So I had a Malware attack yesterday. I found your useful instructions, downloaded tons of Anti-Spyware programms and got to this end result.
I've attached my HiJack output and Super AntiSpyware Log and would be grateful for your help in cleaning up my computer.
Regards
Andrew
Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 14:26:51, on 16/03/2008
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)
Boot mode: Normal
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Windows Defender\MsMpEng.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Intel\Wireless\Bin\EvtEng.exe
C:\Program Files\Intel\Wireless\Bin\S24EvMon.exe
C:\Program Files\Intel\Wireless\Bin\WLKeeper.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
C:\WINDOWS\eHome\ehRecvr.exe
C:\WINDOWS\eHome\ehSched.exe
C:\PROGRA~1\McAfee\MSC\mcmscsvc.exe
C:\WINDOWS\ehome\ehtray.exe
C:\Program Files\Java\j2re1.4.2_03\bin\jusched.exe
C:\WINDOWS\stsystra.exe
c:\program files\common files\mcafee\mna\mcnasvc.exe
C:\Program Files\Intel\Wireless\bin\ZCfgSvc.exe
C:\Program Files\Intel\Wireless\Bin\ifrmewrk.exe
C:\Program Files\ATI Technologies\ATI.ACE\cli.exe
C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
c:\PROGRA~1\COMMON~1\mcafee\mcproxy\mcproxy.exe
C:\Program Files\Dell\QuickSet\quickset.exe
C:\Program Files\CyberLink\PowerDVD\DVDLauncher.exe
C:\Program Files\Common Files\InstallShield\UpdateService\issch.exe
C:\Program Files\Dell\Media Experience\PCMService.exe
C:\WINDOWS\system32\dla\tfswctrl.exe
C:\Program Files\Common Files\Real\Update_OB\realsched.exe
C:\Program Files\McAfee\MPF\MPFSrv.exe
C:\Program Files\STOPzilla!\STOPzilla.exe
c:\PROGRA~1\mcafee.com\agent\mcagent.exe
C:\Program Files\McAfee\MSK\MskSrver.exe
C:\Program Files\Dell\NICCONFIGSVC\NICCONFIGSVC.exe
C:\Program Files\Windows Defender\MSASCui.exe
C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe
C:\Program Files\Intel\Wireless\Bin\RegSrvc.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\MSN Messenger\MsnMsgr.Exe
C:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe
C:\Program Files\WinZip\WZQKPICK.EXE
C:\WINDOWS\system32\dllhost.exe
C:\PROGRA~1\Intel\Wireless\Bin\Dot1XCfg.exe
C:\PROGRA~1\McAfee\VIRUSS~1\mcsysmon.exe
C:\WINDOWS\eHome\ehmsas.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\ATI Technologies\ATI.ACE\cli.exe
C:\Program Files\Messenger\msmsgs.exe
C:\PROGRA~1\McAfee\VIRUSS~1\mcshield.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\Internet Explorer\IEXPLORE.EXE
C:\Program Files\Common Files\Microsoft Shared\Source Engine\OSE.EXE
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Local Page =
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
R3 - Default URLSearchHook is missing
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll
O2 - BHO: SITEguard BHO - {1827766B-9F49-4854-8034-F6EE26FCB1EC} - C:\Program Files\STOPzilla!\SZSG.dll
O2 - BHO: McAntiPhishingBHO - {377C180E-6F0E-4D4C-980F-F45BD3D40CF4} - c:\PROGRA~1\mcafee\msk\mcapbho.dll
O2 - BHO: DriveLetterAccess - {5CA3D70E-1895-11CF-8E15-001234567890} - C:\WINDOWS\system32\dla\tfswshx.dll
O2 - BHO: scriptproxy - {7DB2D5A0-7241-4E79-B68D-6309F01C5231} - C:\Program Files\McAfee\VirusScan\scriptsn.dll
O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - (no file)
O2 - BHO: STOPzilla Browser Helper Object - {E3215F20-3212-11D6-9F8B-00D0B743919D} - C:\Program Files\STOPzilla!\SZIEBHO.dll
O3 - Toolbar: STOPzilla - {98828DED-A591-462F-83BA-D2F62A68B8B8} - C:\Program Files\STOPzilla!\SZSG.dll
O4 - HKLM\..\Run: [ehTray] C:\WINDOWS\ehome\ehtray.exe
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\j2re1.4.2_03\bin\jusched.exe"
O4 - HKLM\..\Run: [SigmatelSysTrayApp] stsystra.exe
O4 - HKLM\..\Run: [IntelZeroConfig] "C:\Program Files\Intel\Wireless\bin\ZCfgSvc.exe"
O4 - HKLM\..\Run: [IntelWireless] "C:\Program Files\Intel\Wireless\Bin\ifrmewrk.exe" /tf Intel PROSet/Wireless
O4 - HKLM\..\Run: [ATICCC] "C:\Program Files\ATI Technologies\ATI.ACE\cli.exe" runtime -Delay
O4 - HKLM\..\Run: [SynTPEnh] "C:\Program Files\Synaptics\SynTP\SynTPEnh.exe"
O4 - HKLM\..\Run: [Dell QuickSet] C:\Program Files\Dell\QuickSet\quickset.exe
O4 - HKLM\..\Run: [ShowLOMControl]
O4 - HKLM\..\Run: [DVDLauncher] "C:\Program Files\CyberLink\PowerDVD\DVDLauncher.exe"
O4 - HKLM\..\Run: [ISUSPM Startup] "C:\PROGRA~1\COMMON~1\INSTAL~1\UPDATE~1\ISUSPM.exe" -startup
O4 - HKLM\..\Run: [ISUSScheduler] "C:\Program Files\Common Files\InstallShield\UpdateService\issch.exe" -start
O4 - HKLM\..\Run: [PCMService] "C:\Program Files\Dell\Media Experience\PCMService.exe"
O4 - HKLM\..\Run: [dla] C:\WINDOWS\system32\dla\tfswctrl.exe
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe"
O4 - HKLM\..\Run: [6c12a96a] "rundll32.exe" "C:\WINDOWS\system32\afkmxvaa.dll",b
O4 - HKLM\..\Run: [mcagent_exe] "C:\Program Files\McAfee.com\Agent\mcagent.exe" /runkey
O4 - HKLM\..\Run: [McENUI] "C:\PROGRA~1\McAfee\MHN\McENUI.exe" /hide
O4 - HKLM\..\Run: [Windows Defender] "C:\Program Files\Windows Defender\MSASCui.exe" -hide
O4 - HKLM\..\Run: [!AVG Anti-Spyware] "C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe" /minimized
O4 - HKCU\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [MsnMsgr] "C:\Program Files\MSN Messenger\MsnMsgr.Exe" /background
O4 - HKCU\..\Run: [SUPERAntiSpyware] "C:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe"
O4 - HKUS\S-1-5-19\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-20\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'NETWORK SERVICE')
O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'Default user')
O4 - Global Startup: Adobe Gamma Loader.exe.lnk = C:\Program Files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe
O4 - Global Startup: WinZip Quick Pick.lnk = C:\Program Files\WinZip\WZQKPICK.EXE
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~3\OFFICE11\EXCEL.EXE/3000
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\j2re1.4.2_03\bin\npjpi142_03.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\j2re1.4.2_03\bin\npjpi142_03.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~3\OFFICE11\REFIEBAR.DLL
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O10 - Unknown file in Winsock LSP: c:\program files\common files\is3\anti-spyware\is3lsp.dll
O10 - Unknown file in Winsock LSP: c:\program files\common files\is3\anti-spyware\is3lsp.dll
O10 - Unknown file in Winsock LSP: c:\program files\common files\is3\anti-spyware\is3lsp.dll
O10 - Unknown file in Winsock LSP: c:\program files\common files\is3\anti-spyware\is3lsp.dll
O10 - Unknown file in Winsock LSP: c:\program files\common files\is3\anti-spyware\is3lsp.dll
O10 - Unknown file in Winsock LSP: c:\program files\common files\is3\anti-spyware\is3lsp.dll
O15 - Trusted Zone: http://*.mcafee.com
O16 - DPF: {05CA9FB0-3E3E-4B36-BF41-0E3A5CAA8CD8} (Office Genuine Advantage Validation Tool) - http://go.microsoft....k/?linkid=58813
O16 - DPF: {11260943-421B-11D0-8EAC-0000C07D88CF} (iPIX ActiveX Control) - http://www.ipix.com/download/ipixx.cab
O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) - http://go.microsoft....k/?linkid=39204
O16 - DPF: {4ED9DDF0-7479-4BBE-9335-5A1EDB1D8A21} (McAfee.com Operating System Class) - http://download.mcaf...01/mcinsctl.cab
O16 - DPF: {C36112BF-2FA3-4694-8603-3B510EA3B465} (Lycos File Upload Component) - http://f008.mail.lyc...ileUploader.cab
O16 - DPF: {D8089245-3211-40F6-819B-9E5E92CD61A2} (FlashXControl Object) - https://flashcasino....-en/FlashAX.cab
O20 - Winlogon Notify: !SASWinLogon - C:\Program Files\SUPERAntiSpyware\SASWINLO.dll
O23 - Service: Ati HotKey Poller - ATI Technologies Inc. - C:\WINDOWS\system32\Ati2evxx.exe
O23 - Service: AVG Anti-Spyware Guard - GRISOFT s.r.o. - C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
O23 - Service: Intel® PROSet/Wireless Event Log (EvtEng) - Intel Corporation - C:\Program Files\Intel\Wireless\Bin\EvtEng.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: McAfee Services (mcmscsvc) - McAfee, Inc. - C:\PROGRA~1\McAfee\MSC\mcmscsvc.exe
O23 - Service: McAfee Network Agent (McNASvc) - McAfee, Inc. - c:\program files\common files\mcafee\mna\mcnasvc.exe
O23 - Service: McAfee Scanner (McODS) - McAfee, Inc. - C:\PROGRA~1\McAfee\VIRUSS~1\mcods.exe
O23 - Service: McAfee Proxy Service (McProxy) - McAfee, Inc. - c:\PROGRA~1\COMMON~1\mcafee\mcproxy\mcproxy.exe
O23 - Service: McAfee Real-time Scanner (McShield) - McAfee, Inc. - C:\PROGRA~1\McAfee\VIRUSS~1\mcshield.exe
O23 - Service: McAfee SystemGuards (McSysmon) - McAfee, Inc. - C:\PROGRA~1\McAfee\VIRUSS~1\mcsysmon.exe
O23 - Service: McAfee Personal Firewall Service (MpfService) - McAfee, Inc. - C:\Program Files\McAfee\MPF\MPFSrv.exe
O23 - Service: McAfee SpamKiller Service (MSK80Service) - McAfee, Inc. - C:\Program Files\McAfee\MSK\MskSrver.exe
O23 - Service: NICCONFIGSVC - Dell Inc. - C:\Program Files\Dell\NICCONFIGSVC\NICCONFIGSVC.exe
O23 - Service: Intel® PROSet/Wireless Registry Service (RegSrvc) - Intel Corporation - C:\Program Files\Intel\Wireless\Bin\RegSrvc.exe
O23 - Service: Intel® PROSet/Wireless Service (S24EventMonitor) - Intel Corporation - C:\Program Files\Intel\Wireless\Bin\S24EvMon.exe
O23 - Service: STOPzilla Service (szserver) - iS3, Inc. - C:\Program Files\Common Files\iS3\Anti-Spyware\SZServer.exe
O23 - Service: Intel® PROSet/Wireless SSO Service (WLANKEEPER) - Intel® Corporation - C:\Program Files\Intel\Wireless\Bin\WLKeeper.exe
--
End of file - 10670 bytes
SUPERAntiSpyware Scan Log
http://www.superantispyware.com
Generated 03/16/2008 at 12:51 PM
Application Version : 4.0.1154
Core Rules Database Version : 3420
Trace Rules Database Version: 1412
Scan type : Complete Scan
Total Scan Time : 01:26:22
Memory items scanned : 686
Memory threats detected : 0
Registry items scanned : 5232
Registry threats detected : 0
File items scanned : 103659
File threats detected : 87
Adware.Tracking Cookie
C:\Documents and Settings\Andrew Storm\Cookies\andrew storm@stopzilla[2].txt
C:\Documents and Settings\Andrew Storm\Cookies\andrew [email protected][1].txt
C:\Documents and Settings\Andrew Storm\Cookies\andrew storm@adrevolver[2].txt
C:\Documents and Settings\Andrew Storm\Cookies\andrew [email protected][1].txt
C:\Documents and Settings\Andrew Storm\Cookies\andrew storm@atdmt[1].txt
C:\Documents and Settings\Andrew Storm\Cookies\andrew storm@doubleclick[1].txt
C:\Documents and Settings\Andrew Storm\Cookies\andrew [email protected][2].txt
C:\Documents and Settings\Andrew Storm\Cookies\andrew storm@serving-sys[2].txt
C:\Documents and Settings\Andrew Storm\Cookies\andrew storm@specificclick[1].txt
C:\Documents and Settings\Andrew Storm\Cookies\andrew [email protected][1].txt
C:\Documents and Settings\Andrew Storm\Cookies\andrew storm@cgi-bin[3].txt
C:\Documents and Settings\Andrew Storm\Cookies\andrew [email protected][1].txt
C:\Documents and Settings\Andrew Storm\Cookies\andrew storm@1072588149[1].txt
Adware.OuterInfo-Installer
C:\RECYCLER\S-1-5-21-527237240-746137067-725345543-1003\DC12.EXE
Adware.Rabio Search Enhancer
C:\SYSTEM VOLUME INFORMATION\_RESTORE{C328F4D7-4C9C-4715-BD17-52F317183D89}\RP250\A0238619.DLL
C:\SYSTEM VOLUME INFORMATION\_RESTORE{C328F4D7-4C9C-4715-BD17-52F317183D89}\RP250\A0238620.EXE
Adware.Vundo-Variant/Small-A
C:\SYSTEM VOLUME INFORMATION\_RESTORE{C328F4D7-4C9C-4715-BD17-52F317183D89}\RP250\A0238624.DLL
Trace.Known Threat Sources
C:\Documents and Settings\Andrew Storm\Local Settings\Temporary Internet Files\Content.IE5\O1Q3ST6V\content.footer_02-over[1].gif
C:\Documents and Settings\Andrew Storm\Local Settings\Temporary Internet Files\Content.IE5\O1Q34HIJ\cons.lnav.contactus[1].gif
C:\Documents and Settings\Andrew Storm\Local Settings\Temporary Internet Files\Content.IE5\ST6V8XAB\site.header[1].gif
C:\Documents and Settings\Andrew Storm\Local Settings\Temporary Internet Files\Content.IE5\O1Q34HIJ\cons.lnav.footer[1].gif
C:\Documents and Settings\Andrew Storm\Local Settings\Temporary Internet Files\Content.IE5\O1Q3ST6V\oi.icon[1].jpg
C:\Documents and Settings\Andrew Storm\Local Settings\Temporary Internet Files\Content.IE5\WLMB01EF\outerinfo[1].htm
C:\Documents and Settings\Andrew Storm\Local Settings\Temporary Internet Files\Content.IE5\ST6V8XAB\cons.lnav.eula[1].gif
C:\Documents and Settings\Andrew Storm\Local Settings\Temporary Internet Files\Content.IE5\ST6V8XAB\cons.lnav.eula-over[1].gif
C:\Documents and Settings\Andrew Storm\Local Settings\Temporary Internet Files\Content.IE5\WLMB01EF\right.bg.green[1].gif
C:\Documents and Settings\Andrew Storm\Local Settings\Temporary Internet Files\Content.IE5\O1Q3ST6V\cons.lnav.support[1].gif
C:\Documents and Settings\Andrew Storm\Local Settings\Temporary Internet Files\Content.IE5\ST6V8XAB\CAZ6JYB5.gif
C:\Documents and Settings\Andrew Storm\Local Settings\Temporary Internet Files\Content.IE5\O1Q34HIJ\cons.navbar.part[1].gif
C:\Documents and Settings\Andrew Storm\Local Settings\Temporary Internet Files\Content.IE5\O1Q34HIJ\cons.footer.privacy.green-o[1].gif
C:\Documents and Settings\Andrew Storm\Local Settings\Temporary Internet Files\Content.IE5\O1Q34HIJ\index.leftcap[1].gif
C:\Documents and Settings\Andrew Storm\Local Settings\Temporary Internet Files\Content.IE5\O1Q34HIJ\index.header[1].gif
C:\Documents and Settings\Andrew Storm\Local Settings\Temporary Internet Files\Content.IE5\O1Q3ST6V\CAAFCXI7.gif
C:\Documents and Settings\Andrew Storm\Local Settings\Temporary Internet Files\Content.IE5\WLMB01EF\cons.lnav.about[1].gif
C:\Documents and Settings\Andrew Storm\Local Settings\Temporary Internet Files\Content.IE5\WLMB01EF\index.rightcap[1].gif
C:\Documents and Settings\Andrew Storm\Local Settings\Temporary Internet Files\Content.IE5\WLMB01EF\CSScriptLib[1].js
C:\Documents and Settings\Andrew Storm\Local Settings\Temporary Internet Files\Content.IE5\ST6V8XAB\spacer[2].gif
C:\Documents and Settings\Andrew Storm\Local Settings\Temporary Internet Files\Content.IE5\WLMB01EF\cons.lnav.support-over[1].gif
C:\Documents and Settings\Andrew Storm\Local Settings\Temporary Internet Files\Content.IE5\O1Q34HIJ\content.bottom_01[1].gif
C:\Documents and Settings\Andrew Storm\Local Settings\Temporary Internet Files\Content.IE5\WLMB01EF\uninstall_1[1].jpg
C:\Documents and Settings\Andrew Storm\Local Settings\Temporary Internet Files\Content.IE5\WLMB01EF\cons.lnav.privacy[1].gif
C:\Documents and Settings\Andrew Storm\Local Settings\Temporary Internet Files\Content.IE5\O1Q34HIJ\content.top_02[1].gif
C:\Documents and Settings\Andrew Storm\Local Settings\Temporary Internet Files\Content.IE5\O1Q3ST6V\step.1.save[1].jpg
C:\Documents and Settings\Andrew Storm\Local Settings\Temporary Internet Files\Content.IE5\WLMB01EF\CA8DO5GZ.gif
C:\Documents and Settings\Andrew Storm\Local Settings\Temporary Internet Files\Content.IE5\ST6V8XAB\cons.lnav.download[1].gif
C:\Documents and Settings\Andrew Storm\Local Settings\Temporary Internet Files\Content.IE5\WLMB01EF\CA638167.gif
C:\Documents and Settings\Andrew Storm\Local Settings\Temporary Internet Files\Content.IE5\O1Q34HIJ\cons.lnav.uninstall[1].gif
C:\Documents and Settings\Andrew Storm\Local Settings\Temporary Internet Files\Content.IE5\O1Q3ST6V\content.top_03[1].gif
C:\Documents and Settings\Andrew Storm\Local Settings\Temporary Internet Files\Content.IE5\ST6V8XAB\cons.lnav.download-over[2].gif
C:\Documents and Settings\Andrew Storm\Local Settings\Temporary Internet Files\Content.IE5\WLMB01EF\cons.navbar.adv-over[1].gif
C:\Documents and Settings\Andrew Storm\Local Settings\Temporary Internet Files\Content.IE5\O1Q34HIJ\CA2VWJJ8.gif
C:\Documents and Settings\Andrew Storm\Local Settings\Temporary Internet Files\Content.IE5\ST6V8XAB\footer[1].gif
C:\Documents and Settings\Andrew Storm\Local Settings\Temporary Internet Files\Content.IE5\WLMB01EF\uninstall_2[1].jpg
C:\Documents and Settings\Andrew Storm\Local Settings\Temporary Internet Files\Content.IE5\WLMB01EF\cons.navbar.cons[1].gif
C:\Documents and Settings\Andrew Storm\Local Settings\Temporary Internet Files\Content.IE5\WLMB01EF\step.5.agree[1].jpg
C:\Documents and Settings\Andrew Storm\Local Settings\Temporary Internet Files\Content.IE5\WLMB01EF\cons.footer.spacer.green[1].gif
C:\Documents and Settings\Andrew Storm\Local Settings\Temporary Internet Files\Content.IE5\ST6V8XAB\cons.lnav.header[1].gif
C:\Documents and Settings\Andrew Storm\Local Settings\Temporary Internet Files\Content.IE5\WLMB01EF\step.4.run[1].jpg
C:\Documents and Settings\Andrew Storm\Local Settings\Temporary Internet Files\Content.IE5\ST6V8XAB\contactus.green[1].gif
C:\Documents and Settings\Andrew Storm\Local Settings\Temporary Internet Files\Content.IE5\O1Q34HIJ\uninstall_3[1].jpg
C:\Documents and Settings\Andrew Storm\Local Settings\Temporary Internet Files\Content.IE5\WLMB01EF\cons.lnav.spacer[1].gif
C:\Documents and Settings\Andrew Storm\Local Settings\Temporary Internet Files\Content.IE5\ST6V8XAB\content.bottom_04[1].gif
C:\Documents and Settings\Andrew Storm\Local Settings\Temporary Internet Files\Content.IE5\O1Q34HIJ\download.oi.green[1].gif
C:\Documents and Settings\Andrew Storm\Local Settings\Temporary Internet Files\Content.IE5\O1Q3ST6V\cons.footer.eula.green-over[1].gif
C:\Documents and Settings\Andrew Storm\Local Settings\Temporary Internet Files\Content.IE5\ST6V8XAB\CA5WONDH.gif
C:\Documents and Settings\Andrew Storm\Local Settings\Temporary Internet Files\Content.IE5\O1Q3ST6V\cons.lnav.contactus-over[1].gif
C:\Documents and Settings\Andrew Storm\Local Settings\Temporary Internet Files\Content.IE5\O1Q34HIJ\cons.lnav.about-over[1].gif
C:\Documents and Settings\Andrew Storm\Local Settings\Temporary Internet Files\Content.IE5\WLMB01EF\step.6.install[1].jpg
C:\Documents and Settings\Andrew Storm\Local Settings\Temporary Internet Files\Content.IE5\O1Q34HIJ\content.bottom_05[1].gif
C:\Documents and Settings\Andrew Storm\Local Settings\Temporary Internet Files\Content.IE5\O1Q3ST6V\cons.lnav.uninstall-over[1].gif
C:\Documents and Settings\Andrew Storm\Local Settings\Temporary Internet Files\Content.IE5\O1Q34HIJ\step.3.icon[1].jpg
C:\Documents and Settings\Andrew Storm\Local Settings\Temporary Internet Files\Content.IE5\O1Q3ST6V\cons.footer.privacy.green[1].gif
C:\Documents and Settings\Andrew Storm\Local Settings\Temporary Internet Files\Content.IE5\WLMB01EF\CAYFCRLQ.gif
C:\Documents and Settings\Andrew Storm\Local Settings\Temporary Internet Files\Content.IE5\ST6V8XAB\index.partners[1].gif
C:\Documents and Settings\Andrew Storm\Local Settings\Temporary Internet Files\Content.IE5\ST6V8XAB\index.partners-over[1].gif
C:\Documents and Settings\Andrew Storm\Local Settings\Temporary Internet Files\Content.IE5\WLMB01EF\cons.navbar.part-over[1].gif
C:\Documents and Settings\Andrew Storm\Local Settings\Temporary Internet Files\Content.IE5\ST6V8XAB\uninstall_6[1].jpg
C:\Documents and Settings\Andrew Storm\Local Settings\Temporary Internet Files\Content.IE5\O1Q3ST6V\content.bottom_03[1].gif
C:\Documents and Settings\Andrew Storm\Local Settings\Temporary Internet Files\Content.IE5\O1Q34HIJ\step.2.desktop[1].jpg
C:\Documents and Settings\Andrew Storm\Local Settings\Temporary Internet Files\Content.IE5\O1Q34HIJ\index.advertisers-over[1].gif
C:\Documents and Settings\Andrew Storm\Local Settings\Temporary Internet Files\Content.IE5\O1Q34HIJ\contactus.phone[1].gif
C:\Documents and Settings\Andrew Storm\Local Settings\Temporary Internet Files\Content.IE5\O1Q3ST6V\outerinfo.index[1].gif
C:\Documents and Settings\Andrew Storm\Local Settings\Temporary Internet Files\Content.IE5\O1Q34HIJ\cons.footer.eula.green[1].gif
C:\Documents and Settings\Andrew Storm\Local Settings\Temporary Internet Files\Content.IE5\O1Q3ST6V\uninstall_5[1].jpg
C:\Documents and Settings\Andrew Storm\Local Settings\Temporary Internet Files\Content.IE5\O1Q3ST6V\index.middle.vert[1].gif
C:\Documents and Settings\Andrew Storm\Local Settings\Temporary Internet Files\Content.IE5\WLMB01EF\index.middle.hori[1].gif
C:\Documents and Settings\Andrew Storm\Local Settings\Temporary Internet Files\Content.IE5\ST6V8XAB\index.consumers-over[1].gif