GMER 1.0.15.15281 - http://www.gmer.net Rootkit scan 2010-09-27 14:09:03 Windows 5.1.2600 Service Pack 2 Running: gmer.exe; Driver: C:\DOCUME~1\MARKTH~1\LOCALS~1\Temp\awtdrkob.sys ---- System - GMER 1.0.15 ---- SSDT GoBack2K.sys (Norton GoBack Engine Driver/Symantec Corporation) ZwClose [0xF75D2A40] SSDT GoBack2K.sys (Norton GoBack Engine Driver/Symantec Corporation) ZwFsControlFile [0xF75D2AD0] SSDT \??\C:\Program Files\AVG\AVG9\Identity Protection\Agent\Driver\Platform_XP\AVGIDSShim.sys (IDS Application Activity Monitor Loader Driver./AVG Technologies CZ, s.r.o. ) ZwOpenProcess [0xF6702670] SSDT \??\C:\Program Files\AVG\AVG9\Identity Protection\Agent\Driver\Platform_XP\AVGIDSShim.sys (IDS Application Activity Monitor Loader Driver./AVG Technologies CZ, s.r.o. ) ZwTerminateProcess [0xF6702720] SSDT \??\C:\Program Files\AVG\AVG9\Identity Protection\Agent\Driver\Platform_XP\AVGIDSShim.sys (IDS Application Activity Monitor Loader Driver./AVG Technologies CZ, s.r.o. ) ZwTerminateThread [0xF67027C0] SSDT \??\C:\Program Files\AVG\AVG9\Identity Protection\Agent\Driver\Platform_XP\AVGIDSShim.sys (IDS Application Activity Monitor Loader Driver./AVG Technologies CZ, s.r.o. ) ZwWriteVirtualMemory [0xF6702860] ---- Kernel code sections - GMER 1.0.15 ---- .text ntoskrnl.exe!_abnormal_termination + 19D 804E2809 3 Bytes [2A, 5D, F7] {SUB BL, [EBP-0x9]} ---- User code sections - GMER 1.0.15 ---- .text C:\Program Files\Internet Explorer\iexplore.exe[3516] USER32.dll!DialogBoxParamW 7E42555F 5 Bytes JMP 3E1DF4B9 C:\WINDOWS\system32\IEFRAME.dll (Internet Explorer/Microsoft Corporation) .text C:\Program Files\Internet Explorer\iexplore.exe[3516] USER32.dll!DialogBoxIndirectParamW 7E432032 5 Bytes JMP 3E35203E C:\WINDOWS\system32\IEFRAME.dll (Internet Explorer/Microsoft Corporation) .text C:\Program Files\Internet Explorer\iexplore.exe[3516] USER32.dll!MessageBoxIndirectA 7E43A04A 5 Bytes JMP 3E351FBF C:\WINDOWS\system32\IEFRAME.dll (Internet Explorer/Microsoft Corporation) .text C:\Program Files\Internet Explorer\iexplore.exe[3516] USER32.dll!DialogBoxParamA 7E43B10C 5 Bytes JMP 3E352003 C:\WINDOWS\system32\IEFRAME.dll (Internet Explorer/Microsoft Corporation) .text C:\Program Files\Internet Explorer\iexplore.exe[3516] USER32.dll!MessageBoxExW 7E4505D8 5 Bytes JMP 3E351F4B C:\WINDOWS\system32\IEFRAME.dll (Internet Explorer/Microsoft Corporation) .text C:\Program Files\Internet Explorer\iexplore.exe[3516] USER32.dll!MessageBoxExA 7E4505FC 5 Bytes JMP 3E351F85 C:\WINDOWS\system32\IEFRAME.dll (Internet Explorer/Microsoft Corporation) .text C:\Program Files\Internet Explorer\iexplore.exe[3516] USER32.dll!DialogBoxIndirectParamA 7E456B50 5 Bytes JMP 3E352079 C:\WINDOWS\system32\IEFRAME.dll (Internet Explorer/Microsoft Corporation) .text C:\Program Files\Internet Explorer\iexplore.exe[3516] USER32.dll!MessageBoxIndirectW 7E4662AB 5 Bytes JMP 3E20176A C:\WINDOWS\system32\IEFRAME.dll (Internet Explorer/Microsoft Corporation) .text C:\Program Files\Internet Explorer\iexplore.exe[3516] ole32.dll!OleLoadFromStream 7753031B 5 Bytes JMP 3E35223B C:\WINDOWS\system32\IEFRAME.dll (Internet Explorer/Microsoft Corporation) ---- Devices - GMER 1.0.15 ---- AttachedDevice \FileSystem\Ntfs \Ntfs AVGIDSFilter.sys (IDS Application Activity Monitor Filter Driver./AVG Technologies CZ, s.r.o. ) AttachedDevice \Driver\Tcpip \Device\Ip avgtdix.sys (AVG Network connection watcher/AVG Technologies CZ, s.r.o.) AttachedDevice \Driver\Tcpip \Device\Tcp avgtdix.sys (AVG Network connection watcher/AVG Technologies CZ, s.r.o.) AttachedDevice \Driver\Tcpip \Device\Udp avgtdix.sys (AVG Network connection watcher/AVG Technologies CZ, s.r.o.) Device \Driver\Disk \Device\Harddisk0\DR0 GoBack2K.sys (Norton GoBack Engine Driver/Symantec Corporation) AttachedDevice \Driver\Tcpip \Device\RawIp avgtdix.sys (AVG Network connection watcher/AVG Technologies CZ, s.r.o.) Device \FileSystem\Cdfs \Cdfs DLAIFS_M.SYS (Drive Letter Access Component/Sonic Solutions) ---- Services - GMER 1.0.15 ---- Service PRAGMAstpevxeibp\PRAGMAd.sys (*** hidden *** ) [SYSTEM] PRAGMAstpevxeibp <-- ROOTKIT !!! ---- Registry - GMER 1.0.15 ---- Reg HKLM\SYSTEM\CurrentControlSet\Control\Lsa@LsaPid 668 Reg HKLM\SYSTEM\CurrentControlSet\Control\Network@FilterClasses scheduler?loadbalance?failover? Reg HKLM\SYSTEM\CurrentControlSet\Control\Session Manager@PendingFileRenameOperations \??\C:\WINDOWS\TEMP\PRAGMAf718.tmp??\??\C:\DOCUME~1\MARKTH~1\LOCALS~1\Temp\SAS_SelfExtract?? Reg HKLM\SYSTEM\CurrentControlSet\Control\Session Manager\Memory Management\PrefetchParameters@VideoInitTime 359 Reg HKLM\SYSTEM\CurrentControlSet\Control\Watchdog\Display@ShutdownCount 2137 Reg HKLM\SYSTEM\CurrentControlSet\Services\Avgfwfd\Parameters\Adapters\NdisWanIp@UpperBindings \Device\{FC1B4770-FC05-48B5-BFCD-C25B815FAEE4} Reg HKLM\SYSTEM\CurrentControlSet\Services\Avgfwfd\Parameters\Adapters\{1F282026-21F7-4363-A66A-5D447E5DBE6C}@UpperBindings \Device\{13E0C825-2E30-4A05-B9DC-BCE3B1BDC82C} Reg HKLM\SYSTEM\CurrentControlSet\Services\Avgfwfd\Parameters\Adapters\{9D97D7CE-7C2B-4101-9CBB-88B811317DAA}@UpperBindings \Device\{AB9F69FE-C6DD-4F1B-9A5E-ED17ECB56CE9} Reg HKLM\SYSTEM\CurrentControlSet\Services\Eventlog\Application@Sources WSH?WMIAdapter?WmdmPmSN?WinMgmt?Winlogon?Windows Product Activation?Windows 3.1 Migration?WebClient?VSS?VBRuntime?Userinit?Userenv?SysmonLog?Starter?SpoolerCtrs?Software Restriction Policies?Software Installation?SecurityCenter?SclgNtfy?SceSrv?SceCli?safrslv?SAFrdms?RPC?Remote Assistance?PerfProc?PerfOS?PerfNet?Perfmon?Perflib?PerfDisk?Perfctrs?Outlook?Offline Files?Oakley?ntbackup?NDP1.1sp1-KB979906-X86?NDP1.1sp1-KB953297-X86?MSSQLSERVER/MSDE?MSSOAP?MsiInstaller?MSDTC Client?MSDTC?MSDMine?mnmsrvc?Microsoft Office Document Imaging?Microsoft Office 11?Microsoft H.323 Telephony Service Provider?MDM?LoadPerf?JavaQuickStarterService?HelpSvc?Folder Redirection?File Deployment?EventSystem?ESENT?DrWatson?DiskQuota?crypt32?COM+?COM?Ci?Chkdsk?Bonjour Service?AutoEnrollment?Autochk?ASP.NET 1.1.4322.0?Application Management?Application Hang?Application Error?AegisP?.NET Runtime?Application? Reg HKLM\SYSTEM\CurrentControlSet\Services\Eventlog\System@Sources WZCSVC?Wudf01000?WPDClassInstaller?Workstation?WMPNetworkSvc?WindowsMedia?Windows Update Agent?Windows Script Host?Windows Installer 3.1?Windows File Protection?Win32k?WgaNotify?W32Time?VolSnap?viaide?VgaSave?USER32?UPS?ultra?udfs?toside?TermServSessDir?TermService?TermServDevices?TermDD?tdi?TCPMon?Tcpip?System Error?SynTP?sym_u3?sym_hi?SymSnap?symc8xx?symc810?StillImage?SSDPSRV?Srv?srservice?sr?sparrow?sndblst?Simbad?SideBySide?sfloppy?Setup?Service Control Manager?Server?serial?scsiport?Schedule?Schannel?SCardSvr?Save Dump?SAM?rtl8139?RTL8023xp?RSVP?Removable Storage Service?RemoteAccess?redbook?Rdbss?RasMan?RasAuto?ql1280?ql1240?ql12160?ql10wnt?ql1080?PSched?Print?PptpMiniport?PolicyAgent?PlugPlayManager?perc2?PCTCore?pcmcia?pciide?pci?parvdm?partmgr?parport?OSPFMib?OSPF?null?NtServicePack?ntfs?npfs?Nla?Netlogon?NetDDE?NetBT?NetBIOS?NdisWan?ndis?Mup?msfs?msadlib?MrxSmb?MRxDAV?mraid35x?mouclass?Modem?LsaSrv?LmHosts?LDMS?LDM?lbrtfdc?Kerberos?kbdclass?KB929969?KB928090-IE7?isapnp?IPXSAP?IPXRouterManager?IPXR Reg HKLM\SYSTEM\CurrentControlSet\Services\PRAGMAstpevxeibp Reg HKLM\SYSTEM\CurrentControlSet\Services\PRAGMAstpevxeibp@start 1 Reg HKLM\SYSTEM\CurrentControlSet\Services\PRAGMAstpevxeibp@type 1 Reg HKLM\SYSTEM\CurrentControlSet\Services\PRAGMAstpevxeibp@imagepath \systemroot\PRAGMAstpevxeibp\PRAGMAd.sys Reg HKLM\SYSTEM\CurrentControlSet\Services\PRAGMAstpevxeibp\modules Reg HKLM\SYSTEM\CurrentControlSet\Services\PRAGMAstpevxeibp\modules@PRAGMAd \systemroot\PRAGMAstpevxeibp\PRAGMAd.sys Reg HKLM\SYSTEM\CurrentControlSet\Services\PRAGMAstpevxeibp\modules@PRAGMAc \systemroot\PRAGMAstpevxeibp\PRAGMAc.dll Reg HKLM\SYSTEM\CurrentControlSet\Services\PRAGMAstpevxeibp\modules@pragmaserf pragmaserf Reg HKLM\SYSTEM\CurrentControlSet\Services\PRAGMAstpevxeibp\modules@pragmabbr pragmabbr Reg HKLM\SYSTEM\CurrentControlSet\Services\SharedAccess\Epoch@Epoch 15164 Reg HKLM\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile@EnableFirewall 1 Reg HKLM\SYSTEM\CurrentControlSet\Services\Tcpip\Parameters\Interfaces\{9D97D7CE-7C2B-4101-9CBB-88B811317DAA}@LeaseObtainedTime 1285516305 Reg HKLM\SYSTEM\CurrentControlSet\Services\Tcpip\Parameters\Interfaces\{9D97D7CE-7C2B-4101-9CBB-88B811317DAA}@T1 1301284305 Reg HKLM\SYSTEM\CurrentControlSet\Services\Tcpip\Parameters\Interfaces\{9D97D7CE-7C2B-4101-9CBB-88B811317DAA}@T2 1313110305 Reg HKLM\SYSTEM\CurrentControlSet\Services\Tcpip\Parameters\Interfaces\{9D97D7CE-7C2B-4101-9CBB-88B811317DAA}@LeaseTerminatesTime 1317052305 Reg HKLM\SYSTEM\CurrentControlSet\Services\Tcpip\Parameters\Interfaces\{9D97D7CE-7C2B-4101-9CBB-88B811317DAA}@DhcpRetryTime 15767996 Reg HKLM\SYSTEM\CurrentControlSet\Services\{9D97D7CE-7C2B-4101-9CBB-88B811317DAA}\Parameters\Tcpip@LeaseObtainedTime 1285516305 Reg HKLM\SYSTEM\CurrentControlSet\Services\{9D97D7CE-7C2B-4101-9CBB-88B811317DAA}\Parameters\Tcpip@T1 1301284305 Reg HKLM\SYSTEM\CurrentControlSet\Services\{9D97D7CE-7C2B-4101-9CBB-88B811317DAA}\Parameters\Tcpip@T2 1313110305 Reg HKLM\SYSTEM\CurrentControlSet\Services\{9D97D7CE-7C2B-4101-9CBB-88B811317DAA}\Parameters\Tcpip@LeaseTerminatesTime 1317052305 Reg HKLM\SYSTEM\ControlSet003\Control\Lsa@LsaPid 668 Reg HKLM\SYSTEM\ControlSet003\Control\Network@FilterClasses scheduler?loadbalance?failover? Reg HKLM\SOFTWARE\Classes\CLSID\{00021493-0000-0000-C000-000000000046} Reg HKLM\SOFTWARE\Classes\CLSID\InprocServer32 Reg HKLM\SOFTWARE\Classes\CLSID\InprocServer32@ C:\Program Files\Google\Google Toolbar\GoogleToolbar_32.dll Reg HKLM\SOFTWARE\Classes\CLSID\InprocServer32 C:\Program Files\Google\Google Toolbar\GoogleToolbar_32.dll Reg HKCU\Software@24d1ca9a-a864-4f7b-86fe-495eb56529d8 Reg HKCU\Software@7bde84a2-f58f-46ec-9eac-f1f90fead080 Reg HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer@Shutdown Setting 2 Reg HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\ComDlg32\OpenSaveMRU\*@MRUList hedgajcbif Reg HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\ComDlg32\OpenSaveMRU\*@f E:\jobs.pdf Reg HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\ComDlg32\OpenSaveMRU\exe@MRUList ajihgfedcb Reg HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\ComDlg32\OpenSaveMRU\exe@b C:\Documents and Settings\Samantha Grove\My Documents\iTunesSetup.exe Reg HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\LowRegistry@TimeGetWork 440223 Reg HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{2318C2B1-4965-11D4-9B18-009027A5CD4F}@Flags 1 Reg HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{AA58ED58-01DD-4D91-8333-CF10577473F7}@Flags 1 Reg HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{AF69DE43-7D58-4638-B6FA-CE66B5AD205D}@Flags 1 Reg HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{02478D38-C3F9-4EFB-9B51-7695ECA05670}\iexplore@Count 129 Reg HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{06849E9F-C8D7-4D59-B87D-784B7D6BE0B3}\iexplore@Count 121 Reg HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{06849E9F-C8D7-4D59-B87D-784B7D6BE0B3}\iexplore@Blocked 121 Reg HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{08B0E5C0-4FCB-11CF-AAA5-00401C608501}\iexplore@Count 124 Reg HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{08B0E5C0-4FCB-11CF-AAA5-00401C608501}\iexplore@Blocked 124 Reg HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{18DF081C-E8AD-4283-A596-FA578C2EBDC3}\iexplore@Count 121 Reg HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{18DF081C-E8AD-4283-A596-FA578C2EBDC3}\iexplore@Blocked 121 Reg HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{2318C2B1-4965-11D4-9B18-009027A5CD4F}\iexplore@Count 85 Reg HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{2318C2B1-4965-11D4-9B18-009027A5CD4F}\iexplore@Blocked 85 Reg HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{2A0F3D1B-0909-4FF4-B272-609CCE6054E7}\iexplore@Count 12 Reg HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{2A0F3D1B-0909-4FF4-B272-609CCE6054E7}\iexplore@Blocked 12 Reg HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{3049C3E9-B461-4BC5-8870-4C09146192CA}\iexplore@Count 129 Reg HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{3049C3E9-B461-4BC5-8870-4C09146192CA}\iexplore@Blocked 129 Reg HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{3CA2F312-6F6E-4B53-A66E-4E65E497C8C0}\iexplore@Count 129 Reg HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{3CA2F312-6F6E-4B53-A66E-4E65E497C8C0}\iexplore@Blocked 129 Reg HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{472734EA-242A-422B-ADF8-83D1E48CC825}\iexplore@Count 12 Reg HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{472734EA-242A-422B-ADF8-83D1E48CC825}\iexplore@Blocked 12 Reg HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{5CA3D70E-1895-11CF-8E15-001234567890}\iexplore@Count 129 Reg HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{5CA3D70E-1895-11CF-8E15-001234567890}\iexplore@Blocked 129 Reg HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{761497BB-D6F0-462C-B6EB-D4DAF1D92D43}\iexplore@Count 121 Reg HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{761497BB-D6F0-462C-B6EB-D4DAF1D92D43}\iexplore@Blocked 121 Reg HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{92780B25-18CC-41C8-B9BE-3C9C571A8263}\iexplore@Count 123 Reg HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{92780B25-18CC-41C8-B9BE-3C9C571A8263}\iexplore@Blocked 123 Reg HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{AF69DE43-7D58-4638-B6FA-CE66B5AD205D}\iexplore@Count 129 Reg HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{AF69DE43-7D58-4638-B6FA-CE66B5AD205D}\iexplore@Blocked 129 Reg HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{D27CDB6E-AE6D-11CF-96B8-444553540000}\iexplore@Count 209 Reg HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{DBC80044-A445-435B-BC74-9C25C1C588A9}\iexplore@Count 121 Reg HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{DBC80044-A445-435B-BC74-9C25C1C588A9}\iexplore@Blocked 121 Reg HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{E2E2DD38-D088-4134-82B7-F2BA38496583}\iexplore@Count 123 Reg HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{E2E2DD38-D088-4134-82B7-F2BA38496583}\iexplore@Blocked 123 Reg HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{E7E6F031-17CE-4C07-BC86-EABFE594F69C}\iexplore@Count 121 Reg HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{E7E6F031-17CE-4C07-BC86-EABFE594F69C}\iexplore@Blocked 121 Reg HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{F6D90F16-9C73-11D3-B32E-00C04F990BB4} Reg HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{F6D90F16-9C73-11D3-B32E-00C04F990BB4}\iexplore Reg HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{F6D90F16-9C73-11D3-B32E-00C04F990BB4}\iexplore@Type 1 Reg HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{F6D90F16-9C73-11D3-B32E-00C04F990BB4}\iexplore@Flags 0 Reg HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{F6D90F16-9C73-11D3-B32E-00C04F990BB4}\iexplore@Count 42 Reg HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{F6D90F16-9C73-11D3-B32E-00C04F990BB4}\iexplore@Time 0xDA 0x07 0x09 0x00 ... Reg HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{FB5F1910-F110-11D2-BB9E-00C04F795683}\iexplore@Count 123 Reg HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{FB5F1910-F110-11D2-BB9E-00C04F795683}\iexplore@Blocked 123 Reg HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings@GlobalUserOffline 0 Reg HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\Extensible Cache\MSHist012010092620100927 Reg HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\Extensible Cache\MSHist012010092620100927@CachePath %USERPROFILE%\Local Settings\History\History.IE5\MSHist012010092620100927 Reg HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\Extensible Cache\MSHist012010092620100927@CachePrefix :2010092620100927: Reg HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\Extensible Cache\MSHist012010092620100927@CacheLimit 8192 Reg HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\Extensible Cache\MSHist012010092620100927@CacheOptions 11 Reg HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\Extensible Cache\MSHist012010092620100927@CacheRepair 0 Reg HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\1@CurrentLevel 66816 Reg HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\2@CurrentLevel 69632 Reg HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\3@CurrentLevel 70912 Reg HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\4@CurrentLevel 73728 Reg HKCU\Software\Microsoft\Windows\CurrentVersion\Run@{039C656D-323C-4CF3-CABF-1D02E9464F4F} "C:\Documents and Settings\Mark Thomson\Application Data\Nouvqe\kalae.exe" Reg HKCU\Software\Microsoft\Windows\CurrentVersion\Run@Vkoqegukoge rundll32.exe "C:\WINDOWS\ielprha.dll",Startup Reg HKCU\Software\Microsoft\Windows\CurrentVersion\Run@dfrgsnapnt.exe C:\DOCUME~1\MARKTH~1\LOCALS~1\Temp\dfrgsnapnt.exe Reg HKCU\Software\Microsoft\Windows\CurrentVersion\Run@MalwareRemovalBot C:\Program Files\MalwareRemovalBot\MalwareRemovalBot.exe -boot Reg HKCU\Software\Microsoft\Windows\CurrentVersion\WinTrust\Trust Providers\Software Publishing@State 146432 Reg HKCU\Software\Microsoft\Windows\ShellNoRoam\Bags\1230\Shell@WinPos1024x768(1).left 51 Reg HKCU\Software\Microsoft\Windows\ShellNoRoam\Bags\1230\Shell@WinPos1024x768(1).top 58 Reg HKCU\Software\Microsoft\Windows\ShellNoRoam\Bags\1230\Shell@WinPos1024x768(1).right 851 Reg HKCU\Software\Microsoft\Windows\ShellNoRoam\Bags\1230\Shell@WinPos1024x768(1).bottom 658 Reg HKCU\Software\Microsoft\Windows\ShellNoRoam\Bags\1230\Shell@FFlags 1 Reg HKCU\Software\Microsoft\Windows\ShellNoRoam\Bags\1230\Shell@Vid {65F125E5-7BE1-4810-BA9D-D271C8432CE3} Reg HKCU\Software\Microsoft\Windows\ShellNoRoam\Bags\1230\Shell@Mode 6 Reg HKCU\Software\Microsoft\Windows\ShellNoRoam\Bags\1230\Shell@ScrollPos1024x768(1).y 0 Reg HKCU\Software\Microsoft\Windows\ShellNoRoam\Bags\1239\Shell@MinPos1024x768(1).x -1 Reg HKCU\Software\Microsoft\Windows\ShellNoRoam\Bags\1239\Shell@MinPos1024x768(1).y -1 Reg HKCU\Software\Microsoft\Windows\ShellNoRoam\Bags\1239\Shell@WinPos1024x768(1).left 22 Reg HKCU\Software\Microsoft\Windows\ShellNoRoam\Bags\1239\Shell@WinPos1024x768(1).top 29 Reg HKCU\Software\Microsoft\Windows\ShellNoRoam\Bags\1239\Shell@WinPos1024x768(1).right 822 Reg HKCU\Software\Microsoft\Windows\ShellNoRoam\Bags\1239\Shell@WinPos1024x768(1).bottom 629 Reg HKCU\Software\Microsoft\Windows\ShellNoRoam\Bags\25\Shell@MinPos1024x768(1).x -32000 Reg HKCU\Software\Microsoft\Windows\ShellNoRoam\Bags\25\Shell@MinPos1024x768(1).y -32000 Reg HKCU\Software\Microsoft\Windows\ShellNoRoam\Bags\25\Shell@WinPos1024x768(1).left 44 Reg HKCU\Software\Microsoft\Windows\ShellNoRoam\Bags\25\Shell@WinPos1024x768(1).top 58 Reg HKCU\Software\Microsoft\Windows\ShellNoRoam\Bags\25\Shell@WinPos1024x768(1).right 844 Reg HKCU\Software\Microsoft\Windows\ShellNoRoam\Bags\25\Shell@WinPos1024x768(1).bottom 658 Reg HKCU\Software\Microsoft\Windows\ShellNoRoam\Bags\3\Shell@WinPos1024x768(1).left 22 Reg HKCU\Software\Microsoft\Windows\ShellNoRoam\Bags\3\Shell@WinPos1024x768(1).top 29 Reg HKCU\Software\Microsoft\Windows\ShellNoRoam\Bags\3\Shell@WinPos1024x768(1).right 822 Reg HKCU\Software\Microsoft\Windows\ShellNoRoam\Bags\3\Shell@WinPos1024x768(1).bottom 629 Reg HKCU\Software\Microsoft\Windows\ShellNoRoam\Bags\3\Shell@ScrollPos1024x768(1).y 182 Reg HKCU\Software\Microsoft\Windows\ShellNoRoam\Bags\35\Shell@WinPos1024x768(1).left 51 Reg HKCU\Software\Microsoft\Windows\ShellNoRoam\Bags\35\Shell@WinPos1024x768(1).top 58 Reg HKCU\Software\Microsoft\Windows\ShellNoRoam\Bags\35\Shell@WinPos1024x768(1).right 851 Reg HKCU\Software\Microsoft\Windows\ShellNoRoam\Bags\35\Shell@WinPos1024x768(1).bottom 658 Reg HKCU\Software\Microsoft\Windows\ShellNoRoam\Bags\668\Shell@WinPos1024x768(1).left 51 Reg HKCU\Software\Microsoft\Windows\ShellNoRoam\Bags\668\Shell@WinPos1024x768(1).top 58 Reg HKCU\Software\Microsoft\Windows\ShellNoRoam\Bags\668\Shell@WinPos1024x768(1).right 851 Reg HKCU\Software\Microsoft\Windows\ShellNoRoam\Bags\668\Shell@WinPos1024x768(1).bottom 658 Reg HKCU\Software\Microsoft\Windows\ShellNoRoam\Bags\91\Shell@WinPos1024x768(1).right 932 Reg HKCU\Software\Microsoft\Windows\ShellNoRoam\Bags\91\Shell@WinPos1024x768(1).bottom 738 Reg HKCU\Software\Microsoft\Windows\ShellNoRoam\MUICache@C:\Documents and Settings\Mark Thomson\Desktop\Shortcut to SAS_793E76.COM.pif Shortcut to SAS_793E76.COM Reg HKCU\Software\Microsoft\Windows\ShellNoRoam\MUICache@C:\WINDOWS\system32\ntvdm.exe NTVDM.EXE Reg HKCU\Software\Microsoft\Windows\ShellNoRoam\MUICache@@C:\WINDOWS\system32\SHELL32.dll,-22914 Contains letters, reports, and other documents and files. Reg HKCU\Software\Microsoft\Windows\ShellNoRoam\MUICache@@shell32.dll,-31242 Rename this file Reg HKCU\Software\Microsoft\Windows\ShellNoRoam\MUICache@@shell32.dll,-31370 E-mail this file Reg HKCU\Software\Microsoft\Windows\ShellNoRoam\MUICache@C:\Documents and Settings\Mark Thomson\My Documents\Glack\SAS_793E76.COM SAS_793E76 Reg HKCU\Software\Microsoft\Windows\ShellNoRoam\MUICache@C:\DOCUME~1\MARKTH~1\LOCALS~1\Temp\SAS_SelfExtract\SEAutorun.com SEAutorun Reg HKCU\Software\Microsoft\Windows\ShellNoRoam\MUICache@C:\DOCUME~1\MARKTH~1\LOCALS~1\Temp\SAS_SelfExtract\program.com SUPERAntiSpyware Application Reg HKCU\Software\Microsoft\Windows\ShellNoRoam\MUICache@C:\WINDOWS\system32\GPhotos.scr Google Photos Screensaver Reg HKCU\Software\Microsoft\Windows\ShellNoRoam\MUICache@C:\Program Files\Common Files\Microsoft Shared\OFFICE11\MSOXMLED.EXE XML Editor ---- Disk sectors - GMER 1.0.15 ---- Disk \Device\Harddisk0\DR0 sector 00: rootkit-like behavior; ---- Files - GMER 1.0.15 ---- File C:\Config.Msi 0 bytes File C:\Documents and Settings\All Users\Application Data\pragmamfeklnmal.dll 1163 bytes File C:\Documents and Settings\All Users\Documents\Server\admin.txt 2 bytes File C:\Documents and Settings\All Users\Documents\Server\server.dat 54784 bytes File C:\Documents and Settings\Mark Thomson\Application Data\Microsoft\Internet Explorer\Quick Launch\Antivirus.lnk 613 bytes File C:\Documents and Settings\Mark Thomson\Application Data\FunWebProducts 0 bytes File C:\Documents and Settings\Mark Thomson\Application Data\FunWebProducts\Data 0 bytes File C:\Documents and Settings\Mark Thomson\Application Data\FunWebProducts\Data\Mark Thomson 0 bytes File C:\Documents and Settings\Mark Thomson\Application Data\MalwareRemovalBot 0 bytes File C:\Documents and Settings\Mark Thomson\Application Data\MalwareRemovalBot\Log 0 bytes File C:\Documents and Settings\Mark Thomson\Application Data\MalwareRemovalBot\Log\2010 Sep 24 - 10_46_59 AM_062.log 6012 bytes File C:\Documents and Settings\Mark Thomson\Application Data\MalwareRemovalBot\rs.dat 224 bytes File C:\Documents and Settings\Mark Thomson\Application Data\MalwareRemovalBot\Settings 0 bytes File C:\Documents and Settings\Mark Thomson\Application Data\MalwareRemovalBot\Settings\ScanResults.pie 39454 bytes File C:\Documents and Settings\Mark Thomson\Application Data\Nouvqe\kalae.exe 90624 bytes executable File C:\Documents and Settings\Mark Thomson\Application Data\U3\4054910C9FC16F95 0 bytes File C:\Documents and Settings\Mark Thomson\Cookies\mark__thomson@doubleclick[1].txt 122 bytes File C:\Documents and Settings\Mark Thomson\Cookies\mark__thomson@download.cnet[1].txt 123 bytes File C:\Documents and Settings\Mark Thomson\Cookies\mark__thomson@google.co[1].txt 349 bytes File C:\Documents and Settings\Mark Thomson\Cookies\mark__thomson@google[1].txt 345 bytes File C:\Documents and Settings\Mark Thomson\Cookies\mark__thomson@revsci[1].txt 1276 bytes File C:\Documents and Settings\Mark Thomson\Cookies\mark__thomson@scorecardresearch[1].txt 113 bytes File C:\Documents and Settings\Mark Thomson\Cookies\mark__thomson@trialpay[1].txt 278 bytes File C:\Documents and Settings\Mark Thomson\Cookies\mark__thomson@trusearch[1].txt 100 bytes File C:\Documents and Settings\Mark Thomson\Cookies\mark__thomson@wwwadcntr[1].txt 321 bytes File C:\Documents and Settings\Mark Thomson\Cookies\mark__thomson@yahoo[1].txt 83 bytes File C:\Documents and Settings\Mark Thomson\Cookies\mark__thomson@64.111.212[1].txt 100 bytes File C:\Documents and Settings\Mark Thomson\Cookies\mark__thomson@67.201.62[1].txt 79 bytes File C:\Documents and Settings\Mark Thomson\Cookies\mark__thomson@ad.yieldmanager[2].txt 723 bytes File C:\Documents and Settings\Mark Thomson\Cookies\mark__thomson@advertise[1].txt 162 bytes File C:\Documents and Settings\Mark Thomson\Cookies\mark__thomson@bluekai[2].txt 534 bytes File C:\Documents and Settings\Mark Thomson\Cookies\mark__thomson@cnet[1].txt 1177 bytes File C:\Documents and Settings\Mark Thomson\Cookies\mark__thomson@com[1].txt 95 bytes File C:\Documents and Settings\Mark Thomson\Desktop\Malwarebytes' Anti-Malware 0 bytes File C:\Documents and Settings\Mark Thomson\Desktop\Malwarebytes' Anti-Malware\Malwarebytes' Anti-Malware Help.lnk 841 bytes File C:\Documents and Settings\Mark Thomson\Desktop\Malwarebytes' Anti-Malware\Malwarebytes' Anti-Malware.lnk 841 bytes File C:\Documents and Settings\Mark Thomson\Desktop\Malwarebytes' Anti-Malware\Uninstall Malwarebytes' Anti-Malware.lnk 865 bytes File C:\Documents and Settings\Mark Thomson\Local Settings\Application Data\Google\Toolbar Cache\6.5.708.1000 0 bytes File C:\Documents and Settings\Mark Thomson\Local Settings\Application Data\Google\Toolbar Cache\6.5.708.1000\en-GB 0 bytes File C:\Documents and Settings\Mark Thomson\Local Settings\Application Data\Google\Toolbar Cache\6.5.708.1000\en-GB\annotaions_whitelist.json.content 370 bytes File C:\Documents and Settings\Mark Thomson\Local Settings\Application Data\Google\Toolbar Cache\6.5.708.1000\en-GB\translate_languages.json.content 1457 bytes File C:\Documents and Settings\Mark Thomson\Local Settings\History\History.IE5\MSHist012010092620100927 0 bytes File C:\Documents and Settings\Mark Thomson\Local Settings\History\History.IE5\MSHist012010092620100927\index.dat 49152 bytes File C:\Documents and Settings\Mark Thomson\Local Settings\Temp\0.6893608857765097.exe 81920 bytes File C:\Documents and Settings\Mark Thomson\Local Settings\Temp\pragmamainqt.dll 10455 bytes File C:\Documents and Settings\Mark Thomson\Local Settings\Temp\SAS_SelfExtract\AppLogs\SUPERANTISPYWARE-9-26-2010( 17-23-12 ).SDB 378572 bytes File C:\Documents and Settings\Mark Thomson\Local Settings\Temporary Internet Files\Content.IE5\0JFMHIFS 0 bytes File C:\Documents and Settings\Mark Thomson\Local Settings\Temporary Internet Files\Content.IE5\0JFMHIFS\%23161[1] 794 bytes File C:\Documents and Settings\Mark Thomson\Local Settings\Temporary Internet Files\Content.IE5\0JFMHIFS\16631_0[1].png 396 bytes File C:\Documents and Settings\Mark Thomson\Local Settings\Temporary Internet Files\Content.IE5\0JFMHIFS\187[1].gif 53 bytes File C:\Documents and Settings\Mark Thomson\Local Settings\Temporary Internet Files\Content.IE5\0JFMHIFS\3000-2239_4-10320142[1].htm 101957 bytes File C:\Documents and Settings\Mark Thomson\Local Settings\Temporary Internet Files\Content.IE5\0JFMHIFS\5811038[1].js 760 bytes File C:\Documents and Settings\Mark Thomson\Local Settings\Temporary Internet Files\Content.IE5\0JFMHIFS\5q1hyil2[1].png 171 bytes File C:\Documents and Settings\Mark Thomson\Local Settings\Temporary Internet Files\Content.IE5\0JFMHIFS\ac[1].htm 1041 bytes File C:\Documents and Settings\Mark Thomson\Local Settings\Temporary Internet Files\Content.IE5\0JFMHIFS\ac[2].htm 1266 bytes File C:\Documents and Settings\Mark Thomson\Local Settings\Temporary Internet Files\Content.IE5\0JFMHIFS\ac[3].htm 0 bytes File C:\Documents and Settings\Mark Thomson\Local Settings\Temporary Internet Files\Content.IE5\0JFMHIFS\antivirus_right[1].gif 4920 bytes File C:\Documents and Settings\Mark Thomson\Local Settings\Temporary Internet Files\Content.IE5\0JFMHIFS\neoLoginSprite[1].png 731 bytes File C:\Documents and Settings\Mark Thomson\Local Settings\Temporary Internet Files\Content.IE5\0JFMHIFS\new-look[1].png 7190 bytes File C:\Documents and Settings\Mark Thomson\Local Settings\Temporary Internet Files\Content.IE5\0JFMHIFS\popupArrow[1].png 431 bytes File C:\Documents and Settings\Mark Thomson\Local Settings\Temporary Internet Files\Content.IE5\0JFMHIFS\ratingStars[1].gif 1755 bytes File C:\Documents and Settings\Mark Thomson\Local Settings\Temporary Internet Files\Content.IE5\0JFMHIFS\scrollerBg[1].gif 5324 bytes File C:\Documents and Settings\Mark Thomson\Local Settings\Temporary Internet Files\Content.IE5\0JFMHIFS\search[1] 541 bytes File C:\Documents and Settings\Mark Thomson\Local Settings\Temporary Internet Files\Content.IE5\0JFMHIFS\search[1].gif 2886 bytes File C:\Documents and Settings\Mark Thomson\Local Settings\Temporary Internet Files\Content.IE5\0JFMHIFS\search[2] 568 bytes File C:\Documents and Settings\Mark Thomson\Local Settings\Temporary Internet Files\Content.IE5\0JFMHIFS\SecondRun[1].gif 807 bytes File C:\Documents and Settings\Mark Thomson\Local Settings\Temporary Internet Files\Content.IE5\0JFMHIFS\site4headerBg[1].png 8120 bytes File C:\Documents and Settings\Mark Thomson\Local Settings\Temporary Internet Files\Content.IE5\0JFMHIFS\statusOr[1].jpg 1194 bytes File C:\Documents and Settings\Mark Thomson\Local Settings\Temporary Internet Files\Content.IE5\0JFMHIFS\toolbarBkg2[1].png 3618 bytes File C:\Documents and Settings\Mark Thomson\Local Settings\Temporary Internet Files\Content.IE5\0JFMHIFS\tools[1] 3560 bytes File C:\Documents and Settings\Mark Thomson\Local Settings\Temporary Internet Files\Content.IE5\0JFMHIFS\wt_v3[1].js 4767 bytes File C:\Documents and Settings\Mark Thomson\Local Settings\Temporary Internet Files\Content.IE5\0JFMHIFS\xb1-banner3[1].png 31149 bytes File C:\Documents and Settings\Mark Thomson\Local Settings\Temporary Internet Files\Content.IE5\0JFMHIFS\default[1].css 71168 bytes File C:\Documents and Settings\Mark Thomson\Local Settings\Temporary Internet Files\Content.IE5\0JFMHIFS\download[1].xml 1308 bytes File C:\Documents and Settings\Mark Thomson\Local Settings\Temporary Internet Files\Content.IE5\0JFMHIFS\download[2].xml 1308 bytes File C:\Documents and Settings\Mark Thomson\Local Settings\Temporary Internet Files\Content.IE5\0JFMHIFS\dw[1].gif 43 bytes File C:\Documents and Settings\Mark Thomson\Local Settings\Temporary Internet Files\Content.IE5\0JFMHIFS\dw[1].js 16222 bytes File C:\Documents and Settings\Mark Thomson\Local Settings\Temporary Internet Files\Content.IE5\0JFMHIFS\easier-search[1].png 7157 bytes File C:\Documents and Settings\Mark Thomson\Local Settings\Temporary Internet Files\Content.IE5\0JFMHIFS\ErrorPageTemplate[1] 2168 bytes File C:\Documents and Settings\Mark Thomson\Local Settings\Temporary Internet Files\Content.IE5\0JFMHIFS\Facebook_MPU[1].jpg 37180 bytes File C:\Documents and Settings\Mark Thomson\Local Settings\Temporary Internet Files\Content.IE5\0JFMHIFS\fmimg1367661906667610211_32x32[1].png 2802 bytes File C:\Documents and Settings\Mark Thomson\Local Settings\Temporary Internet Files\Content.IE5\0JFMHIFS\fmimg2061791047982020619_32x32[1].png 2759 bytes File C:\Documents and Settings\Mark Thomson\Local Settings\Temporary Internet Files\Content.IE5\0JFMHIFS\fmimg4413383112739052960[1].png 1459 bytes File C:\Documents and Settings\Mark Thomson\Local Settings\Temporary Internet Files\Content.IE5\0JFMHIFS\fmimg5118503011213171703[1].png 2596 bytes File C:\Documents and Settings\Mark Thomson\Local Settings\Temporary Internet Files\Content.IE5\0JFMHIFS\fmimg5975234224912014594_32x32[1].png 2638 bytes File C:\Documents and Settings\Mark Thomson\Local Settings\Temporary Internet Files\Content.IE5\0JFMHIFS\fmimg7018928402934970340_32x32[1].png 2663 bytes File C:\Documents and Settings\Mark Thomson\Local Settings\Temporary Internet Files\Content.IE5\0JFMHIFS\fmimg8979563240042413583[1].png 366 bytes File C:\Documents and Settings\Mark Thomson\Local Settings\Temporary Internet Files\Content.IE5\0JFMHIFS\Foreman_11117089_7804_avg32[1].png 2798 bytes File C:\Documents and Settings\Mark Thomson\Local Settings\Temporary Internet Files\Content.IE5\0JFMHIFS\Foreman_11464099_8928_Foreman_11086761_9010_sheild_32x32[1].jpg 2168 bytes File C:\Documents and Settings\Mark Thomson\Local Settings\Temporary Internet Files\Content.IE5\0JFMHIFS\gw[1].js 5034 bytes File C:\Documents and Settings\Mark Thomson\Local Settings\Temporary Internet Files\Content.IE5\0JFMHIFS\hr[1].gif 1444 bytes File C:\Documents and Settings\Mark Thomson\Local Settings\Temporary Internet Files\Content.IE5\0JFMHIFS\ico_check_green[1].png 605 bytes File C:\Documents and Settings\Mark Thomson\Local Settings\Temporary Internet Files\Content.IE5\0JFMHIFS\info_48[1] 6993 bytes File C:\Documents and Settings\Mark Thomson\Local Settings\Temporary Internet Files\Content.IE5\0JFMHIFS\lclrfine[1].xml 6584 bytes File C:\Documents and Settings\Mark Thomson\Local Settings\Temporary Internet Files\Content.IE5\0JFMHIFS\lclsrch[1].xml 1531 bytes File C:\Documents and Settings\Mark Thomson\Local Settings\Temporary Internet Files\Content.IE5\0JFMHIFS\loading_transparent[2].gif 1985 bytes File C:\Documents and Settings\Mark Thomson\Local Settings\Temporary Internet Files\Content.IE5\0JFMHIFS\logo1w[1].png 7330 bytes File C:\Documents and Settings\Mark Thomson\Local Settings\Temporary Internet Files\Content.IE5\0JFMHIFS\logo[2].gif 1337 bytes File C:\Documents and Settings\Mark Thomson\Local Settings\Temporary Internet Files\Content.IE5\0JFMHIFS\avg-gen-m10_362x127[1].gif 8404 bytes File C:\Documents and Settings\Mark Thomson\Local Settings\Temporary Internet Files\Content.IE5\0JFMHIFS\balloon[1].xml 34787 bytes File C:\Documents and Settings\Mark Thomson\Local Settings\Temporary Internet Files\Content.IE5\0JFMHIFS\beacon[1].js 1087 bytes File C:\Documents and Settings\Mark Thomson\Local Settings\Temporary Internet Files\Content.IE5\0JFMHIFS\bg_blu_1px[1].gif 669 bytes File C:\Documents and Settings\Mark Thomson\Local Settings\Temporary Internet Files\Content.IE5\0JFMHIFS\bg_ylo_top_1px[1].gif 595 bytes File C:\Documents and Settings\Mark Thomson\Local Settings\Temporary Internet Files\Content.IE5\0JFMHIFS\bottom_full[1].png 1319 bytes File C:\Documents and Settings\Mark Thomson\Local Settings\Temporary Internet Files\Content.IE5\0JFMHIFS\brandNavPipe[1].gif 45 bytes File C:\Documents and Settings\Mark Thomson\Local Settings\Temporary Internet Files\Content.IE5\0JFMHIFS\c729bxo3[1].swf 3052 bytes File C:\Documents and Settings\Mark Thomson\Local Settings\Temporary Internet Files\Content.IE5\0JFMHIFS\autocompleteBg[1].png 2858 bytes File C:\Documents and Settings\Mark Thomson\Local Settings\Temporary Internet Files\Content.IE5\0JFMHIFS\catSpotDownload_v2_single[1].css 1039 bytes File C:\Documents and Settings\Mark Thomson\Local Settings\Temporary Internet Files\Content.IE5\0JFMHIFS\fmimg7029831463065274486_32x32[1].png 1965 bytes File C:\Documents and Settings\Mark Thomson\Local Settings\Temporary Internet Files\Content.IE5\0JFMHIFS\nav_icon1[1].jpg 1723 bytes File C:\Documents and Settings\Mark Thomson\Local Settings\Temporary Internet Files\Content.IE5\1ODN4HWP 0 bytes File C:\Documents and Settings\Mark Thomson\Local Settings\Temporary Internet Files\Content.IE5\6ECK1D1O 0 bytes File C:\Documents and Settings\Mark Thomson\Local Settings\Temporary Internet Files\Content.IE5\6ECK1D1O\272847368[1].js 672 bytes File C:\Documents and Settings\Mark Thomson\Local Settings\Temporary Internet Files\Content.IE5\6ECK1D1O\2894[2] 41 bytes File C:\Documents and Settings\Mark Thomson\Local Settings\Temporary Internet Files\Content.IE5\6ECK1D1O\3001-2239_4-10320142[1].htm 97726 bytes File C:\Documents and Settings\Mark Thomson\Local Settings\Temporary Internet Files\Content.IE5\6ECK1D1O\300x250-cs7straighttalk-25k[1].gif 21187 bytes File C:\Documents and Settings\Mark Thomson\Local Settings\Temporary Internet Files\Content.IE5\6ECK1D1O\4806[1].htm 25637 bytes File C:\Documents and Settings\Mark Thomson\Local Settings\Temporary Internet Files\Content.IE5\6ECK1D1O\7vrftcmg[1].js 587 bytes File C:\Documents and Settings\Mark Thomson\Local Settings\Temporary Internet Files\Content.IE5\6ECK1D1O\acCA1EQM85.htm 1098 bytes File C:\Documents and Settings\Mark Thomson\Local Settings\Temporary Internet Files\Content.IE5\6ECK1D1O\acCAJ6FQ51.htm 1251 bytes File C:\Documents and Settings\Mark Thomson\Local Settings\Temporary Internet Files\Content.IE5\6ECK1D1O\acCAMQ359G.htm 1101 bytes File C:\Documents and Settings\Mark Thomson\Local Settings\Temporary Internet Files\Content.IE5\6ECK1D1O\ac[10].htm 1266 bytes File C:\Documents and Settings\Mark Thomson\Local Settings\Temporary Internet Files\Content.IE5\6ECK1D1O\ac[11].htm 1206 bytes File C:\Documents and Settings\Mark Thomson\Local Settings\Temporary Internet Files\Content.IE5\6ECK1D1O\ac[1].htm 1191 bytes File C:\Documents and Settings\Mark Thomson\Local Settings\Temporary Internet Files\Content.IE5\6ECK1D1O\ac[2].htm 1272 bytes File C:\Documents and Settings\Mark Thomson\Local Settings\Temporary Internet Files\Content.IE5\6ECK1D1O\ac[3].htm 0 bytes File C:\Documents and Settings\Mark Thomson\Local Settings\Temporary Internet Files\Content.IE5\6ECK1D1O\ac[4].htm 0 bytes File C:\Documents and Settings\Mark Thomson\Local Settings\Temporary Internet Files\Content.IE5\6ECK1D1O\ac[5].htm 0 bytes File C:\Documents and Settings\Mark Thomson\Local Settings\Temporary Internet Files\Content.IE5\6ECK1D1O\ac[6].htm 1026 bytes File C:\Documents and Settings\Mark Thomson\Local Settings\Temporary Internet Files\Content.IE5\6ECK1D1O\ac[7].htm 0 bytes File C:\Documents and Settings\Mark Thomson\Local Settings\Temporary Internet Files\Content.IE5\6ECK1D1O\ac[8].htm 1296 bytes File C:\Documents and Settings\Mark Thomson\Local Settings\Temporary Internet Files\Content.IE5\6ECK1D1O\ac[9].htm 0 bytes File C:\Documents and Settings\Mark Thomson\Local Settings\Temporary Internet Files\Content.IE5\6ECK1D1O\print[1].css 8170 bytes File C:\Documents and Settings\Mark Thomson\Local Settings\Temporary Internet Files\Content.IE5\6ECK1D1O\rblogoFooter[1].gif 1307 bytes File C:\Documents and Settings\Mark Thomson\Local Settings\Temporary Internet Files\Content.IE5\6ECK1D1O\scrollerLi[1].gif 424 bytes File C:\Documents and Settings\Mark Thomson\Local Settings\Temporary Internet Files\Content.IE5\6ECK1D1O\search[1] 500 bytes File C:\Documents and Settings\Mark Thomson\Local Settings\Temporary Internet Files\Content.IE5\6ECK1D1O\search[2] 549 bytes File C:\Documents and Settings\Mark Thomson\Local Settings\Temporary Internet Files\Content.IE5\6ECK1D1O\search[3] 579 bytes File C:\Documents and Settings\Mark Thomson\Local Settings\Temporary Internet Files\Content.IE5\6ECK1D1O\selectorsSprite[1].png 601 bytes File C:\Documents and Settings\Mark Thomson\Local Settings\Temporary Internet Files\Content.IE5\6ECK1D1O\site4logo[1].png 6724 bytes File C:\Documents and Settings\Mark Thomson\Local Settings\Temporary Internet Files\Content.IE5\6ECK1D1O\site4rbHeader[1].png 4888 bytes File C:\Documents and Settings\Mark Thomson\Local Settings\Temporary Internet Files\Content.IE5\6ECK1D1O\sitenav[1].png 442 bytes File C:\Documents and Settings\Mark Thomson\Local Settings\Temporary Internet Files\Content.IE5\6ECK1D1O\smlListBkg[1].png 500 bytes File C:\Documents and Settings\Mark Thomson\Local Settings\Temporary Internet Files\Content.IE5\6ECK1D1O\spinner[1].gif 6820 bytes File C:\Documents and Settings\Mark Thomson\Local Settings\Temporary Internet Files\Content.IE5\6ECK1D1O\spon-warrow[1].gif 219 bytes File C:\Documents and Settings\Mark Thomson\Local Settings\Temporary Internet Files\Content.IE5\6ECK1D1O\tabbed-2[1].png 6876 bytes File C:\Documents and Settings\Mark Thomson\Local Settings\Temporary Internet Files\Content.IE5\6ECK1D1O\td[1].xml 420 bytes File C:\Documents and Settings\Mark Thomson\Local Settings\Temporary Internet Files\Content.IE5\6ECK1D1O\td[2].xml 420 bytes File C:\Documents and Settings\Mark Thomson\Local Settings\Temporary Internet Files\Content.IE5\6ECK1D1O\top_full[1].png 370 bytes File C:\Documents and Settings\Mark Thomson\Local Settings\Temporary Internet Files\Content.IE5\6ECK1D1O\tt_promo_1[1].jpg 23230 bytes File C:\Documents and Settings\Mark Thomson\Local Settings\Temporary Internet Files\Content.IE5\6ECK1D1O\UK_SECROS_sd_728_03b_1-6-10[1].gif 11691 bytes File C:\Documents and Settings\Mark Thomson\Local Settings\Temporary Internet Files\Content.IE5\6ECK1D1O\flexButton[1].gif 1200 bytes File C:\Documents and Settings\Mark Thomson\Local Settings\Temporary Internet Files\Content.IE5\6ECK1D1O\fmimg1657085450203353602[1].png 1823 bytes File C:\Documents and Settings\Mark Thomson\Local Settings\Temporary Internet Files\Content.IE5\6ECK1D1O\fmimg1731251581612613878[1].png 981 bytes File C:\Documents and Settings\Mark Thomson\Local Settings\Temporary Internet Files\Content.IE5\6ECK1D1O\fmimg2636649066659479858_32x32[1].png 1965 bytes File C:\Documents and Settings\Mark Thomson\Local Settings\Temporary Internet Files\Content.IE5\6ECK1D1O\fmimg2756583355776667281[1].png 1443 bytes File C:\Documents and Settings\Mark Thomson\Local Settings\Temporary Internet Files\Content.IE5\6ECK1D1O\fmimg4516646597258016925[1].png 1229 bytes File C:\Documents and Settings\Mark Thomson\Local Settings\Temporary Internet Files\Content.IE5\6ECK1D1O\fmimg6082894515847147638[1].png 2798 bytes File C:\Documents and Settings\Mark Thomson\Local Settings\Temporary Internet Files\Content.IE5\6ECK1D1O\fmimg6452271142490832514_32x32[1].png 1980 bytes File C:\Documents and Settings\Mark Thomson\Local Settings\Temporary Internet Files\Content.IE5\6ECK1D1O\fmimg6590336278021934381_32x32[1].png 2570 bytes File C:\Documents and Settings\Mark Thomson\Local Settings\Temporary Internet Files\Content.IE5\6ECK1D1O\fmimg7126535568390505567[1].png 745 bytes File C:\Documents and Settings\Mark Thomson\Local Settings\Temporary Internet Files\Content.IE5\6ECK1D1O\fmimg7304320718505958152[1].png 2374 bytes File C:\Documents and Settings\Mark Thomson\Local Settings\Temporary Internet Files\Content.IE5\6ECK1D1O\google_co_uk[1].htm 13498 bytes File C:\Documents and Settings\Mark Thomson\Local Settings\Temporary Internet Files\Content.IE5\6ECK1D1O\httpErrorPagesScripts[1] 7579 bytes File C:\Documents and Settings\Mark Thomson\Local Settings\Temporary Internet Files\Content.IE5\6ECK1D1O\ico_check_blue[1].png 636 bytes File C:\Documents and Settings\Mark Thomson\Local Settings\Temporary Internet Files\Content.IE5\6ECK1D1O\IEFirst_V3[1].css 6757 bytes File C:\Documents and Settings\Mark Thomson\Local Settings\Temporary Internet Files\Content.IE5\6ECK1D1O\Lang_setting[1].png 8424 bytes File C:\Documents and Settings\Mark Thomson\Local Settings\Temporary Internet Files\Content.IE5\6ECK1D1O\lightintegration[1].js 30092 bytes File C:\Documents and Settings\Mark Thomson\Local Settings\Temporary Internet Files\Content.IE5\6ECK1D1O\listIcon[1].gif 387 bytes File C:\Documents and Settings\Mark Thomson\Local Settings\Temporary Internet Files\Content.IE5\6ECK1D1O\logo[1].gif 3698 bytes File C:\Documents and Settings\Mark Thomson\Local Settings\Temporary Internet Files\Content.IE5\6ECK1D1O\matrix[1].css 15637 bytes File C:\Documents and Settings\Mark Thomson\Local Settings\Temporary Internet Files\Content.IE5\6ECK1D1O\mgyhp_sm[1].png 331 bytes File C:\Documents and Settings\Mark Thomson\Local Settings\Temporary Internet Files\Content.IE5\6ECK1D1O\neoSearchWrapSprite[1].png 923 bytes File C:\Documents and Settings\Mark Thomson\Local Settings\Temporary Internet Files\Content.IE5\6ECK1D1O\overviewSprite[1].gif 3091 bytes File C:\Documents and Settings\Mark Thomson\Local Settings\Temporary Internet Files\Content.IE5\6ECK1D1O\popupBkg[1].png 11169 bytes File C:\Documents and Settings\Mark Thomson\Local Settings\Temporary Internet Files\Content.IE5\6ECK1D1O\antivirus_left[1].gif 54849 bytes File C:\Documents and Settings\Mark Thomson\Local Settings\Temporary Internet Files\Content.IE5\6ECK1D1O\avg_free_stb_all_9_115_cnet[1].exe 2133536 bytes executable File C:\Documents and Settings\Mark Thomson\Local Settings\Temporary Internet Files\Content.IE5\6ECK1D1O\beacon[1].js 1087 bytes File C:\Documents and Settings\Mark Thomson\Local Settings\Temporary Internet Files\Content.IE5\6ECK1D1O\bg_ylo_bot_1px[1].gif 155 bytes File C:\Documents and Settings\Mark Thomson\Local Settings\Temporary Internet Files\Content.IE5\6ECK1D1O\button_setting_off[1].png 8654 bytes File C:\Documents and Settings\Mark Thomson\Local Settings\Temporary Internet Files\Content.IE5\6ECK1D1O\checkBrowser[1].htm 2850 bytes File C:\Documents and Settings\Mark Thomson\Local Settings\Temporary Internet Files\Content.IE5\6ECK1D1O\checkBrowser[2].htm 2851 bytes File C:\Documents and Settings\Mark Thomson\Local Settings\Temporary Internet Files\Content.IE5\6ECK1D1O\commIcon[1].jpg 934 bytes File C:\Documents and Settings\Mark Thomson\Local Settings\Temporary Internet Files\Content.IE5\6ECK1D1O\download.tron.postdl.unicorn.compressed[1].js 12956 bytes File C:\Documents and Settings\Mark Thomson\Local Settings\Temporary Internet Files\Content.IE5\6ECK1D1O\down[1] 3414 bytes File C:\Documents and Settings\Mark Thomson\Local Settings\Temporary Internet Files\Content.IE5\6ECK1D1O\favicon[1].ico 1150 bytes File C:\Documents and Settings\Mark Thomson\Local Settings\Temporary Internet Files\Content.IE5\8YFHRU1P 0 bytes File C:\Documents and Settings\Mark Thomson\Local Settings\Temporary Internet Files\Content.IE5\8YFHRU1P\google_co_uk[1].htm 13205 bytes File C:\Documents and Settings\Mark Thomson\Local Settings\Temporary Internet Files\Content.IE5\HPDNWUIK 0 bytes File C:\Documents and Settings\Mark Thomson\Local Settings\Temporary Internet Files\Content.IE5\HPDNWUIK\%23116[1] 1058 bytes File C:\Documents and Settings\Mark Thomson\Local Settings\Temporary Internet Files\Content.IE5\HPDNWUIK\2894[1] 41 bytes File C:\Documents and Settings\Mark Thomson\Local Settings\Temporary Internet Files\Content.IE5\HPDNWUIK\3055-2239_4-10320142[1].htm 59424 bytes executable File C:\Documents and Settings\Mark Thomson\Local Settings\Temporary Internet Files\Content.IE5\HPDNWUIK\3474-4_4-0[1].htm 636 bytes File C:\Documents and Settings\Mark Thomson\Local Settings\Temporary Internet Files\Content.IE5\HPDNWUIK\3zvkkhxx[1].js 133538 bytes File C:\Documents and Settings\Mark Thomson\Local Settings\Temporary Internet Files\Content.IE5\HPDNWUIK\92392e8dfac80a0f921354ff1e761f187295_32x32_32x32[1].png 2184 bytes File C:\Documents and Settings\Mark Thomson\Local Settings\Temporary Internet Files\Content.IE5\HPDNWUIK\a42C7frQevs[1].js 60367 bytes File C:\Documents and Settings\Mark Thomson\Local Settings\Temporary Internet Files\Content.IE5\HPDNWUIK\ac[1].htm 0 bytes File C:\Documents and Settings\Mark Thomson\Local Settings\Temporary Internet Files\Content.IE5\HPDNWUIK\ac[2].htm 0 bytes File C:\Documents and Settings\Mark Thomson\Local Settings\Temporary Internet Files\Content.IE5\HPDNWUIK\ac[3].htm 0 bytes File C:\Documents and Settings\Mark Thomson\Local Settings\Temporary Internet Files\Content.IE5\HPDNWUIK\ac[4].htm 0 bytes File C:\Documents and Settings\Mark Thomson\Local Settings\Temporary Internet Files\Content.IE5\HPDNWUIK\ac[5].htm 0 bytes File C:\Documents and Settings\Mark Thomson\Local Settings\Temporary Internet Files\Content.IE5\HPDNWUIK\advertisement_pointrt_sm[1].gif 872 bytes File C:\Documents and Settings\Mark Thomson\Local Settings\Temporary Internet Files\Content.IE5\HPDNWUIK\all[1].js 88994 bytes File C:\Documents and Settings\Mark Thomson\Local Settings\Temporary Internet Files\Content.IE5\HPDNWUIK\fb-favicon-16x18[1].gif 379 bytes File C:\Documents and Settings\Mark Thomson\Local Settings\Temporary Internet Files\Content.IE5\HPDNWUIK\FirstRun[1].gif 807 bytes File C:\Documents and Settings\Mark Thomson\Local Settings\Temporary Internet Files\Content.IE5\HPDNWUIK\fmimg1162976125136943559[1].png 1122 bytes File C:\Documents and Settings\Mark Thomson\Local Settings\Temporary Internet Files\Content.IE5\HPDNWUIK\fmimg1433797636395230865_32x32[1].png 2345 bytes File C:\Documents and Settings\Mark Thomson\Local Settings\Temporary Internet Files\Content.IE5\HPDNWUIK\fmimg1504893042192913640[1].png 1227 bytes File C:\Documents and Settings\Mark Thomson\Local Settings\Temporary Internet Files\Content.IE5\HPDNWUIK\fmimg2939502318270847101_32x32[1].png 1439 bytes File C:\Documents and Settings\Mark Thomson\Local Settings\Temporary Internet Files\Content.IE5\HPDNWUIK\fmimg3354803867218288463_32x32[1].png 2173 bytes File C:\Documents and Settings\Mark Thomson\Local Settings\Temporary Internet Files\Content.IE5\HPDNWUIK\fmimg789217366708619930[1].png 2798 bytes File C:\Documents and Settings\Mark Thomson\Local Settings\Temporary Internet Files\Content.IE5\HPDNWUIK\oreo.moo.rb.combined[1].js 185732 bytes File C:\Documents and Settings\Mark Thomson\Local Settings\Temporary Internet Files\Content.IE5\HPDNWUIK\pdl[2].css 10364 bytes File C:\Documents and Settings\Mark Thomson\Local Settings\Temporary Internet Files\Content.IE5\HPDNWUIK\pipe[1].gif 65 bytes File C:\Documents and Settings\Mark Thomson\Local Settings\Temporary Internet Files\Content.IE5\HPDNWUIK\prev[1].gif 529 bytes File C:\Documents and Settings\Mark Thomson\Local Settings\Temporary Internet Files\Content.IE5\HPDNWUIK\ratingStarsSm[1].gif 1398 bytes File C:\Documents and Settings\Mark Thomson\Local Settings\Temporary Internet Files\Content.IE5\HPDNWUIK\rbLogo[1].png 7198 bytes File C:\Documents and Settings\Mark Thomson\Local Settings\Temporary Internet Files\Content.IE5\HPDNWUIK\redball[1].png 1585 bytes File C:\Documents and Settings\Mark Thomson\Local Settings\Temporary Internet Files\Content.IE5\HPDNWUIK\scrollerArws[1].gif 574 bytes File C:\Documents and Settings\Mark Thomson\Local Settings\Temporary Internet Files\Content.IE5\HPDNWUIK\search[1] 592 bytes File C:\Documents and Settings\Mark Thomson\Local Settings\Temporary Internet Files\Content.IE5\HPDNWUIK\search_icon[1].png 5290 bytes File C:\Documents and Settings\Mark Thomson\Local Settings\Temporary Internet Files\Content.IE5\HPDNWUIK\siteId1hedB[1].gif 371 bytes File C:\Documents and Settings\Mark Thomson\Local Settings\Temporary Internet Files\Content.IE5\HPDNWUIK\td[1].xml 420 bytes File C:\Documents and Settings\Mark Thomson\Local Settings\Temporary Internet Files\Content.IE5\HPDNWUIK\tighter-security[1].png 7330 bytes File C:\Documents and Settings\Mark Thomson\Local Settings\Temporary Internet Files\Content.IE5\HPDNWUIK\top_basic[1].png 315 bytes File C:\Documents and Settings\Mark Thomson\Local Settings\Temporary Internet Files\Content.IE5\HPDNWUIK\verp[1].htm 179 bytes File C:\Documents and Settings\Mark Thomson\Local Settings\Temporary Internet Files\Content.IE5\HPDNWUIK\verp[2].htm 179 bytes File C:\Documents and Settings\Mark Thomson\Local Settings\Temporary Internet Files\Content.IE5\HPDNWUIK\VT_hdr[1].jpg 25586 bytes File C:\Documents and Settings\Mark Thomson\Local Settings\Temporary Internet Files\Content.IE5\HPDNWUIK\generic_software[1].jpg 1818 bytes File C:\Documents and Settings\Mark Thomson\Local Settings\Temporary Internet Files\Content.IE5\HPDNWUIK\go[1].gif 717 bytes File C:\Documents and Settings\Mark Thomson\Local Settings\Temporary Internet Files\Content.IE5\HPDNWUIK\iframe[1].htm 24881 bytes File C:\Documents and Settings\Mark Thomson\Local Settings\Temporary Internet Files\Content.IE5\HPDNWUIK\info12[1].gif 540 bytes File C:\Documents and Settings\Mark Thomson\Local Settings\Temporary Internet Files\Content.IE5\HPDNWUIK\lclprog[1].xml 2173 bytes File C:\Documents and Settings\Mark Thomson\Local Settings\Temporary Internet Files\Content.IE5\HPDNWUIK\MadUCat[1].js 5416 bytes File C:\Documents and Settings\Mark Thomson\Local Settings\Temporary Internet Files\Content.IE5\HPDNWUIK\moveSprite[1].gif 609 bytes File C:\Documents and Settings\Mark Thomson\Local Settings\Temporary Internet Files\Content.IE5\HPDNWUIK\mpufalltechpreview2010[1].jpg 65929 bytes File C:\Documents and Settings\Mark Thomson\Local Settings\Temporary Internet Files\Content.IE5\HPDNWUIK\AP[1].js 32221 bytes File C:\Documents and Settings\Mark Thomson\Local Settings\Temporary Internet Files\Content.IE5\HPDNWUIK\auxHead[1].gif 5535 bytes File C:\Documents and Settings\Mark Thomson\Local Settings\Temporary Internet Files\Content.IE5\HPDNWUIK\b3ifxgah[1].gif 145 bytes File C:\Documents and Settings\Mark Thomson\Local Settings\Temporary Internet Files\Content.IE5\HPDNWUIK\bgBody[1].gif 207 bytes File C:\Documents and Settings\Mark Thomson\Local Settings\Temporary Internet Files\Content.IE5\HPDNWUIK\bg_features_top_1px[1].png 2922 bytes File C:\Documents and Settings\Mark Thomson\Local Settings\Temporary Internet Files\Content.IE5\HPDNWUIK\bullet[1] 3169 bytes File C:\Documents and Settings\Mark Thomson\Local Settings\Temporary Internet Files\Content.IE5\HPDNWUIK\b[1].jpg 304 bytes File C:\Documents and Settings\Mark Thomson\Local Settings\Temporary Internet Files\Content.IE5\HPDNWUIK\Clear_type[1].png 6071 bytes File C:\Documents and Settings\Mark Thomson\Local Settings\Temporary Internet Files\Content.IE5\HPDNWUIK\convpixel[1].jpg 0 bytes File C:\Documents and Settings\Mark Thomson\Local Settings\Temporary Internet Files\Content.IE5\HPDNWUIK\dm_marketing_message-en-us[1].htm 30042 bytes File C:\Documents and Settings\Mark Thomson\Local Settings\Temporary Internet Files\Content.IE5\HPDNWUIK\dot3[1].gif 45 bytes File C:\Documents and Settings\Mark Thomson\Local Settings\Temporary Internet Files\Content.IE5\HPDNWUIK\dotclear[1].gif 43 bytes File C:\Documents and Settings\Mark Thomson\Local Settings\Temporary Internet Files\Content.IE5\HPDNWUIK\download[1].xml 1308 bytes File C:\Documents and Settings\Mark Thomson\Local Settings\Temporary Internet Files\Content.IE5\HPDNWUIK\errorPageStrings[1] 850 bytes File C:\Documents and Settings\Mark Thomson\Local Settings\Temporary Internet Files\Content.IE5\HPDNWUIK\favicon[1].ico 1150 bytes File C:\Documents and Settings\Mark Thomson\Local Settings\Temporary Internet Files\Content.IE5\HPDNWUIK\fmimg8215212947478227198_32x32[1].png 2522 bytes File C:\Documents and Settings\Mark Thomson\Local Settings\Temporary Internet Files\Content.IE5\HPDNWUIK\neoBrandNavSprite[1].png 972 bytes File C:\Documents and Settings\Mark Thomson\Local Settings\Temporary Internet Files\Content.IE5\IROSTIC0 0 bytes File C:\Documents and Settings\Mark Thomson\Local Settings\Temporary Internet Files\Content.IE5\IROSTIC0\%23159[1] 932 bytes File C:\Documents and Settings\Mark Thomson\Local Settings\Temporary Internet Files\Content.IE5\IROSTIC0\1352049[1].gif 43 bytes File C:\Documents and Settings\Mark Thomson\Local Settings\Temporary Internet Files\Content.IE5\IROSTIC0\1555[1].js 45 bytes File C:\Documents and Settings\Mark Thomson\Local Settings\Temporary Internet Files\Content.IE5\IROSTIC0\1581[1].js 45 bytes File C:\Documents and Settings\Mark Thomson\Local Settings\Temporary Internet Files\Content.IE5\IROSTIC0\191wiexm[1].png 1278 bytes File C:\Documents and Settings\Mark Thomson\Local Settings\Temporary Internet Files\Content.IE5\IROSTIC0\300x250_chicken[1].gif 21587 bytes File C:\Documents and Settings\Mark Thomson\Local Settings\Temporary Internet Files\Content.IE5\IROSTIC0\4248729692240a0f8bec299e86071b217df7_32x32[1].jpg 913 bytes File C:\Documents and Settings\Mark Thomson\Local Settings\Temporary Internet Files\Content.IE5\IROSTIC0\438946de92ec0a0f8bec0b9aafacf481447b_Panda_32x32_32x32[1].jpg 1060 bytes File C:\Documents and Settings\Mark Thomson\Local Settings\Temporary Internet Files\Content.IE5\IROSTIC0\iframe[1].htm 24881 bytes File C:\Documents and Settings\Mark Thomson\Local Settings\Temporary Internet Files\Content.IE5\IROSTIC0\iframe[2] 43 bytes File C:\Documents and Settings\Mark Thomson\Local Settings\Temporary Internet Files\Content.IE5\IROSTIC0\lclAdv[1].xml 6261 bytes File C:\Documents and Settings\Mark Thomson\Local Settings\Temporary Internet Files\Content.IE5\IROSTIC0\logo_top_alpha[1].png 4163 bytes File C:\Documents and Settings\Mark Thomson\Local Settings\Temporary Internet Files\Content.IE5\IROSTIC0\modalClose[1].gif 789 bytes File C:\Documents and Settings\Mark Thomson\Local Settings\Temporary Internet Files\Content.IE5\IROSTIC0\myListsSprite[1].png 7246 bytes File C:\Documents and Settings\Mark Thomson\Local Settings\Temporary Internet Files\Content.IE5\IROSTIC0\nav_logo14[1].png 29390 bytes File C:\Documents and Settings\Mark Thomson\Local Settings\Temporary Internet Files\Content.IE5\IROSTIC0\neoGo[1].png 914 bytes File C:\Documents and Settings\Mark Thomson\Local Settings\Temporary Internet Files\Content.IE5\IROSTIC0\neoPipe[1].gif 69 bytes File C:\Documents and Settings\Mark Thomson\Local Settings\Temporary Internet Files\Content.IE5\IROSTIC0\neoSearchBoxSprite[1].gif 2091 bytes File C:\Documents and Settings\Mark Thomson\Local Settings\Temporary Internet Files\Content.IE5\IROSTIC0\next[1].gif 527 bytes File C:\Documents and Settings\Mark Thomson\Local Settings\Temporary Internet Files\Content.IE5\IROSTIC0\Phishing_filter[1].png 5787 bytes File C:\Documents and Settings\Mark Thomson\Local Settings\Temporary Internet Files\Content.IE5\IROSTIC0\runonce3[1].htm 39137 bytes File C:\Documents and Settings\Mark Thomson\Local Settings\Temporary Internet Files\Content.IE5\IROSTIC0\search[1] 503 bytes File C:\Documents and Settings\Mark Thomson\Local Settings\Temporary Internet Files\Content.IE5\IROSTIC0\search[1].htm 45581 bytes File C:\Documents and Settings\Mark Thomson\Local Settings\Temporary Internet Files\Content.IE5\IROSTIC0\search[2] 549 bytes File C:\Documents and Settings\Mark Thomson\Local Settings\Temporary Internet Files\Content.IE5\IROSTIC0\select_arrows[1].png 1188 bytes File C:\Documents and Settings\Mark Thomson\Local Settings\Temporary Internet Files\Content.IE5\IROSTIC0\showad[1].js 2466 bytes File C:\Documents and Settings\Mark Thomson\Local Settings\Temporary Internet Files\Content.IE5\IROSTIC0\shuttleCock11x11[1].gif 534 bytes File C:\Documents and Settings\Mark Thomson\Local Settings\Temporary Internet Files\Content.IE5\IROSTIC0\siteId4hed[1].gif 2543 bytes File C:\Documents and Settings\Mark Thomson\Local Settings\Temporary Internet Files\Content.IE5\IROSTIC0\tips[1].png 1058 bytes File C:\Documents and Settings\Mark Thomson\Local Settings\Temporary Internet Files\Content.IE5\IROSTIC0\toolbarAccents[1].png 1074 bytes File C:\Documents and Settings\Mark Thomson\Local Settings\Temporary Internet Files\Content.IE5\IROSTIC0\ttPlus3000Install[1].png 1828 bytes File C:\Documents and Settings\Mark Thomson\Local Settings\Temporary Internet Files\Content.IE5\IROSTIC0\vertListLine[1].png 200 bytes File C:\Documents and Settings\Mark Thomson\Local Settings\Temporary Internet Files\Content.IE5\IROSTIC0\video_player_bg[1].png 1242 bytes File C:\Documents and Settings\Mark Thomson\Local Settings\Temporary Internet Files\Content.IE5\IROSTIC0\cnet_redball_blue_s-36x36[1].jpg 1770 bytes File C:\Documents and Settings\Mark Thomson\Local Settings\Temporary Internet Files\Content.IE5\IROSTIC0\Customer_experience[1].png 6482 bytes File C:\Documents and Settings\Mark Thomson\Local Settings\Temporary Internet Files\Content.IE5\IROSTIC0\dlNowGrn[1].gif 2219 bytes File C:\Documents and Settings\Mark Thomson\Local Settings\Temporary Internet Files\Content.IE5\IROSTIC0\dnserror[1] 6537 bytes File C:\Documents and Settings\Mark Thomson\Local Settings\Temporary Internet Files\Content.IE5\IROSTIC0\download.tron.title.detail2.compressed[1].js 50809 bytes File C:\Documents and Settings\Mark Thomson\Local Settings\Temporary Internet Files\Content.IE5\IROSTIC0\eye93f1j[1].png 245 bytes File C:\Documents and Settings\Mark Thomson\Local Settings\Temporary Internet Files\Content.IE5\IROSTIC0\favcenter[1] 3366 bytes File C:\Documents and Settings\Mark Thomson\Local Settings\Temporary Internet Files\Content.IE5\IROSTIC0\fmimg1476259598927388055_32x32[1].png 2914 bytes File C:\Documents and Settings\Mark Thomson\Local Settings\Temporary Internet Files\Content.IE5\IROSTIC0\fmimg1647876642801717240[1].png 656 bytes File C:\Documents and Settings\Mark Thomson\Local Settings\Temporary Internet Files\Content.IE5\IROSTIC0\fmimg4742092937227735543_32x32[1].png 2029 bytes File C:\Documents and Settings\Mark Thomson\Local Settings\Temporary Internet Files\Content.IE5\IROSTIC0\fmimg5773073424231643423[1].png 2213 bytes File C:\Documents and Settings\Mark Thomson\Local Settings\Temporary Internet Files\Content.IE5\IROSTIC0\fmimg6683867066697947049[1].png 1361 bytes File C:\Documents and Settings\Mark Thomson\Local Settings\Temporary Internet Files\Content.IE5\IROSTIC0\fmimg7538914062044406667[1].png 2250 bytes File C:\Documents and Settings\Mark Thomson\Local Settings\Temporary Internet Files\Content.IE5\IROSTIC0\fmimg8185537691731107617_32x32[1].png 521 bytes File C:\Documents and Settings\Mark Thomson\Local Settings\Temporary Internet Files\Content.IE5\IROSTIC0\Foreman_11095227_2915_winrar_foldertreeview_32x24[1].jpg 1180 bytes File C:\Documents and Settings\Mark Thomson\Local Settings\Temporary Internet Files\Content.IE5\IROSTIC0\4njhzfug[1].png 110 bytes File C:\Documents and Settings\Mark Thomson\Local Settings\Temporary Internet Files\Content.IE5\IROSTIC0\b[1].gif 43 bytes File C:\Documents and Settings\Mark Thomson\Local Settings\Temporary Internet Files\Content.IE5\IROSTIC0\fmimg2885718502175163287[1].png 2798 bytes File C:\Documents and Settings\Mark Thomson\Local Settings\Temporary Internet Files\Content.IE5\IROSTIC0\pt2[1].js 7614 bytes File C:\Documents and Settings\Mark Thomson\Local Settings\Temporary Internet Files\Content.IE5\IROSTIC0\ac[1].htm 1431 bytes File C:\Documents and Settings\Mark Thomson\Local Settings\Temporary Internet Files\Content.IE5\IROSTIC0\ac[2].htm 0 bytes File C:\Documents and Settings\Mark Thomson\Local Settings\Temporary Internet Files\Content.IE5\IROSTIC0\ac[3].htm 1146 bytes File C:\Documents and Settings\Mark Thomson\Local Settings\Temporary Internet Files\Content.IE5\IROSTIC0\ac[4].htm 1143 bytes File C:\Documents and Settings\Mark Thomson\Local Settings\Temporary Internet Files\Content.IE5\IROSTIC0\ac[5].htm 0 bytes File C:\Documents and Settings\Mark Thomson\Local Settings\Temporary Internet Files\Content.IE5\IROSTIC0\adinfo_top[1].gif 106 bytes File C:\Documents and Settings\Mark Thomson\Local Settings\Temporary Internet Files\Content.IE5\IROSTIC0\advanced-printing[1].png 7381 bytes File C:\Documents and Settings\Mark Thomson\Local Settings\Temporary Internet Files\Content.IE5\IROSTIC0\aro_blue[1].png 4731 bytes File C:\Documents and Settings\Mark Thomson\Local Settings\Temporary Internet Files\Content.IE5\IROSTIC0\avg_button[1].gif 5489 bytes File C:\Documents and Settings\Mark Thomson\Local Settings\Temporary Internet Files\Content.IE5\IROSTIC0\avg_free_stb_all_9_115_cnet[1].exe 2133536 bytes executable File C:\Documents and Settings\Mark Thomson\Local Settings\Temporary Internet Files\Content.IE5\IROSTIC0\background_gradient[1] 453 bytes File C:\Documents and Settings\Mark Thomson\Local Settings\Temporary Internet Files\Content.IE5\IROSTIC0\bg_def3fa_curve_leftbot[1].png 3318 bytes File C:\Documents and Settings\Mark Thomson\Local Settings\Temporary Internet Files\Content.IE5\IROSTIC0\bottom_basic[1].png 767 bytes File C:\Documents and Settings\Mark Thomson\Local Settings\Temporary Internet Files\Content.IE5\MC5I1U7U 0 bytes File C:\Documents and Settings\Mark Thomson\Local Settings\Temporary Internet Files\Content.IE5\WC9VT6MV 0 bytes File C:\Documents and Settings\Mark Thomson\Local Settings\Temporary Internet Files\Content.IE5\WC9VT6MV\google_co_uk[1].htm 13287 bytes File C:\Documents and Settings\Mark Thomson\Recent\D'Hond's Method.xls.lnk 1242 bytes File C:\Documents and Settings\Mark Thomson\Recent\Jane School.lnk 453 bytes ---- EOF - GMER 1.0.15 ----