dslreports logo
site
    All Forums Hot Topics Gallery
spc
Search Topic:
uniqs
15
share rss forum feed


LoPhatPhuud
Premium,VIP,MVM
join:2002-01-06
Albuquerque, NM
kudos:26
Reviews:
·Comcast

1 recommendation

reply to sirchief

Re: Problem with redirects

Download and run Sophos AntiRootkit. Post the log in this thread, even if nothing is found.

You find link(s) and instructions here:
»Security Cleanup FAQ »Rootkit Detection Applications
--
When angry count four; when very angry, swear.
Microsoft MVP/Consumer Security 2005-2011
Gladiator Security Forum


sirchief
Premium
join:2001-12-14
Cromwell, CT

Sophos Anti-Rootkit Version 1.5.20 (c) 2009 Sophos Plc
Started logging on 11/13/2012 at 17:05:24 PM
User "Steve" on computer "STEVE-PC"
Windows version 6.0 SP 2.0 Service Pack 2 build 6002 SM=0x300 PT=0x1 WOW64
Info: Starting registry scan.
Info: Starting disk scan of C: (NTFS).
Hidden: file C:\Users\Steve\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\HX1AA653\JusticeSystem;en=OrangeNewHavenConnecticut;at=JusticeSystem;at=CrimeLawandJustice;at=Lawyers;at=Judges;at=OrangeNewHavenConnecticut;u=sz%7C728x90!;ord=67631944[1].js
Hidden: file C:\Users\Steve\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\878QGNFY\=728x90;tile=1;ca=MedicalResearch;en=Stress;at=MedicalResearch;at=HealthandSafetyatSchool;at=Family;at=Stress;at=BehavioralConditions;u=sz_728x90!;ord=60304306[1].js
Hidden: file C:\Users\Steve\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\878QGNFY\80%5ED70010%5ED70024%5ED70094%5ED70112%5ED70116%5ED70195%5ED70513%5ED70675%5ED70758%5ED72008%5ED70688%5ED71585%5ED71622%5ED71628%5ED72297%5ED72665;ord=63825988[1].js
Hidden: file C:\Users\Steve\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\878QGNFY\der=coed;age=14u;skill=other;siteid=3061940;org=littleleaguebaseballandsoftball;fldr=cromwelllittleleague;stemp=rugbymatch;scat=league;stype=plus;ord=43689542;[1].js
Hidden: file C:\Users\Steve\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\0MPQHGZE\der=coed;age=14u;skill=other;siteid=3061940;org=littleleaguebaseballandsoftball;fldr=cromwelllittleleague;stemp=rugbymatch;scat=league;stype=plus;ord=43689542;[1].js
Hidden: file C:\Users\Steve\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\XLGWZX96\der=coed;age=14u;skill=other;siteid=3061940;org=littleleaguebaseballandsoftball;fldr=cromwelllittleleague;stemp=rugbymatch;scat=league;stype=plus;ord=18514894;[1].js
Hidden: file C:\Users\Steve\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\HX1AA653\der=coed;age=14u;skill=other;siteid=3061940;org=littleleaguebaseballandsoftball;fldr=cromwelllittleleague;stemp=rugbymatch;scat=league;stype=plus;ord=18514894;[1].js
Hidden: file C:\Users\Steve\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\0MPQHGZE\der=coed;age=14u;skill=other;siteid=3061940;org=littleleaguebaseballandsoftball;fldr=cromwelllittleleague;stemp=rugbymatch;scat=league;stype=plus;ord=57183217;[1].js
Hidden: file C:\Users\Steve\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\XLGWZX96\der=coed;age=14u;skill=other;siteid=3061940;org=littleleaguebaseballandsoftball;fldr=cromwelllittleleague;stemp=rugbymatch;scat=league;stype=plus;ord=57183217;[1].js
Info: Starting disk scan of D: (NTFS).
Stopped logging on 11/13/2012 at 18:09:02 PM

Sophos Anti-Rootkit Version 1.5.20 (c) 2009 Sophos Plc
Started logging on 11/13/2012 at 18:18:52 PM
User "Steve" on computer "STEVE-PC"
Windows version 6.0 SP 2.0 Service Pack 2 build 6002 SM=0x300 PT=0x1 WOW64
Info: Starting registry scan.
Info: Starting disk scan of C: (NTFS).
Hidden: file C:\Users\Steve\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\HX1AA653\JusticeSystem;en=OrangeNewHavenConnecticut;at=JusticeSystem;at=CrimeLawandJustice;at=Lawyers;at=Judges;at=OrangeNewHavenConnecticut;u=sz%7C728x90!;ord=67631944[1].js
Hidden: file C:\Users\Steve\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\878QGNFY\=728x90;tile=1;ca=MedicalResearch;en=Stress;at=MedicalResearch;at=HealthandSafetyatSchool;at=Family;at=Stress;at=BehavioralConditions;u=sz_728x90!;ord=60304306[1].js
Hidden: file C:\Users\Steve\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\HX1AA653\errorPageStrings[1]
Hidden: file C:\Users\Steve\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\878QGNFY\80%5ED70010%5ED70024%5ED70094%5ED70112%5ED70116%5ED70195%5ED70513%5ED70675%5ED70758%5ED72008%5ED70688%5ED71585%5ED71622%5ED71628%5ED72297%5ED72665;ord=63825988[1].js
Hidden: file C:\Users\Steve\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\878QGNFY\der=coed;age=14u;skill=other;siteid=3061940;org=littleleaguebaseballandsoftball;fldr=cromwelllittleleague;stemp=rugbymatch;scat=league;stype=plus;ord=43689542;[1].js
Hidden: file C:\Users\Steve\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\0MPQHGZE\der=coed;age=14u;skill=other;siteid=3061940;org=littleleaguebaseballandsoftball;fldr=cromwelllittleleague;stemp=rugbymatch;scat=league;stype=plus;ord=43689542;[1].js
Hidden: file C:\Users\Steve\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\XLGWZX96\der=coed;age=14u;skill=other;siteid=3061940;org=littleleaguebaseballandsoftball;fldr=cromwelllittleleague;stemp=rugbymatch;scat=league;stype=plus;ord=18514894;[1].js
Hidden: file C:\Users\Steve\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\HX1AA653\der=coed;age=14u;skill=other;siteid=3061940;org=littleleaguebaseballandsoftball;fldr=cromwelllittleleague;stemp=rugbymatch;scat=league;stype=plus;ord=18514894;[1].js
Hidden: file C:\Users\Steve\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\0MPQHGZE\der=coed;age=14u;skill=other;siteid=3061940;org=littleleaguebaseballandsoftball;fldr=cromwelllittleleague;stemp=rugbymatch;scat=league;stype=plus;ord=57183217;[1].js
Hidden: file C:\Users\Steve\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\XLGWZX96\der=coed;age=14u;skill=other;siteid=3061940;org=littleleaguebaseballandsoftball;fldr=cromwelllittleleague;stemp=rugbymatch;scat=league;stype=plus;ord=57183217;[1].js
Hidden: file C:\Users\Steve\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\878QGNFY\ErrorPageTemplate[1]
Hidden: file C:\Users\Steve\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\HX1AA653\errorPageStrings[2]
Hidden: file C:\Users\Steve\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\HX1AA653\httpErrorPagesScripts[1]
Info: Starting disk scan of D: (NTFS).
Stopped logging on 11/13/2012 at 19:22:58 PM

I couldn't select the "Running processes" at the beginning of the scan as it was greyed out.

Thank you again.


sirchief
Premium
join:2001-12-14
Cromwell, CT
Another log after another scan:

Sophos Anti-Rootkit Version 1.5.20 (c) 2009 Sophos Plc
Started logging on 11/13/2012 at 17:05:24 PM
User "Steve" on computer "STEVE-PC"
Windows version 6.0 SP 2.0 Service Pack 2 build 6002 SM=0x300 PT=0x1 WOW64
Info: Starting registry scan.
Info: Starting disk scan of C: (NTFS).
Hidden: file C:\Users\Steve\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\HX1AA653\JusticeSystem;en=OrangeNewHavenConnecticut;at=JusticeSystem;at=CrimeLawandJustice;at=Lawyers;at=Judges;at=OrangeNewHavenConnecticut;u=sz%7C728x90!;ord=67631944[1].js
Hidden: file C:\Users\Steve\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\878QGNFY\=728x90;tile=1;ca=MedicalResearch;en=Stress;at=MedicalResearch;at=HealthandSafetyatSchool;at=Family;at=Stress;at=BehavioralConditions;u=sz_728x90!;ord=60304306[1].js
Hidden: file C:\Users\Steve\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\878QGNFY\80%5ED70010%5ED70024%5ED70094%5ED70112%5ED70116%5ED70195%5ED70513%5ED70675%5ED70758%5ED72008%5ED70688%5ED71585%5ED71622%5ED71628%5ED72297%5ED72665;ord=63825988[1].js
Hidden: file C:\Users\Steve\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\878QGNFY\der=coed;age=14u;skill=other;siteid=3061940;org=littleleaguebaseballandsoftball;fldr=cromwelllittleleague;stemp=rugbymatch;scat=league;stype=plus;ord=43689542;[1].js
Hidden: file C:\Users\Steve\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\0MPQHGZE\der=coed;age=14u;skill=other;siteid=3061940;org=littleleaguebaseballandsoftball;fldr=cromwelllittleleague;stemp=rugbymatch;scat=league;stype=plus;ord=43689542;[1].js
Hidden: file C:\Users\Steve\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\XLGWZX96\der=coed;age=14u;skill=other;siteid=3061940;org=littleleaguebaseballandsoftball;fldr=cromwelllittleleague;stemp=rugbymatch;scat=league;stype=plus;ord=18514894;[1].js
Hidden: file C:\Users\Steve\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\HX1AA653\der=coed;age=14u;skill=other;siteid=3061940;org=littleleaguebaseballandsoftball;fldr=cromwelllittleleague;stemp=rugbymatch;scat=league;stype=plus;ord=18514894;[1].js
Hidden: file C:\Users\Steve\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\0MPQHGZE\der=coed;age=14u;skill=other;siteid=3061940;org=littleleaguebaseballandsoftball;fldr=cromwelllittleleague;stemp=rugbymatch;scat=league;stype=plus;ord=57183217;[1].js
Hidden: file C:\Users\Steve\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\XLGWZX96\der=coed;age=14u;skill=other;siteid=3061940;org=littleleaguebaseballandsoftball;fldr=cromwelllittleleague;stemp=rugbymatch;scat=league;stype=plus;ord=57183217;[1].js
Info: Starting disk scan of D: (NTFS).
Stopped logging on 11/13/2012 at 18:09:02 PM

Sophos Anti-Rootkit Version 1.5.20 (c) 2009 Sophos Plc
Started logging on 11/13/2012 at 18:18:52 PM
User "Steve" on computer "STEVE-PC"
Windows version 6.0 SP 2.0 Service Pack 2 build 6002 SM=0x300 PT=0x1 WOW64
Info: Starting registry scan.
Info: Starting disk scan of C: (NTFS).
Hidden: file C:\Users\Steve\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\HX1AA653\JusticeSystem;en=OrangeNewHavenConnecticut;at=JusticeSystem;at=CrimeLawandJustice;at=Lawyers;at=Judges;at=OrangeNewHavenConnecticut;u=sz%7C728x90!;ord=67631944[1].js
Hidden: file C:\Users\Steve\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\878QGNFY\=728x90;tile=1;ca=MedicalResearch;en=Stress;at=MedicalResearch;at=HealthandSafetyatSchool;at=Family;at=Stress;at=BehavioralConditions;u=sz_728x90!;ord=60304306[1].js
Hidden: file C:\Users\Steve\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\HX1AA653\errorPageStrings[1]
Hidden: file C:\Users\Steve\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\878QGNFY\80%5ED70010%5ED70024%5ED70094%5ED70112%5ED70116%5ED70195%5ED70513%5ED70675%5ED70758%5ED72008%5ED70688%5ED71585%5ED71622%5ED71628%5ED72297%5ED72665;ord=63825988[1].js
Hidden: file C:\Users\Steve\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\878QGNFY\der=coed;age=14u;skill=other;siteid=3061940;org=littleleaguebaseballandsoftball;fldr=cromwelllittleleague;stemp=rugbymatch;scat=league;stype=plus;ord=43689542;[1].js
Hidden: file C:\Users\Steve\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\0MPQHGZE\der=coed;age=14u;skill=other;siteid=3061940;org=littleleaguebaseballandsoftball;fldr=cromwelllittleleague;stemp=rugbymatch;scat=league;stype=plus;ord=43689542;[1].js
Hidden: file C:\Users\Steve\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\XLGWZX96\der=coed;age=14u;skill=other;siteid=3061940;org=littleleaguebaseballandsoftball;fldr=cromwelllittleleague;stemp=rugbymatch;scat=league;stype=plus;ord=18514894;[1].js
Hidden: file C:\Users\Steve\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\HX1AA653\der=coed;age=14u;skill=other;siteid=3061940;org=littleleaguebaseballandsoftball;fldr=cromwelllittleleague;stemp=rugbymatch;scat=league;stype=plus;ord=18514894;[1].js
Hidden: file C:\Users\Steve\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\0MPQHGZE\der=coed;age=14u;skill=other;siteid=3061940;org=littleleaguebaseballandsoftball;fldr=cromwelllittleleague;stemp=rugbymatch;scat=league;stype=plus;ord=57183217;[1].js
Hidden: file C:\Users\Steve\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\XLGWZX96\der=coed;age=14u;skill=other;siteid=3061940;org=littleleaguebaseballandsoftball;fldr=cromwelllittleleague;stemp=rugbymatch;scat=league;stype=plus;ord=57183217;[1].js
Hidden: file C:\Users\Steve\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\878QGNFY\ErrorPageTemplate[1]
Hidden: file C:\Users\Steve\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\HX1AA653\errorPageStrings[2]
Hidden: file C:\Users\Steve\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\HX1AA653\httpErrorPagesScripts[1]
Info: Starting disk scan of D: (NTFS).
Stopped logging on 11/13/2012 at 19:22:58 PM

Sophos Anti-Rootkit Version 1.5.20 (c) 2009 Sophos Plc
Started logging on 11/13/2012 at 20:56:48 PM
User "Steve" on computer "STEVE-PC"
Windows version 6.0 SP 2.0 Service Pack 2 build 6002 SM=0x300 PT=0x1 WOW64
Info: Starting registry scan.
Info: Starting disk scan of C: (NTFS).
Hidden: file C:\Users\Steve\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\XLGWZX96\aturette%252F%253Futm_source%253Dad_114403_23951_23951%2526utm_medium%253Dcpc%2526utm_campaign%253DAONdlUS_567665_279361%2526req%253D50a2f59e3b86101eb4c66e8b.1[1].js
Hidden: file C:\Users\Steve\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\HX1AA653\aturette%252F%253Futm_source%253Dad_114403_23951_23951%2526utm_medium%253Dcpc%2526utm_campaign%253DAONdlUS_567665_279361%2526req%253D50a2f59e3b86101eb4c66e8b.1[1].js
Hidden: file C:\Users\Steve\AppData\Roaming\Microsoft\Windows\Cookies\O3APR9U8.txt
Hidden: file C:\Users\Steve\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\QWB55JST\ADTECH;loc=100;cookie=info;target=_blank;key=;grp=[group];misc=7261ee7b78b34f69bad309fb84260781;rdclick=;kvuniqimp=7261ee7b78b34f69bad309fb84260781;kvafseq=1[1].js
Hidden: file C:\Users\Steve\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\G5O0656Y\ADTECH;loc=100;cookie=info;target=_blank;key=;grp=[group];misc=47dcdc56353b4f98bcafcd9bc1720420;rdclick=;kvuniqimp=47dcdc56353b4f98bcafcd9bc1720420;kvafseq=1[1].js
Hidden: file C:\Users\Steve\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\QWB55JST\ADTECH;loc=100;cookie=info;target=_blank;key=;grp=[group];misc=1b28e40c59aa4438b50086263b459f62;rdclick=;kvuniqimp=1b28e40c59aa4438b50086263b459f62;kvafseq=1[1].js
Hidden: file C:\Users\Steve\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\HX1AA653\ADTECH;loc=100;cookie=info;target=_blank;key=;grp=[group];misc=00b2188448bf44ef8737968d016340f7;rdclick=;kvuniqimp=00b2188448bf44ef8737968d016340f7;kvafseq=1[1].js
Hidden: file C:\Users\Steve\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\878QGNFY\dref=http%253A%252F%252Fwww.chinaontv.com%252Fcityfocus_videoplayer.php%253Fvid%253D6422%2526utm_source%253DADK%2526utm_medium%253DCPC%2526utm_campaign%253DADK[1].js
Hidden: file C:\Users\Steve\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\878QGNFY\AAAAQAAAAAAVVNEAKAAWAJSXAAAAAAAAgIAAQUAAIQABBLXnwAAAAA.%2526vpid%253D252%2526referrer%253Dhttp%25253A%25252F%25252Fwww.chinaontv.com%25252Fads%25252Far_160_600[1].js
Hidden: file C:\Users\Steve\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\0MPQHGZE\alm%2526beacon%253D1%2526guid%253D1352857681248b4a3a328b64d%2526ref%253Dhttp%25253A%25252F%25252Fapr.lijit.com%25252F%25252F%25252Fwww%25252Fdelivery%25252Ffpi[1].js
Hidden: file C:\Users\Steve\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\G5O0656Y\alm%2526beacon%253D1%2526guid%253D1352857681232b4e1412c8a82%2526ref%253Dhttp%25253A%25252F%25252Fapr.lijit.com%25252F%25252F%25252Fwww%25252Fdelivery%25252Ffpi[1].js
Hidden: file C:\Users\Steve\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\878QGNFY\dref=http%253A%252F%252Fwww.chinaontv.com%252Fcityfocus_videoplayer.php%253Fvid%253D6422%2526utm_source%253DADK%2526utm_medium%253DCPC%2526utm_campaign%253DADK[2].js
Hidden: file C:\Users\Steve\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\XLGWZX96\dref=http%253A%252F%252Fwww.chinaflix.com%252Fvideoplayer_cuisine.php%253Fpid%253D4884%2526utm_source%253DADK%2526utm_medium%253DCPC%2526utm_campaign%253DADK[1].js
Hidden: file C:\Users\Steve\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\XLGWZX96\dref=http%253A%252F%252Fwww.chinaflix.com%252Fvideoplayer_cuisine.php%253Fpid%253D4884%2526utm_source%253DADK%2526utm_medium%253DCPC%2526utm_campaign%253DADK[2].js
Hidden: file C:\Users\Steve\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\QWB55JST\QUAAIQADhPnAAAAAAA.%2526vpid%253D45%2526referrer%253Dhttp%25253A%25252F%25252Fmenshealthbase.com%25252Fwp-content%25252Fthemes%25252Fmenshealthbase%25252Fffiad[1].js
Hidden: file C:\Users\Steve\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\X2X4NI84\tm_source%253D65687978%2526utm_medium%253Dcpc%2526utm_campaign%253D65687978_574778_277603_%257B113643%257D_142300_none%2526click%253D50a2fab22ab6101eb4cdd2d1.1[1].js
Hidden: file C:\Users\Steve\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\HX1AA653\dref=http%253A%252F%252Fwww.chinaflix.com%252Fvideoplayer_cuisine.php%253Fpid%253D4884%2526utm_source%253DADK%2526utm_medium%253DCPC%2526utm_campaign%253DADK[1].js
Hidden: file C:\Users\Steve\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\X2X4NI84\d_wAAAAA.%2526vpid%253D45%2526referrer%253Dhttp%25253A%25252F%25252Fmenshealthbase.com%25252Fwp-content%25252Fthemes%25252Fmenshealthbase%25252Flib%25252Fffiad[1].js
Hidden: file C:\Users\Steve\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\878QGNFY\QUAAIQADhJKlQAAAAA.%2526vpid%253D45%2526referrer%253Dhttp%25253A%25252F%25252Fmenshealthbase.com%25252Fwp-content%25252Fthemes%25252Fmenshealthbase%25252Fffiad[1].js
Hidden: file C:\Users\Steve\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\0MPQHGZE\gCWgAkSAAAAAAAAgIAAQUAAIQAWhLboQAAAAA.%2526vpid%253D45%2526referrer%253Dhttp%25253A%25252F%25252Fapr.lijit.com%25252F%25252F%25252Fwww%25252Fdelivery%25252Ffpi[1].js
Hidden: file C:\Users\Steve\AppData\Roaming\Microsoft\Windows\Cookies\N715JPFT.txt
Hidden: file C:\Users\Steve\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\X2X4NI84\like[1].htm
Hidden: file C:\Users\Steve\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\XLGWZX96\![1].htm
Hidden: file C:\Users\Steve\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\G5O0656Y\like[1].htm
Hidden: file C:\Users\Steve\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\G5O0656Y\like[2].htm
Hidden: file C:\Users\Steve\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\1LW3CKR9\like[1].htm
Hidden: file C:\Users\Steve\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\1LW3CKR9\like[2].htm
Hidden: file C:\Users\Steve\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\0MPQHGZE\like[1].htm
Hidden: file C:\Users\Steve\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\0MPQHGZE\like[2].htm
Hidden: file C:\Users\Steve\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\0MPQHGZE\like[3].htm
Hidden: file C:\Users\Steve\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\X2X4NI84\like[2].htm
Hidden: file C:\Users\Steve\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\X2X4NI84\de[1].htm
Hidden: file C:\Users\Steve\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\0MPQHGZE\like[4].htm
Hidden: file C:\Users\Steve\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\1LW3CKR9\fpi[1].htm
Hidden: file C:\Users\Steve\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\QWB55JST\beacon[2].htm
Hidden: file C:\Users\Steve\AppData\Roaming\Microsoft\Windows\Cookies\5ZTIQM4U.txt
Hidden: file C:\Users\Steve\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\G5O0656Y\ddc[1].htm
Hidden: file C:\Users\Steve\AppData\Roaming\Microsoft\Windows\Cookies\8BZJ86H9.txt
Hidden: file C:\Users\Steve\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\1LW3CKR9\![1].htm
Hidden: file C:\Users\Steve\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\1LW3CKR9\ddc[1].htm
Hidden: file C:\Users\Steve\AppData\Roaming\Microsoft\Windows\Cookies\DY97OW69.txt
Hidden: file C:\Users\Steve\AppData\Roaming\Microsoft\Windows\Cookies\37ARWVRO.txt
Hidden: file C:\Users\Steve\AppData\Roaming\Microsoft\Windows\Cookies\HMAV4BQ8.txt
Hidden: file C:\Users\Steve\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\1LW3CKR9\likebox[1].htm
Hidden: file C:\Users\Steve\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\QWB55JST\52854036;loc=100;cookie=info;target=_blank;key=;grp=[group];misc=cb904f4a67da471c9fb79f99a0fddbe1;rdclick=;kvuniqimp=cb904f4a67da471c9fb79f99a0fddbe1;kvafseq=1[1].js
Hidden: file C:\Users\Steve\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\QWB55JST\52854037;loc=100;cookie=info;target=_blank;key=;grp=[group];misc=f60f92a8917c48f18fb86c55de53c4c2;rdclick=;kvuniqimp=f60f92a8917c48f18fb86c55de53c4c2;kvafseq=1[1].js
Hidden: file C:\Users\Steve\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\QWB55JST\ADTECH;loc=100;cookie=info;target=_blank;key=;grp=[group];misc=6295390025f04972b7e9566399426f9e;rdclick=;kvuniqimp=6295390025f04972b7e9566399426f9e;kvafseq=1[1].js
Hidden: file C:\Users\Steve\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\QWB55JST\ADTECH;loc=100;cookie=info;target=_blank;key=;grp=[group];misc=d2a8c5aeff2d4b9fbed9aef55f51f8a5;rdclick=;kvuniqimp=d2a8c5aeff2d4b9fbed9aef55f51f8a5;kvafseq=1[1].js
Hidden: file C:\Users\Steve\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\QWB55JST\dref=http%253A%252F%252Fwww.chinaflix.com%252Fvideoplayer_cuisine.php%253Fpid%253D4884%2526utm_source%253DADK%2526utm_medium%253DCPC%2526utm_campaign%253DADK[1].js
Hidden: file C:\Users\Steve\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\X2X4NI84\dref=http%253A%252F%252Fwww.chinaflix.com%252Fvideoplayer_cuisine.php%253Fpid%253D4884%2526utm_source%253DADK%2526utm_medium%253DCPC%2526utm_campaign%253DADK[1].js
Hidden: file C:\Users\Steve\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\QWB55JST\krwAAAAA.%2526vpid%253D45%2526referrer%253Dhttp%25253A%25252F%25252Fmenshealthbase.com%25252Fwp-content%25252Fthemes%25252Fmenshealthbase%25252Flib%25252Fffiad[1].js
Hidden: file C:\Users\Steve\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\X2X4NI84\IMQAAAAA.%2526vpid%253D45%2526referrer%253Dhttp%25253A%25252F%25252Fmenshealthbase.com%25252Fwp-content%25252Fthemes%25252Fmenshealthbase%25252Flib%25252Fffiad[1].js
Hidden: file C:\Users\Steve\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\1LW3CKR9\ttp%25253A%25252F%25252Fwww.filmannex.com%25252Fchannels%2526width%253D300%2526height%253D250%2526informer%253D7395367%2526uri%253Dhttp%253A%252F%252Fwww.lijit[1].js
Hidden: file C:\Users\Steve\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\1LW3CKR9\_kQAAAAA.%2526vpid%253D45%2526referrer%253Dhttp%25253A%25252F%25252Fmenshealthbase.com%25252Fwp-content%25252Fthemes%25252Fmenshealthbase%25252Flib%25252Fffiad[1].js
Hidden: file C:\Users\Steve\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\G5O0656Y\dref=http%253A%252F%252Fwww.chinaontv.com%252Fcityfocus_videoplayer.php%253Fvid%253D6422%2526utm_source%253DADK%2526utm_medium%253DCPC%2526utm_campaign%253DADK[1].js
Info: Starting disk scan of D: (NTFS).
Stopped logging on 11/13/2012 at 22:09:24 PM