

InterviewSolution
1. |
Solve : Help! Computer infected, unable to run files due to infection!? |
Answer» Well,
We'll see about that... Please download ComboFix from BleepingComputer.com Alternate link: GeeksToGo.com Alternate link: Forospyware.com Rename ComboFix.exe to commy.bat before you save it to your Desktop
If you must, go ahead and download it from a clean computer and transfer it to the infected one via flash drive or burnt cd.SORRY! for the late response, had some relatives in town. Sittin' on the computer isn't very savvy. So I kept the laptop off and turned it on today, and actually it was letting me run things, so i can that commy.bat, and here ya go. ComboFix 10-02-04.06 - Kaleb 02/04/2010 19:31:28.1.2 - x86 Microsoft® Windows Vista™ Home Premium 6.0.6001.1.1252.1.1033.18.893.312 [GMT -8:00] Running from: c:\users\Kaleb\Desktop\commy.bat.exe SP: Windows Defender *disabled* (Updated) {D68DDC3A-831F-4FAE-9E44-DA132C1ACF46} . ((((((((((((((((((((((((((((((((((((((( Other Deletions ))))))))))))))))))))))))))))))))))))))))))))))))) . c:\$recycle.bin\S-1-5-21-2714304592-1191437367-953324204-500 c:\users\Kaleb\AppData\Local\djxbtv c:\users\Kaleb\AppData\Local\djxbtv\joyvsysguard.exe c:\windows\system32\stacsv.exe D:\Autorun.inf . ((((((((((((((((((((((((( Files Created from 2010-01-05 to 2010-02-05 ))))))))))))))))))))))))))))))) . 2010-02-05 03:40 . 2010-02-05 03:43--------d-----w-c:\users\Kaleb\AppData\Local\temp 2010-02-05 03:40 . 2010-02-05 03:40--------d-----w-c:\users\Default\AppData\Local\temp 2010-01-30 22:06 . 2010-01-30 22:06--------d-----w-c:\users\Kaleb\AppData\Roaming\Malwarebytes 2010-01-30 22:06 . 2010-01-08 00:0738224----a-w-c:\windows\system32\drivers\mbamswissarmy.sys 2010-01-30 22:06 . 2010-01-30 22:06--------d-----w-c:\program files\Malwarebytes' Anti-Malware 2010-01-30 22:06 . 2010-01-30 22:06--------d-----w-c:\programdata\Malwarebytes 2010-01-30 22:06 . 2010-01-08 00:0719160----a-w-c:\windows\system32\drivers\mbam.sys 2010-01-30 13:08 . 2010-01-30 13:08--------d-----w-c:\program files\a-squared Free 2010-01-30 12:45 . 2010-01-30 12:45--------d-----w-c:\users\Kaleb\AppData\Roaming\AVG8 2010-01-22 08:05 . 2010-01-22 08:05--------d-----w-c:\program files\Common Files\Tencent 2010-01-22 08:05 . 2010-01-22 08:05--------d-----w-c:\program files\Tencent 2010-01-22 08:05 . 2010-01-22 08:10--------d-----w-c:\users\Kaleb\AppData\Roaming\Tencent 2010-01-22 08:05 . 2010-01-22 08:0518760----a-w-c:\windows\system32\QQVistaHelper.dll 2010-01-13 03:59 . 2009-10-19 14:27156672----a-w-c:\windows\system32\t2embed.dll 2010-01-13 03:59 . 2009-10-19 14:2472704----a-w-c:\windows\system32\fontsub.dll 2010-01-13 02:36 . 2010-01-13 02:36--------d-----w-c:\program files\Common Files\Software Update Utility 2010-01-13 02:35 . 2010-01-13 02:35--------d-----w-c:\program files\AIM . (((((((((((((((((((((((((((((((((((((((( Find3M Report )))))))))))))))))))))))))))))))))))))))))))))))))))) . 2010-01-26 07:55 . 2008-05-06 15:4394----a-w-c:\users\Kaleb\AppData\Roaming\wklnhst.dat 2010-01-14 19:12 . 2009-10-09 07:16181120------w-c:\windows\system32\MpSigStub.exe 2010-01-13 11:03 . 2006-11-02 11:18--------d-----w-c:\program files\Windows Mail 2009-12-28 11:07 . 2007-02-26 13:47--------d-----w-c:\programdata\Microsoft Help 2009-12-18 13:05 . 2010-01-21 20:25833024----a-w-c:\windows\system32\wininet.dll 2009-12-18 13:01 . 2010-01-21 20:2578336----a-w-c:\windows\system32\ieencode.dll 2009-12-18 10:14 . 2010-01-21 20:2526624----a-w-c:\windows\system32\ieUnatt.exe 2009-11-09 13:22 . 2009-12-28 11:0824064----a-w-c:\windows\system32\nshhttp.dll 2009-11-09 13:20 . 2009-12-28 11:0831232----a-w-c:\windows\system32\httpapi.dll 2009-11-09 11:04 . 2009-12-28 11:08411136----a-w-c:\windows\system32\drivers\http.sys . ((((((((((((((((((((((((((((((((((((( Reg Loading Points )))))))))))))))))))))))))))))))))))))))))))))))))) . . *Note* empty entries & legit default entries are not shown REGEDIT4 [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] "Aim"="c:\program files\AIM\aim.exe" [2009-12-01 3951976] "QQIntl"="c:\program files\Tencent\QQIntl\Bin\QQ.exe" [2010-01-22 144712] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] "Windows Defender"="c:\program files\Windows Defender\MSASCui.exe" [2008-01-19 1008184] "SynTPEnh"="c:\program files\Synaptics\SynTP\SynTPEnh.exe" [2006-11-17 815104] "SMSERIAL"="c:\program files\Motorola\SMSERIAL\sm56hlpr.exe" [2007-01-17 634880] "HostManager"="c:\program files\Common Files\AOL\1183363162\ee\AOLSoftware.exe" [2006-09-26 50736] "IntelliPoint"="c:\program files\Microsoft IntelliPoint\ipoint.exe" [2007-02-05 849280] "ArcSoft Connection Service"="c:\program files\Common Files\ArcSoft\Connection Service\Bin\ACDaemon.exe" [2009-10-10 203264] "QuickTime Task"="c:\program files\QuickTime\QTTask.exe" [2007-06-29 286720] c:\programdata\Microsoft\Windows\Start Menu\Programs\Startup\ Kodak EasyShare software.lnk.disabled [2009-6-21 2001] [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system] "EnableUIADesktopToggle"= 0 (0x0) [HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\windows] "AppInit_DLLs"=c:\progra~1\Google\GOOGLE~1\GoogleDesktopNetwork3.dll [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\CONTROL\SafeBoot\Minimal\WinDefend] @="Service" [HKEY_CURRENT_USER\software\microsoft\windows\currentversion\run-] "MySpaceIM"=c:\program files\MySpace\IM\MySpaceIM.exe "AOL Fast Start"="c:\program files\AOL 9.0b\AOL.EXE" -b "Aim6"="c:\program files\AIM6\aim6.exe" /d locale=en-US ee://aol/imApp "SpybotSD TeaTimer"=c:\program files\Spybot - Search & Destroy\TeaTimer.exe ""= [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run-] "Google Desktop Search"="c:\program files\Google\Google Desktop Search\GoogleDesktop.exe" /startup [HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\McAfeeAntiSpyware] "DisableMonitoring"=dword:00000001 [HKEY_LOCAL_MACHINE\software\microsoft\security center\Svc\S-1-5-21-2714304592-1191437367-953324204-1000] "EnableNotificationsRef"=dword:00000002 [HKEY_LOCAL_MACHINE\software\microsoft\security center\Svc\S-1-5-21-2714304592-1191437367-953324204-500] "EnableNotificationsRef"=dword:00000002 R2 a2free;a-squared Free Service;c:\program files\a-squared Free\a2service.exe [1/30/2010 5:08 AM 1858144] R2 Viewpoint Manager Service;Viewpoint Manager Service;c:\program files\Viewpoint\Common\ViewpointService.exe [5/20/2009 7:03 PM 24652] R3 RTL8187;Realtek RTL8187 Wireless 802.11g 54Mbps USB 2.0 Network Adapter;c:\windows\System32\drivers\RTL8187.sys [2/26/2007 5:39 AM 205312] S3 GoogleDesktopManager-061008-081103;Google Desktop Manager 5.7.806.10245;c:\program files\Google\Google Desktop Search\GoogleDesktop.exe [2/26/2007 5:51 AM 29744] . Contents of the 'Scheduled Tasks' folder . . ------- Supplementary Scan ------- . uStart Page = hxxp://www.google.nl/ mStart Page = hxxp://www.gateway.com/g/startpage.html?Ch=Retail&Br=GTW&Loc=ENG_US&Sys=PTB&M=MT6452 uSearchURL,(Default) = hxxp://www.google.com/keyword/%s IE: E&xport to Microsoft Excel - c:\progra~1\MICROS~2\Office12\EXCEL.EXE/3000 IE: QQ - c:\program files\Tencent\QQIntl\Bin\AddEmotion.htm FF - ProfilePath - c:\users\Kaleb\AppData\Roaming\Mozilla\Firefox\Profiles\zhpm7tfa.default\ FF - prefs.js: browser.search.defaulturl - hxxp://slirsredirect.search.aol.com/slirs_http/sredir?sredir=2706&invocationType=tb50fftrie7&query= FF - prefs.js: browser.search.selectedEngine - AIM Search FF - prefs.js: browser.startup.homepage - www.google.com FF - prefs.js: keyword.URL - hxxp://slirsredirect.search.aol.com/slirs_http/sredir?invocationType=bu10aiminstabie7&sredir=2706&query= FF - plugin: c:\program files\Java\jre1.6.0\bin\npjava11.dll FF - plugin: c:\program files\Java\jre1.6.0\bin\npjava12.dll FF - plugin: c:\program files\Java\jre1.6.0\bin\npjava13.dll FF - plugin: c:\program files\Java\jre1.6.0\bin\npjava14.dll FF - plugin: c:\program files\Java\jre1.6.0\bin\npjava32.dll FF - plugin: c:\program files\Java\jre1.6.0\bin\npjpi160.dll FF - plugin: c:\program files\Java\jre1.6.0\bin\npoji610.dll FF - plugin: c:\program files\Mozilla Firefox\plugins\np-mswmp.dll FF - plugin: c:\program files\Mozilla Firefox\plugins\npdnupdater2.dll FF - plugin: c:\program files\Mozilla Firefox\plugins\npViewpoint.dll FF - plugin: c:\program files\Viewpoint\Viewpoint Experience Technology\npViewpoint.dll FF - HiddenExtension: Microsoft .NET Framework Assistant: {20a82645-c095-46ed-80e3-08825760534b} - c:\windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\DotNetAssistantExtension\ ---- FIREFOX POLICIES ---- FF - user.js: network.protocol-handler.warn-external.dnupdate - false);user_pref(network.protocol-handler.warn-external.dnupdate, false FF - user.js: browser.sessionstore.resume_from_crash - false FF - user.js: network.protocol-handler.warn-external.dnupdate - false);user_pref(network.protocol-handler.warn-external.dnupdate, false. - - - - ORPHANS REMOVED - - - - HKCU-Run-ainnhyvx - c:\users\Kaleb\AppData\Local\djxbtv\joyvsysguard.exe ActiveSetup-ccc-core-static - msiexec ************************************************************************** catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net Rootkit scan 2010-02-04 19:44 Windows 6.0.6001 Service Pack 1 NTFS scanning hidden processes ... scanning hidden autostart entries ... scanning hidden files ... scan completed successfully hidden files: 0 ************************************************************************** . --------------------- LOCKED REGISTRY KEYS --------------------- [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0000\AllUserSettings] @Denied: (A) (Users) @Denied: (A) (Everyone) @Allowed: (B 1 2 3 4 5) (S-1-5-20) "BlindDial"=dword:00000000 "MSCurrentCountry"=dword:000000b5 . Completion time: 2010-02-04 19:58:18 ComboFix-quarantined-files.txt 2010-02-05 03:58 Pre-Run: 82,248,601,600 bytes free Post-Run: 82,173,390,848 bytes free - - End Of File - - 2C2C94E0AAD66610F4EC6FE5E7B3A91B Hi again. Please do these steps in order. 1. Please download TFC by OldTimer to your desktop
Alternate link: BleepingComputer.com. (Note: if you already have the program installed, just follow the directions. No need to re-download or re-install!) Double Click mbam-setup.exe to install the application. (Note: if you already have the program installed, open Malwarebytes from the Start Menu or Desktop shortcut, click the Update tab, and click Check for Updates, before doing the scan as instructed below!)
If MBAM encounters a file that is difficult to remove,you will be presented with 1 of 2 prompts,click OK to either and let MBAM proceed with the disinfection process. If asked to restart the computer, please do so immediately. 3. Please visit this webpage for instructions for downloading and running SUPERAntiSpyware (SAS) to scan and remove malware from your computer: http://www.bleepingcomputer.com/virus-removal/how-to-use-superantispyware-tutorial Post the log from SUPERAntiSpyware when you've accomplished that. 4. Please run a free online scan with the ESET Online Scanner
5. Post the following in your next reply:
here is the logs. MBAM Malwarebytes' Anti-Malware 1.44 Database version: 3694 Windows 6.0.6001 Service Pack 1 Internet Explorer 7.0.6001.18000 2/5/2010 12:19:50 PM mbam-log-2010-02-05 (12-19-50).txt Scan type: Full Scan (C:\|D:\|) Objects scanned: 246171 Time elapsed: 1 hour(s), 47 minute(s), 1 second(s) Memory Processes Infected: 0 Memory Modules Infected: 0 Registry Keys Infected: 1 Registry Values Infected: 0 Registry Data Items Infected: 0 Folders Infected: 0 Files Infected: 1 Memory Processes Infected: (No malicious items detected) Memory Modules Infected: (No malicious items detected) Registry Keys Infected: HKEY_CURRENT_USER\Software\avsoft (Trojan.FakeAV) -> Quarantined and deleted successfully. Registry Values Infected: (No malicious items detected) Registry Data Items Infected: (No malicious items detected) Folders Infected: (No malicious items detected) Files Infected: C:\Qoobox\Quarantine\C\Users\Kaleb\AppData\Local\djxbtv\joyvsysguard.exe.vir (Trojan.Downloader) -> Quarantined and deleted successfully. -------------------------------------------------------------------------- SUPERANTI spyware Log http://www.superantispyware.com Generated 02/05/2010 at 02:13 PM Application Version : 4.33.1000 Core Rules Database Version : 4560 Trace Rules Database Version: 2372 Scan type : Complete Scan Total Scan Time : 01:36:34 Memory items scanned : 319 Memory threats detected : 0 Registry items scanned : 6082 Registry threats detected : 0 File items scanned : 56890 File threats detected : 318 Adware.Tracking Cookie C:\Users\Kaleb\AppData\Roaming\Microsoft\Windows\Cookies\[emailprotected][1].txt C:\Users\Kaleb\AppData\Roaming\Microsoft\Windows\Cookies\[emailprotected][2].txt C:\Users\Kaleb\AppData\Roaming\Microsoft\Windows\Cookies\[emailprotected][1].txt C:\Users\Kaleb\AppData\Roaming\Microsoft\Windows\Cookies\[emailprotected][1].txt C:\Users\Kaleb\AppData\Roaming\Microsoft\Windows\Cookies\[emailprotected][1].txt C:\Users\Kaleb\AppData\Roaming\Microsoft\Windows\Cookies\[emailprotected][1].txt C:\Users\Kaleb\AppData\Roaming\Microsoft\Windows\Cookies\[emailprotected][1].txt C:\Users\Kaleb\AppData\Roaming\Microsoft\Windows\Cookies\[emailprotected][2].txt C:\Users\Kaleb\AppData\Roaming\Microsoft\Windows\Cookies\[emailprotected][2].txt C:\Users\Kaleb\AppData\Roaming\Microsoft\Windows\Cookies\[emailprotected][1].txt C:\Users\Kaleb\AppData\Roaming\Microsoft\Windows\Cookies\[emailprotected][1].txt C:\Users\Kaleb\AppData\Roaming\Microsoft\Windows\Cookies\[emailprotected][2].txt C:\Users\Kaleb\AppData\Roaming\Microsoft\Windows\Cookies\[emailprotected][1].txt C:\Users\Kaleb\AppData\Roaming\Microsoft\Windows\Cookies\[emailprotected][1].txt C:\Users\Kaleb\AppData\Roaming\Microsoft\Windows\Cookies\[emailprotected][1].txt C:\Users\Kaleb\AppData\Roaming\Microsoft\Windows\Cookies\[emailprotected][2].txt C:\Users\Kaleb\AppData\Roaming\Microsoft\Windows\Cookies\[emailprotected][1].txt C:\Users\Kaleb\AppData\Roaming\Microsoft\Windows\Cookies\[emailprotected][2].txt C:\Users\Kaleb\AppData\Roaming\Microsoft\Windows\Cookies\[emailprotected][2].txt C:\Users\Kaleb\AppData\Roaming\Microsoft\Windows\Cookies\[emailprotected][1].txt C:\Users\Kaleb\AppData\Roaming\Microsoft\Windows\Cookies\[emailprotected][2].txt C:\Users\Kaleb\AppData\Roaming\Microsoft\Windows\Cookies\[emailprotected][2].txt C:\Users\Kaleb\AppData\Roaming\Microsoft\Windows\Cookies\[emailprotected][1].txt C:\Users\Kaleb\AppData\Roaming\Microsoft\Windows\Cookies\[emailprotected][1].txt C:\Users\Kaleb\AppData\Roaming\Microsoft\Windows\Cookies\[emailprotected][2].txt C:\Users\Kaleb\AppData\Roaming\Microsoft\Windows\Cookies\[emailprotected][1].txt C:\Users\Kaleb\AppData\Roaming\Microsoft\Windows\Cookies\[emailprotected][3].txt C:\Users\Kaleb\AppData\Roaming\Microsoft\Windows\Cookies\[emailprotected][1].txt C:\Users\Kaleb\AppData\Roaming\Microsoft\Windows\Cookies\[emailprotected][1].txt C:\Users\Kaleb\AppData\Roaming\Microsoft\Windows\Cookies\[emailprotected][2].txt C:\Users\Kaleb\AppData\Roaming\Microsoft\Windows\Cookies\[emailprotected][1].txt C:\Users\Kaleb\AppData\Roaming\Microsoft\Windows\Cookies\[emailprotected][1].txt C:\Users\Kaleb\AppData\Roaming\Microsoft\Windows\Cookies\[emailprotected][2].txt C:\Users\Kaleb\AppData\Roaming\Microsoft\Windows\Cookies\[emailprotected][1].txt C:\Users\Kaleb\AppData\Roaming\Microsoft\Windows\Cookies\[emailprotected][1].txt C:\Users\Kaleb\AppData\Roaming\Microsoft\Windows\Cookies\[emailprotected][2].txt C:\Users\Kaleb\AppData\Roaming\Microsoft\Windows\Cookies\[emailprotected][1].txt C:\Users\Kaleb\AppData\Roaming\Microsoft\Windows\Cookies\[emailprotected][2].txt C:\Users\Kaleb\AppData\Roaming\Microsoft\Windows\Cookies\[emailprotected][2].txt C:\Users\Kaleb\AppData\Roaming\Microsoft\Windows\Cookies\[emailprotected][2].txt C:\Users\Kaleb\AppData\Roaming\Microsoft\Windows\Cookies\[emailprotected][1].txt C:\Users\Kaleb\AppData\Roaming\Microsoft\Windows\Cookies\[emailprotected][2].txt C:\Users\Kaleb\AppData\Roaming\Microsoft\Windows\Cookies\[emailprotected][2].txt C:\Users\Kaleb\AppData\Roaming\Microsoft\Windows\Cookies\[emailprotected][2].txt C:\Users\Kaleb\AppData\Roaming\Microsoft\Windows\Cookies\[emailprotected][2].txt C:\Users\Kaleb\AppData\Roaming\Microsoft\Windows\Cookies\[emailprotected][2].txt C:\Users\Kaleb\AppData\Roaming\Microsoft\Windows\Cookies\[emailprotected][1].txt C:\Users\Kaleb\AppData\Roaming\Microsoft\Windows\Cookies\[emailprotected][2].txt C:\Users\Kaleb\AppData\Roaming\Microsoft\Windows\Cookies\[emailprotected][2].txt C:\Users\Kaleb\AppData\Roaming\Microsoft\Windows\Cookies\[emailprotected][2].txt C:\Users\Kaleb\AppData\Roaming\Microsoft\Windows\Cookies\[emailprotected]orn[1].txt C:\Users\Kaleb\AppData\Roaming\Microsoft\Windows\Cookies\[emailprotected][2].txt C:\Users\Kaleb\AppData\Roaming\Microsoft\Windows\Cookies\[emailprotected][2].txt C:\Users\Kaleb\AppData\Roaming\Microsoft\Windows\Cookies\[emailprotected][1].txt C:\Users\Kaleb\AppData\Roaming\Microsoft\Windows\Cookies\[emailprotected][1].txt C:\Users\Kaleb\AppData\Roaming\Microsoft\Windows\Cookies\[emailprotected][1].txt C:\Users\Kaleb\AppData\Roaming\Microsoft\Windows\Cookies\[emailprotected][2].txt C:\Users\Kaleb\AppData\Roaming\Microsoft\Windows\Cookies\[emailprotected][1].txt C:\Users\Kaleb\AppData\Roaming\Microsoft\Windows\Cookies\[emailprotected][1].txt C:\Users\Kaleb\AppData\Roaming\Microsoft\Windows\Cookies\[emailprotected][1].txt C:\Users\Kaleb\AppData\Roaming\Microsoft\Windows\Cookies\[emailprotected][1].txt C:\Users\Kaleb\AppData\Roaming\Microsoft\Windows\Cookies\[emailprotected][1].txt C:\Users\Kaleb\AppData\Roaming\Microsoft\Windows\Cookies\[emailprotected][2].txt C:\Users\Kaleb\AppData\Roaming\Microsoft\Windows\Cookies\[emailprotected][2].txt C:\Users\Kaleb\AppData\Roaming\Microsoft\Windows\Cookies\[emailprotected][2].txt C:\Users\Kaleb\AppData\Roaming\Microsoft\Windows\Cookies\[emailprotected][1].txt C:\Users\Kaleb\AppData\Roaming\Microsoft\Windows\Cookies\[emailprotected][2].txt C:\Users\Kaleb\AppData\Roaming\Microsoft\Windows\Cookies\[emailprotected][1].txt C:\Users\Kaleb\AppData\Roaming\Microsoft\Windows\Cookies\[emailprotected][1].txt C:\Users\Kaleb\AppData\Roaming\Microsoft\Windows\Cookies\[emailprotected][1].txt C:\Users\Kaleb\AppData\Roaming\Microsoft\Windows\Cookies\[emailprotected][2].txt C:\Users\Kaleb\AppData\Roaming\Microsoft\Windows\Cookies\[emailprotected][1].txt C:\Users\Kaleb\AppData\Roaming\Microsoft\Windows\Cookies\[emailprotected][2].txt C:\Users\Kaleb\AppData\Roaming\Microsoft\Windows\Cookies\[emailprotected][1].txt C:\Users\Kaleb\AppData\Roaming\Microsoft\Windows\Cookies\[emailprotected][1].txt C:\Users\Kaleb\AppData\Roaming\Microsoft\Windows\Cookies\[emailprotected][2].txt C:\Users\Kaleb\AppData\Roaming\Microsoft\Windows\Cookies\[emailprotected][1].txt C:\Users\Kaleb\AppData\Roaming\Microsoft\Windows\Cookies\[emailprotected][1].txt C:\Users\Kaleb\AppData\Roaming\Microsoft\Windows\Cookies\[emailprotected][1].txt C:\Users\Kaleb\AppData\Roaming\Microsoft\Windows\Cookies\[emailprotected][2].txt C:\Users\Kaleb\AppData\Roaming\Microsoft\Windows\Cookies\[emailprotected][1].txt C:\Users\Kaleb\AppData\Roaming\Microsoft\Windows\Cookies\[emailprotected][1].txt C:\Users\Kaleb\AppData\Roaming\Microsoft\Windows\Cookies\[emailprotected][2].txt C:\Users\Kaleb\AppData\Roaming\Microsoft\Windows\Cookies\[emailprotected][1].txt C:\Users\Kaleb\AppData\Roaming\Microsoft\Windows\Cookies\[emailprotected][2].txt C:\Users\Kaleb\AppData\Roaming\Microsoft\Windows\Cookies\[emailprotected][2].txt C:\Users\Kaleb\AppData\Roaming\Microsoft\Windows\Cookies\[emailprotected][1].txt C:\Users\Kaleb\AppData\Roaming\Microsoft\Windows\Cookies\[emailprotected][1].txt C:\Users\Kaleb\AppData\Roaming\Microsoft\Windows\Cookies\[emailprotected][1].txt C:\Users\Kaleb\AppData\Roaming\Microsoft\Windows\Cookies\[emailprotected][1].txt C:\Users\Kaleb\AppData\Roaming\Microsoft\Windows\Cookies\[emailprotected][1].txt C:\Users\Kaleb\AppData\Roaming\Microsoft\Windows\Cookies\[emailprotected][1].txt C:\Users\Kaleb\AppData\Roaming\Microsoft\Windows\Cookies\[emailprotected][1].txt C:\Users\Kaleb\AppData\Roaming\Microsoft\Windows\Cookies\[emailprotected][1].txt C:\Users\Kaleb\AppData\Roaming\Microsoft\Windows\Cookies\[emailprotected][2].txt C:\Users\Kaleb\AppData\Roaming\Microsoft\Windows\Cookies\[emailprotected][1].txt C:\Users\Kaleb\AppData\Roaming\Microsoft\Windows\Cookies\[emailprotected][2].txt C:\Users\Kaleb\AppData\Roaming\Microsoft\Windows\Cookies\[emailprotected][2].txt C:\Users\Kaleb\AppData\Roaming\Microsoft\Windows\Cookies\[emailprotected][1].txt C:\Users\Kaleb\AppData\Roaming\Microsoft\Windows\Cookies\[emailprotected][1].txt C:\Users\Kaleb\AppData\Roaming\Microsoft\Windows\Cookies\[emailprotected][2].txt C:\Users\Kaleb\AppData\Roaming\Microsoft\Windows\Cookies\[emailprotected][2].txt C:\Users\Kaleb\AppData\Roaming\Microsoft\Windows\Cookies\[emailprotected][1].txt C:\Users\Kaleb\AppData\Roaming\Microsoft\Windows\Cookies\[emailprotected][2].txt C:\Users\Kaleb\AppData\Roaming\Microsoft\Windows\Cookies\[emailprotected][2].txt C:\Users\Kaleb\AppData\Roaming\Microsoft\Windows\Cookies\[emailprotected][1].txt C:\Users\Kaleb\AppData\Roaming\Microsoft\Windows\Cookies\[emailprotected][2].txt C:\Users\Kaleb\AppData\Roaming\Microsoft\Windows\Cookies\[emailprotected][2].txt C:\Users\Kaleb\AppData\Roaming\Microsoft\Windows\Cookies\[emailprotected][1].txt C:\Users\Kaleb\AppData\Roaming\Microsoft\Windows\Cookies\[emailprotected][1].txt C:\Users\Kaleb\AppData\Roaming\Microsoft\Windows\Cookies\[emailprotected][1].txt C:\Users\Kaleb\AppData\Roaming\Microsoft\Windows\Cookies\[emailprotected][1].txt C:\Users\Kaleb\AppData\Roaming\Microsoft\Windows\Cookies\[emailprotected][2].txt C:\Users\Kaleb\AppData\Roaming\Microsoft\Windows\Cookies\[emailprotected][2].txt C:\Users\Kaleb\AppData\Roaming\Microsoft\Windows\Cookies\[emailprotected][1].txt C:\Users\Kaleb\AppData\Roaming\Microsoft\Windows\Cookies\[emailprotected][1].txt C:\Users\Kaleb\AppData\Roaming\Microsoft\Windows\Cookies\[emailprotected][1].txt C:\Users\Kaleb\AppData\Roaming\Microsoft\Windows\Cookies\[emailprotected][1].txt C:\Users\Kaleb\AppData\Roaming\Microsoft\Windows\Cookies\[emailprotected][2].txt C:\Users\Kaleb\AppData\Roaming\Microsoft\Windows\Cookies\[emailprotected][2].txt C:\Users\Kaleb\AppData\Roaming\Microsoft\Windows\Cookies\[emailprotected][2].txt C:\Users\Kaleb\AppData\Roaming\Microsoft\Windows\Cookies\[emailprotected][2].txt C:\Users\Kaleb\AppData\Roaming\Microsoft\Windows\Cookies\[emailprotected][2].txt C:\Users\Kaleb\AppData\Roaming\Microsoft\Windows\Cookies\[emailprotected][1].txt C:\Users\Kaleb\AppData\Roaming\Microsoft\Windows\Cookies\[emailprotected][1].txt C:\Users\Kaleb\AppData\Roaming\Microsoft\Windows\Cookies\[emailprotected][1].txt C:\Users\Kaleb\AppData\Roaming\Microsoft\Windows\Cookies\[emailprotected][1].txt C:\Users\Kaleb\AppData\Roaming\Microsoft\Windows\Cookies\[emailprotected][2].txt C:\Users\Kaleb\AppData\Roaming\Microsoft\Windows\Cookies\[emailprotected][2].txt C:\Users\Kaleb\AppData\Roaming\Microsoft\Windows\Cookies\[emailprotected][1].txt C:\Users\Kaleb\AppData\Roaming\Microsoft\Windows\Cookies\[emailprotected][2].txt C:\Users\Kaleb\AppData\Roaming\Microsoft\Windows\Cookies\[emailprotected][1].txt C:\Users\Kaleb\AppData\Roaming\Microsoft\Windows\Cookies\[emailprotected][1].txt C:\Users\Kaleb\AppData\Roaming\Microsoft\Windows\Cookies\[emailprotected][1].txt C:\Users\Kaleb\AppData\Roaming\Microsoft\Windows\Cookies\[emailprotected][2].txt C:\Users\Kaleb\AppData\Roaming\Microsoft\Windows\Cookies\[emailprotected][1].txt C:\Users\Kaleb\AppData\Roaming\Microsoft\Windows\Cookies\[emailprotected][1].txt C:\Users\Kaleb\AppData\Roaming\Microsoft\Windows\Cookies\[emailprotected][3].txt C:\Users\Kaleb\AppData\Roaming\Microsoft\Windows\Cookies\[emailprotected][1].txt C:\Users\Kaleb\AppData\Roaming\Microsoft\Windows\Cookies\[emailprotected][3].txt C:\Users\Kaleb\AppData\Roaming\Microsoft\Windows\Cookies\[emailprotected][1].txt C:\Users\Kaleb\AppData\Roaming\Microsoft\Windows\Cookies\[emailprotected][1].txt C:\Users\Kaleb\AppData\Roaming\Microsoft\Windows\Cookies\[emailprotected][2].txt C:\Users\Kaleb\AppData\Roaming\Microsoft\Windows\Cookies\[emailprotected][2].txt C:\Users\Kaleb\AppData\Roaming\Microsoft\Windows\Cookies\[emailprotected][2].txt C:\Users\Kaleb\AppData\Roaming\Microsoft\Windows\Cookies\[emailprotected][2].txt C:\Users\Kaleb\AppData\Roaming\Microsoft\Windows\Cookies\[emailprotected][2].txt C:\Users\Kaleb\AppData\Roaming\Microsoft\Windows\Cookies\[emailprotected][2].txt C:\Users\Kaleb\AppData\Roaming\Microsoft\Windows\Cookies\[emailprotected][1].txt C:\Users\Kaleb\AppData\Roaming\Microsoft\Windows\Cookies\[emailprotected][2].txt C:\Users\Kaleb\AppData\Roaming\Microsoft\Windows\Cookies\[emailprotected][2].txt C:\Users\Kaleb\AppData\Roaming\Microsoft\Windows\Cookies\[emailprotected][2].txt C:\Users\Kaleb\AppData\Roaming\Microsoft\Windows\Cookies\[emailprotected][2].txt C:\Users\Kaleb\AppData\Roaming\Microsoft\Windows\Cookies\[emailprotected][2].txt C:\Users\Kaleb\AppData\Roaming\Microsoft\Windows\Cookies\[emailprotected][1].txt C:\Users\Kaleb\AppData\Roaming\Microsoft\Windows\Cookies\[emailprotected][1].txt C:\Users\Kaleb\AppData\Roaming\Microsoft\Windows\Cookies\[emailprotected][2].txt C:\Users\Kaleb\AppData\Roaming\Microsoft\Windows\Cookies\[emailprotected][1].txt C:\Users\Kaleb\AppData\Roaming\Microsoft\Windows\Cookies\[emailprotected][4].txt C:\Users\Kaleb\AppData\Roaming\Microsoft\Windows\Cookies\[emailprotected][1].txt C:\Users\Kaleb\AppData\Roaming\Microsoft\Windows\Cookies\[emailprotected][2].txt C:\Users\Kaleb\AppData\Roaming\Microsoft\Windows\Cookies\[emailprotected][1].txt C:\Users\Kaleb\AppData\Roaming\Microsoft\Windows\Cookies\[emailprotected][1].txt C:\Users\Kaleb\AppData\Roaming\Microsoft\Windows\Cookies\[emailprotected][2].txt C:\Users\Kaleb\AppData\Roaming\Microsoft\Windows\Cookies\[emailprotected][2].txt C:\Users\Kaleb\AppData\Roaming\Microsoft\Windows\Cookies\[emailprotected][1].txt C:\Users\Kaleb\AppData\Roaming\Microsoft\Windows\Cookies\[emailprotected][1].txt C:\Users\Kaleb\AppData\Roaming\Microsoft\Windows\Cookies\[emailprotected][2].txt C:\Users\Kaleb\AppData\Roaming\Microsoft\Windows\Cookies\[emailprotected][2].txt C:\Users\Kaleb\AppData\Roaming\Microsoft\Windows\Cookies\[emailprotected][1].txt C:\Users\Kaleb\AppData\Roaming\Microsoft\Windows\Cookies\[emailprotected][1].txt C:\Users\Kaleb\AppData\Roaming\Microsoft\Windows\Cookies\[emailprotected][1].txt C:\Users\Kaleb\AppData\Roaming\Microsoft\Windows\Cookies\[emailprotected][1].txt C:\Users\Kaleb\AppData\Roaming\Microsoft\Windows\Cookies\[emailprotected][1].txt C:\Users\Kaleb\AppData\Roaming\Microsoft\Windows\Cookies\[emailprotected][2].txt C:\Users\Kaleb\AppData\Roaming\Microsoft\Windows\Cookies\[emailprotected][1].txt C:\Users\Kaleb\AppData\Roaming\Microsoft\Windows\Cookies\[emailprotected][1].txt C:\Users\Kaleb\AppData\Roaming\Microsoft\Windows\Cookies\[emailprotected][2].txt C:\Users\Kaleb\AppData\Roaming\Microsoft\Windows\Cookies\[emailprotected][1].txt C:\Users\Kaleb\AppData\Roaming\Microsoft\Windows\Cookies\[emailprotected][1].txt C:\Users\Kaleb\AppData\Roaming\Microsoft\Windows\Cookies\[emailprotected][2].txt C:\Users\Kaleb\AppData\Roaming\Microsoft\Windows\Cookies\[emailprotected][1].txt C:\Users\Kaleb\AppData\Roaming\Microsoft\Windows\Cookies\[emailprotected][2].txt C:\Users\Kaleb\AppData\Roaming\Microsoft\Windows\Cookies\[emailprotected][1].txt C:\Users\Kaleb\AppData\Roaming\Microsoft\Windows\Cookies\[emailprotected][2].txt C:\Users\Kaleb\AppData\Roaming\Microsoft\Windows\Cookies\[emailprotected][2].txt C:\Users\Kaleb\AppData\Roaming\Microsoft\Windows\Cookies\[emailprotected][2].txt C:\Users\Kaleb\AppData\Roaming\Microsoft\Windows\Cookies\[emailprotected][1].txt C:\Users\Kaleb\AppData\Roaming\Microsoft\Windows\Cookies\[emailprotected][1].txt C:\Users\Kaleb\AppData\Roaming\Microsoft\Windows\Cookies\[emailprotected][2].txt C:\Users\Kaleb\AppData\Roaming\Microsoft\Windows\Cookies\[emailprotected][2].txt C:\Users\Kaleb\AppData\Roaming\Microsoft\Windows\Cookies\[emailprotected][1].txt C:\Users\Kaleb\AppData\Roaming\Microsoft\Windows\Cookies\[emailprotected][2].txt C:\Users\Kaleb\AppData\Roaming\Microsoft\Windows\Cookies\[emailprotected][2].txt C:\Users\Kaleb\AppData\Roaming\Microsoft\Windows\Cookies\[emailprotected][2].txt C:\Users\Kaleb\AppData\Roaming\Microsoft\Windows\Cookies\[emailprotected][2].txt C:\Users\Kaleb\AppData\Roaming\Microsoft\Windows\Cookies\[emailprotected][2].txt C:\Users\Kaleb\AppData\Roaming\Microsoft\Windows\Cookies\[emailprotected][3].txt C:\Users\Kaleb\AppData\Roaming\Microsoft\Windows\Cookies\[emailprotected][1].txt C:\Users\Kaleb\AppData\Roaming\Microsoft\Windows\Cookies\[emailprotected][1].txt C:\Users\Kaleb\AppData\Roaming\Microsoft\Windows\Cookies\[emailprotected][2].txt C:\Users\Kaleb\AppData\Roaming\Microsoft\Windows\Cookies\[emailprotected][2].txt C:\Users\Kaleb\AppData\Roaming\Microsoft\Windows\Cookies\[emailprotected][2].txt C:\Users\Kaleb\AppData\Roaming\Microsoft\Windows\Cookies\[emailprotected][1].txt C:\Users\Kaleb\AppData\Roaming\Microsoft\Windows\Cookies\[emailprotected][1].txt C:\Users\Kaleb\AppData\Roaming\Microsoft\Windows\Cookies\[emailprotected][2].txt C:\Users\Kaleb\AppData\Roaming\Microsoft\Windows\Cookies\[emailprotected][1].txt C:\Users\Kaleb\AppData\Roaming\Microsoft\Windows\Cookies\[emailprotected][1].txt C:\Users\Kaleb\AppData\Roaming\Microsoft\Windows\Cookies\[emailprotected][2].txt C:\Users\Kaleb\AppData\Roaming\Microsoft\Windows\Cookies\[emailprotected][2].txt C:\Users\Kaleb\AppData\Roaming\Microsoft\Windows\Cookies\[emailprotected][1].txt C:\Users\Kaleb\AppData\Roaming\Microsoft\Windows\Cookies\[emailprotected][2].txt C:\Users\Kaleb\AppData\Roaming\Microsoft\Windows\Cookies\[emailprotected][1].txt C:\Users\Kaleb\AppData\Roaming\Microsoft\Windows\Cookies\[emailprotected][2].txt C:\Users\Kaleb\AppData\Roaming\Microsoft\Windows\Cookies\[emailprotected][1].txt C:\Users\Kaleb\AppData\Roaming\Microsoft\Windows\Cookies\[emailprotected][2].txt C:\Users\Kaleb\AppData\Roaming\Microsoft\Windows\Cookies\[emailprotected][2].txt C:\Users\Kaleb\AppData\Roaming\Microsoft\Windows\Cookies\[emailprotected][1].txt C:\Users\Kaleb\AppData\Roaming\Microsoft\Windows\Cookies\[emailprotected][2].txt C:\Users\Kaleb\AppData\Roaming\Microsoft\Windows\Cookies\[emailprotected][1].txt C:\Users\Kaleb\AppData\Roaming\Microsoft\Windows\Cookies\[emailprotected][3].txt C:\Users\Kaleb\AppData\Roaming\Microsoft\Windows\Cookies\[emailprotected][2].txt C:\Users\Kaleb\AppData\Roaming\Microsoft\Windows\Cookies\[emailprotected][2].txt C:\Users\Kaleb\AppData\Roaming\Microsoft\Windows\Cookies\[emailprotected][2].txt C:\Users\Kaleb\AppData\Roaming\Microsoft\Windows\Cookies\[emailprotected][2].txt C:\Users\Kaleb\AppData\Roaming\Microsoft\Windows\Cookies\[emailprotected][1].txt C:\Users\Kaleb\AppData\Roaming\Microsoft\Windows\Cookies\[emailprotected][2].txt C:\Users\Kaleb\AppData\Roaming\Microsoft\Windows\Cookies\[emailprotected][1].txt C:\Users\Kaleb\AppData\Roaming\Microsoft\Windows\Cookies\[emailprotected][3].txt C:\Users\Kaleb\AppData\Roaming\Microsoft\Windows\Cookies\[emailprotected][2].txt C:\Users\Kaleb\AppData\Roaming\Microsoft\Windows\Cookies\[emailprotected][3].txt C:\Users\Kaleb\AppData\Roaming\Microsoft\Windows\Cookies\[emailprotected][1].txt C:\Users\Kaleb\AppData\Roaming\Microsoft\Windows\Cookies\[emailprotected][1].txt C:\Users\Kaleb\AppData\Roaming\Microsoft\Windows\Cookies\[emailprotected][1].txt C:\Users\Kaleb\AppData\Roaming\Microsoft\Windows\Cookies\[emailprotected][1].txt C:\Users\Kaleb\AppData\Roaming\Microsoft\Windows\Cookies\[emailprotected][1].txt C:\Users\Kaleb\AppData\Roaming\Microsoft\Windows\Cookies\[emailprotected][2].txt C:\Users\Kaleb\AppData\Roaming\Microsoft\Windows\Cookies\[emailprotected][1].txt C:\Users\Kaleb\AppData\Roaming\Microsoft\Windows\Cookies\[emailprotected][1].txt C:\Users\Kaleb\AppData\Roaming\Microsoft\Windows\Cookies\[emailprotected][1].txt C:\Users\Kaleb\AppData\Roaming\Microsoft\Windows\Cookies\[emailprotected][1].txt C:\Users\Kaleb\AppData\Roaming\Microsoft\Windows\Cookies\[emailprotected][2].txt C:\Users\Kaleb\AppData\Roaming\Microsoft\Windows\Cookies\[emailprotected][1].txt C:\Users\Kaleb\AppData\Roaming\Microsoft\Windows\Cookies\[emailprotected][1].txt C:\Users\Kaleb\AppData\Roaming\Microsoft\Windows\Cookies\[emailprotected][2].txt C:\Users\Kaleb\AppData\Roaming\Microsoft\Windows\Cookies\[emailprotected][1].txt C:\Users\Kaleb\AppData\Roaming\Microsoft\Windows\Cookies\[emailprotected][2].txt C:\Users\Kaleb\AppData\Roaming\Microsoft\Windows\Cookies\[emailprotected][3].txt C:\Users\Kaleb\AppData\Roaming\Microsoft\Windows\Cookies\[emailprotected][1].txt C:\Users\Kaleb\AppData\Roaming\Microsoft\Windows\Cookies\[emailprotected][2].txt C:\Users\Kaleb\AppData\Roaming\Microsoft\Windows\Cookies\[emailprotected][2].txt C:\Users\Kaleb\AppData\Roaming\Microsoft\Windows\Cookies\[emailprotected][1].txt C:\Users\Kaleb\AppData\Roaming\Microsoft\Windows\Cookies\[emailprotected][3].txt C:\Users\Kaleb\AppData\Roaming\Microsoft\Windows\Cookies\[emailprotected][2].txt C:\Users\Kaleb\AppData\Roaming\Microsoft\Windows\Cookies\[emailprotected][11].txt C:\Users\Kaleb\AppData\Roaming\Microsoft\Windows\Cookies\[emailprotected][2].txt C:\Users\Kaleb\AppData\Roaming\Microsoft\Windows\Cookies\[emailprotected][1].txt C:\Users\Kaleb\AppData\Roaming\Microsoft\Windows\Cookies\[emailprotected][1].txt C:\Users\Kaleb\AppData\Roaming\Microsoft\Windows\Cookies\[emailprotected][2].txt C:\Users\Kaleb\AppData\Roaming\Microsoft\Windows\Cookies\[emailprotected][1].txt C:\Users\Kaleb\AppData\Roaming\Microsoft\Windows\Cookies\[emailprotected][1].txt C:\Users\Kaleb\AppData\Roaming\Microsoft\Windows\Cookies\[emailprotected][1].txt C:\Users\Kaleb\AppData\Roaming\Microsoft\Windows\Cookies\[emailprotected][1].txt C:\Users\Kaleb\AppData\Roaming\Microsoft\Windows\Cookies\[emailprotected][2].txt C:\Users\Kaleb\AppData\Roaming\Microsoft\Windows\Cookies\[emailprotected][1].txt C:\Users\Kaleb\AppData\Roaming\Microsoft\Windows\Cookies\[emailprotected][1].txt C:\Users\Kaleb\AppData\Roaming\Microsoft\Windows\Cookies\[emailprotected][1].txt C:\Users\Kaleb\AppData\Roaming\Microsoft\Windows\Cookies\[emailprotected][2].txt C:\Users\Kaleb\AppData\Roaming\Microsoft\Windows\Cookies\[emailprotected][1].txt C:\Users\Kaleb\AppData\Roaming\Microsoft\Windows\Cookies\[emailprotected][1].txt C:\Users\Kaleb\AppData\Roaming\Microsoft\Windows\Cookies\[emailprotected][1].txt C:\Users\Kaleb\AppData\Roaming\Microsoft\Windows\Cookies\[emailprotected][1].txt C:\Users\Kaleb\AppData\Roaming\Microsoft\Windows\Cookies\[emailprotected][1].txt C:\Users\Kaleb\AppData\Roaming\Microsoft\Windows\Cookies\[emailprotected][1].txt C:\Users\Kaleb\AppData\Roaming\Microsoft\Windows\Cookies\[emailprotected][2].txt C:\Users\Kaleb\AppData\Roaming\Microsoft\Windows\Cookies\[emailprotected][1].txt C:\Users\Kaleb\AppData\Roaming\Microsoft\Windows\Cookies\[emailprotected][2].txt C:\Users\Kaleb\AppData\Roaming\Microsoft\Windows\Cookies\Low\[emailprotected][1].txt C:\Users\Kaleb\AppData\Roaming\Microsoft\Windows\Cookies\Low\[emailprotected][2].txt C:\Users\Kaleb\AppData\Roaming\Microsoft\Windows\Cookies\Low\[emailprotected]3.clickhype[1].txt C:\Users\Kaleb\AppData\Roaming\Microsoft\Windows\Cookies\Low\[emailprotected][1].txt C:\Users\Kaleb\AppData\Roaming\Microsoft\Windows\Cookies\Low\[emailprotected][2].txt C:\Users\Kaleb\AppData\Roaming\Microsoft\Windows\Cookies\Low\[emailprotected][1].txt C:\Users\Kaleb\AppData\Roaming\Microsoft\Windows\Cookies\Low\[emailprotected][1].txt C:\Users\Kaleb\AppData\Roaming\Microsoft\Windows\Cookies\Low\[emailprotected][2].txt C:\Users\Kaleb\AppData\Roaming\Microsoft\Windows\Cookies\Low\[emailprotected][1].txt C:\Users\Kaleb\AppData\Roaming\Microsoft\Windows\Cookies\Low\[emailprotected][1].txt C:\Users\Kaleb\AppData\Roaming\Microsoft\Windows\Cookies\Low\[emailprotected][1].txt C:\Users\Kaleb\AppData\Roaming\Microsoft\Windows\Cookies\Low\[emailprotected][1].txt C:\Users\Kaleb\AppData\Roaming\Microsoft\Windows\Cookies\Low\[emailprotected][1].txt C:\Users\Kaleb\AppData\Roaming\Microsoft\Windows\Cookies\Low\[emailprotected][1].txt C:\Users\Kaleb\AppData\Roaming\Microsoft\Windows\Cookies\Low\[emailprotected][1].txt C:\Users\Kaleb\AppData\Roaming\Microsoft\Windows\Cookies\Low\[emailprotected][2].txt C:\Users\Kaleb\AppData\Roaming\Microsoft\Windows\Cookies\Low\[emailprotected][1].txt C:\Users\Kaleb\AppData\Roaming\Microsoft\Windows\Cookies\Low\[emailprotected][1].txt C:\Users\Kaleb\AppData\Roaming\Microsoft\Windows\Cookies\Low\[emailprotected][1].txt C:\Users\Kaleb\AppData\Roaming\Microsoft\Windows\Cookies\Low\[emailprotected][2].txt C:\Users\Kaleb\AppData\Roaming\Microsoft\Windows\Cookies\Low\[emailprotected][2].txt C:\Users\Kaleb\AppData\Roaming\Microsoft\Windows\Cookies\Low\[emailprotected][1].txt C:\Users\Kaleb\AppData\Roaming\Microsoft\Windows\Cookies\Low\[emailprotected][1].txt C:\Users\Kaleb\AppData\Roaming\Microsoft\Windows\Cookies\Low\[emailprotected][2].txt C:\Users\Kaleb\AppData\Roaming\Microsoft\Windows\Cookies\Low\[emailprotected][1].txt C:\Users\Kaleb\AppData\Roaming\Microsoft\Windows\Cookies\Low\[emailprotected][1].txt C:\Users\Kaleb\AppData\Roaming\Microsoft\Windows\Cookies\Low\[emailprotected][1].txt C:\Users\Kaleb\AppData\Roaming\Microsoft\Windows\Cookies\Low\[emailprotected][1].txt C:\Users\Kaleb\AppData\Roaming\Microsoft\Windows\Cookies\Low\[emailprotected][2].txt C:\Users\Kaleb\AppData\Roaming\Microsoft\Windows\Cookies\Low\[emailprotected][2].txt C:\Users\Kaleb\AppData\Roaming\Microsoft\Windows\Cookies\Low\[emailprotected][1].txt C:\Users\Kaleb\AppData\Roaming\Microsoft\Windows\Cookies\Low\[emailprotected][2].txt C:\Users\Kaleb\AppData\Roaming\Microsoft\Windows\Cookies\Low\[emailprotected][1].txt C:\Users\Kaleb\AppData\Roaming\Microsoft\Windows\Cookies\Low\[emailprotected][2].txt C:\Users\Kaleb\AppData\Roaming\Microsoft\Windows\Cookies\Low\[emailprotected][1].txt C:\Users\Kaleb\AppData\Roaming\Microsoft\Windows\Cookies\Low\[emailprotected][2].txt C:\Users\Kaleb\AppData\Roaming\Microsoft\Windows\Cookies\Low\[emailprotected][1].txt C:\Users\Kaleb\AppData\Roaming\Microsoft\Windows\Cookies\Low\[emailprotected][2].txt C:\Users\Kaleb\AppData\Roaming\Microsoft\Windows\Cookies\Low\[emailprotected][1].txt C:\Users\Kaleb\AppData\Roaming\Microsoft\Windows\Cookies\Low\[emailprotected][1].txt Trojan.Dropper/Sys-NV C:\PROGRAM FILES\TENCENT\QQINTL\BIN\SELFUPDATE.EXE ------------------------------------------------------------------- [emailprotected] as downloader log: all ok # version=7 # OnlineScannerApp.exe=1.0.0.1 # OnlineScanner.ocx=1.0.0.6211 # api_version=3.0.2 # EOSSerial=64319a3b88c44540bfa4541fceec7e9d # end=finished # remove_checked=true # archives_checked=true # unwanted_checked=true # unsafe_checked=true # antistealth_checked=true # utc_time=2010-02-06 01:13:10 # local_time=2010-02-05 05:13:10 (-0800, Pacific Standard Time) # country="United States" # lang=1033 # osver=6.0.6001 NT Service Pack 1 # compatibility_mode=1029 16777213 100 100 0 0 0 0 # compatibility_mode=5892 16776574 100 100 0 102019924 0 0 # compatibility_mode=8192 67108863 100 0 0 0 0 0 # scanned=136705 # found=0 # cleaned=0 # scan_time=6393 To manually create a new Restore Point
To remove all of the tools we used and the files and folders they created, please do the following: Please download OTC.exe by OldTimer:
== Please download TFC by OldTimer to your desktop
Download Security Check by screen317 from SpywareInfoforum.org or Changelog.fr.
Results of screen317's Security Check version 0.99.1 Windows Vista Service Pack 1 (UAC is enabled) Out of date service pack!! `````````````````````````````` Antivirus/Firewall Check: Windows Firewall Disabled! AVG 9.0 ESET Online Scanner v3 a-squared Free 4.5 WMIC entry does not exist for antivirus; attempting automatic update. `````````````````````````````` Anti-malware/Other Utilities Check: Spybot - Search & Destroy SUPERAntiSpyware Free Edition Java(TM) SE Runtime Environment 6 Adobe Flash Player 10 Adobe Reader 8 Out of date Adobe Reader installed! `````````````````````````````` Process Check: objlist.exe by Laurent AVG avgwdsvc.exe AVG avgtray.exe AVG avgrsx.exe AVG avgnsx.exe AVG avgemc.exe AVG avgemc.exe `````````````````````````````` DNS Vulnerability Check: GREAT! (Not vulnerable to DNS cache poisoning) `````````End of Log``````````` Please consider updating to Windows Vista Service Pack 2 (SP2). Windows Vista Service Pack 2 (SP2) contains all the updates released since SP1 plus support for new types of hardware and emerging hardware standards. It is now available via Windows Update or as a standalone installation here. == Please download the newest version of Adobe Acrobat Reader from Adobe.com Before installing: it is important to remove older versions of Acrobat Reader since it does not do so automatically and old versions still leave you vulnerable. Go to the Control Panel and enter Add or Remove Programs. Search in the list for all previous installed versions of Adobe Acrobat Reader. Uninstall/Remove each of them. Once old versions are gone, please install the newest version. == Please read the following information that I have provided, which will help you prevent malicious software in the future. Please keep in mind, malware is a continuous danger on the Internet. It is highly important to stay safe while browsing, to prevent re-infection. Software recommendations Firewall
Resident Protection help A number of programs have resident protection and it is a good idea to run the resident protection of one of each type of program to maintain protection. However, it is important to run only one resident program of each type since they can conflict and become less effective. That means only one antivirus, firewall, and scanning anti-spyware program at a time. Passive protectors such as SpywareBlaster can be run with any of them. Rogue programs help There are a lot of rogue programs out there that want to scare you into giving them your money and some malware actually claims to be security programs. If you get a popup for a security program that you did not install yourself, do NOT click on it and ask for help immediately. It is very important to run an antivirus and firewall, but you can't always rely on REVIEWS and ads for information. Ask in a security forum that you trust if you are not sure. If you are unsure and looking for anti-spyware programs, you can find out if it is a rogue here: http://www.spywarewarrior.com/rogue_anti-spyware.htm Securing your computer
Mozilla's Firefox browser is a very good alternative. In addition to being generally more secure than Internet Explorer, it has a very good built-in popup blocker and add-ons, like NoScript, can make it even more secure. Opera is another good option. If you are interested:
|
|