Jump to content


 


Register a free account to unlock additional features at BleepingComputer.com
Welcome to BleepingComputer, a free community where people like yourself come together to discuss and learn how to use their computers. Using the site is easy and fun. As a guest, you can browse and view the various discussions in the forums, but can not create a new topic or reply to an existing one unless you are logged in. Other benefits of registering an account are subscribing to topics and forums, creating a blog, and having no ads shown anywhere on the site.


Click here to Register a free account now! or read our Welcome Guide to learn how to use this site.

Photo

Please help :-(


  • Please log in to reply
17 replies to this topic

#1 Marci4

Marci4

  • Members
  • 18 posts
  • OFFLINE
  •  
  • Local time:12:31 AM

Posted 21 July 2005 - 12:07 PM

HI, could anyone here please help me. I keep having problems, mostly with a trojan that's in my restore program, but I believe there are other things on my pc causing havoc. This is my Hijack This log, I hope it means somehting to you, as I have no clue what it all means. Any help would be much appreciated. Marci4

Logfile of HijackThis v1.99.1
Scan saved at 3:00:27 AM, on 22/07/2005
Platform: Windows ME (Win9x 4.90.3000)
MSIE: Internet Explorer v5.50 (5.50.4134.0100)

Running processes:
C:\WINDOWS\SYSTEM\KERNEL32.DLL
C:\WINDOWS\SYSTEM\MSGSRV32.EXE
C:\WINDOWS\SYSTEM\mmtask.tsk
C:\WINDOWS\SYSTEM\MPREXE.EXE
C:\WINDOWS\SYSTEM\MSTASK.EXE
C:\WINDOWS\EXPLORER.EXE
C:\WINDOWS\TASKMON.EXE
C:\WINDOWS\SYSTEM\SYSTRAY.EXE
C:\WINDOWS\LOADQM.EXE
C:\WINDOWS\SYSTEM\RESTORE\STMGR.EXE
C:\PROGRAM FILES\ACD SYSTEMS\DEVDETECT\DEVDETECT.EXE
C:\PROGRAM FILES\GRISOFT\AVG FREE\AVGCC.EXE
C:\PROGRAM FILES\GRISOFT\AVG FREE\AVGAMSVR.EXE
C:\PROGRAM FILES\WEBROOT\SPY SWEEPER\SPYSWEEPER.EXE
C:\PROGRAM FILES\PANICWARE\POP-UP STOPPER FREE EDITION\PSFREE.EXE
C:\WINDOWS\SYSTEM\WMIEXE.EXE
C:\PROGRAM FILES\WEBROOT\SPY SWEEPER\WRSSSDK.EXE
C:\WINDOWS\SYSTEM\DDHELP.EXE
C:\WINDOWS\SYSTEM\RNAAPP.EXE
C:\WINDOWS\SYSTEM\TAPISRV.EXE
C:\PROGRAM FILES\INTERNET EXPLORER\IEXPLORE.EXE
C:\WINDOWS\SYSTEM\STIMON.EXE
C:\WINDOWS\SYSTEM\PSTORES.EXE
C:\WINDOWS\RUNDLL32.EXE
C:\WINDOWS\RUNDLL32.EXE
C:\WINDOWS\TEMP\TD_0011.DIR\HIJACKTHIS.EXE

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://www.yahoo.com
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.emailcash.com.au
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,SearchURL = http://www.clickyestoenter.net/ie/
O3 - Toolbar: @msdxmLC.dll,-1@1033,&Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINDOWS\SYSTEM\MSDXM.OCX
O4 - HKLM\..\Run: [ScanRegistry] C:\WINDOWS\scanregw.exe /autorun
O4 - HKLM\..\Run: [TaskMonitor] C:\WINDOWS\taskmon.exe
O4 - HKLM\..\Run: [SystemTray] SysTray.Exe
O4 - HKLM\..\Run: [LoadQM] loadqm.exe
O4 - HKLM\..\Run: [Camera Detector] C:\PROGRA~1\ACDSYS~1\DEVDET~1\DEVDET~1.EXE -autorun
O4 - HKLM\..\Run: [LoadPowerProfile] Rundll32.exe powrprof.dll,LoadCurrentPwrScheme
O4 - HKLM\..\Run: [AVG7_CC] C:\PROGRA~1\GRISOFT\AVGFRE~1\AVGCC.EXE /STARTUP
O4 - HKLM\..\Run: [AVG7_AMSVR] C:\PROGRA~1\GRISOFT\AVGFRE~1\AVGAMSVR.EXE
O4 - HKLM\..\Run: [SpySweeper] "C:\PROGRAM FILES\WEBROOT\SPY SWEEPER\SPYSWEEPER.EXE" /startintray
O4 - HKLM\..\RunServices: [LoadPowerProfile] Rundll32.exe powrprof.dll,LoadCurrentPwrScheme
O4 - HKLM\..\RunServices: [SchedulingAgent] mstask.exe
O4 - HKLM\..\RunServices: [*StateMgr] C:\WINDOWS\System\Restore\StateMgr.exe
O4 - HKCU\..\Run: [PopUpStopperFreeEdition] "C:\PROGRAM FILES\PANICWARE\POP-UP STOPPER FREE EDITION\PSFREE.EXE"
O4 - Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office\OSA9.EXE
O6 - HKCU\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O9 - Extra button: ICQ Pro - {6224f700-cba3-4071-b251-47cb894244cd} - C:\PROGRA~1\ICQ\ICQ.exe
O9 - Extra 'Tools' menuitem: ICQ - {6224f700-cba3-4071-b251-47cb894244cd} - C:\PROGRA~1\ICQ\ICQ.exe
O15 - Trusted Zone: *.windupdates.com
O15 - Trusted Zone: *.skoobidoo.com
O15 - Trusted Zone: *.slotchbar.com
O15 - Trusted Zone: *.windupdates.com (HKLM)
O15 - Trusted Zone: *.skoobidoo.com (HKLM)
O15 - Trusted Zone: *.slotchbar.com (HKLM)
O15 - Trusted IP range: 81.222.131.59
O17 - HKLM\System\CCS\Services\VxD\MSTCP: NameServer = 69.50.188.180,85.255.112.5



Also my AVG keeps locating:

C:\_RESTORE\TEMP\A0000029.CPY Trojan Horse Clicker.FR
everytime I heal it, it comes back as soon as I restart my PC, even when I've disabled restore. Can I just delete this file?

BC AdBot (Login to Remove)

 


#2 OldTimer

OldTimer

    Malware Expert


  • Members
  • 11,092 posts
  • OFFLINE
  •  
  • Gender:Male
  • Location:North Carolina
  • Local time:01:31 AM

Posted 23 July 2005 - 06:25 PM

Hello Marci4 and welcome to the BC malware forum. After reviewing your log I see a few items that require our attention. Please print these directions and then proceed with the following steps in order.

Step #1

Download CCleaner and install it but do not run it yet.

Important
Your copy of HijackThis needs to be in a folder of it's own. If it is run from Temporary folders the backups and HijackThis itself could be accidentally deleted if the Temporary folders are cleaned. If it is run from the desktop then the backup files and folders can clutter up the desktop and be accidentally deleted. If it is run from inside a compressed file then the backups are not created at all.
  • Please open My Computer
  • Double-click on Local Disk (C:)
  • Click on the File menu, point to New and then click on Folder. Name the folder 'HijackThis' or 'HJT'.
  • Unzip to or copy and paste HijackThis.exe to the new folder (do not run HijackThis directly out of the sfx or compressed file).
Step #2

Start HijackThis and click the Scan button to perform a scan. Look for the following items and click in the checkbox in front of each item to select it:R1 - HKCU\Software\Microsoft\Internet Explorer\Main,SearchURL = http://www.clickyestoenter.net/ie/
O15 - Trusted Zone: *.windupdates.com
O15 - Trusted Zone: *.skoobidoo.com
O15 - Trusted Zone: *.slotchbar.com
O15 - Trusted Zone: *.windupdates.com (HKLM)
O15 - Trusted Zone: *.skoobidoo.com (HKLM)
O15 - Trusted Zone: *.slotchbar.com (HKLM)
O15 - Trusted IP range: 81.222.131.59
O17 - HKLM\System\CCS\Services\VxD\MSTCP: NameServer = 69.50.188.180,85.255.112.5

Now close ALL open windows except HijackThis and click the Fix Checked button to finish the repair.

Step #3

Start CCleaner and click on the Run Cleaner button in the lower right-hand corner. When it is finished close CCleaner.

Step #4

Reboot normally and run at least 2 of the following on-line virus scans:Trend Micro Housecall
BitDefender On-Line Virus Scan
Panda ActiveScan
eTrust Antivirus Web Scanner
Make sure that you choose "fix", "clean" or "autoclean". If you have any files that cannot be automatically disinfected or quarantined then you will need to delete them manually.

Step #5

AdAware SE v1.06

Download, install, update, configure and run a scan with Ad-aware SE v1.06:
  • Download and Install AdAware SE Personal, keeping the default options. However, some of the settings will need to be changed before your first scan.
  • Close ALL windows except Ad-Aware SE.
  • Click on the‘world’ icon at the top right of the Ad-Aware SE window and let AdAware SE update the reference list for the adware and malware.
  • Once the update is finished click on the ‘Gear’ icon (second from the left at the top of the window) to access the preferences/settings window:
    • In the ‘General’ window make sure the following are selected in green:
      • Under Safety:
        • Automatically save log-file
      • Automatically quarantine objects prior to removal
      • Safe Mode (always request confirmation)
    • Under Definitions:
      • Prompt to update outdated definitions - set the number of days
  • Click on the ‘Scanning’ button on the left and select in green:
    • Under Driver, Folders & Files:
      • Scan Within Archives
    • Under Select drives & folders to scan:
      • choose all hard drives
    • Under Memory & Registry: all green
      • Scan Active Processes
      • Scan Registry
      • Deep Scan Registry
      • Scan my IE favorites for banned URL’s
      • Scan my Hosts file
  • Click on the ‘Advanced’ button on the left and select in green:
    • Under Shell Integration:
      • Move deleted files to recycle bin
    • Under Logfile Detail Level: all green
      • include addtional object information
      • DESELECT - include negligible objects information
      • include environment information
    • Under Alternate Data Streams:
      • Don't log streams smaller than 0 bytes
      • Don't log ADS with the following names: CA_INOCULATEIT
  • Click the ‘Tweak’ button and select in green:
    • Under ‘Scanning Engine’:
      • Unload recognized processes during scanning
      • Scan registry for all users instead of current user only
    • Under ‘Cleaning Engine’:
      • Let Windows remove files in use at next reboot
    • Under Log Files:
      • Include basic Ad-aware SE settings in logfile
      • Include additional Ad-aware SE settings in logfile
      • Please do not check: Include Module list in logfile
  • Click on ‘Proceed’ to save the settings.
  • Click ‘Start’
  • Choose 'Perform Full System Scan'
  • DESELECT "Search for negligible risk entries", as negligible risk entries (MRU's) are not considered to be a threat.
  • Click ‘Next’ and Ad-Aware SE will scan your hard drive(s) with the options you have selected and clean automatically.
  • If Ad-Aware SE finds bad entries, you will receive a list of what it found in the window.
  • Right-click on the list and choose Select All
  • Click the Next button to finish removing the items that were found
  • When finished, REBOOT to complete the removal of what Ad-Aware SE found
Step #6

OK. Reboot your computer normally, start HijackThis and perform a new scan. Use the Add Reply button to post your new log file back here along with details of any problems you encountered performing the above steps and I will review it when it comes in. At this time, do not worry about the Restore points. We will clean those out when we are finished.

OT
I do not respond to PM's requesting help. That's what the forums are here for. Please use them so that others may benefit from your questions and the responses you receive.
OldTimer

Posted Image

#3 Marci4

Marci4
  • Topic Starter

  • Members
  • 18 posts
  • OFFLINE
  •  
  • Local time:12:31 AM

Posted 26 July 2005 - 09:33 PM

HI, thanks so much for your help. I've done everything as listed. I still keep getting this message from AVG

Trojan horse Clicker.FR in C:\Windows\SYSTEM|RDSNDIN.EXE

here is my new HJT log

Logfile of HijackThis v1.99.1
Scan saved at 12:30:31 PM, on 27/07/2005
Platform: Windows ME (Win9x 4.90.3000)
MSIE: Internet Explorer v5.50 (5.50.4134.0100)

Running processes:
C:\WINDOWS\SYSTEM\KERNEL32.DLL
C:\WINDOWS\SYSTEM\MSGSRV32.EXE
C:\WINDOWS\SYSTEM\MPREXE.EXE
C:\WINDOWS\SYSTEM\MSTASK.EXE
C:\WINDOWS\SYSTEM\mmtask.tsk
C:\WINDOWS\SYSTEM\RESTORE\STMGR.EXE
C:\WINDOWS\EXPLORER.EXE
C:\WINDOWS\TASKMON.EXE
C:\WINDOWS\SYSTEM\SYSTRAY.EXE
C:\WINDOWS\LOADQM.EXE
C:\PROGRAM FILES\ACD SYSTEMS\DEVDETECT\DEVDETECT.EXE
C:\PROGRAM FILES\GRISOFT\AVG FREE\AVGCC.EXE
C:\PROGRAM FILES\GRISOFT\AVG FREE\AVGAMSVR.EXE
C:\WINDOWS\SYSTEM\WMIEXE.EXE
C:\PROGRAM FILES\WEBROOT\SPY SWEEPER\SPYSWEEPER.EXE
C:\PROGRAM FILES\PANICWARE\POP-UP STOPPER FREE EDITION\PSFREE.EXE
C:\PROGRAM FILES\WEBROOT\SPY SWEEPER\WRSSSDK.EXE
C:\WINDOWS\SYSTEM\RNAAPP.EXE
C:\WINDOWS\SYSTEM\TAPISRV.EXE
C:\WINDOWS\SYSTEM\DDHELP.EXE
C:\WINDOWS\TEMP\TD_0001.DIR\HIJACKTHIS.EXE

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://www.yahoo.com
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.emailcash.com.au
O3 - Toolbar: @msdxmLC.dll,-1@1033,&Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINDOWS\SYSTEM\MSDXM.OCX
O4 - HKLM\..\Run: [ScanRegistry] C:\WINDOWS\scanregw.exe /autorun
O4 - HKLM\..\Run: [TaskMonitor] C:\WINDOWS\taskmon.exe
O4 - HKLM\..\Run: [SystemTray] SysTray.Exe
O4 - HKLM\..\Run: [LoadQM] loadqm.exe
O4 - HKLM\..\Run: [Camera Detector] C:\PROGRA~1\ACDSYS~1\DEVDET~1\DEVDET~1.EXE -autorun
O4 - HKLM\..\Run: [LoadPowerProfile] Rundll32.exe powrprof.dll,LoadCurrentPwrScheme
O4 - HKLM\..\Run: [AVG7_CC] C:\PROGRA~1\GRISOFT\AVGFRE~1\AVGCC.EXE /STARTUP
O4 - HKLM\..\Run: [AVG7_AMSVR] C:\PROGRA~1\GRISOFT\AVGFRE~1\AVGAMSVR.EXE
O4 - HKLM\..\Run: [SpySweeper] "C:\PROGRAM FILES\WEBROOT\SPY SWEEPER\SPYSWEEPER.EXE" /startintray
O4 - HKLM\..\RunServices: [LoadPowerProfile] Rundll32.exe powrprof.dll,LoadCurrentPwrScheme
O4 - HKLM\..\RunServices: [SchedulingAgent] mstask.exe
O4 - HKLM\..\RunServices: [*StateMgr] C:\WINDOWS\System\Restore\StateMgr.exe
O4 - HKCU\..\Run: [PopUpStopperFreeEdition] "C:\PROGRAM FILES\PANICWARE\POP-UP STOPPER FREE EDITION\PSFREE.EXE"
O4 - HKCU\..\RunServices: [PopUpStopperFreeEdition] "C:\PROGRAM FILES\PANICWARE\POP-UP STOPPER FREE EDITION\PSFREE.EXE"
O4 - Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office\OSA9.EXE
O6 - HKCU\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O9 - Extra button: ICQ Pro - {6224f700-cba3-4071-b251-47cb894244cd} - C:\PROGRA~1\ICQ\ICQ.exe
O9 - Extra 'Tools' menuitem: ICQ - {6224f700-cba3-4071-b251-47cb894244cd} - C:\PROGRA~1\ICQ\ICQ.exe
O9 - Extra button: (no name) - {85d1f590-48f4-11d9-9669-0800200c9a66} - %windir%\bdoscandel.exe (file missing)
O9 - Extra 'Tools' menuitem: Uninstall BitDefender Online Scanner v8 - {85d1f590-48f4-11d9-9669-0800200c9a66} - %windir%\bdoscandel.exe (file missing)
O16 - DPF: {5D86DDB5-BDF9-441B-9E9E-D4730F4EE499} (BDSCANONLINE Control) - http://www.bitdefender.com/scan8/oscan8.cab
O16 - DPF: {9A9307A0-7DA4-4DAF-B042-5009F29E09E1} (ActiveScan Installer Class) - http://www.pandasoftware.com/activescan/as5/asinst.cab
O16 - DPF: {74D05D43-3236-11D4-BDCD-00C04F9A3B61} (HouseCall Control) - http://a840.g.akamai.net/7/840/537/2004061...all/xscan53.cab
O16 - DPF: {7B297BFD-85E4-4092-B2AF-16A91B2EA103} (WScanCtl Class) - http://www3.ca.com/securityadvisor/virusinfo/webscan.cab


Thanks
Marci4

#4 OldTimer

OldTimer

    Malware Expert


  • Members
  • 11,092 posts
  • OFFLINE
  •  
  • Gender:Male
  • Location:North Carolina
  • Local time:01:31 AM

Posted 27 July 2005 - 08:53 AM

Hi Marci4. the log is clean. Good job! Let's try a different scanner to see if there is anything that is not showing up in the HijackThis log.

Download WinPFind.zip and unzip the contents to the C:\ folder.

Start in Safe Mode Using the F8 method:
  • Restart the computer.
  • As soon as the BIOS is loaded begin tapping the F8 key until the boot menu appears.
  • Use the arrow keys to select the Safe Mode menu item.
  • Press the Enter key.
Locate the c:\winpfind\winpfind.exe file and double-click it to run it. Now click the Start Scan button to begin the scan.

When the scan is complete reboot normally and post the WinPFind.txt file (located in the WinPFind folder) back here so I can review it.

OT
I do not respond to PM's requesting help. That's what the forums are here for. Please use them so that others may benefit from your questions and the responses you receive.
OldTimer

Posted Image

#5 Marci4

Marci4
  • Topic Starter

  • Members
  • 18 posts
  • OFFLINE
  •  
  • Local time:12:31 AM

Posted 31 July 2005 - 05:40 AM

HI,

I'm really sorry about this, but I tried to:

".... and unzip the contents to the C:\ folder."

and I must be doing it wrong as I can't get it to work. How exactly do I do that?
Sorry again

Thanx
Marci

#6 OldTimer

OldTimer

    Malware Expert


  • Members
  • 11,092 posts
  • OFFLINE
  •  
  • Gender:Male
  • Location:North Carolina
  • Local time:01:31 AM

Posted 31 July 2005 - 11:17 AM

Hi Marci4. Do you have a zip program like ZipCentral or WinZip? If not then you will need one to unzip the file. Here is a link to ZipCentral (it's what I use and it's free):

http://zipcentral.iscool.net/

Just download and install it. Then you can double-click on the WinPFind.zip file to extract the contents.

In addition, a new version of WinPFind has beenn released and you should download the latest version of that also. Here is the link again:

http://www.bleepingcomputer.com/files/winpfind.php

Let me know if you have any further questions.

Cheers.

OT
I do not respond to PM's requesting help. That's what the forums are here for. Please use them so that others may benefit from your questions and the responses you receive.
OldTimer

Posted Image

#7 Marci4

Marci4
  • Topic Starter

  • Members
  • 18 posts
  • OFFLINE
  •  
  • Local time:12:31 AM

Posted 17 August 2005 - 07:16 PM

OMG! I've finaly managed to do it, as you can see it's taken me ages. But thanks soooo much for your elp here.



WARNING: not all files found by this scanner are bad. Consult with a knowledgable person before proceeding.

If you see a message in the titlebar saying "Not responding..." you can ignore it. Windows somethimes displays this message due to the high volume of disk I/O. As long as the hard disk light is flashing, the program is still working properly.

»»»»»»»»»»»»»»»»» Checking Selected Standard Folders »»»»»»»»»»»»»»»»»»»»

Checking %SystemDrive% folder...

Checking %ProgramFilesDir% folder...
PEC2 16/12/2004 3:25:08 PM 12305800 C:\Program Files\e-Record_v401_Setup.EXE

Checking %WinDir% folder...
PECompact2 26/07/2005 11:25:08 AM 15442435 C:\WINDOWS\LPT$VPN.745
qoologic 26/07/2005 11:25:08 AM 15442435 C:\WINDOWS\LPT$VPN.745
SAHAgent 26/07/2005 11:25:08 AM 15442435 C:\WINDOWS\LPT$VPN.745
PECompact2 26/07/2005 11:25:08 AM 15442435 C:\WINDOWS\VPTNFILE.745
qoologic 26/07/2005 11:25:08 AM 15442435 C:\WINDOWS\VPTNFILE.745
SAHAgent 26/07/2005 11:25:08 AM 15442435 C:\WINDOWS\VPTNFILE.745
UPX! 27/07/2005 12:53:28 AM 1044560 C:\WINDOWS\vsapi32.dll
aspack 27/07/2005 12:53:28 AM 1044560 C:\WINDOWS\vsapi32.dll

Checking %System% folder...
UPX! 29/07/2005 12:17:32 AM 45568 C:\WINDOWS\SYSTEM\ntfsnlpa.exe
PTech 14/10/2002 4:31:52 PM 7832 C:\WINDOWS\SYSTEM\lxbbinst.drv
FSG! 16/07/2005 8:25:08 PM 705 C:\WINDOWS\SYSTEM\msexnpfi.exe

Checking %System%\Drivers folder and sub-folders...

Checking the Windows folder for system and hidden files within the last 60 days...
18/08/2005 9:44:50 AM 4694048 C:\WINDOWS\CLASSES.DAT
5/07/2005 4:07:04 PM 192544 C:\WINDOWS\HWINFO.DAT
18/08/2005 9:52:28 AM 1040416 C:\WINDOWS\USER.DAT
18/08/2005 9:49:18 AM 2355232 C:\WINDOWS\SYSTEM.DAT
5/07/2005 4:04:16 PM 23155 C:\WINDOWS\folder.htt
5/07/2005 4:04:16 PM 271 C:\WINDOWS\desktop.ini
14/08/2005 1:56:50 AM 54156 C:\WINDOWS\QTFont.qfn
18/08/2005 9:42:34 AM 25866 C:\WINDOWS\ttfCache
18/08/2005 9:42:24 AM 1196644 C:\WINDOWS\ShellIconCache
5/07/2005 4:04:16 PM 23155 C:\WINDOWS\SYSTEM\folder.htt
5/07/2005 4:04:16 PM 271 C:\WINDOWS\SYSTEM\desktop.ini
5/07/2005 4:02:50 PM 9793 C:\WINDOWS\HELP\windows.GID
15/07/2005 9:50:00 AM 10820 C:\WINDOWS\HELP\nocontnt.GID
5/07/2005 4:02:50 PM 4753 C:\WINDOWS\WEB\wiadev.htt
5/07/2005 4:02:50 PM 18952 C:\WINDOWS\WEB\wiacam.htt
5/07/2005 4:02:50 PM 20150 C:\WINDOWS\WEB\wiastream.htt
5/07/2005 4:02:50 PM 1574 C:\WINDOWS\WEB\wiastyle.css
5/07/2005 4:02:50 PM 2998 C:\WINDOWS\WEB\PICTURES.ICO
5/07/2005 4:02:50 PM 10134 C:\WINDOWS\WEB\CAMERA.ICO
5/07/2005 4:02:50 PM 10134 C:\WINDOWS\WEB\STREAM.ICO
5/07/2005 4:04:18 PM 1535 C:\WINDOWS\WEB\webview.css
5/07/2005 4:04:18 PM 18163 C:\WINDOWS\WEB\controlp.htt
5/07/2005 4:04:18 PM 4780 C:\WINDOWS\WEB\default.htt
5/07/2005 4:04:18 PM 16287 C:\WINDOWS\WEB\nethood.htt
5/07/2005 4:04:20 PM 11034 C:\WINDOWS\WEB\recycle.htt
5/07/2005 4:04:20 PM 6391 C:\WINDOWS\WEB\schedule.htt
5/07/2005 4:04:20 PM 9227 C:\WINDOWS\WEB\dialup.htt
5/07/2005 4:04:20 PM 8246 C:\WINDOWS\WEB\wvleft.bmp
5/07/2005 4:04:20 PM 1749 C:\WINDOWS\WEB\wvleft.gif
5/07/2005 4:04:20 PM 54 C:\WINDOWS\WEB\wvline.gif
5/07/2005 4:04:20 PM 9439 C:\WINDOWS\WEB\wvlogo.gif
5/07/2005 4:04:20 PM 90056 C:\WINDOWS\WEB\classic.bmp
5/07/2005 4:04:20 PM 641 C:\WINDOWS\WEB\classic.htt
5/07/2005 4:04:20 PM 18100 C:\WINDOWS\WEB\folder.bmp
5/07/2005 4:04:20 PM 1031 C:\WINDOWS\WEB\starter.htt
5/07/2005 4:04:20 PM 31080 C:\WINDOWS\WEB\starter.bmp
5/07/2005 4:04:20 PM 18100 C:\WINDOWS\WEB\preview.bmp
5/07/2005 4:04:22 PM 18276 C:\WINDOWS\WEB\imgview.htt
5/07/2005 4:04:22 PM 830 C:\WINDOWS\WEB\deskmovr.htt
5/07/2005 4:04:22 PM 3469 C:\WINDOWS\WEB\safemode.htt
5/07/2005 4:04:22 PM 20510 C:\WINDOWS\WEB\fsresult.htt
5/07/2005 4:04:22 PM 29797 C:\WINDOWS\WEB\standard.htt
5/07/2005 4:04:22 PM 33916 C:\WINDOWS\WEB\webview.js
5/07/2005 4:04:22 PM 2642 C:\WINDOWS\WEB\exclam.gif
5/07/2005 4:04:22 PM 842 C:\WINDOWS\WEB\bullet.gif
5/07/2005 4:04:22 PM 80 C:\WINDOWS\WEB\plushot.gif
5/07/2005 4:04:22 PM 59 C:\WINDOWS\WEB\pluscold.gif
5/07/2005 4:04:22 PM 77 C:\WINDOWS\WEB\minhot.gif
5/07/2005 4:04:22 PM 56 C:\WINDOWS\WEB\mincold.gif
5/07/2005 4:04:22 PM 11870 C:\WINDOWS\WEB\printers.htt
5/07/2005 4:04:24 PM 25217 C:\WINDOWS\WEB\sysroot.htt
5/07/2005 4:04:24 PM 2848 C:\WINDOWS\WEB\brfcase.htt
5/07/2005 4:04:26 PM 11083 C:\WINDOWS\WEB\ftp.htt
5/07/2005 4:04:20 PM 3191 C:\WINDOWS\WEB\folder.htt
18/08/2005 9:44:24 AM 13026 C:\WINDOWS\PCHEALTH\HELPCTR\Database\HelpSessionHistory.stream
18/08/2005 8:38:18 AM 6 C:\WINDOWS\TASKS\SA.DAT
9/08/2005 7:01:10 PM 0 C:\WINDOWS\TEMP\CS67A179AE-3C93-43F7-A869-6111DF507C7C.tmp
9/08/2005 7:01:10 PM 0 C:\WINDOWS\TEMP\CS86C6CBB6-78D1-48BD-8619-AE1A11E6D7DE.tmp
9/08/2005 7:01:10 PM 0 C:\WINDOWS\TEMP\CSDA3FEA02-597E-46BD-894D-D192F71F6E93.tmp
9/08/2005 7:01:10 PM 0 C:\WINDOWS\TEMP\CS35350476-0456-4F98-BECA-68904694C1B2.tmp
9/08/2005 7:01:10 PM 0 C:\WINDOWS\TEMP\CS08A91EF9-94B1-447B-B743-78A74229A59F.tmp
9/08/2005 7:01:10 PM 0 C:\WINDOWS\TEMP\CSBAF07993-8A29-487C-B8BD-BF32333453B7.tmp
9/08/2005 7:01:10 PM 0 C:\WINDOWS\TEMP\CS5191FCFE-9A89-4A80-9A7E-0C7E2D8A9FA0.tmp
9/08/2005 7:01:10 PM 0 C:\WINDOWS\TEMP\CS1D1BD214-2CF6-4287-9E00-8A080D568F36.tmp
9/08/2005 7:01:10 PM 0 C:\WINDOWS\TEMP\CS5ECE9A8B-D504-4A62-B950-424886CC325C.tmp
9/08/2005 7:01:10 PM 0 C:\WINDOWS\TEMP\CS03B2B7B5-B59B-4C89-9405-E3B3A9F25522.tmp
9/08/2005 7:01:10 PM 0 C:\WINDOWS\TEMP\CSABC22FA9-9C23-4B7C-BBA5-45BD07AD3581.tmp
9/08/2005 7:01:10 PM 0 C:\WINDOWS\TEMP\CS57C8D31E-D61C-4E44-8439-90C33A994E81.tmp
9/08/2005 7:01:10 PM 0 C:\WINDOWS\TEMP\CSFDD76388-2058-4696-B3CE-68A2ECAB3EB4.tmp
9/08/2005 7:01:10 PM 0 C:\WINDOWS\TEMP\CSC1A4761E-8276-483D-9D85-C862AECB33B1.tmp
9/08/2005 7:01:10 PM 0 C:\WINDOWS\TEMP\CS0F22332A-BFA1-4E8A-9F11-2E2CB70543CD.tmp
9/08/2005 7:01:10 PM 0 C:\WINDOWS\TEMP\CS97D1DE27-E53A-479C-950D-ED3FE6A7CA20.tmp
9/08/2005 7:01:10 PM 0 C:\WINDOWS\TEMP\CSC26212F0-8BB2-4BF6-B6CA-0A872F55ACFE.tmp
9/08/2005 7:01:10 PM 0 C:\WINDOWS\TEMP\CSFF505C0E-477D-4F83-AF3A-8A02AF5C2F54.tmp
9/08/2005 7:01:10 PM 0 C:\WINDOWS\TEMP\CS8D1CE539-31F7-4B36-9C36-CDC4EB97E108.tmp
9/08/2005 7:01:10 PM 0 C:\WINDOWS\TEMP\CSCD529814-DE78-4951-BD44-BB90E09A7F69.tmp
9/08/2005 7:01:10 PM 0 C:\WINDOWS\TEMP\CS98D1F09F-0A8B-4D75-9551-9193DC5FDDE9.tmp
9/08/2005 7:01:10 PM 0 C:\WINDOWS\TEMP\CS8B538AE7-C71A-40F6-9215-A394451D60DE.tmp
9/08/2005 7:01:10 PM 0 C:\WINDOWS\TEMP\CSAF4AEC99-5F50-45E4-AA2D-BB5D7C777EC3.tmp
9/08/2005 7:01:10 PM 0 C:\WINDOWS\TEMP\CS66AC6224-2A18-4E1F-A44F-5E57E7188A17.tmp
9/08/2005 7:01:10 PM 0 C:\WINDOWS\TEMP\CS188D6373-F77A-4911-A76A-17C8D0C44ECA.tmp
9/08/2005 7:01:10 PM 0 C:\WINDOWS\TEMP\CSDA355DD9-EEE1-4FBC-A02C-DB6C625FEB6E.tmp
9/08/2005 7:01:10 PM 0 C:\WINDOWS\TEMP\CS553AB118-D0FF-472E-A845-473F2A251711.tmp
9/08/2005 7:01:10 PM 0 C:\WINDOWS\TEMP\CS4156D7A3-68BF-413E-8DE4-53D6C070F567.tmp
9/08/2005 7:01:10 PM 0 C:\WINDOWS\TEMP\CS881274C5-957D-4C6C-AD31-59E87649F3E1.tmp
9/08/2005 7:01:10 PM 0 C:\WINDOWS\TEMP\CS9AD52901-F212-424B-AA8F-CC1C30250234.tmp
9/08/2005 7:01:10 PM 0 C:\WINDOWS\TEMP\CS9603BE5A-7590-4713-A596-852039C1BC32.tmp
9/08/2005 7:01:10 PM 0 C:\WINDOWS\TEMP\CSC5BFB764-0660-4CB6-819E-8EFEDCFAF925.tmp
9/08/2005 7:01:32 PM 0 C:\WINDOWS\TEMP\CS2D12D590-BD45-4EF5-A118-A0E90411E3A6.tmp
9/08/2005 7:01:32 PM 0 C:\WINDOWS\TEMP\CS59381B47-063B-4523-8899-9F7C7A54B0B9.tmp
9/08/2005 7:01:32 PM 0 C:\WINDOWS\TEMP\CS8E12C1D7-AA4E-41CE-A98B-C2DE17BE5F9E.tmp
9/08/2005 7:01:32 PM 0 C:\WINDOWS\TEMP\CS0F040063-D1D1-44FD-B3EF-AB4B0371163D.tmp
9/08/2005 7:01:32 PM 0 C:\WINDOWS\TEMP\CSCB97C28E-E588-490C-A802-C7D569782AE3.tmp
9/08/2005 7:01:32 PM 0 C:\WINDOWS\TEMP\CS937491FE-50F9-4B60-A7FA-0D615EB05D3C.tmp
9/08/2005 7:01:32 PM 0 C:\WINDOWS\TEMP\CS63B56189-1D6F-4DD0-AD29-1CB9CC01D384.tmp
9/08/2005 7:01:32 PM 0 C:\WINDOWS\TEMP\CSE5D0992F-9CFA-4371-A2BA-E874BB6697B3.tmp
9/08/2005 7:01:32 PM 0 C:\WINDOWS\TEMP\CS89693CD3-81D7-4D94-AB6F-8378DF57FAD9.tmp
9/08/2005 7:01:32 PM 0 C:\WINDOWS\TEMP\CSDE6DEB4C-566E-4D0A-B7F3-32037EF25A2B.tmp
9/08/2005 7:01:32 PM 0 C:\WINDOWS\TEMP\CSCA19211C-4428-4ED0-AAE0-974EC602959F.tmp
9/08/2005 7:01:32 PM 0 C:\WINDOWS\TEMP\CS1D1936BC-F787-4958-B982-4332CA054FBA.tmp
9/08/2005 7:01:32 PM 0 C:\WINDOWS\TEMP\CS24F1F05F-1067-41C7-BEAC-45789738657E.tmp
9/08/2005 7:01:32 PM 0 C:\WINDOWS\TEMP\CS26B58545-F4F4-49AB-859C-53BC152583C6.tmp
9/08/2005 7:01:32 PM 0 C:\WINDOWS\TEMP\CSDF9D59CF-EC8E-40B0-A1D2-6C914E0A1951.tmp
9/08/2005 7:01:32 PM 0 C:\WINDOWS\TEMP\CSA1E6B887-EC0C-446D-82B1-763FD03A82C2.tmp
9/08/2005 7:01:32 PM 0 C:\WINDOWS\TEMP\CS6FD22086-BAEC-45F1-905F-FCDD67DA9F09.tmp
9/08/2005 7:01:32 PM 0 C:\WINDOWS\TEMP\CS992AC8F3-FD45-4C6A-A15C-C0E83D04FB86.tmp
9/08/2005 7:01:32 PM 0 C:\WINDOWS\TEMP\CS9F066697-D757-4FB0-847D-2341EA37CD7E.tmp
9/08/2005 7:01:32 PM 0 C:\WINDOWS\TEMP\CSF26B6D95-1DBB-4DD9-915E-18B14FCB83B1.tmp
9/08/2005 7:01:32 PM 0 C:\WINDOWS\TEMP\CSE4852E05-10F4-4E10-871C-084813A7385D.tmp
9/08/2005 7:01:32 PM 0 C:\WINDOWS\TEMP\CSB5D72C5D-E990-4F47-9C17-7A71D4B28D3B.tmp
9/08/2005 7:01:32 PM 0 C:\WINDOWS\TEMP\CSC8D82C27-BE98-401E-9C20-86F97411E43F.tmp
9/08/2005 7:01:32 PM 0 C:\WINDOWS\TEMP\CSC30EE08F-AAA8-4CBF-BBC6-A2B01379AB49.tmp
9/08/2005 7:01:32 PM 0 C:\WINDOWS\TEMP\CS2A3AD399-5CB1-465C-A8DA-CB603328B6BC.tmp
9/08/2005 7:01:32 PM 0 C:\WINDOWS\TEMP\CSBEDA2F4E-1AF9-478A-8840-2301413A1F4D.tmp
9/08/2005 7:01:32 PM 0 C:\WINDOWS\TEMP\CS02D55269-73B3-4801-80CA-451445A0CAE8.tmp
9/08/2005 7:01:32 PM 0 C:\WINDOWS\TEMP\CS98E2F09F-5A75-418A-ACE6-F836623DDABB.tmp
9/08/2005 7:01:32 PM 0 C:\WINDOWS\TEMP\CSAEFAC004-15CE-49AB-9C56-867B22FCDC5F.tmp
9/08/2005 7:01:32 PM 0 C:\WINDOWS\TEMP\CSD69A6D5B-ED90-4224-8ADC-93FBD16C5C5F.tmp
9/08/2005 7:01:32 PM 0 C:\WINDOWS\TEMP\CSD2D78E15-85DD-49A9-AA08-822A13F7F80B.tmp
9/08/2005 7:01:32 PM 0 C:\WINDOWS\TEMP\CS8D1A0728-F9DA-4B22-A0D5-8B87B6E90D18.tmp
9/08/2005 7:01:32 PM 0 C:\WINDOWS\TEMP\CSACE7F9D4-537D-4C51-AD04-B95314819CEF.tmp
9/08/2005 7:01:32 PM 0 C:\WINDOWS\TEMP\CSC2FA7BE8-E08E-40A3-A249-79E85F14F825.tmp
9/08/2005 7:01:32 PM 0 C:\WINDOWS\TEMP\CS0DB86E99-8D39-4018-885A-4DFCA2F0F9BA.tmp
9/08/2005 7:01:32 PM 0 C:\WINDOWS\TEMP\CS29300C64-3217-47E0-99F7-DBEF172CE263.tmp
9/08/2005 7:01:32 PM 0 C:\WINDOWS\TEMP\CSD7C46855-92A5-4AF3-B71E-D016DECC0442.tmp
9/08/2005 7:01:32 PM 0 C:\WINDOWS\TEMP\CSD39D486D-30BF-4FC2-9FCD-5284805E4EB4.tmp
9/08/2005 7:01:32 PM 0 C:\WINDOWS\TEMP\CSD9CF7568-C534-4941-8389-4EC9D556EA52.tmp
9/08/2005 7:01:32 PM 0 C:\WINDOWS\TEMP\CS153E1B7C-16B3-4361-8D92-E793137D174F.tmp
9/08/2005 7:01:32 PM 0 C:\WINDOWS\TEMP\CSF3A59CF7-C70D-49A0-8AFC-AB0FA9421263.tmp
9/08/2005 7:01:32 PM 0 C:\WINDOWS\TEMP\CSA472FF9E-06BC-4456-845F-354D8B6E4B99.tmp
9/08/2005 7:01:32 PM 0 C:\WINDOWS\TEMP\CS5D214571-047B-49A3-8306-3833DAEA99C1.tmp
9/08/2005 7:01:32 PM 0 C:\WINDOWS\TEMP\CS5017A415-75B4-4CAE-AD58-61311916645E.tmp
9/08/2005 7:01:32 PM 0 C:\WINDOWS\TEMP\CS5C23034E-A1A0-4D20-B602-A3F42FD6C6A2.tmp
9/08/2005 7:01:32 PM 0 C:\WINDOWS\TEMP\CSCE1ACBF8-DA67-4FAE-83BF-00F7E276F1BE.tmp
9/08/2005 7:01:32 PM 0 C:\WINDOWS\TEMP\CS433EADEA-9B70-427C-B64C-7ACFB8F00955.tmp
9/08/2005 7:01:32 PM 0 C:\WINDOWS\TEMP\CS8258805B-C537-40FF-AAA7-64F415AF57A6.tmp
9/08/2005 7:01:32 PM 0 C:\WINDOWS\TEMP\CS094CEA5F-564B-4CC8-B54D-6970092C0C7F.tmp
9/08/2005 7:01:32 PM 0 C:\WINDOWS\TEMP\CS517E5078-7331-4297-8283-D77574A2EB24.tmp
9/08/2005 7:01:32 PM 0 C:\WINDOWS\TEMP\CS41BC3D6D-4D99-4274-8664-D95DE493A05D.tmp
9/08/2005 7:01:32 PM 0 C:\WINDOWS\TEMP\CS311CCC87-E77D-46B0-956E-529B2654FDF6.tmp
9/08/2005 7:01:32 PM 0 C:\WINDOWS\TEMP\CSEC96A483-A780-4622-ACC0-82FC4D59D894.tmp
9/08/2005 7:01:32 PM 0 C:\WINDOWS\TEMP\CS24BDEB0F-D209-4FE0-8EBD-81E94F98A911.tmp
9/08/2005 7:01:32 PM 0 C:\WINDOWS\TEMP\CSB51CBB82-D936-4746-BECC-A3A7504E410F.tmp
9/08/2005 7:01:32 PM 0 C:\WINDOWS\TEMP\CS214FC300-2BA0-4D3F-877B-609E5F3D210D.tmp
9/08/2005 7:01:32 PM 0 C:\WINDOWS\TEMP\CSEF980BA7-DD67-40F9-B384-655570FB3356.tmp
9/08/2005 7:01:32 PM 0 C:\WINDOWS\TEMP\CSEC8A0600-6014-4FFE-A658-E1BE2C96E41A.tmp
9/08/2005 7:01:32 PM 0 C:\WINDOWS\TEMP\CS01D968EB-52EC-426F-BB48-BB792B2787C1.tmp
9/08/2005 7:01:32 PM 0 C:\WINDOWS\TEMP\CS400A663A-CADE-4334-B9FC-D43B1EE51AF2.tmp
9/08/2005 7:01:32 PM 0 C:\WINDOWS\TEMP\CS7399412A-E82F-40DB-84A5-307C76DCD35D.tmp
9/08/2005 7:01:32 PM 0 C:\WINDOWS\TEMP\CSD60BB073-B694-4D16-8A4A-E4F8F6218E82.tmp
9/08/2005 7:01:32 PM 0 C:\WINDOWS\TEMP\CSB7B2524D-D22D-4679-8EFF-A7EAA94F0927.tmp
9/08/2005 7:01:32 PM 0 C:\WINDOWS\TEMP\CSA645536D-9C78-4341-8A2A-8276809F3604.tmp
9/08/2005 7:01:32 PM 0 C:\WINDOWS\TEMP\CS866485BD-6147-4E16-805F-ABE6B1AF0216.tmp
9/08/2005 7:01:32 PM 0 C:\WINDOWS\TEMP\CS47FFB66B-F3E0-4F81-A22E-46E415954458.tmp
9/08/2005 7:01:32 PM 0 C:\WINDOWS\TEMP\CS20901B0A-9D4E-4129-8577-F71AC6F7EFE8.tmp
9/08/2005 7:01:32 PM 0 C:\WINDOWS\TEMP\CS0C5ADF71-0865-4BAC-A803-886A16289B31.tmp
9/08/2005 7:01:32 PM 0 C:\WINDOWS\TEMP\CS8D582573-8285-4C94-93A3-1E6316FF5ABC.tmp
9/08/2005 7:05:24 PM 0 C:\WINDOWS\TEMP\CSCEB52DD0-AFC9-4A8C-8A6C-EFF1704E3E2C.tmp
9/08/2005 7:05:24 PM 0 C:\WINDOWS\TEMP\CS8860546D-34DE-4726-9B2D-1571BBBA18A3.tmp
9/08/2005 7:05:24 PM 0 C:\WINDOWS\TEMP\CSAE3B88DF-1DCA-4741-BA28-C4E63D38B80F.tmp
9/08/2005 7:05:24 PM 0 C:\WINDOWS\TEMP\CSF5046B15-9941-4E7A-A456-C61597869004.tmp
9/08/2005 7:05:24 PM 0 C:\WINDOWS\TEMP\CS105ABDA1-C720-42A3-A2D4-E7EAD5506F79.tmp
9/08/2005 7:05:24 PM 0 C:\WINDOWS\TEMP\CS9E12D83A-3B6A-4279-A3B8-633C9E9F8E18.tmp
9/08/2005 7:05:24 PM 0 C:\WINDOWS\TEMP\CS0F46096D-7073-4075-A1BD-7FAE680FB902.tmp
9/08/2005 7:05:24 PM 0 C:\WINDOWS\TEMP\CS77BD85DB-35BF-49FE-B65A-22CDE43B23A8.tmp
9/08/2005 7:05:24 PM 0 C:\WINDOWS\TEMP\CSD99E60F2-B4CD-48B4-97D3-334E82595AAF.tmp
9/08/2005 7:05:24 PM 0 C:\WINDOWS\TEMP\CS1995425A-FE12-4060-A586-A8D252458646.tmp
9/08/2005 7:05:24 PM 0 C:\WINDOWS\TEMP\CS2B448033-0B1F-4755-B0FB-6521991A11EA.tmp
9/08/2005 7:05:24 PM 0 C:\WINDOWS\TEMP\CS49A4ADEA-B8E2-475F-95C0-511DC7B1F310.tmp
9/08/2005 7:05:24 PM 0 C:\WINDOWS\TEMP\CSD9EA952D-D788-48FB-8293-B762AFBCCEB9.tmp
9/08/2005 7:05:24 PM 0 C:\WINDOWS\TEMP\CSB41AA1D1-0069-4B75-AF7F-47E85B83B7E3.tmp
9/08/2005 7:05:24 PM 0 C:\WINDOWS\TEMP\CSF3B258E2-9D3A-452D-9232-5C333425275F.tmp
9/08/2005 7:05:24 PM 0 C:\WINDOWS\TEMP\CSF89CDF52-C434-4588-A4D2-0EB2143C3C41.tmp
9/08/2005 7:05:24 PM 0 C:\WINDOWS\TEMP\CS91B4D950-8CA7-46D5-B144-940C23494C2F.tmp
9/08/2005 7:05:24 PM 0 C:\WINDOWS\TEMP\CS68F244D4-D171-4766-84C5-F240B1DA24F2.tmp
9/08/2005 7:05:24 PM 0 C:\WINDOWS\TEMP\CSA2786F60-6662-43F1-9BED-8BCD2F55D625.tmp
9/08/2005 7:05:24 PM 0 C:\WINDOWS\TEMP\CS7D949131-A7E9-4B7B-B38F-F19CE609F193.tmp
9/08/2005 7:05:24 PM 0 C:\WINDOWS\TEMP\CS171B596F-2733-48A0-903A-23E4F574DB18.tmp
9/08/2005 7:05:24 PM 0 C:\WINDOWS\TEMP\CS49478F7B-DF8E-4F44-A6AA-73B543DFC2C9.tmp
9/08/2005 7:05:24 PM 0 C:\WINDOWS\TEMP\CS4129EB5D-8AB2-4DDA-86C8-D4785B4A1C1A.tmp
9/08/2005 7:05:24 PM 0 C:\WINDOWS\TEMP\CSC642CE8D-78E6-47DA-931B-95B266C33BE5.tmp
9/08/2005 7:05:24 PM 0 C:\WINDOWS\TEMP\CSFCF89B45-8A1D-4469-81C1-1AC44E9498CA.tmp
9/08/2005 7:05:24 PM 0 C:\WINDOWS\TEMP\CS127129CB-E8EA-4335-BEE5-51F86EDA855B.tmp
9/08/2005 7:05:24 PM 0 C:\WINDOWS\TEMP\CSA5F8407D-406E-4926-8379-7039E91CA528.tmp
9/08/2005 7:05:24 PM 0 C:\WINDOWS\TEMP\CS5FF7061E-9738-4E79-ACE1-460823C8152C.tmp
9/08/2005 7:05:24 PM 0 C:\WINDOWS\TEMP\CS51BD6470-73CC-42CB-A13D-DEC024C70350.tmp
9/08/2005 7:05:24 PM 0 C:\WINDOWS\TEMP\CSA3C8F846-87FB-4868-981C-09944FC6DFD0.tmp
9/08/2005 7:05:24 PM 0 C:\WINDOWS\TEMP\CSDCD2CB01-314E-41E4-A5B9-379D3F0431B0.tmp
9/08/2005 7:05:24 PM 0 C:\WINDOWS\TEMP\CSF5E1275B-537B-40ED-8E83-03AE1266B8B6.tmp
9/08/2005 7:10:38 PM 0 C:\WINDOWS\TEMP\CSEC4788F8-6B9C-498D-9519-929C1FF29649.tmp
9/08/2005 7:10:38 PM 0 C:\WINDOWS\TEMP\CS4AAD1C11-5761-4525-A041-181F14CCBB90.tmp
9/08/2005 7:10:38 PM 0 C:\WINDOWS\TEMP\CSE3AD8867-1837-457B-ACD4-DF0E2BDCFC06.tmp
9/08/2005 7:10:38 PM 0 C:\WINDOWS\TEMP\CSBAABE5AA-3965-4AA0-871E-F5202D1B462D.tmp
9/08/2005 7:10:38 PM 0 C:\WINDOWS\TEMP\CSBF20D627-3260-41EE-B5F7-64DD4419CA73.tmp
9/08/2005 7:10:38 PM 0 C:\WINDOWS\TEMP\CS56ACF3E9-F956-408F-ACFA-E1568D2E9C41.tmp
9/08/2005 7:10:38 PM 0 C:\WINDOWS\TEMP\CS0CA69294-9FB0-4B73-99C6-AFA1F06C24D6.tmp
9/08/2005 7:10:38 PM 0 C:\WINDOWS\TEMP\CS100EFBE1-2FB3-42D0-B315-818D54CA7A11.tmp
9/08/2005 7:10:38 PM 0 C:\WINDOWS\TEMP\CSBC57D636-7E33-43F4-8EF0-4129E6B2C56E.tmp
9/08/2005 7:10:38 PM 0 C:\WINDOWS\TEMP\CS5061D2AC-738A-429C-8AF1-3C0F139A7A3F.tmp
9/08/2005 7:10:38 PM 0 C:\WINDOWS\TEMP\CS1BE66A5E-6D38-4BE0-951D-298141BFA6AD.tmp
9/08/2005 7:10:38 PM 0 C:\WINDOWS\TEMP\CSAD00973D-1698-4354-9492-90B1D6CB32AB.tmp
9/08/2005 7:10:38 PM 0 C:\WINDOWS\TEMP\CSECB66C46-8C6F-4212-B2E2-2416F38BA939.tmp
9/08/2005 7:10:38 PM 0 C:\WINDOWS\TEMP\CSD8FD5916-405F-4C18-A821-9CA0195C9E11.tmp
9/08/2005 7:10:38 PM 0 C:\WINDOWS\TEMP\CSB8695BFD-8A0D-4A74-8D7B-A4C579716794.tmp
9/08/2005 7:10:38 PM 0 C:\WINDOWS\TEMP\CSC66C7CB4-6F3D-4D8F-824E-40C46D05DEB3.tmp
9/08/2005 7:10:38 PM 0 C:\WINDOWS\TEMP\CSEF980911-9F0E-4F81-B9D5-6B78E9544823.tmp
9/08/2005 7:10:38 PM 0 C:\WINDOWS\TEMP\CS1AA9747F-92A9-4274-9670-965299DE9922.tmp
9/08/2005 7:10:38 PM 0 C:\WINDOWS\TEMP\CS0CAAB94E-B6E9-45E8-B5FF-E4A8C1F03B87.tmp
9/08/2005 7:10:38 PM 0 C:\WINDOWS\TEMP\CS5447E7F9-8CDE-475A-95A2-314ADD9F715E.tmp
9/08/2005 7:10:38 PM 0 C:\WINDOWS\TEMP\CS831FC599-F7D4-413A-91E5-4C64A4B69B2B.tmp
9/08/2005 7:10:38 PM 0 C:\WINDOWS\TEMP\CSF7493D3F-1A17-4823-A0B0-1491BF0FF83B.tmp
9/08/2005 7:10:38 PM 0 C:\WINDOWS\TEMP\CS322FC73E-953B-4744-90EA-9EB1F4FDCCC4.tmp
9/08/2005 7:10:38 PM 0 C:\WINDOWS\TEMP\CS90C5DC70-D454-436B-AA77-B43331F7CE05.tmp
9/08/2005 7:10:38 PM 0 C:\WINDOWS\TEMP\CS7E6C7B23-B554-45C9-960B-1DFD8E8F06FE.tmp
9/08/2005 7:10:38 PM 0 C:\WINDOWS\TEMP\CS1E918857-34F1-44D1-A0F0-65BC8B74E46A.tmp
9/08/2005 7:10:38 PM 0 C:\WINDOWS\TEMP\CS7E0A57ED-6CB9-4A94-BEE9-B623A2B64D47.tmp
9/08/2005 7:10:38 PM 0 C:\WINDOWS\TEMP\CS7BF22C2D-38C3-46EB-8772-EF848D83CFE7.tmp
9/08/2005 7:10:38 PM 0 C:\WINDOWS\TEMP\CSA3E445CC-C01D-4ABB-9E22-3AF265B89C71.tmp
9/08/2005 7:10:38 PM 0 C:\WINDOWS\TEMP\CSA992EAC5-10E4-41BF-8537-9A24784924CC.tmp
9/08/2005 7:10:38 PM 0 C:\WINDOWS\TEMP\CS96D787FD-720D-493A-BAF9-59A577102F95.tmp
9/08/2005 7:10:38 PM 0 C:\WINDOWS\TEMP\CS8C3FFE30-655E-4A3F-B5D8-C01AE0D07B48.tmp
9/08/2005 7:10:38 PM 0 C:\WINDOWS\TEMP\CS169A0E3C-B440-4F23-9DF5-C8DF35FC734A.tmp
9/08/2005 7:10:38 PM 0 C:\WINDOWS\TEMP\CSA244666B-F2C2-4A50-9607-C9E28E682350.tmp
9/08/2005 7:10:38 PM 0 C:\WINDOWS\TEMP\CS13B1E42D-A8F9-42BF-829B-8744CE91BBF2.tmp
9/08/2005 7:10:38 PM 0 C:\WINDOWS\TEMP\CS979DF069-1955-4985-A3F1-E2D236C12E5B.tmp
9/08/2005 7:10:38 PM 0 C:\WINDOWS\TEMP\CS8A77A7A1-4422-43E2-8211-6695CB6DE485.tmp
9/08/2005 7:10:38 PM 0 C:\WINDOWS\TEMP\CS3BCF066E-F1D6-4D76-B9AE-0C91E745BC9E.tmp
9/08/2005 7:10:38 PM 0 C:\WINDOWS\TEMP\CS1647C30D-FB23-4D55-9BA5-11C81B4710FD.tmp
9/08/2005 7:10:38 PM 0 C:\WINDOWS\TEMP\CS08ADAB14-3C75-4227-9878-E6C068EA5338.tmp
9/08/2005 7:10:38 PM 0 C:\WINDOWS\TEMP\CSD50872CF-6B03-4360-95DB-57B16DFB7CC9.tmp
9/08/2005 7:10:38 PM 0 C:\WINDOWS\TEMP\CSA294ACDD-53B9-4E79-BBD9-2014E81A2135.tmp
9/08/2005 7:10:38 PM 0 C:\WINDOWS\TEMP\CSAD811DCC-A633-4686-B042-37DE6D36E20C.tmp
9/08/2005 7:10:38 PM 0 C:\WINDOWS\TEMP\CSFA5D2D54-9589-4492-B0D3-920CF7FA9E72.tmp
9/08/2005 7:10:38 PM 0 C:\WINDOWS\TEMP\CSCB8B7779-5B75-474A-82B4-D3D80A1BC9E2.tmp
9/08/2005 7:10:38 PM 0 C:\WINDOWS\TEMP\CS93453C38-6190-484C-BBDB-24E88A568F9F.tmp
9/08/2005 7:10:38 PM 0 C:\WINDOWS\TEMP\CS328F1E98-F4E1-477D-8710-801A1B9B8FF3.tmp
9/08/2005 7:10:38 PM 0 C:\WINDOWS\TEMP\CS53982BAE-2FBA-4A5E-8F76-A63BB65FF74B.tmp
9/08/2005 7:10:38 PM 0 C:\WINDOWS\TEMP\CSBEBDDCE2-DD0F-4BCB-B7B8-4ECD108E46A5.tmp
9/08/2005 7:10:38 PM 0 C:\WINDOWS\TEMP\CSA9667BAC-A2CF-4EF7-8EA8-544EC4C2D020.tmp
9/08/2005 7:10:38 PM 0 C:\WINDOWS\TEMP\CS9CF10B10-8F39-428A-91A4-A96F01D7C227.tmp
9/08/2005 7:10:38 PM 0 C:\WINDOWS\TEMP\CS0AA0159F-D5FC-4533-9854-2A96143FD758.tmp
9/08/2005 7:10:38 PM 0 C:\WINDOWS\TEMP\CS9AE35BEA-3B39-4DB3-A356-D73B3B62DCC7.tmp
9/08/2005 7:10:38 PM 0 C:\WINDOWS\TEMP\CS8DCD6F27-2D95-48FE-9E6F-35D2E620400A.tmp
9/08/2005 7:10:38 PM 0 C:\WINDOWS\TEMP\CSCAFC36F8-2452-4976-807B-C6633DAC920F.tmp
9/08/2005 7:10:38 PM 0 C:\WINDOWS\TEMP\CSF8F70A71-B7DC-40F2-B001-1A845F720772.tmp
9/08/2005 7:10:38 PM 0 C:\WINDOWS\TEMP\CS6B56EC81-4D30-44D9-8E1C-8CFC8322F729.tmp
9/08/2005 7:10:38 PM 0 C:\WINDOWS\TEMP\CS5150B1A4-29C6-43F3-8BD8-EC828DE4A86B.tmp
9/08/2005 7:10:38 PM 0 C:\WINDOWS\TEMP\CS0FA589B1-FF28-424F-803A-4B7FFDBE9697.tmp
9/08/2005 7:10:38 PM 0 C:\WINDOWS\TEMP\CSA6B95849-4F26-472F-8CB6-400D2EE0056E.tmp
9/08/2005 7:10:38 PM 0 C:\WINDOWS\TEMP\CSA12B07FE-2A25-4775-9A45-1F17AC36B980.tmp
9/08/2005 7:10:38 PM 0 C:\WINDOWS\TEMP\CSB56A84CB-00D1-4429-9DCF-D57D3CFAE95E.tmp
9/08/2005 7:10:38 PM 0 C:\WINDOWS\TEMP\CSCEE13AE3-E307-43FA-98EC-B14277428CE8.tmp
9/08/2005 7:10:38 PM 0 C:\WINDOWS\TEMP\CS2489996A-57DA-4919-B28D-A663FF1B4542.tmp
9/08/2005 7:10:38 PM 0 C:\WINDOWS\TEMP\CS431D03BC-14C1-439B-927F-CFDD54DD58C9.tmp
9/08/2005 7:10:38 PM 0 C:\WINDOWS\TEMP\CSB8CE1E31-5736-46D0-95E3-5FEA508C3F3D.tmp
9/08/2005 7:10:38 PM 0 C:\WINDOWS\TEMP\CSBD7E076E-F67B-48EF-B31A-D290AC5C21B6.tmp
9/08/2005 7:10:38 PM 0 C:\WINDOWS\TEMP\CS6DC80571-CBA6-4F57-B8F7-EB10A3B5AAA5.tmp
9/08/2005 7:10:38 PM 0 C:\WINDOWS\TEMP\CS25774F5C-9D40-4A48-99A3-EFC547F44AAB.tmp
10/08/2005 5:27:36 PM 0 C:\WINDOWS\TEMP\CS08B1317E-EED3-4230-8A9A-B3A5B9E4305A.tmp
10/08/2005 5:27:36 PM 0 C:\WINDOWS\TEMP\CSC4D1A53D-A6A6-439B-A893-425EF1C9629A.tmp
10/08/2005 5:27:36 PM 0 C:\WINDOWS\TEMP\CS896A3B14-0011-4999-97F6-39B967A01580.tmp
10/08/2005 5:27:36 PM 0 C:\WINDOWS\TEMP\CSCB598D73-08B8-4182-95FD-F709017BBFAA.tmp
10/08/2005 5:27:36 PM 0 C:\WINDOWS\TEMP\CS3965D14B-3DC9-465A-99A6-EA48D7D97AAF.tmp
10/08/2005 5:27:36 PM 0 C:\WINDOWS\TEMP\CS1FED6C49-8783-4107-ACBD-50D3F820DEE0.tmp
10/08/2005 5:27:36 PM 0 C:\WINDOWS\TEMP\CS68114261-E622-4F97-B67C-591A085C45AD.tmp
10/08/2005 5:27:36 PM 0 C:\WINDOWS\TEMP\CSBB72C5B2-A63F-4DF9-987A-8A76757447E6.tmp
10/08/2005 5:27:36 PM 0 C:\WINDOWS\TEMP\CSE7F86FEF-6DCD-47B0-9F88-7721B6F6D158.tmp
10/08/2005 5:27:36 PM 0 C:\WINDOWS\TEMP\CS8A395779-646B-4809-9571-92B1EB60A6E7.tmp
10/08/2005 5:27:36 PM 0 C:\WINDOWS\TEMP\CS7CF92419-FD08-4F41-8F2E-1525C20B5698.tmp
10/08/2005 5:27:36 PM 0 C:\WINDOWS\TEMP\CS4732EFEA-CB1B-4A6B-B1E3-5DE1BEC87223.tmp
10/08/2005 5:27:36 PM 0 C:\WINDOWS\TEMP\CS3D72336C-922F-46F1-9C9E-64F89DEA8A13.tmp
10/08/2005 5:27:36 PM 0 C:\WINDOWS\TEMP\CSFAC12731-2950-4FD1-9617-079CC70E2AC3.tmp
10/08/2005 5:27:36 PM 0 C:\WINDOWS\TEMP\CS887BC30A-CB7D-4EEF-9510-109120B349A9.tmp
10/08/2005 5:27:36 PM 0 C:\WINDOWS\TEMP\CS18B08087-281F-4DA7-BE43-7D815779239A.tmp
10/08/2005 5:27:36 PM 0 C:\WINDOWS\TEMP\CSD3F3B5C5-8D2E-4EF9-A16B-7294F8AD6161.tmp
10/08/2005 5:27:36 PM 0 C:\WINDOWS\TEMP\CS92045B2A-CCCB-4E31-8D77-540E37571EA7.tmp
10/08/2005 5:27:36 PM 0 C:\WINDOWS\TEMP\CS92F6267A-4EF8-4796-8C15-3C52679ECDB3.tmp
10/08/2005 5:27:36 PM 0 C:\WINDOWS\TEMP\CSEF1C0411-BFDA-4F8C-BD3B-DE1D10B01269.tmp
10/08/2005 5:27:36 PM 0 C:\WINDOWS\TEMP\CS4F3BEC6E-053E-4838-9271-E52491696E79.tmp
10/08/2005 5:27:36 PM 0 C:\WINDOWS\TEMP\CS25A144C6-B81B-483F-88CB-652FADEF97F3.tmp
10/08/2005 5:27:36 PM 0 C:\WINDOWS\TEMP\CSD41A8C6A-DDFF-4420-87EE-2C31D4A547FF.tmp
10/08/2005 5:27:36 PM 0 C:\WINDOWS\TEMP\CS42B9F3CD-FFBC-47C3-A873-D875C7471D7C.tmp
10/08/2005 5:27:36 PM 0 C:\WINDOWS\TEMP\CSA92072AE-1BA7-42B2-80BB-DA94694BF60C.tmp
10/08/2005 5:27:36 PM 0 C:\WINDOWS\TEMP\CS46EAF570-6390-43DA-B2CA-3023FF71AD9B.tmp
10/08/2005 5:27:36 PM 0 C:\WINDOWS\TEMP\CS2E8C8924-5949-4D4E-BD99-E994971E9243.tmp
10/08/2005 5:27:36 PM 0 C:\WINDOWS\TEMP\CSB768BD67-3019-4346-AF1D-BFA3BD64D40F.tmp
10/08/2005 5:27:36 PM 0 C:\WINDOWS\TEMP\CSC940B43F-84AB-4DAF-ABD4-C3FB3077DE77.tmp
10/08/2005 5:27:36 PM 0 C:\WINDOWS\TEMP\CS61628CCC-925F-452C-B18A-56BC89C28806.tmp
10/08/2005 5:27:36 PM 0 C:\WINDOWS\TEMP\CS0238E1ED-8B92-4722-86C6-C4E6EA2C0F99.tmp
10/08/2005 5:27:36 PM 0 C:\WINDOWS\TEMP\CS763FE3F0-B26E-480D-A917-4E633FC765E8.tmp
10/08/2005 5:28:14 PM 0 C:\WINDOWS\TEMP\CS988487CF-8493-440F-BD4B-0332E5A1F8A7.tmp
10/08/2005 5:28:14 PM 0 C:\WINDOWS\TEMP\CS9DE5DF5B-788B-424C-81F2-CC0161F89B44.tmp
10/08/2005 5:28:14 PM 0 C:\WINDOWS\TEMP\CS81F26EC7-3FD3-4CF7-9E66-5CA3D02B0C30.tmp
10/08/2005 5:28:14 PM 0 C:\WINDOWS\TEMP\CSFFD795B5-CE9F-460D-803D-33BD8E5323E1.tmp
10/08/2005 5:28:14 PM 0 C:\WINDOWS\TEMP\CSC90A322B-32B0-4C32-86E4-6CEC116683D3.tmp
10/08/2005 5:28:14 PM 0 C:\WINDOWS\TEMP\CS9B855FC4-1270-4BC7-88A2-634932792500.tmp
10/08/2005 5:28:14 PM 0 C:\WINDOWS\TEMP\CS7C6E48FC-4DDF-45B2-8508-CF921FBD0A51.tmp
10/08/2005 5:28:14 PM 0 C:\WINDOWS\TEMP\CSC44CD1AE-7358-4486-9127-0041C2BBC8AB.tmp
10/08/2005 5:28:14 PM 0 C:\WINDOWS\TEMP\CS2C87C7CC-D3AD-4171-93AA-8907EA7AAC7B.tmp
10/08/2005 5:28:14 PM 0 C:\WINDOWS\TEMP\CS653F8D2E-A84A-4CE1-9CE9-9FB79C37D9FE.tmp
10/08/2005 5:28:14 PM 0 C:\WINDOWS\TEMP\CS1229603A-A932-4B63-A939-9564115F0576.tmp
10/08/2005 5:28:16 PM 0 C:\WINDOWS\TEMP\CSF95B9439-EF57-4B42-ACD7-59B311C6BE8B.tmp
10/08/2005 5:28:16 PM 0 C:\WINDOWS\TEMP\CS1546BADD-5ED1-4521-B319-20FE58FD3B6D.tmp
10/08/2005 5:28:16 PM 0 C:\WINDOWS\TEMP\CSAFB5A7CE-18FA-4DBF-939B-B49486264944.tmp
10/08/2005 5:28:16 PM 0 C:\WINDOWS\TEMP\CSBE3D2630-EB8C-4864-B963-1D7210374979.tmp
10/08/2005 5:28:16 PM 0 C:\WINDOWS\TEMP\CSED7A2285-E348-4A3C-BFC3-E457E8781D1A.tmp
10/08/2005 5:28:16 PM 0 C:\WINDOWS\TEMP\CSDCE90FD4-38FB-431F-A570-7D29FA7733DA.tmp
10/08/2005 5:28:16 PM 0 C:\WINDOWS\TEMP\CS2464E384-4291-411E-8D98-B8E0059D3CBF.tmp
10/08/2005 5:28:16 PM 0 C:\WINDOWS\TEMP\CS97F8C803-C26E-4070-BC2D-7E0BEA43F48A.tmp
10/08/2005 5:28:16 PM 0 C:\WINDOWS\TEMP\CS3730C597-83C5-4497-9B39-775BC169357F.tmp
10/08/2005 5:28:16 PM 0 C:\WINDOWS\TEMP\CSECB84147-240A-463C-B6DE-E84844CA74F4.tmp
10/08/2005 5:28:16 PM 0 C:\WINDOWS\TEMP\CSE0844C5F-E785-405C-AFAF-C8EE4351E14E.tmp
10/08/2005 5:28:16 PM 0 C:\WINDOWS\TEMP\CSF3FCFD9B-44DD-4AA9-8E23-7E6B7CC88941.tmp
10/08/2005 5:28:16 PM 0 C:\WINDOWS\TEMP\CS5243CCFE-86E2-4D3F-882E-E805E2478EE4.tmp
10/08/2005 5:28:16 PM 0 C:\WINDOWS\TEMP\CSD7508AFC-CDE8-493A-985E-69B784EFB638.tmp
10/08/2005 5:28:16 PM 0 C:\WINDOWS\TEMP\CSA9445D61-2FEB-410A-AF5D-BE4D4B127607.tmp
10/08/2005 5:28:16 PM 0 C:\WINDOWS\TEMP\CS1E5A6F5F-66AC-49EE-A707-F1F5AB5F9BFF.tmp
10/08/2005 5:28:16 PM 0 C:\WINDOWS\TEMP\CS3C70303B-7392-46AA-9616-2A105E3E4166.tmp
10/08/2005 5:28:16 PM 0 C:\WINDOWS\TEMP\CS417266C0-30CF-4397-9B44-D17E4EE62EC6.tmp
10/08/2005 5:28:16 PM 0 C:\WINDOWS\TEMP\CS220CA920-EB69-4D39-B2B5-84DC2264F683.tmp
10/08/2005 5:28:16 PM 0 C:\WINDOWS\TEMP\CS211851FF-212F-4D7B-9F2A-FCBEB494F0A7.tmp
10/08/2005 5:28:16 PM 0 C:\WINDOWS\TEMP\CSAED296A0-1DD5-4A51-BCA9-7E63DDCCB4C3.tmp
10/08/2005 5:28:16 PM 0 C:\WINDOWS\TEMP\CS105E3E3E-15C8-4CAA-B1D4-D8A027C679AC.tmp
10/08/2005 5:28:16 PM 0 C:\WINDOWS\TEMP\CSD5783E65-D8E8-4496-865E-E3F685080CFF.tmp

#8 OldTimer

OldTimer

    Malware Expert


  • Members
  • 11,092 posts
  • OFFLINE
  •  
  • Gender:Male
  • Location:North Carolina
  • Local time:01:31 AM

Posted 18 August 2005 - 01:15 PM

Hi Marci4. The log appears to still be the older verison and much of it was cut off. Let's try a new log with the new version.

Delete the c:\winpfind folder.

Now download WinPFind.zip and unzip the contents to the C:\ folder.

Start in Safe Mode Using the F8 method:
  • Restart the computer.
  • As soon as the BIOS is loaded begin tapping the F8 key until the boot menu appears.
  • Use the arrow keys to select the Safe Mode menu item.
  • Press the Enter key.
Locate the c:\winpfind\winpfind.exe file and double-click it to run it. Now click the Start Scan button to begin the scan.

When the scan is complete reboot normally. Open the WinPFind.txt file (located in the WinPFind folder) with Notepad. press the Ctrl-A keys at the same time to select all text. Now press the Ctrl-C keys at the same time to copy the text to the clipboard. Come back here and click the Add Reply button. Click in the edit box and press the b]Ctrl-V[/b] keys at the same time to paste the text into the editbox.

I will review the new log when it comes in.

Cheers.

OT
I do not respond to PM's requesting help. That's what the forums are here for. Please use them so that others may benefit from your questions and the responses you receive.
OldTimer

Posted Image

#9 Marci4

Marci4
  • Topic Starter

  • Members
  • 18 posts
  • OFFLINE
  •  
  • Local time:12:31 AM

Posted 18 August 2005 - 11:54 PM

WARNING: not all files found by this scanner are bad. Consult with a knowledgable person before proceeding.

If you see a message in the titlebar saying "Not responding..." you can ignore it. Windows somethimes displays this message due to the high volume of disk I/O. As long as the hard disk light is flashing, the program is still working properly.

»»»»»»»»»»»»»»»»» Windows OS and Versions »»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»
Product Name: Windows Millennium Edition Version: 4.90.3000
Internet Explorer Version: 6.0.2800.1106

»»»»»»»»»»»»»»»»» Checking Selected Standard Folders »»»»»»»»»»»»»»»»»»»»

Checking %SystemDrive% folder...

Checking %ProgramFilesDir% folder...
PEC2 16/12/2004 3:25:08 PM 12305800 C:\Program Files\e-Record_v401_Setup.EXE

Checking %WinDir% folder...

Items found in C:\WINDOWS\HOSTS

PECompact2 26/07/2005 11:25:08 AM 15442435 C:\WINDOWS\LPT$VPN.745
qoologic 26/07/2005 11:25:08 AM 15442435 C:\WINDOWS\LPT$VPN.745
SAHAgent 26/07/2005 11:25:08 AM 15442435 C:\WINDOWS\LPT$VPN.745
PECompact2 26/07/2005 11:25:08 AM 15442435 C:\WINDOWS\VPTNFILE.745
qoologic 26/07/2005 11:25:08 AM 15442435 C:\WINDOWS\VPTNFILE.745
SAHAgent 26/07/2005 11:25:08 AM 15442435 C:\WINDOWS\VPTNFILE.745
UPX! 27/07/2005 12:53:28 AM 1044560 C:\WINDOWS\vsapi32.dll
aspack 27/07/2005 12:53:28 AM 1044560 C:\WINDOWS\vsapi32.dll

Checking %System% folder...
UPX! 29/07/2005 12:17:32 AM 45568 C:\WINDOWS\SYSTEM\ntfsnlpa.exe
PTech 14/10/2002 4:31:52 PM 7832 C:\WINDOWS\SYSTEM\lxbbinst.drv
FSG! 16/07/2005 8:25:08 PM 705 C:\WINDOWS\SYSTEM\msexnpfi.exe

Checking %System%\Drivers folder and sub-folders...

Checking the Windows folder and sub-folders for system and hidden files within the last 60 days...
H 19/08/2005 12:42:48 PM 4694048 C:\WINDOWS\CLASSES.DAT
H 5/07/2005 4:07:04 PM 192544 C:\WINDOWS\HWINFO.DAT
H 19/08/2005 12:53:18 PM 1040416 C:\WINDOWS\USER.DAT
H 19/08/2005 12:51:26 PM 2355232 C:\WINDOWS\SYSTEM.DAT
H 5/07/2005 4:04:16 PM 23155 C:\WINDOWS\folder.htt
H 5/07/2005 4:04:16 PM 271 C:\WINDOWS\desktop.ini
H 14/08/2005 1:56:50 AM 54156 C:\WINDOWS\QTFont.qfn
H 19/08/2005 12:49:34 PM 25866 C:\WINDOWS\ttfCache
H 19/08/2005 12:40:12 PM 1108222 C:\WINDOWS\ShellIconCache
H 5/07/2005 4:04:16 PM 23155 C:\WINDOWS\SYSTEM\folder.htt
H 5/07/2005 4:04:16 PM 271 C:\WINDOWS\SYSTEM\desktop.ini
H 5/07/2005 4:02:50 PM 9793 C:\WINDOWS\HELP\windows.GID
H 15/07/2005 9:50:00 AM 10820 C:\WINDOWS\HELP\nocontnt.GID
H 5/07/2005 4:02:50 PM 4753 C:\WINDOWS\WEB\wiadev.htt
H 5/07/2005 4:02:50 PM 18952 C:\WINDOWS\WEB\wiacam.htt
H 5/07/2005 4:02:50 PM 20150 C:\WINDOWS\WEB\wiastream.htt
H 5/07/2005 4:02:50 PM 1574 C:\WINDOWS\WEB\wiastyle.css
H 5/07/2005 4:02:50 PM 2998 C:\WINDOWS\WEB\PICTURES.ICO
H 5/07/2005 4:02:50 PM 10134 C:\WINDOWS\WEB\CAMERA.ICO
H 5/07/2005 4:02:50 PM 10134 C:\WINDOWS\WEB\STREAM.ICO
H 5/07/2005 4:04:18 PM 1535 C:\WINDOWS\WEB\webview.css
H 5/07/2005 4:04:18 PM 18163 C:\WINDOWS\WEB\controlp.htt
H 5/07/2005 4:04:18 PM 4780 C:\WINDOWS\WEB\default.htt
H 5/07/2005 4:04:18 PM 16287 C:\WINDOWS\WEB\nethood.htt
H 5/07/2005 4:04:20 PM 11034 C:\WINDOWS\WEB\recycle.htt
H 5/07/2005 4:04:20 PM 6391 C:\WINDOWS\WEB\schedule.htt
H 5/07/2005 4:04:20 PM 9227 C:\WINDOWS\WEB\dialup.htt
H 5/07/2005 4:04:20 PM 8246 C:\WINDOWS\WEB\wvleft.bmp
H 5/07/2005 4:04:20 PM 1749 C:\WINDOWS\WEB\wvleft.gif
H 5/07/2005 4:04:20 PM 54 C:\WINDOWS\WEB\wvline.gif
H 5/07/2005 4:04:20 PM 9439 C:\WINDOWS\WEB\wvlogo.gif
H 5/07/2005 4:04:20 PM 90056 C:\WINDOWS\WEB\classic.bmp
H 5/07/2005 4:04:20 PM 641 C:\WINDOWS\WEB\classic.htt
H 5/07/2005 4:04:20 PM 18100 C:\WINDOWS\WEB\folder.bmp
H 5/07/2005 4:04:20 PM 1031 C:\WINDOWS\WEB\starter.htt
H 5/07/2005 4:04:20 PM 31080 C:\WINDOWS\WEB\starter.bmp
H 5/07/2005 4:04:20 PM 18100 C:\WINDOWS\WEB\preview.bmp
H 5/07/2005 4:04:22 PM 18276 C:\WINDOWS\WEB\imgview.htt
H 5/07/2005 4:04:22 PM 830 C:\WINDOWS\WEB\deskmovr.htt
H 5/07/2005 4:04:22 PM 3469 C:\WINDOWS\WEB\safemode.htt
H 5/07/2005 4:04:22 PM 20510 C:\WINDOWS\WEB\fsresult.htt
H 5/07/2005 4:04:22 PM 29797 C:\WINDOWS\WEB\standard.htt
H 5/07/2005 4:04:22 PM 33916 C:\WINDOWS\WEB\webview.js
H 5/07/2005 4:04:22 PM 2642 C:\WINDOWS\WEB\exclam.gif
H 5/07/2005 4:04:22 PM 842 C:\WINDOWS\WEB\bullet.gif
H 5/07/2005 4:04:22 PM 80 C:\WINDOWS\WEB\plushot.gif
H 5/07/2005 4:04:22 PM 59 C:\WINDOWS\WEB\pluscold.gif
H 5/07/2005 4:04:22 PM 77 C:\WINDOWS\WEB\minhot.gif
H 5/07/2005 4:04:22 PM 56 C:\WINDOWS\WEB\mincold.gif
H 5/07/2005 4:04:22 PM 11870 C:\WINDOWS\WEB\printers.htt
H 5/07/2005 4:04:24 PM 25217 C:\WINDOWS\WEB\sysroot.htt
H 5/07/2005 4:04:24 PM 2848 C:\WINDOWS\WEB\brfcase.htt
H 5/07/2005 4:04:26 PM 11083 C:\WINDOWS\WEB\ftp.htt
H 5/07/2005 4:04:20 PM 3191 C:\WINDOWS\WEB\folder.htt
H 19/08/2005 12:51:12 PM 13026 C:\WINDOWS\PCHEALTH\HELPCTR\Database\HelpSessionHistory.stream
H 19/08/2005 12:26:06 PM 6 C:\WINDOWS\TASKS\SA.DAT
H 9/08/2005 7:01:10 PM 0 C:\WINDOWS\TEMP\CS67A179AE-3C93-43F7-A869-6111DF507C7C.tmp
H 9/08/2005 7:01:10 PM 0 C:\WINDOWS\TEMP\CS86C6CBB6-78D1-48BD-8619-AE1A11E6D7DE.tmp
H 9/08/2005 7:01:10 PM 0 C:\WINDOWS\TEMP\CSDA3FEA02-597E-46BD-894D-D192F71F6E93.tmp
H 9/08/2005 7:01:10 PM 0 C:\WINDOWS\TEMP\CS35350476-0456-4F98-BECA-68904694C1B2.tmp
H 9/08/2005 7:01:10 PM 0 C:\WINDOWS\TEMP\CS08A91EF9-94B1-447B-B743-78A74229A59F.tmp
H 9/08/2005 7:01:10 PM 0 C:\WINDOWS\TEMP\CSBAF07993-8A29-487C-B8BD-BF32333453B7.tmp
H 9/08/2005 7:01:10 PM 0 C:\WINDOWS\TEMP\CS5191FCFE-9A89-4A80-9A7E-0C7E2D8A9FA0.tmp
H 9/08/2005 7:01:10 PM 0 C:\WINDOWS\TEMP\CS1D1BD214-2CF6-4287-9E00-8A080D568F36.tmp
H 9/08/2005 7:01:10 PM 0 C:\WINDOWS\TEMP\CS5ECE9A8B-D504-4A62-B950-424886CC325C.tmp
H 9/08/2005 7:01:10 PM 0 C:\WINDOWS\TEMP\CS03B2B7B5-B59B-4C89-9405-E3B3A9F25522.tmp
H 9/08/2005 7:01:10 PM 0 C:\WINDOWS\TEMP\CSABC22FA9-9C23-4B7C-BBA5-45BD07AD3581.tmp
H 9/08/2005 7:01:10 PM 0 C:\WINDOWS\TEMP\CS57C8D31E-D61C-4E44-8439-90C33A994E81.tmp
H 9/08/2005 7:01:10 PM 0 C:\WINDOWS\TEMP\CSFDD76388-2058-4696-B3CE-68A2ECAB3EB4.tmp
H 9/08/2005 7:01:10 PM 0 C:\WINDOWS\TEMP\CSC1A4761E-8276-483D-9D85-C862AECB33B1.tmp
H 9/08/2005 7:01:10 PM 0 C:\WINDOWS\TEMP\CS0F22332A-BFA1-4E8A-9F11-2E2CB70543CD.tmp
H 9/08/2005 7:01:10 PM 0 C:\WINDOWS\TEMP\CS97D1DE27-E53A-479C-950D-ED3FE6A7CA20.tmp
H 9/08/2005 7:01:10 PM 0 C:\WINDOWS\TEMP\CSC26212F0-8BB2-4BF6-B6CA-0A872F55ACFE.tmp
H 9/08/2005 7:01:10 PM 0 C:\WINDOWS\TEMP\CSFF505C0E-477D-4F83-AF3A-8A02AF5C2F54.tmp
H 9/08/2005 7:01:10 PM 0 C:\WINDOWS\TEMP\CS8D1CE539-31F7-4B36-9C36-CDC4EB97E108.tmp
H 9/08/2005 7:01:10 PM 0 C:\WINDOWS\TEMP\CSCD529814-DE78-4951-BD44-BB90E09A7F69.tmp
H 9/08/2005 7:01:10 PM 0 C:\WINDOWS\TEMP\CS98D1F09F-0A8B-4D75-9551-9193DC5FDDE9.tmp
H 9/08/2005 7:01:10 PM 0 C:\WINDOWS\TEMP\CS8B538AE7-C71A-40F6-9215-A394451D60DE.tmp
H 9/08/2005 7:01:10 PM 0 C:\WINDOWS\TEMP\CSAF4AEC99-5F50-45E4-AA2D-BB5D7C777EC3.tmp
H 9/08/2005 7:01:10 PM 0 C:\WINDOWS\TEMP\CS66AC6224-2A18-4E1F-A44F-5E57E7188A17.tmp
H 9/08/2005 7:01:10 PM 0 C:\WINDOWS\TEMP\CS188D6373-F77A-4911-A76A-17C8D0C44ECA.tmp
H 9/08/2005 7:01:10 PM 0 C:\WINDOWS\TEMP\CSDA355DD9-EEE1-4FBC-A02C-DB6C625FEB6E.tmp
H 9/08/2005 7:01:10 PM 0 C:\WINDOWS\TEMP\CS553AB118-D0FF-472E-A845-473F2A251711.tmp
H 9/08/2005 7:01:10 PM 0 C:\WINDOWS\TEMP\CS4156D7A3-68BF-413E-8DE4-53D6C070F567.tmp
H 9/08/2005 7:01:10 PM 0 C:\WINDOWS\TEMP\CS881274C5-957D-4C6C-AD31-59E87649F3E1.tmp
H 9/08/2005 7:01:10 PM 0 C:\WINDOWS\TEMP\CS9AD52901-F212-424B-AA8F-CC1C30250234.tmp
H 9/08/2005 7:01:10 PM 0 C:\WINDOWS\TEMP\CS9603BE5A-7590-4713-A596-852039C1BC32.tmp
H 9/08/2005 7:01:10 PM 0 C:\WINDOWS\TEMP\CSC5BFB764-0660-4CB6-819E-8EFEDCFAF925.tmp
H 9/08/2005 7:01:32 PM 0 C:\WINDOWS\TEMP\CS2D12D590-BD45-4EF5-A118-A0E90411E3A6.tmp
H 9/08/2005 7:01:32 PM 0 C:\WINDOWS\TEMP\CS59381B47-063B-4523-8899-9F7C7A54B0B9.tmp
H 9/08/2005 7:01:32 PM 0 C:\WINDOWS\TEMP\CS8E12C1D7-AA4E-41CE-A98B-C2DE17BE5F9E.tmp
H 9/08/2005 7:01:32 PM 0 C:\WINDOWS\TEMP\CS0F040063-D1D1-44FD-B3EF-AB4B0371163D.tmp
H 9/08/2005 7:01:32 PM 0 C:\WINDOWS\TEMP\CSCB97C28E-E588-490C-A802-C7D569782AE3.tmp
H 9/08/2005 7:01:32 PM 0 C:\WINDOWS\TEMP\CS937491FE-50F9-4B60-A7FA-0D615EB05D3C.tmp
H 9/08/2005 7:01:32 PM 0 C:\WINDOWS\TEMP\CS63B56189-1D6F-4DD0-AD29-1CB9CC01D384.tmp
H 9/08/2005 7:01:32 PM 0 C:\WINDOWS\TEMP\CSE5D0992F-9CFA-4371-A2BA-E874BB6697B3.tmp
H 9/08/2005 7:01:32 PM 0 C:\WINDOWS\TEMP\CS89693CD3-81D7-4D94-AB6F-8378DF57FAD9.tmp
H 9/08/2005 7:01:32 PM 0 C:\WINDOWS\TEMP\CSDE6DEB4C-566E-4D0A-B7F3-32037EF25A2B.tmp
H 9/08/2005 7:01:32 PM 0 C:\WINDOWS\TEMP\CSCA19211C-4428-4ED0-AAE0-974EC602959F.tmp
H 9/08/2005 7:01:32 PM 0 C:\WINDOWS\TEMP\CS1D1936BC-F787-4958-B982-4332CA054FBA.tmp
H 9/08/2005 7:01:32 PM 0 C:\WINDOWS\TEMP\CS24F1F05F-1067-41C7-BEAC-45789738657E.tmp
H 9/08/2005 7:01:32 PM 0 C:\WINDOWS\TEMP\CS26B58545-F4F4-49AB-859C-53BC152583C6.tmp
H 9/08/2005 7:01:32 PM 0 C:\WINDOWS\TEMP\CSDF9D59CF-EC8E-40B0-A1D2-6C914E0A1951.tmp
H 9/08/2005 7:01:32 PM 0 C:\WINDOWS\TEMP\CSA1E6B887-EC0C-446D-82B1-763FD03A82C2.tmp
H 9/08/2005 7:01:32 PM 0 C:\WINDOWS\TEMP\CS6FD22086-BAEC-45F1-905F-FCDD67DA9F09.tmp
H 9/08/2005 7:01:32 PM 0 C:\WINDOWS\TEMP\CS992AC8F3-FD45-4C6A-A15C-C0E83D04FB86.tmp
H 9/08/2005 7:01:32 PM 0 C:\WINDOWS\TEMP\CS9F066697-D757-4FB0-847D-2341EA37CD7E.tmp
H 9/08/2005 7:01:32 PM 0 C:\WINDOWS\TEMP\CSF26B6D95-1DBB-4DD9-915E-18B14FCB83B1.tmp
H 9/08/2005 7:01:32 PM 0 C:\WINDOWS\TEMP\CSE4852E05-10F4-4E10-871C-084813A7385D.tmp
H 9/08/2005 7:01:32 PM 0 C:\WINDOWS\TEMP\CSB5D72C5D-E990-4F47-9C17-7A71D4B28D3B.tmp
H 9/08/2005 7:01:32 PM 0 C:\WINDOWS\TEMP\CSC8D82C27-BE98-401E-9C20-86F97411E43F.tmp
H 9/08/2005 7:01:32 PM 0 C:\WINDOWS\TEMP\CSC30EE08F-AAA8-4CBF-BBC6-A2B01379AB49.tmp
H 9/08/2005 7:01:32 PM 0 C:\WINDOWS\TEMP\CS2A3AD399-5CB1-465C-A8DA-CB603328B6BC.tmp
H 9/08/2005 7:01:32 PM 0 C:\WINDOWS\TEMP\CSBEDA2F4E-1AF9-478A-8840-2301413A1F4D.tmp
H 9/08/2005 7:01:32 PM 0 C:\WINDOWS\TEMP\CS02D55269-73B3-4801-80CA-451445A0CAE8.tmp
H 9/08/2005 7:01:32 PM 0 C:\WINDOWS\TEMP\CS98E2F09F-5A75-418A-ACE6-F836623DDABB.tmp
H 9/08/2005 7:01:32 PM 0 C:\WINDOWS\TEMP\CSAEFAC004-15CE-49AB-9C56-867B22FCDC5F.tmp
H 9/08/2005 7:01:32 PM 0 C:\WINDOWS\TEMP\CSD69A6D5B-ED90-4224-8ADC-93FBD16C5C5F.tmp
H 9/08/2005 7:01:32 PM 0 C:\WINDOWS\TEMP\CSD2D78E15-85DD-49A9-AA08-822A13F7F80B.tmp
H 9/08/2005 7:01:32 PM 0 C:\WINDOWS\TEMP\CS8D1A0728-F9DA-4B22-A0D5-8B87B6E90D18.tmp
H 9/08/2005 7:01:32 PM 0 C:\WINDOWS\TEMP\CSACE7F9D4-537D-4C51-AD04-B95314819CEF.tmp
H 9/08/2005 7:01:32 PM 0 C:\WINDOWS\TEMP\CSC2FA7BE8-E08E-40A3-A249-79E85F14F825.tmp
H 9/08/2005 7:01:32 PM 0 C:\WINDOWS\TEMP\CS0DB86E99-8D39-4018-885A-4DFCA2F0F9BA.tmp
H 9/08/2005 7:01:32 PM 0 C:\WINDOWS\TEMP\CS29300C64-3217-47E0-99F7-DBEF172CE263.tmp
H 9/08/2005 7:01:32 PM 0 C:\WINDOWS\TEMP\CSD7C46855-92A5-4AF3-B71E-D016DECC0442.tmp
H 9/08/2005 7:01:32 PM 0 C:\WINDOWS\TEMP\CSD39D486D-30BF-4FC2-9FCD-5284805E4EB4.tmp
H 9/08/2005 7:01:32 PM 0 C:\WINDOWS\TEMP\CSD9CF7568-C534-4941-8389-4EC9D556EA52.tmp
H 9/08/2005 7:01:32 PM 0 C:\WINDOWS\TEMP\CS153E1B7C-16B3-4361-8D92-E793137D174F.tmp
H 9/08/2005 7:01:32 PM 0 C:\WINDOWS\TEMP\CSF3A59CF7-C70D-49A0-8AFC-AB0FA9421263.tmp
H 9/08/2005 7:01:32 PM 0 C:\WINDOWS\TEMP\CSA472FF9E-06BC-4456-845F-354D8B6E4B99.tmp
H 9/08/2005 7:01:32 PM 0 C:\WINDOWS\TEMP\CS5D214571-047B-49A3-8306-3833DAEA99C1.tmp
H 9/08/2005 7:01:32 PM 0 C:\WINDOWS\TEMP\CS5017A415-75B4-4CAE-AD58-61311916645E.tmp
H 9/08/2005 7:01:32 PM 0 C:\WINDOWS\TEMP\CS5C23034E-A1A0-4D20-B602-A3F42FD6C6A2.tmp
H 9/08/2005 7:01:32 PM 0 C:\WINDOWS\TEMP\CSCE1ACBF8-DA67-4FAE-83BF-00F7E276F1BE.tmp
H 9/08/2005 7:01:32 PM 0 C:\WINDOWS\TEMP\CS433EADEA-9B70-427C-B64C-7ACFB8F00955.tmp
H 9/08/2005 7:01:32 PM 0 C:\WINDOWS\TEMP\CS8258805B-C537-40FF-AAA7-64F415AF57A6.tmp
H 9/08/2005 7:01:32 PM 0 C:\WINDOWS\TEMP\CS094CEA5F-564B-4CC8-B54D-6970092C0C7F.tmp
H 9/08/2005 7:01:32 PM 0 C:\WINDOWS\TEMP\CS517E5078-7331-4297-8283-D77574A2EB24.tmp
H 9/08/2005 7:01:32 PM 0 C:\WINDOWS\TEMP\CS41BC3D6D-4D99-4274-8664-D95DE493A05D.tmp
H 9/08/2005 7:01:32 PM 0 C:\WINDOWS\TEMP\CS311CCC87-E77D-46B0-956E-529B2654FDF6.tmp
H 9/08/2005 7:01:32 PM 0 C:\WINDOWS\TEMP\CSEC96A483-A780-4622-ACC0-82FC4D59D894.tmp
H 9/08/2005 7:01:32 PM 0 C:\WINDOWS\TEMP\CS24BDEB0F-D209-4FE0-8EBD-81E94F98A911.tmp
H 9/08/2005 7:01:32 PM 0 C:\WINDOWS\TEMP\CSB51CBB82-D936-4746-BECC-A3A7504E410F.tmp
H 9/08/2005 7:01:32 PM 0 C:\WINDOWS\TEMP\CS214FC300-2BA0-4D3F-877B-609E5F3D210D.tmp
H 9/08/2005 7:01:32 PM 0 C:\WINDOWS\TEMP\CSEF980BA7-DD67-40F9-B384-655570FB3356.tmp
H 9/08/2005 7:01:32 PM 0 C:\WINDOWS\TEMP\CSEC8A0600-6014-4FFE-A658-E1BE2C96E41A.tmp
H 9/08/2005 7:01:32 PM 0 C:\WINDOWS\TEMP\CS01D968EB-52EC-426F-BB48-BB792B2787C1.tmp
H 9/08/2005 7:01:32 PM 0 C:\WINDOWS\TEMP\CS400A663A-CADE-4334-B9FC-D43B1EE51AF2.tmp
H 9/08/2005 7:01:32 PM 0 C:\WINDOWS\TEMP\CS7399412A-E82F-40DB-84A5-307C76DCD35D.tmp
H 9/08/2005 7:01:32 PM 0 C:\WINDOWS\TEMP\CSD60BB073-B694-4D16-8A4A-E4F8F6218E82.tmp
H 9/08/2005 7:01:32 PM 0 C:\WINDOWS\TEMP\CSB7B2524D-D22D-4679-8EFF-A7EAA94F0927.tmp
H 9/08/2005 7:01:32 PM 0 C:\WINDOWS\TEMP\CSA645536D-9C78-4341-8A2A-8276809F3604.tmp
H 9/08/2005 7:01:32 PM 0 C:\WINDOWS\TEMP\CS866485BD-6147-4E16-805F-ABE6B1AF0216.tmp
H 9/08/2005 7:01:32 PM 0 C:\WINDOWS\TEMP\CS47FFB66B-F3E0-4F81-A22E-46E415954458.tmp
H 9/08/2005 7:01:32 PM 0 C:\WINDOWS\TEMP\CS20901B0A-9D4E-4129-8577-F71AC6F7EFE8.tmp
H 9/08/2005 7:01:32 PM 0 C:\WINDOWS\TEMP\CS0C5ADF71-0865-4BAC-A803-886A16289B31.tmp
H 9/08/2005 7:01:32 PM 0 C:\WINDOWS\TEMP\CS8D582573-8285-4C94-93A3-1E6316FF5ABC.tmp
H 9/08/2005 7:05:24 PM 0 C:\WINDOWS\TEMP\CSCEB52DD0-AFC9-4A8C-8A6C-EFF1704E3E2C.tmp
H 9/08/2005 7:05:24 PM 0 C:\WINDOWS\TEMP\CS8860546D-34DE-4726-9B2D-1571BBBA18A3.tmp
H 9/08/2005 7:05:24 PM 0 C:\WINDOWS\TEMP\CSAE3B88DF-1DCA-4741-BA28-C4E63D38B80F.tmp
H 9/08/2005 7:05:24 PM 0 C:\WINDOWS\TEMP\CSF5046B15-9941-4E7A-A456-C61597869004.tmp
H 9/08/2005 7:05:24 PM 0 C:\WINDOWS\TEMP\CS105ABDA1-C720-42A3-A2D4-E7EAD5506F79.tmp
H 9/08/2005 7:05:24 PM 0 C:\WINDOWS\TEMP\CS9E12D83A-3B6A-4279-A3B8-633C9E9F8E18.tmp
H 9/08/2005 7:05:24 PM 0 C:\WINDOWS\TEMP\CS0F46096D-7073-4075-A1BD-7FAE680FB902.tmp
H 9/08/2005 7:05:24 PM 0 C:\WINDOWS\TEMP\CS77BD85DB-35BF-49FE-B65A-22CDE43B23A8.tmp
H 9/08/2005 7:05:24 PM 0 C:\WINDOWS\TEMP\CSD99E60F2-B4CD-48B4-97D3-334E82595AAF.tmp
H 9/08/2005 7:05:24 PM 0 C:\WINDOWS\TEMP\CS1995425A-FE12-4060-A586-A8D252458646.tmp
H 9/08/2005 7:05:24 PM 0 C:\WINDOWS\TEMP\CS2B448033-0B1F-4755-B0FB-6521991A11EA.tmp
H 9/08/2005 7:05:24 PM 0 C:\WINDOWS\TEMP\CS49A4ADEA-B8E2-475F-95C0-511DC7B1F310.tmp
H 9/08/2005 7:05:24 PM 0 C:\WINDOWS\TEMP\CSD9EA952D-D788-48FB-8293-B762AFBCCEB9.tmp
H 9/08/2005 7:05:24 PM 0 C:\WINDOWS\TEMP\CSB41AA1D1-0069-4B75-AF7F-47E85B83B7E3.tmp
H 9/08/2005 7:05:24 PM 0 C:\WINDOWS\TEMP\CSF3B258E2-9D3A-452D-9232-5C333425275F.tmp
H 9/08/2005 7:05:24 PM 0 C:\WINDOWS\TEMP\CSF89CDF52-C434-4588-A4D2-0EB2143C3C41.tmp
H 9/08/2005 7:05:24 PM 0 C:\WINDOWS\TEMP\CS91B4D950-8CA7-46D5-B144-940C23494C2F.tmp
H 9/08/2005 7:05:24 PM 0 C:\WINDOWS\TEMP\CS68F244D4-D171-4766-84C5-F240B1DA24F2.tmp
H 9/08/2005 7:05:24 PM 0 C:\WINDOWS\TEMP\CSA2786F60-6662-43F1-9BED-8BCD2F55D625.tmp
H 9/08/2005 7:05:24 PM 0 C:\WINDOWS\TEMP\CS7D949131-A7E9-4B7B-B38F-F19CE609F193.tmp
H 9/08/2005 7:05:24 PM 0 C:\WINDOWS\TEMP\CS171B596F-2733-48A0-903A-23E4F574DB18.tmp
H 9/08/2005 7:05:24 PM 0 C:\WINDOWS\TEMP\CS49478F7B-DF8E-4F44-A6AA-73B543DFC2C9.tmp
H 9/08/2005 7:05:24 PM 0 C:\WINDOWS\TEMP\CS4129EB5D-8AB2-4DDA-86C8-D4785B4A1C1A.tmp
H 9/08/2005 7:05:24 PM 0 C:\WINDOWS\TEMP\CSC642CE8D-78E6-47DA-931B-95B266C33BE5.tmp
H 9/08/2005 7:05:24 PM 0 C:\WINDOWS\TEMP\CSFCF89B45-8A1D-4469-81C1-1AC44E9498CA.tmp
H 9/08/2005 7:05:24 PM 0 C:\WINDOWS\TEMP\CS127129CB-E8EA-4335-BEE5-51F86EDA855B.tmp
H 9/08/2005 7:05:24 PM 0 C:\WINDOWS\TEMP\CSA5F8407D-406E-4926-8379-7039E91CA528.tmp
H 9/08/2005 7:05:24 PM 0 C:\WINDOWS\TEMP\CS5FF7061E-9738-4E79-ACE1-460823C8152C.tmp
H 9/08/2005 7:05:24 PM 0 C:\WINDOWS\TEMP\CS51BD6470-73CC-42CB-A13D-DEC024C70350.tmp
H 9/08/2005 7:05:24 PM 0 C:\WINDOWS\TEMP\CSA3C8F846-87FB-4868-981C-09944FC6DFD0.tmp
H 9/08/2005 7:05:24 PM 0 C:\WINDOWS\TEMP\CSDCD2CB01-314E-41E4-A5B9-379D3F0431B0.tmp
H 9/08/2005 7:05:24 PM 0 C:\WINDOWS\TEMP\CSF5E1275B-537B-40ED-8E83-03AE1266B8B6.tmp
H 9/08/2005 7:10:38 PM 0 C:\WINDOWS\TEMP\CSEC4788F8-6B9C-498D-9519-929C1FF29649.tmp
H 9/08/2005 7:10:38 PM 0 C:\WINDOWS\TEMP\CS4AAD1C11-5761-4525-A041-181F14CCBB90.tmp
H 9/08/2005 7:10:38 PM 0 C:\WINDOWS\TEMP\CSE3AD8867-1837-457B-ACD4-DF0E2BDCFC06.tmp
H 9/08/2005 7:10:38 PM 0 C:\WINDOWS\TEMP\CSBAABE5AA-3965-4AA0-871E-F5202D1B462D.tmp
H 9/08/2005 7:10:38 PM 0 C:\WINDOWS\TEMP\CSBF20D627-3260-41EE-B5F7-64DD4419CA73.tmp
H 9/08/2005 7:10:38 PM 0 C:\WINDOWS\TEMP\CS56ACF3E9-F956-408F-ACFA-E1568D2E9C41.tmp
H 9/08/2005 7:10:38 PM 0 C:\WINDOWS\TEMP\CS0CA69294-9FB0-4B73-99C6-AFA1F06C24D6.tmp
H 9/08/2005 7:10:38 PM 0 C:\WINDOWS\TEMP\CS100EFBE1-2FB3-42D0-B315-818D54CA7A11.tmp
H 9/08/2005 7:10:38 PM 0 C:\WINDOWS\TEMP\CSBC57D636-7E33-43F4-8EF0-4129E6B2C56E.tmp
H 9/08/2005 7:10:38 PM 0 C:\WINDOWS\TEMP\CS5061D2AC-738A-429C-8AF1-3C0F139A7A3F.tmp
H 9/08/2005 7:10:38 PM 0 C:\WINDOWS\TEMP\CS1BE66A5E-6D38-4BE0-951D-298141BFA6AD.tmp
H 9/08/2005 7:10:38 PM 0 C:\WINDOWS\TEMP\CSAD00973D-1698-4354-9492-90B1D6CB32AB.tmp
H 9/08/2005 7:10:38 PM 0 C:\WINDOWS\TEMP\CSECB66C46-8C6F-4212-B2E2-2416F38BA939.tmp
H 9/08/2005 7:10:38 PM 0 C:\WINDOWS\TEMP\CSD8FD5916-405F-4C18-A821-9CA0195C9E11.tmp
H 9/08/2005 7:10:38 PM 0 C:\WINDOWS\TEMP\CSB8695BFD-8A0D-4A74-8D7B-A4C579716794.tmp
H 9/08/2005 7:10:38 PM 0 C:\WINDOWS\TEMP\CSC66C7CB4-6F3D-4D8F-824E-40C46D05DEB3.tmp
H 9/08/2005 7:10:38 PM 0 C:\WINDOWS\TEMP\CSEF980911-9F0E-4F81-B9D5-6B78E9544823.tmp
H 9/08/2005 7:10:38 PM 0 C:\WINDOWS\TEMP\CS1AA9747F-92A9-4274-9670-965299DE9922.tmp
H 9/08/2005 7:10:38 PM 0 C:\WINDOWS\TEMP\CS0CAAB94E-B6E9-45E8-B5FF-E4A8C1F03B87.tmp
H 9/08/2005 7:10:38 PM 0 C:\WINDOWS\TEMP\CS5447E7F9-8CDE-475A-95A2-314ADD9F715E.tmp
H 9/08/2005 7:10:38 PM 0 C:\WINDOWS\TEMP\CS831FC599-F7D4-413A-91E5-4C64A4B69B2B.tmp
H 9/08/2005 7:10:38 PM 0 C:\WINDOWS\TEMP\CSF7493D3F-1A17-4823-A0B0-1491BF0FF83B.tmp
H 9/08/2005 7:10:38 PM 0 C:\WINDOWS\TEMP\CS322FC73E-953B-4744-90EA-9EB1F4FDCCC4.tmp
H 9/08/2005 7:10:38 PM 0 C:\WINDOWS\TEMP\CS90C5DC70-D454-436B-AA77-B43331F7CE05.tmp
H 9/08/2005 7:10:38 PM 0 C:\WINDOWS\TEMP\CS7E6C7B23-B554-45C9-960B-1DFD8E8F06FE.tmp
H 9/08/2005 7:10:38 PM 0 C:\WINDOWS\TEMP\CS1E918857-34F1-44D1-A0F0-65BC8B74E46A.tmp
H 9/08/2005 7:10:38 PM 0 C:\WINDOWS\TEMP\CS7E0A57ED-6CB9-4A94-BEE9-B623A2B64D47.tmp
H 9/08/2005 7:10:38 PM 0 C:\WINDOWS\TEMP\CS7BF22C2D-38C3-46EB-8772-EF848D83CFE7.tmp
H 9/08/2005 7:10:38 PM 0 C:\WINDOWS\TEMP\CSA3E445CC-C01D-4ABB-9E22-3AF265B89C71.tmp
H 9/08/2005 7:10:38 PM 0 C:\WINDOWS\TEMP\CSA992EAC5-10E4-41BF-8537-9A24784924CC.tmp
H 9/08/2005 7:10:38 PM 0 C:\WINDOWS\TEMP\CS96D787FD-720D-493A-BAF9-59A577102F95.tmp
H 9/08/2005 7:10:38 PM 0 C:\WINDOWS\TEMP\CS8C3FFE30-655E-4A3F-B5D8-C01AE0D07B48.tmp
H 9/08/2005 7:10:38 PM 0 C:\WINDOWS\TEMP\CS169A0E3C-B440-4F23-9DF5-C8DF35FC734A.tmp
H 9/08/2005 7:10:38 PM 0 C:\WINDOWS\TEMP\CSA244666B-F2C2-4A50-9607-C9E28E682350.tmp
H 9/08/2005 7:10:38 PM 0 C:\WINDOWS\TEMP\CS13B1E42D-A8F9-42BF-829B-8744CE91BBF2.tmp
H 9/08/2005 7:10:38 PM 0 C:\WINDOWS\TEMP\CS979DF069-1955-4985-A3F1-E2D236C12E5B.tmp
H 9/08/2005 7:10:38 PM 0 C:\WINDOWS\TEMP\CS8A77A7A1-4422-43E2-8211-6695CB6DE485.tmp
H 9/08/2005 7:10:38 PM 0 C:\WINDOWS\TEMP\CS3BCF066E-F1D6-4D76-B9AE-0C91E745BC9E.tmp
H 9/08/2005 7:10:38 PM 0 C:\WINDOWS\TEMP\CS1647C30D-FB23-4D55-9BA5-11C81B4710FD.tmp
H 9/08/2005 7:10:38 PM 0 C:\WINDOWS\TEMP\CS08ADAB14-3C75-4227-9878-E6C068EA5338.tmp
H 9/08/2005 7:10:38 PM 0 C:\WINDOWS\TEMP\CSD50872CF-6B03-4360-95DB-57B16DFB7CC9.tmp
H 9/08/2005 7:10:38 PM 0 C:\WINDOWS\TEMP\CSA294ACDD-53B9-4E79-BBD9-2014E81A2135.tmp
H 9/08/2005 7:10:38 PM 0 C:\WINDOWS\TEMP\CSAD811DCC-A633-4686-B042-37DE6D36E20C.tmp
H 9/08/2005 7:10:38 PM 0 C:\WINDOWS\TEMP\CSFA5D2D54-9589-4492-B0D3-920CF7FA9E72.tmp
H 9/08/2005 7:10:38 PM 0 C:\WINDOWS\TEMP\CSCB8B7779-5B75-474A-82B4-D3D80A1BC9E2.tmp
H 9/08/2005 7:10:38 PM 0 C:\WINDOWS\TEMP\CS93453C38-6190-484C-BBDB-24E88A568F9F.tmp
H 9/08/2005 7:10:38 PM 0 C:\WINDOWS\TEMP\CS328F1E98-F4E1-477D-8710-801A1B9B8FF3.tmp
H 9/08/2005 7:10:38 PM 0 C:\WINDOWS\TEMP\CS53982BAE-2FBA-4A5E-8F76-A63BB65FF74B.tmp
H 9/08/2005 7:10:38 PM 0 C:\WINDOWS\TEMP\CSBEBDDCE2-DD0F-4BCB-B7B8-4ECD108E46A5.tmp
H 9/08/2005 7:10:38 PM 0 C:\WINDOWS\TEMP\CSA9667BAC-A2CF-4EF7-8EA8-544EC4C2D020.tmp
H 9/08/2005 7:10:38 PM 0 C:\WINDOWS\TEMP\CS9CF10B10-8F39-428A-91A4-A96F01D7C227.tmp
H 9/08/2005 7:10:38 PM 0 C:\WINDOWS\TEMP\CS0AA0159F-D5FC-4533-9854-2A96143FD758.tmp
H 9/08/2005 7:10:38 PM 0 C:\WINDOWS\TEMP\CS9AE35BEA-3B39-4DB3-A356-D73B3B62DCC7.tmp
H 9/08/2005 7:10:38 PM 0 C:\WINDOWS\TEMP\CS8DCD6F27-2D95-48FE-9E6F-35D2E620400A.tmp
H 9/08/2005 7:10:38 PM 0 C:\WINDOWS\TEMP\CSCAFC36F8-2452-4976-807B-C6633DAC920F.tmp
H 9/08/2005 7:10:38 PM 0 C:\WINDOWS\TEMP\CSF8F70A71-B7DC-40F2-B001-1A845F720772.tmp
H 9/08/2005 7:10:38 PM 0 C:\WINDOWS\TEMP\CS6B56EC81-4D30-44D9-8E1C-8CFC8322F729.tmp
H 9/08/2005 7:10:38 PM 0 C:\WINDOWS\TEMP\CS5150B1A4-29C6-43F3-8BD8-EC828DE4A86B.tmp
H 9/08/2005 7:10:38 PM 0 C:\WINDOWS\TEMP\CS0FA589B1-FF28-424F-803A-4B7FFDBE9697.tmp
H 9/08/2005 7:10:38 PM 0 C:\WINDOWS\TEMP\CSA6B95849-4F26-472F-8CB6-400D2EE0056E.tmp
H 9/08/2005 7:10:38 PM 0 C:\WINDOWS\TEMP\CSA12B07FE-2A25-4775-9A45-1F17AC36B980.tmp
H 9/08/2005 7:10:38 PM 0 C:\WINDOWS\TEMP\CSB56A84CB-00D1-4429-9DCF-D57D3CFAE95E.tmp
H 9/08/2005 7:10:38 PM 0 C:\WINDOWS\TEMP\CSCEE13AE3-E307-43FA-98EC-B14277428CE8.tmp
H 9/08/2005 7:10:38 PM 0 C:\WINDOWS\TEMP\CS2489996A-57DA-4919-B28D-A663FF1B4542.tmp
H 9/08/2005 7:10:38 PM 0 C:\WINDOWS\TEMP\CS431D03BC-14C1-439B-927F-CFDD54DD58C9.tmp
H 9/08/2005 7:10:38 PM 0 C:\WINDOWS\TEMP\CSB8CE1E31-5736-46D0-95E3-5FEA508C3F3D.tmp
H 9/08/2005 7:10:38 PM 0 C:\WINDOWS\TEMP\CSBD7E076E-F67B-48EF-B31A-D290AC5C21B6.tmp
H 9/08/2005 7:10:38 PM 0 C:\WINDOWS\TEMP\CS6DC80571-CBA6-4F57-B8F7-EB10A3B5AAA5.tmp
H 9/08/2005 7:10:38 PM 0 C:\WINDOWS\TEMP\CS25774F5C-9D40-4A48-99A3-EFC547F44AAB.tmp
H 10/08/2005 5:27:36 PM 0 C:\WINDOWS\TEMP\CS08B1317E-EED3-4230-8A9A-B3A5B9E4305A.tmp
H 10/08/2005 5:27:36 PM 0 C:\WINDOWS\TEMP\CSC4D1A53D-A6A6-439B-A893-425EF1C9629A.tmp
H 10/08/2005 5:27:36 PM 0 C:\WINDOWS\TEMP\CS896A3B14-0011-4999-97F6-39B967A01580.tmp
H 10/08/2005 5:27:36 PM 0 C:\WINDOWS\TEMP\CSCB598D73-08B8-4182-95FD-F709017BBFAA.tmp
H 10/08/2005 5:27:36 PM 0 C:\WINDOWS\TEMP\CS3965D14B-3DC9-465A-99A6-EA48D7D97AAF.tmp
H 10/08/2005 5:27:36 PM 0 C:\WINDOWS\TEMP\CS1FED6C49-8783-4107-ACBD-50D3F820DEE0.tmp
H 10/08/2005 5:27:36 PM 0 C:\WINDOWS\TEMP\CS68114261-E622-4F97-B67C-591A085C45AD.tmp
H 10/08/2005 5:27:36 PM 0 C:\WINDOWS\TEMP\CSBB72C5B2-A63F-4DF9-987A-8A76757447E6.tmp
H 10/08/2005 5:27:36 PM 0 C:\WINDOWS\TEMP\CSE7F86FEF-6DCD-47B0-9F88-7721B6F6D158.tmp
H 10/08/2005 5:27:36 PM 0 C:\WINDOWS\TEMP\CS8A395779-646B-4809-9571-92B1EB60A6E7.tmp
H 10/08/2005 5:27:36 PM 0 C:\WINDOWS\TEMP\CS7CF92419-FD08-4F41-8F2E-1525C20B5698.tmp
H 10/08/2005 5:27:36 PM 0 C:\WINDOWS\TEMP\CS4732EFEA-CB1B-4A6B-B1E3-5DE1BEC87223.tmp
H 10/08/2005 5:27:36 PM 0 C:\WINDOWS\TEMP\CS3D72336C-922F-46F1-9C9E-64F89DEA8A13.tmp
H 10/08/2005 5:27:36 PM 0 C:\WINDOWS\TEMP\CSFAC12731-2950-4FD1-9617-079CC70E2AC3.tmp
H 10/08/2005 5:27:36 PM 0 C:\WINDOWS\TEMP\CS887BC30A-CB7D-4EEF-9510-109120B349A9.tmp
H 10/08/2005 5:27:36 PM 0 C:\WINDOWS\TEMP\CS18B08087-281F-4DA7-BE43-7D815779239A.tmp
H 10/08/2005 5:27:36 PM 0 C:\WINDOWS\TEMP\CSD3F3B5C5-8D2E-4EF9-A16B-7294F8AD6161.tmp
H 10/08/2005 5:27:36 PM 0 C:\WINDOWS\TEMP\CS92045B2A-CCCB-4E31-8D77-540E37571EA7.tmp
H 10/08/2005 5:27:36 PM 0 C:\WINDOWS\TEMP\CS92F6267A-4EF8-4796-8C15-3C52679ECDB3.tmp
H 10/08/2005 5:27:36 PM 0 C:\WINDOWS\TEMP\CSEF1C0411-BFDA-4F8C-BD3B-DE1D10B01269.tmp
H 10/08/2005 5:27:36 PM 0 C:\WINDOWS\TEMP\CS4F3BEC6E-053E-4838-9271-E52491696E79.tmp
H 10/08/2005 5:27:36 PM 0 C:\WINDOWS\TEMP\CS25A144C6-B81B-483F-88CB-652FADEF97F3.tmp
H 10/08/2005 5:27:36 PM 0 C:\WINDOWS\TEMP\CSD41A8C6A-DDFF-4420-87EE-2C31D4A547FF.tmp
H 10/08/2005 5:27:36 PM 0 C:\WINDOWS\TEMP\CS42B9F3CD-FFBC-47C3-A873-D875C7471D7C.tmp
H 10/08/2005 5:27:36 PM 0 C:\WINDOWS\TEMP\CSA92072AE-1BA7-42B2-80BB-DA94694BF60C.tmp
H 10/08/2005 5:27:36 PM 0 C:\WINDOWS\TEMP\CS46EAF570-6390-43DA-B2CA-3023FF71AD9B.tmp
H 10/08/2005 5:27:36 PM 0 C:\WINDOWS\TEMP\CS2E8C8924-5949-4D4E-BD99-E994971E9243.tmp
H 10/08/2005 5:27:36 PM 0 C:\WINDOWS\TEMP\CSB768BD67-3019-4346-AF1D-BFA3BD64D40F.tmp
H 10/08/2005 5:27:36 PM 0 C:\WINDOWS\TEMP\CSC940B43F-84AB-4DAF-ABD4-C3FB3077DE77.tmp
H 10/08/2005 5:27:36 PM 0 C:\WINDOWS\TEMP\CS61628CCC-925F-452C-B18A-56BC89C28806.tmp
H 10/08/2005 5:27:36 PM 0 C:\WINDOWS\TEMP\CS0238E1ED-8B92-4722-86C6-C4E6EA2C0F99.tmp
H 10/08/2005 5:27:36 PM 0 C:\WINDOWS\TEMP\CS763FE3F0-B26E-480D-A917-4E633FC765E8.tmp
H 10/08/2005 5:28:14 PM 0 C:\WINDOWS\TEMP\CS988487CF-8493-440F-BD4B-0332E5A1F8A7.tmp
H 10/08/2005 5:28:14 PM 0 C:\WINDOWS\TEMP\CS9DE5DF5B-788B-424C-81F2-CC0161F89B44.tmp
H 10/08/2005 5:28:14 PM 0 C:\WINDOWS\TEMP\CS81F26EC7-3FD3-4CF7-9E66-5CA3D02B0C30.tmp
H 10/08/2005 5:28:14 PM 0 C:\WINDOWS\TEMP\CSFFD795B5-CE9F-460D-803D-33BD8E5323E1.tmp
H 10/08/2005 5:28:14 PM 0 C:\WINDOWS\TEMP\CSC90A322B-32B0-4C32-86E4-6CEC116683D3.tmp
H 10/08/2005 5:28:14 PM 0 C:\WINDOWS\TEMP\CS9B855FC4-1270-4BC7-88A2-634932792500.tmp
H 10/08/2005 5:28:14 PM 0 C:\WINDOWS\TEMP\CS7C6E48FC-4DDF-45B2-8508-CF921FBD0A51.tmp
H 10/08/2005 5:28:14 PM 0 C:\WINDOWS\TEMP\CSC44CD1AE-7358-4486-9127-0041C2BBC8AB.tmp
H 10/08/2005 5:28:14 PM 0 C:\WINDOWS\TEMP\CS2C87C7CC-D3AD-4171-93AA-8907EA7AAC7B.tmp
H 10/08/2005 5:28:14 PM 0 C:\WINDOWS\TEMP\CS653F8D2E-A84A-4CE1-9CE9-9FB79C37D9FE.tmp
H 10/08/2005 5:28:14 PM 0 C:\WINDOWS\TEMP\CS1229603A-A932-4B63-A939-9564115F0576.tmp
H 10/08/2005 5:28:16 PM 0 C:\WINDOWS\TEMP\CSF95B9439-EF57-4B42-ACD7-59B311C6BE8B.tmp
H 10/08/2005 5:28:16 PM 0 C:\WINDOWS\TEMP\CS1546BADD-5ED1-4521-B319-20FE58FD3B6D.tmp
H 10/08/2005 5:28:16 PM 0 C:\WINDOWS\TEMP\CSAFB5A7CE-18FA-4DBF-939B-B49486264944.tmp
H 10/08/2005 5:28:16 PM 0 C:\WINDOWS\TEMP\CSBE3D2630-EB8C-4864-B963-1D7210374979.tmp
H 10/08/2005 5:28:16 PM 0 C:\WINDOWS\TEMP\CSED7A2285-E348-4A3C-BFC3-E457E8781D1A.tmp
H 10/08/2005 5:28:16 PM 0 C:\WINDOWS\TEMP\CSDCE90FD4-38FB-431F-A570-7D29FA7733DA.tmp
H 10/08/2005 5:28:16 PM 0 C:\WINDOWS\TEMP\CS2464E384-4291-411E-8D98-B8E0059D3CBF.tmp
H 10/08/2005 5:28:16 PM 0 C:\WINDOWS\TEMP\CS97F8C803-C26E-4070-BC2D-7E0BEA43F48A.tmp
H 10/08/2005 5:28:16 PM 0 C:\WINDOWS\TEMP\CS3730C597-83C5-4497-9B39-775BC169357F.tmp
H 10/08/2005 5:28:16 PM 0 C:\WINDOWS\TEMP\CSECB84147-240A-463C-B6DE-E84844CA74F4.tmp
H 10/08/2005 5:28:16 PM 0 C:\WINDOWS\TEMP\CSE0844C5F-E785-405C-AFAF-C8EE4351E14E.tmp
H 10/08/2005 5:28:16 PM 0 C:\WINDOWS\TEMP\CSF3FCFD9B-44DD-4AA9-8E23-7E6B7CC88941.tmp
H 10/08/2005 5:28:16 PM 0 C:\WINDOWS\TEMP\CS5243CCFE-86E2-4D3F-882E-E805E2478EE4.tmp
H 10/08/2005 5:28:16 PM 0 C:\WINDOWS\TEMP\CSD7508AFC-CDE8-493A-985E-69B784EFB638.tmp
H 10/08/2005 5:28:16 PM 0 C:\WINDOWS\TEMP\CSA9445D61-2FEB-410A-AF5D-BE4D4B127607.tmp
H 10/08/2005 5:28:16 PM 0 C:\WINDOWS\TEMP\CS1E5A6F5F-66AC-49EE-A707-F1F5AB5F9BFF.tmp
H 10/08/2005 5:28:16 PM 0 C:\WINDOWS\TEMP\CS3C70303B-7392-46AA-9616-2A105E3E4166.tmp
H 10/08/2005 5:28:16 PM 0 C:\WINDOWS\TEMP\CS417266C0-30CF-4397-9B44-D17E4EE62EC6.tmp
H 10/08/2005 5:28:16 PM 0 C:\WINDOWS\TEMP\CS220CA920-EB69-4D39-B2B5-84DC2264F683.tmp
H 10/08/2005 5:28:16 PM 0 C:\WINDOWS\TEMP\CS211851FF-212F-4D7B-9F2A-FCBEB494F0A7.tmp
H 10/08/2005 5:28:16 PM 0 C:\WINDOWS\TEMP\CSAED296A0-1DD5-4A51-BCA9-7E63DDCCB4C3.tmp
H 10/08/2005 5:28:16 PM 0 C:\WINDOWS\TEMP\CS105E3E3E-15C8-4CAA-B1D4-D8A027C679AC.tmp
H 10/08/2005 5:28:16 PM 0 C:\WINDOWS\TEMP\CSD5783E65-D8E8-4496-865E-E3F685080CFF.tmp
H 10/08/2005 5:28:16 PM 0 C:\WINDOWS\TEMP\CS9FED2540-5AB6-4623-8F29-DD9383952E17.tmp
H 10/08/2005 5:28:16 PM 0 C:\WINDOWS\TEMP\CS24F690D5-6025-456E-979B-0F4A560B864A.tmp
H 10/08/2005 5:28:16 PM 0 C:\WINDOWS\TEMP\CSDA7E8951-1FD1-4745-B767-95224884B33F.tmp
H 10/08/2005 5:28:16 PM 0 C:\WINDOWS\TEMP\CS1E79887D-FD31-484D-AEA7-66238B888CDD.tmp
H 10/08/2005 5:28:16 PM 0 C:\WINDOWS\TEMP\CSA127C603-CD4A-4AEC-BB39-8CEFE58994B3.tmp
H 10/08/2005 5:28:16 PM 0 C:\WINDOWS\TEMP\CS844FE498-DB2B-4476-86DA-DD4BBCFB7ED9.tmp
H 10/08/2005 5:28:16 PM 0 C:\WINDOWS\TEMP\CS9BEE2A4E-6AFA-4B50-9F28-E3F093941F9F.tmp
H 10/08/2005 5:28:16 PM 0 C:\WINDOWS\TEMP\CSBF55579E-58A4-4D0C-8BCD-3739869B77BA.tmp
H 10/08/2005 5:28:16 PM 0 C:\WINDOWS\TEMP\CS0DAB603D-5343-43FC-ABC1-E05998C7D86A.tmp
H 10/08/2005 5:28:16 PM 0 C:\WINDOWS\TEMP\CSA3533A86-26EC-458D-ADDB-B18A0DB524F8.tmp
H 10/08/2005 5:28:16 PM 0 C:\WINDOWS\TEMP\CSC2D5DBAB-C038-42CA-B61E-419A5A0A765C.tmp
H 10/08/2005 5:28:16 PM 0 C:\WINDOWS\TEMP\CS9CD82AC3-BC97-4FBF-A1ED-04DC62F42545.tmp
H 10/08/2005 5:28:16 PM 0 C:\WINDOWS\TEMP\CS0285988F-B1F4-42CD-B2DB-5CE289819A07.tmp
H 10/08/2005 5:28:16 PM 0 C:\WINDOWS\TEMP\CS2E45FA51-3139-4486-AD1D-5CC88663E9EE.tmp
H 10/08/2005 5:28:16 PM 0 C:\WINDOWS\TEMP\CS3EFA4DB8-632C-4F8F-8F3C-84DB44CA116A.tmp
H 10/08/2005 5:28:16 PM 0 C:\WINDOWS\TEMP\CSC300C26B-1360-49BA-838C-3FA734C52BEB.tmp
H 10/08/2005 5:28:16 PM 0 C:\WINDOWS\TEMP\CS87758B86-BF68-4A6F-8AD2-0CC612D12B66.tmp
H 10/08/2005 5:28:16 PM 0 C:\WINDOWS\TEMP\CS556432A4-CEA5-4D3E-B361-7221345ED88D.tmp
H 10/08/2005 5:28:16 PM 0 C:\WINDOWS\TEMP\CS4547F690-CE9A-4A2B-BCA0-9E4F06163E24.tmp
H 10/08/2005 5:28:16 PM 0 C:\WINDOWS\TEMP\CS9E5BD038-C2A4-49AF-86B4-73220CA03F91.tmp
H 10/08/2005 5:28:16 PM 0 C:\WINDOWS\TEMP\CS4D40BE82-1230-4B0E-B2C9-EEDADD57CBDA.tmp
H 10/08/2005 5:28:16 PM 0 C:\WINDOWS\TEMP\CSF5FF0F1C-CD18-4F69-BB76-AB0DCFB7B99B.tmp
H 10/08/2005 5:28:16 PM 0 C:\WINDOWS\TEMP\CSEF2ED2A7-82FE-4ECE-8F69-DDEE8388D1DC.tmp
H 10/08/2005 5:28:16 PM 0 C:\WINDOWS\TEMP\CSADF151EE-F3DC-43D7-B9C3-7D288DC73B44.tmp
H 10/08/2005 5:28:16 PM 0 C:\WINDOWS\TEMP\CS022CB1E0-8353-453D-A26A-69689F967E71.tmp
H 10/08/2005 5:28:16 PM 0 C:\WINDOWS\TEMP\CS470F3CBD-244D-454C-A802-98C95F0AACEC.tmp
H 10/08/2005 5:28:16 PM 0 C:\WINDOWS\TEMP\CS01FBEC12-31CD-4FB8-8FC5-A38EBEB28FFB.tmp
H 10/08/2005 5:28:16 PM 0 C:\WINDOWS\TEMP\CS0F3C3B5A-5624-4C50-899C-352205D541C0.tmp
H 10/08/2005 5:28:16 PM 0 C:\WINDOWS\TEMP\CS6FE6188E-B06A-4460-927B-2B00144E631D.tmp
H 10/08/2005 5:28:16 PM 0 C:\WINDOWS\TEMP\CS83013C85-1A89-41D1-BA55-12FC15B0D141.tmp
H 10/08/2005 5:28:16 PM 0 C:\WINDOWS\TEMP\CSA1D22AC4-1566-4E62-8500-09C673E2B3DF.tmp
H 10/08/2005 5:28:16 PM 0 C:\WINDOWS\TEMP\CS1E4D58DF-B13A-48C0-B77E-6E2B3E9CDD31.tmp
H 10/08/2005 5:28:16 PM 0 C:\WINDOWS\TEMP\CSBFB291FF-8D25-4EFF-914F-090E73FF316A.tmp
H 10/08/2005 5:28:16 PM 0 C:\WINDOWS\TEMP\CS10A5C957-F01F-48C4-99FF-0E604F68B8F1.tmp
H 10/08/2005 5:28:16 PM 0 C:\WINDOWS\TEMP\CS057CC2A0-9746-49C5-B72A-4B57FAC71835.tmp
H 10/08/2005 8:57:46 PM 0 C:\WINDOWS\TEMP\CS5821B43E-F003-457D-BDCE-317018A3ED26.tmp
H 10/08/2005 8:57:46 PM 0 C:\WINDOWS\TEMP\CS661B085D-617D-42D0-A8BF-9D742F681C40.tmp
H 10/08/2005 8:57:46 PM 0 C:\WINDOWS\TEMP\CS49385D2F-291F-4A06-B384-D036B5698A1A.tmp
H 10/08/2005 8:57:46 PM 0 C:\WINDOWS\TEMP\CSBEA3A1DA-49DB-4AD0-9E7C-FC72475ED7F8.tmp
H 10/08/2005 8:57:46 PM 0 C:\WINDOWS\TEMP\CS58BEA37D-E774-4C09-8AB5-7D8D6DA27C67.tmp
H 10/08/2005 8:57:46 PM 0 C:\WINDOWS\TEMP\CS6C18BF77-13BB-45E0-9730-A8F678FD8116.tmp
H 10/08/2005 8:57:46 PM 0 C:\WINDOWS\TEMP\CSD5AE453C-1EC9-474D-9801-170D6D177F66.tmp
H 10/08/2005 8:57:46 PM 0 C:\WINDOWS\TEMP\CSAEDD6E5F-E25B-4948-94B2-64C9D1D01958.tmp
H 10/08/2005 8:57:46 PM 0 C:\WINDOWS\TEMP\CSFDDA0936-ECB8-47D3-B143-2560C32BF278.tmp
H 10/08/2005 8:57:46 PM 0 C:\WINDOWS\TEMP\CS37B414B1-C5E4-4A58-9212-DDC090A8397B.tmp
H 10/08/2005 8:57:46 PM 0 C:\WINDOWS\TEMP\CS909DDF3D-DDA2-4D7B-98A4-466602CB3F23.tmp
H 10/08/2005 8:57:46 PM 0 C:\WINDOWS\TEMP\CS4139941B-BAE2-46CC-BC0C-ABB64E7FE0CD.tmp
H 10/08/2005 8:57:46 PM 0 C:\WINDOWS\TEMP\CSA1585960-6746-407A-AF66-DDF1D393B42D.tmp
H 10/08/2005 8:57:46 PM 0 C:\WINDOWS\TEMP\CS3BFE5166-D705-405B-91BC-B6A35325B92C.tmp
H 10/08/2005 8:57:46 PM 0 C:\WINDOWS\TEMP\CSDDAB589B-C47B-40A5-A2EF-433D4E7D6B08.tmp
H 10/08/2005 8:57:46 PM 0 C:\WINDOWS\TEMP\CS29F6326D-3ABB-4CA1-B79C-390E2846DA46.tmp
H 10/08/2005 8:57:46 PM 0 C:\WINDOWS\TEMP\CSC0EA89E2-705D-489C-B443-F7A4A5E48B79.tmp
H 10/08/2005 8:57:46 PM 0 C:\WINDOWS\TEMP\CS16317D5D-47F5-441C-A1F8-70BA6DB62E08.tmp
H 10/08/2005 8:57:46 PM 0 C:\WINDOWS\TEMP\CSC080B830-DCC6-49E1-A506-11B7A3E251EC.tmp
H 10/08/2005 8:57:46 PM 0 C:\WINDOWS\TEMP\CS3730C0BE-1B53-470F-8DFB-A07C0567D416.tmp
H 10/08/2005 8:57:46 PM 0 C:\WINDOWS\TEMP\CS41CFCEA7-FFCC-4438-A6E7-FCBA2BC343DC.tmp
H 10/08/2005 8:57:46 PM 0 C:\WINDOWS\TEMP\CSE07A08A2-B876-476D-9E65-D5E4E00F1FCB.tmp
H 10/08/2005 8:57:46 PM 0 C:\WINDOWS\TEMP\CSD295914C-5194-46B3-B6E0-7E46BCCA0693.tmp
H 10/08/2005 8:57:46 PM 0 C:\WINDOWS\TEMP\CS003DDC6E-2BE6-4FA0-A811-5FD42BA0A485.tmp
H 10/08/2005 8:57:46 PM 0 C:\WINDOWS\TEMP\CS2292930B-66EF-4624-8145-5CD3AB93F805.tmp
H 10/08/2005 8:57:46 PM 0 C:\WINDOWS\TEMP\CS184A8851-B2FC-4B77-8676-E0D1B6E8132C.tmp
H 10/08/2005 8:57:46 PM 0 C:\WINDOWS\TEMP\CS281DFF61-EE08-4304-9224-3A72A970BDB3.tmp
H 10/08/2005 8:57:46 PM 0 C:\WINDOWS\TEMP\CSAC472CBA-5F27-49DA-9C89-0122034D52D7.tmp
H 10/08/2005 8:57:46 PM 0 C:\WINDOWS\TEMP\CS6B9248FD-1B38-43AE-A75E-6EA28B5BAB3E.tmp
H 10/08/2005 8:57:46 PM 0 C:\WINDOWS\TEMP\CS50A20324-D375-4D8D-9E35-E3B9E55BEC00.tmp
H 10/08/2005 8:57:46 PM 0 C:\WINDOWS\TEMP\CS3CA5F656-6EF2-4C0E-A858-574F6A75B420.tmp
H 10/08/2005 8:57:46 PM 0 C:\WINDOWS\TEMP\CSA692CB64-98B8-4924-AD22-4D477CD53A6B.tmp
H 10/08/2005 9:02:22 PM 0 C:\WINDOWS\TEMP\CSDE4F58EA-7814-4784-A182-F98D7C7C7072.tmp
H 10/08/2005 9:02:22 PM 0 C:\WINDOWS\TEMP\CS7ABB0B65-1E72-421F-B1CD-E26DCBBD6458.tmp
H 10/08/2005 9:02:22 PM 0 C:\WINDOWS\TEMP\CS3C8B32C2-041E-4AE4-8302-868A49C22D2A.tmp
H 10/08/2005 9:02:22 PM 0 C:\WINDOWS\TEMP\CS3DCF460E-E476-41D7-AE43-7A7369BA534A.tmp
H 10/08/2005 9:02:22 PM 0 C:\WINDOWS\TEMP\CS4D62763D-F293-4112-915D-E8EAE3119BD3.tmp
H 10/08/2005 9:02:22 PM 0 C:\WINDOWS\TEMP\CSEB2145DB-4C43-4F64-AB6F-1CD1A41CC03A.tmp
H 10/08/2005 9:02:22 PM 0 C:\WINDOWS\TEMP\CS4CA4635A-2ADD-4432-9113-18CEE4AEAF2D.tmp
H 10/08/2005 9:02:22 PM 0 C:\WINDOWS\TEMP\CS584BF990-88C1-4BAB-9D2C-5F914B2BA3DC.tmp
H 10/08/2005 9:02:22 PM 0 C:\WINDOWS\TEMP\CSD98E8073-B01A-45E5-9C49-3B7EB6128C59.tmp
H 10/08/2005 9:02:22 PM 0 C:\WINDOWS\TEMP\CS09591727-05D6-43E1-8490-C7901059C565.tmp
H 10/08/2005 9:02:22 PM 0 C:\WINDOWS\TEMP\CS76A92558-B51A-4990-892B-69091722B08E.tmp
H 10/08/2005 9:02:22 PM 0 C:\WINDOWS\TEMP\CS8BE2BA56-45DB-4A8E-A2E0-6EFA1B99A6E7.tmp
H 10/08/2005 9:02:22 PM 0 C:\WINDOWS\TEMP\CS63E2D6F8-83B5-4349-B440-F11C1EDDABF0.tmp
H 10/08/2005 9:02:22 PM 0 C:\WINDOWS\TEMP\CS5B6D26B3-195A-4784-B58B-C452C1BE730A.tmp
H 10/08/2005 9:02:22 PM 0 C:\WINDOWS\TEMP\CS35343A49-90E6-4E74-94CE-1C4CF9657110.tmp
H 10/08/2005 9:02:22 PM 0 C:\WINDOWS\TEMP\CSB9467928-6AF3-4441-994F-C38A0E0A1EDF.tmp
H 10/08/2005 9:02:22 PM 0 C:\WINDOWS\TEMP\CS748F38A2-F199-4F13-8214-E507F1779790.tmp
H 10/08/2005 9:02:22 PM 0 C:\WINDOWS\TEMP\CSD957D7EE-2D0D-455C-9F62-B032CC096569.tmp
H 10/08/2005 9:02:22 PM 0 C:\WINDOWS\TEMP\CSDE3C0712-AB6A-4574-8BC6-3C9AECBEFF1C.tmp
H 10/08/2005 9:02:22 PM 0 C:\WINDOWS\TEMP\CS59D5F80B-600A-434E-80A1-F51AFBC43625.tmp
H 10/08/2005 9:02:22 PM 0 C:\WINDOWS\TEMP\CS2B6F4B05-CC19-47DA-B486-7DD35B3ADF85.tmp
H 10/08/2005 9:02:22 PM 0 C:\WINDOWS\TEMP\CS10CBF1D8-1D53-48DE-B34C-D3174470AA7F.tmp
H 10/08/2005 9:02:22 PM 0 C:\WINDOWS\TEMP\CS95115C13-D8EF-4B48-938E-011E7A91702A.tmp
H 10/08/2005 9:02:22 PM 0 C:\WINDOWS\TEMP\CS4573D29F-E379-468A-9DBF-1412A3E72685.tmp
H 10/08/2005 9:02:22 PM 0 C:\WINDOWS\TEMP\CSC272FA0E-4F53-4C52-B433-F7857658CDDF.tmp
H 10/08/2005 9:02:22 PM 0 C:\WINDOWS\TEMP\CS105AE4DE-D440-4B9A-BD7D-633BAB086D05.tmp
H 10/08/2005 9:02:22 PM 0 C:\WINDOWS\TEMP\CS40F4F1F8-CB06-49A4-9C85-7B76912A59B7.tmp
H 10/08/2005 9:02:22 PM 0 C:\WINDOWS\TEMP\CS0720632F-6ABD-4D66-B264-293F5EAB6850.tmp
H 10/08/2005 9:02:22 PM 0 C:\WINDOWS\TEMP\CS9E37D24C-1309-4A96-B99F-A7D4AA4F61E3.tmp
H 10/08/2005 9:02:22 PM 0 C:\WINDOWS\TEMP\CSE87E70C2-10E7-41E8-A782-920A1D15D923.tmp
H 10/08/2005 9:02:22 PM 0 C:\WINDOWS\TEMP\CS06722E9C-8067-4FF2-9612-8EE5CB571906.tmp
H 10/08/2005 9:02:22 PM 0 C:\WINDOWS\TEMP\CS9727F126-CFC9-4627-A723-2CFBB83C29FD.tmp
H 10/08/2005 9:02:22 PM 0 C:\WINDOWS\TEMP\CS97C46565-1152-47CC-A9EA-03E98B3295BA.tmp
H 10/08/2005 9:02:22 PM 0 C:\WINDOWS\TEMP\CSCE7F7E7E-D97D-4255-AABB-8571AF0F8FB9.tmp
H 10/08/2005 9:02:22 PM 0 C:\WINDOWS\TEMP\CS3F0218D4-F283-4E72-9696-FDEC46A21412.tmp
H 10/08/2005 9:02:22 PM 0 C:\WINDOWS\TEMP\CSE68E588B-0FE2-4B7D-AF9C-A1D12985E18F.tmp
H 10/08/2005 9:02:22 PM 0 C:\WINDOWS\TEMP\CS24113309-77F9-4C84-89EA-9EC2CAF0C47E.tmp
H 10/08/2005 9:02:22 PM 0 C:\WINDOWS\TEMP\CS6AA9983B-5660-4EA7-8126-86BD938A6FE2.tmp
H 10/08/2005 9:02:22 PM 0 C:\WINDOWS\TEMP\CS707C0009-2287-4F06-82B2-7D9456600BD0.tmp
H 10/08/2005 9:02:22 PM 0 C:\WINDOWS\TEMP\CSEC707E4C-7602-4ED8-9C2B-6CBBC520A987.tmp
H 10/08/2005 9:02:22 PM 0 C:\WINDOWS\TEMP\CSDB785FD3-2015-4BD4-849E-8D5400DBDB33.tmp
H 10/08/2005 9:02:22 PM 0 C:\WINDOWS\TEMP\CSED6A0F70-62C9-4C3F-A2CB-4B1A8D154BFA.tmp
H 10/08/2005 9:02:22 PM 0 C:\WINDOWS\TEMP\CS482AFF2E-8473-472E-96AA-D2136463CF11.tmp
H 10/08/2005 9:02:22 PM 0 C:\WINDOWS\TEMP\CSEC50E712-3EA5-4942-AE2D-B9AC62E1E9BE.tmp
H 10/08/2005 9:02:22 PM 0 C:\WINDOWS\TEMP\CS38C66D31-F2DB-4D90-AFD7-C4B62AA8D92C.tmp
H 10/08/2005 9:02:22 PM 0 C:\WINDOWS\TEMP\CSDFB192AC-5D59-4203-972C-F1958EDA0F6F.tmp
H 10/08/2005 9:02:22 PM 0 C:\WINDOWS\TEMP\CSFBEAAB6B-BC7D-4E51-B803-4EC7980516BE.tmp
H 10/08/2005 9:02:22 PM 0 C:\WINDOWS\TEMP\CS7F592C8D-DF39-4539-BB50-FB347FF353BC.tmp
H 10/08/2005 9:02:22 PM 0 C:\WINDOWS\TEMP\CSDA590D27-7ACB-43F7-B89C-15F1AE113EEC.tmp
H 10/08/2005 9:02:22 PM 0 C:\WINDOWS\TEMP\CS01301647-E4DE-448D-8612-A3744F4D0296.tmp
H 10/08/2005 9:02:22 PM 0 C:\WINDOWS\TEMP\CSCECB0FDD-AA89-447C-980D-1BDCE4D19895.tmp
H 10/08/2005 9:02:22 PM 0 C:\WINDOWS\TEMP\CS4CBD6FA0-6D3A-4F5E-BAA8-ACA4997D59A5.tmp
H 10/08/2005 9:02:22 PM 0 C:\WINDOWS\TEMP\CS75AA1025-413D-4A46-9085-DB7AF31D2290.tmp
H 10/08/2005 9:02:22 PM 0 C:\WINDOWS\TEMP\CS61308DB2-8962-44CB-AD11-EE89C68E8071.tmp
H 10/08/2005 9:02:22 PM 0 C:\WINDOWS\TEMP\CSCB7C3B02-CAFC-4C47-8585-B1514BB462CF.tmp
H 10/08/2005 9:02:22 PM 0 C:\WINDOWS\TEMP\CS511466A4-FC56-44CE-8B82-EC97AD8707AB.tmp
H 10/08/2005 9:02:22 PM 0 C:\WINDOWS\TEMP\CS1A4C2854-BAB1-4C7C-85C6-5A85D68B8770.tmp
H 10/08/2005 9:02:22 PM 0 C:\WINDOWS\TEMP\CS2DD895AC-094C-40B1-8EE7-CCBAD1FED5A0.tmp
H 10/08/2005 9:02:22 PM 0 C:\WINDOWS\TEMP\CS61B12A54-8436-4510-8C73-026D2832FE5D.tmp
H 10/08/2005 9:02:22 PM 0 C:\WINDOWS\TEMP\CS68D7E890-A571-4DE5-B53A-D46F70E7A05C.tmp
H 10/08/2005 9:02:22 PM 0 C:\WINDOWS\TEMP\CSB7A5451D-F21A-4992-826E-6E1029581976.tmp
H 10/08/2005 9:02:22 PM 0 C:\WINDOWS\TEMP\CSB9DC2620-9E4B-41CA-BE80-49AB49F60E16.tmp
H 10/08/2005 9:02:22 PM 0 C:\WINDOWS\TEMP\CSC8980620-D059-45FC-B153-CCCF380C03A8.tmp

Checking for CPL files...

#10 OldTimer

OldTimer

    Malware Expert


  • Members
  • 11,092 posts
  • OFFLINE
  •  
  • Gender:Male
  • Location:North Carolina
  • Local time:01:31 AM

Posted 19 August 2005 - 02:28 PM

Hi Marci4. that looks like the newer verison but it is still only a partial log. Part of the reason appears to be all of the files in the temp folders.

Try running CCleaner before running the WinPFind program. That should clean out all of the garbage.

After that, run WinPFind. When you post the log back, look at the bottom line. If it does not include a message regarding the date/time the scan was run then make a secone post and in the log file start where the first post was cut off.

Cheers.

OT
I do not respond to PM's requesting help. That's what the forums are here for. Please use them so that others may benefit from your questions and the responses you receive.
OldTimer

Posted Image

#11 Marci4

Marci4
  • Topic Starter

  • Members
  • 18 posts
  • OFFLINE
  •  
  • Local time:12:31 AM

Posted 29 August 2005 - 02:44 AM

Ok, no matter what I do that's all that will scan (winPfind). It always stops at the same spot. I have tried everything (several times) now. Downloaded winpfind again (and again) - after competely deleting the previous one. Cleared cookies & temp files. But nothing seems to work. Started new scans many times... nothing. So now I'm completely lost.
Any ideas? I have no idea what I'm doing wrong.
Thanks
Marci

#12 OldTimer

OldTimer

    Malware Expert


  • Members
  • 11,092 posts
  • OFFLINE
  •  
  • Gender:Male
  • Location:North Carolina
  • Local time:01:31 AM

Posted 29 August 2005 - 11:10 AM

Hi Marci4. Let's try a couple of different things here in the following order.

Step 1

Since we have the data up to the cpl files let's remove that from the scan and see if we can get the rest to scan properly.

Start WinPFind and do the following:
  • Click the Configure Scan Options button
  • In the Folder Options group click the checkbox in front of each of the following to clear the checkmark:
    • System Drive Folder
    • Program Files Folder
    • Windows Folder
    • System Folder
    • Windows Folder / Sub-Folders 60 days or less
  • Click the Apply button
    Click the Start Scan button and post the results
If the above does not complete then proceed to Step 2.

Step 2

Go back to the Configuration screen as described above and clear the checkbox for the next item in the Folder Options group. Rerun the scan and try again.

Post the results back here for the scan that does complete.

Cheers.

OT
I do not respond to PM's requesting help. That's what the forums are here for. Please use them so that others may benefit from your questions and the responses you receive.
OldTimer

Posted Image

#13 Marci4

Marci4
  • Topic Starter

  • Members
  • 18 posts
  • OFFLINE
  •  
  • Local time:12:31 AM

Posted 29 August 2005 - 07:45 PM

ok, here it is - hope it's right this time. I also wated to ask you, s there any way I can edit my past posts? (I wanted to delete those past scans so they wouldn't take so much space). Thanks

WARNING: not all files found by this scanner are bad. Consult with a knowledgable person before proceeding.

If you see a message in the titlebar saying "Not responding..." you can ignore it. Windows somethimes displays this message due to the high volume of disk I/O. As long as the hard disk light is flashing, the program is still working properly.

»»»»»»»»»»»»»»»»» Windows OS and Versions »»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»
Product Name: Windows Millennium Edition Version: 4.90.3000
Internet Explorer Version: 6.0.2800.1106

»»»»»»»»»»»»»»»»» Checking Selected Standard Folders »»»»»»»»»»»»»»»»»»»»

Checking %System%\Drivers folder and sub-folders...

Checking for CPL files...
Microsoft Corporation 29/08/2002 7:07:38 AM 292352 C:\WINDOWS\SYSTEM\INETCPL.CPL
Microsoft Corporation 8/06/2000 5:00:00 PM 62464 C:\WINDOWS\SYSTEM\INTL.CPL
Microsoft Corporation 8/06/2000 5:00:00 PM 104368 C:\WINDOWS\SYSTEM\MODEM.CPL
Microsoft Corporation 8/06/2000 5:00:00 PM 41232 C:\WINDOWS\SYSTEM\ODBCCP32.CPL
Microsoft Corporation 8/06/2000 5:00:00 PM 61200 C:\WINDOWS\SYSTEM\POWERCFG.CPL
Microsoft Corporation 8/06/2000 5:00:00 PM 79872 C:\WINDOWS\SYSTEM\APPWIZ.CPL
Microsoft Corporation 8/06/2000 5:00:00 PM 221280 C:\WINDOWS\SYSTEM\DESK.CPL
Microsoft Corporation 8/06/2000 5:00:00 PM 250128 C:\WINDOWS\SYSTEM\JOY.CPL
Microsoft Corporation 8/06/2000 5:00:00 PM 111616 C:\WINDOWS\SYSTEM\MAIN.CPL
Microsoft Corporation 8/06/2000 5:00:00 PM 408576 C:\WINDOWS\SYSTEM\MMSYS.CPL
Microsoft Corporation 8/06/2000 5:00:00 PM 14448 C:\WINDOWS\SYSTEM\NETCPL.CPL
Microsoft Corporation 8/06/2000 5:00:00 PM 47104 C:\WINDOWS\SYSTEM\PASSWORD.CPL
Microsoft Corporation 8/06/2000 5:00:00 PM 389872 C:\WINDOWS\SYSTEM\SYSDM.CPL
Microsoft Corporation 8/06/2000 5:00:00 PM 15360 C:\WINDOWS\SYSTEM\TELEPHON.CPL
Microsoft Corporation 8/06/2000 5:00:00 PM 15152 C:\WINDOWS\SYSTEM\WUAUCPL.CPL
Microsoft Corporation 8/06/2000 5:00:00 PM 66560 C:\WINDOWS\SYSTEM\ACCESS.CPL
Microsoft Corporation 8/06/2000 5:00:00 PM 15360 C:\WINDOWS\SYSTEM\THEMES.CPL
Microsoft Corporation 8/06/2000 5:00:00 PM 36864 C:\WINDOWS\SYSTEM\TIMEDATE.CPL
Microsoft Corporation 10/02/1999 11:48:48 AM 40960 C:\WINDOWS\SYSTEM\FINDFAST.CPL
Apple Computer, Inc. 14/12/2003 9:20:50 AM 323072 C:\WINDOWS\SYSTEM\QuickTime.cpl
Sun Microsystems, Inc. 6/12/2004 9:31:48 PM 49265 C:\WINDOWS\SYSTEM\jpicpl32.cpl

»»»»»»»»»»»»»»»»» Checking Selected Startup Folders »»»»»»»»»»»»»»»»»»»»»

Checking files in %ALLUSERSPROFILE%\Startup folder...

Checking files in %ALLUSERSPROFILE%\Application Data folder...

Checking files in %USERPROFILE%\Startup folder...
28/03/2005 10:34:50 AM 560 C:\WINDOWS\Start Menu\Programs\StartUp\Microsoft Office.lnk

Checking files in %USERPROFILE%\Application Data folder...
29/08/2005 11:22:56 PM 1179 C:\WINDOWS\Application Data\dw.log
12/07/2005 5:06:48 PM 60328 C:\WINDOWS\Application Data\GDIPFONTCACHEV1.DAT
13/07/2005 9:54:58 PM 0 C:\WINDOWS\Application Data\Install.dat

»»»»»»»»»»»»»»»»» Checking Selected Registry Keys »»»»»»»»»»»»»»»»»»»»»»»

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\User Agent\Post Platform]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved]
{FEF10FA2-355E-4e06-9381-9B24D7F7CC88} = C:\WINDOWS\SYSTEM\SHELL32.DLL
{53C74826-AB99-4d33-ACA4-3117F51D3788} = C:\WINDOWS\SYSTEM\SHELL32.DLL
{E88DCCE0-B7B3-11d1-A9F0-00AA0060FA31} = C:\WINDOWS\SYSTEM\ZIPFLDR.DLL
{BD472F60-27FA-11cf-B8B4-444553540000} = C:\WINDOWS\SYSTEM\ZIPFLDR.DLL
{888DCA60-FC0A-11CF-8F0F-00C04FD7D062} = C:\WINDOWS\SYSTEM\ZIPFLDR.DLL

[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved]

[HKEY_CLASSES_ROOT\*\shellex\ContextMenuHandlers]
HKEY_CLASSES_ROOT\*\shellex\ContextMenuHandlers\Open With
{09799AFB-AD67-11d1-ABCD-00C04FC30936} = C:\WINDOWS\SYSTEM\SHELL32.DLL
HKEY_CLASSES_ROOT\*\shellex\ContextMenuHandlers\BriefcaseMenu
{85BBD920-42A0-1069-A2E4-08002B30309D} = syncui.dll
HKEY_CLASSES_ROOT\*\shellex\ContextMenuHandlers\AVG Shell Extension
{1E2CDF40-419B-11D2-A5A1-002018648BA7} =
HKEY_CLASSES_ROOT\*\shellex\ContextMenuHandlers\AVG7 Shell Extension
{9F97547E-4609-42C5-AE0C-81C61FFAEBC3} = C:\Program Files\Grisoft\AVG Free\avgse.dll
HKEY_CLASSES_ROOT\*\shellex\ContextMenuHandlers\ZipCentral
{40E85620-3DCB-11D3-8A0D-0060080C1EFA} = C:\Program Files\ZipCentral\zccm.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Folder\shellex\ContextMenuHandlers]
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Folder\shellex\ContextMenuHandlers\BriefcaseMenu
{85BBD920-42A0-1069-A2E4-08002B30309D} = syncui.dll
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Folder\shellex\ContextMenuHandlers\AVG Shell Extension
{1E2CDF40-419B-11D2-A5A1-002018648BA7} =
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Folder\shellex\ContextMenuHandlers\AVG7 Shell Extension
{9F97547E-4609-42C5-AE0C-81C61FFAEBC3} = C:\Program Files\Grisoft\AVG Free\avgse.dll
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Folder\shellex\ContextMenuHandlers\ZipCentral
{40E85620-3DCB-11D3-8A0D-0060080C1EFA} = C:\Program Files\ZipCentral\zccm.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Directory\shellex\ContextMenuHandlers]
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Directory\shellex\ContextMenuHandlers\ZipCentral
{40E85620-3DCB-11D3-8A0D-0060080C1EFA} = C:\Program Files\ZipCentral\zccm.dll

<<< WARNING! - NOT A VALID WIN98 KEY! (ME is Ok) >>>
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Folder\shellex\ColumnHandlers]
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Folder\shellex\ColumnHandlers\{24F14F01-7B1C-11d1-838f-0000F80461CF}
= C:\WINDOWS\SYSTEM\SHELL32.DLL
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Folder\shellex\ColumnHandlers\{24F14F02-7B1C-11d1-838f-0000F80461CF}
= C:\WINDOWS\SYSTEM\SHELL32.DLL
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Folder\shellex\ColumnHandlers\{0D2E74C4-3C34-11d2-A27E-00C04FC30871}
= C:\WINDOWS\SYSTEM\SHELL32.DLL
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Folder\shellex\ColumnHandlers\{7ab770c7-0e23-4d7a-8aa2-19bfad479829}
= C:\WINDOWS\SYSTEM\SHELL32.DLL
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Folder\shellex\ColumnHandlers\{884EA37B-37C0-11d2-BE3F-00A0C9A83DA1}
= C:\WINDOWS\SYSTEM\DOCPROP2.DLL

[HKLM\Software\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Explorer Bars]
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Explorer Bars\{4D5C8C25-D075-11d0-B416-00C04FB90376}
&Tip of the Day = C:\WINDOWS\SYSTEM\SHDOCVW.DLL

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\ToolBar]
{8E718888-423F-11D2-876E-00A0C9082467} = &Radio : C:\WINDOWS\SYSTEM\MSDXM.OCX

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Extensions]
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Extensions\{6224f700-cba3-4071-b251-47cb894244cd}
ButtonText = ICQ Pro : C:\PROGRA~1\ICQ\ICQ.exe
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Extensions\{c95fe080-8f5d-11d2-a20b-00aa003c157a}
ButtonText = @shdoclc.dll,-866 :

[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Explorer Bars]
HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Explorer Bars\{C4EE31F3-4768-11D2-BE5C-00A0C9A83DA1}
File and Folders Search ActiveX Control = C:\WINDOWS\SYSTEM\SHELL32.DLL
HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Explorer Bars\{EFA24E61-B078-11D0-89E4-00C04FC9E26E}
Favorites Band = C:\WINDOWS\SYSTEM\SHDOCVW.DLL
HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Explorer Bars\{EFA24E62-B078-11D0-89E4-00C04FC9E26E}
History Band = C:\WINDOWS\SYSTEM\SHDOCVW.DLL
HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Explorer Bars\{32683183-48a0-441b-a342-7c2a440a9478}
Media Band = C:\WINDOWS\SYSTEM\BROWSEUI.DLL
HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Explorer Bars\{EFA24E64-B078-11D0-89E4-00C04FC9E26E}
Explorer Band = C:\WINDOWS\SYSTEM\SHDOCVW.DLL

[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Toolbar]
HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Toolbar\WebBrowser
{01E04581-4EEE-11D0-BFE9-00AA005B4383} = &Address : C:\WINDOWS\SYSTEM\BROWSEUI.DLL
{EF99BD32-C1FB-11D2-892F-0090271D4F88} = :
{BDAD1DAD-C946-4A17-ADC1-64B5B4FF55D0} = :
{0E5CBF21-D15F-11D0-8301-00AA005B4383} = &Links : C:\WINDOWS\SYSTEM\BROWSEUI.DLL
{42CDD1BF-3FFB-4238-8AD1-7859DF00B1D6} = :
HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Toolbar\ShellBrowser
{01E04581-4EEE-11D0-BFE9-00AA005B4383} = &Address : C:\WINDOWS\SYSTEM\BROWSEUI.DLL
{0E5CBF21-D15F-11D0-8301-00AA005B4383} = &Links : C:\WINDOWS\SYSTEM\BROWSEUI.DLL
{42CDD1BF-3FFB-4238-8AD1-7859DF00B1D6} = :

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
ScanRegistry C:\WINDOWS\scanregw.exe /autorun
TaskMonitor C:\WINDOWS\taskmon.exe
SystemTray SysTray.Exe
LoadQM loadqm.exe
Camera Detector C:\PROGRA~1\ACDSYS~1\DEVDET~1\DEVDET~1.EXE -autorun
LoadPowerProfile Rundll32.exe powrprof.dll,LoadCurrentPwrScheme
AVG7_CC C:\PROGRA~1\GRISOFT\AVGFRE~1\AVGCC.EXE /STARTUP
AVG7_AMSVR C:\PROGRA~1\GRISOFT\AVGFRE~1\AVGAMSVR.EXE
Lexmark X74-X75 "C:\Program Files\Lexmark X74-X75\lxbbbmgr.exe"
LexStart lexstart.exe

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\OptionalComponents]
MSFS Installed = 1
MAPI Installed = 1
IMAIL Installed = 1

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\RunOnce]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\RunOnceEx]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\RunServices]
LoadPowerProfile Rundll32.exe powrprof.dll,LoadCurrentPwrScheme
SchedulingAgent mstask.exe
*StateMgr C:\WINDOWS\System\Restore\StateMgr.exe

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\RunServicesOnce]

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
PopUpStopperFreeEdition "C:\PROGRAM FILES\PANICWARE\POP-UP STOPPER FREE EDITION\PSFREE.EXE"

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\RunOnce]

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\RunServices]

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\RunServicesOnce]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\policies]

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\WinOldApp
NoRealMode 1


HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Network

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Ratings

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\NonEnum
{BDEADF00-C265-11D0-BCED-00A0C90AB50F} = C:\PROGRA~1\COMMON~1\MICROS~1\Web Folders\MSONSEXT.DLL
{6DFD7C5C-2451-11d3-A299-00C04F8EF6AF} =
{0DF44EAA-FF21-4412-828E-260A8728E7F1} =


[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\policies]

HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer
NoDriveTypeAutoRun •
CDRAutoRun
NoActiveDesktop 0
ClassicShell 0
ForceActiveDesktopOn 0
NoBandCustomize 0
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System
DisableRegistryTools 0
NoDispAppearancePage 0

HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\ActiveDesktop
NoChangingWallpaper 0
NoComponents 0
NoAddingComponents 0
NoDeletingComponents 0
NoEditingComponents 0
NoHTMLWallPaper 0


[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad]
WebCheck {E6FB5E20-DE35-11CF-9C87-00AA005127ED} = C:\WINDOWS\SYSTEM\WEBCHECK.DLL
UPnPMonitor {e57ce738-33e8-4c51-8354-bb4de9d215d1} = C:\WINDOWS\SYSTEM\UPNPUI.DLL
AUHook {BCBCD383-3E06-11D3-91A9-00C04F68105C} = C:\WINDOWS\SYSTEM\AUHOOK.DLL


»»»»»»»»»»»»»»»»»»»»»»»» Scan Complete »»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»
WinPFind v1.3.1 - Log file written to "WinPFind.Txt" in the WinPFind folder.
Scan completed on 30/08/2005 10:41:37 AM

#14 OldTimer

OldTimer

    Malware Expert


  • Members
  • 11,092 posts
  • OFFLINE
  •  
  • Gender:Male
  • Location:North Carolina
  • Local time:01:31 AM

Posted 29 August 2005 - 11:09 PM

Hi Marci4. Ok, let's see if we can't get this cleaned up. Please print these directions and ehn proceed with the following steps in order.

Download the Pocket Killbox and unzip the contents of KillBox.zip to your desktop.
  • Double-click on KillBox.exe to launch the program.
  • Highlight the files in bold below and press the Ctrl key and the C key at the same time to copy them to the clipboard
    • C:\WINDOWS\SYSTEM\ntfsnlpa.exe
      C:\WINDOWS\SYSTEM\msexnpfi.exe
  • In Killbox click on the File menu and then the Paste from Clipboard item
  • In the Full Path of File to Delete field drop down the arrow and make sure that all of the files are listed
  • Click the option to Delete on Reboot
  • Now click on the red button with a white 'X' in the middle to delete the files
  • Click Yes when it says all files will be deleted on the next reboot
  • Click Yes when it asks if you want to reboot now
  • If you get a "PendingFileRenameOperations Registry Data has been Removed by External Process!" message then just reboot manually
  • Reboot and post a new WinPFind log
I will review the new information when it comes in.

OT
I do not respond to PM's requesting help. That's what the forums are here for. Please use them so that others may benefit from your questions and the responses you receive.
OldTimer

Posted Image

#15 Marci4

Marci4
  • Topic Starter

  • Members
  • 18 posts
  • OFFLINE
  •  
  • Local time:12:31 AM

Posted 05 September 2005 - 06:44 PM

Ok here it is, had to do it in 2 parts again.
Part 1

WARNING: not all files found by this scanner are bad. Consult with a knowledgable person before proceeding.

If you see a message in the titlebar saying "Not responding..." you can ignore it. Windows somethimes displays this message due to the high volume of disk I/O. As long as the hard disk light is flashing, the program is still working properly.

»»»»»»»»»»»»»»»»» Windows OS and Versions »»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»
Product Name: Windows Millennium Edition Version: 4.90.3000
Internet Explorer Version: 6.0.2800.1106

»»»»»»»»»»»»»»»»» Checking Selected Standard Folders »»»»»»»»»»»»»»»»»»»»

Checking %SystemDrive% folder...

Checking %ProgramFilesDir% folder...
PEC2 16/12/2004 3:25:08 PM 12305800 C:\Program Files\e-Record_v401_Setup.EXE

Checking %WinDir% folder...

Items found in C:\WINDOWS\HOSTS

PECompact2 26/07/2005 11:25:08 AM 15442435 C:\WINDOWS\LPT$VPN.745
qoologic 26/07/2005 11:25:08 AM 15442435 C:\WINDOWS\LPT$VPN.745
SAHAgent 26/07/2005 11:25:08 AM 15442435 C:\WINDOWS\LPT$VPN.745
PECompact2 26/07/2005 11:25:08 AM 15442435 C:\WINDOWS\VPTNFILE.745
qoologic 26/07/2005 11:25:08 AM 15442435 C:\WINDOWS\VPTNFILE.745
SAHAgent 26/07/2005 11:25:08 AM 15442435 C:\WINDOWS\VPTNFILE.745
UPX! 27/07/2005 12:53:28 AM 1044560 C:\WINDOWS\vsapi32.dll
aspack 27/07/2005 12:53:28 AM 1044560 C:\WINDOWS\vsapi32.dll

Checking %System% folder...
PTech 14/10/2002 4:31:52 PM 7832 C:\WINDOWS\SYSTEM\lxbbinst.drv

Checking %System%\Drivers folder and sub-folders...

Checking the Windows folder and sub-folders for system and hidden files within the last 60 days...
6/09/2005 12:19:26 AM RH 4694048 C:\WINDOWS\CLASSES.DAT
6/09/2005 9:11:14 AM RH 1040416 C:\WINDOWS\USER.DAT
6/09/2005 9:15:08 AM RH 2392096 C:\WINDOWS\SYSTEM.DAT
6/09/2005 9:07:50 AM H 25866 C:\WINDOWS\ttfCache
6/09/2005 9:07:36 AM H 1196140 C:\WINDOWS\ShellIconCache
15/07/2005 9:50:00 AM H 10820 C:\WINDOWS\HELP\nocontnt.GID
6/09/2005 9:09:26 AM H 13026 C:\WINDOWS\PCHEALTH\HELPCTR\Database\HelpSessionHistory.stream
6/09/2005 12:33:44 AM H 6 C:\WINDOWS\TASKS\SA.DAT
9/08/2005 7:01:10 PM H 0 C:\WINDOWS\TEMP\CS67A179AE-3C93-43F7-A869-6111DF507C7C.tmp
9/08/2005 7:01:10 PM H 0 C:\WINDOWS\TEMP\CS86C6CBB6-78D1-48BD-8619-AE1A11E6D7DE.tmp
9/08/2005 7:01:10 PM H 0 C:\WINDOWS\TEMP\CSDA3FEA02-597E-46BD-894D-D192F71F6E93.tmp
9/08/2005 7:01:10 PM H 0 C:\WINDOWS\TEMP\CS35350476-0456-4F98-BECA-68904694C1B2.tmp
9/08/2005 7:01:10 PM H 0 C:\WINDOWS\TEMP\CS08A91EF9-94B1-447B-B743-78A74229A59F.tmp
9/08/2005 7:01:10 PM H 0 C:\WINDOWS\TEMP\CSBAF07993-8A29-487C-B8BD-BF32333453B7.tmp
9/08/2005 7:01:10 PM H 0 C:\WINDOWS\TEMP\CS5191FCFE-9A89-4A80-9A7E-0C7E2D8A9FA0.tmp
9/08/2005 7:01:10 PM H 0 C:\WINDOWS\TEMP\CS1D1BD214-2CF6-4287-9E00-8A080D568F36.tmp
9/08/2005 7:01:10 PM H 0 C:\WINDOWS\TEMP\CS5ECE9A8B-D504-4A62-B950-424886CC325C.tmp
9/08/2005 7:01:10 PM H 0 C:\WINDOWS\TEMP\CS03B2B7B5-B59B-4C89-9405-E3B3A9F25522.tmp
9/08/2005 7:01:10 PM H 0 C:\WINDOWS\TEMP\CSABC22FA9-9C23-4B7C-BBA5-45BD07AD3581.tmp
9/08/2005 7:01:10 PM H 0 C:\WINDOWS\TEMP\CS57C8D31E-D61C-4E44-8439-90C33A994E81.tmp
9/08/2005 7:01:10 PM H 0 C:\WINDOWS\TEMP\CSFDD76388-2058-4696-B3CE-68A2ECAB3EB4.tmp
9/08/2005 7:01:10 PM H 0 C:\WINDOWS\TEMP\CSC1A4761E-8276-483D-9D85-C862AECB33B1.tmp
9/08/2005 7:01:10 PM H 0 C:\WINDOWS\TEMP\CS0F22332A-BFA1-4E8A-9F11-2E2CB70543CD.tmp
9/08/2005 7:01:10 PM H 0 C:\WINDOWS\TEMP\CS97D1DE27-E53A-479C-950D-ED3FE6A7CA20.tmp
9/08/2005 7:01:10 PM H 0 C:\WINDOWS\TEMP\CSC26212F0-8BB2-4BF6-B6CA-0A872F55ACFE.tmp
9/08/2005 7:01:10 PM H 0 C:\WINDOWS\TEMP\CSFF505C0E-477D-4F83-AF3A-8A02AF5C2F54.tmp
9/08/2005 7:01:10 PM H 0 C:\WINDOWS\TEMP\CS8D1CE539-31F7-4B36-9C36-CDC4EB97E108.tmp
9/08/2005 7:01:10 PM H 0 C:\WINDOWS\TEMP\CSCD529814-DE78-4951-BD44-BB90E09A7F69.tmp
9/08/2005 7:01:10 PM H 0 C:\WINDOWS\TEMP\CS98D1F09F-0A8B-4D75-9551-9193DC5FDDE9.tmp
9/08/2005 7:01:10 PM H 0 C:\WINDOWS\TEMP\CS8B538AE7-C71A-40F6-9215-A394451D60DE.tmp
9/08/2005 7:01:10 PM H 0 C:\WINDOWS\TEMP\CSAF4AEC99-5F50-45E4-AA2D-BB5D7C777EC3.tmp
9/08/2005 7:01:10 PM H 0 C:\WINDOWS\TEMP\CS66AC6224-2A18-4E1F-A44F-5E57E7188A17.tmp
9/08/2005 7:01:10 PM H 0 C:\WINDOWS\TEMP\CS188D6373-F77A-4911-A76A-17C8D0C44ECA.tmp
9/08/2005 7:01:10 PM H 0 C:\WINDOWS\TEMP\CSDA355DD9-EEE1-4FBC-A02C-DB6C625FEB6E.tmp
9/08/2005 7:01:10 PM H 0 C:\WINDOWS\TEMP\CS553AB118-D0FF-472E-A845-473F2A251711.tmp
9/08/2005 7:01:10 PM H 0 C:\WINDOWS\TEMP\CS4156D7A3-68BF-413E-8DE4-53D6C070F567.tmp
9/08/2005 7:01:10 PM H 0 C:\WINDOWS\TEMP\CS881274C5-957D-4C6C-AD31-59E87649F3E1.tmp
9/08/2005 7:01:10 PM H 0 C:\WINDOWS\TEMP\CS9AD52901-F212-424B-AA8F-CC1C30250234.tmp
9/08/2005 7:01:10 PM H 0 C:\WINDOWS\TEMP\CS9603BE5A-7590-4713-A596-852039C1BC32.tmp
9/08/2005 7:01:10 PM H 0 C:\WINDOWS\TEMP\CSC5BFB764-0660-4CB6-819E-8EFEDCFAF925.tmp
9/08/2005 7:01:32 PM H 0 C:\WINDOWS\TEMP\CS2D12D590-BD45-4EF5-A118-A0E90411E3A6.tmp
9/08/2005 7:01:32 PM H 0 C:\WINDOWS\TEMP\CS59381B47-063B-4523-8899-9F7C7A54B0B9.tmp
9/08/2005 7:01:32 PM H 0 C:\WINDOWS\TEMP\CS8E12C1D7-AA4E-41CE-A98B-C2DE17BE5F9E.tmp
9/08/2005 7:01:32 PM H 0 C:\WINDOWS\TEMP\CS0F040063-D1D1-44FD-B3EF-AB4B0371163D.tmp
9/08/2005 7:01:32 PM H 0 C:\WINDOWS\TEMP\CSCB97C28E-E588-490C-A802-C7D569782AE3.tmp
9/08/2005 7:01:32 PM H 0 C:\WINDOWS\TEMP\CS937491FE-50F9-4B60-A7FA-0D615EB05D3C.tmp
9/08/2005 7:01:32 PM H 0 C:\WINDOWS\TEMP\CS63B56189-1D6F-4DD0-AD29-1CB9CC01D384.tmp
9/08/2005 7:01:32 PM H 0 C:\WINDOWS\TEMP\CSE5D0992F-9CFA-4371-A2BA-E874BB6697B3.tmp
9/08/2005 7:01:32 PM H 0 C:\WINDOWS\TEMP\CS89693CD3-81D7-4D94-AB6F-8378DF57FAD9.tmp
9/08/2005 7:01:32 PM H 0 C:\WINDOWS\TEMP\CSDE6DEB4C-566E-4D0A-B7F3-32037EF25A2B.tmp
9/08/2005 7:01:32 PM H 0 C:\WINDOWS\TEMP\CSCA19211C-4428-4ED0-AAE0-974EC602959F.tmp
9/08/2005 7:01:32 PM H 0 C:\WINDOWS\TEMP\CS1D1936BC-F787-4958-B982-4332CA054FBA.tmp
9/08/2005 7:01:32 PM H 0 C:\WINDOWS\TEMP\CS24F1F05F-1067-41C7-BEAC-45789738657E.tmp
9/08/2005 7:01:32 PM H 0 C:\WINDOWS\TEMP\CS26B58545-F4F4-49AB-859C-53BC152583C6.tmp
9/08/2005 7:01:32 PM H 0 C:\WINDOWS\TEMP\CSDF9D59CF-EC8E-40B0-A1D2-6C914E0A1951.tmp
9/08/2005 7:01:32 PM H 0 C:\WINDOWS\TEMP\CSA1E6B887-EC0C-446D-82B1-763FD03A82C2.tmp
9/08/2005 7:01:32 PM H 0 C:\WINDOWS\TEMP\CS6FD22086-BAEC-45F1-905F-FCDD67DA9F09.tmp
9/08/2005 7:01:32 PM H 0 C:\WINDOWS\TEMP\CS992AC8F3-FD45-4C6A-A15C-C0E83D04FB86.tmp
9/08/2005 7:01:32 PM H 0 C:\WINDOWS\TEMP\CS9F066697-D757-4FB0-847D-2341EA37CD7E.tmp
9/08/2005 7:01:32 PM H 0 C:\WINDOWS\TEMP\CSF26B6D95-1DBB-4DD9-915E-18B14FCB83B1.tmp
9/08/2005 7:01:32 PM H 0 C:\WINDOWS\TEMP\CSE4852E05-10F4-4E10-871C-084813A7385D.tmp
9/08/2005 7:01:32 PM H 0 C:\WINDOWS\TEMP\CSB5D72C5D-E990-4F47-9C17-7A71D4B28D3B.tmp
9/08/2005 7:01:32 PM H 0 C:\WINDOWS\TEMP\CSC8D82C27-BE98-401E-9C20-86F97411E43F.tmp
9/08/2005 7:01:32 PM H 0 C:\WINDOWS\TEMP\CSC30EE08F-AAA8-4CBF-BBC6-A2B01379AB49.tmp
9/08/2005 7:01:32 PM H 0 C:\WINDOWS\TEMP\CS2A3AD399-5CB1-465C-A8DA-CB603328B6BC.tmp
9/08/2005 7:01:32 PM H 0 C:\WINDOWS\TEMP\CSBEDA2F4E-1AF9-478A-8840-2301413A1F4D.tmp
9/08/2005 7:01:32 PM H 0 C:\WINDOWS\TEMP\CS02D55269-73B3-4801-80CA-451445A0CAE8.tmp
9/08/2005 7:01:32 PM H 0 C:\WINDOWS\TEMP\CS98E2F09F-5A75-418A-ACE6-F836623DDABB.tmp
9/08/2005 7:01:32 PM H 0 C:\WINDOWS\TEMP\CSAEFAC004-15CE-49AB-9C56-867B22FCDC5F.tmp
9/08/2005 7:01:32 PM H 0 C:\WINDOWS\TEMP\CSD69A6D5B-ED90-4224-8ADC-93FBD16C5C5F.tmp
9/08/2005 7:01:32 PM H 0 C:\WINDOWS\TEMP\CSD2D78E15-85DD-49A9-AA08-822A13F7F80B.tmp
9/08/2005 7:01:32 PM H 0 C:\WINDOWS\TEMP\CS8D1A0728-F9DA-4B22-A0D5-8B87B6E90D18.tmp
9/08/2005 7:01:32 PM H 0 C:\WINDOWS\TEMP\CSACE7F9D4-537D-4C51-AD04-B95314819CEF.tmp
9/08/2005 7:01:32 PM H 0 C:\WINDOWS\TEMP\CSC2FA7BE8-E08E-40A3-A249-79E85F14F825.tmp
9/08/2005 7:01:32 PM H 0 C:\WINDOWS\TEMP\CS0DB86E99-8D39-4018-885A-4DFCA2F0F9BA.tmp
9/08/2005 7:01:32 PM H 0 C:\WINDOWS\TEMP\CS29300C64-3217-47E0-99F7-DBEF172CE263.tmp
9/08/2005 7:01:32 PM H 0 C:\WINDOWS\TEMP\CSD7C46855-92A5-4AF3-B71E-D016DECC0442.tmp
9/08/2005 7:01:32 PM H 0 C:\WINDOWS\TEMP\CSD39D486D-30BF-4FC2-9FCD-5284805E4EB4.tmp
9/08/2005 7:01:32 PM H 0 C:\WINDOWS\TEMP\CSD9CF7568-C534-4941-8389-4EC9D556EA52.tmp
9/08/2005 7:01:32 PM H 0 C:\WINDOWS\TEMP\CS153E1B7C-16B3-4361-8D92-E793137D174F.tmp
9/08/2005 7:01:32 PM H 0 C:\WINDOWS\TEMP\CSF3A59CF7-C70D-49A0-8AFC-AB0FA9421263.tmp
9/08/2005 7:01:32 PM H 0 C:\WINDOWS\TEMP\CSA472FF9E-06BC-4456-845F-354D8B6E4B99.tmp
9/08/2005 7:01:32 PM H 0 C:\WINDOWS\TEMP\CS5D214571-047B-49A3-8306-3833DAEA99C1.tmp
9/08/2005 7:01:32 PM H 0 C:\WINDOWS\TEMP\CS5017A415-75B4-4CAE-AD58-61311916645E.tmp
9/08/2005 7:01:32 PM H 0 C:\WINDOWS\TEMP\CS5C23034E-A1A0-4D20-B602-A3F42FD6C6A2.tmp
9/08/2005 7:01:32 PM H 0 C:\WINDOWS\TEMP\CSCE1ACBF8-DA67-4FAE-83BF-00F7E276F1BE.tmp
9/08/2005 7:01:32 PM H 0 C:\WINDOWS\TEMP\CS433EADEA-9B70-427C-B64C-7ACFB8F00955.tmp
9/08/2005 7:01:32 PM H 0 C:\WINDOWS\TEMP\CS8258805B-C537-40FF-AAA7-64F415AF57A6.tmp
9/08/2005 7:01:32 PM H 0 C:\WINDOWS\TEMP\CS094CEA5F-564B-4CC8-B54D-6970092C0C7F.tmp
9/08/2005 7:01:32 PM H 0 C:\WINDOWS\TEMP\CS517E5078-7331-4297-8283-D77574A2EB24.tmp
9/08/2005 7:01:32 PM H 0 C:\WINDOWS\TEMP\CS41BC3D6D-4D99-4274-8664-D95DE493A05D.tmp
9/08/2005 7:01:32 PM H 0 C:\WINDOWS\TEMP\CS311CCC87-E77D-46B0-956E-529B2654FDF6.tmp
9/08/2005 7:01:32 PM H 0 C:\WINDOWS\TEMP\CSEC96A483-A780-4622-ACC0-82FC4D59D894.tmp
9/08/2005 7:01:32 PM H 0 C:\WINDOWS\TEMP\CS24BDEB0F-D209-4FE0-8EBD-81E94F98A911.tmp
9/08/2005 7:01:32 PM H 0 C:\WINDOWS\TEMP\CSB51CBB82-D936-4746-BECC-A3A7504E410F.tmp
9/08/2005 7:01:32 PM H 0 C:\WINDOWS\TEMP\CS214FC300-2BA0-4D3F-877B-609E5F3D210D.tmp
9/08/2005 7:01:32 PM H 0 C:\WINDOWS\TEMP\CSEF980BA7-DD67-40F9-B384-655570FB3356.tmp
9/08/2005 7:01:32 PM H 0 C:\WINDOWS\TEMP\CSEC8A0600-6014-4FFE-A658-E1BE2C96E41A.tmp
9/08/2005 7:01:32 PM H 0 C:\WINDOWS\TEMP\CS01D968EB-52EC-426F-BB48-BB792B2787C1.tmp
9/08/2005 7:01:32 PM H 0 C:\WINDOWS\TEMP\CS400A663A-CADE-4334-B9FC-D43B1EE51AF2.tmp
9/08/2005 7:01:32 PM H 0 C:\WINDOWS\TEMP\CS7399412A-E82F-40DB-84A5-307C76DCD35D.tmp
9/08/2005 7:01:32 PM H 0 C:\WINDOWS\TEMP\CSD60BB073-B694-4D16-8A4A-E4F8F6218E82.tmp
9/08/2005 7:01:32 PM H 0 C:\WINDOWS\TEMP\CSB7B2524D-D22D-4679-8EFF-A7EAA94F0927.tmp
9/08/2005 7:01:32 PM H 0 C:\WINDOWS\TEMP\CSA645536D-9C78-4341-8A2A-8276809F3604.tmp
9/08/2005 7:01:32 PM H 0 C:\WINDOWS\TEMP\CS866485BD-6147-4E16-805F-ABE6B1AF0216.tmp
9/08/2005 7:01:32 PM H 0 C:\WINDOWS\TEMP\CS47FFB66B-F3E0-4F81-A22E-46E415954458.tmp
9/08/2005 7:01:32 PM H 0 C:\WINDOWS\TEMP\CS20901B0A-9D4E-4129-8577-F71AC6F7EFE8.tmp
9/08/2005 7:01:32 PM H 0 C:\WINDOWS\TEMP\CS0C5ADF71-0865-4BAC-A803-886A16289B31.tmp
9/08/2005 7:01:32 PM H 0 C:\WINDOWS\TEMP\CS8D582573-8285-4C94-93A3-1E6316FF5ABC.tmp
9/08/2005 7:05:24 PM H 0 C:\WINDOWS\TEMP\CSCEB52DD0-AFC9-4A8C-8A6C-EFF1704E3E2C.tmp
9/08/2005 7:05:24 PM H 0 C:\WINDOWS\TEMP\CS8860546D-34DE-4726-9B2D-1571BBBA18A3.tmp
9/08/2005 7:05:24 PM H 0 C:\WINDOWS\TEMP\CSAE3B88DF-1DCA-4741-BA28-C4E63D38B80F.tmp
9/08/2005 7:05:24 PM H 0 C:\WINDOWS\TEMP\CSF5046B15-9941-4E7A-A456-C61597869004.tmp
9/08/2005 7:05:24 PM H 0 C:\WINDOWS\TEMP\CS105ABDA1-C720-42A3-A2D4-E7EAD5506F79.tmp
9/08/2005 7:05:24 PM H 0 C:\WINDOWS\TEMP\CS9E12D83A-3B6A-4279-A3B8-633C9E9F8E18.tmp
9/08/2005 7:05:24 PM H 0 C:\WINDOWS\TEMP\CS0F46096D-7073-4075-A1BD-7FAE680FB902.tmp
9/08/2005 7:05:24 PM H 0 C:\WINDOWS\TEMP\CS77BD85DB-35BF-49FE-B65A-22CDE43B23A8.tmp
9/08/2005 7:05:24 PM H 0 C:\WINDOWS\TEMP\CSD99E60F2-B4CD-48B4-97D3-334E82595AAF.tmp
9/08/2005 7:05:24 PM H 0 C:\WINDOWS\TEMP\CS1995425A-FE12-4060-A586-A8D252458646.tmp
9/08/2005 7:05:24 PM H 0 C:\WINDOWS\TEMP\CS2B448033-0B1F-4755-B0FB-6521991A11EA.tmp
9/08/2005 7:05:24 PM H 0 C:\WINDOWS\TEMP\CS49A4ADEA-B8E2-475F-95C0-511DC7B1F310.tmp
9/08/2005 7:05:24 PM H 0 C:\WINDOWS\TEMP\CSD9EA952D-D788-48FB-8293-B762AFBCCEB9.tmp
9/08/2005 7:05:24 PM H 0 C:\WINDOWS\TEMP\CSB41AA1D1-0069-4B75-AF7F-47E85B83B7E3.tmp
9/08/2005 7:05:24 PM H 0 C:\WINDOWS\TEMP\CSF3B258E2-9D3A-452D-9232-5C333425275F.tmp
9/08/2005 7:05:24 PM H 0 C:\WINDOWS\TEMP\CSF89CDF52-C434-4588-A4D2-0EB2143C3C41.tmp
9/08/2005 7:05:24 PM H 0 C:\WINDOWS\TEMP\CS91B4D950-8CA7-46D5-B144-940C23494C2F.tmp
9/08/2005 7:05:24 PM H 0 C:\WINDOWS\TEMP\CS68F244D4-D171-4766-84C5-F240B1DA24F2.tmp
9/08/2005 7:05:24 PM H 0 C:\WINDOWS\TEMP\CSA2786F60-6662-43F1-9BED-8BCD2F55D625.tmp
9/08/2005 7:05:24 PM H 0 C:\WINDOWS\TEMP\CS7D949131-A7E9-4B7B-B38F-F19CE609F193.tmp
9/08/2005 7:05:24 PM H 0 C:\WINDOWS\TEMP\CS171B596F-2733-48A0-903A-23E4F574DB18.tmp
9/08/2005 7:05:24 PM H 0 C:\WINDOWS\TEMP\CS49478F7B-DF8E-4F44-A6AA-73B543DFC2C9.tmp
9/08/2005 7:05:24 PM H 0 C:\WINDOWS\TEMP\CS4129EB5D-8AB2-4DDA-86C8-D4785B4A1C1A.tmp
9/08/2005 7:05:24 PM H 0 C:\WINDOWS\TEMP\CSC642CE8D-78E6-47DA-931B-95B266C33BE5.tmp
9/08/2005 7:05:24 PM H 0 C:\WINDOWS\TEMP\CSFCF89B45-8A1D-4469-81C1-1AC44E9498CA.tmp
9/08/2005 7:05:24 PM H 0 C:\WINDOWS\TEMP\CS127129CB-E8EA-4335-BEE5-51F86EDA855B.tmp
9/08/2005 7:05:24 PM H 0 C:\WINDOWS\TEMP\CSA5F8407D-406E-4926-8379-7039E91CA528.tmp
9/08/2005 7:05:24 PM H 0 C:\WINDOWS\TEMP\CS5FF7061E-9738-4E79-ACE1-460823C8152C.tmp
9/08/2005 7:05:24 PM H 0 C:\WINDOWS\TEMP\CS51BD6470-73CC-42CB-A13D-DEC024C70350.tmp
9/08/2005 7:05:24 PM H 0 C:\WINDOWS\TEMP\CSA3C8F846-87FB-4868-981C-09944FC6DFD0.tmp
9/08/2005 7:05:24 PM H 0 C:\WINDOWS\TEMP\CSDCD2CB01-314E-41E4-A5B9-379D3F0431B0.tmp
9/08/2005 7:05:24 PM H 0 C:\WINDOWS\TEMP\CSF5E1275B-537B-40ED-8E83-03AE1266B8B6.tmp
9/08/2005 7:10:38 PM H 0 C:\WINDOWS\TEMP\CSEC4788F8-6B9C-498D-9519-929C1FF29649.tmp
9/08/2005 7:10:38 PM H 0 C:\WINDOWS\TEMP\CS4AAD1C11-5761-4525-A041-181F14CCBB90.tmp
9/08/2005 7:10:38 PM H 0 C:\WINDOWS\TEMP\CSE3AD8867-1837-457B-ACD4-DF0E2BDCFC06.tmp
9/08/2005 7:10:38 PM H 0 C:\WINDOWS\TEMP\CSBAABE5AA-3965-4AA0-871E-F5202D1B462D.tmp
9/08/2005 7:10:38 PM H 0 C:\WINDOWS\TEMP\CSBF20D627-3260-41EE-B5F7-64DD4419CA73.tmp
9/08/2005 7:10:38 PM H 0 C:\WINDOWS\TEMP\CS56ACF3E9-F956-408F-ACFA-E1568D2E9C41.tmp
9/08/2005 7:10:38 PM H 0 C:\WINDOWS\TEMP\CS0CA69294-9FB0-4B73-99C6-AFA1F06C24D6.tmp
9/08/2005 7:10:38 PM H 0 C:\WINDOWS\TEMP\CS100EFBE1-2FB3-42D0-B315-818D54CA7A11.tmp
9/08/2005 7:10:38 PM H 0 C:\WINDOWS\TEMP\CSBC57D636-7E33-43F4-8EF0-4129E6B2C56E.tmp
9/08/2005 7:10:38 PM H 0 C:\WINDOWS\TEMP\CS5061D2AC-738A-429C-8AF1-3C0F139A7A3F.tmp
9/08/2005 7:10:38 PM H 0 C:\WINDOWS\TEMP\CS1BE66A5E-6D38-4BE0-951D-298141BFA6AD.tmp
9/08/2005 7:10:38 PM H 0 C:\WINDOWS\TEMP\CSAD00973D-1698-4354-9492-90B1D6CB32AB.tmp
9/08/2005 7:10:38 PM H 0 C:\WINDOWS\TEMP\CSECB66C46-8C6F-4212-B2E2-2416F38BA939.tmp
9/08/2005 7:10:38 PM H 0 C:\WINDOWS\TEMP\CSD8FD5916-405F-4C18-A821-9CA0195C9E11.tmp
9/08/2005 7:10:38 PM H 0 C:\WINDOWS\TEMP\CSB8695BFD-8A0D-4A74-8D7B-A4C579716794.tmp
9/08/2005 7:10:38 PM H 0 C:\WINDOWS\TEMP\CSC66C7CB4-6F3D-4D8F-824E-40C46D05DEB3.tmp
9/08/2005 7:10:38 PM H 0 C:\WINDOWS\TEMP\CSEF980911-9F0E-4F81-B9D5-6B78E9544823.tmp
9/08/2005 7:10:38 PM H 0 C:\WINDOWS\TEMP\CS1AA9747F-92A9-4274-9670-965299DE9922.tmp
9/08/2005 7:10:38 PM H 0 C:\WINDOWS\TEMP\CS0CAAB94E-B6E9-45E8-B5FF-E4A8C1F03B87.tmp
9/08/2005 7:10:38 PM H 0 C:\WINDOWS\TEMP\CS5447E7F9-8CDE-475A-95A2-314ADD9F715E.tmp
9/08/2005 7:10:38 PM H 0 C:\WINDOWS\TEMP\CS831FC599-F7D4-413A-91E5-4C64A4B69B2B.tmp
9/08/2005 7:10:38 PM H 0 C:\WINDOWS\TEMP\CSF7493D3F-1A17-4823-A0B0-1491BF0FF83B.tmp
9/08/2005 7:10:38 PM H 0 C:\WINDOWS\TEMP\CS322FC73E-953B-4744-90EA-9EB1F4FDCCC4.tmp
9/08/2005 7:10:38 PM H 0 C:\WINDOWS\TEMP\CS90C5DC70-D454-436B-AA77-B43331F7CE05.tmp
9/08/2005 7:10:38 PM H 0 C:\WINDOWS\TEMP\CS7E6C7B23-B554-45C9-960B-1DFD8E8F06FE.tmp
9/08/2005 7:10:38 PM H 0 C:\WINDOWS\TEMP\CS1E918857-34F1-44D1-A0F0-65BC8B74E46A.tmp
9/08/2005 7:10:38 PM H 0 C:\WINDOWS\TEMP\CS7E0A57ED-6CB9-4A94-BEE9-B623A2B64D47.tmp
9/08/2005 7:10:38 PM H 0 C:\WINDOWS\TEMP\CS7BF22C2D-38C3-46EB-8772-EF848D83CFE7.tmp
9/08/2005 7:10:38 PM H 0 C:\WINDOWS\TEMP\CSA3E445CC-C01D-4ABB-9E22-3AF265B89C71.tmp
9/08/2005 7:10:38 PM H 0 C:\WINDOWS\TEMP\CSA992EAC5-10E4-41BF-8537-9A24784924CC.tmp
9/08/2005 7:10:38 PM H 0 C:\WINDOWS\TEMP\CS96D787FD-720D-493A-BAF9-59A577102F95.tmp
9/08/2005 7:10:38 PM H 0 C:\WINDOWS\TEMP\CS8C3FFE30-655E-4A3F-B5D8-C01AE0D07B48.tmp
9/08/2005 7:10:38 PM H 0 C:\WINDOWS\TEMP\CS169A0E3C-B440-4F23-9DF5-C8DF35FC734A.tmp
9/08/2005 7:10:38 PM H 0 C:\WINDOWS\TEMP\CSA244666B-F2C2-4A50-9607-C9E28E682350.tmp
9/08/2005 7:10:38 PM H 0 C:\WINDOWS\TEMP\CS13B1E42D-A8F9-42BF-829B-8744CE91BBF2.tmp
9/08/2005 7:10:38 PM H 0 C:\WINDOWS\TEMP\CS979DF069-1955-4985-A3F1-E2D236C12E5B.tmp
9/08/2005 7:10:38 PM H 0 C:\WINDOWS\TEMP\CS8A77A7A1-4422-43E2-8211-6695CB6DE485.tmp
9/08/2005 7:10:38 PM H 0 C:\WINDOWS\TEMP\CS3BCF066E-F1D6-4D76-B9AE-0C91E745BC9E.tmp
9/08/2005 7:10:38 PM H 0 C:\WINDOWS\TEMP\CS1647C30D-FB23-4D55-9BA5-11C81B4710FD.tmp
9/08/2005 7:10:38 PM H 0 C:\WINDOWS\TEMP\CS08ADAB14-3C75-4227-9878-E6C068EA5338.tmp
9/08/2005 7:10:38 PM H 0 C:\WINDOWS\TEMP\CSD50872CF-6B03-4360-95DB-57B16DFB7CC9.tmp
9/08/2005 7:10:38 PM H 0 C:\WINDOWS\TEMP\CSA294ACDD-53B9-4E79-BBD9-2014E81A2135.tmp
9/08/2005 7:10:38 PM H 0 C:\WINDOWS\TEMP\CSAD811DCC-A633-4686-B042-37DE6D36E20C.tmp
9/08/2005 7:10:38 PM H 0 C:\WINDOWS\TEMP\CSFA5D2D54-9589-4492-B0D3-920CF7FA9E72.tmp
9/08/2005 7:10:38 PM H 0 C:\WINDOWS\TEMP\CSCB8B7779-5B75-474A-82B4-D3D80A1BC9E2.tmp
9/08/2005 7:10:38 PM H 0 C:\WINDOWS\TEMP\CS93453C38-6190-484C-BBDB-24E88A568F9F.tmp
9/08/2005 7:10:38 PM H 0 C:\WINDOWS\TEMP\CS328F1E98-F4E1-477D-8710-801A1B9B8FF3.tmp
9/08/2005 7:10:38 PM H 0 C:\WINDOWS\TEMP\CS53982BAE-2FBA-4A5E-8F76-A63BB65FF74B.tmp
9/08/2005 7:10:38 PM H 0 C:\WINDOWS\TEMP\CSBEBDDCE2-DD0F-4BCB-B7B8-4ECD108E46A5.tmp
9/08/2005 7:10:38 PM H 0 C:\WINDOWS\TEMP\CSA9667BAC-A2CF-4EF7-8EA8-544EC4C2D020.tmp
9/08/2005 7:10:38 PM H 0 C:\WINDOWS\TEMP\CS9CF10B10-8F39-428A-91A4-A96F01D7C227.tmp
9/08/2005 7:10:38 PM H 0 C:\WINDOWS\TEMP\CS0AA0159F-D5FC-4533-9854-2A96143FD758.tmp
9/08/2005 7:10:38 PM H 0 C:\WINDOWS\TEMP\CS9AE35BEA-3B39-4DB3-A356-D73B3B62DCC7.tmp
9/08/2005 7:10:38 PM H 0 C:\WINDOWS\TEMP\CS8DCD6F27-2D95-48FE-9E6F-35D2E620400A.tmp
9/08/2005 7:10:38 PM H 0 C:\WINDOWS\TEMP\CSCAFC36F8-2452-4976-807B-C6633DAC920F.tmp
9/08/2005 7:10:38 PM H 0 C:\WINDOWS\TEMP\CSF8F70A71-B7DC-40F2-B001-1A845F720772.tmp
9/08/2005 7:10:38 PM H 0 C:\WINDOWS\TEMP\CS6B56EC81-4D30-44D9-8E1C-8CFC8322F729.tmp
9/08/2005 7:10:38 PM H 0 C:\WINDOWS\TEMP\CS5150B1A4-29C6-43F3-8BD8-EC828DE4A86B.tmp
9/08/2005 7:10:38 PM H 0 C:\WINDOWS\TEMP\CS0FA589B1-FF28-424F-803A-4B7FFDBE9697.tmp
9/08/2005 7:10:38 PM H 0 C:\WINDOWS\TEMP\CSA6B95849-4F26-472F-8CB6-400D2EE0056E.tmp
9/08/2005 7:10:38 PM H 0 C:\WINDOWS\TEMP\CSA12B07FE-2A25-4775-9A45-1F17AC36B980.tmp
9/08/2005 7:10:38 PM H 0 C:\WINDOWS\TEMP\CSB56A84CB-00D1-4429-9DCF-D57D3CFAE95E.tmp
9/08/2005 7:10:38 PM H 0 C:\WINDOWS\TEMP\CSCEE13AE3-E307-43FA-98EC-B14277428CE8.tmp
9/08/2005 7:10:38 PM H 0 C:\WINDOWS\TEMP\CS2489996A-57DA-4919-B28D-A663FF1B4542.tmp
9/08/2005 7:10:38 PM H 0 C:\WINDOWS\TEMP\CS431D03BC-14C1-439B-927F-CFDD54DD58C9.tmp
9/08/2005 7:10:38 PM H 0 C:\WINDOWS\TEMP\CSB8CE1E31-5736-46D0-95E3-5FEA508C3F3D.tmp
9/08/2005 7:10:38 PM H 0 C:\WINDOWS\TEMP\CSBD7E076E-F67B-48EF-B31A-D290AC5C21B6.tmp
9/08/2005 7:10:38 PM H 0 C:\WINDOWS\TEMP\CS6DC80571-CBA6-4F57-B8F7-EB10A3B5AAA5.tmp
9/08/2005 7:10:38 PM H 0 C:\WINDOWS\TEMP\CS25774F5C-9D40-4A48-99A3-EFC547F44AAB.tmp
10/08/2005 5:27:36 PM H 0 C:\WINDOWS\TEMP\CS08B1317E-EED3-4230-8A9A-B3A5B9E4305A.tmp
10/08/2005 5:27:36 PM H 0 C:\WINDOWS\TEMP\CSC4D1A53D-A6A6-439B-A893-425EF1C9629A.tmp
10/08/2005 5:27:36 PM H 0 C:\WINDOWS\TEMP\CS896A3B14-0011-4999-97F6-39B967A01580.tmp
10/08/2005 5:27:36 PM H 0 C:\WINDOWS\TEMP\CSCB598D73-08B8-4182-95FD-F709017BBFAA.tmp
10/08/2005 5:27:36 PM H 0 C:\WINDOWS\TEMP\CS3965D14B-3DC9-465A-99A6-EA48D7D97AAF.tmp
10/08/2005 5:27:36 PM H 0 C:\WINDOWS\TEMP\CS1FED6C49-8783-4107-ACBD-50D3F820DEE0.tmp
10/08/2005 5:27:36 PM H 0 C:\WINDOWS\TEMP\CS68114261-E622-4F97-B67C-591A085C45AD.tmp
10/08/2005 5:27:36 PM H 0 C:\WINDOWS\TEMP\CSBB72C5B2-A63F-4DF9-987A-8A76757447E6.tmp
10/08/2005 5:27:36 PM H 0 C:\WINDOWS\TEMP\CSE7F86FEF-6DCD-47B0-9F88-7721B6F6D158.tmp
10/08/2005 5:27:36 PM H 0 C:\WINDOWS\TEMP\CS8A395779-646B-4809-9571-92B1EB60A6E7.tmp
10/08/2005 5:27:36 PM H 0 C:\WINDOWS\TEMP\CS7CF92419-FD08-4F41-8F2E-1525C20B5698.tmp
10/08/2005 5:27:36 PM H 0 C:\WINDOWS\TEMP\CS4732EFEA-CB1B-4A6B-B1E3-5DE1BEC87223.tmp
10/08/2005 5:27:36 PM H 0 C:\WINDOWS\TEMP\CS3D72336C-922F-46F1-9C9E-64F89DEA8A13.tmp
10/08/2005 5:27:36 PM H 0 C:\WINDOWS\TEMP\CSFAC12731-2950-4FD1-9617-079CC70E2AC3.tmp
10/08/2005 5:27:36 PM H 0 C:\WINDOWS\TEMP\CS887BC30A-CB7D-4EEF-9510-109120B349A9.tmp
10/08/2005 5:27:36 PM H 0 C:\WINDOWS\TEMP\CS18B08087-281F-4DA7-BE43-7D815779239A.tmp
10/08/2005 5:27:36 PM H 0 C:\WINDOWS\TEMP\CSD3F3B5C5-8D2E-4EF9-A16B-7294F8AD6161.tmp
10/08/2005 5:27:36 PM H 0 C:\WINDOWS\TEMP\CS92045B2A-CCCB-4E31-8D77-540E37571EA7.tmp
10/08/2005 5:27:36 PM H 0 C:\WINDOWS\TEMP\CS92F6267A-4EF8-4796-8C15-3C52679ECDB3.tmp
10/08/2005 5:27:36 PM H 0 C:\WINDOWS\TEMP\CSEF1C0411-BFDA-4F8C-BD3B-DE1D10B01269.tmp
10/08/2005 5:27:36 PM H 0 C:\WINDOWS\TEMP\CS4F3BEC6E-053E-4838-9271-E52491696E79.tmp
10/08/2005 5:27:36 PM H 0 C:\WINDOWS\TEMP\CS25A144C6-B81B-483F-88CB-652FADEF97F3.tmp
10/08/2005 5:27:36 PM H 0 C:\WINDOWS\TEMP\CSD41A8C6A-DDFF-4420-87EE-2C31D4A547FF.tmp
10/08/2005 5:27:36 PM H 0 C:\WINDOWS\TEMP\CS42B9F3CD-FFBC-47C3-A873-D875C7471D7C.tmp
10/08/2005 5:27:36 PM H 0 C:\WINDOWS\TEMP\CSA92072AE-1BA7-42B2-80BB-DA94694BF60C.tmp
10/08/2005 5:27:36 PM H 0 C:\WINDOWS\TEMP\CS46EAF570-6390-43DA-B2CA-3023FF71AD9B.tmp
10/08/2005 5:27:36 PM H 0 C:\WINDOWS\TEMP\CS2E8C8924-5949-4D4E-BD99-E994971E9243.tmp
10/08/2005 5:27:36 PM H 0 C:\WINDOWS\TEMP\CSB768BD67-3019-4346-AF1D-BFA3BD64D40F.tmp
10/08/2005 5:27:36 PM H 0 C:\WINDOWS\TEMP\CSC940B43F-84AB-4DAF-ABD4-C3FB3077DE77.tmp
10/08/2005 5:27:36 PM H 0 C:\WINDOWS\TEMP\CS61628CCC-925F-452C-B18A-56BC89C28806.tmp
10/08/2005 5:27:36 PM H 0 C:\WINDOWS\TEMP\CS0238E1ED-8B92-4722-86C6-C4E6EA2C0F99.tmp
10/08/2005 5:27:36 PM H 0 C:\WINDOWS\TEMP\CS763FE3F0-B26E-480D-A917-4E633FC765E8.tmp
10/08/2005 5:28:14 PM H 0 C:\WINDOWS\TEMP\CS988487CF-8493-440F-BD4B-0332E5A1F8A7.tmp
10/08/2005 5:28:14 PM H 0 C:\WINDOWS\TEMP\CS9DE5DF5B-788B-424C-81F2-CC0161F89B44.tmp
10/08/2005 5:28:14 PM H 0 C:\WINDOWS\TEMP\CS81F26EC7-3FD3-4CF7-9E66-5CA3D02B0C30.tmp
10/08/2005 5:28:14 PM H 0 C:\WINDOWS\TEMP\CSFFD795B5-CE9F-460D-803D-33BD8E5323E1.tmp
10/08/2005 5:28:14 PM H 0 C:\WINDOWS\TEMP\CSC90A322B-32B0-4C32-86E4-6CEC116683D3.tmp
10/08/2005 5:28:14 PM H 0 C:\WINDOWS\TEMP\CS9B855FC4-1270-4BC7-88A2-634932792500.tmp
10/08/2005 5:28:14 PM H 0 C:\WINDOWS\TEMP\CS7C6E48FC-4DDF-45B2-8508-CF921FBD0A51.tmp
10/08/2005 5:28:14 PM H 0 C:\WINDOWS\TEMP\CSC44CD1AE-7358-4486-9127-0041C2BBC8AB.tmp
10/08/2005 5:28:14 PM H 0 C:\WINDOWS\TEMP\CS2C87C7CC-D3AD-4171-93AA-8907EA7AAC7B.tmp
10/08/2005 5:28:14 PM H 0 C:\WINDOWS\TEMP\CS653F8D2E-A84A-4CE1-9CE9-9FB79C37D9FE.tmp
10/08/2005 5:28:14 PM H 0 C:\WINDOWS\TEMP\CS1229603A-A932-4B63-A939-9564115F0576.tmp
10/08/2005 5:28:16 PM H 0 C:\WINDOWS\TEMP\CSF95B9439-EF57-4B42-ACD7-59B311C6BE8B.tmp
10/08/2005 5:28:16 PM H 0 C:\WINDOWS\TEMP\CS1546BADD-5ED1-4521-B319-20FE58FD3B6D.tmp
10/08/2005 5:28:16 PM H 0 C:\WINDOWS\TEMP\CSAFB5A7CE-18FA-4DBF-939B-B49486264944.tmp
10/08/2005 5:28:16 PM H 0 C:\WINDOWS\TEMP\CSBE3D2630-EB8C-4864-B963-1D7210374979.tmp
10/08/2005 5:28:16 PM H 0 C:\WINDOWS\TEMP\CSED7A2285-E348-4A3C-BFC3-E457E8781D1A.tmp
10/08/2005 5:28:16 PM H 0 C:\WINDOWS\TEMP\CSDCE90FD4-38FB-431F-A570-7D29FA7733DA.tmp
10/08/2005 5:28:16 PM H 0 C:\WINDOWS\TEMP\CS2464E384-4291-411E-8D98-B8E0059D3CBF.tmp
10/08/2005 5:28:16 PM H 0 C:\WINDOWS\TEMP\CS97F8C803-C26E-4070-BC2D-7E0BEA43F48A.tmp
10/08/2005 5:28:16 PM H 0 C:\WINDOWS\TEMP\CS3730C597-83C5-4497-9B39-775BC169357F.tmp
10/08/2005 5:28:16 PM H 0 C:\WINDOWS\TEMP\CSECB84147-240A-463C-B6DE-E84844CA74F4.tmp
10/08/2005 5:28:16 PM H 0 C:\WINDOWS\TEMP\CSE0844C5F-E785-405C-AFAF-C8EE4351E14E.tmp
10/08/2005 5:28:16 PM H 0 C:\WINDOWS\TEMP\CSF3FCFD9B-44DD-4AA9-8E23-7E6B7CC88941.tmp
10/08/2005 5:28:16 PM H 0 C:\WINDOWS\TEMP\CS5243CCFE-86E2-4D3F-882E-E805E2478EE4.tmp
10/08/2005 5:28:16 PM H 0 C:\WINDOWS\TEMP\CSD7508AFC-CDE8-493A-985E-69B784EFB638.tmp
10/08/2005 5:28:16 PM H 0 C:\WINDOWS\TEMP\CSA9445D61-2FEB-410A-AF5D-BE4D4B127607.tmp
10/08/2005 5:28:16 PM H 0 C:\WINDOWS\TEMP\CS1E5A6F5F-66AC-49EE-A707-F1F5AB5F9BFF.tmp
10/08/2005 5:28:16 PM H 0 C:\WINDOWS\TEMP\CS3C70303B-7392-46AA-9616-2A105E3E4166.tmp
10/08/2005 5:28:16 PM H 0 C:\WINDOWS\TEMP\CS417266C0-30CF-4397-9B44-D17E4EE62EC6.tmp
10/08/2005 5:28:16 PM H 0 C:\WINDOWS\TEMP\CS220CA920-EB69-4D39-B2B5-84DC2264F683.tmp
10/08/2005 5:28:16 PM H 0 C:\WINDOWS\TEMP\CS211851FF-212F-4D7B-9F2A-FCBEB494F0A7.tmp
10/08/2005 5:28:16 PM H 0 C:\WINDOWS\TEMP\CSAED296A0-1DD5-4A51-BCA9-7E63DDCCB4C3.tmp
10/08/2005 5:28:16 PM H 0 C:\WINDOWS\TEMP\CS105E3E3E-15C8-4CAA-B1D4-D8A027C679AC.tmp
10/08/2005 5:28:16 PM H 0 C:\WINDOWS\TEMP\CSD5783E65-D8E8-4496-865E-E3F685080CFF.tmp
10/08/2005 5:28:16 PM H 0 C:\WINDOWS\TEMP\CS9FED2540-5AB6-4623-8F29-DD9383952E17.tmp
10/08/2005 5:28:16 PM H 0 C:\WINDOWS\TEMP\CS24F690D5-6025-456E-979B-0F4A560B864A.tmp
10/08/2005 5:28:16 PM H 0 C:\WINDOWS\TEMP\CSDA7E8951-1FD1-4745-B767-95224884B33F.tmp
10/08/2005 5:28:16 PM H 0 C:\WINDOWS\TEMP\CS1E79887D-FD31-484D-AEA7-66238B888CDD.tmp
10/08/2005 5:28:16 PM H 0 C:\WINDOWS\TEMP\CSA127C603-CD4A-4AEC-BB39-8CEFE58994B3.tmp
10/08/2005 5:28:16 PM H 0 C:\WINDOWS\TEMP\CS844FE498-DB2B-4476-86DA-DD4BBCFB7ED9.tmp
10/08/2005 5:28:16 PM H 0 C:\WINDOWS\TEMP\CS9BEE2A4E-6AFA-4B50-9F28-E3F093941F9F.tmp
10/08/2005 5:28:16 PM H 0 C:\WINDOWS\TEMP\CSBF55579E-58A4-4D0C-8BCD-3739869B77BA.tmp
10/08/2005 5:28:16 PM H 0 C:\WINDOWS\TEMP\CS0DAB603D-5343-43FC-ABC1-E05998C7D86A.tmp
10/08/2005 5:28:16 PM H 0 C:\WINDOWS\TEMP\CSA3533A86-26EC-458D-ADDB-B18A0DB524F8.tmp
10/08/2005 5:28:16 PM H 0 C:\WINDOWS\TEMP\CSC2D5DBAB-C038-42CA-B61E-419A5A0A765C.tmp
10/08/2005 5:28:16 PM H 0 C:\WINDOWS\TEMP\CS9CD82AC3-BC97-4FBF-A1ED-04DC62F42545.tmp
10/08/2005 5:28:16 PM H 0 C:\WINDOWS\TEMP\CS0285988F-B1F4-42CD-B2DB-5CE289819A07.tmp
10/08/2005 5:28:16 PM H 0 C:\WINDOWS\TEMP\CS2E45FA51-3139-4486-AD1D-5CC88663E9EE.tmp
10/08/2005 5:28:16 PM H 0 C:\WINDOWS\TEMP\CS3EFA4DB8-632C-4F8F-8F3C-84DB44CA116A.tmp
10/08/2005 5:28:16 PM H 0 C:\WINDOWS\TEMP\CSC300C26B-1360-49BA-838C-3FA734C52BEB.tmp
10/08/2005 5:28:16 PM H 0 C:\WINDOWS\TEMP\CS87758B86-BF68-4A6F-8AD2-0CC612D12B66.tmp
10/08/2005 5:28:16 PM H 0 C:\WINDOWS\TEMP\CS556432A4-CEA5-4D3E-B361-7221345ED88D.tmp
10/08/2005 5:28:16 PM H 0 C:\WINDOWS\TEMP\CS4547F690-CE9A-4A2B-BCA0-9E4F06163E24.tmp
10/08/2005 5:28:16 PM H 0 C:\WINDOWS\TEMP\CS9E5BD038-C2A4-49AF-86B4-73220CA03F91.tmp
10/08/2005 5:28:16 PM H 0 C:\WINDOWS\TEMP\CS4D40BE82-1230-4B0E-B2C9-EEDADD57CBDA.tmp
10/08/2005 5:28:16 PM H 0 C:\WINDOWS\TEMP\CSF5FF0F1C-CD18-4F69-BB76-AB0DCFB7B99B.tmp
10/08/2005 5:28:16 PM H 0 C:\WINDOWS\TEMP\CSEF2ED2A7-82FE-4ECE-8F69-DDEE8388D1DC.tmp
10/08/2005 5:28:16 PM H 0 C:\WINDOWS\TEMP\CSADF151EE-F3DC-43D7-B9C3-7D288DC73B44.tmp
10/08/2005 5:28:16 PM H 0 C:\WINDOWS\TEMP\CS022CB1E0-8353-453D-A26A-69689F967E71.tmp
10/08/2005 5:28:16 PM H 0 C:\WINDOWS\TEMP\CS470F3CBD-244D-454C-A802-98C95F0AACEC.tmp
10/08/2005 5:28:16 PM H 0 C:\WINDOWS\TEMP\CS01FBEC12-31CD-4FB8-8FC5-A38EBEB28FFB.tmp
10/08/2005 5:28:16 PM H 0 C:\WINDOWS\TEMP\CS0F3C3B5A-5624-4C50-899C-352205D541C0.tmp
10/08/2005 5:28:16 PM H 0 C:\WINDOWS\TEMP\CS6FE6188E-B06A-4460-927B-2B00144E631D.tmp
10/08/2005 5:28:16 PM H 0 C:\WINDOWS\TEMP\CS83013C85-1A89-41D1-BA55-12FC15B0D141.tmp
10/08/2005 5:28:16 PM H 0 C:\WINDOWS\TEMP\CSA1D22AC4-1566-4E62-8500-09C673E2B3DF.tmp
10/08/2005 5:28:16 PM H 0 C:\WINDOWS\TEMP\CS1E4D58DF-B13A-48C0-B77E-6E2B3E9CDD31.tmp
10/08/2005 5:28:16 PM H 0 C:\WINDOWS\TEMP\CSBFB291FF-8D25-4EFF-914F-090E73FF316A.tmp
10/08/2005 5:28:16 PM H 0 C:\WINDOWS\TEMP\CS10A5C957-F01F-48C4-99FF-0E604F68B8F1.tmp
10/08/2005 5:28:16 PM H 0 C:\WINDOWS\TEMP\CS057CC2A0-9746-49C5-B72A-4B57FAC71835.tmp
10/08/2005 8:57:46 PM H 0 C:\WINDOWS\TEMP\CS5821B43E-F003-457D-BDCE-317018A3ED26.tmp
10/08/2005 8:57:46 PM H 0 C:\WINDOWS\TEMP\CS661B085D-617D-42D0-A8BF-9D742F681C40.tmp
10/08/2005 8:57:46 PM H 0 C:\WINDOWS\TEMP\CS49385D2F-291F-4A06-B384-D036B5698A1A.tmp
10/08/2005 8:57:46 PM H 0 C:\WINDOWS\TEMP\CSBEA3A1DA-49DB-4AD0-9E7C-FC72475ED7F8.tmp
10/08/2005 8:57:46 PM H 0 C:\WINDOWS\TEMP\CS58BEA37D-E774-4C09-8AB5-7D8D6DA27C67.tmp
10/08/2005 8:57:46 PM H 0 C:\WINDOWS\TEMP\CS6C18BF77-13BB-45E0-9730-A8F678FD8116.tmp
10/08/2005 8:57:46 PM H 0 C:\WINDOWS\TEMP\CSD5AE453C-1EC9-474D-9801-170D6D177F66.tmp
10/08/2005 8:57:46 PM H 0 C:\WINDOWS\TEMP\CSAEDD6E5F-E25B-4948-94B2-64C9D1D01958.tmp
10/08/2005 8:57:46 PM H 0 C:\WINDOWS\TEMP\CSFDDA0936-ECB8-47D3-B143-2560C32BF278.tmp
10/08/2005 8:57:46 PM H 0 C:\WINDOWS\TEMP\CS37B414B1-C5E4-4A58-9212-DDC090A8397B.tmp
10/08/2005 8:57:46 PM H 0 C:\WINDOWS\TEMP\CS909DDF3D-DDA2-4D7B-98A4-466602CB3F23.tmp
10/08/2005 8:57:46 PM H 0 C:\WINDOWS\TEMP\CS4139941B-BAE2-46CC-BC0C-ABB64E7FE0CD.tmp
10/08/2005 8:57:46 PM H 0 C:\WINDOWS\TEMP\CSA1585960-6746-407A-AF66-DDF1D393B42D.tmp
10/08/2005 8:57:46 PM H 0 C:\WINDOWS\TEMP\CS3BFE5166-D705-405B-91BC-B6A35325B92C.tmp
10/08/2005 8:57:46 PM H 0 C:\WINDOWS\TEMP\CSDDAB589B-C47B-40A5-A2EF-433D4E7D6B08.tmp
10/08/2005 8:57:46 PM H 0 C:\WINDOWS\TEMP\CS29F6326D-3ABB-4CA1-B79C-390E2846DA46.tmp
10/08/2005 8:57:46 PM H 0 C:\WINDOWS\TEMP\CSC0EA89E2-705D-489C-B443-F7A4A5E48B79.tmp
10/08/2005 8:57:46 PM H 0 C:\WINDOWS\TEMP\CS16317D5D-47F5-441C-A1F8-70BA6DB62E08.tmp
10/08/2005 8:57:46 PM H 0 C:\WINDOWS\TEMP\CSC080B830-DCC6-49E1-A506-11B7A3E251EC.tmp
10/08/2005 8:57:46 PM H 0 C:\WINDOWS\TEMP\CS3730C0BE-1B53-470F-8DFB-A07C0567D416.tmp
10/08/2005 8:57:46 PM H 0 C:\WINDOWS\TEMP\CS41CFCEA7-FFCC-4438-A6E7-FCBA2BC343DC.tmp
10/08/2005 8:57:46 PM H 0 C:\WINDOWS\TEMP\CSE07A08A2-B876-476D-9E65-D5E4E00F1FCB.tmp
10/08/2005 8:57:46 PM H 0 C:\WINDOWS\TEMP\CSD295914C-5194-46B3-B6E0-7E46BCCA0693.tmp
10/08/2005 8:57:46 PM H 0 C:\WINDOWS\TEMP\CS003DDC6E-2BE6-4FA0-A811-5FD42BA0A485.tmp
10/08/2005 8:57:46 PM H 0 C:\WINDOWS\TEMP\CS2292930B-66EF-4624-8145-5CD3AB93F805.tmp
10/08/2005 8:57:46 PM H 0 C:\WINDOWS\TEMP\CS184A8851-B2FC-4B77-8676-E0D1B6E8132C.tmp
10/08/2005 8:57:46 PM H 0 C:\WINDOWS\TEMP\CS281DFF61-EE08-4304-9224-3A72A970BDB3.tmp
10/08/2005 8:57:46 PM H 0 C:\WINDOWS\TEMP\CSAC472CBA-5F27-49DA-9C89-0122034D52D7.tmp
10/08/2005 8:57:46 PM H 0 C:\WINDOWS\TEMP\CS6B9248FD-1B38-43AE-A75E-6EA28B5BAB3E.tmp
10/08/2005 8:57:46 PM H 0 C:\WINDOWS\TEMP\CS50A20324-D375-4D8D-9E35-E3B9E55BEC00.tmp
10/08/2005 8:57:46 PM H 0 C:\WINDOWS\TEMP\CS3CA5F656-6EF2-4C0E-A858-574F6A75B420.tmp
10/08/2005 8:57:46 PM H 0 C:\WINDOWS\TEMP\CSA692CB64-98B8-4924-AD22-4D477CD53A6B.tmp
10/08/2005 9:02:22 PM H 0 C:\WINDOWS\TEMP\CSDE4F58EA-7814-4784-A182-F98D7C7C7072.tmp
10/08/2005 9:02:22 PM H 0 C:\WINDOWS\TEMP\CS7ABB0B65-1E72-421F-B1CD-E26DCBBD6458.tmp
10/08/2005 9:02:22 PM H 0 C:\WINDOWS\TEMP\CS3C8B32C2-041E-4AE4-8302-868A49C22D2A.tmp
10/08/2005 9:02:22 PM H 0 C:\WINDOWS\TEMP\CS3DCF460E-E476-41D7-AE43-7A7369BA534A.tmp
10/08/2005 9:02:22 PM H 0 C:\WINDOWS\TEMP\CS4D62763D-F293-4112-915D-E8EAE3119BD3.tmp
10/08/2005 9:02:22 PM H 0 C:\WINDOWS\TEMP\CSEB2145DB-4C43-4F64-AB6F-1CD1A41CC03A.tmp
10/08/2005 9:02:22 PM H 0 C:\WINDOWS\TEMP\CS4CA4635A-2ADD-4432-9113-18CEE4AEAF2D.tmp
10/08/2005 9:02:22 PM H 0 C:\WINDOWS\TEMP\CS584BF990-88C1-4BAB-9D2C-5F914B2BA3DC.tmp
10/08/2005 9:02:22 PM H 0 C:\WINDOWS\TEMP\CSD98E8073-B01A-45E5-9C49-3B7EB6128C59.tmp
10/08/2005 9:02:22 PM H 0 C:\WINDOWS\TEMP\CS09591727-05D6-43E1-8490-C7901059C565.tmp
10/08/2005 9:02:22 PM H 0 C:\WINDOWS\TEMP\CS76A92558-B51A-4990-892B-69091722B08E.tmp
10/08/2005 9:02:22 PM H 0 C:\WINDOWS\TEMP\CS8BE2BA56-45DB-4A8E-A2E0-6EFA1B99A6E7.tmp
10/08/2005 9:02:22 PM H 0 C:\WINDOWS\TEMP\CS63E2D6F8-83B5-4349-B440-F11C1EDDABF0.tmp
10/08/2005 9:02:22 PM H 0 C:\WINDOWS\TEMP\CS5B6D26B3-195A-4784-B58B-C452C1BE730A.tmp
10/08/2005 9:02:22 PM H 0 C:\WINDOWS\TEMP\CS35343A49-90E6-4E74-94CE-1C4CF9657110.tmp
10/08/2005 9:02:22 PM H 0 C:\WINDOWS\TEMP\CSB9467928-6AF3-4441-994F-C38A0E0A1EDF.tmp
10/08/2005 9:02:22 PM H 0 C:\WINDOWS\TEMP\CS748F38A2-F199-4F13-8214-E507F1779790.tmp
10/08/2005 9:02:22 PM H 0 C:\WINDOWS\TEMP\CSD957D7EE-2D0D-455C-9F62-B032CC096569.tmp
10/08/2005 9:02:22 PM H 0 C:\WINDOWS\TEMP\CSDE3C0712-AB6A-4574-8BC6-3C9AECBEFF1C.tmp
10/08/2005 9:02:22 PM H 0 C:\WINDOWS\TEMP\CS59D5F80B-600A-434E-80A1-F51AFBC43625.tmp
10/08/2005 9:02:22 PM H 0 C:\WINDOWS\TEMP\CS2B6F4B05-CC19-47DA-B486-7DD35B3ADF85.tmp
10/08/2005 9:02:22 PM H 0 C:\WINDOWS\TEMP\CS10CBF1D8-1D53-48DE-B34C-D3174470AA7F.tmp
10/08/2005 9:02:22 PM H 0 C:\WINDOWS\TEMP\CS95115C13-D8EF-4B48-938E-011E7A91702A.tmp
10/08/2005 9:02:22 PM H 0 C:\WINDOWS\TEMP\CS4573D29F-E379-468A-9DBF-1412A3E72685.tmp
10/08/2005 9:02:22 PM H 0 C:\WINDOWS\TEMP\CSC272FA0E-4F53-4C52-B433-F7857658CDDF.tmp
10/08/2005 9:02:22 PM H 0 C:\WINDOWS\TEMP\CS105AE4DE-D440-4B9A-BD7D-633BAB086D05.tmp
10/08/2005 9:02:22 PM H 0 C:\WINDOWS\TEMP\CS40F4F1F8-CB06-49A4-9C85-7B76912A59B7.tmp
10/08/2005 9:02:22 PM H 0 C:\WINDOWS\TEMP\CS0720632F-6ABD-4D66-B264-293F5EAB6850.tmp
10/08/2005 9:02:22 PM H 0 C:\WINDOWS\TEMP\CS9E37D24C-1309-4A96-B99F-A7D4AA4F61E3.tmp
10/08/2005 9:02:22 PM H 0 C:\WINDOWS\TEMP\CSE87E70C2-10E7-41E8-A782-920A1D15D923.tmp
10/08/2005 9:02:22 PM H 0 C:\WINDOWS\TEMP\CS06722E9C-8067-4FF2-9612-8EE5CB571906.tmp
10/08/2005 9:02:22 PM H 0 C:\WINDOWS\TEMP\CS9727F126-CFC9-4627-A723-2CFBB83C29FD.tmp
10/08/2005 9:02:22 PM H 0 C:\WINDOWS\TEMP\CS97C46565-1152-47CC-A9EA-03E98B3295BA.tmp
10/08/2005 9:02:22 PM H 0 C:\WINDOWS\TEMP\CSCE7F7E7E-D97D-4255-AABB-8571AF0F8FB9.tmp
10/08/2005 9:02:22 PM H 0 C:\WINDOWS\TEMP\CS3F0218D4-F283-4E72-9696-FDEC46A21412.tmp
10/08/2005 9:02:22 PM H 0 C:\WINDOWS\TEMP\CSE68E588B-0FE2-4B7D-AF9C-A1D12985E18F.tmp
10/08/2005 9:02:22 PM H 0 C:\WINDOWS\TEMP\CS24113309-77F9-4C84-89EA-9EC2CAF0C47E.tmp
10/08/2005 9:02:22 PM H 0 C:\WINDOWS\TEMP\CS6AA9983B-5660-4EA7-8126-86BD938A6FE2.tmp
10/08/2005 9:02:22 PM H 0 C:\WINDOWS\TEMP\CS707C0009-2287-4F06-82B2-7D9456600BD0.tmp
10/08/2005 9:02:22 PM H 0 C:\WINDOWS\TEMP\CSEC707E4C-7602-4ED8-9C2B-6CBBC520A987.tmp
10/08/2005 9:02:22 PM H 0 C:\WINDOWS\TEMP\CSDB785FD3-2015-4BD4-849E-8D5400DBDB33.tmp
10/08/2005 9:02:22 PM H 0 C:\WINDOWS\TEMP\CSED6A0F70-62C9-4C3F-A2CB-4B1A8D154BFA.tmp
10/08/2005 9:02:22 PM H 0 C:\WINDOWS\TEMP\CS482AFF2E-8473-472E-96AA-D2136463CF11.tmp
10/08/2005 9:02:22 PM H 0 C:\WINDOWS\TEMP\CSEC50E712-3EA5-4942-AE2D-B9AC62E1E9BE.tmp
10/08/2005 9:02:22 PM H 0 C:\WINDOWS\TEMP\CS38C66D31-F2DB-4D90-AFD7-C4B62AA8D92C.tmp
10/08/2005 9:02:22 PM H 0 C:\WINDOWS\TEMP\CSDFB192AC-5D59-4203-972C-F1958EDA0F6F.tmp
10/08/2005 9:02:22 PM H 0 C:\WINDOWS\TEMP\CSFBEAAB6B-BC7D-4E51-B803-4EC7980516BE.tmp
10/08/2005 9:02:22 PM H 0 C:\WINDOWS\TEMP\CS7F592C8D-DF39-4539-BB50-FB347FF353BC.tmp
10/08/2005 9:02:22 PM H 0 C:\WINDOWS\TEMP\CSDA590D27-7ACB-43F7-B89C-15F1AE113EEC.tmp
10/08/2005 9:02:22 PM H 0 C:\WINDOWS\TEMP\CS01301647-E4DE-448D-8612-A3744F4D0296.tmp
10/08/2005 9:02:22 PM H 0 C:\WINDOWS\TEMP\CSCECB0FDD-AA89-447C-980D-1BDCE4D19895.tmp
10/08/2005 9:02:22 PM H 0 C:\WINDOWS\TEMP\CS4CBD6FA0-6D3A-4F5E-BAA8-ACA4997D59A5.tmp
10/08/2005 9:02:22 PM H 0 C:\WINDOWS\TEMP\CS75AA1025-413D-4A46-9085-DB7AF31D2290.tmp
10/08/2005 9:02:22 PM H 0 C:\WINDOWS\TEMP\CS61308DB2-8962-44CB-AD11-EE89C68E8071.tmp
10/08/2005 9:02:22 PM H 0 C:\WINDOWS\TEMP\CSCB7C3B02-CAFC-4C47-8585-B1514BB462CF.tmp
10/08/2005 9:02:22 PM H 0 C:\WINDOWS\TEMP\CS511466A4-FC56-44CE-8B82-EC97AD8707AB.tmp
10/08/2005 9:02:22 PM H 0 C:\WINDOWS\TEMP\CS1A4C2854-BAB1-4C7C-85C6-5A85D68B8770.tmp
10/08/2005 9:02:22 PM H 0 C:\WINDOWS\TEMP\CS2DD895AC-094C-40B1-8EE7-CCBAD1FED5A0.tmp
10/08/2005 9:02:22 PM H 0 C:\WINDOWS\TEMP\CS61B12A54-8436-4510-8C73-026D2832FE5D.tmp
10/08/2005 9:02:22 PM H 0 C:\WINDOWS\TEMP\CS68D7E890-A571-4DE5-B53A-D46F70E7A05C.tmp
10/08/2005 9:02:22 PM H 0 C:\WINDOWS\TEMP\CSB7A5451D-F21A-4992-826E-6E1029581976.tmp
10/08/2005 9:02:22 PM H 0 C:\WINDOWS\TEMP\CSB9DC2620-9E4B-41CA-BE80-49AB49F60E16.tmp
10/08/2005 9:02:22 PM H 0 C:\WINDOWS\TEMP\CSC8980620-D059-45FC-B153-CCCF380C03A8.tmp
10/08/2005 9:02:22 PM H 0 C:\WINDOWS\TEMP\CSADFB713E-8B92-485B-BCC4-101AD261852A.tmp
10/08/2005 9:02:22 PM H 0 C:\WINDOWS\TEMP\CSFDE2CA4C-1170-44FA-8B0F-0A50D95B127B.tmp
10/08/2005 9:02:22 PM H 0 C:\WINDOWS\TEMP\CSA86CD01E-26DD-459D-94EA-FBBB31DFA616.tmp
10/08/2005 9:02:22 PM H 0 C:\WINDOWS\TEMP\CS30EC607C-ACC3-4235-A67E-08687E6FD06B.tmp
10/08/2005 9:02:22 PM H 0 C:\WINDOWS\TEMP\CS40E95241-AEAF-4969-8E1C-02E606757890.tmp
10/08/2005 9:02:22 PM H 0 C:\WINDOWS\TEMP\CS5BC3C37C-B8C8-47B5-9081-4933252CA878.tmp
11/08/2005 5:58:04 PM H 0 C:\WINDOWS\TEMP\CS0700709F-2757-43FC-8DF1-16020E20C60F.tmp
11/08/2005 5:58:04 PM H 0 C:\WINDOWS\TEMP\CSA343EE5D-C962-40DC-B56E-59BCDA991CA6.tmp
11/08/2005 5:58:04 PM H 0 C:\WINDOWS\TEMP\CSF90D29CA-1015-4EC3-ABEE-71F55704D29D.tmp
11/08/2005 5:58:04 PM H 0 C:\WINDOWS\TEMP\CS5FE4C289-9ABD-4271-ADD3-41FAEAC14BC2.tmp
11/08/2005 5:58:04 PM H 0 C:\WINDOWS\TEMP\CSF3358CD2-FB07-4C66-AAE8-703CCB7175C4.tmp
11/08/2005 5:58:04 PM H 0 C:\WINDOWS\TEMP\CSF82A9EB7-81C0-426B-966C-B61C186FE1F0.tmp
11/08/2005 5:58:04 PM H 0 C:\WINDOWS\TEMP\CSF264679B-7C46-4C24-89FC-146574C533E0.tmp
11/08/2005 5:58:04 PM H 0 C:\WINDOWS\TEMP\CS2376562C-64D1-4F2B-91CC-1F2115B5E92F.tmp
11/08/2005 5:58:04 PM H 0 C:\WINDOWS\TEMP\CSDC7B910C-D1E3-4DDF-ABE4-533AB5B3CE9E.tmp
11/08/2005 5:58:04 PM H 0 C:\WINDOWS\TEMP\CS0D11CA6F-0881-40F8-898D-77B34BF935E8.tmp

Checking for CPL files...


Part 2

WARNING: not all files found by this scanner are bad. Consult with a knowledgable person before proceeding.

If you see a message in the titlebar saying "Not responding..." you can ignore it. Windows somethimes displays this message due to the high volume of disk I/O. As long as the hard disk light is flashing, the program is still working properly.

»»»»»»»»»»»»»»»»» Windows OS and Versions »»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»
Product Name: Windows Millennium Edition Version: 4.90.3000
Internet Explorer Version: 6.0.2800.1106

»»»»»»»»»»»»»»»»» Checking Selected Standard Folders »»»»»»»»»»»»»»»»»»»»

Checking %System%\Drivers folder and sub-folders...

Checking for CPL files...
Microsoft Corporation 29/08/2002 7:07:38 AM 292352 C:\WINDOWS\SYSTEM\INETCPL.CPL
Microsoft Corporation 8/06/2000 5:00:00 PM 62464 C:\WINDOWS\SYSTEM\INTL.CPL
Microsoft Corporation 8/06/2000 5:00:00 PM 104368 C:\WINDOWS\SYSTEM\MODEM.CPL
Microsoft Corporation 8/06/2000 5:00:00 PM 41232 C:\WINDOWS\SYSTEM\ODBCCP32.CPL
Microsoft Corporation 8/06/2000 5:00:00 PM 61200 C:\WINDOWS\SYSTEM\POWERCFG.CPL
Microsoft Corporation 8/06/2000 5:00:00 PM 79872 C:\WINDOWS\SYSTEM\APPWIZ.CPL
Microsoft Corporation 8/06/2000 5:00:00 PM 221280 C:\WINDOWS\SYSTEM\DESK.CPL
Microsoft Corporation 8/06/2000 5:00:00 PM 250128 C:\WINDOWS\SYSTEM\JOY.CPL
Microsoft Corporation 8/06/2000 5:00:00 PM 111616 C:\WINDOWS\SYSTEM\MAIN.CPL
Microsoft Corporation 8/06/2000 5:00:00 PM 408576 C:\WINDOWS\SYSTEM\MMSYS.CPL
Microsoft Corporation 8/06/2000 5:00:00 PM 14448 C:\WINDOWS\SYSTEM\NETCPL.CPL
Microsoft Corporation 8/06/2000 5:00:00 PM 47104 C:\WINDOWS\SYSTEM\PASSWORD.CPL
Microsoft Corporation 8/06/2000 5:00:00 PM 389872 C:\WINDOWS\SYSTEM\SYSDM.CPL
Microsoft Corporation 8/06/2000 5:00:00 PM 15360 C:\WINDOWS\SYSTEM\TELEPHON.CPL
Microsoft Corporation 8/06/2000 5:00:00 PM 15152 C:\WINDOWS\SYSTEM\WUAUCPL.CPL
Microsoft Corporation 8/06/2000 5:00:00 PM 66560 C:\WINDOWS\SYSTEM\ACCESS.CPL
Microsoft Corporation 8/06/2000 5:00:00 PM 15360 C:\WINDOWS\SYSTEM\THEMES.CPL
Microsoft Corporation 8/06/2000 5:00:00 PM 36864 C:\WINDOWS\SYSTEM\TIMEDATE.CPL
Microsoft Corporation 10/02/1999 11:48:48 AM 40960 C:\WINDOWS\SYSTEM\FINDFAST.CPL
Apple Computer, Inc. 14/12/2003 9:20:50 AM 323072 C:\WINDOWS\SYSTEM\QuickTime.cpl
Sun Microsystems, Inc. 6/12/2004 9:31:48 PM 49265 C:\WINDOWS\SYSTEM\jpicpl32.cpl

»»»»»»»»»»»»»»»»» Checking Selected Startup Folders »»»»»»»»»»»»»»»»»»»»»

Checking files in %ALLUSERSPROFILE%\Startup folder...

Checking files in %ALLUSERSPROFILE%\Application Data folder...

Checking files in %USERPROFILE%\Startup folder...
28/03/2005 10:34:50 AM 560 C:\WINDOWS\Start Menu\Programs\StartUp\Microsoft Office.lnk

Checking files in %USERPROFILE%\Application Data folder...
31/08/2005 5:10:56 AM 1304 C:\WINDOWS\Application Data\dw.log
12/07/2005 5:06:48 PM 60328 C:\WINDOWS\Application Data\GDIPFONTCACHEV1.DAT
13/07/2005 9:54:58 PM 0 C:\WINDOWS\Application Data\Install.dat

»»»»»»»»»»»»»»»»» Checking Selected Registry Keys »»»»»»»»»»»»»»»»»»»»»»»

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\User Agent\Post Platform]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved]
{FEF10FA2-355E-4e06-9381-9B24D7F7CC88} = C:\WINDOWS\SYSTEM\SHELL32.DLL
{53C74826-AB99-4d33-ACA4-3117F51D3788} = C:\WINDOWS\SYSTEM\SHELL32.DLL
{E88DCCE0-B7B3-11d1-A9F0-00AA0060FA31} = C:\WINDOWS\SYSTEM\ZIPFLDR.DLL
{BD472F60-27FA-11cf-B8B4-444553540000} = C:\WINDOWS\SYSTEM\ZIPFLDR.DLL




0 user(s) are reading this topic

0 members, 0 guests, 0 anonymous users