Jump to content


 


Register a free account to unlock additional features at BleepingComputer.com
Welcome to BleepingComputer, a free community where people like yourself come together to discuss and learn how to use their computers. Using the site is easy and fun. As a guest, you can browse and view the various discussions in the forums, but can not create a new topic or reply to an existing one unless you are logged in. Other benefits of registering an account are subscribing to topics and forums, creating a blog, and having no ads shown anywhere on the site.


Click here to Register a free account now! or read our Welcome Guide to learn how to use this site.

Photo

Advertisements playing in Background with no windows open


  • Please log in to reply
5 replies to this topic

#1 Dennise08

Dennise08

  • Members
  • 6 posts
  • OFFLINE
  •  
  • Local time:02:33 PM

Posted 07 April 2012 - 03:19 AM

My computer was recently infected by the Smart HDD program and the Internet Security 2012 which I removed using tutorials on here. Now whenever I start a web browser advertisements will start playing without any visible window. Even after I close the browser(IE & Chrome) they still play (sometimes more than one at a time). I run Malwarebytes and it doesn't find any thing.

BC AdBot (Login to Remove)

 


#2 Broni

Broni

    The Coolest BC Computer


  • BC Advisor
  • 42,679 posts
  • OFFLINE
  •  
  • Gender:Male
  • Location:Daly City, CA
  • Local time:03:33 PM

Posted 07 April 2012 - 10:53 AM

Welcome aboard Posted Image

Download Security Check from HERE, and save it to your Desktop.

* Double-click SecurityCheck.exe
* Follow the onscreen instructions inside of the black box.
* A Notepad document should open automatically called checkup.txt; please post the contents of that document.

=============================================================================

Please download Farbar Service Scanner (FSS) and run it on the computer with the issue.
  • Make sure the following options are checked:
    • Internet Services
    • Windows Firewall
    • System Restore
    • Security Center/Action Center
    • Windows Update
    • Windows Defender
  • Press "Scan".
  • It will create a log (FSS.txt) in the same directory the tool is run.
  • Please copy and paste the log to your reply.

====================================================================================

Please download MiniToolBox and run it.

Checkmark following boxes:
  • Report IE Proxy Settings
  • Report FF Proxy Settings
  • List content of Hosts
  • List IP configuration
  • List Winsock Entries
  • List last 10 Event Viewer log
  • List Installed Programs
  • List Devices (do NOT change any settings here)
  • List Users, Partitions and Memory size
Click Go and post the result.

=============================================================================

Download Malwarebytes' Anti-Malware (aka MBAM): https://www.bleepingcomputer.com/download/malwarebytes-anti-malware/ to your desktop.

* Double-click mbam-setup.exe and follow the prompts to install the program.
* At the end, be sure a checkmark is placed next to Update Malwarebytes' Anti-Malware and Launch Malwarebytes' Anti-Malware, then click Finish.
* If an update is found, it will download and install the latest version.
* Once the program has loaded, select Perform quick scan, then click Scan.
* When the scan is complete, click OK, then Show Results to view the results.
* Be sure that everything is checked, and click Remove Selected.
* When completed, a log will open in Notepad.
* Post the log back here.

Be sure to restart the computer.

The log can also be found here:
C:\Documents and Settings\Username\Application Data\Malwarebytes\Malwarebytes' Anti-Malware\Logs\log-date.txt
Or at C:\Program Files\Malwarebytes' Anti-Malware\Logs\log-date.txt

=============================================================================

Download aswMBR to your desktop.
Double click the aswMBR.exe to run it.
If you see this question: Would you like to download latest Avast! virus definitions?" say "Yes".
Click the "Scan" button to start scan.
On completion of the scan click "Save log", save it to your desktop and post in your next reply.

NOTE. aswMBR will create MBR.dat file on your desktop. This is a copy of your MBR. Do NOT delete it.

My Website

p4433470.gif

My help doesn't cost a penny, but if you'd like to consider a donation, click p22001735.gif


 


#3 Dennise08

Dennise08
  • Topic Starter

  • Members
  • 6 posts
  • OFFLINE
  •  
  • Local time:02:33 PM

Posted 07 April 2012 - 09:30 PM

Results of screen317's Security Check version 0.99.24
Windows 7 x86 (UAC is enabled)
Internet Explorer 8 Out of date!
``````````````````````````````
Antivirus/Firewall Check:

Windows Security Center service is not running! This report may not be accurate!
avast! Free Antivirus
WMI entry may not exist for antivirus; attempting automatic update.
```````````````````````````````
Anti-malware/Other Utilities Check:

Spybot - Search & Destroy
Java™ 6 Update 29
Out of date Java installed!
Adobe Flash Player 11.1.102.55
Adobe Reader X (10.1.2)
````````````````````````````````
Process Check:
objlist.exe by Laurent

AVAST Software Avast AvastSvc.exe
AVAST Software Avast AvastUI.exe
``````````End of Log````````````




Farbar Service Scanner Version: 01-03-2012
Ran by Aura (administrator) on 07-04-2012 at 19:24:41
Running from "C:\Users\Aura\Downloads"
Microsoft Windows 7 Ultimate (X86)
Boot Mode: Normal
****************************************************************

Internet Services:
============

Connection Status:
==============
Localhost is accessible.
LAN connected.
Google IP is accessible.
Yahoo IP is accessible.


Windows Firewall:
=============
mpsdrv Service is not running. Checking service configuration:
The start type of mpsdrv service is OK.
The ImagePath of mpsdrv service is OK.

MpsSvc Service is not running. Checking service configuration:
Checking Start type: Attention! Unable to open MpsSvc registry key. The service key does not exist.
Checking ImagePath: Attention! Unable to open MpsSvc registry key. The service key does not exist.
Checking ServiceDll: Attention! Unable to open MpsSvc registry key. The service key does not exist.

bfe Service is not running. Checking service configuration:
Checking Start type: Attention! Unable to open bfe registry key. The service key does not exist.
Checking ImagePath: Attention! Unable to open bfe registry key. The service key does not exist.
Checking ServiceDll: Attention! Unable to open bfe registry key. The service key does not exist.


Firewall Disabled Policy:
==================


System Restore:
============

System Restore Disabled Policy:
========================


Action Center:
============
wscsvc Service is not running. Checking service configuration:
Checking Start type: Attention! Unable to open wscsvc registry key. The service key does not exist.
Checking ImagePath: Attention! Unable to open wscsvc registry key. The service key does not exist.
Checking ServiceDll: Attention! Unable to open wscsvc registry key. The service key does not exist.


Windows Update:
============

Windows Defender:
==============
WinDefend Service is not running. Checking service configuration:
Checking Start type: Attention! Unable to open WinDefend registry key. The service key does not exist.
Checking ImagePath: Attention! Unable to open WinDefend registry key. The service key does not exist.
Checking ServiceDll: Attention! Unable to open WinDefend registry key. The service key does not exist.


File Check:
========
C:\Windows\system32\nsisvc.dll => MD5 is legit
C:\Windows\system32\Drivers\nsiproxy.sys => MD5 is legit
C:\Windows\system32\dhcpcore.dll => MD5 is legit
C:\Windows\system32\Drivers\afd.sys => MD5 is legit
C:\Windows\system32\Drivers\tdx.sys => MD5 is legit
C:\Windows\system32\Drivers\tcpip.sys
[2012-02-23 20:54] - [2011-09-29 08:43] - 1285488 ____A (Microsoft Corporation) 56C198AC82EFA622DD93E9E43575F79C

C:\Windows\system32\dnsrslvr.dll
[2012-02-23 20:54] - [2011-03-02 22:29] - 0132608 ____A (Microsoft Corporation) B15BE77A2BACF9C3177D27518AFE26A9

C:\Windows\system32\mpssvc.dll
[2009-07-13 16:53] - [2009-07-13 18:15] - 0565760 ____A (Microsoft Corporation) 5CD996CECF45CBC3E8D109C86B82D69E

C:\Windows\system32\bfe.dll
[2009-07-13 16:54] - [2009-07-13 18:14] - 0493568 ____A (Microsoft Corporation) 85AC71C045CEB054ED48A7841AAE0C11

C:\Windows\system32\Drivers\mpsdrv.sys => MD5 is legit
C:\Windows\system32\SDRSVC.dll
[2009-07-13 16:23] - [2009-07-13 18:16] - 0125952 ____A (Microsoft Corporation) 5FD90ABDBFAEE85986802622CBB03446

C:\Windows\system32\vssvc.exe
[2009-07-13 16:24] - [2009-07-13 18:14] - 1025536 ____A (Microsoft Corporation) 7EA2BCD94D9CFAF4C556F5CC94532A6C

C:\Windows\system32\wscsvc.dll
[2012-02-23 20:51] - [2010-12-20 22:38] - 0073728 ____A (Microsoft Corporation) A661A76333057B383A06E65F0073222F

C:\Windows\system32\wbem\WMIsvc.dll => MD5 is legit
C:\Windows\system32\wuaueng.dll
[2009-07-13 17:15] - [2009-07-13 18:16] - 1912832 ____A (Microsoft Corporation) A33408CC036F9C08142B11BE5E93F0A1

C:\Windows\system32\qmgr.dll
[2009-07-13 16:30] - [2009-07-13 18:16] - 0589312 ____A (Microsoft Corporation) 53F476476F55A27F580661BDE09C4EC4

C:\Windows\system32\es.dll => MD5 is legit
C:\Windows\system32\cryptsvc.dll => MD5 is legit
C:\Program Files\Windows Defender\MpSvc.dll => MD5 is legit
C:\Windows\system32\svchost.exe => MD5 is legit
C:\Windows\system32\rpcss.dll => MD5 is legit


**** End of log ****






MiniToolBox by Farbar Version: 18-01-2012
Ran by Aura (administrator) on 07-04-2012 at 19:27:37
Microsoft Windows 7 Ultimate (X86)
Boot Mode: Normal
***************************************************************************

========================= IE Proxy Settings: ==============================

Proxy is not enabled.
No Proxy Server is set.
Hosts file not detected in the default directory
========================= IP Configuration: ================================

Realtek RTL8102E/RTL8103E Family PCI-E Fast Ethernet NIC (NDIS 6.20) = Local Area Connection (Connected)


# ----------------------------------
# IPv4 Configuration
# ----------------------------------
pushd interface ipv4

reset
set global icmpredirects=enabled


popd
# End of IPv4 configuration



Windows IP Configuration

Host Name . . . . . . . . . . . . : Aura-PC
Primary Dns Suffix . . . . . . . :
Node Type . . . . . . . . . . . . : Hybrid
IP Routing Enabled. . . . . . . . : No
WINS Proxy Enabled. . . . . . . . : No
DNS Suffix Search List. . . . . . : lv.cox.net

Ethernet adapter Local Area Connection:

Connection-specific DNS Suffix . : lv.cox.net
Description . . . . . . . . . . . : Realtek RTL8102E/RTL8103E Family PCI-E Fast Ethernet NIC (NDIS 6.20)
Physical Address. . . . . . . . . : 6C-62-6D-8C-B3-97
DHCP Enabled. . . . . . . . . . . : Yes
Autoconfiguration Enabled . . . . : Yes
Link-local IPv6 Address . . . . . : fe80::6569:fe7e:e921:7c7d%12(Preferred)
IPv4 Address. . . . . . . . . . . : 70.173.5.237(Preferred)
Subnet Mask . . . . . . . . . . . : 255.255.255.0
Lease Obtained. . . . . . . . . . : Saturday, April 07, 2012 7:17:35 PM
Lease Expires . . . . . . . . . . : Sunday, April 08, 2012 7:17:35 PM
Default Gateway . . . . . . . . . : 70.173.5.1
DHCP Server . . . . . . . . . . . : 172.19.41.31
DHCPv6 IAID . . . . . . . . . . . : 258761325
DHCPv6 Client DUID. . . . . . . . : 00-01-00-01-15-EB-D7-62-6C-62-6D-8C-B3-97
DNS Servers . . . . . . . . . . . : 68.105.28.11
68.105.29.11
68.105.28.12
NetBIOS over Tcpip. . . . . . . . : Enabled

Tunnel adapter Local Area Connection* 9:

Media State . . . . . . . . . . . : Media disconnected
Connection-specific DNS Suffix . :
Description . . . . . . . . . . . : Microsoft Teredo Tunneling Adapter
Physical Address. . . . . . . . . : 00-00-00-00-00-00-00-E0
DHCP Enabled. . . . . . . . . . . : No
Autoconfiguration Enabled . . . . : Yes

Tunnel adapter 6TO4 Adapter:

Media State . . . . . . . . . . . : Media disconnected
Connection-specific DNS Suffix . :
Description . . . . . . . . . . . : Microsoft 6to4 Adapter
Physical Address. . . . . . . . . : 00-00-00-00-00-00-00-E0
DHCP Enabled. . . . . . . . . . . : No
Autoconfiguration Enabled . . . . : Yes

Tunnel adapter isatap.lv.cox.net:

Media State . . . . . . . . . . . : Media disconnected
Connection-specific DNS Suffix . :
Description . . . . . . . . . . . : Microsoft ISATAP Adapter #2
Physical Address. . . . . . . . . : 00-00-00-00-00-00-00-E0
DHCP Enabled. . . . . . . . . . . : No
Autoconfiguration Enabled . . . . : Yes
Server: cdns1.cox.net
Address: 68.105.28.11

Name: google.com
Addresses: 74.125.224.201
74.125.224.206
74.125.224.192
74.125.224.193
74.125.224.194
74.125.224.195
74.125.224.196
74.125.224.197
74.125.224.198
74.125.224.199
74.125.224.200


Pinging google.com [74.125.224.196] with 32 bytes of data:
Reply from 74.125.224.196: bytes=32 time=33ms TTL=58
Reply from 74.125.224.196: bytes=32 time=28ms TTL=58

Ping statistics for 74.125.224.196:
Packets: Sent = 2, Received = 2, Lost = 0 (0% loss),
Approximate round trip times in milli-seconds:
Minimum = 28ms, Maximum = 33ms, Average = 30ms
Server: cdns1.cox.net
Address: 68.105.28.11

Name: yahoo.com
Addresses: 72.30.38.140
98.139.183.24
209.191.122.70


Pinging yahoo.com [98.139.183.24] with 32 bytes of data:
Reply from 98.139.183.24: bytes=32 time=118ms TTL=55
Reply from 98.139.183.24: bytes=32 time=124ms TTL=55

Ping statistics for 98.139.183.24:
Packets: Sent = 2, Received = 2, Lost = 0 (0% loss),
Approximate round trip times in milli-seconds:
Minimum = 118ms, Maximum = 124ms, Average = 121ms
Server: cdns1.cox.net
Address: 68.105.28.11

Name: bleepingcomputer.com
Address: 208.43.87.2


Pinging bleepingcomputer.com [208.43.87.2] with 32 bytes of data:
Request timed out.
Request timed out.

Ping statistics for 208.43.87.2:
Packets: Sent = 2, Received = 0, Lost = 2 (100% loss),

Pinging 127.0.0.1 with 32 bytes of data:
Reply from 127.0.0.1: bytes=32 time<1ms TTL=128
Reply from 127.0.0.1: bytes=32 time<1ms TTL=128

Ping statistics for 127.0.0.1:
Packets: Sent = 2, Received = 2, Lost = 0 (0% loss),
Approximate round trip times in milli-seconds:
Minimum = 0ms, Maximum = 0ms, Average = 0ms
===========================================================================
Interface List
12...6c 62 6d 8c b3 97 ......Realtek RTL8102E/RTL8103E Family PCI-E Fast Ethernet NIC (NDIS 6.20)
1...........................Software Loopback Interface 1
11...00 00 00 00 00 00 00 e0 Microsoft Teredo Tunneling Adapter
13...00 00 00 00 00 00 00 e0 Microsoft 6to4 Adapter
14...00 00 00 00 00 00 00 e0 Microsoft ISATAP Adapter #2
===========================================================================

IPv4 Route Table
===========================================================================
Active Routes:
Network Destination Netmask Gateway Interface Metric
0.0.0.0 0.0.0.0 70.173.5.1 70.173.5.237 20
70.173.5.0 255.255.255.0 On-link 70.173.5.237 276
70.173.5.237 255.255.255.255 On-link 70.173.5.237 276
70.173.5.255 255.255.255.255 On-link 70.173.5.237 276
127.0.0.0 255.0.0.0 On-link 127.0.0.1 306
127.0.0.1 255.255.255.255 On-link 127.0.0.1 306
127.255.255.255 255.255.255.255 On-link 127.0.0.1 306
224.0.0.0 240.0.0.0 On-link 127.0.0.1 306
224.0.0.0 240.0.0.0 On-link 70.173.5.237 276
255.255.255.255 255.255.255.255 On-link 127.0.0.1 306
255.255.255.255 255.255.255.255 On-link 70.173.5.237 276
===========================================================================
Persistent Routes:
None

IPv6 Route Table
===========================================================================
Active Routes:
If Metric Network Destination Gateway
1 306 ::1/128 On-link
12 276 fe80::/64 On-link
12 276 fe80::6569:fe7e:e921:7c7d/128
On-link
1 306 ff00::/8 On-link
12 276 ff00::/8 On-link
===========================================================================
Persistent Routes:
None
========================= Winsock entries =====================================

Catalog5 01 mswsock.dll [File Not found] ()
Catalog5 02 mswsock.dll [File Not found] ()
Catalog5 03 C:\Windows\System32\winrnr.dll [20992] (Microsoft Corporation)
Catalog5 04 C:\Windows\system32\napinsp.dll [52224] (Microsoft Corporation)
Catalog5 05 C:\Windows\system32\pnrpnsp.dll [65024] (Microsoft Corporation)
Catalog5 06 C:\Windows\system32\pnrpnsp.dll [65024] (Microsoft Corporation)
Catalog5 07 C:\Program Files\Bonjour\mdnsNSP.dll [121704] (Apple Inc.)
Catalog9 01 mswsock.dll [File Not found] ()
Catalog9 02 mswsock.dll [File Not found] ()
Catalog9 03 mswsock.dll [File Not found] ()
Catalog9 04 mswsock.dll [File Not found] ()
Catalog9 05 mswsock.dll [File Not found] ()
Catalog9 06 mswsock.dll [File Not found] ()
Catalog9 07 mswsock.dll [File Not found] ()
Catalog9 08 mswsock.dll [File Not found] ()
Catalog9 09 mswsock.dll [File Not found] ()
Catalog9 10 mswsock.dll [File Not found] ()
Catalog9 11 mswsock.dll [File Not found] ()
Catalog9 12 mswsock.dll [File Not found] ()
Catalog9 13 mswsock.dll [File Not found] ()
Catalog9 14 mswsock.dll [File Not found] ()
Catalog9 15 mswsock.dll [File Not found] ()
Catalog9 16 mswsock.dll [File Not found] ()
Catalog9 17 mswsock.dll [File Not found] ()
Catalog9 18 mswsock.dll [File Not found] ()
Catalog9 19 mswsock.dll [File Not found] ()
Catalog9 20 mswsock.dll [File Not found] ()
Catalog9 21 mswsock.dll [File Not found] ()
Catalog9 22 mswsock.dll [File Not found] ()

========================= Event log errors: ===============================

Application errors:
==================
Error: (04/07/2012 07:17:38 PM) (Source: Winlogon) (User: )
Description: Windows license activation failed. Error 0x00000000.

Error: (04/07/2012 07:17:38 PM) (Source: Software Protection Platform Service) (User: )
Description: License Activation (slui.exe) failed with the following error code:
0x80070005

Error: (04/06/2012 11:18:57 PM) (Source: Winlogon) (User: )
Description: Windows license activation failed. Error 0x00000000.

Error: (04/06/2012 11:18:56 PM) (Source: Software Protection Platform Service) (User: )
Description: License Activation (slui.exe) failed with the following error code:
0x80070005

Error: (04/06/2012 02:43:59 PM) (Source: Application Error) (User: )
Description: Faulting application name: iexplore.exe, version: 8.0.7600.16930, time stamp: 0x4eeae23b
Faulting module name: msxml3.dll, version: 8.110.7600.16723, time stamp: 0x4d103aab
Exception code: 0xc0000005
Fault offset: 0x0002e64f
Faulting process id: 0xd64
Faulting application start time: 0xiexplore.exe0
Faulting application path: iexplore.exe1
Faulting module path: iexplore.exe2
Report Id: iexplore.exe3

Error: (04/06/2012 09:42:08 AM) (Source: Winlogon) (User: )
Description: Windows license activation failed. Error 0x00000000.

Error: (04/06/2012 09:42:07 AM) (Source: Software Protection Platform Service) (User: )
Description: License Activation (slui.exe) failed with the following error code:
0x80070005

Error: (04/06/2012 01:32:19 AM) (Source: Application Error) (User: )
Description: Faulting application name: iexplore.exe, version: 8.0.7600.16930, time stamp: 0x4eeae23b
Faulting module name: msxml3.dll, version: 8.110.7600.16723, time stamp: 0x4d103aab
Exception code: 0xc0000005
Fault offset: 0x0002e64f
Faulting process id: 0x10fc
Faulting application start time: 0xiexplore.exe0
Faulting application path: iexplore.exe1
Faulting module path: iexplore.exe2
Report Id: iexplore.exe3

Error: (04/06/2012 01:14:35 AM) (Source: Application Error) (User: )
Description: Faulting application name: iexplore.exe, version: 8.0.7600.16930, time stamp: 0x4eeae23b
Faulting module name: msxml3.dll, version: 8.110.7600.16723, time stamp: 0x4d103aab
Exception code: 0xc0000005
Fault offset: 0x0002e64f
Faulting process id: 0xfdc
Faulting application start time: 0xiexplore.exe0
Faulting application path: iexplore.exe1
Faulting module path: iexplore.exe2
Report Id: iexplore.exe3

Error: (04/06/2012 00:54:50 AM) (Source: Application Error) (User: )
Description: Faulting application name: iexplore.exe, version: 8.0.7600.16930, time stamp: 0x4eeae23b
Faulting module name: msxml3.dll, version: 8.110.7600.16723, time stamp: 0x4d103aab
Exception code: 0xc0000005
Fault offset: 0x0002e64f
Faulting process id: 0x3f0
Faulting application start time: 0xiexplore.exe0
Faulting application path: iexplore.exe1
Faulting module path: iexplore.exe2
Report Id: iexplore.exe3


System errors:
=============
Error: (04/07/2012 07:17:49 PM) (Source: Service Control Manager) (User: )
Description: The Computer Browser service terminated with the following error:
%%1060

Error: (04/07/2012 07:17:49 PM) (Source: Service Control Manager) (User: )
Description: The following boot-start or system-start driver(s) failed to load:
fiyi

Error: (04/07/2012 07:17:48 PM) (Source: Service Control Manager) (User: )
Description: The EPOWER service terminated with the following error:
%%126

Error: (04/07/2012 07:17:48 PM) (Source: Service Control Manager) (User: )
Description: The Emproxy service terminated with the following error:
%%126

Error: (04/07/2012 07:17:48 PM) (Source: Service Control Manager) (User: )
Description: The SBSD Security Center Service service depends the following service: wscsvc. This service might not be installed.

Error: (04/07/2012 07:17:48 PM) (Source: Service Control Manager) (User: )
Description: The IPsec Policy Agent service depends the following service: BFE. This service might not be installed.

Error: (04/07/2012 07:17:47 PM) (Source: Service Control Manager) (User: )
Description: The IKE and AuthIP IPsec Keying Modules service depends the following service: BFE. This service might not be installed.

Error: (04/07/2012 07:17:39 PM) (Source: Microsoft-Windows-DNS-Client) (User: NETWORK SERVICE)
Description: There was an error while attempting to read the local hosts file.

Error: (04/07/2012 07:17:38 PM) (Source: Microsoft-Windows-DNS-Client) (User: NETWORK SERVICE)
Description: There was an error while attempting to read the local hosts file.

Error: (04/07/2012 01:22:56 AM) (Source: Microsoft-Windows-DNS-Client) (User: SYSTEM)
Description: There was an error while attempting to read the local hosts file.


Microsoft Office Sessions:
=========================
Error: (04/07/2012 07:17:38 PM) (Source: Winlogon)(User: )
Description: 0x000000000x00000001

Error: (04/07/2012 07:17:38 PM) (Source: Software Protection Platform Service)(User: )
Description: 0x80070005

Error: (04/06/2012 11:18:57 PM) (Source: Winlogon)(User: )
Description: 0x000000000x00000001

Error: (04/06/2012 11:18:56 PM) (Source: Software Protection Platform Service)(User: )
Description: 0x80070005

Error: (04/06/2012 02:43:59 PM) (Source: Application Error)(User: )
Description: iexplore.exe8.0.7600.169304eeae23bmsxml3.dll8.110.7600.167234d103aabc00000050002e64fd6401cd143e5c8da70cC:\Program Files\Internet Explorer\iexplore.exeC:\Windows\System32\msxml3.dll9d7db48c-8031-11e1-9803-6c626d8cb397

Error: (04/06/2012 09:42:08 AM) (Source: Winlogon)(User: )
Description: 0x000000000x00000001

Error: (04/06/2012 09:42:07 AM) (Source: Software Protection Platform Service)(User: )
Description: 0x80070005

Error: (04/06/2012 01:32:19 AM) (Source: Application Error)(User: )
Description: iexplore.exe8.0.7600.169304eeae23bmsxml3.dll8.110.7600.167234d103aabc00000050002e64f10fc01cd13cfab063850C:\Program Files\Internet Explorer\iexplore.exeC:\Windows\System32\msxml3.dll058a3f10-7fc3-11e1-b1c3-6c626d8cb397

Error: (04/06/2012 01:14:35 AM) (Source: Application Error)(User: )
Description: iexplore.exe8.0.7600.169304eeae23bmsxml3.dll8.110.7600.167234d103aabc00000050002e64ffdc01cd13cd4789884cC:\Program Files\Internet Explorer\iexplore.exeC:\Windows\System32\msxml3.dll8b6fea9c-7fc0-11e1-b1c3-6c626d8cb397

Error: (04/06/2012 00:54:50 AM) (Source: Application Error)(User: )
Description: iexplore.exe8.0.7600.169304eeae23bmsxml3.dll8.110.7600.167234d103aabc00000050002e64f3f001cd13ca77344058C:\Program Files\Internet Explorer\iexplore.exeC:\Windows\System32\msxml3.dllc912d678-7fbd-11e1-b1c3-6c626d8cb397


=========================== Installed Programs ============================

Adobe AIR (Version: 2.7.1.19610)
Adobe Flash Player 11 ActiveX (Version: 11.2.202.228)
Adobe Flash Player 11 Plugin (Version: 11.1.102.55)
Adobe Reader X (10.1.2) (Version: 10.1.2)
Apple Application Support (Version: 2.1.7)
Apple Mobile Device Support (Version: 5.1.1.4)
Apple Software Update (Version: 2.1.3.127)
avast! Free Antivirus (Version: 6.0.1367.0)
Bonjour (Version: 3.0.0.10)
Byki (Version: 4.0)
Byki Express
Free File Opener v2011.7.0.1 (Version: 2011.7.0.1)
Free Video Flip and Rotate version 2.0.0.1228
Free YouTube Download version 3.0.20.1228
Free YouTube to MP3 Converter version 3.10.15.1228
Google Chrome (Version: 18.0.1025.151)
Google Earth Plug-in (Version: 6.1.0.5001)
Google Update Helper (Version: 1.3.21.111)
iTunes (Version: 10.6.1.7)
Java Auto Updater (Version: 2.0.6.1)
Java™ 6 Update 29 (Version: 6.0.290)
LeapFrog Connect (Version: 3.2.19.13664)
LeapFrog Tag Plugin (Version: 3.2.19.13664)
LG Android Driver (Version: 1.0)
LG USB Modem Driver (Version: 4.9.7)
Malwarebytes Anti-Malware version 1.60.1.1000 (Version: 1.60.1.1000)
Microsoft .NET Framework 4 Client Profile (Version: 4.0.30319)
Microsoft Silverlight (Version: 4.1.10111.0)
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.4148 (Version: 9.0.30729.4148)
QuickTime (Version: 7.70.80.34)
Spybot - Search & Destroy (Version: 1.6.2)
Use the entry named LeapFrog Connect to uninstall (LeapFrog Tag Plugin) (Version: 3.2.19.13664)
Windows Driver Package - LeapFrog (FlyUsb) USB (11/05/2008 1.1.1.0) (Version: 11/05/2008 1.1.1.0)
Windows Driver Package - Leapfrog (Leapfrog-USBLAN) Net (09/10/2009 02.03.05.012) (Version: 09/10/2009 02.03.05.012)
WModem Driver Installer (Version: 2.0.6.9)

========================= Devices: ================================


========================= Memory info: ===================================

Percentage of memory in use: 31%
Total physical RAM: 1791.24 MB
Available physical RAM: 1226.57 MB
Total Pagefile: 3582.48 MB
Available Pagefile: 2810 MB
Total Virtual: 2047.88 MB
Available Virtual: 1934.75 MB

========================= Partitions: =====================================

1 Drive c: () (Fixed) (Total:69.15 GB) (Free:27.52 GB) NTFS

========================= Users: ========================================

User accounts for \\AURA-PC

Administrator Aura Guest


**** End of log ****








Malwarebytes Anti-Malware 1.60.1.1000
www.malwarebytes.org

Database version: v2012.04.05.03

Windows 7 x86 NTFS
Internet Explorer 8.0.7600.16385
Aura :: AURA-PC [administrator]

4/7/2012 7:31:09 PM
mbam-log-2012-04-07 (19-31-09).txt

Scan type: Quick scan
Scan options enabled: Memory | Startup | Registry | File System | Heuristics/Extra | Heuristics/Shuriken | PUP | PUM
Scan options disabled: P2P
Objects scanned: 182321
Time elapsed: 4 minute(s), 42 second(s)

Memory Processes Detected: 0
(No malicious items detected)

Memory Modules Detected: 0
(No malicious items detected)

Registry Keys Detected: 0
(No malicious items detected)

Registry Values Detected: 0
(No malicious items detected)

Registry Data Items Detected: 0
(No malicious items detected)

Folders Detected: 0
(No malicious items detected)

Files Detected: 0
(No malicious items detected)

(end)






aswMBR version 0.9.9.1665 Copyright© 2011 AVAST Software
Run date: 2012-04-07 19:31:46
-----------------------------
19:31:46.454 OS Version: Windows 6.1.7600
19:31:46.454 Number of processors: 2 586 0x603
19:31:46.454 ComputerName: AURA-PC UserName: Aura
19:31:47.358 Initialize success
19:31:47.546 AVAST engine defs: 12032802
19:32:00.213 Disk 0 (boot) \Device\Harddisk0\DR0 -> \Device\0000005c
19:32:00.228 Disk 0 Vendor: WDC_WD74 33.0 Size: 70911MB BusType: 3
19:32:00.244 Disk 0 MBR read successfully
19:32:00.244 Disk 0 MBR scan
19:32:00.260 Disk 0 Windows 7 default MBR code
19:32:00.260 Disk 0 Partition 1 80 (A) 07 HPFS/NTFS NTFS 100 MB offset 2048
19:32:00.275 Disk 0 Partition 2 00 07 HPFS/NTFS NTFS 70809 MB offset 206848
19:32:00.306 Disk 0 scanning sectors +145223680
19:32:00.353 Disk 0 scanning C:\Windows\system32\drivers
19:32:16.283 Service scanning
19:32:38.609 Modules scanning
19:32:51.183 Disk 0 trace - called modules:
19:32:51.199 ntkrnlpa.exe CLASSPNP.SYS disk.sys ACPI.sys halmacpi.dll storport.sys nvstor.sys
19:32:51.713 1 nt!IofCallDriver -> \Device\Harddisk0\DR0[0x856ac030]
19:32:51.713 3 CLASSPNP.SYS[881b559e] -> nt!IofCallDriver -> [0x850174f0]
19:32:51.713 5 ACPI.sys[87c343b2] -> nt!IofCallDriver -> \Device\0000005c[0x85017030]
19:32:52.228 AVAST engine scan C:\Windows
19:32:53.991 AVAST engine scan C:\Windows\system32
19:35:58.946 AVAST engine scan C:\Windows\system32\drivers
19:36:05.342 AVAST engine scan C:\Users\Aura
19:37:05.265 Disk 0 MBR has been saved successfully to "C:\Users\Aura\Desktop\MBR.dat"
19:37:05.281 The log file has been saved successfully to "C:\Users\Aura\Desktop\aswMBR.txt"

Edited by Dennise08, 07 April 2012 - 09:37 PM.


#4 Broni

Broni

    The Coolest BC Computer


  • BC Advisor
  • 42,679 posts
  • OFFLINE
  •  
  • Gender:Male
  • Location:Daly City, CA
  • Local time:03:33 PM

Posted 07 April 2012 - 10:16 PM

Please download GMER from one of the following locations and save it to your desktop:
  • Main Mirror
    This version will download a randomly named file (Recommended)
  • Zipped Mirror
    This version will download a zip file you will need to extract first. If you use this mirror, please extract the zip file to your desktop.
  • Disconnect from the Internet and close all running programs.
  • Temporarily disable any real-time active protection so your security programs will not conflict with gmer's driver.
  • Double-click on the randomly named GMER file (i.e. n7gmo46c.exe) and allow the gmer.sys driver to load if asked.
  • Note: If you downloaded the zipped version, extract the file to its own folder such as C:\gmer and then double-click on gmer.exe.

    Posted Image
  • GMER will open to the Rootkit/Malware tab and perform an automatic quick scan when first run. (do not use the computer while the scan is in progress)
  • If you receive a WARNING!!! about rootkit activity and are asked to fully scan your system...click NO.
  • Now click the Scan button. If you see a rootkit warning window, click OK.
  • When the scan is finished, click the Save... button to save the scan results to your Desktop. Save the file as gmer.log.
  • Click the Copy button and paste the results into your next reply.
  • Exit GMER and be sure to re-enable your anti-virus, Firewall and any other security programs you had disabled.

IMPORTANT! If for some reason GMER refuses to run, try again.
If it still fails, try to UN-check "Devices" in right pane.
If still no joy, try to run it from Safe Mode.

My Website

p4433470.gif

My help doesn't cost a penny, but if you'd like to consider a donation, click p22001735.gif


 


#5 Dennise08

Dennise08
  • Topic Starter

  • Members
  • 6 posts
  • OFFLINE
  •  
  • Local time:02:33 PM

Posted 07 April 2012 - 11:43 PM

GMER 1.0.15.15641 - http://www.gmer.net
Rootkit scan 2012-04-07 21:39:28
Windows 6.1.7600 Harddisk0\DR0 -> \Device\0000005c WDC_WD74 rev.33.0
Running: 8hyl4wb5.exe; Driver: C:\Users\Aura\AppData\Local\Temp\kxldrpow.sys


---- System - GMER 1.0.15 ----

SSDT \SystemRoot\System32\Drivers\aswSnx.SYS (avast! Virtualization Driver/AVAST Software) ZwAddBootEntry [0x8CE47FC4]
SSDT \SystemRoot\System32\Drivers\aswSP.SYS (avast! self protection module/AVAST Software) ZwAllocateVirtualMemory [0x8D6FC510]
SSDT \SystemRoot\System32\Drivers\aswSnx.SYS (avast! Virtualization Driver/AVAST Software) ZwCreateEvent [0x8CE4A456]
SSDT \SystemRoot\System32\Drivers\aswSnx.SYS (avast! Virtualization Driver/AVAST Software) ZwCreateEventPair [0x8CE4A4AE]
SSDT \SystemRoot\System32\Drivers\aswSnx.SYS (avast! Virtualization Driver/AVAST Software) ZwCreateIoCompletion [0x8CE4A5C4]
SSDT \SystemRoot\System32\Drivers\aswSnx.SYS (avast! Virtualization Driver/AVAST Software) ZwCreateMutant [0x8CE4A3AC]
SSDT \SystemRoot\System32\Drivers\aswSnx.SYS (avast! Virtualization Driver/AVAST Software) ZwCreateSection [0x8CE4A4FE]
SSDT \SystemRoot\System32\Drivers\aswSnx.SYS (avast! Virtualization Driver/AVAST Software) ZwCreateSemaphore [0x8CE4A400]
SSDT \SystemRoot\System32\Drivers\aswSnx.SYS (avast! Virtualization Driver/AVAST Software) ZwCreateTimer [0x8CE4A572]
SSDT \SystemRoot\System32\Drivers\aswSnx.SYS (avast! Virtualization Driver/AVAST Software) ZwDeleteBootEntry [0x8CE47FE8]
SSDT \SystemRoot\System32\Drivers\aswSP.SYS (avast! self protection module/AVAST Software) ZwFreeVirtualMemory [0x8D6FC5C0]
SSDT \SystemRoot\System32\Drivers\aswSnx.SYS (avast! Virtualization Driver/AVAST Software) ZwLoadDriver [0x8CE47DB2]
SSDT \SystemRoot\System32\Drivers\aswSnx.SYS (avast! Virtualization Driver/AVAST Software) ZwModifyBootEntry [0x8CE4800C]
SSDT \SystemRoot\System32\Drivers\aswSnx.SYS (avast! Virtualization Driver/AVAST Software) ZwNotifyChangeKey [0x8CE4A9BC]
SSDT \SystemRoot\System32\Drivers\aswSnx.SYS (avast! Virtualization Driver/AVAST Software) ZwNotifyChangeMultipleKeys [0x8CE48AA4]
SSDT \SystemRoot\System32\Drivers\aswSnx.SYS (avast! Virtualization Driver/AVAST Software) ZwOpenEvent [0x8CE4A486]
SSDT \SystemRoot\System32\Drivers\aswSnx.SYS (avast! Virtualization Driver/AVAST Software) ZwOpenEventPair [0x8CE4A4D6]
SSDT \SystemRoot\System32\Drivers\aswSnx.SYS (avast! Virtualization Driver/AVAST Software) ZwOpenIoCompletion [0x8CE4A5EE]
SSDT \SystemRoot\System32\Drivers\aswSnx.SYS (avast! Virtualization Driver/AVAST Software) ZwOpenMutant [0x8CE4A3D8]
SSDT \SystemRoot\System32\Drivers\aswSnx.SYS (avast! Virtualization Driver/AVAST Software) ZwOpenSection [0x8CE4A53E]
SSDT \SystemRoot\System32\Drivers\aswSnx.SYS (avast! Virtualization Driver/AVAST Software) ZwOpenSemaphore [0x8CE4A42E]
SSDT \SystemRoot\System32\Drivers\aswSnx.SYS (avast! Virtualization Driver/AVAST Software) ZwOpenTimer [0x8CE4A59C]
SSDT \SystemRoot\System32\Drivers\aswSP.SYS (avast! self protection module/AVAST Software) ZwProtectVirtualMemory [0x8D6FC658]
SSDT \SystemRoot\System32\Drivers\aswSnx.SYS (avast! Virtualization Driver/AVAST Software) ZwQueryObject [0x8CE4896A]
SSDT \SystemRoot\System32\Drivers\aswSnx.SYS (avast! Virtualization Driver/AVAST Software) ZwSetBootEntryOrder [0x8CE48030]
SSDT \SystemRoot\System32\Drivers\aswSnx.SYS (avast! Virtualization Driver/AVAST Software) ZwSetBootOptions [0x8CE48054]
SSDT \SystemRoot\System32\Drivers\aswSnx.SYS (avast! Virtualization Driver/AVAST Software) ZwSetSystemInformation [0x8CE47E0C]
SSDT \SystemRoot\System32\Drivers\aswSnx.SYS (avast! Virtualization Driver/AVAST Software) ZwSetSystemPowerState [0x8CE47F48]
SSDT \SystemRoot\System32\Drivers\aswSnx.SYS (avast! Virtualization Driver/AVAST Software) ZwShutdownSystem [0x8CE47F24]
SSDT \SystemRoot\System32\Drivers\aswSnx.SYS (avast! Virtualization Driver/AVAST Software) ZwSystemDebugControl [0x8CE47F6C]
SSDT \SystemRoot\System32\Drivers\aswSnx.SYS (avast! Virtualization Driver/AVAST Software) ZwVdmControl [0x8CE48078]

Code \SystemRoot\System32\Drivers\aswSP.SYS (avast! self protection module/AVAST Software) ZwCreateProcessEx [0x8D7107A2]

---- Kernel code sections - GMER 1.0.15 ----

.text ntkrnlpa.exe!ZwSaveKeyEx + 13AD 828545D9 1 Byte [06]
.text ntkrnlpa.exe!KiDispatchInterrupt + 5A2 82879092 19 Bytes [E0, 0F, BA, F0, 07, 73, 09, ...] {LOOPNZ 0x11; MOV EDX, 0x97307f0; MOV CR4, EAX; OR AL, 0x80; MOV CR4, EAX; RET ; MOV ECX, CR3}
.text ntkrnlpa.exe!RtlSidHashLookup + 244 82880884 4 Bytes [C4, 7F, E4, 8C]
.text ntkrnlpa.exe!RtlSidHashLookup + 26C 828808AC 4 Bytes [10, C5, 6F, 8D]
.text ntkrnlpa.exe!RtlSidHashLookup + 320 82880960 8 Bytes [56, A4, E4, 8C, AE, A4, E4, ...] {PUSH ESI; MOVSB ; IN AL, 0x8c; SCASB ; MOVSB ; IN AL, 0x8c}
.text ntkrnlpa.exe!RtlSidHashLookup + 32C 8288096C 4 Bytes [C4, A5, E4, 8C]
.text ntkrnlpa.exe!RtlSidHashLookup + 348 82880988 4 Bytes [AC, A3, E4, 8C]
.text ...
PAGE ntkrnlpa.exe!ObMakeTemporaryObject 82A1A342 5 Bytes JMP 8D70D69C \SystemRoot\System32\Drivers\aswSP.SYS (avast! self protection module/AVAST Software)
PAGE ntkrnlpa.exe!ObInsertObject + 27 82A34055 5 Bytes JMP 8D70F174 \SystemRoot\System32\Drivers\aswSP.SYS (avast! self protection module/AVAST Software)
PAGE ntkrnlpa.exe!ZwReplyWaitReceivePortEx + 108 82A7E65A 4 Bytes CALL 8CE49025 \SystemRoot\System32\Drivers\aswSnx.SYS (avast! Virtualization Driver/AVAST Software)
PAGE ntkrnlpa.exe!ZwAlpcSendWaitReceivePort + 122 82A86734 4 Bytes CALL 8CE4903B \SystemRoot\System32\Drivers\aswSnx.SYS (avast! Virtualization Driver/AVAST Software)
PAGE ntkrnlpa.exe!ZwCreateProcessEx 82AEC3C8 7 Bytes JMP 8D7107A6 \SystemRoot\System32\Drivers\aswSP.SYS (avast! self protection module/AVAST Software)
? C:\Users\Aura\AppData\Local\Temp\aswMBR.sys The system cannot find the file specified. !
.text user32.dll!UnhookWindowsHookEx 773CCC7B 5 Bytes [E9, 88, 3D, E4, 88] {JMP 0xffffffff88e43d8d}
.text user32.dll!UnhookWinEvent 773CD924 5 Bytes [E9, D3, 2A, E4, 88] {JMP 0xffffffff88e42ad8}
.text user32.dll!SetWindowsHookExW 773D210A 5 Bytes [E9, F5, E6, E3, 88] {JMP 0xffffffff88e3e6fa}
.text user32.dll!SetWinEventHook 773D507E 5 Bytes [E9, 75, B1, E3, 88] {JMP 0xffffffff88e3b17a}
.text user32.dll!SetWindowsHookExA 773F6DFA 5 Bytes [E9, 01, 98, E1, 88] {JMP 0xffffffff88e19806}
.text kernel32.dll!GetBinaryTypeW + 70 762B78FC 1 Byte [62]

---- User code sections - GMER 1.0.15 ----

.text C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe[320] ntdll.dll!LdrUnloadDll 7775BD1F 5 Bytes JMP 001603FC
.text C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe[320] ntdll.dll!LdrLoadDll 7775F425 5 Bytes JMP 001601F8
.text C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe[320] kernel32.dll!GetBinaryTypeW + 70 762B78FC 1 Byte [62]
.text C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe[320] USER32.dll!UnhookWindowsHookEx 773CCC7B 5 Bytes JMP 00180A08
.text C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe[320] USER32.dll!UnhookWinEvent 773CD924 5 Bytes JMP 001803FC
.text C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe[320] USER32.dll!SetWindowsHookExW 773D210A 5 Bytes JMP 00180804
.text C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe[320] USER32.dll!SetWinEventHook 773D507E 5 Bytes JMP 001801F8
.text C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe[320] USER32.dll!SetWindowsHookExA 773F6DFA 5 Bytes JMP 00180600
.text C:\Windows\system32\taskhost.exe[388] ntdll.dll!LdrUnloadDll 7775BD1F 5 Bytes JMP 000503FC
.text C:\Windows\system32\taskhost.exe[388] ntdll.dll!LdrLoadDll 7775F425 5 Bytes JMP 000501F8
.text C:\Windows\system32\taskhost.exe[388] kernel32.dll!GetBinaryTypeW + 70 762B78FC 1 Byte [62]
.text C:\Windows\system32\taskhost.exe[388] USER32.dll!UnhookWindowsHookEx 773CCC7B 5 Bytes JMP 000E0A08
.text C:\Windows\system32\taskhost.exe[388] USER32.dll!UnhookWinEvent 773CD924 5 Bytes JMP 000E03FC
.text C:\Windows\system32\taskhost.exe[388] USER32.dll!SetWindowsHookExW 773D210A 5 Bytes JMP 000E0804
.text C:\Windows\system32\taskhost.exe[388] USER32.dll!SetWinEventHook 773D507E 5 Bytes JMP 000E01F8
.text C:\Windows\system32\taskhost.exe[388] USER32.dll!SetWindowsHookExA 773F6DFA 5 Bytes JMP 000E0600
.text C:\Windows\system32\csrss.exe[404] kernel32.dll!GetBinaryTypeW + 70 762B78FC 1 Byte [62]
.text C:\Windows\System32\spoolsv.exe[412] ntdll.dll!LdrUnloadDll 7775BD1F 5 Bytes JMP 000603FC
.text C:\Windows\System32\spoolsv.exe[412] ntdll.dll!LdrLoadDll 7775F425 5 Bytes JMP 000601F8
.text C:\Windows\System32\spoolsv.exe[412] kernel32.dll!GetBinaryTypeW + 70 762B78FC 1 Byte [62]
.text C:\Windows\System32\spoolsv.exe[412] USER32.dll!UnhookWindowsHookEx 773CCC7B 5 Bytes JMP 00100A08
.text C:\Windows\System32\spoolsv.exe[412] USER32.dll!UnhookWinEvent 773CD924 5 Bytes JMP 001003FC
.text C:\Windows\System32\spoolsv.exe[412] USER32.dll!SetWindowsHookExW 773D210A 5 Bytes JMP 00100804
.text C:\Windows\System32\spoolsv.exe[412] USER32.dll!SetWinEventHook 773D507E 5 Bytes JMP 001001F8
.text C:\Windows\System32\spoolsv.exe[412] USER32.dll!SetWindowsHookExA 773F6DFA 5 Bytes JMP 00100600
.text C:\Windows\system32\wininit.exe[464] ntdll.dll!LdrUnloadDll 7775BD1F 5 Bytes JMP 000303FC
.text C:\Windows\system32\wininit.exe[464] ntdll.dll!LdrLoadDll 7775F425 5 Bytes JMP 000301F8
.text C:\Windows\system32\wininit.exe[464] kernel32.dll!GetBinaryTypeW + 70 762B78FC 1 Byte [62]
.text C:\Windows\system32\wininit.exe[464] USER32.dll!UnhookWindowsHookEx 773CCC7B 5 Bytes JMP 000C0A08
.text C:\Windows\system32\wininit.exe[464] USER32.dll!UnhookWinEvent 773CD924 5 Bytes JMP 000C03FC
.text C:\Windows\system32\wininit.exe[464] USER32.dll!SetWindowsHookExW 773D210A 5 Bytes JMP 000C0804
.text C:\Windows\system32\wininit.exe[464] USER32.dll!SetWinEventHook 773D507E 5 Bytes JMP 000C01F8
.text C:\Windows\system32\wininit.exe[464] USER32.dll!SetWindowsHookExA 773F6DFA 5 Bytes JMP 000C0600
.text C:\Windows\system32\csrss.exe[476] kernel32.dll!GetBinaryTypeW + 70 762B78FC 1 Byte [62]
.text C:\Windows\system32\services.exe[520] ntdll.dll!LdrUnloadDll 7775BD1F 5 Bytes JMP 000603FC
.text C:\Windows\system32\services.exe[520] ntdll.dll!LdrLoadDll 7775F425 5 Bytes JMP 000601F8
.text C:\Windows\system32\services.exe[520] kernel32.dll!GetBinaryTypeW + 70 762B78FC 1 Byte [62]
.text C:\Windows\system32\lsass.exe[536] ntdll.dll!LdrUnloadDll 7775BD1F 5 Bytes JMP 000603FC
.text C:\Windows\system32\lsass.exe[536] ntdll.dll!LdrLoadDll 7775F425 5 Bytes JMP 000601F8
.text C:\Windows\system32\lsass.exe[536] kernel32.dll!GetBinaryTypeW + 70 762B78FC 1 Byte [62]
.text C:\Windows\system32\lsass.exe[536] USER32.dll!UnhookWindowsHookEx 773CCC7B 5 Bytes JMP 00650A08
.text C:\Windows\system32\lsass.exe[536] USER32.dll!UnhookWinEvent 773CD924 5 Bytes JMP 006503FC
.text C:\Windows\system32\lsass.exe[536] USER32.dll!SetWindowsHookExW 773D210A 5 Bytes JMP 00650804
.text C:\Windows\system32\lsass.exe[536] USER32.dll!SetWinEventHook 773D507E 5 Bytes JMP 006501F8
.text C:\Windows\system32\lsass.exe[536] USER32.dll!SetWindowsHookExA 773F6DFA 5 Bytes JMP 00650600
.text C:\Windows\system32\lsm.exe[544] ntdll.dll!LdrUnloadDll 7775BD1F 5 Bytes JMP 000A03FC
.text C:\Windows\system32\lsm.exe[544] ntdll.dll!LdrLoadDll 7775F425 5 Bytes JMP 000A01F8
.text C:\Windows\system32\lsm.exe[544] kernel32.dll!GetBinaryTypeW + 70 762B78FC 1 Byte [62]
.text C:\Windows\system32\winlogon.exe[600] ntdll.dll!LdrUnloadDll 7775BD1F 5 Bytes JMP 000303FC
.text C:\Windows\system32\winlogon.exe[600] ntdll.dll!LdrLoadDll 7775F425 5 Bytes JMP 000301F8
.text C:\Windows\system32\winlogon.exe[600] kernel32.dll!GetBinaryTypeW + 70 762B78FC 1 Byte [62]
.text C:\Windows\system32\winlogon.exe[600] USER32.dll!UnhookWindowsHookEx 773CCC7B 5 Bytes JMP 000C0A08
.text C:\Windows\system32\winlogon.exe[600] USER32.dll!UnhookWinEvent 773CD924 5 Bytes JMP 000C03FC
.text C:\Windows\system32\winlogon.exe[600] USER32.dll!SetWindowsHookExW 773D210A 5 Bytes JMP 000C0804
.text C:\Windows\system32\winlogon.exe[600] USER32.dll!SetWinEventHook 773D507E 5 Bytes JMP 000C01F8
.text C:\Windows\system32\winlogon.exe[600] USER32.dll!SetWindowsHookExA 773F6DFA 5 Bytes JMP 000C0600
.text C:\ProgramData\71INKUmw.exe[660] ntdll.dll!LdrUnloadDll 7775BD1F 5 Bytes JMP 001503FC
.text C:\ProgramData\71INKUmw.exe[660] ntdll.dll!LdrLoadDll 7775F425 5 Bytes JMP 001501F8
.text C:\ProgramData\71INKUmw.exe[660] kernel32.dll!GetBinaryTypeW + 70 762B78FC 1 Byte [62]
.text C:\ProgramData\71INKUmw.exe[660] USER32.dll!UnhookWindowsHookEx 773CCC7B 5 Bytes JMP 001E0A08
.text C:\ProgramData\71INKUmw.exe[660] USER32.dll!UnhookWinEvent 773CD924 5 Bytes JMP 001E03FC
.text C:\ProgramData\71INKUmw.exe[660] USER32.dll!SetWindowsHookExW 773D210A 5 Bytes JMP 001E0804
.text C:\ProgramData\71INKUmw.exe[660] USER32.dll!SetWinEventHook 773D507E 5 Bytes JMP 001E01F8
.text C:\ProgramData\71INKUmw.exe[660] USER32.dll!SetWindowsHookExA 773F6DFA 5 Bytes JMP 001E0600
.text C:\Windows\system32\svchost.exe[692] ntdll.dll!LdrUnloadDll 7775BD1F 5 Bytes JMP 000603FC
.text C:\Windows\system32\svchost.exe[692] ntdll.dll!LdrLoadDll 7775F425 5 Bytes JMP 000601F8
.text C:\Windows\system32\svchost.exe[692] kernel32.dll!GetBinaryTypeW + 70 762B78FC 1 Byte [62]
.text C:\Windows\system32\svchost.exe[784] ntdll.dll!LdrUnloadDll 7775BD1F 5 Bytes JMP 000603FC
.text C:\Windows\system32\svchost.exe[784] ntdll.dll!LdrLoadDll 7775F425 5 Bytes JMP 000601F8
.text C:\Windows\system32\svchost.exe[784] kernel32.dll!GetBinaryTypeW + 70 762B78FC 1 Byte [62]
.text C:\Windows\System32\svchost.exe[828] ntdll.dll!LdrUnloadDll 7775BD1F 5 Bytes JMP 000A03FC
.text C:\Windows\System32\svchost.exe[828] ntdll.dll!LdrLoadDll 7775F425 5 Bytes JMP 000A01F8
.text C:\Windows\System32\svchost.exe[828] kernel32.dll!GetBinaryTypeW + 70 762B78FC 1 Byte [62]
.text C:\Windows\System32\svchost.exe[828] USER32.dll!UnhookWindowsHookEx 773CCC7B 5 Bytes JMP 00490A08
.text C:\Windows\System32\svchost.exe[828] USER32.dll!UnhookWinEvent 773CD924 5 Bytes JMP 004903FC
.text C:\Windows\System32\svchost.exe[828] USER32.dll!SetWindowsHookExW 773D210A 5 Bytes JMP 00490804
.text C:\Windows\System32\svchost.exe[828] USER32.dll!SetWinEventHook 773D507E 5 Bytes JMP 004901F8
.text C:\Windows\System32\svchost.exe[828] USER32.dll!SetWindowsHookExA 773F6DFA 5 Bytes JMP 00490600
.text C:\Windows\System32\svchost.exe[916] ntdll.dll!LdrUnloadDll 7775BD1F 5 Bytes JMP 000603FC
.text C:\Windows\System32\svchost.exe[916] ntdll.dll!LdrLoadDll 7775F425 5 Bytes JMP 000601F8
.text C:\Windows\System32\svchost.exe[916] kernel32.dll!GetBinaryTypeW + 70 762B78FC 1 Byte [62]
.text C:\Windows\System32\svchost.exe[916] USER32.dll!UnhookWindowsHookEx 773CCC7B 5 Bytes JMP 00580A08
.text C:\Windows\System32\svchost.exe[916] USER32.dll!UnhookWinEvent 773CD924 5 Bytes JMP 005803FC
.text C:\Windows\System32\svchost.exe[916] USER32.dll!SetWindowsHookExW 773D210A 5 Bytes JMP 00580804
.text C:\Windows\System32\svchost.exe[916] USER32.dll!SetWinEventHook 773D507E 5 Bytes JMP 005801F8
.text C:\Windows\System32\svchost.exe[916] USER32.dll!SetWindowsHookExA 773F6DFA 5 Bytes JMP 00580600
.text C:\Windows\system32\svchost.exe[960] ntdll.dll!LdrUnloadDll 7775BD1F 5 Bytes JMP 000603FC
.text C:\Windows\system32\svchost.exe[960] ntdll.dll!LdrLoadDll 7775F425 5 Bytes JMP 000601F8
.text C:\Windows\system32\svchost.exe[960] kernel32.dll!GetBinaryTypeW + 70 762B78FC 1 Byte [62]
.text C:\Windows\system32\svchost.exe[960] USER32.dll!UnhookWindowsHookEx 773CCC7B 5 Bytes JMP 00970A08
.text C:\Windows\system32\svchost.exe[960] USER32.dll!UnhookWinEvent 773CD924 5 Bytes JMP 009703FC
.text C:\Windows\system32\svchost.exe[960] USER32.dll!SetWindowsHookExW 773D210A 5 Bytes JMP 00970804
.text C:\Windows\system32\svchost.exe[960] USER32.dll!SetWinEventHook 773D507E 5 Bytes JMP 009701F8
.text C:\Windows\system32\svchost.exe[960] USER32.dll!SetWindowsHookExA 773F6DFA 5 Bytes JMP 00970600
.text C:\Windows\system32\taskeng.exe[1064] ntdll.dll!LdrUnloadDll 7775BD1F 5 Bytes JMP 000603FC
.text C:\Windows\system32\taskeng.exe[1064] ntdll.dll!LdrLoadDll 7775F425 5 Bytes JMP 000601F8
.text C:\Windows\system32\taskeng.exe[1064] kernel32.dll!GetBinaryTypeW + 70 762B78FC 1 Byte [62]
.text C:\Windows\system32\taskeng.exe[1064] USER32.dll!UnhookWindowsHookEx 773CCC7B 5 Bytes JMP 000F0A08
.text C:\Windows\system32\taskeng.exe[1064] USER32.dll!UnhookWinEvent 773CD924 5 Bytes JMP 000F03FC
.text C:\Windows\system32\taskeng.exe[1064] USER32.dll!SetWindowsHookExW 773D210A 5 Bytes JMP 000F0804
.text C:\Windows\system32\taskeng.exe[1064] USER32.dll!SetWinEventHook 773D507E 5 Bytes JMP 000F01F8
.text C:\Windows\system32\taskeng.exe[1064] USER32.dll!SetWindowsHookExA 773F6DFA 5 Bytes JMP 000F0600
.text C:\Windows\system32\svchost.exe[1116] ntdll.dll!LdrUnloadDll 7775BD1F 5 Bytes JMP 000603FC
.text C:\Windows\system32\svchost.exe[1116] ntdll.dll!LdrLoadDll 7775F425 5 Bytes JMP 000601F8
.text C:\Windows\system32\svchost.exe[1116] kernel32.dll!GetBinaryTypeW + 70 762B78FC 1 Byte [62]
.text C:\Windows\system32\svchost.exe[1116] USER32.dll!UnhookWindowsHookEx 773CCC7B 5 Bytes JMP 002A0A08
.text C:\Windows\system32\svchost.exe[1116] USER32.dll!UnhookWinEvent 773CD924 5 Bytes JMP 002A03FC
.text C:\Windows\system32\svchost.exe[1116] USER32.dll!SetWindowsHookExW 773D210A 5 Bytes JMP 002A0804
.text C:\Windows\system32\svchost.exe[1116] USER32.dll!SetWinEventHook 773D507E 5 Bytes JMP 002A01F8
.text C:\Windows\system32\svchost.exe[1116] USER32.dll!SetWindowsHookExA 773F6DFA 5 Bytes JMP 002A0600
.text C:\Windows\system32\svchost.exe[1228] ntdll.dll!LdrUnloadDll 7775BD1F 5 Bytes JMP 000603FC
.text C:\Windows\system32\svchost.exe[1228] ntdll.dll!LdrLoadDll 7775F425 5 Bytes JMP 000601F8
.text C:\Windows\system32\svchost.exe[1228] kernel32.dll!GetBinaryTypeW + 70 762B78FC 1 Byte [62]
.text C:\Windows\system32\svchost.exe[1228] USER32.dll!UnhookWindowsHookEx 773CCC7B 5 Bytes JMP 00F70A08
.text C:\Windows\system32\svchost.exe[1228] USER32.dll!UnhookWinEvent 773CD924 5 Bytes JMP 00F703FC
.text C:\Windows\system32\svchost.exe[1228] USER32.dll!SetWindowsHookExW 773D210A 5 Bytes JMP 00F70804
.text C:\Windows\system32\svchost.exe[1228] USER32.dll!SetWinEventHook 773D507E 5 Bytes JMP 00F701F8
.text C:\Windows\system32\svchost.exe[1228] USER32.dll!SetWindowsHookExA 773F6DFA 5 Bytes JMP 00F70600
.text C:\Program Files\AVAST Software\Avast\AvastSvc.exe[1316] kernel32.dll!SetUnhandledExceptionFilter 762A30E2 4 Bytes [C2, 04, 00, 90] {RET 0x4; NOP }
.text C:\Program Files\AVAST Software\Avast\AvastSvc.exe[1316] kernel32.dll!GetBinaryTypeW + 70 762B78FC 1 Byte [62]
.text C:\Program Files\Common Files\Adobe\ARM\1.0\armsvc.exe[1352] ntdll.dll!LdrUnloadDll 7775BD1F 5 Bytes JMP 000703FC
.text C:\Program Files\Common Files\Adobe\ARM\1.0\armsvc.exe[1352] ntdll.dll!LdrLoadDll 7775F425 5 Bytes JMP 000701F8
.text C:\Program Files\Common Files\Adobe\ARM\1.0\armsvc.exe[1352] kernel32.dll!GetBinaryTypeW + 70 762B78FC 1 Byte [62]
.text C:\Program Files\Common Files\Adobe\ARM\1.0\armsvc.exe[1352] USER32.dll!UnhookWindowsHookEx 773CCC7B 5 Bytes JMP 00100A08
.text C:\Program Files\Common Files\Adobe\ARM\1.0\armsvc.exe[1352] USER32.dll!UnhookWinEvent 773CD924 5 Bytes JMP 001003FC
.text C:\Program Files\Common Files\Adobe\ARM\1.0\armsvc.exe[1352] USER32.dll!SetWindowsHookExW 773D210A 5 Bytes JMP 00100804
.text C:\Program Files\Common Files\Adobe\ARM\1.0\armsvc.exe[1352] USER32.dll!SetWinEventHook 773D507E 5 Bytes JMP 001001F8
.text C:\Program Files\Common Files\Adobe\ARM\1.0\armsvc.exe[1352] USER32.dll!SetWindowsHookExA 773F6DFA 5 Bytes JMP 00100600
.text C:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe[1464] ntdll.dll!LdrUnloadDll 7775BD1F 5 Bytes JMP 000603FC
.text C:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe[1464] ntdll.dll!LdrLoadDll 7775F425 5 Bytes JMP 000601F8
.text C:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe[1464] kernel32.dll!GetBinaryTypeW + 70 762B78FC 1 Byte [62]
.text C:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe[1464] USER32.dll!UnhookWindowsHookEx 773CCC7B 5 Bytes JMP 00210A08
.text C:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe[1464] USER32.dll!UnhookWinEvent 773CD924 5 Bytes JMP 002103FC
.text C:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe[1464] USER32.dll!SetWindowsHookExW 773D210A 5 Bytes JMP 00210804
.text C:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe[1464] USER32.dll!SetWinEventHook 773D507E 5 Bytes JMP 002101F8
.text C:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe[1464] USER32.dll!SetWindowsHookExA 773F6DFA 5 Bytes JMP 00210600
.text C:\Windows\system32\Dwm.exe[1484] ntdll.dll!LdrUnloadDll 7775BD1F 5 Bytes JMP 000603FC
.text C:\Windows\system32\Dwm.exe[1484] ntdll.dll!LdrLoadDll 7775F425 5 Bytes JMP 000601F8
.text C:\Windows\system32\Dwm.exe[1484] kernel32.dll!GetBinaryTypeW + 70 762B78FC 1 Byte [62]
.text C:\Windows\system32\Dwm.exe[1484] USER32.dll!UnhookWindowsHookEx 773CCC7B 5 Bytes JMP 000F0A08
.text C:\Windows\system32\Dwm.exe[1484] USER32.dll!UnhookWinEvent 773CD924 5 Bytes JMP 000F03FC
.text C:\Windows\system32\Dwm.exe[1484] USER32.dll!SetWindowsHookExW 773D210A 5 Bytes JMP 000F0804
.text C:\Windows\system32\Dwm.exe[1484] USER32.dll!SetWinEventHook 773D507E 5 Bytes JMP 000F01F8
.text C:\Windows\system32\Dwm.exe[1484] USER32.dll!SetWindowsHookExA 773F6DFA 5 Bytes JMP 000F0600
.text C:\Windows\Explorer.EXE[1508] ntdll.dll!LdrUnloadDll 7775BD1F 5 Bytes JMP 000603FC
.text C:\Windows\Explorer.EXE[1508] ntdll.dll!LdrLoadDll 7775F425 5 Bytes JMP 000601F8
.text C:\Windows\Explorer.EXE[1508] kernel32.dll!GetBinaryTypeW + 70 762B78FC 1 Byte [62]
.text C:\Windows\Explorer.EXE[1508] USER32.dll!UnhookWindowsHookEx 773CCC7B 5 Bytes JMP 003A0A08
.text C:\Windows\Explorer.EXE[1508] USER32.dll!UnhookWinEvent 773CD924 5 Bytes JMP 003A03FC
.text C:\Windows\Explorer.EXE[1508] USER32.dll!SetWindowsHookExW 773D210A 5 Bytes JMP 003A0804
.text C:\Windows\Explorer.EXE[1508] USER32.dll!SetWinEventHook 773D507E 5 Bytes JMP 003A01F8
.text C:\Windows\Explorer.EXE[1508] USER32.dll!SetWindowsHookExA 773F6DFA 5 Bytes JMP 003A0600
.text C:\Program Files\AVAST Software\Avast\AvastUI.exe[1808] kernel32.dll!GetBinaryTypeW + 70 762B78FC 1 Byte [62]
.text C:\Program Files\Bonjour\mDNSResponder.exe[1920] ntdll.dll!LdrUnloadDll 7775BD1F 5 Bytes JMP 000603FC
.text C:\Program Files\Bonjour\mDNSResponder.exe[1920] ntdll.dll!LdrLoadDll 7775F425 5 Bytes JMP 000601F8
.text C:\Program Files\Bonjour\mDNSResponder.exe[1920] kernel32.dll!GetBinaryTypeW + 70 762B78FC 1 Byte [62]
.text C:\Program Files\Bonjour\mDNSResponder.exe[1920] USER32.dll!UnhookWindowsHookEx 773CCC7B 5 Bytes JMP 00200A08
.text C:\Program Files\Bonjour\mDNSResponder.exe[1920] USER32.dll!UnhookWinEvent 773CD924 5 Bytes JMP 002003FC
.text C:\Program Files\Bonjour\mDNSResponder.exe[1920] USER32.dll!SetWindowsHookExW 773D210A 5 Bytes JMP 00200804
.text C:\Program Files\Bonjour\mDNSResponder.exe[1920] USER32.dll!SetWinEventHook 773D507E 5 Bytes JMP 002001F8
.text C:\Program Files\Bonjour\mDNSResponder.exe[1920] USER32.dll!SetWindowsHookExA 773F6DFA 5 Bytes JMP 00200600
.text C:\Program Files\Common Files\Java\Java Update\jusched.exe[1960] ntdll.dll!LdrUnloadDll 7775BD1F 5 Bytes JMP 001703FC
.text C:\Program Files\Common Files\Java\Java Update\jusched.exe[1960] ntdll.dll!LdrLoadDll 7775F425 5 Bytes JMP 001701F8
.text C:\Program Files\Common Files\Java\Java Update\jusched.exe[1960] kernel32.dll!GetBinaryTypeW + 70 762B78FC 1 Byte [62]
.text C:\Program Files\Common Files\Java\Java Update\jusched.exe[1960] USER32.dll!UnhookWindowsHookEx 773CCC7B 5 Bytes JMP 00310A08
.text C:\Program Files\Common Files\Java\Java Update\jusched.exe[1960] USER32.dll!UnhookWinEvent 773CD924 5 Bytes JMP 003103FC
.text C:\Program Files\Common Files\Java\Java Update\jusched.exe[1960] USER32.dll!SetWindowsHookExW 773D210A 5 Bytes JMP 00310804
.text C:\Program Files\Common Files\Java\Java Update\jusched.exe[1960] USER32.dll!SetWinEventHook 773D507E 5 Bytes JMP 003101F8
.text C:\Program Files\Common Files\Java\Java Update\jusched.exe[1960] USER32.dll!SetWindowsHookExA 773F6DFA 5 Bytes JMP 00310600
.text C:\Windows\System32\svchost.exe[1988] ntdll.dll!LdrUnloadDll 7775BD1F 5 Bytes JMP 000603FC
.text C:\Windows\System32\svchost.exe[1988] ntdll.dll!LdrLoadDll 7775F425 5 Bytes JMP 000601F8
.text C:\Windows\System32\svchost.exe[1988] kernel32.dll!GetBinaryTypeW + 70 762B78FC 1 Byte [62]
.text C:\Program Files\LeapFrog\LeapFrog Connect\Monitor.exe[2016] ntdll.dll!LdrUnloadDll 7775BD1F 5 Bytes JMP 000603FC
.text C:\Program Files\LeapFrog\LeapFrog Connect\Monitor.exe[2016] ntdll.dll!LdrLoadDll 7775F425 5 Bytes JMP 000601F8
.text C:\Program Files\LeapFrog\LeapFrog Connect\Monitor.exe[2016] kernel32.dll!GetBinaryTypeW + 70 762B78FC 1 Byte [62]
.text C:\Program Files\LeapFrog\LeapFrog Connect\Monitor.exe[2016] USER32.dll!UnhookWindowsHookEx 773CCC7B 5 Bytes JMP 00210A08
.text C:\Program Files\LeapFrog\LeapFrog Connect\Monitor.exe[2016] USER32.dll!UnhookWinEvent 773CD924 5 Bytes JMP 002103FC
.text C:\Program Files\LeapFrog\LeapFrog Connect\Monitor.exe[2016] USER32.dll!SetWindowsHookExW 773D210A 5 Bytes JMP 00210804
.text C:\Program Files\LeapFrog\LeapFrog Connect\Monitor.exe[2016] USER32.dll!SetWinEventHook 773D507E 5 Bytes JMP 002101F8
.text C:\Program Files\LeapFrog\LeapFrog Connect\Monitor.exe[2016] USER32.dll!SetWindowsHookExA 773F6DFA 5 Bytes JMP 00210600
.text C:\Program Files\HTC\ModeSelection\VMMModeSelection.exe[2032] ntdll.dll!LdrUnloadDll 7775BD1F 5 Bytes JMP 000603FC
.text C:\Program Files\HTC\ModeSelection\VMMModeSelection.exe[2032] ntdll.dll!LdrLoadDll 7775F425 5 Bytes JMP 000601F8
.text C:\Program Files\HTC\ModeSelection\VMMModeSelection.exe[2032] kernel32.dll!GetBinaryTypeW + 70 762B78FC 1 Byte [62]
.text C:\Program Files\HTC\ModeSelection\VMMModeSelection.exe[2032] USER32.dll!UnhookWindowsHookEx 773CCC7B 5 Bytes JMP 000F0A08
.text C:\Program Files\HTC\ModeSelection\VMMModeSelection.exe[2032] USER32.dll!UnhookWinEvent 773CD924 5 Bytes JMP 000F03FC
.text C:\Program Files\HTC\ModeSelection\VMMModeSelection.exe[2032] USER32.dll!SetWindowsHookExW 773D210A 5 Bytes JMP 000F0804
.text C:\Program Files\HTC\ModeSelection\VMMModeSelection.exe[2032] USER32.dll!SetWinEventHook 773D507E 5 Bytes JMP 000F01F8
.text C:\Program Files\HTC\ModeSelection\VMMModeSelection.exe[2032] USER32.dll!SetWindowsHookExA 773F6DFA 5 Bytes JMP 000F0600
.text C:\Program Files\iTunes\iTunesHelper.exe[2044] ntdll.dll!LdrUnloadDll 7775BD1F 5 Bytes JMP 000603FC
.text C:\Program Files\iTunes\iTunesHelper.exe[2044] ntdll.dll!LdrLoadDll 7775F425 5 Bytes JMP 000601F8
.text C:\Program Files\iTunes\iTunesHelper.exe[2044] kernel32.dll!GetBinaryTypeW + 70 762B78FC 1 Byte [62]
.text C:\Program Files\iTunes\iTunesHelper.exe[2044] USER32.dll!UnhookWindowsHookEx 773CCC7B 5 Bytes JMP 00100A08
.text C:\Program Files\iTunes\iTunesHelper.exe[2044] USER32.dll!UnhookWinEvent 773CD924 5 Bytes JMP 001003FC
.text C:\Program Files\iTunes\iTunesHelper.exe[2044] USER32.dll!SetWindowsHookExW 773D210A 5 Bytes JMP 00100804
.text C:\Program Files\iTunes\iTunesHelper.exe[2044] USER32.dll!SetWinEventHook 773D507E 5 Bytes JMP 001001F8
.text C:\Program Files\iTunes\iTunesHelper.exe[2044] USER32.dll!SetWindowsHookExA 773F6DFA 5 Bytes JMP 00100600
.text C:\Program Files\LeapFrog\LeapFrog Connect\CommandService.exe[2080] ntdll.dll!LdrUnloadDll 7775BD1F 5 Bytes JMP 000603FC
.text C:\Program Files\LeapFrog\LeapFrog Connect\CommandService.exe[2080] ntdll.dll!LdrLoadDll 7775F425 5 Bytes JMP 000601F8
.text C:\Program Files\LeapFrog\LeapFrog Connect\CommandService.exe[2080] kernel32.dll!GetBinaryTypeW + 70 762B78FC 1 Byte [62]
.text C:\Program Files\LeapFrog\LeapFrog Connect\CommandService.exe[2080] USER32.dll!UnhookWindowsHookEx 773CCC7B 5 Bytes JMP 00100A08
.text C:\Program Files\LeapFrog\LeapFrog Connect\CommandService.exe[2080] USER32.dll!UnhookWinEvent 773CD924 5 Bytes JMP 001003FC
.text C:\Program Files\LeapFrog\LeapFrog Connect\CommandService.exe[2080] USER32.dll!SetWindowsHookExW 773D210A 5 Bytes JMP 00100804
.text C:\Program Files\LeapFrog\LeapFrog Connect\CommandService.exe[2080] USER32.dll!SetWinEventHook 773D507E 5 Bytes JMP 001001F8
.text C:\Program Files\LeapFrog\LeapFrog Connect\CommandService.exe[2080] USER32.dll!SetWindowsHookExA 773F6DFA 5 Bytes JMP 00100600
.text C:\Windows\system32\sppsvc.exe[2120] ntdll.dll!LdrUnloadDll 7775BD1F 5 Bytes JMP 000703FC
.text C:\Windows\system32\sppsvc.exe[2120] ntdll.dll!LdrLoadDll 7775F425 5 Bytes JMP 000701F8
.text C:\Windows\system32\sppsvc.exe[2120] kernel32.dll!GetBinaryTypeW + 70 762B78FC 1 Byte [62]
.text C:\Windows\system32\sppsvc.exe[2120] USER32.dll!UnhookWindowsHookEx 773CCC7B 5 Bytes JMP 000E0A08
.text C:\Windows\system32\sppsvc.exe[2120] USER32.dll!UnhookWinEvent 773CD924 5 Bytes JMP 000E03FC
.text C:\Windows\system32\sppsvc.exe[2120] USER32.dll!SetWindowsHookExW 773D210A 5 Bytes JMP 000E0804
.text C:\Windows\system32\sppsvc.exe[2120] USER32.dll!SetWinEventHook 773D507E 5 Bytes JMP 000E01F8
.text C:\Windows\system32\sppsvc.exe[2120] USER32.dll!SetWindowsHookExA 773F6DFA 5 Bytes JMP 000E0600
.text C:\Windows\system32\svchost.exe[2156] ntdll.dll!LdrUnloadDll 7775BD1F 5 Bytes JMP 000A03FC
.text C:\Windows\system32\svchost.exe[2156] ntdll.dll!LdrLoadDll 7775F425 5 Bytes JMP 000A01F8
.text C:\Windows\system32\svchost.exe[2156] kernel32.dll!GetBinaryTypeW + 70 762B78FC 1 Byte [62]
.text C:\Program Files\Internet Explorer\iexplore.exe[2300] ntdll.dll!LdrUnloadDll 7775BD1F 5 Bytes JMP 000503FC
.text C:\Program Files\Internet Explorer\iexplore.exe[2300] ntdll.dll!LdrLoadDll 7775F425 5 Bytes JMP 000501F8
.text C:\Program Files\Internet Explorer\iexplore.exe[2300] kernel32.dll!GetBinaryTypeW + 70 762B78FC 1 Byte [62]
.text C:\Program Files\Internet Explorer\iexplore.exe[2300] USER32.dll!UnhookWindowsHookEx 773CCC7B 5 Bytes JMP 000F0A08
.text C:\Program Files\Internet Explorer\iexplore.exe[2300] USER32.dll!UnhookWinEvent 773CD924 5 Bytes JMP 000F03FC
.text C:\Program Files\Internet Explorer\iexplore.exe[2300] USER32.dll!CreateWindowExW 773D0E51 5 Bytes JMP 6B3D812F C:\Windows\system32\IEFRAME.dll (Internet Browser/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\iexplore.exe[2300] USER32.dll!SetWindowsHookExW 773D210A 5 Bytes JMP 000F0804
.text C:\Program Files\Internet Explorer\iexplore.exe[2300] USER32.dll!SetWinEventHook 773D507E 5 Bytes JMP 000F01F8
.text C:\Program Files\Internet Explorer\iexplore.exe[2300] USER32.dll!DialogBoxIndirectParamW 773F4AA7 5 Bytes JMP 6B5001A0 C:\Windows\system32\IEFRAME.dll (Internet Browser/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\iexplore.exe[2300] USER32.dll!DialogBoxParamW 773F564A 5 Bytes JMP 6B2F4B87 C:\Windows\system32\IEFRAME.dll (Internet Browser/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\iexplore.exe[2300] USER32.dll!SetWindowsHookExA 773F6DFA 5 Bytes JMP 000F0600
.text C:\Program Files\Internet Explorer\iexplore.exe[2300] USER32.dll!DialogBoxParamA 7740CF6A 5 Bytes JMP 6B50013D C:\Windows\system32\IEFRAME.dll (Internet Browser/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\iexplore.exe[2300] USER32.dll!DialogBoxIndirectParamA 7740D29C 5 Bytes JMP 6B500203 C:\Windows\system32\IEFRAME.dll (Internet Browser/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\iexplore.exe[2300] USER32.dll!MessageBoxIndirectA 7741E8C9 5 Bytes JMP 6B5000D2 C:\Windows\system32\IEFRAME.dll (Internet Browser/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\iexplore.exe[2300] USER32.dll!MessageBoxIndirectW 7741E9C3 5 Bytes JMP 6B500067 C:\Windows\system32\IEFRAME.dll (Internet Browser/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\iexplore.exe[2300] USER32.dll!MessageBoxExA 7741EA29 5 Bytes JMP 6B500005 C:\Windows\system32\IEFRAME.dll (Internet Browser/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\iexplore.exe[2300] USER32.dll!MessageBoxExW 7741EA4D 5 Bytes JMP 6B4FFFA3 C:\Windows\system32\IEFRAME.dll (Internet Browser/Microsoft Corporation)
.text C:\Program Files\iPod\bin\iPodService.exe[2528] ntdll.dll!LdrUnloadDll 7775BD1F 5 Bytes JMP 000603FC
.text C:\Program Files\iPod\bin\iPodService.exe[2528] ntdll.dll!LdrLoadDll 7775F425 5 Bytes JMP 000601F8
.text C:\Program Files\iPod\bin\iPodService.exe[2528] kernel32.dll!GetBinaryTypeW + 70 762B78FC 1 Byte [62]
.text C:\Program Files\iPod\bin\iPodService.exe[2528] USER32.dll!UnhookWindowsHookEx 773CCC7B 5 Bytes JMP 00200A08
.text C:\Program Files\iPod\bin\iPodService.exe[2528] USER32.dll!UnhookWinEvent 773CD924 5 Bytes JMP 002003FC
.text C:\Program Files\iPod\bin\iPodService.exe[2528] USER32.dll!SetWindowsHookExW 773D210A 5 Bytes JMP 00200804
.text C:\Program Files\iPod\bin\iPodService.exe[2528] USER32.dll!SetWinEventHook 773D507E 5 Bytes JMP 002001F8
.text C:\Program Files\iPod\bin\iPodService.exe[2528] USER32.dll!SetWindowsHookExA 773F6DFA 5 Bytes JMP 00200600
.text C:\Windows\system32\SearchIndexer.exe[2628] ntdll.dll!LdrUnloadDll 7775BD1F 5 Bytes JMP 000603FC
.text C:\Windows\system32\SearchIndexer.exe[2628] ntdll.dll!LdrLoadDll 7775F425 5 Bytes JMP 000601F8
.text C:\Windows\system32\SearchIndexer.exe[2628] kernel32.dll!GetBinaryTypeW + 70 762B78FC 1 Byte [62]
.text C:\Windows\system32\SearchIndexer.exe[2628] USER32.dll!UnhookWindowsHookEx 773CCC7B 5 Bytes JMP 00140A08
.text C:\Windows\system32\SearchIndexer.exe[2628] USER32.dll!UnhookWinEvent 773CD924 5 Bytes JMP 001403FC
.text C:\Windows\system32\SearchIndexer.exe[2628] USER32.dll!SetWindowsHookExW 773D210A 5 Bytes JMP 00140804
.text C:\Windows\system32\SearchIndexer.exe[2628] USER32.dll!SetWinEventHook 773D507E 5 Bytes JMP 001401F8
.text C:\Windows\system32\SearchIndexer.exe[2628] USER32.dll!SetWindowsHookExA 773F6DFA 5 Bytes JMP 00140600
.text C:\Windows\system32\WUDFHost.exe[2804] ntdll.dll!LdrUnloadDll 7775BD1F 5 Bytes JMP 000603FC
.text C:\Windows\system32\WUDFHost.exe[2804] ntdll.dll!LdrLoadDll 7775F425 5 Bytes JMP 000601F8
.text C:\Windows\system32\WUDFHost.exe[2804] kernel32.dll!GetBinaryTypeW + 70 762B78FC 1 Byte [62]
.text C:\Windows\system32\WUDFHost.exe[2804] USER32.dll!UnhookWindowsHookEx 773CCC7B 5 Bytes JMP 00190A08
.text C:\Windows\system32\WUDFHost.exe[2804] USER32.dll!UnhookWinEvent 773CD924 5 Bytes JMP 001903FC
.text C:\Windows\system32\WUDFHost.exe[2804] USER32.dll!SetWindowsHookExW 773D210A 5 Bytes JMP 00190804
.text C:\Windows\system32\WUDFHost.exe[2804] USER32.dll!SetWinEventHook 773D507E 5 Bytes JMP 001901F8
.text C:\Windows\system32\WUDFHost.exe[2804] USER32.dll!SetWindowsHookExA 773F6DFA 5 Bytes JMP 00190600
.text C:\Windows\system32\taskeng.exe[3340] ntdll.dll!LdrUnloadDll 7775BD1F 5 Bytes JMP 000A03FC
.text C:\Windows\system32\taskeng.exe[3340] ntdll.dll!LdrLoadDll 7775F425 5 Bytes JMP 000A01F8
.text C:\Windows\system32\taskeng.exe[3340] kernel32.dll!GetBinaryTypeW + 70 762B78FC 1 Byte [62]
.text C:\Windows\system32\taskeng.exe[3340] USER32.dll!UnhookWindowsHookEx 773CCC7B 5 Bytes JMP 00130A08
.text C:\Windows\system32\taskeng.exe[3340] USER32.dll!UnhookWinEvent 773CD924 5 Bytes JMP 001303FC
.text C:\Windows\system32\taskeng.exe[3340] USER32.dll!SetWindowsHookExW 773D210A 5 Bytes JMP 00130804
.text C:\Windows\system32\taskeng.exe[3340] USER32.dll!SetWinEventHook 773D507E 5 Bytes JMP 001301F8
.text C:\Windows\system32\taskeng.exe[3340] USER32.dll!SetWindowsHookExA 773F6DFA 5 Bytes JMP 00130600
.text C:\Windows\system32\svchost.exe[3468] ntdll.dll!LdrUnloadDll 7775BD1F 5 Bytes JMP 000603FC
.text C:\Windows\system32\svchost.exe[3468] ntdll.dll!LdrLoadDll 7775F425 5 Bytes JMP 000601F8
.text C:\Windows\system32\svchost.exe[3468] kernel32.dll!GetBinaryTypeW + 70 762B78FC 1 Byte [62]
.text C:\ProgramData\71INKUmw.exe[3768] ntdll.dll!LdrUnloadDll 7775BD1F 5 Bytes JMP 001503FC
.text C:\ProgramData\71INKUmw.exe[3768] ntdll.dll!LdrLoadDll 7775F425 5 Bytes JMP 001501F8
.text C:\ProgramData\71INKUmw.exe[3768] kernel32.dll!GetBinaryTypeW + 70 762B78FC 1 Byte [62]
.text C:\ProgramData\71INKUmw.exe[3768] USER32.dll!UnhookWindowsHookEx 773CCC7B 5 Bytes JMP 001E0A08
.text C:\ProgramData\71INKUmw.exe[3768] USER32.dll!UnhookWinEvent 773CD924 5 Bytes JMP 001E03FC
.text C:\ProgramData\71INKUmw.exe[3768] USER32.dll!SetWindowsHookExW 773D210A 5 Bytes JMP 001E0804
.text C:\ProgramData\71INKUmw.exe[3768] USER32.dll!SetWinEventHook 773D507E 5 Bytes JMP 001E01F8
.text C:\ProgramData\71INKUmw.exe[3768] USER32.dll!SetWindowsHookExA 773F6DFA 5 Bytes JMP 001E0600
.text C:\Windows\system32\svchost.exe[3796] ntdll.dll!LdrUnloadDll 7775BD1F 5 Bytes JMP 000603FC
.text C:\Windows\system32\svchost.exe[3796] ntdll.dll!LdrLoadDll 7775F425 5 Bytes JMP 000601F8
.text C:\Windows\system32\svchost.exe[3796] kernel32.dll!GetBinaryTypeW + 70 762B78FC 1 Byte [62]
.text C:\Program Files\Internet Explorer\iexplore.exe[4044] ntdll.dll!LdrUnloadDll 7775BD1F 5 Bytes JMP 000503FC
.text C:\Program Files\Internet Explorer\iexplore.exe[4044] ntdll.dll!LdrLoadDll 7775F425 5 Bytes JMP 000501F8
.text C:\Program Files\Internet Explorer\iexplore.exe[4044] kernel32.dll!GetBinaryTypeW + 70 762B78FC 1 Byte [62]
.text C:\Program Files\Internet Explorer\iexplore.exe[4044] USER32.dll!UnhookWindowsHookEx 773CCC7B 5 Bytes JMP 6B3E8362 C:\Windows\system32\IEFRAME.dll (Internet Browser/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\iexplore.exe[4044] USER32.dll!CallNextHookEx 773CCC8F 5 Bytes JMP 6B3C9D40 C:\Windows\system32\IEFRAME.dll (Internet Browser/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\iexplore.exe[4044] USER32.dll!UnhookWinEvent 773CD924 5 Bytes JMP 000F03FC
.text C:\Program Files\Internet Explorer\iexplore.exe[4044] USER32.dll!CreateWindowExW 773D0E51 5 Bytes JMP 6B3D812F C:\Windows\system32\IEFRAME.dll (Internet Browser/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\iexplore.exe[4044] USER32.dll!SetWindowsHookExW 773D210A 5 Bytes JMP 6B38461B C:\Windows\system32\IEFRAME.dll (Internet Browser/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\iexplore.exe[4044] USER32.dll!SetWinEventHook 773D507E 5 Bytes JMP 000F01F8
.text C:\Program Files\Internet Explorer\iexplore.exe[4044] USER32.dll!DialogBoxIndirectParamW 773F4AA7 5 Bytes JMP 6B5001A0 C:\Windows\system32\IEFRAME.dll (Internet Browser/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\iexplore.exe[4044] USER32.dll!DialogBoxParamW 773F564A 5 Bytes JMP 6B2F4B87 C:\Windows\system32\IEFRAME.dll (Internet Browser/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\iexplore.exe[4044] USER32.dll!SetWindowsHookExA 773F6DFA 5 Bytes JMP 000F0600
.text C:\Program Files\Internet Explorer\iexplore.exe[4044] USER32.dll!DialogBoxParamA 7740CF6A 5 Bytes JMP 6B50013D C:\Windows\system32\IEFRAME.dll (Internet Browser/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\iexplore.exe[4044] USER32.dll!DialogBoxIndirectParamA 7740D29C 5 Bytes JMP 6B500203 C:\Windows\system32\IEFRAME.dll (Internet Browser/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\iexplore.exe[4044] USER32.dll!MessageBoxIndirectA 7741E8C9 5 Bytes JMP 6B5000D2 C:\Windows\system32\IEFRAME.dll (Internet Browser/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\iexplore.exe[4044] USER32.dll!MessageBoxIndirectW 7741E9C3 5 Bytes JMP 6B500067 C:\Windows\system32\IEFRAME.dll (Internet Browser/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\iexplore.exe[4044] USER32.dll!MessageBoxExA 7741EA29 5 Bytes JMP 6B500005 C:\Windows\system32\IEFRAME.dll (Internet Browser/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\iexplore.exe[4044] USER32.dll!MessageBoxExW 7741EA4D 5 Bytes JMP 6B4FFFA3 C:\Windows\system32\IEFRAME.dll (Internet Browser/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\iexplore.exe[4044] ole32.dll!OleLoadFromStream 75F45BF6 5 Bytes JMP 6B5004FE C:\Windows\system32\IEFRAME.dll (Internet Browser/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\iexplore.exe[4044] ole32.dll!CoCreateInstance 75F9590C 5 Bytes JMP 6B3D8C1D C:\Windows\system32\IEFRAME.dll (Internet Browser/Microsoft Corporation)
.text C:\Windows\system32\AUDIODG.EXE[5440] kernel32.dll!GetBinaryTypeW + 70 762B78FC 1 Byte [62]
.text C:\Program Files\Internet Explorer\iexplore.exe[5664] ntdll.dll!LdrUnloadDll 7775BD1F 5 Bytes JMP 000503FC
.text C:\Program Files\Internet Explorer\iexplore.exe[5664] ntdll.dll!LdrLoadDll 7775F425 5 Bytes JMP 000501F8
.text C:\Program Files\Internet Explorer\iexplore.exe[5664] kernel32.dll!GetBinaryTypeW + 70 762B78FC 1 Byte [62]
.text C:\Program Files\Internet Explorer\iexplore.exe[5664] USER32.dll!UnhookWindowsHookEx 773CCC7B 5 Bytes JMP 6B3E8362 C:\Windows\system32\IEFRAME.dll (Internet Browser/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\iexplore.exe[5664] USER32.dll!CallNextHookEx 773CCC8F 5 Bytes JMP 6B3C9D40 C:\Windows\system32\IEFRAME.dll (Internet Browser/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\iexplore.exe[5664] USER32.dll!UnhookWinEvent 773CD924 5 Bytes JMP 000F03FC
.text C:\Program Files\Internet Explorer\iexplore.exe[5664] USER32.dll!CreateWindowExW 773D0E51 5 Bytes JMP 6B3D812F C:\Windows\system32\IEFRAME.dll (Internet Browser/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\iexplore.exe[5664] USER32.dll!SetWindowsHookExW 773D210A 5 Bytes JMP 6B38461B C:\Windows\system32\IEFRAME.dll (Internet Browser/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\iexplore.exe[5664] USER32.dll!SetWinEventHook 773D507E 5 Bytes JMP 000F01F8
.text C:\Program Files\Internet Explorer\iexplore.exe[5664] USER32.dll!DialogBoxIndirectParamW 773F4AA7 5 Bytes JMP 6B5001A0 C:\Windows\system32\IEFRAME.dll (Internet Browser/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\iexplore.exe[5664] USER32.dll!DialogBoxParamW 773F564A 5 Bytes JMP 6B2F4B87 C:\Windows\system32\IEFRAME.dll (Internet Browser/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\iexplore.exe[5664] USER32.dll!SetWindowsHookExA 773F6DFA 5 Bytes JMP 000F0600
.text C:\Program Files\Internet Explorer\iexplore.exe[5664] USER32.dll!DialogBoxParamA 7740CF6A 5 Bytes JMP 6B50013D C:\Windows\system32\IEFRAME.dll (Internet Browser/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\iexplore.exe[5664] USER32.dll!DialogBoxIndirectParamA 7740D29C 5 Bytes JMP 6B500203 C:\Windows\system32\IEFRAME.dll (Internet Browser/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\iexplore.exe[5664] USER32.dll!MessageBoxIndirectA 7741E8C9 5 Bytes JMP 6B5000D2 C:\Windows\system32\IEFRAME.dll (Internet Browser/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\iexplore.exe[5664] USER32.dll!MessageBoxIndirectW 7741E9C3 5 Bytes JMP 6B500067 C:\Windows\system32\IEFRAME.dll (Internet Browser/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\iexplore.exe[5664] USER32.dll!MessageBoxExA 7741EA29 5 Bytes JMP 6B500005 C:\Windows\system32\IEFRAME.dll (Internet Browser/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\iexplore.exe[5664] USER32.dll!MessageBoxExW 7741EA4D 5 Bytes JMP 6B4FFFA3 C:\Windows\system32\IEFRAME.dll (Internet Browser/Microsoft Corporation)
.text C:\Users\Aura\Desktop\8hyl4wb5.exe[6036] ntdll.dll!LdrUnloadDll 7775BD1F 5 Bytes JMP 001603FC
.text C:\Users\Aura\Desktop\8hyl4wb5.exe[6036] ntdll.dll!LdrLoadDll 7775F425 5 Bytes JMP 001601F8
.text C:\Users\Aura\Desktop\8hyl4wb5.exe[6036] kernel32.dll!GetBinaryTypeW + 70 762B78FC 1 Byte [62]
.text C:\Users\Aura\Desktop\8hyl4wb5.exe[6036] USER32.dll!UnhookWindowsHookEx 773CCC7B 5 Bytes JMP 00210A08
.text C:\Users\Aura\Desktop\8hyl4wb5.exe[6036] USER32.dll!UnhookWinEvent 773CD924 5 Bytes JMP 002103FC
.text C:\Users\Aura\Desktop\8hyl4wb5.exe[6036] USER32.dll!SetWindowsHookExW 773D210A 5 Bytes JMP 00210804
.text C:\Users\Aura\Desktop\8hyl4wb5.exe[6036] USER32.dll!SetWinEventHook 773D507E 5 Bytes JMP 002101F8
.text C:\Users\Aura\Desktop\8hyl4wb5.exe[6036] USER32.dll!SetWindowsHookExA 773F6DFA 5 Bytes JMP 00210600

---- Devices - GMER 1.0.15 ----

Device \FileSystem\Ntfs \Ntfs aswSP.SYS (avast! self protection module/AVAST Software)
Device \Driver\ACPI_HAL \Device\00000046 halmacpi.dll (Hardware Abstraction Layer DLL/Microsoft Corporation)

AttachedDevice \Driver\tdx \Device\Tcp aswTdi.SYS (avast! TDI Filter Driver/AVAST Software)
AttachedDevice \Driver\volmgr \Device\HarddiskVolume1 fvevol.sys (BitLocker Drive Encryption Driver/Microsoft Corporation)
AttachedDevice \Driver\volmgr \Device\HarddiskVolume2 fvevol.sys (BitLocker Drive Encryption Driver/Microsoft Corporation)
AttachedDevice \Driver\volmgr \Device\HarddiskVolume3 fvevol.sys (BitLocker Drive Encryption Driver/Microsoft Corporation)
AttachedDevice \Driver\volmgr \Device\HarddiskVolume4 fvevol.sys (BitLocker Drive Encryption Driver/Microsoft Corporation)
AttachedDevice \Driver\volmgr \Device\HarddiskVolume5 fvevol.sys (BitLocker Drive Encryption Driver/Microsoft Corporation)
AttachedDevice \Driver\volmgr \Device\HarddiskVolume6 fvevol.sys (BitLocker Drive Encryption Driver/Microsoft Corporation)
AttachedDevice \Driver\tdx \Device\Udp aswTdi.SYS (avast! TDI Filter Driver/AVAST Software)

---- Files - GMER 1.0.15 ----

File C:\Windows\System32\config\systemprofile\AppData\Local\Microsoft\Internet Explorer\Recovery\High\Active\{F7778F70-8131-11E1-A3B7-6C626D8CB397}.dat 0 bytes
File C:\Windows\System32\config\systemprofile\AppData\Local\Microsoft\Internet Explorer\Recovery\High\Active\{F7778F71-8131-11E1-A3B7-6C626D8CB397}.dat 0 bytes
File C:\Windows\System32\config\systemprofile\AppData\Local\Microsoft\Internet Explorer\Recovery\High\Active\{F7778F72-8131-11E1-A3B7-6C626D8CB397}.dat 0 bytes
File C:\Windows\System32\config\systemprofile\AppData\Local\Microsoft\Internet Explorer\Recovery\High\Active\{D6551BA7-8131-11E1-A3B7-6C626D8CB397}.dat 4608 bytes
File C:\Windows\System32\config\systemprofile\AppData\Local\Microsoft\Internet Explorer\Recovery\High\Active\{DCCE3660-8131-11E1-A3B7-6C626D8CB397}.dat 4096 bytes
File C:\Windows\System32\config\systemprofile\AppData\Local\Microsoft\Internet Explorer\Recovery\High\Active\{DCCE3668-8131-11E1-A3B7-6C626D8CB397}.dat 4608 bytes
File C:\Windows\System32\config\systemprofile\AppData\Local\Microsoft\Internet Explorer\Recovery\High\Active\{EAD0F187-8131-11E1-A3B7-6C626D8CB397}.dat 0 bytes
File C:\Windows\System32\config\systemprofile\AppData\Local\Microsoft\Internet Explorer\Recovery\High\Active\{F1652D97-8131-11E1-A3B7-6C626D8CB397}.dat 3584 bytes
File C:\Windows\System32\config\systemprofile\AppData\Local\Microsoft\Internet Explorer\Recovery\High\Active\{F1652D98-8131-11E1-A3B7-6C626D8CB397}.dat 4608 bytes
File C:\Windows\System32\config\systemprofile\AppData\Local\Microsoft\Internet Explorer\Recovery\High\Active\{F1652D99-8131-11E1-A3B7-6C626D8CB397}.dat 4608 bytes
File C:\Windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\MXR2HF81\sh082[1].html 42022 bytes
File C:\Windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\MXR2HF81\show[1].gif 0 bytes
File C:\Windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\MXR2HF81\show_ads[1].js 0 bytes
File C:\Windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\MXR2HF81\socket.io[1].js 42299 bytes
File C:\Windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\MXR2HF81\aj_gbn_dblclicks[1].js 3213 bytes
File C:\Windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\MXR2HF81\api[1].txt 105 bytes
File C:\Windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\MXR2HF81\TTT[1].swf 245941 bytes
File C:\Windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\MXR2HF81\lightr_gdt[1].gif 0 bytes
File C:\Windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\MXR2HF81\loginControl[1].js 11810 bytes
File C:\Windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\MXR2HF81\hover_sound_on_button_300x250[1].png 5745 bytes
File C:\Windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\MXR2HF81\i2[1].htm 0 bytes
File C:\Windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\MXR2HF81\i2[2].htm 725 bytes
File C:\Windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\MXR2HF81\i2[3].htm 725 bytes
File C:\Windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\MXR2HF81\ql9vukDCc4R[1].png 1177 bytes
File C:\Windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\MXR2HF81\qn_random[1].gif 630 bytes
File C:\Windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\MXR2HF81\rs[1].js 28387 bytes
File C:\Windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\MXR2HF81\S2s76rwkqf2e_w200[1].jpg 33288 bytes
File C:\Windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\MXR2HF81\S2sd6rwqt893_w200[1].jpg 44306 bytes
File C:\Windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\MXR2HF81\Sale_Spring_Pantech_111095_160x600_040312[1].swf 34537 bytes
File C:\Windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\MXR2HF81\set[1].gif 43 bytes
File C:\Windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\MXR2HF81\InBannerVideo[1].swf 29941 bytes
File C:\Windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\MXR2HF81\index-ie[1].css 11077 bytes
File C:\Windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\MXR2HF81\8236287e39d41f51d4cacab8961d8e97[1].gif 19601 bytes
File C:\Windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\MXR2HF81\85978_US_2012_Q2_Brand_Cross_Vertical_300x250[1].js 4291 bytes
File C:\Windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\MXR2HF81\85978_US_2012_Q2_Brand_Cross_Vertical_300x250[1].swf 0 bytes
File C:\Windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\MXR2HF81\8807455732131993243[1].jpg 0 bytes
File C:\Windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\MXR2HF81\9d05518b2d2c0afde9ffbfc5815eda90[1].swf 0 bytes
File C:\Windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\MXR2HF81\;ord=3056879480031663794[1].htm 800 bytes
File C:\Windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\MXR2HF81\;ord=3113649105352332439[1].htm 16495 bytes
File C:\Windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\MXR2HF81\;ord=3498891075239591849[1].htm 16483 bytes
File C:\Windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\MXR2HF81\;ord=3808217604899782569[1].htm 16483 bytes
File C:\Windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\MXR2HF81\;ord=3808217604899782569[2].htm 798 bytes
File C:\Windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\MXR2HF81\;ord=4003848793672649743[1].htm 16535 bytes
File C:\Windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\MXR2HF81\;ord=4027571990627769856[1].htm 800 bytes
File C:\Windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\MXR2HF81\;ord=4072923519793089279[1].htm 800 bytes
File C:\Windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\MXR2HF81\;ord=4115306520010484339[1].htm 798 bytes
File C:\Windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\MXR2HF81\;ord=4356949748017486167[1].htm 800 bytes
File C:\Windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\MXR2HF81\;ord=7392340516139788589[1].htm 0 bytes
File C:\Windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\MXR2HF81\;ord=7392340516139788589[2].htm 0 bytes
File C:\Windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\MXR2HF81\;ord=8207757340085224912[1].htm 798 bytes
File C:\Windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\MXR2HF81\;ord=8720514410590606080[1].htm 16485 bytes
File C:\Windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\MXR2HF81\a3e7fcb1e2655552b5570041b25e6d1[1].swf 28138 bytes
File C:\Windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\MXR2HF81\class-120x600[1].gif 0 bytes
File C:\Windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\MXR2HF81\click[1].htm 6705 bytes
File C:\Windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\MXR2HF81\click[2].htm 6589 bytes
File C:\Windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\MXR2HF81\click[4] 10276 bytes
File C:\Windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\MXR2HF81\click[5] 7772 bytes
File C:\Windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\MXR2HF81\passback.c.r[2].htm 0 bytes
File C:\Windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\MXR2HF81\pop-11[1].js 0 bytes
File C:\Windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\MXR2HF81\prWriteCode[1].js 42 bytes
File C:\Windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\MXR2HF81\player[1].swf 0 bytes
File C:\Windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\MXR2HF81\engagement[1].xml 0 bytes
File C:\Windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\MXR2HF81\bookmark[1].png 0 bytes
File C:\Windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\MXR2HF81\button1[1].gif 0 bytes
File C:\Windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\MXR2HF81\caCAFWFUA8 16337 bytes
File C:\Windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\MXR2HF81\03.05.12_BPSpringBreak_MSN_40K_728x90_A[1].swf 27404 bytes
File C:\Windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\MXR2HF81\11039923707@x71[1].htm 0 bytes
File C:\Windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\MXR2HF81\11442917810@x23[1].htm 2187 bytes
File C:\Windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\MXR2HF81\120209_22_BUN_DBL_FeaturesPlus_70_160x600[1].swf 44433 bytes
File C:\Windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\MXR2HF81\1305583660486[1].png 3647 bytes
File C:\Windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\MXR2HF81\1328661820-sharegames-1-2[1].gif 0 bytes
File C:\Windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\MXR2HF81\N3%20Artisan_728x90[1].jpg 35433 bytes
File C:\Windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\MXR2HF81\ncript237[1].js 7132 bytes
File C:\Windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\MXR2HF81\ohiogamefishing[1].com 59 bytes
File C:\Windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\MXR2HF81\updated_ETF_FCS1_300x250[1].swf 38982 bytes
File C:\Windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\MXR2HF81\viapi[1].xml 88 bytes
File C:\Windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\MXR2HF81\visit[1].js 844 bytes
File C:\Windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\MXR2HF81\visit[2].js 1164 bytes
File C:\Windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\MXR2HF81\widget081[1].css 0 bytes
File C:\Windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\MXR2HF81\WWA_Spring12_Brand_JH_LoveHowIFeel_728x90[1].swf 0 bytes
File C:\Windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\MXR2HF81\1d32601b3-6277-4ba5-82de-d3e7919ab383@x90[1] 2132 bytes
File C:\Windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\MXR2HF81\26770X872751.skimlinks[1].js 28915 bytes
File C:\Windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\MXR2HF81\37536[1].gif 43 bytes
File C:\Windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\MXR2HF81\41813_10868409830_9730_q[1].jpg 0 bytes
File C:\Windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\MXR2HF81\4257[1].gif 0 bytes
File C:\Windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\MXR2HF81\4512[1].gif 0 bytes
File C:\Windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\MXR2HF81\4643[1].gif 0 bytes
File C:\Windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\MXR2HF81\4746[1].gif 0 bytes
File C:\Windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\MXR2HF81\4916[1].gif 0 bytes
File C:\Windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\MXR2HF81\5-1004810[1].js 203 bytes
File C:\Windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\MXR2HF81\5208[1].gif 0 bytes
File C:\Windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\MXR2HF81\53739d16-d4cb-4e89-91df-9f2871cceb54[1] 30234 bytes
File C:\Windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\MXR2HF81\5381[1].gif 0 bytes
File C:\Windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\MXR2HF81\5384[1].gif 0 bytes
File C:\Windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\MXR2HF81\5389[1].gif 0 bytes
File C:\Windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\MXR2HF81\ace-createaccount-popup[1].js 7049 bytes
File C:\Windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\MXR2HF81\get.code[1].js 0 bytes
File C:\Windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\MXR2HF81\get.hash[1].php 0 bytes
File C:\Windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\MXR2HF81\g[1].js 0 bytes
File C:\Windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\MXR2HF81\adsCAELA2BI.js 9926 bytes
File C:\Windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\MXR2HF81\adsCAX4K75C.js 9787 bytes
File C:\Windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\MXR2HF81\expansion_embed[1].js 0 bytes
File C:\Windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\MXR2HF81\f3KaqM7xIBg[1].swf 0 bytes
File C:\Windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\MXR2HF81\f581b3d240f3e9f38c9039a9ae46905[1].gif 11783 bytes
File C:\Windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\MXR2HF81\find_ad[1].js 0 bytes
File C:\Windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\MXR2HF81\flash[1].swf 0 bytes
File C:\Windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\MXR2HF81\fmr[1].js 0 bytes
File C:\Windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\MXR2HF81\fm[1].js 0 bytes
File C:\Windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\MXR2HF81\fm[2].js 2598 bytes
File C:\Windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\MXR2HF81\fm[3].js 2561 bytes
File C:\Windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\MXR2HF81\fm[4].js 2495 bytes
File C:\Windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\MXR2HF81\fp[1] 22973 bytes
File C:\Windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\MXR2HF81\documentwrite[1].js 0 bytes
File C:\Windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\MXR2HF81\dppix[1].html 7915 bytes
File C:\Windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\MXR2HF81\tags[1].js 0 bytes
File C:\Windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\MXR2HF81\tools.flashembed-1.0.4.min[1].js 0 bytes
File C:\Windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\MXR2HF81\tr-clk[1].htm 0 bytes
File C:\Windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\MXR2HF81\ads[10].js 9787 bytes
File C:\Windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\MXR2HF81\ads[11].js 10441 bytes
File C:\Windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\MXR2HF81\ads[1].js 0 bytes
File C:\Windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\MXR2HF81\ads[2].js 0 bytes
File C:\Windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\MXR2HF81\ads[3].js 0 bytes
File C:\Windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\MXR2HF81\ads[4].js 0 bytes
File C:\Windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\MXR2HF81\ads[5].js 0 bytes
File C:\Windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\MXR2HF81\ads[6].js 0 bytes
File C:\Windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\MXR2HF81\ads[7].js 0 bytes
File C:\Windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\MXR2HF81\ads[8].js 10047 bytes
File C:\Windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\MXR2HF81\ads[9].js 9787 bytes
File C:\Windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\MXR2HF81\ADTECH;loc=100;target=_blank;key=key1+key2+key3+key4;grp=[group];misc=1333858783864[1] 1493 bytes
File C:\Windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\MXR2HF81\ad_choices_en[2].png 0 bytes
File C:\Windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\MXR2HF81\clk[1].htm 0 bytes
File C:\Windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\MXR2HF81\clk[2].htm 0 bytes
File C:\Windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\MXR2HF81\clk[3].htm 0 bytes
File C:\Windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\MXR2HF81\CollisionAdMarker[1].png 0 bytes
File C:\Windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\MXR2HF81\crossdomain[1].xml 0 bytes
File C:\Windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\MXR2HF81\crossdomain[2].xml 0 bytes
File C:\Windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\MXR2HF81\crossdomain[3].xml 0 bytes
File C:\Windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\MXR2HF81\crossdomain[4].xml 269 bytes
File C:\Windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\MXR2HF81\xml[1].xml 0 bytes
File C:\Windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\MXR2HF81\x[1].gif 1331 bytes
File C:\Windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\MXR2HF81\yui-reset[1].css 1473 bytes
File C:\Windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\MXR2HF81\5390[1].gif 0 bytes
File C:\Windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\MXR2HF81\5394[1].gif 0 bytes
File C:\Windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\MXR2HF81\5396[1].gif 0 bytes
File C:\Windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\MXR2HF81\5403[1].gif 0 bytes
File C:\Windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\MXR2HF81\5408[1].gif 0 bytes
File C:\Windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\MXR2HF81\573189_100003622905810_900608118_q[1].jpg 0 bytes
File C:\Windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\MXR2HF81\5d578ef83d877257cbee0bd9e4b07536[1].gif 0 bytes
File C:\Windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\MXR2HF81\6a4f9ef39a57f44a7d219c9579a8d1c7[1].gif 0 bytes
File C:\Windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\MXR2HF81\blank[1].mp4 5669 bytes
File C:\Windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\MXR2HF81\crossdomain[6].xml 0 bytes
File C:\Windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\MXR2HF81\c[1].js 1000 bytes
File C:\Windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\MXR2HF81\dar_youknowbest_com[1].htm 0 bytes
File C:\Windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\MXR2HF81\dar_youknowbest_com[2].htm 0 bytes
File C:\Windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\MXR2HF81\dar_youknowbest_com[3].htm 0 bytes
File C:\Windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\MXR2HF81\dar_youknowbest_com[4].htm 0 bytes
File C:\Windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\MXR2HF81\dar_youknowbest_com[5].htm 1748 bytes
File C:\Windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\MXR2HF81\jquery.min[1].js 0 bytes
File C:\Windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\MXR2HF81\js[1] 0 bytes
File C:\Windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\MXR2HF81\js[2] 1356 bytes
File C:\Windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\MXR2HF81\js[3] 1292 bytes
File C:\Windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\MXR2HF81\js[4] 1286 bytes
File C:\Windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\MXR2HF81\js[5] 1304 bytes
File C:\Windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\MXR2HF81\jwplayer-5.7[1].js 133009 bytes
File C:\Windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\MXR2HF81\banner[1] 0 bytes
File C:\Windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\MXR2HF81\banner[2] 0 bytes
File C:\Windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\MXR2HF81\banner[3] 0 bytes
File C:\Windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\MXR2HF81\bbk[1].css 0 bytes
File C:\Windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\MXR2HF81\1531[1].js 0 bytes
File C:\Windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\MXR2HF81\160x600_ad1_career_002_2_17_NonGames[1].gif 0 bytes
File C:\Windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\MXR2HF81\1638903911@x23[1].htm 0 bytes
File C:\Windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\MXR2HF81\crossdomain[5].xml 151 bytes
File C:\Windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\MXR2HF81\AdFrame_2016[1].json 0 bytes
File C:\Windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\RWFRL000\companions[1].js 12565 bytes
File C:\Windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\RWFRL000\surly[1].js 2101 bytes
File C:\Windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\RWFRL000\fantapper_com[1].txt 0 bytes
File C:\Windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\RWFRL000\fb_signin_icon[1].png 0 bytes
File C:\Windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\RWFRL000\fm[1].js 0 bytes
File C:\Windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\RWFRL000\fm[2].js 3377 bytes
File C:\Windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\RWFRL000\fm[3].js 0 bytes
File C:\Windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\RWFRL000\dar_youknowbest_com[1].htm 0 bytes
File C:\Windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\RWFRL000\dar_youknowbest_com[2].htm 0 bytes
File C:\Windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\RWFRL000\dar_youknowbest_com[3].htm 0 bytes
File C:\Windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\RWFRL000\dar_youknowbest_com[4].htm 1748 bytes
File C:\Windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\RWFRL000\dar_youknowbest_com[5].htm 1748 bytes
File C:\Windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\RWFRL000\PortalServe[2] 665 bytes
File C:\Windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\RWFRL000\PortalServe[2].htm 18023 bytes
File C:\Windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\RWFRL000\fp[1] 0 bytes
File C:\Windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\RWFRL000\ci[1].png 1525 bytes
File C:\Windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\RWFRL000\banner[1] 0 bytes
File C:\Windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\RWFRL000\banner[1].htm 5370 bytes
File C:\Windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\RWFRL000\banner[2] 0 bytes
File C:\Windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\RWFRL000\banner[3] 5916 bytes
File C:\Windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\RWFRL000\AdControl[1] 0 bytes
File C:\Windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\RWFRL000\0c189f68-4dd2-45b3-95bb-448a3d2ff226[1] 0 bytes
File C:\Windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\RWFRL000\1-11686-Nespresso-Banners-160x600[1].swf 35953 bytes
File C:\Windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\RWFRL000\dpx[1].gif 0 bytes
File C:\Windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\RWFRL000\S2s66rwnn3sm_w200[1].jpg 0 bytes
File C:\Windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\RWFRL000\S2w16s4kj3j0_w200[1].jpg 0 bytes
File C:\Windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\RWFRL000\S2w86rw9psj2_w200[1].jpg 0 bytes
File C:\Windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\RWFRL000\liverail_preroll[1].swf 0 bytes
File C:\Windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\RWFRL000\1[1].txt 0 bytes
File C:\Windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\RWFRL000\i2[1].htm 0 bytes
File C:\Windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\RWFRL000\i2[2].htm 0 bytes
File C:\Windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\RWFRL000\viapi[1].xml 155 bytes
File C:\Windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\RWFRL000\viapi[2].xml 84 bytes
File C:\Windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\RWFRL000\vi_player[1].js 17421 bytes
File C:\Windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\RWFRL000\ads[1].js 0 bytes
File C:\Windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\RWFRL000\ads[2].js 0 bytes
File C:\Windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\RWFRL000\ads[3].js 0 bytes
File C:\Windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\RWFRL000\ads[4].js 0 bytes
File C:\Windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\RWFRL000\ads[5].js 9500 bytes
File C:\Windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\RWFRL000\ads[6].js 9787 bytes
File C:\Windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\RWFRL000\ads[7].js 9787 bytes
File C:\Windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\RWFRL000\tattooartists[1].org 0 bytes
File C:\Windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\RWFRL000\;ord=2371037256021607888[1].htm 0 bytes
File C:\Windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\RWFRL000\;ord=3182901427204685729[1].htm 0 bytes
File C:\Windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\RWFRL000\;ord=4027571990627769856[1].htm 0 bytes
File C:\Windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\RWFRL000\;ord=4552569591201487191[1].htm 0 bytes
File C:\Windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\RWFRL000\;ord=7367830141465363070[1].htm 0 bytes
File C:\Windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\RWFRL000\;ord=8108928819253826405[1].htm 0 bytes
File C:\Windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\RWFRL000\;ord=8541335425254971898[1].htm 800 bytes
File C:\Windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\RWFRL000\;ord=8720514410590606080[1].htm 0 bytes
File C:\Windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\RWFRL000\x[1].gif 0 bytes
File C:\Windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\RWFRL000\dvtp_src[1].js 7832 bytes
File C:\Windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\RWFRL000\Shell_160x600[1].swf 8059 bytes
File C:\Windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\RWFRL000\546[1].js 0 bytes
File C:\Windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\RWFRL000\546[2].js 0 bytes
File C:\Windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\RWFRL000\AdFrame_2014[1].json 599 bytes
File C:\Windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\SJZAKRLB\1-US_FY12-MarApr_Tribal_BANNER_GW_LASweeps_flash_728x90[1].swf 0 bytes
File C:\Windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\SJZAKRLB\lineageland[1].ru 0 bytes
File C:\Windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\SJZAKRLB\Loading[1].swf 2018 bytes
File C:\Windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\SJZAKRLB\click[2].htm 0 bytes
File C:\Windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\SJZAKRLB\click[3].htm 0 bytes
File C:\Windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\SJZAKRLB\AdControl[1] 0 bytes
File C:\Windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\SJZAKRLB\adc_wfp_smokeygetrid_300x250[1].jpg 0 bytes
File C:\Windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\SJZAKRLB\AdFrame_2017[1].json 0 bytes
File C:\Windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\SJZAKRLB\d5cfcffc8c61de1b0cbb1d6dc7eebe22[1].swf 39571 bytes
File C:\Windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\SJZAKRLB\dar_youknowbest_com[1].htm 0 bytes
File C:\Windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\SJZAKRLB\dar_youknowbest_com[2].htm 0 bytes
File C:\Windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\SJZAKRLB\;ord=8244994471563929854[1].htm 0 bytes
File C:\Windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\SJZAKRLB\S2s66rwnn3sp_w200[1].jpg 0 bytes
File C:\Windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\SJZAKRLB\S2s66rwnn3sr_w200[1].jpg 0 bytes
File C:\Windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\SJZAKRLB\S2sf6rsmx9zp_w200[1].jpg 0 bytes
File C:\Windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\SJZAKRLB\ads[2].js 0 bytes
File C:\Windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\SJZAKRLB\ads[3].js 0 bytes
File C:\Windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\SJZAKRLB\ads[4].js 0 bytes
File C:\Windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\SJZAKRLB\ads[5].js 0 bytes
File C:\Windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\SJZAKRLB\ultimatemotorcycling[1].com 0 bytes
File C:\Windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\SJZAKRLB\2105d96b7877d8fb41416ca3f1946edc[1].swf 8682 bytes
File C:\Windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\SJZAKRLB\viapi[1].xml 155 bytes
File C:\Windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\SJZAKRLB\tr-clk[1].htm 0 bytes
File C:\Windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\SJZAKRLB\trans[1].gif 0 bytes
File C:\Windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\SJZAKRLB\Dex_wedding_160x600[1].swf 0 bytes
File C:\Windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\SJZAKRLB\dvtp_src[1].js 0 bytes
File C:\Windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\SJZAKRLB\js[1] 0 bytes
File C:\Windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\SJZAKRLB\js[2] 0 bytes
File C:\Windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\SJZAKRLB\js[3] 1283 bytes
File C:\Windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\SJZAKRLB\banner[1] 0 bytes
File C:\Windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\SJZAKRLB\banner[2] 0 bytes
File C:\Windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\SJZAKRLB\banner[3] 5988 bytes
File C:\Windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\SJZAKRLB\4552[1].js 0 bytes
File C:\Windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\SJZAKRLB\4552[2].js 0 bytes
File C:\Windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\SJZAKRLB\caCAB4FPQJ 0 bytes
File C:\Windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\SJZAKRLB\pm[1].htm 0 bytes
File C:\Windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\SJZAKRLB\PortalServe[1].htm 0 bytes
File C:\Windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\SJZAKRLB\PRScript[1].txt 0 bytes
File C:\Windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\SJZAKRLB\fm[1].js 0 bytes
File C:\Windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\SJZAKRLB\fm[2].js 0 bytes
File C:\Windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\SJZAKRLB\getjs[2].aspx 0 bytes
File C:\Windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\TBPQOOT8\HM_AQ_GA_SansDeleteButton_ENUS_728x90[1].swf 0 bytes
File C:\Windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\TBPQOOT8\hypegames[1].com 0 bytes
File C:\Windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\TBPQOOT8\gamesweasel[1].com 0 bytes
File C:\Windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\TBPQOOT8\genreicons[1].png 0 bytes
File C:\Windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\TBPQOOT8\GenreWidget[1].js 0 bytes
File C:\Windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\TBPQOOT8\getdata[1].htm 0 bytes
File C:\Windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\TBPQOOT8\get[2].png 0 bytes
File C:\Windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\TBPQOOT8\h1_gradient[1].gif 0 bytes
File C:\Windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\TBPQOOT8\clk[1] 0 bytes
File C:\Windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\TBPQOOT8\commonsensewithmoney[1].com 0 bytes
File C:\Windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\TBPQOOT8\Controller[1].swf 0 bytes
File C:\Windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\TBPQOOT8\createUserControl[1].js 0 bytes
File C:\Windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\TBPQOOT8\crochet-world[1].com 0 bytes
File C:\Windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\TBPQOOT8\crossdomain[2].xml 0 bytes
File C:\Windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\TBPQOOT8\crossdomain[3].xml 0 bytes
File C:\Windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\TBPQOOT8\2-newLloyds_nocalc_300x250[1].swf 0 bytes
File C:\Windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\TBPQOOT8\203274_100002533176233_3465809_q[1].jpg 0 bytes
File C:\Windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\TBPQOOT8\2283807869c5e6c592d978b66e361e3d[1].gif 0 bytes
File C:\Windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\TBPQOOT8\22fa192417114077180502ec8ab0fbfc[1].swf 0 bytes
File C:\Windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\TBPQOOT8\3482d79cfb5d961709713a43a2b42f65[1].png 0 bytes
File C:\Windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\TBPQOOT8\4259[1].gif 0 bytes
File C:\Windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\TBPQOOT8\4367[1].xml 12793 bytes
File C:\Windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\TBPQOOT8\4378[1].gif 0 bytes
File C:\Windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\TBPQOOT8\4499[1].gif 0 bytes
File C:\Windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\TBPQOOT8\4996[1].gif 0 bytes
File C:\Windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\TBPQOOT8\5027[1].gif 0 bytes
File C:\Windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\TBPQOOT8\viapi[1].xml 222 bytes
File C:\Windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\TBPQOOT8\visit[1].js 0 bytes
File C:\Windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\TBPQOOT8\vpaid_adapter[1].swf 0 bytes
File C:\Windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\TBPQOOT8\WebSocketMain[1].swf 0 bytes
File C:\Windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\TBPQOOT8\WWA_Spring12_Brand_JH_USNWR_Easiest_300x250[1].swf 0 bytes
File C:\Windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\TBPQOOT8\xd_proxy[1].htm 0 bytes
File C:\Windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\TBPQOOT8\xrefid[1].htm 0 bytes
File C:\Windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\TBPQOOT8\x[1].gif 0 bytes
File C:\Windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\TBPQOOT8\zw05_160x600_1009ext[1].swf 0 bytes
File C:\Windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\TBPQOOT8\dvtp_src[1].js 0 bytes
File C:\Windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\TBPQOOT8\e8b1780d1cdc2f336b4a7ae7eb741b27[1].gif 0 bytes
File C:\Windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\TBPQOOT8\engagement[1].xml 0 bytes
File C:\Windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\TBPQOOT8\engagement[2].xml 95 bytes
File C:\Windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\TBPQOOT8\banner[1].htm 0 bytes
File C:\Windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\TBPQOOT8\banner[2] 0 bytes
File C:\Windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\TBPQOOT8\banner[3] 0 bytes
File C:\Windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\TBPQOOT8\beacon[1].js 0 bytes
File C:\Windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\TBPQOOT8\beacon[2].htm 0 bytes
File C:\Windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\TBPQOOT8\static-100x75-c966f0a[1].jpg 0 bytes
File C:\Windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\TBPQOOT8\jquery.tools.min[1].js 0 bytes
File C:\Windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\TBPQOOT8\js[3] 0 bytes
File C:\Windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\TBPQOOT8\js[4] 0 bytes
File C:\Windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\TBPQOOT8\js[5] 1304 bytes
File C:\Windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\TBPQOOT8\![1].gif 0 bytes
File C:\Windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\TBPQOOT8\right[1].gif 0 bytes
File C:\Windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\TBPQOOT8\S2s96rwa555g_w200[1].jpg 0 bytes
File C:\Windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\TBPQOOT8\S2sb6rwa759r_w200[1].jpg 0 bytes
File C:\Windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\TBPQOOT8\S2w46s4kvbbb_w200[1].jpg 0 bytes
File C:\Windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\TBPQOOT8\set[1].gif 0 bytes
File C:\Windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\TBPQOOT8\Shell_160x600[1].swf 0 bytes
File C:\Windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\TBPQOOT8\show[1].htm 0 bytes
File C:\Windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\TBPQOOT8\si[1].htm 0 bytes
File C:\Windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\TBPQOOT8\l_kYQEMzvfA[1].png 0 bytes
File C:\Windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\TBPQOOT8\ads[10].js 0 bytes
File C:\Windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\TBPQOOT8\ads[11].js 9926 bytes
File C:\Windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\TBPQOOT8\ads[2].js 0 bytes
File C:\Windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\TBPQOOT8\favorites[1].js 0 bytes
File C:\Windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\TBPQOOT8\finish_jdra_leftovers15_rev_us_linear_450x360_as3[1].swf 0 bytes
File C:\Windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\TBPQOOT8\flashwrite_1_2[1].js 0 bytes
File C:\Windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\TBPQOOT8\flash[1].swf 0 bytes
File C:\Windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\TBPQOOT8\ForwardIFull_0[1].png 0 bytes
File C:\Windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\TBPQOOT8\fo[1].js 0 bytes
File C:\Windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\TBPQOOT8\AdFrame_2019[1].json 0 bytes
File C:\Windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\TBPQOOT8\AdFrame_2021[1].json 0 bytes
File C:\Windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\TBPQOOT8\AdId=2567906;BnId=1;ct=813290368;st=4771;adcid=1;itime=858741690;reqtype=5;[1] 0 bytes
File C:\Windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\TBPQOOT8\80367900-29cb-4634-828d-cefa88c32d74[1] 0 bytes
File C:\Windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\TBPQOOT8\85978_US_2012_Q2_Brand_Cross_Vertical_300x250[1].swf 0 bytes
File C:\Windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\TBPQOOT8\899f32264f51d194dff3d695df22a309[1].swf 0 bytes
File C:\Windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\TBPQOOT8\;ord=2574711721202038212[1].htm 0 bytes
File C:\Windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\TBPQOOT8\;ord=2586975837863708112[1].htm 0 bytes
File C:\Windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\TBPQOOT8\;ord=2689624975403225856[1].htm 0 bytes
File C:\Windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\TBPQOOT8\;ord=3086377651569414968[1].htm 0 bytes
File C:\Windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\TBPQOOT8\;ord=3113649105352332439[1].htm 0 bytes
File C:\Windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\TBPQOOT8\;ord=3203150547956636816[1].htm 0 bytes
File C:\Windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\TBPQOOT8\;ord=3265435126060651264[1].htm 800 bytes
File C:\Windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\TBPQOOT8\;ord=4072923519793089279[1].htm 0 bytes
File C:\Windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\TBPQOOT8\;ord=4072923519793089279[2].htm 0 bytes
File C:\Windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\TBPQOOT8\;ord=4408796729364561207[1].htm 0 bytes
File C:\Windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\TBPQOOT8\;ord=6961021591869983759[1].htm 0 bytes
File C:\Windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\TBPQOOT8\;ord=7285366441750227571[1].htm 0 bytes
File C:\Windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\TBPQOOT8\@x94[1].htm 0 bytes
File C:\Windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\TBPQOOT8\a3e7fcb1e2655552b5570041b25e6d1[1].swf 0 bytes
File C:\Windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\TBPQOOT8\mrmovietimes[1].com 0 bytes
File C:\Windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\TBPQOOT8\mt[1].js 0 bytes
File C:\Windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\TBPQOOT8\mt[2].js 0 bytes
File C:\Windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\TBPQOOT8\null[1].gif 0 bytes
File C:\Windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\TBPQOOT8\p030kt_4FXu[1].js 0 bytes
File C:\Windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\TBPQOOT8\crossdomain[5].xml 0 bytes
File C:\Windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\TBPQOOT8\c_100_us[1].png 0 bytes
File C:\Windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\TBPQOOT8\dar_youknowbest_com[1].htm 0 bytes
File C:\Windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\TBPQOOT8\dar_youknowbest_com[2].htm 0 bytes
File C:\Windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\TBPQOOT8\dar_youknowbest_com[3].htm 0 bytes
File C:\Windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\TBPQOOT8\dar_youknowbest_com[4].htm 0 bytes
File C:\Windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\TBPQOOT8\dar_youknowbest_com[5].htm 0 bytes
File C:\Windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\TBPQOOT8\dar_youknowbest_com[6].htm 0 bytes
File C:\Windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\TBPQOOT8\dar_youknowbest_com[7].htm 0 bytes
File C:\Windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\TBPQOOT8\dar_youknowbest_com[8].htm 0 bytes
File C:\Windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\TBPQOOT8\dar_youknowbest_com[9].htm 1748 bytes
File C:\Windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\TBPQOOT8\casale-728[1].htm 0 bytes
File C:\Windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\TBPQOOT8\ads[5].js 0 bytes
File C:\Windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\TBPQOOT8\ads[6].js 0 bytes
File C:\Windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\TBPQOOT8\ads[7].js 0 bytes
File C:\Windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\TBPQOOT8\ads[8].js 0 bytes
File C:\Windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\TBPQOOT8\ads[9].js 0 bytes
File C:\Windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\TBPQOOT8\adv2[1].jsp 0 bytes
File C:\Windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\TBPQOOT8\ad[1].gif 0 bytes
File C:\Windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\TBPQOOT8\5378[1].gif 0 bytes
File C:\Windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\TBPQOOT8\5379[1].gif 0 bytes
File C:\Windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\TBPQOOT8\5385[1].gif 0 bytes
File C:\Windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\TBPQOOT8\5386[1].gif 0 bytes
File C:\Windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\TBPQOOT8\5393[1].gif 0 bytes
File C:\Windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\TBPQOOT8\5398[1].gif 0 bytes
File C:\Windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\TBPQOOT8\573602_100003242261173_820225567_q[1].jpg 0 bytes
File C:\Windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\TBPQOOT8\62c6c91a03e6a19ce1b63cb44701a56d[1].swf 0 bytes
File C:\Windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\TBPQOOT8\698aca63c26a4310f9773ae4d46dc9a5[1].jpg 0 bytes
File C:\Windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\TBPQOOT8\ad_call[1].js 0 bytes
File C:\Windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\TBPQOOT8\ad_choices_i_UR[1].png 0 bytes
File C:\Windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\TBPQOOT8\ad_choices_UR[1].png 0 bytes
File C:\Windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\TBPQOOT8\ace-account-verification[1].js 0 bytes
File C:\Windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\TBPQOOT8\ace-alert[1].js 0 bytes
File C:\Windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\TBPQOOT8\ace-utils[1].js 0 bytes
File C:\Windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\TBPQOOT8\aceUAC[1].js 16842 bytes
File C:\Windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\TBPQOOT8\Ad.autoLoad[1].js 0 bytes
File C:\Windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\TBPQOOT8\redvase[1].js 0 bytes
File C:\Windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\TBPQOOT8\red_blob[1].png 0 bytes
File C:\Windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\TBPQOOT8\red_gdt[1].gif 176 bytes
File C:\Windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\TBPQOOT8\refi-200x150-fa739d3[1].jpg 0 bytes
File C:\Windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\TBPQOOT8\LiveRail.Interstitial-1.0.min[1].js 0 bytes
File C:\Windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\TBPQOOT8\logo[1].png 0 bytes
File C:\Windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\TBPQOOT8\br_fob[1].js 0 bytes
File C:\Windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\TBPQOOT8\qn_action[1].gif 0 bytes
File C:\Windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\TBPQOOT8\qn_adventure[1].gif 0 bytes
File C:\Windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\TBPQOOT8\qn_arcade[1].gif 0 bytes
File C:\Windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\TBPQOOT8\qn_puzzle[1].gif 0 bytes
File C:\Windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\TBPQOOT8\qn_sports[1].gif 0 bytes
File C:\Windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\TBPQOOT8\10926-BrightRollRetargeting-Elizabeth-728x90[1].flv 0 bytes
File C:\Windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\TBPQOOT8\1301347487821[1].png 0 bytes
File C:\Windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\TBPQOOT8\132[1].png 0 bytes
File C:\Windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\TBPQOOT8\almuraba[1].net 0 bytes
File C:\Windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\TBPQOOT8\quant[1].js 5299 bytes
File C:\Windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\TBPQOOT8\Pix-1x1[1].gif 0 bytes
File C:\Windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\TBPQOOT8\click[1] 0 bytes
File C:\Windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\TBPQOOT8\lysol_intoiletbowl_reflection15_etailing_us_linear_450x360_as3[1].swf 0 bytes
File C:\Windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\TBPQOOT8\1px[1].png 0 bytes
File C:\Windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\TBPQOOT8\1vGqA-l6BPK[1].js 0 bytes
File C:\Windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\TBPQOOT8\surly[1].js 0 bytes
File C:\Windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\TBPQOOT8\surly[2].js 0 bytes
File C:\Windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\TBPQOOT8\surly[3].js 0 bytes
File C:\Windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\TBPQOOT8\surly[4].js 0 bytes
File C:\Windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\TBPQOOT8\T5Rs2_ktfdr[1].js 0 bytes
File C:\Windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\TBPQOOT8\tap[2].gif 0 bytes
File C:\Windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\TBPQOOT8\telemetry_player_vpaid_as3[2].swf 0 bytes
File C:\Windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\TBPQOOT8\display[1].php 0 bytes
File C:\Windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\TBPQOOT8\dppix[1].html 0 bytes
File C:\Windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\TBPQOOT8\dpx[1].gif 0 bytes
File C:\Windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\TCWHLT6F\HM_AQ_GA_MobileSlotMachineSU_ENUS_728x90[1].swf 0 bytes
File C:\Windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\TCWHLT6F\i2[1].htm 0 bytes
File C:\Windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\TCWHLT6F\i2[2].htm 0 bytes
File C:\Windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\TCWHLT6F\tf_adChoice10[1].js 0 bytes
File C:\Windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\TCWHLT6F\tr-clk[1].htm 0 bytes
File C:\Windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\TCWHLT6F\Track[1].txt 0 bytes
File C:\Windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\TCWHLT6F\;ord=3498891075239591849[1].htm 0 bytes
File C:\Windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\TCWHLT6F\ads[4].htm 0 bytes
File C:\Windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\TCWHLT6F\ads[4].js 0 bytes
File C:\Windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\TCWHLT6F\ads[5].js 0 bytes
File C:\Windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\TCWHLT6F\ads[6].js 0 bytes
File C:\Windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\TCWHLT6F\ads[7].js 0 bytes
File C:\Windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\TCWHLT6F\clk[1] 0 bytes
File C:\Windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\TCWHLT6F\clk[1].htm 0 bytes
File C:\Windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\TCWHLT6F\clk[2].htm 0 bytes
File C:\Windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\TCWHLT6F\cms-2-frame[1].htm 0 bytes
File C:\Windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\TCWHLT6F\connect_using_fb[1].png 0 bytes
File C:\Windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\TCWHLT6F\cookies[1].js 0 bytes
File C:\Windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\TCWHLT6F\core003[1].js 0 bytes
File C:\Windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\TCWHLT6F\InBannerVideo[1].swf 0 bytes
File C:\Windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\TCWHLT6F\India_banner[1].swf 0 bytes
File C:\Windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\TCWHLT6F\i[1].gif 0 bytes
File C:\Windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\TCWHLT6F\jquery-ui.min[1].js 0 bytes
File C:\Windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\TCWHLT6F\jquery.min[1].js 0 bytes
File C:\Windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\TCWHLT6F\1531[1].js 0 bytes
File C:\Windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\TCWHLT6F\1d32601b3-6277-4ba5-82de-d3e7919ab383@x90[1] 0 bytes
File C:\Windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\TCWHLT6F\displayAd[1].js 0 bytes
File C:\Windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\TCWHLT6F\DLX@x72[2].htm 0 bytes
File C:\Windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\TCWHLT6F\dot[1].gif 0 bytes
File C:\Windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\TCWHLT6F\login_logo[1].png 0 bytes
File C:\Windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\TCWHLT6F\mt[1].js 0 bytes
File C:\Windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\TCWHLT6F\mt[2].js 0 bytes
File C:\Windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\TCWHLT6F\newsandtribune[1].com 0 bytes
File C:\Windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\TCWHLT6F\osd[1].js 0 bytes
File C:\Windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\TCWHLT6F\ova[1].swf 0 bytes
File C:\Windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\TCWHLT6F\ad_choices_i[1].png 0 bytes
File C:\Windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\TCWHLT6F\fantapper[1].com 0 bytes
File C:\Windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\TCWHLT6F\fcbb08e8c9a6812a4967f3be44e10027[1].swf 0 bytes
File C:\Windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\TCWHLT6F\adframe.min.4a[1].js 0 bytes
File C:\Windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\TCWHLT6F\AdFrame_2013[2].json 0 bytes
File C:\Windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\TCWHLT6F\AdFrame_2018[2].json 0 bytes
File C:\Windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\TCWHLT6F\AdId=2487995;BnId=3;itime=858672449;nodecode=yes;link=[insert%20click%20tracking%20here][1] 0 bytes
File C:\Windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\TCWHLT6F\AdId=2567907;BnId=1;ct=846298853;st=5068;adcid=1;itime=858774326;reqtype=5;[1] 0 bytes
File C:\Windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\TCWHLT6F\AdId=2647920;BnId=1;ct=772030026;st=1741;adcid=1;itime=858672449;reqtype=5;[1] 0 bytes
File C:\Windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\TCWHLT6F\crossdomain[1].xml 0 bytes
File C:\Windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\TCWHLT6F\crossdomain[2].xml 0 bytes
File C:\Windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\TCWHLT6F\cutildee6d705a5077f097c8c64e02d002b24[1].js 0 bytes
File C:\Windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\TCWHLT6F\dapAdChoice[1].js 0 bytes
File C:\Windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\TCWHLT6F\dar_youknowbest_com[2].htm 0 bytes
File C:\Windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\TCWHLT6F\dar_youknowbest_com[3].htm 1748 bytes
File C:\Windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\TCWHLT6F\surly[1].js 0 bytes
File C:\Windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\TCWHLT6F\s[1].htm 0 bytes
File C:\Windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\TCWHLT6F\telemetry_player_vpaid_as3[3].swf 0 bytes
File C:\Windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\TCWHLT6F\S2s66rwnn3ss_w200[1].jpg 0 bytes
File C:\Windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\TCWHLT6F\S2w36qw97jpx_w200[1].jpg 0 bytes
File C:\Windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\TCWHLT6F\S2w86s4kvcrv_w200[1].jpg 0 bytes
File C:\Windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\TCWHLT6F\aggieathletics[1].com 0 bytes
File C:\Windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\TCWHLT6F\all[1].js 0 bytes
File C:\Windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\TCWHLT6F\drinkoftheweek[1].com 0 bytes
File C:\Windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\TCWHLT6F\engagement[1].xml 0 bytes
File C:\Windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\TCWHLT6F\engagement[2].xml 0 bytes
File C:\Windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\TCWHLT6F\V3player[1].swf 26058 bytes
File C:\Windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\TCWHLT6F\ImageAdLoader[1].swf 11928 bytes
File C:\Windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\TCWHLT6F\imgad[1].swf 0 bytes
File C:\Windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\TCWHLT6F\2532[1].js 0 bytes
File C:\Windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\TCWHLT6F\2532[2].js 0 bytes
File C:\Windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\TCWHLT6F\274930_100000867254964_1911852510_q[1].jpg 0 bytes
File C:\Windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\TCWHLT6F\35149f5f-c0bf-4ee2-8351-a11514130651[1] 34883 bytes
File C:\Windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\TCWHLT6F\3ddfc84cd3885d4534dbd88e4a9d4768[1].swf 0 bytes
File C:\Windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\TCWHLT6F\41480_100001041915225_2196606_q[1].jpg 0 bytes
File C:\Windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\TCWHLT6F\4642[1].gif 0 bytes
File C:\Windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\TCWHLT6F\4667[1].gif 0 bytes
File C:\Windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\TCWHLT6F\4913[1].gif 0 bytes
File C:\Windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\TCWHLT6F\4[1].gif 0 bytes
File C:\Windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\TCWHLT6F\5382[1].gif 0 bytes
File C:\Windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\TCWHLT6F\5383[1].gif 0 bytes
File C:\Windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\TCWHLT6F\5391[1].gif 0 bytes
File C:\Windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\TCWHLT6F\5399[1].gif 0 bytes
File C:\Windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\TCWHLT6F\5400[1].gif 0 bytes
File C:\Windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\TCWHLT6F\5401[1].gif 0 bytes
File C:\Windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\TCWHLT6F\5404[1].gif 0 bytes
File C:\Windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\TCWHLT6F\5405[1].gif 0 bytes
File C:\Windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\TCWHLT6F\5406[1].gif 0 bytes
File C:\Windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\TCWHLT6F\5407[1].gif 0 bytes
File C:\Windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\TCWHLT6F\6238afb1007089f07d7bae115b081125[1].swf 0 bytes
File C:\Windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\TCWHLT6F\fundognames[1].com 0 bytes
File C:\Windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\TCWHLT6F\gaware[1].htm 0 bytes
File C:\Windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\TCWHLT6F\getCode[1].js 0 bytes
File C:\Windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\TCWHLT6F\gmpix-0.9e-live[1].js 0 bytes
File C:\Windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\TCWHLT6F\g[1].js 0 bytes
File C:\Windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\TCWHLT6F\flash[1].swf 0 bytes
File C:\Windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\TCWHLT6F\flash[2].swf 0 bytes
File C:\Windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\TCWHLT6F\fm[1].js 0 bytes
File C:\Windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\TCWHLT6F\fm[2].js 0 bytes
File C:\Windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\TCWHLT6F\fm[3].js 0 bytes
File C:\Windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\TCWHLT6F\fm[4].js 0 bytes
File C:\Windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\TCWHLT6F\pixel[1].gif 0 bytes
File C:\Windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\TCWHLT6F\pixel[2].gif 0 bytes
File C:\Windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\TCWHLT6F\box_77_top-left[1].png 0 bytes
File C:\Windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\TCWHLT6F\box_77_top-right[1].png 0 bytes
File C:\Windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\TCWHLT6F\1-newLloyds_nocalc_728x90[1].swf 0 bytes
File C:\Windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\TCWHLT6F\11039923707@x96[1].htm 0 bytes
File C:\Windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\TCWHLT6F\1333858756[1].gif 0 bytes
File C:\Windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\TCWHLT6F\Shell_160x600[1].swf 0 bytes
File C:\Windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\TCWHLT6F\showad[1].js 0 bytes
File C:\Windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\TCWHLT6F\smallstar[1].gif 0 bytes
File C:\Windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\TCWHLT6F\splashControl[1].js 0 bytes
File C:\Windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\TCWHLT6F\left[1].gif 0 bytes
File C:\Windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\TCWHLT6F\light_gdt[1].gif 147 bytes
File C:\Windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\TCWHLT6F\;ord=4003848793672649743[1].htm 0 bytes
File C:\Windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\TCWHLT6F\;ord=4408796729364561207[1].htm 0 bytes
File C:\Windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\TCWHLT6F\;ord=7182449920007571365[1].htm 0 bytes
File C:\Windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\TCWHLT6F\;ord=7182449920007571365[2].htm 0 bytes
File C:\Windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\TCWHLT6F\;ord=7285366441750227571[1].htm 0 bytes
File C:\Windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\TCWHLT6F\;ord=7367830141465363070[1].htm 0 bytes
File C:\Windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\TCWHLT6F\;ord=7421708048258140069[1].htm 0 bytes
File C:\Windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\TCWHLT6F\;ord=8244994471563929854[1].htm 0 bytes
File C:\Windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\TCWHLT6F\ace-alert2[1].js 0 bytes
File C:\Windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\TCWHLT6F\ace-alert[1].css 0 bytes
File C:\Windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\TCWHLT6F\ace-login[1].js 0 bytes
File C:\Windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\TCWHLT6F\ace-reset-password[1].js 0 bytes
File C:\Windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\TCWHLT6F\visit[1].js 0 bytes
File C:\Windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\TCWHLT6F\visit[2].js 0 bytes
File C:\Windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\TCWHLT6F\workawesome[1].com 0 bytes
File C:\Windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\TCWHLT6F\work[1].htm 0 bytes
File C:\Windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\TCWHLT6F\xml[1].xml 0 bytes
File C:\Windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\TCWHLT6F\xml[2].xml 0 bytes
File C:\Windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\TCWHLT6F\x[1].gif 0 bytes
File C:\Windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\TCWHLT6F\x[2].gif 0 bytes
File C:\Windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\TCWHLT6F\b100x100_GC_3[1].gif 0 bytes
File C:\Windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\TCWHLT6F\baseball.realgm[1].com 0 bytes
File C:\Windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\TCWHLT6F\q9T5l3Sx81U[1].js 0 bytes
File C:\Windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\TCWHLT6F\qn_casino[1].gif 0 bytes
File C:\Windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\TCWHLT6F\qn_shooting[1].gif 0 bytes
File C:\Windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\TCWHLT6F\render_ads[1].js 0 bytes
File C:\Windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\TCWHLT6F\caCAD6TSM4 0 bytes
File C:\Windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\TCWHLT6F\adsbymf[1].gif 0 bytes
File C:\Windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\TCWHLT6F\adchoice_1.4[1].gif 0 bytes
File C:\Windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\TCWHLT6F\star[1].png 0 bytes
File C:\Windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\TCWHLT6F\CATWTXBI.HTM 0 bytes
File C:\Windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\TCWHLT6F\cc22e130e5104f56d33a1d850042df7c[1].gif 0 bytes
File C:\Windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\TCWHLT6F\click[1].htm 0 bytes
File C:\Windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\TCWHLT6F\click[2] 0 bytes
File C:\Windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\TCWHLT6F\click[3] 0 bytes
File C:\Windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\TCWHLT6F\click[4] 0 bytes
File C:\Windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\TCWHLT6F\click[5] 0 bytes
File C:\Windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\UF2TCMUI\js[2] 0 bytes
File C:\Windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\UF2TCMUI\telemetry_player_vpaid_as3[2].swf 0 bytes
File C:\Windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\UF2TCMUI\getjs[1].aspx 0 bytes
File C:\Windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\UF2TCMUI\ads[2].js 0 bytes
File C:\Windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\UF2TCMUI\ads[3].js 0 bytes
File C:\Windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\UF2TCMUI\ads[4].js 0 bytes
File C:\Windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\UF2TCMUI\ads[5].js 0 bytes
File C:\Windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\UF2TCMUI\ads[6].js 0 bytes
File C:\Windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\UF2TCMUI\fm[1].js 0 bytes
File C:\Windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\UF2TCMUI\fm[2].js 0 bytes
File C:\Windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\UF2TCMUI\fm[3].js 0 bytes
File C:\Windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\UF2TCMUI\fm[4].js 0 bytes
File C:\Windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\UF2TCMUI\fm[5].js 0 bytes
File C:\Windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\UF2TCMUI\fp[1] 0 bytes
File C:\Windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\UF2TCMUI\swfobject[1].js 0 bytes
File C:\Windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\UF2TCMUI\AdId=2548885;BnId=1;ct=849964507;st=1246;adcid=1;itime=858778959;reqtype=5;[1] 0 bytes
File C:\Windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\UF2TCMUI\admeld-match[1] 0 bytes
File C:\Windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\UF2TCMUI\Track[1].txt 0 bytes
File C:\Windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\UF2TCMUI\S2s66rwnn3st_w200[1].jpg 0 bytes
File C:\Windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\UF2TCMUI\S2w76s4kj8hj_w200[1].gif 0 bytes
File C:\Windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\UF2TCMUI\;ord=2970774706455616178[1].htm 0 bytes
File C:\Windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\UF2TCMUI\;ord=8207757340085224912[1].htm 0 bytes
File C:\Windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\UF2TCMUI\;ord=8253609160601326437[1].htm 0 bytes
File C:\Windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\UF2TCMUI\1326126768888[1].png 0 bytes
File C:\Windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\UF2TCMUI\viapi[1] 0 bytes
File C:\Windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\UF2TCMUI\banner[1] 0 bytes
File C:\Windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\UF2TCMUI\blank[1].gif 0 bytes
File C:\Windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\UF2TCMUI\box_19_top-right[1].png 0 bytes
File C:\Windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\UF2TCMUI\dot[1].gif 0 bytes
File C:\Windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\UF2TCMUI\Monkey_ExpenseReport_160x600_NonGames[1].jpg 0 bytes
File C:\Windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\UF2TCMUI\numberOfDays[1] 0 bytes
File C:\Windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\UF2TCMUI\1ca64212c-1ae6-4075-8f52-34ff36c55449@x90[1] 0 bytes
File C:\Windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\UF2TCMUI\2c88a3f9012b68e61a2357ddfa1775e4[1].swf 0 bytes
File C:\Windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\UF2TCMUI\318142a31df7dea25894cda740bd9990[1].swf 0 bytes
File C:\Windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\UF2TCMUI\4-1004808[1].js 0 bytes
File C:\Windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\UF2TCMUI\5-1004812[1].js 0 bytes
File C:\Windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\UF2TCMUI\5db65acfd3ede1cda075a24abf97f48c[1].swf 0 bytes
File C:\Windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\UF2TCMUI\6c86df1598d0c8e7e5a855cf8c57c3da[1].gif 0 bytes
File C:\Windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\UF2TCMUI\grist[1].org 0 bytes
File C:\Windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\UF2TCMUI\dar_youknowbest_com[1].htm 0 bytes
File C:\Windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\UF2TCMUI\dar_youknowbest_com[2].htm 0 bytes
File C:\Windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\UF2TCMUI\dar_youknowbest_com[3].htm 0 bytes
File C:\Windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\UF2TCMUI\dar_youknowbest_com[4].htm 0 bytes
File C:\Windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\UF2TCMUI\dar_youknowbest_com[5].htm 0 bytes
File C:\Windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\UF2TCMUI\dar_youknowbest_com[6].htm 0 bytes
File C:\Windows\System32\config\systemprofile\AppData\Roaming\Microsoft\Windows\Cookies\81KGNEWZ.txt 0 bytes
File C:\Windows\System32\config\systemprofile\AppData\Roaming\Microsoft\Windows\Cookies\0SG3LI84.txt 0 bytes
File C:\Windows\System32\config\systemprofile\AppData\Roaming\Microsoft\Windows\Cookies\C3368HI0.txt 0 bytes
File C:\Windows\System32\config\systemprofile\AppData\Roaming\Microsoft\Windows\Cookies\CKK4ZM3U.txt 0 bytes
File C:\Windows\System32\config\systemprofile\AppData\Roaming\Microsoft\Windows\Cookies\K9Y5PR78.txt 0 bytes
File C:\Windows\Temp\~DFADBCAB46BBDFAD52.TMP 0 bytes
File C:\Windows\Temp\~DFD74ED1F54637D2A0.TMP 0 bytes
File C:\Windows\Temp\~DFDF7A3FC20D3D67F2.TMP 512 bytes
File C:\Windows\Temp\~DF87C5378327FA5E0A.TMP 16384 bytes
File C:\Windows\Temp\~DF887CDBD886C5E460.TMP 32768 bytes
File C:\Windows\Temp\~DF8B13366D928EF4F7.TMP 0 bytes
File C:\Windows\Temp\~DFF93067531B54706F.TMP 0 bytes
File C:\Windows\Temp\~DF696E94F1692A51BF.TMP 512 bytes

---- EOF - GMER 1.0.15 ----

#6 Broni

Broni

    The Coolest BC Computer


  • BC Advisor
  • 42,679 posts
  • OFFLINE
  •  
  • Gender:Male
  • Location:Daly City, CA
  • Local time:03:33 PM

Posted 08 April 2012 - 12:32 PM

More advanced tools will be needed.

Please follow the instructions in ==>This Guide<== starting at Step 6. If you cannot complete a step, skip it and continue.

Once the proper logs are created, then make a NEW TOPIC and post it ==>HERE<== Please include a description of your computer issues, what you have done to resolve them, and a link to this topic.

If you can produce at least some of the logs, then please create the new topic and explain what happens when you try to create the log(s) that you couldn't get. If you cannot produce any of the logs, then still post the topic and explain that you followed the Prep. Guide, were unable to create the logs, and describe what happens when you try to create the logs.

It would be helpful if you post a note here once you have completed the steps in the guide and have started your topic in malware removal. Good luck and be patient.

If HelpBot replies to your topic, PLEASE follow Step One so it will report your topic to the team members.

My Website

p4433470.gif

My help doesn't cost a penny, but if you'd like to consider a donation, click p22001735.gif


 





0 user(s) are reading this topic

0 members, 0 guests, 0 anonymous users