Jump to content


 


Register a free account to unlock additional features at BleepingComputer.com
Welcome to BleepingComputer, a free community where people like yourself come together to discuss and learn how to use their computers. Using the site is easy and fun. As a guest, you can browse and view the various discussions in the forums, but can not create a new topic or reply to an existing one unless you are logged in. Other benefits of registering an account are subscribing to topics and forums, creating a blog, and having no ads shown anywhere on the site.


Click here to Register a free account now! or read our Welcome Guide to learn how to use this site.

Photo

HJT Log - hrlyrbl


  • This topic is locked This topic is locked
11 replies to this topic

#1 hrlyrbl

hrlyrbl

  • Members
  • 8 posts
  • OFFLINE
  •  
  • Local time:12:55 AM

Posted 01 September 2005 - 10:59 AM

I have lots of adware and spyware on my computer. It is running really slow and keeps having to increase virtual memory. I really need help. I have tried to run spybot but it gets stuck on checking bots at number 636 and just stops there. I did run spy sweeper and it found numerous problems. I would clean or delete them but most of them would come right back. I have mcafee virus scan. It cleans most of the them but then they come right back again. Some of them can't be cleaned so I either quarantine or delete them depending on whether I know what it is. My sister told me to get on here and see if you could help me. My son has to use this computer for school work bcuz he has dylexia.





Logfile of HijackThis v1.99.1
Scan saved at 10:45:37 AM, on 9/1/2005
Platform: Windows XP SP1 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\csrss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\PROGRA~1\COMMON~1\AOL\ACS\acsd.exe
C:\WINDOWS\system32\cisvc.exe
c:\PROGRA~1\mcafee.com\vso\mcvsrte.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Webroot\Spy Sweeper\WRSSSDK.exe
C:\WINDOWS\system32\cmd.exe
C:\WINDOWS\System32\nfsiod.exe
C:\WINDOWS\System32\nfsiod.exe
C:\WINDOWS\explorer.exe
C:\WINDOWS\wanmpsvc.exe
C:\WINDOWS\System32\hkcmd.exe
C:\Program Files\HP\hpcoretech\hpcmpmgr.exe
C:\Program Files\MUSICMATCH\MUSICMATCH Jukebox\mm_tray.exe
C:\PROGRA~1\mcafee.com\agent\mcagent.exe
C:\PROGRA~1\mcafee.com\agent\mcupdate.exe
c:\PROGRA~1\mcafee.com\vso\mcshield.exe
C:\Program Files\Roxio\Easy CD Creator 5\DirectCD\DirectCD.exe
C:\PROGRA~1\mcafee.com\vso\mcvsshld.exe
c:\progra~1\mcafee.com\vso\mcvsescn.exe
C:\Program Files\Real\RealPlayer\RealPlay.exe
C:\Program Files\QuickTime\qttask.exe
C:\Program Files\Common Files\Microsoft Shared\Works Shared\WkUFind.exe
C:\Program Files\HP\HP Software Update\HPWuSchd2.exe
C:\PROGRA~1\McAfee.com\PERSON~1\MpfAgent.exe
C:\WINDOWS\System32\k44xpl.exe
C:\Program Files\Dell Support\DSAgnt.exe
C:\Program Files\Messenger\msmsgs.exe
C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe
c:\progra~1\mcafee.com\vso\mcvsftsn.exe
C:\WINDOWS\System32\HPZipm12.exe
C:\WINDOWS\system32\cidaemon.exe
C:\WINDOWS\system32\cidaemon.exe
C:\WINDOWS\system32\cmd.exe
C:\WINDOWS\explorer.exe
C:\Program Files\America Online 9.0\waol.exe
C:\Program Files\America Online 9.0\shellmon.exe
C:\Program Files\America Online 9.0\aolwbspd.exe
C:\Program Files\AOL Companion\companion.exe
C:\WINDOWS\system32\cmd.exe
C:\WINDOWS\explorer.exe
C:\WINDOWS\system32\cmd.exe
C:\WINDOWS\explorer.exe
C:\WINDOWS\system32\cmd.exe
C:\WINDOWS\explorer.exe
C:\WINDOWS\system32\cmd.exe
C:\WINDOWS\explorer.exe
C:\WINDOWS\system32\cmd.exe
C:\WINDOWS\explorer.exe
C:\Documents and Settings\Owner\Local Settings\Temp\Temporary Directory 2 for HijackThis.zip\HijackThis.exe
C:\WINDOWS\notepad.exe

R1 - HKCU\Software\Microsoft\Internet Explorer,SearchURL = http://searchmiracle.com/sp.php
R3 - Default URLSearchHook is missing
O1 - Hosts: 69.31.81.22 www.google.ae
O1 - Hosts: 69.31.81.22 www.google.am
O1 - Hosts: 69.31.81.22 www.google.as
O1 - Hosts: 69.31.81.22 www.google.at
O1 - Hosts: 69.31.81.22 www.google.az
O1 - Hosts: 69.31.81.22 www.google.be
O1 - Hosts: 69.31.81.22 www.google.bi
O1 - Hosts: 69.31.81.22 www.google.ca
O1 - Hosts: 69.31.81.22 www.google.cd
O1 - Hosts: 69.31.81.22 www.google.cg
O1 - Hosts: 69.31.81.22 www.google.ch
O1 - Hosts: 69.31.81.22 www.google.ci
O1 - Hosts: 69.31.81.22 www.google.cl
O1 - Hosts: 69.31.81.22 www.google.co.cr
O1 - Hosts: 69.31.81.22 www.google.co.hu
O1 - Hosts: 69.31.81.22 www.google.co.il
O1 - Hosts: 69.31.81.22 www.google.co.in
O1 - Hosts: 69.31.81.22 www.google.co.je
O1 - Hosts: 69.31.81.22 www.google.co.jp
O1 - Hosts: 69.31.81.22 www.google.co.ke
O1 - Hosts: 69.31.81.22 www.google.co.kr
O1 - Hosts: 69.31.81.22 www.google.co.ls
O1 - Hosts: 69.31.81.22 www.google.co.nz
O1 - Hosts: 69.31.81.22 www.google.co.th
O1 - Hosts: 69.31.81.22 www.google.co.ug
O1 - Hosts: 69.31.81.22 www.google.co.uk
O1 - Hosts: 69.31.81.22 www.google.co.ve
O1 - Hosts: 69.31.81.22 www.google.com
O1 - Hosts: 69.31.81.22 www.google.com.ag
O1 - Hosts: 69.31.81.22 www.google.com.ar
O1 - Hosts: 69.31.81.22 www.google.com.au
O1 - Hosts: 69.31.81.22 www.google.com.br
O1 - Hosts: 69.31.81.22 www.google.com.co
O1 - Hosts: 69.31.81.22 www.google.com.cu
O1 - Hosts: 69.31.81.22 www.google.com.do
O1 - Hosts: 69.31.81.22 www.google.com.ec
O1 - Hosts: 69.31.81.22 www.google.com.fj
O1 - Hosts: 69.31.81.22 www.google.com.gi
O1 - Hosts: 69.31.81.22 www.google.com.gr
O1 - Hosts: 69.31.81.22 www.google.com.gt
O1 - Hosts: 69.31.81.22 www.google.com.hk
O1 - Hosts: 69.31.81.22 www.google.com.ly
O1 - Hosts: 69.31.81.22 www.google.com.mt
O1 - Hosts: 69.31.81.22 www.google.com.mx
O1 - Hosts: 69.31.81.22 www.google.com.my
O1 - Hosts: 69.31.81.22 www.google.com.na
O1 - Hosts: 69.31.81.22 www.google.com.nf
O1 - Hosts: 69.31.81.22 www.google.com.ni
O1 - Hosts: 69.31.81.22 www.google.com.np
O1 - Hosts: 69.31.81.22 www.google.com.pa
O1 - Hosts: 69.31.81.22 www.google.com.pe
O1 - Hosts: 69.31.81.22 www.google.com.ph
O1 - Hosts: 69.31.81.22 www.google.com.pk
O1 - Hosts: 69.31.81.22 www.google.com.pr
O1 - Hosts: 69.31.81.22 www.google.com.py
O1 - Hosts: 69.31.81.22 www.google.com.sa
O1 - Hosts: 69.31.81.22 www.google.com.sg
O1 - Hosts: 69.31.81.22 www.google.com.sv
O1 - Hosts: 69.31.81.22 www.google.com.tr
O1 - Hosts: 69.31.81.22 www.google.com.tw
O1 - Hosts: 69.31.81.22 www.google.com.ua
O1 - Hosts: 69.31.81.22 www.google.com.uy
O1 - Hosts: 69.31.81.22 www.google.com.vc
O1 - Hosts: 69.31.81.22 www.google.com.vn
O1 - Hosts: 69.31.81.22 www.google.de
O1 - Hosts: 69.31.81.22 www.google.dj
O1 - Hosts: 69.31.81.22 www.google.dk
O1 - Hosts: 69.31.81.22 www.google.es
O1 - Hosts: 69.31.81.22 www.google.fi
O1 - Hosts: 69.31.81.22 www.google.fm
O1 - Hosts: 69.31.81.22 www.google.fr
O1 - Hosts: 69.31.81.22 www.google.gg
O1 - Hosts: 69.31.81.22 www.google.gl
O1 - Hosts: 69.31.81.22 www.google.gm
O1 - Hosts: 69.31.81.22 www.google.hn
O1 - Hosts: 69.31.81.22 www.google.ie
O1 - Hosts: 69.31.81.22 www.google.it
O1 - Hosts: 69.31.81.22 www.google.kz
O1 - Hosts: 69.31.81.22 www.google.li
O1 - Hosts: 69.31.81.22 www.google.lt
O1 - Hosts: 69.31.81.22 www.google.lu
O1 - Hosts: 69.31.81.22 www.google.lv
O1 - Hosts: 69.31.81.22 www.google.mn
O1 - Hosts: 69.31.81.22 www.google.ms
O1 - Hosts: 69.31.81.22 www.google.mu
O1 - Hosts: 69.31.81.22 www.google.mw
O1 - Hosts: 69.31.81.22 www.google.nl
O1 - Hosts: 69.31.81.22 www.google.no
O1 - Hosts: 69.31.81.22 www.google.off.ai
O1 - Hosts: 69.31.81.22 www.google.pl
O1 - Hosts: 69.31.81.22 www.google.pn
O1 - Hosts: 69.31.81.22 www.google.pt
O1 - Hosts: 69.31.81.22 www.google.ro
O1 - Hosts: 69.31.81.22 www.google.ru
O1 - Hosts: 69.31.81.22 www.google.rw
O1 - Hosts: 69.31.81.22 www.google.se
O1 - Hosts: 69.31.81.22 www.google.sh
O1 - Hosts: 69.31.81.22 www.google.sk
O1 - Hosts: 69.31.81.22 www.google.sm
O1 - Hosts: 69.31.81.22 www.google.td
O1 - Hosts: 69.31.81.22 www.google.tm
O2 - BHO: CExtension Object - {0019C3E2-DD48-4A6D-ABCD-8D32436323D9} - C:\WINDOWS\cfgmgr52.dll (file missing)
O3 - Toolbar: McAfee VirusScan - {BA52B914-B692-46c4-B683-905236F6F655} - c:\progra~1\mcafee.com\vso\mcvsshl.dll
O4 - HKLM\..\Run: [IgfxTray] C:\WINDOWS\System32\igfxtray.exe
O4 - HKLM\..\Run: [HotKeysCmds] C:\WINDOWS\System32\hkcmd.exe
O4 - HKLM\..\Run: [HP Component Manager] "C:\Program Files\HP\hpcoretech\hpcmpmgr.exe"
O4 - HKLM\..\Run: [MMTray] C:\Program Files\MUSICMATCH\MUSICMATCH Jukebox\mm_tray.exe
O4 - HKLM\..\Run: [MCAgentExe] c:\PROGRA~1\mcafee.com\agent\mcagent.exe files\mcafee.com\agent\mcagent.exe
O4 - HKLM\..\Run: [MCUpdateExe] C:\PROGRA~1\mcafee.com\agent\mcupdate.exe
O4 - HKLM\..\Run: [AdaptecDirectCD] "C:\Program Files\Roxio\Easy CD Creator 5\DirectCD\DirectCD.exe"
O4 - HKLM\..\Run: [VirusScan Online] "c:\PROGRA~1\mcafee.com\vso\mcvsshld.exe"
O4 - HKLM\..\Run: [RealTray] C:\Program Files\Real\RealPlayer\RealPlay.exe SYSTEMBOOTHIDEPLAYER
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [MPFExe] C:\PROGRA~1\McAfee.com\PERSON~1\MpfTray.exe
O4 - HKLM\..\Run: [Microsoft Works Update Detection] C:\Program Files\Common Files\Microsoft Shared\Works Shared\WkUFind.exe
O4 - HKLM\..\Run: [HP Software Update] C:\Program Files\HP\HP Software Update\HPWuSchd2.exe
O4 - HKLM\..\Run: [VBundleOuterDL] C:\Program Files\VBouncer\BundleOuter.EXE
O4 - HKLM\..\Run: [cfgmgr52] RunDLL32.EXE C:\WINDOWS\cfgmgr52.dll,DllRun
O4 - HKLM\..\Run: [PSGuard] C:\Program Files\PSGuard\PSGuard.exe
O4 - HKLM\..\Run: [IMJPMIG8.1] "C:\WINDOWS\IME\imjp8_1\IMJPMIG.EXE" /Spoil /RemAdvDef /Migration32
O4 - HKLM\..\Run: [CToolBar] TorontoMail.exe
O4 - HKLM\..\Run: [atl_helper] abrek.exe
O4 - HKLM\..\Run: [Media Access] C:\Program Files\Media Access\MediaAccK.exe
O4 - HKLM\..\Run: [SpySweeper] "C:\Program Files\Webroot\Spy Sweeper\SpySweeper.exe" /startintray
O4 - HKLM\..\Run: [winsync] C:\WINDOWS\System32\k44xpl.exe reg_run
O4 - HKLM\..\Run: [VSOCheckTask] "c:\PROGRA~1\mcafee.com\vso\mcmnhdlr.exe" /checktask
O4 - HKCU\..\Run: [Yahoo! Pager] C:\Program Files\Yahoo!\Messenger\ypager.exe -quiet
O4 - HKCU\..\Run: [DellSupport] "C:\Program Files\Dell Support\DSAgnt.exe" /startup
O4 - HKCU\..\Run: [WareOut] "C:\Program Files\WareOut\WareOut.exe"
O4 - HKCU\..\Run: [SYSTRAV] control64.exe
O4 - HKCU\..\Run: [uio] Brong32.exe
O4 - HKCU\..\Run: [ssweeper] KeywordFinder.exe
O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
O4 - Global Startup: Adobe Reader Speed Launch.lnk = C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
O4 - Global Startup: America Online 9.0 Tray Icon.lnk = C:\Program Files\America Online 9.0\aoltray.exe
O4 - Global Startup: AOL Companion.lnk = C:\Program Files\AOL Companion\companion.exe
O4 - Global Startup: HP Digital Imaging Monitor.lnk = C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe
O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office10\OSA.EXE
O8 - Extra context menu item: &Yahoo! Search - file:///C:\Program Files\Yahoo!\Common/ycsrch.htm
O8 - Extra context menu item: Yahoo! &Dictionary - file:///C:\Program Files\Yahoo!\Common/ycdict.htm
O8 - Extra context menu item: Yahoo! &Maps - file:///C:\Program Files\Yahoo!\Common/ycdict.htm
O9 - Extra button: Messenger - {4528BBE0-4E08-11D5-AD55-00010333D0AD} - C:\Program Files\Yahoo!\Messenger\yhexbmes0521.dll
O9 - Extra 'Tools' menuitem: Yahoo! Messenger - {4528BBE0-4E08-11D5-AD55-00010333D0AD} - C:\Program Files\Yahoo!\Messenger\yhexbmes0521.dll
O9 - Extra button: (no name) - {9E248641-0E24-4DDB-9A1F-705087832AD6} - C:\WINDOWS\System32\wuauclt.dll
O9 - Extra 'Tools' menuitem: Java - {9E248641-0E24-4DDB-9A1F-705087832AD6} - C:\WINDOWS\System32\wuauclt.dll
O9 - Extra button: Related - {c95fe080-8f5d-11d2-a20b-00aa003c157a} - C:\WINDOWS\web\related.htm
O9 - Extra 'Tools' menuitem: Show &Related Links - {c95fe080-8f5d-11d2-a20b-00aa003c157a} - C:\WINDOWS\web\related.htm
O9 - Extra button: Real.com - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - C:\WINDOWS\System32\Shdocvw.dll
O9 - Extra button: MoneySide - {E023F504-0C5A-4750-A1E7-A9046DEA8A21} - C:\Program Files\Microsoft Money\System\mnyside.dll
O9 - Extra button: PartyPoker.net - {F4430FE8-2638-42e5-B849-800749B94EED} - C:\Program Files\PartyPoker.net\partypokernet.exe
O9 - Extra 'Tools' menuitem: PartyPoker.net - {F4430FE8-2638-42e5-B849-800749B94EED} - C:\Program Files\PartyPoker.net\partypokernet.exe
O16 - DPF: Yahoo! Poker - http://download.games.yahoo.com/games/clients/y/pt3_x.cab
O16 - DPF: {42F2C9BA-614F-47C0-B3E3-ECFD34EED658} (Installer Class) - http://www.ysbweb.com/ist/softwares/v4.0/ysb_1002952.cab
O16 - DPF: {4ED9DDF0-7479-4BBE-9335-5A1EDB1D8A21} (McAfee.com Operating System Class) - http://download.mcafee.com/molbin/shared/m...84/mcinsctl.cab
O16 - DPF: {9522B3FB-7A2B-4646-8AF6-36E7F593073C} (cpbrkpie Control) - http://a19.g.akamai.net/7/19/7125/4047/ftp...23/cpbrkpie.cab
O16 - DPF: {BCC0FF27-31D9-4614-A68E-C18E1ADA4389} (DwnldGroupMgr Class) - http://download.mcafee.com/molbin/shared/m...,21/mcgdmgr.cab
O17 - HKLM\System\CCS\Services\Tcpip\..\{E6C69A60-ABF7-447F-82ED-E8B99779B384}: NameServer = 205.188.146.145
O20 - Winlogon Notify: igfxcui - C:\WINDOWS\SYSTEM32\igfxsrvc.dll
O23 - Service: AOL Connectivity Service (AOL ACS) - America Online, Inc. - C:\PROGRA~1\COMMON~1\AOL\ACS\acsd.exe
O23 - Service: McAfee.com McShield (McShield) - Unknown owner - c:\PROGRA~1\mcafee.com\vso\mcshield.exe
O23 - Service: McAfee SecurityCenter Update Manager (mcupdmgr.exe) - Networks Associates Technology, Inc - C:\PROGRA~1\McAfee.com\Agent\mcupdmgr.exe
O23 - Service: McAfee.com VirusScan Online Realtime Engine (MCVSRte) - Networks Associates Technology, Inc - c:\PROGRA~1\mcafee.com\vso\mcvsrte.exe
O23 - Service: McAfee.com Personal Firewall Service (MpfService) - McAfee.com Corporation - C:\PROGRA~1\McAfee.com\PERSON~1\MPFSERVICE.exe
O23 - Service: Pml Driver HPZ12 - HP - C:\WINDOWS\System32\HPZipm12.exe
O23 - Service: Webroot Spy Sweeper Engine (svcWRSSSDK) - Webroot Software, Inc. - C:\Program Files\Webroot\Spy Sweeper\WRSSSDK.exe
O23 - Service: WAN Miniport (ATW) Service (WANMiniportService) - America Online, Inc. - C:\WINDOWS\wanmpsvc.exe

BC AdBot (Login to Remove)

 


#2 Daemon

Daemon

    Security Expert


  • Members
  • 1,446 posts
  • OFFLINE
  •  
  • Gender:Male
  • Location:UK
  • Local time:05:55 AM

Posted 01 September 2005 - 01:04 PM

Click here to download the Hoster. Extract it from the zip file into a folder and doubleclick on hoster.exe. Press "Restore Original Hosts" and press "OK". Exit the program.

Click here to download FindQoologic-Narrator.

Save it to your Desktop then extract the files from the zip into their own folder called FindQoologic. Open the FindQoologic folder. Locate and double-click the Find-Qoologic.bat file to run it. Wait until a text opens, save it to your desktop, then post it in your next reply here.

Please Download the following tools to assist us in removing this infection!
  • Download WinPFind
    • Right Click the Zip Folder and Select "Extract All"
    • Extract it somewhere you will remember like the Desktop
    • Dont do anything with it yet!
  • Download Track qoo
    • Save it somewhere you will remember like the Desktop
Reboot into Safe Mode
Restart your computer and as soon as it starts booting up again continuously tap F8. A menu should come up where you will be given the option to enter Safe Mode.

Doubleclick WinPFind.exe
  • Click "Start Scan"
  • It will scan the entire System, so please be patient!
  • Once the Scan is Complete
  • Go to the WinPFind folder
  • Locate WinPFind.txt
  • Place those results in the next post!
Reboot back to Normal Mode!

Double Click on "Track qoo.vbs"

Note - If you Antivirus has Script Blocking, you will get a Pop Up Windows asking you what to do. Allow this Entire Script to Run, its harmless!

Wait a few seconds and a notepad page will pop up, Copy & Paste those results and place them in the next post along with the results of WinPFind!

So, I need 3 logs in your next reply: FindQoologic, WinPFind, and TrackQoo.
Posted Image

Have I helped you? Please consider donating to help me continue with the fight against malware. Click here

#3 hrlyrbl

hrlyrbl
  • Topic Starter

  • Members
  • 8 posts
  • OFFLINE
  •  
  • Local time:12:55 AM

Posted 07 September 2005 - 06:20 PM

WinPFind text:

WARNING: not all files found by this scanner are bad. Consult with a knowledgable person before proceeding.

If you see a message in the titlebar saying "Not responding..." you can ignore it. Windows somethimes displays this message due to the high volume of disk I/O. As long as the hard disk light is flashing, the program is still working properly.

»»»»»»»»»»»»»»»»» Windows OS and Versions »»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»
Product Name: Microsoft Windows XP Current Build: Service Pack 1 Current Build Number: 2600
Internet Explorer Version: 6.0.2800.1106

»»»»»»»»»»»»»»»»» Checking Selected Standard Folders »»»»»»»»»»»»»»»»»»»»

Checking %SystemDrive% folder...

Checking %ProgramFilesDir% folder...

Checking %WinDir% folder...
UPX! 9/1/2005 9:41:28 AM 266919936 C:\WINDOWS\MEMORY.DMP
FSG! 9/1/2005 9:41:28 AM 266919936 C:\WINDOWS\MEMORY.DMP
PEC2 9/1/2005 9:41:28 AM 266919936 C:\WINDOWS\MEMORY.DMP
Umonitor 9/1/2005 9:41:28 AM 266919936 C:\WINDOWS\MEMORY.DMP
qoologic 9/1/2005 9:41:28 AM 266919936 C:\WINDOWS\MEMORY.DMP
PTech 9/1/2005 9:41:28 AM 266919936 C:\WINDOWS\MEMORY.DMP
ad-beh 9/1/2005 9:41:28 AM 266919936 C:\WINDOWS\MEMORY.DMP
_rtneg3 9/1/2005 9:41:28 AM 266919936 C:\WINDOWS\MEMORY.DMP
SAHAgent 9/1/2005 9:41:28 AM 266919936 C:\WINDOWS\MEMORY.DMP
ZepMon 9/1/2005 9:41:28 AM 266919936 C:\WINDOWS\MEMORY.DMP
aurora.exe 9/1/2005 9:41:28 AM 266919936 C:\WINDOWS\MEMORY.DMP
KavSvc 9/1/2005 9:41:28 AM 266919936 C:\WINDOWS\MEMORY.DMP
69.59.186.63 9/1/2005 9:41:28 AM 266919936 C:\WINDOWS\MEMORY.DMP
209.66.67.134 9/1/2005 9:41:28 AM 266919936 C:\WINDOWS\MEMORY.DMP
66.63.167.97 9/1/2005 9:41:28 AM 266919936 C:\WINDOWS\MEMORY.DMP
66.63.167.77 9/1/2005 9:41:28 AM 266919936 C:\WINDOWS\MEMORY.DMP
abetterinternet.com 9/1/2005 9:41:28 AM 266919936 C:\WINDOWS\MEMORY.DMP
web-nex 9/1/2005 9:41:28 AM 266919936 C:\WINDOWS\MEMORY.DMP
yourkey 9/1/2005 9:41:28 AM 266919936 C:\WINDOWS\MEMORY.DMP
winsync 9/1/2005 9:41:28 AM 266919936 C:\WINDOWS\MEMORY.DMP
rec2_run 9/1/2005 9:41:28 AM 266919936 C:\WINDOWS\MEMORY.DMP
WinShutDown 9/1/2005 9:41:28 AM 266919936 C:\WINDOWS\MEMORY.DMP
UPX! 8/12/2005 5:30:30 AM 3072 C:\WINDOWS\uninstIU.exe

Checking %System% folder...
PEC2 9/3/2002 9:30:40 AM 41397 C:\WINDOWS\SYSTEM32\dfrg.msc
69.59.186.63 9/6/2005 11:27:50 AM 46080 C:\WINDOWS\SYSTEM32\dkkfssk.dll
209.66.67.134 9/6/2005 11:27:50 AM 46080 C:\WINDOWS\SYSTEM32\dkkfssk.dll
web-nex 9/6/2005 11:27:50 AM 46080 C:\WINDOWS\SYSTEM32\dkkfssk.dll
winsync 9/6/2005 11:27:50 AM 46080 C:\WINDOWS\SYSTEM32\dkkfssk.dll
69.59.186.63 9/6/2005 11:27:52 AM 10240 C:\WINDOWS\SYSTEM32\doora.dll
209.66.67.134 9/6/2005 11:27:52 AM 10240 C:\WINDOWS\SYSTEM32\doora.dll
web-nex 9/6/2005 11:27:52 AM 10240 C:\WINDOWS\SYSTEM32\doora.dll
winsync 9/6/2005 11:27:52 AM 10240 C:\WINDOWS\SYSTEM32\doora.dll
UPX! 8/15/2005 12:18:30 PM 25105 C:\WINDOWS\SYSTEM32\MTE2ODM6ODoxNg.exe
UPX! 9/3/2002 9:29:02 AM RHS 16392 C:\WINDOWS\SYSTEM32\nfsiod.exe
Umonitor 9/3/2002 9:54:44 AM 631808 C:\WINDOWS\SYSTEM32\rasdlg.dll
winsync 9/3/2002 10:10:48 AM 1309184 C:\WINDOWS\SYSTEM32\wbdbase.deu
69.59.186.63 8/30/2005 4:15:00 PM 30720 C:\WINDOWS\SYSTEM32\wuauclt.dll
209.66.67.134 8/30/2005 4:15:00 PM 30720 C:\WINDOWS\SYSTEM32\wuauclt.dll
66.63.167.97 8/30/2005 4:15:00 PM 30720 C:\WINDOWS\SYSTEM32\wuauclt.dll
66.63.167.77 8/30/2005 4:15:00 PM 30720 C:\WINDOWS\SYSTEM32\wuauclt.dll
web-nex 8/30/2005 4:15:00 PM 30720 C:\WINDOWS\SYSTEM32\wuauclt.dll
winsync 8/30/2005 4:15:00 PM 30720 C:\WINDOWS\SYSTEM32\wuauclt.dll
rec2_run 8/30/2005 4:15:00 PM 30720 C:\WINDOWS\SYSTEM32\wuauclt.dll

Checking %System%\Drivers folder and sub-folders...

Items found in C:\WINDOWS\SYSTEM32\drivers\etc\HOSTS


Checking the Windows folder and sub-folders for system and hidden files within the last 60 days...
9/6/2005 4:55:12 PM S 2048 C:\WINDOWS\bootstat.dat
9/6/2005 11:31:20 AM H 54156 C:\WINDOWS\QTFont.qfn
8/13/2005 9:58:10 PM RH 749 C:\WINDOWS\WindowsShell.Manifest
8/13/2005 9:58:20 PM H 65 C:\WINDOWS\Downloaded Program Files\desktop.ini
8/18/2005 6:09:36 AM HS 122 C:\WINDOWS\Favorites\Desktop.ini
8/13/2005 9:59:14 PM HS 67 C:\WINDOWS\Fonts\desktop.ini
8/13/2005 9:58:20 PM H 65 C:\WINDOWS\occache\desktop.ini
8/13/2005 9:58:22 PM H 65 C:\WINDOWS\Offline Web Pages\desktop.ini
8/13/2005 10:00:16 PM H 442368 C:\WINDOWS\repair\ntuser.dat
8/13/2005 9:58:10 PM RH 749 C:\WINDOWS\system32\cdplayer.exe.manifest
8/13/2005 9:58:20 PM RH 488 C:\WINDOWS\system32\logonui.exe.manifest
8/13/2005 9:58:10 PM RH 749 C:\WINDOWS\system32\ncpa.cpl.manifest
8/13/2005 9:58:10 PM RH 749 C:\WINDOWS\system32\nwc.cpl.manifest
8/13/2005 9:58:10 PM RH 749 C:\WINDOWS\system32\sapi.cpl.manifest
8/13/2005 9:58:20 PM RH 488 C:\WINDOWS\system32\WindowsLogon.manifest
8/13/2005 9:58:10 PM RH 749 C:\WINDOWS\system32\wuaucpl.cpl.manifest
9/6/2005 4:55:04 PM H 8192 C:\WINDOWS\system32\config\default.LOG
8/13/2005 2:45:46 PM H 0 C:\WINDOWS\system32\config\default.tmp.LOG
9/6/2005 4:55:24 PM H 1024 C:\WINDOWS\system32\config\SAM.LOG
9/6/2005 4:55:14 PM H 12288 C:\WINDOWS\system32\config\SECURITY.LOG
9/6/2005 4:56:26 PM H 147456 C:\WINDOWS\system32\config\software.LOG
8/13/2005 2:45:44 PM H 0 C:\WINDOWS\system32\config\software.tmp.LOG
9/6/2005 4:55:18 PM H 716800 C:\WINDOWS\system32\config\system.LOG
8/13/2005 2:44:56 PM H 0 C:\WINDOWS\system32\config\system.tmp.LOG
8/13/2005 2:44:54 PM H 1024 C:\WINDOWS\system32\config\TempKey.LOG
8/13/2005 2:45:46 PM H 1024 C:\WINDOWS\system32\config\userdiff.LOG
8/13/2005 10:00:22 PM H 1024 C:\WINDOWS\system32\config\userdifr.LOG
9/6/2005 4:54:00 PM H 6 C:\WINDOWS\Tasks\SA.DAT
8/18/2005 9:40:54 AM H 102 C:\WINDOWS\Temp\CS003E9758-BCB1-44EC-B3EF-05C99FA8DB82.tmp
8/16/2005 1:35:10 PM H 72148 C:\WINDOWS\Temp\CS00731E64-BE9E-42BD-93D2-0DFA802B3EBD.tmp
8/23/2005 3:37:26 AM H 10 C:\WINDOWS\Temp\CS014D23BA-54EA-49AA-9316-3C51FAB00FA6.tmp
8/18/2005 8:44:54 AM H 68 C:\WINDOWS\Temp\CS0155420E-4F26-46C7-8C3B-A8422768A9D7.tmp
8/16/2005 11:37:16 AM H 39450 C:\WINDOWS\Temp\CS0162767D-F89B-4BF1-A35B-2C4369599E19.tmp
8/17/2005 11:12:02 PM H 128 C:\WINDOWS\Temp\CS01694842-4FFF-4455-B821-98594A1ED99E.tmp
8/16/2005 10:43:44 AM H 10 C:\WINDOWS\Temp\CS01765A9C-DFD9-4A8D-9345-0565C4E553D3.tmp
8/18/2005 9:40:54 AM H 10 C:\WINDOWS\Temp\CS01E07469-20C6-414B-A10C-5006E73F046E.tmp
8/18/2005 9:23:22 AM H 128 C:\WINDOWS\Temp\CS02163834-D21D-436A-9BC8-5D2789807DD1.tmp
8/18/2005 9:23:22 AM H 160 C:\WINDOWS\Temp\CS02487C72-C074-4C03-96E2-19140410F61C.tmp
8/15/2005 4:47:28 PM H 38178 C:\WINDOWS\Temp\CS02A1AF4E-9D5C-424F-BD24-DF6D92B12704.tmp
8/15/2005 5:33:52 PM H 23268 C:\WINDOWS\Temp\CS0373DE89-97DA-41E5-91F2-54383AE8BCE4.tmp
8/17/2005 11:12:02 PM H 204 C:\WINDOWS\Temp\CS03751FF2-170F-4694-924E-C4435F5C7952.tmp
8/26/2005 7:21:58 PM H 42 C:\WINDOWS\Temp\CS03D3AA9F-78E5-4117-AF6E-AE01AE454F25.tmp
8/16/2005 11:41:20 AM H 354088 C:\WINDOWS\Temp\CS041F291A-9B43-461B-BB9C-18EEF55C978E.tmp
8/18/2005 9:40:54 AM H 120 C:\WINDOWS\Temp\CS0452E0F9-124D-4A10-B91E-138507F3CA0E.tmp
8/16/2005 4:59:52 PM H 128 C:\WINDOWS\Temp\CS048758EE-CC0F-497A-8415-7836EBBBF072.tmp
8/27/2005 1:11:54 PM H 10 C:\WINDOWS\Temp\CS04FB626A-336E-4223-BBF6-CAD00E303095.tmp
8/15/2005 5:44:38 PM H 1269554 C:\WINDOWS\Temp\CS050E773D-D83C-4B2C-87D4-11F2746514F6.tmp
8/16/2005 11:37:16 AM H 306 C:\WINDOWS\Temp\CS05596691-6DAD-4C20-B506-74800AC60D83.tmp
8/23/2005 3:12:22 PM H 748 C:\WINDOWS\Temp\CS05600702-9BC5-4FF5-A603-C4D558AD39B3.tmp
8/16/2005 10:43:44 AM H 10 C:\WINDOWS\Temp\CS05BE233F-4BBD-4417-98E9-CAD48FFE6CF5.tmp
8/16/2005 6:17:08 PM H 10 C:\WINDOWS\Temp\CS061B71A6-D899-45ED-9F3D-227156D7EACD.tmp
8/27/2005 1:11:54 PM H 10 C:\WINDOWS\Temp\CS0626991C-4D75-4B2E-8652-1B70703BB5D4.tmp
8/23/2005 4:11:00 PM H 0 C:\WINDOWS\Temp\CS06314A9A-7446-4CBD-A0ED-ECF21032B7FA.tmp
8/26/2005 7:21:58 PM H 10 C:\WINDOWS\Temp\CS063A3A6E-C464-4C87-83F1-94078A364B94.tmp
8/16/2005 10:43:44 AM H 474 C:\WINDOWS\Temp\CS06710F7F-417E-4F71-9A96-411C6D0A489A.tmp
8/15/2005 5:44:38 PM H 204 C:\WINDOWS\Temp\CS06956DA9-0447-4402-94A1-102304769E76.tmp
8/23/2005 3:12:24 PM H 973372 C:\WINDOWS\Temp\CS069F1136-448A-4F37-A82E-A3A661B3E70C.tmp
8/16/2005 6:14:46 PM H 128 C:\WINDOWS\Temp\CS071D4E04-5C61-46E9-8AE3-7ECE84A5143B.tmp
8/18/2005 9:23:22 AM H 30 C:\WINDOWS\Temp\CS072FD9EA-90F0-43A6-A939-8C2C878C79D1.tmp
8/18/2005 9:23:22 AM H 6426 C:\WINDOWS\Temp\CS073FB951-5574-4DFF-A900-CC226E29667B.tmp
8/18/2005 9:40:54 AM H 10 C:\WINDOWS\Temp\CS075F2F02-CCEA-4903-BBC0-5BFB74A2FF86.tmp
8/16/2005 10:43:44 AM H 0 C:\WINDOWS\Temp\CS079BF77A-CA01-4CDB-B524-07E84F943F38.tmp
8/27/2005 1:11:54 PM H 196 C:\WINDOWS\Temp\CS07AD4685-8054-4880-ADBB-F4CF0037535E.tmp
8/18/2005 9:24:30 AM H 402 C:\WINDOWS\Temp\CS07E38C36-E85D-4937-985A-910D60B5F0A0.tmp
8/16/2005 6:17:08 PM H 100 C:\WINDOWS\Temp\CS088F8F12-7BC3-4490-8F7E-BE8E368D07C8.tmp
8/15/2005 5:39:56 PM H 30 C:\WINDOWS\Temp\CS08CD63B2-A3E1-4810-9E6E-888381F31BD7.tmp
8/26/2005 7:21:58 PM H 162 C:\WINDOWS\Temp\CS08E52904-2B11-4386-9A9E-D9AC563E0DE1.tmp
8/16/2005 6:14:46 PM H 1269554 C:\WINDOWS\Temp\CS0A04DD4D-3D22-421D-AEAD-528F3771B33E.tmp
8/16/2005 11:37:16 AM H 545542 C:\WINDOWS\Temp\CS0A226474-5D24-444E-8BB2-609FA05BAA66.tmp
8/16/2005 4:24:14 PM H 10 C:\WINDOWS\Temp\CS0A3854B3-52B5-4550-96E4-FD3B7EA16A32.tmp
8/18/2005 9:39:16 AM H 240 C:\WINDOWS\Temp\CS0AC783E6-7857-4834-AB33-856267524D52.tmp
8/16/2005 4:24:12 PM H 10 C:\WINDOWS\Temp\CS0B01BFEA-5595-4194-ACC4-DB8F616F933C.tmp
8/18/2005 9:24:34 AM H 10 C:\WINDOWS\Temp\CS0BA4E7FA-F2D9-42E4-BC47-882BC29A860E.tmp
8/16/2005 4:24:12 PM H 10 C:\WINDOWS\Temp\CS0C281136-5767-48FF-B4E9-68FD680CAFCE.tmp
8/15/2005 4:47:28 PM H 2016 C:\WINDOWS\Temp\CS0C6A9E5B-ACE1-4F65-87C8-81E549AFFDF7.tmp
8/16/2005 10:43:44 AM H 10 C:\WINDOWS\Temp\CS0C7812E0-7582-4E84-A63E-EB0CD44BF3D8.tmp
8/18/2005 9:24:26 AM H 30 C:\WINDOWS\Temp\CS0CA19FBE-C04E-4489-8EED-D12BC19F08C8.tmp
8/26/2005 7:21:58 PM H 640 C:\WINDOWS\Temp\CS0D338FA1-66AB-4E2D-AFAD-F4EE011EF962.tmp
8/16/2005 6:17:08 PM H 498 C:\WINDOWS\Temp\CS0D73925F-914E-44E2-B1BE-3B69AA9B5746.tmp
8/16/2005 10:43:44 AM H 10 C:\WINDOWS\Temp\CS0DA1CF6B-5238-4258-A0B6-3EFB2EAC40FC.tmp
8/27/2005 1:11:54 PM H 10 C:\WINDOWS\Temp\CS0E0816DE-30BE-4BE8-A36D-B214693ED24C.tmp
8/17/2005 10:40:36 PM H 10 C:\WINDOWS\Temp\CS0E09D141-8731-481C-9915-C09F92562292.tmp
8/18/2005 9:24:34 AM H 196 C:\WINDOWS\Temp\CS0E2894BA-DAA4-417C-B9EC-5B93A3FD548B.tmp
8/27/2005 1:11:54 PM H 124 C:\WINDOWS\Temp\CS0E63E238-735B-4AE9-9722-D5239AAC5E7A.tmp
8/27/2005 1:11:54 PM H 10 C:\WINDOWS\Temp\CS0E7571E3-5490-4E5B-8E75-E064548451E0.tmp
8/15/2005 5:39:56 PM H 540 C:\WINDOWS\Temp\CS0EC788A6-3312-426C-91E9-A968DFD823E0.tmp
8/18/2005 8:44:54 AM H 0 C:\WINDOWS\Temp\CS0EEA1213-BDEA-45F5-972A-0B2D7C8C3823.tmp
8/16/2005 4:59:52 PM H 160 C:\WINDOWS\Temp\CS0F01328C-392D-4255-8880-63D96C1A2AC3.tmp
8/18/2005 9:56:38 AM H 1269554 C:\WINDOWS\Temp\CS0F01E2DA-AA12-4982-A0F1-8E6DDE0F4B0E.tmp
8/27/2005 8:14:22 AM H 549780 C:\WINDOWS\Temp\CS0F115F13-7582-4EE7-A5B8-0D3AC74C7895.tmp
8/18/2005 9:23:22 AM H 306 C:\WINDOWS\Temp\CS0F4F9230-A695-4A1B-81B9-D134769D438E.tmp
8/15/2005 5:39:56 PM H 0 C:\WINDOWS\Temp\CS0F9D80F0-3269-47C7-A297-31FDDB0FA528.tmp
8/17/2005 11:12:02 PM H 38178 C:\WINDOWS\Temp\CS0FAB2907-0BFE-487F-A18B-163866E951F7.tmp
8/27/2005 1:11:54 PM H 10 C:\WINDOWS\Temp\CS0FFBE283-FAE6-44DD-8D1D-7DA2052CD4F8.tmp
8/18/2005 8:44:54 AM H 48 C:\WINDOWS\Temp\CS100AC7EE-F72A-4606-8DCE-DF5B77BFD49A.tmp
8/15/2005 5:33:52 PM H 32 C:\WINDOWS\Temp\CS1061EDC1-9DB6-46FA-B5CA-E1FD79BF1A9A.tmp
8/18/2005 9:23:22 AM H 1055442 C:\WINDOWS\Temp\CS10F4C4CA-9FC9-4211-86E9-545E67F6092D.tmp
8/17/2005 11:17:04 PM H 80614 C:\WINDOWS\Temp\CS11103D94-220F-48A3-B940-1D8B0AEA0420.tmp
8/18/2005 9:56:38 AM H 306 C:\WINDOWS\Temp\CS114F695B-6B03-429B-9570-B58C7E0A1265.tmp
8/17/2005 10:40:34 PM H 120 C:\WINDOWS\Temp\CS12B70525-44F0-4F32-82C1-615E264A498A.tmp
8/17/2005 11:22:06 PM H 548 C:\WINDOWS\Temp\CS12F631F9-A449-419D-8AAA-56F98C2E35D9.tmp
8/17/2005 10:40:36 PM H 10 C:\WINDOWS\Temp\CS130374DF-7188-495B-9F9B-819D9AB5BB96.tmp
8/23/2005 3:37:26 AM H 30 C:\WINDOWS\Temp\CS131A309D-E627-46E1-8F2A-8E04EC50F870.tmp
8/18/2005 9:40:54 AM H 114 C:\WINDOWS\Temp\CS1325D5A3-B415-46EB-B4B7-AB442177C4AD.tmp
8/18/2005 9:40:54 AM H 10 C:\WINDOWS\Temp\CS133EE6A9-18C4-48D3-AE5A-2D7672F9A372.tmp
8/17/2005 10:40:36 PM H 100 C:\WINDOWS\Temp\CS1355834A-3878-4AB5-AC3F-9C054FAEFF46.tmp
8/23/2005 4:11:02 PM H 10 C:\WINDOWS\Temp\CS136E040F-2C08-4275-92A8-0C6B17158698.tmp
8/15/2005 5:39:56 PM H 0 C:\WINDOWS\Temp\CS1395C4BB-1EEA-4A5D-B84F-EB62E93CD120.tmp
8/16/2005 4:59:52 PM H 204 C:\WINDOWS\Temp\CS140928BC-A2E4-433B-9CAB-6C007A4024DF.tmp
8/26/2005 7:21:58 PM H 100 C:\WINDOWS\Temp\CS143005BB-8538-4051-AB4C-F1EF77793B48.tmp
8/18/2005 8:44:56 AM H 10 C:\WINDOWS\Temp\CS15812126-22B8-4A7E-8CD5-B2BF4827355D.tmp
8/15/2005 5:44:38 PM H 5464 C:\WINDOWS\Temp\CS15B36BE7-9FAA-4541-8F0A-7F0BCA12D0B9.tmp
8/18/2005 9:40:54 AM H 10 C:\WINDOWS\Temp\CS15D3E736-2BEB-48FB-BDB7-71EB24E2891C.tmp
8/27/2005 8:14:22 AM H 103056 C:\WINDOWS\Temp\CS16384E99-821D-44EB-B33C-31C31302C123.tmp
8/18/2005 9:24:32 AM H 68 C:\WINDOWS\Temp\CS16DD17EC-4AF7-499C-84B1-CFE1C33E4B7A.tmp
8/16/2005 6:17:08 PM H 114 C:\WINDOWS\Temp\CS173252F6-B607-4553-A86E-2720E8B76E2C.tmp
8/23/2005 3:12:22 PM H 0 C:\WINDOWS\Temp\CS17329121-3D2B-41C4-85B0-EA490CFD4C39.tmp
8/16/2005 4:24:12 PM H 10 C:\WINDOWS\Temp\CS1741ED09-7FB9-45F0-B071-FE3A32E1C7D7.tmp
8/23/2005 3:37:26 AM H 10 C:\WINDOWS\Temp\CS174540E9-CBF2-425E-9DF2-6170ABCAB0D0.tmp
8/18/2005 9:40:54 AM H 10 C:\WINDOWS\Temp\CS17763F4B-C09C-479D-A514-DBD48678537E.tmp
8/15/2005 4:47:28 PM H 2146620 C:\WINDOWS\Temp\CS178FD606-7D2F-490B-87DF-1C6D0D74E104.tmp
8/18/2005 9:40:54 AM H 136 C:\WINDOWS\Temp\CS18218F6D-22DE-4B76-9500-694F34903BD2.tmp
8/17/2005 10:35:56 PM H 545542 C:\WINDOWS\Temp\CS1864DBF3-EA38-4C8C-81F7-207E33C10A35.tmp
8/17/2005 10:40:36 PM H 100 C:\WINDOWS\Temp\CS18A055C4-5B5F-415D-9024-309583076AD4.tmp
8/16/2005 6:14:46 PM H 5464 C:\WINDOWS\Temp\CS198F0CCD-4159-428C-ADD0-F4A52C0DDFA5.tmp
8/18/2005 8:44:54 AM H 48 C:\WINDOWS\Temp\CS1994CD1B-1860-488A-9FB2-A685E99D4A5A.tmp
8/23/2005 3:37:26 AM H 10 C:\WINDOWS\Temp\CS1A0DB15B-5DAA-4A7D-8E70-D3A6BA5788A8.tmp
8/23/2005 4:11:02 PM H 42 C:\WINDOWS\Temp\CS1A3C3BD0-CECD-4E39-84E3-F96778283700.tmp
8/15/2005 5:44:38 PM H 2016 C:\WINDOWS\Temp\CS1A40FB9F-D517-43F0-908E-2E07503619A3.tmp
8/23/2005 3:12:24 PM H 1450538 C:\WINDOWS\Temp\CS1A542F27-2DAC-475F-9212-376966DBEDA2.tmp
8/16/2005 6:14:46 PM H 101690 C:\WINDOWS\Temp\CS1A5E0229-CEE4-4973-9537-DF10A3909A8F.tmp
8/27/2005 1:11:54 PM H 408 C:\WINDOWS\Temp\CS1A5E8388-FA62-454E-A404-431D80F56148.tmp
8/16/2005 4:24:12 PM H 10 C:\WINDOWS\Temp\CS1A6BA61E-CC9E-4254-A8B1-483A7A40C110.tmp
8/15/2005 5:39:56 PM H 240 C:\WINDOWS\Temp\CS1A82E841-C015-4577-8792-1F67F04382B4.tmp
8/16/2005 11:37:16 AM H 30 C:\WINDOWS\Temp\CS1AA35FDF-AD80-4A70-B9C6-0FAB9EC6BE12.tmp
8/16/2005 10:43:44 AM H 14 C:\WINDOWS\Temp\CS1AB3542D-C76F-4D51-B6F0-ACDC1F94E6B7.tmp
8/27/2005 8:15:34 AM H 80570 C:\WINDOWS\Temp\CS1ACA93C8-11A8-4947-8EC9-3C13F86EEF89.tmp
8/17/2005 10:35:56 PM H 973372 C:\WINDOWS\Temp\CS1AE44BD3-9B2E-40F7-B445-33E743FF3020.tmp
8/16/2005 10:43:44 AM H 10 C:\WINDOWS\Temp\CS1AF95C74-A2F1-4091-847B-4464276E947A.tmp
8/15/2005 5:44:38 PM H 973372 C:\WINDOWS\Temp\CS1AFB074C-3B08-4494-93A6-72E3AC4F0F24.tmp
8/17/2005 10:40:36 PM H 10 C:\WINDOWS\Temp\CS1B3F7FD9-FC03-4484-AC00-2516343E368E.tmp
8/23/2005 4:11:00 PM H 10 C:\WINDOWS\Temp\CS1B47BA27-2E5F-4176-96BA-C911A98BAE7C.tmp
8/23/2005 4:11:00 PM H 376 C:\WINDOWS\Temp\CS1B5391BD-C011-4D1A-A22E-78DCAD397448.tmp
8/17/2005 10:40:36 PM H 48 C:\WINDOWS\Temp\CS1B73CD46-CBC6-48F9-BEC8-42EC8C35ECE1.tmp
8/17/2005 10:35:56 PM H 2016 C:\WINDOWS\Temp\CS1BCC6AFB-AAFF-433C-A731-BB8DE44443B4.tmp
8/27/2005 1:11:54 PM H 10 C:\WINDOWS\Temp\CS1BFA1F7E-3FD4-4958-A802-068C2B21313F.tmp
8/16/2005 6:17:08 PM H 10 C:\WINDOWS\Temp\CS1C7D77EF-BF13-4D8E-977F-B7D386F2017E.tmp
8/16/2005 6:14:46 PM H 306 C:\WINDOWS\Temp\CS1CB4A667-BAE0-4EA6-9CE9-C23E682BD234.tmp
8/18/2005 8:44:54 AM H 10 C:\WINDOWS\Temp\CS1CB804CB-8BC0-4B89-BEA2-0B2534446262.tmp
8/16/2005 4:59:52 PM H 1494 C:\WINDOWS\Temp\CS1CCDACFF-3F9A-40B4-9E0E-1554DB24AF1D.tmp
8/27/2005 8:14:22 AM H 240 C:\WINDOWS\Temp\CS1CDB28D3-EAC1-428A-9791-111A20D0B88E.tmp
8/18/2005 9:23:22 AM H 39450 C:\WINDOWS\Temp\CS1D34F349-546C-4A31-B6A5-EAC851948173.tmp
8/17/2005 11:16:42 PM H 1357036 C:\WINDOWS\Temp\CS1D3C58EE-3708-4B62-A63A-F4AF5830C0E3.tmp
8/23/2005 4:11:00 PM H 334 C:\WINDOWS\Temp\CS1D3CF15B-4F08-4BA5-B86A-EF59CA5E375D.tmp
8/18/2005 9:24:26 AM H 10 C:\WINDOWS\Temp\CS1D71D10C-21E1-409F-AB84-7D9B6F2CD0F3.tmp
8/18/2005 9:39:16 AM H 160 C:\WINDOWS\Temp\CS1DF2A4ED-E274-464F-A735-9080AA117A27.tmp
8/18/2005 8:44:54 AM H 0 C:\WINDOWS\Temp\CS1E234179-A70A-4494-BB91-DFF79CCAC02C.tmp
8/27/2005 1:11:54 PM H 162 C:\WINDOWS\Temp\CS1E285E6F-B8ED-45AA-9580-FE611E89DC89.tmp
8/18/2005 8:44:54 AM H 42 C:\WINDOWS\Temp\CS1E8B29D4-9D11-4C0E-800B-AF1FB3581465.tmp
8/18/2005 9:40:54 AM H 10 C:\WINDOWS\Temp\CS1EB01853-FEB8-4B60-A2B4-8088B5EFA770.tmp
8/16/2005 4:59:50 PM H 0 C:\WINDOWS\Temp\CS1EC9F584-8B81-405F-B9DF-BCD44096CF48.tmp
8/23/2005 3:37:26 AM H 162 C:\WINDOWS\Temp\CS1F09632C-4619-4ABE-A985-2C7171F2D2A5.tmp
8/18/2005 9:56:34 AM H 0 C:\WINDOWS\Temp\CS1F20956C-D385-47C5-9127-79758F213BD1.tmp
8/18/2005 9:40:54 AM H 48 C:\WINDOWS\Temp\CS1F233AA1-6D9A-431D-BE43-74DF803A0D18.tmp
8/23/2005 3:37:26 AM H 10 C:\WINDOWS\Temp\CS1F984072-5CA0-4F67-B59A-E417B9A489A5.tmp
8/23/2005 3:37:26 AM H 10 C:\WINDOWS\Temp\CS1FC7EDEF-54E4-49E1-A461-12D46DB74399.tmp
8/16/2005 10:43:44 AM H 196 C:\WINDOWS\Temp\CS1FD475E2-D02F-461C-9917-CEE9036C1490.tmp
8/26/2005 7:21:58 PM H 100 C:\WINDOWS\Temp\CS1FFB2D8D-CC29-40CB-A595-A26DDA080948.tmp
8/15/2005 5:33:52 PM H 5464 C:\WINDOWS\Temp\CS20362531-F1A4-409C-9419-8C46F0CBEFBF.tmp
8/15/2005 5:49:42 PM H 1357036 C:\WINDOWS\Temp\CS205ACAEF-93A7-4585-8979-D160625D6D5A.tmp
8/18/2005 8:44:54 AM H 136 C:\WINDOWS\Temp\CS20E0990C-1F51-4E8B-AAD6-C331ED4A13A7.tmp
8/16/2005 4:24:12 PM H 334 C:\WINDOWS\Temp\CS21860E02-D433-46C7-BD22-0C79262B49DA.tmp
8/15/2005 5:44:38 PM H 748 C:\WINDOWS\Temp\CS222D01D0-66B9-484C-80DA-04772DF92EB8.tmp
8/18/2005 9:56:38 AM H 2016 C:\WINDOWS\Temp\CS22BDE6DA-695D-4C69-A6F6-95CC6F154D02.tmp
8/16/2005 10:43:44 AM H 50 C:\WINDOWS\Temp\CS2349F905-CE7F-4E93-AD3D-4ACB3709A20E.tmp
8/16/2005 6:14:46 PM H 160 C:\WINDOWS\Temp\CS237819E0-D7B2-4256-BEA8-CB7A55FBD484.tmp
8/27/2005 1:11:54 PM H 120 C:\WINDOWS\Temp\CS2381DD93-CC40-4FE5-B9ED-F14CDBD51583.tmp
8/16/2005 10:43:44 AM H 48 C:\WINDOWS\Temp\CS2395DA23-5428-4BF6-A00E-88994879E998.tmp
8/16/2005 4:24:12 PM H 68 C:\WINDOWS\Temp\CS239F43F0-297D-4B5A-97AE-C5C7CE793075.tmp
8/18/2005 8:44:54 AM H 0 C:\WINDOWS\Temp\CS23AB6B6B-5E0C-4B98-A46E-DA98EB714D1C.tmp
8/26/2005 7:21:58 PM H 10 C:\WINDOWS\Temp\CS23AF092D-9BBD-4DF4-AC96-F33ABAD13FE0.tmp
8/23/2005 4:11:02 PM H 10 C:\WINDOWS\Temp\CS23BD1F13-6740-4E78-96B3-909140060C16.tmp
8/18/2005 8:44:54 AM H 0 C:\WINDOWS\Temp\CS23F0E414-0B0F-4594-BAC1-6752D08515D7.tmp
8/16/2005 10:43:44 AM H 100 C:\WINDOWS\Temp\CS2481B7B3-872E-4E16-B3D4-098D072217FD.tmp
8/18/2005 9:24:26 AM H 10 C:\WINDOWS\Temp\CS24928EB2-E6D3-4519-9F7C-4CB83F52D1F9.tmp
8/18/2005 8:44:56 AM H 50 C:\WINDOWS\Temp\CS24E1996F-89A0-4795-BD29-8C59DADFBBD1.tmp
8/16/2005 10:43:44 AM H 68 C:\WINDOWS\Temp\CS250A6954-95A5-406B-8C3D-0F813B2993ED.tmp
8/18/2005 8:44:54 AM H 0 C:\WINDOWS\Temp\CS258DE3AE-38E6-435F-A4FA-56AAB1F3CC75.tmp
8/18/2005 9:24:32 AM H 100 C:\WINDOWS\Temp\CS2597084C-0C71-4F27-8262-CFEEC7F21C11.tmp
8/16/2005 4:24:14 PM H 10 C:\WINDOWS\Temp\CS25C1995A-11C2-4AB9-BC1C-FCD4F08514BD.tmp
8/27/2005 8:15:30 AM H 1685142 C:\WINDOWS\Temp\CS25CFE72F-EC99-4CB8-8A99-7E8ECF977BEC.tmp
8/15/2005 5:44:38 PM H 30 C:\WINDOWS\Temp\CS260B61D1-C295-4B4D-A0EE-BA06AE85ED28.tmp
8/18/2005 8:44:56 AM H 124 C:\WINDOWS\Temp\CS26A03D67-357B-4D34-AD4F-8ED6BF5BC745.tmp
8/16/2005 4:24:12 PM H 42 C:\WINDOWS\Temp\CS26DD517F-9232-4F8F-956D-2782F4B28705.tmp
8/27/2005 1:11:54 PM H 10 C:\WINDOWS\Temp\CS272A8E20-8DEF-498C-B79D-E808DDA3A328.tmp
8/16/2005 4:59:52 PM H 39450 C:\WINDOWS\Temp\CS277FBEE1-171D-40AF-834B-5BD020B4F950.tmp
8/17/2005 10:40:34 PM H 42 C:\WINDOWS\Temp\CS281270D3-BA77-41AA-B2E9-92F06520E0F7.tmp
8/18/2005 9:24:34 AM H 10 C:\WINDOWS\Temp\CS2825C63B-EF87-474B-B1AC-6E9ABF5291C7.tmp
8/18/2005 9:24:32 AM H 10 C:\WINDOWS\Temp\CS28BAFA3E-E017-45FA-A095-005C5EA3F808.tmp
8/18/2005 9:24:30 AM H 102 C:\WINDOWS\Temp\CS28C6FF6C-CE5C-4671-9C4F-361DF31F432D.tmp
8/17/2005 10:40:34 PM H 96 C:\WINDOWS\Temp\CS28CCB5B7-DF1E-4A4B-BEFC-414378598D2A.tmp
8/18/2005 9:40:54 AM H 10 C:\WINDOWS\Temp\CS28DC94CF-6FA9-4627-8AC8-E880623E05E5.tmp
8/18/2005 9:40:54 AM H 562 C:\WINDOWS\Temp\CS28E68ED5-002D-4DDD-A5AF-E2FA24F03D75.tmp
8/18/2005 9:24:28 AM H 10 C:\WINDOWS\Temp\CS29031D5A-D23F-4EB2-AAB9-286B7C900E30.tmp
8/16/2005 10:43:44 AM H 10 C:\WINDOWS\Temp\CS298835AE-ECC0-473A-942E-E7C000A6C9E8.tmp
8/17/2005 11:12:02 PM H 160 C:\WINDOWS\Temp\CS29B59A07-BD2D-484D-BAF1-F69E708413A0.tmp
8/16/2005 11:37:16 AM H 32 C:\WINDOWS\Temp\CS2A596E5F-9700-41FD-8D41-DB398E93A7AF.tmp
8/18/2005 9:24:30 AM H 30 C:\WINDOWS\Temp\CS2ABE1DE8-02E0-4DCB-B206-9690A9661E9F.tmp
8/15/2005 4:47:28 PM H 5464 C:\WINDOWS\Temp\CS2AC165C4-771F-481B-942D-EEC755E50CD8.tmp
8/16/2005 4:24:12 PM H 10 C:\WINDOWS\Temp\CS2AE1C6E6-D60E-4808-8D1E-2DF25D3EEF4B.tmp
8/16/2005 10:43:44 AM H 10 C:\WINDOWS\Temp\CS2AFE9F68-F9D5-44C6-96C5-A2D674084420.tmp
8/18/2005 8:44:56 AM H 10 C:\WINDOWS\Temp\CS2B0D4585-4638-4847-A3E4-74174AC98689.tmp
8/26/2005 7:21:58 PM H 96 C:\WINDOWS\Temp\CS2B3D8325-D838-4DA4-BB63-BABF12D2BE4F.tmp
8/18/2005 8:44:54 AM H 114 C:\WINDOWS\Temp\CS2B695E32-D957-4795-AA0D-B57BEFD31CD3.tmp
8/17/2005 10:41:54 PM H 1357036 C:\WINDOWS\Temp\CS2B7EC15D-5A76-4CCF-A357-D6AEE780A6EA.tmp
8/18/2005 9:56:38 AM H 160 C:\WINDOWS\Temp\CS2B96B6D5-7581-4429-A177-32F7518E1719.tmp
8/23/2005 4:11:00 PM H 10 C:\WINDOWS\Temp\CS2C03E930-F3F7-49CF-89D9-C0C14F5F1CC9.tmp
8/23/2005 3:37:26 AM H 10 C:\WINDOWS\Temp\CS2C07C620-3870-4CE3-92E4-E80113E60D94.tmp
8/18/2005 9:56:38 AM H 101690 C:\WINDOWS\Temp\CS2C7C78F7-A6A5-42D9-8C2E-43EE8C92C950.tmp
8/16/2005 6:17:08 PM H 426 C:\WINDOWS\Temp\CS2C7CEFDC-A7E6-4CC8-9883-8269D8A24593.tmp
8/18/2005 9:39:16 AM H 1055442 C:\WINDOWS\Temp\CS2CB43F0A-8316-4276-9A93-D8E8BE71B40E.tmp
8/27/2005 8:14:20 AM H 0 C:\WINDOWS\Temp\CS2CE12394-C67F-48D6-B76C-A7802065B2C0.tmp
8/18/2005 9:24:32 AM H 100 C:\WINDOWS\Temp\CS2CEA913E-C656-4C4E-A522-CEFFE9419ED6.tmp
8/16/2005 11:41:08 AM H 1357036 C:\WINDOWS\Temp\CS2D8E99A0-2A96-4970-B0FD-F6C86C11F972.tmp
8/27/2005 8:14:22 AM H 32 C:\WINDOWS\Temp\CS2D9810BD-AA79-46BB-A885-123C51A68C06.tmp
8/18/2005 9:23:22 AM H 3366 C:\WINDOWS\Temp\CS2DF130A3-96C1-4C53-A6A5-8191D0FEE68A.tmp
8/23/2005 4:11:00 PM H 10 C:\WINDOWS\Temp\CS2E47F013-31C3-4021-8F9A-AB54F293537D.tmp
8/23/2005 3:37:26 AM H 376 C:\WINDOWS\Temp\CS2E615F14-44EA-4629-B402-E5BE5F99D51E.tmp
8/16/2005 6:17:10 PM H 10 C:\WINDOWS\Temp\CS2E8F4707-1047-4DA5-9CA9-19771E41C926.tmp
8/16/2005 10:43:44 AM H 124 C:\WINDOWS\Temp\CS2E93884C-8B0A-4682-9274-F9362810659C.tmp
8/15/2005 5:39:52 PM H 0 C:\WINDOWS\Temp\CS2EDA16A5-FDFA-419B-BD4D-320983A234A7.tmp
8/16/2005 6:17:08 PM H 10 C:\WINDOWS\Temp\CS2F12E73A-BDBC-4FF2-835A-4FEFEE36B035.tmp
8/16/2005 6:17:10 PM H 10 C:\WINDOWS\Temp\CS2F4CA224-C534-4037-86E7-D5DA8D7BADC8.tmp
8/17/2005 11:12:02 PM H 973372 C:\WINDOWS\Temp\CS2FD895F2-5CE3-4930-988F-9830AB8DF036.tmp
8/23/2005 3:37:26 AM H 426 C:\WINDOWS\Temp\CS2FFD781A-E364-4AF8-94E1-AED4531FFBA0.tmp
8/18/2005 9:56:38 AM H 0 C:\WINDOWS\Temp\CS30388138-0A79-4A9B-B969-68F6F0F333A1.tmp
8/27/2005 1:11:54 PM H 10 C:\WINDOWS\Temp\CS309DEAD4-57F8-4B81-B3C9-C45BCE346050.tmp
8/16/2005 6:14:46 PM H 67896 C:\WINDOWS\Temp\CS30B05455-B2CF-4CB5-9F21-81BEB0CF11BC.tmp
8/23/2005 4:11:02 PM H 118 C:\WINDOWS\Temp\CS30BBC2ED-725E-418E-A1ED-C1A06514535C.tmp
8/16/2005 4:24:14 PM H 50 C:\WINDOWS\Temp\CS31351AAC-315F-4608-831A-DA7333A6A1B4.tmp
8/15/2005 5:44:38 PM H 67896 C:\WINDOWS\Temp\CS3157448F-534E-462C-B96F-8343F036486F.tmp
8/27/2005 1:11:54 PM H 0 C:\WINDOWS\Temp\CS318214AF-1CF2-405F-9604-5AE7FE31C5C2.tmp
8/23/2005 4:11:00 PM H 10 C:\WINDOWS\Temp\CS31900DC3-DF2D-4800-9862-70623E076E51.tmp
8/23/2005 3:12:24 PM H 1055442 C:\WINDOWS\Temp\CS31A2BBB5-83AE-47B0-94EB-E6C86E0848D7.tmp
8/15/2005 5:39:56 PM H 983040 C:\WINDOWS\Temp\CS3205440D-E306-4064-A077-01D8E982A7D1.tmp
8/18/2005 9:56:38 AM H 2146620 C:\WINDOWS\Temp\CS3240A2FA-F4BA-46DB-8EE4-485C293888FD.tmp
8/16/2005 10:43:44 AM H 10 C:\WINDOWS\Temp\CS326FF5B7-AB4C-4B1A-9131-3B020C880BF5.tmp
8/18/2005 8:44:54 AM H 102 C:\WINDOWS\Temp\CS328663BC-5EDE-4DD2-BC38-16543726E6E8.tmp
8/23/2005 3:37:26 AM H 0 C:\WINDOWS\Temp\CS329A5FDE-B207-4053-BE8D-080C7C981960.tmp
8/18/2005 9:40:54 AM H 10 C:\WINDOWS\Temp\CS32BBD39A-733E-496B-A356-321F30F58D5F.tmp
8/17/2005 10:40:34 PM H 10 C:\WINDOWS\Temp\CS32F25814-DF0B-4FF7-9944-9A450A0B108A.tmp
8/15/2005 5:39:56 PM H 1111012 C:\WINDOWS\Temp\CS3310BCAA-6CE1-4CC9-B9D8-DAA0B9C988E2.tmp
8/18/2005 9:56:38 AM H 39450 C:\WINDOWS\Temp\CS33590FEB-3D33-494E-9EFF-A5A64A66532A.tmp
8/17/2005 11:16:54 PM H 1655714 C:\WINDOWS\Temp\CS3364587D-3EB2-4A99-8324-3922E4CCDDCE.tmp
8/27/2005 8:14:22 AM H 315 C:\WINDOWS\Temp\CS33912BE5-9A3E-4D76-8FEB-039E043F51D2.tmp
8/27/2005 1:11:54 PM H 10 C:\WINDOWS\Temp\CS33F2B458-DAB7-465D-9D31-882F26479C73.tmp
8/18/2005 8:44:54 AM H 0 C:\WINDOWS\Temp\CS3445B03E-D2DD-4EB7-AFB3-24FF8FF06FD4.tmp
8/23/2005 4:11:00 PM H 10 C:\WINDOWS\Temp\CS344D324B-B4AD-4D8B-8380-4D4190568B90.tmp
8/16/2005 4:24:12 PM H 114 C:\WINDOWS\Temp\CS34D9EFAD-65E6-478B-A388-9671B7DC685D.tmp
8/18/2005 9:26:38 AM H 80614 C:\WINDOWS\Temp\CS34DF9C4C-66E5-4F81-900F-D250C9D69B02.tmp
8/16/2005 10:43:44 AM H 10 C:\WINDOWS\Temp\CS34F680C5-E383-45FC-90E2-F78D871DC9E2.tmp
8/18/2005 8:44:54 AM H 48 C:\WINDOWS\Temp\CS34FCE715-6622-4CB2-8DEA-DCF203F21B07.tmp
8/23/2005 4:11:02 PM H 124 C:\WINDOWS\Temp\CS353F0F95-752D-4CDD-ADC4-C10A4165BD83.tmp
8/27/2005 1:11:54 PM H 10 C:\WINDOWS\Temp\CS3548D534-3B28-4A3D-9592-08761814E5EB.tmp
8/15/2005 5:33:50 PM H 0 C:\WINDOWS\Temp\CS35B0D56F-E532-4E3C-8631-CA75E424BBEE.tmp
8/16/2005 4:24:12 PM H 498 C:\WINDOWS\Temp\CS35F78508-D951-4762-AE30-4A0CE637C0CF.tmp
8/17/2005 10:40:34 PM H 10 C:\WINDOWS\Temp\CS3644E9C3-B82E-43A7-A966-3F8075F5AA23.tmp
8/26/2005 7:22:00 PM H 118 C:\WINDOWS\Temp\CS3660DAFD-3E5F-4F3A-8650-77244B944991.tmp
8/27/2005 1:11:54 PM H 42 C:\WINDOWS\Temp\CS369521EB-14C1-4EDB-B95E-0A553B1C5654.tmp
8/17/2005 10:40:34 PM H 418 C:\WINDOWS\Temp\CS36B5A81B-5B8C-415E-822C-AE4D590E65AD.tmp
8/18/2005 8:44:54 AM H 162 C:\WINDOWS\Temp\CS36F69A59-36C7-4721-85D3-A92DAC98117A.tmp
8/16/2005 6:14:46 PM H 30 C:\WINDOWS\Temp\CS374DB5C3-3F0C-4AA4-AEC1-BEB9A012DAC9.tmp
8/15/2005 4:47:28 PM H 0 C:\WINDOWS\Temp\CS3778B07D-BCDB-4C0C-BEDB-602AAF1E5E7C.tmp
8/26/2005 7:21:58 PM H 10 C:\WINDOWS\Temp\CS378F4E4C-7912-4DA3-BA4B-52E4207B6FC3.tmp
8/18/2005 8:44:56 AM H 10 C:\WINDOWS\Temp\CS379AC567-7163-4A8F-AFC2-5174AC8F0D00.tmp
8/18/2005 9:24:26 AM H 10 C:\WINDOWS\Temp\CS37B2DB1A-9834-4CBD-9CBD-7453A34ED769.tmp
8/26/2005 7:22:00 PM H 10 C:\WINDOWS\Temp\CS37B4B51D-6D20-4C49-935F-38D57E7245EA.tmp
8/27/2005 8:14:22 AM H 748 C:\WINDOWS\Temp\CS37CB663B-1980-4B2D-904F-CA338031F979.tmp
8/15/2005 5:33:52 PM H 1450538 C:\WINDOWS\Temp\CS37FF689E-F92D-495D-A4A0-B88BA17CDE7D.tmp
8/16/2005 4:24:12 PM H 10 C:\WINDOWS\Temp\CS38481E5A-2BE1-4D9A-9294-1BCBB96235BF.tmp
8/16/2005 11:37:16 AM H 101690 C:\WINDOWS\Temp\CS38B07E65-DCEC-48C5-A5B9-D2BCF0D6667E.tmp
8/18/2005 9:24:30 AM H 10 C:\WINDOWS\Temp\CS38BCCF06-1AA4-4849-9573-013A661F1512.tmp
8/16/2005 6:17:10 PM H 162 C:\WINDOWS\Temp\CS3900DF11-1EB6-4684-836D-7EAFF3C8E70D.tmp
8/18/2005 9:24:30 AM H 10 C:\WINDOWS\Temp\CS39536EFF-699F-491D-9DAE-27BE7EE73E3C.tmp
8/17/2005 11:12:02 PM H 545542 C:\WINDOWS\Temp\CS396848AC-AD77-47EC-9ED9-35D20F975475.tmp
8/15/2005 4:47:28 PM H 23268 C:\WINDOWS\Temp\CS399F663F-1207-45FC-94B7-3044A39D1880.tmp
8/16/2005 6:17:08 PM H 10 C:\WINDOWS\Temp\CS39B0160E-45BA-40A0-81DD-979D28916775.tmp
8/16/2005 6:17:10 PM H 50 C:\WINDOWS\Temp\CS3A14563B-DFAE-4746-A436-1745728BE347.tmp
8/27/2005 1:11:54 PM H 30 C:\WINDOWS\Temp\CS3A2EDF54-B97F-4B1E-BEFE-55EB439711ED.tmp
8/17/2005 11:12:02 PM H 30 C:\WINDOWS\Temp\CS3A33938C-CE04-42AA-B252-2F6398A54CF3.tmp
8/27/2005 1:11:54 PM H 42 C:\WINDOWS\Temp\CS3AA3B404-A0CA-4B01-A7B0-AF9C73DE5142.tmp
8/17/2005 10:40:36 PM H 42 C:\WINDOWS\Temp\CS3AB59D50-B14F-424D-9D8A-935B3506C4B8.tmp
8/23/2005 3:37:26 AM H 10 C:\WINDOWS\Temp\CS3AF9E45B-1B29-4C63-B68D-3E312657B2BB.tmp
8/15/2005 5:33:52 PM H 1494 C:\WINDOWS\Temp\CS3B0CA59D-A8ED-4277-83BF-075E7244292F.tmp
8/18/2005 8:44:54 AM H 100 C:\WINDOWS\Temp\CS3B3446F5-3891-4BE9-9CC1-1F138CC1CBD3.tmp
8/15/2005 5:39:56 PM H 0 C:\WINDOWS\Temp\CS3B51C3D9-E10F-4F02-9147-0D1E3482A9C8.tmp
8/27/2005 1:11:54 PM H 10 C:\WINDOWS\Temp\CS3B5DDD4B-3D82-46A1-8381-EFD4CC12638A.tmp
8/27/2005 1:11:54 PM H 10 C:\WINDOWS\Temp\CS3B86320E-0883-41E2-B726-5121B8DAAFE9.tmp
8/17/2005 10:35:54 PM H 240 C:\WINDOWS\Temp\CS3BA20875-FBB2-4591-A173-5BFC4F21E4ED.tmp
8/16/2005 4:24:12 PM H 120 C:\WINDOWS\Temp\CS3BE9C427-AAB8-4648-B353-DFCABF6EB2FA.tmp
8/18/2005 9:56:38 AM H 6426 C:\WINDOWS\Temp\CS3BF98B0E-87D9-4113-9FA2-D568F358033A.tmp
8/15/2005 5:33:52 PM H 38178 C:\WINDOWS\Temp\CS3BFD06A2-20E7-4226-BE75-787D0471F3D7.tmp
8/23/2005 3:37:26 AM H 68 C:\WINDOWS\Temp\CS3C49D7BB-6B9D-42C3-B5BD-2891F2683C46.tmp
8/23/2005 3:12:22 PM H 160 C:\WINDOWS\Temp\CS3C59AA8B-B3F9-4A34-A861-5B7BB077388B.tmp
8/18/2005 9:39:16 AM H 1494 C:\WINDOWS\Temp\CS3C90FBC7-A97D-424A-A88F-DE9E292F0545.tmp
8/15/2005 5:33:52 PM H 3366 C:\WINDOWS\Temp\CS3C9DB2E7-E3FE-4AA0-8122-B37775DCFEDC.tmp
8/16/2005 10:43:44 AM H 118 C:\WINDOWS\Temp\CS3CACAD04-D9B5-4244-9021-195205E6DFC2.tmp
8/23/2005 3:37:26 AM H 10 C:\WINDOWS\Temp\CS3CC66E09-C88C-40CC-A89F-59EA56359D0A.tmp
8/18/2005 9:24:26 AM H 376 C:\WINDOWS\Temp\CS3CD20D9E-B13B-4465-A5E1-B6BB87409D13.tmp
8/16/2005 11:37:16 AM H 67896 C:\WINDOWS\Temp\CS3CDF3F92-55A0-4D0E-9B32-0753FDD15CC1.tmp
8/15/2005 5:33:52 PM H 6426 C:\WINDOWS\Temp\CS3CE6B437-FA27-4663-A07F-48D893133311.tmp
8/16/2005 4:59:50 PM H 0 C:\WINDOWS\Temp\CS3D327F3D-D6B1-4648-9301-74C4ABFC9263.tmp
8/15/2005 4:47:28 PM H 1450538 C:\WINDOWS\Temp\CS3D35B133-F920-4494-82AE-6E9CE57C5236.tmp
8/15/2005 5:44:38 PM H 0 C:\WINDOWS\Temp\CS3D3CCF92-C573-4089-A27C-D694995C6EFD.tmp
8/18/2005 9:39:16 AM H 0 C:\WINDOWS\Temp\CS3D4A4ECE-6334-4C96-BD34-C2BB6E696CC1.tmp
8/16/2005 10:43:44 AM H 136 C:\WINDOWS\Temp\CS3D7A6A4C-D086-4FEB-9B36-ED7D058F4240.tmp
8/23/2005 3:37:26 AM H 10 C:\WINDOWS\Temp\CS3DCC4CDC-4950-4E8C-A13E-E89B86A989DA.tmp
8/15/2005 5:33:52 PM H 1055442 C:\WINDOWS\Temp\CS3E7447EA-ED05-4FEF-98B1-C07E96A17376.tmp
8/17/2005 10:35:54 PM H 30 C:\WINDOWS\Temp\CS3E753D47-4B74-48B7-8C98-2D13DE189F5A.tmp
8/15/2005 5:44:38 PM H 240 C:\WINDOWS\Temp\CS3E7FCF3D-831C-4BA7-905F-F585CF961C1A.tmp
8/17/2005 10:35:54 PM H 2146620 C:\WINDOWS\Temp\CS3E884465-31B4-48D8-BFC8-CDA2E56A7830.tmp
8/16/2005 4:59:52 PM H 6426 C:\WINDOWS\Temp\CS3EE1F8F1-4D20-453E-88C6-1CEA935F68DB.tmp
8/23/2005 3:12:24 PM H 128 C:\WINDOWS\Temp\CS3EEFF8DF-23DB-4E93-AC30-CD8F9C009B0D.tmp
8/26/2005 7:22:00 PM H 10 C:\WINDOWS\Temp\CS3EF0BDC3-292F-4E60-AB8D-0833FDE19209.tmp
8/18/2005 9:40:54 AM H 10 C:\WINDOWS\Temp\CS3EF6F900-ECA6-4057-9594-3FBA628CCF6C.tmp
8/23/2005 4:11:00 PM H 10 C:\WINDOWS\Temp\CS3F095C58-1BCE-45F2-BA31-9F4440D491E3.tmp
8/18/2005 9:23:22 AM H 32 C:\WINDOWS\Temp\CS3F9C0AEA-E958-43B1-8047-8B5FB6DE5120.tmp
8/18/2005 9:40:54 AM H 118 C:\WINDOWS\Temp\CS3FA3A484-35F3-4ADB-AC57-0D0652D8A69E.tmp
8/27/2005 1:11:54 PM H 522 C:\WINDOWS\Temp\CS3FF34DCD-352A-49B9-BF55-4E820D02F90C.tmp
8/18/2005 9:56:38 AM H 1450538 C:\WINDOWS\Temp\CS4039C128-A157-4CA2-B1DF-8C96484E4655.tmp
8/18/2005 9:39:12 AM H 0 C:\WINDOWS\Temp\CS422F3A59-81F3-482B-9704-C2BEB9CCD93D.tmp
8/15/2005 4:47:28 PM H 32 C:\WINDOWS\Temp\CS4292893F-2A5B-44CF-92CB-D8EB12E979E5.tmp
8/26/2005 7:22:00 PM H 10 C:\WINDOWS\Temp\CS42ED8D3D-69BA-437B-A613-67B6E0EC897E.tmp
8/18/2005 9:24:30 AM H 594 C:\WINDOWS\Temp\CS42FF31AD-C4A4-4841-84CF-E539A9987C2D.tmp
8/17/2005 10:35:56 PM H 67896 C:\WINDOWS\Temp\CS43454BC5-B7F1-4459-8C81-3DD343BE04C7.tmp
8/15/2005 5:39:56 PM H 0 C:\WINDOWS\Temp\CS43A9F569-1B81-424B-802E-4585CB54D880.tmp
8/16/2005 6:17:10 PM H 10 C:\WINDOWS\Temp\CS43CAE307-3D10-495A-B46C-7CD6B59462D5.tmp
8/16/2005 4:24:12 PM H 30 C:\WINDOWS\Temp\CS43FDD577-6B3B-4A30-94C3-94C434DF0B94.tmp
8/18/2005 8:44:54 AM H 30 C:\WINDOWS\Temp\CS43FE625A-EDB2-4585-A316-CF4105EC6E9F.tmp
8/18/2005 9:23:22 AM H 2016 C:\WINDOWS\Temp\CS442323BF-60B8-4E2D-8513-02226C262C2F.tmp
8/17/2005 11:12:02 PM H 5464 C:\WINDOWS\Temp\CS44BFA56F-EE2A-417F-B651-B1EE7BA4AFD7.tmp
8/26/2005 7:21:58 PM H 498 C:\WINDOWS\Temp\CS450C44E9-06B4-4AFF-904E-13BF79860A11.tmp
8/26/2005 7:21:58 PM H 10 C:\WINDOWS\Temp\CS4518C593-D8DE-43F3-B15D-C8DCA26E4821.tmp
8/16/2005 4:59:52 PM H 1055442 C:\WINDOWS\Temp\CS456B1319-EFDD-4170-A34E-CE7ADEE55D2B.tmp
8/27/2005 1:11:54 PM H 100 C:\WINDOWS\Temp\CS4620CB7F-8AFB-4013-A2B0-113ACC5B1E2D.tmp
8/27/2005 8:14:22 AM H 204 C:\WINDOWS\Temp\CS464BB635-99F6-41ED-8743-D7EEC20ECB56.tmp
8/27/2005 1:11:54 PM H 96 C:\WINDOWS\Temp\CS4663A89A-AFCD-4F79-BA7E-88B9B6A2652A.tmp
8/18/2005 8:44:54 AM H 10 C:\WINDOWS\Temp\CS4680D652-DC0D-4BD8-893E-BC3ADF60D1DE.tmp
8/27/2005 8:14:22 AM H 0 C:\WINDOWS\Temp\CS472F3F00-2CCA-481D-B80F-EF446A7A8C8F.tmp
8/23/2005 4:11:00 PM H 48 C:\WINDOWS\Temp\CS4750ED18-9463-4944-B3BC-DA33F1BF04E1.tmp
8/18/2005 9:39:16 AM H 101690 C:\WINDOWS\Temp\CS4757084E-C7C5-4964-B683-0E13C67B55B2.tmp
8/17/2005 11:12:02 PM H 0 C:\WINDOWS\Temp\CS47B12CD1-B317-47D9-9935-82640DFBC401.tmp
8/18/2005 8:44:54 AM H 10 C:\WINDOWS\Temp\CS47B59CDD-CC85-42FA-9CC2-DD50A5FF8964.tmp
8/16/2005 11:37:16 AM H 1055442 C:\WINDOWS\Temp\CS47CA889A-9022-410B-B864-1943CA371F5C.tmp
8/23/2005 3:37:26 AM H 10 C:\WINDOWS\Temp\CS47E6A191-EBEE-48C0-8FC4-C9E88F1662AB.tmp
8/23/2005 3:37:26 AM H 10 C:\WINDOWS\Temp\CS48799ECD-0BA8-482C-B1AE-A5F1BBF37786.tmp
8/26/2005 7:22:00 PM H 10 C:\WINDOWS\Temp\CS487DDD55-3363-4A61-8788-EA30332513C2.tmp
8/26/2005 7:21:58 PM H 10 C:\WINDOWS\Temp\CS4936BF24-6695-4913-9AB5-59E096107A9D.tmp
8/16/2005 4:24:12 PM H 10 C:\WINDOWS\Temp\CS4938942C-45FE-489F-A73F-9C9EF1453CE9.tmp
8/15/2005 5:49:52 PM H 1655714 C:\WINDOWS\Temp\CS4943F89B-1D0D-412E-BDAE-C2F9831B25E2.tmp
8/16/2005 6:14:42 PM H 0 C:\WINDOWS\Temp\CS49505301-DE2F-4154-9E8D-02D59A87D15C.tmp
8/16/2005 10:43:44 AM H 10 C:\WINDOWS\Temp\CS496CCBD2-56E5-4DCA-A7E6-31720FF56906.tmp
8/18/2005 8:44:54 AM H 10 C:\WINDOWS\Temp\CS4984FA43-CB28-4E2A-8252-48905E25D441.tmp
8/17/2005 11:12:02 PM H 240 C:\WINDOWS\Temp\CS49DA2323-482C-4B0B-BCEE-A2355C0A4F96.tmp
8/23/2005 3:37:26 AM H 408 C:\WINDOWS\Temp\CS4A3C7613-9315-473A-BE45-16CD9A33183D.tmp
8/18/2005 9:56:38 AM H 23268 C:\WINDOWS\Temp\CS4AB77636-969E-47A1-9354-39C787D76A67.tmp
8/15/2005 5:33:52 PM H 0 C:\WINDOWS\Temp\CS4AF1A76B-67CD-4650-9449-94A31DF781E0.tmp
8/17/2005 11:12:02 PM H 67896 C:\WINDOWS\Temp\CS4AFF2424-FBD8-471A-AC91-D8F6AE073E49.tmp
8/23/2005 3:12:24 PM H 101690 C:\WINDOWS\Temp\CS4B3D6A28-B200-45C2-9010-820BF735B09D.tmp
8/16/2005 6:17:08 PM H 10 C:\WINDOWS\Temp\CS4BBF62BD-CB04-47C0-A4C3-7D8D8D94A162.tmp
8/15/2005 5:33:52 PM H 748 C:\WINDOWS\Temp\CS4C151DA4-34BE-424A-9375-86530EBB631B.tmp
8/16/2005 10:43:44 AM H 10 C:\WINDOWS\Temp\CS4C2C4C45-6B67-4AC5-A4B1-EB1966AED6C0.tmp
8/18/2005 9:40:54 AM H 10 C:\WINDOWS\Temp\CS4C614C8C-9740-4C00-8FEA-31F53E8A7C48.tmp
8/18/2005 9:39:16 AM H 2016 C:\WINDOWS\Temp\CS4CCA3A05-EF33-43E1-AD20-362A2F2284AF.tmp
8/17/2005 10:35:56 PM H 38178 C:\WINDOWS\Temp\CS4E01E4FC-92BD-4135-9385-B18421A9FB9E.tmp
8/15/2005 4:47:26 PM H 0 C:\WINDOWS\Temp\CS4EAE8246-09B4-4F77-B36C-7B56CE1642F5.tmp
8/27/2005 1:11:54 PM H 10 C:\WINDOWS\Temp\CS4EC3AB36-D1C7-4D6D-9E15-7844FF0B0AB2.tmp
8/18/2005 9:23:22 AM H 973372 C:\WINDOWS\Temp\CS4EC51E57-D781-43E2-B5C0-38919AC68D7D.tmp
8/18/2005 9:24:34 AM H 124 C:\WINDOWS\Temp\CS4EDC7183-DCA7-477E-A533-CDDE3359B408.tmp
8/16/2005 6:17:08 PM H 10 C:\WINDOWS\Temp\CS4F4E462F-1A20-42D6-9070-F60F468A1C39.tmp
8/17/2005 11:12:02 PM H 6426 C:\WINDOWS\Temp\CS4F93B8BA-D773-4D02-A57B-D2236A79225F.tmp
8/18/2005 9:40:54 AM H 376 C:\WINDOWS\Temp\CS4F99EBBD-8085-48B4-91A6-748FD07D5CC8.tmp
8/18/2005 9:23:22 AM H 545542 C:\WINDOWS\Temp\CS4FD62FA3-F68D-4F6B-A59A-9C35B14364F3.tmp
8/23/2005 3:37:26 AM H 474 C:\WINDOWS\Temp\CS4FEFF4C4-17CE-4E1E-9178-9DE9476743D6.tmp
8/18/2005 9:24:28 AM H 10 C:\WINDOWS\Temp\CS50103947-C0FE-42D2-BFA3-D007F9807D66.tmp
8/16/2005 4:24:12 PM H 10 C:\WINDOWS\Temp\CS5081B0CB-FF90-4BA2-B023-E0F1B63DE076.tmp
8/16/2005 4:59:52 PM H 973372 C:\WINDOWS\Temp\CS50BD2D99-5011-4BA2-A919-248F1AFED698.tmp
8/16/2005 6:14:46 PM H 240 C:\WINDOWS\Temp\CS50BD8AB1-D2E9-438E-90AB-81F46C0BDA97.tmp
8/18/2005 8:44:54 AM H 0 C:\WINDOWS\Temp\CS50F7AC4C-D4FD-4D42-BD1A-DB69AB8E6488.tmp
8/17/2005 10:40:34 PM H 594 C:\WINDOWS\Temp\CS5140CA26-AAE4-4592-992D-AAC5A9672D69.tmp
8/16/2005 10:43:44 AM H 120 C:\WINDOWS\Temp\CS518208E0-3664-4219-8CFA-16D24B0B94F5.tmp
8/18/2005 9:40:54 AM H 42 C:\WINDOWS\Temp\CS5193184E-C493-467F-AAA3-BAE4C0E8A8F6.tmp
8/17/2005 10:40:36 PM H 10 C:\WINDOWS\Temp\CS51C20C09-5EAE-4DEE-9DAD-063FF7F589BC.tmp
8/16/2005 4:24:12 PM H 10 C:\WINDOWS\Temp\CS51E1A52A-75B2-41A8-8ACE-D9985DD2D382.tmp
8/23/2005 4:11:02 PM H 68 C:\WINDOWS\Temp\CS51E474AE-8209-4328-9DA5-67C8E2E0BA85.tmp
8/26/2005 7:21:58 PM H 10 C:\WINDOWS\Temp\CS5200D86F-F1B8-4233-9A0E-814D39A967D7.tmp
8/17/2005 10:35:50 PM H 0 C:\WINDOWS\Temp\CS5248AAAF-57F9-47B9-837C-74D42B1E9BB3.tmp
8/16/2005 4:24:12 PM H 48 C:\WINDOWS\Temp\CS52678C0A-DE20-407E-9FDA-6AF2910871F3.tmp
8/18/2005 9:24:30 AM H 120 C:\WINDOWS\Temp\CS52A97D87-36B3-456A-BF1E-700F3BCE8F87.tmp
8/27/2005 1:11:54 PM H 376 C:\WINDOWS\Temp\CS52C1482C-6C8F-4EC0-B3A5-9D2D1CBE7871.tmp
8/23/2005 3:37:26 AM H 402 C:\WINDOWS\Temp\CS530B2D53-A680-4983-AA94-4ECD98197EB8.tmp
8/15/2005 4:47:28 PM H 1269554 C:\WINDOWS\Temp\CS53FE019D-2625-43E9-BA2C-F2641BEA947B.tmp
8/16/2005 6:14:46 PM H 1055442 C:\WINDOWS\Temp\CS543B53DF-6B0A-479A-A501-E4C2BBE7D649.tmp
8/18/2005 9:39:16 AM H 306 C:\WINDOWS\Temp\CS544141AF-E998-4719-A234-3BF05C25C8F7.tmp
8/27/2005 1:11:54 PM H 426 C:\WINDOWS\Temp\CS5459C4EE-31C9-4B53-BEC9-0813F8D0CBD9.tmp
8/18/2005 9:24:32 AM H 48 C:\WINDOWS\Temp\CS5464B922-0D74-49A3-86E1-6D12B53436C0.tmp
8/27/2005 1:11:54 PM H 10 C:\WINDOWS\Temp\CS548D97E8-68FC-4BD4-82E8-2832B5C58EEA.tmp
8/26/2005 7:21:58 PM H 336 C:\WINDOWS\Temp\CS54B0DC68-AB67-43CF-832E-A646AD87237F.tmp
8/16/2005 4:24:12 PM H 10 C:\WINDOWS\Temp\CS54BA0681-EF0E-488C-8BD8-E0994DF72365.tmp
8/16/2005 11:43:04 AM H 548 C:\WINDOWS\Temp\CS54FDB33F-9D34-42CE-8967-16EEA7ACD5EB.tmp
8/17/2005 10:40:34 PM H 474 C:\WINDOWS\Temp\CS5540032C-AE08-476D-A961-670964D72682.tmp
8/16/2005 6:17:08 PM H 10 C:\WINDOWS\Temp\CS55440529-4786-4741-87E1-2558BCC1B23F.tmp
8/23/2005 4:11:00 PM H 10 C:\WINDOWS\Temp\CS5551D375-F42D-499E-BB17-D613B3C12B3F.tmp
8/26/2005 7:21:58 PM H 10 C:\WINDOWS\Temp\CS5563DE0A-3898-439F-8D83-D8A8DA29CC8F.tmp
8/18/2005 9:39:16 AM H 204 C:\WINDOWS\Temp\CS55F29ED3-4669-444B-9045-F45A7AA32AF4.tmp
8/16/2005 10:43:44 AM H 10 C:\WINDOWS\Temp\CS56573A1F-2197-462D-B67A-8420E155BF61.tmp
8/18/2005 9:40:54 AM H 10 C:\WINDOWS\Temp\CS566C8707-BC0C-4035-950E-103A3DA4C998.tmp
8/17/2005 10:40:36 PM H 10 C:\WINDOWS\Temp\CS5670F990-413B-4E09-9F6F-5FB3BFDA4877.tmp
8/17/2005 10:40:36 PM H 162 C:\WINDOWS\Temp\CS56964728-AE30-4804-AE9B-CAC544AF37C0.tmp
8/16/2005 6:17:08 PM H 402 C:\WINDOWS\Temp\CS572E1F79-E07A-404A-8F55-454DD7DDCDA2.tmp
8/15/2005 5:33:50 PM H 0 C:\WINDOWS\Temp\CS575FD440-E2F7-46B7-B438-BEA6AEC25E0C.tmp
8/16/2005 4:24:12 PM H 0 C:\WINDOWS\Temp\CS57D53E51-EAA7-4FBE-9504-E7AFA3BE67E5.tmp
8/18/2005 9:40:54 AM H 10 C:\WINDOWS\Temp\CS57E0AEA7-8F7B-4E1B-A134-8C22CBED0B3C.tmp
8/23/2005 4:11:00 PM H 14 C:\WINDOWS\Temp\CS5805BB03-3412-4564-BBB2-FBF5030EC872.tmp
8/16/2005 4:24:12 PM H 48 C:\WINDOWS\Temp\CS58076C0E-33F6-4D1D-9CF3-604E38220F5C.tmp
8/26/2005 7:21:58 PM H 562 C:\WINDOWS\Temp\CS58458588-3E36-4CDC-93F7-0C52C6719214.tmp
8/16/2005 11:37:16 AM H 2146620 C:\WINDOWS\Temp\CS5858D6A3-196C-416D-A7BE-2431E5E094EF.tmp
8/18/2005 9:24:30 AM H 10 C:\WINDOWS\Temp\CS5882D300-7D3D-472A-B510-B6EB3E32F1EE.tmp
8/26/2005 7:21:58 PM H 10 C:\WINDOWS\Temp\CS58E75E09-5761-488E-B65F-1D2165996E7E.tmp
8/23/2005 4:11:00 PM H 402 C:\WINDOWS\Temp\CS590EDEEB-A51E-40BA-B582-DF73C3D967BE.tmp
8/16/2005 6:14:46 PM H 23268 C:\WINDOWS\Temp\CS59179C90-F86E-4632-8596-4F33718E9452.tmp
8/16/2005 4:24:12 PM H 10 C:\WINDOWS\Temp\CS59A2CD48-8A73-43BB-9380-F9EA0E521A7D.tmp
8/15/2005 5:44:38 PM H 6426 C:\WINDOWS\Temp\CS59ACF8D8-F28A-4AF3-8437-264468DFFEAE.tmp
8/16/2005 4:24:12 PM H 10 C:\WINDOWS\Temp\CS59AF8589-DE21-4A1E-B414-B8D4A1D004EA.tmp
8/27/2005 1:11:54 PM H 10 C:\WINDOWS\Temp\CS59B69433-C229-4FAA-8C6B-1C7942B3D018.tmp

#4 hrlyrbl

hrlyrbl
  • Topic Starter

  • Members
  • 8 posts
  • OFFLINE
  •  
  • Local time:12:55 AM

Posted 07 September 2005 - 06:31 PM

8/27/2005 8:14:22 AM H 6144 C:\WINDOWS\Temp\CS5ABB8985-7A8D-4EA7-BEA7-059354B3A4CD.tmp
8/23/2005 3:12:22 PM H 30 C:\WINDOWS\Temp\CS5AD14934-17BC-4856-99C5-346430D67285.tmp
8/26/2005 7:21:58 PM H 10 C:\WINDOWS\Temp\CS5AE0A3C0-9360-4D15-AF9D-B9BC713EA46F.tmp
8/26/2005 7:21:58 PM H 10 C:\WINDOWS\Temp\CS5B09A7C6-CB07-47E8-8EB2-20D12E8F5AD7.tmp
8/18/2005 9:24:28 AM H 426 C:\WINDOWS\Temp\CS5B575FA9-1FD9-4147-B176-650E24773A5C.tmp
8/27/2005 1:11:54 PM H 498 C:\WINDOWS\Temp\CS5BBA20C9-7631-4A79-8565-E20521B7001C.tmp
8/27/2005 8:15:34 AM H 356560 C:\WINDOWS\Temp\CS5BBB89FB-43A1-4DA0-9D89-D2B2DBEFE20A.tmp
8/18/2005 9:24:26 AM H 336 C:\WINDOWS\Temp\CS5BDCC5F0-6A15-44EC-9B94-2E7B10024D68.tmp
8/16/2005 11:37:16 AM H 748 C:\WINDOWS\Temp\CS5C2E52BD-56C1-4762-AA89-E8F81F162D85.tmp
8/27/2005 1:11:54 PM H 10 C:\WINDOWS\Temp\CS5C9C2B2E-2C2D-44D4-82F3-4578C73F99DA.tmp
8/18/2005 9:39:16 AM H 38178 C:\WINDOWS\Temp\CS5CAF1585-9C65-4857-9246-2B12B9B31E3D.tmp
8/26/2005 7:21:58 PM H 10 C:\WINDOWS\Temp\CS5CB47C32-9BD2-40CF-9BFF-336F9D2E683C.tmp
8/16/2005 4:24:14 PM H 196 C:\WINDOWS\Temp\CS5CBBEBD3-7091-4CDF-A34E-472B3D9EE986.tmp
8/26/2005 7:21:58 PM H 474 C:\WINDOWS\Temp\CS5D13F58D-0262-4BB8-A486-DAA006E72471.tmp
8/27/2005 1:11:54 PM H 474 C:\WINDOWS\Temp\CS5D46C046-7C43-4FFA-B90B-B252F30AFB6D.tmp
8/16/2005 11:37:16 AM H 0 C:\WINDOWS\Temp\CS5D590B4E-5E96-48D3-A72B-1F2FF6E5E289.tmp
8/16/2005 6:14:46 PM H 39450 C:\WINDOWS\Temp\CS5D5EFFCE-3A05-4051-B16A-816E1A2E7960.tmp
8/16/2005 4:59:52 PM H 1269554 C:\WINDOWS\Temp\CS5E4AA9DD-94FA-4408-932F-BF19D5FA4913.tmp
8/18/2005 9:24:26 AM H 14 C:\WINDOWS\Temp\CS5E61B9A9-829E-48ED-BC39-57FEE6BD62D9.tmp
8/18/2005 9:40:54 AM H 30 C:\WINDOWS\Temp\CS5EB8F780-C20C-46D1-9BB4-05A1E6676A3D.tmp
8/17/2005 10:40:34 PM H 10 C:\WINDOWS\Temp\CS5EDBC090-FCA8-42FC-A53B-DFAE8362BCDE.tmp
8/26/2005 7:21:58 PM H 100 C:\WINDOWS\Temp\CS5EE92909-F86C-480C-B781-FA7F8F5BD6E1.tmp
8/15/2005 5:44:38 PM H 1450538 C:\WINDOWS\Temp\CS5EF52E1B-3CCF-491A-956A-1DEE5A1837F3.tmp
8/16/2005 4:59:52 PM H 3366 C:\WINDOWS\Temp\CS5F07DE9F-C309-4DD3-A7C1-11333392D4EB.tmp
8/18/2005 9:40:54 AM H 100 C:\WINDOWS\Temp\CS5F714B91-2A8A-4811-8E66-C07A121F4C89.tmp
8/18/2005 9:40:54 AM H 10 C:\WINDOWS\Temp\CS5F87192E-AB0B-4EA6-8B87-DC6274BD3047.tmp
8/27/2005 8:14:22 AM H 40026 C:\WINDOWS\Temp\CS5F882DEB-8421-4D14-998C-6E9682F774A7.tmp
8/15/2005 5:44:38 PM H 101690 C:\WINDOWS\Temp\CS601164BF-57B4-4D74-83CB-F65EFC773573.tmp
8/18/2005 8:44:54 AM H 10 C:\WINDOWS\Temp\CS6023D666-7E69-4FCC-9C66-B9E584833DB1.tmp
8/16/2005 4:59:52 PM H 30 C:\WINDOWS\Temp\CS602D0CA3-4D83-4249-BD97-C3C5ECBAC199.tmp
8/23/2005 3:37:26 AM H 402 C:\WINDOWS\Temp\CS60D739F4-9A8C-44B4-869A-81AAB8B89679.tmp
8/23/2005 4:11:00 PM H 10 C:\WINDOWS\Temp\CS61291E6C-9FA9-4DEB-8302-0A3B0A8D3921.tmp
8/23/2005 3:37:26 AM H 48 C:\WINDOWS\Temp\CS613C53F6-0C61-4BE3-B5E7-D698AF79A4C1.tmp
8/16/2005 4:24:12 PM H 306 C:\WINDOWS\Temp\CS61509982-97D0-4C46-A93F-AAB8BB5779BD.tmp
8/15/2005 4:47:28 PM H 128 C:\WINDOWS\Temp\CS618040C4-F779-47EC-8344-FD7FB9FEA3A9.tmp
8/16/2005 10:43:44 AM H 10 C:\WINDOWS\Temp\CS61A54F04-11A4-4FA3-B7DC-1C30C6EFE3BA.tmp
8/16/2005 10:43:44 AM H 48 C:\WINDOWS\Temp\CS61DCEDE4-B3F9-45F1-AFAF-22222D934CE0.tmp
8/15/2005 5:39:56 PM H 0 C:\WINDOWS\Temp\CS62150194-54BC-4758-9100-C7B8DB1C0A66.tmp
8/16/2005 11:37:16 AM H 1269554 C:\WINDOWS\Temp\CS622238F5-4CCF-4B01-A2D3-12A206E127FB.tmp
8/23/2005 4:11:02 PM H 48 C:\WINDOWS\Temp\CS624AA9AE-9044-426D-A7F3-DD7B5BE105BB.tmp
8/17/2005 10:40:34 PM H 336 C:\WINDOWS\Temp\CS624AD49E-94F7-421E-B89C-DC84FC517A4F.tmp
8/27/2005 8:14:22 AM H 160 C:\WINDOWS\Temp\CS624CEC70-1EB7-4B7F-AB86-09A0D6D47868.tmp
8/26/2005 7:21:58 PM H 30 C:\WINDOWS\Temp\CS628A0E7A-09AD-421F-B208-59FE8DDB9640.tmp
8/16/2005 6:17:08 PM H 10 C:\WINDOWS\Temp\CS629FF05C-8F3E-4C66-AA8A-895DCD033BBC.tmp
8/17/2005 10:40:34 PM H 562 C:\WINDOWS\Temp\CS630FF957-CB26-4FB5-9495-235CFB915E5C.tmp
8/18/2005 9:24:26 AM H 498 C:\WINDOWS\Temp\CS632203A9-AE15-41F0-BFE5-03351B8DF2F6.tmp
8/16/2005 6:17:08 PM H 30 C:\WINDOWS\Temp\CS63AE1E1B-DB49-4548-95C4-65A84B8C607B.tmp
8/16/2005 6:17:08 PM H 10 C:\WINDOWS\Temp\CS63B472DB-C985-407E-AB6D-442BC85930FF.tmp
8/17/2005 10:40:36 PM H 10 C:\WINDOWS\Temp\CS63D91BB8-C70C-4B13-AEFD-C00F806291A4.tmp
8/16/2005 4:24:12 PM H 124 C:\WINDOWS\Temp\CS64979A22-07E9-49EA-95C1-B29C9088EBA8.tmp
8/18/2005 9:23:22 AM H 204 C:\WINDOWS\Temp\CS64AB509D-C102-4204-BB76-2A856801EC8E.tmp
8/26/2005 7:21:58 PM H 10 C:\WINDOWS\Temp\CS652268A1-CCF5-45DE-AF3B-783E83E0EE33.tmp
8/17/2005 10:40:36 PM H 10 C:\WINDOWS\Temp\CS65E3FE25-8D59-4E70-B715-C1622C9604F5.tmp
8/18/2005 8:44:54 AM H 10 C:\WINDOWS\Temp\CS662D49E8-ABB9-4CC7-A14C-29AA64C97669.tmp
8/16/2005 6:17:08 PM H 10 C:\WINDOWS\Temp\CS66309D20-6476-4B8D-BEC5-357AFD5A6CAD.tmp
8/18/2005 9:40:54 AM H 10 C:\WINDOWS\Temp\CS665B6635-8D3F-492A-A585-50989DA08D40.tmp
8/23/2005 3:37:26 AM H 42 C:\WINDOWS\Temp\CS6735121E-33F7-4390-B3D7-40B097A99B70.tmp
8/16/2005 4:59:52 PM H 32 C:\WINDOWS\Temp\CS679E49DF-8FA4-49F2-994C-9FC6E3DAC54E.tmp
8/17/2005 10:35:56 PM H 1450538 C:\WINDOWS\Temp\CS67A78132-1A29-455A-B7D4-8A044B15F531.tmp
8/23/2005 4:11:00 PM H 0 C:\WINDOWS\Temp\CS67BCB226-B25C-4FA7-B923-A55B0E5055BF.tmp
8/16/2005 6:17:08 PM H 42 C:\WINDOWS\Temp\CS67D67269-1D82-43A3-9E41-ABE7EACA6D4B.tmp
8/23/2005 4:11:02 PM H 10 C:\WINDOWS\Temp\CS6837C926-8DBD-46F8-9137-F0866026B0E0.tmp
8/23/2005 4:11:02 PM H 10 C:\WINDOWS\Temp\CS688A53B0-7BE7-4A6A-B187-83999039BA84.tmp
8/15/2005 4:47:28 PM H 545542 C:\WINDOWS\Temp\CS68B7D3B1-1A13-4593-BFEB-3E3491044287.tmp
8/17/2005 10:40:34 PM H 48 C:\WINDOWS\Temp\CS68BB2761-ADB7-4054-A71F-5FCDF3560369.tmp
8/17/2005 10:40:36 PM H 100 C:\WINDOWS\Temp\CS68E1750C-0666-4302-8DCE-1CAAB2176510.tmp
8/16/2005 4:24:12 PM H 102 C:\WINDOWS\Temp\CS69070553-20E0-4E81-AF92-09F57803D2AD.tmp
8/16/2005 4:24:14 PM H 10 C:\WINDOWS\Temp\CS6912A453-21FA-4D11-A615-2B61570AB9A1.tmp
8/16/2005 6:17:08 PM H 10 C:\WINDOWS\Temp\CS69445D00-8484-4A7E-AA6B-91FB76EC80AA.tmp
8/18/2005 9:40:52 AM H 498 C:\WINDOWS\Temp\CS695CCDEF-10DE-4923-8B48-45E621DD3610.tmp
8/15/2005 5:44:38 PM H 545542 C:\WINDOWS\Temp\CS697D261B-2B06-44B3-BF85-958E8EBBD1CF.tmp
8/17/2005 10:35:56 PM H 39450 C:\WINDOWS\Temp\CS6986F68C-B2E8-4E8B-A956-5FB30BBA56F1.tmp
8/27/2005 1:11:54 PM H 114 C:\WINDOWS\Temp\CS69935E61-6611-4C0B-8E5F-8814C7DB9A50.tmp
8/27/2005 1:11:54 PM H 10 C:\WINDOWS\Temp\CS69D66B16-B18A-4A00-9D0E-91D58854CB9C.tmp
8/16/2005 4:59:52 PM H 2016 C:\WINDOWS\Temp\CS6ABF7865-BD46-4AFC-8D8F-12EA2965884A.tmp
8/18/2005 9:23:22 AM H 748 C:\WINDOWS\Temp\CS6AC27333-1FE9-4604-88BF-9517960132A1.tmp
8/15/2005 4:47:28 PM H 0 C:\WINDOWS\Temp\CS6B084CE6-DC72-45D0-B6C3-7EEDE1E1C387.tmp
8/23/2005 3:37:26 AM H 48 C:\WINDOWS\Temp\CS6B8FD374-0AC3-4D70-AD53-90887E97FDF9.tmp
8/18/2005 9:24:26 AM H 562 C:\WINDOWS\Temp\CS6B9D9391-06BE-4C43-AB4D-380A8175DE04.tmp
8/27/2005 8:14:22 AM H 38312 C:\WINDOWS\Temp\CS6BA09145-1E19-43EF-BD86-0AAC35D627EF.tmp
8/27/2005 1:11:54 PM H 50 C:\WINDOWS\Temp\CS6BA2858C-9B40-443E-B1D9-DE2F8E280A87.tmp
8/18/2005 9:23:22 AM H 1450538 C:\WINDOWS\Temp\CS6BDF2174-67CC-4898-9A18-E5EF6F3E3BED.tmp
8/23/2005 4:11:00 PM H 426 C:\WINDOWS\Temp\CS6C84D492-BEFE-415E-8311-81C8FC75A8AC.tmp
8/16/2005 6:17:08 PM H 102 C:\WINDOWS\Temp\CS6CAB0CE7-AB2C-4FC3-A873-DF27D64CBB18.tmp
8/15/2005 5:33:50 PM H 0 C:\WINDOWS\Temp\CS6CEA83F8-17E2-46D0-9895-0CEF78339EF6.tmp
8/15/2005 5:33:52 PM H 101690 C:\WINDOWS\Temp\CS6D21AA41-75F9-4C2C-B4FD-EE6D2DF91000.tmp
8/18/2005 9:56:38 AM H 1494 C:\WINDOWS\Temp\CS6DA1E815-DCEE-4215-A6F5-16C43B77673C.tmp
8/26/2005 7:21:58 PM H 402 C:\WINDOWS\Temp\CS6E817CD2-7121-4120-A586-C02CEC68555E.tmp
8/17/2005 10:42:14 PM H 80614 C:\WINDOWS\Temp\CS6E933EC4-C4D0-472D-B38C-934558B05364.tmp
8/23/2005 4:11:00 PM H 102 C:\WINDOWS\Temp\CS6E9D2621-6369-4573-A6B6-06BC34BEBCCD.tmp
8/18/2005 8:44:56 AM H 10 C:\WINDOWS\Temp\CS6EB5D6F8-C50A-4302-B4B2-CE13F4AA951F.tmp
8/26/2005 7:21:58 PM H 10 C:\WINDOWS\Temp\CS6ECB77BE-496A-470E-9788-054832FD915E.tmp
8/16/2005 6:17:08 PM H 522 C:\WINDOWS\Temp\CS6F50CB29-084C-42DC-B033-119AB54FFD06.tmp
8/23/2005 4:11:00 PM H 498 C:\WINDOWS\Temp\CS6F5D6096-54E1-41F2-9660-16DF9662FB40.tmp
8/18/2005 9:39:16 AM H 1450538 C:\WINDOWS\Temp\CS6F6CF966-E406-451D-8B8E-6F509F140254.tmp
8/23/2005 3:37:26 AM H 334 C:\WINDOWS\Temp\CS6F8F9365-ABFF-437D-BEE3-97EB1360D8D2.tmp
8/23/2005 3:37:26 AM H 114 C:\WINDOWS\Temp\CS701C9E96-9FED-4517-8FE3-5797AFCB6CE8.tmp
8/16/2005 4:59:52 PM H 306 C:\WINDOWS\Temp\CS70624F30-0FB0-4E5C-BFA7-DCC919C3FB6E.tmp
8/16/2005 11:37:16 AM H 1450538 C:\WINDOWS\Temp\CS70A160BB-2323-4A00-B44D-C5FED1505BD5.tmp
8/23/2005 3:37:26 AM H 10 C:\WINDOWS\Temp\CS712852FF-0E70-48A6-9A3C-0655FBDD3E21.tmp
8/18/2005 9:24:32 AM H 10 C:\WINDOWS\Temp\CS713D905E-E219-4008-B310-97055E20714D.tmp
8/18/2005 8:44:54 AM H 100 C:\WINDOWS\Temp\CS715C4899-72AF-47BC-80BF-2DC6701D1A42.tmp
8/16/2005 11:37:16 AM H 23268 C:\WINDOWS\Temp\CS71EA6ADA-7B95-4C39-82CF-ECC6D8486C34.tmp
8/18/2005 8:44:56 AM H 10 C:\WINDOWS\Temp\CS71F1A7F5-A41B-47C9-818A-EF8D55C0F4EA.tmp
8/18/2005 9:23:22 AM H 1494 C:\WINDOWS\Temp\CS71F959AB-A0AB-4004-B5C2-3AE4C62B6A61.tmp
8/23/2005 4:11:00 PM H 10 C:\WINDOWS\Temp\CS72AC487C-4218-402A-8741-2EA45DE47B24.tmp
8/16/2005 4:24:12 PM H 10 C:\WINDOWS\Temp\CS72AFB8BF-810E-4B7B-9E02-22EFC4D999B1.tmp
8/18/2005 9:40:54 AM H 594 C:\WINDOWS\Temp\CS72C0452B-5F79-420C-A4F3-73779AABAC46.tmp
8/18/2005 8:44:54 AM H 10 C:\WINDOWS\Temp\CS72F7185A-3918-4C3E-A86F-FA1BC7E12112.tmp
8/15/2005 4:47:28 PM H 160 C:\WINDOWS\Temp\CS72FF7240-D1DD-4D78-84CB-1CD6DAED33B9.tmp
8/27/2005 1:11:54 PM H 136 C:\WINDOWS\Temp\CS73171B7D-8ED2-4D01-961B-A32338D006F9.tmp
8/16/2005 10:43:44 AM H 498 C:\WINDOWS\Temp\CS735426E3-B233-447F-B42B-24B455338A72.tmp
8/16/2005 4:24:12 PM H 10 C:\WINDOWS\Temp\CS7363C4D1-5219-47F2-9CD1-20085BBAF4B0.tmp
8/18/2005 9:39:16 AM H 67896 C:\WINDOWS\Temp\CS73668E3C-CC9C-48D6-99DD-00D9C81F9075.tmp
8/17/2005 11:12:02 PM H 748 C:\WINDOWS\Temp\CS7429B23E-163E-4EE9-8AD0-8B8CD4BB10B2.tmp
8/18/2005 9:41:06 AM H 1357036 C:\WINDOWS\Temp\CS748FD53D-DA2A-47AE-B791-9B09B580521D.tmp
8/16/2005 10:43:44 AM H 10 C:\WINDOWS\Temp\CS74F447C5-2201-4C92-BC8F-E897FAFFB5BB.tmp
8/16/2005 10:43:44 AM H 498 C:\WINDOWS\Temp\CS7549985E-BC36-44BB-B269-B6EE71FA4A04.tmp
8/23/2005 4:11:00 PM H 10 C:\WINDOWS\Temp\CS757A8EE0-228F-4B78-8861-41C25A813A9F.tmp
8/16/2005 4:59:52 PM H 67896 C:\WINDOWS\Temp\CS75889554-FCEA-49B8-9735-E8DCFBC01BD4.tmp
8/17/2005 10:35:54 PM H 0 C:\WINDOWS\Temp\CS75A51DED-6AD7-49B2-8EDC-1FAE2B2E5C99.tmp
8/16/2005 4:24:12 PM H 408 C:\WINDOWS\Temp\CS75C303FF-5937-4447-B638-6105FC38454E.tmp
8/18/2005 9:40:54 AM H 402 C:\WINDOWS\Temp\CS75C3F23F-4685-4721-93E3-04594F3E5616.tmp
8/17/2005 10:40:34 PM H 10 C:\WINDOWS\Temp\CS75CA153A-2BC4-4F84-9479-33FF7F325E6C.tmp
8/18/2005 9:24:28 AM H 10 C:\WINDOWS\Temp\CS7611E209-0F7F-4F3F-97BB-0A3867B1F082.tmp
8/18/2005 9:40:54 AM H 10 C:\WINDOWS\Temp\CS7637AB83-865C-4466-BF0A-57457C13DF6E.tmp
8/18/2005 9:56:38 AM H 1055442 C:\WINDOWS\Temp\CS766B408F-4490-4399-A931-DDBEEB4CB38E.tmp
8/18/2005 8:44:54 AM H 0 C:\WINDOWS\Temp\CS76736973-22A6-4A59-9F92-D20AA34506BD.tmp
8/26/2005 7:22:00 PM H 10 C:\WINDOWS\Temp\CS7684D46B-285E-4190-8198-9F1088C216F9.tmp
8/18/2005 9:56:38 AM H 240 C:\WINDOWS\Temp\CS769A3B58-D377-4611-9B6C-08A55C29CF41.tmp
8/18/2005 9:40:54 AM H 10 C:\WINDOWS\Temp\CS76A28F3E-77C5-4C1E-88A5-540108F67264.tmp
8/15/2005 5:33:52 PM H 30 C:\WINDOWS\Temp\CS76D76BCE-3DE2-44DA-A024-D476375CF5B5.tmp
8/23/2005 3:37:26 AM H 498 C:\WINDOWS\Temp\CS7741B777-EAFC-42A0-B234-187BD980164F.tmp
8/16/2005 10:43:44 AM H 426 C:\WINDOWS\Temp\CS778E4DF1-A84A-49DE-A77B-8A0536F1A63A.tmp
8/17/2005 11:12:02 PM H 1450538 C:\WINDOWS\Temp\CS77DDA1EA-84D6-4E72-9CB7-273150E603BA.tmp
8/27/2005 1:11:54 PM H 10 C:\WINDOWS\Temp\CS77E1D18C-F18A-459F-B38C-59F687CF4BB1.tmp
8/16/2005 4:59:52 PM H 2146620 C:\WINDOWS\Temp\CS784A66D0-9901-4874-847F-A6BC53F4A8A7.tmp
8/17/2005 10:35:56 PM H 32 C:\WINDOWS\Temp\CS7876C942-5C83-4898-9EDA-C17D636A2B85.tmp
8/16/2005 6:14:46 PM H 1450538 C:\WINDOWS\Temp\CS78C2C43F-DC7E-4E34-8552-C15E143F16A0.tmp
8/17/2005 10:40:36 PM H 10 C:\WINDOWS\Temp\CS78E380C5-DD2E-4138-B69C-15BCD16BAECD.tmp
8/18/2005 9:40:52 AM H 14 C:\WINDOWS\Temp\CS78F82CA9-6DAC-493D-AA5D-757565797F85.tmp
8/16/2005 11:37:16 AM H 0 C:\WINDOWS\Temp\CS791B1E21-9EF3-4A2F-9605-1EEFB105A566.tmp
8/18/2005 8:44:56 AM H 10 C:\WINDOWS\Temp\CS7927DAE7-1986-475B-A5E1-076FCD89C1C6.tmp
8/16/2005 4:24:12 PM H 136 C:\WINDOWS\Temp\CS793C0AAA-5D93-4610-99AD-920291592827.tmp
8/16/2005 6:17:08 PM H 14 C:\WINDOWS\Temp\CS7960216E-2638-4B33-AC78-291B53494490.tmp
8/16/2005 10:43:44 AM H 10 C:\WINDOWS\Temp\CS79B314A1-A135-4C95-AA76-C2EA910BBD05.tmp
8/18/2005 9:39:16 AM H 0 C:\WINDOWS\Temp\CS79E0779C-8C55-416A-85CB-7162EA4B2A50.tmp
8/16/2005 6:14:46 PM H 38178 C:\WINDOWS\Temp\CS79E5EBA0-7762-49EC-8733-FB2583EF4336.tmp
8/18/2005 9:23:22 AM H 5464 C:\WINDOWS\Temp\CS7A1B5C75-377B-432F-8259-35780FF189B6.tmp
8/16/2005 6:14:46 PM H 1494 C:\WINDOWS\Temp\CS7AC10120-166A-4057-BBF1-344B4D7B3510.tmp
8/18/2005 9:24:32 AM H 408 C:\WINDOWS\Temp\CS7AE57515-60CE-4256-A53D-0729B3579A5E.tmp
8/15/2005 5:33:50 PM H 0 C:\WINDOWS\Temp\CS7AEA649C-1922-4620-941B-BE10019089BA.tmp
8/23/2005 3:12:22 PM H 3366 C:\WINDOWS\Temp\CS7B0C186B-6529-46AC-AB6B-7C5AC3BD9938.tmp
8/23/2005 3:12:24 PM H 38178 C:\WINDOWS\Temp\CS7B16D7BC-4690-4EE8-A762-DD9F90FB8A63.tmp
8/23/2005 4:11:00 PM H 10 C:\WINDOWS\Temp\CS7B95CDFB-0D75-48CB-B663-3CB3F37E86C0.tmp
8/23/2005 4:11:02 PM H 50 C:\WINDOWS\Temp\CS7B9FC280-A95D-42C9-9245-89B03DDBC0C0.tmp
8/23/2005 4:11:00 PM H 10 C:\WINDOWS\Temp\CS7BB69E98-93B5-4F92-BC50-B9F0E712CAC3.tmp
8/23/2005 3:37:26 AM H 10 C:\WINDOWS\Temp\CS7BFCC055-82B0-4EC6-BA73-79597D1C7932.tmp
8/17/2005 10:40:36 PM H 10 C:\WINDOWS\Temp\CS7C235FA9-BAAF-46E6-B2C2-A3A38B35A903.tmp
8/16/2005 4:24:12 PM H 96 C:\WINDOWS\Temp\CS7C4769CB-82EA-41F3-ADBD-2796A452742F.tmp
8/27/2005 1:11:54 PM H 14 C:\WINDOWS\Temp\CS7CE6FBFA-3AF6-47C0-AEB1-5D384E0BD506.tmp
8/15/2005 5:39:56 PM H 1966080 C:\WINDOWS\Temp\CS7D1BB73C-648A-44D9-AA3C-95D1EC204898.tmp
8/15/2005 5:33:52 PM H 1269554 C:\WINDOWS\Temp\CS7D3CF326-4EF0-49F0-B62D-E379DC0E1305.tmp
8/15/2005 5:39:56 PM H 0 C:\WINDOWS\Temp\CS7D7FCD06-B3FB-43A6-9A79-F8E3EE21C429.tmp
8/16/2005 6:17:10 PM H 10 C:\WINDOWS\Temp\CS7DC3E5DB-529B-4BB1-A7A9-72CBB7FD83AD.tmp
8/16/2005 6:17:46 PM H 1655714 C:\WINDOWS\Temp\CS7E10C4CE-8771-4EF9-BCFF-2CAC905A5147.tmp
8/17/2005 10:40:36 PM H 124 C:\WINDOWS\Temp\CS7E224D92-DF26-486E-8F9B-99BC1D0D73C4.tmp
8/26/2005 7:21:58 PM H 102 C:\WINDOWS\Temp\CS7E40AE65-4DFF-46A1-990A-AC644890C51B.tmp
8/23/2005 3:37:26 AM H 100 C:\WINDOWS\Temp\CS7E4B4273-2302-4541-9829-39E0133E2961.tmp
8/16/2005 6:17:08 PM H 96 C:\WINDOWS\Temp\CS7ED13399-1A6D-4E0B-9640-BA595E02C5E4.tmp
8/15/2005 5:39:56 PM H 29124 C:\WINDOWS\Temp\CS7ED4AF68-1065-47C5-ACCA-190E49752A06.tmp
8/23/2005 3:37:26 AM H 10 C:\WINDOWS\Temp\CS7EDD18DE-9B3A-4E39-96A6-968141C157BE.tmp
8/17/2005 11:12:02 PM H 1494 C:\WINDOWS\Temp\CS7F04F3B9-457C-496B-B317-E8950FF90F79.tmp
8/16/2005 10:43:44 AM H 10 C:\WINDOWS\Temp\CS7F368CE4-5621-4442-83B7-D6DE9C28A341.tmp
8/23/2005 3:37:26 AM H 196 C:\WINDOWS\Temp\CS7F387411-17C5-4C44-9A76-0D677CB29C49.tmp
8/15/2005 4:47:26 PM H 0 C:\WINDOWS\Temp\CS7F50B03F-2CA5-4942-9D29-CA91E7CC2439.tmp
8/23/2005 3:37:26 AM H 102 C:\WINDOWS\Temp\CS7F72AB93-1141-408B-B0BE-5BC069E7BD27.tmp
8/18/2005 8:44:54 AM H 100 C:\WINDOWS\Temp\CS7F7E6058-8477-4105-987D-FE0CF80EAE4D.tmp
8/23/2005 3:12:16 PM H 0 C:\WINDOWS\Temp\CS7F859C9B-2286-4612-AF11-307178D62A4C.tmp
8/18/2005 9:23:22 AM H 240 C:\WINDOWS\Temp\CS7FA71E51-2D52-436A-AE29-8D16B59CCA94.tmp
8/17/2005 10:40:34 PM H 498 C:\WINDOWS\Temp\CS7FB3D4F3-ED99-4E70-B9BD-EB1BF1A49447.tmp
8/18/2005 9:24:30 AM H 398 C:\WINDOWS\Temp\CS7FC83F66-11F7-4260-93A1-2B101341B32B.tmp
8/23/2005 3:37:26 AM H 10 C:\WINDOWS\Temp\CS805480A4-6790-4094-BEC7-1CECC0BF4EDF.tmp
8/18/2005 8:44:54 AM H 10 C:\WINDOWS\Temp\CS807E2AD7-D364-4881-A24D-B21ED5319233.tmp
8/15/2005 5:39:56 PM H 671048 C:\WINDOWS\Temp\CS80AC71B0-D4C2-43DB-918A-83440C3F65BC.tmp
8/26/2005 7:22:00 PM H 50 C:\WINDOWS\Temp\CS80BE7A64-C9E6-4DEA-B18F-7C883DFA14F2.tmp
8/23/2005 3:37:26 AM H 10 C:\WINDOWS\Temp\CS80C086C9-4A2F-413E-BDF3-8437FB9B18DE.tmp
8/18/2005 9:39:16 AM H 1269554 C:\WINDOWS\Temp\CS80D671F8-C1EF-4814-A704-D14F72819110.tmp
8/16/2005 4:59:52 PM H 38178 C:\WINDOWS\Temp\CS8156AEA4-DBC2-4752-A454-E37102B8EA4E.tmp
8/17/2005 10:40:36 PM H 504 C:\WINDOWS\Temp\CS818022E2-5360-486B-804C-5599720A911F.tmp
8/23/2005 3:37:26 AM H 10 C:\WINDOWS\Temp\CS81A0F6BA-AF6D-4461-9DC9-BABCE0E5C2FE.tmp
8/16/2005 4:24:12 PM H 100 C:\WINDOWS\Temp\CS81E4135D-8084-409A-82B1-3E8C38573370.tmp
8/27/2005 1:11:54 PM H 10 C:\WINDOWS\Temp\CS821609E4-B489-4545-BAE5-3EED965E0545.tmp
8/17/2005 10:42:04 PM H 1655714 C:\WINDOWS\Temp\CS822F0F59-B16B-4A26-9B37-80F03AB6294E.tmp
8/16/2005 4:24:12 PM H 10 C:\WINDOWS\Temp\CS82657AD7-EAA6-4DA3-B2BC-CAA55804684F.tmp
8/18/2005 8:44:54 AM H 10 C:\WINDOWS\Temp\CS8271B8C3-FE89-4848-89EE-AAA1D74D7D51.tmp
8/27/2005 8:14:22 AM H 0 C:\WINDOWS\Temp\CS829117B5-942E-4528-A39E-53F083E9E0AC.tmp
8/27/2005 1:11:54 PM H 402 C:\WINDOWS\Temp\CS82C5AAD8-D9DB-4C9F-9389-00A89299D317.tmp
8/17/2005 10:40:34 PM H 10 C:\WINDOWS\Temp\CS8323F17C-772B-424C-B47B-EF5E4FBED331.tmp
8/23/2005 3:37:26 AM H 30 C:\WINDOWS\Temp\CS83A9BDFB-0268-4002-B7BA-57D6143A1B9C.tmp
8/23/2005 3:37:26 AM H 384 C:\WINDOWS\Temp\CS83CA056B-29A7-4FA8-A0B7-C3A2E233CC06.tmp
8/17/2005 10:40:36 PM H 10 C:\WINDOWS\Temp\CS844B09D5-6769-4C4C-9B62-FE8B1DEA0D52.tmp
8/18/2005 9:40:54 AM H 518 C:\WINDOWS\Temp\CS844CE076-86F9-4B8B-8A10-54EE477C308B.tmp
8/17/2005 10:40:36 PM H 10 C:\WINDOWS\Temp\CS8452DEB9-CEE0-4BE2-9059-BD14208C54B1.tmp
8/16/2005 6:17:10 PM H 124 C:\WINDOWS\Temp\CS84A94952-34A7-43E1-914C-36247CB546A0.tmp
8/26/2005 7:21:58 PM H 504 C:\WINDOWS\Temp\CS84E0D897-B98C-4DDA-BB6C-0ACDFA59F741.tmp
8/23/2005 3:37:26 AM H 10 C:\WINDOWS\Temp\CS84EE38A2-8832-4A49-BEE1-E7658FB22F4C.tmp
8/18/2005 9:39:16 AM H 23268 C:\WINDOWS\Temp\CS85166B0C-1445-45AA-A585-FCC6FB8C57B0.tmp
8/26/2005 7:21:58 PM H 376 C:\WINDOWS\Temp\CS851D15E4-3E3E-448C-A4E3-73F59B13939B.tmp
8/16/2005 4:24:12 PM H 48 C:\WINDOWS\Temp\CS85668717-0D6F-4360-A199-FBCE06FCE553.tmp
8/15/2005 5:39:56 PM H 128 C:\WINDOWS\Temp\CS8571897B-0D73-4334-BADF-41BBBA5DB401.tmp
8/26/2005 7:21:58 PM H 384 C:\WINDOWS\Temp\CS85861455-FD22-47E7-8631-5A207832E8AD.tmp
8/17/2005 10:35:54 PM H 23268 C:\WINDOWS\Temp\CS85DEB2F6-554D-42F6-BF41-2F527947CD1F.tmp
8/16/2005 4:24:12 PM H 10 C:\WINDOWS\Temp\CS860AD2F8-B148-4F6F-8531-C44DAD59E095.tmp
8/18/2005 9:24:30 AM H 654 C:\WINDOWS\Temp\CS86331771-753B-4EB2-9AD5-8240D064E3C0.tmp
8/15/2005 5:33:52 PM H 240 C:\WINDOWS\Temp\CS86407E5C-A02A-462A-B372-024BB7CF5CA9.tmp
8/16/2005 10:43:44 AM H 30 C:\WINDOWS\Temp\CS865B3198-B3B6-4D06-A3F8-FC25951856CB.tmp
8/16/2005 10:43:44 AM H 10 C:\WINDOWS\Temp\CS866CB0C4-B71B-4001-883E-51DE656BB4F3.tmp
8/15/2005 5:33:52 PM H 0 C:\WINDOWS\Temp\CS86721CC2-E58F-4891-89B8-C5DA830395AA.tmp
8/26/2005 7:21:58 PM H 14 C:\WINDOWS\Temp\CS867BDDAA-2013-4144-97DF-7D7445E94225.tmp
8/15/2005 4:47:26 PM H 0 C:\WINDOWS\Temp\CS87129209-6B31-4647-BBFE-A9DCD469D10C.tmp
8/16/2005 4:24:12 PM H 418 C:\WINDOWS\Temp\CS87474B02-4742-40CB-B181-687A0A1E0959.tmp
8/15/2005 5:33:52 PM H 973372 C:\WINDOWS\Temp\CS876D564B-EC05-4A46-A265-535358B0130A.tmp
8/17/2005 10:35:56 PM H 5464 C:\WINDOWS\Temp\CS87FE3A7E-3579-47A8-A077-DDD09CCFD165.tmp
8/16/2005 10:43:44 AM H 306 C:\WINDOWS\Temp\CS882116B2-05FC-4733-998D-81A33220A362.tmp
8/18/2005 9:40:54 AM H 474 C:\WINDOWS\Temp\CS88321F2C-3F65-4FDE-BD23-FFB2FDEA37C0.tmp
8/17/2005 10:40:36 PM H 10 C:\WINDOWS\Temp\CS88978AA5-50D9-4BAC-A123-F8D6E9022EA8.tmp
8/18/2005 9:40:54 AM H 10 C:\WINDOWS\Temp\CS889C42CC-0BCA-4142-9339-14FC146AF8B5.tmp
8/26/2005 7:21:58 PM H 68 C:\WINDOWS\Temp\CS889CB05B-C8C4-499B-B45F-B018603E9F13.tmp
8/16/2005 6:14:46 PM H 204 C:\WINDOWS\Temp\CS88E31D78-F6D1-4E7C-ADB9-7FD40D8A0CC2.tmp
8/16/2005 6:17:10 PM H 100 C:\WINDOWS\Temp\CS8929FDE8-7451-40D8-BE9C-29F58B18CF93.tmp
8/26/2005 7:21:58 PM H 10 C:\WINDOWS\Temp\CS8A3B53B4-384B-4D32-9332-4A8C6D7C7F9F.tmp
8/16/2005 4:24:12 PM H 10 C:\WINDOWS\Temp\CS8A533503-F78F-4A6C-95E4-CC528DC392A0.tmp
8/18/2005 8:44:54 AM H 10 C:\WINDOWS\Temp\CS8A580125-D68F-4C90-A836-BF641D140095.tmp
8/16/2005 4:24:12 PM H 10 C:\WINDOWS\Temp\CS8A5DB3A5-BB1F-4244-B77A-162075710A87.tmp
8/16/2005 4:24:14 PM H 10 C:\WINDOWS\Temp\CS8A6A8C83-19EB-4D33-9F42-A235C354316A.tmp
8/16/2005 4:24:12 PM H 100 C:\WINDOWS\Temp\CS8AD02E2D-6A43-4F48-931D-CB60D6F9F65C.tmp
8/16/2005 11:37:16 AM H 204 C:\WINDOWS\Temp\CS8B4F21B9-E079-4633-BAE1-B607E704B299.tmp
8/16/2005 4:59:50 PM H 0 C:\WINDOWS\Temp\CS8BA2EBC9-150E-49D8-B4E2-5CD659C9EC04.tmp
8/15/2005 5:39:56 PM H 160 C:\WINDOWS\Temp\CS8BCB779E-5AFE-49C2-A831-B1871F8EFA4E.tmp
8/23/2005 4:11:00 PM H 100 C:\WINDOWS\Temp\CS8BDC7F0A-064A-4648-9797-B157282F661E.tmp
8/17/2005 10:40:36 PM H 408 C:\WINDOWS\Temp\CS8BE15B08-FF4C-46F9-B89E-C00EA520F8D1.tmp
8/23/2005 4:11:02 PM H 10 C:\WINDOWS\Temp\CS8C2A5726-00C4-49C8-A19C-3B58246EFF17.tmp
8/16/2005 6:17:10 PM H 10 C:\WINDOWS\Temp\CS8C560C5E-4C08-4A61-9857-FBB09F2E5E65.tmp
8/26/2005 7:21:58 PM H 48 C:\WINDOWS\Temp\CS8C6B2E3B-6AFC-4C54-B0A7-34B3D9A72CAE.tmp
8/23/2005 3:12:24 PM H 204 C:\WINDOWS\Temp\CS8CD3CED5-66DD-4938-BD8A-424C8263DBC3.tmp
8/26/2005 7:21:58 PM H 120 C:\WINDOWS\Temp\CS8CFC3B97-1F2A-4BB0-8969-E6DC454F6F7A.tmp
8/23/2005 3:12:24 PM H 1494 C:\WINDOWS\Temp\CS8D36C434-2B3F-4951-BC5C-48FA9F5F6A45.tmp
8/16/2005 6:17:08 PM H 30 C:\WINDOWS\Temp\CS8D60A77D-EA0A-421B-BEE4-7E5491198CC3.tmp
8/16/2005 10:43:44 AM H 100 C:\WINDOWS\Temp\CS8DD31262-41EE-4DBD-8947-D7BF52F042B1.tmp
8/18/2005 9:40:54 AM H 48 C:\WINDOWS\Temp\CS8E0ED9AF-301D-468F-A720-3819A7B85FA9.tmp
8/23/2005 4:11:00 PM H 402 C:\WINDOWS\Temp\CS8E18CB25-01A1-4DAB-B408-B8F916202775.tmp
8/18/2005 9:24:30 AM H 100 C:\WINDOWS\Temp\CS8E2E4C20-1123-4AA2-B3C4-860CC7F84DF0.tmp
8/16/2005 6:17:10 PM H 10 C:\WINDOWS\Temp\CS8E5A1393-8FB6-446D-8391-C75CB1E230AB.tmp
8/23/2005 4:11:02 PM H 10 C:\WINDOWS\Temp\CS8E7222C7-6BC4-43B5-8357-A69F27DF04D8.tmp
8/23/2005 3:37:26 AM H 10 C:\WINDOWS\Temp\CS8E9CA016-D3E3-4F78-B772-462E38F00BCC.tmp
8/17/2005 11:12:02 PM H 32 C:\WINDOWS\Temp\CS8EC368A2-B329-4B46-B32A-2A98CDBB16E4.tmp
8/23/2005 3:37:26 AM H 14 C:\WINDOWS\Temp\CS8ECFEBE7-87E0-4F7B-B3B0-6872D9C1321C.tmp
8/15/2005 5:44:38 PM H 32 C:\WINDOWS\Temp\CS8EF6E7FD-B46A-4012-9C2D-6FE29377EC5E.tmp
8/16/2005 10:43:44 AM H 0 C:\WINDOWS\Temp\CS8EFCD36E-8901-4A7A-8DC2-9DEE2836231C.tmp
8/18/2005 9:56:34 AM H 0 C:\WINDOWS\Temp\CS8EFE2D30-6C8B-49A4-AF4E-A36656A8CCE9.tmp
8/26/2005 7:22:00 PM H 196 C:\WINDOWS\Temp\CS8F2D414D-0A52-42FB-83A6-FB737D9D4821.tmp
8/15/2005 4:47:28 PM H 3366 C:\WINDOWS\Temp\CS8FF172DA-D9D2-4225-B8A0-B9C37CA2DD3A.tmp
8/23/2005 3:37:26 AM H 10 C:\WINDOWS\Temp\CS90ABC3D4-33C3-41DB-98F6-93500294E4BA.tmp
8/27/2005 1:11:54 PM H 10 C:\WINDOWS\Temp\CS90C3572B-9180-4CE8-B6AC-B09FAA15AB60.tmp
8/23/2005 3:17:04 PM H 1357036 C:\WINDOWS\Temp\CS90C8A129-579D-4E9A-80C2-2F9B8651C06F.tmp
8/18/2005 9:56:38 AM H 748 C:\WINDOWS\Temp\CS90CFD6C2-42CC-4C94-AEDC-1B41F7BDCCCB.tmp
8/23/2005 3:37:26 AM H 10 C:\WINDOWS\Temp\CS90ED8DFE-CC9B-49D4-82BC-0F53AAA207E2.tmp
8/15/2005 5:44:38 PM H 2146620 C:\WINDOWS\Temp\CS91290342-8CBD-4606-897D-4A124CB8A992.tmp
8/27/2005 8:14:22 AM H 2016 C:\WINDOWS\Temp\CS912CFB4D-6BD2-4137-AB9E-E19FCD6D6304.tmp
8/17/2005 11:12:02 PM H 306 C:\WINDOWS\Temp\CS9140572E-F163-4B4C-A596-4E86D4255DED.tmp
8/23/2005 3:12:24 PM H 32 C:\WINDOWS\Temp\CS91508346-A03E-4F75-A657-42A6E05A7117.tmp
8/27/2005 8:14:22 AM H 5464 C:\WINDOWS\Temp\CS919C96DA-3095-4E2A-B8A5-9196B8FDA880.tmp
8/18/2005 8:44:54 AM H 42 C:\WINDOWS\Temp\CS91AF85E5-2694-40C1-8CFC-61518882B494.tmp
8/18/2005 9:42:38 AM H 548 C:\WINDOWS\Temp\CS9243B50E-1770-4EAC-8481-61B20F8D8C57.tmp
8/18/2005 8:44:54 AM H 10 C:\WINDOWS\Temp\CS929D92E1-6C29-413A-B270-012659FBA4F3.tmp
8/27/2005 8:14:22 AM H 2182320 C:\WINDOWS\Temp\CS92B6A4CB-ED5B-4EA1-84CD-B3FFC780ACFF.tmp
8/26/2005 7:21:58 PM H 10 C:\WINDOWS\Temp\CS92E5DE8F-6250-48FD-9784-32894312DF08.tmp
8/18/2005 9:39:12 AM H 0 C:\WINDOWS\Temp\CS937F18C1-1A2A-4A64-A4D1-72A900B9ECE5.tmp
8/16/2005 10:43:44 AM H 30 C:\WINDOWS\Temp\CS93A4AC1C-466A-4F2E-B13C-646A9DCF952F.tmp
8/15/2005 4:47:26 PM H 0 C:\WINDOWS\Temp\CS93AE8D5C-2C88-45AD-AE20-072D6B6C51F1.tmp
8/16/2005 4:59:52 PM H 1450538 C:\WINDOWS\Temp\CS93CFF0C2-2853-4B59-9679-65A7B3B7B049.tmp
8/23/2005 4:11:02 PM H 10 C:\WINDOWS\Temp\CS94892F21-CEB2-4F77-ACA5-96F694CF2351.tmp
8/18/2005 9:40:54 AM H 10 C:\WINDOWS\Temp\CS953B97A6-5DB7-4D06-A192-A38898070053.tmp
8/16/2005 4:59:52 PM H 0 C:\WINDOWS\Temp\CS9554DCDD-0C90-478F-8FC9-14FF09F28827.tmp
8/23/2005 3:12:24 PM H 39450 C:\WINDOWS\Temp\CS956F9A57-FA3A-464B-A3CD-8B2EF55A831F.tmp
8/18/2005 9:40:54 AM H 10 C:\WINDOWS\Temp\CS957CB0D2-61ED-4677-A5E4-F673B73C5C53.tmp
8/18/2005 9:23:22 AM H 0 C:\WINDOWS\Temp\CS9582A0D6-EBFE-4BC3-89F7-CFE60EF65416.tmp
8/16/2005 10:43:44 AM H 10 C:\WINDOWS\Temp\CS959407CC-49D3-4A73-9BD4-944A793B6AB1.tmp
8/17/2005 10:40:34 PM H 10 C:\WINDOWS\Temp\CS9595F4A0-627F-40F6-9A56-34891541ED2F.tmp
8/17/2005 10:40:34 PM H 10 C:\WINDOWS\Temp\CS95EACFAB-8AB2-4652-8A5D-A9515EAE4A4C.tmp
8/18/2005 8:44:54 AM H 0 C:\WINDOWS\Temp\CS9602B10F-3050-46B4-A3A1-0F262DA81FA5.tmp
8/18/2005 9:40:54 AM H 398 C:\WINDOWS\Temp\CS9630E2E0-FC09-4775-98C6-97CA7A8B2DC6.tmp
8/17/2005 10:35:56 PM H 101690 C:\WINDOWS\Temp\CS9635719D-CDB0-4DF5-AA5D-654896AD533E.tmp
8/23/2005 3:12:22 PM H 306 C:\WINDOWS\Temp\CS965A917D-0332-4CFA-96FA-B8AE6C23FFC4.tmp
8/17/2005 10:35:56 PM H 1055442 C:\WINDOWS\Temp\CS9664B2C6-66B3-4A93-A63B-3B38A2F332D6.tmp
8/17/2005 10:40:34 PM H 10 C:\WINDOWS\Temp\CS9673E113-E840-46A3-ADE9-A7CB659E9E87.tmp
8/16/2005 11:37:16 AM H 128 C:\WINDOWS\Temp\CS96A60F2C-9E12-4711-B4DF-B32D66FE42AC.tmp
8/23/2005 3:12:22 PM H 240 C:\WINDOWS\Temp\CS96E25EFD-9F40-48BC-8141-6C0831874B9A.tmp
8/18/2005 9:56:34 AM H 0 C:\WINDOWS\Temp\CS96EA4660-62E1-4908-9FD6-6DF3D0092EA1.tmp
8/18/2005 9:24:30 AM H 10 C:\WINDOWS\Temp\CS97007075-3230-48FE-8147-B42B6C559A1F.tmp
8/16/2005 10:43:44 AM H 518 C:\WINDOWS\Temp\CS9727DA68-BF1C-48AE-898F-983F6035AA71.tmp
8/18/2005 8:44:54 AM H 0 C:\WINDOWS\Temp\CS972D61FF-F459-443F-8006-2163F5C537B5.tmp
8/16/2005 6:17:08 PM H 402 C:\WINDOWS\Temp\CS9736B711-4921-4306-9398-F17F967FCC8B.tmp
8/18/2005 9:39:16 AM H 32 C:\WINDOWS\Temp\CS97489E2F-128E-41CA-BC5F-D5F3C0B760CB.tmp
8/16/2005 4:59:52 PM H 748 C:\WINDOWS\Temp\CS976B559A-DB64-4AB3-8E90-9483DC1E2162.tmp
8/26/2005 7:22:00 PM H 10 C:\WINDOWS\Temp\CS9851BBFA-0D31-4733-A1A6-E139D9270A72.tmp
8/26/2005 7:22:00 PM H 10 C:\WINDOWS\Temp\CS98B24BC9-9C79-4A9B-8322-4EAE58682E24.tmp
8/27/2005 1:11:54 PM H 10 C:\WINDOWS\Temp\CS98B8D399-FB8B-48F3-A173-56F94B7409A8.tmp
8/23/2005 3:12:24 PM H 2016 C:\WINDOWS\Temp\CS98BD899B-3BAA-4D42-B489-7DB175645CB5.tmp
8/17/2005 10:40:34 PM H 14 C:\WINDOWS\Temp\CS98BE14A3-5110-44DC-A5E2-A4F7327C798D.tmp
8/23/2005 3:37:26 AM H 10 C:\WINDOWS\Temp\CS992548CE-D54B-41DA-ACD6-0E75333AFF8B.tmp
8/15/2005 5:44:38 PM H 38178 C:\WINDOWS\Temp\CS992D72A3-1C39-4EFE-98B4-214038C4E44D.tmp
8/18/2005 9:40:54 AM H 10 C:\WINDOWS\Temp\CS9934784C-04F0-41C4-827C-371E2B8FCCDF.tmp
8/27/2005 1:11:54 PM H 10 C:\WINDOWS\Temp\CS995DF309-0D05-4985-AAC4-C8FC38B9A8FB.tmp
8/18/2005 9:23:22 AM H 1269554 C:\WINDOWS\Temp\CS9961D588-C2AC-42E6-B55D-E12FF48EF368.tmp
8/18/2005 9:40:54 AM H 10 C:\WINDOWS\Temp\CS9972BA83-AFE1-41DB-A8C0-268F89B39159.tmp
8/17/2005 10:40:34 PM H 10 C:\WINDOWS\Temp\CS997D43E7-15FB-4AA1-957C-48DB03DEF095.tmp
8/17/2005 10:40:36 PM H 10 C:\WINDOWS\Temp\CS999B087A-22CD-4CBA-A2E7-C5D7918861C2.tmp
8/18/2005 9:39:16 AM H 973372 C:\WINDOWS\Temp\CS99A83509-BA17-4C6D-8E23-05598ECA63C7.tmp
8/16/2005 11:41:14 AM H 1655714 C:\WINDOWS\Temp\CS9A1463D5-E094-4854-A424-5473A1907FE6.tmp
8/26/2005 7:21:58 PM H 136 C:\WINDOWS\Temp\CS9A8C24C6-D430-4E87-ADD7-B72C157686FC.tmp
8/18/2005 9:24:32 AM H 48 C:\WINDOWS\Temp\CS9AA5636A-5F92-4CC5-AEE9-53E7AC678D62.tmp
8/23/2005 4:11:02 PM H 10 C:\WINDOWS\Temp\CS9B5406A8-0A56-44CD-B0A5-7E8AFE87884B.tmp
8/15/2005 4:47:28 PM H 204 C:\WINDOWS\Temp\CS9B67236B-97FA-414F-A55C-6B575AF6FDE0.tmp
8/27/2005 8:14:20 AM H 0 C:\WINDOWS\Temp\CS9B9EC5A6-CA45-409A-9417-120F69B05B27.tmp
8/15/2005 4:47:28 PM H 1055442 C:\WINDOWS\Temp\CS9C3FFA08-5265-4E13-9BCD-5DE77BAFBEDF.tmp
8/16/2005 6:17:08 PM H 136 C:\WINDOWS\Temp\CS9CF9A938-8A7C-42A0-A7EE-F39FDD1F4287.tmp
8/26/2005 7:21:58 PM H 10 C:\WINDOWS\Temp\CS9D255DEB-2F24-44C6-936C-BC42B2B6B200.tmp
8/16/2005 6:17:08 PM H 10 C:\WINDOWS\Temp\CS9D404A5A-75DA-4D5A-BEE2-4868825EF696.tmp
8/18/2005 4:19:18 AM H 72148 C:\WINDOWS\Temp\CS9D4187E5-3AA4-4393-9A76-977321C2FFD0.tmp
8/16/2005 6:17:08 PM H 402 C:\WINDOWS\Temp\CS9D452E86-3E33-4187-AB80-5EE3F8FDF63D.tmp
8/26/2005 7:21:58 PM H 48 C:\WINDOWS\Temp\CS9D9407E9-1553-4451-9626-BD2B739AA530.tmp
8/16/2005 6:17:10 PM H 196 C:\WINDOWS\Temp\CS9D9B2D6C-282D-4A3F-A26A-2175A50EEA2E.tmp
8/27/2005 1:11:54 PM H 48 C:\WINDOWS\Temp\CS9DF45796-5FE4-4B2D-9CEC-EA8DDF1494E0.tmp
8/23/2005 3:12:22 PM H 2146620 C:\WINDOWS\Temp\CS9DF8A805-29B6-4003-89BC-33751D35A45A.tmp
8/26/2005 7:21:58 PM H 10 C:\WINDOWS\Temp\CS9E5AE616-8692-407F-975F-40638C549098.tmp
8/18/2005 9:23:22 AM H 38178 C:\WINDOWS\Temp\CS9E8AF088-606C-4C23-86B6-1EBF55B80E66.tmp
8/18/2005 9:40:54 AM H 10 C:\WINDOWS\Temp\CS9EE9EC7F-4E6F-4C97-AB97-4E744FFCFE62.tmp
8/26/2005 7:21:58 PM H 30 C:\WINDOWS\Temp\CS9EFF16E0-0B06-45B8-B1CC-7774FEA989B2.tmp
8/16/2005 10:43:44 AM H 10 C:\WINDOWS\Temp\CS9F43B7B4-42A6-425C-B972-3B7A323EAD8A.tmp
8/23/2005 3:37:26 AM H 10 C:\WINDOWS\Temp\CS9F575FB0-1204-4B29-A489-2EDE6CF85C43.tmp
8/16/2005 4:24:12 PM H 10 C:\WINDOWS\Temp\CS9F597EF4-4590-464A-9612-F299688A4B9A.tmp
8/17/2005 10:40:36 PM H 384 C:\WINDOWS\Temp\CS9F886D26-F63C-474E-9908-82EED1ACA57C.tmp
8/26/2005 7:22:00 PM H 10 C:\WINDOWS\Temp\CS9FE19D9C-F995-485D-8908-BCA7FA1CA67D.tmp
8/23/2005 3:37:26 AM H 10 C:\WINDOWS\Temp\CSA03614AC-0C22-4C87-B003-B30356EA2801.tmp
8/18/2005 9:56:38 AM H 38178 C:\WINDOWS\Temp\CSA09D6E76-09E3-4154-942B-4B462A9EC14B.tmp
8/18/2005 9:40:54 AM H 30 C:\WINDOWS\Temp\CSA0BE2E46-DD5E-435D-B2D1-6D6EC17B5D9E.tmp
8/18/2005 8:44:56 AM H 10 C:\WINDOWS\Temp\CSA0CF6B48-8798-483E-A7B9-B87C6C0D48CA.tmp
8/16/2005 4:24:12 PM H 162 C:\WINDOWS\Temp\CSA0EB3CA5-B3BC-4B1F-AFC8-482F258C4075.tmp
8/18/2005 9:40:54 AM H 124 C:\WINDOWS\Temp\CSA0FB8FA9-61F6-49D7-BB62-F20BD3A54588.tmp
8/16/2005 6:17:08 PM H 10 C:\WINDOWS\Temp\CSA10648CF-C1F2-47C1-BB60-0B4D46AC7A06.tmp
8/18/2005 9:56:34 AM H 0 C:\WINDOWS\Temp\CSA17EA78A-3FF0-416B-9342-0FA4AFB661CF.tmp
8/27/2005 1:11:54 PM H 10 C:\WINDOWS\Temp\CSA1A332B8-7113-47A0-9A96-2D2F74614E93.tmp
8/18/2005 9:56:34 AM H 0 C:\WINDOWS\Temp\CSA1B82357-3756-48AE-9FE2-5F6CCBA35E0B.tmp
8/18/2005 9:26:32 AM H 1655714 C:\WINDOWS\Temp\CSA1DAA19A-8C3F-4AB0-9047-81C260794F6C.tmp
8/27/2005 1:11:54 PM H 48 C:\WINDOWS\Temp\CSA1FBA552-F467-4307-BEDB-8DA01F36BE47.tmp
8/26/2005 7:21:58 PM H 48 C:\WINDOWS\Temp\CSA23C902A-9B68-4C14-B11F-DD89B038731A.tmp
8/18/2005 9:41:10 AM H 1655714 C:\WINDOWS\Temp\CSA251AE51-380F-44CB-8EAE-2EF9E9505BEB.tmp
8/15/2005 4:47:28 PM H 6426 C:\WINDOWS\Temp\CSA26063BD-FA90-4721-B1F9-4309B5840A72.tmp
8/17/2005 10:40:34 PM H 10 C:\WINDOWS\Temp\CSA277D078-6C61-4312-962A-2BFC2C36C613.tmp
8/17/2005 10:35:56 PM H 3366 C:\WINDOWS\Temp\CSA338E8E5-1420-468D-AAB1-4A26C7F913D8.tmp
8/17/2005 10:35:54 PM H 1269554 C:\WINDOWS\Temp\CSA33B8CD6-55AE-4FC7-BFF8-5C42953312E7.tmp
8/18/2005 9:24:24 AM H 498 C:\WINDOWS\Temp\CSA3A92F57-7451-4C28-93AD-7A91FF6E6EF7.tmp
8/18/2005 9:24:30 AM H 42 C:\WINDOWS\Temp\CSA3BE1D3A-FE98-4124-BB26-7A887EB199E8.tmp
8/18/2005 9:23:18 AM H 0 C:\WINDOWS\Temp\CSA3CDF3A8-0029-4B4F-9508-1A1CD0662D48.tmp
8/18/2005 9:24:32 AM H 10 C:\WINDOWS\Temp\CSA3D16553-1034-4D68-822F-C6098AF0A151.tmp
8/23/2005 3:37:26 AM H 100 C:\WINDOWS\Temp\CSA3D84BEA-2DF9-41FA-A7CB-20683EB71413.tmp
8/18/2005 9:40:54 AM H 100 C:\WINDOWS\Temp\CSA4852D39-A2D0-4684-ADCD-89CE66117408.tmp
8/23/2005 4:11:00 PM H 136 C:\WINDOWS\Temp\CSA487A84D-DC6E-4051-BBDA-538834EF4439.tmp
8/18/2005 9:56:38 AM H 3366 C:\WINDOWS\Temp\CSA48C4081-E325-4F5E-9C5E-128A64D300FF.tmp
8/16/2005 6:14:46 PM H 6426 C:\WINDOWS\Temp\CSA4D47E17-3949-4CA4-BCD8-9738D3E2537C.tmp
8/18/2005 9:40:52 AM H 10 C:\WINDOWS\Temp\CSA56C4068-994B-43EA-ADFD-85B57B9EFA0E.tmp
8/18/2005 9:40:54 AM H 10 C:\WINDOWS\Temp\CSA64BB3F8-232B-4CB7-935D-C99FAB2004AC.tmp
8/16/2005 10:43:44 AM H 114 C:\WINDOWS\Temp\CSA6C73239-69E4-4F34-AA2B-E99329F1B250.tmp
8/18/2005 9:40:54 AM H 10 C:\WINDOWS\Temp\CSA703E48F-0831-4FCE-A737-56C8BDB59FE5.tmp
8/16/2005 4:24:12 PM H 10 C:\WINDOWS\Temp\CSA715B9E7-F4DD-4969-B600-1BA8F5F4CCA4.tmp
8/16/2005 10:43:44 AM H 306 C:\WINDOWS\Temp\CSA72CC924-87A9-4281-A736-EC6D78FB4B7D.tmp
8/27/2005 1:11:54 PM H 10 C:\WINDOWS\Temp\CSA763115C-6FB1-4107-B52E-243F3326FCDA.tmp
8/17/2005 10:40:36 PM H 118 C:\WINDOWS\Temp\CSA76B680B-EDBA-4BE6-8215-D592F8BFEBC7.tmp
8/18/2005 9:24:30 AM H 10 C:\WINDOWS\Temp\CSA7A04207-787C-4CE5-92BE-744A25038748.tmp
8/27/2005 1:11:54 PM H 10 C:\WINDOWS\Temp\CSA81CD4DB-B714-4C7D-8FB0-499A120BA562.tmp
8/16/2005 6:17:10 PM H 10 C:\WINDOWS\Temp\CSA87D1720-3ADC-46EA-B353-8F3CD32B6878.tmp
8/23/2005 4:11:02 PM H 100 C:\WINDOWS\Temp\CSA887709E-836D-4FBC-9B94-BAEDE95C102E.tmp
8/16/2005 4:24:12 PM H 10 C:\WINDOWS\Temp\CSA8BE4C0F-2D9B-4717-A7E8-5EDF13E67392.tmp
8/17/2005 10:40:36 PM H 10 C:\WINDOWS\Temp\CSA8D3761F-91D8-4999-97FF-DBEC55D47986.tmp
8/17/2005 11:12:02 PM H 3366 C:\WINDOWS\Temp\CSA9327860-3AA7-4694-8516-E5D7DB722406.tmp
8/18/2005 8:44:54 AM H 0 C:\WINDOWS\Temp\CSA9374B5C-A048-4D2B-98C6-708320B12899.tmp
8/15/2005 5:39:52 PM H 0 C:\WINDOWS\Temp\CSA93FD428-68E5-4F2C-958D-F0F4E4C1418A.tmp
8/16/2005 6:17:08 PM H 408 C:\WINDOWS\Temp\CSA964A49D-0D80-4CE7-9C43-1421DDDD8AC9.tmp
8/23/2005 3:12:22 PM H 5464 C:\WINDOWS\Temp\CSA9C6016C-6C50-472B-9D15-44833DAF637B.tmp
8/18/2005 8:44:54 AM H 10 C:\WINDOWS\Temp\CSA9D68622-EA47-4C3F-8735-5BFBA7242730.tmp
8/16/2005 6:17:10 PM H 118 C:\WINDOWS\Temp\CSA9E0DA7F-7E2B-4B60-95FC-BE996BB9A84E.tmp
8/18/2005 9:24:32 AM H 42 C:\WINDOWS\Temp\CSAA131D73-9FA5-4266-A6B8-EFF276AEDC32.tmp
8/23/2005 3:37:26 AM H 10 C:\WINDOWS\Temp\CSAA3E7635-FEA1-48F7-B7AB-57C393D46612.tmp
8/17/2005 11:12:02 PM H 39450 C:\WINDOWS\Temp\CSAA73D1F8-14EE-4CA2-AAC3-70B8033DE61A.tmp
8/16/2005 4:24:12 PM H 30 C:\WINDOWS\Temp\CSAAEDA0B3-CDA7-4CD6-AC84-05685B4FC584.tmp
8/23/2005 3:37:26 AM H 10 C:\WINDOWS\Temp\CSAB0670D4-33BD-4B29-A898-C8F3DE820608.tmp
8/27/2005 8:14:22 AM H 68586 C:\WINDOWS\Temp\CSAB35A9BA-09AE-4DC5-85D1-74D7234E4F49.tmp
8/18/2005 9:40:54 AM H 10 C:\WINDOWS\Temp\CSAB4B3561-82C2-4F94-9D77-70A0041BF125.tmp
8/16/2005 6:17:08 PM H 10 C:\WINDOWS\Temp\CSAB6B07D4-1CB4-4A19-9482-BA7964BEC02D.tmp
8/16/2005 6:14:46 PM H 545542 C:\WINDOWS\Temp\CSAB87F3F8-2788-438C-B50E-56621CEF0410.tmp
8/18/2005 9:39:16 AM H 128 C:\WINDOWS\Temp\CSAB8AE310-F51C-46B0-9291-1FAECD62D598.tmp
8/17/2005 10:40:34 PM H 402 C:\WINDOWS\Temp\CSAB91A593-1EC4-443B-9FC4-9BD45DA74AFB.tmp
8/23/2005 4:11:02 PM H 10 C:\WINDOWS\Temp\CSABEDDF76-3A19-44B2-A97A-BCFE01212F55.tmp
8/18/2005 9:40:54 AM H 10 C:\WINDOWS\Temp\CSABF1AB05-19CA-48FD-BECA-0874ED7122C3.tmp
8/16/2005 11:37:16 AM H 240 C:\WINDOWS\Temp\CSABF8E627-8508-4C91-8CDF-22F6DCB880D0.tmp
8/15/2005 5:33:52 PM H 39450 C:\WINDOWS\Temp\CSAC223518-91A1-4A7C-BEE3-A63EC6D21BEB.tmp
8/26/2005 7:21:58 PM H 42 C:\WINDOWS\Temp\CSAC33490D-0D35-4569-82BC-462D55308C3C.tmp
8/18/2005 9:40:54 AM H 10 C:\WINDOWS\Temp\CSAC6ABF57-9ACD-4889-9C69-DE0979CF900A.tmp
8/23/2005 4:11:00 PM H 0 C:\WINDOWS\Temp\CSAC7FC89A-FEB8-4AB3-9BF4-2BF5458C6B8A.tmp
8/18/2005 9:40:54 AM H 408 C:\WINDOWS\Temp\CSACD90693-B2E3-4EA2-8889-3F12B491C615.tmp
8/17/2005 10:42:14 PM H 354088 C:\WINDOWS\Temp\CSACF7828D-6B18-4210-B234-86591B41728E.tmp
8/16/2005 10:43:44 AM H 162 C:\WINDOWS\Temp\CSAD067269-B912-4C0B-A170-72113F7BE8CE.tmp
8/16/2005 10:43:44 AM H 48 C:\WINDOWS\Temp\CSAD1D3B8D-57F9-47E5-9C34-EE64131294A2.tmp
8/16/2005 4:24:12 PM H 0 C:\WINDOWS\Temp\CSAD956CE3-62F9-4A31-A1C2-600E8619793D.tmp
8/18/2005 9:23:22 AM H 0 C:\WINDOWS\Temp\CSADA633F9-743C-40E4-8566-7BDE56E17ED9.tmp
8/23/2005 4:11:00 PM H 10 C:\WINDOWS\Temp\CSAE4E3253-4AD3-42EE-93D3-A3579BE510DB.tmp
8/16/2005 10:43:44 AM H 402 C:\WINDOWS\Temp\CSAE64D1E2-45A9-48E7-8126-442F8B9097E0.tmp
8/16/2005 4:24:12 PM H 10 C:\WINDOWS\Temp\CSAEEA9625-BF42-4072-9A88-DDB520B30A7E.tmp
8/23/2005 4:11:00 PM H 504 C:\WINDOWS\Temp\CSAF7D20CF-62FC-4680-885A-9CBABE5A4812.tmp
8/18/2005 9:40:54 AM H 68 C:\WINDOWS\Temp\CSAF803428-E413-4744-88B0-B9991FD9547E.tmp
8/16/2005 6:14:46 PM H 973372 C:\WINDOWS\Temp\CSAFA6BD3D-0480-4831-98F8-D05C04ACC565.tmp
8/23/2005 3:37:26 AM H 10 C:\WINDOWS\Temp\CSAFB4C4F9-B33E-4EBC-B9E0-A911AD14BAA2.tmp
8/16/2005 4:24:12 PM H 14 C:\WINDOWS\Temp\CSAFCB1DBB-EF1D-495B-97B4-91CDFC8196DB.tmp
8/27/2005 8:15:26 AM H 1380108 C:\WINDOWS\Temp\CSAFD65C88-D1C7-42B1-9015-5C7D28EDF3E6.tmp
8/16/2005 6:17:08 PM H 562 C:\WINDOWS\Temp\CSAFE86D9D-5296-4BE9-8974-A28B787C0AF3.tmp
8/18/2005 9:24:34 AM H 118 C:\WINDOWS\Temp\CSAFF5F0ED-4DFE-4A83-B5F4-A990C419A566.tmp
8/23/2005 3:37:26 AM H 124 C:\WINDOWS\Temp\CSB0A81EE4-AC00-455E-ABFE-509C4594AD9B.tmp
8/23/2005 4:11:02 PM H 10 C:\WINDOWS\Temp\CSB0F3F978-788C-41F8-A7B4-84476F243BC5.tmp
8/18/2005 8:44:54 AM H 0 C:\WINDOWS\Temp\CSB1005AEB-EBAF-458A-BEDF-44310736444D.tmp
8/23/2005 3:37:26 AM H 10 C:\WINDOWS\Temp\CSB171E013-769D-4CC3-B086-251E224ACEB1.tmp
8/17/2005 10:40:36 PM H 640 C:\WINDOWS\Temp\CSB1ACFA84-B655-436F-9F0E-C0E1B74CAE86.tmp
8/17/2005 10:40:34 PM H 102 C:\WINDOWS\Temp\CSB25E2020-07D9-4122-9B67-18271FFA1C73.tmp
8/26/2005 7:21:58 PM H 402 C:\WINDOWS\Temp\CSB27CF0E0-2358-4454-AF6A-8551685A32C2.tmp
8/15/2005 5:39:52 PM H 0 C:\WINDOWS\Temp\CSB288E8E5-AAFE-4592-A048-4778ABE3CC98.tmp
8/17/2005 10:40:36 PM H 114 C:\WINDOWS\Temp\CSB28ED34E-F21C-4679-B3EB-AE29389F1A20.tmp
8/23/2005 4:11:00 PM H 120 C:\WINDOWS\Temp\CSB31643C3-6612-49A7-BD1D-0BEB8CB69C70.tmp
8/15/2005 5:39:56 PM H 204 C:\WINDOWS\Temp\CSB32B8ADD-F2C1-479A-ADC6-2A8A9869C2E6.tmp
8/23/2005 3:37:26 AM H 10 C:\WINDOWS\Temp\CSB3327509-12E8-4E39-B8AA-AE9F28F24620.tmp
8/26/2005 7:21:56 PM H 498 C:\WINDOWS\Temp\CSB3380315-8FB3-4A18-AFDE-6DCA4612806A.tmp
8/23/2005 4:11:02 PM H 100 C:\WINDOWS\Temp\CSB33DEA96-26D4-401D-B217-AC094ECA11C7.tmp
8/16/2005 6:17:10 PM H 10 C:\WINDOWS\Temp\CSB3474F81-E8FC-4E3D-9DCD-72C489E9D0EF.tmp
8/27/2005 8:14:22 AM H 1494 C:\WINDOWS\Temp\CSB3B6A497-A61B-4D67-A08C-F773323F9558.tmp
8/18/2005 9:56:38 AM H 545542 C:\WINDOWS\Temp\CSB3B7F94F-450A-4FF6-842C-54F2E07D421B.tmp
8/23/2005 4:11:02 PM H 408 C:\WINDOWS\Temp\CSB3E01463-1C8B-4C57-88CF-9FE68D08CFED.tmp
8/23/2005 4:11:02 PM H 196 C:\WINDOWS\Temp\CSB413F5B7-39C8-4525-BD67-9C2F6929CF00.tmp
8/18/2005 8:44:54 AM H 10 C:\WINDOWS\Temp\CSB4494B3B-6F71-482F-9365-CDA598954353.tmp
8/18/2005 9:40:54 AM H 48 C:\WINDOWS\Temp\CSB45D2EBC-10DB-4A1B-8CA6-24D3F9C29002.tmp
8/15/2005 4:47:28 PM H 30 C:\WINDOWS\Temp\CSB478B10A-8A29-4765-9CCD-D4E758A65DF7.tmp
8/16/2005 4:24:12 PM H 10 C:\WINDOWS\Temp\CSB499E3D4-1F93-48F7-8C93-2CC79B684407.tmp
8/18/2005 8:44:54 AM H 10 C:\WINDOWS\Temp\CSB4D96A2E-6588-4783-8817-D376BD3BE07E.tmp
8/18/2005 9:40:54 AM H 336 C:\WINDOWS\Temp\CSB4F1595B-6CC2-4BFE-AC46-921FFDBE479D.tmp
8/26/2005 7:22:00 PM H 10 C:\WINDOWS\Temp\CSB4FD7F22-59D8-46EC-BFED-AB60051C5971.tmp
8/18/2005 9:24:28 AM H 10 C:\WINDOWS\Temp\CSB5086A80-3996-4442-BA09-2DA5025A3B93.tmp
8/16/2005 4:24:12 PM H 398 C:\WINDOWS\Temp\CSB51FF7E6-61F5-4D96-8621-B2557B9BD97F.tmp
8/15/2005 5:39:52 PM H 0 C:\WINDOWS\Temp\CSB54B922F-3A6D-4397-914F-02A81A09D9C3.tmp
8/17/2005 10:35:56 PM H 6426 C:\WINDOWS\Temp\CSB5C63C7B-56B6-4632-B7A2-F81A50F55F8F.tmp
8/15/2005 5:39:56 PM H 73520 C:\WINDOWS\Temp\CSB5CF3780-B411-4C0D-84BB-BA24824908A3.tmp
8/16/2005 6:14:42 PM H 0 C:\WINDOWS\Temp\CSB5DE8AF9-9F07-49D5-928D-67B7BE283C15.tmp
8/18/2005 9:40:54 AM H 162 C:\WINDOWS\Temp\CSB6953A3F-956A-4E51-82D1-23D2538F3167.tmp
8/17/2005 10:40:36 PM H 10 C:\WINDOWS\Temp\CSB6B74FB1-15F0-4A58-AF22-21976EAE7CE5.tmp
8/18/2005 9:23:22 AM H 101690 C:\WINDOWS\Temp\CSB6E965D8-3D96-4352-9623-B843E72A096A.tmp
8/17/2005 10:35:56 PM H 306 C:\WINDOWS\Temp\CSB739E0B3-35B4-4FD6-B213-5D990FE07188.tmp
8/15/2005 5:33:52 PM H 128 C:\WINDOWS\Temp\CSB7467301-5115-4CB8-B000-CD09442D6B27.tmp
8/15/2005 5:39:56 PM H 32 C:\WINDOWS\Temp\CSB75CEFFC-38B6-4897-80A6-C6632BFAADA1.tmp
8/27/2005 1:11:54 PM H 30 C:\WINDOWS\Temp\CSB78F3035-602B-4D89-821A-39AD786AA1FC.tmp
8/18/2005 9:40:54 AM H 42 C:\WINDOWS\Temp\CSB7AE59C9-46EB-4F6F-B5FC-12B2B1ABD066.tmp
8/16/2005 6:17:10 PM H 100 C:\WINDOWS\Temp\CSB7E2F835-C400-4FFC-9FD2-741C37EF6EDB.tmp
8/16/2005 11:41:20 AM H 80614 C:\WINDOWS\Temp\CSB88805BC-DE35-4A32-AA95-921F75EE995D.tmp
8/18/2005 8:44:54 AM H 0 C:\WINDOWS\Temp\CSB8AB06E2-E332-4FE9-87CF-A1F207F44EE3.tmp
8/23/2005 4:11:02 PM H 48 C:\WINDOWS\Temp&#

#5 hrlyrbl

hrlyrbl
  • Topic Starter

  • Members
  • 8 posts
  • OFFLINE
  •  
  • Local time:12:55 AM

Posted 07 September 2005 - 06:35 PM

I don't think it put it all in my reply. I figured out where it stopped and tried to post the rest but I never saw the reply listed. Let me know if it showed up or not and I will try to repost it if I need too. Thanks.

#6 Daemon

Daemon

    Security Expert


  • Members
  • 1,446 posts
  • OFFLINE
  •  
  • Gender:Male
  • Location:UK
  • Local time:05:55 AM

Posted 10 September 2005 - 03:18 AM

Could you post the Find-Qoologic log please.
Posted Image

Have I helped you? Please consider donating to help me continue with the fight against malware. Click here

#7 hrlyrbl

hrlyrbl
  • Topic Starter

  • Members
  • 8 posts
  • OFFLINE
  •  
  • Local time:12:55 AM

Posted 12 September 2005 - 04:01 PM

Find Qoologic last edited 9/02/2005
PLEASE NOTE THAT ALL FILES FOUND BY THIS METHOD ARE NOT BAD FILES, There WILL be LEGIT FILES LISTED PLEASE BE CAREFUL WHILE FIXING. IF YOU ARE UNSURE OF WHAT IT IS LEAVE THEM ALONE.
some examples are MRT.EXE NTDLL.DLL.
»»»»»»»»»»»»»»»»»»»»»»»» Files found »»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»

* winsync C:\WINDOWS\System32\DKKFSSK.DLL
* winsync C:\WINDOWS\System32\DOORA.DLL
* winsync C:\WINDOWS\System32\WUAUCLT.DLL
»»»»»»»»»»»»»»»»»»»»»»»» startup files»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»

* exe C:\docume~1\alluse~1\startm~1\programs\startup\DPPU.EXE

»»»»»»»»»»»»»»»»»»»»»»»» Checking Global Startup »»»»»»»»»»»»»»»»»»»»»»

(fstarts by IMM - test ver. 0.001) NOT using address check -- 0x77f75fae

Global Startup:
C:\Documents and Settings\All Users\Start Menu\Programs\Startup
.
..
Adobe Reader Speed Launch.lnk
America Online 9.0 Tray Icon.lnk
AOL Companion.lnk
desktop.ini
dppu.exe
HP Digital Imaging Monitor.lnk
Microsoft Office.lnk

User Startup:
C:\Documents and Settings\Owner\Start Menu\Programs\Startup
.
..
desktop.ini

»»»»» Search by size and name...
»»»»» Files found by this method are not necessarily bad...
»»»»» Example PNGFILT.DLL ctl3d32.dll are windows files...

C:\WINDOWS\SYSTEM32\K44XPL.EXE
C:\WINDOWS\SYSTEM32\CRRXABR.EXE
C:\WINDOWS\SYSTEM32\DOORA.DLL
C:\WINDOWS\SYSTEM32\DKKFSSK.DLL
C:\WINDOWS\SYSTEM32\QBBGU.DAT
C:\WINDOWS\SYSTEM32\VGACTL.CPL
C:\WINDOWS\SYSTEM32\WUAUCLT.DLL
C:\DOCUME~1\ALLUSE~1\STARTM~1\PROGRAMS\STARTUP\DPPU.EXE

This was the other log that popped up with trackqoo. Since the qoologic didn't show up then I am sure this one didn't either.

REGEDIT4

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"IgfxTray"="C:\\WINDOWS\\System32\\igfxtray.exe"
"HotKeysCmds"="C:\\WINDOWS\\System32\\hkcmd.exe"
"HP Component Manager"="\"C:\\Program Files\\HP\\hpcoretech\\hpcmpmgr.exe\""
"MMTray"="C:\\Program Files\\MUSICMATCH\\MUSICMATCH Jukebox\\mm_tray.exe"
"MCAgentExe"="c:\\PROGRA~1\\mcafee.com\\agent\\mcagent.exe files\\mcafee.com\\agent\\mcagent.exe"
"MCUpdateExe"="C:\\PROGRA~1\\mcafee.com\\agent\\mcupdate.exe"
"AdaptecDirectCD"="\"C:\\Program Files\\Roxio\\Easy CD Creator 5\\DirectCD\\DirectCD.exe\""
"VirusScan Online"="\"c:\\PROGRA~1\\mcafee.com\\vso\\mcvsshld.exe\""
"RealTray"="C:\\Program Files\\Real\\RealPlayer\\RealPlay.exe SYSTEMBOOTHIDEPLAYER"
"QuickTime Task"="\"C:\\Program Files\\QuickTime\\qttask.exe\" -atboottime"
"MPFExe"="C:\\PROGRA~1\\McAfee.com\\PERSON~1\\MpfTray.exe"
"Microsoft Works Update Detection"="C:\\Program Files\\Common Files\\Microsoft Shared\\Works Shared\\WkUFind.exe"
"HP Software Update"="C:\\Program Files\\HP\\HP Software Update\\HPWuSchd2.exe"
"VBundleOuterDL"="C:\\Program Files\\VBouncer\\BundleOuter.EXE"
"cfgmgr52"="RunDLL32.EXE C:\\WINDOWS\\cfgmgr52.dll,DllRun"
"PSGuard"="C:\\Program Files\\PSGuard\\PSGuard.exe"
"IMJPMIG8.1"="\"C:\\WINDOWS\\IME\\imjp8_1\\IMJPMIG.EXE\" /Spoil /RemAdvDef /Migration32"
"CToolBar"="TorontoMail.exe"
"atl_helper"="abrek.exe"
"Media Access"="C:\\Program Files\\Media Access\\MediaAccK.exe"
"SpySweeper"="\"C:\\Program Files\\Webroot\\Spy Sweeper\\SpySweeper.exe\" /startintray"
"winsync"="C:\\WINDOWS\\System32\\k44xpl.exe reg_run"
"VSOCheckTask"="\"c:\\PROGRA~1\\mcafee.com\\vso\\mcmnhdlr.exe\" /checktask"

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\OptionalComponents]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\OptionalComponents\IMAIL]
"Installed"="1"

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\OptionalComponents\MAPI]
"Installed"="1"
"NoChange"="1"

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\OptionalComponents\MSFS]
"Installed"="1"

-----------------
HKEY_CLASSES_ROOT\*\shellex\ContextMenuHandlers


Subkey --- gttsyfts
{d1f4c82b-311f-4552-91cf-469ec47e8d21}
C:\WINDOWS\System32\doora.dll

Subkey --- Offline Files
{750fdf0e-2a26-11d1-a3ea-080036587f03}
C:\WINDOWS\System32\cscui.dll

Subkey --- Open With
{09799AFB-AD67-11d1-ABCD-00C04FC30936}
C:\WINDOWS\system32\SHELL32.dll

Subkey --- Open With EncryptionMenu
{A470F8CF-A1E8-4f65-8335-227475AA5C46}
C:\WINDOWS\system32\SHELL32.dll

Subkey --- Yahoo! Mail
{5464D816-CF16-4784-B9F3-75C0DB52B499}
C:\PROGRA~1\Yahoo!\Common\ymmapi.dll

Subkey --- {a2a9545d-a0c2-42b4-9708-a0b2badd77c8}
Start Menu Pin
C:\WINDOWS\system32\SHELL32.dll

Subkey --- {CFC7205E-2792-4378-9591-3879CC6C9022}

c:\progra~1\mcafee.com\vso\mcvsshl.dll

=====================

HKEY_CLASSES_ROOT\Folder\shellex\ColumnHandlers


Subkey --- {0D2E74C4-3C34-11d2-A27E-00C04FC30871}
C:\WINDOWS\system32\SHELL32.dll

Subkey --- {24F14F01-7B1C-11d1-838f-0000F80461CF}
C:\WINDOWS\system32\SHELL32.dll

Subkey --- {24F14F02-7B1C-11d1-838f-0000F80461CF}
C:\WINDOWS\system32\SHELL32.dll

Subkey --- {66742402-F9B9-11D1-A202-0000F81FEDEE}
C:\WINDOWS\system32\SHELL32.dll

Subkey --- {6EC11407-5B2E-4E25-8BDF-77445B52AB37}
C:\WINDOWS\System32\wuauclt.dll

Subkey --- {F9DB5320-233E-11D1-9F84-707F02C10627}
C:\Program Files\Adobe\Acrobat 7.0\ActiveX\PDFShell.dll

==============================
C:\Documents and Settings\All Users\Start Menu\Programs\Startup

Adobe Reader Speed Launch.lnk
America Online 9.0 Tray Icon.lnk
AOL Companion.lnk
desktop.ini
HP Digital Imaging Monitor.lnk
Microsoft Office.lnk
==============================
C:\Documents and Settings\Owner\Start Menu\Programs\Startup

Adobe Reader Speed Launch.lnk
America Online 9.0 Tray Icon.lnk
AOL Companion.lnk
desktop.ini
HP Digital Imaging Monitor.lnk
Microsoft Office.lnk
desktop.ini
==============================
C:\WINDOWS\system32 cpl files


access.cpl Microsoft Corporation
appwiz.cpl Microsoft Corporation
desk.cpl Microsoft Corporation
hdwwiz.cpl Microsoft Corporation
igfxcpl.cpl Intel Corporation
inetcpl.cpl Microsoft Corporation
intl.cpl Microsoft Corporation
joy.cpl Microsoft Corporation
main.cpl Microsoft Corporation
mmsys.cpl Microsoft Corporation
ncpa.cpl Microsoft Corporation
nusrmgr.cpl Microsoft Corporation
odbccp32.cpl Microsoft Corporation
powercfg.cpl Microsoft Corporation
prefscpl.cpl RealNetworks, Inc.
QuickTime.cpl Apple Computer, Inc.
sysdm.cpl Microsoft Corporation
telephon.cpl Microsoft Corporation
timedate.cpl Microsoft Corporation
vgactl.cpl

If you need anything else let me know. thanks.

#8 Daemon

Daemon

    Security Expert


  • Members
  • 1,446 posts
  • OFFLINE
  •  
  • Gender:Male
  • Location:UK
  • Local time:05:55 AM

Posted 16 September 2005 - 02:25 PM

Apologies - missed this reply, could you re-run and repost the Findqoologic log.
Posted Image

Have I helped you? Please consider donating to help me continue with the fight against malware. Click here

#9 hrlyrbl

hrlyrbl
  • Topic Starter

  • Members
  • 8 posts
  • OFFLINE
  •  
  • Local time:12:55 AM

Posted 26 September 2005 - 12:40 AM

Find Qoologic last edited 9/02/2005
PLEASE NOTE THAT ALL FILES FOUND BY THIS METHOD ARE NOT BAD FILES, There WILL be LEGIT FILES LISTED PLEASE BE CAREFUL WHILE FIXING. IF YOU ARE UNSURE OF WHAT IT IS LEAVE THEM ALONE.
some examples are MRT.EXE NTDLL.DLL.
»»»»»»»»»»»»»»»»»»»»»»»» Files found »»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»

* winsync C:\WINDOWS\System32\DKKFSSK.DLL
* winsync C:\WINDOWS\System32\DOORA.DLL
* winsync C:\WINDOWS\System32\WUAUCLT.DLL
»»»»»»»»»»»»»»»»»»»»»»»» startup files»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»

* exe C:\docume~1\alluse~1\startm~1\programs\startup\DPPU.EXE

»»»»»»»»»»»»»»»»»»»»»»»» Checking Global Startup »»»»»»»»»»»»»»»»»»»»»»

(fstarts by IMM - test ver. 0.001) NOT using address check -- 0x77f75fae

Global Startup:
C:\Documents and Settings\All Users\Start Menu\Programs\Startup
.
..
Adobe Reader Speed Launch.lnk
America Online 9.0 Tray Icon.lnk
AOL Companion.lnk
desktop.ini
dppu.exe
HP Digital Imaging Monitor.lnk
Microsoft Office.lnk

User Startup:
C:\Documents and Settings\Owner\Start Menu\Programs\Startup
.
..
desktop.ini

»»»»» Search by size and name...
»»»»» Files found by this method are not necessarily bad...
»»»»» Example PNGFILT.DLL ctl3d32.dll are windows files...

C:\WINDOWS\SYSTEM32\K44XPL.EXE
C:\WINDOWS\SYSTEM32\CRRXABR.EXE
C:\WINDOWS\SYSTEM32\DOORA.DLL
C:\WINDOWS\SYSTEM32\DKKFSSK.DLL
C:\WINDOWS\SYSTEM32\QBBGU.DAT
C:\WINDOWS\SYSTEM32\VGACTL.CPL
C:\WINDOWS\SYSTEM32\WUAUCLT.DLL
C:\DOCUME~1\ALLUSE~1\STARTM~1\PROGRAMS\STARTUP\DPPU.EXE

#10 Daemon

Daemon

    Security Expert


  • Members
  • 1,446 posts
  • OFFLINE
  •  
  • Gender:Male
  • Location:UK
  • Local time:05:55 AM

Posted 26 September 2005 - 12:53 AM

Click here to download Pocket Killbox by Option^Explicit. Extract it from the zip file then double-click on Killbox.exe to run it.

Select the Delete on reboot option.

Copy this entire list of files to the clipboard. (Highlight the list. Press CTRL + C)

C:\WINDOWS\SYSTEM32\K44XPL.EXE
C:\WINDOWS\SYSTEM32\CRRXABR.EXE
C:\WINDOWS\SYSTEM32\DOORA.DLL
C:\WINDOWS\SYSTEM32\DKKFSSK.DLL
C:\WINDOWS\SYSTEM32\QBBGU.DAT
C:\WINDOWS\SYSTEM32\VGACTL.CPL
C:\WINDOWS\SYSTEM32\WUAUCLT.DLL
C:\Documents and Settings\All Users\Start Menu\Programs\Startup\DPPU.EXE


In the Killbox, go to the toolbar to File > Paste from clipboard. Click Paste from Clipboard. All of the files you pasted in might not show up on the list in Killbox. That's normal. Some may not be present and so will not be listed. Go ahead to the next step.

Click the red icon with the white X at the upper right. You will be prompted to restart - say yes and exit. Restart back into Windows.

Post a new HJT log and also a new log from FindQoologic.
Posted Image

Have I helped you? Please consider donating to help me continue with the fight against malware. Click here

#11 hrlyrbl

hrlyrbl
  • Topic Starter

  • Members
  • 8 posts
  • OFFLINE
  •  
  • Local time:12:55 AM

Posted 28 September 2005 - 06:19 PM

Logfile of HijackThis v1.99.1
Scan saved at 6:06:21 PM, on 9/28/2005
Platform: Windows XP SP1 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\csrss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\PROGRA~1\COMMON~1\AOL\ACS\acsd.exe
C:\WINDOWS\system32\cisvc.exe
c:\PROGRA~1\mcafee.com\vso\mcvsrte.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Webroot\Spy Sweeper\WRSSSDK.exe
C:\WINDOWS\wanmpsvc.exe
c:\PROGRA~1\mcafee.com\vso\mcshield.exe
C:\WINDOWS\system32\cmd.exe
C:\WINDOWS\System32\nfsiod.exe
C:\WINDOWS\System32\nfsiod.exe
C:\PROGRA~1\McAfee.com\PERSON~1\MpfAgent.exe
C:\WINDOWS\explorer.exe
c:\program files\mcafee.com\agent\mcagent.exe
C:\WINDOWS\System32\hkcmd.exe
C:\Program Files\HP\hpcoretech\hpcmpmgr.exe
C:\Program Files\MUSICMATCH\MUSICMATCH Jukebox\mm_tray.exe
C:\Program Files\Roxio\Easy CD Creator 5\DirectCD\DirectCD.exe
C:\PROGRA~1\mcafee.com\vso\mcvsshld.exe
C:\Program Files\Real\RealPlayer\RealPlay.exe
c:\progra~1\mcafee.com\vso\mcvsescn.exe
C:\Program Files\QuickTime\qttask.exe
C:\Program Files\Common Files\Microsoft Shared\Works Shared\WkUFind.exe
C:\Program Files\HP\HP Software Update\HPWuSchd2.exe
C:\Program Files\Yahoo!\Messenger\ypager.exe
C:\Program Files\Dell Support\DSAgnt.exe
C:\Program Files\Messenger\msmsgs.exe
C:\Program Files\AOL Companion\companion.exe
C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe
c:\progra~1\mcafee.com\vso\mcvsftsn.exe
C:\WINDOWS\System32\HPZipm12.exe
C:\WINDOWS\system32\cmd.exe
C:\WINDOWS\explorer.exe
C:\Documents and Settings\Owner\Desktop\HijackThis\HijackThis.exe

R1 - HKCU\Software\Microsoft\Internet Explorer,SearchURL = http://searchmiracle.com/sp.php
R3 - Default URLSearchHook is missing
O1 - Hosts: 69.31.81.22 www.google.ae
O1 - Hosts: 69.31.81.22 www.google.am
O1 - Hosts: 69.31.81.22 www.google.as
O1 - Hosts: 69.31.81.22 www.google.at
O1 - Hosts: 69.31.81.22 www.google.az
O1 - Hosts: 69.31.81.22 www.google.be
O1 - Hosts: 69.31.81.22 www.google.bi
O1 - Hosts: 69.31.81.22 www.google.ca
O1 - Hosts: 69.31.81.22 www.google.cd
O1 - Hosts: 69.31.81.22 www.google.cg
O1 - Hosts: 69.31.81.22 www.google.ch
O1 - Hosts: 69.31.81.22 www.google.ci
O1 - Hosts: 69.31.81.22 www.google.cl
O1 - Hosts: 69.31.81.22 www.google.co.cr
O1 - Hosts: 69.31.81.22 www.google.co.hu
O1 - Hosts: 69.31.81.22 www.google.co.il
O1 - Hosts: 69.31.81.22 www.google.co.in
O1 - Hosts: 69.31.81.22 www.google.co.je
O1 - Hosts: 69.31.81.22 www.google.co.jp
O1 - Hosts: 69.31.81.22 www.google.co.ke
O1 - Hosts: 69.31.81.22 www.google.co.kr
O1 - Hosts: 69.31.81.22 www.google.co.ls
O1 - Hosts: 69.31.81.22 www.google.co.nz
O1 - Hosts: 69.31.81.22 www.google.co.th
O1 - Hosts: 69.31.81.22 www.google.co.ug
O1 - Hosts: 69.31.81.22 www.google.co.uk
O1 - Hosts: 69.31.81.22 www.google.co.ve
O1 - Hosts: 69.31.81.22 www.google.com
O1 - Hosts: 69.31.81.22 www.google.com.ag
O1 - Hosts: 69.31.81.22 www.google.com.ar
O1 - Hosts: 69.31.81.22 www.google.com.au
O1 - Hosts: 69.31.81.22 www.google.com.br
O1 - Hosts: 69.31.81.22 www.google.com.co
O1 - Hosts: 69.31.81.22 www.google.com.cu
O1 - Hosts: 69.31.81.22 www.google.com.do
O1 - Hosts: 69.31.81.22 www.google.com.ec
O1 - Hosts: 69.31.81.22 www.google.com.fj
O1 - Hosts: 69.31.81.22 www.google.com.gi
O1 - Hosts: 69.31.81.22 www.google.com.gr
O1 - Hosts: 69.31.81.22 www.google.com.gt
O1 - Hosts: 69.31.81.22 www.google.com.hk
O1 - Hosts: 69.31.81.22 www.google.com.ly
O1 - Hosts: 69.31.81.22 www.google.com.mt
O1 - Hosts: 69.31.81.22 www.google.com.mx
O1 - Hosts: 69.31.81.22 www.google.com.my
O1 - Hosts: 69.31.81.22 www.google.com.na
O1 - Hosts: 69.31.81.22 www.google.com.nf
O1 - Hosts: 69.31.81.22 www.google.com.ni
O1 - Hosts: 69.31.81.22 www.google.com.np
O1 - Hosts: 69.31.81.22 www.google.com.pa
O1 - Hosts: 69.31.81.22 www.google.com.pe
O1 - Hosts: 69.31.81.22 www.google.com.ph
O1 - Hosts: 69.31.81.22 www.google.com.pk
O1 - Hosts: 69.31.81.22 www.google.com.pr
O1 - Hosts: 69.31.81.22 www.google.com.py
O1 - Hosts: 69.31.81.22 www.google.com.sa
O1 - Hosts: 69.31.81.22 www.google.com.sg
O1 - Hosts: 69.31.81.22 www.google.com.sv
O1 - Hosts: 69.31.81.22 www.google.com.tr
O1 - Hosts: 69.31.81.22 www.google.com.tw
O1 - Hosts: 69.31.81.22 www.google.com.ua
O1 - Hosts: 69.31.81.22 www.google.com.uy
O1 - Hosts: 69.31.81.22 www.google.com.vc
O1 - Hosts: 69.31.81.22 www.google.com.vn
O1 - Hosts: 69.31.81.22 www.google.de
O1 - Hosts: 69.31.81.22 www.google.dj
O1 - Hosts: 69.31.81.22 www.google.dk
O1 - Hosts: 69.31.81.22 www.google.es
O1 - Hosts: 69.31.81.22 www.google.fi
O1 - Hosts: 69.31.81.22 www.google.fm
O1 - Hosts: 69.31.81.22 www.google.fr
O1 - Hosts: 69.31.81.22 www.google.gg
O1 - Hosts: 69.31.81.22 www.google.gl
O1 - Hosts: 69.31.81.22 www.google.gm
O1 - Hosts: 69.31.81.22 www.google.hn
O1 - Hosts: 69.31.81.22 www.google.ie
O1 - Hosts: 69.31.81.22 www.google.it
O1 - Hosts: 69.31.81.22 www.google.kz
O1 - Hosts: 69.31.81.22 www.google.li
O1 - Hosts: 69.31.81.22 www.google.lt
O1 - Hosts: 69.31.81.22 www.google.lu
O1 - Hosts: 69.31.81.22 www.google.lv
O1 - Hosts: 69.31.81.22 www.google.mn
O1 - Hosts: 69.31.81.22 www.google.ms
O1 - Hosts: 69.31.81.22 www.google.mu
O1 - Hosts: 69.31.81.22 www.google.mw
O1 - Hosts: 69.31.81.22 www.google.nl
O1 - Hosts: 69.31.81.22 www.google.no
O1 - Hosts: 69.31.81.22 www.google.off.ai
O1 - Hosts: 69.31.81.22 www.google.pl
O1 - Hosts: 69.31.81.22 www.google.pn
O1 - Hosts: 69.31.81.22 www.google.pt
O1 - Hosts: 69.31.81.22 www.google.ro
O1 - Hosts: 69.31.81.22 www.google.ru
O1 - Hosts: 69.31.81.22 www.google.rw
O1 - Hosts: 69.31.81.22 www.google.se
O1 - Hosts: 69.31.81.22 www.google.sh
O1 - Hosts: 69.31.81.22 www.google.sk
O1 - Hosts: 69.31.81.22 www.google.sm
O1 - Hosts: 69.31.81.22 www.google.td
O1 - Hosts: 69.31.81.22 www.google.tm
O2 - BHO: CExtension Object - {0019C3E2-DD48-4A6D-ABCD-8D32436323D9} - C:\WINDOWS\cfgmgr52.dll (file missing)
O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll
O3 - Toolbar: McAfee VirusScan - {BA52B914-B692-46c4-B683-905236F6F655} - c:\progra~1\mcafee.com\vso\mcvsshl.dll
O4 - HKLM\..\Run: [IgfxTray] C:\WINDOWS\System32\igfxtray.exe
O4 - HKLM\..\Run: [HotKeysCmds] C:\WINDOWS\System32\hkcmd.exe
O4 - HKLM\..\Run: [HP Component Manager] "C:\Program Files\HP\hpcoretech\hpcmpmgr.exe"
O4 - HKLM\..\Run: [MMTray] C:\Program Files\MUSICMATCH\MUSICMATCH Jukebox\mm_tray.exe
O4 - HKLM\..\Run: [MCAgentExe] c:\PROGRA~1\mcafee.com\agent\mcagent.exe files\mcafee.com\agent\mcagent.exe
O4 - HKLM\..\Run: [MCUpdateExe] C:\PROGRA~1\mcafee.com\agent\McUpdate.exe
O4 - HKLM\..\Run: [AdaptecDirectCD] "C:\Program Files\Roxio\Easy CD Creator 5\DirectCD\DirectCD.exe"
O4 - HKLM\..\Run: [VirusScan Online] "c:\PROGRA~1\mcafee.com\vso\mcvsshld.exe"
O4 - HKLM\..\Run: [RealTray] C:\Program Files\Real\RealPlayer\RealPlay.exe SYSTEMBOOTHIDEPLAYER
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [MPFExe] C:\PROGRA~1\McAfee.com\PERSON~1\MpfTray.exe
O4 - HKLM\..\Run: [Microsoft Works Update Detection] C:\Program Files\Common Files\Microsoft Shared\Works Shared\WkUFind.exe
O4 - HKLM\..\Run: [HP Software Update] C:\Program Files\HP\HP Software Update\HPWuSchd2.exe
O4 - HKLM\..\Run: [VBundleOuterDL] C:\Program Files\VBouncer\BundleOuter.EXE
O4 - HKLM\..\Run: [cfgmgr52] RunDLL32.EXE C:\WINDOWS\cfgmgr52.dll,DllRun
O4 - HKLM\..\Run: [PSGuard] C:\Program Files\PSGuard\PSGuard.exe
O4 - HKLM\..\Run: [IMJPMIG8.1] "C:\WINDOWS\IME\imjp8_1\IMJPMIG.EXE" /Spoil /RemAdvDef /Migration32
O4 - HKLM\..\Run: [CToolBar] TorontoMail.exe
O4 - HKLM\..\Run: [atl_helper] abrek.exe
O4 - HKLM\..\Run: [Media Access] C:\Program Files\Media Access\MediaAccK.exe
O4 - HKLM\..\Run: [SpySweeper] "C:\Program Files\Webroot\Spy Sweeper\SpySweeper.exe" /startintray
O4 - HKLM\..\Run: [winsync] C:\WINDOWS\System32\k44xpl.exe reg_run
O4 - HKLM\..\Run: [VSOCheckTask] "c:\PROGRA~1\mcafee.com\vso\mcmnhdlr.exe" /checktask
O4 - HKCU\..\Run: [Yahoo! Pager] C:\Program Files\Yahoo!\Messenger\ypager.exe -quiet
O4 - HKCU\..\Run: [DellSupport] "C:\Program Files\Dell Support\DSAgnt.exe" /startup
O4 - HKCU\..\Run: [WareOut] "C:\Program Files\WareOut\WareOut.exe"
O4 - HKCU\..\Run: [SYSTRAV] control64.exe
O4 - HKCU\..\Run: [uio] Brong32.exe
O4 - HKCU\..\Run: [ssweeper] KeywordFinder.exe
O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
O4 - Global Startup: Adobe Reader Speed Launch.lnk = C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
O4 - Global Startup: America Online 9.0 Tray Icon.lnk = C:\Program Files\America Online 9.0\aoltray.exe
O4 - Global Startup: AOL Companion.lnk = C:\Program Files\AOL Companion\companion.exe
O4 - Global Startup: HP Digital Imaging Monitor.lnk = C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe
O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office10\OSA.EXE
O8 - Extra context menu item: &Yahoo! Search - file:///C:\Program Files\Yahoo!\Common/ycsrch.htm
O8 - Extra context menu item: Yahoo! &Dictionary - file:///C:\Program Files\Yahoo!\Common/ycdict.htm
O8 - Extra context menu item: Yahoo! &Maps - file:///C:\Program Files\Yahoo!\Common/ycdict.htm
O9 - Extra button: Messenger - {4528BBE0-4E08-11D5-AD55-00010333D0AD} - C:\Program Files\Yahoo!\Messenger\yhexbmes0521.dll
O9 - Extra 'Tools' menuitem: Yahoo! Messenger - {4528BBE0-4E08-11D5-AD55-00010333D0AD} - C:\Program Files\Yahoo!\Messenger\yhexbmes0521.dll
O9 - Extra button: (no name) - {9E248641-0E24-4DDB-9A1F-705087832AD6} - C:\WINDOWS\System32\wuauclt.dll (file missing)
O9 - Extra 'Tools' menuitem: Java - {9E248641-0E24-4DDB-9A1F-705087832AD6} - C:\WINDOWS\System32\wuauclt.dll (file missing)
O9 - Extra button: Related - {c95fe080-8f5d-11d2-a20b-00aa003c157a} - C:\WINDOWS\web\related.htm
O9 - Extra 'Tools' menuitem: Show &Related Links - {c95fe080-8f5d-11d2-a20b-00aa003c157a} - C:\WINDOWS\web\related.htm
O9 - Extra button: Real.com - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - C:\WINDOWS\System32\Shdocvw.dll
O9 - Extra button: MoneySide - {E023F504-0C5A-4750-A1E7-A9046DEA8A21} - C:\Program Files\Microsoft Money\System\mnyside.dll
O9 - Extra button: PartyPoker.net - {F4430FE8-2638-42e5-B849-800749B94EED} - C:\Program Files\PartyPoker.net\partypokernet.exe
O9 - Extra 'Tools' menuitem: PartyPoker.net - {F4430FE8-2638-42e5-B849-800749B94EED} - C:\Program Files\PartyPoker.net\partypokernet.exe
O16 - DPF: Yahoo! Poker - http://download.games.yahoo.com/games/clients/y/pt3_x.cab
O16 - DPF: {42F2C9BA-614F-47C0-B3E3-ECFD34EED658} (Installer Class) - http://www.ysbweb.com/ist/softwares/v4.0/ysb_1002952.cab
O16 - DPF: {4ED9DDF0-7479-4BBE-9335-5A1EDB1D8A21} (McAfee.com Operating System Class) - http://download.mcafee.com/molbin/shared/m...84/mcinsctl.cab
O16 - DPF: {9522B3FB-7A2B-4646-8AF6-36E7F593073C} (cpbrkpie Control) - http://a19.g.akamai.net/7/19/7125/4047/ftp...23/cpbrkpie.cab
O16 - DPF: {BCC0FF27-31D9-4614-A68E-C18E1ADA4389} (DwnldGroupMgr Class) - http://download.mcafee.com/molbin/shared/m...,21/mcgdmgr.cab
O20 - Winlogon Notify: igfxcui - C:\WINDOWS\SYSTEM32\igfxsrvc.dll
O23 - Service: AOL Connectivity Service (AOL ACS) - America Online, Inc. - C:\PROGRA~1\COMMON~1\AOL\ACS\acsd.exe
O23 - Service: McAfee.com McShield (McShield) - Unknown owner - c:\PROGRA~1\mcafee.com\vso\mcshield.exe
O23 - Service: McAfee SecurityCenter Update Manager (mcupdmgr.exe) - Networks Associates Technology, Inc - C:\PROGRA~1\McAfee.com\Agent\mcupdmgr.exe
O23 - Service: McAfee.com VirusScan Online Realtime Engine (MCVSRte) - Networks Associates Technology, Inc - c:\PROGRA~1\mcafee.com\vso\mcvsrte.exe
O23 - Service: McAfee.com Personal Firewall Service (MpfService) - McAfee.com Corporation - C:\PROGRA~1\McAfee.com\PERSON~1\MPFSERVICE.exe
O23 - Service: Pml Driver HPZ12 - HP - C:\WINDOWS\System32\HPZipm12.exe
O23 - Service: Webroot Spy Sweeper Engine (svcWRSSSDK) - Webroot Software, Inc. - C:\Program Files\Webroot\Spy Sweeper\WRSSSDK.exe
O23 - Service: WAN Miniport (ATW) Service (WANMiniportService) - America Online, Inc. - C:\WINDOWS\wanmpsvc.exe



Find Qoologic last edited 9/02/2005
PLEASE NOTE THAT ALL FILES FOUND BY THIS METHOD ARE NOT BAD FILES, There WILL be LEGIT FILES LISTED PLEASE BE CAREFUL WHILE FIXING. IF YOU ARE UNSURE OF WHAT IT IS LEAVE THEM ALONE.
some examples are MRT.EXE NTDLL.DLL.
»»»»»»»»»»»»»»»»»»»»»»»» Files found »»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»

»»»»»»»»»»»»»»»»»»»»»»»» startup files»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»


»»»»»»»»»»»»»»»»»»»»»»»» Checking Global Startup »»»»»»»»»»»»»»»»»»»»»»

(fstarts by IMM - test ver. 0.001) NOT using address check -- 0x77f75fae

Global Startup:
C:\Documents and Settings\All Users\Start Menu\Programs\Startup
.
..
Adobe Reader Speed Launch.lnk
America Online 9.0 Tray Icon.lnk
AOL Companion.lnk
desktop.ini
HP Digital Imaging Monitor.lnk
Microsoft Office.lnk

User Startup:
C:\Documents and Settings\Owner\Start Menu\Programs\Startup
.
..
desktop.ini

»»»»» Search by size and name...
»»»»» Files found by this method are not necessarily bad...
»»»»» Example PNGFILT.DLL ctl3d32.dll are windows files...

#12 hrlyrbl

hrlyrbl
  • Topic Starter

  • Members
  • 8 posts
  • OFFLINE
  •  
  • Local time:12:55 AM

Posted 07 October 2005 - 03:55 PM

Was this the only logs you needed? I haven't heard anything back so I wasn't sure.




0 user(s) are reading this topic

0 members, 0 guests, 0 anonymous users