Welcome to MalwareRemoval.com,
What if we told you that you could get malware removal help from experts, and that it was 100% free? MalwareRemoval.com provides free support for people with infected computers. Our help, and the tools we use are always 100% free. No hidden catch. We simply enjoy helping others. You enjoy a clean, safe computer.

Malware Removal Instructions

Alureon H removal

MalwareRemoval.com provides free support for people with infected computers. Using plain language that anyone can understand, our community of volunteer experts will walk you through each step.

Re: Alureon H removal

Unread postby magic » June 26th, 2010, 11:02 am

Hi,

Google doesnt seem to be redirecting anymore.

Please see the attached image of the screenshot of Hitman Pro...
You do not have the required permissions to view the files attached to this post.
magic
Regular Member
 
Posts: 28
Joined: June 8th, 2010, 5:36 pm
Advertisement
Register to Remove

Re: Alureon H removal

Unread postby Airscape » June 26th, 2010, 6:04 pm

Hi magic,

Please run this scan, any problems try it in Safe Mode (the same way you ran Gmer)

Please download Rootkit Unhooker and save it to your desktop.
  • Right-click RKUnhookerLE.exe and select "Run as admin" to run it.
  • Click the Report tab, then click Scan
  • Check Drivers, Stealth Code, Files, and Code Hooks
  • Uncheck the rest, then click OK
  • When prompted to Select Disks for Scan, make sure C:\ is checked and click OK
  • Wait till the scanner has finished then go File > Save Report
  • Save the report somewhere you can find it. Click Close
  • Copy the entire contents of the report and paste it in your next reply.
User avatar
Airscape
Regular Member
 
Posts: 1858
Joined: November 1st, 2008, 11:06 pm

Re: Alureon H removal

Unread postby magic » June 27th, 2010, 6:43 pm

RkU Version: 3.8.388.590, Type LE (SR2)
==============================================
OS Name: Windows Vista
Version 6.0.6002 (Service Pack 2)
Number of processors #2
==============================================
>Drivers
==============================================
0x8E40F000 C:\Windows\system32\DRIVERS\igdkmd32.sys 7315456 bytes (Intel Corporation, Intel Graphics Kernel Mode Driver)
0x81E37000 C:\Windows\system32\ntkrnlpa.exe 3903488 bytes (Microsoft Corporation, NT Kernel & System)
0x81E37000 PnpManager 3903488 bytes
0x81E37000 RAW 3903488 bytes
0x81E37000 WMIxWDM 3903488 bytes
0x96C00000 Win32k 2109440 bytes
0x96C00000 C:\Windows\System32\win32k.sys 2109440 bytes (Microsoft Corporation, Multi-User Win32 Driver)
0x8E00C000 C:\Windows\system32\DRIVERS\bcmwl6.sys 1343488 bytes (Broadcom Corporation, Broadcom 802.11 Network Adapter wireless driver)
0x8A008000 C:\Windows\System32\Drivers\Ntfs.sys 1114112 bytes (Microsoft Corporation, NT File System Driver)
0x89C79000 C:\Windows\system32\drivers\ndis.sys 1093632 bytes (Microsoft Corporation, NDIS 6.0 wrapper driver)
0x89E02000 C:\Windows\System32\drivers\tcpip.sys 958464 bytes (Microsoft Corporation, TCP/IP Driver)
0x804D5000 C:\Windows\system32\CI.dll 917504 bytes (Microsoft Corporation, Code Integrity Module)
0xAE00F000 C:\Windows\system32\drivers\peauth.sys 909312 bytes (Microsoft Corporation, Protected Environment Authentication and Authorization Export Driver)
0xAAA07000 C:\Windows\system32\drivers\spsys.sys 720896 bytes (Microsoft Corporation, security processor)
0x8EB09000 C:\Windows\System32\drivers\dxgkrnl.sys 659456 bytes (Microsoft Corporation, DirectX Graphics Kernel)
0x89F07000 C:\Windows\system32\DRIVERS\HDAudBus.sys 577536 bytes (Microsoft Corporation, High Definition Audio Bus Driver)
0x80605000 C:\Windows\system32\drivers\Wdf01000.sys 507904 bytes (Microsoft Corporation, WDF Dynamic)
0x89C08000 C:\Windows\System32\Drivers\ksecdd.sys 462848 bytes (Microsoft Corporation, Kernel Security Support Provider Interface)
0x8040B000 C:\Windows\system32\mcupdate_GenuineIntel.dll 458752 bytes (Microsoft Corporation, Intel Microcode Update Library)
0xAAAB7000 C:\Windows\system32\drivers\HTTP.sys 446464 bytes (Microsoft Corporation, HTTP Protocol Stack)
0x8EE04000 C:\Windows\system32\drivers\ale_nf.sys 397312 bytes (Norman ASA, Norman ALE Network Filter Driver)
0x8F39E000 C:\Windows\System32\DRIVERS\srv.sys 319488 bytes (Microsoft Corporation, Server driver)
0x8E154000 C:\Windows\system32\DRIVERS\yk60x86.sys 315392 bytes (Marvell, Miniport Driver for Marvell Yukon Ethernet Controller.)
0x80737000 C:\Windows\System32\drivers\volmgrx.sys 303104 bytes (Microsoft Corporation, Volume Manager Extension Driver)
0x8EF16000 C:\Windows\system32\drivers\afd.sys 294912 bytes (Microsoft Corporation, Ancillary Function Driver for WinSock)
0x8068E000 C:\Windows\system32\drivers\acpi.sys 286720 bytes (Microsoft Corporation, ACPI Driver for NT)
0x80494000 C:\Windows\system32\CLFS.SYS 266240 bytes (Microsoft Corporation, Common Log File System Driver)
0x8EC02000 C:\Windows\system32\DRIVERS\storport.sys 266240 bytes (Microsoft Corporation, Microsoft Storage Port Driver)
0x8ED6F000 C:\Windows\system32\drivers\HdAudio.sys 258048 bytes (Microsoft Corporation, High Definition Audio Function Driver)
0x8EBC1000 C:\Windows\system32\DRIVERS\USBPORT.SYS 253952 bytes (Microsoft Corporation, USB 1.1 & 2.0 Port Driver)
0x8F209000 C:\Windows\system32\DRIVERS\rdbss.sys 245760 bytes (Microsoft Corporation, Redirected Drive Buffering SubSystem Driver)
0x89DAF000 C:\Windows\system32\drivers\NETIO.SYS 241664 bytes (Microsoft Corporation, Network I/O Subsystem)
0xAABAF000 C:\Windows\system32\DRIVERS\mrxsmb10.sys 233472 bytes (Microsoft Corporation, Longhorn SMB Downlevel SubRdr)
0x8A118000 C:\Windows\system32\drivers\volsnap.sys 233472 bytes (Microsoft Corporation, Volume Shadow Copy Driver)
0x8ED1E000 C:\Windows\system32\DRIVERS\usbhub.sys 217088 bytes (Microsoft Corporation, Default Hub Driver for USB)
0x81E04000 ACPI_HAL 208896 bytes
0x81E04000 C:\Windows\system32\hal.dll 208896 bytes (Microsoft Corporation, Hardware Abstraction Layer DLL)
0x805B5000 C:\Windows\system32\drivers\fltmgr.sys 204800 bytes (Microsoft Corporation, Microsoft Filesystem Filter Manager)
0x8EF5E000 C:\Windows\System32\DRIVERS\netbt.sys 204800 bytes (Microsoft Corporation, MBT Transport driver)
0x89FA3000 C:\Windows\system32\DRIVERS\msiscsi.sys 192512 bytes (Microsoft Corporation, Microsoft iSCSI Initiator Driver)
0x8EDAE000 C:\Windows\system32\drivers\portcls.sys 184320 bytes (Microsoft Corporation, Port Class (Class Driver for Port/Miniport Devices))
0x89D84000 C:\Windows\system32\drivers\msrpc.sys 176128 bytes (Microsoft Corporation, Kernel Remote Procedure Call Provider)
0x8ECDD000 C:\Windows\system32\DRIVERS\ks.sys 172032 bytes (Microsoft Corporation, Kernel CSA Library)
0x8F330000 C:\Windows\system32\DRIVERS\nwifi.sys 172032 bytes (Microsoft Corporation, NativeWiFi Miniport Driver)
0x8F2DB000 C:\Windows\System32\Drivers\fastfat.SYS 163840 bytes (Microsoft Corporation, Fast FAT File System Driver)
0x8A168000 C:\Windows\System32\drivers\ecache.sys 159744 bytes (Microsoft Corporation, Special Memory Device Cache)
0xAE156000 C:\Windows\system32\DRIVERS\nvcv32mf.sys 159744 bytes (Norman ASA, NVC MiniFilter)
0x806E5000 C:\Windows\system32\drivers\pci.sys 159744 bytes (Microsoft Corporation, NT Plug and Play PCI Enumerator)
0x8F377000 C:\Windows\System32\DRIVERS\srv2.sys 159744 bytes (Microsoft Corporation, Smb 2.0 Server driver)
0x8EDDB000 C:\Windows\system32\drivers\drmk.sys 151552 bytes (Microsoft Corporation, Microsoft Kernel DRM Descrambler Filter)
0x8EC70000 C:\Windows\system32\DRIVERS\ndiswan.sys 143360 bytes (Microsoft Corporation, MS PPP Framing Driver (Strong Encryption))
0x8A1A0000 C:\Windows\system32\drivers\CLASSPNP.SYS 135168 bytes (Microsoft Corporation, SCSI Class System Dll)
0xAAB6F000 C:\Windows\system32\drivers\mrxdav.sys 135168 bytes (Microsoft Corporation, Windows NT WebDav Minirdr)
0x8EE99000 C:\Windows\System32\drivers\VIDEOPRT.SYS 135168 bytes (Microsoft Corporation, Video Port Driver)
0xAAB90000 C:\Windows\system32\DRIVERS\mrxsmb.sys 126976 bytes (Microsoft Corporation, Windows NT SMB Minirdr)
0x80799000 C:\Windows\system32\drivers\ataport.SYS 122880 bytes (Microsoft Corporation, ATAPI Driver Extension)
0xAAB24000 C:\Windows\System32\DRIVERS\srvnet.sys 118784 bytes (Microsoft Corporation, Server Network driver)
0x89EEC000 C:\Windows\System32\drivers\fwpkclnt.sys 110592 bytes (Microsoft Corporation, FWP/IPsec Kernel-Mode API)
0x8F2BD000 C:\Windows\system32\drivers\luafv.sys 110592 bytes (Microsoft Corporation, LUA File Virtualization Filter Driver)
0xAAB41000 C:\Windows\system32\DRIVERS\bowser.sys 102400 bytes (Microsoft Corporation, NT Lan Manager Datagram Receiver Driver)
0x8E1CA000 C:\Windows\system32\DRIVERS\cdrom.sys 98304 bytes (Microsoft Corporation, SCSI CD-ROM Driver)
0xAABE8000 C:\Windows\system32\DRIVERS\mrxsmb20.sys 98304 bytes (Microsoft Corporation, Longhorn SMB 2.0 Redirector)
0x8F254000 C:\Windows\System32\Drivers\dfsc.sys 94208 bytes (Microsoft Corporation, DFS Namespace Client Driver)
0x8EC4E000 C:\Windows\system32\DRIVERS\rasl2tp.sys 94208 bytes (Microsoft Corporation, RAS L2TP mini-port/call-manager driver)
0xAE110000 C:\Windows\system32\DRIVERS\cdfs.sys 90112 bytes (Microsoft Corporation, CD-ROM File System Driver)
0x8EF90000 C:\Windows\system32\DRIVERS\pacer.sys 90112 bytes (Microsoft Corporation, QoS Packet Scheduler)
0x8EEEC000 C:\Windows\system32\DRIVERS\tdx.sys 90112 bytes (Microsoft Corporation, TDI Translation Driver)
0xAAB5A000 C:\Windows\System32\drivers\mpsdrv.sys 86016 bytes (Microsoft Corporation, Microsoft Protection Service Driver)
0x8ECB6000 C:\Windows\system32\DRIVERS\rassstp.sys 86016 bytes (Microsoft Corporation, RAS SSTP Miniport Call Manager)
0x8F28D000 C:\Windows\system32\DRIVERS\USBSTOR.SYS 86016 bytes (Microsoft Corporation, USB Mass Storage Class Driver)
0x8ECA2000 C:\Windows\system32\DRIVERS\raspptp.sys 81920 bytes (Microsoft Corporation, Peer-to-Peer Tunneling Protocol)
0x8EF02000 C:\Windows\system32\DRIVERS\smb.sys 81920 bytes (Microsoft Corporation, SMB Transport driver)
0x8E1A1000 C:\Windows\system32\DRIVERS\i8042prt.sys 77824 bytes (Microsoft Corporation, i8042 Port Driver)
0x8F364000 C:\Windows\system32\DRIVERS\rspndr.sys 77824 bytes (Microsoft Corporation, Link-Layer Topology Responder Driver for NDIS 6)
0x8EFB4000 C:\Windows\system32\DRIVERS\wanarp.sys 77824 bytes (Microsoft Corporation, MS Remote Access and Routing ARP Driver)
0x8A18F000 C:\Windows\system32\drivers\disk.sys 69632 bytes (Microsoft Corporation, PnP Disk Driver)
0x8ED53000 C:\Windows\System32\Drivers\NDProxy.SYS 69632 bytes (Microsoft Corporation, NDIS Proxy)
0x8EE65000 C:\Program Files\Norman\Ngs\Bin\nprosec.sys 69632 bytes (Norman ASA, Norman Process Security Driver)
0x8047B000 C:\Windows\system32\PSHED.dll 69632 bytes (Microsoft Corporation, Platform Specific Hardware Error Driver)
0x807CF000 C:\Windows\system32\drivers\fileinfo.sys 65536 bytes (Microsoft Corporation, FileInfo Filter Driver)
0x8F320000 C:\Windows\system32\DRIVERS\lltdio.sys 65536 bytes (Microsoft Corporation, Link-Layer Topology Mapper I/O Driver)
0x80781000 C:\Windows\System32\drivers\mountmgr.sys 65536 bytes (Microsoft Corporation, Mount Point Manager)
0x8ECCB000 C:\Windows\system32\DRIVERS\termdd.sys 65536 bytes (Microsoft Corporation, Terminal Server Driver)
0x89F94000 C:\Windows\system32\DRIVERS\intelppm.sys 61440 bytes (Microsoft Corporation, Processor Device Driver)
0x8F2AE000 C:\Windows\system32\DRIVERS\monitor.sys 61440 bytes (Microsoft Corporation, Monitor Driver)
0x8A159000 C:\Windows\System32\Drivers\mup.sys 61440 bytes (Microsoft Corporation, Multiple UNC Provider driver)
0x8070C000 C:\Windows\System32\drivers\partmgr.sys 61440 bytes (Microsoft Corporation, Partition Management Driver)
0x8EC93000 C:\Windows\system32\DRIVERS\raspppoe.sys 61440 bytes (Microsoft Corporation, RAS PPPoE mini-port/call-manager driver)
0x8E400000 C:\Windows\system32\DRIVERS\usbehci.sys 61440 bytes (Microsoft Corporation, EHCI eUSB Miniport Driver)
0x80728000 C:\Windows\system32\drivers\volmgr.sys 61440 bytes (Microsoft Corporation, Volume Manager Driver)
0x96E40000 C:\Windows\System32\cdd.dll 57344 bytes (Microsoft Corporation, Canonical Display Driver)
0x8EFA6000 C:\Windows\system32\DRIVERS\netbios.sys 57344 bytes (Microsoft Corporation, NetBIOS interface driver)
0x8EED5000 C:\Windows\System32\Drivers\Npfs.SYS 57344 bytes (Microsoft Corporation, NPFS Driver)
0x807C1000 C:\Windows\system32\drivers\PCIIDEX.SYS 57344 bytes (Microsoft Corporation, PCI IDE Bus Driver Extension)
0x8F26B000 C:\Windows\System32\Drivers\crashdmp.sys 53248 bytes (Microsoft Corporation, Crash Dump Driver)
0x8F3EC000 C:\Program Files\Norman\Ngs\Bin\nregsec.sys 53248 bytes (Norman ASA, Norman Registry Filter Driver)
0x8ED11000 C:\Windows\system32\DRIVERS\umbus.sys 53248 bytes (Microsoft Corporation, User-Mode Bus Enumerator)
0x80681000 C:\Windows\system32\drivers\WDFLDR.SYS 53248 bytes (Microsoft Corporation, WDFLDR)
0xAE0F7000 C:\Windows\System32\drivers\tcpipreg.sys 49152 bytes (Microsoft Corporation, TCP/IP Registry Compatibility Driver)
0x8EE8D000 C:\Windows\System32\drivers\vga.sys 49152 bytes (Microsoft Corporation, VGA/Super VGA Video Driver)
0x8EBAA000 C:\Windows\System32\drivers\watchdog.sys 49152 bytes (Microsoft Corporation, Watchdog Driver)
0x8F278000 C:\Windows\System32\Drivers\dump_dumpata.sys 45056 bytes
0x8E1BF000 C:\Windows\system32\DRIVERS\kbdclass.sys 45056 bytes (Microsoft Corporation, Keyboard Class Driver)
0x8E1B4000 C:\Windows\system32\DRIVERS\mouclass.sys 45056 bytes (Microsoft Corporation, Mouse Class Driver)
0x8EECA000 C:\Windows\System32\Drivers\Msfs.SYS 45056 bytes (Microsoft Corporation, Mailslot driver)
0x8EC65000 C:\Windows\system32\DRIVERS\ndistapi.sys 45056 bytes (Microsoft Corporation, NDIS 3.0 connection wrapper driver)
0x8EC43000 C:\Windows\system32\DRIVERS\TDI.SYS 45056 bytes (Microsoft Corporation, TDI Wrapper)
0x8A1EC000 C:\Windows\system32\DRIVERS\tunnel.sys 45056 bytes (Microsoft Corporation, Microsoft Tunnel Interface Driver)
0x8EBB6000 C:\Windows\system32\DRIVERS\usbuhci.sys 45056 bytes (Microsoft Corporation, UHCI USB Miniport Driver)
0x8071E000 C:\Windows\system32\DRIVERS\BATTC.SYS 40960 bytes (Microsoft Corporation, Battery Class Driver)
0x8F283000 C:\Windows\System32\Drivers\dump_msahci.sys 40960 bytes
0x8F2A4000 C:\Windows\System32\drivers\Dxapi.sys 40960 bytes (Microsoft Corporation, DirectX API Driver)
0x807B7000 C:\Windows\system32\drivers\msahci.sys 40960 bytes (Microsoft Corporation, MS AHCI 1.0 Standard Driver)
0x8ED07000 C:\Windows\system32\DRIVERS\mssmbios.sys 40960 bytes (Microsoft Corporation, System Management BIOS Driver)
0x8F35A000 C:\Windows\system32\DRIVERS\ndisuio.sys 40960 bytes (Microsoft Corporation, NDIS User mode I/O driver)
0x8F245000 C:\Windows\system32\drivers\nsiproxy.sys 40960 bytes (Microsoft Corporation, NSI Proxy)
0xAE0ED000 C:\Windows\System32\Drivers\secdrv.SYS 40960 bytes (Macrovision Corporation, Macrovision Europe Limited, and Macrovision Japan and Asia K.K., Macrovision SECURITY Driver)
0x8A1C1000 C:\Windows\system32\drivers\crcdisk.sys 36864 bytes (Microsoft Corporation, Disk Block Verification Filter Driver)
0x8EE76000 C:\Windows\System32\Drivers\Fs_Rec.SYS 36864 bytes (Microsoft Corporation, File System Recognizer Driver)
0xAE17D000 C:\Windows\System32\Drivers\Normandy.SYS 36864 bytes (RKU Driver)
0x8EEE3000 C:\Windows\System32\DRIVERS\rasacd.sys 36864 bytes (Microsoft Corporation, RAS Automatic Connection Driver)
0x96E20000 C:\Windows\System32\TSDDD.dll 36864 bytes (Microsoft Corporation, Framebuffer Display Driver)
0x8A1F7000 C:\Windows\system32\DRIVERS\tunmp.sys 36864 bytes (Microsoft Corporation, Microsoft Tunnel Interface Driver)
0x8E1EC000 C:\Windows\system32\DRIVERS\wmiacpi.sys 36864 bytes (Microsoft Corporation, Windows Management Interface for ACPI)
0x806D4000 C:\Windows\system32\drivers\WMILIB.SYS 36864 bytes (Microsoft Corporation, WMILIB WMI support library Dll)
0x80791000 C:\Windows\system32\drivers\atapi.sys 32768 bytes (Microsoft Corporation, ATAPI IDE Miniport Driver)
0xAE108000 C:\Windows\system32\drivers\BCM42RLY.sys 32768 bytes (Broadcom Corporation, Broadcom iLine10(tm) PCI Network Adapter Proxy Protocol Driver)
0x8048C000 C:\Windows\system32\BOOTVID.dll 32768 bytes (Microsoft Corporation, VGA Boot Driver)
0x806DD000 C:\Windows\system32\drivers\msisadrv.sys 32768 bytes (Microsoft Corporation, ISA Driver)
0x8EEBA000 C:\Windows\System32\DRIVERS\RDPCDD.sys 32768 bytes (Microsoft Corporation, RDP Miniport)
0x8EEC2000 C:\Windows\SYSTEM32\DRIVERS\RDPENCDD.SYS 32768 bytes
0x8A151000 C:\Windows\System32\Drivers\spldr.sys 32768 bytes (Microsoft Corporation, loader for security processor)
0x8EE86000 C:\Windows\System32\Drivers\Beep.SYS 28672 bytes (Microsoft Corporation, BEEP Driver)
0x80404000 C:\Windows\system32\kdcom.dll 28672 bytes (Microsoft Corporation, Kernel Debugger HW Extension DLL)
0x8EE7F000 C:\Windows\System32\Drivers\Null.SYS 28672 bytes (Microsoft Corporation, NULL Driver)
0x8E1E2000 C:\Windows\system32\DRIVERS\GEARAspiWDM.sys 24576 bytes (GEAR Software Inc., CD DVD Filter)
0xAE103000 C:\Windows\system32\Drivers\LVPr2Mon.sys 20480 bytes (-, -)
0x8F24F000 c:\program files\norman\ngs\bin\ngs.sys 20480 bytes (Norman ASA, Norman General Security Driver)
0x8E1E8000 C:\Windows\system32\DRIVERS\CmBatt.sys 16384 bytes (Microsoft Corporation, Control Method Battery Driver)
0x8071B000 C:\Windows\system32\DRIVERS\compbatt.sys 12288 bytes (Microsoft Corporation, Composite Battery Driver)
0x8F2D8000 C:\Program Files\Norman\Nse\Bin\NDISKIO.SYS 12288 bytes (Norman ASA, Low-level disk I/O driver for Windows NT)
0x8ECDB000 C:\Windows\system32\DRIVERS\swenum.sys 8192 bytes (Microsoft Corporation, Plug and Play Software Device Enumerator)
0x8F2A2000 C:\Windows\system32\DRIVERS\USBD.SYS 8192 bytes (Microsoft Corporation, Universal Serial Bus Driver)
0xAE126000 C:\Program Files\Norman\Npm\Bin\NmchInjDrv.sys 4096 bytes
==============================================
>Stealth
==============================================
0x01D80000 Hidden Image-->msvcm90.dll [ EPROCESS 0x86D5EAD0 ] PID: 2004, 270336 bytes
0x02680000 Hidden Image-->msvcm90.dll [ EPROCESS 0x87084650 ] PID: 3664, 270336 bytes
0x05AC0000 Hidden Image-->WLTRAY.EXE [ EPROCESS 0x86D5EAD0 ] PID: 2004, 4231168 bytes
0x01D60000 Hidden Image-->bcmwlrmt.dll [ EPROCESS 0x86D5EAD0 ] PID: 2004, 77824 bytes
0x02720000 Hidden Image-->bcmwlrmt.dll [ EPROCESS 0x87084650 ] PID: 3664, 77824 bytes
==============================================
magic
Regular Member
 
Posts: 28
Joined: June 8th, 2010, 5:36 pm

Re: Alureon H removal

Unread postby magic » June 27th, 2010, 6:45 pm

>Files
==============================================
!-->[Hidden] C:\Program Files\Norman\nsc\Bin\mstat7Hasj1ki.gz
!-->[Hidden] C:\Program Files\Norman\nsc\Bin\sc10.bin.full.2010.06.27.10.01.04
!-->[Hidden] C:\ProgramData\Microsoft\Search\Data\Applications\Windows\MSS0A2E9.log
!-->[Hidden] C:\Users\owner\AppData\LocalLow\Microsoft\CryptnetUrlCache\Content\D5D8E3E1D876646A16C22BC0C8C5181A_B767886F6AD62D47EE0C723FA439E17A
!-->[Hidden] C:\Users\owner\AppData\LocalLow\Microsoft\CryptnetUrlCache\Content\E2EF7F0FB7284B9ACFD4F65D02218479
!-->[Hidden] C:\Users\owner\AppData\LocalLow\Microsoft\CryptnetUrlCache\Content\F063BF7EF604434CBE00FF198F0D9B10
!-->[Hidden] C:\Users\owner\AppData\LocalLow\Microsoft\CryptnetUrlCache\MetaData\D5D8E3E1D876646A16C22BC0C8C5181A_B767886F6AD62D47EE0C723FA439E17A
!-->[Hidden] C:\Users\owner\AppData\LocalLow\Microsoft\CryptnetUrlCache\MetaData\E2EF7F0FB7284B9ACFD4F65D02218479
!-->[Hidden] C:\Users\owner\AppData\LocalLow\Microsoft\CryptnetUrlCache\MetaData\F063BF7EF604434CBE00FF198F0D9B10
!-->[Hidden] C:\Users\owner\AppData\Local\Microsoft\Internet Explorer\Recovery\Active\{1A5038A1-81D6-11DF-BDCB-0023AE07C20C}.dat
!-->[Hidden] C:\Users\owner\AppData\Local\Microsoft\Internet Explorer\Recovery\Active\{276F4A81-81D6-11DF-BDCB-0023AE07C20C}.dat
!-->[Hidden] C:\Users\owner\AppData\Local\Microsoft\Internet Explorer\Recovery\Active\{2E89D562-81D6-11DF-BDCB-0023AE07C20C}.dat
!-->[Hidden] C:\Users\owner\AppData\Local\Microsoft\Internet Explorer\Recovery\Active\{350D0A9D-81D9-11DF-BDCB-0023AE07C20C}.dat
!-->[Hidden] C:\Users\owner\AppData\Local\Microsoft\Internet Explorer\Recovery\Active\{9EFBE392-81DD-11DF-BDCB-0023AE07C20C}.dat
!-->[Hidden] C:\Users\owner\AppData\Local\Microsoft\Internet Explorer\Recovery\Active\{C24D2351-81DC-11DF-BDCB-0023AE07C20C}.dat
!-->[Hidden] C:\Users\owner\AppData\Local\Microsoft\Internet Explorer\Recovery\Active\{EC5EF051-81D3-11DF-BDCB-0023AE07C20C}.dat
!-->[Hidden] C:\Users\owner\AppData\Local\Microsoft\Internet Explorer\Recovery\Last Active\{9EFBE393-81DD-11DF-BDCB-0023AE07C20C}.dat
!-->[Hidden] C:\Users\owner\AppData\Local\Microsoft\Windows Live Contacts\{36012577-9c9c-460f-90f1-76898bb49b87}\DBStore\Backup\new\edb000D1.log
!-->[Hidden] C:\Users\owner\AppData\Local\Microsoft\Windows Live Contacts\{36012577-9c9c-460f-90f1-76898bb49b87}\DBStore\LogFiles\edb000D1.log
!-->[Hidden] C:\Users\owner\AppData\Local\Microsoft\Windows Live Contacts\{36012577-9c9c-460f-90f1-76898bb49b87}\DBStore\LogFiles\edbtmp.log
!-->[Hidden] C:\Users\owner\AppData\Local\Microsoft\Windows Live Contacts\{9d66ec3a-0b8a-4690-819a-2f0bfec847ae}\DBStore\Backup\new\edb00ACF.log
!-->[Hidden] C:\Users\owner\AppData\Local\Microsoft\Windows Live Contacts\{9d66ec3a-0b8a-4690-819a-2f0bfec847ae}\DBStore\LogFiles\edb00ACF.log
!-->[Hidden] C:\Users\owner\AppData\Local\Microsoft\Windows Live Contacts\{9d66ec3a-0b8a-4690-819a-2f0bfec847ae}\DBStore\LogFiles\edb00AD0.log
!-->[Hidden] C:\Users\owner\AppData\Local\Microsoft\Windows Live Contacts\{9d66ec3a-0b8a-4690-819a-2f0bfec847ae}\DBStore\LogFiles\edb00AD1.log
!-->[Hidden] C:\Users\owner\AppData\Local\Microsoft\Windows Live Contacts\{9d66ec3a-0b8a-4690-819a-2f0bfec847ae}\DBStore\LogFiles\edb00AD2.log
!-->[Hidden] C:\Users\owner\AppData\Local\Microsoft\Windows Live Contacts\{9d66ec3a-0b8a-4690-819a-2f0bfec847ae}\DBStore\LogFiles\edb00AD3.log
!-->[Hidden] C:\Users\owner\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\M3JQ1JC8\10jfw8tc[1].xml
!-->[Hidden] C:\Users\owner\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\M3JQ1JC8\BurstingInteractionsPipe[1].htm
!-->[Hidden] C:\Users\owner\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\M3JQ1JC8\fcbc3555-8e63-4655-8233-2da5fefbae1c[1].swf
!-->[Hidden] C:\Users\owner\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\M3JQ1JC8\y1mx_xevY8C3c-UwAPFpOAQ3hHF5XqOOlWJDh_paW6sVoj-gLgy_pV_iNtboaQX8eloiGnh8rmJzl7KeDS9p95Y2Q[1].jpg
!-->[Hidden] C:\Users\owner\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\OZIUL0LI\3114572_6e1058d9-c90b-4526-8ea0-45e56633dba0[1].js
!-->[Hidden] C:\Users\owner\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\OZIUL0LI\8yhim1ep[1].ico
!-->[Hidden] C:\Users\owner\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\OZIUL0LI\y1mWkylkf7yTF1CEFvWfoXjVjXH6rGjFEXMp4lXfZohi_V52GhrK796HsZDwSGTAw3AnAhV-q6dpj-ufIyWh_XoyA[1].jpg
!-->[Hidden] C:\Users\owner\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\VDU5F004\265[1].swf
!-->[Hidden] C:\Users\owner\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\VDU5F004\65a09613-1384-4fef-bc06-8efd49904f00[1].swf
!-->[Hidden] C:\Users\owner\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\VDU5F004\favicon[7].ico
!-->[Hidden] C:\Users\owner\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\VDU5F004\favicon[8].ico
!-->[Hidden] C:\Users\owner\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\YHCEISX7\10jfw8tc[1].xml
!-->[Hidden] C:\Users\owner\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\YHCEISX7\8yhim1ep[1].ico
!-->[Hidden] C:\Users\owner\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\YHCEISX7\ADSAdClient31[2].txt
!-->[Hidden] C:\Users\owner\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\YHCEISX7\adServer[2].htm
!-->[Hidden] C:\Users\owner\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\YHCEISX7\favicon[7].ico
!-->[Hidden] C:\Users\owner\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\YHCEISX7\whatsnewservice[1].asmx
!-->[Hidden] C:\Users\owner\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\YHCEISX7\y1mxpVb9P9ApmmjREsAkL84x771i1XAiWraWkdJ8W6PUY9zMAu8mhRjVbZOoOqfYHlmGS7Kix0O36xPVX4cpEQYgw[1].jpg
!-->[Hidden] C:\Users\owner\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\074D6C24\10[1].htm
!-->[Hidden] C:\Users\owner\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\074D6C24\15655064[1].jpg
!-->[Hidden] C:\Users\owner\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\074D6C24\15655171[1].jpg
!-->[Hidden] C:\Users\owner\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\074D6C24\15oa2pzl[1].js
!-->[Hidden] C:\Users\owner\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\074D6C24\16vt4yge[1].png
!-->[Hidden] C:\Users\owner\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\074D6C24\1icttijq[1].jpg
!-->[Hidden] C:\Users\owner\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\074D6C24\23245_1584657662_1856_q[1].jpg
!-->[Hidden] C:\Users\owner\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\074D6C24\27403_507752644_1659_q[1].jpg
!-->[Hidden] C:\Users\owner\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\074D6C24\3oviy0dc[1].png
!-->[Hidden] C:\Users\owner\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\074D6C24\41441_504358961_2490_q[1].jpg
!-->[Hidden] C:\Users\owner\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\074D6C24\460132[1].htm
!-->[Hidden] C:\Users\owner\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\074D6C24\66ad7upf[1].png
!-->[Hidden] C:\Users\owner\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\074D6C24\728x90_8_2_Adtech[1].swf
!-->[Hidden] C:\Users\owner\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\074D6C24\7am1obcj[1].png
!-->[Hidden] C:\Users\owner\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\074D6C24\82nxex22[1].png
!-->[Hidden] C:\Users\owner\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\074D6C24\9pbc63ze[1].png
!-->[Hidden] C:\Users\owner\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\074D6C24\a3w6JPoLJckJ[1].jpg
!-->[Hidden] C:\Users\owner\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\074D6C24\addyn_3[1].0%7C500%7C1001178%7C0%7C1%7CADTECH;cookie=info;loc=100;target=_blank;key=key1+key2+key3+;grp=478;misc=1277633344212
!-->[Hidden] C:\Users\owner\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\074D6C24\ads[1]
!-->[Hidden] C:\Users\owner\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\074D6C24\adTag[1].htm
!-->[Hidden] C:\Users\owner\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\074D6C24\ak6z838s[1].css
!-->[Hidden] C:\Users\owner\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\074D6C24\app_2_2318966938_7677[1].gif
!-->[Hidden] C:\Users\owner\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\074D6C24\app_full_proxy[1].gif
!-->[Hidden] C:\Users\owner\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\074D6C24\bak_primarynav[1].gif
!-->[Hidden] C:\Users\owner\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\074D6C24\bntfbbsz[1].js
!-->[Hidden] C:\Users\owner\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\074D6C24\connect_sprite[1].png
!-->[Hidden] C:\Users\owner\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\074D6C24\controller[1].htm
!-->[Hidden] C:\Users\owner\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\074D6C24\eAF7sqpgb-jyGdIAFrMEaw__[1].txt
!-->[Hidden] C:\Users\owner\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\074D6C24\eAF7sqpgb-jyGdIAFrMEaw__[2].txt
!-->[Hidden] C:\Users\owner\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\074D6C24\england-deutschland-5-1[1].jpg
!-->[Hidden] C:\Users\owner\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\074D6C24\fade[1].js
!-->[Hidden] C:\Users\owner\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\074D6C24\getdata[1].xgi
!-->[Hidden] C:\Users\owner\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\074D6C24\goog_imp[1].gif
!-->[Hidden] C:\Users\owner\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\074D6C24\header-tab1[1].png
!-->[Hidden] C:\Users\owner\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\074D6C24\index[1].htm
!-->[Hidden] C:\Users\owner\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\074D6C24\navBar[1].js
!-->[Hidden] C:\Users\owner\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\074D6C24\pluckBlogArchive[1].js
!-->[Hidden] C:\Users\owner\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\074D6C24\pluckRecommend[1].js
!-->[Hidden] C:\Users\owner\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\074D6C24\portal_globalnav[1].css
!-->[Hidden] C:\Users\owner\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\074D6C24\p_520442251=0[1].txt
!-->[Hidden] C:\Users\owner\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\074D6C24\q1398930547_627[1].jpg
!-->[Hidden] C:\Users\owner\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\074D6C24\q6006248039_5785[1].jpg
!-->[Hidden] C:\Users\owner\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\074D6C24\redirectiframe[1].html
!-->[Hidden] C:\Users\owner\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\074D6C24\saje[1].js
!-->[Hidden] C:\Users\owner\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\074D6C24\script[1]
!-->[Hidden] C:\Users\owner\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\074D6C24\search1[1].png
!-->[Hidden] C:\Users\owner\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\074D6C24\searchCA8JMXFP
!-->[Hidden] C:\Users\owner\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\074D6C24\search[10]
!-->[Hidden] C:\Users\owner\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\074D6C24\search[11]
!-->[Hidden] C:\Users\owner\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\074D6C24\search[1].php
!-->[Hidden] C:\Users\owner\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\074D6C24\search[2].htm
!-->[Hidden] C:\Users\owner\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\074D6C24\search[3].htm
!-->[Hidden] C:\Users\owner\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\074D6C24\search[7]
!-->[Hidden] C:\Users\owner\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\074D6C24\search[8]
!-->[Hidden] C:\Users\owner\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\074D6C24\search[9]
!-->[Hidden] C:\Users\owner\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\074D6C24\skynewsBlogComments[1].js
!-->[Hidden] C:\Users\owner\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\074D6C24\slides[1].js
!-->[Hidden] C:\Users\owner\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\074D6C24\styles[2].css
!-->[Hidden] C:\Users\owner\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\074D6C24\tvp-worldcup-finals[1].png
!-->[Hidden] C:\Users\owner\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\074D6C24\WP_ECMC_DEBIT[1].gif
!-->[Hidden] C:\Users\owner\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\074D6C24\WP_MAESTRO[1].gif
!-->[Hidden] C:\Users\owner\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\074D6C24\WP_SOLO_GB[1].gif
!-->[Hidden] C:\Users\owner\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\074D6C24\WP_VISA_DELTA[1].gif
!-->[Hidden] C:\Users\owner\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\074D6C24\yahoo-min[1].js
!-->[Hidden] C:\Users\owner\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\34TPP7LV\15264[1].jpg
!-->[Hidden] C:\Users\owner\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\34TPP7LV\15655359[1].jpg
!-->[Hidden] C:\Users\owner\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\34TPP7LV\1a8txe26[1].png
!-->[Hidden] C:\Users\owner\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\34TPP7LV\23315_61524779101_7074_q[1].jpg
!-->[Hidden] C:\Users\owner\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\34TPP7LV\27440_552895225_6540_q[1].jpg
!-->[Hidden] C:\Users\owner\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\34TPP7LV\2r8n376h[1].js
!-->[Hidden] C:\Users\owner\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\34TPP7LV\41491_1494732479_4100_q[1].jpg
!-->[Hidden] C:\Users\owner\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\34TPP7LV\41500_509676932_9629_q[1].jpg
!-->[Hidden] C:\Users\owner\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\34TPP7LV\4wrf1np6[1].gif
!-->[Hidden] C:\Users\owner\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\34TPP7LV\578804[1].htm
!-->[Hidden] C:\Users\owner\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\34TPP7LV\6003070507296_1_2326c5d1[1].jpg
!-->[Hidden] C:\Users\owner\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\34TPP7LV\75j4m1ms[1].png
!-->[Hidden] C:\Users\owner\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\34TPP7LV\75j4m1ms[2].png
!-->[Hidden] C:\Users\owner\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\34TPP7LV\7xerw0xn[1].css
!-->[Hidden] C:\Users\owner\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\34TPP7LV\95o21x7p[1].png
!-->[Hidden] C:\Users\owner\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\34TPP7LV\9nmotdb7[1].css
!-->[Hidden] C:\Users\owner\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\34TPP7LV\acM_yKhaN4QJ[1].jpg
!-->[Hidden] C:\Users\owner\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\34TPP7LV\ani_whitebg[1].gif
!-->[Hidden] C:\Users\owner\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\34TPP7LV\b672538604_327184043604_1391[1].jpg
!-->[Hidden] C:\Users\owner\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\34TPP7LV\bfap2lfs[1].css
!-->[Hidden] C:\Users\owner\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\34TPP7LV\BSI-Cert_sml[1].png
!-->[Hidden] C:\Users\owner\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\34TPP7LV\chv_14_red[1].gif
!-->[Hidden] C:\Users\owner\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\34TPP7LV\comment-tr[1].png
!-->[Hidden] C:\Users\owner\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\34TPP7LV\d0jpkx5r[1].css
!-->[Hidden] C:\Users\owner\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\34TPP7LV\e4wwvbph[1].js
!-->[Hidden] C:\Users\owner\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\34TPP7LV\Everyman%20Campaign%20Logo[1].gif
!-->[Hidden] C:\Users\owner\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\34TPP7LV\fmy2sf84[1].css
!-->[Hidden] C:\Users\owner\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\34TPP7LV\header-tab2[1].png
!-->[Hidden] C:\Users\owner\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\34TPP7LV\icr-logo[1].jpg
!-->[Hidden] C:\Users\owner\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\34TPP7LV\no-user-image[1].gif
!-->[Hidden] C:\Users\owner\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\34TPP7LV\OBU_Player_30[1].swf
!-->[Hidden] C:\Users\owner\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\34TPP7LV\pluckBlogComments[1].js
!-->[Hidden] C:\Users\owner\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\34TPP7LV\pluckUtils[1].js
!-->[Hidden] C:\Users\owner\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\34TPP7LV\PPF_Logo_sml[1].png
!-->[Hidden] C:\Users\owner\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\34TPP7LV\p_520442251=0[1].txt
!-->[Hidden] C:\Users\owner\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\34TPP7LV\q1267215275_209[1].jpg
!-->[Hidden] C:\Users\owner\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\34TPP7LV\q57860647088_4209[1].jpg
!-->[Hidden] C:\Users\owner\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\34TPP7LV\searchCA2FAWEO
!-->[Hidden] C:\Users\owner\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\34TPP7LV\searchCA4AY6MT
!-->[Hidden] C:\Users\owner\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\34TPP7LV\searchCA76YLXB
!-->[Hidden] C:\Users\owner\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\34TPP7LV\search[10]
!-->[Hidden] C:\Users\owner\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\34TPP7LV\search[11]
!-->[Hidden] C:\Users\owner\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\34TPP7LV\search[2].htm
!-->[Hidden] C:\Users\owner\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\34TPP7LV\search[8]
!-->[Hidden] C:\Users\owner\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\34TPP7LV\search[9]
!-->[Hidden] C:\Users\owner\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\34TPP7LV\side_shadow[1].png
!-->[Hidden] C:\Users\owner\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\34TPP7LV\SiteLifeCss[1].txt
!-->[Hidden] C:\Users\owner\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\34TPP7LV\SiteLifeScripts[1]
!-->[Hidden] C:\Users\owner\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\34TPP7LV\skynewsDiscovery[1].js
!-->[Hidden] C:\Users\owner\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\34TPP7LV\skynews_main[1].js
!-->[Hidden] C:\Users\owner\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\34TPP7LV\ufo[1].js
!-->[Hidden] C:\Users\owner\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\34TPP7LV\__utm[1].gif
!-->[Hidden] C:\Users\owner\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\87QBBGPK\-a_RyEIu2J0J[1].jpg
!-->[Hidden] C:\Users\owner\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\87QBBGPK\1-Sky_25MNS_300x250_v1[1].swf
!-->[Hidden] C:\Users\owner\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\87QBBGPK\15655352[1].jpg
!-->[Hidden] C:\Users\owner\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\87QBBGPK\27404_656405441_4938_q[1].jpg
!-->[Hidden] C:\Users\owner\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\87QBBGPK\32hqy22c[1].js
!-->[Hidden] C:\Users\owner\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\87QBBGPK\41oy6z76[1].js
!-->[Hidden] C:\Users\owner\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\87QBBGPK\6002653230005_1_a367e041[1].jpg
!-->[Hidden] C:\Users\owner\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\87QBBGPK\6003043680009_1_9389e92e[1].jpg
!-->[Hidden] C:\Users\owner\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\87QBBGPK\7l1chn0q[1].js
!-->[Hidden] C:\Users\owner\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\87QBBGPK\7q88hxyg[1].js
!-->[Hidden] C:\Users\owner\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\87QBBGPK\adlink_999_2028017_0_1_AdId=5237925;BnId=1;itime=633339902;key=key1+key2+key3+;nodecode=yes;link=[1]
!-->[Hidden] C:\Users\owner\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\87QBBGPK\ads[3]
!-->[Hidden] C:\Users\owner\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\87QBBGPK\ads[4]
!-->[Hidden] C:\Users\owner\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\87QBBGPK\adview[1].txt
!-->[Hidden] C:\Users\owner\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\87QBBGPK\app_2_128581025231_5622[1].gif
!-->[Hidden] C:\Users\owner\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\87QBBGPK\app_2_2378983609_306[1].gif
!-->[Hidden] C:\Users\owner\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\87QBBGPK\app_2_2603081069_4083[1].gif
!-->[Hidden] C:\Users\owner\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\87QBBGPK\arrow[1].gif
!-->[Hidden] C:\Users\owner\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\87QBBGPK\audaaxxr[1].js
!-->[Hidden] C:\Users\owner\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\87QBBGPK\block-tl[1].png
!-->[Hidden] C:\Users\owner\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\87QBBGPK\bphsa2mz[1].js
!-->[Hidden] C:\Users\owner\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\87QBBGPK\bsw5js90[1].gif
!-->[Hidden] C:\Users\owner\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\87QBBGPK\cekmkov9[1].js
!-->[Hidden] C:\Users\owner\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\87QBBGPK\chv_12_red[1].gif
!-->[Hidden] C:\Users\owner\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\87QBBGPK\cnbfiri3[1].png
!-->[Hidden] C:\Users\owner\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\87QBBGPK\comment-bl[1].png
!-->[Hidden] C:\Users\owner\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\87QBBGPK\competitions_bg[1].gif
!-->[Hidden] C:\Users\owner\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\87QBBGPK\corners_300red[1].gif
!-->[Hidden] C:\Users\owner\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\87QBBGPK\css_7c24766e3b00d28b208e32e26fd06b02[1].css
!-->[Hidden] C:\Users\owner\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\87QBBGPK\data_sync[1].htm
!-->[Hidden] C:\Users\owner\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\87QBBGPK\dvzmwduu[1].js
!-->[Hidden] C:\Users\owner\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\87QBBGPK\eAF7sqpgb-jyGdIAFrMEaw__;jsessionid=D605A01DFD9114A1141D4CFB5665C0A5[1].plukweb6
!-->[Hidden] C:\Users\owner\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\87QBBGPK\flags16x16[1].png
!-->[Hidden] C:\Users\owner\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\87QBBGPK\google_co_uk[1].htm
!-->[Hidden] C:\Users\owner\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\87QBBGPK\handheld[1].css
!-->[Hidden] C:\Users\owner\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\87QBBGPK\i1eczlma[1].js
!-->[Hidden] C:\Users\owner\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\87QBBGPK\ico_delicious[1].gif
!-->[Hidden] C:\Users\owner\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\87QBBGPK\login[1].js
!-->[Hidden] C:\Users\owner\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\87QBBGPK\more_icon[1].gif
!-->[Hidden] C:\Users\owner\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\87QBBGPK\my_jq[1].js
!-->[Hidden] C:\Users\owner\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\87QBBGPK\NewTabPageScripts[1]
!-->[Hidden] C:\Users\owner\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\87QBBGPK\OZJYHi-0LvIJ[1].jpg
!-->[Hidden] C:\Users\owner\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\87QBBGPK\pluckEditBlogPost[1].js
!-->[Hidden] C:\Users\owner\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\87QBBGPK\pluckSearch[1].js
!-->[Hidden] C:\Users\owner\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\87QBBGPK\portal_globalnav[1].js
!-->[Hidden] C:\Users\owner\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\87QBBGPK\print[2].css
!-->[Hidden] C:\Users\owner\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\87QBBGPK\p_520442251=0[1].txt
!-->[Hidden] C:\Users\owner\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\87QBBGPK\q520893480_6698[1].jpg
!-->[Hidden] C:\Users\owner\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\87QBBGPK\realtimejs[1].txt
!-->[Hidden] C:\Users\owner\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\87QBBGPK\screen[1].css
!-->[Hidden] C:\Users\owner\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\87QBBGPK\searchCA2WXE4V
!-->[Hidden] C:\Users\owner\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\87QBBGPK\searchCABVPCCG
!-->[Hidden] C:\Users\owner\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\87QBBGPK\searchCAQ0L1U5
!-->[Hidden] C:\Users\owner\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\87QBBGPK\search[10]
!-->[Hidden] C:\Users\owner\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\87QBBGPK\search[11]
!-->[Hidden] C:\Users\owner\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\87QBBGPK\search[1].htm
!-->[Hidden] C:\Users\owner\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\87QBBGPK\skynewsBookmark[1].js
!-->[Hidden] C:\Users\owner\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\87QBBGPK\skynewsRecommend[1].js
!-->[Hidden] C:\Users\owner\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\87QBBGPK\skynewsReportAbuse[1].js
!-->[Hidden] C:\Users\owner\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\87QBBGPK\spacer[1].gif
!-->[Hidden] C:\Users\owner\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\87QBBGPK\Std_LREC3a-468x60_Demand[1].html
!-->[Hidden] C:\Users\owner\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\87QBBGPK\swfobject[1].js
!-->[Hidden] C:\Users\owner\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\87QBBGPK\tags[1].js
!-->[Hidden] C:\Users\owner\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\87QBBGPK\topmenu_bg[1].gif
!-->[Hidden] C:\Users\owner\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\87QBBGPK\UndiesandOvers[1].htm
!-->[Hidden] C:\Users\owner\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\BKADBH0W\13158[1].png
!-->[Hidden] C:\Users\owner\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\BKADBH0W\23096_1026152718_6977_q[1].jpg
!-->[Hidden] C:\Users\owner\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\BKADBH0W\35671_403959372443_698212443_4554179_2806381_s[1].jpg
!-->[Hidden] C:\Users\owner\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\BKADBH0W\3qlnzd8t[1].js
!-->[Hidden] C:\Users\owner\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\BKADBH0W\41485_1422925207_1218_n[1].jpg
!-->[Hidden] C:\Users\owner\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\BKADBH0W\4lna82ni[1].css
!-->[Hidden] C:\Users\owner\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\BKADBH0W\6003082212496_1_70476d1e[1].jpg
!-->[Hidden] C:\Users\owner\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\BKADBH0W\7c5lvnd6[1].js
!-->[Hidden] C:\Users\owner\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\BKADBH0W\7E9ZQ0shQhQJ[1].jpg
!-->[Hidden] C:\Users\owner\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\BKADBH0W\7gh2kwe9[1].css
!-->[Hidden] C:\Users\owner\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\BKADBH0W\8l4nfau6[1].jpg
!-->[Hidden] C:\Users\owner\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\BKADBH0W\9l8r1ebi[1].png
!-->[Hidden] C:\Users\owner\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\BKADBH0W\9ok794ru[1].js
!-->[Hidden] C:\Users\owner\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\BKADBH0W\;ord=1253863100[1].htm
!-->[Hidden] C:\Users\owner\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\BKADBH0W\adcount_2[1].0%7C999%7C2028017%7C0%7C1%7CAdId=5237925;BnId=1;ct=828549709;st=393;adcid=1;itime=633339902;reqtype=5
!-->[Hidden] C:\Users\owner\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\BKADBH0W\ads[1]
!-->[Hidden] C:\Users\owner\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\BKADBH0W\ads[1].htm
!-->[Hidden] C:\Users\owner\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\BKADBH0W\ads[2]
!-->[Hidden] C:\Users\owner\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\BKADBH0W\ads[2].htm
!-->[Hidden] C:\Users\owner\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\BKADBH0W\ads[3]
!-->[Hidden] C:\Users\owner\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\BKADBH0W\app_2_167746316127_7873[1].gif
!-->[Hidden] C:\Users\owner\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\BKADBH0W\b8ntgiaw[1].css
!-->[Hidden] C:\Users\owner\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\BKADBH0W\bottom_shadow[1].png
!-->[Hidden] C:\Users\owner\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\BKADBH0W\bq-2[1].png
!-->[Hidden] C:\Users\owner\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\BKADBH0W\bqmhyox3[1].jpg
!-->[Hidden] C:\Users\owner\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\BKADBH0W\c8hrcja7[1].png
!-->[Hidden] C:\Users\owner\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\BKADBH0W\chv_13_red[1].gif
!-->[Hidden] C:\Users\owner\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\BKADBH0W\ck2tv556[1].png
!-->[Hidden] C:\Users\owner\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\BKADBH0W\comments[1].gif
!-->[Hidden] C:\Users\owner\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\BKADBH0W\controller[1].swf
!-->[Hidden] C:\Users\owner\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\BKADBH0W\css_ce84c4a203f9581727de3c8acecbdd4f[1].css
!-->[Hidden] C:\Users\owner\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\BKADBH0W\donation[1].png
!-->[Hidden] C:\Users\owner\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\BKADBH0W\en6wnfcw[1].css
!-->[Hidden] C:\Users\owner\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\BKADBH0W\file_news[1].js
!-->[Hidden] C:\Users\owner\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\BKADBH0W\flyout_bg[1].jpg
!-->[Hidden] C:\Users\owner\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\BKADBH0W\footer[1].png
!-->[Hidden] C:\Users\owner\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\BKADBH0W\globalnav[1].js
!-->[Hidden] C:\Users\owner\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\BKADBH0W\google_ads[1].js
!-->[Hidden] C:\Users\owner\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\BKADBH0W\google_co_uk[1].txt
!-->[Hidden] C:\Users\owner\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\BKADBH0W\google_service[1].js
!-->[Hidden] C:\Users\owner\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\BKADBH0W\header[1].png
!-->[Hidden] C:\Users\owner\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\BKADBH0W\header_bg[1].gif
!-->[Hidden] C:\Users\owner\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\BKADBH0W\ico_digg[1].gif
!-->[Hidden] C:\Users\owner\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\BKADBH0W\ico_reddit[1].gif
!-->[Hidden] C:\Users\owner\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\BKADBH0W\js_b0f4a4d77baac5b6ea14727108f1e722[1].js
!-->[Hidden] C:\Users\owner\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\BKADBH0W\j[1].ad
!-->[Hidden] C:\Users\owner\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\BKADBH0W\pluckDiscovery[1].js
!-->[Hidden] C:\Users\owner\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\BKADBH0W\pork.iframe[1].js
!-->[Hidden] C:\Users\owner\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\BKADBH0W\q100000583882914_5516[1].jpg
!-->[Hidden] C:\Users\owner\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\BKADBH0W\safe_image[1].jpg
!-->[Hidden] C:\Users\owner\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\BKADBH0W\scripts[1].js
!-->[Hidden] C:\Users\owner\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\BKADBH0W\searchCAB48SBO
!-->[Hidden] C:\Users\owner\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\BKADBH0W\searchCADGE0ND
!-->[Hidden] C:\Users\owner\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\BKADBH0W\searchCATF91HT
!-->[Hidden] C:\Users\owner\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\BKADBH0W\search[10]
!-->[Hidden] C:\Users\owner\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\BKADBH0W\search[11]
!-->[Hidden] C:\Users\owner\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\BKADBH0W\search[1].htm
!-->[Hidden] C:\Users\owner\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\BKADBH0W\search[2].htm
!-->[Hidden] C:\Users\owner\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\BKADBH0W\search[9]
!-->[Hidden] C:\Users\owner\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\BKADBH0W\SiteLifeProxy[1]
!-->[Hidden] C:\Users\owner\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\BKADBH0W\skynewsBlogArchive[1].js
!-->[Hidden] C:\Users\owner\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\BKADBH0W\Std_LREC3a-468x60_Demand[1].swf
!-->[Hidden] C:\Users\owner\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\BKADBH0W\styles[2].css
!-->[Hidden] C:\Users\owner\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\BKADBH0W\swfobject[2].js
!-->[Hidden] C:\Users\owner\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\BKADBH0W\tabswelcome[1]
!-->[Hidden] C:\Users\owner\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\BKADBH0W\topmenu_over[1].gif
!-->[Hidden] C:\Users\owner\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\BKADBH0W\wrapper1[1].htm
!-->[Hidden] C:\Users\owner\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\BYEFNM4M\15642255[1].jpg
!-->[Hidden] C:\Users\owner\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\BYEFNM4M\15651386[1].jpg
!-->[Hidden] C:\Users\owner\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\BYEFNM4M\15651906[1].jpg
!-->[Hidden] C:\Users\owner\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\BYEFNM4M\1v8g26vu[1].png
!-->[Hidden] C:\Users\owner\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\BYEFNM4M\1wh1cvbg[1].png
!-->[Hidden] C:\Users\owner\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\BYEFNM4M\35400_403958922443_698212443_4554147_7451907_s[1].jpg
!-->[Hidden] C:\Users\owner\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\BYEFNM4M\35400_403958927443_698212443_4554148_996750_s[1].jpg
!-->[Hidden] C:\Users\owner\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\BYEFNM4M\3qd53g3o[1].png
!-->[Hidden] C:\Users\owner\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\BYEFNM4M\41j5eq4v[1].png
!-->[Hidden] C:\Users\owner\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\BYEFNM4M\45rso0c5[1].js
!-->[Hidden] C:\Users\owner\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\BYEFNM4M\5cn7kn5h[1].css
!-->[Hidden] C:\Users\owner\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\BYEFNM4M\6jwhsirz[1].gif
!-->[Hidden] C:\Users\owner\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\BYEFNM4M\ap8tq6be[1].png
!-->[Hidden] C:\Users\owner\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\BYEFNM4M\b6gxokq8[1].png
!-->[Hidden] C:\Users\owner\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\BYEFNM4M\bq-1[1].png
!-->[Hidden] C:\Users\owner\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\BYEFNM4M\breadcrumbs[1].png
!-->[Hidden] C:\Users\owner\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\BYEFNM4M\chv_14_red[1].gif
!-->[Hidden] C:\Users\owner\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\BYEFNM4M\chv_15_white[1].gif
!-->[Hidden] C:\Users\owner\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\BYEFNM4M\codefilter[1].css
!-->[Hidden] C:\Users\owner\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\BYEFNM4M\comment-br[1].png
!-->[Hidden] C:\Users\owner\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\BYEFNM4M\DirectProxy[1]
!-->[Hidden] C:\Users\owner\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\BYEFNM4M\dj0on4gq[1].css
!-->[Hidden] C:\Users\owner\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\BYEFNM4M\ed17aimv[1].js
!-->[Hidden] C:\Users\owner\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\BYEFNM4M\f0uivbqy[1].js
!-->[Hidden] C:\Users\owner\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\BYEFNM4M\FB[1].Share
!-->[Hidden] C:\Users\owner\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\BYEFNM4M\ico_stumbleupon[1].gif
!-->[Hidden] C:\Users\owner\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\BYEFNM4M\install_flash[1].gif
!-->[Hidden] C:\Users\owner\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\BYEFNM4M\jquery-1.4.2.min[1].js
!-->[Hidden] C:\Users\owner\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\BYEFNM4M\jquery-ui-1.8.custom.min[1].js
!-->[Hidden] C:\Users\owner\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\BYEFNM4M\json-min[1].js
!-->[Hidden] C:\Users\owner\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\BYEFNM4M\menu_item[1].gif
!-->[Hidden] C:\Users\owner\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\BYEFNM4M\more[1].gif
!-->[Hidden] C:\Users\owner\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\BYEFNM4M\nav[1].png
!-->[Hidden] C:\Users\owner\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\BYEFNM4M\pluckRecentPhotosCarousel[1].js
!-->[Hidden] C:\Users\owner\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\BYEFNM4M\pluckWriteBlogPost[1].js
!-->[Hidden] C:\Users\owner\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\BYEFNM4M\p_520442251=0[1].txt
!-->[Hidden] C:\Users\owner\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\BYEFNM4M\p_520442251=0[2].txt
!-->[Hidden] C:\Users\owner\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\BYEFNM4M\q111587018865427_7252[1].jpg
!-->[Hidden] C:\Users\owner\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\BYEFNM4M\q1295349728_9063[1].jpg
!-->[Hidden] C:\Users\owner\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\BYEFNM4M\q284203075_3285[1].jpg
!-->[Hidden] C:\Users\owner\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\BYEFNM4M\q520442251_8185[1].jpg
!-->[Hidden] C:\Users\owner\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\BYEFNM4M\q756253034_154[1].jpg
!-->[Hidden] C:\Users\owner\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\BYEFNM4M\requestbatch[1].js
!-->[Hidden] C:\Users\owner\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\BYEFNM4M\requesttypes[1].js
!-->[Hidden] C:\Users\owner\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\BYEFNM4M\searchCA0WI8D9
!-->[Hidden] C:\Users\owner\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\BYEFNM4M\searchCA9PCWA8
!-->[Hidden] C:\Users\owner\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\BYEFNM4M\searchCABZJBBD
!-->[Hidden] C:\Users\owner\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\BYEFNM4M\searchCACSEQ4J
!-->[Hidden] C:\Users\owner\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\BYEFNM4M\searchCAK2IB6T
!-->[Hidden] C:\Users\owner\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\BYEFNM4M\searchCAKY9SM5
!-->[Hidden] C:\Users\owner\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\BYEFNM4M\searchCANHLTCZ
!-->[Hidden] C:\Users\owner\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\BYEFNM4M\searchCAQL9KKC
!-->[Hidden] C:\Users\owner\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\BYEFNM4M\search[10]
!-->[Hidden] C:\Users\owner\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\BYEFNM4M\search[11]
!-->[Hidden] C:\Users\owner\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\BYEFNM4M\search[8]
!-->[Hidden] C:\Users\owner\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\BYEFNM4M\search[9]
!-->[Hidden] C:\Users\owner\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\BYEFNM4M\skynewsBlog[1].js
!-->[Hidden] C:\Users\owner\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\BYEFNM4M\stylesIE8[1].css
!-->[Hidden] C:\Users\owner\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\BYEFNM4M\UElOu7HQV5wJ[1].jpg
!-->[Hidden] C:\Users\owner\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\D0VKI76B\14c1yul5[1].gif
!-->[Hidden] C:\Users\owner\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\D0VKI76B\15655056[1].jpg
!-->[Hidden] C:\Users\owner\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\D0VKI76B\23247_100000849957659_5284_q[1].jpg
!-->[Hidden] C:\Users\owner\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\D0VKI76B\2se78rck[1].js
!-->[Hidden] C:\Users\owner\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\D0VKI76B\300x100_2[1].swf
!-->[Hidden] C:\Users\owner\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\D0VKI76B\41499_516862263_3084_q[1].jpg
!-->[Hidden] C:\Users\owner\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\D0VKI76B\41504_524975564_7585_q[1].jpg
!-->[Hidden] C:\Users\owner\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\D0VKI76B\53-Breaking-News-Image[1].jpg
!-->[Hidden] C:\Users\owner\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\D0VKI76B\6w95fo9x[1].gif
!-->[Hidden] C:\Users\owner\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\D0VKI76B\7xerw0xn[1].css
!-->[Hidden] C:\Users\owner\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\D0VKI76B\ads[2]
!-->[Hidden] C:\Users\owner\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\D0VKI76B\an7hd6a1[1].css
!-->[Hidden] C:\Users\owner\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\D0VKI76B\bak_animation_exclusive[1].gif
!-->[Hidden] C:\Users\owner\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\D0VKI76B\bak_searchbar[1].gif
!-->[Hidden] C:\Users\owner\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\D0VKI76B\cekmkov9[1].js
!-->[Hidden] C:\Users\owner\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\D0VKI76B\connect_li[1].jpg
!-->[Hidden] C:\Users\owner\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\D0VKI76B\corners_300[1].gif
!-->[Hidden] C:\Users\owner\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\D0VKI76B\cr1zs8ak[2].js
!-->[Hidden] C:\Users\owner\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\D0VKI76B\ct9as3cg[1].js
!-->[Hidden] C:\Users\owner\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\D0VKI76B\cuaGIYAxEBQJ[1].jpg
!-->[Hidden] C:\Users\owner\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\D0VKI76B\direct_li[1].jpg
!-->[Hidden] C:\Users\owner\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\D0VKI76B\drupal.org[1].png
!-->[Hidden] C:\Users\owner\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\D0VKI76B\dwbwnck1[1].css
!-->[Hidden] C:\Users\owner\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\D0VKI76B\England_Team_World_Cup[1].htm
!-->[Hidden] C:\Users\owner\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\D0VKI76B\en[1].htm
!-->[Hidden] C:\Users\owner\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\D0VKI76B\esc[1].js
!-->[Hidden] C:\Users\owner\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\D0VKI76B\everyman_logo[1].png
!-->[Hidden] C:\Users\owner\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\D0VKI76B\expand_nor[1]
!-->[Hidden] C:\Users\owner\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\D0VKI76B\gn-skycom[1].gif
!-->[Hidden] C:\Users\owner\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\D0VKI76B\ico_newsvine[1].gif
!-->[Hidden] C:\Users\owner\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\D0VKI76B\js_052d1c2c89e98720da997e6e6060a87e[1].js
!-->[Hidden] C:\Users\owner\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\D0VKI76B\j[1].ad
!-->[Hidden] C:\Users\owner\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\D0VKI76B\logo[1]
!-->[Hidden] C:\Users\owner\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\D0VKI76B\pluckProfile[1].js
!-->[Hidden] C:\Users\owner\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\D0VKI76B\p_520442251=0[1].txt
!-->[Hidden] C:\Users\owner\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\D0VKI76B\q544691288_3578[1].jpg
!-->[Hidden] C:\Users\owner\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\D0VKI76B\q664422372_4183[1].jpg
!-->[Hidden] C:\Users\owner\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\D0VKI76B\q683172673_538[1].jpg
!-->[Hidden] C:\Users\owner\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\D0VKI76B\safe_image[1].jpg
!-->[Hidden] C:\Users\owner\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\D0VKI76B\scrollbar[1].png
!-->[Hidden] C:\Users\owner\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\D0VKI76B\searchCA36SO5H
!-->[Hidden] C:\Users\owner\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\D0VKI76B\searchCA3EVNA3
!-->[Hidden] C:\Users\owner\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\D0VKI76B\searchCA4SIHNY
!-->[Hidden] C:\Users\owner\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\D0VKI76B\searchCACZR7QE
!-->[Hidden] C:\Users\owner\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\D0VKI76B\searchCAE2SZLL
!-->[Hidden] C:\Users\owner\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\D0VKI76B\searchCAQ827YC
!-->[Hidden] C:\Users\owner\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\D0VKI76B\searchCATVXRZX
!-->[Hidden] C:\Users\owner\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\D0VKI76B\search[10]
!-->[Hidden] C:\Users\owner\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\D0VKI76B\search[11]
!-->[Hidden] C:\Users\owner\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\D0VKI76B\search[1].php
!-->[Hidden] C:\Users\owner\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\D0VKI76B\shade[1].png
!-->[Hidden] C:\Users\owner\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\D0VKI76B\skyCommunity[1].js
!-->[Hidden] C:\Users\owner\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\D0VKI76B\skynewsModules[1].js
!-->[Hidden] C:\Users\owner\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\D0VKI76B\skynewsSearch[1].js
!-->[Hidden] C:\Users\owner\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\D0VKI76B\skynews_template_mini[1].css
!-->[Hidden] C:\Users\owner\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\D0VKI76B\Sky_SiteLife[1].css
!-->[Hidden] C:\Users\owner\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\D0VKI76B\spumzqpo[1].css
!-->[Hidden] C:\Users\owner\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\D0VKI76B\urchin[1].js
!-->[Hidden] C:\Users\owner\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\D0VKI76B\__utm[1].js
!-->[Hidden] C:\Users\owner\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\WTJF1JXX\15654959[1].jpg
!-->[Hidden] C:\Users\owner\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\WTJF1JXX\15655404[1].jpg
!-->[Hidden] C:\Users\owner\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\WTJF1JXX\201006415655340[1].htm
!-->[Hidden] C:\Users\owner\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\WTJF1JXX\27393_509504975_317_q[1].jpg
!-->[Hidden] C:\Users\owner\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\WTJF1JXX\27445_741125960_4012_q[1].jpg
!-->[Hidden] C:\Users\owner\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\WTJF1JXX\27460_611837223_3684_q[1].jpg
!-->[Hidden] C:\Users\owner\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\WTJF1JXX\33fhmsfs[1].png
!-->[Hidden] C:\Users\owner\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\WTJF1JXX\3wn9nsg9[1].png
!-->[Hidden] C:\Users\owner\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\WTJF1JXX\6vstpzir[1].css
!-->[Hidden] C:\Users\owner\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\WTJF1JXX\7hwy7at6[1].png
!-->[Hidden] C:\Users\owner\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\WTJF1JXX\88ghwty2[1].css
!-->[Hidden] C:\Users\owner\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\WTJF1JXX\8ko5kw32[1].js
!-->[Hidden] C:\Users\owner\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\WTJF1JXX\8q2anwu7[1].gif
!-->[Hidden] C:\Users\owner\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\WTJF1JXX\8q2anwu7[2].gif
!-->[Hidden] C:\Users\owner\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\WTJF1JXX\a0c6t4d4[1].png
!-->[Hidden] C:\Users\owner\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\WTJF1JXX\bak_animation_breaking[1].gif
!-->[Hidden] C:\Users\owner\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\WTJF1JXX\bl6oqosx[1].css
!-->[Hidden] C:\Users\owner\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\WTJF1JXX\block-bl[1].png
!-->[Hidden] C:\Users\owner\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\WTJF1JXX\btn_forward[1].gif
!-->[Hidden] C:\Users\owner\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\WTJF1JXX\btn_submit[1].gif
!-->[Hidden] C:\Users\owner\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\WTJF1JXX\byqp3nn5[1].gif
!-->[Hidden] C:\Users\owner\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\WTJF1JXX\cl3tql6g[1].png
!-->[Hidden] C:\Users\owner\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\WTJF1JXX\close_nor[1]
!-->[Hidden] C:\Users\owner\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\WTJF1JXX\cny9pytx[1].png
!-->[Hidden] C:\Users\owner\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\WTJF1JXX\comment-tl[1].png
!-->[Hidden] C:\Users\owner\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\WTJF1JXX\connect[1].jpg
!-->[Hidden] C:\Users\owner\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\WTJF1JXX\eAF7sqpgb-jyGdIAFrMEaw__;jsessionid=D605A01DFD9114A1141D4CFB5665C0A5[1].plukweb6
!-->[Hidden] C:\Users\owner\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\WTJF1JXX\enyi8d10[1].gif
!-->[Hidden] C:\Users\owner\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\WTJF1JXX\FacebookProxy[1]
!-->[Hidden] C:\Users\owner\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\WTJF1JXX\first_degree[1].php
!-->[Hidden] C:\Users\owner\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\WTJF1JXX\footer-back[1].png
!-->[Hidden] C:\Users\owner\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\WTJF1JXX\gn-skycom[1].gif
!-->[Hidden] C:\Users\owner\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\WTJF1JXX\hbx[1].js
!-->[Hidden] C:\Users\owner\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\WTJF1JXX\header-bg[1].gif
!-->[Hidden] C:\Users\owner\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\WTJF1JXX\HUELEe-zz7QJ[1].jpg
!-->[Hidden] C:\Users\owner\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\WTJF1JXX\logistics[1].jpg
!-->[Hidden] C:\Users\owner\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\WTJF1JXX\mf_lightbox[1].js
!-->[Hidden] C:\Users\owner\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\WTJF1JXX\poweredByRBSWorldPay[1].gif
!-->[Hidden] C:\Users\owner\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\WTJF1JXX\p_520442251=0[1].txt
!-->[Hidden] C:\Users\owner\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\WTJF1JXX\p_520442251=0[2].txt
!-->[Hidden] C:\Users\owner\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\WTJF1JXX\revenueScience[1].js
!-->[Hidden] C:\Users\owner\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\WTJF1JXX\searchCA0K23KI
!-->[Hidden] C:\Users\owner\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\WTJF1JXX\searchCAH8WFEU
!-->[Hidden] C:\Users\owner\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\WTJF1JXX\searchCAMDK5KR
!-->[Hidden] C:\Users\owner\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\WTJF1JXX\search[10]
!-->[Hidden] C:\Users\owner\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\WTJF1JXX\search[11]
!-->[Hidden] C:\Users\owner\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\WTJF1JXX\search[5]
!-->[Hidden] C:\Users\owner\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\WTJF1JXX\search[6]
!-->[Hidden] C:\Users\owner\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\WTJF1JXX\search[7]
!-->[Hidden] C:\Users\owner\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\WTJF1JXX\search[8]
!-->[Hidden] C:\Users\owner\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\WTJF1JXX\search[9]
!-->[Hidden] C:\Users\owner\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\WTJF1JXX\sitelife_overrides[1].css
!-->[Hidden] C:\Users\owner\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\WTJF1JXX\skynews_indepth_mini[1].css
!-->[Hidden] C:\Users\owner\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\WTJF1JXX\skynews_js_mini[1].css
!-->[Hidden] C:\Users\owner\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\WTJF1JXX\ticker[1].js
!-->[Hidden] C:\Users\owner\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\WTJF1JXX\WP_VISA[1].gif
!-->[Hidden] C:\Users\owner\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\WTJF1JXX\WP_VISA_ELECTRON[2].gif
!-->[Hidden] C:\Users\owner\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\ZN6FK37X\1fjg6c8h[1].png
!-->[Hidden] C:\Users\owner\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\ZN6FK37X\27384_100001058006127_83_q[1].jpg
!-->[Hidden] C:\Users\owner\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\ZN6FK37X\27405_698212443_4181_q[1].jpg
!-->[Hidden] C:\Users\owner\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\ZN6FK37X\27442_1382504805_9100_q[1].jpg
!-->[Hidden] C:\Users\owner\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\ZN6FK37X\41405_1422925207_7765_q[1].jpg
!-->[Hidden] C:\Users\owner\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\ZN6FK37X\41405_1422925207_7765_s[1].jpg
!-->[Hidden] C:\Users\owner\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\ZN6FK37X\41551_507614038_5762_q[1].jpg
!-->[Hidden] C:\Users\owner\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\ZN6FK37X\43cgffib[1].css
!-->[Hidden] C:\Users\owner\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\ZN6FK37X\44cl54a0[1].png
!-->[Hidden] C:\Users\owner\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\ZN6FK37X\5axk9id0[1].css
!-->[Hidden] C:\Users\owner\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\ZN6FK37X\6m1zsoz1[1].png
!-->[Hidden] C:\Users\owner\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\ZN6FK37X\6nuj81lw[1].gif
!-->[Hidden] C:\Users\owner\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\ZN6FK37X\8304jo3r[1].css
!-->[Hidden] C:\Users\owner\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\ZN6FK37X\8b860pbt[1].css
!-->[Hidden] C:\Users\owner\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\ZN6FK37X\ak6z838s[1].css
!-->[Hidden] C:\Users\owner\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\ZN6FK37X\bak_input[1].gif
!-->[Hidden] C:\Users\owner\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\ZN6FK37X\block-br[1].png
!-->[Hidden] C:\Users\owner\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\ZN6FK37X\block-tr[1].png
!-->[Hidden] C:\Users\owner\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\ZN6FK37X\button[1].htm
!-->[Hidden] C:\Users\owner\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\ZN6FK37X\CCA_Logo_sml[1].png
!-->[Hidden] C:\Users\owner\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\ZN6FK37X\cookieHandler[1].js
!-->[Hidden] C:\Users\owner\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\ZN6FK37X\direct[1].jpg
!-->[Hidden] C:\Users\owner\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\ZN6FK37X\direct_default[1].jpg
!-->[Hidden] C:\Users\owner\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\ZN6FK37X\dj0on4gq[1].css
!-->[Hidden] C:\Users\owner\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\ZN6FK37X\eget8ku0[1].css
!-->[Hidden] C:\Users\owner\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\ZN6FK37X\ES%20Music%20Boxers%20Grey%20Front[1].jpg
!-->[Hidden] C:\Users\owner\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\ZN6FK37X\header-back[1].png
!-->[Hidden] C:\Users\owner\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\ZN6FK37X\help_16[2]
!-->[Hidden] C:\Users\owner\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\ZN6FK37X\ico_facebook[1].gif
!-->[Hidden] C:\Users\owner\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\ZN6FK37X\lgo_google2[1].gif
!-->[Hidden] C:\Users\owner\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\ZN6FK37X\logistics_li[1].jpg
!-->[Hidden] C:\Users\owner\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\ZN6FK37X\pluckRecentActivity[1].js
!-->[Hidden] C:\Users\owner\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\ZN6FK37X\p_520442251=0[1].txt
!-->[Hidden] C:\Users\owner\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\ZN6FK37X\p_520442251=0[2].txt
!-->[Hidden] C:\Users\owner\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\ZN6FK37X\rss[1].png
!-->[Hidden] C:\Users\owner\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\ZN6FK37X\searchCA1N7ELU
!-->[Hidden] C:\Users\owner\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\ZN6FK37X\searchCA7AN834
!-->[Hidden] C:\Users\owner\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\ZN6FK37X\searchCAINS77I
!-->[Hidden] C:\Users\owner\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\ZN6FK37X\searchCAP382LC
!-->[Hidden] C:\Users\owner\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\ZN6FK37X\search[10]
!-->[Hidden] C:\Users\owner\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\ZN6FK37X\search[11]
!-->[Hidden] C:\Users\owner\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\ZN6FK37X\search[1].php
!-->[Hidden] C:\Users\owner\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\ZN6FK37X\search[2].htm
!-->[Hidden] C:\Users\owner\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\ZN6FK37X\search[8]
!-->[Hidden] C:\Users\owner\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\ZN6FK37X\search[9]
!-->[Hidden] C:\Users\owner\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\ZN6FK37X\share-button-css[1].txt
!-->[Hidden] C:\Users\owner\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\ZN6FK37X\skinning[1].js
!-->[Hidden] C:\Users\owner\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\ZN6FK37X\skynews_hd_logo[1].jpg
!-->[Hidden] C:\Users\owner\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\ZN6FK37X\skynews_js[1].css
!-->[Hidden] C:\Users\owner\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\ZN6FK37X\skynews_main[1].css
!-->[Hidden] C:\Users\owner\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\ZN6FK37X\skynews_print[1].css
!-->[Hidden] C:\Users\owner\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\ZN6FK37X\skynews_print_mini[1].css
!-->[Hidden] C:\Users\owner\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\ZN6FK37X\top[1]
!-->[Hidden] C:\Users\owner\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\ZN6FK37X\WP_ECMC[1].gif
!-->[Hidden] C:\Users\owner\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\ZN6FK37X\WP_JCB[1].gif
!-->[Hidden] C:\Users\owner\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\ZN6FK37X\__utm[2].gif
!-->[Hidden] C:\Users\owner\AppData\Local\temp\MessengerCache\aT8LnI8Bvh3c6iXRFCZ2Fs18iFq8=
!-->[Hidden] C:\Users\owner\AppData\Local\temp\MessengerCache\MeRtssc0jzYm2BGrSn8o04150fo=
!-->[Hidden] C:\Users\owner\AppData\Local\temp\MessengerCache\SbE2HeVkBAciqxlcEK7bTTO9YFE=
!-->[Hidden] C:\Users\owner\AppData\Local\temp\MessengerCache\SK3dDdfXlQ05n7kHDx7MJS5JPFk=
!-->[Hidden] C:\Users\owner\AppData\Local\temp\MessengerCache\X3RjhOiqQdrJQAJ0PuspagUW43o=
!-->[Hidden] C:\Users\owner\AppData\Local\temp\MessengerCache\ZMkhGIzM9U4uEhguXwrRNSTdiKM=
!-->[Hidden] C:\Users\owner\AppData\Local\temp\~DF9721.tmp::$DATA
!-->[Hidden] C:\Users\owner\AppData\Local\temp\~DF9754.tmp::$DATA
!-->[Hidden] C:\Users\owner\AppData\Local\temp\~DF97CA.tmp::$DATA
!-->[Hidden] C:\Users\owner\AppData\Local\temp\~DF97DA.tmp::$DATA
!-->[Hidden] C:\Users\owner\AppData\Local\temp\~DF982A.tmp::$DATA
!-->[Hidden] C:\Users\owner\AppData\Local\temp\~DF9862.tmp::$DATA
!-->[Hidden] C:\Users\owner\AppData\Local\temp\~DFE903.tmp::$DATA
!-->[Hidden] C:\Users\owner\AppData\Local\temp\~DFEBB1.tmp
!-->[Hidden] C:\Users\owner\AppData\Local\temp\~DFED0E.tmp::$DATA
!-->[Hidden] C:\Users\owner\AppData\Local\temp\~DFF189.tmp
!-->[Hidden] C:\Users\owner\AppData\Local\temp\~DFFB9F.tmp
!-->[Hidden] C:\Users\owner\AppData\Local\temp\~DFFBD2.tmp::$DATA
!-->[Hidden] C:\Users\owner\AppData\Local\temp\~PST3937.tmp
magic
Regular Member
 
Posts: 28
Joined: June 8th, 2010, 5:36 pm

Re: Alureon H removal

Unread postby magic » June 27th, 2010, 6:45 pm

!-->[Hidden] C:\Users\owner\AppData\Local\VirtualStore\Windows\SoftwareDistribution\DataStore\Logs\edb005AB.log
!-->[Hidden] C:\Users\owner\AppData\Local\VirtualStore\Windows\SoftwareDistribution\Download\f5077c3ce294d17e194878295fca300757ff188c
!-->[Hidden] C:\Users\owner\AppData\Local\VirtualStore\Windows\System32\Macromed\Flash\FlashInstall.log
!-->[Hidden] C:\Users\owner\AppData\Roaming\Apple Computer\Logs\asl.120001_27Jun10.log
!-->[Hidden] C:\Users\owner\AppData\Roaming\Microsoft\Windows\Cookies\Low\owner@connextra[4].txt
!-->[Hidden] C:\Users\owner\AppData\Roaming\Microsoft\Windows\Cookies\Low\owner@drupal[1].txt
!-->[Hidden] C:\Users\owner\AppData\Roaming\Microsoft\Windows\Cookies\Low\owner@everyman-campaign[1].txt
!-->[Hidden] C:\Users\owner\AppData\Roaming\Microsoft\Windows\Cookies\Low\owner@kgbanswers.co[1].txt
!-->[Hidden] C:\Users\owner\AppData\Roaming\Microsoft\Windows\Cookies\Low\owner@livesoccertv[1].txt
!-->[Hidden] C:\Users\owner\AppData\Roaming\Microsoft\Windows\Cookies\Low\owner@live[4].txt
!-->[Hidden] C:\Users\owner\AppData\Roaming\Microsoft\Windows\Cookies\Low\owner@prolog.uk[2].txt
!-->[Hidden] C:\Users\owner\AppData\Roaming\Microsoft\Windows\Cookies\Low\owner@undiesandovers.co[3].txt
!-->[Hidden] C:\Users\owner\AppData\Roaming\Microsoft\Windows\Cookies\owner@bs.serving-sys[1].txt
!-->[Hidden] C:\Users\owner\AppData\Roaming\Microsoft\Windows\Cookies\owner@rad.msn[1].txt
!-->[Hidden] C:\Users\owner\AppData\Roaming\Microsoft\Windows\Cookies\owner@serving-sys[3].txt
!-->[Hidden] C:\Users\owner\AppData\Roaming\Microsoft\Word\AutoRecovery save of Document1.asd
!-->[Hidden] C:\Windows.old\Users\Shumaila\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\1MJ976LQ\activity;src=576982;met=1;v=1;pid=34668450;aid=213329352;ko=0;cid=30800763;rid=30818639;rv=1;&timestamp=1238616081780;eid1=2;ecn1=0;etm1=10;[1].gifAZBG0LE
!-->[Hidden] C:\Windows.old\Users\Shumaila\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\A371D9JW\activity;src=2212472;met=1;v=1;pid=18708550;aid=212324007;ko=0;cid=30936479;rid=30954355;rv=2;&timestamp=1238835945677;eid1=2;ecn1=0;etm1=10;[1].gif9784230
!-->[Hidden] C:\Windows.old\Users\Shumaila\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\A371D9JW\activity;src=576982;met=1;v=1;pid=34668450;aid=213329352;ko=0;cid=30800763;rid=30818639;rv=1;&timestamp=1238616071765;eid1=2;ecn1=1;etm1=10;[1].giff9784230
!-->[Hidden] C:\Windows.old\Users\Shumaila\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\A371D9JW\activity;src=576982;met=1;v=1;pid=34668450;aid=213329352;ko=0;cid=30800763;rid=30818639;rv=1;&timestamp=1238616980981;eid1=2;ecn1=0;etm1=30;[1].giff9784230
!-->[Hidden] C:\Windows.old\Users\Shumaila\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\VHXFLHTJ\activity;src=2212472;met=1;v=1;pid=18708550;aid=212324007;ko=0;cid=30936479;rid=30954355;rv=2;&timestamp=1238835935677;eid1=2;ecn1=1;etm1=10;[1].gif;[1].gif
!-->[Hidden] C:\Windows\Prefetch\APPLEMOBILEDEVICEHELPER.EXE-96A367D7.pf
!-->[Hidden] C:\Windows\Prefetch\COM.APPLE.WINDOWSMAIL.CLIENT.-8B85E2DF.pf
!-->[Hidden] C:\Windows\Prefetch\DISTNOTED.EXE-BFFB20F1.pf
!-->[Hidden] C:\Windows\Prefetch\DLLHOST.EXE-7ED62AA2.pf
!-->[Hidden] C:\Windows\Prefetch\ITUNES.EXE-2A42B776.pf
!-->[Hidden] C:\Windows\Prefetch\SOFTWAREUPDATE.EXE-631B74E4.pf
!-->[Hidden] C:\Windows\Prefetch\SYNCSERVER.EXE-5B564BE1.pf
!-->[Hidden] C:\Windows\System32\config\BCD-Template
!-->[Hidden] C:\Windows\System32\config\BCD-Template.LOG
!-->[Hidden] C:\Windows\System32\config\BCD-Template.LOG1
!-->[Hidden] C:\Windows\System32\config\BCD-Template.LOG2
!-->[Hidden] C:\Windows\System32\config\COMPONENTS
!-->[Hidden] C:\Windows\System32\config\COMPONENTS.LOG
!-->[Hidden] C:\Windows\System32\config\COMPONENTS.LOG1
!-->[Hidden] C:\Windows\System32\config\COMPONENTS.LOG2
!-->[Hidden] C:\Windows\System32\config\COMPONENTS.SAV
!-->[Hidden] C:\Windows\System32\config\DEFAULT
!-->[Hidden] C:\Windows\System32\config\DEFAULT.LOG
!-->[Hidden] C:\Windows\System32\config\DEFAULT.LOG1
!-->[Hidden] C:\Windows\System32\config\DEFAULT.LOG2
!-->[Hidden] C:\Windows\System32\config\DEFAULT.SAV
!-->[Hidden] C:\Windows\System32\config\RegBack\COMPONENTS
!-->[Hidden] C:\Windows\System32\config\RegBack\COMPONENTS.LOG1
!-->[Hidden] C:\Windows\System32\config\RegBack\COMPONENTS.LOG2
!-->[Hidden] C:\Windows\System32\config\RegBack\COMPONENTS.OLD
!-->[Hidden] C:\Windows\System32\config\RegBack\DEFAULT
!-->[Hidden] C:\Windows\System32\config\RegBack\DEFAULT.LOG1
!-->[Hidden] C:\Windows\System32\config\RegBack\DEFAULT.LOG2
!-->[Hidden] C:\Windows\System32\config\RegBack\DEFAULT.OLD
!-->[Hidden] C:\Windows\System32\config\RegBack\SAM
!-->[Hidden] C:\Windows\System32\config\RegBack\SAM.LOG1
!-->[Hidden] C:\Windows\System32\config\RegBack\SAM.LOG2
!-->[Hidden] C:\Windows\System32\config\RegBack\SAM.OLD
!-->[Hidden] C:\Windows\System32\config\RegBack\SECURITY
!-->[Hidden] C:\Windows\System32\config\RegBack\SECURITY.LOG1
!-->[Hidden] C:\Windows\System32\config\RegBack\SECURITY.LOG2
!-->[Hidden] C:\Windows\System32\config\RegBack\SECURITY.OLD
!-->[Hidden] C:\Windows\System32\config\RegBack\SOFTWARE
!-->[Hidden] C:\Windows\System32\config\RegBack\SOFTWARE.LOG1
!-->[Hidden] C:\Windows\System32\config\RegBack\SOFTWARE.LOG2
!-->[Hidden] C:\Windows\System32\config\RegBack\SOFTWARE.OLD
!-->[Hidden] C:\Windows\System32\config\RegBack\SYSTEM
!-->[Hidden] C:\Windows\System32\config\RegBack\SYSTEM.LOG1
!-->[Hidden] C:\Windows\System32\config\RegBack\SYSTEM.LOG2
!-->[Hidden] C:\Windows\System32\config\RegBack\SYSTEM.OLD
!-->[Hidden] C:\Windows\System32\config\SAM
!-->[Hidden] C:\Windows\System32\config\SAM.LOG
!-->[Hidden] C:\Windows\System32\config\SAM.LOG1
!-->[Hidden] C:\Windows\System32\config\SAM.LOG2
!-->[Hidden] C:\Windows\System32\config\SECURITY
!-->[Hidden] C:\Windows\System32\config\SECURITY.LOG
!-->[Hidden] C:\Windows\System32\config\SECURITY.LOG1
!-->[Hidden] C:\Windows\System32\config\SECURITY.LOG2
!-->[Hidden] C:\Windows\System32\config\SECURITY.SAV
!-->[Hidden] C:\Windows\System32\config\SOFTWARE
!-->[Hidden] C:\Windows\System32\config\SOFTWARE.LOG
!-->[Hidden] C:\Windows\System32\config\SOFTWARE.LOG1
!-->[Hidden] C:\Windows\System32\config\SOFTWARE.LOG2
!-->[Hidden] C:\Windows\System32\config\SOFTWARE.SAV
!-->[Hidden] C:\Windows\System32\config\SYSTEM
!-->[Hidden] C:\Windows\System32\config\SYSTEM.LOG
!-->[Hidden] C:\Windows\System32\config\SYSTEM.LOG1
!-->[Hidden] C:\Windows\System32\config\SYSTEM.LOG2
!-->[Hidden] C:\Windows\System32\config\SYSTEM.SAV
!-->[Hidden] C:\Windows\System32\config\systemprofile\AppData\LocalLow\Apple Computer\QuickTime\QuickTime.qtp
!-->[Hidden] C:\Windows\System32\config\systemprofile\AppData\LocalLow\desktop.ini
!-->[Hidden] C:\Windows\System32\config\systemprofile\AppData\LocalLow\Google\GoogleEarth\dbCache1.dat
!-->[Hidden] C:\Windows\System32\config\systemprofile\AppData\LocalLow\Google\GoogleEarth\dbCache1.dat.index
!-->[Hidden] C:\Windows\System32\config\systemprofile\AppData\LocalLow\Google\GoogleEarth\dbroot_cache
!-->[Hidden] C:\Windows\System32\config\systemprofile\AppData\LocalLow\Google\GoogleEarth\icons\kh.google.com_icons_city_capital_star.png
!-->[Hidden] C:\Windows\System32\config\systemprofile\AppData\LocalLow\Google\GoogleEarth\icons\kh.google.com_icons_city_major.png
!-->[Hidden] C:\Windows\System32\config\systemprofile\AppData\LocalLow\Microsoft\CryptnetUrlCache\Content\0BDF8CA0263EB3CE11F9034D201E065C
!-->[Hidden] C:\Windows\System32\config\systemprofile\AppData\LocalLow\Microsoft\CryptnetUrlCache\Content\0EBB3788D77094423275558212CCE7B1
!-->[Hidden] C:\Windows\System32\config\systemprofile\AppData\LocalLow\Microsoft\CryptnetUrlCache\Content\130ADF60D1B7B3CF82CC6CA82D961601_6D96F7D8F687E1791E8C828983253F05
!-->[Hidden] C:\Windows\System32\config\systemprofile\AppData\LocalLow\Microsoft\CryptnetUrlCache\Content\130ADF60D1B7B3CF82CC6CA82D961601_97F09ABDFB51E9EA95893A7377496C4F
!-->[Hidden] C:\Windows\System32\config\systemprofile\AppData\LocalLow\Microsoft\CryptnetUrlCache\Content\23B523C9E7746F715D33C6527C18EB9D
!-->[Hidden] C:\Windows\System32\config\systemprofile\AppData\LocalLow\Microsoft\CryptnetUrlCache\Content\2BABD1AB8D042E75AE3EA41B6360B1CF_7592412E08BB1B1D36ED3F4EAD2999EB
!-->[Hidden] C:\Windows\System32\config\systemprofile\AppData\LocalLow\Microsoft\CryptnetUrlCache\Content\2ECFE17A9CBC0C01091A83AE422AA893_DF4020653102734F3C133B9DA89A2DD8
!-->[Hidden] C:\Windows\System32\config\systemprofile\AppData\LocalLow\Microsoft\CryptnetUrlCache\Content\30F7B429BB1DACA9B591B41E016BED66_8FA8D8AE4EE4F31AF56BBDA2D5665732
!-->[Hidden] C:\Windows\System32\config\systemprofile\AppData\LocalLow\Microsoft\CryptnetUrlCache\Content\359452749A9CA6113E5D83F762BF5D66_0D0E2D365F7070F8ECDE5D0F04C0A051
!-->[Hidden] C:\Windows\System32\config\systemprofile\AppData\LocalLow\Microsoft\CryptnetUrlCache\Content\359452749A9CA6113E5D83F762BF5D66_2149E902275E23C42A81C3E19F1DC379
!-->[Hidden] C:\Windows\System32\config\systemprofile\AppData\LocalLow\Microsoft\CryptnetUrlCache\Content\359452749A9CA6113E5D83F762BF5D66_4A5641862FBC8AE8C5A78E002563A664
!-->[Hidden] C:\Windows\System32\config\systemprofile\AppData\LocalLow\Microsoft\CryptnetUrlCache\Content\359452749A9CA6113E5D83F762BF5D66_6D2C75B1D85804948686F666187E1411
!-->[Hidden] C:\Windows\System32\config\systemprofile\AppData\LocalLow\Microsoft\CryptnetUrlCache\Content\455E3D3E6F9CF3D849ECFCC95F48005F_232BDE3813AE2F017E2E3E3BEABE61E1
!-->[Hidden] C:\Windows\System32\config\systemprofile\AppData\LocalLow\Microsoft\CryptnetUrlCache\Content\48C226A0FE7D97DE1C716B47235CB639_339FE4A15083BA9D58F96C1443F0D4C4
!-->[Hidden] C:\Windows\System32\config\systemprofile\AppData\LocalLow\Microsoft\CryptnetUrlCache\Content\48C226A0FE7D97DE1C716B47235CB639_DC3ECA18B04A2937A5690E2E2A52A013
!-->[Hidden] C:\Windows\System32\config\systemprofile\AppData\LocalLow\Microsoft\CryptnetUrlCache\Content\4DB1DABDF57ED9997FE8DCC77E93C04F
!-->[Hidden] C:\Windows\System32\config\systemprofile\AppData\LocalLow\Microsoft\CryptnetUrlCache\Content\5495C2E4531B22B3185CE59F8E73C447
!-->[Hidden] C:\Windows\System32\config\systemprofile\AppData\LocalLow\Microsoft\CryptnetUrlCache\Content\5553AF14BD4C3B1DE599145FD14950E0
!-->[Hidden] C:\Windows\System32\config\systemprofile\AppData\LocalLow\Microsoft\CryptnetUrlCache\Content\60E31627FDA0A46932B0E5948949F2A5
!-->[Hidden] C:\Windows\System32\config\systemprofile\AppData\LocalLow\Microsoft\CryptnetUrlCache\Content\696F3DE637E6DE85B458996D49D759AD
!-->[Hidden] C:\Windows\System32\config\systemprofile\AppData\LocalLow\Microsoft\CryptnetUrlCache\Content\6AA3321A15A787985201D7A6820782F0_0AB46376AFB6F40B0426680E3025D384
!-->[Hidden] C:\Windows\System32\config\systemprofile\AppData\LocalLow\Microsoft\CryptnetUrlCache\Content\6AA3321A15A787985201D7A6820782F0_35BFA9D40D21E81B408449EB9D85CCA4
!-->[Hidden] C:\Windows\System32\config\systemprofile\AppData\LocalLow\Microsoft\CryptnetUrlCache\Content\6AA3321A15A787985201D7A6820782F0_4E35DE6F4FCFB7BE2C045F6B5ED89FC8
!-->[Hidden] C:\Windows\System32\config\systemprofile\AppData\LocalLow\Microsoft\CryptnetUrlCache\Content\6C05FF55E66434DC351985A3C60541B2_305471F92FEBDAC55C5F5411833A3468
!-->[Hidden] C:\Windows\System32\config\systemprofile\AppData\LocalLow\Microsoft\CryptnetUrlCache\Content\7396AF09A6612B894897EF26E61D29A1_9F4DB2210207C55F6B7057F730978388
!-->[Hidden] C:\Windows\System32\config\systemprofile\AppData\LocalLow\Microsoft\CryptnetUrlCache\Content\783DF2F5A7C9BC04C36663632D14B993_169DE3439FD2D9FE0AE07883B5A27A1B
!-->[Hidden] C:\Windows\System32\config\systemprofile\AppData\LocalLow\Microsoft\CryptnetUrlCache\Content\7B2238AACCEDC3F1FFE8E7EB5F575EC9
!-->[Hidden] C:\Windows\System32\config\systemprofile\AppData\LocalLow\Microsoft\CryptnetUrlCache\Content\8890A77645B73478F5B1DED18ACBF795_D3DB95C0E7608ACC9AA10ACCCCEBBDF5
!-->[Hidden] C:\Windows\System32\config\systemprofile\AppData\LocalLow\Microsoft\CryptnetUrlCache\Content\8E4817082536D8AD08C5B04CE63CBC33
!-->[Hidden] C:\Windows\System32\config\systemprofile\AppData\LocalLow\Microsoft\CryptnetUrlCache\Content\8EBFACB3A66359F9514D044C86BA4794
!-->[Hidden] C:\Windows\System32\config\systemprofile\AppData\LocalLow\Microsoft\CryptnetUrlCache\Content\94308059B57B3142E455B38A6EB92015
!-->[Hidden] C:\Windows\System32\config\systemprofile\AppData\LocalLow\Microsoft\CryptnetUrlCache\Content\A44F4E7CB3133FF765C39A53AD8FCFDD
!-->[Hidden] C:\Windows\System32\config\systemprofile\AppData\LocalLow\Microsoft\CryptnetUrlCache\Content\A4C1370976EA5CBCD83ED4662793FEEA_AD0F42DDE7D33D8DBF3DA1198F56814F
!-->[Hidden] C:\Windows\System32\config\systemprofile\AppData\LocalLow\Microsoft\CryptnetUrlCache\Content\A92F33496848CFF4F115ED04BCDD933A_DDA92DE35EE3D6A058552385D706EE1D
!-->[Hidden] C:\Windows\System32\config\systemprofile\AppData\LocalLow\Microsoft\CryptnetUrlCache\Content\B8CC409ACDBF2A2FE04C56F2875B1FD6
!-->[Hidden] C:\Windows\System32\config\systemprofile\AppData\LocalLow\Microsoft\CryptnetUrlCache\Content\BBB768C456D9E2DCD3EF595C400D483D_64C05B9EB32FC3D0CE6CB126561EEBFF
!-->[Hidden] C:\Windows\System32\config\systemprofile\AppData\LocalLow\Microsoft\CryptnetUrlCache\Content\BD8A14C7C024625432CC03FE72E47EF0_58709A8AAB8BB7691D2F845F9EB8DC15
!-->[Hidden] C:\Windows\System32\config\systemprofile\AppData\LocalLow\Microsoft\CryptnetUrlCache\Content\BD8A14C7C024625432CC03FE72E47EF0_CF7E261394FD0A96B317459607B24E08
!-->[Hidden] C:\Windows\System32\config\systemprofile\AppData\LocalLow\Microsoft\CryptnetUrlCache\Content\C315A4F3B8973042495330D0C8311626_476E0C8C4FC37B1EACFCAD465716CFC7
!-->[Hidden] C:\Windows\System32\config\systemprofile\AppData\LocalLow\Microsoft\CryptnetUrlCache\Content\C315A4F3B8973042495330D0C8311626_736700F5F880615648C29AA07A10797A
!-->[Hidden] C:\Windows\System32\config\systemprofile\AppData\LocalLow\Microsoft\CryptnetUrlCache\Content\C315A4F3B8973042495330D0C8311626_FBD1AE25F7C0E07642EBB0768056E5C4
!-->[Hidden] C:\Windows\System32\config\systemprofile\AppData\LocalLow\Microsoft\CryptnetUrlCache\Content\C8E7EC0C85688F4738F3BE49B104BA67
!-->[Hidden] C:\Windows\System32\config\systemprofile\AppData\LocalLow\Microsoft\CryptnetUrlCache\Content\D0F063B6B88A2B8BFE21C3993A613447
!-->[Hidden] C:\Windows\System32\config\systemprofile\AppData\LocalLow\Microsoft\CryptnetUrlCache\Content\D5D8E3E1D876646A16C22BC0C8C5181A_041638D34D251397F5910BC02977E043
!-->[Hidden] C:\Windows\System32\config\systemprofile\AppData\LocalLow\Microsoft\CryptnetUrlCache\Content\D5D8E3E1D876646A16C22BC0C8C5181A_2B359E2B1E784287322CDE33A38D2A5F
!-->[Hidden] C:\Windows\System32\config\systemprofile\AppData\LocalLow\Microsoft\CryptnetUrlCache\Content\D5D8E3E1D876646A16C22BC0C8C5181A_71852A4BB5F64B986C4D6830A1E53F75
!-->[Hidden] C:\Windows\System32\config\systemprofile\AppData\LocalLow\Microsoft\CryptnetUrlCache\Content\D5D8E3E1D876646A16C22BC0C8C5181A_9E5E93164F89B2F6492DE90399938D8B
!-->[Hidden] C:\Windows\System32\config\systemprofile\AppData\LocalLow\Microsoft\CryptnetUrlCache\Content\D5D8E3E1D876646A16C22BC0C8C5181A_B3C6137C84A1C19353796FB295B8B10E
!-->[Hidden] C:\Windows\System32\config\systemprofile\AppData\LocalLow\Microsoft\CryptnetUrlCache\Content\D5D8E3E1D876646A16C22BC0C8C5181A_BECACC94F8F44875C5B1967956F86066
!-->[Hidden] C:\Windows\System32\config\systemprofile\AppData\LocalLow\Microsoft\CryptnetUrlCache\Content\D725F3459E2275E9EA5871B92AD896D0
!-->[Hidden] C:\Windows\System32\config\systemprofile\AppData\LocalLow\Microsoft\CryptnetUrlCache\Content\E0940B0258BD54E5E69C9FD9ABD98139_303D95CC1959286703AEB287DA4A452A
!-->[Hidden] C:\Windows\System32\config\systemprofile\AppData\LocalLow\Microsoft\CryptnetUrlCache\Content\E0940B0258BD54E5E69C9FD9ABD98139_82888DB2123EFD933C6CAA1779FB55EC
!-->[Hidden] C:\Windows\System32\config\systemprofile\AppData\LocalLow\Microsoft\CryptnetUrlCache\Content\E5062987353057B4F90E8C7A2DEAE329
!-->[Hidden] C:\Windows\System32\config\systemprofile\AppData\LocalLow\Microsoft\CryptnetUrlCache\Content\F4B372709D6C2AD766C34D274501DC76_C08D897FBCD7D5D638FCD154D1404CBE
!-->[Hidden] C:\Windows\System32\config\systemprofile\AppData\LocalLow\Microsoft\CryptnetUrlCache\Content\F4B372709D6C2AD766C34D274501DC76_EF6FFFC583656DA078406777A3DA2CD3
!-->[Hidden] C:\Windows\System32\config\systemprofile\AppData\LocalLow\Microsoft\CryptnetUrlCache\Content\FB788E090BC1F3AA2FBC9E8FB2859601
!-->[Hidden] C:\Windows\System32\config\systemprofile\AppData\LocalLow\Microsoft\CryptnetUrlCache\Content\FCEA474F228C13CD0DAD678431D0ACFC
!-->[Hidden] C:\Windows\System32\config\systemprofile\AppData\LocalLow\Microsoft\CryptnetUrlCache\MetaData\0BDF8CA0263EB3CE11F9034D201E065C
!-->[Hidden] C:\Windows\System32\config\systemprofile\AppData\LocalLow\Microsoft\CryptnetUrlCache\MetaData\0EBB3788D77094423275558212CCE7B1
!-->[Hidden] C:\Windows\System32\config\systemprofile\AppData\LocalLow\Microsoft\CryptnetUrlCache\MetaData\130ADF60D1B7B3CF82CC6CA82D961601_6D96F7D8F687E1791E8C828983253F05
!-->[Hidden] C:\Windows\System32\config\systemprofile\AppData\LocalLow\Microsoft\CryptnetUrlCache\MetaData\130ADF60D1B7B3CF82CC6CA82D961601_97F09ABDFB51E9EA95893A7377496C4F
!-->[Hidden] C:\Windows\System32\config\systemprofile\AppData\LocalLow\Microsoft\CryptnetUrlCache\MetaData\23B523C9E7746F715D33C6527C18EB9D
!-->[Hidden] C:\Windows\System32\config\systemprofile\AppData\LocalLow\Microsoft\CryptnetUrlCache\MetaData\2BABD1AB8D042E75AE3EA41B6360B1CF_7592412E08BB1B1D36ED3F4EAD2999EB
!-->[Hidden] C:\Windows\System32\config\systemprofile\AppData\LocalLow\Microsoft\CryptnetUrlCache\MetaData\2ECFE17A9CBC0C01091A83AE422AA893_DF4020653102734F3C133B9DA89A2DD8
!-->[Hidden] C:\Windows\System32\config\systemprofile\AppData\LocalLow\Microsoft\CryptnetUrlCache\MetaData\30F7B429BB1DACA9B591B41E016BED66_8FA8D8AE4EE4F31AF56BBDA2D5665732
!-->[Hidden] C:\Windows\System32\config\systemprofile\AppData\LocalLow\Microsoft\CryptnetUrlCache\MetaData\359452749A9CA6113E5D83F762BF5D66_0D0E2D365F7070F8ECDE5D0F04C0A051
!-->[Hidden] C:\Windows\System32\config\systemprofile\AppData\LocalLow\Microsoft\CryptnetUrlCache\MetaData\359452749A9CA6113E5D83F762BF5D66_2149E902275E23C42A81C3E19F1DC379
!-->[Hidden] C:\Windows\System32\config\systemprofile\AppData\LocalLow\Microsoft\CryptnetUrlCache\MetaData\359452749A9CA6113E5D83F762BF5D66_4A5641862FBC8AE8C5A78E002563A664
!-->[Hidden] C:\Windows\System32\config\systemprofile\AppData\LocalLow\Microsoft\CryptnetUrlCache\MetaData\359452749A9CA6113E5D83F762BF5D66_6D2C75B1D85804948686F666187E1411
!-->[Hidden] C:\Windows\System32\config\systemprofile\AppData\LocalLow\Microsoft\CryptnetUrlCache\MetaData\455E3D3E6F9CF3D849ECFCC95F48005F_232BDE3813AE2F017E2E3E3BEABE61E1
!-->[Hidden] C:\Windows\System32\config\systemprofile\AppData\LocalLow\Microsoft\CryptnetUrlCache\MetaData\48C226A0FE7D97DE1C716B47235CB639_339FE4A15083BA9D58F96C1443F0D4C4
!-->[Hidden] C:\Windows\System32\config\systemprofile\AppData\LocalLow\Microsoft\CryptnetUrlCache\MetaData\48C226A0FE7D97DE1C716B47235CB639_DC3ECA18B04A2937A5690E2E2A52A013
!-->[Hidden] C:\Windows\System32\config\systemprofile\AppData\LocalLow\Microsoft\CryptnetUrlCache\MetaData\4DB1DABDF57ED9997FE8DCC77E93C04F
!-->[Hidden] C:\Windows\System32\config\systemprofile\AppData\LocalLow\Microsoft\CryptnetUrlCache\MetaData\5495C2E4531B22B3185CE59F8E73C447
!-->[Hidden] C:\Windows\System32\config\systemprofile\AppData\LocalLow\Microsoft\CryptnetUrlCache\MetaData\5553AF14BD4C3B1DE599145FD14950E0
!-->[Hidden] C:\Windows\System32\config\systemprofile\AppData\LocalLow\Microsoft\CryptnetUrlCache\MetaData\60E31627FDA0A46932B0E5948949F2A5
!-->[Hidden] C:\Windows\System32\config\systemprofile\AppData\LocalLow\Microsoft\CryptnetUrlCache\MetaData\696F3DE637E6DE85B458996D49D759AD
!-->[Hidden] C:\Windows\System32\config\systemprofile\AppData\LocalLow\Microsoft\CryptnetUrlCache\MetaData\6AA3321A15A787985201D7A6820782F0_0AB46376AFB6F40B0426680E3025D384
!-->[Hidden] C:\Windows\System32\config\systemprofile\AppData\LocalLow\Microsoft\CryptnetUrlCache\MetaData\6AA3321A15A787985201D7A6820782F0_35BFA9D40D21E81B408449EB9D85CCA4
!-->[Hidden] C:\Windows\System32\config\systemprofile\AppData\LocalLow\Microsoft\CryptnetUrlCache\MetaData\6AA3321A15A787985201D7A6820782F0_4E35DE6F4FCFB7BE2C045F6B5ED89FC8
!-->[Hidden] C:\Windows\System32\config\systemprofile\AppData\LocalLow\Microsoft\CryptnetUrlCache\MetaData\6C05FF55E66434DC351985A3C60541B2_305471F92FEBDAC55C5F5411833A3468
!-->[Hidden] C:\Windows\System32\config\systemprofile\AppData\LocalLow\Microsoft\CryptnetUrlCache\MetaData\7396AF09A6612B894897EF26E61D29A1_9F4DB2210207C55F6B7057F730978388
!-->[Hidden] C:\Windows\System32\config\systemprofile\AppData\LocalLow\Microsoft\CryptnetUrlCache\MetaData\783DF2F5A7C9BC04C36663632D14B993_169DE3439FD2D9FE0AE07883B5A27A1B
!-->[Hidden] C:\Windows\System32\config\systemprofile\AppData\LocalLow\Microsoft\CryptnetUrlCache\MetaData\7B2238AACCEDC3F1FFE8E7EB5F575EC9
!-->[Hidden] C:\Windows\System32\config\systemprofile\AppData\LocalLow\Microsoft\CryptnetUrlCache\MetaData\8890A77645B73478F5B1DED18ACBF795_D3DB95C0E7608ACC9AA10ACCCCEBBDF5
!-->[Hidden] C:\Windows\System32\config\systemprofile\AppData\LocalLow\Microsoft\CryptnetUrlCache\MetaData\8E4817082536D8AD08C5B04CE63CBC33
!-->[Hidden] C:\Windows\System32\config\systemprofile\AppData\LocalLow\Microsoft\CryptnetUrlCache\MetaData\8EBFACB3A66359F9514D044C86BA4794
!-->[Hidden] C:\Windows\System32\config\systemprofile\AppData\LocalLow\Microsoft\CryptnetUrlCache\MetaData\94308059B57B3142E455B38A6EB92015
!-->[Hidden] C:\Windows\System32\config\systemprofile\AppData\LocalLow\Microsoft\CryptnetUrlCache\MetaData\A44F4E7CB3133FF765C39A53AD8FCFDD
!-->[Hidden] C:\Windows\System32\config\systemprofile\AppData\LocalLow\Microsoft\CryptnetUrlCache\MetaData\A4C1370976EA5CBCD83ED4662793FEEA_AD0F42DDE7D33D8DBF3DA1198F56814F
!-->[Hidden] C:\Windows\System32\config\systemprofile\AppData\LocalLow\Microsoft\CryptnetUrlCache\MetaData\A92F33496848CFF4F115ED04BCDD933A_DDA92DE35EE3D6A058552385D706EE1D
!-->[Hidden] C:\Windows\System32\config\systemprofile\AppData\LocalLow\Microsoft\CryptnetUrlCache\MetaData\B8CC409ACDBF2A2FE04C56F2875B1FD6
!-->[Hidden] C:\Windows\System32\config\systemprofile\AppData\LocalLow\Microsoft\CryptnetUrlCache\MetaData\BBB768C456D9E2DCD3EF595C400D483D_64C05B9EB32FC3D0CE6CB126561EEBFF
!-->[Hidden] C:\Windows\System32\config\systemprofile\AppData\LocalLow\Microsoft\CryptnetUrlCache\MetaData\BD8A14C7C024625432CC03FE72E47EF0_58709A8AAB8BB7691D2F845F9EB8DC15
!-->[Hidden] C:\Windows\System32\config\systemprofile\AppData\LocalLow\Microsoft\CryptnetUrlCache\MetaData\BD8A14C7C024625432CC03FE72E47EF0_CF7E261394FD0A96B317459607B24E08
!-->[Hidden] C:\Windows\System32\config\systemprofile\AppData\LocalLow\Microsoft\CryptnetUrlCache\MetaData\C315A4F3B8973042495330D0C8311626_476E0C8C4FC37B1EACFCAD465716CFC7
!-->[Hidden] C:\Windows\System32\config\systemprofile\AppData\LocalLow\Microsoft\CryptnetUrlCache\MetaData\C315A4F3B8973042495330D0C8311626_736700F5F880615648C29AA07A10797A
!-->[Hidden] C:\Windows\System32\config\systemprofile\AppData\LocalLow\Microsoft\CryptnetUrlCache\MetaData\C315A4F3B8973042495330D0C8311626_FBD1AE25F7C0E07642EBB0768056E5C4
!-->[Hidden] C:\Windows\System32\config\systemprofile\AppData\LocalLow\Microsoft\CryptnetUrlCache\MetaData\C8E7EC0C85688F4738F3BE49B104BA67
!-->[Hidden] C:\Windows\System32\config\systemprofile\AppData\LocalLow\Microsoft\CryptnetUrlCache\MetaData\D0F063B6B88A2B8BFE21C3993A613447
!-->[Hidden] C:\Windows\System32\config\systemprofile\AppData\LocalLow\Microsoft\CryptnetUrlCache\MetaData\D5D8E3E1D876646A16C22BC0C8C5181A_041638D34D251397F5910BC02977E043
!-->[Hidden] C:\Windows\System32\config\systemprofile\AppData\LocalLow\Microsoft\CryptnetUrlCache\MetaData\D5D8E3E1D876646A16C22BC0C8C5181A_2B359E2B1E784287322CDE33A38D2A5F
!-->[Hidden] C:\Windows\System32\config\systemprofile\AppData\LocalLow\Microsoft\CryptnetUrlCache\MetaData\D5D8E3E1D876646A16C22BC0C8C5181A_71852A4BB5F64B986C4D6830A1E53F75
!-->[Hidden] C:\Windows\System32\config\systemprofile\AppData\LocalLow\Microsoft\CryptnetUrlCache\MetaData\D5D8E3E1D876646A16C22BC0C8C5181A_9E5E93164F89B2F6492DE90399938D8B
!-->[Hidden] C:\Windows\System32\config\systemprofile\AppData\LocalLow\Microsoft\CryptnetUrlCache\MetaData\D5D8E3E1D876646A16C22BC0C8C5181A_B3C6137C84A1C19353796FB295B8B10E
!-->[Hidden] C:\Windows\System32\config\systemprofile\AppData\LocalLow\Microsoft\CryptnetUrlCache\MetaData\D5D8E3E1D876646A16C22BC0C8C5181A_BECACC94F8F44875C5B1967956F86066
!-->[Hidden] C:\Windows\System32\config\systemprofile\AppData\LocalLow\Microsoft\CryptnetUrlCache\MetaData\D725F3459E2275E9EA5871B92AD896D0
!-->[Hidden] C:\Windows\System32\config\systemprofile\AppData\LocalLow\Microsoft\CryptnetUrlCache\MetaData\E0940B0258BD54E5E69C9FD9ABD98139_303D95CC1959286703AEB287DA4A452A
!-->[Hidden] C:\Windows\System32\config\systemprofile\AppData\LocalLow\Microsoft\CryptnetUrlCache\MetaData\E0940B0258BD54E5E69C9FD9ABD98139_82888DB2123EFD933C6CAA1779FB55EC
!-->[Hidden] C:\Windows\System32\config\systemprofile\AppData\LocalLow\Microsoft\CryptnetUrlCache\MetaData\E5062987353057B4F90E8C7A2DEAE329
!-->[Hidden] C:\Windows\System32\config\systemprofile\AppData\LocalLow\Microsoft\CryptnetUrlCache\MetaData\F4B372709D6C2AD766C34D274501DC76_C08D897FBCD7D5D638FCD154D1404CBE
!-->[Hidden] C:\Windows\System32\config\systemprofile\AppData\LocalLow\Microsoft\CryptnetUrlCache\MetaData\F4B372709D6C2AD766C34D274501DC76_EF6FFFC583656DA078406777A3DA2CD3
!-->[Hidden] C:\Windows\System32\config\systemprofile\AppData\LocalLow\Microsoft\CryptnetUrlCache\MetaData\FB788E090BC1F3AA2FBC9E8FB2859601
!-->[Hidden] C:\Windows\System32\config\systemprofile\AppData\LocalLow\Microsoft\CryptnetUrlCache\MetaData\FCEA474F228C13CD0DAD678431D0ACFC
!-->[Hidden] C:\Windows\System32\config\systemprofile\AppData\Local\2w8Pf0CAB6ms
!-->[Hidden] C:\Windows\System32\config\systemprofile\AppData\Local\Adobe\Color\ACECache10.lst
!-->[Hidden] C:\Windows\System32\config\systemprofile\AppData\Local\Adobe\Color\Profiles\wscRGB.icc
!-->[Hidden] C:\Windows\System32\config\systemprofile\AppData\Local\Adobe\Color\Profiles\wsRGB.icc
!-->[Hidden] C:\Windows\System32\config\systemprofile\AppData\Local\d3d9caps.dat
!-->[Hidden] C:\Windows\System32\config\systemprofile\AppData\Local\desktop.ini
!-->[Hidden] C:\Windows\System32\config\systemprofile\AppData\Local\Downloaded Installations\{E5087118-21AB-4D58-8697-6FA06C9C930C}\GEAR driver installer for x86 and x64.msi
!-->[Hidden] C:\Windows\System32\config\systemprofile\AppData\Local\GDIPFONTCACHEV1.DAT
!-->[Hidden] C:\Windows\System32\config\systemprofile\AppData\Local\Google\Custom Buttons\toolbar.google.com_MXE8GT6B9RBHXCGLZ06L.xml
!-->[Hidden] C:\Windows\System32\config\systemprofile\AppData\Local\K5OjaYgo0v
!-->[Hidden] C:\Windows\System32\config\systemprofile\AppData\Local\Microsoft\Internet Explorer\DOMStore\G5VTZ4YB\www.videojug[1].xml
!-->[Hidden] C:\Windows\System32\config\systemprofile\AppData\Local\Microsoft\Internet Explorer\DOMStore\index.dat
!-->[Hidden] C:\Windows\System32\config\systemprofile\AppData\Local\Microsoft\Internet Explorer\MSIMGSIZ.DAT
!-->[Hidden] C:\Windows\System32\config\systemprofile\AppData\Local\Microsoft\Portable Devices\wpdlog00.sqm
!-->[Hidden] C:\Windows\System32\config\systemprofile\AppData\Local\Microsoft\Portable Devices\wpdlog01.sqm
!-->[Hidden] C:\Windows\System32\config\systemprofile\AppData\Local\Microsoft\Portable Devices\wpdlog02.sqm
!-->[Hidden] C:\Windows\System32\config\systemprofile\AppData\Local\Microsoft\Portable Devices\wpdlog03.sqm
!-->[Hidden] C:\Windows\System32\config\systemprofile\AppData\Local\Microsoft\Portable Devices\wpdlog04.sqm
!-->[Hidden] C:\Windows\System32\config\systemprofile\AppData\Local\Microsoft\Portable Devices\wpdlog05.sqm
!-->[Hidden] C:\Windows\System32\config\systemprofile\AppData\Local\Microsoft\Portable Devices\wpdlog06.sqm
!-->[Hidden] C:\Windows\System32\config\systemprofile\AppData\Local\Microsoft\Portable Devices\wpdlog07.sqm
!-->[Hidden] C:\Windows\System32\config\systemprofile\AppData\Local\Microsoft\Portable Devices\wpdlog08.sqm
!-->[Hidden] C:\Windows\System32\config\systemprofile\AppData\Local\Microsoft\Portable Devices\wpdlog09.sqm
!-->[Hidden] C:\Windows\System32\config\systemprofile\AppData\Local\Microsoft\Portable Devices\wpdlog10.sqm
!-->[Hidden] C:\Windows\System32\config\systemprofile\AppData\Local\Microsoft\Portable Devices\wpdlog11.sqm
!-->[Hidden] C:\Windows\System32\config\systemprofile\AppData\Local\Microsoft\Portable Devices\wpdlog12.sqm
!-->[Hidden] C:\Windows\System32\config\systemprofile\AppData\Local\Microsoft\Portable Devices\wpdlog13.sqm
!-->[Hidden] C:\Windows\System32\config\systemprofile\AppData\Local\Microsoft\Portable Devices\wpdlog14.sqm
!-->[Hidden] C:\Windows\System32\config\systemprofile\AppData\Local\Microsoft\Portable Devices\wpdlog15.sqm
!-->[Hidden] C:\Windows\System32\config\systemprofile\AppData\Local\Microsoft\Portable Devices\wpdlog16.sqm
!-->[Hidden] C:\Windows\System32\config\systemprofile\AppData\Local\Microsoft\Portable Devices\wpdlog17.sqm
!-->[Hidden] C:\Windows\System32\config\systemprofile\AppData\Local\Microsoft\Portable Devices\wpdlog18.sqm
!-->[Hidden] C:\Windows\System32\config\systemprofile\AppData\Local\Microsoft\Portable Devices\wpdlog19.sqm
!-->[Hidden] C:\Windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows Media\11.0\WMSDKNS.DTD
!-->[Hidden] C:\Windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows Media\11.0\WMSDKNS.XML
!-->[Hidden] C:\Windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows Photo Gallery\Original Images\desktop.ini
!-->[Hidden] C:\Windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows Sidebar\Gadgets\desktop.ini
!-->[Hidden] C:\Windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\Burn\Burn\desktop.ini
!-->[Hidden] C:\Windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\GameExplorer\desktop.ini
!-->[Hidden] C:\Windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\History\desktop.ini
!-->[Hidden] C:\Windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\History\History.IE5\desktop.ini
!-->[Hidden] C:\Windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\History\History.IE5\index.dat
!-->[Hidden] C:\Windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\History\History.IE5\MSHist012010053120100607\index.dat
!-->[Hidden] C:\Windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\History\History.IE5\MSHist012010060720100608\index.dat
!-->[Hidden] C:\Windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\desktop.ini
!-->[Hidden] C:\Windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\EAU6UEJ3\desktop.ini
!-->[Hidden] C:\Windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\index.dat
!-->[Hidden] C:\Windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\S5ISAA2K\desktop.ini
!-->[Hidden] C:\Windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\TT9TG7D9\desktop.ini
!-->[Hidden] C:\Windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\ZVRSSN0J\desktop.ini
!-->[Hidden] C:\Windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\desktop.ini
!-->[Hidden] C:\Windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\UsrClass.dat
!-->[Hidden] C:\Windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\UsrClass.dat.LOG1
!-->[Hidden] C:\Windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\UsrClass.dat.LOG2
!-->[Hidden] C:\Windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\UsrClass.dat{50685d1f-4e38-11df-984e-0023ae07c20c}.TM.blf
!-->[Hidden] C:\Windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\UsrClass.dat{50685d1f-4e38-11df-984e-0023ae07c20c}.TMContainer00000000000000000001.regtrans-ms
!-->[Hidden] C:\Windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\UsrClass.dat{50685d1f-4e38-11df-984e-0023ae07c20c}.TMContainer00000000000000000002.regtrans-ms
!-->[Hidden] C:\Windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\UsrClass.dat{66924bdc-707b-11df-a6d5-0023ae07c20c}.TM.blf
!-->[Hidden] C:\Windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\UsrClass.dat{66924bdc-707b-11df-a6d5-0023ae07c20c}.TMContainer00000000000000000001.regtrans-ms
!-->[Hidden] C:\Windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\UsrClass.dat{66924bdc-707b-11df-a6d5-0023ae07c20c}.TMContainer00000000000000000002.regtrans-ms
!-->[Hidden] C:\Windows\System32\config\systemprofile\AppData\Roaming\Adobe\Acrobat\9.0\UserCache.bin
!-->[Hidden] C:\Windows\System32\config\systemprofile\AppData\Roaming\Adobe\Flash Player\AssetCache\TGEZM7WT\1C04C61346A1FA3139A37D860ED92632AA13DECF.heu
!-->[Hidden] C:\Windows\System32\config\systemprofile\AppData\Roaming\Adobe\Flash Player\AssetCache\TGEZM7WT\1C04C61346A1FA3139A37D860ED92632AA13DECF.swz
!-->[Hidden] C:\Windows\System32\config\systemprofile\AppData\Roaming\Adobe\Flash Player\AssetCache\TGEZM7WT\cacheSize.txt
!-->[Hidden] C:\Windows\System32\config\systemprofile\AppData\Roaming\desktop.ini
!-->[Hidden] C:\Windows\System32\config\systemprofile\AppData\Roaming\Macromedia\Flash Player\#SharedObjects\L3DBUHXW\67.15.218.106\RMM_PVP.sol
!-->[Hidden] C:\Windows\System32\config\systemprofile\AppData\Roaming\Macromedia\Flash Player\#SharedObjects\L3DBUHXW\67.15.218.106\syndicate\beyondthedow\beyondthedow.swf\Lightningcast.sol
!-->[Hidden] C:\Windows\System32\config\systemprofile\AppData\Roaming\Macromedia\Flash Player\#SharedObjects\L3DBUHXW\67.15.218.106\syndicate\bighealthtree\bighealthtree.swf\Lightningcast.sol
!-->[Hidden] C:\Windows\System32\config\systemprofile\AppData\Roaming\Macromedia\Flash Player\#SharedObjects\L3DBUHXW\bandtools.nabbr.com\bandtools\media\player02\screens\injector.swf\injectorSO.sol
!-->[Hidden] C:\Windows\System32\config\systemprofile\AppData\Roaming\Macromedia\Flash Player\#SharedObjects\L3DBUHXW\brightcove.com\StreamMinerInfo.sol
!-->[Hidden] C:\Windows\System32\config\systemprofile\AppData\Roaming\Macromedia\Flash Player\#SharedObjects\L3DBUHXW\cache.theatre247.com\swf\t247_2_0.swf\rk2.sol
!-->[Hidden] C:\Windows\System32\config\systemprofile\AppData\Roaming\Macromedia\Flash Player\#SharedObjects\L3DBUHXW\cdn.visiblemeasures.com\sessionData.sol
!-->[Hidden] C:\Windows\System32\config\systemprofile\AppData\Roaming\Macromedia\Flash Player\#SharedObjects\L3DBUHXW\cdn.visiblemeasures.com\userData.sol
!-->[Hidden] C:\Windows\System32\config\systemprofile\AppData\Roaming\Macromedia\Flash Player\#SharedObjects\L3DBUHXW\cdn1.telemetryverification.net\dbg.sol
!-->[Hidden] C:\Windows\System32\config\systemprofile\AppData\Roaming\Macromedia\Flash Player\#SharedObjects\L3DBUHXW\cdn5.specificclick.net\img\gu.sol
!-->[Hidden] C:\Windows\System32\config\systemprofile\AppData\Roaming\Macromedia\Flash Player\#SharedObjects\L3DBUHXW\core.videoegg.com\#com\videoegg\Demo.sol
!-->[Hidden] C:\Windows\System32\config\systemprofile\AppData\Roaming\Macromedia\Flash Player\#SharedObjects\L3DBUHXW\core.videoegg.com\#com\videoegg\OptOut.sol
!-->[Hidden] C:\Windows\System32\config\systemprofile\AppData\Roaming\Macromedia\Flash Player\#SharedObjects\L3DBUHXW\core.videoegg.com\#com\videoegg\Retargeting.sol
!-->[Hidden] C:\Windows\System32\config\systemprofile\AppData\Roaming\Macromedia\Flash Player\#SharedObjects\L3DBUHXW\core.videoegg.com\#com\videoegg\Tearsheet.sol
!-->[Hidden] C:\Windows\System32\config\systemprofile\AppData\Roaming\Macromedia\Flash Player\#SharedObjects\L3DBUHXW\core.videoegg.com\#com\videoegg\Twig.sol
!-->[Hidden] C:\Windows\System32\config\systemprofile\AppData\Roaming\Macromedia\Flash Player\#SharedObjects\L3DBUHXW\core.videoegg.com\#ve\admanager.sol
!-->[Hidden] C:\Windows\System32\config\systemprofile\AppData\Roaming\Macromedia\Flash Player\#SharedObjects\L3DBUHXW\d.yimg.com\ks\ymovies\AdPlugin.swf\session.sol
!-->[Hidden] C:\Windows\System32\config\systemprofile\AppData\Roaming\Macromedia\Flash Player\#SharedObjects\L3DBUHXW\d.yimg.com\VolumePrefs.sol
!-->[Hidden] C:\Windows\System32\config\systemprofile\AppData\Roaming\Macromedia\Flash Player\#SharedObjects\L3DBUHXW\d.yimg.com\YEPBWPrefs.sol
!-->[Hidden] C:\Windows\System32\config\systemprofile\AppData\Roaming\Macromedia\Flash Player\#SharedObjects\L3DBUHXW\findel.scene7.com\s7_storage_tracker.sol
!-->[Hidden] C:\Windows\System32\config\systemprofile\AppData\Roaming\Macromedia\Flash Player\#SharedObjects\L3DBUHXW\flash.quantserve.com\com.quantserve.sol
!-->[Hidden] C:\Windows\System32\config\systemprofile\AppData\Roaming\Macromedia\Flash Player\#SharedObjects\L3DBUHXW\flashtalking.com\ft5414-1.sol
!-->[Hidden] C:\Windows\System32\config\systemprofile\AppData\Roaming\Macromedia\Flash Player\#SharedObjects\L3DBUHXW\images-na.ssl-images-amazon.com\mercury.sol
!-->[Hidden] C:\Windows\System32\config\systemprofile\AppData\Roaming\Macromedia\Flash Player\#SharedObjects\L3DBUHXW\inplay.tubemogul.com\StreamMinerInfo.sol
!-->[Hidden] C:\Windows\System32\config\systemprofile\AppData\Roaming\Macromedia\Flash Player\#SharedObjects\L3DBUHXW\is1.j.tv2n.net\dbg.sol
!-->[Hidden] C:\Windows\System32\config\systemprofile\AppData\Roaming\Macromedia\Flash Player\#SharedObjects\L3DBUHXW\lads.myspacecdn.com\player.sol
!-->[Hidden] C:\Windows\System32\config\systemprofile\AppData\Roaming\Macromedia\Flash Player\#SharedObjects\L3DBUHXW\lads.myspacecdn.com\videos\Main.swf\preferences.sol
!-->[Hidden] C:\Windows\System32\config\systemprofile\AppData\Roaming\Macromedia\Flash Player\#SharedObjects\L3DBUHXW\media.podaddies.com\podaddies_user_data.sol
!-->[Hidden] C:\Windows\System32\config\systemprofile\AppData\Roaming\Macromedia\Flash Player\#SharedObjects\L3DBUHXW\p.ooyala.com\auth.sol
!-->[Hidden] C:\Windows\System32\config\systemprofile\AppData\Roaming\Macromedia\Flash Player\#SharedObjects\L3DBUHXW\p.ooyala.com\auth2.sol
!-->[Hidden] C:\Windows\System32\config\systemprofile\AppData\Roaming\Macromedia\Flash Player\#SharedObjects\L3DBUHXW\p.ooyala.com\perf.sol
!-->[Hidden] C:\Windows\System32\config\systemprofile\AppData\Roaming\Macromedia\Flash Player\#SharedObjects\L3DBUHXW\redir.adap.tv\adap.tv.sol
!-->[Hidden] C:\Windows\System32\config\systemprofile\AppData\Roaming\Macromedia\Flash Player\#SharedObjects\L3DBUHXW\s.ytimg.com\hdTooltipClue2.sol
!-->[Hidden] C:\Windows\System32\config\systemprofile\AppData\Roaming\Macromedia\Flash Player\#SharedObjects\L3DBUHXW\s.ytimg.com\soundData.sol
!-->[Hidden] C:\Windows\System32\config\systemprofile\AppData\Roaming\Macromedia\Flash Player\#SharedObjects\L3DBUHXW\s.ytimg.com\videostats.sol
!-->[Hidden] C:\Windows\System32\config\systemprofile\AppData\Roaming\Macromedia\Flash Player\#SharedObjects\L3DBUHXW\s0.2mdn.net\ft3839-11.sol
!-->[Hidden] C:\Windows\System32\config\systemprofile\AppData\Roaming\Macromedia\Flash Player\#SharedObjects\L3DBUHXW\s0.2mdn.net\ft4913-2.sol
!-->[Hidden] C:\Windows\System32\config\systemprofile\AppData\Roaming\Macromedia\Flash Player\#SharedObjects\L3DBUHXW\s0.2mdn.net\ft4913-6.sol
!-->[Hidden] C:\Windows\System32\config\systemprofile\AppData\Roaming\Macromedia\Flash Player\#SharedObjects\L3DBUHXW\tap-cdn.rubiconproject.com\anon_user.sol
!-->[Hidden] C:\Windows\System32\config\systemprofile\AppData\Roaming\Macromedia\Flash Player\#SharedObjects\L3DBUHXW\twitter.com\flash\twitter_badge.swf\OdeoPodcastPlayerColors.sol
!-->[Hidden] C:\Windows\System32\config\systemprofile\AppData\Roaming\Macromedia\Flash Player\#SharedObjects\L3DBUHXW\video.flashtalking.com\ft5724-1.sol
!-->[Hidden] C:\Windows\System32\config\systemprofile\AppData\Roaming\Macromedia\Flash Player\#SharedObjects\L3DBUHXW\video.flashtalking.com\ft5753-1.sol
!-->[Hidden] C:\Windows\System32\config\systemprofile\AppData\Roaming\Macromedia\Flash Player\#SharedObjects\L3DBUHXW\video.flashtalking.com\ft6086-1.sol
!-->[Hidden] C:\Windows\System32\config\systemprofile\AppData\Roaming\Macromedia\Flash Player\#SharedObjects\L3DBUHXW\video.flashtalking.com\ft6388-1.sol
!-->[Hidden] C:\Windows\System32\config\systemprofile\AppData\Roaming\Macromedia\Flash Player\#SharedObjects\L3DBUHXW\vizu.com\acUserData.sol
!-->[Hidden] C:\Windows\System32\config\systemprofile\AppData\Roaming\Macromedia\Flash Player\#SharedObjects\L3DBUHXW\vox-static.liverail.com\com.quantserve.sol
!-->[Hidden] C:\Windows\System32\config\systemprofile\AppData\Roaming\Macromedia\Flash Player\#SharedObjects\L3DBUHXW\www.blinkx.com\f2\libraries\LightningCastComponent.swf\Lightningcast.sol
!-->[Hidden] C:\Windows\System32\config\systemprofile\AppData\Roaming\Macromedia\Flash Player\#SharedObjects\L3DBUHXW\www.blinkx.com\f2\player.swf\blinkxPlayerSkin1.sol
!-->[Hidden] C:\Windows\System32\config\systemprofile\AppData\Roaming\Macromedia\Flash Player\#SharedObjects\L3DBUHXW\www.we7.com\analytics.sol
!-->[Hidden] C:\Windows\System32\config\systemprofile\AppData\Roaming\Macromedia\Flash Player\macromedia.com\support\flashplayer\sys\#67.15.218.106\settings.sol
!-->[Hidden] C:\Windows\System32\config\systemprofile\AppData\Roaming\Macromedia\Flash Player\macromedia.com\support\flashplayer\sys\#ak.c.ooyala.com\settings.sol
!-->[Hidden] C:\Windows\System32\config\systemprofile\AppData\Roaming\Macromedia\Flash Player\macromedia.com\support\flashplayer\sys\#bandtools.nabbr.com\settings.sol
!-->[Hidden] C:\Windows\System32\config\systemprofile\AppData\Roaming\Macromedia\Flash Player\macromedia.com\support\flashplayer\sys\#brightcove.com\settings.sol
!-->[Hidden] C:\Windows\System32\config\systemprofile\AppData\Roaming\Macromedia\Flash Player\macromedia.com\support\flashplayer\sys\#cache.theatre247.com\settings.sol
!-->[Hidden] C:\Windows\System32\config\systemprofile\AppData\Roaming\Macromedia\Flash Player\macromedia.com\support\flashplayer\sys\#cdn.visiblemeasures.com\settings.sol
!-->[Hidden] C:\Windows\System32\config\systemprofile\AppData\Roaming\Macromedia\Flash Player\macromedia.com\support\flashplayer\sys\#cdn1.telemetryverification.net\settings.sol
!-->[Hidden] C:\Windows\System32\config\systemprofile\AppData\Roaming\Macromedia\Flash Player\macromedia.com\support\flashplayer\sys\#cdn5.specificclick.net\settings.sol
!-->[Hidden] C:\Windows\System32\config\systemprofile\AppData\Roaming\Macromedia\Flash Player\macromedia.com\support\flashplayer\sys\#core.videoegg.com\settings.sol
!-->[Hidden] C:\Windows\System32\config\systemprofile\AppData\Roaming\Macromedia\Flash Player\macromedia.com\support\flashplayer\sys\#d.yimg.com\settings.sol
!-->[Hidden] C:\Windows\System32\config\systemprofile\AppData\Roaming\Macromedia\Flash Player\macromedia.com\support\flashplayer\sys\#findel.scene7.com\settings.sol
!-->[Hidden] C:\Windows\System32\config\systemprofile\AppData\Roaming\Macromedia\Flash Player\macromedia.com\support\flashplayer\sys\#flash.quantserve.com\settings.sol
!-->[Hidden] C:\Windows\System32\config\systemprofile\AppData\Roaming\Macromedia\Flash Player\macromedia.com\support\flashplayer\sys\#flashtalking.com\settings.sol
!-->[Hidden] C:\Windows\System32\config\systemprofile\AppData\Roaming\Macromedia\Flash Player\macromedia.com\support\flashplayer\sys\#images-na.ssl-images-amazon.com\settings.sol
!-->[Hidden] C:\Windows\System32\config\systemprofile\AppData\Roaming\Macromedia\Flash Player\macromedia.com\support\flashplayer\sys\#inplay.tubemogul.com\settings.sol
!-->[Hidden] C:\Windows\System32\config\systemprofile\AppData\Roaming\Macromedia\Flash Player\macromedia.com\support\flashplayer\sys\#is1.j.tv2n.net\settings.sol
!-->[Hidden] C:\Windows\System32\config\systemprofile\AppData\Roaming\Macromedia\Flash Player\macromedia.com\support\flashplayer\sys\#lads.myspace.com\settings.sol
!-->[Hidden] C:\Windows\System32\config\systemprofile\AppData\Roaming\Macromedia\Flash Player\macromedia.com\support\flashplayer\sys\#lads.myspacecdn.com\settings.sol
!-->[Hidden] C:\Windows\System32\config\systemprofile\AppData\Roaming\Macromedia\Flash Player\macromedia.com\support\flashplayer\sys\#media.podaddies.com\settings.sol
!-->[Hidden] C:\Windows\System32\config\systemprofile\AppData\Roaming\Macromedia\Flash Player\macromedia.com\support\flashplayer\sys\#p.ooyala.com\settings.sol
!-->[Hidden] C:\Windows\System32\config\systemprofile\AppData\Roaming\Macromedia\Flash Player\macromedia.com\support\flashplayer\sys\#redir.adap.tv\settings.sol
!-->[Hidden] C:\Windows\System32\config\systemprofile\AppData\Roaming\Macromedia\Flash Player\macromedia.com\support\flashplayer\sys\#s.ytimg.com\settings.sol
!-->[Hidden] C:\Windows\System32\config\systemprofile\AppData\Roaming\Macromedia\Flash Player\macromedia.com\support\flashplayer\sys\#s0.2mdn.net\settings.sol
!-->[Hidden] C:\Windows\System32\config\systemprofile\AppData\Roaming\Macromedia\Flash Player\macromedia.com\support\flashplayer\sys\#tap-cdn.rubiconproject.com\settings.sol
!-->[Hidden] C:\Windows\System32\config\systemprofile\AppData\Roaming\Macromedia\Flash Player\macromedia.com\support\flashplayer\sys\#twitter.com\settings.sol
!-->[Hidden] C:\Windows\System32\config\systemprofile\AppData\Roaming\Macromedia\Flash Player\macromedia.com\support\flashplayer\sys\#video.flashtalking.com\settings.sol
!-->[Hidden] C:\Windows\System32\config\systemprofile\AppData\Roaming\Macromedia\Flash Player\macromedia.com\support\flashplayer\sys\#vizu.com\settings.sol
!-->[Hidden] C:\Windows\System32\config\systemprofile\AppData\Roaming\Macromedia\Flash Player\macromedia.com\support\flashplayer\sys\#vox-static.liverail.com\settings.sol
!-->[Hidden] C:\Windows\System32\config\systemprofile\AppData\Roaming\Macromedia\Flash Player\macromedia.com\support\flashplayer\sys\#www.blinkx.com\settings.sol
!-->[Hidden] C:\Windows\System32\config\systemprofile\AppData\Roaming\Macromedia\Flash Player\macromedia.com\support\flashplayer\sys\#www.jokeroo.com\settings.sol
!-->[Hidden] C:\Windows\System32\config\systemprofile\AppData\Roaming\Macromedia\Flash Player\macromedia.com\support\flashplayer\sys\#www.we7.com\settings.sol
!-->[Hidden] C:\Windows\System32\config\systemprofile\AppData\Roaming\Macromedia\Flash Player\macromedia.com\support\flashplayer\sys\settings.sol
!-->[Hidden] C:\Windows\System32\config\systemprofile\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\desktop.ini
!-->[Hidden] C:\Windows\System32\config\systemprofile\AppData\Roaming\Microsoft\Internet Explorer\UserData\02P2JPKV\pmocntr[1].xml
!-->[Hidden] C:\Windows\System32\config\systemprofile\AppData\Roaming\Microsoft\Internet Explorer\UserData\02P2JPKV\tba[1].xml
!-->[Hidden] C:\Windows\System32\config\systemprofile\AppData\Roaming\Microsoft\Internet Explorer\UserData\index.dat
!-->[Hidden] C:\Windows\System32\config\systemprofile\AppData\Roaming\Microsoft\Windows\Cookies\desktop.ini
!-->[Hidden] C:\Windows\System32\config\systemprofile\AppData\Roaming\Microsoft\Windows\Cookies\index.dat
!-->[Hidden] C:\Windows\System32\config\systemprofile\AppData\Roaming\Microsoft\Windows\Cookies\system@00381712ls.ls100.blueseek[1].txt
!-->[Hidden] C:\Windows\System32\config\systemprofile\AppData\Roaming\Microsoft\Windows\Cookies\system@15502.gotitsearch[1].txt
!-->[Hidden] C:\Windows\System32\config\systemprofile\AppData\Roaming\Microsoft\Windows\Cookies\system@1se[1].txt
!-->[Hidden] C:\Windows\System32\config\systemprofile\AppData\Roaming\Microsoft\Windows\Cookies\system@1se[2].txt
!-->[Hidden] C:\Windows\System32\config\systemprofile\AppData\Roaming\Microsoft\Windows\Cookies\system@21016.t10-click[2].txt
!-->[Hidden] C:\Windows\System32\config\systemprofile\AppData\Roaming\Microsoft\Windows\Cookies\system@64.111.196[1].txt
!-->[Hidden] C:\Windows\System32\config\systemprofile\AppData\Roaming\Microsoft\Windows\Cookies\system@64.111.196[2].txt
!-->[Hidden] C:\Windows\System32\config\systemprofile\AppData\Roaming\Microsoft\Windows\Cookies\system@64.111.196[3].txt
!-->[Hidden] C:\Windows\System32\config\systemprofile\AppData\Roaming\Microsoft\Windows\Cookies\system@64.111.196[4].txt
!-->[Hidden] C:\Windows\System32\config\systemprofile\AppData\Roaming\Microsoft\Windows\Cookies\system@64.111.196[5].txt
!-->[Hidden] C:\Windows\System32\config\systemprofile\AppData\Roaming\Microsoft\Windows\Cookies\system@64.111.196[6].txt
!-->[Hidden] C:\Windows\System32\config\systemprofile\AppData\Roaming\Microsoft\Windows\Cookies\system@64.111.196[7].txt
!-->[Hidden] C:\Windows\System32\config\systemprofile\AppData\Roaming\Microsoft\Windows\Cookies\system@64.111.196[8].txt
!-->[Hidden] C:\Windows\System32\config\systemprofile\AppData\Roaming\Microsoft\Windows\Cookies\system@64.111.196[9].txt
!-->[Hidden] C:\Windows\System32\config\systemprofile\AppData\Roaming\Microsoft\Windows\Cookies\system@66.230.188[1].txt
!-->[Hidden] C:\Windows\System32\config\systemprofile\AppData\Roaming\Microsoft\Windows\Cookies\system@66.45.56[1].txt
!-->[Hidden] C:\Windows\System32\config\systemprofile\AppData\Roaming\Microsoft\Windows\Cookies\system@67.201.36[1].txt
!-->[Hidden] C:\Windows\System32\config\systemprofile\AppData\Roaming\Microsoft\Windows\Cookies\system@67.201.62[1].txt
!-->[Hidden] C:\Windows\System32\config\systemprofile\AppData\Roaming\Microsoft\Windows\Cookies\system@67.201.62[2].txt
!-->[Hidden] C:\Windows\System32\config\systemprofile\AppData\Roaming\Microsoft\Windows\Cookies\system@67.201.62[3].txt
!-->[Hidden] C:\Windows\System32\config\systemprofile\AppData\Roaming\Microsoft\Windows\Cookies\system@67.201.62[4].txt
!-->[Hidden] C:\Windows\System32\config\systemprofile\AppData\Roaming\Microsoft\Windows\Cookies\system@67.201.62[5].txt
!-->[Hidden] C:\Windows\System32\config\systemprofile\AppData\Roaming\Microsoft\Windows\Cookies\system@67.201.62[6].txt
!-->[Hidden] C:\Windows\System32\config\systemprofile\AppData\Roaming\Microsoft\Windows\Cookies\system@67.201.62[7].txt
!-->[Hidden] C:\Windows\System32\config\systemprofile\AppData\Roaming\Microsoft\Windows\Cookies\system@78.140.141[1].txt
!-->[Hidden] C:\Windows\System32\config\systemprofile\AppData\Roaming\Microsoft\Windows\Cookies\system@848612.gotitsearch[1].txt
!-->[Hidden] C:\Windows\System32\config\systemprofile\AppData\Roaming\Microsoft\Windows\Cookies\system@a.shop[2].txt
!-->[Hidden] C:\Windows\System32\config\systemprofile\AppData\Roaming\Microsoft\Windows\Cookies\system@abmr[1].txt
!-->[Hidden] C:\Windows\System32\config\systemprofile\AppData\Roaming\Microsoft\Windows\Cookies\system@ad.uk.doubleclick[1].txt
!-->[Hidden] C:\Windows\System32\config\systemprofile\AppData\Roaming\Microsoft\Windows\Cookies\system@ad.yieldmanager[1].txt
!-->[Hidden] C:\Windows\System32\config\systemprofile\AppData\Roaming\Microsoft\Windows\Cookies\system@ad.yieldmanager[2].txt
!-->[Hidden] C:\Windows\System32\config\systemprofile\AppData\Roaming\Microsoft\Windows\Cookies\system@ad.yieldmanager[3].txt
!-->[Hidden] C:\Windows\System32\config\systemprofile\AppData\Roaming\Microsoft\Windows\Cookies\system@ad.yieldmanager[4].txt
!-->[Hidden] C:\Windows\System32\config\systemprofile\AppData\Roaming\Microsoft\Windows\Cookies\system@ad.yieldmanager[5].txt
!-->[Hidden] C:\Windows\System32\config\systemprofile\AppData\Roaming\Microsoft\Windows\Cookies\system@ad.yieldmanager[7].txt
!-->[Hidden] C:\Windows\System32\config\systemprofile\AppData\Roaming\Microsoft\Windows\Cookies\system@ad.yieldmanager[8].txt
!-->[Hidden] C:\Windows\System32\config\systemprofile\AppData\Roaming\Microsoft\Windows\Cookies\system@addthis[2].txt
!-->[Hidden] C:\Windows\System32\config\systemprofile\AppData\Roaming\Microsoft\Windows\Cookies\system@adfirmative[2].txt
!-->[Hidden] C:\Windows\System32\config\systemprofile\AppData\Roaming\Microsoft\Windows\Cookies\system@adfirmative[3].txt
!-->[Hidden] C:\Windows\System32\config\systemprofile\AppData\Roaming\Microsoft\Windows\Cookies\system@adjug[1].txt
!-->[Hidden] C:\Windows\System32\config\systemprofile\AppData\Roaming\Microsoft\Windows\Cookies\system@adjug[2].txt
!-->[Hidden] C:\Windows\System32\config\systemprofile\AppData\Roaming\Microsoft\Windows\Cookies\system@admax.quisma[2].txt
!-->[Hidden] C:\Windows\System32\config\systemprofile\AppData\Roaming\Microsoft\Windows\Cookies\system@adn.blinkx[1].txt
!-->[Hidden] C:\Windows\System32\config\systemprofile\AppData\Roaming\Microsoft\Windows\Cookies\system@adn.blinkx[2].txt
!-->[Hidden] C:\Windows\System32\config\systemprofile\AppData\Roaming\Microsoft\Windows\Cookies\system@adn.blinkx[3].txt
!-->[Hidden] C:\Windows\System32\config\systemprofile\AppData\Roaming\Microsoft\Windows\Cookies\system@adn.blinkx[4].txt
!-->[Hidden] C:\Windows\System32\config\systemprofile\AppData\Roaming\Microsoft\Windows\Cookies\system@adnxs[1].txt
!-->[Hidden] C:\Windows\System32\config\systemprofile\AppData\Roaming\Microsoft\Windows\Cookies\system@ads.bighealthtree[1].txt
!-->[Hidden] C:\Windows\System32\config\systemprofile\AppData\Roaming\Microsoft\Windows\Cookies\system@ads.bighealthtree[2].txt
!-->[Hidden] C:\Windows\System32\config\systemprofile\AppData\Roaming\Microsoft\Windows\Cookies\system@ads.financialcontent[1].txt
!-->[Hidden] C:\Windows\System32\config\systemprofile\AppData\Roaming\Microsoft\Windows\Cookies\system@ads.gossipcenter[1].txt
!-->[Hidden] C:\Windows\System32\config\systemprofile\AppData\Roaming\Microsoft\Windows\Cookies\system@ads.gossipcenter[2].txt
!-->[Hidden] C:\Windows\System32\config\systemprofile\AppData\Roaming\Microsoft\Windows\Cookies\system@ads.gossipcenter[3].txt
!-->[Hidden] C:\Windows\System32\config\systemprofile\AppData\Roaming\Microsoft\Windows\Cookies\system@ads.gossipcenter[4].txt
!-->[Hidden] C:\Windows\System32\config\systemprofile\AppData\Roaming\Microsoft\Windows\Cookies\system@ads.pubmatic[1].txt
!-->[Hidden] C:\Windows\System32\config\systemprofile\AppData\Roaming\Microsoft\Windows\Cookies\system@ads.smartadx[2].txt
!-->[Hidden] C:\Windows\System32\config\systemprofile\AppData\Roaming\Microsoft\Windows\Cookies\system@adserve.podaddies[1].txt
!-->[Hidden] C:\Windows\System32\config\systemprofile\AppData\Roaming\Microsoft\Windows\Cookies\system@adserve.podaddies[2].txt
!-->[Hidden] C:\Windows\System32\config\systemprofile\AppData\Roaming\Microsoft\Windows\Cookies\system@advertise[1].txt
!-->[Hidden] C:\Windows\System32\config\systemprofile\AppData\Roaming\Microsoft\Windows\Cookies\system@advertise[2].txt
!-->[Hidden] C:\Windows\System32\config\systemprofile\AppData\Roaming\Microsoft\Windows\Cookies\system@advertise[3].txt
!-->[Hidden] C:\Windows\System32\config\systemprofile\AppData\Roaming\Microsoft\Windows\Cookies\system@advertise[4].txt
!-->[Hidden] C:\Windows\System32\config\systemprofile\AppData\Roaming\Microsoft\Windows\Cookies\system@advertise[5].txt
!-->[Hidden] C:\Windows\System32\config\systemprofile\AppData\Roaming\Microsoft\Windows\Cookies\system@advertise[6].txt
!-->[Hidden] C:\Windows\System32\config\systemprofile\AppData\Roaming\Microsoft\Windows\Cookies\system@advertise[7].txt
!-->[Hidden] C:\Windows\System32\config\systemprofile\AppData\Roaming\Microsoft\Windows\Cookies\system@advertise[9].txt
!-->[Hidden] C:\Windows\System32\config\systemprofile\AppData\Roaming\Microsoft\Windows\Cookies\system@advertising[1].txt
!-->[Hidden] C:\Windows\System32\config\systemprofile\AppData\Roaming\Microsoft\Windows\Cookies\system@advertising[2].txt
!-->[Hidden] C:\Windows\System32\config\systemprofile\AppData\Roaming\Microsoft\Windows\Cookies\system@advertising[3].txt
!-->[Hidden] C:\Windows\System32\config\systemprofile\AppData\Roaming\Microsoft\Windows\Cookies\system@advertising[4].txt
!-->[Hidden] C:\Windows\System32\config\systemprofile\AppData\Roaming\Microsoft\Windows\Cookies\system@advertising[5].txt
!-->[Hidden] C:\Windows\System32\config\systemprofile\AppData\Roaming\Microsoft\Windows\Cookies\system@adviva[2].txt
!-->[Hidden] C:\Windows\System32\config\systemprofile\AppData\Roaming\Microsoft\Windows\Cookies\system@adviva[3].txt
!-->[Hidden] C:\Windows\System32\config\systemprofile\AppData\Roaming\Microsoft\Windows\Cookies\system@adviva[4].txt
!-->[Hidden] C:\Windows\System32\config\systemprofile\AppData\Roaming\Microsoft\Windows\Cookies\system@affgold1.91462.blueseek[1].txt
!-->[Hidden] C:\Windows\System32\config\systemprofile\AppData\Roaming\Microsoft\Windows\Cookies\system@affgold1.91491.blueseek[1].txt
!-->[Hidden] C:\Windows\System32\config\systemprofile\AppData\Roaming\Microsoft\Windows\Cookies\system@affgold2.91456.blueseek[1].txt
!-->[Hidden] C:\Windows\System32\config\systemprofile\AppData\Roaming\Microsoft\Windows\Cookies\system@affgold6.91423.blueseek[1].txt
!-->[Hidden] C:\Windows\System32\config\systemprofile\AppData\Roaming\Microsoft\Windows\Cookies\system@affgold8.91462.blueseek[1].txt
!-->[Hidden] C:\Windows\System32\config\systemprofile\AppData\Roaming\Microsoft\Windows\Cookies\system@amgdgt[1].txt
!-->[Hidden] C:\Windows\System32\config\systemprofile\AppData\Roaming\Microsoft\Windows\Cookies\system@apmebf[1].txt
!-->[Hidden] C:\Windows\System32\config\systemprofile\AppData\Roaming\Microsoft\Windows\Cookies\system@apmebf[2].txt
!-->[Hidden] C:\Windows\System32\config\systemprofile\AppData\Roaming\Microsoft\Windows\Cookies\system@atdmt[1].txt
!-->[Hidden] C:\Windows\System32\config\systemprofile\AppData\Roaming\Microsoft\Windows\Cookies\system@atdmt[2].txt
!-->[Hidden] C:\Windows\System32\config\systemprofile\AppData\Roaming\Microsoft\Windows\Cookies\system@atdmt[3].txt
!-->[Hidden] C:\Windows\System32\config\systemprofile\AppData\Roaming\Microsoft\Windows\Cookies\system@atdmt[4].txt
!-->[Hidden] C:\Windows\System32\config\systemprofile\AppData\Roaming\Microsoft\Windows\Cookies\system@atdmt[5].txt
!-->[Hidden] C:\Windows\System32\config\systemprofile\AppData\Roaming\Microsoft\Windows\Cookies\system@beyondthedow[1].txt
!-->[Hidden] C:\Windows\System32\config\systemprofile\AppData\Roaming\Microsoft\Windows\Cookies\system@bidsystem[1].txt
!-->[Hidden] C:\Windows\System32\config\systemprofile\AppData\Roaming\Microsoft\Windows\Cookies\system@bidsystem[2].txt
!-->[Hidden] C:\Windows\System32\config\systemprofile\AppData\Roaming\Microsoft\Windows\Cookies\system@bidsystem[3].txt
!-->[Hidden] C:\Windows\System32\config\systemprofile\AppData\Roaming\Microsoft\Windows\Cookies\system@bidsystem[4].txt
!-->[Hidden] C:\Windows\System32\config\systemprofile\AppData\Roaming\Microsoft\Windows\Cookies\system@bidsystem[5].txt
!-->[Hidden] C:\Windows\System32\config\systemprofile\AppData\Roaming\Microsoft\Windows\Cookies\system@bidsystem[6].txt
!-->[Hidden] C:\Windows\System32\config\systemprofile\AppData\Roaming\Microsoft\Windows\Cookies\system@bidsystem[7].txt
!-->[Hidden] C:\Windows\System32\config\systemprofile\AppData\Roaming\Microsoft\Windows\Cookies\system@bighealthtree[1].txt
!-->[Hidden] C:\Windows\System32\config\systemprofile\AppData\Roaming\Microsoft\Windows\Cookies\system@blinkx[1].txt
!-->[Hidden] C:\Windows\System32\config\systemprofile\AppData\Roaming\Microsoft\Windows\Cookies\system@blinkx[2].txt
!-->[Hidden] C:\Windows\System32\config\systemprofile\AppData\Roaming\Microsoft\Windows\Cookies\system@blinkx[3].txt
!-->[Hidden] C:\Windows\System32\config\systemprofile\AppData\Roaming\Microsoft\Windows\Cookies\system@blinkx[4].txt
!-->[Hidden] C:\Windows\System32\config\systemprofile\AppData\Roaming\Microsoft\Windows\Cookies\system@bluekai[2].txt
!-->[Hidden] C:\Windows\System32\config\systemprofile\AppData\Roaming\Microsoft\Windows\Cookies\system@bluesq[1].txt
!-->[Hidden] C:\Windows\System32\config\systemprofile\AppData\Roaming\Microsoft\Windows\Cookies\system@bs.serving-sys[1].txt
!-->[Hidden] C:\Windows\System32\config\systemprofile\AppData\Roaming\Microsoft\Windows\Cookies\system@bs.serving-sys[2].txt
!-->[Hidden] C:\Windows\System32\config\systemprofile\AppData\Roaming\Microsoft\Windows\Cookies\system@bs.serving-sys[3].txt
!-->[Hidden] C:\Windows\System32\config\systemprofile\AppData\Roaming\Microsoft\Windows\Cookies\system@c.adfirmative[1].txt
!-->[Hidden] C:\Windows\System32\config\systemprofile\AppData\Roaming\Microsoft\Windows\Cookies\system@c.adfirmative[2].txt
!-->[Hidden] C:\Windows\System32\config\systemprofile\AppData\Roaming\Microsoft\Windows\Cookies\system@c.ppcxml[1].txt
!-->[Hidden] C:\Windows\System32\config\systemprofile\AppData\Roaming\Microsoft\Windows\Cookies\system@c.ppcxml[2].txt
!-->[Hidden] C:\Windows\System32\config\systemprofile\AppData\Roaming\Microsoft\Windows\Cookies\system@c.ppcxml[3].txt
!-->[Hidden] C:\Windows\System32\config\systemprofile\AppData\Roaming\Microsoft\Windows\Cookies\system@CAAZ1R5Q.txt
!-->[Hidden] C:\Windows\System32\config\systemprofile\AppData\Roaming\Microsoft\Windows\Cookies\system@CAIACXIJ.txt
!-->[Hidden] C:\Windows\System32\config\systemprofile\AppData\Roaming\Microsoft\Windows\Cookies\system@CAJBDDN0.txt
!-->[Hidden] C:\Windows\System32\config\systemprofile\AppData\Roaming\Microsoft\Windows\Cookies\system@cam.demdex[1].txt
!-->[Hidden] C:\Windows\System32\config\systemprofile\AppData\Roaming\Microsoft\Windows\Cookies\system@CAM2Q1RE.txt
!-->[Hidden] C:\Windows\System32\config\systemprofile\AppData\Roaming\Microsoft\Windows\Cookies\system@CAZJPD2U.txt
!-->[Hidden] C:\Windows\System32\config\systemprofile\AppData\Roaming\Microsoft\Windows\Cookies\system@chinaontv[2].txt
!-->[Hidden] C:\Windows\System32\config\systemprofile\AppData\Roaming\Microsoft\Windows\Cookies\system@chinaontv[3].txt
!-->[Hidden] C:\Windows\System32\config\systemprofile\AppData\Roaming\Microsoft\Windows\Cookies\system@click.kiwinets[1].txt
!-->[Hidden] C:\Windows\System32\config\systemprofile\AppData\Roaming\Microsoft\Windows\Cookies\system@clickpayz4.91462.blueseek[1].txt
!-->[Hidden] C:\Windows\System32\config\systemprofile\AppData\Roaming\Microsoft\Windows\Cookies\system@clickpayz4.91462.blueseek[2].txt
!-->[Hidden] C:\Windows\System32\config\systemprofile\AppData\Roaming\Microsoft\Windows\Cookies\system@clickpayz4.91462.blueseek[3].txt
!-->[Hidden] C:\Windows\System32\config\systemprofile\AppData\Roaming\Microsoft\Windows\Cookies\system@clickpayz5.91456.blueseek[1].txt
!-->[Hidden] C:\Windows\System32\config\systemprofile\AppData\Roaming\Microsoft\Windows\Cookies\system@clickpayz5.91462.blueseek[1].txt
!-->[Hidden] C:\Windows\System32\config\systemprofile\AppData\Roaming\Microsoft\Windows\Cookies\system@clickpayz7.91462.blueseek[1].txt
!-->[Hidden] C:\Windows\System32\config\systemprofile\AppData\Roaming\Microsoft\Windows\Cookies\system@clicksor[2].txt
!-->[Hidden] C:\Windows\System32\config\systemprofile\AppData\Roaming\Microsoft\Windows\Cookies\system@content.pkr[1].txt
!-->[Hidden] C:\Windows\System32\config\systemprofile\AppData\Roaming\Microsoft\Windows\Cookies\system@content.yieldmanager[1].txt
!-->[Hidden] C:\Windows\System32\config\systemprofile\AppData\Roaming\Microsoft\Windows\Cookies\system@content.yieldmanager[3].txt
!-->[Hidden] C:\Windows\System32\config\systemprofile\AppData\Roaming\Microsoft\Windows\Cookies\system@content.yieldmanager[4].txt
!-->[Hidden] C:\Windows\System32\config\systemprofile\AppData\Roaming\Microsoft\Windows\Cookies\system@cptgt[1].txt
!-->[Hidden] C:\Windows\System32\config\systemprofile\AppData\Roaming\Microsoft\Windows\Cookies\system@cptgt[2].txt
!-->[Hidden] C:\Windows\System32\config\systemprofile\AppData\Roaming\Microsoft\Windows\Cookies\system@cptgt[3].txt
!-->[Hidden] C:\Windows\System32\config\systemprofile\AppData\Roaming\Microsoft\Windows\Cookies\system@cptgt[5].txt
!-->[Hidden] C:\Windows\System32\config\systemprofile\AppData\Roaming\Microsoft\Windows\Cookies\system@criteo[2].txt
!-->[Hidden] C:\Windows\System32\config\systemprofile\AppData\Roaming\Microsoft\Windows\Cookies\system@ctasnet[2].txt
!-->[Hidden] C:\Windows\System32\config\systemprofile\AppData\Roaming\Microsoft\Windows\Cookies\system@dashboardad[1].txt
!-->[Hidden] C:\Windows\System32\config\systemprofile\AppData\Roaming\Microsoft\Windows\Cookies\system@dir.knowledgewiki[1].txt
!-->[Hidden] C:\Windows\System32\config\systemprofile\AppData\Roaming\Microsoft\Windows\Cookies\system@doubleclick[10].txt
!-->[Hidden] C:\Windows\System32\config\systemprofile\AppData\Roaming\Microsoft\Windows\Cookies\system@doubleclick[11].txt
!-->[Hidden] C:\Windows\System32\config\systemprofile\AppData\Roaming\Microsoft\Windows\Cookies\system@doubleclick[1].txt
!-->[Hidden] C:\Windows\System32\config\systemprofile\AppData\Roaming\Microsoft\Windows\Cookies\system@doubleclick[2].txt
!-->[Hidden] C:\Windows\System32\config\systemprofile\AppData\Roaming\Microsoft\Windows\Cookies\system@doubleclick[3].txt
!-->[Hidden] C:\Windows\System32\config\systemprofile\AppData\Roaming\Microsoft\Windows\Cookies\system@doubleclick[4].txt
!-->[Hidden] C:\Windows\System32\config\systemprofile\AppData\Roaming\Microsoft\Windows\Cookies\system@doubleclick[5].txt
!-->[Hidden] C:\Windows\System32\config\systemprofile\AppData\Roaming\Microsoft\Windows\Cookies\system@doubleclick[6].txt
!-->[Hidden] C:\Windows\System32\config\systemprofile\AppData\Roaming\Microsoft\Windows\Cookies\system@doubleclick[7].txt
!-->[Hidden] C:\Windows\System32\config\systemprofile\AppData\Roaming\Microsoft\Windows\Cookies\system@doubleclick[8].txt
!-->[Hidden] C:\Windows\System32\config\systemprofile\AppData\Roaming\Microsoft\Windows\Cookies\system@doubleclick[9].txt
!-->[Hidden] C:\Windows\System32\config\systemprofile\AppData\Roaming\Microsoft\Windows\Cookies\system@ebay.co[1].txt
!-->[Hidden] C:\Windows\System32\config\systemprofile\AppData\Roaming\Microsoft\Windows\Cookies\system@ebay.co[2].txt
!-->[Hidden] C:\Windows\System32\config\systemprofile\AppData\Roaming\Microsoft\Windows\Cookies\system@ebay.co[3].txt
!-->[Hidden] C:\Windows\System32\config\systemprofile\AppData\Roaming\Microsoft\Windows\Cookies\system@ebay.co[4].txt
!-->[Hidden] C:\Windows\System32\config\systemprofile\AppData\Roaming\Microsoft\Windows\Cookies\system@ebayobjects[1].txt
!-->[Hidden] C:\Windows\System32\config\systemprofile\AppData\Roaming\Microsoft\Windows\Cookies\system@ebayobjects[2].txt
!-->[Hidden] C:\Windows\System32\config\systemprofile\AppData\Roaming\Microsoft\Windows\Cookies\system@ebayobjects[3].txt
!-->[Hidden] C:\Windows\System32\config\systemprofile\AppData\Roaming\Microsoft\Windows\Cookies\system@ebayobjects[4].txt
!-->[Hidden] C:\Windows\System32\config\systemprofile\AppData\Roaming\Microsoft\Windows\Cookies\system@ebayrtm[2].txt
!-->[Hidden] C:\Windows\System32\config\systemprofile\AppData\Roaming\Microsoft\Windows\Cookies\system@ebay[1].txt
!-->[Hidden] C:\Windows\System32\config\systemprofile\AppData\Roaming\Microsoft\Windows\Cookies\system@ebay[2].txt
!-->[Hidden] C:\Windows\System32\config\systemprofile\AppData\Roaming\Microsoft\Windows\Cookies\system@ebay[3].txt
!-->[Hidden] C:\Windows\System32\config\systemprofile\AppData\Roaming\Microsoft\Windows\Cookies\system@ebay[4].txt
!-->[Hidden] C:\Windows\System32\config\systemprofile\AppData\Roaming\Microsoft\Windows\Cookies\system@electronicfan[1].txt
!-->[Hidden] C:\Windows\System32\config\systemprofile\AppData\Roaming\Microsoft\Windows\Cookies\system@elitemarket[1].txt
!-->[Hidden] C:\Windows\System32\config\systemprofile\AppData\Roaming\Microsoft\Windows\Cookies\system@facebook[1].txt
!-->[Hidden] C:\Windows\System32\config\systemprofile\AppData\Roaming\Microsoft\Windows\Cookies\system@fantribes[1].txt
!-->[Hidden] C:\Windows\System32\config\systemprofile\AppData\Roaming\Microsoft\Windows\Cookies\system@fantribes[2].txt
!-->[Hidden] C:\Windows\System32\config\systemprofile\AppData\Roaming\Microsoft\Windows\Cookies\system@fantribes[3].txt
!-->[Hidden] C:\Windows\System32\config\systemprofile\AppData\Roaming\Microsoft\Windows\Cookies\system@feed.genieknows[1].txt
!-->[Hidden] C:\Windows\System32\config\systemprofile\AppData\Roaming\Microsoft\Windows\Cookies\system@feed.genieknows[2].txt
!-->[Hidden] C:\Windows\System32\config\systemprofile\AppData\Roaming\Microsoft\Windows\Cookies\system@financialcontent[1].txt
!-->[Hidden] C:\Windows\System32\config\systemprofile\AppData\Roaming\Microsoft\Windows\Cookies\system@flashtalking[1].txt
!-->[Hidden] C:\Windows\System32\config\systemprofile\AppData\Roaming\Microsoft\Windows\Cookies\system@flashtalking[2].txt
!-->[Hidden] C:\Windows\System32\config\systemprofile\AppData\Roaming\Microsoft\Windows\Cookies\system@flashtalking[3].txt
!-->[Hidden] C:\Windows\System32\config\systemprofile\AppData\Roaming\Microsoft\Windows\Cookies\system@flashtalking[4].txt
!-->[Hidden] C:\Windows\System32\config\systemprofile\AppData\Roaming\Microsoft\Windows\Cookies\system@google.co[1].txt
!-->[Hidden] C:\Windows\System32\config\systemprofile\AppData\Roaming\Microsoft\Windows\Cookies\system@google.co[2].txt
!-->[Hidden] C:\Windows\System32\config\systemprofile\AppData\Roaming\Microsoft\Windows\Cookies\system@google.co[3].txt
!-->[Hidden] C:\Windows\System32\config\systemprofile\AppData\Roaming\Microsoft\Windows\Cookies\system@google.co[4].txt
!-->[Hidden] C:\Windows\System32\config\systemprofile\AppData\Roaming\Microsoft\Windows\Cookies\system@google.co[5].txt
!-->[Hidden] C:\Windows\System32\config\systemprofile\AppData\Roaming\Microsoft\Windows\Cookies\system@google.co[6].txt
!-->[Hidden] C:\Windows\System32\config\systemprofile\AppData\Roaming\Microsoft\Windows\Cookies\system@google[1].txt
!-->[Hidden] C:\Windows\System32\config\systemprofile\AppData\Roaming\Microsoft\Windows\Cookies\system@google[2].txt
!-->[Hidden] C:\Windows\System32\config\systemprofile\AppData\Roaming\Microsoft\Windows\Cookies\system@google[3].txt
!-->[Hidden] C:\Windows\System32\config\systemprofile\AppData\Roaming\Microsoft\Windows\Cookies\system@google[4].txt
!-->[Hidden] C:\Windows\System32\config\systemprofile\AppData\Roaming\Microsoft\Windows\Cookies\system@google[5].txt
!-->[Hidden] C:\Windows\System32\config\systemprofile\AppData\Roaming\Microsoft\Windows\Cookies\system@google[6].txt
!-->[Hidden] C:\Windows\System32\config\systemprofile\AppData\Roaming\Microsoft\Windows\Cookies\system@google[7].txt
!-->[Hidden] C:\Windows\System32\config\systemprofile\AppData\Roaming\Microsoft\Windows\Cookies\system@google[8].txt
!-->[Hidden] C:\Windows\System32\config\systemprofile\AppData\Roaming\Microsoft\Windows\Cookies\system@gossipcenter[2].txt
!-->[Hidden] C:\Windows\System32\config\systemprofile\AppData\Roaming\Microsoft\Windows\Cookies\system@gossipcenter[3].txt
!-->[Hidden] C:\Windows\System32\config\systemprofile\AppData\Roaming\Microsoft\Windows\Cookies\system@gossipcenter[4].txt
!-->[Hidden] C:\Windows\System32\config\systemprofile\AppData\Roaming\Microsoft\Windows\Cookies\system@gotitsearch[1].txt
!-->[Hidden] C:\Windows\System32\config\systemprofile\AppData\Roaming\Microsoft\Windows\Cookies\system@gotitsearch[2].txt
!-->[Hidden] C:\Windows\System32\config\systemprofile\AppData\Roaming\Microsoft\Windows\Cookies\system@iesnare[2].txt
!-->[Hidden] C:\Windows\System32\config\systemprofile\AppData\Roaming\Microsoft\Windows\Cookies\system@invitemedia[1].txt
!-->[Hidden] C:\Windows\System32\config\systemprofile\AppData\Roaming\Microsoft\Windows\Cookies\system@invitemedia[2].txt
!-->[Hidden] C:\Windows\System32\config\systemprofile\AppData\Roaming\Microsoft\Windows\Cookies\system@kitegreed[1].txt
!-->[Hidden] C:\Windows\System32\config\systemprofile\AppData\Roaming\Microsoft\Windows\Cookies\system@knowledgewiki[1].txt
!-->[Hidden] C:\Windows\System32\config\systemprofile\AppData\Roaming\Microsoft\Windows\Cookies\system@liverail[1].txt
!-->[Hidden] C:\Windows\System32\config\systemprofile\AppData\Roaming\Microsoft\Windows\Cookies\system@liverail[2].txt
!-->[Hidden] C:\Windows\System32\config\systemprofile\AppData\Roaming\Microsoft\Windows\Cookies\system@looksmart[1].txt
!-->[Hidden] C:\Windows\System32\config\systemprofile\AppData\Roaming\Microsoft\Windows\Cookies\system@looksmart[2].txt
!-->[Hidden] C:\Windows\System32\config\systemprofile\AppData\Roaming\Microsoft\Windows\Cookies\system@looksmart[3].txt
!-->[Hidden] C:\Windows\System32\config\systemprofile\AppData\Roaming\Microsoft\Windows\Cookies\system@lovefilm.db.advertising[1].txt
!-->[Hidden] C:\Windows\System32\config\systemprofile\AppData\Roaming\Microsoft\Windows\Cookies\system@lovefilm.db.advertising[3].txt
!-->[Hidden] C:\Windows\System32\config\systemprofile\AppData\Roaming\Microsoft\Windows\Cookies\system@lovefilm[1].txt
!-->[Hidden] C:\Windows\System32\config\systemprofile\AppData\Roaming\Microsoft\Windows\Cookies\system@lovefilm[2].txt
!-->[Hidden] C:\Windows\System32\config\systemprofile\AppData\Roaming\Microsoft\Windows\Cookies\system@mail.google[2].txt
!-->[Hidden] C:\Windows\System32\config\systemprofile\AppData\Roaming\Microsoft\Windows\Cookies\system@mail.google[3].txt
!-->[Hidden] C:\Windows\System32\config\systemprofile\AppData\Roaming\Microsoft\Windows\Cookies\system@mdinfo[2].txt
!-->[Hidden] C:\Windows\System32\config\systemprofile\AppData\Roaming\Microsoft\Windows\Cookies\system@mediaplex[1].txt
!-->[Hidden] C:\Windows\System32\config\systemprofile\AppData\Roaming\Microsoft\Windows\Cookies\system@mediaplex[2].txt
!-->[Hidden] C:\Windows\System32\config\systemprofile\AppData\Roaming\Microsoft\Windows\Cookies\system@mediatraffic[1].txt
!-->[Hidden] C:\Windows\System32\config\systemprofile\AppData\Roaming\Microsoft\Windows\Cookies\system@mediatraffic[2].txt
!-->[Hidden] C:\Windows\System32\config\systemprofile\AppData\Roaming\Microsoft\Windows\Cookies\system@myroitracking[1].txt
!-->[Hidden] C:\Windows\System32\config\systemprofile\AppData\Roaming\Microsoft\Windows\Cookies\system@overture[1].txt
!-->[Hidden] C:\Windows\System32\config\systemprofile\AppData\Roaming\Microsoft\Windows\Cookies\system@overture[2].txt
!-->[Hidden] C:\Windows\System32\config\systemprofile\AppData\Roaming\Microsoft\Windows\Cookies\system@overture[3].txt
!-->[Hidden] C:\Windows\System32\config\systemprofile\AppData\Roaming\Microsoft\Windows\Cookies\system@pacifictranscription.com[2].txt
!-->[Hidden] C:\Windows\System32\config\systemprofile\AppData\Roaming\Microsoft\Windows\Cookies\system@pkr[1].txt
!-->[Hidden] C:\Windows\System32\config\systemprofile\AppData\Roaming\Microsoft\Windows\Cookies\system@pkr[2].txt
!-->[Hidden] C:\Windows\System32\config\systemprofile\AppData\Roaming\Microsoft\Windows\Cookies\system@promo.bluesq[1].txt
!-->[Hidden] C:\Windows\System32\config\systemprofile\AppData\Roaming\Microsoft\Windows\Cookies\system@pubmatic[2].txt
!-->[Hidden] C:\Windows\System32\config\systemprofile\AppData\Roaming\Microsoft\Windows\Cookies\system@pubmatic[3].txt
!-->[Hidden] C:\Windows\System32\config\systemprofile\AppData\Roaming\Microsoft\Windows\Cookies\system@quantserve[1].txt
!-->[Hidden] C:\Windows\System32\config\systemprofile\AppData\Roaming\Microsoft\Windows\Cookies\system@quantserve[2].txt
!-->[Hidden] C:\Windows\System32\config\systemprofile\AppData\Roaming\Microsoft\Windows\Cookies\system@quantserve[3].txt
!-->[Hidden] C:\Windows\System32\config\systemprofile\AppData\Roaming\Microsoft\Windows\Cookies\system@quantserve[4].txt
!-->[Hidden] C:\Windows\System32\config\systemprofile\AppData\Roaming\Microsoft\Windows\Cookies\system@quantserve[5].txt
!-->[Hidden] C:\Windows\System32\config\systemprofile\AppData\Roaming\Microsoft\Windows\Cookies\system@revsci[1].txt
!-->[Hidden] C:\Windows\System32\config\systemprofile\AppData\Roaming\Microsoft\Windows\Cookies\system@rubiconproject[1].txt
!-->[Hidden] C:\Windows\System32\config\systemprofile\AppData\Roaming\Microsoft\Windows\Cookies\system@scorecardresearch[1].txt
!-->[Hidden] C:\Windows\System32\config\systemprofile\AppData\Roaming\Microsoft\Windows\Cookies\system@scorecardresearch[2].txt
!-->[Hidden] C:\Windows\System32\config\systemprofile\AppData\Roaming\Microsoft\Windows\Cookies\system@scorecardresearch[3].txt
!-->[Hidden] C:\Windows\System32\config\systemprofile\AppData\Roaming\Microsoft\Windows\Cookies\system@scorecardresearch[4].txt
!-->[Hidden] C:\Windows\System32\config\systemprofile\AppData\Roaming\Microsoft\Windows\Cookies\system@scorecardresearch[5].txt
!-->[Hidden] C:\Windows\System32\config\systemprofile\AppData\Roaming\Microsoft\Windows\Cookies\system@scorecardresearch[6].txt
!-->[Hidden] C:\Windows\System32\config\systemprofile\AppData\Roaming\Microsoft\Windows\Cookies\system@scorecardresearch[7].txt
!-->[Hidden] C:\Windows\System32\config\systemprofile\AppData\Roaming\Microsoft\Windows\Cookies\system@securestudies[2].txt
!-->[Hidden] C:\Windows\System32\config\systemprofile\AppData\Roaming\Microsoft\Windows\Cookies\system@securestudies[3].txt
!-->[Hidden] C:\Windows\System32\config\systemprofile\AppData\Roaming\Microsoft\Windows\Cookies\system@securestudies[4].txt
!-->[Hidden] C:\Windows\System32\config\systemprofile\AppData\Roaming\Microsoft\Windows\Cookies\system@securestudies[5].txt
!-->[Hidden] C:\Windows\System32\config\systemprofile\AppData\Roaming\Microsoft\Windows\Cookies\system@securestudies[6].txt
!-->[Hidden] C:\Windows\System32\config\systemprofile\AppData\Roaming\Microsoft\Windows\Cookies\system@sensic[1].txt
!-->[Hidden] C:\Windows\System32\config\systemprofile\AppData\Roaming\Microsoft\Windows\Cookies\system@serving-sys[1].txt
!-->[Hidden] C:\Windows\System32\config\systemprofile\AppData\Roaming\Microsoft\Windows\Cookies\system@serving-sys[2].txt
!-->[Hidden] C:\Windows\System32\config\systemprofile\AppData\Roaming\Microsoft\Windows\Cookies\system@serving-sys[3].txt
!-->[Hidden] C:\Windows\System32\config\systemprofile\AppData\Roaming\Microsoft\Windows\Cookies\system@shop-com.co[1].txt
!-->[Hidden] C:\Windows\System32\config\systemprofile\AppData\Roaming\Microsoft\Windows\Cookies\system@shop.lovefilm[1].txt
!-->[Hidden] C:\Windows\System32\config\systemprofile\AppData\Roaming\Microsoft\Windows\Cookies\system@sitewatch[1].txt
!-->[Hidden] C:\Windows\System32\config\systemprofile\AppData\Roaming\Microsoft\Windows\Cookies\system@smartadx[1].txt
!-->[Hidden] C:\Windows\System32\config\systemprofile\AppData\Roaming\Microsoft\Windows\Cookies\system@spanair[1].txt
!-->[Hidden] C:\Windows\System32\config\systemprofile\AppData\Roaming\Microsoft\Windows\Cookies\system@spotxchange[1].txt
!-->[Hidden] C:\Windows\System32\config\systemprofile\AppData\Roaming\Microsoft\Windows\Cookies\system@spotxchange[2].txt
!-->[Hidden] C:\Windows\System32\config\systemprofile\AppData\Roaming\Microsoft\Windows\Cookies\system@spotxchange[4].txt
!-->[Hidden] C:\Windows\System32\config\systemprofile\AppData\Roaming\Microsoft\Windows\Cookies\system@spotxchange[5].txt
!-->[Hidden] C:\Windows\System32\config\systemprofile\AppData\Roaming\Microsoft\Windows\Cookies\system@struq[1].txt
!-->[Hidden] C:\Windows\System32\config\systemprofile\AppData\Roaming\Microsoft\Windows\Cookies\system@tag.admeld[1].txt
!-->[Hidden] C:\Windows\System32\config\systemprofile\AppData\Roaming\Microsoft\Windows\Cookies\system@tidaltv[1].txt
!-->[Hidden] C:\Windows\System32\config\systemprofile\AppData\Roaming\Microsoft\Windows\Cookies\system@trusearch[1].txt
!-->[Hidden] C:\Windows\System32\config\systemprofile\AppData\Roaming\Microsoft\Windows\Cookies\system@trusearch[2].txt
!-->[Hidden] C:\Windows\System32\config\systemprofile\AppData\Roaming\Microsoft\Windows\Cookies\system@trusearch[3].txt
!-->[Hidden] C:\Windows\System32\config\systemprofile\AppData\Roaming\Microsoft\Windows\Cookies\system@trusearch[4].txt
!-->[Hidden] C:\Windows\System32\config\systemprofile\AppData\Roaming\Microsoft\Windows\Cookies\system@trusearch[5].txt
!-->[Hidden] C:\Windows\System32\config\systemprofile\AppData\Roaming\Microsoft\Windows\Cookies\system@trusearch[6].txt
!-->[Hidden] C:\Windows\System32\config\systemprofile\AppData\Roaming\Microsoft\Windows\Cookies\system@turn[2].txt
!-->[Hidden] C:\Windows\System32\config\systemprofile\AppData\Roaming\Microsoft\Windows\Cookies\system@uk.ebayrtm[1].txt
!-->[Hidden] C:\Windows\System32\config\systemprofile\AppData\Roaming\Microsoft\Windows\Cookies\system@uk.ebayrtm[2].txt
!-->[Hidden] C:\Windows\System32\config\systemprofile\AppData\Roaming\Microsoft\Windows\Cookies\system@uk.ebayrtm[3].txt
!-->[Hidden] C:\Windows\System32\config\systemprofile\AppData\Roaming\Microsoft\Windows\Cookies\system@uk.ebayrtm[5].txt
!-->[Hidden] C:\Windows\System32\config\systemprofile\AppData\Roaming\Microsoft\Windows\Cookies\system@utarget.co[2].txt
!-->[Hidden] C:\Windows\System32\config\systemprofile\AppData\Roaming\Microsoft\Windows\Cookies\system@velvettissue[2].txt
!-->[Hidden] C:\Windows\System32\config\systemprofile\AppData\Roaming\Microsoft\Windows\Cookies\system@video.google.co[1].txt
!-->[Hidden] C:\Windows\System32\config\systemprofile\AppData\Roaming\Microsoft\Windows\Cookies\system@video.google.co[2].txt
!-->[Hidden] C:\Windows\System32\config\systemprofile\AppData\Roaming\Microsoft\Windows\Cookies\system@videoegg.adbureau[2].txt
!-->[Hidden] C:\Windows\System32\config\systemprofile\AppData\Roaming\Microsoft\Windows\Cookies\system@videoegg[1].txt
!-->[Hidden] C:\Windows\System32\config\systemprofile\AppData\Roaming\Microsoft\Windows\Cookies\system@world.chinaontv[2].txt
!-->[Hidden] C:\Windows\System32\config\systemprofile\AppData\Roaming\Microsoft\Windows\Cookies\system@world.chinaontv[3].txt
!-->[Hidden] C:\Windows\System32\config\systemprofile\AppData\Roaming\Microsoft\Windows\Cookies\system@www.blinkx[1].txt
!-->[Hidden] C:\Windows\System32\config\systemprofile\AppData\Roaming\Microsoft\Windows\Cookies\system@www.blinkx[2].txt
!-->[Hidden] C:\Windows\System32\config\systemprofile\AppData\Roaming\Microsoft\Windows\Cookies\system@www.blinkx[4].txt
!-->[Hidden] C:\Windows\System32\config\systemprofile\AppData\Roaming\Microsoft\Windows\Cookies\system@www.blinkx[5].txt
!-->[Hidden] C:\Windows\System32\config\systemprofile\AppData\Roaming\Microsoft\Windows\Cookies\system@www.findlocatesearch[1].txt
!-->[Hidden] C:\Windows\System32\config\systemprofile\AppData\Roaming\Microsoft\Windows\Cookies\system@www.findweblocate[1].txt
!-->[Hidden] C:\Windows\System32\config\systemprofile\AppData\Roaming\Microsoft\Windows\Cookies\system@www.gossipcenter[1].txt
!-->[Hidden] C:\Windows\System32\config\systemprofile\AppData\Roaming\Microsoft\Windows\Cookies\system@www.gossipcenter[2].txt
!-->[Hidden] C:\Windows\System32\config\systemprofile\AppData\Roaming\Microsoft\Windows\Cookies\system@www.gossipcenter[3].txt
!-->[Hidden] C:\Windows\System32\config\systemprofile\AppData\Roaming\Microsoft\Windows\Cookies\system@www.gossipcenter[4].txt
!-->[Hidden] C:\Windows\System32\config\systemprofile\AppData\Roaming\Microsoft\Windows\Cookies\system@www.pkr[2].txt
!-->[Hidden] C:\Windows\System32\config\systemprofile\AppData\Roaming\Microsoft\Windows\Cookies\system@www.pkr[3].txt
!-->[Hidden] C:\Windows\System32\config\systemprofile\AppData\Roaming\Microsoft\Windows\Cookies\system@www.shop-com.co[1].txt
!-->[Hidden] C:\Windows\System32\config\systemprofile\AppData\Roaming\Microsoft\Windows\Cookies\system@www.spanair[2].txt
!-->[Hidden] C:\Windows\System32\config\systemprofile\AppData\Roaming\Microsoft\Windows\Cookies\system@www.utarget.co[1].txt
!-->[Hidden] C:\Windows\System32\config\systemprofile\AppData\Roaming\Microsoft\Windows\Cookies\system@www.velvettissue[1].txt
!-->[Hidden] C:\Windows\System32\config\systemprofile\AppData\Roaming\Microsoft\Windows\Cookies\system@www2.barkingpages.co[1].txt
!-->[Hidden] C:\Windows\System32\config\systemprofile\AppData\Roaming\Microsoft\Windows\Cookies\system@www2.shopodo.co[1].txt
!-->[Hidden] C:\Windows\System32\config\systemprofile\AppData\Roaming\Microsoft\Windows\Cookies\system@www2.shopodo.co[2].txt
!-->[Hidden] C:\Windows\System32\config\systemprofile\AppData\Roaming\Microsoft\Windows\Cookies\system@wwwadcntr[1].txt
!-->[Hidden] C:\Windows\System32\config\systemprofile\AppData\Roaming\Microsoft\Windows\Cookies\system@wwwadcntr[2].txt
!-->[Hidden] C:\Windows\System32\config\systemprofile\AppData\Roaming\Microsoft\Windows\Cookies\system@wwwadcntr[3].txt
!-->[Hidden] C:\Windows\System32\config\systemprofile\AppData\Roaming\Microsoft\Windows\Cookies\system@wwwadcntr[4].txt
!-->[Hidden] C:\Windows\System32\config\systemprofile\AppData\Roaming\Microsoft\Windows\Cookies\system@xml.admanage[1].txt
!-->[Hidden] C:\Windows\System32\config\systemprofile\AppData\Roaming\Microsoft\Windows\Cookies\system@yahoo[1].txt
!-->[Hidden] C:\Windows\System32\config\systemprofile\AppData\Roaming\Microsoft\Windows\Cookies\system@yieldmanager[1].txt
!-->[Hidden] C:\Windows\System32\config\systemprofile\AppData\Roaming\Microsoft\Windows\Cookies\system@youtube[1].txt
!-->[Hidden] C:\Windows\System32\config\systemprofile\AppData\Roaming\Microsoft\Windows\Cookies\system@youtube[2].txt
!-->[Hidden] C:\Windows\System32\config\systemprofile\AppData\Roaming\Microsoft\Windows\Cookies\system@youtube[3].txt
!-->[Hidden] C:\Windows\System32\config\systemprofile\AppData\Roaming\Microsoft\Windows\Cookies\system@youtube[4].txt
!-->[Hidden] C:\Windows\System32\config\systemprofile\AppData\Roaming\Microsoft\Windows\Cookies\system@yumenetworks[1].txt
!-->[Hidden] C:\Windows\System32\config\systemprofile\AppData\Roaming\Microsoft\Windows\IETldCache\index.dat
!-->[Hidden] C:\Windows\System32\config\systemprofile\AppData\Roaming\Microsoft\Windows\Network Shortcuts\desktop.ini
!-->[Hidden] C:\Windows\System32\config\systemprofile\AppData\Roaming\Microsoft\Windows\Printer Shortcuts\desktop.ini
!-->[Hidden] C:\Windows\System32\config\systemprofile\AppData\Roaming\Microsoft\Windows\Recent\desktop.ini
!-->[Hidden] C:\Windows\System32\config\systemprofile\AppData\Roaming\Microsoft\Windows\SendTo\desktop.ini
!-->[Hidden] C:\Windows\System32\config\systemprofile\AppData\Roaming\Microsoft\Windows\Start Menu\desktop.ini
!-->[Hidden] C:\Windows\System32\config\systemprofile\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Administrative Tools\desktop.ini
!-->[Hidden] C:\Windows\System32\config\systemprofile\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\desktop.ini
!-->[Hidden] C:\Windows\System32\config\systemprofile\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\desktop.ini
!-->[Hidden] C:\Windows\System32\config\systemprofile\AppData\Roaming\Microsoft\Windows\Templates\2w8Pf0CAB6ms
!-->[Hidden] C:\Windows\System32\config\systemprofile\AppData\Roaming\Microsoft\Windows\Templates\desktop.ini
!-->[Hidden] C:\Windows\System32\config\systemprofile\AppData\Roaming\Microsoft\Windows\Templates\K5OjaYgo0v
!-->[Hidden] C:\Windows\System32\config\systemprofile\AppData\Roaming\PC Suite\Settings\PCCSConfig.dat
!-->[Hidden] C:\Windows\System32\config\systemprofile\Contacts\desktop.ini
!-->[Hidden] C:\Windows\System32\config\systemprofile\Desktop\desktop.ini
!-->[Hidden] C:\Windows\System32\config\systemprofile\Documents\desktop.ini
!-->[Hidden] C:\Windows\System32\config\systemprofile\Downloads\desktop.ini
!-->[Hidden] C:\Windows\System32\config\systemprofile\Favorites\desktop.ini
!-->[Hidden] C:\Windows\System32\config\systemprofile\Links\desktop.ini
!-->[Hidden] C:\Windows\System32\config\systemprofile\Music\desktop.ini
!-->[Hidden] C:\Windows\System32\config\systemprofile\Music\Playlists\desktop.ini
!-->[Hidden] C:\Windows\System32\config\systemprofile\Music\Sample Music.lnk
!-->[Hidden] C:\Windows\System32\config\systemprofile\ntuser.dat
!-->[Hidden] C:\Windows\System32\config\systemprofile\ntuser.dat.LOG
!-->[Hidden] C:\Windows\System32\config\systemprofile\ntuser.dat.LOG1
!-->[Hidden] C:\Windows\System32\config\systemprofile\ntuser.dat.LOG2
!-->[Hidden] C:\Windows\System32\config\systemprofile\ntuser.dat{c92be680-c7c0-11dc-8ff1-806e6f6e6963}.TM.blf
!-->[Hidden] C:\Windows\System32\config\systemprofile\ntuser.dat{c92be680-c7c0-11dc-8ff1-806e6f6e6963}.TMContainer00000000000000000001.regtrans-ms
!-->[Hidden] C:\Windows\System32\config\systemprofile\ntuser.dat{c92be680-c7c0-11dc-8ff1-806e6f6e6963}.TMContainer00000000000000000002.regtrans-ms
!-->[Hidden] C:\Windows\System32\config\systemprofile\Pictures\desktop.ini
!-->[Hidden] C:\Windows\System32\config\systemprofile\Pictures\Sample Pictures.lnk
!-->[Hidden] C:\Windows\System32\config\systemprofile\Pictures\Slide Shows\desktop.ini
!-->[Hidden] C:\Windows\System32\config\systemprofile\Saved Games\desktop.ini
!-->[Hidden] C:\Windows\System32\config\systemprofile\Searches\desktop.ini
!-->[Hidden] C:\Windows\System32\config\systemprofile\Videos\desktop.ini
!-->[Hidden] C:\Windows\System32\config\systemprofile\Videos\Sample Videos.lnk
!-->[Hidden] C:\Windows\System32\config\TxR\{250834b7-750c-494d-bdc3-da86b6e2101a}.TxR.0.regtrans-ms
!-->[Hidden] C:\Windows\System32\config\TxR\{250834b7-750c-494d-bdc3-da86b6e2101a}.TxR.1.regtrans-ms
!-->[Hidden] C:\Windows\System32\config\TxR\{250834b7-750c-494d-bdc3-da86b6e2101a}.TxR.2.regtrans-ms
!-->[Hidden] C:\Windows\System32\config\TxR\{250834B7-750C-494d-BDC3-DA86B6E2101A}.TxR.3.regtrans-ms
!-->[Hidden] C:\Windows\System32\config\TxR\{250834b7-750c-494d-bdc3-da86b6e2101a}.TxR.blf
!-->[Hidden] C:\Windows\System32\config\TxR\{250834B7-750C-494d-BDC3-DA86B6E2101B}.TM.blf
!-->[Hidden] C:\Windows\System32\config\TxR\{250834B7-750C-494d-BDC3-DA86B6E2101B}.TMContainer00000000000000000001.regtrans-ms
!-->[Hidden] C:\Windows\System32\config\TxR\{250834B7-750C-494d-BDC3-DA86B6E2101B}.TMContainer00000000000000000002.regtrans-ms
==============================================
magic
Regular Member
 
Posts: 28
Joined: June 8th, 2010, 5:36 pm

Re: Alureon H removal

Unread postby magic » June 27th, 2010, 6:46 pm

>Hooks
==============================================
ntkrnlpa.exe+0x000A87AA, Type: Inline - RelativeJump 0x81EDF7AA-->81EDF7B1 [ntkrnlpa.exe]
ntkrnlpa.exe+0x000AC934, Type: Inline - RelativeCall 0x81EE3934-->888EE6B9 [unknown_code_page]
ntkrnlpa.exe+0x000ACD40, Type: Inline - PushRet 0x81EE3D40-->A18EE6B4 [unknown_code_page]
[1464]Photoshop.exe-->advapi32.dll-->kernel32.dll-->GetProcAddress, Type: IAT modification 0x77C814BC-->00000000 [shimeng.dll]
[1464]Photoshop.exe-->advapi32.dll-->RegCloseKey, Type: IAT modification 0x00F6B030-->00000000 [AcLayers.dll]
[1464]Photoshop.exe-->advapi32.dll-->RegCreateKeyExA, Type: IAT modification 0x00F6B014-->00000000 [AcLayers.dll]
[1464]Photoshop.exe-->advapi32.dll-->RegDeleteKeyA, Type: IAT modification 0x00F6B010-->00000000 [AcLayers.dll]
[1464]Photoshop.exe-->advapi32.dll-->RegEnumValueA, Type: IAT modification 0x00F6B00C-->00000000 [AcLayers.dll]
[1464]Photoshop.exe-->advapi32.dll-->RegOpenKeyA, Type: IAT modification 0x00F6B01C-->00000000 [AcLayers.dll]
[1464]Photoshop.exe-->advapi32.dll-->RegOpenKeyExA, Type: IAT modification 0x00F6B028-->00000000 [AcLayers.dll]
[1464]Photoshop.exe-->advapi32.dll-->RegQueryValueExA, Type: IAT modification 0x00F6B03C-->00000000 [AcLayers.dll]
[1464]Photoshop.exe-->advapi32.dll-->RegSetValueExA, Type: IAT modification 0x00F6B02C-->00000000 [AcLayers.dll]
[1464]Photoshop.exe-->gdi32.dll-->kernel32.dll-->GetProcAddress, Type: IAT modification 0x77B61170-->00000000 [shimeng.dll]
[1464]Photoshop.exe-->kernel32.dll-->CreateProcessA, Type: IAT modification 0x00F6B3A8-->00000000 [AcGenral.dll]
[1464]Photoshop.exe-->kernel32.dll-->GetProcAddress, Type: IAT modification 0x00F6B32C-->00000000 [shimeng.dll]
[1464]Photoshop.exe-->kernel32.dll-->LoadLibraryExW, Type: Inline - DirectJump 0x76839109-->00000000 [unknown_code_page]
[1464]Photoshop.exe-->shell32.dll-->kernel32.dll-->GetProcAddress, Type: IAT modification 0x768E1414-->00000000 [shimeng.dll]
[1464]Photoshop.exe-->user32.dll-->kernel32.dll-->GetProcAddress, Type: IAT modification 0x77D51300-->00000000 [shimeng.dll]
[1464]Photoshop.exe-->ws2_32.dll-->accept, Type: Inline - DirectJump 0x762FBDF6-->00000000 [unknown_code_page]
[1464]Photoshop.exe-->ws2_32.dll-->closesocket, Type: Inline - DirectJump 0x762E330C-->00000000 [unknown_code_page]
[1464]Photoshop.exe-->ws2_32.dll-->connect, Type: Inline - DirectJump 0x762E40D9-->00000000 [unknown_code_page]
[1464]Photoshop.exe-->ws2_32.dll-->htons, Type: Inline - DirectJump 0x762E3010-->00000000 [unknown_code_page]
[1464]Photoshop.exe-->ws2_32.dll-->kernel32.dll-->GetProcAddress, Type: IAT modification 0x4B0D11E8-->00000000 [shimeng.dll]
[1464]Photoshop.exe-->ws2_32.dll-->WSAAccept, Type: Inline - DirectJump 0x762FBB56-->00000000 [unknown_code_page]
[1464]Photoshop.exe-->ws2_32.dll-->WSAAsyncSelect, Type: Inline - DirectJump 0x762FA17C-->00000000 [unknown_code_page]
[1464]Photoshop.exe-->ws2_32.dll-->WSAConnect, Type: Inline - DirectJump 0x762ED7B0-->00000000 [unknown_code_page]
[1464]Photoshop.exe-->ws2_32.dll-->WSAEventSelect, Type: Inline - DirectJump 0x762E5BFA-->00000000 [unknown_code_page]
[1516]taskeng.exe-->kernel32.dll-->LoadLibraryExW, Type: Inline - DirectJump 0x76839109-->00000000 [unknown_code_page]
[1516]taskeng.exe-->ws2_32.dll-->accept, Type: Inline - DirectJump 0x762FBDF6-->00000000 [unknown_code_page]
[1516]taskeng.exe-->ws2_32.dll-->closesocket, Type: Inline - DirectJump 0x762E330C-->00000000 [unknown_code_page]
[1516]taskeng.exe-->ws2_32.dll-->connect, Type: Inline - DirectJump 0x762E40D9-->00000000 [unknown_code_page]
[1516]taskeng.exe-->ws2_32.dll-->htons, Type: Inline - DirectJump 0x762E3010-->00000000 [unknown_code_page]
[1516]taskeng.exe-->ws2_32.dll-->WSAAccept, Type: Inline - DirectJump 0x762FBB56-->00000000 [unknown_code_page]
[1516]taskeng.exe-->ws2_32.dll-->WSAAsyncSelect, Type: Inline - DirectJump 0x762FA17C-->00000000 [unknown_code_page]
[1516]taskeng.exe-->ws2_32.dll-->WSAConnect, Type: Inline - DirectJump 0x762ED7B0-->00000000 [unknown_code_page]
[1516]taskeng.exe-->ws2_32.dll-->WSAEventSelect, Type: Inline - DirectJump 0x762E5BFA-->00000000 [unknown_code_page]
[1756]dwm.exe-->kernel32.dll-->LoadLibraryExW, Type: Inline - DirectJump 0x76839109-->00000000 [unknown_code_page]
[1756]dwm.exe-->ws2_32.dll-->accept, Type: Inline - DirectJump 0x762FBDF6-->00000000 [unknown_code_page]
[1756]dwm.exe-->ws2_32.dll-->closesocket, Type: Inline - DirectJump 0x762E330C-->00000000 [unknown_code_page]
[1756]dwm.exe-->ws2_32.dll-->connect, Type: Inline - DirectJump 0x762E40D9-->00000000 [unknown_code_page]
[1756]dwm.exe-->ws2_32.dll-->htons, Type: Inline - DirectJump 0x762E3010-->00000000 [unknown_code_page]
[1756]dwm.exe-->ws2_32.dll-->WSAAccept, Type: Inline - DirectJump 0x762FBB56-->00000000 [unknown_code_page]
[1756]dwm.exe-->ws2_32.dll-->WSAAsyncSelect, Type: Inline - DirectJump 0x762FA17C-->00000000 [unknown_code_page]
[1756]dwm.exe-->ws2_32.dll-->WSAConnect, Type: Inline - DirectJump 0x762ED7B0-->00000000 [unknown_code_page]
[1756]dwm.exe-->ws2_32.dll-->WSAEventSelect, Type: Inline - DirectJump 0x762E5BFA-->00000000 [unknown_code_page]
[1788]explorer.exe-->kernel32.dll-->ntdll.dll-->NtClose, Type: IAT modification 0x77DF1050-->00000000 [LVPrcInj01.dll]
[1788]explorer.exe-->kernel32.dll-->ntdll.dll-->NtCreateFile, Type: IAT modification 0x77DF1018-->00000000 [LVPrcInj01.dll]
[1788]explorer.exe-->kernel32.dll-->ntdll.dll-->NtDeviceIoControlFile, Type: IAT modification 0x77DF1054-->00000000 [LVPrcInj01.dll]
[1788]explorer.exe-->kernel32.dll-->ntdll.dll-->NtDuplicateObject, Type: IAT modification 0x77DF1354-->00000000 [LVPrcInj01.dll]
[2604]rundll32.exe-->advapi32.dll-->kernel32.dll-->GetProcAddress, Type: IAT modification 0x77C814BC-->00000000 [shimeng.dll]
[2604]rundll32.exe-->gdi32.dll-->kernel32.dll-->GetProcAddress, Type: IAT modification 0x77B61170-->00000000 [shimeng.dll]
[2604]rundll32.exe-->shell32.dll-->kernel32.dll-->GetProcAddress, Type: IAT modification 0x768E1414-->00000000 [shimeng.dll]
[2604]rundll32.exe-->user32.dll-->kernel32.dll-->GetProcAddress, Type: IAT modification 0x77D51300-->00000000 [shimeng.dll]
[2660]unsecapp.exe-->kernel32.dll-->LoadLibraryExW, Type: Inline - DirectJump 0x76839109-->00000000 [unknown_code_page]
[2660]unsecapp.exe-->ws2_32.dll-->accept, Type: Inline - DirectJump 0x762FBDF6-->00000000 [unknown_code_page]
[2660]unsecapp.exe-->ws2_32.dll-->closesocket, Type: Inline - DirectJump 0x762E330C-->00000000 [unknown_code_page]
[2660]unsecapp.exe-->ws2_32.dll-->connect, Type: Inline - DirectJump 0x762E40D9-->00000000 [unknown_code_page]
[2660]unsecapp.exe-->ws2_32.dll-->htons, Type: Inline - DirectJump 0x762E3010-->00000000 [unknown_code_page]
[2660]unsecapp.exe-->ws2_32.dll-->WSAAccept, Type: Inline - DirectJump 0x762FBB56-->00000000 [unknown_code_page]
[2660]unsecapp.exe-->ws2_32.dll-->WSAAsyncSelect, Type: Inline - DirectJump 0x762FA17C-->00000000 [unknown_code_page]
[2660]unsecapp.exe-->ws2_32.dll-->WSAConnect, Type: Inline - DirectJump 0x762ED7B0-->00000000 [unknown_code_page]
[2660]unsecapp.exe-->ws2_32.dll-->WSAEventSelect, Type: Inline - DirectJump 0x762E5BFA-->00000000 [unknown_code_page]
[2996]iexplore.exe-->advapi32.dll-->kernel32.dll-->GetProcAddress, Type: IAT modification 0x77C814BC-->00000000 [IEShims.dll]
[2996]iexplore.exe-->gdi32.dll-->kernel32.dll-->CopyFileW, Type: IAT modification 0x77B61130-->00000000 [IEShims.dll]
[2996]iexplore.exe-->gdi32.dll-->kernel32.dll-->CreateFileW, Type: IAT modification 0x77B6119C-->00000000 [IEShims.dll]
[2996]iexplore.exe-->gdi32.dll-->kernel32.dll-->DeleteFileW, Type: IAT modification 0x77B611BC-->00000000 [IEShims.dll]
[2996]iexplore.exe-->gdi32.dll-->kernel32.dll-->GetProcAddress, Type: IAT modification 0x77B61170-->00000000 [IEShims.dll]
[2996]iexplore.exe-->gdi32.dll-->kernel32.dll-->LoadLibraryA, Type: IAT modification 0x77B6111C-->00000000 [IEShims.dll]
[2996]iexplore.exe-->gdi32.dll-->kernel32.dll-->LoadLibraryExW, Type: IAT modification 0x77B61110-->00000000 [IEShims.dll]
[2996]iexplore.exe-->gdi32.dll-->kernel32.dll-->LoadLibraryW, Type: IAT modification 0x77B61174-->00000000 [IEShims.dll]
[2996]iexplore.exe-->gdi32.dll-->kernel32.dll-->SearchPathW, Type: IAT modification 0x77B611AC-->00000000 [IEShims.dll]
[2996]iexplore.exe-->mswsock.dll-->kernel32.dll-->GetProcAddress, Type: IAT modification 0x6D64123C-->00000000 [IEShims.dll]
[2996]iexplore.exe-->shell32.dll-->kernel32.dll-->CopyFileW, Type: IAT modification 0x768E125C-->00000000 [IEShims.dll]
[2996]iexplore.exe-->shell32.dll-->kernel32.dll-->CreateDirectoryW, Type: IAT modification 0x768E13B0-->00000000 [IEShims.dll]
[2996]iexplore.exe-->shell32.dll-->kernel32.dll-->CreateFileW, Type: IAT modification 0x768E1460-->00000000 [IEShims.dll]
[2996]iexplore.exe-->shell32.dll-->kernel32.dll-->CreateHardLinkW, Type: IAT modification 0x768E11A4-->00000000 [IEShims.dll]
[2996]iexplore.exe-->shell32.dll-->kernel32.dll-->CreateProcessW, Type: IAT modification 0x768E12E8-->00000000 [IEShims.dll]
[2996]iexplore.exe-->shell32.dll-->kernel32.dll-->DeleteFileW, Type: IAT modification 0x768E13B4-->00000000 [IEShims.dll]
[2996]iexplore.exe-->shell32.dll-->kernel32.dll-->FindClose, Type: IAT modification 0x768E132C-->00000000 [IEShims.dll]
[2996]iexplore.exe-->shell32.dll-->kernel32.dll-->FindFirstFileW, Type: IAT modification 0x768E1328-->00000000 [IEShims.dll]
[2996]iexplore.exe-->shell32.dll-->kernel32.dll-->FindNextFileW, Type: IAT modification 0x768E1114-->00000000 [IEShims.dll]
[2996]iexplore.exe-->shell32.dll-->kernel32.dll-->GetBinaryTypeW, Type: IAT modification 0x768E1280-->00000000 [IEShims.dll]
[2996]iexplore.exe-->shell32.dll-->kernel32.dll-->GetFileAttributesA, Type: IAT modification 0x768E1370-->00000000 [IEShims.dll]
[2996]iexplore.exe-->shell32.dll-->kernel32.dll-->GetFileAttributesExW, Type: IAT modification 0x768E14A4-->00000000 [IEShims.dll]
[2996]iexplore.exe-->shell32.dll-->kernel32.dll-->GetFileAttributesW, Type: IAT modification 0x768E13BC-->00000000 [IEShims.dll]
[2996]iexplore.exe-->shell32.dll-->kernel32.dll-->GetLongPathNameW, Type: IAT modification 0x768E14EC-->00000000 [IEShims.dll]
[2996]iexplore.exe-->shell32.dll-->kernel32.dll-->GetPrivateProfileIntW, Type: IAT modification 0x768E1390-->00000000 [IEShims.dll]
[2996]iexplore.exe-->shell32.dll-->kernel32.dll-->GetPrivateProfileSectionNamesW, Type: IAT modification 0x768E1164-->00000000 [IEShims.dll]
[2996]iexplore.exe-->shell32.dll-->kernel32.dll-->GetPrivateProfileSectionW, Type: IAT modification 0x768E1100-->00000000 [IEShims.dll]
[2996]iexplore.exe-->shell32.dll-->kernel32.dll-->GetPrivateProfileStringW, Type: IAT modification 0x768E13A0-->00000000 [IEShims.dll]
[2996]iexplore.exe-->shell32.dll-->kernel32.dll-->GetShortPathNameA, Type: IAT modification 0x768E136C-->00000000 [IEShims.dll]
[2996]iexplore.exe-->shell32.dll-->kernel32.dll-->GetShortPathNameW, Type: IAT modification 0x768E1428-->00000000 [IEShims.dll]
[2996]iexplore.exe-->shell32.dll-->kernel32.dll-->LoadLibraryA, Type: IAT modification 0x768E14E0-->00000000 [IEShims.dll]
[2996]iexplore.exe-->shell32.dll-->kernel32.dll-->LoadLibraryExW, Type: IAT modification 0x768E1284-->00000000 [IEShims.dll]
[2996]iexplore.exe-->shell32.dll-->kernel32.dll-->LoadLibraryW, Type: IAT modification 0x768E1448-->00000000 [IEShims.dll]
[2996]iexplore.exe-->shell32.dll-->kernel32.dll-->MoveFileExW, Type: IAT modification 0x768E13C0-->00000000 [IEShims.dll]
[2996]iexplore.exe-->shell32.dll-->kernel32.dll-->MoveFileW, Type: IAT modification 0x768E130C-->00000000 [IEShims.dll]
[2996]iexplore.exe-->shell32.dll-->kernel32.dll-->RemoveDirectoryW, Type: IAT modification 0x768E13AC-->00000000 [IEShims.dll]
[2996]iexplore.exe-->shell32.dll-->kernel32.dll-->ReplaceFileW, Type: IAT modification 0x768E1140-->00000000 [IEShims.dll]
[2996]iexplore.exe-->shell32.dll-->kernel32.dll-->SearchPathW, Type: IAT modification 0x768E1384-->00000000 [IEShims.dll]
[2996]iexplore.exe-->shell32.dll-->kernel32.dll-->SetCurrentDirectoryW, Type: IAT modification 0x768E124C-->00000000 [IEShims.dll]
[2996]iexplore.exe-->shell32.dll-->kernel32.dll-->SetFileAttributesW, Type: IAT modification 0x768E13B8-->00000000 [IEShims.dll]
[2996]iexplore.exe-->shell32.dll-->kernel32.dll-->WritePrivateProfileSectionW, Type: IAT modification 0x768E1168-->00000000 [IEShims.dll]
[2996]iexplore.exe-->shell32.dll-->kernel32.dll-->WritePrivateProfileStringW, Type: IAT modification 0x768E116C-->00000000 [IEShims.dll]
[2996]iexplore.exe-->shell32.dll-->ntdll.dll-->NtQueryDirectoryFile, Type: IAT modification 0x768E2320-->00000000 [IEShims.dll]
[2996]iexplore.exe-->shell32.dll-->user32.dll-->LoadImageW, Type: IAT modification 0x768E1890-->00000000 [IEShims.dll]
[2996]iexplore.exe-->shell32.dll-->user32.dll-->PrivateExtractIconsW, Type: IAT modification 0x768E1A6C-->00000000 [IEShims.dll]
[2996]iexplore.exe-->shell32.dll-->user32.dll-->WinHelpW, Type: IAT modification 0x768E191C-->00000000 [IEShims.dll]
[2996]iexplore.exe-->user32.dll-->advapi32.dll-->RegCloseKey, Type: IAT modification 0x77D5154C-->00000000 [IEShims.dll]
[2996]iexplore.exe-->user32.dll-->advapi32.dll-->RegCreateKeyExW, Type: IAT modification 0x77D51548-->00000000 [IEShims.dll]
[2996]iexplore.exe-->user32.dll-->advapi32.dll-->RegDeleteKeyW, Type: IAT modification 0x77D51544-->00000000 [IEShims.dll]
[2996]iexplore.exe-->user32.dll-->advapi32.dll-->RegEnumValueW, Type: IAT modification 0x77D51524-->00000000 [IEShims.dll]
[2996]iexplore.exe-->user32.dll-->advapi32.dll-->RegOpenKeyExW, Type: IAT modification 0x77D51528-->00000000 [IEShims.dll]
[2996]iexplore.exe-->user32.dll-->advapi32.dll-->RegQueryInfoKeyW, Type: IAT modification 0x77D51520-->00000000 [IEShims.dll]
[2996]iexplore.exe-->user32.dll-->advapi32.dll-->RegQueryValueExW, Type: IAT modification 0x77D5152C-->00000000 [IEShims.dll]
[2996]iexplore.exe-->user32.dll-->CallNextHookEx, Type: Inline - RelativeJump 0x775A8E3B-->00000000 [ieframe.dll]
[2996]iexplore.exe-->user32.dll-->CreateDialogIndirectParamA, Type: Inline - RelativeJump 0x775C26F1-->00000000 [ieframe.dll]
[2996]iexplore.exe-->user32.dll-->CreateDialogIndirectParamW, Type: Inline - RelativeJump 0x775C9A62-->00000000 [ieframe.dll]
[2996]iexplore.exe-->user32.dll-->CreateDialogParamA, Type: Inline - RelativeJump 0x775C17AA-->00000000 [ieframe.dll]
[2996]iexplore.exe-->user32.dll-->CreateDialogParamW, Type: Inline - RelativeJump 0x775A72A2-->00000000 [ieframe.dll]
[2996]iexplore.exe-->user32.dll-->CreateWindowExW, Type: Inline - RelativeJump 0x775B1305-->00000000 [ieframe.dll]
[2996]iexplore.exe-->user32.dll-->DialogBoxIndirectParamA, Type: Inline - RelativeJump 0x775E847D-->00000000 [ieframe.dll]
[2996]iexplore.exe-->user32.dll-->DialogBoxIndirectParamW, Type: Inline - RelativeJump 0x775D2EF5-->00000000 [ieframe.dll]
[2996]iexplore.exe-->user32.dll-->DialogBoxParamA, Type: Inline - RelativeJump 0x775E8152-->00000000 [ieframe.dll]
[2996]iexplore.exe-->user32.dll-->DialogBoxParamW, Type: Inline - RelativeJump 0x775D10B0-->00000000 [ieframe.dll]
[2996]iexplore.exe-->user32.dll-->EnableWindow, Type: Inline - RelativeJump 0x775ACD8B-->00000000 [ieframe.dll]
[2996]iexplore.exe-->user32.dll-->EndDialog, Type: Inline - RelativeJump 0x775D326E-->00000000 [ieframe.dll]
[2996]iexplore.exe-->user32.dll-->GetAsyncKeyState, Type: Inline - RelativeJump 0x775A863C-->00000000 [ieframe.dll]
[2996]iexplore.exe-->user32.dll-->GetKeyState, Type: Inline - RelativeJump 0x775B8CB1-->00000000 [ieframe.dll]
[2996]iexplore.exe-->user32.dll-->IsDialogMessage, Type: Inline - RelativeJump 0x775C1847-->00000000 [ieframe.dll]
[2996]iexplore.exe-->user32.dll-->IsDialogMessageW, Type: Inline - RelativeJump 0x775C0745-->00000000 [ieframe.dll]
[2996]iexplore.exe-->user32.dll-->kernel32.dll-->CopyFileW, Type: IAT modification 0x77D511A8-->00000000 [IEShims.dll]
[2996]iexplore.exe-->user32.dll-->kernel32.dll-->CreateFileW, Type: IAT modification 0x77D512B8-->00000000 [IEShims.dll]
[2996]iexplore.exe-->user32.dll-->kernel32.dll-->CreateProcessW, Type: IAT modification 0x77D511B4-->00000000 [IEShims.dll]
[2996]iexplore.exe-->user32.dll-->kernel32.dll-->DeleteFileW, Type: IAT modification 0x77D511B0-->00000000 [IEShims.dll]
[2996]iexplore.exe-->user32.dll-->kernel32.dll-->FindClose, Type: IAT modification 0x77D511E4-->00000000 [IEShims.dll]
[2996]iexplore.exe-->user32.dll-->kernel32.dll-->FindFirstFileW, Type: IAT modification 0x77D511EC-->00000000 [IEShims.dll]
[2996]iexplore.exe-->user32.dll-->kernel32.dll-->FindNextFileW, Type: IAT modification 0x77D511E8-->00000000 [IEShims.dll]
[2996]iexplore.exe-->user32.dll-->kernel32.dll-->GetPrivateProfileStringW, Type: IAT modification 0x77D51328-->00000000 [IEShims.dll]
[2996]iexplore.exe-->user32.dll-->kernel32.dll-->GetProcAddress, Type: IAT modification 0x77D51300-->00000000 [IEShims.dll]
[2996]iexplore.exe-->user32.dll-->kernel32.dll-->LoadLibraryA, Type: IAT modification 0x77D51250-->00000000 [IEShims.dll]
[2996]iexplore.exe-->user32.dll-->kernel32.dll-->LoadLibraryExW, Type: IAT modification 0x77D5115C-->00000000 [IEShims.dll]
[2996]iexplore.exe-->user32.dll-->kernel32.dll-->LoadLibraryW, Type: IAT modification 0x77D512FC-->00000000 [IEShims.dll]
[2996]iexplore.exe-->user32.dll-->kernel32.dll-->MoveFileW, Type: IAT modification 0x77D511AC-->00000000 [IEShims.dll]
[2996]iexplore.exe-->user32.dll-->kernel32.dll-->SearchPathW, Type: IAT modification 0x77D51154-->00000000 [IEShims.dll]
[2996]iexplore.exe-->user32.dll-->kernel32.dll-->SetCurrentDirectoryW, Type: IAT modification 0x77D511D8-->00000000 [IEShims.dll]
[2996]iexplore.exe-->user32.dll-->kernel32.dll-->WritePrivateProfileStringW, Type: IAT modification 0x77D512BC-->00000000 [IEShims.dll]
[2996]iexplore.exe-->user32.dll-->keybd_event, Type: Inline - RelativeJump 0x775FD972-->00000000 [ieframe.dll]
[2996]iexplore.exe-->user32.dll-->MessageBoxExA, Type: Inline - RelativeJump 0x775FD639-->00000000 [ieframe.dll]
[2996]iexplore.exe-->user32.dll-->MessageBoxExW, Type: Inline - RelativeJump 0x775FD65D-->00000000 [ieframe.dll]
[2996]iexplore.exe-->user32.dll-->MessageBoxIndirectA, Type: Inline - RelativeJump 0x775FD4D9-->00000000 [ieframe.dll]
[2996]iexplore.exe-->user32.dll-->MessageBoxIndirectW, Type: Inline - RelativeJump 0x775FD5D3-->00000000 [ieframe.dll]
[2996]iexplore.exe-->user32.dll-->SendInput, Type: Inline - RelativeJump 0x775D2F75-->00000000 [ieframe.dll]
[2996]iexplore.exe-->user32.dll-->SetCursorPos, Type: Inline - RelativeJump 0x775E6FB2-->00000000 [ieframe.dll]
[2996]iexplore.exe-->user32.dll-->SetKeyboardState, Type: Inline - RelativeJump 0x775D0987-->00000000 [ieframe.dll]
[2996]iexplore.exe-->user32.dll-->SetWindowsHookExW, Type: Inline - RelativeJump 0x775A87AD-->00000000 [ieframe.dll]
[2996]iexplore.exe-->user32.dll-->UnhookWindowsHookEx, Type: Inline - RelativeJump 0x775A98DB-->00000000 [ieframe.dll]
[2996]iexplore.exe-->wininet.dll-->kernel32.dll-->GetProcAddress, Type: IAT modification 0x704114B0-->00000000 [IEShims.dll]
[2996]iexplore.exe-->ws2_32.dll-->kernel32.dll-->GetProcAddress, Type: IAT modification 0x4B0D11E8-->00000000 [IEShims.dll]
[3584]MSASCui.exe-->kernel32.dll-->LoadLibraryExW, Type: Inline - DirectJump 0x76839109-->00000000 [unknown_code_page]
[3584]MSASCui.exe-->ws2_32.dll-->accept, Type: Inline - DirectJump 0x762FBDF6-->00000000 [unknown_code_page]
[3584]MSASCui.exe-->ws2_32.dll-->closesocket, Type: Inline - DirectJump 0x762E330C-->00000000 [unknown_code_page]
[3584]MSASCui.exe-->ws2_32.dll-->connect, Type: Inline - DirectJump 0x762E40D9-->00000000 [unknown_code_page]
[3584]MSASCui.exe-->ws2_32.dll-->htons, Type: Inline - DirectJump 0x762E3010-->00000000 [unknown_code_page]
[3584]MSASCui.exe-->ws2_32.dll-->WSAAccept, Type: Inline - DirectJump 0x762FBB56-->00000000 [unknown_code_page]
[3584]MSASCui.exe-->ws2_32.dll-->WSAAsyncSelect, Type: Inline - DirectJump 0x762FA17C-->00000000 [unknown_code_page]
[3584]MSASCui.exe-->ws2_32.dll-->WSAConnect, Type: Inline - DirectJump 0x762ED7B0-->00000000 [unknown_code_page]
[3584]MSASCui.exe-->ws2_32.dll-->WSAEventSelect, Type: Inline - DirectJump 0x762E5BFA-->00000000 [unknown_code_page]
[3596]igfxtray.exe-->kernel32.dll-->LoadLibraryExW, Type: Inline - DirectJump 0x76839109-->00000000 [unknown_code_page]
[3596]igfxtray.exe-->ws2_32.dll-->accept, Type: Inline - DirectJump 0x762FBDF6-->00000000 [unknown_code_page]
[3596]igfxtray.exe-->ws2_32.dll-->closesocket, Type: Inline - DirectJump 0x762E330C-->00000000 [unknown_code_page]
[3596]igfxtray.exe-->ws2_32.dll-->connect, Type: Inline - DirectJump 0x762E40D9-->00000000 [unknown_code_page]
[3596]igfxtray.exe-->ws2_32.dll-->htons, Type: Inline - DirectJump 0x762E3010-->00000000 [unknown_code_page]
[3596]igfxtray.exe-->ws2_32.dll-->WSAAccept, Type: Inline - DirectJump 0x762FBB56-->00000000 [unknown_code_page]
[3596]igfxtray.exe-->ws2_32.dll-->WSAAsyncSelect, Type: Inline - DirectJump 0x762FA17C-->00000000 [unknown_code_page]
[3596]igfxtray.exe-->ws2_32.dll-->WSAConnect, Type: Inline - DirectJump 0x762ED7B0-->00000000 [unknown_code_page]
[3596]igfxtray.exe-->ws2_32.dll-->WSAEventSelect, Type: Inline - DirectJump 0x762E5BFA-->00000000 [unknown_code_page]
[3624]hkcmd.exe-->kernel32.dll-->LoadLibraryExW, Type: Inline - DirectJump 0x76839109-->00000000 [unknown_code_page]
[3624]hkcmd.exe-->ws2_32.dll-->accept, Type: Inline - DirectJump 0x762FBDF6-->00000000 [unknown_code_page]
[3624]hkcmd.exe-->ws2_32.dll-->closesocket, Type: Inline - DirectJump 0x762E330C-->00000000 [unknown_code_page]
[3624]hkcmd.exe-->ws2_32.dll-->connect, Type: Inline - DirectJump 0x762E40D9-->00000000 [unknown_code_page]
[3624]hkcmd.exe-->ws2_32.dll-->htons, Type: Inline - DirectJump 0x762E3010-->00000000 [unknown_code_page]
[3624]hkcmd.exe-->ws2_32.dll-->WSAAccept, Type: Inline - DirectJump 0x762FBB56-->00000000 [unknown_code_page]
[3624]hkcmd.exe-->ws2_32.dll-->WSAAsyncSelect, Type: Inline - DirectJump 0x762FA17C-->00000000 [unknown_code_page]
[3624]hkcmd.exe-->ws2_32.dll-->WSAConnect, Type: Inline - DirectJump 0x762ED7B0-->00000000 [unknown_code_page]
[3624]hkcmd.exe-->ws2_32.dll-->WSAEventSelect, Type: Inline - DirectJump 0x762E5BFA-->00000000 [unknown_code_page]
[3640]igfxpers.exe-->kernel32.dll-->LoadLibraryExW, Type: Inline - DirectJump 0x76839109-->00000000 [unknown_code_page]
[3640]igfxpers.exe-->ws2_32.dll-->accept, Type: Inline - DirectJump 0x762FBDF6-->00000000 [unknown_code_page]
[3640]igfxpers.exe-->ws2_32.dll-->closesocket, Type: Inline - DirectJump 0x762E330C-->00000000 [unknown_code_page]
[3640]igfxpers.exe-->ws2_32.dll-->connect, Type: Inline - DirectJump 0x762E40D9-->00000000 [unknown_code_page]
[3640]igfxpers.exe-->ws2_32.dll-->htons, Type: Inline - DirectJump 0x762E3010-->00000000 [unknown_code_page]
[3640]igfxpers.exe-->ws2_32.dll-->WSAAccept, Type: Inline - DirectJump 0x762FBB56-->00000000 [unknown_code_page]
[3640]igfxpers.exe-->ws2_32.dll-->WSAAsyncSelect, Type: Inline - DirectJump 0x762FA17C-->00000000 [unknown_code_page]
[3640]igfxpers.exe-->ws2_32.dll-->WSAConnect, Type: Inline - DirectJump 0x762ED7B0-->00000000 [unknown_code_page]
[3640]igfxpers.exe-->ws2_32.dll-->WSAEventSelect, Type: Inline - DirectJump 0x762E5BFA-->00000000 [unknown_code_page]
[3664]WLTRAY.EXE-->kernel32.dll-->LoadLibraryExW, Type: Inline - DirectJump 0x76839109-->00000000 [unknown_code_page]
[3664]WLTRAY.EXE-->ws2_32.dll-->accept, Type: Inline - DirectJump 0x762FBDF6-->00000000 [unknown_code_page]
[3664]WLTRAY.EXE-->ws2_32.dll-->closesocket, Type: Inline - DirectJump 0x762E330C-->00000000 [unknown_code_page]
[3664]WLTRAY.EXE-->ws2_32.dll-->connect, Type: Inline - DirectJump 0x762E40D9-->00000000 [unknown_code_page]
[3664]WLTRAY.EXE-->ws2_32.dll-->htons, Type: Inline - DirectJump 0x762E3010-->00000000 [unknown_code_page]
[3664]WLTRAY.EXE-->ws2_32.dll-->WSAAccept, Type: Inline - DirectJump 0x762FBB56-->00000000 [unknown_code_page]
[3664]WLTRAY.EXE-->ws2_32.dll-->WSAAsyncSelect, Type: Inline - DirectJump 0x762FA17C-->00000000 [unknown_code_page]
[3664]WLTRAY.EXE-->ws2_32.dll-->WSAConnect, Type: Inline - DirectJump 0x762ED7B0-->00000000 [unknown_code_page]
[3664]WLTRAY.EXE-->ws2_32.dll-->WSAEventSelect, Type: Inline - DirectJump 0x762E5BFA-->00000000 [unknown_code_page]
[3676]PDVDDXSrv.exe-->kernel32.dll-->LoadLibraryExW, Type: Inline - DirectJump 0x76839109-->00000000 [unknown_code_page]
[3676]PDVDDXSrv.exe-->ws2_32.dll-->accept, Type: Inline - DirectJump 0x762FBDF6-->00000000 [unknown_code_page]
[3676]PDVDDXSrv.exe-->ws2_32.dll-->closesocket, Type: Inline - DirectJump 0x762E330C-->00000000 [unknown_code_page]
[3676]PDVDDXSrv.exe-->ws2_32.dll-->connect, Type: Inline - DirectJump 0x762E40D9-->00000000 [unknown_code_page]
[3676]PDVDDXSrv.exe-->ws2_32.dll-->htons, Type: Inline - DirectJump 0x762E3010-->00000000 [unknown_code_page]
[3676]PDVDDXSrv.exe-->ws2_32.dll-->WSAAccept, Type: Inline - DirectJump 0x762FBB56-->00000000 [unknown_code_page]
[3676]PDVDDXSrv.exe-->ws2_32.dll-->WSAAsyncSelect, Type: Inline - DirectJump 0x762FA17C-->00000000 [unknown_code_page]
[3676]PDVDDXSrv.exe-->ws2_32.dll-->WSAConnect, Type: Inline - DirectJump 0x762ED7B0-->00000000 [unknown_code_page]
[3676]PDVDDXSrv.exe-->ws2_32.dll-->WSAEventSelect, Type: Inline - DirectJump 0x762E5BFA-->00000000 [unknown_code_page]
[3724]igfxsrvc.exe-->kernel32.dll-->LoadLibraryExW, Type: Inline - DirectJump 0x76839109-->00000000 [unknown_code_page]
[3724]igfxsrvc.exe-->ws2_32.dll-->accept, Type: Inline - DirectJump 0x762FBDF6-->00000000 [unknown_code_page]
[3724]igfxsrvc.exe-->ws2_32.dll-->closesocket, Type: Inline - DirectJump 0x762E330C-->00000000 [unknown_code_page]
[3724]igfxsrvc.exe-->ws2_32.dll-->connect, Type: Inline - DirectJump 0x762E40D9-->00000000 [unknown_code_page]
[3724]igfxsrvc.exe-->ws2_32.dll-->htons, Type: Inline - DirectJump 0x762E3010-->00000000 [unknown_code_page]
[3724]igfxsrvc.exe-->ws2_32.dll-->WSAAccept, Type: Inline - DirectJump 0x762FBB56-->00000000 [unknown_code_page]
[3724]igfxsrvc.exe-->ws2_32.dll-->WSAAsyncSelect, Type: Inline - DirectJump 0x762FA17C-->00000000 [unknown_code_page]
[3724]igfxsrvc.exe-->ws2_32.dll-->WSAConnect, Type: Inline - DirectJump 0x762ED7B0-->00000000 [unknown_code_page]
[3724]igfxsrvc.exe-->ws2_32.dll-->WSAEventSelect, Type: Inline - DirectJump 0x762E5BFA-->00000000 [unknown_code_page]
[3740]COCIManager.exe-->kernel32.dll-->LoadLibraryExW, Type: Inline - DirectJump 0x76839109-->00000000 [unknown_code_page]
[3740]COCIManager.exe-->ws2_32.dll-->accept, Type: Inline - DirectJump 0x762FBDF6-->00000000 [unknown_code_page]
[3740]COCIManager.exe-->ws2_32.dll-->closesocket, Type: Inline - DirectJump 0x762E330C-->00000000 [unknown_code_page]
[3740]COCIManager.exe-->ws2_32.dll-->connect, Type: Inline - DirectJump 0x762E40D9-->00000000 [unknown_code_page]
[3740]COCIManager.exe-->ws2_32.dll-->htons, Type: Inline - DirectJump 0x762E3010-->00000000 [unknown_code_page]
[3740]COCIManager.exe-->ws2_32.dll-->WSAAccept, Type: Inline - DirectJump 0x762FBB56-->00000000 [unknown_code_page]
[3740]COCIManager.exe-->ws2_32.dll-->WSAAsyncSelect, Type: Inline - DirectJump 0x762FA17C-->00000000 [unknown_code_page]
[3740]COCIManager.exe-->ws2_32.dll-->WSAConnect, Type: Inline - DirectJump 0x762ED7B0-->00000000 [unknown_code_page]
[3740]COCIManager.exe-->ws2_32.dll-->WSAEventSelect, Type: Inline - DirectJump 0x762E5BFA-->00000000 [unknown_code_page]
[3812]iTunesHelper.exe-->kernel32.dll-->LoadLibraryExW, Type: Inline - DirectJump 0x76839109-->00000000 [unknown_code_page]
[3812]iTunesHelper.exe-->ws2_32.dll-->accept, Type: Inline - DirectJump 0x762FBDF6-->00000000 [unknown_code_page]
[3812]iTunesHelper.exe-->ws2_32.dll-->closesocket, Type: Inline - DirectJump 0x762E330C-->00000000 [unknown_code_page]
[3812]iTunesHelper.exe-->ws2_32.dll-->connect, Type: Inline - DirectJump 0x762E40D9-->00000000 [unknown_code_page]
[3812]iTunesHelper.exe-->ws2_32.dll-->htons, Type: Inline - DirectJump 0x762E3010-->00000000 [unknown_code_page]
[3812]iTunesHelper.exe-->ws2_32.dll-->WSAAccept, Type: Inline - DirectJump 0x762FBB56-->00000000 [unknown_code_page]
[3812]iTunesHelper.exe-->ws2_32.dll-->WSAAsyncSelect, Type: Inline - DirectJump 0x762FA17C-->00000000 [unknown_code_page]
[3812]iTunesHelper.exe-->ws2_32.dll-->WSAConnect, Type: Inline - DirectJump 0x762ED7B0-->00000000 [unknown_code_page]
[3812]iTunesHelper.exe-->ws2_32.dll-->WSAEventSelect, Type: Inline - DirectJump 0x762E5BFA-->00000000 [unknown_code_page]
[3824]jusched.exe-->kernel32.dll-->LoadLibraryExW, Type: Inline - DirectJump 0x76839109-->00000000 [unknown_code_page]
[3824]jusched.exe-->ws2_32.dll-->accept, Type: Inline - DirectJump 0x762FBDF6-->00000000 [unknown_code_page]
[3824]jusched.exe-->ws2_32.dll-->closesocket, Type: Inline - DirectJump 0x762E330C-->00000000 [unknown_code_page]
[3824]jusched.exe-->ws2_32.dll-->connect, Type: Inline - DirectJump 0x762E40D9-->00000000 [unknown_code_page]
[3824]jusched.exe-->ws2_32.dll-->htons, Type: Inline - DirectJump 0x762E3010-->00000000 [unknown_code_page]
[3824]jusched.exe-->ws2_32.dll-->WSAAccept, Type: Inline - DirectJump 0x762FBB56-->00000000 [unknown_code_page]
[3824]jusched.exe-->ws2_32.dll-->WSAAsyncSelect, Type: Inline - DirectJump 0x762FA17C-->00000000 [unknown_code_page]
[3824]jusched.exe-->ws2_32.dll-->WSAConnect, Type: Inline - DirectJump 0x762ED7B0-->00000000 [unknown_code_page]
[3824]jusched.exe-->ws2_32.dll-->WSAEventSelect, Type: Inline - DirectJump 0x762E5BFA-->00000000 [unknown_code_page]
[3876]NOELauncher.exe-->advapi32.dll-->kernel32.dll-->GetProcAddress, Type: IAT modification 0x77C814BC-->00000000 [shimeng.dll]
[3876]NOELauncher.exe-->gdi32.dll-->kernel32.dll-->GetProcAddress, Type: IAT modification 0x77B61170-->00000000 [shimeng.dll]
[3876]NOELauncher.exe-->kernel32.dll-->GetProcAddress, Type: IAT modification 0x0040A128-->00000000 [shimeng.dll]
[3876]NOELauncher.exe-->kernel32.dll-->LoadLibraryExW, Type: Inline - DirectJump 0x76839109-->00000000 [unknown_code_page]
[3876]NOELauncher.exe-->shell32.dll-->kernel32.dll-->GetProcAddress, Type: IAT modification 0x768E1414-->00000000 [shimeng.dll]
[3876]NOELauncher.exe-->user32.dll-->kernel32.dll-->GetProcAddress, Type: IAT modification 0x77D51300-->00000000 [shimeng.dll]
[3876]NOELauncher.exe-->ws2_32.dll-->accept, Type: Inline - DirectJump 0x762FBDF6-->00000000 [unknown_code_page]
[3876]NOELauncher.exe-->ws2_32.dll-->closesocket, Type: Inline - DirectJump 0x762E330C-->00000000 [unknown_code_page]
[3876]NOELauncher.exe-->ws2_32.dll-->connect, Type: Inline - DirectJump 0x762E40D9-->00000000 [unknown_code_page]
[3876]NOELauncher.exe-->ws2_32.dll-->htons, Type: Inline - DirectJump 0x762E3010-->00000000 [unknown_code_page]
[3876]NOELauncher.exe-->ws2_32.dll-->kernel32.dll-->GetProcAddress, Type: IAT modification 0x4B0D11E8-->00000000 [shimeng.dll]
[3876]NOELauncher.exe-->ws2_32.dll-->WSAAccept, Type: Inline - DirectJump 0x762FBB56-->00000000 [unknown_code_page]
[3876]NOELauncher.exe-->ws2_32.dll-->WSAAsyncSelect, Type: Inline - DirectJump 0x762FA17C-->00000000 [unknown_code_page]
[3876]NOELauncher.exe-->ws2_32.dll-->WSAConnect, Type: Inline - DirectJump 0x762ED7B0-->00000000 [unknown_code_page]
[3876]NOELauncher.exe-->ws2_32.dll-->WSAEventSelect, Type: Inline - DirectJump 0x762E5BFA-->00000000 [unknown_code_page]
[3896]Quickcam.exe-->kernel32.dll-->FindResourceA, Type: IAT modification 0x004FD2D0-->00000000 [Quickcam.exe]
[3896]Quickcam.exe-->kernel32.dll-->FindResourceExW, Type: IAT modification 0x004FD2CC-->00000000 [Quickcam.exe]
[3896]Quickcam.exe-->kernel32.dll-->FindResourceW, Type: IAT modification 0x004FD4B8-->00000000 [Quickcam.exe]
[3896]Quickcam.exe-->kernel32.dll-->FreeResource, Type: IAT modification 0x004FD3E8-->00000000 [Quickcam.exe]
[3896]Quickcam.exe-->kernel32.dll-->GetProfileIntA, Type: IAT modification 0x004FD2C8-->00000000 [Quickcam.exe]
[3896]Quickcam.exe-->kernel32.dll-->GetProfileIntW, Type: IAT modification 0x004FD37C-->00000000 [Quickcam.exe]
[3896]Quickcam.exe-->kernel32.dll-->LoadLibraryExW, Type: Inline - DirectJump 0x76839109-->00000000 [unknown_code_page]
[3896]Quickcam.exe-->kernel32.dll-->LoadResource, Type: IAT modification 0x004FD4BC-->00000000 [Quickcam.exe]
[3896]Quickcam.exe-->kernel32.dll-->LockResource, Type: IAT modification 0x004FD4C0-->00000000 [Quickcam.exe]
[3896]Quickcam.exe-->kernel32.dll-->ntdll.dll-->NtClose, Type: IAT modification 0x77DF1050-->00000000 [LVPrcInj01.dll]
[3896]Quickcam.exe-->kernel32.dll-->ntdll.dll-->NtCreateFile, Type: IAT modification 0x77DF1018-->00000000 [LVPrcInj01.dll]
[3896]Quickcam.exe-->kernel32.dll-->ntdll.dll-->NtDeviceIoControlFile, Type: IAT modification 0x77DF1054-->00000000 [LVPrcInj01.dll]
[3896]Quickcam.exe-->kernel32.dll-->ntdll.dll-->NtDuplicateObject, Type: IAT modification 0x77DF1354-->00000000 [LVPrcInj01.dll]
[3896]Quickcam.exe-->kernel32.dll-->SizeofResource, Type: IAT modification 0x004FD4C4-->00000000 [Quickcam.exe]
[3896]Quickcam.exe-->user32.dll-->LoadMenuA, Type: IAT modification 0x004FD7B8-->00000000 [Quickcam.exe]
[3896]Quickcam.exe-->user32.dll-->LoadMenuW, Type: IAT modification 0x004FD6D4-->00000000 [Quickcam.exe]
[3896]Quickcam.exe-->user32.dll-->LoadStringA, Type: IAT modification 0x004FD7B4-->00000000 [Quickcam.exe]
[3896]Quickcam.exe-->user32.dll-->LoadStringW, Type: IAT modification 0x004FD7B0-->00000000 [Quickcam.exe]
[3896]Quickcam.exe-->ws2_32.dll-->accept, Type: Inline - DirectJump 0x762FBDF6-->00000000 [unknown_code_page]
[3896]Quickcam.exe-->ws2_32.dll-->closesocket, Type: Inline - DirectJump 0x762E330C-->00000000 [unknown_code_page]
[3896]Quickcam.exe-->ws2_32.dll-->connect, Type: Inline - DirectJump 0x762E40D9-->00000000 [unknown_code_page]
[3896]Quickcam.exe-->ws2_32.dll-->htons, Type: Inline - DirectJump 0x762E3010-->00000000 [unknown_code_page]
[3896]Quickcam.exe-->ws2_32.dll-->WSAAccept, Type: Inline - DirectJump 0x762FBB56-->00000000 [unknown_code_page]
[3896]Quickcam.exe-->ws2_32.dll-->WSAAsyncSelect, Type: Inline - DirectJump 0x762FA17C-->00000000 [unknown_code_page]
[3896]Quickcam.exe-->ws2_32.dll-->WSAConnect, Type: Inline - DirectJump 0x762ED7B0-->00000000 [unknown_code_page]
[3896]Quickcam.exe-->ws2_32.dll-->WSAEventSelect, Type: Inline - DirectJump 0x762E5BFA-->00000000 [unknown_code_page]
[3920]sidebar.exe-->kernel32.dll-->LoadLibraryExW, Type: Inline - DirectJump 0x76839109-->00000000 [unknown_code_page]
[3920]sidebar.exe-->kernel32.dll-->ntdll.dll-->NtClose, Type: IAT modification 0x77DF1050-->00000000 [LVPrcInj01.dll]
[3920]sidebar.exe-->kernel32.dll-->ntdll.dll-->NtCreateFile, Type: IAT modification 0x77DF1018-->00000000 [LVPrcInj01.dll]
[3920]sidebar.exe-->kernel32.dll-->ntdll.dll-->NtDeviceIoControlFile, Type: IAT modification 0x77DF1054-->00000000 [LVPrcInj01.dll]
[3920]sidebar.exe-->kernel32.dll-->ntdll.dll-->NtDuplicateObject, Type: IAT modification 0x77DF1354-->00000000 [LVPrcInj01.dll]
[3920]sidebar.exe-->ws2_32.dll-->accept, Type: Inline - DirectJump 0x762FBDF6-->00000000 [unknown_code_page]
[3920]sidebar.exe-->ws2_32.dll-->closesocket, Type: Inline - DirectJump 0x762E330C-->00000000 [unknown_code_page]
[3920]sidebar.exe-->ws2_32.dll-->connect, Type: Inline - DirectJump 0x762E40D9-->00000000 [unknown_code_page]
[3920]sidebar.exe-->ws2_32.dll-->htons, Type: Inline - DirectJump 0x762E3010-->00000000 [unknown_code_page]
[3920]sidebar.exe-->ws2_32.dll-->WSAAccept, Type: Inline - DirectJump 0x762FBB56-->00000000 [unknown_code_page]
[3920]sidebar.exe-->ws2_32.dll-->WSAAsyncSelect, Type: Inline - DirectJump 0x762FA17C-->00000000 [unknown_code_page]
[3920]sidebar.exe-->ws2_32.dll-->WSAConnect, Type: Inline - DirectJump 0x762ED7B0-->00000000 [unknown_code_page]
[3920]sidebar.exe-->ws2_32.dll-->WSAEventSelect, Type: Inline - DirectJump 0x762E5BFA-->00000000 [unknown_code_page]
[3948]TeaTimer.exe-->kernel32.dll-->LoadLibraryExW, Type: Inline - DirectJump 0x76839109-->00000000 [unknown_code_page]
[3948]TeaTimer.exe-->ws2_32.dll-->accept, Type: Inline - DirectJump 0x762FBDF6-->00000000 [unknown_code_page]
[3948]TeaTimer.exe-->ws2_32.dll-->closesocket, Type: Inline - DirectJump 0x762E330C-->00000000 [unknown_code_page]
[3948]TeaTimer.exe-->ws2_32.dll-->connect, Type: Inline - DirectJump 0x762E40D9-->00000000 [unknown_code_page]
[3948]TeaTimer.exe-->ws2_32.dll-->htons, Type: Inline - DirectJump 0x762E3010-->00000000 [unknown_code_page]
[3948]TeaTimer.exe-->ws2_32.dll-->WSAAccept, Type: Inline - DirectJump 0x762FBB56-->00000000 [unknown_code_page]
[3948]TeaTimer.exe-->ws2_32.dll-->WSAAsyncSelect, Type: Inline - DirectJump 0x762FA17C-->00000000 [unknown_code_page]
[3948]TeaTimer.exe-->ws2_32.dll-->WSAConnect, Type: Inline - DirectJump 0x762ED7B0-->00000000 [unknown_code_page]
[3948]TeaTimer.exe-->ws2_32.dll-->WSAEventSelect, Type: Inline - DirectJump 0x762E5BFA-->00000000 [unknown_code_page]
[3972]PCSuite.exe-->kernel32.dll-->LoadLibraryExW, Type: Inline - DirectJump 0x76839109-->00000000 [unknown_code_page]
[3972]PCSuite.exe-->ws2_32.dll-->accept, Type: Inline - DirectJump 0x762FBDF6-->00000000 [unknown_code_page]
[3972]PCSuite.exe-->ws2_32.dll-->closesocket, Type: Inline - DirectJump 0x762E330C-->00000000 [unknown_code_page]
[3972]PCSuite.exe-->ws2_32.dll-->connect, Type: Inline - DirectJump 0x762E40D9-->00000000 [unknown_code_page]
[3972]PCSuite.exe-->ws2_32.dll-->htons, Type: Inline - DirectJump 0x762E3010-->00000000 [unknown_code_page]
[3972]PCSuite.exe-->ws2_32.dll-->WSAAccept, Type: Inline - DirectJump 0x762FBB56-->00000000 [unknown_code_page]
[3972]PCSuite.exe-->ws2_32.dll-->WSAAsyncSelect, Type: Inline - DirectJump 0x762FA17C-->00000000 [unknown_code_page]
[3972]PCSuite.exe-->ws2_32.dll-->WSAConnect, Type: Inline - DirectJump 0x762ED7B0-->00000000 [unknown_code_page]
[3972]PCSuite.exe-->ws2_32.dll-->WSAEventSelect, Type: Inline - DirectJump 0x762E5BFA-->00000000 [unknown_code_page]
[3996]msnmsgr.exe-->kernel32.dll-->CloseHandle, Type: Inline - DirectJump 0x7685AE8D-->00000000 [unknown_code_page]
[3996]msnmsgr.exe-->kernel32.dll-->CreateFileA, Type: Inline - DirectJump 0x7685CE5F-->00000000 [unknown_code_page]
[3996]msnmsgr.exe-->kernel32.dll-->CreateFileW, Type: Inline - DirectJump 0x7685AECB-->00000000 [unknown_code_page]
[3996]msnmsgr.exe-->kernel32.dll-->FindFirstFileA, Type: Inline - DirectJump 0x7683895D-->00000000 [unknown_code_page]
[3996]msnmsgr.exe-->kernel32.dll-->FindFirstFileW, Type: Inline - DirectJump 0x7684F00C-->00000000 [unknown_code_page]
[3996]msnmsgr.exe-->kernel32.dll-->LoadLibraryExW, Type: Inline - DirectJump 0x76839109-->00000000 [unknown_code_page]
[3996]msnmsgr.exe-->kernel32.dll-->ntdll.dll-->NtClose, Type: IAT modification 0x77DF1050-->00000000 [LVPrcInj01.dll]
[3996]msnmsgr.exe-->kernel32.dll-->ntdll.dll-->NtCreateFile, Type: IAT modification 0x77DF1018-->00000000 [LVPrcInj01.dll]
[3996]msnmsgr.exe-->kernel32.dll-->ntdll.dll-->NtDeviceIoControlFile, Type: IAT modification 0x77DF1054-->00000000 [LVPrcInj01.dll]
[3996]msnmsgr.exe-->kernel32.dll-->ntdll.dll-->NtDuplicateObject, Type: IAT modification 0x77DF1354-->00000000 [LVPrcInj01.dll]
[3996]msnmsgr.exe-->ws2_32.dll-->accept, Type: Inline - DirectJump 0x762FBDF6-->00000000 [unknown_code_page]
[3996]msnmsgr.exe-->ws2_32.dll-->closesocket, Type: Inline - DirectJump 0x762E330C-->00000000 [unknown_code_page]
[3996]msnmsgr.exe-->ws2_32.dll-->connect, Type: Inline - DirectJump 0x762E40D9-->00000000 [unknown_code_page]
[3996]msnmsgr.exe-->ws2_32.dll-->htons, Type: Inline - DirectJump 0x762E3010-->00000000 [unknown_code_page]
[3996]msnmsgr.exe-->ws2_32.dll-->WSAAccept, Type: Inline - DirectJump 0x762FBB56-->00000000 [unknown_code_page]
[3996]msnmsgr.exe-->ws2_32.dll-->WSAAsyncSelect, Type: Inline - DirectJump 0x762FA17C-->00000000 [unknown_code_page]
[3996]msnmsgr.exe-->ws2_32.dll-->WSAConnect, Type: Inline - DirectJump 0x762ED7B0-->00000000 [unknown_code_page]
[3996]msnmsgr.exe-->ws2_32.dll-->WSAEventSelect, Type: Inline - DirectJump 0x762E5BFA-->00000000 [unknown_code_page]
[4664]iexplore.exe-->advapi32.dll-->kernel32.dll-->GetProcAddress, Type: IAT modification 0x77C814BC-->00000000 [IEShims.dll]
[4664]iexplore.exe-->gdi32.dll-->kernel32.dll-->CopyFileW, Type: IAT modification 0x77B61130-->00000000 [IEShims.dll]
[4664]iexplore.exe-->gdi32.dll-->kernel32.dll-->CreateFileW, Type: IAT modification 0x77B6119C-->00000000 [IEShims.dll]
[4664]iexplore.exe-->gdi32.dll-->kernel32.dll-->DeleteFileW, Type: IAT modification 0x77B611BC-->00000000 [IEShims.dll]
[4664]iexplore.exe-->gdi32.dll-->kernel32.dll-->GetProcAddress, Type: IAT modification 0x77B61170-->00000000 [IEShims.dll]
[4664]iexplore.exe-->gdi32.dll-->kernel32.dll-->LoadLibraryA, Type: IAT modification 0x77B6111C-->00000000 [IEShims.dll]
[4664]iexplore.exe-->gdi32.dll-->kernel32.dll-->LoadLibraryExW, Type: IAT modification 0x77B61110-->00000000 [IEShims.dll]
[4664]iexplore.exe-->gdi32.dll-->kernel32.dll-->LoadLibraryW, Type: IAT modification 0x77B61174-->00000000 [IEShims.dll]
[4664]iexplore.exe-->gdi32.dll-->kernel32.dll-->SearchPathW, Type: IAT modification 0x77B611AC-->00000000 [IEShims.dll]
[4664]iexplore.exe-->mswsock.dll-->kernel32.dll-->GetProcAddress, Type: IAT modification 0x6D64123C-->00000000 [IEShims.dll]
[4664]iexplore.exe-->shell32.dll-->kernel32.dll-->CopyFileW, Type: IAT modification 0x768E125C-->00000000 [IEShims.dll]
[4664]iexplore.exe-->shell32.dll-->kernel32.dll-->CreateDirectoryW, Type: IAT modification 0x768E13B0-->00000000 [IEShims.dll]
[4664]iexplore.exe-->shell32.dll-->kernel32.dll-->CreateFileW, Type: IAT modification 0x768E1460-->00000000 [IEShims.dll]
[4664]iexplore.exe-->shell32.dll-->kernel32.dll-->CreateHardLinkW, Type: IAT modification 0x768E11A4-->00000000 [IEShims.dll]
[4664]iexplore.exe-->shell32.dll-->kernel32.dll-->CreateProcessW, Type: IAT modification 0x768E12E8-->00000000 [IEShims.dll]
[4664]iexplore.exe-->shell32.dll-->kernel32.dll-->DeleteFileW, Type: IAT modification 0x768E13B4-->00000000 [IEShims.dll]
[4664]iexplore.exe-->shell32.dll-->kernel32.dll-->FindClose, Type: IAT modification 0x768E132C-->00000000 [IEShims.dll]
[4664]iexplore.exe-->shell32.dll-->kernel32.dll-->FindFirstFileW, Type: IAT modification 0x768E1328-->00000000 [IEShims.dll]
[4664]iexplore.exe-->shell32.dll-->kernel32.dll-->FindNextFileW, Type: IAT modification 0x768E1114-->00000000 [IEShims.dll]
[4664]iexplore.exe-->shell32.dll-->kernel32.dll-->GetBinaryTypeW, Type: IAT modification 0x768E1280-->00000000 [IEShims.dll]
[4664]iexplore.exe-->shell32.dll-->kernel32.dll-->GetFileAttributesA, Type: IAT modification 0x768E1370-->00000000 [IEShims.dll]
[4664]iexplore.exe-->shell32.dll-->kernel32.dll-->GetFileAttributesExW, Type: IAT modification 0x768E14A4-->00000000 [IEShims.dll]
[4664]iexplore.exe-->shell32.dll-->kernel32.dll-->GetFileAttributesW, Type: IAT modification 0x768E13BC-->00000000 [IEShims.dll]
[4664]iexplore.exe-->shell32.dll-->kernel32.dll-->GetLongPathNameW, Type: IAT modification 0x768E14EC-->00000000 [IEShims.dll]
[4664]iexplore.exe-->shell32.dll-->kernel32.dll-->GetPrivateProfileIntW, Type: IAT modification 0x768E1390-->00000000 [IEShims.dll]
[4664]iexplore.exe-->shell32.dll-->kernel32.dll-->GetPrivateProfileSectionNamesW, Type: IAT modification 0x768E1164-->00000000 [IEShims.dll]
[4664]iexplore.exe-->shell32.dll-->kernel32.dll-->GetPrivateProfileSectionW, Type: IAT modification 0x768E1100-->00000000 [IEShims.dll]
[4664]iexplore.exe-->shell32.dll-->kernel32.dll-->GetPrivateProfileStringW, Type: IAT modification 0x768E13A0-->00000000 [IEShims.dll]
[4664]iexplore.exe-->shell32.dll-->kernel32.dll-->GetShortPathNameA, Type: IAT modification 0x768E136C-->00000000 [IEShims.dll]
[4664]iexplore.exe-->shell32.dll-->kernel32.dll-->GetShortPathNameW, Type: IAT modification 0x768E1428-->00000000 [IEShims.dll]
[4664]iexplore.exe-->shell32.dll-->kernel32.dll-->LoadLibraryA, Type: IAT modification 0x768E14E0-->00000000 [IEShims.dll]
[4664]iexplore.exe-->shell32.dll-->kernel32.dll-->LoadLibraryExW, Type: IAT modification 0x768E1284-->00000000 [IEShims.dll]
[4664]iexplore.exe-->shell32.dll-->kernel32.dll-->LoadLibraryW, Type: IAT modification 0x768E1448-->00000000 [IEShims.dll]
[4664]iexplore.exe-->shell32.dll-->kernel32.dll-->MoveFileExW, Type: IAT modification 0x768E13C0-->00000000 [IEShims.dll]
[4664]iexplore.exe-->shell32.dll-->kernel32.dll-->MoveFileW, Type: IAT modification 0x768E130C-->00000000 [IEShims.dll]
[4664]iexplore.exe-->shell32.dll-->kernel32.dll-->RemoveDirectoryW, Type: IAT modification 0x768E13AC-->00000000 [IEShims.dll]
[4664]iexplore.exe-->shell32.dll-->kernel32.dll-->ReplaceFileW, Type: IAT modification 0x768E1140-->00000000 [IEShims.dll]
[4664]iexplore.exe-->shell32.dll-->kernel32.dll-->SearchPathW, Type: IAT modification 0x768E1384-->00000000 [IEShims.dll]
[4664]iexplore.exe-->shell32.dll-->kernel32.dll-->SetCurrentDirectoryW, Type: IAT modification 0x768E124C-->00000000 [IEShims.dll]
[4664]iexplore.exe-->shell32.dll-->kernel32.dll-->SetFileAttributesW, Type: IAT modification 0x768E13B8-->00000000 [IEShims.dll]
[4664]iexplore.exe-->shell32.dll-->kernel32.dll-->WritePrivateProfileSectionW, Type: IAT modification 0x768E1168-->00000000 [IEShims.dll]
[4664]iexplore.exe-->shell32.dll-->kernel32.dll-->WritePrivateProfileStringW, Type: IAT modification 0x768E116C-->00000000 [IEShims.dll]
[4664]iexplore.exe-->shell32.dll-->ntdll.dll-->NtQueryDirectoryFile, Type: IAT modification 0x768E2320-->00000000 [IEShims.dll]
[4664]iexplore.exe-->shell32.dll-->user32.dll-->LoadImageW, Type: IAT modification 0x768E1890-->00000000 [IEShims.dll]
[4664]iexplore.exe-->shell32.dll-->user32.dll-->PrivateExtractIconsW, Type: IAT modification 0x768E1A6C-->00000000 [IEShims.dll]
[4664]iexplore.exe-->shell32.dll-->user32.dll-->WinHelpW, Type: IAT modification 0x768E191C-->00000000 [IEShims.dll]
[4664]iexplore.exe-->user32.dll-->advapi32.dll-->RegCloseKey, Type: IAT modification 0x77D5154C-->00000000 [IEShims.dll]
[4664]iexplore.exe-->user32.dll-->advapi32.dll-->RegCreateKeyExW, Type: IAT modification 0x77D51548-->00000000 [IEShims.dll]
[4664]iexplore.exe-->user32.dll-->advapi32.dll-->RegDeleteKeyW, Type: IAT modification 0x77D51544-->00000000 [IEShims.dll]
[4664]iexplore.exe-->user32.dll-->advapi32.dll-->RegEnumValueW, Type: IAT modification 0x77D51524-->00000000 [IEShims.dll]
[4664]iexplore.exe-->user32.dll-->advapi32.dll-->RegOpenKeyExW, Type: IAT modification 0x77D51528-->00000000 [IEShims.dll]
[4664]iexplore.exe-->user32.dll-->advapi32.dll-->RegQueryInfoKeyW, Type: IAT modification 0x77D51520-->00000000 [IEShims.dll]
[4664]iexplore.exe-->user32.dll-->advapi32.dll-->RegQueryValueExW, Type: IAT modification 0x77D5152C-->00000000 [IEShims.dll]
[4664]iexplore.exe-->user32.dll-->CallNextHookEx, Type: Inline - RelativeJump 0x775A8E3B-->00000000 [ieframe.dll]
[4664]iexplore.exe-->user32.dll-->CreateDialogIndirectParamA, Type: Inline - RelativeJump 0x775C26F1-->00000000 [ieframe.dll]
[4664]iexplore.exe-->user32.dll-->CreateDialogIndirectParamW, Type: Inline - RelativeJump 0x775C9A62-->00000000 [ieframe.dll]
[4664]iexplore.exe-->user32.dll-->CreateDialogParamA, Type: Inline - RelativeJump 0x775C17AA-->00000000 [ieframe.dll]
[4664]iexplore.exe-->user32.dll-->CreateDialogParamW, Type: Inline - RelativeJump 0x775A72A2-->00000000 [ieframe.dll]
[4664]iexplore.exe-->user32.dll-->CreateWindowExW, Type: Inline - RelativeJump 0x775B1305-->00000000 [ieframe.dll]
[4664]iexplore.exe-->user32.dll-->DialogBoxIndirectParamA, Type: Inline - RelativeJump 0x775E847D-->00000000 [ieframe.dll]
[4664]iexplore.exe-->user32.dll-->DialogBoxIndirectParamW, Type: Inline - RelativeJump 0x775D2EF5-->00000000 [ieframe.dll]
[4664]iexplore.exe-->user32.dll-->DialogBoxParamA, Type: Inline - RelativeJump 0x775E8152-->00000000 [ieframe.dll]
[4664]iexplore.exe-->user32.dll-->DialogBoxParamW, Type: Inline - RelativeJump 0x775D10B0-->00000000 [ieframe.dll]
[4664]iexplore.exe-->user32.dll-->EnableWindow, Type: Inline - RelativeJump 0x775ACD8B-->00000000 [ieframe.dll]
[4664]iexplore.exe-->user32.dll-->EndDialog, Type: Inline - RelativeJump 0x775D326E-->00000000 [ieframe.dll]
[4664]iexplore.exe-->user32.dll-->GetAsyncKeyState, Type: Inline - RelativeJump 0x775A863C-->00000000 [ieframe.dll]
[4664]iexplore.exe-->user32.dll-->GetKeyState, Type: Inline - RelativeJump 0x775B8CB1-->00000000 [ieframe.dll]
[4664]iexplore.exe-->user32.dll-->IsDialogMessage, Type: Inline - RelativeJump 0x775C1847-->00000000 [ieframe.dll]
[4664]iexplore.exe-->user32.dll-->IsDialogMessageW, Type: Inline - RelativeJump 0x775C0745-->00000000 [ieframe.dll]
[4664]iexplore.exe-->user32.dll-->kernel32.dll-->CopyFileW, Type: IAT modification 0x77D511A8-->00000000 [IEShims.dll]
[4664]iexplore.exe-->user32.dll-->kernel32.dll-->CreateFileW, Type: IAT modification 0x77D512B8-->00000000 [IEShims.dll]
[4664]iexplore.exe-->user32.dll-->kernel32.dll-->CreateProcessW, Type: IAT modification 0x77D511B4-->00000000 [IEShims.dll]
[4664]iexplore.exe-->user32.dll-->kernel32.dll-->DeleteFileW, Type: IAT modification 0x77D511B0-->00000000 [IEShims.dll]
[4664]iexplore.exe-->user32.dll-->kernel32.dll-->FindClose, Type: IAT modification 0x77D511E4-->00000000 [IEShims.dll]
[4664]iexplore.exe-->user32.dll-->kernel32.dll-->FindFirstFileW, Type: IAT modification 0x77D511EC-->00000000 [IEShims.dll]
[4664]iexplore.exe-->user32.dll-->kernel32.dll-->FindNextFileW, Type: IAT modification 0x77D511E8-->00000000 [IEShims.dll]
[4664]iexplore.exe-->user32.dll-->kernel32.dll-->GetPrivateProfileStringW, Type: IAT modification 0x77D51328-->00000000 [IEShims.dll]
[4664]iexplore.exe-->user32.dll-->kernel32.dll-->GetProcAddress, Type: IAT modification 0x77D51300-->00000000 [IEShims.dll]
[4664]iexplore.exe-->user32.dll-->kernel32.dll-->LoadLibraryA, Type: IAT modification 0x77D51250-->00000000 [IEShims.dll]
[4664]iexplore.exe-->user32.dll-->kernel32.dll-->LoadLibraryExW, Type: IAT modification 0x77D5115C-->00000000 [IEShims.dll]
[4664]iexplore.exe-->user32.dll-->kernel32.dll-->LoadLibraryW, Type: IAT modification 0x77D512FC-->00000000 [IEShims.dll]
[4664]iexplore.exe-->user32.dll-->kernel32.dll-->MoveFileW, Type: IAT modification 0x77D511AC-->00000000 [IEShims.dll]
[4664]iexplore.exe-->user32.dll-->kernel32.dll-->SearchPathW, Type: IAT modification 0x77D51154-->00000000 [IEShims.dll]
[4664]iexplore.exe-->user32.dll-->kernel32.dll-->SetCurrentDirectoryW, Type: IAT modification 0x77D511D8-->00000000 [IEShims.dll]
[4664]iexplore.exe-->user32.dll-->kernel32.dll-->WritePrivateProfileStringW, Type: IAT modification 0x77D512BC-->00000000 [IEShims.dll]
[4664]iexplore.exe-->user32.dll-->keybd_event, Type: Inline - RelativeJump 0x775FD972-->00000000 [ieframe.dll]
[4664]iexplore.exe-->user32.dll-->MessageBoxExA, Type: Inline - RelativeJump 0x775FD639-->00000000 [ieframe.dll]
[4664]iexplore.exe-->user32.dll-->MessageBoxExW, Type: Inline - RelativeJump 0x775FD65D-->00000000 [ieframe.dll]
[4664]iexplore.exe-->user32.dll-->MessageBoxIndirectA, Type: Inline - RelativeJump 0x775FD4D9-->00000000 [ieframe.dll]
[4664]iexplore.exe-->user32.dll-->MessageBoxIndirectW, Type: Inline - RelativeJump 0x775FD5D3-->00000000 [ieframe.dll]
[4664]iexplore.exe-->user32.dll-->SendInput, Type: Inline - RelativeJump 0x775D2F75-->00000000 [ieframe.dll]
[4664]iexplore.exe-->user32.dll-->SetCursorPos, Type: Inline - RelativeJump 0x775E6FB2-->00000000 [ieframe.dll]
[4664]iexplore.exe-->user32.dll-->SetKeyboardState, Type: Inline - RelativeJump 0x775D0987-->00000000 [ieframe.dll]
[4664]iexplore.exe-->user32.dll-->SetWindowsHookExW, Type: Inline - RelativeJump 0x775A87AD-->00000000 [ieframe.dll]
[4664]iexplore.exe-->user32.dll-->UnhookWindowsHookEx, Type: Inline - RelativeJump 0x775A98DB-->00000000 [ieframe.dll]
[4664]iexplore.exe-->wininet.dll-->kernel32.dll-->GetProcAddress, Type: IAT modification 0x704114B0-->00000000 [IEShims.dll]
[4664]iexplore.exe-->ws2_32.dll-->kernel32.dll-->GetProcAddress, Type: IAT modification 0x4B0D11E8-->00000000 [IEShims.dll]
[4948]WINWORD.EXE-->kernel32.dll-->LoadLibraryExW, Type: Inline - DirectJump 0x76839109-->00000000 [unknown_code_page]
[4948]WINWORD.EXE-->kernel32.dll-->SetUnhandledExceptionFilter, Type: Inline - RelativeJump 0x7683A84F-->00000000 [MSO.DLL]
[4948]WINWORD.EXE-->ws2_32.dll-->accept, Type: Inline - DirectJump 0x762FBDF6-->00000000 [unknown_code_page]
[4948]WINWORD.EXE-->ws2_32.dll-->closesocket, Type: Inline - DirectJump 0x762E330C-->00000000 [unknown_code_page]
[4948]WINWORD.EXE-->ws2_32.dll-->connect, Type: Inline - DirectJump 0x762E40D9-->00000000 [unknown_code_page]
[4948]WINWORD.EXE-->ws2_32.dll-->htons, Type: Inline - DirectJump 0x762E3010-->00000000 [unknown_code_page]
[4948]WINWORD.EXE-->ws2_32.dll-->WSAAccept, Type: Inline - DirectJump 0x762FBB56-->00000000 [unknown_code_page]
[4948]WINWORD.EXE-->ws2_32.dll-->WSAAsyncSelect, Type: Inline - DirectJump 0x762FA17C-->00000000 [unknown_code_page]
[4948]WINWORD.EXE-->ws2_32.dll-->WSAConnect, Type: Inline - DirectJump 0x762ED7B0-->00000000 [unknown_code_page]
[4948]WINWORD.EXE-->ws2_32.dll-->WSAEventSelect, Type: Inline - DirectJump 0x762E5BFA-->00000000 [unknown_code_page]
[5044]iexplore.exe-->user32.dll-->CreateWindowExW, Type: Inline - RelativeJump 0x775B1305-->00000000 [ieframe.dll]
[5044]iexplore.exe-->user32.dll-->DialogBoxIndirectParamA, Type: Inline - RelativeJump 0x775E847D-->00000000 [ieframe.dll]
[5044]iexplore.exe-->user32.dll-->DialogBoxIndirectParamW, Type: Inline - RelativeJump 0x775D2EF5-->00000000 [ieframe.dll]
[5044]iexplore.exe-->user32.dll-->DialogBoxParamA, Type: Inline - RelativeJump 0x775E8152-->00000000 [ieframe.dll]
[5044]iexplore.exe-->user32.dll-->DialogBoxParamW, Type: Inline - RelativeJump 0x775D10B0-->00000000 [ieframe.dll]
[5044]iexplore.exe-->user32.dll-->MessageBoxExA, Type: Inline - RelativeJump 0x775FD639-->00000000 [ieframe.dll]
[5044]iexplore.exe-->user32.dll-->MessageBoxExW, Type: Inline - RelativeJump 0x775FD65D-->00000000 [ieframe.dll]
[5044]iexplore.exe-->user32.dll-->MessageBoxIndirectA, Type: Inline - RelativeJump 0x775FD4D9-->00000000 [ieframe.dll]
[5044]iexplore.exe-->user32.dll-->MessageBoxIndirectW, Type: Inline - RelativeJump 0x775FD5D3-->00000000 [ieframe.dll]
[5168]wlcomm.exe-->kernel32.dll-->LoadLibraryExW, Type: Inline - DirectJump 0x76839109-->00000000 [unknown_code_page]
[5168]wlcomm.exe-->ws2_32.dll-->accept, Type: Inline - DirectJump 0x762FBDF6-->00000000 [unknown_code_page]
[5168]wlcomm.exe-->ws2_32.dll-->closesocket, Type: Inline - DirectJump 0x762E330C-->00000000 [unknown_code_page]
[5168]wlcomm.exe-->ws2_32.dll-->connect, Type: Inline - DirectJump 0x762E40D9-->00000000 [unknown_code_page]
[5168]wlcomm.exe-->ws2_32.dll-->htons, Type: Inline - DirectJump 0x762E3010-->00000000 [unknown_code_page]
[5168]wlcomm.exe-->ws2_32.dll-->WSAAccept, Type: Inline - DirectJump 0x762FBB56-->00000000 [unknown_code_page]
[5168]wlcomm.exe-->ws2_32.dll-->WSAAsyncSelect, Type: Inline - DirectJump 0x762FA17C-->00000000 [unknown_code_page]
[5168]wlcomm.exe-->ws2_32.dll-->WSAConnect, Type: Inline - DirectJump 0x762ED7B0-->00000000 [unknown_code_page]
[5168]wlcomm.exe-->ws2_32.dll-->WSAEventSelect, Type: Inline - DirectJump 0x762E5BFA-->00000000 [unknown_code_page]
[5444]iexplore.exe-->advapi32.dll-->kernel32.dll-->GetProcAddress, Type: IAT modification 0x77C814BC-->00000000 [IEShims.dll]
[5444]iexplore.exe-->gdi32.dll-->kernel32.dll-->CopyFileW, Type: IAT modification 0x77B61130-->00000000 [IEShims.dll]
[5444]iexplore.exe-->gdi32.dll-->kernel32.dll-->CreateFileW, Type: IAT modification 0x77B6119C-->00000000 [IEShims.dll]
[5444]iexplore.exe-->gdi32.dll-->kernel32.dll-->DeleteFileW, Type: IAT modification 0x77B611BC-->00000000 [IEShims.dll]
[5444]iexplore.exe-->gdi32.dll-->kernel32.dll-->GetProcAddress, Type: IAT modification 0x77B61170-->00000000 [IEShims.dll]
[5444]iexplore.exe-->gdi32.dll-->kernel32.dll-->LoadLibraryA, Type: IAT modification 0x77B6111C-->00000000 [IEShims.dll]
[5444]iexplore.exe-->gdi32.dll-->kernel32.dll-->LoadLibraryExW, Type: IAT modification 0x77B61110-->00000000 [IEShims.dll]
[5444]iexplore.exe-->gdi32.dll-->kernel32.dll-->LoadLibraryW, Type: IAT modification 0x77B61174-->00000000 [IEShims.dll]
[5444]iexplore.exe-->gdi32.dll-->kernel32.dll-->SearchPathW, Type: IAT modification 0x77B611AC-->00000000 [IEShims.dll]
[5444]iexplore.exe-->mswsock.dll-->kernel32.dll-->GetProcAddress, Type: IAT modification 0x6D64123C-->00000000 [IEShims.dll]
[5444]iexplore.exe-->shell32.dll-->kernel32.dll-->CopyFileW, Type: IAT modification 0x768E125C-->00000000 [IEShims.dll]
[5444]iexplore.exe-->shell32.dll-->kernel32.dll-->CreateDirectoryW, Type: IAT modification 0x768E13B0-->00000000 [IEShims.dll]
[5444]iexplore.exe-->shell32.dll-->kernel32.dll-->CreateFileW, Type: IAT modification 0x768E1460-->00000000 [IEShims.dll]
[5444]iexplore.exe-->shell32.dll-->kernel32.dll-->CreateHardLinkW, Type: IAT modification 0x768E11A4-->00000000 [IEShims.dll]
[5444]iexplore.exe-->shell32.dll-->kernel32.dll-->CreateProcessW, Type: IAT modification 0x768E12E8-->00000000 [IEShims.dll]
[5444]iexplore.exe-->shell32.dll-->kernel32.dll-->DeleteFileW, Type: IAT modification 0x768E13B4-->00000000 [IEShims.dll]
[5444]iexplore.exe-->shell32.dll-->kernel32.dll-->FindClose, Type: IAT modification 0x768E132C-->00000000 [IEShims.dll]
[5444]iexplore.exe-->shell32.dll-->kernel32.dll-->FindFirstFileW, Type: IAT modification 0x768E1328-->00000000 [IEShims.dll]
[5444]iexplore.exe-->shell32.dll-->kernel32.dll-->FindNextFileW, Type: IAT modification 0x768E1114-->00000000 [IEShims.dll]
[5444]iexplore.exe-->shell32.dll-->kernel32.dll-->GetBinaryTypeW, Type: IAT modification 0x768E1280-->00000000 [IEShims.dll]
[5444]iexplore.exe-->shell32.dll-->kernel32.dll-->GetFileAttributesA, Type: IAT modification 0x768E1370-->00000000 [IEShims.dll]
[5444]iexplore.exe-->shell32.dll-->kernel32.dll-->GetFileAttributesExW, Type: IAT modification 0x768E14A4-->00000000 [IEShims.dll]
[5444]iexplore.exe-->shell32.dll-->kernel32.dll-->GetFileAttributesW, Type: IAT modification 0x768E13BC-->00000000 [IEShims.dll]
[5444]iexplore.exe-->shell32.dll-->kernel32.dll-->GetLongPathNameW, Type: IAT modification 0x768E14EC-->00000000 [IEShims.dll]
[5444]iexplore.exe-->shell32.dll-->kernel32.dll-->GetPrivateProfileIntW, Type: IAT modification 0x768E1390-->00000000 [IEShims.dll]
[5444]iexplore.exe-->shell32.dll-->kernel32.dll-->GetPrivateProfileSectionNamesW, Type: IAT modification 0x768E1164-->00000000 [IEShims.dll]
[5444]iexplore.exe-->shell32.dll-->kernel32.dll-->GetPrivateProfileSectionW, Type: IAT modification 0x768E1100-->00000000 [IEShims.dll]
[5444]iexplore.exe-->shell32.dll-->kernel32.dll-->GetPrivateProfileStringW, Type: IAT modification 0x768E13A0-->00000000 [IEShims.dll]
[5444]iexplore.exe-->shell32.dll-->kernel32.dll-->GetShortPathNameA, Type: IAT modification 0x768E136C-->00000000 [IEShims.dll]
[5444]iexplore.exe-->shell32.dll-->kernel32.dll-->GetShortPathNameW, Type: IAT modification 0x768E1428-->00000000 [IEShims.dll]
[5444]iexplore.exe-->shell32.dll-->kernel32.dll-->LoadLibraryA, Type: IAT modification 0x768E14E0-->00000000 [IEShims.dll]
[5444]iexplore.exe-->shell32.dll-->kernel32.dll-->LoadLibraryExW, Type: IAT modification 0x768E1284-->00000000 [IEShims.dll]
[5444]iexplore.exe-->shell32.dll-->kernel32.dll-->LoadLibraryW, Type: IAT modification 0x768E1448-->00000000 [IEShims.dll]
[5444]iexplore.exe-->shell32.dll-->kernel32.dll-->MoveFileExW, Type: IAT modification 0x768E13C0-->00000000 [IEShims.dll]
[5444]iexplore.exe-->shell32.dll-->kernel32.dll-->MoveFileW, Type: IAT modification 0x768E130C-->00000000 [IEShims.dll]
[5444]iexplore.exe-->shell32.dll-->kernel32.dll-->RemoveDirectoryW, Type: IAT modification 0x768E13AC-->00000000 [IEShims.dll]
[5444]iexplore.exe-->shell32.dll-->kernel32.dll-->ReplaceFileW, Type: IAT modification 0x768E1140-->00000000 [IEShims.dll]
[5444]iexplore.exe-->shell32.dll-->kernel32.dll-->SearchPathW, Type: IAT modification 0x768E1384-->00000000 [IEShims.dll]
[5444]iexplore.exe-->shell32.dll-->kernel32.dll-->SetCurrentDirectoryW, Type: IAT modification 0x768E124C-->00000000 [IEShims.dll]
[5444]iexplore.exe-->shell32.dll-->kernel32.dll-->SetFileAttributesW, Type: IAT modification 0x768E13B8-->00000000 [IEShims.dll]
[5444]iexplore.exe-->shell32.dll-->kernel32.dll-->WritePrivateProfileSectionW, Type: IAT modification 0x768E1168-->00000000 [IEShims.dll]
[5444]iexplore.exe-->shell32.dll-->kernel32.dll-->WritePrivateProfileStringW, Type: IAT modification 0x768E116C-->00000000 [IEShims.dll]
[5444]iexplore.exe-->shell32.dll-->ntdll.dll-->NtQueryDirectoryFile, Type: IAT modification 0x768E2320-->00000000 [IEShims.dll]
[5444]iexplore.exe-->shell32.dll-->user32.dll-->LoadImageW, Type: IAT modification 0x768E1890-->00000000 [IEShims.dll]
[5444]iexplore.exe-->shell32.dll-->user32.dll-->PrivateExtractIconsW, Type: IAT modification 0x768E1A6C-->00000000 [IEShims.dll]
[5444]iexplore.exe-->shell32.dll-->user32.dll-->WinHelpW, Type: IAT modification 0x768E191C-->00000000 [IEShims.dll]
[5444]iexplore.exe-->user32.dll-->advapi32.dll-->RegCloseKey, Type: IAT modification 0x77D5154C-->00000000 [IEShims.dll]
[5444]iexplore.exe-->user32.dll-->advapi32.dll-->RegCreateKeyExW, Type: IAT modification 0x77D51548-->00000000 [IEShims.dll]
[5444]iexplore.exe-->user32.dll-->advapi32.dll-->RegDeleteKeyW, Type: IAT modification 0x77D51544-->00000000 [IEShims.dll]
[5444]iexplore.exe-->user32.dll-->advapi32.dll-->RegEnumValueW, Type: IAT modification 0x77D51524-->00000000 [IEShims.dll]
[5444]iexplore.exe-->user32.dll-->advapi32.dll-->RegOpenKeyExW, Type: IAT modification 0x77D51528-->00000000 [IEShims.dll]
[5444]iexplore.exe-->user32.dll-->advapi32.dll-->RegQueryInfoKeyW, Type: IAT modification 0x77D51520-->00000000 [IEShims.dll]
[5444]iexplore.exe-->user32.dll-->advapi32.dll-->RegQueryValueExW, Type: IAT modification 0x77D5152C-->00000000 [IEShims.dll]
[5444]iexplore.exe-->user32.dll-->CallNextHookEx, Type: Inline - RelativeJump 0x775A8E3B-->00000000 [ieframe.dll]
[5444]iexplore.exe-->user32.dll-->CreateDialogIndirectParamA, Type: Inline - RelativeJump 0x775C26F1-->00000000 [ieframe.dll]
[5444]iexplore.exe-->user32.dll-->CreateDialogIndirectParamW, Type: Inline - RelativeJump 0x775C9A62-->00000000 [ieframe.dll]
[5444]iexplore.exe-->user32.dll-->CreateDialogParamA, Type: Inline - RelativeJump 0x775C17AA-->00000000 [ieframe.dll]
[5444]iexplore.exe-->user32.dll-->CreateDialogParamW, Type: Inline - RelativeJump 0x775A72A2-->00000000 [ieframe.dll]
[5444]iexplore.exe-->user32.dll-->CreateWindowExW, Type: Inline - RelativeJump 0x775B1305-->00000000 [ieframe.dll]
[5444]iexplore.exe-->user32.dll-->DialogBoxIndirectParamA, Type: Inline - RelativeJump 0x775E847D-->00000000 [ieframe.dll]
[5444]iexplore.exe-->user32.dll-->DialogBoxIndirectParamW, Type: Inline - RelativeJump 0x775D2EF5-->00000000 [ieframe.dll]
[5444]iexplore.exe-->user32.dll-->DialogBoxParamA, Type: Inline - RelativeJump 0x775E8152-->00000000 [ieframe.dll]
[5444]iexplore.exe-->user32.dll-->DialogBoxParamW, Type: Inline - RelativeJump 0x775D10B0-->00000000 [ieframe.dll]
[5444]iexplore.exe-->user32.dll-->EnableWindow, Type: Inline - RelativeJump 0x775ACD8B-->00000000 [ieframe.dll]
[5444]iexplore.exe-->user32.dll-->EndDialog, Type: Inline - RelativeJump 0x775D326E-->00000000 [ieframe.dll]
[5444]iexplore.exe-->user32.dll-->GetAsyncKeyState, Type: Inline - RelativeJump 0x775A863C-->00000000 [ieframe.dll]
[5444]iexplore.exe-->user32.dll-->GetKeyState, Type: Inline - RelativeJump 0x775B8CB1-->00000000 [ieframe.dll]
[5444]iexplore.exe-->user32.dll-->IsDialogMessage, Type: Inline - RelativeJump 0x775C1847-->00000000 [ieframe.dll]
[5444]iexplore.exe-->user32.dll-->IsDialogMessageW, Type: Inline - RelativeJump 0x775C0745-->00000000 [ieframe.dll]
[5444]iexplore.exe-->user32.dll-->kernel32.dll-->CopyFileW, Type: IAT modification 0x77D511A8-->00000000 [IEShims.dll]
[5444]iexplore.exe-->user32.dll-->kernel32.dll-->CreateFileW, Type: IAT modification 0x77D512B8-->00000000 [IEShims.dll]
[5444]iexplore.exe-->user32.dll-->kernel32.dll-->CreateProcessW, Type: IAT modification 0x77D511B4-->00000000 [IEShims.dll]
[5444]iexplore.exe-->user32.dll-->kernel32.dll-->DeleteFileW, Type: IAT modification 0x77D511B0-->00000000 [IEShims.dll]
[5444]iexplore.exe-->user32.dll-->kernel32.dll-->FindClose, Type: IAT modification 0x77D511E4-->00000000 [IEShims.dll]
[5444]iexplore.exe-->user32.dll-->kernel32.dll-->FindFirstFileW, Type: IAT modification 0x77D511EC-->00000000 [IEShims.dll]
[5444]iexplore.exe-->user32.dll-->kernel32.dll-->FindNextFileW, Type: IAT modification 0x77D511E8-->00000000 [IEShims.dll]
[5444]iexplore.exe-->user32.dll-->kernel32.dll-->GetPrivateProfileStringW, Type: IAT modification 0x77D51328-->00000000 [IEShims.dll]
[5444]iexplore.exe-->user32.dll-->kernel32.dll-->GetProcAddress, Type: IAT modification 0x77D51300-->00000000 [IEShims.dll]
[5444]iexplore.exe-->user32.dll-->kernel32.dll-->LoadLibraryA, Type: IAT modification 0x77D51250-->00000000 [IEShims.dll]
[5444]iexplore.exe-->user32.dll-->kernel32.dll-->LoadLibraryExW, Type: IAT modification 0x77D5115C-->00000000 [IEShims.dll]
[5444]iexplore.exe-->user32.dll-->kernel32.dll-->LoadLibraryW, Type: IAT modification 0x77D512FC-->00000000 [IEShims.dll]
[5444]iexplore.exe-->user32.dll-->kernel32.dll-->MoveFileW, Type: IAT modification 0x77D511AC-->00000000 [IEShims.dll]
[5444]iexplore.exe-->user32.dll-->kernel32.dll-->SearchPathW, Type: IAT modification 0x77D51154-->00000000 [IEShims.dll]
[5444]iexplore.exe-->user32.dll-->kernel32.dll-->SetCurrentDirectoryW, Type: IAT modification 0x77D511D8-->00000000 [IEShims.dll]
[5444]iexplore.exe-->user32.dll-->kernel32.dll-->WritePrivateProfileStringW, Type: IAT modification 0x77D512BC-->00000000 [IEShims.dll]
[5444]iexplore.exe-->user32.dll-->keybd_event, Type: Inline - RelativeJump 0x775FD972-->00000000 [ieframe.dll]
[5444]iexplore.exe-->user32.dll-->MessageBoxExA, Type: Inline - RelativeJump 0x775FD639-->00000000 [ieframe.dll]
[5444]iexplore.exe-->user32.dll-->MessageBoxExW, Type: Inline - RelativeJump 0x775FD65D-->00000000 [ieframe.dll]
[5444]iexplore.exe-->user32.dll-->MessageBoxIndirectA, Type: Inline - RelativeJump 0x775FD4D9-->00000000 [ieframe.dll]
[5444]iexplore.exe-->user32.dll-->MessageBoxIndirectW, Type: Inline - RelativeJump 0x775FD5D3-->00000000 [ieframe.dll]
[5444]iexplore.exe-->user32.dll-->SendInput, Type: Inline - RelativeJump 0x775D2F75-->00000000 [ieframe.dll]
[5444]iexplore.exe-->user32.dll-->SetCursorPos, Type: Inline - RelativeJump 0x775E6FB2-->00000000 [ieframe.dll]
[5444]iexplore.exe-->user32.dll-->SetKeyboardState, Type: Inline - RelativeJump 0x775D0987-->00000000 [ieframe.dll]
[5444]iexplore.exe-->user32.dll-->SetWindowsHookExW, Type: Inline - RelativeJump 0x775A87AD-->00000000 [ieframe.dll]
[5444]iexplore.exe-->user32.dll-->UnhookWindowsHookEx, Type: Inline - RelativeJump 0x775A98DB-->00000000 [ieframe.dll]
[5444]iexplore.exe-->wininet.dll-->kernel32.dll-->GetProcAddress, Type: IAT modification 0x704114B0-->00000000 [IEShims.dll]
[5444]iexplore.exe-->ws2_32.dll-->kernel32.dll-->GetProcAddress, Type: IAT modification 0x4B0D11E8-->00000000 [IEShims.dll]
[5484]FlashUtil10h_ActiveX.exe-->kernel32.dll-->LoadLibraryExW, Type: Inline - DirectJump 0x76839109-->00000000 [unknown_code_page]
[5484]FlashUtil10h_ActiveX.exe-->ws2_32.dll-->accept, Type: Inline - DirectJump 0x762FBDF6-->00000000 [unknown_code_page]
[5484]FlashUtil10h_ActiveX.exe-->ws2_32.dll-->closesocket, Type: Inline - DirectJump 0x762E330C-->00000000 [unknown_code_page]
[5484]FlashUtil10h_ActiveX.exe-->ws2_32.dll-->connect, Type: Inline - DirectJump 0x762E40D9-->00000000 [unknown_code_page]
[5484]FlashUtil10h_ActiveX.exe-->ws2_32.dll-->htons, Type: Inline - DirectJump 0x762E3010-->00000000 [unknown_code_page]
[5484]FlashUtil10h_ActiveX.exe-->ws2_32.dll-->WSAAccept, Type: Inline - DirectJump 0x762FBB56-->00000000 [unknown_code_page]
[5484]FlashUtil10h_ActiveX.exe-->ws2_32.dll-->WSAAsyncSelect, Type: Inline - DirectJump 0x762FA17C-->00000000 [unknown_code_page]
[5484]FlashUtil10h_ActiveX.exe-->ws2_32.dll-->WSAConnect, Type: Inline - DirectJump 0x762ED7B0-->00000000 [unknown_code_page]
[5484]FlashUtil10h_ActiveX.exe-->ws2_32.dll-->WSAEventSelect, Type: Inline - DirectJump 0x762E5BFA-->00000000 [unknown_code_page]
[5932]nscrnsav.scr-->kernel32.dll-->LoadLibraryExW, Type: Inline - DirectJump 0x76839109-->00000000 [unknown_code_page]
[5932]nscrnsav.scr-->ws2_32.dll-->accept, Type: Inline - DirectJump 0x762FBDF6-->00000000 [unknown_code_page]
[5932]nscrnsav.scr-->ws2_32.dll-->closesocket, Type: Inline - DirectJump 0x762E330C-->00000000 [unknown_code_page]
[5932]nscrnsav.scr-->ws2_32.dll-->connect, Type: Inline - DirectJump 0x762E40D9-->00000000 [unknown_code_page]
[5932]nscrnsav.scr-->ws2_32.dll-->htons, Type: Inline - DirectJump 0x762E3010-->00000000 [unknown_code_page]
[5932]nscrnsav.scr-->ws2_32.dll-->WSAAccept, Type: Inline - DirectJump 0x762FBB56-->00000000 [unknown_code_page]
[5932]nscrnsav.scr-->ws2_32.dll-->WSAAsyncSelect, Type: Inline - DirectJump 0x762FA17C-->00000000 [unknown_code_page]
[5932]nscrnsav.scr-->ws2_32.dll-->WSAConnect, Type: Inline - DirectJump 0x762ED7B0-->00000000 [unknown_code_page]
[5932]nscrnsav.scr-->ws2_32.dll-->WSAEventSelect, Type: Inline - DirectJump 0x762E5BFA-->00000000 [unknown_code_page]
magic
Regular Member
 
Posts: 28
Joined: June 8th, 2010, 5:36 pm

Re: Alureon H removal

Unread postby Airscape » June 28th, 2010, 2:56 pm

Hi magic,

I'm afraid this seems to be a false positive, or either you need to allow HitmanPro to clean/remove instead of adding to quarantine.
If that doesn't work, please try uninstalling HitmanPro via control panel > programs and features before these instructions, then reinstalling after the instructions.

While in programs and features also remove Spybot S&D, you can install again after running ComboFix.

Delete any previous versions of ComboFix and download a new one from Here. Save it directly to the desktop and run it as before.
Please post back with the C:\ComboFix.txt log, and try reinstalling HitmanPro to see if it still detects anything.
User avatar
Airscape
Regular Member
 
Posts: 1858
Joined: November 1st, 2008, 11:06 pm

Re: Alureon H removal

Unread postby magic » June 28th, 2010, 5:15 pm

Hi thank you.

Have uninstalled Hitman Pro and Spybot S&D. After running the ComboFix, i re-installed Hitman Pro which still picks up the RDPENCDD.sys as malware.

Here is the new ComboFix.txt log:

ComboFix 10-06-27.06 - owner 28/06/2010 20:41:43.3.2 - x86
Microsoft® Windows Vista™ Home Premium 6.0.6002.2.1252.44.1033.18.3034.1861 [GMT 1:00]
Running from: c:\users\owner\Desktop\ComboFix.exe
SP: Windows Defender *enabled* (Updated) {D68DDC3A-831F-4FAE-9E44-DA132C1ACF46}
* Resident AV is active

.

((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.

c:\windows\TEMP\logishrd\LVPrcInj01.dll
.
---- Previous Run -------
.
c:\windows\look.bat

.
((((((((((((((((((((((((( Files Created from 2010-05-28 to 2010-06-28 )))))))))))))))))))))))))))))))
.

2010-06-28 19:59 . 2010-06-28 19:59 -------- d-----w- c:\users\Public\AppData\Local\temp
2010-06-28 19:59 . 2010-06-28 19:59 -------- d-----w- c:\users\Default\AppData\Local\temp
2010-06-25 06:53 . 2010-06-28 20:03 -------- d-----w- c:\users\owner\AppData\Local\temp
2010-06-23 19:48 . 2009-11-08 09:55 99176 ----a-w- c:\windows\system32\PresentationHostProxy.dll
2010-06-23 19:48 . 2009-11-08 09:55 49472 ----a-w- c:\windows\system32\netfxperf.dll
2010-06-23 19:48 . 2009-11-08 09:55 297808 ----a-w- c:\windows\system32\mscoree.dll
2010-06-23 19:48 . 2009-11-08 09:55 295264 ----a-w- c:\windows\system32\PresentationHost.exe
2010-06-23 19:48 . 2009-11-08 09:55 1130824 ----a-w- c:\windows\system32\dfshim.dll
2010-06-23 19:46 . 2010-04-16 16:43 28672 ----a-w- c:\windows\system32\Apphlpdm.dll
2010-06-23 19:46 . 2010-04-16 14:39 4240384 ----a-w- c:\windows\system32\GameUXLegacyGDFs.dll
2010-06-22 18:25 . 2010-06-07 15:16 220024 ----a-w- c:\windows\sigcheck.exe
2010-06-22 18:14 . 2010-06-22 18:14 -------- d-----w- c:\windows\maxdrive
2010-06-21 18:44 . 2010-06-21 18:44 -------- d-----w- C:\$WINDOWS.~BT
2010-06-20 20:08 . 2010-06-20 20:08 -------- d-----w- c:\program files\Trellian
2010-06-17 08:45 . 2010-05-28 10:40 30584 ----a-w- c:\windows\system32\drivers\nnetsecl.sys
2010-06-17 08:45 . 2010-05-25 12:28 34192 ----a-w- c:\windows\system32\drivers\nnetsecl64.sys
2010-06-12 17:03 . 2010-06-12 17:03 -------- d-----w- c:\program files\trend micro
2010-06-12 17:03 . 2010-06-12 17:04 -------- d-----w- C:\rsit
2010-06-10 10:59 . 2010-06-10 10:59 -------- d-----w- c:\windows\system32\20-20 Technologies
2010-06-09 14:51 . 2010-06-09 14:51 -------- d-----w- c:\program files\Enigma Software Group
2010-06-08 20:37 . 2010-06-08 20:37 -------- d-----w- C:\MGADiagToolOutput
2010-06-07 21:30 . 2010-06-28 06:32 16968 ----a-w- c:\windows\system32\drivers\hitmanpro35.sys
2010-06-07 21:29 . 2010-06-08 07:14 -------- d-----w- c:\programdata\Hitman Pro
2010-06-07 21:29 . 2010-06-07 21:29 -------- d-----w- c:\program files\Hitman Pro 3.5
2010-06-07 20:40 . 2010-05-19 07:37 67664 ----a-w- c:\windows\system32\drivers\ale_nf64.sys
2010-06-07 20:40 . 2010-05-14 08:35 48272 ----a-w- c:\windows\system32\drivers\nnetsec.sys
2010-06-07 20:40 . 2010-05-10 08:13 376136 ----a-w- c:\windows\system32\drivers\tdi_nf.sys
2010-06-07 20:21 . 2010-05-19 07:36 60960 ----a-w- c:\windows\system32\drivers\ale_nf.sys
2010-06-07 20:21 . 2009-10-07 12:22 76944 ----a-w- c:\windows\system32\drivers\tdi_rd.sys
2010-06-07 20:21 . 2009-10-07 12:20 82072 ----a-w- c:\windows\system32\drivers\ndis_rd.sys
2010-06-07 20:21 . 2009-10-14 11:03 23392 ----a-w- c:\windows\system32\drivers\nvcv32mf.sys
2010-06-07 20:21 . 2009-10-11 13:06 214344 ----a-w- c:\windows\system32\nscrnsav.scr
2010-06-06 19:52 . 2010-06-07 06:59 -------- d-----w- c:\windows\system32\MpEngineStore
2010-06-05 10:23 . 2010-06-28 20:01 -------- d-----w- c:\program files\Spybot - Search & Destroy
2010-06-05 10:23 . 2010-06-28 19:29 -------- d-----w- c:\programdata\Spybot - Search & Destroy
2010-06-03 07:00 . 2010-05-21 13:14 221568 ------w- c:\windows\system32\MpSigStub.exe
2010-06-02 21:48 . 2010-06-07 20:40 -------- d-----w- c:\program files\Norman

.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2010-06-28 19:23 . 2009-12-01 22:21 -------- d-----w- c:\users\owner\AppData\Roaming\LPC
2010-06-23 19:50 . 2009-05-31 19:51 -------- d-----w- c:\program files\Microsoft.NET
2010-06-20 15:47 . 2009-06-28 18:33 -------- d-----w- c:\users\owner\AppData\Roaming\Skype
2010-06-20 15:06 . 2009-06-28 18:37 -------- d-----w- c:\users\owner\AppData\Roaming\skypePM
2010-06-17 22:32 . 2010-04-28 11:01 -------- d-----w- c:\program files\QuickTime
2010-06-17 22:32 . 2010-04-20 20:37 -------- d-----w- c:\program files\Malwarebytes' Anti-Malware
2010-06-17 22:32 . 2010-04-28 11:05 -------- d-----w- c:\program files\iTunes
2010-06-11 07:50 . 2006-11-02 11:18 -------- d-----w- c:\program files\Windows Mail
2010-06-11 07:40 . 2009-05-31 19:48 -------- d-----w- c:\programdata\Microsoft Help
2010-06-09 14:51 . 2009-06-04 21:12 -------- d-----w- c:\program files\Common Files\Wise Installation Wizard
2010-06-07 18:29 . 2008-01-21 02:24 6144 ----a-w- c:\windows\system32\drivers\RDPENCDD.sys
2010-06-07 17:45 . 2009-08-02 20:20 -------- d-----w- c:\users\owner\AppData\Roaming\CoreFTP
2010-06-07 17:45 . 2009-12-09 07:52 -------- d-----w- c:\program files\Microsoft Silverlight
2010-06-07 17:45 . 2009-08-02 19:57 -------- d-----w- c:\program files\SmartFTP Client
2010-06-07 17:45 . 2010-04-28 10:53 -------- d-----w- c:\program files\Bonjour
2010-06-07 06:52 . 2009-05-17 12:48 6756 ----a-w- c:\users\owner\AppData\Local\d3d9caps.dat
2010-06-05 19:20 . 2010-04-22 18:09 411368 ----a-w- c:\windows\system32\deployJava1.dll
2010-05-26 17:06 . 2010-06-10 16:12 34304 ----a-w- c:\windows\system32\atmlib.dll
2010-05-26 14:47 . 2010-06-10 16:12 289792 ----a-w- c:\windows\system32\atmfd.dll
2010-05-23 11:00 . 2010-04-10 09:54 -------- d-----w- c:\program files\Google
2010-05-08 17:43 . 2010-05-08 14:45 -------- d-----w- c:\programdata\WinZip
2010-05-04 05:59 . 2010-06-10 16:12 916480 ----a-w- c:\windows\system32\wininet.dll
2010-05-04 05:55 . 2010-06-10 16:12 71680 ----a-w- c:\windows\system32\iesetup.dll
2010-05-04 05:55 . 2010-06-10 16:12 109056 ----a-w- c:\windows\system32\iesysprep.dll
2010-05-04 04:31 . 2010-06-10 16:12 133632 ----a-w- c:\windows\system32\ieUnatt.exe
2010-05-01 14:13 . 2010-06-10 16:12 2037248 ----a-w- c:\windows\system32\win32k.sys
2010-04-29 14:39 . 2010-04-20 20:37 38224 ----a-w- c:\windows\system32\drivers\mbamswissarmy.sys
2010-04-29 14:39 . 2010-04-20 20:37 20952 ----a-w- c:\windows\system32\drivers\mbam.sys
2010-04-23 14:13 . 2010-05-25 17:57 2048 ----a-w- c:\windows\system32\tzres.dll
2010-04-16 07:33 . 2010-04-16 07:33 41472 ----a-w- c:\windows\system32\drivers\usbaapl.sys
2010-04-16 07:33 . 2010-04-16 07:33 3003680 ----a-w- c:\windows\system32\usbaaplrc.dll
2010-04-08 12:20 . 2010-04-08 12:20 91424 ----a-w- c:\windows\system32\dnssd.dll
2010-04-08 12:20 . 2010-04-08 12:20 107808 ----a-w- c:\windows\system32\dns-sd.exe
2010-04-05 17:01 . 2010-06-10 16:12 67072 ----a-w- c:\windows\system32\asycfilt.dll
2009-05-17 13:42 . 2009-05-17 13:42 76 --sh--r- c:\windows\CT4CET.bin
.

((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Sidebar"="c:\program files\windows sidebar\sidebar.exe" [2009-04-11 1233920]
"PC Suite Tray"="c:\program files\Nokia\Nokia PC Suite 7\PCSuite.exe" [2009-11-11 1451520]
"msnmsgr"="c:\program files\Windows Live\Messenger\msnmsgr.exe" [2009-07-26 3883856]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Windows Defender"="c:\program files\Windows Defender\MSASCui.exe" [2008-01-21 1008184]
"IgfxTray"="c:\windows\system32\igfxtray.exe" [2008-11-11 150040]
"HotKeysCmds"="c:\windows\system32\hkcmd.exe" [2008-11-11 178712]
"Persistence"="c:\windows\system32\igfxpers.exe" [2008-11-11 154136]
"Broadcom Wireless Manager UI"="c:\windows\system32\WLTRAY.exe" [2008-11-17 3810304]
"PDVDDXSrv"="c:\program files\CyberLink\PowerDVD DX\PDVDDXSrv.exe" [2008-05-23 128296]
"Adobe Reader Speed Launcher"="c:\program files\Adobe\Reader 9.0\Reader\Reader_sl.exe" [2010-04-04 36272]
"Adobe ARM"="c:\program files\Common Files\Adobe\ARM\1.0\AdobeARM.exe" [2010-03-24 952768]
"QuickTime Task"="c:\program files\QuickTime\QTTask.exe" [2010-03-17 421888]
"iTunesHelper"="c:\program files\iTunes\iTunesHelper.exe" [2010-04-24 142120]
"SunJavaUpdateSched"="c:\program files\Common Files\Java\Java Update\jusched.exe" [2010-02-18 248040]
"Norman ZANDA"="c:\program files\Norman\Npm\Bin\ZLH.EXE" [2009-11-24 189824]
"NPCTray"="c:\program files\Norman\npc\bin\npc_tray.exe" [2010-02-22 93616]
"NOELauncher"="c:\program files\Norman\nsc\bin\noelauncher.exe" [2010-03-23 74056]
"LogitechQuickCamRibbon"="c:\program files\Logitech\QuickCam\Quickcam.exe" [2008-12-20 2656528]

c:\users\owner\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\
Logitech . Product Registration.lnk - c:\program files\Logitech\QuickCam\eReg.exe [2008-11-7 517384]

c:\programdata\Microsoft\Windows\Start Menu\Programs\Startup\
Adobe Gamma Loader.lnk - c:\program files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe [2009-7-31 113664]

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"EnableUIADesktopToggle"= 0 (0x0)

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\drivers32]
"aux4"=wdmaud.drv

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\MSIServer]
@="Service"

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\WinDefend]
@="Service"

[HKEY_LOCAL_MACHINE\software\microsoft\security center\Svc]
"VistaSp2"=hex(b):d3,de,9a,2f,25,3a,ca,01

R2 clr_optimization_v4.0.30319_32;Microsoft .NET Framework NGEN v4.0.30319_X86;c:\windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe [2010-03-18 130384]
R2 gupdate;Google Update Service (gupdate);c:\program files\Google\Update\GoogleUpdate.exe [2010-04-10 136176]
R3 NASS;Norman Anti Spam Service;c:\program files\Norman\nsc\bin\nassvc32.exe [2010-03-23 133832]
R3 nsesvc;Norman Scanner Engine Service;c:\program files\Norman\Nse\Bin\NSESVC.EXE [2010-06-14 282624]
R3 NUAA;Norman User Activity Agent;c:\program files\Norman\npc\bin\nuaa.exe [2009-10-11 99656]
R3 NvcMFlt;NvcMFlt;c:\windows\system32\DRIVERS\nvcv32mf.sys [2009-10-14 23392]
R3 nvcoas;Norman Virus Control on-access component;c:\program files\Norman\Nvc\Bin\nvcoas.exe [2010-05-21 202056]
R3 Scheduler;Norman Scheduler Service;c:\program files\Norman\Npm\Bin\scheduler.exe [2009-10-15 133272]
R3 WPFFontCache_v0400;Windows Presentation Foundation Font Cache 4.0.0.0;c:\windows\Microsoft.NET\Framework\v4.0.30319\WPF\WPFFontCache_v0400.exe [2010-03-18 753504]
S1 ALE_NF;Norman Network Filter ALE driver;c:\windows\system32\drivers\ale_nf.sys [2010-05-19 60960]
S1 NGS;Norman General Security Driver;c:\program files\norman\ngs\bin\ngs.sys [2010-01-04 26744]
S1 NPROSEC;Norman Security driver;c:\program files\Norman\Ngs\Bin\nprosec.sys [2010-05-10 72392]
S2 Ndiskio;Ndiskio;c:\program files\Norman\Nse\Bin\NDISKIO.SYS [2009-10-09 22880]
S2 NNFSVC;Norman Network Filtering service;c:\program files\Norman\Ngs\Bin\Nnf.exe [2010-05-07 210640]
S2 NPFSvc32;Norman Personal Firewall Service;c:\program files\Norman\npf\bin\npfsvc32.exe [2010-06-02 286328]
S2 NPROSECSVC;Norman Security service;c:\program files\Norman\Ngs\Bin\Nprosec.exe [2010-05-07 103016]
S2 nregsec;Norman Registry Security driver;c:\program files\Norman\Ngs\Bin\nregsec.sys [2010-05-14 40384]
S2 NVOY;Norman Resource Provider;c:\program files\Norman\npm\bin\nvoy.exe [2010-03-15 98776]
S2 sprtsvc_TalkTalk;SupportSoft Sprocket Service (TalkTalk);c:\program files\TalkTalk\bin\sprtsvc.exe [2007-10-12 202016]
S2 tgsrvc_TalkTalk;SupportSoft Repair Service (TalkTalk);c:\program files\Common Files\Supportsoft\bin\tgsrvc.exe [2007-08-02 148768]
S2 TomTomHOMEService;TomTomHOMEService;c:\program files\TomTom HOME 2\TomTomHOMEService.exe [2009-08-19 92008]
S2 yksvc;Marvell Yukon Service;RUNDLL32.EXE ykx32coinst,serviceStartProc [x]


[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost]
LocalServiceAndNoImpersonation REG_MULTI_SZ FontCache
.
Contents of the 'Scheduled Tasks' folder

2010-06-28 c:\windows\Tasks\GoogleUpdateTaskMachineCore.job
- c:\program files\Google\Update\GoogleUpdate.exe [2010-04-10 09:54]

2010-06-28 c:\windows\Tasks\GoogleUpdateTaskMachineUA.job
- c:\program files\Google\Update\GoogleUpdate.exe [2010-04-10 09:54]
.
.
------- Supplementary Scan -------
.
uStart Page = hxxp://login.live.com/login.srf?wa=wsig ... &mkt=en-gb
uInternet Settings,ProxyOverride = *.local
DPF: {1C11B948-582A-433F-A98D-A8C4D5CC64F2} - hxxp://bq.kp.2020.net/planner/Core/Play ... _Win32.cab
DPF: {96816368-C1E3-414D-A193-63C3CC921990} - hxxp://holidaystore-sitges.remotemanage ... Render.ocx
.

**************************************************************************
scanning hidden processes ...

scanning hidden autostart entries ...

scanning hidden files ...

scan completed successfully
hidden files:

**************************************************************************
.
------------------------ Other Running Processes ------------------------
.
c:\program files\Norman\Npm\Bin\Elogsvc.exe
c:\program files\Norman\Npm\Bin\Zanda.exe
c:\windows\System32\WLTRYSVC.EXE
c:\windows\System32\bcmwltry.exe
c:\program files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe
c:\program files\Bonjour\mDNSResponder.exe
c:\program files\Common Files\LogiShrd\LVMVFM\LVPrcSrv.exe
c:\windows\system32\RUNDLL32.EXE
c:\windows\system32\wbem\unsecapp.exe
c:\windows\servicing\TrustedInstaller.exe
c:\windows\system32\nscrnsav.scr
.
**************************************************************************
.
Completion time: 2010-06-28 21:12:14 - machine was rebooted
ComboFix-quarantined-files.txt 2010-06-28 20:12
ComboFix2.txt 2010-06-17 23:02
ComboFix3.txt 2010-06-15 21:55

Pre-Run: 110,335,205,376 bytes free
Post-Run: 110,346,813,440 bytes free

- - End Of File - - 9926F107CDF2A77660D04D3AC6123A70
magic
Regular Member
 
Posts: 28
Joined: June 8th, 2010, 5:36 pm

Re: Alureon H removal

Unread postby Airscape » June 29th, 2010, 12:40 pm

OK, Still no evidence that what Hitman Pro is showing is true. Is it possible to configure Hitman Pro to ignore the RDPENCDD.sys file?

Go to VirusTotal or Jotti to upload the file.
Click the browse button next to the white box.
Copy/paste the following into the file name box:

c:\windows\maxdrive\RDPENCDD.sys

Click Open.
Click Send/Submit, and the file will be scanned for malware.
After a while, a window will open, with details of what the scans found.
Note details of any viruses found, and post the results/links in your next reply.

Note:If the file has been scanned before, It's very important that you reanalyze the file if asked.
User avatar
Airscape
Regular Member
 
Posts: 1858
Joined: November 1st, 2008, 11:06 pm

Re: Alureon H removal

Unread postby magic » June 29th, 2010, 2:15 pm

Thanks, below is the log as requested.

We it does not appear that you can prevent hitman pro from scanning that file. However we assume the results below indicate that the file may still be infected?

Thanks


File RDPENCDD.sys received on 2010.06.29 18:02:58 (UTC)
Current status: Loading ... queued waiting scanning finished NOT FOUND STOPPED


Result: 3/41 (7.32%)
Loading server information...
Your file is queued in position: 1.
Estimated start time is between 42 and 60 seconds.
Do not close the window until scan is complete.
The scanner that was processing your file is stopped at this moment, we are going to wait a few seconds to try to recover your result.
If you are waiting for more than five minutes you have to resend your file.
Your file is being scanned by VirusTotal in this moment,
results will be shown as they're generated.
Compact Print results Your file has expired or does not exists.
Service is stopped in this moments, your file is waiting to be scanned (position: ) for an undefined time.
You can wait for web response (automatic reload) or type your email in the form below and click "request" so the system sends you a notification when the scan is finished. Email:


Antivirus Version Last Update Result
a-squared 5.0.0.31 2010.06.29 -
AhnLab-V3 2010.06.29.00 2010.06.29 -
AntiVir 8.2.4.2 2010.06.29 -
Antiy-AVL 2.0.3.7 2010.06.25 -
Authentium 5.2.0.5 2010.06.29 -
Avast 4.8.1351.0 2010.06.29 Win32:Alureon-FZ
Avast5 5.0.332.0 2010.06.29 Win32:Alureon-FZ
AVG 9.0.0.836 2010.06.29 -
BitDefender 7.2 2010.06.29 -
CAT-QuickHeal 10.00 2010.06.29 -
ClamAV 0.96.0.3-git 2010.06.29 -
Comodo 5257 2010.06.29 -
DrWeb 5.0.2.03300 2010.06.29 -
eSafe 7.0.17.0 2010.06.29 -
eTrust-Vet 36.1.7674 2010.06.29 -
F-Prot 4.6.1.107 2010.06.29 -
F-Secure 9.0.15370.0 2010.06.29 -
Fortinet 4.1.133.0 2010.06.29 -
GData 21 2010.06.29 Win32:Alureon-FZ
Ikarus T3.1.1.84.0 2010.06.29 -
Jiangmin 13.0.900 2010.06.27 -
Kaspersky 7.0.0.125 2010.06.29 -
McAfee 5.400.0.1158 2010.06.29 -
McAfee-GW-Edition 2010.1 2010.06.29 -
Microsoft 1.5902 2010.06.29 -
NOD32 5238 2010.06.29 -
Norman 6.05.10 2010.06.29 -
nProtect 2010-06-29.01 2010.06.29 -
Panda 10.0.2.7 2010.06.29 -
PCTools 7.0.3.5 2010.06.29 -
Prevx 3.0 2010.06.29 -
Rising 22.54.01.03 2010.06.29 -
Sophos 4.54.0 2010.06.29 -
Sunbelt 6522 2010.06.29 -
Symantec 20101.1.0.89 2010.06.29 -
TheHacker 6.5.2.0.304 2010.06.28 -
TrendMicro 9.120.0.1004 2010.06.29 -
TrendMicro-HouseCall 9.120.0.1004 2010.06.29 -
VBA32 3.12.12.5 2010.06.29 -
ViRobot 2010.6.29.3912 2010.06.29 -
VirusBuster 5.0.27.0 2010.06.29 -
Additional information
File size: 6144 bytes
MD5...: e6c6deac7256b5a37c7a31c81d34d2a3
SHA1..: b2c66d79042e6d42ec4c659daf452d64a6cacebc
SHA256: 592994cb5f71a287e7bb1760c1ebf0042e4b58c4e7dd7d0be53e28d3f51a4b54
ssdeep: 48:qdKmGRcE7qRUnekbGeqUWc2qUW0QqJiWjdM+XZCeTBo49MUz:SKXRehcFhMtj
dfp

PEiD..: -
PEInfo: PE Structure information

( base data )
entrypointaddress.: 0x5005
timedatestamp.....: 0x47919225 (Sat Jan 19 06:01:09 2008)
machinetype.......: 0x14c (I386)

( 7 sections )
name viradd virsiz rawdsiz ntrpy md5
.rdata 0x1000 0x61 0x200 0.96 0c3fcad1d46527ff681ef270db73b53d
.data 0x2000 0x8 0x200 0.16 0b2e7741e0c0fc65af1542e370d89f53
PAGE 0x3000 0x478 0x600 4.29 8e06161e175b193a179fb6770d65ab12
PAGE 0x4000 0x58 0x200 0.21 4e2b01a0cb67c40d66dd8ca3c3d45984
INIT 0x5000 0x106 0x200 2.83 decc06f7ec35e49ab5450a0d5ea7dd7e
.rsrc 0x6000 0x3e8 0x400 5.89 fa139b89cdd765f680a7e6c867ef0ad0
.reloc 0x7000 0x78 0x200 0.89 c6bd1c742ec12f83121ed740f11873ae

( 2 imports )
> ntoskrnl.exe: KeTickCount, RtlWriteRegistryValue
> VIDEOPRT.SYS: VideoPortZeroMemory, VideoPortInitialize

( 0 exports )

RDS...: NSRL Reference Data Set
-
trid..: Generic Win/DOS Executable (49.9%)
DOS Executable Generic (49.8%)
Autodesk FLIC Image File (extensions: flc, fli, cel) (0.1%)
Symantec Reputation Network: Suspicious.Insight http://www.symantec.com/security_respon ... 23-0550-99
pdfid.: -
sigcheck:
publisher....: n/a
copyright....: n/a
product......: n/a
description..: n/a
original name: n/a
internal name: n/a
file version.: n/a
comments.....: n/a
signers......: -
signing date.: -
verified.....: Unsigned
magic
Regular Member
 
Posts: 28
Joined: June 8th, 2010, 5:36 pm

Re: Alureon H removal

Unread postby Airscape » June 30th, 2010, 1:53 pm

Yes it does show an infection, though it may not be active.


View Hidden Files & Folders
To view Hidden Files & Folders do the following:
Click Start
Open Computer
Select the Tools menu and click Folder Options
Select the View Tab
Under the Hidden files and folders heading select Show hidden files and folders
Uncheck the Hide protected operating system files (recommended) option
Click Yes to confirm
Click OK

Note: Doing the above will show hidden system files on the desktop and else where. Do Not try to delete/modify these files, it will damage the pc.

~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~

You may want to print off this post, you wont have access to the site during some instructions.

Please navigate to the file below using Start > Computer > (C:) then right click on the file and copy it.

C:\Windows.old\Windows\winsxs\x86_microsoft-windows-t..llaboration-drivers_31bf3856ad364e35_6.0.6001.18000_none_06cf4b56d5c130dc\RDPENCDD.sys

Now right-click and select paste on an empty space on the C:\ drive (next to the Windows folder).... there should now be a copy of the file above directly on the C drive.


Please now boot into the Vista Recovery Environment as you did earlier in this post.
To do so, restart your computer and begin tapping the F8 key to enable the Advanced Start menu > select Repair your computer

At the System Recovery options screen select Command prompt


Type the following into the command prompt and hit Enter (note the spaces)


ren C:\WINDOWS\system32\drivers\RDPENCDD.sys C:\WINDOWS\system32\drivers\RDPENCDD.sys.old


Type the following into the command prompt and hit Enter (note the spaces)


copy c:\rdpencdd.sys c:\windows\system32\drivers\rdpencdd.sys
exit



Click Restart at the main screen and restart the pc into Normal Mode.

Please post a new HijackThis log when finished and an update on the problem.
User avatar
Airscape
Regular Member
 
Posts: 1858
Joined: November 1st, 2008, 11:06 pm

Re: Alureon H removal

Unread postby magic » June 30th, 2010, 3:33 pm

Thanks for the above.

When we try and carry out the ren command in the system reocvery x sources promt it states the syntax is incorrect, please advise.

Thanks
magic
Regular Member
 
Posts: 28
Joined: June 8th, 2010, 5:36 pm

Re: Alureon H removal

Unread postby Airscape » June 30th, 2010, 11:54 pm

Hi magic,
You may want to print off this post if possible. If no printer then write it down, it's fairly short, note the spaces though.
Assuming the file is still on the c drive, please do the following.
Restart your computer and begin tapping the F8 key to enable the Advanced Start menu > select Repair your computer
At the System Recovery options screen select Command prompt

Type the following at the c:\windows\system32> prompt and hit Enter (note the spaces)

cd C:\

Type the following at the C:\ prompt and hit Enter (note the spaces)

ren C:\WINDOWS\system32\drivers\RDPENCDD.sys C:\WINDOWS\system32\drivers\RDPENCDD.sys.old

Type the following at the C:\ prompt and hit Enter (note the spaces)

copy c:\rdpencdd.sys c:\windows\system32\drivers\rdpencdd.sys

Finally type exit > hit Enter > click Restart at the main screen, and restart the pc normally.


Please provide an update on the problem when done.
User avatar
Airscape
Regular Member
 
Posts: 1858
Joined: November 1st, 2008, 11:06 pm

Re: Alureon H removal

Unread postby magic » July 1st, 2010, 3:40 am

Thanks for the revised instructions however how do we get a c:\windows\system32>prompt ?

We we access the system recovery command promt it is at the x sources stage
(we tried typing c:\windows\system32 in the x sources promt but this produced an error as well)

So we tried: cd c:windows\system32

the: cd c:\

which produce: c:\> promt
then typed ren<space><filename><space><filename>

but it still returned syntax error - are we doing something wrong?

Look forward to hearing from you.
magic
Regular Member
 
Posts: 28
Joined: June 8th, 2010, 5:36 pm

Re: Alureon H removal

Unread postby Airscape » July 1st, 2010, 8:17 pm

Hi magic, sorry this should work. Make sure the copied rdpencdd.sys file is still on the c: drive as explained above.



Restart your computer and begin tapping the F8 key to enable the Advanced Start menu > select Repair your computer
At the System Recovery options screen select Command prompt


Type the following at the first prompt and hit Enter (note the spaces)

cd /d C:\windows\system32\drivers

Type the following at the C:\windows\system32\drivers> prompt and hit Enter (note the spaces)

ren C:\WINDOWS\system32\drivers\RDPENCDD.sys RDPENCDD.sys.old

Type the following at the C:\windows\system32\drivers prompt and hit Enter (note the spaces)

cd /d C:\

Type the following at the C:\ prompt and hit Enter (note the spaces)

copy c:\rdpencdd.sys c:\windows\system32\drivers\rdpencdd.sys



Finally type exit > hit Enter > click Restart at the main screen, and restart the pc normally.


Please provide an update on the problem when done.
User avatar
Airscape
Regular Member
 
Posts: 1858
Joined: November 1st, 2008, 11:06 pm
Advertisement
Register to Remove

PreviousNext

  • Similar Topics
    Replies
    Views
    Last post

Return to Infected? Virus, malware, adware, ransomware, oh my!



Who is online

Users browsing this forum: No registered users and 63 guests

Contact us:

Advertisements do not imply our endorsement of that product or service. Register to remove all ads. The forum is run by volunteers who donate their time and expertise. We make every attempt to ensure that the help and advice posted is accurate and will not cause harm to your computer. However, we do not guarantee that they are accurate and they are to be used at your own risk. All trademarks are the property of their respective owners.

Member site: UNITE Against Malware