Jump to content

cchao

Honorary Members
  • Posts

    27
  • Joined

  • Last visited

Reputation

0 Neutral
  1. Okay thank you. I'm going to delete all the programs that you told me to download for cleaning the malware. Thanks again.
  2. Fix result of Farbar Recovery Scan Tool (x64) Version: 10-10-2016 Ran by ChiemMax (10-10-2016 20:15:15) Run:3 Running from C:\Users\ChiemMax\Desktop Loaded Profiles: ChiemMax (Available Profiles: ChiemMax & Kao & Guest) Boot Mode: Normal ============================================== fixlist content: ***************** start CreateRestorePoint: CloseProcesses: C:\WINDOWS\couponprinter_x64.ocx C:\Users\ChiemMax\AppData\Roaming\simplitec C:\ProgramData\simplitec C:\Program Files (x86)\simplitec C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\simplicheck.lnk FF Plugin HKU\S-1-5-21-3173931314-375326031-4078295803-1001: CouponNetwork.com/CMDUniversalCouponPrintActivator -> C:\Users\ChiemMax\AppData\Roaming\CATALI~1\NPBCSK~1.DLL [2013-06-07] (Catalina Marketing Corporation) FF Plugin HKU\S-1-5-21-3173931314-375326031-4078295803-1001-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0: CouponNetwork.com/CMDUniversalCouponPrintActivator -> C:\Users\ChiemMax\AppData\Roaming\CATALI~1\NPBCSK~1.DLL [2013-06-07] (Catalina Marketing Corporation) FF Plugin ProgramFiles/Appdata: C:\Program Files (x86)\mozilla firefox\browser\plugins\npMozCouponPrinter.dll [2013-08-02] (Coupons, Inc.) 2016-09-25 22:23 - 2014-01-20 18:54 - 00000000 ____D C:\Users\ChiemMax\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Catalina – Print Savings 2016-09-25 22:23 - 2013-12-14 00:06 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Coupons 2016-09-25 22:13 - 2014-04-29 22:18 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\simplitec Task: {44C2997F-3662-4BC8-BB8D-E3F87546DD46} - System32\Tasks\SweetLabs App Platform => C:\Users\ChiemMax\AppData\Local\SweetLabs App Platform\Engine\ServiceHostAppUpdater.exe [2016-09-18] (Pokki) ShortcutWithArgument: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Google Chrome.lnk -> C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Google Inc.) -> " ShortcutWithArgument: C:\Users\Public\Desktop\Google Chrome.lnk -> C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Google Inc.) -> " DeleteKey: HKLM\SOFTWARE\Classes\CLSID\{1A53AD8B-D0B9-4E7F-88E4-50C07A65F2DC} DeleteKey: HKLM\SOFTWARE\Classes\CLSID\{A85A5E6A-DE2C-4F4E-99DC-F469DF5A0EEC} DeleteKey: HKLM\SOFTWARE\Classes\coupons.couponprinter_x64.1 DeleteKey: HKLM\SOFTWARE\Classes\Interface\{6E780F0B-BCD6-40CB-B2DB-7AF47AB4D4A4} DeleteKey: HKLM\SOFTWARE\Classes\Interface\{A138BE8B-F051-4802-9A3F-A750A6D862D4} DeleteKey: HKLM\SOFTWARE\Classes\Interface\{B3E37FAA-3669-4212-A35D-157BF70ADC04} DeleteKey: HKLM\SOFTWARE\Classes\Interface\{E755701B-A61B-4194-8902-17A61C4C1672} DeleteKey: HKLM\SOFTWARE\Classes\TypeLib\{87255C51-CD7D-4506-B9AD-97606DAF53F3} DeleteKey: HKLM\SOFTWARE\Classes\TypeLib\{CBED5D4B-6859-452B-80EA-3E66910984D7} DeleteKey: HKLM\SOFTWARE\Classes\WOW6432Node\CLSID\{A85A5E6A-DE2C-4F4E-99DC-F469DF5A0EEC} DeleteKey: HKLM\SOFTWARE\Classes\WOW6432Node\Interface\{6E780F0B-BCD6-40CB-B2DB-7AF47AB4D4A4} DeleteKey: HKLM\SOFTWARE\Classes\WOW6432Node\Interface\{A138BE8B-F051-4802-9A3F-A750A6D862D4} DeleteKey: HKLM\SOFTWARE\Classes\WOW6432Node\Interface\{B3E37FAA-3669-4212-A35D-157BF70ADC04} DeleteKey: HKLM\SOFTWARE\Classes\WOW6432Node\Interface\{E755701B-A61B-4194-8902-17A61C4C1672} DeleteKey: HKLM\SOFTWARE\Classes\WOW6432Node\TypeLib\{87255C51-CD7D-4506-B9AD-97606DAF53F3} DeleteKey: HKLM\SOFTWARE\Classes\WOW6432Node\TypeLib\{CBED5D4B-6859-452B-80EA-3E66910984D7} DeleteKey: HKLM\SOFTWARE\Microsoft\Internet Explorer\ActiveX Compatibility\{1A53AD8B-D0B9-4E7F-88E4-50C07A65F2DC} DeleteKey: HKLM\SOFTWARE\WOW6432Node\CouponsInc DeleteKey: HKLM\SOFTWARE\WOW6432Node\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{628F3201-34D0-49C0-BB9A-82A26AEFB291} DeleteKey: HKU\S-1-5-21-3173931314-375326031-4078295803-1001-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\Stats\{1A53AD8B-D0B9-4E7F-88E4-50C07A65F2DC} DeleteKey: HKU\S-1-5-21-3173931314-375326031-4078295803-1001-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\SOFTWARE\{1C43BAF1-00C2-40A8-A09E-F84CFD79546D} DeleteKey: HKU\S-1-5-21-3173931314-375326031-4078295803-1001-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0_Classes\Interface\{3B3F3AAD-FB97-49FF-BFEE-D22869AC4326} DeleteKey: HKU\S-1-5-21-3173931314-375326031-4078295803-1001\SOFTWARE\Classes\Interface\{3B3F3AAD-FB97-49FF-BFEE-D22869AC4326} DeleteKey: HKU\S-1-5-21-3173931314-375326031-4078295803-1001\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\Stats\{1A53AD8B-D0B9-4E7F-88E4-50C07A65F2DC} DeleteKey: HKU\S-1-5-21-3173931314-375326031-4078295803-1001\SOFTWARE\{1C43BAF1-00C2-40A8-A09E-F84CFD79546D} DeleteKey: HKU\S-1-5-21-3173931314-375326031-4078295803-1001_Classes\Interface\{3B3F3AAD-FB97-49FF-BFEE-D22869AC4326} DeleteKey: HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432NODE\SIMPLITEC end ***************** Restore point was successfully created. Processes closed successfully. C:\WINDOWS\couponprinter_x64.ocx => moved successfully C:\Users\ChiemMax\AppData\Roaming\simplitec => moved successfully C:\ProgramData\simplitec => moved successfully C:\Program Files (x86)\simplitec => moved successfully "C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\simplicheck.lnk" => not found. "HKU\S-1-5-21-3173931314-375326031-4078295803-1001\Software\MozillaPlugins\CouponNetwork.com/CMDUniversalCouponPrintActivator" => key removed successfully C:\Users\ChiemMax\AppData\Roaming\CATALI~1\NPBCSK~1.DLL => not found. HKU\S-1-5-21-3173931314-375326031-4078295803-1001-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\Software\MozillaPlugins\CouponNetwork.com/CMDUniversalCouponPrintActivator => key not found. C:\Users\ChiemMax\AppData\Roaming\CATALI~1\NPBCSK~1.DLL => not found. C:\Program Files (x86)\mozilla firefox\browser\plugins\npMozCouponPrinter.dll => moved successfully "C:\Users\ChiemMax\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Catalina – Print Savings" => not found. "C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Coupons" => not found. C:\ProgramData\Microsoft\Windows\Start Menu\Programs\simplitec => moved successfully HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{44C2997F-3662-4BC8-BB8D-E3F87546DD46} => key not found. C:\WINDOWS\System32\Tasks\SweetLabs App Platform => not found. HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\SweetLabs App Platform => key not found. C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Google Chrome.lnk => Shortcut argument removed successfully. C:\Users\Public\Desktop\Google Chrome.lnk => not found. HKLM\SOFTWARE\Classes\CLSID\{1A53AD8B-D0B9-4E7F-88E4-50C07A65F2DC} => could not remove at first attempt (ErrorCode: C0000121), see next line. HKLM\SOFTWARE\Classes\CLSID\{1A53AD8B-D0B9-4E7F-88E4-50C07A65F2DC} => key removed successfully HKLM\SOFTWARE\Classes\CLSID\{A85A5E6A-DE2C-4F4E-99DC-F469DF5A0EEC} => could not remove at first attempt (ErrorCode: C0000121), see next line. HKLM\SOFTWARE\Classes\CLSID\{A85A5E6A-DE2C-4F4E-99DC-F469DF5A0EEC} => key removed successfully HKLM\SOFTWARE\Classes\coupons.couponprinter_x64.1 => could not remove at first attempt (ErrorCode: C0000121), see next line. HKLM\SOFTWARE\Classes\coupons.couponprinter_x64.1 => key removed successfully HKLM\SOFTWARE\Classes\Interface\{6E780F0B-BCD6-40CB-B2DB-7AF47AB4D4A4} => could not remove at first attempt (ErrorCode: C0000121), see next line. HKLM\SOFTWARE\Classes\Interface\{6E780F0B-BCD6-40CB-B2DB-7AF47AB4D4A4} => key removed successfully HKLM\SOFTWARE\Classes\Interface\{A138BE8B-F051-4802-9A3F-A750A6D862D4} => could not remove at first attempt (ErrorCode: C0000121), see next line. HKLM\SOFTWARE\Classes\Interface\{A138BE8B-F051-4802-9A3F-A750A6D862D4} => key removed successfully HKLM\SOFTWARE\Classes\Interface\{B3E37FAA-3669-4212-A35D-157BF70ADC04} => could not remove at first attempt (ErrorCode: C0000121), see next line. HKLM\SOFTWARE\Classes\Interface\{B3E37FAA-3669-4212-A35D-157BF70ADC04} => key removed successfully HKLM\SOFTWARE\Classes\Interface\{E755701B-A61B-4194-8902-17A61C4C1672} => could not remove at first attempt (ErrorCode: C0000121), see next line. HKLM\SOFTWARE\Classes\Interface\{E755701B-A61B-4194-8902-17A61C4C1672} => key removed successfully HKLM\SOFTWARE\Classes\TypeLib\{87255C51-CD7D-4506-B9AD-97606DAF53F3} => could not remove at first attempt (ErrorCode: C0000121), see next line. HKLM\SOFTWARE\Classes\TypeLib\{87255C51-CD7D-4506-B9AD-97606DAF53F3} => key removed successfully HKLM\SOFTWARE\Classes\TypeLib\{CBED5D4B-6859-452B-80EA-3E66910984D7} => could not remove at first attempt (ErrorCode: C0000121), see next line. HKLM\SOFTWARE\Classes\TypeLib\{CBED5D4B-6859-452B-80EA-3E66910984D7} => key removed successfully HKLM\SOFTWARE\Classes\WOW6432Node\CLSID\{A85A5E6A-DE2C-4F4E-99DC-F469DF5A0EEC} => could not remove at first attempt (ErrorCode: C0000121), see next line. HKLM\SOFTWARE\Classes\WOW6432Node\CLSID\{A85A5E6A-DE2C-4F4E-99DC-F469DF5A0EEC} => key removed successfully HKLM\SOFTWARE\Classes\WOW6432Node\Interface\{6E780F0B-BCD6-40CB-B2DB-7AF47AB4D4A4} => could not remove at first attempt (ErrorCode: C0000121), see next line. HKLM\SOFTWARE\Classes\WOW6432Node\Interface\{6E780F0B-BCD6-40CB-B2DB-7AF47AB4D4A4} => key removed successfully HKLM\SOFTWARE\Classes\WOW6432Node\Interface\{A138BE8B-F051-4802-9A3F-A750A6D862D4} => could not remove at first attempt (ErrorCode: C0000121), see next line. HKLM\SOFTWARE\Classes\WOW6432Node\Interface\{A138BE8B-F051-4802-9A3F-A750A6D862D4} => key removed successfully HKLM\SOFTWARE\Classes\WOW6432Node\Interface\{B3E37FAA-3669-4212-A35D-157BF70ADC04} => could not remove at first attempt (ErrorCode: C0000121), see next line. HKLM\SOFTWARE\Classes\WOW6432Node\Interface\{B3E37FAA-3669-4212-A35D-157BF70ADC04} => key removed successfully HKLM\SOFTWARE\Classes\WOW6432Node\Interface\{E755701B-A61B-4194-8902-17A61C4C1672} => could not remove at first attempt (ErrorCode: C0000121), see next line. HKLM\SOFTWARE\Classes\WOW6432Node\Interface\{E755701B-A61B-4194-8902-17A61C4C1672} => key removed successfully HKLM\SOFTWARE\Classes\WOW6432Node\TypeLib\{87255C51-CD7D-4506-B9AD-97606DAF53F3} => key not found. HKLM\SOFTWARE\Classes\WOW6432Node\TypeLib\{CBED5D4B-6859-452B-80EA-3E66910984D7} => key not found. HKLM\SOFTWARE\Microsoft\Internet Explorer\ActiveX Compatibility\{1A53AD8B-D0B9-4E7F-88E4-50C07A65F2DC} => could not remove at first attempt (ErrorCode: C0000121), see next line. HKLM\SOFTWARE\Microsoft\Internet Explorer\ActiveX Compatibility\{1A53AD8B-D0B9-4E7F-88E4-50C07A65F2DC} => key removed successfully HKLM\SOFTWARE\WOW6432Node\CouponsInc => could not remove at first attempt (ErrorCode: C0000121), see next line. HKLM\SOFTWARE\WOW6432Node\CouponsInc => key removed successfully HKLM\SOFTWARE\WOW6432Node\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{628F3201-34D0-49C0-BB9A-82A26AEFB291} => key removed successfully HKU\S-1-5-21-3173931314-375326031-4078295803-1001-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\Stats\{1A53AD8B-D0B9-4E7F-88E4-50C07A65F2DC} => key not found. HKU\S-1-5-21-3173931314-375326031-4078295803-1001-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\SOFTWARE\{1C43BAF1-00C2-40A8-A09E-F84CFD79546D} => key not found. HKU\S-1-5-21-3173931314-375326031-4078295803-1001-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0_Classes\Interface\{3B3F3AAD-FB97-49FF-BFEE-D22869AC4326} => key not found. HKU\S-1-5-21-3173931314-375326031-4078295803-1001\SOFTWARE\Classes\Interface\{3B3F3AAD-FB97-49FF-BFEE-D22869AC4326} => could not remove at first attempt (ErrorCode: C0000121), see next line. HKU\S-1-5-21-3173931314-375326031-4078295803-1001\SOFTWARE\Classes\Interface\{3B3F3AAD-FB97-49FF-BFEE-D22869AC4326} => key removed successfully HKU\S-1-5-21-3173931314-375326031-4078295803-1001\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\Stats\{1A53AD8B-D0B9-4E7F-88E4-50C07A65F2DC} => could not remove at first attempt (ErrorCode: C0000121), see next line. HKU\S-1-5-21-3173931314-375326031-4078295803-1001\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\Stats\{1A53AD8B-D0B9-4E7F-88E4-50C07A65F2DC} => key removed successfully HKU\S-1-5-21-3173931314-375326031-4078295803-1001\SOFTWARE\{1C43BAF1-00C2-40A8-A09E-F84CFD79546D} => key removed successfully HKU\S-1-5-21-3173931314-375326031-4078295803-1001_Classes\Interface\{3B3F3AAD-FB97-49FF-BFEE-D22869AC4326} => key not found. HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432NODE\SIMPLITEC => could not remove at first attempt (ErrorCode: C0000121), see next line. HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432NODE\SIMPLITEC => key removed successfully The system needed a reboot. ==== End of Fixlog 20:16:22 ====
  3. Fix result of Farbar Recovery Scan Tool (x64) Version: 10-10-2016 Ran by ChiemMax (10-10-2016 20:15:15) Run:3 Running from C:\Users\ChiemMax\Desktop Loaded Profiles: ChiemMax (Available Profiles: ChiemMax & Kao & Guest) Boot Mode: Normal ============================================== fixlist content: ***************** start CreateRestorePoint: CloseProcesses: C:\WINDOWS\couponprinter_x64.ocx C:\Users\ChiemMax\AppData\Roaming\simplitec C:\ProgramData\simplitec C:\Program Files (x86)\simplitec C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\simplicheck.lnk FF Plugin HKU\S-1-5-21-3173931314-375326031-4078295803-1001: CouponNetwork.com/CMDUniversalCouponPrintActivator -> C:\Users\ChiemMax\AppData\Roaming\CATALI~1\NPBCSK~1.DLL [2013-06-07] (Catalina Marketing Corporation) FF Plugin HKU\S-1-5-21-3173931314-375326031-4078295803-1001-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0: CouponNetwork.com/CMDUniversalCouponPrintActivator -> C:\Users\ChiemMax\AppData\Roaming\CATALI~1\NPBCSK~1.DLL [2013-06-07] (Catalina Marketing Corporation) FF Plugin ProgramFiles/Appdata: C:\Program Files (x86)\mozilla firefox\browser\plugins\npMozCouponPrinter.dll [2013-08-02] (Coupons, Inc.) 2016-09-25 22:23 - 2014-01-20 18:54 - 00000000 ____D C:\Users\ChiemMax\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Catalina – Print Savings 2016-09-25 22:23 - 2013-12-14 00:06 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Coupons 2016-09-25 22:13 - 2014-04-29 22:18 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\simplitec Task: {44C2997F-3662-4BC8-BB8D-E3F87546DD46} - System32\Tasks\SweetLabs App Platform => C:\Users\ChiemMax\AppData\Local\SweetLabs App Platform\Engine\ServiceHostAppUpdater.exe [2016-09-18] (Pokki) ShortcutWithArgument: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Google Chrome.lnk -> C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Google Inc.) -> " ShortcutWithArgument: C:\Users\Public\Desktop\Google Chrome.lnk -> C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Google Inc.) -> " DeleteKey: HKLM\SOFTWARE\Classes\CLSID\{1A53AD8B-D0B9-4E7F-88E4-50C07A65F2DC} DeleteKey: HKLM\SOFTWARE\Classes\CLSID\{A85A5E6A-DE2C-4F4E-99DC-F469DF5A0EEC} DeleteKey: HKLM\SOFTWARE\Classes\coupons.couponprinter_x64.1 DeleteKey: HKLM\SOFTWARE\Classes\Interface\{6E780F0B-BCD6-40CB-B2DB-7AF47AB4D4A4} DeleteKey: HKLM\SOFTWARE\Classes\Interface\{A138BE8B-F051-4802-9A3F-A750A6D862D4} DeleteKey: HKLM\SOFTWARE\Classes\Interface\{B3E37FAA-3669-4212-A35D-157BF70ADC04} DeleteKey: HKLM\SOFTWARE\Classes\Interface\{E755701B-A61B-4194-8902-17A61C4C1672} DeleteKey: HKLM\SOFTWARE\Classes\TypeLib\{87255C51-CD7D-4506-B9AD-97606DAF53F3} DeleteKey: HKLM\SOFTWARE\Classes\TypeLib\{CBED5D4B-6859-452B-80EA-3E66910984D7} DeleteKey: HKLM\SOFTWARE\Classes\WOW6432Node\CLSID\{A85A5E6A-DE2C-4F4E-99DC-F469DF5A0EEC} DeleteKey: HKLM\SOFTWARE\Classes\WOW6432Node\Interface\{6E780F0B-BCD6-40CB-B2DB-7AF47AB4D4A4} DeleteKey: HKLM\SOFTWARE\Classes\WOW6432Node\Interface\{A138BE8B-F051-4802-9A3F-A750A6D862D4} DeleteKey: HKLM\SOFTWARE\Classes\WOW6432Node\Interface\{B3E37FAA-3669-4212-A35D-157BF70ADC04} DeleteKey: HKLM\SOFTWARE\Classes\WOW6432Node\Interface\{E755701B-A61B-4194-8902-17A61C4C1672} DeleteKey: HKLM\SOFTWARE\Classes\WOW6432Node\TypeLib\{87255C51-CD7D-4506-B9AD-97606DAF53F3} DeleteKey: HKLM\SOFTWARE\Classes\WOW6432Node\TypeLib\{CBED5D4B-6859-452B-80EA-3E66910984D7} DeleteKey: HKLM\SOFTWARE\Microsoft\Internet Explorer\ActiveX Compatibility\{1A53AD8B-D0B9-4E7F-88E4-50C07A65F2DC} DeleteKey: HKLM\SOFTWARE\WOW6432Node\CouponsInc DeleteKey: HKLM\SOFTWARE\WOW6432Node\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{628F3201-34D0-49C0-BB9A-82A26AEFB291} DeleteKey: HKU\S-1-5-21-3173931314-375326031-4078295803-1001-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\Stats\{1A53AD8B-D0B9-4E7F-88E4-50C07A65F2DC} DeleteKey: HKU\S-1-5-21-3173931314-375326031-4078295803-1001-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\SOFTWARE\{1C43BAF1-00C2-40A8-A09E-F84CFD79546D} DeleteKey: HKU\S-1-5-21-3173931314-375326031-4078295803-1001-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0_Classes\Interface\{3B3F3AAD-FB97-49FF-BFEE-D22869AC4326} DeleteKey: HKU\S-1-5-21-3173931314-375326031-4078295803-1001\SOFTWARE\Classes\Interface\{3B3F3AAD-FB97-49FF-BFEE-D22869AC4326} DeleteKey: HKU\S-1-5-21-3173931314-375326031-4078295803-1001\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\Stats\{1A53AD8B-D0B9-4E7F-88E4-50C07A65F2DC} DeleteKey: HKU\S-1-5-21-3173931314-375326031-4078295803-1001\SOFTWARE\{1C43BAF1-00C2-40A8-A09E-F84CFD79546D} DeleteKey: HKU\S-1-5-21-3173931314-375326031-4078295803-1001_Classes\Interface\{3B3F3AAD-FB97-49FF-BFEE-D22869AC4326} DeleteKey: HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432NODE\SIMPLITEC end ***************** Restore point was successfully created. Processes closed successfully. C:\WINDOWS\couponprinter_x64.ocx => moved successfully C:\Users\ChiemMax\AppData\Roaming\simplitec => moved successfully C:\ProgramData\simplitec => moved successfully C:\Program Files (x86)\simplitec => moved successfully "C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\simplicheck.lnk" => not found. "HKU\S-1-5-21-3173931314-375326031-4078295803-1001\Software\MozillaPlugins\CouponNetwork.com/CMDUniversalCouponPrintActivator" => key removed successfully C:\Users\ChiemMax\AppData\Roaming\CATALI~1\NPBCSK~1.DLL => not found. HKU\S-1-5-21-3173931314-375326031-4078295803-1001-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\Software\MozillaPlugins\CouponNetwork.com/CMDUniversalCouponPrintActivator => key not found. C:\Users\ChiemMax\AppData\Roaming\CATALI~1\NPBCSK~1.DLL => not found. C:\Program Files (x86)\mozilla firefox\browser\plugins\npMozCouponPrinter.dll => moved successfully "C:\Users\ChiemMax\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Catalina – Print Savings" => not found. "C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Coupons" => not found.
  4. Emsisoft Emergency Kit - Version 11.9 Last update: 10/7/2016 2:03:16 PM User account: MAX\ChiemMax Computer name: MAX OS version: Windows 10x64 Scan settings: Scan type: Custom Scan Objects: Rootkits, Memory, Traces, C:\ Detect PUPs: On Scan archives: On ADS Scan: On File extension filter: Off Advanced caching: On Direct disk access: Off Scan start: 10/7/2016 2:20:51 PM C:\Users\ChiemMax\AppData\Roaming\simplitec detected: Application.AppInstall (A) C:\ProgramData\simplitec detected: Application.AppInstall (A) C:\Program Files (x86)\simplitec detected: Application.AppInstall (A) Key: HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432NODE\SIMPLITEC detected: Application.InstallAd (A) Scanned 514790 Found 4 Scan end: 10/7/2016 5:32:12 PM Scan time: 3:11:21
  5. Should I have quarantined the tracking cookies with hitmanpro? I wasn't sure if I was suppose to or not since you said don't delete anything.
  6. HitmanPro 3.7.14.280 www.hitmanpro.com Computer name . . . . : MAX Windows . . . . . . . : 10.0.0.14393.X64/8 User name . . . . . . : MAX\ChiemMax UAC . . . . . . . . . : Enabled License . . . . . . . : Free Scan date . . . . . . : 2016-10-07 13:16:36 Scan mode . . . . . . : Normal Scan duration . . . . : 23m 24s Disk access mode . . : Direct disk access (SRB) Cloud . . . . . . . . : Internet Reboot . . . . . . . : No Threats . . . . . . . : 0 Traces . . . . . . . : 537 Objects scanned . . . : 2,560,401 Files scanned . . . . : 140,711 Remnants scanned . . : 885,913 files / 1,533,777 keys Suspicious files ____________________________________________________________ C:\Users\ChiemMax\AppData\Local\Microsoft\Windows\INetCache\IE\4LGB5CTD\FRST64[1].exe Size . . . . . . . : 2,404,864 bytes Age . . . . . . . : 4.0 days (2016-10-03 12:36:30) Entropy . . . . . : 7.6 SHA-256 . . . . . : 619A0964AE0899EBD470560C8B93914D73C2B183A75BD83686417A4ECB4A2655 Needs elevation . : Yes Fuzzy . . . . . . : 24.0 Program has no publisher information but prompts the user for permission elevation. Entropy (or randomness) indicates the program is encrypted, compressed or obfuscated. This is not typical for most programs. Authors name is missing in version info. This is not common to most programs. Version control is missing. This file is probably created by an individual. This is not typical for most programs. Time indicates that the file appeared recently on this computer. Forensic Cluster -0.1s C:\Users\ChiemMax\AppData\Local\Microsoft\Windows\INetCache\IE\04TQEDUP\FRST64[1].exe 0.0s C:\Users\ChiemMax\AppData\Local\Microsoft\Windows\INetCache\IE\4LGB5CTD\FRST64[1].exe C:\Users\ChiemMax\AppData\Local\Microsoft\Windows\INetCache\IE\LAL3FIU3\FRST64[1].exe Size . . . . . . . : 2,405,376 bytes Age . . . . . . . : 0.8 days (2016-10-06 16:59:10) Entropy . . . . . : 7.6 SHA-256 . . . . . : 74A30ABB1EDB9EF68C38FD39E5DE9707B2B52BDC0B614B3F9AFC2602D3A718E5 Needs elevation . : Yes Fuzzy . . . . . . : 24.0 Program has no publisher information but prompts the user for permission elevation. Entropy (or randomness) indicates the program is encrypted, compressed or obfuscated. This is not typical for most programs. Authors name is missing in version info. This is not common to most programs. Version control is missing. This file is probably created by an individual. This is not typical for most programs. Time indicates that the file appeared recently on this computer. Forensic Cluster -3.0s C:\Windows\rescache\_merged\1988706685\ -3.0s C:\Windows\rescache\_merged\1988706685\74616841.pri -0.8s C:\Users\ChiemMax\AppData\Local\Microsoft\Windows\INetCache\IE\IZ2Q3UMK\82[1].htm -0.8s C:\Users\ChiemMax\AppData\Local\Microsoft\Windows\INetCookies\576I3STI.cookie -0.1s C:\Users\ChiemMax\AppData\Local\Microsoft\Windows\INetCache\IE\04TQEDUP\FRST64[2].exe 0.0s C:\Users\ChiemMax\AppData\Local\Microsoft\Windows\INetCache\IE\LAL3FIU3\FRST64[1].exe 0.0s C:\Users\ChiemMax\Desktop\FRST64.exe 2.8s C:\Users\ChiemMax\Desktop\FRST-OlderVersion\ C:\Users\ChiemMax\Desktop\FRST-OlderVersion\FRST64.exe Size . . . . . . . : 2,404,864 bytes Age . . . . . . . : 7.6 days (2016-09-29 21:51:52) Entropy . . . . . : 7.6 SHA-256 . . . . . : 619A0964AE0899EBD470560C8B93914D73C2B183A75BD83686417A4ECB4A2655 Needs elevation . : Yes Fuzzy . . . . . . : 23.0 Program has no publisher information but prompts the user for permission elevation. Entropy (or randomness) indicates the program is encrypted, compressed or obfuscated. This is not typical for most programs. Authors name is missing in version info. This is not common to most programs. Version control is missing. This file is probably created by an individual. This is not typical for most programs. Time indicates that the file appeared recently on this computer. Forensic Cluster 0.0s C:\Users\ChiemMax\Desktop\FRST-OlderVersion\FRST64.exe 0.0s C:\Users\ChiemMax\Downloads\FRST-OlderVersion\FRST64.exe C:\Users\ChiemMax\Desktop\FRST64.exe Size . . . . . . . : 2,405,376 bytes Age . . . . . . . : 0.8 days (2016-10-06 16:59:10) Entropy . . . . . : 7.6 SHA-256 . . . . . : 74A30ABB1EDB9EF68C38FD39E5DE9707B2B52BDC0B614B3F9AFC2602D3A718E5 Needs elevation . : Yes Fuzzy . . . . . . : 24.0 Program has no publisher information but prompts the user for permission elevation. Entropy (or randomness) indicates the program is encrypted, compressed or obfuscated. This is not typical for most programs. Authors name is missing in version info. This is not common to most programs. Version control is missing. This file is probably created by an individual. This is not typical for most programs. Time indicates that the file appeared recently on this computer. Forensic Cluster -3.0s C:\Windows\rescache\_merged\1988706685\ -3.0s C:\Windows\rescache\_merged\1988706685\74616841.pri -0.8s C:\Users\ChiemMax\AppData\Local\Microsoft\Windows\INetCache\IE\IZ2Q3UMK\82[1].htm -0.8s C:\Users\ChiemMax\AppData\Local\Microsoft\Windows\INetCookies\576I3STI.cookie -0.1s C:\Users\ChiemMax\AppData\Local\Microsoft\Windows\INetCache\IE\04TQEDUP\FRST64[2].exe 0.0s C:\Users\ChiemMax\AppData\Local\Microsoft\Windows\INetCache\IE\LAL3FIU3\FRST64[1].exe 0.0s C:\Users\ChiemMax\Desktop\FRST64.exe 2.8s C:\Users\ChiemMax\Desktop\FRST-OlderVersion\ C:\Users\ChiemMax\Downloads\FRST-OlderVersion\FRST64.exe Size . . . . . . . : 2,404,352 bytes Age . . . . . . . : 7.6 days (2016-09-29 21:51:52) Entropy . . . . . : 7.6 SHA-256 . . . . . : 003671152E9C80D316767EC62EFA9A34F8F282CC80E338F13246262E5F9C529C Needs elevation . : Yes Fuzzy . . . . . . : 23.0 Program has no publisher information but prompts the user for permission elevation. Entropy (or randomness) indicates the program is encrypted, compressed or obfuscated. This is not typical for most programs. Authors name is missing in version info. This is not common to most programs. Version control is missing. This file is probably created by an individual. This is not typical for most programs. Time indicates that the file appeared recently on this computer. Forensic Cluster 0.0s C:\Users\ChiemMax\Desktop\FRST-OlderVersion\FRST64.exe 0.0s C:\Users\ChiemMax\Downloads\FRST-OlderVersion\FRST64.exe Potential Unwanted Programs _________________________________________________ C:\WINDOWS\couponprinter_x64.ocx (CouponBar) Size . . . . . . . : 652,160 bytes Age . . . . . . . : 1161.8 days (2013-08-02 18:44:58) Entropy . . . . . : 6.2 SHA-256 . . . . . : 1F42F01FA8D7731AA3462E0873AEC930E66E2B58B91C08751E01AFA914BFA8F1 Product . . . . . : Coupons, Inc. Coupon Printer Description . . . : Coupons, Inc. Coupon Printer 4.0.2.0 Version . . . . . : 4.0.2.0 Copyright . . . . : Copyright (C) 2013 RSA Key Size . . . : 2048 LanguageID . . . . : 1033 Authenticode . . . : Valid Fuzzy . . . . . . : -4.0 HKLM\SOFTWARE\Classes\CLSID\{1A53AD8B-D0B9-4E7F-88E4-50C07A65F2DC}\ (CouponBar) HKLM\SOFTWARE\Classes\CLSID\{A85A5E6A-DE2C-4F4E-99DC-F469DF5A0EEC}\ (CouponBar) HKLM\SOFTWARE\Classes\coupons.couponprinter_x64.1\ (CouponBar) HKLM\SOFTWARE\Classes\Interface\{6E780F0B-BCD6-40CB-B2DB-7AF47AB4D4A4}\ (CouponBar) HKLM\SOFTWARE\Classes\Interface\{A138BE8B-F051-4802-9A3F-A750A6D862D4}\ (CouponBar) HKLM\SOFTWARE\Classes\Interface\{B3E37FAA-3669-4212-A35D-157BF70ADC04}\ (CouponBar) HKLM\SOFTWARE\Classes\Interface\{E755701B-A61B-4194-8902-17A61C4C1672}\ (CouponBar) HKLM\SOFTWARE\Classes\TypeLib\{87255C51-CD7D-4506-B9AD-97606DAF53F3}\ (CouponBar) HKLM\SOFTWARE\Classes\TypeLib\{CBED5D4B-6859-452B-80EA-3E66910984D7}\ (CouponBar) HKLM\SOFTWARE\Classes\WOW6432Node\CLSID\{A85A5E6A-DE2C-4F4E-99DC-F469DF5A0EEC}\ (CouponBar) HKLM\SOFTWARE\Classes\WOW6432Node\Interface\{6E780F0B-BCD6-40CB-B2DB-7AF47AB4D4A4}\ (CouponBar) HKLM\SOFTWARE\Classes\WOW6432Node\Interface\{A138BE8B-F051-4802-9A3F-A750A6D862D4}\ (CouponBar) HKLM\SOFTWARE\Classes\WOW6432Node\Interface\{B3E37FAA-3669-4212-A35D-157BF70ADC04}\ (CouponBar) HKLM\SOFTWARE\Classes\WOW6432Node\Interface\{E755701B-A61B-4194-8902-17A61C4C1672}\ (CouponBar) HKLM\SOFTWARE\Classes\WOW6432Node\TypeLib\{87255C51-CD7D-4506-B9AD-97606DAF53F3}\ (CouponBar) HKLM\SOFTWARE\Classes\WOW6432Node\TypeLib\{CBED5D4B-6859-452B-80EA-3E66910984D7}\ (CouponBar) HKLM\SOFTWARE\Microsoft\Internet Explorer\ActiveX Compatibility\{1A53AD8B-D0B9-4E7F-88E4-50C07A65F2DC}\ (CouponBar) HKLM\SOFTWARE\WOW6432Node\CouponsInc\ (CouponBar) HKLM\SOFTWARE\WOW6432Node\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{628F3201-34D0-49C0-BB9A-82A26AEFB291}\ (CouponBar) HKU\S-1-5-21-3173931314-375326031-4078295803-1001-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\Stats\{1A53AD8B-D0B9-4E7F-88E4-50C07A65F2DC}\ (CouponBar) HKU\S-1-5-21-3173931314-375326031-4078295803-1001-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\SOFTWARE\{1C43BAF1-00C2-40A8-A09E-F84CFD79546D}\ (CouponBar) HKU\S-1-5-21-3173931314-375326031-4078295803-1001-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0_Classes\Interface\{3B3F3AAD-FB97-49FF-BFEE-D22869AC4326}\ (UniDeals) HKU\S-1-5-21-3173931314-375326031-4078295803-1001\SOFTWARE\Classes\Interface\{3B3F3AAD-FB97-49FF-BFEE-D22869AC4326}\ (UniDeals) HKU\S-1-5-21-3173931314-375326031-4078295803-1001\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\Stats\{1A53AD8B-D0B9-4E7F-88E4-50C07A65F2DC}\ (CouponBar) HKU\S-1-5-21-3173931314-375326031-4078295803-1001\SOFTWARE\{1C43BAF1-00C2-40A8-A09E-F84CFD79546D}\ (CouponBar) HKU\S-1-5-21-3173931314-375326031-4078295803-1001_Classes\Interface\{3B3F3AAD-FB97-49FF-BFEE-D22869AC4326}\ (UniDeals) Cookies _____________________________________________________________________ C:\Users\ChiemMax\AppData\Local\Microsoft\Windows\INetCookies\000BJTTN.txt C:\Users\ChiemMax\AppData\Local\Microsoft\Windows\INetCookies\007SAU55.txt C:\Users\ChiemMax\AppData\Local\Microsoft\Windows\INetCookies\0CYN7WBK.txt C:\Users\ChiemMax\AppData\Local\Microsoft\Windows\INetCookies\1LH60GP2.txt C:\Users\ChiemMax\AppData\Local\Microsoft\Windows\INetCookies\1MK8YWEH.txt C:\Users\ChiemMax\AppData\Local\Microsoft\Windows\INetCookies\1SI5IX56.txt C:\Users\ChiemMax\AppData\Local\Microsoft\Windows\INetCookies\1SQDA5F8.txt C:\Users\ChiemMax\AppData\Local\Microsoft\Windows\INetCookies\21Y6FT3E.txt C:\Users\ChiemMax\AppData\Local\Microsoft\Windows\INetCookies\2HY7FTLV.txt C:\Users\ChiemMax\AppData\Local\Microsoft\Windows\INetCookies\3TITZ106.txt C:\Users\ChiemMax\AppData\Local\Microsoft\Windows\INetCookies\4C45430W.txt C:\Users\ChiemMax\AppData\Local\Microsoft\Windows\INetCookies\5Q4GCNEN.txt C:\Users\ChiemMax\AppData\Local\Microsoft\Windows\INetCookies\6E4WQFS0.txt C:\Users\ChiemMax\AppData\Local\Microsoft\Windows\INetCookies\6FVSL0GJ.txt C:\Users\ChiemMax\AppData\Local\Microsoft\Windows\INetCookies\6M0W3KOK.txt C:\Users\ChiemMax\AppData\Local\Microsoft\Windows\INetCookies\7JE5D9T3.txt C:\Users\ChiemMax\AppData\Local\Microsoft\Windows\INetCookies\7XY7MJTL.txt C:\Users\ChiemMax\AppData\Local\Microsoft\Windows\INetCookies\8BDM6L1J.txt C:\Users\ChiemMax\AppData\Local\Microsoft\Windows\INetCookies\8HBFKZZT.txt C:\Users\ChiemMax\AppData\Local\Microsoft\Windows\INetCookies\9W48R698.txt C:\Users\ChiemMax\AppData\Local\Microsoft\Windows\INetCookies\AKB945M3.txt C:\Users\ChiemMax\AppData\Local\Microsoft\Windows\INetCookies\AXPN7Z1W.txt C:\Users\ChiemMax\AppData\Local\Microsoft\Windows\INetCookies\CX5MSUF4.txt C:\Users\ChiemMax\AppData\Local\Microsoft\Windows\INetCookies\DK2BYO9S.txt C:\Users\ChiemMax\AppData\Local\Microsoft\Windows\INetCookies\G4O0UF4I.txt C:\Users\ChiemMax\AppData\Local\Microsoft\Windows\INetCookies\IXW2VAY5.txt C:\Users\ChiemMax\AppData\Local\Microsoft\Windows\INetCookies\J4HTCY79.txt C:\Users\ChiemMax\AppData\Local\Microsoft\Windows\INetCookies\K2Q9SWUE.txt C:\Users\ChiemMax\AppData\Local\Microsoft\Windows\INetCookies\KPW283GA.txt C:\Users\ChiemMax\AppData\Local\Microsoft\Windows\INetCookies\KRM917V6.txt C:\Users\ChiemMax\AppData\Local\Microsoft\Windows\INetCookies\L9C2U319.txt C:\Users\ChiemMax\AppData\Local\Microsoft\Windows\INetCookies\Low\06UTHS2S.txt C:\Users\ChiemMax\AppData\Local\Microsoft\Windows\INetCookies\Low\0F1LMCMF.txt C:\Users\ChiemMax\AppData\Local\Microsoft\Windows\INetCookies\Low\0G90FZGN.txt C:\Users\ChiemMax\AppData\Local\Microsoft\Windows\INetCookies\Low\0HL7HGWH.txt C:\Users\ChiemMax\AppData\Local\Microsoft\Windows\INetCookies\Low\0S31SGF5.txt C:\Users\ChiemMax\AppData\Local\Microsoft\Windows\INetCookies\Low\10GNBK0D.txt C:\Users\ChiemMax\AppData\Local\Microsoft\Windows\INetCookies\Low\113XQ45D.txt C:\Users\ChiemMax\AppData\Local\Microsoft\Windows\INetCookies\Low\142D54GK.txt C:\Users\ChiemMax\AppData\Local\Microsoft\Windows\INetCookies\Low\1FX332C7.txt C:\Users\ChiemMax\AppData\Local\Microsoft\Windows\INetCookies\Low\1IDBU31L.txt C:\Users\ChiemMax\AppData\Local\Microsoft\Windows\INetCookies\Low\1K58UCEB.txt C:\Users\ChiemMax\AppData\Local\Microsoft\Windows\INetCookies\Low\1ME6HMQU.txt C:\Users\ChiemMax\AppData\Local\Microsoft\Windows\INetCookies\Low\1N0DDUCL.txt C:\Users\ChiemMax\AppData\Local\Microsoft\Windows\INetCookies\Low\1OMTZMRV.txt C:\Users\ChiemMax\AppData\Local\Microsoft\Windows\INetCookies\Low\1P4E91VI.txt C:\Users\ChiemMax\AppData\Local\Microsoft\Windows\INetCookies\Low\1PIBSKJP.txt C:\Users\ChiemMax\AppData\Local\Microsoft\Windows\INetCookies\Low\1PQPBRQ0.txt C:\Users\ChiemMax\AppData\Local\Microsoft\Windows\INetCookies\Low\1Q9EM92H.txt C:\Users\ChiemMax\AppData\Local\Microsoft\Windows\INetCookies\Low\1XCFI0Y1.txt C:\Users\ChiemMax\AppData\Local\Microsoft\Windows\INetCookies\Low\20QTCXC6.txt C:\Users\ChiemMax\AppData\Local\Microsoft\Windows\INetCookies\Low\21WVR519.txt C:\Users\ChiemMax\AppData\Local\Microsoft\Windows\INetCookies\Low\25MECLS4.txt C:\Users\ChiemMax\AppData\Local\Microsoft\Windows\INetCookies\Low\29R10Z5M.txt C:\Users\ChiemMax\AppData\Local\Microsoft\Windows\INetCookies\Low\2BVUJBH2.txt C:\Users\ChiemMax\AppData\Local\Microsoft\Windows\INetCookies\Low\2FPCMBDV.txt C:\Users\ChiemMax\AppData\Local\Microsoft\Windows\INetCookies\Low\2MYVUPI6.txt C:\Users\ChiemMax\AppData\Local\Microsoft\Windows\INetCookies\Low\2Q8PFRLY.txt C:\Users\ChiemMax\AppData\Local\Microsoft\Windows\INetCookies\Low\2RXP1WQC.txt C:\Users\ChiemMax\AppData\Local\Microsoft\Windows\INetCookies\Low\2T83DC4H.txt C:\Users\ChiemMax\AppData\Local\Microsoft\Windows\INetCookies\Low\323FL06B.txt C:\Users\ChiemMax\AppData\Local\Microsoft\Windows\INetCookies\Low\32J2YXGO.txt C:\Users\ChiemMax\AppData\Local\Microsoft\Windows\INetCookies\Low\33EEVDVJ.txt C:\Users\ChiemMax\AppData\Local\Microsoft\Windows\INetCookies\Low\33W43XIR.txt C:\Users\ChiemMax\AppData\Local\Microsoft\Windows\INetCookies\Low\35S7VS0N.txt C:\Users\ChiemMax\AppData\Local\Microsoft\Windows\INetCookies\Low\36QK3I7N.txt C:\Users\ChiemMax\AppData\Local\Microsoft\Windows\INetCookies\Low\3HZM47F5.txt C:\Users\ChiemMax\AppData\Local\Microsoft\Windows\INetCookies\Low\3ST3D0YP.txt C:\Users\ChiemMax\AppData\Local\Microsoft\Windows\INetCookies\Low\3VGV0IR6.txt C:\Users\ChiemMax\AppData\Local\Microsoft\Windows\INetCookies\Low\3WKX5LK2.txt C:\Users\ChiemMax\AppData\Local\Microsoft\Windows\INetCookies\Low\429KPK52.txt C:\Users\ChiemMax\AppData\Local\Microsoft\Windows\INetCookies\Low\42ZYE6YG.txt C:\Users\ChiemMax\AppData\Local\Microsoft\Windows\INetCookies\Low\44IOJHYW.txt C:\Users\ChiemMax\AppData\Local\Microsoft\Windows\INetCookies\Low\4M63038K.txt C:\Users\ChiemMax\AppData\Local\Microsoft\Windows\INetCookies\Low\4RB3YOOI.txt C:\Users\ChiemMax\AppData\Local\Microsoft\Windows\INetCookies\Low\518OQU5H.txt C:\Users\ChiemMax\AppData\Local\Microsoft\Windows\INetCookies\Low\55NMVNKP.txt C:\Users\ChiemMax\AppData\Local\Microsoft\Windows\INetCookies\Low\59FE4676.txt C:\Users\ChiemMax\AppData\Local\Microsoft\Windows\INetCookies\Low\5E8O2HRP.txt C:\Users\ChiemMax\AppData\Local\Microsoft\Windows\INetCookies\Low\5JBWZIPX.txt C:\Users\ChiemMax\AppData\Local\Microsoft\Windows\INetCookies\Low\5QLKBK9X.txt C:\Users\ChiemMax\AppData\Local\Microsoft\Windows\INetCookies\Low\5QU0PZK6.txt C:\Users\ChiemMax\AppData\Local\Microsoft\Windows\INetCookies\Low\5WF2JTWR.txt C:\Users\ChiemMax\AppData\Local\Microsoft\Windows\INetCookies\Low\5Z0I1URJ.txt C:\Users\ChiemMax\AppData\Local\Microsoft\Windows\INetCookies\Low\676KSDIY.txt C:\Users\ChiemMax\AppData\Local\Microsoft\Windows\INetCookies\Low\67LNAK65.txt C:\Users\ChiemMax\AppData\Local\Microsoft\Windows\INetCookies\Low\6H9JRLEX.txt C:\Users\ChiemMax\AppData\Local\Microsoft\Windows\INetCookies\Low\6KIVHBUY.txt C:\Users\ChiemMax\AppData\Local\Microsoft\Windows\INetCookies\Low\6LRZEJHW.txt C:\Users\ChiemMax\AppData\Local\Microsoft\Windows\INetCookies\Low\6SF4Z095.txt C:\Users\ChiemMax\AppData\Local\Microsoft\Windows\INetCookies\Low\6TLYHVLY.txt C:\Users\ChiemMax\AppData\Local\Microsoft\Windows\INetCookies\Low\6YQUGS32.txt C:\Users\ChiemMax\AppData\Local\Microsoft\Windows\INetCookies\Low\73HEIAA1.txt C:\Users\ChiemMax\AppData\Local\Microsoft\Windows\INetCookies\Low\743KHQIX.txt C:\Users\ChiemMax\AppData\Local\Microsoft\Windows\INetCookies\Low\78B9ZKQJ.txt C:\Users\ChiemMax\AppData\Local\Microsoft\Windows\INetCookies\Low\7AW4K23P.txt C:\Users\ChiemMax\AppData\Local\Microsoft\Windows\INetCookies\Low\7BPL1S16.txt C:\Users\ChiemMax\AppData\Local\Microsoft\Windows\INetCookies\Low\7F31VFVG.txt C:\Users\ChiemMax\AppData\Local\Microsoft\Windows\INetCookies\Low\7G5JDKFW.txt C:\Users\ChiemMax\AppData\Local\Microsoft\Windows\INetCookies\Low\7TEGJGT6.txt C:\Users\ChiemMax\AppData\Local\Microsoft\Windows\INetCookies\Low\7V0F3GEU.txt C:\Users\ChiemMax\AppData\Local\Microsoft\Windows\INetCookies\Low\7YICHMAL.txt C:\Users\ChiemMax\AppData\Local\Microsoft\Windows\INetCookies\Low\8ATHED6U.txt C:\Users\ChiemMax\AppData\Local\Microsoft\Windows\INetCookies\Low\8E811HZH.txt C:\Users\ChiemMax\AppData\Local\Microsoft\Windows\INetCookies\Low\8GSU62XQ.txt C:\Users\ChiemMax\AppData\Local\Microsoft\Windows\INetCookies\Low\8SIQFSF2.txt C:\Users\ChiemMax\AppData\Local\Microsoft\Windows\INetCookies\Low\8SLHTXSU.txt C:\Users\ChiemMax\AppData\Local\Microsoft\Windows\INetCookies\Low\8V35L0S3.txt C:\Users\ChiemMax\AppData\Local\Microsoft\Windows\INetCookies\Low\91RMA2I7.txt C:\Users\ChiemMax\AppData\Local\Microsoft\Windows\INetCookies\Low\9403U81V.txt C:\Users\ChiemMax\AppData\Local\Microsoft\Windows\INetCookies\Low\965U9BHS.txt C:\Users\ChiemMax\AppData\Local\Microsoft\Windows\INetCookies\Low\9JLE407J.txt C:\Users\ChiemMax\AppData\Local\Microsoft\Windows\INetCookies\Low\9PZZAK18.txt C:\Users\ChiemMax\AppData\Local\Microsoft\Windows\INetCookies\Low\9XQ9JHCK.txt C:\Users\ChiemMax\AppData\Local\Microsoft\Windows\INetCookies\Low\9Y3R7ENX.txt C:\Users\ChiemMax\AppData\Local\Microsoft\Windows\INetCookies\Low\9YBC2AAS.txt C:\Users\ChiemMax\AppData\Local\Microsoft\Windows\INetCookies\Low\A440PUSW.txt C:\Users\ChiemMax\AppData\Local\Microsoft\Windows\INetCookies\Low\ALGN6QTH.txt C:\Users\ChiemMax\AppData\Local\Microsoft\Windows\INetCookies\Low\AMDDS2V3.txt C:\Users\ChiemMax\AppData\Local\Microsoft\Windows\INetCookies\Low\AUMOSB0M.txt C:\Users\ChiemMax\AppData\Local\Microsoft\Windows\INetCookies\Low\AVFJGU09.txt C:\Users\ChiemMax\AppData\Local\Microsoft\Windows\INetCookies\Low\AZA19MYZ.txt C:\Users\ChiemMax\AppData\Local\Microsoft\Windows\INetCookies\Low\B3T9W5CH.txt C:\Users\ChiemMax\AppData\Local\Microsoft\Windows\INetCookies\Low\B4NH0D2T.txt C:\Users\ChiemMax\AppData\Local\Microsoft\Windows\INetCookies\Low\BFG6G86L.txt C:\Users\ChiemMax\AppData\Local\Microsoft\Windows\INetCookies\Low\BHZ2VKCK.txt C:\Users\ChiemMax\AppData\Local\Microsoft\Windows\INetCookies\Low\BHZO4DKR.txt C:\Users\ChiemMax\AppData\Local\Microsoft\Windows\INetCookies\Low\BQ0ET519.txt C:\Users\ChiemMax\AppData\Local\Microsoft\Windows\INetCookies\Low\BREGRMY6.txt C:\Users\ChiemMax\AppData\Local\Microsoft\Windows\INetCookies\Low\BXQOA2ZD.txt C:\Users\ChiemMax\AppData\Local\Microsoft\Windows\INetCookies\Low\BYDJMVFH.txt C:\Users\ChiemMax\AppData\Local\Microsoft\Windows\INetCookies\Low\C9DHH3HW.txt C:\Users\ChiemMax\AppData\Local\Microsoft\Windows\INetCookies\Low\CGQJL2TI.txt C:\Users\ChiemMax\AppData\Local\Microsoft\Windows\INetCookies\Low\CH4W3E9K.txt C:\Users\ChiemMax\AppData\Local\Microsoft\Windows\INetCookies\Low\CHZM1C2T.txt C:\Users\ChiemMax\AppData\Local\Microsoft\Windows\INetCookies\Low\CS1YZZBU.txt C:\Users\ChiemMax\AppData\Local\Microsoft\Windows\INetCookies\Low\D1Q2C3ZF.txt C:\Users\ChiemMax\AppData\Local\Microsoft\Windows\INetCookies\Low\D2T00K2P.txt C:\Users\ChiemMax\AppData\Local\Microsoft\Windows\INetCookies\Low\D8WW2H1X.txt C:\Users\ChiemMax\AppData\Local\Microsoft\Windows\INetCookies\Low\DD00W7SM.txt C:\Users\ChiemMax\AppData\Local\Microsoft\Windows\INetCookies\Low\DDRS7OX3.txt C:\Users\ChiemMax\AppData\Local\Microsoft\Windows\INetCookies\Low\DISLFLLK.txt C:\Users\ChiemMax\AppData\Local\Microsoft\Windows\INetCookies\Low\DLL1JJ2E.txt C:\Users\ChiemMax\AppData\Local\Microsoft\Windows\INetCookies\Low\DML4PWZL.txt C:\Users\ChiemMax\AppData\Local\Microsoft\Windows\INetCookies\Low\DNVZ1KD0.txt C:\Users\ChiemMax\AppData\Local\Microsoft\Windows\INetCookies\Low\E3DO86SI.txt C:\Users\ChiemMax\AppData\Local\Microsoft\Windows\INetCookies\Low\E4SXDE3M.txt C:\Users\ChiemMax\AppData\Local\Microsoft\Windows\INetCookies\Low\E5LV98C3.txt C:\Users\ChiemMax\AppData\Local\Microsoft\Windows\INetCookies\Low\E949NGH0.txt C:\Users\ChiemMax\AppData\Local\Microsoft\Windows\INetCookies\Low\EAGD91J3.txt C:\Users\ChiemMax\AppData\Local\Microsoft\Windows\INetCookies\Low\EBOOHBNC.txt C:\Users\ChiemMax\AppData\Local\Microsoft\Windows\INetCookies\Low\ED8M9FA8.txt C:\Users\ChiemMax\AppData\Local\Microsoft\Windows\INetCookies\Low\EF6X7Z0A.txt C:\Users\ChiemMax\AppData\Local\Microsoft\Windows\INetCookies\Low\ELMXYMWS.txt C:\Users\ChiemMax\AppData\Local\Microsoft\Windows\INetCookies\Low\ELW7XDM9.txt C:\Users\ChiemMax\AppData\Local\Microsoft\Windows\INetCookies\Low\EM48L2IQ.txt C:\Users\ChiemMax\AppData\Local\Microsoft\Windows\INetCookies\Low\EROFZ282.txt C:\Users\ChiemMax\AppData\Local\Microsoft\Windows\INetCookies\Low\ETFH1WWT.txt C:\Users\ChiemMax\AppData\Local\Microsoft\Windows\INetCookies\Low\EY4PWZ1Z.txt C:\Users\ChiemMax\AppData\Local\Microsoft\Windows\INetCookies\Low\F18WENAF.txt C:\Users\ChiemMax\AppData\Local\Microsoft\Windows\INetCookies\Low\F22DL8CC.txt C:\Users\ChiemMax\AppData\Local\Microsoft\Windows\INetCookies\Low\F5ISEAL2.txt C:\Users\ChiemMax\AppData\Local\Microsoft\Windows\INetCookies\Low\F7D8YD05.txt C:\Users\ChiemMax\AppData\Local\Microsoft\Windows\INetCookies\Low\F8ZQ4JA0.txt C:\Users\ChiemMax\AppData\Local\Microsoft\Windows\INetCookies\Low\FCA61UEZ.txt C:\Users\ChiemMax\AppData\Local\Microsoft\Windows\INetCookies\Low\FI5ZVY0V.txt C:\Users\ChiemMax\AppData\Local\Microsoft\Windows\INetCookies\Low\FIOT2STX.txt C:\Users\ChiemMax\AppData\Local\Microsoft\Windows\INetCookies\Low\FPM0ALK4.txt C:\Users\ChiemMax\AppData\Local\Microsoft\Windows\INetCookies\Low\FR1LJCC2.txt C:\Users\ChiemMax\AppData\Local\Microsoft\Windows\INetCookies\Low\FZX2YVJW.txt C:\Users\ChiemMax\AppData\Local\Microsoft\Windows\INetCookies\Low\G3Z4DMJ7.txt C:\Users\ChiemMax\AppData\Local\Microsoft\Windows\INetCookies\Low\G75GAJAL.txt C:\Users\ChiemMax\AppData\Local\Microsoft\Windows\INetCookies\Low\GFBBIQPA.txt C:\Users\ChiemMax\AppData\Local\Microsoft\Windows\INetCookies\Low\GS45OT4B.txt C:\Users\ChiemMax\AppData\Local\Microsoft\Windows\INetCookies\Low\GUF1IOU3.txt C:\Users\ChiemMax\AppData\Local\Microsoft\Windows\INetCookies\Low\GV5511I1.txt C:\Users\ChiemMax\AppData\Local\Microsoft\Windows\INetCookies\Low\H0ELSKSE.txt C:\Users\ChiemMax\AppData\Local\Microsoft\Windows\INetCookies\Low\H1Z60VOR.txt C:\Users\ChiemMax\AppData\Local\Microsoft\Windows\INetCookies\Low\H2F7BEBB.txt C:\Users\ChiemMax\AppData\Local\Microsoft\Windows\INetCookies\Low\H2LPYFRG.txt C:\Users\ChiemMax\AppData\Local\Microsoft\Windows\INetCookies\Low\H9O1QYQL.txt C:\Users\ChiemMax\AppData\Local\Microsoft\Windows\INetCookies\Low\H9TWP4V7.txt C:\Users\ChiemMax\AppData\Local\Microsoft\Windows\INetCookies\Low\HR9FJW7D.txt C:\Users\ChiemMax\AppData\Local\Microsoft\Windows\INetCookies\Low\HRQ0NM0Q.txt C:\Users\ChiemMax\AppData\Local\Microsoft\Windows\INetCookies\Low\HVMAODIB.txt C:\Users\ChiemMax\AppData\Local\Microsoft\Windows\INetCookies\Low\HVPW9Q3F.txt C:\Users\ChiemMax\AppData\Local\Microsoft\Windows\INetCookies\Low\I146MJKR.txt C:\Users\ChiemMax\AppData\Local\Microsoft\Windows\INetCookies\Low\I7GUPFLA.txt C:\Users\ChiemMax\AppData\Local\Microsoft\Windows\INetCookies\Low\IAJVHOO2.txt C:\Users\ChiemMax\AppData\Local\Microsoft\Windows\INetCookies\Low\IOYI42XA.txt C:\Users\ChiemMax\AppData\Local\Microsoft\Windows\INetCookies\Low\IZVIJLDA.txt C:\Users\ChiemMax\AppData\Local\Microsoft\Windows\INetCookies\Low\J6CMFIPS.txt C:\Users\ChiemMax\AppData\Local\Microsoft\Windows\INetCookies\Low\J6Z12APU.txt C:\Users\ChiemMax\AppData\Local\Microsoft\Windows\INetCookies\Low\J87PSM77.txt C:\Users\ChiemMax\AppData\Local\Microsoft\Windows\INetCookies\Low\JA86OXQN.txt C:\Users\ChiemMax\AppData\Local\Microsoft\Windows\INetCookies\Low\JABRLWZ1.txt C:\Users\ChiemMax\AppData\Local\Microsoft\Windows\INetCookies\Low\JI24B4GS.txt C:\Users\ChiemMax\AppData\Local\Microsoft\Windows\INetCookies\Low\JIE3BU7J.txt C:\Users\ChiemMax\AppData\Local\Microsoft\Windows\INetCookies\Low\JLEMTJ9L.txt C:\Users\ChiemMax\AppData\Local\Microsoft\Windows\INetCookies\Low\JRUHTKGA.txt C:\Users\ChiemMax\AppData\Local\Microsoft\Windows\INetCookies\Low\JTYHHWHB.txt C:\Users\ChiemMax\AppData\Local\Microsoft\Windows\INetCookies\Low\JWPBWTYT.txt C:\Users\ChiemMax\AppData\Local\Microsoft\Windows\INetCookies\Low\JWTQAPMM.txt C:\Users\ChiemMax\AppData\Local\Microsoft\Windows\INetCookies\Low\K0ABR5KW.txt C:\Users\ChiemMax\AppData\Local\Microsoft\Windows\INetCookies\Low\K4BNEYX0.txt C:\Users\ChiemMax\AppData\Local\Microsoft\Windows\INetCookies\Low\K80ZABNF.txt C:\Users\ChiemMax\AppData\Local\Microsoft\Windows\INetCookies\Low\KBHZ2I58.txt C:\Users\ChiemMax\AppData\Local\Microsoft\Windows\INetCookies\Low\KCQ5KJE2.txt C:\Users\ChiemMax\AppData\Local\Microsoft\Windows\INetCookies\Low\KKLAYSLL.txt C:\Users\ChiemMax\AppData\Local\Microsoft\Windows\INetCookies\Low\KLJ8XMUG.txt C:\Users\ChiemMax\AppData\Local\Microsoft\Windows\INetCookies\Low\KTNQQMJP.txt C:\Users\ChiemMax\AppData\Local\Microsoft\Windows\INetCookies\Low\KVPLDUMP.txt C:\Users\ChiemMax\AppData\Local\Microsoft\Windows\INetCookies\Low\KYYBSOEP.txt C:\Users\ChiemMax\AppData\Local\Microsoft\Windows\INetCookies\Low\KZLTXZBI.txt C:\Users\ChiemMax\AppData\Local\Microsoft\Windows\INetCookies\Low\KZY5BWVK.txt C:\Users\ChiemMax\AppData\Local\Microsoft\Windows\INetCookies\Low\L06ZJPCG.txt C:\Users\ChiemMax\AppData\Local\Microsoft\Windows\INetCookies\Low\L2EZZD3B.txt C:\Users\ChiemMax\AppData\Local\Microsoft\Windows\INetCookies\Low\L6YB9OXZ.txt C:\Users\ChiemMax\AppData\Local\Microsoft\Windows\INetCookies\Low\L7CV4ONW.txt C:\Users\ChiemMax\AppData\Local\Microsoft\Windows\INetCookies\Low\LOHBU086.txt C:\Users\ChiemMax\AppData\Local\Microsoft\Windows\INetCookies\Low\LOSK1KO8.txt C:\Users\ChiemMax\AppData\Local\Microsoft\Windows\INetCookies\Low\LTKBN1GD.txt C:\Users\ChiemMax\AppData\Local\Microsoft\Windows\INetCookies\Low\LWIF0UKV.txt C:\Users\ChiemMax\AppData\Local\Microsoft\Windows\INetCookies\Low\M16W7CWG.txt C:\Users\ChiemMax\AppData\Local\Microsoft\Windows\INetCookies\Low\M95B1WXY.txt C:\Users\ChiemMax\AppData\Local\Microsoft\Windows\INetCookies\Low\MAGNRMAJ.txt C:\Users\ChiemMax\AppData\Local\Microsoft\Windows\INetCookies\Low\MTV6VZYU.txt C:\Users\ChiemMax\AppData\Local\Microsoft\Windows\INetCookies\Low\MVCUT7KO.txt C:\Users\ChiemMax\AppData\Local\Microsoft\Windows\INetCookies\Low\MW2469NN.txt C:\Users\ChiemMax\AppData\Local\Microsoft\Windows\INetCookies\Low\MWCUW20D.txt C:\Users\ChiemMax\AppData\Local\Microsoft\Windows\INetCookies\Low\MZ8029SK.txt C:\Users\ChiemMax\AppData\Local\Microsoft\Windows\INetCookies\Low\N74VS0JQ.txt C:\Users\ChiemMax\AppData\Local\Microsoft\Windows\INetCookies\Low\ND6ZBDG3.txt C:\Users\ChiemMax\AppData\Local\Microsoft\Windows\INetCookies\Low\NG0GUIPB.txt C:\Users\ChiemMax\AppData\Local\Microsoft\Windows\INetCookies\Low\NKAS4YT5.txt C:\Users\ChiemMax\AppData\Local\Microsoft\Windows\INetCookies\Low\NS62FL1L.txt C:\Users\ChiemMax\AppData\Local\Microsoft\Windows\INetCookies\Low\NY53G1AA.txt C:\Users\ChiemMax\AppData\Local\Microsoft\Windows\INetCookies\Low\O5YC2FXZ.txt C:\Users\ChiemMax\AppData\Local\Microsoft\Windows\INetCookies\Low\OB08C1SP.txt C:\Users\ChiemMax\AppData\Local\Microsoft\Windows\INetCookies\Low\OCQJ7JR5.txt C:\Users\ChiemMax\AppData\Local\Microsoft\Windows\INetCookies\Low\OGHMBYCD.txt C:\Users\ChiemMax\AppData\Local\Microsoft\Windows\INetCookies\Low\OITXYY12.txt C:\Users\ChiemMax\AppData\Local\Microsoft\Windows\INetCookies\Low\OMD5Q26T.txt C:\Users\ChiemMax\AppData\Local\Microsoft\Windows\INetCookies\Low\OMMMJ59N.txt C:\Users\ChiemMax\AppData\Local\Microsoft\Windows\INetCookies\Low\ON5DWL03.txt C:\Users\ChiemMax\AppData\Local\Microsoft\Windows\INetCookies\Low\OOMC87JT.txt C:\Users\ChiemMax\AppData\Local\Microsoft\Windows\INetCookies\Low\OV40HF3K.txt C:\Users\ChiemMax\AppData\Local\Microsoft\Windows\INetCookies\Low\P6RMW1XY.txt C:\Users\ChiemMax\AppData\Local\Microsoft\Windows\INetCookies\Low\PAG582J9.txt C:\Users\ChiemMax\AppData\Local\Microsoft\Windows\INetCookies\Low\PL0YJPFR.txt C:\Users\ChiemMax\AppData\Local\Microsoft\Windows\INetCookies\Low\PLX3KQME.txt C:\Users\ChiemMax\AppData\Local\Microsoft\Windows\INetCookies\Low\PO8TCEPV.txt C:\Users\ChiemMax\AppData\Local\Microsoft\Windows\INetCookies\Low\PRDNK1PM.txt C:\Users\ChiemMax\AppData\Local\Microsoft\Windows\INetCookies\Low\Q34FNJV8.txt C:\Users\ChiemMax\AppData\Local\Microsoft\Windows\INetCookies\Low\Q9SHNMOJ.txt C:\Users\ChiemMax\AppData\Local\Microsoft\Windows\INetCookies\Low\QDAKN1M9.txt C:\Users\ChiemMax\AppData\Local\Microsoft\Windows\INetCookies\Low\QJB97ADU.txt C:\Users\ChiemMax\AppData\Local\Microsoft\Windows\INetCookies\Low\QKS74R21.txt C:\Users\ChiemMax\AppData\Local\Microsoft\Windows\INetCookies\Low\QQ283C00.txt C:\Users\ChiemMax\AppData\Local\Microsoft\Windows\INetCookies\Low\QQSQMUFO.txt C:\Users\ChiemMax\AppData\Local\Microsoft\Windows\INetCookies\Low\QRC5ACA0.txt C:\Users\ChiemMax\AppData\Local\Microsoft\Windows\INetCookies\Low\QUUL11F1.txt C:\Users\ChiemMax\AppData\Local\Microsoft\Windows\INetCookies\Low\RKDJ4D7N.txt C:\Users\ChiemMax\AppData\Local\Microsoft\Windows\INetCookies\Low\RNB0GK0Z.txt C:\Users\ChiemMax\AppData\Local\Microsoft\Windows\INetCookies\Low\SAMW6R5T.txt C:\Users\ChiemMax\AppData\Local\Microsoft\Windows\INetCookies\Low\SDYQQJ6D.txt C:\Users\ChiemMax\AppData\Local\Microsoft\Windows\INetCookies\Low\SHHGZGI0.txt C:\Users\ChiemMax\AppData\Local\Microsoft\Windows\INetCookies\Low\SJ4ZR8KA.txt C:\Users\ChiemMax\AppData\Local\Microsoft\Windows\INetCookies\Low\SL1DAE0F.txt C:\Users\ChiemMax\AppData\Local\Microsoft\Windows\INetCookies\Low\SP8PXDLS.txt C:\Users\ChiemMax\AppData\Local\Microsoft\Windows\INetCookies\Low\SPOO0OGB.txt C:\Users\ChiemMax\AppData\Local\Microsoft\Windows\INetCookies\Low\SXERD4QN.txt C:\Users\ChiemMax\AppData\Local\Microsoft\Windows\INetCookies\Low\T961UU5I.txt C:\Users\ChiemMax\AppData\Local\Microsoft\Windows\INetCookies\Low\TAY4S16T.txt C:\Users\ChiemMax\AppData\Local\Microsoft\Windows\INetCookies\Low\TBFTJMH8.txt C:\Users\ChiemMax\AppData\Local\Microsoft\Windows\INetCookies\Low\TDX2BPKP.txt C:\Users\ChiemMax\AppData\Local\Microsoft\Windows\INetCookies\Low\TGK20C82.txt C:\Users\ChiemMax\AppData\Local\Microsoft\Windows\INetCookies\Low\THH0ANKI.txt C:\Users\ChiemMax\AppData\Local\Microsoft\Windows\INetCookies\Low\TJU8BXRA.txt C:\Users\ChiemMax\AppData\Local\Microsoft\Windows\INetCookies\Low\TK1WDYK3.txt C:\Users\ChiemMax\AppData\Local\Microsoft\Windows\INetCookies\Low\TKHFKRPW.txt C:\Users\ChiemMax\AppData\Local\Microsoft\Windows\INetCookies\Low\TNCWB2UE.txt C:\Users\ChiemMax\AppData\Local\Microsoft\Windows\INetCookies\Low\TUH4VU8Z.txt C:\Users\ChiemMax\AppData\Local\Microsoft\Windows\INetCookies\Low\U2C3KS2R.txt C:\Users\ChiemMax\AppData\Local\Microsoft\Windows\INetCookies\Low\U3S2ZE0U.txt C:\Users\ChiemMax\AppData\Local\Microsoft\Windows\INetCookies\Low\U5XQ9E48.txt C:\Users\ChiemMax\AppData\Local\Microsoft\Windows\INetCookies\Low\U8EN7VBH.txt C:\Users\ChiemMax\AppData\Local\Microsoft\Windows\INetCookies\Low\UEGASMF5.txt C:\Users\ChiemMax\AppData\Local\Microsoft\Windows\INetCookies\Low\UQABQSDV.txt C:\Users\ChiemMax\AppData\Local\Microsoft\Windows\INetCookies\Low\UQU01NK3.txt C:\Users\ChiemMax\AppData\Local\Microsoft\Windows\INetCookies\Low\URAK054X.txt C:\Users\ChiemMax\AppData\Local\Microsoft\Windows\INetCookies\Low\V0UB4A5W.txt C:\Users\ChiemMax\AppData\Local\Microsoft\Windows\INetCookies\Low\V75EZM2Y.txt C:\Users\ChiemMax\AppData\Local\Microsoft\Windows\INetCookies\Low\VQOJF9LX.txt C:\Users\ChiemMax\AppData\Local\Microsoft\Windows\INetCookies\Low\VUXBJ78A.txt C:\Users\ChiemMax\AppData\Local\Microsoft\Windows\INetCookies\Low\VXPI19F6.txt C:\Users\ChiemMax\AppData\Local\Microsoft\Windows\INetCookies\Low\VZDI96GD.txt C:\Users\ChiemMax\AppData\Local\Microsoft\Windows\INetCookies\Low\VZOP7YI6.txt C:\Users\ChiemMax\AppData\Local\Microsoft\Windows\INetCookies\Low\W15OD2YI.txt C:\Users\ChiemMax\AppData\Local\Microsoft\Windows\INetCookies\Low\W3L7HX8V.txt C:\Users\ChiemMax\AppData\Local\Microsoft\Windows\INetCookies\Low\W41MTA0P.txt C:\Users\ChiemMax\AppData\Local\Microsoft\Windows\INetCookies\Low\W6A0MZC0.txt C:\Users\ChiemMax\AppData\Local\Microsoft\Windows\INetCookies\Low\W902UZ0A.txt C:\Users\ChiemMax\AppData\Local\Microsoft\Windows\INetCookies\Low\W9ZK990P.txt C:\Users\ChiemMax\AppData\Local\Microsoft\Windows\INetCookies\Low\WCNNPRA6.txt C:\Users\ChiemMax\AppData\Local\Microsoft\Windows\INetCookies\Low\WJN3FFPD.txt C:\Users\ChiemMax\AppData\Local\Microsoft\Windows\INetCookies\Low\WMFBUDSN.txt C:\Users\ChiemMax\AppData\Local\Microsoft\Windows\INetCookies\Low\WQKNJOHB.txt C:\Users\ChiemMax\AppData\Local\Microsoft\Windows\INetCookies\Low\WWG8WSAX.txt C:\Users\ChiemMax\AppData\Local\Microsoft\Windows\INetCookies\Low\WWKULJL0.txt C:\Users\ChiemMax\AppData\Local\Microsoft\Windows\INetCookies\Low\XFYPBJHL.txt C:\Users\ChiemMax\AppData\Local\Microsoft\Windows\INetCookies\Low\XJ2B3SY6.txt C:\Users\ChiemMax\AppData\Local\Microsoft\Windows\INetCookies\Low\Y0088MRK.txt C:\Users\ChiemMax\AppData\Local\Microsoft\Windows\INetCookies\Low\Y31QX2H7.txt C:\Users\ChiemMax\AppData\Local\Microsoft\Windows\INetCookies\Low\Y3I5OCI6.txt C:\Users\ChiemMax\AppData\Local\Microsoft\Windows\INetCookies\Low\Y3K0P4W3.txt C:\Users\ChiemMax\AppData\Local\Microsoft\Windows\INetCookies\Low\Y3XMCVRW.txt C:\Users\ChiemMax\AppData\Local\Microsoft\Windows\INetCookies\Low\Y4TUVNNK.txt C:\Users\ChiemMax\AppData\Local\Microsoft\Windows\INetCookies\Low\Y5QLEJ3D.txt C:\Users\ChiemMax\AppData\Local\Microsoft\Windows\INetCookies\Low\YCCZZ6EK.txt C:\Users\ChiemMax\AppData\Local\Microsoft\Windows\INetCookies\Low\YG46SPWQ.txt C:\Users\ChiemMax\AppData\Local\Microsoft\Windows\INetCookies\Low\YQRK5OXW.txt C:\Users\ChiemMax\AppData\Local\Microsoft\Windows\INetCookies\Low\YWWDSLKU.txt C:\Users\ChiemMax\AppData\Local\Microsoft\Windows\INetCookies\Low\YX2901S4.txt C:\Users\ChiemMax\AppData\Local\Microsoft\Windows\INetCookies\Low\YZCGU5ZG.txt C:\Users\ChiemMax\AppData\Local\Microsoft\Windows\INetCookies\Low\Z383KLBT.txt C:\Users\ChiemMax\AppData\Local\Microsoft\Windows\INetCookies\Low\Z54BW8EO.txt C:\Users\ChiemMax\AppData\Local\Microsoft\Windows\INetCookies\Low\Z8LS0VPV.txt C:\Users\ChiemMax\AppData\Local\Microsoft\Windows\INetCookies\Low\ZRABJ80K.txt C:\Users\ChiemMax\AppData\Local\Microsoft\Windows\INetCookies\Low\ZSDX6BA0.txt C:\Users\ChiemMax\AppData\Local\Microsoft\Windows\INetCookies\Low\ZVF9UMEW.txt C:\Users\ChiemMax\AppData\Local\Microsoft\Windows\INetCookies\Low\ZXB56SZ9.txt C:\Users\ChiemMax\AppData\Local\Microsoft\Windows\INetCookies\N6S78FJR.txt C:\Users\ChiemMax\AppData\Local\Microsoft\Windows\INetCookies\NNSAEOAV.txt C:\Users\ChiemMax\AppData\Local\Microsoft\Windows\INetCookies\NSCLIDVC.txt C:\Users\ChiemMax\AppData\Local\Microsoft\Windows\INetCookies\ORARZYO1.txt C:\Users\ChiemMax\AppData\Local\Microsoft\Windows\INetCookies\PK7ODPZD.txt C:\Users\ChiemMax\AppData\Local\Microsoft\Windows\INetCookies\SQAD1YAW.txt C:\Users\ChiemMax\AppData\Local\Microsoft\Windows\INetCookies\SQBGOL6D.txt C:\Users\ChiemMax\AppData\Local\Microsoft\Windows\INetCookies\SVWLUV3F.txt C:\Users\ChiemMax\AppData\Local\Microsoft\Windows\INetCookies\TDHIBI5O.txt C:\Users\ChiemMax\AppData\Local\Microsoft\Windows\INetCookies\TKS7W2OA.txt C:\Users\ChiemMax\AppData\Local\Microsoft\Windows\INetCookies\UJBFU09R.txt C:\Users\ChiemMax\AppData\Local\Microsoft\Windows\INetCookies\VSPQVIFK.txt C:\Users\ChiemMax\AppData\Local\Microsoft\Windows\INetCookies\Y6FCAIAW.txt C:\Users\ChiemMax\AppData\Local\Microsoft\Windows\INetCookies\ZWRYNIV0.txt C:\Users\ChiemMax\AppData\Roaming\Mozilla\Firefox\Profiles\y98f42bd.default-1475142416062\cookies.sqlite:200053012.log.optimizely.com C:\Users\ChiemMax\AppData\Roaming\Mozilla\Firefox\Profiles\y98f42bd.default-1475142416062\cookies.sqlite:2o7.net C:\Users\ChiemMax\AppData\Roaming\Mozilla\Firefox\Profiles\y98f42bd.default-1475142416062\cookies.sqlite:3135740712.log.optimizely.com C:\Users\ChiemMax\AppData\Roaming\Mozilla\Firefox\Profiles\y98f42bd.default-1475142416062\cookies.sqlite:998766.fls.doubleclick.net C:\Users\ChiemMax\AppData\Roaming\Mozilla\Firefox\Profiles\y98f42bd.default-1475142416062\cookies.sqlite:a.scorecardresearch.com C:\Users\ChiemMax\AppData\Roaming\Mozilla\Firefox\Profiles\y98f42bd.default-1475142416062\cookies.sqlite:abmr.net C:\Users\ChiemMax\AppData\Roaming\Mozilla\Firefox\Profiles\y98f42bd.default-1475142416062\cookies.sqlite:acuityplatform.com C:\Users\ChiemMax\AppData\Roaming\Mozilla\Firefox\Profiles\y98f42bd.default-1475142416062\cookies.sqlite:ad.360yield.com C:\Users\ChiemMax\AppData\Roaming\Mozilla\Firefox\Profiles\y98f42bd.default-1475142416062\cookies.sqlite:adadvisor.net C:\Users\ChiemMax\AppData\Roaming\Mozilla\Firefox\Profiles\y98f42bd.default-1475142416062\cookies.sqlite:adaptv.advertising.com C:\Users\ChiemMax\AppData\Roaming\Mozilla\Firefox\Profiles\y98f42bd.default-1475142416062\cookies.sqlite:adbrn.com C:\Users\ChiemMax\AppData\Roaming\Mozilla\Firefox\Profiles\y98f42bd.default-1475142416062\cookies.sqlite:addthis.com C:\Users\ChiemMax\AppData\Roaming\Mozilla\Firefox\Profiles\y98f42bd.default-1475142416062\cookies.sqlite:adfarm1.adition.com C:\Users\ChiemMax\AppData\Roaming\Mozilla\Firefox\Profiles\y98f42bd.default-1475142416062\cookies.sqlite:adform.net C:\Users\ChiemMax\AppData\Roaming\Mozilla\Firefox\Profiles\y98f42bd.default-1475142416062\cookies.sqlite:adgrx.com C:\Users\ChiemMax\AppData\Roaming\Mozilla\Firefox\Profiles\y98f42bd.default-1475142416062\cookies.sqlite:adhigh.net C:\Users\ChiemMax\AppData\Roaming\Mozilla\Firefox\Profiles\y98f42bd.default-1475142416062\cookies.sqlite:adingo.jp C:\Users\ChiemMax\AppData\Roaming\Mozilla\Firefox\Profiles\y98f42bd.default-1475142416062\cookies.sqlite:adnxs.com C:\Users\ChiemMax\AppData\Roaming\Mozilla\Firefox\Profiles\y98f42bd.default-1475142416062\cookies.sqlite:ads.avocet.io C:\Users\ChiemMax\AppData\Roaming\Mozilla\Firefox\Profiles\y98f42bd.default-1475142416062\cookies.sqlite:ads.creative-serving.com C:\Users\ChiemMax\AppData\Roaming\Mozilla\Firefox\Profiles\y98f42bd.default-1475142416062\cookies.sqlite:ads.deliverimp.com C:\Users\ChiemMax\AppData\Roaming\Mozilla\Firefox\Profiles\y98f42bd.default-1475142416062\cookies.sqlite:ads.kiosked.com C:\Users\ChiemMax\AppData\Roaming\Mozilla\Firefox\Profiles\y98f42bd.default-1475142416062\cookies.sqlite:ads.linkedin.com C:\Users\ChiemMax\AppData\Roaming\Mozilla\Firefox\Profiles\y98f42bd.default-1475142416062\cookies.sqlite:ads.nexage.com C:\Users\ChiemMax\AppData\Roaming\Mozilla\Firefox\Profiles\y98f42bd.default-1475142416062\cookies.sqlite:ads.pubmatic.com C:\Users\ChiemMax\AppData\Roaming\Mozilla\Firefox\Profiles\y98f42bd.default-1475142416062\cookies.sqlite:ads.stickyadstv.com C:\Users\ChiemMax\AppData\Roaming\Mozilla\Firefox\Profiles\y98f42bd.default-1475142416062\cookies.sqlite:ads.undertone.com C:\Users\ChiemMax\AppData\Roaming\Mozilla\Firefox\Profiles\y98f42bd.default-1475142416062\cookies.sqlite:adscale.de C:\Users\ChiemMax\AppData\Roaming\Mozilla\Firefox\Profiles\y98f42bd.default-1475142416062\cookies.sqlite:adsrvr.org C:\Users\ChiemMax\AppData\Roaming\Mozilla\Firefox\Profiles\y98f42bd.default-1475142416062\cookies.sqlite:adsymptotic.com C:\Users\ChiemMax\AppData\Roaming\Mozilla\Firefox\Profiles\y98f42bd.default-1475142416062\cookies.sqlite:adtech.de C:\Users\ChiemMax\AppData\Roaming\Mozilla\Firefox\Profiles\y98f42bd.default-1475142416062\cookies.sqlite:adtechjp.com C:\Users\ChiemMax\AppData\Roaming\Mozilla\Firefox\Profiles\y98f42bd.default-1475142416062\cookies.sqlite:adtechus.com C:\Users\ChiemMax\AppData\Roaming\Mozilla\Firefox\Profiles\y98f42bd.default-1475142416062\cookies.sqlite:advertising.com C:\Users\ChiemMax\AppData\Roaming\Mozilla\Firefox\Profiles\y98f42bd.default-1475142416062\cookies.sqlite:aexp.demdex.net C:\Users\ChiemMax\AppData\Roaming\Mozilla\Firefox\Profiles\y98f42bd.default-1475142416062\cookies.sqlite:agkn.com C:\Users\ChiemMax\AppData\Roaming\Mozilla\Firefox\Profiles\y98f42bd.default-1475142416062\cookies.sqlite:amgdgt.com C:\Users\ChiemMax\AppData\Roaming\Mozilla\Firefox\Profiles\y98f42bd.default-1475142416062\cookies.sqlite:angsrvr.com C:\Users\ChiemMax\AppData\Roaming\Mozilla\Firefox\Profiles\y98f42bd.default-1475142416062\cookies.sqlite:at.atwola.com C:\Users\ChiemMax\AppData\Roaming\Mozilla\Firefox\Profiles\y98f42bd.default-1475142416062\cookies.sqlite:atdmt.com C:\Users\ChiemMax\AppData\Roaming\Mozilla\Firefox\Profiles\y98f42bd.default-1475142416062\cookies.sqlite:atemda.com C:\Users\ChiemMax\AppData\Roaming\Mozilla\Firefox\Profiles\y98f42bd.default-1475142416062\cookies.sqlite:bankofamerica.tt.omtrdc.net C:\Users\ChiemMax\AppData\Roaming\Mozilla\Firefox\Profiles\y98f42bd.default-1475142416062\cookies.sqlite:basebanner.com C:\Users\ChiemMax\AppData\Roaming\Mozilla\Firefox\Profiles\y98f42bd.default-1475142416062\cookies.sqlite:bidr.io C:\Users\ChiemMax\AppData\Roaming\Mozilla\Firefox\Profiles\y98f42bd.default-1475142416062\cookies.sqlite:bidswitch.net C:\Users\ChiemMax\AppData\Roaming\Mozilla\Firefox\Profiles\y98f42bd.default-1475142416062\cookies.sqlite:bizrate.com C:\Users\ChiemMax\AppData\Roaming\Mozilla\Firefox\Profiles\y98f42bd.default-1475142416062\cookies.sqlite:bluekai.com C:\Users\ChiemMax\AppData\Roaming\Mozilla\Firefox\Profiles\y98f42bd.default-1475142416062\cookies.sqlite:bofa.demdex.net C:\Users\ChiemMax\AppData\Roaming\Mozilla\Firefox\Profiles\y98f42bd.default-1475142416062\cookies.sqlite:bs.serving-sys.com C:\Users\ChiemMax\AppData\Roaming\Mozilla\Firefox\Profiles\y98f42bd.default-1475142416062\cookies.sqlite:c.appier.net C:\Users\ChiemMax\AppData\Roaming\Mozilla\Firefox\Profiles\y98f42bd.default-1475142416062\cookies.sqlite:casalemedia.com C:\Users\ChiemMax\AppData\Roaming\Mozilla\Firefox\Profiles\y98f42bd.default-1475142416062\cookies.sqlite:chango.com C:\Users\ChiemMax\AppData\Roaming\Mozilla\Firefox\Profiles\y98f42bd.default-1475142416062\cookies.sqlite:collective-media.net C:\Users\ChiemMax\AppData\Roaming\Mozilla\Firefox\Profiles\y98f42bd.default-1475142416062\cookies.sqlite:comcast.demdex.net C:\Users\ChiemMax\AppData\Roaming\Mozilla\Firefox\Profiles\y98f42bd.default-1475142416062\cookies.sqlite:comcastathena.demdex.net C:\Users\ChiemMax\AppData\Roaming\Mozilla\Firefox\Profiles\y98f42bd.default-1475142416062\cookies.sqlite:connexity.net C:\Users\ChiemMax\AppData\Roaming\Mozilla\Firefox\Profiles\y98f42bd.default-1475142416062\cookies.sqlite:contextweb.com C:\Users\ChiemMax\AppData\Roaming\Mozilla\Firefox\Profiles\y98f42bd.default-1475142416062\cookies.sqlite:creditcards-com.demdex.net C:\Users\ChiemMax\AppData\Roaming\Mozilla\Firefox\Profiles\y98f42bd.default-1475142416062\cookies.sqlite:crwdcntrl.net C:\Users\ChiemMax\AppData\Roaming\Mozilla\Firefox\Profiles\y98f42bd.default-1475142416062\cookies.sqlite:ctnsnet.com C:\Users\ChiemMax\AppData\Roaming\Mozilla\Firefox\Profiles\y98f42bd.default-1475142416062\cookies.sqlite:cxense.com C:\Users\ChiemMax\AppData\Roaming\Mozilla\Firefox\Profiles\y98f42bd.default-1475142416062\cookies.sqlite:d.adroll.com C:\Users\ChiemMax\AppData\Roaming\Mozilla\Firefox\Profiles\y98f42bd.default-1475142416062\cookies.sqlite:demdex.net C:\Users\ChiemMax\AppData\Roaming\Mozilla\Firefox\Profiles\y98f42bd.default-1475142416062\cookies.sqlite:dish.demdex.net C:\Users\ChiemMax\AppData\Roaming\Mozilla\Firefox\Profiles\y98f42bd.default-1475142416062\cookies.sqlite:dmtry.com C:\Users\ChiemMax\AppData\Roaming\Mozilla\Firefox\Profiles\y98f42bd.default-1475142416062\cookies.sqlite:domdex.com C:\Users\ChiemMax\AppData\Roaming\Mozilla\Firefox\Profiles\y98f42bd.default-1475142416062\cookies.sqlite:dotomi.com C:\Users\ChiemMax\AppData\Roaming\Mozilla\Firefox\Profiles\y98f42bd.default-1475142416062\cookies.sqlite:doubleclick.net C:\Users\ChiemMax\AppData\Roaming\Mozilla\Firefox\Profiles\y98f42bd.default-1475142416062\cookies.sqlite:dpclk.com C:\Users\ChiemMax\AppData\Roaming\Mozilla\Firefox\Profiles\y98f42bd.default-1475142416062\cookies.sqlite:dpm.demdex.net C:\Users\ChiemMax\AppData\Roaming\Mozilla\Firefox\Profiles\y98f42bd.default-1475142416062\cookies.sqlite:dynamicyield.com C:\Users\ChiemMax\AppData\Roaming\Mozilla\Firefox\Profiles\y98f42bd.default-1475142416062\cookies.sqlite:erne.co C:\Users\ChiemMax\AppData\Roaming\Mozilla\Firefox\Profiles\y98f42bd.default-1475142416062\cookies.sqlite:everesttech.net C:\Users\ChiemMax\AppData\Roaming\Mozilla\Firefox\Profiles\y98f42bd.default-1475142416062\cookies.sqlite:eyereturn.com C:\Users\ChiemMax\AppData\Roaming\Mozilla\Firefox\Profiles\y98f42bd.default-1475142416062\cookies.sqlite:eyeviewads.com C:\Users\ChiemMax\AppData\Roaming\Mozilla\Firefox\Profiles\y98f42bd.default-1475142416062\cookies.sqlite:fastclick.net C:\Users\ChiemMax\AppData\Roaming\Mozilla\Firefox\Profiles\y98f42bd.default-1475142416062\cookies.sqlite:flashtalking.com C:\Users\ChiemMax\AppData\Roaming\Mozilla\Firefox\Profiles\y98f42bd.default-1475142416062\cookies.sqlite:ford.demdex.net C:\Users\ChiemMax\AppData\Roaming\Mozilla\Firefox\Profiles\y98f42bd.default-1475142416062\cookies.sqlite:go.flx1.com C:\Users\ChiemMax\AppData\Roaming\Mozilla\Firefox\Profiles\y98f42bd.default-1475142416062\cookies.sqlite:go.sonobi.com C:\Users\ChiemMax\AppData\Roaming\Mozilla\Firefox\Profiles\y98f42bd.default-1475142416062\cookies.sqlite:gssprt.jp C:\Users\ChiemMax\AppData\Roaming\Mozilla\Firefox\Profiles\y98f42bd.default-1475142416062\cookies.sqlite:gwallet.com C:\Users\ChiemMax\AppData\Roaming\Mozilla\Firefox\Profiles\y98f42bd.default-1475142416062\cookies.sqlite:ib.mookie1.com C:\Users\ChiemMax\AppData\Roaming\Mozilla\Firefox\Profiles\y98f42bd.default-1475142416062\cookies.sqlite:ih.adscale.de C:\Users\ChiemMax\AppData\Roaming\Mozilla\Firefox\Profiles\y98f42bd.default-1475142416062\cookies.sqlite:imrworldwide.com C:\Users\ChiemMax\AppData\Roaming\Mozilla\Firefox\Profiles\y98f42bd.default-1475142416062\cookies.sqlite:in.getclicky.com C:\Users\ChiemMax\AppData\Roaming\Mozilla\Firefox\Profiles\y98f42bd.default-1475142416062\cookies.sqlite:ipredictive.com C:\Users\ChiemMax\AppData\Roaming\Mozilla\Firefox\Profiles\y98f42bd.default-1475142416062\cookies.sqlite:kau.li C:\Users\ChiemMax\AppData\Roaming\Mozilla\Firefox\Profiles\y98f42bd.default-1475142416062\cookies.sqlite:korrelate.net C:\Users\ChiemMax\AppData\Roaming\Mozilla\Firefox\Profiles\y98f42bd.default-1475142416062\cookies.sqlite:krxd.net C:\Users\ChiemMax\AppData\Roaming\Mozilla\Firefox\Profiles\y98f42bd.default-1475142416062\cookies.sqlite:legolas-media.com C:\Users\ChiemMax\AppData\Roaming\Mozilla\Firefox\Profiles\y98f42bd.default-1475142416062\cookies.sqlite:lenovo.demdex.net C:\Users\ChiemMax\AppData\Roaming\Mozilla\Firefox\Profiles\y98f42bd.default-1475142416062\cookies.sqlite:lijit.com C:\Users\ChiemMax\AppData\Roaming\Mozilla\Firefox\Profiles\y98f42bd.default-1475142416062\cookies.sqlite:link.krxd.net C:\Users\ChiemMax\AppData\Roaming\Mozilla\Firefox\Profiles\y98f42bd.default-1475142416062\cookies.sqlite:liverail.com C:\Users\ChiemMax\AppData\Roaming\Mozilla\Firefox\Profiles\y98f42bd.default-1475142416062\cookies.sqlite:match.adsby.bidtheatre.com C:\Users\ChiemMax\AppData\Roaming\Mozilla\Firefox\Profiles\y98f42bd.default-1475142416062\cookies.sqlite:match.rundsp.com C:\Users\ChiemMax\AppData\Roaming\Mozilla\Firefox\Profiles\y98f42bd.default-1475142416062\cookies.sqlite:mathtag.com C:\Users\ChiemMax\AppData\Roaming\Mozilla\Firefox\Profiles\y98f42bd.default-1475142416062\cookies.sqlite:media6degrees.com C:\Users\ChiemMax\AppData\Roaming\Mozilla\Firefox\Profiles\y98f42bd.default-1475142416062\cookies.sqlite:mediaplex.com C:\Users\ChiemMax\AppData\Roaming\Mozilla\Firefox\Profiles\y98f42bd.default-1475142416062\cookies.sqlite:ml314.com C:\Users\ChiemMax\AppData\Roaming\Mozilla\Firefox\Profiles\y98f42bd.default-1475142416062\cookies.sqlite:mookie1.com C:\Users\ChiemMax\AppData\Roaming\Mozilla\Firefox\Profiles\y98f42bd.default-1475142416062\cookies.sqlite:mxptint.net C:\Users\ChiemMax\AppData\Roaming\Mozilla\Firefox\Profiles\y98f42bd.default-1475142416062\cookies.sqlite:nbcu.demdex.net C:\Users\ChiemMax\AppData\Roaming\Mozilla\Firefox\Profiles\y98f42bd.default-1475142416062\cookies.sqlite:nbcuni.demdex.net C:\Users\ChiemMax\AppData\Roaming\Mozilla\Firefox\Profiles\y98f42bd.default-1475142416062\cookies.sqlite:nexac.com C:\Users\ChiemMax\AppData\Roaming\Mozilla\Firefox\Profiles\y98f42bd.default-1475142416062\cookies.sqlite:openx.net C:\Users\ChiemMax\AppData\Roaming\Mozilla\Firefox\Profiles\y98f42bd.default-1475142416062\cookies.sqlite:optimatic.com C:\Users\ChiemMax\AppData\Roaming\Mozilla\Firefox\Profiles\y98f42bd.default-1475142416062\cookies.sqlite:outbrain.com C:\Users\ChiemMax\AppData\Roaming\Mozilla\Firefox\Profiles\y98f42bd.default-1475142416062\cookies.sqlite:owneriq.net C:\Users\ChiemMax\AppData\Roaming\Mozilla\Firefox\Profiles\y98f42bd.default-1475142416062\cookies.sqlite:pagefair.com C:\Users\ChiemMax\AppData\Roaming\Mozilla\Firefox\Profiles\y98f42bd.default-1475142416062\cookies.sqlite:pixel-a.sitescout.com C:\Users\ChiemMax\AppData\Roaming\Mozilla\Firefox\Profiles\y98f42bd.default-1475142416062\cookies.sqlite:pixel.rubiconproject.com C:\Users\ChiemMax\AppData\Roaming\Mozilla\Firefox\Profiles\y98f42bd.default-1475142416062\cookies.sqlite:pixel.sitescout.com C:\Users\ChiemMax\AppData\Roaming\Mozilla\Firefox\Profiles\y98f42bd.default-1475142416062\cookies.sqlite:po.st C:\Users\ChiemMax\AppData\Roaming\Mozilla\Firefox\Profiles\y98f42bd.default-1475142416062\cookies.sqlite:pool.admedo.com C:\Users\ChiemMax\AppData\Roaming\Mozilla\Firefox\Profiles\y98f42bd.default-1475142416062\cookies.sqlite:postrelease.com C:\Users\ChiemMax\AppData\Roaming\Mozilla\Firefox\Profiles\y98f42bd.default-1475142416062\cookies.sqlite:pswec.com C:\Users\ChiemMax\AppData\Roaming\Mozilla\Firefox\Profiles\y98f42bd.default-1475142416062\cookies.sqlite:pubmatic.com C:\Users\ChiemMax\AppData\Roaming\Mozilla\Firefox\Profiles\y98f42bd.default-1475142416062\cookies.sqlite:revsci.net C:\Users\ChiemMax\AppData\Roaming\Mozilla\Firefox\Profiles\y98f42bd.default-1475142416062\cookies.sqlite:rfihub.com C:\Users\ChiemMax\AppData\Roaming\Mozilla\Firefox\Profiles\y98f42bd.default-1475142416062\cookies.sqlite:rlcdn.com C:\Users\ChiemMax\AppData\Roaming\Mozilla\Firefox\Profiles\y98f42bd.default-1475142416062\cookies.sqlite:ru4.com C:\Users\ChiemMax\AppData\Roaming\Mozilla\Firefox\Profiles\y98f42bd.default-1475142416062\cookies.sqlite:rubiconproject.com C:\Users\ChiemMax\AppData\Roaming\Mozilla\Firefox\Profiles\y98f42bd.default-1475142416062\cookies.sqlite:sa.scorecardresearch.com C:\Users\ChiemMax\AppData\Roaming\Mozilla\Firefox\Profiles\y98f42bd.default-1475142416062\cookies.sqlite:samsungelectronicsamericainc.demdex.net C:\Users\ChiemMax\AppData\Roaming\Mozilla\Firefox\Profiles\y98f42bd.default-1475142416062\cookies.sqlite:scorecardresearch.com C:\Users\ChiemMax\AppData\Roaming\Mozilla\Firefox\Profiles\y98f42bd.default-1475142416062\cookies.sqlite:servesharp.net C:\Users\ChiemMax\AppData\Roaming\Mozilla\Firefox\Profiles\y98f42bd.default-1475142416062\cookies.sqlite:serving-sys.com C:\Users\ChiemMax\AppData\Roaming\Mozilla\Firefox\Profiles\y98f42bd.default-1475142416062\cookies.sqlite:simpli.fi C:\Users\ChiemMax\AppData\Roaming\Mozilla\Firefox\Profiles\y98f42bd.default-1475142416062\cookies.sqlite:sitescout.com C:\Users\ChiemMax\AppData\Roaming\Mozilla\Firefox\Profiles\y98f42bd.default-1475142416062\cookies.sqlite:skimresources.com C:\Users\ChiemMax\AppData\Roaming\Mozilla\Firefox\Profiles\y98f42bd.default-1475142416062\cookies.sqlite:smartadserver.com C:\Users\ChiemMax\AppData\Roaming\Mozilla\Firefox\Profiles\y98f42bd.default-1475142416062\cookies.sqlite:survey.g.doubleclick.net C:\Users\ChiemMax\AppData\Roaming\Mozilla\Firefox\Profiles\y98f42bd.default-1475142416062\cookies.sqlite:swid.switchads.com C:\Users\ChiemMax\AppData\Roaming\Mozilla\Firefox\Profiles\y98f42bd.default-1475142416062\cookies.sqlite:sxp.smartclip.net C:\Users\ChiemMax\AppData\Roaming\Mozilla\Firefox\Profiles\y98f42bd.default-1475142416062\cookies.sqlite:taboola.com C:\Users\ChiemMax\AppData\Roaming\Mozilla\Firefox\Profiles\y98f42bd.default-1475142416062\cookies.sqlite:tags.bluekai.com C:\Users\ChiemMax\AppData\Roaming\Mozilla\Firefox\Profiles\y98f42bd.default-1475142416062\cookies.sqlite:tap-t.rubiconproject.com C:\Users\ChiemMax\AppData\Roaming\Mozilla\Firefox\Profiles\y98f42bd.default-1475142416062\cookies.sqlite:tap.rubiconproject.com C:\Users\ChiemMax\AppData\Roaming\Mozilla\Firefox\Profiles\y98f42bd.default-1475142416062\cookies.sqlite:tap2-cdn.rubiconproject.com C:\Users\ChiemMax\AppData\Roaming\Mozilla\Firefox\Profiles\y98f42bd.default-1475142416062\cookies.sqlite:tapad.com C:\Users\ChiemMax\AppData\Roaming\Mozilla\Firefox\Profiles\y98f42bd.default-1475142416062\cookies.sqlite:tdameritrade.demdex.net C:\Users\ChiemMax\AppData\Roaming\Mozilla\Firefox\Profiles\y98f42bd.default-1475142416062\cookies.sqlite:tidaltv.com C:\Users\ChiemMax\AppData\Roaming\Mozilla\Firefox\Profiles\y98f42bd.default-1475142416062\cookies.sqlite:trc.taboola.com C:\Users\ChiemMax\AppData\Roaming\Mozilla\Firefox\Profiles\y98f42bd.default-1475142416062\cookies.sqlite:tremorhub.com C:\Users\ChiemMax\AppData\Roaming\Mozilla\Firefox\Profiles\y98f42bd.default-1475142416062\cookies.sqlite:tribalfusion.com C:\Users\ChiemMax\AppData\Roaming\Mozilla\Firefox\Profiles\y98f42bd.default-1475142416062\cookies.sqlite:tubemogul.com C:\Users\ChiemMax\AppData\Roaming\Mozilla\Firefox\Profiles\y98f42bd.default-1475142416062\cookies.sqlite:turn.com C:\Users\ChiemMax\AppData\Roaming\Mozilla\Firefox\Profiles\y98f42bd.default-1475142416062\cookies.sqlite:univide.com C:\Users\ChiemMax\AppData\Roaming\Mozilla\Firefox\Profiles\y98f42bd.default-1475142416062\cookies.sqlite:vindicosuite.com C:\Users\ChiemMax\AppData\Roaming\Mozilla\Firefox\Profiles\y98f42bd.default-1475142416062\cookies.sqlite:virool.com C:\Users\ChiemMax\AppData\Roaming\Mozilla\Firefox\Profiles\y98f42bd.default-1475142416062\cookies.sqlite:visualdna.com C:\Users\ChiemMax\AppData\Roaming\Mozilla\Firefox\Profiles\y98f42bd.default-1475142416062\cookies.sqlite:vivaki.demdex.net C:\Users\ChiemMax\AppData\Roaming\Mozilla\Firefox\Profiles\y98f42bd.default-1475142416062\cookies.sqlite:vizu.com C:\Users\ChiemMax\AppData\Roaming\Mozilla\Firefox\Profiles\y98f42bd.default-1475142416062\cookies.sqlite:w55c.net C:\Users\ChiemMax\AppData\Roaming\Mozilla\Firefox\Profiles\y98f42bd.default-1475142416062\cookies.sqlite:wtp101.com C:\Users\ChiemMax\AppData\Roaming\Mozilla\Firefox\Profiles\y98f42bd.default-1475142416062\cookies.sqlite:xfinitydigital.demdex.net C:\Users\ChiemMax\AppData\Roaming\Mozilla\Firefox\Profiles\y98f42bd.default-1475142416062\cookies.sqlite:zedo.com
  7. Thank you. I unpinned them from the task bar and also deleted the shortcuts on my desktop and made new ones. Now it is fixed. Is everything done? Am I okay to delete all the software programs you told me to download to scan my laptop? Everything is back to normal. It doesn't go to yourconnectivity.net anymore and also I haven't experienced any pop ups.
  8. Please let me know what else I need to do. Thank you.
  9. Fix result of Farbar Recovery Scan Tool (x64) Version: 04-10-2016 Ran by ChiemMax (06-10-2016 16:59:17) Run:2 Running from C:\Users\ChiemMax\Desktop Loaded Profiles: ChiemMax (Available Profiles: ChiemMax & Kao & Guest) Boot Mode: Normal ============================================== fixlist content: ***************** start CreateRestorePoint: CloseProcesses: DeleteKey: HKLM\SOFTWARE\Classes\cpbrkpie.Coupon6Ctrl.1 DeleteKey: HKLM\SOFTWARE\Classes\P78f2079a_7049_47b3_897f_9fbc294bb718_.P78f2079a_7049_47b3_897f_9fbc294bb718_ DeleteKey: HKLM\SOFTWARE\Classes\P78f2079a_7049_47b3_897f_9fbc294bb718_.P78f2079a_7049_47b3_897f_9fbc294bb718_.9 DeleteKey: HKLM\SOFTWARE\Classes\Toolbar3.CustomInternetSecurityImpl DeleteKey: HKLM\SOFTWARE\Classes\Toolbar3.CustomInternetSecurityImpl.1 DeleteKey: HKLM\SOFTWARE\Classes\Toolbar3.SearchProviderManager DeleteKey: HKLM\SOFTWARE\Classes\Toolbar3.SearchProviderManager.1 end ***************** Restore point was successfully created. Processes closed successfully. HKLM\SOFTWARE\Classes\cpbrkpie.Coupon6Ctrl.1 => could not remove at first attempt (ErrorCode: C0000121), see next line. HKLM\SOFTWARE\Classes\cpbrkpie.Coupon6Ctrl.1 => key removed successfully HKLM\SOFTWARE\Classes\P78f2079a_7049_47b3_897f_9fbc294bb718_.P78f2079a_7049_47b3_897f_9fbc294bb718_ => could not remove at first attempt (ErrorCode: C0000121), see next line. HKLM\SOFTWARE\Classes\P78f2079a_7049_47b3_897f_9fbc294bb718_.P78f2079a_7049_47b3_897f_9fbc294bb718_ => key removed successfully HKLM\SOFTWARE\Classes\P78f2079a_7049_47b3_897f_9fbc294bb718_.P78f2079a_7049_47b3_897f_9fbc294bb718_.9 => could not remove at first attempt (ErrorCode: C0000121), see next line. HKLM\SOFTWARE\Classes\P78f2079a_7049_47b3_897f_9fbc294bb718_.P78f2079a_7049_47b3_897f_9fbc294bb718_.9 => key removed successfully HKLM\SOFTWARE\Classes\Toolbar3.CustomInternetSecurityImpl => could not remove at first attempt (ErrorCode: C0000121), see next line. HKLM\SOFTWARE\Classes\Toolbar3.CustomInternetSecurityImpl => key removed successfully HKLM\SOFTWARE\Classes\Toolbar3.CustomInternetSecurityImpl.1 => could not remove at first attempt (ErrorCode: C0000121), see next line. HKLM\SOFTWARE\Classes\Toolbar3.CustomInternetSecurityImpl.1 => key removed successfully HKLM\SOFTWARE\Classes\Toolbar3.SearchProviderManager => could not remove at first attempt (ErrorCode: C0000121), see next line. HKLM\SOFTWARE\Classes\Toolbar3.SearchProviderManager => key removed successfully HKLM\SOFTWARE\Classes\Toolbar3.SearchProviderManager.1 => could not remove at first attempt (ErrorCode: C0000121), see next line. HKLM\SOFTWARE\Classes\Toolbar3.SearchProviderManager.1 => key removed successfully The system needed a reboot. ==== End of Fixlog 17:00:44 ====
  10. Index of file:///C:/Program Files (x86)/Mozilla Firefox/ This pops up when I open mozilla from my desktop.
  11. When I open Mozilla firefox, the program files(x86)/mozillafirefox opens up. Same thing with Google Chrome.
  12. That's all of the scans. Can I delete all of the programs you told me to download?
  13. ~ ZHPCleaner v2016.10.3.155 by Nicolas Coolman (2016/10/03) ~ Run by ChiemMax (Administrator) (03/10/2016 15:54:04) ~ Web: https://www.nicolascoolman.com ~ Blog: https://www.anti-malware.top ~ Facebook : https://www.facebook.com/nicolascoolman1 ~ State version : Version OK ~ Type : Scan ~ Report : C:\Users\ChiemMax\Desktop\ZHPCleaner.txt ~ Quarantine : C:\Users\ChiemMax\AppData\Roaming\ZHP\ZHPCleaner_Quarantine.txt ~ UAC : Activate ~ Boot Mode : Normal (Normal boot) Windows 10 Home, 64-bit (Build 14393) ---\\ Services (0) ~ No malicious or unnecessary items found. ---\\ Browser internet (0) ~ No malicious or unnecessary items found. ---\\ Hosts file (1) ~ The hosts file is legitimate (21) ---\\ Scheduled automatic tasks. (0) ~ No malicious or unnecessary items found. ---\\ Explorer ( File, Folder) (13) FOUND file: C:\Windows\Installer\wix{3540181E-340A-4E7A-B409-31663472B2F7}.SchedServiceConfig.rmi =>.Superfluous.Empty FOUND file: C:\Windows\Installer\wix{787136D2-F0F8-4625-AA3F-72D7795AC842}.SchedServiceConfig.rmi =>.Superfluous.Empty FOUND file: C:\Windows\Installer\wix{BDD99690-3541-4619-9D2A-3CDDB3E15F9E}.SchedServiceConfig.rmi =>.Superfluous.Empty FOUND file: C:\Windows\Installer\wix{F4404AFD-2EF3-40C1-8C09-29E5F3B6972B}.SchedServiceConfig.rmi =>.Superfluous.Empty FOUND folder: C:\Program Files (x86)\QuickTime =>Riskware.QuickTime FOUND folder: C:\WINDOWS\Installer\MSI6F23.tmp- =>.Superfluous.Empty FOUND folder: C:\WINDOWS\Installer\MSI76C5.tmp- =>.Superfluous.Empty FOUND folder: C:\WINDOWS\Installer\MSI7F30.tmp- =>.Superfluous.Empty FOUND folder: C:\WINDOWS\Installer\MSI81E1.tmp- =>.Superfluous.Empty FOUND folder: C:\WINDOWS\Installer\MSIA56B.tmp- =>.Superfluous.Empty FOUND folder: C:\WINDOWS\Installer\MSIB3D0.tmp- =>.Superfluous.Empty FOUND folder: C:\WINDOWS\Installer\MSIB6EE.tmp- =>.Superfluous.Empty FOUND folder: C:\WINDOWS\Installer\MSIB700.tmp- =>.Superfluous.Empty ---\\ Registry ( Key, Value, Data) (9) FOUND value: HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\\QuickTime Task ["C:\Program Files (x86)\QuickTime\QTTask.exe" -atboottime] =>Riskware.QuickTime FOUND key: [X64] HKLM\SOFTWARE\Classes\cpbrkpie.Coupon6Ctrl.1 [cpbrkpie Control] =>PUP.Optional.CouponBar FOUND key: [X64] HKLM\SOFTWARE\Classes\P78f2079a_7049_47b3_897f_9fbc294bb718_.P78f2079a_7049_47b3_897f_9fbc294bb718_ [youtubeadblocker] =>PUP.Optional.Multiplug FOUND key: [X64] HKLM\SOFTWARE\Classes\P78f2079a_7049_47b3_897f_9fbc294bb718_.P78f2079a_7049_47b3_897f_9fbc294bb718_.9 [youtubeadblocker] =>PUP.Optional.Multiplug FOUND key: [X64] HKLM\SOFTWARE\Classes\Toolbar3.CustomInternetSecurityImpl [CustomInternetSecurityImpl Class] =>PUP.Optional.BestToolbars FOUND key: [X64] HKLM\SOFTWARE\Classes\Toolbar3.CustomInternetSecurityImpl.1 [CustomInternetSecurityImpl Class] =>PUP.Optional.BestToolbars FOUND key: [X64] HKLM\SOFTWARE\Classes\Toolbar3.SearchProviderManager [SearchProviderManager Class] =>PUP.Optional.BestToolbars FOUND key: [X64] HKLM\SOFTWARE\Classes\Toolbar3.SearchProviderManager.1 [SearchProviderManager Class] =>PUP.Optional.BestToolbars FOUND key: [X64] HKLM\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Uninstall\{A92DAB39-4E2C-4304-9AB6-BC44E68B55E2} [Google Inc.] =>Heuristic.Suspect ---\\ Summary of the elements found (6) https://www.nicolascoolman.com/fr/logiciels-superflus =>.Superfluous.Empty https://www.anti-malware.top/2016/04/21/riskware-quicktime/ =>Riskware.QuickTime https://www.nicolascoolman.com/fr/pup-couponbar/ =>PUP.Optional.CouponBar https://www.anti-malware.top/2016/04/28/pup-optional-multiplug/ =>PUP.Optional.Multiplug https://www.nicolascoolman.com/fr/repaquetage-et_infections/ =>PUP.Optional.BestToolbars https://www.anti-malware.top/2016/04/22/heuristic-suspect/ =>Heuristic.Suspect ---\\ Result of repair ~ Any repair made ~ Browser not found (Opera Software) ---\\ Statistics ~ Items scanned : 90180 ~ Items found : 22 ~ Items cancelled : 0 ~ Items repaired : 0 ~ End of search in 00h05mn05s ~==================== ZHPCleaner--03102016-15_59_09.txt
  14. ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~ Junkware Removal Tool (JRT) by Malwarebytes Version: 8.0.8 (09.20.2016) Operating System: Windows 10 Home x64 Ran by ChiemMax (Administrator) on Mon 10/03/2016 at 15:46:52.08 ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~ File System: 1 Successfully deleted: C:\WINDOWS\couponprinter.ocx (File) Registry: 1 Successfully deleted: HKCU\Software\Microsoft\Internet Explorer\SearchScopes\{25A670C9-D00F-49EC-978F-E37C2C7EB4B2} (Registry Key) ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~ Scan was completed on Mon 10/03/2016 at 15:49:57.06 End of JRT log ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
Back to top
×
×
  • Create New...

Important Information

This site uses cookies - We have placed cookies on your device to help make this website better. You can adjust your cookie settings, otherwise we'll assume you're okay to continue.