on Add/Remove programs and remove all older versions of Java.
    • Check any item with Java Runtime Environment (JRE or J2SE) in the name.
    • Click the Remove or Change/Remove button.
    • Repeat as many times as necessary to remove each Java version.
    • Reboot your computer once all Java components are removed.
    • Then from your desktop double-click on the download to install the newest version.(Vista or Win 7 users, right click on the jre-7u5-windows-i586.exe and select "Run as an Administrator.")
    • Don't install any of the toolbars that are offered.


    After doing the above, for the remains of the Java, can you do this:

    Open Java in the Control Panel and under the General tab, under Temporary Internet Files, click the Settings button. Then click on Delete Files.

    Make sure both of these options are checked:

    • Applications and Applets
    • Trace and Log Files
    OK out of all the screens. :)

    ---

    Can you run the following tools, and copy/paste the logs that they produce here. If its over a few posts, that's fine :)


    Please download the latest version of TDSSKiller from here and save it to your Desktop.
    • Doubleclick on TDSSKiller.exe to run the application, then click on Change parameters.
      [​IMG]
    • Put a checkmark beside loaded modules.
      [​IMG]
    • A reboot will be needed to apply the changes. Do it.
    • TDSSKiller will launch automatically after the reboot. Also your computer may seem very slow and unusable. This is normal. Give it enough time to load your background programs.
    • Then click on Change parameters in TDSSKiller.
    • Check all boxes then click OK.
      [​IMG]
    • Click the Start Scan button.
      [​IMG]
    • The scan should take no longer than 2 minutes.
    • If a suspicious object is detected, the default action will be Skip, click on Continue.
      [​IMG]
    • If malicious objects are found, they will show in the Scan results - Select action for found objects and offer three options.
      Ensure Cure (default) is selected, then click Continue > Reboot now to finish the cleaning process.
      [​IMG]
      Note: If Cure is not available, please choose Skip instead, do not choose Delete unless instructed.
    • A report will be created in your root directory, (usually C:\ folder) in the form of "TDSSKiller.[Version]_[Date]_[Time]_log.txt". Please copy and paste the contents of that file here.


    --------------------------

    Download aswMBR.exe ( 511KB ) to your desktop.

    Double click the aswMBR.exe to run it

    Click the "Scan" button to start scan
    [​IMG]

    On completion of the scan click save log, save it to your desktop and post in your next reply
    [​IMG]

    -------------------------

    Delete any copies of Combofix that you have.

    Download ComboFix from one of these locations:

    Link 1
    Link 2


    * IMPORTANT !!! As you download it rename it to username123.exe and save it to your Desktop


    • Disable your AntiVirus and AntiSpyware applications, usually via a right click on the System Tray icon. They may otherwise interfere with our tools

      • Click on this link to see a list of programs that should be disabled. The list is not all inclusive. If yours is not listed and you don't know how to disable it, please ask.
      • Remember to re-enable the protection again afterwards before connecting to the Internet.
    • Double click on ComboFix.exe & follow the prompts.

    • As part of it's process, ComboFix will check to see if the Microsoft Windows Recovery Console is installed. With malware infections being as they are today, it's strongly recommended to have this pre-installed on your machine before doing any malware removal. It will allow you to boot up into a special recovery/repair mode that will allow us to more easily help you should your computer have a problem after an attempted removal of malware.

    • Follow the prompts to allow ComboFix to download and install the Microsoft Windows Recovery Console, and when prompted, agree to the End-User License Agreement to install the Microsoft Windows Recovery Console.

    **Please note: If the Microsoft Windows Recovery Console is already installed, ComboFix will continue it's malware removal procedures.


    [​IMG]


    Once the Microsoft Windows Recovery Console is installed using ComboFix, you should see the following message:

    [​IMG]


    Click on Yes, to continue scanning for malware.

    When finished, it shall produce a log for you. Please include the C:\ComboFix.txt in your next reply.

    eddie
     
  9. Sponsor

As Seen On
As Seen On...

Welcome to Tech Support Guy!

Are you looking for the solution to your computer problem? Join our site today to ask your question. This site is completely free -- paid for by advertisers and donations.

If you're not already familiar with forums, watch our Welcome Guide to get started.

Join over 733,556 other people just like you!

Loading...
Thread Status:
Not open for further replies.

Short URL to this thread: https://techguy.org/1068040

  1. This site uses cookies to help personalise content, tailor your experience and to keep you logged in if you register.
    By continuing to use this site, you are consenting to our use of cookies.
    Dismiss Notice