Check-up
Results of screen317's Security Check version 0.99.7
Windows XP Service Pack 3
Internet Explorer 8
``````````````````````````````
Antivirus/Firewall Check:
Windows Firewall Enabled!
```````````````````````````````
Anti-malware/Other Utilities Check:
Malwarebytes' Anti-Malware
Java 6 Update 20
Out of date Java installed!
Adobe Flash Player 10.3.181.26
Adobe Reader 9
Out of date Adobe Reader installed!
Mozilla Firefox (x86 en-US..)
Firefox Out of Date!
````````````````````````````````
Process Check:
objlist.exe by Laurent
``````````End of Log````````````
Minitoolbox
MiniToolBox by Farbar
Ran by Steph (administrator) on 09-07-2011 at 11:06:17
Microsoft Windows XP Service Pack 3 (X86)
***************************************************************************
========================= IE Proxy Settings: ==============================
Proxy is not enabled.
No Proxy Server is set.
========================= End of IE Proxy Settings ========================
=============== Hosts content: ============================================
# Copyright © 1993-1999 Microsoft Corp.
#
# This is a sample HOSTS file used by Microsoft TCP/IP for Windows.
#
# This file contains the mappings of IP addresses to host names. Each
# entry should be kept on an individual line. The IP address should
# be placed in the first column followed by the corresponding host name.
# The IP address and the host name should be separated by at least one
# space.
#
# Additionally, comments (such as these) may be inserted on individual
# lines or following the machine name denoted by a '#' symbol.
#
# For example:
#
# 102.54.94.97 rhino.acme.com # source server
# 38.25.63.10 x.acme.com # x client host
127.0.0.1 localhost
=============== End of Hosts ==============================================
================= IP Configuration: =======================================
# ----------------------------------
# Interface IP Configuration
# ----------------------------------
pushd interface ip
# Interface IP Configuration for "Hamachi"
set address name="Hamachi" source=dhcp
set dns name="Hamachi" source=dhcp register=NONE
set wins name="Hamachi" source=dhcp
# Interface IP Configuration for "Wireless Network Connection"
set address name="Wireless Network Connection" source=dhcp
set dns name="Wireless Network Connection" source=dhcp register=PRIMARY
set wins name="Wireless Network Connection" source=dhcp
# Interface IP Configuration for "Local Area Connection"
set address name="Local Area Connection" source=static addr=192.168.0.1 mask=255.255.255.0
set dns name="Local Area Connection" source=static addr=none register=PRIMARY
set wins name="Local Area Connection" source=static addr=none
popd
# End of interface IP configuration
Windows IP Configuration
Host Name . . . . . . . . . . . . : STEPHANIE
Primary Dns Suffix . . . . . . . :
Node Type . . . . . . . . . . . . : Hybrid
IP Routing Enabled. . . . . . . . : Yes
WINS Proxy Enabled. . . . . . . . : No
Ethernet adapter Hamachi:
Connection-specific DNS Suffix . :
Description . . . . . . . . . . . : Hamachi Network Interface
Physical Address. . . . . . . . . : 00-23-C3-3B-0D-C8
Dhcp Enabled. . . . . . . . . . . : Yes
Autoconfiguration Enabled . . . . : No
IP Address. . . . . . . . . . . . : 5.59.13.200
Subnet Mask . . . . . . . . . . . : 255.0.0.0
Default Gateway . . . . . . . . . :
DHCP Server . . . . . . . . . . . : 5.0.0.1
Lease Obtained. . . . . . . . . . : Saturday, July 09, 2011 10:50:42 AM
Lease Expires . . . . . . . . . . : Sunday, July 08, 2012 10:50:42 AM
Ethernet adapter Wireless Network Connection:
Connection-specific DNS Suffix . :
Description . . . . . . . . . . . : Atheros AR5007EG Wireless Network Adapter
Physical Address. . . . . . . . . : 00-24-2B-0A-F6-23
Dhcp Enabled. . . . . . . . . . . : Yes
Autoconfiguration Enabled . . . . : Yes
IP Address. . . . . . . . . . . . : 10.0.0.7
Subnet Mask . . . . . . . . . . . : 255.255.255.0
Default Gateway . . . . . . . . . : 10.0.0.1
DHCP Server . . . . . . . . . . . : 10.0.0.1
DNS Servers . . . . . . . . . . . : 10.0.0.1
Lease Obtained. . . . . . . . . . : Saturday, July 09, 2011 10:48:44 AM
Lease Expires . . . . . . . . . . : Sunday, July 10, 2011 10:48:44 AM
Ethernet adapter Local Area Connection:
Media State . . . . . . . . . . . : Media disconnected
Description . . . . . . . . . . . : Realtek RTL8102E Family PCI-E Fast Ethernet NIC
Physical Address. . . . . . . . . : 00-23-8B-3F-10-AD
Server: UnKnown
Address: 10.0.0.1
Name: google.com
Addresses: 74.125.224.148, 74.125.224.144, 74.125.224.147, 74.125.224.146
74.125.224.145
Pinging google.com [74.125.224.114] with 32 bytes of data:
Reply from 74.125.224.114: bytes=32 time=18ms TTL=55
Reply from 74.125.224.114: bytes=32 time=35ms TTL=55
Ping statistics for 74.125.224.114:
Packets: Sent = 2, Received = 2, Lost = 0 (0% loss),
Approximate round trip times in milli-seconds:
Minimum = 18ms, Maximum = 35ms, Average = 26ms
Server: UnKnown
Address: 10.0.0.1
Name: yahoo.com
Addresses: 69.147.125.65, 72.30.2.43, 98.137.149.56, 209.191.122.70
67.195.160.76
Pinging yahoo.com [98.137.149.56] with 32 bytes of data:
Reply from 98.137.149.56: bytes=32 time=21ms TTL=53
Reply from 98.137.149.56: bytes=32 time=18ms TTL=53
Ping statistics for 98.137.149.56:
Packets: Sent = 2, Received = 2, Lost = 0 (0% loss),
Approximate round trip times in milli-seconds:
Minimum = 18ms, Maximum = 21ms, Average = 19ms
Pinging 127.0.0.1 with 32 bytes of data:
Reply from 127.0.0.1: bytes=32 time<1ms TTL=128
Reply from 127.0.0.1: bytes=32 time<1ms TTL=128
Ping statistics for 127.0.0.1:
Packets: Sent = 2, Received = 2, Lost = 0 (0% loss),
Approximate round trip times in milli-seconds:
Minimum = 0ms, Maximum = 0ms, Average = 0ms
===========================================================================
Interface List
0x1 ........................... MS TCP Loopback interface
0x2 ...00 23 c3 3b 0d c8 ...... Hamachi Network Interface
0x3 ...00 24 2b 0a f6 23 ...... Atheros AR5007EG Wireless Network Adapter - Packet Scheduler Miniport
0x4 ...00 23 8b 3f 10 ad ...... Realtek RTL8102E Family PCI-E Fast Ethernet NIC - Packet Scheduler Miniport
===========================================================================
===========================================================================
Active Routes:
Network Destination Netmask Gateway Interface Metric
0.0.0.0 0.0.0.0 10.0.0.1 10.0.0.7 25
5.0.0.0 255.0.0.0 5.59.13.200 5.59.13.200 20
5.59.13.200 255.255.255.255 127.0.0.1 127.0.0.1 20
5.255.255.255 255.255.255.255 5.59.13.200 5.59.13.200 20
10.0.0.0 255.255.255.0 10.0.0.7 10.0.0.7 25
10.0.0.7 255.255.255.255 127.0.0.1 127.0.0.1 25
10.255.255.255 255.255.255.255 10.0.0.7 10.0.0.7 25
127.0.0.0 255.0.0.0 127.0.0.1 127.0.0.1 1
169.254.0.0 255.255.0.0 10.0.0.7 10.0.0.7 20
224.0.0.0 240.0.0.0 5.59.13.200 5.59.13.200 20
224.0.0.0 240.0.0.0 10.0.0.7 10.0.0.7 25
255.255.255.255 255.255.255.255 5.59.13.200 5.59.13.200 1
255.255.255.255 255.255.255.255 10.0.0.7 4 1
255.255.255.255 255.255.255.255 10.0.0.7 10.0.0.7 1
Default Gateway: 10.0.0.1
===========================================================================
Persistent Routes:
None
================= End of IP Configuration =================================
========================= Event log errors: ===============================
Application errors:
==================
Error: (07/08/2011 10:19:12 PM) (Source: Application Error) (User: )
Description: Faulting application iexplore.exe, version 8.0.6001.18702, faulting module mshtml.dll, version 8.0.6001.19088, fault address 0x0008d944.
Processing media-specific event for [iexplore.exe!ws!]
Error: (07/08/2011 08:05:19 PM) (Source: Brother BrLog) (User: )
Description: TWN BrtTWN: [2011/07/08 20:05:19.140]: [00003348]: Initialize TwdsMain Class failed!
Error: (07/08/2011 08:05:19 PM) (Source: Brother BrLog) (User: )
Description: TWN BrtTWN: [2011/07/08 20:05:19.140]: [00003348]: ##### Fatal ERROR!! Create STI-device failed! #####
Error: (07/08/2011 07:57:56 PM) (Source: Brother BrLog) (User: )
Description: TWN BrtTWN: [2011/07/08 19:57:56.484]: [00003348]: Initialize TwdsMain Class failed!
Error: (07/08/2011 07:57:56 PM) (Source: Brother BrLog) (User: )
Description: TWN BrtTWN: [2011/07/08 19:57:56.468]: [00003348]: ##### Fatal ERROR!! Create STI-device failed! #####
Error: (07/08/2011 02:04:19 PM) (Source: Application Error) (User: )
Description: Faulting application iexplore.exe, version 8.0.6001.18702, faulting module mshtml.dll, version 8.0.6001.19088, fault address 0x00023247.
Processing media-specific event for [iexplore.exe!ws!]
Error: (07/08/2011 10:21:58 AM) (Source: Brother BrLog) (User: )
Description: TWN BrtTWN: [2011/07/08 10:21:58.265]: [00001380]: Initialize TwdsMain Class failed!
Error: (07/08/2011 10:21:58 AM) (Source: Brother BrLog) (User: )
Description: TWN BrtTWN: [2011/07/08 10:21:58.265]: [00001380]: ##### Fatal ERROR!! Create STI-device failed! #####
Error: (07/08/2011 00:36:36 AM) (Source: Application Error) (User: )
Description: Faulting application iexplore.exe, version 8.0.6001.18702, faulting module mshtml.dll, version 8.0.6001.19088, fault address 0x0009b0fe.
Processing media-specific event for [iexplore.exe!ws!]
Error: (07/07/2011 11:54:22 PM) (Source: Application Error) (User: )
Description: Faulting application iexplore.exe, version 8.0.6001.18702, faulting module unknown, version 0.0.0.0, fault address 0x00000000.
Processing media-specific event for [iexplore.exe!ws!]
System errors:
=============
Error: (07/09/2011 10:48:52 AM) (Source: Service Control Manager) (User: )
Description: The adfs service failed to start due to the following error:
%%2
Error: (07/08/2011 07:56:38 PM) (Source: Service Control Manager) (User: )
Description: The adfs service failed to start due to the following error:
%%2
Error: (07/08/2011 10:16:46 AM) (Source: Service Control Manager) (User: )
Description: The adfs service failed to start due to the following error:
%%2
Error: (07/07/2011 08:10:25 PM) (Source: Service Control Manager) (User: )
Description: The adfs service failed to start due to the following error:
%%2
Error: (07/07/2011 10:00:07 AM) (Source: Service Control Manager) (User: )
Description: The adfs service failed to start due to the following error:
%%2
Error: (07/06/2011 08:09:43 PM) (Source: Service Control Manager) (User: )
Description: The adfs service failed to start due to the following error:
%%2
Error: (07/06/2011 10:22:36 AM) (Source: Service Control Manager) (User: )
Description: The adfs service failed to start due to the following error:
%%2
Error: (07/06/2011 00:21:45 AM) (Source: Service Control Manager) (User: )
Description: The following boot-start or system-start driver(s) failed to load:
abp480n5
adpu160m
agp440
agpCPQ
Aha154x
aic78u2
aic78xx
AliIde
alim1541
amdagp
amsint
asc
asc3350p
asc3550
cbidf
cd20xrnt
CmdIde
Cpqarray
dac2w2k
dac960nt
dpti2o
hpn
i2omp
ini910u
IntelIde
mraid35x
perc2
perc2hib
ql1080
Ql10wnt
ql12160
ql1240
ql1280
sisagp
Sparrow
symc810
symc8xx
sym_hi
sym_u3
TosIde
ultra
viaagp
ViaIde
Error: (07/06/2011 00:21:37 AM) (Source: Service Control Manager) (User: )
Description: The adfs service failed to start due to the following error:
%%2
Error: (07/05/2011 11:00:40 PM) (Source: Service Control Manager) (User: )
Description: The adfs service failed to start due to the following error:
%%2
Microsoft Office Sessions:
=========================
========================= End of Event log errors =========================
========================= Memory info: ====================================
Percentage of memory in use: 54%
Total physical RAM: 1011.88 MB
Available physical RAM: 463.78 MB
Total Pagefile: 2430.37 MB
Available Pagefile: 2006.2 MB
Total Virtual: 2047.88 MB
Available Virtual: 1997.46 MB
======================= Partitions: =======================================
1 Drive c: (ACER) (Fixed) (Total:225.25 GB) (Free:173.09 GB) NTFS
================= Users: ==================================================
User accounts for \\STEPHANIE
-------------------------------------------------------------------------------
Administrator ASPNET Guest
HelpAssistant Steph SUPPORT_388945a0
The command completed successfully.
================= End of Users ============================================
Mbam
Malwarebytes' Anti-Malware 1.50.1.1100
www.malwarebytes.org
Database version: 7030
Windows 5.1.2600 Service Pack 3
Internet Explorer 8.0.6001.18702
7/9/2011 11:24:38 AM
mbam-log-2011-07-09 (11-24-38).txt
Scan type: Quick scan
Objects scanned: 190268
Time elapsed: 14 minute(s), 41 second(s)
Memory Processes Infected: 0
Memory Modules Infected: 0
Registry Keys Infected: 0
Registry Values Infected: 0
Registry Data Items Infected: 0
Folders Infected: 0
Files Infected: 0
Memory Processes Infected:
(No malicious items detected)
Memory Modules Infected:
(No malicious items detected)
Registry Keys Infected:
(No malicious items detected)
Registry Values Infected:
(No malicious items detected)
Registry Data Items Infected:
(No malicious items detected)
Folders Infected:
(No malicious items detected)
Files Infected:
(No malicious items detected)
Gmer
GMER 1.0.15.15640 -
http://www.gmer.net
Rootkit scan 2011-07-09 14:58:37
Windows 5.1.2600 Service Pack 3 Harddisk0\DR0 -> \Device\Ide\IdeDeviceP0T0L0-3 ST9250410AS rev.0002SDM1
Running: 0tk8yv9v.exe; Driver: C:\DOCUME~1\Steph\LOCALS~1\Temp\uxdirpoc.sys
---- Kernel code sections - GMER 1.0.15 ----
.text KDCOM.DLL!KdSendPacket F7AA7345 6 Bytes [FA, 8D, 46, 01, 25, FF]
.text KDCOM.DLL!KdSendPacket F7AA734D 5 Bytes [80, 79, 07, 48, 0D]
.text KDCOM.DLL!KdSendPacket F7AA7353 29 Bytes [FF, FF, FF, 40, 0F, B6, F0, ...]
.text KDCOM.DLL!KdSendPacket F7AA7371 28 Bytes [FF, FF, FF, 42, 0F, B6, FA, ...]
.text KDCOM.DLL!KdD0Transition + 8 F7AA738E 17 Bytes [08, 03, 55, F8, 03, D8, 81, ...]
.text KDCOM.DLL!KdD0Transition + 1A F7AA73A0 42 Bytes [FF, FF, FF, 43, 0F, B6, C3, ...]
.text KDCOM.DLL!KdDebuggerInitialize0 + 25 F7AA73CB 6 Bytes [00, C9, C2, 08, 00, 55] {ADD CL, CL; RET 0x8; PUSH EBP}
.text KDCOM.DLL!KdDebuggerInitialize0 + 2C F7AA73D2 23 Bytes [EC, 83, C8, FF, 83, 7D, 08, ...]
.text KDCOM.DLL!KdDebuggerInitialize0 + 44 F7AA73EA 162 Bytes [42, 5E, F6, C1, 01, 74, 0A, ...]
.text KDCOM.DLL!KdRestore + 2D F7AA748D 1 Byte [43]
.text KDCOM.DLL!KdRestore + 2D F7AA748D 77 Bytes [43, 08, 89, 45, FC, 8B, 55, ...]
.text KDCOM.DLL!KdRestore + 7C F7AA74DC 25 Bytes [C9, C2, 08, 00, 55, 8B, EC, ...]
.text KDCOM.DLL!KdRestore + 97 F7AA74F7 21 Bytes [89, 06, 89, 46, 08, 89, 46, ...]
.text KDCOM.DLL!KdRestore + AD F7AA750D 241 Bytes CALL F7AA746D \WINDOWS\system32\KDCOM.DLL (Kernel Debugger HW Extension DLL/Microsoft Corporation)
.text ...
PAGEKD KDCOM.DLL!KdReceivePacket + 2 F7AA7F4E 205 Bytes [F0, 8D, 45, FC, 50, 53, 56, ...]
PAGEKD KDCOM.DLL!KdReceivePacket + D0 F7AA801C 2 Bytes [75, 0E] {JNZ 0x10}
PAGEKD KDCOM.DLL!KdReceivePacket + D3 F7AA801F 1 Byte [C0]
PAGEKD KDCOM.DLL!KdReceivePacket + D3 F7AA801F 103 Bytes [C0, 02, 83, C2, 02, 84, DB, ...]
PAGEKD KDCOM.DLL!KdReceivePacket + 13B F7AA8087 131 Bytes [7D, 0C, B8, 4D, 5A, 00, 00, ...]
PAGEKD ...
---- Kernel IAT/EAT - GMER 1.0.15 ----
IAT \WINDOWS\system32\ntoskrnl.exe[KDCOM.dll!KdSendPacket] [F7AA7631] \WINDOWS\system32\KDCOM.DLL (Kernel Debugger HW Extension DLL/Microsoft Corporation)
IAT \WINDOWS\system32\ntoskrnl.exe[KDCOM.dll!KdD0Transition] [F7AA75DF] \WINDOWS\system32\KDCOM.DLL (Kernel Debugger HW Extension DLL/Microsoft Corporation)
IAT \WINDOWS\system32\ntoskrnl.exe[KDCOM.dll!KdD3Transition] [F7AA75E9] \WINDOWS\system32\KDCOM.DLL (Kernel Debugger HW Extension DLL/Microsoft Corporation)
IAT \WINDOWS\system32\ntoskrnl.exe[KDCOM.dll!KdReceivePacket] [F7AA760D] \WINDOWS\system32\KDCOM.DLL (Kernel Debugger HW Extension DLL/Microsoft Corporation)
IAT \WINDOWS\system32\ntoskrnl.exe[KDCOM.dll!KdDebuggerInitialize0] [F7AA75F3] \WINDOWS\system32\KDCOM.DLL (Kernel Debugger HW Extension DLL/Microsoft Corporation)
IAT \WINDOWS\system32\ntoskrnl.exe[KDCOM.dll!KdSave] [F7AA7625] \WINDOWS\system32\KDCOM.DLL (Kernel Debugger HW Extension DLL/Microsoft Corporation)
IAT \WINDOWS\system32\ntoskrnl.exe[KDCOM.dll!KdDebuggerInitialize1] [F7AA75FF] \WINDOWS\system32\KDCOM.DLL (Kernel Debugger HW Extension DLL/Microsoft Corporation)
IAT \WINDOWS\system32\ntoskrnl.exe[KDCOM.dll!KdRestore] [F7AA7619] \WINDOWS\system32\KDCOM.DLL (Kernel Debugger HW Extension DLL/Microsoft Corporation)
IAT \WINDOWS\system32\hal.dll[KDCOM.dll!KdRestore] [F7AA7619] \WINDOWS\system32\KDCOM.DLL (Kernel Debugger HW Extension DLL/Microsoft Corporation)
IAT \WINDOWS\system32\KDCOM.DLL[ntoskrnl.exe!WRITE_REGISTER_UCHAR] 6C6C642E
IAT \WINDOWS\system32\KDCOM.DLL[ntoskrnl.exe!READ_REGISTER_UCHAR] 8B550000
IAT \WINDOWS\system32\KDCOM.DLL[ntoskrnl.exe!HalPrivateDispatchTable] 835151EC
IAT \WINDOWS\system32\KDCOM.DLL[ntoskrnl.exe!KeFindConfigurationEntry] 8300F865
IAT \WINDOWS\system32\KDCOM.DLL[ntoskrnl.exe!InbvDisplayString] 8A000C7D
IAT \WINDOWS\system32\KDCOM.DLL[ntoskrnl.exe!KdDebuggerNotPresent] 00010081
IAT \WINDOWS\system32\KDCOM.DLL[ntoskrnl.exe!_strupr] 01918A00
IAT \WINDOWS\system32\KDCOM.DLL[ntoskrnl.exe!strstr] 0F000001
IAT \WINDOWS\system32\KDCOM.DLL[ntoskrnl.exe!MmMapIoSpace] 00008386
IAT \WINDOWS\system32\KDCOM.DLL[ntoskrnl.exe!atol] 57565300
IAT \WINDOWS\system32\KDCOM.DLL[HAL.dll!READ_PORT_UCHAR] 736F746E
IAT \WINDOWS\system32\KDCOM.DLL[HAL.dll!WRITE_PORT_UCHAR] 6C6E726B
IAT \WINDOWS\system32\KDCOM.DLL[HAL.dll!HalQueryRealTimeClock] 6578652E
IAT \WINDOWS\system32\KDCOM.DLL[HAL.dll!HalInitSystem] 00000000
IAT \WINDOWS\system32\KDCOM.DLL[HAL.dll!KdComPortInUse] 2E6C6168
---- Devices - GMER 1.0.15 ----
AttachedDevice \Driver\Kbdclass \Device\KeyboardClass0 SynTP.sys (Synaptics Touchpad Driver/Synaptics, Inc.)
AttachedDevice \FileSystem\Fastfat \Fat fltMgr.sys (Microsoft Filesystem Filter Manager/Microsoft Corporation)
---- Threads - GMER 1.0.15 ----
Thread System [4:108] 86F280B3
Thread System [4:120] 86F297FB
---- Registry - GMER 1.0.15 ----
Reg HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows@AppInit_DLLs
Reg HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows@DeviceNotSelectedTimeout 15
Reg HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows@GDIProcessHandleQuota 10000
Reg HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows@Spooler yes
Reg HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows@swapdisk
Reg HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows@TransmissionRetryTimeout 90
Reg HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows@USERProcessHandleQuota 10000
Reg HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows@LoadAppInit_DLLs 1
---- Disk sectors - GMER 1.0.15 ----
Disk \Device\Harddisk0\DR0 sector 00: rootkit-like behavior
---- Files - GMER 1.0.15 ----
File C:\Documents and Settings\Steph\Local Settings\Temporary Internet Files\Content.IE5\CVWGFGIH\kate-bosworth-profilepic_0[1].jpg 11505 bytes
File C:\Documents and Settings\Steph\Local Settings\Temporary Internet Files\Content.IE5\EDZO32FD\us_widget[1].htm 5859 bytes
File C:\Documents and Settings\Steph\Local Settings\Temporary Internet Files\Content.IE5\EDZO32FD\smith-family-020811-20[1].jpg 14820 bytes
File C:\Documents and Settings\Steph\Local Settings\Temporary Internet Files\Content.IE5\FLOZMA8W\ptj[2] 251 bytes
File C:\Documents and Settings\Steph\Local Settings\Temporary Internet Files\Content.IE5\J9VA8U27\Conforming_Citi_160x600_rebranding_ISN_11421-9_8777849381_ADV[1].swf 29328 bytes
File C:\Documents and Settings\Steph\Local Settings\Temporary Internet Files\Content.IE5\N87AMLFM\onsaleoff[1].png 682 bytes
File C:\Documents and Settings\Steph\Local Settings\Temporary Internet Files\Content.IE5\N87AMLFM\ping[11].gif 43 bytes
File C:\Documents and Settings\Steph\Local Settings\Temporary Internet Files\Content.IE5\N87AMLFM\glamadapt_jsrv[7].act 12298 bytes
File C:\Documents and Settings\Steph\Local Settings\Temporary Internet Files\Content.IE5\OIROJ4GR\ad[1].xml 13024 bytes
File C:\Documents and Settings\Steph\Local Settings\Temporary Internet Files\Content.IE5\OIROJ4GR\imp[1].gif 43 bytes
File C:\Documents and Settings\Steph\Local Settings\Temporary Internet Files\Content.IE5\OIROJ4GR\ajs[4].php 2608 bytes
File C:\Documents and Settings\Steph\Local Settings\Temporary Internet Files\Content.IE5\OIROJ4GR\0RAt4QMi9H_2103524606[1].htm 1446 bytes
File C:\Documents and Settings\Steph\Local Settings\Temporary Internet Files\Content.IE5\OIROJ4GR\set[1].gif 43 bytes
---- EOF - GMER 1.0.15 ----