Jump to content


 


Register a free account to unlock additional features at BleepingComputer.com
Welcome to BleepingComputer, a free community where people like yourself come together to discuss and learn how to use their computers. Using the site is easy and fun. As a guest, you can browse and view the various discussions in the forums, but can not create a new topic or reply to an existing one unless you are logged in. Other benefits of registering an account are subscribing to topics and forums, creating a blog, and having no ads shown anywhere on the site.


Click here to Register a free account now! or read our Welcome Guide to learn how to use this site.

Photo

Commbofix log


  • This topic is locked This topic is locked
2 replies to this topic

#1 mannahbk

mannahbk

  • Members
  • 1 posts
  • OFFLINE
  •  
  • Local time:01:39 PM

Posted 18 September 2009 - 06:03 AM

ComboFix 09-09-17.04 - newpc i 09/18/09 13:27.3.1 - NTFSx86
Microsoft Windows XP Professional 5.1.2600.2.1252.1.1033.18.1015.709 [GMT 5.5:30]
Running from: c:\documents and settings\newpc\Desktop\ComboFix.exe
AV: Quick Heal 10.00 *On-access scanning disabled* (Updated) {05C1329D-F0E0-4B19-9D15-54F9BC3ADE87}
.

((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
.
---- Previous Run -------
.
c:\documents and settings\All Users\Application Data\Microsoft\Network\Downloader\qmgr0.dat
c:\documents and settings\All Users\Application Data\Microsoft\Network\Downloader\qmgr1.dat
c:\program files\AskSearch\bin\DefaultSearch.dll
c:\windows\system32\setting.ini
c:\windows\system32\setup.ini
c:\windows\wpd99.drv

-- Previous Run --

Infected copy of c:\windows\system32\imm32.dll was found and disinfected
Restored copy from - c:\windows\system32\dllcache\imm32.dll

--------

.
((((((((((((((((((((((((((((((((((((((( Drivers/Services )))))))))))))))))))))))))))))))))))))))))))))))))
.

-------\Legacy_ASC3360PR
-------\Service_asc3360pr


((((((((((((((((((((((((( Files Created from 2009-08-18 to 2009-09-18 )))))))))))))))))))))))))))))))
.

2009-09-17 08:53 . 2009-09-17 08:53 -------- d-----w- c:\documents and settings\newpc\Application Data\Windows Search
2009-09-17 07:33 . 2009-09-17 07:33 -------- d-----w- c:\documents and settings\newpc\Application Data\Windows Desktop Search
2009-09-17 07:32 . 2009-09-17 07:32 -------- d-----w- c:\program files\Windows Desktop Search
2009-09-17 07:32 . 2009-09-17 07:32 -------- d-----w- c:\windows\system32\GroupPolicy
2009-09-17 07:32 . 2007-09-27 05:16 23856 ----a-w- c:\windows\system32\spupdsvc.exe
2009-09-17 07:32 . 2009-09-17 07:32 -------- d--h--w- c:\windows\$hf_mig$
2009-09-17 07:31 . 2009-09-17 07:31 -------- d-----w- c:\program files\MSECache
2009-09-16 10:47 . 2009-09-18 05:24 -------- d-----w- c:\documents and settings\New Folder\Ben Dover - Naughty British Babes
2009-09-16 10:38 . 2009-09-17 05:46 -------- d-----w- c:\documents and settings\New Folder\Naughty.America.Real.Big.Tits.1.2009.XXX.DVDRip.XviD-CiCXXX
2009-09-16 04:05 . 2009-09-16 04:05 -------- d-----w- c:\documents and settings\New Folder\Daddy_Cool_2009_Hindi_1CD_Pre-DVDRip_E_SUB_xRG
2009-09-16 04:04 . 2009-09-16 04:04 -------- d-----w- c:\documents and settings\New Folder\Fox_2009_Hindi_1CD_Pre-DVDRip_XviD_Mp3_xRG
2009-09-15 12:43 . 2009-09-15 12:43 -------- d-----w- c:\documents and settings\New Folder\Aagey_Se_Right_2009_Hindi_1CD_PreDVDRip_XviD_xRG
2009-09-15 10:27 . 2009-09-15 18:41 -------- d-----w- c:\documents and settings\New Folder\Lesbian.Seductions.26.XXX.DVDRip.XviD-FLESHLiGHT
2009-09-15 10:17 . 2009-09-16 11:49 -------- d-----w- c:\documents and settings\New Folder\South.Beach.Cruisin.3.XXX.DVDRip.XVID-DFA
2009-09-15 07:06 . 2009-09-15 07:06 639224 ----a-w- c:\windows\system32\drivers\sptd.sys
2009-09-14 12:44 . 2009-09-14 13:09 -------- d-----w- c:\documents and settings\New Folder\Aamras_2009_1CD_Pre-DVDRip_E-SuB_xRG
2009-09-14 04:24 . 2009-09-14 04:25 -------- d-----w- c:\documents and settings\LocalService\Application Data\Yahoo!
2009-09-11 09:55 . 2009-09-14 12:48 -------- d-----w- c:\documents and settings\New Folder\Austin Powers International Man Of Mystery KLAXXON
2009-08-20 07:33 . 2009-08-20 07:33 -------- d-----w- c:\program files\ConvertHelper
2009-08-20 07:26 . 2009-08-20 07:32 3782822 ----a-w- c:\program files\ConvertHelperSetup.exe
2009-08-20 07:24 . 2009-08-20 07:24 -------- d-----w- c:\documents and settings\newpc\dwhelper
2009-08-20 07:13 . 2009-03-07 05:14 1878888 ----a-w- c:\program files\install_flash_player.exe
2009-08-20 07:06 . 2009-08-20 07:06 0 ----a-w- c:\windows\nsreg.dat
2009-08-20 07:06 . 2009-08-20 07:06 -------- d-----w- c:\documents and settings\newpc\Local Settings\Application Data\Mozilla
2009-08-20 07:05 . 2007-10-25 05:32 6021344 ----a-w- c:\program files\Firefox Setup 2.0.0.8.exe

.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2009-09-18 07:45 . 2009-07-06 07:18 -------- d-----w- c:\documents and settings\newpc\Application Data\uTorrent
2009-09-17 05:51 . 2008-12-02 11:32 -------- d-----w- c:\documents and settings\All Users\Application Data\pdf995
2009-09-14 04:24 . 2009-03-23 08:25 -------- d-----w- c:\documents and settings\All Users\Application Data\Yahoo! Companion
2009-08-27 09:50 . 2008-12-03 08:07 -------- d-----w- c:\program files\Java
2009-08-26 09:32 . 2009-05-16 12:43 -------- d-----w- c:\documents and settings\newpc\Application Data\BearShare
2009-07-24 06:34 . 2009-08-01 05:11 1375247 ----a-w- c:\program files\wrar39b5.exe
2009-04-04 07:16 . 2009-04-04 07:16 1211996 ----a-w- c:\program files\camfrogSetup.exe
2009-03-30 07:51 . 2009-03-30 07:51 321704 ----a-w- c:\program files\bolinstaller.exe
2009-03-18 05:59 . 2009-03-18 05:59 1606064 ----a-w- c:\program files\googletalk-setup.exe
2009-03-04 11:52 . 2008-11-25 05:10 40960 ----a-w- c:\program files\WINAMP 5.531 PROFESSIONAL CRACK INCLUDED[LATEST] by NiMo™.exe
2009-03-04 11:50 . 2008-12-02 11:44 5386240 ----a-w- c:\program files\ps2pdf995.exe
2009-03-04 11:50 . 2008-12-02 11:31 2654208 ----a-w- c:\program files\pdf995s.exe
2009-03-04 11:50 . 2008-12-12 06:35 32768 ----a-w- c:\program files\msgr9us.exe
2009-03-04 11:50 . 2009-03-03 06:34 5529600 ----a-w- c:\program files\mplayerc.exe
2009-01-28 06:16 . 2009-01-28 06:16 1724650 ----a-w- c:\program files\tminstall.exe
2008-12-02 10:56 . 2008-12-02 10:56 4127350 ----a-w- c:\program files\BullzipPDFPrinter_6_0_0_702.zip
2008-10-01 13:57 . 2009-04-04 11:08 14550083 ----a-w- c:\program files\vlc-0.9.3-ToRp3dO™.exe
2004-09-04 11:33 . 2009-03-19 03:54 4678475 ----a-w- c:\program files\VLC Media Player.exe
.

((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4

[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{201f27d4-3704-41d6-89c1-aa35e39143ed}]
2009-04-02 07:17 333192 ----a-w- c:\program files\AskBarDis\bar\bin\askBar.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar]
"{3041d03e-fd4b-44e0-b742-2d9b88305f98}"= "c:\program files\AskBarDis\bar\bin\askBar.dll" [2009-04-02 333192]

[HKEY_CLASSES_ROOT\clsid\{3041d03e-fd4b-44e0-b742-2d9b88305f98}]
[HKEY_CLASSES_ROOT\TypeLib\{4b1c1e16-6b34-430e-b074-5928eca4c150}]

[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Toolbar\Webbrowser]
"{3041D03E-FD4B-44E0-B742-2D9B88305F98}"= "c:\program files\AskBarDis\bar\bin\askBar.dll" [2009-04-02 333192]

[HKEY_CLASSES_ROOT\clsid\{3041d03e-fd4b-44e0-b742-2d9b88305f98}]
[HKEY_CLASSES_ROOT\TypeLib\{4b1c1e16-6b34-430e-b074-5928eca4c150}]

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Search Protection"="c:\program files\Yahoo!\Search Protection\SearchProtection.exe" [2009-02-03 111856]
"YSearchProtection"="c:\program files\Yahoo!\Search Protection\SearchProtection.exe" [2009-02-03 111856]
"Bol IM"="c:\program files\Rediff Bol\RediffMessenger.exe" [2007-06-21 3348440]
"uTorrent"="c:\program files\uTorrent\uTorrent.exe" [2009-07-06 288048]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"IgfxTray"="c:\windows\system32\igfxtray.exe" [2006-04-26 180224]
"HotKeysCmds"="c:\windows\system32\hkcmd.exe" [2006-04-26 159744]
"Persistence"="c:\windows\system32\igfxpers.exe" [2006-04-26 200704]
"NeroFilterCheck"="c:\windows\system32\NeroCheck.exe" [2009-03-04 155648]
"HP Software Update"="c:\program files\HP\HP Software Update\HPWuSchd2.exe" [2007-05-08 136760]
"Email Protection"="c:\progra~1\QUICKH~1\QUICKH~1\EMLPROUI.EXE" [2009-03-04 267640]
"Update Scheduler"="c:\progra~1\QUICKH~1\QUICKH~1\UPSCHD.EXE" [2009-03-04 95608]
"ResumeQuickupDownload"="c:\progra~1\QUICKH~1\QUICKH~1\acappaa.exe" [2009-03-04 95608]
"YSearchProtection"="c:\program files\Yahoo!\Search Protection\SearchProtection.exe" [2009-02-03 111856]
"SoundMan"="SOUNDMAN.EXE" - c:\windows\SOUNDMAN.EXE [2009-03-04 81920]

[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"YSearchProtection"="c:\program files\Yahoo!\Search Protection\SearchProtection.exe" [2009-02-03 111856]

c:\documents and settings\newpc\Start Menu\Programs\Startup\
OneNote 2007 Screen Clipper and Launcher.lnk - c:\program files\Microsoft Office\Office12\ONENOTEM.EXE [2006-10-26 91648]

c:\documents and settings\All Users\Start Menu\Programs\Startup\
Adobe Reader Speed Launch.lnk - c:\program files\Adobe\Acrobat 7.0\Reader\reader_sl.exe [2004-12-14 29696]
Windows Search.lnk - c:\program files\Windows Desktop Search\WindowsSearch.exe [2008-5-26 123904]

[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\policies\explorer]
"Hidden"= 1 (0x1)

[hkey_local_machine\software\microsoft\windows\currentversion\explorer\ShellExecuteHooks]
"{56F9679E-7826-4C84-81F3-532071A8BCC5}"= "c:\program files\Windows Desktop Search\MSNLNamespaceMgr.dll" [2008-05-26 304128]

[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Startup .exe]
path=c:\documents and settings\All Users\Start Menu\Programs\Startup\Startup .exe
backup=c:\windows\pss\Startup .exeCommon Startup

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\services]
"wscsvc"=2 (0x2)
"wuauserv"=2 (0x2)

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]
"EnableFirewall"= 0 (0x0)

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"c:\\Program Files\\Microsoft Office\\Office12\\OUTLOOK.EXE"=
"c:\\Program Files\\Microsoft Office\\Office12\\GROOVE.EXE"=
"c:\\Program Files\\Microsoft Office\\Office12\\ONENOTE.EXE"=
"c:\\Program Files\\Insignia\\TAV3.1.2\\Time&Attendance.exe"=
"c:\\Program Files\\Yahoo!\\Messenger\\YahooMessenger.exe"=
"c:\\Program Files\\VideoLAN\\VLC\\vlc.exe"=
"c:\\WINDOWS\\system32\\NeroCheck.exe"=
"c:\\PROGRA~1\\QUICKH~1\\QUICKH~1\\sensor.exe"=
"c:\\WINDOWS\\system32\\igfxsrvc.exe"=
"c:\\WINDOWS\\system32\\hkcmd.exe"=
"c:\\PROGRA~1\\QUICKH~1\\QUICKH~1\\CATEYE.EXE"=
"c:\\Program Files\\Adobe\\Acrobat 7.0\\Reader\\reader_sl.exe"=
"c:\\WINDOWS\\SOUNDMAN.EXE"=
"c:\\Program Files\\Microsoft Office\\Office12\\ONENOTEM.EXE"=
"c:\\Program Files\\TeamViewer\\Version4\\TeamViewer.exe"=
"c:\\Program Files\\Rediff Bol\\RediffMessenger.exe"=
"c:\\Program Files\\BearShare Applications\\BearShare\\BearShare.exe"=
"c:\\Program Files\\uTorrent\\uTorrent.exe"=

R2 catflt;catflt;c:\windows\system32\drivers\catflt.sys [3/4/09 18:05 65144]
R2 EMLSS;EMLSS;c:\windows\system32\drivers\EMLTDI.SYS [3/4/09 18:05 28656]
R2 Quick Heal Antivirus Plus Mail Protection;Quick Heal Antivirus Plus Mail Protection;c:\progra~1\QUICKH~1\QUICKH~1\EMLPROXY.EXE [3/4/09 18:05 50552]
R2 Quick Update Service;Quick Update Service;c:\progra~1\QUICKH~1\QUICKH~1\quhlpsvc.exe [3/4/09 18:05 58744]
S2 ASKUpgrade;ASKUpgrade;c:\program files\AskBarDis\bar\bin\ASKUpgrade.exe [7/6/09 12:51 234888]
S2 vobegj;Network Server;c:\windows\system32\svchost.exe -k netsvcs [8/4/04 00:56 14336]
S4 Online Protection System;Online Protection System;c:\progra~1\QUICKH~1\QUICKH~1\opssvc.exe [3/4/09 18:05 17272]

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Svchost - NetSvcs
vobegj
.
Contents of the 'Scheduled Tasks' folder

2009-09-17 c:\windows\Tasks\abc.job
- c:\progra~1\QUICKH~1\QUICKH~1\SCANNER.EXE [2009-03-04 13:59]
.
.
------- Supplementary Scan -------
.
uStart Page = hxxp://search.bearshare.com/intl/
mStart Page = hxxp://www.yahoo.com
mSearch Bar = hxxp://us.rd.yahoo.com/customize/ie/defaults/sb/msgr9/*http://www.yahoo.com/ext/search/search.html
uInternet Connection Wizard,ShellNext = iexplore
uSearchURL,(Default) = hxxp://toolbar.ask.com/toolbarv/askRedirect?o=13925&gct=&gc=1&q=%s
IE: E&xport to Microsoft Excel - c:\progra~1\MICROS~2\Office12\EXCEL.EXE/3000
TCP: {C595C6C5-20FA-4A9B-8E09-6AFC8F455C01} = 203.94.227.70,203.94.243.70
FF - ProfilePath - c:\documents and settings\newpc\Application Data\Mozilla\Firefox\Profiles\9buzklat.default\
.

**************************************************************************

catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2009-09-18 13:33
Windows 5.1.2600 Service Pack 2 NTFS

scanning hidden processes ...

scanning hidden autostart entries ...

scanning hidden files ...


c:\windows\TEMP\Adobe
c:\windows\TEMP\Adobe\Acrobat
c:\windows\TEMP\Adobe\Acrobat\7.0
c:\windows\TEMP\AskBarDis
c:\windows\TEMP\AskBarDis\RegTool
c:\windows\TEMP\AskBarDis\RegTool\RegToolConfig.ini 182 bytes
c:\windows\TEMP\AskBarDis\upgrade
c:\windows\TEMP\BearShareInstaller
c:\windows\TEMP\BearShareInstaller\BearShare.ico 25214 bytes
c:\windows\TEMP\BearShareInstaller\BearShareV7.exe 10430296 bytes executable
c:\windows\TEMP\BearSharePreview
c:\windows\TEMP\BearSharePreview\PVW1.tmp 0 bytes
c:\windows\TEMP\BearSharePreview\PVW1.tmp.mp3 512000 bytes
c:\windows\TEMP\BearSharePreview\PVW10.tmp 0 bytes
c:\windows\TEMP\BearSharePreview\PVW10.tmp.mp3 135296 bytes
c:\windows\TEMP\BearSharePreview\PVW11.tmp 0 bytes
c:\windows\TEMP\BearSharePreview\PVW11.tmp.mp3 0 bytes
c:\windows\TEMP\BearSharePreview\PVW12.tmp 0 bytes
c:\windows\TEMP\BearSharePreview\PVW12.tmp.wma 512000 bytes
c:\windows\TEMP\BearSharePreview\PVW13.tmp 0 bytes
c:\windows\TEMP\BearSharePreview\PVW13.tmp.wma 512000 bytes
c:\windows\TEMP\BearSharePreview\PVW14.tmp 0 bytes
c:\windows\TEMP\BearSharePreview\PVW14.tmp.wma 512000 bytes
c:\windows\TEMP\BearSharePreview\PVW15.tmp 0 bytes
c:\windows\TEMP\BearSharePreview\PVW15.tmp.wma 512000 bytes
c:\windows\TEMP\BearSharePreview\PVW35.tmp.mp3 516224 bytes
c:\windows\TEMP\BearSharePreview\PVW36.tmp 0 bytes
c:\windows\TEMP\BearSharePreview\PVW36.tmp.ASF 512000 bytes
c:\windows\TEMP\BearSharePreview\PVW37.tmp 0 bytes
c:\windows\TEMP\BearSharePreview\PVW37.tmp.ASF 512000 bytes
c:\windows\TEMP\BearSharePreview\PVW38.tmp 0 bytes
c:\windows\TEMP\BearSharePreview\PVW38.tmp.wmv 512000 bytes
c:\windows\TEMP\BearSharePreview\PVW39.tmp 0 bytes
c:\windows\TEMP\BearSharePreview\PVW39.tmp.wmv 512000 bytes
c:\windows\TEMP\BearSharePreview\PVW3A.tmp 0 bytes
c:\windows\TEMP\BearSharePreview\PVW3A.tmp.wmv 512000 bytes
c:\windows\TEMP\BearSharePreview\PVW3B.tmp 0 bytes
c:\windows\TEMP\BearSharePreview\PVW3C.tmp 0 bytes
c:\windows\TEMP\BearSharePreview\PVW3C.tmp.asf 512000 bytes
c:\windows\TEMP\BearSharePreview\PVW3D.tmp 0 bytes
c:\windows\TEMP\BearSharePreview\PVW3D.tmp.asf 512000 bytes
c:\windows\TEMP\BearSharePreview\PVW3E.tmp 0 bytes
c:\windows\TEMP\BearSharePreview\PVW3E.tmp.asf 512000 bytes
c:\windows\TEMP\BearSharePreview\PVW3F.tmp 0 bytes
c:\windows\TEMP\BearSharePreview\PVW3F.tmp.asf 512000 bytes
c:\windows\TEMP\BearSharePreview\PVW40.tmp 0 bytes
c:\windows\TEMP\BearSharePreview\PVW40.tmp.avi 512000 bytes
c:\windows\TEMP\BearSharePreview\PVW41.tmp 0 bytes
c:\windows\TEMP\BearSharePreview\PVW41.tmp.avi 512000 bytes
c:\windows\TEMP\BearSharePreview\PVW42.tmp 0 bytes
c:\windows\TEMP\BearSharePreview\PVW42.tmp.Avi 512000 bytes
c:\windows\TEMP\BearSharePreview\PVW43.tmp 0 bytes
c:\windows\TEMP\BearSharePreview\PVW43.tmp.wmv 512000 bytes
c:\windows\TEMP\BearSharePreview\PVW44.tmp 0 bytes
c:\windows\TEMP\BearSharePreview\PVW44.tmp.wmv 512000 bytes
c:\windows\TEMP\BearSharePreview\PVW45.tmp 0 bytes
c:\windows\TEMP\BearSharePreview\PVW45.tmp.wmv 0 bytes
c:\windows\TEMP\BearSharePreview\PVW46.tmp 0 bytes
c:\windows\TEMP\BearSharePreview\PVW46.tmp.asf 512000 bytes
c:\windows\TEMP\BearSharePreview\PVW47.tmp 0 bytes
c:\windows\TEMP\BearSharePreview\PVW47.tmp.asf 512000 bytes
c:\windows\TEMP\BearSharePreview\PVW48.tmp 0 bytes
c:\windows\TEMP\BearSharePreview\PVW48.tmp.asf 512000 bytes
c:\windows\TEMP\BearSharePreview\PVW49.tmp 0 bytes
c:\windows\TEMP\BearSharePreview\PVW49.tmp.mp3 512000 bytes
c:\windows\TEMP\BearSharePreview\PVW4A.tmp 0 bytes
c:\windows\TEMP\BearSharePreview\PVW4A.tmp.wma 512000 bytes
c:\windows\TEMP\BearSharePreview\PVW4B.tmp 0 bytes
c:\windows\TEMP\BearSharePreview\PVW4B.tmp.wma 512000 bytes
c:\windows\TEMP\BearSharePreview\PVW4C.tmp 0 bytes
c:\windows\TEMP\BearSharePreview\PVW4C.tmp.wma 512000 bytes
c:\windows\TEMP\BearSharePreview\PVW4D.tmp 0 bytes
c:\windows\TEMP\BearSharePreview\PVW4D.tmp.wma 512000 bytes
c:\windows\TEMP\BearSharePreview\PVW4E.tmp 0 bytes
c:\windows\TEMP\BearSharePreview\PVW4E.tmp.wma 512000 bytes
c:\windows\TEMP\BearSharePreview\PVW4F.tmp 0 bytes
c:\windows\TEMP\BearSharePreview\PVW4F.tmp.wma 512000 bytes
c:\windows\TEMP\BearSharePreview\PVW70.tmp 0 bytes
c:\windows\TEMP\BearSharePreview\PVW70.tmp.mp3 321409 bytes
c:\windows\TEMP\BearSharePreview\PVW71.tmp 0 bytes
c:\windows\TEMP\BearSharePreview\PVW71.tmp.mp3 102528 bytes
c:\windows\TEMP\BearSharePreview\PVW72.tmp 0 bytes
c:\windows\TEMP\BearSharePreview\PVW72.tmp.mp3 356310 bytes
c:\windows\TEMP\BearSharePreview\PVW73.tmp 0 bytes
c:\windows\TEMP\BearSharePreview\PVW73.tmp.mp3 135296 bytes
c:\windows\TEMP\BearSharePreview\PVW74.tmp 0 bytes
c:\windows\TEMP\BearSharePreview\PVW74.tmp.mp3 262272 bytes
c:\windows\TEMP\BearSharePreview\PVW75.tmp 0 bytes
c:\windows\TEMP\BearSharePreview\PVW16.tmp 0 bytes
c:\windows\TEMP\BearSharePreview\PVW1C.tmp.avi 512000 bytes
c:\windows\TEMP\BearSharePreview\PVW219.tmp.mp3 512000 bytes
c:\windows\TEMP\BearSharePreview\PVW2F.tmp.asf 512000 bytes
c:\windows\TEMP\BearSharePreview\PVW35.tmp 0 bytes
c:\windows\TEMP\BearSharePreview\PVW3B.tmp.wmv 512000 bytes
c:\windows\TEMP\BearSharePreview\PVW5.tmp 0 bytes
c:\windows\TEMP\BearSharePreview\PVW6F.tmp.mp3 321409 bytes
c:\windows\TEMP\BearSharePreview\PVW75.tmp.wma 512000 bytes
c:\windows\TEMP\BearSharePreview\PVW87.tmp 0 bytes
c:\windows\TEMP\BearSharePreview\PVW96.tmp 0 bytes
c:\windows\TEMP\BearSharePreview\PVWA4.tmp 0 bytes
c:\windows\TEMP\BearSharePreview\PVWAA.tmp.mp3 512000 bytes
c:\windows\TEMP\BearSharePreview\PVWB0.tmp 0 bytes
c:\windows\TEMP\BearSharePreview\PVWB7.tmp.avi 512000 bytes
c:\windows\TEMP\BearSharePreview\PVWE9.tmp.mp3 512000 bytes
c:\windows\TEMP\BearSharePreview\PVW76.tmp 0 bytes
c:\windows\TEMP\BearSharePreview\PVW76.tmp.WMV 512000 bytes
c:\windows\TEMP\BearSharePreview\PVW77.tmp 0 bytes
c:\windows\TEMP\BearSharePreview\PVW77.tmp.WMV 512000 bytes
c:\windows\TEMP\BearSharePreview\PVW78.tmp 0 bytes
c:\windows\TEMP\BearSharePreview\PVW78.tmp.avi 512000 bytes
c:\windows\TEMP\BearSharePreview\PVW79.tmp 0 bytes
c:\windows\TEMP\BearSharePreview\PVW79.tmp.WMV 512000 bytes
c:\windows\TEMP\BearSharePreview\PVW7A.tmp 0 bytes
c:\windows\TEMP\BearSharePreview\PVW7A.tmp.WMV 512000 bytes
c:\windows\TEMP\BearSharePreview\PVW7B.tmp 0 bytes
c:\windows\TEMP\BearSharePreview\PVW7B.tmp.wma 512000 bytes
c:\windows\TEMP\BearSharePreview\PVW7C.tmp 0 bytes
c:\windows\TEMP\BearSharePreview\PVW7C.tmp.wma 512000 bytes
c:\windows\TEMP\BearSharePreview\PVW7D.tmp 0 bytes
c:\windows\TEMP\BearSharePreview\PVW7D.tmp.MP3 512000 bytes
c:\windows\TEMP\BearSharePreview\PVW7E.tmp 0 bytes
c:\windows\TEMP\BearSharePreview\PVW7E.tmp.MP3 512000 bytes
c:\windows\TEMP\BearSharePreview\PVW7F.tmp 0 bytes
c:\windows\TEMP\BearSharePreview\PVW7F.tmp.wma 0 bytes
c:\windows\TEMP\BearSharePreview\PVW80.tmp 0 bytes
c:\windows\TEMP\BearSharePreview\PVW80.tmp.wma 0 bytes
c:\windows\TEMP\BearSharePreview\PVW16.tmp.mp3 0 bytes
c:\windows\TEMP\BearSharePreview\PVW17.tmp 0 bytes
c:\windows\TEMP\BearSharePreview\PVW17.tmp.mp3 266368 bytes
c:\windows\TEMP\BearSharePreview\PVW18.tmp 0 bytes
c:\windows\TEMP\BearSharePreview\PVW18.tmp.wmv 512000 bytes
c:\windows\TEMP\BearSharePreview\PVW19.tmp 0 bytes
c:\windows\TEMP\BearSharePreview\PVW19.tmp.mp3 327808 bytes
c:\windows\TEMP\BearSharePreview\PVW1A.tmp 0 bytes
c:\windows\TEMP\BearSharePreview\PVW1A.tmp.wmv 512000 bytes
c:\windows\TEMP\BearSharePreview\PVW1B.tmp 0 bytes
c:\windows\TEMP\BearSharePreview\PVW1B.tmp.wmv 512000 bytes
c:\windows\TEMP\BearSharePreview\PVW1C.tmp 0 bytes
c:\windows\TEMP\BearSharePreview\PVW21A.tmp 0 bytes
c:\windows\TEMP\BearSharePreview\PVW21A.tmp.mp3 512000 bytes
c:\windows\TEMP\BearSharePreview\PVW21B.tmp 0 bytes
c:\windows\TEMP\BearSharePreview\PVW21B.tmp.mp3 512000 bytes
c:\windows\TEMP\BearSharePreview\PVW21C.tmp 0 bytes
c:\windows\TEMP\BearSharePreview\PVW21C.tmp.mp3 512000 bytes
c:\windows\TEMP\BearSharePreview\PVW21D.tmp 0 bytes
c:\windows\TEMP\BearSharePreview\PVW21D.tmp.mp3 512000 bytes
c:\windows\TEMP\BearSharePreview\PVW21E.tmp 0 bytes
c:\windows\TEMP\BearSharePreview\PVW21E.tmp.mp3 512000 bytes
c:\windows\TEMP\BearSharePreview\PVW21F.tmp 0 bytes
c:\windows\TEMP\BearSharePreview\PVW21F.tmp.mp3 512128 bytes
c:\windows\TEMP\BearSharePreview\PVW25.tmp 0 bytes
c:\windows\TEMP\BearSharePreview\PVW25.tmp.wmv 512000 bytes
c:\windows\TEMP\BearSharePreview\PVW26.tmp 0 bytes
c:\windows\TEMP\BearSharePreview\PVW26.tmp.wmv 294912 bytes
c:\windows\TEMP\BearSharePreview\PVW27.tmp 0 bytes
c:\windows\TEMP\BearSharePreview\PVW27.tmp.mp3 229376 bytes
c:\windows\TEMP\BearSharePreview\PVW28.tmp 0 bytes
c:\windows\TEMP\BearSharePreview\PVW28.tmp.mp3 512000 bytes
c:\windows\TEMP\BearSharePreview\PVW29.tmp 0 bytes
c:\windows\TEMP\BearSharePreview\PVW29.tmp.wmv 512000 bytes
c:\windows\TEMP\BearSharePreview\PVW2A.tmp 0 bytes
c:\windows\TEMP\BearSharePreview\PVW2A.tmp.mp3 516224 bytes
c:\windows\TEMP\BearSharePreview\PVW2B.tmp 0 bytes
c:\windows\TEMP\BearSharePreview\PVW2B.tmp.mp3 262272 bytes
c:\windows\TEMP\BearSharePreview\PVW2C.tmp 0 bytes
c:\windows\TEMP\BearSharePreview\PVW2C.tmp.mp3 516224 bytes
c:\windows\TEMP\BearSharePreview\PVW2D.tmp 0 bytes
c:\windows\TEMP\BearSharePreview\PVW2D.tmp.mp3 512000 bytes
c:\windows\TEMP\BearSharePreview\PVW2E.tmp 0 bytes
c:\windows\TEMP\BearSharePreview\PVW2E.tmp.mp3 0 bytes
c:\windows\TEMP\BearSharePreview\PVW2F.tmp 0 bytes
c:\windows\TEMP\BearSharePreview\PVW5.tmp.asf 512000 bytes
c:\windows\TEMP\BearSharePreview\PVW50.tmp 0 bytes
c:\windows\TEMP\BearSharePreview\PVW50.tmp.WMV 512000 bytes
c:\windows\TEMP\BearSharePreview\PVW51.tmp 0 bytes
c:\windows\TEMP\BearSharePreview\PVW51.tmp.WMV 512000 bytes
c:\windows\TEMP\BearSharePreview\PVW52.tmp 0 bytes
c:\windows\TEMP\BearSharePreview\PVW52.tmp.mp3 327680 bytes
c:\windows\TEMP\BearSharePreview\PVW53.tmp 0 bytes
c:\windows\TEMP\BearSharePreview\PVW53.tmp.wma 512000 bytes
c:\windows\TEMP\BearSharePreview\PVW54.tmp 0 bytes
c:\windows\TEMP\BearSharePreview\PVW54.tmp.wma 512000 bytes
c:\windows\TEMP\BearSharePreview\PVW55.tmp 0 bytes
c:\windows\TEMP\BearSharePreview\PVW55.tmp.mp3 491520 bytes
c:\windows\TEMP\BearSharePreview\PVW56.tmp 0 bytes
c:\windows\TEMP\BearSharePreview\PVW56.tmp.wma 512000 bytes
c:\windows\TEMP\BearSharePreview\PVW57.tmp 0 bytes
c:\windows\TEMP\BearSharePreview\PVW57.tmp.mp3 331904 bytes
c:\windows\TEMP\BearSharePreview\PVW58.tmp 0 bytes
c:\windows\TEMP\BearSharePreview\PVW58.tmp.wma 512000 bytes
c:\windows\TEMP\BearSharePreview\PVW59.tmp 0 bytes
c:\windows\TEMP\BearSharePreview\PVW59.tmp.wma 512000 bytes
c:\windows\TEMP\BearSharePreview\PVW5A.tmp 0 bytes
c:\windows\TEMP\BearSharePreview\PVW5A.tmp.wma 512000 bytes
c:\windows\TEMP\BearSharePreview\PVW5B.tmp 0 bytes
c:\windows\TEMP\BearSharePreview\PVW5B.tmp.mp3 262144 bytes
c:\windows\TEMP\BearSharePreview\PVW5C.tmp 0 bytes
c:\windows\TEMP\BearSharePreview\PVW5C.tmp.WMV 512000 bytes
c:\windows\TEMP\BearSharePreview\PVW5D.tmp 0 bytes
c:\windows\TEMP\BearSharePreview\PVW5D.tmp.mp3 516224 bytes
c:\windows\TEMP\BearSharePreview\PVW5E.tmp 0 bytes
c:\windows\TEMP\BearSharePreview\PVW5E.tmp.wmv 512000 bytes
c:\windows\TEMP\BearSharePreview\PVW5F.tmp 0 bytes
c:\windows\TEMP\BearSharePreview\PVW5F.tmp.asf 512000 bytes
c:\windows\TEMP\BearSharePreview\PVWEA.tmp 0 bytes
c:\windows\TEMP\BearSharePreview\PVWEA.tmp.wma 512000 bytes
c:\windows\TEMP\BearSharePreview\PVWEB.tmp 0 bytes
c:\windows\TEMP\BearSharePreview\PVWEB.tmp.mp3 516224 bytes
c:\windows\TEMP\BearSharePreview\PVWEC.tmp 0 bytes
c:\windows\TEMP\BearSharePreview\PVWEC.tmp.mp3 512000 bytes
c:\windows\TEMP\BearSharePreview\PVWED.tmp 0 bytes
c:\windows\TEMP\BearSharePreview\PVWED.tmp.mp3 516224 bytes
c:\windows\TEMP\BearSharePreview\PVWF.tmp 0 bytes
c:\windows\TEMP\BearSharePreview\PVWF.tmp.mp3 512000 bytes
c:\windows\TEMP\BearSharePreview\PVWF9.tmp 0 bytes
c:\windows\TEMP\BearSharePreview\PVWF9.tmp.asf 512000 bytes
c:\windows\TEMP\BearSharePreview\PVWFA.tmp 0 bytes
c:\windows\TEMP\BearSharePreview\PVWFA.tmp.asf 512000 bytes
c:\windows\TEMP\BearSharePreview\PVWFB.tmp 0 bytes
c:\windows\TEMP\BearSharePreview\PVWFB.tmp.asf 512000 bytes
c:\windows\TEMP\BearSharePreview\PVWFC.tmp 0 bytes
c:\windows\TEMP\BearSharePreview\PVWFC.tmp.asf 512000 bytes
c:\windows\TEMP\BearSharePreview\PVWFD.tmp 0 bytes
c:\windows\TEMP\BearSharePreview\PVWFD.tmp.asf 512000 bytes
c:\windows\TEMP\BearSharePreview\PVWFE.tmp 0 bytes
c:\windows\TEMP\BearSharePreview\PVWFE.tmp.asf 512000 bytes
c:\windows\TEMP\BearSharePreview\PVW9E.tmp 0 bytes
c:\windows\TEMP\BearSharePreview\PVW9E.tmp.mp3 512000 bytes
c:\windows\TEMP\BearSharePreview\PVW9F.tmp 0 bytes
c:\windows\TEMP\BearSharePreview\PVW9F.tmp.mp3 512000 bytes
c:\windows\TEMP\BearSharePreview\PVWA0.tmp 0 bytes
c:\windows\TEMP\BearSharePreview\PVWA0.tmp.mp3 294912 bytes
c:\windows\TEMP\BearSharePreview\PVWA1.tmp 0 bytes
c:\windows\TEMP\BearSharePreview\PVWA1.tmp.mp3 512000 bytes
c:\windows\TEMP\BearSharePreview\PVWA2.tmp 0 bytes
c:\windows\TEMP\BearSharePreview\PVWA2.tmp.mp3 512000 bytes
c:\windows\TEMP\BearSharePreview\PVWA3.tmp 0 bytes
c:\windows\TEMP\BearSharePreview\PVWA3.tmp.mp3 516224 bytes
c:\windows\TEMP\BearSharePreview\PVW81.tmp 0 bytes
c:\windows\TEMP\BearSharePreview\PVW81.tmp.wma 0 bytes
c:\windows\TEMP\BearSharePreview\PVW82.tmp 0 bytes
c:\windows\TEMP\BearSharePreview\PVW82.tmp.MP3 512000 bytes
c:\windows\TEMP\BearSharePreview\PVW83.tmp 0 bytes
c:\windows\TEMP\BearSharePreview\PVW83.tmp.mp3 294912 bytes
c:\windows\TEMP\BearSharePreview\PVW84.tmp 0 bytes
c:\windows\TEMP\BearSharePreview\PVW84.tmp.mp3 512000 bytes
c:\windows\TEMP\BearSharePreview\PVW85.tmp 0 bytes
c:\windows\TEMP\BearSharePreview\PVW85.tmp.MP3 512000 bytes
c:\windows\TEMP\BearSharePreview\PVW86.tmp 0 bytes
c:\windows\TEMP\BearSharePreview\PVW86.tmp.avi 512000 bytes
c:\windows\TEMP\BearSharePreview\PVW96.tmp.mp3 512000 bytes
c:\windows\TEMP\BearSharePreview\PVW97.tmp 0 bytes
c:\windows\TEMP\BearSharePreview\PVW97.tmp.mp3 512000 bytes
c:\windows\TEMP\BearSharePreview\PVW98.tmp 0 bytes
c:\windows\TEMP\BearSharePreview\PVW98.tmp.mp3 512000 bytes
c:\windows\TEMP\BearSharePreview\PVW99.tmp 0 bytes
c:\windows\TEMP\BearSharePreview\PVW99.tmp.mp3 512000 bytes
c:\windows\TEMP\BearSharePreview\PVW9A.tmp 0 bytes
c:\windows\TEMP\BearSharePreview\PVW9A.tmp.mp3 0 bytes
c:\windows\TEMP\BearSharePreview\PVW9B.tmp 0 bytes
c:\windows\TEMP\BearSharePreview\PVW9B.tmp.mp3 512000 bytes
c:\windows\TEMP\BearSharePreview\PVW9C.tmp 0 bytes
c:\windows\TEMP\BearSharePreview\PVW9C.tmp.mp3 512000 bytes
c:\windows\TEMP\BearSharePreview\PVW9D.tmp 0 bytes
c:\windows\TEMP\BearSharePreview\PVW9D.tmp.mp3 512000 bytes
c:\windows\TEMP\BearSharePreview\PVWA4.tmp.mp3 516224 bytes
c:\windows\TEMP\BearSharePreview\PVWA5.tmp 0 bytes
c:\windows\TEMP\BearSharePreview\PVWA5.tmp.mp3 516224 bytes
c:\windows\TEMP\BearSharePreview\PVWA6.tmp 0 bytes
c:\windows\TEMP\BearSharePreview\PVWA6.tmp.mp3 516224 bytes
c:\windows\TEMP\BearSharePreview\PVWA7.tmp 0 bytes
c:\windows\TEMP\BearSharePreview\PVWA7.tmp.mp3 512000 bytes
c:\windows\TEMP\BearSharePreview\PVWA8.tmp 0 bytes
c:\windows\TEMP\BearSharePreview\PVWA8.tmp.mp3 512000 bytes
c:\windows\TEMP\BearSharePreview\PVWA9.tmp 0 bytes
c:\windows\TEMP\BearSharePreview\PVWA9.tmp.mp3 512000 bytes
c:\windows\TEMP\BearSharePreview\PVWAA.tmp 0 bytes
c:\windows\TEMP\BearSharePreview\PVWAB.tmp 0 bytes
c:\windows\TEMP\BearSharePreview\PVWAB.tmp.mp3 512000 bytes
c:\windows\TEMP\BearSharePreview\PVWAC.tmp 0 bytes
c:\windows\TEMP\BearSharePreview\PVWAC.tmp.mp3 512000 bytes
c:\windows\TEMP\BearSharePreview\PVWAD.tmp 0 bytes
c:\windows\TEMP\BearSharePreview\PVWAD.tmp.mp3 512000 bytes
c:\windows\TEMP\BearSharePreview\PVWAE.tmp 0 bytes
c:\windows\TEMP\BearSharePreview\PVWAE.tmp.avi 512000 bytes
c:\windows\TEMP\BearSharePreview\PVWAF.tmp 0 bytes
c:\windows\TEMP\BearSharePreview\PVWAF.tmp.asf 512000 bytes
c:\windows\TEMP\BearSharePreview\PVWB.tmp 0 bytes
c:\windows\TEMP\BearSharePreview\PVWB.tmp.mp3 516224 bytes
c:\windows\TEMP\BearSharePreview\PVW30.tmp 0 bytes
c:\windows\TEMP\BearSharePreview\PVW30.tmp.asf 512000 bytes
c:\windows\TEMP\BearSharePreview\PVW31.tmp 0 bytes
c:\windows\TEMP\BearSharePreview\PVW31.tmp.asf 512000 bytes
c:\windows\TEMP\BearSharePreview\PVW32.tmp 0 bytes
c:\windows\TEMP\BearSharePreview\PVW32.tmp.asf 512000 bytes
c:\windows\TEMP\BearSharePreview\PVW33.tmp 0 bytes
c:\windows\TEMP\BearSharePreview\PVW33.tmp.asf 512000 bytes
c:\windows\TEMP\BearSharePreview\PVW34.tmp 0 bytes
c:\windows\TEMP\BearSharePreview\PVW34.tmp.mp3 0 bytes
c:\windows\TEMP\BearSharePreview\PVW6.tmp 0 bytes
c:\windows\TEMP\BearSharePreview\PVW6.tmp.asf 512000 bytes
c:\windows\TEMP\BearSharePreview\PVW60.tmp 0 bytes
c:\windows\TEMP\BearSharePreview\PVW60.tmp.asf 512000 bytes
c:\windows\TEMP\BearSharePreview\PVW62.tmp 0 bytes
c:\windows\TEMP\BearSharePreview\PVW62.tmp.wmv 512000 bytes
c:\windows\TEMP\BearSharePreview\PVW68.tmp 0 bytes
c:\windows\TEMP\BearSharePreview\PVW68.tmp.WMV 512000 bytes
c:\windows\TEMP\BearSharePreview\PVW69.tmp 0 bytes
c:\windows\TEMP\BearSharePreview\PVW69.tmp.WMV 512000 bytes
c:\windows\TEMP\BearSharePreview\PVW6A.tmp 0 bytes
c:\windows\TEMP\BearSharePreview\PVW6A.tmp.WMV 512000 bytes
c:\windows\TEMP\BearSharePreview\PVW6B.tmp 0 bytes
c:\windows\TEMP\BearSharePreview\PVW6B.tmp.mp3 327680 bytes
c:\windows\TEMP\BearSharePreview\PVW6C.tmp 0 bytes
c:\windows\TEMP\BearSharePreview\PVW6C.tmp.mp3 69760 bytes
c:\windows\TEMP\BearSharePreview\PVW6D.tmp 0 bytes
c:\windows\TEMP\BearSharePreview\PVW6D.tmp.mp3 0 bytes
c:\windows\TEMP\BearSharePreview\PVW6E.tmp 0 bytes
c:\windows\TEMP\BearSharePreview\PVW6E.tmp.mp3 229504 bytes
c:\windows\TEMP\BearSharePreview\PVW6F.tmp 0 bytes
c:\windows\TEMP\BearSharePreview\PVW87.tmp.WMV 512000 bytes
c:\windows\TEMP\BearSharePreview\PVW88.tmp 0 bytes
c:\windows\TEMP\BearSharePreview\PVW88.tmp.WMV 512000 bytes
c:\windows\TEMP\BearSharePreview\PVW89.tmp 0 bytes
c:\windows\TEMP\BearSharePreview\PVW89.tmp.WMV 512000 bytes
c:\windows\TEMP\BearSharePreview\PVW8A.tmp 0 bytes
c:\windows\TEMP\BearSharePreview\PVW8A.tmp.avi 512000 bytes
c:\windows\TEMP\BearSharePreview\PVW8B.tmp 0 bytes
c:\windows\TEMP\BearSharePreview\PVW8B.tmp.avi 512000 bytes
c:\windows\TEMP\BearSharePreview\PVW8C.tmp 0 bytes
c:\windows\TEMP\BearSharePreview\PVW8C.tmp.avi 512000 bytes
c:\windows\TEMP\BearSharePreview\PVW8D.tmp 0 bytes
c:\windows\TEMP\BearSharePreview\PVW8D.tmp.mp3 512000 bytes
c:\windows\TEMP\BearSharePreview\PVW91.tmp 0 bytes
c:\windows\TEMP\BearSharePreview\PVW91.tmp.avi 512000 bytes
c:\windows\TEMP\BearSharePreview\PVW92.tmp 0 bytes
c:\windows\TEMP\BearSharePreview\PVW92.tmp.WMV 512000 bytes
c:\windows\TEMP\BearSharePreview\PVW93.tmp 0 bytes
c:\windows\TEMP\BearSharePreview\PVW93.tmp.avi 512000 bytes
c:\windows\TEMP\BearSharePreview\PVW94.tmp 0 bytes
c:\windows\TEMP\BearSharePreview\PVW94.tmp.WMV 512000 bytes
c:\windows\TEMP\BearSharePreview\PVW95.tmp 0 bytes
c:\windows\TEMP\BearSharePreview\PVW95.tmp.wmv 512000 bytes
c:\windows\TEMP\BearSharePreview\PVWB0.tmp.avi 512000 bytes
c:\windows\TEMP\BearSharePreview\PVWB1.tmp 0 bytes
c:\windows\TEMP\BearSharePreview\PVWB1.tmp.asf 512000 bytes
c:\windows\TEMP\BearSharePreview\PVWB2.tmp 0 bytes
c:\windows\TEMP\BearSharePreview\PVWB2.tmp.avi 512000 bytes
c:\windows\TEMP\BearSharePreview\PVWB3.tmp 0 bytes
c:\windows\TEMP\BearSharePreview\PVWB3.tmp.avi 512000 bytes
c:\windows\TEMP\BearSharePreview\PVWB4.tmp 0 bytes
c:\windows\TEMP\BearSharePreview\PVWB4.tmp.asf 512000 bytes
c:\windows\TEMP\BearSharePreview\PVWB5.tmp 0 bytes
c:\windows\TEMP\BearSharePreview\PVWB5.tmp.avi 512000 bytes
c:\windows\TEMP\BearSharePreview\PVWB6.tmp 0 bytes
c:\windows\TEMP\BearSharePreview\PVWB6.tmp.avi 512000 bytes
c:\windows\TEMP\BearSharePreview\PVWB7.tmp 0 bytes
c:\windows\TEMP\BearSharePreview\PVWB8.tmp 0 bytes
c:\windows\TEMP\BearSharePreview\PVWB8.tmp.avi 512000 bytes
c:\windows\TEMP\BearSharePreview\PVWB9.tmp 0 bytes
c:\windows\TEMP\BearSharePreview\PVWB9.tmp.asf 512000 bytes
c:\windows\TEMP\BearSharePreview\PVWBA.tmp 0 bytes
c:\windows\TEMP\BearSharePreview\PVWBA.tmp.avi 512000 bytes
c:\windows\TEMP\BearSharePreview\PVWBB.tmp 0 bytes
c:\windows\TEMP\BearSharePreview\PVWBB.tmp.avi 512000 bytes
c:\windows\TEMP\BearSharePreview\PVWBC.tmp 0 bytes
c:\windows\TEMP\BearSharePreview\PVWBC.tmp.avi 512000 bytes
c:\windows\TEMP\BearSharePreview\PVWBD.tmp 0 bytes
c:\windows\TEMP\BearSharePreview\PVWBD.tmp.asf 512000 bytes
c:\windows\TEMP\BearSharePreview\PVW1D.tmp 0 bytes
c:\windows\TEMP\BearSharePreview\PVW1D.tmp.avi 512000 bytes
c:\windows\TEMP\BearSharePreview\PVW2.tmp 0 bytes
c:\windows\TEMP\BearSharePreview\PVW2.tmp.mp3 516224 bytes
c:\windows\TEMP\BearSharePreview\PVW20.tmp 0 bytes
c:\windows\TEMP\BearSharePreview\PVW20.tmp.avi 512000 bytes
c:\windows\TEMP\BearSharePreview\PVW21.tmp 0 bytes
c:\windows\TEMP\BearSharePreview\PVW21.tmp.wmv 512000 bytes
c:\windows\TEMP\BearSharePreview\PVW216.tmp 0 bytes
c:\windows\TEMP\BearSharePreview\PVW216.tmp.mp3 0 bytes
c:\windows\TEMP\BearSharePreview\PVW217.tmp 0 bytes
c:\windows\TEMP\BearSharePreview\PVW217.tmp.wma 98304 bytes
c:\windows\TEMP\BearSharePreview\PVW218.tmp 0 bytes
c:\windows\TEMP\BearSharePreview\PVW218.tmp.mp3 512000 bytes
c:\windows\TEMP\BearSharePreview\PVW219.tmp 0 bytes
c:\windows\TEMP\BearSharePreview\PVWBE.tmp 0 bytes
c:\windows\TEMP\BearSharePreview\PVWBE.tmp.avi 512000 bytes
c:\windows\TEMP\BearSharePreview\PVWBF.tmp 0 bytes
c:\windows\TEMP\BearSharePreview\PVWBF.tmp.avi 512000 bytes
c:\windows\TEMP\BearSharePreview\PVWC.tmp 0 bytes
c:\windows\TEMP\BearSharePreview\PVWC.tmp.asf 512000 bytes
c:\windows\TEMP\BearSharePreview\PVWC2.tmp 0 bytes
c:\windows\TEMP\BearSharePreview\PVWC2.tmp.avi 512000 bytes
c:\windows\TEMP\BearSharePreview\PVWC3.tmp 0 bytes
c:\windows\TEMP\BearSharePreview\PVWC3.tmp.avi 512000 bytes
c:\windows\TEMP\BearSharePreview\PVWD1.tmp 0 bytes
c:\windows\TEMP\BearSharePreview\PVWD1.tmp.wmv 512000 bytes
c:\windows\TEMP\BearSharePreview\PVWD3.tmp 0 bytes
c:\windows\TEMP\BearSharePreview\PVWD3.tmp.asf 512000 bytes
c:\windows\TEMP\BearSharePreview\PVWE.tmp 0 bytes
c:\windows\TEMP\BearSharePreview\PVWE.tmp.mp3 0 bytes
c:\windows\TEMP\BearSharePreview\PVWE7.tmp 0 bytes
c:\windows\TEMP\BearSharePreview\PVWE7.tmp.mp3 327808 bytes
c:\windows\TEMP\BearSharePreview\PVWE9.tmp 0 bytes
c:\windows\TEMP\imvcache
c:\windows\TEMP\imvcache\airtel
c:\windows\TEMP\imvcache\airtel\airtel.imv 8268 bytes
c:\windows\TEMP\imvcache\airtel\AirtelIMV_21apr09.swf 294762 bytes
c:\windows\TEMP\imvcache\fivestar
c:\windows\TEMP\imvcache\fivestar\fivestar.imv 9780 bytes
c:\windows\TEMP\imvcache\fivestar\fivestar.swf 871696 bytes
c:\windows\TEMP\imvcache\insonye
c:\windows\TEMP\imvcache\insonye\insonye.imv 9048 bytes
c:\windows\TEMP\imvcache\insonye\sonyericsson.swf 108504 bytes
c:\windows\TEMP\imvcache\lg
c:\windows\TEMP\imvcache\lg\lg.imv 8548 bytes
c:\windows\TEMP\imvcache\lg\lg.swf 472658 bytes
c:\windows\TEMP\imvcache\lipton
c:\windows\TEMP\imvcache\lipton\lipton.imv 8216 bytes
c:\windows\TEMP\imvcache\lipton\lipton.swf 147364 bytes
c:\windows\TEMP\imvcache\maruti
c:\windows\TEMP\imvcache\maruti\maruti.imv 8148 bytes
c:\windows\TEMP\imvcache\maruti\maruti.swf 476076 bytes
c:\windows\TEMP\imvcache\maruti\maruti_IMV.swf 476024 bytes
c:\windows\TEMP\imvcache\perk
c:\windows\TEMP\imvcache\perk\perk.imv 8296 bytes
c:\windows\TEMP\imvcache\perk\perk.swf 224521 bytes
c:\windows\TEMP\imvcache\reebok
c:\windows\TEMP\imvcache\reebok\reebok.imv 8244 bytes
c:\windows\TEMP\imvcache\reebok\reebok.swf 200066 bytes
c:\windows\TEMP\iss2.tmp
c:\windows\TEMP\iss6C.tmp
c:\windows\TEMP\iss6F.tmp
c:\windows\TEMP\iss72.tmp
c:\windows\TEMP\iss75.tmp
c:\windows\TEMP\iss78.tmp
c:\windows\TEMP\iss7B.tmp
c:\windows\TEMP\OneNoteRuntimeCache
c:\windows\TEMP\OneNoteRuntimeCache\OneNoteRuntimeCache_Files
c:\windows\TEMP\dgm000 0 bytes
c:\windows\TEMP\Excel8.0
c:\windows\TEMP\Excel8.0\MSForms.exd 225928 bytes
c:\windows\TEMP\Excel8.0\ShockwaveFlashObjects.exd 18400 bytes
c:\windows\TEMP\gaopdx000 0 bytes
c:\windows\TEMP\gxvxc000 0 bytes
c:\windows\TEMP\HpScan
c:\windows\TEMP\HpScan\hppscan16.tif 4598192 bytes
c:\windows\TEMP\HpScan\hppscan1.tif 4099397 bytes
c:\windows\TEMP\HpScan\hppscan10.tif 4858122 bytes
c:\windows\TEMP\HpScan\hppscan11.tif 3226714 bytes
c:\windows\TEMP\HpScan\hppscan12.tif 4014936 bytes
c:\windows\TEMP\HpScan\hppscan13.tif 4352334 bytes
c:\windows\TEMP\HpScan\hppscan14.tif 3981600 bytes
c:\windows\TEMP\HpScan\hppscan15.tif 4466328 bytes
c:\windows\TEMP\HpScan\hppscan17.tif 4120068 bytes
c:\windows\TEMP\HpScan\hppscan18.tif 3298239 bytes
c:\windows\TEMP\HpScan\hppscan19.tif 11829120 bytes
c:\windows\TEMP\HpScan\hppscan2.tif 4431491 bytes
c:\windows\TEMP\HpScan\hppscan20.tif 14777080 bytes
c:\windows\TEMP\HpScan\hppscan21.tif 8080320 bytes
c:\windows\TEMP\HpScan\hppscan22.tif 4097871 bytes
c:\windows\TEMP\HpScan\hppscan23.tif 3263341 bytes
c:\windows\TEMP\HpScan\hppscan24.tif 414863 bytes
c:\windows\TEMP\HpScan\hppscan25.tif 3197729 bytes
c:\windows\TEMP\HpScan\hppscan26.tif 643205 bytes
c:\windows\TEMP\HpScan\hppscan27.tif 3582857 bytes
c:\windows\TEMP\HpScan\hppscan28.tif 20022010 bytes
c:\windows\TEMP\HpScan\hppscan29.tif 339281 bytes
c:\windows\TEMP\HpScan\hppscan3.tif 3876918 bytes
c:\windows\TEMP\HpScan\hppscan30.tif 4700417 bytes
c:\windows\TEMP\HpScan\hppscan31.tif 4093054 bytes
c:\windows\TEMP\HpScan\hppscan32.tif 5289895 bytes
c:\windows\TEMP\HpScan\hppscan33.tif 4755259 bytes
c:\windows\TEMP\HpScan\hppscan4.tif 4538289 bytes
c:\windows\TEMP\HpScan\hppscan5.tif 5006565 bytes
c:\windows\TEMP\HpScan\hppscan6.tif 3988073 bytes
c:\windows\TEMP\HpScan\hppscan7.tif 5052573 bytes
c:\windows\TEMP\HpScan\hppscan8.tif 4568105 bytes
c:\windows\TEMP\HpScan\hppscan9.tif 5337388 bytes
c:\windows\TEMP\hsperfdata_newpc
c:\windows\TEMP\Perflib_Perfdata_a0c.dat 16384 bytes
c:\windows\TEMP\Perflib_Perfdata_a14.dat 16384 bytes
c:\windows\TEMP\Perflib_Perfdata_a34.dat 16384 bytes
c:\windows\TEMP\Perflib_Perfdata_a48.dat 16384 bytes
c:\windows\TEMP\Perflib_Perfdata_a5c.dat 16384 bytes
c:\windows\TEMP\Perflib_Perfdata_a94.dat 16384 bytes
c:\windows\TEMP\Perflib_Perfdata_ab8.dat 16384 bytes
c:\windows\TEMP\Perflib_Perfdata_ac4.dat 16384 bytes
c:\windows\TEMP\Perflib_Perfdata_ac8.dat 16384 bytes
c:\windows\TEMP\Perflib_Perfdata_b1c.dat 16384 bytes
c:\windows\TEMP\Perflib_Perfdata_b30.dat 16384 bytes
c:\windows\TEMP\Perflib_Perfdata_b50.dat 16384 bytes
c:\windows\TEMP\Perflib_Perfdata_b58.dat 16384 bytes
c:\windows\TEMP\Perflib_Perfdata_b5c.dat 16384 bytes
c:\windows\TEMP\Perflib_Perfdata_770.dat 16384 bytes
c:\windows\TEMP\Perflib_Perfdata_78.dat 16384 bytes
c:\windows\TEMP\Perflib_Perfdata_794.dat 16384 bytes
c:\windows\TEMP\Perflib_Perfdata_7cc.dat 16384 bytes
c:\windows\TEMP\Perflib_Perfdata_7d4.dat 16384 bytes
c:\windows\TEMP\Perflib_Perfdata_7e4.dat 16384 bytes
c:\windows\TEMP\Perflib_Perfdata_7f0.dat
c:\windows\TEMP\Perflib_Perfdata_80c.dat 16384 bytes
c:\windows\TEMP\Perflib_Perfdata_810.dat 16384 bytes
c:\windows\TEMP\Perflib_Perfdata_818.dat 16384 bytes
c:\windows\TEMP\Perflib_Perfdata_824.dat 16384 bytes
c:\windows\TEMP\Perflib_Perfdata_84c.dat 16384 bytes
c:\windows\TEMP\Perflib_Perfdata_854.dat 16384 bytes
c:\windows\TEMP\Perflib_Perfdata_858.dat 16384 bytes
c:\windows\TEMP\Perflib_Perfdata_bc0.dat 16384 bytes
c:\windows\TEMP\Perflib_Perfdata_c20.dat 16384 bytes
c:\windows\TEMP\Perflib_Perfdata_c34.dat 16384 bytes
c:\windows\TEMP\Perflib_Perfdata_c38.dat 16384 bytes
c:\windows\TEMP\Perflib_Perfdata_cc.dat 16384 bytes
c:\windows\TEMP\Perflib_Perfdata_d0.dat 16384 bytes
c:\windows\TEMP\Perflib_Perfdata_d8.dat 16384 bytes
c:\windows\TEMP\Perflib_Perfdata_d98.dat 16384 bytes
c:\windows\TEMP\Perflib_Perfdata_dd4.dat 16384 bytes
c:\windows\TEMP\Perflib_Perfdata_de8.dat 16384 bytes
c:\windows\TEMP\kungsf000 0 bytes
c:\windows\TEMP\msohtmlclip
c:\windows\TEMP\msohtmlclip1
c:\windows\TEMP\msohtmlclip1\01
c:\windows\TEMP\msohtmlclip1\01\clip_colorschememapping.xml 314 bytes
c:\windows\TEMP\msohtmlclip1\01\clip_themedata.thmx 3081 bytes
c:\windows\TEMP\msqpdx000 0 bytes
c:\windows\TEMP\OIS
c:\windows\TEMP\OIS\cacheFiles
c:\windows\TEMP\OIS\temp
c:\windows\TEMP\Perflib_Perfdata_898.dat 16384 bytes
c:\windows\TEMP\Perflib_Perfdata_8d4.dat 16384 bytes
c:\windows\TEMP\Perflib_Perfdata_8d8.dat 16384 bytes
c:\windows\TEMP\Perflib_Perfdata_8f0.dat 16384 bytes
c:\windows\TEMP\Perflib_Perfdata_8f8.dat 16384 bytes
c:\windows\TEMP\Perflib_Perfdata_90c.dat 16384 bytes
c:\windows\TEMP\Perflib_Perfdata_94c.dat 16384 bytes
c:\windows\TEMP\Perflib_Perfdata_950.dat 16384 bytes
c:\windows\TEMP\Perflib_Perfdata_954.dat 16384 bytes
c:\windows\TEMP\Perflib_Perfdata_974.dat 16384 bytes
c:\windows\TEMP\Perflib_Perfdata_97c.dat 16384 bytes
c:\windows\TEMP\Perflib_Perfdata_9a0.dat 16384 bytes
c:\windows\TEMP\Perflib_Perfdata_9e8.dat 16384 bytes
c:\windows\TEMP\Perflib_Perfdata_9f4.dat 16384 bytes
c:\windows\TEMP\WERac2f.dir00
c:\windows\TEMP\WERac2f.dir00\appcompat.txt 89174 bytes
c:\windows\TEMP\WERac2f.dir00\INST.EXE.hdmp 5733776 bytes
c:\windows\TEMP\WERac2f.dir00\INST.EXE.mdmp 86678 bytes
c:\windows\TEMP\WEReb89.dir00
c:\windows\TEMP\WEReb89.dir00\IEXPLORE.EXE.hdmp 298315086 bytes
c:\windows\TEMP\WEReb89.dir00\IEXPLORE.EXE.mdmp 115388 bytes
c:\windows\TEMP\WERf198.dir00
c:\windows\TEMP\WERf198.dir00\mplayerc.exe.mdmp 0 bytes
c:\windows\TEMP\Winamp.tmp 0 bytes
c:\windows\TEMP\WT1.tmp 367112 bytes
c:\windows\TEMP\WT11B.tmp 367112 bytes
c:\windows\TEMP\WT11C.tmp 383140 bytes
c:\windows\TEMP\WT1C8.tmp 367112 bytes
c:\windows\TEMP\WT1C9.tmp 383140 bytes
c:\windows\TEMP\WT1F.tmp 367112 bytes
c:\windows\TEMP\WT2.tmp 383140 bytes
c:\windows\TEMP\WT20.tmp 383140 bytes
c:\windows\TEMP\WT2D.tmp 367112 bytes
c:\windows\TEMP\WT2E.tmp 383140 bytes
c:\windows\TEMP\WT31.tmp 367112 bytes
c:\windows\TEMP\WT32.tmp 383140 bytes
c:\windows\TEMP\WT34.tmp 367112 bytes
c:\windows\TEMP\WT35.tmp 383140 bytes
c:\windows\TEMP\WT3D.tmp 367112 bytes
c:\windows\TEMP\WT3E.tmp 383140 bytes
c:\windows\TEMP\WT43.tmp 367112 bytes
c:\windows\TEMP\WT44.tmp 383140 bytes
c:\windows\TEMP\WT4E.tmp 367112 bytes
c:\windows\TEMP\WT4F.tmp 383140 bytes
c:\windows\TEMP\WT54.tmp 367112 bytes
c:\windows\TEMP\WT55.tmp 383140 bytes
c:\windows\TEMP\uac000 0 bytes
c:\windows\TEMP\uttB.tmp 0 bytes
c:\windows\TEMP\uttB.tmp.exe 875768 bytes executable
c:\windows\TEMP\VBE
c:\windows\TEMP\VGX19C.tmp 2153 bytes
c:\windows\TEMP\VGX19D.tmp 2873 bytes
c:\windows\TEMP\VGX19E.tmp 6049 bytes
c:\windows\TEMP\VGX19F.tmp 31094 bytes
c:\windows\TEMP\VGX1A0.tmp 9778 bytes
c:\windows\TEMP\VGX1A1.tmp 7766 bytes
c:\windows\TEMP\VGX1A2.tmp 4007 bytes
c:\windows\TEMP\VGX1A3.tmp 10507 bytes
c:\windows\TEMP\VGX1A4.tmp 3369 bytes
c:\windows\TEMP\visit report1.jpg 102991 bytes
c:\windows\TEMP\visit report2.jpg 149408 bytes
c:\windows\TEMP\vlt2
c:\windows\TEMP\vlt2\default
c:\windows\TEMP\vlt2\default\credits.png 20039 bytes
c:\windows\TEMP\vlt2\default\equalizer.png 7566 bytes
c:\windows\TEMP\vlt2\default\font.otf 24700 bytes
c:\windows\TEMP\vlt2\default\main
c:\windows\TEMP\vlt2\default\main\dvd_menu.png 2869 bytes
c:\windows\TEMP\vlt2\default\main\dvd_nextchapter.png 2867 bytes
c:\windows\TEMP\vlt2\default\main\dvd_nexttitle.png 2852 bytes
c:\windows\TEMP\vlt2\default\main\dvd_prevchapter.png 2864 bytes
c:\windows\TEMP\vlt2\default\main\dvd_prevtitle.png 2854 bytes
c:\windows\TEMP\vlt2\default\main\main.png 5978 bytes
c:\windows\TEMP\vlt2\default\main\main_down.png 11276 bytes
c:\windows\TEMP\vlt2\default\main\main_over.png 14885 bytes
c:\windows\TEMP\vlt2\default\main\main_up.png 10792 bytes
c:\windows\TEMP\vlt2\default\main\pause_down.png 1549 bytes
c:\windows\TEMP\vlt2\default\main\pause_over.png 1747 bytes
c:\windows\TEMP\vlt2\default\main\pause_up.png 1447 bytes
c:\windows\TEMP\vlt2\default\main\timeslider.png 132 bytes
c:\windows\TEMP\vlt2\default\main\vol_bg.png 7912 bytes
c:\windows\TEMP\vlt2\default\main\vol_mask.png 1020 bytes
c:\windows\TEMP\vlt2\default\main\vol_slider.png 180 bytes
c:\windows\TEMP\vlt2\default\minimal.png 1456 bytes
c:\windows\TEMP\vlt2\default\playlist
c:\windows\TEMP\vlt2\default\playlist\playlist.png 2603 bytes
c:\windows\TEMP\vlt2\default\playlist\playlist_down.png 4952 bytes
c:\windows\TEMP\vlt2\default\playlist\playlist_over.png 8068 bytes
c:\windows\TEMP\vlt2\default\playlist\playlist_up.png 5452 bytes
c:\windows\TEMP\vlt2\default\playlist\playtreeglyphs.png 181 bytes
c:\windows\TEMP\vlt2\default\playlist\plscroller.png 132 bytes
c:\windows\TEMP\vlt2\default\switch.png 687 bytes
c:\windows\TEMP\vlt2\default\theme.xml 34959 bytes
c:\windows\TEMP\vlt3
c:\windows\TEMP\vlt3\default
c:\windows\TEMP\vlt3\default\credits.png 20039 bytes
c:\windows\TEMP\vlt3\default\equalizer.png 7566 bytes
c:\windows\TEMP\vlt3\default\font.otf 24700 bytes
c:\windows\TEMP\vlt3\default\main
c:\windows\TEMP\vlt3\default\main\dvd_menu.png 2869 bytes
c:\windows\TEMP\vlt3\default\main\dvd_nextchapter.png 2867 bytes
c:\windows\TEMP\vlt3\default\main\dvd_nexttitle.png 2852 bytes
c:\windows\TEMP\vlt3\default\main\dvd_prevchapter.png 2864 bytes
c:\windows\TEMP\vlt3\default\main\dvd_prevtitle.png 2854 bytes
c:\windows\TEMP\vlt3\default\main\main.png 5978 bytes
c:\windows\TEMP\vlt3\default\main\main_down.png 11276 bytes
c:\windows\TEMP\vlt3\default\main\main_over.png 14885 bytes
c:\windows\TEMP\vlt3\default\main\main_up.png 10792 bytes
c:\windows\TEMP\vlt3\default\main\pause_down.png 1549 bytes
c:\windows\TEMP\vlt3\default\main\pause_over.png 1747 bytes
c:\windows\TEMP\vlt3\default\main\pause_up.png 1447 bytes
c:\windows\TEMP\vlt3\default\main\timeslider.png 132 bytes
c:\windows\TEMP\vlt3\default\main\vol_bg.png 7912 bytes
c:\windows\TEMP\vlt3\default\main\vol_mask.png 1020 bytes
c:\windows\TEMP\vlt3\default\main\vol_slider.png 180 bytes
c:\windows\TEMP\vlt3\default\minimal.png 1456 bytes
c:\windows\TEMP\vlt3\default\playlist
c:\windows\TEMP\vlt3\default\playlist\playlist.png 2603 bytes
c:\windows\TEMP\vlt3\default\playlist\playlist_down.png 4952 bytes
c:\windows\TEMP\vlt3\default\playlist\playlist_over.png 8068 bytes
c:\windows\TEMP\vlt3\default\playlist\playlist_up.png 5452 bytes
c:\windows\TEMP\vlt3\default\playlist\playtreeglyphs.png 181 bytes
c:\windows\TEMP\vlt3\default\playlist\plscroller.png 132 bytes
c:\windows\TEMP\vlt3\default\switch.png 687 bytes
c:\windows\TEMP\vlt3\default\theme.xml 34959 bytes
c:\windows\TEMP\vlt4
c:\windows\TEMP\vlt4\default
c:\windows\TEMP\vlt4\default\credits.png 20039 bytes
c:\windows\TEMP\vlt4\default\equalizer.png 7566 bytes
c:\windows\TEMP\vlt4\default\font.otf 24700 bytes
c:\windows\TEMP\vlt4\default\main
c:\windows\TEMP\vlt4\default\main\dvd_menu.png 2869 bytes
c:\windows\TEMP\vlt4\default\main\dvd_nextchapter.png 2867 bytes
c:\windows\TEMP\vlt4\default\main\dvd_nexttitle.png 2852 bytes
c:\windows\TEMP\vlt4\default\main\dvd_prevchapter.png 2864 bytes
c:\windows\TEMP\vlt4\default\main\dvd_prevtitle.png 2854 bytes
c:\windows\TEMP\vlt4\default\main\main.png 5978 bytes
c:\windows\TEMP\vlt4\default\main\main_down.png 11276 bytes
c:\windows\TEMP\vlt4\default\main\main_over.png 14885 bytes
c:\windows\TEMP\vlt4\default\main\main_up.png 10792 bytes
c:\windows\TEMP\vlt4\default\main\pause_down.png 1549 bytes
c:\windows\TEMP\vlt4\default\main\pause_over.png 1747 bytes
c:\windows\TEMP\vlt4\default\main\pause_up.png 1447 bytes
c:\windows\TEMP\vlt4\default\main\timeslider.png 132 bytes
c:\windows\TEMP\vlt4\default\main\vol_bg.png 7912 bytes
c:\windows\TEMP\vlt4\default\main\vol_mask.png 1020 bytes
c:\windows\TEMP\vlt4\default\main\vol_slider.png 180 bytes
c:\windows\TEMP\vlt4\default\minimal.png 1456 bytes
c:\windows\TEMP\vlt4\default\playlist
c:\windows\TEMP\vlt4\default\playlist\playlist.png 2603 bytes
c:\windows\TEMP\vlt4\default\playlist\playlist_down.png 4952 bytes
c:\windows\TEMP\vlt4\default\playlist\playlist_over.png 8068 bytes
c:\windows\TEMP\vlt4\default\playlist\playlist_up.png 5452 bytes
c:\windows\TEMP\vlt4\default\playlist\playtreeglyphs.png 181 bytes
c:\windows\TEMP\vlt4\default\playlist\plscroller.png 132 bytes
c:\windows\TEMP\vlt4\default\switch.png 687 bytes
c:\windows\TEMP\vlt4\default\theme.xml 34959 bytes
c:\windows\TEMP\vsfoce000 0 bytes
c:\windows\TEMP\WER0f6f.dir00
c:\windows\TEMP\WER0f6f.dir00\mplayerc.exe.mdmp 0 bytes
c:\windows\TEMP\WER259a.dir00
c:\windows\TEMP\WER259a.dir00\explorer.exe.hdmp 0 bytes
c:\windows\TEMP\WER259a.dir00\explorer.exe.mdmp 91626 bytes
c:\windows\TEMP\WER2931.dir00
c:\windows\TEMP\WER2931.dir00\explorer.exe.hdmp 0 bytes
c:\windows\TEMP\WER2931.dir00\explorer.exe.mdmp 91626 bytes
c:\windows\TEMP\WER2b5a.dir00
c:\windows\TEMP\WER2b5a.dir00\explorer.exe.hdmp 0 bytes
c:\windows\TEMP\WER2b5a.dir00\explorer.exe.mdmp 91626 bytes
c:\windows\TEMP\WER2d7c.dir00
c:\windows\TEMP\WER2d7c.dir00\appcompat.txt 177978 bytes
c:\windows\TEMP\WER2d7c.dir00\WINWORD.EXE.hdmp 14111938 bytes
c:\windows\TEMP\WER2d7c.dir00\WINWORD.EXE.mdmp 75937 bytes
c:\windows\TEMP\ovfsth000 0 bytes
c:\windows\TEMP\ymsgr5 1489 bytes
c:\windows\TEMP\ymsgr6 10399 bytes
c:\windows\TEMP\ymsgr7 10399 bytes
c:\windows\TEMP\ymsgr8 1395 bytes
c:\windows\TEMP\ymsgr9 1401 bytes
c:\windows\TEMP\ypt19.tmp 0 bytes
c:\windows\TEMP\ytasfw000 0 bytes
c:\windows\TEMP\ytb_7.2.4.4_1.6.5_ysp_1.2.7_mail_bts_pub_us_setup_.exe 3021880 bytes executable
c:\windows\TEMP\~DF11E8.tmp 16384 bytes
c:\windows\TEMP\~DF1219.tmp 16384 bytes
c:\windows\TEMP\~DF143C.tmp 16384 bytes
c:\windows\TEMP\~DF15A1.tmp 49152 bytes
c:\windows\TEMP\~DF1BD6.tmp 16384 bytes
c:\windows\TEMP\~DF1BDD.tmp 16384 bytes
c:\windows\TEMP\~DF1D6C.tmp 16384 bytes
c:\windows\TEMP\~DF1DED.tmp 16384 bytes
c:\windows\TEMP\~DF207.tmp 16384 bytes
c:\windows\TEMP\~DF2192.tmp 16384 bytes
c:\windows\TEMP\~DF2A24.tmp 16384 bytes
c:\windows\TEMP\~DF2F8C.tmp 16384 bytes
c:\windows\TEMP\~DF302C.tmp 16384 bytes
c:\windows\TEMP\~DF37F5.tmp 16384 bytes
c:\windows\TEMP\~DF394C.tmp 16384 bytes
c:\windows\TEMP\~DF396E.tmp 16384 bytes
c:\windows\TEMP\~DF3F47.tmp 16384 bytes
c:\windows\TEMP\~DF40F4.tmp 16384 bytes
c:\windows\TEMP\~DF46BB.tmp 16384 bytes
c:\windows\TEMP\~DF4CF2.tmp 16384 bytes
c:\windows\TEMP\~DF4EF9.tmp 16384 bytes
c:\windows\TEMP\~DF4FF9.tmp 16384 bytes
c:\windows\TEMP\~DF500E.tmp 16384 bytes
c:\windows\TEMP\~DF511F.tmp 16384 bytes
c:\windows\TEMP\[MONOVA.ORG] Pure Indian Hardcore with Hindi dialouges.torrent 18913 bytes
c:\windows\TEMP\_avast4_
c:\windows\TEMP\~DF8C26.tmp 16384 bytes
c:\windows\TEMP\~DF923B.tmp 16384 bytes
c:\windows\TEMP\~DF99B3.tmp 16384 bytes
c:\windows\TEMP\~DF9A14.tmp 16384 bytes
c:\windows\TEMP\~DF9B74.tmp 16384 bytes
c:\windows\TEMP\~DF9C08.tmp 16384 bytes
c:\windows\TEMP\~DF9CC4.tmp 16384 bytes
c:\windows\TEMP\~DF9D1.tmp 16384 bytes
c:\windows\TEMP\~DF9ED3.tmp 16384 bytes
c:\windows\TEMP\~DFA1D1.tmp 16384 bytes
c:\windows\TEMP\~DFA4B1.tmp 16384 bytes
c:\windows\TEMP\~DFA607.tmp 16384 bytes
c:\windows\TEMP\~DFABAA.tmp 16384 bytes
c:\windows\TEMP\~DFABEE.tmp 16384 bytes
c:\windows\TEMP\~DFAFAC.tmp 16384 bytes
c:\windows\TEMP\~DFB2EB.tmp 16384 bytes
c:\windows\TEMP\~DFB449.tmp 16384 bytes
c:\windows\TEMP\~DFB470.tmp 16384 bytes
c:\windows\TEMP\~DFB6C4.tmp 16384 bytes
c:\windows\TEMP\~DFB7EA.tmp 16384 bytes
c:\windows\TEMP\~DFBC31.tmp 16384 bytes
c:\windows\TEMP\~DFBD89.tmp 16384 bytes
c:\windows\TEMP\~DFBE99.tmp 16384 bytes
c:\windows\TEMP\~DFC136.tmp 16384 bytes
c:\windows\TEMP\~DFC164.tmp 16384 bytes
c:\windows\TEMP\~DFC467.tmp 16384 bytes
c:\windows\TEMP\~DFC48D.tmp 16384 bytes
c:\windows\TEMP\~DFC6A.tmp 16384 bytes
c:\windows\TEMP\~DFC803.tmp 16384 bytes
c:\windows\TEMP\~DFCA12.tmp 16384 bytes
c:\windows\TEMP\~DFCA15.tmp 16384 bytes
c:\windows\TEMP\WER33c7.dir00
c:\windows\TEMP\WER33c7.dir00\OUTLOOK.EXE.hdmp 0 bytes
c:\windows\TEMP\WER33c7.dir00\OUTLOOK.EXE.mdmp 1145979 bytes
c:\windows\TEMP\WER3495.dir00
c:\windows\TEMP\WER3495.dir00\OUTLOOK.EXE.hdmp 0 bytes
c:\windows\TEMP\WER3495.dir00\OUTLOOK.EXE.mdmp 1145979 bytes
c:\windows\TEMP\WER59d8.dir00
c:\windows\TEMP\WER59d8.dir00\OUTLOOK.EXE.hdmp 0 bytes
c:\windows\TEMP\WER59d8.dir00\OUTLOOK.EXE.mdmp 1145979 bytes
c:\windows\TEMP\WER6a62.dir00
c:\windows\TEMP\WER6a62.dir00\IEXPLORE.EXE.hdmp 226049599 bytes
c:\windows\TEMP\WER6a62.dir00\IEXPLORE.EXE.mdmp 106679 bytes
c:\windows\TEMP\WER6aba.dir00
c:\windows\TEMP\WER6aba.dir00\IEXPLORE.EXE.hdmp 226479679 bytes
c:\windows\TEMP\WER6aba.dir00\IEXPLORE.EXE.mdmp 106679 bytes
c:\windows\TEMP\WER705e.dir00
c:\windows\TEMP\WER705e.dir00\appcompat.txt 89174 bytes
c:\windows\TEMP\WER705e.dir00\INST.EXE.hdmp 5733776 bytes
c:\windows\TEMP\WER705e.dir00\INST.EXE.mdmp 86678 bytes
c:\windows\TEMP\pf1226346002.tmp 661797 bytes
c:\windows\TEMP\pf1858234708.tmp 532666 bytes
c:\windows\TEMP\pf1894800003.tmp 628422 bytes
c:\windows\TEMP\pf2284637872.tmp 616128 bytes
c:\windows\TEMP\pf2382493909.tmp 640372 bytes
c:\windows\TEMP\pf2995309035.tmp 500492 bytes
c:\windows\TEMP\pf3218919180.tmp 742699 bytes
c:\windows\TEMP\pf3427971782.tmp 521721 bytes
c:\windows\TEMP\pf3777717265.tmp 224807 bytes
c:\windows\TEMP\pf3787109626.tmp 978488 bytes
c:\windows\TEMP\pf3906418700.tmp 10198043 bytes
c:\windows\TEMP\pf4089028237.tmp 661973 bytes
c:\windows\TEMP\pf4161753597.tmp 666024 bytes
c:\windows\TEMP\pf4163226486.tmp 481049 bytes
c:\windows\TEMP\pf522065160.tmp 395297 bytes
c:\windows\TEMP\pf568598118.tmp 296583 bytes
c:\windows\TEMP\pf742013625.tmp 663708 bytes
c:\windows\TEMP\pf884140734.tmp 297520 bytes
c:\windows\TEMP\pf99373734.tmp 689710 bytes
c:\windows\TEMP\seneka000 0 bytes
c:\windows\TEMP\skynet000 0 bytes
c:\windows\TEMP\tata21.jpg 95127 bytes
c:\windows\TEMP\tdss000 0 bytes
c:\windows\TEMP\track1.wav 652671224 bytes
c:\windows\TEMP\TWAIN.LOG 3957 bytes
c:\windows\TEMP\Twain001.Mtx 5 bytes
c:\windows\TEMP\Twunk001.MTX 156 bytes
c:\windows\TEMP\~DFCBDE.tmp 16384 bytes
c:\windows\TEMP\~DFD217.tmp 16384 bytes
c:\windows\TEMP\~DFD3D2.tmp 16384 bytes
c:\windows\TEMP\~DFD4F4.tmp 16384 bytes
c:\windows\TEMP\~DFD6E2.tmp 16384 bytes
c:\windows\TEMP\~DFD8C6.tmp 16384 bytes
c:\windows\TEMP\~DFD9EA.tmp 16384 bytes
c:\windows\TEMP\~DFDC26.tmp 16384 bytes
c:\windows\TEMP\~DFDE36.tmp 16384 bytes
c:\windows\TEMP\~DFDFAF.tmp 16384 bytes
c:\windows\TEMP\~DFE40.tmp 16384 bytes
c:\windows\TEMP\~DFE536.tmp 16384 bytes
c:\windows\TEMP\~DFEA9B.tmp 16384 bytes
c:\windows\TEMP\~DFED90.tmp 16384 bytes
c:\windows\TEMP\~DFF12F.tmp 16384 bytes
c:\windows\TEMP\~DFF172.tmp 16384 bytes
c:\windows\TEMP\~DFF275.tmp 16384 bytes
c:\windows\TEMP\~DFF33B.tmp 16384 bytes
c:\windows\TEMP\~DFF676.tmp 16384 bytes
c:\windows\TEMP\~DFF84C.tmp 16384 bytes
c:\windows\TEMP\~DFFD19.tmp 16384 bytes
c:\windows\TEMP\~DFFE8C.tmp 16384 bytes
c:\windows\TEMP\~nsu.tmp
c:\windows\TEMP\~tm3E.tmp 986612 bytes
c:\windows\TEMP\~DF5224.tmp 16384 bytes
c:\windows\TEMP\~DF55.tmp 0 bytes
c:\windows\TEMP\~DF56FD.tmp 16384 bytes
c:\windows\TEMP\~DF57FF.tmp 16384 bytes
c:\windows\TEMP\~DF5CCF.tmp 16384 bytes
c:\windows\TEMP\~DF60FA.tmp 16384 bytes
c:\windows\TEMP\~DF621B.tmp 16384 bytes
c:\windows\TEMP\~DF6266.tmp 16384 bytes
c:\windows\TEMP\~DF633F.tmp 16384 bytes
c:\windows\TEMP\~DF647A.tmp 16384 bytes
c:\windows\TEMP\~DF64B2.tmp 16384 bytes
c:\windows\TEMP\~DF6A1B.tmp 16384 bytes
c:\windows\TEMP\~DF6D24.tmp 16384 bytes
c:\windows\TEMP\~DF6E94.tmp 16384 bytes
c:\windows\TEMP\~DF70B8.tmp 16384 bytes
c:\windows\TEMP\~DF711B.tmp 16384 bytes
c:\windows\TEMP\~DF722.tmp 16384 bytes
c:\windows\TEMP\~DF7501.tmp 16384 bytes
c:\windows\TEMP\~DF7737.tmp 16384 bytes
c:\windows\TEMP\~DF782A.tmp 16384 bytes
c:\windows\TEMP\~DF7998.tmp 16384 bytes
c:\windows\TEMP\~DF7E38.tmp 16384 bytes
c:\windows\TEMP\~DF7E75.tmp 16384 bytes
c:\windows\TEMP\~DF8067.tmp 16384 bytes
c:\windows\TEMP\~DF80AF.tmp 16384 bytes
c:\windows\TEMP\~DF8158.tmp 81920 bytes
c:\windows\TEMP\~DF8420.tmp 16384 bytes
c:\windows\TEMP\~DF85D0.tmp 16384 bytes
c:\windows\TEMP\~DF8725.tmp 16384 bytes
c:\windows\TEMP\~DF8944.tmp 16384 bytes
c:\windows\TEMP\WT57.tmp 383140 bytes
c:\windows\TEMP\WT58.tmp 367112 bytes
c:\windows\TEMP\WT59.tmp 383140 bytes
c:\windows\TEMP\WT78.tmp 367112 bytes
c:\windows\TEMP\WT79.tmp 383140 bytes
c:\windows\TEMP\WT7A.tmp 367112 bytes
c:\windows\TEMP\WT7B.tmp 383140 bytes
c:\windows\TEMP\WT85.tmp 367112 bytes
c:\windows\TEMP\WT86.tmp 383140 bytes
c:\windows\TEMP\WT87.tmp 367112 bytes
c:\windows\TEMP\WT88.tmp 383140 bytes
c:\windows\TEMP\WTD4.tmp 367112 bytes
c:\windows\TEMP\WTD5.tmp 383140 bytes
c:\windows\TEMP\WTF1.tmp 367112 bytes
c:\windows\TEMP\WTF2.tmp 383140 bytes
c:\windows\TEMP\wzszx000 0 bytes
c:\windows\TEMP\ycp19.tmp 57885 bytes
c:\windows\TEMP\ycp1A.tmp 57885 bytes
c:\windows\TEMP\ymsgr10 1489 bytes
c:\windows\TEMP\ymsgr2 1401 bytes
c:\windows\TEMP\ymsgr3 1489 bytes
c:\windows\TEMP\Perflib_Perfdata_870.dat 16384 bytes
c:\windows\TEMP\Perflib_Perfdata_9f8.dat 16384 bytes
c:\windows\TEMP\Perflib_Perfdata_b90.dat 16384 bytes
c:\windows\TEMP\runonce.ini 34 bytes
c:\windows\TEMP\Twunk002.MTX 0 bytes
c:\windows\TEMP\WER2e5a.dir00
c:\windows\TEMP\WER2e5a.dir00\explorer.exe.hdmp 0 bytes
c:\windows\TEMP\WER2e5a.dir00\explorer.exe.mdmp 91626 bytes
c:\windows\TEMP\WT56.tmp 367112 bytes
c:\windows\TEMP\ymsgr4 1401 bytes
c:\windows\TEMP\{4E461D88-B864-4B10-A1E8-69AA17542428} 629198 bytes
c:\windows\TEMP\~DF51B6.tmp 16384 bytes
c:\windows\TEMP\~DF8A49.tmp 16384 bytes
c:\windows\TEMP\~DFCB4E.tmp 16384 bytes
c:\windows\TEMP\WER787e.dir00
c:\windows\TEMP\WER787e.dir00\IEXPLORE.EXE.hdmp 298315086 bytes
c:\windows\TEMP\WER787e.dir00\IEXPLORE.EXE.mdmp 115388 bytes
c:\windows\TEMP\WER7aa0.dir00
c:\windows\TEMP\WER7aa0.dir00\appcompat.txt 177978 bytes
c:\windows\TEMP\WER7aa0.dir00\WINWORD.EXE.hdmp 14111938 bytes
c:\windows\TEMP\WER7aa0.dir00\WINWORD.EXE.mdmp 75937 bytes
c:\windows\TEMP\WER7e71.dir00
c:\windows\TEMP\WER7e71.dir00\vlc.exe.hdmp 0 bytes
c:\windows\TEMP\WER7e71.dir00\vlc.exe.mdmp 181446 bytes
c:\windows\TEMP\WER898a.dir00
c:\windows\TEMP\WER898a.dir00\OUTLOOK.EXE.hdmp 0 bytes
c:\windows\TEMP\WER898a.dir00\OUTLOOK.EXE.mdmp 1145979 bytes
c:\windows\TEMP\WER8f0e.dir00
c:\windows\TEMP\WER8f0e.dir00\OUTLOOK.EXE.hdmp 0 bytes
c:\windows\TEMP\WER8f0e.dir00\OUTLOOK.EXE.mdmp 1145979 bytes
c:\windows\TEMP\WER8f93.dir00
c:\windows\TEMP\WER8f93.dir00\appcompat.txt 89174 bytes
c:\windows\TEMP\WER8f93.dir00\INST.EXE.hdmp 5733776 bytes
c:\windows\TEMP\WER8f93.dir00\INST.EXE.mdmp 86678 bytes
c:\windows\TEMP\WER8fb4.dir00
c:\windows\TEMP\WER8fb4.dir00\appcompat.txt 89174 bytes
c:\windows\TEMP\WER8fb4.dir00\INST.EXE.hdmp 5733776 bytes
c:\windows\TEMP\WER8fb4.dir00\INST.EXE.mdmp 86678 bytes
c:\windows\TEMP\WER9e00.dir00
c:\windows\TEMP\WER9e00.dir00\appcompat.txt 16296 bytes
c:\windows\TEMP\WER9e00.dir00\manifest.txt 1656 bytes
c:\windows\TEMP\WER9e00.dir00\SearchIndexer.exe.hdmp 7413029 bytes
c:\windows\TEMP\WER9e00.dir00\SearchIndexer.exe.mdmp 92531 bytes
c:\windows\TEMP\WER9e71.dir00
c:\windows\TEMP\WER9e71.dir00\appcompat.txt 89174 bytes
c:\windows\TEMP\WER9e71.dir00\INST.EXE.hdmp 5733776 bytes
c:\windows\TEMP\WER9e71.dir00\INST.EXE.mdmp 86678 bytes
c:\windows\TEMP\WERa80f.dir00
c:\windows\TEMP\WERa80f.dir00\appcompat.txt 89174 bytes
c:\windows\TEMP\WERa80f.dir00\INST.EXE.hdmp 5733776 bytes
c:\windows\TEMP\WERa80f.dir00\INST.EXE.mdmp 86678 bytes
c:\windows\TEMP\plugtmp
c:\windows\TEMP\qFGCGv+g.pdf.part 80516 bytes
c:\windows\TEMP\QH0369.ins
c:\windows\TEMP\QH0369.ins\ACAPPAA.EXE 95608 bytes executable
c:\windows\TEMP\QH0369.ins\ACTIVATE.EXE 210296 bytes executable
c:\windows\TEMP\QH0369.ins\ACTXMOD.DLL 75128 bytes executable
c:\windows\TEMP\QH0369.ins\AMTEMP.ARJ 219 bytes
c:\windows\TEMP\QH0369.ins\ARJSDK.DLL 20480 bytes executable
c:\windows\TEMP\QH0369.ins\ARKIT.EXE 3094664 bytes executable
c:\windows\TEMP\QH0369.ins\ASAE_DLG.DLL 79224 bytes executable
c:\windows\TEMP\QH0369.ins\ASCLSRVC.EXE 79224 bytes executable
c:\windows\TEMP\QH0369.ins\ASCONFIG.DAT 65 bytes
c:\windows\TEMP\QH0369.ins\ASCONFIG.INI 90 bytes
c:\windows\TEMP\QH0369.ins\ASEXLENM.DLL 95608 bytes executable
c:\windows\TEMP\QH0369.ins\ASMAIN.EXE 116088 bytes executable
c:\windows\TEMP\QH0369.ins\ASMTINFO.INX 139 bytes
c:\windows\TEMP\QH0369.ins\ASNTCLN.EXE 14200 bytes executable
c:\windows\TEMP\QH0369.ins\ASPLYSCN.DLL 62840 bytes executable
c:\windows\TEMP\QH0369.ins\ASPYRES.DLL 5072248 bytes executable
c:\windows\TEMP\QH0369.ins\ASQHSIG.INX 475 bytes
c:\windows\TEMP\QH0369.ins\ASREPSUB.DLL 107896 bytes executable
c:\windows\TEMP\QH0369.ins\ASRES.DLL 4932984 bytes executable
c:\windows\TEMP\QH0369.ins\InstErr.log 57 bytes
c:\windows\TEMP\QH0369.ins\INSTFW.EXE 34388080 bytes executable
c:\windows\TEMP\QH0369.ins\LIBZ.DLL 45056 bytes executable
c:\windows\TEMP\QH0369.ins\LICENSE.TXT 10390 bytes
c:\windows\TEMP\QH0369.ins\LINKS.DAT 2312 bytes
c:\windows\TEMP\QH0369.ins\LINWORM.IN0 12 bytes
c:\windows\TEMP\QH0369.ins\LINWORM.IN1 12 bytes
c:\windows\TEMP\QH0369.ins\LINWORM.IN2 12 bytes
c:\windows\TEMP\QH0369.ins\LINWORM.IN3 12 bytes
c:\windows\TEMP\QH0369.ins\LINWORM.IN4 12 bytes
c:\windows\TEMP\QH0369.ins\LINWORM.INX 287262 bytes
c:\windows\TEMP\QH0369.ins\LOGDISP.DLL 58744 bytes executable
c:\windows\TEMP\QH0369.ins\LOGFUN.DLL 193912 bytes executable
c:\windows\TEMP\QH0369.ins\LOGS.ARJ 111 bytes
c:\windows\TEMP\QH0369.ins\LSONTEXE.EXT 261 bytes
c:\windows\TEMP\QH0369.ins\LSPMOD.DLL 75128 bytes executable
c:\windows\TEMP\QH0369.ins\LZESDK.DLL 24576 bytes executable
c:\windows\TEMP\QH0369.ins\MAC95.DAT 35261 bytes
c:\windows\TEMP\QH0369.ins\MACDUMP.DAT 1085 bytes
c:\windows\TEMP\QH0369.ins\MACHINFO.EXE 508162 bytes executable
c:\windows\TEMP\QH0369.ins\MACRINFO.DLL 45056 bytes executable
c:\windows\TEMP\QH0369.ins\MACSCAN.DLL 65536 bytes executable
c:\windows\TEMP\QH0369.ins\MANUAL.PDF 790408 bytes
c:\windows\TEMP\QH0369.ins\MBFSWRAP.DLL 24576 bytes executable
c:\windows\TEMP\QH0369.ins\MFC71U.DLL 1047552 bytes executable
c:\windows\TEMP\QH0369.ins\MIMESDK.DLL 45056 bytes executable
c:\windows\TEMP\QH0369.ins\MISC.DLL 83320 bytes executable
c:\windows\TEMP\QH0369.ins\MISCSCAN.DLL 45056 bytes executable
c:\windows\TEMP\QH0369.ins\MODLOG.DLL 79224 bytes executable
c:\windows\TEMP\QH0369.ins\MODRES.DLL 2426232 bytes executable
c:\windows\TEMP\QH0369.ins\MODSTAT.DLL 124280 bytes executable
c:\windows\TEMP\QH0369.ins\MODSTUI.DLL 42360 bytes executable
c:\windows\TEMP\QH0369.ins\MSDCODE.DLL 20480 bytes executable
c:\windows\TEMP\QH0369.ins\MSEXPSDK.DLL 20480 bytes executable
c:\windows\TEMP\QH0369.ins\MSG32.HTM 1 bytes
c:\windows\TEMP\QH0369.ins\MSGVIEW.DLL 120184 bytes executable
c:\windows\TEMP\QH0369.ins\MSVCP71.DLL 499712 bytes executable
c:\windows\TEMP\QH0369.ins\ASSPINCL.INX 64 bytes
c:\windows\TEMP\QH0369.ins\AUTOVIEW.DLL 111992 bytes executable
c:\windows\TEMP\QH0369.ins\AVCAILIB.DLL 202104 bytes executable
c:\windows\TEMP\QH0369.ins\BATSCAN.DLL 24576 bytes executable
c:\windows\TEMP\QH0369.ins\BKDRELF.DLL 24576 bytes executable
c:\windows\TEMP\QH0369.ins\BKDREPOC.DLL 28672 bytes executable
c:\windows\TEMP\QH0369.ins\BKDREXLN.INX 14040 bytes
c:\windows\TEMP\QH0369.ins\BKDRSCAN.DLL 57344 bytes executable
c:\windows\TEMP\QH0369.ins\BOOT.DLL 20480 bytes executable
c:\windows\TEMP\QH0369.ins\BOOT.DRV 1467 bytes
c:\windows\TEMP\QH0369.ins\BOOTSCAN.DLL 40960 bytes executable
c:\windows\TEMP\QH0369.ins\BRFFOLD.DLL 71032 bytes executable
c:\windows\TEMP\QH0369.ins\CABSDK.DLL 45056 bytes executable
c:\windows\TEMP\QH0369.ins\CATEYE.EXE 206200 bytes executable
c:\windows\TEMP\QH0369.ins\CATFLT.2K 65016 bytes executable
c:\windows\TEMP\QH0369.ins\CATFLT.CAT 69 bytes
c:\windows\TEMP\QH0369.ins\CATFLT.INF 3478 bytes
c:\windows\TEMP\QH0369.ins\CATFLT.X64 47160 bytes executable
c:\windows\TEMP\QH0369.ins\CDRW_NTL.DLL 111714 bytes executable
c:\windows\TEMP\QH0369.ins\CHMSCAN.DLL 20480 bytes executable
c:\windows\TEMP\QH0369.ins\CHMSDK.DLL 32768 bytes executable
c:\windows\TEMP\QH0369.ins\CONFIG.ARJ 5537 bytes
c:\windows\TEMP\QH0369.ins\CONIO.SYS 5120 bytes executable
c:\windows\TEMP\QH0369.ins\COUNTRY.DAT 142570 bytes
c:\windows\TEMP\QH0369.ins\CTESDK.DLL 28672 bytes executable
c:\windows\TEMP\QH0369.ins\CTRLLIB.DLL 243064 bytes executable
c:\windows\TEMP\QH0369.ins\DA.EXE 51244 bytes
c:\windows\TEMP\QH0369.ins\DBXSDK.DLL 28672 bytes executable
c:\windows\TEMP\QH0369.ins\DELNBOOT.EXE 12664 bytes executable
c:\windows\TEMP\QH0369.ins\DELONNB.DLL 62840 bytes executable
c:\windows\TEMP\QH0369.ins\DFGFILE.CNF 83276 bytes
c:\windows\TEMP\QH0369.ins\DISASM.DLL 32768 bytes executable
c:\windows\TEMP\QH0369.ins\DISKWIN.DLL 24576 bytes executable
c:\windows\TEMP\QH0369.ins\DMGCLNR.DLL 111992 bytes executable
c:\windows\TEMP\QH0369.ins\DOSPOLY.DLL 106496 bytes executable
c:\windows\TEMP\QH0369.ins\DOSSCAN.DLL 77824 bytes executable
c:\windows\TEMP\QH0369.ins\DRVCOMM.DLL 20480 bytes executable
c:\windows\TEMP\QH0369.ins\DUSE.DLL 20480 bytes executable
c:\windows\TEMP\QH0369.ins\ECDCORE.DLL 140664 bytes executable
c:\windows\TEMP\QH0369.ins\ELFFILE.DLL 24576 bytes executable
c:\windows\TEMP\QH0369.ins\ELFSCAN.DLL 24576 bytes executable
c:\windows\TEMP\QH0369.ins\EMG.ARJ 656993 bytes
c:\windows\TEMP\QH0369.ins\EMLPROUI.EXE 267640 bytes executable
c:\windows\TEMP\QH0369.ins\EMLPROXY.EXE 50552 bytes executable
c:\windows\TEMP\QH0369.ins\EMLTDI.SYS 28656 bytes executable
c:\windows\TEMP\QH0369.ins\EMLTDI.X64 18488 bytes executable
c:\windows\TEMP\QH0369.ins\EMPXCORE.DLL 165240 bytes executable
c:\windows\TEMP\QH0369.ins\catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
c:\windows\TEMP\QH0369.ins\EXPIRE.NWS 2367 bytes
c:\windows\TEMP\QH0369.ins\FBSCH.EXE 37752 bytes executable
c:\windows\TEMP\QH0369.ins\FILESDK.DLL 24576 bytes executable
c:\windows\TEMP\QH0369.ins\FILEWR64.DLL 82296 bytes executable
c:\windows\TEMP\QH0369.ins\NATIVLST.DAT 16392 bytes
c:\windows\TEMP\QH0369.ins\NATIVSCN.EXE 62976 bytes executable
c:\windows\TEMP\QH0369.ins\NETCON.DLL 58744 bytes executable
c:\windows\TEMP\QH0369.ins\NEWFILE.TMP 739962 bytes
c:\windows\TEMP\QH0369.ins\NEWS.DAT 57 bytes
c:\windows\TEMP\QH0369.ins\NT5DRV.2K 40056 bytes executable
c:\windows\TEMP\QH0369.ins\NT5DRV.X64 45112 bytes executable
c:\windows\TEMP\QH0369.ins\NT5DRV.XP 40056 bytes executable
c:\windows\TEMP\QH0369.ins\NTCLNSRV.EXE 58744 bytes executable
c:\windows\TEMP\QH0369.ins\NTMS32.DLL 99704 bytes executable
c:\windows\TEMP\QH0369.ins\NTSYS.DLL 39424 bytes executable
c:\windows\TEMP\QH0369.ins\NVBKDRSN.DLL 34816 bytes executable
c:\windows\TEMP\QH0369.ins\NVDISASM.DLL 18432 bytes executable
c:\windows\TEMP\QH0369.ins\NVFLSDK.DLL 5632 bytes executable
c:\windows\TEMP\QH0369.ins\NVHRLSCN.DLL 26624 bytes executable
c:\windows\TEMP\QH0369.ins\NVHURSCN.DLL 28672 bytes executable
c:\windows\TEMP\QH0369.ins\NVPEPLY.DLL 357888 bytes executable
c:\windows\TEMP\QH0369.ins\NVPESCN.DLL 102912 bytes executable
c:\windows\TEMP\QH0369.ins\OPSWATAI.DLL 132472 bytes executable
c:\windows\TEMP\QH0369.ins\OSFILES.DAT 159274 bytes
c:\windows\TEMP\QH0369.ins\PEPOLY.DLL 270336 bytes executable
c:\windows\TEMP\QH0369.ins\PEPOLY00.DLL 3710976 bytes executable
c:\windows\TEMP\QH0369.ins\PEPOLY01.DLL 184320 bytes executable
c:\windows\TEMP\QH0369.ins\PEPOLY02.DLL 4165632 bytes executable
c:\windows\TEMP\QH0369.ins\PESCAN.DLL 98304 bytes executable
c:\windows\TEMP\QH0369.ins\PLATFORM.DLL 20480 bytes executable
c:\windows\TEMP\QH0369.ins\PMAC95.DAT 11818 bytes
c:\windows\TEMP\QH0369.ins\PROCSMOD.DLL 79224 bytes executable
c:\windows\TEMP\QH0369.ins\PSAPI.DLL 18192 bytes executable
c:\windows\TEMP\QH0369.ins\PSSCAN.DLL 54648 bytes executable
c:\windows\TEMP\QH0369.ins\QHCMD.FPI 967 bytes
c:\windows\TEMP\QH0369.ins\QHDATA.ARJ 71799904 bytes
c:\windows\TEMP\QH0369.ins\QHDELTMP.EXE 30072 bytes executable
c:\windows\TEMP\QH0369.ins\QHSECURE.DLL 122880 bytes executable
c:\windows\TEMP\QH0369.ins\QHSET.EXE 226680 bytes executable
c:\windows\TEMP\QH0369.ins\QHUNPACK.EXE 221184 bytes executable
c:\windows\TEMP\QH0369.ins\QUAR.DLL 58744 bytes executable
c:\windows\TEMP\QH0369.ins\QUARFUN.DLL 382328 bytes executable
c:\windows\TEMP\QH0369.ins\QUHELPER.DLL 66936 bytes executable
c:\windows\TEMP\QH0369.ins\QUHLPSVC.EXE 58744 bytes executable
c:\windows\TEMP\QH0369.ins\QUICKUP.EXE 247160 bytes executable
c:\windows\TEMP\QH0369.ins\RARSDK.DLL 114688 bytes executable
c:\windows\TEMP\QH0369.ins\RCSCAN.DLL 79224 bytes executable
c:\windows\TEMP\QH0369.ins\README.TXT 9134 bytes
c:\windows\TEMP\QH0369.ins\ASSCAN.DLL 132472 bytes executable
c:\windows\TEMP\QH0369.ins\DMGDEF.DAT 51481 bytes
c:\windows\TEMP\QH0369.ins\FILEWRAP.DLL 79224 bytes executable
c:\windows\TEMP\QH0369.ins\INSTALL.DLL
c:\windows\TEMP\QH0369.ins\MSVCR71.DLL 348160 bytes executable
c:\windows\TEMP\QH0369.ins\NVPLTFRM.DLL 6144 bytes executable
c:\windows\TEMP\QH0369.ins\OPSUIIPC.DLL 16760 bytes executable
c:\windows\TEMP\QH0369.ins\REGACT.DAT 0 bytes
c:\windows\TEMP\QH0369.ins\SCANSET.DLL 472440 bytes executable
c:\windows\TEMP\QH0369.ins\SIGBKDR.IN0 12 bytes
c:\windows\TEMP\QH0369.ins\SIGMBKDR.IN0 12 bytes
c:\windows\TEMP\QH0369.ins\SIGMWARE.IN0 12 bytes
c:\windows\TEMP\QH0369.ins\SIGSWF.INX 464 bytes
c:\windows\TEMP\QH0369.ins\SPROGMOD.DLL 75128 bytes executable
c:\windows\TEMP\QH0369.ins\REGDEF.IN0 274 bytes
c:\windows\TEMP\QH0369.ins\REGDEF.IN1 274 bytes
c:\windows\TEMP\QH0369.ins\REGDEF.IN2 274 bytes
c:\windows\TEMP\QH0369.ins\REGDEF.IN3 274 bytes
c:\windows\TEMP\QH0369.ins\REGDEF.IN4 274 bytes
c:\windows\TEMP\QH0369.ins\REGDEF.INX 107410 bytes
c:\windows\TEMP\QH0369.ins\REGINX.DLL 91512 bytes executable
c:\windows\TEMP\QH0369.ins\REGIST64.DLL 86904 bytes executable
c:\windows\TEMP\QH0369.ins\REGISTRY.DLL 83320 bytes executable
c:\windows\TEMP\QH0369.ins\RENEW.EXE 144760 bytes executable
c:\windows\TEMP\QH0369.ins\REPORTS.ARJ 159 bytes
c:\windows\TEMP\QH0369.ins\RGSEARCH.DLL 58744 bytes executable
c:\windows\TEMP\QH0369.ins\RMS.DAT 3435 bytes
c:\windows\TEMP\QH0369.ins\RMSUPP.DAT 1337846 bytes
c:\windows\TEMP\QH0369.ins\ROOT.ARJ 36041416 bytes
c:\windows\TEMP\QH0369.ins\SCAN.DLL 94208 bytes executable
c:\windows\TEMP\QH0369.ins\SCANABT.DLL 99704 bytes executable
c:\windows\TEMP\QH0369.ins\SCANAPI.DLL 28672 bytes executable
c:\windows\TEMP\QH0369.ins\SCANCHK.DAT 1664 bytes
c:\windows\TEMP\QH0369.ins\SCANETLS.DLL 31096 bytes executable
c:\windows\TEMP\QH0369.ins\SCANEXL.DLL 75128 bytes executable
c:\windows\TEMP\QH0369.ins\SCANMSG.EXE 111992 bytes executable
c:\windows\TEMP\QH0369.ins\SCANNER.EXE 107896 bytes executable
c:\windows\TEMP\QH0369.ins\SCANOPT.DLL 349560 bytes executable
c:\windows\TEMP\QH0369.ins\SCANRES.DLL 8013176 bytes executable
c:\windows\TEMP\QH0369.ins\SCANRPT.DLL 31096 bytes executable
c:\windows\TEMP\QH0369.ins\SCANSDK.DLL 40960 bytes executable
c:\windows\TEMP\QH0369.ins\SCANSTS.DLL 107896 bytes executable
c:\windows\TEMP\QH0369.ins\SCANTLS.DLL 210296 bytes executable
c:\windows\TEMP\QH0369.ins\SCANVER.CNF 20 bytes
c:\windows\TEMP\QH0369.ins\SCANWSCS.EXE 134488 bytes executable
c:\windows\TEMP\QH0369.ins\SCREENNT.2K 17400 bytes executable
c:\windows\TEMP\QH0369.ins\SCREENNT.X64 25656 bytes executable
c:\windows\TEMP\QH0369.ins\SCREENNT.XP 19960 bytes executable
c:\windows\TEMP\QH0369.ins\SECDESC.DLL 50552 bytes executable
c:\windows\TEMP\QH0369.ins\SECTION.INI 207 bytes
c:\windows\TEMP\QH0369.ins\SENSOR.EXE 144760 bytes executable
c:\windows\TEMP\QH0369.ins\SETUP.DAT 11286 bytes
c:\windows\TEMP\QH0369.ins\SETUPCFG.DLL 99704 bytes executable
c:\windows\TEMP\QH0369.ins\SG32OVBS.INX 6580 bytes
c:\windows\TEMP\QH0369.ins\SHSSDK.DLL 28672 bytes executable
c:\windows\TEMP\QH0369.ins\SIG32.INX 44904 bytes
c:\windows\TEMP\QH0369.ins\SIG32CE.INX 104 bytes
c:\windows\TEMP\QH0369.ins\SIGAIF.INX 920 bytes
c:\windows\TEMP\QH0369.ins\SIGBAT.INX 208248 bytes
c:\windows\TEMP\QH0369.ins\SPYDLL.DLL 54648 bytes executable
c:\windows\TEMP\QH0369.ins\SUPPORT.DAT 35295 bytes
c:\windows\TEMP\QH0369.ins\TARSDK.DLL 20480 bytes executable
c:\windows\TEMP\QH0369.ins\temp
c:\windows\TEMP\QH0369.ins\THISDOC.DAT 1120 bytes
c:\windows\TEMP\QH0369.ins\TNEFSDK.DLL 24576 bytes executable
c:\windows\TEMP\QH0369.ins\TPINFO.DAT 190 bytes
c:\windows\TEMP\QH0369.ins\TRACKDLG.DLL 28536 bytes executable
c:\windows\TEMP\QH0369.ins\TRACKERS.DLL 95608 bytes executable
c:\windows\TEMP\QH0369.ins\UINSMF64.EXE 116088 bytes executable
c:\windows\TEMP\QH0369.ins\UNARJ32.DLL 28672 bytes executable
c:\windows\TEMP\QH0369.ins\UNINST.DLL 263544 bytes executable
c:\windows\TEMP\QH0369.ins\UNINST.EXE 189816 bytes executable
c:\windows\TEMP\QH0369.ins\UNINSTFW.EXE 50552 bytes executable
c:\windows\TEMP\QH0369.ins\UPACKSDK.DLL 20480 bytes executable
c:\windows\TEMP\QH0369.ins\UPGDNRES.DLL 58744 bytes executable
c:\windows\TEMP\QH0369.ins\UPSCHD.EXE 95608 bytes executable
c:\windows\TEMP\QH0369.ins\VBSSCAN.DLL 86016 bytes executable
c:\windows\TEMP\QH0369.ins\VERINFO.DLL 75128 bytes executable
c:\windows\TEMP\QH0369.ins\VIRINFO.DLL 37752 bytes executable
c:\windows\TEMP\QH0369.ins\VIRLIST.DLL 20480 bytes executable
c:\windows\TEMP\QH0369.ins\VIRSTAT.DLL 71032 bytes executable
c:\windows\TEMP\QH0369.ins\VIRUSDB.DLL 83320 bytes executable
c:\windows\TEMP\QH0369.ins\VXDSCAN.DLL 32768 bytes executable
c:\windows\TEMP\QH0369.ins\WEL.NWS 3277 bytes
c:\windows\TEMP\QH0369.ins\WHATSNEW.ICO 1078 bytes
c:\windows\TEMP\QH0369.ins\WHATSNEW.TXT 9163 bytes
c:\windows\TEMP\QH0369.ins\WORMSCAN.DLL 90112 bytes executable
c:\windows\TEMP\QH0369.ins\ZIPSCAN.DLL 24576 bytes executable
c:\windows\TEMP\QH0369.ins\ZIPSDK.DLL 45056 bytes executable
c:\windows\TEMP\QH0369.ins\ZOOSCAN.DLL 24576 bytes executable
c:\windows\TEMP\QH0369.ins\FNSYSITF.DLL 18296 bytes executable
c:\windows\TEMP\QH0369.ins\GDIPLUS.DLL 1700352 bytes executable
c:\windows\TEMP\QH0369.ins\GZIPSDK.DLL 28672 bytes executable
c:\windows\TEMP\QH0369.ins\HELP.CHM 271927 bytes
c:\windows\TEMP\QH0369.ins\HEURSCAN.DLL 40960 bytes executable
c:\windows\TEMP\QH0369.ins\HFILEMOD.DLL 79224 bytes executable
c:\windows\TEMP\QH0369.ins\HLPSCAN.DLL 24576 bytes executable
c:\windows\TEMP\QH0369.ins\HRLYSCAN.DLL 36864 bytes executable
c:\windows\TEMP\QH0369.ins\IEBHOMOD.DLL 75128 bytes executable
c:\windows\TEMP\QH0369.ins\IECHKLST.DAT 105193 bytes
c:\windows\TEMP\QH0369.ins\IESETMOD.DLL 83320 bytes executable
c:\windows\TEMP\QH0369.ins\IETLBMOD.DLL 75128 bytes executable
c:\windows\TEMP\QH0369.ins\INDEX.DAT 78 bytes
c:\windows\TEMP\QH0369.ins\INETSDK.DLL 32632 bytes executable
c:\windows\TEMP\QH0369.ins\INFOEML.DAT 15720 bytes
c:\windows\TEMP\QH0369.ins\INFOFW64.DLL 81272 bytes executable
c:\windows\TEMP\QH0369.ins\INFOFWRI.DLL 79224 bytes executable
c:\windows\TEMP\QH0369.ins\INFORI.DLL 87416 bytes executable
c:\windows\TEMP\QH0369.ins\INFORI64.DLL 94072 bytes executable
c:\windows\TEMP\QH0369.ins\INFOSTAT.DAT 2096 bytes
c:\windows\TEMP\QH0369.ins\INISCAN.DLL 24576 bytes executable
c:\windows\TEMP\QH0369.ins\INST.EXE
c:\windows\TEMP\QH0369.ins\SIGBKDR.IN1 12 bytes
c:\windows\TEMP\QH0369.ins\SIGBKDR.IN2 12 bytes
c:\windows\TEMP\QH0369.ins\SIGBKDR.IN3 12 bytes
c:\windows\TEMP\QH0369.ins\SIGBKDR.IN4 12 bytes
c:\windows\TEMP\QH0369.ins\SIGBKDR.INX 6089837 bytes
c:\windows\TEMP\QH0369.ins\SIGBOOT.INX 3869 bytes
c:\windows\TEMP\QH0369.ins\SIGDOS.INX 31128 bytes
c:\windows\TEMP\QH0369.ins\SIGDOS2.INX 445368 bytes
c:\windows\TEMP\QH0369.ins\SIGELF.INX 10800 bytes
c:\windows\TEMP\QH0369.ins\SIGEXDNA.IN0 12 bytes
c:\windows\TEMP\QH0369.ins\SIGEXDNA.IN1 12 bytes
c:\windows\TEMP\QH0369.ins\SIGEXDNA.IN2 12 bytes
c:\windows\TEMP\QH0369.ins\SIGEXDNA.IN3 12 bytes
c:\windows\TEMP\QH0369.ins\SIGEXDNA.IN4 12 bytes
c:\windows\TEMP\QH0369.ins\SIGEXDNA.INX 24509 bytes
c:\windows\TEMP\QH0369.ins\SIGEXRK.IN0 12 bytes
c:\windows\TEMP\QH0369.ins\SIGEXRK.IN1 12 bytes
c:\windows\TEMP\QH0369.ins\SIGEXRK.IN2 12 bytes
c:\windows\TEMP\QH0369.ins\SIGEXRK.IN3 12 bytes
c:\windows\TEMP\QH0369.ins\SIGEXRK.IN4 12 bytes
c:\windows\TEMP\QH0369.ins\SIGEXRK.INX 739962 bytes
c:\windows\TEMP\QH0369.ins\SIGHLP.INX 254 bytes
c:\windows\TEMP\QH0369.ins\SIGINF.INX 20984 bytes
c:\windows\TEMP\QH0369.ins\SIGINI.INX 74544 bytes
c:\windows\TEMP\QH0369.ins\SIGMBKDR.IN1 12 bytes
c:\windows\TEMP\QH0369.ins\SIGMBKDR.IN2 12 bytes
c:\windows\TEMP\QH0369.ins\SIGMBKDR.IN3 12 bytes
c:\windows\TEMP\QH0369.ins\SIGMBKDR.IN4
c:\windows\TEMP\QH0369.ins\SIGMBKDR.INX 12 bytes
c:\windows\TEMP\QH0369.ins\SIGMSPWR.IN0 12 bytes
c:\windows\TEMP\QH0369.ins\SIGMSPWR.IN1 12 bytes
c:\windows\TEMP\QH0369.ins\SIGMSPWR.IN2 12 bytes
c:\windows\TEMP\QH0369.ins\SIGMSPWR.IN3 12 bytes
c:\windows\TEMP\QH0369.ins\SIGMSPWR.IN4 12 bytes
c:\windows\TEMP\QH0369.ins\SIGMSPWR.INX 12 bytes
c:\windows\TEMP\QH0369.ins\SIGMTRJN.IN0 12 bytes
c:\windows\TEMP\QH0369.ins\SIGMTRJN.IN1 12 bytes
c:\windows\TEMP\QH0369.ins\SIGMTRJN.IN2 12 bytes
c:\windows\TEMP\QH0369.ins\SIGMTRJN.IN3 12 bytes
c:\windows\TEMP\QH0369.ins\SIGMTRJN.IN4 12 bytes
c:\windows\TEMP\QH0369.ins\SIGMTRJN.INX 1608 bytes
c:\windows\TEMP\QH0369.ins\SIGMWARE.IN1 12 bytes
c:\windows\TEMP\QH0369.ins\SIGMWARE.IN2 12 bytes
c:\windows\TEMP\QH0369.ins\SIGMWARE.IN3 12 bytes
c:\windows\TEMP\QH0369.ins\SIGMWARE.IN4 12 bytes
c:\windows\TEMP\QH0369.ins\SIGMWARE.INX 88 bytes
c:\windows\TEMP\QH0369.ins\SIGMWORM.IN0 12 bytes
c:\windows\TEMP\QH0369.ins\SIGMWORM.IN1 12 bytes
c:\windows\TEMP\QH0369.ins\SIGMWORM.IN2 12 bytes
c:\windows\TEMP\QH0369.ins\SIGMWORM.IN3 12 bytes
c:\windows\TEMP\QH0369.ins\SIGMWORM.IN4 12 bytes
c:\windows\TEMP\QH0369.ins\SIGMWORM.INX 4648 bytes
c:\windows\TEMP\QH0369.ins\SIGPOLY.INX 8579 bytes
c:\windows\TEMP\QH0369.ins\SIGSPWR.IN0 12 bytes
c:\windows\TEMP\QH0369.ins\SIGSPWR.IN1 12 bytes
c:\windows\TEMP\QH0369.ins\SIGSPWR.IN2 12 bytes
c:\windows\TEMP\QH0369.ins\SIGSPWR.IN3 12 bytes
c:\windows\TEMP\QH0369.ins\SIGSPWR.IN4 12 bytes
c:\windows\TEMP\QH0369.ins\SIGSPWR.INX 190 bytes
c:\windows\TEMP\QH0369.ins\SIGTRJN.IN0 12 bytes
c:\windows\TEMP\QH0369.ins\SIGTRJN.IN1 12 bytes
c:\windows\TEMP\QH0369.ins\SIGTRJN.IN2 12 bytes
c:\windows\TEMP\QH0369.ins\SIGTRJN.IN3 12 bytes
c:\windows\TEMP\QH0369.ins\SIGTRJN.IN4 12 bytes
c:\windows\TEMP\QH0369.ins\SIGTRJN.INX 33151622 bytes
c:\windows\TEMP\QH0369.ins\SIGVBS.INX 202320 bytes
c:\windows\TEMP\QH0369.ins\SIGWARE.IN0 12 bytes
c:\windows\TEMP\QH0369.ins\SIGWARE.IN1 12 bytes
c:\windows\TEMP\QH0369.ins\SIGWARE.IN2 12 bytes
c:\windows\TEMP\QH0369.ins\SIGWARE.IN3 12 bytes
c:\windows\TEMP\QH0369.ins\SIGWARE.IN4 12 bytes
c:\windows\TEMP\QH0369.ins\SIGWARE.INX 3620087 bytes
c:\windows\TEMP\QH0369.ins\SIGWORM.IN0 12 bytes
c:\windows\TEMP\QH0369.ins\SIGWORM.IN1 12 bytes
c:\windows\TEMP\QH0369.ins\SIGWORM.IN2 12 bytes
c:\windows\TEMP\QH0369.ins\SIGWORM.IN3 12 bytes
c:\windows\TEMP\QH0369.ins\SIGWORM.IN4 12 bytes
c:\windows\TEMP\QH0369.ins\SIGWORM.INX 2763907 bytes
c:\windows\TEMP\QH0369.ins\SIGWORMO.INX 530591 bytes
c:\windows\TEMP\QH0369.ins\SIGZOO.INX 4692312 bytes
c:\windows\TEMP\QH0369.ins\SISSDK.DLL 20480 bytes executable
c:\windows\TEMP\QH0369.ins\SLIC.TXT 10390 bytes
c:\windows\TEMP\QH0369.ins\SOUNDS.ARJ 148748 bytes
c:\windows\TEMP\QH0369.ins\SP000000.INX 3665396 bytes
c:\windows\TEMP\QH0369.ins\SP000001.INX 3151793 bytes
c:\windows\TEMP\QH0369.ins\SP000002.INX 2646318 bytes
c:\windows\TEMP\QH0369.ins\SPORDER.DLL 9488 bytes executable
c:\windows\TEMP\QH0369.ins\NVPOLY00.DLL 39936 bytes executable
c:\windows\TEMP\QH0369.ins\NVPOLY01.DLL 40960 bytes executable
c:\windows\TEMP\QH0369.ins\NVPOLY02.DLL 4036096 bytes executable
c:\windows\TEMP\QH0369.ins\NVRGSTRY.DLL 5120 bytes executable
c:\windows\TEMP\QH0369.ins\NVSCHDL.DLL 86016 bytes executable
c:\windows\TEMP\QH0369.ins\NVSCN.DLL 37888 bytes executable
c:\windows\TEMP\QH0369.ins\NVSCNSDK.DLL 25600 bytes executable
c:\windows\TEMP\QH0369.ins\NVVRLST.DLL 4096 bytes executable
c:\windows\TEMP\QH0369.ins\NVWRMSCN.DLL 92672 bytes executable
c:\windows\TEMP\QH0369.ins\NWCONMOD.DLL 75128 bytes executable
c:\windows\TEMP\QH0369.ins\OAV.DAT 1247020 bytes
c:\windows\TEMP\QH0369.ins\OAVCHK.DLL 79224 bytes executable
c:\windows\TEMP\QH0369.ins\OLESDK.DLL 40960 bytes executable
c:\windows\TEMP\QH0369.ins\ONLINENT.EXE 214392 bytes executable
c:\windows\TEMP\QH0369.ins\ONLNALRT.DLL 54648 bytes executable
c:\windows\TEMP\QH0369.ins\ONLNMF.DLL 10752 bytes executable
c:\windows\TEMP\QH0369.ins\ONLNSVC.EXE 103800 bytes executable
c:\windows\TEMP\QH0369.ins\OPSCORE.DLL 34168 bytes executable
c:\windows\TEMP\QH0369.ins\OPSITF.DLL 21880 bytes executable
c:\windows\TEMP\QH0369.ins\OPSSVC.EXE 17272 bytes executable
c:\windows\TEMP\QH7460.ins
c:\windows\TEMP\QH7460.ins\ARJSDK.DLL 20480 bytes executable
c:\windows\TEMP\QH7460.ins\ARKIT.EXE 2950248 bytes executable
c:\windows\TEMP\QH7460.ins\AUTOVIEW.DLL 103800 bytes executable
c:\windows\TEMP\QH7460.ins\AVCAILIB.DLL 107896 bytes executable
c:\windows\TEMP\QH7460.ins\BATSCAN.DLL 24576 bytes executable
c:\windows\TEMP\QH7460.ins\BKDRELF.DLL 24576 bytes executable
c:\windows\TEMP\QH7460.ins\BKDREPOC.DLL 28672 bytes executable
c:\windows\TEMP\QH7460.ins\BKDRSCAN.DLL 49152 bytes executable
c:\windows\TEMP\QH7460.ins\BOOT.DLL 20480 bytes executable
c:\windows\TEMP\QH7460.ins\BOOT.DRV 1467 bytes
c:\windows\TEMP\QH7460.ins\BOOTSCAN.DLL 40960 bytes executable
c:\windows\TEMP\QH7460.ins\BRFFOLD.DLL 71032 bytes executable
c:\windows\TEMP\QH7460.ins\CABSDK.DLL 45056 bytes executable
c:\windows\TEMP\QH7460.ins\CATEYE.EXE 206200 bytes executable
c:\windows\TEMP\QH7460.ins\CDRW_NTL.DLL 111714 bytes executable
c:\windows\TEMP\QH7460.ins\CHMSCAN.DLL 20480 bytes executable
c:\windows\TEMP\QH7460.ins\CHMSDK.DLL 32768 bytes executable
c:\windows\TEMP\QH7460.ins\CONFIG.ARJ 5223 bytes
c:\windows\TEMP\QH7460.ins\CONIO.SYS 5120 bytes executable
c:\windows\TEMP\QH7460.ins\COUNTRY.DAT 142570 bytes
c:\windows\TEMP\QH7460.ins\CTESDK.DLL 28672 bytes executable
c:\windows\TEMP\QH7460.ins\CTRLLIB.DLL 243064 bytes executable
c:\windows\TEMP\QH7460.ins\DA.EXE 51244 bytes
c:\windows\TEMP\QH7460.ins\DBXSDK.DLL 24576 bytes executable
c:\windows\TEMP\QH7460.ins\DELNBOOT.EXE 12664 bytes executable
c:\windows\TEMP\QH7460.ins\DELONNB.DLL 62840 bytes executable
c:\windows\TEMP\QH7460.ins\DISASM.DLL 32768 bytes executable
c:\windows\TEMP\QH7460.ins\DISKWIN.DLL 24576 bytes executable
c:\windows\TEMP\QH7460.ins\DMGCLNR.DLL 91512 bytes executable
c:\windows\TEMP\QH7460.ins\DMGDEF.DAT 50837 bytes
c:\windows\TEMP\QH7460.ins\DOSPOLY.DLL 86016 bytes executable
c:\windows\TEMP\QH7460.ins\DOSSCAN.DLL 77824 bytes executable
c:\windows\TEMP\QH7460.ins\DRVCOMM.DLL 20480 bytes executable
c:\windows\TEMP\QH7460.ins\DUSE.DLL 20480 bytes executable
c:\windows\TEMP\QH7460.ins\ECDCORE.DLL 140664 bytes executable
c:\windows\TEMP\QH7460.ins\ELFFILE.DLL 24576 bytes executable
c:\windows\TEMP\QH7460.ins\ELFSCAN.DLL 24576 bytes executable
c:\windows\TEMP\QH7460.ins\INSTALL.DLL 189816 bytes executable
c:\windows\TEMP\QH7460.ins\LIBZ.DLL 45056 bytes executable
c:\windows\TEMP\QH7460.ins\LICENSE.TXT 6836 bytes
c:\windows\TEMP\QH7460.ins\LINKS.DAT 2312 bytes
c:\windows\TEMP\QH7460.ins\LINWORM.IN0 12 bytes
c:\windows\TEMP\QH7460.ins\LINWORM.IN1 12 bytes
c:\windows\TEMP\QH7460.ins\LINWORM.IN2 12 bytes
c:\windows\TEMP\QH7460.ins\LINWORM.IN3 12 bytes
c:\windows\TEMP\QH7460.ins\LINWORM.IN4 12 bytes
c:\windows\TEMP\QH7460.ins\LINWORM.INX 285347 bytes
c:\windows\TEMP\QH7460.ins\LOGDISP.DLL 58744 bytes executable
c:\windows\TEMP\QH7460.ins\LOGFUN.DLL 189816 bytes executable
c:\windows\TEMP\QH7460.ins\LOGS.ARJ 111 bytes
c:\windows\TEMP\QH7460.ins\LSONTEXE.EXT 234 bytes
c:\windows\TEMP\QH7460.ins\LZESDK.DLL 24576 bytes executable
c:\windows\TEMP\QH7460.ins\MAC95.DAT 35261 bytes
c:\windows\TEMP\QH7460.ins\MACDUMP.DAT 1085 bytes
c:\windows\TEMP\QH7460.ins\MACHINFO.EXE 504557 bytes executable
c:\windows\TEMP\QH7460.ins\MACRINFO.DLL 45056 bytes executable
c:\windows\TEMP\QH7460.ins\MACSCAN.DLL 65536 bytes executable
c:\windows\TEMP\QH7460.ins\MBFSWRAP.DLL 24576 bytes executable
c:\windows\TEMP\QH7460.ins\MFC71U.DLL 1047552 bytes executable
c:\windows\TEMP\QH7460.ins\MIMESDK.DLL 45056 bytes executable
c:\windows\TEMP\QH7460.ins\MISC.DLL 83320 bytes executable
c:\windows\TEMP\QH7460.ins\MISCSCAN.DLL 28672 bytes executable
c:\windows\TEMP\QH7460.ins\MODRES.DLL 2422136 bytes executable
c:\windows\TEMP\QH7460.ins\MSDCODE.DLL 20480 bytes executable
c:\windows\TEMP\QH7460.ins\MSEXPSDK.DLL 20480 bytes executable
c:\windows\TEMP\QH7460.ins\MSG32.HTM 1 bytes
c:\windows\TEMP\QH7460.ins\MSGVIEW.DLL 120184 bytes executable
c:\windows\TEMP\QH7460.ins\MSVCP71.DLL 499712 bytes executable
c:\windows\TEMP\QH7460.ins\MSVCR71.DLL 348160 bytes executable
c:\windows\TEMP\QH7460.ins\NATIVLST.DAT 15352 bytes
c:\windows\TEMP\QH7460.ins\NATIVSCN.EXE 62464 bytes executable
c:\windows\TEMP\QH7460.ins\NEWFILE.TMP 592612 bytes
c:\windows\TEMP\QH7460.ins\NEWS.DAT 57 bytes
c:\windows\TEMP\QH7460.ins\NT5DRV.2K 39672 bytes executable
c:\windows\TEMP\QH7460.ins\NT5DRV.X64 44592 bytes executable
c:\windows\TEMP\QH7460.ins\NT5DRV.XP 39672 bytes executable
c:\windows\TEMP\QH7460.ins\NTCLNSRV.EXE 53248 bytes executable
c:\windows\TEMP\QH7460.ins\NTMS32.DLL 120184 bytes executable
c:\windows\TEMP\QH7460.ins\NTSYS.DLL 39424 bytes executable
c:\windows\TEMP\QH7460.ins\NVBKDRSN.DLL 31232 bytes executable
c:\windows\TEMP\QH7460.ins\NVDISASM.DLL 18432 bytes executable
c:\windows\TEMP\QH7460.ins\NVFLSDK.DLL 5632 bytes executable
c:\windows\TEMP\QH7460.ins\NVHRLSCN.DLL 24576 bytes executable
c:\windows\TEMP\QH7460.ins\NVHURSCN.DLL 28672 bytes executable
c:\windows\TEMP\QH7460.ins\NVPEPLY.DLL 270848 bytes executable
c:\windows\TEMP\QH7460.ins\NVPESCN.DLL 93184 bytes executable
c:\windows\TEMP\QH7460.ins\NVPLTFRM.DLL 6144 bytes executable
c:\windows\TEMP\QH7460.ins\NVRGSTRY.DLL 5120 bytes executable
c:\windows\TEMP\QH7460.ins\NVSCHDL.DLL 86016 bytes executable
c:\windows\TEMP\QH7460.ins\NVSCN.DLL 37888 bytes executable
c:\windows\TEMP\QH7460.ins\NVSCNSDK.DLL 25600 bytes executable
c:\windows\TEMP\QH7460.ins\NVVRLST.DLL 4096 bytes executable
c:\windows\TEMP\QH7460.ins\NVWRMSCN.DLL 75264 bytes executable
c:\windows\TEMP\QH7460.ins\QHSECURE.DLL 122880 bytes executable
c:\windows\TEMP\QH7460.ins\QHSET.EXE 212992 bytes executable
c:\windows\TEMP\QH7460.ins\QHUNPACK.EXE 221184 bytes executable
c:\windows\TEMP\QH7460.ins\QUAR.DLL 58744 bytes executable
c:\windows\TEMP\QH7460.ins\QUARFUN.DLL 357752 bytes executable
c:\windows\TEMP\QH7460.ins\QUHELPER.DLL 103800 bytes executable
c:\windows\TEMP\QH7460.ins\QUHLPSVC.EXE 58744 bytes executable
c:\windows\TEMP\QH7460.ins\QUICKUP.EXE 210296 bytes executable
c:\windows\TEMP\QH7460.ins\RARSDK.DLL 114688 bytes executable
c:\windows\TEMP\QH7460.ins\RCSCAN.DLL 91512 bytes executable
c:\windows\TEMP\QH7460.ins\README.TXT 6846 bytes
c:\windows\TEMP\QH7460.ins\REGACT.DAT 0 bytes
c:\windows\TEMP\QH7460.ins\REGDEF.IN0 274 bytes
c:\windows\TEMP\QH7460.ins\REGDEF.IN1 274 bytes
c:\windows\TEMP\QH7460.ins\REGDEF.IN2 274 bytes
c:\windows\TEMP\QH7460.ins\REGDEF.IN3 274 bytes
c:\windows\TEMP\QH7460.ins\REGDEF.IN4 274 bytes
c:\windows\TEMP\QH7460.ins\REGDEF.INX 50494 bytes
c:\windows\TEMP\QH7460.ins\REGINX.DLL 103800 bytes executable
c:\windows\TEMP\QH7460.ins\REGISTRY.DLL 83320 bytes executable
c:\windows\TEMP\QH7460.ins\REPORTS.ARJ 159 bytes
c:\windows\TEMP\QH7460.ins\RGSEARCH.DLL 58744 bytes executable
c:\windows\TEMP\QH7460.ins\ROOT.ARJ 20726115 bytes
c:\windows\TEMP\QH7460.ins\SCAN.DLL 94208 bytes executable
c:\windows\TEMP\QH7460.ins\SCANABT.DLL 91512 bytes executable
c:\windows\TEMP\QH7460.ins\SCANAPI.DLL 28672 bytes executable
c:\windows\TEMP\QH7460.ins\SCANCHK.DAT 1639 bytes
c:\windows\TEMP\QH7460.ins\SCANEXL.DLL 79224 bytes executable
c:\windows\TEMP\QH7460.ins\SCANMSG.EXE 116088 bytes executable
c:\windows\TEMP\QH7460.ins\SCANNER.EXE 214392 bytes executable
c:\windows\TEMP\QH7460.ins\SCANOPT.DLL 324984 bytes executable
c:\windows\TEMP\QH7460.ins\SCANRES.DLL 6788472 bytes executable
c:\windows\TEMP\QH7460.ins\SCANRPT.DLL 75128 bytes executable
c:\windows\TEMP\QH7460.ins\SCANSDK.DLL 40960 bytes executable
c:\windows\TEMP\QH7460.ins\SCANSET.DLL 419192 bytes executable
c:\windows\TEMP\QH7460.ins\SCANSTS.DLL 107896 bytes executable
c:\windows\TEMP\QH7460.ins\SCANTLS.DLL 210296 bytes executable
c:\windows\TEMP\QH7460.ins\SCANVER.CNF 20 bytes
c:\windows\TEMP\QH7460.ins\SCANWSCS.EXE 91512 bytes executable
c:\windows\TEMP\QH7460.ins\SCREENNT.2K 17400 bytes executable
c:\windows\TEMP\QH7460.ins\SCREENNT.X64 25648 bytes executable
c:\windows\TEMP\QH7460.ins\SCREENNT.XP 19960 bytes executable
c:\windows\TEMP\QH7460.ins\SECDESC.DLL 50552 bytes executable
c:\windows\TEMP\QH7460.ins\SECTION.INI 207 bytes
c:\windows\TEMP\QH7460.ins\SENSOR.EXE 144760 bytes executable
c:\windows\TEMP\QH7460.ins\SETUP.DAT 8406 bytes
c:\windows\TEMP\QH7460.ins\EMLPROUI.EXE 275832 bytes executable
c:\windows\TEMP\QH7460.ins\EMLPROXY.EXE 50552 bytes executable
c:\windows\TEMP\QH7460.ins\EMLTDI.SYS 12160 bytes executable
c:\windows\TEMP\QH7460.ins\EMLTDI.X64 16944 bytes executable
c:\windows\TEMP\QH7460.ins\EMLTDINT.SYS 16848 bytes executable
c:\windows\TEMP\QH7460.ins\EMPXCORE.DLL 161144 bytes executable
c:\windows\TEMP\QH7460.ins\Entries.lst 33320 bytes
c:\windows\TEMP\QH7460.ins\EXPIRE.DAT 57 bytes
c:\windows\TEMP\QH7460.ins\EXPIRE.NWS 2367 bytes
c:\windows\TEMP\QH7460.ins\FBSCH.EXE 38776 bytes executable
c:\windows\TEMP\QH7460.ins\FILESDK.DLL 24576 bytes executable
c:\windows\TEMP\QH7460.ins\FILEWRAP.DLL 79224 bytes executable
c:\windows\TEMP\QH7460.ins\GDIPLUS.DLL 1700352 bytes executable
c:\windows\TEMP\QH7460.ins\GZIPSDK.DLL 28672 bytes executable
c:\windows\TEMP\QH7460.ins\HELP.CHM 321883 bytes
c:\windows\TEMP\QH7460.ins\HEURSCAN.DLL 40960 bytes executable
c:\windows\TEMP\QH7460.ins\HLPSCAN.DLL 24576 bytes executable
c:\windows\TEMP\QH7460.ins\HRLYSCAN.DLL 36864 bytes executable
c:\windows\TEMP\QH7460.ins\INDEX.DAT 78 bytes
c:\windows\TEMP\QH7460.ins\INETSDK.DLL 32632 bytes executable
c:\windows\TEMP\QH7460.ins\INFOEML.DAT 15720 bytes
c:\windows\TEMP\QH7460.ins\INFOFWRI.DLL 66936 bytes executable
c:\windows\TEMP\QH7460.ins\INFORI.DLL 83320 bytes executable
c:\windows\TEMP\QH7460.ins\INFOSTAT.DAT 1048 bytes
c:\windows\TEMP\QH7460.ins\INISCAN.DLL 24576 bytes executable
c:\windows\TEMP\QH7460.ins\EMG.ARJ 619675 bytes
c:\windows\TEMP\QH7460.ins\INST.EXE 618496 bytes executable
c:\windows\TEMP\QH7460.ins\NT4DRV.SYS 37320 bytes executable
c:\windows\TEMP\QH7460.ins\OAV.DAT 1148572 bytes
c:\windows\TEMP\QH7460.ins\QHFWINST.EXE 2925000 bytes executable
c:\windows\TEMP\QH7460.ins\SCANETLS.DLL 30584 bytes executable
c:\windows\TEMP\QH7460.ins\SETUPCFG.DLL 99704 bytes executable
c:\windows\TEMP\QH7460.ins\SIGEXDNA.IN2 12 bytes
c:\windows\TEMP\QH7460.ins\SIGMTRJN.IN0 12 bytes
c:\windows\TEMP\QH7460.ins\SIGPOLY.INX 6770 bytes
c:\windows\TEMP\QH7460.ins\SIGWORM.IN0 12 bytes
c:\windows\TEMP\QH7460.ins\SG32OVBS.INX 6580 bytes
c:\windows\TEMP\QH7460.ins\SHSSDK.DLL 28672 bytes executable
c:\windows\TEMP\QH7460.ins\SIG32.INX 42954 bytes
c:\windows\TEMP\QH7460.ins\SIG32CE.INX 104 bytes
c:\windows\TEMP\QH7460.ins\SIGAIF.INX 920 bytes
c:\windows\TEMP\QH7460.ins\SIGBAT.INX 184840 bytes
c:\windows\TEMP\QH7460.ins\SIGBKDR.IN0 12 bytes
c:\windows\TEMP\QH7460.ins\SIGBKDR.IN1 12 bytes
c:\windows\TEMP\QH7460.ins\SIGBKDR.IN2 12 bytes
c:\windows\TEMP\QH7460.ins\SIGBKDR.IN3 12 bytes
c:\windows\TEMP\QH7460.ins\SIGBKDR.IN4 12 bytes
c:\windows\TEMP\QH7460.ins\SIGBKDR.INX 6013386 bytes
c:\windows\TEMP\QH7460.ins\SIGBOOT.INX 3869 bytes
c:\windows\TEMP\QH7460.ins\SIGDOS.INX 31128 bytes
c:\windows\TEMP\QH7460.ins\SIGDOS2.INX 445368 bytes
c:\windows\TEMP\QH7460.ins\SIGELF.INX 10800 bytes
c:\windows\TEMP\QH7460.ins\SIGEXDNA.IN0 12 bytes
c:\windows\TEMP\QH7460.ins\SIGEXDNA.IN1 12 bytes
c:\windows\TEMP\QH7460.ins\SIGEXDNA.IN3 12 bytes
c:\windows\TEMP\QH7460.ins\SIGEXDNA.IN4 12 bytes
c:\windows\TEMP\QH7460.ins\SIGEXDNA.INX 17828 bytes
c:\windows\TEMP\QH7460.ins\SIGEXRK.IN0 12 bytes
c:\windows\TEMP\QH7460.ins\SIGEXRK.IN1 12 bytes
c:\windows\TEMP\QH7460.ins\SIGEXRK.IN2 12 bytes
c:\windows\TEMP\QH7460.ins\SIGEXRK.IN3 12 bytes
c:\windows\TEMP\QH7460.ins\SIGEXRK.IN4 12 bytes
c:\windows\TEMP\QH7460.ins\SIGEXRK.INX 592612 bytes
c:\windows\TEMP\QH7460.ins\SIGHLP.INX 254 bytes
c:\windows\TEMP\QH7460.ins\SIGINF.INX 1680 bytes
c:\windows\TEMP\QH7460.ins\SIGINI.INX 74544 bytes
c:\windows\TEMP\QH7460.ins\SIGMBKDR.IN0 12 bytes
c:\windows\TEMP\QH7460.ins\SIGMBKDR.IN1 12 bytes
c:\windows\TEMP\QH7460.ins\SIGMBKDR.IN2 12 bytes
c:\windows\TEMP\QH7460.ins\SIGMBKDR.IN3 12 bytes
c:\windows\TEMP\QH7460.ins\SIGMBKDR.IN4 12 bytes
c:\windows\TEMP\QH7460.ins\SIGMBKDR.INX 12 bytes
c:\windows\TEMP\QH7460.ins\SIGMSPWR.IN0 12 bytes
c:\windows\TEMP\QH7460.ins\SIGMSPWR.IN1 12 bytes
c:\windows\TEMP\QH7460.ins\SIGMSPWR.IN2 12 bytes
c:\windows\TEMP\QH7460.ins\SIGMSPWR.IN3 12 bytes
c:\windows\TEMP\QH7460.ins\SIGMSPWR.IN4 12 bytes
c:\windows\TEMP\QH7460.ins\SIGMSPWR.INX 12 bytes
c:\windows\TEMP\QH7460.ins\SIGMTRJN.IN1 12 bytes
c:\windows\TEMP\QH7460.ins\SIGMTRJN.IN2 12 bytes
c:\windows\TEMP\QH7460.ins\SIGMTRJN.IN3 12 bytes
c:\windows\TEMP\QH7460.ins\SIGMTRJN.IN4 12 bytes
c:\windows\TEMP\QH7460.ins\SIGMTRJN.INX 1532 bytes
c:\windows\TEMP\QH7460.ins\SIGMWARE.IN0 12 bytes
c:\windows\TEMP\QH7460.ins\SIGMWARE.IN1 12 bytes
c:\windows\TEMP\QH7460.ins\SIGMWARE.IN2 12 bytes
c:\windows\TEMP\QH7460.ins\SIGMWARE.IN3 12 bytes
c:\windows\TEMP\QH7460.ins\SIGMWARE.IN4 12 bytes
c:\windows\TEMP\QH7460.ins\SIGMWARE.INX 88 bytes
c:\windows\TEMP\QH7460.ins\SIGMWORM.IN0 12 bytes
c:\windows\TEMP\QH7460.ins\SIGMWORM.IN1 88 bytes
c:\windows\TEMP\QH7460.ins\SIGMWORM.IN2 12 bytes
c:\windows\TEMP\QH7460.ins\SIGMWORM.IN3 12 bytes
c:\windows\TEMP\QH7460.ins\SIGMWORM.IN4 12 bytes
c:\windows\TEMP\QH7460.ins\SIGMWORM.INX 4268 bytes
c:\windows\TEMP\QH7460.ins\SIGSPWR.IN0 12 bytes
c:\windows\TEMP\QH7460.ins\SIGSPWR.IN1 12 bytes
c:\windows\TEMP\QH7460.ins\SIGSPWR.IN2 12 bytes
c:\windows\TEMP\QH7460.ins\SIGSPWR.IN3 12 bytes
c:\windows\TEMP\QH7460.ins\SIGSPWR.IN4 12 bytes
c:\windows\TEMP\QH7460.ins\SIGSPWR.INX 190 bytes
c:\windows\TEMP\QH7460.ins\SIGTRJN.IN0 12 bytes
c:\windows\TEMP\QH7460.ins\SIGTRJN.IN1 12 bytes
c:\windows\TEMP\QH7460.ins\SIGTRJN.IN2 12 bytes
c:\windows\TEMP\QH7460.ins\SIGTRJN.IN3 12 bytes
c:\windows\TEMP\QH7460.ins\SIGTRJN.IN4 12 bytes
c:\windows\TEMP\QH7460.ins\SIGTRJN.INX 13415071 bytes
c:\windows\TEMP\QH7460.ins\SIGVBS.INX 176328 bytes
c:\windows\TEMP\QH7460.ins\SIGWARE.IN0 12 bytes
c:\windows\TEMP\QH7460.ins\SIGWARE.IN1 12 bytes
c:\windows\TEMP\QH7460.ins\SIGWARE.IN2 12 bytes
c:\windows\TEMP\QH7460.ins\SIGWARE.IN3 12 bytes
c:\windows\TEMP\QH7460.ins\SIGWARE.IN4 12 bytes
c:\windows\TEMP\QH7460.ins\SIGWARE.INX 2116432 bytes
c:\windows\TEMP\QH7460.ins\SIGWORM.IN1 12 bytes
c:\windows\TEMP\QH7460.ins\SIGWORM.IN2 12 bytes
c:\windows\TEMP\QH7460.ins\SIGWORM.IN3 12 bytes
c:\windows\TEMP\QH7460.ins\SIGWORM.IN4 12 bytes
c:\windows\TEMP\QH7460.ins\SIGWORM.INX 1800838 bytes
c:\windows\TEMP\QH7460.ins\SIGWORMO.INX 504375 bytes
c:\windows\TEMP\QH7460.ins\SIGZOO.INX 4692374 bytes
c:\windows\TEMP\QH7460.ins\SISSDK.DLL 20480 bytes executable
c:\windows\TEMP\QH7460.ins\SLIC.TXT 6836 bytes
c:\windows\TEMP\QH7460.ins\SOUNDS.ARJ 148748 bytes
c:\windows\TEMP\QH7460.ins\SPORDER.DLL 9488 bytes executable
c:\windows\TEMP\QH7460.ins\SUPPORT.DAT 25259 bytes
c:\windows\TEMP\QH7460.ins\TARSDK.DLL 20480 bytes executable
c:\windows\TEMP\QH7460.ins\THISDOC.DAT 1120 bytes
c:\windows\TEMP\QH7460.ins\TNEFSDK.DLL 24576 bytes executable
c:\windows\TEMP\QH7460.ins\TPINFO.DAT 180 bytes
c:\windows\TEMP\QH7460.ins\UNARJ32.DLL 28672 bytes executable
c:\windows\TEMP\QH7460.ins\UNINST.DLL 259448 bytes executable
c:\windows\TEMP\QH7460.ins\UNINST.EXE 189816 bytes executable
c:\windows\TEMP\QH7460.ins\UPACKSDK.DLL 20480 bytes executable
c:\windows\TEMP\QH7460.ins\UPSCHD.EXE 95608 bytes executable
c:\windows\TEMP\QH7460.ins\VBSSCAN.DLL 65536 bytes executable
c:\windows\TEMP\QH7460.ins\VIRINFO.DLL 37752 bytes executable
c:\windows\TEMP\QH7460.ins\VIRLIST.DLL 20480 bytes executable
c:\windows\TEMP\QH7460.ins\VIRSTAT.DLL 71032 bytes executable
c:\windows\TEMP\QH7460.ins\VIRUSDB.DLL 83320 bytes executable
c:\windows\TEMP\QH7460.ins\VXDSCAN.DLL 32768 bytes executable
c:\windows\TEMP\QH7460.ins\WEL.NWS 3277 bytes
c:\windows\TEMP\QH7460.ins\WHATSNEW.ICO 1078 bytes
c:\windows\TEMP\QH7460.ins\WHATSNEW.TXT 5995 bytes
c:\windows\TEMP\QH7460.ins\WORMSCAN.DLL 73728 bytes executable
c:\windows\TEMP\QH7460.ins\ZIPSCAN.DLL 24576 bytes executable
c:\windows\TEMP\QH7460.ins\ZIPSDK.DLL 45056 bytes executable
c:\windows\TEMP\QH7460.ins\ZOOSCAN.DLL 24576 bytes executable
c:\windows\TEMP\QH7460.ins\OAVCHK.DLL 79224 bytes executable
c:\windows\TEMP\QH7460.ins\OLESDK.DLL 40960 bytes executable
c:\windows\TEMP\QH7460.ins\ONLINENT.EXE 206200 bytes executable
c:\windows\TEMP\QH7460.ins\ONLINENT.NT4 198008 bytes executable
c:\windows\TEMP\QH7460.ins\ONLNALRT.DLL 40312 bytes executable
c:\windows\TEMP\QH7460.ins\ONLNMF.DLL 45056 bytes executable
c:\windows\TEMP\QH7460.ins\ONLNSVC.EXE 99704 bytes executable
c:\windows\TEMP\QH7460.ins\ONLNSVC.NT4 87416 bytes executable
c:\windows\TEMP\QH7460.ins\OSFILES.DAT 156142 bytes
c:\windows\TEMP\QH7460.ins\PEPOLY.DLL 200704 bytes executable
c:\windows\TEMP\QH7460.ins\PESCAN.DLL 90112 bytes executable
c:\windows\TEMP\QH7460.ins\PLATFORM.DLL 20480 bytes executable
c:\windows\TEMP\QH7460.ins\PMAC95.DAT 11818 bytes
c:\windows\TEMP\QH7460.ins\PSAPI.DLL 18192 bytes executable
c:\windows\TEMP\QH7460.ins\PSSCAN.DLL 243064 bytes executable
c:\windows\TEMP\QH7460.ins\QHCMD.FPI 967 bytes
c:\windows\TEMP\QH7460.ins\QHDATA.ARJ 24985324 bytes
c:\windows\TEMP\QH7460.ins\QHDELTMP.EXE 24576 bytes executable
c:\windows\TEMP\QHDELTMP.EXE 30072 bytes executable
c:\windows\TEMP\quadra000 0 bytes
c:\windows\TEMP\r2h37.tmp 141 bytes
c:\windows\TEMP\r2h3B.tmp 156 bytes
c:\windows\TEMP\r2h3E.tmp 156 bytes
c:\windows\TEMP\r2h6D.tmp 145 bytes
c:\windows\TEMP\r2h8.tmp 122 bytes
c:\windows\TEMP\RarSFX0
c:\windows\TEMP\Re_ High Pressure Gas Train.msg 96277 bytes
c:\windows\TEMP\rotscx000 0 bytes
c:\windows\TEMP\RtlCPAPI.dll 156672 bytes executable

scan completed successfully
hidden files: 1629

**************************************************************************
.
Completion time: 2009-09-18 13:37
ComboFix-quarantined-files.txt 2009-09-18 08:05

Pre-Run: 5,595,213,824 bytes free
Post-Run: 5,560,537,088 bytes free

Current=3 Default=3 Failed=2 LastKnownGood=4 Sets=1,2,3,4
1815

BC AdBot (Login to Remove)

 


#2 Shannon2012

Shannon2012

  • Security Colleague
  • 3,657 posts
  • OFFLINE
  •  
  • Gender:Male
  • Location:North Carolina, USA
  • Local time:04:09 AM

Posted 05 October 2009 - 07:24 AM

Hello and welcome to Bleeping Computer

We apologize for the delay in responding to your request for help. Here at Bleeping Computer we get overwhelmed at times, and we are trying our best to keep up. Please note that your topic was not intentionally overlooked. Our mission is to help everyone in need, but sometimes it takes just a little longer to get to every request for help. No one is ignored here.

If you have since resolved the original problem you were having, we would appreciate you letting us know. If not please perform the following steps below so we can have a look at the current condition of your machine.

If you have not done so, include a clear description of the problems you're having, along with any steps you may have performed so far.

Upon completing the steps below another staff member will review and take the steps necessary with you to get your machine back in working order clean and free of malware.

If you have already posted a DDS log, please do so again, as your situation may have changed.
Use the 'Add Reply' and add the new log to this thread.


Thanks and again sorry for the delay.

We need to see some information about what is happening in your machine. Please perform the following scan:
  • Download DDS by sUBs from one of the following links. Save it to your desktop.
  • Double click on the DDS icon, allow it to run.
  • A small box will open, with an explaination about the tool. No input is needed, the scan is running.
  • Notepad will open with the results.
  • Follow the instructions that pop up for posting the results.
  • Close the program window, and delete the program from your desktop.
Please note: You may have to disable any script protection running if the scan fails to run. After downloading the tool, disconnect from the internet and disable all antivirus protection. Run the scan, enable your A/V and reconnect to the internet.

Information on A/V control HERE
Shannon

#3 teacup61

teacup61

    Bleepin' Texan!


  • Malware Response Team
  • 17,075 posts
  • OFFLINE
  •  
  • Gender:Female
  • Location:Wills Point, Texas
  • Local time:03:09 AM

Posted 13 October 2009 - 07:20 PM

Due to the lack of feedback this Topic is closed.

If you need this topic reopened, please request this by sending the moderating team a PM with the address of the thread. This applies only to the original topic starter.

Everyone else please begin a New Topic
Please make a donation so I can keep helping people just like you.
Every little bit helps! :)
You can even use your credit card! Thank you!

Posted Image


Error reading poptart in Drive A: Delete kids y/n?




0 user(s) are reading this topic

0 members, 0 guests, 0 anonymous users