Welcome to MalwareRemoval.com,
What if we told you that you could get malware removal help from experts, and that it was 100% free? MalwareRemoval.com provides free support for people with infected computers. Our help, and the tools we use are always 100% free. No hidden catch. We simply enjoy helping others. You enjoy a clean, safe computer.

Malware Removal Instructions

Help needed with browser hijack

MalwareRemoval.com provides free support for people with infected computers. Using plain language that anyone can understand, our community of volunteer experts will walk you through each step.

Help needed with browser hijack

Unread postby dcowie » January 24th, 2010, 10:04 am

I have picked up a nasty little virus. Prime symptom is hijacked search results, i.e. when I click on a link returned by my search engine, I get re-directed to some marketing site. Also experiencing crashes and shutdowns - i.e. DCOM Server Process launcher Terminated warning followed by shutdown. I have run scans with Spybot and Malwarebytes with no success. The requested HijackThis logs are below. Many thanks in advance for any assistance anyone can offer.


Logfile of Trend Micro HijackThis v2.0.3 (BETA)
Scan saved at 8:42:33 AM, on 24/01/2010
Platform: Windows Vista SP2 (WinNT 6.00.1906)
MSIE: Internet Explorer v8.00 (8.00.6001.18882)
Boot mode: Normal

Running processes:
C:\Windows\system32\taskeng.exe
C:\Windows\system32\Dwm.exe
C:\Windows\Explorer.EXE
C:\Program Files\Windows Defender\MSASCui.exe
C:\Program Files\Common Files\InstallShield\UpdateService\issch.exe
C:\Windows\RtHDVCpl.exe
C:\Program Files\Dell Support Center\bin\sprtcmd.exe
C:\Program Files\Adobe\Adobe Version Cue\ControlPanel\VersionCueTray.exe
C:\Windows\System32\rundll32.exe
c:\PROGRA~1\mcafee.com\agent\mcagent.exe
C:\Windows\System32\rundll32.exe
C:\Windows\vVX1000.exe
C:\Program Files\iTunes\iTunesHelper.exe
C:\Program Files\Java\jre6\bin\jusched.exe
C:\Program Files\Common Files\Real\Update_OB\realsched.exe
C:\Program Files\DellSupport\DSAgnt.exe
C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
C:\Program Files\Adobe\Adobe Acrobat 6.0\Distillr\acrotray.exe
C:\Program Files\McAfee Security Scan\1.0.150\SSScheduler.exe
C:\Program Files\Windows Media Player\wmpnscfg.exe
C:\Users\David\AppData\Local\Google\Update\1.2.183.13\GoogleCrashHandler.exe
C:\Windows\system32\wuauclt.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\Program Files\TrendMicro\HiJackThis\HiJackThis.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.google.ca/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =
R1 - HKCU\Software\Microsoft\Internet Explorer\SearchURL,(Default) = http://ca.search.yahoo.com/search?fr=mcafee&p=%s
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
R3 - URLSearchHook: CommentsBar - Stickers and Comments Toolbar - {29456bfc-6fb2-4b36-b6a6-086a4cfc6770} - C:\Program Files\CommentsBar_-_Stickers_and_Comments\tbComm.dll
O1 - Hosts file is located at: C:\Windows\System32\drivers\etc\hosts
O1 - Hosts: ::1 localhost
O2 - BHO: (no name) - {02478D38-C3F9-4efb-9B51-7695ECA05670} - (no file)
O2 - BHO: AcroIEHelperStub - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll
O2 - BHO: Skype add-on (mastermind) - {22BF413B-C6D2-4d91-82A9-A0F997BA588C} - C:\Program Files\Skype\Toolbars\Internet Explorer\SkypeIEPlugin.dll
O2 - BHO: McAfee Phishing Filter - {27B4851A-3207-45A2-B947-BE8AFE6163AB} - c:\PROGRA~1\mcafee\msk\mskapbho.dll
O2 - BHO: CommentsBar - Stickers and Comments Toolbar - {29456bfc-6fb2-4b36-b6a6-086a4cfc6770} - C:\Program Files\CommentsBar_-_Stickers_and_Comments\tbComm.dll
O2 - BHO: RealPlayer Download and Record Plugin for Internet Explorer - {3049C3E9-B461-4BC5-8870-4C09146192CA} - c:\program files\real\realplayer\rpbrowserrecordplugin.dll
O2 - BHO: Spybot-S&D IE Protection - {53707962-6F74-2D53-2644-206D7942484F} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll
O2 - BHO: scriptproxy - {7DB2D5A0-7241-4E79-B68D-6309F01C5231} - C:\Program Files\McAfee\VirusScan\scriptsn.dll
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - C:\Program Files\Google\Google Toolbar\GoogleToolbar.dll
O2 - BHO: AcroIEToolbarHelper Class - {AE7CD045-E861-484f-8273-0445EE161910} - C:\Program Files\Adobe\Adobe Acrobat 6.0\Acrobat\AcroIEFavClient.dll
O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\5.4.4525.1752\swg.dll
O2 - BHO: McAfee SiteAdvisor BHO - {B164E929-A1B6-4A06-B104-2CD0E90A88FF} - c:\PROGRA~1\mcafee\SITEAD~1\mcieplg.dll
O2 - BHO: Google Dictionary Compression sdch - {C84D72FE-E17D-4195-BB24-76C02E2E7C4E} - C:\Program Files\Google\Google Toolbar\Component\fastsearch_A8904FB862BD9564.dll
O2 - BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll
O3 - Toolbar: Adobe PDF - {47833539-D0C5-4125-9FA8-0819E2EAAC93} - C:\Program Files\Adobe\Adobe Acrobat 6.0\Acrobat\AcroIEFavClient.dll
O3 - Toolbar: Google Toolbar - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - C:\Program Files\Google\Google Toolbar\GoogleToolbar.dll
O3 - Toolbar: CommentsBar - Stickers and Comments Toolbar - {29456bfc-6fb2-4b36-b6a6-086a4cfc6770} - C:\Program Files\CommentsBar_-_Stickers_and_Comments\tbComm.dll
O3 - Toolbar: McAfee SiteAdvisor Toolbar - {0EBBBE48-BAD4-4B4C-8E5A-516ABECAE064} - c:\PROGRA~1\mcafee\SITEAD~1\mcieplg.dll
O4 - HKLM\..\Run: [Windows Defender] %ProgramFiles%\Windows Defender\MSASCui.exe -hide
O4 - HKLM\..\Run: [ISUSPM Startup] C:\PROGRA~1\COMMON~1\INSTAL~1\UPDATE~1\ISUSPM.exe -startup
O4 - HKLM\..\Run: [ISUSScheduler] "C:\Program Files\Common Files\InstallShield\UpdateService\issch.exe" -start
O4 - HKLM\..\Run: [RtHDVCpl] RtHDVCpl.exe
O4 - HKLM\..\Run: [NBKeyScan] "C:\Program Files\Nero\Nero8\Nero BackItUp\NBKeyScan.exe"
O4 - HKLM\..\Run: [dscactivate] "C:\Program Files\Dell Support Center\gs_agent\custom\dsca.exe"
O4 - HKLM\..\Run: [DellSupportCenter] "C:\Program Files\Dell Support Center\bin\sprtcmd.exe" /P DellSupportCenter
O4 - HKLM\..\Run: [AdobeVersionCue] C:\Program Files\Adobe\Adobe Version Cue\ControlPanel\VersionCueTray.exe
O4 - HKLM\..\Run: [NvSvc] RUNDLL32.EXE C:\Windows\system32\nvsvc.dll,nvsvcStart
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\Windows\system32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\Windows\system32\NvMcTray.dll,NvTaskbarInit
O4 - HKLM\..\Run: [AppleSyncNotifier] C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleSyncNotifier.exe
O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 9.0\Reader\Reader_sl.exe"
O4 - HKLM\..\Run: [LifeCam] "C:\Program Files\Microsoft LifeCam\LifeExp.exe"
O4 - HKLM\..\Run: [VX1000] C:\Windows\vVX1000.exe
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\QTTask.exe" -atboottime
O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre6\bin\jusched.exe"
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
O4 - HKLM\..\Run: [mcagent_exe] "C:\Program Files\McAfee.com\Agent\mcagent.exe" /runkey
O4 - HKCU\..\Run: [DellSupport] "C:\Program Files\DellSupport\DSAgnt.exe" /startup
O4 - HKCU\..\Run: [swg] "C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe"
O4 - HKCU\..\Run: [BgMonitor_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}] "C:\Program Files\Common Files\Nero\Lib\NMBgMonitor.exe"
O4 - HKCU\..\Run: [DellSupportCenter] "C:\Program Files\Dell Support Center\bin\sprtcmd.exe" /P DellSupportCenter
O4 - HKCU\..\Run: [Google Update] "C:\Users\David\AppData\Local\Google\Update\GoogleUpdate.exe" /c
O4 - HKCU\..\Run: [WMPNSCFG] C:\Program Files\Windows Media Player\WMPNSCFG.exe
O4 - HKCU\..\Run: [SpybotSD TeaTimer] C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
O4 - HKUS\S-1-5-19\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /detectMem (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-19\..\Run: [WindowsWelcomeCenter] rundll32.exe oobefldr.dll,ShowWelcomeCenter (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-20\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /detectMem (User 'NETWORK SERVICE')
O4 - Global Startup: Acrobat Assistant.lnk = C:\Program Files\Adobe\Adobe Acrobat 6.0\Distillr\acrotray.exe
O4 - Global Startup: Adobe Gamma Loader.lnk = C:\Program Files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe
O4 - Global Startup: AutoCAD Startup Accelerator.lnk = C:\Program Files\Common Files\Autodesk Shared\acstart17.exe
O4 - Global Startup: McAfee Security Scan.lnk = ?
O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office10\OSA.EXE
O9 - Extra button: PokerStars - {3AD14F0C-ED16-4e43-B6D8-661B03F6A1EF} - C:\Program Files\PokerStars\PokerStarsUpdate.exe
O9 - Extra button: Skype - {77BF5300-1474-4EC7-9980-D32B190E9B07} - C:\Program Files\Skype\Toolbars\Internet Explorer\SkypeIEPlugin.dll
O9 - Extra button: (no name) - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll
O9 - Extra 'Tools' menuitem: Spybot - Search && Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll
O13 - Gopher Prefix:
O15 - Trusted Zone: http://*.mcafee.com
O16 - DPF: {CF40ACC5-E1BB-4AFF-AC72-04C2F616BCA7} - http://wwwimages.adobe.com/www.adobe.co ... nos/gp.cab
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - http://fpdownload2.macromedia.com/get/s ... wflash.cab
O16 - DPF: {E2883E8F-472F-4FB0-9522-AC9BF37916A7} - http://platformdl.adobe.com/NOS/getPlusPlus/1.6/gp.cab
O17 - HKLM\System\CCS\Services\Tcpip\..\{5B231708-7E2A-4040-961C-15E978E31674}: NameServer = 66.181.69.123 65.99.220.104
O18 - Protocol: sacore - {5513F07E-936B-4E52-9B00-067394E91CC5} - c:\PROGRA~1\mcafee\SITEAD~1\mcieplg.dll
O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~1\COMMON~1\Skype\SKYPE4~1.DLL
O18 - Filter: x-sdch - (no CLSID) - (no file)
O20 - Winlogon Notify: GoToAssist - C:\Program Files\Citrix\GoToAssist\480\G2AWinLogon.dll (file missing)
O22 - SharedTaskScheduler: Component Categories cache daemon - {8C7461EF-2B13-11d2-BE35-3078302C2030} - C:\Windows\system32\browseui.dll
O23 - Service: AdobeVersionCue - Adobe Sytems - C:\Program Files\Adobe\Adobe Version Cue\service\VersionCue.exe
O23 - Service: Apple Mobile Device - Apple Inc. - C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
O23 - Service: Autodesk Licensing Service - Autodesk - C:\Program Files\Common Files\Autodesk Shared\Service\AdskScSrv.exe
O23 - Service: Bonjour Service - Apple Inc. - C:\Program Files\Bonjour\mDNSResponder.exe
O23 - Service: DSBrokerService - Unknown owner - C:\Program Files\DellSupport\brkrsvc.exe
O23 - Service: GoToAssist - Citrix Online, a division of Citrix Systems, Inc. - C:\Program Files\Citrix\GoToAssist\480\g2aservice.exe
O23 - Service: Google Software Updater (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Roxio\Roxio MyDVD DE\InstallShield\Driver\1050\Intel 32\IDriverT.exe
O23 - Service: iPod Service - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: McAfee SiteAdvisor Service - Unknown owner - C:\Program Files\McAfee\SiteAdvisor\McSACore.exe
O23 - Service: McAfee Services (mcmscsvc) - McAfee, Inc. - C:\PROGRA~1\McAfee\MSC\mcmscsvc.exe
O23 - Service: McAfee Network Agent (McNASvc) - McAfee, Inc. - c:\PROGRA~1\COMMON~1\mcafee\mna\mcnasvc.exe
O23 - Service: McAfee Scanner (McODS) - McAfee, Inc. - C:\PROGRA~1\McAfee\VIRUSS~1\mcods.exe
O23 - Service: McAfee Proxy Service (McProxy) - McAfee, Inc. - c:\PROGRA~1\COMMON~1\mcafee\mcproxy\mcproxy.exe
O23 - Service: McAfee Real-time Scanner (McShield) - McAfee, Inc. - C:\PROGRA~1\McAfee\VIRUSS~1\McShield.exe
O23 - Service: McAfee SystemGuards (McSysmon) - McAfee, Inc. - C:\PROGRA~1\McAfee\VIRUSS~1\mcsysmon.exe
O23 - Service: McAfee Personal Firewall Service (MpfService) - McAfee, Inc. - C:\Program Files\McAfee\MPF\MPFSrv.exe
O23 - Service: McAfee Anti-Spam Service (MSK80Service) - McAfee, Inc. - C:\Program Files\McAfee\MSK\MskSrver.exe
O23 - Service: SBSD Security Center Service (SBSDWSCService) - Safer Networking Ltd. - C:\Program Files\Spybot - Search & Destroy\SDWinSec.exe
O23 - Service: SupportSoft Sprocket Service (dellsupportcenter) (sprtsvc_dellsupportcenter) - SupportSoft, Inc. - C:\Program Files\Dell Support Center\bin\sprtsvc.exe
O23 - Service: stllssvr - Unknown owner - C:\Program Files\Common Files\SureThing Shared\stllssvr.exe (file missing)

--
End of file - 12652 bytes


*************


Acrobat.com
Acrobat.com
Adobe AIR
Adobe AIR
Adobe Creative Suite
Adobe Flash Player 10 ActiveX
Adobe Flash Player 10 Plugin
Adobe Reader 9
Adobe SVG Viewer 3.0
AMDAway INF
Apple Application Support
Apple Mobile Device Support
Apple Software Update
ATI Parental Control & Encoder
AutoCAD 2007 - English
Autodesk DWF Viewer
AVerMedia M779 Driver
AVIcodec (remove only)
Black's Digital Solution Studio
Bonjour
Canon Camera Window DC_DV 6 for ZoomBrowser EX
Canon Camera Window MC 6 for ZoomBrowser EX
Canon G.726 WMP-Decoder
Canon MovieEdit Task for ZoomBrowser EX
Canon RAW Image Task for ZoomBrowser EX
Canon RemoteCapture Task for ZoomBrowser EX
Canon Utilities PhotoStitch
Canon Utilities ZoomBrowser EX
CommentsBar_-_Stickers_and_Comments Toolbar
ConvertXtoDVD 3.1.3.40
Dell Resource CD
Dell Support Center (Support Software)
DellSupport
DivX Codec
DivX Content Uploader
DivX Player
DivX Web Player
Full Tilt Poker
getPlus(R) for Adobe
Google Earth
Google SketchUp 6
Google SketchUp 6 Exporters
Google SketchUp LayOut 6
Google SketchUp Pro 6
Google Toolbar for Internet Explorer
Google Toolbar for Internet Explorer
GoToAssist 8.0.0.480
HiJackThis
Hotfix for Microsoft .NET Framework 3.5 SP1 (KB953595)
Hotfix for Microsoft .NET Framework 3.5 SP1 (KB958484)
iTunes
Java(TM) 6 Update 17
Java(TM) SE Runtime Environment 6
Malwarebytes' Anti-Malware
McAfee Security Scan
McAfee SecurityCenter
Microsoft .NET Framework 1.1
Microsoft .NET Framework 1.1
Microsoft .NET Framework 1.1 Security Update (KB953297)
Microsoft .NET Framework 3.5 SP1
Microsoft .NET Framework 3.5 SP1
Microsoft LifeCam
Microsoft Outlook Web Access S/MIME
Microsoft Silverlight
Microsoft Visual C++ 2005 Redistributable
Microsoft Word 2002
Microsoft Works
Microsoft Works Suite 2006 Setup Launcher
Microsoft Works Suite Add-in for Microsoft Word
MobileMe Control Panel
Mozilla Firefox (3.0.17)
mp3-2-wav converter 1.14
MSXML 4.0 SP2 (KB936181)
MSXML 4.0 SP2 (KB941833)
MSXML 4.0 SP2 (KB954430)
MSXML 4.0 SP2 (KB973688)
neroxml
NVIDIA Drivers
NVIDIANetworkDiagnostic
PartyPoker
PokerStars
PokerStove version 1.23
QuickTime
RealPlayer
Realtek High Definition Audio Driver
Rhapsody Player Engine
Roxio Update Manager
Shareaza version 2.3.0.0
Skype™ 4.0
Sonic Activation Module
Spybot - Search & Destroy
System Requirements Lab
Update for Microsoft .NET Framework 3.5 SP1 (KB963707)
VCRedistSetup
WinRAR archiver
dcowie
Regular Member
 
Posts: 23
Joined: January 24th, 2010, 9:54 am
Advertisement
Register to Remove

Re: Help needed with browser hijack

Unread postby MWR 3 day Mod » January 27th, 2010, 7:27 pm

Hi,

We are sorry to see your topic is over three days old and no one has yet been able to respond and offer help.

If you still require assistance, please post a link to your topic in our Waiting for help with malware removal? forum, and our staff will make an effort to assist you as promptly as possible. Only post a LINK to this topic, DO NOT post your DDS log!

Please do not reply to this topic.

If you haven't posted within two days in the "Waiting for help with malware removal?" forum, we will assume you have been able to get assistance in other ways and this topic will be closed.
MWR 3 day Mod
MRU Undergrad
MRU Undergrad
 
Posts: 2534
Joined: April 4th, 2008, 8:40 am

Re: Help needed with browser hijack

Unread postby Jack&Jill » January 30th, 2010, 2:27 am

Hello dcowie,

Welcome to Malware Removal. I am Jack&Jill, and I will be helping you out.

Before we go further, there are a few things that I would like to make clear so that we are share the same understanding.
  • Please observe and follow these Forum Rules and HOW TO GET HELP AT THIS FORUM (YOU MUST READ THIS).
  • It will take some time for me to go through your logs, so please be patient with me.
  • Backing up important data is a good idea as malware removal is a hazardous undertaking. Please do so if you haven't already.
  • Any advice is for your computer only and is taken at your own risk. Fixes sometimes will cause unexpected results, but I will do my best to assist you.
  • Reply and keep only to this thread. If you have the same topic elsewhere, please inform me or the other forum so that either can be closed.
  • If you have any doubts or problems during the fix, please stop and ask.
  • If you need to be away for a while during the fix, please let me know.
  • Lack of malware symptoms does not mean your computer is clean. Stick to this topic until I give the All Clear.
  • Do not use or run any tools without supervision as they may cause more harm if improperly used.
  • Refrain from installing any new programs except those that I request during the fix to prevent interference to my diagnosis of the problem.
  • Please read the instructions carefully and follow them closely, in the order they are presented to you.
  • All the tools that I will ask you to download and use are safe. Please allow if prompted by any of your security softwares.
  • If you do not reply within 3 days, this topic will be closed.

If you are agreeable to the above, then everything should go smoothly :) . We may begin.
I am working on your log now and will be back the soonest.

At the mean time, please complete the following steps.

Remove P2P software
  • IMPORTANT: I notice there are signs of one or more P2P (Peer to Peer) File Sharing Programs on your computer.

    Shareaza version 2.3.0.0

  • Please read our P2P Policy where we explain why it's not a good idea to have them.
  • Even if you are using a "safe" P2P program, it is only the program that is safe. You will be sharing files from uncertified sources, and these are often infected. The bad guys use P2P filesharing as a major conduit to spread their wares.
  • Go to Control Panel > Add/Remove Programs and uninstall the P2P program(s) listed above (in red).
  • Please remove them before we continue with fixing your computer.

For Windows Vista, please use right click and select Run as administrator instead of double click to run all the tools I ask you to, or they may not work properly.

Validate Windows
  • Please download MGADiag.exe from Microsoft and save it to a convenient location. Click here.
  • Double click on MGADiag.exe to run it.
  • Click Continue.
  • The program will run. It takes a while to finish the diagnosis, please be patient.
  • Once done, click on Copy.
  • Open Notepad and paste the contents in. Save this file and post it in your next reply.

Check for additional security risks
  • Please download CKScanner© by askey127 and save to your desktop. Click here.
  • Double click on CKScanner.exe and click Search For Files.
  • After a very short time, when the cursor hourglass disappears, click Save List To File. You will be prompted, click OK.
  • Post the contents of ckfiles.txt in your reply, it is located on your desktop.

Is this a business / work computer?

Please post back:
1. new uninstall list
2. MGADiag result
3. CKScanner log
4. the answer to my question about your computer
User avatar
Jack&Jill
MRU Emeritus
MRU Emeritus
 
Posts: 2284
Joined: August 19th, 2008, 5:37 am
Location: South East Asia

Re: Help needed with browser hijack

Unread postby dcowie » January 30th, 2010, 11:01 am

Jack&Jill,

Thanks in advance for your assistance...it is hugely appreciated.

Shareaza was removed, and the PC is not a work or business computer.

Copied below are the logs you requested.

Diagnostic Report (1.9.0011.0):
-----------------------------------------
WGA Data-->
Validation Status: Genuine
Validation Code: 0

Cached Validation Code: N/A, hr = 0xc004f012
Windows Product Key: *****-*****-F4GJK-KG77H-B9HD2
Windows Product Key Hash: iJAth4TbScMi8HdcPurlASXdEkw=
Windows Product ID: 89578-OEM-7332157-00204
Windows Product ID Type: 2
Windows License Type: OEM SLP
Windows OS version: 6.0.6002.2.00010300.2.0.003
ID: {F95992AD-A948-410E-A27A-F94D59ED01A3}(1)
Is Admin: Yes
TestCab: 0x0
WGA Version: N/A, hr = 0x80070002
Signed By: N/A, hr = 0x80070002
Product Name: Windows Vista (TM) Home Premium
Architecture: 0x00000000
Build lab: 6002.vistasp2_gdr.090803-2339
TTS Error: M:20100125185616922-
Validation Diagnostic:
Resolution Status: N/A

WgaER Data-->
ThreatID(s): N/A, hr = 0x80070002
Version: 6.0.6001.18000

WGA Notifications Data-->
Cached Result: N/A, hr = 0x80070002
File Exists: No
Version: N/A, hr = 0x80070002
WgaTray.exe Signed By: N/A, hr = 0x80070002
WgaLogon.dll Signed By: N/A, hr = 0x80070002

OGA Notifications Data-->
Cached Result: N/A, hr = 0x80070002
Version: N/A, hr = 0x80070002
OGAExec.exe Signed By: N/A, hr = 0x80070002
OGAAddin.dll Signed By: N/A, hr = 0x80070002

OGA Data-->
Office Status: 100 Genuine
Microsoft Word 2002 - 100 Genuine
OGA Version: N/A, 0x80070002
Signed By: N/A, hr = 0x80070002
Office Diagnostics: 025D1FF3-364-80041010_025D1FF3-229-80041010_025D1FF3-230-1_025D1FF3-517-80040154_025D1FF3-237-80040154_025D1FF3-238-2_025D1FF3-244-80070002_025D1FF3-258-3_E2AD56EA-765-d003_E2AD56EA-766-0_E2AD56EA-134-80004005

Browser Data-->
Proxy settings: N/A
User Agent: Mozilla/4.0 (compatible; MSIE 8.0; Win32)
Default Browser: C:\Users\David\AppData\Local\Google\Chrome\Application\chrome.exe
Download signed ActiveX controls: Prompt
Download unsigned ActiveX controls: Disabled
Run ActiveX controls and plug-ins: Allowed
Initialize and script ActiveX controls not marked as safe: Disabled
Allow scripting of Internet Explorer Webbrowser control: Disabled
Active scripting: Allowed
Script ActiveX controls marked as safe for scripting: Allowed

File Scan Data-->

Other data-->
Office Details: <GenuineResults><MachineData><UGUID>{F95992AD-A948-410E-A27A-F94D59ED01A3}</UGUID><Version>1.9.0011.0</Version><OS>6.0.6002.2.00010300.2.0.003</OS><Architecture>x32</Architecture><PKey>*****-*****-*****-*****-B9HD2</PKey><PID>89578-OEM-7332157-00204</PID><PIDType>2</PIDType><SID>S-1-5-21-2209711222-1865678921-789788502</SID><SYSTEM><Manufacturer>Dell Inc.</Manufacturer><Model>Inspiron 531</Model></SYSTEM><BIOS><Manufacturer>Dell Inc.</Manufacturer><Version>1.0.6</Version><SMBIOSVersion major="2" minor="5"/><Date>20070906000000.000000+000</Date></BIOS><HWID>69303507010000F8</HWID><UserLCID>1009</UserLCID><SystemLCID>0409</SystemLCID><TimeZone>Eastern Standard Time(GMT-05:00)</TimeZone><iJoin>0</iJoin><SBID><stat>3</stat><msppid></msppid><name></name><model></model></SBID><OEM><OEMID>DELL </OEMID><OEMTableID>AS09 </OEMTableID></OEM><GANotification/></MachineData><Software><Office><Result>100</Result><Products><Product GUID="{911B0409-6000-11D3-8CFE-0050048383C9}"><LegitResult>100</LegitResult><Name>Microsoft Word 2002</Name><Ver>10</Ver><Val>9CF5E85BB9ACDFA</Val><Hash>1Ggu41R2+mA+9tA2HepOcmjwtV0=</Hash><Pid>54189-OEM-1650002-00509</Pid><PidType>16</PidType></Product></Products><Applications><App Id="1B" Version="10" Result="100"/></Applications></Office></Software></GenuineResults>

Spsys.log Content: U1BMRwEAAAAAAQAABAAAAAVBIwAAAAAAYWECAATwkIe1KsX7GZ7KAZWnLvbizrpQQvBAlB2zelt2S6JFismEfT+puYGDwPvifPD90WHHzwYcl6U6exLh/mXiyqMLwLWZvpT4ivSx+tT2WsBZYbIZJJLJezdT4XiJM5DWJ9vWy3OurH7DdY1oDDOQ1ifb1stzrqx+w3WNaAwzkNYn29bLc66sfsN1jWgMM5DWJ9vWy3OurH7DdY1oDDOQ1ifb1stzrqx+w3WNaAwzkNYn29bLc66sfsN1jWgMM5DWJ9vWy3OurH7DdY1oDDOQ1ifb1stzrqx+w3WNaAwzkNYn29bLc66sfsN1jWgMM5DWJ9vWy3OurH7DdY1oDDOQ1ifb1stzrqx+w3WNaAw=

Licensing Data-->
Software licensing service version: 6.0.6002.18005
Name: Windows(TM) Vista, HomePremium edition
Description: Windows Operating System - Vista, OEM_SLP channel
Activation ID: bffdc375-bbd5-499d-8ef1-4f37b61c895f
Application ID: 55c92734-d682-4d71-983e-d6ec3f16059f
Extended PID: 89578-00146-321-500204-02-4105-6000.0000-2942007
Installation ID: 004741405174983146462934849336110302731310967033636752
Processor Certificate URL: http://go.microsoft.com/fwlink/?LinkID=43473
Machine Certificate URL: http://go.microsoft.com/fwlink/?LinkID=43474
Use License URL: http://go.microsoft.com/fwlink/?LinkID=43476
Product Key Certificate URL: http://go.microsoft.com/fwlink/?LinkID=43475
Partial Product Key: B9HD2
License Status: Licensed

HWID Data-->
HWID Hash Current: MgAAAAEAAgABAAEAAgABAAAAAgABAAEAJJR4r2CqilSSAGjkBj9SnfL0xIiGtKxWyPQ=

OEM Activation 1.0 Data-->
N/A

OEM Activation 2.0 Data-->
BIOS valid for OA 2.0: yes
Windows marker version: 0x20000
OEMID and OEMTableID Consistent: yes
BIOS Information:
ACPI Table Name OEMID Value OEMTableID Value
APIC DELL AS09
FACP DELL AS09
HPET DELL AS09
MCFG DELL AS09
SLIC DELL AS09
SSDT DELL AS09


*****************************************************************************

CKScanner - Additional Security Risks - These are not necessarily bad
c:\program files\autodesk autocad 2007\crack_patch\adlmdll.dll
c:\program files\autodesk autocad 2007\crack_patch\lacadp.dll
c:\program files\autodesk autocad 2007\crack_patch\readme.txt
c:\users\david\desktop\downloads\music\cracker-greenland\00-cracker-greenland-2006.nfo
c:\users\david\desktop\downloads\music\cracker-greenland\00-cracker-greenland-2006.sfv
scanner sequence 3.EM.11
----- EOF -----
dcowie
Regular Member
 
Posts: 23
Joined: January 24th, 2010, 9:54 am

Re: Help needed with browser hijack

Unread postby Jack&Jill » January 31st, 2010, 9:25 am

Hello dcowie :),

Cracks / Keygens / Warez / Illegal softwares detected!!!

Your log indicates the presence and usage of one or more of the above. Very likely your computer got infected due to the illegal softwares or the illegitimate websites you visited to get them.

Please read Illegal copies of software and Forum Rules.
Any time the helper detects that you may have illegal software on your machine, that helper may stop assisting you immediately until you can demonstrate that you have rectified the situation. We will not support fixing machines with pirated or otherwise illegal software.

If you still want help, please remove the illegal items from your computer, and if you still need the softwares, get legal ones from legitimate sources.
If you advised that the illegal softwares have been removed and I find it otherwise (the tools we use can and will detect them), then I will have no choice but to have this topic closed.
If there are more such new findings after this, the topic will also be closed.

Please remove/uninstall the following before we continue:
AutoCAD 2007 - English

Please post a new CKScanner log.

What do you use AutoCAD 2007 and Google SketchUp 6 for?

Please post back:
1. new uninstall list
2. new CKScanner log
3. the answer to my question about the 2 programs
User avatar
Jack&Jill
MRU Emeritus
MRU Emeritus
 
Posts: 2284
Joined: August 19th, 2008, 5:37 am
Location: South East Asia

Re: Help needed with browser hijack

Unread postby dcowie » January 31st, 2010, 12:52 pm

J&J,

Autocad 2007 removed as requested...apologies for that. It was a leftover from my gf's student days in architecture. I don't believe the program has been used in quite a long time...same thing for Google sketch up. When used they were for putting together landscape drawings.

New log below, and uninstall list....cheers.


CKScanner - Additional Security Risks - These are not necessarily bad
c:\users\david\desktop\downloads\music\cracker-greenland\00-cracker-greenland-2006.nfo
c:\users\david\desktop\downloads\music\cracker-greenland\00-cracker-greenland-2006.sfv
scanner sequence 3.LB.11
----- EOF -----

Acrobat.com
Acrobat.com
Adobe AIR
Adobe AIR
Adobe Creative Suite
Adobe Flash Player 10 ActiveX
Adobe Flash Player 10 Plugin
Adobe Reader 9
Adobe SVG Viewer 3.0
AMDAway INF
Apple Application Support
Apple Mobile Device Support
Apple Software Update
ATI Parental Control & Encoder
Autodesk DWF Viewer
AVerMedia M779 Driver
AVIcodec (remove only)
Black's Digital Solution Studio
Bonjour
Canon Camera Window DC_DV 6 for ZoomBrowser EX
Canon Camera Window MC 6 for ZoomBrowser EX
Canon G.726 WMP-Decoder
Canon MovieEdit Task for ZoomBrowser EX
Canon RAW Image Task for ZoomBrowser EX
Canon RemoteCapture Task for ZoomBrowser EX
Canon Utilities PhotoStitch
Canon Utilities ZoomBrowser EX
ConvertXtoDVD 3.1.3.40
Dell Resource CD
Dell Support Center (Support Software)
DellSupport
Full Tilt Poker
getPlus(R) for Adobe
Google Earth
Google SketchUp 6
Google SketchUp 6 Exporters
Google SketchUp LayOut 6
Google SketchUp Pro 6
Google Toolbar for Internet Explorer
Google Toolbar for Internet Explorer
GoToAssist 8.0.0.480
HiJackThis
Hotfix for Microsoft .NET Framework 3.5 SP1 (KB953595)
Hotfix for Microsoft .NET Framework 3.5 SP1 (KB958484)
iTunes
Java(TM) 6 Update 18
Java(TM) SE Runtime Environment 6
Malwarebytes' Anti-Malware
McAfee Security Scan
McAfee SecurityCenter
Microsoft .NET Framework 1.1
Microsoft .NET Framework 1.1
Microsoft .NET Framework 1.1 Security Update (KB953297)
Microsoft .NET Framework 3.5 SP1
Microsoft .NET Framework 3.5 SP1
Microsoft LifeCam
Microsoft Outlook Web Access S/MIME
Microsoft Silverlight
Microsoft Visual C++ 2005 Redistributable
Microsoft Word 2002
Microsoft Works
Microsoft Works Suite 2006 Setup Launcher
Microsoft Works Suite Add-in for Microsoft Word
MobileMe Control Panel
Mozilla Firefox (3.0.17)
mp3-2-wav converter 1.14
MSXML 4.0 SP2 (KB936181)
MSXML 4.0 SP2 (KB941833)
MSXML 4.0 SP2 (KB954430)
MSXML 4.0 SP2 (KB973688)
neroxml
NVIDIA Drivers
NVIDIANetworkDiagnostic
PartyPoker
PokerStars
QuickTime
RealPlayer
Realtek High Definition Audio Driver
Rhapsody Player Engine
Roxio Update Manager
Skype™ 4.0
Sonic Activation Module
Spybot - Search & Destroy
System Requirements Lab
Update for Microsoft .NET Framework 3.5 SP1 (KB963707)
VCRedistSetup
WinRAR archiver
dcowie
Regular Member
 
Posts: 23
Joined: January 24th, 2010, 9:54 am

Re: Help needed with browser hijack

Unread postby Jack&Jill » January 31st, 2010, 9:51 pm

Hello dcowie :),

Please download GMER and save it to your desktop. Click here.
  • Double click the .exe file. If asked to allow gmer.sys driver to load, please consent.
  • If it gives you a warning about rootkit activity and asks if you want to run scan, click on No.
  • In the right panel, you will see several boxes that have been checked (ticked).
    • Uncheck Sections
    • Uncheck IAT/EAT
    • Uncheck All other Drives/Partitions except C:\ (leave C:\ checked)
    • Uncheck Show All (don't miss this one)
  • Then click the Scan button and wait for it to finish.
  • Once done, click on the Save... button and save it as "Gmer.txt" at a convenient location. Post the contents of that report.
    Rootkit scans often produce false positives. Do NOT take any action on any "<--- ROOKIT" entries.

Do not run any other programs while GMER is running.

Please post back:
1. the GMER log
User avatar
Jack&Jill
MRU Emeritus
MRU Emeritus
 
Posts: 2284
Joined: August 19th, 2008, 5:37 am
Location: South East Asia

Re: Help needed with browser hijack

Unread postby dcowie » February 1st, 2010, 8:49 am

J&J,

Followed your instructions, but GMER crashes (4 times) after scan is initiated.
dcowie
Regular Member
 
Posts: 23
Joined: January 24th, 2010, 9:54 am

Re: Help needed with browser hijack

Unread postby Jack&Jill » February 1st, 2010, 10:09 am

Hello dcowie :),

Please try again, but this time uncheck the option Devices too.
User avatar
Jack&Jill
MRU Emeritus
MRU Emeritus
 
Posts: 2284
Joined: August 19th, 2008, 5:37 am
Location: South East Asia

Re: Help needed with browser hijack

Unread postby dcowie » February 1st, 2010, 5:45 pm

Hello J&J,

GMER scan completed...log is below

GMER 1.0.15.15281 - http://www.gmer.net
Rootkit scan 2010-02-01 16:07:55
Windows 6.0.6002 Service Pack 2
Running: kt5yy707.exe; Driver: C:\Users\David\AppData\Local\Temp\kxldipob.sys


---- System - GMER 1.0.15 ----

Code \SystemRoot\system32\drivers\mfehidk.sys (Host Intrusion Detection Link Driver/McAfee, Inc.) ZwCreateFile [0x8D41D79E]
Code \SystemRoot\system32\drivers\mfehidk.sys (Host Intrusion Detection Link Driver/McAfee, Inc.) ZwCreateProcess [0x8D41D738]
Code \SystemRoot\system32\drivers\mfehidk.sys (Host Intrusion Detection Link Driver/McAfee, Inc.) ZwCreateProcessEx [0x8D41D74C]
Code \SystemRoot\system32\drivers\mfehidk.sys (Host Intrusion Detection Link Driver/McAfee, Inc.) ZwMapViewOfSection [0x8D41D7DC]
Code \SystemRoot\system32\drivers\mfehidk.sys (Host Intrusion Detection Link Driver/McAfee, Inc.) ZwNotifyChangeKey [0x8D41D81F]
Code \SystemRoot\system32\drivers\mfehidk.sys (Host Intrusion Detection Link Driver/McAfee, Inc.) ZwOpenProcess [0x8D41D710]
Code \SystemRoot\system32\drivers\mfehidk.sys (Host Intrusion Detection Link Driver/McAfee, Inc.) ZwOpenThread [0x8D41D724]
Code \SystemRoot\system32\drivers\mfehidk.sys (Host Intrusion Detection Link Driver/McAfee, Inc.) ZwProtectVirtualMemory [0x8D41D7B2]
Code \SystemRoot\system32\drivers\mfehidk.sys (Host Intrusion Detection Link Driver/McAfee, Inc.) ZwReplaceKey [0x8D41D847]
Code \SystemRoot\system32\drivers\mfehidk.sys (Host Intrusion Detection Link Driver/McAfee, Inc.) ZwRestoreKey [0x8D41D833]
Code \SystemRoot\system32\drivers\mfehidk.sys (Host Intrusion Detection Link Driver/McAfee, Inc.) ZwSetContextThread [0x8D41D78A]
Code \SystemRoot\system32\drivers\mfehidk.sys (Host Intrusion Detection Link Driver/McAfee, Inc.) ZwSetInformationProcess [0x8D41D776]
Code \SystemRoot\system32\drivers\mfehidk.sys (Host Intrusion Detection Link Driver/McAfee, Inc.) ZwTerminateProcess [0x8D41D80B]
Code \SystemRoot\system32\drivers\mfehidk.sys (Host Intrusion Detection Link Driver/McAfee, Inc.) ZwUnmapViewOfSection [0x8D41D7F2]
Code \SystemRoot\system32\drivers\mfehidk.sys (Host Intrusion Detection Link Driver/McAfee, Inc.) ZwYieldExecution [0x8D41D7C8]
Code \SystemRoot\system32\drivers\mfehidk.sys (Host Intrusion Detection Link Driver/McAfee, Inc.) ZwCreateUserProcess [0x8D41D762]
Code \SystemRoot\system32\drivers\mfehidk.sys (Host Intrusion Detection Link Driver/McAfee, Inc.) NtCreateFile
Code \SystemRoot\system32\drivers\mfehidk.sys (Host Intrusion Detection Link Driver/McAfee, Inc.) NtMapViewOfSection
Code \SystemRoot\system32\drivers\mfehidk.sys (Host Intrusion Detection Link Driver/McAfee, Inc.) NtOpenProcess
Code \SystemRoot\system32\drivers\mfehidk.sys (Host Intrusion Detection Link Driver/McAfee, Inc.) NtOpenThread
Code \SystemRoot\system32\drivers\mfehidk.sys (Host Intrusion Detection Link Driver/McAfee, Inc.) NtSetInformationProcess

---- EOF - GMER 1.0.15 ----
dcowie
Regular Member
 
Posts: 23
Joined: January 24th, 2010, 9:54 am

Re: Help needed with browser hijack

Unread postby Jack&Jill » February 1st, 2010, 8:06 pm

Hello dcowie :),

You have Malwarebytes' Anti-Malware (MBAM) on your machine. I wish to take a look at the most recent log file. Open MBAM and click on the Logs tab. Open the file at the bottom of the list and post the contents back here. If there is no log or you have yet to run MBAM, please let me know.

For Windows Vista, please use right click and select Run as administrator instead of double click to run all the tools I ask you to, or they may not work properly.

Please download OTL© by OldTimer and save it to your desktop. Click here.
  • Double click on OTL.exe to run it.
  • Make sure all the Use SafeList options is checked (ticked). There are six of them.
  • Check Scan All Users.
  • At the lower right corner, check LOP Check and Purity Check.
  • Click on Run Scan at the top left hand corner. This might take a while.
  • When done, two Notepad files will open. Please post the contents of these 2 Notepad files in your next reply. One log per reply please.
    Note: These files are saved as OTL.txt and Extras.txt on the desktop.

Please download SysProt AntiRootkit© by swatkat and save it to your desktop. Click here.
  • Scroll down to the bottom of the page and click on SysProt.zip under the Attachments section to save the file.
  • Unzip it into a folder on your desktop and enter it, then double click on SysProt.exe to start the program.
  • Go to the Log tab and check (tick) all items listed in the Write to log box.
  • Check Hidden Objects Only at the bottom of the window too.
  • Click on the Create Log button on the bottom right.
  • After a few seconds a new window should appear. Select Scan root drive only and click Start.
  • When completed, you will be prompted showing the location of SysProtLog.txt, which is the same folder SysProt.exe was extracted to. Post the contents of the log in your reply.

Please post back:
1. previous MBAM report
2. OTL logs (OTL.txt and Extras.txt)
3. SysProt result
User avatar
Jack&Jill
MRU Emeritus
MRU Emeritus
 
Posts: 2284
Joined: August 19th, 2008, 5:37 am
Location: South East Asia

Re: Help needed with browser hijack

Unread postby dcowie » February 2nd, 2010, 9:05 am

J&J,

Everything requested completed successfully. Included in this reply are the Malwarebytes log, and the first of the two OTL logs (OTL.txt). Remaining logs follow in separate posts...cheers.

Malwarebytes' Anti-Malware 1.44
Database version: 3619
Windows 6.0.6002 Service Pack 2
Internet Explorer 8.0.6001.18882

23/01/2010 12:02:45 PM
mbam-log-2010-01-23 (12-02-45).txt

Scan type: Full Scan (C:\|D:\|)
Objects scanned: 354722
Time elapsed: 2 hour(s), 27 minute(s), 41 second(s)

Memory Processes Infected: 0
Memory Modules Infected: 0
Registry Keys Infected: 0
Registry Values Infected: 0
Registry Data Items Infected: 0
Folders Infected: 0
Files Infected: 0

Memory Processes Infected:
(No malicious items detected)

Memory Modules Infected:
(No malicious items detected)

Registry Keys Infected:
(No malicious items detected)

Registry Values Infected:
(No malicious items detected)

Registry Data Items Infected:
(No malicious items detected)

Folders Infected:
(No malicious items detected)

Files Infected:
(No malicious items detected)

---------------------------------------------------------------
OTL logfile created on: 02/02/2010 6:53:58 AM - Run 1
OTL by OldTimer - Version 3.1.27.1 Folder = C:\Users\David\Desktop
Windows Vista Home Premium Edition Service Pack 2 (Version = 6.0.6002) - Type = NTWorkstation
Internet Explorer (Version = 8.0.6001.18882)
Locale: 00001009 | Country: Canada | Language: ENC | Date Format: dd/MM/yyyy

2.00 Gb Total Physical Memory | 1.00 Gb Available Physical Memory | 56.00% Memory free
4.00 Gb Paging File | 3.00 Gb Available in Paging File | 73.00% Paging File free
Paging file location(s): ?:\pagefile.sys [binary data]

%SystemDrive% = C: | %SystemRoot% = C:\Windows | %ProgramFiles% = C:\Program Files
Drive C: | 222.78 Gb Total Space | 105.34 Gb Free Space | 47.29% Space Free | Partition Type: NTFS
Drive D: | 10.00 Gb Total Space | 5.35 Gb Free Space | 53.52% Space Free | Partition Type: NTFS
E: Drive not present or media not loaded
F: Drive not present or media not loaded
G: Drive not present or media not loaded
H: Drive not present or media not loaded
I: Drive not present or media not loaded

Computer Name: HARRY
Current User Name: David
Logged in as Administrator.

Current Boot Mode: Normal
Scan Mode: All users
Company Name Whitelist: Off
Skip Microsoft Files: Off
File Age = 30 Days
Output = Standard

========== Processes (SafeList) ==========

PRC - [2010/02/02 06:51:01 | 000,548,864 | ---- | M] (OldTimer Tools) -- C:\Users\David\Desktop\OTL.exe
PRC - [2010/01/23 15:00:30 | 000,307,672 | ---- | M] (Mozilla Corporation) -- C:\Program Files\Mozilla Firefox\firefox.exe
PRC - [2010/01/22 19:16:42 | 000,141,608 | ---- | M] (Apple Inc.) -- C:\Program Files\iTunes\iTunesHelper.exe
PRC - [2010/01/22 19:16:30 | 000,545,576 | ---- | M] (Apple Inc.) -- C:\Program Files\iPod\bin\iPodService.exe
PRC - [2010/01/11 15:21:52 | 000,246,504 | ---- | M] (Sun Microsystems, Inc.) -- C:\Program Files\Common Files\Java\Java Update\jusched.exe
PRC - [2009/12/08 14:25:28 | 000,093,320 | ---- | M] (McAfee, Inc.) -- C:\Program Files\McAfee\SiteAdvisor\McSACore.exe
PRC - [2009/12/08 08:11:03 | 000,198,160 | ---- | M] (RealNetworks, Inc.) -- C:\Program Files\Common Files\Real\Update_OB\realsched.exe
PRC - [2009/11/04 16:53:34 | 000,144,704 | ---- | M] (McAfee, Inc.) -- C:\Program Files\McAfee\VirusScan\Mcshield.exe
PRC - [2009/11/04 15:59:50 | 000,606,736 | ---- | M] (McAfee, Inc.) -- C:\Program Files\McAfee\VirusScan\mcsysmon.exe
PRC - [2009/10/31 18:35:22 | 000,136,176 | ---- | M] (Google Inc.) -- C:\Users\David\AppData\Local\Google\Update\1.2.183.13\GoogleCrashHandler.exe
PRC - [2009/10/29 06:54:44 | 001,218,008 | ---- | M] (McAfee, Inc.) -- C:\Program Files\McAfee.com\Agent\mcagent.exe
PRC - [2009/10/29 06:54:44 | 000,865,832 | ---- | M] (McAfee, Inc.) -- C:\Program Files\McAfee\MSC\mcmscsvc.exe
PRC - [2009/10/27 11:19:46 | 000,895,696 | ---- | M] (McAfee, Inc.) -- C:\Program Files\McAfee\MPF\MpfSrv.exe
PRC - [2009/10/02 13:02:56 | 000,026,640 | ---- | M] (McAfee, Inc.) -- C:\Program Files\McAfee\MSK\msksrver.exe
PRC - [2009/08/28 18:42:54 | 000,144,672 | ---- | M] (Apple Inc.) -- C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
PRC - [2009/07/27 19:19:10 | 000,199,184 | ---- | M] (McAfee, Inc.) -- C:\Program Files\McAfee Security Scan\1.0.150\SSScheduler.exe
PRC - [2009/07/08 11:54:34 | 000,359,952 | ---- | M] (McAfee, Inc.) -- c:\Program Files\Common Files\McAfee\McProxy\McProxy.exe
PRC - [2009/07/07 19:10:02 | 002,482,848 | ---- | M] (McAfee, Inc.) -- c:\Program Files\Common Files\McAfee\MNA\McNASvc.exe
PRC - [2009/05/21 09:55:32 | 000,206,064 | ---- | M] (SupportSoft, Inc.) -- C:\Program Files\Dell Support Center\bin\sprtcmd.exe
PRC - [2009/04/11 01:27:36 | 002,926,592 | ---- | M] (Microsoft Corporation) -- C:\Windows\explorer.exe
PRC - [2009/01/26 15:31:16 | 002,144,088 | RHS- | M] (Safer Networking Limited) -- C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
PRC - [2009/01/26 15:31:10 | 001,153,368 | ---- | M] (Safer Networking Ltd.) -- C:\Program Files\Spybot - Search & Destroy\SDWinSec.exe
PRC - [2009/01/21 16:25:48 | 000,039,408 | ---- | M] (Google Inc.) -- C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
PRC - [2008/12/12 11:17:38 | 000,238,888 | ---- | M] (Apple Inc.) -- C:\Program Files\Bonjour\mDNSResponder.exe
PRC - [2008/08/13 17:32:40 | 000,201,968 | ---- | M] (SupportSoft, Inc.) -- C:\Program Files\Dell Support Center\bin\sprtsvc.exe
PRC - [2008/01/19 02:38:38 | 001,008,184 | ---- | M] (Microsoft Corporation) -- C:\Program Files\Windows Defender\MSASCui.exe
PRC - [2008/01/19 02:33:39 | 000,202,240 | ---- | M] (Microsoft Corporation) -- C:\Program Files\Windows Media Player\wmpnscfg.exe
PRC - [2007/05/17 16:45:33 | 000,271,720 | ---- | M] (Microsoft Corporation) -- C:\Program Files\Microsoft LifeCam\MSCamS32.exe
PRC - [2007/04/10 16:46:52 | 000,709,992 | ---- | M] (Microsoft Corporation) -- C:\Windows\vVX1000.exe
PRC - [2007/03/15 11:09:36 | 000,460,784 | ---- | M] (Gteko Ltd.) -- C:\Program Files\DellSupport\DSAgnt.exe
PRC - [2007/03/01 14:38:48 | 004,390,912 | ---- | M] (Realtek Semiconductor) -- C:\Windows\RtHDVCpl.exe
PRC - [2006/10/03 10:37:04 | 000,081,920 | ---- | M] (Macrovision Corporation) -- C:\Program Files\Common Files\InstallShield\UpdateService\issch.exe
PRC - [2004/03/25 10:35:26 | 001,732,608 | ---- | M] (Adobe Systems) -- C:\Program Files\Adobe\Adobe Version Cue\ControlPanel\VersionCueTray.exe
PRC - [2003/05/15 00:19:50 | 000,217,193 | ---- | M] (Adobe Systems Inc.) -- C:\Program Files\Adobe\Adobe Acrobat 6.0\Distillr\acrotray.exe


========== Modules (SafeList) ==========

MOD - [2010/02/02 06:51:01 | 000,548,864 | ---- | M] (OldTimer Tools) -- C:\Users\David\Desktop\OTL.exe
MOD - [2009/12/08 13:12:24 | 000,014,544 | ---- | M] (McAfee, Inc.) -- c:\Program Files\McAfee\SiteAdvisor\sahook.dll
MOD - [2009/04/11 01:21:38 | 001,686,016 | ---- | M] (Microsoft Corporation) -- C:\Windows\winsxs\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.6002.18005_none_5cb72f96088b0de0\comctl32.dll


========== Win32 Services (SafeList) ==========

SRV - File not found [On_Demand | Stopped] -- -- (stllssvr)
SRV - [2010/01/22 19:16:30 | 000,545,576 | ---- | M] (Apple Inc.) [On_Demand | Running] -- C:\Program Files\iPod\bin\iPodService.exe -- (iPod Service)
SRV - [2009/12/08 14:25:28 | 000,093,320 | ---- | M] (McAfee, Inc.) [Auto | Running] -- C:\Program Files\McAfee\SiteAdvisor\McSACore.exe -- (McAfee SiteAdvisor Service)
SRV - [2009/11/06 09:18:50 | 000,051,168 | ---- | M] (NOS Microsystems Ltd.) [On_Demand | Stopped] -- C:\Program Files\NOS\bin\getPlus_Helper.dll -- (getPlusHelper) getPlus(R)
SRV - [2009/11/04 16:53:34 | 000,144,704 | ---- | M] (McAfee, Inc.) [Unknown | Running] -- C:\Program Files\McAfee\VirusScan\Mcshield.exe -- (McShield)
SRV - [2009/11/04 15:59:50 | 000,606,736 | ---- | M] (McAfee, Inc.) [On_Demand | Running] -- C:\Program Files\McAfee\VirusScan\mcsysmon.exe -- (McSysmon)
SRV - [2009/10/29 06:54:44 | 000,865,832 | ---- | M] (McAfee, Inc.) [Auto | Running] -- C:\Program Files\McAfee\MSC\mcmscsvc.exe -- (mcmscsvc)
SRV - [2009/10/28 11:50:32 | 000,365,072 | ---- | M] (McAfee, Inc.) [On_Demand | Stopped] -- C:\Program Files\McAfee\VirusScan\mcods.exe -- (McODS)
SRV - [2009/10/27 11:19:46 | 000,895,696 | ---- | M] (McAfee, Inc.) [Auto | Running] -- C:\Program Files\McAfee\MPF\MPFSrv.exe -- (MpfService)
SRV - [2009/10/02 13:02:56 | 000,026,640 | ---- | M] (McAfee, Inc.) [Auto | Running] -- C:\Program Files\McAfee\MSK\MskSrver.exe -- (MSK80Service)
SRV - [2009/09/24 20:27:04 | 000,793,088 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\System32\FntCache.dll -- (FontCache)
SRV - [2009/08/28 18:42:54 | 000,144,672 | ---- | M] (Apple Inc.) [Auto | Running] -- C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe -- (Apple Mobile Device)
SRV - [2009/07/08 11:54:34 | 000,359,952 | ---- | M] (McAfee, Inc.) [Auto | Running] -- c:\Program Files\Common Files\McAfee\McProxy\McProxy.exe -- (McProxy)
SRV - [2009/07/07 19:10:02 | 002,482,848 | ---- | M] (McAfee, Inc.) [Auto | Running] -- c:\Program Files\Common Files\McAfee\MNA\McNASvc.exe -- (McNASvc)
SRV - [2009/04/24 20:57:14 | 000,182,768 | ---- | M] (Google) [On_Demand | Stopped] -- C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe -- (gusvc)
SRV - [2009/02/02 09:14:45 | 000,085,096 | ---- | M] (Autodesk) [On_Demand | Stopped] -- C:\Program Files\Common Files\Autodesk Shared\Service\AdskScSrv.exe -- (Autodesk Licensing Service)
SRV - [2009/01/26 15:31:10 | 001,153,368 | ---- | M] (Safer Networking Ltd.) [Auto | Running] -- C:\Program Files\Spybot - Search & Destroy\SDWinSec.exe -- (SBSDWSCService)
SRV - [2008/12/12 11:17:38 | 000,238,888 | ---- | M] (Apple Inc.) [Auto | Running] -- C:\Program Files\Bonjour\mDNSResponder.exe -- (Bonjour Service)
SRV - [2008/08/13 17:32:40 | 000,201,968 | ---- | M] (SupportSoft, Inc.) [Auto | Running] -- C:\Program Files\Dell Support Center\bin\sprtsvc.exe -- (sprtsvc_dellsupportcenter) SupportSoft Sprocket Service (dellsupportcenter)
SRV - [2008/01/19 02:38:24 | 000,272,952 | ---- | M] (Microsoft Corporation) [Auto | Running] -- C:\Program Files\Windows Defender\MpSvc.dll -- (WinDefend)
SRV - [2007/10/21 16:48:10 | 000,016,936 | ---- | M] (Citrix Online, a division of Citrix Systems, Inc.) [On_Demand | Stopped] -- C:\Program Files\Citrix\GoToAssist\480\g2aservice.exe -- (GoToAssist)
SRV - [2007/05/17 16:45:33 | 000,271,720 | ---- | M] (Microsoft Corporation) [Auto | Running] -- C:\Program Files\Microsoft LifeCam\MSCamS32.exe -- (MSCamSvc)
SRV - [2007/03/19 11:44:44 | 000,070,656 | ---- | M] () [On_Demand | Stopped] -- C:\Program Files\DellSupport\brkrsvc.exe -- (DSBrokerService)
SRV - [2006/11/02 07:35:29 | 000,013,312 | ---- | M] (Microsoft Corporation) [Auto | Stopped] -- C:\Windows\ehome\ehstart.dll -- (ehstart)
SRV - [2004/10/22 02:24:18 | 000,073,728 | ---- | M] (Macrovision Corporation) [On_Demand | Stopped] -- C:\Program Files\Roxio\Roxio MyDVD DE\InstallShield\Driver\1050\Intel 32\IDriverT.exe -- (IDriverT)
SRV - [2004/03/25 10:35:26 | 000,061,440 | ---- | M] (Adobe Sytems) [On_Demand | Stopped] -- C:\Program Files\Adobe\Adobe Version Cue\service\VersionCue.exe -- (AdobeVersionCue)


========== Driver Services (SafeList) ==========

DRV - [2010/01/26 16:54:36 | 000,035,920 | ---- | M] (NVIDIA Corporation) [Kernel | Boot | Running] -- C:\Windows\system32\drivers\nvstor.sys -- (nvstor)
DRV - [2009/11/04 16:54:12 | 000,214,664 | ---- | M] (McAfee, Inc.) [Kernel | System | Running] -- C:\Windows\System32\drivers\mfehidk.sys -- (mfehidk)
DRV - [2009/11/04 16:54:12 | 000,079,816 | ---- | M] (McAfee, Inc.) [Kernel | On_Demand | Running] -- C:\Windows\System32\drivers\mfeavfk.sys -- (mfeavfk)
DRV - [2009/11/04 16:54:12 | 000,040,552 | ---- | M] (McAfee, Inc.) [Kernel | On_Demand | Running] -- C:\Windows\System32\drivers\mfesmfk.sys -- (mfesmfk)
DRV - [2009/11/04 16:54:12 | 000,035,272 | ---- | M] (McAfee, Inc.) [Kernel | On_Demand | Running] -- C:\Windows\System32\drivers\mfebopk.sys -- (mfebopk)
DRV - [2009/09/16 09:22:14 | 000,034,248 | ---- | M] (McAfee, Inc.) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\drivers\mferkdk.sys -- (mferkdk)
DRV - [2009/08/28 18:42:52 | 000,040,448 | ---- | M] (Apple, Inc.) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\drivers\usbaapl.sys -- (USBAAPL)
DRV - [2009/07/16 12:32:26 | 000,130,424 | ---- | M] (McAfee, Inc.) [Kernel | System | Running] -- C:\Windows\System32\drivers\Mpfp.sys -- (MPFP)
DRV - [2009/05/18 13:17:00 | 000,026,600 | ---- | M] (GEAR Software Inc.) [Kernel | On_Demand | Running] -- C:\Windows\System32\drivers\GEARAspiWDM.sys -- (GEARAspiWDM)
DRV - [2009/04/10 23:42:54 | 000,073,216 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\drivers\USBAUDIO.sys -- (usbaudio) USB Audio Driver (WDM)
DRV - [2008/12/13 11:51:08 | 000,047,360 | ---- | M] (VSO Software) [Kernel | On_Demand | Running] -- C:\Windows\System32\drivers\pcouffin.sys -- (pcouffin)
DRV - [2008/04/16 13:51:56 | 000,022,784 | ---- | M] (Research In Motion Limited) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\drivers\RimUsb.sys -- (RimUsb)
DRV - [2007/09/17 07:07:00 | 007,624,192 | ---- | M] (NVIDIA Corporation) [Kernel | On_Demand | Running] -- C:\Windows\System32\drivers\nvlddmkm.sys -- (nvlddmkm)
DRV - [2007/04/10 16:46:53 | 001,966,312 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\drivers\VX1000.sys -- (VX1000)
DRV - [2007/03/01 15:21:10 | 001,744,928 | ---- | M] (Realtek Semiconductor Corp.) [Kernel | On_Demand | Running] -- C:\Windows\System32\drivers\RTKVHDA.sys -- (IntcAzAudAddService) Service for Realtek HD Audio (WDM)
DRV - [2007/02/25 11:10:48 | 000,005,376 | --S- | M] (Gteko Ltd.) [Kernel | Auto | Running] -- C:\Windows\System32\drivers\dsunidrv.sys -- (dsunidrv)
DRV - [2007/02/21 14:49:47 | 000,017,512 | ---- | M] (VIA Technologies, Inc.) [Kernel | Disabled | Stopped] -- C:\Windows\system32\drivers\viaide.sys -- (viaide)
DRV - [2007/02/21 14:49:47 | 000,016,488 | ---- | M] (CMD Technology, Inc.) [Kernel | Disabled | Stopped] -- C:\Windows\system32\drivers\cmdide.sys -- (cmdide)
DRV - [2007/02/21 14:49:47 | 000,014,952 | ---- | M] (Acer Laboratories Inc.) [Kernel | Disabled | Stopped] -- C:\Windows\system32\drivers\aliide.sys -- (aliide)
DRV - [2007/01/06 00:59:34 | 000,086,096 | ---- | M] (NVIDIA Corporation) [Kernel | Disabled | Stopped] -- C:\Windows\system32\drivers\nvraid.sys -- (nvraid) NVIDIA nForce(tm)
DRV - [2006/11/02 04:51:45 | 000,900,712 | ---- | M] (QLogic Corporation) [Kernel | Disabled | Stopped] -- C:\Windows\system32\drivers\ql2300.sys -- (ql2300)
DRV - [2006/11/02 04:51:38 | 000,420,968 | ---- | M] (Adaptec, Inc.) [Kernel | Disabled | Stopped] -- C:\Windows\system32\drivers\adp94xx.sys -- (adp94xx)
DRV - [2006/11/02 04:51:34 | 000,316,520 | ---- | M] (Emulex) [Kernel | Disabled | Stopped] -- C:\Windows\system32\drivers\elxstor.sys -- (elxstor)
DRV - [2006/11/02 04:51:32 | 000,297,576 | ---- | M] (Adaptec, Inc.) [Kernel | Disabled | Stopped] -- C:\Windows\system32\drivers\adpahci.sys -- (adpahci)
DRV - [2006/11/02 04:51:25 | 000,235,112 | ---- | M] (ULi Electronics Inc.) [Kernel | Disabled | Stopped] -- C:\Windows\system32\drivers\uliahci.sys -- (uliahci)
DRV - [2006/11/02 04:51:25 | 000,232,040 | ---- | M] (Intel Corporation) [Kernel | Disabled | Stopped] -- C:\Windows\system32\drivers\iastorv.sys -- (iaStorV)
DRV - [2006/11/02 04:51:00 | 000,147,048 | ---- | M] (Adaptec, Inc.) [Kernel | Disabled | Stopped] -- C:\Windows\system32\drivers\adpu320.sys -- (adpu320)
DRV - [2006/11/02 04:50:45 | 000,115,816 | ---- | M] (Promise Technology, Inc.) [Kernel | Disabled | Stopped] -- C:\Windows\system32\drivers\ulsata2.sys -- (ulsata2)
DRV - [2006/11/02 04:50:41 | 000,112,232 | ---- | M] (VIA Technologies Inc.,Ltd) [Kernel | Disabled | Stopped] -- C:\Windows\system32\drivers\vsmraid.sys -- (vsmraid)
DRV - [2006/11/02 04:50:35 | 000,106,088 | ---- | M] (QLogic Corporation) [Kernel | Disabled | Stopped] -- C:\Windows\system32\drivers\ql40xx.sys -- (ql40xx)
DRV - [2006/11/02 04:50:35 | 000,098,408 | ---- | M] (Promise Technology, Inc.) [Kernel | Disabled | Stopped] -- C:\Windows\system32\drivers\ulsata.sys -- (UlSata)
DRV - [2006/11/02 04:50:35 | 000,098,408 | ---- | M] (Adaptec, Inc.) [Kernel | Disabled | Stopped] -- C:\Windows\system32\drivers\adpu160m.sys -- (adpu160m)
DRV - [2006/11/02 04:50:19 | 000,045,160 | ---- | M] (IBM Corporation) [Kernel | Disabled | Stopped] -- C:\Windows\system32\drivers\nfrd960.sys -- (nfrd960)
DRV - [2006/11/02 04:50:17 | 000,041,576 | ---- | M] (Intel Corp./ICP vortex GmbH) [Kernel | Disabled | Stopped] -- C:\Windows\system32\drivers\iirsp.sys -- (iirsp)
DRV - [2006/11/02 04:50:16 | 000,071,784 | ---- | M] (Silicon Integrated Systems) [Kernel | Disabled | Stopped] -- C:\Windows\system32\drivers\sisraid4.sys -- (SiSRaid4)
DRV - [2006/11/02 04:50:11 | 000,071,272 | ---- | M] (Adaptec, Inc.) [Kernel | Disabled | Stopped] -- C:\Windows\system32\drivers\djsvs.sys -- (aic78xx)
DRV - [2006/11/02 04:50:10 | 000,067,688 | ---- | M] (Adaptec, Inc.) [Kernel | Disabled | Stopped] -- C:\Windows\system32\drivers\arcsas.sys -- (arcsas)
DRV - [2006/11/02 04:50:10 | 000,065,640 | ---- | M] (LSI Logic) [Kernel | Disabled | Stopped] -- C:\Windows\system32\drivers\lsi_scsi.sys -- (LSI_SCSI)
DRV - [2006/11/02 04:50:10 | 000,038,504 | ---- | M] (Silicon Integrated Systems Corp.) [Kernel | Disabled | Stopped] -- C:\Windows\system32\drivers\sisraid2.sys -- (SiSRaid2)
DRV - [2006/11/02 04:50:10 | 000,037,480 | ---- | M] (Hewlett-Packard Company) [Kernel | Disabled | Stopped] -- C:\Windows\system32\drivers\hpcisss.sys -- (HpCISSs)
DRV - [2006/11/02 04:50:09 | 000,067,688 | ---- | M] (Adaptec, Inc.) [Kernel | Disabled | Stopped] -- C:\Windows\system32\drivers\arc.sys -- (arc)
DRV - [2006/11/02 04:50:09 | 000,035,944 | ---- | M] (Integrated Technology Express, Inc.) [Kernel | Disabled | Stopped] -- C:\Windows\system32\drivers\iteraid.sys -- (iteraid)
DRV - [2006/11/02 04:50:07 | 000,035,944 | ---- | M] (Integrated Technology Express, Inc.) [Kernel | Disabled | Stopped] -- C:\Windows\system32\drivers\iteatapi.sys -- (iteatapi)
DRV - [2006/11/02 04:50:05 | 000,065,640 | ---- | M] (LSI Logic) [Kernel | Disabled | Stopped] -- C:\Windows\system32\drivers\lsi_sas.sys -- (LSI_SAS)
DRV - [2006/11/02 04:50:05 | 000,035,944 | ---- | M] (LSI Logic) [Kernel | Disabled | Stopped] -- C:\Windows\system32\drivers\symc8xx.sys -- (Symc8xx)
DRV - [2006/11/02 04:50:04 | 000,065,640 | ---- | M] (LSI Logic) [Kernel | Disabled | Stopped] -- C:\Windows\system32\drivers\lsi_fc.sys -- (LSI_FC)
DRV - [2006/11/02 04:50:03 | 000,034,920 | ---- | M] (LSI Logic) [Kernel | Disabled | Stopped] -- C:\Windows\system32\drivers\sym_u3.sys -- (Sym_u3)
DRV - [2006/11/02 04:49:59 | 000,033,384 | ---- | M] (LSI Logic Corporation) [Kernel | Disabled | Stopped] -- C:\Windows\system32\drivers\mraid35x.sys -- (Mraid35x)
DRV - [2006/11/02 04:49:56 | 000,031,848 | ---- | M] (LSI Logic) [Kernel | Disabled | Stopped] -- C:\Windows\system32\drivers\sym_hi.sys -- (Sym_hi)
DRV - [2006/11/02 04:49:53 | 000,028,776 | ---- | M] (LSI Logic Corporation) [Kernel | Disabled | Stopped] -- C:\Windows\system32\drivers\megasas.sys -- (megasas)
DRV - [2006/11/02 03:25:24 | 000,071,808 | ---- | M] (Brother Industries Ltd.) [Kernel | Disabled | Stopped] -- C:\Windows\system32\drivers\brserid.sys -- (Brserid) Brother MFC Serial Port Interface Driver (WDM)
DRV - [2006/11/02 03:24:47 | 000,011,904 | ---- | M] (Brother Industries Ltd.) [Kernel | On_Demand | Stopped] -- C:\Windows\system32\drivers\brusbser.sys -- (BrUsbSer)
DRV - [2006/11/02 03:24:46 | 000,005,248 | ---- | M] (Brother Industries, Ltd.) [Kernel | On_Demand | Stopped] -- C:\Windows\system32\drivers\brfiltup.sys -- (BrFiltUp)
DRV - [2006/11/02 03:24:45 | 000,013,568 | ---- | M] (Brother Industries, Ltd.) [Kernel | On_Demand | Stopped] -- C:\Windows\system32\drivers\brfiltlo.sys -- (BrFiltLo)
DRV - [2006/11/02 03:24:44 | 000,062,336 | ---- | M] (Brother Industries Ltd.) [Kernel | Disabled | Stopped] -- C:\Windows\system32\drivers\brserwdm.sys -- (BrSerWdm)
DRV - [2006/11/02 03:24:44 | 000,012,160 | ---- | M] (Brother Industries Ltd.) [Kernel | Disabled | Stopped] -- C:\Windows\system32\drivers\brusbmdm.sys -- (BrUsbMdm)
DRV - [2006/11/02 02:36:50 | 000,020,608 | ---- | M] (N-trig Innovative Technologies) [Kernel | Disabled | Stopped] -- C:\Windows\system32\drivers\ntrigdigi.sys -- (ntrigdigi)
DRV - [2006/11/02 02:30:56 | 000,429,056 | ---- | M] (NVIDIA Corporation) [Kernel | On_Demand | Running] -- C:\Windows\System32\drivers\nvm60x32.sys -- (NVENETFD)
DRV - [2006/11/02 02:30:54 | 000,117,760 | ---- | M] (Intel Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\drivers\E1G60I32.sys -- (E1G60) Intel(R)
DRV - [2006/11/02 01:37:21 | 000,020,480 | ---- | M] (Macrovision Corporation, Macrovision Europe Limited, and Macrovision Japan and Asia K.K.) [Kernel | Auto | Running] -- C:\Windows\System32\drivers\secdrv.sys -- (secdrv)
DRV - [2006/10/05 16:07:28 | 000,004,736 | ---- | M] (Gteko Ltd.) [Kernel | On_Demand | Running] -- C:\Program Files\DellSupport\GTAction\triggers\DSproct.sys -- (DSproct)
DRV - [2005/01/21 11:31:44 | 000,069,810 | ---- | M] (AuthenTec, Inc.) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\drivers\FLMckUSB.sys -- (FLMCKUSB) AuthenTec TruePrint USB Driver (AES3400, AES3500, AES4000)


========== Standard Registry (SafeList) ==========


========== Internet Explorer ==========



IE - HKU\.DEFAULT\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
IE - HKU\.DEFAULT\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyOverride" = *.local

IE - HKU\S-1-5-18\S-1-5-18\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
IE - HKU\S-1-5-18\S-1-5-18\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyOverride" = *.local



IE - HKU\S-1-5-21-2209711222-1865678921-789788502-1000\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://www.google.ca/
IE - HKU\S-1-5-21-2209711222-1865678921-789788502-1000\SOFTWARE\Microsoft\Internet Explorer\Main,StartPageCache = 1
IE - HKU\S-1-5-21-2209711222-1865678921-789788502-1000\S-1-5-21-2209711222-1865678921-789788502-1000\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0

========== FireFox ==========

FF - prefs.js..browser.startup.homepage: "http://www.google.ca/"
FF - prefs.js..extensions.enabledItems: {B7082FAA-CB62-4872-9106-E42DD88EDE45}:3.0

FF - HKLM\software\mozilla\Firefox\Extensions\\{B7082FAA-CB62-4872-9106-E42DD88EDE45}: C:\Program Files\McAfee\SiteAdvisor [2010/01/25 17:32:24 | 000,000,000 | ---D | M]
FF - HKLM\software\mozilla\Mozilla Firefox 3.0.17\extensions\\Components: C:\Program Files\Mozilla Firefox\components [2010/02/01 21:10:36 | 000,000,000 | ---D | M]
FF - HKLM\software\mozilla\Mozilla Firefox 3.0.17\extensions\\Plugins: C:\Program Files\Mozilla Firefox\plugins [2010/02/01 21:10:36 | 000,000,000 | ---D | M]

[2008/12/09 11:47:31 | 000,000,000 | ---D | M] -- C:\Users\David\AppData\Roaming\Mozilla\Extensions
[2010/02/02 06:54:21 | 000,000,000 | ---D | M] -- C:\Users\David\AppData\Roaming\Mozilla\Firefox\Profiles\4heyesc6.default\extensions
[2008/08/13 07:11:48 | 000,002,386 | ---- | M] () -- C:\Users\David\AppData\Roaming\Mozilla\Firefox\Profiles\4heyesc6.default\searchplugins\siteadvisor.xml
[2010/01/27 19:41:51 | 000,000,000 | ---D | M] -- C:\Program Files\Mozilla Firefox\extensions
[2008/12/09 11:47:24 | 000,000,000 | ---D | M] -- C:\Program Files\Mozilla Firefox\extensions\talkback@mozilla.org

O1 HOSTS File: ([2006/09/18 16:41:30 | 000,000,761 | ---- | M]) - C:\Windows\System32\drivers\etc\hosts
O1 - Hosts: 127.0.0.1 localhost
O1 - Hosts: ::1 localhost
O2 - BHO: (no name) - {02478D38-C3F9-4efb-9B51-7695ECA05670} - No CLSID value found.
O2 - BHO: (Adobe PDF Link Helper) - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll (Adobe Systems Incorporated)
O2 - BHO: (Skype add-on (mastermind)) - {22BF413B-C6D2-4d91-82A9-A0F997BA588C} - C:\Program Files\Skype\Toolbars\Internet Explorer\SkypeIEPlugin.dll (Skype Technologies S.A.)
O2 - BHO: (McAfee Phishing Filter) - {27B4851A-3207-45A2-B947-BE8AFE6163AB} - c:\Program Files\McAfee\MSK\mskapbho.dll ()
O2 - BHO: (RealPlayer Download and Record Plugin for Internet Explorer) - {3049C3E9-B461-4BC5-8870-4C09146192CA} - c:\Program Files\Real\realplayer\rpbrowserrecordplugin.dll (RealPlayer)
O2 - BHO: (Spybot-S&D IE Protection) - {53707962-6F74-2D53-2644-206D7942484F} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll (Safer Networking Limited)
O2 - BHO: (scriptproxy) - {7DB2D5A0-7241-4E79-B68D-6309F01C5231} - C:\Program Files\McAfee\VirusScan\scriptsn.dll (McAfee, Inc.)
O2 - BHO: (Google Toolbar Helper) - {AA58ED58-01DD-4d91-8333-CF10577473F7} - C:\Program Files\Google\Google Toolbar\GoogleToolbar.dll (Google Inc.)
O2 - BHO: (AcroIEToolbarHelper Class) - {AE7CD045-E861-484f-8273-0445EE161910} - C:\Program Files\Adobe\Adobe Acrobat 6.0\Acrobat\AcroIEFavClient.dll ()
O2 - BHO: (Google Toolbar Notifier BHO) - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\5.4.4525.1752\swg.dll (Google Inc.)
O2 - BHO: (McAfee SiteAdvisor BHO) - {B164E929-A1B6-4A06-B104-2CD0E90A88FF} - c:\Program Files\McAfee\SiteAdvisor\McIEPlg.dll (McAfee, Inc.)
O2 - BHO: (Google Dictionary Compression sdch) - {C84D72FE-E17D-4195-BB24-76C02E2E7C4E} - C:\Program Files\Google\Google Toolbar\Component\fastsearch_A8904FB862BD9564.dll (Google Inc.)
O2 - BHO: (Java(tm) Plug-In 2 SSV Helper) - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll (Sun Microsystems, Inc.)
O3 - HKLM\..\Toolbar: (McAfee SiteAdvisor Toolbar) - {0EBBBE48-BAD4-4B4C-8E5A-516ABECAE064} - c:\Program Files\McAfee\SiteAdvisor\McIEPlg.dll (McAfee, Inc.)
O3 - HKLM\..\Toolbar: (Google Toolbar) - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - C:\Program Files\Google\Google Toolbar\GoogleToolbar.dll (Google Inc.)
O3 - HKLM\..\Toolbar: (Adobe PDF) - {47833539-D0C5-4125-9FA8-0819E2EAAC93} - C:\Program Files\Adobe\Adobe Acrobat 6.0\Acrobat\AcroIEFavClient.dll ()
O3 - HKU\S-1-5-21-2209711222-1865678921-789788502-1000\..\Toolbar\WebBrowser: (Google Toolbar) - {2318C2B1-4965-11D4-9B18-009027A5CD4F} - C:\Program Files\Google\Google Toolbar\GoogleToolbar.dll (Google Inc.)
O3 - HKU\S-1-5-21-2209711222-1865678921-789788502-1000\..\Toolbar\WebBrowser: (Adobe PDF) - {47833539-D0C5-4125-9FA8-0819E2EAAC93} - C:\Program Files\Adobe\Adobe Acrobat 6.0\Acrobat\AcroIEFavClient.dll ()
O4 - HKLM..\Run: [Adobe Reader Speed Launcher] C:\Program Files\Adobe\Reader 9.0\Reader\Reader_sl.exe (Adobe Systems Incorporated)
O4 - HKLM..\Run: [AdobeVersionCue] C:\Program Files\Adobe\Adobe Version Cue\ControlPanel\VersionCueTray.exe (Adobe Systems)
O4 - HKLM..\Run: [AppleSyncNotifier] C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleSyncNotifier.exe (Apple Inc.)
O4 - HKLM..\Run: [DellSupportCenter] C:\Program Files\Dell Support Center\bin\sprtcmd.exe (SupportSoft, Inc.)
O4 - HKLM..\Run: [dscactivate] C:\Program Files\Dell Support Center\gs_agent\custom\dsca.exe ( )
O4 - HKLM..\Run: [ISUSPM Startup] C:\Program Files\Common Files\InstallShield\UpdateService\ISUSPM.exe (Macrovision Corporation)
O4 - HKLM..\Run: [ISUSScheduler] C:\Program Files\Common Files\InstallShield\UpdateService\issch.exe (Macrovision Corporation)
O4 - HKLM..\Run: [iTunesHelper] C:\Program Files\iTunes\iTunesHelper.exe (Apple Inc.)
O4 - HKLM..\Run: [LifeCam] C:\Program Files\Microsoft LifeCam\LifeExp.exe (Microsoft Corporation)
O4 - HKLM..\Run: [mcagent_exe] C:\Program Files\McAfee.com\Agent\mcagent.exe (McAfee, Inc.)
O4 - HKLM..\Run: [NBKeyScan] C:\Program Files\Nero\Nero8\Nero BackItUp\NBKeyScan.exe File not found
O4 - HKLM..\Run: [NvCplDaemon] C:\Windows\System32\NvCpl.DLL (NVIDIA Corporation)
O4 - HKLM..\Run: [NvMediaCenter] C:\Windows\System32\NvMcTray.DLL (NVIDIA Corporation)
O4 - HKLM..\Run: [NvSvc] C:\Windows\System32\nvsvc.DLL (NVIDIA Corporation)
O4 - HKLM..\Run: [POEngine] File not found
O4 - HKLM..\Run: [QuickTime Task] C:\Program Files\QuickTime\QTTask.exe (Apple Inc.)
O4 - HKLM..\Run: [RtHDVCpl] C:\Windows\RtHDVCpl.exe (Realtek Semiconductor)
O4 - HKLM..\Run: [SunJavaUpdateSched] C:\Program Files\Common Files\Java\Java Update\jusched.exe (Sun Microsystems, Inc.)
O4 - HKLM..\Run: [TkBellExe] C:\Program Files\Common Files\Real\Update_OB\realsched.exe (RealNetworks, Inc.)
O4 - HKLM..\Run: [VX1000] C:\Windows\vVX1000.exe (Microsoft Corporation)
O4 - HKLM..\Run: [Windows Defender] C:\Program Files\Windows Defender\MSASCui.exe (Microsoft Corporation)
O4 - HKU\S-1-5-19..\Run: [WindowsWelcomeCenter] C:\Windows\System32\oobefldr.dll (Microsoft Corporation)
O4 - HKU\S-1-5-20..\Run: [WindowsWelcomeCenter] C:\Windows\System32\oobefldr.dll (Microsoft Corporation)
O4 - HKU\S-1-5-21-2209711222-1865678921-789788502-1000..\Run: [BgMonitor_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}] C:\Program Files\Common Files\Nero\Lib\NMBgMonitor.exe File not found
O4 - HKU\S-1-5-21-2209711222-1865678921-789788502-1000..\Run: [DellSupport] C:\Program Files\DellSupport\DSAgnt.exe (Gteko Ltd.)
O4 - HKU\S-1-5-21-2209711222-1865678921-789788502-1000..\Run: [DellSupportCenter] C:\Program Files\Dell Support Center\bin\sprtcmd.exe (SupportSoft, Inc.)
O4 - HKU\S-1-5-21-2209711222-1865678921-789788502-1000..\Run: [Google Update] C:\Users\David\AppData\Local\Google\Update\GoogleUpdate.exe (Google Inc.)
O4 - HKU\S-1-5-21-2209711222-1865678921-789788502-1000..\Run: [SpybotSD TeaTimer] C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe (Safer Networking Limited)
O4 - HKU\S-1-5-21-2209711222-1865678921-789788502-1000..\Run: [swg] C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe (Google Inc.)
O4 - HKU\S-1-5-21-2209711222-1865678921-789788502-1000..\Run: [WMPNSCFG] C:\Program Files\Windows Media Player\wmpnscfg.exe (Microsoft Corporation)
O9 - Extra Button: PokerStars - {3AD14F0C-ED16-4e43-B6D8-661B03F6A1EF} - C:\Program Files\PokerStars\PokerStarsUpdate.exe (PokerStars)
O9 - Extra Button: Skype - {77BF5300-1474-4EC7-9980-D32B190E9B07} - C:\Program Files\Skype\Toolbars\Internet Explorer\SkypeIEPlugin.dll (Skype Technologies S.A.)
O9 - Extra 'Tools' menuitem : Spybot - Search && Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll (Safer Networking Limited)
O10 - NameSpace_Catalog5\Catalog_Entries\000000000005 [] - C:\Program Files\Bonjour\mdnsNSP.dll (Apple Inc.)
O13 - gopher Prefix: missing
O15 - HKU\S-1-5-21-2209711222-1865678921-789788502-1000\..Trusted Domains: internet ([]about in Trusted sites)
O15 - HKU\S-1-5-21-2209711222-1865678921-789788502-1000\..Trusted Domains: mcafee.com ([]http in Trusted sites)
O15 - HKU\S-1-5-21-2209711222-1865678921-789788502-1000\..Trusted Domains: mcafee.com ([]https in Trusted sites)
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} http://java.sun.com/update/1.6.0/jinsta ... s-i586.cab (Java Plug-in 1.6.0_18)
O16 - DPF: {CAFEEFAC-0016-0000-0000-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinsta ... s-i586.cab (Java Plug-in 1.6.0)
O16 - DPF: {CAFEEFAC-0016-0000-0018-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinsta ... s-i586.cab (Java Plug-in 1.6.0_18)
O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinsta ... s-i586.cab (Java Plug-in 1.6.0_18)
O16 - DPF: {CF40ACC5-E1BB-4AFF-AC72-04C2F616BCA7} http://wwwimages.adobe.com/www.adobe.co ... nos/gp.cab (Reg Error: Key error.)
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} http://fpdownload2.macromedia.com/get/s ... wflash.cab (Shockwave Flash Object)
O16 - DPF: {E2883E8F-472F-4FB0-9522-AC9BF37916A7} http://platformdl.adobe.com/NOS/getPlusPlus/1.6/gp.cab (Reg Error: Key error.)
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 192.168.1.254
O18 - Protocol\Handler\dssrequest {5513F07E-936B-4E52-9B00-067394E91CC5} - c:\Program Files\McAfee\SiteAdvisor\McIEPlg.dll (McAfee, Inc.)
O18 - Protocol\Handler\sacore {5513F07E-936B-4E52-9B00-067394E91CC5} - c:\Program Files\McAfee\SiteAdvisor\McIEPlg.dll (McAfee, Inc.)
O18 - Protocol\Handler\skype4com {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\Program Files\Common Files\Skype\Skype4COM.dll (Skype Technologies)
O18 - Protocol\Handler\x-excid {9D6CC632-1337-4a33-9214-2DA092E776F4} - c:\Windows\Downloaded Program Files\mimectl.dll ()
O18 - Protocol\Filter\x-sdch - No CLSID value found
O20 - HKLM Winlogon: Shell - (explorer.exe) - C:\Windows\explorer.exe (Microsoft Corporation)
O20 - HKLM Winlogon: UserInit - (C:\Windows\system32\sdra64.exe) - C:\Windows\System32\sdra64.exe ( )
O20 - Winlogon\Notify\GoToAssist: DllName - C:\Program Files\Citrix\GoToAssist\480\G2AWinLogon.dll - C:\Program Files\Citrix\GoToAssist\480\G2AWinLogon.dll File not found
O24 - Desktop WallPaper: C:\Users\David\AppData\Roaming\Microsoft\Windows Photo Gallery\Windows Photo Gallery Wallpaper.jpg
O24 - Desktop BackupWallPaper: C:\Users\David\AppData\Roaming\Microsoft\Windows Photo Gallery\Windows Photo Gallery Wallpaper.jpg
O32 - HKLM CDRom: AutoRun - 1
O32 - AutoRun File - [2006/09/18 16:43:36 | 000,000,024 | ---- | M] () - C:\autoexec.bat -- [ NTFS ]
O34 - HKLM BootExecute: (autocheck autochk *) - File not found
O35 - comfile [open] -- "%1" %*
O35 - exefile [open] -- "%1" %*

========== Files/Folders - Created Within 30 Days ==========

[2010/02/02 06:50:38 | 000,548,864 | ---- | C] (OldTimer Tools) -- C:\Users\David\Desktop\OTL.exe
[2010/02/01 21:14:48 | 000,000,000 | ---D | C] -- C:\Program Files\iPod
[2010/02/01 21:14:34 | 000,000,000 | ---D | C] -- C:\Program Files\iTunes
[2010/02/01 21:09:47 | 000,000,000 | ---D | C] -- C:\Program Files\QuickTime
[2010/01/30 09:46:40 | 000,000,000 | ---D | C] -- C:\MGADiagToolOutput
[2010/01/30 09:44:58 | 000,000,000 | ---D | C] -- C:\ProgramData\Office Genuine Advantage
[2010/01/30 09:43:45 | 001,560,952 | ---- | C] (Microsoft Corporation) -- C:\Users\David\Desktop\MGADiag.exe
[2010/01/29 09:20:01 | 000,204,496 | ---- | C] (Malwarebytes) -- C:\Users\David\Desktop\StartUpLite.exe
[2010/01/27 19:42:51 | 000,000,000 | ---D | C] -- C:\ProgramData\Sun
[2010/01/27 19:41:47 | 000,153,376 | ---- | C] (Sun Microsystems, Inc.) -- C:\Windows\System32\javaws.exe
[2010/01/27 19:41:47 | 000,145,184 | ---- | C] (Sun Microsystems, Inc.) -- C:\Windows\System32\javaw.exe
[2010/01/27 19:41:47 | 000,145,184 | ---- | C] (Sun Microsystems, Inc.) -- C:\Windows\System32\java.exe
[2010/01/25 15:36:15 | 000,000,000 | -HSD | C] -- C:\Windows\System32\lowsec
[2010/01/24 09:09:19 | 000,000,000 | ---D | C] -- C:\Windows\CheckSur
[2010/01/23 16:43:40 | 000,000,000 | ---D | C] -- C:\Program Files\TrendMicro
[2010/01/23 15:35:24 | 000,000,000 | ---D | C] -- C:\Windows\pss
[2010/01/23 13:29:59 | 000,181,120 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\MpSigStub.exe
[2010/01/23 13:18:24 | 000,130,424 | ---- | C] (McAfee, Inc.) -- C:\Windows\System32\drivers\Mpfp.sys
[2010/01/23 13:17:54 | 000,000,000 | ---D | C] -- C:\Program Files\Common Files\McAfee
[2010/01/23 13:17:52 | 000,000,000 | ---D | C] -- C:\Program Files\McAfee.com
[2010/01/23 12:14:26 | 000,000,000 | ---D | C] -- C:\ProgramData\Spybot - Search & Destroy
[2010/01/23 12:14:26 | 000,000,000 | ---D | C] -- C:\Program Files\Spybot - Search & Destroy
[2010/01/23 08:10:27 | 000,000,000 | ---D | C] -- C:\Users\David\AppData\Roaming\Malwarebytes
[2010/01/23 08:10:23 | 000,038,224 | ---- | C] (Malwarebytes Corporation) -- C:\Windows\System32\drivers\mbamswissarmy.sys
[2010/01/23 08:10:22 | 000,019,160 | ---- | C] (Malwarebytes Corporation) -- C:\Windows\System32\drivers\mbam.sys
[2010/01/23 08:10:22 | 000,000,000 | ---D | C] -- C:\ProgramData\Malwarebytes
[2010/01/23 08:10:21 | 000,000,000 | ---D | C] -- C:\Program Files\Malwarebytes' Anti-Malware
[2010/01/22 21:10:31 | 000,156,672 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\t2embed.dll
[2010/01/22 21:10:31 | 000,072,704 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\fontsub.dll
[2010/01/22 21:10:03 | 000,164,352 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\ieui.dll
[2010/01/22 21:10:03 | 000,109,056 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\iesysprep.dll
[2010/01/22 21:10:03 | 000,071,680 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\iesetup.dll
[2010/01/22 21:10:03 | 000,055,808 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\iernonce.dll
[2010/01/22 21:10:02 | 000,173,056 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\ie4uinit.exe
[2010/01/22 21:10:01 | 000,133,632 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\ieUnatt.exe
[2010/01/22 21:10:00 | 001,638,912 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\mshtml.tlb
[2010/01/22 21:09:59 | 000,055,296 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\msfeedsbs.dll
[2010/01/22 21:09:59 | 000,013,312 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\msfeedssync.exe
[2010/01/22 21:09:58 | 000,594,432 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\msfeeds.dll
[2010/01/22 21:09:58 | 000,387,584 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\iedkcs32.dll
[2010/01/22 21:09:58 | 000,184,320 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\iepeers.dll
[2010/01/22 21:09:58 | 000,025,600 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\jsproxy.dll
[2010/01/22 21:09:57 | 001,469,440 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\inetcpl.cpl
[2010/01/18 09:11:20 | 000,000,000 | ---D | C] -- C:\68b411019a85948517
[2008/12/13 11:51:08 | 000,047,360 | ---- | C] (VSO Software) -- C:\Users\David\AppData\Roaming\pcouffin.sys

========== Files - Modified Within 30 Days ==========

[2010/02/02 06:51:47 | 003,932,160 | -HS- | M] () -- C:\Users\David\ntuser.dat
[2010/02/02 06:51:01 | 000,548,864 | ---- | M] (OldTimer Tools) -- C:\Users\David\Desktop\OTL.exe
[2010/02/02 06:44:56 | 000,011,654 | ---- | M] () -- C:\Windows\System32\Config.MPF
[2010/02/02 06:41:59 | 000,000,908 | ---- | M] () -- C:\Windows\tasks\GoogleUpdateTaskUserS-1-5-21-2209711222-1865678921-789788502-1000UA.job
[2010/02/02 06:39:31 | 000,003,664 | -H-- | M] () -- C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-2P-1.C7483456-A289-439d-8115-601632D005A0
[2010/02/02 06:39:31 | 000,003,664 | -H-- | M] () -- C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-2P-0.C7483456-A289-439d-8115-601632D005A0
[2010/02/02 06:39:29 | 000,000,006 | -H-- | M] () -- C:\Windows\tasks\SA.DAT
[2010/02/02 06:39:19 | 000,067,584 | --S- | M] () -- C:\Windows\bootstat.dat
[2010/02/02 06:39:12 | 2145,902,592 | -HS- | M] () -- C:\hiberfil.sys
[2010/02/01 21:18:11 | 000,524,288 | -HS- | M] () -- C:\Users\David\ntuser.dat{ba2d0684-07c0-11df-baf8-ada2ffca9819}.TMContainer00000000000000000001.regtrans-ms
[2010/02/01 21:18:11 | 000,065,536 | -HS- | M] () -- C:\Users\David\ntuser.dat{ba2d0684-07c0-11df-baf8-ada2ffca9819}.TM.blf
[2010/02/01 21:17:34 | 001,348,135 | -H-- | M] () -- C:\Users\David\AppData\Local\IconCache.db
[2010/02/01 21:15:49 | 000,001,804 | ---- | M] () -- C:\Users\Public\Desktop\iTunes.lnk
[2010/02/01 19:40:00 | 000,000,856 | ---- | M] () -- C:\Windows\tasks\GoogleUpdateTaskUserS-1-5-21-2209711222-1865678921-789788502-1000Core.job
[2010/02/01 19:14:00 | 000,000,418 | -H-- | M] () -- C:\Windows\tasks\User_Feed_Synchronization-{5534744B-AA83-4504-A996-4815F336029C}.job
[2010/02/01 07:44:53 | 226,920,704 | ---- | M] () -- C:\Windows\MEMORY.DMP
[2010/02/01 07:41:53 | 000,293,376 | ---- | M] () -- C:\Users\David\Desktop\kt5yy707.exe
[2010/02/01 07:18:40 | 000,068,160 | ---- | M] () -- C:\Users\David\AppData\Local\GDIPFONTCACHEV1.DAT
[2010/02/01 07:18:17 | 000,282,296 | ---- | M] () -- C:\Windows\System32\FNTCACHE.DAT
[2010/01/31 13:11:52 | 000,010,716 | ---- | M] () -- C:\Users\David\AppData\Roaming\wklnhst.dat
[2010/01/31 13:07:41 | 000,002,477 | ---- | M] () -- C:\Users\David\Desktop\HiJackThis.lnk
[2010/01/30 09:48:00 | 000,441,856 | ---- | M] () -- C:\Users\David\Desktop\CKScanner.exe
[2010/01/30 09:43:51 | 001,560,952 | ---- | M] (Microsoft Corporation) -- C:\Users\David\Desktop\MGADiag.exe
[2010/01/29 18:57:43 | 000,225,280 | ---- | M] () -- C:\Users\David\AppData\Local\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2010/01/29 18:57:13 | 000,000,668 | ---- | M] () -- C:\Users\David\AppData\Roaming\vso_ts_preview.xml
[2010/01/29 09:20:01 | 000,204,496 | ---- | M] (Malwarebytes) -- C:\Users\David\Desktop\StartUpLite.exe
[2010/01/27 13:41:02 | 000,002,044 | ---- | M] () -- C:\Users\David\Desktop\Google Chrome.lnk
[2010/01/26 16:54:36 | 000,035,920 | ---- | M] (NVIDIA Corporation) -- C:\Windows\System32\drivers\nvstor.sys
[2010/01/24 07:00:22 | 000,001,356 | ---- | M] () -- C:\Users\David\AppData\Local\d3d9caps.dat
[2010/01/23 16:42:26 | 001,401,344 | ---- | M] () -- C:\Users\David\Desktop\HijackThis.msi
[2010/01/23 15:14:42 | 000,000,340 | ---- | M] () -- C:\Windows\tasks\McDefragTask.job
[2010/01/23 15:14:42 | 000,000,318 | ---- | M] () -- C:\Windows\tasks\McQcTask.job
[2010/01/23 12:14:30 | 000,001,017 | ---- | M] () -- C:\Users\David\Desktop\Spybot - Search & Destroy.lnk
[2010/01/23 08:10:26 | 000,000,780 | ---- | M] () -- C:\Users\Public\Desktop\Malwarebytes' Anti-Malware.lnk
[2010/01/22 20:52:50 | 000,524,288 | -HS- | M] () -- C:\Users\David\ntuser.dat{ba2d0684-07c0-11df-baf8-ada2ffca9819}.TMContainer00000000000000000002.regtrans-ms
[2010/01/22 20:46:59 | 000,524,288 | -HS- | M] () -- C:\Users\David\NTUSER.DAT{3a539871-6a70-11db-887c-d362bd253390}.TMContainer00000000000000000001.regtrans-ms
[2010/01/22 20:46:59 | 000,065,536 | -HS- | M] () -- C:\Users\David\NTUSER.DAT{3a539871-6a70-11db-887c-d362bd253390}.TM.blf
[2010/01/14 11:12:06 | 000,181,120 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\MpSigStub.exe
[2010/01/07 16:07:14 | 000,038,224 | ---- | M] (Malwarebytes Corporation) -- C:\Windows\System32\drivers\mbamswissarmy.sys
[2010/01/07 16:07:04 | 000,019,160 | ---- | M] (Malwarebytes Corporation) -- C:\Windows\System32\drivers\mbam.sys
[2010/01/04 07:38:51 | 000,703,448 | ---- | M] () -- C:\Windows\System32\PerfStringBackup.INI
[2010/01/04 07:38:51 | 000,608,270 | ---- | M] () -- C:\Windows\System32\perfh009.dat
[2010/01/04 07:38:51 | 000,109,138 | ---- | M] () -- C:\Windows\System32\perfc009.dat

========== Files Created - No Company Name ==========

[2010/02/01 21:15:49 | 000,001,804 | ---- | C] () -- C:\Users\Public\Desktop\iTunes.lnk
[2010/02/01 07:41:48 | 000,293,376 | ---- | C] () -- C:\Users\David\Desktop\kt5yy707.exe
[2010/01/30 09:47:59 | 000,441,856 | ---- | C] () -- C:\Users\David\Desktop\CKScanner.exe
[2010/01/23 16:43:41 | 000,002,477 | ---- | C] () -- C:\Users\David\Desktop\HiJackThis.lnk
[2010/01/23 16:42:15 | 001,401,344 | ---- | C] () -- C:\Users\David\Desktop\HijackThis.msi
[2010/01/23 16:36:51 | 2145,902,592 | -HS- | C] () -- C:\hiberfil.sys
[2010/01/23 13:21:06 | 000,011,654 | ---- | C] () -- C:\Windows\System32\Config.MPF
[2010/01/23 13:18:10 | 000,000,340 | ---- | C] () -- C:\Windows\tasks\McDefragTask.job
[2010/01/23 13:18:08 | 000,000,318 | ---- | C] () -- C:\Windows\tasks\McQcTask.job
[2010/01/23 12:14:30 | 000,001,017 | ---- | C] () -- C:\Users\David\Desktop\Spybot - Search & Destroy.lnk
[2010/01/23 08:10:26 | 000,000,780 | ---- | C] () -- C:\Users\Public\Desktop\Malwarebytes' Anti-Malware.lnk
[2010/01/22 20:52:50 | 000,524,288 | -HS- | C] () -- C:\Users\David\ntuser.dat{ba2d0684-07c0-11df-baf8-ada2ffca9819}.TMContainer00000000000000000002.regtrans-ms
[2010/01/22 20:52:50 | 000,524,288 | -HS- | C] () -- C:\Users\David\ntuser.dat{ba2d0684-07c0-11df-baf8-ada2ffca9819}.TMContainer00000000000000000001.regtrans-ms
[2010/01/22 20:52:50 | 000,065,536 | -HS- | C] () -- C:\Users\David\ntuser.dat{ba2d0684-07c0-11df-baf8-ada2ffca9819}.TM.blf
[2009/08/18 16:37:24 | 000,117,248 | ---- | C] () -- C:\Windows\System32\EhStorAuthn.dll
[2009/02/22 08:05:17 | 000,000,056 | -H-- | C] () -- C:\ProgramData\ezsidmv.dat
[2009/01/25 11:46:32 | 000,027,648 | ---- | C] () -- C:\Windows\System32\AVSredirect.dll
[2008/12/13 11:52:40 | 000,000,668 | ---- | C] () -- C:\Users\David\AppData\Roaming\vso_ts_preview.xml
[2008/12/13 11:52:23 | 000,000,034 | ---- | C] () -- C:\Users\David\AppData\Roaming\pcouffin.log
[2008/12/13 11:51:08 | 000,087,608 | ---- | C] () -- C:\Users\David\AppData\Roaming\inst.exe
[2008/12/13 11:51:08 | 000,007,887 | ---- | C] () -- C:\Users\David\AppData\Roaming\pcouffin.cat
[2008/12/13 11:51:08 | 000,001,144 | ---- | C] () -- C:\Users\David\AppData\Roaming\pcouffin.inf
[2007/11/08 15:46:10 | 000,010,716 | ---- | C] () -- C:\Users\David\AppData\Roaming\wklnhst.dat
[2007/11/05 13:55:24 | 000,000,376 | ---- | C] () -- C:\Windows\ODBC.INI
[2007/10/22 18:03:02 | 000,225,280 | ---- | C] () -- C:\Users\David\AppData\Local\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2007/10/21 08:05:13 | 000,000,120 | ---- | C] () -- C:\Windows\wininit.ini
[2007/10/21 07:10:19 | 000,001,356 | ---- | C] () -- C:\Users\David\AppData\Local\d3d9caps.dat
[2007/04/10 16:46:52 | 000,015,498 | ---- | C] () -- C:\Windows\VX1000.ini
[2007/03/19 04:04:58 | 000,003,584 | ---- | C] () -- C:\Windows\System32\namResES.dll
[2007/03/19 04:04:58 | 000,003,072 | ---- | C] () -- C:\Windows\System32\namResIT.dll
[2007/03/19 04:04:58 | 000,003,072 | ---- | C] () -- C:\Windows\System32\namResFR.dll
[2007/03/19 04:04:58 | 000,003,072 | ---- | C] () -- C:\Windows\System32\namResENG.dll
[2007/03/19 04:04:58 | 000,003,072 | ---- | C] () -- C:\Windows\System32\namResDE.dll
[2007/03/19 04:04:56 | 000,003,584 | ---- | C] () -- C:\Windows\System32\namResPTB.dll
[2007/03/19 04:04:56 | 000,003,072 | ---- | C] () -- C:\Windows\System32\namResZHC.dll
[2007/03/19 04:04:56 | 000,003,072 | ---- | C] () -- C:\Windows\System32\namResKO.dll
[2007/03/19 04:04:56 | 000,003,072 | ---- | C] () -- C:\Windows\System32\namResJA.dll
[2007/03/19 04:04:54 | 000,022,016 | ---- | C] () -- C:\Windows\System32\nam_page.dll
[2007/03/19 04:04:54 | 000,003,072 | ---- | C] () -- C:\Windows\System32\namResZHT.dll
[2007/02/22 10:17:50 | 000,000,071 | ---- | C] () -- C:\Windows\pn.ini
[2007/02/22 10:17:50 | 000,000,051 | ---- | C] () -- C:\Windows\pr.ini
[2006/11/02 07:35:32 | 000,005,632 | ---- | C] () -- C:\Windows\System32\sysprepMCE.dll
[2006/11/02 02:40:29 | 000,013,750 | ---- | C] () -- C:\Windows\System32\pacerprf.ini
[2006/03/18 08:16:04 | 000,540,178 | ---- | C] () -- C:\Windows\System32\x264vfw.dll

========== LOP Check ==========

[2008/10/08 17:03:23 | 000,000,000 | ---D | M] -- C:\Users\David\AppData\Roaming\Autodesk
[2010/01/29 09:40:19 | 000,000,000 | ---D | M] -- C:\Users\David\AppData\Roaming\Shareaza
[2008/12/22 17:10:35 | 000,000,000 | ---D | M] -- C:\Users\David\AppData\Roaming\Template
[2008/09/06 13:45:49 | 000,000,000 | ---D | M] -- C:\Users\David\AppData\Roaming\TravelerSafe+
[2010/01/29 18:56:07 | 000,000,000 | ---D | M] -- C:\Users\David\AppData\Roaming\uTorrent
[2010/01/28 18:27:05 | 000,000,000 | ---D | M] -- C:\Users\David\AppData\Roaming\Vso
[2009/02/16 11:01:38 | 000,000,000 | ---D | M] -- C:\Users\David\AppData\Roaming\WorksImaging
[2010/01/23 15:14:42 | 000,000,340 | ---- | M] () -- C:\Windows\Tasks\McDefragTask.job
[2010/01/23 15:14:42 | 000,000,318 | ---- | M] () -- C:\Windows\Tasks\McQcTask.job
[2010/02/01 21:17:56 | 000,032,618 | ---- | M] () -- C:\Windows\Tasks\SCHEDLGU.TXT
[2010/02/01 19:14:00 | 000,000,418 | -H-- | M] () -- C:\Windows\Tasks\User_Feed_Synchronization-{5534744B-AA83-4504-A996-4815F336029C}.job

========== Purity Check ==========



========== Alternate Data Streams ==========

@Alternate Data Stream - 76 bytes -> C:\Users\David\Desktop\Downloads:Roxio EMC Stream
< End of report >
dcowie
Regular Member
 
Posts: 23
Joined: January 24th, 2010, 9:54 am

Re: Help needed with browser hijack

Unread postby dcowie » February 2nd, 2010, 9:08 am

J&J,

Here is OTL's Extras.txt...sysprot log to follow.

OTL Extras logfile created on: 02/02/2010 6:53:58 AM - Run 1
OTL by OldTimer - Version 3.1.27.1 Folder = C:\Users\David\Desktop
Windows Vista Home Premium Edition Service Pack 2 (Version = 6.0.6002) - Type = NTWorkstation
Internet Explorer (Version = 8.0.6001.18882)
Locale: 00001009 | Country: Canada | Language: ENC | Date Format: dd/MM/yyyy

2.00 Gb Total Physical Memory | 1.00 Gb Available Physical Memory | 56.00% Memory free
4.00 Gb Paging File | 3.00 Gb Available in Paging File | 73.00% Paging File free
Paging file location(s): ?:\pagefile.sys [binary data]

%SystemDrive% = C: | %SystemRoot% = C:\Windows | %ProgramFiles% = C:\Program Files
Drive C: | 222.78 Gb Total Space | 105.34 Gb Free Space | 47.29% Space Free | Partition Type: NTFS
Drive D: | 10.00 Gb Total Space | 5.35 Gb Free Space | 53.52% Space Free | Partition Type: NTFS
E: Drive not present or media not loaded
F: Drive not present or media not loaded
G: Drive not present or media not loaded
H: Drive not present or media not loaded
I: Drive not present or media not loaded

Computer Name: HARRY
Current User Name: David
Logged in as Administrator.

Current Boot Mode: Normal
Scan Mode: All users
Company Name Whitelist: Off
Skip Microsoft Files: Off
File Age = 30 Days
Output = Standard

========== Extra Registry (SafeList) ==========


========== File Associations ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\<extension>]
.cpl [@ = cplfile] -- C:\Windows\System32\control.exe (Microsoft Corporation)
.hlp [@ = hlpfile] -- C:\Windows\winhlp32.exe (Microsoft Corporation)
.html [@ = htmlfile] -- C:\Program Files\Internet Explorer\IEXPLORE.EXE (Microsoft Corporation)

[HKEY_USERS\S-1-5-21-2209711222-1865678921-789788502-1000\SOFTWARE\Classes\<extension>]
.html [@ = ChromeHTML] -- C:\Users\David\AppData\Local\Google\Chrome\Application\chrome.exe (Google Inc.)

========== Shell Spawning ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\<key>\shell\[command]\command]
batfile [open] -- "%1" %*
cmdfile [open] -- "%1" %*
comfile [open] -- "%1" %*
cplfile [cplopen] -- %SystemRoot%\System32\control.exe "%1",%* (Microsoft Corporation)
exefile [open] -- "%1" %*
helpfile [open] -- Reg Error: Key error.
hlpfile [open] -- %SystemRoot%\winhlp32.exe %1 (Microsoft Corporation)
htmlfile [edit] -- "C:\Program Files\Microsoft Office\Office10\msohtmed.exe" %1 (Microsoft Corporation)
htmlfile [open] -- "C:\Program Files\Internet Explorer\IEXPLORE.EXE" -nohome (Microsoft Corporation)
htmlfile [opennew] -- "C:\Program Files\Internet Explorer\IEXPLORE.EXE" %1 (Microsoft Corporation)
htmlfile [print] -- "C:\Program Files\Microsoft Office\Office10\msohtmed.exe" /p %1 (Microsoft Corporation)
http [open] -- "C:\Program Files\Internet Explorer\IEXPLORE.EXE" -nohome (Microsoft Corporation)
https [open] -- "C:\Program Files\Internet Explorer\IEXPLORE.EXE" -nohome (Microsoft Corporation)
inffile [install] -- %SystemRoot%\System32\InfDefaultInstall.exe "%1" (Microsoft Corporation)
piffile [open] -- "%1" %*
regfile [merge] -- Reg Error: Key error.
scrfile [config] -- "%1"
scrfile [install] -- rundll32.exe desk.cpl,InstallScreenSaver %l (Microsoft Corporation)
scrfile [open] -- "%1" /S
txtfile [edit] -- Reg Error: Key error.
Unknown [openas] -- %SystemRoot%\system32\rundll32.exe %SystemRoot%\system32\shell32.dll,OpenAs_RunDLL %1
Directory [cmd] -- cmd.exe /s /k pushd "%V" (Microsoft Corporation)
Directory [find] -- %SystemRoot%\Explorer.exe (Microsoft Corporation)
Folder [open] -- %SystemRoot%\Explorer.exe /separate,/idlist,%I,%L (Microsoft Corporation)
Folder [explore] -- %SystemRoot%\Explorer.exe /separate,/e,/idlist,%I,%L (Microsoft Corporation)
Drive [find] -- %SystemRoot%\Explorer.exe (Microsoft Corporation)
Applications\iexplore.exe [open] -- "C:\Program Files\Internet Explorer\iexplore.exe" %1 (Microsoft Corporation)
CLSID\{871C5380-42A0-1069-A2EA-08002B30309D} [OpenHomePage] -- "C:\Program Files\Internet Explorer\iexplore.exe" (Microsoft Corporation)

========== Security Center Settings ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center]
"cval" = 1

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\McAfeeAntiSpyware]
"DisableMonitoring" = 1

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Svc]
"AntiVirusOverride" = 0
"AntiSpywareOverride" = 0
"FirewallOverride" = 0
"VistaSp1" = Reg Error: Unknown registry data type -- File not found
"VistaSp2" = Reg Error: Unknown registry data type -- File not found

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Svc\Vol]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile]
"DisableNotifications" = 0
"EnableFirewall" = 0

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile]
"DisableNotifications" = 0
"EnableFirewall" = 1

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\PublicProfile]
"DisableNotifications" = 0
"EnableFirewall" = 0

========== Authorized Applications List ==========


========== Vista Active Open Ports Exception List ==========

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\FirewallRules]
"{048D447E-961F-404A-BF81-9BFDF141B32E}" = lport=445 | protocol=6 | dir=in | app=system |
"{0647995B-B93B-45C2-8CEE-381DC5354AF3}" = lport=1900 | protocol=17 | dir=in | svc=ssdpsrv | app=%systemroot%\system32\svchost.exe |
"{14B5624C-F061-448B-B836-412F06BFE0BA}" = rport=137 | protocol=17 | dir=out | app=system |
"{2EF36DA3-FC9D-4A4A-8746-11B864FF106A}" = lport=137 | protocol=17 | dir=in | app=system |
"{2F470F77-1470-4329-8249-BA0544FFAF48}" = rport=5355 | protocol=17 | dir=out | svc=dnscache | app=%systemroot%\system32\svchost.exe |
"{3AE471AB-4227-40ED-9C71-B5BC917A2D4A}" = rport=3702 | protocol=17 | dir=out | svc=fdrespub | app=%systemroot%\system32\svchost.exe |
"{3EAA141D-6FE9-495D-9D21-C8E390E0F7CE}" = lport=3702 | protocol=17 | dir=in | svc=fdphost | app=%systemroot%\system32\svchost.exe |
"{5364E6A7-A8B2-45D6-8A7E-D47EB02B0F58}" = lport=3702 | protocol=17 | dir=in | svc=fdrespub | app=%systemroot%\system32\svchost.exe |
"{53B25B81-2BEB-4CE2-8581-69CC4DE1C1DE}" = lport=rpc | protocol=6 | dir=in | svc=spooler | app=%systemroot%\system32\spoolsv.exe |
"{648FDD6E-2709-492A-A2DF-0591C3670AE2}" = lport=5355 | protocol=17 | dir=in | svc=dnscache | app=%systemroot%\system32\svchost.exe |
"{7E256D9C-EC73-43AB-B212-CB36923DF90D}" = rport=3702 | protocol=17 | dir=out | svc=fdphost | app=%systemroot%\system32\svchost.exe |
"{861F6549-D718-4148-8B1B-0B5F4EAD755B}" = rport=139 | protocol=6 | dir=out | app=system |
"{9E64E0E4-2035-4C6A-B04C-B75AC92E54D9}" = lport=139 | protocol=6 | dir=in | app=system |
"{BCE7A8DD-7F4B-4ED3-A8F7-6BBA8FD7D52C}" = lport=rpc-epmap | protocol=6 | dir=in | svc=rpcss | name=@firewallapi.dll,-28539 |
"{C0CB8F59-4A9F-4730-A90D-4818DEB856BD}" = rport=445 | protocol=6 | dir=out | app=system |
"{C3DD1CD7-67E8-4672-93A5-E4063ACEAF6F}" = lport=138 | protocol=17 | dir=in | app=system |
"{CE63AC42-175D-4AFD-AB4E-9E089BDB23F8}" = rport=1900 | protocol=17 | dir=out | svc=ssdpsrv | app=%systemroot%\system32\svchost.exe |
"{D0C816BC-F4C5-4537-8AD9-8FC50D41A82D}" = rport=138 | protocol=17 | dir=out | app=system |

========== Vista Active Application Exception List ==========

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\FirewallRules]
"{048BA0BC-1C90-401D-8AA9-CA2BA362DD62}" = protocol=17 | dir=in | app=c:\program files\yahoo!\messenger\yahoomessenger.exe |
"{0A09C139-BBBF-4E73-BA9A-9772C018CDC1}" = protocol=6 | dir=in | app=c:\program files\common files\mcafee\mna\mcnasvc.exe |
"{0D339E68-1073-410A-B709-C82E9181DA87}" = protocol=6 | dir=in | app=c:\program files\utorrent\utorrent.exe |
"{14F14F68-E02C-4C71-8327-A964AA5A88E3}" = protocol=17 | dir=in | app=c:\program files\utorrent\utorrent.exe |
"{25383295-9DC9-44CA-9C82-34875ED0371A}" = protocol=17 | dir=in | app=c:\program files\utorrent\utorrent.exe |
"{2B34F66B-F6DB-4929-B529-D6681AA71F2C}" = protocol=17 | dir=in | app=c:\program files\microsoft lifecam\lifecam.exe |
"{2EECDC65-EBA9-456D-8281-5D74AB995C77}" = protocol=17 | dir=in | app=c:\program files\bonjour\mdnsresponder.exe |
"{3E4F2EEE-5859-4022-8819-B2A52A29F255}" = protocol=17 | dir=in | app=c:\program files\bonjour\mdnsresponder.exe |
"{4F5F1952-CBE9-4CAD-8183-D0BE46F64506}" = protocol=6 | dir=in | app=c:\program files\yahoo!\messenger\yahoomessenger.exe |
"{5C7EBF62-3A07-4F68-9E10-25985FDED923}" = protocol=17 | dir=in | app=c:\program files\itunes\itunes.exe |
"{6A795C98-971B-445B-BE43-522181F78876}" = protocol=17 | dir=in | app=c:\program files\microsoft lifecam\lifeexp.exe |
"{A90FFE46-16C6-419A-A7EA-3AD4FAD9B453}" = protocol=6 | dir=in | app=c:\program files\itunes\itunes.exe |
"{A94A0771-4721-4058-B08F-66B6DFB7AD91}" = protocol=6 | dir=in | app=c:\program files\microsoft lifecam\lifecam.exe |
"{AECBDC4B-A996-47F0-9531-8EA84BE3C967}" = protocol=6 | dir=in | app=c:\program files\itunes\itunes.exe |
"{B7A3FC53-5CCD-4CF7-8431-D34190740338}" = protocol=6 | dir=in | app=c:\program files\microsoft lifecam\lifeexp.exe |
"{C844BE18-3D23-4E5B-A95F-761E6A9053F7}" = dir=in | app=c:\program files\skype\phone\skype.exe |
"{CBE02381-2BAB-480C-BC91-0C35B4FE74E0}" = protocol=6 | dir=out | svc=upnphost | app=%systemroot%\system32\svchost.exe |
"{D264CD38-A1F8-4072-A976-611BDAA99932}" = protocol=58 | dir=out | name=@firewallapi.dll,-28546 |
"{D9E56566-84DE-4714-BE50-548FC6540551}" = protocol=17 | dir=in | app=c:\program files\itunes\itunes.exe |
"{DC481A02-E0CC-4EFF-99A2-8A727C8E8185}" = protocol=6 | dir=in | app=c:\program files\bonjour\mdnsresponder.exe |
"{E6907524-D9BC-489D-8125-86DE3FA0ED28}" = protocol=6 | dir=in | app=c:\program files\utorrent\utorrent.exe |
"{E70CA18D-BFDA-477A-9131-18A17CE7C0D4}" = protocol=6 | dir=in | app=c:\program files\bonjour\mdnsresponder.exe |
"{EFF176DF-A0D4-4B0B-8CE7-D5990C5F656B}" = protocol=1 | dir=in | name=@firewallapi.dll,-28543 |
"{FB617100-B00B-4C34-920A-5B5547D8749B}" = protocol=1 | dir=out | name=@firewallapi.dll,-28544 |
"{FF426218-0F5F-4A1B-B3E2-757BD280C9D5}" = protocol=58 | dir=in | name=@firewallapi.dll,-28545 |
"TCP Query User{2A96E09E-EF11-431D-BFE7-AA8F2A99E2AF}C:\program files\internet explorer\iexplore.exe" = protocol=6 | dir=in | app=c:\program files\internet explorer\iexplore.exe |
"TCP Query User{62D5E991-9D11-457D-A932-04C3AB7CF169}C:\program files\utorrent\utorrent.exe" = protocol=6 | dir=in | app=c:\program files\utorrent\utorrent.exe |
"TCP Query User{757137EE-14BE-4CF2-BFDB-807B07CE73BE}C:\program files\internet explorer\iexplore.exe" = protocol=6 | dir=in | app=c:\program files\internet explorer\iexplore.exe |
"TCP Query User{9CE451EF-A033-4266-81CF-1286DC4B0A0D}C:\users\david\appdata\local\google\chrome\application\chrome.exe" = protocol=6 | dir=in | app=c:\users\david\appdata\local\google\chrome\application\chrome.exe |
"TCP Query User{C938172B-96AB-4EF7-BC09-ADB101DFC115}C:\program files\pokeroffice\bin\javaw.exe" = protocol=6 | dir=in | app=c:\program files\pokeroffice\bin\javaw.exe |
"UDP Query User{6FC4F5DE-A310-492C-B4B3-5728A41EC10B}C:\program files\internet explorer\iexplore.exe" = protocol=17 | dir=in | app=c:\program files\internet explorer\iexplore.exe |
"UDP Query User{7E0992F8-790F-4123-B917-3AB4804DEA6A}C:\program files\utorrent\utorrent.exe" = protocol=17 | dir=in | app=c:\program files\utorrent\utorrent.exe |
"UDP Query User{B67E4C4B-6762-4456-B905-019242F4EB9D}C:\program files\internet explorer\iexplore.exe" = protocol=17 | dir=in | app=c:\program files\internet explorer\iexplore.exe |
"UDP Query User{B93C7B3E-CBBF-4E05-BB0A-4C32DAC7558A}C:\users\david\appdata\local\google\chrome\application\chrome.exe" = protocol=17 | dir=in | app=c:\users\david\appdata\local\google\chrome\application\chrome.exe |
"UDP Query User{D30F39B0-5C03-4EBE-AFA4-67CE69E1B01A}C:\program files\pokeroffice\bin\javaw.exe" = protocol=17 | dir=in | app=c:\program files\pokeroffice\bin\javaw.exe |

========== HKEY_LOCAL_MACHINE Uninstall List ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"{00203668-8170-44A0-BE44-B632FA4D780F}" = Adobe AIR
"{07287123-B8AC-41CE-8346-3D777245C35B}" = Bonjour
"{0761C9A8-8F3A-4216-B4A7-B7AFBF24A24A}" = HiJackThis
"{12E75B98-8463-4C1F-8DDA-F6CF31566A55}" = Google SketchUp Pro 6
"{1451DE6B-ABE1-4F62-BE9A-B363A17588A2}" = QuickTime
"{17E3A651-12B9-4149-BAE8-E6FB9A5ADC4F}" = Microsoft Works Suite Add-in for Microsoft Word
"{18455581-E099-4BA8-BC6B-F34B2F06600C}" = Google Toolbar for Internet Explorer
"{1E04F83B-2AB9-4301-9EF7-E86307F79C72}" = Google Earth
"{2318C2B1-4965-11d4-9B18-009027A5CD4F}" = Google Toolbar for Internet Explorer
"{24D753CA-6AE9-4E30-8F5F-EFC93E08BF3D}" = Skype™ 4.0
"{26A24AE4-039D-4CA4-87B4-2F83216015FF}" = Java(TM) 6 Update 18
"{2DFF31F9-7893-4922-AF66-C9A1EB4EBB31}" = Rhapsody Player Engine
"{30465B6C-B53F-49A1-9EBA-A3F187AD502E}" = Roxio Update Manager
"{3248F0A8-6813-11D6-A77B-00B0D0160000}" = Java(TM) SE Runtime Environment 6
"{35E1EC43-D4FC-4E4A-AAB3-20DDA27E8BB0}" = Sonic Activation Module
"{36CDA33B-909B-4719-97D1-C4B99309BDC7}" = ATI Parental Control & Encoder
"{3921A67A-5AB1-4E48-9444-C71814CF3027}" = VCRedistSetup
"{3AC54383-31D1-4907-961B-B12CBB1D0AE8}" = MobileMe Control Panel
"{3FA365DF-2D68-45ED-8F83-8C8A33E65143}" = Apple Application Support
"{42929F0F-CE14-47AF-9FC7-FF297A603021}" = Dell Resource CD
"{4A03706F-666A-4037-7777-5F2748764D10}" = Java Auto Updater
"{56C049BE-79E9-4502-BEA7-9754A3E60F9B}" = neroxml
"{63AFACBC-4795-4A1B-8037-5085DC03FC54}" = Microsoft LifeCam
"{6956856F-B6B3-4BE0-BA0B-8F495BE32033}" = Apple Software Update
"{6CF08AD2-00C5-4A63-B74B-2EFFFAFEBE1A}" = Microsoft Outlook Web Access S/MIME
"{6D52C408-B09A-4520-9B18-475B81D393F1}" = Microsoft Works
"{7299052b-02a4-4627-81f2-1818da5d550d}" = Microsoft Visual C++ 2005 Redistributable
"{76C24F39-B161-498F-BD8B-C64789812D13}_is1" = ConvertXtoDVD 3.1.3.40
"{77DCDCE3-2DED-62F3-8154-05E745472D07}" = Acrobat.com
"{7EFA5E6F-74F7-4AFB-8AEA-AA790BD3A76D}" = DellSupport
"{82B7209D-B838-4BC6-9390-4F1D06E12068}" = AVerMedia M779 Driver
"{89F4137D-6C26-4A84-BDB8-2E5A4BB71E00}" = Microsoft Silverlight
"{911B0409-6000-11D3-8CFE-0050048383C9}" = Microsoft Word 2002
"{98736A65-3C79-49EC-B7E9-A3C77774B0E6}" = Google SketchUp 6
"{AADEA55D-C834-4BCB-98A3-4B8D1C18F4EE}" = Apple Mobile Device Support
"{AC76BA86-7AD7-1033-7B44-A90000000001}" = Adobe Reader 9
"{B4092C6D-E886-4CB2-BA68-FE5A88D31DE6}_is1" = Spybot - Search & Destroy
"{C12D609B-EB71-411B-82C3-9BE6D40435D7}" = Google SketchUp LayOut 6
"{CA8B0FB9-69D0-4B50-8342-7CF0C96F10E6}" = Black's Digital Solution Studio
"{CB2F7EDD-9D1F-43C1-90FC-4F52EAE172A1}" = Microsoft .NET Framework 1.1
"{CE2CDD62-0124-36CA-84D3-9F4DCF5C5BD9}" = Microsoft .NET Framework 3.5 SP1
"{CF40ACC5-E1BB-4aff-AC72-04C2F616BCA7}" = getPlus(R) for Adobe
"{D4C9692E-4EFA-4DA0-8B7F-9439466D9E31}" = Full Tilt Poker
"{D52ECEBC-9B20-41A5-81C4-A62DE2367419}" = Adobe Creative Suite
"{DE1AF137-C455-494A-A817-EFE44BCCFDEE}" = Works Upgrade
"{E3BFEE55-39E2-4BE0-B966-89FE583822C1}" = Dell Support Center (Support Software)
"{EB459C2F-41CA-4222-B9CA-F8EBA40B8DAB}" = Google SketchUp 6 Exporters
"{EFAD4066-CAF3-4B27-9669-12EED352C376}" = NVIDIANetworkDiagnostic
"{F132AF7F-7BCA-4EDE-8A7C-958108FE7DBC}" = Realtek High Definition Audio Driver
"{F439D7AF-03F3-4F8E-AEC4-571BFE977C61}" = iTunes
"Adobe AIR" = Adobe AIR
"Adobe Flash Player ActiveX" = Adobe Flash Player 10 ActiveX
"Adobe Flash Player Plugin" = Adobe Flash Player 10 Plugin
"Adobe SVG Viewer" = Adobe SVG Viewer 3.0
"AMDAway INF" = AMDAway INF
"Autodesk DWF Viewer" = Autodesk DWF Viewer
"AVIcodec" = AVIcodec (remove only)
"CameraWindowDVC6" = Canon Camera Window DC_DV 6 for ZoomBrowser EX
"CameraWindowMC" = Canon Camera Window MC 6 for ZoomBrowser EX
"Canon G.726 WMP-Decoder" = Canon G.726 WMP-Decoder
"com.adobe.mauby.4875E02D9FB21EE389F73B8D1702B320485DF8CE.1" = Acrobat.com
"GoToAssist" = GoToAssist 8.0.0.480
"InstallShield_{82B7209D-B838-4BC6-9390-4F1D06E12068}" = AVerMedia M779 Driver
"InstallShield_{EFAD4066-CAF3-4B27-9669-12EED352C376}" = NVIDIANetworkDiagnostic
"Malwarebytes' Anti-Malware_is1" = Malwarebytes' Anti-Malware
"McAfee Security Scan" = McAfee Security Scan
"Microsoft .NET Framework 1.1 (1033)" = Microsoft .NET Framework 1.1
"Microsoft .NET Framework 3.5 SP1" = Microsoft .NET Framework 3.5 SP1
"MovieEditTask" = Canon MovieEdit Task for ZoomBrowser EX
"Mozilla Firefox (3.0.17)" = Mozilla Firefox (3.0.17)
"mp3-2-wav" = mp3-2-wav converter 1.14
"MSC" = McAfee SecurityCenter
"NVIDIA Drivers" = NVIDIA Drivers
"PartyPoker" = PartyPoker
"PhotoStitch" = Canon Utilities PhotoStitch
"PokerStars" = PokerStars
"RAW Image Task" = Canon RAW Image Task for ZoomBrowser EX
"RealPlayer 12.0" = RealPlayer
"RemoteCaptureTask" = Canon RemoteCapture Task for ZoomBrowser EX
"SystemRequirementsLab" = System Requirements Lab
"WinRAR archiver" = WinRAR archiver
"Works2006Setup" = Microsoft Works Suite 2006 Setup Launcher
"ZoomBrowser EX" = Canon Utilities ZoomBrowser EX

========== HKEY_USERS Uninstall List ==========

[HKEY_USERS\S-1-5-21-2209711222-1865678921-789788502-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"Google Chrome" = Google Chrome
"uTorrent" = µTorrent

========== Last 10 Event Log Errors ==========

Error reading Event Logs: The Event Service is not operating properly or the Event Logs are corrupt!

< End of report >
dcowie
Regular Member
 
Posts: 23
Joined: January 24th, 2010, 9:54 am

Re: Help needed with browser hijack

Unread postby dcowie » February 2nd, 2010, 9:15 am

J&J,

Lastly, sysprot log...broken into four sections because of message size limits.

SysProt AntiRootkit v1.0.1.0
by swatkat

******************************************************************************************
******************************************************************************************

No Hidden Processes found

******************************************************************************************
******************************************************************************************
Kernel Modules:
Module Name: \SystemRoot\System32\Drivers\dump_diskdump.sys
Service Name: ---
Module Base: 8D26A000
Module End: 8D274000
Hidden: Yes

Module Name: \SystemRoot\System32\Drivers\dump_nvstor.sys
Service Name: ---
Module Base: 8D274000
Module End: 8D281000
Hidden: Yes

******************************************************************************************
******************************************************************************************
No SSDT Hooks found

******************************************************************************************
******************************************************************************************
Kernel Hooks:
Hooked Function: ZwCreateUserProcess
At Address: 825D8B82
Jump To: 8D224766
Module Name: C:\Windows\system32\drivers\mfehidk.sys

Hooked Function: ZwYieldExecution
At Address: 8243A982
Jump To: 8D2247CC
Module Name: C:\Windows\system32\drivers\mfehidk.sys

Hooked Function: ZwUnmapViewOfSection
At Address: 8261F709
Jump To: 8D2247F6
Module Name: C:\Windows\system32\drivers\mfehidk.sys

Hooked Function: ZwTerminateProcess
At Address: 825FFD5D
Jump To: 8D22480F
Module Name: C:\Windows\system32\drivers\mfehidk.sys

Hooked Function: ZwSetInformationProcess
At Address: 82623474
Jump To: 8D22477A
Module Name: C:\Windows\system32\drivers\mfehidk.sys

Hooked Function: ZwSetContextThread
At Address: 826A1253
Jump To: 8D22478E
Module Name: C:\Windows\system32\drivers\mfehidk.sys

Hooked Function: ZwRestoreKey
At Address: 826617B2
Jump To: 8D224837
Module Name: C:\Windows\system32\drivers\mfehidk.sys

Hooked Function: ZwReplaceKey
At Address: 826629B6
Jump To: 8D22484B
Module Name: C:\Windows\system32\drivers\mfehidk.sys

Hooked Function: ZwProtectVirtualMemory
At Address: 82628E7D
Jump To: 8D2247B6
Module Name: C:\Windows\system32\drivers\mfehidk.sys

Hooked Function: ZwOpenThread
At Address: 8262B09A
Jump To: 8D224728
Module Name: C:\Windows\system32\drivers\mfehidk.sys

Hooked Function: ZwOpenProcess
At Address: 8262FB48
Jump To: 8D224714
Module Name: C:\Windows\system32\drivers\mfehidk.sys

Hooked Function: ZwNotifyChangeKey
At Address: 825CE5B5
Jump To: 8D224823
Module Name: C:\Windows\system32\drivers\mfehidk.sys

Hooked Function: ZwMapViewOfSection
At Address: 8261F446
Jump To: 8D2247E0
Module Name: C:\Windows\system32\drivers\mfehidk.sys

Hooked Function: ZwCreateProcessEx
At Address: 826A0796
Jump To: 8D224750
Module Name: C:\Windows\system32\drivers\mfehidk.sys

Hooked Function: ZwCreateProcess
At Address: 826A074B
Jump To: 8D22473C
Module Name: C:\Windows\system32\drivers\mfehidk.sys

Hooked Function: ZwCreateFile
At Address: 82650D59
Jump To: 8D2247A2
Module Name: C:\Windows\system32\drivers\mfehidk.sys

Hooked Function: PsSetContextThread
At Address: 826A1253
Jump To: 8D22478E
Module Name: C:\Windows\system32\drivers\mfehidk.sys

******************************************************************************************
******************************************************************************************
No IRP Hooks found

******************************************************************************************
******************************************************************************************
Ports:
Local Address: HARRY.LAN:NETBIOS-SSN
Remote Address: 0.0.0.0:0
Type: TCP
Process: System
State: LISTENING

Local Address: HARRY:49268
Remote Address: LOCALHOST:49266
Type: TCP
Process: C:\Program Files\Mozilla Firefox\firefox.exe
State: ESTABLISHED

Local Address: HARRY:49266
Remote Address: LOCALHOST:49268
Type: TCP
Process: C:\Program Files\Mozilla Firefox\firefox.exe
State: ESTABLISHED

Local Address: HARRY:49265
Remote Address: LOCALHOST:49264
Type: TCP
Process: C:\Program Files\Mozilla Firefox\firefox.exe
State: ESTABLISHED

Local Address: HARRY:49264
Remote Address: LOCALHOST:49265
Type: TCP
Process: C:\Program Files\Mozilla Firefox\firefox.exe
State: ESTABLISHED

Local Address: HARRY:49156
Remote Address: LOCALHOST:27015
Type: TCP
Process: C:\Program Files\iTunes\iTunesHelper.exe
State: ESTABLISHED

Local Address: HARRY:27015
Remote Address: LOCALHOST:49156
Type: TCP
Process: C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
State: ESTABLISHED

Local Address: HARRY:27015
Remote Address: 0.0.0.0:0
Type: TCP
Process: C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
State: LISTENING

Local Address: HARRY:5354
Remote Address: 0.0.0.0:0
Type: TCP
Process: C:\Program Files\Bonjour\mDNSResponder.exe
State: LISTENING

Local Address: HARRY:49291
Remote Address: SPYNETTEST.MICROSOFT.COM:HTTPS
Type: TCP
Process: C:\Program Files\Windows Defender\MSASCui.exe
State: ESTABLISHED

Local Address: HARRY:49290
Remote Address: LGA15S04-IN-F100.1E100.NET:HTTP
Type: TCP
Process: C:\Program Files\Mozilla Firefox\firefox.exe
State: ESTABLISHED

Local Address: HARRY:49287
Remote Address: VW-IN-F121.1E100.NET:HTTP
Type: TCP
Process: C:\Program Files\Mozilla Firefox\firefox.exe
State: CLOSE_WAIT

Local Address: HARRY:49286
Remote Address: ANY-IN-2415.1E100.NET:HTTP
Type: TCP
Process: C:\Program Files\Mozilla Firefox\firefox.exe
State: CLOSE_WAIT

Local Address: HARRY:49282
Remote Address: LGA15S04-IN-F137.1E100.NET:HTTP
Type: TCP
Process: C:\Program Files\Mozilla Firefox\firefox.exe
State: ESTABLISHED

Local Address: HARRY:49281
Remote Address: LGA15S01-IN-F100.1E100.NET:HTTP
Type: TCP
Process: C:\Program Files\Mozilla Firefox\firefox.exe
State: ESTABLISHED

Local Address: HARRY:49280
Remote Address: NUQ04S01-IN-F113.1E100.NET:HTTP
Type: TCP
Process: C:\Program Files\Mozilla Firefox\firefox.exe
State: ESTABLISHED

Local Address: HARRY:49279
Remote Address: STATIC.78-47-248-115.CLIENTS.YOUR-SERVER.DE:HTTP
Type: TCP
Process: C:\Program Files\Mozilla Firefox\firefox.exe
State: CLOSE_WAIT

Local Address: HARRY:49278
Remote Address: LGA15S04-IN-F104.1E100.NET:HTTP
Type: TCP
Process: C:\Program Files\Mozilla Firefox\firefox.exe
State: ESTABLISHED

Local Address: HARRY:49277
Remote Address: LGA15S04-IN-F104.1E100.NET:HTTP
Type: TCP
Process: C:\Program Files\Mozilla Firefox\firefox.exe
State: ESTABLISHED

Local Address: HARRY:49275
Remote Address: LGA15S04-IN-F100.1E100.NET:HTTP
Type: TCP
Process: C:\Program Files\Mozilla Firefox\firefox.exe
State: ESTABLISHED

Local Address: HARRY:49274
Remote Address: LGA15S04-IN-F100.1E100.NET:HTTP
Type: TCP
Process: C:\Program Files\Mozilla Firefox\firefox.exe
State: ESTABLISHED

Local Address: HARRY:49269
Remote Address: LGA15S04-IN-F100.1E100.NET:HTTP
Type: TCP
Process: C:\Program Files\Mozilla Firefox\firefox.exe
State: ESTABLISHED

Local Address: HARRY:49267
Remote Address: LGA15S04-IN-F104.1E100.NET:HTTP
Type: TCP
Process: C:\Program Files\Mozilla Firefox\firefox.exe
State: ESTABLISHED

Local Address: HARRY:49158
Remote Address: 0.0.0.0:0
Type: TCP
Process: C:\Windows\System32\services.exe
State: LISTENING

Local Address: HARRY:49157
Remote Address: 0.0.0.0:0
Type: TCP
Process: C:\Windows\System32\svchost.exe
State: LISTENING

Local Address: HARRY:49155
Remote Address: 0.0.0.0:0
Type: TCP
Process: C:\Windows\System32\svchost.exe
State: LISTENING

Local Address: HARRY:49154
Remote Address: 0.0.0.0:0
Type: TCP
Process: C:\Windows\System32\lsass.exe
State: LISTENING

Local Address: HARRY:49153
Remote Address: 0.0.0.0:0
Type: TCP
Process: C:\Windows\System32\svchost.exe
State: LISTENING

Local Address: HARRY:49152
Remote Address: 0.0.0.0:0
Type: TCP
Process: C:\Windows\System32\wininit.exe
State: LISTENING

Local Address: HARRY:6646
Remote Address: 0.0.0.0:0
Type: TCP
Process: C:\Program Files\Common Files\McAfee\MNA\McNASvc.exe
State: LISTENING

Local Address: HARRY:5357
Remote Address: 0.0.0.0:0
Type: TCP
Process: System
State: LISTENING

Local Address: HARRY:MICROSOFT-DS
Remote Address: 0.0.0.0:0
Type: TCP
Process: System
State: LISTENING

Local Address: HARRY:EPMAP
Remote Address: 0.0.0.0:0
Type: TCP
Process: C:\Windows\System32\svchost.exe
State: LISTENING

Local Address: HARRY.LAN:62487
Remote Address: NA
Type: UDP
Process: C:\Windows\System32\svchost.exe
State: NA

Local Address: HARRY.LAN:6646
Remote Address: NA
Type: UDP
Process: C:\Program Files\Common Files\McAfee\MNA\McNASvc.exe
State: NA

Local Address: HARRY.LAN:5353
Remote Address: NA
Type: UDP
Process: C:\Program Files\Bonjour\mDNSResponder.exe
State: NA

Local Address: HARRY.LAN:SSDP
Remote Address: NA
Type: UDP
Process: C:\Windows\System32\svchost.exe
State: NA

Local Address: HARRY.LAN:138
Remote Address: NA
Type: UDP
Process: System
State: NA

Local Address: HARRY.LAN:NETBIOS-NS
Remote Address: NA
Type: UDP
Process: System
State: NA

Local Address: HARRY:62585
Remote Address: NA
Type: UDP
Process: C:\Windows\System32\svchost.exe
State: NA

Local Address: HARRY:62488
Remote Address: NA
Type: UDP
Process: C:\Windows\System32\svchost.exe
State: NA

Local Address: HARRY:53304
Remote Address: NA
Type: UDP
Process: C:\Windows\System32\svchost.exe
State: NA

Local Address: HARRY:SSDP
Remote Address: NA
Type: UDP
Process: C:\Windows\System32\svchost.exe
State: NA

Local Address: HARRY:62486
Remote Address: NA
Type: UDP
Process: C:\Windows\System32\svchost.exe
State: NA

Local Address: HARRY:SSDP
Remote Address: NA
Type: UDP
Process: C:\Windows\System32\svchost.exe
State: NA

Local Address: HARRY:59090
Remote Address: NA
Type: UDP
Process: C:\Windows\System32\svchost.exe
State: NA

Local Address: HARRY:59088
Remote Address: NA
Type: UDP
Process: C:\Program Files\Bonjour\mDNSResponder.exe
State: NA

Local Address: HARRY:50067
Remote Address: NA
Type: UDP
Process: C:\Program Files\Bonjour\mDNSResponder.exe
State: NA

Local Address: HARRY:LLMNR
Remote Address: NA
Type: UDP
Process: C:\Windows\System32\svchost.exe
State: NA

Local Address: HARRY:IPSEC-MSFT
Remote Address: NA
Type: UDP
Process: C:\Windows\System32\svchost.exe
State: NA

Local Address: HARRY:UPNP-DISCOVERY
Remote Address: NA
Type: UDP
Process: C:\Windows\System32\svchost.exe
State: NA

Local Address: HARRY:UPNP-DISCOVERY
Remote Address: NA
Type: UDP
Process: C:\Windows\System32\svchost.exe
State: NA

Local Address: HARRY:500
Remote Address: NA
Type: UDP
Process: C:\Windows\System32\svchost.exe
State: NA

Local Address: HARRY:123
Remote Address: NA
Type: UDP
Process: C:\Windows\System32\svchost.exe
State: NA

******************************************************************************************
******************************************************************************************
Hidden files/folders:
Object: C:\System Volume Information\MountPointManagerRemoteDatabase
Status: Access denied

Object: C:\System Volume Information\SPP
Status: Access denied

Object: C:\System Volume Information\SystemRestore
Status: Access denied

Object: C:\System Volume Information\tracking.log
Status: Access denied

Object: C:\System Volume Information\{1ac61f97-04fe-11df-bb6a-ef118efdcf7e}{3808876b-c176-4e48-b7ae-04046e6cc752}
Status: Access denied

Object: C:\System Volume Information\{3808876b-c176-4e48-b7ae-04046e6cc752}
Status: Access denied

Object: C:\System Volume Information\{395a2126-068c-11df-ae64-99cf058a215a}{3808876b-c176-4e48-b7ae-04046e6cc752}
Status: Access denied

Object: C:\System Volume Information\{75c34998-05c6-11df-8ad7-b1acfc84830b}{3808876b-c176-4e48-b7ae-04046e6cc752}
Status: Access denied

Object: C:\System Volume Information\{dbe7d218-0768-11df-aedb-ad6f0327882f}{3808876b-c176-4e48-b7ae-04046e6cc752}
Status: Access denied

Object: C:\Windows\System32\LogFiles\WMI\RtBackup\EtwRTDiagLog.etl
Status: Access denied

Object: C:\Windows\System32\LogFiles\WMI\RtBackup\EtwRTEventLog-Application.etl
Status: Access denied

Object: C:\Windows\System32\LogFiles\WMI\RtBackup\EtwRTEventlog-Security.etl
Status: Access denied

Object: C:\Windows\System32\LogFiles\WMI\RtBackup\EtwRTEventLog-System.etl
Status: Access denied

Object: C:\Windows\System32\LogFiles\WMI\RtBackup\EtwRTMsMpPsSession.etl
Status: Access denied

Object: C:\Windows.old\Documents and Settings\David\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\18VBDUF7\OCAZ13XD2CANA04A1CALCKUAPCA63HLC3CA4MEMWTCA7WZP2MCACJ7387CA5NXFEFCABCTESJCA85NDTTCACRXGDUCALG30K8CAPHQFY2CAUZF79ICAQ6N3DDCAI2SKG9
Status: Hidden

Object: C:\Windows.old\Documents and Settings\David\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\2FGHYXL1\1CAHOEKBJCAKE2ONYCAOGNMZGCAXM41SPCA8I18VDCAH8L3BOCAG3XEYECAT9UVIDCA8UNYXVCAAD3PMTCAGSI99FCAZF1V3JCAPMM1SFCAFB7E6GCA4P6AE4CAL5CUI3
Status: Hidden

Object: C:\Windows.old\Documents and Settings\David\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\2FGHYXL1\2CAGCXM08CAYEVJPICA1RQ1OCCAULNIEHCA85BS9ICA6M9MCXCAW3S5NBCAAKYEW6CAVHSFBPCAAE5AZICAQWI1OJCA95CYD1CAEW52IGCADQYHA8CABKU3M9CAEPH1ZS
Status: Hidden

Object: C:\Windows.old\Documents and Settings\David\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\2FGHYXL1\2CAONXLG1CAU6HUI2CAI5B3E3CA1ED79CCATEK1WQCAIAUSCUCAWSRFD2CACKSBK1CA730G81CAGXY55TCAW9O5VTCAOYFIT3CA13ME3MCA8V2O69CA58K6GHCAYSL74X
Status: Hidden

Object: C:\Windows.old\Documents and Settings\David\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\2FGHYXL1\2CAZ1GWWFCA2D5EIZCATWZ78ZCAQ3FHGMCA0FN7VCCAEIUC0DCACI0MUNCA0GA63UCAC7L85ZCARNZVN7CAUIALUCCAG0KZEJCA6BF17LCAIF00UPCA3X81UQCAMVLZBV
Status: Hidden

Object: C:\Windows.old\Documents and Settings\David\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\2FGHYXL1\2LCAEJU6DVCAOVSA5WCA0ZW88SCAY9VSJJCAUSV86VCAZV4JGRCAJW098ZCABP7DWECA86T9M7CA0ZOUKLCA29MMIVCA38RMO4CA9EFTXECAVKSXTCCAH8SZ0SCAGU7X5
Status: Hidden

Object: C:\Windows.old\Documents and Settings\David\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\2FGHYXL1\4CA0MKUEBCALNQCOTCAKKYJUPCAYYFU0UCAKYRQVKCA6L3D0ACAZ7DPGNCANKTDKJCARNFKNNCAUJPENNCANYJEPCCASRE1C8CA8JNPYZCAJKJ27PCAD302JECAKN3DD2
Status: Hidden

Object: C:\Windows.old\Documents and Settings\David\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\2FGHYXL1\4CAB6ENCMCAA4ACLICABITQSPCA252KNCCASI2VGXCA69N5BQCAUCO84ECAE1TXMUCAYZMNSXCAKT4N3GCAI9JY51CA1UH1PKCA5SEQ84CAXGQ259CA4R48K8CAS4K6M2
Status: Hidden

Object: C:\Windows.old\Documents and Settings\David\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\2FGHYXL1\4CAZRPL5MCAHU8KJ5CA4NWGO1CAXELHKMCAXRARCHCA1NL8QMCAT8GGGNCAPZAEIICA8CB2YSCAI5SC1TCATPDORSCAYAE2U4CAJEWUK1CAZHBEP0CAGCGWLRCAP91RDJ
Status: Hidden

Object: C:\Windows.old\Documents and Settings\David\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\2FGHYXL1\5CAJ9WF4UCAB3HW14CAINQOMMCAUDIE2GCAU6472ACAWL0SH0CA5IEQJ6CADRWFGYCAYGN8QJCAR2369SCAY69Z2JCAYGLXR9CANG7SAJCACBR3SUCAJUE68WCARU42VO
Status: Hidden

Object: C:\Windows.old\Documents and Settings\David\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\2FGHYXL1\8CAT75ROXCA996Y45CAT515RLCAXINGKJCA5RNPBKCA6RJCIOCA4BKJVCCAFW7FULCAEVGHEJCA69DX9WCABL46WNCAI2TL66CA2MMCNOCAQCL22CCADC94V0CA0ZIY28
Status: Hidden

Object: C:\Windows.old\Documents and Settings\David\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\2FGHYXL1\9CAB9C8PTCAS6H8YBCABKN4NHCAALK5KECA17FP89CA5378EYCABP0BJPCAFSJQQTCAQW25MZCAZF4W2HCAFDS237CANZSLQ4CASH6YRQCAA4URXFCA03FJFVCA420B8Z
Status: Hidden

Object: C:\Windows.old\Documents and Settings\David\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\2FGHYXL1\ag.epiblog;abr=!webtv;kw=bottom;kw=articlesguides;kw=blogs;kw=editor;kw=2009;kw=04;kw=five-foods-that[1].html;sz=300x250;tile=4;o
Status: Hidden

Object: C:\Windows.old\Documents and Settings\David\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\2FGHYXL1\BCAAYHBSCCAS4KC8TCA1170PKCAY6ONACCAOFYHTBCA43KJ8HCA7CLG8ECA831ANICAEXGDMPCA7L6SB8CATAK342CAX4G9HUCAHJI0XKCAQ7QSB8CATLDNM9CAA1E92E
Status: Hidden

Object: C:\Windows.old\Documents and Settings\David\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\2FGHYXL1\BCAEZ6LYNCA58FD32CASYQU86CAB7L32JCA0OZO9WCAM2VK4ACAJ0Q7DPCA6WTVHTCA8B8FIWCAKT6LH6CAZ79HAJCAW3JMD7CAKPL4LSCA4P4WXMCA6OP2I0CA1J123Z
Status: Hidden

Object: C:\Windows.old\Documents and Settings\David\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\2FGHYXL1\CCA8J6AEQCAURGTA7CATTDEWXCAMUAPKNCAZRUH0DCA9UB11HCAJEE9H8CAPB194NCARVFF7UCABQ34HUCA7OOEMKCATG3OX1CA0ZAPQMCAQ2CHFUCA9WDO34CAGVWBW0
Status: Hidden

Object: C:\Windows.old\Documents and Settings\David\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\2FGHYXL1\DCAKAPIKICA9ZKA7ICA6CLAVECAB682XICAEC5JCECAQKIPCQCAHS1K7YCAUHKGH4CAR6UXY4CAMHFT71CA5MF1WRCAEUL6MWCALSF98ECAOFJ884CASB2MZ1CACC4174
Status: Hidden

Object: C:\Windows.old\Documents and Settings\David\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\2FGHYXL1\GCARL9CC3CA0L5MFHCABUG9BYCA0QJ2RQCANPQH6JCA5PGCKNCAAEQQ4ZCA1Z8APMCAGBT5UZCAYYGR3TCA3BPUGNCAT3YT89CAKFLMWSCAT1OC76CAY7ZOLUCANHNR6W
Status: Hidden

Object: C:\Windows.old\Documents and Settings\David\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\2FGHYXL1\ICAMTL7RHCAW79EFQCAXDTB9ICASEQSTMCAIUMX54CAXW33LCCASNSUT7CA2YER9LCAKXOLFFCAJ3FROOCAPYNA76CA932MHSCAX9CE2VCAWF0B6ICA8DXIBZCADANLLV
Status: Hidden

Object: C:\Windows.old\Documents and Settings\David\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\2FGHYXL1\ion;kw=Casual+Entertaining;kw=Entertaining;kw=ba;ad=null;kw=recipes;kw=food;kw=views;kw=Golden-Pan-Fried-Fish-350404;sz=300x250;t
Status: Hidden

Object: C:\Windows.old\Documents and Settings\David\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\2FGHYXL1\JCAWKDMF8CAVLU2W7CA4F9QLRCAT54UYVCAAJVV7RCAJZP5QNCA1E24M0CALB0WGNCABZJNIQCA5CSX85CA1TAEFRCALPQNNUCAF4QRBDCA4OHAV8CAXMQ0TWCA1DEKRE
Status: Hidden

Object: C:\Windows.old\Documents and Settings\David\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\2FGHYXL1\KCA4FYBAJCA5UP3QECACH4L3JCARJVG1CCATRUDN2CAOF4TKCCAE65QZ1CAN86A3FCAUDHE8CCAFT9IGOCAEQLVALCAJK33KYCA2JUEEMCAYNL4B2CAJUEOIUCALKC9FI
Status: Hidden

Object: C:\Windows.old\Documents and Settings\David\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\2FGHYXL1\KVCA1L7XX9CAH8WG5CCAOXBMIECAORF1X7CA2VJA88CA6X2YE7CATCDGT0CA9Q951ACABL2WRYCA4R1Q0NCAGWAO0CCAMERFY5CAX2OM06CAHXZ0OKCA86GV91CAG6URG
Status: Hidden

Object: C:\Windows.old\Documents and Settings\David\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\2FGHYXL1\n;kw=Casual+Entertaining;kw=Entertaining;kw=ba;ad=null;kw=recipes;kw=food;kw=reviews;kw=Golden-Pan-Fried-Fish-350404;sz=300x250;t
Status: Hidden

Object: C:\Windows.old\Documents and Settings\David\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\2FGHYXL1\nion;kw=Casual+Entertaining;kw=Entertaining;kw=ba;ad=null;kw=recipes;kw=food;kw=views;kw=Golden-Pan-Fried-Fish-350404;sz=300x250;
Status: Hidden

Object: C:\Windows.old\Documents and Settings\David\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\2FGHYXL1\OCAOJBG13CA3GWA9QCAQXUSJWCA8OWVH9CA07UUGTCAQ0IKYBCAOI5MV3CAV5DI2KCA2X5FD7CAM1HFRYCAIKZGGFCAF92KHTCAGTMUIMCAYJ2QKECAQ0VZMJCABYI02B
Status: Hidden

Object: C:\Windows.old\Documents and Settings\David\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\2FGHYXL1\RCAYB4IK8CAFXUF5XCATJ0E9TCAPGE56OCAAMEYJICAAAPXIICAU4ZY7NCA189A0ECAMXBOOQCAURUYWLCAVJO2VECAXF4B6YCAT6ZSVPCANIY80CCA8U9M63CANGAAQJ
Status: Hidden

Object: C:\Windows.old\Documents and Settings\David\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\2FGHYXL1\TCA3E0CB3CA1T4MTPCA5LQYY3CAZA82AYCAL81140CAGHO5VQCAA5TUUOCALA6KXLCAT5PJ0HCASR432BCA2ZMFJUCAX4YUCVCA04SF5MCAC2FR3JCA9HYJ0LCAEDUVQF
Status: Hidden

Object: C:\Windows.old\Documents and Settings\David\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\2FGHYXL1\TWCA1U9G3UCAI14932CA2RZXAACA1PZEF8CA37CM45CACI1MQYCABNQ2OVCALHYH05CAKY9EN4CA8043N1CAO77QG4CAS20PZPCA2U2ZS2CAUPC6C4CA50PU53CA4H04E
Status: Hidden

Object: C:\Windows.old\Documents and Settings\David\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\2FGHYXL1\union;kw=Casual+Entertaining;kw=Entertaining;kw=ba;ad=null;kw=recipes;kw=food;kw=views;kw=Golden-Pan-Fried-Fish-350404;sz=120x60;
Status: Hidden

Object: C:\Windows.old\Documents and Settings\David\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\2FGHYXL1\UYCALSQZVUCA32SBR5CAVKEPYWCA1I4NOBCA33X8V1CAG6X6ZMCA329YJTCAGB7FUHCAS1EE6YCA3OS2I3CACYBD4ECA2CSMKECAU1TOV9CACS5RJVCAW548U5CAYKDMF
Status: Hidden

Object: C:\Windows.old\Documents and Settings\David\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\2FGHYXL1\VCADNOPF9CAL5TS23CAB772IGCACWQLWRCAE8HTR3CAMTJALHCAWRX03XCA8SP1Y9CA03IUMACAQF66MBCA87NWV1CAIE37FMCA75J9QCCAQC730JCARZIUYVCA6S6LKY
Status: Hidden

Object: C:\Windows.old\Documents and Settings\David\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\2FGHYXL1\WCA4BLYUJCA13E70ACA9Z71IGCA393YI7CA7WWR4LCAB96CQ6CAHPXZDVCA78RJB3CARBMCROCA5U3MPPCA49GX83CAEQ3UFKCAF8QT4WCARASW3MCALQB6J9CAO09S21
Status: Hidden

Object: C:\Windows.old\Documents and Settings\David\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\2FGHYXL1\WCACK2MR3CANWF49NCAB8Y7WECA11YH7NCADIE85YCAM3UWSNCAS3EF5TCAOFDHOLCAE59K8SCAEN7D8YCA5U8PLACA7GHDYVCA5YZ6ZUCA5BGUKNCAH6OC1BCAJI0SG1
Status: Hidden

Object: C:\Windows.old\Documents and Settings\David\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\2FGHYXL1\YCAKKM5HOCASZK6CSCAHFLUH9CAYIHI1MCASZAGU0CADL8FDUCA8L32YWCARQTULHCAV1M0PNCAUNXUFZCAQFZ2Y7CAX39E64CADXGLUBCAE0WLTOCAH8UF0ACA52G18Q
Status: Hidden

Object: C:\Windows.old\Documents and Settings\David\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\2FGHYXL1\YCAOWFFUWCAHAAETTCAQOVIEFCADEXS4YCAM6CGL1CAYV16ZWCAE0DK64CA1W17RJCA8234C4CA0SJ32NCAK8P88TCADMOFF7CAAA9V6PCAWGKR71CARB94Z4CAKNW22J
Status: Hidden

Object: C:\Windows.old\Documents and Settings\David\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\2FGHYXL1\ZCATKFGQFCAYFVMJDCAM8ESTTCAVC1QV2CAWGR0JRCA3VMTKDCA7L2ID1CA9E6R3KCA6INB6UCA6GXMN0CAYP1714CAFU63L5CAJMSSPBCA4AE0F9CAWSQFC9CA1LOCOQ
Status: Hidden

Object: C:\Windows.old\Documents and Settings\David\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\5GXUDIYO\0CALBQJ5SCA38S9YACA9VXE8YCAMZW9R7CAQKAVAECAQA5RZICAW1PMN8CAGFIYEBCA73EO07CA6PSHJ7CA7U971TCA2AM06PCAZNC5GDCA06CF1QCAA2EGDOCA7H9K3N
Status: Hidden

Object: C:\Windows.old\Documents and Settings\David\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\5GXUDIYO\4CAR31WQDCAHM5W4CCAAYR3FKCAZ0ZD1JCASHJ0DVCAYHA2LHCA51V290CA1TSTF4CAAAK1BNCAXQ6RXZCAY84P2ICAUPXM04CAIYI5LPCAOTU3R5CA9JK7M0CASUGTL3
Status: Hidden

Object: C:\Windows.old\Documents and Settings\David\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\5GXUDIYO\5CA3Z0N5MCAC543QJCAYMWU62CAFN68ACCAHPB999CAXXE851CAVLMDYECAU5M0ATCA5J7K9UCAGH99ZXCAB4XR51CAAJFNRZCA0YYMV8CAS9RRKBCA65GCL6CAB65RR2
Status: Hidden

Object: C:\Windows.old\Documents and Settings\David\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\5GXUDIYO\7KCA7138X0CAUUA6K0CAJAPX2BCAVUSABRCA9V1VU5CABSJQSPCAPO0MILCANF6MFACAWH8KYHCA3V7XCVCABRDF4WCASK7B8ACA6O762GCA45WA80CAEIXURLCAYFHST
Status: Hidden

Object: C:\Windows.old\Documents and Settings\David\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\5GXUDIYO\8CAN29LNOCA7W1WE1CAMVMAJKCAYPH926CAXYEMS7CAYV3YY7CAC4VI8ZCACZQX0XCARD2U3XCAKFEYJ4CAILFYZOCAGOQCNYCAML4TUFCANOH06MCAENF19KCA7DAFYF
Status: Hidden

Object: C:\Windows.old\Documents and Settings\David\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\5GXUDIYO\9XCADHDI4PCA72EZKLCAD5FSNKCAENE6KVCAI3N67XCAF9QMEWCASKOR8WCAMDSLO2CAKB8XGKCAFQYKKWCA6TPM11CAFPO8LECA7NR7TSCA6TDNJMCA4Y9P7UCA8JTJN
Status: Hidden

Object: C:\Windows.old\Documents and Settings\David\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\5GXUDIYO\ACAM87K7HCA2X8DW1CAVXD40RCABS5AWUCAE43TEZCAOLPK3OCAPG96W5CA7NFME8CAV9D1G4CAN1XMV9CAVS3CW6CAPSXBQ6CAN9U6KGCAUMZ4U7CAVCB5M8CAKD4F2R
Status: Hidden

Object: C:\Windows.old\Documents and Settings\David\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\5GXUDIYO\ACAMW8XO4CA9H0GT8CAKM8T23CA56D4EKCA20JN5TCAKDDSESCA69GUX6CA5Z8TEWCAEZ8SAECA006XE5CAL3X43FCAES8BDGCAR75RCVCAMOWOROCA7OST17CATNONH5
Status: Hidden

Object: C:\Windows.old\Documents and Settings\David\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\5GXUDIYO\CCANKRY9RCA0OXENHCA3PQONOCAE03DOJCAKI31JGCARL9I56CAO2Q033CA4SURPRCA2HT0JNCAJS5BCRCATNJNSPCAPEN39ECAR3M3W8CA0CD9Y7CAGVY17DCAFK3UQB
Status: Hidden

Object: C:\Windows.old\Documents and Settings\David\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\5GXUDIYO\DCXP4PCAGXHMFKCAI7N636CA2I8E3XCA4WM21TCAXG3E8YCAX0RH5QCAZTBRTKCAJT7JSTCAMBZC55CAW59JSUCA9V5YGGCA6TZERHCAWD1BE9CAOP8S6LCASPP3YJCAF
Status: Hidden

Object: C:\Windows.old\Documents and Settings\David\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\5GXUDIYO\HCAQZN711CALZZ84LCA76EGU9CAKVCO3DCAF45S34CACCYN63CA73FBOVCADVUXQ5CAYUTJIJCAUUIMD8CA35ENLYCALGLMNQCA9CH8IVCAEA9RXICAXBNA2TCAY1EJ8N
Status: Hidden

Object: C:\Windows.old\Documents and Settings\David\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\5GXUDIYO\ion;kw=Casual+Entertaining;kw=Entertaining;kw=ba;ad=null;kw=recipes;kw=food;kw=reviews;kw=Golden-Pan-Fried-Fish-350404;sz=120x60;
Status: Hidden

Object: C:\Windows.old\Documents and Settings\David\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\5GXUDIYO\LCAXP0AA8CAC8E3LDCAMGCXKBCAI3R1IDCAS2SUBICAN0VRVPCAZSD6P6CAIJ8QOCCAILLB28CA61L4U8CADWWI2FCAJK7Q22CAXDN7UYCAGT0WDTCACXIPD7CAYU1FL1
Status: Hidden

Object: C:\Windows.old\Documents and Settings\David\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\5GXUDIYO\NCALXG9ERCA7JJN70CAALCXNVCA8TSYG1CAC6QT5PCAQBXRAECA6TDFFACAQ0MIX3CAPMBXB0CAFKVAJ9CA9Y6CMDCAO7MW3ZCAXC3TJ6CAKEARZ2CAG3YXPLCAU00IPT
Status: Hidden

Object: C:\Windows.old\Documents and Settings\David\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\5GXUDIYO\nion;kw=Casual+Entertaining;kw=Entertaining;kw=ba;ad=null;kw=recipes;kw=food;kw=views;kw=Golden-Pan-Fried-Fish-350404;sz=300x250;
Status: Hidden

Object: C:\Windows.old\Documents and Settings\David\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\5GXUDIYO\OCAHBMXJ3CAGQ2G7WCAVKHGQ4CA7H0MI5CA2M7IZ7CAZISEMICA3PF14NCAAYSUR1CAJBOHYPCASXT348CAIV4ABMCAPLVA33CA7HLIZXCAS77LE6CAJ1RT38CAI8P2HO
Status: Hidden

Object: C:\Windows.old\Documents and Settings\David\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\5GXUDIYO\on;kw=Casual+Entertaining;kw=Entertaining;kw=ba;ad=null;kw=recipes;kw=food;kw=reviews;kw=Golden-Pan-Fried-Fish-350404;sz=120x60;t
Status: Hidden

Object: C:\Windows.old\Documents and Settings\David\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\5GXUDIYO\on;kw=Casual+Entertaining;kw=Entertaining;kw=ba;ad=null;kw=recipes;kw=food;kw=reviews;kw=Golden-Pan-Fried-Fish-350404;sz=300x250;
Status: Hidden

Object: C:\Windows.old\Documents and Settings\David\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\5GXUDIYO\on;kw=Casual+Entertaining;kw=Entertaining;kw=ba;ad=null;kw=recipes;kw=food;kw=reviews;kw=Golden-Pan-Fried-Fish-350404;sz=728x90;t
Status: Hidden

Object: C:\Windows.old\Documents and Settings\David\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\5GXUDIYO\PCAF7LD5TCALHTQM5CABD3YIECAZHKIBLCAOTUD7RCA6QD2G8CAKU0U08CA1BWF20CA6XN6X7CAA5B3N2CAASW7KJCA9P0S0CCAI4EW65CAN802IICAH9G8J0CAGZ9X81
Status: Hidden

Object: C:\Windows.old\Documents and Settings\David\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\5GXUDIYO\PCAWSC06VCA7US431CAB6O4XNCASQ8UX0CAX50BXJCAEXQK1ICAANPUTXCADH3EZWCA07GDSWCAK3YKIHCAPYX1A0CATJQ6A9CAI14AOZCACLNE14CAZM32R3CAS1QDTJ
Status: Hidden

Object: C:\Windows.old\Documents and Settings\David\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\5GXUDIYO\PWCAD2WCJDCATIS0KPCA0K99KACAYQULZYCAMRI6AKCAIIRH34CA9X3498CAKIBHAKCAUJ1M4FCA2I6BH6CADTO0B2CAOWWZJICAPAGI0ECAEWTIX8CA3S48AKCA5MEMA
Status: Hidden

Object: C:\Windows.old\Documents and Settings\David\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\5GXUDIYO\ZCAFM2WNOCA4LJSVOCA7YCE7ECAABHVAACAE11VZACAAXHJPZCAAGYEQHCAF6RDFRCAY0MFKNCAQFOT51CABPYWEQCADI60VMCAI46OH6CAKSWPXLCAEP823UCAJGYXMG
Status: Hidden

Object: C:\Windows.old\Documents and Settings\David\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\5H5JT4UB\9CAMO71P9CA643I3CCAV3T5NACA8UQ4UOCA5YJG2UCAWLGTYUCAHKVSS7CAH9RCVLCA5TDN0OCAZZCPCQCA1ANHF3CAW8X5BVCAUQ1T5VCAZGZSEHCA52C73GCAQ00D74
Status: Hidden

Object: C:\Windows.old\Documents and Settings\David\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\5H5JT4UB\ag.epiblog;abr=!webtv;kw=top;kw=articlesguides;kw=blogs;kw=editor;kw=2009;kw=04;kw=five-foods-that[1].html;sz=300x250;tile=3;ord=
Status: Hidden

Object: C:\Windows.old\Documents and Settings\David\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\5H5JT4UB\ECANDHO8BCARM1OPJCA2MEEEICA0BYGX4CAAWE21PCA2XDMI7CA0SJ2GDCAEHPM6ZCA4VR5U4CAS9F28OCADSQUNJCAQU42SKCA7KT7S1CADYPM3ACANJNT0YCA2X3YGY
Status: Hidden

Object: C:\Windows.old\Documents and Settings\David\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\5H5JT4UB\ICAU6WU4ZCAKVUF0UCA5R7JT5CAS5AG37CATVZOG9CASUREQACAUAZO2XCA4ZD9VHCAV1WKU1CAE80EJVCAN4MBC8CA0DIMGBCAPZEFRCCAY4XH67CAIHK1SHCAYU6KJK
Status: Hidden

Object: C:\Windows.old\Documents and Settings\David\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\5H5JT4UB\ion;kw=Casual+Entertaining;kw=Entertaining;kw=ba;ad=null;kw=recipes;kw=food;kw=views;kw=Golden-Pan-Fried-Fish-350404;sz=300x250;t
Status: Hidden

Object: C:\Windows.old\Documents and Settings\David\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\5H5JT4UB\JCABONOG0CA224X9SCAIOQBZICAYGY0UUCALK6Z2VCAL0YPNZCA9GDCV8CA3OH8FSCAE6QAOECAJ9VDWXCA3O8VZNCA83HGYNCALEQ24CCAKVG2A2CA2UQEJ0CAL2OZWP
Status: Hidden

Object: C:\Windows.old\Documents and Settings\David\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\5H5JT4UB\JCAXPX4GDCAJYQQ3ECALUIU7ECAO7S6MQCA4KGHADCAR74E15CARWLE64CA3FSYPECAT4GDS2CAKHW7Q7CAFZOFVKCACNUIECCA1IDRFYCAILHSFHCAF2VHXDCAU2DL8J
Status: Hidden

Object: C:\Windows.old\Documents and Settings\David\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\5H5JT4UB\KCA1BU1HOCAZ3RRVFCAHW0CZ6CAL9JKAGCAMKNT5UCAAXGBFGCABK27GLCANO49FGCADLP7FTCANFGMSSCA9C0NSDCAI9HQJJCA7TEP2ICAGDRWYJCAI4KAYQCAJONPSB
Status: Hidden

Object: C:\Windows.old\Documents and Settings\David\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\5H5JT4UB\LCABP2SYVCAGR7ZQGCAO5RBQ1CAQIFYXTCAMG1XBPCAGJ5XSKCAV6J9ZZCAILNU1PCAAC8BCMCA0RS5WJCA336TMRCABXQ536CA9OGXBECA1KUT1PCAN2C5NCCAVJN3AJ
Status: Hidden

Object: C:\Windows.old\Documents and Settings\David\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\5H5JT4UB\NCAIO3NL4CAS8JAIFCA0YWPZ1CA087VFMCAH0ZU13CAK6KOQ4CASZZ0I2CAJEM117CAIHEZDSCA5J3ZS6CA0MCX12CAXXDEXICABKUYR4CAV4F32UCAQKWVJBCA7720YD
Status: Hidden

Object: C:\Windows.old\Documents and Settings\David\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\5H5JT4UB\OCA9PDWCGCA65MRIFCAUWJ2R3CA65Y3MWCA01XPK7CA07RNLNCA8DNE35CAWA2K5QCAXP416ECAK0P4K6CAUGVLGQCAK5CZ7ACAUDSGYYCAFE021OCAMX665PCAV1GU1V
Status: Hidden

Object: C:\Windows.old\Documents and Settings\David\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\5H5JT4UB\on;kw=Casual+Entertaining;kw=Entertaining;kw=ba;ad=null;kw=recipes;kw=food;kw=reviews;kw=Golden-Pan-Fried-Fish-350404;sz=300x250;
Status: Hidden

Object: C:\Windows.old\Documents and Settings\David\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\5H5JT4UB\QCAELVVE7CA1XE493CARHY27BCAYKH41TCAP36GYYCA32E0BXCAU66J3GCA7ACKHPCAHHCJ06CAPTZ3JXCAKEKLMHCAS158VQCA18RAT4CA9B1WFKCAV3MKFKCAGRB5FR
Status: Hidden

Object: C:\Windows.old\Documents and Settings\David\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\5H5JT4UB\SCABZTC3QCA8Z1WAPCAAROP06CAHPHRFKCA2U243PCA23LN24CAUC06ZSCA9P275SCA96M6XUCAOKXQF8CAG8AZ1LCAIO3NXLCAZX9C6OCA6ZJVPICA9RS5ODCA5K5JON
Status: Hidden

Object: C:\Windows.old\Documents and Settings\David\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\5H5JT4UB\SCAFFT3SVCAAEI6F7CA88L9EXCA3SD08DCA7CEDWQCAMQAM7LCA4FVI6UCA16HZ0WCAP8IVCECAKAJ8HVCAW76JJLCA5SRTDTCABBNILNCADRVBQWCA0P9W0ICATCG3JS
Status: Hidden

Object: C:\Windows.old\Documents and Settings\David\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\5H5JT4UB\TCAAJTTUICALIB2LVCA8LM971CABC623HCALZ0DYHCA88SRDJCATAGBNSCA4JB1H1CAUHFI9WCAWDEOHQCAOO8SYACAAXVH8ECAH7L36OCAUYJ4I9CAURVYCUCACFE5XV
Status: Hidden

Object: C:\Windows.old\Documents and Settings\David\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\5H5JT4UB\VCAE1DY9RCAAUZ1E4CA2MNQVFCACD8RJ0CA1GA8OFCA1UXH3WCAJ1EKUSCA07E074CAM6PN73CAQY5WC2CADERHE2CAFU8F74CA948WVZCALB41UVCAA4RFCZCADETOUR
Status: Hidden

Object: C:\Windows.old\Documents and Settings\David\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\5H5JT4UB\WCAS6INCICA8IKJWYCA9Y9PEUCAXK3KCUCAO2TFO4CAYX8Z2ECAQZM5YYCASPBWM9CAWC10Q7CAFHATRPCALI1RS3CAXFSFVZCABH2K8YCAA2U29ZCA04ZNB5CAWVSCTI
Status: Hidden

Object: C:\Windows.old\Documents and Settings\David\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\5H5JT4UB\YCABWC2HYCAJ704H6CATUW3YSCALCH032CA7P40BVCACEFB44CAIF051TCAJ1MVM5CAEBAEGBCAVJOBHWCAYCYQSOCAUKFCVTCABG70BSCA0JC09NCAL7FCQACALZ4ZHU
Status: Hidden

Object: C:\Windows.old\Documents and Settings\David\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\5H5JT4UB\YCACWZJWUCA8JMRQDCA4XY069CA7IFCY2CAAZID0QCAP2FKTWCA1WONPVCANPM45UCA0KPBANCAKQBFLCCAOP74IVCA5RKZTICAALHGVSCACRE4CDCAJ3N9HACAE8C8EZ
Status: Hidden

Object: C:\Windows.old\Documents and Settings\David\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\5H5JT4UB\Z2CA6PWWN7CA8Z514TCACQF8LQCA950OAUCAEQ9QSUCAUVW599CADHBOEXCAZ1512OCATWHY69CAM4HS63CAAR74S9CAHWK6V2CAFY0E99CAEZ47F8CA7WRLQ9CALZPPO
Status: Hidden

Object: C:\Windows.old\Documents and Settings\David\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\6M8YKNLP\0CAH5OYRICAB2BYC7CAXO96OMCAB428C2CADPOHHGCADOFJPRCAITTR7ICADWBSWCCA2XASCWCA2P6ECOCANMH0KVCA9VOHH2CA60OO71CAG2CACCCAR59SSUCAU3M3EW
Status: Hidden

Object: C:\Windows.old\Documents and Settings\David\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\6M8YKNLP\1CAGD6QIICAZEMBYDCA86HKFVCA1TZE8ECAWOKXFDCAXGMAY5CAXVVJ0GCADL1KQ1CAYVPFFHCA5NTJZOCADH6VI6CAD7HIZ7CAABY2KKCACBALQTCACAAFK3CA6B0V3U
Status: Hidden

Object: C:\Windows.old\Documents and Settings\David\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\6M8YKNLP\2CASIMW3DCAO7MILXCA922Y20CART9CKYCA45QDI9CA90D1E1CACFWA6NCAHHAFSLCA2X6FZXCAA5VPWLCAW6ZBXMCAN2VQ1FCAF72J8QCA62X0KCCAN5WWPZCAT8MBCO
Status: Hidden

Object: C:\Windows.old\Documents and Settings\David\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\6M8YKNLP\2CAUIC7T3CA62UHT0CA19TO49CAPMZBN0CAJGA0N4CAIFZPKHCAXFD22ACAGJ0H4DCA2HIKHPCAR7Q0V8CA2XJ6OOCAKSLKEFCA7W37RRCAF8NYWCCA0XAEXJCA421M1U
Status: Hidden

Object: C:\Windows.old\Documents and Settings\David\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\6M8YKNLP\2NCAUBV4QICACBKBOBCA1UCJ4UCAELXL0YCAHHMBQ2CAMS7ZHLCAIAGFFMCAXBQVRGCAZXDF3GCAZGHVSHCALZVA0OCAAF9S0VCATLM86BCA5W15EFCAI5FO4ZCA8B7PC
Status: Hidden

Object: C:\Windows.old\Documents and Settings\David\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\6M8YKNLP\3CAMKI828CARF2GQJCASD2X5GCAH55EEBCA54B3U1CA32098NCAA3QCSHCAEJEKCXCAH3IDDYCAOKBWV2CA76K2MECATXFGEYCA657VB1CA4TEO0NCA5I5ZMRCAK5WXL6
Status: Hidden

Object: C:\Windows.old\Documents and Settings\David\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\6M8YKNLP\3CAT23FU1CAQ48LOWCA4S2PWGCA8ET3XDCA1YPL8ZCAISGPR6CASJF0S0CA3X079UCAQF3RBUCA4GXJGACAGBYICXCAR5VRHYCAHAGZVZCADR2ZMKCAJ4FW29CAG2754L
Status: Hidden

Object: C:\Windows.old\Documents and Settings\David\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\6M8YKNLP\5CAFYBLEACANCJOA5CA31O28PCA4OX3QZCA91O3L4CA97SFV0CAUPSYNACA91ARRFCALKMBKSCAW3GOUDCAU33VKNCA9MLVURCADE2326CAXD1E0HCAYOHX8LCADF5QO2
Status: Hidden

Object: C:\Windows.old\Documents and Settings\David\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\6M8YKNLP\5CAQ3YUFXCAUUT0RUCAF8ED1NCABXLU5RCA8N4Q13CA70AAEYCABKG6RDCA44SU52CA4JOZBACAO0NIEACAOD5T9PCA52HSPXCA561A4CCADNCYLSCAKWS7EXCAL3HTU4
Status: Hidden

Object: C:\Windows.old\Documents and Settings\David\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\6M8YKNLP\7CAI444KGCAS0GDC1CAUWRO2PCAAMBWQUCAUISVUOCAFSCYPECAHGZV6SCAA0BL5ECAERY8L2CA7JV1F1CAP4JXVQCANJVBK1CA7XJHG5CA8SBNB3CAOEYB2RCADMQ9S7
Status: Hidden

Object: C:\Windows.old\Documents and Settings\David\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\6M8YKNLP\9CA7X1AK8CADP0NIWCA751XQKCAD3TWHHCACHM091CA8L4T70CA9MZ3CSCAFR6BNVCAN0NYDECASNL5Z8CALTUD82CAF8HZZXCAUG7TCGCACYPLGWCAAZ8OYJCAIU5M5S
Status: Hidden

Object: C:\Windows.old\Documents and Settings\David\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\6M8YKNLP\9CAM5DZ5NCAVJVMY7CAER8YXQCA3LY5X3CAMOGOMVCA3PDGFTCA5GSZ0YCAF0HQK6CAVRCI4PCATZNP7WCAE34ZO4CA60MA90CAQHK4TPCA0RY9BUCA98FGJ5CANDRUZK
Status: Hidden

Object: C:\Windows.old\Documents and Settings\David\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\6M8YKNLP\ACAIVDXNXCARU04D7CAF7XNMQCAR83LQZCA5MYDRRCA6Q07I2CAML1SE3CAQSJ7F6CA652BOUCAMZ7QKRCAC2KCY6CAQWFG8OCA2SPE04CATPUCXECADUHUH1CAUAGGHS
Status: Hidden

Object: C:\Windows.old\Documents and Settings\David\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\6M8YKNLP\C0KQB6CA43L24DCABLUT13CAI4U7RPCAOWZUSOCAS0VMP8CARCGY1HCAHN0XTNCAXRCXJNCA5KTZUUCANVWX63CA3PQBO2CADE7CI5CAVOSLZHCAR0G8UNCA2S598HCAP
Status: Hidden

Object: C:\Windows.old\Documents and Settings\David\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\6M8YKNLP\CCAKI9HNNCABUNU03CAMJ68KOCA7O8IF7CAG4KRS9CA6WO8HLCABEI670CALGD4ITCAGCEU3JCAD1V4D5CAM2YS0DCA6UXEWXCA25O5XOCAM5P5LRCAKXATNXCAJYFJR3
Status: Hidden

Object: C:\Windows.old\Documents and Settings\David\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\6M8YKNLP\CCAZKL029CAAPDL99CALLFK26CAF687NACAZN9H0OCA5L6AR2CA45COH1CAMGAPVGCAPR4FZECAIPBZ07CACX3KHBCA607S8PCAXIRRV7CAERH5TSCAZNICZGCANSYI2L
Status: Hidden

Object: C:\Windows.old\Documents and Settings\David\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\6M8YKNLP\D8CA6EPQXMCA24HGFPCA51ZTDECA6J7UO9CA406K1KCAQ7HHV5CASF3H23CAGV8W5UCA15PJN6CAEWUCP0CAUI94NGCAFQZPBZCACLU1VICA85U89WCA5W94WBCAKJQPL
Status: Hidden

Object: C:\Windows.old\Documents and Settings\David\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\6M8YKNLP\DCAIGUP3QCA5QMF5ECAW00HLBCANW356ICAS9HD15CAHZ011ACALPVWFMCA5OQNYNCAHSBS8BCA9BQ4CSCAB93IIICA59WD9UCAZ9VALMCAYGXQ5ICA7FED34CA3Y2MXW
Status: Hidden

Object: C:\Windows.old\Documents and Settings\David\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\6M8YKNLP\E3CAZ6SMMCCAMJKXG2CAWA8LGOCAVQJL5QCAGTPVMTCAZ8HTG2CAJO4HNPCAG8FN8BCA4BDS6NCAWMJH5SCACHMNPECAES91INCAVP28V6CAKBAEQNCAXMHPFQCAP71BI
Status: Hidden

Object: C:\Windows.old\Documents and Settings\David\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\6M8YKNLP\FCA06UDT4CA0CQAH6CANJD6T4CAPZ76RDCAYNFJK8CA5Z4YUNCARHSMFPCA53MZICCAU3FINNCANX774GCAPK64KZCAEL1H3SCAPJI2FZCA6TS3DTCAN62CP3CAWM2M6E
Status: Hidden
dcowie
Regular Member
 
Posts: 23
Joined: January 24th, 2010, 9:54 am

Re: Help needed with browser hijack

Unread postby dcowie » February 2nd, 2010, 9:26 am

Object: C:\Windows.old\Documents and Settings\David\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\6M8YKNLP\HCAWG2S3WCA2V93S1CA6MPTTLCAHY31GOCACQTADICAO1STFZCAPQPGJDCA1BLTT1CAL4O4M3CA5TQHWWCA0NCOOPCA49CXD0CABZX1O3CABNESLVCAEE7RDLCAA8P4ZA
Status: Hidden

Object: C:\Windows.old\Documents and Settings\David\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\6M8YKNLP\HZCALWXLZCCAH66NXICA7915Y4CA4JH4UTCAQKD5ZVCACI8O6QCAQAP1VFCAP0UOETCAC8S2HRCADNXUQ9CA983UEZCARAR3HGCACBKA0OCA2SFGWICA9GGGK7CA92SIB
Status: Hidden

Object: C:\Windows.old\Documents and Settings\David\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\6M8YKNLP\ily+Reunion;kw=Casual+Entertaining;kw=Entertaining;kw=ba;ad=null;kw=recipes;kw=food;kw=reviews;kw=Golden-Pan-Fried-Fish-350404;sz
Status: Hidden

Object: C:\Windows.old\Documents and Settings\David\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\6M8YKNLP\ion;kw=Casual+Entertaining;kw=Entertaining;kw=ba;ad=null;kw=recipes;kw=food;kw=views;kw=Golden-Pan-Fried-Fish-350404;sz=300x250;t
Status: Hidden

Object: C:\Windows.old\Documents and Settings\David\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\6M8YKNLP\JCA814KD6CAMI617JCAUAZ2YFCAUNFU7PCAWCRHC6CATCRRIUCA3TTRTDCANZ3ZJ1CA5U6AOHCAALJFSGCAW3PIEMCAPFORY2CABJZVR4CAKL15TQCA4C8Z7RCANFJDBX
Status: Hidden

Object: C:\Windows.old\Documents and Settings\David\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\6M8YKNLP\LCA0HFGE5CA0MA2N0CAL509LTCA18JCGNCAWJDMY9CAMUJKUICAJMFWW1CAN6AIGNCACKY50BCA7QL0NDCAIEDGZ5CA3Q45ZFCAXUZC4VCA1X1B6VCAICQJV0CAFEC0K7
Status: Hidden

Object: C:\Windows.old\Documents and Settings\David\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\6M8YKNLP\MCA46G82UCA39ROCMCAT2Z7RZCAH5NQRECAVC8D1XCA3HNEPPCARRILTJCA3FRN40CAGD16TACAM7LX4NCAQW5Z8MCAY31WKHCA2ZUVNTCAR1RQTZCA8D7HPDCA0UCC56
Status: Hidden

Object: C:\Windows.old\Documents and Settings\David\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\6M8YKNLP\MCAP71AHVCADG4KFACAJ4315DCAW1IHR7CABRYF2SCAUW54KZCAH79K3CCA263BBYCAWLLCNBCASP85RZCAF55A1NCAL5YTBTCACVX08QCA17RJS8CAENK5V4CAVJL9RU
Status: Hidden

Object: C:\Windows.old\Documents and Settings\David\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\6M8YKNLP\MSIQRECAKTR9A7CAQBHVRRCAJ29BDQCAIYHST1CA36KAP6CA2STNJ7CA5XLWR9CAPZND7CCAYNCOJ3CANLP99LCA0AZ4VRCA8ZUSY0CAWEHRG7CA6I2JOFCAJK1JPCCA2
Status: Hidden

Object: C:\Windows.old\Documents and Settings\David\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\6M8YKNLP\MYCA6SUZ2ECAHJ6746CAT9EFIYCA7440CVCA0XPPBZCA5R0OQ6CA3GGFLKCAPXUJU8CAC9L0BWCA7T9U1OCAD6YJVBCAQG0J71CAN61US2CAJCNY73CAP0LWIICAXB3A3
Status: Hidden

Object: C:\Windows.old\Documents and Settings\David\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\6M8YKNLP\n;kw=Casual+Entertaining;kw=Entertaining;kw=ba;ad=null;kw=recipes;kw=food;kw=reviews;kw=Golden-Pan-Fried-Fish-350404;sz=300x250;t
Status: Hidden

Object: C:\Windows.old\Documents and Settings\David\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\6M8YKNLP\nion;kw=Casual+Entertaining;kw=Entertaining;kw=ba;ad=null;kw=recipes;kw=food;kw=views;kw=Golden-Pan-Fried-Fish-350404;sz=120x60;t
Status: Hidden

Object: C:\Windows.old\Documents and Settings\David\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\6M8YKNLP\nion;kw=Casual+Entertaining;kw=Entertaining;kw=ba;ad=null;kw=recipes;kw=food;kw=views;kw=Golden-Pan-Fried-Fish-350404;sz=300x250;
Status: Hidden

Object: C:\Windows.old\Documents and Settings\David\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\6M8YKNLP\OCA9HE7CACARHMMYICAY8GUC3CA9WTPSOCAKE1XCGCA745M3ACAZ3LOJ1CA2R3RAKCAXW0G57CALIU35OCAG83C9ICA727F6SCADPC3T8CAXX3INYCAHCDKM5CAJNQRBM
Status: Hidden

Object: C:\Windows.old\Documents and Settings\David\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\6M8YKNLP\OCATOZEYTCALX7MHSCAEDKTG0CA9D1MB6CASFQNKPCAXHA3NJCA7SE5MMCAEW97TSCA5Z7SM9CA654SCGCAE71LOTCAIME0UOCAC34U1RCAU19FMGCA15U0MTCAI90N49
Status: Hidden

Object: C:\Windows.old\Documents and Settings\David\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\6M8YKNLP\on;kw=Casual+Entertaining;kw=Entertaining;kw=ba;ad=null;kw=recipes;kw=food;kw=reviews;kw=Golden-Pan-Fried-Fish-350404;sz=300x250;
Status: Hidden

Object: C:\Windows.old\Documents and Settings\David\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\6M8YKNLP\on;kw=Casual+Entertaining;kw=Entertaining;kw=ba;ad=null;kw=recipes;kw=food;kw=reviews;kw=Golden-Pan-Fried-Fish-350404;sz=300x250;
Status: Hidden

Object: C:\Windows.old\Documents and Settings\David\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\6M8YKNLP\QCAO38LBDCA7ROHO9CA79AM8BCAEN5N5ZCABKKZZMCAFEMDOQCALWONBBCAEZPHRKCAFHO7I6CAHWGPJICAVJCFMUCAUFNAL0CAVOGD3VCAZSHHKUCAKNY3W1CAO4LYEF
Status: Hidden

Object: C:\Windows.old\Documents and Settings\David\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\6M8YKNLP\QCAUBOBT9CAF72P60CADRBL46CA1EETSVCACGDYLSCAID756HCA7GNINLCA72FWZCCAMW92LDCAULF5UOCAED2J7NCAEL2GLGCAIJMXJZCAFMQJWKCAFU7M3ACA2O2714
Status: Hidden

Object: C:\Windows.old\Documents and Settings\David\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\6M8YKNLP\QCAZ14477CAYBN4K8CAMMUVR8CAD3R3MBCAXYPAHACAEY4H8ECA45Z74HCAL5G5XYCAP69XJXCANB5RMWCA24TCAACAJYPFXWCANZ60T3CAWTDCBQCAK5RET7CAWWFVMO
Status: Hidden

Object: C:\Windows.old\Documents and Settings\David\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\6M8YKNLP\SCA7S3CX5CAI4VM31CANRPV1CCA4936DKCATAZBTACAKJAMMTCA559ZX0CAZ7MSMWCAK6K9K3CADN6AEQCAF9IC3ACA162E46CA7OBA7WCAOH9606CANUK360CA05PT8I
Status: Hidden

Object: C:\Windows.old\Documents and Settings\David\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\6M8YKNLP\UCAXP7TZECA2LH69ACAX5NU7WCAUKB41UCAQ23236CARV6ICNCAJWJVRNCATZW67SCA99MWOVCAIFSL08CA3SMI0DCA5Y23KJCACIV4LJCAUGZIOLCA5KJ1WICAF4E2GR
Status: Hidden

Object: C:\Windows.old\Documents and Settings\David\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\6M8YKNLP\union;kw=Casual+Entertaining;kw=Entertaining;kw=ba;ad=null;kw=recipes;kw=food;kw=views;kw=Golden-Pan-Fried-Fish-350404;sz=728x90;
Status: Hidden

Object: C:\Windows.old\Documents and Settings\David\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\6M8YKNLP\union;kw=Casual+Entertaining;kw=Entertaining;kw=ba;ad=null;kw=recipes;kw=food;kw=views;kw=Golden-Pan-Fried-Fish-350404;sz=728x90;
Status: Hidden

Object: C:\Windows.old\Documents and Settings\David\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\6M8YKNLP\VCAYKEZW8CA88E3O5CAGYN7TBCAK4Y54MCAAEDPNACA3KFA8QCATDT5HDCABLQ5CUCAWYC9ZGCAJF70T6CAJRNZ2CCATM4HUXCAVSP2FECA1609TSCA2U54B1CAMF5XPE
Status: Hidden

Object: C:\Windows.old\Documents and Settings\David\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\6M8YKNLP\WCADWQZ41CA2US6J3CA3V2HKFCAM0DQHPCAJ1APTFCAFOABI4CAAIUKE7CAP90VWZCA5M73E5CAXOBIG8CABY7017CAPMPFFDCALG2QMGCAECKXB2CAPGB2EOCAI294OQ
Status: Hidden

Object: C:\Windows.old\Documents and Settings\David\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\6M8YKNLP\WCAFNMBEHCADFK5VHCAOTPPMMCA482125CAVYKQSQCAFWQTL6CAPG5CL4CAK6LRVNCABUVQB2CAM32Z8HCACN6OO8CA8DA1H8CA8UTPTVCADOUWN4CAV9PM6BCAT9JTBX
Status: Hidden

Object: C:\Windows.old\Documents and Settings\David\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\6M8YKNLP\X1CARO2HMGCAAH0L4HCAO9TAFICAUIDNQOCASKBYITCAKR6GQ5CABS2O90CA6U0Q3MCA2JZ156CAZJW70ICA86H3CBCAWODX8VCA8LLIGECADMU2R5CADPIJOUCAWX91W
Status: Hidden

Object: C:\Windows.old\Documents and Settings\David\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\6M8YKNLP\XCAVSFWH1CA1ZYQ8TCAHSOLKKCA7R9DE5CAUHO9PUCAZTT1SACA8STL66CALEPE87CANJ5BZYCA0TRUXBCA1ISPKHCA7DRCC8CALRSYZXCAZP6PZNCARZJ9B0CAS2TDGK
Status: Hidden

Object: C:\Windows.old\Documents and Settings\David\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\6M8YKNLP\YCAPXCOJ4CAKCPTFJCASBNBAKCA8C8014CAP4YTMDCA311TAVCA3NNRGTCA0BXFXRCATB1CKYCANKIGC9CA4NGJYFCAIA0CTGCAKR3ZQ0CAHTLQVYCAKUH2CRCAOUZEDM
Status: Hidden

Object: C:\Windows.old\Documents and Settings\David\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\6M8YKNLP\ZCAM1F0BVCA9S2N3HCA8QTN2JCAEZZDS0CATCIUAWCAJQOOTJCAH1RF9QCA12QK9HCAJXBC4OCA6IP6ZTCAT51385CA8M0HLSCASNN1MZCAXSIIXQCAYH7N3ECA6FKEUT
Status: Hidden

Object: C:\Windows.old\Documents and Settings\David\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\G2LW5W4B\0CA01WW7SCA91MZIECA6JU41PCAIW61GHCAQLUAA2CAA6P14QCAZLHBFNCA890BUUCAAVP3T3CAEIHWBZCAAVQM7JCAFJ4XJLCA1YADX8CAL6TKS6CAZZ3PU3CA0SQH6A
Status: Hidden

Object: C:\Windows.old\Documents and Settings\David\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\G2LW5W4B\0CA9GS45UCADFKM8QCAOFST7PCAWVD2LOCA0JPCL9CA4KSJ72CA6X4H1UCA3S0ZVRCAAM8BPVCAJ0IZ2ECA6PKXCWCATINE7UCAU6NNOZCAFCEL5CCA0K9EUOCAA1HV4X
Status: Hidden

Object: C:\Windows.old\Documents and Settings\David\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\G2LW5W4B\1CAT4W6PFCA0PCKOTCADI4GNQCAC1G2ODCAJV0VRPCA2J44BVCAPWW8HDCATNSVACCA4K2PT9CAW035YRCADGCA53CA0T27DVCATQZE7YCAC15MYACAWS0UC4CAMAWSGC
Status: Hidden

Object: C:\Windows.old\Documents and Settings\David\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\G2LW5W4B\3CASDOKD4CA0TM6WHCANF0ZOSCAW3YUOICAYTP4ZSCAQTTB9ZCASE8PNNCAEVW8KJCA7ITU98CATQ3SATCA00J1T6CAWJMNEECABS9TI7CAVJ8OH9CAOZ6GR9CA3XKUGM
Status: Hidden

Object: C:\Windows.old\Documents and Settings\David\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\G2LW5W4B\4CA98SF7OCAVL8VVSCAZ0NYUECA8YC6SHCA66FMTOCALJI41CCAA99H9JCAN9P80DCA2MTAUYCA9UM6NTCADAKOJACA5U6VF2CAQNGLKHCAKJP4ATCAZBW231CA7XTTYY
Status: Hidden

Object: C:\Windows.old\Documents and Settings\David\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\G2LW5W4B\4CANJHEOHCA0T8GK4CABOG5OACAFG8J51CALO2U7MCAVSPU27CABQRAMDCAG2DD2UCALX5HBBCAVUWI1DCACXYNLVCAGWNB3HCAWAR52HCAKIG4KKCARE1F66CA0NT6LW
Status: Hidden

Object: C:\Windows.old\Documents and Settings\David\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\G2LW5W4B\5CAF5TLKFCAUXIKIECAWCR0E7CACM44GTCAT9H52LCADCEI66CAI5WJ45CA6T8REFCAOZSPSPCAKTUBGKCA2T3GJYCAV2A2FMCANW2EWBCA5T8UDDCAXRLNBBCADC5PQ5
Status: Hidden

Object: C:\Windows.old\Documents and Settings\David\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\G2LW5W4B\5CAP0PPFHCATTB50ICAH24ZPMCAQ5BU0VCAEM3WVSCA6769ZYCAKRCUEHCA2R8Z2PCAN59EMQCAUZONSECABT6V8ECAWGW631CA5YQV9PCA739TMRCAKV1S8UCA5BH0C9
Status: Hidden

Object: C:\Windows.old\Documents and Settings\David\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\G2LW5W4B\7CAHPUHMSCA3N9X39CA38MWBMCAKBSH74CA9D8B59CAZ4TW8ICAGS7HCTCAI3D2HTCAS9P18QCAZQUHALCABVQU9VCAKYB2SDCAW2K8CZCAY1ZDTQCAQAOLUKCAMKMWBS
Status: Hidden

Object: C:\Windows.old\Documents and Settings\David\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\G2LW5W4B\8CAC1P981CALAK52SCAF6YE1WCAQ1BJPRCAD5KKS3CA0OFGU4CAUF26KWCA9EC46PCA80XC6VCAATAJG4CAVBYKG3CAK8TOUOCAANKKZSCAU63FCTCAHGDR3TCAQ6X7E3
Status: Hidden

Object: C:\Windows.old\Documents and Settings\David\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\G2LW5W4B\9CAU0Q3RDCA0943JJCA4G5H7ZCA5P5BB3CADOL5X4CAGK4792CA8JEEGVCAA2S593CA0ZUZJ4CA20TAP8CAKZU816CATUUWG9CAKRQ8OWCAL75OB4CAF0418RCAFXEAPU
Status: Hidden

Object: C:\Windows.old\Documents and Settings\David\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\G2LW5W4B\ag.epiblog;abr=!webtv;kw=top;kw=articlesguides;kw=blogs;kw=editor;kw=2009;kw=04;kw=five-foods-that[1].html;sz=728x90;tile=2;ord=7
Status: Hidden

Object: C:\Windows.old\Documents and Settings\David\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\G2LW5W4B\DCAC6UT2ACANO300GCA9EDYU0CAAO8O15CA3G1FJ8CAT0IGOKCAH18YU2CAR89VYSCA51BGRGCAPHMPWFCAZN75Q8CAX86J2VCAFHRB7FCAUJ5BCMCASVBQ94CA33NIOR
Status: Hidden

Object: C:\Windows.old\Documents and Settings\David\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\G2LW5W4B\FCA53FPM0CAC6CYJ0CA0BA2B0CAWY3PX1CAQ97GTXCA2WFRW9CADOKEQ3CA02M86LCA7U7OWXCA9EQF9KCAK7MYKJCAKSPRLXCASZFN9KCA19GPF0CAB154F8CAKZT1QU
Status: Hidden

Object: C:\Windows.old\Documents and Settings\David\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\G2LW5W4B\FCAODV2IFCAMCKUKQCADC4ELMCA58AS64CAGL3U5XCAJMYH0LCA9BIKUWCA7JETXECA10P1WFCAYVHV6VCAL9GFGVCA3GDHJ2CAZM2VQYCA3I29WFCAEU79ZICAW18N1U
Status: Hidden

Object: C:\Windows.old\Documents and Settings\David\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\G2LW5W4B\HCAEC4ZGJCAJCLJ4DCA5RJ1CHCA4SQXJ7CAKPWKYZCA7OM2AQCATHW68XCAI4P51VCAHQ7IXJCA16Q2RKCAM51X29CA2J62Y9CACQKP8QCA43VV2FCA8CJZPRCAIG5PHW
Status: Hidden

Object: C:\Windows.old\Documents and Settings\David\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\G2LW5W4B\J1CAQ3E0L5CATR92LSCANFRGYZCAQG4HS3CATZRWXXCAQH7R2OCAQJ22X3CAUOX1ZKCAZOR3FOCAXUTX6GCA2IGCUKCA37S3BACAP1KG29CADW0Q8KCA1V76FYCAYEYFT
Status: Hidden

Object: C:\Windows.old\Documents and Settings\David\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\G2LW5W4B\JCA6R5OFMCAYFL1X8CAUJJLXVCAR0KMCPCAPF33FHCA3PTIVPCA5GYJGVCAMV1VKBCA8UCA28CAX484GSCA9JX4L3CAN8AE70CAGE38WICA1XYK87CAI84740CAJW4IJB
Status: Hidden

Object: C:\Windows.old\Documents and Settings\David\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\G2LW5W4B\KCA60Q7WJCAC6AQRGCA786I7ICAKKUHNTCAUC3U1KCAXSQ56OCAG9W46JCA337ZI4CAXU0UZ0CA2IX57PCAL0KVD0CADS73PHCAJNRUWOCATW4XW4CATK5Z2VCAIMVZSE
Status: Hidden

Object: C:\Windows.old\Documents and Settings\David\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\G2LW5W4B\MCA4F8V13CA0KA9BBCASLHY0HCA33100VCAGG1IOBCAYPV0QWCA8AN9S0CAGY0UYZCASWY32ECARBESMHCA0DJ70VCAGZR89DCA45RBQCCAJTV23QCAS3S5KOCA4IEDVI
Status: Hidden

Object: C:\Windows.old\Documents and Settings\David\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\G2LW5W4B\MCAAG640NCAYFTQLQCALH3EB0CAAXW4EXCA1D1VMNCA5IFIKKCAA4WJ4ZCAWM87XKCAMDV74FCAXWI3JHCADNWIUDCAY21QDKCAZO6YSZCANYMHGJCA39XNVUCA4L5IY6
Status: Hidden

Object: C:\Windows.old\Documents and Settings\David\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\G2LW5W4B\nion;kw=Casual+Entertaining;kw=Entertaining;kw=ba;ad=null;kw=recipes;kw=food;kw=views;kw=Golden-Pan-Fried-Fish-350404;sz=300x250;
Status: Hidden

Object: C:\Windows.old\Documents and Settings\David\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\G2LW5W4B\nion;kw=Casual+Entertaining;kw=Entertaining;kw=ba;ad=null;kw=recipes;kw=food;kw=views;kw=Golden-Pan-Fried-Fish-350404;sz=728x90;t
Status: Hidden

Object: C:\Windows.old\Documents and Settings\David\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\G2LW5W4B\OCA7JG8WFCA56IVA1CA0HQK8ZCA66JB27CA2GAJ42CAFMZ9QQCAWY1RVECAJT6WVICAMKNWNWCAEG3GWOCAOAV1I4CAHWGCI8CA6K9SY2CAC74TPOCAGHCXQTCAKL3LOG
Status: Hidden

Object: C:\Windows.old\Documents and Settings\David\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\G2LW5W4B\on;kw=Casual+Entertaining;kw=Entertaining;kw=ba;ad=null;kw=recipes;kw=food;kw=reviews;kw=Golden-Pan-Fried-Fish-350404;sz=120x60;t
Status: Hidden

Object: C:\Windows.old\Documents and Settings\David\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\G2LW5W4B\PCA7F19C5CA7HA92ECAFFLQS7CAFE50FZCAZGIIH7CA3S5ZC3CAR837ZICA02L04TCAT4YGDKCAVB409UCAX603EACALXZ0XRCANUL6EVCA91BY10CANK86S5CA38QP80
Status: Hidden

Object: C:\Windows.old\Documents and Settings\David\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\G2LW5W4B\RCAWAEFSACAYU9XV4CAP432IPCA3AV9TFCA7ZY3B3CAKH85V6CA5P3FKACANB8P5ZCAAPNNRCCAHNW9QUCA1BI4P6CAQHGRX8CA5I2TO3CARCWN5GCARUCQMGCA7T0VP9
Status: Hidden

Object: C:\Windows.old\Documents and Settings\David\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\G2LW5W4B\TCA1BS1WVCAB72CKRCA6D26WMCA3PCU3QCAPTNPL6CABC4PP6CAO97ZOSCAJ0309RCA3HNH95CAH8COWNCAD4OF7UCAYPE0N9CATG3RE9CAHPKR0XCA2VKENQCAEAKXMX
Status: Hidden

Object: C:\Windows.old\Documents and Settings\David\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\G2LW5W4B\VCAGHAXNDCAKN5DPRCAKUCG5PCA7IR6VZCAZVR142CA745ENOCA2DI6HUCAQOQ7M7CA4M92IVCA6EQ483CA3M5KMICAGEGC2ECAACR1Z0CA8Z480JCAWFEJ99CAALMY4X
Status: Hidden

Object: C:\Windows.old\Documents and Settings\David\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\G2LW5W4B\WCARPMI54CAEQDGQ9CAU2MNOFCAV3AS1VCAG3AVB1CA29T5ISCAYTCGOVCAZPY0FDCAPM9A2VCA29BUMJCAZ9VQDPCAAUD0ZTCACUJ8B8CAKLG0Z8CA6T123PCAUXZ0KV
Status: Hidden

Object: C:\Windows.old\Documents and Settings\David\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\G2LW5W4B\XCAUBWGXLCA8X0GVICAR86MI6CAILX3TKCA1X1HOOCAKLWYPFCAQLOOGHCAPGBDJRCASMC5PCCALI60NHCA3WQUPDCA3ZWU51CACV7YNVCA40G1UXCA8HIQZACAUTKOD8
Status: Hidden

Object: C:\Windows.old\Documents and Settings\David\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\G2LW5W4B\YCAQO6RTLCAUST825CACVC3NICA4N5F5XCAFT0CDOCAOYIPFBCAP2YC8ACALPCJ26CARKR8ZDCAZ7KF8ZCA8ZOBY7CAZA16MNCAJZFYZNCAO9BWHJCA1VDGCRCAO7LMF0
Status: Hidden

Object: C:\Windows.old\Documents and Settings\David\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\G2LW5W4B\ZYCA0TQKRBCABYQ7SVCA3817FNCAF5KVIVCABA4B4XCAZL95G1CANEVA8FCAGCT0ZHCART43LSCA4SNZQ9CA91XOU1CABFJZFFCAYF5NKZCAENO266CA2COV5RCAJKOYU
Status: Hidden

Object: C:\Windows.old\Documents and Settings\David\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\S0UN2NFS\1CAVBHOVACADIVRNGCA6229OMCAB6N06NCAOYIU0CCAB1WWK1CAMH848OCA5A7OR4CAN0FCOGCA5XDBGNCA7HI54TCAHWJUAVCAZLDU87CAW2SD27CA4FZ3SOCA7RPQNJ
Status: Hidden

Object: C:\Windows.old\Documents and Settings\David\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\S0UN2NFS\3CAND7JB3CAZV1HYCCA46Z4MMCAYEY17RCAV6Z9GWCAA73DDZCAWX1KM6CA717BZ1CAZVAM3ECAU2MTPGCA2D2A7UCA34OLQACAEZODJECA813FX5CAHRA3U9CA55KT0J
Status: Hidden

Object: C:\Windows.old\Documents and Settings\David\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\S0UN2NFS\4CA4L594CCA2G2DBECA5CGN99CA5IVFK7CAW5VXSHCA36KRQLCAB9TXBTCAFEI3O5CA4O6QKDCAAWF84ACA890PT0CAGHR3YMCA3PEVDXCAW55ZVHCAI9CM11CATPHA03
Status: Hidden

Object: C:\Windows.old\Documents and Settings\David\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\S0UN2NFS\4CAK8TKFACAXKUBGFCAWK7GWVCA2T6G0HCANO86HWCAPD5D4LCANNJS8NCAODR7JECAKJI8QBCASO9X5ZCA2KBY04CAHOLAA9CA1H1TH5CAVCVNIECAB7D7ZHCAG4AA33
Status: Hidden

Object: C:\Windows.old\Documents and Settings\David\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\S0UN2NFS\5CADPXR2XCASV23PMCAH2K13ACAOKEQGOCAKWJG3SCAKKGSRHCA3C2SDPCA2OOP64CA0Y7C8ZCATD38LCCAZX1BC7CAUETQ3DCAPUHTNRCAXQ90VKCAMJY697CAHK512Q
Status: Hidden

Object: C:\Windows.old\Documents and Settings\David\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\S0UN2NFS\6CA7B2H0RCAX05MTACATGOY7PCA5LAXQWCA63HEKLCAZDUT8BCACO1EI9CANG9XGBCA8LF31YCAX2MBSUCACEEQ2TCAMY3GVGCAW86LNXCAZR4ATMCATPAO64CAGVA5XF
Status: Hidden

Object: C:\Windows.old\Documents and Settings\David\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\S0UN2NFS\6CARV3FGMCAJ23LBFCAAFTJ79CA2TNVWICA1X8MKGCAYH0DFTCA34CR8ZCAIY4Y7OCAJFBC8YCAQO3PGMCA07P62NCA1STL7NCA2ESBOLCAUZHM5RCAPDGHNWCA5RE3N8
Status: Hidden

Object: C:\Windows.old\Documents and Settings\David\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\S0UN2NFS\7CAKU7PH9CAOLLWCACA11XN1ACADAFXK2CA54GWVKCA8KAF5YCAEVJA59CAR9X4P1CA3TGNCDCAV8OB7DCAZPDAOCCACG65GVCAVXXXEJCAPTIVIFCA4B5LG0CAYXALVE
Status: Hidden

Object: C:\Windows.old\Documents and Settings\David\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\S0UN2NFS\9CAY3JNCGCAJOWU9ICA9RBKO0CAG4K0QBCAB50QPQCANGCLAFCA99NVRDCA7356W9CA4TPFOBCAPIBX1UCA7C63FICAZA2FJBCAL8EZHICAY0C2TSCAVQGPM3CA725UX4
Status: Hidden

Object: C:\Windows.old\Documents and Settings\David\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\S0UN2NFS\;frmt=0;frmt=2;frmt=14;frmt=22;frmt=1;plID=1909907080;kw=video;kw=portal;kw=epi;ttID=5295870001;kw=80dishes;kw=preroll;cue=pre;cg
Status: Hidden

Object: C:\Windows.old\Documents and Settings\David\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\S0UN2NFS\BYCAVSBNSSCAV88WBECA7XEFQ1CAE9VHDKCAMNATZBCAUOQSQECAPM4PZZCAPPEKVXCACBJVYNCAY9X98LCA1FT815CA2NBTRBCAAKKFZUCAW3JYMYCA8HIDKXCANE8NT
Status: Hidden

Object: C:\Windows.old\Documents and Settings\David\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\S0UN2NFS\CCAQS7IICCA7WWXKACACHK85FCATOJI35CALVSETICAK4SO93CA1TF5NICAGMI1YZCAKSSSAJCAKMT3LSCA9YJULDCA8RFBQLCAS9AIS0CAG4GY62CATGV1LRCAGV7QT3
Status: Hidden

Object: C:\Windows.old\Documents and Settings\David\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\S0UN2NFS\DCAMJ1C37CAHKK0D8CA21B1E8CACQ0N9BCAERPPBYCA0XCV70CAMO3VLPCAG11SXWCAFD1NGUCA8J8NLDCAMPNKFBCAX7JVNECAF4HO2LCASLJ7D6CA2WG25TCAU5GZFG
Status: Hidden

Object: C:\Windows.old\Documents and Settings\David\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\S0UN2NFS\ECAG9ZZONCA1RRP7NCAWI33RICAYC24UUCAOYGJ03CAYZA3BICAIIYXVGCAGLDPL1CAY8S1P9CA4HJ1FICAW3EA0ZCA5QHC1RCAJ1IZ77CAH1I4PWCA5RKD0VCAWRP0YP
Status: Hidden

Object: C:\Windows.old\Documents and Settings\David\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\S0UN2NFS\F4CA84QTVZCAJECVDMCAAUR8FLCATEP14WCAZ17BB0CA2B8O1WCATF0CZPCA1Y02LICAUY99DHCAFHBCW8CA36MPBFCAMM60I6CAUKF2F4CA6DIWD0CA434EVGCA73OOZ
Status: Hidden

Object: C:\Windows.old\Documents and Settings\David\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\S0UN2NFS\GCAHT8FBWCAQFN99SCARDATYKCA5NI82WCADQDJ8TCA7RTZZ4CAPI5MO9CA543Q0CCAKWLQ0FCADW5XM2CA2FIFUQCAD7KMU6CA26HTEQCAULKJGJCAPKCX3NCAFV24R5
Status: Hidden

Object: C:\Windows.old\Documents and Settings\David\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\S0UN2NFS\HCAFKV36HCAEHDBAVCAVOLZHXCA1ZP8FNCA9ZKS8QCASBYB46CAUA7Z3KCADEB9MECA8UGM9ZCAWO34KACA43MN3ZCA5ZCOXICA6LX5APCAPOGG3ECA447AFJCA121KJ6
Status: Hidden

Object: C:\Windows.old\Documents and Settings\David\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\S0UN2NFS\ion;kw=Casual+Entertaining;kw=Entertaining;kw=ba;ad=null;kw=recipes;kw=food;kw=reviews;kw=Golden-Pan-Fried-Fish-350404;sz=728x90;
Status: Hidden

Object: C:\Windows.old\Documents and Settings\David\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\S0UN2NFS\ion;kw=Casual+Entertaining;kw=Entertaining;kw=ba;ad=null;kw=recipes;kw=food;kw=views;kw=Golden-Pan-Fried-Fish-350404;sz=300x250;t
Status: Hidden

Object: C:\Windows.old\Documents and Settings\David\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\S0UN2NFS\KCA7GLVGKCABGAF2ACARIAC8ZCAZZFULWCA3QY699CASWWF8XCAKV3MJMCAU65B9CCA8OE7UFCAG6T6UWCA03C510CARRWV09CA2YD01RCAA5TXB0CA5KCNOTCAD0E2ID
Status: Hidden

Object: C:\Windows.old\Documents and Settings\David\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\S0UN2NFS\LCAGPW1LGCAXSAYCXCACNL6LJCAIB0WVUCALX17ALCARU2QA2CAF7HFQZCABZ9G5NCAZBMA3JCAGN3ESPCA48A2ERCAVRUWU9CAD6SQNVCAZKXGRLCACVQU45CA0NWF7R
Status: Hidden

Object: C:\Windows.old\Documents and Settings\David\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\S0UN2NFS\LFCAZODWUHCAGQEPMICAD6TS3MCATU3WMMCA8ZPG1ACAFX02F7CA1X173BCA30H738CAEONNTACAGM1BVGCAVRH11XCAP0W1HQCAL8IT7BCAZN9YW3CAQNQJOMCAZDX5V
Status: Hidden

Object: C:\Windows.old\Documents and Settings\David\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\S0UN2NFS\MHCA0IAK28CAZEX1TJCAYXRT9RCAHHDXUMCACOBARMCAO9NB0XCAB7S6PCCAMEGPISCA36E70GCA9O5TSFCA9Z6YITCA46EXM4CAN3J1NSCARW9IQBCADWMASJCAPOJYQ
Status: Hidden

Object: C:\Windows.old\Documents and Settings\David\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\S0UN2NFS\NCAUZVV0OCA2OTMRVCACKO09KCA8LH5Y5CA1ME7I8CAXTSI2FCAOOABCZCADBQ8FPCA9DN6SOCAPF1PX9CA10DSQ4CA5ZTTM0CABLNTQYCAFAXWTQCAFJ1AEACA17WQ65
Status: Hidden

Object: C:\Windows.old\Documents and Settings\David\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\S0UN2NFS\nion;kw=Casual+Entertaining;kw=Entertaining;kw=ba;ad=null;kw=recipes;kw=food;kw=views;kw=Golden-Pan-Fried-Fish-350404;sz=120x60;t
Status: Hidden

Object: C:\Windows.old\Documents and Settings\David\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\S0UN2NFS\nion;kw=Casual+Entertaining;kw=Entertaining;kw=ba;ad=null;kw=recipes;kw=food;kw=views;kw=Golden-Pan-Fried-Fish-350404;sz=300x250;
Status: Hidden

Object: C:\Windows.old\Documents and Settings\David\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\S0UN2NFS\nion;kw=Casual+Entertaining;kw=Entertaining;kw=ba;ad=null;kw=recipes;kw=food;kw=views;kw=Golden-Pan-Fried-Fish-350404;sz=300x250;
Status: Hidden

Object: C:\Windows.old\Documents and Settings\David\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\S0UN2NFS\OCATBR158CAAG56PPCA737Z13CA8HPQIBCAWT6RN6CA5PMWJZCAZY88XBCA9F6FQPCA8VM846CAWRGJVCCAJJ9798CAGVYOMHCATFDRPECAAY6ZMWCA1N33T4CANCEMZ2
Status: Hidden

Object: C:\Windows.old\Documents and Settings\David\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\S0UN2NFS\PCA4V02RWCAZDULNUCAFU8LIVCAPXV0ZBCAUL5UQKCAVE7WU3CA1DL1AQCAE9ZSTKCAA7SFHUCAY5X5OMCAWMRJEGCAYXWEBYCA62IEAGCADOH3U4CAIC43L4CAI2XQAJ
Status: Hidden

Object: C:\Windows.old\Documents and Settings\David\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\S0UN2NFS\PCAN3CP4SCA2ZHQAMCA95ZHX6CAJ5JSF3CAET4GJ1CAWID7WMCAFPF6FUCA10BDZ6CA9KROADCAWXM1GGCA0X5N63CA36UO6UCA8HWSENCATB947XCAH7EDN7CAR55SWC
Status: Hidden

Object: C:\Windows.old\Documents and Settings\David\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\S0UN2NFS\QCA90CHNGCAWPZY6WCATHJ6H4CA1WV0UZCAVVTD5MCAH8JKCCCA1UY1T4CA2L7RWKCAYIFDNMCAD7DS2UCAZNAKKDCAQ3I0RCCAC635L2CAUBHFKCCACC5TT9CAC3297Q
Status: Hidden

Object: C:\Windows.old\Documents and Settings\David\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\S0UN2NFS\QCAAYWA6JCA4FJP9ACA0CW24XCAOMXRCVCAH3SW23CAIS866CCAY7O3NPCAH3OAT3CAQ3LYOTCA61WOHCCA1H7K7RCA41PXRNCAGBCXW5CAEYXG8GCAM586JLCAV5FTSR
Status: Hidden

Object: C:\Windows.old\Documents and Settings\David\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\S0UN2NFS\QCAL4JM5VCA8RYMIMCAENLDO4CADTH112CA9XAGE7CAFOKO3VCAD7HDA0CAS3JZ0LCA29WKDQCAQZ4BIECAMCBJJLCAWK559RCASONNTNCAKUMR0PCAQE96YYCANWY5L6
Status: Hidden

Object: C:\Windows.old\Documents and Settings\David\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\S0UN2NFS\QCATLY0L3CARJ507DCAB9RCIYCASRYOUICA3HZMR9CAHBZB4QCAIO364BCAWEXBKXCAK81WIKCA37GMB4CA3KKYVSCAP8XIS1CA81LAGJCACN0MF8CAVWWDPBCA312D4L
Status: Hidden

Object: C:\Windows.old\Documents and Settings\David\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\S0UN2NFS\QCAV3848ICAIEFIJ3CAORXRMUCA5W24NICAUAFMQVCAG0LRTFCA994DT5CALD38NKCALMYIGMCARSDJ24CAFQXT6PCA8G6NS1CAZT73OFCAYBDPJXCANKEQ1VCAGK6VE5
Status: Hidden

Object: C:\Windows.old\Documents and Settings\David\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\S0UN2NFS\RCA8Q7B2RCAIHXLBJCAP0H5M7CAI0BDLNCAKWCX0XCAJMYBJUCAYGB83TCAN3JCZPCAVO2XI2CAWWMRPHCA3GZ1OSCA1EX8THCAX4O38ACA1I7UR9CA26NVLUCAT3SF4P
Status: Hidden

Object: C:\Windows.old\Documents and Settings\David\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\S0UN2NFS\S4CATALMIGCAZQPY94CA29JQAXCAA2FJB6CAOJNQKWCAXI2CA0CAWU2ZKHCADR8H0DCAH98O6ICANCPWQ2CAM0ZA3LCAACTM2SCAWKEW37CAKCDGUFCAIYWMRICAKC64S
Status: Hidden

Object: C:\Windows.old\Documents and Settings\David\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\S0UN2NFS\SCA23EICICAZ6D21ZCA9ZM0O9CAGUOSFBCAM21QPECAQ7CPU4CATRU4H6CAPJR7N6CAXE5N46CAMDH0B0CA4SP7EFCAU3J3Z7CAIQ8F58CALB4BP3CARBBMH0CACYIO0I
Status: Hidden

Object: C:\Windows.old\Documents and Settings\David\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\S0UN2NFS\SCABGX2XDCAHZXO2WCAGKDM2XCAZSWE3WCARC2WSACABY3GQ6CABX0N4ICA5OYAX5CA3UU246CAHXUYF0CAB8ZIUICARQGNYBCANQF3DJCA69832XCAZSNEJDCAXVD31C
Status: Hidden

Object: C:\Windows.old\Documents and Settings\David\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\S0UN2NFS\T7CAUI20DPCAIVGGL1CA7SSD43CA8NQLZVCAAUG127CAJC6HB0CA6Q59SMCAESOVPWCAWLV006CA7E22QHCAEVDSLECATR8SPHCAJN70A1CAPHHBP9CAMP27HHCA149JE
Status: Hidden

Object: C:\Windows.old\Documents and Settings\David\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\S0UN2NFS\union;kw=Casual+Entertaining;kw=Entertaining;kw=ba;ad=null;kw=recipes;kw=food;kw=views;kw=Golden-Pan-Fried-Fish-350404;sz=120x60;
Status: Hidden

Object: C:\Windows.old\Documents and Settings\David\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\S0UN2NFS\UPCA4JS2ABCARNJCETCAOM36P4CAVR56W5CARBH44TCAOHJJQACAEOY0W6CAUJCU3UCAN7SRS9CAP02W9UCAMVSUARCAXPYDOCCAEGUOH5CAJDXV80CAW48BCGCATPMRZ
Status: Hidden

Object: C:\Windows.old\Documents and Settings\David\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\S0UN2NFS\VOCAKUBQ76CA0L7Z1WCAWB4H2ECAN3DHPRCAH4US68CADXCWR6CASZQ8UICA1C7WQ3CATBUHNVCALQGNZBCA9SHES5CARF8EVFCA5TT0HWCA7QRFPHCATF4E6QCAB4259
Status: Hidden

Object: C:\Windows.old\Documents and Settings\David\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\S0UN2NFS\WCAW6UY7YCAYV2PKOCAGMIBW2CAS9MI8GCAEA6R8ICAIPJTPCCAO8RUMJCAZOM43JCAMQCUVXCA9SP0SICAID8ZM3CAVG3V2RCA2GJKY2CABWZ9AUCACBVNHFCAK0UVMQ
Status: Hidden

Object: C:\Windows.old\Documents and Settings\David\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\S0UN2NFS\XCA0DX5TTCA6BICOKCAAUM154CADAU9G3CAKIQX28CAWYJEA2CAKAUYFACABLFKEUCAZ9SQC8CA70MQCJCA66QM4QCAJOGFE9CA0F1MDGCAWRXCGPCAH53803CA8PGHMD
Status: Hidden

Object: C:\Windows.old\Documents and Settings\David\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\S0UN2NFS\XCAF7R2ZWCA8O07U5CABX0QZRCA8PUFWOCAAR00GNCAH0E9RGCA11LPVVCA1H5K80CATVYZ7UCAA5DAORCASMPEBCCA195J6ACAVCQRD0CA56UQWICAU0HEVHCANM3LAS
Status: Hidden

Object: C:\Windows.old\Documents and Settings\David\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\S0UN2NFS\ZCA0ZLCR2CAAUNUAFCAGOE3JJCAXX4P1NCAT6A68CCA2WQCE7CAFR7FXICAX33SY1CANA90WECAR8CFBJCASS1UN3CATJZ51ACA2R6OMTCAMWK85ECAT5A79LCAOAP640
Status: Hidden

Object: C:\Windows.old\Documents and Settings\David\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\S0UN2NFS\ZCA2JYAJTCAHUV1W2CAVM31MACAPZZBBKCA31L6OTCAA2KFG0CAZIXHE9CARDJ9U6CAT53LW5CAYTZTS7CAQS5ZX3CANC6N3KCAJYU86ACALK0HW8CA28CJ5CCABCIANM
Status: Hidden

Object: C:\Windows.old\Documents and Settings\David\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\S0UN2NFS\ZCAQ3LNTMCAIOXWRNCAGZL6MGCAN58TJWCAKHMTE0CATX1JZQCASY7SPXCA9F6AZYCARL2FJNCA9VSW69CA98P9Y2CAV1VEJVCAYCV47LCA5HW12DCANK0Q35CAQ3RIB3
Status: Hidden

Object: C:\Windows.old\Documents and Settings\David\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\VQFCMUKZ\0CAF9HTL3CAMQEHVACASCGQYYCA91GACKCAAX1K61CAC8CAVVCA5I3Q76CA3QZYFOCAMJKY2YCAKHGO2FCASZRVIYCATVAH7TCAOE5F65CAQBSGTSCA11TVGVCAMK4CR1
Status: Hidden

Object: C:\Windows.old\Documents and Settings\David\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\VQFCMUKZ\0CANKFW1ZCA472GQICA6JVSXXCAIIK757CAI9357ZCA9I5J8UCANIYAOCCALG8HSRCAZ5BSFLCA4RSW5GCAU8UA1TCAKVZ9T9CAHK5907CARCRXORCADDXP1NCABO6COW
Status: Hidden

Object: C:\Windows.old\Documents and Settings\David\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\VQFCMUKZ\0CAO2EM0ACAEUZA0LCANF3G96CABU6FWPCA6NQQFDCA0P2SIKCA6ULXH9CAIUGQZHCADBUBJZCAS1KLTPCA7V87DPCAB3A7CMCALRNJ5KCAY2D4CCCAE34ZO7CA8PVLTN
Status: Hidden

Object: C:\Windows.old\Documents and Settings\David\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\VQFCMUKZ\2CA3FW9DTCACIXBGRCAGCDGCLCAOSBH5JCAJ4SULBCATR0KW5CA21KMKWCAMACJTCCAM6DAMRCA30XYKVCABFCQ3UCAU5T1A9CAXN6FAOCAISIY09CAIF1X6NCAKK0ZV5
Status: Hidden

Object: C:\Windows.old\Documents and Settings\David\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\VQFCMUKZ\2CALU18BHCA2DYPYJCAAN4133CASWBR1XCAHJZSW0CAS2MMK5CAV417MXCAMLJYTCCATIDPGVCAKCG35ZCA2EYT0OCAPZ5AVOCAUU9GBNCAH7Z2R2CAR2NSO0CABUYGYI
Status: Hidden

Object: C:\Windows.old\Documents and Settings\David\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\VQFCMUKZ\5CA5FQIY2CAW2RRXQCAB5UHSJCAEMHFVYCAO8C8RUCAUCC8U8CAYDN2WTCAUQ0JAUCA49OE4BCASCTWUWCA7ZIPECCAPKA24RCAH2SJSOCA1M5XPECAI0PKB7CAP9TRZV
Status: Hidden

Object: C:\Windows.old\Documents and Settings\David\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\VQFCMUKZ\7CAKAQPAHCAJS747TCA4JW3LMCA0XOO8WCANSHGNKCA0W87PDCAHQZ3T4CAOIXWG2CAU4YZOMCACAJWTECA9E4IFNCASXURSDCAEEIGZ7CA0S64NGCAVPX90MCADKEDCW
Status: Hidden

Object: C:\Windows.old\Documents and Settings\David\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\VQFCMUKZ\ag.epiblog;abr=!webtv;dcopt=ist;kw=articlesguides;kw=blogs;kw=editor;kw=2009;kw=04;kw=five-foods-that[1].html;sz=120x60;tile=1;or
Status: Hidden

Object: C:\Windows.old\Documents and Settings\David\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\VQFCMUKZ\DCA86JV5GCAFLE3KECABPU5IDCARDRO25CA5QYPRKCABMJ3WSCAB5TYALCAENMUXJCAI03OL6CA203S2KCA2PQ2ITCAHEYSOYCAMC5PXWCAKWUGS7CAL0EIRRCAKDVX03
Status: Hidden

Object: C:\Windows.old\Documents and Settings\David\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\VQFCMUKZ\DCAYQ87K9CAKMQRNDCAFAOF2NCAS3ZIR2CA6FO08MCAMMBFI7CAKGWTLKCAAWKNXMCAXJBLZ6CAENL8HUCARH14QECAYIA0GTCAT5OLSUCAQBQJDXCA2AWWOVCATJ29FO
Status: Hidden

Object: C:\Windows.old\Documents and Settings\David\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\VQFCMUKZ\GCALKTWZZCA0R4GA6CAU1RTIMCA5ILY20CAGWB8JZCA1YYJBPCAURAHGTCA7GG3L4CALWKKJ7CAV31IRECACO4B2ZCA5B3FPTCAZVHOIRCAAGDZKCCAE8BRYYCA2ORS1M
Status: Hidden

Object: C:\Windows.old\Documents and Settings\David\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\VQFCMUKZ\GCAMLVZ0KCANSRRYHCA7JYL8XCA5V2M0ICAEA0LYQCAD8OT31CAX5R2YICASE2SLDCAAND8UTCABL2ZOGCAP2Y9FICAZZ3L92CAZYTVJECARWHD06CAVW0CNUCAS7ZQWW
Status: Hidden

Object: C:\Windows.old\Documents and Settings\David\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\VQFCMUKZ\GCAXSXMSKCAQFFFA0CAWQM5GACAG293R9CA3QA9L7CA0HCBDJCAX4ZUSACA4JQFVKCAG2JZ3FCARGOLCYCAUJGP8QCASFYQT4CAI3XSLHCAI5KB92CA4CTYUSCA5Z65E0
Status: Hidden

Object: C:\Windows.old\Documents and Settings\David\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\VQFCMUKZ\HCAHH9P73CATI7OVACA7AKH0CCA6P0PLJCA5C7K5QCAXILH37CAWGWN8UCAQGKN7ACAW0WIMCCA05N795CA268VNXCASRMXBDCAG4RM6XCAN24DVBCAJ1EC1KCAE8IP9O
Status: Hidden

Object: C:\Windows.old\Documents and Settings\David\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\VQFCMUKZ\HCALB0J34CA00NPCWCA4IC6K5CA5TQ54PCAS63Y6PCAVWC8IRCA5HF5B5CAGUFQOGCA50M9AXCA53JR4SCAS3IEA4CAF3IRHBCAY580TMCA2X1GUNCANK35APCAG0C654
Status: Hidden

Object: C:\Windows.old\Documents and Settings\David\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\VQFCMUKZ\I3CABT8HMACAQRRHQHCAXK4YBJCAG4LYH2CAVKU9F4CATA7IYJCAKKQ704CAXWGWQ7CANFFHSOCALQNL9PCAQ109YKCAGAT63WCA1LG27YCAWP2M9DCAT3EQ8PCAUQ67R
Status: Hidden

Object: C:\Windows.old\Documents and Settings\David\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\VQFCMUKZ\ICAEORAXCCAK6J1NCCAYWI280CABAHJYACAR1KBZ4CA10EQPPCAVHKSS1CAKVQXTQCA0Z1773CABGJME9CA62F07ECAAEFKP1CASLOWM5CAZFD6U5CA74BWC3CASPQLXK
Status: Hidden

Object: C:\Windows.old\Documents and Settings\David\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\VQFCMUKZ\ion;kw=Casual+Entertaining;kw=Entertaining;kw=ba;ad=null;kw=recipes;kw=food;kw=reviews;kw=Golden-Pan-Fried-Fish-350404;sz=728x90;
Status: Hidden

Object: C:\Windows.old\Documents and Settings\David\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\VQFCMUKZ\MCACW1LZACACAY6VLCA80PFOJCAPVFIJKCAW5TAPECAEU63RECA7H41BCCAXIDG2SCAXZR9RICA53VN3CCA8B1PCECAHBPSBICAKIZP3RCAOAK4PQCA0DAB33CA0B3UXP
Status: Hidden

Object: C:\Windows.old\Documents and Settings\David\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\VQFCMUKZ\nion;kw=Casual+Entertaining;kw=Entertaining;kw=ba;ad=null;kw=recipes;kw=food;kw=views;kw=Golden-Pan-Fried-Fish-350404;sz=728x90;t
Status: Hidden

Object: C:\Windows.old\Documents and Settings\David\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\VQFCMUKZ\OCA8BQ7FWCANMA8FACAJLPKUXCAAZAMVCCAQY2NSICAOV1KLTCA8ZGPJMCANWA7M3CAVEQG8SCASMX8C5CAH7KR2GCAJ6V0UCCAEVHOOHCAQYI20UCA6WSYYPCAQ2RZ3O
Status: Hidden

Object: C:\Windows.old\Documents and Settings\David\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\VQFCMUKZ\OCAGNGAR2CAYCDNAOCABBUMQTCAVHP2KZCAZUFIUFCAQNRZG1CAVXTV27CAGPCF6UCAV5HRGWCA3FVFXHCAGPZ1DLCAS6BD4XCADCEVJBCAFLYVSACADN97ZZCALUG324
Status: Hidden

Object: C:\Windows.old\Documents and Settings\David\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\VQFCMUKZ\QCAIB04WJCA75HIPHCAEV1WKZCAGUUXW4CA2TT1SNCAKSA6FZCA4BAL1RCA9BVRJYCA7KQLG1CAL5AS8MCAXFLH88CA2DZHLRCA6GU9JYCAPKUT2QCAH8A2F7CA0DRIOB
Status: Hidden

Object: C:\Windows.old\Documents and Settings\David\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\VQFCMUKZ\QCAKA9RCYCASAR5WBCADQIS13CA17F7INCACQ5UHVCAVBYQZ9CA56I6D3CAU9DMN9CAT464SFCA77GG6BCA1XG9BDCAR4Q7XTCAQD22F4CA55M0PECAMRU07ECA8YUDI7
Status: Hidden

Object: C:\Windows.old\Documents and Settings\David\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\VQFCMUKZ\RCA1YU9LRCAL5UU69CAWFKKTHCALS2PN2CA80KDKXCA7R39MDCAR9U806CA28BWIACAJ48NIHCA9MSAE9CAWCN8J1CA3X0547CA2V9QK2CA0SY8COCA0CD3EPCA364F3U
Status: Hidden

Object: C:\Windows.old\Documents and Settings\David\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\VQFCMUKZ\RCAEP3RWQCAZHVVIFCAAJIM77CAPKK9H1CAWIR5UQCAKWXI28CAEJ3P0HCA9HOGGFCA6O7279CAPTF0CWCAT0CX62CAC2NLV3CASJ8GN8CAWS4C6WCAJ3ZNFBCA901F6G
Status: Hidden

Object: C:\Windows.old\Documents and Settings\David\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\VQFCMUKZ\UCA3WW9SSCAEPQUF0CANLC2DXCANJ646PCAHRQMFBCA753VP9CA0VEBTVCA6V1WIDCACB4AKACA1MZ3ZUCA0F2R7WCAQ8WBI3CA9G87VKCA17X05BCAQH4996CAK4OQPU
Status: Hidden

Object: C:\Windows.old\Documents and Settings\David\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\VQFCMUKZ\union;kw=Casual+Entertaining;kw=Entertaining;kw=ba;ad=null;kw=recipes;kw=food;kw=views;kw=Golden-Pan-Fried-Fish-350404;sz=728x90;
Status: Hidden

Object: C:\Windows.old\Documents and Settings\David\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\VQFCMUKZ\W9CAUL5Y1XCAH9ERHYCAWRL9QWCAXN5A2VCAYKGG0GCATCE6LJCA2B5AG5CAFM1NEACAKBUGCMCAFY9OWDCABNHNTCCARSX31QCAWX8DRPCAT6HR53CARVODJVCAQ5VWZ
Status: Hidden

Object: C:\Windows.old\Documents and Settings\David\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\VQFCMUKZ\WCA8YGUH7CA7408TKCAEG1ZY3CAS5GHX6CAR6M6IJCA4UJFBICA32Y6BLCAM1R22HCATP6N7WCA8XM19NCADWMGAGCAO5SDP8CA5UEKCPCABQFCSQCAUO8CYKCA1E8Q04
Status: Hidden

Object: C:\Windows.old\Documents and Settings\David\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\VQFCMUKZ\YCAXXT95QCAV1ZDQTCAYI51FACA546EBOCAU5KIWGCANYDNU9CAWX19PXCA3FLKDTCAJBBDLMCADR1LRDCALDTV8SCA224X25CAB1PSDDCA9FILLXCAKKK2PBCA9C0S83
Status: Hidden

Object: C:\Windows.old\Documents and Settings\David\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\VQFCMUKZ\ZCACT3FYNCAP091KLCAD5BZBDCA5PA38SCAN38ZVTCA3CENVECAKEG63QCAKT88Z3CAL7TRCICAYNPQ4SCANCCTYVCA83TMN4CA4O8XHKCAXPB6YXCADD2NVSCAHX6G4H
Status: Hidden

Object: C:\Windows.old\Documents and Settings\David\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\VQFCMUKZ\ZCADHVIYSCA53Z5DXCAY7HTKGCA434YS4CAGT0JZ3CADZ2TBFCASSSSVFCA36JVIGCAGGP81WCA7M8RKDCAVMK1JFCA3KJGKACAKU8MIICAU133Y9CAP20DNZCAGERQSJ
Status: Hidden

Object: C:\Windows.old\Documents and Settings\David\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\VQFCMUKZ\ZCAEY9T02CAPE4UZMCAD1KT0NCAXIDGQXCA47QET6CA8AS0JOCAFMTURRCAW501KBCA4YJV7GCAY9HKWRCA0Z96SZCAMCH0GFCAGEVK80CA5UNLU2CACG9IE4CAMKKSTU
Status: Hidden

Object: C:\Windows.old\Documents and Settings\David\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\YXF2N5JY\0CA9A7IACCA5LXWC7CAE6HIMGCAX0IZ2RCAQGK3F7CAPZRSUSCA9BS5CTCAGLOICUCAGFXKIGCACOFDL0CAQ23YNSCAF4WPX8CAYICHL4CAPZJB2TCAWYUIJHCAM8PS2G
Status: Hidden

Object: C:\Windows.old\Documents and Settings\David\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\YXF2N5JY\0UCAM0LZ6FCA32AIKMCA4RUVVVCA4YA3OECAT9D0XKCA3ICQZWCAK258JHCACGO62PCAYB172ACAPZDE9YCAXX10KZCA1KME6CCA1JJH63CA7J31B7CAV6ME97CAP4Q0F
Status: Hidden

Object: C:\Windows.old\Documents and Settings\David\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\YXF2N5JY\3CADEYKQGCA1IHF19CAHU4BD9CAT8PHVWCAA0J4RUCACT4EQ6CA63RP55CAPOJYXICADM6UJ0CAHNDW04CA3DY08YCAQHWVPKCAVTURZ4CAWSUDJUCA7LXM7MCAMQI1EY
Status: Hidden

Object: C:\Windows.old\Documents and Settings\David\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\YXF2N5JY\4CA5H948NCA79U790CA40Q8XMCAIN2MYMCAQHNAWECAE4YKI8CA9Y7QLACADFNG40CADNOC7TCAFA4L71CA8RBU8HCAK5A3HZCASYRYB3CA5A9YUTCACF1D9XCAMWRTIN
Status: Hidden

Object: C:\Windows.old\Documents and Settings\David\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\YXF2N5JY\5CA7YLW2ICAPZRBGFCA0DZR20CAD10G0ACASUPUS9CAU6HZM0CA67M0BICAGNS1TQCANX22XKCAIYDBWKCAAKWXJQCAQ830T4CA7UE2C7CA0KJNJVCAV9NAGBCAHNJ7O2
Status: Hidden

Object: C:\Windows.old\Documents and Settings\David\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\YXF2N5JY\5CAXMQGAACASWIYBDCAA0JHOJCAVZWSFCCA81292RCAS4ZT87CA6XVWA1CACISL8SCA2J0901CAN0P190CA5COUNRCAZR4ULYCAF2BD25CA8D6RRYCAEZSP5ACAJ83FR1
Status: Hidden

Object: C:\Windows.old\Documents and Settings\David\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\YXF2N5JY\6CAVKIJDRCAYNVXNQCARW6GOTCASAE00SCA0UPSVACABQPISBCA2OITETCARUUO9ZCAFL50JOCAK1V9VOCAH1HR2WCAM24JY0CATUGQJECACEHX31CANL4O1GCAKSNFKF
Status: Hidden

Object: C:\Windows.old\Documents and Settings\David\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\YXF2N5JY\7CA5F0H7FCAPLBVQTCA1ITB53CAULQ7G1CAXF004YCAV1LWM8CAD4ULNGCATF4HX3CA5KJRXWCAJENYZ1CAB6AMZJCA00TCY6CAYZNOQ9CA6AA31VCAU077ZSCAETGSX0
Status: Hidden

Object: C:\Windows.old\Documents and Settings\David\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\YXF2N5JY\7CAOUHARXCAETO5KMCABX86AXCAACZIM4CA0NICG2CA9BIIK8CAW8NY5LCAKLJMVICAW4PMODCAVSQZXNCA15VMMGCAZCCXI4CACLOCE8CA38PKZSCA91RFTHCA850J9N
Status: Hidden

Object: C:\Windows.old\Documents and Settings\David\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\YXF2N5JY\7CAX2SFIHCAL2X0XTCADRGYP6CAG7GQCLCAO6UAEGCA5VU6Q3CAE1IXV0CAD1AW0JCALCYH5MCAGQ6LHLCA4KIKLHCAB7T9FFCASANE0GCANMD1AOCAJO9Y25CA41Q6SD
Status: Hidden

Object: C:\Windows.old\Documents and Settings\David\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\YXF2N5JY\9CAMVD7WGCAYIJQRKCAQTG5XNCARWSXKQCAFNUVEJCA4RZNE7CAL83T54CAL60YQ6CAWGR1DFCA4PRTNQCAQH39AACAYURDM1CAES961RCAPEANM1CAE4NF5JCAI1MX93
Status: Hidden

Object: C:\Windows.old\Documents and Settings\David\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\YXF2N5JY\9CAY27MVWCAT301FACAMOACUDCA6C7A75CA7Y34Z6CAWXC716CA0M578KCAOXBZLRCA0BR7A7CACHOOTUCADM0MD7CAMCTAO7CATOGTM3CA6X47FDCAGG2Y5QCAJOPX4F
Status: Hidden

Object: C:\Windows.old\Documents and Settings\David\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\YXF2N5JY\BCA6D0LGMCAVO9IQQCA0KZ0RQCADCPK9UCANBX1OWCA2IQ28DCAGYMQPWCA1PFYMUCAH3D7DJCAO5CHY3CADWPLGFCARQ3PIJCAHL18H1CA1A223GCAVLUEQ2CA6HS9EA
Status: Hidden

Object: C:\Windows.old\Documents and Settings\David\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\YXF2N5JY\BCARGOVV6CAE17P8TCAEYXB46CAVWZXUXCA4B174SCAXPU200CAYS0Z0UCATZ0FTMCAYEGFYWCA76AOGCCAYOKCD0CAWRN1KXCA07K80BCAP6JGC5CAEVQMARCA8OL2E6
Status: Hidden

Object: C:\Windows.old\Documents and Settings\David\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\YXF2N5JY\C3CAG03FALCA50GW8GCA0WB0TJCA7GXVSJCAM7YEGKCA3Z3Y0LCADXA0RHCAB9DISUCA9T8D3VCA13W5O8CAL74UH4CAPHZ6KJCAIX5FCECATNOIWOCA7RZA1ZCAM89RL
Status: Hidden

Object: C:\Windows.old\Documents and Settings\David\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\YXF2N5JY\DCAFT2RLACAAP6HVYCAVWHN7NCAMU936YCAQE396ECADLFFFVCAXMAEA6CA517PV8CAWCZK7KCAO5V1DKCAKRE3OQCARFBG4JCA4O2RJ2CA5NKB7RCAWVG4OUCA7I2FM5
Status: Hidden

Object: C:\Windows.old\Documents and Settings\David\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\YXF2N5JY\ECAOYQ8CACAY0VSDRCA7R565BCAHA9S3SCAP5M0Z3CAS2ALCFCAIJUQ9SCAJB031GCAM88W17CARSVLFXCAZMFJB5CA1955R4CA9BAFDWCA7L03DKCANQ9MZQCAOQ7UON
Status: Hidden

Object: C:\Windows.old\Documents and Settings\David\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\YXF2N5JY\G0CA11UFGUCAXTCJIACAZQ91ZLCA4ZUG55CA07QD3VCAOJD2INCA6279E2CAGR1AQWCADJQ6VGCAYT3WGTCAOLYJ5ECA95PEP9CA1JX9J4CAZPKWCUCAY1PQ6BCA1WTH9
Status: Hidden

Object: C:\Windows.old\Documents and Settings\David\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\YXF2N5JY\GCA8J4YBNCAFGOO4ACA6RXCOWCAMLFXGKCAAMK19RCA5MSSWFCA8MS6H9CA1YBAB3CA374I9YCAJ6ZBPVCAT0XHPACALUGTSHCATWOYIACAH9E9HQCA4ST0X4CAHBIQZC
Status: Hidden

Object: C:\Windows.old\Documents and Settings\David\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\YXF2N5JY\GCADRHBAXCABB3UV0CATFP4ESCACYDDTGCAOJD2ZQCAMYS395CAQP4Y9CCAF7CQ0UCAKRQ26PCA7KCCTECA5HQ693CAUCMFQ9CAVR0I7NCAJHVBX4CALACTN0CAMWY69A
Status: Hidden

Object: C:\Windows.old\Documents and Settings\David\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\YXF2N5JY\GCAJU5EX1CAJ5JX9CCAVFDAQ5CAGHFN27CASA4ILYCAWI173HCAVOH9PDCACM9ETPCA6WE3QTCAAKMPOFCAEOUHJ8CAI8BGL8CACTCS96CARZMMT3CAFG05Z2CAW3C9T6
Status: Hidden

Object: C:\Windows.old\Documents and Settings\David\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\YXF2N5JY\I7CAQPQS51CAZM23NECA33K8V2CAJ9W334CATOMDV7CAXZ9Z3VCAF01O2YCAXE3L3HCA0BHUDGCAV9J126CASM8DKECAKRKYMKCA7TV57RCAGYB91QCADY5UNQCAL5A7L
Status: Hidden

Object: C:\Windows.old\Documents and Settings\David\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\YXF2N5JY\ICA0VZ96CCA3YJRYGCAH4XD9VCAOJFJ36CAPPBI54CALOJWNFCAD4299YCASW4XOBCASQNQIZCAK49UEQCAQN1YZWCA98GD3UCAFAHJ0JCAEC91MRCAD8WPV9CATXNZ6H
Status: Hidden

Object: C:\Windows.old\Documents and Settings\David\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\YXF2N5JY\ICAKPJY2YCAR916HNCA1C2IPLCAWR1PDUCA750LZPCAPMDH42CA1S69W2CA2QJZ8ZCAP0A41KCAEDZK48CAZGPGI3CAUVUD2FCAXNTVN3CAQKSZ7RCA3ULDIOCAFAV4P6
Status: Hidden

Object: C:\Windows.old\Documents and Settings\David\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\YXF2N5JY\ICAMMI448CAV3WV95CAHJ6W3VCA6B11ZECADQ371ICA0MTP20CA18ZEJLCAIAMA1DCA4KB9X1CAEF3WJLCA1MLQ7ECA1K82G6CALEZ9ZLCA4FEPAGCAR81ZF4CAPG5FV7
Status: Hidden

Object: C:\Windows.old\Documents and Settings\David\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\YXF2N5JY\ion;kw=Casual+Entertaining;kw=Entertaining;kw=ba;ad=null;kw=recipes;kw=food;kw=reviews;kw=Golden-Pan-Fried-Fish-350404;sz=120x60;
Status: Hidden

Object: C:\Windows.old\Documents and Settings\David\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\YXF2N5JY\JCA69FSBQCA70WT80CAOM5P7LCABD871TCAPT1PC3CAFY2X7QCAGW7LNRCAF35M3GCARFPB5PCA2VVAZICA7QNPVCCA3LQVKECACUVQIGCAI2V66RCAQE5HHOCA6VP7L3
Status: Hidden

Object: C:\Windows.old\Documents and Settings\David\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\YXF2N5JY\LCAYSS1EFCAKARWUECA71IHBTCACQGTZCCAL2OLA6CA11CR9UCA6ZV5G0CA89UWN0CA9OFDJVCA0KAX9YCAUJ3PD3CAMFLDH9CA8D8GG3CAMTM50XCACRM5WTCAEO0WCX
Status: Hidden

Object: C:\Windows.old\Documents and Settings\David\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\YXF2N5JY\MCABFHGT5CADJH0IVCA1HBJHICAWFSFC5CAAA7E17CAJB8986CACWREGICARC3N01CA72OS81CAIV5NP7CABR8IYGCA0ZQZ3ZCAXA0Z89CA2KUZMOCARH05U3CAD688L4
Status: Hidden

Object: C:\Windows.old\Documents and Settings\David\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\YXF2N5JY\MCCADPYSF1CAVER22ICA3F1X3BCABHYNGFCAEM0X3GCAVSD2OCCAWO9KQUCA02LJZPCARGDJYXCAGTGNDBCAUW0QQVCAM15DVKCAOENXMYCA4YHEJPCAVELGA7CAOTT90
Status: Hidden

Object: C:\Windows.old\Documents and Settings\David\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\YXF2N5JY\on;kw=Casual+Entertaining;kw=Entertaining;kw=ba;ad=null;kw=recipes;kw=food;kw=reviews;kw=Golden-Pan-Fried-Fish-350404;sz=728x90;t
Status: Hidden

Object: C:\Windows.old\Documents and Settings\David\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\YXF2N5JY\OZCAJ0267JCA58B89XCAZ6WR7UCA4C69WSCAFJEY9ZCAEKVFH3CAD2AGOACAYKESH0CA2SOBK4CALJ2W3TCA1PB1KWCAZHQMJ2CA0ZA6YQCAPHAL75CAOEKSVICAMQ3DD
Status: Hidden

Object: C:\Windows.old\Documents and Settings\David\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\YXF2N5JY\PCA6R81YUCAB3FEPWCA05XOKGCA15903XCASTBW2HCAZTB74MCAGBBH9NCAP0CXS8CAAXZLARCAAJNLQ0CA74MQYTCABX5CHPCAZ31J7YCA97O59VCAD7IS5JCAMB5FO8
Status: Hidden

Object: C:\Windows.old\Documents and Settings\David\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\YXF2N5JY\QCA9NH3W0CASXESI8CA6J1WKKCARN8NOJCAA7J1CICAA50Y5QCA7V8CW5CAI9DPDLCA3KAPJWCAIBSEGMCAB8WFKKCA4BGG2YCAWDJZJ8CAYN9MYOCAS82LOACA1W6N2W
Status: Hidden

Object: C:\Windows.old\Documents and Settings\David\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\YXF2N5JY\RCASELAIDCA2MMIU4CA5LNM9UCAM2NEGLCANQVT07CACYPK2LCAZFMVNGCA4TRBD2CA0ITJUHCASY5LBRCAOHQ92MCAADRC84CA7RCR1SCARW6BXYCAW28R1LCALEUGEX
Status: Hidden

Object: C:\Windows.old\Documents and Settings\David\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\YXF2N5JY\RCAU47XTHCAE35P5CCA6UFSXMCA9JO2EOCACE4KMICADZ0HLSCAMZDW94CAZCZPSTCAC8JV0GCAXWSVAHCAH864FPCAVQ0OKHCA1CTYRACA7QY069CARNMTAFCAIJJLM0
Status: Hidden

Object: C:\Windows.old\Documents and Settings\David\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\YXF2N5JY\TCAKICRL2CA44XC1KCAX0WK2ACAULFBGSCABA5FIYCASPY10RCAAYM2Z1CANCB424CAM9QFNHCA2OFIJ1CA3N259BCALI8TJPCAZYLK14CA620HKDCA7IVKW3CAM1CJ28
Status: Hidden

Object: C:\Windows.old\Documents and Settings\David\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\YXF2N5JY\TUCAMVQAS2CA9NYMHMCAJ4RT81CAN514SLCA3NZRASCAV4IFPWCAX6TCKOCA26ERVUCAKGPXMHCAUWPY44CA87HPHWCAQ4ZC4UCANQ4QJFCAXMJ0NDCAR4IM06CAQV5PV
Status: Hidden

Object: C:\Windows.old\Documents and Settings\David\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\YXF2N5JY\union;kw=Casual+Entertaining;kw=Entertaining;kw=ba;ad=null;kw=recipes;kw=food;kw=views;kw=Golden-Pan-Fried-Fish-350404;sz=120x60;
Status: Hidden

Object: C:\Windows.old\Documents and Settings\David\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\YXF2N5JY\V5CAB6M4P2CA6DVRR1CAN2T7FFCAMFSAV4CAMSS54MCATNIIXNCAZ2VHHACASHZCF8CAEIRKLQCAV5UR8TCAYZATPTCACIVCVKCAS41U5LCA82KHM5CA93Q757CA86C0T
Status: Hidden

Object: C:\Windows.old\Documents and Settings\David\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\YXF2N5JY\VCATIBFFRCA9M6AZUCAO8ZQQNCAPC6PTSCA4J9DZ2CAWATMN3CA0EZU80CAI0WD7CCA11Y28NCAD5KIQOCANO8FUXCA76W82MCA9KE7X8CAI6VSR7CAY3U51VCANNTP0A
Status: Hidden

Object: C:\Windows.old\Documents and Settings\David\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\YXF2N5JY\XCA8AS1UECAAMN8GPCAY1I743CAZ76YWOCAWAGZO9CA6267WRCAKJTC1MCAFCBAFTCAN91UBXCA4WLBL4CAZ0Z3H6CAGG8ZFCCAK5351VCAZSWASICA0WO6GQCAVZD6OJ
Status: Hidden

Object: C:\Windows.old\Documents and Settings\David\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\YXF2N5JY\YCAVHJ31DCADD3GYICA85DIW8CAS8X2FOCAM17UW7CAHUQK3UCAU9T3QPCABUTTSYCAHV5QA5CAL34TVQCANVFH1UCA4CH0HTCABCNTTKCAWJVWGRCAGX8RKXCADWH89W
Status: Hidden

Object: C:\Windows.old\Users\David\AppData\Local\Application Data\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\18VBDUF7\OCAZ13XD2CANA04A1CALCKUAPCA63HLC3CA4MEMWTCA7WZP2MCACJ7387CA5NXFEFCABCTESJCA85NDTTCACRXGDUCALG30K8CAPHQFY2CAUZF79ICAQ6N3DDCAI2SKG9
Status: Hidden

Object: C:\Windows.old\Users\David\AppData\Local\Application Data\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\2FGHYXL1\1CAHOEKBJCAKE2ONYCAOGNMZGCAXM41SPCA8I18VDCAH8L3BOCAG3XEYECAT9UVIDCA8UNYXVCAAD3PMTCAGSI99FCAZF1V3JCAPMM1SFCAFB7E6GCA4P6AE4CAL5CUI3
Status: Hidden

Object: C:\Windows.old\Users\David\AppData\Local\Application Data\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\2FGHYXL1\2CAGCXM08CAYEVJPICA1RQ1OCCAULNIEHCA85BS9ICA6M9MCXCAW3S5NBCAAKYEW6CAVHSFBPCAAE5AZICAQWI1OJCA95CYD1CAEW52IGCADQYHA8CABKU3M9CAEPH1ZS
Status: Hidden

Object: C:\Windows.old\Users\David\AppData\Local\Application Data\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\2FGHYXL1\2CAONXLG1CAU6HUI2CAI5B3E3CA1ED79CCATEK1WQCAIAUSCUCAWSRFD2CACKSBK1CA730G81CAGXY55TCAW9O5VTCAOYFIT3CA13ME3MCA8V2O69CA58K6GHCAYSL74X
Status: Hidden

Object: C:\Windows.old\Users\David\AppData\Local\Application Data\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\2FGHYXL1\2CAZ1GWWFCA2D5EIZCATWZ78ZCAQ3FHGMCA0FN7VCCAEIUC0DCACI0MUNCA0GA63UCAC7L85ZCARNZVN7CAUIALUCCAG0KZEJCA6BF17LCAIF00UPCA3X81UQCAMVLZBV
Status: Hidden

Object: C:\Windows.old\Users\David\AppData\Local\Application Data\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\2FGHYXL1\2LCAEJU6DVCAOVSA5WCA0ZW88SCAY9VSJJCAUSV86VCAZV4JGRCAJW098ZCABP7DWECA86T9M7CA0ZOUKLCA29MMIVCA38RMO4CA9EFTXECAVKSXTCCAH8SZ0SCAGU7X5
Status: Hidden

Object: C:\Windows.old\Users\David\AppData\Local\Application Data\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\2FGHYXL1\4CA0MKUEBCALNQCOTCAKKYJUPCAYYFU0UCAKYRQVKCA6L3D0ACAZ7DPGNCANKTDKJCARNFKNNCAUJPENNCANYJEPCCASRE1C8CA8JNPYZCAJKJ27PCAD302JECAKN3DD2
Status: Hidden

Object: C:\Windows.old\Users\David\AppData\Local\Application Data\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\2FGHYXL1\4CAB6ENCMCAA4ACLICABITQSPCA252KNCCASI2VGXCA69N5BQCAUCO84ECAE1TXMUCAYZMNSXCAKT4N3GCAI9JY51CA1UH1PKCA5SEQ84CAXGQ259CA4R48K8CAS4K6M2
Status: Hidden

Object: C:\Windows.old\Users\David\AppData\Local\Application Data\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\2FGHYXL1\4CAZRPL5MCAHU8KJ5CA4NWGO1CAXELHKMCAXRARCHCA1NL8QMCAT8GGGNCAPZAEIICA8CB2YSCAI5SC1TCATPDORSCAYAE2U4CAJEWUK1CAZHBEP0CAGCGWLRCAP91RDJ
Status: Hidden

Object: C:\Windows.old\Users\David\AppData\Local\Application Data\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\2FGHYXL1\5CAJ9WF4UCAB3HW14CAINQOMMCAUDIE2GCAU6472ACAWL0SH0CA5IEQJ6CADRWFGYCAYGN8QJCAR2369SCAY69Z2JCAYGLXR9CANG7SAJCACBR3SUCAJUE68WCARU42VO
Status: Hidden

Object: C:\Windows.old\Users\David\AppData\Local\Application Data\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\2FGHYXL1\8CAT75ROXCA996Y45CAT515RLCAXINGKJCA5RNPBKCA6RJCIOCA4BKJVCCAFW7FULCAEVGHEJCA69DX9WCABL46WNCAI2TL66CA2MMCNOCAQCL22CCADC94V0CA0ZIY28
Status: Hidden

Object: C:\Windows.old\Users\David\AppData\Local\Application Data\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\2FGHYXL1\9CAB9C8PTCAS6H8YBCABKN4NHCAALK5KECA17FP89CA5378EYCABP0BJPCAFSJQQTCAQW25MZCAZF4W2HCAFDS237CANZSLQ4CASH6YRQCAA4URXFCA03FJFVCA420B8Z
Status: Hidden

Object: C:\Windows.old\Users\David\AppData\Local\Application Data\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\2FGHYXL1\ag.epiblog;abr=!webtv;kw=bottom;kw=articlesguides;kw=blogs;kw=editor;kw=2009;kw=04;kw=five-foods-that[1].html;sz=300x250;tile=4;o
Status: Hidden

Object: C:\Windows.old\Users\David\AppData\Local\Application Data\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\2FGHYXL1\BCAAYHBSCCAS4KC8TCA1170PKCAY6ONACCAOFYHTBCA43KJ8HCA7CLG8ECA831ANICAEXGDMPCA7L6SB8CATAK342CAX4G9HUCAHJI0XKCAQ7QSB8CATLDNM9CAA1E92E
Status: Hidden

Object: C:\Windows.old\Users\David\AppData\Local\Application Data\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\2FGHYXL1\BCAEZ6LYNCA58FD32CASYQU86CAB7L32JCA0OZO9WCAM2VK4ACAJ0Q7DPCA6WTVHTCA8B8FIWCAKT6LH6CAZ79HAJCAW3JMD7CAKPL4LSCA4P4WXMCA6OP2I0CA1J123Z
Status: Hidden

Object: C:\Windows.old\Users\David\AppData\Local\Application Data\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\2FGHYXL1\CCA8J6AEQCAURGTA7CATTDEWXCAMUAPKNCAZRUH0DCA9UB11HCAJEE9H8CAPB194NCARVFF7UCABQ34HUCA7OOEMKCATG3OX1CA0ZAPQMCAQ2CHFUCA9WDO34CAGVWBW0
Status: Hidden

Object: C:\Windows.old\Users\David\AppData\Local\Application Data\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\2FGHYXL1\DCAKAPIKICA9ZKA7ICA6CLAVECAB682XICAEC5JCECAQKIPCQCAHS1K7YCAUHKGH4CAR6UXY4CAMHFT71CA5MF1WRCAEUL6MWCALSF98ECAOFJ884CASB2MZ1CACC4174
Status: Hidden

Object: C:\Windows.old\Users\David\AppData\Local\Application Data\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\2FGHYXL1\GCARL9CC3CA0L5MFHCABUG9BYCA0QJ2RQCANPQH6JCA5PGCKNCAAEQQ4ZCA1Z8APMCAGBT5UZCAYYGR3TCA3BPUGNCAT3YT89CAKFLMWSCAT1OC76CAY7ZOLUCANHNR6W
Status: Hidden

Object: C:\Windows.old\Users\David\AppData\Local\Application Data\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\2FGHYXL1\ICAMTL7RHCAW79EFQCAXDTB9ICASEQSTMCAIUMX54CAXW33LCCASNSUT7CA2YER9LCAKXOLFFCAJ3FROOCAPYNA76CA932MHSCAX9CE2VCAWF0B6ICA8DXIBZCADANLLV
Status: Hidden

Object: C:\Windows.old\Users\David\AppData\Local\Application Data\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\2FGHYXL1\ion;kw=Casual+Entertaining;kw=Entertaining;kw=ba;ad=null;kw=recipes;kw=food;kw=views;kw=Golden-Pan-Fried-Fish-350404;sz=300x250;t
Status: Hidden

Object: C:\Windows.old\Users\David\AppData\Local\Application Data\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\2FGHYXL1\JCAWKDMF8CAVLU2W7CA4F9QLRCAT54UYVCAAJVV7RCAJZP5QNCA1E24M0CALB0WGNCABZJNIQCA5CSX85CA1TAEFRCALPQNNUCAF4QRBDCA4OHAV8CAXMQ0TWCA1DEKRE
Status: Hidden

Object: C:\Windows.old\Users\David\AppData\Local\Application Data\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\2FGHYXL1\KCA4FYBAJCA5UP3QECACH4L3JCARJVG1CCATRUDN2CAOF4TKCCAE65QZ1CAN86A3FCAUDHE8CCAFT9IGOCAEQLVALCAJK33KYCA2JUEEMCAYNL4B2CAJUEOIUCALKC9FI
Status: Hidden

Object: C:\Windows.old\Users\David\AppData\Local\Application Data\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\2FGHYXL1\KVCA1L7XX9CAH8WG5CCAOXBMIECAORF1X7CA2VJA88CA6X2YE7CATCDGT0CA9Q951ACABL2WRYCA4R1Q0NCAGWAO0CCAMERFY5CAX2OM06CAHXZ0OKCA86GV91CAG6URG
Status: Hidden

Object: C:\Windows.old\Users\David\AppData\Local\Application Data\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\2FGHYXL1\n;kw=Casual+Entertaining;kw=Entertaining;kw=ba;ad=null;kw=recipes;kw=food;kw=reviews;kw=Golden-Pan-Fried-Fish-350404;sz=300x250;t
Status: Hidden

Object: C:\Windows.old\Users\David\AppData\Local\Application Data\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\2FGHYXL1\nion;kw=Casual+Entertaining;kw=Entertaining;kw=ba;ad=null;kw=recipes;kw=food;kw=views;kw=Golden-Pan-Fried-Fish-350404;sz=300x250;
Status: Hidden

Object: C:\Windows.old\Users\David\AppData\Local\Application Data\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\2FGHYXL1\OCAOJBG13CA3GWA9QCAQXUSJWCA8OWVH9CA07UUGTCAQ0IKYBCAOI5MV3CAV5DI2KCA2X5FD7CAM1HFRYCAIKZGGFCAF92KHTCAGTMUIMCAYJ2QKECAQ0VZMJCABYI02B
Status: Hidden

Object: C:\Windows.old\Users\David\AppData\Local\Application Data\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\2FGHYXL1\RCAYB4IK8CAFXUF5XCATJ0E9TCAPGE56OCAAMEYJICAAAPXIICAU4ZY7NCA189A0ECAMXBOOQCAURUYWLCAVJO2VECAXF4B6YCAT6ZSVPCANIY80CCA8U9M63CANGAAQJ
Status: Hidden

Object: C:\Windows.old\Users\David\AppData\Local\Application Data\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\2FGHYXL1\TCA3E0CB3CA1T4MTPCA5LQYY3CAZA82AYCAL81140CAGHO5VQCAA5TUUOCALA6KXLCAT5PJ0HCASR432BCA2ZMFJUCAX4YUCVCA04SF5MCAC2FR3JCA9HYJ0LCAEDUVQF
Status: Hidden

Object: C:\Windows.old\Users\David\AppData\Local\Application Data\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\2FGHYXL1\TWCA1U9G3UCAI14932CA2RZXAACA1PZEF8CA37CM45CACI1MQYCABNQ2OVCALHYH05CAKY9EN4CA8043N1CAO77QG4CAS20PZPCA2U2ZS2CAUPC6C4CA50PU53CA4H04E
Status: Hidden

Object: C:\Windows.old\Users\David\AppData\Local\Application Data\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\2FGHYXL1\union;kw=Casual+Entertaining;kw=Entertaining;kw=ba;ad=null;kw=recipes;kw=food;kw=views;kw=Golden-Pan-Fried-Fish-350404;sz=120x60;
Status: Hidden

Object: C:\Windows.old\Users\David\AppData\Local\Application Data\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\2FGHYXL1\UYCALSQZVUCA32SBR5CAVKEPYWCA1I4NOBCA33X8V1CAG6X6ZMCA329YJTCAGB7FUHCAS1EE6YCA3OS2I3CACYBD4ECA2CSMKECAU1TOV9CACS5RJVCAW548U5CAYKDMF
Status: Hidden

Object: C:\Windows.old\Users\David\AppData\Local\Application Data\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\2FGHYXL1\VCADNOPF9CAL5TS23CAB772IGCACWQLWRCAE8HTR3CAMTJALHCAWRX03XCA8SP1Y9CA03IUMACAQF66MBCA87NWV1CAIE37FMCA75J9QCCAQC730JCARZIUYVCA6S6LKY
Status: Hidden

Object: C:\Windows.old\Users\David\AppData\Local\Application Data\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\2FGHYXL1\WCA4BLYUJCA13E70ACA9Z71IGCA393YI7CA7WWR4LCAB96CQ6CAHPXZDVCA78RJB3CARBMCROCA5U3MPPCA49GX83CAEQ3UFKCAF8QT4WCARASW3MCALQB6J9CAO09S21
Status: Hidden

Object: C:\Windows.old\Users\David\AppData\Local\Application Data\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\2FGHYXL1\WCACK2MR3CANWF49NCAB8Y7WECA11YH7NCADIE85YCAM3UWSNCAS3EF5TCAOFDHOLCAE59K8SCAEN7D8YCA5U8PLACA7GHDYVCA5YZ6ZUCA5BGUKNCAH6OC1BCAJI0SG1
Status: Hidden

Object: C:\Windows.old\Users\David\AppData\Local\Application Data\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\2FGHYXL1\YCAKKM5HOCASZK6CSCAHFLUH9CAYIHI1MCASZAGU0CADL8FDUCA8L32YWCARQTULHCAV1M0PNCAUNXUFZCAQFZ2Y7CAX39E64CADXGLUBCAE0WLTOCAH8UF0ACA52G18Q
Status: Hidden

Object: C:\Windows.old\Users\David\AppData\Local\Application Data\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\2FGHYXL1\YCAOWFFUWCAHAAETTCAQOVIEFCADEXS4YCAM6CGL1CAYV16ZWCAE0DK64CA1W17RJCA8234C4CA0SJ32NCAK8P88TCADMOFF7CAAA9V6PCAWGKR71CARB94Z4CAKNW22J
Status: Hidden

Object: C:\Windows.old\Users\David\AppData\Local\Application Data\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\2FGHYXL1\ZCATKFGQFCAYFVMJDCAM8ESTTCAVC1QV2CAWGR0JRCA3VMTKDCA7L2ID1CA9E6R3KCA6INB6UCA6GXMN0CAYP1714CAFU63L5CAJMSSPBCA4AE0F9CAWSQFC9CA1LOCOQ
Status: Hidden

Object: C:\Windows.old\Users\David\AppData\Local\Application Data\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\5GXUDIYO\0CALBQJ5SCA38S9YACA9VXE8YCAMZW9R7CAQKAVAECAQA5RZICAW1PMN8CAGFIYEBCA73EO07CA6PSHJ7CA7U971TCA2AM06PCAZNC5GDCA06CF1QCAA2EGDOCA7H9K3N
Status: Hidden

Object: C:\Windows.old\Users\David\AppData\Local\Application Data\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\5GXUDIYO\4CAR31WQDCAHM5W4CCAAYR3FKCAZ0ZD1JCASHJ0DVCAYHA2LHCA51V290CA1TSTF4CAAAK1BNCAXQ6RXZCAY84P2ICAUPXM04CAIYI5LPCAOTU3R5CA9JK7M0CASUGTL3
Status: Hidden

Object: C:\Windows.old\Users\David\AppData\Local\Application Data\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\5GXUDIYO\5CA3Z0N5MCAC543QJCAYMWU62CAFN68ACCAHPB999CAXXE851CAVLMDYECAU5M0ATCA5J7K9UCAGH99ZXCAB4XR51CAAJFNRZCA0YYMV8CAS9RRKBCA65GCL6CAB65RR2
Status: Hidden

Object: C:\Windows.old\Users\David\AppData\Local\Application Data\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\5GXUDIYO\7KCA7138X0CAUUA6K0CAJAPX2BCAVUSABRCA9V1VU5CABSJQSPCAPO0MILCANF6MFACAWH8KYHCA3V7XCVCABRDF4WCASK7B8ACA6O762GCA45WA80CAEIXURLCAYFHST
Status: Hidden
dcowie
Regular Member
 
Posts: 23
Joined: January 24th, 2010, 9:54 am
Advertisement
Register to Remove

Next

  • Similar Topics
    Replies
    Views
    Last post

Return to Infected? Virus, malware, adware, ransomware, oh my!



Who is online

Users browsing this forum: No registered users and 544 guests

Contact us:

Advertisements do not imply our endorsement of that product or service. Register to remove all ads. The forum is run by volunteers who donate their time and expertise. We make every attempt to ensure that the help and advice posted is accurate and will not cause harm to your computer. However, we do not guarantee that they are accurate and they are to be used at your own risk. All trademarks are the property of their respective owners.

Member site: UNITE Against Malware