Okay I got some more problems, spyware problems I think, not sure, but here you go, I already downloaded the Hijackthis in the other post that you guys solved, but I got another problem, so heres my log.
Logfile of HijackThis v1.99.1
Scan saved at 3:55:19 PM, on 9/14/2005
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\csrss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe
C:\Program Files\Common Files\Symantec Shared\SNDSrvc.exe
C:\Program Files\Common Files\Symantec Shared\SPBBC\SPBBCSvc.exe
C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Webroot\Spy Sweeper\SpySweeper.exe
C:\Program Files\Common Files\Symantec Shared\ccApp.exe
C:\Program Files\Common Files\Real\Update_OB\realsched.exe
C:\Program Files\America Online 9.0\waol.exe
C:\Program Files\Hewlett-Packard\Digital Imaging\bin\hpotdd01.exe
C:\Program Files\Common Files\AOL\ACS\AOLAcsd.exe
C:\Program Files\Common Files\AOL\TopSpeed\2.0\aoltsmon.exe
C:\Program Files\Norton AntiVirus\navapsvc.exe
C:\Program Files\Common Files\AOL\TopSpeed\2.0\aoltpspd.exe
C:\Program Files\Norton AntiVirus\IWP\NPFMntor.exe
C:\WINDOWS\system32\nvsvc32.exe
C:\WINDOWS\system32\pctspk.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Webroot\Spy Sweeper\WRSSSDK.exe
C:\Program Files\Common Files\Symantec Shared\CCPD-LC\symlcsvc.exe
C:\WINDOWS\system32\wdfmgr.exe
C:\WINDOWS\System32\alg.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\America Online 9.0\shellmon.exe
C:\Program Files\Xfire\Xfire.exe
C:\Program Files\MSN Messenger\msnmsgr.exe
C:\WINDOWS\system32\intmon.exe
C:\WINDOWS\system32\shnlog.exe
C:\Program Files\Messenger\msmsgs.exe
C:\WINDOWS\System32\rsvp.exe
C:\Documents and Settings\VP TP PP\Desktop\hijackthis\HijackThis.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = about:blank
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://www.security2k.net/search.php?qq=%1
O1 - Hosts: 207.68.172.246 msn.com
O1 - Hosts: 207.68.172.246 msn.com
O1 - Hosts: 207.68.172.246 msn.com
O1 - Hosts: 207.68.172.246 msn.com
O1 - Hosts: 207.68.172.246 msn.com
O1 - Hosts: 207.68.172.246 msn.com
O1 - Hosts: 207.68.172.246 msn.com
O1 - Hosts: 207.68.172.246 msn.com
O1 - Hosts: 207.68.172.246 msn.com
O1 - Hosts: 207.68.172.246 msn.com
O1 - Hosts: 207.68.172.246 msn.com
O2 - BHO: HP Class - {FFFFFFFF-FFFF-FFFF-FFFF-FFFFFFFFFFFA} - C:\WINDOWS\system32\hp970E.tmp
O3 - Toolbar: Norton AntiVirus - {42CDD1BF-3FFB-4238-8AD1-7859DF00B1D6} - C:\Program Files\Norton AntiVirus\NavShExt.dll
O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar2.dll
O4 - HKLM\..\Run: [SpySweeper] "C:\Program Files\Webroot\Spy Sweeper\SpySweeper.exe" /startintray
O4 - HKLM\..\Run: [ccApp] "C:\Program Files\Common Files\Symantec Shared\ccApp.exe"
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [Pure Networks Port Magic] "C:\PROGRA~1\PURENE~1\PORTMA~1\PortAOL.exe" -Run
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKCU\..\Run: [MsnMsgr] "C:\Program Files\MSN Messenger\MsnMsgr.Exe" /background
O4 - HKCU\..\Run: [AOL Fast Start] "C:\Program Files\America Online 9.0\AOL.EXE" -b
O4 - Global Startup: hpoddt01.exe.lnk = ?
O8 - Extra context menu item: &AOL Toolbar search - res://C:\Program Files\AOL Toolbar\toolbar.dll/SEARCH.HTML
O8 - Extra context menu item: &Google Search - res://c:\program files\google\GoogleToolbar2.dll/cmsearch.html
O8 - Extra context menu item: &Translate English Word - res://c:\program files\google\GoogleToolbar2.dll/cmwordtrans.html
O8 - Extra context menu item: Backward Links - res://c:\program files\google\GoogleToolbar2.dll/cmbacklinks.html
O8 - Extra context menu item: Cached Snapshot of Page - res://c:\program files\google\GoogleToolbar2.dll/cmcache.html
O8 - Extra context menu item: Similar Pages - res://c:\program files\google\GoogleToolbar2.dll/cmsimilar.html
O8 - Extra context menu item: Translate Page into English - res://c:\program files\google\GoogleToolbar2.dll/cmtrans.html
O9 - Extra button: Real.com - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - C:\WINDOWS\system32\Shdocvw.dll
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O12 - Plugin for .avi: C:\Program Files\Internet Explorer\PLUGINS\npqtplugin.dll
O16 - DPF: {04E214E5-63AF-4236-83C6-A7ADCBF9BD02} (HouseCall Control) - http://housecall60.trendmicro.com/housecall/xscan60.cab
O23 - Service: AOL Connectivity Service (AOL ACS) - America Online - C:\Program Files\Common Files\AOL\ACS\AOLAcsd.exe
O23 - Service: AOL TopSpeed Monitor (AOL TopSpeedMonitor) - America Online, Inc - C:\Program Files\Common Files\AOL\TopSpeed\2.0\aoltsmon.exe
O23 - Service: Symantec Event Manager (ccEvtMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
O23 - Service: Symantec Password Validation (ccPwdSvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccPwdSvc.exe
O23 - Service: Symantec Settings Manager (ccSetMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe
O23 - Service: Norton AntiVirus Auto-Protect Service (navapsvc) - Symantec Corporation - C:\Program Files\Norton AntiVirus\navapsvc.exe
O23 - Service: Norton AntiVirus Firewall Monitor Service (NPFMntor) - Symantec Corporation - C:\Program Files\Norton AntiVirus\IWP\NPFMntor.exe
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe
O23 - Service: PCTEL Speaker Phone (Pctspk) - PCtel, Inc. - C:\WINDOWS\system32\pctspk.exe
O23 - Service: Pml Driver HPZ12 - HP - C:\WINDOWS\system32\HPZipm12.exe
O23 - Service: SAVScan - Symantec Corporation - C:\Program Files\Norton AntiVirus\SAVScan.exe
O23 - Service: ScriptBlocking Service (SBService) - Symantec Corporation - C:\PROGRA~1\COMMON~1\SYMANT~1\SCRIPT~1\SBServ.exe
O23 - Service: Symantec Network Drivers Service (SNDSrvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\SNDSrvc.exe
O23 - Service: Symantec SPBBCSvc (SPBBCSvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\SPBBC\SPBBCSvc.exe
O23 - Service: Webroot Spy Sweeper Engine (svcWRSSSDK) - Webroot Software, Inc. - C:\Program Files\Webroot\Spy Sweeper\WRSSSDK.exe
O23 - Service: Symantec Core LC - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\CCPD-LC\symlcsvc.exe

Recommended Answers

All 23 Replies

There might be a moderator that responds to this, but I would recommend the following steps.

1)Download Microsoft Anti-spyware
2)Update Microsoft Anti-spyware
3)Restart your computer
4)Repeatedly strike f8 (to boot into safe mode)
5)Select safe mode
6)Run a scan in Microsoft Anti-spyware
--Optional--
7)Go to www.mozilla.org/firefox
8)Download firefox (It is more secure than Internet Explorer)

You could also do this with other spyware programs. I know that Ewido is popular with this crowd, as well as CCleaner.

www.ewido.com and www.filehippo.com

Happy hunting!

ShaneMcP

Okay, it wouldn't let me download it so...yeah...:/

Microsoft Anti-spyware? Try ewido and update it. Do a google search for microsoft antispyware download if you really want to get it, otherwise download Ewido, I've heard some good things.

ShaneMcP

If you have a pirated version of Windows (or your system fails the genuine Microsoft Windows test for whatever reason), you cannot download the program.

Hi,
Open a new file in NotePad, and copy the contents of the below "Quote" box:-

cd %windir%
cd system32
attrib -s -r -h hp970E.tmp
del hp970E.tmp
attrib -s -r -h intmon.exe
del intmon.exe
attrib -s -r -h shnlog.exe
del shnlog.exe

Go to File Menu (in NotePad) > Save As, and type the filename as Test1.bat and save the file. Exit from NotePad.


Boot the computer in safe mode:-
Restart (or switch ON) the PC. Then, keep tapping the F8 Key. From the menu that will be displayed, out of which choose Safe Mode and press Enter.


Run HijackThis and click Do only a System scan.
Then put a check mark infront of below listed entries:-

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = about:blank
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://www.security2k.net/search.php?qq=%1
O1 - Hosts: 207.68.172.246 msn.com
O1 - Hosts: 207.68.172.246 msn.com
O1 - Hosts: 207.68.172.246 msn.com
O1 - Hosts: 207.68.172.246 msn.com
O1 - Hosts: 207.68.172.246 msn.com
O1 - Hosts: 207.68.172.246 msn.com
O1 - Hosts: 207.68.172.246 msn.com
O1 - Hosts: 207.68.172.246 msn.com
O1 - Hosts: 207.68.172.246 msn.com
O1 - Hosts: 207.68.172.246 msn.com
O1 - Hosts: 207.68.172.246 msn.com
O2 - BHO: HP Class - {FFFFFFFF-FFFF-FFFF-FFFF-FFFFFFFFFFFA} - C:\WINDOWS\system32\hp970E.tmp

Close all other open programs except Hijackthis and click the button Fix Checked in HijackThis.


Double-click on the Test1.bat file that was created earlier. A DOS type window should open and close by itself.


Run WebRoot SpySweeper, click "Options" button. Here click "Sweep Options" tab, and here select all the Hard Disk Partitions. In the "Where to sweep" option box, select "Sweep all folders on the selected drives". In the "What to sweep" option box, make sure all the items are selected. Then click "Sweep Now" button and click "Start" and remove any malware it may find.


Run Ewido, click on the "Scanner" button in the left menu, then click on the "Complete System Scan" button.
If ewido finds anything, it will pop up a notification. You can select "Clean" and check the boxes "Perform action with all infections" and "Create encrypted backup" before clicking on OK.


Reboot to Normal Mode. Run HijackThis again, click Do a System scan and save log, and post the fresh log.

Alright, I did all that, that Ewido helped very well, I had 105 infected files, all trojan downloaders lol. ;) Heres my log. And, thanks again, Swatkat, you helped me very good, same with you Shane. Oh and is PSGuard bad for your computer? Cause everytime I usually get a virus or something it says download it. :?:
Logfile of HijackThis v1.99.1
Scan saved at 4:40:15 PM, on 9/15/2005
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\csrss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe
C:\Program Files\Common Files\Symantec Shared\SNDSrvc.exe
C:\Program Files\Common Files\Symantec Shared\SPBBC\SPBBCSvc.exe
C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Webroot\Spy Sweeper\SpySweeper.exe
C:\Program Files\Common Files\Symantec Shared\ccApp.exe
C:\Program Files\Common Files\Real\Update_OB\realsched.exe
C:\Program Files\America Online 9.0\waol.exe
C:\Program Files\Hewlett-Packard\Digital Imaging\bin\hpotdd01.exe
C:\Program Files\Common Files\AOL\ACS\AOLAcsd.exe
C:\Program Files\Common Files\AOL\TopSpeed\2.0\aoltsmon.exe
C:\Program Files\Common Files\AOL\TopSpeed\2.0\aoltpspd.exe
C:\Program Files\ewido\security suite\ewidoctrl.exe
C:\Program Files\ewido\security suite\ewidoguard.exe
C:\Program Files\Messenger\msmsgs.exe
C:\Program Files\Norton AntiVirus\navapsvc.exe
C:\Program Files\Norton AntiVirus\IWP\NPFMntor.exe
C:\WINDOWS\system32\nvsvc32.exe
C:\WINDOWS\system32\pctspk.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Webroot\Spy Sweeper\WRSSSDK.exe
C:\Program Files\Common Files\Symantec Shared\CCPD-LC\symlcsvc.exe
C:\WINDOWS\system32\wdfmgr.exe
C:\WINDOWS\System32\alg.exe
C:\Program Files\America Online 9.0\shellmon.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\wuauclt.exe
C:\Documents and Settings\VP TP PP\Desktop\hijackthis\HijackThis.exe

O3 - Toolbar: Norton AntiVirus - {42CDD1BF-3FFB-4238-8AD1-7859DF00B1D6} - C:\Program Files\Norton AntiVirus\NavShExt.dll
O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar2.dll
O4 - HKLM\..\Run: [SpySweeper] "C:\Program Files\Webroot\Spy Sweeper\SpySweeper.exe" /startintray
O4 - HKLM\..\Run: [ccApp] "C:\Program Files\Common Files\Symantec Shared\ccApp.exe"
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [Pure Networks Port Magic] "C:\PROGRA~1\PURENE~1\PORTMA~1\PortAOL.exe" -Run
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKCU\..\Run: [MsnMsgr] "C:\Program Files\MSN Messenger\MsnMsgr.Exe" /background
O4 - HKCU\..\Run: [AOL Fast Start] "C:\Program Files\America Online 9.0\AOL.EXE" -b
O4 - Global Startup: hpoddt01.exe.lnk = ?
O8 - Extra context menu item: &AOL Toolbar search - res://C:\Program Files\AOL Toolbar\toolbar.dll/SEARCH.HTML
O8 - Extra context menu item: &Google Search - res://c:\program files\google\GoogleToolbar2.dll/cmsearch.html
O8 - Extra context menu item: &Translate English Word - res://c:\program files\google\GoogleToolbar2.dll/cmwordtrans.html
O8 - Extra context menu item: Backward Links - res://c:\program files\google\GoogleToolbar2.dll/cmbacklinks.html
O8 - Extra context menu item: Cached Snapshot of Page - res://c:\program files\google\GoogleToolbar2.dll/cmcache.html
O8 - Extra context menu item: Similar Pages - res://c:\program files\google\GoogleToolbar2.dll/cmsimilar.html
O8 - Extra context menu item: Translate Page into English - res://c:\program files\google\GoogleToolbar2.dll/cmtrans.html
O9 - Extra button: Real.com - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - C:\WINDOWS\system32\Shdocvw.dll
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O12 - Plugin for .avi: C:\Program Files\Internet Explorer\PLUGINS\npqtplugin.dll
O16 - DPF: {04E214E5-63AF-4236-83C6-A7ADCBF9BD02} (HouseCall Control) - http://housecall60.trendmicro.com/housecall/xscan60.cab
O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) - http://go.microsoft.com/fwlink/?linkid=39204
O23 - Service: AOL Connectivity Service (AOL ACS) - America Online - C:\Program Files\Common Files\AOL\ACS\AOLAcsd.exe
O23 - Service: AOL TopSpeed Monitor (AOL TopSpeedMonitor) - America Online, Inc - C:\Program Files\Common Files\AOL\TopSpeed\2.0\aoltsmon.exe
O23 - Service: Symantec Event Manager (ccEvtMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
O23 - Service: Symantec Password Validation (ccPwdSvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccPwdSvc.exe
O23 - Service: Symantec Settings Manager (ccSetMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe
O23 - Service: ewido security suite control - ewido networks - C:\Program Files\ewido\security suite\ewidoctrl.exe
O23 - Service: ewido security suite guard - ewido networks - C:\Program Files\ewido\security suite\ewidoguard.exe
O23 - Service: Norton AntiVirus Auto-Protect Service (navapsvc) - Symantec Corporation - C:\Program Files\Norton AntiVirus\navapsvc.exe
O23 - Service: Norton AntiVirus Firewall Monitor Service (NPFMntor) - Symantec Corporation - C:\Program Files\Norton AntiVirus\IWP\NPFMntor.exe
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe
O23 - Service: PCTEL Speaker Phone (Pctspk) - PCtel, Inc. - C:\WINDOWS\system32\pctspk.exe
O23 - Service: Pml Driver HPZ12 - HP - C:\WINDOWS\system32\HPZipm12.exe
O23 - Service: SAVScan - Symantec Corporation - C:\Program Files\Norton AntiVirus\SAVScan.exe
O23 - Service: ScriptBlocking Service (SBService) - Symantec Corporation - C:\PROGRA~1\COMMON~1\SYMANT~1\SCRIPT~1\SBServ.exe
O23 - Service: Symantec Network Drivers Service (SNDSrvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\SNDSrvc.exe
O23 - Service: Symantec SPBBCSvc (SPBBCSvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\SPBBC\SPBBCSvc.exe
O23 - Service: Webroot Spy Sweeper Engine (svcWRSSSDK) - Webroot Software, Inc. - C:\Program Files\Webroot\Spy Sweeper\WRSSSDK.exe
O23 - Service: Symantec Core LC - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\CCPD-LC\symlcsvc.exe

Hi,
Log looks clean :) Do NOT install PSGuard, it's a spyware/adware.

For safer Internet browsing, you can use alternate browsers like Opera and/or FireFox. These browsers are safer, faster and feature-rich than Internet Explorer.

You can use SpywareBlaster to prevent the installation of Internet Explorer based spyware. It is a "run-once" tool, and need not be running in background. Once you install it, run it and click "Enable All Protection" and close it!

Also, dont forget to run CCleaner regularly to delete junk files, Temporary Internet files and other unnecessary files.

Okay, thanks but....everytime I logon to my computer now Norton deletes a virus called Backdoor.greybird, so I dunno whats going on, :!:

Hi,
Seems like there are some hidden "bad" files! Download WinPFind.Zip and completely extract it to a folder. Then run WinPFind.exe and click "Start Scan". When the scan is complete, click the "Copy to clipboard" button, to copy its log and then post it here.

Oh yeah, also, I run scans with Spysweeper to see if PSGUARD is gone, it's not, it keeps reappearing. Anything to help me with that? Heres the scan log.

WARNING: not all files found by this scanner are bad. Consult with a knowledgable person before proceeding.


If you see a message in the titlebar saying "Not responding..." you can ignore it. Windows somethimes displays this message due to the high volume of disk I/O. As long as the hard disk light is flashing, the program is still working properly.


»»»»»»»»»»»»»»»»» Windows OS and Versions »»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»
Product Name: Microsoft Windows XP    Current Build: Service Pack 2    Current Build Number: 2600
Internet Explorer Version: 6.0.2900.2180


»»»»»»»»»»»»»»»»» Checking Selected Standard Folders »»»»»»»»»»»»»»»»»»»»


Checking %SystemDrive% folder...


Checking %ProgramFilesDir% folder...


Checking %WinDir% folder...
PECompact2           8/29/2005 11:37:02 PM       15707121   C:\WINDOWS\lpt$vpn.809
qoologic             8/29/2005 11:37:02 PM       15707121   C:\WINDOWS\lpt$vpn.809
SAHAgent             8/29/2005 11:37:02 PM       15707121   C:\WINDOWS\lpt$vpn.809
UPX!                 5/3/2005 11:44:44 AM        25157      C:\WINDOWS\RMAgentOutput.dll
UPX!                 1/10/2005 4:17:24 PM        170053     C:\WINDOWS\tsc.exe
UPX!                 8/30/2005 3:27:30 PM        3072       C:\WINDOWS\uninstIU.exe
PECompact2           8/29/2005 11:37:02 PM       15707121   C:\WINDOWS\VPTNFILE.809
qoologic             8/29/2005 11:37:02 PM       15707121   C:\WINDOWS\VPTNFILE.809
SAHAgent             8/29/2005 11:37:02 PM       15707121   C:\WINDOWS\VPTNFILE.809
UPX!                 2/18/2005 6:40:14 PM        1044560    C:\WINDOWS\vsapi32.dll
aspack               2/18/2005 6:40:14 PM        1044560    C:\WINDOWS\vsapi32.dll


Checking %System% folder...
aspack               3/18/2005 5:19:58 PM        2337488    C:\WINDOWS\SYSTEM32\d3dx9_25.dll
PEC2                 8/23/2001 5:00:00 AM        41397      C:\WINDOWS\SYSTEM32\dfrg.msc
PTech                8/29/2005 1:27:12 PM        520968     C:\WINDOWS\SYSTEM32\LegitCheckControl.DLL
aspack               8/4/2004 12:56:38 AM        708096     C:\WINDOWS\SYSTEM32\ntdll.dll
Umonitor             8/4/2004 12:56:46 AM        657920     C:\WINDOWS\SYSTEM32\rasdlg.dll
winsync              8/23/2001 5:00:00 AM        1309184    C:\WINDOWS\SYSTEM32\wbdbase.deu


Checking %System%\Drivers folder and sub-folders...
PTech                8/3/2004 10:41:38 PM        1309184    C:\WINDOWS\SYSTEM32\drivers\mtlstrm.sys


Items found in C:\WINDOWS\SYSTEM32\drivers\etc\hosts



Checking the Windows folder and sub-folders for system and hidden files within the last 60 days...
9/17/2005 9:40:00 AM      S 2048       C:\WINDOWS\bootstat.dat
9/8/2005 10:27:54 AM     H  54156      C:\WINDOWS\QTFont.qfn
7/21/2005 7:48:26 PM    RH  749        C:\WINDOWS\WindowsShell.Manifest
7/21/2005 7:48:32 PM     H  65         C:\WINDOWS\Downloaded Program Files\desktop.ini
7/21/2005 7:49:18 PM     HS 67         C:\WINDOWS\Fonts\desktop.ini
8/8/2005 11:57:58 AM     H  10820      C:\WINDOWS\Help\update.GID
7/21/2005 7:48:34 PM     H  65         C:\WINDOWS\Offline Web Pages\desktop.ini
7/21/2005 7:48:54 PM    RHS 727        C:\WINDOWS\PCHealth\HelpCtr\PackageStore\package_1.cab
7/21/2005 7:48:54 PM    RHS 19854      C:\WINDOWS\PCHealth\HelpCtr\PackageStore\package_2.cab
7/21/2005 7:48:54 PM    RHS 243124     C:\WINDOWS\PCHealth\HelpCtr\PackageStore\package_3.cab
7/21/2005 8:14:16 PM    RHS 305145     C:\WINDOWS\PCHealth\HelpCtr\PackageStore\package_7.cab
7/21/2005 8:16:04 PM    RHS 68327      C:\WINDOWS\PCHealth\HelpCtr\PackageStore\package_8.cab
7/21/2005 7:49:56 PM     H  229376     C:\WINDOWS\repair\ntuser.dat
7/21/2005 7:48:26 PM    RH  749        C:\WINDOWS\system32\cdplayer.exe.manifest
7/21/2005 7:48:32 PM    RH  488        C:\WINDOWS\system32\logonui.exe.manifest
7/21/2005 7:48:26 PM    RH  749        C:\WINDOWS\system32\ncpa.cpl.manifest
7/21/2005 7:48:26 PM    RH  749        C:\WINDOWS\system32\nwc.cpl.manifest
7/21/2005 7:48:26 PM    RH  749        C:\WINDOWS\system32\sapi.cpl.manifest
7/21/2005 7:48:32 PM    RH  488        C:\WINDOWS\system32\WindowsLogon.manifest
7/21/2005 7:48:26 PM    RH  749        C:\WINDOWS\system32\wuaucpl.cpl.manifest
9/17/2005 9:41:30 AM     H  1024       C:\WINDOWS\system32\config\default.LOG
9/17/2005 9:40:04 AM     H  1024       C:\WINDOWS\system32\config\SAM.LOG
9/17/2005 9:40:54 AM     H  1024       C:\WINDOWS\system32\config\SECURITY.LOG
9/17/2005 9:50:02 AM     H  1024       C:\WINDOWS\system32\config\software.LOG
9/17/2005 9:41:42 AM     H  1024       C:\WINDOWS\system32\config\system.LOG
7/21/2005 12:34:02 PM    H  1024       C:\WINDOWS\system32\config\TempKey.LOG
7/21/2005 12:34:02 PM    H  1024       C:\WINDOWS\system32\config\userdiff.LOG
7/21/2005 12:37:36 PM    HS 62         C:\WINDOWS\system32\config\systemprofile\Application Data\desktop.ini
7/21/2005 8:16:04 PM      S 558        C:\WINDOWS\system32\config\systemprofile\Application Data\Microsoft\CryptnetUrlCache\Content\E6024EAC88E6B6165D49FE3C95ADD735
7/21/2005 8:16:04 PM      S 144        C:\WINDOWS\system32\config\systemprofile\Application Data\Microsoft\CryptnetUrlCache\MetaData\E6024EAC88E6B6165D49FE3C95ADD735
7/21/2005 12:37:36 PM    HS 62         C:\WINDOWS\system32\config\systemprofile\Local Settings\desktop.ini
7/21/2005 7:48:58 PM     HS 113        C:\WINDOWS\system32\config\systemprofile\Local Settings\History\desktop.ini
7/21/2005 7:48:58 PM     HS 113        C:\WINDOWS\system32\config\systemprofile\Local Settings\History\History.IE5\desktop.ini
7/21/2005 7:48:58 PM     HS 67         C:\WINDOWS\system32\config\systemprofile\Local Settings\Temporary Internet Files\desktop.ini
7/21/2005 7:48:58 PM     HS 67         C:\WINDOWS\system32\config\systemprofile\Local Settings\Temporary Internet Files\Content.IE5\desktop.ini
7/21/2005 7:48:58 PM     HS 67         C:\WINDOWS\system32\config\systemprofile\Local Settings\Temporary Internet Files\Content.IE5\C9OHB233\desktop.ini
7/21/2005 7:48:58 PM     HS 67         C:\WINDOWS\system32\config\systemprofile\Local Settings\Temporary Internet Files\Content.IE5\GXIJSHIF\desktop.ini
7/21/2005 7:48:58 PM     HS 67         C:\WINDOWS\system32\config\systemprofile\Local Settings\Temporary Internet Files\Content.IE5\QFAI2UBJ\desktop.ini
7/21/2005 7:48:58 PM     HS 67         C:\WINDOWS\system32\config\systemprofile\Local Settings\Temporary Internet Files\Content.IE5\ULTDCX7Y\desktop.ini
7/21/2005 7:48:34 PM     HS 181        C:\WINDOWS\system32\config\systemprofile\SendTo\desktop.ini
7/21/2005 12:37:36 PM    HS 62         C:\WINDOWS\system32\config\systemprofile\Start Menu\desktop.ini
7/21/2005 7:49:50 PM     HS 206        C:\WINDOWS\system32\config\systemprofile\Start Menu\Programs\desktop.ini
7/21/2005 7:49:50 PM     HS 482        C:\WINDOWS\system32\config\systemprofile\Start Menu\Programs\Accessories\desktop.ini
7/21/2005 7:49:50 PM     HS 348        C:\WINDOWS\system32\config\systemprofile\Start Menu\Programs\Accessories\Accessibility\desktop.ini
7/21/2005 7:49:50 PM     HS 84         C:\WINDOWS\system32\config\systemprofile\Start Menu\Programs\Accessories\Entertainment\desktop.ini
7/21/2005 7:49:50 PM     HS 84         C:\WINDOWS\system32\config\systemprofile\Start Menu\Programs\Startup\desktop.ini
7/21/2005 8:29:14 PM     HS 388        C:\WINDOWS\system32\Microsoft\Protect\S-1-5-18\User\d9db54d4-1353-4451-b809-b80755aa36be
7/21/2005 8:29:14 PM     HS 24         C:\WINDOWS\system32\Microsoft\Protect\S-1-5-18\User\Preferred
9/17/2005 9:40:06 AM     H  6          C:\WINDOWS\Tasks\SA.DAT
9/17/2005 9:41:22 AM     H  0          C:\WINDOWS\Temp\CS0010814E-ADE7-425F-9381-9E0EE0A174B9.tmp
8/30/2005 4:03:32 PM     H  10         C:\WINDOWS\Temp\CS0017C4CC-4583-4802-B920-121022840F4F.tmp
8/21/2005 8:29:14 PM     H  726        C:\WINDOWS\Temp\CS00256776-71DF-4F50-AF3E-F40688ECE4DB.tmp
8/3/2005 11:55:26 AM     H  10         C:\WINDOWS\Temp\CS00546EE6-CF29-4070-B1E6-405169F0E943.tmp
8/22/2005 12:29:02 AM    H  10         C:\WINDOWS\Temp\CS008109FB-B760-448D-9CA8-7B4711F71A2C.tmp
8/13/2005 11:56:22 AM    H  48         C:\WINDOWS\Temp\CS0082805C-E0DA-41F2-9FF2-0CAA12E0703C.tmp
8/22/2005 12:29:02 AM    H  10         C:\WINDOWS\Temp\CS011083A8-1E1C-411F-89BD-ED21725EE864.tmp
8/1/2005 8:52:54 PM      H  100        C:\WINDOWS\Temp\CS0140750B-ACED-4915-9979-61C47FDE79A3.tmp
8/1/2005 1:44:36 AM      H  3411       C:\WINDOWS\Temp\CS01EC81FA-B531-4CB9-BE03-4C0951E51DFA.tmp
8/15/2005 4:31:44 AM     H  1350       C:\WINDOWS\Temp\CS01ED8725-6AD8-4A0A-AD48-9B1681D90B5B.tmp
8/22/2005 12:29:02 AM    H  10         C:\WINDOWS\Temp\CS01FB1A79-D3DF-4BC6-94AA-15336BD0200D.tmp
7/27/2005 1:47:24 PM     H  10         C:\WINDOWS\Temp\CS01FD7266-2CE6-44FF-BC44-879F56917517.tmp
8/1/2005 8:52:54 PM      H  10         C:\WINDOWS\Temp\CS0206A474-F6A4-4AA6-B284-BAF00864C374.tmp
8/3/2005 11:55:06 AM     H  1227876    C:\WINDOWS\Temp\CS02332A92-541F-4117-A7BA-94CC1CE9B281.tmp
9/14/2005 7:39:30 AM     H  10         C:\WINDOWS\Temp\CS02391E08-AF0B-4F7F-A835-F6FAA96AA46A.tmp
8/22/2005 12:29:02 AM    H  10         C:\WINDOWS\Temp\CS02520C0D-7060-47A8-8462-AF54769AB268.tmp
7/27/2005 1:47:24 PM     H  124        C:\WINDOWS\Temp\CS0269FE86-92A1-4BB4-B56F-350D1E8CB0C2.tmp
8/22/2005 1:47:48 AM     H  3411       C:\WINDOWS\Temp\CS026DDCBF-D5D4-4D8F-8727-E2EE1D69D5A4.tmp
8/7/2005 1:22:16 AM      H  1227876    C:\WINDOWS\Temp\CS0283E76C-6306-4D76-BDBB-8D12997DCF29.tmp
8/6/2005 11:34:08 AM     H  10         C:\WINDOWS\Temp\CS02B05021-877C-4268-873C-84483D8BC287.tmp
8/30/2005 7:18:04 PM     H  32         C:\WINDOWS\Temp\CS02C64254-D0EC-42A6-BB57-51EF513F68E4.tmp
8/6/2005 11:02:42 AM     H  619544     C:\WINDOWS\Temp\CS03379701-D835-4F33-924E-6D667AE266E3.tmp
8/6/2005 11:34:08 AM     H  10         C:\WINDOWS\Temp\CS0376ACCB-506F-4E48-8279-072D4FACAA52.tmp
7/27/2005 1:47:22 PM     H  30         C:\WINDOWS\Temp\CS03976415-25FA-476B-B380-033E3D274B7A.tmp
8/15/2005 4:32:00 AM     H  48         C:\WINDOWS\Temp\CS039A5384-5179-4DB6-9233-18A88B45D108.tmp
8/15/2005 4:32:00 AM     H  10         C:\WINDOWS\Temp\CS03BDEE3F-D4FD-47D1-AE57-76ADE8C4F820.tmp
8/26/2005 2:56:02 PM     H  1324922    C:\WINDOWS\Temp\CS040B4839-0AEB-457B-B747-928108834D61.tmp
8/6/2005 11:03:00 AM     H  10         C:\WINDOWS\Temp\CS04119D49-E62F-442A-B0A0-94A73C759B8B.tmp
7/27/2005 6:47:44 AM     H  37532      C:\WINDOWS\Temp\CS04146F24-F2B7-4DF3-A613-C64881BF5681.tmp
8/8/2005 7:46:02 PM      H  162        C:\WINDOWS\Temp\CS0416CB9F-5501-48DE-9066-2BDA6149B4D2.tmp
9/17/2005 9:41:04 AM     H  0          C:\WINDOWS\Temp\CS0434026A-72A7-4F28-BC45-81817BAC42A3.tmp
8/29/2005 4:23:02 PM     H  2018310    C:\WINDOWS\Temp\CS043CA5FF-D537-4605-B356-65B54F964EE8.tmp
8/7/2005 1:22:16 AM      H  1030002    C:\WINDOWS\Temp\CS043EE9C0-CD6D-4F49-947D-9756A09F311C.tmp
8/29/2005 4:23:22 PM     H  330388     C:\WINDOWS\Temp\CS0559175B-8F2D-4F69-A6A4-668DBA4712C8.tmp
9/9/2005 3:54:20 PM      H  10         C:\WINDOWS\Temp\CS056304CD-90AD-4934-B602-EB5D8DFE043C.tmp
8/19/2005 7:43:30 AM     H  10         C:\WINDOWS\Temp\CS056C06C3-D0F9-4C0E-8A15-5D6A4B2E59BD.tmp
8/6/2005 11:03:00 AM     H  124        C:\WINDOWS\Temp\CS05848768-0DE8-4B72-9EB4-25DF6E6F69E3.tmp
8/6/2005 11:03:00 AM     H  10         C:\WINDOWS\Temp\CS05D89398-F28B-4B50-A710-83BABD7E9BF2.tmp
9/17/2005 9:41:04 AM     H  0          C:\WINDOWS\Temp\CS06221E3B-54F7-4655-AA48-B3211D4B2B29.tmp
8/8/2005 7:46:04 PM      H  10         C:\WINDOWS\Temp\CS0628CFCC-6156-49A2-B476-56F51C10FD2F.tmp
8/1/2005 8:52:54 PM      H  10         C:\WINDOWS\Temp\CS06432D10-4200-40DD-979C-F195C7462334.tmp
8/1/2005 1:53:08 PM      H  240        C:\WINDOWS\Temp\CS06C9BE59-D88E-493B-A3AB-B1E1144854BD.tmp
8/22/2005 12:29:02 AM    H  330        C:\WINDOWS\Temp\CS0703551F-3101-4AA2-AA96-2A0DA56FAF8E.tmp
8/22/2005 1:47:48 AM     H  1030002    C:\WINDOWS\Temp\CS076B7B66-E4C5-46F7-AA36-E4496B1E8BAB.tmp
9/9/2005 3:54:20 PM      H  10         C:\WINDOWS\Temp\CS077AC0EB-382C-4E3F-8A53-4307B704A0CC.tmp
7/27/2005 1:47:22 PM     H  10         C:\WINDOWS\Temp\CS07B83843-8207-40C9-83DB-4200DCC91215.tmp
8/22/2005 2:47:24 AM     H  68         C:\WINDOWS\Temp\CS07C730E3-01A9-43C3-BDDD-EFECCC7D36F2.tmp
7/27/2005 1:47:22 PM     H  664        C:\WINDOWS\Temp\CS07DD9F82-5C39-4D48-89D7-D2D22D983C0A.tmp
8/22/2005 12:29:02 AM    H  10         C:\WINDOWS\Temp\CS07E4E687-100B-417B-B881-97056FF93CF8.tmp
8/13/2005 11:56:20 AM    H  568        C:\WINDOWS\Temp\CS083E4DEA-8567-4501-B19E-1749C46D62CA.tmp
8/6/2005 11:02:42 AM     H  126        C:\WINDOWS\Temp\CS084324FC-49F8-450A-B4ED-49A25E81F4A0.tmp
8/3/2005 11:55:06 AM     H  726        C:\WINDOWS\Temp\CS08627E9A-AA89-43C1-A7CF-5BACD79C5DC7.tmp
8/19/2005 7:43:30 AM     H  136        C:\WINDOWS\Temp\CS087198EF-E3D8-4965-8F98-734C20488211.tmp
8/8/2005 10:22:08 AM     H  414        C:\WINDOWS\Temp\CS0877E2F8-A57E-41F5-AE2B-CF40DA5F14BB.tmp
8/3/2005 11:55:26 AM     H  10         C:\WINDOWS\Temp\CS0879B04F-2FD6-405F-9381-B827B47BE981.tmp
8/1/2005 3:44:16 AM      H  10         C:\WINDOWS\Temp\CS0895BB10-292F-46A6-854A-FC6EACB28422.tmp
9/14/2005 7:39:32 AM     H  120        C:\WINDOWS\Temp\CS08C4A69D-7810-419D-858F-C5B8B622CD2B.tmp
8/30/2005 4:03:32 PM     H  102        C:\WINDOWS\Temp\CS08DFF4D1-B000-4968-A608-202026A67747.tmp
8/8/2005 7:46:02 PM      H  10         C:\WINDOWS\Temp\CS08E92913-D942-4708-80D0-A905D6B5C451.tmp
8/6/2005 11:34:08 AM     H  102        C:\WINDOWS\Temp\CS094590A4-DABE-430D-8238-259B93773EAD.tmp
8/19/2005 4:43:58 AM     H  1030002    C:\WINDOWS\Temp\CS09CDEFB1-B9D5-4A96-91D3-D74F5D29EC67.tmp
8/19/2005 4:44:18 AM     H  81290      C:\WINDOWS\Temp\CS09F59036-1BF4-41F5-B488-73CAC2C0F812.tmp
8/15/2005 4:32:00 AM     H  10         C:\WINDOWS\Temp\CS0A37F649-CAC0-4C4C-92B9-3D401D22418F.tmp
7/27/2005 1:47:22 PM     H  312        C:\WINDOWS\Temp\CS0A3B95A8-074E-40D9-A574-22CE6BE93E5E.tmp
8/22/2005 2:47:24 AM     H  10         C:\WINDOWS\Temp\CS0A55A65C-CBE9-4D70-99FC-132C3CB3A003.tmp
8/6/2005 11:03:00 AM     H  10         C:\WINDOWS\Temp\CS0ADFA148-3644-42A2-8C83-E20E3EB6F8AA.tmp
7/27/2005 1:47:22 PM     H  10         C:\WINDOWS\Temp\CS0B1F74B3-8773-4A99-960A-C10AF2783417.tmp
8/6/2005 11:34:12 AM     H  81290      C:\WINDOWS\Temp\CS0B37D192-0519-4E2F-8B4B-135089E3C77F.tmp
9/14/2005 7:39:30 AM     H  10         C:\WINDOWS\Temp\CS0B87A764-093F-4662-AEF6-8C29FFB957DD.tmp
8/3/2005 11:55:26 AM     H  124        C:\WINDOWS\Temp\CS0BF69784-F54D-4305-9D4C-C34B0A1CB8A0.tmp
8/8/2005 7:46:02 PM      H  68         C:\WINDOWS\Temp\CS0C340A61-2C06-4399-853C-4DC19EA07B62.tmp
9/9/2005 3:54:20 PM      H  96         C:\WINDOWS\Temp\CS0C4D7229-52A6-43DB-9264-4A4644FD6CA1.tmp
8/26/2005 11:55:58 PM    H  10         C:\WINDOWS\Temp\CS0C568DB1-B942-42B9-B53B-A9B1455F5712.tmp
8/26/2005 11:55:58 PM    H  162        C:\WINDOWS\Temp\CS0C570CF5-B08B-4B0D-8B84-F1CEDFC94F81.tmp
9/9/2005 3:54:20 PM      H  10         C:\WINDOWS\Temp\CS0C6597BE-D017-49D6-B964-BBAB908817DD.tmp
8/26/2005 11:55:58 PM    H  10         C:\WINDOWS\Temp\CS0C9C4295-3358-4408-B9B1-FEEA0D682DF3.tmp
9/14/2005 7:39:32 AM     H  48         C:\WINDOWS\Temp\CS0CA06E82-A468-4AD3-8EC0-3ACEB86DE353.tmp
9/15/2005 3:29:34 PM     H  80814      C:\WINDOWS\Temp\CS0CCA5558-0DF1-40E6-A0A1-51D2FC244F26.tmp
8/19/2005 7:43:30 AM     H  10         C:\WINDOWS\Temp\CS0CF249F2-2C92-43E7-B6BE-B03EA78BF6EE.tmp
8/22/2005 1:47:48 AM     H  37532      C:\WINDOWS\Temp\CS0D09DBB1-B468-4B62-ADFC-9B02B6F27962.tmp
9/9/2005 3:54:20 PM      H  48         C:\WINDOWS\Temp\CS0D0C8424-2067-443D-9B62-9875AD7B7BF7.tmp
8/1/2005 8:52:54 PM      H  10         C:\WINDOWS\Temp\CS0D4717BF-26FE-4B17-A1CF-EC8D454F0DCD.tmp
8/26/2005 2:56:24 PM     H  69542      C:\WINDOWS\Temp\CS0D6FCF49-8A09-4A93-966F-37C62E3CC60A.tmp
8/6/2005 11:34:08 AM     H  114        C:\WINDOWS\Temp\CS0D8E2810-EF3A-4A0C-8AA3-455756EED2E8.tmp
8/22/2005 12:29:02 AM    H  10         C:\WINDOWS\Temp\CS0D8E4AAF-359D-488F-8ABA-F51E12B74CD5.tmp
8/6/2005 11:34:08 AM     H  600        C:\WINDOWS\Temp\CS0D982592-E9C8-48EB-9DCF-ADF4D0554B04.tmp
8/22/2005 12:29:02 AM    H  10         C:\WINDOWS\Temp\CS0DEDD486-1CC5-4E9A-B420-3CD7B4F3936A.tmp
8/6/2005 11:34:08 AM     H  342        C:\WINDOWS\Temp\CS0DEE66AC-FDCF-41D5-A0A2-1E6A8BD98F2C.tmp
9/15/2005 3:28:14 PM     H  30         C:\WINDOWS\Temp\CS0DF75249-D81B-4B1F-9994-F02CF2BDAB66.tmp
8/26/2005 11:55:58 PM    H  10         C:\WINDOWS\Temp\CS0E0B2D37-D386-4D5D-8B29-0FB7BCBC20AD.tmp
8/3/2005 11:55:26 AM     H  48         C:\WINDOWS\Temp\CS0E215A1F-03F8-43A3-8863-FCC68649F4B9.tmp
9/17/2005 9:41:22 AM     H  0          C:\WINDOWS\Temp\CS0EC880C9-D393-4EFC-8741-F07733DA19C0.tmp
8/1/2005 1:53:08 PM      H  5568       C:\WINDOWS\Temp\CS0ED458E1-76EF-46F4-A428-A77149791C94.tmp
8/21/2005 8:29:14 PM     H  168        C:\WINDOWS\Temp\CS0F36A3AC-A501-4B0F-91A1-F543D99C701A.tmp
8/29/2005 6:22:44 PM     H  10         C:\WINDOWS\Temp\CS0F5888AA-E117-4506-9B8E-79DA2344CCE5.tmp
8/19/2005 7:43:30 AM     H  10         C:\WINDOWS\Temp\CS0F847589-BE3E-4DE9-8902-0C4BA509A0A1.tmp
8/22/2005 12:29:02 AM    H  102        C:\WINDOWS\Temp\CS0FAA4E5F-0702-4897-AD84-D3C7ACE73F54.tmp
7/27/2005 1:47:22 PM     H  10         C:\WINDOWS\Temp\CS0FAA650A-68D7-4E24-BD1D-DBA8722ED20B.tmp
7/27/2005 6:47:44 AM     H  1350       C:\WINDOWS\Temp\CS0FC9135A-7DEA-4EE2-8948-FC258FBDB3C2.tmp
8/26/2005 11:55:58 PM    H  500        C:\WINDOWS\Temp\CS0FCA9EE0-B6CE-4364-B4B0-B90888EAE147.tmp
8/26/2005 11:55:58 PM    H  414        C:\WINDOWS\Temp\CS100E21F3-745F-480C-90BA-C6AF8DBE897F.tmp
8/7/2005 1:22:38 AM      H  330388     C:\WINDOWS\Temp\CS10205742-1D90-45F3-B1B9-CCB31CB3CA3E.tmp
8/1/2005 1:53:08 PM      H  1324922    C:\WINDOWS\Temp\CS1047C8D2-DBD1-43CD-8136-430B5133472B.tmp
8/8/2005 10:22:08 AM     H  10         C:\WINDOWS\Temp\CS106802D6-FE8A-4F17-8639-1820624EC30E.tmp
9/14/2005 7:39:32 AM     H  10         C:\WINDOWS\Temp\CS10709F5F-FA3E-4A2F-B7C9-E7BD81194C7F.tmp
8/29/2005 6:22:44 PM     H  14         C:\WINDOWS\Temp\CS1083A931-27CE-4930-AAE3-A5F6E16C8A62.tmp
9/14/2005 7:39:32 AM     H  100        C:\WINDOWS\Temp\CS109F1B99-8B0D-4290-9275-6C122DF891DD.tmp
9/9/2005 2:54:50 PM      H  619544     C:\WINDOWS\Temp\CS10A227E2-925D-471F-8CE0-79C6945C68F8.tmp
8/6/2005 11:34:08 AM     H  124        C:\WINDOWS\Temp\CS10E433D3-CAAA-41DD-87A7-DF9728897C7A.tmp
9/9/2005 2:54:50 PM      H  32         C:\WINDOWS\Temp\CS10F25D67-BAD2-4D0B-8E77-50C68E663C78.tmp
8/13/2005 11:56:22 AM    H  10         C:\WINDOWS\Temp\CS1103D2E6-F99B-4A1C-B067-6CF6741EEA3D.tmp
9/17/2005 9:41:04 AM     H  0          C:\WINDOWS\Temp\CS11433D32-E8F8-43B0-83AF-CB191E2D7343.tmp
8/6/2005 11:34:08 AM     H  10         C:\WINDOWS\Temp\CS11483648-1323-4A6B-9803-6C129B33E222.tmp
8/29/2005 6:22:44 PM     H  10         C:\WINDOWS\Temp\CS1151C5E4-8BF6-42E4-A271-8AAE393219CC.tmp
8/15/2005 4:31:44 AM     H  1227876    C:\WINDOWS\Temp\CS1162E562-8111-44B8-A9DB-CCF68B7CE15A.tmp
8/19/2005 7:43:30 AM     H  100        C:\WINDOWS\Temp\CS11B1D782-4C06-4D1B-A742-25B4A028885B.tmp
8/1/2005 8:52:54 PM      H  10         C:\WINDOWS\Temp\CS1220453E-7AED-4AA5-822B-90F5FF4EE943.tmp
8/19/2005 7:43:30 AM     H  10         C:\WINDOWS\Temp\CS1257CD96-96A0-4DFE-BB5F-946BDBF5A683.tmp
7/27/2005 6:47:44 AM     H  66056      C:\WINDOWS\Temp\CS12B760CA-74EA-4378-A346-B1C5F82212C0.tmp
8/8/2005 10:22:08 AM     H  100        C:\WINDOWS\Temp\CS12ED0ED1-ED5E-459D-8E57-4CB38102476D.tmp
8/21/2005 8:29:14 PM     H  1227876    C:\WINDOWS\Temp\CS132759D3-2FC0-4A00-A2FE-E6080E1F0614.tmp
8/30/2005 4:03:34 PM     H  96         C:\WINDOWS\Temp\CS132D17C3-05B4-4ED2-AE42-B72C776EEF29.tmp
8/1/2005 3:44:16 AM      H  30         C:\WINDOWS\Temp\CS132D345B-F463-433D-9CA4-830B3FD04B09.tmp
9/17/2005 9:41:04 AM     H  0          C:\WINDOWS\Temp\CS1372D6BA-D346-4450-94FC-B30D37186CF6.tmp
8/13/2005 11:56:20 AM    H  10         C:\WINDOWS\Temp\CS138C04D0-7127-47C1-AA71-77D438FAD205.tmp
9/17/2005 9:41:24 AM     H  0          C:\WINDOWS\Temp\CS141D9BA2-BF18-4BD4-8FD5-865DFA582EC5.tmp
7/27/2005 1:47:24 PM     H  10         C:\WINDOWS\Temp\CS1424C5C1-B359-496A-A8E0-141F907F96A7.tmp
8/3/2005 11:55:26 AM     H  10         C:\WINDOWS\Temp\CS145DBD88-5C8B-4FFF-B6DD-C0410BC6273D.tmp
8/30/2005 4:03:34 PM     H  414        C:\WINDOWS\Temp\CS14658F44-65E6-4D23-9771-779E18192D9B.tmp
8/29/2005 6:22:44 PM     H  10         C:\WINDOWS\Temp\CS1478EC9A-EC20-4060-91A8-99EE11B55513.tmp
8/7/2005 1:22:16 AM      H  619544     C:\WINDOWS\Temp\CS14819544-E53D-4B47-A7AB-F2A4AA911B67.tmp
9/14/2005 7:39:32 AM     H  10         C:\WINDOWS\Temp\CS14A90956-0EA0-4A5A-AEC8-0F6862FB38BB.tmp
8/19/2005 7:43:30 AM     H  14         C:\WINDOWS\Temp\CS14A9A19E-DD77-4250-9BC9-1C556A8BECF6.tmp
8/19/2005 4:43:58 AM     H  3411       C:\WINDOWS\Temp\CS14AD6294-7E01-4394-B9BF-469009D9CCB8.tmp
8/15/2005 4:32:00 AM     H  528        C:\WINDOWS\Temp\CS14D49B53-84B3-4715-9421-7698EAD90305.tmp
8/8/2005 3:46:26 PM      H  1030002    C:\WINDOWS\Temp\CS14D4DE8D-65A8-4A0A-91E0-90E661A395E3.tmp
8/30/2005 4:03:30 PM     H  48         C:\WINDOWS\Temp\CS14EE9E42-0668-407E-ACFC-9322EAEC9686.tmp
9/17/2005 9:41:22 AM     H  0          C:\WINDOWS\Temp\CS14F748F7-2388-414F-8EB3-BCC6700DBE2C.tmp
8/6/2005 11:02:42 AM     H  3411       C:\WINDOWS\Temp\CS14FF0E6D-6A2D-48F4-8100-632E5CD5701D.tmp
8/19/2005 7:43:30 AM     H  10         C:\WINDOWS\Temp\CS15046775-A638-4417-BE27-8A2C2942DD0A.tmp
8/22/2005 2:47:24 AM     H  10         C:\WINDOWS\Temp\CS156DFD74-233D-449A-9960-0EE8079D004A.tmp
8/19/2005 7:43:30 AM     H  100        C:\WINDOWS\Temp\CS157961CE-268A-4359-B974-98B447C12505.tmp
9/9/2005 2:54:50 PM      H  934        C:\WINDOWS\Temp\CS1588C95F-23F5-480B-94AE-65BB42CCBECC.tmp
8/8/2005 10:22:06 AM     H  312        C:\WINDOWS\Temp\CS15C5D27C-0025-4BE1-A762-658C6D89D8A9.tmp
8/30/2005 4:03:36 PM     H  10         C:\WINDOWS\Temp\CS16268E6C-ECD8-414C-A823-9F8FF215AE9F.tmp
8/1/2005 8:52:54 PM      H  408        C:\WINDOWS\Temp\CS1644460F-D812-4D6E-9990-03359F6DDCE7.tmp
8/26/2005 11:55:58 PM    H  10         C:\WINDOWS\Temp\CS164D5EBD-1130-4BE4-A11D-A09430F59951.tmp
8/22/2005 2:47:24 AM     H  14         C:\WINDOWS\Temp\CS16755A86-F008-4651-BF1F-1533077DE75D.tmp
8/30/2005 3:03:50 PM     H  2018310    C:\WINDOWS\Temp\CS16AF0CAE-C31F-45D1-826E-6E6BCBCD1E6B.tmp
8/7/2005 1:22:16 AM      H  32         C:\WINDOWS\Temp\CS17070CA1-43C6-4F32-9129-D7A6308950B0.tmp
8/21/2005 8:29:14 PM     H  1350       C:\WINDOWS\Temp\CS170C5BB6-13A1-4972-B859-5CCEF39ABF3F.tmp
8/22/2005 12:29:02 AM    H  120        C:\WINDOWS\Temp\CS170C7F50-0D30-4038-9DFD-7FC58460FB1A.tmp
8/3/2005 11:55:26 AM     H  600        C:\WINDOWS\Temp\CS175D1D5E-7AFD-4F00-AF03-2F5A80F27DCA.tmp
8/15/2005 4:32:02 AM     H  69542      C:\WINDOWS\Temp\CS1760293B-C0DB-4A44-860B-8D95E14C3F44.tmp
8/3/2005 11:55:06 AM     H  126        C:\WINDOWS\Temp\CS1775DF37-33C0-4430-B913-65F3B651ED96.tmp
8/8/2005 7:46:02 PM      H  480        C:\WINDOWS\Temp\CS177CBE8E-1CAA-4D4B-A7C3-4655481BF998.tmp
8/1/2005 1:53:08 PM      H  160        C:\WINDOWS\Temp\CS17A07876-6178-43B1-8D23-E97852B6C1CB.tmp
8/19/2005 7:43:30 AM     H  10         C:\WINDOWS\Temp\CS17C27D7E-E578-4A0A-A4E2-2425519120C4.tmp
8/1/2005 3:44:16 AM      H  10         C:\WINDOWS\Temp\CS17E84DEC-0AB3-4C84-BC86-D9AB60D126FE.tmp
8/8/2005 10:22:06 AM     H  10         C:\WINDOWS\Temp\CS17F9F90E-9E6B-47D1-AD96-09B0D3FBAA10.tmp
8/26/2005 11:55:58 PM    H  100        C:\WINDOWS\Temp\CS17FD1161-B8CC-44ED-BA14-4F07856B3251.tmp
7/27/2005 6:47:44 AM     H  2018310    C:\WINDOWS\Temp\CS181266CC-F59D-4237-B9DB-2E12F0B1EE3A.tmp
8/8/2005 7:46:04 PM      H  10         C:\WINDOWS\Temp\CS1829696A-6A4A-4869-93D8-10F2DD0254FF.tmp
8/30/2005 4:03:32 PM     H  10         C:\WINDOWS\Temp\CS1841F0AC-51CD-4BDA-887F-F6540B1F6B4C.tmp
8/22/2005 1:48:06 AM     H  330388     C:\WINDOWS\Temp\CS18495013-D55E-4318-9197-89D725F122A0.tmp
8/8/2005 10:22:08 AM     H  68         C:\WINDOWS\Temp\CS189F28D9-8DDD-4B4B-A3A2-8E6D84EE77EC.tmp
8/6/2005 11:03:00 AM     H  10         C:\WINDOWS\Temp\CS18A4D658-869C-42BF-A87D-B01D654D31CE.tmp
8/8/2005 10:22:06 AM     H  10         C:\WINDOWS\Temp\CS18D44271-5171-4936-9E3B-91E84A8DCFCA.tmp
8/21/2005 8:29:34 PM     H  1219708    C:\WINDOWS\Temp\CS18DBE2C4-8919-44FC-B190-5700F61C503A.tmp
8/19/2005 7:43:30 AM     H  10         C:\WINDOWS\Temp\CS18DF8C43-3BDF-401C-978E-CD201CAF0CFE.tmp
8/19/2005 7:43:30 AM     H  48         C:\WINDOWS\Temp\CS18E10B0E-0B1D-41D9-87B8-0872FD49BDC9.tmp
8/19/2005 4:43:58 AM     H  35144      C:\WINDOWS\Temp\CS1900A2C0-482D-4D82-ABAA-5DB76A4D4969.tmp
8/6/2005 11:03:00 AM     H  48         C:\WINDOWS\Temp\CS190E54A6-8735-43EC-B43F-E0721BBB9D99.tmp
8/1/2005 3:44:16 AM      H  10         C:\WINDOWS\Temp\CS194D4A7E-B156-4D0A-9482-F5AAE9658602.tmp
9/9/2005 2:54:50 PM      H  22632      C:\WINDOWS\Temp\CS195296E6-8E91-46F6-9E32-D05ED60B2798.tmp
8/26/2005 2:56:02 PM     H  5568       C:\WINDOWS\Temp\CS197B237B-6008-452D-A5E7-52F085595F75.tmp
8/3/2005 11:55:06 AM     H  934        C:\WINDOWS\Temp\CS19A3BE73-13C4-4BB6-A682-D77BACA55F1E.tmp
9/17/2005 9:41:04 AM     H  0          C:\WINDOWS\Temp\CS19B50E41-A7EB-4152-98AA-A07BD52C870D.tmp
8/15/2005 4:31:44 AM     H  22632      C:\WINDOWS\Temp\CS19C3DC4C-CC9A-43D0-92B3-1D5DE6242E06.tmp
8/1/2005 8:52:54 PM      H  42         C:\WINDOWS\Temp\CS19F3BB3B-992B-4C5B-BFC9-D15333DBC1B3.tmp
8/8/2005 7:46:02 PM      H  42         C:\WINDOWS\Temp\CS1A316FAB-AF3B-453F-8A9C-0513C3B6EB79.tmp
8/22/2005 12:29:02 AM    H  10         C:\WINDOWS\Temp\CS1A46A3FF-44CE-4952-A989-36E421CE9082.tmp
8/8/2005 7:46:02 PM      H  10         C:\WINDOWS\Temp\CS1A669A58-A0DC-49F9-93FA-EAA866F23206.tmp
9/15/2005 3:28:14 PM     H  2016       C:\WINDOWS\Temp\CS1A84CF2E-F5D6-4CB9-BD1C-3824C904FF68.tmp
8/7/2005 1:22:16 AM      H  37532      C:\WINDOWS\Temp\CS1ACDA559-9806-4E48-AF13-CDDD46C2981F.tmp
8/22/2005 12:29:02 AM    H  528        C:\WINDOWS\Temp\CS1ADAE2BF-60D5-46BC-B36E-786AD26C9F45.tmp
9/17/2005 9:41:04 AM     H  0          C:\WINDOWS\Temp\CS1AE7BD0D-3315-47C9-B6BA-1B1CDE8891D7.tmp
8/21/2005 8:29:36 PM     H  81290      C:\WINDOWS\Temp\CS1B0F4EFB-BC09-4118-B712-A5963465CF87.tmp
8/6/2005 11:03:00 AM     H  342        C:\WINDOWS\Temp\CS1B10FF0F-BAA5-4C80-B7D0-41DD025BA6F1.tmp
8/8/2005 7:46:02 PM      H  310        C:\WINDOWS\Temp\CS1B74E405-8C07-419D-8899-B50010AFD760.tmp
8/8/2005 10:22:08 AM     H  100        C:\WINDOWS\Temp\CS1BAD7453-7E76-4314-84C7-3846C5DEA1CA.tmp
8/6/2005 11:33:54 AM     H  1227876    C:\WINDOWS\Temp\CS1BE6566A-ABE3-4270-AE5E-5F5AF1EAC7FF.tmp
8/29/2005 6:22:44 PM     H  310        C:\WINDOWS\Temp\CS1BFFDF1F-93FA-4D00-B5D9-2530E740A2D5.tmp
8/22/2005 2:47:24 AM     H  100        C:\WINDOWS\Temp\CS1C25C6AA-0B2B-4688-B70C-D0BF96AF386B.tmp
8/3/2005 11:55:32 AM     H  1565690    C:\WINDOWS\Temp\CS1C2B4A5C-B387-4543-B310-B8B1A566FBD0.tmp
8/30/2005 4:03:32 PM     H  10         C:\WINDOWS\Temp\CS1C3ABF73-E968-46F3-8BA3-59277D87AFD1.tmp
8/19/2005 7:43:30 AM     H  10         C:\WINDOWS\Temp\CS1C408552-E055-4842-A85E-4B93E7BC5641.tmp
8/15/2005 4:32:00 AM     H  10         C:\WINDOWS\Temp\CS1C53E41D-AFD4-4CA3-BA24-E7B734F8148F.tmp
9/17/2005 9:41:22 AM     H  0          C:\WINDOWS\Temp\CS1C97F239-C53D-42EE-AD33-CFAB58F45DC6.tmp
7/27/2005 1:47:24 PM     H  10         C:\WINDOWS\Temp\CS1CA02B3E-258B-4179-9523-A2703C426369.tmp
8/8/2005 10:22:08 AM     H  30         C:\WINDOWS\Temp\CS1CEFAA1F-E977-405F-9B09-3417CD002373.tmp
8/22/2005 2:47:24 AM     H  10         C:\WINDOWS\Temp\CS1CF6D77C-480A-4913-96BB-ED248B644006.tmp
8/8/2005 7:46:02 PM      H  30         C:\WINDOWS\Temp\CS1D048857-9FA2-4A96-ADFB-5A40A6496EF2.tmp
8/1/2005 3:44:16 AM      H  100        C:\WINDOWS\Temp\CS1D851492-60BC-4529-BE93-2972AF989688.tmp
8/19/2005 4:44:14 AM     H  69542      C:\WINDOWS\Temp\CS1D9AA181-C12E-46B3-B049-EE348B32B748.tmp
8/26/2005 2:56:24 PM     H  1219708    C:\WINDOWS\Temp\CS1DC63667-792B-4D86-B10A-28627D0424FE.tmp
8/8/2005 7:46:02 PM      H  10         C:\WINDOWS\Temp\CS1DD75C65-8C83-4CFE-BCC7-1DBA80BC5CCF.tmp
8/30/2005 3:03:50 PM     H  97206      C:\WINDOWS\Temp\CS1DDED691-EAA2-45EB-8E39-46CD76F6D54D.tmp
8/22/2005 1:47:48 AM     H  726        C:\WINDOWS\Temp\CS1DF3E459-9D01-4EB3-B68F-E67C1E43044C.tmp
8/29/2005 6:22:44 PM     H  102        C:\WINDOWS\Temp\CS1E0BDDBA-97EF-4DD8-A30D-95F31C4BB182.tmp
8/15/2005 4:32:00 AM     H  312        C:\WINDOWS\Temp\CS1E1B3114-A6B6-47E6-BE0B-A4CD07690F86.tmp
8/3/2005 11:55:06 AM     H  66056      C:\WINDOWS\Temp\CS1E3F4B41-5786-4054-94B5-7B073A0E3BD6.tmp
7/27/2005 1:47:24 PM     H  10         C:\WINDOWS\Temp\CS1E51A5E8-3627-48C8-B820-ABB205BE93D6.tmp
8/3/2005 11:55:06 AM     H  1030002    C:\WINDOWS\Temp\CS1E85DA4F-5691-4DA2-A718-FD4385C17FAC.tmp
9/14/2005 7:39:30 AM     H  100        C:\WINDOWS\Temp\CS1EBF67BA-9421-4E96-8CFD-0456FE3F7EC9.tmp
8/6/2005 11:34:08 AM     H  30         C:\WINDOWS\Temp\CS1EC38674-9DCA-4F17-A534-6D6E34564866.tmp
8/22/2005 12:29:02 AM    H  118        C:\WINDOWS\Temp\CS1EC4A9F5-780E-4ABD-A308-9954F4B4F922.tmp
8/30/2005 7:18:04 PM     H  73520      C:\WINDOWS\Temp\CS1EC73FF7-752B-473B-9999-7D0BC5E145DB.tmp
9/17/2005 9:41:22 AM     H  0          C:\WINDOWS\Temp\CS1EE02F7A-A150-409B-BFA7-78C1FA6AAAD2.tmp
8/1/2005 1:44:36 AM      H  22632      C:\WINDOWS\Temp\CS1F308B24-01C1-4327-9886-388E8B7AC7CA.tmp
8/7/2005 1:22:16 AM      H  30         C:\WINDOWS\Temp\CS1F3F7F2A-BF93-4F8E-9D79-0068EBEED322.tmp
8/6/2005 11:03:00 AM     H  10         C:\WINDOWS\Temp\CS1F5F9FAD-1916-443B-B17B-2E358C1579BB.tmp
8/22/2005 2:47:24 AM     H  10         C:\WINDOWS\Temp\CS1F754BC4-DC01-4067-A8F9-6C7BDEE14F3F.tmp
9/9/2005 3:54:20 PM      H  10         C:\WINDOWS\Temp\CS1F850217-C099-4D45-BA8A-585871EF701F.tmp
8/3/2005 11:55:26 AM     H  10         C:\WINDOWS\Temp\CS1F996583-F07F-41D0-8208-1B95831AAD28.tmp
9/17/2005 9:41:22 AM     H  0          C:\WINDOWS\Temp\CS1FA8F27B-E8BC-43B1-A9C8-7D450B01AAD4.tmp
8/8/2005 10:22:06 AM     H  500        C:\WINDOWS\Temp\CS1FC5F845-A89A-4652-9229-43D9C3EE265E.tmp
9/17/2005 9:41:22 AM     H  0          C:\WINDOWS\Temp\CS1FD506CE-1E32-4028-A1DD-86B65BEA34C8.tmp
9/9/2005 3:54:20 PM      H  10         C:\WINDOWS\Temp\CS1FFF1EA5-D00C-4E8D-9E6D-F4893EC8FE76.tmp
8/15/2005 4:31:58 AM     H  504        C:\WINDOWS\Temp\CS20234CF0-82A5-4DF6-9FE1-20D9E1C21A2A.tmp
8/26/2005 11:55:58 PM    H  10         C:\WINDOWS\Temp\CS205D335E-5D9A-4C0C-AAB0-970587DDC724.tmp
8/8/2005 3:46:40 PM      H  1219708    C:\WINDOWS\Temp\CS20662209-420A-4BB0-9BB8-AC9612744E79.tmp
8/13/2005 11:56:20 AM    H  10         C:\WINDOWS\Temp\CS207F82F5-88A2-41C7-8013-C9F0F77C0CE6.tmp
9/14/2005 7:39:32 AM     H  10         C:\WINDOWS\Temp\CS20D3DBDE-EB02-486E-A27E-18B4B8E7D3FB.tmp
8/8/2005 7:46:02 PM      H  10         C:\WINDOWS\Temp\CS20E10126-8344-4C35-869B-13E5ECBB3D1B.tmp
8/26/2005 11:55:58 PM    H  10         C:\WINDOWS\Temp\CS21132E2C-6834-48FC-98F2-6D20A198267D.tmp
8/6/2005 11:03:00 AM     H  10         C:\WINDOWS\Temp\CS212844B8-AE6F-456B-B0CB-C88339C49888.tmp
8/1/2005 3:44:16 AM      H  10         C:\WINDOWS\Temp\CS216EFEBF-51AF-42CC-A9CE-5239F7523E97.tmp
8/26/2005 2:56:02 PM     H  240        C:\WINDOWS\Temp\CS217774CC-0E3A-49D7-9694-A3351C856BFB.tmp
8/19/2005 7:43:30 AM     H  42         C:\WINDOWS\Temp\CS2186024C-3398-4990-AFCC-4E94244F8FBB.tmp
8/1/2005 1:53:26 PM      H  1565690    C:\WINDOWS\Temp\CS21B82406-8DAE-4127-B249-45A3F8114B50.tmp
9/17/2005 9:41:04 AM     H  0          C:\WINDOWS\Temp\CS21C8BC7E-F7BF-4299-B568-747C5E45A225.tmp
8/1/2005 8:52:54 PM      H  504        C:\WINDOWS\Temp\CS21CB3EAF-2846-4ED9-B7BA-BDF2C5121EEA.tmp
8/6/2005 11:33:54 AM     H  160        C:\WINDOWS\Temp\CS21CFDE96-F2DC-4A27-B1A6-C90700754A1C.tmp
8/3/2005 11:55:06 AM     H  32         C:\WINDOWS\Temp\CS225A2EDB-0FD8-4B90-864E-575F1EABA3DD.tmp
8/1/2005 3:44:16 AM      H  10         C:\WINDOWS\Temp\CS226F9940-1806-48EB-A2DC-3F15134BCE10.tmp
7/27/2005 6:47:44 AM     H  30         C:\WINDOWS\Temp\CS22B68D04-4BED-42BB-A035-4B33A3724495.tmp
8/6/2005 11:03:00 AM     H  10         C:\WINDOWS\Temp\CS22CC2736-453A-4A64-8DC3-C131648F5458.tmp
8/1/2005 8:52:54 PM      H  10         C:\WINDOWS\Temp\CS22CE2FC9-5FFC-440A-8857-A0177B3DABF2.tmp
8/15/2005 4:32:00 AM     H  10         C:\WINDOWS\Temp\CS22F8F64A-B1DE-4CBB-ABF2-71C3CC45F1DA.tmp
7/27/2005 1:47:22 PM     H  42         C:\WINDOWS\Temp\CS231CE1DA-44D9-4F15-95A1-D59AD12B1505.tmp
8/30/2005 7:18:04 PM     H  458752     C:\WINDOWS\Temp\CS2330F1C8-FDFB-4C96-BA79-7C01C004A8B4.tmp
8/29/2005 4:23:02 PM     H  1324922    C:\WINDOWS\Temp\CS23759B2F-D2FC-4080-8A04-C46EAEB3A934.tmp
8/6/2005 11:03:00 AM     H  10         C:\WINDOWS\Temp\CS23F04FB4-7561-4C78-BE0D-C77D10BD66D9.tmp
8/26/2005 11:55:58 PM    H  10         C:\WINDOWS\Temp\CS2409CB24-9F92-49AD-A187-6C222FF984BF.tmp
8/22/2005 2:47:24 AM     H  10         C:\WINDOWS\Temp\CS240EF417-B5CE-4ED0-BDED-B31EAD99AE6A.tmp
8/1/2005 3:44:16 AM      H  10         C:\WINDOWS\Temp\CS24469DA7-FDCE-4270-8004-07528B650FAE.tmp
8/19/2005 7:43:30 AM     H  10         C:\WINDOWS\Temp\CS247417ED-74AF-47C3-AE48-2BD5AFA9F832.tmp
8/15/2005 4:31:58 AM     H  30         C:\WINDOWS\Temp\CS24A13926-3AA3-436D-BB3E-CD22A37805C3.tmp
9/17/2005 9:41:24 AM     H  0          C:\WINDOWS\Temp\CS24D343EB-1F2F-4A8C-8B84-B39E3847164B.tmp
8/30/2005 4:03:32 PM     H  10         C:\WINDOWS\Temp\CS251FFECA-B305-417E-8D2A-FAA7BC5014E5.tmp
8/30/2005 4:03:32 PM     H  10         C:\WINDOWS\Temp\CS2521E086-54C1-4240-9971-51A9C997AE6E.tmp
8/6/2005 11:34:12 AM     H  1565690    C:\WINDOWS\Temp\CS25D574E3-E067-4F1D-8D9D-BC7DBBE2A754.tmp
9/15/2005 3:28:14 PM     H  1468038    C:\WINDOWS\Temp\CS2639A90A-CC44-4C53-B9C8-4B9FB6356A83.tmp
7/27/2005 1:47:22 PM     H  600        C:\WINDOWS\Temp\CS266E52D8-6944-4CDD-9F7F-AD2ADBAB774C.tmp
8/15/2005 4:31:44 AM     H  32         C:\WINDOWS\Temp\CS266FF526-BD39-48FC-93FA-68792EF28762.tmp
7/27/2005 1:47:22 PM     H  10         C:\WINDOWS\Temp\CS268067C4-9927-4D77-9DE3-789C90E530DD.tmp
8/6/2005 11:34:08 AM     H  118        C:\WINDOWS\Temp\CS2683BC5F-6CC7-41AB-98EC-E95E288DE6E8.tmp
8/21/2005 8:29:36 PM     H  330388     C:\WINDOWS\Temp\CS26960F4D-FE6D-4D47-B1CD-232887465CBA.tmp
9/15/2005 3:28:14 PM     H  204        C:\WINDOWS\Temp\CS26B47885-9B7A-4D5B-B323-A6E4C5B42884.tmp
8/15/2005 4:32:00 AM     H  10         C:\WINDOWS\Temp\CS26FA7888-865D-49B4-8A9A-00A0851603EC.tmp
8/8/2005 7:46:02 PM      H  114        C:\WINDOWS\Temp\CS2731C8D8-3704-4275-BB1F-6945D653F241.tmp
9/17/2005 9:41:24 AM     H  0          C:\WINDOWS\Temp\CS273B5AA7-1761-41CC-BA2E-7356DC30ABEF.tmp
8/29/2005 6:22:44 PM     H  10         C:\WINDOWS\Temp\CS2766A429-82C0-44F6-BC96-3DF5DBA836EB.tmp
8/6/2005 11:02:42 AM     H  5568       C:\WINDOWS\Temp\CS279BBC49-1A04-4556-A720-2A07FCE597A0.tmp
8/29/2005 6:22:44 PM     H  10         C:\WINDOWS\Temp\CS27AD65A4-F858-45BF-9A56-DAC0EFC87988.tmp
9/14/2005 7:39:30 AM     H  30         C:\WINDOWS\Temp\CS27BB2AF4-EB3F-45D2-BD46-2779DDD534B0.tmp
8/29/2005 6:22:44 PM     H  10         C:\WINDOWS\Temp\CS27C5E45D-5180-43EF-ADF8-AF2514AEB74D.tmp
8/1/2005 8:52:54 PM      H  118        C:\WINDOWS\Temp\CS281865B4-F79D-4509-BE98-9CDF509D2926.tmp
9/9/2005 3:54:20 PM      H  30         C:\WINDOWS\Temp\CS285BF074-513B-4FEE-83E3-401E254D391B.tmp
8/8/2005 10:22:06 AM     H  322        C:\WINDOWS\Temp\CS286B86C3-05B7-4B02-AF94-0F6EBE50CF3E.tmp
7/27/2005 1:47:22 PM     H  10         C:\WINDOWS\Temp\CS2873693D-7861-4350-8E25-CBEFDA4575AF.tmp
9/14/2005 7:39:30 AM     H  10         C:\WINDOWS\Temp\CS289A7127-FF78-4ABA-915C-5B06980C7FE7.tmp
8/29/2005 6:22:44 PM     H  118        C:\WINDOWS\Temp\CS28D59D15-F23A-4210-9F5B-0F304D04CF6A.tmp
8/1/2005 3:44:16 AM      H  10         C:\WINDOWS\Temp\CS292D52BC-6966-4F51-B905-0CA0BE711993.tmp
7/27/2005 1:47:22 PM     H  428        C:\WINDOWS\Temp\CS2945562A-DD10-461E-95BD-48639716F4B8.tmp
9/17/2005 9:41:22 AM     H  0          C:\WINDOWS\Temp\CS294D7763-DC73-4D13-A924-E1E95F715CA6.tmp
8/22/2005 1:47:48 AM     H  30         C:\WINDOWS\Temp\CS29DC4CDC-9C83-487B-B1B4-760624431824.tmp
7/27/2005 1:47:22 PM     H  10         C:\WINDOWS\Temp\CS29DC6D82-FD9F-421F-B5A3-8D016749A4DE.tmp
8/3/2005 11:55:32 AM     H  81290      C:\WINDOWS\Temp\CS29F9C76A-3BF2-4EBF-8058-5FC52332376F.tmp
7/27/2005 1:47:22 PM     H  408        C:\WINDOWS\Temp\CS2A2ADC91-F03A-44A1-AB0B-2B92D50A59B8.tmp
8/29/2005 6:22:44 PM     H  120        C:\WINDOWS\Temp\CS2A5940D9-7068-4DEA-B37A-CCBCC8C3871F.tmp
9/17/2005 9:41:22 AM     H  0          C:\WINDOWS\Temp\CS2A9A3342-B168-43AC-BFB2-5762D1304983.tmp
8/1/2005 8:52:54 PM      H  48         C:\WINDOWS\Temp\CS2AEBB959-BE77-476E-943D-4BAD1458E195.tmp
8/6/2005 11:33:54 AM     H  528154     C:\WINDOWS\Temp\CS2AF7B946-F39B-4425-A6AF-33140089D10B.tmp
8/15/2005 4:31:44 AM     H  1030002    C:\WINDOWS\Temp\CS2B2AE864-3947-4D3A-94E5-A20A8AEE46AF.tmp
8/19/2005 4:43:58 AM     H  37532      C:\WINDOWS\Temp\CS2B7229C5-D2DD-4E20-B9DC-1291F63919D6.tmp
8/6/2005 11:34:08 AM     H  660        C:\WINDOWS\Temp\CS2B7D87AC-77E0-4786-AE36-451719D33E88.tmp
8/13/2005 11:56:22 AM    H  96         C:\WINDOWS\Temp\CS2B850CAA-C208-477E-8101-8BB6DC62AE8F.tmp
9/17/2005 9:41:04 AM     H  0          C:\WINDOWS\Temp\CS2BC28915-2F77-4263-828E-BF75C7C6DE4C.tmp
8/1/2005 1:44:36 AM      H  5808       C:\WINDOWS\Temp\CS2BD33882-B10D-4CBC-8738-5E5B7693A9C0.tmp
8/15/2005 4:32:00 AM     H  10         C:\WINDOWS\Temp\CS2BE29BDC-857D-4517-BAFF-11B900A81CD5.tmp
8/22/2005 1:47:48 AM     H  168        C:\WINDOWS\Temp\CS2C0C0AA8-83EE-43EB-B658-B91547787AF6.tmp
9/9/2005 2:54:50 PM      H  35144      C:\WINDOWS\Temp\CS2C79727E-CB44-46B8-B198-299DD0CD42EE.tmp
8/19/2005 7:43:30 AM     H  102        C:\WINDOWS\Temp\CS2C8AE23B-440C-463C-AD2C-68553D11038B.tmp
8/26/2005 11:55:58 PM    H  30         C:\WINDOWS\Temp\CS2C9FAEBD-F517-4007-8829-B56716175B0D.tmp
8/7/2005 1:22:16 AM      H  3411       C:\WINDOWS\Temp\CS2CBCB48E-0900-4FA5-A365-BBC462A17CED.tmp
9/14/2005 7:39:32 AM     H  10         C:\WINDOWS\Temp\CS2D1A2BDF-D1D3-426E-B56D-819706506304.tmp
8/13/2005 11:56:22 AM    H  10         C:\WINDOWS\Temp\CS2D8D846A-45D5-474C-81F1-8F9C9F18644D.tmp
8/15/2005 4:32:00 AM     H  100        C:\WINDOWS\Temp\CS2D8E8211-D7BC-4324-84E4-A9D4823A3CA4.tmp
8/30/2005 7:18:04 PM     H  240        C:\WINDOWS\Temp\CS2DA49450-0654-4CFC-86B9-82C4CD8BC2E0.tmp
8/13/2005 11:56:22 AM    H  10         C:\WINDOWS\Temp\CS2DE89A83-9DFE-4F38-8595-FCB9ABEAADB8.tmp
8/13/2005 11:56:22 AM    H  48         C:\WINDOWS\Temp\CS2DF23118-6C53-42D9-B5F1-2466BC88FC71.tmp
8/13/2005 11:56:20 AM    H  10         C:\WINDOWS\Temp\CS2E0BC839-E2E9-485D-BEC3-02BAE7DE40BB.tmp
8/26/2005 2:56:02 PM     H  5808       C:\WINDOWS\Temp\CS2E339D25-AE4F-4756-81F3-B98F4ECA9405.tmp
8/29/2005 6:22:44 PM     H  480        C:\WINDOWS\Temp\CS2E345710-B799-4098-847F-034A7C9A840C.tmp
7/27/2005 1:47:22 PM     H  136        C:\WINDOWS\Temp\CS2E420A11-B357-4E04-A26F-F0D4BB9677BE.tmp
8/1/2005 3:44:16 AM      H  310        C:\WINDOWS\Temp\CS2E69F911-E17B-497E-90E2-16DCFC9DEFBB.tmp
8/3/2005 11:55:26 AM     H  10         C:\WINDOWS\Temp\CS2EC74840-2C20-4FA0-8D3E-6F40E3AA3C3A.tmp
9/14/2005 7:39:30 AM     H  48         C:\WINDOWS\Temp\CS2EE66529-3DE1-43C3-9B97-2C5884516D0F.tmp
8/1/2005 1:53:08 PM      H  619544     C:\WINDOWS\Temp\CS2F04E818-4D4C-4D3F-9050-BCFFDAC6A022.tmp
8/30/2005 4:03:30 PM     H  504        C:\WINDOWS\Temp\CS2F141A79-0458-4BE7-BE3E-FBFE248CC628.tmp
8/26/2005 2:56:02 PM     H  2018310    C:\WINDOWS\Temp\CS2F34E172-0894-40B2-B5AC-26B86CD0CBAC.tmp
8/6/2005 11:03:00 AM     H  312        C:\WINDOWS\Temp\CS2F418BB7-9430-4E67-BF03-44CF9765F391.tmp
7/27/2005 1:47:22 PM     H  10         C:\WINDOWS\Temp\CS2F46C68F-C8A2-414E-93FF-99D783073F71.tmp
8/21/2005 8:29:14 PM     H  160        C:\WINDOWS\Temp\CS2F88AF91-1AB5-4EC0-8A2B-E0410CAB71CC.tmp
8/15/2005 4:32:04 AM     H  330388     C:\WINDOWS\Temp\CS2F95626C-745A-4988-96B2-FFB6EFD821F6.tmp
8/30/2005 4:03:30 PM     H  10         C:\WINDOWS\Temp\CS2FA9A2A6-F507-43D3-B432-061A788A2BD7.tmp
8/15/2005 4:32:00 AM     H  48         C:\WINDOWS\Temp\CS2FBB72D4-FBAF-410F-92E2-00AA0C478285.tmp
8/6/2005 11:33:54 AM     H  168        C:\WINDOWS\Temp\CS309E153D-A79E-49B7-BF1B-D97FE798D759.tmp
8/29/2005 6:22:44 PM     H  10         C:\WINDOWS\Temp\CS30D9E311-1ED1-4F99-9390-5FCB8E1747FD.tmp
8/26/2005 11:55:58 PM    H  480        C:\WINDOWS\Temp\CS31554032-D211-4A82-8624-C293E97D6C2C.tmp
8/3/2005 11:55:26 AM     H  42         C:\WINDOWS\Temp\CS3163DFF1-CC52-40A7-8FD1-1148B1F12D06.tmp
8/15/2005 4:32:00 AM     H  102        C:\WINDOWS\Temp\CS316FEA66-7668-489F-9BF3-C32148142955.tmp
8/22/2005 1:47:48 AM     H  126        C:\WINDOWS\Temp\CS318018E6-8F31-4CE4-97F3-ED6723A9C1DA.tmp
8/7/2005 1:22:16 AM      H  66056      C:\WINDOWS\Temp\CS31C1EE4A-D34F-4197-8853-FA9103F297D2.tmp
8/22/2005 1:47:48 AM     H  619544     C:\WINDOWS\Temp\CS31D1668A-7353-4F2F-B4B5-C90C449C1600.tmp
9/14/2005 7:39:30 AM     H  10         C:\WINDOWS\Temp\CS320C0A20-510A-468B-8343-DC48F82BF758.tmp
7/27/2005 6:47:44 AM     H  726        C:\WINDOWS\Temp\CS323CCA4F-8C06-497E-B0FE-9105997460CC.tmp
8/29/2005 4:23:02 PM     H  168        C:\WINDOWS\Temp\CS325E0242-2EF5-4F44-832A-0087F764E8F9.tmp
8/13/2005 11:56:20 AM    H  10         C:\WINDOWS\Temp\CS3273AC4F-6D0C-41C4-B248-8A888C5AF546.tmp
7/27/2005 1:47:22 PM     H  100        C:\WINDOWS\Temp\CS327D22A2-347D-4B37-8EDE-E405104CBB98.tmp
8/6/2005 11:03:00 AM     H  10         C:\WINDOWS\Temp\CS3298C787-3144-406A-AA61-E0905468DB39.tmp
8/19/2005 4:43:58 AM     H  168        C:\WINDOWS\Temp\CS32B2AC6C-2350-4C9C-B24F-9707B7AAA35B.tmp
8/1/2005 1:53:08 PM      H  270        C:\WINDOWS\Temp\CS32E3C6A8-C371-4472-9578-5E3D5D4822EB.tmp
7/27/2005 6:47:44 AM     H  240        C:\WINDOWS\Temp\CS32E68787-5702-41EE-8E98-09209234631B.tmp
8/1/2005 8:52:54 PM      H  100        C:\WINDOWS\Temp\CS33011576-BFC1-4F32-B576-9CC55BC4E66D.tmp
9/9/2005 3:54:20 PM      H  456        C:\WINDOWS\Temp\CS3309C7F5-DD63-4477-8721-F55DFD76687F.tmp
8/30/2005 4:03:36 PM     H  10         C:\WINDOWS\Temp\CS33114430-A754-41B5-BBE7-777269D9E75A.tmp
8/29/2005 4:23:02 PM     H  1030002    C:\WINDOWS\Temp\CS33866EDB-D68B-4049-9548-B67E496C9B75.tmp
8/8/2005 7:46:02 PM      H  10         C:\WINDOWS\Temp\CS338B0464-343D-466D-A832-82F0A2C41013.tmp
7/27/2005 1:47:22 PM     H  10         C:\WINDOWS\Temp\CS339D2CB5-573C-4A3E-8047-10916B1EAF9C.tmp
8/29/2005 4:23:02 PM     H  270        C:\WINDOWS\Temp\CS33C441AE-178E-43CE-94BE-33B1F95CA4BE.tmp
8/6/2005 11:34:08 AM     H  48         C:\WINDOWS\Temp\CS33F5A5F7-39F4-4A61-8A61-F95E097C8273.tmp
8/30/2005 3:04:16 PM     H  1219708    C:\WINDOWS\Temp\CS3408C93B-26F9-4AA2-8879-75B4F0F8722C.tmp
8/22/2005 2:47:24 AM     H  480        C:\WINDOWS\Temp\CS3409A402-1AF8-4E40-96E0-E86C37C8C361.tmp
8/6/2005 11:34:08 AM     H  136        C:\WINDOWS\Temp\CS341398B1-7DD1-436A-A321-D984CB181011.tmp
8/3/2005 11:55:06 AM     H  168        C:\WINDOWS\Temp\CS34142D6D-41E3-4335-AF65-DACFD55747A4.tmp
8/22/2005 12:29:02 AM    H  310        C:\WINDOWS\Temp\CS342F4CC9-92ED-4982-90FD-414C47B154CA.tmp
8/1/2005 3:44:16 AM      H  10         C:\WINDOWS\Temp\CS34CAE43A-050C-4020-A85F-FBC58B9D0481.tmp
7/27/2005 6:47:44 AM     H  5568       C:\WINDOWS\Temp\CS34D63808-6407-46B2-8296-9E6EEBB305FA.tmp
8/8/2005 10:22:06 AM     H  10         C:\WINDOWS\Temp\CS34EA4D47-3000-4AB7-8366-157AD495D8F7.tmp
9/17/2005 9:41:22 AM     H  0          C:\WINDOWS\Temp\CS34F09E6A-062A-42CD-95A1-6FE4AE7A793E.tmp
7/27/2005 1:47:22 PM     H  96         C:\WINDOWS\Temp\CS34F4C98B-765A-4430-9D55-6ECBD228F297.tmp
8/8/2005 10:22:06 AM     H  330        C:\WINDOWS\Temp\CS354831BF-72CF-44A9-952C-861FA1C0EE93.tmp
8/19/2005 7:43:30 AM     H  10         C:\WINDOWS\Temp\CS35656497-DB2A-4C9E-A7D0-666B33A2F80C.tmp
9/9/2005 3:54:20 PM      H  114        C:\WINDOWS\Temp\CS358C52B8-A2DA-45ED-B9AE-3190C94E9B60.tmp
8/8/2005 7:46:02 PM      H  322        C:\WINDOWS\Temp\CS35B588D7-93BE-4FFD-BA88-EB6F979D5DAC.tmp
8/13/2005 11:56:22 AM    H  50         C:\WINDOWS\Temp\CS35D6F647-7E42-4DEB-AFC4-583F53209A38.tmp
8/6/2005 11:02:42 AM     H  5808       C:\WINDOWS\Temp\CS3652EA60-2F82-4037-B86F-7415F57FFE54.tmp
9/9/2005 3:54:20 PM      H  10         C:\WINDOWS\Temp\CS365586A0-4031-44AC-B8A3-59DBFD30427C.tmp
9/9/2005 3:54:20 PM      H  42         C:\WINDOWS\Temp\CS36CB257B-886F-4F9A-9248-316867357360.tmp
8/21/2005 8:29:14 PM     H  1324922    C:\WINDOWS\Temp\CS36D0D01F-3578-4514-A050-263CFED936D8.tmp
8/3/2005 11:55:06 AM     H  3411       C:\WINDOWS\Temp\CS36DAF84F-56A6-4B46-B3E5-F03FBC31BA83.tmp
8/1/2005 8:52:54 PM      H  10         C:\WINDOWS\Temp\CS36DBBAB3-5BC2-402E-BA9E-2E163D8EBF1A.tmp
8/29/2005 4:23:02 PM     H  30         C:\WINDOWS\Temp\CS37247629-252F-4586-AADE-309378B4A401.tmp
8/1/2005 1:44:36 AM      H  97206      C:\WINDOWS\Temp\CS372537C4-32C4-4830-8B88-EF46A7A44315.tmp
8/6/2005 11:34:08 AM     H  42         C:\WINDOWS\Temp\CS37733449-8093-47A1-8088-E9C5247E914F.tmp
9/9/2005 3:54:20 PM      H  10         C:\WINDOWS\Temp\CS3787D4D8-6AB2-49FE-A272-01FB5CB37782.tmp
8/15/2005 4:32:00 AM     H  30         C:\WINDOWS\Temp\CS379C1ADD-02BF-4237-AC3D-1A90D2A219C6.tmp
8/21/2005 8:29:14 PM     H  37532      C:\WINDOWS\Temp\CS37E0FFAE-5760-4059-8631-FFAFE494AAC7.tmp
9/17/2005 9:41:22 AM     H  0          C:\WINDOWS\Temp\CS38415190-7C6F-49DB-BD73-C328238C9C58.tmp
9/17/2005 9:41:24 AM     H  0          C:\WINDOWS\Temp\CS3855B8D5-5D29-4B45-AC06-A9323BDF138A.tmp
8/19/2005 7:43:30 AM     H  124        C:\WINDOWS\Temp\CS386A87D0-3DCF-4E39-9BCF-331CBE251B3C.tmp
8/6/2005 11:03:00 AM     H  10         C:\WINDOWS\Temp\CS387EABD8-7050-4C1D-B356-F9F70DC90350.tmp
9/17/2005 9:41:24 AM     H  0          C:\WINDOWS\Temp\CS388F4C02-AE34-4947-99E3-325B4BC5BD61.tmp
8/6/2005 11:34:08 AM     H  500        C:\WINDOWS\Temp\CS38EC2FCF-1616-4D4B-9C12-BFA68F4168D9.tmp
8/6/2005 11:34:08 AM     H  312        C:\WINDOWS\Temp\CS38FEDD09-6EB5-4286-A7BF-10ABCEC57C22.tmp
8/19/2005 7:43:30 AM     H  10         C:\WINDOWS\Temp\CS3914BD7A-DD7A-4AD1-B37C-E61F3E3E86AC.tmp
8/3/2005 11:55:06 AM     H  2018310    C:\WINDOWS\Temp\CS3915BF67-68AC-4CE7-8AC6-993C03838782.tmp
8/8/2005 10:22:08 AM     H  50         C:\WINDOWS\Temp\CS393867B2-2000-4B4B-94B1-71BA41DC7E66.tmp
8/30/2005 4:03:30 PM     H  310        C:\WINDOWS\Temp\CS39672A3A-0DFE-4374-BF4C-76692B18FBF4.tmp
7/27/2005 1:47:22 PM     H  568        C:\WINDOWS\Temp\CS3967ABC9-6440-4F5B-BB85-11C3D0C6F950.tmp
8/6/2005 11:34:08 AM     H  10         C:\WINDOWS\Temp\CS396E8394-F7BD-4C19-BD89-E84D813B4592.tmp
8/8/2005 10:22:06 AM     H  10         C:\WINDOWS\Temp\CS3972EC25-C99F-4C5F-84C3-1A843927D61C.tmp
8/26/2005 11:55:58 PM    H  10         C:\WINDOWS\Temp\CS39BB4205-9388-4948-932A-45B30045B0E1.tmp
8/30/2005 4:03:30 PM     H  500        C:\WINDOWS\Temp\CS39C436C9-4308-4FE4-90CD-4E3E5525D5F7.tmp
8/8/2005 3:46:26 PM      H  1350       C:\WINDOWS\Temp\CS39CFE282-8D3D-4360-ABE4-89683453B6C0.tmp
8/30/2005 3:03:50 PM     H  35144      C:\WINDOWS\Temp\CS3A1AD980-CD09-4B3A-AE53-A43C1AA659E4.tmp
8/13/2005 11:56:20 AM    H  48         C:\WINDOWS\Temp\CS3A2CB5BE-A4B0-4D58-8A20-759BB0DA7984.tmp
8/1/2005 1:53:08 PM      H  168        C:\WINDOWS\Temp\CS3A2FD437-E8A8-4487-BE9A-9928972CC528.tmp
8/29/2005 6:22:44 PM     H  10         C:\WINDOWS\Temp\CS3A3B3380-6021-475C-A863-AF2DC7FDEBE1.tmp
8/26/2005 11:55:58 PM    H  100        C:\WINDOWS\Temp\CS3A56871B-FB2B-45C4-8AE3-CEA246D1E0E6.tmp
8/3/2005 11:55:06 AM     H  619544     C:\WINDOWS\Temp\CS3A65742A-72B8-4DF3-B54E-0FAC670D6280.tmp
8/1/2005 1:44:36 AM      H  1030002    C:\WINDOWS\Temp\CS3A6BE4DA-8F45-4FC9-A584-4DA75857BEEB.tmp
8/22/2005 2:47:24 AM     H  42         C:\WINDOWS\Temp\CS3A9F059C-01B0-407F-B555-155917EB5200.tmp
8/26/2005 11:55:58 PM    H  14         C:\WINDOWS\Temp\CS3B26376E-1811-4A2D-AF27-E3FCE2605B27.tmp
8/13/2005 11:56:22 AM    H  10         C:\WINDOWS\Temp\CS3B28038E-481F-4B2D-8738-E340581E06EB.tmp
8/22/2005 1:47:48 AM     H  2018310    C:\WINDOWS\Temp\CS3B2DD792-B703-4D10-972E-022FBCB24C1C.tmp
8/8/2005 7:46:02 PM      H  10         C:\WINDOWS\Temp\CS3B3B8BDC-5DE7-4D34-930C-6887B940EFF4.tmp
9/14/2005 7:39:32 AM     H  658        C:\WINDOWS\Temp\CS3B491E01-6867-4BEB-AF95-FF2CE96D876E.tmp
8/30/2005 4:03:36 PM     H  10         C:\WINDOWS\Temp\CS3B5F2AF4-7E5E-41CE-8CA6-1EE039B3F6C4.tmp
8/8/2005 10:22:08 AM     H  120        C:\WINDOWS\Temp\CS3B8F620A-AF57-4D8E-95AE-3413FC732BA9.tmp
9/17/2005 9:41:04 AM     H  0          C:\WINDOWS\Temp\CS3B9D7050-41B4-46E4-8CD4-9BBAF5DB3EFD.tmp
9/14/2005 7:39:32 AM     H  10         C:\WINDOWS\Temp\CS3BA5A3BE-D527-4030-9E59-7DEEFEA3D088.tmp
8/6/2005 11:03:00 AM     H  10         C:\WINDOWS\Temp\CS3BA937C6-4796-4C2C-89D2-773E4EB7AA4C.tmp
8/19/2005 7:43:30 AM     H  10         C:\WINDOWS\Temp\CS3BFBE93C-FC4B-498D-96A4-EB19CE1B7542.tmp
9/17/2005 9:41:24 AM     H  0          C:\WINDOWS\Temp\CS3C0AAC96-8677-4E5A-862B-D8475D754E64.tmp
9/15/2005 3:28:14 PM     H  1077934    C:\WINDOWS\Temp\CS3C45B7DF-DD71-4116-8331-FE99A8143E80.tmp
8/26/2005 2:56:02 PM     H  160        C:\WINDOWS\Temp\CS3C5AB9C9-23AC-4F42-8408-82E62B427209.tmp
8/1/2005 8:52:54 PM      H  10         C:\WINDOWS\Temp\CS3C947604-D24A-4F44-876B-D5DB047AF9C2.tmp
8/22/2005 2:47:24 AM     H  10         C:\WINDOWS\Temp\CS3CA42834-627A-4930-AC79-1F722CF7E46E.tmp
8/6/2005 11:02:42 AM     H  2018310    C:\WINDOWS\Temp\CS3D5C20F5-D778-4DB2-BD61-8F20D40F7DAA.tmp
9/14/2005 7:39:32 AM     H  136        C:\WINDOWS\Temp\CS3D952521-08C5-4378-9385-241C9EB6BE0B.tmp
8/3/2005 11:55:26 AM     H  10         C:\WINDOWS\Temp\CS3DA97FB5-E902-43D4-BD39-B60D12F5BAAB.tmp
8/13/2005 11:56:20 AM    H  324        C:\WINDOWS\Temp\CS3DC817A5-91F0-4AF4-8535-F91BD114B7DB.tmp
9/9/2005 3:54:20 PM      H  10         C:\WINDOWS\Temp\CS3DEAAA45-416C-4C7C-97C0-82CAE1E7EBED.tmp
9/17/2005 9:41:04 AM     H  0          C:\WINDOWS\Temp\CS3DF8C263-BA7A-436E-B7FE-1D1181C2C1BC.tmp
8/6/2005 11:33:54 AM     H  1324922    C:\WINDOWS\Temp\CS3E19485C-A725-403B-BB23-12503581BC50.tmp
8/1/2005 1:53:08 PM      H  37532      C:\WINDOWS\Temp\CS3E33833C-8887-4E5E-AC71-CEC44A87D61C.tmp
8/1/2005 8:52:54 PM      H  500        C:\WINDOWS\Temp\CS3E3CF347-B926-4E13-8F46-96A3A7A27813.tmp
8/3/2005 11:55:26 AM     H  10         C:\WINDOWS\Temp\CS3E4DCD77-1C28-44F6-ADFF-15A6EE27A99E.tmp
7/27/2005 1:47:22 PM     H  10         C:\WINDOWS\Temp\CS3E9E16AF-06D8-4037-8DCE-EAE413081530.tmp
9/17/2005 9:41:20 AM     H  0          C:\WINDOWS\Temp\CS3EC905A1-1821-4A02-A3C5-F3CFC3144E1E.tmp
8/8/2005 7:46:02 PM      H  10         C:\WINDOWS\Temp\CS3EDA65D2-3184-4DB1-B5DE-1EAE6B3F3429.tmp
8/3/2005 11:55:06 AM     H  37532      C:\WINDOWS\Temp\CS3F2224AA-0B4F-446F-B160-8D5EF43568E3.tmp
8/26/2005 2:56:02 PM     H  37532      C:\WINDOWS\Temp\CS3F41A03C-00BF-499E-B2EF-B05E50B8555B.tmp
8/30/2005 4:03:32 PM     H  330        C:\WINDOWS\Temp\CS3F550DB8-A5F1-481B-B1C8-D0117C315DE1.tmp
8/1/2005 1:44:36 AM      H  726        C:\WINDOWS\Temp\CS3F751FF5-19B4-4624-B561-571632568886.tmp
8/1/2005 1:44:36 AM      H  619544     C:\WINDOWS\Temp\CS3F914086-7C30-4D5E-821E-EDD937876039.tmp
8/6/2005 11:34:08 AM     H  10         C:\WINDOWS\Temp\CS3F9A8B1F-B8D5-4978-925B-D1C68F5650C6.tmp
8/30/2005 4:03:32 PM     H  310        C:\WINDOWS\Temp\CS3FA363BB-E166-43D9-8435-1D5DC9FAB9BD.tmp
8/3/2005 11:55:26 AM     H  120        C:\WINDOWS\Temp\CS3FEE48BA-7AA0-40BF-B010-664E21C3175E.tmp
8/8/2005 7:46:04 PM      H  118        C:\WINDOWS\Temp\CS400BDDBB-F98F-4404-B9DF-BD2B510526EA.tmp
8/8/2005 7:46:02 PM      H  10         C:\WINDOWS\Temp\CS4015734E-A990-4B69-A218-9B761B19150E.tmp
8/22/2005 12:29:02 AM    H  124        C:\WINDOWS\Temp\CS40191F80-392A-4D63-A0C4-67C687C632FA.tmp
8/15/2005 4:32:00 AM     H  10         C:\WINDOWS\Temp\CS4032E07F-03DB-4136-A9BD-5945CADA41D5.tmp
9/15/2005 3:28:14 PM     H  23436      C:\WINDOWS\Temp\CS404A548B-CE5A-4222-9814-7AFB7F814B4D.tmp
9/14/2005 7:39:32 AM     H  30         C:\WINDOWS\Temp\CS406EFCD8-2B2E-408E-8D60-635EA05FC61A.tmp
8/6/2005 11:03:00 AM     H  600        C:\WINDOWS\Temp\CS40875EFC-A810-43E3-A21F-F9B7F95A60E4.tmp
8/22/2005 12:29:02 AM    H  30         C:\WINDOWS\Temp\CS40990279-1FDF-467B-9D43-2B147870F9BB.tmp
8/1/2005 1:44:36 AM      H  32         C:\WINDOWS\Temp\CS40EAA520-BF22-422C-9DC2-51885A5237BE.tmp
8/19/2005 7:43:30 AM     H  120        C:\WINDOWS\Temp\CS41372860-E3CC-4EC9-9EA9-956FB3897E92.tmp
8/1/2005 8:52:54 PM      H  10         C:\WINDOWS\Temp\CS4140022D-AD45-436C-B4EE-E77FDB5A1D76.tmp
8/29/2005 6:22:44 PM     H  100        C:\WINDOWS\Temp\CS416F42E9-4C89-410D-B720-F6D3BA114F65.tmp
9/17/2005 9:41:04 AM     H  0          C:\WINDOWS\Temp\CS41718238-0A01-4B20-8DD0-2B14B8B5A7BC.tmp
8/1/2005 8:52:54 PM      H  340        C:\WINDOWS\Temp\CS41969991-8569-490C-B1B8-155052048770.tmp
8/26/2005 11:55:58 PM    H  124        C:\WINDOWS\Temp\CS41ACB920-A48F-4345-AF19-5114910EAE15.tmp
9/17/2005 9:41:24 AM     H  0          C:\WINDOWS\Temp\CS41D470C5-AD14-4E90-BDD7-4A8A9CAE90C4.tmp
8/30/2005 4:03:36 PM     H  10         C:\WINDOWS\Temp\CS41ECC432-0F98-486B-9896-93C4AE8006AC.tmp
8/29/2005 6:22:44 PM     H  10         C:\WINDOWS\Temp\CS41EF245C-FFF7-4434-9F58-3A78BE66DBCF.tmp
8/29/2005 6:22:44 PM     H  408        C:\WINDOWS\Temp\CS429E56C9-2DEC-4D3C-AE88-414A98F57816.tmp
7/27/2005 1:47:22 PM     H  10         C:\WINDOWS\Temp\CS42B98321-3938-41AE-9C90-3C288E547F41.tmp
9/17/2005 9:41:22 AM     H  0          C:\WINDOWS\Temp\CS430CD551-4FC8-4478-9BEA-393076DF5944.tmp
8/1/2005 8:52:54 PM      H  10         C:\WINDOWS\Temp\CS435C61C3-E562-4E02-8E71-120CBB13EEB4.tmp
9/14/2005 7:39:32 AM     H  96         C:\WINDOWS\Temp\CS439070B8-D1FE-4E55-9676-4E572655C63D.tmp
9/9/2005 2:54:50 PM      H  97206      C:\WINDOWS\Temp\CS439B72BC-D4B4-4FE3-B9A0-D359045CCF85.tmp
8/8/2005 7:46:02 PM      H  48         C:\WINDOWS\Temp\CS43C0DB0B-3096-4FC6-A681-44F41C759D90.tmp
8/30/2005 4:03:34 PM     H  480        C:\WINDOWS\Temp\CS43CA792C-284B-4BDA-A01E-7F6C163EFEA0.tmp
8/22/2005 2:47:24 AM     H  100        C:\WINDOWS\Temp\CS43EBA2B3-202F-40A1-A5B7-D29721C98C4B.tmp
8/7/2005 1:22:38 AM      H  81290      C:\WINDOWS\Temp\CS43FB7F32-D78C-4682-B46D-160591DA9A7B.tmp
8/6/2005 11:02:42 AM     H  1030002    C:\WINDOWS\Temp\CS44389A1C-EB1E-40D6-8E39-430C0ECCC47A.tmp
8/19/2005 7:43:30 AM     H  10         C:\WINDOWS\Temp\CS4448002E-C1CF-4B80-BE76-898251B18829.tmp
8/1/2005 1:45:02 AM      H  330388     C:\WINDOWS\Temp\CS444E5E1F-54C0-4576-8B3E-4AFBD8EB2954.tmp
8/3/2005 11:55:26 AM     H  664        C:\WINDOWS\Temp\CS447F55FF-7D9F-4B14-BBB6-66E8338CF0AE.tmp
8/13/2005 11:56:22 AM    H  10         C:\WINDOWS\Temp\CS44806938-113A-48CB-9EEB-A1EFEE092578.tmp
8/30/2005 3:03:50 PM     H  5568       C:\WINDOWS\Temp\CS44C91B6E-7F94-4C5C-AE0F-FD986F58EFD4.tmp
9/17/2005 9:41:22 AM     H  0          C:\WINDOWS\Temp\CS44E61F4C-037D-4DB2-904A-732887591CBB.tmp
8/29/2005 6:22:44 PM     H  10         C:\WINDOWS\Temp\CS450BC081-0251-4A62-896D-CC44DCBC544F.tmp
7/27/2005 6:48:04 AM     H  1219708    C:\WINDOWS\Temp\CS45166110-FE07-4BFF-96D8-5BD465E24DFA.tmp
8/8/2005 10:22:08 AM     H  10         C:\WINDOWS\Temp\CS45167679-918C-4FDB-9361-5305DFCBCD41.tmp
8/1/2005 3:44:16 AM      H  10         C:\WINDOWS\Temp\CS4519CF7B-731A-4AD6-9C72-813BC6FC2E65.tmp
9/15/2005 3:28:14 PM     H  2238222    C:\WINDOWS\Temp\CS45314B24-9BB3-4E47-8DF7-4089350A5FE0.tmp
7/27/2005 6:47:44 AM     H  5808       C:\WINDOWS\Temp\CS45A85FA4-6412-41BA-9788-286087742F71.tmp
7/27/2005 1:47:24 PM     H  10         C:\WINDOWS\Temp\CS45AE9BB3-CC2A-4C81-B463-1ED9EC378E4D.tmp
8/1/2005 1:44:36 AM      H  168        C:\WINDOWS\Temp\CS46463004-0227-4401-B32D-911CDDEEF31D.tmp
9/9/2005 3:54:20 PM      H  100        C:\WINDOWS\Temp\CS464F15B1-6B83-47C4-9F10-053BDC639C2B.tmp
8/8/2005 7:46:02 PM      H  10         C:\WINDOWS\Temp\CS466D16E2-62D3-4CE0-996D-5DCBCE0858F7.tmp
8/6/2005 11:33:54 AM     H  97206      C:\WINDOWS\Temp\CS46804AC7-D210-4424-B65D-232F4A957B5A.tmp
8/22/2005 1:47:48 AM     H  97206      C:\WINDOWS\Temp\CS4688E735-3B93-4A4E-8873-2C0CE8DC2532.tmp
8/1/2005 1:53:26 PM      H  1219708    C:\WINDOWS\Temp\CS46A5BF0D-116E-4897-8BFC-8C859444FC4C.tmp
8/30/2005 3:03:50 PM     H  160        C:\WINDOWS\Temp\CS46B7D40C-DFA0-4A88-885E-24B2AD5160D3.tmp
8/26/2005 11:55:58 PM    H  10         C:\WINDOWS\Temp\CS46FAFE54-4262-4F3A-8F3C-BD13325638FA.tmp
8/26/2005 2:56:02 PM     H  3411       C:\WINDOWS\Temp\CS4723386E-1320-44AD-8032-2199CE2E41E6.tmp
8/3/2005 11:55:26 AM     H  10         C:\WINDOWS\Temp\CS4725E0DE-3051-4303-9FE4-18B9B9EC6B5E.tmp
8/21/2005 8:29:14 PM     H  30         C:\WINDOWS\Temp\CS472FBCD6-87D6-4DC0-ABC5-DC126AA0DF97.tmp
8/3/2005 11:55:26 AM     H  10         C:\WINDOWS\Temp\CS476C6F73-D806-4B1E-824E-2681863B41AA.tmp
8/6/2005 11:34:08 AM     H  10         C:\WINDOWS\Temp\CS47730242-56C7-4595-8E65-672D7355AC75.tmp
8/8/2005 7:46:04 PM      H  10         C:\WINDOWS\Temp\CS47734C26-36BB-4C6C-8F0F-98E52F508F79.tmp
9/15/2005 3:28:14 PM     H  240        C:\WINDOWS\Temp\CS48052471-A624-462A-A026-EDBC6CCF001F.tmp
8/6/2005 11:03:00 AM     H  10         C:\WINDOWS\Temp\CS482AB6BA-CB12-4A6E-82EE-81946AC09E17.tmp
8/22/2005 2:47:24 AM     H  330        C:\WINDOWS\Temp\CS4836FF6C-6D3F-4A44-9BCD-3B0176BEE9F7.tmp
8/6/2005 11:03:00 AM     H  10         C:\WINDOWS\Temp\CS48573E3D-F7C3-4B64-A40A-3D3E7DAF0ACA.tmp
9/9/2005 3:54:20 PM      H  416        C:\WINDOWS\Temp\CS488C7CB9-44D3-4119-AC79-368382675565.tmp
8/6/2005 11:03:00 AM     H  136        C:\WINDOWS\Temp\CS48D9276F-C170-4EA6-BC96-692F256450E6.tmp
8/1/2005 1:45:02 AM      H  81290      C:\WINDOWS\Temp\CS48DBE9CF-B167-40C7-84AF-95361ECC5F4C.tmp
7/27/2005 1:47:22 PM     H  10         C:\WINDOWS\Temp\CS48E1974D-536D-4B62-999B-CBC6C41233B9.tmp
8/30/2005 4:03:38 PM     H  10         C:\WINDOWS\Temp\CS48F07C3E-55A0-440D-BB37-3DFD27600276.tmp
8/13/2005 11:56:20 AM    H  342        C:\WINDOWS\Temp\CS49184043-1CD8-4722-9198-ADFC1B85830D.tmp
8/8/2005 10:22:06 AM     H  312        C:\WINDOWS\Temp\CS491C4360-C641-4D3C-8E3F-2EFD3BA702E4.tmp
9/9/2005 2:54:50 PM      H  240        C:\WINDOWS\Temp\CS496F840B-3BC9-4707-AA03-248B76A1E802.tmp
8/19/2005 4:43:58 AM     H  126        C:\WINDOWS\Temp\CS498D280E-98AF-44BB-A6F6-577C6B30900F.tmp
8/7/2005 1:22:16 AM      H  726        C:\WINDOWS\Temp\CS4993769A-C45B-4246-BC29-29C0D1AE667C.tmp
8/22/2005 2:47:24 AM     H  10         C:\WINDOWS\Temp\CS49CD1374-B932-46A1-AB31-56F22CCEFD2E.tmp
8/22/2005 1:47:48 AM     H  160        C:\WINDOWS\Temp\CS49D06856-88DB-48D3-B84D-8BC5DE136D39.tmp
7/27/2005 1:47:22 PM     H  118        C:\WINDOWS\Temp\CS49D4B070-0895-4EEA-A6E1-955815D39A18.tmp
9/9/2005 3:54:20 PM      H  10         C:\WINDOWS\Temp\CS49DFDAB8-CEC5-4B37-BDE8-B6AE2B1424E2.tmp
8/3/2005 11:55:26 AM     H  324        C:\WINDOWS\Temp\CS49F57288-745F-4AF8-87CD-1EFCB5505A3E.tmp
8/29/2005 6:22:44 PM     H  100        C:\WINDOWS\Temp\CS4A088AC6-FFCB-4CE3-BF74-4AFC3FAFEE24.tmp
8/22/2005 2:47:24 AM     H  10         C:\WINDOWS\Temp\CS4A5D3459-F359-4F8F-A3A6-AC1F19A9BE64.tmp
8/8/2005 10:22:08 AM     H  100        C:\WINDOWS\Temp\CS4A8C744E-6050-4164-8646-EDCA11908C24.tmp
8/22/2005 2:47:24 AM     H  120        C:\WINDOWS\Temp\CS4A9381C9-162B-4185-94FF-B3B77D2BFF62.tmp
8/6/2005 11:03:00 AM     H  10         C:\WINDOWS\Temp\CS4AC02CCE-D978-4BF3-9350-EAE6B8EDB3E1.tmp
8/8/2005 7:46:02 PM      H  14         C:\WINDOWS\Temp\CS4AC7D672-45EC-4AFF-8FB5-FAA7B10601B4.tmp
8/8/2005 7:46:02 PM      H  504        C:\WINDOWS\Temp\CS4AD11F5F-54A7-4257-9C94-C243FB8FB725.tmp
9/9/2005 3:54:20 PM      H  10         C:\WINDOWS\Temp\CS4AE3BD34-A5DB-4094-A342-120E0B6AC80A.tmp
8/15/2005 4:32:00 AM     H  10         C:\WINDOWS\Temp\CS4AECF4A1-8C8E-473D-AE2A-F047AAB27C2C.tmp
9/17/2005 9:41:22 AM     H  0          C:\WINDOWS\Temp\CS4B072AB8-79AC-4D51-A2FE-7C3A25C45808.tmp
8/6/2005 11:03:00 AM     H  660        C:\WINDOWS\Temp\CS4B2DD4C8-3CE4-460D-8E37-68F4212AA377.tmp
8/1/2005 1:44:36 AM      H  528154     C:\WINDOWS\Temp\CS4B321E5A-8D68-4123-9FD6-92AD62154F08.tmp
7/27/2005 6:48:06 AM     H  1565690    C:\WINDOWS\Temp\CS4B5D643C-065C-4510-8062-988FE48F9DAB.tmp
8/30/2005 3:04:16 PM     H  330388     C:\WINDOWS\Temp\CS4BACD89F-900F-435D-9A82-8BFB8834CA04.tmp
8/30/2005 4:03:38 PM     H  120        C:\WINDOWS\Temp\CS4BBFE83E-FDE0-4EDD-9290-8DDA7AED2A98.tmp
8/1/2005 1:53:08 PM      H  1350       C:\WINDOWS\Temp\CS4BE03591-DEEC-44D7-BEC6-1688793A3C1F.tmp
8/8/2005 10:22:06 AM     H  10         C:\WINDOWS\Temp\CS4BECF4DC-E1A3-45BF-9418-6D1C25E88893.tmp
8/1/2005 8:52:54 PM      H  10         C:\WINDOWS\Temp\CS4BEFBBF5-7C0B-4A42-9711-2328EFFC4B65.tmp
8/8/2005 7:46:04 PM      H  10         C:\WINDOWS\Temp\CS4C074F30-0183-43EE-A7FD-D8C70C4DBE02.tmp
8/29/2005 4:23:02 PM     H  66056      C:\WINDOWS\Temp\CS4C21EC22-2636-4DB9-808E-B501C029CBE4.tmp
8/19/2005 7:43:30 AM     H  414        C:\WINDOWS\Temp\CS4C25DA00-2718-4224-8031-DFA064EA066E.tmp
8/30/2005 4:03:38 PM     H  10         C:\WINDOWS\Temp\CS4C4A0C0A-7DBF-428D-AF04-64018823F6CC.tmp
8/1/2005 1:44:36 AM      H  2018310    C:\WINDOWS\Temp\CS4C4F5EF6-F788-4A29-B56C-6AA5BA7D98FC.tmp
8/15/2005 4:31:44 AM     H  270        C:\WINDOWS\Temp\CS4C5063E7-F051-4134-8CAA-35A8D72D2E4E.tmp
8/1/2005 8:52:54 PM      H  42         C:\WINDOWS\Temp\CS4C6D3AA7-EDB3-4757-9905-08527CD4E482.tmp
9/17/2005 9:41:22 AM     H  0          C:\WINDOWS\Temp\CS4C80DEA5-3127-46C0-A50D-346EC6281F93.tmp
8/1/2005 8:52:54 PM      H  120        C:\WINDOWS\Temp\CS4C8E0BFE-1241-4C49-BDDA-F1D1F1DC0057.tmp
8/26/2005 2:56:02 PM     H  126        C:\WINDOWS\Temp\CS4C941F79-2B58-4EDA-AF7C-057F9E0758AB.tmp
9/9/2005 3:54:20 PM      H  10         C:\WINDOWS\Temp\CS4CC3516B-3A96-435D-AC63-564C6DD2606F.tmp
8/3/2005 11:55:16 AM     H  69542      C:\WINDOWS\Temp\CS4CC40EB3-293A-472C-99E5-8209567F4465.tmp
8/29/2005 6:22:44 PM     H  504        C:\WINDOWS\Temp\CS4CD4A478-50BA-4CA4-8865-36E2279849C2.tmp
8/6/2005 11:34:08 AM     H  100        C:\WINDOWS\Temp\CS4CF4D203-4C93-4372-B444-5BA5C95E638D.tmp
9/14/2005 7:39:32 AM     H  120        C:\WINDOWS\Temp\CS4D3BE3BD-516B-4385-B1D1-7874377DD98F.tmp
9/9/2005 3:54:20 PM      H  10         C:\WINDOWS\Temp\CS4D50E383-7537-46AC-8E08-F1B83A94AF80.tmp
8/1/2005 1:44:52 AM      H  69542      C:\WINDOWS\Temp\CS4D644E25-2EEF-4E89-803C-2C893E2181A6.tmp
8/6/2005 11:03:00 AM     H  100        C:\WINDOWS\Temp\CS4E390F05-F8C6-46A1-BF5E-E2A89E280477.tmp
8/21/2005 8:29:14 PM     H  97206      C:\WINDOWS\Temp\CS4E3E5C18-4937-4703-B4B7-829FA9BD8EE9.tmp
8/30/2005 3:03:50 PM     H  30         C:\WINDOWS\Temp\CS4E44819D-4172-4AD2-BC72-73D6AE553231.tmp
8/3/2005 11:55:06 AM     H  35144      C:\WINDOWS\Temp\CS4E5FDB62-0794-40F6-B692-8D0256128464.tmp
8/22/2005 1:47:48 AM     H  1324922    C:\WINDOWS\Temp\CS4E8C7123-A4B4-4161-BC35-236FB6980658.tmp
8/13/2005 11:56:22 AM    H  102        C:\WINDOWS\Temp\CS4EA2E4B3-8261-4335-8C78-CE563374F3FB.tmp
9/15/2005 3:28:14 PM     H  748        C:\WINDOWS\Temp\CS4ED9B4C3-30F0-4523-BC24-A0DAB22845AF.tmp
8/30/2005 4:03:32 PM     H  120        C:\WINDOWS\Temp\CS4F34994F-ED49-4771-A22C-8258D685787C.tmp
8/3/2005 11:55:26 AM     H  312        C:\WINDOWS\Temp\CS4F40A74D-9C5C-4C9C-AA5F-5293C853EFC3.tmp
8/21/2005 8:29:36 PM     H  1565690    C:\WINDOWS\Temp\CS4F421162-A253-4011-B4CB-C029CA627DD7.tmp
8/8/2005 3:46:26 PM      H  97206      C:\WINDOWS\Temp\CS4F478F7F-4B68-42BA-A435-E637F2B3409E.tmp
8/3/2005 11:55:06 AM     H  97206      C:\WINDOWS\Temp\CS4F5C26C4-A0ED-4832-9DEC-0167B3802F06.tmp
8/29/2005 4:23:02 PM     H  3411       C:\WINDOWS\Temp\CS4F8F76B7-2A1E-4C18-8912-DA1683665652.tmp
8/22/2005 12:29:02 AM    H  322        C:\WINDOWS\Temp\CS4FBC8E01-A418-4BB5-A22C-078AFDDF1BFF.tmp
8/29/2005 6:22:44 PM     H  10         C:\WINDOWS\Temp\CS4FC8AC4A-430C-4EC1-A4A2-F6D259A42875.tmp
9/9/2005 2:54:50 PM      H  5808       C:\WINDOWS\Temp\CS4FC9FCB8-14DD-4BF2-BBD6-AFE348B3BA18.tmp
8/22/2005 12:29:02 AM    H  42         C:\WINDOWS\Temp\CS4FCCE840-150F-4EAB-8098-A81063533701.tmp
9/15/2005 3:28:14 PM     H  556850     C:\WINDOWS\Temp\CS4FEA186D-0B25-461C-AF3E-6AFC4222D1EB.tmp
9/14/2005 7:39:32 AM     H  102        C:\WINDOWS\Temp\CS50470EE8-1BF3-4442-BC97-0BFB1AB3AA79.tmp
9/9/2005 2:54:50 PM      H  726        C:\WINDOWS\Temp\CS5068CF75-CCD2-4D84-9394-586C07B11A03.tmp
8/19/2005 7:43:30 AM     H  10         C:\WINDOWS\Temp\CS51298B86-C32E-417C-AEA6-8EBCEB885418.tmp
9/9/2005 3:54:20 PM      H  10         C:\WINDOWS\Temp\CS51312120-0619-4DB9-81E3-B71EA92ADAC8.tmp
9/17/2005 9:41:24 AM     H  0          C:\WINDOWS\Temp\CS513337F7-84CD-484D-8787-017C681A4314.tmp
8/6/2005 11:03:00 AM     H  10         C:\WINDOWS\Temp\CS515FD748-2BE6-4E57-B5ED-B8141CDE8468.tmp
8/30/2005 4:03:36 PM     H  100        C:\WINDOWS\Temp\CS51AE8326-F85E-4706-9B64-DE9C9C795189.tmp
9/17/2005 9:41:00 AM     H  0          C:\WINDOWS\Temp\CS51F97162-5B18-42BB-9D47-1472BE655F9D.tmp
8/3/2005 11:55:26 AM     H  10         C:\WINDOWS\Temp\CS5200BDB8-8858-428B-8EB0-A3948FA819F3.tmp
8/22/2005 1:48:06 AM     H  81290      C:\WINDOWS\Temp\CS5228222E-B5AB-427F-8006-30D77DF891A5.tmp
8/29/2005 4:23:02 PM     H  35144      C:\WINDOWS\Temp\CS52336FE4-3EFB-4D47-8CE3-DE25ED34B658.tmp
8/1/2005 1:53:08 PM      H  126        C:\WINDOWS\Temp\CS524E6902-43CA-45DD-A898-85A7C8BD661E.tmp
9/17/2005 9:41:24 AM     H  0          C:\WINDOWS\Temp\CS525FC6E5-F748-481C-8275-D1D21C9E00F3.tmp
9/15/2005 3:28:14 PM     H  160        C:\WINDOWS\Temp\CS5270CD38-61F2-42FF-A57C-16EDB6F7DF18.tmp
8/30/2005 4:03:34 PM     H  10         C:\WINDOWS\Temp\CS5271D044-983C-4D81-A824-2278285EAD59.tmp
8/15/2005 4:32:00 AM     H  100        C:\WINDOWS\Temp\CS52A7BCEA-4907-423F-A687-7FCCB4C1117F.tmp
8/22/2005 1:47:48 AM     H  5568       C:\WINDOWS\Temp\CS52A90D24-AAC3-4DD3-90B3-88E10954C7C2.tmp
8/8/2005 3:46:26 PM      H  5808       C:\WINDOWS\Temp\CS52E68989-DEDE-4E77-A971-DFDE8F65A99E.tmp
8/13/2005 11:56:20 AM    H  10         C:\WINDOWS\Temp\CS

Hi,
Download CleanUp! and install it. Run it, click "Options" and here move the "Quick Setup" slider to Thorough Cleaning. Now, if you have any bookmarks/favorites, then uncheck the option Delete Favorite Places/Bookmarks and then click "OK". In the main window, click "CleanUp!" button to start cleaning. After it completes, restart the PC. Perform an online virus scan at Panda ActiveScan with the "Disinfection" option enabled. Save the log file of this scan and please post it back.

Will this get rid of PSGUARD? Cause my Etrustpestpatrol always picks it up, it says Trojan.win32.startpage.ie or something and then I look at it and its in my hkey_machine_software/psguard.

Hi,
Panda ActiveScan is an online virus scanner, and it removes most of the spyware. If it cant remove them, it gives the names of "bad" files so that we can manually delete them. Click on the "Scan your PC" button in the above provided Panda link.


CleanUp is a very good tool to remove junk files. I can see that there are a lot of files in Temp folder. These files can be related to spyware, please use CleanUp to thoroughly clean the system.

Okay well, It didn't disinfect them so, I guess it couldn't delete them, so here you go, ;)

Incident Status Location

Spyware:spyware/smitfraud No disinfected C:\WINDOWS\uninstIU.exe
Adware:Adware/Popuper No disinfected C:\WINDOWS\system32\hp7BF.tmp

My computer is also acting a little slower then normal.... :-| It seems my computer is always having problems now, lol.

Hi,
Open a new file in NotePad, and copy the contents of the below "Quote" box to NotePad:-

cd %windir%
attrib -s -r -h uninstIU.exe
del uninstIU.exe
cd system32
attrib -s -r -h hp7BF.tmp
del hp7BF.tmp
cd %windir%
cd Temp
attrib -s -r -h *.*
del *.*

Go to File Menu (in NotePad) > Save As and type the filename as Test.BAT and save the file. Exit from NotePad.

Double-click on the Test.BAT file that was created earlier, a DOS type window should open and close by itself.


Restart the PC, and please post a new WinPFind log.

Alright, just wait for me, it won't be long.

Okay, thanks for guiding me through this whole mess, and heres the log.

WARNING: not all files found by this scanner are bad. Consult with a knowledgable person before proceeding.


If you see a message in the titlebar saying "Not responding..." you can ignore it. Windows somethimes displays this message due to the high volume of disk I/O. As long as the hard disk light is flashing, the program is still working properly.


»»»»»»»»»»»»»»»»» Windows OS and Versions »»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»
Product Name: Microsoft Windows XP    Current Build: Service Pack 2    Current Build Number: 2600
Internet Explorer Version: 6.0.2900.2180


»»»»»»»»»»»»»»»»» Checking Selected Standard Folders »»»»»»»»»»»»»»»»»»»»


Checking %SystemDrive% folder...


Checking %ProgramFilesDir% folder...


Checking %WinDir% folder...
PECompact2           8/29/2005 11:37:02 PM       15707121   C:\WINDOWS\lpt$vpn.809
qoologic             8/29/2005 11:37:02 PM       15707121   C:\WINDOWS\lpt$vpn.809
SAHAgent             8/29/2005 11:37:02 PM       15707121   C:\WINDOWS\lpt$vpn.809
UPX!                 5/3/2005 11:44:44 AM        25157      C:\WINDOWS\RMAgentOutput.dll
UPX!                 1/10/2005 4:17:24 PM        170053     C:\WINDOWS\tsc.exe
PECompact2           8/29/2005 11:37:02 PM       15707121   C:\WINDOWS\VPTNFILE.809
qoologic             8/29/2005 11:37:02 PM       15707121   C:\WINDOWS\VPTNFILE.809
SAHAgent             8/29/2005 11:37:02 PM       15707121   C:\WINDOWS\VPTNFILE.809
UPX!                 2/18/2005 6:40:14 PM        1044560    C:\WINDOWS\vsapi32.dll
aspack               2/18/2005 6:40:14 PM        1044560    C:\WINDOWS\vsapi32.dll


Checking %System% folder...
aspack               3/18/2005 5:19:58 PM        2337488    C:\WINDOWS\SYSTEM32\d3dx9_25.dll
PEC2                 8/23/2001 5:00:00 AM        41397      C:\WINDOWS\SYSTEM32\dfrg.msc
PTech                8/29/2005 1:27:12 PM        520968     C:\WINDOWS\SYSTEM32\LegitCheckControl.DLL
aspack               8/4/2004 12:56:38 AM        708096     C:\WINDOWS\SYSTEM32\ntdll.dll
Umonitor             8/4/2004 12:56:46 AM        657920     C:\WINDOWS\SYSTEM32\rasdlg.dll
winsync              8/23/2001 5:00:00 AM        1309184    C:\WINDOWS\SYSTEM32\wbdbase.deu


Checking %System%\Drivers folder and sub-folders...
PTech                8/3/2004 10:41:38 PM        1309184    C:\WINDOWS\SYSTEM32\drivers\mtlstrm.sys


Items found in C:\WINDOWS\SYSTEM32\drivers\etc\hosts



Checking the Windows folder and sub-folders for system and hidden files within the last 60 days...
9/18/2005 12:45:56 PM     S 2048       C:\WINDOWS\bootstat.dat
9/8/2005 10:27:54 AM     H  54156      C:\WINDOWS\QTFont.qfn
7/21/2005 7:48:26 PM    RH  749        C:\WINDOWS\WindowsShell.Manifest
7/21/2005 7:48:32 PM     H  65         C:\WINDOWS\Downloaded Program Files\desktop.ini
7/21/2005 7:49:18 PM     HS 67         C:\WINDOWS\Fonts\desktop.ini
8/8/2005 11:57:58 AM     H  10820      C:\WINDOWS\Help\update.GID
7/21/2005 7:48:34 PM     H  65         C:\WINDOWS\Offline Web Pages\desktop.ini
7/21/2005 7:48:54 PM    RHS 727        C:\WINDOWS\PCHealth\HelpCtr\PackageStore\package_1.cab
7/21/2005 7:48:54 PM    RHS 19854      C:\WINDOWS\PCHealth\HelpCtr\PackageStore\package_2.cab
7/21/2005 7:48:54 PM    RHS 243124     C:\WINDOWS\PCHealth\HelpCtr\PackageStore\package_3.cab
7/21/2005 8:14:16 PM    RHS 305145     C:\WINDOWS\PCHealth\HelpCtr\PackageStore\package_7.cab
7/21/2005 8:16:04 PM    RHS 68327      C:\WINDOWS\PCHealth\HelpCtr\PackageStore\package_8.cab
7/21/2005 7:49:56 PM     H  229376     C:\WINDOWS\repair\ntuser.dat
7/21/2005 7:48:26 PM    RH  749        C:\WINDOWS\system32\cdplayer.exe.manifest
7/21/2005 7:48:32 PM    RH  488        C:\WINDOWS\system32\logonui.exe.manifest
7/21/2005 7:48:26 PM    RH  749        C:\WINDOWS\system32\ncpa.cpl.manifest
7/21/2005 7:48:26 PM    RH  749        C:\WINDOWS\system32\nwc.cpl.manifest
7/21/2005 7:48:26 PM    RH  749        C:\WINDOWS\system32\sapi.cpl.manifest
7/21/2005 7:48:32 PM    RH  488        C:\WINDOWS\system32\WindowsLogon.manifest
7/21/2005 7:48:26 PM    RH  749        C:\WINDOWS\system32\wuaucpl.cpl.manifest
9/18/2005 12:47:06 PM    H  1024       C:\WINDOWS\system32\config\default.LOG
9/18/2005 12:45:58 PM    H  1024       C:\WINDOWS\system32\config\SAM.LOG
9/18/2005 12:47:06 PM    H  1024       C:\WINDOWS\system32\config\SECURITY.LOG
9/18/2005 12:51:20 PM    H  1024       C:\WINDOWS\system32\config\software.LOG
9/18/2005 12:47:40 PM    H  1024       C:\WINDOWS\system32\config\system.LOG
7/21/2005 12:34:02 PM    H  1024       C:\WINDOWS\system32\config\TempKey.LOG
7/21/2005 12:34:02 PM    H  1024       C:\WINDOWS\system32\config\userdiff.LOG
7/21/2005 12:37:36 PM    HS 62         C:\WINDOWS\system32\config\systemprofile\Application Data\desktop.ini
7/21/2005 8:16:04 PM      S 558        C:\WINDOWS\system32\config\systemprofile\Application Data\Microsoft\CryptnetUrlCache\Content\E6024EAC88E6B6165D49FE3C95ADD735
7/21/2005 8:16:04 PM      S 144        C:\WINDOWS\system32\config\systemprofile\Application Data\Microsoft\CryptnetUrlCache\MetaData\E6024EAC88E6B6165D49FE3C95ADD735
7/21/2005 12:37:36 PM    HS 62         C:\WINDOWS\system32\config\systemprofile\Local Settings\desktop.ini
7/21/2005 7:48:58 PM     HS 113        C:\WINDOWS\system32\config\systemprofile\Local Settings\History\desktop.ini
7/21/2005 7:48:58 PM     HS 113        C:\WINDOWS\system32\config\systemprofile\Local Settings\History\History.IE5\desktop.ini
7/21/2005 7:48:58 PM     HS 67         C:\WINDOWS\system32\config\systemprofile\Local Settings\Temporary Internet Files\desktop.ini
7/21/2005 7:48:58 PM     HS 67         C:\WINDOWS\system32\config\systemprofile\Local Settings\Temporary Internet Files\Content.IE5\desktop.ini
7/21/2005 7:48:58 PM     HS 67         C:\WINDOWS\system32\config\systemprofile\Local Settings\Temporary Internet Files\Content.IE5\C9OHB233\desktop.ini
7/21/2005 7:48:58 PM     HS 67         C:\WINDOWS\system32\config\systemprofile\Local Settings\Temporary Internet Files\Content.IE5\GXIJSHIF\desktop.ini
7/21/2005 7:48:58 PM     HS 67         C:\WINDOWS\system32\config\systemprofile\Local Settings\Temporary Internet Files\Content.IE5\QFAI2UBJ\desktop.ini
7/21/2005 7:48:58 PM     HS 67         C:\WINDOWS\system32\config\systemprofile\Local Settings\Temporary Internet Files\Content.IE5\ULTDCX7Y\desktop.ini
7/21/2005 7:48:34 PM     HS 181        C:\WINDOWS\system32\config\systemprofile\SendTo\desktop.ini
7/21/2005 12:37:36 PM    HS 62         C:\WINDOWS\system32\config\systemprofile\Start Menu\desktop.ini
7/21/2005 7:49:50 PM     HS 206        C:\WINDOWS\system32\config\systemprofile\Start Menu\Programs\desktop.ini
7/21/2005 7:49:50 PM     HS 482        C:\WINDOWS\system32\config\systemprofile\Start Menu\Programs\Accessories\desktop.ini
7/21/2005 7:49:50 PM     HS 348        C:\WINDOWS\system32\config\systemprofile\Start Menu\Programs\Accessories\Accessibility\desktop.ini
7/21/2005 7:49:50 PM     HS 84         C:\WINDOWS\system32\config\systemprofile\Start Menu\Programs\Accessories\Entertainment\desktop.ini
7/21/2005 7:49:50 PM     HS 84         C:\WINDOWS\system32\config\systemprofile\Start Menu\Programs\Startup\desktop.ini
7/21/2005 8:29:14 PM     HS 388        C:\WINDOWS\system32\Microsoft\Protect\S-1-5-18\User\d9db54d4-1353-4451-b809-b80755aa36be
7/21/2005 8:29:14 PM     HS 24         C:\WINDOWS\system32\Microsoft\Protect\S-1-5-18\User\Preferred
9/18/2005 12:46:00 PM    H  6          C:\WINDOWS\Tasks\SA.DAT
9/18/2005 12:47:22 PM    H  0          C:\WINDOWS\Temp\CS079E91F5-EA23-44A3-AFE5-067B0541DA0D.tmp
9/18/2005 12:47:22 PM    H  0          C:\WINDOWS\Temp\CS09367E49-FB77-4253-8423-A682FCC35699.tmp
9/18/2005 12:47:22 PM    H  0          C:\WINDOWS\Temp\CS0ACB939B-772C-48E1-AD93-4F661FA7D70D.tmp
9/18/2005 12:47:22 PM    H  0          C:\WINDOWS\Temp\CS0D3F9C93-26EA-4AB0-822F-2897606ADA41.tmp
9/18/2005 12:47:22 PM    H  0          C:\WINDOWS\Temp\CS14E22178-8260-4A89-8A6A-3246C1A3D6AB.tmp
9/18/2005 12:47:22 PM    H  0          C:\WINDOWS\Temp\CS1818A08B-D5C3-4C0B-B853-B2D9A006C59D.tmp
9/18/2005 12:47:22 PM    H  0          C:\WINDOWS\Temp\CS1934FEEC-A114-4CB2-BD7A-6F93A1456AAB.tmp
9/18/2005 12:46:36 PM    H  0          C:\WINDOWS\Temp\CS1AB7582B-04C4-47A6-9764-06B54686CDD3.tmp
9/18/2005 12:46:36 PM    H  0          C:\WINDOWS\Temp\CS1ABA4452-AD30-4C27-A314-03764738141C.tmp
9/18/2005 12:46:36 PM    H  0          C:\WINDOWS\Temp\CS1E988164-6C25-485F-AA9A-7C650D1FF535.tmp
9/18/2005 12:47:22 PM    H  0          C:\WINDOWS\Temp\CS1FDDB43C-88C7-4FC8-8E06-46CF43D094CB.tmp
9/18/2005 12:47:22 PM    H  0          C:\WINDOWS\Temp\CS1FEE919B-02B2-408B-97C4-6844D3B256A3.tmp
9/18/2005 12:46:36 PM    H  0          C:\WINDOWS\Temp\CS2077BFBB-7E74-4C1B-AC2D-E62C2F872027.tmp
9/18/2005 12:46:36 PM    H  0          C:\WINDOWS\Temp\CS249D7BFE-0486-42DA-8F3A-33351CEC8F90.tmp
9/18/2005 12:47:22 PM    H  0          C:\WINDOWS\Temp\CS27284E79-F7D9-4249-BAC3-474893C7E7EF.tmp
9/18/2005 12:47:22 PM    H  0          C:\WINDOWS\Temp\CS2B2B6076-A17D-4921-91BD-86B517BA92F3.tmp
9/18/2005 12:46:36 PM    H  0          C:\WINDOWS\Temp\CS2CB9DE7D-EE2C-4092-B4A6-624401A05635.tmp
9/18/2005 12:47:22 PM    H  0          C:\WINDOWS\Temp\CS2D257754-5A1F-402D-9912-32136F5DE06F.tmp
9/18/2005 12:47:22 PM    H  0          C:\WINDOWS\Temp\CS2F1144BC-DDF3-4B39-84F2-1AA813BF708C.tmp
9/18/2005 12:47:22 PM    H  0          C:\WINDOWS\Temp\CS2FC6A3E4-DCF8-4252-916E-59360408BAC7.tmp
9/18/2005 12:46:36 PM    H  0          C:\WINDOWS\Temp\CS3039545E-7CA9-45E8-910D-B783415CEB92.tmp
9/18/2005 12:47:22 PM    H  0          C:\WINDOWS\Temp\CS31C392BC-6E4C-4565-812C-521F6FE39896.tmp
9/18/2005 12:47:22 PM    H  0          C:\WINDOWS\Temp\CS31E717B8-47D3-47E8-BEB4-74BCE8D0E1BA.tmp
9/18/2005 12:47:22 PM    H  0          C:\WINDOWS\Temp\CS335AD8C0-FB87-4112-8D0C-935843CEEEC2.tmp
9/18/2005 12:47:22 PM    H  0          C:\WINDOWS\Temp\CS376A1C6A-4FAF-4E64-A013-2B4EF6B0F4AB.tmp
9/18/2005 12:46:36 PM    H  0          C:\WINDOWS\Temp\CS399B33D1-99B5-491D-8A5D-8541237E00C2.tmp
9/18/2005 12:47:22 PM    H  0          C:\WINDOWS\Temp\CS39A7DC0B-E038-46ED-BF78-80A196632DFA.tmp
9/18/2005 12:46:48 PM    H  0          C:\WINDOWS\Temp\CS39BF6B79-A085-43F5-9E83-0CB03AD964F2.tmp
9/18/2005 12:46:36 PM    H  0          C:\WINDOWS\Temp\CS3CA34F7B-8CCC-4F46-928B-B4EA07A087F0.tmp
9/18/2005 12:46:36 PM    H  0          C:\WINDOWS\Temp\CS3CDBE6DC-E086-46A6-BF75-26E8C5C38570.tmp
9/18/2005 12:47:22 PM    H  0          C:\WINDOWS\Temp\CS428EB9C8-25D6-475C-9045-7EC42898094D.tmp
9/18/2005 12:46:36 PM    H  0          C:\WINDOWS\Temp\CS440FA121-FAEC-4698-86C2-04E9EFF1F2BC.tmp
9/18/2005 12:47:22 PM    H  0          C:\WINDOWS\Temp\CS44109F81-A4F6-4A89-B9A0-93D143955542.tmp
9/18/2005 12:47:22 PM    H  0          C:\WINDOWS\Temp\CS44EEBD5F-293E-4A43-A3FC-346AA443A75A.tmp
9/18/2005 12:47:28 PM    H  0          C:\WINDOWS\Temp\CS49B434FE-9771-4686-9CFA-0219F476874F.tmp
9/18/2005 12:47:22 PM    H  0          C:\WINDOWS\Temp\CS4C964E46-A9FF-4055-9845-B4420CFC5C5F.tmp
9/18/2005 12:46:36 PM    H  0          C:\WINDOWS\Temp\CS4D333290-CA42-49A4-B47F-7720F9514A17.tmp
9/18/2005 12:47:22 PM    H  0          C:\WINDOWS\Temp\CS4FF12148-E39E-4247-BF13-4ED3A3863569.tmp
9/18/2005 12:47:22 PM    H  0          C:\WINDOWS\Temp\CS506374A1-F9C4-45A0-A23D-36CD253F1FA7.tmp
9/18/2005 12:46:36 PM    H  0          C:\WINDOWS\Temp\CS54690E4C-5235-4974-8207-C2F1E3D85910.tmp
9/18/2005 12:47:22 PM    H  0          C:\WINDOWS\Temp\CS591D56FB-7080-4560-A37B-F6EDB24BA439.tmp
9/18/2005 12:46:36 PM    H  0          C:\WINDOWS\Temp\CS5C6279F8-3175-442F-B543-DA84F92559A8.tmp
9/18/2005 12:47:22 PM    H  0          C:\WINDOWS\Temp\CS5CD9B950-BC02-4499-B3D4-4763D78C7914.tmp
9/18/2005 12:47:22 PM    H  0          C:\WINDOWS\Temp\CS5ED9D316-6905-471E-AC16-A3FFFC35ED59.tmp
9/18/2005 12:47:22 PM    H  0          C:\WINDOWS\Temp\CS63E8D034-EC96-4867-AA52-BA922F19E266.tmp
9/18/2005 12:47:22 PM    H  0          C:\WINDOWS\Temp\CS6487D2ED-0DAF-4336-8B77-8AEE778C7F3C.tmp
9/18/2005 12:46:36 PM    H  0          C:\WINDOWS\Temp\CS65F13EAE-FFD5-47E8-85B1-026295D1C973.tmp
9/18/2005 12:47:22 PM    H  0          C:\WINDOWS\Temp\CS662AB783-0F8F-4517-A9FB-3651F4D0541C.tmp
9/18/2005 12:46:36 PM    H  0          C:\WINDOWS\Temp\CS67A3A072-8700-46C4-A6ED-0FF92C66C8DF.tmp
9/18/2005 12:47:22 PM    H  0          C:\WINDOWS\Temp\CS68ACDB72-EF06-4E15-993E-C26E61112F27.tmp
9/18/2005 12:46:36 PM    H  0          C:\WINDOWS\Temp\CS69CD4158-0736-4994-87C5-E67609AE5983.tmp
9/18/2005 12:47:22 PM    H  0          C:\WINDOWS\Temp\CS6AD39BD4-209F-4747-8BE3-D49FE0CA5098.tmp
9/18/2005 12:47:28 PM    H  0          C:\WINDOWS\Temp\CS6E2069E7-AFA9-45AE-BBCE-615A361DE014.tmp
9/18/2005 12:47:22 PM    H  0          C:\WINDOWS\Temp\CS6ED3B683-AE65-47BB-B429-A48A66F216DC.tmp
9/18/2005 12:47:22 PM    H  0          C:\WINDOWS\Temp\CS78C44681-FDF7-45C9-BD67-C55D5F6B56CF.tmp
9/18/2005 12:47:28 PM    H  0          C:\WINDOWS\Temp\CS79BE0AF9-2FA2-4E03-AD12-2EED2806A498.tmp
9/18/2005 12:46:36 PM    H  0          C:\WINDOWS\Temp\CS7A437CED-37E0-4B0A-B77B-ABAA6A5B11B9.tmp
9/18/2005 12:47:22 PM    H  0          C:\WINDOWS\Temp\CS7AF9B617-A96B-4EE8-BD8B-848FE2F1253C.tmp
9/18/2005 12:47:22 PM    H  0          C:\WINDOWS\Temp\CS81787687-3051-4E9E-9A8D-1C973C52D8CB.tmp
9/18/2005 12:47:22 PM    H  0          C:\WINDOWS\Temp\CS86D96F2C-87ED-42BB-AF8F-FBB593527DEB.tmp
9/18/2005 12:47:22 PM    H  0          C:\WINDOWS\Temp\CS8A16C4BF-2B7B-4002-AF1F-3A03C0C2B9F5.tmp
9/18/2005 12:47:22 PM    H  0          C:\WINDOWS\Temp\CS8E2841D3-079E-42CA-A4C8-B0270387545A.tmp
9/18/2005 12:47:22 PM    H  0          C:\WINDOWS\Temp\CS909B876C-919E-42EC-AE45-380042464C53.tmp
9/18/2005 12:47:22 PM    H  0          C:\WINDOWS\Temp\CS925C0093-1E94-45B7-9E41-2E3D3ADA63DE.tmp
9/18/2005 12:47:22 PM    H  0          C:\WINDOWS\Temp\CS93BA3246-C8DC-469A-8AA6-0F7D6996C5CD.tmp
9/18/2005 12:46:36 PM    H  0          C:\WINDOWS\Temp\CS976F5E88-A763-47C3-8960-B89DC7856462.tmp
9/18/2005 12:46:36 PM    H  0          C:\WINDOWS\Temp\CS9ACA02DF-F960-4343-9BD1-7B2A0FF28D26.tmp
9/18/2005 12:47:22 PM    H  0          C:\WINDOWS\Temp\CSA81333F0-9137-4C92-8635-35D3E5E2907B.tmp
9/18/2005 12:46:36 PM    H  0          C:\WINDOWS\Temp\CSA874905B-00D7-4915-8675-B6A2B9647768.tmp
9/18/2005 12:47:22 PM    H  0          C:\WINDOWS\Temp\CSAED01BF6-2E46-4427-B69E-E3F8BCAB3472.tmp
9/18/2005 12:47:22 PM    H  0          C:\WINDOWS\Temp\CSAF0110D5-B882-4F89-9537-5179D8C728A3.tmp
9/18/2005 12:47:22 PM    H  0          C:\WINDOWS\Temp\CSAF2BFC28-3A13-468D-AD18-CC736A489FF2.tmp
9/18/2005 12:47:22 PM    H  0          C:\WINDOWS\Temp\CSAFDF185D-AC2D-4A85-B42F-A8948A49A482.tmp
9/18/2005 12:47:22 PM    H  0          C:\WINDOWS\Temp\CSB077CC8D-148F-496B-9E28-83F1ECCAC8B6.tmp
9/18/2005 12:47:22 PM    H  0          C:\WINDOWS\Temp\CSB8E3DF12-3387-4498-AE25-BC6CBDF824DA.tmp
9/18/2005 12:47:22 PM    H  0          C:\WINDOWS\Temp\CSB8F4F8F7-620F-4D79-9DF7-6FD0D2BAC1DE.tmp
9/18/2005 12:47:28 PM    H  0          C:\WINDOWS\Temp\CSBA3DA8B7-96D8-4D61-ACA1-7DDED3E43366.tmp
9/18/2005 12:47:22 PM    H  0          C:\WINDOWS\Temp\CSBBD9463F-2874-401B-9910-040F91A5BA09.tmp
9/18/2005 12:47:22 PM    H  0          C:\WINDOWS\Temp\CSC08D917C-762C-4C19-8763-DFB0BE1FD1CD.tmp
9/18/2005 12:47:22 PM    H  0          C:\WINDOWS\Temp\CSC31325FA-BBD2-4EFC-B1FF-2FA5FE4AC7D5.tmp
9/18/2005 12:47:22 PM    H  0          C:\WINDOWS\Temp\CSC5AB991E-8D55-497E-A311-B71B9B60C462.tmp
9/18/2005 12:46:36 PM    H  0          C:\WINDOWS\Temp\CSC95BF84D-E9F6-4DD6-805F-1B6FA6630489.tmp
9/18/2005 12:46:36 PM    H  0          C:\WINDOWS\Temp\CSC9945CAD-D8C4-46FA-8FA3-BE79DDE2F8D5.tmp
9/18/2005 12:47:22 PM    H  0          C:\WINDOWS\Temp\CSCB295775-3B30-4A1C-8D0F-67415CFEF180.tmp
9/18/2005 12:47:22 PM    H  0          C:\WINDOWS\Temp\CSD51CB0F5-FCA7-42DE-A113-77CE6150584F.tmp
9/18/2005 12:47:22 PM    H  0          C:\WINDOWS\Temp\CSD6C34414-68C2-4C06-9AF7-5E8FB1720B6E.tmp
9/18/2005 12:46:36 PM    H  0          C:\WINDOWS\Temp\CSD7BA8BB5-E96A-4A1F-9571-C31C2BD1E9A6.tmp
9/18/2005 12:47:22 PM    H  0          C:\WINDOWS\Temp\CSD97E4A94-8BE9-4A40-AA0A-5E0C0AA8C41C.tmp
9/18/2005 12:47:22 PM    H  0          C:\WINDOWS\Temp\CSDE191912-5936-4B6C-8874-74DA9180AB79.tmp
9/18/2005 12:47:22 PM    H  0          C:\WINDOWS\Temp\CSE1880BE1-A5E5-4273-B19A-0D0068E7E81B.tmp
9/18/2005 12:46:34 PM    H  0          C:\WINDOWS\Temp\CSE33FB57C-02B9-406A-9FDB-AF36EA545E1D.tmp
9/18/2005 12:47:22 PM    H  0          C:\WINDOWS\Temp\CSE4981711-77AF-4686-B3C2-A2DCC68A320F.tmp
9/18/2005 12:47:22 PM    H  0          C:\WINDOWS\Temp\CSE8007758-B0B1-44A4-B895-88659B7CAC7C.tmp
9/18/2005 12:47:22 PM    H  0          C:\WINDOWS\Temp\CSE8750571-7785-4FD6-A5AC-589B992642AC.tmp
9/18/2005 12:47:22 PM    H  0          C:\WINDOWS\Temp\CSEA5582A9-224C-436D-B826-03A85FE15529.tmp
9/18/2005 12:46:36 PM    H  0          C:\WINDOWS\Temp\CSEDFD79ED-2DCA-4020-972F-62F49200F09E.tmp
9/18/2005 12:47:22 PM    H  0          C:\WINDOWS\Temp\CSEEEDBAD7-A663-4454-826E-AC981E4A34A4.tmp
9/18/2005 12:47:22 PM    H  0          C:\WINDOWS\Temp\CSF08C67A8-F8E2-4709-8165-043FEE74A733.tmp
9/18/2005 12:47:22 PM    H  0          C:\WINDOWS\Temp\CSF1BDB970-CEBA-4FE5-8462-238EA80B6F82.tmp
9/18/2005 12:47:22 PM    H  0          C:\WINDOWS\Temp\CSF85464F5-CFFA-4276-88A1-410B634DE5CF.tmp
9/18/2005 12:46:36 PM    H  0          C:\WINDOWS\Temp\CSFC151F18-25C8-4024-BD59-990C0283D5C0.tmp
7/26/2005 12:05:38 AM    HS 113        C:\WINDOWS\Temp\History\History.IE5\desktop.ini
7/26/2005 12:05:38 AM    HS 67         C:\WINDOWS\Temp\Temporary Internet Files\Content.IE5\desktop.ini
7/26/2005 12:05:38 AM    HS 67         C:\WINDOWS\Temp\Temporary Internet Files\Content.IE5\49UJWDMB\desktop.ini
7/26/2005 12:05:38 AM    HS 67         C:\WINDOWS\Temp\Temporary Internet Files\Content.IE5\CLUBW9YZ\desktop.ini
7/26/2005 12:05:38 AM    HS 67         C:\WINDOWS\Temp\Temporary Internet Files\Content.IE5\KTIJC5IZ\desktop.ini
7/26/2005 12:05:38 AM    HS 67         C:\WINDOWS\Temp\Temporary Internet Files\Content.IE5\O5EV8LE7\desktop.ini


Checking for CPL files...
Microsoft Corporation          8/4/2004 12:56:58 AM        68608      C:\WINDOWS\SYSTEM32\access.cpl
Avance Logic, Inc.             7/11/2002 10:17:44 PM   R   616960     C:\WINDOWS\SYSTEM32\ALSNDMGR.CPL
Microsoft Corporation          8/4/2004 12:56:58 AM        549888     C:\WINDOWS\SYSTEM32\appwiz.cpl
Microsoft Corporation          8/4/2004 12:56:58 AM        110592     C:\WINDOWS\SYSTEM32\bthprops.cpl
Microsoft Corporation          8/4/2004 12:56:58 AM        135168     C:\WINDOWS\SYSTEM32\desk.cpl
Microsoft Corporation          8/4/2004 12:56:58 AM        80384      C:\WINDOWS\SYSTEM32\firewall.cpl
Microsoft Corporation          8/4/2004 12:56:58 AM        155136     C:\WINDOWS\SYSTEM32\hdwwiz.cpl
Microsoft Corporation          8/4/2004 12:56:58 AM        358400     C:\WINDOWS\SYSTEM32\inetcpl.cpl
Microsoft Corporation          8/4/2004 12:56:58 AM        129536     C:\WINDOWS\SYSTEM32\intl.cpl
Microsoft Corporation          8/4/2004 12:56:58 AM        380416     C:\WINDOWS\SYSTEM32\irprops.cpl
Microsoft Corporation          8/4/2004 12:56:58 AM        68608      C:\WINDOWS\SYSTEM32\joy.cpl
Microsoft Corporation          8/23/2001 5:00:00 AM        187904     C:\WINDOWS\SYSTEM32\main.cpl
Microsoft Corporation          8/4/2004 12:56:58 AM        618496     C:\WINDOWS\SYSTEM32\mmsys.cpl
Microsoft Corporation          8/23/2001 5:00:00 AM        35840      C:\WINDOWS\SYSTEM32\ncpa.cpl
Microsoft Corporation          8/4/2004 12:56:58 AM        25600      C:\WINDOWS\SYSTEM32\netsetup.cpl
Microsoft Corporation          8/4/2004 12:56:58 AM        257024     C:\WINDOWS\SYSTEM32\nusrmgr.cpl
8/2/2005 4:35:00 PM         73728      C:\WINDOWS\SYSTEM32\nvtuicpl.cpl
Microsoft Corporation          8/23/2001 5:00:00 AM        36864      C:\WINDOWS\SYSTEM32\nwc.cpl
Microsoft Corporation          8/4/2004 12:56:58 AM        32768      C:\WINDOWS\SYSTEM32\odbccp32.cpl
Microsoft Corporation          8/4/2004 12:56:58 AM        114688     C:\WINDOWS\SYSTEM32\powercfg.cpl
Apple Computer, Inc.           1/6/2004 4:02:36 PM         323072     C:\WINDOWS\SYSTEM32\QuickTime.cpl
Microsoft Corporation          8/4/2004 12:56:58 AM        298496     C:\WINDOWS\SYSTEM32\sysdm.cpl
Microsoft Corporation          8/23/2001 5:00:00 AM        28160      C:\WINDOWS\SYSTEM32\telephon.cpl
Microsoft Corporation          8/4/2004 12:56:58 AM        94208      C:\WINDOWS\SYSTEM32\timedate.cpl
Microsoft Corporation          8/4/2004 12:56:58 AM        148480     C:\WINDOWS\SYSTEM32\wscui.cpl
Microsoft Corporation          8/4/2004 12:56:58 AM        162304     C:\WINDOWS\SYSTEM32\wuaucpl.cpl
Microsoft Corporation          8/23/2001 5:00:00 AM        187904     C:\WINDOWS\SYSTEM32\dllcache\main.cpl
Microsoft Corporation          8/23/2001 5:00:00 AM        35840      C:\WINDOWS\SYSTEM32\dllcache\ncpa.cpl
Microsoft Corporation          8/23/2001 5:00:00 AM        36864      C:\WINDOWS\SYSTEM32\dllcache\nwc.cpl
Microsoft Corporation          8/23/2001 5:00:00 AM        28160      C:\WINDOWS\SYSTEM32\dllcache\telephon.cpl


»»»»»»»»»»»»»»»»» Checking Selected Startup Folders »»»»»»»»»»»»»»»»»»»»»


Checking files in %ALLUSERSPROFILE%\Startup folder...
7/21/2005 7:49:50 PM     HS 84         C:\Documents and Settings\All Users\Start Menu\Programs\Startup\desktop.ini
7/25/2005 1:47:36 PM        779        C:\Documents and Settings\All Users\Start Menu\Programs\Startup\hpoddt01.exe.lnk


Checking files in %ALLUSERSPROFILE%\Application Data folder...
7/21/2005 12:37:36 PM    HS 62         C:\Documents and Settings\All Users\Application Data\desktop.ini
7/25/2005 1:54:32 PM        191        C:\Documents and Settings\All Users\Application Data\hpzinstall.log


Checking files in %USERPROFILE%\Startup folder...
7/21/2005 7:49:50 PM     HS 84         C:\Documents and Settings\VP TP PP\Start Menu\Programs\Startup\desktop.ini


Checking files in %USERPROFILE%\Application Data folder...
7/21/2005 12:37:36 PM    HS 62         C:\Documents and Settings\VP TP PP\Application Data\desktop.ini


»»»»»»»»»»»»»»»»» Checking Selected Registry Keys »»»»»»»»»»»»»»»»»»»»»»»


[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\User Agent\Post Platform]
SV1  =


[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved]


[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved]


[HKEY_CLASSES_ROOT\*\shellex\ContextMenuHandlers]
HKEY_CLASSES_ROOT\*\shellex\ContextMenuHandlers\ewido
{57BD36D7-CE32-4600-9B1C-1A0C47EFC02E}   = C:\Program Files\ewido\security suite\context.dll
HKEY_CLASSES_ROOT\*\shellex\ContextMenuHandlers\Offline Files
{750fdf0e-2a26-11d1-a3ea-080036587f03}   = %SystemRoot%\System32\cscui.dll
HKEY_CLASSES_ROOT\*\shellex\ContextMenuHandlers\Open With
{09799AFB-AD67-11d1-ABCD-00C04FC30936}   = %SystemRoot%\system32\SHELL32.dll
HKEY_CLASSES_ROOT\*\shellex\ContextMenuHandlers\Open With EncryptionMenu
{A470F8CF-A1E8-4f65-8335-227475AA5C46}   = %SystemRoot%\system32\SHELL32.dll
HKEY_CLASSES_ROOT\*\shellex\ContextMenuHandlers\Symantec.Norton.Antivirus.IEContextMenu
{5345A4D5-41EB-4A2F-9616-CE1D4F6C35B2}   = C:\Program Files\Norton AntiVirus\NavShExt.dll
HKEY_CLASSES_ROOT\*\shellex\ContextMenuHandlers\WinRAR
=
HKEY_CLASSES_ROOT\*\shellex\ContextMenuHandlers\WinZip
{E0D79304-84BE-11CE-9641-444553540000}   = C:\PROGRA~1\WINZIP\WZSHLSTB.DLL
HKEY_CLASSES_ROOT\*\shellex\ContextMenuHandlers\{a2a9545d-a0c2-42b4-9708-a0b2badd77c8}
Start Menu Pin   = %SystemRoot%\system32\SHELL32.dll


[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Folder\shellex\ContextMenuHandlers]
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Folder\shellex\ContextMenuHandlers\SpySweeper
{7C9D5882-CB4A-4090-96C8-430BFE8B795B}   = C:\PROGRA~1\Webroot\SPYSWE~1\SSCtxMnu.dll
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Folder\shellex\ContextMenuHandlers\Symantec.Norton.Antivirus.IEContextMenu
{5345A4D5-41EB-4A2F-9616-CE1D4F6C35B2}   = C:\Program Files\Norton AntiVirus\NavShExt.dll
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Folder\shellex\ContextMenuHandlers\WinRAR
=
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Folder\shellex\ContextMenuHandlers\WinZip
{E0D79304-84BE-11CE-9641-444553540000}   = C:\PROGRA~1\WINZIP\WZSHLSTB.DLL


[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Directory\shellex\ContextMenuHandlers]
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Directory\shellex\ContextMenuHandlers\EncryptionMenu
{A470F8CF-A1E8-4f65-8335-227475AA5C46}   = %SystemRoot%\system32\SHELL32.dll
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Directory\shellex\ContextMenuHandlers\ewido
{57BD36D7-CE32-4600-9B1C-1A0C47EFC02E}   = C:\Program Files\ewido\security suite\context.dll
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Directory\shellex\ContextMenuHandlers\Offline Files
{750fdf0e-2a26-11d1-a3ea-080036587f03}   = %SystemRoot%\System32\cscui.dll
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Directory\shellex\ContextMenuHandlers\Sharing
{f81e9010-6ea4-11ce-a7ff-00aa003ca9f6}   = ntshrui.dll
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Directory\shellex\ContextMenuHandlers\WinRAR
=
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Directory\shellex\ContextMenuHandlers\WinZip
{E0D79304-84BE-11CE-9641-444553540000}   = C:\PROGRA~1\WINZIP\WZSHLSTB.DLL


[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Folder\shellex\ColumnHandlers]
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Folder\shellex\ColumnHandlers\{0D2E74C4-3C34-11d2-A27E-00C04FC30871}
= %SystemRoot%\system32\SHELL32.dll
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Folder\shellex\ColumnHandlers\{24F14F01-7B1C-11d1-838f-0000F80461CF}
= %SystemRoot%\system32\SHELL32.dll
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Folder\shellex\ColumnHandlers\{24F14F02-7B1C-11d1-838f-0000F80461CF}
= %SystemRoot%\system32\SHELL32.dll
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Folder\shellex\ColumnHandlers\{66742402-F9B9-11D1-A202-0000F81FEDEE}
= %SystemRoot%\system32\SHELL32.dll


[HKLM\Software\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects]


[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Explorer Bars]
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Explorer Bars\{4D5C8C25-D075-11d0-B416-00C04FB90376}
&Tip of the Day = %SystemRoot%\System32\shdocvw.dll
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Explorer Bars\{FE54FA40-D68C-11d2-98FA-00C0F0318AFE}Real.com = C:\WINDOWS\system32\Shdocvw.dll


[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\ToolBar]
{42CDD1BF-3FFB-4238-8AD1-7859DF00B1D6}   = Norton AntiVirus : C:\Program Files\Norton AntiVirus\NavShExt.dll
{2318C2B1-4965-11d4-9B18-009027A5CD4F}   = &Google  : c:\program files\google\googletoolbar2.dll


[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Extensions]
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Extensions\{CD67F990-D8E9-11d2-98FE-00C0F0318AFE}
ButtonText   = Real.com :
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Extensions\{FB5F1910-F110-11d2-BB9E-00C04F795683}
ButtonText   = Messenger    : C:\Program Files\Messenger\msmsgs.exe


[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Explorer Bars]
HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Explorer Bars\{32683183-48a0-441b-a342-7c2a440a9478}
=


[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Toolbar]
HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Toolbar\ShellBrowser
{01E04581-4EEE-11D0-BFE9-00AA005B4383} = &Address   : %SystemRoot%\System32\browseui.dll
{42CDD1BF-3FFB-4238-8AD1-7859DF00B1D6} = Norton AntiVirus   : C:\Program Files\Norton AntiVirus\NavShExt.dll
HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Toolbar\WebBrowser
{01E04581-4EEE-11D0-BFE9-00AA005B4383} = &Address   : %SystemRoot%\System32\browseui.dll
{0E5CBF21-D15F-11D0-8301-00AA005B4383} = &Links : %SystemRoot%\system32\SHELL32.dll
{2318C2B1-4965-11D4-9B18-009027A5CD4F} = &Google    : c:\program files\google\googletoolbar2.dll


[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
SpySweeper  "C:\Program Files\Webroot\Spy Sweeper\SpySweeper.exe" /startintray
ccApp   "C:\Program Files\Common Files\Symantec Shared\ccApp.exe"
NvCplDaemon RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup
Pure Networks Port Magic    "C:\PROGRA~1\PURENE~1\PORTMA~1\PortAOL.exe" -Run
TkBellExe   "C:\Program Files\Common Files\Real\Update_OB\realsched.exe"  -osboot
QuickTime Task  "C:\Program Files\QuickTime\qttask.exe" -atboottime
nwiz    nwiz.exe /install
NvMediaCenter   RUNDLL32.EXE C:\WINDOWS\system32\NvMcTray.dll,NvTaskbarInit


[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\OptionalComponents]


[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\RunOnce]


[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\RunOnceEx]


[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\RunServices]


[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\RunServicesOnce]


[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
MsnMsgr "C:\Program Files\MSN Messenger\MsnMsgr.Exe" /background
Steam


[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\RunOnce]


[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\RunServices]


[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\RunServicesOnce]


[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows\load]


[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows\run]


[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\policies]


HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer


HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\Run
notepad.exe


HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\NonEnum
{BDEADF00-C265-11D0-BCED-00A0C90AB50F} = C:\PROGRA~1\COMMON~1\MICROS~1\WEBFOL~1\MSONSEXT.DLL
{6DFD7C5C-2451-11d3-A299-00C04F8EF6AF} =
{0DF44EAA-FF21-4412-828E-260A8728E7F1} =



HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Ratings


HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\system
dontdisplaylastusername 0
legalnoticecaption
legalnoticetext
shutdownwithoutlogon    1
undockwithoutlogon  1



[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\policies]


HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer
NoDriveTypeAutoRun  145


HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System



[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad]
PostBootReminder                {7849596a-48ea-486e-8937-a2a3009f31a9} = %SystemRoot%\system32\SHELL32.dll
CDBurn                          {fbeb8a05-beee-4442-804e-409d6c4515e9} = %SystemRoot%\system32\SHELL32.dll
WebCheck                        {E6FB5E20-DE35-11CF-9C87-00AA005127ED} = %SystemRoot%\System32\webcheck.dll
SysTray                         {35CEC8A3-2BE6-11D2-8773-92E220524153} = C:\WINDOWS\System32\stobject.dll


[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon]
UserInit    = C:\WINDOWS\system32\userinit.exe,
Shell       = explorer.exe
System      =


HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\crypt32chain
= crypt32.dll


HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\cryptnet
= cryptnet.dll


HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\cscdll
= cscdll.dll


HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\ScCertProp
= wlnotify.dll


HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\Schedule
= wlnotify.dll


HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\sclgntfy
= sclgntfy.dll


HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\SensLogn
= WlNotify.dll


HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\termsrv
= wlnotify.dll


HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\wlballoon
= wlnotify.dll


[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options]
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\Your Image File Name Here without a path
Debugger = ntsd -d


[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows]
AppInit_DLLs



»»»»»»»»»»»»»»»»»»»»»»»» Scan Complete »»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»
WinPFind v1.4.0 - Log file written to "WinPFind.Txt" in the WinPFind folder.
Scan completed on 9/18/2005 12:52:38 PM

Hi,
WinPFind log looks clean. If you find your computer slow, you can run Disk Defragmenter. It is present in Start > All Programs > Accessories > System Tools > Disk Defragmenter. Run Disk Defragmenter for all the drives.

Alright I disk defragmented, thank you very much for your help, but one question, what about the spyware/adware in my post that I said panda active scan detected but it didn't remove them. Did you do the word pad to get rid of them or..?

Hi,
Yes, the Batch file created by NotePad/WordPad was used to delete those files :)

Alright, well, thank you very much Swatkat for helping me through all this, and the previous thread I made. Thanks a lot, :cheesy:

Be a part of the DaniWeb community

We're a friendly, industry-focused community of developers, IT pros, digital marketers, and technology enthusiasts meeting, networking, learning, and sharing knowledge.