Jump to content


 


Register a free account to unlock additional features at BleepingComputer.com
Welcome to BleepingComputer, a free community where people like yourself come together to discuss and learn how to use their computers. Using the site is easy and fun. As a guest, you can browse and view the various discussions in the forums, but can not create a new topic or reply to an existing one unless you are logged in. Other benefits of registering an account are subscribing to topics and forums, creating a blog, and having no ads shown anywhere on the site.


Click here to Register a free account now! or read our Welcome Guide to learn how to use this site.

Photo

Need Help Removing Adwareremover2007 And Mediamegaportal Popups


  • This topic is locked This topic is locked
17 replies to this topic

#1 Penguin73

Penguin73

  • Members
  • 19 posts
  • OFFLINE
  •  
  • Local time:06:08 AM

Posted 10 February 2008 - 09:59 PM

I need help removing malware popups from my computer. I have ran Ad Aware 2007, Spybot Search & Destory, BitDefender, and McAfee virus checker. This malware started with trustedanitvirus pop-ups and sometimes changed my desktop background with a privacy warning. I thought I had gotten rid of the problems, but it has started to come back with a vengance. I have posted my HijackThis log below. Is there something else I am missing? Please Help.

Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 9:45:37 PM, on 2/10/2008
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16574)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Lavasoft\Ad-Aware 2007\aawservice.exe
C:\WINDOWS\system32\LEXBCES.EXE
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\system32\LEXPPS.EXE
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Common Files\McAfee\HackerWatch\HWAPI.exe
C:\PROGRA~1\McAfee\MSC\mcmscsvc.exe
c:\program files\common files\mcafee\mna\mcnasvc.exe
C:\PROGRA~1\McAfee\VIRUSS~1\mcods.exe
C:\PROGRA~1\McAfee\MSC\mcpromgr.exe
c:\PROGRA~1\COMMON~1\mcafee\mcproxy\mcproxy.exe
c:\PROGRA~1\COMMON~1\mcafee\redirsvc\redirsvc.exe
C:\PROGRA~1\McAfee\VIRUSS~1\mcshield.exe
C:\PROGRA~1\McAfee\VIRUSS~1\mcsysmon.exe
C:\Program Files\McAfee\MPF\MPFSrv.exe
C:\PROGRA~1\McAfee\MPS\mps.exe
C:\WINDOWS\System32\nvsvc32.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Viewpoint\Common\ViewpointService.exe
C:\WINDOWS\wanmpsvc.exe
C:\WINDOWS\Explorer.EXE
c:\PROGRA~1\mcafee.com\agent\mcagent.exe
C:\Program Files\McAfee\MPS\mpsevh.exe
C:\WINDOWS\System32\DSentry.exe
C:\Program Files\Roxio\Easy CD Creator 5\DirectCD\DirectCD.exe
C:\Program Files\ESPNRunTime\DIGServices.exe
C:\Program Files\Common Files\Real\Update_OB\realsched.exe
C:\Program Files\Musicmatch\Musicmatch Jukebox\mm_tray.exe
C:\Program Files\Winamp\winampa.exe
C:\Program Files\Musicmatch\Musicmatch Jukebox\mm_server.exe
C:\Program Files\HP\HP Software Update\HPWuSchd2.exe
C:\Program Files\Java\jre1.6.0_03\bin\jusched.exe
C:\PROGRA~1\DELLMO~1\MOH.exe
C:\PROGRA~1\MUSICM~1\MUSICM~1\MMDiag.exe
C:\Program Files\MSN Messenger\MsnMsgr.Exe
C:\Program Files\Dilberttest3\Screen Saver\FWLink.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
C:\Program Files\Digital Line Detect\DLG.exe
C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe
C:\Program Files\Kodak\pictures\Kodak EasyShare software\bin\EasyShare.exe
C:\Program Files\MUSICMATCH\MUSICMATCH Jukebox\mim.exe
C:\Program Files\Viewpoint\Viewpoint Manager\ViewMgr.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\HP\Digital Imaging\bin\hpqSTE08.exe
C:\Program Files\MSN Messenger\usnsvc.exe
C:\Program Files\internet explorer\iexplore.exe
C:\Program Files\Yahoo!\Messenger\ymsgr_tray.exe
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://cm.my.yahoo.com/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar = http://red.clientapps.yahoo.com/customize/...rch/search.html
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyServer = :0
O2 - BHO: (no name) - {02478D38-C3F9-4efb-9B51-7695ECA05670} - (no file)
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 5.0\Reader\ActiveX\AcroIEHelper.ocx
O2 - BHO: REALBAR - {4E7BD74F-2B8D-469E-C0FF-FD60B590A87D} - C:\PROGRA~1\COMMON~1\Real\Toolbar\realbar.dll
O2 - BHO: Spybot-S&D IE Protection - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O2 - BHO: (no name) - {65D886A2-7CA7-479B-BB95-14D1EFB7946A} - (no file)
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll
O2 - BHO: scriptproxy - {7DB2D5A0-7241-4E79-B68D-6309F01C5231} - c:\PROGRA~1\mcafee\VIRUSS~1\scriptcl.dll
O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - (no file)
O2 - BHO: SXG Advisor - {846034C7-4A99-4334-B701-A09EA3164949} - C:\WINDOWS\dpvtpormqv.dll (file missing)
O2 - BHO: Windows Live Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
O2 - BHO: ST - {9394EDE7-C8B5-483E-8773-474BF36AF6E4} - C:\Program Files\MSN Apps\ST\01.02.0002.1001\en-xu\stmain.dll
O2 - BHO: Electric_Fire_House_Radio Toolbar - {9b99c7d1-0617-40d5-8007-48aef252ba69} - C:\Program Files\Electric_Fire_House_Radio\tbEle0.dll
O2 - BHO: MSNToolBandBHO - {BDBD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\Program Files\MSN Apps\MSN Toolbar\01.02.2001.0001\en-us\msntb.dll
O3 - Toolbar: REALBAR - {4E7BD74F-2B8D-469E-C0FF-FD60B590A87D} - C:\PROGRA~1\COMMON~1\Real\Toolbar\realbar.dll
O3 - Toolbar: MSN - {BDAD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\Program Files\MSN Apps\MSN Toolbar\01.02.2001.0001\en-us\msntb.dll
O3 - Toolbar: &ESPN - {AE6F2894-AF10-4C9C-B16E-1DFC6FF8C0C6} - C:\Program Files\ESPN\Toolbar\DIGToolBar.dll
O3 - Toolbar: Electric_Fire_House_Radio Toolbar - {9b99c7d1-0617-40d5-8007-48aef252ba69} - C:\Program Files\Electric_Fire_House_Radio\tbEle0.dll
O3 - Toolbar: The elfwgps - {7BEF19B0-E219-418B-916B-836635B35328} - C:\WINDOWS\elfwgps.dll (file missing)
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\System32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [DVDSentry] C:\WINDOWS\System32\DSentry.exe
O4 - HKLM\..\Run: [AdaptecDirectCD] "C:\Program Files\Roxio\Easy CD Creator 5\DirectCD\DirectCD.exe"
O4 - HKLM\..\Run: [nwiz] nwiz.exe /install
O4 - HKLM\..\Run: [DIGServices] C:\Program Files\ESPNRunTime\DIGServices.exe /brand=ESPN /priority=0 /poll=24
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
O4 - HKLM\..\Run: [MimBoot] C:\PROGRA~1\MUSICM~1\MUSICM~1\mimboot.exe
O4 - HKLM\..\Run: [MMTray] "C:\Program Files\Musicmatch\Musicmatch Jukebox\mm_tray.exe"
O4 - HKLM\..\Run: [WinampAgent] C:\Program Files\Winamp\winampa.exe
O4 - HKLM\..\Run: [mm_server] "C:\Program Files\Musicmatch\Musicmatch Jukebox\mm_server.exe"
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [HP Software Update] C:\Program Files\HP\HP Software Update\HPWuSchd2.exe
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_03\bin\jusched.exe"
O4 - HKCU\..\Run: [ModemOnHold] C:\PROGRA~1\DELLMO~1\MOH.exe
O4 - HKCU\..\Run: [MsnMsgr] "C:\Program Files\MSN Messenger\MsnMsgr.Exe" /background
O4 - HKCU\..\Run: [Dilberttest3 web link] "C:\Program Files\Dilberttest3\Screen Saver\FWLink.exe"
O4 - HKCU\..\Run: [Yahoo! Pager] "C:\Program Files\Yahoo!\Messenger\YahooMessenger.exe" -quiet
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [SpybotSD TeaTimer] C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
O4 - HKUS\S-1-5-18\..\Run: [Yahoo! Pager] "C:\PROGRA~1\Yahoo!\MESSEN~1\YAHOOM~1.EXE" -quiet (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [Yahoo! Pager] "C:\PROGRA~1\Yahoo!\MESSEN~1\YAHOOM~1.EXE" -quiet (User 'Default user')
O4 - Global Startup: Digital Line Detect.lnk = ?
O4 - Global Startup: HP Digital Imaging Monitor.lnk = C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe
O4 - Global Startup: Kodak EasyShare software.lnk = C:\Program Files\Kodak\pictures\Kodak EasyShare software\bin\EasyShare.exe
O8 - Extra context menu item: &Search - http://bar.mywebsearch.com/menusearch.html?p=ZSzeb001
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll
O9 - Extra button: (no name) - {85d1f590-48f4-11d9-9669-0800200c9a66} - C:\WINDOWS\bdoscandel.exe
O9 - Extra 'Tools' menuitem: Uninstall BitDefender Online Scanner v8 - {85d1f590-48f4-11d9-9669-0800200c9a66} - C:\WINDOWS\bdoscandel.exe
O9 - Extra button: (no name) - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - (no file)
O9 - Extra button: (no name) - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O9 - Extra 'Tools' menuitem: Spybot - Search & Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O12 - Plugin for .spop: C:\Program Files\Internet Explorer\Plugins\NPDocBox.dll
O16 - DPF: {1D6711C8-7154-40BB-8380-3DEA45B69CBF} -
O16 - DPF: {56336BCB-3D8A-11D6-A00B-0050DA18DE71} - http://207.188.7.150/20a8d6fcbe9db50a3317/...ip/RdxIE601.cab
O16 - DPF: {5D86DDB5-BDF9-441B-9E9E-D4730F4EE499} (BDSCANONLINE Control) - http://download.bitdefender.com/resources/scan8/oscan8.cab
O16 - DPF: {77E32299-629F-43C6-AB77-6A1E6D7663F6} (Groove Control) - http://www.nick.com/common/groove/gx/GrooveAX27.cab
O16 - DPF: {9AA73F41-EC64-489E-9A73-9CD52E528BC4} (ZoneAxRcMgr Class) - http://zone.msn.com/binGame/ZAxRcMgr.cab
O16 - DPF: {B8BE5E93-A60C-4D26-A2DC-220313175592} (MSN Games - Installer) - http://cdn2.zone.msn.com/binFramework/v10/...ro.cab56649.cab
O16 - DPF: {E598AC61-4C6F-4F4D-877F-FAC49CA91FA3} (acpRunner Class) - https://www-3.ibm.com/pc/support/access/asl.../AcpControl.cab
O21 - SSODL: aswmklt - {2562E1B6-9833-4AD8-A6B3-3C33FAD9E467} - C:\WINDOWS\aswmklt.dll
O23 - Service: Ad-Aware 2007 Service (aawservice) - Lavasoft - C:\Program Files\Lavasoft\Ad-Aware 2007\aawservice.exe
O23 - Service: DSBrokerService - Unknown owner - C:\Program Files\DellSupport\brkrsvc.exe
O23 - Service: McAfee E-mail Proxy (Emproxy) - McAfee, Inc. - C:\PROGRA~1\COMMON~1\McAfee\EmProxy\emproxy.exe
O23 - Service: Kodak Camera Connection Software (KodakCCS) - Eastman Kodak Company - C:\WINDOWS\system32\drivers\KodakCCS.exe
O23 - Service: LexBce Server (LexBceS) - Lexmark International, Inc. - C:\WINDOWS\system32\LEXBCES.EXE
O23 - Service: McAfee HackerWatch Service - McAfee, Inc. - C:\Program Files\Common Files\McAfee\HackerWatch\HWAPI.exe
O23 - Service: McAfee Update Manager (mcmispupdmgr) - McAfee, Inc. - C:\PROGRA~1\McAfee\MSC\mcupdmgr.exe
O23 - Service: McAfee Services (mcmscsvc) - McAfee, Inc. - C:\PROGRA~1\McAfee\MSC\mcmscsvc.exe
O23 - Service: McAfee Network Agent (McNASvc) - McAfee, Inc. - c:\program files\common files\mcafee\mna\mcnasvc.exe
O23 - Service: McAfee Scanner (McODS) - McAfee, Inc. - C:\PROGRA~1\McAfee\VIRUSS~1\mcods.exe
O23 - Service: McAfee Protection Manager (mcpromgr) - McAfee, Inc. - C:\PROGRA~1\McAfee\MSC\mcpromgr.exe
O23 - Service: McAfee Proxy Service (McProxy) - McAfee, Inc. - c:\PROGRA~1\COMMON~1\mcafee\mcproxy\mcproxy.exe
O23 - Service: McAfee Redirector Service (McRedirector) - McAfee, Inc. - c:\PROGRA~1\COMMON~1\mcafee\redirsvc\redirsvc.exe
O23 - Service: McAfee Real-time Scanner (McShield) - McAfee, Inc. - C:\PROGRA~1\McAfee\VIRUSS~1\mcshield.exe
O23 - Service: McAfee SystemGuards (McSysmon) - McAfee, Inc. - C:\PROGRA~1\McAfee\VIRUSS~1\mcsysmon.exe
O23 - Service: McAfee Personal Firewall Service (MpfService) - McAfee, Inc. - C:\Program Files\McAfee\MPF\MPFSrv.exe
O23 - Service: McAfee Privacy Service (MPS9) - McAfee, Inc. - C:\PROGRA~1\McAfee\MPS\mps.exe
O23 - Service: Intel® NMS (NMSSvc) - Intel Corporation - C:\WINDOWS\System32\NMSSvc.exe
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\System32\nvsvc32.exe
O23 - Service: Viewpoint Manager Service - Viewpoint Corporation - C:\Program Files\Viewpoint\Common\ViewpointService.exe
O23 - Service: WAN Miniport (ATW) Service (WANMiniportService) - America Online, Inc. - C:\WINDOWS\wanmpsvc.exe

--
End of file - 12019 bytes

BC AdBot (Login to Remove)

 


#2 chryssi2001

chryssi2001

  • Members
  • 1,930 posts
  • OFFLINE
  •  
  • Local time:02:08 PM

Posted 16 February 2008 - 02:57 AM

Hello Penguin73,

I am sorry for the misunderstanding. You should post the new Hijackthis log in your old topic.
I will be assisting you with your malware issues.

Please be patient as I need some time to review your new Hijackthis log and i will post back recommendations for repairs.
  • Whatever repairs we make, are for fixing your computer problems only and by no means should be used on another computer.
  • Continue to respond to this thread until I give you the All Clean! If you have any question or you're stuck in there please reply it to me. I will try my best to help you!
  • Please bookmark or favourite this page. In case you need it as reference or etc.

Posted Image
Private Messages for personal support will be ignored. If you need help post in the forum.

#3 chryssi2001

chryssi2001

  • Members
  • 1,930 posts
  • OFFLINE
  •  
  • Local time:02:08 PM

Posted 16 February 2008 - 09:20 AM

Hello Penguin73,

OPTIONAL
I see that Viewpoint is installed. Viewpoint, Viewpoint Manager, Viewpoint Media Player are Viewpoint components which are installed as a side effect of installing other software, most notably AOL and AOL Instant Messenger (AIM). Viewpoint Manager is responsible for managing and updating Viewpoint Media Player's components. You can disable this using the Viewpoint Manager Control Panel found in the Windows Control Panel menu. By selecting Disable auto-updating for the Viewpoint Manager -- the player will no longer attempt to check for updates. Anything that is installed without your consent is suspect. Read what Viewpoint says and make your own decision.

To provide a satisfying consumer experience and to operate effectively, the Viewpoint Media Player periodically sends information to servers at Viewpoint. Each installation of the Viewpoint Media Player is identifiable to Viewpoint via a Customer Unique Identifier (CUID), an alphanumeric identifier embedded in the Viewpoint Media Player. The Viewpoint Media Player randomly generates the CUID during installation and uses it to indicate a unique installation of the product. A CUID is never connected to a user's name, email address, or other personal contact information. CUIDs are used for the sole purpose of filtering redundant information. Each of these information exchanges occurs anonymously.


Viewpoint Manager is considered as foistware instead of malware since it is installed without user's approval but doesn't spy or do anything "bad". This may change, read Viewpoint to Plunge Into Adware.
I recommend that you remove the Viewpoint products; however, decide for yourself. To uninstall the the Viewpoint components (Viewpoint, Viewpoint Manager, Viewpoint Media Player):
  • Click Start, point to Settings, and then click Control Panel.
  • In Control Panel, double-click Add or Remove Programs.
  • In Add or Remove Programs, highlight >>Viewpoint component<< , click Remove.
  • Do the same for each Viewpoint component.
-----------------------------------------
OPTIONAL

You have Electric_Fire_House_Radio Toolbar installed.
Have a read here.
Electric_Fire_House_Radio Toolbar - a Conduit/EffectiveBrand "Free Community" toolbar - modifies the default IE URL search hook. Some Conduit toolbars are reputed to have a certain adware/trackware functionality.

Use add/remove programs to uninstall it if you decide to do so.
-----------------------------------------
Download SDFix and save it to your Desktop.

Double click SDFix.exe and it will extract the files to %systemdrive%
(Drive that contains the Windows Directory, typically C:\SDFix)

Please then reboot your computer in Safe Mode by doing the following :
  • Restart your computer
  • After hearing your computer beep once during startup, but before the Windows icon appears, tap the F8 key continually;
  • Instead of Windows loading as normal, the Advanced Options Menu should appear;
  • Select the first option, to run Windows in Safe Mode, then press Enter.
  • Choose your usual account.
  • Open the extracted SDFix folder and double click RunThis.bat to start the script.
  • Type Y to begin the cleanup process.
  • It will remove any Trojan Services and Registry Entries that it finds then prompt you to press any key to Reboot.
  • Press any Key and it will restart the PC.
  • When the PC restarts the Fixtool will run again and complete the removal process then display Finished, press any key to end the script and load your desktop icons.
  • Once the desktop icons load the SDFix report will open on screen and also save into the SDFix folder as Report.txt
    (Report.txt will also be copied to Clipboard ready for posting back on the forum).
  • Finally paste the contents of the Report.txt back on the forum with a new HijackThis log
-----------------------------------------
Post back:
SDFix report.
A new HijackThis log.
Posted Image
Private Messages for personal support will be ignored. If you need help post in the forum.

#4 Penguin73

Penguin73
  • Topic Starter

  • Members
  • 19 posts
  • OFFLINE
  •  
  • Local time:06:08 AM

Posted 16 February 2008 - 06:39 PM

Here they are:

SDFix: Version 1.142

Run by Michael on Sat 02/16/2008 at 05:30 PM

Microsoft Windows XP [Version 5.1.2600]

Running From: C:\SDFix

Safe Mode:
Checking Services:


Restoring Windows Registry Values
Restoring Windows Default Hosts File

Rebooting...


Normal Mode:
Checking Files:

Trojan Files Found:

C:\DOCUME~1\Michael\LOCALS~1\Temp\ac8zt2.dat - Deleted
C:\WINDOWS\rs.txt - Deleted
C:\WINDOWS\search_res.txt - Deleted





Removing Temp Files...

ADS Check:



Final Check:

catchme 0.3.1344.2 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2008-02-16 18:14:44
Windows 5.1.2600 Service Pack 2 NTFS

scanning hidden processes ...

scanning hidden services & system hive ...

scanning hidden registry entries ...

scanning hidden files ...

scan completed successfully
hidden processes: 0
hidden services: 0
hidden files: 0


Remaining Services:
------------------



Authorized Application Key Export:

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\standardprofile\authorizedapplications\list]
"C:\\Program Files\\Yahoo!\\Messenger\\YahooMessenger.exe"="C:\\Program Files\\Yahoo!\\Messenger\\YahooMessenger.exe:*:Enabled:Yahoo! Messenger"
"C:\\Program Files\\MSN Messenger\\msnmsgr.exe"="C:\\Program Files\\MSN Messenger\\msnmsgr.exe:*:Enabled:Messenger"
"C:\\Program Files\\Kodak\\pictures\\Kodak EasyShare software\\bin\\EasyShare.exe"="C:\\Program Files\\Kodak\\pictures\\Kodak EasyShare software\\bin\\EasyShare.exe:*:Enabled:EasyShare"

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\domainprofile\authorizedapplications\list]

Remaining Files:
---------------

File Backups: - C:\SDFix\backups\backups.zip

Files with Hidden Attributes:

Tue 21 Aug 2007 4,348 A.SH. --- "C:\Documents and Settings\All Users\DRM\DRMv1.bak"
Tue 1 May 2007 1,318,912 ...H. --- "C:\Program Files\PopCap Games\BookWorm Deluxe\game.exe"
Wed 11 Jul 2007 1,318,912 ...H. --- "C:\Program Files\PopCap Games\BookWorm Deluxe\game2.exe"
Sun 21 Jan 2007 1,290,240 ...H. --- "C:\Program Files\PopCap Games\Zuma Deluxe\popcapgame1.exe"
Sat 20 Jan 2007 1,290,240 ...H. --- "C:\Program Files\PopCap Games\Zuma Deluxe\popcapgame2.exe"
Tue 29 Jan 2008 0 A..H. --- "C:\Documents and Settings\Christopher\Local Settings\Temp\BIT94.tmp"
Tue 29 Jan 2008 0 A..H. --- "C:\Documents and Settings\Christopher\Local Settings\Temp\BIT96.tmp"
Tue 29 Jan 2008 0 A..H. --- "C:\Documents and Settings\Christopher\Local Settings\Temp\BIT98.tmp"
Tue 29 Jan 2008 0 A..H. --- "C:\Documents and Settings\Christopher\Local Settings\Temp\BIT9A.tmp"
Tue 29 Jan 2008 0 A..H. --- "C:\Documents and Settings\Christopher\Local Settings\Temp\BIT9E.tmp"
Tue 29 Jan 2008 0 A..H. --- "C:\Documents and Settings\Christopher\Local Settings\Temp\BITA0.tmp"
Tue 29 Jan 2008 0 A..H. --- "C:\Documents and Settings\Christopher\Local Settings\Temp\BITA3.tmp"
Tue 29 Jan 2008 0 A..H. --- "C:\Documents and Settings\Christopher\Local Settings\Temp\BITA6.tmp"
Tue 29 Jan 2008 0 A..H. --- "C:\Documents and Settings\Christopher\Local Settings\Temp\BITA9.tmp"
Tue 29 Jan 2008 0 A..H. --- "C:\Documents and Settings\Christopher\Local Settings\Temp\BITAB.tmp"
Wed 6 Feb 2008 0 A..H. --- "C:\Documents and Settings\Ginna\Local Settings\Temp\BIT100.tmp"
Wed 6 Feb 2008 0 A..H. --- "C:\Documents and Settings\Ginna\Local Settings\Temp\BIT101.tmp"
Thu 7 Feb 2008 0 A..H. --- "C:\Documents and Settings\Ginna\Local Settings\Temp\BIT102.tmp"
Thu 7 Feb 2008 0 A..H. --- "C:\Documents and Settings\Ginna\Local Settings\Temp\BIT103.tmp"
Wed 6 Feb 2008 0 A..H. --- "C:\Documents and Settings\Ginna\Local Settings\Temp\BIT104.tmp"
Thu 7 Feb 2008 0 A..H. --- "C:\Documents and Settings\Ginna\Local Settings\Temp\BIT105.tmp"
Fri 8 Feb 2008 0 A..H. --- "C:\Documents and Settings\Ginna\Local Settings\Temp\BIT106.tmp"
Sat 9 Feb 2008 0 A..H. --- "C:\Documents and Settings\Ginna\Local Settings\Temp\BIT107.tmp"
Thu 7 Feb 2008 0 A..H. --- "C:\Documents and Settings\Ginna\Local Settings\Temp\BIT108.tmp"
Thu 7 Feb 2008 0 A..H. --- "C:\Documents and Settings\Ginna\Local Settings\Temp\BIT109.tmp"
Thu 7 Feb 2008 0 A..H. --- "C:\Documents and Settings\Ginna\Local Settings\Temp\BIT10A.tmp"
Wed 6 Feb 2008 0 A..H. --- "C:\Documents and Settings\Ginna\Local Settings\Temp\BIT10B.tmp"
Thu 7 Feb 2008 0 A..H. --- "C:\Documents and Settings\Ginna\Local Settings\Temp\BIT10C.tmp"
Thu 7 Feb 2008 0 A..H. --- "C:\Documents and Settings\Ginna\Local Settings\Temp\BIT10D.tmp"
Mon 11 Feb 2008 0 A..H. --- "C:\Documents and Settings\Ginna\Local Settings\Temp\BIT10E.tmp"
Tue 12 Feb 2008 0 A..H. --- "C:\Documents and Settings\Ginna\Local Settings\Temp\BIT10F.tmp"
Mon 11 Feb 2008 0 A..H. --- "C:\Documents and Settings\Ginna\Local Settings\Temp\BIT110.tmp"
Wed 6 Feb 2008 0 A..H. --- "C:\Documents and Settings\Ginna\Local Settings\Temp\BIT111.tmp"
Wed 13 Feb 2008 0 A..H. --- "C:\Documents and Settings\Ginna\Local Settings\Temp\BIT112.tmp"
Wed 6 Feb 2008 0 A..H. --- "C:\Documents and Settings\Ginna\Local Settings\Temp\BIT113.tmp"
Thu 7 Feb 2008 0 A..H. --- "C:\Documents and Settings\Ginna\Local Settings\Temp\BIT114.tmp"
Wed 6 Feb 2008 0 A..H. --- "C:\Documents and Settings\Ginna\Local Settings\Temp\BIT115.tmp"
Thu 24 Jan 2008 85,946 A..H. --- "C:\Documents and Settings\Ginna\Local Settings\Temp\BIT116.tmp"
Wed 6 Feb 2008 0 A..H. --- "C:\Documents and Settings\Ginna\Local Settings\Temp\BIT117.tmp"
Thu 7 Feb 2008 0 A..H. --- "C:\Documents and Settings\Ginna\Local Settings\Temp\BIT118.tmp"
Thu 7 Feb 2008 0 A..H. --- "C:\Documents and Settings\Ginna\Local Settings\Temp\BIT119.tmp"
Thu 7 Feb 2008 0 A..H. --- "C:\Documents and Settings\Ginna\Local Settings\Temp\BIT11A.tmp"
Thu 7 Feb 2008 0 A..H. --- "C:\Documents and Settings\Ginna\Local Settings\Temp\BIT11B.tmp"
Thu 7 Feb 2008 0 A..H. --- "C:\Documents and Settings\Ginna\Local Settings\Temp\BIT11C.tmp"
Sat 9 Feb 2008 0 A..H. --- "C:\Documents and Settings\Ginna\Local Settings\Temp\BIT11D.tmp"
Wed 6 Feb 2008 0 A..H. --- "C:\Documents and Settings\Ginna\Local Settings\Temp\BIT11E.tmp"
Thu 7 Feb 2008 0 A..H. --- "C:\Documents and Settings\Ginna\Local Settings\Temp\BIT11F.tmp"
Thu 7 Feb 2008 0 A..H. --- "C:\Documents and Settings\Ginna\Local Settings\Temp\BIT120.tmp"
Thu 7 Feb 2008 0 A..H. --- "C:\Documents and Settings\Ginna\Local Settings\Temp\BIT121.tmp"
Thu 7 Feb 2008 0 A..H. --- "C:\Documents and Settings\Ginna\Local Settings\Temp\BIT122.tmp"
Thu 7 Feb 2008 0 A..H. --- "C:\Documents and Settings\Ginna\Local Settings\Temp\BIT123.tmp"
Wed 6 Feb 2008 0 A..H. --- "C:\Documents and Settings\Ginna\Local Settings\Temp\BIT124.tmp"
Thu 7 Feb 2008 0 A..H. --- "C:\Documents and Settings\Ginna\Local Settings\Temp\BIT125.tmp"
Thu 7 Feb 2008 0 A..H. --- "C:\Documents and Settings\Ginna\Local Settings\Temp\BIT126.tmp"
Mon 4 Feb 2008 0 A..H. --- "C:\Documents and Settings\Ginna\Local Settings\Temp\BIT127.tmp"
Thu 7 Feb 2008 0 A..H. --- "C:\Documents and Settings\Ginna\Local Settings\Temp\BIT128.tmp"
Mon 4 Feb 2008 0 A..H. --- "C:\Documents and Settings\Ginna\Local Settings\Temp\BIT129.tmp"
Thu 7 Feb 2008 0 A..H. --- "C:\Documents and Settings\Ginna\Local Settings\Temp\BIT12A.tmp"
Thu 7 Feb 2008 0 A..H. --- "C:\Documents and Settings\Ginna\Local Settings\Temp\BIT12B.tmp"
Mon 4 Feb 2008 0 A..H. --- "C:\Documents and Settings\Ginna\Local Settings\Temp\BIT12C.tmp"
Mon 4 Feb 2008 0 A..H. --- "C:\Documents and Settings\Ginna\Local Settings\Temp\BIT12D.tmp"
Wed 6 Feb 2008 0 A..H. --- "C:\Documents and Settings\Ginna\Local Settings\Temp\BIT12E.tmp"
Wed 6 Feb 2008 0 A..H. --- "C:\Documents and Settings\Ginna\Local Settings\Temp\BIT12F.tmp"
Wed 6 Feb 2008 0 A..H. --- "C:\Documents and Settings\Ginna\Local Settings\Temp\BIT130.tmp"
Wed 6 Feb 2008 0 A..H. --- "C:\Documents and Settings\Ginna\Local Settings\Temp\BIT131.tmp"
Thu 7 Feb 2008 0 A..H. --- "C:\Documents and Settings\Ginna\Local Settings\Temp\BIT132.tmp"
Thu 7 Feb 2008 0 A..H. --- "C:\Documents and Settings\Ginna\Local Settings\Temp\BIT133.tmp"
Thu 7 Feb 2008 0 A..H. --- "C:\Documents and Settings\Ginna\Local Settings\Temp\BIT134.tmp"
Wed 6 Feb 2008 0 A..H. --- "C:\Documents and Settings\Ginna\Local Settings\Temp\BIT135.tmp"
Wed 6 Feb 2008 0 A..H. --- "C:\Documents and Settings\Ginna\Local Settings\Temp\BIT136.tmp"
Thu 7 Feb 2008 0 A..H. --- "C:\Documents and Settings\Ginna\Local Settings\Temp\BIT137.tmp"
Wed 6 Feb 2008 0 A..H. --- "C:\Documents and Settings\Ginna\Local Settings\Temp\BIT138.tmp"
Thu 7 Feb 2008 0 A..H. --- "C:\Documents and Settings\Ginna\Local Settings\Temp\BIT139.tmp"
Thu 7 Feb 2008 0 A..H. --- "C:\Documents and Settings\Ginna\Local Settings\Temp\BIT13A.tmp"
Wed 6 Feb 2008 0 A..H. --- "C:\Documents and Settings\Ginna\Local Settings\Temp\BIT13B.tmp"
Thu 7 Feb 2008 0 A..H. --- "C:\Documents and Settings\Ginna\Local Settings\Temp\BIT13C.tmp"
Thu 7 Feb 2008 0 A..H. --- "C:\Documents and Settings\Ginna\Local Settings\Temp\BIT13D.tmp"
Thu 7 Feb 2008 0 A..H. --- "C:\Documents and Settings\Ginna\Local Settings\Temp\BIT13E.tmp"
Thu 7 Feb 2008 0 A..H. --- "C:\Documents and Settings\Ginna\Local Settings\Temp\BIT13F.tmp"
Thu 7 Feb 2008 0 A..H. --- "C:\Documents and Settings\Ginna\Local Settings\Temp\BIT140.tmp"
Wed 6 Feb 2008 0 A..H. --- "C:\Documents and Settings\Ginna\Local Settings\Temp\BIT141.tmp"
Mon 4 Feb 2008 0 A..H. --- "C:\Documents and Settings\Ginna\Local Settings\Temp\BIT142.tmp"
Mon 4 Feb 2008 0 A..H. --- "C:\Documents and Settings\Ginna\Local Settings\Temp\BIT143.tmp"
Wed 6 Feb 2008 0 A..H. --- "C:\Documents and Settings\Ginna\Local Settings\Temp\BIT144.tmp"
Wed 6 Feb 2008 0 A..H. --- "C:\Documents and Settings\Ginna\Local Settings\Temp\BIT145.tmp"
Wed 6 Feb 2008 0 A..H. --- "C:\Documents and Settings\Ginna\Local Settings\Temp\BIT146.tmp"
Mon 4 Feb 2008 0 A..H. --- "C:\Documents and Settings\Ginna\Local Settings\Temp\BIT147.tmp"
Mon 4 Feb 2008 0 A..H. --- "C:\Documents and Settings\Ginna\Local Settings\Temp\BIT148.tmp"
Mon 4 Feb 2008 0 A..H. --- "C:\Documents and Settings\Ginna\Local Settings\Temp\BIT149.tmp"
Wed 6 Feb 2008 0 A..H. --- "C:\Documents and Settings\Ginna\Local Settings\Temp\BIT14A.tmp"
Thu 24 Jan 2008 85,946 A..H. --- "C:\Documents and Settings\Ginna\Local Settings\Temp\BIT14B.tmp"
Mon 4 Feb 2008 0 A..H. --- "C:\Documents and Settings\Ginna\Local Settings\Temp\BIT14C.tmp"
Wed 6 Feb 2008 0 A..H. --- "C:\Documents and Settings\Ginna\Local Settings\Temp\BIT14D.tmp"
Mon 4 Feb 2008 0 A..H. --- "C:\Documents and Settings\Ginna\Local Settings\Temp\BIT14E.tmp"
Wed 6 Feb 2008 0 A..H. --- "C:\Documents and Settings\Ginna\Local Settings\Temp\BIT14F.tmp"
Mon 4 Feb 2008 0 A..H. --- "C:\Documents and Settings\Ginna\Local Settings\Temp\BIT150.tmp"
Mon 4 Feb 2008 0 A..H. --- "C:\Documents and Settings\Ginna\Local Settings\Temp\BIT151.tmp"
Wed 6 Feb 2008 0 A..H. --- "C:\Documents and Settings\Ginna\Local Settings\Temp\BIT152.tmp"
Mon 4 Feb 2008 0 A..H. --- "C:\Documents and Settings\Ginna\Local Settings\Temp\BIT153.tmp"
Mon 4 Feb 2008 0 A..H. --- "C:\Documents and Settings\Ginna\Local Settings\Temp\BIT154.tmp"
Mon 4 Feb 2008 0 A..H. --- "C:\Documents and Settings\Ginna\Local Settings\Temp\BIT155.tmp"
Wed 6 Feb 2008 0 A..H. --- "C:\Documents and Settings\Ginna\Local Settings\Temp\BIT156.tmp"
Mon 4 Feb 2008 0 A..H. --- "C:\Documents and Settings\Ginna\Local Settings\Temp\BIT157.tmp"
Wed 6 Feb 2008 0 A..H. --- "C:\Documents and Settings\Ginna\Local Settings\Temp\BIT158.tmp"
Wed 6 Feb 2008 0 A..H. --- "C:\Documents and Settings\Ginna\Local Settings\Temp\BIT159.tmp"
Mon 4 Feb 2008 0 A..H. --- "C:\Documents and Settings\Ginna\Local Settings\Temp\BIT15A.tmp"
Wed 6 Feb 2008 0 A..H. --- "C:\Documents and Settings\Ginna\Local Settings\Temp\BIT15B.tmp"
Wed 6 Feb 2008 0 A..H. --- "C:\Documents and Settings\Ginna\Local Settings\Temp\BIT15C.tmp"
Wed 6 Feb 2008 0 A..H. --- "C:\Documents and Settings\Ginna\Local Settings\Temp\BIT15D.tmp"
Wed 6 Feb 2008 0 A..H. --- "C:\Documents and Settings\Ginna\Local Settings\Temp\BIT15E.tmp"
Wed 6 Feb 2008 0 A..H. --- "C:\Documents and Settings\Ginna\Local Settings\Temp\BIT15F.tmp"
Wed 6 Feb 2008 0 A..H. --- "C:\Documents and Settings\Ginna\Local Settings\Temp\BIT160.tmp"
Wed 6 Feb 2008 0 A..H. --- "C:\Documents and Settings\Ginna\Local Settings\Temp\BIT161.tmp"
Wed 6 Feb 2008 0 A..H. --- "C:\Documents and Settings\Ginna\Local Settings\Temp\BIT162.tmp"
Wed 6 Feb 2008 0 A..H. --- "C:\Documents and Settings\Ginna\Local Settings\Temp\BIT163.tmp"
Wed 6 Feb 2008 0 A..H. --- "C:\Documents and Settings\Ginna\Local Settings\Temp\BIT164.tmp"
Wed 6 Feb 2008 0 A..H. --- "C:\Documents and Settings\Ginna\Local Settings\Temp\BIT165.tmp"
Wed 6 Feb 2008 0 A..H. --- "C:\Documents and Settings\Ginna\Local Settings\Temp\BIT166.tmp"
Wed 6 Feb 2008 0 A..H. --- "C:\Documents and Settings\Ginna\Local Settings\Temp\BIT167.tmp"
Wed 6 Feb 2008 0 A..H. --- "C:\Documents and Settings\Ginna\Local Settings\Temp\BIT168.tmp"
Wed 6 Feb 2008 0 A..H. --- "C:\Documents and Settings\Ginna\Local Settings\Temp\BIT169.tmp"
Wed 6 Feb 2008 0 A..H. --- "C:\Documents and Settings\Ginna\Local Settings\Temp\BIT16A.tmp"
Wed 6 Feb 2008 0 A..H. --- "C:\Documents and Settings\Ginna\Local Settings\Temp\BIT16B.tmp"
Thu 7 Feb 2008 0 A..H. --- "C:\Documents and Settings\Ginna\Local Settings\Temp\BIT16C.tmp"
Thu 7 Feb 2008 0 A..H. --- "C:\Documents and Settings\Ginna\Local Settings\Temp\BIT16D.tmp"
Thu 7 Feb 2008 0 A..H. --- "C:\Documents and Settings\Ginna\Local Settings\Temp\BIT16E.tmp"
Thu 7 Feb 2008 0 A..H. --- "C:\Documents and Settings\Ginna\Local Settings\Temp\BIT16F.tmp"
Thu 7 Feb 2008 0 A..H. --- "C:\Documents and Settings\Ginna\Local Settings\Temp\BIT170.tmp"
Thu 7 Feb 2008 0 A..H. --- "C:\Documents and Settings\Ginna\Local Settings\Temp\BIT171.tmp"
Thu 7 Feb 2008 0 A..H. --- "C:\Documents and Settings\Ginna\Local Settings\Temp\BIT172.tmp"
Thu 7 Feb 2008 0 A..H. --- "C:\Documents and Settings\Ginna\Local Settings\Temp\BIT173.tmp"
Thu 7 Feb 2008 0 A..H. --- "C:\Documents and Settings\Ginna\Local Settings\Temp\BIT174.tmp"
Thu 7 Feb 2008 0 A..H. --- "C:\Documents and Settings\Ginna\Local Settings\Temp\BIT175.tmp"
Thu 7 Feb 2008 0 A..H. --- "C:\Documents and Settings\Ginna\Local Settings\Temp\BIT176.tmp"
Thu 7 Feb 2008 0 A..H. --- "C:\Documents and Settings\Ginna\Local Settings\Temp\BIT177.tmp"
Thu 7 Feb 2008 0 A..H. --- "C:\Documents and Settings\Ginna\Local Settings\Temp\BIT178.tmp"
Thu 7 Feb 2008 0 A..H. --- "C:\Documents and Settings\Ginna\Local Settings\Temp\BIT179.tmp"
Fri 8 Feb 2008 0 A..H. --- "C:\Documents and Settings\Ginna\Local Settings\Temp\BIT17A.tmp"
Fri 8 Feb 2008 0 A..H. --- "C:\Documents and Settings\Ginna\Local Settings\Temp\BIT17B.tmp"
Sat 9 Feb 2008 0 A..H. --- "C:\Documents and Settings\Ginna\Local Settings\Temp\BIT17C.tmp"
Fri 8 Feb 2008 0 A..H. --- "C:\Documents and Settings\Ginna\Local Settings\Temp\BIT17D.tmp"
Fri 8 Feb 2008 0 A..H. --- "C:\Documents and Settings\Ginna\Local Settings\Temp\BIT17E.tmp"
Sat 9 Feb 2008 0 A..H. --- "C:\Documents and Settings\Ginna\Local Settings\Temp\BIT17F.tmp"
Sat 9 Feb 2008 0 A..H. --- "C:\Documents and Settings\Ginna\Local Settings\Temp\BIT180.tmp"
Mon 4 Feb 2008 0 A..H. --- "C:\Documents and Settings\Ginna\Local Settings\Temp\BIT181.tmp"
Mon 4 Feb 2008 0 A..H. --- "C:\Documents and Settings\Ginna\Local Settings\Temp\BIT182.tmp"
Fri 8 Feb 2008 0 A..H. --- "C:\Documents and Settings\Ginna\Local Settings\Temp\BIT183.tmp"
Fri 8 Feb 2008 0 A..H. --- "C:\Documents and Settings\Ginna\Local Settings\Temp\BIT184.tmp"
Mon 4 Feb 2008 0 A..H. --- "C:\Documents and Settings\Ginna\Local Settings\Temp\BIT185.tmp"
Fri 8 Feb 2008 0 A..H. --- "C:\Documents and Settings\Ginna\Local Settings\Temp\BIT186.tmp"
Sat 9 Feb 2008 0 A..H. --- "C:\Documents and Settings\Ginna\Local Settings\Temp\BIT187.tmp"
Fri 8 Feb 2008 0 A..H. --- "C:\Documents and Settings\Ginna\Local Settings\Temp\BIT188.tmp"
Fri 8 Feb 2008 0 A..H. --- "C:\Documents and Settings\Ginna\Local Settings\Temp\BIT189.tmp"
Mon 4 Feb 2008 0 A..H. --- "C:\Documents and Settings\Ginna\Local Settings\Temp\BIT18A.tmp"
Mon 4 Feb 2008 0 A..H. --- "C:\Documents and Settings\Ginna\Local Settings\Temp\BIT18B.tmp"
Tue 29 Jan 2008 0 A..H. --- "C:\Documents and Settings\Ginna\Local Settings\Temp\BIT18C.tmp"
Tue 29 Jan 2008 0 A..H. --- "C:\Documents and Settings\Ginna\Local Settings\Temp\BIT18D.tmp"
Fri 8 Feb 2008 0 A..H. --- "C:\Documents and Settings\Ginna\Local Settings\Temp\BIT18E.tmp"
Fri 8 Feb 2008 0 A..H. --- "C:\Documents and Settings\Ginna\Local Settings\Temp\BIT18F.tmp"
Tue 29 Jan 2008 0 A..H. --- "C:\Documents and Settings\Ginna\Local Settings\Temp\BIT190.tmp"
Tue 29 Jan 2008 0 A..H. --- "C:\Documents and Settings\Ginna\Local Settings\Temp\BIT191.tmp"
Tue 29 Jan 2008 0 A..H. --- "C:\Documents and Settings\Ginna\Local Settings\Temp\BIT192.tmp"
Fri 8 Feb 2008 0 A..H. --- "C:\Documents and Settings\Ginna\Local Settings\Temp\BIT193.tmp"
Wed 6 Feb 2008 0 A..H. --- "C:\Documents and Settings\Ginna\Local Settings\Temp\BIT194.tmp"
Fri 8 Feb 2008 0 A..H. --- "C:\Documents and Settings\Ginna\Local Settings\Temp\BIT195.tmp"
Tue 29 Jan 2008 0 A..H. --- "C:\Documents and Settings\Ginna\Local Settings\Temp\BIT196.tmp"
Tue 29 Jan 2008 0 A..H. --- "C:\Documents and Settings\Ginna\Local Settings\Temp\BIT197.tmp"
Tue 29 Jan 2008 0 A..H. --- "C:\Documents and Settings\Ginna\Local Settings\Temp\BIT198.tmp"
Mon 4 Feb 2008 0 A..H. --- "C:\Documents and Settings\Ginna\Local Settings\Temp\BIT199.tmp"
Fri 8 Feb 2008 0 A..H. --- "C:\Documents and Settings\Ginna\Local Settings\Temp\BIT19A.tmp"
Thu 7 Feb 2008 0 A..H. --- "C:\Documents and Settings\Ginna\Local Settings\Temp\BIT19B.tmp"
Fri 8 Feb 2008 0 A..H. --- "C:\Documents and Settings\Ginna\Local Settings\Temp\BIT19C.tmp"
Fri 8 Feb 2008 0 A..H. --- "C:\Documents and Settings\Ginna\Local Settings\Temp\BIT19D.tmp"
Fri 8 Feb 2008 0 A..H. --- "C:\Documents and Settings\Ginna\Local Settings\Temp\BIT19E.tmp"
Fri 8 Feb 2008 0 A..H. --- "C:\Documents and Settings\Ginna\Local Settings\Temp\BIT19F.tmp"
Fri 8 Feb 2008 0 A..H. --- "C:\Documents and Settings\Ginna\Local Settings\Temp\BIT1A0.tmp"
Mon 4 Feb 2008 0 A..H. --- "C:\Documents and Settings\Ginna\Local Settings\Temp\BIT1A1.tmp"
Mon 4 Feb 2008 0 A..H. --- "C:\Documents and Settings\Ginna\Local Settings\Temp\BIT1A2.tmp"
Mon 4 Feb 2008 0 A..H. --- "C:\Documents and Settings\Ginna\Local Settings\Temp\BIT1A3.tmp"
Thu 31 Jan 2008 0 A..H. --- "C:\Documents and Settings\Ginna\Local Settings\Temp\BIT1A4.tmp"
Thu 31 Jan 2008 0 A..H. --- "C:\Documents and Settings\Ginna\Local Settings\Temp\BIT1A5.tmp"
Thu 31 Jan 2008 0 A..H. --- "C:\Documents and Settings\Ginna\Local Settings\Temp\BIT1A6.tmp"
Thu 24 Jan 2008 85,946 A..H. --- "C:\Documents and Settings\Ginna\Local Settings\Temp\BIT1A7.tmp"
Thu 31 Jan 2008 0 A..H. --- "C:\Documents and Settings\Ginna\Local Settings\Temp\BIT1A8.tmp"
Thu 31 Jan 2008 0 A..H. --- "C:\Documents and Settings\Ginna\Local Settings\Temp\BIT1A9.tmp"
Thu 31 Jan 2008 0 A..H. --- "C:\Documents and Settings\Ginna\Local Settings\Temp\BIT1AA.tmp"
Mon 4 Feb 2008 0 A..H. --- "C:\Documents and Settings\Ginna\Local Settings\Temp\BIT1AB.tmp"
Thu 31 Jan 2008 0 A..H. --- "C:\Documents and Settings\Ginna\Local Settings\Temp\BIT1AC.tmp"
Thu 31 Jan 2008 0 A..H. --- "C:\Documents and Settings\Ginna\Local Settings\Temp\BIT1AD.tmp"
Thu 31 Jan 2008 0 A..H. --- "C:\Documents and Settings\Ginna\Local Settings\Temp\BIT1AE.tmp"
Thu 31 Jan 2008 0 A..H. --- "C:\Documents and Settings\Ginna\Local Settings\Temp\BIT1AF.tmp"
Fri 1 Feb 2008 0 A..H. --- "C:\Documents and Settings\Ginna\Local Settings\Temp\BIT1B0.tmp"
Mon 4 Feb 2008 0 A..H. --- "C:\Documents and Settings\Ginna\Local Settings\Temp\BIT1B1.tmp"
Thu 31 Jan 2008 0 A..H. --- "C:\Documents and Settings\Ginna\Local Settings\Temp\BIT1B2.tmp"
Fri 1 Feb 2008 0 A..H. --- "C:\Documents and Settings\Ginna\Local Settings\Temp\BIT1B3.tmp"
Thu 31 Jan 2008 0 A..H. --- "C:\Documents and Settings\Ginna\Local Settings\Temp\BIT1B4.tmp"
Thu 31 Jan 2008 0 A..H. --- "C:\Documents and Settings\Ginna\Local Settings\Temp\BIT1B5.tmp"
Fri 1 Feb 2008 0 A..H. --- "C:\Documents and Settings\Ginna\Local Settings\Temp\BIT1B6.tmp"
Thu 31 Jan 2008 0 A..H. --- "C:\Documents and Settings\Ginna\Local Settings\Temp\BIT1B7.tmp"
Thu 31 Jan 2008 0 A..H. --- "C:\Documents and Settings\Ginna\Local Settings\Temp\BIT1B8.tmp"
Fri 1 Feb 2008 0 A..H. --- "C:\Documents and Settings\Ginna\Local Settings\Temp\BIT1B9.tmp"
Thu 31 Jan 2008 0 A..H. --- "C:\Documents and Settings\Ginna\Local Settings\Temp\BIT1BA.tmp"
Mon 4 Feb 2008 0 A..H. --- "C:\Documents and Settings\Ginna\Local Settings\Temp\BIT1BB.tmp"
Thu 31 Jan 2008 0 A..H. --- "C:\Documents and Settings\Ginna\Local Settings\Temp\BIT1BC.tmp"
Thu 31 Jan 2008 0 A..H. --- "C:\Documents and Settings\Ginna\Local Settings\Temp\BIT1BD.tmp"
Mon 4 Feb 2008 0 A..H. --- "C:\Documents and Settings\Ginna\Local Settings\Temp\BIT1BE.tmp"
Tue 29 Jan 2008 0 A..H. --- "C:\Documents and Settings\Ginna\Local Settings\Temp\BIT1BF.tmp"
Thu 31 Jan 2008 0 A..H. --- "C:\Documents and Settings\Ginna\Local Settings\Temp\BIT1C0.tmp"
Tue 29 Jan 2008 0 A..H. --- "C:\Documents and Settings\Ginna\Local Settings\Temp\BIT1C1.tmp"
Tue 29 Jan 2008 0 A..H. --- "C:\Documents and Settings\Ginna\Local Settings\Temp\BIT1C2.tmp"
Tue 29 Jan 2008 0 A..H. --- "C:\Documents and Settings\Ginna\Local Settings\Temp\BIT1C3.tmp"
Thu 31 Jan 2008 0 A..H. --- "C:\Documents and Settings\Ginna\Local Settings\Temp\BIT1C4.tmp"
Tue 29 Jan 2008 0 A..H. --- "C:\Documents and Settings\Ginna\Local Settings\Temp\BIT1C5.tmp"
Tue 29 Jan 2008 0 A..H. --- "C:\Documents and Settings\Ginna\Local Settings\Temp\BIT1C6.tmp"
Tue 29 Jan 2008 0 A..H. --- "C:\Documents and Settings\Ginna\Local Settings\Temp\BIT1C7.tmp"
Tue 29 Jan 2008 0 A..H. --- "C:\Documents and Settings\Ginna\Local Settings\Temp\BIT1C8.tmp"
Tue 29 Jan 2008 0 A..H. --- "C:\Documents and Settings\Ginna\Local Settings\Temp\BIT1C9.tmp"
Tue 29 Jan 2008 0 A..H. --- "C:\Documents and Settings\Ginna\Local Settings\Temp\BIT1CA.tmp"
Tue 29 Jan 2008 0 A..H. --- "C:\Documents and Settings\Ginna\Local Settings\Temp\BIT1CB.tmp"
Tue 29 Jan 2008 0 A..H. --- "C:\Documents and Settings\Ginna\Local Settings\Temp\BIT1CC.tmp"
Wed 30 Jan 2008 0 A..H. --- "C:\Documents and Settings\Ginna\Local Settings\Temp\BIT1CD.tmp"
Thu 31 Jan 2008 0 A..H. --- "C:\Documents and Settings\Ginna\Local Settings\Temp\BIT1CE.tmp"
Thu 31 Jan 2008 0 A..H. --- "C:\Documents and Settings\Ginna\Local Settings\Temp\BIT1CF.tmp"
Wed 30 Jan 2008 0 A..H. --- "C:\Documents and Settings\Ginna\Local Settings\Temp\BIT1D0.tmp"
Wed 30 Jan 2008 0 A..H. --- "C:\Documents and Settings\Ginna\Local Settings\Temp\BIT1D1.tmp"
Wed 30 Jan 2008 0 A..H. --- "C:\Documents and Settings\Ginna\Local Settings\Temp\BIT1D2.tmp"
Mon 4 Feb 2008 0 A..H. --- "C:\Documents and Settings\Ginna\Local Settings\Temp\BIT1D3.tmp"
Wed 30 Jan 2008 0 A..H. --- "C:\Documents and Settings\Ginna\Local Settings\Temp\BIT1D4.tmp"
Wed 30 Jan 2008 0 A..H. --- "C:\Documents and Settings\Ginna\Local Settings\Temp\BIT1D5.tmp"
Wed 30 Jan 2008 0 A..H. --- "C:\Documents and Settings\Ginna\Local Settings\Temp\BIT1D6.tmp"
Wed 30 Jan 2008 0 A..H. --- "C:\Documents and Settings\Ginna\Local Settings\Temp\BIT1D7.tmp"
Wed 30 Jan 2008 0 A..H. --- "C:\Documents and Settings\Ginna\Local Settings\Temp\BIT1D8.tmp"
Wed 30 Jan 2008 0 A..H. --- "C:\Documents and Settings\Ginna\Local Settings\Temp\BIT1D9.tmp"
Wed 30 Jan 2008 0 A..H. --- "C:\Documents and Settings\Ginna\Local Settings\Temp\BIT1DA.tmp"
Wed 30 Jan 2008 0 A..H. --- "C:\Documents and Settings\Ginna\Local Settings\Temp\BIT1DB.tmp"
Wed 30 Jan 2008 0 A..H. --- "C:\Documents and Settings\Ginna\Local Settings\Temp\BIT1DC.tmp"
Wed 30 Jan 2008 0 A..H. --- "C:\Documents and Settings\Ginna\Local Settings\Temp\BIT1DD.tmp"
Thu 31 Jan 2008 0 A..H. --- "C:\Documents and Settings\Ginna\Local Settings\Temp\BIT1DE.tmp"
Mon 4 Feb 2008 0 A..H. --- "C:\Documents and Settings\Ginna\Local Settings\Temp\BIT1DF.tmp"
Fri 1 Feb 2008 0 A..H. --- "C:\Documents and Settings\Ginna\Local Settings\Temp\BIT1E0.tmp"
Mon 4 Feb 2008 0 A..H. --- "C:\Documents and Settings\Ginna\Local Settings\Temp\BIT1E1.tmp"
Tue 5 Feb 2008 0 A..H. --- "C:\Documents and Settings\Ginna\Local Settings\Temp\BIT1E2.tmp"
Tue 5 Feb 2008 0 A..H. --- "C:\Documents and Settings\Ginna\Local Settings\Temp\BIT1E3.tmp"
Tue 5 Feb 2008 0 A..H. --- "C:\Documents and Settings\Ginna\Local Settings\Temp\BIT1E4.tmp"
Tue 5 Feb 2008 0 A..H. --- "C:\Documents and Settings\Ginna\Local Settings\Temp\BIT1E5.tmp"
Tue 5 Feb 2008 0 A..H. --- "C:\Documents and Settings\Ginna\Local Settings\Temp\BIT1E6.tmp"
Tue 5 Feb 2008 0 A..H. --- "C:\Documents and Settings\Ginna\Local Settings\Temp\BIT1E7.tmp"
Wed 6 Feb 2008 0 A..H. --- "C:\Documents and Settings\Ginna\Local Settings\Temp\BIT1E8.tmp"
Wed 6 Feb 2008 0 A..H. --- "C:\Documents and Settings\Ginna\Local Settings\Temp\BIT1E9.tmp"
Thu 7 Feb 2008 0 A..H. --- "C:\Documents and Settings\Ginna\Local Settings\Temp\BIT1EA.tmp"
Wed 6 Feb 2008 0 A..H. --- "C:\Documents and Settings\Ginna\Local Settings\Temp\BIT1EB.tmp"
Wed 6 Feb 2008 0 A..H. --- "C:\Documents and Settings\Ginna\Local Settings\Temp\BIT1EC.tmp"
Wed 6 Feb 2008 0 A..H. --- "C:\Documents and Settings\Ginna\Local Settings\Temp\BIT1ED.tmp"
Wed 6 Feb 2008 0 A..H. --- "C:\Documents and Settings\Ginna\Local Settings\Temp\BIT1EE.tmp"
Wed 6 Feb 2008 0 A..H. --- "C:\Documents and Settings\Ginna\Local Settings\Temp\BIT1EF.tmp"
Wed 6 Feb 2008 0 A..H. --- "C:\Documents and Settings\Ginna\Local Settings\Temp\BIT1F0.tmp"
Fri 1 Feb 2008 0 A..H. --- "C:\Documents and Settings\Ginna\Local Settings\Temp\BIT1F1.tmp"
Wed 6 Feb 2008 0 A..H. --- "C:\Documents and Settings\Ginna\Local Settings\Temp\BIT1F2.tmp"
Fri 1 Feb 2008 0 A..H. --- "C:\Documents and Settings\Ginna\Local Settings\Temp\BIT1F3.tmp"
Sat 2 Feb 2008 0 A..H. --- "C:\Documents and Settings\Ginna\Local Settings\Temp\BIT1F4.tmp"
Wed 6 Feb 2008 0 A..H. --- "C:\Documents and Settings\Ginna\Local Settings\Temp\BIT1F5.tmp"
Wed 6 Feb 2008 0 A..H. --- "C:\Documents and Settings\Ginna\Local Settings\Temp\BIT1F6.tmp"
Sat 2 Feb 2008 0 A..H. --- "C:\Documents and Settings\Ginna\Local Settings\Temp\BIT1F7.tmp"
Thu 7 Feb 2008 0 A..H. --- "C:\Documents and Settings\Ginna\Local Settings\Temp\BIT1F8.tmp"
Sat 2 Feb 2008 0 A..H. --- "C:\Documents and Settings\Ginna\Local Settings\Temp\BIT1F9.tmp"
Thu 7 Feb 2008 0 A..H. --- "C:\Documents and Settings\Ginna\Local Settings\Temp\BIT1FA.tmp"
Sat 2 Feb 2008 0 A..H. --- "C:\Documents and Settings\Ginna\Local Settings\Temp\BIT1FB.tmp"
Thu 7 Feb 2008 0 A..H. --- "C:\Documents and Settings\Ginna\Local Settings\Temp\BIT1FC.tmp"
Fri 8 Feb 2008 0 A..H. --- "C:\Documents and Settings\Ginna\Local Settings\Temp\BIT1FD.tmp"
Fri 8 Feb 2008 0 A..H. --- "C:\Documents and Settings\Ginna\Local Settings\Temp\BIT1FE.tmp"
Fri 8 Feb 2008 0 A..H. --- "C:\Documents and Settings\Ginna\Local Settings\Temp\BIT1FF.tmp"
Thu 7 Feb 2008 0 A..H. --- "C:\Documents and Settings\Ginna\Local Settings\Temp\BIT2.tmp"
Fri 8 Feb 2008 0 A..H. --- "C:\Documents and Settings\Ginna\Local Settings\Temp\BIT200.tmp"
Fri 8 Feb 2008 0 A..H. --- "C:\Documents and Settings\Ginna\Local Settings\Temp\BIT201.tmp"
Fri 8 Feb 2008 0 A..H. --- "C:\Documents and Settings\Ginna\Local Settings\Temp\BIT202.tmp"
Sat 9 Feb 2008 0 A..H. --- "C:\Documents and Settings\Ginna\Local Settings\Temp\BIT203.tmp"
Sat 9 Feb 2008 0 A..H. --- "C:\Documents and Settings\Ginna\Local Settings\Temp\BIT204.tmp"
Wed 6 Feb 2008 0 A..H. --- "C:\Documents and Settings\Ginna\Local Settings\Temp\BIT205.tmp"
Wed 6 Feb 2008 0 A..H. --- "C:\Documents and Settings\Ginna\Local Settings\Temp\BIT206.tmp"
Wed 6 Feb 2008 0 A..H. --- "C:\Documents and Settings\Ginna\Local Settings\Temp\BIT207.tmp"
Wed 6 Feb 2008 0 A..H. --- "C:\Documents and Settings\Ginna\Local Settings\Temp\BIT208.tmp"
Wed 6 Feb 2008 0 A..H. --- "C:\Documents and Settings\Ginna\Local Settings\Temp\BIT209.tmp"
Wed 6 Feb 2008 0 A..H. --- "C:\Documents and Settings\Ginna\Local Settings\Temp\BIT20A.tmp"
Wed 6 Feb 2008 0 A..H. --- "C:\Documents and Settings\Ginna\Local Settings\Temp\BIT20B.tmp"
Wed 6 Feb 2008 0 A..H. --- "C:\Documents and Settings\Ginna\Local Settings\Temp\BIT20C.tmp"
Wed 6 Feb 2008 0 A..H. --- "C:\Documents and Settings\Ginna\Local Settings\Temp\BIT20D.tmp"
Wed 6 Feb 2008 0 A..H. --- "C:\Documents and Settings\Ginna\Local Settings\Temp\BIT20E.tmp"
Wed 6 Feb 2008 0 A..H. --- "C:\Documents and Settings\Ginna\Local Settings\Temp\BIT20F.tmp"
Wed 6 Feb 2008 0 A..H. --- "C:\Documents and Settings\Ginna\Local Settings\Temp\BIT210.tmp"
Wed 6 Feb 2008 0 A..H. --- "C:\Documents and Settings\Ginna\Local Settings\Temp\BIT211.tmp"
Mon 28 Jan 2008 0 A..H. --- "C:\Documents and Settings\Ginna\Local Settings\Temp\BIT212.tmp"
Thu 31 Jan 2008 0 A..H. --- "C:\Documents and Settings\Ginna\Local Settings\Temp\BIT213.tmp"
Mon 28 Jan 2008 0 A..H. --- "C:\Documents and Settings\Ginna\Local Settings\Temp\BIT214.tmp"
Thu 31 Jan 2008 0 A..H. --- "C:\Documents and Settings\Ginna\Local Settings\Temp\BIT215.tmp"
Wed 6 Feb 2008 0 A..H. --- "C:\Documents and Settings\Ginna\Local Settings\Temp\BIT216.tmp"
Thu 31 Jan 2008 0 A..H. --- "C:\Documents and Settings\Ginna\Local Settings\Temp\BIT217.tmp"
Wed 6 Feb 2008 0 A..H. --- "C:\Documents and Settings\Ginna\Local Settings\Temp\BIT218.tmp"
Thu 31 Jan 2008 0 A..H. --- "C:\Documents and Settings\Ginna\Local Settings\Temp\BIT219.tmp"
Mon 28 Jan 2008 0 A..H. --- "C:\Documents and Settings\Ginna\Local Settings\Temp\BIT21A.tmp"
Thu 31 Jan 2008 0 A..H. --- "C:\Documents and Settings\Ginna\Local Settings\Temp\BIT21B.tmp"
Wed 6 Feb 2008 0 A..H. --- "C:\Documents and Settings\Ginna\Local Settings\Temp\BIT21C.tmp"
Thu 7 Feb 2008 0 A..H. --- "C:\Documents and Settings\Ginna\Local Settings\Temp\BIT21D.tmp"
Thu 31 Jan 2008 0 A..H. --- "C:\Documents and Settings\Ginna\Local Settings\Temp\BIT21E.tmp"
Thu 31 Jan 2008 0 A..H. --- "C:\Documents and Settings\Ginna\Local Settings\Temp\BIT21F.tmp"
Wed 6 Feb 2008 0 A..H. --- "C:\Documents and Settings\Ginna\Local Settings\Temp\BIT220.tmp"
Thu 31 Jan 2008 0 A..H. --- "C:\Documents and Settings\Ginna\Local Settings\Temp\BIT221.tmp"
Wed 6 Feb 2008 0 A..H. --- "C:\Documents and Settings\Ginna\Local Settings\Temp\BIT222.tmp"
Thu 31 Jan 2008 0 A..H. --- "C:\Documents and Settings\Ginna\Local Settings\Temp\BIT223.tmp"
Thu 31 Jan 2008 0 A..H. --- "C:\Documents and Settings\Ginna\Local Settings\Temp\BIT224.tmp"
Wed 6 Feb 2008 0 A..H. --- "C:\Documents and Settings\Ginna\Local Settings\Temp\BIT225.tmp"
Thu 31 Jan 2008 0 A..H. --- "C:\Documents and Settings\Ginna\Local Settings\Temp\BIT226.tmp"
Mon 28 Jan 2008 0 A..H. --- "C:\Documents and Settings\Ginna\Local Settings\Temp\BIT227.tmp"
Mon 28 Jan 2008 0 A..H. --- "C:\Documents and Settings\Ginna\Local Settings\Temp\BIT228.tmp"
Thu 31 Jan 2008 0 A..H. --- "C:\Documents and Settings\Ginna\Local Settings\Temp\BIT229.tmp"
Wed 6 Feb 2008 0 A..H. --- "C:\Documents and Settings\Ginna\Local Settings\Temp\BIT22A.tmp"
Thu 31 Jan 2008 0 A..H. --- "C:\Documents and Settings\Ginna\Local Settings\Temp\BIT22B.tmp"
Wed 6 Feb 2008 0 A..H. --- "C:\Documents and Settings\Ginna\Local Settings\Temp\BIT22C.tmp"
Thu 31 Jan 2008 0 A..H. --- "C:\Documents and Settings\Ginna\Local Settings\Temp\BIT22D.tmp"
Thu 31 Jan 2008 0 A..H. --- "C:\Documents and Settings\Ginna\Local Settings\Temp\BIT22E.tmp"
Wed 6 Feb 2008 0 A..H. --- "C:\Documents and Settings\Ginna\Local Settings\Temp\BIT22F.tmp"
Thu 31 Jan 2008 0 A..H. --- "C:\Documents and Settings\Ginna\Local Settings\Temp\BIT230.tmp"
Wed 6 Feb 2008 0 A..H. --- "C:\Documents and Settings\Ginna\Local Settings\Temp\BIT231.tmp"
Thu 31 Jan 2008 0 A..H. --- "C:\Documents and Settings\Ginna\Local Settings\Temp\BIT232.tmp"
Wed 6 Feb 2008 0 A..H. --- "C:\Documents and Settings\Ginna\Local Settings\Temp\BIT233.tmp"
Thu 7 Feb 2008 0 A..H. --- "C:\Documents and Settings\Ginna\Local Settings\Temp\BIT234.tmp"
Wed 6 Feb 2008 0 A..H. --- "C:\Documents and Settings\Ginna\Local Settings\Temp\BIT235.tmp"
Thu 7 Feb 2008 0 A..H. --- "C:\Documents and Settings\Ginna\Local Settings\Temp\BIT236.tmp"
Wed 6 Feb 2008 0 A..H. --- "C:\Documents and Settings\Ginna\Local Settings\Temp\BIT237.tmp"
Thu 7 Feb 2008 0 A..H. --- "C:\Documents and Settings\Ginna\Local Settings\Temp\BIT238.tmp"
Wed 6 Feb 2008 0 A..H. --- "C:\Documents and Settings\Ginna\Local Settings\Temp\BIT239.tmp"
Wed 6 Feb 2008 0 A..H. --- "C:\Documents and Settings\Ginna\Local Settings\Temp\BIT23A.tmp"
Thu 7 Feb 2008 0 A..H. --- "C:\Documents and Settings\Ginna\Local Settings\Temp\BIT23B.tmp"
Wed 6 Feb 2008 0 A..H. --- "C:\Documents and Settings\Ginna\Local Settings\Temp\BIT23C.tmp"
Wed 6 Feb 2008 0 A..H. --- "C:\Documents and Settings\Ginna\Local Settings\Temp\BIT23D.tmp"
Thu 7 Feb 2008 0 A..H. --- "C:\Documents and Settings\Ginna\Local Settings\Temp\BIT23E.tmp"
Thu 7 Feb 2008 0 A..H. --- "C:\Documents and Settings\Ginna\Local Settings\Temp\BIT23F.tmp"
Wed 6 Feb 2008 0 A..H. --- "C:\Documents and Settings\Ginna\Local Settings\Temp\BIT240.tmp"
Thu 31 Jan 2008 0 A..H. --- "C:\Documents and Settings\Ginna\Local Settings\Temp\BIT241.tmp"
Thu 31 Jan 2008 0 A..H. --- "C:\Documents and Settings\Ginna\Local Settings\Temp\BIT242.tmp"
Wed 6 Feb 2008 0 A..H. --- "C:\Documents and Settings\Ginna\Local Settings\Temp\BIT243.tmp"
Thu 31 Jan 2008 0 A..H. --- "C:\Documents and Settings\Ginna\Local Settings\Temp\BIT244.tmp"
Thu 31 Jan 2008 0 A..H. --- "C:\Documents and Settings\Ginna\Local Settings\Temp\BIT245.tmp"
Wed 6 Feb 2008 0 A..H. --- "C:\Documents and Settings\Ginna\Local Settings\Temp\BIT246.tmp"
Thu 31 Jan 2008 0 A..H. --- "C:\Documents and Settings\Ginna\Local Settings\Temp\BIT247.tmp"
Thu 31 Jan 2008 0 A..H. --- "C:\Documents and Settings\Ginna\Local Settings\Temp\BIT248.tmp"
Wed 6 Feb 2008 0 A..H. --- "C:\Documents and Settings\Ginna\Local Settings\Temp\BIT249.tmp"
Thu 31 Jan 2008 0 A..H. --- "C:\Documents and Settings\Ginna\Local Settings\Temp\BIT24A.tmp"
Thu 31 Jan 2008 0 A..H. --- "C:\Documents and Settings\Ginna\Local Settings\Temp\BIT24B.tmp"
Thu 31 Jan 2008 0 A..H. --- "C:\Documents and Settings\Ginna\Local Settings\Temp\BIT24C.tmp"
Wed 6 Feb 2008 0 A..H. --- "C:\Documents and Settings\Ginna\Local Settings\Temp\BIT24D.tmp"
Wed 6 Feb 2008 0 A..H. --- "C:\Documents and Settings\Ginna\Local Settings\Temp\BIT24E.tmp"
Thu 7 Feb 2008 0 A..H. --- "C:\Documents and Settings\Ginna\Local Settings\Temp\BIT24F.tmp"
Mon 28 Jan 2008 0 A..H. --- "C:\Documents and Settings\Ginna\Local Settings\Temp\BIT250.tmp"
Thu 31 Jan 2008 0 A..H. --- "C:\Documents and Settings\Ginna\Local Settings\Temp\BIT251.tmp"
Thu 31 Jan 2008 0 A..H. --- "C:\Documents and Settings\Ginna\Local Settings\Temp\BIT252.tmp"
Thu 31 Jan 2008 0 A..H. --- "C:\Documents and Settings\Ginna\Local Settings\Temp\BIT253.tmp"
Thu 31 Jan 2008 0 A..H. --- "C:\Documents and Settings\Ginna\Local Settings\Temp\BIT254.tmp"
Thu 31 Jan 2008 0 A..H. --- "C:\Documents and Settings\Ginna\Local Settings\Temp\BIT255.tmp"
Thu 31 Jan 2008 0 A..H. --- "C:\Documents and Settings\Ginna\Local Settings\Temp\BIT256.tmp"
Thu 31 Jan 2008 0 A..H. --- "C:\Documents and Settings\Ginna\Local Settings\Temp\BIT257.tmp"
Thu 31 Jan 2008 0 A..H. --- "C:\Documents and Settings\Ginna\Local Settings\Temp\BIT258.tmp"
Wed 6 Feb 2008 0 A..H. --- "C:\Documents and Settings\Ginna\Local Settings\Temp\BIT259.tmp"
Thu 7 Feb 2008 0 A..H. --- "C:\Documents and Settings\Ginna\Local Settings\Temp\BIT25A.tmp"
Wed 6 Feb 2008 0 A..H. --- "C:\Documents and Settings\Ginna\Local Settings\Temp\BIT25B.tmp"
Thu 31 Jan 2008 0 A..H. --- "C:\Documents and Settings\Ginna\Local Settings\Temp\BIT25C.tmp"
Thu 31 Jan 2008 0 A..H. --- "C:\Documents and Settings\Ginna\Local Settings\Temp\BIT25D.tmp"
Thu 31 Jan 2008 0 A..H. --- "C:\Documents and Settings\Ginna\Local Settings\Temp\BIT25E.tmp"
Thu 31 Jan 2008 0 A..H. --- "C:\Documents and Settings\Ginna\Local Settings\Temp\BIT25F.tmp"
Wed 6 Feb 2008 0 A..H. --- "C:\Documents and Settings\Ginna\Local Settings\Temp\BIT260.tmp"
Wed 6 Feb 2008 0 A..H. --- "C:\Documents and Settings\Ginna\Local Settings\Temp\BIT261.tmp"
Fri 8 Feb 2008 0 A..H. --- "C:\Documents and Settings\Ginna\Local Settings\Temp\BIT262.tmp"
Thu 31 Jan 2008 0 A..H. --- "C:\Documents and Settings\Ginna\Local Settings\Temp\BIT263.tmp"
Wed 6 Feb 2008 0 A..H. --- "C:\Documents and Settings\Ginna\Local Settings\Temp\BIT264.tmp"
Fri 8 Feb 2008 0 A..H. --- "C:\Documents and Settings\Ginna\Local Settings\Temp\BIT265.tmp"
Fri 8 Feb 2008 0 A..H. --- "C:\Documents and Settings\Ginna\Local Settings\Temp\BIT266.tmp"
Fri 8 Feb 2008 0 A..H. --- "C:\Documents and Settings\Ginna\Local Settings\Temp\BIT267.tmp"
Fri 8 Feb 2008 0 A..H. --- "C:\Documents and Settings\Ginna\Local Settings\Temp\BIT268.tmp"
Thu 7 Feb 2008 0 A..H. --- "C:\Documents and Settings\Ginna\Local Settings\Temp\BIT269.tmp"
Thu 7 Feb 2008 0 A..H. --- "C:\Documents and Settings\Ginna\Local Settings\Temp\BIT26A.tmp"
Wed 6 Feb 2008 0 A..H. --- "C:\Documents and Settings\Ginna\Local Settings\Temp\BIT26B.tmp"
Thu 7 Feb 2008 0 A..H. --- "C:\Documents and Settings\Ginna\Local Settings\Temp\BIT26C.tmp"
Thu 7 Feb 2008 0 A..H. --- "C:\Documents and Settings\Ginna\Local Settings\Temp\BIT26D.tmp"
Thu 7 Feb 2008 0 A..H. --- "C:\Documents and Settings\Ginna\Local Settings\Temp\BIT26E.tmp"
Thu 7 Feb 2008 0 A..H. --- "C:\Documents and Settings\Ginna\Local Settings\Temp\BIT26F.tmp"
Fri 8 Feb 2008 0 A..H. --- "C:\Documents and Settings\Ginna\Local Settings\Temp\BIT270.tmp"
Thu 7 Feb 2008 0 A..H. --- "C:\Documents and Settings\Ginna\Local Settings\Temp\BIT271.tmp"
Thu 7 Feb 2008 0 A..H. --- "C:\Documents and Settings\Ginna\Local Settings\Temp\BIT272.tmp"
Thu 7 Feb 2008 0 A..H. --- "C:\Documents and Settings\Ginna\Local Settings\Temp\BIT273.tmp"
Thu 7 Feb 2008 0 A..H. --- "C:\Documents and Settings\Ginna\Local Settings\Temp\BIT274.tmp"
Thu 7 Feb 2008 0 A..H. --- "C:\Documents and Settings\Ginna\Local Settings\Temp\BIT275.tmp"
Thu 7 Feb 2008 0 A..H. --- "C:\Documents and Settings\Ginna\Local Settings\Temp\BIT276.tmp"
Fri 8 Feb 2008 0 A..H. --- "C:\Documents and Settings\Ginna\Local Settings\Temp\BIT277.tmp"
Thu 7 Feb 2008 0 A..H. --- "C:\Documents and Settings\Ginna\Local Settings\Temp\BIT278.tmp"
Thu 7 Feb 2008 0 A..H. --- "C:\Documents and Settings\Ginna\Local Settings\Temp\BIT279.tmp"
Fri 8 Feb 2008 0 A..H. --- "C:\Documents and Settings\Ginna\Local Settings\Temp\BIT27A.tmp"
Thu 7 Feb 2008 0 A..H. --- "C:\Documents and Settings\Ginna\Local Settings\Temp\BIT27B.tmp"
Fri 8 Feb 2008 0 A..H. --- "C:\Documents and Settings\Ginna\Local Settings\Temp\BIT27C.tmp"
Thu 7 Feb 2008 0 A..H. --- "C:\Documents and Settings\Ginna\Local Settings\Temp\BIT27D.tmp"
Thu 7 Feb 2008 0 A..H. --- "C:\Documents and Settings\Ginna\Local Settings\Temp\BIT27E.tmp"
Thu 7 Feb 2008 0 A..H. --- "C:\Documents and Settings\Ginna\Local Settings\Temp\BIT27F.tmp"
Fri 8 Feb 2008 0 A..H. --- "C:\Documents and Settings\Ginna\Local Settings\Temp\BIT280.tmp"
Fri 8 Feb 2008 0 A..H. --- "C:\Documents and Settings\Ginna\Local Settings\Temp\BIT281.tmp"
Thu 7 Feb 2008 0 A..H. --- "C:\Documents and Settings\Ginna\Local Settings\Temp\BIT282.tmp"
Thu 7 Feb 2008 0 A..H. --- "C:\Documents and Settings\Ginna\Local Settings\Temp\BIT283.tmp"
Thu 7 Feb 2008 0 A..H. --- "C:\Documents and Settings\Ginna\Local Settings\Temp\BIT284.tmp"
Fri 8 Feb 2008 0 A..H. --- "C:\Documents and Settings\Ginna\Local Settings\Temp\BIT285.tmp"
Thu 7 Feb 2008 0 A..H. --- "C:\Documents and Settings\Ginna\Local Settings\Temp\BIT286.tmp"
Thu 7 Feb 2008 0 A..H. --- "C:\Documents and Settings\Ginna\Local Settings\Temp\BIT287.tmp"
Fri 8 Feb 2008 0 A..H. --- "C:\Documents and Settings\Ginna\Local Settings\Temp\BIT288.tmp"
Thu 7 Feb 2008 0 A..H. --- "C:\Documents and Settings\Ginna\Local Settings\Temp\BIT289.tmp"
Thu 7 Feb 2008 0 A..H. --- "C:\Documents and Settings\Ginna\Local Settings\Temp\BIT28A.tmp"
Fri 8 Feb 2008 0 A..H. --- "C:\Documents and Settings\Ginna\Local Settings\Temp\BIT28B.tmp"
Thu 7 Feb 2008 0 A..H. --- "C:\Documents and Settings\Ginna\Local Settings\Temp\BIT28C.tmp"
Sun 3 Feb 2008 0 A..H. --- "C:\Documents and Settings\Ginna\Local Settings\Temp\BIT28D.tmp"
Sun 3 Feb 2008 0 A..H. --- "C:\Documents and Settings\Ginna\Local Settings\Temp\BIT28E.tmp"
Sun 3 Feb 2008 0 A..H. --- "C:\Documents and Settings\Ginna\Local Settings\Temp\BIT28F.tmp"
Sun 3 Feb 2008 0 A..H. --- "C:\Documents and Settings\Ginna\Local Settings\Temp\BIT290.tmp"
Sun 3 Feb 2008 0 A..H. --- "C:\Documents and Settings\Ginna\Local Settings\Temp\BIT291.tmp"
Sun 3 Feb 2008 0 A..H. --- "C:\Documents and Settings\Ginna\Local Settings\Temp\BIT292.tmp"
Thu 7 Feb 2008 0 A..H. --- "C:\Documents and Settings\Ginna\Local Settings\Temp\BIT293.tmp"
Sun 3 Feb 2008 0 A..H. --- "C:\Documents and Settings\Ginna\Local Settings\Temp\BIT294.tmp"
Thu 7 Feb 2008 0 A..H. --- "C:\Documents and Settings\Ginna\Local Settings\Temp\BIT295.tmp"
Wed 6 Feb 2008 0 A..H. --- "C:\Documents and Settings\Ginna\Local Settings\Temp\BIT296.tmp"
Thu 7 Feb 2008 0 A..H. --- "C:\Documents and Settings\Ginna\Local Settings\Temp\BIT297.tmp"
Mon 28 Jan 2008 0 A..H. --- "C:\Documents and Settings\Ginna\Local Settings\Temp\BIT298.tmp"
Sun 3 Feb 2008 0 A..H. --- "C:\Documents and Settings\Ginna\Local Settings\Temp\BIT299.tmp"
Mon 28 Jan 2008 0 A..H. --- "C:\Documents and Settings\Ginna\Local Settings\Temp\BIT29A.tmp"
Thu 7 Feb 2008 0 A..H. --- "C:\Documents and Settings\Ginna\Local Settings\Temp\BIT29B.tmp"
Mon 28 Jan 2008 0 A..H. --- "C:\Documents and Settings\Ginna\Local Settings\Temp\BIT29C.tmp"
Mon 28 Jan 2008 0 A..H. --- "C:\Documents and Settings\Ginna\Local Settings\Temp\BIT29D.tmp"
Sun 3 Feb 2008 0 A..H. --- "C:\Documents and Settings\Ginna\Local Settings\Temp\BIT29E.tmp"
Thu 7 Feb 2008 0 A..H. --- "C:\Documents and Settings\Ginna\Local Settings\Temp\BIT29F.tmp"
Mon 28 Jan 2008 0 A..H. --- "C:\Documents and Settings\Ginna\Local Settings\Temp\BIT2A0.tmp"
Mon 28 Jan 2008 0 A..H. --- "C:\Documents and Settings\Ginna\Local Settings\Temp\BIT2A1.tmp"
Mon 28 Jan 2008 0 A..H. --- "C:\Documents and Settings\Ginna\Local Settings\Temp\BIT2A2.tmp"
Sun 3 Feb 2008 0 A..H. --- "C:\Documents and Settings\Ginna\Local Settings\Temp\BIT2A3.tmp"
Thu 7 Feb 2008 0 A..H. --- "C:\Documents and Settings\Ginna\Local Settings\Temp\BIT2A4.tmp"
Mon 28 Jan 2008 0 A..H. --- "C:\Documents and Settings\Ginna\Local Settings\Temp\BIT2A5.tmp"
Thu 7 Feb 2008 0 A..H. --- "C:\Documents and Settings\Ginna\Local Settings\Temp\BIT2A6.tmp"
Mon 28 Jan 2008 0 A..H. --- "C:\Documents and Settings\Ginna\Local Settings\Temp\BIT2A7.tmp"
Mon 28 Jan 2008 0 A..H. --- "C:\Documents and Settings\Ginna\Local Settings\Temp\BIT2A8.tmp"
Sun 3 Feb 2008 0 A..H. --- "C:\Documents and Settings\Ginna\Local Settings\Temp\BIT2A9.tmp"
Mon 28 Jan 2008 0 A..H. --- "C:\Documents and Settings\Ginna\Local Settings\Temp\BIT2AA.tmp"
Thu 7 Feb 2008 0 A..H. --- "C:\Documents and Settings\Ginna\Local Settings\Temp\BIT2AB.tmp"
Mon 28 Jan 2008 0 A..H. --- "C:\Documents and Settings\Ginna\Local Settings\Temp\BIT2AC.tmp"
Mon 28 Jan 2008 0 A..H. --- "C:\Documents and Settings\Ginna\Local Settings\Temp\BIT2AD.tmp"
Mon 28 Jan 2008 0 A..H. --- "C:\Documents and Settings\Ginna\Local Settings\Temp\BIT2AE.tmp"
Mon 28 Jan 2008 0 A..H. --- "C:\Documents and Settings\Ginna\Local Settings\Temp\BIT2AF.tmp"
Thu 31 Jan 2008 0 A..H. --- "C:\Documents and Settings\Ginna\Local Settings\Temp\BIT2B.tmp"
Sun 3 Feb 2008 0 A..H. --- "C:\Documents and Settings\Ginna\Local Settings\Temp\BIT2B0.tmp"
Thu 7 Feb 2008 0 A..H. --- "C:\Documents and Settings\Ginna\Local Settings\Temp\BIT2B1.tmp"
Mon 28 Jan 2008 0 A..H. --- "C:\Documents and Settings\Ginna\Local Settings\Temp\BIT2B2.tmp"
Sun 3 Feb 2008 0 A..H. --- "C:\Documents and Settings\Ginna\Local Settings\Temp\BIT2B3.tmp"
Sun 3 Feb 2008 0 A..H. --- "C:\Documents and Settings\Ginna\Local Settings\Temp\BIT2B4.tmp"
Sun 3 Feb 2008 0 A..H. --- "C:\Documents and Settings\Ginna\Local Settings\Temp\BIT2B5.tmp"
Fri 8 Feb 2008 0 A..H. --- "C:\Documents and Settings\Ginna\Local Settings\Temp\BIT2B6.tmp"
Mon 28 Jan 2008 0 A..H. --- "C:\Documents and Settings\Ginna\Local Settings\Temp\BIT2B7.tmp"
Sun 3 Feb 2008 0 A..H. --- "C:\Documents and Settings\Ginna\Local Settings\Temp\BIT2B8.tmp"
Mon 28 Jan 2008 0 A..H. --- "C:\Documents and Settings\Ginna\Local Settings\Temp\BIT2B9.tmp"
Sun 3 Feb 2008 0 A..H. --- "C:\Documents and Settings\Ginna\Local Settings\Temp\BIT2BA.tmp"
Fri 8 Feb 2008 0 A..H. --- "C:\Documents and Settings\Ginna\Local Settings\Temp\BIT2BB.tmp"
Fri 8 Feb 2008 0 A..H. --- "C:\Documents and Settings\Ginna\Local Settings\Temp\BIT2BC.tmp"
Mon 28 Jan 2008 0 A..H. --- "C:\Documents and Settings\Ginna\Local Settings\Temp\BIT2BD.tmp"
Sun 3 Feb 2008 0 A..H. --- "C:\Documents and Settings\Ginna\Local Settings\Temp\BIT2BE.tmp"
Wed 6 Feb 2008 0 A..H. --- "C:\Documents and Settings\Ginna\Local Settings\Temp\BIT2BF.tmp"
Thu 31 Jan 2008 0 A..H. --- "C:\Documents and Settings\Ginna\Local Settings\Temp\BIT2C.tmp"
Fri 8 Feb 2008 0 A..H. --- "C:\Documents and Settings\Ginna\Local Settings\Temp\BIT2C0.tmp"
Wed 6 Feb 2008 0 A..H. --- "C:\Documents and Settings\Ginna\Local Settings\Temp\BIT2C1.tmp"
Mon 28 Jan 2008 0 A..H. --- "C:\Documents and Settings\Ginna\Local Settings\Temp\BIT2C2.tmp"
Wed 6 Feb 2008 0 A..H. --- "C:\Documents and Settings\Ginna\Local Settings\Temp\BIT2C3.tmp"
Wed 6 Feb 2008 0 A..H. --- "C:\Documents and Settings\Ginna\Local Settings\Temp\BIT2C4.tmp"
Sun 3 Feb 2008 0 A..H. --- "C:\Documents and Settings\Ginna\Local Settings\Temp\BIT2C5.tmp"
Thu 7 Feb 2008 0 A..H. --- "C:\Documents and Settings\Ginna\Local Settings\Temp\BIT2C6.tmp"
Fri 8 Feb 2008 0 A..H. --- "C:\Documents and Settings\Ginna\Local Settings\Temp\BIT2C7.tmp"
Thu 7 Feb 2008 0 A..H. --- "C:\Documents and Settings\Ginna\Local Settings\Temp\BIT2C8.tmp"
Thu 7 Feb 2008 0 A..H. --- "C:\Documents and Settings\Ginna\Local Settings\Temp\BIT2C9.tmp"
Fri 8 Feb 2008 0 A..H. --- "C:\Documents and Settings\Ginna\Local Settings\Temp\BIT2CA.tmp"
Thu 7 Feb 2008 0 A..H. --- "C:\Documents and Settings\Ginna\Local Settings\Temp\BIT2CB.tmp"
Fri 8 Feb 2008 0 A..H. --- "C:\Documents and Settings\Ginna\Local Settings\Temp\BIT2CC.tmp"
Thu 7 Feb 2008 0 A..H. --- "C:\Documents and Settings\Ginna\Local Settings\Temp\BIT2CD.tmp"
Thu 7 Feb 2008 0 A..H. --- "C:\Documents and Settings\Ginna\Local Settings\Temp\BIT2CE.tmp"
Fri 8 Feb 2008 0 A..H. --- "C:\Documents and Settings\Ginna\Local Settings\Temp\BIT2CF.tmp"
Fri 25 Jan 2008 0 A..H. --- "C:\Documents and Settings\Ginna\Local Settings\Temp\BIT2D.tmp"
Thu 7 Feb 2008 0 A..H. --- "C:\Documents and Settings\Ginna\Local Settings\Temp\BIT2D0.tmp"
Fri 8 Feb 2008 0 A..H. --- "C:\Documents and Settings\Ginna\Local Settings\Temp\BIT2D1.tmp"
Thu 7 Feb 2008 0 A..H. --- "C:\Documents and Settings\Ginna\Local Settings\Temp\BIT2D2.tmp"
Fri 8 Feb 2008 0 A..H. --- "C:\Documents and Settings\Ginna\Local Settings\Temp\BIT2D3.tmp"
Fri 8 Feb 2008 0 A..H. --- "C:\Documents and Settings\Ginna\Local Settings\Temp\BIT2D4.tmp"
Fri 8 Feb 2008 0 A..H. --- "C:\Documents and Settings\Ginna\Local Settings\Temp\BIT2D5.tmp"
Fri 8 Feb 2008 0 A..H. --- "C:\Documents and Settings\Ginna\Local Settings\Temp\BIT2D6.tmp"
Fri 8 Feb 2008 0 A..H. --- "C:\Documents and Settings\Ginna\Local Settings\Temp\BIT2D7.tmp"
Sat 9 Feb 2008 0 A..H. --- "C:\Documents and Settings\Ginna\Local Settings\Temp\BIT2D8.tmp"
Sat 9 Feb 2008 0 A..H. --- "C:\Documents and Settings\Ginna\Local Settings\Temp\BIT2D9.tmp"
Sat 9 Feb 2008 0 A..H. --- "C:\Documents and Settings\Ginna\Local Settings\Temp\BIT2DA.tmp"
Sat 9 Feb 2008 0 A..H. --- "C:\Documents and Settings\Ginna\Local Settings\Temp\BIT2DB.tmp"
Sat 9 Feb 2008 0 A..H. --- "C:\Documents and Settings\Ginna\Local Settings\Temp\BIT2DC.tmp"
Sat 9 Feb 2008 0 A..H. --- "C:\Documents and Settings\Ginna\Local Settings\Temp\BIT2DD.tmp"
Sat 9 Feb 2008 0 A..H. --- "C:\Documents and Settings\Ginna\Local Settings\Temp\BIT2DE.tmp"
Sat 9 Feb 2008 0 A..H. --- "C:\Documents and Settings\Ginna\Local Settings\Temp\BIT2DF.tmp"
Thu 31 Jan 2008 0 A..H. --- "C:\Documents and Settings\Ginna\Local Settings\Temp\BIT2E.tmp"
Sat 9 Feb 2008 0 A..H. --- "C:\Documents and Settings\Ginna\Local Settings\Temp\BIT2E0.tmp"
Sat 9 Feb 2008 0 A..H. --- "C:\Documents and Settings\Ginna\Local Settings\Temp\BIT2E1.tmp"
Sat 9 Feb 2008 0 A..H. --- "C:\Documents and Settings\Ginna\Local Settings\Temp\BIT2E2.tmp"
Sun 10 Feb 2008 0 A..H. --- "C:\Documents and Settings\Ginna\Local Settings\Temp\BIT2E3.tmp"
Mon 11 Feb 2008 0 A..H. --- "C:\Documents and Settings\Ginna\Local Settings\Temp\BIT2E4.tmp"
Tue 12 Feb 2008 0 A..H. --- "C:\Documents and Settings\Ginna\Local Settings\Temp\BIT2E5.tmp"
Tue 12 Feb 2008 0 A..H. --- "C:\Documents and Settings\Ginna\Local Settings\Temp\BIT2E6.tmp"
Tue 12 Feb 2008 0 A..H. --- "C:\Documents and Settings\Ginna\Local Settings\Temp\BIT2E7.tmp"
Sun 10 Feb 2008 0 A..H. --- "C:\Documents and Settings\Ginna\Local Settings\Temp\BIT2E8.tmp"
Fri 8 Feb 2008 0 A..H. --- "C:\Documents and Settings\Ginna\Local Settings\Temp\BIT2E9.tmp"
Sun 10 Feb 2008 0 A..H. --- "C:\Documents and Settings\Ginna\Local Settings\Temp\BIT2EA.tmp"
Sat 9 Feb 2008 0 A..H. --- "C:\Documents and Settings\Ginna\Local Settings\Temp\BIT2EB.tmp"
Sun 10 Feb 2008 0 A..H. --- "C:\Documents and Settings\Ginna\Local Settings\Temp\BIT2EC.tmp"
Sun 10 Feb 2008 0 A..H. --- "C:\Documents and Settings\Ginna\Local Settings\Temp\BIT2ED.tmp"
Sun 10 Feb 2008 0 A..H. --- "C:\Documents and Settings\Ginna\Local Settings\Temp\BIT2EE.tmp"
Sun 10 Feb 2008 0 A..H. --- "C:\Documents and Settings\Ginna\Local Settings\Temp\BIT2EF.tmp"
Thu 31 Jan 2008 0 A..H. --- "C:\Documents and Settings\Ginna\Local Settings\Temp\BIT2F.tmp"
Sun 10 Feb 2008 0 A..H. --- "C:\Documents and Settings\Ginna\Local Settings\Temp\BIT2F0.tmp"
Sun 10 Feb 2008 0 A..H. --- "C:\Documents and Settings\Ginna\Local Settings\Temp\BIT2F1.tmp"
Sun 10 Feb 2008 0 A..H. --- "C:\Documents and Settings\Ginna\Local Settings\Temp\BIT2F2.tmp"
Sun 10 Feb 2008 0 A..H. --- "C:\Documents and Settings\Ginna\Local Settings\Temp\BIT2F3.tmp"
Sun 10 Feb 2008 0 A..H. --- "C:\Documents and Settings\Ginna\Local Settings\Temp\BIT2F4.tmp"
Sun 10 Feb 2008 0 A..H. --- "C:\Documents and Settings\Ginna\Local Settings\Temp\BIT2F5.tmp"
Tue 12 Feb 2008 0 A..H. --- "C:\Documents and Settings\Ginna\Local Settings\Temp\BIT2F6.tmp"
Sun 10 Feb 2008 0 A..H. --- "C:\Documents and Settings\Ginna\Local Settings\Temp\BIT2F7.tmp"
Sun 10 Feb 2008 0 A..H. --- "C:\Documents and Settings\Ginna\Local Settings\Temp\BIT2F8.tmp"
Thu 7 Feb 2008 0 A..H. --- "C:\Documents and Settings\Ginna\Local Settings\Temp\BIT2F9.tmp"
Thu 7 Feb 2008 0 A..H. --- "C:\Documents and Settings\Ginna\Local Settings\Temp\BIT2FA.tmp"
Thu 7 Feb 2008 0 A..H. --- "C:\Documents and Settings\Ginna\Local Settings\Temp\BIT2FB.tmp"
Sun 10 Feb 2008 0 A..H. --- "C:\Documents and Settings\Ginna\Local Settings\Temp\BIT2FC.tmp"
Thu 7 Feb 2008 0 A..H. --- "C:\Documents and Settings\Ginna\Local Settings\Temp\BIT2FD.tmp"
Thu 7 Feb 2008 0 A..H. --- "C:\Documents and Settings\Ginna\Local Settings\Temp\BIT2FE.tmp"
Thu 7 Feb 2008 0 A..H. --- "C:\Documents and Settings\Ginna\Local Settings\Temp\BIT2FF.tmp"
Fri 8 Feb 2008 0 A..H. --- "C:\Documents and Settings\Ginna\Local Settings\Temp\BIT3.tmp"
Fri 25 Jan 2008 0 A..H. --- "C:\Documents and Settings\Ginna\Local Settings\Temp\BIT30.tmp"
Mon 11 Feb 2008 0 A..H. --- "C:\Documents and Settings\Ginna\Local Settings\Temp\BIT300.tmp"
Thu 7 Feb 2008 0 A..H. --- "C:\Documents and Settings\Ginna\Local Settings\Temp\BIT301.tmp"
Thu 7 Feb 2008 0 A..H. --- "C:\Documents and Settings\Ginna\Local Settings\Temp\BIT302.tmp"
Thu 7 Feb 2008 0 A..H. --- "C:\Documents and Settings\Ginna\Local Settings\Temp\BIT303.tmp"
Thu 7 Feb 2008 0 A..H. --- "C:\Documents and Settings\Ginna\Local Settings\Temp\BIT304.tmp"
Thu 7 Feb 2008 0 A..H. --- "C:\Documents and Settings\Ginna\Local Settings\Temp\BIT305.tmp"
Thu 7 Feb 2008 0 A..H. --- "C:\Documents and Settings\Ginna\Local Settings\Temp\BIT306.tmp"
Thu 7 Feb 2008 0 A..H. --- "C:\Documents and Settings\Ginna\Local Settings\Temp\BIT307.tmp"
Thu 7 Feb 2008 0 A..H. --- "C:\Documents and Settings\Ginna\Local Settings\Temp\BIT308.tmp"
Thu 7 Feb 2008 0 A..H. --- "C:\Documents and Settings\Ginna\Local Settings\Temp\BIT309.tmp"
Thu 7 Feb 2008 0 A..H. --- "C:\Documents and Settings\Ginna\Local Settings\Temp\BIT30A.tmp"
Thu 7 Feb 2008 0 A..H. --- "C:\Documents and Settings\Ginna\Local Settings\Temp\BIT30B.tmp"
Thu 7 Feb 2008 0 A..H. --- "C:\Documents and Settings\Ginna\Local Settings\Temp\BIT30C.tmp"
Thu 7 Feb 2008 0 A..H. --- "C:\Documents and Settings\Ginna\Local Settings\Temp\BIT30D.tmp"
Thu 7 Feb 2008 0 A..H. --- "C:\Documents and Settings\Ginna\Local Settings\Temp\BIT30E.tmp"
Fri 8 Feb 2008 0 A..H. --- "C:\Documents and Settings\Ginna\Local Settings\Temp\BIT30F.tmp"
Fri 25 Jan 2008 0 A..H. --- "C:\Documents and Settings\Ginna\Local Settings\Temp\BIT31.tmp"
Thu 7 Feb 2008 0 A..H. --- "C:\Documents and Settings\Ginna\Local Settings\Temp\BIT310.tmp"
Thu 7 Feb 2008 0 A..H. --- "C:\Documents and Settings\Ginna\Local Settings\Temp\BIT311.tmp"
Thu 7 Feb 2008 0 A..H. --- "C:\Documents and Settings\Ginna\Local Settings\Temp\BIT312.tmp"
Thu 7 Feb 2008 0 A..H. --- "C:\Documents and Settings\Ginna\Local Settings\Temp\BIT313.tmp"
Thu 7 Feb 2008 0 A..H. --- "C:\Documents and Settings\Ginna\Local Settings\Temp\BIT314.tmp"
Thu 7 Feb 2008 0 A..H. --- "C:\Documents and Settings\Ginna\Local Settings\Temp\BIT315.tmp"
Fri 8 Feb 2008 0 A..H. --- "C:\Documents and Settings\Ginna\Local Settings\Temp\BIT316.tmp"
Fri 8 Feb 2008 0 A..H. --- "C:\Documents and Settings\Ginna\Local Settings\Temp\BIT317.tmp"
Fri 8 Feb 2008 0 A..H. --- "C:\Documents and Settings\Ginna\Local Settings\Temp\BIT318.tmp"
Fri 8 Feb 2008 0 A..H. --- "C:\Documents and Settings\Ginna\Local Settings\Temp\BIT319.tmp"
Fri 8 Feb 2008 0 A..H. --- "C:\Documents and Settings\Ginna\Local Settings\Temp\BIT31A.tmp"
Fri 8 Feb 2008 0 A..H. --- "C:\Documents and Settings\Ginna\Local Settings\Temp\BIT31B.tmp"
Fri 8 Feb 2008 0 A..H. --- "C:\Documents and Settings\Ginna\Local Settings\Temp\BIT31C.tmp"
Fri 8 Feb 2008 0 A..H. --- "C:\Documents and Settings\Ginna\Local Settings\Temp\BIT31D.tmp"
Fri 8 Feb 2008 0 A..H. --- "C:\Documents and Settings\Ginna\Local Settings\Temp\BIT31E.tmp"
Fri 8 Feb 2008 0 A..H. --- "C:\Documents and Settings\Ginna\Local Settings\Temp\BIT31F.tmp"
Thu 31 Jan 2008 0 A..H. --- "C:\Documents and Settings\Ginna\Local Settings\Temp\BIT32.tmp"
Fri 8 Feb 2008 0 A..H. --- "C:\Documents and Settings\Ginna\Local Settings\Temp\BIT320.tmp"
Fri 8 Feb 2008 0 A..H. --- "C:\Documents and Settings\Ginna\Local Settings\Temp\BIT321.tmp"
Fri 8 Feb 2008 0 A..H. --- "C:\Documents and Settings\Ginna\Local Settings\Temp\BIT322.tmp"
Fri 8 Feb 2008 0 A..H. --- "C:\Documents and Settings\Ginna\Local Settings\Temp\BIT323.tmp"
Fri 8 Feb 2008 0 A..H. --- "C:\Documents and Settings\Ginna\Local Settings\Temp\BIT324.tmp"
Fri 8 Feb 2008 0 A..H. --- "C:\Documents and Settings\Ginna\Local Settings\Temp\BIT325.tmp"
Mon 11 Feb 2008 0 A..H. --- "C:\Documents and Settings\Ginna\Local Settings\Temp\BIT326.tmp"
Mon 11 Feb 2008 0 A..H. --- "C:\Documents and Settings\Ginna\Local Settings\Temp\BIT327.tmp"
Mon 11 Feb 2008 0 A..H. --- "C:\Documents and Settings\Ginna\Local Settings\Temp\BIT328.tmp"
Mon 11 Feb 2008 0 A..H. --- "C:\Documents and Settings\Ginna\Local Settings\Temp\BIT329.tmp"
Mon 11 Feb 2008 0 A..H. --- "C:\Documents and Settings\Ginna\Local Settings\Temp\BIT32A.tmp"
Mon 11 Feb 2008 0 A..H. --- "C:\Documents and Settings\Ginna\Local Settings\Temp\BIT32B.tmp"
Mon 11 Feb 2008 0 A..H. --- "C:\Documents and Settings\Ginna\Local Settings\Temp\BIT32C.tmp"
Mon 11 Feb 2008 0 A..H. --- "C:\Documents and Settings\Ginna\Local Settings\Temp\BIT32D.tmp"
Mon 11 Feb 2008 0 A..H. --- "C:\Documents and Settings\Ginna\Local Settings\Temp\BIT32E.tmp"
Mon 11 Feb 2008 0 A..H. --- "C:\Documents and Settings\Ginna\Local Settings\Temp\BIT32F.tmp"
Mon 11 Feb 2008 0 A..H. --- "C:\Documents and Settings\Ginna\Local Settings\Temp\BIT330.tmp"
Mon 11 Feb 2008 0 A..H. --- "C:\Documents and Settings\Ginna\Local Settings\Temp\BIT331.tmp"
Mon 11 Feb 2008 0 A..H. --- "C:\Documents and Settings\Ginna\Local Settings\Temp\BIT332.tmp"
Tue 12 Feb 2008 0 A..H. --- "C:\Documents and Settings\Ginna\Local Settings\Temp\BIT333.tmp"
Fri 8 Feb 2008 0 A..H. --- "C:\Documents and Settings\Ginna\Local Settings\Temp\BIT334.tmp"
Fri 8 Feb 2008 0 A..H. --- "C:\Documents and Settings\Ginna\Local Settings\Temp\BIT335.tmp"
Fri 8 Feb 2008 0 A..H. --- "C:\Documents and Settings\Ginna\Local Settings\Temp\BIT336.tmp"
Fri 8 Feb 2008 0 A..H. --- "C:\Documents and Settings\Ginna\Local Settings\Temp\BIT337.tmp"
Fri 8 Feb 2008 0 A..H. --- "C:\Documents and Settings\Ginna\Local Settings\Temp\BIT338.tmp"
Fri 8 Feb 2008 0 A..H. --- "C:\Documents and Settings\Ginna\Local Settings\Temp\BIT339.tmp"
Mon 11 Feb 2008 0 A..H. --- "C:\Documents and Settings\Ginna\Local Settings\Temp\BIT33A.tmp"
Mon 11 Feb 2008 0 A..H. --- "C:\Documents and Settings\Ginna\Local Settings\Temp\BIT33B.tmp"
Fri 8 Feb 2008 0 A..H. --- "C:\Documents and Settings\Ginna\Local Settings\Temp\BIT33C.tmp"
Fri 8 Feb 2008 0 A..H. --- "C:\Documents and Settings\Ginna\Local Settings\Temp\BIT33D.tmp"
Fri 8 Feb 2008 0 A..H. --- "C:\Documents and Settings\Ginna\Local Settings\Temp\BIT33E.tmp"
Mon 11 Feb 2008 0 A..H. --- "C:\Documents and Settings\Ginna\Local Settings\Temp\BIT33F.tmp"
Fri 8 Feb 2008 0 A..H. --- "C:\Documents and Settings\Ginna\Local Settings\Temp\BIT340.tmp"
Mon 11 Feb 2008 0 A..H. --- "C:\Documents and Settings\Ginna\Local Settings\Temp\BIT341.tmp"
Fri 8 Feb 2008 0 A..H. --- "C:\Documents and Settings\Ginna\Local Settings\Temp\BIT342.tmp"
Fri 8 Feb 2008 0 A..H. --- "C:\Documents and Settings\Ginna\Local Settings\Temp\BIT343.tmp"
Mon 11 Feb 2008 0 A..H. --- "C:\Documents and Settings\Ginna\Local Settings\Temp\BIT344.tmp"
Fri 8 Feb 2008 0 A..H. --- "C:\Documents and Settings\Ginna\Local Settings\Temp\BIT345.tmp"
Fri 8 Feb 2008 0 A..H. --- "C:\Documents and Settings\Ginna\Local Settings\Temp\BIT346.tmp"
Mon 11 Feb 2008 0 A..H. --- "C:\Documents and Settings\Ginna\Local Settings\Temp\BIT347.tmp"
Mon 11 Feb 2008 0 A..H. --- "C:\Documents and Settings\Ginna\Local Settings\Temp\BIT348.tmp"
Fri 8 Feb 2008 0 A..H. --- "C:\Documents and Settings\Ginna\Local Settings\Temp\BIT349.tmp"
Fri 8 Feb 2008 0 A..H. --- "C:\Documents and Settings\Ginna\Local Settings\Temp\BIT34A.tmp"
Fri 8 Feb 2008 0 A..H. --- "C:\Documents and Settings\Ginna\Local Settings\Temp\BIT34B.tmp"
Mon 11 Feb 2008 0 A..H. --- "C:\Documents and Settings\Ginna\Local Settings\Temp\BIT34C.tmp"
Mon 11 Feb 2008 0 A..H. --- "C:\Documents and Settings\Ginna\Local Settings\Temp\BIT34D.tmp"
Fri 8 Feb 2008 0 A..H. --- "C:\Documents and Settings\Ginna\Local Settings\Temp\BIT34E.tmp"
Fri 8 Feb 2008 0 A..H. --- "C:\Documents and Settings\Ginna\Local Settings\Temp\BIT34F.tmp"
Thu 31 Jan 2008 0 A..H. --- "C:\Documents and Settings\Ginna\Local Settings\Temp\BIT35.tmp"
Fri 8 Feb 2008 0 A..H. --- "C:\Documents and Settings\Ginna\Local Settings\Temp\BIT350.tmp"
Fri 8 Feb 2008 0 A..H. --- "C:\Documents and Settings\Ginna\Local Settings\Temp\BIT351.tmp"
Mon 11 Feb 2008 0 A..H. --- "C:\Documents and Settings\Ginna\Local Settings\Temp\BIT352.tmp"
Fri 8 Feb 2008 0 A..H. --- "C:\Documents and Settings\Ginna\Local Settings\Temp\BIT353.tmp"
Fri 8 Feb 2008 0 A..H. --- "C:\Documents and Settings\Ginna\Local Settings\Temp\BIT354.tmp"
Mon 11 Feb 2008 0 A..H. --- "C:\Documents and Settings\Ginna\Local Settings\Temp\BIT355.tmp"
Mon 11 Feb 2008 0 A..H. --- "C:\Documents and Settings\Ginna\Local Settings\Temp\BIT356.tmp"
Mon 11 Feb 2008 0 A..H. --- "C:\Documents and Settings\Ginna\Local Settings\Temp\BIT357.tmp"
Fri 8 Feb 2008 0 A..H. --- "C:\Documents and Settings\Ginna\Local Settings\Temp\BIT358.tmp"
Mon 11 Feb 2008 0 A..H. --- "C:\Documents and Settings\Ginna\Local Settings\Temp\BIT359.tmp"
Mon 11 Feb 2008 0 A..H. --- "C:\Documents and Settings\Ginna\Local Settings\Temp\BIT35A.tmp"
Mon 11 Feb 2008 0 A..H. --- "C:\Documents and Settings\Ginna\Local Settings\Temp\BIT35B.tmp"
Fri 8 Feb 2008 0 A..H. --- "C:\Documents and Settings\Ginna\Local Settings\Temp\BIT35C.tmp"
Mon 11 Feb 2008 0 A..H. --- "C:\Documents and Settings\Ginna\Local Settings\Temp\BIT35D.tmp"
Fri 8 Feb 2008 0 A..H. --- "C:\Documents and Settings\Ginna\Local Settings\Temp\BIT35E.tmp"
Mon 11 Feb 2008 0 A..H. --- "C:\Documents and Settings\Ginna\Local Settings\Temp\BIT35F.tmp"
Thu 31 Jan 2008 0 A..H. --- "C:\Documents and Settings\Ginna\Local Settings\Temp\BIT36.tmp"
Mon 11 Feb 2008 0 A..H. --- "C:\Documents and Settings\Ginna\Local Settings\Temp\BIT360.tmp"
Fri 8 Feb 2008 0 A..H. --- "C:\Documents and Settings\Ginna\Local Settings\Temp\BIT361.tmp"
Mon 11 Feb 2008 0 A..H. --- "C:\Documents and Settings\Ginna\Local Settings\Temp\BIT362.tmp"
Mon 11 Feb 2008 0 A..H. --- "C:\Documents and Settings\Ginna\Local Settings\Temp\BIT363.tmp"
Mon 11 Feb 2008 0 A..H. --- "C:\Documents and Settings\Ginna\Local Settings\Temp\BIT364.tmp"
Mon 11 Feb 2008 0 A..H. --- "C:\Documents and Settings\Ginna\Local Settings\Temp\BIT365.tmp"
Mon 11 Feb 2008 0 A..H. --- "C:\Documents and Settings\Ginna\Local Settings\Temp\BIT366.tmp"
Mon 11 Feb 2008 0 A..H. --- "C:\Documents and Settings\Ginna\Local Settings\Temp\BIT367.tmp"
Fri 8 Feb 2008 0 A..H. --- "C:\Documents and Settings\Ginna\Local Settings\Temp\BIT368.tmp"
Fri 8 Feb 2008 0 A..H. --- "C:\Documents and Settings\Ginna\Local Settings\Temp\BIT369.tmp"
Mon 11 Feb 2008 0 A..H. --- "C:\Documents and Settings\Ginna\Local Settings\Temp\BIT36A.tmp"
Fri 8 Feb 2008 0 A..H. --- "C:\Documents and Settings\Ginna\Local Settings\Temp\BIT36B.tmp"
Mon 11 Feb 2008 0 A..H. --- "C:\Documents and Settings\Ginna\Local Settings\Temp\BIT36C.tmp"
Mon 11 Feb 2008 0 A..H. --- "C:\Documents and Settings\Ginna\Local Settings\Temp\BIT36D.tmp"
Fri 8 Feb 2008 0 A..H. --- "C:\Documents and Settings\Ginna\Local Settings\Temp\BIT36E.tmp"
Fri 8 Feb 2008 0 A..H. --- "C:\Documents and Settings\Ginna\Local Settings\Temp\BIT36F.tmp"
Mon 11 Feb 2008 0 A..H. --- "C:\Documents and Settings\Ginna\Local Settings\Temp\BIT370.tmp"
Fri 8 Feb 2008 0 A..H. --- "C:\Documents and Settings\Ginna\Local Settings\Temp\BIT371.tmp"
Mon 11 Feb 2008 0 A..H. --- "C:\Documents and Settings\Ginna\Local Settings\Temp\BIT372.tmp"
Fri 8 Feb 2008 0 A..H. --- "C:\Documents and Settings\Ginna\Local Settings\Temp\BIT373.tmp"
Mon 11 Feb 2008 0 A..H. --- "C:\Documents and Settings\Ginna\Local Settings\Temp\BIT374.tmp"
Fri 8 Feb 2008 0 A..H. --- "C:\Documents and Settings\Ginna\Local Settings\Temp\BIT375.tmp"
Mon 11 Feb 2008 0 A..H. --- "C:\Documents and Settings\Ginna\Local Settings\Temp\BIT376.tmp"
Fri 8 Feb 2008 0 A..H. --- "C:\Documents and Settings\Ginna\Local Settings\Temp\BIT377.tmp"
Fri 8 Feb 2008 0 A..H. --- "C:\Documents and Settings\Ginna\Local Settings\Temp\BIT378.tmp"
Fri 8 Feb 2008 0 A..H. --- "C:\Documents and Settings\Ginna\Local Settings\Temp\BIT379.tmp"
Mon 11 Feb 2008 0 A..H. --- "C:\Documents and Settings\Ginna\Local Settings\Temp\BIT37A.tmp"
Fri 8 Feb 2008 0 A..H. --- "C:\Documents and Settings\Ginna\Local Settings\Temp\BIT37B.tmp"
Fri 8 Feb 2008 0 A..H. --- "C:\Documents and Settings\Ginna\Local Settings\Temp\BIT37C.tmp"
Fri 8 Feb 2008 0 A..H. --- "C:\Documents and Settings\Ginna\Local Settings\Temp\BIT37D.tmp"
Fri 8 Feb 2008 0 A..H. --- "C:\Documents and Settings\Ginna\Local Settings\Temp\BIT37E.tmp"
Mon 11 Feb 2008 0 A..H. --- "C:\Documents and Settings\Ginna\Local Settings\Temp\BIT37F.tmp"
Thu 31 Jan 2008 0 A..H. --- "C:\Documents and Settings\Ginna\Local Settings\Temp\BIT38.tmp"
Tue 12 Feb 2008 0 A..H. --- "C:\Documents and Settings\Ginna\Local Settings\Temp\BIT380.tmp"
Tue 12 Feb 2008 0 A..H. --- "C:\Documents and Settings\Ginna\Local Settings\Temp\BIT381.tmp"
Mon 11 Feb 2008 0 A..H. --- "C:\Documents and Settings\Ginna\Local Settings\Temp\BIT382.tmp"
Mon 11 Feb 2008 0 A..H. --- "C:\Documents and Settings\Ginna\Local Settings\Temp\BIT383.tmp"
Tue 12 Feb 2008 0 A..H. --- "C:\Documents and Settings\Ginna\Local Settings\Temp\BIT384.tmp"
Tue 12 Feb 2008 0 A..H. --- "C:\Documents and Settings\Ginna\Local Settings\Temp\BIT385.tmp"
Wed 13 Feb 2008 0 A..H. --- "C:\Documents and Settings\Ginna\Local Settings\Temp\BIT386.tmp"
Wed 13 Feb 2008 0 A..H. --- "C:\Documents and Settings\Ginna\Local Settings\Temp\BIT387.tmp"
Wed 13 Feb 2008 0 A..H. --- "C:\Documents and Settings\Ginna\Local Settings\Temp\BIT388.tmp"
Wed 13 Feb 2008 0 A..H. --- "C:\Documents and Settings\Ginna\Local Settings\Temp\BIT389.tmp"
Wed 13 Feb 2008 0 A..H. --- "C:\Documents and Settings\Ginna\Local Settings\Temp\BIT38B.tmp"
Wed 13 Feb 2008 0 A..H. --- "C:\Documents and Settings\Ginna\Local Settings\Temp\BIT38C.tmp"
Wed 13 Feb 2008 0 A..H. --- "C:\Documents and Settings\Ginna\Local Settings\Temp\BIT38D.tmp"
Wed 13 Feb 2008 0 A..H. --- "C:\Documents and Settings\Ginna\Local Settings\Temp\BIT38E.tmp"
Wed 13 Feb 2008 0 A..H. --- "C:\Documents and Settings\Ginna\Local Settings\Temp\BIT38F.tmp"
Wed 13 Feb 2008 0 A..H. --- "C:\Documents and Settings\Ginna\Local Settings\Temp\BIT390.tmp"
Wed 13 Feb 2008 0 A..H. --- "C:\Documents and Settings\Ginna\Local Settings\Temp\BIT391.tmp"
Wed 13 Feb 2008 0 A..H. --- "C:\Documents and Settings\Ginna\Local Settings\Temp\BIT392.tmp"
Wed 13 Feb 2008 0 A..H. --- "C:\Documents and Settings\Ginna\Local Settings\Temp\BIT393.tmp"
Wed 13 Feb 2008 0 A..H. --- "C:\Documents and Settings\Ginna\Local Settings\Temp\BIT394.tmp"
Wed 13 Feb 2008 0 A..H. --- "C:\Documents and Settings\Ginna\Local Settings\Temp\BIT395.tmp"
Wed 13 Feb 2008 0 A..H. --- "C:\Documents and Settings\Ginna\Local Settings\Temp\BIT396.tmp"
Wed 13 Feb 2008 0 A..H. --- "C:\Documents and Settings\Ginna\Local Settings\Temp\BIT397.tmp"
Wed 13 Feb 2008 0 A..H. --- "C:\Documents and Settings\Ginna\Local Settings\Temp\BIT398.tmp"
Wed 13 Feb 2008 0 A..H. --- "C:\Documents and Settings\Ginna\Local Settings\Temp\BIT399.tmp"
Wed 13 Feb 2008 0 A..H. --- "C:\Documents and Settings\Ginna\Local Settings\Temp\BIT39B.tmp"
Thu 31 Jan 2008 0 A..H. --- "C:\Documents and Settings\Ginna\Local Settings\Temp\BIT3A.tmp"
Mon 11 Feb 2008 0 A..H. --- "C:\Documents and Settings\Ginna\Local Settings\Temp\BIT3A3.tmp"
Fri 8 Feb 2008 0 A..H. --- "C:\Documents and Settings\Ginna\Local Settings\Temp\BIT3A7.tmp"
Fri 8 Feb 2008 0 A..H. --- "C:\Documents and Settings\Ginna\Local Settings\Temp\BIT3A8.tmp"
Fri 8 Feb 2008 0 A..H. --- "C:\Documents and Settings\Ginna\Local Settings\Temp\BIT3A9.tmp"
Mon 11 Feb 2008 0 A..H. --- "C:\Documents and Settings\Ginna\Local Settings\Temp\BIT3AA.tmp"
Fri 8 Feb 2008 0 A..H. --- "C:\Documents and Settings\Ginna\Local Settings\Temp\BIT3AB.tmp"
Fri 8 Feb 2008 0 A..H. --- "C:\Documents and Settings\Ginna\Local Settings\Temp\BIT3AC.tmp"
Fri 8 Feb 2008 0 A..H. --- "C:\Documents and Settings\Ginna\Local Settings\Temp\BIT3AD.tmp"
Sat 9 Feb 2008 0 A..H. --- "C:\Documents and Settings\Ginna\Local Settings\Temp\BIT3AE.tmp"
Sat 9 Feb 2008 0 A..H. --- "C:\Documents and Settings\Ginna\Local Settings\Temp\BIT3AF.tmp"
Sat 26 Jan 2008 0 A..H. --- "C:\Documents and Settings\Ginna\Local Settings\Temp\BIT3B.tmp"
Sat 9 Feb 2008 0 A..H. --- "C:\Documents and Settings\Ginna\Local Settings\Temp\BIT3B0.tmp"
Sat 9 Feb 2008 0 A..H. --- "C:\Documents and Settings\Ginna\Local Settings\Temp\BIT3B1.tmp"
Fri 8 Feb 2008 0 A..H. --- "C:\Documents and Settings\Ginna\Local Settings\Temp\BIT3B2.tmp"
Fri 8 Feb 2008 0 A..H. --- "C:\Documents and Settings\Ginna\Local Settings\Temp\BIT3B3.tmp"
Sat 9 Feb 2008 0 A..H. --- "C:\Documents and Settings\Ginna\Local Settings\Temp\BIT3B4.tmp"
Mon 11 Feb 2008 0 A..H. --- "C:\Documents and Settings\Ginna\Local Settings\Temp\BIT3B5.tmp"
Mon 11 Feb 2008 0 A..H. --- "C:\Documents and Settings\Ginna\Local Settings\Temp\BIT3B6.tmp"
Mon 11 Feb 2008 0 A..H. --- "C:\Documents and Settings\Ginna\Local Settings\Temp\BIT3B7.tmp"
Sat 9 Feb 2008 0 A..H. --- "C:\Documents and Settings\Ginna\Local Settings\Temp\BIT3BA.tmp"
Sat 9 Feb 2008 0 A..H. --- "C:\Documents and Settings\Ginna\Local Settings\Temp\BIT3BB.tmp"
Sun 10 Feb 2008 0 A..H. --- "C:\Documents and Settings\Ginna\Local Settings\Temp\BIT3BC.tmp"
Sun 10 Feb 2008 0 A..H. --- "C:\Documents and Settings\Ginna\Local Settings\Temp\BIT3BD.tmp"
Sun 10 Feb 2008 0 A..H. --- "C:\Documents and Settings\Ginna\Local Settings\Temp\BIT3BE.tmp"
Mon 11 Feb 2008 0 A..H. --- "C:\Documents and Settings\Ginna\Local Settings\Temp\BIT3BF.tmp"
Thu 31 Jan 2008 0 A..H. --- "C:\Documents and Settings\Ginna\Local Settings\Temp\BIT3C.tmp"
Sun 10 Feb 2008 0 A..H. --- "C:\Documents and Settings\Ginna\Local Settings\Temp\BIT3C0.tmp"
Sun 10 Feb 2008 0 A..H. --- "C:\Documents and Settings\Ginna\Local Settings\Temp\BIT3C1.tmp"
Sun 10 Feb 2008 0 A..H. --- "C:\Documents and Settings\Ginna\Local Settings\Temp\BIT3C2.tmp"
Sun 10 Feb 2008 0 A..H. --- "C:\Documents and Settings\Ginna\Local Settings\Temp\BIT3C3.tmp"
Sun 10 Feb 2008 0 A..H. --- "C:\Documents and Settings\Ginna\Local Settings\Temp\BIT3C4.tmp"
Sun 10 Feb 2008 0 A..H. --- "C:\Documents and Settings\Ginna\Local Settings\Temp\BIT3C5.tmp"
Sun 10 Feb 2008 0 A..H. --- "C:\Documents and Settings\Ginna\Local Settings\Temp\BIT3C6.tmp"
Sun 10 Feb 2008 0 A..H. --- "C:\Documents and Settings\Ginna\Local Settings\Temp\BIT3C7.tmp"
Sun 10 Feb 2008 0 A..H. --- "C:\Documents and Settings\Ginna\Local Settings\Temp\BIT3C8.tmp"
Sun 10 Feb 2008 0 A..H. --- "C:\Documents and Settings\Ginna\Local Settings\Temp\BIT3C9.tmp"
Sun 10 Feb 2008 0 A..H. --- "C:\Documents and Settings\Ginna\Local Settings\Temp\BIT3CA.tmp"
Sun 10 Feb 2008 0 A..H. --- "C:\Documents and Settings\Ginna\Local Settings\Temp\BIT3CB.tmp"
Sun 10 Feb 2008 0 A..H. --- "C:\Documents and Settings\Ginna\Local Settings\Temp\BIT3CC.tmp"
Mon 11 Feb 2008 0 A..H. --- "C:\Documents and Settings\Ginna\Local Settings\Temp\BIT3CD.tmp"
Sun 10 Feb 2008 0 A..H. --- "C:\Documents and Settings\Ginna\Local Settings\Temp\BIT3CE.tmp"
Mon 11 Feb 2008 0 A..H. --- "C:\Documents and Settings\Ginna\Local Settings\Temp\BIT3CF.tmp"
Thu 31 Jan 2008 0 A..H. --- "C:\Documents and Settings\Ginna\Local Settings\Temp\BIT3D.tmp"
Mon 11 Feb 2008 0 A..H. --- "C:\Documents and Settings\Ginna\Local Settings\Temp\BIT3D0.tmp"
Wed 13 Feb 2008 0 A..H. --- "C:\Documents and Settings\Ginna\Local Settings\Temp\BIT3D3.tmp"
Mon 11 Feb 2008 0 A..H. --- "C:\Documents and Settings\Ginna\Local Settings\Temp\BIT3D4.tmp"
Wed 13 Feb 2008 0 A..H. --- "C:\Documents and Settings\Ginna\Local Settings\Temp\BIT3D5.tmp"
Mon 11 Feb 2008 0 A..H. --- "C:\Documents and Settings\Ginna\Local Settings\Temp\BIT3D7.tmp"
Thu 7 Feb 2008 0 A..H. --- "C:\Documents and Settings\Ginna\Local Settings\Temp\BIT3E.tmp"
Mon 11 Feb 2008 0 A..H. --- "C:\Documents and Settings\Ginna\Local Settings\Temp\BIT3E2.tmp"
Mon 11 Feb 2008 0 A..H. --- "C:\Documents and Settings\Ginna\Local Settings\Temp\BIT3E3.tmp"
Mon 11 Feb 2008 0 A..H. --- "C:\Documents and Settings\Ginna\Local Settings\Temp\BIT3E4.tmp"
Mon 11 Feb 2008 0 A..H. --- "C:\Documents and Settings\Ginna\Local Settings\Temp\BIT3E5.tmp"
Mon 11 Feb 2008 0 A..H. --- "C:\Documents and Settings\Ginna\Local Settings\Temp\BIT3E6.tmp"
Mon 11 Feb 2008 0 A..H. --- "C:\Documents and Settings\Ginna\Local Settings\Temp\BIT3E7.tmp"
Wed 13 Feb 2008 0 A..H. --- "C:\Documents and Settings\Ginna\Local Settings\Temp\BIT3F0.tmp"
Mon 11 Feb 2008 0 A..H. --- "C:\Documents and Settings\Ginna\Local Settings\Temp\BIT3F1.tmp"
Mon 11 Feb 2008 0 A..H. --- "C:\Documents and Settings\Ginna\Local Settings\Temp\BIT3F2.tmp"
Mon 11 Feb 2008 0 A..H. --- "C:\Documents and Settings\Ginna\Local Settings\Temp\BIT3F3.tmp"
Wed 13 Feb 2008 0 A..H. --- "C:\Documents and Settings\Ginna\Local Settings\Temp\BIT3F4.tmp"
Sat 9 Feb 2008 0 A..H. --- "C:\Documents and Settings\Ginna\Local Settings\Temp\BIT4.tmp"
Thu 31 Jan 2008 0 A..H. --- "C:\Documents and Settings\Ginna\Local Settings\Temp\BIT40.tmp"
Mon 11 Feb 2008 0 A..H. --- "C:\Documents and Settings\Ginna\Local Settings\Temp\BIT40E.tmp"
Tue 29 Jan 2008 0 A..H. --- "C:\Documents and Settings\Ginna\Local Settings\Temp\BIT41.tmp"
Thu 31 Jan 2008 0 A..H. --- "C:\Documents and Settings\Ginna\Local Settings\Temp\BIT42.tmp"
Mon 11 Feb 2008 0 A..H. --- "C:\Documents and Settings\Ginna\Local Settings\Temp\BIT424.tmp"
Mon 11 Feb 2008 0 A..H. --- "C:\Documents and Settings\Ginna\Local Settings\Temp\BIT425.tmp"
Mon 11 Feb 2008 0 A..H. --- "C:\Documents and Settings\Ginna\Local Settings\Temp\BIT426.tmp"
Mon 11 Feb 2008 0 A..H. --- "C:\Documents and Settings\Ginna\Local Settings\Temp\BIT427.tmp"
Mon 11 Feb 2008 0 A..H. --- "C:\Documents and Settings\Ginna\Local Settings\Temp\BIT428.tmp"
Mon 11 Feb 2008 0 A..H. --- "C:\Documents and Settings\Ginna\Local Settings\Temp\BIT429.tmp"
Mon 11 Feb 2008 0 A..H. --- "C:\Documents and Settings\Ginna\Local Settings\Temp\BIT42A.tmp"
Mon 11 Feb 2008 0 A..H. --- "C:\Documents and Settings\Ginna\Local Settings\Temp\BIT42B.tmp"
Mon 11 Feb 2008 0 A..H. --- "C:\Documents and Settings\Ginna\Local Settings\Temp\BIT42C.tmp"
Mon 11 Feb 2008 0 A..H. --- "C:\Documents and Settings\Ginna\Local Settings\Temp\BIT42D.tmp"
Mon 11 Feb 2008 0 A..H. --- "C:\Documents and Settings\Ginna\Local Settings\Temp\BIT42E.tmp"
Mon 11 Feb 2008 0 A..H. --- "C:\Documents and Settings\Ginna\Local Settings\Temp\BIT42F.tmp"
Sun 27 Jan 2008 0 A..H. --- "C:\Documents and Settings\Ginna\Local Settings\Temp\BIT43.tmp"
Mon 11 Feb 2008 0 A..H. --- "C:\Documents and Settings\Ginna\Local Settings\Temp\BIT430.tmp"
Mon 11 Feb 2008 0 A..H. --- "C:\Documents and Settings\Ginna\Local Settings\Temp\BIT431.tmp"
Mon 11 Feb 2008 0 A..H. --- "C:\Documents and Settings\Ginna\Local Settings\Temp\BIT432.tmp"
Mon 11 Feb 2008 0 A..H. --- "C:\Documents and Settings\Ginna\Local Settings\Temp\BIT433.tmp"
Mon 11 Feb 2008 0 A..H. --- "C:\Documents and Settings\Ginna\Local Settings\Temp\BIT434.tmp"
Mon 11 Feb 2008 0 A..H. --- "C:\Documents and Settings\Ginna\Local Settings\Temp\BIT435.tmp"
Mon 11 Feb 2008 0 A..H. --- "C:\Documents and Settings\Ginna\Local Settings\Temp\BIT436.tmp"
Mon 11 Feb 2008 0 A..H. --- "C:\Documents and Settings\Ginna\Local Settings\Temp\BIT439.tmp"
Mon 11 Feb 2008 0 A..H. --- "C:\Documents and Settings\Ginna\Local Settings\Temp\BIT43A.tmp"
Mon 11 Feb 2008 0 A..H. --- "C:\Documents and Settings\Ginna\Local Settings\Temp\BIT43C.tmp"
Mon 11 Feb 2008 0 A..H. --- "C:\Documents and Settings\Ginna\Local Settings\Temp\BIT43E.tmp"
Mon 11 Feb 2008 0 A..H. --- "C:\Documents and Settings\Ginna\Local Settings\Temp\BIT43F.tmp"
Sun 27 Jan 2008 0 A..H. --- "C:\Documents and Settings\Ginna\Local Settings\Temp\BIT44.tmp"
Mon 11 Feb 2008 0 A..H. --- "C:\Documents and Settings\Ginna\Local Settings\Temp\BIT440.tmp"
Mon 11 Feb 2008 0 A..H. --- "C:\Documents and Settings\Ginna\Local Settings\Temp\BIT441.tmp"
Mon 11 Feb 2008 0 A..H. --- "C:\Documents and Settings\Ginna\Local Settings\Temp\BIT442.tmp"
Mon 11 Feb 2008 0 A..H. --- "C:\Documents and Settings\Ginna\Local Settings\Temp\BIT443.tmp"
Mon 11 Feb 2008 0 A..H. --- "C:\Documents and Settings\Ginna\Local Settings\Temp\BIT444.tmp"
Mon 11 Feb 2008 0 A..H. --- "C:\Documents and Settings\Ginna\Local Settings\Temp\BIT445.tmp"
Mon 11 Feb 2008 0 A..H. --- "C:\Documents and Settings\Ginna\Local Settings\Temp\BIT446.tmp"
Mon 11 Feb 2008 0 A..H. --- "C:\Documents and Settings\Ginna\Local Settings\Temp\BIT447.tmp"
Mon 11 Feb 2008 0 A..H. --- "C:\Documents and Settings\Ginna\Local Settings\Temp\BIT448.tmp"
Mon 11 Feb 2008 0 A..H. --- "C:\Documents and Settings\Ginna\Local Settings\Temp\BIT449.tmp"
Mon 11 Feb 2008 0 A..H. --- "C:\Documents and Settings\Ginna\Local Settings\Temp\BIT44A.tmp"
Mon 11 Feb 2008 0 A..H. --- "C:\Documents and Settings\Ginna\Local Settings\Temp\BIT44B.tmp"
Mon 11 Feb 2008 0 A..H. --- "C:\Documents and Settings\Ginna\Local Settings\Temp\BIT44C.tmp"
Mon 11 Feb 2008 0 A..H. --- "C:\Documents and Settings\Ginna\Local Settings\Temp\BIT44D.tmp"
Mon 11 Feb 2008 0 A..H. --- "C:\Documents and Settings\Ginna\Local Settings\Temp\BIT44E.tmp"
Mon 11 Feb 2008 0 A..H. --- "C:\Documents and Settings\Ginna\Local Settings\Temp\BIT44F.tmp"
Thu 31 Jan 2008 0 A..H. --- "C:\Documents and Settings\Ginna\Local Settings\Temp\BIT45.tmp"
Mon 11 Feb 2008 0 A..H. --- "C:\Documents and Settings\Ginna\Local Settings\Temp\BIT450.tmp"
Mon 11 Feb 2008 0 A..H. --- "C:\Documents and Settings\Ginna\Local Settings\Temp\BIT451.tmp"
Mon 11 Feb 2008 0 A..H. --- "C:\Documents and Settings\Ginna\Local Settings\Temp\BIT452.tmp"
Mon 11 Feb 2008 0 A..H. --- "C:\Documents and Settings\Ginna\Local Settings\Temp\BIT453.tmp"
Mon 11 Feb 2008 0 A..H. --- "C:\Documents and Settings\Ginna\Local Settings\Temp\BIT454.tmp"
Mon 11 Feb 2008 0 A..H. --- "C:\Documents and Settings\Ginna\Local Settings\Temp\BIT455.tmp"
Mon 11 Feb 2008 0 A..H. --- "C:\Documents and Settings\Ginna\Local Settings\Temp\BIT456.tmp"
Mon 11 Feb 2008 0 A..H. --- "C:\Documents and Settings\Ginna\Local Settings\Temp\BIT457.tmp"
Mon 11 Feb 2008 0 A..H. --- "C:\Documents and Settings\Ginna\Local Settings\Temp\BIT458.tmp"
Mon 11 Feb 2008 0 A..H. --- "C:\Documents and Settings\Ginna\Local Settings\Temp\BIT459.tmp"
Mon 11 Feb 2008 0 A..H. --- "C:\Documents and Settings\Ginna\Local Settings\Temp\BIT45C.tmp"
Mon 11 Feb 2008 0 A..H. --- "C:\Documents and Settings\Ginna\Local Settings\Temp\BIT45E.tmp"
Mon 11 Feb 2008 0 A..H. --- "C:\Documents and Settings\Ginna\Local Settings\Temp\BIT45F.tmp"
Sun 27 Jan 2008 0 A..H. --- "C:\Documents and Settings\Ginna\Local Settings\Temp\BIT46.tmp"
Mon 11 Feb 2008 0 A..H. --- "C:\Documents and Settings\Ginna\Local Settings\Temp\BIT462.tmp"
Mon 11 Feb 2008 0 A..H. --- "C:\Documents and Settings\Ginna\Local Settings\Temp\BIT463.tmp"
Thu 31 Jan 2008 0 A..H. --- "C:\Documents and Settings\Ginna\Local Settings\Temp\BIT47.tmp"
Thu 31 Jan 2008 0 A..H. --- "C:\Documents and Settings\Ginna\Local Settings\Temp\BIT48.tmp"
Mon 11 Feb 2008 0 A..H. --- "C:\Documents and Settings\Ginna\Local Settings\Temp\BIT48A.tmp"
Thu 31 Jan 2008 0 A..H. --- "C:\Documents and Settings\Ginna\Local Settings\Temp\BIT49.tmp"
Mon 11 Feb 2008 0 A..H. --- "C:\Documents and Settings\Ginna\Local Settings\Temp\BIT49A.tmp"
Mon 11 Feb 2008 0 A..H. --- "C:\Documents and Settings\Ginna\Local Settings\Temp\BIT49B.tmp"
Mon 11 Feb 2008 0 A..H. --- "C:\Documents and Settings\Ginna\Local Settings\Temp\BIT49C.tmp"
Sat 26 Jan 2008 0 A..H. --- "C:\Documents and Settings\Ginna\Local Settings\Temp\BIT4A.tmp"
Mon 11 Feb 2008 0 A..H. --- "C:\Documents and Settings\Ginna\Local Settings\Temp\BIT4AC.tmp"
Mon 11 Feb 2008 0 A..H. --- "C:\Documents and Settings\Ginna\Local Settings\Temp\BIT4AE.tmp"
Mon 11 Feb 2008 0 A..H. --- "C:\Documents and Settings\Ginna\Local Settings\Temp\BIT4AF.tmp"
Thu 31 Jan 2008 0 A..H. --- "C:\Documents and Settings\Ginna\Local Settings\Temp\BIT4B.tmp"
Mon 11 Feb 2008 0 A..H. --- "C:\Documents and Settings\Ginna\Local Settings\Temp\BIT4B1.tmp"
Mon 11 Feb 2008 0 A..H. --- "C:\Documents and Settings\Ginna\Local Settings\Temp\BIT4B3.tmp"
Mon 11 Feb 2008 0 A..H. --- "C:\Documents and Settings\Ginna\Local Settings\Temp\BIT4B4.tmp"
Mon 11 Feb 2008 0 A..H. --- "C:\Documents and Settings\Ginna\Local Settings\Temp\BIT4B6.tmp"
Mon 11 Feb 2008 0 A..H. --- "C:\Documents and Settings\Ginna\Local Settings\Temp\BIT4B8.tmp"
Mon 11 Feb 2008 0 A..H. --- "C:\Documents and Settings\Ginna\Local Settings\Temp\BIT4B9.tmp"
Mon 11 Feb 2008 0 A..H. --- "C:\Documents and Settings\Ginna\Local Settings\Temp\BIT4BB.tmp"
Mon 11 Feb 2008 0 A..H. --- "C:\Documents and Settings\Ginna\Local Settings\Temp\BIT4BD.tmp"
Mon 11 Feb 2008 0 A..H. --- "C:\Documents and Settings\Ginna\Local Settings\Temp\BIT4BF.tmp"
Sat 26 Jan 2008 0 A..H. --- "C:\Documents and Settings\Ginna\Local Settings\Temp\BIT4C.tmp"
Mon 11 Feb 2008 0 A..H. --- "C:\Documents and Settings\Ginna\Local Settings\Temp\BIT4C1.tmp"
Mon 11 Feb 2008 0 A..H. --- "C:\Documents and Settings\Ginna\Local Settings\Temp\BIT4C2.tmp"
Sun 27 Jan 2008 0 A..H. --- "C:\Documents and Settings\Ginna\Local Settings\Temp\BIT4D.tmp"
Mon 11 Feb 2008 0 A..H. --- "C:\Documents and Settings\Ginna\Local Settings\Temp\BIT4DF.tmp"
Sat 26 Jan 2008 0 A..H. --- "C:\Documents and Settings\Ginna\Local Settings\Temp\BIT4E.tmp"
Mon 11 Feb 2008 0 A..H. --- "C:\Documents and Settings\Ginna\Local Settings\Temp\BIT4E2.tmp"
Mon 11 Feb 2008 0 A..H. --- "C:\Documents and Settings\Ginna\Local Settings\Temp\BIT4E3.tmp"
Tue 12 Feb 2008 0 A..H. --- "C:\Documents and Settings\Ginna\Local Settings\Temp\BIT4E4.tmp"
Mon 11 Feb 2008 0 A..H. --- "C:\Documents and Settings\Ginna\Local Settings\Temp\BIT4E5.tmp"
Mon 11 Feb 2008 0 A..H. --- "C:\Documents and Settings\Ginna\Local Settings\Temp\BIT4E6.tmp"
Mon 11 Feb 2008 0 A..H. --- "C:\Documents and Settings\Ginna\Local Settings\Temp\BIT4E8.tmp"
Mon 11 Feb 2008 0 A..H. --- "C:\Documents and Settings\Ginna\Local Settings\Temp\BIT4EA.tmp"
Mon 11 Feb 2008 0 A..H. --- "C:\Documents and Settings\Ginna\Local Settings\Temp\BIT4EB.tmp"
Mon 11 Feb 2008 0 A..H. --- "C:\Documents and Settings\Ginna\Local Settings\Temp\BIT4EC.tmp"
Mon 11 Feb 2008 0 A..H. --- "C:\Documents and Settings\Ginna\Local Settings\Temp\BIT4ED.tmp"
Mon 11 Feb 2008 0 A..H. --- "C:\Documents and Settings\Ginna\Local Settings\Temp\BIT4EF.tmp"
Sat 26 Jan 2008 0 A..H. --- "C:\Documents and Settings\Ginna\Local Settings\Temp\BIT4F.tmp"
Mon 11 Feb 2008 0 A..H. --- "C:\Documents and Settings\Ginna\Local Settings\Temp\BIT4F0.tmp"
Mon 11 Feb 2008 0 A..H. --- "C:\Documents and Settings\Ginna\Local Settings\Temp\BIT4F1.tmp"
Mon 11 Feb 2008 0 A..H. --- "C:\Documents and Settings\Ginna\Local Settings\Temp\BIT4F2.tmp"
Mon 11 Feb 2008 0 A..H. --- "C:\Documents and Settings\Ginna\Local Settings\Temp\BIT4F4.tmp"
Mon 11 Feb 2008 0 A..H. --- "C:\Documents and Settings\Ginna\Local Settings\Temp\BIT4F5.tmp"
Mon 11 Feb 2008 0 A..H. --- "C:\Documents and Settings\Ginna\Local Settings\Temp\BIT4F6.tmp"
Mon 11 Feb 2008 0 A..H. --- "C:\Documents and Settings\Ginna\Local Settings\Temp\BIT4F7.tmp"
Mon 11 Feb 2008 0 A..H. --- "C:\Documents and Settings\Ginna\Local Settings\Temp\BIT4F8.tmp"
Mon 11 Feb 2008 0 A..H. --- "C:\Documents and Settings\Ginna\Local Settings\Temp\BIT4F9.tmp"
Mon 11 Feb 2008 0 A..H. --- "C:\Documents and Settings\Ginna\Local Settings\Temp\BIT4FA.tmp"
Mon 11 Feb 2008 0 A..H. --- "C:\Documents and Settings\Ginna\Local Settings\Temp\BIT4FB.tmp"
Mon 11 Feb 2008 0 A..H. --- "C:\Documents and Settings\Ginna\Local Settings\Temp\BIT4FC.tmp"
Mon 11 Feb 2008 0 A..H. --- "C:\Documents and Settings\Ginna\Local Settings\Temp\BIT4FD.tmp"
Mon 11 Feb 2008 0 A..H. --- "C:\Documents and Settings\Ginna\Local Settings\Temp\BIT4FE.tmp"
Mon 11 Feb 2008 0 A..H. --- "C:\Documents and Settings\Ginna\Local Settings\Temp\BIT4FF.tmp"
Mon 11 Feb 2008 0 A..H. --- "C:\Documents and Settings\Ginna\Local Settings\Temp\BIT5.tmp"
Sun 27 Jan 2008 0 A..H. --- "C:\Documents and Settings\Ginna\Local Settings\Temp\BIT50.tmp"
Sat 26 Jan 2008 0 A..H. --- "C:\Documents and Settings\Ginna\Local Settings\Temp\BIT51.tmp"
Tue 12 Feb 2008 0 A..H. --- "C:\Documents and Settings\Ginna\Local Settings\Temp\BIT514.tmp"
Mon 11 Feb 2008 0 A..H. --- "C:\Documents and Settings\Ginna\Local Settings\Temp\BIT518.tmp"
Mon 11 Feb 2008 0 A..H. --- "C:\Documents and Settings\Ginna\Local Settings\Temp\BIT519.tmp"
Mon 11 Feb 2008 0 A..H. --- "C:\Documents and Settings\Ginna\Local Settings\Temp\BIT51A.tmp"
Tue 12 Feb 2008 0 A..H. --- "C:\Documents and Settings\Ginna\Local Settings\Temp\BIT51B.tmp"
Mon 11 Feb 2008 0 A..H. --- "C:\Documents and Settings\Ginna\Local Settings\Temp\BIT51C.tmp"
Mon 11 Feb 2008 0 A..H. --- "C:\Documents and Settings\Ginna\Local Settings\Temp\BIT51D.tmp"
Mon 11 Feb 2008 0 A..H. --- "C:\Documents and Settings\Ginna\Local Settings\Temp\BIT51E.tmp"
Mon 11 Feb 2008 0 A..H. --- "C:\Documents and Settings\Ginna\Local Settings\Temp\BIT51F.tmp"
Sun 27 Jan 2008 0 A..H. --- "C:\Documents and Settings\Ginna\Local Settings\Temp\BIT52.tmp"
Mon 11 Feb 2008 0 A..H. --- "C:\Documents and Settings\Ginna\Local Settings\Temp\BIT520.tmp"
Tue 12 Feb 2008 0 A..H. --- "C:\Documents and Settings\Ginna\Local Settings\Temp\BIT521.tmp"
Tue 12 Feb 2008 0 A..H. --- "C:\Documents and Settings\Ginna\Local Settings\Temp\BIT522.tmp"
Tue 12 Feb 2008 0 A..H. --- "C:\Documents and Settings\Ginna\Local Settings\Temp\BIT523.tmp"
Tue 12 Feb 2008 0 A..H. --- "C:\Documents and Settings\Ginna\Local Settings\Temp\BIT524.tmp"
Tue 12 Feb 2008 0 A..H. --- "C:\Documents and Settings\Ginna\Local Settings\Temp\BIT525.tmp"
Tue 12 Feb 2008 0 A..H. --- "C:\Documents and Settings\Ginna\Local Settings\Temp\BIT526.tmp"
Tue 12 Feb 2008 0 A..H. --- "C:\Documents and Settings\Ginna\Local Settings\Temp\BIT527.tmp"
Tue 12 Feb 2008 0 A..H. --- "C:\Documents and Settings\Ginna\Local Settings\Temp\BIT528.tmp"
Tue 12 Feb 2008 0 A..H. --- "C:\Documents and Settings\Ginna\Local Settings\Temp\BIT52A.tmp"
Tue 12 Feb 2008 0 A..H. --- "C:\Documents and Settings\Ginna\Local Settings\Temp\BIT52B.tmp"
Tue 12 Feb 2008 0 A..H. --- "C:\Documents and Settings\Ginna\Local Settings\Temp\BIT52D.tmp"
Tue 12 Feb 2008 0 A..H. --- "C:\Documents and Settings\Ginna\Local Settings\Temp\BIT52F.tmp"
Sat 26 Jan 2008 0 A..H. --- "C:\Documents and Settings\Ginna\Local Settings\Temp\BIT53.tmp"
Tue 12 Feb 2008 0 A..H. --- "C:\Documents and Settings\Ginna\Local Settings\Temp\BIT530.tmp"
Tue 12 Feb 2008 0 A..H. --- "C:\Documents and Settings\Ginna\Local Settings\Temp\BIT531.tmp"
Tue 12 Feb 2008 0 A..H. --- "C:\Documents and Settings\Ginna\Local Settings\Temp\BIT532.tmp"
Sat 26 Jan 2008 0 A..H. --- "C:\Documents and Settings\Ginna\Local Settings\Temp\BIT54.tmp"
Sun 27 Jan 2008 0 A..H. --- "C:\Documents and Settings\Ginna\Local Settings\Temp\BIT55.tmp"
Tue 12 Feb 2008 0 A..H. --- "C:\Documents and Settings\Ginna\Local Settings\Temp\BIT55A.tmp"
Tue 12 Feb 2008 0 A..H. --- "C:\Documents and Settings\Ginna\Local Settings\Temp\BIT55F.tmp"
Sat 26 Jan 2008 0 A..H. --- "C:\Documents and Settings\Ginna\Local Settings\Temp\BIT56.tmp"
Tue 12 Feb 2008 0 A..H. --- "C:\Documents and Settings\Ginna\Local Settings\Temp\BIT560.tmp"
Tue 12 Feb 2008 0 A..H. --- "C:\Documents and Settings\Ginna\Local Settings\Temp\BIT561.tmp"
Tue 12 Feb 2008 0 A..H. --- "C:\Documents and Settings\Ginna\Local Settings\Temp\BIT563.tmp"
Tue 12 Feb 2008 0 A..H. --- "C:\Documents and Settings\Ginna\Local Settings\Temp\BIT564.tmp"
Tue 12 Feb 2008 0 A..H. --- "C:\Documents and Settings\Ginna\Local Settings\Temp\BIT565.tmp"
Tue 12 Feb 2008 0 A..H. --- "C:\Documents and Settings\Ginna\Local Settings\Temp\BIT567.tmp"
Tue 12 Feb 2008 0 A..H. --- "C:\Documents and Settings\Ginna\Local Settings\Temp\BIT569.tmp"
Tue 12 Feb 2008 0 A..H. --- "C:\Documents and Settings\Ginna\Local Settings\Temp\BIT56A.tmp"
Tue 12 Feb 2008 0 A..H. --- "C:\Documents and Settings\Ginna\Local Settings\Temp\BIT56B.tmp"
Tue 12 Feb 2008 0 A..H. --- "C:\Documents and Settings\Ginna\Local Settings\Temp\BIT56E.tmp"
Tue 12 Feb 2008 0 A..H. --- "C:\Documents and Settings\Ginna\Local Settings\Temp\BIT56F.tmp"
Sun 27 Jan 2008 0 A..H. --- "C:\Documents and Settings\Ginna\Local Settings\Temp\BIT57.tmp"
Tue 12 Feb 2008 0 A..H. --- "C:\Documents and Settings\Ginna\Local Settings\Temp\BIT570.tmp"
Tue 12 Feb 2008 0 A..H. --- "C:\Documents and Settings\Ginna\Local Settings\Temp\BIT572.tmp"
Tue 12 Feb 2008 0 A..H. --- "C:\Documents and Settings\Ginna\Local Settings\Temp\BIT574.tmp"
Tue 12 Feb 2008 0 A..H. --- "C:\Documents and Settings\Ginna\Local Settings\Temp\BIT576.tmp"
Tue 12 Feb 2008 0 A..H. --- "C:\Documents and Settings\Ginna\Local Settings\Temp\BIT578.tmp"
Tue 12 Feb 2008 0 A..H. --- "C:\Documents and Settings\Ginna\Local Settings\Temp\BIT57A.tmp"
Tue 12 Feb 2008 0 A..H. --- "C:\Documents and Settings\Ginna\Local Settings\Temp\BIT57C.tmp"
Tue 12 Feb 2008 0 A..H. --- "C:\Documents and Settings\Ginna\Local Settings\Temp\BIT57D.tmp"
Tue 12 Feb 2008 0 A..H. --- "C:\Documents and Settings\Ginna\Local Settings\Temp\BIT57E.tmp"
Tue 12 Feb 2008 0 A..H. --- "C:\Documents and Settings\Ginna\Local Settings\Temp\BIT57F.tmp"
Sat 26 Jan 2008 0 A..H. --- "C:\Documents and Settings\Ginna\Local Settings\Temp\BIT58.tmp"
Tue 12 Feb 2008 0 A..H. --- "C:\Documents and Settings\Ginna\Local Settings\Temp\BIT582.tmp"
Tue 12 Feb 2008 0 A..H. --- "C:\Documents and Settings\Ginna\Local Settings\Temp\BIT583.tmp"
Tue 12 Feb 2008 0 A..H. --- "C:\Documents and Settings\Ginna\Local Settings\Temp\BIT584.tmp"
Tue 12 Feb 2008 0 A..H. --- "C:\Documents and Settings\Ginna\Local Settings\Temp\BIT585.tmp"
Tue 12 Feb 2008 0 A..H. --- "C:\Documents and Settings\Ginna\Local Settings\Temp\BIT587.tmp"
Tue 12 Feb 2008 0 A..H. --- "C:\Documents and Settings\Ginna\Local Settings\Temp\BIT589.tmp"
Tue 12 Feb 2008 0 A..H. --- "C:\Documents and Settings\Ginna\Local Settings\Temp\BIT58B.tmp"
Tue 12 Feb 2008 0 A..H. --- "C:\Documents and Settings\Ginna\Local Settings\Temp\BIT58C.tmp"
Tue 12 Feb 2008 0 A..H. --- "C:\Documents and Settings\Ginna\Local Settings\Temp\BIT58E.tmp"
Sun 27 Jan 2008 0 A..H. --- "C:\Documents and Settings\Ginna\Local Settings\Temp\BIT59.tmp"
Tue 12 Feb 2008 0 A..H. --- "C:\Documents and Settings\Ginna\Local Settings\Temp\BIT590.tmp"
Tue 12 Feb 2008 0 A..H. --- "C:\Documents and Settings\Ginna\Local Settings\Temp\BIT591.tmp"
Tue 12 Feb 2008 0 A..H. --- "C:\Documents and Settings\Ginna\Local Settings\Temp\BIT592.tmp"
Tue 12 Feb 2008 0 A..H. --- "C:\Documents and Settings\Ginna\Local Settings\Temp\BIT594.tmp"
Tue 12 Feb 2008 0 A..H. --- "C:\Documents and Settings\Ginna\Local Settings\Temp\BIT595.tmp"
Tue 12 Feb 2008 0 A..H. --- "C:\Documents and Settings\Ginna\Local Settings\Temp\BIT597.tmp"
Tue 12 Feb 2008 0 A..H. --- "C:\Documents and Settings\Ginna\Local Settings\Temp\BIT599.tmp"
Tue 12 Feb 2008 0 A..H. --- "C:\Documents and Settings\Ginna\Local Settings\Temp\BIT59A.tmp"
Tue 12 Feb 2008 0 A..H. --- "C:\Documents and Settings\Ginna\Local Settings\Temp\BIT59B.tmp"
Tue 12 Feb 2008 0 A..H. --- "C:\Documents and Settings\Ginna\Local Settings\Temp\BIT59D.tmp"
Tue 12 Feb 2008 0 A..H. --- "C:\Documents and Settings\Ginna\Local Settings\Temp\BIT59E.tmp"
Tue 12 Feb 2008 0 A..H. --- "C:\Documents and Settings\Ginna\Local Settings\Temp\BIT59F.tmp"
Sat 26 Jan 2008 0 A..H. --- "C:\Documents and Settings\Ginna\Local Settings\Temp\BIT5A.tmp"
Tue 12 Feb 2008 0 A..H. --- "C:\Documents and Settings\Ginna\Local Settings\Temp\BIT5A0.tmp"
Tue 12 Feb 2008 0 A..H. --- "C:\Documents and Settings\Ginna\Local Settings\Temp\BIT5A3.tmp"
Tue 12 Feb 2008 0 A..H. --- "C:\Documents and Settings\Ginna\Local Settings\Temp\BIT5A4.tmp"
Tue 12 Feb 2008 0 A..H. --- "C:\Documents and Settings\Ginna\Local Settings\Temp\BIT5A5.tmp"
Tue 12 Feb 2008 0 A..H. --- "C:\Documents and Settings\Ginna\Local Settings\Temp\BIT5A6.tmp"
Sat 26 Jan 2008 0 A..H. --- "C:\Documents and Settings\Ginna\Local Settings\Temp\BIT5B.tmp"
Sat 26 Jan 2008 0 A..H. --- "C:\Documents and Settings\Ginna\Local Settings\Temp\BIT5C.tmp"
Tue 12 Feb 2008 0 A..H. --- "C:\Documents and Settings\Ginna\Local Settings\Temp\BIT5CD.tmp"
Sun 27 Jan 2008 0 A..H. --- "C:\Documents and Settings\Ginna\Local Settings\Temp\BIT5D.tmp"
Tue 12 Feb 2008 0 A..H. --- "C:\Documents and Settings\Ginna\Local Settings\Temp\BIT5DC.tmp"
Mon 4 Feb 2008 0 A..H. --- "C:\Documents and Settings\Ginna\Local Settings\Temp\BIT5E.tmp"
Tue 12 Feb 2008 0 A..H. --- "C:\Documents and Settings\Ginna\Local Settings\Temp\BIT5EB.tmp"
Tue 12 Feb 2008 0 A..H. --- "C:\Documents and Settings\Ginna\Local Settings\Temp\BIT5EC.tmp"
Tue 12 Feb 2008 0 A..H. --- "C:\Documents and Settings\Ginna\Local Settings\Temp\BIT5ED.tmp"
Tue 12 Feb 2008 0 A..H. --- "C:\Documents and Settings\Ginna\Local Settings\Temp\BIT5EE.tmp"
Tue 12 Feb 2008 0 A..H. --- "C:\Documents and Settings\Ginna\Local Settings\Temp\BIT5EF.tmp"
Sat 26 Jan 2008 0 A..H. --- "C:\Documents and Settings\Ginna\Local Settings\Temp\BIT5F.tmp"
Sat 26 Jan 2008 0 A..H. --- "C:\Documents and Settings\Ginna\Local Settings\Temp\BIT60.tmp"
Thu 24 Jan 2008 85,946 A..H. --- "C:\Documents and Settings\Ginna\Local Settings\Temp\BIT61.tmp"
Sun 27 Jan 2008 0 A..H. --- "C:\Documents and Settings\Ginna\Local Settings\Temp\BIT62.tmp"
Sun 27 Jan 2008 0 A..H. --- "C:\Documents and Settings\Ginna\Local Settings\Temp\BIT63.tmp"
Sun 27 Jan 2008 0 A..H. --- "C:\Documents and Settings\Ginna\Local Settings\Temp\BIT64.tmp"
Tue 29 Jan 2008 0 A..H. --- "C:\Documents and Settings\Ginna\Local Settings\Temp\BIT65.tmp"
Sat 26 Jan 2008 0 A..H. --- "C:\Documents and Settings\Ginna\Local Settings\Temp\BIT66.tmp"
Sat 26 Jan 2008 0 A..H. --- "C:\Documents and Settings\Ginna\Local Settings\Temp\BIT67.tmp"
Thu 24 Jan 2008 0 A..H. --- "C:\Documents and Settings\Ginna\Local Settings\Temp\BIT68.tmp"
Thu 24 Jan 2008 0 A..H. --- "C:\Documents and Settings\Ginna\Local Settings\Temp\BIT69.tmp"
Sat 26 Jan 2008 0 A..H. --- "C:\Documents and Settings\Ginna\Local Settings\Temp\BIT6A.tmp"
Thu 24 Jan 2008 0 A..H. --- "C:\Documents and Settings\Ginna\Local Settings\Temp\BIT6B.tmp"
Sat 26 Jan 2008 0 A..H. --- "C:\Documents and Settings\Ginna\Local Settings\Temp\BIT6C.tmp"
Thu 24 Jan 2008 0 A..H. --- "C:\Documents and Settings\Ginna\Local Settings\Temp\BIT6D.tmp"
Thu 24 Jan 2008 0 A..H. --- "C:\Documents and Settings\Ginna\Local Settings\Temp\BIT6E.tmp"
Sat 26 Jan 2008 0 A..H. --- "C:\Documents and Settings\Ginna\Local Settings\Temp\BIT6F.tmp"
Sat 26 Jan 2008 0 A..H. --- "C:\Documents and Settings\Ginna\Local Settings\Temp\BIT70.tmp"
Sat 26 Jan 2008 0 A..H. --- "C:\Documents and Settings\Ginna\Local Settings\Temp\BIT71.tmp"
Sun 27 Jan 2008 0 A..H. --- "C:\Documents and Settings\Ginna\Local Settings\Temp\BIT72.tmp"
Sun 27 Jan 2008 0 A..H. --- "C:\Documents and Settings\Ginna\Local Settings\Temp\BIT73.tmp"
Sun 27 Jan 2008 0 A..H. --- "C:\Documents and Settings\Ginna\Local Settings\Temp\BIT74.tmp"
Sat 26 Jan 2008 0 A..H. --- "C:\Documents and Settings\Ginna\Local Settings\Temp\BIT75.tmp"
Sat 26 Jan 2008 0 A..H. --- "C:\Documents and Settings\Ginna\Local Settings\Temp\BIT76.tmp"
Sun 27 Jan 2008 0 A..H. --- "C:\Documents and Settings\Ginna\Local Settings\Temp\BIT77.tmp"
Sun 27 Jan 2008 0 A..H. --- "C:\Documents and Settings\Ginna\Local Settings\Temp\BIT78.tmp"
Tue 29 Jan 2008 0 A..H. --- "C:\Documents and Settings\Ginna\Local Settings\Temp\BIT79.tmp"
Sat 26 Jan 2008 0 A..H. --- "C:\Documents and Settings\Ginna\Local Settings\Temp\BIT7A.tmp"
Sat 26 Jan 2008 0 A..H. --- "C:\Documents and Settings\Ginna\Local Settings\Temp\BIT7B.tmp"
Sat 26 Jan 2008 0 A..H. --- "C:\Documents and Settings\Ginna\Local Settings\Temp\BIT7C.tmp"
Sun 27 Jan 2008 0 A..H. --- "C:\Documents and Settings\Ginna\Local Settings\Temp\BIT7D.tmp"
Sat 26 Jan 2008 0 A..H. --- "C:\Documents and Settings\Ginna\Local Settings\Temp\BIT7E.tmp"
Sat 26 Jan 2008 0 A..H. --- "C:\Documents and Settings\Ginna\Local Settings\Temp\BIT7F.tmp"
Sat 26 Jan 2008 0 A..H. --- "C:\Documents and Settings\Ginna\Local Settings\Temp\BIT80.tmp"
Sun 27 Jan 2008 0 A..H. --- "C:\Documents and Settings\Ginna\Local Settings\Temp\BIT81.tmp"
Sat 26 Jan 2008 0 A..H. --- "C:\Documents and Settings\Ginna\Local Settings\Temp\BIT82.tmp"
Sat 26 Jan 2008 0 A..H. --- "C:\Documents and Settings\Ginna\Local Settings\Temp\BIT83.tmp"
Sun 27 Jan 2008 0 A..H. --- "C:\Documents and Settings\Ginna\Local Settings\Temp\BIT84.tmp"
Sun 27 Jan 2008 0 A..H. --- "C:\Documents and Settings\Ginna\Local Settings\Temp\BIT85.tmp"
Tue 29 Jan 2008 0 A..H. --- "C:\Documents and Settings\Ginna\Local Settings\Temp\BIT86.tmp"
Sun 27 Jan 2008 0 A..H. --- "C:\Documents and Settings\Ginna\Local Settings\Temp\BIT87.tmp"
Sun 27 Jan 2008 0 A..H. --- "C:\Documents and Settings\Ginna\Local Settings\Temp\BIT88.tmp"
Tue 29 Jan 2008 0 A..H. --- "C:\Documents and Settings\Ginna\Local Settings\Temp\BIT89.tmp"
Sun 27 Jan 2008 0 A..H. --- "C:\Documents and Settings\Ginna\Local Settings\Temp\BIT8A.tmp"
Tue 29 Jan 2008 0 A..H. --- "C:\Documents and Settings\Ginna\Local Settings\Temp\BIT8B.tmp"
Tue 29 Jan 2008 0 A..H. --- "C:\Documents and Settings\Ginna\Local Settings\Temp\BIT8C.tmp"
Sun 27 Jan 2008 0 A..H. --- "C:\Documents and Settings\Ginna\Local Settings\Temp\BIT8D.tmp"
Sun 27 Jan 2008 0 A..H. --- "C:\Documents and Settings\Ginna\Local Settings\Temp\BIT8E.tmp"
Sun 27 Jan 2008 0 A..H. --- "C:\Documents and Settings\Ginna\Local Settings\Temp\BIT8F.tmp"
Sun 27 Jan 2008 0 A..H. --- "C:\Documents and Settings\Ginna\Local Settings\Temp\BIT90.tmp"
Sun 27 Jan 2008 0 A..H. --- "C:\Documents and Settings\Ginna\Local Settings\Temp\BIT91.tmp"
Sun 27 Jan 2008 0 A..H. --- "C:\Documents and Settings\Ginna\Local Settings\Temp\BIT92.tmp"
Tue 29 Jan 2008 0 A..H. --- "C:\Documents and Settings\Ginna\Local Settings\Temp\BIT93.tmp"
Thu 31 Jan 2008 0 A..H. --- "C:\Documents and Settings\Ginna\Local Settings\Temp\BIT94.tmp"
Tue 29 Jan 2008 0 A..H. --- "C:\Documents and Settings\Ginna\Local Settings\Temp\BIT95.tmp"
Fri 1 Feb 2008 0 A..H. --- "C:\Documents and Settings\Ginna\Local Settings\Temp\BIT96.tmp"
Tue 29 Jan 2008 0 A..H. --- "C:\Documents and Settings\Ginna\Local Settings\Temp\BIT97.tmp"
Thu 31 Jan 2008 0 A..H. --- "C:\Documents and Settings\Ginna\Local Settings\Temp\BIT98.tmp"
Tue 29 Jan 2008 0 A..H. --- "C:\Documents and Settings\Ginna\Local Settings\Temp\BIT99.tmp"
Mon 4 Feb 2008 0 A..H. --- "C:\Documents and Settings\Ginna\Local Settings\Temp\BIT9A.tmp"
Wed 6 Feb 2008 0 A..H. --- "C:\Documents and Settings\Ginna\Local Settings\Temp\BIT9B.tmp"
Tue 29 Jan 2008 0 A..H. --- "C:\Documents and Settings\Ginna\Local Settings\Temp\BIT9C.tmp"
Mon 4 Feb 2008 0 A..H. --- "C:\Documents and Settings\Ginna\Local Settings\Temp\BIT9D.tmp"
Thu 31 Jan 2008 0 A..H. --- "C:\Documents and Settings\Ginna\Local Settings\Temp\BIT9E.tmp"
Tue 29 Jan 2008 0 A..H. --- "C:\Documents and Settings\Ginna\Local Settings\Temp\BIT9F.tmp"
Mon 4 Feb 2008 0 A..H. --- "C:\Documents and Settings\Ginna\Local Settings\Temp\BITA0.tmp"
Mon 4 Feb 2008 0 A..H. --- "C:\Documents and Settings\Ginna\Local Settings\Temp\BITA1.tmp"
Tue 29 Jan 2008 0 A..H. --- "C:\Documents and Settings\Ginna\Local Settings\Temp\BITA2.tmp"
Mon 4 Feb 2008 0 A..H. --- "C:\Documents and Settings\Ginna\Local Settings\Temp\BITA3.tmp"
Tue 29 Jan 2008 0 A..H. --- "C:\Documents and Settings\Ginna\Local Settings\Temp\BITA4.tmp"
Fri 1 Feb 2008 0 A..H. --- "C:\Documents and Settings\Ginna\Local Settings\Temp\BITA5.tmp"
Fri 1 Feb 2008 0 A..H. --- "C:\Documents and Settings\Ginna\Local Settings\Temp\BITA6.tmp"
Mon 4 Feb 2008 0 A..H. --- "C:\Documents and Settings\Ginna\Local Settings\Temp\BITA7.tmp"
Tue 29 Jan 2008 0 A..H. --- "C:\Documents and Settings\Ginna\Local Settings\Temp\BITA8.tmp"
Thu 31 Jan 2008 0 A..H. --- "C:\Documents and Settings\Ginna\Local Settings\Temp\BITA9.tmp"
Tue 29 Jan 2008 0 A..H. --- "C:\Documents and Settings\Ginna\Local Settings\Temp\BITAA.tmp"
Thu 31 Jan 2008 0 A..H. --- "C:\Documents and Settings\Ginna\Local Settings\Temp\BITAB.tmp"
Tue 29 Jan 2008 0 A..H. --- "C:\Documents and Settings\Ginna\Local Settings\Temp\BITAC.tmp"
Tue 29 Jan 2008 0 A..H. --- "C:\Documents and Settings\Ginna\Local Settings\Temp\BITAD.tmp"
Thu 24 Jan 2008 0 A..H. --- "C:\Documents and Settings\Ginna\Local Settings\Temp\BITAE.tmp"
Wed 30 Jan 2008 0 A..H. --- "C:\Documents and Settings\Ginna\Local Settings\Temp\BITAF.tmp"
Thu 31 Jan 2008 0 A..H. --- "C:\Documents and Settings\Ginna\Local Settings\Temp\BITB0.tmp"
Tue 29 Jan 2008 0 A..H. --- "C:\Documents and Settings\Ginna\Local Settings\Temp\BITB1.tmp"
Fri 1 Feb 2008 0 A..H. --- "C:\Documents and Settings\Ginna\Local Settings\Temp\BITB2.tmp"
Fri 1 Feb 2008 0 A..H. --- "C:\Documents and Settings\Ginna\Local Settings\Temp\BITB3.tmp"
Mon 4 Feb 2008 0 A..H. --- "C:\Documents and Settings\Ginna\Local Settings\Temp\BITB4.tmp"
Wed 30 Jan 2008 0 A..H. --- "C:\Documents and Settings\Ginna\Local Settings\Temp\BITB5.tmp"
Fri 1 Feb 2008 0 A..H. --- "C:\Documents and Settings\Ginna\Local Settings\Temp\BITB6.tmp"
Tue 5 Feb 2008 0 A..H. --- "C:\Documents and Settings\Ginna\Local Settings\Temp\BITB7.tmp"
Wed 30 Jan 2008 0 A..H. --- "C:\Documents and Settings\Ginna\Local Settings\Temp\BITB8.tmp"
Wed 30 Jan 2008 0 A..H. --- "C:\Documents and Settings\Ginna\Local Settings\Temp\BITB9.tmp"
Wed 30 Jan 2008 0 A..H. --- "C:\Documents and Settings\Ginna\Local Settings\Temp\BITBA.tmp"
Fri 1 Feb 2008 0 A..H. --- "C:\Documents and Settings\Ginna\Local Settings\Temp\BITBB.tmp"
Wed 30 Jan 2008 0 A..H. --- "C:\Documents and Settings\Ginna\Local Settings\Temp\BITBC.tmp"
Fri 1 Feb 2008 0 A..H. --- "C:\Documents and Settings\Ginna\Local Settings\Temp\BITBD.tmp"
Wed 30 Jan 2008 0 A..H. --- "C:\Documents and Settings\Ginna\Local Settings\Temp\BITBE.tmp"
Tue 5 Feb 2008 0 A..H. --- "C:\Documents and Settings\Ginna\Local Settings\Temp\BITBF.tmp"
Tue 29 Jan 2008 0 A..H. --- "C:\Documents and Settings\Ginna\Local Settings\Temp\BITC0.tmp"
Thu 31 Jan 2008 0 A..H. --- "C:\Documents and Settings\Ginna\Local Settings\Temp\BITC1.tmp"
Tue 29 Jan 2008 0 A..H. --- "C:\Documents and Settings\Ginna\Local Settings\Temp\BITC2.tmp"
Thu 31 Jan 2008 0 A..H. --- "C:\Documents and Settings\Ginna\Local Settings\Temp\BITC3.tmp"
Tue 29 Jan 2008 0 A..H. --- "C:\Documents and Settings\Ginna\Local Settings\Temp\BITC4.tmp"
Thu 31 Jan 2008 0 A..H. --- "C:\Documents and Settings\Ginna\Local Settings\Temp\BITC5.tmp"
Tue 29 Jan 2008 0 A..H. --- "C:\Documents and Settings\Ginna\Local Settings\Temp\BITC6.tmp"
Tue 5 Feb 2008 0 A..H. --- "C:\Documents and Settings\Ginna\Local Settings\Temp\BITC7.tmp"
Tue 29 Jan 2008 0 A..H. --- "C:\Documents and Settings\Ginna\Local Settings\Temp\BITC8.tmp"
Tue 29 Jan 2008 0 A..H. --- "C:\Documents and Settings\Ginna\Local Settings\Temp\BITC9.tmp"
Tue 29 Jan 2008 0 A..H. --- "C:\Documents and Settings\Ginna\Local Settings\Temp\BITCA.tmp"
Thu 31 Jan 2008 0 A..H. --- "C:\Documents and Settings\Ginna\Local Settings\Temp\BITCB.tmp"
Tue 5 Feb 2008 0 A..H. --- "C:\Documents and Settings\Ginna\Local Settings\Temp\BITCC.tmp"
Tue 29 Jan 2008 0 A..H. --- "C:\Documents and Settings\Ginna\Local Settings\Temp\BITCD.tmp"
Tue 29 Jan 2008 0 A..H. --- "C:\Documents and Settings\Ginna\Local Settings\Temp\BITCE.tmp"
Tue 29 Jan 2008 0 A..H. --- "C:\Documents and Settings\Ginna\Local Settings\Temp\BITCF.tmp"
Mon 4 Feb 2008 0 A..H. --- "C:\Documents and Settings\Ginna\Local Settings\Temp\BITD0.tmp"
Mon 4 Feb 2008 0 A..H. --- "C:\Documents and Settings\Ginna\Local Settings\Temp\BITD1.tmp"
Tue 5 Feb 2008 0 A..H. --- "C:\Documents and Settings\Ginna\Local Settings\Temp\BITD2.tmp"
Mon 4 Feb 2008 0 A..H. --- "C:\Documents and Settings\Ginna\Local Settings\Temp\BITD3.tmp"
Tue 5 Feb 2008 0 A..H. --- "C:\Documents and Settings\Ginna\Local Settings\Temp\BITD4.tmp"
Mon 4 Feb 2008 0 A..H. --- "C:\Documents and Settings\Ginna\Local Settings\Temp\BITD5.tmp"
Mon 4 Feb 2008 0 A..H. --- "C:\Documents and Settings\Ginna\Local Settings\Temp\BITD6.tmp"
Tue 5 Feb 2008 0 A..H. --- "C:\Documents and Settings\Ginna\Local Settings\Temp\BITD7.tmp"
Mon 4 Feb 2008 0 A..H. --- "C:\Documents and Settings\Ginna\Local Settings\Temp\BITD8.tmp"
Tue 5 Feb 2008 0 A..H. --- "C:\Documents and Settings\Ginna\Local Settings\Temp\BITD9.tmp"
Tue 5 Feb 2008 0 A..H. --- "C:\Documents and Settings\Ginna\Local Settings\Temp\BITDA.tmp"
Mon 4 Feb 2008 0 A..H. --- "C:\Documents and Settings\Ginna\Local Settings\Temp\BITDB.tmp"
Mon 4 Feb 2008 0 A..H. --- "C:\Documents and Settings\Ginna\Local Settings\Temp\BITDC.tmp"
Tue 5 Feb 2008 0 A..H. --- "C:\Documents and Settings\Ginna\Local Settings\Temp\BITDD.tmp"
Tue 5 Feb 2008 0 A..H. --- "C:\Documents and Settings\Ginna\Local Settings\Temp\BITDE.tmp"
Mon 4 Feb 2008 0 A..H. --- "C:\Documents and Settings\Ginna\Local Settings\Temp\BITDF.tmp"
Mon 4 Feb 2008 0 A..H. --- "C:\Documents and Settings\Ginna\Local Settings\Temp\BITE0.tmp"
Tue 5 Feb 2008 0 A..H. --- "C:\Documents and Settings\Ginna\Local Settings\Temp\BITE1.tmp"
Tue 5 Feb 2008 0 A..H. --- "C:\Documents and Settings\Ginna\Local Settings\Temp\BITE2.tmp"
Mon 4 Feb 2008 0 A..H. --- "C:\Documents and Settings\Ginna\Local Settings\Temp\BITE3.tmp"
Mon 4 Feb 2008 0 A..H. --- "C:\Documents and Settings\Ginna\Local Settings\Temp\BITE4.tmp"
Mon 4 Feb 2008 0 A..H. --- "C:\Documents and Settings\Ginna\Local Settings\Temp\BITE5.tmp"
Tue 5 Feb 2008 0 A..H. --- "C:\Documents and Settings\Ginna\Local Settings\Temp\BITE6.tmp"
Mon 4 Feb 2008 0 A..H. --- "C:\Documents and Settings\Ginna\Local Settings\Temp\BITE7.tmp"
Tue 5 Feb 2008 0 A..H. --- "C:\Documents and Settings\Ginna\Local Settings\Temp\BITE8.tmp"
Mon 4 Feb 2008 0 A..H. --- "C:\Documents and Settings\Ginna\Local Settings\Temp\BITE9.tmp"
Mon 4 Feb 2008 0 A..H. --- "C:\Documents and Settings\Ginna\Local Settings\Temp\BITEA.tmp"
Tue 5 Feb 2008 0 A..H. --- "C:\Documents and Settings\Ginna\Local Settings\Temp\BITEB.tmp"
Tue 5 Feb 2008 0 A..H. --- "C:\Documents and Settings\Ginna\Local Settings\Temp\BITEC.tmp"
Mon 4 Feb 2008 0 A..H. --- "C:\Documents and Settings\Ginna\Local Settings\Temp\BITED.tmp"
Tue 5 Feb 2008 0 A..H. --- "C:\Documents and Settings\Ginna\Local Settings\Temp\BITEE.tmp"
Mon 4 Feb 2008 0 A..H. --- "C:\Documents and Settings\Ginna\Local Settings\Temp\BITEF.tmp"
Tue 5 Feb 2008 0 A..H. --- "C:\Documents and Settings\Ginna\Local Settings\Temp\BITF0.tmp"
Mon 4 Feb 2008 0 A..H. --- "C:\Documents and Settings\Ginna\Local Settings\Temp\BITF1.tmp"
Mon 4 Feb 2008 0 A..H. --- "C:\Documents and Settings\Ginna\Local Settings\Temp\BITF2.tmp"
Tue 5 Feb 2008 0 A..H. --- "C:\Documents and Settings\Ginna\Local Settings\Temp\BITF3.tmp"
Wed 6 Feb 2008 0 A..H. --- "C:\Documents and Settings\Ginna\Local Settings\Temp\BITF4.tmp"
Thu 7 Feb 2008 0 A..H. --- "C:\Documents and Settings\Ginna\Local Settings\Temp\BITF5.tmp"
Thu 7 Feb 2008 0 A..H. --- "C:\Documents and Settings\Ginna\Local Settings\Temp\BITF6.tmp"
Wed 6 Feb 2008 0 A..H. --- "C:\Documents and Settings\Ginna\Local Settings\Temp\BITF7.tmp"
Wed 6 Feb 2008 0 A..H. --- "C:\Documents and Settings\Ginna\Local Settings\Temp\BITF8.tmp"
Thu 7 Feb 2008 0 A..H. --- "C:\Documents and Settings\Ginna\Local Settings\Temp\BITF9.tmp"
Wed 6 Feb 2008 0 A..H. --- "C:\Documents and Settings\Ginna\Local Settings\Temp\BITFA.tmp"
Wed 6 Feb 2008 0 A..H. --- "C:\Documents and Settings\Ginna\Local Settings\Temp\BITFB.tmp"
Thu 7 Feb 2008 0 A..H. --- "C:\Documents and Settings\Ginna\Local Settings\Temp\BITFC.tmp"
Wed 6 Feb 2008 0 A..H. --- "C:\Documents and Settings\Ginna\Local Settings\Temp\BITFD.tmp"
Thu 7 Feb 2008 0 A..H. --- "C:\Documents and Settings\Ginna\Local Settings\Temp\BITFE.tmp"
Wed 6 Feb 2008 0 A..H. --- "C:\Documents and Settings\Ginna\Local Settings\Temp\BITFF.tmp"
Wed 23 Jan 2008 0 A..H. --- "C:\WINDOWS\SoftwareDistribution\Download\f7db876e78b88fd8276fd7d29cb7e4eb\BIT7.tmp"
Thu 25 Oct 2001 106,496 A..H. --- "C:\Program Files\Common Files\aolshare\shell\us\shellext.dll"
Mon 11 Feb 2008 23,580 A..H. --- "C:\Documents and Settings\Ginna\Local Settings\Temporary Internet Files\Content.IE5\0JFYTHS8\PFT510.tmp"
Sun 13 May 2007 8 A..H. --- "C:\Documents and Settings\Elizabeth\Application Data\Gtek\GTUpdate\AUpdate\Channels\ch_u1\lock.tmp"
Tue 26 Jun 2007 8 A..H. --- "C:\Documents and Settings\Elizabeth\Application Data\Gtek\GTUpdate\AUpdate\Channels\ch_u2\lock.tmp"
Tue 26 Jun 2007 8 A..H. --- "C:\Documents and Settings\Elizabeth\Application Data\Gtek\GTUpdate\AUpdate\Channels\ch_u3\lock.tmp"
Tue 26 Jun 2007 8 A..H. --- "C:\Documents and Settings\Elizabeth\Application Data\Gtek\GTUpdate\AUpdate\Channels\ch_u4\lock.tmp"
Sun 23 Sep 2007 8 A..H. --- "C:\Documents and Settings\Ginna\Application Data\GTek\GTUpdate\AUpdate\Channels\ch_u1\lock.tmp"
Sun 23 Sep 2007 8 A..H. --- "C:\Documents and Settings\Ginna\Application Data\GTek\GTUpdate\AUpdate\Channels\ch_u2\lock.tmp"
Sun 21 Oct 2007 8 A..H. --- "C:\Documents and Settings\Leslie\Application Data\GTek\GTUpdate\AUpdate\Channels\ch_u1\lock.tmp"
Sun 21 Oct 2007 8 A..H. --- "C:\Documents and Settings\Leslie\Application Data\GTek\GTUpdate\AUpdate\Channels\ch_u2\lock.tmp"
Sun 21 Oct 2007 8 A..H. --- "C:\Documents and Settings\Leslie\Application Data\GTek\GTUpdate\AUpdate\Channels\ch_u3\lock.tmp"
Sun 21 Oct 2007 8 A..H. --- "C:\Documents and Settings\Leslie\Application Data\GTek\GTUpdate\AUpdate\Channels\ch_u4\lock.tmp"

Finished!


HijackThis file:

Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 6:36:52 PM, on 2/16/2008
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16608)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Lavasoft\Ad-Aware 2007\aawservice.exe
C:\WINDOWS\system32\LEXBCES.EXE
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\system32\LEXPPS.EXE
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Common Files\McAfee\HackerWatch\HWAPI.exe
C:\PROGRA~1\McAfee\MSC\mcmscsvc.exe
c:\program files\common files\mcafee\mna\mcnasvc.exe
C:\PROGRA~1\McAfee\VIRUSS~1\mcods.exe
C:\PROGRA~1\McAfee\MSC\mcpromgr.exe
c:\PROGRA~1\COMMON~1\mcafee\mcproxy\mcproxy.exe
c:\PROGRA~1\COMMON~1\mcafee\redirsvc\redirsvc.exe
C:\PROGRA~1\McAfee\VIRUSS~1\mcshield.exe
C:\PROGRA~1\McAfee\VIRUSS~1\mcsysmon.exe
C:\Program Files\McAfee\MPF\MPFSrv.exe
C:\PROGRA~1\McAfee\MPS\mps.exe
C:\WINDOWS\System32\nvsvc32.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\wanmpsvc.exe
C:\Program Files\McAfee\MPS\mpsevh.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\notepad.exe
C:\WINDOWS\System32\DSentry.exe
C:\Program Files\Roxio\Easy CD Creator 5\DirectCD\DirectCD.exe
C:\Program Files\ESPNRunTime\DIGServices.exe
C:\Program Files\Common Files\Real\Update_OB\realsched.exe
C:\Program Files\Musicmatch\Musicmatch Jukebox\mm_tray.exe
C:\Program Files\Winamp\winampa.exe
C:\Program Files\Musicmatch\Musicmatch Jukebox\mm_server.exe
C:\Program Files\HP\HP Software Update\HPWuSchd2.exe
C:\Program Files\Java\jre1.6.0_03\bin\jusched.exe
C:\PROGRA~1\DELLMO~1\MOH.exe
C:\PROGRA~1\MUSICM~1\MUSICM~1\MMDiag.exe
C:\Program Files\MSN Messenger\MsnMsgr.Exe
C:\Program Files\Dilberttest3\Screen Saver\FWLink.exe
C:\WINDOWS\system32\ctfmon.exe
c:\PROGRA~1\mcafee.com\agent\mcagent.exe
C:\Program Files\MUSICMATCH\MUSICMATCH Jukebox\mim.exe
C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
C:\Program Files\Digital Line Detect\DLG.exe
C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe
C:\Program Files\Kodak\pictures\Kodak EasyShare software\bin\EasyShare.exe
C:\Program Files\HP\Digital Imaging\bin\hpqSTE08.exe
C:\Program Files\internet explorer\iexplore.exe
C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLLoginProxy.exe
C:\Program Files\Yahoo!\Messenger\ymsgr_tray.exe
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://cm.my.yahoo.com/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar = http://red.clientapps.yahoo.com/customize/...rch/search.html
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyServer = :0
O2 - BHO: (no name) - {02478D38-C3F9-4efb-9B51-7695ECA05670} - (no file)
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 5.0\Reader\ActiveX\AcroIEHelper.ocx
O2 - BHO: REALBAR - {4E7BD74F-2B8D-469E-C0FF-FD60B590A87D} - C:\PROGRA~1\COMMON~1\Real\Toolbar\realbar.dll
O2 - BHO: Spybot-S&D IE Protection - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O2 - BHO: (no name) - {65D886A2-7CA7-479B-BB95-14D1EFB7946A} - (no file)
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll
O2 - BHO: scriptproxy - {7DB2D5A0-7241-4E79-B68D-6309F01C5231} - c:\PROGRA~1\mcafee\VIRUSS~1\scriptcl.dll
O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - (no file)
O2 - BHO: Windows Live Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
O2 - BHO: ST - {9394EDE7-C8B5-483E-8773-474BF36AF6E4} - C:\Program Files\MSN Apps\ST\01.02.0002.1001\en-xu\stmain.dll
O2 - BHO: (no name) - {9b99c7d1-0617-40d5-8007-48aef252ba69} - (no file)
O2 - BHO: MSNToolBandBHO - {BDBD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\Program Files\MSN Apps\MSN Toolbar\01.02.2001.0001\en-us\msntb.dll
O3 - Toolbar: REALBAR - {4E7BD74F-2B8D-469E-C0FF-FD60B590A87D} - C:\PROGRA~1\COMMON~1\Real\Toolbar\realbar.dll
O3 - Toolbar: MSN - {BDAD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\Program Files\MSN Apps\MSN Toolbar\01.02.2001.0001\en-us\msntb.dll
O3 - Toolbar: &ESPN - {AE6F2894-AF10-4C9C-B16E-1DFC6FF8C0C6} - C:\Program Files\ESPN\Toolbar\DIGToolBar.dll
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\System32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [DVDSentry] C:\WINDOWS\System32\DSentry.exe
O4 - HKLM\..\Run: [AdaptecDirectCD] "C:\Program Files\Roxio\Easy CD Creator 5\DirectCD\DirectCD.exe"
O4 - HKLM\..\Run: [nwiz] nwiz.exe /install
O4 - HKLM\..\Run: [DIGServices] C:\Program Files\ESPNRunTime\DIGServices.exe /brand=ESPN /priority=0 /poll=24
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
O4 - HKLM\..\Run: [MimBoot] C:\PROGRA~1\MUSICM~1\MUSICM~1\mimboot.exe
O4 - HKLM\..\Run: [MMTray] "C:\Program Files\Musicmatch\Musicmatch Jukebox\mm_tray.exe"
O4 - HKLM\..\Run: [WinampAgent] C:\Program Files\Winamp\winampa.exe
O4 - HKLM\..\Run: [mm_server] "C:\Program Files\Musicmatch\Musicmatch Jukebox\mm_server.exe"
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [HP Software Update] C:\Program Files\HP\HP Software Update\HPWuSchd2.exe
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_03\bin\jusched.exe"
O4 - HKCU\..\Run: [ModemOnHold] C:\PROGRA~1\DELLMO~1\MOH.exe
O4 - HKCU\..\Run: [MsnMsgr] "C:\Program Files\MSN Messenger\MsnMsgr.Exe" /background
O4 - HKCU\..\Run: [Dilberttest3 web link] "C:\Program Files\Dilberttest3\Screen Saver\FWLink.exe"
O4 - HKCU\..\Run: [Yahoo! Pager] "C:\Program Files\Yahoo!\Messenger\YahooMessenger.exe" -quiet
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [SpybotSD TeaTimer] C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
O4 - HKUS\S-1-5-18\..\Run: [Yahoo! Pager] "C:\PROGRA~1\Yahoo!\MESSEN~1\YAHOOM~1.EXE" -quiet (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [Yahoo! Pager] "C:\PROGRA~1\Yahoo!\MESSEN~1\YAHOOM~1.EXE" -quiet (User 'Default user')
O4 - Global Startup: Digital Line Detect.lnk = ?
O4 - Global Startup: HP Digital Imaging Monitor.lnk = C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe
O4 - Global Startup: Kodak EasyShare software.lnk = C:\Program Files\Kodak\pictures\Kodak EasyShare software\bin\EasyShare.exe
O8 - Extra context menu item: &Search - http://bar.mywebsearch.com/menusearch.html?p=ZSzeb001
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll
O9 - Extra button: (no name) - {85d1f590-48f4-11d9-9669-0800200c9a66} - C:\WINDOWS\bdoscandel.exe
O9 - Extra 'Tools' menuitem: Uninstall BitDefender Online Scanner v8 - {85d1f590-48f4-11d9-9669-0800200c9a66} - C:\WINDOWS\bdoscandel.exe
O9 - Extra button: (no name) - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - (no file)
O9 - Extra button: (no name) - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O9 - Extra 'Tools' menuitem: Spybot - Search & Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O12 - Plugin for .spop: C:\Program Files\Internet Explorer\Plugins\NPDocBox.dll
O16 - DPF: {1D6711C8-7154-40BB-8380-3DEA45B69CBF} -
O16 - DPF: {56336BCB-3D8A-11D6-A00B-0050DA18DE71} - http://207.188.7.150/20a8d6fcbe9db50a3317/...ip/RdxIE601.cab
O16 - DPF: {5D86DDB5-BDF9-441B-9E9E-D4730F4EE499} (BDSCANONLINE Control) - http://download.bitdefender.com/resources/scan8/oscan8.cab
O16 - DPF: {77E32299-629F-43C6-AB77-6A1E6D7663F6} (Groove Control) - http://www.nick.com/common/groove/gx/GrooveAX27.cab
O16 - DPF: {9AA73F41-EC64-489E-9A73-9CD52E528BC4} (ZoneAxRcMgr Class) - http://zone.msn.com/binGame/ZAxRcMgr.cab
O16 - DPF: {B8BE5E93-A60C-4D26-A2DC-220313175592} (MSN Games - Installer) - http://cdn2.zone.msn.com/binFramework/v10/...ro.cab56649.cab
O16 - DPF: {E598AC61-4C6F-4F4D-877F-FAC49CA91FA3} (acpRunner Class) - https://www-3.ibm.com/pc/support/access/asl.../AcpControl.cab
O23 - Service: Ad-Aware 2007 Service (aawservice) - Lavasoft - C:\Program Files\Lavasoft\Ad-Aware 2007\aawservice.exe
O23 - Service: DSBrokerService - Unknown owner - C:\Program Files\DellSupport\brkrsvc.exe
O23 - Service: McAfee E-mail Proxy (Emproxy) - McAfee, Inc. - C:\PROGRA~1\COMMON~1\McAfee\EmProxy\emproxy.exe
O23 - Service: Kodak Camera Connection Software (KodakCCS) - Eastman Kodak Company - C:\WINDOWS\system32\drivers\KodakCCS.exe
O23 - Service: LexBce Server (LexBceS) - Lexmark International, Inc. - C:\WINDOWS\system32\LEXBCES.EXE
O23 - Service: McAfee HackerWatch Service - McAfee, Inc. - C:\Program Files\Common Files\McAfee\HackerWatch\HWAPI.exe
O23 - Service: McAfee Update Manager (mcmispupdmgr) - McAfee, Inc. - C:\PROGRA~1\McAfee\MSC\mcupdmgr.exe
O23 - Service: McAfee Services (mcmscsvc) - McAfee, Inc. - C:\PROGRA~1\McAfee\MSC\mcmscsvc.exe
O23 - Service: McAfee Network Agent (McNASvc) - McAfee, Inc. - c:\program files\common files\mcafee\mna\mcnasvc.exe
O23 - Service: McAfee Scanner (McODS) - McAfee, Inc. - C:\PROGRA~1\McAfee\VIRUSS~1\mcods.exe
O23 - Service: McAfee Protection Manager (mcpromgr) - McAfee, Inc. - C:\PROGRA~1\McAfee\MSC\mcpromgr.exe
O23 - Service: McAfee Proxy Service (McProxy) - McAfee, Inc. - c:\PROGRA~1\COMMON~1\mcafee\mcproxy\mcproxy.exe
O23 - Service: McAfee Redirector Service (McRedirector) - McAfee, Inc. - c:\PROGRA~1\COMMON~1\mcafee\redirsvc\redirsvc.exe
O23 - Service: McAfee Real-time Scanner (McShield) - McAfee, Inc. - C:\PROGRA~1\McAfee\VIRUSS~1\mcshield.exe
O23 - Service: McAfee SystemGuards (McSysmon) - McAfee, Inc. - C:\PROGRA~1\McAfee\VIRUSS~1\mcsysmon.exe
O23 - Service: McAfee Personal Firewall Service (MpfService) - McAfee, Inc. - C:\Program Files\McAfee\MPF\MPFSrv.exe
O23 - Service: McAfee Privacy Service (MPS9) - McAfee, Inc. - C:\PROGRA~1\McAfee\MPS\mps.exe
O23 - Service: Intel® NMS (NMSSvc) - Intel Corporation - C:\WINDOWS\System32\NMSSvc.exe
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\System32\nvsvc32.exe
O23 - Service: WAN Miniport (ATW) Service (WANMiniportService) - America Online, Inc. - C:\WINDOWS\wanmpsvc.exe

--
End of file - 11333 bytes

#5 chryssi2001

chryssi2001

  • Members
  • 1,930 posts
  • OFFLINE
  •  
  • Local time:02:08 PM

Posted 17 February 2008 - 05:59 AM

Hello Penguin73,

Go to Start-Settings-Control Panel, click on Add remove Programs. If any of the following programs are listed there, click on the program to highlight it, and click on remove. Then close the Control Panel.
Dilberttest3
---------------------------------------------------
Disable Spybot's TeaTimer. This is a two step process.

Spybot S&D's tea timer normally provides real-time protection from spyware, however it may interfere with what we need to do. We will disable it until the machine is clean when it can be re-enabled.

First step:
  • Right-click the Spybot Icon in the System Tray (looks like a blue/white calendar with a padlock symbol)
  • If you have the new version 1.5, Click once on Resident Protection, then Right click the Spybot icon again and make sure Resident Protection is now Unchecked. The Spybot icon in the System tray should now be now colorless.
  • If you have Version 1.4, Click on Exit Spybot S&D Resident
Second step, For Either Version :
  • Open Spybot S&D
  • Click Mode, choose Advanced Mode
  • Go To the bottom of the Vertical Panel on the Left, Click Tools
  • then, also in left panel, click Resident shows a red/white shield.
  • If your firewall raises a question, say OK
  • In the Resident protection status frame, Uncheck the box labeled Resident "Tea-Timer"(Protection of over-all system settings) active
  • OK any prompts.
  • Use File, Exit to terminate Spybot
  • Reboot your machine for the changes to take effect.
Don't forget to re-enable it, when your computer is clean.
---------------------------------------------------
FIX HIJACKTHIS ENTRIES

Open up Hijackthis.
Click on do a system scan only.
Place a checkmark next to these lines(if still present).

R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar = http://red.clientapps.yahoo.com/customize/...rch/search.html
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyServer = :0
O2 - BHO: (no name) - {02478D38-C3F9-4efb-9B51-7695ECA05670} - (no file)
O2 - BHO: (no name) - {65D886A2-7CA7-479B-BB95-14D1EFB7946A} - (no file)
O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - (no file)
O2 - BHO: (no name) - {9b99c7d1-0617-40d5-8007-48aef252ba69} - (no file)
O4 - HKCU\..\Run: [Dilberttest3 web link] "C:\Program Files\Dilberttest3\Screen Saver\FWLink.exe"
O8 - Extra context menu item: &Search - http://bar.mywebsearch.com/menusearch.html?p=ZSzeb001
O9 - Extra button: (no name) - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - (no file)
O16 - DPF: {1D6711C8-7154-40BB-8380-3DEA45B69CBF} -
O16 - DPF: {56336BCB-3D8A-11D6-A00B-0050DA18DE71} - http://207.188.7.150/20a8d6fcbe9db50a3317/...ip/RdxIE601.cab


Then close all windows except Hijackthis and click Fix Checked
Close HijackThis.
---------------------------------------------------
Please download the OTMoveIt2 by OldTimer and Save it to your Desktop.
  • Please double-click OTMoveIt2.exe to run it. (Note: If you are running on Vista, right-click on the file and choose Run As Administrator).
  • Copy the lines in the codebox below to the clipboard by highlighting ALL of them and pressing CTRL + C (or, after highlighting, right-click and choose Copy):

    C:\Program Files\Dilberttest3
    C:\Program Files\Viewpoint
  • Return to OTMoveIt2, right click in the "Paste Standard List of Files/Folders to Move" window (under the light blue bar) and choose Paste.
  • Click the red Moveit! button.
  • Copy everything in the Results window (under the green bar) to the clipboard by highlighting ALL of them and pressing CTRL + C (or, after highlighting, right-click and choose copy), and paste it in your next reply.
  • Close OTMoveIt2
Note: If a file or folder cannot be moved immediately you may be asked to reboot the machine to finish the move process. If you are asked to reboot the machine choose Yes. In this case, after the reboot, open Notepad (Start->All Programs->Accessories->Notepad), click File->Open, in the File Name box enter *.log and press the Enter key, navigate to the C:\_OTMoveIt\MovedFiles folder, and open the newest .log file present, and copy/paste the contents of that document back here in your next post.
---------------------------------------------------
Please download ATF cleaner
Make sure that all browser windows are closed.Double-click ATF-Cleaner.exe to run the program.
Under Main choose: Select All
Click the Empty Selected button.
If you use Firefox browserClick Firefox at the top and choose: Select All
Click the Empty Selected button.
NOTE: If you would like to keep your saved passwords, please click No at the prompt.
If you use Opera browserClick Opera at the top and choose: Select All
Click the Empty Selected button.
NOTE: If you would like to keep your saved passwords, please click No at the prompt.
Click Exit on the Main menu to close the program.
---------------------------------------------------
Download and Install SuperAntiSpyware Free
  • Launch SuperAntiSpyware
  • Click Check for Updates and update to the latest definitions.
  • Click Scan your Computer
    • Check all boxes in the Scan Location box.
    • Check the Complete Scan radio button.
    • Click Scanning Preferences/Control Centre button.
      • Uncheck Ignore files larger than 4MB (recommended)
      • Check Scan Alternate Data Streams.
      • Click Close.
    • Click Next
  • SuperAntiSpyware will now scan your computer for infection. (This could take in excess of an hour depending on the number of files scanned)
  • When finished it will present you with a summary of its findings.
  • Click OK.
  • The Removal Screen will open.
    • Check the items in the list to mark them for Quarantine.
    • Click Next and SAS will Quarantine them.
Please send me the log.
  • Click the Preferences button.
    • Click the Statistics/Logs tab.
    • Logs are listed by date and time, click on the latest one to highlight it (at the top).
    • Click View log.
  • This will open a log page.
  • Copy/Paste the contents in your next post please.
CAUTION: SuperAntiSpyware comes with a programme called Bootsafe, do not for any reason use this programme, if used on an infected computer it could render it UNBOOTABLE.
---------------------------------------------------
Post back:
OTMoveIt2 report.
SuperAntiSpyware report.
A new Hijackthis log.
Posted Image
Private Messages for personal support will be ignored. If you need help post in the forum.

#6 Penguin73

Penguin73
  • Topic Starter

  • Members
  • 19 posts
  • OFFLINE
  •  
  • Local time:06:08 AM

Posted 17 February 2008 - 10:15 PM

Ok...here goes:

C:\Program Files\Dilberttest3\Screen Saver moved successfully.
C:\Program Files\Dilberttest3 moved successfully.
C:\Program Files\Viewpoint\Common moved successfully.
C:\Program Files\Viewpoint moved successfully.

OTMoveIt2 v1.0.20 log created on 02172008_174142

SUPERAntiSpyware Scan Log
http://www.superantispyware.com

Generated 02/17/2008 at 09:39 PM

Application Version : 3.9.1008

Core Rules Database Version : 3404
Trace Rules Database Version: 1396

Scan type : Complete Scan
Total Scan Time : 03:40:38

Memory items scanned : 744
Memory threats detected : 0
Registry items scanned : 6334
Registry threats detected : 0
File items scanned : 115905
File threats detected : 2

Adware.WhenU
C:\Program Files\Save

Adware.eXact Advertising
C:\PROGRAM FILES\MAIL.COM\MCALERT.EXE



Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 10:14:04 PM, on 2/17/2008
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16608)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Lavasoft\Ad-Aware 2007\aawservice.exe
C:\WINDOWS\system32\LEXBCES.EXE
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\system32\LEXPPS.EXE
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\System32\DSentry.exe
C:\Program Files\Roxio\Easy CD Creator 5\DirectCD\DirectCD.exe
C:\Program Files\ESPNRunTime\DIGServices.exe
C:\Program Files\Common Files\Real\Update_OB\realsched.exe
C:\Program Files\Musicmatch\Musicmatch Jukebox\mm_tray.exe
C:\Program Files\Winamp\winampa.exe
C:\Program Files\Musicmatch\Musicmatch Jukebox\mm_server.exe
C:\Program Files\HP\HP Software Update\HPWuSchd2.exe
C:\Program Files\Java\jre1.6.0_03\bin\jusched.exe
C:\WINDOWS\system32\svchost.exe
C:\PROGRA~1\DELLMO~1\MOH.exe
C:\Program Files\Common Files\McAfee\HackerWatch\HWAPI.exe
C:\Program Files\MSN Messenger\MsnMsgr.Exe
C:\PROGRA~1\MUSICM~1\MUSICM~1\MMDiag.exe
C:\PROGRA~1\McAfee\MSC\mcmscsvc.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe
C:\Program Files\Digital Line Detect\DLG.exe
c:\program files\common files\mcafee\mna\mcnasvc.exe
C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe
C:\Program Files\MUSICMATCH\MUSICMATCH Jukebox\mim.exe
C:\Program Files\Kodak\pictures\Kodak EasyShare software\bin\EasyShare.exe
C:\PROGRA~1\McAfee\VIRUSS~1\mcods.exe
C:\PROGRA~1\McAfee\MSC\mcpromgr.exe
c:\PROGRA~1\COMMON~1\mcafee\mcproxy\mcproxy.exe
c:\PROGRA~1\COMMON~1\mcafee\redirsvc\redirsvc.exe
C:\PROGRA~1\McAfee\VIRUSS~1\mcshield.exe
c:\PROGRA~1\mcafee.com\agent\mcagent.exe
C:\PROGRA~1\McAfee\VIRUSS~1\mcsysmon.exe
C:\Program Files\McAfee\MPF\MPFSrv.exe
C:\PROGRA~1\McAfee\MPS\mps.exe
C:\WINDOWS\System32\nvsvc32.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\wanmpsvc.exe
C:\Program Files\McAfee\MPS\mpsevh.exe
C:\Program Files\HP\Digital Imaging\bin\hpqSTE08.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Yahoo!\Messenger\ymsgr_tray.exe
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://cm.my.yahoo.com/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyServer = :0
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 5.0\Reader\ActiveX\AcroIEHelper.ocx
O2 - BHO: REALBAR - {4E7BD74F-2B8D-469E-C0FF-FD60B590A87D} - C:\PROGRA~1\COMMON~1\Real\Toolbar\realbar.dll
O2 - BHO: Spybot-S&D IE Protection - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll
O2 - BHO: scriptproxy - {7DB2D5A0-7241-4E79-B68D-6309F01C5231} - c:\PROGRA~1\mcafee\VIRUSS~1\scriptcl.dll
O2 - BHO: Windows Live Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
O2 - BHO: ST - {9394EDE7-C8B5-483E-8773-474BF36AF6E4} - C:\Program Files\MSN Apps\ST\01.02.0002.1001\en-xu\stmain.dll
O2 - BHO: MSNToolBandBHO - {BDBD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\Program Files\MSN Apps\MSN Toolbar\01.02.2001.0001\en-us\msntb.dll
O3 - Toolbar: REALBAR - {4E7BD74F-2B8D-469E-C0FF-FD60B590A87D} - C:\PROGRA~1\COMMON~1\Real\Toolbar\realbar.dll
O3 - Toolbar: MSN - {BDAD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\Program Files\MSN Apps\MSN Toolbar\01.02.2001.0001\en-us\msntb.dll
O3 - Toolbar: &ESPN - {AE6F2894-AF10-4C9C-B16E-1DFC6FF8C0C6} - C:\Program Files\ESPN\Toolbar\DIGToolBar.dll
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\System32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [DVDSentry] C:\WINDOWS\System32\DSentry.exe
O4 - HKLM\..\Run: [AdaptecDirectCD] "C:\Program Files\Roxio\Easy CD Creator 5\DirectCD\DirectCD.exe"
O4 - HKLM\..\Run: [nwiz] nwiz.exe /install
O4 - HKLM\..\Run: [DIGServices] C:\Program Files\ESPNRunTime\DIGServices.exe /brand=ESPN /priority=0 /poll=24
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
O4 - HKLM\..\Run: [MimBoot] C:\PROGRA~1\MUSICM~1\MUSICM~1\mimboot.exe
O4 - HKLM\..\Run: [MMTray] "C:\Program Files\Musicmatch\Musicmatch Jukebox\mm_tray.exe"
O4 - HKLM\..\Run: [WinampAgent] C:\Program Files\Winamp\winampa.exe
O4 - HKLM\..\Run: [mm_server] "C:\Program Files\Musicmatch\Musicmatch Jukebox\mm_server.exe"
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [HP Software Update] C:\Program Files\HP\HP Software Update\HPWuSchd2.exe
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_03\bin\jusched.exe"
O4 - HKCU\..\Run: [ModemOnHold] C:\PROGRA~1\DELLMO~1\MOH.exe
O4 - HKCU\..\Run: [MsnMsgr] "C:\Program Files\MSN Messenger\MsnMsgr.Exe" /background
O4 - HKCU\..\Run: [Yahoo! Pager] "C:\Program Files\Yahoo!\Messenger\YahooMessenger.exe" -quiet
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [SUPERAntiSpyware] C:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe
O4 - HKUS\S-1-5-18\..\Run: [Yahoo! Pager] "C:\PROGRA~1\Yahoo!\MESSEN~1\YAHOOM~1.EXE" -quiet (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [Yahoo! Pager] "C:\PROGRA~1\Yahoo!\MESSEN~1\YAHOOM~1.EXE" -quiet (User 'Default user')
O4 - Global Startup: Digital Line Detect.lnk = ?
O4 - Global Startup: HP Digital Imaging Monitor.lnk = C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe
O4 - Global Startup: Kodak EasyShare software.lnk = C:\Program Files\Kodak\pictures\Kodak EasyShare software\bin\EasyShare.exe
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll
O9 - Extra button: (no name) - {85d1f590-48f4-11d9-9669-0800200c9a66} - C:\WINDOWS\bdoscandel.exe
O9 - Extra 'Tools' menuitem: Uninstall BitDefender Online Scanner v8 - {85d1f590-48f4-11d9-9669-0800200c9a66} - C:\WINDOWS\bdoscandel.exe
O9 - Extra button: (no name) - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O9 - Extra 'Tools' menuitem: Spybot - Search & Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O12 - Plugin for .spop: C:\Program Files\Internet Explorer\Plugins\NPDocBox.dll
O16 - DPF: {5D86DDB5-BDF9-441B-9E9E-D4730F4EE499} (BDSCANONLINE Control) - http://download.bitdefender.com/resources/scan8/oscan8.cab
O16 - DPF: {77E32299-629F-43C6-AB77-6A1E6D7663F6} (Groove Control) - http://www.nick.com/common/groove/gx/GrooveAX27.cab
O16 - DPF: {9AA73F41-EC64-489E-9A73-9CD52E528BC4} (ZoneAxRcMgr Class) - http://zone.msn.com/binGame/ZAxRcMgr.cab
O16 - DPF: {B8BE5E93-A60C-4D26-A2DC-220313175592} (MSN Games - Installer) - http://cdn2.zone.msn.com/binFramework/v10/...ro.cab56649.cab
O16 - DPF: {E598AC61-4C6F-4F4D-877F-FAC49CA91FA3} (acpRunner Class) - https://www-3.ibm.com/pc/support/access/asl.../AcpControl.cab
O20 - Winlogon Notify: !SASWinLogon - C:\Program Files\SUPERAntiSpyware\SASWINLO.dll
O23 - Service: Ad-Aware 2007 Service (aawservice) - Lavasoft - C:\Program Files\Lavasoft\Ad-Aware 2007\aawservice.exe
O23 - Service: DSBrokerService - Unknown owner - C:\Program Files\DellSupport\brkrsvc.exe
O23 - Service: McAfee E-mail Proxy (Emproxy) - McAfee, Inc. - C:\PROGRA~1\COMMON~1\McAfee\EmProxy\emproxy.exe
O23 - Service: Kodak Camera Connection Software (KodakCCS) - Eastman Kodak Company - C:\WINDOWS\system32\drivers\KodakCCS.exe
O23 - Service: LexBce Server (LexBceS) - Lexmark International, Inc. - C:\WINDOWS\system32\LEXBCES.EXE
O23 - Service: McAfee HackerWatch Service - McAfee, Inc. - C:\Program Files\Common Files\McAfee\HackerWatch\HWAPI.exe
O23 - Service: McAfee Update Manager (mcmispupdmgr) - McAfee, Inc. - C:\PROGRA~1\McAfee\MSC\mcupdmgr.exe
O23 - Service: McAfee Services (mcmscsvc) - McAfee, Inc. - C:\PROGRA~1\McAfee\MSC\mcmscsvc.exe
O23 - Service: McAfee Network Agent (McNASvc) - McAfee, Inc. - c:\program files\common files\mcafee\mna\mcnasvc.exe
O23 - Service: McAfee Scanner (McODS) - McAfee, Inc. - C:\PROGRA~1\McAfee\VIRUSS~1\mcods.exe
O23 - Service: McAfee Protection Manager (mcpromgr) - McAfee, Inc. - C:\PROGRA~1\McAfee\MSC\mcpromgr.exe
O23 - Service: McAfee Proxy Service (McProxy) - McAfee, Inc. - c:\PROGRA~1\COMMON~1\mcafee\mcproxy\mcproxy.exe
O23 - Service: McAfee Redirector Service (McRedirector) - McAfee, Inc. - c:\PROGRA~1\COMMON~1\mcafee\redirsvc\redirsvc.exe
O23 - Service: McAfee Real-time Scanner (McShield) - McAfee, Inc. - C:\PROGRA~1\McAfee\VIRUSS~1\mcshield.exe
O23 - Service: McAfee SystemGuards (McSysmon) - McAfee, Inc. - C:\PROGRA~1\McAfee\VIRUSS~1\mcsysmon.exe
O23 - Service: McAfee Personal Firewall Service (MpfService) - McAfee, Inc. - C:\Program Files\McAfee\MPF\MPFSrv.exe
O23 - Service: McAfee Privacy Service (MPS9) - McAfee, Inc. - C:\PROGRA~1\McAfee\MPS\mps.exe
O23 - Service: Intel® NMS (NMSSvc) - Intel Corporation - C:\WINDOWS\System32\NMSSvc.exe
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\System32\nvsvc32.exe
O23 - Service: WAN Miniport (ATW) Service (WANMiniportService) - America Online, Inc. - C:\WINDOWS\wanmpsvc.exe

--
End of file - 10286 bytes

#7 chryssi2001

chryssi2001

  • Members
  • 1,930 posts
  • OFFLINE
  •  
  • Local time:02:08 PM

Posted 18 February 2008 - 07:18 AM

Hello Penguin73,

Disable SUPERAntiSpyware until the computer is clean
  • Right-click on the shortcut from the system tray
  • Choose View Control Center (preferences/options)
  • On the General and Startup tab, uncheck Start SUPERAntispyware when Windows starts.
  • Click Close to exit.
Don't forget to re-enable it, when your computer is clean.
------------------------------------------------
FIX HIJACKTHIS ENTRIES

Open up Hijackthis.
Click on do a system scan only.
Place a checkmark next to these lines(if still present).

R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyServer = :0


Then close all windows except Hijackthis and click Fix Checked
------------------------------------------------
LIST OF PROGRAMS USING HIJACKTHIS
  • Now click on Open the Misc Tools section.
  • Look under System tools.
  • Click on the Open Uninstall Manager... button.
  • Click on the Save list... button.
  • It will prompt you to save. Save this log in a convenient location. By default it's named uninstall_list.txt.
  • Notepad will open. Please copy and paste the contents of this log in your next reply.
See in this link details.
http://img.bleepingcomputer.com/tutorials/...install-man.jpg
------------------------------------------------
Update Java Runtime:

You are using an old version of Java. Sun's Java is sometimes updated in order to eliminate the exploitation of vulnerabilities in an existing version. For this reason, it's extremely important that you keep the program up to date, and also remove the older more vulnerable versions from your system. The most current version of Sun Java is: Java Runtime Environment Version 6 Update 4.
  • Go to http://java.sun.com/javase/downloads/index.jsp
  • Go to Java Runtime Environment (JRE) 6 Update 4 and click on Download button.
  • In Platform box choose Windows.
  • Check the box to Accept License Agreement and click Continue.
  • Click on Windows Offline Installation, click on the link under it which says "jre-6u4-windows-i586-p.exe" and save the downloaded file to your desktop.
  • Go to Start => Control Panel => Add or Remove Programs
  • Uninstall all old versions of Java (Java 3 Runtime Environment, JRE or JSE)
  • Reboot your computer
  • Delete the folder C:\Program Files\Java if present
  • Install the new version by running the newly-downloaded file with the java icon which will be at your desktop, and follow the on-screen instructions.
  • Reboot your computer
------------------------------------------------
Post back:
Programs list
A new HijackThis log.
Posted Image
Private Messages for personal support will be ignored. If you need help post in the forum.

#8 Penguin73

Penguin73
  • Topic Starter

  • Members
  • 19 posts
  • OFFLINE
  •  
  • Local time:06:08 AM

Posted 18 February 2008 - 10:24 PM

Programs List:


3D Groove Playback Engine
7 Wonders
7 Wonders II
Action Replay Code Manager
Ad-Aware 2007
Adobe Acrobat 5.0
Adobe Flash Player 9 ActiveX
Adobe Flash Player ActiveX
Adobe Shockwave Player
America Online
ArcSoft Camera Suite
BCM V.92 56K Modem
Bicycle Board Games 2.0
Big Fish Games Client
Bookworm Deluxe 1.03
Buildalot
CCScore
Civilization III Complete Edition
Classic PhoneTools
Concord EyeQ Duo 2000 Digital Camera
Concord EyeQ Duo 2000 Memory Browser TWAIN Driver V1.00
Dell Digital Jukebox Driver
Dell Modem-On-Hold
Dell Picture Studio - Dell Image Expert
Dell ResourceCD
Dell Solution Center
DellSupport
Diablo II
Digital Line Detect
Diner Dash 2 Free Trial
Diner Dash Flo on the Go (remove only)
Diner Dash Hometown Hero
Dr. Seuss™ Kindergarten
DVDSentry
Easy CD Creator 5 Basic
Edmark - FrippleTown (Remove only)
ESPN RunTime
ESSCDBK
ESScore
ESSgui
ESShelp
ESSini
ESSPCD
ESSSONIC
ESSTOOLS
ESSvpaht
ESSvpot
Graphic Converter 2003
Hello Kitty Cutie World
Hidden Relics
HijackThis 2.0.2
HLPIndex
HLPRFO
Homeschool Tracker Basic
Hotfix for Windows XP (KB915865)
Hoyle Board Games 5
Hoyle Word Games 3
HP Customer Participation Program 8.0
HP Deskjet 8.0 Software
HP Imaging Device Functions 8.0
HP Photosmart Essential
HP Solution Center 8.0
HP Update
HPSSupply
Indeo® Software
Intel® PRO Ethernet Adapter and Software
Intel® PROSet II
iWin Games (remove only)
Java™ 6 Update 4
Jewel Quest (remove only)
JumpStart Advanced Kindergarten
Kazaa Media Desktop 2.1.1
Kazaa Media Desktop 2.5
Kodak EasyShare software
KSU
Lexmark Z23-Z33
Mail.com Alert
McAfee SecurityCenter
Microsoft .NET Framework (English)
Microsoft .NET Framework (English) v1.0.3705
Microsoft .NET Framework 2.0
Microsoft Data Access Components KB870669
Microsoft Internationalized Domain Names Mitigation APIs
Microsoft National Language Support Downlevel APIs
Microsoft Text-to-Speech Engine 4.0 (English)
Microsoft User-Mode Driver Framework Feature Pack 1.0.0 (Pre-Release 5348)
mIRC
Modem Helper
Mplayer.com
MS Access 97 SP2
MSN Toolbar
MSXML 4.0 SP2 (KB927978)
MSXML 4.0 SP2 (KB936181)
MSXML 4.0 SP2 Parser and SDK
Musicmatch® Jukebox
NeoAudio extraction audio
Notifier
NVIDIA Display Driver
NVIDIA Windows 2000/XP Display Drivers
OTtBPSDK
Paint Shop Pro 7
PCDADDIN
PCDHELP
Peggle (remove only)
Phonics 2-3
Poker Superstars II
PowerDVD
Quicken 2002 New User Edition
QuickTime
RealPlayer
Rhapsody Player Engine
RollerCoaster Tycoon 2
Security Update for Microsoft .NET Framework 2.0 (KB928365)
Security Update for Step By Step Interactive Training (KB898458)
Security Update for Step By Step Interactive Training (KB923723)
Security Update for Windows Internet Explorer 7 (KB928090)
Security Update for Windows Internet Explorer 7 (KB929969)
Security Update for Windows Internet Explorer 7 (KB931768)
Security Update for Windows Internet Explorer 7 (KB933566)
Security Update for Windows Internet Explorer 7 (KB937143)
Security Update for Windows Internet Explorer 7 (KB938127)
Security Update for Windows Internet Explorer 7 (KB939653)
Security Update for Windows Internet Explorer 7 (KB942615)
Security Update for Windows Internet Explorer 7 (KB944533)
Security Update for Windows Media Player (KB911564)
Security Update for Windows Media Player 10 (KB917734)
Security Update for Windows Media Player 6.4 (KB925398)
Security Update for Windows XP (KB883939)
Security Update for Windows XP (KB890046)
Security Update for Windows XP (KB893756)
Security Update for Windows XP (KB896358)
Security Update for Windows XP (KB896422)
Security Update for Windows XP (KB896423)
Security Update for Windows XP (KB896424)
Security Update for Windows XP (KB896428)
Security Update for Windows XP (KB896688)
Security Update for Windows XP (KB899587)
Security Update for Windows XP (KB899588)
Security Update for Windows XP (KB899591)
Security Update for Windows XP (KB900725)
Security Update for Windows XP (KB901017)
Security Update for Windows XP (KB901190)
Security Update for Windows XP (KB901214)
Security Update for Windows XP (KB902400)
Security Update for Windows XP (KB903235)
Security Update for Windows XP (KB904706)
Security Update for Windows XP (KB905414)
Security Update for Windows XP (KB905749)
Security Update for Windows XP (KB905915)
Security Update for Windows XP (KB908519)
Security Update for Windows XP (KB908531)
Security Update for Windows XP (KB911280)
Security Update for Windows XP (KB911562)
Security Update for Windows XP (KB911567)
Security Update for Windows XP (KB911927)
Security Update for Windows XP (KB912812)
Security Update for Windows XP (KB912919)
Security Update for Windows XP (KB913446)
Security Update for Windows XP (KB913580)
Security Update for Windows XP (KB914388)
Security Update for Windows XP (KB914389)
Security Update for Windows XP (KB916281)
Security Update for Windows XP (KB917159)
Security Update for Windows XP (KB917344)
Security Update for Windows XP (KB917422)
Security Update for Windows XP (KB917953)
Security Update for Windows XP (KB918118)
Security Update for Windows XP (KB918439)
Security Update for Windows XP (KB918899)
Security Update for Windows XP (KB919007)
Security Update for Windows XP (KB920213)
Security Update for Windows XP (KB920214)
Security Update for Windows XP (KB920670)
Security Update for Windows XP (KB920683)
Security Update for Windows XP (KB920685)
Security Update for Windows XP (KB921398)
Security Update for Windows XP (KB921503)
Security Update for Windows XP (KB921883)
Security Update for Windows XP (KB922616)
Security Update for Windows XP (KB922760)
Security Update for Windows XP (KB922819)
Security Update for Windows XP (KB923191)
Security Update for Windows XP (KB923414)
Security Update for Windows XP (KB923694)
Security Update for Windows XP (KB923980)
Security Update for Windows XP (KB924191)
Security Update for Windows XP (KB924270)
Security Update for Windows XP (KB924496)
Security Update for Windows XP (KB924667)
Security Update for Windows XP (KB925486)
Security Update for Windows XP (KB925902)
Security Update for Windows XP (KB926255)
Security Update for Windows XP (KB926436)
Security Update for Windows XP (KB927779)
Security Update for Windows XP (KB927802)
Security Update for Windows XP (KB928255)
Security Update for Windows XP (KB928843)
Security Update for Windows XP (KB929123)
Security Update for Windows XP (KB930178)
Security Update for Windows XP (KB931261)
Security Update for Windows XP (KB931784)
Security Update for Windows XP (KB932168)
Security Update for Windows XP (KB933729)
Security Update for Windows XP (KB935839)
Security Update for Windows XP (KB935840)
Security Update for Windows XP (KB936021)
Security Update for Windows XP (KB938829)
Security Update for Windows XP (KB941202)
Security Update for Windows XP (KB941568)
Security Update for Windows XP (KB941644)
Security Update for Windows XP (KB943055)
Security Update for Windows XP (KB943460)
Security Update for Windows XP (KB943485)
Security Update for Windows XP (KB944653)
Security Update for Windows XP (KB946026)
SFR
Shareaza version 2.2.5.0
SHASTA
Shockwave
Shrek Screensaver
Sid Meier's Alpha Centauri 2000/XP Compatibility Update
Sid Meier's Planetary Pack
SimCity 3000 Unlimited
SKIN0001
SKINXSDK
Slingo Deluxe
Spybot - Search & Destroy
Starcraft
Subway Scramble
SUPERAntiSpyware Free Edition
The KMPlayer (remove only)
Trillian
Typing Instructor Deluxe
Update for Windows XP (KB894391)
Update for Windows XP (KB896727)
Update for Windows XP (KB898461)
Update for Windows XP (KB900485)
Update for Windows XP (KB910437)
Update for Windows XP (KB916595)
Update for Windows XP (KB920872)
Update for Windows XP (KB922582)
Update for Windows XP (KB927891)
Update for Windows XP (KB929338)
Update for Windows XP (KB930916)
Update for Windows XP (KB931836)
Update for Windows XP (KB933360)
Update for Windows XP (KB936357)
Update for Windows XP (KB938828)
Update for Windows XP (KB942763)
Virtual Villagers
Virtual Villagers 2
Visual Pinball
VPRINTOL
Winamp (remove only)
Windows Installer 3.1 (KB893803)
Windows Installer 3.1 (KB893803)
Windows Internet Explorer 7
Windows Live Messenger
Windows Live Sign-in Assistant
Windows Media Format 11 runtime
Windows Media Format 11 runtime
Windows Media Player 11
Windows Media Player 11
Windows XP Hotfix - KB834707
Windows XP Hotfix - KB867282
Windows XP Hotfix - KB873333
Windows XP Hotfix - KB873339
Windows XP Hotfix - KB885250
Windows XP Hotfix - KB885835
Windows XP Hotfix - KB885836
Windows XP Hotfix - KB886185
Windows XP Hotfix - KB887472
Windows XP Hotfix - KB887742
Windows XP Hotfix - KB888113
Windows XP Hotfix - KB888302
Windows XP Hotfix - KB890047
Windows XP Hotfix - KB890175
Windows XP Hotfix - KB890859
Windows XP Hotfix - KB890923
Windows XP Hotfix - KB891781
Windows XP Hotfix - KB893066
Windows XP Hotfix - KB893086
Windows XP Service Pack 2
Winnie the Pooh Preschool
WinRAR archiver
WIRELESS
WordBiz version 1.7
WordPerfect Office 2002
WordPerfect Office 2002
Yahoo! Address AutoComplete
Yahoo! Internet Mail
Yahoo! Messenger
Zuma Deluxe 1.0



Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 10:23:03 PM, on 2/18/2008
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16608)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Lavasoft\Ad-Aware 2007\aawservice.exe
C:\WINDOWS\system32\LEXBCES.EXE
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\system32\LEXPPS.EXE
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Common Files\McAfee\HackerWatch\HWAPI.exe
C:\PROGRA~1\McAfee\MSC\mcmscsvc.exe
c:\program files\common files\mcafee\mna\mcnasvc.exe
C:\PROGRA~1\McAfee\VIRUSS~1\mcods.exe
C:\PROGRA~1\McAfee\MSC\mcpromgr.exe
c:\PROGRA~1\COMMON~1\mcafee\mcproxy\mcproxy.exe
c:\PROGRA~1\COMMON~1\mcafee\redirsvc\redirsvc.exe
C:\PROGRA~1\McAfee\VIRUSS~1\mcshield.exe
C:\PROGRA~1\McAfee\VIRUSS~1\mcsysmon.exe
C:\Program Files\McAfee\MPF\MPFSrv.exe
C:\PROGRA~1\McAfee\MPS\mps.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\System32\nvsvc32.exe
c:\PROGRA~1\mcafee.com\agent\mcagent.exe
C:\Program Files\McAfee\MPS\mpsevh.exe
C:\WINDOWS\System32\DSentry.exe
C:\Program Files\Roxio\Easy CD Creator 5\DirectCD\DirectCD.exe
C:\Program Files\ESPNRunTime\DIGServices.exe
C:\Program Files\Common Files\Real\Update_OB\realsched.exe
C:\Program Files\Musicmatch\Musicmatch Jukebox\mm_tray.exe
C:\Program Files\Winamp\winampa.exe
C:\Program Files\Musicmatch\Musicmatch Jukebox\mm_server.exe
C:\Program Files\HP\HP Software Update\HPWuSchd2.exe
C:\Program Files\Musicmatch\Musicmatch Jukebox\MMDiag.exe
C:\Program Files\Java\jre1.6.0_04\bin\jusched.exe
C:\PROGRA~1\DELLMO~1\MOH.exe
C:\Program Files\MSN Messenger\MsnMsgr.Exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Digital Line Detect\DLG.exe
C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe
C:\Program Files\Kodak\pictures\Kodak EasyShare software\bin\EasyShare.exe
C:\Program Files\MUSICMATCH\MUSICMATCH Jukebox\mim.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\wanmpsvc.exe
C:\WINDOWS\system32\wuauclt.exe
C:\Program Files\HP\Digital Imaging\bin\hpqSTE08.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\MSN Messenger\usnsvc.exe
C:\Program Files\Yahoo!\Messenger\ymsgr_tray.exe
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://cm.my.yahoo.com/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 5.0\Reader\ActiveX\AcroIEHelper.ocx
O2 - BHO: REALBAR - {4E7BD74F-2B8D-469E-C0FF-FD60B590A87D} - C:\PROGRA~1\COMMON~1\Real\Toolbar\realbar.dll
O2 - BHO: Spybot-S&D IE Protection - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_04\bin\ssv.dll
O2 - BHO: scriptproxy - {7DB2D5A0-7241-4E79-B68D-6309F01C5231} - c:\PROGRA~1\mcafee\VIRUSS~1\scriptcl.dll
O2 - BHO: Windows Live Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
O2 - BHO: ST - {9394EDE7-C8B5-483E-8773-474BF36AF6E4} - C:\Program Files\MSN Apps\ST\01.02.0002.1001\en-xu\stmain.dll
O2 - BHO: MSNToolBandBHO - {BDBD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\Program Files\MSN Apps\MSN Toolbar\01.02.2001.0001\en-us\msntb.dll
O3 - Toolbar: REALBAR - {4E7BD74F-2B8D-469E-C0FF-FD60B590A87D} - C:\PROGRA~1\COMMON~1\Real\Toolbar\realbar.dll
O3 - Toolbar: MSN - {BDAD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\Program Files\MSN Apps\MSN Toolbar\01.02.2001.0001\en-us\msntb.dll
O3 - Toolbar: &ESPN - {AE6F2894-AF10-4C9C-B16E-1DFC6FF8C0C6} - C:\Program Files\ESPN\Toolbar\DIGToolBar.dll
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\System32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [DVDSentry] C:\WINDOWS\System32\DSentry.exe
O4 - HKLM\..\Run: [AdaptecDirectCD] "C:\Program Files\Roxio\Easy CD Creator 5\DirectCD\DirectCD.exe"
O4 - HKLM\..\Run: [nwiz] nwiz.exe /install
O4 - HKLM\..\Run: [DIGServices] C:\Program Files\ESPNRunTime\DIGServices.exe /brand=ESPN /priority=0 /poll=24
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
O4 - HKLM\..\Run: [MimBoot] C:\PROGRA~1\MUSICM~1\MUSICM~1\mimboot.exe
O4 - HKLM\..\Run: [MMTray] "C:\Program Files\Musicmatch\Musicmatch Jukebox\mm_tray.exe"
O4 - HKLM\..\Run: [WinampAgent] C:\Program Files\Winamp\winampa.exe
O4 - HKLM\..\Run: [mm_server] "C:\Program Files\Musicmatch\Musicmatch Jukebox\mm_server.exe"
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [HP Software Update] C:\Program Files\HP\HP Software Update\HPWuSchd2.exe
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_04\bin\jusched.exe"
O4 - HKCU\..\Run: [ModemOnHold] C:\PROGRA~1\DELLMO~1\MOH.exe
O4 - HKCU\..\Run: [MsnMsgr] "C:\Program Files\MSN Messenger\MsnMsgr.Exe" /background
O4 - HKCU\..\Run: [Yahoo! Pager] "C:\Program Files\Yahoo!\Messenger\YahooMessenger.exe" -quiet
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKUS\S-1-5-18\..\Run: [Yahoo! Pager] "C:\PROGRA~1\Yahoo!\MESSEN~1\YAHOOM~1.EXE" -quiet (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [Yahoo! Pager] "C:\PROGRA~1\Yahoo!\MESSEN~1\YAHOOM~1.EXE" -quiet (User 'Default user')
O4 - Global Startup: Digital Line Detect.lnk = ?
O4 - Global Startup: HP Digital Imaging Monitor.lnk = C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe
O4 - Global Startup: Kodak EasyShare software.lnk = C:\Program Files\Kodak\pictures\Kodak EasyShare software\bin\EasyShare.exe
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_04\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_04\bin\ssv.dll
O9 - Extra button: (no name) - {85d1f590-48f4-11d9-9669-0800200c9a66} - C:\WINDOWS\bdoscandel.exe
O9 - Extra 'Tools' menuitem: Uninstall BitDefender Online Scanner v8 - {85d1f590-48f4-11d9-9669-0800200c9a66} - C:\WINDOWS\bdoscandel.exe
O9 - Extra button: (no name) - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O9 - Extra 'Tools' menuitem: Spybot - Search & Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O12 - Plugin for .spop: C:\Program Files\Internet Explorer\Plugins\NPDocBox.dll
O16 - DPF: {5D86DDB5-BDF9-441B-9E9E-D4730F4EE499} (BDSCANONLINE Control) - http://download.bitdefender.com/resources/scan8/oscan8.cab
O16 - DPF: {77E32299-629F-43C6-AB77-6A1E6D7663F6} (Groove Control) - http://www.nick.com/common/groove/gx/GrooveAX27.cab
O16 - DPF: {9AA73F41-EC64-489E-9A73-9CD52E528BC4} (ZoneAxRcMgr Class) - http://zone.msn.com/binGame/ZAxRcMgr.cab
O16 - DPF: {B8BE5E93-A60C-4D26-A2DC-220313175592} (MSN Games - Installer) - http://cdn2.zone.msn.com/binFramework/v10/...ro.cab56649.cab
O16 - DPF: {E598AC61-4C6F-4F4D-877F-FAC49CA91FA3} (acpRunner Class) - https://www-3.ibm.com/pc/support/access/asl.../AcpControl.cab
O20 - Winlogon Notify: !SASWinLogon - C:\Program Files\SUPERAntiSpyware\SASWINLO.dll
O23 - Service: Ad-Aware 2007 Service (aawservice) - Lavasoft - C:\Program Files\Lavasoft\Ad-Aware 2007\aawservice.exe
O23 - Service: DSBrokerService - Unknown owner - C:\Program Files\DellSupport\brkrsvc.exe
O23 - Service: McAfee E-mail Proxy (Emproxy) - McAfee, Inc. - C:\PROGRA~1\COMMON~1\McAfee\EmProxy\emproxy.exe
O23 - Service: Kodak Camera Connection Software (KodakCCS) - Eastman Kodak Company - C:\WINDOWS\system32\drivers\KodakCCS.exe
O23 - Service: LexBce Server (LexBceS) - Lexmark International, Inc. - C:\WINDOWS\system32\LEXBCES.EXE
O23 - Service: McAfee HackerWatch Service - McAfee, Inc. - C:\Program Files\Common Files\McAfee\HackerWatch\HWAPI.exe
O23 - Service: McAfee Update Manager (mcmispupdmgr) - McAfee, Inc. - C:\PROGRA~1\McAfee\MSC\mcupdmgr.exe
O23 - Service: McAfee Services (mcmscsvc) - McAfee, Inc. - C:\PROGRA~1\McAfee\MSC\mcmscsvc.exe
O23 - Service: McAfee Network Agent (McNASvc) - McAfee, Inc. - c:\program files\common files\mcafee\mna\mcnasvc.exe
O23 - Service: McAfee Scanner (McODS) - McAfee, Inc. - C:\PROGRA~1\McAfee\VIRUSS~1\mcods.exe
O23 - Service: McAfee Protection Manager (mcpromgr) - McAfee, Inc. - C:\PROGRA~1\McAfee\MSC\mcpromgr.exe
O23 - Service: McAfee Proxy Service (McProxy) - McAfee, Inc. - c:\PROGRA~1\COMMON~1\mcafee\mcproxy\mcproxy.exe
O23 - Service: McAfee Redirector Service (McRedirector) - McAfee, Inc. - c:\PROGRA~1\COMMON~1\mcafee\redirsvc\redirsvc.exe
O23 - Service: McAfee Real-time Scanner (McShield) - McAfee, Inc. - C:\PROGRA~1\McAfee\VIRUSS~1\mcshield.exe
O23 - Service: McAfee SystemGuards (McSysmon) - McAfee, Inc. - C:\PROGRA~1\McAfee\VIRUSS~1\mcsysmon.exe
O23 - Service: McAfee Personal Firewall Service (MpfService) - McAfee, Inc. - C:\Program Files\McAfee\MPF\MPFSrv.exe
O23 - Service: McAfee Privacy Service (MPS9) - McAfee, Inc. - C:\PROGRA~1\McAfee\MPS\mps.exe
O23 - Service: Intel® NMS (NMSSvc) - Intel Corporation - C:\WINDOWS\System32\NMSSvc.exe
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\System32\nvsvc32.exe
O23 - Service: WAN Miniport (ATW) Service (WANMiniportService) - America Online, Inc. - C:\WINDOWS\wanmpsvc.exe

--
End of file - 10142 bytes

#9 chryssi2001

chryssi2001

  • Members
  • 1,930 posts
  • OFFLINE
  •  
  • Local time:02:08 PM

Posted 19 February 2008 - 01:21 AM

Hello Penguin73,

P2P PROGRAMS

IMPORTANT I notice there are signs of one or more P2P (Person to Person) File Sharing Programs on your computer.

Kazaa Media Desktop 2.1.1
Kazaa Media Desktop 2.5
Shareaza version 2.2.5.0


I'd like you to read the Guidelines for P2P Programs where we explain why it's not a good idea to have them.

Also available here.

My recommendation is you go to Control Panel > Add/Remove Programs and uninstall the programs listed above (in red).

If you choose not to remove them, please do not use them until this computer is clean.
-------------------------------------------------
OTMoveIt2.exe
  • Please double-click OTMoveIt2.exe to run it. (Note: If you are running on Vista, right-click on the file and choose Run As Administrator).
  • Copy the lines in the codebox below to the clipboard by highlighting ALL of them and pressing CTRL + C (or, after highlighting, right-click and choose Copy):

    C:\Program Files\Save
  • Return to OTMoveIt2, right click in the "Paste Standard List of Files/Folders to Move" window (under the light blue bar) and choose Paste.
  • Click the red Moveit! button.
  • Copy everything in the Results window (under the green bar) to the clipboard by highlighting ALL of them and pressing CTRL + C (or, after highlighting, right-click and choose copy), and paste it in your next reply.
  • Close OTMoveIt2
Note: If a file or folder cannot be moved immediately you may be asked to reboot the machine to finish the move process. If you are asked to reboot the machine choose Yes. In this case, after the reboot, open Notepad (Start->All Programs->Accessories->Notepad), click File->Open, in the File Name box enter *.log and press the Enter key, navigate to the C:\_OTMoveIt\MovedFiles folder, and open the newest .log file present, and copy/paste the contents of that document back here in your next post.
-------------------------------------------------
Malwarebytes' Anti-Malware

Please download Malwarebytes' Anti-Malware to your desktop.
  • Double-click mbam-setup.exe and follow the prompts to install the program.
  • At the end, be sure a checkmark is placed next to Update Malwarebytes' Anti-Malware and Launch Malwarebytes' Anti-Malware, then click Finish.
  • If an update is found, it will download and install the latest version.
  • Once the program has loaded, select Perform full scan, then click Scan.
  • When the scan is complete, click OK, then Show Results to view the results.
  • Be sure that everything is checked, and click Remove Selected.
  • When completed, a log will open in Notepad. Please save it to a convenient location.
  • The log can also be found here:
    C:\Documents and Settings\Username\Application Data\Malwarebytes\Malwarebytes' Anti-Malware\Logs\mbam-log-date (time).txt
  • Post that log back here.
-------------------------------------------------
Post back:
OTMoveIt2 report.
Malwarebytes' Anti-Malware report.
Tell me how the pc is behaving now.
Posted Image
Private Messages for personal support will be ignored. If you need help post in the forum.

#10 Penguin73

Penguin73
  • Topic Starter

  • Members
  • 19 posts
  • OFFLINE
  •  
  • Local time:06:08 AM

Posted 22 February 2008 - 06:54 PM

Sorry, busy last few days...will post again later tonight or early tomorrow

Penguin73

#11 chryssi2001

chryssi2001

  • Members
  • 1,930 posts
  • OFFLINE
  •  
  • Local time:02:08 PM

Posted 23 February 2008 - 02:08 AM

Ok Penguin, we are almost done. Thanks for letting me know :thumbsup:
Posted Image
Private Messages for personal support will be ignored. If you need help post in the forum.

#12 Penguin73

Penguin73
  • Topic Starter

  • Members
  • 19 posts
  • OFFLINE
  •  
  • Local time:06:08 AM

Posted 23 February 2008 - 12:26 PM

File/Folder C:\Program Files\Save not found.

OTMoveIt2 v1.0.20 log created on 02232008_102346


Malwarebytes' Anti-Malware 1.05
Database version: 396

Scan type: Full Scan (C:\|)
Objects scanned: 152844
Time elapsed: 1 hour(s), 32 minute(s), 26 second(s)

Memory Processes Infected: 0
Memory Modules Infected: 0
Registry Keys Infected: 3
Registry Values Infected: 0
Registry Data Items Infected: 0
Folders Infected: 3
Files Infected: 22

Memory Processes Infected:
(No malicious items detected)

Memory Modules Infected:
(No malicious items detected)

Registry Keys Infected:
HKEY_CLASSES_ROOT\elfwgps.bdgw (Trojan.FakeAlert) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\elfwgps.toolbar.1 (Trojan.FakeAlert) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Multimedia\WMPlayer\Schemes\f3pss (Adware.MyWebSearch) -> Quarantined and deleted successfully.

Registry Values Infected:
(No malicious items detected)

Registry Data Items Infected:
(No malicious items detected)

Folders Infected:
C:\Program Files\dynamic toolbar (Adware.2020search) -> Quarantined and deleted successfully.
C:\Program Files\dynamic toolbar\REALBAR (Adware.2020search) -> Quarantined and deleted successfully.
C:\Program Files\dynamic toolbar\REALBAR\Cache (Adware.2020search) -> Quarantined and deleted successfully.

Files Infected:
C:\Documents and Settings\Ginna\Local Settings\Temp\BIT116.tmp (Trojan.Fakealert) -> Quarantined and deleted successfully.
C:\Documents and Settings\Ginna\Local Settings\Temp\BIT14B.tmp (Trojan.Fakealert) -> Quarantined and deleted successfully.
C:\Documents and Settings\Ginna\Local Settings\Temp\BIT1A7.tmp (Trojan.Fakealert) -> Quarantined and deleted successfully.
C:\Documents and Settings\Ginna\Local Settings\Temp\BIT61.tmp (Trojan.Fakealert) -> Quarantined and deleted successfully.
C:\Program Files\dynamic toolbar\REALBAR\Cache\bubble.bmp (Adware.2020search) -> Quarantined and deleted successfully.
C:\Program Files\dynamic toolbar\REALBAR\Cache\bubble16.bmp (Adware.2020search) -> Quarantined and deleted successfully.
C:\Program Files\dynamic toolbar\REALBAR\Cache\celebs.bmp (Adware.2020search) -> Quarantined and deleted successfully.
C:\Program Files\dynamic toolbar\REALBAR\Cache\ErrorLog.txt (Adware.2020search) -> Quarantined and deleted successfully.
C:\Program Files\dynamic toolbar\REALBAR\Cache\gotb.bmp (Adware.2020search) -> Quarantined and deleted successfully.
C:\Program Files\dynamic toolbar\REALBAR\Cache\highlight.bmp (Adware.2020search) -> Quarantined and deleted successfully.
C:\Program Files\dynamic toolbar\REALBAR\Cache\hotstuff.bmp (Adware.2020search) -> Quarantined and deleted successfully.
C:\Program Files\dynamic toolbar\REALBAR\Cache\hotstuffsm.bmp (Adware.2020search) -> Quarantined and deleted successfully.
C:\Program Files\dynamic toolbar\REALBAR\Cache\movies.bmp (Adware.2020search) -> Quarantined and deleted successfully.
C:\Program Files\dynamic toolbar\REALBAR\Cache\music.bmp (Adware.2020search) -> Quarantined and deleted successfully.
C:\Program Files\dynamic toolbar\REALBAR\Cache\news.bmp (Adware.2020search) -> Quarantined and deleted successfully.
C:\Program Files\dynamic toolbar\REALBAR\Cache\ngames.bmp (Adware.2020search) -> Quarantined and deleted successfully.
C:\Program Files\dynamic toolbar\REALBAR\Cache\radio.bmp (Adware.2020search) -> Quarantined and deleted successfully.
C:\Program Files\dynamic toolbar\REALBAR\Cache\REALBARTB0115.cfg (Adware.2020search) -> Quarantined and deleted successfully.
C:\Program Files\dynamic toolbar\REALBAR\Cache\REALBARTB1115.cfg (Adware.2020search) -> Quarantined and deleted successfully.
C:\Program Files\dynamic toolbar\REALBAR\Cache\rollingstone.bmp (Adware.2020search) -> Quarantined and deleted successfully.
C:\Program Files\dynamic toolbar\REALBAR\Cache\sports.bmp (Adware.2020search) -> Quarantined and deleted successfully.
C:\WINDOWS\adaway.lic (Rogue.AdwareAway) -> Quarantined and deleted successfully.


My computer is running a lot better now than when I first posted. I have not seen a pop-up in a while. As far as the P2P programs, I do not usae Kazaa anymore. I did try removing it, but it gave me an error about a .dll file not found, I will reboot and try again later today. I do use Sharazza sometimes, but rarely, and I am very particular about what I download. (usually only .mp3s or Videos)

I do have a few questions, though. I have downloaded many different programs to get rid of all the malware and pop-ups and such. What programs do I really need to keep on the computer? I had used Adaware 2007 and AVG Virus checker until I signed up with high-speed internet. They offered the McAfee which I am using now, but they didn't seem capable to solve this wave of problems. I really only want to keep what is necessary to prevent and remove this issues in the future.

Also, even before this, my computer was running slow at boot-up. Is there anything else that can be done to help it boot quicker? Are there programs in memory that are not really needed?

Thanks for all the help. My computer is definitely better now than it was a month ago.

Penguin73

#13 chryssi2001

chryssi2001

  • Members
  • 1,930 posts
  • OFFLINE
  •  
  • Local time:02:08 PM

Posted 23 February 2008 - 01:35 PM

Hello Penguin73,

I do not usae Kazaa anymore. I did try removing it, but it gave me an error about a .dll file not found, I will reboot and try again later today.

Try to remove it in Safe mode, and then find and remove the folder too.

How to go in Safe mode
Go in Safe Mode by restarting your computer, then continually tapping F8 until a menu appears. Use your up arrow key to highlight Safe Mode, then hit enter.
-------------------------------------------

I do use Sharazza sometimes, but rarely, and I am very particular about what I download. (usually only .mp3s or Videos)


It's a nice way to get infected no matter how carefull you are.

Did you use Shareaza or Kazaa these last days?
Malwarebytes' Anti-Malware shows some infections which could be new or hiding.
Some new infected files in your Temporary files were found too.
-------------------------------------------

I do have a few questions, though. I have downloaded many different programs to get rid of all the malware and pop-ups and such. What programs do I really need to keep on the computer? I had used Adaware 2007 and AVG Virus checker until I signed up with high-speed internet. They offered the McAfee which I am using now, but they didn't seem capable to solve this wave of problems. I really only want to keep what is necessary to prevent and remove this issues in the future.

Having a lot of Anti-Spyware programs doesn't mean you will be always free from infections.

There are a lot of things you can do to prevent your pc from infection.
When we finish cleaning your pc in my all clean speech i suggest some programs, which you can use, and some links which you can read about how to prevent infections.
We can talk about them later on.
-------------------------------------------

Also, even before this, my computer was running slow at boot-up. Is there anything else that can be done to help it boot quicker? Are there programs in memory that are not really needed?

You can disable from start-up the below programs and use them when you need to:
Yahoo Messenger
Msn Messenger
Musicmatch Jukebox
Quick Time

We can do this using HijackThis log if you want.
-------------------------------------------
Some evidence in your Malwarebytes' Anti-Malware report makes me suspect there is infection left behind or something is re-creating infection.

So i need you to run another tool please.
-------------------------------------------
Download and Run ComboFix
If you already have Combofix, please delete this copy and download it again as it's being updated regularly.Note: Do not mouseclick combofix's window whilst it's running. That may cause it to stall

Combofix should never take more that 20 minutes including the reboot if malware is detected.
If it does, open Task Manager then Processes tab (press ctrl, alt and del at the same time) and end any processes of findstr, find, sed or swreg, then combofix should continue.
If that happened we want to know, and also what process you had to end.
-------------------------------------------
Post back:
Combofix report.
A new HijackThis log.
Posted Image
Private Messages for personal support will be ignored. If you need help post in the forum.

#14 Penguin73

Penguin73
  • Topic Starter

  • Members
  • 19 posts
  • OFFLINE
  •  
  • Local time:06:08 AM

Posted 27 February 2008 - 10:40 AM

ComboFix 08-02-25.3 - Michael 2008-02-27 10:08:00.2 - NTFSx86
Microsoft Windows XP Home Edition 5.1.2600.2.1252.1.1033.18.188 [GMT -5:00]
Running from: C:\Documents and Settings\Michael\Local Settings\Temporary Internet Files\Content.IE5\VD22QYUI\ComboFix[1].exe
* Created a new restore point

WARNING -THIS MACHINE DOES NOT HAVE THE RECOVERY CONSOLE INSTALLED !!
.

((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.

C:\Documents and Settings\All Users\Application Data\Microsoft\Network\Downloader\qmgr0.dat
C:\Documents and Settings\All Users\Application Data\Microsoft\Network\Downloader\qmgr1.dat
C:\Documents and Settings\Ginna\Application Data\.#
C:\Documents and Settings\Ginna\Application Data\.#\MBX@3104@1195B78.###
C:\Documents and Settings\Ginna\Application Data\.#\MBX@3104@1195BD8.###

----- BITS: Possible infected sites -----

hxxp://softworldnetwork.com
hxxp://onsafepro.com
hxxp://softworldnetwork2.com
.
((((((((((((((((((((((((( Files Created from 2008-01-27 to 2008-02-27 )))))))))))))))))))))))))))))))
.

2008-02-23 12:27 . 2008-02-23 12:27 <DIR> d-------- C:\Program Files\Dynamic Toolbar
2008-02-23 10:27 . 2008-02-23 10:27 <DIR> d-------- C:\Documents and Settings\Michael\Application Data\Malwarebytes
2008-02-23 10:26 . 2008-02-23 10:26 <DIR> d-------- C:\Program Files\Malwarebytes' Anti-Malware
2008-02-23 10:26 . 2008-02-23 10:26 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\Malwarebytes
2008-02-20 15:03 . 2008-02-20 19:31 <DIR> d-------- C:\Program Files\Democracy
2008-02-20 15:03 . 2008-02-20 15:03 4,096 --a------ C:\WINDOWS\d3dx.dat
2008-02-18 21:57 . 2007-12-14 01:59 69,632 --a------ C:\WINDOWS\SYSTEM32\javacpl.cpl
2008-02-18 21:56 . 2008-02-18 21:56 <DIR> d-------- C:\Program Files\Common Files\Java
2008-02-17 22:08 . 2008-02-17 22:08 9,216 --ahs---- C:\WINDOWS\Thumbs.db
2008-02-17 17:54 . 2008-02-17 17:54 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\SUPERAntiSpyware.com
2008-02-17 17:53 . 2008-02-17 22:12 <DIR> d-------- C:\Program Files\SUPERAntiSpyware
2008-02-17 17:53 . 2008-02-17 17:53 <DIR> d-------- C:\Documents and Settings\Michael\Application Data\SUPERAntiSpyware.com
2008-02-17 17:41 . 2008-02-17 17:41 <DIR> d-------- C:\_OTMoveIt
2008-02-16 17:20 . 2008-02-16 17:20 <DIR> d-------- C:\WINDOWS\ERUNT
2008-02-16 17:14 . 2008-02-23 10:24 <DIR> d-------- C:\SDFix
2008-02-13 19:04 . 2008-02-13 19:04 118 --a------ C:\WINDOWS\SYSTEM32\MRT.INI
2008-02-13 13:19 . 2008-02-23 15:45 <DIR> d-------- C:\Program Files\7 Wonders II
2008-02-03 16:48 . 2008-02-06 22:44 <DIR> d-------- C:\Program Files\Slingo
2008-01-28 11:26 . 2008-01-28 11:26 <DIR> d-------- C:\Program Files\Trend Micro

.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2008-02-26 21:25 --------- d-----w C:\Program Files\McAfee
2008-02-19 02:57 --------- d-----w C:\Program Files\Java
2008-02-17 22:53 --------- d-----w C:\Program Files\Common Files\Wise Installation Wizard
2008-02-16 19:48 --------- d-----w C:\Program Files\Electric_Fire_House_Radio
2008-02-10 06:17 --------- d-----w C:\Program Files\mIRC
2008-02-06 14:51 171,400 ----a-w C:\WINDOWS\system32\drivers\mfehidk.sys
2008-02-04 18:12 --------- d-----w C:\Documents and Settings\Ginna\Application Data\funkitron
2008-02-03 21:49 --------- d-----w C:\Documents and Settings\Michael\Application Data\funkitron
2008-02-03 21:29 --------- d-----w C:\Program Files\Subway Scramble
2008-02-01 03:32 --------- d-----w C:\Program Files\Hidden Relics
2008-01-27 16:59 --------- d-----w C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy
2008-01-26 06:19 --------- d-----w C:\Program Files\Spybot - Search & Destroy
2008-01-24 04:45 --------- d-----w C:\Program Files\iWin Games
2008-01-24 04:40 --------- d-----w C:\Program Files\DIGStream
2008-01-24 01:04 --------- d-----w C:\Documents and Settings\All Users\Application Data\Lavasoft
2008-01-24 01:03 --------- d-----w C:\Program Files\Lavasoft
2008-01-24 01:03 --------- d-----w C:\Documents and Settings\Michael\Application Data\Lavasoft
2008-01-23 20:04 --------- d-----w C:\Documents and Settings\Ginna\Application Data\Lavasoft
2008-01-23 16:53 --------- d-----w C:\Program Files\BFG
2008-01-23 16:43 --------- d-----w C:\Program Files\Enigma Software Group
2008-01-23 06:12 --------- d-----w C:\Program Files\XoftSpySE
2008-01-23 03:55 --------- d-----w C:\Program Files\iWin.com
2008-01-23 03:54 --------- d-----w C:\Program Files\Games
2008-01-23 03:54 --------- d-----w C:\Program Files\Carmen Sandiego Junior
2008-01-23 02:35 --------- d-----w C:\Program Files\Comcast Play Games
2008-01-21 01:54 --------- d-----w C:\Documents and Settings\Michael\Application Data\uTorrent
2008-01-16 23:09 --------- d-----w C:\Program Files\The Scruffs
2008-01-12 20:02 --------- d-----w C:\Documents and Settings\Ginna\Application Data\U3
2008-01-12 04:58 --------- d---a-w C:\Documents and Settings\All Users\Application Data\TEMP
2008-01-12 04:47 --------- d-----w C:\Documents and Settings\All Users\Application Data\BigFishGamesCache
2008-01-11 05:53 44,544 ----a-w C:\WINDOWS\SYSTEM32\DLLCACHE\pngfilt.dll
2008-01-11 01:56 --------- d-----w C:\Documents and Settings\Leslie\Application Data\Big Fish Games
2008-01-11 01:51 --------- d-----w C:\Documents and Settings\Ginna\Application Data\Big Fish Games
2008-01-09 20:01 53,248 ----a-w C:\WINDOWS\bdoscandel.exe
2008-01-07 01:02 --------- d-----w C:\Documents and Settings\Michael\Application Data\Big Fish Games
2008-01-06 17:40 --------- d-----w C:\Program Files\Poker Superstars II
2008-01-06 03:43 --------- d-----w C:\Program Files\Escape From Paradise
2008-01-05 02:57 --------- d-----w C:\Program Files\Buildalot
2007-12-19 23:01 347,136 ----a-w C:\WINDOWS\SYSTEM32\DLLCACHE\dxtmsft.dll
2007-12-18 09:51 179,584 ------w C:\WINDOWS\SYSTEM32\DLLCACHE\mrxdav.sys
2007-12-14 16:32 12,632 ----a-w C:\WINDOWS\SYSTEM32\lsdelete.exe
2007-12-08 05:21 3,592,192 ----a-w C:\WINDOWS\SYSTEM32\DLLCACHE\mshtml.dll
2007-12-06 11:01 625,664 ------w C:\WINDOWS\SYSTEM32\DLLCACHE\iexplore.exe
2007-12-06 11:00 70,656 ------w C:\WINDOWS\SYSTEM32\DLLCACHE\ie4uinit.exe
2007-12-06 11:00 13,824 ------w C:\WINDOWS\SYSTEM32\DLLCACHE\ieudinit.exe
2007-12-06 04:59 161,792 ------w C:\WINDOWS\SYSTEM32\DLLCACHE\ieakui.dll
2007-12-04 18:38 550,912 ------w C:\WINDOWS\SYSTEM32\oleaut32.dll
2007-12-04 18:38 550,912 ------w C:\WINDOWS\SYSTEM32\DLLCACHE\oleaut32.dll
2003-02-11 23:10 207,759 ----a-w C:\Program Files\INSTALL.LOG
.

((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ModemOnHold"="C:\PROGRA~1\DELLMO~1\MOH.exe" [2002-06-17 04:13 81920]
"MsnMsgr"="C:\Program Files\MSN Messenger\MsnMsgr.exe" [2007-01-19 11:54 5674352]
"Yahoo! Pager"="C:\Program Files\Yahoo!\Messenger\YahooMessenger.exe" [2007-06-07 13:08 4670968]
"ctfmon.exe"="C:\WINDOWS\system32\ctfmon.exe" [2004-08-04 02:56 15360]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"NvCplDaemon"="C:\WINDOWS\System32\NvCpl.dll" [2003-10-06 13:16 5058560]
"DVDSentry"="C:\WINDOWS\System32\DSentry.exe" [2002-08-14 19:22 28672]
"AdaptecDirectCD"="C:\Program Files\Roxio\Easy CD Creator 5\DirectCD\DirectCD.exe" [2002-04-10 17:44 679936]
"nwiz"="nwiz.exe" [2003-10-06 13:16 741376 C:\WINDOWS\SYSTEM32\nwiz.exe]
"DIGServices"="C:\Program Files\ESPNRunTime\DIGServices.exe" [2005-05-19 12:55 101888]
"TkBellExe"="C:\Program Files\Common Files\Real\Update_OB\realsched.exe" [2006-04-14 17:05 180269]
"MimBoot"="C:\PROGRA~1\MUSICM~1\MUSICM~1\mimboot.exe" [2006-01-19 10:06 11776]
"MMTray"="C:\Program Files\Musicmatch\Musicmatch Jukebox\mm_tray.exe" [2006-01-19 10:06 110592]
"WinampAgent"="C:\Program Files\Winamp\winampa.exe" [2006-06-21 12:14 35328]
"mm_server"="C:\Program Files\Musicmatch\Musicmatch Jukebox\mm_server.exe" [2006-01-19 10:06 102400]
"QuickTime Task"="C:\Program Files\QuickTime\qttask.exe" [2007-04-09 21:03 77824]
"HP Software Update"="C:\Program Files\HP\HP Software Update\HPWuSchd2.exe" [2006-12-10 20:52 49152]
"SunJavaUpdateSched"="C:\Program Files\Java\jre1.6.0_04\bin\jusched.exe" [2007-12-14 03:42 144784]

[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"Yahoo! Pager"="C:\PROGRA~1\Yahoo!\MESSEN~1\YAHOOM~1.exe" [2007-06-07 13:08 4670968]

C:\Documents and Settings\Ginna\Start Menu\Programs\Startup\
iWin Desktop Alerts.lnk - C:\Documents and Settings\All Users\Application Data\iWin Games\DesktopAlerts\DesktopAlerts.exe [2007-12-16 23:29:24 58368]

C:\Documents and Settings\All Users\Start Menu\Programs\Startup\
Digital Line Detect.lnk - C:\Program Files\Digital Line Detect\DLG.exe [2003-02-11 18:02:39 45056]
HP Digital Imaging Monitor.lnk - C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe [2007-01-02 20:40:10 210520]
Kodak EasyShare software.lnk - C:\Program Files\Kodak\pictures\Kodak EasyShare software\bin\EasyShare.exe [2005-11-04 14:04:48 176128]

[hkey_local_machine\software\microsoft\windows\currentversion\explorer\shellexecutehooks]
"{5AE067D3-9AFB-48E0-853A-EBB7F4A000DA}"= C:\Program Files\SUPERAntiSpyware\SASSEH.DLL [2006-12-20 13:55 77824]

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\!SASWinLogon]
C:\Program Files\SUPERAntiSpyware\SASWINLO.dll 2007-04-19 13:41 294912 C:\Program Files\SUPERAntiSpyware\SASWINLO.dll

[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\securityproviders]
SecurityProviders msapsspc.dll, schannel.dll, digest.dll, msnsspc.dll,

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]
"EnableFirewall"= 0 (0x0)

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"C:\\Program Files\\Yahoo!\\Messenger\\YahooMessenger.exe"=
"C:\\Program Files\\MSN Messenger\\msnmsgr.exe"=
"C:\\Program Files\\Kodak\\pictures\\Kodak EasyShare software\\bin\\EasyShare.exe"=

S2 CoachCap;Concord EyeQ Duo 2000 USB Video Capture V1.00;C:\WINDOWS\system32\drivers\CoachCap.sys [2002-03-03 12:26]
S3 NMSCFG;NIC Management Service Configuration Driver;C:\WINDOWS\system32\drivers\NMSCFG.SYS [2002-05-03 12:30]
S3 NMSSvc;Intel® NMS;C:\WINDOWS\System32\NMSSvc.exe [2002-05-03 12:29]

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost]
hpdevmgmt REG_MULTI_SZ hpqcxs08 hpqddsvc

.
Contents of the 'Scheduled Tasks' folder
"2008-02-22 03:30:03 C:\WINDOWS\Tasks\McAfee.com Scan for Viruses - My Computer (PENGUIN-Michael).job"
- c:\PROGRA~1\mcafee.com\vso\mcmnhdlr.exe
"2007-12-15 06:39:18 C:\WINDOWS\Tasks\McDefragTask.job"
- c:\program files\mcafee\mqc\QcConsol.exe'
"2008-01-01 06:00:01 C:\WINDOWS\Tasks\McQcTask.job"
- c:\program files\mcafee\mqc\QcConsol.exe
.
**************************************************************************

catchme 0.3.1344 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2008-02-27 10:17:00
Windows 5.1.2600 Service Pack 2 NTFS

scanning hidden processes ...

scanning hidden autostart entries ...

scanning hidden files ...

scan completed successfully
hidden files: 0

**************************************************************************
.
Completion time: 2008-02-27 10:18:58
ComboFix-quarantined-files.txt 2008-02-27 15:18:23
ComboFix2.txt 2008-01-23 06:54:53
.
2008-02-14 00:05:15 --- E O F ---

Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 10:35:29 AM, on 2/27/2008
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16608)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Lavasoft\Ad-Aware 2007\aawservice.exe
C:\WINDOWS\system32\LEXBCES.EXE
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\system32\LEXPPS.EXE
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\System32\DSentry.exe
C:\Program Files\Roxio\Easy CD Creator 5\DirectCD\DirectCD.exe
C:\Program Files\ESPNRunTime\DIGServices.exe
C:\Program Files\Common Files\Real\Update_OB\realsched.exe
C:\Program Files\Musicmatch\Musicmatch Jukebox\mm_tray.exe
C:\Program Files\Winamp\winampa.exe
C:\Program Files\Musicmatch\Musicmatch Jukebox\mm_server.exe
C:\Program Files\HP\HP Software Update\HPWuSchd2.exe
C:\Program Files\Musicmatch\Musicmatch Jukebox\MMDiag.exe
C:\Program Files\Java\jre1.6.0_04\bin\jusched.exe
C:\PROGRA~1\DELLMO~1\MOH.exe
C:\Program Files\MSN Messenger\MsnMsgr.Exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Digital Line Detect\DLG.exe
C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe
C:\Program Files\Kodak\pictures\Kodak EasyShare software\bin\EasyShare.exe
C:\Program Files\MUSICMATCH\MUSICMATCH Jukebox\mim.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Common Files\McAfee\HackerWatch\HWAPI.exe
C:\PROGRA~1\McAfee\MSC\mcmscsvc.exe
c:\program files\common files\mcafee\mna\mcnasvc.exe
C:\PROGRA~1\McAfee\VIRUSS~1\mcods.exe
C:\PROGRA~1\McAfee\MSC\mcpromgr.exe
c:\PROGRA~1\COMMON~1\mcafee\mcproxy\mcproxy.exe
c:\PROGRA~1\COMMON~1\mcafee\redirsvc\redirsvc.exe
C:\PROGRA~1\McAfee\VIRUSS~1\mcshield.exe
C:\Program Files\McAfee\MPF\MPFSrv.exe
C:\PROGRA~1\McAfee\MPS\mps.exe
C:\WINDOWS\System32\nvsvc32.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\wanmpsvc.exe
c:\PROGRA~1\mcafee.com\agent\mcagent.exe
C:\Program Files\McAfee\MPS\mpsevh.exe
C:\WINDOWS\system32\wuauclt.exe
C:\Program Files\HP\Digital Imaging\bin\hpqSTE08.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\MSN Messenger\usnsvc.exe
c:\program files\mcafee\msc\mcuimgr.exe
C:\Program Files\Yahoo!\Messenger\ymsgr_tray.exe
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://cm.my.yahoo.com/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 5.0\Reader\ActiveX\AcroIEHelper.ocx
O2 - BHO: REALBAR - {4E7BD74F-2B8D-469E-C0FF-FD60B590A87D} - C:\PROGRA~1\COMMON~1\Real\Toolbar\realbar.dll
O2 - BHO: Spybot-S&D IE Protection - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_04\bin\ssv.dll
O2 - BHO: scriptproxy - {7DB2D5A0-7241-4E79-B68D-6309F01C5231} - c:\PROGRA~1\mcafee\VIRUSS~1\scriptcl.dll
O2 - BHO: Windows Live Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
O2 - BHO: ST - {9394EDE7-C8B5-483E-8773-474BF36AF6E4} - C:\Program Files\MSN Apps\ST\01.02.0002.1001\en-xu\stmain.dll
O2 - BHO: MSNToolBandBHO - {BDBD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\Program Files\MSN Apps\MSN Toolbar\01.02.2001.0001\en-us\msntb.dll
O3 - Toolbar: REALBAR - {4E7BD74F-2B8D-469E-C0FF-FD60B590A87D} - C:\PROGRA~1\COMMON~1\Real\Toolbar\realbar.dll
O3 - Toolbar: MSN - {BDAD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\Program Files\MSN Apps\MSN Toolbar\01.02.2001.0001\en-us\msntb.dll
O3 - Toolbar: &ESPN - {AE6F2894-AF10-4C9C-B16E-1DFC6FF8C0C6} - C:\Program Files\ESPN\Toolbar\DIGToolBar.dll
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\System32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [DVDSentry] C:\WINDOWS\System32\DSentry.exe
O4 - HKLM\..\Run: [AdaptecDirectCD] "C:\Program Files\Roxio\Easy CD Creator 5\DirectCD\DirectCD.exe"
O4 - HKLM\..\Run: [nwiz] nwiz.exe /install
O4 - HKLM\..\Run: [DIGServices] C:\Program Files\ESPNRunTime\DIGServices.exe /brand=ESPN /priority=0 /poll=24
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
O4 - HKLM\..\Run: [MimBoot] C:\PROGRA~1\MUSICM~1\MUSICM~1\mimboot.exe
O4 - HKLM\..\Run: [MMTray] "C:\Program Files\Musicmatch\Musicmatch Jukebox\mm_tray.exe"
O4 - HKLM\..\Run: [WinampAgent] C:\Program Files\Winamp\winampa.exe
O4 - HKLM\..\Run: [mm_server] "C:\Program Files\Musicmatch\Musicmatch Jukebox\mm_server.exe"
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [HP Software Update] C:\Program Files\HP\HP Software Update\HPWuSchd2.exe
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_04\bin\jusched.exe"
O4 - HKCU\..\Run: [ModemOnHold] C:\PROGRA~1\DELLMO~1\MOH.exe
O4 - HKCU\..\Run: [MsnMsgr] "C:\Program Files\MSN Messenger\MsnMsgr.Exe" /background
O4 - HKCU\..\Run: [Yahoo! Pager] "C:\Program Files\Yahoo!\Messenger\YahooMessenger.exe" -quiet
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKUS\S-1-5-18\..\Run: [Yahoo! Pager] "C:\PROGRA~1\Yahoo!\MESSEN~1\YAHOOM~1.EXE" -quiet (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [Yahoo! Pager] "C:\PROGRA~1\Yahoo!\MESSEN~1\YAHOOM~1.EXE" -quiet (User 'Default user')
O4 - Global Startup: Digital Line Detect.lnk = ?
O4 - Global Startup: HP Digital Imaging Monitor.lnk = C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe
O4 - Global Startup: Kodak EasyShare software.lnk = C:\Program Files\Kodak\pictures\Kodak EasyShare software\bin\EasyShare.exe
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_04\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_04\bin\ssv.dll
O9 - Extra button: (no name) - {85d1f590-48f4-11d9-9669-0800200c9a66} - C:\WINDOWS\bdoscandel.exe
O9 - Extra 'Tools' menuitem: Uninstall BitDefender Online Scanner v8 - {85d1f590-48f4-11d9-9669-0800200c9a66} - C:\WINDOWS\bdoscandel.exe
O9 - Extra button: (no name) - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O9 - Extra 'Tools' menuitem: Spybot - Search & Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O12 - Plugin for .spop: C:\Program Files\Internet Explorer\Plugins\NPDocBox.dll
O16 - DPF: {5D86DDB5-BDF9-441B-9E9E-D4730F4EE499} (BDSCANONLINE Control) - http://download.bitdefender.com/resources/scan8/oscan8.cab
O16 - DPF: {77E32299-629F-43C6-AB77-6A1E6D7663F6} (Groove Control) - http://www.nick.com/common/groove/gx/GrooveAX27.cab
O16 - DPF: {9AA73F41-EC64-489E-9A73-9CD52E528BC4} (ZoneAxRcMgr Class) - http://zone.msn.com/binGame/ZAxRcMgr.cab
O16 - DPF: {B8BE5E93-A60C-4D26-A2DC-220313175592} (MSN Games - Installer) - http://cdn2.zone.msn.com/binFramework/v10/...ro.cab56649.cab
O16 - DPF: {E598AC61-4C6F-4F4D-877F-FAC49CA91FA3} (acpRunner Class) - https://www-3.ibm.com/pc/support/access/asl.../AcpControl.cab
O20 - Winlogon Notify: !SASWinLogon - C:\Program Files\SUPERAntiSpyware\SASWINLO.dll
O23 - Service: Ad-Aware 2007 Service (aawservice) - Lavasoft - C:\Program Files\Lavasoft\Ad-Aware 2007\aawservice.exe
O23 - Service: DSBrokerService - Unknown owner - C:\Program Files\DellSupport\brkrsvc.exe
O23 - Service: McAfee E-mail Proxy (Emproxy) - McAfee, Inc. - C:\PROGRA~1\COMMON~1\McAfee\EmProxy\emproxy.exe
O23 - Service: Kodak Camera Connection Software (KodakCCS) - Eastman Kodak Company - C:\WINDOWS\system32\drivers\KodakCCS.exe
O23 - Service: LexBce Server (LexBceS) - Lexmark International, Inc. - C:\WINDOWS\system32\LEXBCES.EXE
O23 - Service: McAfee HackerWatch Service - McAfee, Inc. - C:\Program Files\Common Files\McAfee\HackerWatch\HWAPI.exe
O23 - Service: McAfee Update Manager (mcmispupdmgr) - McAfee, Inc. - C:\PROGRA~1\McAfee\MSC\mcupdmgr.exe
O23 - Service: McAfee Services (mcmscsvc) - McAfee, Inc. - C:\PROGRA~1\McAfee\MSC\mcmscsvc.exe
O23 - Service: McAfee Network Agent (McNASvc) - McAfee, Inc. - c:\program files\common files\mcafee\mna\mcnasvc.exe
O23 - Service: McAfee Scanner (McODS) - McAfee, Inc. - C:\PROGRA~1\McAfee\VIRUSS~1\mcods.exe
O23 - Service: McAfee Protection Manager (mcpromgr) - McAfee, Inc. - C:\PROGRA~1\McAfee\MSC\mcpromgr.exe
O23 - Service: McAfee Proxy Service (McProxy) - McAfee, Inc. - c:\PROGRA~1\COMMON~1\mcafee\mcproxy\mcproxy.exe
O23 - Service: McAfee Redirector Service (McRedirector) - McAfee, Inc. - c:\PROGRA~1\COMMON~1\mcafee\redirsvc\redirsvc.exe
O23 - Service: McAfee Real-time Scanner (McShield) - McAfee, Inc. - C:\PROGRA~1\McAfee\VIRUSS~1\mcshield.exe
O23 - Service: McAfee SystemGuards (McSysmon) - McAfee, Inc. - C:\PROGRA~1\McAfee\VIRUSS~1\mcsysmon.exe
O23 - Service: McAfee Personal Firewall Service (MpfService) - McAfee, Inc. - C:\Program Files\McAfee\MPF\MPFSrv.exe
O23 - Service: McAfee Privacy Service (MPS9) - McAfee, Inc. - C:\PROGRA~1\McAfee\MPS\mps.exe
O23 - Service: Intel® NMS (NMSSvc) - Intel Corporation - C:\WINDOWS\System32\NMSSvc.exe
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\System32\nvsvc32.exe
O23 - Service: WAN Miniport (ATW) Service (WANMiniportService) - America Online, Inc. - C:\WINDOWS\wanmpsvc.exe

--
End of file - 10141 bytes

Combo fix ran a lot quicker this time than when I first used it a month ago, but I had to reboot the computer to get the program to release my computer. The PC locked up after the scan, but did go thru the entire process.

No one has used any P2P programs since this started. So no infection could be coming thru there.

As far as boot-up processes, I want Yahoo and Windows messengers to auto boot, but amything else non-essential needs to not slow the PC down on startup.

Penguin73

#15 chryssi2001

chryssi2001

  • Members
  • 1,930 posts
  • OFFLINE
  •  
  • Local time:02:08 PM

Posted 27 February 2008 - 01:46 PM

Hello Penguin73,

Can you please explain to me what do you mean by:

The PC locked up after the scan

What where the symptoms? Was it stuck and you had to reboot?
---------------------------------------------------
It seems you've installed Combofix in a temporary file, and by now it's deleted.
In case you still have an older version of Combofix on you pc, please delete it.
Use one of my links below to re-install Combofix, at your Desktop please.
---------------------------------------------------
We need to Download Combofix again.

Download and Run ComboFix
If you already have Combofix, please delete this copy and download it again as it's being updated regularly.

Download this file from one of the three below listed places :
For information regarding this download, please visit this webpage:
http://www.bleepingcomputer.com/combofix/how-to-use-combofix

http://download.bleepingcomputer.com/sUBs/ComboFix.exe
http://www.forospyware.com/sUBs/ComboFix.exe
http://subs.geekstogo.com/ComboFix.exe

Don't run Combofix yet.
---------------------------------------------------
Remove Poker programs
From your log I can see you've installed poker programs. A lot of poker programs are infected/can infect you with malware.

Here are links to some poker sites regarded as safe for your reference.
1. http://www.pokerstars.net/- This is a free to use/play site with play money.
2. http://www.pokerstars.com/ - This is a free to use/play site with play money and real money.

---------------------------------------------------
Go to Start-Settings-Control Panel, click on Add remove Programs. If any of the following programs are listed there, click on the program to highlight it, and click on remove. Then close the Control Panel.
Dynamic Toolbar
Electric_Fire_House_Radio
Poker Superstars II

---------------------------------------------------
Fixing the below lines, will make the following programs not start when the pc boots, so you will have to start them mannually.
Now regarding the HP software updates. If a shortcut doesn't exist, create your own and run it manually. If you don't want to create a shortcut don't check the red-coloured line.

Musicmatch
Musicmatch Jukebox
QuickTime


FIX HIJACKTHIS ENTRIES

Open up Hijackthis.
Click on do a system scan only.
Place a checkmark next to these lines(if still present).

O4 - HKLM\..\Run: [MimBoot] C:\PROGRA~1\MUSICM~1\MUSICM~1\mimboot.exe
O4 - HKLM\..\Run: [MMTray] "C:\Program Files\Musicmatch\Musicmatch Jukebox\mm_tray.exe"
O4 - HKLM\..\Run: [mm_server] "C:\Program Files\Musicmatch\Musicmatch Jukebox\mm_server.exe"
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [HP Software Update] C:\Program Files\HP\HP Software Update\HPWuSchd2.exe


Then close all windows except Hijackthis and click Fix Checked
Close HijackThis.
---------------------------------------------------
COMBOFIX-Script
  • Please open Notepad (Start -> Run -> type notepad in the Open field -> OK) and copy and paste the text present inside the code box below:

    Folder::
    C:\Program Files\Dynamic Toolbar
    C:\Program Files\Electric_Fire_House_Radio
    C:\Program Files\Poker Superstars II
  • Save this as CFScript.txt and change the "Save as type" to "All Files" and place it on your desktop.

    Posted Image
  • Referring to the screenshot above, drag CFScript.txt into ComboFix.exe.
  • ComboFix will now run a scan on your system. It may reboot your system when it finishes. This is normal.
  • When finished, it shall produce a log for you. Copy and paste the contents of the log in your next reply.
CAUTION: Do not mouse-click ComboFix's window while it is running. That may cause it to stall.
---------------------------------------------------
Update Adobe Reader
Recently there have been vunerabilities detected in older versions of Adobe Reader. It is strongly suggested that you update to the current version. Adobe Reader 8.
You can download it from http://www.adobe.com/products/acrobat/readstep2.html
If you already have Adobe Photoshop® Album Starter Edition installed or do not wish to have it installed UNcheck the box which says Also Download Adobe Photoshop® Album Starter Edition.

Adobe 8 is a large program and if you prefer a smaller program you can get Foxit 2.0 instead from http://www.foxitsoftware.com/pdf/rd_intro.php
---------------------------------------------------
Run Kaspersky Online AV Scanner
Using Internet Explorer Go to http://www.kaspersky.com/kos/eng/partner/d...kavwebscan.html and click the Accept button at the end of the page.
Note for Internet Explorer 7 users: If at any time you have trouble with the accept button of the licence, click on the Zoom tool located at the right bottom of the IE window and set the zoom to 75 %. Once the license accepted, reset to 100%.
  • Read the Requirements and limitations before you click Accept.
  • Allow the ActiveX download if necessary.
  • Once the database has downloaded, click Next.
  • Click Scan Settings and change the "Scan using the following antivirus database" from standard to extended and then click OK.
  • Click on "My Computer" and then put the kettle on!
  • When the scan has completed, click Save Report As...
  • Enter a name for the file in the Filename: text box and then click the down arrow to the right of Save as type: and select text file (*.txt)
  • Click Save - by default the file will be saved to your Desktop, but you can change this if you wish.
Copy and paste the report into your next reply along with a fresh HJT log and a description of how your PC is behaving.
---------------------------------------------------
Post back:
Combofix report.
Kaspersky report.
A new HijackThis log.
Posted Image
Private Messages for personal support will be ignored. If you need help post in the forum.




0 user(s) are reading this topic

0 members, 0 guests, 0 anonymous users