Hi, here it is
OTL logfile created on: 29/01/2012 20:19:35 - Run 2
OTL by OldTimer - Version 3.2.31.0 Folder = C:\Documents and Settings\User\Desktop
Windows XP Home Edition Service Pack 3 (Version = 5.1.2600) - Type = NTWorkstation
Internet Explorer (Version = 8.0.6001.18702)
Locale: 00000809 | Country: United Kingdom | Language: ENG | Date Format: dd/MM/yyyy
1.99 Gb Total Physical Memory | 1.06 Gb Available Physical Memory | 53.04% Memory free
3.84 Gb Paging File | 2.97 Gb Available in Paging File | 77.30% Paging File free
Paging file location(s): C:\pagefile.sys 2046 4092 [binary data]
%SystemDrive% = C: | %SystemRoot% = C:\WINDOWS | %ProgramFiles% = C:\Program Files
Drive C: | 465.66 Gb Total Space | 262.33 Gb Free Space | 56.33% Space Free | Partition Type: NTFS
Computer Name: 0IGOTOZG63 | User Name: User | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: All users
Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 30 Days
========== Processes (SafeList) ==========
PRC - C:\Documents and Settings\User\Desktop\OTL.exe (OldTimer Tools)
PRC - C:\Program Files\Java\jre7\bin\jqs.exe (Oracle Corporation)
PRC - C:\Program Files\iolo\Common\Lib\ioloServiceManager.exe (iolo technologies, LLC)
PRC - C:\Program Files\Mozilla Firefox\firefox.exe (Mozilla Corporation)
PRC - C:\Program Files\Alwil Software\Avast5\AvastUI.exe (AVAST Software)
PRC - C:\Program Files\Alwil Software\Avast5\AvastSvc.exe (AVAST Software)
PRC - C:\Program Files\Trusteer\Rapport\bin\RapportService.exe (Trusteer Ltd.)
PRC - C:\Program Files\Trusteer\Rapport\bin\RapportMgmtService.exe (Trusteer Ltd.)
PRC - C:\Program Files\CheckPoint\ZoneAlarm\vsmon.exe (Check Point Software Technologies LTD)
PRC - C:\Program Files\CheckPoint\ZoneAlarm\zatray.exe (Check Point Software Technologies LTD)
PRC - C:\Program Files\Google\Update\1.3.21.79\GoogleCrashHandler.exe (Google Inc.)
PRC - C:\Program Files\CheckPoint\ZAForceField\ISWSVC.exe (Check Point Software Technologies)
PRC - C:\Program Files\CheckPoint\ZAForceField\ForceField.exe (Check Point Software Technologies)
PRC - C:\Program Files\IDrive\IDriveETray.exe (Pro Softnet Corp.)
PRC - C:\Program Files\IDrive\IDriveEBackground.exe (Pro-SoftNet Corp, U.S.A)
PRC - C:\Program Files\IDrive\IDriveWebM.exe ( Pro-Softnet)
PRC - C:\Program Files\Vodafone\Vodafone Mobile Connect\Bin\MobileConnect.exe (Vodafone)
PRC - C:\Program Files\Vodafone\Vodafone Mobile Connect\Bin\VMCService.exe (Vodafone)
PRC - c:\Program Files\Arclab\MailList Controller\amlcSVC.exe (Arclab Software Technologies)
PRC - C:\WINDOWS\explorer.exe (Microsoft Corporation)
PRC - C:\Program Files\Kontiki\KService.exe (Kontiki Inc.)
PRC - C:\Program Files\Acronis\TrueImageHome\TrueImageMonitor.exe (Acronis)
PRC - C:\Program Files\Acronis\TrueImageHome\TimounterMonitor.exe (Acronis)
PRC - C:\Program Files\Common Files\Acronis\Schedule2\schedhlp.exe (Acronis)
PRC - C:\Program Files\Common Files\Acronis\Schedule2\schedul2.exe (Acronis)
PRC - C:\Program Files\NETGEAR\WG111v2\WG111v2.exe ()
PRC - C:\Program Files\TP-LINK\TWCU\TWCU.exe (TP-LINK TECHNOLOGIES CO., LTD)
PRC - C:\WINDOWS\system32\acs.exe ()
PRC - C:\Program Files\Common Files\Ulead Systems\DVD\ULCDRSvr.exe (Ulead Systems, Inc.)
PRC - C:\Program Files\Adobe\Acrobat 6.0\Distillr\acrotray.exe (Adobe Systems Inc.)
PRC - C:\WINDOWS\htpatch.exe ()
========== Modules (No Company Name) ==========
MOD - C:\Program Files\Alwil Software\Avast5\defs\12012900\algo.dll ()
MOD - C:\Program Files\Mozilla Firefox\js3250.dll ()
MOD - C:\WINDOWS\system32\Macromed\Flash\NPSWF32.dll ()
MOD - C:\Program Files\Trusteer\Rapport\bin\js32.dll ()
MOD - C:\WINDOWS\assembly\NativeImages_v2.0.50727_32\System.Transactions\8efcd633af87989355382b5039f1b7df\System.Transactions.ni.dll ()
MOD - C:\WINDOWS\assembly\NativeImages_v2.0.50727_32\System.ServiceProce#\abef85f2fb8ba830eda73e2d12e8d41e\System.ServiceProcess.ni.dll ()
MOD - C:\WINDOWS\assembly\NativeImages_v2.0.50727_32\System.Management\90b90e700e59d73d6d692cf74e1ba16e\System.Management.ni.dll ()
MOD - C:\WINDOWS\assembly\NativeImages_v2.0.50727_32\System.Security\36c12de583ee81e9c99acb72b09d77ac\System.Security.ni.dll ()
MOD - C:\WINDOWS\assembly\NativeImages_v2.0.50727_32\System.Configuration\bce0720436dc6cb76006377f295ea365\System.Configuration.ni.dll ()
MOD - C:\WINDOWS\assembly\NativeImages_v2.0.50727_32\System.Xml\70cacc44f0b4257f6037eda7a59a0aeb\System.Xml.ni.dll ()
MOD - C:\WINDOWS\assembly\NativeImages_v2.0.50727_32\System.Windows.Forms\71a2ae9ad561a62181cbd9fb11e9de7a\System.Windows.Forms.ni.dll ()
MOD - C:\WINDOWS\assembly\NativeImages_v2.0.50727_32\System.Drawing\c10bea3c4bb7ef654651141bf9419090\System.Drawing.ni.dll ()
MOD - C:\WINDOWS\assembly\NativeImages_v2.0.50727_32\System.Data\ec323cf1df697cc0a45f67de685db90c\System.Data.ni.dll ()
MOD - C:\WINDOWS\assembly\NativeImages_v2.0.50727_32\System\af39f6e644af02873b9bae319f2bfb13\System.ni.dll ()
MOD - C:\WINDOWS\assembly\NativeImages_v2.0.50727_32\mscorlib\ca87ba84221991839abbe7d4bc9c6721\mscorlib.ni.dll ()
MOD - C:\WINDOWS\assembly\GAC_32\System.Data\2.0.0.0__b77a5c561934e089\System.Data.dll ()
MOD - C:\WINDOWS\assembly\GAC_MSIL\System.Runtime.Remoting\2.0.0.0__b77a5c561934e089\System.Runtime.Remoting.dll ()
MOD - C:\WINDOWS\assembly\GAC_32\System.Transactions\2.0.0.0__b77a5c561934e089\System.Transactions.dll ()
MOD - C:\Documents and Settings\All Users\Application Data\Trusteer\Rapport\store\exts\RapportMS\28896\RapportMS.dll ()
MOD - C:\Documents and Settings\User\Application Data\Mozilla\Firefox\Profiles\7q7rrwgl.default\extensions\{3112ca9c-de6d-4884-a869-9855de68056c}\components\frozen.dll ()
MOD - C:\Documents and Settings\User\Application Data\Mozilla\Firefox\Profiles\7q7rrwgl.default\extensions\{3112ca9c-de6d-4884-a869-9855de68056c}\components\googletoolbar-ff3.dll ()
MOD - C:\Documents and Settings\User\Application Data\Mozilla\Firefox\Profiles\7q7rrwgl.default\extensions\{6AC85730-7D0F-4de0-B3FA-21142DD85326}\platform\WINNT\components\ColorZilla.dll ()
MOD - C:\Program Files\Google\Google Desktop Search\gzlib.dll ()
MOD - C:\WINDOWS\system32\pdf995mon.dll ()
MOD - C:\Program Files\iolo\Common\Lib\Aquarius.dll ()
MOD - C:\WINDOWS\system32\msjetoledb40.dll ()
MOD - C:\WINDOWS\system32\cpwmon2k.dll ()
MOD - C:\Program Files\Common Files\Acronis\Common\rpc_client.dll ()
MOD - C:\Program Files\NETGEAR\WG111v2\WG111v2.exe ()
MOD - C:\Program Files\dBpowerAMP\dBShell.dll ()
MOD - C:\Program Files\NETGEAR\WG111v2\NWTools.dll ()
MOD - C:\WINDOWS\system32\acs.exe ()
MOD - C:\Program Files\NETGEAR\WG111v2\acAuth.dll ()
MOD - C:\WINDOWS\htpatch.exe ()
MOD - C:\WINDOWS\system32\HPBHEALR.DLL ()
========== Win32 Services (SafeList) ==========
SRV - (AppMgmt) -- File not found
SRV - (JavaQuickStarterService) -- C:\Program Files\Java\jre7\bin\jqs.exe (Oracle Corporation)
SRV - (ioloSystemService) -- C:\Program Files\iolo\Common\Lib\ioloServiceManager.exe (iolo technologies, LLC)
SRV - (avast! Antivirus) -- C:\Program Files\Alwil Software\Avast5\AvastSvc.exe (AVAST Software)
SRV - (RapportMgmtService) -- C:\Program Files\Trusteer\Rapport\bin\RapportMgmtService.exe (Trusteer Ltd.)
SRV - (vsmon) -- C:\Program Files\CheckPoint\ZoneAlarm\vsmon.exe (Check Point Software Technologies LTD)
SRV - (IswSvc) -- C:\Program Files\CheckPoint\ZAForceField\IswSvc.exe (Check Point Software Technologies)
SRV - (IDriveE Service) -- C:\Program Files\IDrive\IDriveE Service.exe (Pro Softnet Corporation)
SRV - (IDriveWebM) -- C:\Program Files\IDrive\IDriveWebM.exe ( Pro-Softnet)
SRV - (ACDaemon) -- C:\Program Files\Common Files\ArcSoft\Connection Service\Bin\ACService.exe (ArcSoft Inc.)
SRV - (VMCService) -- C:\Program Files\Vodafone\Vodafone Mobile Connect\Bin\VMCService.exe (Vodafone)
SRV - (MailList Controller) -- c:\Program Files\Arclab\MailList Controller\amlcSVC.exe (Arclab Software Technologies)
SRV - (Iprip) -- C:\WINDOWS\system32\iprip.dll (Microsoft Corporation)
SRV - (KService) -- C:\Program Files\Kontiki\KService.exe (Kontiki Inc.)
SRV - (AcrSch2Svc) -- C:\Program Files\Common Files\Acronis\Schedule2\schedul2.exe (Acronis)
SRV - (ACS) -- C:\WINDOWS\system32\acs.exe ()
SRV - (UleadBurningHelper) -- C:\Program Files\Common Files\Ulead Systems\DVD\ULCDRSvr.exe (Ulead Systems, Inc.)
SRV - (Pml Driver HPZ12) -- C:\WINDOWS\system32\HPZipm12.exe (HP)
SRV - (Visual Studio Analyzer RPC bridge) -- C:\Program Files\Microsoft Visual Studio\Common\Tools\VS-Ent98\Vanalyzr\VARPC.EXE (Microsoft Corporation)
========== Driver Services (SafeList) ==========
DRV - (RapportCerberus_34302) -- C:\Documents and Settings\All Users\Application Data\Trusteer\Rapport\store\exts\RapportCerberus\34302\RapportCerberus32_34302.sys ()
DRV - (aswSnx) -- C:\WINDOWS\System32\drivers\aswSnx.sys (AVAST Software)
DRV - (aswSP) -- C:\WINDOWS\System32\drivers\aswSP.sys (AVAST Software)
DRV - (aswRdr) -- C:\WINDOWS\System32\drivers\aswRdr.sys (AVAST Software)
DRV - (aswTdi) -- C:\WINDOWS\System32\drivers\aswTdi.sys (AVAST Software)
DRV - (aswMon2) -- C:\WINDOWS\System32\drivers\aswmon2.sys (AVAST Software)
DRV - (aswFsBlk) -- C:\WINDOWS\System32\drivers\aswFsBlk.sys (AVAST Software)
DRV - (Aavmker4) -- C:\WINDOWS\System32\drivers\aavmker4.sys (AVAST Software)
DRV - (RapportEI) -- C:\Program Files\Trusteer\Rapport\bin\RapportEI.sys (Trusteer Ltd.)
DRV - (RapportPG) -- C:\Program Files\Trusteer\Rapport\bin\RapportPG.sys (Trusteer Ltd.)
DRV - (RapportKELL) -- C:\WINDOWS\System32\Drivers\RapportKELL.sys (Trusteer Ltd.)
DRV - (Vsdatant) -- C:\WINDOWS\system32\vsdatant.sys (Check Point Software Technologies LTD)
DRV - (ISWKL) -- C:\Program Files\CheckPoint\ZAForceField\ISWKL.sys (Check Point Software Technologies)
DRV - (RapportIaso) -- c:\Documents and Settings\All Users\Application Data\Trusteer\Rapport\store\exts\RapportMS\28896\RapportIaso.sys (Trusteer Ltd.)
DRV - (StarOpen) -- C:\WINDOWS\System32\drivers\StarOpen.sys ()
DRV - (hwdatacard) -- C:\WINDOWS\system32\drivers\ewusbmdm.sys (Huawei Technologies Co., Ltd.)
DRV - (timounter) -- C:\WINDOWS\system32\DRIVERS\timntr.sys (Acronis)
DRV - (tifsfilter) -- C:\WINDOWS\system32\drivers\tifsfilt.sys (Acronis)
DRV - (snapman) -- C:\WINDOWS\system32\DRIVERS\snapman.sys (Acronis)
DRV - (AtcL002) -- C:\WINDOWS\system32\drivers\l251x86.sys (Atheros Communications, Inc.)
DRV - (gameenum) -- C:\WINDOWS\system32\drivers\gameenum.sys (Microsoft Corporation)
DRV - (ss_mdm) -- C:\WINDOWS\system32\drivers\ss_mdm.sys (MCCI Corporation)
DRV - (ss_mdfl) -- C:\WINDOWS\system32\drivers\ss_mdfl.sys (MCCI Corporation)
DRV - (ss_bus) SAMSUNG Mobile USB Device 1.0 driver (WDM) -- C:\WINDOWS\system32\drivers\ss_bus.sys (MCCI Corporation)
DRV - (IntcAzAudAddService) Service for Realtek HD Audio (WDM) -- C:\WINDOWS\system32\drivers\RtkHDAud.sys (Realtek Semiconductor Corp.)
DRV - (AR5523) -- C:\WINDOWS\system32\drivers\ar5523.sys (Atheros Communications, Inc.)
DRV - (RTLWUSB) -- C:\WINDOWS\system32\drivers\wg111v2.sys (NETGEAR Inc.)
DRV - (hpt4qic) -- C:\WINDOWS\system32\drivers\hpt4qic.sys (Microsoft Corporation)
DRV - (SQTECH905C) -- C:\WINDOWS\system32\drivers\Capt905c.sys (Service & Quality Technology.)
DRV - (MTsensor) -- C:\WINDOWS\system32\drivers\ASACPI.sys ()
DRV - (SISNIC) -- C:\WINDOWS\system32\drivers\sisnic.sys (SiS Corporation)
DRV - (IFP800) -- C:\WINDOWS\system32\drivers\ifp800.sys (iRiver, Inc.)
DRV - (IFP700) -- C:\WINDOWS\system32\drivers\ifp700.sys (iRiver, Inc.)
DRV - (alcan5wn) SpeedTouch USB ADSL PPP Networking Driver (NDISWAN) -- C:\WINDOWS\system32\drivers\alcan5wn.sys (THOMSON)
DRV - (alcaudsl) -- C:\WINDOWS\system32\drivers\alcaudsl.sys (THOMSON)
DRV - (Aspi32) -- C:\WINDOWS\System32\drivers\ASPI32.SYS (Adaptec)
DRV - (Intels51) Intel® -- C:\WINDOWS\system32\drivers\Intels51.sys (Intel Corporation)
DRV - (EUSBMSD) -- C:\WINDOWS\system32\drivers\EUSBMSD.SYS (SCM Microsystems Inc.)
DRV - (HCF_MSFT) -- C:\WINDOWS\system32\drivers\HCF_MSFT.sys (Conexant)
DRV - (CW50) -- C:\WINDOWS\system32\drivers\CW50.sys (CASIO COMPUTER CO.,LTD.)
DRV - (HITUMINI) -- C:\WINDOWS\system32\drivers\RDCUMINI.sys (American Megatrends, Inc.)
DRV - (HituMass) -- C:\WINDOWS\system32\drivers\RDCUMASS.sys (American Megatrends, Inc.)
DRV - (epatapnt) -- C:\WINDOWS\System32\Drivers\epatapnt.mpd (Shuttle Technology. )
DRV - (SHARSHTL) -- C:\WINDOWS\System32\Drivers\sharshtl.sys (Microsoft Corporation)
========== Standard Registry (SafeList) ==========
========== Internet Explorer ==========
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Search,Default_Search_URL =
http://www.google.com/ie
IE - HKU\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
IE - HKU\S-1-5-18\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
IE - HKU\S-1-5-19\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
IE - HKU\S-1-5-20\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
IE - HKU\S-1-5-21-1801674531-117609710-839522115-1004\SOFTWARE\Microsoft\Internet Explorer\Main,SearchMigratedDefaultName = Google
IE - HKU\S-1-5-21-1801674531-117609710-839522115-1004\SOFTWARE\Microsoft\Internet Explorer\Main,SearchMigratedDefaultURL =
http://www.google.com/search?q={searchTerms}&sourceid=ie7&rls=com.microsoft:en-US&ie=utf8&oe=utf8
IE - HKU\S-1-5-21-1801674531-117609710-839522115-1004\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page Redirect Cache AcceptLangs = en-gb
IE - HKU\S-1-5-21-1801674531-117609710-839522115-1004\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page Redirect Cache_TIMESTAMP = 4E 9D AE 47 0D DE CC 01 [binary data]
IE - HKU\S-1-5-21-1801674531-117609710-839522115-1004\SOFTWARE\Microsoft\Internet Explorer\Search,SearchAssistant =
http://www.google.com/ie
IE - HKU\S-1-5-21-1801674531-117609710-839522115-1004\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
IE - HKU\S-1-5-21-1801674531-117609710-839522115-1004\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyOverride" = <local>
========== FireFox ==========
FF - HKLM\Software\MozillaPlugins\@adobe.com/FlashPlayer: C:\WINDOWS\system32\Macromed\Flash\NPSWF32.dll ()
FF - HKLM\Software\MozillaPlugins\@checkpoint.com/FFApi: C:\Program Files\CheckPoint\ZAForceField\TrustChecker\bin\npFFApi.dll ()
FF - HKLM\Software\MozillaPlugins\@emusic.com/dlm-plugin: C:\Program Files\eMusic Download Manager\plugin\npemusic.dll (eMusic.com)
FF - HKLM\Software\MozillaPlugins\@foxitsoftware.com/Foxit Reader Plugin,version=1.0,application/pdf: C:\Program Files\Foxit Software\Foxit Reader\plugins\npFoxitReaderPlugin.dll (Foxit Corporation)
FF - HKLM\Software\MozillaPlugins\@Google.com/GoogleEarthPlugin: C:\Program Files\Google\Google Earth\plugin\npgeplugin.dll (Google)
FF - HKLM\Software\MozillaPlugins\@java.com/JavaPlugin: C:\Program Files\Java\jre7\bin\new_plugin\npjp2.dll (Oracle Corporation)
FF - HKLM\Software\MozillaPlugins\@Microsoft.com/NpCtrl,version=1.0: c:\Program Files\Microsoft Silverlight\4.0.60831.0\npctrl.dll ( Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/WPF,version=3.5: c:\WINDOWS\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\NPWPF.dll (Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@pack.google.com/Google Updater;version=14: C:\Program Files\Google\Google Updater\2.4.1851.5542\npCIDetect14.dll (Google)
FF - HKLM\Software\MozillaPlugins\@tools.google.com/Google Update;version=3: C:\Program Files\Google\Update\1.3.21.79\npGoogleUpdate3.dll (Google Inc.)
FF - HKLM\Software\MozillaPlugins\@tools.google.com/Google Update;version=9: C:\Program Files\Google\Update\1.3.21.79\npGoogleUpdate3.dll (Google Inc.)
FF - HKCU\Software\MozillaPlugins\@emusic.com/dlm-plugin: C:\Program Files\eMusic Download Manager\plugin\npemusic.dll (eMusic.com)
FF - HKEY_LOCAL_MACHINE\software\mozilla\eMusic Download Manager\Extensions\\Components: C:\Program Files\eMusic Download Manager\xulrunner\components [2009/10/27 20:37:31 | 000,000,000 | ---D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\eMusic Download Manager\Extensions\\Plugins: C:\Program Files\eMusic Download Manager\xulrunner\plugins [2010/02/01 22:12:47 | 000,000,000 | ---D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\Extensions\\{B728AB94-9BC7-49b7-B76A-422BB31B2FD0}: C:\Program Files\ArcSoft\Video Downloader\Plugin_FireFox [2010/12/31 16:18:37 | 000,000,000 | ---D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\Extensions\\RAWThumbnailViewer@arcsoft.com.cn: C:\Program Files\ArcSoft\RAW Thumbnail Viewer\FireFox Extension [2010/12/31 16:19:48 | 000,000,000 | ---D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\Extensions\\{FFB96CC1-7EB3-449D-B827-DB661701C6BB}: C:\Program Files\CheckPoint\ZAForceField\TrustChecker [2012/01/25 13:42:38 | 000,000,000 | ---D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 3.6.25\extensions\\Components: C:\Program Files\Mozilla Firefox\components [2011/12/22 09:42:51 | 000,000,000 | ---D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 3.6.25\extensions\\Plugins: C:\Program Files\Mozilla Firefox\plugins [2011/12/22 09:42:51 | 000,000,000 | ---D | M]
[2010/06/13 11:55:28 | 000,000,000 | ---D | M] (No name found) -- C:\Documents and Settings\User\Application Data\Mozilla\Extensions
[2010/06/13 11:55:28 | 000,000,000 | ---D | M] (No name found) -- C:\Documents and Settings\User\Application Data\Mozilla\Extensions\{ea278cf8-93cd-484f-b951-57360482d33a}
[2012/01/29 20:02:22 | 000,000,000 | ---D | M] (No name found) -- C:\Documents and Settings\User\Application Data\Mozilla\Firefox\Profiles\7q7rrwgl.default\extensions
[2010/04/28 17:07:38 | 000,000,000 | ---D | M] (Microsoft .NET Framework Assistant) -- C:\Documents and Settings\User\Application Data\Mozilla\Firefox\Profiles\7q7rrwgl.default\extensions\{20a82645-c095-46ed-80e3-08825760534b}
[2011/07/03 08:46:28 | 000,000,000 | ---D | M] (Google Toolbar for Firefox) -- C:\Documents and Settings\User\Application Data\Mozilla\Firefox\Profiles\7q7rrwgl.default\extensions\{3112ca9c-de6d-4884-a869-9855de68056c}
[2011/12/18 11:51:07 | 000,000,000 | ---D | M] (SeoQuake) -- C:\Documents and Settings\User\Application Data\Mozilla\Firefox\Profiles\7q7rrwgl.default\extensions\{317B5128-0B0B-49b2-B2DB-1E7560E16C74}
[2011/08/30 10:09:51 | 000,000,000 | ---D | M] (AddThis) -- C:\Documents and Settings\User\Application Data\Mozilla\Firefox\Profiles\7q7rrwgl.default\extensions\{3e0e7d2a-070f-4a47-b019-91fe5385ba79}
[2011/12/28 17:19:57 | 000,000,000 | ---D | M] (RefControl) -- C:\Documents and Settings\User\Application Data\Mozilla\Firefox\Profiles\7q7rrwgl.default\extensions\{455D905A-D37C-4643-A9E2-F6FEFAA0424A}
[2011/09/23 16:22:47 | 000,000,000 | ---D | M] (InFormEnter) -- C:\Documents and Settings\User\Application Data\Mozilla\Firefox\Profiles\7q7rrwgl.default\extensions\{5546F97E-11A5-46b0-9082-32AD74AAA920}
[2011/12/21 11:03:44 | 000,000,000 | ---D | M] (ColorZilla) -- C:\Documents and Settings\User\Application Data\Mozilla\Firefox\Profiles\7q7rrwgl.default\extensions\{6AC85730-7D0F-4de0-B3FA-21142DD85326}
[2010/08/30 13:46:52 | 000,000,000 | ---D | M] ("DVDVideoSoft Menu") -- C:\Documents and Settings\User\Application Data\Mozilla\Firefox\Profiles\7q7rrwgl.default\extensions\{ACAA314B-EEBA-48e4-AD47-84E31C44796C}
[2012/01/09 17:15:07 | 000,000,000 | ---D | M] ("StumbleUpon") -- C:\Documents and Settings\User\Application Data\Mozilla\Firefox\Profiles\7q7rrwgl.default\extensions\{AE93811A-5C9A-4d34-8462-F7B864FC4696}
[2011/12/08 09:46:55 | 000,000,000 | ---D | M] (SearchStatus) -- C:\Documents and Settings\User\Application Data\Mozilla\Firefox\Profiles\7q7rrwgl.default\extensions\{d57c9ff1-6389-48fc-b770-f78bd89b6e8a}
[2010/01/22 22:39:58 | 000,000,000 | ---D | M] (Clipmarks) -- C:\Documents and Settings\User\Application Data\Mozilla\Firefox\Profiles\7q7rrwgl.default\extensions\{e1170235-2845-420c-acc3-42261a29dd46}
[2011/05/24 08:05:23 | 000,000,000 | ---D | M] (Page Speed) -- C:\Documents and Settings\User\Application Data\Mozilla\Firefox\Profiles\7q7rrwgl.default\extensions\{e3f6c2cc-d8db-498c-af6c-499fb211db97}
[2010/01/09 08:32:09 | 000,000,000 | ---D | M] (bit.ly preview) -- C:\Documents and Settings\User\Application Data\Mozilla\Firefox\Profiles\7q7rrwgl.default\extensions\bitlypreview@jay.ridgeway
[2011/03/21 20:05:05 | 000,000,000 | ---D | M] ("Blank Canvas Signatures for Gmail ") -- C:\Documents and Settings\User\Application Data\Mozilla\Firefox\Profiles\7q7rrwgl.default\extensions\gmail_sigs@blankcanvasweb.com
[2010/03/19 22:56:18 | 000,000,000 | ---D | M] (SEO Blogger) -- C:\Documents and Settings\User\Application Data\Mozilla\Firefox\Profiles\7q7rrwgl.default\extensions\seo-blogger@wordtracker.com
[2011/06/21 21:30:30 | 000,000,000 | ---D | M] (SEO Doctor) -- C:\Documents and Settings\User\Application Data\Mozilla\Firefox\Profiles\7q7rrwgl.default\extensions\seodoctor@prelovac.com
[2012/01/29 16:16:08 | 000,000,000 | ---D | M] (socialmonkee) -- C:\Documents and Settings\User\Application Data\Mozilla\Firefox\Profiles\7q7rrwgl.default\extensions\sm@submitter.net
[2011/09/17 10:48:13 | 000,000,000 | ---D | M] (SortPlaces) -- C:\Documents and Settings\User\Application Data\Mozilla\Firefox\Profiles\7q7rrwgl.default\extensions\sortplaces@andyhalford.com
[2011/10/31 09:40:53 | 000,000,000 | ---D | M] (Stealthy) -- C:\Documents and Settings\User\Application Data\Mozilla\Firefox\Profiles\7q7rrwgl.default\extensions\stealthyextension@gmail.com
[2011/10/31 09:40:52 | 000,000,000 | ---D | M] (No name found) -- C:\Documents and Settings\User\Application Data\Mozilla\Firefox\Profiles\7q7rrwgl.default\extensions\stealthyextension@gmail.com\chrome
[2009/05/31 13:08:26 | 000,000,000 | ---D | M] (No name found) -- C:\Program Files\Mozilla Firefox\extensions
[2009/10/27 20:37:31 | 000,000,000 | ---D | M] (eMusic - Apple iTunes Support) -- C:\PROGRAM FILES\EMUSIC DOWNLOAD MANAGER\XULRUNNER\EXTENSIONS\DLM_ITUNES@EMUSIC.COM
[2009/10/27 20:37:32 | 000,000,000 | ---D | M] (eMusic - Nullsoft Winamp Support) -- C:\PROGRAM FILES\EMUSIC DOWNLOAD MANAGER\XULRUNNER\EXTENSIONS\DLM_WINAMP@EMUSIC.COM
[2009/10/27 20:37:32 | 000,000,000 | ---D | M] (eMusic - Microsoft Media Player Support) -- C:\PROGRAM FILES\EMUSIC DOWNLOAD MANAGER\XULRUNNER\EXTENSIONS\DLM_WMP@EMUSIC.COM
[2008/02/27 16:57:38 | 000,106,496 | ---- | M] (British Broadcasting Corporation) -- C:\Program Files\mozilla firefox\plugins\npBBCPlugin.dll
[2009/08/09 00:11:22 | 010,437,264 | ---- | M] (PDFTron Systems Inc.) -- C:\Program Files\mozilla firefox\plugins\PDFNetC.dll
[2009/08/09 00:30:36 | 000,107,760 | ---- | M] () -- C:\Program Files\mozilla firefox\plugins\ScorchPDFWrapper.dll
[2011/06/23 16:42:58 | 000,001,538 | ---- | M] () -- C:\Program Files\mozilla firefox\searchplugins\amazon-en-GB.xml
[2011/06/23 16:42:58 | 000,000,947 | ---- | M] () -- C:\Program Files\mozilla firefox\searchplugins\chambers-en-GB.xml
[2011/06/23 16:42:58 | 000,000,769 | ---- | M] () -- C:\Program Files\mozilla firefox\searchplugins\eBay-en-GB.xml
[2011/06/23 16:42:58 | 000,001,135 | ---- | M] () -- C:\Program Files\mozilla firefox\searchplugins\yahoo-en-GB.xml
O1 HOSTS File: ([2012/01/25 20:57:54 | 000,000,027 | ---- | M]) - C:\WINDOWS\system32\drivers\etc\hosts
O1 - Hosts: 127.0.0.1 localhost
O2 - BHO: (Octh Class) - {000123B4-9B42-4900-B3F7-F4B073EFC214} - C:\Program Files\Orbitdownloader\orbitcth.dll (Orbitdownloader.com)
O2 - BHO: (IEPlugin Class) - {11222041-111B-46E3-BD29-EFB2449479B1} - C:\Program Files\ArcSoft\Video Downloader\ArcURLRecord.dll (ArcSoft, Inc.)
O2 - BHO: (AskBar BHO) - {201f27d4-3704-41d6-89c1-aa35e39143ed} - C:\Program Files\AskBarDis\bar\bin\askBar.dll (Ask.com)
O2 - BHO: (ZoneAlarm Security Engine Registrar) - {8A4A36C2-0535-4D2C-BD3D-496CB7EED6E3} - C:\Program Files\CheckPoint\ZAForceField\Trustchecker\bin\TrustCheckerIEPlugin.dll (Check Point Software Technologies)
O2 - BHO: (ToolbarBHO Class) - {9519AF7E-638D-4933-BAD6-D33D23C79FE5} - C:\Program Files\ArcSoft\RAW Thumbnail Viewer\EXIFToolBar.dll (ArcSoft Inc.)
O2 - BHO: (AcroIEToolbarHelper Class) - {AE7CD045-E861-484f-8273-0445EE161910} - C:\Program Files\Adobe\Acrobat 6.0\Acrobat\AcroIEFavClient.dll ()
O2 - BHO: (Google Toolbar Notifier BHO) - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\5.7.7227.1100\swg.dll (Google Inc.)
O2 - BHO: (Java Plug-In 2 SSV Helper) - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre7\bin\jp2ssv.dll (Oracle Corporation)
O2 - BHO: (EpsonToolBandKicker Class) - {E99421FB-68DD-40F0-B4AC-B7027CAE2F1A} - C:\Program Files\epson\EPSON Web-To-Page\EPSON Web-To-Page.dll (SEIKO EPSON CORPORATION)
O3 - HKLM\..\Toolbar: (Foxit Toolbar) - {3041d03e-fd4b-44e0-b742-2d9b88305f98} - C:\Program Files\AskBarDis\bar\bin\askBar.dll (Ask.com)
O3 - HKLM\..\Toolbar: (Adobe PDF) - {47833539-D0C5-4125-9FA8-0819E2EAAC93} - C:\Program Files\Adobe\Acrobat 6.0\Acrobat\AcroIEFavClient.dll ()
O3 - HKLM\..\Toolbar: (Grab Pro) - {C55BBCD6-41AD-48AD-9953-3609C48EACC7} - C:\Program Files\Orbitdownloader\GrabPro.dll ()
O3 - HKLM\..\Toolbar: (ZoneAlarm Security Engine) - {EE2AC4E5-B0B0-4EC6-88A9-BCA1A32AB107} - C:\Program Files\CheckPoint\ZAForceField\Trustchecker\bin\TrustCheckerIEPlugin.dll (Check Point Software Technologies)
O3 - HKLM\..\Toolbar: (EPSON Web-To-Page) - {EE5D279F-081B-4404-994D-C6B60AAEBA6D} - C:\Program Files\epson\EPSON Web-To-Page\EPSON Web-To-Page.dll (SEIKO EPSON CORPORATION)
O3 - HKLM\..\Toolbar: (RAW Thumbnail Viewer) - {F301665A-12F8-4331-804A-5BCBD379668C} - C:\Program Files\ArcSoft\RAW Thumbnail Viewer\EXIFToolBar.dll (ArcSoft Inc.)
O3 - HKU\.DEFAULT\..\Toolbar\WebBrowser: (no name) - {42CDD1BF-3FFB-4238-8AD1-7859DF00B1D6} - No CLSID value found.
O3 - HKU\S-1-5-18\..\Toolbar\WebBrowser: (no name) - {42CDD1BF-3FFB-4238-8AD1-7859DF00B1D6} - No CLSID value found.
O3 - HKU\S-1-5-21-1801674531-117609710-839522115-1004\..\Toolbar\ShellBrowser: (no name) - {42CDD1BF-3FFB-4238-8AD1-7859DF00B1D6} - No CLSID value found.
O3 - HKU\S-1-5-21-1801674531-117609710-839522115-1004\..\Toolbar\WebBrowser: (Foxit Toolbar) - {3041D03E-FD4B-44E0-B742-2D9B88305F98} - C:\Program Files\AskBarDis\bar\bin\askBar.dll (Ask.com)
O3 - HKU\S-1-5-21-1801674531-117609710-839522115-1004\..\Toolbar\WebBrowser: (Adobe PDF) - {47833539-D0C5-4125-9FA8-0819E2EAAC93} - C:\Program Files\Adobe\Acrobat 6.0\Acrobat\AcroIEFavClient.dll ()
O3 - HKU\S-1-5-21-1801674531-117609710-839522115-1004\..\Toolbar\WebBrowser: (Grab Pro) - {C55BBCD6-41AD-48AD-9953-3609C48EACC7} - C:\Program Files\Orbitdownloader\GrabPro.dll ()
O3 - HKU\S-1-5-21-1801674531-117609710-839522115-1004\..\Toolbar\WebBrowser: (ZoneAlarm Security Engine) - {EE2AC4E5-B0B0-4EC6-88A9-BCA1A32AB107} - C:\Program Files\CheckPoint\ZAForceField\Trustchecker\bin\TrustCheckerIEPlugin.dll (Check Point Software Technologies)
O3 - HKU\S-1-5-21-1801674531-117609710-839522115-1004\..\Toolbar\WebBrowser: (EPSON Web-To-Page) - {EE5D279F-081B-4404-994D-C6B60AAEBA6D} - C:\Program Files\epson\EPSON Web-To-Page\EPSON Web-To-Page.dll (SEIKO EPSON CORPORATION)
O4 - HKLM..\Run: [Acronis Scheduler2 Service] C:\Program Files\Common Files\Acronis\Schedule2\schedhlp.exe (Acronis)
O4 - HKLM..\Run: [AcronisTimounterMonitor] C:\Program Files\Acronis\TrueImageHome\TimounterMonitor.exe (Acronis)
O4 - HKLM..\Run: [ArcSoft Connection Service] C:\Program Files\Common Files\ArcSoft\Connection Service\Bin\ACDaemon.exe (ArcSoft Inc.)
O4 - HKLM..\Run: [avast] C:\Program Files\Alwil Software\Avast5\avastUI.exe (AVAST Software)
O4 - HKLM..\Run: [HTpatch] C:\WINDOWS\htpatch.exe ()
O4 - HKLM..\Run: [ISW] C:\Program Files\CheckPoint\ZAForceField\ForceField.exe (Check Point Software Technologies)
O4 - HKLM..\Run: [MobileConnect] C:\Program Files\Vodafone\Vodafone Mobile Connect\Bin\MobileConnect.exe (Vodafone)
O4 - HKLM..\Run: [NeroFilterCheck] C:\WINDOWS\system32\NeroCheck.exe (Ahead Software Gmbh)
O4 - HKLM..\Run: [NvCplDaemon] C:\WINDOWS\System32\NvCpl.dll (NVIDIA Corporation)
O4 - HKLM..\Run: [nwiz] C:\WINDOWS\System32\nwiz.exe (NVIDIA Corporation)
O4 - HKLM..\Run: [SpeedTouch USB Diagnostics] C:\Program Files\Thomson\SpeedTouch USB\Dragdiag.exe (THOMSON Telecom Belgium)
O4 - HKLM..\Run: [TrueImageMonitor.exe] C:\Program Files\Acronis\TrueImageHome\TrueImageMonitor.exe (Acronis)
O4 - HKLM..\Run: [TWCU] C:\Program Files\TP-LINK\TWCU\TWCU.exe (TP-LINK TECHNOLOGIES CO., LTD)
O4 - HKLM..\Run: [ZoneAlarm] C:\Program Files\CheckPoint\ZoneAlarm\zatray.exe (Check Point Software Technologies LTD)
O4 - HKU\S-1-5-21-1801674531-117609710-839522115-1004..\Run: [IDriveE Startup] C:\Program Files\IDrive\IDrvieEStartup.exe (Pro Softnet Corporation)
O4 - HKU\S-1-5-21-1801674531-117609710-839522115-1004..\Run: [NBJ] C:\Program Files\Ahead\Nero BackItUp\NBJ.exe (Ahead Software AG)
O4 - Startup: C:\Documents and Settings\All Users\Start Menu\Programs\Startup\Acrobat Assistant.lnk = C:\Program Files\Adobe\Acrobat 6.0\Distillr\acrotray.exe (Adobe Systems Inc.)
O4 - Startup: C:\Documents and Settings\All Users\Start Menu\Programs\Startup\Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office\OSA9.EXE (Microsoft Corporation)
O4 - Startup: C:\Documents and Settings\All Users\Start Menu\Programs\Startup\NETGEAR WG111v2 Smart Wizard.lnk = C:\Program Files\NETGEAR\WG111v2\WG111v2.exe ()
O4 - Startup: C:\Documents and Settings\User\Start Menu\Programs\Startup\IDrive Tray.lnk = C:\Program Files\IDrive\IDriveEReg2ini.exe (Pro Softnet Corp.)
O6 - HKLM\Software\Policies\Microsoft\Internet Explorer\Restrictions present
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoResolveTrack = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: HonorAutoRunSetting = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveAutoRun = 67108863
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 323
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDrives = 0
O7 - HKU\.DEFAULT\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O7 - HKU\.DEFAULT\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 323
O7 - HKU\.DEFAULT\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveAutoRun = 67108863
O7 - HKU\S-1-5-18\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O7 - HKU\S-1-5-18\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 323
O7 - HKU\S-1-5-18\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveAutoRun = 67108863
O7 - HKU\S-1-5-19\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O7 - HKU\S-1-5-19\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145
O7 - HKU\S-1-5-20\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O7 - HKU\S-1-5-20\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145
O7 - HKU\S-1-5-21-1801674531-117609710-839522115-1004\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O7 - HKU\S-1-5-21-1801674531-117609710-839522115-1004\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 323
O7 - HKU\S-1-5-21-1801674531-117609710-839522115-1004\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoResolveTrack = 1
O7 - HKU\S-1-5-21-1801674531-117609710-839522115-1004\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveAutoRun = 67108863
O7 - HKU\S-1-5-21-1801674531-117609710-839522115-1004\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDrives = 0
O8 - Extra context menu item: Free YouTube Download - C:\Documents and Settings\User\Application Data\DVDVideoSoftIEHelpers\youtubedownload.htm ()
O8 - Extra context menu item: Free YouTube to MP3 Converter - C:\Documents and Settings\User\Application Data\DVDVideoSoftIEHelpers\freeyoutubetomp3converter.htm ()
O8 - Extra context menu item: Read EXIF - C:\Program Files\ArcSoft\RAW Thumbnail Viewer\ArcEXIFM.htm ()
O15 - HKU\S-1-5-21-1801674531-117609710-839522115-1004\..Trusted Domains: localhost ([]http in Local intranet)
O16 - DPF: {001EE746-A1F9-460E-80AD-269E088D6A01}
http://shop.ebrary.com/support/plugins/ebraryRdr.cab (Infotl Control)
O16 - DPF: {0246ECA8-996F-11D1-BE2F-00A0C9037DFE}
http://www.truedoc.com/activex/tdserver.cab (TDServer Control)
O16 - DPF: {02BCC737-B171-4746-94C9-0D8A0B2C0089}
http://office.microsoft.com/templates/ieawsdc.cab (Microsoft Office Template and Media Control)
O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700}
http://go.microsoft.com/fwlink/?linkid=36467&clcid=0x409 (Windows Genuine Advantage Validation Tool)
O16 - DPF: {41695A8E-6414-11D4-8FB3-00D0B7730277}
http://activex.microsoft.com/objects/ocget.dll (Reg Error: Key error.)
O16 - DPF: {4C39376E-FA9D-4349-BACC-D305C1750EF3}
http://tools.ebayimg.com/eps/wl/activex/eBay_Enhanced_Picture_Control_v1-0-3-48.cab (EPUImageControl Class)
O16 - DPF: {4E62C4DE-627D-4604-B157-4B7D6B09F02E}
https://moneymanager.egg.com/Pinsafe/accounttracking.cab (AccountTracking Profile Manager Class)
O16 - DPF: {5ED80217-570B-4DA9-BF44-BE107C0EC166}
http://cdn.scan.onecare.live.com/resource/download/scanner/wlscbase8942.cab (Windows Live Safety Center Base Module)
O16 - DPF: {6BEA1C48-1850-486C-8F58-C7354BA3165E}
http://updates.lifescapeinc.com/installers/pinstall/pinstall.cab (Reg Error: Key error.)
O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3}
http://update.microsoft.com/microsoftupdate/v6/V5Controls/en/x86/client/muweb_site.cab?1146667490500 (MUWebControl Class)
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93}
http://java.sun.com/update/1.7.0/jinstall-1_7_0_02-windows-i586.cab (Java Plug-in 1.7.0_02)
O16 - DPF: {9F1C11AA-197B-4942-BA54-47A8489BB47F}
http://v4.windowsupdate.microsoft.com/CAB/x86/unicode/iuctl.CAB?37901.2256134259 (Reg Error: Key error.)
O16 - DPF: {A8F2B9BD-A6A0-486A-9744-18920D898429}
http://www.sibelius.com/download/software/win/ActiveXPlugin.cab (ScorchPlugin Class)
O16 - DPF: {AA218328-0EA8-4D70-8972-E987A9190FF4}
http://activex.microsoft.com/objects/ocget.dll (Reg Error: Key error.)
O16 - DPF: {CAFEEFAC-0014-0001-0001-ABCDEFFEDCBA} Reg Error: Key error. (Reg Error: Key error.)
O16 - DPF: {CAFEEFAC-0017-0000-0002-ABCDEFFEDCBA}
http://java.sun.com/update/1.7.0/jinstall-1_7_0_02-windows-i586.cab (Java Plug-in 1.7.0_02)
O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA}
http://java.sun.com/update/1.7.0/jinstall-1_7_0_02-windows-i586.cab (Java Plug-in 1.7.0_02)
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000}
http://fpdownload.macromedia.com/get/flashplayer/current/swflash.cab (Shockwave Flash Object)
O16 - DPF: {DA4F543C-C8A9-4E88-9A79-548CBB46F18F}
http://activex.microsoft.com/objects/ocget.dll (Reg Error: Key error.)
O16 - DPF: {E855A2D4-987E-4F3B-A51C-64D10A7E2479}
http://tools.ebayimg.com/eps/activex/EPSControl_v1-0-3-0.cab (EPSImageControl Class)
O16 - DPF: DirectAnimation Java Classes file://C:\WINDOWS\Java\classes\dajava.cab (Reg Error: Key error.)
O16 - DPF: Microsoft XML Parser for Java file://C:\WINDOWS\Java\classes\xmldso.cab (Reg Error: Key error.)
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 192.168.0.1
O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{AEB41B01-A73B-4A02-B6C6-351D23A4B011}: DhcpNameServer = 192.168.0.1
O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{E7683FB5-EED4-4E31-BDC3-8C41F6101A86}: DhcpNameServer = 192.168.0.1
O20 - HKLM Winlogon: Shell - (Explorer.exe) -C:\WINDOWS\explorer.exe (Microsoft Corporation)
O20 - HKLM Winlogon: UserInit - (C:\WINDOWS\system32\userinit.exe) -C:\WINDOWS\system32\userinit.exe (Microsoft Corporation)
O24 - Desktop WallPaper: C:\WINDOWS\Web\Wallpaper\Bliss.bmp
O24 - Desktop BackupWallPaper: C:\WINDOWS\Web\Wallpaper\Bliss.bmp
O30 - LSA: Authentication Packages - (relog_ap) -C:\WINDOWS\System32\relog_ap.dll (Acronis)
O32 - HKLM CDRom: AutoRun - 1
O32 - AutoRun File - [2003/10/10 22:48:43 | 000,000,000 | ---- | M] () - C:\AUTOEXEC.BAT -- [ NTFS ]
O34 - HKLM BootExecute: (autocheck autochk *)
O35 - HKLM\..comfile [open] -- "%1" %*
O35 - HKLM\..exefile [open] -- "%1" %*
O37 - HKLM\...com [@ = ComFile] -- "%1" %*
O37 - HKLM\...exe [@ = exefile] -- "%1" %*
========== Files/Folders - Created Within 30 Days ==========
[2012/01/29 20:15:57 | 000,584,192 | ---- | C] (OldTimer Tools) -- C:\Documents and Settings\User\Desktop\OTL.exe
[2012/01/29 18:17:15 | 004,393,882 | R--- | C] (Swearware) -- C:\Documents and Settings\User\Desktop\ComboFix.exe
[2012/01/28 21:16:10 | 000,000,000 | ---D | C] -- C:\Documents and Settings\User\Desktop\malware cleaning
[2012/01/28 18:59:33 | 000,000,000 | ---D | C] -- C:\Documents and Settings\User\Local Settings\Application Data\Sun
[2012/01/28 18:45:21 | 000,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Application Data\Sun
[2012/01/28 18:45:19 | 000,000,000 | ---D | C] -- C:\Program Files\Common Files\Java
[2012/01/28 18:45:02 | 000,637,848 | ---- | C] (Oracle Corporation) -- C:\WINDOWS\System32\npdeployJava1.dll
[2012/01/28 18:45:02 | 000,567,184 | ---- | C] (Oracle Corporation) -- C:\WINDOWS\System32\deployJava1.dll
[2012/01/28 18:45:02 | 000,223,112 | ---- | C] (Oracle Corporation) -- C:\WINDOWS\System32\javaws.exe
[2012/01/28 18:45:02 | 000,173,960 | ---- | C] (Oracle Corporation) -- C:\WINDOWS\System32\javaw.exe
[2012/01/28 18:45:02 | 000,173,960 | ---- | C] (Oracle Corporation) -- C:\WINDOWS\System32\java.exe
[2012/01/28 18:45:02 | 000,141,312 | ---- | C] (Oracle Corporation) -- C:\WINDOWS\System32\javacpl.cpl
[2012/01/25 20:18:41 | 000,000,000 | RHSD | C] -- C:\cmdcons
[2012/01/25 20:14:47 | 000,518,144 | ---- | C] (SteelWerX) -- C:\WINDOWS\SWREG.exe
[2012/01/25 20:14:47 | 000,406,528 | ---- | C] (SteelWerX) -- C:\WINDOWS\SWSC.exe
[2012/01/25 20:14:47 | 000,212,480 | ---- | C] (SteelWerX) -- C:\WINDOWS\SWXCACLS.exe
[2012/01/25 20:14:47 | 000,060,416 | ---- | C] (NirSoft) -- C:\WINDOWS\NIRCMD.exe
[2012/01/25 20:14:26 | 000,000,000 | ---D | C] -- C:\WINDOWS\ERDNT
[2012/01/25 20:14:07 | 000,000,000 | ---D | C] -- C:\Qoobox
[2012/01/25 20:13:57 | 000,000,000 | R--D | C] -- C:\Documents and Settings\User\Start Menu\Programs\Administrative Tools
[2012/01/25 13:19:38 | 000,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Start Menu\Programs\Check Point
[2012/01/25 13:19:33 | 000,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Application Data\CheckPoint
[2012/01/13 12:02:48 | 000,000,000 | ---D | C] -- C:\Program Files\TaxCalc 2011
[2012/01/11 10:50:56 | 000,000,000 | ---D | C] -- C:\Documents and Settings\User\Desktop\Backlinks Report
[2012/01/10 12:33:07 | 000,000,000 | ---D | C] -- C:\Documents and Settings\User\Desktop\WATER ORG POSTS
[2012/01/01 15:58:24 | 000,000,000 | ---D | C] -- C:\Documents and Settings\User\Desktop\FURNITURE
[7 C:\WINDOWS\*.tmp files -> C:\WINDOWS\*.tmp -> ]
========== Files - Modified Within 30 Days ==========
[2012/01/29 20:16:01 | 000,584,192 | ---- | M] (OldTimer Tools) -- C:\Documents and Settings\User\Desktop\OTL.exe
[2012/01/29 19:54:00 | 000,000,882 | ---- | M] () -- C:\WINDOWS\tasks\GoogleUpdateTaskMachineUA.job
[2012/01/29 19:22:39 | 000,437,004 | ---- | M] () -- C:\WINDOWS\System32\perfh009.dat
[2012/01/29 19:22:39 | 000,069,536 | ---- | M] () -- C:\WINDOWS\System32\perfc009.dat
[2012/01/29 19:15:27 | 000,002,048 | --S- | M] () -- C:\WINDOWS\bootstat.dat
[2012/01/29 18:26:16 | 004,393,882 | R--- | M] (Swearware) -- C:\Documents and Settings\User\Desktop\ComboFix.exe
[2012/01/29 16:54:01 | 000,000,878 | ---- | M] () -- C:\WINDOWS\tasks\GoogleUpdateTaskMachineCore.job
[2012/01/29 16:43:17 | 000,000,362 | ---- | M] () -- C:\WINDOWS\tasks\Symantec NetDetect.job
[2012/01/29 11:35:55 | 000,000,000 | ---- | M] () -- C:\Documents and Settings\User\defogger_reenable
[2012/01/29 10:13:43 | 000,000,327 | RHS- | M] () -- C:\boot.ini
[2012/01/28 19:36:16 | 000,002,626 | ---- | M] () -- C:\WINDOWS\System32\CONFIG.NT
[2012/01/28 18:44:44 | 000,223,112 | ---- | M] (Oracle Corporation) -- C:\WINDOWS\System32\javaws.exe
[2012/01/28 18:44:44 | 000,173,960 | ---- | M] (Oracle Corporation) -- C:\WINDOWS\System32\javaw.exe
[2012/01/28 18:44:44 | 000,173,960 | ---- | M] (Oracle Corporation) -- C:\WINDOWS\System32\java.exe
[2012/01/28 18:44:44 | 000,141,312 | ---- | M] (Oracle Corporation) -- C:\WINDOWS\System32\javacpl.cpl
[2012/01/28 18:44:43 | 000,637,848 | ---- | M] (Oracle Corporation) -- C:\WINDOWS\System32\npdeployJava1.dll
[2012/01/28 18:44:41 | 000,567,184 | ---- | M] (Oracle Corporation) -- C:\WINDOWS\System32\deployJava1.dll
[2012/01/28 11:09:35 | 000,020,712 | ---- | M] () -- C:\WINDOWS\System32\wpa.dbl
[2012/01/27 19:40:08 | 000,000,648 | ---- | M] () -- C:\WINDOWS\QUICKEN.INI
[2012/01/27 19:39:56 | 000,008,006 | ---- | M] () -- C:\WINDOWS\qwshellx.ini
[2012/01/25 20:57:54 | 000,000,027 | ---- | M] () -- C:\WINDOWS\System32\drivers\etc\hosts
[2012/01/25 13:29:38 | 000,415,859 | ---- | M] () -- C:\WINDOWS\System32\vsconfig.xml
[2012/01/06 14:33:34 | 005,135,836 | ---- | M] (TweetAdder.com) -- C:\Documents and Settings\User\Desktop\tweetadder3.exe
[2012/01/06 11:51:24 | 000,029,696 | ---- | M] (iolo technologies, LLC) -- C:\WINDOWS\System32\iolobtdfg.exe
[2012/01/06 11:51:16 | 000,011,776 | ---- | M] (iolo technologies, LLC) -- C:\WINDOWS\System32\smrgdf.exe
[2012/01/06 11:29:06 | 002,083,464 | ---- | M] (iolo technologies, LLC) -- C:\WINDOWS\System32\Incinerator32.dll
[2012/01/04 16:31:14 | 000,002,908 | ---- | M] () -- C:\Documents and Settings\User\Desktop\application-form-2012-01-04.csv
[2012/01/01 15:35:36 | 000,145,358 | ---- | M] () -- C:\Documents and Settings\User\Desktop\larynx.jpg
[7 C:\WINDOWS\*.tmp files -> C:\WINDOWS\*.tmp -> ]
========== Files Created - No Company Name ==========
[2012/01/29 11:35:55 | 000,000,000 | ---- | C] () -- C:\Documents and Settings\User\defogger_reenable
[2012/01/25 20:18:47 | 000,260,272 | RHS- | C] () -- C:\cmldr
[2012/01/25 20:14:47 | 000,256,000 | ---- | C] () -- C:\WINDOWS\PEV.exe
[2012/01/25 20:14:47 | 000,208,896 | ---- | C] () -- C:\WINDOWS\MBR.exe
[2012/01/25 20:14:47 | 000,098,816 | ---- | C] () -- C:\WINDOWS\sed.exe
[2012/01/25 20:14:47 | 000,080,412 | ---- | C] () -- C:\WINDOWS\grep.exe
[2012/01/25 20:14:47 | 000,068,096 | ---- | C] () -- C:\WINDOWS\zip.exe
[2012/01/25 13:22:46 | 000,415,859 | ---- | C] () -- C:\WINDOWS\System32\vsconfig.xml
[2012/01/04 16:31:13 | 000,002,908 | ---- | C] () -- C:\Documents and Settings\User\Desktop\application-form-2012-01-04.csv
[2012/01/01 16:03:43 | 002,620,762 | ---- | C] () -- C:\Documents and Settings\User\Desktop\09 CaroMioBen.wma
[2012/01/01 15:35:32 | 000,145,358 | ---- | C] () -- C:\Documents and Settings\User\Desktop\larynx.jpg
[2011/11/30 15:42:24 | 000,007,219 | ---- | C] () -- C:\WINDOWS\hplj1010.ini
[2011/11/30 15:16:52 | 000,000,417 | ---- | C] () -- C:\WINDOWS\hpbvspst.ini
[2011/11/30 15:16:51 | 000,001,112 | ---- | C] () -- C:\WINDOWS\hpbvnstp.ini
[2011/11/06 11:43:03 | 000,000,054 | ---- | C] () -- C:\WINDOWS\Player.INI
[2010/12/14 12:55:16 | 000,016,968 | ---- | C] () -- C:\WINDOWS\System32\drivers\hitmanpro35.sys
[2010/09/04 15:21:18 | 000,165,376 | ---- | C] () -- C:\WINDOWS\System32\unrar.dll
[2010/09/04 15:21:17 | 000,000,038 | ---- | C] () -- C:\WINDOWS\avisplitter.ini
[2010/09/04 15:21:15 | 000,790,528 | ---- | C] () -- C:\WINDOWS\System32\xvidcore.dll
[2010/09/04 15:21:15 | 000,134,144 | ---- | C] () -- C:\WINDOWS\System32\xvidvfw.dll
[2010/09/04 15:21:15 | 000,108,032 | ---- | C] () -- C:\WINDOWS\System32\ff_vfw.dll
[2010/08/21 12:18:55 | 000,026,032 | ---- | C] () -- C:\WINDOWS\System32\IDriveEXceedCryReg.exe
[2010/08/21 12:18:54 | 000,055,808 | ---- | C] () -- C:\WINDOWS\System32\zlib1.dll
[2010/01/15 20:26:56 | 000,000,000 | ---- | C] () -- C:\WINDOWS\SmartAdWrapper.INI
[2009/12/12 16:54:27 | 000,000,013 | -H-- | C] () -- C:\Documents and Settings\All Users\Application Data\˜113.›sys
[2009/10/23 16:57:24 | 019,247,104 | ---- | C] () -- C:\Documents and Settings\User\Application Data\TweetAdder
[2009/08/20 20:19:01 | 000,000,028 | ---- | C] () -- C:\WINDOWS\pdf995.ini
[2009/08/20 20:16:11 | 000,051,716 | ---- | C] () -- C:\WINDOWS\System32\pdf995mon.dll
[2009/08/20 20:16:11 | 000,000,085 | ---- | C] () -- C:\WINDOWS\wpd99.drv
[2009/08/13 10:51:14 | 000,000,000 | ---- | C] () -- C:\Documents and Settings\All Users\Application Data\LauncherAccess.dt
[2009/08/13 10:43:39 | 000,005,632 | ---- | C] () -- C:\WINDOWS\System32\drivers\StarOpen.sys
[2009/08/04 14:11:43 | 000,120,200 | ---- | C] () -- C:\WINDOWS\System32\DLLDEV32i.dll
[2009/08/04 14:11:06 | 000,006,211 | ---- | C] () -- C:\WINDOWS\mgxoschk.ini
[2009/07/01 16:51:34 | 000,000,000 | ---- | C] () -- C:\WINDOWS\ABC_mru.ini
[2009/06/02 16:39:57 | 000,087,552 | ---- | C] () -- C:\WINDOWS\System32\cpwmon2k.dll
[2009/04/10 18:24:28 | 000,000,754 | ---- | C] () -- C:\WINDOWS\WORDPAD.INI
[2008/10/16 15:55:33 | 000,072,192 | ---- | C] () -- C:\WINDOWS\cadkasdeinst01e.exe
[2008/09/22 14:21:34 | 000,127,092 | R--- | C] () -- C:\Documents and Settings\All Users\Application Data\DeviceManager.xml.rc4
[2008/09/02 16:04:23 | 000,086,016 | ---- | C] () -- C:\WINDOWS\System32\BinCoder.dll
[2008/08/20 16:45:46 | 000,020,270 | ---- | C] () -- C:\Documents and Settings\All Users\Application Data\DeviceInstaller.xml
[2008/08/19 16:17:06 | 000,149,480 | ---- | C] () -- C:\WINDOWS\System32\drivers\ar5523.bin
[2008/08/19 16:17:06 | 000,149,392 | ---- | C] () -- C:\WINDOWS\System32\ar5523.bin
[2008/08/19 16:17:03 | 000,192,512 | ---- | C] () -- C:\WINDOWS\System32\AegisI5.exe
[2008/08/19 16:17:03 | 000,036,864 | ---- | C] () -- C:\WINDOWS\System32\acs.exe
[2008/08/12 21:04:59 | 000,000,185 | ---- | C] () -- C:\WINDOWS\System32\msblcd32.dll
[2008/05/11 09:39:05 | 000,221,184 | ---- | C] () -- C:\WINDOWS\System32\lame_enc.dll
[2008/03/14 19:16:54 | 000,049,152 | R--- | C] () -- C:\WINDOWS\System32\ChCfg.exe
[2008/03/14 19:14:35 | 000,200,704 | R--- | C] () -- C:\WINDOWS\System32\igfxCoIn_v4704.dll
[2008/03/14 19:11:38 | 000,005,810 | R--- | C] () -- C:\WINDOWS\System32\drivers\ASACPI.sys
[2007/07/30 08:10:26 | 000,000,029 | ---- | C] () -- C:\WINDOWS\DEBUGSM.INI
[2007/07/21 14:07:12 | 000,111,932 | ---- | C] () -- C:\WINDOWS\System32\EPPICPrinterDB.dat
[2007/07/21 14:07:12 | 000,001,146 | ---- | C] () -- C:\WINDOWS\System32\EPPICPresetData_DU.dat
[2007/07/21 14:07:12 | 000,001,139 | ---- | C] () -- C:\WINDOWS\System32\EPPICPresetData_BP.dat
[2007/07/21 14:07:12 | 000,001,136 | ---- | C] () -- C:\WINDOWS\System32\EPPICPresetData_ES.dat
[2007/07/21 14:07:12 | 000,001,129 | ---- | C] () -- C:\WINDOWS\System32\EPPICPresetData_FR.dat
[2007/07/21 14:07:12 | 000,001,129 | ---- | C] () -- C:\WINDOWS\System32\EPPICPresetData_CF.dat
[2007/07/21 14:07:12 | 000,001,120 | ---- | C] () -- C:\WINDOWS\System32\EPPICPresetData_IT.dat
[2007/07/21 14:07:12 | 000,001,107 | ---- | C] () -- C:\WINDOWS\System32\EPPICPresetData_GE.dat
[2007/07/21 14:07:12 | 000,001,104 | ---- | C] () -- C:\WINDOWS\System32\EPPICPresetData_EN.dat
[2007/07/21 14:07:12 | 000,000,097 | ---- | C] () -- C:\WINDOWS\System32\PICSDK.ini
[2007/07/21 14:07:11 | 000,031,053 | ---- | C] () -- C:\WINDOWS\System32\EPPICPattern131.dat
[2007/07/21 14:07:11 | 000,027,417 | ---- | C] () -- C:\WINDOWS\System32\EPPICPattern121.dat
[2007/07/21 14:07:11 | 000,026,154 | ---- | C] () -- C:\WINDOWS\System32\EPPICPattern1.dat
[2007/07/21 14:07:11 | 000,024,903 | ---- | C] () -- C:\WINDOWS\System32\EPPICPattern3.dat
[2007/07/21 14:07:11 | 000,021,390 | ---- | C] () -- C:\WINDOWS\System32\EPPICPattern5.dat
[2007/07/21 14:07:11 | 000,020,148 | ---- | C] () -- C:\WINDOWS\System32\EPPICPattern2.dat
[2007/07/21 14:07:11 | 000,011,811 | ---- | C] () -- C:\WINDOWS\System32\EPPICPattern4.dat
[2007/07/21 14:07:11 | 000,004,943 | ---- | C] () -- C:\WINDOWS\System32\EPPICPattern6.dat
[2007/07/21 14:07:11 | 000,001,139 | ---- | C] () -- C:\WINDOWS\System32\EPPICPresetData_PT.dat
[2007/07/21 14:02:17 | 000,000,025 | ---- | C] () -- C:\WINDOWS\CDE DX6000EFDG.ini
[2007/03/27 18:38:22 | 000,045,056 | R--- | C] () -- C:\Program Files\SetAttrib.exe
[2007/03/12 12:12:52 | 000,159,744 | ---- | C] () -- C:\WINDOWS\System32\hasher.dll
[2006/10/01 09:55:14 | 000,000,034 | ---- | C] () -- C:\WINDOWS\ebraryRdr.ini
[2006/06/17 18:09:15 | 000,000,004 | ---- | C] () -- C:\Documents and Settings\User\Application Data\ETCPitchBenches
[2006/06/17 18:09:03 | 000,000,396 | ---- | C] () -- C:\Documents and Settings\User\Application Data\ETCPitchScores
[2006/06/17 18:08:42 | 000,000,244 | ---- | C] () -- C:\Documents and Settings\User\Application Data\ETCPrefs
[2006/06/17 18:08:42 | 000,000,015 | ---- | C] () -- C:\Documents and Settings\User\Application Data\ETCHarmonyBench5
[2006/06/17 18:08:42 | 000,000,015 | ---- | C] () -- C:\Documents and Settings\User\Application Data\ETCHarmonyBench4
[2006/06/17 18:08:42 | 000,000,015 | ---- | C] () -- C:\Documents and Settings\User\Application Data\ETCHarmonyBench3
[2006/06/17 18:08:42 | 000,000,015 | ---- | C] () -- C:\Documents and Settings\User\Application Data\ETCHarmonyBench2
[2006/06/17 18:08:42 | 000,000,015 | ---- | C] () -- C:\Documents and Settings\User\Application Data\ETCHarmonyBench1
[2006/06/17 18:08:42 | 000,000,015 | ---- | C] () -- C:\Documents and Settings\User\Application Data\ETCHarmonyBench0
[2006/06/08 22:05:59 | 000,001,368 | ---- | C] () -- C:\WINDOWS\System32\SpoonUninstall-dBpowerAMP WMA V9.1 Codec.dat
[2006/05/04 13:24:00 | 000,036,593 | ---- | C] () -- C:\WINDOWS\System32\SpoonUninstall-dBpowerAMP Music Converter.dat
[2006/05/03 14:13:06 | 000,205,312 | R--- | C] () -- C:\WINDOWS\patchw32.dll
[2006/05/03 14:12:30 | 000,205,312 | R--- | C] () -- C:\WINDOWS\pw32a.dll
[2006/04/26 14:36:00 | 000,204,800 | ---- | C] () -- C:\WINDOWS\System32\IVIresizeW7.dll
[2006/04/26 14:36:00 | 000,200,704 | ---- | C] () -- C:\WINDOWS\System32\IVIresizeA6.dll
[2006/04/26 14:36:00 | 000,192,512 | ---- | C] () -- C:\WINDOWS\System32\IVIresizeP6.dll
[2006/04/26 14:36:00 | 000,192,512 | ---- | C] () -- C:\WINDOWS\System32\IVIresizeM6.dll
[2006/04/26 14:36:00 | 000,188,416 | ---- | C] () -- C:\WINDOWS\System32\IVIresizePX.dll
[2006/04/26 14:36:00 | 000,020,480 | ---- | C] () -- C:\WINDOWS\System32\IVIresize.dll
[2006/04/20 22:06:43 | 000,000,107 | ---- | C] () -- C:\WINDOWS\VobEdit.INI
[2006/04/11 12:30:55 | 000,000,127 | ---- | C] () -- C:\Documents and Settings\User\Local Settings\Application Data\fusioncache.dat
[2006/02/28 12:00:00 | 013,107,200 | ---- | C] () -- C:\WINDOWS\System32\oembios.bin
[2006/02/28 12:00:00 | 000,673,088 | ---- | C] () -- C:\WINDOWS\System32\mlang.dat
[2006/02/28 12:00:00 | 000,272,128 | ---- | C] () -- C:\WINDOWS\System32\perfi009.dat
[2006/02/28 12:00:00 | 000,218,003 | ---- | C] () -- C:\WINDOWS\System32\dssec.dat
[2006/02/28 12:00:00 | 000,046,258 | ---- | C] () -- C:\WINDOWS\System32\mib.bin
[2006/02/28 12:00:00 | 000,028,626 | ---- | C] () -- C:\WINDOWS\System32\perfd009.dat
[2006/02/28 12:00:00 | 000,004,569 | ---- | C] () -- C:\WINDOWS\System32\secupd.dat
[2006/02/28 12:00:00 | 000,004,461 | ---- | C] () -- C:\WINDOWS\System32\oembios.dat
[2006/02/28 12:00:00 | 000,001,804 | ---- | C] () -- C:\WINDOWS\System32\dcache.bin
[2006/02/15 13:41:47 | 000,001,089 | ---- | C] () -- C:\WINDOWS\atm.ini
[2005/12/27 18:16:30 | 000,000,180 | -H-- | C] () -- C:\WINDOWS\System32\einfopsv10.dll
[2005/11/16 12:01:53 | 000,002,936 | ---- | C] () -- C:\Documents and Settings\All Users\Application Data\QTSBandwidthCache
[2005/11/13 13:19:56 | 000,099,970 | ---- | C] () -- C:\WINDOWS\UninstallFirefox.exe
[2005/11/13 13:19:31 | 000,003,445 | ---- | C] () -- C:\WINDOWS\mozver.dat
[2005/11/13 13:04:19 | 000,000,315 | ---- | C] () -- C:\WINDOWS\System32\PCRVersion.ini
[2005/10/29 10:15:06 | 000,005,606 | ---- | C] () -- C:\WINDOWS\System32\stci.dll
[2005/10/10 14:45:41 | 000,000,000 | ---- | C] () -- C:\WINDOWS\PROTOCOL.INI
[2005/10/03 13:29:51 | 000,000,043 | ---- | C] () -- C:\WINDOWS\gswin32.ini
[2005/03/29 13:59:47 | 000,006,688 | ---- | C] () -- C:\WINDOWS\movexe.exe
[2005/02/23 13:59:49 | 000,000,116 | ---- | C] () -- C:\WINDOWS\NeroDigital.ini
[2004/12/25 17:34:42 | 000,696,320 | ---- | C] () -- C:\WINDOWS\System32\libeay32.dll
[2004/12/25 17:34:42 | 000,155,648 | ---- | C] () -- C:\WINDOWS\System32\ssleay32.dll
[2004/11/15 10:40:34 | 000,000,062 | ---- | C] () -- C:\WINDOWS\I_VIEW32.INI
[2004/11/12 16:04:10 | 000,795,832 | ---- | C] () -- C:\WINDOWS\System32\libeay32_0.9.6l.dll
[2004/11/05 14:20:20 | 000,039,095 | ---- | C] () -- C:\WINDOWS\iccsigs.dat
[2004/09/29 14:17:28 | 005,927,424 | ---- | C] () -- C:\WINDOWS\System32\Drs732.dll
[2004/09/14 18:36:31 | 000,000,056 | ---- | C] () -- C:\WINDOWS\lifeart.ini
[2004/08/30 14:25:06 | 000,000,000 | ---- | C] () -- C:\Documents and Settings\User\Application Data\dm.ini
[2004/05/22 08:18:43 | 000,004,212 | -H-- | C] () -- C:\WINDOWS\System32\zllictbl.dat
[2004/05/02 17:50:19 | 000,126,464 | ---- | C] () -- C:\Documents and Settings\User\Local Settings\Application Data\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2004/04/27 09:31:47 | 000,000,056 | ---- | C] () -- C:\WINDOWS\SSB.ini
[2004/04/23 14:01:12 | 000,000,026 | ---- | C] () -- C:\WINDOWS\System32\HANDLE.INI
[2004/03/08 13:24:47 | 000,011,036 | ---- | C] () -- C:\WINDOWS\CDPlayer.ini
[2004/03/07 22:23:27 | 000,130,048 | ---- | C] () -- C:\WINDOWS\System32\SpoonUninstall.exe
[2004/02/17 10:22:27 | 000,081,920 | ---- | C] () -- C:\WINDOWS\System32\TyrannLite.dll
[2003/12/31 16:02:55 | 000,000,107 | ---- | C] () -- C:\WINDOWS\INTUIT.INI
[2003/12/27 13:16:46 | 000,053,248 | ---- | C] () -- C:\WINDOWS\System32\zlib.dll
[2003/12/27 13:15:06 | 000,000,407 | ---- | C] () -- C:\WINDOWS\webpos20.ini
[2003/12/22 15:24:44 | 000,000,264 | ---- | C] () -- C:\WINDOWS\QVPC.INI
[2003/10/26 11:59:10 | 000,001,783 | ---- | C] () -- C:\WINDOWS\nsreg.dat
[2003/10/24 21:59:18 | 000,000,313 | ---- | C] () -- C:\WINDOWS\browsev2.ini
[2003/10/24 13:44:44 | 000,180,224 | ---- | C] () -- C:\WINDOWS\System32\xwsindex.exe
[2003/10/22 16:12:09 | 000,009,336 | ---- | C] () -- C:\Documents and Settings\User\Application Data\Comma Separated Values (Windows).EML
[2003/10/22 09:26:08 | 000,008,006 | ---- | C] () -- C:\WINDOWS\qwshellx.ini
[2003/10/10 23:02:56 | 000,000,090 | ---- | C] () -- C:\WINDOWS\A5.INI
[2003/10/10 22:51:07 | 000,000,186 | ---- | C] () -- C:\WINDOWS\rtpatch.ini
[2003/10/10 22:48:43 | 000,003,433 | ---- | C] () -- C:\WINDOWS\WPR.INI
[2003/10/10 22:48:43 | 000,000,648 | ---- | C] () -- C:\WINDOWS\QUICKEN.INI
[2003/10/10 21:21:14 | 000,001,793 | ---- | C] () -- C:\WINDOWS\System32\fxsperf.ini
[2003/10/09 19:27:13 | 000,112,688 | ---- | C] () -- C:\WINDOWS\System32\shw32.dll
[2003/10/09 11:50:48 | 000,000,185 | ---- | C] () -- C:\WINDOWS\mdm.ini
[2003/10/09 11:32:05 | 000,000,886 | ---- | C] () -- C:\WINDOWS\ODBC.INI
[2003/10/09 11:01:49 | 000,210,944 | ---- | C] () -- C:\WINDOWS\System32\Msvcrt10.dll
[2003/10/07 12:44:34 | 000,006,550 | ---- | C] () -- C:\WINDOWS\jautoexp.dat
[2003/10/07 11:57:59 | 000,004,346 | ---- | C] () -- C:\WINDOWS\ODBCINST.INI
[2003/10/07 11:57:01 | 000,939,032 | ---- | C] () -- C:\WINDOWS\System32\FNTCACHE.DAT
[2003/10/07 11:18:45 | 000,000,154 | ---- | C] () -- C:\WINDOWS\Wininit.ini
[2003/10/07 11:18:45 | 000,000,092 | ---- | C] () -- C:\WINDOWS\CMISETUP.INI
[2003/10/07 11:18:45 | 000,000,026 | ---- | C] () -- C:\WINDOWS\CMCDPLAY.INI
[2003/10/07 11:18:35 | 000,237,568 | ---- | C] () -- C:\WINDOWS\CMIUninstall.exe
[2003/10/07 11:18:35 | 000,212,992 | ---- | C] () -- C:\WINDOWS\CmiRmRedundDir.exe
[2003/10/07 11:18:35 | 000,028,672 | ---- | C] () -- C:\WINDOWS\CMIRmDriver.dll
[2003/10/07 11:16:28 | 000,032,768 | ---- | C] () -- C:\WINDOWS\SIS_LIB.DLL
[2003/10/07 11:16:27 | 000,028,672 | R--- | C] () -- C:\WINDOWS\htpatch.exe
[2003/10/07 11:16:27 | 000,003,072 | R--- | C] () -- C:\WINDOWS\winio.sys
[2003/10/07 11:14:55 | 000,011,230 | ---- | C] () -- C:\WINDOWS\Ascd_tmp.ini
[2003/10/07 11:14:55 | 000,005,824 | ---- | C] () -- C:\WINDOWS\System32\drivers\ASUSHWIO.SYS
[2003/10/07 11:12:41 | 000,002,048 | --S- | C] () -- C:\WINDOWS\bootstat.dat
[2003/10/07 11:08:15 | 000,024,208 | ---- | C] () -- C:\WINDOWS\System32\emptyregdb.dat
[2003/04/09 13:40:22 | 000,147,456 | ---- | C] () -- C:\WINDOWS\System32\lttls13n.dll
[2003/04/09 13:40:14 | 000,708,608 | ---- | C] () -- C:\WINDOWS\System32\ltcry13n.dll
[2003/04/09 13:40:02 | 000,118,784 | ---- | C] () -- C:\WINDOWS\System32\lfkodak.dll
[2003/04/09 13:40:00 | 000,338,944 | ---- | C] () -- C:\WINDOWS\System32\lffpx7.dll
[2003/03/09 20:31:04 | 000,561,152 | ---- | C] () -- C:\WINDOWS\System32\hpotscl.dll
[2002/11/04 03:09:00 | 000,045,056 | ---- | C] () -- C:\WINDOWS\System32\besch.exe
[2002/11/04 03:09:00 | 000,028,672 | ---- | C] () -- C:\WINDOWS\System32\besched.dll
[2002/09/02 15:45:30 | 000,001,024 | ---- | C] () -- C:\WINDOWS\System32\atsdrve.dll
[2002/08/29 12:00:00 | 000,437,004 | ---- | C] () -- C:\WINDOWS\System32\perfh009.dat
[2002/08/29 12:00:00 | 000,069,536 | ---- | C] () -- C:\WINDOWS\System32\perfc009.dat
[2002/08/29 12:00:00 | 000,000,741 | ---- | C] () -- C:\WINDOWS\System32\noise.dat
[2002/06/06 01:01:58 | 000,029,696 | ---- | C] () -- C:\WINDOWS\System32\asutl8.dll
[2002/03/31 13:26:54 | 000,000,514 | ---- | C] () -- C:\WINDOWS\ISYSKNOW.INI
[2001/07/31 11:17:12 | 000,094,274 | ---- | C] () -- C:\WINDOWS\System32\HPBHEALR.DLL
[1999/07/05 10:00:00 | 000,074,703 | ---- | C] () -- C:\WINDOWS\System32\mfc45.dll
[1999/01/22 18:46:56 | 000,065,536 | ---- | C] () -- C:\WINDOWS\System32\MSRTEDIT.DLL
[1998/12/24 14:38:02 | 000,002,496 | ---- | C] () -- C:\WINDOWS\ISYS.INI
[1998/09/30 13:11:20 | 000,657,408 | ---- | C] () -- C:\WINDOWS\System32\ISYSU532.DLL
[1998/07/31 04:14:40 | 000,000,246 | ---- | C] () -- C:\WINDOWS\ISYSSQL.INI
[1998/06/09 23:00:00 | 000,015,120 | ---- | C] () -- C:\WINDOWS\System32\REPUTIL.DLL
[1998/05/17 23:00:00 | 000,014,017 | ---- | C] () -- C:\WINDOWS\JAUTOEXP.INI
[1998/01/12 08:00:00 | 000,040,448 | ---- | C] () -- C:\WINDOWS\System32\REGOBJ.DLL
========== Alternate Data Streams ==========
@Alternate Data Stream - 68 bytes -> C:\WINDOWS\winnt256.bmp:KAVICHS
@Alternate Data Stream - 68 bytes -> C:\WINDOWS\winnt.bmp:KAVICHS
@Alternate Data Stream - 68 bytes -> C:\WINDOWS\Windows Update.log:KAVICHS
@Alternate Data Stream - 68 bytes -> C:\WINDOWS\webpos20.ini:KAVICHS
@Alternate Data Stream - 68 bytes -> C:\WINDOWS\System32\wpa.dbl:KAVICHS
@Alternate Data Stream - 68 bytes -> C:\WINDOWS\System32\tsccvid.dll:KAVICHS
@Alternate Data Stream - 68 bytes -> C:\WINDOWS\System32\tapectrl.cfg:KAVICHS
@Alternate Data Stream - 68 bytes -> C:\WINDOWS\System32\SpoonUninstall.exe:KAVICHS
@Alternate Data Stream - 68 bytes -> C:\WINDOWS\System32\pnpwhsc.dll:KAVICHS
@Alternate Data Stream - 68 bytes -> C:\WINDOWS\System32\nwiz.exe:KAVICHS
@Alternate Data Stream - 68 bytes -> C:\WINDOWS\System32\nvwrseng.dll:KAVICHS
@Alternate Data Stream - 68 bytes -> C:\WINDOWS\System32\nvsvc32.exe:KAVICHS
@Alternate Data Stream - 68 bytes -> C:\WINDOWS\System32\nvrseng.dll:KAVICHS
@Alternate Data Stream - 68 bytes -> C:\WINDOWS\System32\nview.dll:KAVICHS
@Alternate Data Stream - 68 bytes -> C:\WINDOWS\System32\NvCpl.dll:KAVICHS
@Alternate Data Stream - 68 bytes -> C:\WINDOWS\System32\msg723.acm:KAVICHS
@Alternate Data Stream - 68 bytes -> C:\WINDOWS\System32\mapi32.dll:KAVICHS
@Alternate Data Stream - 68 bytes -> C:\WINDOWS\System32\javasup.vxd:KAVICHS
@Alternate Data Stream - 68 bytes -> C:\WINDOWS\System32\hpzlnt07.dll:KAVICHS
@Alternate Data Stream - 68 bytes -> C:\WINDOWS\System32\hpotscl.dll:KAVICHS
@Alternate Data Stream - 68 bytes -> C:\WINDOWS\System32\fxsroute.dll:KAVICHS
@Alternate Data Stream - 68 bytes -> C:\WINDOWS\System32\drivers\serscan.sys:KAVICHS
@Alternate Data Stream - 68 bytes -> C:\WINDOWS\System32\drivers\MODEMCSA.sys:KAVICHS
@Alternate Data Stream - 68 bytes -> C:\WINDOWS\System32\drivers\HCF_MSFT.sys:KAVICHS
@Alternate Data Stream - 68 bytes -> C:\WINDOWS\System32\drivers\etc\services:KAVICHS
@Alternate Data Stream - 68 bytes -> C:\WINDOWS\System32\drivers\etc\quotes:KAVICHS
@Alternate Data Stream - 68 bytes -> C:\WINDOWS\System32\drivers\drvmcdb.sys:KAVICHS
@Alternate Data Stream - 68 bytes -> C:\WINDOWS\System32\drivers\cmuda.sys:KAVICHS
@Alternate Data Stream - 68 bytes -> C:\WINDOWS\System32\drivers\audstub.sys:KAVICHS
@Alternate Data Stream - 68 bytes -> C:\WINDOWS\System32\dc210usd.dll:KAVICHS
@Alternate Data Stream - 68 bytes -> C:\WINDOWS\System32\dc210_32.dll:KAVICHS
@Alternate Data Stream - 68 bytes -> C:\WINDOWS\System32\cmuda.dll:KAVICHS
@Alternate Data Stream - 68 bytes -> C:\WINDOWS\System\cmicnfg.cpl:KAVICHS
@Alternate Data Stream - 68 bytes -> C:\WINDOWS\SiSUSBrg.exe:KAVICHS
@Alternate Data Stream - 68 bytes -> C:\WINDOWS\SiSport.sys:KAVICHS
@Alternate Data Stream - 68 bytes -> C:\WINDOWS\msshlib2.log:KAVICHS
@Alternate Data Stream - 68 bytes -> C:\WINDOWS\mover.log:KAVICHS
@Alternate Data Stream - 68 bytes -> C:\WINDOWS\MDACSET.log:KAVICHS
@Alternate Data Stream - 68 bytes -> C:\WINDOWS\GRAPH5.XLB:KAVICHS
@Alternate Data Stream - 68 bytes -> C:\WINDOWS\Forest.bmp:KAVICHS
@Alternate Data Stream - 68 bytes -> C:\WINDOWS\EXCEL5.XLB:KAVICHS
@Alternate Data Stream - 68 bytes -> C:\WINDOWS\DYNAZIP.LOG:KAVICHS
@Alternate Data Stream - 68 bytes -> C:\WINDOWS\Clouds.bmp:KAVICHS
@Alternate Data Stream - 68 bytes -> C:\WINDOWS\Circles.bmp:KAVICHS
@Alternate Data Stream - 68 bytes -> C:\WINDOWS\Bubbles.bmp:KAVICHS
@Alternate Data Stream - 68 bytes -> C:\WINDOWS\analyse.log:KAVICHS
@Alternate Data Stream - 68 bytes -> C:\Documents and Settings\User\Start Menu\Programs\Startup\desktop.ini:KAVICHS
@Alternate Data Stream - 68 bytes -> C:\Documents and Settings\User\Start Menu\Programs\NoteWorthy Composer.lnk:KAVICHS
@Alternate Data Stream - 68 bytes -> C:\Documents and Settings\User\Start Menu\Programs\Musicnotes Player.lnk:KAVICHS
@Alternate Data Stream - 68 bytes -> C:\Documents and Settings\User\Start Menu\Programs\desktop.ini:KAVICHS
@Alternate Data Stream - 68 bytes -> C:\Documents and Settings\User\ntuser.ini:KAVICHS
@Alternate Data Stream - 68 bytes -> C:\Documents and Settings\User\My Documents\desktop.ini:KAVICHS
@Alternate Data Stream - 68 bytes -> C:\Documents and Settings\User\Application Data\Microsoft\Internet Explorer\Quick Launch\desktop.ini:KAVICHS
@Alternate Data Stream - 68 bytes -> C:\Documents and Settings\User\Application Data\desktop.ini:KAVICHS
@Alternate Data Stream - 68 bytes -> C:\Documents and Settings\All Users\Start Menu\Programs\Startup\Microsoft Office.lnk:KAVICHS
@Alternate Data Stream - 68 bytes -> C:\Documents and Settings\All Users\Start Menu\Programs\Startup\desktop.ini:KAVICHS
@Alternate Data Stream - 68 bytes -> C:\Documents and Settings\All Users\Start Menu\Programs\desktop.ini:KAVICHS
@Alternate Data Stream - 68 bytes -> C:\Documents and Settings\All Users\Documents\desktop.ini:KAVICHS
@Alternate Data Stream - 68 bytes -> C:\Documents and Settings\All Users\Application Data\desktop.ini:KAVICHS
@Alternate Data Stream - 36 bytes -> C:\WINDOWS\Zapotec.bmp:KAVICHS
@Alternate Data Stream - 36 bytes -> C:\WINDOWS\xpsp1hfm.log:KAVICHS
@Alternate Data Stream - 36 bytes -> C:\WINDOWS\WPR.INI:KAVICHS
@Alternate Data Stream - 36 bytes -> C:\WINDOWS\WMSysPrx.prx:KAVICHS
@Alternate Data Stream - 36 bytes -> C:\WINDOWS\wiaservc.log:KAVICHS
@Alternate Data Stream - 36 bytes -> C:\WINDOWS\vminst.log:KAVICHS
@Alternate Data Stream - 36 bytes -> C:\WINDOWS\vbaddin.ini:KAVICHS
@Alternate Data Stream - 36 bytes -> C:\WINDOWS\vb.ini:KAVICHS
@Alternate Data Stream - 36 bytes -> C:\WINDOWS\uninst.exe:KAVICHS
@Alternate Data Stream - 36 bytes -> C:\WINDOWS\tsoc.log:KAVICHS
@Alternate Data Stream - 36 bytes -> C:\WINDOWS\tasks\Symantec NetDetect.job:KAVICHS
@Alternate Data Stream - 36 bytes -> C:\WINDOWS\System32\zonedon.reg:KAVICHS
@Alternate Data Stream - 36 bytes -> C:\WINDOWS\System32\zonedoff.reg:KAVICHS
@Alternate Data Stream - 36 bytes -> C:\WINDOWS\System32\zlib.dll:KAVICHS
@Alternate Data Stream - 36 bytes -> C:\WINDOWS\System32\xwsindex.exe:KAVICHS
@Alternate Data Stream - 36 bytes -> C:\WINDOWS\System32\xpsp1hfm.exe:KAVICHS
@Alternate Data Stream - 36 bytes -> C:\WINDOWS\System32\write.exe:KAVICHS
@Alternate Data Stream - 36 bytes -> C:\WINDOWS\System32\WPWIZDLL.DLL:KAVICHS
@Alternate Data Stream - 36 bytes -> C:\WINDOWS\System32\WNASPI32.DLL:KAVICHS
@Alternate Data Stream - 36 bytes -> C:\WINDOWS\System32\wmvdmoe.dll:KAVICHS
@Alternate Data Stream - 36 bytes -> C:\WINDOWS\System32\wmvcore2.dll:KAVICHS
@Alternate Data Stream - 36 bytes -> C:\WINDOWS\System32\wmv8dmod.dll:KAVICHS
@Alternate Data Stream - 36 bytes -> C:\WINDOWS\System32\wmpstub.exe:KAVICHS
@Alternate Data Stream - 36 bytes -> C:\WINDOWS\System32\wmpscheme.xml:KAVICHS
@Alternate Data Stream - 36 bytes -> C:\WINDOWS\System32\wmimgmt.msc:KAVICHS
@Alternate Data Stream - 36 bytes -> C:\WINDOWS\System32\wmidx.ocx:KAVICHS
@Alternate Data Stream - 36 bytes -> C:\WINDOWS\System32\wjview.exe:KAVICHS
@Alternate Data Stream - 36 bytes -> C:\WINDOWS\System32\WINSOCK.SRG:KAVICHS
@Alternate Data Stream - 36 bytes -> C:\WINDOWS\System32\WINDBVER.EXE:KAVICHS
@Alternate Data Stream - 36 bytes -> C:\WINDOWS\System32\winchat.exe:KAVICHS
@Alternate Data Stream - 36 bytes -> C:\WINDOWS\System32\WEBPOST.DLL:KAVICHS
@Alternate Data Stream - 36 bytes -> C:\WINDOWS\System32\VSFLEX3.OCX:KAVICHS
@Alternate Data Stream - 36 bytes -> C:\WINDOWS\System32\VSEXT.SRG:KAVICHS
@Alternate Data Stream - 36 bytes -> C:\WINDOWS\System32\VSDBFLEX.SRG:KAVICHS
@Alternate Data Stream - 36 bytes -> C:\WINDOWS\System32\vmhelper.dll:KAVICHS
@Alternate Data Stream - 36 bytes -> C:\WINDOWS\System32\vfpodbc.dll:KAVICHS
@Alternate Data Stream - 36 bytes -> C:\WINDOWS\System32\ven2232.olb:KAVICHS
@Alternate Data Stream - 36 bytes -> C:\WINDOWS\System32\VBDB32.DLL:KAVICHS
@Alternate Data Stream - 36 bytes -> C:\WINDOWS\System32\vbar332.dll:KAVICHS
@Alternate Data Stream - 36 bytes -> C:\WINDOWS\System32\VBAR2232.DLL:KAVICHS
@Alternate Data Stream - 36 bytes -> C:\WINDOWS\System32\VBAME.DLL:KAVICHS
@Alternate Data Stream - 36 bytes -> C:\WINDOWS\System32\VBAEND32.OLB:KAVICHS
@Alternate Data Stream - 36 bytes -> C:\WINDOWS\System32\VBAEN32.OLB:KAVICHS
@Alternate Data Stream - 36 bytes -> C:\WINDOWS\System32\VBAEN32.DLL:KAVICHS
@Alternate Data Stream - 36 bytes -> C:\WINDOWS\System32\VB5StKit.dll:KAVICHS
@Alternate Data Stream - 36 bytes -> C:\WINDOWS\System32\VB5DB.DLL:KAVICHS
@Alternate Data Stream - 36 bytes -> C:\WINDOWS\System32\VB40032.DLL:KAVICHS
@Alternate Data Stream - 36 bytes -> C:\WINDOWS\System32\usrlogon.cmd:KAVICHS
@Alternate Data Stream - 36 bytes -> C:\WINDOWS\System32\udaprop.dll:KAVICHS
@Alternate Data Stream - 36 bytes -> C:\WINDOWS\System32\TyrannLite.dll:KAVICHS
@Alternate Data Stream - 36 bytes -> C:\WINDOWS\System32\tsshutdn.exe:KAVICHS
@Alternate Data Stream - 36 bytes -> C:\WINDOWS\System32\tslabels.ini:KAVICHS
@Alternate Data Stream - 36 bytes -> C:\WINDOWS\System32\tslabels.h:KAVICHS
@Alternate Data Stream - 36 bytes -> C:\WINDOWS\System32\tskill.exe:KAVICHS
@Alternate Data Stream - 36 bytes -> C:\WINDOWS\System32\tsdiscon.exe:KAVICHS
@Alternate Data Stream - 36 bytes -> C:\WINDOWS\System32\tscon.exe:KAVICHS
@Alternate Data Stream - 36 bytes -> C:\WINDOWS\System32\TLBINF32.DLL:KAVICHS
@Alternate Data Stream - 36 bytes -> C:\WINDOWS\System32\THREED32.OCX:KAVICHS
@Alternate Data Stream - 36 bytes -> C:\WINDOWS\System32\tabctl32.ocx:KAVICHS
@Alternate Data Stream - 36 bytes -> C:\WINDOWS\System32\TABCTL32.DEP:KAVICHS
@Alternate Data Stream - 36 bytes -> C:\WINDOWS\System32\SYSINFO.SRG:KAVICHS
@Alternate Data Stream - 36 bytes -> C:\WINDOWS\System32\SYSINFO.OCX:KAVICHS
@Alternate Data Stream - 36 bytes -> C:\WINDOWS\System32\SYSINFO.DEP:KAVICHS
@Alternate Data Stream - 36 bytes -> C:\WINDOWS\System32\subrange.uce:KAVICHS
@Alternate Data Stream - 36 bytes -> C:\WINDOWS\System32\stkit432.dll:KAVICHS
@Alternate Data Stream - 36 bytes -> C:\WINDOWS\System32\SSTABS32.OCX:KAVICHS
@Alternate Data Stream - 36 bytes -> C:\WINDOWS\System32\SSTAB.SRG:KAVICHS
@Alternate Data Stream - 36 bytes -> C:\WINDOWS\System32\SSDOCK32.OCX:KAVICHS
@Alternate Data Stream - 36 bytes -> C:\WINDOWS\System32\SQLSODBC.HLP:KAVICHS
@Alternate Data Stream - 36 bytes -> C:\WINDOWS\System32\SQLPARSE.DLL:KAVICHS
@Alternate Data Stream - 36 bytes -> C:\WINDOWS\System32\SPIN32.OCX:KAVICHS
@Alternate Data Stream - 36 bytes -> C:\WINDOWS\System32\sndvol32.exe:KAVICHS
@Alternate Data Stream - 36 bytes -> C:\WINDOWS\System32\shw32.dll:KAVICHS
@Alternate Data Stream - 36 bytes -> C:\WINDOWS\System32\shiftjis.uce:KAVICHS
@Alternate Data Stream - 36 bytes -> C:\WINDOWS\System32\shadow.exe:KAVICHS
@Alternate Data Stream - 36 bytes -> C:\WINDOWS\System32\SELFREG.DLL:KAVICHS
@Alternate Data Stream - 36 bytes -> C:\WINDOWS\System32\SCRRUN.DEP:KAVICHS
@Alternate Data Stream - 36 bytes -> C:\WINDOWS\System32\scripto.dll:KAVICHS
@Alternate Data Stream - 36 bytes -> C:\WINDOWS\System32\SCRIPTLE.DLL:KAVICHS
@Alternate Data Stream - 36 bytes -> C:\WINDOWS\System32\SCP32.DLL:KAVICHS
@Alternate Data Stream - 36 bytes -> C:\WINDOWS\System32\rwinsta.exe:KAVICHS
@Alternate Data Stream - 36 bytes -> C:\WINDOWS\System32\RICHTX32.OCX:KAVICHS
@Alternate Data Stream - 36 bytes -> C:\WINDOWS\System32\RICHTX32.DEP:KAVICHS
@Alternate Data Stream - 36 bytes -> C:\WINDOWS\System32\RICHTEXT.SRG:KAVICHS
@Alternate Data Stream - 36 bytes -> C:\WINDOWS\System32\reset.exe:KAVICHS
@Alternate Data Stream - 36 bytes -> C:\WINDOWS\System32\REPUTIL.DLL:KAVICHS
@Alternate Data Stream - 36 bytes -> C:\WINDOWS\System32\REGOBJ.DLL:KAVICHS
@Alternate Data Stream - 36 bytes -> C:\WINDOWS\System32\regini.exe:KAVICHS
@Alternate Data Stream - 36 bytes -> C:\WINDOWS\System32\rdpcfgex.dll:KAVICHS
@Alternate Data Stream - 36 bytes -> C:\WINDOWS\System32\RDOCURS.DLL:KAVICHS
@Alternate Data Stream - 36 bytes -> C:\WINDOWS\System32\RACREG32.DLL:KAVICHS
@Alternate Data Stream - 36 bytes -> C:\WINDOWS\System32\RACMGR32.EXE:KAVICHS
@Alternate Data Stream - 36 bytes -> C:\WINDOWS\System32\qwinsta.exe:KAVICHS
@Alternate Data Stream - 36 bytes -> C:\WINDOWS\System32\qvusd.dll:KAVICHS
@Alternate Data Stream - 36 bytes -> C:\WINDOWS\System32\qappsrv.exe:KAVICHS
@Alternate Data Stream - 36 bytes -> C:\WINDOWS\System32\PUBDLG.DLL:KAVICHS
@Alternate Data Stream - 36 bytes -> C:\WINDOWS\System32\POSTWPP.DLL:KAVICHS
@Alternate Data Stream - 36 bytes -> C:\WINDOWS\System32\PIPARSE.DLL:KAVICHS
@Alternate Data Stream - 36 bytes -> C:\WINDOWS\System32\PICCLP32.DEP:KAVICHS
@Alternate Data Stream - 36 bytes -> C:\WINDOWS\System32\PICCLIP.SRG:KAVICHS
@Alternate Data Stream - 36 bytes -> C:\WINDOWS\System32\Pgtextje.ttf:KAVICHS
@Alternate Data Stream - 36 bytes -> C:\WINDOWS\System32\Pgtextj_.ttf:KAVICHS
@Alternate Data Stream - 36 bytes -> C:\WINDOWS\System32\PGTEXTJ_.FOT:KAVICHS
@Alternate Data Stream - 36 bytes -> C:\WINDOWS\System32\Pgtext.ttf:KAVICHS
@Alternate Data Stream - 36 bytes -> C:\WINDOWS\System32\PGTEXT.FOT:KAVICHS
@Alternate Data Stream - 36 bytes -> C:\WINDOWS\System32\pgmus.ttf:KAVICHS
@Alternate Data Stream - 36 bytes -> C:\WINDOWS\System32\PGMUS.FOT:KAVICHS
@Alternate Data Stream - 36 bytes -> C:\WINDOWS\System32\Pgjazz__.ttf:KAVICHS
@Alternate Data Stream - 36 bytes -> C:\WINDOWS\System32\pgjazz__.FOT:KAVICHS
@Alternate Data Stream - 36 bytes -> C:\WINDOWS\System32\Pgchords.ttf:KAVICHS
@Alternate Data Stream - 36 bytes -> C:\WINDOWS\System32\PGCHORDS.FOT:KAVICHS
@Alternate Data Stream - 36 bytes -> C:\WINDOWS\System32\PDM.DLL:KAVICHS
@Alternate Data Stream - 36 bytes -> C:\WINDOWS\System32\OUTLWAB.DLL:KAVICHS
@Alternate Data Stream - 36 bytes -> C:\WINDOWS\System32\ODKOB32.DLL:KAVICHS
@Alternate Data Stream - 36 bytes -> C:\WINDOWS\System32\OC30.DLL:KAVICHS
@Alternate Data Stream - 36 bytes -> C:\WINDOWS\System32\nvwrszht.dll:KAVICHS
@Alternate Data Stream - 36 bytes -> C:\WINDOWS\System32\nvwrszhc.dll:KAVICHS
@Alternate Data Stream - 36 bytes -> C:\WINDOWS\System32\nvwrstr.dll:KAVICHS
@Alternate Data Stream - 36 bytes -> C:\WINDOWS\System32\nvwrssv.dll:KAVICHS
@Alternate Data Stream - 36 bytes -> C:\WINDOWS\System32\nvwrssl.dll:KAVICHS
@Alternate Data Stream - 36 bytes -> C:\WINDOWS\System32\nvwrssk.dll:KAVICHS
@Alternate Data Stream - 36 bytes -> C:\WINDOWS\System32\nvwrsru.dll:KAVICHS
@Alternate Data Stream - 36 bytes -> C:\WINDOWS\System32\nvwrsptb.dll:KAVICHS
@Alternate Data Stream - 36 bytes -> C:\WINDOWS\System32\nvwrspt.dll:KAVICHS
@Alternate Data Stream - 36 bytes -> C:\WINDOWS\System32\nvwrspl.dll:KAVICHS
@Alternate Data Stream - 36 bytes -> C:\WINDOWS\System32\nvwrsno.dll:KAVICHS
@Alternate Data Stream - 36 bytes -> C:\WINDOWS\System32\nvwrsnl.dll:KAVICHS
@Alternate Data Stream - 36 bytes -> C:\WINDOWS\System32\nvwrsko.dll:KAVICHS
@Alternate Data Stream - 36 bytes -> C:\WINDOWS\System32\nvwrsja.dll:KAVICHS
@Alternate Data Stream - 36 bytes -> C:\WINDOWS\System32\nvwrsit.dll:KAVICHS
@Alternate Data Stream - 36 bytes -> C:\WINDOWS\System32\nvwrshu.dll:KAVICHS
@Alternate Data Stream - 36 bytes -> C:\WINDOWS\System32\nvwrshe.dll:KAVICHS
@Alternate Data Stream - 36 bytes -> C:\WINDOWS\System32\nvwrsfr.dll:KAVICHS
@Alternate Data Stream - 36 bytes -> C:\WINDOWS\System32\nvwrsfi.dll:KAVICHS
@Alternate Data Stream - 36 bytes -> C:\WINDOWS\System32\nvwrsesm.dll:KAVICHS
@Alternate Data Stream - 36 bytes -> C:\WINDOWS\System32\nvwrses.dll:KAVICHS
@Alternate Data Stream - 36 bytes -> C:\WINDOWS\System32\nvwrsel.dll:KAVICHS
@Alternate Data Stream - 36 bytes -> C:\WINDOWS\System32\nvwrsde.dll:KAVICHS
@Alternate Data Stream - 36 bytes -> C:\WINDOWS\System32\nvwrsda.dll:KAVICHS
@Alternate Data Stream - 36 bytes -> C:\WINDOWS\System32\nvwrscs.dll:KAVICHS
@Alternate Data Stream - 36 bytes -> C:\WINDOWS\System32\nvwrsar.dll:KAVICHS
@Alternate Data Stream - 36 bytes -> C:\WINDOWS\System32\nvtuicpl.cpl:KAVICHS
@Alternate Data Stream - 36 bytes -> C:\WINDOWS\System32\nvshell.dll:KAVICHS
@Alternate Data Stream - 36 bytes -> C:\WINDOWS\System32\nvrszht.dll:KAVICHS
@Alternate Data Stream - 36 bytes -> C:\WINDOWS\System32\nvrszhc.dll:KAVICHS
@Alternate Data Stream - 36 bytes -> C:\WINDOWS\System32\nvrstr.dll:KAVICHS
@Alternate Data Stream - 36 bytes -> C:\WINDOWS\System32\nvrssv.dll:KAVICHS
@Alternate Data Stream - 36 bytes -> C:\WINDOWS\System32\nvrssl.dll:KAVICHS
@Alternate Data Stream - 36 bytes -> C:\WINDOWS\System32\nvrssk.dll:KAVICHS
@Alternate Data Stream - 36 bytes -> C:\WINDOWS\System32\nvrsru.dll:KAVICHS
@Alternate Data Stream - 36 bytes -> C:\WINDOWS\System32\nvrsptb.dll:KAVICHS
@Alternate Data Stream - 36 bytes -> C:\WINDOWS\System32\nvrspt.dll:KAVICHS
@Alternate Data Stream - 36 bytes -> C:\WINDOWS\System32\nvrspl.dll:KAVICHS
@Alternate Data Stream - 36 bytes -> C:\WINDOWS\System32\nvrsno.dll:KAVICHS
@Alternate Data Stream - 36 bytes -> C:\WINDOWS\System32\nvrsnl.dll:KAVICHS
@Alternate Data Stream - 36 bytes -> C:\WINDOWS\System32\nvrsko.dll:KAVICHS
@Alternate Data Stream - 36 bytes -> C:\WINDOWS\System32\nvrsja.dll:KAVICHS
@Alternate Data Stream - 36 bytes -> C:\WINDOWS\System32\nvrsit.dll:KAVICHS
@Alternate Data Stream - 36 bytes -> C:\WINDOWS\System32\nvrshu.dll:KAVICHS
@Alternate Data Stream - 36 bytes -> C:\WINDOWS\System32\nvrshe.dll:KAVICHS
@Alternate Data Stream - 36 bytes -> C:\WINDOWS\System32\nvrsfr.dll:KAVICHS
@Alternate Data Stream - 36 bytes -> C:\WINDOWS\System32\nvrsfi.dll:KAVICHS
@Alternate Data Stream - 36 bytes -> C:\WINDOWS\System32\nvrsesm.dll:KAVICHS
@Alternate Data Stream - 36 bytes -> C:\WINDOWS\System32\nvrses.dll:KAVICHS
@Alternate Data Stream - 36 bytes -> C:\WINDOWS\System32\nvrsel.dll:KAVICHS
@Alternate Data Stream - 36 bytes -> C:\WINDOWS\System32\nvrsde.dll:KAVICHS
@Alternate Data Stream - 36 bytes -> C:\WINDOWS\System32\nvrsda.dll:KAVICHS
@Alternate Data Stream - 36 bytes -> C:\WINDOWS\System32\nvrscs.dll:KAVICHS
@Alternate Data Stream - 36 bytes -> C:\WINDOWS\System32\nvrsar.dll:KAVICHS
@Alternate Data Stream - 36 bytes -> C:\WINDOWS\System32\nvoglnt.dll:KAVICHS
@Alternate Data Stream - 36 bytes -> C:\WINDOWS\System32\nvmctray.dll:KAVICHS
@Alternate Data Stream - 36 bytes -> C:\WINDOWS\System32\nvinstnt.dll:KAVICHS
@Alternate Data Stream - 36 bytes -> C:\WINDOWS\System32\nviewimg.dll:KAVICHS
@Alternate Data Stream - 36 bytes -> C:\WINDOWS\System32\npwmsdrm.dll:KAVICHS
@Alternate Data Stream - 36 bytes -> C:\WINDOWS\System32\noise.tha:KAVICHS
@Alternate Data Stream - 36 bytes -> C:\WINDOWS\System32\noise.sve:KAVICHS
@Alternate Data Stream - 36 bytes -> C:\WINDOWS\System32\noise.nld:KAVICHS
@Alternate Data Stream - 36 bytes -> C:\WINDOWS\System32\noise.ita:KAVICHS
@Alternate Data Stream - 36 bytes -> C:\WINDOWS\System32\noise.fra:KAVICHS
@Alternate Data Stream - 36 bytes -> C:\WINDOWS\System32\noise.esn:KAVICHS
@Alternate Data Stream - 36 bytes -> C:\WINDOWS\System32\noise.enu:KAVICHS
@Alternate Data Stream - 36 bytes -> C:\WINDOWS\System32\noise.eng:KAVICHS
@Alternate Data Stream - 36 bytes -> C:\WINDOWS\System32\noise.deu:KAVICHS
@Alternate Data Stream - 36 bytes -> C:\WINDOWS\System32\noise.dat:KAVICHS
@Alternate Data Stream - 36 bytes -> C:\WINDOWS\System32\nmevtmsg.dll:KAVICHS
@Alternate Data Stream - 36 bytes -> C:\WINDOWS\System32\msxml4r.dll:KAVICHS
@Alternate Data Stream - 36 bytes -> C:\WINDOWS\System32\MSXBSE35.DLL:KAVICHS
@Alternate Data Stream - 36 bytes -> C:\WINDOWS\System32\MSXB3032.DLL:KAVICHS
@Alternate Data Stream - 36 bytes -> C:\WINDOWS\System32\MSWINSCK.DEP:KAVICHS
@Alternate Data Stream - 36 bytes -> C:\WINDOWS\System32\Msvcrt10.dll:KAVICHS
@Alternate Data Stream - 36 bytes -> C:\WINDOWS\System32\msuni11.dll:KAVICHS
@Alternate Data Stream - 36 bytes -> C:\WINDOWS\System32\MSTEXT35.DLL:KAVICHS
@Alternate Data Stream - 36 bytes -> C:\WINDOWS\System32\msstkprp.dll:KAVICHS
@Alternate Data Stream - 36 bytes -> C:\WINDOWS\System32\MSSDM.DLL:KAVICHS
@Alternate Data Stream - 36 bytes -> C:\WINDOWS\System32\MSSCRIPT.HLP:KAVICHS
@Alternate Data Stream - 36 bytes -> C:\WINDOWS\System32\MSSCRIPT.CNT:KAVICHS
@Alternate Data Stream - 36 bytes -> C:\WINDOWS\System32\MSRTEDIT.DLL:KAVICHS
@Alternate Data Stream - 36 bytes -> C:\WINDOWS\System32\MSREPL35.DLL:KAVICHS
@Alternate Data Stream - 36 bytes -> C:\WINDOWS\System32\MSRDO20.SRG:KAVICHS
@Alternate Data Stream - 36 bytes -> C:\WINDOWS\System32\MSRDO20.DLL:KAVICHS
@Alternate Data Stream - 36 bytes -> C:\WINDOWS\System32\MSRDO20.DEP:KAVICHS
@Alternate Data Stream - 36 bytes -> C:\WINDOWS\System32\MSRDC20.SRG:KAVICHS
@Alternate Data Stream - 36 bytes -> C:\WINDOWS\System32\MSRDC20.OCX:KAVICHS
@Alternate Data Stream - 36 bytes -> C:\WINDOWS\System32\MSRDC20.DEP:KAVICHS
@Alternate Data Stream - 36 bytes -> C:\WINDOWS\System32\msrd2x35.dll:KAVICHS
@Alternate Data Stream - 36 bytes -> C:\WINDOWS\System32\MSRD2X32.DLL:KAVICHS
@Alternate Data Stream - 36 bytes -> C:\WINDOWS\System32\MSPX3032.DLL:KAVICHS
@Alternate Data Stream - 36 bytes -> C:\WINDOWS\System32\MSPDOX35.DLL:KAVICHS
@Alternate Data Stream - 36 bytes -> C:\WINDOWS\System32\MSOUTL32.OCX:KAVICHS
@Alternate Data Stream - 36 bytes -> C:\WINDOWS\System32\MSMASK32.OCX:KAVICHS
@Alternate Data Stream - 36 bytes -> C:\WINDOWS\System32\MSMASK32.DEP:KAVICHS
@Alternate Data Stream - 36 bytes -> C:\WINDOWS\System32\MSMASK.SRG:KAVICHS
@Alternate Data Stream - 36 bytes -> C:\WINDOWS\System32\MSMAPI32.OCX:KAVICHS
@Alternate Data Stream - 36 bytes -> C:\WINDOWS\System32\MSMAPI32.DEP:KAVICHS
@Alternate Data Stream - 36 bytes -> C:\WINDOWS\System32\MSMAPI.SRG:KAVICHS
@Alternate Data Stream - 36 bytes -> C:\WINDOWS\System32\MSLTUS35.DLL:KAVICHS
@Alternate Data Stream - 36 bytes -> C:\WINDOWS\System32\MSLS2.DLL:KAVICHS
@Alternate Data Stream - 36 bytes -> C:\WINDOWS\System32\msjter35.dll:KAVICHS
@Alternate Data Stream - 36 bytes -> C:\WINDOWS\System32\MSJTER32.DLL:KAVICHS
@Alternate Data Stream - 36 bytes -> C:\WINDOWS\System32\MSJT4JLT.DLL:KAVICHS
@Alternate Data Stream - 36 bytes -> C:\WINDOWS\System32\MSJT3032.DLL:KAVICHS
@Alternate Data Stream - 36 bytes -> C:\WINDOWS\System32\Msjint35.dll:KAVICHS
@Alternate Data Stream - 36 bytes -> C:\WINDOWS\System32\MSJINT32.DLL:KAVICHS
@Alternate Data Stream - 36 bytes -> C:\WINDOWS\System32\msjet35.dll:KAVICHS
@Alternate Data Stream - 36 bytes -> C:\WINDOWS\System32\msjdbc10.dll:KAVICHS
@Alternate Data Stream - 36 bytes -> C:\WINDOWS\System32\msjava.dll:KAVICHS
@Alternate Data Stream - 36 bytes -> C:\WINDOWS\System32\msisam11.dll:KAVICHS
@Alternate Data Stream - 36 bytes -> C:\WINDOWS\System32\MSINET.DEP:KAVICHS
@Alternate Data Stream - 36 bytes -> C:\WINDOWS\System32\MSIMUSIC.DLL:KAVICHS
@Alternate Data Stream - 36 bytes -> C:\WINDOWS\System32\MSIMRT32.DLL:KAVICHS
@Alternate Data Stream - 36 bytes -> C:\WINDOWS\System32\MSIMRT16.DLL:KAVICHS
@Alternate Data Stream - 36 bytes -> C:\WINDOWS\System32\MSIMRT.DLL:KAVICHS
@Alternate Data Stream - 36 bytes -> C:\WINDOWS\System32\MSHFLXGD.SRG:KAVICHS
@Alternate Data Stream - 36 bytes -> C:\WINDOWS\System32\MSHFLXGD.OCX:KAVICHS
@Alternate Data Stream - 36 bytes -> C:\WINDOWS\System32\MSHFLXGD.DEP:KAVICHS
@Alternate Data Stream - 36 bytes -> C:\WINDOWS\System32\msg.exe:KAVICHS
@Alternate Data Stream - 36 bytes -> C:\WINDOWS\System32\MSFLXGRD.OCX:KAVICHS
@Alternate Data Stream - 36 bytes -> C:\WINDOWS\System32\MSFLXGRD.DEP:KAVICHS
@Alternate Data Stream - 36 bytes -> C:\WINDOWS\System32\MSEXCL35.DLL:KAVICHS
@Alternate Data Stream - 36 bytes -> C:\WINDOWS\System32\MSEXCH35.DLL:KAVICHS
@Alternate Data Stream - 36 bytes -> C:\WINDOWS\System32\msdtcprf.ini:KAVICHS
@Alternate Data Stream - 36 bytes -> C:\WINDOWS\System32\msdtcprf.h:KAVICHS
@Alternate Data Stream - 36 bytes -> C:\WINDOWS\System32\MSDBRPTR.DLL:KAVICHS
@Alternate Data Stream - 36 bytes -> C:\WINDOWS\System32\MSDBRPTR.DEP:KAVICHS
@Alternate Data Stream - 36 bytes -> C:\WINDOWS\System32\MSDBRPT.SRG:KAVICHS
@Alternate Data Stream - 36 bytes -> C:\WINDOWS\System32\MSDBRPT.DLL:KAVICHS
@Alternate Data Stream - 36 bytes -> C:\WINDOWS\System32\MSDBGEN.DLL:KAVICHS
@Alternate Data Stream - 36 bytes -> C:\WINDOWS\System32\MSDBG.DLL:KAVICHS
@Alternate Data Stream - 36 bytes -> C:\WINDOWS\System32\MSDATREP.SRG:KAVICHS
@Alternate Data Stream - 36 bytes -> C:\WINDOWS\System32\MSDATREP.OCX:KAVICHS
@Alternate Data Stream - 36 bytes -> C:\WINDOWS\System32\MSDATREP.DEP:KAVICHS
@Alternate Data Stream - 36 bytes -> C:\WINDOWS\System32\MSDATLST.OCX:KAVICHS
@Alternate Data Stream - 36 bytes -> C:\WINDOWS\System32\MSDATLST.DEP:KAVICHS
@Alternate Data Stream - 36 bytes -> C:\WINDOWS\System32\MSDATGRD.SRG:KAVICHS
@Alternate Data Stream - 36 bytes -> C:\WINDOWS\System32\MSDATGRD.OCX:KAVICHS
@Alternate Data Stream - 36 bytes -> C:\WINDOWS\System32\MSDATGRD.DEP:KAVICHS
@Alternate Data Stream - 36 bytes -> C:\WINDOWS\System32\MSCOMM32.OCX:KAVICHS
@Alternate Data Stream - 36 bytes -> C:\WINDOWS\System32\MSCOMM32.DEP:KAVICHS
@Alternate Data Stream - 36 bytes -> C:\WINDOWS\System32\MSCOMM.SRG:KAVICHS
@Alternate Data Stream - 36 bytes -> C:\WINDOWS\System32\MSCOMCTL.SRG:KAVICHS
@Alternate Data Stream - 36 bytes -> C:\WINDOWS\System32\MSCOMCTL.DEP:KAVICHS
@Alternate Data Stream - 36 bytes -> C:\WINDOWS\System32\MSCOMCT2.SRG:KAVICHS
@Alternate Data Stream - 36 bytes -> C:\WINDOWS\System32\MSCOMCT2.DEP:KAVICHS
@Alternate Data Stream - 36 bytes -> C:\WINDOWS\System32\MSCHRT20.SRG:KAVICHS
@Alternate Data Stream - 36 bytes -> C:\WINDOWS\System32\MSCHRT20.OCX:KAVICHS
@Alternate Data Stream - 36 bytes -> C:\WINDOWS\System32\MSCHRT20.DEP:KAVICHS
@Alternate Data Stream - 36 bytes -> C:\WINDOWS\System32\MSCAL.OCX:KAVICHS
@Alternate Data Stream - 36 bytes -> C:\WINDOWS\System32\MSCAL.HLP:KAVICHS
@Alternate Data Stream - 36 bytes -> C:\WINDOWS\System32\MSCAL.DEP:KAVICHS
@Alternate Data Stream - 36 bytes -> C:\WINDOWS\System32\MSCAL.CNT:KAVICHS
@Alternate Data Stream - 36 bytes -> C:\WINDOWS\System32\MSBIND.DLL:KAVICHS
@Alternate Data Stream - 36 bytes -> C:\WINDOWS\System32\MSBIND.DEP:KAVICHS
@Alternate Data Stream - 36 bytes -> C:\WINDOWS\System32\msawt.dll:KAVICHS
@Alternate Data Stream - 36 bytes -> C:\WINDOWS\System32\MSADODC.OCX:KAVICHS
@Alternate Data Stream - 36 bytes -> C:\WINDOWS\System32\MSADODC.DEP:KAVICHS
@Alternate Data Stream - 36 bytes -> C:\WINDOWS\System32\mindex.dll:KAVICHS
@Alternate Data Stream - 36 bytes -> C:\WINDOWS\System32\MFCANS32.DLL:KAVICHS
@Alternate Data Stream - 36 bytes -> C:\WINDOWS\System32\MFC42ENU.DLL:KAVICHS
@Alternate Data Stream - 36 bytes -> C:\WINDOWS\System32\MDT2FW95.DLL:KAVICHS
@Alternate Data Stream - 36 bytes -> C:\WINDOWS\System32\MDM.EXE:KAVICHS
@Alternate Data Stream - 36 bytes -> C:\WINDOWS\System32\MCI32.OCX:KAVICHS
@Alternate Data Stream - 36 bytes -> C:\WINDOWS\System32\MCI32.DEP:KAVICHS
@Alternate Data Stream - 36 bytes -> C:\WINDOWS\System32\MCI.SRG:KAVICHS
@Alternate Data Stream - 36 bytes -> C:\WINDOWS\System32\mapisvc.inf:KAVICHS
@Alternate Data Stream - 36 bytes -> C:\WINDOWS\System32\MAPISRVR.EXE:KAVICHS
@Alternate Data Stream - 36 bytes -> C:\WINDOWS\System32\MAPI.DLL:KAVICHS
@Alternate Data Stream - 36 bytes -> C:\WINDOWS\System32\MabryObj.dll:KAVICHS
@Alternate Data Stream - 36 bytes -> C:\WINDOWS\System32\Lvkrn13n.dll:KAVICHS
@Alternate Data Stream - 36 bytes -> C:\WINDOWS\System32\LTWVC13n.dll:KAVICHS
@Alternate Data Stream - 36 bytes -> C:\WINDOWS\System32\LTWND13n.dll:KAVICHS
@Alternate Data Stream - 36 bytes -> C:\WINDOWS\System32\ltwen13n.dll:KAVICHS
@Alternate Data Stream - 36 bytes -> C:\WINDOWS\System32\lttwn13n.dll:KAVICHS
@Alternate Data Stream - 36 bytes -> C:\WINDOWS\System32\lttw213n.dll:KAVICHS
@Alternate Data Stream - 36 bytes -> C:\WINDOWS\System32\lttmb13n.dll:KAVICHS
@Alternate Data Stream - 36 bytes -> C:\WINDOWS\System32\lttls13n.dll:KAVICHS
@Alternate Data Stream - 36 bytes -> C:\WINDOWS\System32\LTTLB13n.dll:KAVICHS
@Alternate Data Stream - 36 bytes -> C:\WINDOWS\System32\Ltsgm13n.dll:KAVICHS
@Alternate Data Stream - 36 bytes -> C:\WINDOWS\System32\LTSCR13n.dll:KAVICHS
@Alternate Data Stream - 36 bytes -> C:\WINDOWS\System32\LTRTN13n.dll:KAVICHS
@Alternate Data Stream - 36 bytes -> C:\WINDOWS\System32\Ltpnt13n.dll:KAVICHS
@Alternate Data Stream - 36 bytes -> C:\WINDOWS\System32\ltpdg13n.dll:KAVICHS
@Alternate Data Stream - 36 bytes -> C:\WINDOWS\System32\ltlst13n.dll:KAVICHS
@Alternate Data Stream - 36 bytes -> C:\WINDOWS\System32\ltkrn13n.dll:KAVICHS
@Alternate Data Stream - 36 bytes -> C:\WINDOWS\System32\ltisi13n.dll:KAVICHS
@Alternate Data Stream - 36 bytes -> C:\WINDOWS\System32\LTIMG13n.dll:KAVICHS
@Alternate Data Stream - 36 bytes -> C:\WINDOWS\System32\LTFIL13n.dll:KAVICHS
@Alternate Data Stream - 36 bytes -> C:\WINDOWS\System32\LTEFX13n.dll:KAVICHS
@Alternate Data Stream - 36 bytes -> C:\WINDOWS\System32\ltdlg13n.dll:KAVICHS
@Alternate Data Stream - 36 bytes -> C:\WINDOWS\System32\LTDIS13n.dll:KAVICHS
@Alternate Data Stream - 36 bytes -> C:\WINDOWS\System32\LTDic13n.dll:KAVICHS
@Alternate Data Stream - 36 bytes -> C:\WINDOWS\System32\ltcry13n.dll:KAVICHS
@Alternate Data Stream - 36 bytes -> C:\WINDOWS\System32\LTCON13n.dll:KAVICHS
@Alternate Data Stream - 36 bytes -> C:\WINDOWS\System32\LTCLR13n.dll:KAVICHS
@Alternate Data Stream - 36 bytes -> C:\WINDOWS\System32\LTAUT13n.dll:KAVICHS
@Alternate Data Stream - 36 bytes -> C:\WINDOWS\System32\ltann13n.dll:KAVICHS
@Alternate Data Stream - 36 bytes -> C:\WINDOWS\System32\logoff.exe:KAVICHS
@Alternate Data Stream - 36 bytes -> C:\WINDOWS\System32\lfxwd13n.dll:KAVICHS
@Alternate Data Stream - 36 bytes -> C:\WINDOWS\System32\lfXpm13n.dll:KAVICHS
@Alternate Data Stream - 36 bytes -> C:\WINDOWS\System32\lfXbm13n.dll:KAVICHS
@Alternate Data Stream - 36 bytes -> C:\WINDOWS\System32\lfwpg13n.dll:KAVICHS
@Alternate Data Stream - 36 bytes -> C:\WINDOWS\System32\lfwmp13n.dll:KAVICHS
@Alternate Data Stream - 36 bytes -> C:\WINDOWS\System32\Lfwmf13n.dll:KAVICHS
@Alternate Data Stream - 36 bytes -> C:\WINDOWS\System32\lfwfx13n.dll:KAVICHS
@Alternate Data Stream - 36 bytes -> C:\WINDOWS\System32\lfvec13n.dll:KAVICHS
@Alternate Data Stream - 36 bytes -> C:\WINDOWS\System32\lftif13n.dll:KAVICHS
@Alternate Data Stream - 36 bytes -> C:\WINDOWS\System32\lftga13n.dll:KAVICHS
@Alternate Data Stream - 36 bytes -> C:\WINDOWS\System32\LFSMP13n.dll:KAVICHS
@Alternate Data Stream - 36 bytes -> C:\WINDOWS\System32\lfshp13n.dll:KAVICHS
@Alternate Data Stream - 36 bytes -> C:\WINDOWS\System32\lfsgi13n.dll:KAVICHS
@Alternate Data Stream - 36 bytes -> C:\WINDOWS\System32\lfsct13n.dll:KAVICHS
@Alternate Data Stream - 36 bytes -> C:\WINDOWS\System32\lfRaw13n.dll:KAVICHS
@Alternate Data Stream - 36 bytes -> C:\WINDOWS\System32\lfras13n.dll:KAVICHS
@Alternate Data Stream - 36 bytes -> C:\WINDOWS\System32\LFPTK13n.dll:KAVICHS
@Alternate Data Stream - 36 bytes -> C:\WINDOWS\System32\lfpsd13n.dll:KAVICHS
@Alternate Data Stream - 36 bytes -> C:\WINDOWS\System32\LFPNM13n.dll:KAVICHS
@Alternate Data Stream - 36 bytes -> C:\WINDOWS\System32\Lfpng13n.dll:KAVICHS
@Alternate Data Stream - 36 bytes -> C:\WINDOWS\System32\lfplt13n.dll:KAVICHS
@Alternate Data Stream - 36 bytes -> C:\WINDOWS\System32\lfpdf13n.dll:KAVICHS
@Alternate Data Stream - 36 bytes -> C:\WINDOWS\System32\lfpcx13n.dll:KAVICHS
@Alternate Data Stream - 36 bytes -> C:\WINDOWS\System32\Lfpct13n.dll:KAVICHS
@Alternate Data Stream - 36 bytes -> C:\WINDOWS\System32\lfPCL13n.dll:KAVICHS
@Alternate Data Stream - 36 bytes -> C:\WINDOWS\System32\lfpcd13n.dll:KAVICHS
@Alternate Data Stream - 36 bytes -> C:\WINDOWS\System32\lfmsp13n.dll:KAVICHS
@Alternate Data Stream - 36 bytes -> C:\WINDOWS\System32\lfmpg13n.dll:KAVICHS
@Alternate Data Stream - 36 bytes -> C:\WINDOWS\System32\lfmac13n.dll:KAVICHS
@Alternate Data Stream - 36 bytes -> C:\WINDOWS\System32\lflmb13n.dll:KAVICHS
@Alternate Data Stream - 36 bytes -> C:\WINDOWS\System32\lflma13n.dll:KAVICHS
@Alternate Data Stream - 36 bytes -> C:\WINDOWS\System32\lfkodak.dll:KAVICHS
@Alternate Data Stream - 36 bytes -> C:\WINDOWS\System32\lfjbg13n.dll:KAVICHS
@Alternate Data Stream - 36 bytes -> C:\WINDOWS\System32\LFJ2K13n.dll:KAVICHS
@Alternate Data Stream - 36 bytes -> C:\WINDOWS\System32\lfitg13n.dll:KAVICHS
@Alternate Data Stream - 36 bytes -> C:\WINDOWS\System32\lfimg13n.dll:KAVICHS
@Alternate Data Stream - 36 bytes -> C:\WINDOWS\System32\lfiff13n.dll:KAVICHS
@Alternate Data Stream - 36 bytes -> C:\WINDOWS\System32\lfica13n.dll:KAVICHS
@Alternate Data Stream - 36 bytes -> C:\WINDOWS\System32\lfgif13n.dll:KAVICHS
@Alternate Data Stream - 36 bytes -> C:\WINDOWS\System32\lfgbr13n.dll:KAVICHS
@Alternate Data Stream - 36 bytes -> C:\WINDOWS\System32\lffpx7.dll:KAVICHS
@Alternate Data Stream - 36 bytes -> C:\WINDOWS\System32\lffpx13n.dll:KAVICHS
@Alternate Data Stream - 36 bytes -> C:\WINDOWS\System32\lfflc13n.dll:KAVICHS
@Alternate Data Stream - 36 bytes -> C:\WINDOWS\System32\lffax13n.dll:KAVICHS
@Alternate Data Stream - 36 bytes -> C:\WINDOWS\System32\lfeps13n.dll:KAVICHS
@Alternate Data Stream - 36 bytes -> C:\WINDOWS\System32\lfdxf13n.dll:KAVICHS
@Alternate Data Stream - 36 bytes -> C:\WINDOWS\System32\lfdwg13n.dll:KAVICHS
@Alternate Data Stream - 36 bytes -> C:\WINDOWS\System32\lfdwf13n.dll:KAVICHS
@Alternate Data Stream - 36 bytes -> C:\WINDOWS\System32\lfdrw13n.dll:KAVICHS
@Alternate Data Stream - 36 bytes -> C:\WINDOWS\System32\Lfdgn13n.dll:KAVICHS
@Alternate Data Stream - 36 bytes -> C:\WINDOWS\System32\lfCUT13n.dll:KAVICHS
@Alternate Data Stream - 36 bytes -> C:\WINDOWS\System32\LFCMW13n.dll:KAVICHS
@Alternate Data Stream - 36 bytes -> C:\WINDOWS\System32\LFCMP13n.dll:KAVICHS
@Alternate Data Stream - 36 bytes -> C:\WINDOWS\System32\lfclp13n.dll:KAVICHS
@Alternate Data Stream - 36 bytes -> C:\WINDOWS\System32\Lfcgm13n.dll:KAVICHS
@Alternate Data Stream - 36 bytes -> C:\WINDOWS\System32\lfcal13n.dll:KAVICHS
@Alternate Data Stream - 36 bytes -> C:\WINDOWS\System32\lfbmp13n.dll:KAVICHS
@Alternate Data Stream - 36 bytes -> C:\WINDOWS\System32\lfawd13n.dll:KAVICHS
@Alternate Data Stream - 36 bytes -> C:\WINDOWS\System32\lfavi13n.dll:KAVICHS
@Alternate Data Stream - 36 bytes -> C:\WINDOWS\System32\lfani13n.dll:KAVICHS
@Alternate Data Stream - 36 bytes -> C:\WINDOWS\System32\lfAFP13n.dll:KAVICHS
@Alternate Data Stream - 36 bytes -> C:\WINDOWS\System32\korean.uce:KAVICHS
@Alternate Data Stream - 36 bytes -> C:\WINDOWS\System32\keystone.exe:KAVICHS
@Alternate Data Stream - 36 bytes -> C:\WINDOWS\System32\kanji_2.uce:KAVICHS
@Alternate Data Stream - 36 bytes -> C:\WINDOWS\System32\kanji_1.uce:KAVICHS
@Alternate Data Stream - 36 bytes -> C:\WINDOWS\System32\jview.exe:KAVICHS
@Alternate Data Stream - 36 bytes -> C:\WINDOWS\System32\jit.dll:KAVICHS
@Alternate Data Stream - 36 bytes -> C:\WINDOWS\System32\jdbgmgr.exe:KAVICHS
@Alternate Data Stream - 36 bytes -> C:\WINDOWS\System32\javart.dll:KAVICHS
@Alternate Data Stream - 36 bytes -> C:\WINDOWS\System32\javaprxy.dll:KAVICHS
@Alternate Data Stream - 36 bytes -> C:\WINDOWS\System32\JAVALE.DLL:KAVICHS
@Alternate Data Stream - 36 bytes -> C:\WINDOWS\System32\javaee.dll:KAVICHS
@Alternate Data Stream - 36 bytes -> C:\WINDOWS\System32\javacypt.dll:KAVICHS
@Alternate Data Stream - 36 bytes -> C:\WINDOWS\System32\ISYSU532.DLL:KAVICHS
@Alternate Data Stream - 36 bytes -> C:\WINDOWS\System32\ISYSPDFL.DLL:KAVICHS
@Alternate Data Stream - 36 bytes -> C:\WINDOWS\System32\ISYSPDF3.DLL:KAVICHS
@Alternate Data Stream - 36 bytes -> C:\WINDOWS\System32\ISYS532.DLL:KAVICHS
@Alternate Data Stream - 36 bytes -> C:\WINDOWS\System32\INLOADER.DLL:KAVICHS
@Alternate Data Stream - 36 bytes -> C:\WINDOWS\System32\INETCTLS.SRG:KAVICHS
@Alternate Data Stream - 36 bytes -> C:\WINDOWS\System32\IMOCX32.OCX:KAVICHS
@Alternate Data Stream - 36 bytes -> C:\WINDOWS\System32\IMGMAN31.DLL:KAVICHS
@Alternate Data Stream - 36 bytes -> C:\WINDOWS\System32\IM31WPG.DIL:KAVICHS
@Alternate Data Stream - 36 bytes -> C:\WINDOWS\System32\IM31WMF.DIL:KAVICHS
@Alternate Data Stream - 36 bytes -> C:\WINDOWS\System32\IM31TIF.DIL:KAVICHS
@Alternate Data Stream - 36 bytes -> C:\WINDOWS\System32\IM31TGA.DIL:KAVICHS
@Alternate Data Stream - 36 bytes -> C:\WINDOWS\System32\IM31PNG.DIL:KAVICHS
@Alternate Data Stream - 36 bytes -> C:\WINDOWS\System32\IM31PCX.DIL:KAVICHS
@Alternate Data Stream - 36 bytes -> C:\WINDOWS\System32\IM31PCD.DIL:KAVICHS
@Alternate Data Stream - 36 bytes -> C:\WINDOWS\System32\IM31JPG.DIL:KAVICHS
@Alternate Data Stream - 36 bytes -> C:\WINDOWS\System32\IM31IMG.DIL:KAVICHS
@Alternate Data Stream - 36 bytes -> C:\WINDOWS\System32\IM31FAX.DIL:KAVICHS
@Alternate Data Stream - 36 bytes -> C:\WINDOWS\System32\IM31EPS.DIL:KAVICHS
@Alternate Data Stream - 36 bytes -> C:\WINDOWS\System32\IM31DXF.DIL:KAVICHS
@Alternate Data Stream - 36 bytes -> C:\WINDOWS\System32\IM31BMP.DIL:KAVICHS
@Alternate Data Stream - 36 bytes -> C:\WINDOWS\System32\ideograf.uce:KAVICHS
@Alternate Data Stream - 36 bytes -> C:\WINDOWS\System32\icfgnt5.dll:KAVICHS
@Alternate Data Stream - 36 bytes -> C:\WINDOWS\System32\HTMUTIL.DLL:KAVICHS
@Alternate Data Stream - 36 bytes -> C:\WINDOWS\System32\hticons.dll:KAVICHS
@Alternate Data Stream - 36 bytes -> C:\WINDOWS\System32\hpzcon07.dll:KAVICHS
@Alternate Data Stream - 36 bytes -> C:\WINDOWS\System32\hpzcoi07.dll:KAVICHS
@Alternate Data Stream - 36 bytes -> C:\WINDOWS\System32\HPZc3212.dll:KAVICHS
@Alternate Data Stream - 36 bytes -> C:\WINDOWS\System32\HLP95EN.DLL:KAVICHS
@Alternate Data Stream - 36 bytes -> C:\WINDOWS\System32\HANDLE.INI:KAVICHS
@Alternate Data Stream - 36 bytes -> C:\WINDOWS\System32\getuname.dll:KAVICHS
@Alternate Data Stream - 36 bytes -> C:\WINDOWS\System32\gb2312.uce:KAVICHS
@Alternate Data Stream - 36 bytes -> C:\WINDOWS\System32\fxssend.exe:KAVICHS
@Alternate Data Stream - 36 bytes -> C:\WINDOWS\System32\fxsperf.ini:KAVICHS
@Alternate Data Stream - 36 bytes -> C:\WINDOWS\System32\fxscount.h:KAVICHS
@Alternate Data Stream - 36 bytes -> C:\WINDOWS\System32\fxsclntR.dll:KAVICHS
@Alternate Data Stream - 36 bytes -> C:\WINDOWS\System32\fxscfgwz.dll:KAVICHS
@Alternate Data Stream - 36 bytes -> C:\WINDOWS\System32\FTPx.ocx:KAVICHS
@Alternate Data Stream - 36 bytes -> C:\WINDOWS\System32\FTPx.dll:KAVICHS
@Alternate Data Stream - 36 bytes -> C:\WINDOWS\System32\FTPWPP.DLL:KAVICHS
@Alternate Data Stream - 36 bytes -> C:\WINDOWS\System32\FPWPP.DLL:KAVICHS
@Alternate Data Stream - 36 bytes -> C:\WINDOWS\System32\FPHttp.dll:KAVICHS
@Alternate Data Stream - 36 bytes -> C:\WINDOWS\System32\FNTCACHE.DAT:KAVICHS
@Alternate Data Stream - 36 bytes -> C:\WINDOWS\System32\fnfilter.dll:KAVICHS
@Alternate Data Stream - 36 bytes -> C:\WINDOWS\System32\FM20ENU.DLL:KAVICHS
@Alternate Data Stream - 36 bytes -> C:\WINDOWS\System32\FM20.DLL:KAVICHS
@Alternate Data Stream - 36 bytes -> C:\WINDOWS\System32\EXSEC32.DLL:KAVICHS
@Alternate Data Stream - 36 bytes -> C:\WINDOWS\System32\EqnClass.Dll:KAVICHS
@Alternate Data Stream - 36 bytes -> C:\WINDOWS\System32\emptyregdb.dat:KAVICHS
@Alternate Data Stream - 36 bytes -> C:\WINDOWS\System32\EMLCNS32.DLL:KAVICHS
@Alternate Data Stream - 36 bytes -> C:\WINDOWS\System32\EMDAZ32.DLL:KAVICHS
@Alternate Data Stream - 36 bytes -> C:\WINDOWS\System32\dzgtactx.dll:KAVICHS
@Alternate Data Stream - 36 bytes -> C:\WINDOWS\System32\dx3j.dll:KAVICHS
@Alternate Data Stream - 36 bytes -> C:\WINDOWS\System32\DRVVFP.HLP:KAVICHS
@Alternate Data Stream - 36 bytes -> C:\WINDOWS\System32\DRVVFP.CNT:KAVICHS
@Alternate Data Stream - 36 bytes -> C:\WINDOWS\System32\drivers\SHARSHTL.SYS:KAVICHS
@Alternate Data Stream - 36 bytes -> C:\WINDOWS\System32\drivers\etc\protocol:KAVICHS
@Alternate Data Stream - 36 bytes -> C:\WINDOWS\System32\drivers\etc\networks:KAVICHS
@Alternate Data Stream - 36 bytes -> C:\WINDOWS\System32\drivers\etc\lmhosts.sam:KAVICHS
@Alternate Data Stream - 36 bytes -> C:\WINDOWS\System32\drivers\EPATAPNT.MPD:KAVICHS
@Alternate Data Stream - 36 bytes -> C:\WINDOWS\System32\drivers\ASUSHWIO.SYS:KAVICHS
@Alternate Data Stream - 36 bytes -> C:\WINDOWS\System32\drivers\ASPI32.SYS:KAVICHS
@Alternate Data Stream - 36 bytes -> C:\WINDOWS\System32\dmcpl.exe:KAVICHS
@Alternate Data Stream - 36 bytes -> C:\WINDOWS\System32\dgrpsetu.dll:KAVICHS
@Alternate Data Stream - 36 bytes -> C:\WINDOWS\System32\DDAO36.DLL:KAVICHS
@Alternate Data Stream - 36 bytes -> C:\WINDOWS\System32\dbmsvinn.dLL:KAVICHS
@Alternate Data Stream - 36 bytes -> C:\WINDOWS\System32\DBMSSOCN.DLL:KAVICHS
@Alternate Data Stream - 36 bytes -> C:\WINDOWS\System32\dbmsadsn.dll:KAVICHS
@Alternate Data Stream - 36 bytes -> C:\WINDOWS\System32\DBLIST32.OCX:KAVICHS
@Alternate Data Stream - 36 bytes -> C:\WINDOWS\System32\DBLIST32.DEP:KAVICHS
@Alternate Data Stream - 36 bytes -> C:\WINDOWS\System32\DBLIST.SRG:KAVICHS
@Alternate Data Stream - 36 bytes -> C:\WINDOWS\System32\DBGRID32.OCX:KAVICHS
@Alternate Data Stream - 36 bytes -> C:\WINDOWS\System32\DBGRID32.DEP:KAVICHS
@Alternate Data Stream - 36 bytes -> C:\WINDOWS\System32\DBGRID.SRG:KAVICHS
@Alternate Data Stream - 36 bytes -> C:\WINDOWS\System32\DBADAPT.DLL:KAVICHS
@Alternate Data Stream - 36 bytes -> C:\WINDOWS\System32\DATALIST.SRG:KAVICHS
@Alternate Data Stream - 36 bytes -> C:\WINDOWS\System32\CTVLST32.OCX:KAVICHS
@Alternate Data Stream - 36 bytes -> C:\WINDOWS\System32\CSPLST32.OCX:KAVICHS
@Alternate Data Stream - 36 bytes -> C:\WINDOWS\System32\CSLIST32.OCX:KAVICHS
@Alternate Data Stream - 36 bytes -> C:\WINDOWS\System32\CSFORM32.OCX:KAVICHS
@Alternate Data Stream - 36 bytes -> C:\WINDOWS\System32\CSCOMB32.OCX:KAVICHS
@Alternate Data Stream - 36 bytes -> C:\WINDOWS\System32\CSCMD32.OCX:KAVICHS
@Alternate Data Stream - 36 bytes -> C:\WINDOWS\System32\CRSWPP.DLL:KAVICHS
@Alternate Data Stream - 36 bytes -> C:\WINDOWS\System32\COMMTB32.DLL:KAVICHS
@Alternate Data Stream - 36 bytes -> C:\WINDOWS\System32\COMDLG32.DEP:KAVICHS
@Alternate Data Stream - 36 bytes -> C:\WINDOWS\System32\comctl32.ocx:KAVICHS
@Alternate Data Stream - 36 bytes -> C:\WINDOWS\System32\COMCTL32.NU7:KAVICHS
@Alternate Data Stream - 36 bytes -> C:\WINDOWS\System32\COMCTL32.DEP:KAVICHS
@Alternate Data Stream - 36 bytes -> C:\WINDOWS\System32\COMCTL2.SRG:KAVICHS
@Alternate Data Stream - 36 bytes -> C:\WINDOWS\System32\COMCTL.SRG:KAVICHS
@Alternate Data Stream - 36 bytes -> C:\WINDOWS\System32\COMCT332.SRG:KAVICHS
@Alternate Data Stream - 36 bytes -> C:\WINDOWS\System32\comct332.ocx:KAVICHS
@Alternate Data Stream - 36 bytes -> C:\WINDOWS\System32\COMCT332.DEP:KAVICHS
@Alternate Data Stream - 36 bytes -> C:\WINDOWS\System32\COMCT232.OCX:KAVICHS
@Alternate Data Stream - 36 bytes -> C:\WINDOWS\System32\COMCT232.DEP:KAVICHS
@Alternate Data Stream - 36 bytes -> C:\WINDOWS\System32\CMDIALOG.SRG:KAVICHS
@Alternate Data Stream - 36 bytes -> C:\WINDOWS\System32\clspack.exe:KAVICHS
@Alternate Data Stream - 36 bytes -> C:\WINDOWS\System32\CIRAS.OCX:KAVICHS
@Alternate Data Stream - 36 bytes -> C:\WINDOWS\System32\charmap.exe:KAVICHS
@Alternate Data Stream - 36 bytes -> C:\WINDOWS\System32\cdmodem.dll:KAVICHS
@Alternate Data Stream - 36 bytes -> C:\WINDOWS\System32\calc.exe:KAVICHS
@Alternate Data Stream - 36 bytes -> C:\WINDOWS\System32\c_28603.nls:KAVICHS
@Alternate Data Stream - 36 bytes -> C:\WINDOWS\System32\c_28599.nls:KAVICHS
@Alternate Data Stream - 36 bytes -> C:\WINDOWS\System32\C_28597.NLS:KAVICHS
@Alternate Data Stream - 36 bytes -> C:\WINDOWS\System32\C_28595.NLS:KAVICHS
@Alternate Data Stream - 36 bytes -> C:\WINDOWS\System32\C_28594.NLS:KAVICHS
@Alternate Data Stream - 36 bytes -> C:\WINDOWS\System32\c_20127.nls:KAVICHS
@Alternate Data Stream - 36 bytes -> C:\WINDOWS\System32\bopomofo.uce:KAVICHS
@Alternate Data Stream - 36 bytes -> C:\WINDOWS\System32\besched.dll:KAVICHS
@Alternate Data Stream - 36 bytes -> C:\WINDOWS\System32\besch.exe:KAVICHS
@Alternate Data Stream - 36 bytes -> C:\WINDOWS\System32\BENTOFIO.DLL:KAVICHS
@Alternate Data Stream - 36 bytes -> C:\WINDOWS\System32\Base64.dll:KAVICHS
@Alternate Data Stream - 36 bytes -> C:\WINDOWS\System32\azip32.dll:KAVICHS
@Alternate Data Stream - 36 bytes -> C:\WINDOWS\System32\avwav.dll:KAVICHS
@Alternate Data Stream - 36 bytes -> C:\WINDOWS\System32\avtapi.dll:KAVICHS
@Alternate Data Stream - 36 bytes -> C:\WINDOWS\System32\avmeter.dll:KAVICHS
@Alternate Data Stream - 36 bytes -> C:\WINDOWS\System32\AUTPRX32.DLL:KAVICHS
@Alternate Data Stream - 36 bytes -> C:\WINDOWS\System32\AUTOEXEC.NT:KAVICHS
@Alternate Data Stream - 36 bytes -> C:\WINDOWS\System32\AUTMGR32.EXE:KAVICHS
@Alternate Data Stream - 36 bytes -> C:\WINDOWS\System32\Audio3D.dll:KAVICHS
@Alternate Data Stream - 36 bytes -> C:\WINDOWS\System32\atrace.dll:KAVICHS
@Alternate Data Stream - 36 bytes -> C:\WINDOWS\System32\atl70.dll:KAVICHS
@Alternate Data Stream - 36 bytes -> C:\WINDOWS\System32\asutl8.dll:KAVICHS
@Alternate Data Stream - 36 bytes -> C:\WINDOWS\System32\ADODC.SRG:KAVICHS
@Alternate Data Stream - 36 bytes -> C:\WINDOWS\System32\ADIST5.PPD:KAVICHS
@Alternate Data Stream - 36 bytes -> C:\WINDOWS\System32\acctres.dll:KAVICHS
@Alternate Data Stream - 36 bytes -> C:\WINDOWS\System32\a3d.dll:KAVICHS
@Alternate Data Stream - 36 bytes -> C:\WINDOWS\System\WOWPOST.EXE:KAVICHS
@Alternate Data Stream - 36 bytes -> C:\WINDOWS\System\WINASPI.DLL:KAVICHS
@Alternate Data Stream - 36 bytes -> C:\WINDOWS\System\WFWNET.DRV:KAVICHS
@Alternate Data Stream - 36 bytes -> C:\WINDOWS\System\VGA.DRV:KAVICHS
@Alternate Data Stream - 36 bytes -> C:\WINDOWS\System\vaspid.386:KAVICHS
@Alternate Data Stream - 36 bytes -> C:\WINDOWS\System\TIMER.DRV:KAVICHS
@Alternate Data Stream - 36 bytes -> C:\WINDOWS\System\SYSTEM.DRV:KAVICHS
@Alternate Data Stream - 36 bytes -> C:\WINDOWS\System\SOUND.DRV:KAVICHS
@Alternate Data Stream - 36 bytes -> C:\WINDOWS\System\setup.inf:KAVICHS
@Alternate Data Stream - 36 bytes -> C:\WINDOWS\System\READMEHP.WRI:KAVICHS
@Alternate Data Stream - 36 bytes -> C:\WINDOWS\System\QCTL3D.DLL:KAVICHS
@Alternate Data Stream - 36 bytes -> C:\WINDOWS\System\QCONNECT.DLL:KAVICHS
@Alternate Data Stream - 36 bytes -> C:\WINDOWS\System\PJAM.WAV:KAVICHS
@Alternate Data Stream - 36 bytes -> C:\WINDOWS\System\PFEED.WAV:KAVICHS
@Alternate Data Stream - 36 bytes -> C:\WINDOWS\System\PERROR.WAV:KAVICHS
@Alternate Data Stream - 36 bytes -> C:\WINDOWS\System\PCOVER.WAV:KAVICHS
@Alternate Data Stream - 36 bytes -> C:\WINDOWS\System\PCOMMERR.WAV:KAVICHS
@Alternate Data Stream - 36 bytes -> C:\WINDOWS\System\PADDPAP.WAV:KAVICHS
@Alternate Data Stream - 36 bytes -> C:\WINDOWS\System\MOUSE.DRV:KAVICHS
@Alternate Data Stream - 36 bytes -> C:\WINDOWS\System\KEYBOARD.DRV:KAVICHS
@Alternate Data Stream - 36 bytes -> C:\WINDOWS\System\HPPCL5EO.HLP:KAVICHS
@Alternate Data Stream - 36 bytes -> C:\WINDOWS\System\HPPCL5E4.DLL:KAVICHS
@Alternate Data Stream - 36 bytes -> C:\WINDOWS\System\HPPCL5E3.DLL:KAVICHS
@Alternate Data Stream - 36 bytes -> C:\WINDOWS\System\HPPCL5E2.DLL:KAVICHS
@Alternate Data Stream - 36 bytes -> C:\WINDOWS\System\HPPCL5E1.DLL:KAVICHS
@Alternate Data Stream - 36 bytes -> C:\WINDOWS\System\HPPCL5E.HLP:KAVICHS
@Alternate Data Stream - 36 bytes -> C:\WINDOWS\System\HPPCL5E.DRV:KAVICHS
@Alternate Data Stream - 36 bytes -> C:\WINDOWS\System\FINSTALL.HLP:KAVICHS
@Alternate Data Stream - 36 bytes -> C:\WINDOWS\System\FINSTALL.DLL:KAVICHS
@Alternate Data Stream - 36 bytes -> C:\WINDOWS\System\CTL3DV2.DLL:KAVICHS
@Alternate Data Stream - 36 bytes -> C:\WINDOWS\System\CTL3D.DLL:KAVICHS
@Alternate Data Stream - 36 bytes -> C:\WINDOWS\System\cmswtape.386:KAVICHS
@Alternate Data Stream - 36 bytes -> C:\WINDOWS\System\cmids3d.dll:KAVICHS
@Alternate Data Stream - 36 bytes -> C:\WINDOWS\System\CmiCnfg.ini:KAVICHS
@Alternate Data Stream - 36 bytes -> C:\WINDOWS\System\AVICAP.DLL:KAVICHS
@Alternate Data Stream - 36 bytes -> C:\WINDOWS\ST4UNST.EXE:KAVICHS
@Alternate Data Stream - 36 bytes -> C:\WINDOWS\ST4UNST.003:KAVICHS
@Alternate Data Stream - 36 bytes -> C:\WINDOWS\ST4UNST.002:KAVICHS
@Alternate Data Stream - 36 bytes -> C:\WINDOWS\ST4UNST.001:KAVICHS
@Alternate Data Stream - 36 bytes -> C:\WINDOWS\ST4UNST.000:KAVICHS
@Alternate Data Stream - 36 bytes -> C:\WINDOWS\SSB.ini:KAVICHS
@Alternate Data Stream - 36 bytes -> C:\WINDOWS\Soap Bubbles.bmp:KAVICHS
@Alternate Data Stream - 36 bytes -> C:\WINDOWS\SKY32V3C.DLL:KAVICHS
@Alternate Data Stream - 36 bytes -> C:\WINDOWS\SIS_LIB.DLL:KAVICHS
@Alternate Data Stream - 36 bytes -> C:\WINDOWS\setuplog.txt:KAVICHS
@Alternate Data Stream - 36 bytes -> C:\WINDOWS\setupact.log:KAVICHS
@Alternate Data Stream - 36 bytes -> C:\WINDOWS\setdebug.exe:KAVICHS
@Alternate Data Stream - 36 bytes -> C:\WINDOWS\sessmgr.setup.log:KAVICHS
@Alternate Data Stream - 36 bytes -> C:\WINDOWS\SchedLgU.Txt:KAVICHS
@Alternate Data Stream - 36 bytes -> C:\WINDOWS\Santa Fe Stucco.bmp:KAVICHS
@Alternate Data Stream - 36 bytes -> C:\WINDOWS\rtpatch.ini:KAVICHS
@Alternate Data Stream - 36 bytes -> C:\WINDOWS\River Sumida.bmp:KAVICHS
@Alternate Data Stream - 36 bytes -> C:\WINDOWS\Rhododendron.bmp:KAVICHS
@Alternate Data Stream - 36 bytes -> C:\WINDOWS\regopt.log:KAVICHS
@Alternate Data Stream - 36 bytes -> C:\WINDOWS\qwshellx.ini:KAVICHS
@Alternate Data Stream - 36 bytes -> C:\WINDOWS\QVPC.INI:KAVICHS
@Alternate Data Stream - 36 bytes -> C:\WINDOWS\QUICKEN.INI:KAVICHS
@Alternate Data Stream - 36 bytes -> C:\WINDOWS\Q828026.log:KAVICHS
@Alternate Data Stream - 36 bytes -> C:\WINDOWS\Q819696.log:KAVICHS
@Alternate Data Stream - 36 bytes -> C:\WINDOWS\Q817606.log:KAVICHS
@Alternate Data Stream - 36 bytes -> C:\WINDOWS\Q817287.log:KAVICHS
@Alternate Data Stream - 36 bytes -> C:\WINDOWS\Q815021.log:KAVICHS
@Alternate Data Stream - 36 bytes -> C:\WINDOWS\Q814033.log:KAVICHS
@Alternate Data Stream - 36 bytes -> C:\WINDOWS\Q811630.log:KAVICHS
@Alternate Data Stream - 36 bytes -> C:\WINDOWS\Q811493.log:KAVICHS
@Alternate Data Stream - 36 bytes -> C:\WINDOWS\Q810833.log:KAVICHS
@Alternate Data Stream - 36 bytes -> C:\WINDOWS\Q810577.log:KAVICHS
@Alternate Data Stream - 36 bytes -> C:\WINDOWS\Q810565.log:KAVICHS
@Alternate Data Stream - 36 bytes -> C:\WINDOWS\Q330994.exe:KAVICHS
@Alternate Data Stream - 36 bytes -> C:\WINDOWS\Q329834.log:KAVICHS
@Alternate Data Stream - 36 bytes -> C:\WINDOWS\Q329441.log:KAVICHS
@Alternate Data Stream - 36 bytes -> C:\WINDOWS\Q329390.log:KAVICHS
@Alternate Data Stream - 36 bytes -> C:\WINDOWS\Q329170.log:KAVICHS
@Alternate Data Stream - 36 bytes -> C:\WINDOWS\Q329115.log:KAVICHS
@Alternate Data Stream - 36 bytes -> C:\WINDOWS\Q329048.log:KAVICHS
@Alternate Data Stream - 36 bytes -> C:\WINDOWS\Q328310.log:KAVICHS
@Alternate Data Stream - 36 bytes -> C:\WINDOWS\Q323255.log:KAVICHS
@Alternate Data Stream - 36 bytes -> C:\WINDOWS\Prairie Wind.bmp:KAVICHS
@Alternate Data Stream - 36 bytes -> C:\WINDOWS\OEWABLog.txt:KAVICHS
@Alternate Data Stream - 36 bytes -> C:\WINDOWS\ODBCINST.INI:KAVICHS
@Alternate Data Stream - 36 bytes -> C:\WINDOWS\ODBC.INI:KAVICHS
@Alternate Data Stream - 36 bytes -> C:\WINDOWS\ocmsn.log:KAVICHS
@Alternate Data Stream - 36 bytes -> C:\WINDOWS\ocgen.log:KAVICHS
@Alternate Data Stream - 36 bytes -> C:\WINDOWS\ntdtcsetup.log:KAVICHS
@Alternate Data Stream - 36 bytes -> C:\WINDOWS\nsreg.dat:KAVICHS
@Alternate Data Stream - 36 bytes -> C:\WINDOWS\msgsocm.log:KAVICHS
@Alternate Data Stream - 36 bytes -> C:\WINDOWS\ModemLog_Intel® Ham 5628 V.92 Modem.txt:KAVICHS
@Alternate Data Stream - 36 bytes -> C:\WINDOWS\mdm.ini:KAVICHS
@Alternate Data Stream - 36 bytes -> C:\WINDOWS\KB840374.log:KAVICHS
@Alternate Data Stream - 36 bytes -> C:\WINDOWS\KB837001.log:KAVICHS
@Alternate Data Stream - 36 bytes -> C:\WINDOWS\KB835732.log:KAVICHS
@Alternate Data Stream - 36 bytes -> C:\WINDOWS\KB828741.log:KAVICHS
@Alternate Data Stream - 36 bytes -> C:\WINDOWS\KB828035.log:KAVICHS
@Alternate Data Stream - 36 bytes -> C:\WINDOWS\KB828028.log:KAVICHS
@Alternate Data Stream - 36 bytes -> C:\WINDOWS\KB825119.log:KAVICHS
@Alternate Data Stream - 36 bytes -> C:\WINDOWS\KB824146.log:KAVICHS
@Alternate Data Stream - 36 bytes -> C:\WINDOWS\KB824141.log:KAVICHS
@Alternate Data Stream - 36 bytes -> C:\WINDOWS\KB824105.log:KAVICHS
@Alternate Data Stream - 36 bytes -> C:\WINDOWS\KB823980.log:KAVICHS
@Alternate Data Stream - 36 bytes -> C:\WINDOWS\KB823559.log:KAVICHS
@Alternate Data Stream - 36 bytes -> C:\WINDOWS\KB823182.log:KAVICHS
@Alternate Data Stream - 36 bytes -> C:\WINDOWS\KB821557.log:KAVICHS
@Alternate Data Stream - 36 bytes -> C:\WINDOWS\KB810217.log:KAVICHS
@Alternate Data Stream - 36 bytes -> C:\WINDOWS\JAUTOEXP.INI:KAVICHS
@Alternate Data Stream - 36 bytes -> C:\WINDOWS\jautoexp.dat:KAVICHS
@Alternate Data Stream - 36 bytes -> C:\WINDOWS\ISYSSQL.INI:KAVICHS
@Alternate Data Stream - 36 bytes -> C:\WINDOWS\ISYSKNOW.INI:KAVICHS
@Alternate Data Stream - 36 bytes -> C:\WINDOWS\ISYS.INI:KAVICHS
@Alternate Data Stream - 36 bytes -> C:\WINDOWS\ISYS.GRP:KAVICHS
@Alternate Data Stream - 36 bytes -> C:\WINDOWS\INTUIT.INI:KAVICHS
@Alternate Data Stream - 36 bytes -> C:\WINDOWS\iis6.log:KAVICHS
@Alternate Data Stream - 36 bytes -> C:\WINDOWS\IEPatchUninstall.log:KAVICHS
@Alternate Data Stream - 36 bytes -> C:\WINDOWS\Greenstone.bmp:KAVICHS
@Alternate Data Stream - 36 bytes -> C:\WINDOWS\Gone Fishing.bmp:KAVICHS
@Alternate Data Stream - 36 bytes -> C:\WINDOWS\FeatherTexture.bmp:KAVICHS
@Alternate Data Stream - 36 bytes -> C:\WINDOWS\FaxSetup.log:KAVICHS
@Alternate Data Stream - 36 bytes -> C:\WINDOWS\FASTWiz.log:KAVICHS
@Alternate Data Stream - 36 bytes -> C:\WINDOWS\DUNZIP32.DLL:KAVICHS
@Alternate Data Stream - 36 bytes -> C:\WINDOWS\DtcInstall.log:KAVICHS
@Alternate Data Stream - 36 bytes -> C:\WINDOWS\DINSTALL.RC:KAVICHS
@Alternate Data Stream - 36 bytes -> C:\WINDOWS\dahotfix.log:KAVICHS
@Alternate Data Stream - 36 bytes -> C:\WINDOWS\COM+.log:KAVICHS
@Alternate Data Stream - 36 bytes -> C:\WINDOWS\Coffee Bean.bmp:KAVICHS
@Alternate Data Stream - 36 bytes -> C:\WINDOWS\CMIUninstall.exe:KAVICHS
@Alternate Data Stream - 36 bytes -> C:\WINDOWS\CMISETUP.INI:KAVICHS
@Alternate Data Stream - 36 bytes -> C:\WINDOWS\CmiRmRedundDir.exe:KAVICHS
@Alternate Data Stream - 36 bytes -> C:\WINDOWS\CMIRmDriver.dll:KAVICHS
@Alternate Data Stream - 36 bytes -> C:\WINDOWS\CMCDPLAY.INI:KAVICHS
@Alternate Data Stream - 36 bytes -> C:\WINDOWS\CDPlayer.ini:KAVICHS
@Alternate Data Stream - 36 bytes -> C:\WINDOWS\browsev2.ini:KAVICHS
@Alternate Data Stream - 36 bytes -> C:\WINDOWS\bootstat.dat:KAVICHS
@Alternate Data Stream - 36 bytes -> C:\WINDOWS\Blue Lace 16.bmp:KAVICHS
@Alternate Data Stream - 36 bytes -> C:\WINDOWS\AWMODEM.INF:KAVICHS
@Alternate Data Stream - 36 bytes -> C:\WINDOWS\A5.INI:KAVICHS
@Alternate Data Stream - 36 bytes -> C:\VIRTPART.DAT:KAVICHS
@Alternate Data Stream - 36 bytes -> C:\msconfig.exe.lnk:KAVICHS
@Alternate Data Stream - 36 bytes -> C:\Documents and Settings\User\My Documents\xxLogins.doc:KAVICHS
@Alternate Data Stream - 36 bytes -> C:\Documents and Settings\User\Local Settings\Application Data\FASTWiz.log:KAVICHS
@Alternate Data Stream - 36 bytes -> C:\Documents and Settings\User\Local Settings\Application Data\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini:KAVICHS
@Alternate Data Stream - 36 bytes -> C:\Documents and Settings\User\Desktop\zzTO-DO.txt:KAVICHS
@Alternate Data Stream - 36 bytes -> C:\Documents and Settings\User\Desktop\Quicken 5.lnk:KAVICHS
@Alternate Data Stream - 36 bytes -> C:\Documents and Settings\User\Desktop\Alpha 5.lnk:KAVICHS
@Alternate Data Stream - 36 bytes -> C:\Documents and Settings\User\Application Data\Comma Separated Values (Windows).EML:KAVICHS
@Alternate Data Stream - 36 bytes -> C:\Documents and Settings\All Users\Start Menu\Programs\MSN Explorer.lnk:KAVICHS
@Alternate Data Stream - 36 bytes -> C:\Documents and Settings\All Users\Desktop\PowerDVD.lnk:KAVICHS
@Alternate Data Stream - 36 bytes -> C:\Documents and Settings\All Users\Application Data\hpzinstall.log:KAVICHS
@Alternate Data Stream - 36 bytes -> C:\CONFIG.SYS:KAVICHS
< End of report >