Welcome to MalwareRemoval.com,
What if we told you that you could get malware removal help from experts, and that it was 100% free? MalwareRemoval.com provides free support for people with infected computers. Our help, and the tools we use are always 100% free. No hidden catch. We simply enjoy helping others. You enjoy a clean, safe computer.

Malware Removal Instructions

Google/Bing redirect error - please help

MalwareRemoval.com provides free support for people with infected computers. Using plain language that anyone can understand, our community of volunteer experts will walk you through each step.

Google/Bing redirect error - please help

Unread postby jkwings » June 29th, 2010, 8:02 pm

I'm having the same problem that it looks like many others are having. When I do a Google search or a Bing search and click on one of the links it often redirects me to two or three seemingly random sites. Often these sites have a cursive Q or green globe logo by the URL. I would greatly appreciate any help with this issue as it's incredibly frustrating. Thanks very much!

Hijackthis log:
Logfile of Trend Micro HijackThis v2.0.4
Scan saved at 7:55:34 PM, on 6/29/2010
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\csrss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Intel\Wireless\Bin\EvtEng.exe
C:\Program Files\Intel\Wireless\Bin\S24EvMon.exe
C:\Program Files\Intel\Wireless\Bin\WLKeeper.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
C:\Program Files\Bonjour\mDNSResponder.exe
C:\PROGRA~1\McAfee\MSC\mcmscsvc.exe
c:\program files\common files\mcafee\mna\mcnasvc.exe
c:\PROGRA~1\COMMON~1\mcafee\mcproxy\mcproxy.exe
C:\Program Files\McAfee\MPF\MPFSrv.exe
C:\Program Files\McAfee\MSK\MskSrver.exe
C:\Program Files\Intel\Wireless\Bin\RegSrvc.exe
C:\WINDOWS\system32\svchost.exe
c:\PROGRA~1\mcafee.com\agent\mcagent.exe
C:\WINDOWS\System32\alg.exe
C:\WINDOWS\system32\wbem\wmiprvse.exe
C:\Program Files\Intel\Wireless\bin\ZCfgSvc.exe
C:\Program Files\Intel\Wireless\Bin\ifrmewrk.exe
C:\WINDOWS\stsystra.exe
C:\Program Files\Dell\QuickSet\quickset.exe
C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
C:\Program Files\ATI Technologies\ATI.ACE\cli.exe
C:\WINDOWS\system32\dla\tfswctrl.exe
C:\Program Files\Common Files\InstallShield\UpdateService\issch.exe
C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe
C:\Program Files\Dell\MediaDirect\PCMService.exe
C:\Program Files\HP\HP Software Update\HPWuSchd2.exe
C:\WINDOWS\V0510Mon.exe
C:\Program Files\iTunes\iTunesHelper.exe
C:\Program Files\NetWaiting\netWaiting.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Dell Support\DSAgnt.exe
C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
C:\Program Files\Digital Line Detect\DLG.exe
C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe
C:\Program Files\Google\Google Desktop Search\GoogleDesktopIndex.exe
C:\Program Files\Google\Google Desktop Search\GoogleDesktopDisplay.exe
C:\Program Files\HP\Digital Imaging\bin\hpqimzone.exe
C:\Program Files\iPod\bin\iPodService.exe
C:\Program Files\ATI Technologies\ATI.ACE\cli.exe
C:\Program Files\HP\Digital Imaging\bin\hpqSTE08.exe
C:\WINDOWS\system32\wuauclt.exe
C:\PROGRA~1\McAfee\VIRUSS~1\mcsysmon.exe
C:\Program Files\Spyware Doctor\BDT\BDTUpdateService.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\Program Files\Mozilla Firefox\plugin-container.exe
C:\Program Files\Java\jre6\bin\jqs.exe
C:\WINDOWS\explorer.exe
C:\Program Files\Carbonite\Carbonite Backup\CarboniteUI.exe
C:\Program Files\Carbonite\Carbonite Backup\carboniteservice.exe
C:\WINDOWS\System32\vssvc.exe
C:\WINDOWS\system32\dllhost.exe
C:\WINDOWS\system32\dllhost.exe
C:\WINDOWS\system32\msdtc.exe
C:\Program Files\Uniblue\RegistryBooster\registrybooster.exe
C:\PROGRA~1\McAfee\VIRUSS~1\mcshield.exe
c:\PROGRA~1\mcafee\msc\mcshell.exe
C:\PROGRA~1\McAfee\VIRUSS~1\mcods.exe
C:\WINDOWS\system32\msiexec.exe
C:\WINDOWS\system32\NOTEPAD.EXE
C:\Program Files\Trend Micro\HiJackThis\HiJackThis.exe
C:\WINDOWS\system32\wbem\wmiprvse.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = www.google.com/ig/dell?hl=en&client=del ... bd=0070602
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.comcast.net/
R1 - HKLM\Software\Microsoft\Internet Explorer\Search,Default_Page_URL = www.google.com/ig/dell?hl=en&client=del ... bd=0070602
R1 - HKCU\Software\Microsoft\Internet Connection Wizard,ShellNext = http://www.comcast.net/
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Window Title = Windows Internet Explorer provided by Comcast
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyServer = :0
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = *.local
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
O2 - BHO: McAfee Phishing Filter - {27B4851A-3207-45A2-B947-BE8AFE6163AB} - c:\PROGRA~1\mcafee\msk\mskapbho.dll
O2 - BHO: Browser Defender BHO - {2A0F3D1B-0909-4FF4-B272-609CCE6054E7} - C:\Program Files\Spyware Doctor\BDT\PCTBrowserDefender.dll
O2 - BHO: DriveLetterAccess - {5CA3D70E-1895-11CF-8E15-001234567890} - C:\WINDOWS\system32\dla\tfswshx.dll
O2 - BHO: scriptproxy - {7DB2D5A0-7241-4E79-B68D-6309F01C5231} - C:\Program Files\McAfee\VirusScan\scriptsn.dll
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - C:\Program Files\Google\Google Toolbar\GoogleToolbar_32.dll
O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\5.5.5126.1836\swg.dll
O2 - BHO: Browser Address Error Redirector - {CA6319C0-31B7-401E-A518-A07C3DB8F777} - C:\Program Files\BAE\BAE.dll
O2 - BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll
O2 - BHO: JQSIEStartDetectorImpl - {E7E6F031-17CE-4C07-BC86-EABFE594F69C} - C:\Program Files\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll
O3 - Toolbar: Google Toolbar - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - C:\Program Files\Google\Google Toolbar\GoogleToolbar_32.dll
O3 - Toolbar: PC Tools Browser Guard - {472734EA-242A-422B-ADF8-83D1E48CC825} - C:\Program Files\Spyware Doctor\BDT\PCTBrowserDefender.dll
O4 - HKLM\..\Run: [IntelZeroConfig] "C:\Program Files\Intel\Wireless\bin\ZCfgSvc.exe"
O4 - HKLM\..\Run: [IntelWireless] "C:\Program Files\Intel\Wireless\Bin\ifrmewrk.exe" /tf Intel PROSet/Wireless
O4 - HKLM\..\Run: [SigmatelSysTrayApp] stsystra.exe
O4 - HKLM\..\Run: [Dell QuickSet] C:\Program Files\Dell\QuickSet\quickset.exe
O4 - HKLM\..\Run: [SynTPEnh] C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
O4 - HKLM\..\Run: [ATICCC] "C:\Program Files\ATI Technologies\ATI.ACE\cli.exe" runtime -Delay
O4 - HKLM\..\Run: [dla] C:\WINDOWS\system32\dla\tfswctrl.exe
O4 - HKLM\..\Run: [ISUSPM Startup] C:\PROGRA~1\COMMON~1\INSTAL~1\UPDATE~1\ISUSPM.exe -startup
O4 - HKLM\..\Run: [ISUSScheduler] "C:\Program Files\Common Files\InstallShield\UpdateService\issch.exe" -start
O4 - HKLM\..\Run: [Google Desktop Search] "C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe" /startup
O4 - HKLM\..\Run: [PCMService] "C:\Program Files\Dell\MediaDirect\PCMService.exe"
O4 - HKLM\..\Run: [HP Software Update] C:\Program Files\HP\HP Software Update\HPWuSchd2.exe
O4 - HKLM\..\Run: [mcagent_exe] "C:\Program Files\McAfee.com\Agent\mcagent.exe" /runkey
O4 - HKLM\..\Run: [V0510Mon.exe] C:\WINDOWS\V0510Mon.exe
O4 - HKLM\..\Run: [KernelFaultCheck] %systemroot%\system32\dumprep 0 -k
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Common Files\Java\Java Update\jusched.exe"
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
O4 - HKLM\..\Run: [Carbonite Backup] C:\Program Files\Carbonite\Carbonite Backup\CarboniteUI.exe
O4 - HKLM\..\Run: [Malwarebytes Anti-Malware (reboot)] "C:\Program Files\Malwarebytes' Anti-Malware\mbam.exe" /runcleanupscript
O4 - HKLM\..\RunOnce: [Malwarebytes' Anti-Malware] C:\Program Files\Malwarebytes' Anti-Malware\mbamgui.exe /install /silent
O4 - HKCU\..\Run: [ModemOnHold] C:\Program Files\NetWaiting\netWaiting.exe
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [DellSupport] "C:\Program Files\Dell Support\DSAgnt.exe" /startup
O4 - HKCU\..\Run: [swg] "C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe"
O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
O4 - HKCU\..\RunOnce: [RegistryBooster] "C:\Program Files\Uniblue\RegistryBooster\launcher.exe" delay 20000
O4 - Global Startup: Adobe Reader Speed Launch.lnk = C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
O4 - Global Startup: Digital Line Detect.lnk = ?
O4 - Global Startup: HP Digital Imaging Monitor.lnk = C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe
O4 - Global Startup: HP Photosmart Premier Fast Start.lnk = C:\Program Files\HP\Digital Imaging\bin\hpqthb08.exe
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office12\EXCEL.EXE/3000
O8 - Extra context menu item: Google Sidewiki... - res://C:\Program Files\Google\Google Toolbar\Component\GoogleToolbarDynamic_mui_en_2EC7709873947E87.dll/cmsidewiki.html
O9 - Extra button: Send to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~2\Office12\ONBttnIE.dll
O9 - Extra 'Tools' menuitem: S&end to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~2\Office12\ONBttnIE.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\Office12\REFIEBAR.DLL
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O16 - DPF: {0CCA191D-13A6-4E29-B746-314DEE697D83} (Facebook Photo Uploader 5 Control) - http://upload.facebook.com/controls/200 ... oader5.cab
O16 - DPF: {4CCA4E80-9259-11D9-AC6E-444553544200} (FixController Control) - http://h30155.www3.hp.com/ediags/dd/ins ... _v01_5.cab
O16 - DPF: {5F8469B4-B055-49DD-83F7-62B522420ECC} (Facebook Photo Uploader Control) - http://upload.facebook.com/controls/Fac ... loader.cab
O16 - DPF: {6F750202-1362-4815-A476-88533DE61D0C} (Kodak Gallery Easy Upload Manager Class) - http://www.kodakgallery.com/downloads/B ... ofupld.cab
O16 - DPF: {AE6C4705-0F11-4ACB-BDD4-37F138BEF289} (Image Uploader Control) - http://meijer.lifepics.com/net/Uploader ... ader41.cab
O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~1\COMMON~1\Skype\SKYPE4~1.DLL
O20 - AppInit_DLLs: C:\PROGRA~1\Google\GOOGLE~1\GOEC62~1.DLL
O22 - SharedTaskScheduler: Browseui preloader - {438755C2-A8BA-11D1-B96B-00A0C90312E1} - C:\WINDOWS\system32\browseui.dll
O22 - SharedTaskScheduler: Component Categories cache daemon - {8C7461EF-2B13-11d2-BE35-3078302C2030} - C:\WINDOWS\system32\browseui.dll
O23 - Service: Apple Mobile Device - Apple Inc. - C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
O23 - Service: Ati HotKey Poller - ATI Technologies Inc. - C:\WINDOWS\system32\Ati2evxx.exe
O23 - Service: Bonjour Service - Apple Inc. - C:\Program Files\Bonjour\mDNSResponder.exe
O23 - Service: Browser Defender Update Service - Unknown owner - C:\Program Files\Spyware Doctor\BDT\BDTUpdateService.exe
O23 - Service: CarboniteService - Carbonite, Inc. (www.carbonite.com) - C:\Program Files\Carbonite\Carbonite Backup\carboniteservice.exe
O23 - Service: Intel(R) PROSet/Wireless Event Log (EvtEng) - Intel Corporation - C:\Program Files\Intel\Wireless\Bin\EvtEng.exe
O23 - Service: Google Update Service (gupdate) (gupdate) - Google Inc. - C:\Program Files\Google\Update\GoogleUpdate.exe
O23 - Service: Google Software Updater (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\1050\Intel 32\IDriverT.exe
O23 - Service: iPod Service - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: Java Quick Starter (JavaQuickStarterService) - Sun Microsystems, Inc. - C:\Program Files\Java\jre6\bin\jqs.exe
O23 - Service: McAfee Services (mcmscsvc) - McAfee, Inc. - C:\PROGRA~1\McAfee\MSC\mcmscsvc.exe
O23 - Service: McAfee Network Agent (McNASvc) - McAfee, Inc. - c:\program files\common files\mcafee\mna\mcnasvc.exe
O23 - Service: McAfee Scanner (McODS) - McAfee, Inc. - C:\PROGRA~1\McAfee\VIRUSS~1\mcods.exe
O23 - Service: McAfee Proxy Service (McProxy) - McAfee, Inc. - c:\PROGRA~1\COMMON~1\mcafee\mcproxy\mcproxy.exe
O23 - Service: McAfee Real-time Scanner (McShield) - McAfee, Inc. - C:\PROGRA~1\McAfee\VIRUSS~1\mcshield.exe
O23 - Service: McAfee SystemGuards (McSysmon) - McAfee, Inc. - C:\PROGRA~1\McAfee\VIRUSS~1\mcsysmon.exe
O23 - Service: McAfee Personal Firewall Service (MpfService) - McAfee, Inc. - C:\Program Files\McAfee\MPF\MPFSrv.exe
O23 - Service: McAfee SpamKiller Service (MSK80Service) - McAfee, Inc. - C:\Program Files\McAfee\MSK\MskSrver.exe
O23 - Service: Intel(R) PROSet/Wireless Registry Service (RegSrvc) - Intel Corporation - C:\Program Files\Intel\Wireless\Bin\RegSrvc.exe
O23 - Service: Intel(R) PROSet/Wireless Service (S24EventMonitor) - Intel Corporation - C:\Program Files\Intel\Wireless\Bin\S24EvMon.exe
O23 - Service: PC Tools Auxiliary Service (sdAuxService) - PC Tools - C:\Program Files\Spyware Doctor\pctsAuxs.exe
O23 - Service: PC Tools Security Service (sdCoreService) - PC Tools - C:\Program Files\Spyware Doctor\pctsSvc.exe
O23 - Service: Intel(R) PROSet/Wireless SSO Service (WLANKEEPER) - Intel(R) Corporation - C:\Program Files\Intel\Wireless\Bin\WLKeeper.exe

Uninstall list:
Uninstall List
100% Free Euchre 7.12
Across Lite 2.0
Adobe Flash Player 10 ActiveX
Adobe Reader 7.1.0
Adobe Shockwave Player 11
Advanced Video FX Engine
Amazon MP3 Downloader 1.0.3
Apple Application Support
Apple Mobile Device Support
Apple Software Update
ATI Catalyst Control Center
ATI Display Driver
Bonjour
Broadcom Management Programs
Browser Defender 2.0.6.15
BUM
Carbonite
CCleaner (remove only)
Championship Euchre All-Stars 7.16
Comcast High-Speed Internet Install Wizard
Conexant HDA D110 MDC V.92 Modem
Critical Update for Windows Media Player 11 (KB959772)
Data Lifeguard Diagnostic for Windows 1.21
DeductionPro 2007
Dell Support 3.2.1
Desktop Doctor
Digital Line Detect
DivX Content Uploader
DivX Web Player
Documentation & Support Launcher
Euchre Baron
Euchre Challenge - Teacher (remove only)
Games, Music, & Photos Launcher
Garmin Communicator Plugin
Garmin USB Drivers
Google Desktop
Google Toolbar for Internet Explorer
Google Toolbar for Internet Explorer
Google Update Helper
H&R Block Deluxe + Efile + State 2009
H&R Block Michigan 2009
High Definition Audio Driver Package - KB835221
HiJackThis
Hotfix for Microsoft .NET Framework 3.5 SP1 (KB953595)
Hotfix for Microsoft .NET Framework 3.5 SP1 (KB958484)
Hotfix for Windows Media Format 11 SDK (KB929399)
Hotfix for Windows Media Player 11 (KB939683)
Hotfix for Windows XP (KB926239)
Hotfix for Windows XP (KB952287)
Hotfix for Windows XP (KB961118)
Hotfix for Windows XP (KB970653-v3)
Hotfix for Windows XP (KB976098-v2)
Hotfix for Windows XP (KB979306)
Hotfix for Windows XP (KB981793)
HP Customer Participation Program 7.0
HP Document Viewer 7.0
HP Driver Diagnostics
HP Imaging Device Functions 7.0
HP Photosmart Premier Software 6.5
HP Photosmart, Officejet and Deskjet 7.0.A
HP Software Update
HP Solution Center 7.0
Impulse
Impulse
Intel(R) PROSet/Wireless Software
Internet Service Offers Launcher
iTunes
J2SE Runtime Environment 5.0 Update 6
Java(TM) 6 Update 20
Malwarebytes' Anti-Malware
McAfee SecurityCenter
mCore
mDrWiFi
MediaDirect
mHlpDell
Microsoft .NET Framework 1.1
Microsoft .NET Framework 1.1
Microsoft .NET Framework 1.1 Security Update (KB979906)
Microsoft .NET Framework 2.0 Service Pack 2
Microsoft .NET Framework 3.0 Service Pack 2
Microsoft .NET Framework 3.5 SP1
Microsoft .NET Framework 3.5 SP1
Microsoft Compression Client Pack 1.0 for Windows XP
Microsoft Office 2007 Service Pack 2 (SP2)
Microsoft Office 2007 Service Pack 2 (SP2)
Microsoft Office 2007 Service Pack 2 (SP2)
Microsoft Office 2007 Service Pack 2 (SP2)
Microsoft Office 2007 Service Pack 2 (SP2)
Microsoft Office 2007 Service Pack 2 (SP2)
Microsoft Office 2007 Service Pack 2 (SP2)
Microsoft Office Excel MUI (English) 2007
Microsoft Office Home and Student 2007
Microsoft Office Home and Student 2007
Microsoft Office OneNote MUI (English) 2007
Microsoft Office PowerPoint MUI (English) 2007
Microsoft Office Proof (English) 2007
Microsoft Office Proof (French) 2007
Microsoft Office Proof (Spanish) 2007
Microsoft Office Proofing (English) 2007
Microsoft Office Proofing Tools 2007 Service Pack 2 (SP2)
Microsoft Office Proofing Tools 2007 Service Pack 2 (SP2)
Microsoft Office Proofing Tools 2007 Service Pack 2 (SP2)
Microsoft Office Shared MUI (English) 2007
Microsoft Office Shared Setup Metadata MUI (English) 2007
Microsoft Office Word MUI (English) 2007
Microsoft Plus! Digital Media Edition Installer
Microsoft Plus! Photo Story 2 LE
Microsoft Silverlight
Microsoft User-Mode Driver Framework Feature Pack 1.0
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17
mIWA
mLogView
mMHouse
Modem Helper
Mozilla Firefox (3.6.6)
mPfMgr
mPfWiz
mProSafe
mSSO
MSXML 4.0 SP2 (KB927978)
MSXML 4.0 SP2 (KB936181)
MSXML 4.0 SP2 (KB954430)
MSXML 4.0 SP2 (KB973688)
MSXML 6 Service Pack 2 (KB973686)
Musicmatch for Windows Media Player
mWlsSafe
mWMI
mXML
mZConfig
Netflix Movie Viewer
NetWaiting
OCR Software by I.R.I.S 7.0
OutlookAddinSetup
Pdf995 (installed by TaxCut)
PdfEdit995 (installed by TaxCut)
QuickSet
QuickTime
Rocketfish 2MP AF Webcam Driver (1.00.06.00)
Rocketfish Live! Cam Center
Rocketfish Webcam User's Guide
SearchAssist
Security Update for 2007 Microsoft Office System (KB969559)
Security Update for 2007 Microsoft Office System (KB976321)
Security Update for 2007 Microsoft Office System (KB982312)
Security Update for 2007 Microsoft Office System (KB982331)
Security Update for Microsoft Office Excel 2007 (KB982308)
Security Update for Microsoft Office InfoPath 2007 (KB979441)
Security Update for Microsoft Office PowerPoint 2007 (KB982158)
Security Update for Microsoft Office system 2007 (972581)
Security Update for Microsoft Office system 2007 (KB969613)
Security Update for Microsoft Office system 2007 (KB974234)
Security Update for Microsoft Office Visio Viewer 2007 (KB973709)
Security Update for Microsoft Office Word 2007 (KB982135)
Security Update for Step By Step Interactive Training (KB923723)
Security Update for Windows Media Player (KB952069)
Security Update for Windows Media Player (KB954155)
Security Update for Windows Media Player (KB968816)
Security Update for Windows Media Player (KB973540)
Security Update for Windows Media Player (KB978695)
Security Update for Windows Media Player 10 (KB917734)
Security Update for Windows Media Player 10 (KB936782)
Security Update for Windows Media Player 11 (KB936782)
Security Update for Windows Media Player 11 (KB954154)
Security Update for Windows XP (KB893756)
Security Update for Windows XP (KB896428)
Security Update for Windows XP (KB899587)
Security Update for Windows XP (KB900725)
Security Update for Windows XP (KB901017)
Security Update for Windows XP (KB902400)
Security Update for Windows XP (KB905414)
Security Update for Windows XP (KB905749)
Security Update for Windows XP (KB911927)
Security Update for Windows XP (KB913580)
Security Update for Windows XP (KB914389)
Security Update for Windows XP (KB917953)
Security Update for Windows XP (KB921503)
Security Update for Windows XP (KB922819)
Security Update for Windows XP (KB923561)
Security Update for Windows XP (KB923789)
Security Update for Windows XP (KB923980)
Security Update for Windows XP (KB925902)
Security Update for Windows XP (KB927779)
Security Update for Windows XP (KB928090)
Security Update for Windows XP (KB929123)
Security Update for Windows XP (KB930178)
Security Update for Windows XP (KB931261)
Security Update for Windows XP (KB931768)
Security Update for Windows XP (KB931784)
Security Update for Windows XP (KB932168)
Security Update for Windows XP (KB933566)
Security Update for Windows XP (KB933729)
Security Update for Windows XP (KB935839)
Security Update for Windows XP (KB935840)
Security Update for Windows XP (KB936021)
Security Update for Windows XP (KB937143)
Security Update for Windows XP (KB938127)
Security Update for Windows XP (KB938464)
Security Update for Windows XP (KB938829)
Security Update for Windows XP (KB939653)
Security Update for Windows XP (KB941202)
Security Update for Windows XP (KB941568)
Security Update for Windows XP (KB941569)
Security Update for Windows XP (KB941644)
Security Update for Windows XP (KB941693)
Security Update for Windows XP (KB942615)
Security Update for Windows XP (KB943055)
Security Update for Windows XP (KB943460)
Security Update for Windows XP (KB943485)
Security Update for Windows XP (KB944338)
Security Update for Windows XP (KB944533)
Security Update for Windows XP (KB944653)
Security Update for Windows XP (KB945553)
Security Update for Windows XP (KB946026)
Security Update for Windows XP (KB946648)
Security Update for Windows XP (KB947864)
Security Update for Windows XP (KB948590)
Security Update for Windows XP (KB948881)
Security Update for Windows XP (KB950749)
Security Update for Windows XP (KB950759)
Security Update for Windows XP (KB950760)
Security Update for Windows XP (KB950762)
Security Update for Windows XP (KB950974)
Security Update for Windows XP (KB951066)
Security Update for Windows XP (KB951376)
Security Update for Windows XP (KB951376-v2)
Security Update for Windows XP (KB951698)
Security Update for Windows XP (KB951748)
Security Update for Windows XP (KB952004)
Security Update for Windows XP (KB952954)
Security Update for Windows XP (KB953838)
Security Update for Windows XP (KB953839)
Security Update for Windows XP (KB954211)
Security Update for Windows XP (KB954600)
Security Update for Windows XP (KB955069)
Security Update for Windows XP (KB956390)
Security Update for Windows XP (KB956391)
Security Update for Windows XP (KB956572)
Security Update for Windows XP (KB956802)
Security Update for Windows XP (KB956803)
Security Update for Windows XP (KB956841)
Security Update for Windows XP (KB956844)
Security Update for Windows XP (KB957095)
Security Update for Windows XP (KB957097)
Security Update for Windows XP (KB958215)
Security Update for Windows XP (KB958470)
Security Update for Windows XP (KB958644)
Security Update for Windows XP (KB958687)
Security Update for Windows XP (KB958690)
Security Update for Windows XP (KB958869)
Security Update for Windows XP (KB959426)
Security Update for Windows XP (KB960225)
Security Update for Windows XP (KB960714)
Security Update for Windows XP (KB960715)
Security Update for Windows XP (KB960803)
Security Update for Windows XP (KB960859)
Security Update for Windows XP (KB961371)
Security Update for Windows XP (KB961373)
Security Update for Windows XP (KB961501)
Security Update for Windows XP (KB963027)
Security Update for Windows XP (KB968537)
Security Update for Windows XP (KB969059)
Security Update for Windows XP (KB969897)
Security Update for Windows XP (KB969898)
Security Update for Windows XP (KB969947)
Security Update for Windows XP (KB970238)
Security Update for Windows XP (KB970430)
Security Update for Windows XP (KB971468)
Security Update for Windows XP (KB971486)
Security Update for Windows XP (KB971557)
Security Update for Windows XP (KB971633)
Security Update for Windows XP (KB971657)
Security Update for Windows XP (KB971961)
Security Update for Windows XP (KB972260)
Security Update for Windows XP (KB972270)
Security Update for Windows XP (KB973346)
Security Update for Windows XP (KB973354)
Security Update for Windows XP (KB973507)
Security Update for Windows XP (KB973525)
Security Update for Windows XP (KB973869)
Security Update for Windows XP (KB973904)
Security Update for Windows XP (KB974112)
Security Update for Windows XP (KB974318)
Security Update for Windows XP (KB974392)
Security Update for Windows XP (KB974455)
Security Update for Windows XP (KB974571)
Security Update for Windows XP (KB975025)
Security Update for Windows XP (KB975467)
Security Update for Windows XP (KB975560)
Security Update for Windows XP (KB975561)
Security Update for Windows XP (KB975562)
Security Update for Windows XP (KB976325)
Security Update for Windows XP (KB977165)
Security Update for Windows XP (KB977816)
Security Update for Windows XP (KB977914)
Security Update for Windows XP (KB978037)
Security Update for Windows XP (KB978251)
Security Update for Windows XP (KB978262)
Security Update for Windows XP (KB978338)
Security Update for Windows XP (KB978542)
Security Update for Windows XP (KB978601)
Security Update for Windows XP (KB978706)
Security Update for Windows XP (KB979309)
Security Update for Windows XP (KB979482)
Security Update for Windows XP (KB979559)
Security Update for Windows XP (KB979683)
Security Update for Windows XP (KB980195)
Security Update for Windows XP (KB980218)
Security Update for Windows XP (KB980232)
Security Update for Windows XP (KB981350)
Security Update for Windows XP (KB982381)
Skype™ 3.8
Snood 4
Sonic DLA
Sonic RecordNow Audio
Sonic RecordNow Copy
Sonic RecordNow Data
Sonic Update Manager
Spyware Doctor 7.0
Synaptics Pointing Device Driver
System Requirements Lab
System Requirements Lab
TaxCut Michigan 2007
TaxCut Michigan 2008
TaxCut Premium + State + Efile 2007
TaxCut Premium + State + Efile 2008
TBS WMP Plug-in
TeamViewer 5
Uniblue RegistryBooster
Update for 2007 Microsoft Office System (KB967642)
Update for Microsoft .NET Framework 3.5 SP1 (KB963707)
Update for Microsoft Office OneNote 2007 (KB980729)
Update for Windows XP (KB894391)
Update for Windows XP (KB898461)
Update for Windows XP (KB900485)
Update for Windows XP (KB910437)
Update for Windows XP (KB911280)
Update for Windows XP (KB916595)
Update for Windows XP (KB920872)
Update for Windows XP (KB922582)
Update for Windows XP (KB925720)
Update for Windows XP (KB927891)
Update for Windows XP (KB930916)
Update for Windows XP (KB933360)
Update for Windows XP (KB936357)
Update for Windows XP (KB938828)
Update for Windows XP (KB942763)
Update for Windows XP (KB942840)
Update for Windows XP (KB946627)
Update for Windows XP (KB951072-v2)
Update for Windows XP (KB955759)
Update for Windows XP (KB955839)
Update for Windows XP (KB967715)
Update for Windows XP (KB968389)
Update for Windows XP (KB971737)
Update for Windows XP (KB973687)
Update for Windows XP (KB973815)
Update for Windows XP (KB976749)
Update for Windows XP (KB978207)
Update for Windows XP (KB980182)
URL Assistant
Windows Driver Package - Garmin (grmnusb) GARMIN Devices (06/03/2009 2.3.0.0)
Windows Imaging Component
Windows Media Format 11 runtime
Windows Media Format 11 runtime
Windows Media Player 10
Windows Media Player 11
Windows Media Player 11
Windows XP Hotfix - KB885836
Windows XP Hotfix - KB886185
Windows XP Hotfix - KB888302
Windows XP Hotfix - KB890859
jkwings
Active Member
 
Posts: 10
Joined: June 29th, 2010, 7:53 pm
Advertisement
Register to Remove

Re: Google/Bing redirect error - please help

Unread postby deltalima » July 2nd, 2010, 9:09 am

Hi jkwings,

Welcome to the forum.

My nickname is deltalima and I will be helping you with your computer problems.

The logs can take some time to research, so please be patient with me.

Please be aware that removing Malware is a potentially hazardous undertaking. I will take care not to knowingly suggest courses of action that might damage your computer. However it is impossible for me to foresee all interactions that may happen between the software on your computer and those we'll use to clear you of infection, and I cannot guarantee the safety of your system. It is possible that we might encounter situations where the only recourse is to re-format and re-install your operating system, or to necessitate you taking your computer to a repair shop.


Please note the following:
  • I will working be on your Malware issues, this may or may not, solve other issues you have with your machine.
  • The fixes are specific to your problem and should only be used for this issue on this machine.
  • Please continue to review my answers until I tell you your machine appears to be clear. Absence of symptoms does not mean that everything is clear.
  • If after 3 days you have not responded to this topic, it will be closed, and you will need to start a new one.
  • It's often worth reading through these instructions and printing them for ease of reference.
  • If you don't know or understand something, please don't hesitate to say or ask!! It's better to be sure and safe than sorry.
  • Please reply to this thread. Do not start a new topic.

Download and run OTL
Download OTL by Old Timer and save it to your Desktop.
  • Double click on OTL.exe to run it.
  • Under Output, ensure that Minimal Output is selected.
  • Under Extra Registry section, select Use SafeList.
  • Click the Scan All Users checkbox.
  • Click on Run Scan at the top left hand corner.
  • When done, two Notepad files will open.
    • OTL.txt <-- Will be opened
    • Extras.txt <-- Will be minimized
  • Please post the contents of these 2 Notepad files in your next reply.

Please download GMER Rootkit Scanner from here.
  • Double click the .exe file. If asked to allow gmer.sys driver to load, please consent
  • If it gives you a warning at program start about rootkit activity and asks if you want to run a scan...click NO.
  • Run Gmer again and click on the Rootkit tab.
  • Look at the right hand side (under Files) and uncheck all drives with the exception of your C drive.
  • Make sure all other boxes on the right of the screen are checked, EXCEPT for "Show All".
  • Click on the "Scan" and wait for the scan to finish.
    Note: Before scanning, make sure all other running programs are closed and no other actions like a scheduled antivirus scan will occur while this scan completes. Also do not use your computer during the scan.
  • When completed, click on the Copy button and right-click on your Desktop, choose "New" > Text document. Once the file is created, open it and right-click again and choose Paste or Ctrl+V. Save the file as gmer.txt and copy the information in your next reply.
  • Note: If you have any problems, try running GMER in SAFE MODE
Important! Please do not select the "Show all" checkbox during the scan..

Please post the GMER log along with OTL.txt and Extras.txt from the OTL scan into your next reply.
User avatar
deltalima
Admin/Teacher
Admin/Teacher
 
Posts: 7614
Joined: February 28th, 2009, 4:38 pm
Location: UK

Re: Google/Bing redirect error - please help

Unread postby jkwings » July 2nd, 2010, 3:44 pm

Thanks so much for your help. Here are the logs generated by OTL. I ran GMER and it crashed after about 5 hours so I am going to try it again in safe mode. Again, thanks very much.

OTL.txt:
OTL logfile created on: 7/2/2010 10:13:55 AM - Run 1
OTL by OldTimer - Version 3.2.7.0 Folder = C:\Documents and Settings\Jesse\Desktop
Windows XP Home Edition Service Pack 2 (Version = 5.1.2600) - Type = NTWorkstation
Internet Explorer (Version = 6.0.2900.2180)
Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy

1,022.00 Mb Total Physical Memory | 163.00 Mb Available Physical Memory | 16.00% Memory free
2.00 Gb Paging File | 1.00 Gb Available in Paging File | 59.00% Paging File free
Paging file location(s): C:\pagefile.sys 1536 3072 [binary data]

%SystemDrive% = C: | %SystemRoot% = C:\WINDOWS | %ProgramFiles% = C:\Program Files
Drive C: | 69.47 Gb Total Space | 28.87 Gb Free Space | 41.55% Space Free | Partition Type: NTFS
D: Drive not present or media not loaded
E: Drive not present or media not loaded
F: Drive not present or media not loaded
G: Drive not present or media not loaded
H: Drive not present or media not loaded
I: Drive not present or media not loaded

Computer Name: RALPH
Current User Name: Jesse
Logged in as Administrator.

Current Boot Mode: Normal
Scan Mode: All users
Company Name Whitelist: Off
Skip Microsoft Files: Off
File Age = 30 Days
Output = Minimal

========== Processes (SafeList) ==========

PRC - C:\Documents and Settings\Jesse\Desktop\OTL.exe (OldTimer Tools)
PRC - C:\Program Files\Mozilla Firefox\firefox.exe (Mozilla Corporation)
PRC - C:\Program Files\McAfee\MSC\mcmscsvc.exe (McAfee, Inc.)
PRC - C:\Program Files\Uniblue\RegistryBooster\registrybooster.exe (Uniblue Systems Limited)
PRC - C:\Program Files\Carbonite\Carbonite Backup\CarboniteService.exe (Carbonite, Inc. (www.carbonite.com))
PRC - C:\Program Files\Carbonite\Carbonite Backup\CarboniteUI.exe (Carbonite, Inc.)
PRC - C:\Program Files\Spyware Doctor\BDT\BDTUpdateService.exe (Threat Expert Ltd.)
PRC - c:\Program Files\McAfee.com\Agent\mcagent.exe (McAfee, Inc.)
PRC - C:\Program Files\McAfee\MPF\MpfSrv.exe (McAfee, Inc.)
PRC - c:\Program Files\McAfee\MSC\mcupdmgr.exe (McAfee, Inc.)
PRC - C:\Program Files\McAfee\VirusScan\Mcshield.exe (McAfee, Inc.)
PRC - C:\Program Files\McAfee\VirusScan\mcsysmon.exe (McAfee, Inc.)
PRC - C:\Program Files\McAfee\MSK\msksrver.exe (McAfee, Inc.)
PRC - c:\Program Files\Common Files\McAfee\McProxy\McProxy.exe (McAfee, Inc.)
PRC - c:\Program Files\Common Files\McAfee\MNA\McNASvc.exe (McAfee, Inc.)
PRC - C:\WINDOWS\V0510Mon.exe (Creative Technology Ltd.)
PRC - C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe (Google Inc.)
PRC - C:\WINDOWS\explorer.exe (Microsoft Corporation)
PRC - C:\Program Files\Google\Google Desktop Search\GoogleDesktopIndex.exe ()
PRC - C:\Program Files\Google\Google Desktop Search\GoogleDesktopDisplay.exe ()
PRC - C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe ()
PRC - C:\Program Files\Dell\QuickSet\quickset.exe (Dell Inc)
PRC - C:\Program Files\Intel\Wireless\Bin\EvtEng.exe (Intel Corporation)
PRC - C:\Program Files\Intel\Wireless\Bin\ZCfgSvc.exe (Intel Corporation)
PRC - C:\Program Files\Intel\Wireless\Bin\WLKEEPER.exe (Intel(R) Corporation)
PRC - C:\Program Files\Intel\Wireless\Bin\iFrmewrk.exe (Intel Corporation)
PRC - C:\Program Files\Intel\Wireless\Bin\S24EvMon.exe (Intel Corporation )
PRC - C:\Program Files\Intel\Wireless\Bin\RegSrvc.exe (Intel Corporation)
PRC - C:\Program Files\Dell Support\DSAgnt.exe (Gteko Ltd.)
PRC - C:\Program Files\Dell\MediaDirect\PCMService.exe (CyberLink Corp.)
PRC - C:\Program Files\Adobe\Acrobat 7.0\Reader\AcroRd32.exe (Adobe Systems Incorporated)
PRC - C:\WINDOWS\stsystra.exe (SigmaTel, Inc.)
PRC - C:\Program Files\HP\Digital Imaging\bin\hpqimzone.exe (Hewlett-Packard Development Company, L.P.)
PRC - C:\Program Files\ATI Technologies\ATI.ACE\CLI.exe (ATI Technologies Inc.)
PRC - C:\Program Files\Common Files\InstallShield\UpdateService\issch.exe (InstallShield Software Corporation)
PRC - C:\Program Files\Digital Line Detect\DLG.exe (BVRP Software)
PRC - C:\Program Files\NetWaiting\netwaiting.exe ()


========== Modules (SafeList) ==========

MOD - C:\Documents and Settings\Jesse\Desktop\OTL.exe (OldTimer Tools)
MOD - C:\WINDOWS\WinSxS\x86_Microsoft.Windows.Common-Controls_6595b64144ccf1df_6.0.2600.2982_x-ww_ac3f9c03\comctl32.dll (Microsoft Corporation)
MOD - C:\WINDOWS\system32\msscript.ocx (Microsoft Corporation)


========== Win32 Services (SafeList) ==========

SRV - (mcmscsvc) -- C:\Program Files\McAfee\MSC\mcmscsvc.exe (McAfee, Inc.)
SRV - (CarboniteService) -- C:\Program Files\Carbonite\Carbonite Backup\carboniteservice.exe (Carbonite, Inc. (www.carbonite.com))
SRV - (sdCoreService) -- C:\Program Files\Spyware Doctor\pctsSvc.exe (PC Tools)
SRV - (sdAuxService) -- C:\Program Files\Spyware Doctor\pctsAuxs.exe (PC Tools)
SRV - (Browser Defender Update Service) -- C:\Program Files\Spyware Doctor\BDT\BDTUpdateService.exe (Threat Expert Ltd.)
SRV - (MpfService) -- C:\Program Files\McAfee\MPF\MPFSrv.exe (McAfee, Inc.)
SRV - (McODS) -- C:\Program Files\McAfee\VirusScan\mcods.exe (McAfee, Inc.)
SRV - (McShield) -- C:\Program Files\McAfee\VirusScan\Mcshield.exe (McAfee, Inc.)
SRV - (McSysmon) -- C:\Program Files\McAfee\VirusScan\mcsysmon.exe (McAfee, Inc.)
SRV - (MSK80Service) -- C:\Program Files\McAfee\MSK\MskSrver.exe (McAfee, Inc.)
SRV - (McProxy) -- c:\Program Files\Common Files\McAfee\McProxy\McProxy.exe (McAfee, Inc.)
SRV - (McNASvc) -- c:\program files\common files\mcafee\mna\mcnasvc.exe (McAfee, Inc.)
SRV - (EvtEng) Intel(R) -- C:\Program Files\Intel\Wireless\Bin\EvtEng.exe (Intel Corporation)
SRV - (WLANKEEPER) Intel(R) -- C:\Program Files\Intel\Wireless\Bin\WLKEEPER.exe (Intel(R) Corporation)
SRV - (S24EventMonitor) Intel(R) -- C:\Program Files\Intel\Wireless\Bin\S24EvMon.exe (Intel Corporation )
SRV - (RegSrvc) Intel(R) -- C:\Program Files\Intel\Wireless\Bin\RegSrvc.exe (Intel Corporation)


========== Driver Services (SafeList) ==========

DRV - (PCTCore) -- C:\WINDOWS\system32\drivers\PCTCore.sys (PC Tools)
DRV - (mfehidk) -- C:\WINDOWS\system32\drivers\mfehidk.sys (McAfee, Inc.)
DRV - (mfeavfk) -- C:\WINDOWS\system32\drivers\mfeavfk.sys (McAfee, Inc.)
DRV - (mfesmfk) -- C:\WINDOWS\system32\drivers\mfesmfk.sys (McAfee, Inc.)
DRV - (mfebopk) -- C:\WINDOWS\system32\drivers\mfebopk.sys (McAfee, Inc.)
DRV - (mferkdk) -- C:\WINDOWS\system32\drivers\mferkdk.sys (McAfee, Inc.)
DRV - (MPFP) -- C:\WINDOWS\system32\drivers\Mpfp.sys (McAfee, Inc.)
DRV - (V0510Dev) -- C:\WINDOWS\system32\drivers\V0510Vid.sys (Creative Technology Ltd.)
DRV - (MSHUSBVideo) -- C:\WINDOWS\system32\drivers\nx6000.sys (Microsoft Corporation)
DRV - (V0510Vfx) -- C:\WINDOWS\system32\drivers\V0510Vfx.sys (EyePower Games Pte. Ltd.)
DRV - (s24trans) -- C:\WINDOWS\system32\drivers\s24trans.sys (Intel Corporation)
DRV - (NETw3x32) Intel(R) -- C:\WINDOWS\system32\drivers\NETw3x32.sys (Intel® Corporation)
DRV - (bcm4sbxp) -- C:\WINDOWS\system32\drivers\bcm4sbxp.sys (Broadcom Corporation)
DRV - (ati2mtag) -- C:\WINDOWS\system32\drivers\ati2mtag.sys (ATI Technologies Inc.)
DRV - (STHDA) -- C:\WINDOWS\system32\drivers\sthda.sys (SigmaTel, Inc.)
DRV - (SynTP) -- C:\WINDOWS\system32\drivers\SynTP.sys (Synaptics, Inc.)
DRV - (DSproct) -- C:\Program Files\Dell Support\GTAction\triggers\DSproct.sys (GTek Technologies Ltd.)
DRV - (rismxdp) -- C:\WINDOWS\system32\drivers\rixdptsk.sys (REDC)
DRV - (rimsptsk) -- C:\WINDOWS\system32\drivers\rimsptsk.sys (REDC)
DRV - (rimmptsk) -- C:\WINDOWS\system32\drivers\rimmptsk.sys (REDC)
DRV - (APPDRV) -- C:\WINDOWS\SYSTEM32\DRIVERS\APPDRV.SYS (Dell Inc)
DRV - (HSF_DPV) -- C:\WINDOWS\system32\drivers\HSF_DPV.sys (Conexant Systems, Inc.)
DRV - (HSFHWAZL) -- C:\WINDOWS\system32\drivers\HSFHWAZL.sys (Conexant Systems, Inc.)
DRV - (winachsf) -- C:\WINDOWS\system32\drivers\HSF_CNXT.sys (Conexant Systems, Inc.)
DRV - (tfsnudfa) -- C:\WINDOWS\system32\dla\tfsnudfa.sys (Sonic Solutions)
DRV - (tfsnudf) -- C:\WINDOWS\system32\dla\tfsnudf.sys (Sonic Solutions)
DRV - (tfsnifs) -- C:\WINDOWS\system32\dla\tfsnifs.sys (Sonic Solutions)
DRV - (tfsncofs) -- C:\WINDOWS\system32\dla\tfsncofs.sys (Sonic Solutions)
DRV - (tfsnboio) -- C:\WINDOWS\system32\dla\tfsnboio.sys (Sonic Solutions)
DRV - (tfsnopio) -- C:\WINDOWS\system32\dla\tfsnopio.sys (Sonic Solutions)
DRV - (tfsnpool) -- C:\WINDOWS\system32\dla\tfsnpool.sys (Sonic Solutions)
DRV - (tfsndrct) -- C:\WINDOWS\system32\dla\tfsndrct.sys (Sonic Solutions)
DRV - (tfsndres) -- C:\WINDOWS\system32\dla\tfsndres.sys (Sonic Solutions)
DRV - (drvmcdb) -- C:\WINDOWS\system32\drivers\drvmcdb.sys (Sonic Solutions)
DRV - (drvnddm) -- C:\WINDOWS\system32\drivers\drvnddm.sys (Sonic Solutions)
DRV - (HDAudBus) -- C:\WINDOWS\system32\drivers\Hdaudbus.sys (Windows (R) Server 2003 DDK provider)
DRV - (amdagp) -- C:\WINDOWS\system32\DRIVERS\amdagp.sys (Advanced Micro Devices, Inc.)
DRV - (sisagp) -- C:\WINDOWS\system32\DRIVERS\sisagp.sys (Silicon Integrated Systems Corporation)
DRV - (nv) -- C:\WINDOWS\system32\drivers\nv4_mini.sys (NVIDIA Corporation)
DRV - (usbaudio) USB Audio Driver (WDM) -- C:\WINDOWS\system32\drivers\USBAUDIO.sys (Microsoft Corporation)
DRV - (sscdbhk5) -- C:\WINDOWS\system32\drivers\sscdbhk5.sys (Sonic Solutions)
DRV - (ssrtln) -- C:\WINDOWS\system32\drivers\ssrtln.sys (Sonic Solutions)
DRV - (omci) -- C:\WINDOWS\system32\drivers\omci.sys (Dell Inc)
DRV - (Sparrow) -- C:\WINDOWS\system32\DRIVERS\sparrow.sys (Adaptec, Inc.)
DRV - (sym_u3) -- C:\WINDOWS\system32\DRIVERS\sym_u3.sys (LSI Logic)
DRV - (sym_hi) -- C:\WINDOWS\system32\DRIVERS\sym_hi.sys (LSI Logic)
DRV - (symc8xx) -- C:\WINDOWS\system32\DRIVERS\symc8xx.sys (LSI Logic)
DRV - (symc810) -- C:\WINDOWS\system32\DRIVERS\symc810.sys (Symbios Logic Inc.)
DRV - (ultra) -- C:\WINDOWS\system32\DRIVERS\ultra.sys (Promise Technology, Inc.)
DRV - (ql12160) -- C:\WINDOWS\system32\DRIVERS\ql12160.sys (QLogic Corporation)
DRV - (ql1080) -- C:\WINDOWS\system32\DRIVERS\ql1080.sys (QLogic Corporation)
DRV - (ql1280) -- C:\WINDOWS\system32\DRIVERS\ql1280.sys (QLogic Corporation)
DRV - (dac2w2k) -- C:\WINDOWS\system32\DRIVERS\dac2w2k.sys (Mylex Corporation)
DRV - (mraid35x) -- C:\WINDOWS\system32\DRIVERS\mraid35x.sys (American Megatrends Inc.)
DRV - (asc) -- C:\WINDOWS\system32\DRIVERS\asc.sys (Advanced System Products, Inc.)
DRV - (asc3550) -- C:\WINDOWS\system32\DRIVERS\asc3550.sys (Advanced System Products, Inc.)
DRV - (AliIde) -- C:\WINDOWS\system32\DRIVERS\aliide.sys (Acer Laboratories Inc.)
DRV - (CmdIde) -- C:\WINDOWS\system32\DRIVERS\cmdide.sys (CMD Technology, Inc.)


========== Standard Registry (SafeList) ==========


========== Internet Explorer ==========

IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Search_URL = http://www.google.com/ie
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Local Page = %SystemRoot%\system32\blank.htm
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Search Page = http://www.google.com
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://www.comcast.net/
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Search,Default_Page_URL = www.google.com/ig/dell?hl=en&client=del ... bd=0070602
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Search,Default_Search_URL = http://www.google.com/ie
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Search,SearchAssistant = http://www.google.com/ie
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Search,Start Page = www.google.com/ig/dell?hl=en&client=del ... bd=0070602


IE - HKU\.DEFAULT\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Page_URL = www.google.com/ig/dell?hl=en&client=del ... bd=0070602
IE - HKU\.DEFAULT\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = www.google.com/ig/dell?hl=en&client=del ... bd=0070602
IE - HKU\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
IE - HKU\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyOverride" = *.local
IE - HKU\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyServer" = :0

IE - HKU\S-1-5-18\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Page_URL = www.google.com/ig/dell?hl=en&client=del ... bd=0070602
IE - HKU\S-1-5-18\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = www.google.com/ig/dell?hl=en&client=del ... bd=0070602
IE - HKU\S-1-5-18\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
IE - HKU\S-1-5-18\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyOverride" = *.local
IE - HKU\S-1-5-18\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyServer" = :0



IE - HKU\S-1-5-21-1460104785-494194024-1023429310-1006\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Page_URL = www.google.com/ig/dell?hl=en&client=del ... bd=0070602
IE - HKU\S-1-5-21-1460104785-494194024-1023429310-1006\SOFTWARE\Microsoft\Internet Explorer\Main,Search Page = http://www.google.com/hws/sb/dell-usuk- ... channel=us
IE - HKU\S-1-5-21-1460104785-494194024-1023429310-1006\SOFTWARE\Microsoft\Internet Explorer\Search,SearchAssistant = http://www.google.com/ie
IE - HKU\S-1-5-21-1460104785-494194024-1023429310-1006\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
IE - HKU\S-1-5-21-1460104785-494194024-1023429310-1006\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyOverride" = *.local
IE - HKU\S-1-5-21-1460104785-494194024-1023429310-1006\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyServer" = :0

========== FireFox ==========

FF - prefs.js..browser.search.defaultenginename: "Google"
FF - prefs.js..browser.search.defaulturl: "http://www.google.com/search?lr=&ie=UTF-8&oe=UTF-8&q="
FF - prefs.js..browser.search.selectedEngine: "Google"
FF - prefs.js..browser.startup.homepage: "http://www.cnn.com/"
FF - prefs.js..extensions.enabledItems: moveplayer@movenetworks.com:7
FF - prefs.js..extensions.enabledItems: {B13721C7-F507-4982-B2E5-502A71474FED}:2.2.0.94
FF - prefs.js..extensions.enabledItems: LogMeInClient@logmein.com:1.0.0.586
FF - prefs.js..extensions.enabledItems: {CAFEEFAC-0016-0000-0020-ABCDEFFEDCBA}:6.0.20
FF - prefs.js..extensions.enabledItems: jqs@sun.com:1.0
FF - prefs.js..network.proxy.ftp: ":0"
FF - prefs.js..network.proxy.gopher: ":0"
FF - prefs.js..network.proxy.http: ":0"
FF - prefs.js..network.proxy.share_proxy_settings: true
FF - prefs.js..network.proxy.socks: ":0"
FF - prefs.js..network.proxy.ssl: ":0"


FF - HKLM\software\mozilla\Mozilla Firefox 3.6.6\extensions\\Components: C:\Program Files\Mozilla Firefox\components [2010/06/29 13:59:59 | 000,000,000 | ---D | M]
FF - HKLM\software\mozilla\Mozilla Firefox 3.6.6\extensions\\Plugins: C:\Program Files\Mozilla Firefox\plugins [2010/06/29 18:49:17 | 000,000,000 | ---D | M]

[2009/01/22 10:35:59 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Jesse\Application Data\Mozilla\Extensions
[2010/07/01 11:07:40 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Jesse\Application Data\Mozilla\Firefox\Profiles\98aqx86i.default\extensions
[2009/09/02 15:55:50 | 000,000,000 | ---D | M] (Microsoft .NET Framework Assistant) -- C:\Documents and Settings\Jesse\Application Data\Mozilla\Firefox\Profiles\98aqx86i.default\extensions\{20a82645-c095-46ed-80e3-08825760534b}
[2010/04/30 17:09:40 | 000,000,000 | ---D | M] (Google Toolbar for Firefox) -- C:\Documents and Settings\Jesse\Application Data\Mozilla\Firefox\Profiles\98aqx86i.default\extensions\{3112ca9c-de6d-4884-a869-9855de68056c}
[2010/04/27 11:51:25 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Jesse\Application Data\Mozilla\Firefox\Profiles\98aqx86i.default\extensions\LogMeInClient@logmein.com
[2010/07/02 10:05:56 | 000,000,000 | ---D | M] -- C:\Program Files\Mozilla Firefox\extensions
[2007/06/29 19:11:35 | 000,000,000 | ---D | M] (Google Toolbar for Firefox) -- C:\Program Files\Mozilla Firefox\extensions\{3112ca9c-de6d-4884-a869-9855de68056c}
[2010/06/29 18:49:23 | 000,000,000 | ---D | M] (Java Console) -- C:\Program Files\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0020-ABCDEFFEDCBA}
[2010/04/12 17:29:19 | 000,411,368 | ---- | M] (Sun Microsystems, Inc.) -- C:\Program Files\Mozilla Firefox\plugins\npdeployJava1.dll
[2008/09/15 11:52:06 | 000,376,832 | ---- | M] ( ) -- C:\Program Files\Mozilla Firefox\plugins\npsnapfish.dll
[2008/08/28 21:45:53 | 000,221,184 | ---- | M] (CNN) -- C:\Program Files\Mozilla Firefox\plugins\NPTURNMED.dll

O1 HOSTS File: ([2004/08/04 06:00:00 | 000,000,734 | ---- | M]) - C:\WINDOWS\system32\drivers\etc\hosts
O1 - Hosts: 127.0.0.1 localhost
O2 - BHO: (Adobe PDF Reader Link Helper) - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll (Adobe Systems Incorporated)
O2 - BHO: (McAfee Phishing Filter) - {27B4851A-3207-45A2-B947-BE8AFE6163AB} - c:\Program Files\McAfee\MSK\mskapbho.dll ()
O2 - BHO: (PC Tools Browser Guard BHO) - {2A0F3D1B-0909-4FF4-B272-609CCE6054E7} - C:\Program Files\Spyware Doctor\BDT\PCTBrowserDefender.dll (Threat Expert Ltd.)
O2 - BHO: (DriveLetterAccess) - {5CA3D70E-1895-11CF-8E15-001234567890} - C:\WINDOWS\system32\dla\tfswshx.dll (Sonic Solutions)
O2 - BHO: (scriptproxy) - {7DB2D5A0-7241-4E79-B68D-6309F01C5231} - C:\Program Files\McAfee\VirusScan\scriptsn.dll (McAfee, Inc.)
O2 - BHO: (Google Toolbar Helper) - {AA58ED58-01DD-4d91-8333-CF10577473F7} - C:\Program Files\Google\Google Toolbar\GoogleToolbar_32.dll (Google Inc.)
O2 - BHO: (Google Toolbar Notifier BHO) - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\5.5.5126.1836\swg.dll (Google Inc.)
O2 - BHO: (CBrowserHelperObject Object) - {CA6319C0-31B7-401E-A518-A07C3DB8F777} - C:\Program Files\BAE\BAE.dll (Dell Inc.)
O3 - HKLM\..\Toolbar: (Google Toolbar) - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - C:\Program Files\Google\Google Toolbar\GoogleToolbar_32.dll (Google Inc.)
O3 - HKLM\..\Toolbar: (PC Tools Browser Guard) - {472734EA-242A-422B-ADF8-83D1E48CC825} - C:\Program Files\Spyware Doctor\BDT\PCTBrowserDefender.dll (Threat Expert Ltd.)
O3 - HKU\S-1-5-21-1460104785-494194024-1023429310-1006\..\Toolbar\ShellBrowser: (Google Toolbar) - {2318C2B1-4965-11D4-9B18-009027A5CD4F} - C:\Program Files\Google\Google Toolbar\GoogleToolbar_32.dll (Google Inc.)
O3 - HKU\S-1-5-21-1460104785-494194024-1023429310-1006\..\Toolbar\WebBrowser: (Google Toolbar) - {2318C2B1-4965-11D4-9B18-009027A5CD4F} - C:\Program Files\Google\Google Toolbar\GoogleToolbar_32.dll (Google Inc.)
O3 - HKU\S-1-5-21-1460104785-494194024-1023429310-1006\..\Toolbar\WebBrowser: (PC Tools Browser Guard) - {472734EA-242A-422B-ADF8-83D1E48CC825} - C:\Program Files\Spyware Doctor\BDT\PCTBrowserDefender.dll (Threat Expert Ltd.)
O4 - HKLM..\Run: [ATICCC] C:\Program Files\ATI Technologies\ATI.ACE\cli.exe (ATI Technologies Inc.)
O4 - HKLM..\Run: [Carbonite Backup] C:\Program Files\Carbonite\Carbonite Backup\CarboniteUI.exe (Carbonite, Inc.)
O4 - HKLM..\Run: [Dell QuickSet] C:\Program Files\Dell\QuickSet\quickset.exe (Dell Inc)
O4 - HKLM..\Run: [Google Desktop Search] C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe ()
O4 - HKLM..\Run: [IntelWireless] C:\Program Files\Intel\Wireless\Bin\ifrmewrk.exe (Intel Corporation)
O4 - HKLM..\Run: [IntelZeroConfig] C:\Program Files\Intel\Wireless\bin\ZCfgSvc.exe (Intel Corporation)
O4 - HKLM..\Run: [ISUSPM Startup] C:\Program Files\Common Files\InstallShield\UpdateService\ISUSPM.exe (InstallShield Software Corporation)
O4 - HKLM..\Run: [ISUSScheduler] C:\Program Files\Common Files\InstallShield\UpdateService\issch.exe (InstallShield Software Corporation)
O4 - HKLM..\Run: [KernelFaultCheck] File not found
O4 - HKLM..\Run: [mcagent_exe] C:\Program Files\McAfee.com\Agent\mcagent.exe (McAfee, Inc.)
O4 - HKLM..\Run: [PCMService] C:\Program Files\Dell\MediaDirect\PCMService.exe (CyberLink Corp.)
O4 - HKLM..\Run: [SigmatelSysTrayApp] C:\WINDOWS\stsystra.exe (SigmaTel, Inc.)
O4 - HKLM..\Run: [V0510Mon.exe] C:\WINDOWS\V0510Mon.exe (Creative Technology Ltd.)
O4 - HKU\S-1-5-21-1460104785-494194024-1023429310-1006..\Run: [DellSupport] C:\Program Files\Dell Support\DSAgnt.exe (Gteko Ltd.)
O4 - HKU\S-1-5-21-1460104785-494194024-1023429310-1006..\Run: [ModemOnHold] C:\Program Files\NetWaiting\netwaiting.exe ()
O4 - HKU\S-1-5-21-1460104785-494194024-1023429310-1006..\Run: [swg] C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe (Google Inc.)
O4 - HKU\S-1-5-21-1460104785-494194024-1023429310-1006..\RunOnce: [RegistryBooster] C:\Program Files\Uniblue\RegistryBooster\launcher.exe (Uniblue Systems Limited)
O4 - Startup: C:\Documents and Settings\All Users\Start Menu\Programs\Startup\Adobe Reader Speed Launch.lnk = C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe (Adobe Systems Incorporated)
O4 - Startup: C:\Documents and Settings\All Users\Start Menu\Programs\Startup\Digital Line Detect.lnk = C:\Program Files\Digital Line Detect\DLG.exe (BVRP Software)
O4 - Startup: C:\Documents and Settings\All Users\Start Menu\Programs\Startup\HP Photosmart Premier Fast Start.lnk = C:\Program Files\HP\Digital Imaging\bin\hpqthb08.exe (Hewlett-Packard Development Company, L.P.)
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: HonorAutoRunSetting = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoCDBurning = 0
O7 - HKU\.DEFAULT\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145
O7 - HKU\S-1-5-18\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145
O7 - HKU\S-1-5-19\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145
O7 - HKU\S-1-5-20\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145
O7 - HKU\S-1-5-21-1460104785-494194024-1023429310-1006\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145
O8 - Extra context menu item: E&xport to Microsoft Excel - C:\Program Files\Microsoft Office\Office12\EXCEL.EXE (Microsoft Corporation)
O8 - Extra context menu item: Google Sidewiki... - C:\Program Files\Google\Google Toolbar\Component\GoogleToolbarDynamic_mui_en_89D8574934B26AC4.dll (Google Inc.)
O9 - Extra Button: Send to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\Program Files\Microsoft Office\Office12\ONBttnIE.dll (Microsoft Corporation)
O9 - Extra 'Tools' menuitem : S&end to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\Program Files\Microsoft Office\Office12\ONBttnIE.dll (Microsoft Corporation)
O9 - Extra Button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\Program Files\Microsoft Office\Office12\REFIEBAR.DLL (Microsoft Corporation)
O10 - NameSpace_Catalog5\Catalog_Entries\000000000004 [] - C:\Program Files\Bonjour\mdnsNSP.dll (Apple Inc.)
O15 - HKLM\..Trusted Domains: localhost ([]http in Local intranet)
O16 - DPF: {0CCA191D-13A6-4E29-B746-314DEE697D83} http://upload.facebook.com/controls/200 ... oader5.cab (Facebook Photo Uploader 5 Control)
O16 - DPF: {4CCA4E80-9259-11D9-AC6E-444553544200} http://h30155.www3.hp.com/ediags/dd/ins ... _v01_5.cab (FixController Control)
O16 - DPF: {5F8469B4-B055-49DD-83F7-62B522420ECC} http://upload.facebook.com/controls/Fac ... loader.cab (Facebook Photo Uploader Control)
O16 - DPF: {6F750202-1362-4815-A476-88533DE61D0C} http://www.kodakgallery.com/downloads/B ... ofupld.cab (Kodak Gallery Easy Upload Manager Class)
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} http://java.sun.com/update/1.6.0/jinsta ... s-i586.cab (Java Plug-in 1.6.0_20)
O16 - DPF: {AE6C4705-0F11-4ACB-BDD4-37F138BEF289} http://meijer.lifepics.com/net/Uploader ... ader41.cab (Image Uploader Control)
O16 - DPF: {CAFEEFAC-0015-0000-0006-ABCDEFFEDCBA} http://java.sun.com/update/1.5.0/jinsta ... s-i586.cab (Reg Error: Key error.)
O16 - DPF: {CAFEEFAC-0016-0000-0020-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinsta ... s-i586.cab (Java Plug-in 1.6.0_20)
O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinsta ... s-i586.cab (Java Plug-in 1.6.0_20)
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} http://download.macromedia.com/pub/shoc ... wflash.cab (Shockwave Flash Object)
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 192.168.1.254
O18 - Protocol\Handler\ms-help {314111c7-a502-11d2-bbca-00c04f8ec294} - C:\Program Files\Common Files\Microsoft Shared\Help\hxds.dll (Microsoft Corporation)
O18 - Protocol\Handler\skype4com {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\Program Files\Common Files\Skype\Skype4COM.dll (Skype Technologies)
O18 - Protocol\Filter\text/xml {807563E5-5146-11D5-A672-00B0D022E945} - C:\Program Files\Common Files\Microsoft Shared\OFFICE12\MSOXMLMF.DLL (Microsoft Corporation)
O20 - AppInit_DLLs: (C:\PROGRA~1\Google\GOOGLE~1\GOEC62~1.DLL) - C:\Program Files\Google\Google Desktop Search\GoogleDesktopNetwork3.dll ()
O20 - HKLM Winlogon: Shell - (Explorer.exe) - C:\WINDOWS\explorer.exe (Microsoft Corporation)
O20 - Winlogon\Notify\AtiExtEvent: DllName - Ati2evxx.dll - C:\WINDOWS\System32\ati2evxx.dll (ATI Technologies Inc.)
O20 - Winlogon\Notify\WgaLogon: DllName - Reg Error: Value error. - Reg Error: Value error. File not found
O24 - Desktop WallPaper: C:\Documents and Settings\Jesse\Local Settings\Application Data\Microsoft\Wallpaper1.bmp
O24 - Desktop BackupWallPaper: C:\Documents and Settings\Jesse\Local Settings\Application Data\Microsoft\Wallpaper1.bmp
O32 - HKLM CDRom: AutoRun - 1
O32 - AutoRun File - [2004/08/10 14:04:08 | 000,000,000 | ---- | M] () - C:\AUTOEXEC.BAT -- [ NTFS ]
O33 - MountPoints2\{aee6d085-21b1-11dc-aea8-0019b979d52c}\Shell - "" = AutoRun
O33 - MountPoints2\{aee6d085-21b1-11dc-aea8-0019b979d52c}\Shell\AutoRun - "" = Auto&Play
O33 - MountPoints2\{aee6d085-21b1-11dc-aea8-0019b979d52c}\Shell\AutoRun\command - "" = E:\LaunchU3.exe -- File not found
O34 - HKLM BootExecute: (autocheck autochk *) - File not found
O35 - HKLM\..comfile [open] -- "%1" %*
O35 - HKLM\..exefile [open] -- "%1" %*
O37 - HKLM\...com [@ = comfile] -- "%1" %*
O37 - HKLM\...exe [@ = exefile] -- "%1" %*

========== Files/Folders - Created Within 30 Days ==========

[2010/07/02 10:12:30 | 000,574,464 | ---- | C] (OldTimer Tools) -- C:\Documents and Settings\Jesse\Desktop\OTL.exe
[2010/06/30 03:18:20 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Jesse\Local Settings\Application Data\Threat Expert
[2010/06/29 19:51:43 | 000,000,000 | ---D | C] -- C:\Program Files\Trend Micro
[2010/06/29 19:32:12 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Jesse\Desktop\Improving Comp. Performance
[2010/06/29 19:28:09 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Jesse\Application Data\Malwarebytes
[2010/06/29 19:27:53 | 000,038,224 | ---- | C] (Malwarebytes Corporation) -- C:\WINDOWS\System32\drivers\mbamswissarmy.sys
[2010/06/29 19:27:51 | 000,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Application Data\Malwarebytes
[2010/06/29 19:27:50 | 000,020,952 | ---- | C] (Malwarebytes Corporation) -- C:\WINDOWS\System32\drivers\mbam.sys
[2010/06/29 19:27:50 | 000,000,000 | ---D | C] -- C:\Program Files\Malwarebytes' Anti-Malware
[2010/06/29 19:17:24 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Jesse\Application Data\Uniblue
[2010/06/29 19:16:23 | 000,000,000 | ---D | C] -- C:\Program Files\Uniblue
[2010/06/29 18:58:38 | 000,000,000 | ---D | C] -- C:\Program Files\Carbonite
[2010/06/29 18:58:38 | 000,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Application Data\Carbonite
[2010/06/29 18:49:53 | 000,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Application Data\Sun
[2010/06/29 18:49:17 | 000,411,368 | ---- | C] (Sun Microsystems, Inc.) -- C:\WINDOWS\System32\deployJava1.dll
[2010/06/29 18:49:17 | 000,153,376 | ---- | C] (Sun Microsystems, Inc.) -- C:\WINDOWS\System32\javaws.exe
[2010/06/29 18:49:16 | 000,145,184 | ---- | C] (Sun Microsystems, Inc.) -- C:\WINDOWS\System32\javaw.exe
[2010/06/29 18:49:16 | 000,145,184 | ---- | C] (Sun Microsystems, Inc.) -- C:\WINDOWS\System32\java.exe
[2010/06/29 18:30:37 | 000,000,000 | ---D | C] -- C:\Program Files\Western Digital Corporation
[2010/06/29 17:57:37 | 001,652,688 | ---- | C] (Threat Expert Ltd.) -- C:\WINDOWS\PCTBDCore.dll
[2010/06/29 17:57:37 | 000,165,840 | ---- | C] (Threat Expert Ltd.) -- C:\WINDOWS\PCTBDRes.dll
[2010/06/29 17:57:37 | 000,149,456 | ---- | C] (PC Tools) -- C:\WINDOWS\SGDetectionTool.dll
[2010/06/29 17:53:02 | 000,233,136 | ---- | C] (PC Tools) -- C:\WINDOWS\System32\drivers\pctgntdi.sys
[2010/06/29 17:52:50 | 000,218,592 | ---- | C] (PC Tools) -- C:\WINDOWS\System32\drivers\PCTCore.sys
[2010/06/29 17:52:50 | 000,088,040 | ---- | C] (PC Tools) -- C:\WINDOWS\System32\drivers\PCTAppEvent.sys
[2010/06/29 17:52:41 | 000,063,360 | ---- | C] (PC Tools) -- C:\WINDOWS\System32\drivers\pctplsg.sys
[2010/06/29 17:52:33 | 000,000,000 | ---D | C] -- C:\Program Files\Common Files\PC Tools
[2010/06/29 17:52:32 | 000,000,000 | ---D | C] -- C:\Program Files\Spyware Doctor
[2010/06/29 17:52:32 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Jesse\Application Data\PC Tools
[2010/06/29 17:52:32 | 000,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Application Data\PC Tools
[2010/06/29 17:51:10 | 000,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Application Data\TEMP
[2010/06/29 17:45:41 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Jesse\My Documents\Downloads
[2010/06/28 21:21:10 | 000,000,000 | ---D | C] -- C:\Documents and Settings\NetworkService\Application Data\Macromedia
[2010/06/28 21:21:08 | 000,000,000 | ---D | C] -- C:\Documents and Settings\NetworkService\Application Data\Adobe
[2010/06/27 17:36:50 | 000,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Application Data\NOS
[2010/06/20 14:52:53 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Jesse\.jnlp-applet
[1 C:\WINDOWS\System32\*.tmp files -> C:\WINDOWS\System32\*.tmp -> ]
[1 C:\Documents and Settings\Jesse\Desktop\*.tmp files -> C:\Documents and Settings\Jesse\Desktop\*.tmp -> ]

========== Files - Modified Within 30 Days ==========

[2010/07/02 10:32:27 | 000,000,886 | ---- | M] () -- C:\WINDOWS\tasks\GoogleUpdateTaskMachineUA.job
[2010/07/02 10:18:10 | 000,000,006 | -H-- | M] () -- C:\WINDOWS\tasks\SA.DAT
[2010/07/02 10:15:24 | 000,293,376 | ---- | M] () -- C:\Documents and Settings\Jesse\Desktop\7q3nw7uo.exe
[2010/07/02 10:12:50 | 000,574,464 | ---- | M] (OldTimer Tools) -- C:\Documents and Settings\Jesse\Desktop\OTL.exe
[2010/07/01 21:32:06 | 000,000,882 | ---- | M] () -- C:\WINDOWS\tasks\GoogleUpdateTaskMachineCore.job
[2010/07/01 15:13:40 | 000,028,323 | ---- | M] () -- C:\WINDOWS\System32\Config.MPF
[2010/07/01 15:12:32 | 000,002,048 | --S- | M] () -- C:\WINDOWS\bootstat.dat
[2010/07/01 15:12:28 | 1072,103,424 | -HS- | M] () -- C:\hiberfil.sys
[2010/07/01 15:07:45 | 000,000,178 | -HS- | M] () -- C:\Documents and Settings\Jesse\ntuser.ini
[2010/07/01 15:07:44 | 005,505,024 | -H-- | M] () -- C:\Documents and Settings\Jesse\NTUSER.DAT
[2010/07/01 01:00:00 | 000,000,352 | ---- | M] () -- C:\WINDOWS\tasks\McQcTask.job
[2010/06/29 19:01:05 | 000,001,875 | ---- | M] () -- C:\Documents and Settings\All Users\Desktop\Carbonite Backup Drive.lnk
[2010/06/29 12:13:06 | 000,000,284 | ---- | M] () -- C:\WINDOWS\tasks\AppleSoftwareUpdate.job
[2010/06/25 22:15:31 | 000,002,473 | ---- | M] () -- C:\Documents and Settings\Jesse\Desktop\Microsoft Office Excel 2007.lnk
[2010/06/23 09:15:01 | 000,504,314 | ---- | M] () -- C:\WINDOWS\System32\PerfStringBackup.INI
[2010/06/23 09:15:01 | 000,443,034 | ---- | M] () -- C:\WINDOWS\System32\perfh009.dat
[2010/06/23 09:15:01 | 000,072,134 | ---- | M] () -- C:\WINDOWS\System32\perfc009.dat
[2010/06/22 08:50:34 | 000,002,206 | ---- | M] () -- C:\WINDOWS\System32\wpa.dbl
[2010/06/12 09:40:32 | 000,157,160 | ---- | M] () -- C:\WINDOWS\System32\FNTCACHE.DAT
[2010/06/12 09:20:56 | 000,001,374 | ---- | M] () -- C:\WINDOWS\imsins.BAK
[2010/06/10 22:50:49 | 000,020,707 | ---- | M] () -- C:\Documents and Settings\Jesse\Desktop\katy checklist-INSTRUCTIONS.docx
[2010/06/05 14:38:50 | 000,015,691 | ---- | M] () -- C:\Documents and Settings\Jesse\Desktop\katy checklist.docx
[1 C:\WINDOWS\System32\*.tmp files -> C:\WINDOWS\System32\*.tmp -> ]
[1 C:\Documents and Settings\Jesse\Desktop\*.tmp files -> C:\Documents and Settings\Jesse\Desktop\*.tmp -> ]

========== Files Created - No Company Name ==========

[2010/07/02 10:15:23 | 000,293,376 | ---- | C] () -- C:\Documents and Settings\Jesse\Desktop\7q3nw7uo.exe
[2010/06/29 19:01:05 | 000,001,875 | ---- | C] () -- C:\Documents and Settings\All Users\Desktop\Carbonite Backup Drive.lnk
[2010/06/29 17:57:38 | 000,767,952 | ---- | C] () -- C:\WINDOWS\BDTSupport.dll
[2010/06/29 17:57:37 | 001,152,444 | ---- | C] () -- C:\WINDOWS\UDB.zip
[2010/06/29 17:57:37 | 000,000,882 | ---- | C] () -- C:\WINDOWS\RegSDImport.xml
[2010/06/29 17:57:37 | 000,000,879 | ---- | C] () -- C:\WINDOWS\RegISSImport.xml
[2010/06/29 17:57:37 | 000,000,131 | ---- | C] () -- C:\WINDOWS\IDB.zip
[2010/06/29 17:53:02 | 000,007,387 | ---- | C] () -- C:\WINDOWS\System32\drivers\pctgntdi.cat
[2010/06/29 17:52:50 | 000,007,412 | ---- | C] () -- C:\WINDOWS\System32\drivers\PCTAppEvent.cat
[2010/06/29 17:52:50 | 000,007,383 | ---- | C] () -- C:\WINDOWS\System32\drivers\pctcore.cat
[2010/06/29 17:52:41 | 000,007,383 | ---- | C] () -- C:\WINDOWS\System32\drivers\pctplsg.cat
[2010/06/10 21:09:33 | 000,020,707 | ---- | C] () -- C:\Documents and Settings\Jesse\Desktop\katy checklist-INSTRUCTIONS.docx
[2010/06/04 14:10:46 | 000,015,691 | ---- | C] () -- C:\Documents and Settings\Jesse\Desktop\katy checklist.docx
[2008/12/28 15:13:26 | 000,000,080 | RHS- | C] () -- C:\WINDOWS\System32\50F65862CC.dll
[2008/02/18 18:39:04 | 000,000,231 | ---- | C] () -- C:\WINDOWS\pwcsu.INI
[2008/02/18 18:30:27 | 000,001,793 | ---- | C] () -- C:\WINDOWS\aopr.ini
[2008/01/26 17:08:59 | 000,000,023 | ---- | C] () -- C:\WINDOWS\BlendSettings.ini
[2007/12/18 16:41:15 | 000,051,716 | ---- | C] () -- C:\WINDOWS\System32\pdf995mon.dll
[2007/12/18 16:41:15 | 000,000,142 | ---- | C] () -- C:\WINDOWS\wpd99.drv
[2007/08/11 20:35:16 | 000,000,054 | ---- | C] () -- C:\WINDOWS\VistaEmail.ini
[2007/06/30 18:53:25 | 000,077,824 | R--- | C] () -- C:\WINDOWS\System32\HPZIDS01.dll
[2007/06/02 15:08:42 | 000,000,061 | ---- | C] () -- C:\WINDOWS\smscfg.ini
[2007/06/02 15:04:39 | 000,198,144 | ---- | C] () -- C:\WINDOWS\System32\_psisdecd.dll
[2007/06/02 15:01:42 | 000,000,342 | ---- | C] () -- C:\WINDOWS\wininit.ini
[2007/06/02 14:24:13 | 000,016,480 | ---- | C] () -- C:\WINDOWS\System32\rixdicon.dll
[2007/06/02 14:22:35 | 000,001,121 | ---- | C] () -- C:\WINDOWS\System32\OEMINFO.INI
[2005/04/09 11:04:54 | 000,000,000 | ---- | C] () -- C:\WINDOWS\System32\px.ini
[2004/08/10 14:12:05 | 000,000,780 | ---- | C] () -- C:\WINDOWS\orun32.ini
[2004/08/10 14:01:18 | 000,001,793 | ---- | C] () -- C:\WINDOWS\System32\fxsperf.ini
[2001/07/07 03:00:00 | 000,003,399 | ---- | C] () -- C:\WINDOWS\System32\hptcpmon.ini

========== Alternate Data Streams ==========

@Alternate Data Stream - 163 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:DFC5A2B2
@Alternate Data Stream - 122 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:A8ADE5D8
< End of report >
jkwings
Active Member
 
Posts: 10
Joined: June 29th, 2010, 7:53 pm

Re: Google/Bing redirect error - please help

Unread postby jkwings » July 2nd, 2010, 3:47 pm

Extras.Txt, part 1:
Extras.Txt:
OTL Extras logfile created on: 7/2/2010 10:13:55 AM - Run 1
OTL by OldTimer - Version 3.2.7.0 Folder = C:\Documents and Settings\Jesse\Desktop
Windows XP Home Edition Service Pack 2 (Version = 5.1.2600) - Type = NTWorkstation
Internet Explorer (Version = 6.0.2900.2180)
Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy

1,022.00 Mb Total Physical Memory | 163.00 Mb Available Physical Memory | 16.00% Memory free
2.00 Gb Paging File | 1.00 Gb Available in Paging File | 59.00% Paging File free
Paging file location(s): C:\pagefile.sys 1536 3072 [binary data]

%SystemDrive% = C: | %SystemRoot% = C:\WINDOWS | %ProgramFiles% = C:\Program Files
Drive C: | 69.47 Gb Total Space | 28.87 Gb Free Space | 41.55% Space Free | Partition Type: NTFS
D: Drive not present or media not loaded
E: Drive not present or media not loaded
F: Drive not present or media not loaded
G: Drive not present or media not loaded
H: Drive not present or media not loaded
I: Drive not present or media not loaded

Computer Name: RALPH
Current User Name: Jesse
Logged in as Administrator.

Current Boot Mode: Normal
Scan Mode: All users
Company Name Whitelist: Off
Skip Microsoft Files: Off
File Age = 30 Days
Output = Minimal

========== Extra Registry (SafeList) ==========


========== File Associations ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\<extension>]
.html [@ = FirefoxHTML] -- C:\Program Files\Mozilla Firefox\firefox.exe (Mozilla Corporation)

========== Shell Spawning ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\<key>\shell\[command]\command]
batfile [open] -- "%1" %*
cmdfile [open] -- "%1" %*
comfile [open] -- "%1" %*
exefile [open] -- "%1" %*
htmlfile [edit] -- "C:\Program Files\Microsoft Office\Office12\msohtmed.exe" %1 (Microsoft Corporation)
htmlfile [print] -- "C:\Program Files\Microsoft Office\Office12\msohtmed.exe" /p %1 (Microsoft Corporation)
http [open] -- "C:\Program Files\Mozilla Firefox\firefox.exe" -requestPending -osint -url "%1" (Mozilla Corporation)
https [open] -- "C:\Program Files\Mozilla Firefox\firefox.exe" -requestPending -osint -url "%1" (Mozilla Corporation)
piffile [open] -- "%1" %*
regfile [merge] -- Reg Error: Key error.
scrfile [config] -- "%1"
scrfile [install] -- rundll32.exe desk.cpl,InstallScreenSaver %l (Microsoft Corporation)
scrfile [open] -- "%1" /S
txtfile [edit] -- Reg Error: Key error.
Unknown [openas] -- %SystemRoot%\system32\rundll32.exe %SystemRoot%\system32\shell32.dll,OpenAs_RunDLL %1
Directory [find] -- %SystemRoot%\Explorer.exe (Microsoft Corporation)
Directory [OneNote.Open] -- C:\PROGRA~1\MICROS~2\Office12\ONENOTE.EXE "%L" (Microsoft Corporation)
Folder [open] -- %SystemRoot%\Explorer.exe /idlist,%I,%L (Microsoft Corporation)
Folder [explore] -- %SystemRoot%\Explorer.exe /e,/idlist,%I,%L (Microsoft Corporation)
Drive [find] -- %SystemRoot%\Explorer.exe (Microsoft Corporation)

========== Security Center Settings ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center]
"FirstRunDisabled" = 1
"UpdatesDisableNotify" = 0
"AntiVirusOverride" = 0
"FirewallOverride" = 0
"AntiVirusDisableNotify" = 0
"FirewallDisableNotify" = 0

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\AhnlabAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\ComputerAssociatesAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\KasperskyAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\McAfeeAntiVirus]
"DisableMonitoring" = 1

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\McAfeeFirewall]
"DisableMonitoring" = 1

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\PandaAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\PandaFirewall]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\SophosAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\SymantecAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\SymantecFirewall]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\TinyFirewall]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\TrendAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\TrendFirewall]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\ZoneLabsFirewall]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile]
"EnableFirewall" = 0
jkwings
Active Member
 
Posts: 10
Joined: June 29th, 2010, 7:53 pm

Re: Google/Bing redirect error - please help

Unread postby jkwings » July 2nd, 2010, 3:47 pm

Extras.txt, part 2:
Extras.Txt:
OTL Extras logfile created on: 7/2/2010 10:13:55 AM - Run 1
OTL by OldTimer - Version 3.2.7.0 Folder = C:\Documents and Settings\Jesse\Desktop
Windows XP Home Edition Service Pack 2 (Version = 5.1.2600) - Type = NTWorkstation
Internet Explorer (Version = 6.0.2900.2180)
Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy

1,022.00 Mb Total Physical Memory | 163.00 Mb Available Physical Memory | 16.00% Memory free
2.00 Gb Paging File | 1.00 Gb Available in Paging File | 59.00% Paging File free
Paging file location(s): C:\pagefile.sys 1536 3072 [binary data]

%SystemDrive% = C: | %SystemRoot% = C:\WINDOWS | %ProgramFiles% = C:\Program Files
Drive C: | 69.47 Gb Total Space | 28.87 Gb Free Space | 41.55% Space Free | Partition Type: NTFS
D: Drive not present or media not loaded
E: Drive not present or media not loaded
F: Drive not present or media not loaded
G: Drive not present or media not loaded
H: Drive not present or media not loaded
I: Drive not present or media not loaded

Computer Name: RALPH
Current User Name: Jesse
Logged in as Administrator.

Current Boot Mode: Normal
Scan Mode: All users
Company Name Whitelist: Off
Skip Microsoft Files: Off
File Age = 30 Days
Output = Minimal

========== Extra Registry (SafeList) ==========


========== File Associations ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\<extension>]
.html [@ = FirefoxHTML] -- C:\Program Files\Mozilla Firefox\firefox.exe (Mozilla Corporation)

========== Shell Spawning ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\<key>\shell\[command]\command]
batfile [open] -- "%1" %*
cmdfile [open] -- "%1" %*
comfile [open] -- "%1" %*
exefile [open] -- "%1" %*
htmlfile [edit] -- "C:\Program Files\Microsoft Office\Office12\msohtmed.exe" %1 (Microsoft Corporation)
htmlfile [print] -- "C:\Program Files\Microsoft Office\Office12\msohtmed.exe" /p %1 (Microsoft Corporation)
http [open] -- "C:\Program Files\Mozilla Firefox\firefox.exe" -requestPending -osint -url "%1" (Mozilla Corporation)
https [open] -- "C:\Program Files\Mozilla Firefox\firefox.exe" -requestPending -osint -url "%1" (Mozilla Corporation)
piffile [open] -- "%1" %*
regfile [merge] -- Reg Error: Key error.
scrfile [config] -- "%1"
scrfile [install] -- rundll32.exe desk.cpl,InstallScreenSaver %l (Microsoft Corporation)
scrfile [open] -- "%1" /S
txtfile [edit] -- Reg Error: Key error.
Unknown [openas] -- %SystemRoot%\system32\rundll32.exe %SystemRoot%\system32\shell32.dll,OpenAs_RunDLL %1
Directory [find] -- %SystemRoot%\Explorer.exe (Microsoft Corporation)
Directory [OneNote.Open] -- C:\PROGRA~1\MICROS~2\Office12\ONENOTE.EXE "%L" (Microsoft Corporation)
Folder [open] -- %SystemRoot%\Explorer.exe /idlist,%I,%L (Microsoft Corporation)
Folder [explore] -- %SystemRoot%\Explorer.exe /e,/idlist,%I,%L (Microsoft Corporation)
Drive [find] -- %SystemRoot%\Explorer.exe (Microsoft Corporation)

========== Security Center Settings ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center]
"FirstRunDisabled" = 1
"UpdatesDisableNotify" = 0
"AntiVirusOverride" = 0
"FirewallOverride" = 0
"AntiVirusDisableNotify" = 0
"FirewallDisableNotify" = 0

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\AhnlabAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\ComputerAssociatesAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\KasperskyAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\McAfeeAntiVirus]
"DisableMonitoring" = 1

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\McAfeeFirewall]
"DisableMonitoring" = 1

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\PandaAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\PandaFirewall]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\SophosAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\SymantecAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\SymantecFirewall]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\TinyFirewall]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\TrendAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\TrendFirewall]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\ZoneLabsFirewall]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile]
"EnableFirewall" = 0
jkwings
Active Member
 
Posts: 10
Joined: June 29th, 2010, 7:53 pm

Re: Google/Bing redirect error - please help

Unread postby deltalima » July 2nd, 2010, 4:08 pm

Hi jkwings,

If you still have problems with GMER in safe mode then please run the following alternative scan.

Scan With RKUnHooker

  • Please Download Rootkit Unhooker Save it to your desktop.
  • Now double-click on RKUnhookerLE.exe to run it.
  • Click the Report tab, then click Scan.
  • Check (Tick) Drivers, Stealth, Files, Code Hooks. Uncheck the rest. then Click OK.
  • Wait till the scanner has finished and then click File, Save Report.
  • Save the report somewhere where you can find it. Click Close.
  • Copy the entire contents of the report and paste it in a reply here.
User avatar
deltalima
Admin/Teacher
Admin/Teacher
 
Posts: 7614
Joined: February 28th, 2009, 4:38 pm
Location: UK

Re: Google/Bing redirect error - please help

Unread postby jkwings » July 3rd, 2010, 9:29 am

Yeah the GMER was problematic in safe mode as well. Here is part 1 of the rootkit report:

RkU Version: 3.8.388.590, Type LE (SR2)
==============================================
OS Name: Windows XP
Version 5.1.2600 (Service Pack 2)
Number of processors #2
==============================================
>Drivers
==============================================
0xBF0DC000 C:\WINDOWS\System32\ati3duag.dll 2756608 bytes (ATI Technologies Inc. , ati3duag.dll)
0x804D7000 C:\WINDOWS\system32\ntkrnlpa.exe 2146304 bytes (Microsoft Corporation, NT Kernel & System)
0x804D7000 PnpManager 2146304 bytes
0x804D7000 RAW 2146304 bytes
0x804D7000 WMIxWDM 2146304 bytes
0xBF800000 Win32k 1851392 bytes
0xBF800000 C:\WINDOWS\System32\win32k.sys 1851392 bytes (Microsoft Corporation, Multi-User Win32 Driver)
0xBF37D000 C:\WINDOWS\System32\ativvaxx.dll 1753088 bytes (ATI Technologies Inc. , Radeon Video Acceleration Universal Driver)
0xF6CF3000 C:\WINDOWS\system32\DRIVERS\NETw3x32.sys 1712128 bytes (Intel® Corporation, Intel® Wireless LAN Driver)
0xF6ECF000 C:\WINDOWS\system32\DRIVERS\ati2mtag.sys 1638400 bytes (ATI Technologies Inc., ATI Radeon WindowsNT Miniport Driver)
0xEE2D5000 C:\WINDOWS\system32\drivers\sthda.sys 1114112 bytes (SigmaTel, Inc., NDRC)
0xEE184000 C:\WINDOWS\system32\DRIVERS\HSF_DPV.sys 1036288 bytes (Conexant Systems, Inc., HSF_DP driver)
0xEE0D4000 C:\WINDOWS\system32\DRIVERS\HSF_CNXT.sys 720896 bytes (Conexant Systems, Inc., HSF_CNXT driver)
0xF73B6000 Ntfs.sys 577536 bytes (Microsoft Corporation, NT File System Driver)
0xB9097000 C:\WINDOWS\system32\DRIVERS\mrxsmb.sys 454656 bytes (Microsoft Corporation, Windows NT SMB Minirdr)
0xF6B00000 C:\WINDOWS\system32\DRIVERS\update.sys 364544 bytes (Microsoft Corporation, Update Driver)
0xEBE45000 C:\WINDOWS\system32\DRIVERS\tcpip.sys 360448 bytes (Microsoft Corporation, TCP/IP Protocol Driver)
0xAF129000 C:\WINDOWS\system32\DRIVERS\srv.sys 356352 bytes (Microsoft Corporation, Server driver)
0xF6C73000 C:\WINDOWS\system32\DRIVERS\rixdptsk.sys 311296 bytes (REDC, RICOH XD SM Driver)
0xBFFA0000 C:\WINDOWS\System32\ATMFD.DLL 286720 bytes (Adobe Systems Incorporated, Windows NT OpenType/Type 1 Font Driver)
0xBF055000 C:\WINDOWS\System32\ati2cqag.dll 282624 bytes (ATI Technologies Inc., Central Memory Manager / Queue Server Module)
0xBF012000 C:\WINDOWS\System32\ati2dvag.dll 274432 bytes (ATI Technologies Inc., ATI Radeon WindowsNT Display Driver)
0xBF09A000 C:\WINDOWS\System32\atikvmag.dll 270336 bytes (ATI Technologies Inc., Virtual Command And Memory Manager)
0xADA8C000 C:\WINDOWS\System32\Drivers\HTTP.sys 266240 bytes (Microsoft Corporation, HTTP Protocol Stack)
0xF746F000 PCTCore.sys 233472 bytes (PC Tools, PC Tools KDS Core Driver)
0xB9064000 C:\WINDOWS\system32\drivers\mfehidk.sys 208896 bytes (McAfee, Inc., Host Intrusion Detection Link Driver)
0xEE281000 C:\WINDOWS\system32\DRIVERS\HSFHWAZL.sys 204800 bytes (Conexant Systems, Inc., HSF_HWAZL WDM driver)
0xF6C44000 C:\WINDOWS\system32\DRIVERS\SynTP.sys 192512 bytes (Synaptics, Inc., Synaptics Touchpad Driver)
0xF7522000 ACPI.sys 188416 bytes (Microsoft Corporation, ACPI Driver for NT)
0xF7389000 NDIS.sys 184320 bytes (Microsoft Corporation, NDIS 5.1 wrapper driver)
0xAF1F8000 C:\WINDOWS\system32\DRIVERS\mrxdav.sys 180224 bytes (Microsoft Corporation, Windows NT WebDav Minirdr)
0xAD061000 C:\WINDOWS\system32\drivers\kmixer.sys 176128 bytes (Microsoft Corporation, Kernel Mode Audio Mixer)
0xB9106000 C:\WINDOWS\system32\DRIVERS\rdbss.sys 176128 bytes (Microsoft Corporation, Redirected Drive Buffering SubSystem Driver)
0xB97AF000 C:\WINDOWS\system32\DRIVERS\netbt.sys 163840 bytes (Microsoft Corporation, MBT Transport driver)
0xEBDF6000 C:\WINDOWS\System32\Drivers\Mpfp.sys 159744 bytes (McAfee, Inc., McAfee Personal Firewall Plus Driver)
0xF6E95000 C:\WINDOWS\system32\DRIVERS\HDAudBus.sys 155648 bytes (Windows (R) Server 2003 DDK provider, High Definition Audio Bus Driver v1.0)
0xF6C21000 C:\WINDOWS\system32\DRIVERS\ks.sys 143360 bytes (Microsoft Corporation, Kernel CSA Library)
0xF6CD0000 C:\WINDOWS\system32\DRIVERS\USBPORT.SYS 143360 bytes (Microsoft Corporation, USB 1.1 & 2.0 Port Driver)
0xB926D000 C:\WINDOWS\System32\drivers\afd.sys 139264 bytes (Microsoft Corporation, Ancillary Function Driver for WinSock)
0xEE2B3000 C:\WINDOWS\system32\drivers\portcls.sys 139264 bytes (Microsoft Corporation, Port Class (Class Driver for Port/Miniport Devices))
0xB994E000 C:\WINDOWS\system32\DRIVERS\ipnat.sys 135168 bytes (Microsoft Corporation, IP Network Address Translator)
0x806E3000 ACPI_HAL 134272 bytes
0x806E3000 C:\WINDOWS\system32\hal.dll 134272 bytes (Microsoft Corporation, Hardware Abstraction Layer DLL)
0xF74F1000 fltMgr.sys 131072 bytes (Microsoft Corporation, Microsoft Filesystem Filter Manager)
0xF74D2000 ftdisk.sys 126976 bytes (Microsoft Corporation, FT Disk Driver)
0xF736E000 Mup.sys 110592 bytes (Microsoft Corporation, Multiple UNC Provider driver)
0xAF2B5000 C:\WINDOWS\system32\dla\tfsnudf.sys 102400 bytes (Sonic Solutions, Drive Letter Access Component)
0xAF29C000 C:\WINDOWS\system32\dla\tfsnudfa.sys 102400 bytes (Sonic Solutions, Drive Letter Access Component)
0xF74BA000 atapi.sys 98304 bytes (Microsoft Corporation, IDE/ATAPI Port Driver)
0xF7443000 KSecDD.sys 94208 bytes (Microsoft Corporation, Kernel Security Support Provider Interface)
0xF6C0A000 C:\WINDOWS\system32\DRIVERS\ndiswan.sys 94208 bytes (Microsoft Corporation, MS PPP Framing Driver (Strong Encryption))
0xAF2CE000 C:\WINDOWS\system32\dla\tfsnifs.sys 90112 bytes (Sonic Solutions, Drive Letter Access Component)
0xF745A000 drvmcdb.sys 86016 bytes (Sonic Solutions, Device Driver)
0xAEEBC000 C:\WINDOWS\system32\drivers\wdmaud.sys 86016 bytes (Microsoft Corporation, MMSYSTEM Wave/Midi API mapper)
0xF6EBB000 C:\WINDOWS\system32\DRIVERS\VIDEOPRT.SYS 81920 bytes (Microsoft Corporation, Video Port Driver)
0xEBE9D000 C:\WINDOWS\system32\DRIVERS\ipsec.sys 77824 bytes (Microsoft Corporation, IPSec Driver)
0xBF000000 C:\WINDOWS\System32\drivers\dxg.sys 73728 bytes (Microsoft Corporation, DirectX Graphics Driver)
0xADCAD000 C:\WINDOWS\system32\drivers\mfeavfk.sys 73728 bytes (McAfee, Inc., Anti-Virus File System Filter Driver)
0xF74A8000 sr.sys 73728 bytes (Microsoft Corporation, System Restore Filesystem Filter Driver)
0xF7511000 pci.sys 69632 bytes (Microsoft Corporation, NT Plug and Play PCI Enumerator)
0xF6BF9000 C:\WINDOWS\system32\DRIVERS\psched.sys 69632 bytes (Microsoft Corporation, MS QoS Packet Scheduler)
0xF6CBF000 C:\WINDOWS\system32\DRIVERS\sdbus.sys 69632 bytes (Microsoft Corporation, SecureDigital Bus Driver)
0xF76E1000 C:\WINDOWS\system32\DRIVERS\bcm4sbxp.sys 65536 bytes (Broadcom Corporation, Broadcom Corporation NDIS 5.1 ethernet driver)
0xB2BEF000 C:\WINDOWS\System32\Drivers\Cdfs.SYS 65536 bytes (Microsoft Corporation, CD-ROM File System Driver)
0xF7861000 C:\WINDOWS\system32\drivers\drmk.sys 61440 bytes (Microsoft Corporation, Microsoft Kernel DRM Descrambler Filter)
0xF76B1000 ohci1394.sys 61440 bytes (Microsoft Corporation, 1394 OpenHCI Port Driver)
0xF7731000 C:\WINDOWS\system32\DRIVERS\redbook.sys 61440 bytes (Microsoft Corporation, Redbook Audio Filter Driver)
0xAF011000 C:\WINDOWS\system32\drivers\sysaudio.sys 61440 bytes (Microsoft Corporation, System Audio WDM Filter)
0xF6BA9000 C:\WINDOWS\system32\DRIVERS\usbhub.sys 61440 bytes (Microsoft Corporation, Default Hub Driver for USB)
0xF76C1000 C:\WINDOWS\system32\DRIVERS\1394BUS.SYS 53248 bytes (Microsoft Corporation, 1394 Bus Device Driver)
0xF7721000 C:\WINDOWS\system32\DRIVERS\cdrom.sys 53248 bytes (Microsoft Corporation, SCSI CD-ROM Driver)
0xF7691000 C:\WINDOWS\system32\DRIVERS\CLASSPNP.SYS 53248 bytes (Microsoft Corporation, SCSI Class System Dll)
0xF7701000 C:\WINDOWS\system32\DRIVERS\i8042prt.sys 53248 bytes (Microsoft Corporation, i8042 Port Driver)
0xF7741000 C:\WINDOWS\system32\DRIVERS\rasl2tp.sys 53248 bytes (Microsoft Corporation, RAS L2TP mini-port/call-manager driver)
0xF76F1000 C:\WINDOWS\system32\DRIVERS\rimsptsk.sys 53248 bytes (REDC, RICOH MS Driver)
0xF7671000 VolSnap.sys 53248 bytes (Microsoft Corporation, Volume Shadow Copy Driver)
0xF76A1000 PxHelp20.sys 49152 bytes (Sonic Solutions, Px Engine Device Driver for Windows 2000/XP)
0xF7761000 C:\WINDOWS\system32\DRIVERS\raspptp.sys 49152 bytes (Microsoft Corporation, Peer-to-Peer Tunneling Protocol)
0xF7711000 C:\WINDOWS\system32\DRIVERS\imapi.sys 45056 bytes (Microsoft Corporation, IMAPI Kernel Driver)
0xF7661000 MountMgr.sys 45056 bytes (Microsoft Corporation, Mount Manager)
0xF7751000 C:\WINDOWS\system32\DRIVERS\raspppoe.sys 45056 bytes (Microsoft Corporation, RAS PPPoE mini-port/call-manager driver)
0xB80A8000 C:\WINDOWS\system32\drivers\drvnddm.sys 40960 bytes (Sonic Solutions, Device Driver Manager)
0xF7831000 C:\WINDOWS\System32\Drivers\NDProxy.SYS 40960 bytes (Microsoft Corporation, NDIS Proxy)
0xAEED1000 C:\WINDOWS\system32\DRIVERS\secdrv.sys 40960 bytes (Macrovision Corporation, Macrovision Europe Limited, and Macrovision Japan and Asia K.K., Macrovision SECURITY Driver)
0xF7781000 C:\WINDOWS\system32\DRIVERS\termdd.sys 40960 bytes (Microsoft Corporation, Terminal Server Driver)
0xF7681000 disk.sys 36864 bytes (Microsoft Corporation, PnP Disk Driver)
0xEC142000 C:\WINDOWS\System32\Drivers\Fips.SYS 36864 bytes (Microsoft Corporation, FIPS Crypto Driver)
0xF78C1000 C:\WINDOWS\system32\DRIVERS\intelppm.sys 36864 bytes (Microsoft Corporation, Processor Device Driver)
0xED8F9000 C:\WINDOWS\system32\DRIVERS\ipfltdrv.sys 36864 bytes (Microsoft Corporation, IP FILTER DRIVER)
0xF7651000 isapnp.sys 36864 bytes (Microsoft Corporation, PNP ISA Bus Driver)
0xAE82E000 C:\WINDOWS\system32\drivers\mfesmfk.sys 36864 bytes (McAfee, Inc., System Monitor Filter Driver)
0xF7771000 C:\WINDOWS\system32\DRIVERS\msgpc.sys 36864 bytes (Microsoft Corporation, MS General Packet Classifier)
0xED8D9000 C:\WINDOWS\system32\DRIVERS\netbios.sys 36864 bytes (Microsoft Corporation, NetBIOS interface driver)
0xAD2C8000 C:\WINDOWS\System32\Drivers\Normandy.SYS 36864 bytes (RKU Driver)
0xB8098000 C:\WINDOWS\system32\dla\tfsncofs.sys 36864 bytes (Sonic Solutions, Drive Letter Access Component)
0xED909000 C:\WINDOWS\system32\DRIVERS\wanarp.sys 36864 bytes (Microsoft Corporation, MS Remote Access and Routing ARP Driver)
0xF7911000 C:\WINDOWS\System32\Drivers\Modem.SYS 32768 bytes (Microsoft Corporation, Modem Device Driver)
0xF79B9000 C:\WINDOWS\System32\Drivers\Npfs.SYS 32768 bytes (Microsoft Corporation, NPFS Driver)
0xF79A1000 C:\WINDOWS\system32\DRIVERS\HIDPARSE.SYS 28672 bytes (Microsoft Corporation, Hid Parsing Library)
0xB7FB7000 C:\WINDOWS\system32\drivers\mfebopk.sys 28672 bytes (McAfee, Inc., Buffer Overflow Protection Driver)
0xF78D1000 C:\WINDOWS\system32\DRIVERS\PCIIDEX.SYS 28672 bytes (Microsoft Corporation, PCI IDE Bus Driver Extension)
0xF79F1000 C:\WINDOWS\system32\DRIVERS\rimmptsk.sys 28672 bytes (REDC, RICOH MMC Driver)
0xB1606000 C:\WINDOWS\system32\dla\tfsnboio.sys 28672 bytes (Sonic Solutions, Drive Letter Access Component)
0xF79E9000 C:\WINDOWS\system32\DRIVERS\usbehci.sys 28672 bytes (Microsoft Corporation, EHCI eUSB Miniport Driver)
0xF7A09000 C:\WINDOWS\System32\Drivers\GEARAspiWDM.sys 24576 bytes (GEAR Software Inc., CD DVD Filter)
0xF7A01000 C:\WINDOWS\system32\DRIVERS\kbdclass.sys 24576 bytes (Microsoft Corporation, Keyboard Class Driver)
0xF79F9000 C:\WINDOWS\system32\DRIVERS\mouclass.sys 24576 bytes (Microsoft Corporation, Mouse Class Driver)
0xF7991000 C:\WINDOWS\system32\drivers\ssrtln.sys 24576 bytes (Sonic Solutions, Shared Driver Component)
0xF79A9000 C:\WINDOWS\System32\drivers\vga.sys 24576 bytes (Microsoft Corporation, VGA/Super VGA Video Driver)
0xB83E3000 C:\WINDOWS\system32\DRIVERS\AegisP.sys 20480 bytes (Meetinghouse Data Communications, IEEE 802.1X Protocol Driver)
0xF79B1000 C:\WINDOWS\System32\Drivers\Msfs.SYS 20480 bytes (Microsoft Corporation, Mailslot driver)
0xF7A29000 C:\WINDOWS\system32\DRIVERS\omci.sys 20480 bytes (Dell Inc, OMCI Device Driver)
0xF78D9000 PartMgr.sys 20480 bytes (Microsoft Corporation, Partition Manager)
0xF7A19000 C:\WINDOWS\system32\DRIVERS\ptilink.sys 20480 bytes (Parallel Technologies, Inc., Parallel Technologies DirectParallel IO Library)
0xF7A21000 C:\WINDOWS\system32\DRIVERS\raspti.sys 20480 bytes (Microsoft Corporation, PTI DirectParallel(R) mini-port/call-manager driver)
0xF7A11000 C:\WINDOWS\system32\DRIVERS\TDI.SYS 20480 bytes (Microsoft Corporation, TDI Wrapper)
0xF79E1000 C:\WINDOWS\system32\DRIVERS\usbuhci.sys 20480 bytes (Microsoft Corporation, UHCI USB Miniport Driver)
0xB1E32000 C:\WINDOWS\System32\watchdog.sys 20480 bytes (Microsoft Corporation, Watchdog Driver)
0xED979000 C:\WINDOWS\SYSTEM32\DRIVERS\APPDRV.SYS 16384 bytes (Dell Inc, App Support Driver)
0xF7A69000 C:\WINDOWS\system32\DRIVERS\BATTC.SYS 16384 bytes (Microsoft Corporation, Battery Class Driver)
0xF734A000 C:\WINDOWS\system32\DRIVERS\CmBatt.sys 16384 bytes (Microsoft Corporation, Control Method Battery Driver)
0xF706B000 C:\WINDOWS\system32\DRIVERS\mssmbios.sys 16384 bytes (Microsoft Corporation, System Management BIOS Driver)
0xB25E9000 C:\WINDOWS\system32\DRIVERS\ndisuio.sys 16384 bytes (Microsoft Corporation, NDIS User mode I/O Driver)
0xF677E000 C:\WINDOWS\system32\DRIVERS\s24trans.sys 16384 bytes (Intel Corporation, Intel WLAN Packet Driver)
0xF7B05000 C:\WINDOWS\system32\dla\tfsnopio.sys 16384 bytes (Sonic Solutions, Drive Letter Access Component)
0xF7A61000 C:\WINDOWS\system32\BOOTVID.dll 12288 bytes (Microsoft Corporation, VGA Boot Driver)
0xF7A65000 compbatt.sys 12288 bytes (Microsoft Corporation, Composite Battery Driver)
0xB25DD000 C:\WINDOWS\System32\drivers\Dxapi.sys 12288 bytes (Microsoft Corporation, DirectX API Driver)
0xAF0AD000 C:\WINDOWS\system32\DRIVERS\mdmxsdk.sys 12288 bytes (Conexant, Diagnostic Interface DRIVER)
0xF707B000 C:\WINDOWS\system32\DRIVERS\ndistapi.sys 12288 bytes (Microsoft Corporation, NDIS 3.0 connection wrapper driver)
0xF677A000 C:\WINDOWS\system32\DRIVERS\rasacd.sys 12288 bytes (Microsoft Corporation, RAS Automatic Connection Driver)
0xF7B49000 C:\WINDOWS\system32\DRIVERS\wmiacpi.sys 12288 bytes (Microsoft Corporation, Windows Management Interface for ACPI)
0xF7C13000 C:\WINDOWS\System32\Drivers\Beep.SYS 8192 bytes (Microsoft Corporation, BEEP Driver)
0xB8F0F000 C:\Program Files\Dell Support\GTAction\triggers\DSproct.sys 8192 bytes (GTek Technologies Ltd., Process Trigger Driver)
0xF7C0F000 C:\WINDOWS\System32\Drivers\Fs_Rec.SYS 8192 bytes (Microsoft Corporation, File System Recognizer Driver)
0xF7C09000 C:\WINDOWS\System32\Drivers\i2omgmt.SYS 8192 bytes (Microsoft Corporation, I2O Utility Filter)
0xF7B51000 C:\WINDOWS\system32\KDCOM.DLL 8192 bytes (Microsoft Corporation, Kernel Debugger HW Extension DLL)
0xF7B57000 C:\WINDOWS\System32\Drivers\mnmdd.SYS 8192 bytes (Microsoft Corporation, Frame buffer simulator)
0xF7B59000 C:\WINDOWS\System32\DRIVERS\RDPCDD.sys 8192 bytes (Microsoft Corporation, RDP Miniport)
0xF7BD5000 C:\WINDOWS\system32\drivers\sscdbhk5.sys 8192 bytes (Sonic Solutions, Shared Driver Component)
0xF7BD7000 C:\WINDOWS\system32\DRIVERS\swenum.sys 8192 bytes (Microsoft Corporation, Plug and Play Software Device Enumerator)
0xB230F000 C:\WINDOWS\system32\dla\tfsnpool.sys 8192 bytes (Sonic Solutions, Drive Letter Access Component)
0xF7BD3000 C:\WINDOWS\system32\DRIVERS\USBD.SYS 8192 bytes (Microsoft Corporation, Universal Serial Bus Driver)
0xF7B53000 C:\WINDOWS\system32\DRIVERS\WMILIB.SYS 8192 bytes (Microsoft Corporation, WMILIB WMI support library Dll)
0xF7C5F000 C:\WINDOWS\system32\DRIVERS\audstub.sys 4096 bytes (Microsoft Corporation, AudStub Driver)
0xB812B000 C:\WINDOWS\System32\drivers\dxgthk.sys 4096 bytes (Microsoft Corporation, DirectX Graphics Driver Thunk)
0xF7C1A000 C:\WINDOWS\System32\Drivers\Null.SYS 4096 bytes (Microsoft Corporation, NULL Driver)
0xF7C19000 pciide.sys 4096 bytes (Microsoft Corporation, Generic PCI IDE Bus Driver)
0xF7C50000 C:\WINDOWS\system32\dla\tfsndrct.sys 4096 bytes (Sonic Solutions, Drive Letter Access Component)
0xF7C4F000 C:\WINDOWS\system32\dla\tfsndres.sys 4096 bytes (Sonic Solutions, Drive Letter Access Component)
!!!!!!!!!!!Hidden driver: 0x86D28AEA ?_empty_? 1302 bytes
!!!!!!!!!!!Hidden driver: 0x86DC7DA0 ?_empty_? 0 bytes
==============================================
>Stealth
==============================================
0xF74BA000 WARNING: suspicious driver modification [atapi.sys::0x86D28AEA]
0xF7B49000 WARNING: Virus alike driver modification [wmiacpi.sys], 12288 bytes
==============================================
>Files
==============================================
!-->[Hidden] C:\contents of old hard drive\ Root\Documents and Settings\Documents and Settings\Jesse Wilson\Local Settings\Temporary Internet Files\Content.IE5\14CVD18T\;spt=;ptyp=main;path=MAIN;file=poll_exclude_html;dcove=d;sz=178x37;dcopt=undefined;ptile=1;ord=828248020169[2]e=content_8_html;dcove=d;sz=300x250;dcop[1]
!-->[Hidden] C:\contents of old hard drive\ Root\Documents and Settings\Documents and Settings\Jesse Wilson\Local Settings\Temporary Internet Files\Content.IE5\14CVD18T\music;sz=728x90;kch=2179803025;kbg=FFFFFF;kr=A;kgender=m;kage=22;kpu=amyklc;kvideoid=LHnJGXwr-HU;ord=372537947169733[2].6_html;dcove=d;sz=300x250;dcop[1]
!-->[Hidden] C:\contents of old hard drive\ Root\Documents and Settings\Documents and Settings\Jesse Wilson\Local Settings\Temporary Internet Files\Content.IE5\14CVD18T\music;sz=728x90;kch=2179803025;kbg=FFFFFF;kr=H;kgender=m;kage=22;kpu=gjourney;kvideoid=8JgTsEpXEWo;ord=7455140714510606[2]html;dcove=d;sz=300x250;dcop[1]
!-->[Hidden] C:\contents of old hard drive\ Root\Documents and Settings\Documents and Settings\Jesse Wilson\Local Settings\Temporary Internet Files\Content.IE5\14CVD18T\_default;sz=728x90;kch=1600166264;kbg=FFFFFF;ksearch=auld%20lang%20syne;kr=F;kgender=m;kage=22;ord=15868462653170[2].1016_html;dcove=d;sz=300x250;dcop[1]
!-->[Hidden] C:\contents of old hard drive\ Root\Documents and Settings\Documents and Settings\Jesse Wilson\Local Settings\Temporary Internet Files\Content.IE5\19BQWV63\;spt=;ptyp=main;path=MAIN;file=poll_exclude_html;dcove=d;sz=178x37;dcopt=undefined;ptile=1;ord=2257925869[2]_html;dcove=d;sz=728x90;dcopt=ist;ptile=1;[2].htm
!-->[Hidden] C:\contents of old hard drive\ Root\Documents and Settings\Documents and Settings\Jesse Wilson\Local Settings\Temporary Internet Files\Content.IE5\19BQWV63\;spt=;ptyp=main;path=MAIN;file=poll_exclude_html;dcove=d;sz=178x37;dcopt=undefined;ptile=1;ord=494450485045[2]h=bc_hkn_leetchretires_ap;file=index_htm[3]
!-->[Hidden] C:\contents of old hard drive\ Root\Documents and Settings\Documents and Settings\Jesse Wilson\Local Settings\Temporary Internet Files\Content.IE5\19BQWV63\;spt=;ptyp=main;path=MAIN;file=poll_exclude_html;dcove=d;sz=178x37;dcopt=undefined;ptile=1;ord=761379144330[2]16,5855,5880,6298,6520,6582,6997,7313,77[1].htm
!-->[Hidden] C:\contents of old hard drive\ Root\Documents and Settings\Documents and Settings\Jesse Wilson\Local Settings\Temporary Internet Files\Content.IE5\19BQWV63\;spt=;ptyp=main;path=MAIN;file=poll_exclude_html;dcove=d;sz=178x37;dcopt=undefined;ptile=1;ord=864323206028[1]16,5855,5880,6298,6520,6582,6997,7313,77[1].htm
!-->[Hidden] C:\contents of old hard drive\ Root\Documents and Settings\Documents and Settings\Jesse Wilson\Local Settings\Temporary Internet Files\Content.IE5\19BQWV63\;spt=;ptyp=main;path=MAIN;file=poll_exclude_html;dcove=d;sz=178x37;dcopt=undefined;ptile=1;ord=957585335054[2]16,5855,5880,6298,6520,6582,6997,7313,77[1].htm
!-->[Hidden] C:\contents of old hard drive\ Root\Documents and Settings\Documents and Settings\Jesse Wilson\Local Settings\Temporary Internet Files\Content.IE5\19BQWV63\;spt=;ptyp=main;path=_element;path=ssi;path=sect;path=3_0;path=MAIN;file=728x90_exclude_html;dcove=d;sz=728x90;dcopt=undefined;ptile=1;ord=57032266816[2].htm
!-->[Hidden] C:\contents of old hard drive\ Root\Documents and Settings\Documents and Settings\Jesse Wilson\Local Settings\Temporary Internet Files\Content.IE5\19BQWV63\;spt=;writ=extramustard;path=si_blogs;path=extramustard;path=10_spot;path=2007;path=05;file=is-lebron-new-kg_html;dcove=d;sz=160x600;ptile=2;ord=88723[2].htm
!-->[Hidden] C:\contents of old hard drive\ Root\Documents and Settings\Documents and Settings\Jesse Wilson\Local Settings\Temporary Internet Files\Content.IE5\19BQWV63\;spt=;writ=extramustard;path=si_blogs;path=extramustard;path=10_spot;path=2007;path=05;file=is-lebron-new-kg_html;dcove=d;sz=728x90;dcopt=ist;ptile=1;[2].htm
!-->[Hidden] C:\contents of old hard drive\ Root\Documents and Settings\Documents and Settings\Jesse Wilson\Local Settings\Temporary Internet Files\Content.IE5\19BQWV63\;spt=baseball_mlb;slug=hancock;slug=lawsuit;slug=ap;path=2007;path=baseball;path=mlb;path=05;path=24;path=hancock_lawsuit_ap;file=index_html[2]dex_htm[3]
!-->[Hidden] C:\contents of old hard drive\ Root\Documents and Settings\Documents and Settings\Jesse Wilson\Local Settings\Temporary Internet Files\Content.IE5\23AXWNMJ\site=cnn&cnn_pagetype=main&cnn_position=88x31_spon1&cnn_rollup=homepage&params.styles=fs&tile=1180093421503&page[1].htm=728x90;dcopt=ist;ptile=1;ord=4[2]
!-->[Hidden] C:\contents of old hard drive\ Root\Documents and Settings\Documents and Settings\Jesse Wilson\Local Settings\Temporary Internet Files\Content.IE5\23AXWNMJ\site=cnn&cnn_position=306x60_lft&cnn_rollup=homepage&params.styles=fs&tile=1180093421503&page[1].htm3421503&page[1].htm=728x90;dcopt=ist;ptile=1;ord=4[2]
!-->[Hidden] C:\contents of old hard drive\ Root\Documents and Settings\Documents and Settings\Jesse Wilson\Local Settings\Temporary Internet Files\Content.IE5\65XYJE5S\home_;site=nbc;sect=home;sub=;genre=;daypart=;!category=home;!category=js;!category=nbc;network=tvn;sz=728x90;tagtype=js;dcopt=ist;uri=;pos=1;tile=1;o[2].htm
!-->[Hidden] C:\contents of old hard drive\ Root\Documents and Settings\Documents and Settings\Jesse Wilson\Local Settings\Temporary Internet Files\Content.IE5\8NHBIA3H\_default;sz=300x35;kch=3000513466;kbg=FFFFFF;kgender=m;kage=22;kvideoid=RjeO4Ve9cQQ;ord=5891549018941209[2]156103888;eid1=2;ecn1=0;etm1=10;[1].gif
!-->[Hidden] C:\contents of old hard drive\ Root\Documents and Settings\Documents and Settings\Jesse Wilson\Local Settings\Temporary Internet Files\Content.IE5\8NHBIA3H\_default;sz=728x90;kch=1600166264;kbg=FFFFFF;ksearch=cube;kr=F;kgender=m;kage=22;ord=1330840496925701[2].5]156103888;eid1=2;ecn1=0;etm1=10;[1].gif
!-->[Hidden] C:\contents of old hard drive\ Root\Documents and Settings\Documents and Settings\Jesse Wilson\Local Settings\Temporary Internet Files\Content.IE5\AGA4NLUA\Celeb_InternalPromo;MN=93221313;wm=o;rm=1;!c=d-jav;!c=d-dxp;!c=d-pxp;sz=318x113;ptile=2;dcove=d;ord=351961209[1]ve=d;ord=352197448[1]
!-->[Hidden] C:\contents of old hard drive\ Root\Documents and Settings\Documents and Settings\Jesse Wilson\Local Settings\Temporary Internet Files\Content.IE5\AGA4NLUA\Celeb_InternalPromo;MN=93221313;wm=o;rm=1;!c=d-jav;!c=d-dxp;!c=d-pxp;sz=318x113;ptile=2;dcove=d;ord=352243344[1]ve=d;ord=352197448[1]
!-->[Hidden] C:\contents of old hard drive\ Root\Documents and Settings\Documents and Settings\Jesse Wilson\Local Settings\Temporary Internet Files\Content.IE5\AGA4NLUA\EntGen_Style;MN=93221508;wm=o;rm=1;!c=d-jav;!c=d-dxp;!c=d-pxp;sz=300x250;ptile=1;dcove=d;ord=352026533[1]rd=352200403[1]
!-->[Hidden] C:\contents of old hard drive\ Root\Documents and Settings\Documents and Settings\Jesse Wilson\Local Settings\Temporary Internet Files\Content.IE5\AGA4NLUA\EntGen_Style;MN=93221508;wm=o;rm=1;!c=d-jav;!c=d-dxp;!c=d-pxp;sz=300x250;ptile=1;dcove=d;ord=352207603[1]rd=352200403[1]
!-->[Hidden] C:\contents of old hard drive\ Root\Documents and Settings\Documents and Settings\Jesse Wilson\Local Settings\Temporary Internet Files\Content.IE5\AGA4NLUA\EntGen_Style;MN=93221508;wm=o;rm=1;!c=d-jav;!c=d-dxp;!c=d-pxp;sz=300x250;ptile=1;dcove=d;ord=352212260[1]rd=352200403[1]
!-->[Hidden] C:\contents of old hard drive\ Root\Documents and Settings\Documents and Settings\Jesse Wilson\Local Settings\Temporary Internet Files\Content.IE5\AGA4NLUA\EntGen_Style;MN=93221508;wm=o;rm=1;!c=d-jav;!c=d-dxp;!c=d-pxp;sz=300x250;ptile=1;dcove=d;ord=352221062[1]rd=352200403[1]
!-->[Hidden] C:\contents of old hard drive\ Root\Documents and Settings\Documents and Settings\Jesse Wilson\Local Settings\Temporary Internet Files\Content.IE5\AGA4NLUA\NOSALE_ConsMrktng;MN=93220973;wm=o;rm=1;!c=d-jav;!c=d-dxp;!c=d-pxp;sz=240x52;tile=5;dcove=d;ord=352432777[1]352200403[1]
!-->[Hidden] C:\contents of old hard drive\ Root\Documents and Settings\Documents and Settings\Jesse Wilson\Local Settings\Temporary Internet Files\Content.IE5\AGA4NLUA\NOSALE_ConsMrktng;MN=93220973;wm=o;rm=1;!c=d-jav;!c=d-dxp;!c=d-pxp;sz=240x52;tile=5;dcove=d;ord=352445175[1]352200403[1]
!-->[Hidden] C:\contents of old hard drive\ Root\Documents and Settings\Documents and Settings\Jesse Wilson\Local Settings\Temporary Internet Files\Content.IE5\AGA4NLUA\NOSALE_ConsMrktng;MN=93220974;wm=o;rm=1;!c=d-jav;!c=d-dxp;!c=d-pxp;sz=240x60;tile=2;dcove=d;ord=351920771[1]352200403[1]
!-->[Hidden] C:\contents of old hard drive\ Root\Documents and Settings\Documents and Settings\Jesse Wilson\Local Settings\Temporary Internet Files\Content.IE5\DHN5QD49\Celeb_InternalPromo;MN=93221313;wm=o;rm=1;!c=d-jav;!c=d-dxp;!c=d-pxp;sz=318x113;ptile=2;dcove=d;ord=352200403[1]e_surgeries_ap;file=index_html;dcove=d[2]
!-->[Hidden] C:\contents of old hard drive\ Root\Documents and Settings\Documents and Settings\Jesse Wilson\Local Settings\Temporary Internet Files\Content.IE5\DHN5QD49\Celeb_InternalPromo;MN=93221313;wm=o;rm=1;!c=d-jav;!c=d-dxp;!c=d-pxp;sz=318x113;ptile=2;dcove=d;ord=352445175[1]e_surgeries_ap;file=index_html;dcove=d[2]
!-->[Hidden] C:\contents of old hard drive\ Root\Documents and Settings\Documents and Settings\Jesse Wilson\Local Settings\Temporary Internet Files\Content.IE5\DHN5QD49\Celeb_Photos_MothersDay;MN=93227154;wm=o;rm=1;!c=d-fls;!c=d-jav;!c=d-dxp;!c=d-pxp;sz=170x30;ptile=1;dcove=d;ord=352372570[1]ap;file=index_html;dcove=d[2]
!-->[Hidden] C:\contents of old hard drive\ Root\Documents and Settings\Documents and Settings\Jesse Wilson\Local Settings\Temporary Internet Files\Content.IE5\DHN5QD49\EntGen_Photos;MN=93220710;wm=o;rm=1;!c=d-jav;!c=d-pps;!c=d-int;!c=d-dtl;!c=d-ptl;dcopt=ist;sz=170x30;ptile=1;dcove=d;ord=352181716[1]ndex_html;dcove=d[2]
!-->[Hidden] C:\contents of old hard drive\ Root\Documents and Settings\Documents and Settings\Jesse Wilson\Local Settings\Temporary Internet Files\Content.IE5\DHN5QD49\EntGen_Style;MN=93221508;wm=o;rm=1;!c=d-jav;!c=d-dxp;!c=d-pxp;sz=300x250;ptile=1;dcove=d;ord=352215514[1]ath=wade_surgeries_ap;file=index_html;dcove=d[2]
!-->[Hidden] C:\contents of old hard drive\ Root\Documents and Settings\Documents and Settings\Jesse Wilson\Local Settings\Temporary Internet Files\Content.IE5\DHN5QD49\NOSALE_ConsMrktng;MN=93220973;wm=o;rm=1;!c=d-jav;!c=d-dxp;!c=d-pxp;sz=240x52;tile=5;dcove=d;ord=351961209[1];dcove=d;ord=352181716[1]ndex_html;dcove=d[2]
!-->[Hidden] C:\contents of old hard drive\ Root\Documents and Settings\Documents and Settings\Jesse Wilson\Local Settings\Temporary Internet Files\Content.IE5\DHN5QD49\NOSALE_ConsMrktng;MN=93220973;wm=o;rm=1;!c=d-jav;!c=d-dxp;!c=d-pxp;sz=240x52;tile=5;dcove=d;ord=352200403[1];dcove=d;ord=352181716[1]ndex_html;dcove=d[2]
!-->[Hidden] C:\contents of old hard drive\ Root\Documents and Settings\Documents and Settings\Jesse Wilson\Local Settings\Temporary Internet Files\Content.IE5\DHN5QD49\NOSALE_ConsMrktng;MN=93220974;wm=o;rm=1;!c=d-jav;!c=d-dxp;!c=d-pxp;sz=240x60;tile=2;dcove=d;ord=351828969[1]3[1]e_surgeries_ap;file=index_html;dcove=d[2]
!-->[Hidden] C:\contents of old hard drive\ Root\Documents and Settings\Documents and Settings\Jesse Wilson\Local Settings\Temporary Internet Files\Content.IE5\DHN5QD49\NOSALE_ConsMrktng;MN=93220974;wm=o;rm=1;!c=d-jav;!c=d-dxp;!c=d-pxp;sz=240x60;tile=2;dcove=d;ord=351973897[1]3[1]e_surgeries_ap;file=index_html;dcove=d[2]
!-->[Hidden] C:\contents of old hard drive\ Root\Documents and Settings\Documents and Settings\Jesse Wilson\Local Settings\Temporary Internet Files\Content.IE5\DHN5QD49\NOSALE_ConsMrktng;MN=93220974;wm=o;rm=1;!c=d-jav;!c=d-dxp;!c=d-pxp;sz=240x60;tile=2;dcove=d;ord=352212260[1]3[1]e_surgeries_ap;file=index_html;dcove=d[2]
!-->[Hidden] C:\contents of old hard drive\ Root\Documents and Settings\Documents and Settings\Jesse Wilson\Local Settings\Temporary Internet Files\Content.IE5\DHN5QD49\NOSALE_ConsMrktng;MN=93220974;wm=o;rm=1;!c=d-jav;!c=d-dxp;!c=d-pxp;sz=240x60;tile=2;dcove=d;ord=352230336[1]3[1]e_surgeries_ap;file=index_html;dcove=d[2]
!-->[Hidden] C:\contents of old hard drive\ Root\Documents and Settings\Documents and Settings\Jesse Wilson\Local Settings\Temporary Internet Files\Content.IE5\DHN5QD49\NOSALE_ConsMrktng;MN=93220974;wm=o;rm=1;!c=d-jav;!c=d-dxp;!c=d-pxp;sz=240x60;tile=2;dcove=d;ord=352235343[1]3[1]e_surgeries_ap;file=index_html;dcove=d[2]
!-->[Hidden] C:\contents of old hard drive\ Root\Documents and Settings\Documents and Settings\Jesse Wilson\Local Settings\Temporary Internet Files\Content.IE5\DHN5QD49\NOSALE_ConsMrktng;MN=93220974;wm=o;rm=1;!c=d-jav;!c=d-dxp;!c=d-pxp;sz=240x60;tile=3;dcove=d;ord=352287117[1]3[1]e_surgeries_ap;file=index_html;dcove=d[2]
!-->[Hidden] C:\contents of old hard drive\ Root\Documents and Settings\Documents and Settings\Jesse Wilson\Local Settings\Temporary Internet Files\Content.IE5\DHN5QD49\NOSALE_ConsMrktng;MN=93220974;wm=o;rm=1;!c=d-jav;!c=d-dxp;!c=d-pxp;sz=240x60;tile=3;dcove=d;ord=352327926[1]3[1]e_surgeries_ap;file=index_html;dcove=d[2]
!-->[Hidden] C:\contents of old hard drive\ Root\Documents and Settings\Documents and Settings\Jesse Wilson\Local Settings\Temporary Internet Files\Content.IE5\DHN5QD49\NOSALE_ConsMrktng;MN=93220974;wm=o;rm=1;!c=d-jav;!c=d-dxp;!c=d-pxp;sz=240x60;tile=3;dcove=d;ord=352372570[1]3[1]e_surgeries_ap;file=index_html;dcove=d[2]
!-->[Hidden] C:\contents of old hard drive\ Root\Documents and Settings\Documents and Settings\Jesse Wilson\Local Settings\Temporary Internet Files\Content.IE5\DHN5QD49\NOSALE_ConsMrktng;MN=93220974;wm=o;rm=1;!c=d-jav;!c=d-dxp;!c=d-pxp;sz=240x60;tile=3;dcove=d;ord=352411526[1]3[1]e_surgeries_ap;file=index_html;dcove=d[2]
!-->[Hidden] C:\contents of old hard drive\ Root\Documents and Settings\Documents and Settings\Jesse Wilson\Local Settings\Temporary Internet Files\Content.IE5\FG2QSTUJ\;spt=;ptyp=main;path=MAIN;file=poll_exclude_html;dcove=d;sz=178x37;dcopt=undefined;ptile=1;ord=860878213139[2]2445175[1]=352145734[1]
!-->[Hidden] C:\contents of old hard drive\ Root\Documents and Settings\Documents and Settings\Jesse Wilson\Local Settings\Temporary Internet Files\Content.IE5\FG2QSTUJ\EntGen_PhotosMain;MN=93223123;wm=o;rm=1;!c=d-jav;!c=d-pnd;!c=d-pps;dcopt=ist;sz=300x250;ptile=1;dcove=d;ord=351961209[1]=352145734[1]
!-->[Hidden] C:\contents of old hard drive\ Root\Documents and Settings\Documents and Settings\Jesse Wilson\Local Settings\Temporary Internet Files\Content.IE5\FG2QSTUJ\EntGen_PhotosMain;MN=93223123;wm=o;rm=1;!c=d-jav;!c=d-pnd;!c=d-pps;dcopt=ist;sz=300x250;ptile=1;dcove=d;ord=352243344[1]=352145734[1]
!-->[Hidden] C:\contents of old hard drive\ Root\Documents and Settings\Documents and Settings\Jesse Wilson\Local Settings\Temporary Internet Files\Content.IE5\FG2QSTUJ\EntGen_PhotosMain;MN=93223123;wm=o;rm=1;!c=d-jav;!c=d-pnd;!c=d-pps;dcopt=ist;sz=300x250;ptile=1;dcove=d;ord=352445175[1]=352145734[1]
!-->[Hidden] C:\contents of old hard drive\ Root\Documents and Settings\Documents and Settings\Jesse Wilson\Local Settings\Temporary Internet Files\Content.IE5\FG2QSTUJ\EntGen_Style;MN=93221508;wm=o;rm=1;!c=d-jav;!c=d-dxp;!c=d-pxp;sz=300x250;ptile=1;dcove=d;ord=351964874[1]rd=352445175[1]=352145734[1]
!-->[Hidden] C:\contents of old hard drive\ Root\Documents and Settings\Documents and Settings\Jesse Wilson\Local Settings\Temporary Internet Files\Content.IE5\FG2QSTUJ\EntGen_Style;MN=93221508;wm=o;rm=1;!c=d-jav;!c=d-dxp;!c=d-pxp;sz=300x250;ptile=1;dcove=d;ord=352235343[1]rd=352445175[1]=352145734[1]
!-->[Hidden] C:\contents of old hard drive\ Root\Documents and Settings\Documents and Settings\Jesse Wilson\Local Settings\Temporary Internet Files\Content.IE5\FG2QSTUJ\NOSALE_ConsMrktng;MN=93220973;wm=o;rm=1;!c=d-jav;!c=d-dxp;!c=d-pxp;sz=240x52;tile=5;dcove=d;ord=352032691[1];path=05;path=16;path=patrick_patterson;fi[2]
!-->[Hidden] C:\contents of old hard drive\ Root\Documents and Settings\Documents and Settings\Jesse Wilson\Local Settings\Temporary Internet Files\Content.IE5\FG2QSTUJ\NOSALE_ConsMrktng;MN=93220973;wm=o;rm=1;!c=d-jav;!c=d-dxp;!c=d-pxp;sz=240x52;tile=5;dcove=d;ord=352243344[1]6[1]
!-->[Hidden] C:\contents of old hard drive\ Root\Documents and Settings\Documents and Settings\Jesse Wilson\Local Settings\Temporary Internet Files\Content.IE5\FG2QSTUJ\NOSALE_ConsMrktng;MN=93220973;wm=o;rm=1;!c=d-jav;!c=d-dxp;!c=d-pxp;sz=240x52;tile=5;dcove=d;ord=352316790[1]6[1]
!-->[Hidden] C:\contents of old hard drive\ Root\Documents and Settings\Documents and Settings\Jesse Wilson\Local Settings\Temporary Internet Files\Content.IE5\FG2QSTUJ\NOSALE_ConsMrktng;MN=93220974;wm=o;rm=1;!c=d-jav;!c=d-dxp;!c=d-pxp;sz=240x60;tile=2;dcove=d;ord=351936283[1]6[1]
!-->[Hidden] C:\contents of old hard drive\ Root\Documents and Settings\Documents and Settings\Jesse Wilson\Local Settings\Temporary Internet Files\Content.IE5\FG2QSTUJ\NOSALE_ConsMrktng;MN=93220974;wm=o;rm=1;!c=d-jav;!c=d-dxp;!c=d-pxp;sz=240x60;tile=2;dcove=d;ord=351952716[1]6[1]
!-->[Hidden] C:\contents of old hard drive\ Root\Documents and Settings\Documents and Settings\Jesse Wilson\Local Settings\Temporary Internet Files\Content.IE5\FG2QSTUJ\NOSALE_ConsMrktng;MN=93220974;wm=o;rm=1;!c=d-jav;!c=d-dxp;!c=d-pxp;sz=240x60;tile=2;dcove=d;ord=351964874[1]6[1]
!-->[Hidden] C:\contents of old hard drive\ Root\Documents and Settings\Documents and Settings\Jesse Wilson\Local Settings\Temporary Internet Files\Content.IE5\FG2QSTUJ\NOSALE_ConsMrktng;MN=93220974;wm=o;rm=1;!c=d-jav;!c=d-dxp;!c=d-pxp;sz=240x60;tile=2;dcove=d;ord=352013414[1]6[1]
!-->[Hidden] C:\contents of old hard drive\ Root\Documents and Settings\Documents and Settings\Jesse Wilson\Local Settings\Temporary Internet Files\Content.IE5\FG2QSTUJ\NOSALE_ConsMrktng;MN=93220974;wm=o;rm=1;!c=d-jav;!c=d-dxp;!c=d-pxp;sz=240x60;tile=2;dcove=d;ord=352026533[1];path=05;path=16;path=patrick_patterson;fi[2]
!-->[Hidden] C:\contents of old hard drive\ Root\Documents and Settings\Documents and Settings\Jesse Wilson\Local Settings\Temporary Internet Files\Content.IE5\FG2QSTUJ\NOSALE_ConsMrktng;MN=93220974;wm=o;rm=1;!c=d-jav;!c=d-dxp;!c=d-pxp;sz=240x60;tile=2;dcove=d;ord=352226761[1]352445175[1]=352145734[1]
!-->[Hidden] C:\contents of old hard drive\ Root\Documents and Settings\Documents and Settings\Jesse Wilson\Local Settings\Temporary Internet Files\Content.IE5\FG2QSTUJ\NOSALE_ConsMrktng;MN=93220974;wm=o;rm=1;!c=d-jav;!c=d-dxp;!c=d-pxp;sz=240x60;tile=3;dcove=d;ord=352090424[1]352445175[1]=352145734[1]
!-->[Hidden] C:\contents of old hard drive\ Root\Documents and Settings\Documents and Settings\Jesse Wilson\Local Settings\Temporary Internet Files\Content.IE5\FG2QSTUJ\NOSALE_ConsMrktng;MN=93220974;wm=o;rm=1;!c=d-jav;!c=d-dxp;!c=d-pxp;sz=240x60;tile=3;dcove=d;ord=352109101[1]352445175[1]=352145734[1]
!-->[Hidden] C:\contents of old hard drive\ Root\Documents and Settings\Documents and Settings\Jesse Wilson\Local Settings\Temporary Internet Files\Content.IE5\FG2QSTUJ\NOSALE_ConsMrktng;MN=93220974;wm=o;rm=1;!c=d-jav;!c=d-dxp;!c=d-pxp;sz=240x60;tile=3;dcove=d;ord=352160565[1]352445175[1]=352145734[1]
!-->[Hidden] C:\contents of old hard drive\ Root\Documents and Settings\Documents and Settings\Jesse Wilson\Local Settings\Temporary Internet Files\Content.IE5\FG2QSTUJ\NOSALE_ConsMrktng;MN=93220974;wm=o;rm=1;!c=d-jav;!c=d-dxp;!c=d-pxp;sz=240x60;tile=3;dcove=d;ord=352248201[1]352445175[1]=352145734[1]
!-->[Hidden] C:\contents of old hard drive\ Root\Documents and Settings\Documents and Settings\Jesse Wilson\Local Settings\Temporary Internet Files\Content.IE5\FG2QSTUJ\NOSALE_ConsMrktng;MN=93220974;wm=o;rm=1;!c=d-jav;!c=d-dxp;!c=d-pxp;sz=240x60;tile=3;dcove=d;ord=352331902[1]352445175[1]=352145734[1]
!-->[Hidden] C:\contents of old hard drive\ Root\Documents and Settings\Documents and Settings\Jesse Wilson\Local Settings\Temporary Internet Files\Content.IE5\FG2QSTUJ\NOSALE_ConsMrktng;MN=93220974;wm=o;rm=1;!c=d-jav;!c=d-dxp;!c=d-pxp;sz=240x60;tile=3;dcove=d;ord=352348195[1]352445175[1]=352145734[1]
!-->[Hidden] C:\contents of old hard drive\ Root\Documents and Settings\Documents and Settings\Jesse Wilson\Local Settings\Temporary Internet Files\Content.IE5\FG2QSTUJ\NOSALE_ConsMrktng;MN=93220974;wm=o;rm=1;!c=d-jav;!c=d-dxp;!c=d-pxp;sz=240x60;tile=3;dcove=d;ord=352360873[1]352445175[1]=352145734[1]
!-->[Hidden] C:\contents of old hard drive\ Root\Documents and Settings\Documents and Settings\Jesse Wilson\Local Settings\Temporary Internet Files\Content.IE5\FG2QSTUJ\NOSALE_ConsMrktng;MN=93220974;wm=o;rm=1;!c=d-jav;!c=d-dxp;!c=d-pxp;sz=240x60;tile=4;dcove=d;ord=352308929[1]352445175[1]=352145734[1]
!-->[Hidden] C:\contents of old hard drive\ Root\Documents and Settings\Documents and Settings\Jesse Wilson\Local Settings\Temporary Internet Files\Content.IE5\JYWIP0TT\;spt=;ptyp=main;path=MAIN;file=poll_exclude_html;dcove=d;sz=178x37;dcopt=undefined;ptile=1;ord=378099927327[2]cove=d;ord=352035956[1]=true
!-->[Hidden] C:\contents of old hard drive\ Root\Documents and Settings\Documents and Settings\Jesse Wilson\Local Settings\Temporary Internet Files\Content.IE5\JYWIP0TT\Celeb_Photos_MothersDay;MN=93227154;wm=o;rm=1;!c=d-fls;!c=d-jav;!c=d-dxp;!c=d-pxp;sz=170x30;ptile=1;dcove=d;ord=352327926[1]ap;file=index_html;dcove=d[2]
!-->[Hidden] C:\contents of old hard drive\ Root\Documents and Settings\Documents and Settings\Jesse Wilson\Local Settings\Temporary Internet Files\Content.IE5\JYWIP0TT\EntGen_NewsMain;MN=93223121;wm=o;rm=1;!c=d-jav;!c=d-pnd;!c=d-pps;sz=300x250;ptile=2;dcove=d;ord=352536416[1]ord=352327926[1]ap;file=index_html;dcove=d[2]
!-->[Hidden] C:\contents of old hard drive\ Root\Documents and Settings\Documents and Settings\Jesse Wilson\Local Settings\Temporary Internet Files\Content.IE5\JYWIP0TT\EntGen_Photos;MN=93220709;wm=o;rm=1;!c=d-jav;!c=d-pps;dcopt=ist;sz=300x250;ptile=1;dcove=d;ord=351952716[1]]&u_tz=-240&u_his=5&u_java=true
!-->[Hidden] C:\contents of old hard drive\ Root\Documents and Settings\Documents and Settings\Jesse Wilson\Local Settings\Temporary Internet Files\Content.IE5\JYWIP0TT\EntGen_Photos;MN=93220710;wm=o;rm=1;!c=d-jav;!c=d-pps;!c=d-int;!c=d-dtl;!c=d-ptl;dcopt=ist;sz=170x30;ptile=1;dcove=d;ord=352035956[1]=true
!-->[Hidden] C:\contents of old hard drive\ Root\Documents and Settings\Documents and Settings\Jesse Wilson\Local Settings\Temporary Internet Files\Content.IE5\JYWIP0TT\EntGen_Style;MN=93221508;wm=o;rm=1;!c=d-jav;!c=d-dxp;!c=d-pxp;sz=300x250;ptile=1;dcove=d;ord=352000856[1]e=1;dcove=d;ord=352035956[1]=true
!-->[Hidden] C:\contents of old hard drive\ Root\Documents and Settings\Documents and Settings\Jesse Wilson\Local Settings\Temporary Internet Files\Content.IE5\JYWIP0TT\EntGen_Style;MN=93221508;wm=o;rm=1;!c=d-jav;!c=d-dxp;!c=d-pxp;sz=300x250;ptile=1;dcove=d;ord=352224287[1]e=1;dcove=d;ord=352035956[1]=true
!-->[Hidden] C:\contents of old hard drive\ Root\Documents and Settings\Documents and Settings\Jesse Wilson\Local Settings\Temporary Internet Files\Content.IE5\JYWIP0TT\EntGen_Style;MN=93221508;wm=o;rm=1;!c=d-jav;!c=d-dxp;!c=d-pxp;sz=300x250;ptile=1;dcove=d;ord=352226761[1]e=1;dcove=d;ord=352035956[1]=true
!-->[Hidden] C:\contents of old hard drive\ Root\Documents and Settings\Documents and Settings\Jesse Wilson\Local Settings\Temporary Internet Files\Content.IE5\JYWIP0TT\EntGen_Style;MN=93221508;wm=o;rm=1;!c=d-jav;!c=d-dxp;!c=d-pxp;sz=300x250;ptile=1;dcove=d;ord=352230336[1]e=1;dcove=d;ord=352035956[1]=true
!-->[Hidden] C:\contents of old hard drive\ Root\Documents and Settings\Documents and Settings\Jesse Wilson\Local Settings\Temporary Internet Files\Content.IE5\JYWIP0TT\NOSALE_ConsMrktng;MN=93220973;wm=o;rm=1;!c=d-jav;!c=d-dxp;!c=d-pxp;sz=240x52;tile=6;dcove=d;ord=352536416[1]ord=352327926[1]ap;file=index_html;dcove=d[2]
!-->[Hidden] C:\contents of old hard drive\ Root\Documents and Settings\Documents and Settings\Jesse Wilson\Local Settings\Temporary Internet Files\Content.IE5\JYWIP0TT\NOSALE_ConsMrktng;MN=93220974;wm=o;rm=1;!c=d-jav;!c=d-dxp;!c=d-pxp;sz=240x60;tile=2;dcove=d;ord=351802310[1]ord=352327926[1]ap;file=index_html;dcove=d[2]
!-->[Hidden] C:\contents of old hard drive\ Root\Documents and Settings\Documents and Settings\Jesse Wilson\Local Settings\Temporary Internet Files\Content.IE5\JYWIP0TT\NOSALE_ConsMrktng;MN=93220974;wm=o;rm=1;!c=d-jav;!c=d-dxp;!c=d-pxp;sz=240x60;tile=2;dcove=d;ord=351988728[1]ord=352327926[1]ap;file=index_html;dcove=d[2]
!-->[Hidden] C:\contents of old hard drive\ Root\Documents and Settings\Documents and Settings\Jesse Wilson\Local Settings\Temporary Internet Files\Content.IE5\JYWIP0TT\NOSALE_ConsMrktng;MN=93220974;wm=o;rm=1;!c=d-jav;!c=d-dxp;!c=d-pxp;sz=240x60;tile=2;dcove=d;ord=351993685[1]5516,5855,5880,6298,6520,6582,6997,7313,77[1].htm
!-->[Hidden] C:\contents of old hard drive\ Root\Documents and Settings\Documents and Settings\Jesse Wilson\Local Settings\Temporary Internet Files\Content.IE5\JYWIP0TT\NOSALE_ConsMrktng;MN=93220974;wm=o;rm=1;!c=d-jav;!c=d-dxp;!c=d-pxp;sz=240x60;tile=2;dcove=d;ord=351997751[1]&u_tz=-240&u_his=5&u_java=true
!-->[Hidden] C:\contents of old hard drive\ Root\Documents and Settings\Documents and Settings\Jesse Wilson\Local Settings\Temporary Internet Files\Content.IE5\JYWIP0TT\NOSALE_ConsMrktng;MN=93220974;wm=o;rm=1;!c=d-jav;!c=d-dxp;!c=d-pxp;sz=240x60;tile=3;dcove=d;ord=352070866[1]&u_tz=-240&u_his=5&u_java=true
!-->[Hidden] C:\contents of old hard drive\ Root\Documents and Settings\Documents and Settings\Jesse Wilson\Local Settings\Temporary Internet Files\Content.IE5\JYWIP0TT\NOSALE_ConsMrktng;MN=93220974;wm=o;rm=1;!c=d-jav;!c=d-dxp;!c=d-pxp;sz=240x60;tile=3;dcove=d;ord=352258436[1]&u_tz=-240&u_his=5&u_java=true
!-->[Hidden] C:\contents of old hard drive\ Root\Documents and Settings\Documents and Settings\Jesse Wilson\Local Settings\Temporary Internet Files\Content.IE5\JYWIP0TT\NOSALE_ConsMrktng;MN=93220974;wm=o;rm=1;!c=d-jav;!c=d-dxp;!c=d-pxp;sz=240x60;tile=3;dcove=d;ord=352275270[1]&u_tz=-240&u_his=5&u_java=true
!-->[Hidden] C:\contents of old hard drive\ Root\Documents and Settings\Documents and Settings\Jesse Wilson\Local Settings\Temporary Internet Files\Content.IE5\JYWIP0TT\NOSALE_ConsMrktng;MN=93220974;wm=o;rm=1;!c=d-jav;!c=d-dxp;!c=d-pxp;sz=240x60;tile=3;dcove=d;ord=352393070[1]&u_tz=-240&u_his=5&u_java=true
!-->[Hidden] C:\contents of old hard drive\ Root\Documents and Settings\Documents and Settings\Jesse Wilson\Local Settings\Temporary Internet Files\Content.IE5\JYWIP0TT\NOSALE_ConsMrktng;MN=93220974;wm=o;rm=1;!c=d-jav;!c=d-dxp;!c=d-pxp;sz=240x60;tile=4;dcove=d;ord=352429132[1]&u_tz=-240&u_his=5&u_java=true
!-->[Hidden] C:\contents of old hard drive\ Root\Documents and Settings\Documents and Settings\Jesse Wilson\Local Settings\Temporary Internet Files\Content.IE5\LVZDBTJ0\promotion1;sz=300x35;kch=3000513466;kbg=FFFFFF;kgender=m;kage=22;kvideoid=Nihi_cbGmYI;ord=3449899939306422[2]dcove=d;sz=728x90;dcopt=ist;ptile=1;ord=3[2]
!-->[Hidden] C:\contents of old hard drive\ Root\Documents and Settings\Documents and Settings\Jesse Wilson\Local Settings\Temporary Internet Files\Content.IE5\LVZDBTJ0\_default;sz=160x600;kch=1187796739;kbg=FFFFFF;ksearch=auld%20lang%20syne%2C%20guitar;kr=H;kgender=m;kage=22;ord=1047365256149693[2]e=d;sz=300x250;dcop[2]
!-->[Hidden] C:\contents of old hard drive\ Root\Documents and Settings\Documents and Settings\Jesse Wilson\Local Settings\Temporary Internet Files\Content.IE5\LVZDBTJ0\_default;sz=160x600;kch=1187796739;kbg=FFFFFF;ksearch=journey%2C%20lights;kr=H;kgender=m;kage=22;ord=3647609094706404[2].5149693[2]e=d;sz=300x250;dcop[2]
!-->[Hidden] C:\contents of old hard drive\ Root\Documents and Settings\Documents and Settings\Jesse Wilson\Local Settings\Temporary Internet Files\Content.IE5\LVZDBTJ0\_default;sz=160x600;kch=1187796739;kbg=FFFFFF;ksearch=journey;kr=F;kgender=m;kage=22;ord=1263226487403537[2].54706404[2].5149693[2]e=d;sz=300x250;dcop[2]
!-->[Hidden] C:\contents of old hard drive\ Root\Documents and Settings\Documents and Settings\Jesse Wilson\Local Settings\Temporary Internet Files\Content.IE5\LVZDBTJ0\_default;sz=728x90;kch=1600166264;kbg=FFFFFF;ksearch=auld%20lang%20syne;kr=H;kgender=m;kage=22;ord=3879345388584057[2]2].5149693[2]e=d;sz=300x250;dcop[2]
!-->[Hidden] C:\contents of old hard drive\ Root\Documents and Settings\Documents and Settings\Jesse Wilson\Local Settings\Temporary Internet Files\Content.IE5\LVZDBTJ0\_default;sz=728x90;kch=1600166264;kbg=FFFFFF;ksearch=bonamassa;kr=F;kgender=m;kage=22;ord=1209306532647692[2]584057[2]2].5149693[2]e=d;sz=300x250;dcop[2]
!-->[Hidden] C:\contents of old hard drive\ Root\Documents and Settings\Documents and Settings\Jesse Wilson\Local Settings\Temporary Internet Files\Content.IE5\LVZDBTJ0\_default;sz=728x90;kch=1600166264;kbg=FFFFFF;ksearch=majerle;kr=F;kgender=m;kage=22;ord=8362624226432976[2]2]584057[2]2].5149693[2]e=d;sz=300x250;dcop[2]
!-->[Hidden] C:\contents of old hard drive\ Root\Documents and Settings\Documents and Settings\Jesse Wilson\Local Settings\Temporary Internet Files\Content.IE5\LVZDBTJ0\_default;sz=728x90;kch=1600166264;kbg=FFFFFF;ksearch=warren%20haynes;kr=H;kgender=m;kage=22;ord=4336925795984560[2][2]2].5149693[2]e=d;sz=300x250;dcop[2]
!-->[Hidden] C:\contents of old hard drive\ Root\Documents and Settings\Documents and Settings\Jesse Wilson\Local Settings\Temporary Internet Files\Content.IE5\MU4KI7KS\;spt=;ptyp=main;path=MAIN;file=poll_exclude_html;dcove=d;sz=178x37;dcopt=undefined;ptile=1;ord=197302187284[2]ge[1].htm
!-->[Hidden] C:\contents of old hard drive\ Root\Documents and Settings\Documents and Settings\Jesse Wilson\Local Settings\Temporary Internet Files\Content.IE5\MU4KI7KS\;spt=;ptyp=main;path=MAIN;file=poll_exclude_html;dcove=d;sz=178x37;dcopt=undefined;ptile=1;ord=448640474175[2]ge[1].htm
!-->[Hidden] C:\contents of old hard drive\ Root\Documents and Settings\Documents and Settings\Jesse Wilson\Local Settings\Temporary Internet Files\Content.IE5\MU4KI7KS\;spt=;ptyp=main;path=MAIN;file=poll_exclude_html;dcove=d;sz=178x37;dcopt=undefined;ptile=1;ord=483902917540[2]ge[1].htm
!-->[Hidden] C:\contents of old hard drive\ Root\Documents and Settings\Documents and Settings\Jesse Wilson\Local Settings\Temporary Internet Files\Content.IE5\MU4KI7KS\;spt=;ptyp=main;path=MAIN;file=poll_exclude_html;dcove=d;sz=178x37;dcopt=undefined;ptile=1;ord=539318423211[2]ge[1].htm
!-->[Hidden] C:\contents of old hard drive\ Root\Documents and Settings\Documents and Settings\Jesse Wilson\Local Settings\Temporary Internet Files\Content.IE5\XBBRHX46\_default;sz=160x600;kch=1187796739;kbg=FFFFFF;ksearch=strong%20bag;kr=H;kgender=m;kage=22;ord=6528489526419867[2].htm
!-->[Hidden] C:\contents of old hard drive\ Root\Documents and Settings\Documents and Settings\Jesse Wilson\Local Settings\Temporary Internet Files\Content.IE5\XBBRHX46\_default;sz=300x35;kch=3000513466;kbg=FFFFFF;kgender=m;kage=22;kvideoid=Nihi_cbGmYI;ord=5980382175543324[1]867[2].htm
!-->[Hidden] C:\contents of old hard drive\ Root\Documents and Settings\Documents and Settings\Jesse Wilson\Local Settings\Temporary Internet Files\Content.IE5\XBBRHX46\_default;sz=728x90;kch=1600166264;kbg=FFFFFF;ksearch=i%27m%20yours;kr=F;kgender=m;kage=22;ord=5894735595533764[2].htm
!-->[Hidden] C:\contents of old hard drive\ Root\Documents and Settings\Documents and Settings\Jesse Wilson\Local Settings\Temporary Internet Files\Content.IE5\XBBRHX46\_default;sz=728x90;kch=1600166264;kbg=FFFFFF;ksearch=strong%20bad;kr=F;kgender=m;kage=22;ord=6882626594317379[2]].htm
!-->[Hidden] C:\contents of old hard drive\ Root\Documents and Settings\Documents and Settings\Jesse Wilson\Local Settings\Temporary Internet Files\Content.IE5\XNVSQW9F\_default;sz=160x600;kch=1187796739;kbg=FFFFFF;ksearch=auld%20lang%20syne;kr=H;kgender=m;kage=22;ord=6555763769949594[2]_4_html;dcove=d;sz=300x250;dcop[2]
!-->[Hidden] C:\contents of old hard drive\ Root\Documents and Settings\Documents and Settings\Jesse Wilson\Local Settings\Temporary Internet Files\Content.IE5\XNVSQW9F\_default;sz=160x600;kch=1187796739;kbg=FFFFFF;ksearch=shawn%20lane;kr=F;kgender=m;kage=22;ord=2764021241506655[2]594[2]_4_html;dcove=d;sz=300x250;dcop[2]
!-->[Hidden] C:\contents of old hard drive\ Root\Documents and Settings\Documents and Settings\Jesse Wilson\Local Settings\Temporary Internet Files\Content.IE5\XNVSQW9F\_default;sz=728x90;kch=1600166264;kbg=FFFFFF;ksearch=auld%20lang%20syne;kr=F;kgender=m;kage=22;ord=4874300868576396[2]]_4_html;dcove=d;sz=300x250;dcop[2]
!-->[Hidden] C:\contents of old hard drive\ Root\Documents and Settings\Documents and Settings\Jesse Wilson\Local Settings\Temporary Internet Files\Content.IE5\XNVSQW9F\_default;sz=728x90;kch=1600166264;kbg=FFFFFF;ksearch=bonamassa;kr=F;kgender=m;kage=22;ord=6871855996324830[2]576396[2]]_4_html;dcove=d;sz=300x250;dcop[2]
!-->[Hidden] C:\contents of old hard drive\ Root\Documents and Settings\Documents and Settings\Jesse Wilson\Local Settings\Temporary Internet Files\Content.IE5\XNVSQW9F\_default;sz=728x90;kch=1600166264;kbg=FFFFFF;ksearch=shawn%20lane%2C%20timmons;kr=F;kgender=m;kage=22;ord=3143629588182777[2].5dcove=d;sz=300x250;dcop[2]
!-->[Hidden] C:\contents of old hard drive\ Root\Documents and Settings\Documents and Settings\Jesse Wilson\Local Settings\Temporary Internet Files\Content.IE5\Z6FQVBIK\;spt=basketball_nba;path=basketball;path=nba;path=standings;file=index_html;dcove=d;sz=728x90;dcopt=ist;ptile=1;ord=117066857887[2]udgments_one;file=i[2]
!-->[Hidden] C:\contents of old hard drive\ Root\Documents and Settings\Documents and Settings\Jesse Wilson\Local Settings\Temporary Internet Files\Content.IE5\Z6FQVBIK\activity;src=1411783;met=1;v=1;pid=16626030;aid=96484070;ko=0;cid=20681347;rid=20699240;rv=2;&timestamp=1178285638686;eid1=2;ecn1=1;etm1=10;[1].gife=i[2]
!-->[Hidden] C:\contents of old hard drive\ Root\Documents and Settings\Documents and Settings\Jesse Wilson\Local Settings\Temporary Internet Files\Content.IE5\Z6FQVBIK\promotion1;sz=300x35;kch=3000513466;kbg=FFFFFF;kgender=m;kage=22;kvideoid=Nihi_cbGmYI;ord=2618656588889879[1]04;path=28;path=snap_judgments_one;file=i[2]
!-->[Hidden] C:\contents of old hard drive\ Root\Documents and Settings\Documents and Settings\Jesse Wilson\Local Settings\Temporary Internet Files\Content.IE5\Z6FQVBIK\seller;dcopt=ist;!cat=statichp;seg=GL_RTM_MaleBuyers_101005;sz=275x300;tile=1;ord=1178147727443;[1].htmewart_mandel;path=05;path=02;path=cfb_mailbag;f[2]
!-->[Hidden] C:\contents of old hard drive\ Root\Documents and Settings\Documents and Settings\Jesse Wilson\Local Settings\Temporary Internet Files\Content.IE5\ZQLZHT8U\;spt=;writ=stewart_mandel_college_football_mailbag;slug=cfb;slug=mailbag;path=2007;path=writers;path=stewart_mandel;path=05;path=02;path=cfb_mailbag;f[2]=true
!-->[Hidden] C:\contents of old hard drive\ Root\Documents and Settings\Documents and Settings\Jesse Wilson\Local Settings\Temporary Internet Files\Content.IE5\ZQLZHT8U\;spt=football_nfl;ptyp=gallery;path=multimedia;path=photo_gallery;path=0704;path=gallery_nfl_draft_reaches;file=content_3_html;dcove=d;sz=300x250;dcop[2]=true
!-->[Hidden] C:\contents of old hard drive\ Root\Documents and Settings\Documents and Settings\Jesse Wilson\Local Settings\Temporary Internet Files\Content.IE5\ZQLZHT8U\music;sz=728x90;kch=2179803025;kbg=FFFFFF;kr=F;kgender=m;kage=22;kpu=suitemins;kvideoid=_TDcQdgGi5U;ord=8857826754554544[2][2].5u_tz=-240&u_his=11&u_java=true
!-->[Hidden] C:\contents of old hard drive\ Root\Documents and Settings\Documents and Settings\Jesse Wilson\Local Settings\Temporary Internet Files\Content.IE5\ZQLZHT8U\_default;sz=160x600;kch=1187796739;kbg=FFFFFF;ksearch=auld%20lang%20syne;kr=H;kgender=m;kage=22;ord=513860758215994[2].63_html;dcove=d;sz=300x250;dcop[2]=true
!-->[Hidden] C:\contents of old hard drive\ Root\Documents and Settings\Documents and Settings\Jesse Wilson\Local Settings\Temporary Internet Files\Content.IE5\ZQLZHT8U\_default;sz=160x600;kch=1187796739;kbg=FFFFFF;ksearch=bonamassa;kr=F;kgender=m;kage=22;ord=8879793484811232[2]e=content_3_html;dcove=d;sz=300x250;dcop[2]=true
!-->[Hidden] C:\contents of old hard drive\ Root\Documents and Settings\Documents and Settings\Jesse Wilson\Local Settings\Temporary Internet Files\Content.IE5\ZQLZHT8U\_default;sz=160x600;kch=1187796739;kbg=FFFFFF;ksearch=bonamassa;kr=F;kgender=m;kage=22;ord=8881267661683227[2]u_aw=1280&u_cd=32&u_tz=-240&u_his=11&u_java=true
!-->[Hidden] C:\contents of old hard drive\ Root\Documents and Settings\Documents and Settings\Jesse Wilson\Local Settings\Temporary Internet Files\Content.IE5\ZQLZHT8U\_default;sz=160x600;kch=1187796739;kbg=FFFFFF;ksearch=bonamassa;kr=H;kgender=m;kage=22;ord=5749661448323748[2]u_aw=1280&u_cd=32&u_tz=-240&u_his=11&u_java=true
!-->[Hidden] C:\contents of old hard drive\ Root\Documents and Settings\Documents and Settings\Jesse Wilson\Local Settings\Temporary Internet Files\Content.IE5\ZQLZHT8U\_default;sz=160x600;kch=1187796739;kbg=FFFFFF;ksearch=i%27m%20yours;kr=F;kgender=m;kage=22;ord=2610773971550064[2].5280&u_cd=32&u_tz=-240&u_his=11&u_java=true
!-->[Hidden] C:\contents of old hard drive\ Root\Documents and Settings\Documents and Settings\Jesse Wilson\Local Settings\Temporary Internet Files\Content.IE5\ZQLZHT8U\_default;sz=160x600;kch=1187796739;kbg=FFFFFF;ksearch=majerle;kr=F;kgender=m;kage=22;ord=6170302931781499[2]064[2].5280&u_cd=32&u_tz=-240&u_his=11&u_java=true
!-->[Hidden] C:\contents of old hard drive\ Root\Documents and Settings\Documents and Settings\Jesse Wilson\Local Settings\Temporary Internet Files\Content.IE5\ZQLZHT8U\_default;sz=160x600;kch=1187796739;kbg=FFFFFF;ksearch=shawn%20lane%2C%20timmons;kr=F;kgender=m;kage=22;ord=1477565066602081[2].5u_tz=-240&u_his=11&u_java=true
!-->[Hidden] C:\contents of old hard drive\ Root\Documents and Settings\Documents and Settings\Jesse Wilson\Local Settings\Temporary Internet Files\Content.IE5\ZQLZHT8U\_default;sz=728x90;kch=1600166264;kbg=FFFFFF;ksearch=auld%20lang%20syne;kr=H;kgender=m;kage=22;ord=8821572712241480[2]02081[2].5u_tz=-240&u_his=11&u_java=true
!-->[Hidden] C:\contents of old hard drive\ Root\Documents and Settings\Documents and Settings\Jesse Wilson\Local Settings\Temp\Temporary Internet Files\Content.IE5\23ONFST8\entertainment;sz=450x60;kch=2179803025;kbg=FFFFFF;kkw=Arts++Animation+Comedy+Entertainment;ord=9030106178911652[2]6]
!-->[Hidden] C:\contents of old hard drive\ Root\Documents and Settings\Documents and Settings\Jesse Wilson\Local Settings\Temp\Temporary Internet Files\Content.IE5\23ONFST8\entertainment;sz=450x60;kch=2179803025;kbg=FFFFFF;kkw=Music+Entertainment;ord=6893241094481381[2]30106178911652[2]6]
!-->[Hidden] C:\contents of old hard drive\ Root\Documents and Settings\Documents and Settings\Jesse Wilson\Local Settings\Temp\Temporary Internet Files\Content.IE5\23ONFST8\entertainment_inv;sz=728x90;kch=2179803025;kbg=FFFFFF;kkw=Music+Entertainment;ord=3287989125393927[2].5entomatoes[6]
!-->[Hidden] C:\contents of old hard drive\ Root\Documents and Settings\Documents and Settings\Jesse Wilson\Local Settings\Temp\Temporary Internet Files\Content.IE5\23ONFST8\news&blogs_inv;sz=728x90;kch=2179803025;kbg=FFFFFF;kkw=People+News++Blogs;ord=1895939697467237[2]at+comedy+commercial+concert+cool+crazy+cute+dance+episode+fantasy+fight[3]3].68
!-->[Hidden] C:\contents of old hard drive\ Root\Documents and Settings\Documents and Settings\Jesse Wilson\Local Settings\Temp\Temporary Internet Files\Content.IE5\23ONFST8\sky_inv;sz=728x90;kch=3000513466;kbg=FFFFFF;kkw=2005+2006+amv+animation+anime+baby+band+boy+car+cat+comedy+commercial+concert+cool+crazy+cute+dance+episode+fantasy+fight+f[2].68
!-->[Hidden] C:\contents of old hard drive\ Root\Documents and Settings\Documents and Settings\Jesse Wilson\Local Settings\Temp\Temporary Internet Files\Content.IE5\23ONFST8\sky_inv;sz=728x90;kch=3000513466;kbg=FFFFFF;kkw=2005+2006+amv+animation+anime+baby+band+boy+car+cat+comedy+commercial+concert+cool+crazy+cute+dance+episode+fantasy+fight+f[3].68
!-->[Hidden] C:\contents of old hard drive\ Root\Documents and Settings\Documents and Settings\Jesse Wilson\Local Settings\Temp\Temporary Internet Files\Content.IE5\23ONFST8\sky_inv;sz=728x90;kch=3000513466;kbg=FFFFFF;kkw=2005+2006+amv+animation+anime+baby+band+boy+car+cat+comedy+commercial+concert+cool+crazy+cute+dance+episode+fantasy+fight[2]3].68
!-->[Hidden] C:\contents of old hard drive\ Root\Documents and Settings\Documents and Settings\Jesse Wilson\Local Settings\Temp\Temporary Internet Files\Content.IE5\23ONFST8\sky_inv;sz=728x90;kch=3000513466;kbg=FFFFFF;kkw=2005+2006+amv+animation+anime+baby+band+boy+car+cat+comedy+commercial+concert+cool+crazy+cute+dance+episode+fantasy+fight[3]3].68
!-->[Hidden] C:\contents of old hard drive\ Root\Documents and Settings\Documents and Settings\Jesse Wilson\Local Settings\Temp\Temporary Internet Files\Content.IE5\23ONFST8\videogames;sz=728x90;kch=2179803025;kbg=FFFFFF;kkw=Arts++Animation+Music+Video+Games;ord=6034153367697110[2]652[2]6]
!-->[Hidden] C:\contents of old hard drive\ Root\Documents and Settings\Documents and Settings\Jesse Wilson\Local Settings\Temp\Temporary Internet Files\Content.IE5\6FARAP23\Celeb_InternalPromo;MN=93221313;wm=o;rm=1;!c=d-dxp;!c=d-pxp;sz=318x113;tile=3;dcove=d;ord=415748066[2]4
!-->[Hidden] C:\contents of old hard drive\ Root\Documents and Settings\Documents and Settings\Jesse Wilson\Local Settings\Temp\Temporary Internet Files\Content.IE5\6FARAP23\Celeb_InternalPromo;MN=93221313;wm=o;rm=1;!c=d-dxp;!c=d-pxp;sz=318x113;tile=3;dcove=d;ord=416350793[2]4
!-->[Hidden] C:\contents of old hard drive\ Root\Documents and Settings\Documents and Settings\Jesse Wilson\Local Settings\Temp\Temporary Internet Files\Content.IE5\6FARAP23\EntGen_Photos;MN=93191982;wm=o;rm=1;!c=d-pnd;!c=d-pps;sz=728x90;tile=5;dcove=d;ord=416049409[2]2[2]9684
!-->[Hidden] C:\contents of old hard drive\ Root\Documents and Settings\Documents and Settings\Jesse Wilson\Local Settings\Temp\Temporary Internet Files\Content.IE5\6FARAP23\EntGen_Photos;MN=93191982;wm=o;rm=1;!c=d-pnd;!c=d-pps;sz=728x90;tile=5;dcove=d;ord=416175040[2]2[2]9684
!-->[Hidden] C:\contents of old hard drive\ Root\Documents and Settings\Documents and Settings\Jesse Wilson\Local Settings\Temp\Temporary Internet Files\Content.IE5\6FARAP23\NOSALE_ConsMrktng;MN=93220973;wm=o;rm=1;!c=d-dxp;!c=d-pxp;sz=240x52;tile=6;dcove=d;ord=415850523[2]9684
!-->[Hidden] C:\contents of old hard drive\ Root\Documents and Settings\Documents and Settings\Jesse Wilson\Local Settings\Temp\Temporary Internet Files\Content.IE5\6FARAP23\NOSALE_ConsMrktng;MN=93220973;wm=o;rm=1;!c=d-dxp;!c=d-pxp;sz=240x52;tile=6;dcove=d;ord=416350793[2]9684
!-->[Hidden] C:\contents of old hard drive\ Root\Documents and Settings\Documents and Settings\Jesse Wilson\Local Settings\Temp\Temporary Internet Files\Content.IE5\6FARAP23\NOSALE_ConsMrktng;MN=93220973;wm=o;rm=1;!c=d-dxp;!c=d-pxp;sz=240x52;tile=6;dcove=d;ord=416668099[2]9684
!-->[Hidden] C:\contents of old hard drive\ Root\Documents and Settings\Documents and Settings\Jesse Wilson\Local Settings\Temp\Temporary Internet Files\Content.IE5\6FARAP23\NOSALE_ConsMrktng;MN=93220974;wm=o;rm=1;!c=d-dxp;!c=d-pxp;sz=240x60;tile=3;dcove=d;ord=415010005[2]9684
!-->[Hidden] C:\contents of old hard drive\ Root\Documents and Settings\Documents and Settings\Jesse Wilson\Local Settings\Temp\Temporary Internet Files\Content.IE5\6FARAP23\NOSALE_ConsMrktng;MN=93220974;wm=o;rm=1;!c=d-dxp;!c=d-pxp;sz=240x60;tile=3;dcove=d;ord=415082769[2]9684
!-->[Hidden] C:\contents of old hard drive\ Root\Documents and Settings\Documents and Settings\Jesse Wilson\Local Settings\Temp\Temporary Internet Files\Content.IE5\6FARAP23\NOSALE_ConsMrktng;MN=93220974;wm=o;rm=1;!c=d-dxp;!c=d-pxp;sz=240x60;tile=3;dcove=d;ord=415251001[2]9684
!-->[Hidden] C:\contents of old hard drive\ Root\Documents and Settings\Documents and Settings\Jesse Wilson\Local Settings\Temp\Temporary Internet Files\Content.IE5\6FARAP23\NOSALE_ConsMrktng;MN=93220974;wm=o;rm=1;!c=d-dxp;!c=d-pxp;sz=240x60;tile=3;dcove=d;ord=416062869[2]9684
!-->[Hidden] C:\contents of old hard drive\ Root\Documents and Settings\Documents and Settings\Jesse Wilson\Local Settings\Temp\Temporary Internet Files\Content.IE5\6FARAP23\NOSALE_ConsMrktng;MN=93220974;wm=o;rm=1;!c=d-dxp;!c=d-pxp;sz=240x60;tile=3;dcove=d;ord=416087654[2]9684
!-->[Hidden] C:\contents of old hard drive\ Root\Documents and Settings\Documents and Settings\Jesse Wilson\Local Settings\Temp\Temporary Internet Files\Content.IE5\6FARAP23\NOSALE_ConsMrktng;MN=93220974;wm=o;rm=1;!c=d-dxp;!c=d-pxp;sz=240x60;tile=3;dcove=d;ord=416153950[2]9684
!-->[Hidden] C:\contents of old hard drive\ Root\Documents and Settings\Documents and Settings\Jesse Wilson\Local Settings\Temp\Temporary Internet Files\Content.IE5\6FARAP23\NOSALE_ConsMrktng;MN=93220974;wm=o;rm=1;!c=d-dxp;!c=d-pxp;sz=240x60;tile=3;dcove=d;ord=416158446[2]9684
!-->[Hidden] C:\contents of old hard drive\ Root\Documents and Settings\Documents and Settings\Jesse Wilson\Local Settings\Temp\Temporary Internet Files\Content.IE5\6FARAP23\NOSALE_ConsMrktng;MN=93220974;wm=o;rm=1;!c=d-dxp;!c=d-pxp;sz=240x60;tile=3;dcove=d;ord=416192826[2]9684
!-->[Hidden] C:\contents of old hard drive\ Root\Documents and Settings\Documents and Settings\Jesse Wilson\Local Settings\Temp\Temporary Internet Files\Content.IE5\6FARAP23\NOSALE_ConsMrktng;MN=93220974;wm=o;rm=1;!c=d-dxp;!c=d-pxp;sz=240x60;tile=3;dcove=d;ord=416237991[2]9684
!-->[Hidden] C:\contents of old hard drive\ Root\Documents and Settings\Documents and Settings\Jesse Wilson\Local Settings\Temp\Temporary Internet Files\Content.IE5\6FARAP23\NOSALE_ConsMrktng;MN=93220974;wm=o;rm=1;!c=d-dxp;!c=d-pxp;sz=240x60;tile=3;dcove=d;ord=416536279[2]9684
!-->[Hidden] C:\contents of old hard drive\ Root\Documents and Settings\Documents and Settings\Jesse Wilson\Local Settings\Temp\Temporary Internet Files\Content.IE5\6FARAP23\NOSALE_ConsMrktng;MN=93220974;wm=o;rm=1;!c=d-dxp;!c=d-pxp;sz=240x60;tile=4;dcove=d;ord=415389240[2]9684
!-->[Hidden] C:\contents of old hard drive\ Root\Documents and Settings\Documents and Settings\Jesse Wilson\Local Settings\Temp\Temporary Internet Files\Content.IE5\6FARAP23\NOSALE_ConsMrktng;MN=93220974;wm=o;rm=1;!c=d-dxp;!c=d-pxp;sz=240x60;tile=4;dcove=d;ord=415394678[2]9684
!-->[Hidden] C:\contents of old hard drive\ Root\Documents and Settings\Documents and Settings\Jesse Wilson\Local Settings\Temp\Temporary Internet Files\Content.IE5\6FARAP23\NOSALE_ConsMrktng;MN=93220974;wm=o;rm=1;!c=d-dxp;!c=d-pxp;sz=240x60;tile=4;dcove=d;ord=415409319[2]9684
!-->[Hidden] C:\contents of old hard drive\ Root\Documents and Settings\Documents and Settings\Jesse Wilson\Local Settings\Temp\Temporary Internet Files\Content.IE5\6FARAP23\NOSALE_ConsMrktng;MN=93220974;wm=o;rm=1;!c=d-dxp;!c=d-pxp;sz=240x60;tile=4;dcove=d;ord=415449206[2]9684
!-->[Hidden] C:\contents of old hard drive\ Root\Documents and Settings\Documents and Settings\Jesse Wilson\Local Settings\Temp\Temporary Internet Files\Content.IE5\6FARAP23\NOSALE_ConsMrktng;MN=93220974;wm=o;rm=1;!c=d-dxp;!c=d-pxp;sz=240x60;tile=4;dcove=d;ord=415457658[2]9684
!-->[Hidden] C:\contents of old hard drive\ Root\Documents and Settings\Documents and Settings\Jesse Wilson\Local Settings\Temp\Temporary Internet Files\Content.IE5\6FARAP23\NOSALE_ConsMrktng;MN=93220974;wm=o;rm=1;!c=d-dxp;!c=d-pxp;sz=240x60;tile=4;dcove=d;ord=415471428[2]9684
!-->[Hidden] C:\contents of old hard drive\ Root\Documents and Settings\Documents and Settings\Jesse Wilson\Local Settings\Temp\Temporary Internet Files\Content.IE5\6FARAP23\NOSALE_ConsMrktng;MN=93220974;wm=o;rm=1;!c=d-dxp;!c=d-pxp;sz=240x60;tile=4;dcove=d;ord=415484367[2]9684
!-->[Hidden] C:\contents of old hard drive\ Root\Documents and Settings\Documents and Settings\Jesse Wilson\Local Settings\Temp\Temporary Internet Files\Content.IE5\6FARAP23\NOSALE_ConsMrktng;MN=93220974;wm=o;rm=1;!c=d-dxp;!c=d-pxp;sz=240x60;tile=4;dcove=d;ord=415508612[2]9684
!-->[Hidden] C:\contents of old hard drive\ Root\Documents and Settings\Documents and Settings\Jesse Wilson\Local Settings\Temp\Temporary Internet Files\Content.IE5\6FARAP23\NOSALE_ConsMrktng;MN=93220974;wm=o;rm=1;!c=d-dxp;!c=d-pxp;sz=240x60;tile=4;dcove=d;ord=415528410[2]9684
!-->[Hidden] C:\contents of old hard drive\ Root\Documents and Settings\Documents and Settings\Jesse Wilson\Local Settings\Temp\Temporary Internet Files\Content.IE5\6FARAP23\NOSALE_ConsMrktng;MN=93220974;wm=o;rm=1;!c=d-dxp;!c=d-pxp;sz=240x60;tile=4;dcove=d;ord=415577971[2]9684
!-->[Hidden] C:\contents of old hard drive\ Root\Documents and Settings\Documents and Settings\Jesse Wilson\Local Settings\Temp\Temporary Internet Files\Content.IE5\6FARAP23\NOSALE_ConsMrktng;MN=93220974;wm=o;rm=1;!c=d-dxp;!c=d-pxp;sz=240x60;tile=4;dcove=d;ord=415622596[2]9684
!-->[Hidden] C:\contents of old hard drive\ Root\Documents and Settings\Documents and Settings\Jesse Wilson\Local Settings\Temp\Temporary Internet Files\Content.IE5\6FARAP23\NOSALE_ConsMrktng;MN=93220974;wm=o;rm=1;!c=d-dxp;!c=d-pxp;sz=240x60;tile=4;dcove=d;ord=415758000[2]9684
!-->[Hidden] C:\contents of old hard drive\ Root\Documents and Settings\Documents and Settings\Jesse Wilson\Local Settings\Temp\Temporary Internet Files\Content.IE5\6FARAP23\NOSALE_ConsMrktng;MN=93220974;wm=o;rm=1;!c=d-dxp;!c=d-pxp;sz=240x60;tile=4;dcove=d;ord=415806650[2]9684
!-->[Hidden] C:\contents of old hard drive\ Root\Documents and Settings\Documents and Settings\Jesse Wilson\Local Settings\Temp\Temporary Internet Files\Content.IE5\6FARAP23\NOSALE_ConsMrktng;MN=93220974;wm=o;rm=1;!c=d-dxp;!c=d-pxp;sz=240x60;tile=4;dcove=d;ord=415821632[2]9684
!-->[Hidden] C:\contents of old hard drive\ Root\Documents and Settings\Documents and Settings\Jesse Wilson\Local Settings\Temp\Temporary Internet Files\Content.IE5\6FARAP23\NOSALE_ConsMrktng;MN=93220974;wm=o;rm=1;!c=d-dxp;!c=d-pxp;sz=240x60;tile=4;dcove=d;ord=415845656[2]9684
!-->[Hidden] C:\contents of old hard drive\ Root\Documents and Settings\Documents and Settings\Jesse Wilson\Local Settings\Temp\Temporary Internet Files\Content.IE5\6FARAP23\NOSALE_ConsMrktng;MN=93220974;wm=o;rm=1;!c=d-dxp;!c=d-pxp;sz=240x60;tile=4;dcove=d;ord=415925702[2]9684
!-->[Hidden] C:\contents of old hard drive\ Root\Documents and Settings\Documents and Settings\Jesse Wilson\Local Settings\Temp\Temporary Internet Files\Content.IE5\6FARAP23\NOSALE_ConsMrktng;MN=93220974;wm=o;rm=1;!c=d-dxp;!c=d-pxp;sz=240x60;tile=4;dcove=d;ord=415960471[2]9684
!-->[Hidden] C:\contents of old hard drive\ Root\Documents and Settings\Documents and Settings\Jesse Wilson\Local Settings\Temp\Temporary Internet Files\Content.IE5\6FARAP23\_default;sz=160x600;kch=1187796739;kbg=FFFFFF;ksearch=bill%20dance;kr=R;ord=9588290525725962[2]35089684
!-->[Hidden] C:\contents of old hard drive\ Root\Documents and Settings\Documents and Settings\Jesse Wilson\Local Settings\Temp\Temporary Internet Files\Content.IE5\89030JOB\Celeb_InternalPromo;MN=93221313;wm=o;rm=1;!c=d-dxp;!c=d-pxp;sz=318x113;tile=3;dcove=d;ord=416175040[2]15147362[2]
!-->[Hidden] C:\contents of old hard drive\ Root\Documents and Settings\Documents and Settings\Jesse Wilson\Local Settings\Temp\Temporary Internet Files\Content.IE5\89030JOB\EntGen_Photos;MN=93191982;wm=o;rm=1;!c=d-pnd;!c=d-pps;sz=728x90;tile=5;dcove=d;ord=416350793[2]7[2]]=415147362[2]
!-->[Hidden] C:\contents of old hard drive\ Root\Documents and Settings\Documents and Settings\Jesse Wilson\Local Settings\Temp\Temporary Internet Files\Content.IE5\89030JOB\NOSALE_ConsMrktng;MN=93220973;wm=o;rm=1;!c=d-dxp;!c=d-pxp;sz=240x52;tile=6;dcove=d;ord=416175040[2]d=415147362[2]
!-->[Hidden] C:\contents of old hard drive\ Root\Documents and Settings\Documents and Settings\Jesse Wilson\Local Settings\Temp\Temporary Internet Files\Content.IE5\89030JOB\NOSALE_ConsMrktng;MN=93220974;wm=o;rm=1;!c=d-dxp;!c=d-pxp;sz=240x60;tile=3;dcove=d;ord=415028161[2]d=415147362[2]
!-->[Hidden] C:\contents of old hard drive\ Root\Documents and Settings\Documents and Settings\Jesse Wilson\Local Settings\Temp\Temporary Internet Files\Content.IE5\89030JOB\NOSALE_ConsMrktng;MN=93220974;wm=o;rm=1;!c=d-dxp;!c=d-pxp;sz=240x60;tile=3;dcove=d;ord=415158388[2]d=415147362[2]
!-->[Hidden] C:\contents of old hard drive\ Root\Documents and Settings\Documents and Settings\Jesse Wilson\Local Settings\Temp\Temporary Internet Files\Content.IE5\89030JOB\NOSALE_ConsMrktng;MN=93220974;wm=o;rm=1;!c=d-dxp;!c=d-pxp;sz=240x60;tile=3;dcove=d;ord=415161683[2][2]15147362[2]
!-->[Hidden] C:\contents of old hard drive\ Root\Documents and Settings\Documents and Settings\Jesse Wilson\Local Settings\Temp\Temporary Internet Files\Content.IE5\89030JOB\NOSALE_ConsMrktng;MN=93220974;wm=o;rm=1;!c=d-dxp;!c=d-pxp;sz=240x60;tile=3;dcove=d;ord=415236831[2][2]15147362[2]
!-->[Hidden] C:\contents of old hard drive\ Root\Documents and Settings\Documents and Settings\Jesse Wilson\Local Settings\Temp\Temporary Internet Files\Content.IE5\89030JOB\NOSALE_ConsMrktng;MN=93220974;wm=o;rm=1;!c=d-dxp;!c=d-pxp;sz=240x60;tile=3;dcove=d;ord=416083569[2][2]15147362[2]
!-->[Hidden] C:\contents of old hard drive\ Root\Documents and Settings\Documents and Settings\Jesse Wilson\Local Settings\Temp\Temporary Internet Files\Content.IE5\89030JOB\NOSALE_ConsMrktng;MN=93220974;wm=o;rm=1;!c=d-dxp;!c=d-pxp;sz=240x60;tile=3;dcove=d;ord=416116005[2][2]15147362[2]
!-->[Hidden] C:\contents of old hard drive\ Root\Documents and Settings\Documents and Settings\Jesse Wilson\Local Settings\Temp\Temporary Internet Files\Content.IE5\89030JOB\NOSALE_ConsMrktng;MN=93220974;wm=o;rm=1;!c=d-dxp;!c=d-pxp;sz=240x60;tile=3;dcove=d;ord=416162322[2][2]15147362[2]
!-->[Hidden] C:\contents of old hard drive\ Root\Documents and Settings\Documents and Settings\Jesse Wilson\Local Settings\Temp\Temporary Internet Files\Content.IE5\89030JOB\NOSALE_ConsMrktng;MN=93220974;wm=o;rm=1;!c=d-dxp;!c=d-pxp;sz=240x60;tile=3;dcove=d;ord=416164805[2][2]15147362[2]
!-->[Hidden] C:\contents of old hard drive\ Root\Documents and Settings\Documents and Settings\Jesse Wilson\Local Settings\Temp\Temporary Internet Files\Content.IE5\89030JOB\NOSALE_ConsMrktng;MN=93220974;wm=o;rm=1;!c=d-dxp;!c=d-pxp;sz=240x60;tile=3;dcove=d;ord=416217080[2][2]15147362[2]
!-->[Hidden] C:\contents of old hard drive\ Root\Documents and Settings\Documents and Settings\Jesse Wilson\Local Settings\Temp\Temporary Internet Files\Content.IE5\89030JOB\NOSALE_ConsMrktng;MN=93220974;wm=o;rm=1;!c=d-dxp;!c=d-pxp;sz=240x60;tile=3;dcove=d;ord=416235667[2][2]15147362[2]
!-->[Hidden] C:\contents of old hard drive\ Root\Documents and Settings\Documents and Settings\Jesse Wilson\Local Settings\Temp\Temporary Internet Files\Content.IE5\89030JOB\NOSALE_ConsMrktng;MN=93220974;wm=o;rm=1;!c=d-dxp;!c=d-pxp;sz=240x60;tile=3;dcove=d;ord=416278369[2]d=415147362[2]
!-->[Hidden] C:\contents of old hard drive\ Root\Documents and Settings\Documents and Settings\Jesse Wilson\Local Settings\Temp\Temporary Internet Files\Content.IE5\89030JOB\NOSALE_ConsMrktng;MN=93220974;wm=o;rm=1;!c=d-dxp;!c=d-pxp;sz=240x60;tile=3;dcove=d;ord=416304316[2]d=415147362[2]
!-->[Hidden] C:\contents of old hard drive\ Root\Documents and Settings\Documents and Settings\Jesse Wilson\Local Settings\Temp\Temporary Internet Files\Content.IE5\89030JOB\NOSALE_ConsMrktng;MN=93220974;wm=o;rm=1;!c=d-dxp;!c=d-pxp;sz=240x60;tile=3;dcove=d;ord=416317475[2]d=415147362[2]
!-->[Hidden] C:\contents of old hard drive\ Root\Documents and Settings\Documents and Settings\Jesse Wilson\Local Settings\Temp\Temporary Internet Files\Content.IE5\89030JOB\NOSALE_ConsMrktng;MN=93220974;wm=o;rm=1;!c=d-dxp;!c=d-pxp;sz=240x60;tile=3;dcove=d;ord=416359365[2]d=415147362[2]
!-->[Hidden] C:\contents of old hard drive\ Root\Documents and Settings\Documents and Settings\Jesse Wilson\Local Settings\Temp\Temporary Internet Files\Content.IE5\89030JOB\NOSALE_ConsMrktng;MN=93220974;wm=o;rm=1;!c=d-dxp;!c=d-pxp;sz=240x60;tile=3;dcove=d;ord=416372995[2]d=415147362[2]
!-->[Hidden] C:\contents of old hard drive\ Root\Documents and Settings\Documents and Settings\Jesse Wilson\Local Settings\Temp\Temporary Internet Files\Content.IE5\89030JOB\NOSALE_ConsMrktng;MN=93220974;wm=o;rm=1;!c=d-dxp;!c=d-pxp;sz=240x60;tile=3;dcove=d;ord=416523561[2]d=415147362[2]
!-->[Hidden] C:\contents of old hard drive\ Root\Documents and Settings\Documents and Settings\Jesse Wilson\Local Settings\Temp\Temporary Internet Files\Content.IE5\89030JOB\NOSALE_ConsMrktng;MN=93220974;wm=o;rm=1;!c=d-dxp;!c=d-pxp;sz=240x60;tile=3;dcove=d;ord=416573783[2]d=415147362[2]
!-->[Hidden] C:\contents of old hard drive\ Root\Documents and Settings\Documents and Settings\Jesse Wilson\Local Settings\Temp\Temporary Internet Files\Content.IE5\89030JOB\NOSALE_ConsMrktng;MN=93220974;wm=o;rm=1;!c=d-dxp;!c=d-pxp;sz=240x60;tile=3;dcove=d;ord=416590057[2]d=415147362[2]
!-->[Hidden] C:\contents of old hard drive\ Root\Documents and Settings\Documents and Settings\Jesse Wilson\Local Settings\Temp\Temporary Internet Files\Content.IE5\89030JOB\NOSALE_ConsMrktng;MN=93220974;wm=o;rm=1;!c=d-dxp;!c=d-pxp;sz=240x60;tile=3;dcove=d;ord=416625998[2]d=415147362[2]
!-->[Hidden] C:\contents of old hard drive\ Root\Documents and Settings\Documents and Settings\Jesse Wilson\Local Settings\Temp\Temporary Internet Files\Content.IE5\89030JOB\NOSALE_ConsMrktng;MN=93220974;wm=o;rm=1;!c=d-dxp;!c=d-pxp;sz=240x60;tile=3;dcove=d;ord=416654600[2]d=415147362[2]
!-->[Hidden] C:\contents of old hard drive\ Root\Documents and Settings\Documents and Settings\Jesse Wilson\Local Settings\Temp\Temporary Internet Files\Content.IE5\89030JOB\NOSALE_ConsMrktng;MN=93220974;wm=o;rm=1;!c=d-dxp;!c=d-pxp;sz=240x60;tile=4;dcove=d;ord=415366768[2]d=415147362[2]
!-->[Hidden] C:\contents of old hard drive\ Root\Documents and Settings\Documents and Settings\Jesse Wilson\Local Settings\Temp\Temporary Internet Files\Content.IE5\89030JOB\NOSALE_ConsMrktng;MN=93220974;wm=o;rm=1;!c=d-dxp;!c=d-pxp;sz=240x60;tile=4;dcove=d;ord=415446302[2]d=415147362[2]
!-->[Hidden] C:\contents of old hard drive\ Root\Documents and Settings\Documents and Settings\Jesse Wilson\Local Settings\Temp\Temporary Internet Files\Content.IE5\89030JOB\NOSALE_ConsMrktng;MN=93220974;wm=o;rm=1;!c=d-dxp;!c=d-pxp;sz=240x60;tile=4;dcove=d;ord=415542691[2]d=415147362[2]
!-->[Hidden] C:\contents of old hard drive\ Root\Documents and Settings\Documents and Settings\Jesse Wilson\Local Settings\Temp\Temporary Internet Files\Content.IE5\89030JOB\NOSALE_ConsMrktng;MN=93220974;wm=o;rm=1;!c=d-dxp;!c=d-pxp;sz=240x60;tile=4;dcove=d;ord=415557252[2]d=415147362[2]
!-->[Hidden] C:\contents of old hard drive\ Root\Documents and Settings\Documents and Settings\Jesse Wilson\Local Settings\Temp\Temporary Internet Files\Content.IE5\89030JOB\NOSALE_ConsMrktng;MN=93220974;wm=o;rm=1;!c=d-dxp;!c=d-pxp;sz=240x60;tile=4;dcove=d;ord=415590630[2]d=415147362[2]
!-->[Hidden] C:\contents of old hard drive\ Root\Documents and Settings\Documents and Settings\Jesse Wilson\Local Settings\Temp\Temporary Internet Files\Content.IE5\89030JOB\NOSALE_ConsMrktng;MN=93220974;wm=o;rm=1;!c=d-dxp;!c=d-pxp;sz=240x60;tile=4;dcove=d;ord=415607304[2]d=415147362[2]
!-->[Hidden] C:\contents of old hard drive\ Root\Documents and Settings\Documents and Settings\Jesse Wilson\Local Settings\Temp\Temporary Internet Files\Content.IE5\89030JOB\NOSALE_ConsMrktng;MN=93220974;wm=o;rm=1;!c=d-dxp;!c=d-pxp;sz=240x60;tile=4;dcove=d;ord=415764079[2]d=415147362[2]
!-->[Hidden] C:\contents of old hard drive\ Root\Documents and Settings\Documents and Settings\Jesse Wilson\Local Settings\Temp\Temporary Internet Files\Content.IE5\89030JOB\NOSALE_ConsMrktng;MN=93220974;wm=o;rm=1;!c=d-dxp;!c=d-pxp;sz=240x60;tile=4;dcove=d;ord=415772792[2]d=415147362[2]
!-->[Hidden] C:\contents of old hard drive\ Root\Documents and Settings\Documents and Settings\Jesse Wilson\Local Settings\Temp\Temporary Internet Files\Content.IE5\89030JOB\NOSALE_ConsMrktng;MN=93220974;wm=o;rm=1;!c=d-dxp;!c=d-pxp;sz=240x60;tile=4;dcove=d;ord=415830735[2]d=415147362[2]
!-->[Hidden] C:\contents of old hard drive\ Root\Documents and Settings\Documents and Settings\Jesse Wilson\Local Settings\Temp\Temporary Internet Files\Content.IE5\89030JOB\NOSALE_ConsMrktng;MN=93220974;wm=o;rm=1;!c=d-dxp;!c=d-pxp;sz=240x60;tile=4;dcove=d;ord=415861209[2]d=415147362[2]
!-->[Hidden] C:\contents of old hard drive\ Root\Documents and Settings\Documents and Settings\Jesse Wilson\Local Settings\Temp\Temporary Internet Files\Content.IE5\89030JOB\NOSALE_ConsMrktng;MN=93220974;wm=o;rm=1;!c=d-dxp;!c=d-pxp;sz=240x60;tile=4;dcove=d;ord=415873496[2]d=415147362[2]
!-->[Hidden] C:\contents of old hard drive\ Root\Documents and Settings\Documents and Settings\Jesse Wilson\Local Settings\Temp\Temporary Internet Files\Content.IE5\89030JOB\NOSALE_ConsMrktng;MN=93220974;wm=o;rm=1;!c=d-dxp;!c=d-pxp;sz=240x60;tile=4;dcove=d;ord=415950928[2]d=415147362[2]
!-->[Hidden] C:\contents of old hard drive\ Root\Documents and Settings\Documents and Settings\Jesse Wilson\Local Settings\Temp\Temporary Internet Files\Content.IE5\89030JOB\NOSALE_ConsMrktng;MN=93220974;wm=o;rm=1;!c=d-dxp;!c=d-pxp;sz=240x60;tile=4;dcove=d;ord=415975303[2]d=415147362[2]
!-->[Hidden] C:\contents of old hard drive\ Root\Documents and Settings\Documents and Settings\Jesse Wilson\Local Settings\Temp\Temporary Internet Files\Content.IE5\89030JOB\NOSALE_ConsMrktng;MN=93220974;wm=o;rm=1;!c=d-dxp;!c=d-pxp;sz=240x60;tile=4;dcove=d;ord=415988592[2]d=415147362[2]
!-->[Hidden] C:\contents of old hard drive\ Root\Documents and Settings\Documents and Settings\Jesse Wilson\Local Settings\Temp\Temporary Internet Files\Content.IE5\89030JOB\NOSALE_ConsMrktng;MN=93220974;wm=o;rm=1;!c=d-dxp;!c=d-pxp;sz=240x60;tile=4;dcove=d;ord=416016172[2]d=415147362[2]
!-->[Hidden] C:\contents of old hard drive\ Root\Documents and Settings\Documents and Settings\Jesse Wilson\Local Settings\Temp\Temporary Internet Files\Content.IE5\89030JOB\NOSALE_ConsMrktng;MN=93220975;wm=o;rm=1;!c=d-dxp;!c=d-pxp;sz=318x250;tile=4;dcove=d;ord=415748066[2]=415147362[2]
!-->[Hidden] C:\contents of old hard drive\ Root\Documents and Settings\Documents and Settings\Jesse Wilson\Local Settings\Temp\Temporary Internet Files\Content.IE5\89030JOB\NOSALE_ConsMrktng;MN=93220975;wm=o;rm=1;!c=d-dxp;!c=d-pxp;sz=318x250;tile=4;dcove=d;ord=415850523[2]=415147362[2]
!-->[Hidden] C:\contents of old hard drive\ Root\Documents and Settings\Documents and Settings\Jesse Wilson\Local Settings\Temp\Temporary Internet Files\Content.IE5\89030JOB\NOSALE_ConsMrktng;MN=93220975;wm=o;rm=1;!c=d-dxp;!c=d-pxp;sz=318x250;tile=4;dcove=d;ord=416668099[2]=415147362[2]
!-->[Hidden] C:\contents of old hard drive\ Root\Documents and Settings\Documents and Settings\Jesse Wilson\Local Settings\Temp\Temporary Internet Files\Content.IE5\89030JOB\NOSALE_ConsMrktng;MN=93220976;wm=o;rm=1;!c=d-dxp;!c=d-pxp;sz=300x46;tile=3;dcove=d;ord=414976627[2]]=415147362[2]
!-->[Hidden] C:\contents of old hard drive\ Root\Documents and Settings\Documents and Settings\Jesse Wilson\Local Settings\Temp\Temporary Internet Files\Content.IE5\89030JOB\site=soccernet.espn.go[1].com&cc=na&sec=worldcup&pt=story&adsize=2x1&transactionID=818323130576282831645
!-->[Hidden] C:\contents of old hard drive\ Root\Documents and Settings\Documents and Settings\Jesse Wilson\Local Settings\Temp\Temporary Internet Files\Content.IE5\CLQNGLU3\Celeb_InternalPromo;MN=93221313;wm=o;rm=1;!c=d-dxp;!c=d-pxp;sz=318x113;tile=3;dcove=d;ord=415850523[2]14976627[2]
!-->[Hidden] C:\contents of old hard drive\ Root\Documents and Settings\Documents and Settings\Jesse Wilson\Local Settings\Temp\Temporary Internet Files\Content.IE5\CLQNGLU3\Celeb_InternalPromo;MN=93221313;wm=o;rm=1;!c=d-dxp;!c=d-pxp;sz=318x113;tile=3;dcove=d;ord=416049409[2]14976627[2]
!-->[Hidden] C:\contents of old hard drive\ Root\Documents and Settings\Documents and Settings\Jesse Wilson\Local Settings\Temp\Temporary Internet Files\Content.IE5\CLQNGLU3\EntGen_Photos;MN=93191982;wm=o;rm=1;!c=d-pnd;!c=d-pps;sz=728x90;tile=5;dcove=d;ord=415748066[2]9[2]]2]14976627[2]
!-->[Hidden] C:\contents of old hard drive\ Root\Documents and Settings\Documents and Settings\Jesse Wilson\Local Settings\Temp\Temporary Internet Files\Content.IE5\CLQNGLU3\EntGen_Photos;MN=93191982;wm=o;rm=1;!c=d-pnd;!c=d-pps;sz=728x90;tile=5;dcove=d;ord=416668099[2]9[2]]2]14976627[2]
!-->[Hidden] C:\contents of old hard drive\ Root\Documents and Settings\Documents and Settings\Jesse Wilson\Local Settings\Temp\Temporary Internet Files\Content.IE5\CLQNGLU3\NOSALE_ConsMrktng;MN=93220973;wm=o;rm=1;!c=d-dxp;!c=d-pxp;sz=240x52;tile=5;dcove=d;ord=415147362[2]]2]14976627[2]
!-->[Hidden] C:\contents of old hard drive\ Root\Documents and Settings\Documents and Settings\Jesse Wilson\Local Settings\Temp\Temporary Internet Files\Content.IE5\CLQNGLU3\NOSALE_ConsMrktng;MN=93220973;wm=o;rm=1;!c=d-dxp;!c=d-pxp;sz=240x52;tile=6;dcove=d;ord=416049409[2]]2]14976627[2]
!-->[Hidden] C:\contents of old hard drive\ Root\Documents and Settings\Documents and Settings\Jesse Wilson\Local Settings\Temp\Temporary Internet Files\Content.IE5\CLQNGLU3\NOSALE_ConsMrktng;MN=93220974;wm=o;rm=1;!c=d-dxp;!c=d-pxp;sz=240x60;tile=3;dcove=d;ord=414983567[2]]2]14976627[2]
!-->[Hidden] C:\contents of old hard drive\ Root\Documents and Settings\Documents and Settings\Jesse Wilson\Local Settings\Temp\Temporary Internet Files\Content.IE5\CLQNGLU3\NOSALE_ConsMrktng;MN=93220974;wm=o;rm=1;!c=d-dxp;!c=d-pxp;sz=240x60;tile=3;dcove=d;ord=415106453[2]d=414976627[2]
!-->[Hidden] C:\contents of old hard drive\ Root\Documents and Settings\Documents and Settings\Jesse Wilson\Local Settings\Temp\Temporary Internet Files\Content.IE5\CLQNGLU3\NOSALE_ConsMrktng;MN=93220974;wm=o;rm=1;!c=d-dxp;!c=d-pxp;sz=240x60;tile=3;dcove=d;ord=415126973[2]d=414976627[2]
!-->[Hidden] C:\contents of old hard drive\ Root\Documents and Settings\Documents and Settings\Jesse Wilson\Local Settings\Temp\Temporary Internet Files\Content.IE5\CLQNGLU3\NOSALE_ConsMrktng;MN=93220974;wm=o;rm=1;!c=d-dxp;!c=d-pxp;sz=240x60;tile=3;dcove=d;ord=415151158[2]d=414976627[2]
!-->[Hidden] C:\contents of old hard drive\ Root\Documents and Settings\Documents and Settings\Jesse Wilson\Local Settings\Temp\Temporary Internet Files\Content.IE5\CLQNGLU3\NOSALE_ConsMrktng;MN=93220974;wm=o;rm=1;!c=d-dxp;!c=d-pxp;sz=240x60;tile=3;dcove=d;ord=415163756[2]d=414976627[2]
!-->[Hidden] C:\contents of old hard drive\ Root\Documents and Settings\Documents and Settings\Jesse Wilson\Local Settings\Temp\Temporary Internet Files\Content.IE5\CLQNGLU3\NOSALE_ConsMrktng;MN=93220974;wm=o;rm=1;!c=d-dxp;!c=d-pxp;sz=240x60;tile=3;dcove=d;ord=416077510[2]d=414976627[2]
!-->[Hidden] C:\contents of old hard drive\ Root\Documents and Settings\Documents and Settings\Jesse Wilson\Local Settings\Temp\Temporary Internet Files\Content.IE5\CLQNGLU3\NOSALE_ConsMrktng;MN=93220974;wm=o;rm=1;!c=d-dxp;!c=d-pxp;sz=240x60;tile=3;dcove=d;ord=416095115[2]d=414976627[2]
!-->[Hidden] C:\contents of old hard drive\ Root\Documents and Settings\Documents and Settings\Jesse Wilson\Local Settings\Temp\Temporary Internet Files\Content.IE5\CLQNGLU3\NOSALE_ConsMrktng;MN=93220974;wm=o;rm=1;!c=d-dxp;!c=d-pxp;sz=240x60;tile=3;dcove=d;ord=416097258[2]d=414976627[2]
!-->[Hidden] C:\contents of old hard drive\ Root\Documents and Settings\Documents and Settings\Jesse Wilson\Local Settings\Temp\Temporary Internet Files\Content.IE5\CLQNGLU3\NOSALE_ConsMrktng;MN=93220974;wm=o;rm=1;!c=d-dxp;!c=d-pxp;sz=240x60;tile=3;dcove=d;ord=416112270[2]]2]14976627[2]
!-->[Hidden] C:\contents of old hard drive\ Root\Documents and Settings\Documents and Settings\Jesse Wilson\Local Settings\Temp\Temporary Internet Files\Content.IE5\CLQNGLU3\NOSALE_ConsMrktng;MN=93220974;wm=o;rm=1;!c=d-dxp;!c=d-pxp;sz=240x60;tile=3;dcove=d;ord=416133000[2]]2]14976627[2]
!-->[Hidden] C:\contents of old hard drive\ Root\Documents and Settings\Documents and Settings\Jesse Wilson\Local Settings\Temp\Temporary Internet Files\Content.IE5\CLQNGLU3\NOSALE_ConsMrktng;MN=93220974;wm=o;rm=1;!c=d-dxp;!c=d-pxp;sz=240x60;tile=3;dcove=d;ord=416136254[2]]2]14976627[2]
!-->[Hidden] C:\contents of old hard drive\ Root\Documents and Settings\Documents and Settings\Jesse Wilson\Local Settings\Temp\Temporary Internet Files\Content.IE5\CLQNGLU3\NOSALE_ConsMrktng;MN=93220974;wm=o;rm=1;!c=d-dxp;!c=d-pxp;sz=240x60;tile=3;dcove=d;ord=416200417[2]]2]14976627[2]
!-->[Hidden] C:\contents of old hard drive\ Root\Documents and Settings\Documents and Settings\Jesse Wilson\Local Settings\Temp\Temporary Internet Files\Content.IE5\CLQNGLU3\NOSALE_ConsMrktng;MN=93220974;wm=o;rm=1;!c=d-dxp;!c=d-pxp;sz=240x60;tile=3;dcove=d;ord=416228597[2]]2]14976627[2]
!-->[Hidden] C:\contents of old hard drive\ Root\Documents and Settings\Documents and Settings\Jesse Wilson\Local Settings\Temp\Temporary Internet Files\Content.IE5\CLQNGLU3\NOSALE_ConsMrktng;MN=93220974;wm=o;rm=1;!c=d-dxp;!c=d-pxp;sz=240x60;tile=3;dcove=d;ord=416343462[2]]2]14976627[2]
jkwings
Active Member
 
Posts: 10
Joined: June 29th, 2010, 7:53 pm

Re: Google/Bing redirect error - please help

Unread postby jkwings » July 3rd, 2010, 9:30 am

!-->[Hidden] C:\contents of old hard drive\ Root\Documents and Settings\Documents and Settings\Jesse Wilson\Local Settings\Temp\Temporary Internet Files\Content.IE5\CLQNGLU3\NOSALE_ConsMrktng;MN=93220974;wm=o;rm=1;!c=d-dxp;!c=d-pxp;sz=240x60;tile=3;dcove=d;ord=416515089[2]]2]14976627[2]
!-->[Hidden] C:\contents of old hard drive\ Root\Documents and Settings\Documents and Settings\Jesse Wilson\Local Settings\Temp\Temporary Internet Files\Content.IE5\CLQNGLU3\NOSALE_ConsMrktng;MN=93220974;wm=o;rm=1;!c=d-dxp;!c=d-pxp;sz=240x60;tile=3;dcove=d;ord=416542939[2]]2]14976627[2]
!-->[Hidden] C:\contents of old hard drive\ Root\Documents and Settings\Documents and Settings\Jesse Wilson\Local Settings\Temp\Temporary Internet Files\Content.IE5\CLQNGLU3\NOSALE_ConsMrktng;MN=93220974;wm=o;rm=1;!c=d-dxp;!c=d-pxp;sz=240x60;tile=3;dcove=d;ord=416552262[2]]2]14976627[2]
!-->[Hidden] C:\contents of old hard drive\ Root\Documents and Settings\Documents and Settings\Jesse Wilson\Local Settings\Temp\Temporary Internet Files\Content.IE5\CLQNGLU3\NOSALE_ConsMrktng;MN=93220974;wm=o;rm=1;!c=d-dxp;!c=d-pxp;sz=240x60;tile=4;dcove=d;ord=415255688[2]]2]14976627[2]
!-->[Hidden] C:\contents of old hard drive\ Root\Documents and Settings\Documents and Settings\Jesse Wilson\Local Settings\Temp\Temporary Internet Files\Content.IE5\CLQNGLU3\NOSALE_ConsMrktng;MN=93220974;wm=o;rm=1;!c=d-dxp;!c=d-pxp;sz=240x60;tile=4;dcove=d;ord=415359668[2]]2]14976627[2]
!-->[Hidden] C:\contents of old hard drive\ Root\Documents and Settings\Documents and Settings\Jesse Wilson\Local Settings\Temp\Temporary Internet Files\Content.IE5\CLQNGLU3\NOSALE_ConsMrktng;MN=93220974;wm=o;rm=1;!c=d-dxp;!c=d-pxp;sz=240x60;tile=4;dcove=d;ord=415384674[2][2]14976627[2]
!-->[Hidden] C:\contents of old hard drive\ Root\Documents and Settings\Documents and Settings\Jesse Wilson\Local Settings\Temp\Temporary Internet Files\Content.IE5\CLQNGLU3\NOSALE_ConsMrktng;MN=93220974;wm=o;rm=1;!c=d-dxp;!c=d-pxp;sz=240x60;tile=4;dcove=d;ord=415414727[2][2]14976627[2]
!-->[Hidden] C:\contents of old hard drive\ Root\Documents and Settings\Documents and Settings\Jesse Wilson\Local Settings\Temp\Temporary Internet Files\Content.IE5\CLQNGLU3\NOSALE_ConsMrktng;MN=93220974;wm=o;rm=1;!c=d-dxp;!c=d-pxp;sz=240x60;tile=4;dcove=d;ord=415439252[2][2]14976627[2]
!-->[Hidden] C:\contents of old hard drive\ Root\Documents and Settings\Documents and Settings\Jesse Wilson\Local Settings\Temp\Temporary Internet Files\Content.IE5\CLQNGLU3\NOSALE_ConsMrktng;MN=93220974;wm=o;rm=1;!c=d-dxp;!c=d-pxp;sz=240x60;tile=4;dcove=d;ord=415664876[2][2]14976627[2]
!-->[Hidden] C:\contents of old hard drive\ Root\Documents and Settings\Documents and Settings\Jesse Wilson\Local Settings\Temp\Temporary Internet Files\Content.IE5\CLQNGLU3\NOSALE_ConsMrktng;MN=93220974;wm=o;rm=1;!c=d-dxp;!c=d-pxp;sz=240x60;tile=4;dcove=d;ord=415710863[2][2]14976627[2]
!-->[Hidden] C:\contents of old hard drive\ Root\Documents and Settings\Documents and Settings\Jesse Wilson\Local Settings\Temp\Temporary Internet Files\Content.IE5\CLQNGLU3\NOSALE_ConsMrktng;MN=93220974;wm=o;rm=1;!c=d-dxp;!c=d-pxp;sz=240x60;tile=4;dcove=d;ord=415770048[2][2]14976627[2]
!-->[Hidden] C:\contents of old hard drive\ Root\Documents and Settings\Documents and Settings\Jesse Wilson\Local Settings\Temp\Temporary Internet Files\Content.IE5\CLQNGLU3\NOSALE_ConsMrktng;MN=93220974;wm=o;rm=1;!c=d-dxp;!c=d-pxp;sz=240x60;tile=4;dcove=d;ord=415786882[2][2]14976627[2]
!-->[Hidden] C:\contents of old hard drive\ Root\Documents and Settings\Documents and Settings\Jesse Wilson\Local Settings\Temp\Temporary Internet Files\Content.IE5\CLQNGLU3\NOSALE_ConsMrktng;MN=93220974;wm=o;rm=1;!c=d-dxp;!c=d-pxp;sz=240x60;tile=4;dcove=d;ord=415895839[2][2]14976627[2]
!-->[Hidden] C:\contents of old hard drive\ Root\Documents and Settings\Documents and Settings\Jesse Wilson\Local Settings\Temp\Temporary Internet Files\Content.IE5\CLQNGLU3\NOSALE_ConsMrktng;MN=93220974;wm=o;rm=1;!c=d-dxp;!c=d-pxp;sz=240x60;tile=4;dcove=d;ord=415939111[2][2]14976627[2]
!-->[Hidden] C:\contents of old hard drive\ Root\Documents and Settings\Documents and Settings\Jesse Wilson\Local Settings\Temp\Temporary Internet Files\Content.IE5\CLQNGLU3\NOSALE_ConsMrktng;MN=93220974;wm=o;rm=1;!c=d-dxp;!c=d-pxp;sz=240x60;tile=4;dcove=d;ord=416033166[2][2]14976627[2]
!-->[Hidden] C:\contents of old hard drive\ Root\Documents and Settings\Documents and Settings\Jesse Wilson\Local Settings\Temp\Temporary Internet Files\Content.IE5\CLQNGLU3\NOSALE_ConsMrktng;MN=93220974;wm=o;rm=1;!c=d-dxp;!c=d-pxp;sz=240x60;tile=4;dcove=d;ord=416044382[2][2]14976627[2]
!-->[Hidden] C:\contents of old hard drive\ Root\Documents and Settings\Documents and Settings\Jesse Wilson\Local Settings\Temp\Temporary Internet Files\Content.IE5\CLQNGLU3\NOSALE_ConsMrktng;MN=93220975;wm=o;rm=1;!c=d-dxp;!c=d-pxp;sz=318x250;tile=4;dcove=d;ord=416175040[2]2]14976627[2]
!-->[Hidden] C:\contents of old hard drive\ Root\Documents and Settings\Documents and Settings\Jesse Wilson\Local Settings\Temp\Temporary Internet Files\Content.IE5\CLQNGLU3\NOSALE_ConsMrktng;MN=93220975;wm=o;rm=1;!c=d-dxp;!c=d-pxp;sz=318x250;tile=4;dcove=d;ord=416350793[2]2]14976627[2]
!-->[Hidden] C:\contents of old hard drive\ Root\Documents and Settings\Documents and Settings\Jesse Wilson\Local Settings\Temp\Temporary Internet Files\Content.IE5\Q2EP1PGE\activity;src=1174143;met=1;v=1;pid=13479069;aid=37069077;ko=0;cid=17100301;rid=17118196;rv=12;&timestamp=1151291808123;eid1=2;ecn1=0;etm1=18;[1].gifepisode+fantasy+fight[4]2].5
!-->[Hidden] C:\contents of old hard drive\ Root\Documents and Settings\Documents and Settings\Jesse Wilson\Local Settings\Temp\Temporary Internet Files\Content.IE5\Q2EP1PGE\entertainment;sz=450x60;kch=2179803025;kbg=FFFFFF;kkw=Comedy+Entertainment;ord=308592601386317[2].93585137862[2]808123;eid1=2;ecn1=0;etm1=18;[1].gifepisode+fantasy+fight[4]2].5
!-->[Hidden] C:\contents of old hard drive\ Root\Documents and Settings\Documents and Settings\Jesse Wilson\Local Settings\Temp\Temporary Internet Files\Content.IE5\Q2EP1PGE\entertainment;sz=450x60;kch=2179803025;kbg=FFFFFF;kkw=Comedy+Entertainment;ord=875865324729994[2].93585137862[2]808123;eid1=2;ecn1=0;etm1=18;[1].gifepisode+fantasy+fight[4]2].5
!-->[Hidden] C:\contents of old hard drive\ Root\Documents and Settings\Documents and Settings\Jesse Wilson\Local Settings\Temp\Temporary Internet Files\Content.IE5\Q2EP1PGE\entertainment;sz=450x60;kch=2179803025;kbg=FFFFFF;kkw=Music+Entertainment;ord=7209972518567858[2].93585137862[2]808123;eid1=2;ecn1=0;etm1=18;[1].gifepisode+fantasy+fight[4]2].5
!-->[Hidden] C:\contents of old hard drive\ Root\Documents and Settings\Documents and Settings\Jesse Wilson\Local Settings\Temp\Temporary Internet Files\Content.IE5\Q2EP1PGE\entertainment_inv;sz=728x90;kch=2179803025;kbg=FFFFFF;kkw=Comedy+Entertainment;ord=8064467142701025[2]5137862[2]808123;eid1=2;ecn1=0;etm1=18;[1].gifepisode+fantasy+fight[4]2].5
!-->[Hidden] C:\contents of old hard drive\ Root\Documents and Settings\Documents and Settings\Jesse Wilson\Local Settings\Temp\Temporary Internet Files\Content.IE5\Q2EP1PGE\inv;sz=728x90;kch=3000513466;kbg=FFFFFF;kkw=2005+2006+amv+animation+anime+baby+band+boy+car+cat+comedy+commercial+concert+cool+crazy+cute+dance+episode+fantasy+fight+fil[2]2].2
!-->[Hidden] C:\contents of old hard drive\ Root\Documents and Settings\Documents and Settings\Jesse Wilson\Local Settings\Temp\Temporary Internet Files\Content.IE5\Q2EP1PGE\keywords;kw=ipod+shuffle;cat=293;cat=97927;dcopt=ist;tcat=56169;items=3056;sz=440x198;tile=4;ord=1160863942187;[1].htmert+cool+crazy+cute+dance+episode+fantasy+fight+fil[2]2].2
!-->[Hidden] C:\contents of old hard drive\ Root\Documents and Settings\Documents and Settings\Jesse Wilson\Local Settings\Temp\Temporary Internet Files\Content.IE5\Q2EP1PGE\reggender=3&hosted_id=6760&country2=us&src=wrapper&adchannel=rottentomatoes&regage=0&subdomain=www.rottentomatoes[7]ncert+cool+crazy+cute+dance+episode+fantasy+fight+fil[2]2].2
!-->[Hidden] C:\contents of old hard drive\ Root\Documents and Settings\Documents and Settings\Jesse Wilson\Local Settings\Temp\Temporary Internet Files\Content.IE5\Q2EP1PGE\sky_inv;sz=728x90;kch=3000513466;kbg=FFFFFF;kkw=2005+2006+amv+animation+anime+baby+band+boy+car+cat+comedy+commercial+concert+cool+crazy+cute+dance+episode+fantasy+fight[2]2].5
!-->[Hidden] C:\contents of old hard drive\ Root\Documents and Settings\Documents and Settings\Jesse Wilson\Local Settings\Temp\Temporary Internet Files\Content.IE5\Q2EP1PGE\sky_inv;sz=728x90;kch=3000513466;kbg=FFFFFF;kkw=2005+2006+amv+animation+anime+baby+band+boy+car+cat+comedy+commercial+concert+cool+crazy+cute+dance+episode+fantasy+fight[3]2].5
!-->[Hidden] C:\contents of old hard drive\ Root\Documents and Settings\Documents and Settings\Jesse Wilson\Local Settings\Temp\Temporary Internet Files\Content.IE5\Q2EP1PGE\sky_inv;sz=728x90;kch=3000513466;kbg=FFFFFF;kkw=2005+2006+amv+animation+anime+baby+band+boy+car+cat+comedy+commercial+concert+cool+crazy+cute+dance+episode+fantasy+fight[4]2].5
!-->[Hidden] C:\contents of old hard drive\ Root\Documents and Settings\Documents and Settings\Jesse Wilson\Local Settings\Temp\Temporary Internet Files\Content.IE5\Q2EP1PGE\videogames;sz=450x60;kch=2179803025;kbg=FFFFFF;kkw=Arts++Animation+Music+Video+Games;ord=4171622590276564[2]1291808123;eid1=2;ecn1=0;etm1=18;[1].gifepisode+fantasy+fight[4]2].5
!-->[Hidden] C:\contents of old hard drive\ Root\Documents and Settings\Documents and Settings\Jesse Wilson\Local Settings\Temp\Temporary Internet Files\Content.IE5\Q2EP1PGE\videogames_inv;sz=728x90;kch=2179803025;kbg=FFFFFF;kkw=Arts++Animation+Music+Video+Games;ord=4560724585137862[2]808123;eid1=2;ecn1=0;etm1=18;[1].gifepisode+fantasy+fight[4]2].5
!-->[Hidden] C:\contents of old hard drive\ Root\Documents and Settings\Documents and Settings\Jesse Wilson\Local Settings\Temp\Temporary Internet Files\Content.IE5\Q50V6TQ1\Celeb_InternalPromo;MN=93221313;wm=o;rm=1;!c=d-dxp;!c=d-pxp;sz=318x113;tile=3;dcove=d;ord=416668099[2]82,7313,7769,7854,8135&Targets=12441,1515&Values=31,43,51,60,72,81,[1].htm
!-->[Hidden] C:\contents of old hard drive\ Root\Documents and Settings\Documents and Settings\Jesse Wilson\Local Settings\Temp\Temporary Internet Files\Content.IE5\Q50V6TQ1\EntGen_Photos;MN=93191982;wm=o;rm=1;!c=d-pnd;!c=d-pps;sz=728x90;tile=5;dcove=d;ord=415850523[2]8099[2]82,7313,7769,7854,8135&Targets=12441,1515&Values=31,43,51,60,72,81,[1].htm
!-->[Hidden] C:\contents of old hard drive\ Root\Documents and Settings\Documents and Settings\Jesse Wilson\Local Settings\Temp\Temporary Internet Files\Content.IE5\Q50V6TQ1\NOSALE_ConsMrktng;MN=93220973;wm=o;rm=1;!c=d-dxp;!c=d-pxp;sz=240x52;tile=5;dcove=d;ord=414976627[2]]2282,7313,7769,7854,8135&Targets=12441,1515&Values=31,43,51,60,72,81,[1].htm
!-->[Hidden] C:\contents of old hard drive\ Root\Documents and Settings\Documents and Settings\Jesse Wilson\Local Settings\Temp\Temporary Internet Files\Content.IE5\Q50V6TQ1\NOSALE_ConsMrktng;MN=93220973;wm=o;rm=1;!c=d-dxp;!c=d-pxp;sz=240x52;tile=6;dcove=d;ord=415748066[2]]2282,7313,7769,7854,8135&Targets=12441,1515&Values=31,43,51,60,72,81,[1].htm
!-->[Hidden] C:\contents of old hard drive\ Root\Documents and Settings\Documents and Settings\Jesse Wilson\Local Settings\Temp\Temporary Internet Files\Content.IE5\Q50V6TQ1\NOSALE_ConsMrktng;MN=93220974;wm=o;rm=1;!c=d-dxp;!c=d-pxp;sz=240x60;tile=3;dcove=d;ord=415035071[2]]2282,7313,7769,7854,8135&Targets=12441,1515&Values=31,43,51,60,72,81,[1].htm
!-->[Hidden] C:\contents of old hard drive\ Root\Documents and Settings\Documents and Settings\Jesse Wilson\Local Settings\Temp\Temporary Internet Files\Content.IE5\Q50V6TQ1\NOSALE_ConsMrktng;MN=93220974;wm=o;rm=1;!c=d-dxp;!c=d-pxp;sz=240x60;tile=3;dcove=d;ord=415051965[2]]2282,7313,7769,7854,8135&Targets=12441,1515&Values=31,43,51,60,72,81,[1].htm
!-->[Hidden] C:\contents of old hard drive\ Root\Documents and Settings\Documents and Settings\Jesse Wilson\Local Settings\Temp\Temporary Internet Files\Content.IE5\Q50V6TQ1\NOSALE_ConsMrktng;MN=93220974;wm=o;rm=1;!c=d-dxp;!c=d-pxp;sz=240x60;tile=3;dcove=d;ord=415066636[2]]2282,7313,7769,7854,8135&Targets=12441,1515&Values=31,43,51,60,72,81,[1].htm
!-->[Hidden] C:\contents of old hard drive\ Root\Documents and Settings\Documents and Settings\Jesse Wilson\Local Settings\Temp\Temporary Internet Files\Content.IE5\Q50V6TQ1\NOSALE_ConsMrktng;MN=93220974;wm=o;rm=1;!c=d-dxp;!c=d-pxp;sz=240x60;tile=3;dcove=d;ord=415157237[2]]2282,7313,7769,7854,8135&Targets=12441,1515&Values=31,43,51,60,72,81,[1].htm
!-->[Hidden] C:\contents of old hard drive\ Root\Documents and Settings\Documents and Settings\Jesse Wilson\Local Settings\Temp\Temporary Internet Files\Content.IE5\Q50V6TQ1\NOSALE_ConsMrktng;MN=93220974;wm=o;rm=1;!c=d-dxp;!c=d-pxp;sz=240x60;tile=3;dcove=d;ord=415159810[2]12282,7313,7769,7854,8135&Targets=12441,1515&Values=31,43,51,60,72,81,[1].htm
!-->[Hidden] C:\contents of old hard drive\ Root\Documents and Settings\Documents and Settings\Jesse Wilson\Local Settings\Temp\Temporary Internet Files\Content.IE5\Q50V6TQ1\NOSALE_ConsMrktng;MN=93220974;wm=o;rm=1;!c=d-dxp;!c=d-pxp;sz=240x60;tile=3;dcove=d;ord=415179068[2]12282,7313,7769,7854,8135&Targets=12441,1515&Values=31,43,51,60,72,81,[1].htm
!-->[Hidden] C:\contents of old hard drive\ Root\Documents and Settings\Documents and Settings\Jesse Wilson\Local Settings\Temp\Temporary Internet Files\Content.IE5\Q50V6TQ1\NOSALE_ConsMrktng;MN=93220974;wm=o;rm=1;!c=d-dxp;!c=d-pxp;sz=240x60;tile=3;dcove=d;ord=415195922[2]12282,7313,7769,7854,8135&Targets=12441,1515&Values=31,43,51,60,72,81,[1].htm
!-->[Hidden] C:\contents of old hard drive\ Root\Documents and Settings\Documents and Settings\Jesse Wilson\Local Settings\Temp\Temporary Internet Files\Content.IE5\Q50V6TQ1\NOSALE_ConsMrktng;MN=93220974;wm=o;rm=1;!c=d-dxp;!c=d-pxp;sz=240x60;tile=3;dcove=d;ord=415214379[2]12282,7313,7769,7854,8135&Targets=12441,1515&Values=31,43,51,60,72,81,[1].htm
!-->[Hidden] C:\contents of old hard drive\ Root\Documents and Settings\Documents and Settings\Jesse Wilson\Local Settings\Temp\Temporary Internet Files\Content.IE5\Q50V6TQ1\NOSALE_ConsMrktng;MN=93220974;wm=o;rm=1;!c=d-dxp;!c=d-pxp;sz=240x60;tile=3;dcove=d;ord=416066344[2]12282,7313,7769,7854,8135&Targets=12441,1515&Values=31,43,51,60,72,81,[1].htm
!-->[Hidden] C:\contents of old hard drive\ Root\Documents and Settings\Documents and Settings\Jesse Wilson\Local Settings\Temp\Temporary Internet Files\Content.IE5\Q50V6TQ1\NOSALE_ConsMrktng;MN=93220974;wm=o;rm=1;!c=d-dxp;!c=d-pxp;sz=240x60;tile=3;dcove=d;ord=416080003[2]12282,7313,7769,7854,8135&Targets=12441,1515&Values=31,43,51,60,72,81,[1].htm
!-->[Hidden] C:\contents of old hard drive\ Root\Documents and Settings\Documents and Settings\Jesse Wilson\Local Settings\Temp\Temporary Internet Files\Content.IE5\Q50V6TQ1\NOSALE_ConsMrktng;MN=93220974;wm=o;rm=1;!c=d-dxp;!c=d-pxp;sz=240x60;tile=3;dcove=d;ord=416130406[2]12282,7313,7769,7854,8135&Targets=12441,1515&Values=31,43,51,60,72,81,[1].htm
!-->[Hidden] C:\contents of old hard drive\ Root\Documents and Settings\Documents and Settings\Jesse Wilson\Local Settings\Temp\Temporary Internet Files\Content.IE5\Q50V6TQ1\NOSALE_ConsMrktng;MN=93220974;wm=o;rm=1;!c=d-dxp;!c=d-pxp;sz=240x60;tile=3;dcove=d;ord=416168130[2]12282,7313,7769,7854,8135&Targets=12441,1515&Values=31,43,51,60,72,81,[1].htm
!-->[Hidden] C:\contents of old hard drive\ Root\Documents and Settings\Documents and Settings\Jesse Wilson\Local Settings\Temp\Temporary Internet Files\Content.IE5\Q50V6TQ1\NOSALE_ConsMrktng;MN=93220974;wm=o;rm=1;!c=d-dxp;!c=d-pxp;sz=240x60;tile=3;dcove=d;ord=416209279[2]12282,7313,7769,7854,8135&Targets=12441,1515&Values=31,43,51,60,72,81,[1].htm
!-->[Hidden] C:\contents of old hard drive\ Root\Documents and Settings\Documents and Settings\Jesse Wilson\Local Settings\Temp\Temporary Internet Files\Content.IE5\Q50V6TQ1\NOSALE_ConsMrktng;MN=93220974;wm=o;rm=1;!c=d-dxp;!c=d-pxp;sz=240x60;tile=3;dcove=d;ord=416211593[2]12282,7313,7769,7854,8135&Targets=12441,1515&Values=31,43,51,60,72,81,[1].htm
!-->[Hidden] C:\contents of old hard drive\ Root\Documents and Settings\Documents and Settings\Jesse Wilson\Local Settings\Temp\Temporary Internet Files\Content.IE5\Q50V6TQ1\NOSALE_ConsMrktng;MN=93220974;wm=o;rm=1;!c=d-dxp;!c=d-pxp;sz=240x60;tile=3;dcove=d;ord=416223329[2]12282,7313,7769,7854,8135&Targets=12441,1515&Values=31,43,51,60,72,81,[1].htm
!-->[Hidden] C:\contents of old hard drive\ Root\Documents and Settings\Documents and Settings\Jesse Wilson\Local Settings\Temp\Temporary Internet Files\Content.IE5\Q50V6TQ1\NOSALE_ConsMrktng;MN=93220974;wm=o;rm=1;!c=d-dxp;!c=d-pxp;sz=240x60;tile=3;dcove=d;ord=416225002[2]12282,7313,7769,7854,8135&Targets=12441,1515&Values=31,43,51,60,72,81,[1].htm
!-->[Hidden] C:\contents of old hard drive\ Root\Documents and Settings\Documents and Settings\Jesse Wilson\Local Settings\Temp\Temporary Internet Files\Content.IE5\Q50V6TQ1\NOSALE_ConsMrktng;MN=93220974;wm=o;rm=1;!c=d-dxp;!c=d-pxp;sz=240x60;tile=3;dcove=d;ord=416290266[2]]2282,7313,7769,7854,8135&Targets=12441,1515&Values=31,43,51,60,72,81,[1].htm
!-->[Hidden] C:\contents of old hard drive\ Root\Documents and Settings\Documents and Settings\Jesse Wilson\Local Settings\Temp\Temporary Internet Files\Content.IE5\Q50V6TQ1\NOSALE_ConsMrktng;MN=93220974;wm=o;rm=1;!c=d-dxp;!c=d-pxp;sz=240x60;tile=3;dcove=d;ord=416557580[2]]2282,7313,7769,7854,8135&Targets=12441,1515&Values=31,43,51,60,72,81,[1].htm
!-->[Hidden] C:\contents of old hard drive\ Root\Documents and Settings\Documents and Settings\Jesse Wilson\Local Settings\Temp\Temporary Internet Files\Content.IE5\Q50V6TQ1\NOSALE_ConsMrktng;MN=93220974;wm=o;rm=1;!c=d-dxp;!c=d-pxp;sz=240x60;tile=3;dcove=d;ord=416562918[2]]2282,7313,7769,7854,8135&Targets=12441,1515&Values=31,43,51,60,72,81,[1].htm
!-->[Hidden] C:\contents of old hard drive\ Root\Documents and Settings\Documents and Settings\Jesse Wilson\Local Settings\Temp\Temporary Internet Files\Content.IE5\Q50V6TQ1\NOSALE_ConsMrktng;MN=93220974;wm=o;rm=1;!c=d-dxp;!c=d-pxp;sz=240x60;tile=3;dcove=d;ord=416567014[2]]2282,7313,7769,7854,8135&Targets=12441,1515&Values=31,43,51,60,72,81,[1].htm
!-->[Hidden] C:\contents of old hard drive\ Root\Documents and Settings\Documents and Settings\Jesse Wilson\Local Settings\Temp\Temporary Internet Files\Content.IE5\Q50V6TQ1\NOSALE_ConsMrktng;MN=93220974;wm=o;rm=1;!c=d-dxp;!c=d-pxp;sz=240x60;tile=3;dcove=d;ord=416579582[2]]2282,7313,7769,7854,8135&Targets=12441,1515&Values=31,43,51,60,72,81,[1].htm
!-->[Hidden] C:\contents of old hard drive\ Root\Documents and Settings\Documents and Settings\Jesse Wilson\Local Settings\Temp\Temporary Internet Files\Content.IE5\Q50V6TQ1\NOSALE_ConsMrktng;MN=93220974;wm=o;rm=1;!c=d-dxp;!c=d-pxp;sz=240x60;tile=3;dcove=d;ord=416635262[2]]2282,7313,7769,7854,8135&Targets=12441,1515&Values=31,43,51,60,72,81,[1].htm
!-->[Hidden] C:\contents of old hard drive\ Root\Documents and Settings\Documents and Settings\Jesse Wilson\Local Settings\Temp\Temporary Internet Files\Content.IE5\Q50V6TQ1\NOSALE_ConsMrktng;MN=93220974;wm=o;rm=1;!c=d-dxp;!c=d-pxp;sz=240x60;tile=4;dcove=d;ord=415276568[2]]2282,7313,7769,7854,8135&Targets=12441,1515&Values=31,43,51,60,72,81,[1].htm
!-->[Hidden] C:\contents of old hard drive\ Root\Documents and Settings\Documents and Settings\Jesse Wilson\Local Settings\Temp\Temporary Internet Files\Content.IE5\Q50V6TQ1\NOSALE_ConsMrktng;MN=93220974;wm=o;rm=1;!c=d-dxp;!c=d-pxp;sz=240x60;tile=4;dcove=d;ord=415317257[2]]2282,7313,7769,7854,8135&Targets=12441,1515&Values=31,43,51,60,72,81,[1].htm
!-->[Hidden] C:\contents of old hard drive\ Root\Documents and Settings\Documents and Settings\Jesse Wilson\Local Settings\Temp\Temporary Internet Files\Content.IE5\Q50V6TQ1\NOSALE_ConsMrktng;MN=93220974;wm=o;rm=1;!c=d-dxp;!c=d-pxp;sz=240x60;tile=4;dcove=d;ord=415326099[2]]2282,7313,7769,7854,8135&Targets=12441,1515&Values=31,43,51,60,72,81,[1].htm
!-->[Hidden] C:\contents of old hard drive\ Root\Documents and Settings\Documents and Settings\Jesse Wilson\Local Settings\Temp\Temporary Internet Files\Content.IE5\Q50V6TQ1\NOSALE_ConsMrktng;MN=93220974;wm=o;rm=1;!c=d-dxp;!c=d-pxp;sz=240x60;tile=4;dcove=d;ord=415347029[2]12282,7313,7769,7854,8135&Targets=12441,1515&Values=31,43,51,60,72,81,[1].htm
!-->[Hidden] C:\contents of old hard drive\ Root\Documents and Settings\Documents and Settings\Jesse Wilson\Local Settings\Temp\Temporary Internet Files\Content.IE5\Q50V6TQ1\NOSALE_ConsMrktng;MN=93220974;wm=o;rm=1;!c=d-dxp;!c=d-pxp;sz=240x60;tile=4;dcove=d;ord=415373127[2]12282,7313,7769,7854,8135&Targets=12441,1515&Values=31,43,51,60,72,81,[1].htm
!-->[Hidden] C:\contents of old hard drive\ Root\Documents and Settings\Documents and Settings\Jesse Wilson\Local Settings\Temp\Temporary Internet Files\Content.IE5\Q50V6TQ1\NOSALE_ConsMrktng;MN=93220974;wm=o;rm=1;!c=d-dxp;!c=d-pxp;sz=240x60;tile=4;dcove=d;ord=415380217[2]12282,7313,7769,7854,8135&Targets=12441,1515&Values=31,43,51,60,72,81,[1].htm
!-->[Hidden] C:\contents of old hard drive\ Root\Documents and Settings\Documents and Settings\Jesse Wilson\Local Settings\Temp\Temporary Internet Files\Content.IE5\Q50V6TQ1\NOSALE_ConsMrktng;MN=93220974;wm=o;rm=1;!c=d-dxp;!c=d-pxp;sz=240x60;tile=4;dcove=d;ord=415400376[2]12282,7313,7769,7854,8135&Targets=12441,1515&Values=31,43,51,60,72,81,[1].htm
!-->[Hidden] C:\contents of old hard drive\ Root\Documents and Settings\Documents and Settings\Jesse Wilson\Local Settings\Temp\Temporary Internet Files\Content.IE5\Q50V6TQ1\NOSALE_ConsMrktng;MN=93220974;wm=o;rm=1;!c=d-dxp;!c=d-pxp;sz=240x60;tile=4;dcove=d;ord=415403801[2]12282,7313,7769,7854,8135&Targets=12441,1515&Values=31,43,51,60,72,81,[1].htm
!-->[Hidden] C:\contents of old hard drive\ Root\Documents and Settings\Documents and Settings\Jesse Wilson\Local Settings\Temp\Temporary Internet Files\Content.IE5\Q50V6TQ1\NOSALE_ConsMrktng;MN=93220974;wm=o;rm=1;!c=d-dxp;!c=d-pxp;sz=240x60;tile=4;dcove=d;ord=415407296[2]12282,7313,7769,7854,8135&Targets=12441,1515&Values=31,43,51,60,72,81,[1].htm
!-->[Hidden] C:\contents of old hard drive\ Root\Documents and Settings\Documents and Settings\Jesse Wilson\Local Settings\Temp\Temporary Internet Files\Content.IE5\Q50V6TQ1\NOSALE_ConsMrktng;MN=93220974;wm=o;rm=1;!c=d-dxp;!c=d-pxp;sz=240x60;tile=4;dcove=d;ord=415425763[2]12282,7313,7769,7854,8135&Targets=12441,1515&Values=31,43,51,60,72,81,[1].htm
!-->[Hidden] C:\contents of old hard drive\ Root\Documents and Settings\Documents and Settings\Jesse Wilson\Local Settings\Temp\Temporary Internet Files\Content.IE5\Q50V6TQ1\NOSALE_ConsMrktng;MN=93220974;wm=o;rm=1;!c=d-dxp;!c=d-pxp;sz=240x60;tile=4;dcove=d;ord=415464048[2]]2282,7313,7769,7854,8135&Targets=12441,1515&Values=31,43,51,60,72,81,[1].htm
!-->[Hidden] C:\contents of old hard drive\ Root\Documents and Settings\Documents and Settings\Jesse Wilson\Local Settings\Temp\Temporary Internet Files\Content.IE5\Q50V6TQ1\NOSALE_ConsMrktng;MN=93220974;wm=o;rm=1;!c=d-dxp;!c=d-pxp;sz=240x60;tile=4;dcove=d;ord=415494011[2]12282,7313,7769,7854,8135&Targets=12441,1515&Values=31,43,51,60,72,81,[1].htm
!-->[Hidden] C:\contents of old hard drive\ Root\Documents and Settings\Documents and Settings\Jesse Wilson\Local Settings\Temp\Temporary Internet Files\Content.IE5\Q50V6TQ1\NOSALE_ConsMrktng;MN=93220974;wm=o;rm=1;!c=d-dxp;!c=d-pxp;sz=240x60;tile=4;dcove=d;ord=415553767[2]12282,7313,7769,7854,8135&Targets=12441,1515&Values=31,43,51,60,72,81,[1].htm
!-->[Hidden] C:\contents of old hard drive\ Root\Documents and Settings\Documents and Settings\Jesse Wilson\Local Settings\Temp\Temporary Internet Files\Content.IE5\Q50V6TQ1\NOSALE_ConsMrktng;MN=93220974;wm=o;rm=1;!c=d-dxp;!c=d-pxp;sz=240x60;tile=4;dcove=d;ord=415569489[2]12282,7313,7769,7854,8135&Targets=12441,1515&Values=31,43,51,60,72,81,[1].htm
!-->[Hidden] C:\contents of old hard drive\ Root\Documents and Settings\Documents and Settings\Jesse Wilson\Local Settings\Temp\Temporary Internet Files\Content.IE5\Q50V6TQ1\NOSALE_ConsMrktng;MN=93220974;wm=o;rm=1;!c=d-dxp;!c=d-pxp;sz=240x60;tile=4;dcove=d;ord=415633702[2]12282,7313,7769,7854,8135&Targets=12441,1515&Values=31,43,51,60,72,81,[1].htm
!-->[Hidden] C:\contents of old hard drive\ Root\Documents and Settings\Documents and Settings\Jesse Wilson\Local Settings\Temp\Temporary Internet Files\Content.IE5\Q50V6TQ1\NOSALE_ConsMrktng;MN=93220974;wm=o;rm=1;!c=d-dxp;!c=d-pxp;sz=240x60;tile=4;dcove=d;ord=415647582[2]12282,7313,7769,7854,8135&Targets=12441,1515&Values=31,43,51,60,72,81,[1].htm
!-->[Hidden] C:\contents of old hard drive\ Root\Documents and Settings\Documents and Settings\Jesse Wilson\Local Settings\Temp\Temporary Internet Files\Content.IE5\Q50V6TQ1\NOSALE_ConsMrktng;MN=93220974;wm=o;rm=1;!c=d-dxp;!c=d-pxp;sz=240x60;tile=4;dcove=d;ord=415677104[2]12282,7313,7769,7854,8135&Targets=12441,1515&Values=31,43,51,60,72,81,[1].htm
!-->[Hidden] C:\contents of old hard drive\ Root\Documents and Settings\Documents and Settings\Jesse Wilson\Local Settings\Temp\Temporary Internet Files\Content.IE5\Q50V6TQ1\NOSALE_ConsMrktng;MN=93220974;wm=o;rm=1;!c=d-dxp;!c=d-pxp;sz=240x60;tile=4;dcove=d;ord=415692336[2]12282,7313,7769,7854,8135&Targets=12441,1515&Values=31,43,51,60,72,81,[1].htm
!-->[Hidden] C:\contents of old hard drive\ Root\Documents and Settings\Documents and Settings\Jesse Wilson\Local Settings\Temp\Temporary Internet Files\Content.IE5\Q50V6TQ1\NOSALE_ConsMrktng;MN=93220974;wm=o;rm=1;!c=d-dxp;!c=d-pxp;sz=240x60;tile=4;dcove=d;ord=415732213[2]12282,7313,7769,7854,8135&Targets=12441,1515&Values=31,43,51,60,72,81,[1].htm
!-->[Hidden] C:\contents of old hard drive\ Root\Documents and Settings\Documents and Settings\Jesse Wilson\Local Settings\Temp\Temporary Internet Files\Content.IE5\Q50V6TQ1\NOSALE_ConsMrktng;MN=93220974;wm=o;rm=1;!c=d-dxp;!c=d-pxp;sz=240x60;tile=4;dcove=d;ord=415839377[2]12282,7313,7769,7854,8135&Targets=12441,1515&Values=31,43,51,60,72,81,[1].htm
!-->[Hidden] C:\contents of old hard drive\ Root\Documents and Settings\Documents and Settings\Jesse Wilson\Local Settings\Temp\Temporary Internet Files\Content.IE5\Q50V6TQ1\NOSALE_ConsMrktng;MN=93220974;wm=o;rm=1;!c=d-dxp;!c=d-pxp;sz=240x60;tile=4;dcove=d;ord=415884232[2]12282,7313,7769,7854,8135&Targets=12441,1515&Values=31,43,51,60,72,81,[1].htm
!-->[Hidden] C:\contents of old hard drive\ Root\Documents and Settings\Documents and Settings\Jesse Wilson\Local Settings\Temp\Temporary Internet Files\Content.IE5\Q50V6TQ1\NOSALE_ConsMrktng;MN=93220974;wm=o;rm=1;!c=d-dxp;!c=d-pxp;sz=240x60;tile=4;dcove=d;ord=415916689[2]12282,7313,7769,7854,8135&Targets=12441,1515&Values=31,43,51,60,72,81,[1].htm
!-->[Hidden] C:\contents of old hard drive\ Root\Documents and Settings\Documents and Settings\Jesse Wilson\Local Settings\Temp\Temporary Internet Files\Content.IE5\Q50V6TQ1\NOSALE_ConsMrktng;MN=93220974;wm=o;rm=1;!c=d-dxp;!c=d-pxp;sz=240x60;tile=4;dcove=d;ord=416007619[2]12282,7313,7769,7854,8135&Targets=12441,1515&Values=31,43,51,60,72,81,[1].htm
!-->[Hidden] C:\contents of old hard drive\ Root\Documents and Settings\Documents and Settings\Jesse Wilson\Local Settings\Temp\Temporary Internet Files\Content.IE5\Q50V6TQ1\NOSALE_ConsMrktng;MN=93220975;wm=o;rm=1;!c=d-dxp;!c=d-pxp;sz=318x250;tile=4;dcove=d;ord=416049409[2]2282,7313,7769,7854,8135&Targets=12441,1515&Values=31,43,51,60,72,81,[1].htm
!-->[Hidden] C:\contents of old hard drive\ Root\Documents and Settings\Documents and Settings\Jesse Wilson\Local Settings\Temp\Temporary Internet Files\Content.IE5\Q50V6TQ1\NOSALE_ConsMrktng;MN=93220976;wm=o;rm=1;!c=d-dxp;!c=d-pxp;sz=300x46;tile=3;dcove=d;ord=415147362[2]]2282,7313,7769,7854,8135&Targets=12441,1515&Values=31,43,51,60,72,81,[1].htm
!-->[Hidden] C:\contents of old hard drive\ Root\Documents and Settings\Documents and Settings\Jesse Wilson\Local Settings\Temp\Temporary Internet Files\Content.IE5\Q50V6TQ1\site=soccernet.espn.go[1].com&cc=na&sec=worldcup&pt=story&adsize=728x90&transactionID=959135986263112282,7313,7769,7854,8135&Targets=12441,1515&Values=31,43,51,60,72,81,[1].htm
!-->[Hidden] C:\contents of old hard drive\ Root\Documents and Settings\Documents and Settings\Jesse Wilson\Local Settings\Temp\Temporary Internet Files\Content.IE5\V3TT5X5Q\activity;src=1174143;met=1;v=1;pid=13479069;aid=37069077;ko=0;cid=17100301;rid=17118196;rv=12;&timestamp=1151291776127;eid1=2;ecn1=1;etm1=6;[1].gif+episode+fantasy+fight+f[2].5
!-->[Hidden] C:\contents of old hard drive\ Root\Documents and Settings\Documents and Settings\Jesse Wilson\Local Settings\Temp\Temporary Internet Files\Content.IE5\V3TT5X5Q\sky_inv;sz=728x90;kch=3000513466;kbg=FFFFFF;kkw=2005+2006+amv+animation+anime+baby+band+boy+car+cat+comedy+commercial+concert+cool+crazy+cute+dance+episode+fantasy+fight[4]2].5
!-->[Hidden] C:\contents of old hard drive\ Root\Documents and Settings\Documents and Settings\Jesse Wilson\Local Settings\Temp\Temporary Internet Files\Content.IE5\V3TT5X5Q\sky_inv;sz=728x90;kch=3000513466;kbg=FFFFFF;kkw=2005+2006+amv+animation+anime+baby+band+boy+car+cat+comedy+commercial+concert+cool+crazy+cute+dance+episode+fantasy+fight[5]2].5
!-->[Hidden] C:\contents of old hard drive\ Root\Documents and Settings\Documents and Settings\Jesse Wilson\Local Settings\Temp\Temporary Internet Files\Content.IE5\V3TT5X5Q\sky_inv;sz=728x90;kch=3000513466;kbg=FFFFFF;kkw=2005+2006+amv+animation+anime+baby+band+boy+car+cat+comedy+commercial+concert+cool+crazy+cute+dance+episode+fantasy+fight[6]2].5
!-->[Hidden] C:\contents of old hard drive\ Root\Documents and Settings\Documents and Settings\Jesse Wilson\Local Settings\Temp\Temporary Internet Files\Content.IE5\XKH53D5R\entertainment_inv;sz=728x90;kch=2179803025;kbg=FFFFFF;kkw=Arts++Animation+Comedy+Entertainment;ord=339607008596422[2].43m=1151023576453&network=rottentomatoes&tile=1151023632621
!-->[Hidden] C:\contents of old hard drive\ Root\Documents and Settings\Documents and Settings\Jesse Wilson\Local Settings\Temp\Temporary Internet Files\Content.IE5\XKH53D5R\entertainment_inv;sz=728x90;kch=2179803025;kbg=FFFFFF;kkw=Comedy+Entertainment;ord=4231472275576880[2]607008596422[2].43m=1151023576453&network=rottentomatoes&tile=1151023632621
!-->[Hidden] C:\contents of old hard drive\ Root\Documents and Settings\Documents and Settings\Jesse Wilson\Local Settings\Temp\Temporary Internet Files\Content.IE5\XKH53D5R\entertainment_inv;sz=728x90;kch=2179803025;kbg=FFFFFF;kkw=Music+Entertainment;ord=1453320246208208[2].207008596422[2].43m=1151023576453&network=rottentomatoes&tile=1151023632621
!-->[Hidden] C:\contents of old hard drive\ Root\Documents and Settings\Documents and Settings\Jesse Wilson\Local Settings\Temp\Temporary Internet Files\Content.IE5\XKH53D5R\entertainment_inv;sz=728x90;kch=2179803025;kbg=FFFFFF;kkw=Music+Entertainment;ord=3049445749561436[2].207008596422[2].43m=1151023576453&network=rottentomatoes&tile=1151023632621
!-->[Hidden] C:\contents of old hard drive\ Root\Documents and Settings\Documents and Settings\Jesse Wilson\Local Settings\Temp\Temporary Internet Files\Content.IE5\XKH53D5R\entertainment_inv;sz=728x90;kch=2179803025;kbg=FFFFFF;kkw=Music+Entertainment;ord=3626698248159178[2].507008596422[2].43m=1151023576453&network=rottentomatoes&tile=1151023632621
!-->[Hidden] C:\contents of old hard drive\ Root\Documents and Settings\Documents and Settings\Jesse Wilson\Local Settings\Temp\Temporary Internet Files\Content.IE5\XKH53D5R\inv;sz=728x90;kch=3000513466;kbg=FFFFFF;kkw=2005+2006+amv+animation+anime+baby+band+boy+car+cat+comedy+commercial+concert+cool+crazy+cute+dance+episode+fantasy+fight+fil[2]].37
!-->[Hidden] C:\contents of old hard drive\ Root\Documents and Settings\Documents and Settings\Jesse Wilson\Local Settings\Temp\Temporary Internet Files\Content.IE5\XKH53D5R\inv;sz=728x90;kch=3000513466;kbg=FFFFFF;kkw=2005+2006+amv+animation+anime+baby+band+boy+car+cat+comedy+commercial+concert+cool+crazy+cute+dance+episode+fantasy+fight+fil[3]].37
!-->[Hidden] C:\contents of old hard drive\ Root\Documents and Settings\Documents and Settings\Jesse Wilson\Local Settings\Temp\Temporary Internet Files\Content.IE5\XKH53D5R\sky_inv;sz=728x90;kch=3000513466;kbg=FFFFFF;kkw=2005+2006+amv+animation+anime+baby+band+boy+car+cat+comedy+commercial+concert+cool+crazy+cute+dance+episode+fantasy+fight[2]toes&
!-->[Hidden] C:\contents of old hard drive\ Root\Documents and Settings\Documents and Settings\Jesse Wilson\Local Settings\Temp\Temporary Internet Files\Content.IE5\XKH53D5R\sky_inv;sz=728x90;kch=3000513466;kbg=FFFFFF;kkw=2005+2006+amv+animation+anime+baby+band+boy+car+cat+comedy+commercial+concert+cool+crazy+cute+dance+episode+fantasy+fight[3]32621
!-->[Hidden] C:\contents of old hard drive\ Root\Documents and Settings\Documents and Settings\Jesse Wilson\Local Settings\Temp\Temporary Internet Files\Content.IE5\XKH53D5R\sky_inv;sz=728x90;kch=3000513466;kbg=FFFFFF;kkw=2005+2006+amv+animation+anime+baby+band+boy+car+cat+comedy+commercial+concert+cool+crazy+cute+dance+episode+fantasy+fight[5]32621
!-->[Hidden] C:\contents of old hard drive\ Root\Documents and Settings\Documents and Settings\Jesse Wilson\Local Settings\Temp\Temporary Internet Files\Content.IE5\XKH53D5R\unsuccessfulbid;tn=3;to=h;tr=1;!cat=statichp;tw=760;ta=center;szs=234x60,234x60,234x60;ord=1160863836064;[1].htm53&random=1151023576453&network=rottentomatoes&tile=1151023632621
!-->[Hidden] C:\contents of old hard drive\ Root\Documents and Settings\Documents and Settings\Jesse Wilson\Local Settings\Temp\Temporary Internet Files\Content.IE5\XKH53D5R\_default;sz=160x600;kch=1187796739;kbg=FFFFFF;ksearch=bill%20dance;kr=R;ord=5607918563417045[2]+cat+comedy+commercial+concert+cool+crazy+cute+dance+episode+fantasy+fight[2]toes&
!-->[Hidden] C:\Documents and Settings\Jesse\Application Data\Macromedia\Flash Player\#SharedObjects\V93SGYZP\www.howcast.com\flash\standard_player_v2.swf\HowcastVideoPlayer.sol
!-->[Hidden] C:\Documents and Settings\Jesse\Application Data\Mozilla\Firefox\Crash Reports\pending\7439b0e2-ee91-40f2-9dc6-7ac51ec7e92f.dmp
!-->[Hidden] C:\Documents and Settings\Jesse\Application Data\Mozilla\Firefox\Crash Reports\pending\7439b0e2-ee91-40f2-9dc6-7ac51ec7e92f.extra
!-->[Hidden] C:\Documents and Settings\Jesse\Application Data\Mozilla\Firefox\Profiles\98aqx86i.default\gtb-metrics.xml
!-->[Hidden] C:\Documents and Settings\Jesse\Local Settings\Temporary Internet Files\Content.IE5\GZLNYEJH\syncmessage[1].htm
!-->[Hidden] C:\Documents and Settings\NetworkService\Local Settings\Temporary Internet Files\Content.IE5\3GQK0E1S\imp[1].php%3Frefresh%3D60%26zoneid%3D1689%26cb%3DINSERT_RANDOM_NUMBER_HERE&r=0
!-->[Hidden] C:\Documents and Settings\NetworkService\Local Settings\Temporary Internet Files\Content.IE5\6ARHJ56L\CAEZ8X2P.php%253Fzoneid%253D1111%2526cb%253Dkbm6v&r=0
!-->[Hidden] C:\Documents and Settings\NetworkService\Local Settings\Temporary Internet Files\Content.IE5\6ARHJ56L\CASHMJOP
!-->[Hidden] C:\Documents and Settings\NetworkService\Local Settings\Temporary Internet Files\Content.IE5\6ARHJ56L\tKkD2z-Fwa0&hl=en_US&fs=1&[1].swf
!-->[Hidden] C:\Documents and Settings\NetworkService\Local Settings\Temporary Internet Files\Content.IE5\8JATCR4J\1;;~okv=;campaign=;vid=1746985541;geoloc=US;sourcesite=blinkx;adlocation=player_preroll;source=player;lc_approved=true;text_ads_approved=true;adid=1[1].gif1
!-->[Hidden] C:\Documents and Settings\NetworkService\Local Settings\Temporary Internet Files\Content.IE5\8JATCR4J\ad3.liverail[3].xml
!-->[Hidden] C:\Documents and Settings\NetworkService\Local Settings\Temporary Internet Files\Content.IE5\8JATCR4J\blog;sec0=musicvideos;sec1=blog;!category=music;pos=atf;envid=origin;uri=_blog_top-10-hits-band_96886;tag=adj;mtype=standard;sz=4x4;tile=5;demo=D;u=!c[1].51
!-->[Hidden] C:\Documents and Settings\NetworkService\Local Settings\Temporary Internet Files\Content.IE5\8JATCR4J\CAUZODQ7.php%253Fzoneid%253D1111%2526cb%253Dkbm6v&r=0
!-->[Hidden] C:\Documents and Settings\NetworkService\Local Settings\Temporary Internet Files\Content.IE5\8JATCR4J\pixel[13].swf
!-->[Hidden] C:\Documents and Settings\NetworkService\Local Settings\Temporary Internet Files\Content.IE5\B96KT5NY\blog;sec0=musicvideos;sec1=blog;!category=music;pos=atf;envid=origin;uri=_blog_top-10-hits-band_96886;tag=adj;mtype=standard;sz=300x250;tile=2;demo=D;[1].54
!-->[Hidden] C:\Documents and Settings\NetworkService\Local Settings\Temporary Internet Files\Content.IE5\B96KT5NY\CA5GM1XB.php%253Fzoneid%253D1111%2526cb%253Dkbm6v&r=0
!-->[Hidden] C:\Documents and Settings\NetworkService\Local Settings\Temporary Internet Files\Content.IE5\EJWFY7H9\CAWT23K9.php%253Fzoneid%253D1111%2526cb%253Dkbm6v&r=0
!-->[Hidden] C:\Documents and Settings\NetworkService\Local Settings\Temporary Internet Files\Content.IE5\EJWFY7H9\pixel[6].swf
!-->[Hidden] C:\Documents and Settings\NetworkService\Local Settings\Temporary Internet Files\Content.IE5\EJWFY7H9\pixel[7].swf
!-->[Hidden] C:\Documents and Settings\NetworkService\Local Settings\Temporary Internet Files\Content.IE5\OHAFUZQ1\ad3.liverail[5].xml
!-->[Hidden] C:\Documents and Settings\NetworkService\Local Settings\Temporary Internet Files\Content.IE5\OHAFUZQ1\CAS16R0L.php%253Fzoneid%253D1111%2526cb%253Dkbm6v&r=0
!-->[Hidden] C:\Documents and Settings\NetworkService\Local Settings\Temporary Internet Files\Content.IE5\OHAFUZQ1\jump2[1]
!-->[Hidden] C:\Documents and Settings\NetworkService\Local Settings\Temporary Internet Files\Content.IE5\OHAFUZQ1\search[1]
!-->[Hidden] C:\Documents and Settings\NetworkService\Local Settings\Temporary Internet Files\Content.IE5\Q9XNW1KC\1;;~okv=;campaign=;vid=1747018563;geoloc=US;sourcesite=blinkx;adlocation=player_preroll;source=player;lc_approved=true;text_ads_approved=true;adid=1[1].gif8
!-->[Hidden] C:\Documents and Settings\NetworkService\Local Settings\Temporary Internet Files\Content.IE5\Q9XNW1KC\CAJVELXR.php%253Fzoneid%253D1111%2526cb%253Dkbm6v&r=0
!-->[Hidden] C:\Documents and Settings\NetworkService\Local Settings\Temporary Internet Files\Content.IE5\Q9XNW1KC\dynamic_preroll_playlist[3].fmil
!-->[Hidden] C:\Documents and Settings\NetworkService\Local Settings\Temporary Internet Files\Content.IE5\Q9XNW1KC\tKkD2z-Fwa0&hl=en_US&fs=1&[1].swf
!-->[Hidden] C:\Documents and Settings\NetworkService\Local Settings\Temporary Internet Files\Content.IE5\Q9XNW1KC\TleTUJJQEZQE14PERFjW1QMIhlcOQ%3D%3D%26rurl%3Dhttp%253A%252F%252Fjavascript&cid=oxpv1%3A34-632-1929-354-1111&hrid=d8e570ce2ad02c5792a7a0bec4fabe60-1278127852
!-->[Hidden] C:\Documents and Settings\NetworkService\Local Settings\Temporary Internet Files\Content.IE5\R6FJPVZ0\pixel[13].swf
!-->[Hidden] C:\Documents and Settings\NetworkService\Local Settings\Temporary Internet Files\Content.IE5\R6FJPVZ0\pixel[14].swf
!-->[Hidden] C:\Program Files\McAfee\MSK\Config\cstreams\77876\cstreams.lua
!-->[Hidden] C:\Program Files\McAfee\MSK\Config\cstreams\77876\cstreams.rgx
!-->[Hidden] C:\Program Files\McAfee\MSK\Config\cstreams\77876\manifest
!-->[Hidden] C:\Program Files\McAfee\MSK\Config\sentag\27672\manifest
!-->[Hidden] C:\Program Files\McAfee\MSK\Config\sentag\27672\sentag.lua
!-->[Hidden] C:\Program Files\McAfee\MSK\Config\sentag\27672\sentence.lut
!-->[Hidden] C:\Program Files\McAfee\MSK\Config\sentag\27672\tags.lut
!-->[Hidden] C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP976\A0112316.cfg
!-->[Hidden] C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP976\A0112317.cfg
!-->[Hidden] C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP976\A0112318.cfg
!-->[Hidden] C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP976\A0112319.cfg
!-->[Hidden] C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP976\A0112320.old
!-->[Hidden] C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP976\change.log
!-->[Hidden] C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP976\RestorePointSize
!-->[Hidden] C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP976\rp.log
!-->[Hidden] C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP976\snapshot\ComDb.Dat
!-->[Hidden] C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP976\snapshot\domain.txt
!-->[Hidden] C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP976\snapshot\Repository\$WinMgmt.CFG
!-->[Hidden] C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP976\snapshot\Repository\FS\INDEX.BTR
!-->[Hidden] C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP976\snapshot\Repository\FS\INDEX.MAP
!-->[Hidden] C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP976\snapshot\Repository\FS\MAPPING.VER
!-->[Hidden] C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP976\snapshot\Repository\FS\MAPPING1.MAP
!-->[Hidden] C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP976\snapshot\Repository\FS\MAPPING2.MAP
!-->[Hidden] C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP976\snapshot\Repository\FS\OBJECTS.DATA
!-->[Hidden] C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP976\snapshot\Repository\FS\OBJECTS.MAP
!-->[Hidden] C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP976\snapshot\_REGISTRY_MACHINE_SAM
!-->[Hidden] C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP976\snapshot\_REGISTRY_MACHINE_SECURITY
!-->[Hidden] C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP976\snapshot\_REGISTRY_MACHINE_SOFTWARE
!-->[Hidden] C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP976\snapshot\_REGISTRY_MACHINE_SYSTEM
!-->[Hidden] C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP976\snapshot\_REGISTRY_USER_.DEFAULT
!-->[Hidden] C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP976\snapshot\_REGISTRY_USER_NTUSER_S-1-5-18
!-->[Hidden] C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP976\snapshot\_REGISTRY_USER_NTUSER_S-1-5-19
!-->[Hidden] C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP976\snapshot\_REGISTRY_USER_NTUSER_S-1-5-20
!-->[Hidden] C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP976\snapshot\_REGISTRY_USER_NTUSER_S-1-5-21-1460104785-494194024-1023429310-1006
!-->[Hidden] C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP976\snapshot\_REGISTRY_USER_NTUSER_S-1-5-21-1460104785-494194024-1023429310-1007
!-->[Hidden] C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP976\snapshot\_REGISTRY_USER_USRCLASS_S-1-5-18
!-->[Hidden] C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP976\snapshot\_REGISTRY_USER_USRCLASS_S-1-5-19
!-->[Hidden] C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP976\snapshot\_REGISTRY_USER_USRCLASS_S-1-5-20
!-->[Hidden] C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP976\snapshot\_REGISTRY_USER_USRCLASS_S-1-5-21-1460104785-494194024-1023429310-1006
!-->[Hidden] C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP976\snapshot\_REGISTRY_USER_USRCLASS_S-1-5-21-1460104785-494194024-1023429310-1007
==============================================
>Hooks
==============================================
ntkrnlpa.exe+0x0006EA7E, Type: Inline - RelativeJump 0x80545A7E-->80545A85 [ntkrnlpa.exe]
ntkrnlpa.exe-->KeFindConfigurationEntry, Type: Inline - RelativeJump 0x806A180E-->806A187E [ntkrnlpa.exe]
ntkrnlpa.exe-->NtCreateFile, Type: Inline - RelativeJump 0x80577F76-->B907D790 [mfehidk.sys]
ntkrnlpa.exe-->NtEnumerateKey, Type: Inline - RelativeJump 0x80622E0A-->B907D8D9 [mfehidk.sys]
ntkrnlpa.exe-->NtEnumerateValueKey, Type: Inline - RelativeJump 0x80623074-->B907D8C3 [mfehidk.sys]
ntkrnlpa.exe-->NtMapViewOfSection, Type: Inline - RelativeJump 0x805B0E3E-->B907D7D0 [mfehidk.sys]
ntkrnlpa.exe-->NtNotifyChangeKey, Type: Inline - RelativeJump 0x806242E0-->B907D905 [mfehidk.sys]
ntkrnlpa.exe-->NtOpenProcess, Type: Inline - RelativeJump 0x805CA160-->B907D714 [mfehidk.sys]
ntkrnlpa.exe-->NtOpenThread, Type: Inline - RelativeJump 0x805CA3EC-->B907D728 [mfehidk.sys]
ntkrnlpa.exe-->NtProtectVirtualMemory, Type: Inline - RelativeJump 0x805B7222-->B907D7A4 [mfehidk.sys]
ntkrnlpa.exe-->NtQueryKey, Type: Inline - RelativeJump 0x80623CA0-->B907D941 [mfehidk.sys]
ntkrnlpa.exe-->NtQueryMultipleValueKey, Type: Inline - RelativeJump 0x8062178C-->B907D8AD [mfehidk.sys]
ntkrnlpa.exe-->NtQueryValueKey, Type: Inline - RelativeJump 0x80620664-->B907D897 [mfehidk.sys]
ntkrnlpa.exe-->NtReplaceKey, Type: Inline - RelativeJump 0x806241C6-->B907D92D [mfehidk.sys]
ntkrnlpa.exe-->NtRestoreKey, Type: Inline - RelativeJump 0x806209B2-->B907D919 [mfehidk.sys]
ntkrnlpa.exe-->NtSetContextThread, Type: Inline - RelativeJump 0x805D0456-->B907D77C [mfehidk.sys]
ntkrnlpa.exe-->NtSetInformationProcess, Type: Inline - RelativeJump 0x805CCBAA-->B907D768 [mfehidk.sys]
ntkrnlpa.exe-->NtUnloadKey, Type: Inline - RelativeJump 0x80620F32-->B907D8EF [mfehidk.sys]
ntkrnlpa.exe-->NtUnmapViewOfSection, Type: Inline - RelativeJump 0x805B1C4C-->B907D7E6 [mfehidk.sys]
ntkrnlpa.exe-->NtYieldExecution, Type: Inline - RelativeJump 0x80504ABC-->B907D7BA [mfehidk.sys]
[1092]svchost.exe-->advapi32.dll-->RegCreateKeyA, Type: Inline - RelativeJump 0x77DFBCDB-->00000000 [unknown_code_page]
[1092]svchost.exe-->advapi32.dll-->RegCreateKeyExA, Type: Inline - RelativeJump 0x77DDE9D4-->00000000 [unknown_code_page]
[1092]svchost.exe-->advapi32.dll-->RegCreateKeyExW, Type: Inline - RelativeJump 0x77DD776C-->00000000 [unknown_code_page]
[1092]svchost.exe-->advapi32.dll-->RegCreateKeyW, Type: Inline - RelativeJump 0x77DFBA3D-->00000000 [unknown_code_page]
[1092]svchost.exe-->advapi32.dll-->RegOpenKeyA, Type: Inline - RelativeJump 0x77DDEFA8-->00000000 [unknown_code_page]
[1092]svchost.exe-->advapi32.dll-->RegOpenKeyExA, Type: Inline - RelativeJump 0x77DD7852-->00000000 [unknown_code_page]
[1092]svchost.exe-->advapi32.dll-->RegOpenKeyExW, Type: Inline - RelativeJump 0x77DD6AAF-->00000000 [unknown_code_page]
[1092]svchost.exe-->advapi32.dll-->RegOpenKeyW, Type: Inline - RelativeJump 0x77DD7946-->00000000 [unknown_code_page]
[1092]svchost.exe-->kernel32.dll-->CreateFileA, Type: Inline - RelativeJump 0x7C801A24-->00000000 [unknown_code_page]
[1092]svchost.exe-->kernel32.dll-->CreateFileW, Type: Inline - RelativeJump 0x7C810770-->00000000 [unknown_code_page]
[1092]svchost.exe-->kernel32.dll-->CreateNamedPipeA, Type: Inline - RelativeJump 0x7C85FE94-->00000000 [unknown_code_page]
[1092]svchost.exe-->kernel32.dll-->CreateNamedPipeW, Type: Inline - RelativeJump 0x7C82F0EF-->00000000 [unknown_code_page]
[1092]svchost.exe-->kernel32.dll-->CreatePipe, Type: Inline - RelativeJump 0x7C81E0D7-->00000000 [unknown_code_page]
[1092]svchost.exe-->kernel32.dll-->CreateProcessA, Type: Inline - RelativeJump 0x7C802367-->00000000 [unknown_code_page]
[1092]svchost.exe-->kernel32.dll-->CreateProcessW, Type: Inline - RelativeJump 0x7C802332-->00000000 [unknown_code_page]
[1092]svchost.exe-->kernel32.dll-->GetProcAddress, Type: Inline - RelativeJump 0x7C80ADB0-->00000000 [unknown_code_page]
[1092]svchost.exe-->kernel32.dll-->GetStartupInfoA, Type: Inline - RelativeJump 0x7C801EEE-->00000000 [unknown_code_page]
[1092]svchost.exe-->kernel32.dll-->GetStartupInfoW, Type: Inline - RelativeJump 0x7C801E50-->00000000 [unknown_code_page]
[1092]svchost.exe-->kernel32.dll-->LoadLibraryA, Type: Inline - RelativeJump 0x7C801D77-->00000000 [unknown_code_page]
[1092]svchost.exe-->kernel32.dll-->LoadLibraryExA, Type: Inline - RelativeJump 0x7C801D4F-->00000000 [unknown_code_page]
[1092]svchost.exe-->kernel32.dll-->LoadLibraryExW, Type: Inline - RelativeJump 0x7C801AF1-->00000000 [unknown_code_page]
[1092]svchost.exe-->kernel32.dll-->LoadLibraryW, Type: Inline - RelativeJump 0x7C80AE5B-->00000000 [unknown_code_page]
[1092]svchost.exe-->kernel32.dll-->VirtualProtect, Type: Inline - RelativeJump 0x7C801AD0-->00000000 [unknown_code_page]
[1092]svchost.exe-->kernel32.dll-->VirtualProtectEx, Type: Inline - RelativeJump 0x7C801A5D-->00000000 [unknown_code_page]
[1092]svchost.exe-->kernel32.dll-->WinExec, Type: Inline - RelativeJump 0x7C86158D-->00000000 [unknown_code_page]
[1092]svchost.exe-->wininet.dll-->InternetOpenA, Type: Inline - RelativeJump 0x771C57BE-->00000000 [unknown_code_page]
[1092]svchost.exe-->wininet.dll-->InternetOpenUrlA, Type: Inline - RelativeJump 0x771C5A8A-->00000000 [unknown_code_page]
[1092]svchost.exe-->wininet.dll-->InternetOpenUrlW, Type: Inline - RelativeJump 0x771D5C0F-->00000000 [unknown_code_page]
[1092]svchost.exe-->wininet.dll-->InternetOpenW, Type: Inline - RelativeJump 0x771BAF6D-->00000000 [unknown_code_page]
[1092]svchost.exe-->ws2_32.dll-->socket, Type: Inline - RelativeJump 0x71AB3B91-->00000000 [unknown_code_page]
[1176]svchost.exe-->advapi32.dll-->RegCreateKeyA, Type: Inline - RelativeJump 0x77DFBCDB-->00000000 [unknown_code_page]
[1176]svchost.exe-->advapi32.dll-->RegCreateKeyExA, Type: Inline - RelativeJump 0x77DDE9D4-->00000000 [unknown_code_page]
[1176]svchost.exe-->advapi32.dll-->RegCreateKeyExW, Type: Inline - RelativeJump 0x77DD776C-->00000000 [unknown_code_page]
[1176]svchost.exe-->advapi32.dll-->RegCreateKeyW, Type: Inline - RelativeJump 0x77DFBA3D-->00000000 [unknown_code_page]
[1176]svchost.exe-->advapi32.dll-->RegOpenKeyA, Type: Inline - RelativeJump 0x77DDEFA8-->00000000 [unknown_code_page]
[1176]svchost.exe-->advapi32.dll-->RegOpenKeyExA, Type: Inline - RelativeJump 0x77DD7852-->00000000 [unknown_code_page]
[1176]svchost.exe-->advapi32.dll-->RegOpenKeyExW, Type: Inline - RelativeJump 0x77DD6AAF-->00000000 [unknown_code_page]
[1176]svchost.exe-->advapi32.dll-->RegOpenKeyW, Type: Inline - RelativeJump 0x77DD7946-->00000000 [unknown_code_page]
[1176]svchost.exe-->kernel32.dll-->CreateFileA, Type: Inline - RelativeJump 0x7C801A24-->00000000 [unknown_code_page]
[1176]svchost.exe-->kernel32.dll-->CreateFileW, Type: Inline - RelativeJump 0x7C810770-->00000000 [unknown_code_page]
[1176]svchost.exe-->kernel32.dll-->CreateNamedPipeA, Type: Inline - RelativeJump 0x7C85FE94-->00000000 [unknown_code_page]
[1176]svchost.exe-->kernel32.dll-->CreateNamedPipeW, Type: Inline - RelativeJump 0x7C82F0EF-->00000000 [unknown_code_page]
[1176]svchost.exe-->kernel32.dll-->CreatePipe, Type: Inline - RelativeJump 0x7C81E0D7-->00000000 [unknown_code_page]
[1176]svchost.exe-->kernel32.dll-->CreateProcessA, Type: Inline - RelativeJump 0x7C802367-->00000000 [unknown_code_page]
[1176]svchost.exe-->kernel32.dll-->CreateProcessW, Type: Inline - RelativeJump 0x7C802332-->00000000 [unknown_code_page]
[1176]svchost.exe-->kernel32.dll-->GetProcAddress, Type: Inline - RelativeJump 0x7C80ADB0-->00000000 [unknown_code_page]
[1176]svchost.exe-->kernel32.dll-->GetStartupInfoA, Type: Inline - RelativeJump 0x7C801EEE-->00000000 [unknown_code_page]
[1176]svchost.exe-->kernel32.dll-->GetStartupInfoW, Type: Inline - RelativeJump 0x7C801E50-->00000000 [unknown_code_page]
[1176]svchost.exe-->kernel32.dll-->LoadLibraryA, Type: Inline - RelativeJump 0x7C801D77-->00000000 [unknown_code_page]
[1176]svchost.exe-->kernel32.dll-->LoadLibraryExA, Type: Inline - RelativeJump 0x7C801D4F-->00000000 [unknown_code_page]
[1176]svchost.exe-->kernel32.dll-->LoadLibraryExW, Type: Inline - RelativeJump 0x7C801AF1-->00000000 [unknown_code_page]
[1176]svchost.exe-->kernel32.dll-->LoadLibraryW, Type: Inline - RelativeJump 0x7C80AE5B-->00000000 [unknown_code_page]
[1176]svchost.exe-->kernel32.dll-->VirtualProtect, Type: Inline - RelativeJump 0x7C801AD0-->00000000 [unknown_code_page]
[1176]svchost.exe-->kernel32.dll-->VirtualProtectEx, Type: Inline - RelativeJump 0x7C801A5D-->00000000 [unknown_code_page]
[1176]svchost.exe-->kernel32.dll-->WinExec, Type: Inline - RelativeJump 0x7C86158D-->00000000 [unknown_code_page]
[1176]svchost.exe-->wininet.dll-->InternetOpenA, Type: Inline - RelativeJump 0x771C57BE-->00000000 [unknown_code_page]
[1176]svchost.exe-->wininet.dll-->InternetOpenUrlA, Type: Inline - RelativeJump 0x771C5A8A-->00000000 [unknown_code_page]
[1176]svchost.exe-->wininet.dll-->InternetOpenUrlW, Type: Inline - RelativeJump 0x771D5C0F-->00000000 [unknown_code_page]
[1176]svchost.exe-->wininet.dll-->InternetOpenW, Type: Inline - RelativeJump 0x771BAF6D-->00000000 [unknown_code_page]
[1176]svchost.exe-->ws2_32.dll-->socket, Type: Inline - RelativeJump 0x71AB3B91-->00000000 [unknown_code_page]
[1320]svchost.exe-->advapi32.dll-->RegCreateKeyA, Type: Inline - RelativeJump 0x77DFBCDB-->00000000 [unknown_code_page]
[1320]svchost.exe-->advapi32.dll-->RegCreateKeyExA, Type: Inline - RelativeJump 0x77DDE9D4-->00000000 [unknown_code_page]
[1320]svchost.exe-->advapi32.dll-->RegCreateKeyExW, Type: Inline - RelativeJump 0x77DD776C-->00000000 [unknown_code_page]
[1320]svchost.exe-->advapi32.dll-->RegCreateKeyW, Type: Inline - RelativeJump 0x77DFBA3D-->00000000 [unknown_code_page]
[1320]svchost.exe-->advapi32.dll-->RegOpenKeyA, Type: Inline - RelativeJump 0x77DDEFA8-->00000000 [unknown_code_page]
[1320]svchost.exe-->advapi32.dll-->RegOpenKeyExA, Type: Inline - RelativeJump 0x77DD7852-->00000000 [unknown_code_page]
[1320]svchost.exe-->advapi32.dll-->RegOpenKeyExW, Type: Inline - RelativeJump 0x77DD6AAF-->00000000 [unknown_code_page]
[1320]svchost.exe-->advapi32.dll-->RegOpenKeyW, Type: Inline - RelativeJump 0x77DD7946-->00000000 [unknown_code_page]
[1320]svchost.exe-->kernel32.dll-->CreateFileA, Type: Inline - RelativeJump 0x7C801A24-->00000000 [unknown_code_page]
[1320]svchost.exe-->kernel32.dll-->CreateFileW, Type: Inline - RelativeJump 0x7C810770-->00000000 [unknown_code_page]
[1320]svchost.exe-->kernel32.dll-->CreateNamedPipeA, Type: Inline - RelativeJump 0x7C85FE94-->00000000 [unknown_code_page]
[1320]svchost.exe-->kernel32.dll-->CreateNamedPipeW, Type: Inline - RelativeJump 0x7C82F0EF-->00000000 [unknown_code_page]
[1320]svchost.exe-->kernel32.dll-->CreatePipe, Type: Inline - RelativeJump 0x7C81E0D7-->00000000 [unknown_code_page]
[1320]svchost.exe-->kernel32.dll-->CreateProcessA, Type: Inline - RelativeJump 0x7C802367-->00000000 [unknown_code_page]
[1320]svchost.exe-->kernel32.dll-->CreateProcessW, Type: Inline - RelativeJump 0x7C802332-->00000000 [unknown_code_page]
[1320]svchost.exe-->kernel32.dll-->GetProcAddress, Type: Inline - RelativeJump 0x7C80ADB0-->00000000 [unknown_code_page]
[1320]svchost.exe-->kernel32.dll-->GetStartupInfoA, Type: Inline - RelativeJump 0x7C801EEE-->00000000 [unknown_code_page]
[1320]svchost.exe-->kernel32.dll-->GetStartupInfoW, Type: Inline - RelativeJump 0x7C801E50-->00000000 [unknown_code_page]
[1320]svchost.exe-->kernel32.dll-->LoadLibraryA, Type: Inline - RelativeJump 0x7C801D77-->00000000 [unknown_code_page]
[1320]svchost.exe-->kernel32.dll-->LoadLibraryExA, Type: Inline - RelativeJump 0x7C801D4F-->00000000 [unknown_code_page]
[1320]svchost.exe-->kernel32.dll-->LoadLibraryExW, Type: Inline - RelativeJump 0x7C801AF1-->00000000 [unknown_code_page]
[1320]svchost.exe-->kernel32.dll-->LoadLibraryW, Type: Inline - RelativeJump 0x7C80AE5B-->00000000 [unknown_code_page]
[1320]svchost.exe-->kernel32.dll-->VirtualProtect, Type: Inline - RelativeJump 0x7C801AD0-->00000000 [unknown_code_page]
[1320]svchost.exe-->kernel32.dll-->VirtualProtectEx, Type: Inline - RelativeJump 0x7C801A5D-->00000000 [unknown_code_page]
[1320]svchost.exe-->kernel32.dll-->WinExec, Type: Inline - RelativeJump 0x7C86158D-->00000000 [unknown_code_page]
[1320]svchost.exe-->mswsock.dll+0x00004057, Type: Inline - RelativeJump 0x71A54057-->00000000 [unknown_code_page]
[1320]svchost.exe-->mswsock.dll+0x0000433A, Type: Inline - RelativeJump 0x71A5433A-->00000000 [unknown_code_page]
[1320]svchost.exe-->mswsock.dll+0x00005847, Type: Inline - RelativeJump 0x71A55847-->00000000 [unknown_code_page]
[1320]svchost.exe-->ntdll.dll-->KiUserExceptionDispatcher, Type: Inline - RelativeJump 0x7C90E47C-->00000000 [unknown_code_page]
[1320]svchost.exe-->ntdll.dll-->NtProtectVirtualMemory, Type: Inline - RelativeJump 0x7C90D6EE-->00000000 [unknown_code_page]
[1320]svchost.exe-->ntdll.dll-->NtWriteVirtualMemory, Type: Inline - RelativeJump 0x7C90DFAE-->00000000 [unknown_code_page]
[1320]svchost.exe-->user32.dll-->GetCursorPos, Type: Inline - RelativeJump 0x7E41BD76-->00000000 [unknown_code_page]
[1320]svchost.exe-->wininet.dll-->InternetOpenA, Type: Inline - RelativeJump 0x771C57BE-->00000000 [unknown_code_page]
[1320]svchost.exe-->wininet.dll-->InternetOpenUrlA, Type: Inline - RelativeJump 0x771C5A8A-->00000000 [unknown_code_page]
[1320]svchost.exe-->wininet.dll-->InternetOpenUrlW, Type: Inline - RelativeJump 0x771D5C0F-->00000000 [unknown_code_page]
[1320]svchost.exe-->wininet.dll-->InternetOpenW, Type: Inline - RelativeJump 0x771BAF6D-->00000000 [unknown_code_page]
[1320]svchost.exe-->ws2_32.dll-->socket, Type: Inline - RelativeJump 0x71AB3B91-->00000000 [unknown_code_page]
[1728]svchost.exe-->advapi32.dll-->RegCreateKeyA, Type: Inline - RelativeJump 0x77DFBCDB-->00000000 [unknown_code_page]
[1728]svchost.exe-->advapi32.dll-->RegCreateKeyExA, Type: Inline - RelativeJump 0x77DDE9D4-->00000000 [unknown_code_page]
[1728]svchost.exe-->advapi32.dll-->RegCreateKeyExW, Type: Inline - RelativeJump 0x77DD776C-->00000000 [unknown_code_page]
[1728]svchost.exe-->advapi32.dll-->RegCreateKeyW, Type: Inline - RelativeJump 0x77DFBA3D-->00000000 [unknown_code_page]
[1728]svchost.exe-->advapi32.dll-->RegOpenKeyA, Type: Inline - RelativeJump 0x77DDEFA8-->00000000 [unknown_code_page]
[1728]svchost.exe-->advapi32.dll-->RegOpenKeyExA, Type: Inline - RelativeJump 0x77DD7852-->00000000 [unknown_code_page]
[1728]svchost.exe-->advapi32.dll-->RegOpenKeyExW, Type: Inline - RelativeJump 0x77DD6AAF-->00000000 [unknown_code_page]
[1728]svchost.exe-->advapi32.dll-->RegOpenKeyW, Type: Inline - RelativeJump 0x77DD7946-->00000000 [unknown_code_page]
[1728]svchost.exe-->kernel32.dll-->CreateFileA, Type: Inline - RelativeJump 0x7C801A24-->00000000 [unknown_code_page]
[1728]svchost.exe-->kernel32.dll-->CreateFileW, Type: Inline - RelativeJump 0x7C810770-->00000000 [unknown_code_page]
[1728]svchost.exe-->kernel32.dll-->CreateNamedPipeA, Type: Inline - RelativeJump 0x7C85FE94-->00000000 [unknown_code_page]
[1728]svchost.exe-->kernel32.dll-->CreateNamedPipeW, Type: Inline - RelativeJump 0x7C82F0EF-->00000000 [unknown_code_page]
[1728]svchost.exe-->kernel32.dll-->CreatePipe, Type: Inline - RelativeJump 0x7C81E0D7-->00000000 [unknown_code_page]
[1728]svchost.exe-->kernel32.dll-->CreateProcessA, Type: Inline - RelativeJump 0x7C802367-->00000000 [unknown_code_page]
[1728]svchost.exe-->kernel32.dll-->CreateProcessW, Type: Inline - RelativeJump 0x7C802332-->00000000 [unknown_code_page]
[1728]svchost.exe-->kernel32.dll-->GetProcAddress, Type: Inline - RelativeJump 0x7C80ADB0-->00000000 [unknown_code_page]
[1728]svchost.exe-->kernel32.dll-->GetStartupInfoA, Type: Inline - RelativeJump 0x7C801EEE-->00000000 [unknown_code_page]
[1728]svchost.exe-->kernel32.dll-->GetStartupInfoW, Type: Inline - RelativeJump 0x7C801E50-->00000000 [unknown_code_page]
[1728]svchost.exe-->kernel32.dll-->LoadLibraryA, Type: Inline - RelativeJump 0x7C801D77-->00000000 [unknown_code_page]
[1728]svchost.exe-->kernel32.dll-->LoadLibraryExA, Type: Inline - RelativeJump 0x7C801D4F-->00000000 [unknown_code_page]
[1728]svchost.exe-->kernel32.dll-->LoadLibraryExW, Type: Inline - RelativeJump 0x7C801AF1-->00000000 [unknown_code_page]
[1728]svchost.exe-->kernel32.dll-->LoadLibraryW, Type: Inline - RelativeJump 0x7C80AE5B-->00000000 [unknown_code_page]
[1728]svchost.exe-->kernel32.dll-->VirtualProtect, Type: Inline - RelativeJump 0x7C801AD0-->00000000 [unknown_code_page]
[1728]svchost.exe-->kernel32.dll-->VirtualProtectEx, Type: Inline - RelativeJump 0x7C801A5D-->00000000 [unknown_code_page]
[1728]svchost.exe-->kernel32.dll-->WinExec, Type: Inline - RelativeJump 0x7C86158D-->00000000 [unknown_code_page]
[1728]svchost.exe-->wininet.dll-->InternetOpenA, Type: Inline - RelativeJump 0x771C57BE-->00000000 [unknown_code_page]
[1728]svchost.exe-->wininet.dll-->InternetOpenUrlA, Type: Inline - RelativeJump 0x771C5A8A-->00000000 [unknown_code_page]
[1728]svchost.exe-->wininet.dll-->InternetOpenUrlW, Type: Inline - RelativeJump 0x771D5C0F-->00000000 [unknown_code_page]
[1728]svchost.exe-->wininet.dll-->InternetOpenW, Type: Inline - RelativeJump 0x771BAF6D-->00000000 [unknown_code_page]
[1728]svchost.exe-->ws2_32.dll-->socket, Type: Inline - RelativeJump 0x71AB3B91-->00000000 [unknown_code_page]
[1784]svchost.exe-->advapi32.dll-->RegCreateKeyA, Type: Inline - RelativeJump 0x77DFBCDB-->00000000 [unknown_code_page]
[1784]svchost.exe-->advapi32.dll-->RegCreateKeyExA, Type: Inline - RelativeJump 0x77DDE9D4-->00000000 [unknown_code_page]
[1784]svchost.exe-->advapi32.dll-->RegCreateKeyExW, Type: Inline - RelativeJump 0x77DD776C-->00000000 [unknown_code_page]
[1784]svchost.exe-->advapi32.dll-->RegCreateKeyW, Type: Inline - RelativeJump 0x77DFBA3D-->00000000 [unknown_code_page]
[1784]svchost.exe-->advapi32.dll-->RegOpenKeyA, Type: Inline - RelativeJump 0x77DDEFA8-->00000000 [unknown_code_page]
[1784]svchost.exe-->advapi32.dll-->RegOpenKeyExA, Type: Inline - RelativeJump 0x77DD7852-->00000000 [unknown_code_page]
[1784]svchost.exe-->advapi32.dll-->RegOpenKeyExW, Type: Inline - RelativeJump 0x77DD6AAF-->00000000 [unknown_code_page]
[1784]svchost.exe-->advapi32.dll-->RegOpenKeyW, Type: Inline - RelativeJump 0x77DD7946-->00000000 [unknown_code_page]
[1784]svchost.exe-->kernel32.dll-->CreateFileA, Type: Inline - RelativeJump 0x7C801A24-->00000000 [unknown_code_page]
[1784]svchost.exe-->kernel32.dll-->CreateFileW, Type: Inline - RelativeJump 0x7C810770-->00000000 [unknown_code_page]
[1784]svchost.exe-->kernel32.dll-->CreateNamedPipeA, Type: Inline - RelativeJump 0x7C85FE94-->00000000 [unknown_code_page]
[1784]svchost.exe-->kernel32.dll-->CreateNamedPipeW, Type: Inline - RelativeJump 0x7C82F0EF-->00000000 [unknown_code_page]
[1784]svchost.exe-->kernel32.dll-->CreatePipe, Type: Inline - RelativeJump 0x7C81E0D7-->00000000 [unknown_code_page]
[1784]svchost.exe-->kernel32.dll-->CreateProcessA, Type: Inline - RelativeJump 0x7C802367-->00000000 [unknown_code_page]
[1784]svchost.exe-->kernel32.dll-->CreateProcessW, Type: Inline - RelativeJump 0x7C802332-->00000000 [unknown_code_page]
[1784]svchost.exe-->kernel32.dll-->GetProcAddress, Type: Inline - RelativeJump 0x7C80ADB0-->00000000 [unknown_code_page]
[1784]svchost.exe-->kernel32.dll-->GetStartupInfoA, Type: Inline - RelativeJump 0x7C801EEE-->00000000 [unknown_code_page]
[1784]svchost.exe-->kernel32.dll-->GetStartupInfoW, Type: Inline - RelativeJump 0x7C801E50-->00000000 [unknown_code_page]
[1784]svchost.exe-->kernel32.dll-->LoadLibraryA, Type: Inline - RelativeJump 0x7C801D77-->00000000 [unknown_code_page]
[1784]svchost.exe-->kernel32.dll-->LoadLibraryExA, Type: Inline - RelativeJump 0x7C801D4F-->00000000 [unknown_code_page]
[1784]svchost.exe-->kernel32.dll-->LoadLibraryExW, Type: Inline - RelativeJump 0x7C801AF1-->00000000 [unknown_code_page]
[1784]svchost.exe-->kernel32.dll-->LoadLibraryW, Type: Inline - RelativeJump 0x7C80AE5B-->00000000 [unknown_code_page]
[1784]svchost.exe-->kernel32.dll-->VirtualProtect, Type: Inline - RelativeJump 0x7C801AD0-->00000000 [unknown_code_page]
[1784]svchost.exe-->kernel32.dll-->VirtualProtectEx, Type: Inline - RelativeJump 0x7C801A5D-->00000000 [unknown_code_page]
[1784]svchost.exe-->kernel32.dll-->WinExec, Type: Inline - RelativeJump 0x7C86158D-->00000000 [unknown_code_page]
[1784]svchost.exe-->wininet.dll-->InternetOpenA, Type: Inline - RelativeJump 0x771C57BE-->00000000 [unknown_code_page]
[1784]svchost.exe-->wininet.dll-->InternetOpenUrlA, Type: Inline - RelativeJump 0x771C5A8A-->00000000 [unknown_code_page]
[1784]svchost.exe-->wininet.dll-->InternetOpenUrlW, Type: Inline - RelativeJump 0x771D5C0F-->00000000 [unknown_code_page]
[1784]svchost.exe-->wininet.dll-->InternetOpenW, Type: Inline - RelativeJump 0x771BAF6D-->00000000 [unknown_code_page]
[1784]svchost.exe-->ws2_32.dll-->socket, Type: Inline - RelativeJump 0x71AB3B91-->00000000 [unknown_code_page]
[1888]McProxy.exe-->kernel32.dll-->LoadLibraryA, Type: Inline - RelativeJump 0x7C801D77-->00000000 [McProxy.exe]
[1888]McProxy.exe-->kernel32.dll-->LoadLibraryW, Type: Inline - RelativeJump 0x7C80AE5B-->00000000 [McProxy.exe]
[2276]svchost.exe-->advapi32.dll-->RegCreateKeyA, Type: Inline - RelativeJump 0x77DFBCDB-->00000000 [unknown_code_page]
[2276]svchost.exe-->advapi32.dll-->RegCreateKeyExA, Type: Inline - RelativeJump 0x77DDE9D4-->00000000 [unknown_code_page]
[2276]svchost.exe-->advapi32.dll-->RegCreateKeyExW, Type: Inline - RelativeJump 0x77DD776C-->00000000 [unknown_code_page]
[2276]svchost.exe-->advapi32.dll-->RegCreateKeyW, Type: Inline - RelativeJump 0x77DFBA3D-->00000000 [unknown_code_page]
[2276]svchost.exe-->advapi32.dll-->RegOpenKeyA, Type: Inline - RelativeJump 0x77DDEFA8-->00000000 [unknown_code_page]
[2276]svchost.exe-->advapi32.dll-->RegOpenKeyExA, Type: Inline - RelativeJump 0x77DD7852-->00000000 [unknown_code_page]
[2276]svchost.exe-->advapi32.dll-->RegOpenKeyExW, Type: Inline - RelativeJump 0x77DD6AAF-->00000000 [unknown_code_page]
[2276]svchost.exe-->advapi32.dll-->RegOpenKeyW, Type: Inline - RelativeJump 0x77DD7946-->00000000 [unknown_code_page]
[2276]svchost.exe-->kernel32.dll-->CreateFileA, Type: Inline - RelativeJump 0x7C801A24-->00000000 [unknown_code_page]
[2276]svchost.exe-->kernel32.dll-->CreateFileW, Type: Inline - RelativeJump 0x7C810770-->00000000 [unknown_code_page]
[2276]svchost.exe-->kernel32.dll-->CreateNamedPipeA, Type: Inline - RelativeJump 0x7C85FE94-->00000000 [unknown_code_page]
[2276]svchost.exe-->kernel32.dll-->CreateNamedPipeW, Type: Inline - RelativeJump 0x7C82F0EF-->00000000 [unknown_code_page]
[2276]svchost.exe-->kernel32.dll-->CreatePipe, Type: Inline - RelativeJump 0x7C81E0D7-->00000000 [unknown_code_page]
[2276]svchost.exe-->kernel32.dll-->CreateProcessA, Type: Inline - RelativeJump 0x7C802367-->00000000 [unknown_code_page]
[2276]svchost.exe-->kernel32.dll-->CreateProcessW, Type: Inline - RelativeJump 0x7C802332-->00000000 [unknown_code_page]
[2276]svchost.exe-->kernel32.dll-->GetProcAddress, Type: Inline - RelativeJump 0x7C80ADB0-->00000000 [unknown_code_page]
[2276]svchost.exe-->kernel32.dll-->GetStartupInfoA, Type: Inline - RelativeJump 0x7C801EEE-->00000000 [unknown_code_page]
[2276]svchost.exe-->kernel32.dll-->GetStartupInfoW, Type: Inline - RelativeJump 0x7C801E50-->00000000 [unknown_code_page]
[2276]svchost.exe-->kernel32.dll-->LoadLibraryA, Type: Inline - RelativeJump 0x7C801D77-->00000000 [unknown_code_page]
[2276]svchost.exe-->kernel32.dll-->LoadLibraryExA, Type: Inline - RelativeJump 0x7C801D4F-->00000000 [unknown_code_page]
[2276]svchost.exe-->kernel32.dll-->LoadLibraryExW, Type: Inline - RelativeJump 0x7C801AF1-->00000000 [unknown_code_page]
[2276]svchost.exe-->kernel32.dll-->LoadLibraryW, Type: Inline - RelativeJump 0x7C80AE5B-->00000000 [unknown_code_page]
[2276]svchost.exe-->kernel32.dll-->VirtualProtect, Type: Inline - RelativeJump 0x7C801AD0-->00000000 [unknown_code_page]
[2276]svchost.exe-->kernel32.dll-->VirtualProtectEx, Type: Inline - RelativeJump 0x7C801A5D-->00000000 [unknown_code_page]
[2276]svchost.exe-->kernel32.dll-->WinExec, Type: Inline - RelativeJump 0x7C86158D-->00000000 [unknown_code_page]
[2276]svchost.exe-->wininet.dll-->InternetOpenA, Type: Inline - RelativeJump 0x771C57BE-->00000000 [unknown_code_page]
[2276]svchost.exe-->wininet.dll-->InternetOpenUrlA, Type: Inline - RelativeJump 0x771C5A8A-->00000000 [unknown_code_page]
[2276]svchost.exe-->wininet.dll-->InternetOpenUrlW, Type: Inline - RelativeJump 0x771D5C0F-->00000000 [unknown_code_page]
[2276]svchost.exe-->wininet.dll-->InternetOpenW, Type: Inline - RelativeJump 0x771BAF6D-->00000000 [unknown_code_page]
[2360]explorer.exe-->advapi32.dll-->RegCreateKeyA, Type: Inline - RelativeJump 0x77DFBCDB-->00000000 [unknown_code_page]
[2360]explorer.exe-->advapi32.dll-->RegCreateKeyExA, Type: Inline - RelativeJump 0x77DDE9D4-->00000000 [unknown_code_page]
[2360]explorer.exe-->advapi32.dll-->RegCreateKeyExW, Type: Inline - RelativeJump 0x77DD776C-->00000000 [unknown_code_page]
[2360]explorer.exe-->advapi32.dll-->RegCreateKeyW, Type: Inline - RelativeJump 0x77DFBA3D-->00000000 [unknown_code_page]
[2360]explorer.exe-->advapi32.dll-->RegOpenKeyA, Type: Inline - RelativeJump 0x77DDEFA8-->00000000 [unknown_code_page]
[2360]explorer.exe-->advapi32.dll-->RegOpenKeyExA, Type: Inline - RelativeJump 0x77DD7852-->00000000 [unknown_code_page]
[2360]explorer.exe-->advapi32.dll-->RegOpenKeyExW, Type: Inline - RelativeJump 0x77DD6AAF-->00000000 [unknown_code_page]
[2360]explorer.exe-->advapi32.dll-->RegOpenKeyW, Type: Inline - RelativeJump 0x77DD7946-->00000000 [unknown_code_page]
[2360]explorer.exe-->kernel32.dll-->CreateFileA, Type: Inline - RelativeJump 0x7C801A24-->00000000 [unknown_code_page]
[2360]explorer.exe-->kernel32.dll-->CreateFileW, Type: Inline - RelativeJump 0x7C810770-->00000000 [unknown_code_page]
[2360]explorer.exe-->kernel32.dll-->CreateNamedPipeA, Type: Inline - RelativeJump 0x7C85FE94-->00000000 [unknown_code_page]
[2360]explorer.exe-->kernel32.dll-->CreateNamedPipeW, Type: Inline - RelativeJump 0x7C82F0EF-->00000000 [unknown_code_page]
[2360]explorer.exe-->kernel32.dll-->CreatePipe, Type: Inline - RelativeJump 0x7C81E0D7-->00000000 [unknown_code_page]
[2360]explorer.exe-->kernel32.dll-->CreateProcessA, Type: Inline - RelativeJump 0x7C802367-->00000000 [unknown_code_page]
[2360]explorer.exe-->kernel32.dll-->CreateProcessW, Type: Inline - RelativeJump 0x7C802332-->00000000 [unknown_code_page]
[2360]explorer.exe-->kernel32.dll-->GetProcAddress, Type: Inline - RelativeJump 0x7C80ADB0-->00000000 [unknown_code_page]
[2360]explorer.exe-->kernel32.dll-->GetStartupInfoA, Type: Inline - RelativeJump 0x7C801EEE-->00000000 [unknown_code_page]
[2360]explorer.exe-->kernel32.dll-->GetStartupInfoW, Type: Inline - RelativeJump 0x7C801E50-->00000000 [unknown_code_page]
[2360]explorer.exe-->kernel32.dll-->LoadLibraryA, Type: Inline - RelativeJump 0x7C801D77-->00000000 [unknown_code_page]
[2360]explorer.exe-->kernel32.dll-->LoadLibraryExA, Type: Inline - RelativeJump 0x7C801D4F-->00000000 [unknown_code_page]
[2360]explorer.exe-->kernel32.dll-->LoadLibraryExW, Type: Inline - RelativeJump 0x7C801AF1-->00000000 [unknown_code_page]
[2360]explorer.exe-->kernel32.dll-->LoadLibraryW, Type: Inline - RelativeJump 0x7C80AE5B-->00000000 [unknown_code_page]
[2360]explorer.exe-->kernel32.dll-->VirtualProtect, Type: Inline - RelativeJump 0x7C801AD0-->00000000 [unknown_code_page]
[2360]explorer.exe-->kernel32.dll-->VirtualProtectEx, Type: Inline - RelativeJump 0x7C801A5D-->00000000 [unknown_code_page]
[2360]explorer.exe-->kernel32.dll-->WinExec, Type: Inline - RelativeJump 0x7C86158D-->00000000 [unknown_code_page]
[2360]explorer.exe-->mswsock.dll+0x00004057, Type: Inline - RelativeJump 0x71A54057-->00000000 [unknown_code_page]
[2360]explorer.exe-->mswsock.dll+0x0000433A, Type: Inline - RelativeJump 0x71A5433A-->00000000 [unknown_code_page]
[2360]explorer.exe-->mswsock.dll+0x00005847, Type: Inline - RelativeJump 0x71A55847-->00000000 [unknown_code_page]
[2360]explorer.exe-->ntdll.dll-->KiUserExceptionDispatcher, Type: Inline - RelativeJump 0x7C90E47C-->00000000 [unknown_code_page]
[2360]explorer.exe-->ntdll.dll-->NtProtectVirtualMemory, Type: Inline - RelativeJump 0x7C90D6EE-->00000000 [unknown_code_page]
[2360]explorer.exe-->ntdll.dll-->NtWriteVirtualMemory, Type: Inline - RelativeJump 0x7C90DFAE-->00000000 [unknown_code_page]
[2360]explorer.exe-->wininet.dll-->InternetOpenA, Type: Inline - RelativeJump 0x771C57BE-->00000000 [unknown_code_page]
[2360]explorer.exe-->wininet.dll-->InternetOpenUrlA, Type: Inline - RelativeJump 0x771C5A8A-->00000000 [unknown_code_page]
[2360]explorer.exe-->wininet.dll-->InternetOpenUrlW, Type: Inline - RelativeJump 0x771D5C0F-->00000000 [unknown_code_page]
[2360]explorer.exe-->wininet.dll-->InternetOpenW, Type: Inline - RelativeJump 0x771BAF6D-->00000000 [unknown_code_page]
[2360]explorer.exe-->ws2_32.dll-->socket, Type: Inline - RelativeJump 0x71AB3B91-->00000000 [unknown_code_page]
[3268]dllhost.exe-->advapi32.dll-->RegCreateKeyA, Type: Inline - RelativeJump 0x77DFBCDB-->00000000 [unknown_code_page]
[3268]dllhost.exe-->advapi32.dll-->RegCreateKeyExA, Type: Inline - RelativeJump 0x77DDE9D4-->00000000 [unknown_code_page]
[3268]dllhost.exe-->advapi32.dll-->RegCreateKeyExW, Type: Inline - RelativeJump 0x77DD776C-->00000000 [unknown_code_page]
[3268]dllhost.exe-->advapi32.dll-->RegCreateKeyW, Type: Inline - RelativeJump 0x77DFBA3D-->00000000 [unknown_code_page]
[3268]dllhost.exe-->advapi32.dll-->RegOpenKeyA, Type: Inline - RelativeJump 0x77DDEFA8-->00000000 [unknown_code_page]
[3268]dllhost.exe-->advapi32.dll-->RegOpenKeyExA, Type: Inline - RelativeJump 0x77DD7852-->00000000 [unknown_code_page]
[3268]dllhost.exe-->advapi32.dll-->RegOpenKeyExW, Type: Inline - RelativeJump 0x77DD6AAF-->00000000 [unknown_code_page]
[3268]dllhost.exe-->advapi32.dll-->RegOpenKeyW, Type: Inline - RelativeJump 0x77DD7946-->00000000 [unknown_code_page]
[3268]dllhost.exe-->kernel32.dll-->CreateFileA, Type: Inline - RelativeJump 0x7C801A24-->00000000 [unknown_code_page]
[3268]dllhost.exe-->kernel32.dll-->CreateFileW, Type: Inline - RelativeJump 0x7C810770-->00000000 [unknown_code_page]
[3268]dllhost.exe-->kernel32.dll-->CreateNamedPipeA, Type: Inline - RelativeJump 0x7C85FE94-->00000000 [unknown_code_page]
[3268]dllhost.exe-->kernel32.dll-->CreateNamedPipeW, Type: Inline - RelativeJump 0x7C82F0EF-->00000000 [unknown_code_page]
[3268]dllhost.exe-->kernel32.dll-->CreatePipe, Type: Inline - RelativeJump 0x7C81E0D7-->00000000 [unknown_code_page]
[3268]dllhost.exe-->kernel32.dll-->CreateProcessA, Type: Inline - RelativeJump 0x7C802367-->00000000 [unknown_code_page]
[3268]dllhost.exe-->kernel32.dll-->CreateProcessW, Type: Inline - RelativeJump 0x7C802332-->00000000 [unknown_code_page]
[3268]dllhost.exe-->kernel32.dll-->GetProcAddress, Type: Inline - RelativeJump 0x7C80ADB0-->00000000 [unknown_code_page]
[3268]dllhost.exe-->kernel32.dll-->GetStartupInfoA, Type: Inline - RelativeJump 0x7C801EEE-->00000000 [unknown_code_page]
[3268]dllhost.exe-->kernel32.dll-->GetStartupInfoW, Type: Inline - RelativeJump 0x7C801E50-->00000000 [unknown_code_page]
[3268]dllhost.exe-->kernel32.dll-->LoadLibraryA, Type: Inline - RelativeJump 0x7C801D77-->00000000 [unknown_code_page]
[3268]dllhost.exe-->kernel32.dll-->LoadLibraryExA, Type: Inline - RelativeJump 0x7C801D4F-->00000000 [unknown_code_page]
[3268]dllhost.exe-->kernel32.dll-->LoadLibraryExW, Type: Inline - RelativeJump 0x7C801AF1-->00000000 [unknown_code_page]
[3268]dllhost.exe-->kernel32.dll-->LoadLibraryW, Type: Inline - RelativeJump 0x7C80AE5B-->00000000 [unknown_code_page]
[3268]dllhost.exe-->kernel32.dll-->VirtualProtect, Type: Inline - RelativeJump 0x7C801AD0-->00000000 [unknown_code_page]
[3268]dllhost.exe-->kernel32.dll-->VirtualProtectEx, Type: Inline - RelativeJump 0x7C801A5D-->00000000 [unknown_code_page]
[3268]dllhost.exe-->kernel32.dll-->WinExec, Type: Inline - RelativeJump 0x7C86158D-->00000000 [unknown_code_page]
[3268]dllhost.exe-->wininet.dll-->InternetOpenA, Type: Inline - RelativeJump 0x771C57BE-->00000000 [unknown_code_page]
[3268]dllhost.exe-->wininet.dll-->InternetOpenUrlA, Type: Inline - RelativeJump 0x771C5A8A-->00000000 [unknown_code_page]
[3268]dllhost.exe-->wininet.dll-->InternetOpenUrlW, Type: Inline - RelativeJump 0x771D5C0F-->00000000 [unknown_code_page]
[3268]dllhost.exe-->wininet.dll-->InternetOpenW, Type: Inline - RelativeJump 0x771BAF6D-->00000000 [unknown_code_page]
[3268]dllhost.exe-->ws2_32.dll-->socket, Type: Inline - RelativeJump 0x71AB3B91-->00000000 [unknown_code_page]
[3680]wuauclt.exe-->advapi32.dll-->RegCreateKeyA, Type: Inline - RelativeJump 0x77DFBCDB-->00000000 [unknown_code_page]
[3680]wuauclt.exe-->advapi32.dll-->RegCreateKeyExA, Type: Inline - RelativeJump 0x77DDE9D4-->00000000 [unknown_code_page]
[3680]wuauclt.exe-->advapi32.dll-->RegCreateKeyExW, Type: Inline - RelativeJump 0x77DD776C-->00000000 [unknown_code_page]
[3680]wuauclt.exe-->advapi32.dll-->RegCreateKeyW, Type: Inline - RelativeJump 0x77DFBA3D-->00000000 [unknown_code_page]
[3680]wuauclt.exe-->advapi32.dll-->RegOpenKeyA, Type: Inline - RelativeJump 0x77DDEFA8-->00000000 [unknown_code_page]
[3680]wuauclt.exe-->advapi32.dll-->RegOpenKeyExA, Type: Inline - RelativeJump 0x77DD7852-->00000000 [unknown_code_page]
[3680]wuauclt.exe-->advapi32.dll-->RegOpenKeyExW, Type: Inline - RelativeJump 0x77DD6AAF-->00000000 [unknown_code_page]
[3680]wuauclt.exe-->advapi32.dll-->RegOpenKeyW, Type: Inline - RelativeJump 0x77DD7946-->00000000 [unknown_code_page]
[3680]wuauclt.exe-->mswsock.dll+0x00004057, Type: Inline - RelativeJump 0x71A54057-->00000000 [unknown_code_page]
[3680]wuauclt.exe-->mswsock.dll+0x0000433A, Type: Inline - RelativeJump 0x71A5433A-->00000000 [unknown_code_page]
[3680]wuauclt.exe-->mswsock.dll+0x00005847, Type: Inline - RelativeJump 0x71A55847-->00000000 [unknown_code_page]
[3680]wuauclt.exe-->ntdll.dll-->KiUserExceptionDispatcher, Type: Inline - RelativeJump 0x7C90E47C-->00000000 [unknown_code_page]
[3680]wuauclt.exe-->ntdll.dll-->NtProtectVirtualMemory, Type: Inline - RelativeJump 0x7C90D6EE-->00000000 [unknown_code_page]
[3680]wuauclt.exe-->ntdll.dll-->NtWriteVirtualMemory, Type: Inline - RelativeJump 0x7C90DFAE-->00000000 [unknown_code_page]
[688]svchost.exe-->advapi32.dll-->RegCreateKeyA, Type: Inline - RelativeJump 0x77DFBCDB-->00000000 [unknown_code_page]
[688]svchost.exe-->advapi32.dll-->RegCreateKeyExA, Type: Inline - RelativeJump 0x77DDE9D4-->00000000 [unknown_code_page]
[688]svchost.exe-->advapi32.dll-->RegCreateKeyExW, Type: Inline - RelativeJump 0x77DD776C-->00000000 [unknown_code_page]
[688]svchost.exe-->advapi32.dll-->RegCreateKeyW, Type: Inline - RelativeJump 0x77DFBA3D-->00000000 [unknown_code_page]
[688]svchost.exe-->advapi32.dll-->RegOpenKeyA, Type: Inline - RelativeJump 0x77DDEFA8-->00000000 [unknown_code_page]
[688]svchost.exe-->advapi32.dll-->RegOpenKeyExA, Type: Inline - RelativeJump 0x77DD7852-->00000000 [unknown_code_page]
[688]svchost.exe-->advapi32.dll-->RegOpenKeyExW, Type: Inline - RelativeJump 0x77DD6AAF-->00000000 [unknown_code_page]
[688]svchost.exe-->advapi32.dll-->RegOpenKeyW, Type: Inline - RelativeJump 0x77DD7946-->00000000 [unknown_code_page]
[688]svchost.exe-->kernel32.dll-->CreateFileA, Type: Inline - RelativeJump 0x7C801A24-->00000000 [unknown_code_page]
[688]svchost.exe-->kernel32.dll-->CreateFileW, Type: Inline - RelativeJump 0x7C810770-->00000000 [unknown_code_page]
[688]svchost.exe-->kernel32.dll-->CreateNamedPipeA, Type: Inline - RelativeJump 0x7C85FE94-->00000000 [unknown_code_page]
[688]svchost.exe-->kernel32.dll-->CreateNamedPipeW, Type: Inline - RelativeJump 0x7C82F0EF-->00000000 [unknown_code_page]
[688]svchost.exe-->kernel32.dll-->CreatePipe, Type: Inline - RelativeJump 0x7C81E0D7-->00000000 [unknown_code_page]
[688]svchost.exe-->kernel32.dll-->CreateProcessA, Type: Inline - RelativeJump 0x7C802367-->00000000 [unknown_code_page]
[688]svchost.exe-->kernel32.dll-->CreateProcessW, Type: Inline - RelativeJump 0x7C802332-->00000000 [unknown_code_page]
[688]svchost.exe-->kernel32.dll-->GetProcAddress, Type: Inline - RelativeJump 0x7C80ADB0-->00000000 [unknown_code_page]
[688]svchost.exe-->kernel32.dll-->GetStartupInfoA, Type: Inline - RelativeJump 0x7C801EEE-->00000000 [unknown_code_page]
[688]svchost.exe-->kernel32.dll-->GetStartupInfoW, Type: Inline - RelativeJump 0x7C801E50-->00000000 [unknown_code_page]
[688]svchost.exe-->kernel32.dll-->LoadLibraryA, Type: Inline - RelativeJump 0x7C801D77-->00000000 [unknown_code_page]
[688]svchost.exe-->kernel32.dll-->LoadLibraryExA, Type: Inline - RelativeJump 0x7C801D4F-->00000000 [unknown_code_page]
[688]svchost.exe-->kernel32.dll-->LoadLibraryExW, Type: Inline - RelativeJump 0x7C801AF1-->00000000 [unknown_code_page]
[688]svchost.exe-->kernel32.dll-->LoadLibraryW, Type: Inline - RelativeJump 0x7C80AE5B-->00000000 [unknown_code_page]
[688]svchost.exe-->kernel32.dll-->VirtualProtect, Type: Inline - RelativeJump 0x7C801AD0-->00000000 [unknown_code_page]
[688]svchost.exe-->kernel32.dll-->VirtualProtectEx, Type: Inline - RelativeJump 0x7C801A5D-->00000000 [unknown_code_page]
[688]svchost.exe-->kernel32.dll-->WinExec, Type: Inline - RelativeJump 0x7C86158D-->00000000 [unknown_code_page]
[688]svchost.exe-->wininet.dll-->InternetOpenA, Type: Inline - RelativeJump 0x771C57BE-->00000000 [unknown_code_page]
[688]svchost.exe-->wininet.dll-->InternetOpenUrlA, Type: Inline - RelativeJump 0x771C5A8A-->00000000 [unknown_code_page]
[688]svchost.exe-->wininet.dll-->InternetOpenUrlW, Type: Inline - RelativeJump 0x771D5C0F-->00000000 [unknown_code_page]
[688]svchost.exe-->wininet.dll-->InternetOpenW, Type: Inline - RelativeJump 0x771BAF6D-->00000000 [unknown_code_page]
[688]svchost.exe-->ws2_32.dll-->socket, Type: Inline - RelativeJump 0x71AB3B91-->00000000 [unknown_code_page]
[880]services.exe-->advapi32.dll-->RegCreateKeyA, Type: Inline - RelativeJump 0x77DFBCDB-->00000000 [unknown_code_page]
[880]services.exe-->advapi32.dll-->RegCreateKeyExA, Type: Inline - RelativeJump 0x77DDE9D4-->00000000 [unknown_code_page]
[880]services.exe-->advapi32.dll-->RegCreateKeyExW, Type: Inline - RelativeJump 0x77DD776C-->00000000 [unknown_code_page]
[880]services.exe-->advapi32.dll-->RegCreateKeyW, Type: Inline - RelativeJump 0x77DFBA3D-->00000000 [unknown_code_page]
[880]services.exe-->advapi32.dll-->RegOpenKeyA, Type: Inline - RelativeJump 0x77DDEFA8-->00000000 [unknown_code_page]
[880]services.exe-->advapi32.dll-->RegOpenKeyExA, Type: Inline - RelativeJump 0x77DD7852-->00000000 [unknown_code_page]
[880]services.exe-->advapi32.dll-->RegOpenKeyExW, Type: Inline - RelativeJump 0x77DD6AAF-->00000000 [unknown_code_page]
[880]services.exe-->advapi32.dll-->RegOpenKeyW, Type: Inline - RelativeJump 0x77DD7946-->00000000 [unknown_code_page]
[880]services.exe-->kernel32.dll-->CreateFileA, Type: Inline - RelativeJump 0x7C801A24-->00000000 [unknown_code_page]
[880]services.exe-->kernel32.dll-->CreateFileW, Type: Inline - RelativeJump 0x7C810770-->00000000 [unknown_code_page]
[880]services.exe-->kernel32.dll-->CreateNamedPipeA, Type: Inline - RelativeJump 0x7C85FE94-->00000000 [unknown_code_page]
[880]services.exe-->kernel32.dll-->CreateNamedPipeW, Type: Inline - RelativeJump 0x7C82F0EF-->00000000 [unknown_code_page]
[880]services.exe-->kernel32.dll-->CreatePipe, Type: Inline - RelativeJump 0x7C81E0D7-->00000000 [unknown_code_page]
[880]services.exe-->kernel32.dll-->CreateProcessA, Type: Inline - RelativeJump 0x7C802367-->00000000 [unknown_code_page]
[880]services.exe-->kernel32.dll-->CreateProcessW, Type: Inline - RelativeJump 0x7C802332-->00000000 [unknown_code_page]
[880]services.exe-->kernel32.dll-->GetProcAddress, Type: Inline - RelativeJump 0x7C80ADB0-->00000000 [unknown_code_page]
[880]services.exe-->kernel32.dll-->GetStartupInfoA, Type: Inline - RelativeJump 0x7C801EEE-->00000000 [unknown_code_page]
[880]services.exe-->kernel32.dll-->GetStartupInfoW, Type: Inline - RelativeJump 0x7C801E50-->00000000 [unknown_code_page]
[880]services.exe-->kernel32.dll-->LoadLibraryA, Type: Inline - RelativeJump 0x7C801D77-->00000000 [unknown_code_page]
[880]services.exe-->kernel32.dll-->LoadLibraryExA, Type: Inline - RelativeJump 0x7C801D4F-->00000000 [unknown_code_page]
[880]services.exe-->kernel32.dll-->LoadLibraryExW, Type: Inline - RelativeJump 0x7C801AF1-->00000000 [unknown_code_page]
[880]services.exe-->kernel32.dll-->LoadLibraryW, Type: Inline - RelativeJump 0x7C80AE5B-->00000000 [unknown_code_page]
[880]services.exe-->kernel32.dll-->VirtualProtect, Type: Inline - RelativeJump 0x7C801AD0-->00000000 [unknown_code_page]
[880]services.exe-->kernel32.dll-->VirtualProtectEx, Type: Inline - RelativeJump 0x7C801A5D-->00000000 [unknown_code_page]
[880]services.exe-->kernel32.dll-->WinExec, Type: Inline - RelativeJump 0x7C86158D-->00000000 [unknown_code_page]
[880]services.exe-->wininet.dll-->InternetOpenA, Type: Inline - RelativeJump 0x771C57BE-->00000000 [unknown_code_page]
[880]services.exe-->wininet.dll-->InternetOpenUrlA, Type: Inline - RelativeJump 0x771C5A8A-->00000000 [unknown_code_page]
[880]services.exe-->wininet.dll-->InternetOpenUrlW, Type: Inline - RelativeJump 0x771D5C0F-->00000000 [unknown_code_page]
[880]services.exe-->wininet.dll-->InternetOpenW, Type: Inline - RelativeJump 0x771BAF6D-->00000000 [unknown_code_page]
[880]services.exe-->ws2_32.dll-->socket, Type: Inline - RelativeJump 0x71AB3B91-->00000000 [unknown_code_page]
[892]lsass.exe-->advapi32.dll-->RegCreateKeyA, Type: Inline - RelativeJump 0x77DFBCDB-->00000000 [unknown_code_page]
[892]lsass.exe-->advapi32.dll-->RegCreateKeyExA, Type: Inline - RelativeJump 0x77DDE9D4-->00000000 [unknown_code_page]
[892]lsass.exe-->advapi32.dll-->RegCreateKeyExW, Type: Inline - RelativeJump 0x77DD776C-->00000000 [unknown_code_page]
[892]lsass.exe-->advapi32.dll-->RegCreateKeyW, Type: Inline - RelativeJump 0x77DFBA3D-->00000000 [unknown_code_page]
[892]lsass.exe-->advapi32.dll-->RegOpenKeyA, Type: Inline - RelativeJump 0x77DDEFA8-->00000000 [unknown_code_page]
[892]lsass.exe-->advapi32.dll-->RegOpenKeyExA, Type: Inline - RelativeJump 0x77DD7852-->00000000 [unknown_code_page]
[892]lsass.exe-->advapi32.dll-->RegOpenKeyExW, Type: Inline - RelativeJump 0x77DD6AAF-->00000000 [unknown_code_page]
[892]lsass.exe-->advapi32.dll-->RegOpenKeyW, Type: Inline - RelativeJump 0x77DD7946-->00000000 [unknown_code_page]
[892]lsass.exe-->kernel32.dll-->CreateFileA, Type: Inline - RelativeJump 0x7C801A24-->00000000 [unknown_code_page]
[892]lsass.exe-->kernel32.dll-->CreateFileW, Type: Inline - RelativeJump 0x7C810770-->00000000 [unknown_code_page]
[892]lsass.exe-->kernel32.dll-->CreateNamedPipeA, Type: Inline - RelativeJump 0x7C85FE94-->00000000 [unknown_code_page]
[892]lsass.exe-->kernel32.dll-->CreateNamedPipeW, Type: Inline - RelativeJump 0x7C82F0EF-->00000000 [unknown_code_page]
[892]lsass.exe-->kernel32.dll-->CreatePipe, Type: Inline - RelativeJump 0x7C81E0D7-->00000000 [unknown_code_page]
[892]lsass.exe-->kernel32.dll-->CreateProcessA, Type: Inline - RelativeJump 0x7C802367-->00000000 [unknown_code_page]
[892]lsass.exe-->kernel32.dll-->CreateProcessW, Type: Inline - RelativeJump 0x7C802332-->00000000 [unknown_code_page]
[892]lsass.exe-->kernel32.dll-->GetProcAddress, Type: Inline - RelativeJump 0x7C80ADB0-->00000000 [unknown_code_page]
[892]lsass.exe-->kernel32.dll-->GetStartupInfoA, Type: Inline - RelativeJump 0x7C801EEE-->00000000 [unknown_code_page]
[892]lsass.exe-->kernel32.dll-->GetStartupInfoW, Type: Inline - RelativeJump 0x7C801E50-->00000000 [unknown_code_page]
[892]lsass.exe-->kernel32.dll-->LoadLibraryA, Type: Inline - RelativeJump 0x7C801D77-->00000000 [unknown_code_page]
[892]lsass.exe-->kernel32.dll-->LoadLibraryExA, Type: Inline - RelativeJump 0x7C801D4F-->00000000 [unknown_code_page]
[892]lsass.exe-->kernel32.dll-->LoadLibraryExW, Type: Inline - RelativeJump 0x7C801AF1-->00000000 [unknown_code_page]
[892]lsass.exe-->kernel32.dll-->LoadLibraryW, Type: Inline - RelativeJump 0x7C80AE5B-->00000000 [unknown_code_page]
[892]lsass.exe-->kernel32.dll-->VirtualProtect, Type: Inline - RelativeJump 0x7C801AD0-->00000000 [unknown_code_page]
[892]lsass.exe-->kernel32.dll-->VirtualProtectEx, Type: Inline - RelativeJump 0x7C801A5D-->00000000 [unknown_code_page]
[892]lsass.exe-->kernel32.dll-->WinExec, Type: Inline - RelativeJump 0x7C86158D-->00000000 [unknown_code_page]
[892]lsass.exe-->wininet.dll-->InternetOpenA, Type: Inline - RelativeJump 0x771C57BE-->00000000 [unknown_code_page]
[892]lsass.exe-->wininet.dll-->InternetOpenUrlA, Type: Inline - RelativeJump 0x771C5A8A-->00000000 [unknown_code_page]
[892]lsass.exe-->wininet.dll-->InternetOpenUrlW, Type: Inline - RelativeJump 0x771D5C0F-->00000000 [unknown_code_page]
[892]lsass.exe-->wininet.dll-->InternetOpenW, Type: Inline - RelativeJump 0x771BAF6D-->00000000 [unknown_code_page]
[892]lsass.exe-->ws2_32.dll-->socket, Type: Inline - RelativeJump 0x71AB3B91-->00000000 [unknown_code_page]


!!POSSIBLE ROOTKIT ACTIVITY DETECTED!! =)
jkwings
Active Member
 
Posts: 10
Joined: June 29th, 2010, 7:53 pm

Re: Google/Bing redirect error - please help

Unread postby deltalima » July 3rd, 2010, 9:45 am

Hi jkwings,

TDSSKiller

  • Please Download TDSSKiller.exe and save it on your desktop.
  • Important!: only run this fix once.
  • Double click TDSSKiller.exe to run it.
  • a log file should be created on your C: drive named something like TDSSKiller.2.3.2.0 13.06.2010
  • To find the log click Start > Computer > C:.
  • Please post the contents of that log in your next reply.
User avatar
deltalima
Admin/Teacher
Admin/Teacher
 
Posts: 7614
Joined: February 28th, 2009, 4:38 pm
Location: UK

Re: Google/Bing redirect error - please help

Unread postby jkwings » July 3rd, 2010, 10:08 am

The TDSSKiller is asking me to reboot - should I? Here is the log:

10:06:06:312 11936 TDSS rootkit removing tool 2.3.2.2 Jun 30 2010 17:23:49
10:06:06:312 11936 ================================================================================
10:06:06:312 11936 SystemInfo:

10:06:06:312 11936 OS Version: 5.1.2600 ServicePack: 2.0
10:06:06:312 11936 Product type: Workstation
10:06:06:312 11936 ComputerName: RALPH
10:06:06:312 11936 UserName: Jesse
10:06:06:312 11936 Windows directory: C:\WINDOWS
10:06:06:312 11936 System windows directory: C:\WINDOWS
10:06:06:312 11936 Processor architecture: Intel x86
10:06:06:312 11936 Number of processors: 2
10:06:06:312 11936 Page size: 0x1000
10:06:06:328 11936 Boot type: Normal boot
10:06:06:328 11936 ================================================================================
10:06:07:000 11936 Initialize success
10:06:07:000 11936
10:06:07:000 11936 Scanning Services ...
10:06:08:203 11936 Raw services enum returned 393 services
10:06:08:265 11936
10:06:08:265 11936 Scanning Drivers ...
10:06:10:500 11936 abp480n5 (6abb91494fe6c59089b9336452ab2ea3) C:\WINDOWS\system32\DRIVERS\ABP480N5.SYS
10:06:10:671 11936 ACPI (a10c7534f7223f4a73a948967d00e69b) C:\WINDOWS\system32\DRIVERS\ACPI.sys
10:06:10:734 11936 ACPIEC (9859c0f6936e723e4892d7141b1327d5) C:\WINDOWS\system32\drivers\ACPIEC.sys
10:06:10:781 11936 adpu160m (9a11864873da202c996558b2106b0bbc) C:\WINDOWS\system32\DRIVERS\adpu160m.sys
10:06:10:968 11936 aec (1ee7b434ba961ef845de136224c30fec) C:\WINDOWS\system32\drivers\aec.sys
10:06:11:031 11936 AegisP (375eb0b97e3950adef3633c27a82438b) C:\WINDOWS\system32\DRIVERS\AegisP.sys
10:06:11:203 11936 AFD (55e6e1c51b6d30e54335750955453702) C:\WINDOWS\System32\drivers\afd.sys
10:06:11:250 11936 agp440 (2c428fa0c3e3a01ed93c9b2a27d8d4bb) C:\WINDOWS\system32\DRIVERS\agp440.sys
10:06:11:281 11936 agpCPQ (67288b07d6aba6c1267b626e67bc56fd) C:\WINDOWS\system32\DRIVERS\agpCPQ.sys
10:06:11:343 11936 Aha154x (c23ea9b5f46c7f7910db3eab648ff013) C:\WINDOWS\system32\DRIVERS\aha154x.sys
10:06:11:421 11936 aic78u2 (19dd0fb48b0c18892f70e2e7d61a1529) C:\WINDOWS\system32\DRIVERS\aic78u2.sys
10:06:11:531 11936 aic78xx (b7fe594a7468aa0132deb03fb8e34326) C:\WINDOWS\system32\DRIVERS\aic78xx.sys
10:06:11:765 11936 AliIde (1140ab9938809700b46bb88e46d72a96) C:\WINDOWS\system32\DRIVERS\aliide.sys
10:06:12:015 11936 alim1541 (f312b7cef21eff52fa23056b9d815fad) C:\WINDOWS\system32\DRIVERS\alim1541.sys
10:06:12:046 11936 amdagp (675c16a3c1f8482f85ee4a97fc0dde3d) C:\WINDOWS\system32\DRIVERS\amdagp.sys
10:06:12:109 11936 amsint (79f5add8d24bd6893f2903a3e2f3fad6) C:\WINDOWS\system32\DRIVERS\amsint.sys
10:06:12:281 11936 APPDRV (ec94e05b76d033b74394e7b2175103cf) C:\WINDOWS\SYSTEM32\DRIVERS\APPDRV.SYS
10:06:12:500 11936 Arp1394 (f0d692b0bffb46e30eb3cea168bbc49f) C:\WINDOWS\system32\DRIVERS\arp1394.sys
10:06:12:578 11936 asc (62d318e9a0c8fc9b780008e724283707) C:\WINDOWS\system32\DRIVERS\asc.sys
10:06:12:671 11936 asc3350p (69eb0cc7714b32896ccbfd5edcbea447) C:\WINDOWS\system32\DRIVERS\asc3350p.sys
10:06:12:750 11936 asc3550 (5d8de112aa0254b907861e9e9c31d597) C:\WINDOWS\system32\DRIVERS\asc3550.sys
10:06:12:875 11936 AsyncMac (02000abf34af4c218c35d257024807d6) C:\WINDOWS\system32\DRIVERS\asyncmac.sys
10:06:12:906 11936 atapi (cdfe4411a69c224bd1d11b2da92dac51) C:\WINDOWS\system32\DRIVERS\atapi.sys
10:06:13:000 11936 ati2mtag (2573c08729dd52b7b4f18df1592e0b37) C:\WINDOWS\system32\DRIVERS\ati2mtag.sys
10:06:13:140 11936 Atmarpc (ec88da854ab7d7752ec8be11a741bb7f) C:\WINDOWS\system32\DRIVERS\atmarpc.sys
10:06:13:171 11936 audstub (d9f724aa26c010a217c97606b160ed68) C:\WINDOWS\system32\DRIVERS\audstub.sys
10:06:13:250 11936 bcm4sbxp (6489310d11971f6ba6c7f49be0baf6e0) C:\WINDOWS\system32\DRIVERS\bcm4sbxp.sys
10:06:13:531 11936 Beep (da1f27d85e0d1525f6621372e7b685e9) C:\WINDOWS\system32\drivers\Beep.sys
10:06:13:562 11936 cbidf (90a673fc8e12a79afbed2576f6a7aaf9) C:\WINDOWS\system32\DRIVERS\cbidf2k.sys
10:06:13:625 11936 cbidf2k (90a673fc8e12a79afbed2576f6a7aaf9) C:\WINDOWS\system32\drivers\cbidf2k.sys
10:06:13:656 11936 CCDECODE (6163ed60b684bab19d3352ab22fc48b2) C:\WINDOWS\system32\DRIVERS\CCDECODE.sys
10:06:13:703 11936 cd20xrnt (f3ec03299634490e97bbce94cd2954c7) C:\WINDOWS\system32\DRIVERS\cd20xrnt.sys
10:06:13:828 11936 Cdaudio (c1b486a7658353d33a10cc15211a873b) C:\WINDOWS\system32\drivers\Cdaudio.sys
10:06:13:906 11936 Cdfs (cd7d5152df32b47f4e36f710b35aae02) C:\WINDOWS\system32\drivers\Cdfs.sys
10:06:13:968 11936 Cdrom (af9c19b3100fe010496b1a27181fbf72) C:\WINDOWS\system32\DRIVERS\cdrom.sys
10:06:14:015 11936 CmBatt (4266be808f85826aedf3c64c1e240203) C:\WINDOWS\system32\DRIVERS\CmBatt.sys
10:06:14:046 11936 CmdIde (e5dcb56c533014ecbc556a8357c929d5) C:\WINDOWS\system32\DRIVERS\cmdide.sys
10:06:14:078 11936 Compbatt (df1b1a24bf52d0ebc01ed4ece8979f50) C:\WINDOWS\system32\DRIVERS\compbatt.sys
10:06:14:125 11936 Cpqarray (3ee529119eed34cd212a215e8c40d4b6) C:\WINDOWS\system32\DRIVERS\cpqarray.sys
10:06:14:171 11936 dac2w2k (e550e7418984b65a78299d248f0a7f36) C:\WINDOWS\system32\DRIVERS\dac2w2k.sys
10:06:14:203 11936 dac960nt (683789caa3864eb46125ae86ff677d34) C:\WINDOWS\system32\DRIVERS\dac960nt.sys
10:06:14:390 11936 Disk (00ca44e4534865f8a3b64f7c0984bff0) C:\WINDOWS\system32\DRIVERS\disk.sys
10:06:14:500 11936 dmboot (c0fbb516e06e243f0cf31f597e7ebf7d) C:\WINDOWS\system32\drivers\dmboot.sys
10:06:14:546 11936 dmio (f5e7b358a732d09f4bcf2824b88b9e28) C:\WINDOWS\system32\drivers\dmio.sys
10:06:14:578 11936 dmload (e9317282a63ca4d188c0df5e09c6ac5f) C:\WINDOWS\system32\drivers\dmload.sys
10:06:14:640 11936 DMusic (a6f881284ac1150e37d9ae47ff601267) C:\WINDOWS\system32\drivers\DMusic.sys
10:06:14:734 11936 dpti2o (40f3b93b4e5b0126f2f5c0a7a5e22660) C:\WINDOWS\system32\DRIVERS\dpti2o.sys
10:06:14:796 11936 drmkaud (1ed4dbbae9f5d558dbba4cc450e3eb2e) C:\WINDOWS\system32\drivers\drmkaud.sys
10:06:14:843 11936 drvmcdb (e814854e6b246ccf498874839ab64d77) C:\WINDOWS\system32\drivers\drvmcdb.sys
10:06:14:937 11936 drvnddm (ee83a4ebae70bc93cf14879d062f548b) C:\WINDOWS\system32\drivers\drvnddm.sys
10:06:15:156 11936 DSproct (2ac2372ffad9adc85672cc8e8ae14be9) C:\Program Files\Dell Support\GTAction\triggers\DSproct.sys
10:06:15:375 11936 E100B (3fca03cbca11269f973b70fa483c88ef) C:\WINDOWS\system32\DRIVERS\e100b325.sys
10:06:15:515 11936 Fastfat (3117f595e9615e04f05a54fc15a03b20) C:\WINDOWS\system32\drivers\Fastfat.sys
10:06:15:546 11936 Fdc (ced2e8396a8838e59d8fd529c680e02c) C:\WINDOWS\system32\DRIVERS\fdc.sys
10:06:15:578 11936 Fips (e153ab8a11de5452bcf5ac7652dbf3ed) C:\WINDOWS\system32\drivers\Fips.sys
10:06:15:593 11936 Flpydisk (0dd1de43115b93f4d85e889d7a86f548) C:\WINDOWS\system32\DRIVERS\flpydisk.sys
10:06:15:656 11936 FltMgr (3d234fb6d6ee875eb009864a299bea29) C:\WINDOWS\system32\DRIVERS\fltMgr.sys
10:06:15:875 11936 Fs_Rec (3e1e2bd4f39b0e2b7dc4f4d2bcc2779a) C:\WINDOWS\system32\drivers\Fs_Rec.sys
10:06:15:921 11936 Ftdisk (6ac26732762483366c3969c9e4d2259d) C:\WINDOWS\system32\DRIVERS\ftdisk.sys
10:06:15:984 11936 GEARAspiWDM (8182ff89c65e4d38b2de4bb0fb18564e) C:\WINDOWS\system32\Drivers\GEARAspiWDM.sys
10:06:16:109 11936 Gpc (c0f1d4a21de5a415df8170616703debf) C:\WINDOWS\system32\DRIVERS\msgpc.sys
10:06:16:187 11936 HDAudBus (e31363d186b3e1d7c4e9117884a6aee5) C:\WINDOWS\system32\DRIVERS\HDAudBus.sys
10:06:16:437 11936 HidUsb (1de6783b918f540149aa69943bdfeba8) C:\WINDOWS\system32\DRIVERS\hidusb.sys
10:06:16:484 11936 hpn (b028377dea0546a5fcfba928a8aefae0) C:\WINDOWS\system32\DRIVERS\hpn.sys
10:06:16:609 11936 HPZid412 (30ca91e657cede2f95359d6ef186f650) C:\WINDOWS\system32\DRIVERS\HPZid412.sys
10:06:16:656 11936 HPZipr12 (efd31afa752aa7c7bbb57bcbe2b01c78) C:\WINDOWS\system32\DRIVERS\HPZipr12.sys
10:06:16:781 11936 HPZius12 (7ac43c38ca8fd7ed0b0a4466f753e06e) C:\WINDOWS\system32\DRIVERS\HPZius12.sys
10:06:16:937 11936 HSFHWAZL (1c8caa80e91fb71864e9426f9eed048d) C:\WINDOWS\system32\DRIVERS\HSFHWAZL.sys
10:06:17:109 11936 HSF_DPV (698204d9c2832e53633e53a30a53fc3d) C:\WINDOWS\system32\DRIVERS\HSF_DPV.sys
10:06:17:375 11936 HTTP (9f8b0f4276f618964fd118be4289b7cd) C:\WINDOWS\system32\Drivers\HTTP.sys
10:06:17:609 11936 i2omgmt (8f09f91b5c91363b77bcd15599570f2c) C:\WINDOWS\system32\drivers\i2omgmt.sys
10:06:17:656 11936 i2omp (ed6bf9e441fdea13292a6d30a64a24c3) C:\WINDOWS\system32\DRIVERS\i2omp.sys
10:06:17:671 11936 i8042prt (5502b58eef7486ee6f93f3f164dcb808) C:\WINDOWS\system32\DRIVERS\i8042prt.sys
10:06:17:703 11936 Imapi (f8aa320c6a0409c0380e5d8a99d76ec6) C:\WINDOWS\system32\DRIVERS\imapi.sys
10:06:17:734 11936 ini910u (4a40e045faee58631fd8d91afc620719) C:\WINDOWS\system32\DRIVERS\ini910u.sys
10:06:17:906 11936 IntelIde (2d722b2b54ab55b2fa475eb58d7b2aad) C:\WINDOWS\system32\DRIVERS\intelide.sys
10:06:17:921 11936 intelppm (279fb78702454dff2bb445f238c048d2) C:\WINDOWS\system32\DRIVERS\intelppm.sys
10:06:17:953 11936 Ip6Fw (4448006b6bc60e6c027932cfc38d6855) C:\WINDOWS\system32\DRIVERS\Ip6Fw.sys
10:06:18:000 11936 IpFilterDriver (731f22ba402ee4b62748adaf6363c182) C:\WINDOWS\system32\DRIVERS\ipfltdrv.sys
10:06:18:062 11936 IpInIp (e1ec7f5da720b640cd8fb8424f1b14bb) C:\WINDOWS\system32\DRIVERS\ipinip.sys
10:06:18:109 11936 IpNat (e2168cbc7098ffe963c6f23f472a3593) C:\WINDOWS\system32\DRIVERS\ipnat.sys
10:06:18:140 11936 IPSec (64537aa5c003a6afeee1df819062d0d1) C:\WINDOWS\system32\DRIVERS\ipsec.sys
10:06:18:171 11936 IRENUM (50708daa1b1cbb7d6ac1cf8f56a24410) C:\WINDOWS\system32\DRIVERS\irenum.sys
10:06:18:218 11936 isapnp (e504f706ccb699c2596e9a3da1596e87) C:\WINDOWS\system32\DRIVERS\isapnp.sys
10:06:18:312 11936 Kbdclass (ebdee8a2ee5393890a1acee971c4c246) C:\WINDOWS\system32\DRIVERS\kbdclass.sys
10:06:18:359 11936 kbdhid (e182fa8e49e8ee41b4adc53093f3c7e6) C:\WINDOWS\system32\DRIVERS\kbdhid.sys
10:06:18:437 11936 klmd23 (316353165feba3d0538eaa9c2f60c5b7) C:\WINDOWS\system32\drivers\klmd.sys
10:06:18:484 11936 kmixer (ba5deda4d934e6288c2f66caf58d2562) C:\WINDOWS\system32\drivers\kmixer.sys
10:06:18:546 11936 KSecDD (1be7cc2535d760ae4d481576eb789f24) C:\WINDOWS\system32\drivers\KSecDD.sys
10:06:18:609 11936 mdmxsdk (3c318b9cd391371bed62126581ee9961) C:\WINDOWS\system32\DRIVERS\mdmxsdk.sys
10:06:18:828 11936 mfeavfk (bafdd5e28baea99d7f4772af2f5ec7ee) C:\WINDOWS\system32\drivers\mfeavfk.sys
10:06:19:000 11936 mfebopk (1d003e3056a43d881597d6763e83b943) C:\WINDOWS\system32\drivers\mfebopk.sys
10:06:19:218 11936 mfehidk (3f138a1c8a0659f329f242d1e389b2cf) C:\WINDOWS\system32\drivers\mfehidk.sys
10:06:19:406 11936 mferkdk (41fe2f288e05a6c8ab85dd56770ffbad) C:\WINDOWS\system32\drivers\mferkdk.sys
10:06:19:656 11936 mfesmfk (096b52ea918aa909ba5903d79e129005) C:\WINDOWS\system32\drivers\mfesmfk.sys
10:06:19:796 11936 mnmdd (4ae068242760a1fb6e1a44bf4e16afa6) C:\WINDOWS\system32\drivers\mnmdd.sys
10:06:19:828 11936 Modem (6fc6f9d7acc36dca9b914565a3aeda05) C:\WINDOWS\system32\drivers\Modem.sys
10:06:19:875 11936 Mouclass (34e1f0031153e491910e12551400192c) C:\WINDOWS\system32\DRIVERS\mouclass.sys
10:06:19:921 11936 mouhid (b1c303e17fb9d46e87a98e4ba6769685) C:\WINDOWS\system32\DRIVERS\mouhid.sys
10:06:20:031 11936 MountMgr (65653f3b4477f3c63e68a9659f85ee2e) C:\WINDOWS\system32\drivers\MountMgr.sys
10:06:20:078 11936 MPFP (136157e79849b9e5316ba4008d6075a8) C:\WINDOWS\system32\Drivers\Mpfp.sys
10:06:20:265 11936 mraid35x (3f4bb95e5a44f3be34824e8e7caf0737) C:\WINDOWS\system32\DRIVERS\mraid35x.sys
10:06:20:375 11936 MRxDAV (29414447eb5bde2f8397dc965dbb3156) C:\WINDOWS\system32\DRIVERS\mrxdav.sys
10:06:20:484 11936 MRxSmb (fb6c89bb3ce282b08bdb1e3c179e1c39) C:\WINDOWS\system32\DRIVERS\mrxsmb.sys
10:06:20:781 11936 Msfs (561b3a4333ca2dbdba28b5b956822519) C:\WINDOWS\system32\drivers\Msfs.sys
10:06:20:875 11936 MSHUSBVideo (1bf0eece5d9268d3b822e6c50dbd085f) C:\WINDOWS\system32\Drivers\nx6000.sys
10:06:20:984 11936 MSKSSRV (ae431a8dd3c1d0d0610cdbac16057ad0) C:\WINDOWS\system32\drivers\MSKSSRV.sys
10:06:21:015 11936 MSPCLOCK (13e75fef9dfeb08eeded9d0246e1f448) C:\WINDOWS\system32\drivers\MSPCLOCK.sys
10:06:21:046 11936 MSPQM (1988a33ff19242576c3d0ef9ce785da7) C:\WINDOWS\system32\drivers\MSPQM.sys
10:06:21:078 11936 mssmbios (469541f8bfd2b32659d5d463a6714bce) C:\WINDOWS\system32\DRIVERS\mssmbios.sys
10:06:21:171 11936 MSTEE (bf13612142995096ab084f2db7f40f77) C:\WINDOWS\system32\drivers\MSTEE.sys
10:06:21:265 11936 Mup (82035e0f41c2dd05ae41d27fe6cf7de1) C:\WINDOWS\system32\drivers\Mup.sys
10:06:21:296 11936 NABTSFEC (5c8dc6429c43dc6177c1fa5b76290d1a) C:\WINDOWS\system32\DRIVERS\NABTSFEC.sys
10:06:21:359 11936 NDIS (558635d3af1c7546d26067d5d9b6959e) C:\WINDOWS\system32\drivers\NDIS.sys
10:06:21:390 11936 NdisIP (520ce427a8b298f54112857bcf6bde15) C:\WINDOWS\system32\DRIVERS\NdisIP.sys
10:06:21:453 11936 NdisTapi (08d43bbdacdf23f34d79e44ed35c1b4c) C:\WINDOWS\system32\DRIVERS\ndistapi.sys
10:06:21:484 11936 Ndisuio (34d6cd56409da9a7ed573e1c90a308bf) C:\WINDOWS\system32\DRIVERS\ndisuio.sys
10:06:21:515 11936 NdisWan (0b90e255a9490166ab368cd55a529893) C:\WINDOWS\system32\DRIVERS\ndiswan.sys
10:06:21:578 11936 NDProxy (59fc3fb44d2669bc144fd87826bb571f) C:\WINDOWS\system32\drivers\NDProxy.sys
10:06:21:640 11936 NetBIOS (3a2aca8fc1d7786902ca434998d7ceb4) C:\WINDOWS\system32\DRIVERS\netbios.sys
10:06:21:687 11936 NetBT (0c80e410cd2f47134407ee7dd19cc86b) C:\WINDOWS\system32\DRIVERS\netbt.sys
10:06:21:781 11936 NETw3x32 (71371ed9086a3d65f43967c89634e9a9) C:\WINDOWS\system32\DRIVERS\NETw3x32.sys
10:06:21:984 11936 NIC1394 (5c5c53db4fef16cf87b9911c7e8c6fbc) C:\WINDOWS\system32\DRIVERS\nic1394.sys
10:06:22:062 11936 Npfs (4f601bcb8f64ea3ac0994f98fed03f8e) C:\WINDOWS\system32\drivers\Npfs.sys
10:06:22:109 11936 Ntfs (19a811ef5f1ed5c926a028ce107ff1af) C:\WINDOWS\system32\drivers\Ntfs.sys
10:06:22:281 11936 Null (73c1e1f395918bc2c6dd67af7591a3ad) C:\WINDOWS\system32\drivers\Null.sys
10:06:22:453 11936 nv (2b298519edbfcf451d43e0f1e8f1006d) C:\WINDOWS\system32\DRIVERS\nv4_mini.sys
10:06:22:562 11936 NwlnkFlt (b305f3fad35083837ef46a0bbce2fc57) C:\WINDOWS\system32\DRIVERS\nwlnkflt.sys
10:06:22:578 11936 NwlnkFwd (c99b3415198d1aab7227f2c88fd664b9) C:\WINDOWS\system32\DRIVERS\nwlnkfwd.sys
10:06:22:609 11936 ohci1394 (0951db8e5823ea366b0e408d71e1ba2a) C:\WINDOWS\system32\DRIVERS\ohci1394.sys
10:06:22:734 11936 omci (b17228142cec9b3c222239fd935a37ca) C:\WINDOWS\system32\DRIVERS\omci.sys
10:06:22:875 11936 Parport (29744eb4ce659dfe3b4122deb45bc478) C:\WINDOWS\system32\DRIVERS\parport.sys
10:06:22:953 11936 PartMgr (3334430c29dc338092f79c38ef7b4cd0) C:\WINDOWS\system32\drivers\PartMgr.sys
10:06:22:984 11936 ParVdm (70e98b3fd8e963a6a46a2e6247e0bea1) C:\WINDOWS\system32\drivers\ParVdm.sys
10:06:23:000 11936 PCI (8086d9979234b603ad5bc2f5d890b234) C:\WINDOWS\system32\DRIVERS\pci.sys
10:06:23:140 11936 PCIIde (ccf5f451bb1a5a2a522a76e670000ff0) C:\WINDOWS\system32\DRIVERS\pciide.sys
10:06:23:187 11936 Pcmcia (82a087207decec8456fbe8537947d579) C:\WINDOWS\system32\drivers\Pcmcia.sys
10:06:23:234 11936 PCTCore (807ff1dd6e1bdf8e7d2062fca0daecaf) C:\WINDOWS\system32\drivers\PCTCore.sys
10:06:23:500 11936 perc2 (6c14b9c19ba84f73d3a86dba11133101) C:\WINDOWS\system32\DRIVERS\perc2.sys
10:06:23:812 11936 perc2hib (f50f7c27f131afe7beba13e14a3b9416) C:\WINDOWS\system32\DRIVERS\perc2hib.sys
10:06:23:875 11936 PptpMiniport (1c5cc65aac0783c344f16353e60b72ac) C:\WINDOWS\system32\DRIVERS\raspptp.sys
10:06:23:906 11936 PSched (48671f327553dcf1d27f6197f622a668) C:\WINDOWS\system32\DRIVERS\psched.sys
10:06:23:968 11936 Ptilink (80d317bd1c3dbc5d4fe7b1678c60cadd) C:\WINDOWS\system32\DRIVERS\ptilink.sys
10:06:24:031 11936 PxHelp20 (0457e25bb122b854e267cf552dcdc370) C:\WINDOWS\system32\Drivers\PxHelp20.sys
10:06:24:203 11936 ql1080 (0a63fb54039eb5662433caba3b26dba7) C:\WINDOWS\system32\DRIVERS\ql1080.sys
10:06:24:234 11936 Ql10wnt (6503449e1d43a0ff0201ad5cb1b8c706) C:\WINDOWS\system32\DRIVERS\ql10wnt.sys
10:06:24:281 11936 ql12160 (156ed0ef20c15114ca097a34a30d8a01) C:\WINDOWS\system32\DRIVERS\ql12160.sys
10:06:24:296 11936 ql1240 (70f016bebde6d29e864c1230a07cc5e6) C:\WINDOWS\system32\DRIVERS\ql1240.sys
10:06:24:328 11936 ql1280 (907f0aeea6bc451011611e732bd31fcf) C:\WINDOWS\system32\DRIVERS\ql1280.sys
10:06:24:390 11936 RasAcd (fe0d99d6f31e4fad8159f690d68ded9c) C:\WINDOWS\system32\DRIVERS\rasacd.sys
10:06:24:421 11936 Rasl2tp (98faeb4a4dcf812ba1c6fca4aa3e115c) C:\WINDOWS\system32\DRIVERS\rasl2tp.sys
10:06:24:453 11936 RasPppoe (7306eeed8895454cbed4669be9f79faa) C:\WINDOWS\system32\DRIVERS\raspppoe.sys
10:06:24:468 11936 Raspti (fdbb1d60066fcfbb7452fd8f9829b242) C:\WINDOWS\system32\DRIVERS\raspti.sys
10:06:24:546 11936 Rdbss (03b965b1ca47f6ef60eb5e51cb50e0af) C:\WINDOWS\system32\DRIVERS\rdbss.sys
10:06:24:656 11936 RDPCDD (4912d5b403614ce99c28420f75353332) C:\WINDOWS\system32\DRIVERS\RDPCDD.sys
10:06:24:765 11936 rdpdr (a2cae2c60bc37e0751ef9dda7ceaf4ad) C:\WINDOWS\system32\DRIVERS\rdpdr.sys
10:06:24:937 11936 RDPWD (b54cd38a9ebfbf2b3561426e3fe26f62) C:\WINDOWS\system32\drivers\RDPWD.sys
10:06:24:984 11936 redbook (b31b4588e4086d8d84adbf9845c2402b) C:\WINDOWS\system32\DRIVERS\redbook.sys
10:06:25:046 11936 rimmptsk (24ed7af20651f9fa1f249482e7c1f165) C:\WINDOWS\system32\DRIVERS\rimmptsk.sys
10:06:25:281 11936 rimsptsk (1bdba2d2d402415a78a4ba766dfe0f7b) C:\WINDOWS\system32\DRIVERS\rimsptsk.sys
10:06:25:562 11936 rismxdp (f774ecd11a064f0debb2d4395418153c) C:\WINDOWS\system32\DRIVERS\rixdptsk.sys
10:06:25:796 11936 s24trans (daef68fc328342d219de928c8ee610b2) C:\WINDOWS\system32\DRIVERS\s24trans.sys
10:06:25:953 11936 sdbus (02fc71b020ec8700ee8a46c58bc6f276) C:\WINDOWS\system32\DRIVERS\sdbus.sys
10:06:26:015 11936 Secdrv (90a3935d05b494a5a39d37e71f09a677) C:\WINDOWS\system32\DRIVERS\secdrv.sys
10:06:26:046 11936 serenum (a2d868aeeff612e70e213c451a70cafb) C:\WINDOWS\system32\DRIVERS\serenum.sys
10:06:26:078 11936 Serial (cd9404d115a00d249f70a371b46d5a26) C:\WINDOWS\system32\DRIVERS\serial.sys
10:06:26:109 11936 Sfloppy (0d13b6df6e9e101013a7afb0ce629fe0) C:\WINDOWS\system32\drivers\Sfloppy.sys
10:06:26:187 11936 sisagp (732d859b286da692119f286b21a2a114) C:\WINDOWS\system32\DRIVERS\sisagp.sys
10:06:26:234 11936 SLIP (5caeed86821fa2c6139e32e9e05ccdc9) C:\WINDOWS\system32\DRIVERS\SLIP.sys
10:06:26:328 11936 Sparrow (83c0f71f86d3bdaf915685f3d568b20e) C:\WINDOWS\system32\DRIVERS\sparrow.sys
10:06:26:390 11936 splitter (0ce218578fff5f4f7e4201539c45c78f) C:\WINDOWS\system32\drivers\splitter.sys
10:06:26:421 11936 sr (e41b6d037d6cd08461470af04500dc24) C:\WINDOWS\system32\DRIVERS\sr.sys
10:06:26:468 11936 Srv (7a4f147cc6b133f905f6e65e2f8669fb) C:\WINDOWS\system32\DRIVERS\srv.sys
10:06:26:781 11936 sscdbhk5 (d7968049be0adbb6a57cee3960320911) C:\WINDOWS\system32\drivers\sscdbhk5.sys
10:06:26:937 11936 ssrtln (c3ffd65abfb6441e7606cf74f1155273) C:\WINDOWS\system32\drivers\ssrtln.sys
10:06:27:078 11936 STHDA (3ad78e22210d3fbd9f76de84a8df19b5) C:\WINDOWS\system32\drivers\sthda.sys
10:06:27:328 11936 streamip (284c57df5dc7abca656bc2b96a667afb) C:\WINDOWS\system32\DRIVERS\StreamIP.sys
10:06:27:359 11936 swenum (03c1bae4766e2450219d20b993d6e046) C:\WINDOWS\system32\DRIVERS\swenum.sys
10:06:27:390 11936 swmidi (94abc808fc4b6d7d2bbf42b85e25bb4d) C:\WINDOWS\system32\drivers\swmidi.sys
10:06:27:437 11936 symc810 (1ff3217614018630d0a6758630fc698c) C:\WINDOWS\system32\DRIVERS\symc810.sys
10:06:27:515 11936 symc8xx (070e001d95cf725186ef8b20335f933c) C:\WINDOWS\system32\DRIVERS\symc8xx.sys
10:06:27:890 11936 sym_hi (80ac1c4abbe2df3b738bf15517a51f2c) C:\WINDOWS\system32\DRIVERS\sym_hi.sys
10:06:27:937 11936 sym_u3 (bf4fab949a382a8e105f46ebb4937058) C:\WINDOWS\system32\DRIVERS\sym_u3.sys
10:06:28:093 11936 SynTP (fa2daa32bed908023272a0f77d625dae) C:\WINDOWS\system32\DRIVERS\SynTP.sys
10:06:28:343 11936 sysaudio (650ad082d46bac0e64c9c0e0928492fd) C:\WINDOWS\system32\drivers\sysaudio.sys
10:06:28:406 11936 Tcpip (2a5554fc5b1e04e131230e3ce035c3f9) C:\WINDOWS\system32\DRIVERS\tcpip.sys
10:06:28:468 11936 TDPIPE (38d437cf2d98965f239b0abcd66dcb0f) C:\WINDOWS\system32\drivers\TDPIPE.sys
10:06:28:484 11936 TDTCP (ed0580af02502d00ad8c4c066b156be9) C:\WINDOWS\system32\drivers\TDTCP.sys
10:06:28:515 11936 TermDD (a540a99c281d933f3d69d55e48727f47) C:\WINDOWS\system32\DRIVERS\termdd.sys
10:06:28:593 11936 tfsnboio (30698355067d07da5f9eb81132c9fdd6) C:\WINDOWS\system32\dla\tfsnboio.sys
10:06:28:781 11936 tfsncofs (fb9d825bb4a2abdf24600f7505050e2b) C:\WINDOWS\system32\dla\tfsncofs.sys
10:06:28:906 11936 tfsndrct (cafd8cca11aa1e8b6d2ea1ba8f70ec33) C:\WINDOWS\system32\dla\tfsndrct.sys
10:06:29:015 11936 tfsndres (8db1e78fbf7c426d8ec3d8f1a33d6485) C:\WINDOWS\system32\dla\tfsndres.sys
10:06:29:125 11936 tfsnifs (b92f67a71cc8176f331b8aa8d9f555ad) C:\WINDOWS\system32\dla\tfsnifs.sys
10:06:29:343 11936 tfsnopio (85985faa9a71e2358fcc2edefc2a3c5c) C:\WINDOWS\system32\dla\tfsnopio.sys
10:06:29:421 11936 tfsnpool (bba22094f0f7c210567efdaf11f64495) C:\WINDOWS\system32\dla\tfsnpool.sys
10:06:29:546 11936 tfsnudf (81340bef80b9811e98ce64611e67e3ff) C:\WINDOWS\system32\dla\tfsnudf.sys
10:06:29:828 11936 tfsnudfa (c035fd116224ccc8325f384776b6a8bb) C:\WINDOWS\system32\dla\tfsnudfa.sys
10:06:30:031 11936 TosIde (f2790f6af01321b172aa62f8e1e187d9) C:\WINDOWS\system32\DRIVERS\toside.sys
10:06:30:078 11936 Udfs (12f70256f140cd7d52c58c7048fde657) C:\WINDOWS\system32\drivers\Udfs.sys
10:06:30:125 11936 ultra (1b698a51cd528d8da4ffaed66dfc51b9) C:\WINDOWS\system32\DRIVERS\ultra.sys
10:06:30:312 11936 Update (ced744117e91bdc0beb810f7d8608183) C:\WINDOWS\system32\DRIVERS\update.sys
10:06:30:375 11936 USBAAPL (1df89c499bf45d878b87ebd4421d462d) C:\WINDOWS\system32\Drivers\usbaapl.sys
10:06:30:609 11936 usbaudio (45a0d14b26c35497ad93bce7e15c9941) C:\WINDOWS\system32\drivers\usbaudio.sys
10:06:30:781 11936 usbccgp (bffd9f120cc63bcbaa3d840f3eef9f79) C:\WINDOWS\system32\DRIVERS\usbccgp.sys
10:06:30:828 11936 usbehci (708579b01fed227aadb393cb0c3b4a2c) C:\WINDOWS\system32\DRIVERS\usbehci.sys
10:06:30:937 11936 usbhub (c72f40947f92cea56a8fb532edf025f1) C:\WINDOWS\system32\DRIVERS\usbhub.sys
10:06:30:968 11936 usbprint (a42369b7cd8886cd7c70f33da6fcbcf5) C:\WINDOWS\system32\DRIVERS\usbprint.sys
10:06:31:015 11936 usbscan (a6bc71402f4f7dd5b77fd7f4a8ddba85) C:\WINDOWS\system32\DRIVERS\usbscan.sys
10:06:31:062 11936 USBSTOR (6cd7b22193718f1d17a47a1cd6d37e75) C:\WINDOWS\system32\DRIVERS\USBSTOR.SYS
10:06:31:125 11936 usbuhci (f8fd1400092e23c8f2f31406ef06167b) C:\WINDOWS\system32\DRIVERS\usbuhci.sys
10:06:31:250 11936 usbvideo (8968ff3973a883c49e8b564200f565b9) C:\WINDOWS\system32\Drivers\usbvideo.sys
10:06:31:296 11936 V0510Dev (004415a34b5dc881eaefb860c4b22c24) C:\WINDOWS\system32\DRIVERS\V0510Vid.sys
10:06:31:406 11936 V0510Vfx (86326062a90494bdd79ce383511d7d69) C:\WINDOWS\system32\DRIVERS\V0510Vfx.sys
10:06:31:562 11936 VgaSave (8a60edd72b4ea5aea8202daf0e427925) C:\WINDOWS\System32\drivers\vga.sys
10:06:31:656 11936 viaagp (d92e7c8a30cfd14d8e15b5f7f032151b) C:\WINDOWS\system32\DRIVERS\viaagp.sys
10:06:31:812 11936 ViaIde (59cb1338ad3654417bea49636457f65d) C:\WINDOWS\system32\DRIVERS\viaide.sys
10:06:31:843 11936 VolSnap (ee4660083deba849ff6c485d944b379b) C:\WINDOWS\system32\drivers\VolSnap.sys
10:06:31:968 11936 Wanarp (984ef0b9788abf89974cfed4bfbaacbc) C:\WINDOWS\system32\DRIVERS\wanarp.sys
10:06:32:046 11936 wdmaud (efd235ca22b57c81118c1aeb4798f1c1) C:\WINDOWS\system32\drivers\wdmaud.sys
10:06:32:125 11936 winachsf (74cf3f2e4e40c4a2e18d39d6300a5c24) C:\WINDOWS\system32\DRIVERS\HSF_CNXT.sys
10:06:32:296 11936 WmiAcpi (5d5e0b3c4dc8f7d63a617a4599079e37) C:\WINDOWS\system32\DRIVERS\wmiacpi.sys
10:06:32:296 11936 Suspicious file (Forged): C:\WINDOWS\system32\DRIVERS\wmiacpi.sys. Real md5: 5d5e0b3c4dc8f7d63a617a4599079e37, Fake md5: ae2c8544e747c20062db27456ea2d67a
10:06:32:296 11936 File "C:\WINDOWS\system32\DRIVERS\wmiacpi.sys" infected by TDSS rootkit ... 10:06:35:984 11936 Backup copy found, using it..
10:06:36:078 11936 will be cured on next reboot
10:06:36:187 11936 WSTCODEC (d5842484f05e12121c511aa93f6439ec) C:\WINDOWS\system32\DRIVERS\WSTCODEC.SYS
10:06:36:250 11936 WudfPf (f15feafffbb3644ccc80c5da584e6311) C:\WINDOWS\system32\DRIVERS\WudfPf.sys
10:06:36:265 11936 WudfRd (28b524262bce6de1f7ef9f510ba3985b) C:\WINDOWS\system32\DRIVERS\wudfrd.sys
10:06:36:281 11936 Reboot required for cure complete..
10:06:37:093 11936 Cure on reboot scheduled successfully
10:06:37:093 11936
10:06:37:093 11936 Completed
10:06:37:093 11936
10:06:37:093 11936 Results:
10:06:37:093 11936 Registry objects infected / cured / cured on reboot: 0 / 0 / 0
10:06:37:093 11936 File objects infected / cured / cured on reboot: 1 / 0 / 1
10:06:37:093 11936
10:06:37:093 11936 KLMD(ARK) unloaded successfully
jkwings
Active Member
 
Posts: 10
Joined: June 29th, 2010, 7:53 pm

Re: Google/Bing redirect error - please help

Unread postby deltalima » July 3rd, 2010, 10:16 am

Hi jkwings,

Please run Malwarebytes, update and run a quick scan.

Please post the log and let me know how the computer is running now.
User avatar
deltalima
Admin/Teacher
Admin/Teacher
 
Posts: 7614
Joined: February 28th, 2009, 4:38 pm
Location: UK

Re: Google/Bing redirect error - please help

Unread postby jkwings » July 3rd, 2010, 10:32 am

Will do. Should I reboot as the TDSSKiller is suggesting? Thanks.
jkwings
Active Member
 
Posts: 10
Joined: June 29th, 2010, 7:53 pm

Re: Google/Bing redirect error - please help

Unread postby deltalima » July 3rd, 2010, 10:36 am

Yes, please reboot.
User avatar
deltalima
Admin/Teacher
Admin/Teacher
 
Posts: 7614
Joined: February 28th, 2009, 4:38 pm
Location: UK

Re: Google/Bing redirect error - please help

Unread postby jkwings » July 3rd, 2010, 10:54 am

The log didn't find anything I think. I will re-boot and try to search.

Malwarebytes' Anti-Malware 1.46
www.malwarebytes.org

Database version: 4271

Windows 5.1.2600 Service Pack 2
Internet Explorer 6.0.2900.2180

7/3/2010 10:52:15 AM
mbam-log-2010-07-03 (10-52-15).txt

Scan type: Quick scan
Objects scanned: 144719
Time elapsed: 21 minute(s), 2 second(s)

Memory Processes Infected: 0
Memory Modules Infected: 0
Registry Keys Infected: 0
Registry Values Infected: 0
Registry Data Items Infected: 0
Folders Infected: 0
Files Infected: 0

Memory Processes Infected:
(No malicious items detected)

Memory Modules Infected:
(No malicious items detected)

Registry Keys Infected:
(No malicious items detected)

Registry Values Infected:
(No malicious items detected)

Registry Data Items Infected:
(No malicious items detected)

Folders Infected:
(No malicious items detected)

Files Infected:
(No malicious items detected)
jkwings
Active Member
 
Posts: 10
Joined: June 29th, 2010, 7:53 pm

Re: Google/Bing redirect error - please help

Unread postby deltalima » July 3rd, 2010, 11:01 am

Hi jkwings,

The log didn't find anything


Looking good now.

You are well behind on some of your updates.

You have Internet Explorer version 6 and XP SP2, these URGENTLY need to be updated to IE8 and XP SP3 as they are no longer supported by Microsoft.

Please visit the Microsoft Update site and install all updates, keep doing so until everything is up to date.

You should Download and Install the newest version of Adobe Reader for reading pdf files, due to the vulnerabilities in earlier versions.
All versions numbered lower than 9.3 are vulnerable.
  • Go HERE, UNCHECK any Free Add-Ons, and click Download to install the latest version of Adobe Acrobat Reader.
  • After it completes the Installation, close the Download Manager.

Update Java Runtime
You are using an old version of Java. Sun's Java is sometimes updated in order to eliminate the exploitation of vulnerabilities in an existing version. For this reason, it's extremely important that you keep the program up to date, & also remove the older more vulnerable versions from your system. The most current version of Sun Java is: Java Runtime Environment Version 6 Update 20.
  • Download the latest version of Java Runtime Environment (JRE) 6 Here
  • Scroll down to where it says "JDK 6 Update 20 (JDK or JRE)"
  • Click the orange Download JRE button to the right
  • Select the Windows platform from the dropdown menu
  • Read the License Agreement and then check the box that says: "I agree to the Java SE Runtime Environment 6 with JavaFX License Agreement". Click on Continue.The page will refresh
  • Click on the link to download Windows Offline Installation & save the file to your desktop
  • Close any programs you may have running - especially your web browser
  • Go to Start > Settings > Control Panel, double-click on Add/Remove Programs & remove all older versions of Java
  • Check (highlight) any item with Java Runtime Environment (JRE or J2SE or Java(TM) 6) in the name
  • Click the Remove or Change/Remove button.
  • Repeat as many times as necessary to remove each Java versions
  • Reboot your computer once all Java components are removed
  • Then from your desktop double-click on jre-6u20-windows-i586-p.exe to install the newest version

Please let me know when complete and I will give you instructions to clean up the tools we have used and keep your computer more secure in the future.
User avatar
deltalima
Admin/Teacher
Admin/Teacher
 
Posts: 7614
Joined: February 28th, 2009, 4:38 pm
Location: UK
Advertisement
Register to Remove

Next

  • Similar Topics
    Replies
    Views
    Last post

Return to Infected? Virus, malware, adware, ransomware, oh my!



Who is online

Users browsing this forum: No registered users and 353 guests

Contact us:

Advertisements do not imply our endorsement of that product or service. Register to remove all ads. The forum is run by volunteers who donate their time and expertise. We make every attempt to ensure that the help and advice posted is accurate and will not cause harm to your computer. However, we do not guarantee that they are accurate and they are to be used at your own risk. All trademarks are the property of their respective owners.

Member site: UNITE Against Malware