Jump to content

Welcome to Geeks to Go - Register now for FREE

Need help with your computer or device? Want to learn new tech skills? You're in the right place!
Geeks to Go is a friendly community of tech experts who can solve any problem you have. Just create a free account and post your question. Our volunteers will reply quickly and guide you through the steps. Don't let tech troubles stop you. Join Geeks to Go now and get the support you need!

How it Works Create Account
Photo

OMG, The Adware/Spyware/Malware Never Stops!


  • Please log in to reply

#1
Webslinger64

Webslinger64

    Member

  • Member
  • PipPipPip
  • 567 posts

I have a PC that is constantly filling up with adware/spyware/malware and no matter how much I do to clean it out, it always returns in force and fairly quickly.

This PC is used by my wife primarily for blogging, social media, e-mail and news.  As a blogger, she does visit a lot of sites in the blogging world that I suspect are culprits.

Here's what typically happens.  While she's on the PC doing routine online stuff, it slows down tremendously; gmail accounts load very slowly, video play pauses/disrupts/freezes, web pages load slowly and such.  As a computer user, she's pretty hard on the PC in that she will open multiple browser tabs (upwards of 10-15 at a time) and leave them open all day/all night/ 24/7.  I personally don't think that's a good idea, but those are her habits.

When the PC slows down and she complains about it, I'll use the following programs in this order 1) SuperAntiSpyware, 2)Malwarebytes, 3)Avast antivirus scan, and sometimes I'll run an additional scan through Kaspersky Online Scanner.

Typically after running SuperAntispyware, the program will find anywhere from 600 to 1500 threats.  When the scan finishes, I delete all the threats.  Occassionally, Malwarebytes will find something and I delete those as well.  Up to this point, running Avast antivirus scan and Kaspersky online scan has not shown any viruses.

So, as an example, I ran all these programs yesterday afternoon.  SuperAntiSpyware found hundreds.  Cleaned it all out and the PC was running fast and smooth.  Here we are 24 hours later, ran the scan again and AGAIN found hundreds of threats.

I don't understand why all of this stuff keeps coming back.  Not sure if it's just her browsing habits, or something affecting the PC that I just can't get rid of using the programs I've mentioned.

We both have the exact same PC and mine rarely, if ever, has a problem with this stuff.  Is there something more I should be doing to check for a virus or malware that's deeply rooted in her PC?


Edited by Webslinger64, 29 February 2016 - 09:49 PM.

  • 0

Advertisements


#2
zep516

zep516

    Trusted Helper

  • Malware Removal
  • 8,093 posts
Hi! My name is zep516 and Welcome to Geekstogo!
I'll do the best I can to resolve your computer issue
Please make sure to carefully read any instruction that I give you. If you're not sure, or if something unexpected happens, don't continue Stop and ask! Never be afraid to ask questions! :)

Everything gets download to the desktop and tools are "Run as administrator."

Please download Farbar Recovery Scan Tool and save it to your Desktop.

Note: You need to run the version compatible with your system. If you are not sure which version applies to your system download both of them and try to run them. Only one of them will run on your system, that will be the right version.
  • Right click to run as administrator (XP users click run after receipt of Windows Security Warning - Open File). When the tool opens click Yes to disclaimer.
  • Press Scan button.
  • It will produce a log called FRST.txt in the same directory the tool is run from.
  • Please copy and paste log back here.
  • The first time the tool is run it generates another log (Addition.txt - also located in the same directory as FRST.exe/FRST64.exe). Please also paste that along with the FRST.txt into your reply.

  • 0

#3
Webslinger64

Webslinger64

    Member

  • Topic Starter
  • Member
  • PipPipPip
  • 567 posts

Thank you for the reply and sorry for the delay in getting these posted.  Here you go...

 

FRST.txt

Scan result of Farbar Recovery Scan Tool (FRST) (x64) Version:02-03-2016
Ran by Helena (administrator) on HELENA-PC (02-03-2016 15:22:10)
Running from C:\Users\Helena\Downloads
Loaded Profiles: Helena (Available Profiles: Helena)
Platform: Windows 7 Home Premium Service Pack 1 (X64) Language: English (United States)
Internet Explorer Version 11 (Default browser: FF)
Boot Mode: Normal
Tutorial for Farbar Recovery Scan Tool: http://www.geekstogo...very-scan-tool/

==================== Processes (Whitelisted) =================

(If an entry is included in the fixlist, the process will be closed. The file will not be moved.)

(AVAST Software) C:\Program Files\AVAST Software\Avast\AvastSvc.exe
(AVAST Software) C:\Program Files\AVAST Software\Avast\afwServ.exe
(SUPERAntiSpyware.com) C:\Program Files\SUPERAntiSpyware\SASCORE64.EXE
() C:\Program Files (x86)\Fatal1ty Utility\F-Stream Tuning\Bin\IOMonitorSrv.exe
() C:\Program Files (x86)\D-Link\DWA-121 revA\ANIWConnService.exe
(Intel® Corporation) C:\Program Files\Intel\iCLS Client\HeciServer.exe
(Qualcomm Atheros) C:\Program Files\Qualcomm Atheros\Network Manager\KillerService.exe
(TeamViewer GmbH) C:\Program Files (x86)\TeamViewer\Version9\TeamViewer_Service.exe
(Microsoft Corp.) C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE
(Microsoft Corp.) C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVCM.EXE
(Intel Corporation) C:\Windows\System32\igfxtray.exe
(Intel Corporation) C:\Windows\System32\hkcmd.exe
(Intel Corporation) C:\Windows\System32\igfxsrvc.exe
(Intel Corporation) C:\Windows\System32\igfxpers.exe
(Realtek Semiconductor) C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe
(SUPERAntiSpyware) C:\Program Files\SUPERAntiSpyware\UPD2169.tmp
(CyberLink Corp.) C:\Program Files (x86)\CyberLink\Power2Go8\Power2GoExpress8.exe
() C:\Program Files\Qualcomm Atheros\Network Manager\NetworkManager.exe
(Intel Corporation) C:\Program Files (x86)\Intel\Intel® USB 3.0 eXtensible Host Controller Driver\Application\iusb3mon.exe
(Microsoft Corporation) C:\Program Files (x86)\Microsoft Office\Office14\ONENOTEM.EXE
(D-Link Corp.) C:\Program Files (x86)\D-Link\DWA-121 revA\AirNCFG.exe
(AVAST Software) C:\Program Files\AVAST Software\Avast\avastui.exe
(CyberLink) C:\Program Files (x86)\CyberLink\Power2Go8\CLMLSvc_P2G8.exe
(Oracle Corporation) C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe
(Microsoft Corporation) C:\Windows\System32\GWX\GWX.exe
(Intel Corporation) C:\Program Files (x86)\Intel\Intel® Management Engine Components\DAL\jhi_service.exe
(Intel Corporation) C:\Program Files (x86)\Intel\Intel® Management Engine Components\LMS\LMS.exe
(Oracle Corporation) C:\Program Files (x86)\Common Files\Java\Java Update\jucheck.exe
(Microsoft Corporation) C:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPSVC.EXE
(Microsoft Corporation) C:\Program Files (x86)\Microsoft Office\Office14\WINWORD.EXE
(Microsoft Corporation) C:\Windows\splwow64.exe
(Microsoft Corporation) C:\Program Files (x86)\Microsoft Office\Office14\OUTLOOK.EXE
(Mozilla Corporation) C:\Program Files (x86)\Mozilla Firefox\firefox.exe


==================== Registry (Whitelisted) ===========================

(If an entry is included in the fixlist, the registry item will be restored to default or removed. The file will not be moved.)

HKLM\...\Run: [RTHDVCPL] => C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe [13636824 2013-07-25] (Realtek Semiconductor)
HKLM-x32\...\Run: [USB3MON] => C:\Program Files (x86)\Intel\Intel® USB 3.0 eXtensible Host Controller Driver\Application\iusb3mon.exe [292848 2013-04-10] (Intel Corporation)
HKLM-x32\...\Run: [D-Link D-Link DWA-121] => C:\Program Files (x86)\D-Link\DWA-121 revA\AirNCFG.exe [1079600 2013-03-19] (D-Link Corp.)
HKLM-x32\...\Run: [AvastUI.exe] => C:\Program Files\AVAST Software\Avast\AvastUI.exe [7139768 2016-02-15] (AVAST Software)
HKLM-x32\...\Run: [CLMLServer_For_P2G8] => C:\Program Files (x86)\CyberLink\Power2Go8\CLMLSvc_P2G8.exe [111120 2012-06-07] (CyberLink)
HKLM-x32\...\Run: [CLVirtualDrive] => C:\Program Files (x86)\CyberLink\Power2Go8\VirtualDrive.exe [491120 2012-08-14] (CyberLink Corp.)
HKLM-x32\...\Run: [BCSSync] => C:\Program Files (x86)\Microsoft Office\Office14\BCSSync.exe [89184 2012-11-05] (Microsoft Corporation)
HKLM-x32\...\Run: [SunJavaUpdateSched] => C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe [507776 2014-10-07] (Oracle Corporation)
Winlogon\Notify\igfxcui: C:\Windows\system32\igfxdev.dll (Intel Corporation)
HKU\S-1-5-21-3746497652-99284834-819367531-1000\...\Run: [Fatal1tySTU] => [X]
HKU\S-1-5-21-3746497652-99284834-819367531-1000\...\Run: [ASRockHDMISwitch] => [X]
HKU\S-1-5-21-3746497652-99284834-819367531-1000\...\Run: [SUPERAntiSpyware] => C:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe [7943072 2016-03-01] (SUPERAntiSpyware)
HKU\S-1-5-21-3746497652-99284834-819367531-1000\...\Run: [Power2GoExpress8] => C:\Program Files (x86)\CyberLink\Power2Go8\Power2GoExpress8.exe [1707632 2012-08-14] (CyberLink Corp.)
HKU\S-1-5-21-3746497652-99284834-819367531-1000\...\Run: [Zoom] => 0
HKU\S-1-5-21-3746497652-99284834-819367531-1000\...\RunOnce: [AsrOMG_Day0] => [X]
HKU\S-1-5-21-3746497652-99284834-819367531-1000\...\RunOnce: [AsrOMG_Day1] => [X]
HKU\S-1-5-21-3746497652-99284834-819367531-1000\...\RunOnce: [AsrOMG_Day2] => [X]
HKU\S-1-5-21-3746497652-99284834-819367531-1000\...\RunOnce: [AsrOMG_Day3] => [X]
HKU\S-1-5-21-3746497652-99284834-819367531-1000\...\RunOnce: [AsrOMG_Day4] => [X]
HKU\S-1-5-21-3746497652-99284834-819367531-1000\...\RunOnce: [AsrOMG_Day5] => [X]
HKU\S-1-5-21-3746497652-99284834-819367531-1000\...\RunOnce: [AsrOMG_Day6] => [X]
HKU\S-1-5-21-3746497652-99284834-819367531-1000\...\MountPoints2: G - G:\VZW_Software_upgrade_assistant.exe
HKU\S-1-5-21-3746497652-99284834-819367531-1000\...\MountPoints2: {20f431d5-8ea1-11e3-851b-bc5ff4e83965} - E:\VZW_Software_upgrade_assistant.exe
HKU\S-1-5-21-3746497652-99284834-819367531-1000\...\MountPoints2: {20f431e3-8ea1-11e3-851b-bc5ff4e83965} - E:\VZW_Software_upgrade_assistant.exe
HKU\S-1-5-21-3746497652-99284834-819367531-1000\...\MountPoints2: {66a96897-5ad1-11e4-9346-bc5ff4e83965} - G:\VZW_Software_upgrade_assistant.exe
HKU\S-1-5-21-3746497652-99284834-819367531-1000\...\MountPoints2: {8c3b3ec5-b40b-11e5-aa1c-bc5ff4e83965} - E:\LaunchU3.exe -a
HKU\S-1-5-18\...\Run: [KSS] => "C:\Program Files (x86)\Kaspersky Lab\Kaspersky Security Scan\kss.exe" autorun
ShellIconOverlayIdentifiers: [00avast] -> {472083B0-C522-11CF-8763-00608CC02F24} => C:\Program Files\AVAST Software\Avast\ashShA64.dll [2016-02-11] (AVAST Software)
Startup: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\Killer Network Manager.lnk [2014-01-17]
ShortcutTarget: Killer Network Manager.lnk -> C:\Windows\Installer\{401FADAA-1C16-4721-9F02-19067E1A1CA8}\NetworkManager.exe_130C27D738F34C89BDDF21BCFD74B56D.exe (Flexera Software LLC)
Startup: C:\Users\Helena\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\OneNote 2010 Screen Clipper and Launcher.lnk [2016-02-11]
ShortcutTarget: OneNote 2010 Screen Clipper and Launcher.lnk -> C:\Program Files (x86)\Microsoft Office\Office14\ONENOTEM.EXE (Microsoft Corporation)

==================== Internet (Whitelisted) ====================

(If an item is included in the fixlist, if it is a registry item it will be removed or restored to default.)

Tcpip\Parameters: [DhcpNameServer] 75.75.75.75 75.75.76.76
Tcpip\..\Interfaces\{84E3B946-060C-44A1-B082-3D7859732B3B}: [DhcpNameServer] 75.75.76.76 75.75.75.75
Tcpip\..\Interfaces\{A4E4995F-30E7-4BDF-849C-4FC850F0AC69}: [DhcpNameServer] 75.75.75.75 75.75.76.76

Internet Explorer:
==================
BHO: Groove GFS Browser Helper -> {72853161-30C5-4D22-B7F9-0BBC1D38A37E} -> C:\Program Files\Microsoft Office\Office14\GROOVEEX.DLL [2013-12-18] (Microsoft Corporation)
BHO: avast! Online Security -> {8E5E2654-AD2D-48bf-AC2D-D17F00898D06} -> C:\Program Files\AVAST Software\Avast\aswWebRepIE64.dll [2016-02-11] (AVAST Software)
BHO: Windows Live ID Sign-in Helper -> {9030D464-4C02-4ABF-8ECC-5164760863C6} -> C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll [2012-07-17] (Microsoft Corp.)
BHO: Office Document Cache Handler -> {B4F3A835-0E21-4959-BA22-42B3008E02FF} -> C:\Program Files\Microsoft Office\Office14\URLREDIR.DLL [2013-03-06] (Microsoft Corporation)
BHO-x32: Groove GFS Browser Helper -> {72853161-30C5-4D22-B7F9-0BBC1D38A37E} -> C:\Program Files (x86)\Microsoft Office\Office14\GROOVEEX.DLL [2013-12-18] (Microsoft Corporation)
BHO-x32: Java™ Plug-In SSV Helper -> {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} -> C:\Program Files (x86)\Java\jre1.8.0_25\bin\ssv.dll [2015-11-28] (Oracle Corporation)
BHO-x32: avast! Online Security -> {8E5E2654-AD2D-48bf-AC2D-D17F00898D06} -> C:\Program Files\AVAST Software\Avast\aswWebRepIE.dll [2016-02-11] (AVAST Software)
BHO-x32: Windows Live ID Sign-in Helper -> {9030D464-4C02-4ABF-8ECC-5164760863C6} -> C:\Program Files (x86)\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll [2012-07-17] (Microsoft Corp.)
BHO-x32: Office Document Cache Handler -> {B4F3A835-0E21-4959-BA22-42B3008E02FF} -> C:\Program Files (x86)\Microsoft Office\Office14\URLREDIR.DLL [2013-03-06] (Microsoft Corporation)
BHO-x32: Java™ Plug-In 2 SSV Helper -> {DBC80044-A445-435b-BC74-9C25C1C588A9} -> C:\Program Files (x86)\Java\jre1.8.0_25\bin\jp2ssv.dll [2015-11-28] (Oracle Corporation)
Toolbar: HKLM - No Name - {CC1A175A-E45B-41ED-A30C-C9B1D7A0C02F} -  No File
Handler-x32: belarc - {6318E0AB-2E93-11D1-B8ED-00608CC9A71F} - C:\Program Files (x86)\Belarc\BelarcAdvisor\System\BAVoilaX.dll [2015-11-13] (Belarc, Inc.)

FireFox:
========
FF ProfilePath: C:\Users\Helena\AppData\Roaming\Mozilla\Firefox\Profiles\ju292vok.default-1438795000345
FF DefaultSearchEngine.US: Google
FF Homepage: www.google.com/
FF Plugin: @adobe.com/FlashPlayer -> C:\Windows\system32\Macromed\Flash\NPSWF64_20_0_0_306.dll [2016-02-10] ()
FF Plugin: @microsoft.com/GENUINE -> disabled [No File]
FF Plugin: @microsoft.com/OfficeAuthz,version=14.0 -> C:\PROGRA~1\MICROS~2\Office14\NPAUTHZ.DLL [2010-01-09] (Microsoft Corporation)
FF Plugin-x32: @adobe.com/FlashPlayer -> C:\Windows\SysWOW64\Macromed\Flash\NPSWF32_20_0_0_306.dll [2016-02-10] ()
FF Plugin-x32: @intel-webapi.intel.com/Intel WebAPI ipt;version=4.0.5 -> C:\Program Files (x86)\Intel\Intel® Management Engine Components\IPT\npIntelWebAPIIPT.dll [2013-09-03] (Intel Corporation)
FF Plugin-x32: @intel-webapi.intel.com/Intel WebAPI updater -> C:\Program Files (x86)\Intel\Intel® Management Engine Components\IPT\npIntelWebAPIUpdater.dll [2013-09-03] (Intel Corporation)
FF Plugin-x32: @java.com/DTPlugin,version=11.25.2 -> C:\Program Files (x86)\Java\jre1.8.0_25\bin\dtplugin\npDeployJava1.dll [2015-11-28] (Oracle Corporation)
FF Plugin-x32: @java.com/JavaPlugin,version=11.25.2 -> C:\Program Files (x86)\Java\jre1.8.0_25\bin\plugin2\npjp2.dll [2015-11-28] (Oracle Corporation)
FF Plugin-x32: @microsoft.com/GENUINE -> disabled [No File]
FF Plugin-x32: @microsoft.com/OfficeAuthz,version=14.0 -> C:\PROGRA~2\MICROS~1\Office14\NPAUTHZ.DLL [2010-01-09] (Microsoft Corporation)
FF Plugin-x32: @microsoft.com/SharePoint,version=14.0 -> C:\PROGRA~2\MICROS~1\Office14\NPSPWRAP.DLL [2010-03-24] (Microsoft Corporation)
FF Plugin-x32: @microsoft.com/WLPG,version=16.4.3528.0331 -> C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll [2014-03-31] (Microsoft Corporation)
FF Plugin-x32: @videolan.org/vlc,version=2.1.2 -> C:\Program Files (x86)\VideoLAN\VLC\npvlc.dll [2013-12-08] (VideoLAN)
FF Plugin-x32: Adobe Reader -> C:\Program Files (x86)\Adobe\Acrobat Reader DC\Reader\AIR\nppdf32.dll [2015-12-18] (Adobe Systems Inc.)
FF Extension: NoSquint - C:\Users\Helena\AppData\Roaming\Mozilla\Firefox\Profiles\ju292vok.default-1438795000345\extensions\[email protected] [2015-08-05]
FF Extension: StumbleUpon - C:\Users\Helena\AppData\Roaming\Mozilla\Firefox\Profiles\ju292vok.default-1438795000345\extensions\{AE93811A-5C9A-4d34-8462-F7B864FC4696}.xpi [2015-09-05]
FF Extension: Pin It button - C:\Users\Helena\AppData\Roaming\Mozilla\Firefox\Profiles\ju292vok.default-1438795000345\Extensions\[email protected] [2015-09-03]
FF Extension: Shorten URL (bit.ly) - C:\Users\Helena\AppData\Roaming\Mozilla\Firefox\Profiles\ju292vok.default-1438795000345\Extensions\{a1109c2a-1187-4027-901d-13097b755625}.xpi [2015-08-05]
FF HKLM\...\Firefox\Extensions: [[email protected]] - C:\Program Files\AVAST Software\Avast\WebRep\FF
FF Extension: Avast Online Security - C:\Program Files\AVAST Software\Avast\WebRep\FF [2016-02-12]
FF HKLM-x32\...\Firefox\Extensions: [[email protected]] - C:\Program Files\AVAST Software\Avast\WebRep\FF
FF HKLM-x32\...\Firefox\Extensions: [[email protected]] - C:\Program Files\AVAST Software\Avast\SafePrice\FF
FF Extension: Avast SafePrice - C:\Program Files\AVAST Software\Avast\SafePrice\FF [2016-02-12]

==================== Services (Whitelisted) ========================

(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)

R2 !SASCORE; C:\Program Files\SUPERAntiSpyware\SASCORE64.EXE [172344 2014-08-12] (SUPERAntiSpyware.com)
R2 ASRockIOMon; C:\Program Files (x86)\Fatal1ty Utility\F-Stream Tuning\Bin\IOMonitorSrv.exe [454656 2013-05-28] () [File not signed]
R2 avast! Antivirus; C:\Program Files\AVAST Software\Avast\AvastSvc.exe [237096 2016-02-11] (AVAST Software)
R2 avast! Firewall; C:\Program Files\AVAST Software\Avast\afwServ.exe [119128 2016-02-11] (AVAST Software)
R2 D_Link_DWA-121_WPS; C:\Program Files (x86)\D-Link\DWA-121 revA\ANIWConnService.exe [49152 2012-12-24] () [File not signed]
R2 Intel® Capability Licensing Service Interface; C:\Program Files\Intel\iCLS Client\HeciServer.exe [733696 2013-05-11] (Intel® Corporation) [File not signed]
S3 Intel® Capability Licensing Service TCP IP Interface; C:\Program Files\Intel\iCLS Client\SocketHeciServer.exe [822232 2013-05-11] (Intel® Corporation)
R2 jhi_service; C:\Program Files (x86)\Intel\Intel® Management Engine Components\DAL\jhi_service.exe [169432 2013-09-03] (Intel Corporation)
S2 MBAMService; C:\Program Files (x86)\Malwarebytes Anti-Malware\mbamservice.exe [1135416 2015-10-05] (Malwarebytes)
R2 Qualcomm Atheros Killer Service V2; C:\Program Files\Qualcomm Atheros\Network Manager\KillerService.exe [343040 2013-08-08] (Qualcomm Atheros) [File not signed]
R2 WinDefend; C:\Program Files\Windows Defender\mpsvc.dll [1011712 2013-05-26] (Microsoft Corporation)
S3 AvastVBoxSvc; "C:\Program Files\AVAST Software\Avast\ng\vbox\AvastVBoxSVC.exe" [X]

===================== Drivers (Whitelisted) ==========================

(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)

R1 anodlwf; C:\Windows\System32\DRIVERS\anodlwfx.sys [15872 2010-06-08] ()
R3 AsrDrv101; C:\Windows\SysWOW64\Drivers\AsrDrv101.sys [22280 2014-01-17] (ASRock Incorporation)
S3 AsrHidFilter; C:\Windows\System32\DRIVERS\AsrHidFilter.sys [20232 2013-09-09] (ASRock Inc.)
R0 AsrRamDisk; C:\Windows\System32\DRIVERS\AsrRamDisk.sys [40200 2013-05-09] (ASRock Inc.)
R2 aswHwid; C:\Windows\system32\drivers\aswHwid.sys [37656 2016-02-11] (AVAST Software)
R1 aswKbd; C:\Windows\system32\drivers\aswKbd.sys [37144 2016-02-11] (AVAST Software)
R2 aswMonFlt; C:\Windows\system32\drivers\aswMonFlt.sys [107792 2016-02-11] (AVAST Software)
R0 aswNdisFlt; C:\Windows\System32\DRIVERS\aswNdisFlt.sys [478128 2016-02-11] (AVAST Software)
S1 aswNetSec; C:\Windows\system32\drivers\aswNetSec.sys [552880 2016-02-23] (AVAST Software)
R1 aswRdr; C:\Windows\system32\drivers\aswRdr2.sys [103064 2016-02-11] (AVAST Software)
R0 aswRvrt; C:\Windows\System32\Drivers\aswRvrt.sys [74544 2016-02-11] (AVAST Software)
R1 aswSnx; C:\Windows\system32\drivers\aswSnx.sys [1065720 2016-02-11] (AVAST Software)
R1 aswSP; C:\Windows\system32\drivers\aswSP.sys [463744 2016-02-23] (AVAST Software)
R2 aswStm; C:\Windows\system32\drivers\aswStm.sys [165344 2016-02-11] (AVAST Software)
R0 aswVmm; C:\Windows\System32\Drivers\aswVmm.sys [287016 2016-02-11] (AVAST Software)
R1 BfLwf; C:\Windows\System32\DRIVERS\bflwfx64.sys [67888 2013-02-13] (Qualcomm Atheros, Inc.)
R1 CLVirtualDrive; C:\Windows\System32\DRIVERS\CLVirtualDrive.sys [92536 2012-06-25] (CyberLink)
S3 DRTL8192cu; C:\Windows\System32\DRIVERS\RTL8192cu.sys [748648 2010-08-20] (Realtek Semiconductor Corporation                           )
S3 ebdrv; C:\Windows\system32\drivers\evbda.sys [3286016 2009-06-10] (Broadcom Corporation)
R3 ISCT; C:\Windows\System32\DRIVERS\ISCTD64.sys [46568 2013-08-07] ()
R3 Ke2200; C:\Windows\System32\DRIVERS\e22w7x64.sys [154320 2013-03-20] (Qualcomm Atheros, Inc.)
R3 MBAMProtector; C:\Windows\system32\drivers\mbam.sys [25816 2015-10-05] (Malwarebytes)
S3 MBAMWebAccessControl; C:\Windows\system32\drivers\mwac.sys [63704 2015-10-05] (Malwarebytes Corporation)
R3 MEIx64; C:\Windows\System32\DRIVERS\TeeDriverx64.sys [99288 2013-09-03] (Intel Corporation)
R1 SASDIFSV; C:\Program Files\SUPERAntiSpyware\SASDIFSV64.SYS [14928 2011-07-22] (SUPERAdBlocker.com and SUPERAntiSpyware.com)
R1 SASKUTIL; C:\Program Files\SUPERAntiSpyware\SASKUTIL64.SYS [12368 2011-07-12] (SUPERAdBlocker.com and SUPERAntiSpyware.com)
S2 VBoxAswDrv; \??\C:\Program Files\AVAST Software\Avast\ng\vbox\VBoxAswDrv.sys [X]

==================== NetSvcs (Whitelisted) ===================

(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)


==================== One Month Created files and folders ========

(If an entry is included in the fixlist, the file/folder will be moved.)

2016-03-02 15:22 - 2016-03-02 15:22 - 00017914 _____ C:\Users\Helena\Downloads\FRST.txt
2016-03-02 15:21 - 2016-03-02 15:22 - 00000000 ____D C:\FRST
2016-03-02 15:20 - 2016-03-02 15:20 - 02371584 _____ (Farbar) C:\Users\Helena\Downloads\FRST64.exe
2016-02-27 17:27 - 2016-02-27 17:41 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Auslogics
2016-02-27 17:27 - 2016-02-27 17:41 - 00000000 ____D C:\Program Files (x86)\Auslogics
2016-02-27 17:27 - 2016-02-27 17:27 - 07544696 _____ (Auslogics Labs Pty Ltd ) C:\Users\Helena\Downloads\disk-defrag-setup(1).exe
2016-02-27 17:27 - 2016-02-27 17:27 - 00001258 _____ C:\Users\Helena\Desktop\Auslogics DiskDefrag.lnk
2016-02-27 16:55 - 2016-02-27 17:03 - 00000000 ____D C:\ProgramData\Kaspersky Lab Setup Files
2016-02-27 16:55 - 2016-02-27 16:55 - 02622792 _____ (Kaspersky Lab) C:\Users\Helena\Downloads\kss16.0.0.1344en_ru_de_fr_es_pt_it_zh-hans_nl_pl_tr_cs_ko_id_vi_ar_fa_zh-hant_9328.exe
2016-02-27 16:41 - 2016-02-27 16:41 - 156899600 _____ (Microsoft Corporation) C:\Users\Helena\Downloads\msert.exe
2016-02-25 14:03 - 2016-02-25 14:03 - 00165178 _____ C:\Users\Helena\Downloads\Untitled design.pdf
2016-02-24 15:50 - 2016-02-24 15:50 - 00065890 _____ C:\Users\Helena\Downloads\{7FFD0F2F-CF53-4FBC-A817-9C171CC70B04}.pdf
2016-02-23 18:13 - 2016-02-23 18:13 - 00114455 _____ C:\Users\Helena\Downloads\Longer LAsh(3).pdf
2016-02-23 18:09 - 2016-02-23 18:09 - 00114458 _____ C:\Users\Helena\Downloads\Longer LAsh(2).pdf
2016-02-23 17:51 - 2016-02-23 17:51 - 00114461 _____ C:\Users\Helena\Downloads\Longer LAsh(1).pdf
2016-02-23 17:48 - 2016-02-23 17:48 - 00115078 _____ C:\Users\Helena\Downloads\Longer LAsh.pdf
2016-02-22 22:09 - 2016-02-22 22:10 - 02092450 _____ C:\Users\Helena\Downloads\LongerLash Giveaway.pdf
2016-02-22 20:51 - 2016-02-22 20:51 - 00472987 _____ C:\Users\Helena\Downloads\Tomorrow hopes we have learned something from yesterday_.pdf
2016-02-20 23:02 - 2016-02-20 23:02 - 00098973 _____ C:\Users\Helena\Downloads\BYBC Session Notes.pdf
2016-02-15 16:42 - 2016-02-25 14:08 - 00000000 ____D C:\Users\Helena\Desktop\Green Esthetics
2016-02-12 20:57 - 2016-02-27 16:54 - 00003050 _____ C:\Windows\System32\Tasks\SafeZone scheduled Autoupdate 1455335821
2016-02-12 20:57 - 2016-02-15 17:53 - 00001242 _____ C:\Users\Public\Desktop\Avast SafeZone Browser.lnk
2016-02-12 20:57 - 2016-02-12 20:57 - 00000997 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Avast SafeZone Browser.lnk
2016-02-12 17:38 - 2016-02-22 21:46 - 00000000 ____D C:\Program Files (x86)\Mozilla Firefox
2016-02-11 21:56 - 2016-02-15 17:53 - 00002043 _____ C:\Users\Public\Desktop\Avast Internet Security.lnk
2016-02-11 21:55 - 2016-02-23 15:12 - 00552880 _____ (AVAST Software) C:\Windows\system32\Drivers\aswnetsec.sys
2016-02-11 21:55 - 2016-02-11 21:55 - 00478128 _____ (AVAST Software) C:\Windows\system32\Drivers\aswNdisFlt.sys
2016-02-11 21:55 - 2016-02-11 21:55 - 00398152 _____ (AVAST Software) C:\Windows\system32\aswBoot.exe
2016-02-11 21:55 - 2016-02-11 21:55 - 00052184 _____ (AVAST Software) C:\Windows\avastSS.scr
2016-02-11 21:55 - 2016-02-11 21:55 - 00037144 _____ (AVAST Software) C:\Windows\system32\Drivers\aswKbd.sys
2016-02-11 17:54 - 2016-02-27 17:31 - 00003044 _____ C:\Windows\System32\Tasks\AsrKM
2016-02-10 06:59 - 2016-02-06 03:48 - 25839104 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.dll
2016-02-10 06:59 - 2016-02-06 03:32 - 02724864 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.tlb
2016-02-10 06:59 - 2016-02-06 03:24 - 02887680 _____ (Microsoft Corporation) C:\Windows\system32\iertutil.dll
2016-02-10 06:59 - 2016-02-06 03:11 - 00615936 _____ (Microsoft Corporation) C:\Windows\system32\ieui.dll
2016-02-10 06:59 - 2016-02-06 03:10 - 00144384 _____ (Microsoft Corporation) C:\Windows\system32\ieUnatt.exe
2016-02-10 06:59 - 2016-02-06 03:01 - 20366848 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.dll
2016-02-10 06:59 - 2016-02-06 02:54 - 02724864 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.tlb
2016-02-10 06:59 - 2016-02-06 02:43 - 02280448 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iertutil.dll
2016-02-10 06:59 - 2016-02-06 02:38 - 00476160 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieui.dll
2016-02-10 06:59 - 2016-02-06 02:37 - 00115712 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieUnatt.exe
2016-02-10 06:59 - 2016-02-06 02:32 - 14458368 _____ (Microsoft Corporation) C:\Windows\system32\ieframe.dll
2016-02-10 06:59 - 2016-02-06 02:16 - 12857856 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieframe.dll
2016-02-10 06:59 - 2016-02-06 02:09 - 01547264 _____ (Microsoft Corporation) C:\Windows\system32\urlmon.dll
2016-02-10 06:59 - 2016-02-06 01:54 - 01312256 _____ (Microsoft Corporation) C:\Windows\SysWOW64\urlmon.dll
2016-02-10 06:59 - 2016-01-16 12:06 - 00025024 _____ (Microsoft Corporation) C:\Windows\system32\CompatTelRunner.exe
2016-02-10 06:59 - 2016-01-16 11:54 - 01162240 _____ (Microsoft Corporation) C:\Windows\system32\aeinv.dll
2016-02-10 06:59 - 2016-01-11 07:08 - 01362944 _____ (Microsoft Corporation) C:\Windows\system32\appraiser.dll
2016-02-10 06:59 - 2016-01-11 07:08 - 00696320 _____ (Microsoft Corporation) C:\Windows\system32\invagent.dll
2016-02-10 06:59 - 2016-01-11 07:08 - 00677376 _____ (Microsoft Corporation) C:\Windows\system32\generaltel.dll
2016-02-10 06:59 - 2016-01-11 07:08 - 00499200 _____ (Microsoft Corporation) C:\Windows\system32\devinv.dll
2016-02-10 06:59 - 2016-01-11 07:08 - 00076800 _____ (Microsoft Corporation) C:\Windows\system32\acmigration.dll
2016-02-10 06:59 - 2016-01-06 12:02 - 00275456 _____ (Microsoft Corporation) C:\Windows\system32\InkEd.dll
2016-02-10 06:59 - 2016-01-06 12:02 - 00024576 _____ (Microsoft Corporation) C:\Windows\system32\jnwmon.dll
2016-02-10 06:59 - 2016-01-06 11:41 - 00216064 _____ (Microsoft Corporation) C:\Windows\SysWOW64\InkEd.dll
2016-02-10 06:58 - 2016-01-22 13:31 - 00387784 _____ (Microsoft Corporation) C:\Windows\system32\iedkcs32.dll
2016-02-10 06:58 - 2016-01-22 13:10 - 00341200 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iedkcs32.dll
2016-02-10 06:58 - 2016-01-21 23:56 - 00004096 _____ (Microsoft Corporation) C:\Windows\system32\ieetwcollectorres.dll
2016-02-10 06:58 - 2016-01-21 23:41 - 00066560 _____ (Microsoft Corporation) C:\Windows\system32\iesetup.dll
2016-02-10 06:58 - 2016-01-21 23:40 - 00571904 _____ (Microsoft Corporation) C:\Windows\system32\vbscript.dll
2016-02-10 06:58 - 2016-01-21 23:40 - 00417792 _____ (Microsoft Corporation) C:\Windows\system32\html.iec
2016-02-10 06:58 - 2016-01-21 23:40 - 00088064 _____ (Microsoft Corporation) C:\Windows\system32\MshtmlDac.dll
2016-02-10 06:58 - 2016-01-21 23:40 - 00048640 _____ (Microsoft Corporation) C:\Windows\system32\ieetwproxystub.dll
2016-02-10 06:58 - 2016-01-21 23:33 - 00054784 _____ (Microsoft Corporation) C:\Windows\system32\jsproxy.dll
2016-02-10 06:58 - 2016-01-21 23:32 - 00034304 _____ (Microsoft Corporation) C:\Windows\system32\iernonce.dll
2016-02-10 06:58 - 2016-01-21 23:29 - 06052352 _____ (Microsoft Corporation) C:\Windows\system32\jscript9.dll
2016-02-10 06:58 - 2016-01-21 23:27 - 00817664 _____ (Microsoft Corporation) C:\Windows\system32\jscript.dll
2016-02-10 06:58 - 2016-01-21 23:27 - 00814080 _____ (Microsoft Corporation) C:\Windows\system32\jscript9diag.dll
2016-02-10 06:58 - 2016-01-21 23:27 - 00114688 _____ (Microsoft Corporation) C:\Windows\system32\ieetwcollector.exe
2016-02-10 06:58 - 2016-01-21 23:20 - 00968704 _____ (Microsoft Corporation) C:\Windows\system32\MsSpellCheckingFacility.exe
2016-02-10 06:58 - 2016-01-21 23:17 - 00489984 _____ (Microsoft Corporation) C:\Windows\system32\dxtmsft.dll
2016-02-10 06:58 - 2016-01-21 23:09 - 00077824 _____ (Microsoft Corporation) C:\Windows\system32\JavaScriptCollectionAgent.dll
2016-02-10 06:58 - 2016-01-21 23:08 - 00107520 _____ (Microsoft Corporation) C:\Windows\system32\inseng.dll
2016-02-10 06:58 - 2016-01-21 23:05 - 00199680 _____ (Microsoft Corporation) C:\Windows\system32\msrating.dll
2016-02-10 06:58 - 2016-01-21 23:04 - 00092160 _____ (Microsoft Corporation) C:\Windows\system32\mshtmled.dll
2016-02-10 06:58 - 2016-01-21 23:02 - 00496640 _____ (Microsoft Corporation) C:\Windows\SysWOW64\vbscript.dll
2016-02-10 06:58 - 2016-01-21 23:02 - 00315392 _____ (Microsoft Corporation) C:\Windows\system32\dxtrans.dll
2016-02-10 06:58 - 2016-01-21 23:02 - 00062464 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iesetup.dll
2016-02-10 06:58 - 2016-01-21 23:01 - 00341504 _____ (Microsoft Corporation) C:\Windows\SysWOW64\html.iec
2016-02-10 06:58 - 2016-01-21 23:01 - 00047616 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieetwproxystub.dll
2016-02-10 06:58 - 2016-01-21 23:00 - 00152064 _____ (Microsoft Corporation) C:\Windows\system32\occache.dll
2016-02-10 06:58 - 2016-01-21 23:00 - 00064000 _____ (Microsoft Corporation) C:\Windows\SysWOW64\MshtmlDac.dll
2016-02-10 06:58 - 2016-01-21 22:55 - 00047104 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jsproxy.dll
2016-02-10 06:58 - 2016-01-21 22:55 - 00030720 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iernonce.dll
2016-02-10 06:58 - 2016-01-21 22:51 - 00663552 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jscript.dll
2016-02-10 06:58 - 2016-01-21 22:51 - 00620032 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jscript9diag.dll
2016-02-10 06:58 - 2016-01-21 22:50 - 00262144 _____ (Microsoft Corporation) C:\Windows\system32\webcheck.dll
2016-02-10 06:58 - 2016-01-21 22:48 - 00718336 _____ (Microsoft Corporation) C:\Windows\system32\ie4uinit.exe
2016-02-10 06:58 - 2016-01-21 22:47 - 00798208 _____ (Microsoft Corporation) C:\Windows\system32\msfeeds.dll
2016-02-10 06:58 - 2016-01-21 22:46 - 02123264 _____ (Microsoft Corporation) C:\Windows\system32\inetcpl.cpl
2016-02-10 06:58 - 2016-01-21 22:46 - 01359360 _____ (Microsoft Corporation) C:\Windows\system32\mshtmlmedia.dll
2016-02-10 06:58 - 2016-01-21 22:43 - 00416256 _____ (Microsoft Corporation) C:\Windows\SysWOW64\dxtmsft.dll
2016-02-10 06:58 - 2016-01-21 22:39 - 00060416 _____ (Microsoft Corporation) C:\Windows\SysWOW64\JavaScriptCollectionAgent.dll
2016-02-10 06:58 - 2016-01-21 22:38 - 00091136 _____ (Microsoft Corporation) C:\Windows\SysWOW64\inseng.dll
2016-02-10 06:58 - 2016-01-21 22:37 - 00168960 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msrating.dll
2016-02-10 06:58 - 2016-01-21 22:35 - 04611072 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jscript9.dll
2016-02-10 06:58 - 2016-01-21 22:35 - 00076288 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtmled.dll
2016-02-10 06:58 - 2016-01-21 22:34 - 00279040 _____ (Microsoft Corporation) C:\Windows\SysWOW64\dxtrans.dll
2016-02-10 06:58 - 2016-01-21 22:33 - 00130048 _____ (Microsoft Corporation) C:\Windows\SysWOW64\occache.dll
2016-02-10 06:58 - 2016-01-21 22:31 - 02597376 _____ (Microsoft Corporation) C:\Windows\system32\wininet.dll
2016-02-10 06:58 - 2016-01-21 22:27 - 00230400 _____ (Microsoft Corporation) C:\Windows\SysWOW64\webcheck.dll
2016-02-10 06:58 - 2016-01-21 22:25 - 00687104 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msfeeds.dll
2016-02-10 06:58 - 2016-01-21 22:24 - 02050560 _____ (Microsoft Corporation) C:\Windows\SysWOW64\inetcpl.cpl
2016-02-10 06:58 - 2016-01-21 22:24 - 01155072 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtmlmedia.dll
2016-02-10 06:58 - 2016-01-21 22:08 - 00800768 _____ (Microsoft Corporation) C:\Windows\system32\ieapfltr.dll
2016-02-10 06:58 - 2016-01-21 22:07 - 02120704 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wininet.dll
2016-02-10 06:58 - 2016-01-21 22:02 - 00710144 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieapfltr.dll
2016-02-10 06:57 - 2016-01-16 12:01 - 02085888 _____ (Microsoft Corporation) C:\Windows\system32\ole32.dll
2016-02-10 06:57 - 2016-01-16 11:36 - 01413632 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ole32.dll
2016-02-10 06:57 - 2016-01-11 12:05 - 03169792 _____ (Microsoft Corporation) C:\Windows\system32\wucltux.dll
2016-02-10 06:57 - 2016-01-11 12:05 - 00192512 _____ (Microsoft Corporation) C:\Windows\system32\wuwebv.dll
2016-02-10 06:57 - 2016-01-11 12:05 - 00098816 _____ (Microsoft Corporation) C:\Windows\system32\wudriver.dll
2016-02-10 06:57 - 2016-01-11 11:52 - 00091136 _____ (Microsoft Corporation) C:\Windows\system32\WinSetupUI.dll
2016-02-10 06:57 - 2016-01-11 11:47 - 00174080 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wuwebv.dll
2016-02-10 06:57 - 2016-01-11 11:26 - 02610176 _____ (Microsoft Corporation) C:\Windows\system32\wuaueng.dll
2016-02-10 06:57 - 2016-01-11 11:24 - 00709120 _____ (Microsoft Corporation) C:\Windows\system32\wuapi.dll
2016-02-10 06:57 - 2016-01-11 11:23 - 00140288 _____ (Microsoft Corporation) C:\Windows\system32\wuauclt.exe
2016-02-10 06:57 - 2016-01-11 11:23 - 00037888 _____ (Microsoft Corporation) C:\Windows\system32\wups2.dll
2016-02-10 06:57 - 2016-01-11 11:23 - 00037888 _____ (Microsoft Corporation) C:\Windows\system32\wuapp.exe
2016-02-10 06:57 - 2016-01-11 11:23 - 00036864 _____ (Microsoft Corporation) C:\Windows\system32\wups.dll
2016-02-10 06:57 - 2016-01-11 11:23 - 00012288 _____ (Microsoft Corporation) C:\Windows\system32\wu.upgrade.ps.dll
2016-02-10 06:57 - 2016-01-11 11:14 - 00573440 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wuapi.dll
2016-02-10 06:57 - 2016-01-11 11:14 - 00093696 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wudriver.dll
2016-02-10 06:57 - 2016-01-11 11:14 - 00035328 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wuapp.exe
2016-02-10 06:57 - 2016-01-11 11:14 - 00030208 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wups.dll
2016-02-10 06:57 - 2016-01-07 10:53 - 03211776 _____ (Microsoft Corporation) C:\Windows\system32\win32k.sys
2016-02-10 06:57 - 2016-01-07 10:42 - 00141312 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\mrxdav.sys
2016-02-10 06:57 - 2015-12-20 11:50 - 03180544 _____ (Microsoft Corporation) C:\Windows\system32\rdpcorets.dll
2016-02-10 06:57 - 2015-12-20 11:50 - 00016384 _____ (Microsoft Corporation) C:\Windows\system32\RdpGroupPolicyExtension.dll
2016-02-10 06:57 - 2015-12-20 07:08 - 00243200 _____ (Microsoft Corporation) C:\Windows\system32\rdpudd.dll
2016-02-10 06:56 - 2016-01-21 23:27 - 05573056 _____ (Microsoft Corporation) C:\Windows\system32\ntoskrnl.exe
2016-02-10 06:56 - 2016-01-21 23:27 - 00154560 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\ksecpkg.sys
2016-02-10 06:56 - 2016-01-21 23:27 - 00095680 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\ksecdd.sys
2016-02-10 06:56 - 2016-01-21 23:24 - 01733592 _____ (Microsoft Corporation) C:\Windows\system32\ntdll.dll
2016-02-10 06:56 - 2016-01-21 23:20 - 00503808 _____ (Microsoft Corporation) C:\Windows\system32\srcore.dll
2016-02-10 06:56 - 2016-01-21 23:20 - 00362496 _____ (Microsoft Corporation) C:\Windows\system32\wow64win.dll
2016-02-10 06:56 - 2016-01-21 23:20 - 00243712 _____ (Microsoft Corporation) C:\Windows\system32\wow64.dll
2016-02-10 06:56 - 2016-01-21 23:20 - 00215040 _____ (Microsoft Corporation) C:\Windows\system32\winsrv.dll
2016-02-10 06:56 - 2016-01-21 23:20 - 00210432 _____ (Microsoft Corporation) C:\Windows\system32\wdigest.dll
2016-02-10 06:56 - 2016-01-21 23:20 - 00135680 _____ (Microsoft Corporation) C:\Windows\system32\sspicli.dll
2016-02-10 06:56 - 2016-01-21 23:20 - 00086528 _____ (Microsoft Corporation) C:\Windows\system32\TSpkg.dll
2016-02-10 06:56 - 2016-01-21 23:20 - 00050176 _____ (Microsoft Corporation) C:\Windows\system32\srclient.dll
2016-02-10 06:56 - 2016-01-21 23:20 - 00028672 _____ (Microsoft Corporation) C:\Windows\system32\sspisrv.dll
2016-02-10 06:56 - 2016-01-21 23:20 - 00013312 _____ (Microsoft Corporation) C:\Windows\system32\wow64cpu.dll
2016-02-10 06:56 - 2016-01-21 23:19 - 14179840 _____ (Microsoft Corporation) C:\Windows\system32\shell32.dll
2016-02-10 06:56 - 2016-01-21 23:19 - 01214464 _____ (Microsoft Corporation) C:\Windows\system32\rpcrt4.dll
2016-02-10 06:56 - 2016-01-21 23:19 - 00344064 _____ (Microsoft Corporation) C:\Windows\system32\schannel.dll
2016-02-10 06:56 - 2016-01-21 23:19 - 00028160 _____ (Microsoft Corporation) C:\Windows\system32\secur32.dll
2016-02-10 06:56 - 2016-01-21 23:18 - 00961024 _____ (Microsoft Corporation) C:\Windows\system32\CPFilters.dll
2016-02-10 06:56 - 2016-01-21 23:18 - 00723968 _____ (Microsoft Corporation) C:\Windows\system32\EncDec.dll
2016-02-10 06:56 - 2016-01-21 23:18 - 00016384 _____ (Microsoft Corporation) C:\Windows\system32\ntvdm64.dll
2016-02-10 06:56 - 2016-01-21 23:17 - 00315392 _____ (Microsoft Corporation) C:\Windows\system32\msv1_0.dll
2016-02-10 06:56 - 2016-01-21 23:17 - 00312320 _____ (Microsoft Corporation) C:\Windows\system32\ncrypt.dll
2016-02-10 06:56 - 2016-01-21 23:17 - 00159744 _____ (Microsoft Corporation) C:\Windows\system32\mtxoci.dll
2016-02-10 06:56 - 2016-01-21 23:16 - 01461248 _____ (Microsoft Corporation) C:\Windows\system32\lsasrv.dll
2016-02-10 06:56 - 2016-01-21 23:16 - 00146432 _____ (Microsoft Corporation) C:\Windows\system32\msaudite.dll
2016-02-10 06:56 - 2016-01-21 23:16 - 00060416 _____ (Microsoft Corporation) C:\Windows\system32\msobjs.dll
2016-02-10 06:56 - 2016-01-21 23:15 - 01866752 _____ (Microsoft Corporation) C:\Windows\system32\ExplorerFrame.dll
2016-02-10 06:56 - 2016-01-21 23:15 - 01163264 _____ (Microsoft Corporation) C:\Windows\system32\kernel32.dll
2016-02-10 06:56 - 2016-01-21 23:15 - 00730112 _____ (Microsoft Corporation) C:\Windows\system32\kerberos.dll
2016-02-10 06:56 - 2016-01-21 23:15 - 00422400 _____ (Microsoft Corporation) C:\Windows\system32\KernelBase.dll
2016-02-10 06:56 - 2016-01-21 23:13 - 03993536 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ntkrnlpa.exe
2016-02-10 06:56 - 2016-01-21 23:13 - 03938752 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ntoskrnl.exe
2016-02-10 06:56 - 2016-01-21 23:13 - 00043520 _____ (Microsoft Corporation) C:\Windows\system32\csrsrv.dll
2016-02-10 06:56 - 2016-01-21 23:13 - 00043520 _____ (Microsoft Corporation) C:\Windows\system32\cryptbase.dll
2016-02-10 06:56 - 2016-01-21 23:13 - 00022016 _____ (Microsoft Corporation) C:\Windows\system32\credssp.dll
2016-02-10 06:56 - 2016-01-21 23:12 - 01940992 _____ (Microsoft Corporation) C:\Windows\system32\authui.dll
2016-02-10 06:56 - 2016-01-21 23:12 - 00880128 _____ (Microsoft Corporation) C:\Windows\system32\advapi32.dll
2016-02-10 06:56 - 2016-01-21 23:12 - 00686080 _____ (Microsoft Corporation) C:\Windows\system32\adtschema.dll
2016-02-10 06:56 - 2016-01-21 23:12 - 00006656 _____ (Microsoft Corporation) C:\Windows\system32\apisetschema.dll
2016-02-10 06:56 - 2016-01-21 23:12 - 00006144 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-security-base-l1-1-0.dll
2016-02-10 06:56 - 2016-01-21 23:12 - 00005120 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-file-l1-1-0.dll
2016-02-10 06:56 - 2016-01-21 23:12 - 00004608 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-threadpool-l1-1-0.dll
2016-02-10 06:56 - 2016-01-21 23:12 - 00004608 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-processthreads-l1-1-0.dll
2016-02-10 06:56 - 2016-01-21 23:12 - 00004096 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-sysinfo-l1-1-0.dll
2016-02-10 06:56 - 2016-01-21 23:12 - 00004096 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-synch-l1-1-0.dll
2016-02-10 06:56 - 2016-01-21 23:12 - 00004096 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-localregistry-l1-1-0.dll
2016-02-10 06:56 - 2016-01-21 23:12 - 00004096 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-localization-l1-1-0.dll
2016-02-10 06:56 - 2016-01-21 23:12 - 00003584 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-rtlsupport-l1-1-0.dll
2016-02-10 06:56 - 2016-01-21 23:12 - 00003584 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-processenvironment-l1-1-0.dll
2016-02-10 06:56 - 2016-01-21 23:12 - 00003584 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-namedpipe-l1-1-0.dll
2016-02-10 06:56 - 2016-01-21 23:12 - 00003584 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-misc-l1-1-0.dll
2016-02-10 06:56 - 2016-01-21 23:12 - 00003584 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-memory-l1-1-0.dll
2016-02-10 06:56 - 2016-01-21 23:12 - 00003584 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-libraryloader-l1-1-0.dll
2016-02-10 06:56 - 2016-01-21 23:12 - 00003584 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-heap-l1-1-0.dll
2016-02-10 06:56 - 2016-01-21 23:12 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-xstate-l1-1-0.dll
2016-02-10 06:56 - 2016-01-21 23:12 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-util-l1-1-0.dll
2016-02-10 06:56 - 2016-01-21 23:12 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-string-l1-1-0.dll
2016-02-10 06:56 - 2016-01-21 23:12 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-profile-l1-1-0.dll
2016-02-10 06:56 - 2016-01-21 23:12 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-io-l1-1-0.dll
2016-02-10 06:56 - 2016-01-21 23:12 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-interlocked-l1-1-0.dll
2016-02-10 06:56 - 2016-01-21 23:12 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-handle-l1-1-0.dll
2016-02-10 06:56 - 2016-01-21 23:12 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-fibers-l1-1-0.dll
2016-02-10 06:56 - 2016-01-21 23:12 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-errorhandling-l1-1-0.dll
2016-02-10 06:56 - 2016-01-21 23:12 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-delayload-l1-1-0.dll
2016-02-10 06:56 - 2016-01-21 23:12 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-debug-l1-1-0.dll
2016-02-10 06:56 - 2016-01-21 23:12 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-datetime-l1-1-0.dll
2016-02-10 06:56 - 2016-01-21 23:12 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-console-l1-1-0.dll
2016-02-10 06:56 - 2016-01-21 23:09 - 01314328 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ntdll.dll
2016-02-10 06:56 - 2016-01-21 23:06 - 01114112 _____ (Microsoft Corporation) C:\Windows\SysWOW64\kernel32.dll
2016-02-10 06:56 - 2016-01-21 23:06 - 00665088 _____ (Microsoft Corporation) C:\Windows\SysWOW64\rpcrt4.dll
2016-02-10 06:56 - 2016-01-21 23:06 - 00275456 _____ (Microsoft Corporation) C:\Windows\SysWOW64\KernelBase.dll
2016-02-10 06:56 - 2016-01-21 23:06 - 00171520 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wdigest.dll
2016-02-10 06:56 - 2016-01-21 23:06 - 00096768 _____ (Microsoft Corporation) C:\Windows\SysWOW64\sspicli.dll
2016-02-10 06:56 - 2016-01-21 23:06 - 00065536 _____ (Microsoft Corporation) C:\Windows\SysWOW64\TSpkg.dll
2016-02-10 06:56 - 2016-01-21 23:06 - 00043008 _____ (Microsoft Corporation) C:\Windows\SysWOW64\srclient.dll
2016-02-10 06:56 - 2016-01-21 23:06 - 00005120 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wow32.dll
2016-02-10 06:56 - 2016-01-21 23:05 - 12877824 _____ (Microsoft Corporation) C:\Windows\SysWOW64\shell32.dll
2016-02-10 06:56 - 2016-01-21 23:05 - 00251392 _____ (Microsoft Corporation) C:\Windows\SysWOW64\schannel.dll
2016-02-10 06:56 - 2016-01-21 23:05 - 00022016 _____ (Microsoft Corporation) C:\Windows\SysWOW64\secur32.dll
2016-02-10 06:56 - 2016-01-21 23:04 - 00642048 _____ (Microsoft Corporation) C:\Windows\SysWOW64\CPFilters.dll
2016-02-10 06:56 - 2016-01-21 23:04 - 00535040 _____ (Microsoft Corporation) C:\Windows\SysWOW64\EncDec.dll
2016-02-10 06:56 - 2016-01-21 23:02 - 00553472 _____ (Microsoft Corporation) C:\Windows\SysWOW64\kerberos.dll
2016-02-10 06:56 - 2016-01-21 23:02 - 00259584 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msv1_0.dll
2016-02-10 06:56 - 2016-01-21 23:02 - 00223232 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ncrypt.dll
2016-02-10 06:56 - 2016-01-21 23:02 - 00176128 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msorcl32.dll
2016-02-10 06:56 - 2016-01-21 23:02 - 00146432 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msaudite.dll
2016-02-10 06:56 - 2016-01-21 23:02 - 00114176 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mtxoci.dll
2016-02-10 06:56 - 2016-01-21 23:02 - 00060416 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msobjs.dll
2016-02-10 06:56 - 2016-01-21 23:00 - 01498624 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ExplorerFrame.dll
2016-02-10 06:56 - 2016-01-21 22:59 - 01805824 _____ (Microsoft Corporation) C:\Windows\SysWOW64\authui.dll
2016-02-10 06:56 - 2016-01-21 22:59 - 00686080 _____ (Microsoft Corporation) C:\Windows\SysWOW64\adtschema.dll
2016-02-10 06:56 - 2016-01-21 22:59 - 00642560 _____ (Microsoft Corporation) C:\Windows\SysWOW64\advapi32.dll
2016-02-10 06:56 - 2016-01-21 22:59 - 00017408 _____ (Microsoft Corporation) C:\Windows\SysWOW64\credssp.dll
2016-02-10 06:56 - 2016-01-21 22:59 - 00006656 _____ (Microsoft Corporation) C:\Windows\SysWOW64\apisetschema.dll
2016-02-10 06:56 - 2016-01-21 22:59 - 00005120 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-file-l1-1-0.dll
2016-02-10 06:56 - 2016-01-21 22:59 - 00004608 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-processthreads-l1-1-0.dll
2016-02-10 06:56 - 2016-01-21 22:59 - 00004096 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-sysinfo-l1-1-0.dll
2016-02-10 06:56 - 2016-01-21 22:59 - 00004096 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-synch-l1-1-0.dll
2016-02-10 06:56 - 2016-01-21 22:59 - 00004096 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-misc-l1-1-0.dll
2016-02-10 06:56 - 2016-01-21 22:59 - 00004096 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-localregistry-l1-1-0.dll
2016-02-10 06:56 - 2016-01-21 22:59 - 00004096 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-localization-l1-1-0.dll
2016-02-10 06:56 - 2016-01-21 22:59 - 00003584 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-processenvironment-l1-1-0.dll
2016-02-10 06:56 - 2016-01-21 22:59 - 00003584 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-namedpipe-l1-1-0.dll
2016-02-10 06:56 - 2016-01-21 22:59 - 00003584 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-memory-l1-1-0.dll
2016-02-10 06:56 - 2016-01-21 22:59 - 00003584 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-libraryloader-l1-1-0.dll
2016-02-10 06:56 - 2016-01-21 22:59 - 00003584 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-interlocked-l1-1-0.dll
2016-02-10 06:56 - 2016-01-21 22:59 - 00003584 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-heap-l1-1-0.dll
2016-02-10 06:56 - 2016-01-21 22:59 - 00003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-string-l1-1-0.dll
2016-02-10 06:56 - 2016-01-21 22:59 - 00003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-rtlsupport-l1-1-0.dll
2016-02-10 06:56 - 2016-01-21 22:59 - 00003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-profile-l1-1-0.dll
2016-02-10 06:56 - 2016-01-21 22:59 - 00003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-io-l1-1-0.dll
2016-02-10 06:56 - 2016-01-21 22:59 - 00003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-handle-l1-1-0.dll
2016-02-10 06:56 - 2016-01-21 22:59 - 00003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-fibers-l1-1-0.dll
2016-02-10 06:56 - 2016-01-21 22:59 - 00003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-errorhandling-l1-1-0.dll
2016-02-10 06:56 - 2016-01-21 22:59 - 00003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-delayload-l1-1-0.dll
2016-02-10 06:56 - 2016-01-21 22:59 - 00003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-debug-l1-1-0.dll
2016-02-10 06:56 - 2016-01-21 22:59 - 00003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-datetime-l1-1-0.dll
2016-02-10 06:56 - 2016-01-21 22:59 - 00003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-console-l1-1-0.dll
2016-02-10 06:56 - 2016-01-21 22:19 - 03231232 _____ (Microsoft Corporation) C:\Windows\explorer.exe
2016-02-10 06:56 - 2016-01-21 22:13 - 00064000 _____ (Microsoft Corporation) C:\Windows\system32\auditpol.exe
2016-02-10 06:56 - 2016-01-21 22:12 - 02973184 _____ (Microsoft Corporation) C:\Windows\SysWOW64\explorer.exe
2016-02-10 06:56 - 2016-01-21 22:07 - 00338432 _____ (Microsoft Corporation) C:\Windows\system32\conhost.exe
2016-02-10 06:56 - 2016-01-21 22:07 - 00050176 _____ (Microsoft Corporation) C:\Windows\SysWOW64\auditpol.exe
2016-02-10 06:56 - 2016-01-21 22:05 - 00296960 _____ (Microsoft Corporation) C:\Windows\system32\rstrui.exe
2016-02-10 06:56 - 2016-01-21 21:59 - 00159232 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\mrxsmb.sys
2016-02-10 06:56 - 2016-01-21 21:58 - 00290816 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\mrxsmb10.sys
2016-02-10 06:56 - 2016-01-21 21:58 - 00129024 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\mrxsmb20.sys
2016-02-10 06:56 - 2016-01-21 21:57 - 00112640 _____ (Microsoft Corporation) C:\Windows\system32\smss.exe
2016-02-10 06:56 - 2016-01-21 21:57 - 00030720 _____ (Microsoft Corporation) C:\Windows\system32\lsass.exe
2016-02-10 06:56 - 2016-01-21 21:53 - 00025600 _____ (Microsoft Corporation) C:\Windows\SysWOW64\setup16.exe
2016-02-10 06:56 - 2016-01-21 21:53 - 00014336 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ntvdm64.dll
2016-02-10 06:56 - 2016-01-21 21:53 - 00007680 _____ (Microsoft Corporation) C:\Windows\SysWOW64\instnm.exe
2016-02-10 06:56 - 2016-01-21 21:53 - 00002048 _____ (Microsoft Corporation) C:\Windows\SysWOW64\user.exe
2016-02-10 06:56 - 2016-01-21 21:51 - 00036352 _____ (Microsoft Corporation) C:\Windows\SysWOW64\cryptbase.dll
2016-02-10 06:56 - 2016-01-21 21:51 - 00006144 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-security-base-l1-1-0.dll
2016-02-10 06:56 - 2016-01-21 21:51 - 00004608 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-threadpool-l1-1-0.dll
2016-02-10 06:56 - 2016-01-21 21:51 - 00003584 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-xstate-l1-1-0.dll
2016-02-10 06:56 - 2016-01-21 21:51 - 00003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-util-l1-1-0.dll
2016-02-06 10:12 - 2016-02-06 10:12 - 10202516 _____ C:\Users\Helena\Downloads\IWFGP Clip Art.pdf
2016-02-05 18:17 - 2016-02-05 18:17 - 00359082 _____ C:\Users\Helena\Downloads\document.pdf
2016-02-04 16:32 - 2016-02-04 16:32 - 01294517 _____ C:\Users\Helena\Downloads\Economic(1)
2016-02-04 16:26 - 2016-02-04 16:26 - 01271388 _____ C:\Users\Helena\Downloads\Economic

==================== One Month Modified files and folders ========

(If an entry is included in the fixlist, the file/folder will be moved.)

2016-03-02 15:20 - 2014-03-21 13:37 - 00000000 ____D C:\Users\Helena\Documents\Outlook Files
2016-03-02 14:49 - 2009-07-13 21:45 - 00028944 ____H C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
2016-03-02 14:49 - 2009-07-13 21:45 - 00028944 ____H C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
2016-03-02 14:19 - 2015-10-06 20:22 - 00000830 _____ C:\Windows\Tasks\Adobe Flash Player Updater.job
2016-03-01 21:00 - 2014-01-17 15:22 - 00000000 ____D C:\Program Files\SUPERAntiSpyware
2016-02-29 23:35 - 2015-01-03 18:29 - 00000000 ____D C:\Users\Helena\Desktop\A Gal Needs
2016-02-29 14:37 - 2009-07-13 22:13 - 00782470 _____ C:\Windows\system32\PerfStringBackup.INI
2016-02-29 14:37 - 2009-07-13 20:20 - 00000000 ____D C:\Windows\inf
2016-02-27 17:31 - 2015-09-07 18:13 - 00002984 _____ C:\Windows\System32\Tasks\HDMISwitch
2016-02-27 17:30 - 2009-07-13 22:08 - 00000006 ____H C:\Windows\Tasks\SA.DAT
2016-02-27 17:29 - 2015-07-03 13:42 - 00000000 ____D C:\Users\Helena\Desktop\Primary
2016-02-27 17:28 - 2014-01-17 15:13 - 00000000 ____D C:\ProgramData\Auslogics
2016-02-27 17:27 - 2015-09-06 08:57 - 00291328 ___SH C:\Users\Helena\Desktop\Thumbs.db
2016-02-27 17:18 - 2014-02-07 10:25 - 00000000 ____D C:\Program Files (x86)\Google
2016-02-27 16:52 - 2015-09-16 15:00 - 00000000 ____D C:\Users\Helena\AppData\Roaming\Zoom
2016-02-27 14:49 - 2014-08-29 19:51 - 00192216 _____ (Malwarebytes) C:\Windows\system32\Drivers\MBAMSwissArmy.sys
2016-02-27 03:00 - 2015-04-05 02:00 - 00000000 ___SD C:\Windows\SysWOW64\GWX
2016-02-27 03:00 - 2015-04-05 02:00 - 00000000 ___SD C:\Windows\system32\GWX
2016-02-24 21:38 - 2014-08-23 13:39 - 00000000 ____D C:\Users\Helena\Desktop\Web pictures
2016-02-23 15:12 - 2014-01-17 14:50 - 00463744 _____ (AVAST Software) C:\Windows\system32\Drivers\aswsp.sys
2016-02-22 21:46 - 2014-01-17 14:54 - 00000000 ____D C:\Program Files (x86)\Mozilla Maintenance Service
2016-02-22 14:35 - 2014-01-17 14:50 - 00004182 _____ C:\Windows\System32\Tasks\avast! Emergency Update
2016-02-19 23:43 - 2015-12-29 14:50 - 00000000 ____D C:\Users\Helena\Desktop\Novica
2016-02-18 03:02 - 2015-07-06 10:36 - 00002441 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Acrobat Reader DC.lnk
2016-02-16 18:31 - 2014-07-26 08:24 - 00000000 ____D C:\Users\Helena\AppData\Local\Windows Live
2016-02-14 16:10 - 2014-02-01 22:24 - 00000000 ____D C:\Users\Helena\Recipes
2016-02-11 21:55 - 2014-04-27 13:37 - 00037656 _____ (AVAST Software) C:\Windows\system32\Drivers\aswHwid.sys
2016-02-11 21:55 - 2014-01-17 14:50 - 01065720 _____ (AVAST Software) C:\Windows\system32\Drivers\aswSnx.sys
2016-02-11 21:55 - 2014-01-17 14:50 - 00287016 _____ (AVAST Software) C:\Windows\system32\Drivers\aswvmm.sys
2016-02-11 21:55 - 2014-01-17 14:50 - 00165344 _____ (AVAST Software) C:\Windows\system32\Drivers\aswStm.sys
2016-02-11 21:55 - 2014-01-17 14:50 - 00107792 _____ (AVAST Software) C:\Windows\system32\Drivers\aswMonFlt.sys
2016-02-11 21:55 - 2014-01-17 14:50 - 00103064 _____ (AVAST Software) C:\Windows\system32\Drivers\aswRdr2.sys
2016-02-11 21:55 - 2014-01-17 14:50 - 00074544 _____ (AVAST Software) C:\Windows\system32\Drivers\aswRvrt.sys
2016-02-11 21:55 - 2014-01-17 14:50 - 00000000 ____D C:\ProgramData\AVAST Software
2016-02-11 21:55 - 2014-01-17 14:50 - 00000000 ____D C:\Program Files\AVAST Software
2016-02-11 12:14 - 2009-07-13 20:20 - 00000000 ____D C:\Windows\rescache
2016-02-11 10:24 - 2014-08-02 06:34 - 00000000 ___RD C:\Users\Helena\Virtual Machines
2016-02-11 03:33 - 2009-07-13 21:45 - 00410232 _____ C:\Windows\system32\FNTCACHE.DAT
2016-02-11 03:31 - 2015-04-15 02:26 - 00000000 ____D C:\Windows\system32\appraiser
2016-02-11 03:31 - 2014-05-02 21:31 - 00000000 ___SD C:\Windows\system32\CompatTel
2016-02-11 03:31 - 2011-04-12 01:28 - 00000000 ____D C:\Program Files\Windows Journal
2016-02-11 03:16 - 2014-01-18 10:51 - 00000000 ____D C:\Windows\system32\MRT
2016-02-11 03:13 - 2014-01-18 10:51 - 146614896 _____ (Microsoft Corporation) C:\Windows\system32\MRT.exe
2016-02-11 03:13 - 2009-07-13 19:34 - 00000478 _____ C:\Windows\win.ini
2016-02-10 03:00 - 2016-01-19 21:19 - 08817344 _____ (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerInstaller.exe
2016-02-10 03:00 - 2015-10-06 20:22 - 00003768 _____ C:\Windows\System32\Tasks\Adobe Flash Player Updater
2016-02-10 03:00 - 2014-01-17 15:00 - 00796864 _____ (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerApp.exe
2016-02-10 03:00 - 2014-01-17 15:00 - 00142528 _____ (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerCPLApp.cpl
2016-02-07 21:12 - 2016-01-03 08:07 - 00000000 ____D C:\Users\Helena\AppData\Local\ElevatedDiagnostics
2016-02-07 07:39 - 2014-08-13 07:19 - 00000000 ___RD C:\Users\Helena\Desktop\Helena's Pictures from Panasonic Camera
2016-02-06 19:29 - 2015-04-10 17:23 - 00000000 ____D C:\Users\Helena\Desktop\Insightful

==================== Files in the root of some directories =======

2014-01-17 14:20 - 2014-01-17 14:20 - 0000000 _____ () C:\Users\Helena\AppData\Local\Driver_LOM_8161Present.flag
2014-01-17 14:14 - 2014-01-17 14:14 - 0000000 ____H () C:\ProgramData\DP45977C.lfl

Files to move or delete:
====================
C:\Users\Helena\jobq.dat


==================== Bamital & volsnap =================

(There is no automatic fix for files that do not pass verification.)

C:\Windows\system32\winlogon.exe => File is digitally signed
C:\Windows\system32\wininit.exe => File is digitally signed
C:\Windows\SysWOW64\wininit.exe => File is digitally signed
C:\Windows\explorer.exe => File is digitally signed
C:\Windows\SysWOW64\explorer.exe => File is digitally signed
C:\Windows\system32\svchost.exe => File is digitally signed
C:\Windows\SysWOW64\svchost.exe => File is digitally signed
C:\Windows\system32\services.exe => File is digitally signed
C:\Windows\system32\User32.dll => File is digitally signed
C:\Windows\SysWOW64\User32.dll => File is digitally signed
C:\Windows\system32\userinit.exe => File is digitally signed
C:\Windows\SysWOW64\userinit.exe => File is digitally signed
C:\Windows\system32\rpcss.dll => File is digitally signed
C:\Windows\system32\dnsapi.dll => File is digitally signed
C:\Windows\SysWOW64\dnsapi.dll => File is digitally signed
C:\Windows\system32\Drivers\volsnap.sys => File is digitally signed


LastRegBack: 2016-02-28 05:46

==================== End of FRST.txt ============================

 

Addition.txt

Additional scan result of Farbar Recovery Scan Tool (x64) Version:02-03-2016
Ran by Helena (2016-03-02 15:22:29)
Running from C:\Users\Helena\Downloads
Windows 7 Home Premium Service Pack 1 (X64) (2014-01-17 20:53:42)
Boot Mode: Normal
==========================================================


==================== Accounts: =============================

Administrator (S-1-5-21-3746497652-99284834-819367531-500 - Administrator - Disabled)
Guest (S-1-5-21-3746497652-99284834-819367531-501 - Limited - Disabled)
Helena (S-1-5-21-3746497652-99284834-819367531-1000 - Administrator - Enabled) => C:\Users\Helena
HomeGroupUser$ (S-1-5-21-3746497652-99284834-819367531-1002 - Limited - Enabled)

==================== Security Center ========================

(If an entry is included in the fixlist, it will be removed.)

AV: avast! Antivirus (Enabled - Up to date) {17AD7D40-BA12-9C46-7131-94903A54AD8B}
AS: Windows Defender (Enabled - Up to date) {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
AS: avast! Antivirus (Enabled - Up to date) {ACCC9CA4-9C28-93C8-4B81-AFE241D3E736}
FW: avast! Antivirus (Enabled) {2F96FC65-F07D-9D1E-5A6E-3DA5C487EAF0}

==================== Installed Programs ======================

(Only the adware programs with "Hidden" flag could be added to the fixlist to unhide them. The adware programs should be uninstalled manually.)

Adobe Acrobat Reader DC (HKLM-x32\...\{AC76BA86-7AD7-1033-7B44-AC0F074E4100}) (Version: 15.010.20059 - Adobe Systems Incorporated)
Adobe Flash Player 20 NPAPI (HKLM-x32\...\Adobe Flash Player NPAPI) (Version: 20.0.0.306 - Adobe Systems Incorporated)
ASRock HDMI Switch v1.0.25 (HKLM-x32\...\ASRock HDMI Switch_is1) (Version: 1.0.25 - )
ASRock Key Master v1.0.6 (HKLM-x32\...\ASRock Key Master_is1) (Version: 1.0.6 - )
ASRock XFast RAM v3.0.2 (HKLM\...\ASRock XFast RAM_is1) (Version:  - ASRock Inc.)
Auslogics DiskDefrag (HKLM-x32\...\{DF6A13C0-77DF-41FE-BD05-6D5201EB0CE7}_is1) (Version: 6.2.0.0 - Auslogics Labs Pty Ltd)
Avast Internet Security (HKLM-x32\...\Avast) (Version: 11.1.2253 - AVAST Software)
Belarc Advisor 8.5b (HKLM-x32\...\Belarc Advisor) (Version: 8.5.2.0 - Belarc Inc.)
CCleaner (HKLM\...\CCleaner) (Version: 4.09 - Piriform)
CollageIt 1.9.3 (HKLM-x32\...\{D9757258-30B2-496E-86F2-84920C5858E1}_is1) (Version: 1.9.3 - PearlMountain Technology Co., Ltd)
CyberLink Power2Go 8 (HKLM-x32\...\InstallShield_{2A87D48D-3FDF-41fd-97CD-A1E370EFFFE2}) (Version: 8.0.0.2014 - CyberLink Corp.)
D3DX10 (x32 Version: 15.4.2368.0902 - Microsoft) Hidden
D-Link DWA-121 (HKLM-x32\...\{ACB879B8-19A7-4310-BD93-5D745CA6B798}) (Version:  - D-Link Corporation)
E-Hammer (HKLM-x32\...\E-Hammer1.0.0) (Version: 1.0.0 - Asus)
FamilySearch Indexing 3.26.0 (HKLM-x32\...\0591-8077-9297-0833) (Version: 3.26.0 - FamilySearch)
F-Stream Tuning v2.0.39.1 (HKLM-x32\...\F-Stream Tuning_is1) (Version: 2.0.39.1 - )
Google Update Helper (x32 Version: 1.3.25.11 - Google Inc.) Hidden
HP Officejet Pro 8500 A910 Basic Device Software (HKLM\...\{EE7C94CC-BECB-4000-B5E3-D895307B9D5E}) (Version: 22.50.231.0 - Hewlett-Packard Co.)
HP Officejet Pro 8500 A910 Help (HKLM-x32\...\{871B2A9D-0F12-44B3-88C1-E0CB10A232E4}) (Version: 140.0.2.2 - Hewlett Packard)
I.R.I.S. OCR (HKLM-x32\...\{CA6BCA2F-EDEB-408F-850B-31404BE16A61}) (Version: 12.3.4.0 - HP)
Intel® Management Engine Components (HKLM-x32\...\{65153EA5-8B6E-43B6-857B-C6E4FC25798A}) (Version: 9.5.14.1724 - Intel Corporation)
Intel® Processor Graphics (HKLM-x32\...\{F0E3AD40-2BBD-4360-9C76-B9AC9A5886EA}) (Version: 9.18.10.3186 - Intel Corporation)
Intel® SDK for OpenCL - CPU Only Runtime Package (HKLM-x32\...\{FCB3772C-B7D0-4933-B1A9-3707EBACC573}) (Version: 3.0.0.66956 - Intel Corporation)
Intel® USB 3.0 eXtensible Host Controller Driver (HKLM-x32\...\{240C3DDD-C5E9-4029-9DF7-95650D040CF2}) (Version: 2.0.0.102 - Intel Corporation)
Java 7 Update 51 (HKLM-x32\...\{26A24AE4-039D-4CA4-87B4-2F83217051FF}) (Version: 7.0.510 - Oracle)
Java 8 Update 25 (HKLM-x32\...\{26A24AE4-039D-4CA4-87B4-2F83218025F0}) (Version: 8.0.250 - Oracle Corporation)
Malwarebytes Anti-Malware version 2.2.0.1024 (HKLM-x32\...\Malwarebytes Anti-Malware_is1) (Version: 2.2.0.1024 - Malwarebytes)
Microsoft .NET Framework 4.5.2 (HKLM\...\{92FB6C44-E685-45AD-9B20-CADF4CABA132} - 1033) (Version: 4.5.51209 - Microsoft Corporation)
Microsoft Office Professional Plus 2010 (HKLM-x32\...\Office14.PROPLUSR) (Version: 14.0.7015.1000 - Microsoft Corporation)
Microsoft SQL Server 2005 Compact Edition [ENU] (HKLM-x32\...\{F0B430D1-B6AA-473D-9B06-AA3DD01FD0B8}) (Version: 3.1.0000 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17 (HKLM-x32\...\{9A25302D-30C0-39D9-BD6F-21E6EC160475}) (Version: 9.0.30729 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.6161 (HKLM-x32\...\{9BE518E6-ECC6-35A9-88E4-87755C07200F}) (Version: 9.0.30729.6161 - Microsoft Corporation)
Microsoft Visual C++ 2010  x64 Redistributable - 10.0.40219 (HKLM\...\{1D8E6291-B0D5-35EC-8441-6616F567A0F7}) (Version: 10.0.40219 - Microsoft Corporation)
Microsoft Visual C++ 2010  x86 Redistributable - 10.0.40219 (HKLM-x32\...\{F0C3E5D1-1ADE-321E-8167-68EF0DE699A5}) (Version: 10.0.40219 - Microsoft Corporation)
Microsoft Visual C++ 2012 Redistributable (x64) - 11.0.61030 (HKLM-x32\...\{ca67548a-5ebe-413a-b50c-4b9ceb6d66c6}) (Version: 11.0.61030.0 - Microsoft Corporation)
Microsoft Visual Studio 2010 Tools for Office Runtime (x64) (HKLM\...\Microsoft Visual Studio 2010 Tools for Office Runtime (x64)) (Version: 10.0.50903 - Microsoft Corporation)
Movie Maker (x32 Version: 16.4.3528.0331 - Microsoft Corporation) Hidden
Mozilla Firefox 44.0.2 (x86 en-US) (HKLM-x32\...\Mozilla Firefox 44.0.2 (x86 en-US)) (Version: 44.0.2 - Mozilla)
Mozilla Maintenance Service (HKLM-x32\...\MozillaMaintenanceService) (Version: 44.0.2.5884 - Mozilla)
Qualcomm Atheros Bandwidth Control Filter Driver (Version: 1.0.30.1259 - Qualcomm Atheros) Hidden
Qualcomm Atheros Killer E220x Drivers (Version: 1.0.30.1259 - Qualcomm Atheros) Hidden
Qualcomm Atheros Killer Network Manager Suite (HKLM-x32\...\{FE5DFB80-6937-4154-A2C7-EF845C1301F8}) (Version: 1.0.30.1259 - Qualcomm Atheros)
Qualcomm Atheros Network Manager (Version: 1.0.30.1259 - Qualcomm Atheros) Hidden
Realtek High Definition Audio Driver (HKLM-x32\...\{F132AF7F-7BCA-4EDE-8A7C-958108FE7DBC}) (Version: 6.0.1.7004 - Realtek Semiconductor Corp.)
Revo Uninstaller 1.95 (HKLM-x32\...\Revo Uninstaller) (Version: 1.95 - VS Revo Group)
SafeZone Stable 1.48.2066.76 (x32 Version: 1.48.2066.76 - Avast Software) Hidden
Service Pack 2 for Microsoft Office 2010 (KB2687455) 32-Bit Edition (HKLM-x32\...\{91140000-0011-0000-0000-0000000FF1CE}_Office14.PROPLUSR_{DE28B448-32E8-4E8F-84F0-A52B21A49B5B}) (Version:  - Microsoft)
Speccy (HKLM\...\Speccy) (Version: 1.24 - Piriform)
SUPERAntiSpyware (HKLM\...\{CDDCBBF1-2703-46BC-938B-BCC81A1EEAAA}) (Version: 5.7.1018 - SUPERAntiSpyware.com)
TeamViewer 9 (HKLM-x32\...\TeamViewer 9) (Version: 9.0.41110 - TeamViewer)
VLC media player 2.1.2 (HKLM-x32\...\VLC media player) (Version: 2.1.2 - VideoLAN)
Windows Live Essentials (HKLM-x32\...\WinLiveSuite) (Version: 16.4.3528.0331 - Microsoft Corporation)
Windows XP Mode (HKLM\...\{1374CC63-B520-4f3f-98E8-E9020BF01CFF}) (Version: 1.3.7600.16432 - Microsoft Corporation)

==================== Custom CLSID (Whitelisted): ==========================

(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)

CustomCLSID: HKU\S-1-5-21-3746497652-99284834-819367531-1000_Classes\CLSID\{005A3A96-BAC4-4B0A-94EA-C0CE100EA736}\localserver32 -> C:\Users\Helena\AppData\Roaming\Dropbox\bin\Dropbox.exe /autoplay => No File

==================== Scheduled Tasks (Whitelisted) =============

(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)

Task: {05CD5EB4-1357-4D3C-9B4B-7360B9046F1D} - System32\Tasks\CCleanerSkipUAC => C:\Program Files\CCleaner\CCleaner.exe [2013-12-17] (Piriform Ltd)
Task: {18AAC443-E0DF-4293-9311-E3371C8B285F} - System32\Tasks\AVAST Software\Avast settings backup => C:\Program Files\Common Files\AV\avast! Antivirus\backup.exe [2016-02-18] (AVAST Software)
Task: {4578A731-F52D-490C-B20F-9D41AF761950} - System32\Tasks\Adobe Flash Player Updater => C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe [2016-02-10] (Adobe Systems Incorporated)
Task: {4618A907-6753-4532-9692-25BBFED0CB87} - System32\Tasks\Adobe Acrobat Update Task => C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe [2015-12-13] (Adobe Systems Incorporated)
Task: {80A30D52-C56D-4F6B-9BB9-73AB8853A1C8} - System32\Tasks\HDMISwitch => C:\Program Files (x86)\ASRock Utility\HDMISwitch\Bin\HDMISwitch.exe [2013-09-04] () <==== ATTENTION
Task: {9E6E1712-6541-411C-BFD9-4B42BF3A4EAA} - System32\Tasks\AsrKM => C:\Program Files (x86)\ASRock Utility\Key Master\AsrKM.exe [2013-09-06] ()
Task: {E1AD8EB0-FC13-48C8-9E3E-9E53931DDAE3} - System32\Tasks\avast! Emergency Update => C:\Program Files\AVAST Software\Avast\AvastEmUpdate.exe [2016-02-11] (AVAST Software)
Task: {E302203C-8B8D-4599-8A08-B2926C75E03F} - System32\Tasks\SafeZone scheduled Autoupdate 1455335821 => C:\Program Files\AVAST Software\SZBrowser\launcher.exe [2016-02-17] (Avast Software)

(If an entry is included in the fixlist, the task (.job) file will be moved. The file which is running by the task will not be moved.)

Task: C:\Windows\Tasks\Adobe Flash Player Updater.job => C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe

==================== Shortcuts =============================

(The entries could be listed to be restored or removed.)

==================== Loaded Modules (Whitelisted) ==============

2014-01-17 14:26 - 2013-05-28 18:58 - 00454656 _____ () C:\Program Files (x86)\Fatal1ty Utility\F-Stream Tuning\Bin\IOMonitorSrv.exe
2014-01-17 14:38 - 2012-12-24 21:08 - 00049152 _____ () C:\Program Files (x86)\D-Link\DWA-121 revA\ANIWConnService.exe
2013-09-04 23:17 - 2013-09-04 23:17 - 04300456 _____ () C:\Program Files\Common Files\Microsoft Shared\OFFICE14\Cultures\OFFICE.ODF
2010-10-20 14:23 - 2010-10-20 14:23 - 08801632 _____ () C:\Program Files\Microsoft Office\Office14\1033\GrooveIntlResource.dll
2013-08-08 15:30 - 2013-08-08 15:30 - 00283648 _____ () C:\Program Files\Qualcomm Atheros\Network Manager\NetworkManager.exe
2016-02-11 21:55 - 2016-02-11 21:55 - 00113496 _____ () C:\Program Files\AVAST Software\Avast\log.dll
2016-02-11 21:55 - 2016-02-11 21:55 - 00133768 _____ () C:\Program Files\AVAST Software\Avast\JsonRpcServer.dll
2016-02-27 12:40 - 2016-02-27 12:40 - 02835456 _____ () C:\Program Files\AVAST Software\Avast\defs\16022701\algo.dll
2016-02-11 21:55 - 2016-02-11 21:55 - 00480760 _____ () C:\Program Files\AVAST Software\Avast\ffl2.dll
2016-02-11 21:55 - 2016-02-11 21:55 - 00307808 _____ () C:\Program Files\AVAST Software\Avast\browser_pass.dll
2016-03-02 13:50 - 2016-03-02 13:50 - 02836992 _____ () C:\Program Files\AVAST Software\Avast\defs\16030201\algo.dll
2014-01-17 18:10 - 2012-08-15 05:29 - 00807440 _____ () C:\Program Files (x86)\CyberLink\Power2Go8\UNO.dll
2014-01-17 18:10 - 2012-08-01 03:47 - 01319024 _____ () C:\Program Files (x86)\CyberLink\Power2Go8\Language\ENU\P2GRC.dll
2014-01-17 18:10 - 2012-08-15 05:29 - 00176656 _____ () C:\Program Files (x86)\CyberLink\Power2Go8\CLVistaAudioMixer.dll
2014-01-17 14:39 - 2014-01-17 14:39 - 00315392 _____ () C:\Program Files (x86)\D-Link\DWA-121 revA\ANPDApi.dll
2014-01-17 14:38 - 2013-01-18 19:21 - 00303104 _____ () C:\Program Files (x86)\D-Link\DWA-121 revA\WlanApp.dll
2015-12-30 21:30 - 2015-12-30 21:30 - 40539648 _____ () C:\Program Files\AVAST Software\Avast\libcef.dll
2014-01-17 18:10 - 2012-06-07 20:34 - 00627216 _____ () C:\Program Files (x86)\CyberLink\Power2Go8\CLMediaLibrary.dll
2012-06-08 12:34 - 2012-06-08 12:34 - 00016400 _____ () C:\Program Files (x86)\CyberLink\Power2Go8\CLMLSvcPS.dll
2014-01-17 14:17 - 2013-09-03 17:52 - 01242584 _____ () C:\Program Files (x86)\Intel\Intel® Management Engine Components\LMS\ACE.dll
2013-09-04 23:14 - 2013-09-04 23:14 - 04300456 _____ () C:\Program Files (x86)\Common Files\Microsoft Shared\office14\Cultures\office.odf
2010-10-20 14:45 - 2010-10-20 14:45 - 08801120 _____ () C:\Program Files (x86)\Microsoft Office\Office14\1033\GrooveIntlResource.dll
2015-11-11 02:42 - 2015-11-11 02:42 - 01045672 _____ () C:\Program Files (x86)\Microsoft Office\Office14\ADDINS\UmOutlookAddin.dll
2013-09-04 23:14 - 2013-09-04 23:14 - 04300456 _____ () C:\Program Files (x86)\Common Files\microsoft shared\OFFICE14\Cultures\OFFICE.ODF

==================== Alternate Data Streams (Whitelisted) =========

(If an entry is included in the fixlist, only the ADS will be removed.)


==================== Safe Mode (Whitelisted) ===================

(If an entry is included in the fixlist, it will be removed from the registry. The "AlternateShell" will be restored.)


==================== EXE Association (Whitelisted) ===============

(If an entry is included in the fixlist, the registry item will be restored to default or removed.)


==================== Internet Explorer trusted/restricted ===============

(If an entry is included in the fixlist, it will be removed from the registry.)


==================== Hosts content: ===============================

(If needed Hosts: directive could be included in the fixlist to reset Hosts.)

2009-07-13 19:34 - 2009-06-10 14:00 - 00000824 ____A C:\Windows\system32\Drivers\etc\hosts


==================== Other Areas ============================

(Currently there is no automatic fix for this section.)

HKU\S-1-5-21-3746497652-99284834-819367531-1000\Control Panel\Desktop\\Wallpaper -> C:\Users\Helena\AppData\Roaming\Mozilla\Firefox\Desktop Background.bmp
DNS Servers: 75.75.75.75 - 75.75.76.76
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\System => (ConsentPromptBehaviorAdmin: 5) (ConsentPromptBehaviorUser: 3) (EnableLUA: 1)
Windows Firewall is enabled.

==================== MSCONFIG/TASK MANAGER disabled items ==

(Currently there is no automatic fix for this section.)


==================== FirewallRules (Whitelisted) ===============

(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)

FirewallRules: [{437AC30D-0F9B-43E7-9D26-C8636D8530B2}] => (Allow) C:\Program Files\HP\HP Officejet Pro 8500 A910\Bin\DeviceSetup.exe
FirewallRules: [{2F2ADC61-5CCA-46C3-AF0C-968FBD6DDDC2}] => (Allow) C:\Program Files\HP\HP Officejet Pro 8500 A910\Bin\DeviceSetup.exe
FirewallRules: [{E1DE450D-22E1-4515-9185-DEBB16A33A09}] => (Allow) C:\Program Files\HP\HP Officejet Pro 8500 A910\Bin\HPNetworkCommunicator.exe
FirewallRules: [{4DA3649B-B12B-4F9E-9A76-1DBDA889922D}] => (Allow) C:\Program Files\HP\HP Officejet Pro 8500 A910\Bin\HPNetworkCommunicator.exe
FirewallRules: [{844EF005-C26C-4E6C-B8C2-31A0C370EA96}] => (Allow) C:\Program Files (x86)\TeamViewer\Version9\TeamViewer.exe
FirewallRules: [{174D4580-3AB8-4A40-9B1E-28C59CF5312A}] => (Allow) C:\Program Files (x86)\TeamViewer\Version9\TeamViewer.exe
FirewallRules: [{1930773D-CE2B-4DFD-AF56-BA12ECF365D7}] => (Allow) C:\Program Files (x86)\TeamViewer\Version9\TeamViewer_Service.exe
FirewallRules: [{3D90784B-23D8-4111-8376-12FBDD9E0585}] => (Allow) C:\Program Files (x86)\TeamViewer\Version9\TeamViewer_Service.exe
FirewallRules: [VirtualPC-In-UDP-1] => (Allow) %SystemRoot%\System32\vpc.exe
FirewallRules: [VirtualPC-In-UDP-2] => (Allow) %SystemRoot%\System32\vpc.exe
FirewallRules: [VirtualPC-In-TCP-1] => (Allow) %SystemRoot%\System32\vpc.exe
FirewallRules: [TCP Query User{8A694256-2763-4166-9A98-A5A27CB75D38}C:\program files\hp\hp officejet pro 8500 a910\bin\hpnetworkcommunicator.exe] => (Allow) C:\program files\hp\hp officejet pro 8500 a910\bin\hpnetworkcommunicator.exe
FirewallRules: [UDP Query User{080F6635-8C33-401D-8ED9-56E58CBE1763}C:\program files\hp\hp officejet pro 8500 a910\bin\hpnetworkcommunicator.exe] => (Allow) C:\program files\hp\hp officejet pro 8500 a910\bin\hpnetworkcommunicator.exe
FirewallRules: [{CBAE2DFC-5892-40D5-8B64-429AEDD90798}] => (Allow) C:\Program Files (x86)\Windows Live\Contacts\wlcomm.exe
FirewallRules: [{77980433-A4CD-454B-9590-DC596FD977C5}] => (Allow) LPort=2869
FirewallRules: [{02CD281D-F5FE-4C16-BB5D-770C97885FB1}] => (Allow) LPort=1900
FirewallRules: [{0A6EDCEE-3772-4937-9259-9743EFE90218}] => (Allow) C:\Program Files (x86)\Mozilla Firefox\firefox.exe
FirewallRules: [{56591900-419A-4E7F-83C6-5B7E436A5867}] => (Allow) C:\Program Files (x86)\Mozilla Firefox\firefox.exe
FirewallRules: [TCP Query User{DE3875E1-1CBD-4B36-A128-98E6BE7B4277}C:\program files (x86)\mozilla firefox\firefox.exe] => (Allow) C:\program files (x86)\mozilla firefox\firefox.exe
FirewallRules: [UDP Query User{42A6BA4A-0B2F-47A4-AFBE-B33EB0EFCE18}C:\program files (x86)\mozilla firefox\firefox.exe] => (Allow) C:\program files (x86)\mozilla firefox\firefox.exe
FirewallRules: [{9C573DF7-AD6D-496C-94B5-36AD74F52831}] => (Allow) C:\Program Files (x86)\TeamViewer\Version9\TeamViewer.exe
FirewallRules: [{2D85E6BC-B7CC-4B73-BBB4-5B77121C545F}] => (Allow) C:\Program Files (x86)\TeamViewer\Version9\TeamViewer.exe
FirewallRules: [{4398F3A2-C44E-46A8-918B-588811245027}] => (Allow) C:\Program Files (x86)\TeamViewer\Version9\TeamViewer_Service.exe
FirewallRules: [{C1F7DDBC-9198-4C61-9BA1-250B989ABD0C}] => (Allow) C:\Program Files (x86)\TeamViewer\Version9\TeamViewer_Service.exe
FirewallRules: [{CA3F79F9-4A3F-40EE-93C6-95AD8EE2B646}] => (Allow) C:\Program Files (x86)\Mozilla Firefox\firefox.exe
FirewallRules: [{C0F79F1B-3D4F-45AD-8477-AE98AB1A9D3B}] => (Allow) C:\Program Files (x86)\Mozilla Firefox\firefox.exe
FirewallRules: [{20031123-092F-452E-BE60-71A0DE7F51DE}] => (Allow) C:\Program Files\AVAST Software\Avast\ng\vbox\aswFe.exe
FirewallRules: [{ABDB47A6-1625-4321-A12F-A284E0FB870A}] => (Allow) C:\Program Files\AVAST Software\Avast\ng\vbox\aswFe.exe

==================== Restore Points =========================

14-02-2016 03:00:18 Windows Update
15-02-2016 03:00:17 Windows Update
16-02-2016 03:00:20 Windows Update
17-02-2016 03:00:18 Windows Update
18-02-2016 03:00:17 Windows Update
19-02-2016 03:00:17 Windows Update
20-02-2016 03:00:18 Windows Update
21-02-2016 03:00:18 Windows Update
22-02-2016 03:00:19 Windows Update
23-02-2016 03:00:22 Windows Update
24-02-2016 03:00:17 Windows Update
25-02-2016 03:00:17 Windows Update
26-02-2016 03:00:18 Windows Update
27-02-2016 03:00:17 Windows Update
27-02-2016 16:51:26 Revo Uninstaller's restore point - Zoom
27-02-2016 17:03:09 Revo Uninstaller's restore point - Kaspersky Security Scan
27-02-2016 17:04:43 Revo Uninstaller's restore point - Kaspersky Software Updater Beta
27-02-2016 17:17:02 Revo Uninstaller's restore point - Google Chrome
27-02-2016 17:39:02 Revo Uninstaller's restore point - Auslogics BoostSpeed 8
27-02-2016 17:39:22 Revo Uninstaller's restore point - Auslogics BoostSpeed 8
01-03-2016 12:24:02 Windows Update

==================== Faulty Device Manager Devices =============


==================== Event log errors: =========================

Application errors:
==================
Error: (03/01/2016 05:38:00 PM) (Source: Application Hang) (EventID: 1002) (User: )
Description: The program DllHost.exe version 6.1.7600.16385 stopped interacting with Windows and was closed. To see if more information about the problem is available, check the problem history in the Action Center control panel.

Process ID: 11b8

Start Time: 01d173edf2449123

Termination Time: 3042

Application Path: C:\Windows\system32\DllHost.exe

Report Id: fcc38207-e00e-11e5-a5c8-bc5ff4e83965

Error: (02/27/2016 05:30:47 PM) (Source: WinMgmt) (EventID: 10) (User: )
Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003

Error: (02/26/2016 10:42:45 PM) (Source: Application Error) (EventID: 1000) (User: )
Description: Faulting application name: plugin-container.exe, version: 44.0.2.5884, time stamp: 0x56bbf417
Faulting module name: mozglue.dll, version: 44.0.2.5884, time stamp: 0x56bbe58e
Exception code: 0x80000003
Fault offset: 0x0000ed3b
Faulting process id: 0x28b8
Faulting application start time: 0xplugin-container.exe0
Faulting application path: plugin-container.exe1
Faulting module path: plugin-container.exe2
Report Id: plugin-container.exe3

Error: (02/22/2016 09:47:48 PM) (Source: WinMgmt) (EventID: 10) (User: )
Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003

Error: (02/18/2016 03:01:50 AM) (Source: MsiInstaller) (EventID: 1024) (User: Helena-PC)
Description: Product: Adobe Acrobat Reader DC - Update '{AC76BA86-7AD7-0000-2550-AC0F0A4E5B00}' could not be installed. Error code 1625. Windows Installer can create logs to help troubleshoot issues with installing software packages. Use the following link for instructions on turning on logging support: http://go.microsoft....k/?LinkId=23127

Error: (02/16/2016 10:47:07 PM) (Source: Application Error) (EventID: 1000) (User: )
Description: Faulting application name: plugin-container.exe, version: 44.0.2.5884, time stamp: 0x56bbf417
Faulting module name: mozglue.dll, version: 44.0.2.5884, time stamp: 0x56bbe58e
Exception code: 0x80000003
Fault offset: 0x0000ed3b
Faulting process id: 0x1520
Faulting application start time: 0xplugin-container.exe0
Faulting application path: plugin-container.exe1
Faulting module path: plugin-container.exe2
Report Id: plugin-container.exe3

Error: (02/12/2016 08:58:01 PM) (Source: WinMgmt) (EventID: 10) (User: )
Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003

Error: (02/11/2016 05:54:14 PM) (Source: WinMgmt) (EventID: 10) (User: )
Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003

Error: (02/11/2016 03:43:17 AM) (Source: .NET Runtime Optimization Service) (EventID: 1101) (User: )
Description: .NET Runtime Optimization Service (clr_optimization_v4.0.30319_64) - Failed to compile: Microsoft.MediaCenter.Sports, Version=6.1.0.0, Culture=neutral, PublicKeyToken=31bf3856ad364e35 . Error code = 0x80070020

Error: (02/11/2016 03:36:59 AM) (Source: WinMgmt) (EventID: 10) (User: )
Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003


System errors:
=============
Error: (02/27/2016 05:30:43 PM) (Source: Service Control Manager) (EventID: 7026) (User: )
Description: The following boot-start or system-start driver(s) failed to load:
aswNetSec

Error: (02/27/2016 05:30:31 PM) (Source: Service Control Manager) (EventID: 7000) (User: )
Description: The VBoxAsw Support Driver service failed to start due to the following error:
%%3

Error: (02/24/2016 08:26:31 PM) (Source: DCOM) (EventID: 10010) (User: )
Description: {4EB61BAC-A3B6-4760-9581-655041EF4D69}

Error: (02/24/2016 08:26:06 PM) (Source: Service Control Manager) (EventID: 7034) (User: )
Description: The Google Update Service (gupdate) service terminated unexpectedly.  It has done this 1 time(s).

Error: (02/22/2016 09:47:44 PM) (Source: Service Control Manager) (EventID: 7026) (User: )
Description: The following boot-start or system-start driver(s) failed to load:
aswNetSec

Error: (02/22/2016 09:47:21 PM) (Source: Service Control Manager) (EventID: 7000) (User: )
Description: The VBoxAsw Support Driver service failed to start due to the following error:
%%3

Error: (02/12/2016 08:58:20 PM) (Source: Service Control Manager) (EventID: 7026) (User: )
Description: The following boot-start or system-start driver(s) failed to load:
aswNetSec

Error: (02/12/2016 08:56:52 PM) (Source: Service Control Manager) (EventID: 7000) (User: )
Description: The VBoxAsw Support Driver service failed to start due to the following error:
%%3

Error: (02/12/2016 05:20:12 PM) (Source: Service Control Manager) (EventID: 7011) (User: )
Description: A timeout (30000 milliseconds) was reached while waiting for a transaction response from the lmhosts service.

Error: (02/11/2016 05:53:34 PM) (Source: Service Control Manager) (EventID: 7000) (User: )
Description: The VBoxAsw Support Driver service failed to start due to the following error:
%%3


CodeIntegrity:
===================================
  Date: 2014-01-17 18:54:25.458
  Description: Code Integrity is unable to verify the image integrity of the file \Device\HarddiskVolume1\Windows.old\Windows\SoftwareDistribution\Download\63e7d454eeb6cdac5bd05042201891bd\wow64_microsoft-windows-appid_31bf3856ad364e35_6.1.7601.22411_none_c04d416616480b5a\appidapi.dll because the set of per-page image hashes could not be found on the system.

  Date: 2014-01-17 18:54:25.442
  Description: Code Integrity is unable to verify the image integrity of the file \Device\HarddiskVolume1\Windows.old\Windows\SoftwareDistribution\Download\63e7d454eeb6cdac5bd05042201891bd\wow64_microsoft-windows-appid_31bf3856ad364e35_6.1.7601.22411_none_c04d416616480b5a\appidapi.dll because the set of per-page image hashes could not be found on the system.

  Date: 2014-01-17 18:54:25.442
  Description: Code Integrity is unable to verify the image integrity of the file \Device\HarddiskVolume1\Windows.old\Windows\SoftwareDistribution\Download\63e7d454eeb6cdac5bd05042201891bd\wow64_microsoft-windows-appid_31bf3856ad364e35_6.1.7601.22411_none_c04d416616480b5a\appidapi.dll because the set of per-page image hashes could not be found on the system.

  Date: 2014-01-17 18:54:24.226
  Description: Code Integrity is unable to verify the image integrity of the file \Device\HarddiskVolume1\Windows.old\Windows\SoftwareDistribution\Download\63e7d454eeb6cdac5bd05042201891bd\amd64_microsoft-windows-appid_31bf3856ad364e35_6.1.7601.22411_none_b5f89713e1e7495f\appidapi.dll because the set of per-page image hashes could not be found on the system.

  Date: 2014-01-17 18:54:24.226
  Description: Code Integrity is unable to verify the image integrity of the file \Device\HarddiskVolume1\Windows.old\Windows\SoftwareDistribution\Download\63e7d454eeb6cdac5bd05042201891bd\amd64_microsoft-windows-appid_31bf3856ad364e35_6.1.7601.22411_none_b5f89713e1e7495f\appidapi.dll because the set of per-page image hashes could not be found on the system.

  Date: 2014-01-17 18:54:24.210
  Description: Code Integrity is unable to verify the image integrity of the file \Device\HarddiskVolume1\Windows.old\Windows\SoftwareDistribution\Download\63e7d454eeb6cdac5bd05042201891bd\amd64_microsoft-windows-appid_31bf3856ad364e35_6.1.7601.22411_none_b5f89713e1e7495f\appidapi.dll because the set of per-page image hashes could not be found on the system.

  Date: 2014-01-17 18:54:24.179
  Description: Code Integrity is unable to verify the image integrity of the file \Device\HarddiskVolume1\Windows.old\Windows\SoftwareDistribution\Download\63e7d454eeb6cdac5bd05042201891bd\amd64_microsoft-windows-appid_31bf3856ad364e35_6.1.7601.22411_none_b5f89713e1e7495f\appid.sys because the set of per-page image hashes could not be found on the system.

  Date: 2014-01-17 18:54:24.148
  Description: Code Integrity is unable to verify the image integrity of the file \Device\HarddiskVolume1\Windows.old\Windows\SoftwareDistribution\Download\63e7d454eeb6cdac5bd05042201891bd\amd64_microsoft-windows-appid_31bf3856ad364e35_6.1.7601.22411_none_b5f89713e1e7495f\appid.sys because the set of per-page image hashes could not be found on the system.

  Date: 2014-01-17 18:54:24.132
  Description: Code Integrity is unable to verify the image integrity of the file \Device\HarddiskVolume1\Windows.old\Windows\SoftwareDistribution\Download\63e7d454eeb6cdac5bd05042201891bd\amd64_microsoft-windows-appid_31bf3856ad364e35_6.1.7601.22411_none_b5f89713e1e7495f\appid.sys because the set of per-page image hashes could not be found on the system.


==================== Memory info ===========================

Processor: Intel® Core™ i5-4670 CPU @ 3.40GHz
Percentage of memory in use: 24%
Total physical RAM: 7856.74 MB
Available physical RAM: 5893.44 MB
Total Virtual: 15711.68 MB
Available Virtual: 12675.61 MB

==================== Drives ================================

Drive c: () (Fixed) (Total:931.41 GB) (Free:786.42 GB) NTFS ==>[drive with boot components (obtained from BCD)]

==================== MBR & Partition Table ==================

========================================================
Disk: 0 (MBR Code: Windows 7 or 8) (Size: 931.5 GB) (Disk ID: D39C8DFD)
Partition 1: (Active) - (Size=931.4 GB) - (Type=07 NTFS)

==================== End of Addition.txt ============================


  • 0

#4
zep516

zep516

    Trusted Helper

  • Malware Removal
  • 8,093 posts
Hello,

Not seeing a whole lot here,

Download the enclosed => Attached File  fixlist.txt   1.34KB   278 downloads Save it in the location FRST64 is. Run FRST and click on the Fix button. Wait until finished.

The tool will make a log in the location FRST is, (Fixlog.txt). Please post it to your reply.

Next

Please download AdwCleaner by Xplode onto your Desktop.
  • Close all open programs and internet browsers.
  • Double click on AdwCleaner.exe to run the tool.
  • Click the Scan button and wait for the process to complete.
  • Click the logfile button and the log will open in Notepad.
  • Click on the Clean button follow the prompts.
  • A log file will automatically open after the scan has finished and the PC has rebooted.
  • Please post the content of that log file with your next answer.
  • The report will be saved in the C:\AdwCleaner folder.

    Next

    thisisujrt.gif Please download Junkware Removal Tool to your Desktop.
    Please close your security software to avoid potential conflicts. See Here how to disable you security protection (Anti Virus)
    Run the tool by double-clicking it. If you are using Windows Vista or 7, right-mouse click it and select Run as administrator.
    The tool will open and start scanning your system.
    Please be patient as this can take a while to complete, depending on your system's specifications.
    On completion, a log (JRT.txt) is saved to your Desktop and will automatically open.
    Please post the contents of JRT.txt into your reply.

    In your next reply post;
  • Fixlog.txt
  • The AdwCleaner [SO].txt Log
  • The JRT.txt Log

  • 0

#5
Webslinger64

Webslinger64

    Member

  • Topic Starter
  • Member
  • PipPipPip
  • 567 posts

Thanks for the reply. I am confused with your first set of instructions; specifically saving the fixlist.txt in the location FRST64. Are you wanting fixlist.txt saved to the Farbar Recovery Scan Tool program itself, or in some location on the computer? Am I replacing the original FRST.txt with your download and somehow placing it into the program then clicking the Fix button?

BTW, here's a SuperAntiSpyware scan I just did this morning.

 

SuperAntiSpyware%20Scan%20Results_zpskfx


Edited by Webslinger64, 03 March 2016 - 10:39 AM.

  • 0

#6
zep516

zep516

    Trusted Helper

  • Malware Removal
  • 8,093 posts
The fixlist must be saved to the same location FRST64 is;

To do that

Since FRST64 is located on your computer here==>FRST64 is Running from=>C:\Users\Helena\Downloads

So put/ save the fixlist to the downloads folder(C:\Users\Helena\Downloads), then click fix on FRST64, a log file will be created in the downloads folder called Fixlog.txt

Post the Fixlog and run the two other programs, adwCleaner and Junk removal tool.
  • 0

#7
Webslinger64

Webslinger64

    Member

  • Topic Starter
  • Member
  • PipPipPip
  • 567 posts

Here you go.  Thanks!

Fixlog.txt

 

Fix result of Farbar Recovery Scan Tool (x64) Version:02-03-2016
Ran by Helena (2016-03-03 15:43:31) Run:1
Running from C:\Users\Helena\Downloads
Loaded Profiles: Helena (Available Profiles: Helena)
Boot Mode: Normal
==============================================

fixlist content:
*****************
CloseProcesses:
CreateRestorePoint:
HKU\S-1-5-21-3746497652-99284834-819367531-1000\...\Run: [Zoom] => 0
HKU\S-1-5-21-3746497652-99284834-819367531-1000\...\RunOnce: [AsrOMG_Day0] => [X]
HKU\S-1-5-21-3746497652-99284834-819367531-1000\...\RunOnce: [AsrOMG_Day1] => [X]
HKU\S-1-5-21-3746497652-99284834-819367531-1000\...\RunOnce: [AsrOMG_Day2] => [X]
HKU\S-1-5-21-3746497652-99284834-819367531-1000\...\RunOnce: [AsrOMG_Day3] => [X]
HKU\S-1-5-21-3746497652-99284834-819367531-1000\...\RunOnce: [AsrOMG_Day4] => [X]
HKU\S-1-5-21-3746497652-99284834-819367531-1000\...\RunOnce: [AsrOMG_Day5] => [X]
HKU\S-1-5-21-3746497652-99284834-819367531-1000\...\RunOnce: [AsrOMG_Day6] => [X]
Toolbar: HKLM - No Name - {CC1A175A-E45B-41ED-A30C-C9B1D7A0C02F} -  No File
S3 AvastVBoxSvc; "C:\Program Files\AVAST Software\Avast\ng\vbox\AvastVBoxSVC.exe" [X]
C:\Users\Helena\jobq.dat
CustomCLSID: HKU\S-1-5-21-3746497652-99284834-819367531-1000_Classes\CLSID\{005A3A96-BAC4-4B0A-94EA-C0CE100EA736}\localserver32 -> C:\Users\Helena\AppData\Roaming\Dropbox\bin\Dropbox.exe /autoplay => No File
Task: {80A30D52-C56D-4F6B-9BB9-73AB8853A1C8} - System32\Tasks\HDMISwitch => C:\Program Files (x86)\ASRock Utility\HDMISwitch\Bin\HDMISwitch.exe [2013-09-04] () <==== ATTENTION
C:\Program Files (x86)\ASRock Utility
CMD: bitsadmin /reset /allusers
CMD: ipconfig /flushdns
Emptytemp:
*****************

Processes closed successfully.
Restore point was successfully created.
HKU\S-1-5-21-3746497652-99284834-819367531-1000\Software\Microsoft\Windows\CurrentVersion\Run\\Zoom => value removed successfully
HKU\S-1-5-21-3746497652-99284834-819367531-1000\Software\Microsoft\Windows\CurrentVersion\RunOnce\\AsrOMG_Day0 => value removed successfully
HKU\S-1-5-21-3746497652-99284834-819367531-1000\Software\Microsoft\Windows\CurrentVersion\RunOnce\\AsrOMG_Day1 => value removed successfully
HKU\S-1-5-21-3746497652-99284834-819367531-1000\Software\Microsoft\Windows\CurrentVersion\RunOnce\\AsrOMG_Day2 => value removed successfully
HKU\S-1-5-21-3746497652-99284834-819367531-1000\Software\Microsoft\Windows\CurrentVersion\RunOnce\\AsrOMG_Day3 => value removed successfully
HKU\S-1-5-21-3746497652-99284834-819367531-1000\Software\Microsoft\Windows\CurrentVersion\RunOnce\\AsrOMG_Day4 => value removed successfully
HKU\S-1-5-21-3746497652-99284834-819367531-1000\Software\Microsoft\Windows\CurrentVersion\RunOnce\\AsrOMG_Day5 => value removed successfully
HKU\S-1-5-21-3746497652-99284834-819367531-1000\Software\Microsoft\Windows\CurrentVersion\RunOnce\\AsrOMG_Day6 => value removed successfully
HKLM\SOFTWARE\Microsoft\Internet Explorer\Toolbar\\{CC1A175A-E45B-41ED-A30C-C9B1D7A0C02F} => value removed successfully
HKCR\CLSID\{CC1A175A-E45B-41ED-A30C-C9B1D7A0C02F} => key not found.
AvastVBoxSvc => service could not remove
C:\Users\Helena\jobq.dat => moved successfully
"HKU\S-1-5-21-3746497652-99284834-819367531-1000_Classes\CLSID\{005A3A96-BAC4-4B0A-94EA-C0CE100EA736}" => key removed successfully
HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{80A30D52-C56D-4F6B-9BB9-73AB8853A1C8} => key not found.
C:\Windows\System32\Tasks\HDMISwitch => moved successfully
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\HDMISwitch" => key removed successfully
C:\Program Files (x86)\ASRock Utility => moved successfully

=========  bitsadmin /reset /allusers =========


BITSADMIN version 3.0 [ 7.5.7601 ]
BITS administration utility.
© Copyright 2000-2006 Microsoft Corp.

BITSAdmin is deprecated and is not guaranteed to be available in future versions of Windows.
Administrative tools for the BITS service are now provided by BITS PowerShell cmdlets.

Unable to cancel {4CA5245E-E779-4141-9BDC-5F5F7522CA8F}.
0 out of 1 jobs canceled.

========= End of CMD: =========


=========  ipconfig /flushdns =========


Windows IP Configuration

Successfully flushed the DNS Resolver Cache.

========= End of CMD: =========

EmptyTemp: => 504.6 MB temporary data Removed.


The system needed a reboot.

==== End of Fixlog 15:44:11 ====

 

AdwCleaner txt log

 

# AdwCleaner v5.037 - Logfile created 03/03/2016 at 15:55:12
# Updated 28/02/2016 by Xplode
# Database : 2016-03-02.1 [Server]
# Operating system : Windows 7 Home Premium Service Pack 1 (x64)
# Username : Helena - HELENA-PC
# Running from : C:\Users\Helena\Desktop\adwcleaner_5.037.exe
# Option : Clean
# Support : http://toolslib.net/forum

***** [ Services ] *****


***** [ Folders ] *****

[-] Folder Deleted : C:\Users\Helena\AppData\Roaming\Mozilla\Firefox\Profiles\ju292vok.default-1438795000345\StumbleUpon

***** [ Files ] *****


***** [ DLLs ] *****


***** [ Shortcuts ] *****


***** [ Scheduled tasks ] *****


***** [ Registry ] *****


***** [ Web browsers ] *****


*************************

:: "Tracing" keys removed
:: Winsock settings cleared

*************************

C:\AdwCleaner\AdwCleaner[C1].txt - [833 bytes] - [03/03/2016 15:55:12]
C:\AdwCleaner\AdwCleaner[S1].txt - [888 bytes] - [03/03/2016 15:53:16]

########## EOF - C:\AdwCleaner\AdwCleaner[C1].txt - [977 bytes] ##########

 

JRT.txt log

 

~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
Junkware Removal Tool (JRT) by Malwarebytes
Version: 8.0.3 (02.09.2016)
Operating System: Windows 7 Home Premium x64
Ran by Helena (Administrator) on Thu 03/03/2016 at 16:02:07.00
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~




File System: 8

Successfully deleted: C:\Users\Helena\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\5MZQXCBA (Temporary Internet Files Folder)
Successfully deleted: C:\Users\Helena\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\9PC11YWT (Temporary Internet Files Folder)
Successfully deleted: C:\Users\Helena\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\QVS476TP (Temporary Internet Files Folder)
Successfully deleted: C:\Users\Helena\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\YGPFR2RL (Temporary Internet Files Folder)
Successfully deleted: C:\Windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\5MZQXCBA (Temporary Internet Files Folder)
Successfully deleted: C:\Windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\9PC11YWT (Temporary Internet Files Folder)
Successfully deleted: C:\Windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\QVS476TP (Temporary Internet Files Folder)
Successfully deleted: C:\Windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\YGPFR2RL (Temporary Internet Files Folder)

Deleted the following from C:\Users\Helena\AppData\Roaming\Mozilla\Firefox\Profiles\ju292vok.default-1438795000345\prefs.js
user_pref(browser.urlbar.suggest.searches, true);



Registry: 0





~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
Scan was completed on Thu 03/03/2016 at 16:03:27.88
End of JRT log
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~


 


  • 0

#8
zep516

zep516

    Trusted Helper

  • Malware Removal
  • 8,093 posts
I need to see a clean Malwarebytes log, you can skip the download since you have it already installed.

  • Please download Malwarebytes Anti-Malware to your desktop.
  • Double-click mbam-setup-version.exe and follow the prompts to install the program.
  • Launch Malwarebytes Anti-Malware
  • Then click Finish.
  • If an update is found, you will be prompted to download and install the latest version.
  • Once the program has loaded, select Scan now. Or select the Threat Scan from the Scan menu.
  • When the scan is complete , make sure that that all Threats are selected, and click Remove Selected.
  • Reboot your computer if prompted.


    Posting the Malwarebytes log.

    [list]
  • After the restart once you are back at your desktop, open MBAM once more.
  • Click on the History tab > Application Logs.
  • Double click on the Scan Log which shows the Date and time of the scan just performed.
  • Click 'Export'.
  • Click 'Text file (*.txt)'
  • In the Save File dialog box which appears, click on Desktop.
  • In the File name: box type a name for your scan log.
  • A message box named 'File Saved' should appear stating "Your file has been successfully exported".
  • Click Ok
  • post that saved log to your next reply.

  • 0

#9
Webslinger64

Webslinger64

    Member

  • Topic Starter
  • Member
  • PipPipPip
  • 567 posts

Here you go...

 

Malwarebytes Anti-Malware
www.malwarebytes.org

Scan Date: 3/4/2016
Scan Time: 7:47 AM
Logfile: MBAM Scan Log 030416.txt
Administrator: Yes

Version: 2.2.0.1024
Malware Database: v2016.03.04.03
Rootkit Database: v2016.02.27.01
License: Free
Malware Protection: Disabled
Malicious Website Protection: Disabled
Self-protection: Disabled

OS: Windows 7 Service Pack 1
CPU: x64
File System: NTFS
User: Helena

Scan Type: Threat Scan
Result: Completed
Objects Scanned: 345517
Time Elapsed: 6 min, 30 sec

Memory: Enabled
Startup: Enabled
Filesystem: Enabled
Archives: Enabled
Rootkits: Disabled
Heuristics: Enabled
PUP: Warn
PUM: Enabled

Processes: 0
(No malicious items detected)

Modules: 0
(No malicious items detected)

Registry Keys: 0
(No malicious items detected)

Registry Values: 0
(No malicious items detected)

Registry Data: 0
(No malicious items detected)

Folders: 0
(No malicious items detected)

Files: 0
(No malicious items detected)

Physical Sectors: 0
(No malicious items detected)


(end)


  • 0

#10
zep516

zep516

    Trusted Helper

  • Malware Removal
  • 8,093 posts
Hello,

Can you post the SuperAntispyware log
To do that

Open SUPERAntiSpyware and click View Scan Logs. Copy and paste the latest log to the next reply.
  • 0

Advertisements


#11
Webslinger64

Webslinger64

    Member

  • Topic Starter
  • Member
  • PipPipPip
  • 567 posts

Here you go.  Thanks...

 

SUPERAntiSpyware Scan Log
http://www.superantispyware.com

Generated 03/04/2016 at 08:49 PM

Application Version : 6.0.1216
Database Version : 12475

Scan type       : Complete Scan
Total Scan Time : 00:18:31

Operating System Information
Windows 7 Home Premium 64-bit, Service Pack 1 (Build 6.01.7601)
UAC On - Limited User

Memory items scanned      : 524
Memory threats detected   : 0
Registry items scanned    : 63703
Registry threats detected : 0
File items scanned        : 38971
File threats detected     : 710

Adware.Tracking Cookie
    cdn-static-secure.liverail.com [ C:\USERS\HELENA\APPDATA\ROAMING\MACROMEDIA\FLASH PLAYER\#SHAREDOBJECTS\9A8W2K6K ]
    cdn-static.liverail.com [ C:\USERS\HELENA\APPDATA\ROAMING\MACROMEDIA\FLASH PLAYER\#SHAREDOBJECTS\9A8W2K6K ]
    cdn.vidible.tv [ C:\USERS\HELENA\APPDATA\ROAMING\MACROMEDIA\FLASH PLAYER\#SHAREDOBJECTS\9A8W2K6K ]
    cdn2.dashbida.com [ C:\USERS\HELENA\APPDATA\ROAMING\MACROMEDIA\FLASH PLAYER\#SHAREDOBJECTS\9A8W2K6K ]
    .nypi.dc-storm.com [ C:\USERS\HELENA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\JU292VOK.DEFAULT-1438795000345\COOKIES.SQLITE ]
    centerpointtracking.com [ C:\USERS\HELENA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\JU292VOK.DEFAULT-1438795000345\COOKIES.SQLITE ]
    .abmr.net [ C:\USERS\HELENA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\JU292VOK.DEFAULT-1438795000345\COOKIES.SQLITE ]
    .lijit.com [ C:\USERS\HELENA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\JU292VOK.DEFAULT-1438795000345\COOKIES.SQLITE ]
    adserverc.cliipa.com [ C:\USERS\HELENA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\JU292VOK.DEFAULT-1438795000345\COOKIES.SQLITE ]
    .serving-sys.com [ C:\USERS\HELENA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\JU292VOK.DEFAULT-1438795000345\COOKIES.SQLITE ]
    .atdmt.com [ C:\USERS\HELENA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\JU292VOK.DEFAULT-1438795000345\COOKIES.SQLITE ]
    .iasds01.com [ C:\USERS\HELENA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\JU292VOK.DEFAULT-1438795000345\COOKIES.SQLITE ]
    .advertising.com [ C:\USERS\HELENA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\JU292VOK.DEFAULT-1438795000345\COOKIES.SQLITE ]
    .adgrx.com [ C:\USERS\HELENA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\JU292VOK.DEFAULT-1438795000345\COOKIES.SQLITE ]
    .adgrx.com [ C:\USERS\HELENA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\JU292VOK.DEFAULT-1438795000345\COOKIES.SQLITE ]
    .adgrx.com [ C:\USERS\HELENA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\JU292VOK.DEFAULT-1438795000345\COOKIES.SQLITE ]
    .adgrx.com [ C:\USERS\HELENA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\JU292VOK.DEFAULT-1438795000345\COOKIES.SQLITE ]
    .adgrx.com [ C:\USERS\HELENA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\JU292VOK.DEFAULT-1438795000345\COOKIES.SQLITE ]
    .adtechus.com [ C:\USERS\HELENA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\JU292VOK.DEFAULT-1438795000345\COOKIES.SQLITE ]
    .altitude-arena.com [ C:\USERS\HELENA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\JU292VOK.DEFAULT-1438795000345\COOKIES.SQLITE ]
    idp.securetve.com [ C:\USERS\HELENA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\JU292VOK.DEFAULT-1438795000345\COOKIES.SQLITE ]
    .altitude-arena.com [ C:\USERS\HELENA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\JU292VOK.DEFAULT-1438795000345\COOKIES.SQLITE ]
    .tribalfusion.com [ C:\USERS\HELENA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\JU292VOK.DEFAULT-1438795000345\COOKIES.SQLITE ]
    .advertising.com [ C:\USERS\HELENA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\JU292VOK.DEFAULT-1438795000345\COOKIES.SQLITE ]
    .advertising.com [ C:\USERS\HELENA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\JU292VOK.DEFAULT-1438795000345\COOKIES.SQLITE ]
    .atdmt.com [ C:\USERS\HELENA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\JU292VOK.DEFAULT-1438795000345\COOKIES.SQLITE ]
    .at.atwola.com [ C:\USERS\HELENA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\JU292VOK.DEFAULT-1438795000345\COOKIES.SQLITE ]
    a.komoona.com [ C:\USERS\HELENA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\JU292VOK.DEFAULT-1438795000345\COOKIES.SQLITE ]
    a.tellapart.com [ C:\USERS\HELENA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\JU292VOK.DEFAULT-1438795000345\COOKIES.SQLITE ]
    at1.listrakbi.com [ C:\USERS\HELENA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\JU292VOK.DEFAULT-1438795000345\COOKIES.SQLITE ]
    cx2.ic-live.com [ C:\USERS\HELENA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\JU292VOK.DEFAULT-1438795000345\COOKIES.SQLITE ]
    p10055.ic-live.com [ C:\USERS\HELENA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\JU292VOK.DEFAULT-1438795000345\COOKIES.SQLITE ]
    s.opendsp.com [ C:\USERS\HELENA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\JU292VOK.DEFAULT-1438795000345\COOKIES.SQLITE ]
    stat.komoona.com [ C:\USERS\HELENA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\JU292VOK.DEFAULT-1438795000345\COOKIES.SQLITE ]
    t.tellapart.com [ C:\USERS\HELENA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\JU292VOK.DEFAULT-1438795000345\COOKIES.SQLITE ]
    .serving-sys.com [ C:\USERS\HELENA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\JU292VOK.DEFAULT-1438795000345\COOKIES.SQLITE ]
    .btrll.com [ C:\USERS\HELENA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\JU292VOK.DEFAULT-1438795000345\COOKIES.SQLITE ]
    .adform.net [ C:\USERS\HELENA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\JU292VOK.DEFAULT-1438795000345\COOKIES.SQLITE ]
    .advertising.com [ C:\USERS\HELENA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\JU292VOK.DEFAULT-1438795000345\COOKIES.SQLITE ]
    .mediaforge.com [ C:\USERS\HELENA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\JU292VOK.DEFAULT-1438795000345\COOKIES.SQLITE ]
    .c3tag.com [ C:\USERS\HELENA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\JU292VOK.DEFAULT-1438795000345\COOKIES.SQLITE ]
    .mediaforge.com [ C:\USERS\HELENA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\JU292VOK.DEFAULT-1438795000345\COOKIES.SQLITE ]
    .c3tag.com [ C:\USERS\HELENA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\JU292VOK.DEFAULT-1438795000345\COOKIES.SQLITE ]
    .mediaforge.com [ C:\USERS\HELENA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\JU292VOK.DEFAULT-1438795000345\COOKIES.SQLITE ]
    .serving-sys.com [ C:\USERS\HELENA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\JU292VOK.DEFAULT-1438795000345\COOKIES.SQLITE ]
    .casalemedia.com [ C:\USERS\HELENA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\JU292VOK.DEFAULT-1438795000345\COOKIES.SQLITE ]
    .casalemedia.com [ C:\USERS\HELENA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\JU292VOK.DEFAULT-1438795000345\COOKIES.SQLITE ]
    .casalemedia.com [ C:\USERS\HELENA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\JU292VOK.DEFAULT-1438795000345\COOKIES.SQLITE ]
    .casalemedia.com [ C:\USERS\HELENA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\JU292VOK.DEFAULT-1438795000345\COOKIES.SQLITE ]
    .casalemedia.com [ C:\USERS\HELENA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\JU292VOK.DEFAULT-1438795000345\COOKIES.SQLITE ]
    .connexity.net [ C:\USERS\HELENA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\JU292VOK.DEFAULT-1438795000345\COOKIES.SQLITE ]
    .scorecardresearch.com [ C:\USERS\HELENA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\JU292VOK.DEFAULT-1438795000345\COOKIES.SQLITE ]
    .a.scorecardresearch.com [ C:\USERS\HELENA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\JU292VOK.DEFAULT-1438795000345\COOKIES.SQLITE ]
    .a.scorecardresearch.com [ C:\USERS\HELENA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\JU292VOK.DEFAULT-1438795000345\COOKIES.SQLITE ]
    .a.scorecardresearch.com [ C:\USERS\HELENA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\JU292VOK.DEFAULT-1438795000345\COOKIES.SQLITE ]
    .a.scorecardresearch.com [ C:\USERS\HELENA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\JU292VOK.DEFAULT-1438795000345\COOKIES.SQLITE ]
    .a.scorecardresearch.com [ C:\USERS\HELENA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\JU292VOK.DEFAULT-1438795000345\COOKIES.SQLITE ]
    .questionmarket.com [ C:\USERS\HELENA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\JU292VOK.DEFAULT-1438795000345\COOKIES.SQLITE ]
    .choicestream.com [ C:\USERS\HELENA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\JU292VOK.DEFAULT-1438795000345\COOKIES.SQLITE ]
    www.googleadservices.com [ C:\USERS\HELENA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\JU292VOK.DEFAULT-1438795000345\COOKIES.SQLITE ]
    testdata.coremetrics.com [ C:\USERS\HELENA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\JU292VOK.DEFAULT-1438795000345\COOKIES.SQLITE ]
    .serving-sys.com [ C:\USERS\HELENA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\JU292VOK.DEFAULT-1438795000345\COOKIES.SQLITE ]
    .iasds01.com [ C:\USERS\HELENA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\JU292VOK.DEFAULT-1438795000345\COOKIES.SQLITE ]
    .exelator.com [ C:\USERS\HELENA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\JU292VOK.DEFAULT-1438795000345\COOKIES.SQLITE ]
    .advertising.com [ C:\USERS\HELENA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\JU292VOK.DEFAULT-1438795000345\COOKIES.SQLITE ]
    .pubmatic.com [ C:\USERS\HELENA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\JU292VOK.DEFAULT-1438795000345\COOKIES.SQLITE ]
    .doubleclick.net [ C:\USERS\HELENA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\JU292VOK.DEFAULT-1438795000345\COOKIES.SQLITE ]
    .insightexpressai.com [ C:\USERS\HELENA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\JU292VOK.DEFAULT-1438795000345\COOKIES.SQLITE ]
    .insightexpressai.com [ C:\USERS\HELENA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\JU292VOK.DEFAULT-1438795000345\COOKIES.SQLITE ]
    .aexp.demdex.net [ C:\USERS\HELENA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\JU292VOK.DEFAULT-1438795000345\COOKIES.SQLITE ]
    .comcast.demdex.net [ C:\USERS\HELENA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\JU292VOK.DEFAULT-1438795000345\COOKIES.SQLITE ]
    .dish.demdex.net [ C:\USERS\HELENA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\JU292VOK.DEFAULT-1438795000345\COOKIES.SQLITE ]
    .dpm.demdex.net [ C:\USERS\HELENA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\JU292VOK.DEFAULT-1438795000345\COOKIES.SQLITE ]
    .foxnews.demdex.net [ C:\USERS\HELENA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\JU292VOK.DEFAULT-1438795000345\COOKIES.SQLITE ]
    .homedepot.demdex.net [ C:\USERS\HELENA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\JU292VOK.DEFAULT-1438795000345\COOKIES.SQLITE ]
    .tdameritrade.demdex.net [ C:\USERS\HELENA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\JU292VOK.DEFAULT-1438795000345\COOKIES.SQLITE ]
    .vivaki.demdex.net [ C:\USERS\HELENA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\JU292VOK.DEFAULT-1438795000345\COOKIES.SQLITE ]
    .dotomi.com [ C:\USERS\HELENA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\JU292VOK.DEFAULT-1438795000345\COOKIES.SQLITE ]
    .eqads.com [ C:\USERS\HELENA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\JU292VOK.DEFAULT-1438795000345\COOKIES.SQLITE ]
    .questionmarket.com [ C:\USERS\HELENA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\JU292VOK.DEFAULT-1438795000345\COOKIES.SQLITE ]
    .advertising.com [ C:\USERS\HELENA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\JU292VOK.DEFAULT-1438795000345\COOKIES.SQLITE ]
    .advertising.com [ C:\USERS\HELENA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\JU292VOK.DEFAULT-1438795000345\COOKIES.SQLITE ]
    .mathtag.com [ C:\USERS\HELENA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\JU292VOK.DEFAULT-1438795000345\COOKIES.SQLITE ]
    .amgdgt.com [ C:\USERS\HELENA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\JU292VOK.DEFAULT-1438795000345\COOKIES.SQLITE ]
    .doubleclick.net [ C:\USERS\HELENA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\JU292VOK.DEFAULT-1438795000345\COOKIES.SQLITE ]
    .advertising.com [ C:\USERS\HELENA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\JU292VOK.DEFAULT-1438795000345\COOKIES.SQLITE ]
    .imrworldwide.com [ C:\USERS\HELENA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\JU292VOK.DEFAULT-1438795000345\COOKIES.SQLITE ]
    .swid.switchads.com [ C:\USERS\HELENA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\JU292VOK.DEFAULT-1438795000345\COOKIES.SQLITE ]
    .intentiq.com [ C:\USERS\HELENA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\JU292VOK.DEFAULT-1438795000345\COOKIES.SQLITE ]
    .intentiq.com [ C:\USERS\HELENA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\JU292VOK.DEFAULT-1438795000345\COOKIES.SQLITE ]
    .intentiq.com [ C:\USERS\HELENA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\JU292VOK.DEFAULT-1438795000345\COOKIES.SQLITE ]
    .intentiq.com [ C:\USERS\HELENA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\JU292VOK.DEFAULT-1438795000345\COOKIES.SQLITE ]
    .intentiq.com [ C:\USERS\HELENA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\JU292VOK.DEFAULT-1438795000345\COOKIES.SQLITE ]
    .insightexpressai.com [ C:\USERS\HELENA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\JU292VOK.DEFAULT-1438795000345\COOKIES.SQLITE ]
    .insightexpressai.com [ C:\USERS\HELENA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\JU292VOK.DEFAULT-1438795000345\COOKIES.SQLITE ]
    .insightexpressai.com [ C:\USERS\HELENA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\JU292VOK.DEFAULT-1438795000345\COOKIES.SQLITE ]
    .insightexpressai.com [ C:\USERS\HELENA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\JU292VOK.DEFAULT-1438795000345\COOKIES.SQLITE ]
    .insightexpressai.com [ C:\USERS\HELENA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\JU292VOK.DEFAULT-1438795000345\COOKIES.SQLITE ]
    .insightexpressai.com [ C:\USERS\HELENA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\JU292VOK.DEFAULT-1438795000345\COOKIES.SQLITE ]
    .insightexpressai.com [ C:\USERS\HELENA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\JU292VOK.DEFAULT-1438795000345\COOKIES.SQLITE ]
    .adtech.de [ C:\USERS\HELENA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\JU292VOK.DEFAULT-1438795000345\COOKIES.SQLITE ]
    .adtechjp.com [ C:\USERS\HELENA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\JU292VOK.DEFAULT-1438795000345\COOKIES.SQLITE ]
    .adtechus.com [ C:\USERS\HELENA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\JU292VOK.DEFAULT-1438795000345\COOKIES.SQLITE ]
    .pubmatic.com [ C:\USERS\HELENA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\JU292VOK.DEFAULT-1438795000345\COOKIES.SQLITE ]
    .pubmatic.com [ C:\USERS\HELENA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\JU292VOK.DEFAULT-1438795000345\COOKIES.SQLITE ]
    .pubmatic.com [ C:\USERS\HELENA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\JU292VOK.DEFAULT-1438795000345\COOKIES.SQLITE ]
    .pubmatic.com [ C:\USERS\HELENA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\JU292VOK.DEFAULT-1438795000345\COOKIES.SQLITE ]
    .pubmatic.com [ C:\USERS\HELENA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\JU292VOK.DEFAULT-1438795000345\COOKIES.SQLITE ]
    .pubmatic.com [ C:\USERS\HELENA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\JU292VOK.DEFAULT-1438795000345\COOKIES.SQLITE ]
    .pubmatic.com [ C:\USERS\HELENA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\JU292VOK.DEFAULT-1438795000345\COOKIES.SQLITE ]
    .pubmatic.com [ C:\USERS\HELENA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\JU292VOK.DEFAULT-1438795000345\COOKIES.SQLITE ]
    .pubmatic.com [ C:\USERS\HELENA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\JU292VOK.DEFAULT-1438795000345\COOKIES.SQLITE ]
    .pubmatic.com [ C:\USERS\HELENA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\JU292VOK.DEFAULT-1438795000345\COOKIES.SQLITE ]
    .pubmatic.com [ C:\USERS\HELENA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\JU292VOK.DEFAULT-1438795000345\COOKIES.SQLITE ]
    .pubmatic.com [ C:\USERS\HELENA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\JU292VOK.DEFAULT-1438795000345\COOKIES.SQLITE ]
    .pubmatic.com [ C:\USERS\HELENA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\JU292VOK.DEFAULT-1438795000345\COOKIES.SQLITE ]
    .pubmatic.com [ C:\USERS\HELENA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\JU292VOK.DEFAULT-1438795000345\COOKIES.SQLITE ]
    .pubmatic.com [ C:\USERS\HELENA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\JU292VOK.DEFAULT-1438795000345\COOKIES.SQLITE ]
    .pubmatic.com [ C:\USERS\HELENA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\JU292VOK.DEFAULT-1438795000345\COOKIES.SQLITE ]
    .pubmatic.com [ C:\USERS\HELENA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\JU292VOK.DEFAULT-1438795000345\COOKIES.SQLITE ]
    .pubmatic.com [ C:\USERS\HELENA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\JU292VOK.DEFAULT-1438795000345\COOKIES.SQLITE ]
    .pubmatic.com [ C:\USERS\HELENA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\JU292VOK.DEFAULT-1438795000345\COOKIES.SQLITE ]
    .pubmatic.com [ C:\USERS\HELENA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\JU292VOK.DEFAULT-1438795000345\COOKIES.SQLITE ]
    .pubmatic.com [ C:\USERS\HELENA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\JU292VOK.DEFAULT-1438795000345\COOKIES.SQLITE ]
    .pubmatic.com [ C:\USERS\HELENA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\JU292VOK.DEFAULT-1438795000345\COOKIES.SQLITE ]
    .pubmatic.com [ C:\USERS\HELENA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\JU292VOK.DEFAULT-1438795000345\COOKIES.SQLITE ]
    .pubmatic.com [ C:\USERS\HELENA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\JU292VOK.DEFAULT-1438795000345\COOKIES.SQLITE ]
    .pubmatic.com [ C:\USERS\HELENA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\JU292VOK.DEFAULT-1438795000345\COOKIES.SQLITE ]
    .pubmatic.com [ C:\USERS\HELENA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\JU292VOK.DEFAULT-1438795000345\COOKIES.SQLITE ]
    .pubmatic.com [ C:\USERS\HELENA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\JU292VOK.DEFAULT-1438795000345\COOKIES.SQLITE ]
    .pubmatic.com [ C:\USERS\HELENA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\JU292VOK.DEFAULT-1438795000345\COOKIES.SQLITE ]
    .pubmatic.com [ C:\USERS\HELENA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\JU292VOK.DEFAULT-1438795000345\COOKIES.SQLITE ]
    .pubmatic.com [ C:\USERS\HELENA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\JU292VOK.DEFAULT-1438795000345\COOKIES.SQLITE ]
    .pubmatic.com [ C:\USERS\HELENA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\JU292VOK.DEFAULT-1438795000345\COOKIES.SQLITE ]
    .pubmatic.com [ C:\USERS\HELENA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\JU292VOK.DEFAULT-1438795000345\COOKIES.SQLITE ]
    .pubmatic.com [ C:\USERS\HELENA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\JU292VOK.DEFAULT-1438795000345\COOKIES.SQLITE ]
    .pubmatic.com [ C:\USERS\HELENA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\JU292VOK.DEFAULT-1438795000345\COOKIES.SQLITE ]
    .ligadx.com [ C:\USERS\HELENA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\JU292VOK.DEFAULT-1438795000345\COOKIES.SQLITE ]
    .ligadx.com [ C:\USERS\HELENA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\JU292VOK.DEFAULT-1438795000345\COOKIES.SQLITE ]
    .amgdgt.com [ C:\USERS\HELENA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\JU292VOK.DEFAULT-1438795000345\COOKIES.SQLITE ]
    .liveperson.net [ C:\USERS\HELENA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\JU292VOK.DEFAULT-1438795000345\COOKIES.SQLITE ]
    .liveperson.net [ C:\USERS\HELENA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\JU292VOK.DEFAULT-1438795000345\COOKIES.SQLITE ]
    .swid.switchads.com [ C:\USERS\HELENA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\JU292VOK.DEFAULT-1438795000345\COOKIES.SQLITE ]
    .revsci.net [ C:\USERS\HELENA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\JU292VOK.DEFAULT-1438795000345\COOKIES.SQLITE ]
    495.as.adforgeinc.com [ C:\USERS\HELENA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\JU292VOK.DEFAULT-1438795000345\COOKIES.SQLITE ]
    ads.globaladserver.com [ C:\USERS\HELENA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\JU292VOK.DEFAULT-1438795000345\COOKIES.SQLITE ]
    ads.stickyadstv.com [ C:\USERS\HELENA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\JU292VOK.DEFAULT-1438795000345\COOKIES.SQLITE ]
    .mookie1.com [ C:\USERS\HELENA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\JU292VOK.DEFAULT-1438795000345\COOKIES.SQLITE ]
    ox-d.33across.servedbyopenx.com [ C:\USERS\HELENA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\JU292VOK.DEFAULT-1438795000345\COOKIES.SQLITE ]
    .pubmatic.com [ C:\USERS\HELENA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\JU292VOK.DEFAULT-1438795000345\COOKIES.SQLITE ]
    .pubmatic.com [ C:\USERS\HELENA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\JU292VOK.DEFAULT-1438795000345\COOKIES.SQLITE ]
    .pubmatic.com [ C:\USERS\HELENA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\JU292VOK.DEFAULT-1438795000345\COOKIES.SQLITE ]
    .adlegend.com [ C:\USERS\HELENA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\JU292VOK.DEFAULT-1438795000345\COOKIES.SQLITE ]
    .swid.switchads.com [ C:\USERS\HELENA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\JU292VOK.DEFAULT-1438795000345\COOKIES.SQLITE ]
    .gwallet.com [ C:\USERS\HELENA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\JU292VOK.DEFAULT-1438795000345\COOKIES.SQLITE ]
    match.rundsp.com [ C:\USERS\HELENA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\JU292VOK.DEFAULT-1438795000345\COOKIES.SQLITE ]
    .semasio.net [ C:\USERS\HELENA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\JU292VOK.DEFAULT-1438795000345\COOKIES.SQLITE ]
    .krxd.net [ C:\USERS\HELENA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\JU292VOK.DEFAULT-1438795000345\COOKIES.SQLITE ]
    .smaato.net [ C:\USERS\HELENA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\JU292VOK.DEFAULT-1438795000345\COOKIES.SQLITE ]
    .pubmatic.com [ C:\USERS\HELENA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\JU292VOK.DEFAULT-1438795000345\COOKIES.SQLITE ]
    .adsrvr.org [ C:\USERS\HELENA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\JU292VOK.DEFAULT-1438795000345\COOKIES.SQLITE ]
    .adsrvr.org [ C:\USERS\HELENA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\JU292VOK.DEFAULT-1438795000345\COOKIES.SQLITE ]
    .insightexpressai.com [ C:\USERS\HELENA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\JU292VOK.DEFAULT-1438795000345\COOKIES.SQLITE ]
    .tapad.com [ C:\USERS\HELENA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\JU292VOK.DEFAULT-1438795000345\COOKIES.SQLITE ]
    .tapad.com [ C:\USERS\HELENA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\JU292VOK.DEFAULT-1438795000345\COOKIES.SQLITE ]
    .smartadserver.com [ C:\USERS\HELENA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\JU292VOK.DEFAULT-1438795000345\COOKIES.SQLITE ]
    .adsymptotic.com [ C:\USERS\HELENA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\JU292VOK.DEFAULT-1438795000345\COOKIES.SQLITE ]
    .amgdgt.com [ C:\USERS\HELENA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\JU292VOK.DEFAULT-1438795000345\COOKIES.SQLITE ]
    .scorecardresearch.com [ C:\USERS\HELENA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\JU292VOK.DEFAULT-1438795000345\COOKIES.SQLITE ]
    .scorecardresearch.com [ C:\USERS\HELENA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\JU292VOK.DEFAULT-1438795000345\COOKIES.SQLITE ]
    .admaym.com [ C:\USERS\HELENA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\JU292VOK.DEFAULT-1438795000345\COOKIES.SQLITE ]
    .atemda.com [ C:\USERS\HELENA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\JU292VOK.DEFAULT-1438795000345\COOKIES.SQLITE ]
    .advertising.com [ C:\USERS\HELENA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\JU292VOK.DEFAULT-1438795000345\COOKIES.SQLITE ]
    .servesharp.net [ C:\USERS\HELENA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\JU292VOK.DEFAULT-1438795000345\COOKIES.SQLITE ]
    .servesharp.net [ C:\USERS\HELENA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\JU292VOK.DEFAULT-1438795000345\COOKIES.SQLITE ]
    .adfarm1.adition.com [ C:\USERS\HELENA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\JU292VOK.DEFAULT-1438795000345\COOKIES.SQLITE ]
    .contextweb.com [ C:\USERS\HELENA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\JU292VOK.DEFAULT-1438795000345\COOKIES.SQLITE ]
    .ru4.com [ C:\USERS\HELENA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\JU292VOK.DEFAULT-1438795000345\COOKIES.SQLITE ]
    .dc-storm.com [ C:\USERS\HELENA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\JU292VOK.DEFAULT-1438795000345\COOKIES.SQLITE ]
    .dc-storm.com [ C:\USERS\HELENA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\JU292VOK.DEFAULT-1438795000345\COOKIES.SQLITE ]
    fqtag.com [ C:\USERS\HELENA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\JU292VOK.DEFAULT-1438795000345\COOKIES.SQLITE ]
    .adrta.com [ C:\USERS\HELENA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\JU292VOK.DEFAULT-1438795000345\COOKIES.SQLITE ]
    .adrta.com [ C:\USERS\HELENA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\JU292VOK.DEFAULT-1438795000345\COOKIES.SQLITE ]
    .33across.com [ C:\USERS\HELENA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\JU292VOK.DEFAULT-1438795000345\COOKIES.SQLITE ]
    .adzerk.net [ C:\USERS\HELENA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\JU292VOK.DEFAULT-1438795000345\COOKIES.SQLITE ]
    .bluecava.com [ C:\USERS\HELENA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\JU292VOK.DEFAULT-1438795000345\COOKIES.SQLITE ]
    .q1media.com [ C:\USERS\HELENA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\JU292VOK.DEFAULT-1438795000345\COOKIES.SQLITE ]
    .tru.am [ C:\USERS\HELENA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\JU292VOK.DEFAULT-1438795000345\COOKIES.SQLITE ]
    .tynt.com [ C:\USERS\HELENA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\JU292VOK.DEFAULT-1438795000345\COOKIES.SQLITE ]
    .tellapart.com [ C:\USERS\HELENA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\JU292VOK.DEFAULT-1438795000345\COOKIES.SQLITE ]
    .t.tellapart.com [ C:\USERS\HELENA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\JU292VOK.DEFAULT-1438795000345\COOKIES.SQLITE ]
    .t.tellapart.com [ C:\USERS\HELENA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\JU292VOK.DEFAULT-1438795000345\COOKIES.SQLITE ]
    .tellapart.com [ C:\USERS\HELENA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\JU292VOK.DEFAULT-1438795000345\COOKIES.SQLITE ]
    .choicestream.com [ C:\USERS\HELENA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\JU292VOK.DEFAULT-1438795000345\COOKIES.SQLITE ]
    .choicestream.com [ C:\USERS\HELENA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\JU292VOK.DEFAULT-1438795000345\COOKIES.SQLITE ]
    .dpclk.com [ C:\USERS\HELENA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\JU292VOK.DEFAULT-1438795000345\COOKIES.SQLITE ]
    .mediaforge.com [ C:\USERS\HELENA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\JU292VOK.DEFAULT-1438795000345\COOKIES.SQLITE ]
    .dpclk.com [ C:\USERS\HELENA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\JU292VOK.DEFAULT-1438795000345\COOKIES.SQLITE ]
    .eyeviewads.com [ C:\USERS\HELENA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\JU292VOK.DEFAULT-1438795000345\COOKIES.SQLITE ]
    .adblade.com [ C:\USERS\HELENA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\JU292VOK.DEFAULT-1438795000345\COOKIES.SQLITE ]
    .adsby.bidtheatre.com [ C:\USERS\HELENA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\JU292VOK.DEFAULT-1438795000345\COOKIES.SQLITE ]
    .ahalogy.com [ C:\USERS\HELENA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\JU292VOK.DEFAULT-1438795000345\COOKIES.SQLITE ]
    .udmserve.net [ C:\USERS\HELENA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\JU292VOK.DEFAULT-1438795000345\COOKIES.SQLITE ]
    .adblade.com [ C:\USERS\HELENA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\JU292VOK.DEFAULT-1438795000345\COOKIES.SQLITE ]
    sumome.com [ C:\USERS\HELENA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\JU292VOK.DEFAULT-1438795000345\COOKIES.SQLITE ]
    .adblade.com [ C:\USERS\HELENA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\JU292VOK.DEFAULT-1438795000345\COOKIES.SQLITE ]
    .go.sonobi.com [ C:\USERS\HELENA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\JU292VOK.DEFAULT-1438795000345\COOKIES.SQLITE ]
    .go.sonobi.com [ C:\USERS\HELENA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\JU292VOK.DEFAULT-1438795000345\COOKIES.SQLITE ]
    .go.sonobi.com [ C:\USERS\HELENA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\JU292VOK.DEFAULT-1438795000345\COOKIES.SQLITE ]
    .go.sonobi.com [ C:\USERS\HELENA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\JU292VOK.DEFAULT-1438795000345\COOKIES.SQLITE ]
    .go.sonobi.com [ C:\USERS\HELENA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\JU292VOK.DEFAULT-1438795000345\COOKIES.SQLITE ]
    .go.sonobi.com [ C:\USERS\HELENA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\JU292VOK.DEFAULT-1438795000345\COOKIES.SQLITE ]
    .go.sonobi.com [ C:\USERS\HELENA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\JU292VOK.DEFAULT-1438795000345\COOKIES.SQLITE ]
    .go.sonobi.com [ C:\USERS\HELENA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\JU292VOK.DEFAULT-1438795000345\COOKIES.SQLITE ]
    .go.sonobi.com [ C:\USERS\HELENA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\JU292VOK.DEFAULT-1438795000345\COOKIES.SQLITE ]
    .c.appier.net [ C:\USERS\HELENA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\JU292VOK.DEFAULT-1438795000345\COOKIES.SQLITE ]
    .fwmrm.net [ C:\USERS\HELENA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\JU292VOK.DEFAULT-1438795000345\COOKIES.SQLITE ]
    .pubmatic.com [ C:\USERS\HELENA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\JU292VOK.DEFAULT-1438795000345\COOKIES.SQLITE ]
    .dashbida.com [ C:\USERS\HELENA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\JU292VOK.DEFAULT-1438795000345\COOKIES.SQLITE ]
    .doubleclick.net [ C:\USERS\HELENA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\JU292VOK.DEFAULT-1438795000345\COOKIES.SQLITE ]
    .outbrain.com [ C:\USERS\HELENA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\JU292VOK.DEFAULT-1438795000345\COOKIES.SQLITE ]
    .w.ahalogy.com [ C:\USERS\HELENA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\JU292VOK.DEFAULT-1438795000345\COOKIES.SQLITE ]
    .w.ahalogy.com [ C:\USERS\HELENA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\JU292VOK.DEFAULT-1438795000345\COOKIES.SQLITE ]
    .h30-deploy.hiconversion.com [ C:\USERS\HELENA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\JU292VOK.DEFAULT-1438795000345\COOKIES.SQLITE ]
    .chango.com [ C:\USERS\HELENA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\JU292VOK.DEFAULT-1438795000345\COOKIES.SQLITE ]
    .chango.com [ C:\USERS\HELENA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\JU292VOK.DEFAULT-1438795000345\COOKIES.SQLITE ]
    .chango.com [ C:\USERS\HELENA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\JU292VOK.DEFAULT-1438795000345\COOKIES.SQLITE ]
    .chango.com [ C:\USERS\HELENA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\JU292VOK.DEFAULT-1438795000345\COOKIES.SQLITE ]
    .krxd.net [ C:\USERS\HELENA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\JU292VOK.DEFAULT-1438795000345\COOKIES.SQLITE ]
    .lijit.com [ C:\USERS\HELENA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\JU292VOK.DEFAULT-1438795000345\COOKIES.SQLITE ]
    .lijit.com [ C:\USERS\HELENA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\JU292VOK.DEFAULT-1438795000345\COOKIES.SQLITE ]
    .lijit.com [ C:\USERS\HELENA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\JU292VOK.DEFAULT-1438795000345\COOKIES.SQLITE ]
    .marinsm.com [ C:\USERS\HELENA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\JU292VOK.DEFAULT-1438795000345\COOKIES.SQLITE ]
    .outbrain.com [ C:\USERS\HELENA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\JU292VOK.DEFAULT-1438795000345\COOKIES.SQLITE ]
    .rhythmxchange.com [ C:\USERS\HELENA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\JU292VOK.DEFAULT-1438795000345\COOKIES.SQLITE ]
    .fwmrm.net [ C:\USERS\HELENA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\JU292VOK.DEFAULT-1438795000345\COOKIES.SQLITE ]
    .sitescout.com [ C:\USERS\HELENA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\JU292VOK.DEFAULT-1438795000345\COOKIES.SQLITE ]
    pixel-a.sitescout.com [ C:\USERS\HELENA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\JU292VOK.DEFAULT-1438795000345\COOKIES.SQLITE ]
    pixel.sitescout.com [ C:\USERS\HELENA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\JU292VOK.DEFAULT-1438795000345\COOKIES.SQLITE ]
    .chango.com [ C:\USERS\HELENA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\JU292VOK.DEFAULT-1438795000345\COOKIES.SQLITE ]
    .widget.perfectmarket.com [ C:\USERS\HELENA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\JU292VOK.DEFAULT-1438795000345\COOKIES.SQLITE ]
    .widget.perfectmarket.com [ C:\USERS\HELENA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\JU292VOK.DEFAULT-1438795000345\COOKIES.SQLITE ]
    .widget.perfectmarket.com [ C:\USERS\HELENA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\JU292VOK.DEFAULT-1438795000345\COOKIES.SQLITE ]
    .tubemogul.com [ C:\USERS\HELENA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\JU292VOK.DEFAULT-1438795000345\COOKIES.SQLITE ]
    .tubemogul.com [ C:\USERS\HELENA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\JU292VOK.DEFAULT-1438795000345\COOKIES.SQLITE ]
    .fwmrm.net [ C:\USERS\HELENA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\JU292VOK.DEFAULT-1438795000345\COOKIES.SQLITE ]
    .outbrain.com [ C:\USERS\HELENA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\JU292VOK.DEFAULT-1438795000345\COOKIES.SQLITE ]
    .fwmrm.net [ C:\USERS\HELENA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\JU292VOK.DEFAULT-1438795000345\COOKIES.SQLITE ]
    .chango.com [ C:\USERS\HELENA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\JU292VOK.DEFAULT-1438795000345\COOKIES.SQLITE ]
    .fwmrm.net [ C:\USERS\HELENA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\JU292VOK.DEFAULT-1438795000345\COOKIES.SQLITE ]
    w.ahalogy.com [ C:\USERS\HELENA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\JU292VOK.DEFAULT-1438795000345\COOKIES.SQLITE ]
    .adadvisor.net [ C:\USERS\HELENA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\JU292VOK.DEFAULT-1438795000345\COOKIES.SQLITE ]
    .rfihub.com [ C:\USERS\HELENA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\JU292VOK.DEFAULT-1438795000345\COOKIES.SQLITE ]
    .media6degrees.com [ C:\USERS\HELENA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\JU292VOK.DEFAULT-1438795000345\COOKIES.SQLITE ]
    .bluecava.com [ C:\USERS\HELENA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\JU292VOK.DEFAULT-1438795000345\COOKIES.SQLITE ]
    .adaptv.advertising.com [ C:\USERS\HELENA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\JU292VOK.DEFAULT-1438795000345\COOKIES.SQLITE ]
    .adap.tv [ C:\USERS\HELENA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\JU292VOK.DEFAULT-1438795000345\COOKIES.SQLITE ]
    .adaptv.advertising.com [ C:\USERS\HELENA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\JU292VOK.DEFAULT-1438795000345\COOKIES.SQLITE ]
    .altitude-arena.com [ C:\USERS\HELENA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\JU292VOK.DEFAULT-1438795000345\COOKIES.SQLITE ]
    .owneriq.net [ C:\USERS\HELENA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\JU292VOK.DEFAULT-1438795000345\COOKIES.SQLITE ]
    .admized.com [ C:\USERS\HELENA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\JU292VOK.DEFAULT-1438795000345\COOKIES.SQLITE ]
    .adaptv.advertising.com [ C:\USERS\HELENA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\JU292VOK.DEFAULT-1438795000345\COOKIES.SQLITE ]
    .aexp.demdex.net [ C:\USERS\HELENA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\JU292VOK.DEFAULT-1438795000345\COOKIES.SQLITE ]
    .dmtry.com [ C:\USERS\HELENA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\JU292VOK.DEFAULT-1438795000345\COOKIES.SQLITE ]
    .mediaforge.com [ C:\USERS\HELENA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\JU292VOK.DEFAULT-1438795000345\COOKIES.SQLITE ]
    idp.securetve.com [ C:\USERS\HELENA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\JU292VOK.DEFAULT-1438795000345\COOKIES.SQLITE ]
    idp.securetve.com [ C:\USERS\HELENA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\JU292VOK.DEFAULT-1438795000345\COOKIES.SQLITE ]
    idp.securetve.com [ C:\USERS\HELENA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\JU292VOK.DEFAULT-1438795000345\COOKIES.SQLITE ]
    .pro-market.net [ C:\USERS\HELENA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\JU292VOK.DEFAULT-1438795000345\COOKIES.SQLITE ]
    .adnxs.com [ C:\USERS\HELENA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\JU292VOK.DEFAULT-1438795000345\COOKIES.SQLITE ]
    .owneriq.net [ C:\USERS\HELENA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\JU292VOK.DEFAULT-1438795000345\COOKIES.SQLITE ]
    .rubiconproject.com [ C:\USERS\HELENA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\JU292VOK.DEFAULT-1438795000345\COOKIES.SQLITE ]
    .acuityplatform.com [ C:\USERS\HELENA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\JU292VOK.DEFAULT-1438795000345\COOKIES.SQLITE ]
    engine.adzerk.net [ C:\USERS\HELENA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\JU292VOK.DEFAULT-1438795000345\COOKIES.SQLITE ]
    .rfihub.com [ C:\USERS\HELENA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\JU292VOK.DEFAULT-1438795000345\COOKIES.SQLITE ]
    .bidr.io [ C:\USERS\HELENA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\JU292VOK.DEFAULT-1438795000345\COOKIES.SQLITE ]
    .bluekai.com [ C:\USERS\HELENA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\JU292VOK.DEFAULT-1438795000345\COOKIES.SQLITE ]
    .bluekai.com [ C:\USERS\HELENA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\JU292VOK.DEFAULT-1438795000345\COOKIES.SQLITE ]
    .bnmla.com [ C:\USERS\HELENA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\JU292VOK.DEFAULT-1438795000345\COOKIES.SQLITE ]
    .scanscout.com [ C:\USERS\HELENA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\JU292VOK.DEFAULT-1438795000345\COOKIES.SQLITE ]
    .s.thebrighttag.com [ C:\USERS\HELENA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\JU292VOK.DEFAULT-1438795000345\COOKIES.SQLITE ]
    .s.thebrighttag.com [ C:\USERS\HELENA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\JU292VOK.DEFAULT-1438795000345\COOKIES.SQLITE ]
    .s.thebrighttag.com [ C:\USERS\HELENA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\JU292VOK.DEFAULT-1438795000345\COOKIES.SQLITE ]
    .5257009.log.optimizely.com [ C:\USERS\HELENA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\JU292VOK.DEFAULT-1438795000345\COOKIES.SQLITE ]
    .adsnative.com [ C:\USERS\HELENA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\JU292VOK.DEFAULT-1438795000345\COOKIES.SQLITE ]
    .acuityplatform.com [ C:\USERS\HELENA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\JU292VOK.DEFAULT-1438795000345\COOKIES.SQLITE ]
    .acuityplatform.com [ C:\USERS\HELENA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\JU292VOK.DEFAULT-1438795000345\COOKIES.SQLITE ]
    .acuityplatform.com [ C:\USERS\HELENA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\JU292VOK.DEFAULT-1438795000345\COOKIES.SQLITE ]
    .acuityplatform.com [ C:\USERS\HELENA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\JU292VOK.DEFAULT-1438795000345\COOKIES.SQLITE ]
    .bidswitch.net [ C:\USERS\HELENA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\JU292VOK.DEFAULT-1438795000345\COOKIES.SQLITE ]
    .mediaforge.com [ C:\USERS\HELENA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\JU292VOK.DEFAULT-1438795000345\COOKIES.SQLITE ]
    pix.btrll.com [ C:\USERS\HELENA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\JU292VOK.DEFAULT-1438795000345\COOKIES.SQLITE ]
    pix.btrll.com [ C:\USERS\HELENA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\JU292VOK.DEFAULT-1438795000345\COOKIES.SQLITE ]
    pix.btrll.com [ C:\USERS\HELENA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\JU292VOK.DEFAULT-1438795000345\COOKIES.SQLITE ]
    pix.btrll.com [ C:\USERS\HELENA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\JU292VOK.DEFAULT-1438795000345\COOKIES.SQLITE ]
    .clickagy.com [ C:\USERS\HELENA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\JU292VOK.DEFAULT-1438795000345\COOKIES.SQLITE ]
    .media6degrees.com [ C:\USERS\HELENA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\JU292VOK.DEFAULT-1438795000345\COOKIES.SQLITE ]
    .rubiconproject.com [ C:\USERS\HELENA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\JU292VOK.DEFAULT-1438795000345\COOKIES.SQLITE ]
    .basebanner.com [ C:\USERS\HELENA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\JU292VOK.DEFAULT-1438795000345\COOKIES.SQLITE ]
    .basebanner.com [ C:\USERS\HELENA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\JU292VOK.DEFAULT-1438795000345\COOKIES.SQLITE ]
    .basebanner.com [ C:\USERS\HELENA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\JU292VOK.DEFAULT-1438795000345\COOKIES.SQLITE ]
    .basebanner.com [ C:\USERS\HELENA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\JU292VOK.DEFAULT-1438795000345\COOKIES.SQLITE ]
    .basebanner.com [ C:\USERS\HELENA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\JU292VOK.DEFAULT-1438795000345\COOKIES.SQLITE ]
    .rlcdn.com [ C:\USERS\HELENA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\JU292VOK.DEFAULT-1438795000345\COOKIES.SQLITE ]
    .media6degrees.com [ C:\USERS\HELENA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\JU292VOK.DEFAULT-1438795000345\COOKIES.SQLITE ]
    in.getclicky.com [ C:\USERS\HELENA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\JU292VOK.DEFAULT-1438795000345\COOKIES.SQLITE ]
    .comcast.demdex.net [ C:\USERS\HELENA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\JU292VOK.DEFAULT-1438795000345\COOKIES.SQLITE ]
    .wtp101.com [ C:\USERS\HELENA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\JU292VOK.DEFAULT-1438795000345\COOKIES.SQLITE ]
    .adaptv.advertising.com [ C:\USERS\HELENA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\JU292VOK.DEFAULT-1438795000345\COOKIES.SQLITE ]
    .rubiconproject.com [ C:\USERS\HELENA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\JU292VOK.DEFAULT-1438795000345\COOKIES.SQLITE ]
    .rubiconproject.com [ C:\USERS\HELENA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\JU292VOK.DEFAULT-1438795000345\COOKIES.SQLITE ]
    .rubiconproject.com [ C:\USERS\HELENA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\JU292VOK.DEFAULT-1438795000345\COOKIES.SQLITE ]
    .rubiconproject.com [ C:\USERS\HELENA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\JU292VOK.DEFAULT-1438795000345\COOKIES.SQLITE ]
    .rubiconproject.com [ C:\USERS\HELENA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\JU292VOK.DEFAULT-1438795000345\COOKIES.SQLITE ]
    .rubiconproject.com [ C:\USERS\HELENA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\JU292VOK.DEFAULT-1438795000345\COOKIES.SQLITE ]
    .smartadserver.com [ C:\USERS\HELENA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\JU292VOK.DEFAULT-1438795000345\COOKIES.SQLITE ]
    .lijit.com [ C:\USERS\HELENA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\JU292VOK.DEFAULT-1438795000345\COOKIES.SQLITE ]
    .adaptv.advertising.com [ C:\USERS\HELENA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\JU292VOK.DEFAULT-1438795000345\COOKIES.SQLITE ]
    .fastclick.net [ C:\USERS\HELENA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\JU292VOK.DEFAULT-1438795000345\COOKIES.SQLITE ]
    .ipredictive.com [ C:\USERS\HELENA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\JU292VOK.DEFAULT-1438795000345\COOKIES.SQLITE ]
    .wtp101.com [ C:\USERS\HELENA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\JU292VOK.DEFAULT-1438795000345\COOKIES.SQLITE ]
    recs.richrelevance.com [ C:\USERS\HELENA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\JU292VOK.DEFAULT-1438795000345\COOKIES.SQLITE ]
    .sp1.convertro.com [ C:\USERS\HELENA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\JU292VOK.DEFAULT-1438795000345\COOKIES.SQLITE ]
    .convertro.com [ C:\USERS\HELENA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\JU292VOK.DEFAULT-1438795000345\COOKIES.SQLITE ]
    .sp1.convertro.com [ C:\USERS\HELENA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\JU292VOK.DEFAULT-1438795000345\COOKIES.SQLITE ]
    .sp1.convertro.com [ C:\USERS\HELENA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\JU292VOK.DEFAULT-1438795000345\COOKIES.SQLITE ]
    .convertro.com [ C:\USERS\HELENA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\JU292VOK.DEFAULT-1438795000345\COOKIES.SQLITE ]
    .sp1.convertro.com [ C:\USERS\HELENA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\JU292VOK.DEFAULT-1438795000345\COOKIES.SQLITE ]
    .kau.li [ C:\USERS\HELENA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\JU292VOK.DEFAULT-1438795000345\COOKIES.SQLITE ]
    .pagefair.com [ C:\USERS\HELENA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\JU292VOK.DEFAULT-1438795000345\COOKIES.SQLITE ]
    .media.net [ C:\USERS\HELENA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\JU292VOK.DEFAULT-1438795000345\COOKIES.SQLITE ]
    .apxlv.com [ C:\USERS\HELENA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\JU292VOK.DEFAULT-1438795000345\COOKIES.SQLITE ]
    .cogocast.net [ C:\USERS\HELENA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\JU292VOK.DEFAULT-1438795000345\COOKIES.SQLITE ]
    .demdex.net [ C:\USERS\HELENA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\JU292VOK.DEFAULT-1438795000345\COOKIES.SQLITE ]
    .aexp.demdex.net [ C:\USERS\HELENA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\JU292VOK.DEFAULT-1438795000345\COOKIES.SQLITE ]
    .comcast.demdex.net [ C:\USERS\HELENA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\JU292VOK.DEFAULT-1438795000345\COOKIES.SQLITE ]
    .dish.demdex.net [ C:\USERS\HELENA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\JU292VOK.DEFAULT-1438795000345\COOKIES.SQLITE ]
    .dpm.demdex.net [ C:\USERS\HELENA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\JU292VOK.DEFAULT-1438795000345\COOKIES.SQLITE ]
    .foxnews.demdex.net [ C:\USERS\HELENA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\JU292VOK.DEFAULT-1438795000345\COOKIES.SQLITE ]
    .homedepot.demdex.net [ C:\USERS\HELENA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\JU292VOK.DEFAULT-1438795000345\COOKIES.SQLITE ]
    .tdameritrade.demdex.net [ C:\USERS\HELENA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\JU292VOK.DEFAULT-1438795000345\COOKIES.SQLITE ]
    .vivaki.demdex.net [ C:\USERS\HELENA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\JU292VOK.DEFAULT-1438795000345\COOKIES.SQLITE ]
    .addthis.com [ C:\USERS\HELENA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\JU292VOK.DEFAULT-1438795000345\COOKIES.SQLITE ]
    .rlcdn.com [ C:\USERS\HELENA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\JU292VOK.DEFAULT-1438795000345\COOKIES.SQLITE ]
    .dish.demdex.net [ C:\USERS\HELENA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\JU292VOK.DEFAULT-1438795000345\COOKIES.SQLITE ]
    .at.atwola.com [ C:\USERS\HELENA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\JU292VOK.DEFAULT-1438795000345\COOKIES.SQLITE ]
    .sekindo.com [ C:\USERS\HELENA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\JU292VOK.DEFAULT-1438795000345\COOKIES.SQLITE ]
    .dpm.demdex.net [ C:\USERS\HELENA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\JU292VOK.DEFAULT-1438795000345\COOKIES.SQLITE ]
    tap-t.rubiconproject.com [ C:\USERS\HELENA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\JU292VOK.DEFAULT-1438795000345\COOKIES.SQLITE ]
    tap.rubiconproject.com [ C:\USERS\HELENA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\JU292VOK.DEFAULT-1438795000345\COOKIES.SQLITE ]
    .tellapart.com [ C:\USERS\HELENA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\JU292VOK.DEFAULT-1438795000345\COOKIES.SQLITE ]
    .tellapart.com [ C:\USERS\HELENA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\JU292VOK.DEFAULT-1438795000345\COOKIES.SQLITE ]
    .angsrvr.com [ C:\USERS\HELENA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\JU292VOK.DEFAULT-1438795000345\COOKIES.SQLITE ]
    .sxp.smartclip.net [ C:\USERS\HELENA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\JU292VOK.DEFAULT-1438795000345\COOKIES.SQLITE ]
    .addthis.com [ C:\USERS\HELENA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\JU292VOK.DEFAULT-1438795000345\COOKIES.SQLITE ]
    .udmserve.net [ C:\USERS\HELENA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\JU292VOK.DEFAULT-1438795000345\COOKIES.SQLITE ]
    .ebdr3.com [ C:\USERS\HELENA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\JU292VOK.DEFAULT-1438795000345\COOKIES.SQLITE ]
    .dyntrk.com [ C:\USERS\HELENA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\JU292VOK.DEFAULT-1438795000345\COOKIES.SQLITE ]
    .smartadserver.com [ C:\USERS\HELENA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\JU292VOK.DEFAULT-1438795000345\COOKIES.SQLITE ]
    .criteo.com [ C:\USERS\HELENA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\JU292VOK.DEFAULT-1438795000345\COOKIES.SQLITE ]
    .5257009.log.optimizely.com [ C:\USERS\HELENA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\JU292VOK.DEFAULT-1438795000345\COOKIES.SQLITE ]
    .owneriq.net [ C:\USERS\HELENA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\JU292VOK.DEFAULT-1438795000345\COOKIES.SQLITE ]
    .eyereturn.com [ C:\USERS\HELENA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\JU292VOK.DEFAULT-1438795000345\COOKIES.SQLITE ]
    .rfihub.com [ C:\USERS\HELENA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\JU292VOK.DEFAULT-1438795000345\COOKIES.SQLITE ]
    .everesttech.net [ C:\USERS\HELENA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\JU292VOK.DEFAULT-1438795000345\COOKIES.SQLITE ]
    .everesttech.net [ C:\USERS\HELENA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\JU292VOK.DEFAULT-1438795000345\COOKIES.SQLITE ]
    .univide.com [ C:\USERS\HELENA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\JU292VOK.DEFAULT-1438795000345\COOKIES.SQLITE ]
    .univide.com [ C:\USERS\HELENA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\JU292VOK.DEFAULT-1438795000345\COOKIES.SQLITE ]
    .extend.tv [ C:\USERS\HELENA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\JU292VOK.DEFAULT-1438795000345\COOKIES.SQLITE ]
    .turn.com [ C:\USERS\HELENA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\JU292VOK.DEFAULT-1438795000345\COOKIES.SQLITE ]
    .admaym.com [ C:\USERS\HELENA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\JU292VOK.DEFAULT-1438795000345\COOKIES.SQLITE ]
    .atemda.com [ C:\USERS\HELENA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\JU292VOK.DEFAULT-1438795000345\COOKIES.SQLITE ]
    .flashtalking.com [ C:\USERS\HELENA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\JU292VOK.DEFAULT-1438795000345\COOKIES.SQLITE ]
    .foxnews.demdex.net [ C:\USERS\HELENA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\JU292VOK.DEFAULT-1438795000345\COOKIES.SQLITE ]
    .sekindo.com [ C:\USERS\HELENA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\JU292VOK.DEFAULT-1438795000345\COOKIES.SQLITE ]
    .sekindo.com [ C:\USERS\HELENA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\JU292VOK.DEFAULT-1438795000345\COOKIES.SQLITE ]
    .sekindo.com [ C:\USERS\HELENA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\JU292VOK.DEFAULT-1438795000345\COOKIES.SQLITE ]
    .rfihub.com [ C:\USERS\HELENA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\JU292VOK.DEFAULT-1438795000345\COOKIES.SQLITE ]
    .gumgum.com [ C:\USERS\HELENA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\JU292VOK.DEFAULT-1438795000345\COOKIES.SQLITE ]
    .everesttech.net [ C:\USERS\HELENA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\JU292VOK.DEFAULT-1438795000345\COOKIES.SQLITE ]
    .owneriq.net [ C:\USERS\HELENA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\JU292VOK.DEFAULT-1438795000345\COOKIES.SQLITE ]
    .gumgum.com [ C:\USERS\HELENA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\JU292VOK.DEFAULT-1438795000345\COOKIES.SQLITE ]
    .gumgum.com [ C:\USERS\HELENA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\JU292VOK.DEFAULT-1438795000345\COOKIES.SQLITE ]
    .gumgum.com [ C:\USERS\HELENA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\JU292VOK.DEFAULT-1438795000345\COOKIES.SQLITE ]
    .gumgum.com [ C:\USERS\HELENA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\JU292VOK.DEFAULT-1438795000345\COOKIES.SQLITE ]
    .gumgum.com [ C:\USERS\HELENA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\JU292VOK.DEFAULT-1438795000345\COOKIES.SQLITE ]
    .gumgum.com [ C:\USERS\HELENA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\JU292VOK.DEFAULT-1438795000345\COOKIES.SQLITE ]
    .gumgum.com [ C:\USERS\HELENA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\JU292VOK.DEFAULT-1438795000345\COOKIES.SQLITE ]
    .gumgum.com [ C:\USERS\HELENA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\JU292VOK.DEFAULT-1438795000345\COOKIES.SQLITE ]
    .genieessp.jp [ C:\USERS\HELENA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\JU292VOK.DEFAULT-1438795000345\COOKIES.SQLITE ]
    .genieesspv.jp [ C:\USERS\HELENA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\JU292VOK.DEFAULT-1438795000345\COOKIES.SQLITE ]
    .gssprt.jp [ C:\USERS\HELENA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\JU292VOK.DEFAULT-1438795000345\COOKIES.SQLITE ]
    .href.asia [ C:\USERS\HELENA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\JU292VOK.DEFAULT-1438795000345\COOKIES.SQLITE ]
    .cogocast.net [ C:\USERS\HELENA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\JU292VOK.DEFAULT-1438795000345\COOKIES.SQLITE ]
    .listrakbi.com [ C:\USERS\HELENA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\JU292VOK.DEFAULT-1438795000345\COOKIES.SQLITE ]
    .ebdr3.com [ C:\USERS\HELENA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\JU292VOK.DEFAULT-1438795000345\COOKIES.SQLITE ]
    .adaptv.advertising.com [ C:\USERS\HELENA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\JU292VOK.DEFAULT-1438795000345\COOKIES.SQLITE ]
    .homedepot.demdex.net [ C:\USERS\HELENA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\JU292VOK.DEFAULT-1438795000345\COOKIES.SQLITE ]
    .kau.li [ C:\USERS\HELENA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\JU292VOK.DEFAULT-1438795000345\COOKIES.SQLITE ]
    .openx.net [ C:\USERS\HELENA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\JU292VOK.DEFAULT-1438795000345\COOKIES.SQLITE ]
    .ib.mookie1.com [ C:\USERS\HELENA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\JU292VOK.DEFAULT-1438795000345\COOKIES.SQLITE ]
    .ib.mookie1.com [ C:\USERS\HELENA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\JU292VOK.DEFAULT-1438795000345\COOKIES.SQLITE ]
    .ic-live.com [ C:\USERS\HELENA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\JU292VOK.DEFAULT-1438795000345\COOKIES.SQLITE ]
    .ic-live.com [ C:\USERS\HELENA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\JU292VOK.DEFAULT-1438795000345\COOKIES.SQLITE ]
    .adnxs.com [ C:\USERS\HELENA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\JU292VOK.DEFAULT-1438795000345\COOKIES.SQLITE ]
    .doubleclick.net [ C:\USERS\HELENA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\JU292VOK.DEFAULT-1438795000345\COOKIES.SQLITE ]
    .mookie1.com [ C:\USERS\HELENA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\JU292VOK.DEFAULT-1438795000345\COOKIES.SQLITE ]
    .rlcdn.com [ C:\USERS\HELENA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\JU292VOK.DEFAULT-1438795000345\COOKIES.SQLITE ]
    .bluecava.com [ C:\USERS\HELENA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\JU292VOK.DEFAULT-1438795000345\COOKIES.SQLITE ]
    .udmserve.net [ C:\USERS\HELENA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\JU292VOK.DEFAULT-1438795000345\COOKIES.SQLITE ]
    .intentiq.com [ C:\USERS\HELENA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\JU292VOK.DEFAULT-1438795000345\COOKIES.SQLITE ]
    .ooh.li [ C:\USERS\HELENA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\JU292VOK.DEFAULT-1438795000345\COOKIES.SQLITE ]
    .geo-um.btrll.com [ C:\USERS\HELENA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\JU292VOK.DEFAULT-1438795000345\COOKIES.SQLITE ]
    .jumptap.com [ C:\USERS\HELENA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\JU292VOK.DEFAULT-1438795000345\COOKIES.SQLITE ]
    .jivox.com [ C:\USERS\HELENA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\JU292VOK.DEFAULT-1438795000345\COOKIES.SQLITE ]
    .jivox.com [ C:\USERS\HELENA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\JU292VOK.DEFAULT-1438795000345\COOKIES.SQLITE ]
    .rubiconproject.com [ C:\USERS\HELENA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\JU292VOK.DEFAULT-1438795000345\COOKIES.SQLITE ]
    .ooh.li [ C:\USERS\HELENA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\JU292VOK.DEFAULT-1438795000345\COOKIES.SQLITE ]
    .lijit.com [ C:\USERS\HELENA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\JU292VOK.DEFAULT-1438795000345\COOKIES.SQLITE ]
    .lijit.com [ C:\USERS\HELENA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\JU292VOK.DEFAULT-1438795000345\COOKIES.SQLITE ]
    www.wtp101.com [ C:\USERS\HELENA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\JU292VOK.DEFAULT-1438795000345\COOKIES.SQLITE ]
    .addthis.com [ C:\USERS\HELENA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\JU292VOK.DEFAULT-1438795000345\COOKIES.SQLITE ]
    .gumgum.com [ C:\USERS\HELENA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\JU292VOK.DEFAULT-1438795000345\COOKIES.SQLITE ]
    .owneriq.net [ C:\USERS\HELENA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\JU292VOK.DEFAULT-1438795000345\COOKIES.SQLITE ]
    .liverail.com [ C:\USERS\HELENA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\JU292VOK.DEFAULT-1438795000345\COOKIES.SQLITE ]
    .liverail.com [ C:\USERS\HELENA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\JU292VOK.DEFAULT-1438795000345\COOKIES.SQLITE ]
    .liverail.com [ C:\USERS\HELENA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\JU292VOK.DEFAULT-1438795000345\COOKIES.SQLITE ]
    .liverail.com [ C:\USERS\HELENA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\JU292VOK.DEFAULT-1438795000345\COOKIES.SQLITE ]
    .liverail.com [ C:\USERS\HELENA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\JU292VOK.DEFAULT-1438795000345\COOKIES.SQLITE ]
    .bluecava.com [ C:\USERS\HELENA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\JU292VOK.DEFAULT-1438795000345\COOKIES.SQLITE ]
    .pagefair.com [ C:\USERS\HELENA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\JU292VOK.DEFAULT-1438795000345\COOKIES.SQLITE ]
    .eyeota.net [ C:\USERS\HELENA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\JU292VOK.DEFAULT-1438795000345\COOKIES.SQLITE ]
    .w55c.net [ C:\USERS\HELENA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\JU292VOK.DEFAULT-1438795000345\COOKIES.SQLITE ]
    .w55c.net [ C:\USERS\HELENA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\JU292VOK.DEFAULT-1438795000345\COOKIES.SQLITE ]
    .w55c.net [ C:\USERS\HELENA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\JU292VOK.DEFAULT-1438795000345\COOKIES.SQLITE ]
    .w55c.net [ C:\USERS\HELENA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\JU292VOK.DEFAULT-1438795000345\COOKIES.SQLITE ]
    .w55c.net [ C:\USERS\HELENA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\JU292VOK.DEFAULT-1438795000345\COOKIES.SQLITE ]
    .w55c.net [ C:\USERS\HELENA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\JU292VOK.DEFAULT-1438795000345\COOKIES.SQLITE ]
    .w55c.net [ C:\USERS\HELENA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\JU292VOK.DEFAULT-1438795000345\COOKIES.SQLITE ]
    .w55c.net [ C:\USERS\HELENA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\JU292VOK.DEFAULT-1438795000345\COOKIES.SQLITE ]
    .w55c.net [ C:\USERS\HELENA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\JU292VOK.DEFAULT-1438795000345\COOKIES.SQLITE ]
    .w55c.net [ C:\USERS\HELENA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\JU292VOK.DEFAULT-1438795000345\COOKIES.SQLITE ]
    .w55c.net [ C:\USERS\HELENA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\JU292VOK.DEFAULT-1438795000345\COOKIES.SQLITE ]
    .w55c.net [ C:\USERS\HELENA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\JU292VOK.DEFAULT-1438795000345\COOKIES.SQLITE ]
    .w55c.net [ C:\USERS\HELENA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\JU292VOK.DEFAULT-1438795000345\COOKIES.SQLITE ]
    .w55c.net [ C:\USERS\HELENA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\JU292VOK.DEFAULT-1438795000345\COOKIES.SQLITE ]
    .w55c.net [ C:\USERS\HELENA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\JU292VOK.DEFAULT-1438795000345\COOKIES.SQLITE ]
    .w55c.net [ C:\USERS\HELENA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\JU292VOK.DEFAULT-1438795000345\COOKIES.SQLITE ]
    .w55c.net [ C:\USERS\HELENA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\JU292VOK.DEFAULT-1438795000345\COOKIES.SQLITE ]
    .w55c.net [ C:\USERS\HELENA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\JU292VOK.DEFAULT-1438795000345\COOKIES.SQLITE ]
    .w55c.net [ C:\USERS\HELENA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\JU292VOK.DEFAULT-1438795000345\COOKIES.SQLITE ]
    .w55c.net [ C:\USERS\HELENA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\JU292VOK.DEFAULT-1438795000345\COOKIES.SQLITE ]
    .w55c.net [ C:\USERS\HELENA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\JU292VOK.DEFAULT-1438795000345\COOKIES.SQLITE ]
    .w55c.net [ C:\USERS\HELENA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\JU292VOK.DEFAULT-1438795000345\COOKIES.SQLITE ]
    .w55c.net [ C:\USERS\HELENA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\JU292VOK.DEFAULT-1438795000345\COOKIES.SQLITE ]
    .w55c.net [ C:\USERS\HELENA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\JU292VOK.DEFAULT-1438795000345\COOKIES.SQLITE ]
    .w55c.net [ C:\USERS\HELENA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\JU292VOK.DEFAULT-1438795000345\COOKIES.SQLITE ]
    .w55c.net [ C:\USERS\HELENA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\JU292VOK.DEFAULT-1438795000345\COOKIES.SQLITE ]
    .w55c.net [ C:\USERS\HELENA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\JU292VOK.DEFAULT-1438795000345\COOKIES.SQLITE ]
    .w55c.net [ C:\USERS\HELENA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\JU292VOK.DEFAULT-1438795000345\COOKIES.SQLITE ]
    .w55c.net [ C:\USERS\HELENA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\JU292VOK.DEFAULT-1438795000345\COOKIES.SQLITE ]
    .mookie1.com [ C:\USERS\HELENA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\JU292VOK.DEFAULT-1438795000345\COOKIES.SQLITE ]
    .adingo.jp [ C:\USERS\HELENA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\JU292VOK.DEFAULT-1438795000345\COOKIES.SQLITE ]
    tru.am [ C:\USERS\HELENA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\JU292VOK.DEFAULT-1438795000345\COOKIES.SQLITE ]
    .adap.tv [ C:\USERS\HELENA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\JU292VOK.DEFAULT-1438795000345\COOKIES.SQLITE ]
    .metanetwork.net [ C:\USERS\HELENA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\JU292VOK.DEFAULT-1438795000345\COOKIES.SQLITE ]
    .mediaplex.com [ C:\USERS\HELENA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\JU292VOK.DEFAULT-1438795000345\COOKIES.SQLITE ]
    .mathtag.com [ C:\USERS\HELENA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\JU292VOK.DEFAULT-1438795000345\COOKIES.SQLITE ]
    .mathtag.com [ C:\USERS\HELENA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\JU292VOK.DEFAULT-1438795000345\COOKIES.SQLITE ]
    .richrelevance.com [ C:\USERS\HELENA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\JU292VOK.DEFAULT-1438795000345\COOKIES.SQLITE ]
    .mxptint.net [ C:\USERS\HELENA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\JU292VOK.DEFAULT-1438795000345\COOKIES.SQLITE ]
    recs.richrelevance.com [ C:\USERS\HELENA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\JU292VOK.DEFAULT-1438795000345\COOKIES.SQLITE ]
    .nexac.com [ C:\USERS\HELENA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\JU292VOK.DEFAULT-1438795000345\COOKIES.SQLITE ]
    .nexac.com [ C:\USERS\HELENA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\JU292VOK.DEFAULT-1438795000345\COOKIES.SQLITE ]
    .nexac.com [ C:\USERS\HELENA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\JU292VOK.DEFAULT-1438795000345\COOKIES.SQLITE ]
    .nexac.com [ C:\USERS\HELENA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\JU292VOK.DEFAULT-1438795000345\COOKIES.SQLITE ]
    .nexac.com [ C:\USERS\HELENA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\JU292VOK.DEFAULT-1438795000345\COOKIES.SQLITE ]
    .nexac.com [ C:\USERS\HELENA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\JU292VOK.DEFAULT-1438795000345\COOKIES.SQLITE ]
    .netseer.com [ C:\USERS\HELENA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\JU292VOK.DEFAULT-1438795000345\COOKIES.SQLITE ]
    .outbrain.com [ C:\USERS\HELENA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\JU292VOK.DEFAULT-1438795000345\COOKIES.SQLITE ]
    .opendsp.com [ C:\USERS\HELENA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\JU292VOK.DEFAULT-1438795000345\COOKIES.SQLITE ]
    .optimatic.com [ C:\USERS\HELENA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\JU292VOK.DEFAULT-1438795000345\COOKIES.SQLITE ]
    .spotxchange.com [ C:\USERS\HELENA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\JU292VOK.DEFAULT-1438795000345\COOKIES.SQLITE ]
    .owneriq.net [ C:\USERS\HELENA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\JU292VOK.DEFAULT-1438795000345\COOKIES.SQLITE ]
    .mediaforge.com [ C:\USERS\HELENA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\JU292VOK.DEFAULT-1438795000345\COOKIES.SQLITE ]
    .config.parsely.com [ C:\USERS\HELENA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\JU292VOK.DEFAULT-1438795000345\COOKIES.SQLITE ]
    .contextweb.com [ C:\USERS\HELENA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\JU292VOK.DEFAULT-1438795000345\COOKIES.SQLITE ]
    .smartadserver.com [ C:\USERS\HELENA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\JU292VOK.DEFAULT-1438795000345\COOKIES.SQLITE ]
    .smartadserver.com [ C:\USERS\HELENA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\JU292VOK.DEFAULT-1438795000345\COOKIES.SQLITE ]
    .openx.net [ C:\USERS\HELENA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\JU292VOK.DEFAULT-1438795000345\COOKIES.SQLITE ]
    .smartadserver.com [ C:\USERS\HELENA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\JU292VOK.DEFAULT-1438795000345\COOKIES.SQLITE ]
    .univide.com [ C:\USERS\HELENA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\JU292VOK.DEFAULT-1438795000345\COOKIES.SQLITE ]
    .smartadserver.com [ C:\USERS\HELENA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\JU292VOK.DEFAULT-1438795000345\COOKIES.SQLITE ]
    de.tynt.com [ C:\USERS\HELENA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\JU292VOK.DEFAULT-1438795000345\COOKIES.SQLITE ]
    .adohana.com [ C:\USERS\HELENA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\JU292VOK.DEFAULT-1438795000345\COOKIES.SQLITE ]
    .fastclick.net [ C:\USERS\HELENA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\JU292VOK.DEFAULT-1438795000345\COOKIES.SQLITE ]
    ads.nexage.com [ C:\USERS\HELENA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\JU292VOK.DEFAULT-1438795000345\COOKIES.SQLITE ]
    googleads.g.doubleclick.net [ C:\USERS\HELENA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\JU292VOK.DEFAULT-1438795000345\COOKIES.SQLITE ]
    .angsrvr.com [ C:\USERS\HELENA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\JU292VOK.DEFAULT-1438795000345\COOKIES.SQLITE ]
    .sxp.smartclip.net [ C:\USERS\HELENA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\JU292VOK.DEFAULT-1438795000345\COOKIES.SQLITE ]
    .pubmatic.com [ C:\USERS\HELENA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\JU292VOK.DEFAULT-1438795000345\COOKIES.SQLITE ]
    .ads.pubmatic.com [ C:\USERS\HELENA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\JU292VOK.DEFAULT-1438795000345\COOKIES.SQLITE ]
    .pubmatic.com [ C:\USERS\HELENA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\JU292VOK.DEFAULT-1438795000345\COOKIES.SQLITE ]
    .revsci.net [ C:\USERS\HELENA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\JU292VOK.DEFAULT-1438795000345\COOKIES.SQLITE ]
    .wtp101.com [ C:\USERS\HELENA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\JU292VOK.DEFAULT-1438795000345\COOKIES.SQLITE ]
    .udmserve.net [ C:\USERS\HELENA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\JU292VOK.DEFAULT-1438795000345\COOKIES.SQLITE ]
    .rubiconproject.com [ C:\USERS\HELENA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\JU292VOK.DEFAULT-1438795000345\COOKIES.SQLITE ]
    .rubiconproject.com [ C:\USERS\HELENA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\JU292VOK.DEFAULT-1438795000345\COOKIES.SQLITE ]
    .rubiconproject.com [ C:\USERS\HELENA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\JU292VOK.DEFAULT-1438795000345\COOKIES.SQLITE ]
    .rubiconproject.com [ C:\USERS\HELENA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\JU292VOK.DEFAULT-1438795000345\COOKIES.SQLITE ]
    .rubiconproject.com [ C:\USERS\HELENA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\JU292VOK.DEFAULT-1438795000345\COOKIES.SQLITE ]
    .rubiconproject.com [ C:\USERS\HELENA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\JU292VOK.DEFAULT-1438795000345\COOKIES.SQLITE ]
    .rubiconproject.com [ C:\USERS\HELENA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\JU292VOK.DEFAULT-1438795000345\COOKIES.SQLITE ]
    .rubiconproject.com [ C:\USERS\HELENA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\JU292VOK.DEFAULT-1438795000345\COOKIES.SQLITE ]
    .rubiconproject.com [ C:\USERS\HELENA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\JU292VOK.DEFAULT-1438795000345\COOKIES.SQLITE ]
    .rubiconproject.com [ C:\USERS\HELENA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\JU292VOK.DEFAULT-1438795000345\COOKIES.SQLITE ]
    .rubiconproject.com [ C:\USERS\HELENA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\JU292VOK.DEFAULT-1438795000345\COOKIES.SQLITE ]
    .rubiconproject.com [ C:\USERS\HELENA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\JU292VOK.DEFAULT-1438795000345\COOKIES.SQLITE ]
    .rubiconproject.com [ C:\USERS\HELENA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\JU292VOK.DEFAULT-1438795000345\COOKIES.SQLITE ]
    .rubiconproject.com [ C:\USERS\HELENA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\JU292VOK.DEFAULT-1438795000345\COOKIES.SQLITE ]
    .rubiconproject.com [ C:\USERS\HELENA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\JU292VOK.DEFAULT-1438795000345\COOKIES.SQLITE ]
    .rubiconproject.com [ C:\USERS\HELENA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\JU292VOK.DEFAULT-1438795000345\COOKIES.SQLITE ]
    .rubiconproject.com [ C:\USERS\HELENA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\JU292VOK.DEFAULT-1438795000345\COOKIES.SQLITE ]
    .rubiconproject.com [ C:\USERS\HELENA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\JU292VOK.DEFAULT-1438795000345\COOKIES.SQLITE ]
    .rubiconproject.com [ C:\USERS\HELENA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\JU292VOK.DEFAULT-1438795000345\COOKIES.SQLITE ]
    .rubiconproject.com [ C:\USERS\HELENA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\JU292VOK.DEFAULT-1438795000345\COOKIES.SQLITE ]
    .rubiconproject.com [ C:\USERS\HELENA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\JU292VOK.DEFAULT-1438795000345\COOKIES.SQLITE ]
    .rubiconproject.com [ C:\USERS\HELENA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\JU292VOK.DEFAULT-1438795000345\COOKIES.SQLITE ]
    .rubiconproject.com [ C:\USERS\HELENA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\JU292VOK.DEFAULT-1438795000345\COOKIES.SQLITE ]
    .rubiconproject.com [ C:\USERS\HELENA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\JU292VOK.DEFAULT-1438795000345\COOKIES.SQLITE ]
    .rubiconproject.com [ C:\USERS\HELENA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\JU292VOK.DEFAULT-1438795000345\COOKIES.SQLITE ]
    .rubiconproject.com [ C:\USERS\HELENA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\JU292VOK.DEFAULT-1438795000345\COOKIES.SQLITE ]
    .rubiconproject.com [ C:\USERS\HELENA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\JU292VOK.DEFAULT-1438795000345\COOKIES.SQLITE ]
    .rubiconproject.com [ C:\USERS\HELENA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\JU292VOK.DEFAULT-1438795000345\COOKIES.SQLITE ]
    .rubiconproject.com [ C:\USERS\HELENA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\JU292VOK.DEFAULT-1438795000345\COOKIES.SQLITE ]
    .rubiconproject.com [ C:\USERS\HELENA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\JU292VOK.DEFAULT-1438795000345\COOKIES.SQLITE ]
    .rubiconproject.com [ C:\USERS\HELENA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\JU292VOK.DEFAULT-1438795000345\COOKIES.SQLITE ]
    .rubiconproject.com [ C:\USERS\HELENA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\JU292VOK.DEFAULT-1438795000345\COOKIES.SQLITE ]
    .rubiconproject.com [ C:\USERS\HELENA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\JU292VOK.DEFAULT-1438795000345\COOKIES.SQLITE ]
    .rubiconproject.com [ C:\USERS\HELENA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\JU292VOK.DEFAULT-1438795000345\COOKIES.SQLITE ]
    .rubiconproject.com [ C:\USERS\HELENA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\JU292VOK.DEFAULT-1438795000345\COOKIES.SQLITE ]
    .rubiconproject.com [ C:\USERS\HELENA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\JU292VOK.DEFAULT-1438795000345\COOKIES.SQLITE ]
    .rubiconproject.com [ C:\USERS\HELENA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\JU292VOK.DEFAULT-1438795000345\COOKIES.SQLITE ]
    tap2-cdn.rubiconproject.com [ C:\USERS\HELENA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\JU292VOK.DEFAULT-1438795000345\COOKIES.SQLITE ]
    .provenpixel.com [ C:\USERS\HELENA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\JU292VOK.DEFAULT-1438795000345\COOKIES.SQLITE ]
    .gwallet.com [ C:\USERS\HELENA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\JU292VOK.DEFAULT-1438795000345\COOKIES.SQLITE ]
    .gwallet.com [ C:\USERS\HELENA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\JU292VOK.DEFAULT-1438795000345\COOKIES.SQLITE ]
    .gwallet.com [ C:\USERS\HELENA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\JU292VOK.DEFAULT-1438795000345\COOKIES.SQLITE ]
    .rubiconproject.com [ C:\USERS\HELENA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\JU292VOK.DEFAULT-1438795000345\COOKIES.SQLITE ]
    .rubiconproject.com [ C:\USERS\HELENA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\JU292VOK.DEFAULT-1438795000345\COOKIES.SQLITE ]
    .rubiconproject.com [ C:\USERS\HELENA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\JU292VOK.DEFAULT-1438795000345\COOKIES.SQLITE ]
    .rubiconproject.com [ C:\USERS\HELENA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\JU292VOK.DEFAULT-1438795000345\COOKIES.SQLITE ]
    .turn.com [ C:\USERS\HELENA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\JU292VOK.DEFAULT-1438795000345\COOKIES.SQLITE ]
    .outbrain.com [ C:\USERS\HELENA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\JU292VOK.DEFAULT-1438795000345\COOKIES.SQLITE ]
    .rlcdn.com [ C:\USERS\HELENA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\JU292VOK.DEFAULT-1438795000345\COOKIES.SQLITE ]
    .owneriq.net [ C:\USERS\HELENA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\JU292VOK.DEFAULT-1438795000345\COOKIES.SQLITE ]
    .gssprt.jp [ C:\USERS\HELENA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\JU292VOK.DEFAULT-1438795000345\COOKIES.SQLITE ]
    .rubiconproject.com [ C:\USERS\HELENA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\JU292VOK.DEFAULT-1438795000345\COOKIES.SQLITE ]
    .owneriq.net [ C:\USERS\HELENA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\JU292VOK.DEFAULT-1438795000345\COOKIES.SQLITE ]
    .pixel.rubiconproject.com [ C:\USERS\HELENA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\JU292VOK.DEFAULT-1438795000345\COOKIES.SQLITE ]
    .turn.com [ C:\USERS\HELENA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\JU292VOK.DEFAULT-1438795000345\COOKIES.SQLITE ]
    .adbrn.com [ C:\USERS\HELENA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\JU292VOK.DEFAULT-1438795000345\COOKIES.SQLITE ]
    .adaptv.advertising.com [ C:\USERS\HELENA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\JU292VOK.DEFAULT-1438795000345\COOKIES.SQLITE ]
    .revsci.net [ C:\USERS\HELENA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\JU292VOK.DEFAULT-1438795000345\COOKIES.SQLITE ]
    .rlcdn.com [ C:\USERS\HELENA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\JU292VOK.DEFAULT-1438795000345\COOKIES.SQLITE ]
    .mediaplex.com [ C:\USERS\HELENA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\JU292VOK.DEFAULT-1438795000345\COOKIES.SQLITE ]
    .revsci.net [ C:\USERS\HELENA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\JU292VOK.DEFAULT-1438795000345\COOKIES.SQLITE ]
    .rfihub.com [ C:\USERS\HELENA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\JU292VOK.DEFAULT-1438795000345\COOKIES.SQLITE ]
    .rubiconproject.com [ C:\USERS\HELENA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\JU292VOK.DEFAULT-1438795000345\COOKIES.SQLITE ]
    .turn.com [ C:\USERS\HELENA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\JU292VOK.DEFAULT-1438795000345\COOKIES.SQLITE ]
    recs.richrelevance.com [ C:\USERS\HELENA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\JU292VOK.DEFAULT-1438795000345\COOKIES.SQLITE ]
    .hearstmagazines.112.2o7.net [ C:\USERS\HELENA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\JU292VOK.DEFAULT-1438795000345\COOKIES.SQLITE ]
    .smartadserver.com [ C:\USERS\HELENA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\JU292VOK.DEFAULT-1438795000345\COOKIES.SQLITE ]
    .smartadserver.com [ C:\USERS\HELENA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\JU292VOK.DEFAULT-1438795000345\COOKIES.SQLITE ]
    .listrakbi.com [ C:\USERS\HELENA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\JU292VOK.DEFAULT-1438795000345\COOKIES.SQLITE ]
    .rubiconproject.com [ C:\USERS\HELENA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\JU292VOK.DEFAULT-1438795000345\COOKIES.SQLITE ]
    .rubiconproject.com [ C:\USERS\HELENA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\JU292VOK.DEFAULT-1438795000345\COOKIES.SQLITE ]
    .rubiconproject.com [ C:\USERS\HELENA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\JU292VOK.DEFAULT-1438795000345\COOKIES.SQLITE ]
    .adnxs.com [ C:\USERS\HELENA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\JU292VOK.DEFAULT-1438795000345\COOKIES.SQLITE ]
    .media6degrees.com [ C:\USERS\HELENA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\JU292VOK.DEFAULT-1438795000345\COOKIES.SQLITE ]
    .owneriq.net [ C:\USERS\HELENA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\JU292VOK.DEFAULT-1438795000345\COOKIES.SQLITE ]
    .skimresources.com [ C:\USERS\HELENA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\JU292VOK.DEFAULT-1438795000345\COOKIES.SQLITE ]
    .skimresources.com [ C:\USERS\HELENA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\JU292VOK.DEFAULT-1438795000345\COOKIES.SQLITE ]
    .skimresources.com [ C:\USERS\HELENA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\JU292VOK.DEFAULT-1438795000345\COOKIES.SQLITE ]
    .cogocast.net [ C:\USERS\HELENA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\JU292VOK.DEFAULT-1438795000345\COOKIES.SQLITE ]
    .rfihub.com [ C:\USERS\HELENA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\JU292VOK.DEFAULT-1438795000345\COOKIES.SQLITE ]
    .owneriq.net [ C:\USERS\HELENA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\JU292VOK.DEFAULT-1438795000345\COOKIES.SQLITE ]
    .addthis.com [ C:\USERS\HELENA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\JU292VOK.DEFAULT-1438795000345\COOKIES.SQLITE ]
    dmp.springserve.com [ C:\USERS\HELENA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\JU292VOK.DEFAULT-1438795000345\COOKIES.SQLITE ]
    .sitescout.com [ C:\USERS\HELENA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\JU292VOK.DEFAULT-1438795000345\COOKIES.SQLITE ]
    .sundaysky.com [ C:\USERS\HELENA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\JU292VOK.DEFAULT-1438795000345\COOKIES.SQLITE ]
    .contextweb.com [ C:\USERS\HELENA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\JU292VOK.DEFAULT-1438795000345\COOKIES.SQLITE ]
    .contextweb.com [ C:\USERS\HELENA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\JU292VOK.DEFAULT-1438795000345\COOKIES.SQLITE ]
    .securedvisit.com [ C:\USERS\HELENA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\JU292VOK.DEFAULT-1438795000345\COOKIES.SQLITE ]
    .securedvisit.com [ C:\USERS\HELENA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\JU292VOK.DEFAULT-1438795000345\COOKIES.SQLITE ]
    .mediaplex.com [ C:\USERS\HELENA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\JU292VOK.DEFAULT-1438795000345\COOKIES.SQLITE ]
    .wtp101.com [ C:\USERS\HELENA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\JU292VOK.DEFAULT-1438795000345\COOKIES.SQLITE ]
    .wtp101.com [ C:\USERS\HELENA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\JU292VOK.DEFAULT-1438795000345\COOKIES.SQLITE ]
    .taboola.com [ C:\USERS\HELENA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\JU292VOK.DEFAULT-1438795000345\COOKIES.SQLITE ]
    .taboola.com [ C:\USERS\HELENA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\JU292VOK.DEFAULT-1438795000345\COOKIES.SQLITE ]
    trc.taboola.com [ C:\USERS\HELENA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\JU292VOK.DEFAULT-1438795000345\COOKIES.SQLITE ]
    trc.taboola.com [ C:\USERS\HELENA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\JU292VOK.DEFAULT-1438795000345\COOKIES.SQLITE ]
    trc.taboola.com [ C:\USERS\HELENA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\JU292VOK.DEFAULT-1438795000345\COOKIES.SQLITE ]
    .taboola.com [ C:\USERS\HELENA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\JU292VOK.DEFAULT-1438795000345\COOKIES.SQLITE ]
    trc.taboola.com [ C:\USERS\HELENA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\JU292VOK.DEFAULT-1438795000345\COOKIES.SQLITE ]
    .taboola.com [ C:\USERS\HELENA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\JU292VOK.DEFAULT-1438795000345\COOKIES.SQLITE ]
    .tellapart.com [ C:\USERS\HELENA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\JU292VOK.DEFAULT-1438795000345\COOKIES.SQLITE ]
    .owneriq.net [ C:\USERS\HELENA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\JU292VOK.DEFAULT-1438795000345\COOKIES.SQLITE ]
    .tdameritrade.demdex.net [ C:\USERS\HELENA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\JU292VOK.DEFAULT-1438795000345\COOKIES.SQLITE ]
    .tidaltv.com [ C:\USERS\HELENA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\JU292VOK.DEFAULT-1438795000345\COOKIES.SQLITE ]
    .3lift.com [ C:\USERS\HELENA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\JU292VOK.DEFAULT-1438795000345\COOKIES.SQLITE ]
    dmp.truoptik.com [ C:\USERS\HELENA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\JU292VOK.DEFAULT-1438795000345\COOKIES.SQLITE ]
    dmp.truoptik.com [ C:\USERS\HELENA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\JU292VOK.DEFAULT-1438795000345\COOKIES.SQLITE ]
    dmp.truoptik.com [ C:\USERS\HELENA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\JU292VOK.DEFAULT-1438795000345\COOKIES.SQLITE ]
    .genieessp.jp [ C:\USERS\HELENA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\JU292VOK.DEFAULT-1438795000345\COOKIES.SQLITE ]
    .genieesspv.jp [ C:\USERS\HELENA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\JU292VOK.DEFAULT-1438795000345\COOKIES.SQLITE ]
    .gssprt.jp [ C:\USERS\HELENA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\JU292VOK.DEFAULT-1438795000345\COOKIES.SQLITE ]
    .href.asia [ C:\USERS\HELENA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\JU292VOK.DEFAULT-1438795000345\COOKIES.SQLITE ]
    .owneriq.net [ C:\USERS\HELENA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\JU292VOK.DEFAULT-1438795000345\COOKIES.SQLITE ]
    .lijit.com [ C:\USERS\HELENA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\JU292VOK.DEFAULT-1438795000345\COOKIES.SQLITE ]
    .teads.tv [ C:\USERS\HELENA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\JU292VOK.DEFAULT-1438795000345\COOKIES.SQLITE ]
    .ih.adscale.de [ C:\USERS\HELENA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\JU292VOK.DEFAULT-1438795000345\COOKIES.SQLITE ]
    .254a.com [ C:\USERS\HELENA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\JU292VOK.DEFAULT-1438795000345\COOKIES.SQLITE ]
    .adbrn.com [ C:\USERS\HELENA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\JU292VOK.DEFAULT-1438795000345\COOKIES.SQLITE ]
    .ads.kiosked.com [ C:\USERS\HELENA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\JU292VOK.DEFAULT-1438795000345\COOKIES.SQLITE ]
    .bidswitch.net [ C:\USERS\HELENA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\JU292VOK.DEFAULT-1438795000345\COOKIES.SQLITE ]
    .company-target.com [ C:\USERS\HELENA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\JU292VOK.DEFAULT-1438795000345\COOKIES.SQLITE ]
    .d.liadm.com [ C:\USERS\HELENA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\JU292VOK.DEFAULT-1438795000345\COOKIES.SQLITE ]
    .wtp101.com [ C:\USERS\HELENA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\JU292VOK.DEFAULT-1438795000345\COOKIES.SQLITE ]
    ad.360yield.com [ C:\USERS\HELENA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\JU292VOK.DEFAULT-1438795000345\COOKIES.SQLITE ]
    ads.creative-serving.com [ C:\USERS\HELENA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\JU292VOK.DEFAULT-1438795000345\COOKIES.SQLITE ]
    ads.p161.net [ C:\USERS\HELENA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\JU292VOK.DEFAULT-1438795000345\COOKIES.SQLITE ]
    t.brand-server.com [ C:\USERS\HELENA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\JU292VOK.DEFAULT-1438795000345\COOKIES.SQLITE ]
    .tag.clrstm.com [ C:\USERS\HELENA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\JU292VOK.DEFAULT-1438795000345\COOKIES.SQLITE ]
    .tremorhub.com [ C:\USERS\HELENA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\JU292VOK.DEFAULT-1438795000345\COOKIES.SQLITE ]
    .tremorhub.com [ C:\USERS\HELENA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\JU292VOK.DEFAULT-1438795000345\COOKIES.SQLITE ]
    .tremorhub.com [ C:\USERS\HELENA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\JU292VOK.DEFAULT-1438795000345\COOKIES.SQLITE ]
    .agkn.com [ C:\USERS\HELENA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\JU292VOK.DEFAULT-1438795000345\COOKIES.SQLITE ]
    .erne.co [ C:\USERS\HELENA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\JU292VOK.DEFAULT-1438795000345\COOKIES.SQLITE ]
    .rfihub.com [ C:\USERS\HELENA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\JU292VOK.DEFAULT-1438795000345\COOKIES.SQLITE ]
    .serving-sys.com [ C:\USERS\HELENA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\JU292VOK.DEFAULT-1438795000345\COOKIES.SQLITE ]
    .mediaforge.com [ C:\USERS\HELENA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\JU292VOK.DEFAULT-1438795000345\COOKIES.SQLITE ]
    .rfihub.com [ C:\USERS\HELENA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\JU292VOK.DEFAULT-1438795000345\COOKIES.SQLITE ]
    recs.richrelevance.com [ C:\USERS\HELENA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\JU292VOK.DEFAULT-1438795000345\COOKIES.SQLITE ]
    .criteo.com [ C:\USERS\HELENA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\JU292VOK.DEFAULT-1438795000345\COOKIES.SQLITE ]
    .udmserve.net [ C:\USERS\HELENA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\JU292VOK.DEFAULT-1438795000345\COOKIES.SQLITE ]
    .udmserve.net [ C:\USERS\HELENA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\JU292VOK.DEFAULT-1438795000345\COOKIES.SQLITE ]
    .legolas-media.com [ C:\USERS\HELENA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\JU292VOK.DEFAULT-1438795000345\COOKIES.SQLITE ]
    .legolas-media.com [ C:\USERS\HELENA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\JU292VOK.DEFAULT-1438795000345\COOKIES.SQLITE ]
    .addthis.com [ C:\USERS\HELENA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\JU292VOK.DEFAULT-1438795000345\COOKIES.SQLITE ]
    .adform.net [ C:\USERS\HELENA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\JU292VOK.DEFAULT-1438795000345\COOKIES.SQLITE ]
    .audienceiq.com [ C:\USERS\HELENA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\JU292VOK.DEFAULT-1438795000345\COOKIES.SQLITE ]
    .criteo.com [ C:\USERS\HELENA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\JU292VOK.DEFAULT-1438795000345\COOKIES.SQLITE ]
    .komoona.com [ C:\USERS\HELENA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\JU292VOK.DEFAULT-1438795000345\COOKIES.SQLITE ]
    .rtbidder.net [ C:\USERS\HELENA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\JU292VOK.DEFAULT-1438795000345\COOKIES.SQLITE ]
    .scanscout.com [ C:\USERS\HELENA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\JU292VOK.DEFAULT-1438795000345\COOKIES.SQLITE ]
    .simpli.fi [ C:\USERS\HELENA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\JU292VOK.DEFAULT-1438795000345\COOKIES.SQLITE ]
    .turn.com [ C:\USERS\HELENA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\JU292VOK.DEFAULT-1438795000345\COOKIES.SQLITE ]
    .tynt.com [ C:\USERS\HELENA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\JU292VOK.DEFAULT-1438795000345\COOKIES.SQLITE ]
    .univide.com [ C:\USERS\HELENA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\JU292VOK.DEFAULT-1438795000345\COOKIES.SQLITE ]
    .visiblemeasures.com [ C:\USERS\HELENA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\JU292VOK.DEFAULT-1438795000345\COOKIES.SQLITE ]
    ads.stickyadstv.com [ C:\USERS\HELENA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\JU292VOK.DEFAULT-1438795000345\COOKIES.SQLITE ]
    ads.stickyadstv.com [ C:\USERS\HELENA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\JU292VOK.DEFAULT-1438795000345\COOKIES.SQLITE ]
    ads.stickyadstv.com [ C:\USERS\HELENA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\JU292VOK.DEFAULT-1438795000345\COOKIES.SQLITE ]
    ads.stickyadstv.com [ C:\USERS\HELENA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\JU292VOK.DEFAULT-1438795000345\COOKIES.SQLITE ]
    ads.stickyadstv.com [ C:\USERS\HELENA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\JU292VOK.DEFAULT-1438795000345\COOKIES.SQLITE ]
    ads.stickyadstv.com [ C:\USERS\HELENA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\JU292VOK.DEFAULT-1438795000345\COOKIES.SQLITE ]
    ads.stickyadstv.com [ C:\USERS\HELENA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\JU292VOK.DEFAULT-1438795000345\COOKIES.SQLITE ]
    ads.stickyadstv.com [ C:\USERS\HELENA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\JU292VOK.DEFAULT-1438795000345\COOKIES.SQLITE ]
    .mediaforge.com [ C:\USERS\HELENA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\JU292VOK.DEFAULT-1438795000345\COOKIES.SQLITE ]
    .altitude-arena.com [ C:\USERS\HELENA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\JU292VOK.DEFAULT-1438795000345\COOKIES.SQLITE ]
    ad.360yield.com [ C:\USERS\HELENA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\JU292VOK.DEFAULT-1438795000345\COOKIES.SQLITE ]
    .ads.kiosked.com [ C:\USERS\HELENA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\JU292VOK.DEFAULT-1438795000345\COOKIES.SQLITE ]
    ad.360yield.com [ C:\USERS\HELENA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\JU292VOK.DEFAULT-1438795000345\COOKIES.SQLITE ]
    .adaptv.advertising.com [ C:\USERS\HELENA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\JU292VOK.DEFAULT-1438795000345\COOKIES.SQLITE ]
    s7.addthis.com [ C:\USERS\HELENA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\JU292VOK.DEFAULT-1438795000345\COOKIES.SQLITE ]
    .mookie1.com [ C:\USERS\HELENA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\JU292VOK.DEFAULT-1438795000345\COOKIES.SQLITE ]
    .adaptv.advertising.com [ C:\USERS\HELENA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\JU292VOK.DEFAULT-1438795000345\COOKIES.SQLITE ]
    googleads.g.doubleclick.net [ C:\USERS\HELENA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\JU292VOK.DEFAULT-1438795000345\COOKIES.SQLITE ]
    .adscale.de [ C:\USERS\HELENA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\JU292VOK.DEFAULT-1438795000345\COOKIES.SQLITE ]
    .agkn.com [ C:\USERS\HELENA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\JU292VOK.DEFAULT-1438795000345\COOKIES.SQLITE ]
    .angsrvr.com [ C:\USERS\HELENA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\JU292VOK.DEFAULT-1438795000345\COOKIES.SQLITE ]
    .mathtag.com [ C:\USERS\HELENA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\JU292VOK.DEFAULT-1438795000345\COOKIES.SQLITE ]
    .sxp.smartclip.net [ C:\USERS\HELENA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\JU292VOK.DEFAULT-1438795000345\COOKIES.SQLITE ]
    dmp.springserve.com [ C:\USERS\HELENA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\JU292VOK.DEFAULT-1438795000345\COOKIES.SQLITE ]
    .adnxs.com [ C:\USERS\HELENA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\JU292VOK.DEFAULT-1438795000345\COOKIES.SQLITE ]
    .mathtag.com [ C:\USERS\HELENA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\JU292VOK.DEFAULT-1438795000345\COOKIES.SQLITE ]
    .addthis.com [ C:\USERS\HELENA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\JU292VOK.DEFAULT-1438795000345\COOKIES.SQLITE ]
    tracking.tapinfluence.com [ C:\USERS\HELENA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\JU292VOK.DEFAULT-1438795000345\COOKIES.SQLITE ]
    .sekindo.com [ C:\USERS\HELENA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\JU292VOK.DEFAULT-1438795000345\COOKIES.SQLITE ]
    .sekindo.com [ C:\USERS\HELENA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\JU292VOK.DEFAULT-1438795000345\COOKIES.SQLITE ]
    .sekindo.com [ C:\USERS\HELENA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\JU292VOK.DEFAULT-1438795000345\COOKIES.SQLITE ]
    .addthis.com [ C:\USERS\HELENA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\JU292VOK.DEFAULT-1438795000345\COOKIES.SQLITE ]
    .viglink.com [ C:\USERS\HELENA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\JU292VOK.DEFAULT-1438795000345\COOKIES.SQLITE ]
    .admaym.com [ C:\USERS\HELENA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\JU292VOK.DEFAULT-1438795000345\COOKIES.SQLITE ]
    .atemda.com [ C:\USERS\HELENA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\JU292VOK.DEFAULT-1438795000345\COOKIES.SQLITE ]
    .rubiconproject.com [ C:\USERS\HELENA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\JU292VOK.DEFAULT-1438795000345\COOKIES.SQLITE ]
    .rubiconproject.com [ C:\USERS\HELENA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\JU292VOK.DEFAULT-1438795000345\COOKIES.SQLITE ]
    .rubiconproject.com [ C:\USERS\HELENA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\JU292VOK.DEFAULT-1438795000345\COOKIES.SQLITE ]
    .media.net [ C:\USERS\HELENA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\JU292VOK.DEFAULT-1438795000345\COOKIES.SQLITE ]
    .vivaki.demdex.net [ C:\USERS\HELENA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\JU292VOK.DEFAULT-1438795000345\COOKIES.SQLITE ]
    .track.empire-tracking.com [ C:\USERS\HELENA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\JU292VOK.DEFAULT-1438795000345\COOKIES.SQLITE ]
    .track.empire-tracking.com [ C:\USERS\HELENA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\JU292VOK.DEFAULT-1438795000345\COOKIES.SQLITE ]
    .virool.com [ C:\USERS\HELENA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\JU292VOK.DEFAULT-1438795000345\COOKIES.SQLITE ]
    .gumgum.com [ C:\USERS\HELENA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\JU292VOK.DEFAULT-1438795000345\COOKIES.SQLITE ]
    .w55c.net [ C:\USERS\HELENA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\JU292VOK.DEFAULT-1438795000345\COOKIES.SQLITE ]
    .yume.com [ C:\USERS\HELENA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\JU292VOK.DEFAULT-1438795000345\COOKIES.SQLITE ]
    .yashi.com [ C:\USERS\HELENA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\JU292VOK.DEFAULT-1438795000345\COOKIES.SQLITE ]
    .perfectmarket.com [ C:\USERS\HELENA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\JU292VOK.DEFAULT-1438795000345\COOKIES.SQLITE ]
    .zemanta.com [ C:\USERS\HELENA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\JU292VOK.DEFAULT-1438795000345\COOKIES.SQLITE ]

============
 End of Log
============
 


  • 0

#12
zep516

zep516

    Trusted Helper

  • Malware Removal
  • 8,093 posts
Tracking cookies from navigating the Internet. Not a threat.

While you're here I'd like to run combofix just to look deeper at things. I'm calling it a nite and will look at the log in am.

You can download Combofix from one of these links. I want you to save it to the desktop and run it from there.1. Close any open browsers or any other programs that are open.
2. Close/disable all anti virus and anti malware programs so they do not interfere with the running of ComboFix.

Double click on combofix.exe & follow the prompts.
When finished, it will produce a report for you.

Note 1: Do not mouseclick combofix's window while it's running. That may cause it to stall

Note 2: If you receive an error "Illegal operation attempted on a registry key that has been marked for deletion." Please restart the computer



Please post the Log from Combofix
  • 0

#13
Webslinger64

Webslinger64

    Member

  • Topic Starter
  • Member
  • PipPipPip
  • 567 posts

Here you go...

 

ComboFix 16-03-01.01 - Helena 03/05/2016   7:24.1.4 - x64
Microsoft Windows 7 Home Premium   6.1.7601.1.1252.1.1033.18.7857.5908 [GMT -7:00]
Running from: c:\users\Helena\Downloads\ComboFix.exe
AV: avast! Antivirus *Disabled/Updated* {17AD7D40-BA12-9C46-7131-94903A54AD8B}
FW: avast! Antivirus *Disabled* {2F96FC65-F07D-9D1E-5A6E-3DA5C487EAF0}
SP: avast! Antivirus *Disabled/Updated* {ACCC9CA4-9C28-93C8-4B81-AFE241D3E736}
SP: Windows Defender *Enabled/Updated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
 * Created a new restore point
.
.
(((((((((((((((((((((((((   Files Created from 2016-02-05 to 2016-03-05  )))))))))))))))))))))))))))))))
.
.
2016-03-05 14:27 . 2016-03-05 14:27    --------    d-----w-    c:\users\Default\AppData\Local\temp
2016-03-04 14:58 . 2016-02-19 01:53    11249080    ----a-w-    c:\programdata\Microsoft\Windows Defender\Definition Updates\{AB5DF90F-F4BB-4610-8067-B03D7FE75476}\mpengine.dll
2016-03-03 22:53 . 2016-03-03 22:55    --------    d-----w-    C:\AdwCleaner
2016-03-03 00:52 . 2016-02-12 04:55    398152    ----a-w-    c:\windows\system32\aswBoot.exe
2016-03-02 22:21 . 2016-03-03 22:46    --------    d-----w-    C:\FRST
2016-02-28 00:27 . 2016-02-28 00:41    --------    d-----w-    c:\program files (x86)\Auslogics
2016-02-27 23:55 . 2016-02-28 00:03    --------    d-----w-    c:\programdata\Kaspersky Lab Setup Files
2016-02-12 04:55 . 2016-02-12 04:55    37144    ----a-w-    c:\windows\system32\drivers\aswKbd.sys
2016-02-12 04:55 . 2016-02-12 04:55    52184    ----a-w-    c:\windows\avastSS.scr
2016-02-12 04:55 . 2016-02-12 04:55    478128    ----a-w-    c:\windows\system32\drivers\aswNdisFlt.sys
2016-02-10 13:57 . 2016-01-07 17:42    141312    ----a-w-    c:\windows\system32\drivers\mrxdav.sys
2016-02-10 13:56 . 2016-01-22 06:27    5573056    ----a-w-    c:\windows\system32\ntoskrnl.exe
.
.
.
((((((((((((((((((((((((((((((((((((((((   Find3M Report   ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2016-03-05 04:19 . 2014-08-30 02:51    192216    ----a-w-    c:\windows\system32\drivers\MBAMSwissArmy.sys
2016-02-23 22:12 . 2014-01-17 21:50    463744    ----a-w-    c:\windows\system32\drivers\aswSP.sys
2016-02-12 04:55 . 2014-01-17 21:50    287016    ----a-w-    c:\windows\system32\drivers\aswVmm.sys
2016-02-12 04:55 . 2014-04-27 20:37    37656    ----a-w-    c:\windows\system32\drivers\aswHwid.sys
2016-02-12 04:55 . 2014-01-17 21:50    165344    ----a-w-    c:\windows\system32\drivers\aswStm.sys
2016-02-12 04:55 . 2014-01-17 21:50    74544    ----a-w-    c:\windows\system32\drivers\aswRvrt.sys
2016-02-12 04:55 . 2014-01-17 21:50    107792    ----a-w-    c:\windows\system32\drivers\aswMonFlt.sys
2016-02-12 04:55 . 2014-01-17 21:50    103064    ----a-w-    c:\windows\system32\drivers\aswRdr2.sys
2016-02-12 04:55 . 2014-01-17 21:50    1065720    ----a-w-    c:\windows\system32\drivers\aswSnx.sys
2016-02-11 10:13 . 2014-01-18 17:51    146614896    ----a-w-    c:\windows\system32\MRT.exe
2016-02-10 10:00 . 2014-01-17 22:00    796864    ----a-w-    c:\windows\SysWow64\FlashPlayerApp.exe
2016-02-10 10:00 . 2014-01-17 22:00    142528    ----a-w-    c:\windows\SysWow64\FlashPlayerCPLApp.cpl
2016-02-10 10:00 . 2016-01-20 04:19    8817344    ----a-w-    c:\windows\SysWow64\FlashPlayerInstaller.exe
2016-01-22 05:59 . 2016-02-10 13:56    44032    ----a-w-    c:\windows\apppatch\acwow64.dll
2015-12-10 05:39 . 2015-12-10 05:39    1070232    ----a-w-    c:\windows\SysWow64\MSCOMCTL.OCX
2015-12-08 21:54 . 2016-01-12 20:59    1620992    ----a-w-    c:\windows\SysWow64\WMVDECOD.DLL
2015-12-08 21:54 . 2016-01-12 20:59    902144    ----a-w-    c:\windows\SysWow64\WMADMOD.DLL
2015-12-08 21:54 . 2016-01-12 20:59    815616    ----a-w-    c:\windows\SysWow64\WMADMOE.DLL
2015-12-08 21:54 . 2016-01-12 20:59    739328    ----a-w-    c:\windows\SysWow64\WMSPDMOD.DLL
2015-12-08 21:54 . 2016-01-12 20:59    541184    ----a-w-    c:\windows\SysWow64\WMVSDECD.DLL
2015-12-08 21:54 . 2016-01-12 20:59    740352    ----a-w-    c:\windows\SysWow64\wmpmde.dll
2015-12-08 21:54 . 2016-01-12 20:59    665088    ----a-w-    c:\windows\SysWow64\WMVXENCD.DLL
2015-12-08 21:54 . 2016-01-12 20:59    358400    ----a-w-    c:\windows\SysWow64\WMVSENCD.DLL
2015-12-08 21:54 . 2016-01-12 20:59    1568768    ----a-w-    c:\windows\SysWow64\WMVENCOD.DLL
2015-12-08 21:54 . 2016-01-12 20:59    1325056    ----a-w-    c:\windows\SysWow64\WMSPDMOE.DLL
2015-12-08 21:54 . 2016-01-12 20:59    2285056    ----a-w-    c:\windows\SysWow64\msmpeg2vdec.dll
2015-12-08 21:54 . 2016-01-12 20:59    154112    ----a-w-    c:\windows\SysWow64\VIDRESZR.DLL
2015-12-08 21:53 . 2016-01-12 20:59    206848    ----a-w-    c:\windows\SysWow64\RESAMPLEDMO.DLL
2015-12-08 21:53 . 2016-01-12 20:59    519680    ----a-w-    c:\windows\SysWow64\qdvd.dll
2015-12-08 21:53 . 2016-01-12 20:59    206848    ----a-w-    c:\windows\SysWow64\qasf.dll
2015-12-08 21:53 . 2016-01-12 20:59    1329664    ----a-w-    c:\windows\SysWow64\quartz.dll
2015-12-08 21:53 . 2016-01-12 20:59    509952    ----a-w-    c:\windows\SysWow64\qedit.dll
2015-12-08 21:53 . 2016-01-12 20:59    970240    ----a-w-    c:\windows\SysWow64\msmpeg2adec.dll
2015-12-08 21:53 . 2016-01-12 20:59    829952    ----a-w-    c:\windows\SysWow64\MSMPEG2ENC.DLL
2015-12-08 21:53 . 2016-01-12 20:59    241152    ----a-w-    c:\windows\SysWow64\MPG4DECD.DLL
2015-12-08 21:53 . 2016-01-12 20:59    241152    ----a-w-    c:\windows\SysWow64\MP43DECD.DLL
2015-12-08 21:53 . 2016-01-12 20:59    79872    ----a-w-    c:\windows\SysWow64\MP3DMOD.DLL
2015-12-08 21:53 . 2016-01-12 20:59    415744    ----a-w-    c:\windows\SysWow64\MP4SDECD.DLL
2015-12-08 21:53 . 2016-01-12 20:59    3209728    ----a-w-    c:\windows\SysWow64\mf.dll
2015-12-08 21:53 . 2016-01-12 20:59    609280    ----a-w-    c:\windows\SysWow64\MFWMAAEC.DLL
2015-12-08 21:53 . 2016-01-12 20:59    354816    ----a-w-    c:\windows\SysWow64\mfplat.dll
2015-12-08 21:53 . 2016-01-12 20:59    53248    ----a-w-    c:\windows\SysWow64\mfvdsp.dll
2015-12-08 21:53 . 2016-01-12 20:59    4608    ----a-w-    c:\windows\SysWow64\ksuser.dll
2015-12-08 21:53 . 2016-01-12 20:59    103424    ----a-w-    c:\windows\SysWow64\mfps.dll
2015-12-08 21:53 . 2016-01-12 20:59    489984    ----a-w-    c:\windows\SysWow64\evr.dll
2015-12-08 21:53 . 2016-01-12 20:59    67584    ----a-w-    c:\windows\SysWow64\devenum.dll
2015-12-08 21:53 . 2016-01-12 20:59    153600    ----a-w-    c:\windows\SysWow64\COLORCNV.DLL
2015-12-08 21:53 . 2016-01-12 20:59    50176    ----a-w-    c:\windows\SysWow64\rrinstaller.exe
2015-12-08 21:53 . 2016-01-12 20:59    23040    ----a-w-    c:\windows\SysWow64\mfpmp.exe
2015-12-08 21:53 . 2016-01-12 20:59    193536    ----a-w-    c:\windows\SysWow64\ksproxy.ax
2015-12-08 21:52 . 2016-01-12 20:58    312320    ----a-w-    c:\windows\SysWow64\gdi32.dll
2015-12-08 21:50 . 2016-01-12 20:59    2048    ----a-w-    c:\windows\SysWow64\mferror.dll
2015-12-08 19:07 . 2016-01-12 20:59    1888768    ----a-w-    c:\windows\system32\WMVDECOD.DLL
2015-12-08 19:07 . 2016-01-12 20:59    1232896    ----a-w-    c:\windows\system32\WMADMOD.DLL
2015-12-08 19:07 . 2016-01-12 20:59    978944    ----a-w-    c:\windows\system32\WMSPDMOD.DLL
2015-12-08 19:07 . 2016-01-12 20:59    666112    ----a-w-    c:\windows\system32\WMVSDECD.DLL
2015-12-08 19:07 . 2016-01-12 20:59    1153024    ----a-w-    c:\windows\system32\WMADMOE.DLL
2015-12-08 19:07 . 2016-01-12 20:59    1026048    ----a-w-    c:\windows\system32\wmpmde.dll
2015-12-08 19:07 . 2016-01-12 20:59    642048    ----a-w-    c:\windows\system32\WMVXENCD.DLL
2015-12-08 19:07 . 2016-01-12 20:59    447488    ----a-w-    c:\windows\system32\WMVSENCD.DLL
2015-12-08 19:07 . 2016-01-12 20:59    1955328    ----a-w-    c:\windows\system32\WMVENCOD.DLL
2015-12-08 19:07 . 2016-01-12 20:59    1575424    ----a-w-    c:\windows\system32\WMSPDMOE.DLL
2015-12-08 19:07 . 2009-07-14 00:22    1393152    ----a-w-    c:\windows\system32\WMALFXGFXDSP.dll
2015-12-08 19:07 . 2016-01-12 20:59    2777088    ----a-w-    c:\windows\system32\msmpeg2vdec.dll
2015-12-08 19:07 . 2016-01-12 20:59    292352    ----a-w-    c:\windows\system32\VIDRESZR.DLL
2015-12-08 19:07 . 2016-01-12 20:59    378880    ----a-w-    c:\windows\system32\SysFxUI.dll
2015-12-08 19:07 . 2016-01-12 20:59    225792    ----a-w-    c:\windows\system32\RESAMPLEDMO.DLL
2015-12-08 19:07 . 2016-01-12 20:59    1573888    ----a-w-    c:\windows\system32\quartz.dll
2015-12-08 19:07 . 2016-01-12 20:59    371712    ----a-w-    c:\windows\system32\qdvd.dll
2015-12-08 19:07 . 2016-01-12 20:59    254464    ----a-w-    c:\windows\system32\qasf.dll
2015-12-08 19:07 . 2016-01-12 20:59    624640    ----a-w-    c:\windows\system32\qedit.dll
2015-12-08 19:07 . 2016-01-12 20:59    1307136    ----a-w-    c:\windows\system32\msmpeg2adec.dll
2015-12-08 19:07 . 2016-01-12 20:59    1160192    ----a-w-    c:\windows\system32\MSMPEG2ENC.DLL
2015-12-08 19:07 . 2016-01-12 20:59    4121600    ----a-w-    c:\windows\system32\mf.dll
2015-12-08 19:07 . 2016-01-12 20:59    1010688    ----a-w-    c:\windows\system32\mcmde.dll
2015-12-08 19:07 . 2016-01-12 20:59    70144    ----a-w-    c:\windows\system32\mfvdsp.dll
2015-12-08 19:07 . 2016-01-12 20:59    653824    ----a-w-    c:\windows\system32\MP4SDECD.DLL
2015-12-08 19:07 . 2016-01-12 20:59    484864    ----a-w-    c:\windows\system32\MFWMAAEC.DLL
2015-12-08 19:07 . 2016-01-12 20:59    432128    ----a-w-    c:\windows\system32\mfplat.dll
2015-12-08 19:07 . 2016-01-12 20:59    224768    ----a-w-    c:\windows\system32\MPG4DECD.DLL
2015-12-08 19:07 . 2016-01-12 20:59    223744    ----a-w-    c:\windows\system32\MP43DECD.DLL
2015-12-08 19:07 . 2016-01-12 20:59    100864    ----a-w-    c:\windows\system32\MP3DMOD.DLL
2015-12-08 19:07 . 2016-01-12 20:59    206848    ----a-w-    c:\windows\system32\mfps.dll
2015-12-08 19:07 . 2016-01-12 20:59    5120    ----a-w-    c:\windows\system32\ksuser.dll
2015-12-08 19:07 . 2016-01-12 20:59    632320    ----a-w-    c:\windows\system32\evr.dll
2015-12-08 19:07 . 2016-01-12 20:58    405504    ----a-w-    c:\windows\system32\gdi32.dll
2015-12-08 19:07 . 2016-01-12 20:59    76288    ----a-w-    c:\windows\system32\devenum.dll
2015-12-08 19:07 . 2016-01-12 20:59    189952    ----a-w-    c:\windows\system32\COLORCNV.DLL
2015-12-08 19:07 . 2016-01-12 20:59    55808    ----a-w-    c:\windows\system32\rrinstaller.exe
2015-12-08 19:06 . 2016-01-12 20:59    24576    ----a-w-    c:\windows\system32\mfpmp.exe
2015-12-08 19:06 . 2016-01-12 20:59    250880    ----a-w-    c:\windows\system32\ksproxy.ax
2015-12-08 19:04 . 2016-01-12 20:59    2048    ----a-w-    c:\windows\system32\mferror.dll
2015-12-08 18:54 . 2016-01-12 20:59    116736    ----a-w-    c:\windows\system32\drivers\drmk.sys
2015-12-08 18:12 . 2016-01-12 20:59    230400    ----a-w-    c:\windows\system32\drivers\portcls.sys
2015-12-08 18:11 . 2016-01-12 20:59    5632    ----a-w-    c:\windows\system32\drivers\drmkaud.sys
.
.
(((((((((((((((((((((((((((((((((((((   Reg Loading Points   ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
.
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"SUPERAntiSpyware"="c:\program files\SUPERAntiSpyware\SUPERAntiSpyware.exe" [2016-03-02 7943072]
"Power2GoExpress8"="c:\program files (x86)\CyberLink\Power2Go8\Power2GoExpress8.exe" [2012-08-14 1707632]
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Run]
"USB3MON"="c:\program files (x86)\Intel\Intel® USB 3.0 eXtensible Host Controller Driver\Application\iusb3mon.exe" [2013-04-11 292848]
"D-Link D-Link DWA-121"="c:\program files (x86)\D-Link\DWA-121 revA\AirNCFG.exe" [2013-03-20 1079600]
"AvastUI.exe"="c:\program files\AVAST Software\Avast\AvastUI.exe" [2016-02-15 7139768]
"CLMLServer_For_P2G8"="c:\program files (x86)\CyberLink\Power2Go8\CLMLSvc_P2G8.exe" [2012-06-08 111120]
"CLVirtualDrive"="c:\program files (x86)\CyberLink\Power2Go8\VirtualDrive.exe" [2012-08-14 491120]
"BCSSync"="c:\program files (x86)\Microsoft Office\Office14\BCSSync.exe" [2012-11-05 89184]
"SunJavaUpdateSched"="c:\program files (x86)\Common Files\Java\Java Update\jusched.exe" [2014-10-07 507776]
.
c:\users\Helena\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\
OneNote 2010 Screen Clipper and Launcher.lnk - c:\program files (x86)\Microsoft Office\Office14\ONENOTEM.EXE /tsr [2015-10-13 228552]
.
c:\programdata\Microsoft\Windows\Start Menu\Programs\Startup\
Killer Network Manager.lnk - c:\windows\Installer\{401FADAA-1C16-4721-9F02-19067E1A1CA8}\NetworkManager.exe_130C27D738F34C89BDDF21BCFD74B56D.exe -minimize [2014-1-17 72040]
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"ConsentPromptBehaviorAdmin"= 5 (0x5)
"ConsentPromptBehaviorUser"= 3 (0x3)
"EnableUIADesktopToggle"= 0 (0x0)
"SoftwareSASGeneration"= 1 (0x1)
.
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\!SASCORE]
@=""
.
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\hitmanpro37]
@=""
.
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\hitmanpro37.sys]
@=""
.
R2 ASRockIOMon;ASRock IO Monitor Service;c:\program files (x86)\Fatal1ty Utility\F-Stream Tuning\Bin\IOMonitorSrv.exe;c:\program files (x86)\Fatal1ty Utility\F-Stream Tuning\Bin\IOMonitorSrv.exe [x]
R2 aswStm;aswStm;c:\windows\system32\drivers\aswStm.sys;c:\windows\SYSNATIVE\drivers\aswStm.sys [x]
R2 clr_optimization_v4.0.30319_64;Microsoft .NET Framework NGEN v4.0.30319_X64;c:\windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe;c:\windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe [x]
R2 MBAMService;MBAMService;c:\program files (x86)\Malwarebytes Anti-Malware\mbamservice.exe;c:\program files (x86)\Malwarebytes Anti-Malware\mbamservice.exe [x]
R2 VBoxAswDrv;VBoxAsw Support Driver;c:\program files\AVAST Software\Avast\ng\vbox\VBoxAswDrv.sys;c:\program files\AVAST Software\Avast\ng\vbox\VBoxAswDrv.sys [x]
R3 AsrDrv101;AsrDrv101;c:\windows\SysWOW64\Drivers\AsrDrv101.sys;c:\windows\SysWOW64\Drivers\AsrDrv101.sys [x]
R3 AsrHidFilter;AsrHidFilter;c:\windows\system32\DRIVERS\AsrHidFilter.sys;c:\windows\SYSNATIVE\DRIVERS\AsrHidFilter.sys [x]
R3 AvastVBoxSvc;AvastVBox COM Service;c:\program files\AVAST Software\Avast\ng\vbox\AvastVBoxSVC.exe;c:\program files\AVAST Software\Avast\ng\vbox\AvastVBoxSVC.exe [x]
R3 DRTL8192cu;D-Link DWA Wireless N USB Adapter;c:\windows\system32\DRIVERS\RTL8192cu.sys;c:\windows\SYSNATIVE\DRIVERS\RTL8192cu.sys [x]
R3 ICCS;Intel® Integrated Clock Controller Service - Intel® ICCS;c:\program files (x86)\Intel\Intel® Integrated Clock Controller Service\ICCProxy.exe;c:\program files (x86)\Intel\Intel® Integrated Clock Controller Service\ICCProxy.exe [x]
R3 IEEtwCollectorService;Internet Explorer ETW Collector Service;c:\windows\system32\IEEtwCollector.exe;c:\windows\SYSNATIVE\IEEtwCollector.exe [x]
R3 Intel® Capability Licensing Service TCP IP Interface;Intel® Capability Licensing Service TCP IP Interface;c:\program files\Intel\iCLS Client\SocketHeciServer.exe;c:\program files\Intel\iCLS Client\SocketHeciServer.exe [x]
R3 MBAMWebAccessControl;MBAMWebAccessControl;c:\windows\system32\drivers\mwac.sys;c:\windows\SYSNATIVE\drivers\mwac.sys [x]
R3 RdpVideoMiniport;Remote Desktop Video Miniport Driver;c:\windows\system32\drivers\rdpvideominiport.sys;c:\windows\SYSNATIVE\drivers\rdpvideominiport.sys [x]
R3 TsUsbFlt;TsUsbFlt;c:\windows\system32\drivers\tsusbflt.sys;c:\windows\SYSNATIVE\drivers\tsusbflt.sys [x]
R3 TsUsbGD;Remote Desktop Generic USB Device;c:\windows\system32\drivers\TsUsbGD.sys;c:\windows\SYSNATIVE\drivers\TsUsbGD.sys [x]
R3 WatAdminSvc;Windows Activation Technologies Service;c:\windows\system32\Wat\WatAdminSvc.exe;c:\windows\SYSNATIVE\Wat\WatAdminSvc.exe [x]
S0 AsrRamDisk;AsrRamDisk;c:\windows\system32\DRIVERS\AsrRamDisk.sys;c:\windows\SYSNATIVE\DRIVERS\AsrRamDisk.sys [x]
S0 aswRvrt;avast! Revert; [x]
S0 aswVmm;avast! VM Monitor; [x]
S0 iusb3hcs;Intel® USB 3.0 Host Controller Switch Driver;c:\windows\system32\DRIVERS\iusb3hcs.sys;c:\windows\SYSNATIVE\DRIVERS\iusb3hcs.sys [x]
S1 anodlwf;ANOD Network Security Filter driver;c:\windows\system32\DRIVERS\anodlwfx.sys;c:\windows\SYSNATIVE\DRIVERS\anodlwfx.sys [x]
S1 aswKbd;aswKbd;c:\windows\system32\drivers\aswKbd.sys;c:\windows\SYSNATIVE\drivers\aswKbd.sys [x]
S1 aswSnx;aswSnx;c:\windows\system32\drivers\aswSnx.sys;c:\windows\SYSNATIVE\drivers\aswSnx.sys [x]
S1 aswSP;aswSP;c:\windows\system32\drivers\aswSP.sys;c:\windows\SYSNATIVE\drivers\aswSP.sys [x]
S1 BfLwf;Qualcomm Atheros Bandwidth Control;c:\windows\system32\DRIVERS\bflwfx64.sys;c:\windows\SYSNATIVE\DRIVERS\bflwfx64.sys [x]
S1 CLVirtualDrive;CLVirtualDrive;c:\windows\system32\DRIVERS\CLVirtualDrive.sys;c:\windows\SYSNATIVE\DRIVERS\CLVirtualDrive.sys [x]
S1 SASDIFSV;SASDIFSV;c:\program files\SUPERAntiSpyware\SASDIFSV64.SYS;c:\program files\SUPERAntiSpyware\SASDIFSV64.SYS [x]
S1 SASKUTIL;SASKUTIL;c:\program files\SUPERAntiSpyware\SASKUTIL64.SYS;c:\program files\SUPERAntiSpyware\SASKUTIL64.SYS [x]
S2 !SASCORE;SAS Core Service;c:\program files\SUPERAntiSpyware\SASCORE64.EXE;c:\program files\SUPERAntiSpyware\SASCORE64.EXE [x]
S2 aswHwid;avast! HardwareID;c:\windows\system32\drivers\aswHwid.sys;c:\windows\SYSNATIVE\drivers\aswHwid.sys [x]
S2 aswMonFlt;aswMonFlt;c:\windows\system32\drivers\aswMonFlt.sys;c:\windows\SYSNATIVE\drivers\aswMonFlt.sys [x]
S2 D_Link_DWA-121_WPS;D_Link_DWA-121_WPS Service;c:\program files (x86)\D-Link\DWA-121 revA\ANIWConnService.exe;c:\program files (x86)\D-Link\DWA-121 revA\ANIWConnService.exe [x]
S2 DiagTrack;Diagnostics Tracking Service;c:\windows\System32\svchost.exe;c:\windows\SYSNATIVE\svchost.exe [x]
S2 Intel® Capability Licensing Service Interface;Intel® Capability Licensing Service Interface;c:\program files\Intel\iCLS Client\HeciServer.exe;c:\program files\Intel\iCLS Client\HeciServer.exe [x]
S2 jhi_service;Intel® Dynamic Application Loader Host Interface Service;c:\program files (x86)\Intel\Intel® Management Engine Components\DAL\jhi_service.exe;c:\program files (x86)\Intel\Intel® Management Engine Components\DAL\jhi_service.exe [x]
S2 Qualcomm Atheros Killer Service V2;Qualcomm Atheros Killer Service V2;c:\program files\Qualcomm Atheros\Network Manager\KillerService.exe;c:\program files\Qualcomm Atheros\Network Manager\KillerService.exe [x]
S2 TeamViewer9;TeamViewer 9;c:\program files (x86)\TeamViewer\Version9\TeamViewer_Service.exe;c:\program files (x86)\TeamViewer\Version9\TeamViewer_Service.exe [x]
S3 IntcDAud;Intel® Display Audio;c:\windows\system32\DRIVERS\IntcDAud.sys;c:\windows\SYSNATIVE\DRIVERS\IntcDAud.sys [x]
S3 ISCT;Intel® Smart Connect Technology Device Driver;c:\windows\system32\DRIVERS\ISCTD64.sys;c:\windows\SYSNATIVE\DRIVERS\ISCTD64.sys [x]
S3 iusb3hub;Intel® USB 3.0 Hub Driver;c:\windows\system32\DRIVERS\iusb3hub.sys;c:\windows\SYSNATIVE\DRIVERS\iusb3hub.sys [x]
S3 iusb3xhc;Intel® USB 3.0 eXtensible Host Controller Driver;c:\windows\system32\DRIVERS\iusb3xhc.sys;c:\windows\SYSNATIVE\DRIVERS\iusb3xhc.sys [x]
S3 Ke2200;NDIS Miniport Driver for the Killer e2200 PCI-E Ethernet Controller;c:\windows\system32\DRIVERS\e22w7x64.sys;c:\windows\SYSNATIVE\DRIVERS\e22w7x64.sys [x]
S3 MBAMProtector;MBAMProtector;c:\windows\system32\drivers\mbam.sys;c:\windows\SYSNATIVE\drivers\mbam.sys [x]
.
.
Contents of the 'Scheduled Tasks' folder
.
2016-03-05 c:\windows\Tasks\Adobe Flash Player Updater.job
- c:\windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe [2014-01-17 10:00]
.
.
--------- X64 Entries -----------
.
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\00avast]
@="{472083B0-C522-11CF-8763-00608CC02F24}"
[HKEY_CLASSES_ROOT\CLSID\{472083B0-C522-11CF-8763-00608CC02F24}]
2016-02-12 04:55    905248    ----a-w-    c:\program files\AVAST Software\Avast\ashShA64.dll
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"IgfxTray"="c:\windows\system32\igfxtray.exe" [2013-05-24 165872]
"HotKeysCmds"="c:\windows\system32\hkcmd.exe" [2013-05-24 407536]
"Persistence"="c:\windows\system32\igfxpers.exe" [2013-05-24 444400]
"RTHDVCPL"="c:\program files\Realtek\Audio\HDA\RAVCpl64.exe" [2013-07-26 13636824]
.
------- Supplementary Scan -------
.
uLocal Page = c:\windows\system32\blank.htm
mLocal Page = c:\windows\SysWOW64\blank.htm
IE: E&xport to Microsoft Excel - c:\progra~2\MICROS~1\Office14\EXCEL.EXE/3000
IE: Se&nd to OneNote - c:\progra~2\MICROS~1\Office14\ONBttnIE.dll/105
TCP: DhcpNameServer = 75.75.75.75 75.75.76.76
FF - ProfilePath - c:\users\Helena\AppData\Roaming\Mozilla\Firefox\Profiles\ju292vok.default-1438795000345\
FF - prefs.js: browser.startup.homepage - www.google.com/
.
- - - - ORPHANS REMOVED - - - -
.
Wow6432Node-HKCU-Run-Fatal1tySTU - (no file)
Wow6432Node-HKCU-Run-ASRockHDMISwitch - (no file)
Wow6432Node-HKU-Default-Run-KSS - c:\program files (x86)\Kaspersky Lab\Kaspersky Security Scan\kss.exe
HKLM_Wow6432Node-ActiveSetup-{2D46B6DC-2207-486B-B523-A557E6D54B47} - start
AddRemove-ASRock HDMI Switch_is1 - c:\program files (x86)\ASRock Utility\HDMISwitch\unins000.exe
AddRemove-ASRock Key Master_is1 - c:\program files (x86)\ASRock Utility\Key Master\unins000.exe
.
.
.
--------------------- LOCKED REGISTRY KEYS ---------------------
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Office\Common\Smart Tag\Actions\{B7EFF951-E52F-45CC-9EF7-57124F2177CC}]
@Denied: (A) (Everyone)
"Solution"="{15727DE6-F92D-4E46-ACB4-0E2C58B31A18}"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Schema Library\ActionsPane3]
@Denied: (A) (Everyone)
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Schema Library\ActionsPane3\0]
"Key"="ActionsPane3"
"Location"="c:\\Program Files (x86)\\Common Files\\Microsoft Shared\\VSTO\\ActionsPane3.xsd"
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\PCW\Security]
@Denied: (Full) (Everyone)
.
Completion time: 2016-03-05  07:28:43
ComboFix-quarantined-files.txt  2016-03-05 14:28
.
Pre-Run: 843,986,845,696 bytes free
Post-Run: 843,839,725,568 bytes free
.
- - End Of File - - 02328CDCDFA073A021113096A362AF64
A36C5E4F47E84449FF07ED3517B43A31
 


  • 0

#14
zep516

zep516

    Trusted Helper

  • Malware Removal
  • 8,093 posts
Hello,

Everything's looking ok.

How is the computer ?
  • 0

#15
Webslinger64

Webslinger64

    Member

  • Topic Starter
  • Member
  • PipPipPip
  • 567 posts

It's working great now.  That always seems to be the case though when I run a SuperAntispyware scan.  Once the threats are cleared out, it runs well, but then 24 hours later it's doing the same thing.  I'd like to run a scan tomorrow and see if it comes up clean or still with hundreds or a thousand+ threats.

I do appreciate all of your assistance.  I've learned a lot through this process.


Edited by Webslinger64, 05 March 2016 - 08:24 PM.

  • 0






Similar Topics

0 user(s) are reading this topic

0 members, 0 guests, 0 anonymous users

As Featured On:

Microsoft Yahoo BBC MSN PC Magazine Washington Post HP