Jump to content


 


Register a free account to unlock additional features at BleepingComputer.com
Welcome to BleepingComputer, a free community where people like yourself come together to discuss and learn how to use their computers. Using the site is easy and fun. As a guest, you can browse and view the various discussions in the forums, but can not create a new topic or reply to an existing one unless you are logged in. Other benefits of registering an account are subscribing to topics and forums, creating a blog, and having no ads shown anywhere on the site.


Click here to Register a free account now! or read our Welcome Guide to learn how to use this site.

Photo

Suspect Trojan


  • Please log in to reply
34 replies to this topic

#1 bdfinally

bdfinally

  • Members
  • 34 posts
  • OFFLINE
  •  
  • Local time:10:55 PM

Posted 13 January 2008 - 03:23 PM

computer acting a little hinky and i've run thru all the procedures to clean as much off as possible. here is my first hjt log

Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 2:43:59 PM, on 1/13/2008
Platform: Windows XP SP1 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\LEXBCES.EXE
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\system32\LEXPPS.EXE
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\System32\drivers\CDAC11BA.EXE
C:\WINDOWS\System32\gkqoiebe.exe
C:\Program Files\Common Files\Protexis\License Service\PSIService.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\SYSTEM32\ZONELABS\vsmon.exe
C:\Program Files\Microsoft Hardware\Keyboard\type32.exe
C:\Program Files\Lexmark X1100 Series\lxbkbmgr.exe
C:\Program Files\Zone Labs\ZoneAlarm\zonealarm.exe
C:\Program Files\Lexmark X1100 Series\lxbkbmgr .exe
C:\Program Files\Microsoft Hardware\Keyboard\type32 .exe
C:\Program Files\Lexmark X1100 Series\lxbkbmon.exe
C:\Program Files\SpywareGuard\sgmain.exe
D:\Program Files\Yahoo!\Messenger\ymsgr_tray.exe
C:\Program Files\SpywareGuard\sgbhp.exe
C:\WINDOWS\System32\wuauclt.exe
C:\WINDOWS\System32\WgaTray.exe
C:\Program Files\Opera\Opera.exe
C:\WINDOWS\System32\rundll32.exe
C:\WINDOWS\System32\wuauclt.exe
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe
C:\WINDOWS\System32\windows

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.msnbc.msn.com/
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = about:blank
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Local Page =
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page =
F3 - REG:win.ini: load=C:\WINDOWS\System32\hgdab.exe
O3 - Toolbar: Dictionary.com - {11359F4A-B191-42D7-905A-594F8CF0387B} - C:\WINDOWS\DOWNLOADED PROGRAM FILES\LEXBAR.DLL (file missing)
O3 - Toolbar: Adobe PDF - {47833539-D0C5-4125-9FA8-0819E2EAAC93} - C:\Program Files\Adobe\Acrobat 6.0\Acrobat\AcroIEFavClient.dll
O3 - Toolbar: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - D:\Program Files\Yahoo!\Companion\Installs\cpn0\yt.dll
O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINDOWS\system32\msdxm.ocx
O4 - HKLM\..\Run: [SystemTray] SysTray.Exe
O4 - HKLM\..\Run: [IntelliType] "C:\Program Files\Microsoft Hardware\Keyboard\type32.exe"
O4 - HKLM\..\Run: [Lexmark X1100 Series] "C:\Program Files\Lexmark X1100 Series\lxbkbmgr.exe"
O4 - HKLM\..\Run: [Tweak UI] RUNDLL32.EXE TWEAKUI.CPL,TweakMeUp
O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
O4 - HKCU\..\Run: [Yahoo! Pager] "D:\Program Files\Yahoo!\Messenger\YahooMessenger.exe" -quiet
O4 - HKCU\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\QTTask .exe" -atboottime
O4 - HKCU\..\Run: [2768197e] rundll32.exe "C:\WINDOWS\System32\ghecehjl.dll",b
O4 - HKUS\S-1-5-18\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime (User 'Default user')
O4 - Startup: SpywareGuard.lnk = C:\Program Files\SpywareGuard\sgmain.exe
O4 - Global Startup: ZoneAlarm.lnk = C:\Program Files\Zone Labs\ZoneAlarm\zonealarm.exe
O4 - Global Startup: HP OfficeJet Series 700 StartUp.lnk = C:\Program Files\HP OfficeJet Series 700\bin\HPOstr03.exe
O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office\OSA9.EXE
O4 - Global Startup: Adobe Gamma Loader.lnk = C:\Program Files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe
O8 - Extra context menu item: LimeShop Preferences - file://C:\Program Files\LimeShop\System\Temp\limeshop_script0.htm
O8 - Extra context menu item: Search &Dictionary - C:\Program files\Lexico\Toolbar\dictionary.htm
O8 - Extra context menu item: Search &Thesaurus - C:\Program files\Lexico\Toolbar\thesaurus.htm
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_01\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_01\bin\ssv.dll
O9 - Extra button: Messenger - {4528BBE0-4E08-11D5-AD55-00010333D0AD} - D:\Program Files\Yahoo!\Messenger\yhexbmes0411.dll
O9 - Extra 'Tools' menuitem: Yahoo! Messenger - {4528BBE0-4E08-11D5-AD55-00010333D0AD} - D:\Program Files\Yahoo!\Messenger\yhexbmes0411.dll
O9 - Extra button: ICQ - {6224f700-cba3-4071-b251-47cb894244cd} - C:\Program Files\ICQ\ICQ.exe
O9 - Extra 'Tools' menuitem: ICQ - {6224f700-cba3-4071-b251-47cb894244cd} - C:\Program Files\ICQ\ICQ.exe
O9 - Extra button: (no name) - {85d1f590-48f4-11d9-9669-0800200c9a66} - C:\WINDOWS\bdoscandel.exe
O9 - Extra 'Tools' menuitem: Uninstall BitDefender Online Scanner v8 - {85d1f590-48f4-11d9-9669-0800200c9a66} - C:\WINDOWS\bdoscandel.exe
O9 - Extra button: AIM - {AC9E2541-2814-11d5-BC6D-00B0D0A1DE45} - D:\Program Files\AIM95\aim.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\MSMSGS.EXE (file missing)
O9 - Extra 'Tools' menuitem: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\MSMSGS.EXE (file missing)
O16 - DPF: Yahoo! Chat - http://us.chat1.yimg.com/us.yimg.com/i/cha...t/c381/chat.cab
O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) - http://go.microsoft.com/fwlink/?linkid=39204
O16 - DPF: {1EF9F042-C2EB-4293-8213-474CAEEF531D} (TmHcmsX Control) - http://www.trendsecure.com/framework/contr...vex/TmHcmsX.CAB
O16 - DPF: {215B8138-A3CF-44C5-803F-8226143CFC0A} (Trend Micro ActiveX Scan Agent 6.6) - http://housecall65.trendmicro.com/housecal...ivex/hcImpl.cab
O16 - DPF: {41F17733-B041-4099-A042-B518BB6A408C} - http://a1540.g.akamai.net/7/1540/52/200207...meInstaller.exe
O16 - DPF: {5D86DDB5-BDF9-441B-9E9E-D4730F4EE499} (BDSCANONLINE Control) - http://download.bitdefender.com/resources/scan8/oscan8.cab
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://update.microsoft.com/microsoftupdat...b?1177173261147
O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - http://www.update.microsoft.com/microsoftu...b?1182507576623
O16 - DPF: {82202BE7-C56A-487E-9E55-D84BDC1A5776} - http://install.anark.com/client/version1/w...en/AMClient.cab
O16 - DPF: {9A9307A0-7DA4-4DAF-B042-5009F29E09E1} (ActiveScan Installer Class) - http://acs.pandasoftware.com/activescan/as5free/asinst.cab
O16 - DPF: {A17E30C4-A9BA-11D4-8673-60DB54C10000} (YahooYMailTo Class) - http://us.dl1.yimg.com/download.yahoo.com/.../ymmapi_416.dll
O17 - HKLM\System\CCS\Services\Tcpip\..\{E83A60C0-E2EB-4C33-A02C-B760AB11ECAD}: Domain = domain
O17 - HKLM\System\CCS\Services\Tcpip\..\{E83A60C0-E2EB-4C33-A02C-B760AB11ECAD}: NameServer = 192.168.254.254
O23 - Service: Ati HotKey Poller - Unknown owner - C:\WINDOWS\System32\Ati2evxx.exe
O23 - Service: ATI Smart - Unknown owner - C:\WINDOWS\SYSTEM32\ati2sgag.exe
O23 - Service: AVG Anti-Spyware Guard - GRISOFT s.r.o. - C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
O23 - Service: C-DillaCdaC11BA - Macrovision - C:\WINDOWS\System32\drivers\CDAC11BA.EXE
O23 - Service: DomainService - - C:\WINDOWS\System32\gkqoiebe.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: iPod Service - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: LexBce Server (LexBceS) - Lexmark International, Inc. - C:\WINDOWS\system32\LEXBCES.EXE
O23 - Service: Microsoft cache control (MSControlService) - Unknown owner - C:\WINDOWS\System32\windows
O23 - Service: ProtexisLicensing - Unknown owner - C:\Program Files\Common Files\Protexis\License Service\PSIService.exe
O23 - Service: TrueVector Internet Monitor (vsmon) - Zone Labs Inc. - C:\WINDOWS\SYSTEM32\ZONELABS\vsmon.exe

--
End of file - 8388 bytes

BC AdBot (Login to Remove)

 


#2 OldTimer

OldTimer

    Malware Expert


  • Members
  • 11,092 posts
  • OFFLINE
  •  
  • Gender:Male
  • Location:North Carolina
  • Local time:10:55 PM

Posted 19 January 2008 - 04:52 PM

Hello bdfinally and welcome to the BC HijackThis forum. It looks like there are a few items in there. Let's see what else is hiding on the machine.

Download WinPFind35u.exe to your Desktop and double-click on it to extract the files. It will create a folder named WinPFind35u on your desktop.

Note: You must be logged on to the system with an account that has Administrator privileges to run this program.
  • Close ALL OTHER PROGRAMS.
  • Open the WinPFind3u folder and double-click on WinPFind35U.exe to start the program.
  • In the Drivers section click on Non-Microsoft.
  • Under Additional Scans click the checkboxes in front of the following items to select them:
    • Reg - BotCheck
      Reg - Session Manager Settings
      Reg - Software Policy Settings
      File - Additional Folder Scans
  • Do not change any other settings.
  • Now click the Run Scan button on the toolbar.
  • Let it run unhindered until it finishes.
  • When the scan is complete Notepad will open with the report file loaded in it.
  • Click the Format menu and make sure that Wordwrap is not checked. If it is then click on it to uncheck it.
Use the Add Reply button and Copy/Paste the information back here. I will review it when it comes in.

If, after posting, the last line is not < End of Report > then the log is too big to fit into a single post and you will need to split it into multiple posts or attach it as a file.

Cheers.

OT
I do not respond to PM's requesting help. That's what the forums are here for. Please use them so that others may benefit from your questions and the responses you receive.
OldTimer

Posted Image

#3 bdfinally

bdfinally
  • Topic Starter

  • Members
  • 34 posts
  • OFFLINE
  •  
  • Local time:10:55 PM

Posted 20 January 2008 - 01:11 PM

Thanks for the reply Oldtimer. I've tried to run the scan 3 times and all have been unsuccessful. I hangs up and is non responsive. At this point i'm lean towards wiping th drive and a reformat, but i'm open to your thoughts on the matter. Here's my latest HJT log

Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 1:09:11 PM, on 1/20/2008
Platform: Windows XP SP1 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\LEXBCES.EXE
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\system32\LEXPPS.EXE
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\System32\drivers\CDAC11BA.EXE
C:\WINDOWS\System32\gkqoiebe.exe
C:\Program Files\Common Files\Protexis\License Service\PSIService.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\SYSTEM32\ZONELABS\vsmon.exe
C:\Program Files\Microsoft Hardware\Keyboard\type32.exe
C:\Program Files\Lexmark X1100 Series\lxbkbmgr.exe
C:\Program Files\Microsoft Hardware\Keyboard\type32 .exe
C:\Program Files\Lexmark X1100 Series\lxbkbmgr .exe
C:\Program Files\Lexmark X1100 Series\lxbkbmon.exe
C:\Program Files\Zone Labs\ZoneAlarm\zonealarm.exe
C:\Program Files\SpywareGuard\sgmain.exe
C:\Program Files\SpywareGuard\sgbhp.exe
C:\WINDOWS\System32\WgaTray.exe
C:\WINDOWS\System32\wuauclt.exe
C:\WINDOWS\system32\NOTEPAD.EXE
C:\Program Files\Mozilla Firefox\firefox.exe
C:\Documents and Settings\BRIAN STONEBURG\Desktop\HiJackThis\HijackThis.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.msnbc.msn.com/
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = about:blank
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Local Page =
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page =
F3 - REG:win.ini: load=C:\WINDOWS\System32\hgdab.exe
O3 - Toolbar: Dictionary.com - {11359F4A-B191-42D7-905A-594F8CF0387B} - C:\WINDOWS\DOWNLOADED PROGRAM FILES\LEXBAR.DLL (file missing)
O3 - Toolbar: Adobe PDF - {47833539-D0C5-4125-9FA8-0819E2EAAC93} - C:\Program Files\Adobe\Acrobat 6.0\Acrobat\AcroIEFavClient.dll
O3 - Toolbar: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - D:\Program Files\Yahoo!\Companion\Installs\cpn0\yt.dll
O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINDOWS\system32\msdxm.ocx
O4 - HKLM\..\Run: [SystemTray] SysTray.Exe
O4 - HKLM\..\Run: [IntelliType] "C:\Program Files\Microsoft Hardware\Keyboard\type32.exe"
O4 - HKLM\..\Run: [Lexmark X1100 Series] "C:\Program Files\Lexmark X1100 Series\lxbkbmgr.exe"
O4 - HKLM\..\Run: [Tweak UI] RUNDLL32.EXE TWEAKUI.CPL,TweakMeUp
O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
O4 - HKCU\..\Run: [Yahoo! Pager] "D:\Program Files\Yahoo!\Messenger\YahooMessenger.exe" -quiet
O4 - HKCU\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\QTTask .exe" -atboottime
O4 - HKCU\..\Run: [2768197e] rundll32.exe "C:\WINDOWS\System32\ghecehjl.dll",b
O4 - HKUS\S-1-5-18\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime (User 'Default user')
O4 - Startup: SpywareGuard.lnk = C:\Program Files\SpywareGuard\sgmain.exe
O4 - Global Startup: ZoneAlarm.lnk = C:\Program Files\Zone Labs\ZoneAlarm\zonealarm.exe
O4 - Global Startup: HP OfficeJet Series 700 StartUp.lnk = C:\Program Files\HP OfficeJet Series 700\bin\HPOstr03.exe
O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office\OSA9.EXE
O4 - Global Startup: Adobe Gamma Loader.lnk = C:\Program Files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe
O8 - Extra context menu item: LimeShop Preferences - file://C:\Program Files\LimeShop\System\Temp\limeshop_script0.htm
O8 - Extra context menu item: Search &Dictionary - C:\Program files\Lexico\Toolbar\dictionary.htm
O8 - Extra context menu item: Search &Thesaurus - C:\Program files\Lexico\Toolbar\thesaurus.htm
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_01\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_01\bin\ssv.dll
O9 - Extra button: Messenger - {4528BBE0-4E08-11D5-AD55-00010333D0AD} - D:\Program Files\Yahoo!\Messenger\yhexbmes0411.dll
O9 - Extra 'Tools' menuitem: Yahoo! Messenger - {4528BBE0-4E08-11D5-AD55-00010333D0AD} - D:\Program Files\Yahoo!\Messenger\yhexbmes0411.dll
O9 - Extra button: ICQ - {6224f700-cba3-4071-b251-47cb894244cd} - C:\Program Files\ICQ\ICQ.exe
O9 - Extra 'Tools' menuitem: ICQ - {6224f700-cba3-4071-b251-47cb894244cd} - C:\Program Files\ICQ\ICQ.exe
O9 - Extra button: (no name) - {85d1f590-48f4-11d9-9669-0800200c9a66} - C:\WINDOWS\bdoscandel.exe
O9 - Extra 'Tools' menuitem: Uninstall BitDefender Online Scanner v8 - {85d1f590-48f4-11d9-9669-0800200c9a66} - C:\WINDOWS\bdoscandel.exe
O9 - Extra button: AIM - {AC9E2541-2814-11d5-BC6D-00B0D0A1DE45} - D:\Program Files\AIM95\aim.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\MSMSGS.EXE (file missing)
O9 - Extra 'Tools' menuitem: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\MSMSGS.EXE (file missing)
O16 - DPF: Yahoo! Chat - http://us.chat1.yimg.com/us.yimg.com/i/cha...t/c381/chat.cab
O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) - http://go.microsoft.com/fwlink/?linkid=39204
O16 - DPF: {1EF9F042-C2EB-4293-8213-474CAEEF531D} (TmHcmsX Control) - http://www.trendsecure.com/framework/contr...vex/TmHcmsX.CAB
O16 - DPF: {215B8138-A3CF-44C5-803F-8226143CFC0A} (Trend Micro ActiveX Scan Agent 6.6) - http://housecall65.trendmicro.com/housecal...ivex/hcImpl.cab
O16 - DPF: {41F17733-B041-4099-A042-B518BB6A408C} - http://a1540.g.akamai.net/7/1540/52/200207...meInstaller.exe
O16 - DPF: {5D86DDB5-BDF9-441B-9E9E-D4730F4EE499} (BDSCANONLINE Control) - http://download.bitdefender.com/resources/scan8/oscan8.cab
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://update.microsoft.com/microsoftupdat...b?1177173261147
O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - http://www.update.microsoft.com/microsoftu...b?1182507576623
O16 - DPF: {82202BE7-C56A-487E-9E55-D84BDC1A5776} - http://install.anark.com/client/version1/w...en/AMClient.cab
O16 - DPF: {9A9307A0-7DA4-4DAF-B042-5009F29E09E1} (ActiveScan Installer Class) - http://acs.pandasoftware.com/activescan/as5free/asinst.cab
O16 - DPF: {A17E30C4-A9BA-11D4-8673-60DB54C10000} (YahooYMailTo Class) - http://us.dl1.yimg.com/download.yahoo.com/.../ymmapi_416.dll
O17 - HKLM\System\CCS\Services\Tcpip\..\{E83A60C0-E2EB-4C33-A02C-B760AB11ECAD}: Domain = domain
O17 - HKLM\System\CCS\Services\Tcpip\..\{E83A60C0-E2EB-4C33-A02C-B760AB11ECAD}: NameServer = 192.168.254.254
O23 - Service: Ati HotKey Poller - Unknown owner - C:\WINDOWS\System32\Ati2evxx.exe
O23 - Service: ATI Smart - Unknown owner - C:\WINDOWS\SYSTEM32\ati2sgag.exe
O23 - Service: AVG Anti-Spyware Guard - GRISOFT s.r.o. - C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
O23 - Service: C-DillaCdaC11BA - Macrovision - C:\WINDOWS\System32\drivers\CDAC11BA.EXE
O23 - Service: DomainService - - C:\WINDOWS\System32\gkqoiebe.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: iPod Service - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: LexBce Server (LexBceS) - Lexmark International, Inc. - C:\WINDOWS\system32\LEXBCES.EXE
O23 - Service: ProtexisLicensing - Unknown owner - C:\Program Files\Common Files\Protexis\License Service\PSIService.exe
O23 - Service: TrueVector Internet Monitor (vsmon) - Zone Labs Inc. - C:\WINDOWS\SYSTEM32\ZONELABS\vsmon.exe

--
End of file - 8203 bytes

#4 OldTimer

OldTimer

    Malware Expert


  • Members
  • 11,092 posts
  • OFFLINE
  •  
  • Gender:Male
  • Location:North Carolina
  • Local time:10:55 PM

Posted 20 January 2008 - 03:30 PM

Hi bdfinally. Try running it in Safe Mode (not Safe Mode with Networking).

Cheers.

OT
I do not respond to PM's requesting help. That's what the forums are here for. Please use them so that others may benefit from your questions and the responses you receive.
OldTimer

Posted Image

#5 bdfinally

bdfinally
  • Topic Starter

  • Members
  • 34 posts
  • OFFLINE
  •  
  • Local time:10:55 PM

Posted 20 January 2008 - 07:32 PM

couldn't scoll down to and click the additional folds scan....log is huge appears to be Size = 306176 bytes

#6 OldTimer

OldTimer

    Malware Expert


  • Members
  • 11,092 posts
  • OFFLINE
  •  
  • Gender:Male
  • Location:North Carolina
  • Local time:10:55 PM

Posted 20 January 2008 - 08:11 PM

Try clicking the Maximize button.

Cheers.

OT
I do not respond to PM's requesting help. That's what the forums are here for. Please use them so that others may benefit from your questions and the responses you receive.
OldTimer

Posted Image

#7 bdfinally

bdfinally
  • Topic Starter

  • Members
  • 34 posts
  • OFFLINE
  •  
  • Local time:10:55 PM

Posted 21 January 2008 - 08:21 AM

still can't scroll down to check that last box. the file is here

http://www.fileden.com/files/2008/1/20/171.../WinPFind35.zip

Edited by bdfinally, 21 January 2008 - 08:29 AM.


#8 OldTimer

OldTimer

    Malware Expert


  • Members
  • 11,092 posts
  • OFFLINE
  •  
  • Gender:Male
  • Location:North Carolina
  • Local time:10:55 PM

Posted 21 January 2008 - 02:22 PM

Hi bdfinally. I didn't even need to look that log through to know what it was. This variant of Vundo infects many legitimate files and applications. Start organizing your installation disks because there will most certainly be some re-installation to to.

Let's see if we can't knock it around a bit. Download Combofix from any of the links below, and save it to your desktop. For information regarding this download, please visit this webpage: http://www.bleepingcomputer.com/combofix/how-to-use-combofix

Link 1
Link 2
Link 3


**Note: It is important that it is saved directly to your desktop**

--------------------------------------------------------------------

1. Close any open browsers.

2. Close/disable all anti virus and anti malware programs so they do not interfere with the running of ComboFix.

--------------------------------------------------------------------

Double click on combofix.exe & follow the prompts.
  • When finished, it will produce a report for you.
  • Please post the "C:\ComboFix.txt" along with a new HijackThis log for further review.
Note:
Do not mouseclick combofix's window while it's running. That may cause it to stall


I will review the information when it comes in.

Cheers.

OT
I do not respond to PM's requesting help. That's what the forums are here for. Please use them so that others may benefit from your questions and the responses you receive.
OldTimer

Posted Image

#9 bdfinally

bdfinally
  • Topic Starter

  • Members
  • 34 posts
  • OFFLINE
  •  
  • Local time:10:55 PM

Posted 21 January 2008 - 08:12 PM

it took 1.5 hours and not quite sure it produced all the report, but here it is and hjt log

Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 19:59, on 2008-01-21
Platform: Windows XP SP1 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\LEXBCES.EXE
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\system32\LEXPPS.EXE
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\System32\drivers\CDAC11BA.EXE
C:\Program Files\Common Files\Protexis\License Service\PSIService.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\SYSTEM32\ZONELABS\vsmon.exe
C:\Program Files\Zone Labs\ZoneAlarm\zonealarm.exe
C:\Program Files\SpywareGuard\sgmain.exe
D:\Program Files\Yahoo!\Messenger\ymsgr_tray.exe
C:\Program Files\SpywareGuard\sgbhp.exe
C:\WINDOWS\System32\wuauclt.exe
C:\WINDOWS\System32\WgaTray.exe
C:\WINDOWS\system32\NOTEPAD.EXE
C:\WINDOWS\System32\rundll32.exe
C:\WINDOWS\System32\jusybwlu.exe
H:\downloads\HiJackThis 2\HijackThis.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.msnbc.msn.com/
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = about:blank
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Local Page =
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page =
F3 - REG:win.ini: load=C:\WINDOWS\System32\hgdab.exe
O3 - Toolbar: Dictionary.com - {11359F4A-B191-42D7-905A-594F8CF0387B} - C:\WINDOWS\DOWNLOADED PROGRAM FILES\LEXBAR.DLL (file missing)
O3 - Toolbar: Adobe PDF - {47833539-D0C5-4125-9FA8-0819E2EAAC93} - C:\Program Files\Adobe\Acrobat 6.0\Acrobat\AcroIEFavClient.dll
O3 - Toolbar: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - D:\Program Files\Yahoo!\Companion\Installs\cpn0\yt.dll
O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINDOWS\system32\msdxm.ocx
O4 - HKLM\..\Run: [SystemTray] SysTray.Exe
O4 - HKLM\..\Run: [IntelliType] "C:\Program Files\Microsoft Hardware\Keyboard\type32.exe"
O4 - HKLM\..\Run: [Lexmark X1100 Series] "C:\Program Files\Lexmark X1100 Series\lxbkbmgr.exe"
O4 - HKLM\..\Run: [Tweak UI] RUNDLL32.EXE TWEAKUI.CPL,TweakMeUp
O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
O4 - HKCU\..\Run: [Yahoo! Pager] "D:\Program Files\Yahoo!\Messenger\YahooMessenger.exe" -quiet
O4 - HKCU\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\QTTask .exe" -atboottime
O4 - HKCU\..\Run: [2768197e] rundll32.exe "C:\WINDOWS\System32\vlqhyreg.dll",b
O4 - HKUS\S-1-5-18\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime (User 'Default user')
O4 - Startup: SpywareGuard.lnk = C:\Program Files\SpywareGuard\sgmain.exe
O4 - Global Startup: ZoneAlarm.lnk = C:\Program Files\Zone Labs\ZoneAlarm\zonealarm.exe
O4 - Global Startup: HP OfficeJet Series 700 StartUp.lnk = C:\Program Files\HP OfficeJet Series 700\bin\HPOstr03.exe
O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office\OSA9.EXE
O4 - Global Startup: Adobe Gamma Loader.lnk = C:\Program Files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe
O8 - Extra context menu item: LimeShop Preferences - file://C:\Program Files\LimeShop\System\Temp\limeshop_script0.htm
O8 - Extra context menu item: Search &Dictionary - C:\Program files\Lexico\Toolbar\dictionary.htm
O8 - Extra context menu item: Search &Thesaurus - C:\Program files\Lexico\Toolbar\thesaurus.htm
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_01\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_01\bin\ssv.dll
O9 - Extra button: Messenger - {4528BBE0-4E08-11D5-AD55-00010333D0AD} - D:\Program Files\Yahoo!\Messenger\yhexbmes0411.dll
O9 - Extra 'Tools' menuitem: Yahoo! Messenger - {4528BBE0-4E08-11D5-AD55-00010333D0AD} - D:\Program Files\Yahoo!\Messenger\yhexbmes0411.dll
O9 - Extra button: ICQ - {6224f700-cba3-4071-b251-47cb894244cd} - C:\Program Files\ICQ\ICQ.exe
O9 - Extra 'Tools' menuitem: ICQ - {6224f700-cba3-4071-b251-47cb894244cd} - C:\Program Files\ICQ\ICQ.exe
O9 - Extra button: (no name) - {85d1f590-48f4-11d9-9669-0800200c9a66} - C:\WINDOWS\bdoscandel.exe
O9 - Extra 'Tools' menuitem: Uninstall BitDefender Online Scanner v8 - {85d1f590-48f4-11d9-9669-0800200c9a66} - C:\WINDOWS\bdoscandel.exe
O9 - Extra button: AIM - {AC9E2541-2814-11d5-BC6D-00B0D0A1DE45} - D:\Program Files\AIM95\aim.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\MSMSGS.EXE (file missing)
O9 - Extra 'Tools' menuitem: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\MSMSGS.EXE (file missing)
O16 - DPF: Yahoo! Chat - http://us.chat1.yimg.com/us.yimg.com/i/cha...t/c381/chat.cab
O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) - http://go.microsoft.com/fwlink/?linkid=39204
O16 - DPF: {1EF9F042-C2EB-4293-8213-474CAEEF531D} (TmHcmsX Control) - http://www.trendsecure.com/framework/contr...vex/TmHcmsX.CAB
O16 - DPF: {215B8138-A3CF-44C5-803F-8226143CFC0A} (Trend Micro ActiveX Scan Agent 6.6) - http://housecall65.trendmicro.com/housecal...ivex/hcImpl.cab
O16 - DPF: {41F17733-B041-4099-A042-B518BB6A408C} - http://a1540.g.akamai.net/7/1540/52/200207...meInstaller.exe
O16 - DPF: {5D86DDB5-BDF9-441B-9E9E-D4730F4EE499} (BDSCANONLINE Control) - http://download.bitdefender.com/resources/scan8/oscan8.cab
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://update.microsoft.com/microsoftupdat...b?1177173261147
O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - http://www.update.microsoft.com/microsoftu...b?1182507576623
O16 - DPF: {82202BE7-C56A-487E-9E55-D84BDC1A5776} - http://install.anark.com/client/version1/w...en/AMClient.cab
O16 - DPF: {9A9307A0-7DA4-4DAF-B042-5009F29E09E1} (ActiveScan Installer Class) - http://acs.pandasoftware.com/activescan/as5free/asinst.cab
O16 - DPF: {A17E30C4-A9BA-11D4-8673-60DB54C10000} (YahooYMailTo Class) - http://us.dl1.yimg.com/download.yahoo.com/.../ymmapi_416.dll
O17 - HKLM\System\CCS\Services\Tcpip\..\{E83A60C0-E2EB-4C33-A02C-B760AB11ECAD}: Domain = domain
O17 - HKLM\System\CCS\Services\Tcpip\..\{E83A60C0-E2EB-4C33-A02C-B760AB11ECAD}: NameServer = 192.168.254.254
O23 - Service: Ati HotKey Poller - Unknown owner - C:\WINDOWS\System32\Ati2evxx.exe
O23 - Service: ATI Smart - Unknown owner - C:\WINDOWS\SYSTEM32\ati2sgag.exe
O23 - Service: AVG Anti-Spyware Guard - GRISOFT s.r.o. - C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
O23 - Service: C-DillaCdaC11BA - Macrovision - C:\WINDOWS\System32\drivers\CDAC11BA.EXE
O23 - Service: DomainService - - C:\WINDOWS\System32\jusybwlu.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: iPod Service - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: LexBce Server (LexBceS) - Lexmark International, Inc. - C:\WINDOWS\system32\LEXBCES.EXE
O23 - Service: ProtexisLicensing - Unknown owner - C:\Program Files\Common Files\Protexis\License Service\PSIService.exe
O23 - Service: TrueVector Internet Monitor (vsmon) - Zone Labs Inc. - C:\WINDOWS\SYSTEM32\ZONELABS\vsmon.exe

--
End of file - 7930 bytes

Attached Files



#10 OldTimer

OldTimer

    Malware Expert


  • Members
  • 11,092 posts
  • OFFLINE
  •  
  • Gender:Male
  • Location:North Carolina
  • Local time:10:55 PM

Posted 21 January 2008 - 09:25 PM

Hi bdfinally. Is that all there was? That's just a part and only shows some .tmp files. HijackThis won't show this infection at all so let's run a new WinPFInd35u scan.

First I need you to delete your current version (the file you downloaded and the folder it created. Then download it again and run a new report as shown below.

Download WinPFind35u.exe to your Desktop and double-click on it to extract the files. It will create a folder named WinPFind35u on your desktop.

Note: You must be logged on to the system with an account that has Administrator privileges to run this program.
  • Close ALL OTHER PROGRAMS.
  • Open the WinPFind3u folder and double-click on WinPFind35U.exe to start the program.
  • In the Drivers section click on Non-Microsoft.
  • Under Additional Scans click the checkboxes in front of the following items to select them:
    • Reg - BotCheck
      File - Additional Folder Scans
  • Do not change any other settings.
  • Now click the Run Scan button on the toolbar.
  • Let it run unhindered until it finishes.
  • When the scan is complete Notepad will open with the report file loaded in it.
  • Click the Format menu and make sure that Wordwrap is not checked. If it is then click on it to uncheck it.
Use the Add Reply button and Copy/Paste the information back here. I will review it when it comes in.

If, after posting, the last line is not < End of Report > then the log is too big to fit into a single post and you will need to split it into multiple posts or attach it as a file.

Cheers.

OT
I do not respond to PM's requesting help. That's what the forums are here for. Please use them so that others may benefit from your questions and the responses you receive.
OldTimer

Posted Image

#11 bdfinally

bdfinally
  • Topic Starter

  • Members
  • 34 posts
  • OFFLINE
  •  
  • Local time:10:55 PM

Posted 21 January 2008 - 10:50 PM

still can't scroll down to the additional folder scans...here's the log

http://www.fileden.com/files/2008/1/20/171.../WinPFind35.Txt

#12 OldTimer

OldTimer

    Malware Expert


  • Members
  • 11,092 posts
  • OFFLINE
  •  
  • Gender:Male
  • Location:North Carolina
  • Local time:10:55 PM

Posted 21 January 2008 - 11:05 PM

Hi bdfinally. The WinPFind35 log is unreadable. It's jsut a bunch of ascii characers. Instead of attaching it just copy/paste it into the topic.

What is your screen resolution set at? Is the screen size really small or the font size really large?

Cheers.

OT
I do not respond to PM's requesting help. That's what the forums are here for. Please use them so that others may benefit from your questions and the responses you receive.
OldTimer

Posted Image

#13 bdfinally

bdfinally
  • Topic Starter

  • Members
  • 34 posts
  • OFFLINE
  •  
  • Local time:10:55 PM

Posted 22 January 2008 - 07:24 AM

fonts are large, but i've tried changing the resolution already and has no effect on it in safe mode. the file 1.95 mg

heres the first section

WinPFind35 logfile created on: 2008-01-21 22:24:46
WinPFind35U Version Beta31 Folder = C:\Documents and Settings\BRIAN STONEBURG\Desktop\WinPFind35u
Windows XP Home Edition Service Pack 1 (Version = 5.1.2600) - Type = NTWorkstation
Internet Explorer (Version = 6.0.2800.1106)

511.30 Mb Total Physical Memory | 364.59 Mb Available Physical Memory | 71.31% Memory free
865.41 Mb Paging File | 810.50 Mb Available in Paging File | 93.66% Paging File free
Paging file location(s): C:\pagefile.sys 384 768;

%SystemDrive% = C: | %SystemRoot% = C:\WINDOWS | %ProgramFiles% = C:\Program Files
Drive C: | 37.26 Gb Total Space | 10.76 Gb Free Space | 28.89% Space Free | Partition Type: FAT32
Drive D: | 9.52 Gb Total Space | 6.78 Gb Free Space | 71.24% Space Free | Partition Type: FAT32
Drive E: | 522.80 Mb Total Space | 0.00 Mb Free Space | 0.00% Space Free | Partition Type: CDFS
F: Drive not present or media not loaded

Computer Name: BDFINALLY
Current User Name: BRIAN STONEBURG
Logged in as Administrator.
Cannot determine boot mode.
Scan Mode: Current user


[Processes - Non-Microsoft Only]
winpfind35u.exe -> %UserDesktop%\WinPFind35u\WinPFind35U.exe -> OldTimer Tools [Ver = 1.0.0.0 | Size = 306176 bytes | Modified Date = 2008-01-21 19:33:52 | Attr = ]

[Win32 Services - Non-Microsoft Only]
(Ati HotKey Poller) Ati HotKey Poller [Win32_Own | On_Demand | Stopped] -> %System32%\Ati2evxx.exe -> [Ver = | Size = 254037 bytes | Modified Date = 2003-04-28 22:28:46 | Attr = ]
(ATI Smart) ATI Smart [Win32_Own | On_Demand | Stopped] -> %System32%\ati2sgag.exe -> [Ver = 5.13.0010 | Size = 114775 bytes | Modified Date = 2003-04-28 21:00:00 | Attr = ]
(AVG Anti-Spyware Guard) AVG Anti-Spyware Guard [Win32_Own | On_Demand | Stopped] -> %ProgramFiles%\Grisoft\AVG Anti-Spyware 7.5\guard.exe -> GRISOFT s.r.o. [Ver = 7, 5, 1, 22 | Size = 312880 bytes | Modified Date = 2007-08-26 10:19:16 | Attr = ]
(C-DillaCdaC11BA) C-DillaCdaC11BA [Win32_Own | Auto | Stopped] -> %System32%\drivers\CDAC11BA.EXE -> Macrovision [Ver = 4.16.050 | Size = 52736 bytes | Modified Date = 2005-02-12 10:48:10 | Attr = ]
(dmadmin) Logical Disk Manager Administrative Service [Win32_Shared | On_Demand | Stopped] -> %System32%\dmadmin.exe -> Microsoft Corp., Veritas Software [Ver = 2600.0.503.0 | Size = 204800 bytes | Modified Date = 2002-08-29 12:00:00 | Attr = ]
(DomainService) DomainService [Win32_Own | Auto | Stopped] -> %System32%\jusybwlu.exe -> [Ver = 1, 0, 0, 1 | Size = 74304 bytes | Modified Date = 2008-01-21 19:54:34 | Attr = ]
(IDriverT) InstallDriver Table Manager [Win32_Own | On_Demand | Stopped] -> %CommonProgramFiles%\InstallShield\Driver\11\Intel 32\IDriverT.exe -> Macrovision Corporation [Ver = 11.00.28844 | Size = 69632 bytes | Modified Date = 2005-04-04 00:41:10 | Attr = ]
(iPod Service) iPod Service [Win32_Own | On_Demand | Stopped] -> %ProgramFiles%\iPod\bin\iPodService.exe -> Apple Inc. [Ver = 7.5.0.20 | Size = 504104 bytes | Modified Date = 2007-11-02 18:36:32 | Attr = ]
(LexBceS) LexBce Server [Win32_Own | Auto | Stopped] -> %System32%\LEXBCES.EXE -> Lexmark International, Inc. [Ver = 8.16 | Size = 303104 bytes | Modified Date = 2003-03-28 09:12:10 | Attr = ]
(MSControlService) Microsoft cache control [Win32_Own | On_Demand | Stopped] -> %System32%\windows -> [Ver = | Size = 7168 bytes | Modified Date = 2008-01-21 22:09:52 | Attr = ]
(ProtexisLicensing) ProtexisLicensing [Win32_Own | Auto | Stopped] -> %CommonProgramFiles%\Protexis\License Service\PSIService.exe -> [Ver = 2.0.0.1 | Size = 174656 bytes | Modified Date = 2006-11-02 20:40:12 | Attr = ]
(vsmon) TrueVector Internet Monitor [Win32_Own | Auto | Stopped] -> %System32%\ZONELABS\vsmon.exe -> Zone Labs Inc. [Ver = 3.7.143 | Size = 914744 bytes | Modified Date = 2003-03-14 03:36:18 | Attr = ]

[Driver Services - Non-Microsoft Only]
(Abiosdsk) Abiosdsk [Kernel | Disabled | Stopped] -> -> File not found
(abp480n5) abp480n5 [Kernel | Disabled | Stopped] -> -> File not found
(adpu160m) adpu160m [Kernel | Disabled | Stopped] -> -> File not found
(Aha154x) Aha154x [Kernel | Disabled | Stopped] -> -> File not found
(aic78u2) aic78u2 [Kernel | Disabled | Stopped] -> -> File not found
(aic78xx) aic78xx [Kernel | Disabled | Stopped] -> -> File not found
(AliIde) AliIde [Kernel | Disabled | Stopped] -> -> File not found
(amsint) amsint [Kernel | Disabled | Stopped] -> -> File not found
(asc) asc [Kernel | Disabled | Stopped] -> -> File not found
(asc3350p) asc3350p [Kernel | Disabled | Stopped] -> -> File not found
(asc3550) asc3550 [Kernel | Disabled | Stopped] -> -> File not found
(Atdisk) Atdisk [Kernel | Disabled | Stopped] -> -> File not found
(ati2mtag) ati2mtag [Kernel | On_Demand | Stopped] -> %System32%\DRIVERS\ati2mtag.sys -> ATI Technologies Inc. [Ver = 6.14.10.6343 | Size = 625920 bytes | Modified Date = 2003-04-28 22:39:24 | Attr = ]
(AVG Anti-Spyware Driver) AVG Anti-Spyware Driver [Kernel | System | Stopped] -> %ProgramFiles%\Grisoft\AVG Anti-Spyware 7.5\guard.sys -> [Ver = | Size = 11000 bytes | Modified Date = 2007-08-26 10:19:08 | Attr = ]
(AvgAsCln) AVG Anti-Spyware Clean Driver [Kernel | System | Running] -> %System32%\DRIVERS\AvgAsCln.sys -> GRISOFT, s.r.o. [Ver = 1.0.0.14 | Size = 3968 bytes | Modified Date = 2006-09-05 12:03:16 | Attr = ]
(catchme) catchme [Kernel | On_Demand | Stopped] -> %SystemDrive%\DOCUME~1\BRIANS~1\LOCALS~1\Temp\catchme.sys -> File not found
(cd20xrnt) cd20xrnt [Kernel | Disabled | Stopped] -> -> File not found
(CdaC15BA) CdaC15BA [Kernel | Auto | Stopped] -> %System32%\drivers\CdaC15BA.SYS -> [Ver = | Size = 11376 bytes | Modified Date = 2005-02-12 10:48:08 | Attr = ]
(Changer) Changer [Kernel | System | Stopped] -> -> File not found
(CmdIde) CmdIde [Kernel | Disabled | Stopped] -> -> File not found
(Cpqarray) Cpqarray [Kernel | Disabled | Stopped] -> -> File not found
(dac960nt) dac960nt [Kernel | Disabled | Stopped] -> -> File not found
(dmboot) dmboot [Kernel | Disabled | Stopped] -> %System32%\drivers\dmboot.sys -> Microsoft Corp., Veritas Software [Ver = 2600.0.503.0 | Size = 780928 bytes | Modified Date = 2002-08-29 12:00:00 | Attr = ]
(dmio) dmio [Kernel | Disabled | Stopped] -> %System32%\drivers\dmio.sys -> Microsoft Corp., Veritas Software [Ver = 2600.0.503.0 | Size = 146304 bytes | Modified Date = 2002-08-29 12:00:00 | Attr = ]
(dmload) dmload [Kernel | Disabled | Stopped] -> %System32%\drivers\dmload.sys -> Microsoft Corp., Veritas Software. [Ver = 2600.0.503.0 | Size = 5888 bytes | Modified Date = 2002-08-29 12:00:00 | Attr = ]
(dpti2o) dpti2o [Kernel | Disabled | Stopped] -> -> File not found
(GEARAspiWDM) GEARAspiWDM [Kernel | On_Demand | Running] -> %System32%\Drivers\GEARAspiWDM.sys -> GEAR Software Inc. [Ver = 2.0.6.1 | Size = 15664 bytes | Modified Date = 2006-09-19 15:44:04 | Attr = ]
(gsplittm) gsplittm [Kernel | On_Demand | Stopped] -> %SystemDrive%\DOCUME~1\BRIANS~1\LOCALS~1\Temp\gsplittm.sys -> File not found
(HCF_MSFT) HCF_MSFT [Kernel | On_Demand | Stopped] -> %System32%\DRIVERS\HCF_MSFT.sys -> Conexant [Ver = 2.1.2.171.021.003 | Size = 907456 bytes | Modified Date = 2001-08-17 13:28:02 | Attr = ]
(hpn) hpn [Kernel | Disabled | Stopped] -> -> File not found
(i2omgmt) i2omgmt [Kernel | System | Stopped] -> -> File not found
(i2omp) i2omp [Kernel | Disabled | Stopped] -> -> File not found
(ini910u) ini910u [Kernel | Disabled | Stopped] -> -> File not found
(lbrtfdc) lbrtfdc [Kernel | System | Stopped] -> -> File not found
(MCSTRM) MCSTRM [Kernel | Auto | Stopped] -> %System32%\drivers\mcstrm.sys -> RealNetworks, Inc. [Ver = 5.0.2195.8 | Size = 8413 bytes | Modified Date = 2004-07-27 19:34:32 | Attr = ]
(mraid35x) mraid35x [Kernel | Disabled | Stopped] -> -> File not found
(oreans32) oreans32 [Kernel | System | Stopped] -> %System32%\drivers\oreans32.sys -> [Ver = | Size = 33952 bytes | Modified Date = 2007-04-07 16:55:18 | Attr = ]
(PCIDump) PCIDump [Kernel | System | Stopped] -> -> File not found
(PCIIde) PCIIde [Kernel | Disabled | Stopped] -> -> File not found
(Pcouffin) Low level access layer for CD devices [Kernel | On_Demand | Stopped] -> %System32%\Drivers\Pcouffin.sys -> VSO Software [Ver = 1.22 | Size = 35744 bytes | Modified Date = 2005-01-02 17:51:38 | Attr = ]
(PDCOMP) PDCOMP [Kernel | On_Demand | Stopped] -> -> File not found
(PDFRAME) PDFRAME [Kernel | On_Demand | Stopped] -> -> File not found
(PDRELI) PDRELI [Kernel | On_Demand | Stopped] -> -> File not found
(PDRFRAME) PDRFRAME [Kernel | On_Demand | Stopped] -> -> File not found
(perc2) perc2 [Kernel | Disabled | Stopped] -> -> File not found
(perc2hib) perc2hib [Kernel | Disabled | Stopped] -> -> File not found
(PSC60x) Philips PCI Audio Driver (WDM) [Kernel | On_Demand | Stopped] -> %System32%\drivers\pscaudio.sys -> Philips Components (PSS) [Ver = 5.12.01.3516 | Size = 365460 bytes | Modified Date = 2002-08-27 17:33:32 | Attr = ]
(Ptilink) Direct Parallel Link Driver [Kernel | On_Demand | Stopped] -> %System32%\DRIVERS\ptilink.sys -> Parallel Technologies, Inc. [Ver = 1.10 (XPClient.010817-1148) | Size = 17792 bytes | Modified Date = 2002-08-29 12:00:00 | Attr = ]
(PxHelp20) PxHelp20 [Kernel | Boot | Running] -> %System32%\DRIVERS\PxHelp20.sys -> Sonic Solutions [Ver = 2.02.62a | Size = 20016 bytes | Modified Date = 2003-10-28 06:02:00 | Attr = ]
(ql1080) ql1080 [Kernel | Disabled | Stopped] -> -> File not found
(Ql10wnt) Ql10wnt [Kernel | Disabled | Stopped] -> -> File not found
(ql12160) ql12160 [Kernel | Disabled | Stopped] -> -> File not found
(ql1240) ql1240 [Kernel | Disabled | Stopped] -> -> File not found
(ql1280) ql1280 [Kernel | Disabled | Stopped] -> -> File not found
(QsndEnum) QSound Virtual Audio Devices Bus Enumerator [Kernel | On_Demand | Running] -> %System32%\DRIVERS\QsndEnum.sys -> QSound Labs, Inc. [Ver = 5.00.05.001 built by: WinDDK | Size = 9600 bytes | Modified Date = 2002-07-18 15:47:42 | Attr = ]
(QSoftAud) Philips Sound Agent 2 (WDM) [Kernel | On_Demand | Stopped] -> %System32%\drivers\QSoftAud.sys -> QSound Labs, Inc. [Ver = 5.00.06.031 | Size = 562560 bytes | Modified Date = 2002-08-21 16:14:20 | Attr = ]
(RadProbe) Radeon Probe Driver [Kernel | On_Demand | Stopped] -> %System32%\DRIVERS\RadProbe.sys -> [Ver = 1, 5, 0, 1 | Size = 11468 bytes | Modified Date = 2003-04-19 17:26:08 | Attr = ]
(rtl8139) Realtek RTL8139(A/B/C)-based PCI Fast Ethernet Adapter NT Driver [Kernel | On_Demand | Stopped] -> %System32%\DRIVERS\RTL8139.SYS -> Realtek Semiconductor Corporation [Ver = 5.396.0530.2001 | Size = 23070 bytes | Modified Date = 2001-08-17 12:12:42 | Attr = ]
(SaiNtHid) SaiNtHid [Kernel | On_Demand | Stopped] -> %System32%\DRIVERS\SaiNtHid.sys -> Saitek [Ver = 3,02,000,013 | Size = 48384 bytes | Modified Date = 2003-04-10 11:42:56 | Attr = ]
(SDTHOOK) SDTHOOK [Kernel | On_Demand | Stopped] -> %System32%\DRIVERS\SDTHOOK.sys -> Panda Software [Ver = 1.6.0.0 | Size = 44928 bytes | Modified Date = 2007-06-05 10:56:40 | Attr = ]
(Secdrv) Secdrv [Kernel | On_Demand | Stopped] -> %System32%\DRIVERS\secdrv.sys -> [Ver = | Size = 27440 bytes | Modified Date = 2002-08-29 12:00:00 | Attr = ]
(Simbad) Simbad [Kernel | Disabled | Stopped] -> -> File not found
(Sparrow) Sparrow [Kernel | Disabled | Stopped] -> -> File not found
(symc810) symc810 [Kernel | Disabled | Stopped] -> -> File not found
(symc8xx) symc8xx [Kernel | Disabled | Stopped] -> -> File not found
(sym_hi) sym_hi [Kernel | Disabled | Stopped] -> -> File not found
(sym_u3) sym_u3 [Kernel | Disabled | Stopped] -> -> File not found
(tmcomm) tmcomm [Kernel | Auto | Stopped] -> %System32%\drivers\tmcomm.sys -> Trend Micro Inc. [Ver = 1.6.0.1059 | Size = 102664 bytes | Modified Date = 2008-01-12 14:26:44 | Attr = ]
(TosIde) TosIde [Kernel | Disabled | Stopped] -> -> File not found
(ultra) ultra [Kernel | Disabled | Stopped] -> -> File not found
(ViaIde) ViaIde [Kernel | Disabled | Stopped] -> -> File not found
(vsdatant) vsdatant [Kernel | Auto | Stopped] -> %System32%\vsdatant.sys -> Zone Labs Inc. [Ver = 3.7.143 | Size = 177496 bytes | Modified Date = 2003-03-14 03:36:10 | Attr = ]
(WDICA) WDICA [Kernel | On_Demand | Stopped] -> -> File not found
(WmAdiHid) Logitech WingMan Digital Devices Driver [Kernel | On_Demand | Stopped] -> %System32%\drivers\WmAdiHid.sys -> Logitech Inc. [Ver = 4.25.161 | Size = 20704 bytes | Modified Date = 2003-03-25 04:37:16 | Attr = ]
(WmBEnum) Logitech Virtual Bus Enumerator Driver [Kernel | On_Demand | Running] -> %System32%\drivers\WmBEnum.sys -> Logitech Inc. [Ver = 4.25.161 | Size = 10144 bytes | Modified Date = 2003-03-25 04:37:30 | Attr = ]
(WmFilter) Logitech WingMan HID Filter Driver [Kernel | On_Demand | Stopped] -> %System32%\drivers\WmFilter.sys -> Logitech Inc. [Ver = 4.25.161 | Size = 21216 bytes | Modified Date = 2003-03-25 04:37:34 | Attr = ]
(WmHidLo) Logitech WingMan USB Filter Driver [Kernel | On_Demand | Stopped] -> %System32%\drivers\WmHidLo.sys -> Logitech Inc. [Ver = 4.25.161 | Size = 13920 bytes | Modified Date = 2003-03-25 04:37:34 | Attr = ]
(WmVirHid) Logitech Virtual Hid Device Driver [Kernel | On_Demand | Stopped] -> %System32%\drivers\WmVirHid.sys -> Logitech Inc. [Ver = 4.25.161 | Size = 5728 bytes | Modified Date = 2003-03-25 04:37:30 | Attr = ]
(WmXlCore) Logitech WingMan Translation Layer Driver [Kernel | On_Demand | Running] -> %System32%\drivers\WmXlCore.sys -> Logitech Inc. [Ver = 4.25.161 | Size = 40256 bytes | Modified Date = 2003-03-25 04:37:28 | Attr = ]

[Registry - Non-Microsoft Only]
< Run [HKEY_LOCAL_MACHINE\] > -> HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run ->
IntelliType -> %ProgramFiles%\Microsoft Hardware\Keyboard\type32.exe -> File not found
iTunesHelper -> %ProgramFiles%\iTunes\iTunesHelper.exe -> File not found
Lexmark X1100 Series -> %ProgramFiles%\Lexmark X1100 Series\lxbkbmgr.exe -> File not found
< OptionalComponents [HKEY_LOCAL_MACHINE\] > -> HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\OptionalComponents\ ->
IMAIL-> Installed = 1 ->
MAPI-> Installed = 1 ->
MSFS-> Installed = 1 ->
< Run [HKEY_CURRENT_USER\] > -> HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run ->
2768197e -> %System32%\vlqhyreg.DLL -> [Ver = | Size = 88640 bytes | Modified Date = 2008-01-21 19:54:36 | Attr = ]
MSMSGS -> %ProgramFiles%\Messenger\msmsgs.exe -> File not found
QuickTime Task -> %ProgramFiles%\QuickTime\QTTask .exe -> File not found
Yahoo! Pager -> D:\Program Files\Yahoo!\Messenger\YahooMessenger.exe -> Yahoo! Inc. [Ver = 8,1,0,421 | Size = 4670704 bytes | Modified Date = 2007-08-30 17:43:18 | Attr = ]
< Windows NT\\Load [HKEY_CURRENT_USER\] > -> HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows\\load ->
C:\WINDOWS\System32\hgdab.exe -> %System32%\hgdab.exe -> [Ver = | Size = 348160 bytes | Modified Date = 2008-01-21 22:23:28 | Attr = ]
*MultiFile Done* -> ->
< All Users Startup Folder > -> C:\Documents and Settings\All Users\Start Menu\Programs\Startup ->
%AllUsersStartup%\ZoneAlarm.lnk -> %ProgramFiles%\Zone Labs\ZoneAlarm\zonealarm.exe -> Zone Labs Inc. [Ver = 3.7.143 | Size = 623936 bytes | Modified Date = 2003-03-14 03:37:26 | Attr = ]
%AllUsersStartup%\HP OfficeJet Series 700 StartUp.lnk -> %ProgramFiles%\HP OfficeJet Series 700\bin\HPOstr03.exe -> Hewlett-Packard Co. [Ver = 02.00.00 | Size = 62464 bytes | Modified Date = 1999-11-23 17:56:20 | Attr = ]
%AllUsersStartup%\Adobe Gamma Loader.lnk -> %CommonProgramFiles%\Adobe\Calibration\Adobe Gamma Loader.exe -> Adobe Systems, Inc. [Ver = 1, 0, 0, 1 | Size = 110592 bytes | Modified Date = 2003-09-18 11:08:22 | Attr = ]
< BRIAN STONEBURG Startup Folder > -> C:\Documents and Settings\BRIAN STONEBURG\Start Menu\Programs\Startup ->
%UserStartup%\SpywareGuard.lnk -> %ProgramFiles%\SpywareGuard\sgmain.exe -> [Ver = 2.02.0001 | Size = 360448 bytes | Modified Date = 2003-08-29 19:05:36 | Attr = ]
< ShellExecuteHooks [HKEY_LOCAL_MACHINE] > -> HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks ->
{00DC0058-A87E-4D19-9C26-F1AAC98AD4D7} [HKEY_LOCAL_MACHINE] -> %System32%\vtuvwxv.dll [] -> [Ver = | Size = 40960 bytes | Modified Date = 2008-01-03 00:17:16 | Attr = ]
{57B86673-276A-48B2-BAE7-C6DBB3020EB8} [HKEY_LOCAL_MACHINE] -> %ProgramFiles%\Grisoft\AVG Anti-Spyware 7.5\shellexecutehook.dll [AVG Anti-Spyware 7.5] -> GRISOFT s.r.o. [Ver = 7, 5, 1, 36 | Size = 79408 bytes | Modified Date = 2007-08-26 10:19:10 | Attr = ]
{81559C35-8464-49F7-BB0E-07A383BEF910} [HKEY_LOCAL_MACHINE] -> %ProgramFiles%\SpywareGuard\spywareguard.dll [] -> [Ver = 2.02 | Size = 126976 bytes | Modified Date = 2003-08-02 23:20:58 | Attr = R ]
< SecurityProviders [HKEY_LOCAL_MACHINE] > -> HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SecurityProviders\\SecurityProviders ->
< Winlogon settings [HKEY_LOCAL_MACHINE] > -> HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon ->
< Winlogon settings [HKEY_CURRENT_USER] > -> HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon ->
< Winlogon\Notify settings [HKEY_LOCAL_MACHINE] > -> HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\ ->
vtuvwxv -> %System32%\vtuvwxv.dll -> [Ver = | Size = 40960 bytes | Modified Date = 2008-01-03 00:17:16 | Attr = ]
xwlsxpve -> %System32%\xwlsxpve.dll -> [Ver = | Size = 163904 bytes | Modified Date = 2008-01-13 08:13:18 | Attr = ]
< CurrentVersion Policy Settings [HKEY_LOCAL_MACHINE] > -> HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\ ->
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\ -> ->
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\explorer\ -> ->
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\explorer\\NoDriveAutoRun -> 67108863 ->
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\explorer\\NoDriveTypeAutoRun -> 255 ->
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\explorer\Run\ -> ->
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Network\ -> ->
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Network\\HideSharePwds -> (binary data) ->
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\NonEnum\ -> ->
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\NonEnum\\{BDEADF00-C265-11D0-BCED-00A0C90AB50F} -> 1 ->
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\NonEnum\\{6DFD7C5C-2451-11d3-A299-00C04F8EF6AF} -> 1073741857 ->
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\NonEnum\\{0DF44EAA-FF21-4412-828E-260A8728E7F1} -> 32 ->
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\system\ -> ->
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\system\\dontdisplaylastusername -> 0 ->
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\system\\legalnoticecaption -> ->
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\system\\legalnoticetext -> ->
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\system\\shutdownwithoutlogon -> 1 ->
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\system\\undockwithoutlogon -> 1 ->
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Uninstall\ -> ->
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\WindowsUpdate\ -> ->
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\WinOldApp\ -> ->
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\WinOldApp\\NoRealMode -> 1 ->
< CurrentVersion Policy Settings [HKEY_CURRENT_USER] > -> HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\ ->
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\ -> ->
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\ActiveDesktop\ -> ->
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Associations\ -> ->
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\comdlg32\ -> ->
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\comdlg32\\NoBackButton -> 0 ->
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\comdlg32\\NoFileMru -> 0 ->
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\comdlg32\\NoPlacesBar -> 1 ->
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\ -> ->
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\\NoDriveTypeAutoRun -> 255 ->
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\\ -> (binary data) ->
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\\NoLogoff -> 0 ->
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\\CDRAutoRun -> (binary data) ->
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\Run\ -> ->
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System\ -> ->
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\WindowsUpdate\ -> ->
< HOSTS File > (577894 bytes) -> C:\WINDOWS\System32\drivers\etc\Hosts ->
< Internet Explorer Settings [HKEY_LOCAL_MACHINE\] > -> ->
HKEY_LOCAL_MACHINE\: Main\\Default_Page_URL -> http://www.microsoft.com/isapi/redir.dll?p...&ar=msnhome ->
HKEY_LOCAL_MACHINE\: Main\\Default_Search_URL -> http://www.microsoft.com/isapi/redir.dll?p...amp;ar=iesearch ->
HKEY_LOCAL_MACHINE\: Main\\Search Page -> http://www.microsoft.com/isapi/redir.dll?p...amp;ar=iesearch ->
HKEY_LOCAL_MACHINE\: Main\\Start Page -> about:blank ->
HKEY_LOCAL_MACHINE\: Search\\CustomizeSearch -> http://ie.search.msn.com/{SUB_RFC1766}/srchasst/srchcust.htm ->
HKEY_LOCAL_MACHINE\: Search\\Default_Search_URL -> http://www.microsoft.com/isapi/redir.dll?p...amp;ar=iesearch ->
HKEY_LOCAL_MACHINE\: Search\\SearchAssistant -> http://ie.search.msn.com/{SUB_RFC1766}/srchasst/srchasst.htm ->
< Internet Explorer Settings [HKEY_CURRENT_USER\] > -> ->
HKEY_CURRENT_USER\: Main\\Default_Search_URL -> http://www.microsoft.com/isapi/redir.dll?p...amp;ar=iesearch ->
HKEY_CURRENT_USER\: Main\\Search Page -> http://www.microsoft.com/isapi/redir.dll?p...amp;ar=iesearch ->
HKEY_CURRENT_USER\: Main\\Start Page -> http://www.msnbc.msn.com/ ->
HKEY_CURRENT_USER\: SearchURL\\ -> http://home.microsoft.com/access/autosearch.asp?p=%s[yaho] ->
HKEY_CURRENT_USER\: ProxyEnable -> 0 ->
HKEY_CURRENT_USER\: ProxyOverride -> 127.0.0.1;localhost ->
< Trusted Sites Domains [HKEY_LOCAL_MACHINE\] > -> HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Domains\ ->
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Domains\ -> [Key] 0 domain(s) found. ->
< Trusted Sites Ranges [HKEY_LOCAL_MACHINE\] > -> HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Ranges\ ->
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Ranges\ -> [Key] 0 range(s) found. ->
< Trusted Sites Domains [HKEY_CURRENT_USER\] > -> HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Domains\ ->
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Domains\ -> [Key] 24577 domain(s) found. ->
turbotax.com .[https] -> Trusted sites ->
309 domain(s) and sub-domain(s) not assigned to a zone.
< Trusted Sites Ranges [HKEY_CURRENT_USER\] > -> HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Ranges\ ->
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Ranges\ -> [Key] 1191 range(s) found. ->
< BHO's [HKEY_LOCAL_MACHINE] > -> HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\ ->
{00DC0058-A87E-4D19-9C26-F1AAC98AD4D7} [HKEY_LOCAL_MACHINE] -> %System32%\vtuvwxv.dll [Reg Error: Value does not exist or could not be read.] -> [Ver = | Size = 40960 bytes | Modified Date = 2008-01-03 00:17:16 | Attr = ]
{06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} [HKEY_LOCAL_MACHINE] -> %ProgramFiles%\Adobe\Acrobat 6.0\Acrobat\ActiveX\AcroIEHelper.dll [AcroIEHlprObj Class] -> Adobe Systems Incorporated [Ver = 6.0.0.2003051500 | Size = 50376 bytes | Modified Date = 2003-05-15 00:47:54 | Attr = ]
{11359F4A-B191-42d7-905A-594F8CF0387B} [HKEY_LOCAL_MACHINE] -> %SystemRoot%\DOWNLOADED PROGRAM FILES\LEXBAR.DLL [Dictionary.com] -> File not found
{4A368E80-174F-4872-96B5-0B27DDD11DB2} [HKEY_LOCAL_MACHINE] -> %ProgramFiles%\SpywareGuard\dlprotect.dll [SpywareGuardDLBLOCK.CBrowserHelper] -> [Ver = 2.02 | Size = 192512 bytes | Modified Date = 2003-08-02 23:24:02 | Attr = R ]
{53707962-6F74-2D53-2644-206D7942484F} [HKEY_LOCAL_MACHINE] -> %SystemDrive%\PROGRA~1\SPYBOT~1\SDHelper.dll [] -> Safer Networking Limited [Ver = 1, 4, 0, 0 | Size = 853672 bytes | Modified Date = 2005-05-31 01:04:00 | Attr = ]
{761497BB-D6F0-462C-B6EB-D4DAF1D92D43} [HKEY_LOCAL_MACHINE] -> %ProgramFiles%\Java\jre1.6.0_01\bin\ssv.dll [SSVHelper Class] -> Sun Microsystems, Inc. [Ver = 6.0.10.6 | Size = 501400 bytes | Modified Date = 2007-03-14 03:43:40 | Attr = ]
{8d15fdea-4241-4505-8160-db3421ce3c86} [HKEY_LOCAL_MACHINE] -> %System32%\wcbfangt.dll [Reg Error: Value does not exist or could not be read.] -> [Ver = | Size = 76352 bytes | Modified Date = 2008-01-21 19:54:26 | Attr = ]
{A95B2816-1D7E-4561-A202-68C0DE02353A} [HKEY_LOCAL_MACHINE] -> %System32%\xwlsxpve.dll [Reg Error: Value does not exist or could not be read.] -> [Ver = | Size = 163904 bytes | Modified Date = 2008-01-13 08:13:18 | Attr = ]
{AE7CD045-E861-484f-8273-0445EE161910} [HKEY_LOCAL_MACHINE] -> %ProgramFiles%\Adobe\Acrobat 6.0\Acrobat\AcroIEFavClient.dll [AcroIEToolbarHelper Class] -> [Ver = | Size = 147456 bytes | Modified Date = 2003-05-15 01:03:46 | Attr = ]
{D423644B-21D4-4858-A9DE-89E4718A9EA6} [HKEY_LOCAL_MACHINE] -> %System32%\hgdab.dll [Reg Error: Value does not exist or could not be read.] -> [Ver = | Size = 344576 bytes | Modified Date = 2008-01-03 07:41:32 | Attr = ]
< Internet Explorer Bars [HKEY_LOCAL_MACHINE\] > -> HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Explorer Bars\ ->
{182EC0BE-5110-49C8-A062-BEB1D02A220B} [HKEY_LOCAL_MACHINE] -> %ProgramFiles%\Adobe\Acrobat 6.0\Acrobat\AcroIEFavClient.dll [Adobe PDF] -> [Ver = | Size = 147456 bytes | Modified Date = 2003-05-15 01:03:46 | Attr = ]
{4528BBE0-4E08-11D5-AD55-00010333D0AD} [HKEY_LOCAL_MACHINE] -> D:\Program Files\Yahoo!\Messenger\yhexbmes0411.dll [&Yahoo! Messenger] -> Yahoo! Inc. [Ver = 2003, 4, 11, 1 | Size = 296120 bytes | Modified Date = 2004-02-02 17:35:34 | Attr = ]
< Internet Explorer Bars [HKEY_CURRENT_USER\] > -> HKEY_CURRENT_USER\SOFTWARE\Microsoft\Internet Explorer\Explorer Bars\ ->
{4528BBE0-4E08-11D5-AD55-00010333D0AD} [HKEY_LOCAL_MACHINE] -> D:\Program Files\Yahoo!\Messenger\yhexbmes0411.dll [&Yahoo! Messenger] -> Yahoo! Inc. [Ver = 2003, 4, 11, 1 | Size = 296120 bytes | Modified Date = 2004-02-02 17:35:34 | Attr = ]
< Internet Explorer ToolBars [HKEY_LOCAL_MACHINE] > -> HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\ToolBar ->
{11359F4A-B191-42D7-905A-594F8CF0387B} [HKEY_LOCAL_MACHINE] -> %SystemRoot%\DOWNLOADED PROGRAM FILES\LEXBAR.DLL [Dictionary.com] -> File not found
{47833539-D0C5-4125-9FA8-0819E2EAAC93} [HKEY_LOCAL_MACHINE] -> %ProgramFiles%\Adobe\Acrobat 6.0\Acrobat\AcroIEFavClient.dll [Adobe PDF] -> [Ver = | Size = 147456 bytes | Modified Date = 2003-05-15 01:03:46 | Attr = ]
{8E718888-423F-11D2-876E-00A0C9082467} [HKEY_LOCAL_MACHINE] -> %System32%\msdxm.ocx [&Radio] -> [Ver = | Size = 844048 bytes | Modified Date = 2003-09-17 12:01:28 | Attr = ]
{EF99BD32-C1FB-11D2-892F-0090271D4F88} [HKEY_LOCAL_MACHINE] -> D:\Program Files\Yahoo!\Companion\Installs\cpn0\yt.dll [Yahoo! Toolbar] -> Yahoo! Inc. [Ver = 2005, 8, 4, 2 | Size = 343112 bytes | Modified Date = 2005-08-04 21:54:42 | Attr = ]
< Internet Explorer ToolBars [HKEY_CURRENT_USER\] > -> HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Toolbar\ ->
ShellBrowser\\{014DA6C9-189F-421A-88CD-07CFE51CFF10} [HKEY_LOCAL_MACHINE] -> Reg Error: Key does not exist or could not be opened. [Reg Error: Key does not exist or could not be opened.] -> File not found
ShellBrowser\\{11359F4A-B191-42D7-905A-594F8CF0387B} [HKEY_LOCAL_MACHINE] -> %SystemRoot%\DOWNLOADED PROGRAM FILES\LEXBAR.DLL [Dictionary.com] -> File not found
ShellBrowser\\{2318C2B1-4965-11D4-9B18-009027A5CD4F} [HKEY_LOCAL_MACHINE] -> Reg Error: Key does not exist or could not be opened. [Reg Error: Key does not exist or could not be opened.] -> File not found
ShellBrowser\\{47833539-D0C5-4125-9FA8-0819E2EAAC93} [HKEY_LOCAL_MACHINE] -> %ProgramFiles%\Adobe\Acrobat 6.0\Acrobat\AcroIEFavClient.dll [Adobe PDF] -> [Ver = | Size = 147456 bytes | Modified Date = 2003-05-15 01:03:46 | Attr = ]
WebBrowser\\{11359F4A-B191-42D7-905A-594F8CF0387B} [HKEY_LOCAL_MACHINE] -> %SystemRoot%\DOWNLOADED PROGRAM FILES\LEXBAR.DLL [Dictionary.com] -> File not found
WebBrowser\\{42CDD1BF-3FFB-4238-8AD1-7859DF00B1D6} [HKEY_LOCAL_MACHINE] -> Reg Error: Key does not exist or could not be opened. [Reg Error: Key does not exist or could not be opened.] -> File not found
WebBrowser\\{47833539-D0C5-4125-9FA8-0819E2EAAC93} [HKEY_LOCAL_MACHINE] -> %ProgramFiles%\Adobe\Acrobat 6.0\Acrobat\AcroIEFavClient.dll [Adobe PDF] -> [Ver = | Size = 147456 bytes | Modified Date = 2003-05-15 01:03:46 | Attr = ]
WebBrowser\\{E6AE90A4-1B01-47F0-AA78-E6B122E145E9} [HKEY_LOCAL_MACHINE] -> Reg Error: Key does not exist or could not be opened. [Reg Error: Key does not exist or could not be opened.] -> File not found
WebBrowser\\{EF99BD32-C1FB-11D2-892F-0090271D4F88} [HKEY_LOCAL_MACHINE] -> D:\Program Files\Yahoo!\Companion\Installs\cpn0\yt.dll [Yahoo! Toolbar] -> Yahoo! Inc. [Ver = 2005, 8, 4, 2 | Size = 343112 bytes | Modified Date = 2005-08-04 21:54:42 | Attr = ]
< Internet Explorer Extensions [HKEY_LOCAL_MACHINE] > -> HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Extensions\ ->
{08B0E5C0-4FCB-11CF-AAA5-00401C608501}:{CAFEEFAC-0016-0000-0001-ABCDEFFEDCBC} [HKEY_LOCAL_MACHINE] -> %ProgramFiles%\Java\jre1.6.0_01\bin\npjpi160_01.dll [Sun Java Console] -> Sun Microsystems, Inc. [Ver = 6.0.10.6 | Size = 132760 bytes | Modified Date = 2007-03-14 03:43:42 | Attr = ]
{08B0E5C0-4FCB-11CF-AAA5-00401C608501}:{CAFEEFAC-0016-0000-0001-ABCDEFFEDCBC} [HKEY_CURRENT_USER] -> %ProgramFiles%\Java\jre1.6.0_01\bin\ssv.dll [Sun Java Console] -> Sun Microsystems, Inc. [Ver = 6.0.10.6 | Size = 501400 bytes | Modified Date = 2007-03-14 03:43:40 | Attr = ]
{4528BBE0-4E08-11D5-AD55-00010333D0AD}:{4C171D40-8277-11D5-AD55-00010333D0AD} [HKEY_LOCAL_MACHINE] -> D:\Program Files\Yahoo!\Messenger\yhexbmes0411.dll [Messenger] -> Yahoo! Inc. [Ver = 2003, 4, 11, 1 | Size = 296120 bytes | Modified Date = 2004-02-02 17:35:34 | Attr = ]
{6224f700-cba3-4071-b251-47cb894244cd}:Exec -> %ProgramFiles%\ICQ\ICQ.exe [ICQ] -> ICQ Inc. [Ver = 2002a Beta | Size = 2054213 bytes | Modified Date = 2002-06-19 09:22:56 | Attr = ]
{85d1f590-48f4-11d9-9669-0800200c9a66}:Exec -> %SystemRoot%\bdoscandel.exe [Uninstall BitDefender Online Scanner v8] -> [Ver = | Size = 53248 bytes | Modified Date = 2007-10-25 10:26:48 | Attr = ]
{AC9E2541-2814-11d5-BC6D-00B0D0A1DE45}:Exec -> D:\Program Files\AIM95\aim.exe [AIM] -> America Online, Inc. [Ver = 5.1.3036 | Size = 61440 bytes | Modified Date = 2002-11-13 19:50:20 | Attr = ]
{FB5F1910-F110-11d2-BB9E-00C04F795683}:Exec -> %ProgramFiles%\Messenger\MSMSGS.EXE [Messenger] -> File not found
< Internet Explorer Extensions [HKEY_CURRENT_USER\] > -> HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Extensions\ ->
CmdMapping\\{4528BBE0-4E08-11D5-AD55-00010333D0AD} [HKEY_LOCAL_MACHINE] -> D:\Program Files\Yahoo!\Messenger\yhexbmes0411.dll [&Yahoo! Messenger] -> Yahoo! Inc. [Ver = 2003, 4, 11, 1 | Size = 296120 bytes | Modified Date = 2004-02-02 17:35:34 | Attr = ]
CmdMapping\\{6224f700-cba3-4071-b251-47cb894244cd} [HKEY_LOCAL_MACHINE] -> %ProgramFiles%\ICQ\ICQ.exe [ICQ] -> ICQ Inc. [Ver = 2002a Beta | Size = 2054213 bytes | Modified Date = 2002-06-19 09:22:56 | Attr = ]
CmdMapping\\{85d1f590-48f4-11d9-9669-0800200c9a66} [HKEY_LOCAL_MACHINE] -> %SystemRoot%\bdoscandel.exe [Uninstall BitDefender Online Scanner v8] -> [Ver = | Size = 53248 bytes | Modified Date = 2007-10-25 10:26:48 | Attr = ]
CmdMapping\\{AC9E2541-2814-11d5-BC6D-00B0D0A1DE45} [HKEY_LOCAL_MACHINE] -> D:\Program Files\AIM95\aim.exe [AIM] -> America Online, Inc. [Ver = 5.1.3036 | Size = 61440 bytes | Modified Date = 2002-11-13 19:50:20 | Attr = ]
CmdMapping\\{AF6CABAB-61F9-4f12-A198-B7D41EF1CB52} [HKEY_LOCAL_MACHINE] -> [Reg Error: Key does not exist or could not be opened.] -> File not found
CmdMapping\\{FB5F1910-F110-11d2-BB9E-00C04F795683} [HKEY_LOCAL_MACHINE] -> %ProgramFiles%\Messenger\MSMSGS.EXE [Messenger] -> File not found
< Internet Explorer Menu Extensions [HKEY_CURRENT_USER\] > -> HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\MenuExt\ ->
LimeShop Preferences -> %ProgramFiles%\LimeShop\System\Temp\limeshop_script0.htm -> File not found
Search &Dictionary -> %ProgramFiles%\Lexico\Toolbar\dictionary.htm -> [Ver = | Size = 1103 bytes | Modified Date = 2003-01-11 10:23:38 | Attr = ]
Search &Thesaurus -> %ProgramFiles%\Lexico\Toolbar\thesaurus.htm -> [Ver = | Size = 1104 bytes | Modified Date = 2003-01-11 10:24:04 | Attr = ]
< Internet Explorer Plugins [HKEY_LOCAL_MACHINE] > -> HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Plugins\ ->
PluginsPageFriendlyName -> Microsoft ActiveX Gallery ->
PluginsPage -> http://activex.microsoft.com/controls/find...=%s&mime=%s ->
< DNS Name Servers [HKEY_LOCAL_MACHINE] > -> HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Tcpip\Parameters\Adapters\ ->
{E83A60C0-E2EB-4C33-A02C-B760AB11ECAD} -> 192.168.254.254 (Realtek RTL8139 Family PCI Fast Ethernet NIC) ->
< Default Protocols [HKEY_LOCAL_MACHINE\] - Select to Repair > -> HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\ProtocolDefaults ->
shell -> shell protocol not assigned ->
< Default Protocols [HKEY_CURRENT_USER\] - Select to Repair > -> HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\ProtocolDefaults ->
shell -> shell protocol not assigned ->
< Protocol Handlers [HKEY_LOCAL_MACHINE] > -> HKEY_LOCAL_MACHINE\SOFTWARE\Classes\PROTOCOLS\Handler\ ->
ipp: [HKEY_LOCAL_MACHINE] -> Reg Error: Key does not exist or could not be opened.[Reg Error: Value does not exist or could not be read.] -> File not found
msdaipp: [HKEY_LOCAL_MACHINE] -> Reg Error: Key does not exist or could not be opened.[Reg Error: Value does not exist or could not be read.] -> File not found
vnd.ms.radio:{3DA2AA3B-3D96-11D2-9BD2-204C4F4F5020} [HKEY_LOCAL_MACHINE] -> %System32%\msdxm.ocx[AsyncPProt Class] -> [Ver = | Size = 844048 bytes | Modified Date = 2003-09-17 12:01:28 | Attr = ]
< Downloaded Program Files > -> HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Code Store Database\Distribution Units\ ->
{00000075-0000-0010-8000-00AA00389B71}[HKEY_LOCAL_MACHINE] -> http://codecs.microsoft.com/codecs/i386/voxmsdec.CAB[Reg Error: Key does not exist or could not be opened.] ->
{00000161-0000-0010-8000-00AA00389B71}[HKEY_LOCAL_MACHINE] -> http://codecs.microsoft.com/codecs/i386/msaudio.cab[Reg Error: Key does not exist or could not be opened.] ->
{02BF25D5-8C17-4B23-BC80-D3488ABDDC6B}[HKEY_LOCAL_MACHINE] -> http://www.apple.com/qtactivex/qtplugin.cab[QuickTime Object] ->
{17492023-C23A-453E-A040-C7C580BBF700}[HKEY_LOCAL_MACHINE] -> http://go.microsoft.com/fwlink/?linkid=39204[Windows Genuine Advantage Validation Tool] ->
{1EF9F042-C2EB-4293-8213-474CAEEF531D}[HKEY_LOCAL_MACHINE] -> http://www.trendsecure.com/framework/contr...vex/TmHcmsX.CAB[TmHcmsX Control] ->
{215B8138-A3CF-44C5-803F-8226143CFC0A}[HKEY_LOCAL_MACHINE] -> http://housecall65.trendmicro.com/housecal...ivex/hcImpl.cab[Trend Micro ActiveX Scan Agent 6.6] ->
{33363249-0000-0010-8000-00AA00389B71}[HKEY_LOCAL_MACHINE] -> http://codecs.microsoft.com/codecs/i386/i263_32.cab[Reg Error: Key does not exist or could not be opened.] ->
{33564D57-9980-0010-8000-00AA00389B71}[HKEY_LOCAL_MACHINE] -> http://codecs.microsoft.com/codecs/i386/wmv9dmo.cab[Reg Error: Key does not exist or could not be opened.] ->
{41F17733-B041-4099-A042-B518BB6A408C}[HKEY_LOCAL_MACHINE] -> http://a1540.g.akamai.net/7/1540/52/200207...meInstaller.exe[Reg Error: Key does not exist or could not be opened.] ->
{5D86DDB5-BDF9-441B-9E9E-D4730F4EE499}[HKEY_LOCAL_MACHINE] -> http://download.bitdefender.com/resources/scan8/oscan8.cab[BDSCANONLINE Control] ->
{6414512B-B978-451D-A0D8-FCFDF33E833C}[HKEY_LOCAL_MACHINE] -> http://update.microsoft.com/microsoftupdat...b?1177173261147[WUWebControl Class] ->
{6E32070A-766D-4EE6-879C-DC1FA91D2FC3}[HKEY_LOCAL_MACHINE] -> http://www.update.microsoft.com/microsoftu...b?1182507576623[MUWebControl Class] ->
{82202BE7-C56A-487E-9E55-D84BDC1A5776}[HKEY_LOCAL_MACHINE] -> http://install.anark.com/client/version1/w...en/AMClient.cab[Reg Error: Key does not exist or could not be opened.] ->
{8AD9C840-044E-11D1-B3E9-00805F499D93}[HKEY_LOCAL_MACHINE] -> http://java.sun.com/update/1.6.0/jinstall-...indows-i586.cab[Java Plug-in 1.6.0_01] ->
{9A9307A0-7DA4-4DAF-B042-5009F29E09E1}[HKEY_LOCAL_MACHINE] -> http://acs.pandasoftware.com/activescan/as5free/asinst.cab[ActiveScan Installer Class] ->
{A17E30C4-A9BA-11D4-8673-60DB54C10000}[HKEY_LOCAL_MACHINE] -> http://us.dl1.yimg.com/download.yahoo.com/.../ymmapi_416.dll[YahooYMailTo Class] ->
{CAFEEFAC-0016-0000-0001-ABCDEFFEDCBA}[HKEY_LOCAL_MACHINE] -> http://java.sun.com/update/1.6.0/jinstall-...indows-i586.cab[Java Plug-in 1.6.0_01] ->
{CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA}[HKEY_LOCAL_MACHINE] -> http://java.sun.com/update/1.6.0/jinstall-...indows-i586.cab[Java Plug-in 1.6.0_01] ->
{CEBC955E-58AF-11D2-A30A-00A0C903492B}[HKEY_LOCAL_MACHINE] -> http://windowsupdate.microsoft.com/R1086/V...en/actsetup.cab[CV3 Class] ->
{D27CDB6E-AE6D-11CF-96B8-444553540000}[HKEY_LOCAL_MACHINE] -> http://fpdownload.macromedia.com/get/flash...ent/swflash.cab[Shockwave Flash Object] ->
DirectAnimation Java Classes[HKEY_LOCAL_MACHINE] -> file://C:\WINDOWS\Java\classes\dajava.cab[Reg Error: Key does not exist or could not be opened.] ->
Microsoft XML Parser for Java[HKEY_LOCAL_MACHINE] -> file://C:\WINDOWS\Java\classes\xmldso.cab[Reg Error: Key does not exist or could not be opened.] ->
Yahoo! Chat[HKEY_LOCAL_MACHINE] -> http://us.chat1.yimg.com/us.yimg.com/i/cha...t/c381/chat.cab[Reg Error: Key does not exist or could not be opened.] ->


[Registry - Additional Scans - Non-Microsoft Only]
< BotCheck > -> ->
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Ole\ -> ->
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Ole\\DefaultLaunchPermission -> (binary data) ->
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Ole\\EnableDCOM -> Y ->
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Ole\NONREDIST\ -> ->
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Ole\NONREDIST\\System.EnterpriseServices.Thunk.dll -> ->
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\ -> ->
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\\FirewallDisableNotify -> 0 ->
Reg Error: Key HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows\WindowsUpdate\ not found. -> ->
HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\WindowsFirewall\DomainProfile\ -> ->
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Lsa\ -> ->
*Authentication Packages* -> HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Lsa\\Authentication Packages ->
msv1_0 -> %System32%\msv1_0.dll -> Microsoft Corporation [Ver = 5.1.2600.1106 (xpsp1.020828-1920) | Size = 108544 bytes | Modified Date = 2002-08-29 12:00:00 | Attr = ]
C:\WINDOWS\System32\hgdab -> %System32%\hgdab.exe -> [Ver = | Size = 348160 bytes | Modified Date = 2008-01-21 22:23:28 | Attr = ]
*MultiFile Done* -> ->
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Lsa\\Bounds -> (binary data) ->
*Security Packages* -> HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Lsa\\Security Packages ->
kerberos -> %System32%\kerberos.dll -> Microsoft Corporation [Ver = 5.1.2600.1701 (xpsp2.050614-1532) | Size = 285184 bytes | Modified Date = 2005-06-15 13:50:24 | Attr = ]
msv1_0 -> %System32%\msv1_0.dll -> Microsoft Corporation [Ver = 5.1.2600.1106 (xpsp1.020828-1920) | Size = 108544 bytes | Modified Date = 2002-08-29 12:00:00 | Attr = ]
schannel -> %System32%\schannel.dll -> Microsoft Corporation [Ver = 5.1.2600.1347 (xpsp2.040109-1800) | Size = 136704 bytes | Modified Date = 2004-03-29 21:48:36 | Attr = ]
wdigest -> %System32%\wdigest.dll -> Microsoft Corporation [Ver = 5.1.2600.0 (xpclient.010817-1148) | Size = 46592 bytes | Modified Date = 2002-08-29 12:00:00 | Attr = ]
*MultiFile Done* -> ->
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Lsa\\LsaPid -> 268 ->
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Lsa\\SecureBoot -> 1 ->
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Lsa\\auditbaseobjects -> 0 ->
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Lsa\\crashonauditfail -> 0 ->
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Lsa\\disabledomaincreds -> 0 ->
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Lsa\\everyoneincludesanonymous -> 0 ->
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Lsa\\fipsalgorithmpolicy -> 0 ->
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Lsa\\forceguest -> 1 ->
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Lsa\\fullprivilegeauditing -> (binary data) ->
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Lsa\\limitblankpassworduse -> 1 ->
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Lsa\\lmcompatibilitylevel -> 0 ->
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Lsa\\nodefaultadminowner -> 1 ->
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Lsa\\nolmhash -> 0 ->
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Lsa\\restrictanonymous -> 0 ->
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Lsa\\restrictanonymoussam -> 1 ->
*Notification Packages* -> HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Lsa\\Notification Packages ->
scecli -> %System32%\scecli.dll -> Microsoft Corporation [Ver = 5.1.2600.1106 (xpsp1.020828-1920) | Size = 174592 bytes | Modified Date = 2002-08-29 12:00:00 | Attr = ]
scecli -> %System32%\scecli.dll -> Microsoft Corporation [Ver = 5.1.2600.1106 (xpsp1.020828-1920) | Size = 174592 bytes | Modified Date = 2002-08-29 12:00:00 | Attr = ]
scecli -> %System32%\scecli.dll -> Microsoft Corporation [Ver = 5.1.2600.1106 (xpsp1.020828-1920) | Size = 174592 bytes | Modified Date = 2002-08-29 12:00:00 | Attr = ]
scecli -> %System32%\scecli.dll -> Microsoft Corporation [Ver = 5.1.2600.1106 (xpsp1.020828-1920) | Size = 174592 bytes | Modified Date = 2002-08-29 12:00:00 | Attr = ]
scecli -> %System32%\scecli.dll -> Microsoft Corporation [Ver = 5.1.2600.1106 (xpsp1.020828-1920) | Size = 174592 bytes | Modified Date = 2002-08-29 12:00:00 | Attr = ]
*MultiFile Done* -> ->
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Lsa\\enabledcom -> y ->
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Lsa\AccessProviders\ -> ->
*ProviderOrder* -> HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Lsa\AccessProviders\\ProviderOrder ->
Windows NT Access Provider -> -> File not found
*MultiFile Done* -> ->
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Lsa\AccessProviders\Windows NT Access Provider\ -> ->
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Lsa\AccessProviders\Windows NT Access Provider\\ProviderPath -> C:\WINDOWS\system32\ntmarta.dll [%SystemRoot%\system32\ntmarta.dll] -> Microsoft Corporation [Ver = 5.1.2600.1106 (xpsp1.020828-1920) | Size = 112128 bytes | Modified Date = 2002-08-29 12:00:00 | Attr = ]
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Lsa\Data\ -> ->
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Lsa\Data\\Pattern -> (binary data) ->
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Lsa\GBG\ -> ->
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Lsa\GBG\\GrafBlumGroup -> (binary data) ->
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Lsa\JD\ -> ->
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Lsa\JD\\Lookup -> (binary data) ->
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Lsa\Kerberos\ -> ->
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Lsa\Kerberos\Domains\ -> ->
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Lsa\Kerberos\SidCache\ -> ->
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Lsa\msv1_0\ -> ->
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Lsa\msv1_0\\ntlmminclientsec -> 0 ->
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Lsa\msv1_0\\ntlmminserversec -> 0 ->
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Lsa\Skew1\ -> ->
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Lsa\Skew1\\SkewMatrix -> (binary data) ->
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Lsa\SSO\ -> ->
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Lsa\SSO\Passport1.4\ -> ->
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Lsa\SSO\Passport1.4\\SSOURL -> http:\www.passport.com [http://www.passport.com] -> File not found
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Lsa\SspiCache\ -> ->
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Lsa\SspiCache\\Time -> (binary data) ->
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Lsa\SspiCache\digest.dll\ -> ->
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Lsa\SspiCache\digest.dll\\Name -> Digest ->
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Lsa\SspiCache\digest.dll\\Comment -> Digest SSPI Authentication Package ->
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Lsa\SspiCache\digest.dll\\Capabilities -> 16464 ->
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Lsa\SspiCache\digest.dll\\RpcId -> 65535 ->
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Lsa\SspiCache\digest.dll\\Version -> 1 ->
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Lsa\SspiCache\digest.dll\\TokenSize -> 65535 ->
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Lsa\SspiCache\digest.dll\\Time -> (binary data) ->
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Lsa\SspiCache\digest.dll\\Type -> 49 ->
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Lsa\SspiCache\msapsspc.dll\ -> ->
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Lsa\SspiCache\msapsspc.dll\\Name -> DPA ->
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Lsa\SspiCache\msapsspc.dll\\Comment -> DPA Security Package ->
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Lsa\SspiCache\msapsspc.dll\\Capabilities -> 55 ->
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Lsa\SspiCache\msapsspc.dll\\RpcId -> 17 ->
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Lsa\SspiCache\msapsspc.dll\\Version -> 1 ->
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Lsa\SspiCache\msapsspc.dll\\TokenSize -> 768 ->
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Lsa\SspiCache\msapsspc.dll\\Time -> (binary data) ->
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Lsa\SspiCache\msapsspc.dll\\Type -> 49 ->
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Lsa\SspiCache\msnsspc.dll\ -> ->
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Lsa\SspiCache\msnsspc.dll\\Name -> MSN ->
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Lsa\SspiCache\msnsspc.dll\\Comment -> MSN Security Package ->
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Lsa\SspiCache\msnsspc.dll\\Capabilities -> 55 ->
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Lsa\SspiCache\msnsspc.dll\\RpcId -> 18 ->
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Lsa\SspiCache\msnsspc.dll\\Version -> 1 ->
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Lsa\SspiCache\msnsspc.dll\\TokenSize -> 768 ->
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Lsa\SspiCache\msnsspc.dll\\Time -> (binary data) ->
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Lsa\SspiCache\msnsspc.dll\\Type -> 49 ->
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\ -> ->
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\\DependOnGroup -> ->
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\\DependOnService -> RasMan; ->
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\\Description -> Provides network address translation, addressing, and name resolution services for all computers on your home network through a dial-up connection. ->
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\\DisplayName -> Internet Connection Sharing ->
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\\ErrorControl -> 1 ->
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\\ImagePath -> C:\WINDOWS\System32\svchost.exe [%SystemRoot%\System32\svchost.exe -k netsvcs] -> Microsoft Corporation [Ver = 5.1.2600.0 (xpclient.010817-1148) | Size = 12800 bytes | Modified Date = 2002-08-29 12:00:00 | Attr = ]
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\\ObjectName -> LocalSystem ->
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\\Start -> 2 ->
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\\Type -> 32 ->
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Enum\ -> ->
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Enum\\0 -> Root\LEGACY_SHAREDACCESS\0000 ->
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Enum\\Count -> 1 ->
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Enum\\NextInstance -> 1 ->
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Epoch\ -> ->
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Epoch\\Epoch -> 11477 ->
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\ -> ->
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\\ServiceDll -> C:\WINDOWS\System32\ipnathlp.dll [%SystemRoot%\System32\ipnathlp.dll] -> Microsoft Corporation [Ver = 5.1.2600.1364 (xpsp2.040109-1800) | Size = 439808 bytes | Modified Date = 2004-03-29 21:48:36 | Attr = ]
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\ -> ->
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile\ -> ->
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile\AuthorizedApplications\ -> ->
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile\AuthorizedApplications\List\ -> ->
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\ -> ->
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\AuthorizedApplications\ -> ->
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\AuthorizedApplications\List\ -> ->
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\AuthorizedApplications\List\\C:\WINDOWS\System32\jusybwlu.exe -> C:\WINDOWS\System32\jus ->
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\GloballyOpenPorts\ -> ->
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\GloballyOpenPorts\List\ -> ->
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\GloballyOpenPorts\List\\139:TCP -> 139:TCP:LocalSubNet:Enabled:@xpsp2res.dll [139:TCP:LocalSubNet:Enabled:@xpsp2res.dll,-22004] -> File not found
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\GloballyOpenPorts\List\\445:TCP -> 445:TCP:LocalSubNet:Enabled:@xpsp2res.dll [445:TCP:LocalSubNet:Enabled:@xpsp2res.dll,-22005] -> File not found
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\GloballyOpenPorts\List\\137:UDP -> 137:UDP:LocalSubNet:Enabled:@xpsp2res.dll [137:UDP:LocalSubNet:Enabled:@xpsp2res.dll,-22001] -> File not found
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\GloballyOpenPorts\List\\138:UDP -> 138:UDP:LocalSubNet:Enabled:@xpsp2res.dll [138:UDP:LocalSubNet:Enabled:@xpsp2res.dll,-22002] -> File not found
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\GloballyOpenPorts\List\\1900:UDP -> 1900:UDP:LocalSubNet:Enabled:@xpsp2res.dll [1900:UDP:LocalSubNet:Enabled:@xpsp2res.dll,-22007] -> File not found
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\GloballyOpenPorts\List\\2869:TCP -> 2869:TCP:LocalSubNet:Enabled:@xpsp2res.dll [2869:TCP:LocalSubNet:Enabled:@xpsp2res.dll,-22008] -> File not found
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Setup\ -> ->
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Setup\\ServiceUpgrade -> 1 ->
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Setup\InterfacesUnfirewalledAtUpdate\ -> ->
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Setup\InterfacesUnfirewalledAtUpdate\\All -> 1 ->
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\wuauserv\ -> ->
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\wuauserv\\Type -> 32 ->
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\wuauserv\\Start -> 2 ->
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\wuauserv\\ErrorControl -> 1 ->
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\wuauserv\\ImagePath -> C:\WINDOWS\system32\svchost.exe [%systemroot%\system32\svchost.exe -k netsvcs] -> Microsoft Corporation [Ver = 5.1.2600.0 (xpclient.010817-1148) | Size = 12800 bytes | Modified Date = 2002-08-29 12:00:00 | Attr = ]
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\wuauserv\\DisplayName -> Automatic Updates ->
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\wuauserv\\ObjectName -> LocalSystem ->
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\wuauserv\\Description -> Enables the download and installation of Windows updates. If this service is disabled, this computer will not be able to use the Automatic Updates feature or the Windows Update Web site. ->
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\wuauserv\Parameters\ -> ->
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\wuauserv\Parameters\\ServiceDll -> C:\WINDOWS\System32\wuauserv.dll [C:\WINDOWS\System32\wuauserv.dll] -> Microsoft Corporation [Ver = 5.4.3630.1106 (xpsp1.020828-1920) | Size = 9216 bytes | Modified Date = 2002-08-29 12:00:00 | Attr = ]
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\wuauserv\Security\ -> ->
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\wuauserv\Security\\Security -> (binary data) ->
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\wuauserv\Enum\ -> ->
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\wuauserv\Enum\\0 -> Root\LEGACY_WUAUSERV\0000 ->
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\wuauserv\Enum\\Count -> 1 ->
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\wuauserv\Enum\\NextInstance -> 1 ->
Reg Error: Key HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\RemoteRegistry\ not found. -> ->
Reg Error: Key HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\TlntSvr\ not found. -> ->
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Hardware Profiles\Current\Software\Microsoft\windows\CurrentVersion\Internet Settings\ -> ->
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Hardware Profiles\Current\Software\Microsoft\windows\CurrentVersion\Internet Settings\\ProxyEnable -> 0 ->
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Hardware Profiles\Current\Software\Microsoft\windows\CurrentVersion\Internet Settings\\EnableAutodial -> (binary data) ->

#14 bdfinally

bdfinally
  • Topic Starter

  • Members
  • 34 posts
  • OFFLINE
  •  
  • Local time:10:55 PM

Posted 22 January 2008 - 07:26 AM

next section

[Files/Folders - Created Within 30 days]
pos2BB.tmp -> %SystemDrive%\pos2BB.tmp -> [Ver = | Size = 11033 bytes | Created Date = 2008-01-21 19:42:47 | Attr = ]
pos300.tmp -> %SystemDrive%\pos300.tmp -> [Ver = | Size = 10033 bytes | Created Date = 2008-01-21 19:42:51 | Attr = ]
pos301.tmp -> %SystemDrive%\pos301.tmp -> [Ver = | Size = 7033 bytes | Created Date = 2008-01-21 19:42:51 | Attr = ]
pos2BC.tmp -> %SystemDrive%\pos2BC.tmp -> [Ver = | Size = 6033 bytes | Created Date = 2008-01-21 19:42:47 | Attr = ]
pos2BD.tmp -> %SystemDrive%\pos2BD.tmp -> [Ver = | Size = 9033 bytes | Created Date = 2008-01-21 19:42:47 | Attr = ]
pos2BE.tmp -> %SystemDrive%\pos2BE.tmp -> [Ver = | Size = 14033 bytes | Created Date = 2008-01-21 19:42:47 | Attr = ]
pos302.tmp -> %SystemDrive%\pos302.tmp -> [Ver = | Size = 13033 bytes | Created Date = 2008-01-21 19:42:51 | Attr = ]
pos2BF.tmp -> %SystemDrive%\pos2BF.tmp -> [Ver = | Size = 11033 bytes | Created Date = 2008-01-21 19:42:47 | Attr = ]
n.bat -> %SystemDrive%\n.bat -> [Ver = | Size = 134 bytes | Created Date = 2008-01-03 00:17:50 | Attr = ]
pos2C0.tmp -> %SystemDrive%\pos2C0.tmp -> [Ver = | Size = 12033 bytes | Created Date = 2008-01-21 19:42:47 | Attr = ]
pos2C1.tmp -> %SystemDrive%\pos2C1.tmp -> [Ver = | Size = 14033 bytes | Created Date = 2008-01-21 19:42:47 | Attr = ]
pos2C2.tmp -> %SystemDrive%\pos2C2.tmp -> [Ver = | Size = 5033 bytes | Created Date = 2008-01-21 19:42:47 | Attr = ]
pos2C3.tmp -> %SystemDrive%\pos2C3.tmp -> [Ver = | Size = 13033 bytes | Created Date = 2008-01-21 19:42:47 | Attr = ]
pos2C4.tmp -> %SystemDrive%\pos2C4.tmp -> [Ver = | Size = 10033 bytes | Created Date = 2008-01-21 19:42:47 | Attr = ]
pos2C5.tmp -> %SystemDrive%\pos2C5.tmp -> [Ver = | Size = 12033 bytes | Created Date = 2008-01-21 19:42:47 | Attr = ]
pos2C6.tmp -> %SystemDrive%\pos2C6.tmp -> [Ver = | Size = 13033 bytes | Created Date = 2008-01-21 19:42:48 | Attr = ]
pos2C7.tmp -> %SystemDrive%\pos2C7.tmp -> [Ver = | Size = 6033 bytes | Created Date = 2008-01-21 19:42:48 | Attr = ]
pos2C8.tmp -> %SystemDrive%\pos2C8.tmp -> [Ver = | Size = 14033 bytes | Created Date = 2008-01-21 19:42:48 | Attr = ]
pos2C9.tmp -> %SystemDrive%\pos2C9.tmp -> [Ver = | Size = 9033 bytes | Created Date = 2008-01-21 19:42:48 | Attr = ]
pos2CA.tmp -> %SystemDrive%\pos2CA.tmp -> [Ver = | Size = 13033 bytes | Created Date = 2008-01-21 19:42:48 | Attr = ]
pos2CB.tmp -> %SystemDrive%\pos2CB.tmp -> [Ver = | Size = 12033 bytes | Created Date = 2008-01-21 19:42:48 | Attr = ]
pos2CC.tmp -> %SystemDrive%\pos2CC.tmp -> [Ver = | Size = 12033 bytes | Created Date = 2008-01-21 19:42:48 | Attr = ]
pos2CD.tmp -> %SystemDrive%\pos2CD.tmp -> [Ver = | Size = 5033 bytes | Created Date = 2008-01-21 19:42:48 | Attr = ]
pos2CE.tmp -> %SystemDrive%\pos2CE.tmp -> [Ver = | Size = 5033 bytes | Created Date = 2008-01-21 19:42:48 | Attr = ]
pos2CF.tmp -> %SystemDrive%\pos2CF.tmp -> [Ver = | Size = 11033 bytes | Created Date = 2008-01-21 19:42:48 | Attr = ]
pos2D0.tmp -> %SystemDrive%\pos2D0.tmp -> [Ver = | Size = 12033 bytes | Created Date = 2008-01-21 19:42:48 | Attr = ]
pos2D1.tmp -> %SystemDrive%\pos2D1.tmp -> [Ver = | Size = 10033 bytes | Created Date = 2008-01-21 19:42:48 | Attr = ]
pos2D2.tmp -> %SystemDrive%\pos2D2.tmp -> [Ver = | Size = 9033 bytes | Created Date = 2008-01-21 19:42:48 | Attr = ]
pos2D3.tmp -> %SystemDrive%\pos2D3.tmp -> [Ver = | Size = 7033 bytes | Created Date = 2008-01-21 19:42:48 | Attr = ]
pos2D4.tmp -> %SystemDrive%\pos2D4.tmp -> [Ver = | Size = 9033 bytes | Created Date = 2008-01-21 19:42:48 | Attr = ]
pos2D5.tmp -> %SystemDrive%\pos2D5.tmp -> [Ver = | Size = 13033 bytes | Created Date = 2008-01-21 19:42:48 | Attr = ]
pos2D6.tmp -> %SystemDrive%\pos2D6.tmp -> [Ver = | Size = 12033 bytes | Created Date = 2008-01-21 19:42:48 | Attr = ]
pos2D7.tmp -> %SystemDrive%\pos2D7.tmp -> [Ver = | Size = 12033 bytes | Created Date = 2008-01-21 19:42:49 | Attr = ]
pos2D8.tmp -> %SystemDrive%\pos2D8.tmp -> [Ver = | Size = 5033 bytes | Created Date = 2008-01-21 19:42:49 | Attr = ]
pos2D9.tmp -> %SystemDrive%\pos2D9.tmp -> [Ver = | Size = 11033 bytes | Created Date = 2008-01-21 19:42:49 | Attr = ]
pos2DA.tmp -> %SystemDrive%\pos2DA.tmp -> [Ver = | Size = 14033 bytes | Created Date = 2008-01-21 19:42:49 | Attr = ]
pos2DB.tmp -> %SystemDrive%\pos2DB.tmp -> [Ver = | Size = 13033 bytes | Created Date = 2008-01-21 19:42:49 | Attr = ]
pos2DC.tmp -> %SystemDrive%\pos2DC.tmp -> [Ver = | Size = 11033 bytes | Created Date = 2008-01-21 19:42:49 | Attr = ]
pos2DD.tmp -> %SystemDrive%\pos2DD.tmp -> [Ver = | Size = 8033 bytes | Created Date = 2008-01-21 19:42:49 | Attr = ]
pos2DE.tmp -> %SystemDrive%\pos2DE.tmp -> [Ver = | Size = 8033 bytes | Created Date = 2008-01-21 19:42:49 | Attr = ]
pos2DF.tmp -> %SystemDrive%\pos2DF.tmp -> [Ver = | Size = 10033 bytes | Created Date = 2008-01-21 19:42:49 | Attr = ]
pos2E0.tmp -> %SystemDrive%\pos2E0.tmp -> [Ver = | Size = 13033 bytes | Created Date = 2008-01-21 19:42:49 | Attr = ]
pos2E1.tmp -> %SystemDrive%\pos2E1.tmp -> [Ver = | Size = 12033 bytes | Created Date = 2008-01-21 19:42:49 | Attr = ]
pos2E2.tmp -> %SystemDrive%\pos2E2.tmp -> [Ver = | Size = 13033 bytes | Created Date = 2008-01-21 19:42:49 | Attr = ]
pos2E3.tmp -> %SystemDrive%\pos2E3.tmp -> [Ver = | Size = 12033 bytes | Created Date = 2008-01-21 19:42:49 | Attr = ]
pos2E4.tmp -> %SystemDrive%\pos2E4.tmp -> [Ver = | Size = 5033 bytes | Created Date = 2008-01-21 19:42:49 | Attr = ]
pos2E5.tmp -> %SystemDrive%\pos2E5.tmp -> [Ver = | Size = 5033 bytes | Created Date = 2008-01-21 19:42:49 | Attr = ]
pos2E6.tmp -> %SystemDrive%\pos2E6.tmp -> [Ver = | Size = 13033 bytes | Created Date = 2008-01-21 19:42:49 | Attr = ]
pos2E7.tmp -> %SystemDrive%\pos2E7.tmp -> [Ver = | Size = 9033 bytes | Created Date = 2008-01-21 19:42:49 | Attr = ]
pos2E8.tmp -> %SystemDrive%\pos2E8.tmp -> [Ver = | Size = 11033 bytes | Created Date = 2008-01-21 19:42:50 | Attr = ]
pos2E9.tmp -> %SystemDrive%\pos2E9.tmp -> [Ver = | Size = 7033 bytes | Created Date = 2008-01-21 19:42:50 | Attr = ]
pos2EA.tmp -> %SystemDrive%\pos2EA.tmp -> [Ver = | Size = 7033 bytes | Created Date = 2008-01-21 19:42:50 | Attr = ]
pos2EB.tmp -> %SystemDrive%\pos2EB.tmp -> [Ver = | Size = 7033 bytes | Created Date = 2008-01-21 19:42:50 | Attr = ]
pos2EC.tmp -> %SystemDrive%\pos2EC.tmp -> [Ver = | Size = 10033 bytes | Created Date = 2008-01-21 19:42:50 | Attr = ]
pos2ED.tmp -> %SystemDrive%\pos2ED.tmp -> [Ver = | Size = 13033 bytes | Created Date = 2008-01-21 19:42:50 | Attr = ]
pos2EE.tmp -> %SystemDrive%\pos2EE.tmp -> [Ver = | Size = 6033 bytes | Created Date = 2008-01-21 19:42:50 | Attr = ]
pos2EF.tmp -> %SystemDrive%\pos2EF.tmp -> [Ver = | Size = 10033 bytes | Created Date = 2008-01-21 19:42:50 | Attr = ]
pos2F0.tmp -> %SystemDrive%\pos2F0.tmp -> [Ver = | Size = 9033 bytes | Created Date = 2008-01-21 19:42:50 | Attr = ]
pos2F1.tmp -> %SystemDrive%\pos2F1.tmp -> [Ver = | Size = 10033 bytes | Created Date = 2008-01-21 19:42:50 | Attr = ]
pos2F2.tmp -> %SystemDrive%\pos2F2.tmp -> [Ver = | Size = 10033 bytes | Created Date = 2008-01-21 19:42:50 | Attr = ]
pos2F3.tmp -> %SystemDrive%\pos2F3.tmp -> [Ver = | Size = 12033 bytes | Created Date = 2008-01-21 19:42:50 | Attr = ]
pos2F4.tmp -> %SystemDrive%\pos2F4.tmp -> [Ver = | Size = 11033 bytes | Created Date = 2008-01-21 19:42:50 | Attr = ]
pos2F5.tmp -> %SystemDrive%\pos2F5.tmp -> [Ver = | Size = 11033 bytes | Created Date = 2008-01-21 19:42:50 | Attr = ]
pos2F6.tmp -> %SystemDrive%\pos2F6.tmp -> [Ver = | Size = 7033 bytes | Created Date = 2008-01-21 19:42:50 | Attr = ]
pos2F7.tmp -> %SystemDrive%\pos2F7.tmp -> [Ver = | Size = 11033 bytes | Created Date = 2008-01-21 19:42:50 | Attr = ]
pos2F8.tmp -> %SystemDrive%\pos2F8.tmp -> [Ver = | Size = 10033 bytes | Created Date = 2008-01-21 19:42:50 | Attr = ]
pos2F9.tmp -> %SystemDrive%\pos2F9.tmp -> [Ver = | Size = 13033 bytes | Created Date = 2008-01-21 19:42:51 | Attr = ]
pos2FA.tmp -> %SystemDrive%\pos2FA.tmp -> [Ver = | Size = 12033 bytes | Created Date = 2008-01-21 19:42:51 | Attr = ]
pos2FB.tmp -> %SystemDrive%\pos2FB.tmp -> [Ver = | Size = 11033 bytes | Created Date = 2008-01-21 19:42:51 | Attr = ]
pos2FC.tmp -> %SystemDrive%\pos2FC.tmp -> [Ver = | Size = 8033 bytes | Created Date = 2008-01-21 19:42:51 | Attr = ]
pos2FD.tmp -> %SystemDrive%\pos2FD.tmp -> [Ver = | Size = 8033 bytes | Created Date = 2008-01-21 19:42:51 | Attr = ]
pos2FE.tmp -> %SystemDrive%\pos2FE.tmp -> [Ver = | Size = 12033 bytes | Created Date = 2008-01-21 19:42:51 | Attr = ]
pos2FF.tmp -> %SystemDrive%\pos2FF.tmp -> [Ver = | Size = 7033 bytes | Created Date = 2008-01-21 19:42:51 | Attr = ]
pos303.tmp -> %SystemDrive%\pos303.tmp -> [Ver = | Size = 11033 bytes | Created Date = 2008-01-21 19:42:51 | Attr = ]
pos304.tmp -> %SystemDrive%\pos304.tmp -> [Ver = | Size = 5033 bytes | Created Date = 2008-01-21 19:42:51 | Attr = ]
pos305.tmp -> %SystemDrive%\pos305.tmp -> [Ver = | Size = 6033 bytes | Created Date = 2008-01-21 19:42:51 | Attr = ]
pos306.tmp -> %SystemDrive%\pos306.tmp -> [Ver = | Size = 9033 bytes | Created Date = 2008-01-21 19:42:51 | Attr = ]
pos307.tmp -> %SystemDrive%\pos307.tmp -> [Ver = | Size = 11033 bytes | Created Date = 2008-01-21 19:42:51 | Attr = ]
pos308.tmp -> %SystemDrive%\pos308.tmp -> [Ver = | Size = 9033 bytes | Created Date = 2008-01-21 19:42:51 | Attr = ]
pos309.tmp -> %SystemDrive%\pos309.tmp -> [Ver = | Size = 11033 bytes | Created Date = 2008-01-21 19:42:51 | Attr = ]
pos30A.tmp -> %SystemDrive%\pos30A.tmp -> [Ver = | Size = 10033 bytes | Created Date = 2008-01-21 19:42:52 | Attr = ]
pos30B.tmp -> %SystemDrive%\pos30B.tmp -> [Ver = | Size = 14033 bytes | Created Date = 2008-01-21 19:42:52 | Attr = ]
pos30C.tmp -> %SystemDrive%\pos30C.tmp -> [Ver = | Size = 5033 bytes | Created Date = 2008-01-21 19:42:52 | Attr = ]
pos30D.tmp -> %SystemDrive%\pos30D.tmp -> [Ver = | Size = 6033 bytes | Created Date = 2008-01-21 19:42:52 | Attr = ]
pos30E.tmp -> %SystemDrive%\pos30E.tmp -> [Ver = | Size = 14033 bytes | Created Date = 2008-01-21 19:42:52 | Attr = ]
pos310.tmp -> %SystemDrive%\pos310.tmp -> [Ver = | Size = 13033 bytes | Created Date = 2008-01-21 19:42:52 | Attr = ]
pos30F.tmp -> %SystemDrive%\pos30F.tmp -> [Ver = | Size = 8033 bytes | Created Date = 2008-01-21 19:42:52 | Attr = ]
pos311.tmp -> %SystemDrive%\pos311.tmp -> [Ver = | Size = 7033 bytes | Created Date = 2008-01-21 19:42:52 | Attr = ]
pos312.tmp -> %SystemDrive%\pos312.tmp -> [Ver = | Size = 6033 bytes | Created Date = 2008-01-21 19:42:52 | Attr = ]
pos313.tmp -> %SystemDrive%\pos313.tmp -> [Ver = | Size = 13033 bytes | Created Date = 2008-01-21 19:42:52 | Attr = ]
pos314.tmp -> %SystemDrive%\pos314.tmp -> [Ver = | Size = 8033 bytes | Created Date = 2008-01-21 19:42:52 | Attr = ]
pos315.tmp -> %SystemDrive%\pos315.tmp -> [Ver = | Size = 11033 bytes | Created Date = 2008-01-21 19:42:52 | Attr = ]
pos316.tmp -> %SystemDrive%\pos316.tmp -> [Ver = | Size = 9033 bytes | Created Date = 2008-01-21 19:42:52 | Attr = ]
pos317.tmp -> %SystemDrive%\pos317.tmp -> [Ver = | Size = 8033 bytes | Created Date = 2008-01-21 19:42:52 | Attr = ]
pos318.tmp -> %SystemDrive%\pos318.tmp -> [Ver = | Size = 5033 bytes | Created Date = 2008-01-21 19:42:52 | Attr = ]
pos319.tmp -> %SystemDrive%\pos319.tmp -> [Ver = | Size = 14033 bytes | Created Date = 2008-01-21 19:42:52 | Attr = ]
pos31A.tmp -> %SystemDrive%\pos31A.tmp -> [Ver = | Size = 9033 bytes | Created Date = 2008-01-21 19:42:53 | Attr = ]
pos31B.tmp -> %SystemDrive%\pos31B.tmp -> [Ver = | Size = 6033 bytes | Created Date = 2008-01-21 19:42:53 | Attr = ]
pos31C.tmp -> %SystemDrive%\pos31C.tmp -> [Ver = | Size = 6033 bytes | Created Date = 2008-01-21 19:42:53 | Attr = ]
pos31D.tmp -> %SystemDrive%\pos31D.tmp -> [Ver = | Size = 10033 bytes | Created Date = 2008-01-21 19:42:53 | Attr = ]
pos31E.tmp -> %SystemDrive%\pos31E.tmp -> [Ver = | Size = 10033 bytes | Created Date = 2008-01-21 19:42:53 | Attr = ]
pos31F.tmp -> %SystemDrive%\pos31F.tmp -> [Ver = | Size = 7033 bytes | Created Date = 2008-01-21 19:42:53 | Attr = ]
pos320.tmp -> %SystemDrive%\pos320.tmp -> [Ver = | Size = 11033 bytes | Created Date = 2008-01-21 19:42:53 | Attr = ]
pos321.tmp -> %SystemDrive%\pos321.tmp -> [Ver = | Size = 14033 bytes | Created Date = 2008-01-21 19:42:53 | Attr = ]
pos322.tmp -> %SystemDrive%\pos322.tmp -> [Ver = | Size = 13033 bytes | Created Date = 2008-01-21 19:42:53 | Attr = ]
pos323.tmp -> %SystemDrive%\pos323.tmp -> [Ver = | Size = 13033 bytes | Created Date = 2008-01-21 19:42:53 | Attr = ]
pos324.tmp -> %SystemDrive%\pos324.tmp -> [Ver = | Size = 12033 bytes | Created Date = 2008-01-21 19:42:53 | Attr = ]
pos325.tmp -> %SystemDrive%\pos325.tmp -> [Ver = | Size = 9033 bytes | Created Date = 2008-01-21 19:42:53 | Attr = ]
pos326.tmp -> %SystemDrive%\pos326.tmp -> [Ver = | Size = 6033 bytes | Created Date = 2008-01-21 19:42:53 | Attr = ]
pos327.tmp -> %SystemDrive%\pos327.tmp -> [Ver = | Size = 11033 bytes | Created Date = 2008-01-21 19:42:53 | Attr = ]
pos328.tmp -> %SystemDrive%\pos328.tmp -> [Ver = | Size = 14033 bytes | Created Date = 2008-01-21 19:42:53 | Attr = ]
pos329.tmp -> %SystemDrive%\pos329.tmp -> [Ver = | Size = 12033 bytes | Created Date = 2008-01-21 19:42:53 | Attr = ]
pos32A.tmp -> %SystemDrive%\pos32A.tmp -> [Ver = | Size = 5033 bytes | Created Date = 2008-01-21 19:42:53 | Attr = ]
pos32B.tmp -> %SystemDrive%\pos32B.tmp -> [Ver = | Size = 9033 bytes | Created Date = 2008-01-21 19:42:54 | Attr = ]
pos32C.tmp -> %SystemDrive%\pos32C.tmp -> [Ver = | Size = 11033 bytes | Created Date = 2008-01-21 19:42:54 | Attr = ]
pos32D.tmp -> %SystemDrive%\pos32D.tmp -> [Ver = | Size = 5033 bytes | Created Date = 2008-01-21 19:42:54 | Attr = ]
pos32E.tmp -> %SystemDrive%\pos32E.tmp -> [Ver = | Size = 10033 bytes | Created Date = 2008-01-21 19:42:54 | Attr = ]
pos32F.tmp -> %SystemDrive%\pos32F.tmp -> [Ver = | Size = 8033 bytes | Created Date = 2008-01-21 19:42:54 | Attr = ]
pos330.tmp -> %SystemDrive%\pos330.tmp -> [Ver = | Size = 12033 bytes | Created Date = 2008-01-21 19:42:54 | Attr = ]
pos331.tmp -> %SystemDrive%\pos331.tmp -> [Ver = | Size = 6033 bytes | Created Date = 2008-01-21 19:42:54 | Attr = ]
pos332.tmp -> %SystemDrive%\pos332.tmp -> [Ver = | Size = 9033 bytes | Created Date = 2008-01-21 19:42:54 | Attr = ]
pos333.tmp -> %SystemDrive%\pos333.tmp -> [Ver = | Size = 10033 bytes | Created Date = 2008-01-21 19:42:54 | Attr = ]
pos334.tmp -> %SystemDrive%\pos334.tmp -> [Ver = | Size = 5033 bytes | Created Date = 2008-01-21 19:42:54 | Attr = ]
pos335.tmp -> %SystemDrive%\pos335.tmp -> [Ver = | Size = 9033 bytes | Created Date = 2008-01-21 19:42:54 | Attr = ]
pos535.tmp -> %SystemDrive%\pos535.tmp -> [Ver = | Size = 9033 bytes | Created Date = 2008-01-21 19:54:01 | Attr = ]
pos536.tmp -> %SystemDrive%\pos536.tmp -> [Ver = | Size = 7033 bytes | Created Date = 2008-01-21 19:54:01 | Attr = ]
pos537.tmp -> %SystemDrive%\pos537.tmp -> [Ver = | Size = 14033 bytes | Created Date = 2008-01-21 19:54:01 | Attr = ]
pos538.tmp -> %SystemDrive%\pos538.tmp -> [Ver = | Size = 13033 bytes | Created Date = 2008-01-21 19:54:01 | Attr = ]
pos539.tmp -> %SystemDrive%\pos539.tmp -> [Ver = | Size = 9033 bytes | Created Date = 2008-01-21 19:54:02 | Attr = ]
pos53A.tmp -> %SystemDrive%\pos53A.tmp -> [Ver = | Size = 8033 bytes | Created Date = 2008-01-21 19:54:02 | Attr = ]
pos53B.tmp -> %SystemDrive%\pos53B.tmp -> [Ver = | Size = 5033 bytes | Created Date = 2008-01-21 19:54:02 | Attr = ]
pos53C.tmp -> %SystemDrive%\pos53C.tmp -> [Ver = | Size = 12033 bytes | Created Date = 2008-01-21 19:54:02 | Attr = ]
pos53D.tmp -> %SystemDrive%\pos53D.tmp -> [Ver = | Size = 11033 bytes | Created Date = 2008-01-21 19:54:02 | Attr = ]
pos53E.tmp -> %SystemDrive%\pos53E.tmp -> [Ver = | Size = 8033 bytes | Created Date = 2008-01-21 19:54:02 | Attr = ]
pos540.tmp -> %SystemDrive%\pos540.tmp -> [Ver = | Size = 5033 bytes | Created Date = 2008-01-21 19:54:02 | Attr = ]
pos53F.tmp -> %SystemDrive%\pos53F.tmp -> [Ver = | Size = 11033 bytes | Created Date = 2008-01-21 19:54:02 | Attr = ]
pos541.tmp -> %SystemDrive%\pos541.tmp -> [Ver = | Size = 7033 bytes | Created Date = 2008-01-21 19:54:02 | Attr = ]
pos542.tmp -> %SystemDrive%\pos542.tmp -> [Ver = | Size = 14033 bytes | Created Date = 2008-01-21 19:54:02 | Attr = ]
pos543.tmp -> %SystemDrive%\pos543.tmp -> [Ver = | Size = 8033 bytes | Created Date = 2008-01-21 19:54:02 | Attr = ]
pos544.tmp -> %SystemDrive%\pos544.tmp -> [Ver = | Size = 7033 bytes | Created Date = 2008-01-21 19:54:02 | Attr = ]
pos545.tmp -> %SystemDrive%\pos545.tmp -> [Ver = | Size = 10033 bytes | Created Date = 2008-01-21 19:54:02 | Attr = ]
pos546.tmp -> %SystemDrive%\pos546.tmp -> [Ver = | Size = 14033 bytes | Created Date = 2008-01-21 19:54:02 | Attr = ]
pos547.tmp -> %SystemDrive%\pos547.tmp -> [Ver = | Size = 5033 bytes | Created Date = 2008-01-21 19:54:02 | Attr = ]
pos548.tmp -> %SystemDrive%\pos548.tmp -> [Ver = | Size = 6033 bytes | Created Date = 2008-01-21 19:54:02 | Attr = ]
pos549.tmp -> %SystemDrive%\pos549.tmp -> [Ver = | Size = 14033 bytes | Created Date = 2008-01-21 19:54:02 | Attr = ]
pos54A.tmp -> %SystemDrive%\pos54A.tmp -> [Ver = | Size = 11033 bytes | Created Date = 2008-01-21 19:54:02 | Attr = ]
pos54B.tmp -> %SystemDrive%\pos54B.tmp -> [Ver = | Size = 9033 bytes | Created Date = 2008-01-21 19:54:02 | Attr = ]
pos54C.tmp -> %SystemDrive%\pos54C.tmp -> [Ver = | Size = 7033 bytes | Created Date = 2008-01-21 19:54:02 | Attr = ]
pos54D.tmp -> %SystemDrive%\pos54D.tmp -> [Ver = | Size = 10033 bytes | Created Date = 2008-01-21 19:54:02 | Attr = ]
pos54E.tmp -> %SystemDrive%\pos54E.tmp -> [Ver = | Size = 7033 bytes | Created Date = 2008-01-21 19:54:02 | Attr = ]
pos54F.tmp -> %SystemDrive%\pos54F.tmp -> [Ver = | Size = 5033 bytes | Created Date = 2008-01-21 19:54:02 | Attr = ]
pos550.tmp -> %SystemDrive%\pos550.tmp -> [Ver = | Size = 12033 bytes | Created Date = 2008-01-21 19:54:03 | Attr = ]
pos551.tmp -> %SystemDrive%\pos551.tmp -> [Ver = | Size = 7033 bytes | Created Date = 2008-01-21 19:54:03 | Attr = ]
pos552.tmp -> %SystemDrive%\pos552.tmp -> [Ver = | Size = 14033 bytes | Created Date = 2008-01-21 19:54:03 | Attr = ]
pos553.tmp -> %SystemDrive%\pos553.tmp -> [Ver = | Size = 10033 bytes | Created Date = 2008-01-21 19:54:03 | Attr = ]
pos554.tmp -> %SystemDrive%\pos554.tmp -> [Ver = | Size = 13033 bytes | Created Date = 2008-01-21 19:54:03 | Attr = ]
pos555.tmp -> %SystemDrive%\pos555.tmp -> [Ver = | Size = 6033 bytes | Created Date = 2008-01-21 19:54:03 | Attr = ]
pos556.tmp -> %SystemDrive%\pos556.tmp -> [Ver = | Size = 8033 bytes | Created Date = 2008-01-21 19:54:03 | Attr = ]
pos557.tmp -> %SystemDrive%\pos557.tmp -> [Ver = | Size = 14033 bytes | Created Date = 2008-01-21 19:54:03 | Attr = ]
pos558.tmp -> %SystemDrive%\pos558.tmp -> [Ver = | Size = 9033 bytes | Created Date = 2008-01-21 19:54:03 | Attr = ]
pos559.tmp -> %SystemDrive%\pos559.tmp -> [Ver = | Size = 6033 bytes | Created Date = 2008-01-21 19:54:03 | Attr = ]
pos55A.tmp -> %SystemDrive%\pos55A.tmp -> [Ver = | Size = 5033 bytes | Created Date = 2008-01-21 19:54:03 | Attr = ]
pos55B.tmp -> %SystemDrive%\pos55B.tmp -> [Ver = | Size = 5033 bytes | Created Date = 2008-01-21 19:54:03 | Attr = ]
pos55C.tmp -> %SystemDrive%\pos55C.tmp -> [Ver = | Size = 7033 bytes | Created Date = 2008-01-21 19:54:03 | Attr = ]
pos55D.tmp -> %SystemDrive%\pos55D.tmp -> [Ver = | Size = 6033 bytes | Created Date = 2008-01-21 19:54:03 | Attr = ]
pos55E.tmp -> %SystemDrive%\pos55E.tmp -> [Ver = | Size = 14033 bytes | Created Date = 2008-01-21 19:54:03 | Attr = ]
pos55F.tmp -> %SystemDrive%\pos55F.tmp -> [Ver = | Size = 10033 bytes | Created Date = 2008-01-21 19:54:03 | Attr = ]
pos560.tmp -> %SystemDrive%\pos560.tmp -> [Ver = | Size = 8033 bytes | Created Date = 2008-01-21 19:54:03 | Attr = ]
pos561.tmp -> %SystemDrive%\pos561.tmp -> [Ver = | Size = 11033 bytes | Created Date = 2008-01-21 19:54:03 | Attr = ]
pos562.tmp -> %SystemDrive%\pos562.tmp -> [Ver = | Size = 12033 bytes | Created Date = 2008-01-21 19:54:03 | Attr = ]
pos563.tmp -> %SystemDrive%\pos563.tmp -> [Ver = | Size = 7033 bytes | Created Date = 2008-01-21 19:54:03 | Attr = ]
pos564.tmp -> %SystemDrive%\pos564.tmp -> [Ver = | Size = 8033 bytes | Created Date = 2008-01-21 19:54:03 | Attr = ]
pos565.tmp -> %SystemDrive%\pos565.tmp -> [Ver = | Size = 11033 bytes | Created Date = 2008-01-21 19:54:03 | Attr = ]
pos566.tmp -> %SystemDrive%\pos566.tmp -> [Ver = | Size = 8033 bytes | Created Date = 2008-01-21 19:54:03 | Attr = ]
pos567.tmp -> %SystemDrive%\pos567.tmp -> [Ver = | Size = 12033 bytes | Created Date = 2008-01-21 19:54:04 | Attr = ]
pos568.tmp -> %SystemDrive%\pos568.tmp -> [Ver = | Size = 12033 bytes | Created Date = 2008-01-21 19:54:04 | Attr = ]
pos569.tmp -> %SystemDrive%\pos569.tmp -> [Ver = | Size = 8033 bytes | Created Date = 2008-01-21 19:54:04 | Attr = ]
pos56A.tmp -> %SystemDrive%\pos56A.tmp -> [Ver = | Size = 11033 bytes | Created Date = 2008-01-21 19:54:04 | Attr = ]
pos56B.tmp -> %SystemDrive%\pos56B.tmp -> [Ver = | Size = 8033 bytes | Created Date = 2008-01-21 19:54:04 | Attr = ]
pos56C.tmp -> %SystemDrive%\pos56C.tmp -> [Ver = | Size = 12033 bytes | Created Date = 2008-01-21 19:54:04 | Attr = ]
pos56D.tmp -> %SystemDrive%\pos56D.tmp -> [Ver = | Size = 14033 bytes | Created Date = 2008-01-21 19:54:04 | Attr = ]
pos570.tmp -> %SystemDrive%\pos570.tmp -> [Ver = | Size = 7033 bytes | Created Date = 2008-01-21 19:54:04 | Attr = ]
pos571.tmp -> %SystemDrive%\pos571.tmp -> [Ver = | Size = 14033 bytes | Created Date = 2008-01-21 19:54:04 | Attr = ]
pos572.tmp -> %SystemDrive%\pos572.tmp -> [Ver = | Size = 11033 bytes | Created Date = 2008-01-21 19:54:04 | Attr = ]
pos574.tmp -> %SystemDrive%\pos574.tmp -> [Ver = | Size = 10033 bytes | Created Date = 2008-01-21 19:54:04 | Attr = ]
pos575.tmp -> %SystemDrive%\pos575.tmp -> [Ver = | Size = 7033 bytes | Created Date = 2008-01-21 19:54:04 | Attr = ]
pos576.tmp -> %SystemDrive%\pos576.tmp -> [Ver = | Size = 11033 bytes | Created Date = 2008-01-21 19:54:05 | Attr = ]
pos577.tmp -> %SystemDrive%\pos577.tmp -> [Ver = | Size = 12033 bytes | Created Date = 2008-01-21 19:54:05 | Attr = ]
pos578.tmp -> %SystemDrive%\pos578.tmp -> [Ver = | Size = 10033 bytes | Created Date = 2008-01-21 19:54:05 | Attr = ]
pos579.tmp -> %SystemDrive%\pos579.tmp -> [Ver = | Size = 6033 bytes | Created Date = 2008-01-21 19:54:05 | Attr = ]
pos57A.tmp -> %SystemDrive%\pos57A.tmp -> [Ver = | Size = 6033 bytes | Created Date = 2008-01-21 19:54:05 | Attr = ]
pos57B.tmp -> %SystemDrive%\pos57B.tmp -> [Ver = | Size = 13033 bytes | Created Date = 2008-01-21 19:54:05 | Attr = ]
pos57C.tmp -> %SystemDrive%\pos57C.tmp -> [Ver = | Size = 9033 bytes | Created Date = 2008-01-21 19:54:05 | Attr = ]
pos57D.tmp -> %SystemDrive%\pos57D.tmp -> [Ver = | Size = 9033 bytes | Created Date = 2008-01-21 19:54:05 | Attr = ]
pos57E.tmp -> %SystemDrive%\pos57E.tmp -> [Ver = | Size = 12033 bytes | Created Date = 2008-01-21 19:54:05 | Attr = ]
pos57F.tmp -> %SystemDrive%\pos57F.tmp -> [Ver = | Size = 6033 bytes | Created Date = 2008-01-21 19:54:05 | Attr = ]
pos580.tmp -> %SystemDrive%\pos580.tmp -> [Ver = | Size = 6033 bytes | Created Date = 2008-01-21 19:54:05 | Attr = ]
pos581.tmp -> %SystemDrive%\pos581.tmp -> [Ver = | Size = 6033 bytes | Created Date = 2008-01-21 19:54:05 | Attr = ]
pos582.tmp -> %SystemDrive%\pos582.tmp -> [Ver = | Size = 13033 bytes | Created Date = 2008-01-21 19:54:05 | Attr = ]
pos583.tmp -> %SystemDrive%\pos583.tmp -> [Ver = | Size = 8033 bytes | Created Date = 2008-01-21 19:54:05 | Attr = ]
pos584.tmp -> %SystemDrive%\pos584.tmp -> [Ver = | Size = 7033 bytes | Created Date = 2008-01-21 19:54:05 | Attr = ]
pos585.tmp -> %SystemDrive%\pos585.tmp -> [Ver = | Size = 13033 bytes | Created Date = 2008-01-21 19:54:05 | Attr = ]
pos586.tmp -> %SystemDrive%\pos586.tmp -> [Ver = | Size = 12033 bytes | Created Date = 2008-01-21 19:54:06 | Attr = ]
pos587.tmp -> %SystemDrive%\pos587.tmp -> [Ver = | Size = 6033 bytes | Created Date = 2008-01-21 19:54:06 | Attr = ]
pos588.tmp -> %SystemDrive%\pos588.tmp -> [Ver = | Size = 12033 bytes | Created Date = 2008-01-21 19:54:06 | Attr = ]
pos589.tmp -> %SystemDrive%\pos589.tmp -> [Ver = | Size = 11033 bytes | Created Date = 2008-01-21 19:54:06 | Attr = ]
pos58A.tmp -> %SystemDrive%\pos58A.tmp -> [Ver = | Size = 5033 bytes | Created Date = 2008-01-21 19:54:06 | Attr = ]
pos58B.tmp -> %SystemDrive%\pos58B.tmp -> [Ver = | Size = 8033 bytes | Created Date = 2008-01-21 19:54:06 | Attr = ]
pos58C.tmp -> %SystemDrive%\pos58C.tmp -> [Ver = | Size = 14033 bytes | Created Date = 2008-01-21 19:54:06 | Attr = ]
pos58D.tmp -> %SystemDrive%\pos58D.tmp -> [Ver = | Size = 10033 bytes | Created Date = 2008-01-21 19:54:06 | Attr = ]
pos58E.tmp -> %SystemDrive%\pos58E.tmp -> [Ver = | Size = 13033 bytes | Created Date = 2008-01-21 19:54:06 | Attr = ]
pos58F.tmp -> %SystemDrive%\pos58F.tmp -> [Ver = | Size = 11033 bytes | Created Date = 2008-01-21 19:54:06 | Attr = ]
pos590.tmp -> %SystemDrive%\pos590.tmp -> [Ver = | Size = 11033 bytes | Created Date = 2008-01-21 19:54:06 | Attr = ]
pos591.tmp -> %SystemDrive%\pos591.tmp -> [Ver = | Size = 8033 bytes | Created Date = 2008-01-21 19:54:06 | Attr = ]
pos592.tmp -> %SystemDrive%\pos592.tmp -> [Ver = | Size = 9033 bytes | Created Date = 2008-01-21 19:54:07 | Attr = ]
pos593.tmp -> %SystemDrive%\pos593.tmp -> [Ver = | Size = 5033 bytes | Created Date = 2008-01-21 19:54:07 | Attr = ]
pos594.tmp -> %SystemDrive%\pos594.tmp -> [Ver = | Size = 12033 bytes | Created Date = 2008-01-21 19:54:07 | Attr = ]
pos595.tmp -> %SystemDrive%\pos595.tmp -> [Ver = | Size = 6033 bytes | Created Date = 2008-01-21 19:54:07 | Attr = ]
pos596.tmp -> %SystemDrive%\pos596.tmp -> [Ver = | Size = 11033 bytes | Created Date = 2008-01-21 19:54:07 | Attr = ]
pos597.tmp -> %SystemDrive%\pos597.tmp -> [Ver = | Size = 11033 bytes | Created Date = 2008-01-21 19:54:07 | Attr = ]
pos598.tmp -> %SystemDrive%\pos598.tmp -> [Ver = | Size = 12033 bytes | Created Date = 2008-01-21 19:54:07 | Attr = ]
pos599.tmp -> %SystemDrive%\pos599.tmp -> [Ver = | Size = 12033 bytes | Created Date = 2008-01-21 19:54:07 | Attr = ]
pos59A.tmp -> %SystemDrive%\pos59A.tmp -> [Ver = | Size = 12033 bytes | Created Date = 2008-01-21 19:54:07 | Attr = ]
pos59B.tmp -> %SystemDrive%\pos59B.tmp -> [Ver = | Size = 7033 bytes | Created Date = 2008-01-21 19:54:07 | Attr = ]
pos59C.tmp -> %SystemDrive%\pos59C.tmp -> [Ver = | Size = 6033 bytes | Created Date = 2008-01-21 19:54:07 | Attr = ]
pos59D.tmp -> %SystemDrive%\pos59D.tmp -> [Ver = | Size = 8033 bytes | Created Date = 2008-01-21 19:54:07 | Attr = ]
pos59E.tmp -> %SystemDrive%\pos59E.tmp -> [Ver = | Size = 5033 bytes | Created Date = 2008-01-21 19:54:07 | Attr = ]
pos59F.tmp -> %SystemDrive%\pos59F.tmp -> [Ver = | Size = 6033 bytes | Created Date = 2008-01-21 19:54:08 | Attr = ]
pos5A0.tmp -> %SystemDrive%\pos5A0.tmp -> [Ver = | Size = 13033 bytes | Created Date = 2008-01-21 19:54:08 | Attr = ]
pos5A1.tmp -> %SystemDrive%\pos5A1.tmp -> [Ver = | Size = 7033 bytes | Created Date = 2008-01-21 19:54:08 | Attr = ]
pos5A2.tmp -> %SystemDrive%\pos5A2.tmp -> [Ver = | Size = 11033 bytes | Created Date = 2008-01-21 19:54:08 | Attr = ]
pos5A3.tmp -> %SystemDrive%\pos5A3.tmp -> [Ver = | Size = 9033 bytes | Created Date = 2008-01-21 19:54:08 | Attr = ]
pos5A4.tmp -> %SystemDrive%\pos5A4.tmp -> [Ver = | Size = 5033 bytes | Created Date = 2008-01-21 19:54:08 | Attr = ]
pos5A5.tmp -> %SystemDrive%\pos5A5.tmp -> [Ver = | Size = 12033 bytes | Created Date = 2008-01-21 19:54:08 | Attr = ]
pos5A6.tmp -> %SystemDrive%\pos5A6.tmp -> [Ver = | Size = 13033 bytes | Created Date = 2008-01-21 19:54:08 | Attr = ]
pos5A7.tmp -> %SystemDrive%\pos5A7.tmp -> [Ver = | Size = 9033 bytes | Created Date = 2008-01-21 19:54:08 | Attr = ]
pos5A8.tmp -> %SystemDrive%\pos5A8.tmp -> [Ver = | Size = 11033 bytes | Created Date = 2008-01-21 19:54:08 | Attr = ]
pos5A9.tmp -> %SystemDrive%\pos5A9.tmp -> [Ver = | Size = 5033 bytes | Created Date = 2008-01-21 19:54:08 | Attr = ]
pos5AA.tmp -> %SystemDrive%\pos5AA.tmp -> [Ver = | Size = 8033 bytes | Created Date = 2008-01-21 19:54:08 | Attr = ]
pos5AB.tmp -> %SystemDrive%\pos5AB.tmp -> [Ver = | Size = 8033 bytes | Created Date = 2008-01-21 19:54:08 | Attr = ]
pos5AC.tmp -> %SystemDrive%\pos5AC.tmp -> [Ver = | Size = 11033 bytes | Created Date = 2008-01-21 19:54:09 | Attr = ]
pos5AD.tmp -> %SystemDrive%\pos5AD.tmp -> [Ver = | Size = 7033 bytes | Created Date = 2008-01-21 19:54:09 | Attr = ]
pos5AE.tmp -> %SystemDrive%\pos5AE.tmp -> [Ver = | Size = 9033 bytes | Created Date = 2008-01-21 19:54:09 | Attr = ]
pos5AF.tmp -> %SystemDrive%\pos5AF.tmp -> [Ver = | Size = 8033 bytes | Created Date = 2008-01-21 19:54:09 | Attr = ]
pos5B0.tmp -> %SystemDrive%\pos5B0.tmp -> [Ver = | Size = 8033 bytes | Created Date = 2008-01-21 19:54:09 | Attr = ]
pos600.tmp -> %SystemDrive%\pos600.tmp -> [Ver = | Size = 7033 bytes | Created Date = 2008-01-21 19:54:14 | Attr = ]
pos5B1.tmp -> %SystemDrive%\pos5B1.tmp -> [Ver = | Size = 12033 bytes | Created Date = 2008-01-21 19:54:09 | Attr = ]
pos5B2.tmp -> %SystemDrive%\pos5B2.tmp -> [Ver = | Size = 8033 bytes | Created Date = 2008-01-21 19:54:09 | Attr = ]
pos5B3.tmp -> %SystemDrive%\pos5B3.tmp -> [Ver = | Size = 8033 bytes | Created Date = 2008-01-21 19:54:09 | Attr = ]
pos5B4.tmp -> %SystemDrive%\pos5B4.tmp -> [Ver = | Size = 12033 bytes | Created Date = 2008-01-21 19:54:09 | Attr = ]
pos5B5.tmp -> %SystemDrive%\pos5B5.tmp -> [Ver = | Size = 11033 bytes | Created Date = 2008-01-21 19:54:09 | Attr = ]
pos5B6.tmp -> %SystemDrive%\pos5B6.tmp -> [Ver = | Size = 6033 bytes | Created Date = 2008-01-21 19:54:09 | Attr = ]
pos5B7.tmp -> %SystemDrive%\pos5B7.tmp -> [Ver = | Size = 10033 bytes | Created Date = 2008-01-21 19:54:09 | Attr = ]
pos5B8.tmp -> %SystemDrive%\pos5B8.tmp -> [Ver = | Size = 9033 bytes | Created Date = 2008-01-21 19:54:09 | Attr = ]
pos5B9.tmp -> %SystemDrive%\pos5B9.tmp -> [Ver = | Size = 7033 bytes | Created Date = 2008-01-21 19:54:09 | Attr = ]
pos5BA.tmp -> %SystemDrive%\pos5BA.tmp -> [Ver = | Size = 10033 bytes | Created Date = 2008-01-21 19:54:09 | Attr = ]
pos5BB.tmp -> %SystemDrive%\pos5BB.tmp -> [Ver = | Size = 5033 bytes | Created Date = 2008-01-21 19:54:09 | Attr = ]
pos5BC.tmp -> %SystemDrive%\pos5BC.tmp -> [Ver = | Size = 12033 bytes | Created Date = 2008-01-21 19:54:10 | Attr = ]
pos5BD.tmp -> %SystemDrive%\pos5BD.tmp -> [Ver = | Size = 6033 bytes | Created Date = 2008-01-21 19:54:10 | Attr = ]
pos5BE.tmp -> %SystemDrive%\pos5BE.tmp -> [Ver = | Size = 8033 bytes | Created Date = 2008-01-21 19:54:10 | Attr = ]
pos5BF.tmp -> %SystemDrive%\pos5BF.tmp -> [Ver = | Size = 5033 bytes | Created Date = 2008-01-21 19:54:10 | Attr = ]
pos5C0.tmp -> %SystemDrive%\pos5C0.tmp -> [Ver = | Size = 9033 bytes | Created Date = 2008-01-21 19:54:10 | Attr = ]
pos5C1.tmp -> %SystemDrive%\pos5C1.tmp -> [Ver = | Size = 13033 bytes | Created Date = 2008-01-21 19:54:10 | Attr = ]
pos5C2.tmp -> %SystemDrive%\pos5C2.tmp -> [Ver = | Size = 14033 bytes | Created Date = 2008-01-21 19:54:10 | Attr = ]
pos5C3.tmp -> %SystemDrive%\pos5C3.tmp -> [Ver = | Size = 5033 bytes | Created Date = 2008-01-21 19:54:10 | Attr = ]
pos5C4.tmp -> %SystemDrive%\pos5C4.tmp -> [Ver = | Size = 7033 bytes | Created Date = 2008-01-21 19:54:10 | Attr = ]
pos5C5.tmp -> %SystemDrive%\pos5C5.tmp -> [Ver = | Size = 14033 bytes | Created Date = 2008-01-21 19:54:10 | Attr = ]
pos5C6.tmp -> %SystemDrive%\pos5C6.tmp -> [Ver = | Size = 11033 bytes | Created Date = 2008-01-21 19:54:10 | Attr = ]
pos5C7.tmp -> %SystemDrive%\pos5C7.tmp -> [Ver = | Size = 9033 bytes | Created Date = 2008-01-21 19:54:10 | Attr = ]
pos601.tmp -> %SystemDrive%\pos601.tmp -> [Ver = | Size = 9033 bytes | Created Date = 2008-01-21 19:54:14 | Attr = ]
pos5C8.tmp -> %SystemDrive%\pos5C8.tmp -> [Ver = | Size = 5033 bytes | Created Date = 2008-01-21 19:54:10 | Attr = ]
pos5C9.tmp -> %SystemDrive%\pos5C9.tmp -> [Ver = | Size = 9033 bytes | Created Date = 2008-01-21 19:54:10 | Attr = ]
pos5CA.tmp -> %SystemDrive%\pos5CA.tmp -> [Ver = | Size = 11033 bytes | Created Date = 2008-01-21 19:54:10 | Attr = ]
pos5CB.tmp -> %SystemDrive%\pos5CB.tmp -> [Ver = | Size = 7033 bytes | Created Date = 2008-01-21 19:54:10 | Attr = ]
pos5CC.tmp -> %SystemDrive%\pos5CC.tmp -> [Ver = | Size = 6033 bytes | Created Date = 2008-01-21 19:54:10 | Attr = ]
pos5CD.tmp -> %SystemDrive%\pos5CD.tmp -> [Ver = | Size = 10033 bytes | Created Date = 2008-01-21 19:54:10 | Attr = ]
pos5CE.tmp -> %SystemDrive%\pos5CE.tmp -> [Ver = | Size = 9033 bytes | Created Date = 2008-01-21 19:54:11 | Attr = ]
pos5CF.tmp -> %SystemDrive%\pos5CF.tmp -> [Ver = | Size = 11033 bytes | Created Date = 2008-01-21 19:54:11 | Attr = ]
pos5D0.tmp -> %SystemDrive%\pos5D0.tmp -> [Ver = | Size = 14033 bytes | Created Date = 2008-01-21 19:54:11 | Attr = ]
pos5D1.tmp -> %SystemDrive%\pos5D1.tmp -> [Ver = | Size = 12033 bytes | Created Date = 2008-01-21 19:54:11 | Attr = ]
pos5D2.tmp -> %SystemDrive%\pos5D2.tmp -> [Ver = | Size = 7033 bytes | Created Date = 2008-01-21 19:54:11 | Attr = ]
pos5D3.tmp -> %SystemDrive%\pos5D3.tmp -> [Ver = | Size = 7033 bytes | Created Date = 2008-01-21 19:54:11 | Attr = ]
pos5D4.tmp -> %SystemDrive%\pos5D4.tmp -> [Ver = | Size = 11033 bytes | Created Date = 2008-01-21 19:54:11 | Attr = ]
pos5D5.tmp -> %SystemDrive%\pos5D5.tmp -> [Ver = | Size = 9033 bytes | Created Date = 2008-01-21 19:54:11 | Attr = ]
pos5D6.tmp -> %SystemDrive%\pos5D6.tmp -> [Ver = | Size = 14033 bytes | Created Date = 2008-01-21 19:54:11 | Attr = ]
pos5D7.tmp -> %SystemDrive%\pos5D7.tmp -> [Ver = | Size = 13033 bytes | Created Date = 2008-01-21 19:54:11 | Attr = ]
pos5D8.tmp -> %SystemDrive%\pos5D8.tmp -> [Ver = | Size = 12033 bytes | Created Date = 2008-01-21 19:54:11 | Attr = ]
pos5D9.tmp -> %SystemDrive%\pos5D9.tmp -> [Ver = | Size = 11033 bytes | Created Date = 2008-01-21 19:54:11 | Attr = ]
pos5DA.tmp -> %SystemDrive%\pos5DA.tmp -> [Ver = | Size = 6033 bytes | Created Date = 2008-01-21 19:54:11 | Attr = ]
pos5DB.tmp -> %SystemDrive%\pos5DB.tmp -> [Ver = | Size = 6033 bytes | Created Date = 2008-01-21 19:54:11 | Attr = ]
pos5DC.tmp -> %SystemDrive%\pos5DC.tmp -> [Ver = | Size = 13033 bytes | Created Date = 2008-01-21 19:54:11 | Attr = ]
pos5DD.tmp -> %SystemDrive%\pos5DD.tmp -> [Ver = | Size = 7033 bytes | Created Date = 2008-01-21 19:54:12 | Attr = ]
pos5DE.tmp -> %SystemDrive%\pos5DE.tmp -> [Ver = | Size = 10033 bytes | Created Date = 2008-01-21 19:54:12 | Attr = ]
pos5DF.tmp -> %SystemDrive%\pos5DF.tmp -> [Ver = | Size = 8033 bytes | Created Date = 2008-01-21 19:54:12 | Attr = ]
pos5E0.tmp -> %SystemDrive%\pos5E0.tmp -> [Ver = | Size = 5033 bytes | Created Date = 2008-01-21 19:54:12 | Attr = ]
pos5E1.tmp -> %SystemDrive%\pos5E1.tmp -> [Ver = | Size = 6033 bytes | Created Date = 2008-01-21 19:54:12 | Attr = ]
pos5E2.tmp -> %SystemDrive%\pos5E2.tmp -> [Ver = | Size = 13033 bytes | Created Date = 2008-01-21 19:54:12 | Attr = ]
pos5E3.tmp -> %SystemDrive%\pos5E3.tmp -> [Ver = | Size = 13033 bytes | Created Date = 2008-01-21 19:54:12 | Attr = ]
pos5E4.tmp -> %SystemDrive%\pos5E4.tmp -> [Ver = | Size = 12033 bytes | Created Date = 2008-01-21 19:54:12 | Attr = ]
pos5E5.tmp -> %SystemDrive%\pos5E5.tmp -> [Ver = | Size = 5033 bytes | Created Date = 2008-01-21 19:54:12 | Attr = ]
pos5E6.tmp -> %SystemDrive%\pos5E6.tmp -> [Ver = | Size = 14033 bytes | Created Date = 2008-01-21 19:54:12 | Attr = ]
pos5E7.tmp -> %SystemDrive%\pos5E7.tmp -> [Ver = | Size = 6033 bytes | Created Date = 2008-01-21 19:54:12 | Attr = ]
pos5E8.tmp -> %SystemDrive%\pos5E8.tmp -> [Ver = | Size = 7033 bytes | Created Date = 2008-01-21 19:54:12 | Attr = ]
pos5E9.tmp -> %SystemDrive%\pos5E9.tmp -> [Ver = | Size = 12033 bytes | Created Date = 2008-01-21 19:54:12 | Attr = ]
pos5EA.tmp -> %SystemDrive%\pos5EA.tmp -> [Ver = | Size = 14033 bytes | Created Date = 2008-01-21 19:54:13 | Attr = ]
pos5EB.tmp -> %SystemDrive%\pos5EB.tmp -> [Ver = | Size = 10033 bytes | Created Date = 2008-01-21 19:54:13 | Attr = ]
pos5EC.tmp -> %SystemDrive%\pos5EC.tmp -> [Ver = | Size = 8033 bytes | Created Date = 2008-01-21 19:54:13 | Attr = ]
pos5ED.tmp -> %SystemDrive%\pos5ED.tmp -> [Ver = | Size = 6033 bytes | Created Date = 2008-01-21 19:54:13 | Attr = ]
pos5EE.tmp -> %SystemDrive%\pos5EE.tmp -> [Ver = | Size = 11033 bytes | Created Date = 2008-01-21 19:54:13 | Attr = ]
pos5EF.tmp -> %SystemDrive%\pos5EF.tmp -> [Ver = | Size = 5033 bytes | Created Date = 2008-01-21 19:54:13 | Attr = ]
pos5F0.tmp -> %SystemDrive%\pos5F0.tmp -> [Ver = | Size = 14033 bytes | Created Date = 2008-01-21 19:54:13 | Attr = ]
pos5F1.tmp -> %SystemDrive%\pos5F1.tmp -> [Ver = | Size = 7033 bytes | Created Date = 2008-01-21 19:54:13 | Attr = ]
pos5F2.tmp -> %SystemDrive%\pos5F2.tmp -> [Ver = | Size = 8033 bytes | Created Date = 2008-01-21 19:54:13 | Attr = ]
pos5F3.tmp -> %SystemDrive%\pos5F3.tmp -> [Ver = | Size = 14033 bytes | Created Date = 2008-01-21 19:54:13 | Attr = ]
pos5F4.tmp -> %SystemDrive%\pos5F4.tmp -> [Ver = | Size = 10033 bytes | Created Date = 2008-01-21 19:54:13 | Attr = ]
pos5F5.tmp -> %SystemDrive%\pos5F5.tmp -> [Ver = | Size = 11033 bytes | Created Date = 2008-01-21 19:54:13 | Attr = ]
pos5F6.tmp -> %SystemDrive%\pos5F6.tmp -> [Ver = | Size = 12033 bytes | Created Date = 2008-01-21 19:54:13 | Attr = ]
pos5F7.tmp -> %SystemDrive%\pos5F7.tmp -> [Ver = | Size = 7033 bytes | Created Date = 2008-01-21 19:54:13 | Attr = ]
pos5F8.tmp -> %SystemDrive%\pos5F8.tmp -> [Ver = | Size = 5033 bytes | Created Date = 2008-01-21 19:54:13 | Attr = ]
pos5F9.tmp -> %SystemDrive%\pos5F9.tmp -> [Ver = | Size = 5033 bytes | Created Date = 2008-01-21 19:54:14 | Attr = ]
pos5FA.tmp -> %SystemDrive%\pos5FA.tmp -> [Ver = | Size = 10033 bytes | Created Date = 2008-01-21 19:54:14 | Attr = ]
pos5FB.tmp -> %SystemDrive%\pos5FB.tmp -> [Ver = | Size = 5033 bytes | Created Date = 2008-01-21 19:54:14 | Attr = ]
pos5FC.tmp -> %SystemDrive%\pos5FC.tmp -> [Ver = | Size = 12033 bytes | Created Date = 2008-01-21 19:54:14 | Attr = ]
pos5FD.tmp -> %SystemDrive%\pos5FD.tmp -> [Ver = | Size = 7033 bytes | Created Date = 2008-01-21 19:54:14 | Attr = ]
pos5FE.tmp -> %SystemDrive%\pos5FE.tmp -> [Ver = | Size = 8033 bytes | Created Date = 2008-01-21 19:54:14 | Attr = ]
pos5FF.tmp -> %SystemDrive%\pos5FF.tmp -> [Ver = | Size = 7033 bytes | Created Date = 2008-01-21 19:54:14 | Attr = ]
pos602.tmp -> %SystemDrive%\pos602.tmp -> [Ver = | Size = 10033 bytes | Created Date = 2008-01-21 19:54:14 | Attr = ]
pos603.tmp -> %SystemDrive%\pos603.tmp -> [Ver = | Size = 7033 bytes | Created Date = 2008-01-21 19:54:14 | Attr = ]
pos604.tmp -> %SystemDrive%\pos604.tmp -> [Ver = | Size = 8033 bytes | Created Date = 2008-01-21 19:54:14 | Attr = ]
pos605.tmp -> %SystemDrive%\pos605.tmp -> [Ver = | Size = 9033 bytes | Created Date = 2008-01-21 19:54:14 | Attr = ]
pos606.tmp -> %SystemDrive%\pos606.tmp -> [Ver = | Size = 13033 bytes | Created Date = 2008-01-21 19:54:14 | Attr = ]
pos607.tmp -> %SystemDrive%\pos607.tmp -> [Ver = | Size = 11033 bytes | Created Date = 2008-01-21 19:54:14 | Attr = ]
pos608.tmp -> %SystemDrive%\pos608.tmp -> [Ver = | Size = 8033 bytes | Created Date = 2008-01-21 19:54:14 | Attr = ]
pos609.tmp -> %SystemDrive%\pos609.tmp -> [Ver = | Size = 6033 bytes | Created Date = 2008-01-21 19:54:14 | Attr = ]
pos60A.tmp -> %SystemDrive%\pos60A.tmp -> [Ver = | Size = 7033 bytes | Created Date = 2008-01-21 19:54:14 | Attr = ]
pos60B.tmp -> %SystemDrive%\pos60B.tmp -> [Ver = | Size = 13033 bytes | Created Date = 2008-01-21 19:54:14 | Attr = ]
pos60C.tmp -> %SystemDrive%\pos60C.tmp -> [Ver = | Size = 11033 bytes | Created Date = 2008-01-21 19:54:14 | Attr = ]
pos60D.tmp -> %SystemDrive%\pos60D.tmp -> [Ver = | Size = 11033 bytes | Created Date = 2008-01-21 19:54:14 | Attr = ]
pos60E.tmp -> %SystemDrive%\pos60E.tmp -> [Ver = | Size = 10033 bytes | Created Date = 2008-01-21 19:54:14 | Attr = ]
pos60F.tmp -> %SystemDrive%\pos60F.tmp -> [Ver = | Size = 14033 bytes | Created Date = 2008-01-21 19:54:15 | Attr = ]
pos610.tmp -> %SystemDrive%\pos610.tmp -> [Ver = | Size = 5033 bytes | Created Date = 2008-01-21 19:54:15 | Attr = ]
pos611.tmp -> %SystemDrive%\pos611.tmp -> [Ver = | Size = 13033 bytes | Created Date = 2008-01-21 19:54:15 | Attr = ]
pos612.tmp -> %SystemDrive%\pos612.tmp -> [Ver = | Size = 10033 bytes | Created Date = 2008-01-21 19:54:15 | Attr = ]
pos613.tmp -> %SystemDrive%\pos613.tmp -> [Ver = | Size = 5033 bytes | Created Date = 2008-01-21 19:54:15 | Attr = ]
pos614.tmp -> %SystemDrive%\pos614.tmp -> [Ver = | Size = 10033 bytes | Created Date = 2008-01-21 19:54:15 | Attr = ]
pos615.tmp -> %SystemDrive%\pos615.tmp -> [Ver = | Size = 5033 bytes | Created Date = 2008-01-21 19:54:15 | Attr = ]
pos616.tmp -> %SystemDrive%\pos616.tmp -> [Ver = | Size = 12033 bytes | Created Date = 2008-01-21 19:54:15 | Attr = ]
pos617.tmp -> %SystemDrive%\pos617.tmp -> [Ver = | Size = 8033 bytes | Created Date = 2008-01-21 19:54:15 | Attr = ]
pos618.tmp -> %SystemDrive%\pos618.tmp -> [Ver = | Size = 9033 bytes | Created Date = 2008-01-21 19:54:15 | Attr = ]
pos619.tmp -> %SystemDrive%\pos619.tmp -> [Ver = | Size = 12033 bytes | Created Date = 2008-01-21 19:54:15 | Attr = ]
pos61A.tmp -> %SystemDrive%\pos61A.tmp -> [Ver = | Size = 10033 bytes | Created Date = 2008-01-21 19:54:15 | Attr = ]
pos61B.tmp -> %SystemDrive%\pos61B.tmp -> [Ver = | Size = 6033 bytes | Created Date = 2008-01-21 19:54:15 | Attr = ]
pos61C.tmp -> %SystemDrive%\pos61C.tmp -> [Ver = | Size = 12033 bytes | Created Date = 2008-01-21 19:54:15 | Attr = ]
pos61D.tmp -> %SystemDrive%\pos61D.tmp -> [Ver = | Size = 12033 bytes | Created Date = 2008-01-21 19:54:15 | Attr = ]
pos61E.tmp -> %SystemDrive%\pos61E.tmp -> [Ver = | Size = 6033 bytes | Created Date = 2008-01-21 19:54:15 | Attr = ]
pos61F.tmp -> %SystemDrive%\pos61F.tmp -> [Ver = | Size = 14033 bytes | Created Date = 2008-01-21 19:54:15 | Attr = ]
pos620.tmp -> %SystemDrive%\pos620.tmp -> [Ver = | Size = 10033 bytes | Created Date = 2008-01-21 19:54:16 | Attr = ]
pos621.tmp -> %SystemDrive%\pos621.tmp -> [Ver = | Size = 5033 bytes | Created Date = 2008-01-21 19:54:16 | Attr = ]
pos622.tmp -> %SystemDrive%\pos622.tmp -> [Ver = | Size = 8033 bytes | Created Date = 2008-01-21 19:54:16 | Attr = ]
pos623.tmp -> %SystemDrive%\pos623.tmp -> [Ver = | Size = 14033 bytes | Created Date = 2008-01-21 19:54:16 | Attr = ]
pos624.tmp -> %SystemDrive%\pos624.tmp -> [Ver = | Size = 14033 bytes | Created Date = 2008-01-21 19:54:16 | Attr = ]
pos625.tmp -> %SystemDrive%\pos625.tmp -> [Ver = | Size = 12033 bytes | Created Date = 2008-01-21 19:54:16 | Attr = ]
pos626.tmp -> %SystemDrive%\pos626.tmp -> [Ver = | Size = 6033 bytes | Created Date = 2008-01-21 19:54:16 | Attr = ]
pos627.tmp -> %SystemDrive%\pos627.tmp -> [Ver = | Size = 7033 bytes | Created Date = 2008-01-21 19:54:16 | Attr = ]
pos628.tmp -> %SystemDrive%\pos628.tmp -> [Ver = | Size = 7033 bytes | Created Date = 2008-01-21 19:54:16 | Attr = ]
pos629.tmp -> %SystemDrive%\pos629.tmp -> [Ver = | Size = 6033 bytes | Created Date = 2008-01-21 19:54:16 | Attr = ]
pos62A.tmp -> %SystemDrive%\pos62A.tmp -> [Ver = | Size = 10033 bytes | Created Date = 2008-01-21 19:54:16 | Attr = ]
pos62B.tmp -> %SystemDrive%\pos62B.tmp -> [Ver = | Size = 14033 bytes | Created Date = 2008-01-21 19:54:16 | Attr = ]
pos62C.tmp -> %SystemDrive%\pos62C.tmp -> [Ver = | Size = 12033 bytes | Created Date = 2008-01-21 19:54:16 | Attr = ]
pos62D.tmp -> %SystemDrive%\pos62D.tmp -> [Ver = | Size = 7033 bytes | Created Date = 2008-01-21 19:54:16 | Attr = ]
pos62E.tmp -> %SystemDrive%\pos62E.tmp -> [Ver = | Size = 8033 bytes | Created Date = 2008-01-21 19:54:16 | Attr = ]
pos62F.tmp -> %SystemDrive%\pos62F.tmp -> [Ver = | Size = 8033 bytes | Created Date = 2008-01-21 19:54:17 | Attr = ]
pos630.tmp -> %SystemDrive%\pos630.tmp -> [Ver = | Size = 10033 bytes | Created Date = 2008-01-21 19:54:17 | Attr = ]
pos631.tmp -> %SystemDrive%\pos631.tmp -> [Ver = | Size = 9033 bytes | Created Date = 2008-01-21 19:54:17 | Attr = ]
pos632.tmp -> %SystemDrive%\pos632.tmp -> [Ver = | Size = 7033 bytes | Created Date = 2008-01-21 19:54:17 | Attr = ]
pos633.tmp -> %SystemDrive%\pos633.tmp -> [Ver = | Size = 8033 bytes | Created Date = 2008-01-21 19:54:17 | Attr = ]
pos634.tmp -> %SystemDrive%\pos634.tmp -> [Ver = | Size = 13033 bytes | Created Date = 2008-01-21 19:54:17 | Attr = ]
pos635.tmp -> %SystemDrive%\pos635.tmp -> [Ver = | Size = 7033 bytes | Created Date = 2008-01-21 19:54:17 | Attr = ]
pos636.tmp -> %SystemDrive%\pos636.tmp -> [Ver = | Size = 6033 bytes | Created Date = 2008-01-21 19:54:17 | Attr = ]
pos637.tmp -> %SystemDrive%\pos637.tmp -> [Ver = | Size = 13033 bytes | Created Date = 2008-01-21 19:54:17 | Attr = ]
pos638.tmp -> %SystemDrive%\pos638.tmp -> [Ver = | Size = 6033 bytes | Created Date = 2008-01-21 19:54:17 | Attr = ]
pos639.tmp -> %SystemDrive%\pos639.tmp -> [Ver = | Size = 8033 bytes | Created Date = 2008-01-21 19:54:17 | Attr = ]
pos63A.tmp -> %SystemDrive%\pos63A.tmp -> [Ver = | Size = 10033 bytes | Created Date = 2008-01-21 19:54:17 | Attr = ]
pos63B.tmp -> %SystemDrive%\pos63B.tmp -> [Ver = | Size = 11033 bytes | Created Date = 2008-01-21 19:54:18 | Attr = ]
pos63C.tmp -> %SystemDrive%\pos63C.tmp -> [Ver = | Size = 5033 bytes | Created Date = 2008-01-21 19:54:18 | Attr = ]
pos63D.tmp -> %SystemDrive%\pos63D.tmp -> [Ver = | Size = 10033 bytes | Created Date = 2008-01-21 19:54:18 | Attr = ]
pos63E.tmp -> %SystemDrive%\pos63E.tmp -> [Ver = | Size = 11033 bytes | Created Date = 2008-01-21 19:54:18 | Attr = ]
pos63F.tmp -> %SystemDrive%\pos63F.tmp -> [Ver = | Size = 12033 bytes | Created Date = 2008-01-21 19:54:18 | Attr = ]
pos640.tmp -> %SystemDrive%\pos640.tmp -> [Ver = | Size = 7033 bytes | Created Date = 2008-01-21 19:54:18 | Attr = ]
pos641.tmp -> %SystemDrive%\pos641.tmp -> [Ver = | Size = 7033 bytes | Created Date = 2008-01-21 19:54:18 | Attr = ]
pos642.tmp -> %SystemDrive%\pos642.tmp -> [Ver = | Size = 7033 bytes | Created Date = 2008-01-21 19:54:18 | Attr = ]
pos643.tmp -> %SystemDrive%\pos643.tmp -> [Ver = | Size = 10033 bytes | Created Date = 2008-01-21 19:54:18 | Attr = ]
pos644.tmp -> %SystemDrive%\pos644.tmp -> [Ver = | Size = 5033 bytes | Created Date = 2008-01-21 19:54:18 | Attr = ]
pos645.tmp -> %SystemDrive%\pos645.tmp -> [Ver = | Size = 14033 bytes | Created Date = 2008-01-21 19:54:18 | Attr = ]
pos646.tmp -> %SystemDrive%\pos646.tmp -> [Ver = | Size = 6033 bytes | Created Date = 2008-01-21 19:54:18 | Attr = ]
pos647.tmp -> %SystemDrive%\pos647.tmp -> [Ver = | Size = 8033 bytes | Created Date = 2008-01-21 19:54:18 | Attr = ]
pos648.tmp -> %SystemDrive%\pos648.tmp -> [Ver = | Size = 11033 bytes | Created Date = 2008-01-21 19:54:18 | Attr = ]
pos649.tmp -> %SystemDrive%\pos649.tmp -> [Ver = | Size = 11033 bytes | Created Date = 2008-01-21 19:54:18 | Attr = ]
pos64A.tmp -> %SystemDrive%\pos64A.tmp -> [Ver = | Size = 5033 bytes | Created Date = 2008-01-21 19:54:18 | Attr = ]
pos64B.tmp -> %SystemDrive%\pos64B.tmp -> [Ver = | Size = 5033 bytes | Created Date = 2008-01-21 19:54:19 | Attr = ]
pos64C.tmp -> %SystemDrive%\pos64C.tmp -> [Ver = | Size = 9033 bytes | Created Date = 2008-01-21 19:54:19 | Attr = ]
pos64D.tmp -> %SystemDrive%\pos64D.tmp -> [Ver = | Size = 12033 bytes | Created Date = 2008-01-21 19:54:19 | Attr = ]
pos64E.tmp -> %SystemDrive%\pos64E.tmp -> [Ver = | Size = 13033 bytes | Created Date = 2008-01-21 19:54:19 | Attr = ]
pos64F.tmp -> %SystemDrive%\pos64F.tmp -> [Ver = | Size = 12033 bytes | Created Date = 2008-01-21 19:54:19 | Attr = ]
pos650.tmp -> %SystemDrive%\pos650.tmp -> [Ver = | Size = 7033 bytes | Created Date = 2008-01-21 19:54:19 | Attr = ]
pos651.tmp -> %SystemDrive%\pos651.tmp -> [Ver = | Size = 10033 bytes | Created Date = 2008-01-21 19:54:19 | Attr = ]
pos652.tmp -> %SystemDrive%\pos652.tmp -> [Ver = | Size = 13033 bytes | Created Date = 2008-01-21 19:54:19 | Attr = ]
pos653.tmp -> %SystemDrive%\pos653.tmp -> [Ver = | Size = 10033 bytes | Created Date = 2008-01-21 19:54:19 | Attr = ]
pos654.tmp -> %SystemDrive%\pos654.tmp -> [Ver = | Size = 14033 bytes | Created Date = 2008-01-21 19:54:19 | Attr = ]
pos655.tmp -> %SystemDrive%\pos655.tmp -> [Ver = | Size = 6033 bytes | Created Date = 2008-01-21 19:54:19 | Attr = ]
pos656.tmp -> %SystemDrive%\pos656.tmp -> [Ver = | Size = 6033 bytes | Created Date = 2008-01-21 19:54:19 | Attr = ]
pos657.tmp -> %SystemDrive%\pos657.tmp -> [Ver = | Size = 10033 bytes | Created Date = 2008-01-21 19:54:19 | Attr = ]
pos658.tmp -> %SystemDrive%\pos658.tmp -> [Ver = | Size = 12033 bytes | Created Date = 2008-01-21 19:54:19 | Attr = ]
pos659.tmp -> %SystemDrive%\pos659.tmp -> [Ver = | Size = 6033 bytes | Created Date = 2008-01-21 19:54:19 | Attr = ]
pos65A.tmp -> %SystemDrive%\pos65A.tmp -> [Ver = | Size = 12033 bytes | Created Date = 2008-01-21 19:54:19 | Attr = ]
pos65B.tmp -> %SystemDrive%\pos65B.tmp -> [Ver = | Size = 13033 bytes | Created Date = 2008-01-21 19:54:19 | Attr = ]
pos65C.tmp -> %SystemDrive%\pos65C.tmp -> [Ver = | Size = 12033 bytes | Created Date = 2008-01-21 19:54:19 | Attr = ]
pos65D.tmp -> %SystemDrive%\pos65D.tmp -> [Ver = | Size = 11033 bytes | Created Date = 2008-01-21 19:54:19 | Attr = ]
pos65E.tmp -> %SystemDrive%\pos65E.tmp -> [Ver = | Size = 14033 bytes | Created Date = 2008-01-21 19:54:19 | Attr = ]
pos65F.tmp -> %SystemDrive%\pos65F.tmp -> [Ver = | Size = 7033 bytes | Created Date = 2008-01-21 19:54:20 | Attr = ]
pos660.tmp -> %SystemDrive%\pos660.tmp -> [Ver = | Size = 9033 bytes | Created Date = 2008-01-21 19:54:20 | Attr = ]
pos661.tmp -> %SystemDrive%\pos661.tmp -> [Ver = | Size = 13033 bytes | Created Date = 2008-01-21 19:54:20 | Attr = ]
pos662.tmp -> %SystemDrive%\pos662.tmp -> [Ver = | Size = 5033 bytes | Created Date = 2008-01-21 19:54:20 | Attr = ]
pos663.tmp -> %SystemDrive%\pos663.tmp -> [Ver = | Size = 9033 bytes | Created Date = 2008-01-21 19:54:20 | Attr = ]
pos664.tmp -> %SystemDrive%\pos664.tmp -> [Ver = | Size = 8033 bytes | Created Date = 2008-01-21 19:54:20 | Attr = ]
pos665.tmp -> %SystemDrive%\pos665.tmp -> [Ver = | Size = 9033 bytes | Created Date = 2008-01-21 19:54:20 | Attr = ]
pos666.tmp -> %SystemDrive%\pos666.tmp -> [Ver = | Size = 9033 bytes | Created Date = 2008-01-21 19:54:20 | Attr = ]
pos667.tmp -> %SystemDrive%\pos667.tmp -> [Ver = | Size = 10033 bytes | Created Date = 2008-01-21 19:54:20 | Attr = ]
pos668.tmp -> %SystemDrive%\pos668.tmp -> [Ver = | Size = 11033 bytes | Created Date = 2008-01-21 19:54:20 | Attr = ]
pos669.tmp -> %SystemDrive%\pos669.tmp -> [Ver = | Size = 9033 bytes | Created Date = 2008-01-21 19:54:20 | Attr = ]
pos66A.tmp -> %SystemDrive%\pos66A.tmp -> [Ver = | Size = 10033 bytes | Created Date = 2008-01-21 19:54:20 | Attr = ]
pos66B.tmp -> %SystemDrive%\pos66B.tmp -> [Ver = | Size = 5033 bytes | Created Date = 2008-01-21 19:54:20 | Attr = ]
pos66C.tmp -> %SystemDrive%\pos66C.tmp -> [Ver = | Size = 6033 bytes | Created Date = 2008-01-21 19:54:20 | Attr = ]
pos66D.tmp -> %SystemDrive%\pos66D.tmp -> [Ver = | Size = 5033 bytes | Created Date = 2008-01-21 19:54:20 | Attr = ]
pos66E.tmp -> %SystemDrive%\pos66E.tmp -> [Ver = | Size = 9033 bytes | Created Date = 2008-01-21 19:54:20 | Attr = ]
pos66F.tmp -> %SystemDrive%\pos66F.tmp -> [Ver = | Size = 9033 bytes | Created Date = 2008-01-21 19:54:20 | Attr = ]
pos670.tmp -> %SystemDrive%\pos670.tmp -> [Ver = | Size = 11033 bytes | Created Date = 2008-01-21 19:54:20 | Attr = ]
pos671.tmp -> %SystemDrive%\pos671.tmp -> [Ver = | Size = 5033 bytes | Created Date = 2008-01-21 19:54:21 | Attr = ]
pos672.tmp -> %SystemDrive%\pos672.tmp -> [Ver = | Size = 12033 bytes | Created Date = 2008-01-21 19:54:21 | Attr = ]
pos673.tmp -> %SystemDrive%\pos673.tmp -> [Ver = | Size = 14033 bytes | Created Date = 2008-01-21 19:54:21 | Attr = ]
pos674.tmp -> %SystemDrive%\pos674.tmp -> [Ver = | Size = 13033 bytes | Created Date = 2008-01-21 19:54:21 | Attr = ]
pos675.tmp -> %SystemDrive%\pos675.tmp -> [Ver = | Size = 11033 bytes | Created Date = 2008-01-21 19:54:21 | Attr = ]
pos676.tmp -> %SystemDrive%\pos676.tmp -> [Ver = | Size = 10033 bytes | Created Date = 2008-01-21 19:54:21 | Attr = ]
pos677.tmp -> %SystemDrive%\pos677.tmp -> [Ver = | Size = 7033 bytes | Created Date = 2008-01-21 19:54:21 | Attr = ]
pos678.tmp -> %SystemDrive%\pos678.tmp -> [Ver = | Size = 10033 bytes | Created Date = 2008-01-21 19:54:21 | Attr = ]
pos679.tmp -> %SystemDrive%\pos679.tmp -> [Ver = | Size = 13033 bytes | Created Date = 2008-01-21 19:54:21 | Attr = ]
pos67A.tmp -> %SystemDrive%\pos67A.tmp -> [Ver = | Size = 12033 bytes | Created Date = 2008-01-21 19:54:21 | Attr = ]
pos67B.tmp -> %SystemDrive%\pos67B.tmp -> [Ver = | Size = 10033 bytes | Created Date = 2008-01-21 19:54:21 | Attr = ]
pos67C.tmp -> %SystemDrive%\pos67C.tmp -> [Ver = | Size = 13033 bytes | Created Date = 2008-01-21 19:54:21 | Attr = ]
pos67D.tmp -> %SystemDrive%\pos67D.tmp -> [Ver = | Size = 13033 bytes | Created Date = 2008-01-21 19:54:21 | Attr = ]
pos67E.tmp -> %SystemDrive%\pos67E.tmp -> [Ver = | Size = 6033 bytes | Created Date = 2008-01-21 19:54:21 | Attr = ]
pos67F.tmp -> %SystemDrive%\pos67F.tmp -> [Ver = | Size = 11033 bytes | Created Date = 2008-01-21 19:54:21 | Attr = ]
pos680.tmp -> %SystemDrive%\pos680.tmp -> [Ver = | Size = 13033 bytes | Created Date = 2008-01-21 19:54:21 | Attr = ]
pos681.tmp -> %SystemDrive%\pos681.tmp -> [Ver = | Size = 9033 bytes | Created Date = 2008-01-21 19:54:21 | Attr = ]
pos682.tmp -> %SystemDrive%\pos682.tmp -> [Ver = | Size = 6033 bytes | Created Date = 2008-01-21 19:54:21 | Attr = ]
pos683.tmp -> %SystemDrive%\pos683.tmp -> [Ver = | Size = 10033 bytes | Created Date = 2008-01-21 19:54:21 | Attr = ]
pos684.tmp -> %SystemDrive%\pos684.tmp -> [Ver = | Size = 10033 bytes | Created Date = 2008-01-21 19:54:21 | Attr = ]
pos685.tmp -> %SystemDrive%\pos685.tmp -> [Ver = | Size = 10033 bytes | Created Date = 2008-01-21 19:54:21 | Attr = ]
pos686.tmp -> %SystemDrive%\pos686.tmp -> [Ver = | Size = 14033 bytes | Created Date = 2008-01-21 19:54:22 | Attr = ]
pos687.tmp -> %SystemDrive%\pos687.tmp -> [Ver = | Size = 13033 bytes | Created Date = 2008-01-21 19:54:22 | Attr = ]
pos688.tmp -> %SystemDrive%\pos688.tmp -> [Ver = | Size = 11033 bytes | Created Date = 2008-01-21 19:54:22 | Attr = ]
pos689.tmp -> %SystemDrive%\pos689.tmp -> [Ver = | Size = 9033 bytes | Created Date = 2008-01-21 19:54:22 | Attr = ]
pos68A.tmp -> %SystemDrive%\pos68A.tmp -> [Ver = | Size = 8033 bytes | Created Date = 2008-01-21 19:54:22 | Attr = ]
pos68B.tmp -> %SystemDrive%\pos68B.tmp -> [Ver = | Size = 10033 bytes | Created Date = 2008-01-21 19:54:22 | Attr = ]
pos68C.tmp -> %SystemDrive%\pos68C.tmp -> [Ver = | Size = 14033 bytes | Created Date = 2008-01-21 19:54:22 | Attr = ]
pos68D.tmp -> %SystemDrive%\pos68D.tmp -> [Ver = | Size = 14033 bytes | Created Date = 2008-01-21 19:54:22 | Attr = ]
pos68E.tmp -> %SystemDrive%\pos68E.tmp -> [Ver = | Size = 8033 bytes | Created Date = 2008-01-21 19:54:22 | Attr = ]
pos68F.tmp -> %SystemDrive%\pos68F.tmp -> [Ver = | Size = 6033 bytes | Created Date = 2008-01-21 19:54:22 | Attr = ]
pos690.tmp -> %SystemDrive%\pos690.tmp -> [Ver = | Size = 11033 bytes | Created Date = 2008-01-21 19:54:22 | Attr = ]
pos691.tmp -> %SystemDrive%\pos691.tmp -> [Ver = | Size = 14033 bytes | Created Date = 2008-01-21 19:54:22 | Attr = ]
pos692.tmp -> %SystemDrive%\pos692.tmp -> [Ver = | Size = 14033 bytes | Created Date = 2008-01-21 19:54:22 | Attr = ]
pos693.tmp -> %SystemDrive%\pos693.tmp -> [Ver = | Size = 6033 bytes | Created Date = 2008-01-21 19:54:22 | Attr = ]
pos694.tmp -> %SystemDrive%\pos694.tmp -> [Ver = | Size = 6033 bytes | Created Date = 2008-01-21 19:54:22 | Attr = ]
pos695.tmp -> %SystemDrive%\pos695.tmp -> [Ver = | Size = 14033 bytes | Created Date = 2008-01-21 19:54:22 | Attr = ]
pos696.tmp -> %SystemDrive%\pos696.tmp -> [Ver = | Size = 12033 bytes | Created Date = 2008-01-21 19:54:22 | Attr = ]
pos697.tmp -> %SystemDrive%\pos697.tmp -> [Ver = | Size = 7033 bytes | Created Date = 2008-01-21 19:54:22 | Attr = ]
pos698.tmp -> %SystemDrive%\pos698.tmp -> [Ver = | Size = 7033 bytes | Created Date = 2008-01-21 19:54:22 | Attr = ]
pos699.tmp -> %SystemDrive%\pos699.tmp -> [Ver = | Size = 9033 bytes | Created Date = 2008-01-21 19:54:22 | Attr = ]
pos69A.tmp -> %SystemDrive%\pos69A.tmp -> [Ver = | Size = 7033 bytes | Created Date = 2008-01-21 19:54:22 | Attr = ]
pos69B.tmp -> %SystemDrive%\pos69B.tmp -> [Ver = | Size = 12033 bytes | Created Date = 2008-01-21 19:54:23 | Attr = ]
pos69C.tmp -> %SystemDrive%\pos69C.tmp -> [Ver = | Size = 9033 bytes | Created Date = 2008-01-21 19:54:23 | Attr = ]
pos69D.tmp -> %SystemDrive%\pos69D.tmp -> [Ver = | Size = 9033 bytes | Created Date = 2008-01-21 19:54:23 | Attr = ]
pos69E.tmp -> %SystemDrive%\pos69E.tmp -> [Ver = | Size = 6033 bytes | Created Date = 2008-01-21 19:54:23 | Attr = ]
pos69F.tmp -> %SystemDrive%\pos69F.tmp -> [Ver = | Size = 7033 bytes | Created Date = 2008-01-21 19:54:23 | Attr = ]
pos6A0.tmp -> %SystemDrive%\pos6A0.tmp -> [Ver = | Size = 8033 bytes | Created Date = 2008-01-21 19:54:23 | Attr = ]
pos6A1.tmp -> %SystemDrive%\pos6A1.tmp -> [Ver = | Size = 11033 bytes | Created Date = 2008-01-21 19:54:23 | Attr = ]
pos6A2.tmp -> %SystemDrive%\pos6A2.tmp -> [Ver = | Size = 10033 bytes | Created Date = 2008-01-21 19:54:23 | Attr = ]
pos6A3.tmp -> %SystemDrive%\pos6A3.tmp -> [Ver = | Size = 11033 bytes | Created Date = 2008-01-21 19:54:23 | Attr = ]
pos6A4.tmp -> %SystemDrive%\pos6A4.tmp -> [Ver = | Size = 11033 bytes | Created Date = 2008-01-21 19:54:23 | Attr = ]
pos6A5.tmp -> %SystemDrive%\pos6A5.tmp -> [Ver = | Size = 12033 bytes | Created Date = 2008-01-21 19:54:23 | Attr = ]
pos6A6.tmp -> %SystemDrive%\pos6A6.tmp -> [Ver = | Size = 13033 bytes | Created Date = 2008-01-21 19:54:23 | Attr = ]
pos6A7.tmp -> %SystemDrive%\pos6A7.tmp -> [Ver = | Size = 14033 bytes | Created Date = 2008-01-21 19:54:23 | Attr = ]
pos6A8.tmp -> %SystemDrive%\pos6A8.tmp -> [Ver = | Size = 14033 bytes | Created Date = 2008-01-21 19:54:23 | Attr = ]
pos6A9.tmp -> %SystemDrive%\pos6A9.tmp -> [Ver = | Size = 14033 bytes | Created Date = 2008-01-21 19:54:23 | Attr = ]
pos6AA.tmp -> %SystemDrive%\pos6AA.tmp -> [Ver = | Size = 5033 bytes | Created Date = 2008-01-21 19:54:23 | Attr = ]
pos6AB.tmp -> %SystemDrive%\pos6AB.tmp -> [Ver = | Size = 8033 bytes | Created Date = 2008-01-21 19:54:23 | Attr = ]
pos6AC.tmp -> %SystemDrive%\pos6AC.tmp -> [Ver = | Size = 12033 bytes | Created Date = 2008-01-21 19:54:23 | Attr = ]
pos6AD.tmp -> %SystemDrive%\pos6AD.tmp -> [Ver = | Size = 7033 bytes | Created Date = 2008-01-21 19:54:24 | Attr = ]
pos6AE.tmp -> %SystemDrive%\pos6AE.tmp -> [Ver = | Size = 6033 bytes | Created Date = 2008-01-21 19:54:24 | Attr = ]
pos6AF.tmp -> %SystemDrive%\pos6AF.tmp -> [Ver = | Size = 12033 bytes | Created Date = 2008-01-21 19:54:24 | Attr = ]
pos6B0.tmp -> %SystemDrive%\pos6B0.tmp -> [Ver = | Size = 12033 bytes | Created Date = 2008-01-21 19:54:24 | Attr = ]
pos6B1.tmp -> %SystemDrive%\pos6B1.tmp -> [Ver = | Size = 7033 bytes | Created Date = 2008-01-21 19:54:24 | Attr = ]
pos6B2.tmp -> %SystemDrive%\pos6B2.tmp -> [Ver = | Size = 7033 bytes | Created Date = 2008-01-21 19:54:24 | Attr = ]
pos6B3.tmp -> %SystemDrive%\pos6B3.tmp -> [Ver = | Size = 8033 bytes | Created Date = 2008-01-21 19:54:24 | Attr = ]
pos6B4.tmp -> %SystemDrive%\pos6B4.tmp -> [Ver = | Size = 10033 bytes | Created Date = 2008-01-21 19:54:24 | Attr = ]
pos6B5.tmp -> %SystemDrive%\pos6B5.tmp -> [Ver = | Size = 6033 bytes | Created Date = 2008-01-21 19:54:24 | Attr = ]
pos6B6.tmp -> %SystemDrive%\pos6B6.tmp -> [Ver = | Size = 10033 bytes | Created Date = 2008-01-21 19:54:24 | Attr = ]
pos6B7.tmp -> %SystemDrive%\pos6B7.tmp -> [Ver = | Size = 6033 bytes | Created Date = 2008-01-21 19:54:24 | Attr = ]
pos6B8.tmp -> %SystemDrive%\pos6B8.tmp -> [Ver = | Size = 8033 bytes | Created Date = 2008-01-21 19:54:24 | Attr = ]
pos6B9.tmp -> %SystemDrive%\pos6B9.tmp -> [Ver = | Size = 9033 bytes | Created Date = 2008-01-21 19:54:25 | Attr = ]
pos6BA.tmp -> %SystemDrive%\pos6BA.tmp -> [Ver = | Size = 13033 bytes | Created Date = 2008-01-21 19:54:25 | Attr = ]
pos6BB.tmp -> %SystemDrive%\pos6BB.tmp -> [Ver = | Size = 6033 bytes | Created Date = 2008-01-21 19:54:25 | Attr = ]
pos6BC.tmp -> %SystemDrive%\pos6BC.tmp -> [Ver = | Size = 14033 bytes | Created Date = 2008-01-21 19:54:25 | Attr = ]
pos6BD.tmp -> %SystemDrive%\pos6BD.tmp -> [Ver = | Size = 12033 bytes | Created Date = 2008-01-21 19:54:25 | Attr = ]
pos6BE.tmp -> %SystemDrive%\pos6BE.tmp -> [Ver = | Size = 10033 bytes | Created Date = 2008-01-21 19:54:25 | Attr = ]
pos6BF.tmp -> %SystemDrive%\pos6BF.tmp -> [Ver = | Size = 12033 bytes | Created Date = 2008-01-21 19:54:25 | Attr = ]
pos6C0.tmp -> %SystemDrive%\pos6C0.tmp -> [Ver = | Size = 13033 bytes | Created Date = 2008-01-21 19:54:25 | Attr = ]
pos6C1.tmp -> %SystemDrive%\pos6C1.tmp -> [Ver = | Size = 9033 bytes | Created Date = 2008-01-21 19:54:25 | Attr = ]
pos6C2.tmp -> %SystemDrive%\pos6C2.tmp -> [Ver = | Size = 7033 bytes | Created Date = 2008-01-21 19:54:25 | Attr = ]
pos6C3.tmp -> %SystemDrive%\pos6C3.tmp -> [Ver = | Size = 6033 bytes | Created Date = 2008-01-21 19:54:25 | Attr = ]
pos6C4.tmp -> %SystemDrive%\pos6C4.tmp -> [Ver = | Size = 8033 bytes | Created Date = 2008-01-21 19:54:25 | Attr = ]
pos6C5.tmp -> %SystemDrive%\pos6C5.tmp -> [Ver = | Size = 10033 bytes | Created Date = 2008-01-21 19:54:25 | Attr = ]
pos6C6.tmp -> %SystemDrive%\pos6C6.tmp -> [Ver = | Size = 13033 bytes | Created Date = 2008-01-21 19:54:26 | Attr = ]
pos6C7.tmp -> %SystemDrive%\pos6C7.tmp -> [Ver = | Size = 13033 bytes | Created Date = 2008-01-21 19:54:26 | Attr = ]
pos6C8.tmp -> %SystemDrive%\pos6C8.tmp -> [Ver = | Size = 12033 bytes | Created Date = 2008-01-21 19:54:26 | Attr = ]
pos6C9.tmp -> %SystemDrive%\pos6C9.tmp -> [Ver = | Size = 14033 bytes | Created Date = 2008-01-21 19:54:26 | Attr = ]
pos6CA.tmp -> %SystemDrive%\pos6CA.tmp -> [Ver = | Size = 12033 bytes | Created Date = 2008-01-21 19:54:26 | Attr = ]
pos6CB.tmp -> %SystemDrive%\pos6CB.tmp -> [Ver = | Size = 14033 bytes | Created Date = 2008-01-21 19:54:26 | Attr = ]
pos6CC.tmp -> %SystemDrive%\pos6CC.tmp -> [Ver = | Size = 6033 bytes | Created Date = 2008-01-21 19:54:26 | Attr = ]
pos6CD.tmp -> %SystemDrive%\pos6CD.tmp -> [Ver = | Size = 9033 bytes | Created Date = 2008-01-21 19:54:26 | Attr = ]
pos6CE.tmp -> %SystemDrive%\pos6CE.tmp -> [Ver = | Size = 12033 bytes | Created Date = 2008-01-21 19:54:26 | Attr = ]
pos6CF.tmp -> %SystemDrive%\pos6CF.tmp -> [Ver = | Size = 6033 bytes | Created Date = 2008-01-21 19:54:26 | Attr = ]
pos6D0.tmp -> %SystemDrive%\pos6D0.tmp -> [Ver = | Size = 11033 bytes | Created Date = 2008-01-21 19:54:26 | Attr = ]
pos6D1.tmp -> %SystemDrive%\pos6D1.tmp -> [Ver = | Size = 10033 bytes | Created Date = 2008-01-21 19:54:26 | Attr = ]
pos6D2.tmp -> %SystemDrive%\pos6D2.tmp -> [Ver = | Size = 13033 bytes | Created Date = 2008-01-21 19:54:26 | Attr = ]
pos6D3.tmp -> %SystemDrive%\pos6D3.tmp -> [Ver = | Size = 8033 bytes | Created Date = 2008-01-21 19:54:27 | Attr = ]
pos6D4.tmp -> %SystemDrive%\pos6D4.tmp -> [Ver = | Size = 10033 bytes | Created Date = 2008-01-21 19:54:27 | Attr = ]
pos6D5.tmp -> %SystemDrive%\pos6D5.tmp -> [Ver = | Size = 6033 bytes | Created Date = 2008-01-21 19:54:27 | Attr = ]
pos6D6.tmp -> %SystemDrive%\pos6D6.tmp -> [Ver = | Size = 7033 bytes | Created Date = 2008-01-21 19:54:27 | Attr = ]
pos6D7.tmp -> %SystemDrive%\pos6D7.tmp -> [Ver = | Size = 13033 bytes | Created Date = 2008-01-21 19:54:27 | Attr = ]
pos6D8.tmp -> %SystemDrive%\pos6D8.tmp -> [Ver = | Size = 8033 bytes | Created Date = 2008-01-21 19:54:27 | Attr = ]
pos6D9.tmp -> %SystemDrive%\pos6D9.tmp -> [Ver = | Size = 8033 bytes | Created Date = 2008-01-21 19:54:27 | Attr = ]
pos6DA.tmp -> %SystemDrive%\pos6DA.tmp -> [Ver = | Size = 12033 bytes | Created Date = 2008-01-21 19:54:27 | Attr = ]
pos6DB.tmp -> %SystemDrive%\pos6DB.tmp -> [Ver = | Size = 8033 bytes | Created Date = 2008-01-21 19:54:27 | Attr = ]
pos6DC.tmp -> %SystemDrive%\pos6DC.tmp -> [Ver = | Size = 11033 bytes | Created Date = 2008-01-21 19:54:27 | Attr = ]
pos6DD.tmp -> %SystemDrive%\pos6DD.tmp -> [Ver = | Size = 11033 bytes | Created Date = 2008-01-21 19:54:27 | Attr = ]
pos6DE.tmp -> %SystemDrive%\pos6DE.tmp -> [Ver = | Size = 13033 bytes | Created Date = 2008-01-21 19:54:27 | Attr = ]
pos6DF.tmp -> %SystemDrive%\pos6DF.tmp -> [Ver = | Size = 11033 bytes | Created Date = 2008-01-21 19:54:27 | Attr = ]
pos6E0.tmp -> %SystemDrive%\pos6E0.tmp -> [Ver = | Size = 12033 bytes | Created Date = 2008-01-21 19:54:27 | Attr = ]
pos6E1.tmp -> %SystemDrive%\pos6E1.tmp -> [Ver = | Size = 7033 bytes | Created Date = 2008-01-21 19:54:27 | Attr = ]
pos6E2.tmp -> %SystemDrive%\pos6E2.tmp -> [Ver = | Size = 9033 bytes | Created Date = 2008-01-21 19:54:27 | Attr = ]
pos6E3.tmp -> %SystemDrive%\pos6E3.tmp -> [Ver = | Size = 6033 bytes | Created Date = 2008-01-21 19:54:27 | Attr = ]
pos6E4.tmp -> %SystemDrive%\pos6E4.tmp -> [Ver = | Size = 9033 bytes | Created Date = 2008-01-21 19:54:27 | Attr = ]
pos6E5.tmp -> %SystemDrive%\pos6E5.tmp -> [Ver = | Size = 10033 bytes | Created Date = 2008-01-21 19:54:27 | Attr = ]
pos6E6.tmp -> %SystemDrive%\pos6E6.tmp -> [Ver = | Size = 12033 bytes | Created Date = 2008-01-21 19:54:27 | Attr = ]
pos6E7.tmp -> %SystemDrive%\pos6E7.tmp -> [Ver = | Size = 6033 bytes | Created Date = 2008-01-21 19:54:28 | Attr = ]
pos6E8.tmp -> %SystemDrive%\pos6E8.tmp -> [Ver = | Size = 14033 bytes | Created Date = 2008-01-21 19:54:28 | Attr = ]
pos6E9.tmp -> %SystemDrive%\pos6E9.tmp -> [Ver = | Size = 9033 bytes | Created Date = 2008-01-21 19:54:28 | Attr = ]
pos6EA.tmp -> %SystemDrive%\pos6EA.tmp -> [Ver = | Size = 10033 bytes | Created Date = 2008-01-21 19:54:28 | Attr = ]
pos6EB.tmp -> %SystemDrive%\pos6EB.tmp -> [Ver = | Size = 9033 bytes | Created Date = 2008-01-21 19:54:28 | Attr = ]
pos6EC.tmp -> %SystemDrive%\pos6EC.tmp -> [Ver = | Size = 8033 bytes | Created Date = 2008-01-21 19:54:28 | Attr = ]
pos6ED.tmp -> %SystemDrive%\pos6ED.tmp -> [Ver = | Size = 9033 bytes | Created Date = 2008-01-21 19:54:28 | Attr = ]
pos6EE.tmp -> %SystemDrive%\pos6EE.tmp -> [Ver = | Size = 12033 bytes | Created Date = 2008-01-21 19:54:28 | Attr = ]
pos6EF.tmp -> %SystemDrive%\pos6EF.tmp -> [Ver = | Size = 11033 bytes | Created Date = 2008-01-21 19:54:28 | Attr = ]
pos6F0.tmp -> %SystemDrive%\pos6F0.tmp -> [Ver = | Size = 7033 bytes | Created Date = 2008-01-21 19:54:28 | Attr = ]
pos6F1.tmp -> %SystemDrive%\pos6F1.tmp -> [Ver = | Size = 9033 bytes | Created Date = 2008-01-21 19:54:28 | Attr = ]
pos6F2.tmp -> %SystemDrive%\pos6F2.tmp -> [Ver = | Size = 11033 bytes | Created Date = 2008-01-21 19:54:28 | Attr = ]
pos6F3.tmp -> %SystemDrive%\pos6F3.tmp -> [Ver = | Size = 9033 bytes | Created Date = 2008-01-21 19:54:28 | Attr = ]
pos6F4.tmp -> %SystemDrive%\pos6F4.tmp -> [Ver = | Size = 11033 bytes | Created Date = 2008-01-21 19:54:28 | Attr = ]
pos6F5.tmp -> %SystemDrive%\pos6F5.tmp -> [Ver = | Size = 12033 bytes | Created Date = 2008-01-21 19:54:28 | Attr = ]
pos6F6.tmp -> %SystemDrive%\pos6F6.tmp -> [Ver = | Size = 9033 bytes | Created Date = 2008-01-21 19:54:28 | Attr = ]
pos6F7.tmp -> %SystemDrive%\pos6F7.tmp -> [Ver = | Size = 8033 bytes | Created Date = 2008-01-21 19:54:28 | Attr = ]
pos6F8.tmp -> %SystemDrive%\pos6F8.tmp -> [Ver = | Size = 7033 bytes | Created Date = 2008-01-21 19:54:28 | Attr = ]
pos6F9.tmp -> %SystemDrive%\pos6F9.tmp -> [Ver = | Size = 12033 bytes | Created Date = 2008-01-21 19:54:28 | Attr = ]
pos6FA.tmp -> %SystemDrive%\pos6FA.tmp -> [Ver = | Size = 14033 bytes | Created Date = 2008-01-21 19:54:28 | Attr = ]
pos6FB.tmp -> %SystemDrive%\pos6FB.tmp -> [Ver = | Size = 12033 bytes | Created Date = 2008-01-21 19:54:28 | Attr = ]
pos6FC.tmp -> %SystemDrive%\pos6FC.tmp -> [Ver = | Size = 13033 bytes | Created Date = 2008-01-21 19:54:28 | Attr = ]
pos6FD.tmp -> %SystemDrive%\pos6FD.tmp -> [Ver = | Size = 6033 bytes | Created Date = 2008-01-21 19:54:29 | Attr = ]
pos6FE.tmp -> %SystemDrive%\pos6FE.tmp -> [Ver = | Size = 11033 bytes | Created Date = 2008-01-21 19:54:29 | Attr = ]
pos6FF.tmp -> %SystemDrive%\pos6FF.tmp -> [Ver = | Size = 6033 bytes | Created Date = 2008-01-21 19:54:29 | Attr = ]
pos700.tmp -> %SystemDrive%\pos700.tmp -> [Ver = | Size = 8033 bytes | Created Date = 2008-01-21 19:54:29 | Attr = ]
pos701.tmp -> %SystemDrive%\pos701.tmp -> [Ver = | Size = 10033 bytes | Created Date = 2008-01-21 19:54:29 | Attr = ]
pos702.tmp -> %SystemDrive%\pos702.tmp -> [Ver = | Size = 5033 bytes | Created Date = 2008-01-21 19:54:29 | Attr = ]
pos703.tmp -> %SystemDrive%\pos703.tmp -> [Ver = | Size = 7033 bytes | Created Date = 2008-01-21 19:54:29 | Attr = ]
pos704.tmp -> %SystemDrive%\pos704.tmp -> [Ver = | Size = 9033 bytes | Created Date = 2008-01-21 19:54:29 | Attr = ]
pos705.tmp -> %SystemDrive%\pos705.tmp -> [Ver = | Size = 10033 bytes | Created Date = 2008-01-21 19:54:29 | Attr = ]
pos706.tmp -> %SystemDrive%\pos706.tmp -> [Ver = | Size = 11033 bytes | Created Date = 2008-01-21 19:54:29 | Attr = ]
pos707.tmp -> %SystemDrive%\pos707.tmp -> [Ver = | Size = 13033 bytes | Created Date = 2008-01-21 19:54:29 | Attr = ]
pos708.tmp -> %SystemDrive%\pos708.tmp -> [Ver = | Size = 10033 bytes | Created Date = 2008-01-21 19:54:29 | Attr = ]
pos709.tmp -> %SystemDrive%\pos709.tmp -> [Ver = | Size = 10033 bytes | Created Date = 2008-01-21 19:54:29 | Attr = ]
pos70A.tmp -> %SystemDrive%\pos70A.tmp -> [Ver = | Size = 10033 bytes | Created Date = 2008-01-21 19:54:29 | Attr = ]
pos70B.tmp -> %SystemDrive%\pos70B.tmp -> [Ver = | Size = 9033 bytes | Created Date = 2008-01-21 19:54:29 | Attr = ]
pos70C.tmp -> %SystemDrive%\pos70C.tmp -> [Ver = | Size = 5033 bytes | Created Date = 2008-01-21 19:54:29 | Attr = ]
pos70D.tmp -> %SystemDrive%\pos70D.tmp -> [Ver = | Size = 5033 bytes | Created Date = 2008-01-21 19:54:29 | Attr = ]
pos70E.tmp -> %SystemDrive%\pos70E.tmp -> [Ver = | Size = 7033 bytes | Created Date = 2008-01-21 19:54:29 | Attr = ]
pos70F.tmp -> %SystemDrive%\pos70F.tmp -> [Ver = | Size = 12033 bytes | Created Date = 2008-01-21 19:54:29 | Attr = ]
pos710.tmp -> %SystemDrive%\pos710.tmp -> [Ver = | Size = 9033 bytes | Created Date = 2008-01-21 19:54:29 | Attr = ]
pos711.tmp -> %SystemDrive%\pos711.tmp -> [Ver = | Size = 8033 bytes | Created Date = 2008-01-21 19:54:29 | Attr = ]
pos712.tmp -> %SystemDrive%\pos712.tmp -> [Ver = | Size = 9033 bytes | Created Date = 2008-01-21 19:54:29 | Attr = ]
pos713.tmp -> %SystemDrive%\pos713.tmp -> [Ver = | Size = 8033 bytes | Created Date = 2008-01-21 19:54:29 | Attr = ]
pos714.tmp -> %SystemDrive%\pos714.tmp -> [Ver = | Size = 14033 bytes | Created Date = 2008-01-21 19:54:30 | Attr = ]
pos715.tmp -> %SystemDrive%\pos715.tmp -> [Ver = | Size = 11033 bytes | Created Date = 2008-01-21 19:54:30 | Attr = ]
pos716.tmp -> %SystemDrive%\pos716.tmp -> [Ver = | Size = 6033 bytes | Created Date = 2008-01-21 19:54:30 | Attr = ]
pos717.tmp -> %SystemDrive%\pos717.tmp -> [Ver = | Size = 11033 bytes | Created Date = 2008-01-21 19:54:30 | Attr = ]
pos718.tmp -> %SystemDrive%\pos718.tmp -> [Ver = | Size = 11033 bytes | Created Date = 2008-01-21 19:54:30 | Attr = ]
pos719.tmp -> %SystemDrive%\pos719.tmp -> [Ver = | Size = 13033 bytes | Created Date = 2008-01-21 19:54:30 | Attr = ]
pos71A.tmp -> %SystemDrive%\pos71A.tmp -> [Ver = | Size = 13033 bytes | Created Date = 2008-01-21 19:54:30 | Attr = ]
pos71B.tmp -> %SystemDrive%\pos71B.tmp -> [Ver = | Size = 11033 bytes | Created Date = 2008-01-21 19:54:30 | Attr = ]
pos71C.tmp -> %SystemDrive%\pos71C.tmp -> [Ver = | Size = 7033 bytes | Created Date = 2008-01-21 19:54:30 | Attr = ]
pos71D.tmp -> %SystemDrive%\pos71D.tmp -> [Ver = | Size = 9033 bytes | Created Date = 2008-01-21 19:54:30 | Attr = ]
pos71E.tmp -> %SystemDrive%\pos71E.tmp -> [Ver = | Size = 12033 bytes | Created Date = 2008-01-21 19:54:30 | Attr = ]
pos71F.tmp -> %SystemDrive%\pos71F.tmp -> [Ver = | Size = 5033 bytes | Created Date = 2008-01-21 19:54:30 | Attr = ]
pos720.tmp -> %SystemDrive%\pos720.tmp -> [Ver = | Size = 10033 bytes | Created Date = 2008-01-21 19:54:30 | Attr = ]
pos721.tmp -> %SystemDrive%\pos721.tmp -> [Ver = | Size = 7033 bytes | Created Date = 2008-01-21 19:54:30 | Attr = ]
pos722.tmp -> %SystemDrive%\pos722.tmp -> [Ver = | Size = 5033 bytes | Created Date = 2008-01-21 19:54:30 | Attr = ]
pos723.tmp -> %SystemDrive%\pos723.tmp -> [Ver = | Size = 9033 bytes | Created Date = 2008-01-21 19:54:30 | Attr = ]
pos724.tmp -> %SystemDrive%\pos724.tmp -> [Ver = | Size = 6033 bytes | Created Date = 2008-01-21 19:54:30 | Attr = ]
pos725.tmp -> %SystemDrive%\pos725.tmp -> [Ver = | Size = 11033 bytes | Created Date = 2008-01-21 19:54:30 | Attr = ]
pos726.tmp -> %SystemDrive%\pos726.tmp -> [Ver = | Size = 8033 bytes | Created Date = 2008-01-21 19:54:30 | Attr = ]
pos727.tmp -> %SystemDrive%\pos727.tmp -> [Ver = | Size = 14033 bytes | Created Date = 2008-01-21 19:54:30 | Attr = ]
pos728.tmp -> %SystemDrive%\pos728.tmp -> [Ver = | Size = 10033 bytes | Created Date = 2008-01-21 19:54:30 | Attr = ]
pos729.tmp -> %SystemDrive%\pos729.tmp -> [Ver = | Size = 8033 bytes | Created Date = 2008-01-21 19:54:30 | Attr = ]
pos72A.tmp -> %SystemDrive%\pos72A.tmp -> [Ver = | Size = 5033 bytes | Created Date = 2008-01-21 19:54:30 | Attr = ]
pos72B.tmp -> %SystemDrive%\pos72B.tmp -> [Ver = | Size = 12033 bytes | Created Date = 2008-01-21 19:54:31 | Attr = ]
pos7BA.tmp -> %SystemDrive%\pos7BA.tmp -> [Ver = | Size = 5033 bytes | Created Date = 2008-01-21 20:15:02 | Attr = ]
pos7BB.tmp -> %SystemDrive%\pos7BB.tmp -> [Ver = | Size = 5033 bytes | Created Date = 2008-01-21 20:15:02 | Attr = ]
pos7BC.tmp -> %SystemDrive%\pos7BC.tmp -> [Ver = | Size = 13033 bytes | Created Date = 2008-01-21 20:15:02 | Attr = ]
pos7BD.tmp -> %SystemDrive%\pos7BD.tmp -> [Ver = | Size = 11033 bytes | Created Date = 2008-01-21 20:15:02 | Attr = ]
pos7BE.tmp -> %SystemDrive%\pos7BE.tmp -> [Ver = | Size = 10033 bytes | Created Date = 2008-01-21 20:15:02 | Attr = ]
pos7BF.tmp -> %SystemDrive%\pos7BF.tmp -> [Ver = | Size = 9033 bytes | Created Date = 2008-01-21 20:15:03 | Attr = ]
pos7C0.tmp -> %SystemDrive%\pos7C0.tmp -> [Ver = | Size = 9033 bytes | Created Date = 2008-01-21 20:15:03 | Attr = ]
pos7C1.tmp -> %SystemDrive%\pos7C1.tmp -> [Ver = | Size = 8033 bytes | Created Date = 2008-01-21 20:15:03 | Attr = ]
pos7C2.tmp -> %SystemDrive%\pos7C2.tmp -> [Ver = | Size = 10033 bytes | Created Date = 2008-01-21 20:15:03 | Attr = ]
pos7C3.tmp -> %SystemDrive%\pos7C3.tmp -> [Ver = | Size = 8033 bytes | Created Date = 2008-01-21 20:15:03 | Attr = ]
pos7C4.tmp -> %SystemDrive%\pos7C4.tmp -> [Ver = | Size = 6033 bytes | Created Date = 2008-01-21 20:15:04 | Attr = ]
pos7C5.tmp -> %SystemDrive%\pos7C5.tmp -> [Ver = | Size = 5033 bytes | Created Date = 2008-01-21 20:15:04 | Attr = ]
pos7C6.tmp -> %SystemDrive%\pos7C6.tmp -> [Ver = | Size = 14033 bytes | Created Date = 2008-01-21 20:15:04 | Attr = ]
pos7C7.tmp -> %SystemDrive%\pos7C7.tmp -> [Ver = | Size = 7033 bytes | Created Date = 2008-01-21 20:15:04 | Attr = ]
pos7C8.tmp -> %SystemDrive%\pos7C8.tmp -> [Ver = | Size = 6033 bytes | Created Date = 2008-01-21 20:15:04 | Attr = ]
pos7C9.tmp -> %SystemDrive%\pos7C9.tmp -> [Ver = | Size = 5033 bytes | Created Date = 2008-01-21 20:15:04 | Attr = ]
pos7CA.tmp -> %SystemDrive%\pos7CA.tmp -> [Ver = | Size = 14033 bytes | Created Date = 2008-01-21 20:15:04 | Attr = ]
pos7CB.tmp -> %SystemDrive%\pos7CB.tmp -> [Ver = | Size = 8033 bytes | Created Date = 2008-01-21 20:15:04 | Attr = ]
pos7CC.tmp -> %SystemDrive%\pos7CC.tmp -> [Ver = | Size = 12033 bytes | Created Date = 2008-01-21 20:15:05 | Attr = ]
pos7CD.tmp -> %SystemDrive%\pos7CD.tmp -> [Ver = | Size = 13033 bytes | Created Date = 2008-01-21 20:15:05 | Attr = ]
pos7CE.tmp -> %SystemDrive%\pos7CE.tmp -> [Ver = | Size = 9033 bytes | Created Date = 2008-01-21 20:15:05 | Attr = ]
pos7CF.tmp -> %SystemDrive%\pos7CF.tmp -> [Ver = | Size = 8033 bytes | Created Date = 2008-01-21 20:15:05 | Attr = ]
pos7D0.tmp -> %SystemDrive%\pos7D0.tmp -> [Ver = | Size = 5033 bytes | Created Date = 2008-01-21 20:15:05 | Attr = ]
pos7D1.tmp -> %SystemDrive%\pos7D1.tmp -> [Ver = | Size = 10033 bytes | Created Date = 2008-01-21 20:15:05 | Attr = ]
pos7D2.tmp -> %SystemDrive%\pos7D2.tmp -> [Ver = | Size = 5033 bytes | Created Date = 2008-01-21 20:15:05 | Attr = ]
pos7D3.tmp -> %SystemDrive%\pos7D3.tmp -> [Ver = | Size = 13033 bytes | Created Date = 2008-01-21 20:15:05 | Attr = ]
pos7D4.tmp -> %SystemDrive%\pos7D4.tmp -> [Ver = | Size = 13033 bytes | Created Date = 2008-01-21 20:15:05 | Attr = ]
pos7D5.tmp -> %SystemDrive%\pos7D5.tmp -> [Ver = | Size = 14033 bytes | Created Date = 2008-01-21 20:15:05 | Attr = ]
pos7D6.tmp -> %SystemDrive%\pos7D6.tmp -> [Ver = | Size = 9033 bytes | Created Date = 2008-01-21 20:15:05 | Attr = ]
pos7D7.tmp -> %SystemDrive%\pos7D7.tmp -> [Ver = | Size = 9033 bytes | Created Date = 2008-01-21 20:15:05 | Attr = ]
pos7D8.tmp -> %SystemDrive%\pos7D8.tmp -> [Ver = | Size = 14033 bytes | Created Date = 2008-01-21 20:15:05 | Attr = ]
pos7D9.tmp -> %SystemDrive%\pos7D9.tmp -> [Ver = | Size = 12033 bytes | Created Date = 2008-01-21 20:15:05 | Attr = ]
pos7DA.tmp -> %SystemDrive%\pos7DA.tmp -> [Ver = | Size = 5033 bytes | Created Date = 2008-01-21 20:15:06 | Attr = ]
pos7DB.tmp -> %SystemDrive%\pos7DB.tmp -> [Ver = | Size = 6033 bytes | Created Date = 2008-01-21 20:15:06 | Attr = ]
pos7DC.tmp -> %SystemDrive%\pos7DC.tmp -> [Ver = | Size = 6033 bytes | Created Date = 2008-01-21 20:15:06 | Attr = ]
pos7DD.tmp -> %SystemDrive%\pos7DD.tmp -> [Ver = | Size = 6033 bytes | Created Date = 2008-01-21 20:15:06 | Attr = ]
pos7DE.tmp -> %SystemDrive%\pos7DE.tmp -> [Ver = | Size = 9033 bytes | Created Date = 2008-01-21 20:15:06 | Attr = ]
pos7DF.tmp -> %SystemDrive%\pos7DF.tmp -> [Ver = | Size = 11033 bytes | Created Date = 2008-01-21 20:15:06 | Attr = ]
pos7E0.tmp -> %SystemDrive%\pos7E0.tmp -> [Ver = | Size = 12033 bytes | Created Date = 2008-01-21 20:15:06 | Attr = ]
pos7E1.tmp -> %SystemDrive%\pos7E1.tmp -> [Ver = | Size = 7033 bytes | Created Date = 2008-01-21 20:15:06 | Attr = ]
pos7E2.tmp -> %SystemDrive%\pos7E2.tmp -> [Ver = | Size = 7033 bytes | Created Date = 2008-01-21 20:15:06 | Attr = ]
pos7E3.tmp -> %SystemDrive%\pos7E3.tmp -> [Ver = | Size = 10033 bytes | Created Date = 2008-01-21 20:15:06 | Attr = ]
pos7E4.tmp -> %SystemDrive%\pos7E4.tmp -> [Ver = | Size = 14033 bytes | Created Date = 2008-01-21 20:15:06 | Attr = ]
pos7E5.tmp -> %SystemDrive%\pos7E5.tmp -> [Ver = | Size = 8033 bytes | Created Date = 2008-01-21 20:15:06 | Attr = ]
pos7E6.tmp -> %SystemDrive%\pos7E6.tmp -> [Ver = | Size = 12033 bytes | Created Date = 2008-01-21 20:15:06 | Attr = ]
pos7E7.tmp -> %SystemDrive%\pos7E7.tmp -> [Ver = | Size = 10033 bytes | Created Date = 2008-01-21 20:15:06 | Attr = ]
pos7E8.tmp -> %SystemDrive%\pos7E8.tmp -> [Ver = | Size = 10033 bytes | Created Date = 2008-01-21 20:15:07 | Attr = ]
pos7E9.tmp -> %SystemDrive%\pos7E9.tmp -> [Ver = | Size = 12033 bytes | Created Date = 2008-01-21 20:15:07 | Attr = ]
pos7EA.tmp -> %SystemDrive%\pos7EA.tmp -> [Ver = | Size = 12033 bytes | Created Date = 2008-01-21 20:15:07 | Attr = ]
pos7EB.tmp -> %SystemDrive%\pos7EB.tmp -> [Ver = | Size = 9033 bytes | Created Date = 2008-01-21 20:15:07 | Attr = ]
pos7EC.tmp -> %SystemDrive%\pos7EC.tmp -> [Ver = | Size = 7033 bytes | Created Date = 2008-01-21 20:15:07 | Attr = ]
pos7ED.tmp -> %SystemDrive%\pos7ED.tmp -> [Ver = | Size = 11033 bytes | Created Date = 2008-01-21 20:15:07 | Attr = ]
pos7EE.tmp -> %SystemDrive%\pos7EE.tmp -> [Ver = | Size = 7033 bytes | Created Date = 2008-01-21 20:15:07 | Attr = ]
pos7EF.tmp -> %SystemDrive%\pos7EF.tmp -> [Ver = | Size = 14033 bytes | Created Date = 2008-01-21 20:15:07 | Attr = ]
pos7F0.tmp -> %SystemDrive%\pos7F0.tmp -> [Ver = | Size = 12033 bytes | Created Date = 2008-01-21 20:15:07 | Attr = ]
pos7F1.tmp -> %SystemDrive%\pos7F1.tmp -> [Ver = | Size = 14033 bytes | Created Date = 2008-01-21 20:15:07 | Attr = ]
pos7F2.tmp -> %SystemDrive%\pos7F2.tmp -> [Ver = | Size = 8033 bytes | Created Date = 2008-01-21 20:15:07 | Attr = ]
pos7F3.tmp -> %SystemDrive%\pos7F3.tmp -> [Ver = | Size = 13033 bytes | Created Date = 2008-01-21 20:15:07 | Attr = ]
pos7F4.tmp -> %SystemDrive%\pos7F4.tmp -> [Ver = | Size = 10033 bytes | Created Date = 2008-01-21 20:15:07 | Attr = ]
pos7F5.tmp -> %SystemDrive%\pos7F5.tmp -> [Ver = | Size = 9033 bytes | Created Date = 2008-01-21 20:15:07 | Attr = ]
pos7F6.tmp -> %SystemDrive%\pos7F6.tmp -> [Ver = | Size = 14033 bytes | Created Date = 2008-01-21 20:15:07 | Attr = ]
pos7F7.tmp -> %SystemDrive%\pos7F7.tmp -> [Ver = | Size = 10033 bytes | Created Date = 2008-01-21 20:15:07 | Attr = ]
pos7F8.tmp -> %SystemDrive%\pos7F8.tmp -> [Ver = | Size = 5033 bytes | Created Date = 2008-01-21 20:15:08 | Attr = ]
pos7F9.tmp -> %SystemDrive%\pos7F9.tmp -> [Ver = | Size = 13033 bytes | Created Date = 2008-01-21 20:15:08 | Attr = ]
pos7FA.tmp -> %SystemDrive%\pos7FA.tmp -> [Ver = | Size = 14033 bytes | Created Date = 2008-01-21 20:15:08 | Attr = ]
pos7FB.tmp -> %SystemDrive%\pos7FB.tmp -> [Ver = | Size = 7033 bytes | Created Date = 2008-01-21 20:15:08 | Attr = ]
pos7FC.tmp -> %SystemDrive%\pos7FC.tmp -> [Ver = | Size = 13033 bytes | Created Date = 2008-01-21 20:15:08 | Attr = ]
pos7FD.tmp -> %SystemDrive%\pos7FD.tmp -> [Ver = | Size = 11033 bytes | Created Date = 2008-01-21 20:15:08 | Attr = ]
pos7FE.tmp -> %SystemDrive%\pos7FE.tmp -> [Ver = | Size = 10033 bytes | Created Date = 2008-01-21 20:15:08 | Attr = ]
pos7FF.tmp -> %SystemDrive%\pos7FF.tmp -> [Ver = | Size = 9033 bytes | Created Date = 2008-01-21 20:15:08 | Attr = ]
pos800.tmp -> %SystemDrive%\pos800.tmp -> [Ver = | Size = 7033 bytes | Created Date = 2008-01-21 20:15:08 | Attr = ]
pos801.tmp -> %SystemDrive%\pos801.tmp -> [Ver = | Size = 6033 bytes | Created Date = 2008-01-21 20:15:08 | Attr = ]
pos802.tmp -> %SystemDrive%\pos802.tmp -> [Ver = | Size = 9033 bytes | Created Date = 2008-01-21 20:15:08 | Attr = ]
pos803.tmp -> %SystemDrive%\pos803.tmp -> [Ver = | Size = 11033 bytes | Created Date = 2008-01-21 20:15:09 | Attr = ]
pos804.tmp -> %SystemDrive%\pos804.tmp -> [Ver = | Size = 14033 bytes | Created Date = 2008-01-21 20:15:09 | Attr = ]
pos805.tmp -> %SystemDrive%\pos805.tmp -> [Ver = | Size = 11033 bytes | Created Date = 2008-01-21 20:15:09 | Attr = ]
pos806.tmp -> %SystemDrive%\pos806.tmp -> [Ver = | Size = 5033 bytes | Created Date = 2008-01-21 20:15:09 | Attr = ]
pos807.tmp -> %SystemDrive%\pos807.tmp -> [Ver = | Size = 14033 bytes | Created Date = 2008-01-21 20:15:09 | Attr = ]
pos808.tmp -> %SystemDrive%\pos808.tmp -> [Ver = | Size = 14033 bytes | Created Date = 2008-01-21 20:15:09 | Attr = ]
pos809.tmp -> %SystemDrive%\pos809.tmp -> [Ver = | Size = 10033 bytes | Created Date = 2008-01-21 20:15:09 | Attr = ]
pos80A.tmp -> %SystemDrive%\pos80A.tmp -> [Ver = | Size = 8033 bytes | Created Date = 2008-01-21 20:15:09 | Attr = ]
pos80B.tmp -> %SystemDrive%\pos80B.tmp -> [Ver = | Size = 7033 bytes | Created Date = 2008-01-21 20:15:09 | Attr = ]
pos80C.tmp -> %SystemDrive%\pos80C.tmp -> [Ver = | Size = 11033 bytes | Created Date = 2008-01-21 20:15:09 | Attr = ]
pos80D.tmp -> %SystemDrive%\pos80D.tmp -> [Ver = | Size = 5033 bytes | Created Date = 2008-01-21 20:15:09 | Attr = ]
pos80E.tmp -> %SystemDrive%\pos80E.tmp -> [Ver = | Size = 8033 bytes | Created Date = 2008-01-21 20:15:09 | Attr = ]
pos80F.tmp -> %SystemDrive%\pos80F.tmp -> [Ver = | Size = 13033 bytes | Created Date = 2008-01-21 20:15:10 | Attr = ]
pos810.tmp -> %SystemDrive%\pos810.tmp -> [Ver = | Size = 8033 bytes | Created Date = 2008-01-21 20:15:10 | Attr = ]
pos811.tmp -> %SystemDrive%\pos811.tmp -> [Ver = | Size = 5033 bytes | Created Date = 2008-01-21 20:15:10 | Attr = ]
pos812.tmp -> %SystemDrive%\pos812.tmp -> [Ver = | Size = 10033 bytes | Created Date = 2008-01-21 20:15:10 | Attr = ]
pos813.tmp -> %SystemDrive%\pos813.tmp -> [Ver = | Size = 10033 bytes | Created Date = 2008-01-21 20:15:10 | Attr = ]
pos814.tmp -> %SystemDrive%\pos814.tmp -> [Ver = | Size = 7033 bytes | Created Date = 2008-01-21 20:15:10 | Attr = ]
pos815.tmp -> %SystemDrive%\pos815.tmp -> [Ver = | Size = 6033 bytes | Created Date = 2008-01-21 20:15:10 | Attr = ]
pos816.tmp -> %SystemDrive%\pos816.tmp -> [Ver = | Size = 6033 bytes | Created Date = 2008-01-21 20:15:10 | Attr = ]
pos817.tmp -> %SystemDrive%\pos817.tmp -> [Ver = | Size = 9033 bytes | Created Date = 2008-01-21 20:15:10 | Attr = ]
pos818.tmp -> %SystemDrive%\pos818.tmp -> [Ver = | Size = 13033 bytes | Created Date = 2008-01-21 20:15:10 | Attr = ]
pos819.tmp -> %SystemDrive%\pos819.tmp -> [Ver = | Size = 14033 bytes | Created Date = 2008-01-21 20:15:10 | Attr = ]
pos81A.tmp -> %SystemDrive%\pos81A.tmp -> [Ver = | Size = 13033 bytes | Created Date = 2008-01-21 20:15:11 | Attr = ]
pos81B.tmp -> %SystemDrive%\pos81B.tmp -> [Ver = | Size = 13033 bytes | Created Date = 2008-01-21 20:15:11 | Attr = ]
pos81C.tmp -> %SystemDrive%\pos81C.tmp -> [Ver = | Size = 14033 bytes | Created Date = 2008-01-21 20:15:11 | Attr = ]
pos81D.tmp -> %SystemDrive%\pos81D.tmp -> [Ver = | Size = 5033 bytes | Created Date = 2008-01-21 20:15:11 | Attr = ]
pos81E.tmp -> %SystemDrive%\pos81E.tmp -> [Ver = | Size = 12033 bytes | Created Date = 2008-01-21 20:15:11 | Attr = ]
pos81F.tmp -> %SystemDrive%\pos81F.tmp -> [Ver = | Size = 14033 bytes | Created Date = 2008-01-21 20:15:11 | Attr = ]
pos820.tmp -> %SystemDrive%\pos820.tmp -> [Ver = | Size = 14033 bytes | Created Date = 2008-01-21 20:15:11 | Attr = ]
pos821.tmp -> %SystemDrive%\pos821.tmp -> [Ver = | Size = 6033 bytes | Created Date = 2008-01-21 20:15:11 | Attr = ]
pos822.tmp -> %SystemDrive%\pos822.tmp -> [Ver = | Size = 7033 bytes | Created Date = 2008-01-21 20:15:11 | Attr = ]
pos823.tmp -> %SystemDrive%\pos823.tmp -> [Ver = | Size = 6033 bytes | Created Date = 2008-01-21 20:15:12 | Attr = ]
pos824.tmp -> %SystemDrive%\pos824.tmp -> [Ver = | Size = 12033 bytes | Created Date = 2008-01-21 20:15:12 | Attr = ]
pos825.tmp -> %SystemDrive%\pos825.tmp -> [Ver = | Size = 9033 bytes | Created Date = 2008-01-21 20:15:12 | Attr = ]
pos826.tmp -> %SystemDrive%\pos826.tmp -> [Ver = | Size = 11033 bytes | Created Date = 2008-01-21 20:15:12 | Attr = ]
pos827.tmp -> %SystemDrive%\pos827.tmp -> [Ver = | Size = 12033 bytes | Created Date = 2008-01-21 20:15:12 | Attr = ]
pos828.tmp -> %SystemDrive%\pos828.tmp -> [Ver = | Size = 13033 bytes | Created Date = 2008-01-21 20:15:12 | Attr = ]
pos829.tmp -> %SystemDrive%\pos829.tmp -> [Ver = | Size = 13033 bytes | Created Date = 2008-01-21 20:15:12 | Attr = ]
pos82A.tmp -> %SystemDrive%\pos82A.tmp -> [Ver = | Size = 11033 bytes | Created Date = 2008-01-21 20:15:12 | Attr = ]
pos82B.tmp -> %SystemDrive%\pos82B.tmp -> [Ver = | Size = 11033 bytes | Created Date = 2008-01-21 20:15:12 | Attr = ]
pos82C.tmp -> %SystemDrive%\pos82C.tmp -> [Ver = | Size = 10033 bytes | Created Date = 2008-01-21 20:15:12 | Attr = ]
pos82D.tmp -> %SystemDrive%\pos82D.tmp -> [Ver = | Size = 14033 bytes | Created Date = 2008-01-21 20:15:12 | Attr = ]
pos82E.tmp -> %SystemDrive%\pos82E.tmp -> [Ver = | Size = 6033 bytes | Created Date = 2008-01-21 20:15:12 | Attr = ]
pos82F.tmp -> %SystemDrive%\pos82F.tmp -> [Ver = | Size = 5033 bytes | Created Date = 2008-01-21 20:15:12 | Attr = ]
pos830.tmp -> %SystemDrive%\pos830.tmp -> [Ver = | Size = 11033 bytes | Created Date = 2008-01-21 20:15:12 | Attr = ]
pos831.tmp -> %SystemDrive%\pos831.tmp -> [Ver = | Size = 12033 bytes | Created Date = 2008-01-21 20:15:12 | Attr = ]
pos832.tmp -> %SystemDrive%\pos832.tmp -> [Ver = | Size = 5033 bytes | Created Date = 2008-01-21 20:15:12 | Attr = ]
pos833.tmp -> %SystemDrive%\pos833.tmp -> [Ver = | Size = 7033 bytes | Created Date = 2008-01-21 20:15:12 | Attr = ]
pos834.tmp -> %SystemDrive%\pos834.tmp -> [Ver = | Size = 13033 bytes | Created Date = 2008-01-21 20:15:13 | Attr = ]
pos835.tmp -> %SystemDrive%\pos835.tmp -> [Ver = | Size = 5033 bytes | Created Date = 2008-01-21 20:15:13 | Attr = ]
pos836.tmp -> %SystemDrive%\pos836.tmp -> [Ver = | Size = 5033 bytes | Created Date = 2008-01-21 20:15:13 | Attr = ]
pos837.tmp -> %SystemDrive%\pos837.tmp -> [Ver = | Size = 5033 bytes | Created Date = 2008-01-21 20:15:13 | Attr = ]
pos838.tmp -> %SystemDrive%\pos838.tmp -> [Ver = | Size = 8033 bytes | Created Date = 2008-01-21 20:15:13 | Attr = ]
pos839.tmp -> %SystemDrive%\pos839.tmp -> [Ver = | Size = 14033 bytes | Created Date = 2008-01-21 20:15:13 | Attr = ]
pos83A.tmp -> %SystemDrive%\pos83A.tmp -> [Ver = | Size = 5033 bytes | Created Date = 2008-01-21 20:15:13 | Attr = ]
pos83B.tmp -> %SystemDrive%\pos83B.tmp -> [Ver = | Size = 8033 bytes | Created Date = 2008-01-21 20:15:13 | Attr = ]
pos83C.tmp -> %SystemDrive%\pos83C.tmp -> [Ver = | Size = 9033 bytes | Created Date = 2008-01-21 20:15:13 | Attr = ]
pos83D.tmp -> %SystemDrive%\pos83D.tmp -> [Ver = | Size = 11033 bytes | Created Date = 2008-01-21 20:15:13 | Attr = ]
pos83E.tmp -> %SystemDrive%\pos83E.tmp -> [Ver = | Size = 10033 bytes | Created Date = 2008-01-21 20:15:13 | Attr = ]
pos83F.tmp -> %SystemDrive%\pos83F.tmp -> [Ver = | Size = 14033 bytes | Created Date = 2008-01-21 20:15:13 | Attr = ]
pos840.tmp -> %SystemDrive%\pos840.tmp -> [Ver = | Size = 13033 bytes | Created Date = 2008-01-21 20:15:13 | Attr = ]
pos841.tmp -> %SystemDrive%\pos841.tmp -> [Ver = | Size = 7033 bytes | Created Date = 2008-01-21 20:15:13 | Attr = ]
pos842.tmp -> %SystemDrive%\pos842.tmp -> [Ver = | Size = 10033 bytes | Created Date = 2008-01-21 20:15:13 | Attr = ]
pos843.tmp -> %SystemDrive%\pos843.tmp -> [Ver = | Size = 10033 bytes | Created Date = 2008-01-21 20:15:13 | Attr = ]
pos844.tmp -> %SystemDrive%\pos844.tmp -> [Ver = | Size = 7033 bytes | Created Date = 2008-01-21 20:15:13 | Attr = ]
pos845.tmp -> %SystemDrive%\pos845.tmp -> [Ver = | Size = 12033 bytes | Created Date = 2008-01-21 20:15:13 | Attr = ]
pos846.tmp -> %SystemDrive%\pos846.tmp -> [Ver = | Size = 11033 bytes | Created Date = 2008-01-21 20:15:14 | Attr = ]
pos847.tmp -> %SystemDrive%\pos847.tmp -> [Ver = | Size = 12033 bytes | Created Date = 2008-01-21 20:15:14 | Attr = ]
pos848.tmp -> %SystemDrive%\pos848.tmp -> [Ver = | Size = 12033 bytes | Created Date = 2008-01-21 20:15:14 | Attr = ]
pos849.tmp -> %SystemDrive%\pos849.tmp -> [Ver = | Size = 7033 bytes | Created Date = 2008-01-21 20:15:14 | Attr = ]
pos84A.tmp -> %SystemDrive%\pos84A.tmp -> [Ver = | Size = 12033 bytes | Created Date = 2008-01-21 20:15:14 | Attr = ]
pos84B.tmp -> %SystemDrive%\pos84B.tmp -> [Ver = | Size = 14033 bytes | Created Date = 2008-01-21 20:15:14 | Attr = ]
pos84C.tmp -> %SystemDrive%\pos84C.tmp -> [Ver = | Size = 12033 bytes | Created Date = 2008-01-21 20:15:14 | Attr = ]
pos84D.tmp -> %SystemDrive%\pos84D.tmp -> [Ver = | Size = 12033 bytes | Created Date = 2008-01-21 20:15:14 | Attr = ]
pos84E.tmp -> %SystemDrive%\pos84E.tmp -> [Ver = | Size = 11033 bytes | Created Date = 2008-01-21 20:15:14 | Attr = ]
pos84F.tmp -> %SystemDrive%\pos84F.tmp -> [Ver = | Size = 10033 bytes | Created Date = 2008-01-21 20:15:14 | Attr = ]
pos850.tmp -> %SystemDrive%\pos850.tmp -> [Ver = | Size = 10033 bytes | Created Date = 2008-01-21 20:15:14 | Attr = ]
pos851.tmp -> %SystemDrive%\pos851.tmp -> [Ver = | Size = 6033 bytes | Created Date = 2008-01-21 20:15:14 | Attr = ]
pos852.tmp -> %SystemDrive%\pos852.tmp -> [Ver = | Size = 5033 bytes | Created Date = 2008-01-21 20:15:14 | Attr = ]
pos853.tmp -> %SystemDrive%\pos853.tmp -> [Ver = | Size = 12033 bytes | Created Date = 2008-01-21 20:15:14 | Attr = ]
pos854.tmp -> %SystemDrive%\pos854.tmp -> [Ver = | Size = 10033 bytes | Created Date = 2008-01-21 20:15:14 | Attr = ]
pos855.tmp -> %SystemDrive%\pos855.tmp -> [Ver = | Size = 12033 bytes | Created Date = 2008-01-21 20:15:14 | Attr = ]
pos856.tmp -> %SystemDrive%\pos856.tmp -> [Ver = | Size = 11033 bytes | Created Date = 2008-01-21 20:15:14 | Attr = ]
pos857.tmp -> %SystemDrive%\pos857.tmp -> [Ver = | Size = 12033 bytes | Created Date = 2008-01-21 20:15:14 | Attr = ]
pos858.tmp -> %SystemDrive%\pos858.tmp -> [Ver = | Size = 7033 bytes | Created Date = 2008-01-21 20:15:14 | Attr = ]
pos859.tmp -> %SystemDrive%\pos859.tmp -> [Ver = | Size = 6033 bytes | Created Date = 2008-01-21 20:15:14 | Attr = ]
pos85A.tmp -> %SystemDrive%\pos85A.tmp -> [Ver = | Size = 8033 bytes | Created Date = 2008-01-21 20:15:14 | Attr = ]
pos85B.tmp -> %SystemDrive%\pos85B.tmp -> [Ver = | Size = 10033 bytes | Created Date = 2008-01-21 20:15:14 | Attr = ]
pos85C.tmp -> %SystemDrive%\pos85C.tmp -> [Ver = | Size = 8033 bytes | Created Date = 2008-01-21 20:15:15 | Attr = ]
pos85D.tmp -> %SystemDrive%\pos85D.tmp -> [Ver = | Size = 10033 bytes | Created Date = 2008-01-21 20:15:15 | Attr = ]
pos85E.tmp -> %SystemDrive%\pos85E.tmp -> [Ver = | Size = 8033 bytes | Created Date = 2008-01-21 20:15:15 | Attr = ]
pos85F.tmp -> %SystemDrive%\pos85F.tmp -> [Ver = | Size = 11033 bytes | Created Date = 2008-01-21 20:15:15 | Attr = ]
pos860.tmp -> %SystemDrive%\pos860.tmp -> [Ver = | Size = 13033 bytes | Created Date = 2008-01-21 20:15:15 | Attr = ]
pos861.tmp -> %SystemDrive%\pos861.tmp -> [Ver = | Size = 8033 bytes | Created Date = 2008-01-21 20:15:15 | Attr = ]
pos862.tmp -> %SystemDrive%\pos862.tmp -> [Ver = | Size = 8033 bytes | Created Date = 2008-01-21 20:15:15 | Attr = ]
pos863.tmp -> %SystemDrive%\pos863.tmp -> [Ver = | Size = 13033 bytes | Created Date = 2008-01-21 20:15:15 | Attr = ]
pos864.tmp -> %SystemDrive%\pos864.tmp -> [Ver = | Size = 7033 bytes | Created Date = 2008-01-21 20:15:15 | Attr = ]
pos865.tmp -> %SystemDrive%\pos865.tmp -> [Ver = | Size = 13033 bytes | Created Date = 2008-01-21 20:15:15 | Attr = ]
pos866.tmp -> %SystemDrive%\pos866.tmp -> [Ver = | Size = 10033 bytes | Created Date = 2008-01-21 20:15:15 | Attr = ]
pos867.tmp -> %SystemDrive%\pos867.tmp -> [Ver = | Size = 11033 bytes | Created Date = 2008-01-21 20:15:15 | Attr = ]
pos868.tmp -> %SystemDrive%\pos868.tmp -> [Ver = | Size = 8033 bytes | Created Date = 2008-01-21 20:15:15 | Attr = ]
pos869.tmp -> %SystemDrive%\pos869.tmp -> [Ver = | Size = 5033 bytes | Created Date = 2008-01-21 20:15:15 | Attr = ]
pos86A.tmp -> %SystemDrive%\pos86A.tmp -> [Ver = | Size = 12033 bytes | Created Date = 2008-01-21 20:15:15 | Attr = ]
pos86B.tmp -> %SystemDrive%\pos86B.tmp -> [Ver = | Size = 5033 bytes | Created Date = 2008-01-21 20:15:15 | Attr = ]
pos86C.tmp -> %SystemDrive%\pos86C.tmp -> [Ver = | Size = 11033 bytes | Created Date = 2008-01-21 20:15:15 | Attr = ]
pos86D.tmp -> %SystemDrive%\pos86D.tmp -> [Ver = | Size = 10033 bytes | Created Date = 2008-01-21 20:15:15 | Attr = ]
pos86E.tmp -> %SystemDrive%\pos86E.tmp -> [Ver = | Size = 11033 bytes | Created Date = 2008-01-21 20:15:15 | Attr = ]
pos86F.tmp -> %SystemDrive%\pos86F.tmp -> [Ver = | Size = 7033 bytes | Created Date = 2008-01-21 20:15:15 | Attr = ]
pos870.tmp -> %SystemDrive%\pos870.tmp -> [Ver = | Size = 9033 bytes | Created Date = 2008-01-21 20:15:15 | Attr = ]
pos871.tmp -> %SystemDrive%\pos871.tmp -> [Ver = | Size = 13033 bytes | Created Date = 2008-01-21 20:15:16 | Attr = ]
pos872.tmp -> %SystemDrive%\pos872.tmp -> [Ver = | Size = 11033 bytes | Created Date = 2008-01-21 20:15:16 | Attr = ]
pos873.tmp -> %SystemDrive%\pos873.tmp -> [Ver = | Size = 10033 bytes | Created Date = 2008-01-21 20:15:16 | Attr = ]
pos874.tmp -> %SystemDrive%\pos874.tmp -> [Ver = | Size = 6033 bytes | Created Date = 2008-01-21 20:15:16 | Attr = ]
pos875.tmp -> %SystemDrive%\pos875.tmp -> [Ver = | Size = 5033 bytes | Created Date = 2008-01-21 20:15:16 | Attr = ]
pos876.tmp -> %SystemDrive%\pos876.tmp -> [Ver = | Size = 12033 bytes | Created Date = 2008-01-21 20:15:16 | Attr = ]
pos877.tmp -> %SystemDrive%\pos877.tmp -> [Ver = | Size = 8033 bytes | Created Date = 2008-01-21 20:15:16 | Attr = ]
pos878.tmp -> %SystemDrive%\pos878.tmp -> [Ver = | Size = 12033 bytes | Created Date = 2008-01-21 20:15:16 | Attr = ]
pos879.tmp -> %SystemDrive%\pos879.tmp -> [Ver = | Size = 14033 bytes | Created Date = 2008-01-21 20:15:16 | Attr = ]
pos87A.tmp -> %SystemDrive%\pos87A.tmp -> [Ver = | Size = 12033 bytes | Created Date = 2008-01-21 20:15:16 | Attr = ]

#15 bdfinally

bdfinally
  • Topic Starter

  • Members
  • 34 posts
  • OFFLINE
  •  
  • Local time:10:55 PM

Posted 22 January 2008 - 07:35 AM

last

pos2B7.tmp -> %SystemDrive%\pos2B7.tmp -> [Ver = | Size = 14033 bytes | Modified Date = 2008-01-21 20:14:44 | Attr = ]
pos2B8.tmp -> %SystemDrive%\pos2B8.tmp -> [Ver = | Size = 7033 bytes | Modified Date = 2008-01-21 20:14:44 | Attr = ]
pos2B9.tmp -> %SystemDrive%\pos2B9.tmp -> [Ver = | Size = 6033 bytes | Modified Date = 2008-01-21 20:14:44 | Attr = ]
pos2BA.tmp -> %SystemDrive%\pos2BA.tmp -> [Ver = | Size = 11033 bytes | Modified Date = 2008-01-21 20:14:44 | Attr = ]
tmcomm.sys -> %System32%\drivers\tmcomm.sys -> Trend Micro Inc. [Ver = 1.6.0.1059 | Size = 102664 bytes | Modified Date = 2008-01-12 14:26:44 | Attr = ]
windows -> %System32%\windows -> [Ver = | Size = 7168 bytes | Modified Date = 2008-01-21 22:09:52 | Attr = ]
wpa.dbl -> %System32%\wpa.dbl -> [Ver = | Size = 12696 bytes | Modified Date = 2008-01-21 20:45:04 | Attr = ]
badgh.ini -> %System32%\badgh.ini -> [Ver = | Size = 6680 bytes | Modified Date = 2008-01-21 22:23:46 | Attr = HS]
geryhqlv.ini -> %System32%\geryhqlv.ini -> [Ver = | Size = 1089436 bytes | Modified Date = 2008-01-21 20:46:12 | Attr = HS]
wcbfangt.dll -> %System32%\wcbfangt.dll -> [Ver = | Size = 76352 bytes | Modified Date = 2008-01-21 19:54:26 | Attr = ]
vtuvwxv.dll -> %System32%\vtuvwxv.dll -> [Ver = | Size = 40960 bytes | Modified Date = 2008-01-03 00:17:16 | Attr = ]
D8427239DB.sys -> %System32%\D8427239DB.sys -> [Ver = | Size = 88 bytes | Modified Date = 2008-01-03 00:17:54 | Attr = RHS]
jusybwlu.exe -> %System32%\jusybwlu.exe -> [Ver = 1, 0, 0, 1 | Size = 74304 bytes | Modified Date = 2008-01-21 19:54:34 | Attr = ]
ardCo18 -> %System32%\ardCo18 -> [Folder | Modified Date = 2008-01-03 00:17:26 | Attr = ]
hgdab.dll -> %System32%\hgdab.dll -> [Ver = | Size = 344576 bytes | Modified Date = 2008-01-03 07:41:32 | Attr = ]
xwlsxpve.dllbox -> %System32%\xwlsxpve.dllbox -> [Ver = | Size = 22748 bytes | Modified Date = 2008-01-21 22:25:54 | Attr = HS]
vlqhyreg.dll -> %System32%\vlqhyreg.dll -> [Ver = | Size = 88640 bytes | Modified Date = 2008-01-21 19:54:36 | Attr = ]
xwlsxpve.dll -> %System32%\xwlsxpve.dll -> [Ver = | Size = 163904 bytes | Modified Date = 2008-01-13 08:13:18 | Attr = ]
kapeaqjj.ini -> %System32%\kapeaqjj.ini -> [Ver = | Size = 1044160 bytes | Modified Date = 2008-01-06 10:48:54 | Attr = HS]
vbzip10.dll -> %System32%\vbzip10.dll -> Info-ZIP [Ver = 2.3 | Size = 147456 bytes | Modified Date = 2008-01-03 07:48:22 | Attr = ]
pavas.ico -> %System32%\pavas.ico -> [Ver = | Size = 30590 bytes | Modified Date = 2008-01-13 09:38:26 | Attr = ]
KGyGaAvL.sys -> %System32%\KGyGaAvL.sys -> [Ver = | Size = 3766 bytes | Modified Date = 2008-01-03 00:18:40 | Attr = HS]
Help.ico -> %System32%\Help.ico -> [Ver = | Size = 1406 bytes | Modified Date = 2008-01-13 09:38:26 | Attr = ]
Uninstall.ico -> %System32%\Uninstall.ico -> [Ver = | Size = 2550 bytes | Modified Date = 2008-01-13 09:38:26 | Attr = ]
hgdab.exe -> %System32%\hgdab.exe -> [Ver = | Size = 348160 bytes | Modified Date = 2008-01-21 22:23:28 | Attr = ]
kddkqauh.ini -> %System32%\kddkqauh.ini -> [Ver = | Size = 1046229 bytes | Modified Date = 2008-01-09 17:04:56 | Attr = HS]
badgh.ini2 -> %System32%\badgh.ini2 -> [Ver = | Size = 6680 bytes | Modified Date = 2008-01-21 22:23:30 | Attr = HS]
fksdpeyv.ini -> %System32%\fksdpeyv.ini -> [Ver = | Size = 1060742 bytes | Modified Date = 2008-01-12 09:49:58 | Attr = HS]
ljhecehg.ini -> %System32%\ljhecehg.ini -> [Ver = | Size = 1060442 bytes | Modified Date = 2008-01-13 09:25:10 | Attr = HS]
bootstat.dat -> %SystemRoot%\bootstat.dat -> [Ver = | Size = 2048 bytes | Modified Date = 2008-01-21 22:18:22 | Attr = S]
BDOSCAN8 -> %SystemRoot%\BDOSCAN8 -> [Folder | Modified Date = 2008-01-13 10:43:40 | Attr = ]
Prefetch -> %SystemRoot%\Prefetch -> [Folder | Modified Date = 2008-01-16 23:04:24 | Attr = ]
nero.INI -> %SystemRoot%\nero.INI -> [Ver = | Size = 40 bytes | Modified Date = 2008-01-12 00:39:08 | Attr = ]
lexstat.ini -> %SystemRoot%\lexstat.ini -> [Ver = | Size = 502 bytes | Modified Date = 2008-01-21 21:46:48 | Attr = ]
Adobe Illustrator CS -> %SystemRoot%\Adobe Illustrator CS -> [Folder | Modified Date = 2008-01-02 17:53:12 | Attr = ]
win.ini -> %SystemRoot%\win.ini -> [Ver = | Size = 2269 bytes | Modified Date = 2008-01-18 07:29:20 | Attr = ]
SA.DAT -> %SystemRoot%\tasks\SA.DAT -> [Ver = | Size = 6 bytes | Modified Date = 2008-01-16 23:04:24 | Attr = H ]
ErrorKiller Scheduled Scan.job -> %SystemRoot%\tasks\ErrorKiller Scheduled Scan.job -> [Ver = | Size = 430 bytes | Modified Date = 2008-01-16 23:04:30 | Attr = ]

< End of report >

Edited by OldTimer, 24 January 2008 - 10:27 AM.





0 user(s) are reading this topic

0 members, 0 guests, 0 anonymous users