:OTL SRV - [2010/09/05 06:01:42 | 000,028,762 | ---- | M] (MyWebSearch.com) [Auto] -- C:\Program Files\MyWebSearch\bar\2.bin\MWSSVC.EXE -- (MyWebSearchService) DRV - [2010/10/28 15:47:52 | 000,000,000 | ---- | M] () [Kernel | Boot] -- C:\WINDOWS\System32\drivers\ccxucg.sys -- (ccxucg) DRV - [2010/10/10 16:20:56 | 000,052,736 | ---- | M] () [Kernel | System] -- C:\WINDOWS\PRAGMAsivpdrbces\PRAGMAd.sys -- (PRAGMAsivpdrbces) IE - HKU\.DEFAULT\..\URLSearchHook: {00A6FAF6-072E-44cf-8957-5838F569A31D} - C:\Program Files\MyWebSearch\bar\2.bin\MWSSRCAS.DLL (MyWebSearch.com) IE - HKU\dion_ON_C\Software\Microsoft\Internet Explorer\Main,Start Page = http://home.mywebsea...trLw&n=77ceab12 IE - HKU\dion_ON_C\..\URLSearchHook: {00A6FAF6-072E-44cf-8957-5838F569A31D} - C:\Program Files\MyWebSearch\bar\2.bin\MWSSRCAS.DLL (MyWebSearch.com) IE - HKU\Tamara_x_x_ON_C\..\URLSearchHook: {00A6FAF6-072E-44cf-8957-5838F569A31D} - C:\Program Files\MyWebSearch\bar\2.bin\MWSSRCAS.DLL (MyWebSearch.com) FF - HKLM\software\mozilla\Firefox\Extensions\\m3ffxtbr@mywebsearch.com: C:\Program Files\MyWebSearch\bar\2.bin [2010/09/17 12:38:13 | 000,000,000 | ---D | M] FF - HKLM\software\mozilla\Firefox\Extensions\\{DFAD8032-344F-4105-82EA-26C5B0A84DBF}: C:\Documents and Settings\Tamara x x\Local Settings\Application Data\{DFAD8032-344F-4105-82EA-26C5B0A84DBF} [2010/10/10 16:21:06 | 000,000,000 | ---D | M] O2 - BHO: (C:\WINDOWS\system32\mzmddj1nar.dll) - {D6BA40A1-A502-59BD-F413-04B03A2C8953} - C:\WINDOWS\system32\mzmddj1nar.dll () O3 - HKLM\..\Toolbar: (My Web Search) - {07B18EA9-A523-4961-B6BB-170DE4475CCA} - C:\Program Files\MyWebSearch\bar\2.bin\MWSBAR.DLL (MyWebSearch.com) O3 - HKU\.DEFAULT\..\Toolbar\WebBrowser: (My Web Search) - {07B18EA9-A523-4961-B6BB-170DE4475CCA} - C:\Program Files\MyWebSearch\bar\2.bin\MWSBAR.DLL (MyWebSearch.com) O3 - HKU\dion_ON_C\..\Toolbar\WebBrowser: (My Web Search) - {07B18EA9-A523-4961-B6BB-170DE4475CCA} - C:\Program Files\MyWebSearch\bar\2.bin\MWSBAR.DLL (MyWebSearch.com) O3 - HKU\Tamara_x_x_ON_C\..\Toolbar\WebBrowser: (My Web Search) - {07B18EA9-A523-4961-B6BB-170DE4475CCA} - C:\Program Files\MyWebSearch\bar\2.bin\MWSBAR.DLL (MyWebSearch.com) O4 - HKLM..\Run: [HNUIQOXRmSc] C:\Documents and Settings\Tamara x x\Local Settings\Temp\avp32.exe (Microsoft Corporation) O4 - HKLM..\Run: [HNUIQOXRnE0] C:\Documents and Settings\Tamara x x\Local Settings\Temp\cmd .exe () O4 - HKLM..\Run: [HNUIQOXRnEc] C:\Documents and Settings\Tamara x x\Local Settings\Temp\cmd .exe () O4 - HKLM..\Run: [HNUIQOXRnEg0] C:\Documents and Settings\Tamara x x\Local Settings\Temp\cmd .exe () O4 - HKLM..\Run: [HNUIQOXRnEgc] C:\Documents and Settings\Tamara x x\Local Settings\Temp\cmd .exe () O4 - HKLM..\Run: [HNUIQOXRnEgg0] C:\Documents and Settings\Tamara x x\Local Settings\Temp\cmd .exe () O4 - HKLM..\Run: [HNUIQOXRnEggc] C:\Documents and Settings\Tamara x x\Local Settings\Temp\cmd .exe () O4 - HKLM..\Run: [HNUIQOXRnEggj] C:\Documents and Settings\Tamara x x\Local Settings\Temp\cmd .exe () O4 - HKLM..\Run: [HNUIQOXRnEggK] C:\Documents and Settings\Tamara x x\Local Settings\Temp\cmd .exe () O4 - HKLM..\Run: [HNUIQOXRnEgj] C:\Documents and Settings\Tamara x x\Local Settings\Temp\cmd .exe () O4 - HKLM..\Run: [HNUIQOXRnEgK] C:\Documents and Settings\Tamara x x\Local Settings\Temp\cmd .exe () O4 - HKLM..\Run: [HNUIQOXRnEj] C:\Documents and Settings\Tamara x x\Local Settings\Temp\cmd .exe () O4 - HKLM..\Run: [HNUIQOXRnEK] C:\Documents and Settings\Tamara x x\Local Settings\Temp\cmd .exe () O4 - HKLM..\Run: [HNUIQOXRnH] C:\Documents and Settings\Tamara x x\Local Settings\Temp\cmd .exe () O4 - HKLM..\Run: [HNUIQOXRnsc] C:\Documents and Settings\Tamara x x\Local Settings\Temp\drweb.exe (Microsoft Corporation) O4 - HKLM..\Run: [HNUIQOXRny0] C:\Documents and Settings\Tamara x x\Local Settings\Temp\csrss .exe () O4 - HKLM..\Run: [HNUIQOXRnyc] C:\Documents and Settings\Tamara x x\Local Settings\Temp\csrss.exe () O4 - HKLM..\Run: [HNUIQOXRnyg0] C:\Documents and Settings\Tamara x x\Local Settings\Temp\csrss .exe () O4 - HKLM..\Run: [HNUIQOXRnygc] C:\Documents and Settings\Tamara x x\Local Settings\Temp\csrss .exe () O4 - HKLM..\Run: [HNUIQOXRnygg0] C:\Documents and Settings\Tamara x x\Local Settings\Temp\csrss .exe () O4 - HKLM..\Run: [HNUIQOXRnyggc] C:\Documents and Settings\Tamara x x\Local Settings\Temp\csrss .exe () O4 - HKLM..\Run: [HNUIQOXRnyggK] C:\Documents and Settings\Tamara x x\Local Settings\Temp\csrss .exe () O4 - HKLM..\Run: [HNUIQOXRnygj] C:\Documents and Settings\Tamara x x\Local Settings\Temp\csrss .exe () O4 - HKLM..\Run: [HNUIQOXRnygK] C:\Documents and Settings\Tamara x x\Local Settings\Temp\csrss .exe () O4 - HKLM..\Run: [HNUIQOXRnyj] C:\Documents and Settings\Tamara x x\Local Settings\Temp\csrss .exe () O4 - HKLM..\Run: [HNUIQOXRnyK] C:\Documents and Settings\Tamara x x\Local Settings\Temp\csrss .exe () O4 - HKLM..\Run: [HNUIQOXRnZ] C:\Documents and Settings\Tamara x x\Local Settings\Temp\cmd.exe () O4 - HKLM..\Run: [HNUIQOXRota] C:\Documents and Settings\Tamara x x\Local Settings\Temp\install.exe () O4 - HKLM..\Run: [HNUIQOXRotc] C:\Documents and Settings\Tamara x x\Local Settings\Temp\hexdump.exe () O4 - HKLM..\Run: [HNUIQOXRotGc] C:\Documents and Settings\Tamara x x\Local Settings\Temp\install .exe () O4 - HKLM..\Run: [HNUIQOXRotGK] C:\Documents and Settings\Tamara x x\Local Settings\Temp\install .exe () O4 - HKLM..\Run: [HNUIQOXRotH0] C:\Documents and Settings\Tamara x x\Local Settings\Temp\hexdump .exe () O4 - HKLM..\Run: [HNUIQOXRotHc] C:\Documents and Settings\Tamara x x\Local Settings\Temp\hexdump .exe () O4 - HKLM..\Run: [HNUIQOXRotHg0] C:\Documents and Settings\Tamara x x\Local Settings\Temp\hexdump .exe () O4 - HKLM..\Run: [HNUIQOXRotHgc] C:\Documents and Settings\Tamara x x\Local Settings\Temp\hexdump .exe () O4 - HKLM..\Run: [HNUIQOXRotHggc] C:\Documents and Settings\Tamara x x\Local Settings\Temp\hexdump .exe () O4 - HKLM..\Run: [HNUIQOXRotHgj] C:\Documents and Settings\Tamara x x\Local Settings\Temp\hexdump .exe () O4 - HKLM..\Run: [HNUIQOXRotHgK] C:\Documents and Settings\Tamara x x\Local Settings\Temp\hexdump .exe () O4 - HKLM..\Run: [HNUIQOXRotHj] C:\Documents and Settings\Tamara x x\Local Settings\Temp\hexdump .exe () O4 - HKLM..\Run: [HNUIQOXRotHK] C:\Documents and Settings\Tamara x x\Local Settings\Temp\hexdump .exe () O4 - HKLM..\Run: [HNUIQOXRotJ] C:\Documents and Settings\Tamara x x\Local Settings\Temp\install .exe () O4 - HKLM..\Run: [HNUIQOXRotK] C:\Documents and Settings\Tamara x x\Local Settings\Temp\hexdump .exe () O4 - HKLM..\Run: [HNUIQOXRouqc] C:\Documents and Settings\Tamara x x\Local Settings\Temp\iexplarer.exe (Microsoft Corporation) O4 - HKLM..\Run: [HNUIQOXRouqK] C:\Documents and Settings\Tamara x x\Local Settings\Temp\iexplarer .exe () O4 - HKLM..\Run: [HNUIQOXRpc+] C:\Documents and Settings\Tamara x x\Local Settings\Temp\n2mih8u .exe () O4 - HKLM..\Run: [HNUIQOXRpc70] C:\Documents and Settings\Tamara x x\Local Settings\Temp\n2mih8u .exe () O4 - HKLM..\Run: [HNUIQOXRpc7c] C:\Documents and Settings\Tamara x x\Local Settings\Temp\n2mih8u .exe () O4 - HKLM..\Run: [HNUIQOXRpc7g0] C:\Documents and Settings\Tamara x x\Local Settings\Temp\n2mih8u .exe () O4 - HKLM..\Run: [HNUIQOXRpc7gc] C:\Documents and Settings\Tamara x x\Local Settings\Temp\n2mih8u .exe () O4 - HKLM..\Run: [HNUIQOXRpc7gj] C:\Documents and Settings\Tamara x x\Local Settings\Temp\n2mih8u .exe () O4 - HKLM..\Run: [HNUIQOXRpc7gK] C:\Documents and Settings\Tamara x x\Local Settings\Temp\n2mih8u .exe () O4 - HKLM..\Run: [HNUIQOXRpc7j] C:\Documents and Settings\Tamara x x\Local Settings\Temp\n2mih8u .exe () O4 - HKLM..\Run: [HNUIQOXRpc7K] C:\Documents and Settings\Tamara x x\Local Settings\Temp\n2mih8u .exe () O4 - HKLM..\Run: [HNUIQOXRpcQ] C:\Documents and Settings\Tamara x x\Local Settings\Temp\n2mih8u.exe () O4 - HKLM..\Run: [HNUIQOXRpr0] C:\Documents and Settings\Tamara x x\Local Settings\Temp\login .exe () O4 - HKLM..\Run: [HNUIQOXRprc] C:\Documents and Settings\Tamara x x\Local Settings\Temp\login.exe () O4 - HKLM..\Run: [HNUIQOXRprg0] C:\Documents and Settings\Tamara x x\Local Settings\Temp\login .exe () O4 - HKLM..\Run: [HNUIQOXRprgc] C:\Documents and Settings\Tamara x x\Local Settings\Temp\login .exe () O4 - HKLM..\Run: [HNUIQOXRprgg0] C:\Documents and Settings\Tamara x x\Local Settings\Temp\login .exe () O4 - HKLM..\Run: [HNUIQOXRprggc] C:\Documents and Settings\Tamara x x\Local Settings\Temp\login .exe () O4 - HKLM..\Run: [HNUIQOXRprggg0] C:\Documents and Settings\Tamara x x\Local Settings\Temp\login .exe () O4 - HKLM..\Run: [HNUIQOXRprgggc] C:\Documents and Settings\Tamara x x\Local Settings\Temp\login .exe () O4 - HKLM..\Run: [HNUIQOXRprgggj] C:\Documents and Settings\Tamara x x\Local Settings\Temp\login .exe () O4 - HKLM..\Run: [HNUIQOXRprgggK] C:\Documents and Settings\Tamara x x\Local Settings\Temp\login .exe () O4 - HKLM..\Run: [HNUIQOXRprggj] C:\Documents and Settings\Tamara x x\Local Settings\Temp\login .exe () O4 - HKLM..\Run: [HNUIQOXRprggK] C:\Documents and Settings\Tamara x x\Local Settings\Temp\login .exe () O4 - HKLM..\Run: [HNUIQOXRprgj] C:\Documents and Settings\Tamara x x\Local Settings\Temp\login .exe () O4 - HKLM..\Run: [HNUIQOXRprgK] C:\Documents and Settings\Tamara x x\Local Settings\Temp\login .exe () O4 - HKLM..\Run: [HNUIQOXRprj] C:\Documents and Settings\Tamara x x\Local Settings\Temp\login .exe () O4 - HKLM..\Run: [HNUIQOXRprK] C:\Documents and Settings\Tamara x x\Local Settings\Temp\login .exe () O4 - HKLM..\Run: [HNUIQOXRpSg2c] C:\Documents and Settings\Tamara x x\Local Settings\Temp\l42muyf1sx .exe () O4 - HKLM..\Run: [HNUIQOXRpSg2K] C:\Documents and Settings\Tamara x x\Local Settings\Temp\l42muyf1sx .exe () O4 - HKLM..\Run: [HNUIQOXRpSg5] C:\Documents and Settings\Tamara x x\Local Settings\Temp\l42muyf1sx .exe () O4 - HKLM..\Run: [HNUIQOXRpSgg] C:\Documents and Settings\Tamara x x\Local Settings\Temp\l42muyf1sx.exe () O4 - HKLM..\Run: [HNUIQOXRpSgK] C:\Documents and Settings\Tamara x x\Local Settings\Temp\l42muyf1sx .exe () O4 - HKLM..\Run: [HNUIQOXRpZ] C:\Documents and Settings\Tamara x x\Local Settings\Temp\mdm.exe (Microsoft Corporation) O4 - HKLM..\Run: [HNUIQOXRrc0] C:\Documents and Settings\Tamara x x\Local Settings\Temp\smss .exe () O4 - HKLM..\Run: [HNUIQOXRrcc] C:\Documents and Settings\Tamara x x\Local Settings\Temp\smss .exe () O4 - HKLM..\Run: [HNUIQOXRrcj] C:\Documents and Settings\Tamara x x\Local Settings\Temp\smss .exe () O4 - HKLM..\Run: [HNUIQOXRrcK] C:\Documents and Settings\Tamara x x\Local Settings\Temp\smss .exe () O4 - HKLM..\Run: [HNUIQOXRrg] C:\Documents and Settings\Tamara x x\Local Settings\Temp\smss.exe () O4 - HKLM..\Run: [HNUIQOXRrta] C:\Documents and Settings\Tamara x x\Local Settings\Temp\services.exe (Microsoft Corporation) O4 - HKLM..\Run: [HNUIQOXRrtWc] C:\Documents and Settings\Tamara x x\Local Settings\Temp\services .exe () O4 - HKLM..\Run: [HNUIQOXRrv0] C:\Documents and Settings\Tamara x x\Local Settings\Temp\setup .exe () O4 - HKLM..\Run: [HNUIQOXRrvc] C:\Documents and Settings\Tamara x x\Local Settings\Temp\setup.exe () O4 - HKLM..\Run: [HNUIQOXRrvg0] C:\Documents and Settings\Tamara x x\Local Settings\Temp\setup .exe () O4 - HKLM..\Run: [HNUIQOXRrvgc] C:\Documents and Settings\Tamara x x\Local Settings\Temp\setup .exe () O4 - HKLM..\Run: [HNUIQOXRrvgg0] C:\Documents and Settings\Tamara x x\Local Settings\Temp\setup .exe () O4 - HKLM..\Run: [HNUIQOXRrvggc] C:\Documents and Settings\Tamara x x\Local Settings\Temp\setup .exe () O4 - HKLM..\Run: [HNUIQOXRrvggj] C:\Documents and Settings\Tamara x x\Local Settings\Temp\setup .exe () O4 - HKLM..\Run: [HNUIQOXRrvggK] C:\Documents and Settings\Tamara x x\Local Settings\Temp\setup .exe () O4 - HKLM..\Run: [HNUIQOXRrvgj] C:\Documents and Settings\Tamara x x\Local Settings\Temp\setup .exe () O4 - HKLM..\Run: [HNUIQOXRrvgK] C:\Documents and Settings\Tamara x x\Local Settings\Temp\setup .exe () O4 - HKLM..\Run: [HNUIQOXRrvj] C:\Documents and Settings\Tamara x x\Local Settings\Temp\setup .exe () O4 - HKLM..\Run: [HNUIQOXRrvK] C:\Documents and Settings\Tamara x x\Local Settings\Temp\setup .exe () O4 - HKLM..\Run: [HNUIQOXRsa] C:\Documents and Settings\Tamara x x\Local Settings\Temp\win.exe (Microsoft Corporation) O4 - HKLM..\Run: [HNUIQOXRsPc] C:\Documents and Settings\Tamara x x\Local Settings\Temp\win16.exe (Microsoft Corporation) O4 - HKLM..\Run: [HNUIQOXRsPK] C:\Documents and Settings\Tamara x x\Local Settings\Temp\win32 .exe () O4 - HKLM..\Run: [HNUIQOXRsre] C:\Documents and Settings\Tamara x x\Local Settings\Temp\wininst.exe () O4 - HKLM..\Run: [HNUIQOXRsrJ0] C:\Documents and Settings\Tamara x x\Local Settings\Temp\wininst .exe () O4 - HKLM..\Run: [HNUIQOXRsrJc] C:\Documents and Settings\Tamara x x\Local Settings\Temp\wininst .exe () O4 - HKLM..\Run: [HNUIQOXRsrJg0] C:\Documents and Settings\Tamara x x\Local Settings\Temp\wininst .exe () O4 - HKLM..\Run: [HNUIQOXRsrJgc] C:\Documents and Settings\Tamara x x\Local Settings\Temp\wininst .exe () O4 - HKLM..\Run: [HNUIQOXRsrJgj] C:\Documents and Settings\Tamara x x\Local Settings\Temp\wininst .exe () O4 - HKLM..\Run: [HNUIQOXRsrJgK] C:\Documents and Settings\Tamara x x\Local Settings\Temp\wininst .exe () O4 - HKLM..\Run: [HNUIQOXRsrJj] C:\Documents and Settings\Tamara x x\Local Settings\Temp\wininst .exe () O4 - HKLM..\Run: [HNUIQOXRsrJK] C:\Documents and Settings\Tamara x x\Local Settings\Temp\wininst .exe () O4 - HKLM..\Run: [HNUIQOXRsrN] C:\Documents and Settings\Tamara x x\Local Settings\Temp\wininst .exe () O4 - HKLM..\Run: [MKbMc] C:\WINDOWS\gdi32.exe (Microsoft Corporation) O4 - HKLM..\Run: [MKbtc] C:\WINDOWS\hexdump.exe () O4 - HKLM..\Run: [MKbtH0] C:\WINDOWS\hexdump .exe () O4 - HKLM..\Run: [MKbtHc] C:\WINDOWS\hexdump .exe () O4 - HKLM..\Run: [MKbtHg0] C:\WINDOWS\hexdump .exe () O4 - HKLM..\Run: [MKbtHgc] C:\WINDOWS\hexdump .exe () O4 - HKLM..\Run: [MKbtHgK] C:\WINDOWS\hexdump .exe () O4 - HKLM..\Run: [MKbtHj] C:\WINDOWS\hexdump .exe () O4 - HKLM..\Run: [MKbtHK] C:\WINDOWS\hexdump .exe () O4 - HKLM..\Run: [MKbtK] C:\WINDOWS\hexdump .exe () O4 - HKLM..\Run: [MKbuqc] C:\WINDOWS\iexplarer.exe (Microsoft Corporation) O4 - HKLM..\Run: [MKcr0] C:\WINDOWS\login .exe () O4 - HKLM..\Run: [MKcrc] C:\WINDOWS\login.exe () O4 - HKLM..\Run: [MKcrg0] C:\WINDOWS\login .exe () O4 - HKLM..\Run: [MKcrgc] C:\WINDOWS\login .exe () O4 - HKLM..\Run: [MKcrgg0] C:\WINDOWS\login .exe () O4 - HKLM..\Run: [MKcrggc] C:\WINDOWS\login .exe () O4 - HKLM..\Run: [MKcrggg0] C:\WINDOWS\login .exe () O4 - HKLM..\Run: [MKcrgggc] C:\WINDOWS\login .exe () O4 - HKLM..\Run: [MKcrgggg0] C:\WINDOWS\login .exe () O4 - HKLM..\Run: [MKcrggggc] C:\WINDOWS\login .exe () O4 - HKLM..\Run: [MKcrggggg0] C:\WINDOWS\login .exe () O4 - HKLM..\Run: [MKcrgggggc] C:\WINDOWS\login .exe () O4 - HKLM..\Run: [MKcrgggggg0] C:\WINDOWS\login .exe () O4 - HKLM..\Run: [MKcrggggggc] C:\WINDOWS\login .exe () O4 - HKLM..\Run: [MKcrggggggg0] C:\WINDOWS\login .exe () O4 - HKLM..\Run: [MKcrgggggggc] C:\WINDOWS\login .exe () O4 - HKLM..\Run: [MKcrgggggggg0] C:\WINDOWS\login .exe () O4 - HKLM..\Run: [MKcrggggggggc] C:\WINDOWS\login .exe () O4 - HKLM..\Run: [MKcrgggggggggc] C:\WINDOWS\login .exe () O4 - HKLM..\Run: [MKcrgggggggggK] C:\WINDOWS\login .exe () O4 - HKLM..\Run: [MKcrggggggggj] C:\WINDOWS\login .exe () O4 - HKLM..\Run: [MKcrggggggggK] C:\WINDOWS\login .exe () O4 - HKLM..\Run: [MKcrgggggggj] C:\WINDOWS\login .exe () O4 - HKLM..\Run: [MKcrgggggggK] C:\WINDOWS\login .exe () O4 - HKLM..\Run: [MKcrggggggj] C:\WINDOWS\login .exe () O4 - HKLM..\Run: [MKcrggggggK] C:\WINDOWS\login .exe () O4 - HKLM..\Run: [MKcrgggggj] C:\WINDOWS\login .exe () O4 - HKLM..\Run: [MKcrgggggK] C:\WINDOWS\login .exe () O4 - HKLM..\Run: [MKcrggggj] C:\WINDOWS\login .exe () O4 - HKLM..\Run: [MKcrggggK] C:\WINDOWS\login .exe () O4 - HKLM..\Run: [MKcrgggj] C:\WINDOWS\login .exe () O4 - HKLM..\Run: [MKcrgggK] C:\WINDOWS\login .exe () O4 - HKLM..\Run: [MKcrggj] C:\WINDOWS\login .exe () O4 - HKLM..\Run: [MKcrggK] C:\WINDOWS\login .exe () O4 - HKLM..\Run: [MKcrgj] C:\WINDOWS\login .exe () O4 - HKLM..\Run: [MKcrgK] C:\WINDOWS\login .exe () O4 - HKLM..\Run: [MKcrj] C:\WINDOWS\login .exe () O4 - HKLM..\Run: [MKcrK] C:\WINDOWS\login .exe () O4 - HKLM..\Run: [MKcuc] C:\WINDOWS\lsass.exe () O4 - HKLM..\Run: [MKcZ] C:\WINDOWS\mdm.exe (Microsoft Corporation) O4 - HKLM..\Run: [MKdw+] C:\WINDOWS\nvsvc32.exe () O4 - HKLM..\Run: [MKdws] C:\WINDOWS\nvsvc32 .exe () O4 - HKLM..\Run: [MKerb] C:\WINDOWS\taskmgr.exe () O4 - HKLM..\Run: [MKeta] C:\WINDOWS\services.exe () O4 - HKLM..\Run: [MKetW0] C:\WINDOWS\services .exe () O4 - HKLM..\Run: [MKetWc] C:\WINDOWS\services .exe () O4 - HKLM..\Run: [MKetWg0] C:\WINDOWS\services .exe () O4 - HKLM..\Run: [MKetWgc] C:\WINDOWS\services .exe () O4 - HKLM..\Run: [MKetWgg0] C:\WINDOWS\services .exe () O4 - HKLM..\Run: [MKetWggc] C:\WINDOWS\services .exe () O4 - HKLM..\Run: [MKetWggg0] C:\WINDOWS\services .exe () O4 - HKLM..\Run: [MKetWgggc] C:\WINDOWS\services .exe () O4 - HKLM..\Run: [MKetWgggK] C:\WINDOWS\services .exe () O4 - HKLM..\Run: [MKetWggj] C:\WINDOWS\services .exe () O4 - HKLM..\Run: [MKetWggK] C:\WINDOWS\services .exe () O4 - HKLM..\Run: [MKetWggKWS\services .exe] C:\WINDOWS\services .exe () O4 - HKLM..\Run: [MKetWgj] C:\WINDOWS\services .exe () O4 - HKLM..\Run: [MKetWgK] C:\WINDOWS\services .exe () O4 - HKLM..\Run: [MKetWj] C:\WINDOWS\services .exe () O4 - HKLM..\Run: [MKetWK] C:\WINDOWS\services .exe () O4 - HKLM..\Run: [MKeuf] C:\WINDOWS\spoolsv.exe () O4 - HKLM..\Run: [MKeuK0] C:\WINDOWS\spoolsv .exe () O4 - HKLM..\Run: [MKeuKc] C:\WINDOWS\spoolsv .exe () O4 - HKLM..\Run: [MKeuKK] C:\WINDOWS\spoolsv .exe () O4 - HKLM..\Run: [MKeuN] C:\WINDOWS\spoolsv .exe () O4 - HKLM..\Run: [MKev0] C:\WINDOWS\setup .exe () O4 - HKLM..\Run: [MKevc] C:\WINDOWS\setup.exe () O4 - HKLM..\Run: [MKevj] C:\WINDOWS\setup .exe () O4 - HKLM..\Run: [MKevK] C:\WINDOWS\setup .exe () O4 - HKLM..\Run: [MKexe] C:\WINDOWS\system.exe (Microsoft Corporation) O4 - HKLM..\Run: [MKfa] C:\WINDOWS\win.exe (Microsoft Corporation) O4 - HKLM..\Run: [MKfP0] C:\WINDOWS\win16 .exe () O4 - HKLM..\Run: [MKfPc] C:\WINDOWS\win16.exe () O4 - HKLM..\Run: [MKfPg0] C:\WINDOWS\win16 .exe () O4 - HKLM..\Run: [MKfPgc] C:\WINDOWS\win16 .exe () O4 - HKLM..\Run: [MKfPgg0] C:\WINDOWS\win16 .exe () O4 - HKLM..\Run: [MKfPggc] C:\WINDOWS\win16 .exe () O4 - HKLM..\Run: [MKfPggg0] C:\WINDOWS\win16 .exe () O4 - HKLM..\Run: [MKfPgggc] C:\WINDOWS\win16 .exe () O4 - HKLM..\Run: [MKfPgggg0] C:\WINDOWS\win16 .exe () O4 - HKLM..\Run: [MKfPggggc] C:\WINDOWS\win16 .exe () O4 - HKLM..\Run: [MKfPggggg0] C:\WINDOWS\win16 .exe () O4 - HKLM..\Run: [MKfPgggggc] C:\WINDOWS\win16 .exe () O4 - HKLM..\Run: [MKfPgggggg0] C:\WINDOWS\win16 .exe () O4 - HKLM..\Run: [MKfPggggggc] C:\WINDOWS\win16 .exe () O4 - HKLM..\Run: [MKfPggggggg0] C:\WINDOWS\win16 .exe () O4 - HKLM..\Run: [MKfPgggggggc] C:\WINDOWS\win16 .exe () O4 - HKLM..\Run: [MKfPggggggggc] C:\WINDOWS\win16 .exe () O4 - HKLM..\Run: [MKfPgggggggj] C:\WINDOWS\win16 .exe () O4 - HKLM..\Run: [MKfPgggggggK] C:\WINDOWS\win16 .exe () O4 - HKLM..\Run: [MKfPggggggj] C:\WINDOWS\win16 .exe () O4 - HKLM..\Run: [MKfPggggggK] C:\WINDOWS\win16 .exe () O4 - HKLM..\Run: [MKfPgggggj] C:\WINDOWS\win16 .exe () O4 - HKLM..\Run: [MKfPgggggK] C:\WINDOWS\win16 .exe () O4 - HKLM..\Run: [MKfPggggj] C:\WINDOWS\win16 .exe () O4 - HKLM..\Run: [MKfPggggK] C:\WINDOWS\win16 .exe () O4 - HKLM..\Run: [MKfPgggj] C:\WINDOWS\win16 .exe () O4 - HKLM..\Run: [MKfPgggK] C:\WINDOWS\win16 .exe () O4 - HKLM..\Run: [MKfPggj] C:\WINDOWS\win16 .exe () O4 - HKLM..\Run: [MKfPggK] C:\WINDOWS\win16 .exe () O4 - HKLM..\Run: [MKfPgj] C:\WINDOWS\win16 .exe () O4 - HKLM..\Run: [MKfPgK] C:\WINDOWS\win16 .exe () O4 - HKLM..\Run: [MKfPj] C:\WINDOWS\win16 .exe () O4 - HKLM..\Run: [MKfPK] C:\WINDOWS\win16 .exe () O4 - HKLM..\Run: [MKfre] C:\WINDOWS\wininst.exe (Microsoft Corporation) O4 - HKLM..\Run: [MKfsc] C:\WINDOWS\winlogon.exe () O4 - HKLM..\Run: [MKWPeP] C:\WINDOWS\temp\avp32.exe (Microsoft Corporation) O4 - HKLM..\Run: [MKWPf6] C:\WINDOWS\temp\win16 .exe () O4 - HKLM..\Run: [MKWPfQ] C:\WINDOWS\temp\win16.exe () O4 - HKLM..\Run: [MKWPrc] C:\WINDOWS\temp\winamp.exe () O4 - HKLM..\Run: [MKWPsf] C:\WINDOWS\temp\lsass.exe () O4 - HKLM..\Run: [MKWPsJ] C:\WINDOWS\temp\lsass .exe () O4 - HKLM..\Run: [MKWPtd0] C:\WINDOWS\temp\wininst .exe () O4 - HKLM..\Run: [MKWPtdc] C:\WINDOWS\temp\wininst .exe () O4 - HKLM..\Run: [MKWPtdgc] C:\WINDOWS\temp\wininst .exe () O4 - HKLM..\Run: [MKWPtdj] C:\WINDOWS\temp\wininst .exe () O4 - HKLM..\Run: [MKWPtdK] C:\WINDOWS\temp\wininst .exe () O4 - HKLM..\Run: [MKWPtg] C:\WINDOWS\temp\wininst.exe () O4 - HKLM..\Run: [MKWPtp0c] C:\WINDOWS\temp\iexplarer .exe () O4 - HKLM..\Run: [MKWPtp0K] C:\WINDOWS\temp\iexplarer .exe () O4 - HKLM..\Run: [MKWPtp4] C:\WINDOWS\temp\iexplarer .exe () O4 - HKLM..\Run: [MKWPtpf] C:\WINDOWS\temp\iexplarer.exe () O4 - HKLM..\Run: [MKWPtpJ] C:\WINDOWS\temp\iexplarer .exe () O4 - HKLM..\Run: [MKWPvZ] C:\WINDOWS\temp\install.exe () O4 - HKLM..\Run: [MKWPwe] C:\WINDOWS\temp\setup.exe () O4 - HKLM..\Run: [MKWPwI] C:\WINDOWS\temp\setup .exe () O4 - HKLM..\Run: [MKZe] C:\WINDOWS\avp.exe (Microsoft Corporation) O4 - HKLM..\Run: [MKZSc] C:\WINDOWS\avp32.exe () O4 - HKLM..\Run: [MKZSK] C:\WINDOWS\avp32 .exe () O4 - HKLM..\Run: [My Web Search Bar Search Scope Monitor] C:\Program Files\MyWebSearch\bar\2.bin\m3SrchMn.exe () O4 - HKLM..\Run: [MyWebSearch Email Plugin] C:\Program Files\MyWebSearch\bar\2.bin\mwsoemon.exe () O4 - HKLM..\Run: [nonep] C:\Documents and Settings\Tamara x x\Local Settings\Temp\tmp0cec1dad\ee .exe () O4 - HKLM..\Run: [snp2uvc] C:\WINDOWS\vsnp2uvc.exe File not found O4 - HKLM..\Run: [uPc+MV0NdhaGuo] C:\WINDOWS\System32\n3xy5nh.DLL () O4 - HKLM..\Run: [uPc+MV0NmQaXms] C:\WINDOWS\System32\foj6mp.DLL () O4 - HKLM..\Run: [Yrowamumoke] C:\WINDOWS\idohokofa.DLL () O4 - HKU\.DEFAULT..\Run: [dfrgsnapnt.exe] C:\WINDOWS\temp\dfrgsnapnt.exe (Microsoft Corporation) O4 - HKU\.DEFAULT..\Run: [HNUIQOXRmSc] C:\Documents and Settings\Tamara x x\Local Settings\Temp\avp32.exe (Microsoft Corporation) O4 - HKU\.DEFAULT..\Run: [HNUIQOXRotK] C:\Documents and Settings\Tamara x x\Local Settings\Temp\hexdump .exe () O4 - HKU\.DEFAULT..\Run: [HNUIQOXRouqK] C:\Documents and Settings\Tamara x x\Local Settings\Temp\iexplarer .exe () O4 - HKU\.DEFAULT..\Run: [HNUIQOXRpc+] C:\Documents and Settings\Tamara x x\Local Settings\Temp\n2mih8u .exe () O4 - HKU\.DEFAULT..\Run: [HNUIQOXRpSgK] C:\Documents and Settings\Tamara x x\Local Settings\Temp\l42muyf1sx .exe () O4 - HKU\.DEFAULT..\Run: [HNUIQOXRrcc] C:\Documents and Settings\Tamara x x\Local Settings\Temp\smss .exe () O4 - HKU\.DEFAULT..\Run: [HNUIQOXRrtWc] C:\Documents and Settings\Tamara x x\Local Settings\Temp\services .exe () O4 - HKU\.DEFAULT..\Run: [HNUIQOXRrvK] C:\Documents and Settings\Tamara x x\Local Settings\Temp\setup .exe () O4 - HKU\.DEFAULT..\Run: [HNUIQOXRsrN] C:\Documents and Settings\Tamara x x\Local Settings\Temp\wininst .exe () O4 - HKU\.DEFAULT..\Run: [MKbMc] C:\WINDOWS\gdi32.exe (Microsoft Corporation) O4 - HKU\.DEFAULT..\Run: [MKbtK] C:\WINDOWS\hexdump .exe () O4 - HKU\.DEFAULT..\Run: [MKcr0] C:\WINDOWS\login .exe () O4 - HKU\.DEFAULT..\Run: [MKcrg0] C:\WINDOWS\login .exe () O4 - HKU\.DEFAULT..\Run: [MKcrgc] C:\WINDOWS\login .exe () O4 - HKU\.DEFAULT..\Run: [MKcrggc] C:\WINDOWS\login .exe () O4 - HKU\.DEFAULT..\Run: [MKcrggK] C:\WINDOWS\login .exe () O4 - HKU\.DEFAULT..\Run: [MKcrgj] C:\WINDOWS\login .exe () O4 - HKU\.DEFAULT..\Run: [MKcrgK] C:\WINDOWS\login .exe () O4 - HKU\.DEFAULT..\Run: [MKcrj] C:\WINDOWS\login .exe () O4 - HKU\.DEFAULT..\Run: [MKcrK] C:\WINDOWS\login .exe () O4 - HKU\.DEFAULT..\Run: [MKcuc] C:\WINDOWS\lsass.exe () O4 - HKU\.DEFAULT..\Run: [MKcZ] C:\WINDOWS\mdm.exe (Microsoft Corporation) O4 - HKU\.DEFAULT..\Run: [MKerb] C:\WINDOWS\taskmgr.exe () O4 - HKU\.DEFAULT..\Run: [MKetW0] C:\WINDOWS\services .exe () O4 - HKU\.DEFAULT..\Run: [MKetWc] C:\WINDOWS\services .exe () O4 - HKU\.DEFAULT..\Run: [MKetWg0] C:\WINDOWS\services .exe () O4 - HKU\.DEFAULT..\Run: [MKetWgc] C:\WINDOWS\services .exe () O4 - HKU\.DEFAULT..\Run: [MKetWgj] C:\WINDOWS\services .exe () O4 - HKU\.DEFAULT..\Run: [MKetWgK] C:\WINDOWS\services .exe () O4 - HKU\.DEFAULT..\Run: [MKetWj] C:\WINDOWS\services .exe () O4 - HKU\.DEFAULT..\Run: [MKetWK] C:\WINDOWS\services .exe () O4 - HKU\.DEFAULT..\Run: [MKeuf] C:\WINDOWS\spoolsv.exe () O4 - HKU\.DEFAULT..\Run: [MKexe] C:\WINDOWS\system.exe (Microsoft Corporation) O4 - HKU\.DEFAULT..\Run: [MKfa] C:\WINDOWS\win.exe (Microsoft Corporation) O4 - HKU\.DEFAULT..\Run: [MKfP0] C:\WINDOWS\win16 .exe () O4 - HKU\.DEFAULT..\Run: [MKfre] C:\WINDOWS\wininst.exe (Microsoft Corporation) O4 - HKU\.DEFAULT..\Run: [MKWPeP] C:\WINDOWS\temp\avp32.exe (Microsoft Corporation) O4 - HKU\.DEFAULT..\Run: [MKWPfQ] C:\WINDOWS\temp\win16.exe () O4 - HKU\.DEFAULT..\Run: [MKWPrc] C:\WINDOWS\temp\winamp.exe () O4 - HKU\.DEFAULT..\Run: [MKWPsf] C:\WINDOWS\temp\lsass.exe () O4 - HKU\.DEFAULT..\Run: [MKWPtg] C:\WINDOWS\temp\wininst.exe () O4 - HKU\.DEFAULT..\Run: [MKWPtp4] C:\WINDOWS\temp\iexplarer .exe () O4 - HKU\.DEFAULT..\Run: [MKWPtpf] C:\WINDOWS\temp\iexplarer.exe () O4 - HKU\.DEFAULT..\Run: [MKWPtpJ] C:\WINDOWS\temp\iexplarer .exe () O4 - HKU\.DEFAULT..\Run: [MKWPvZ] C:\WINDOWS\temp\install.exe () O4 - HKU\.DEFAULT..\Run: [MKWPwe] C:\WINDOWS\temp\setup.exe () O4 - HKU\.DEFAULT..\Run: [MKZe] C:\WINDOWS\avp.exe (Microsoft Corporation) O4 - HKU\.DEFAULT..\Run: [uPc+MV0NmQaXms] C:\WINDOWS\System32\foj6mp.DLL () O4 - HKU\dion_ON_C..\Run: [MyWebSearch Email Plugin] C:\PROGRA~1\MYWEBS~1\bar\1.bin\mwsoemon.exe File not found O4 - HKU\Tamara_x_x_ON_C..\Run: [{134DDCDE-3647-82F6-EE94-F56836D4842B}] C:\Documents and Settings\Tamara x x\Application Data\Izkoo\asema.exe () O4 - HKU\Tamara_x_x_ON_C..\Run: [{24984FB9-75B1-7984-F4FB-36E75E4A8403}] C:\Documents and Settings\Tamara x x\Application Data\Cuas\uvydu.exe () O4 - HKU\Tamara_x_x_ON_C..\Run: [{467FD43A-2F18-771E-930B-BAEF778D6D00}] C:\Documents and Settings\Tamara x x\Application Data\Acapqe\xaada.exe () O4 - HKU\Tamara_x_x_ON_C..\Run: [HNUIQOXRmSc] C:\Documents and Settings\Tamara x x\Local Settings\Temp\avp32.exe (Microsoft Corporation) O4 - HKU\Tamara_x_x_ON_C..\Run: [HNUIQOXRnE0] C:\Documents and Settings\Tamara x x\Local Settings\Temp\cmd .exe () O4 - HKU\Tamara_x_x_ON_C..\Run: [HNUIQOXRnEc] C:\Documents and Settings\Tamara x x\Local Settings\Temp\cmd .exe () O4 - HKU\Tamara_x_x_ON_C..\Run: [HNUIQOXRnEg0] C:\Documents and Settings\Tamara x x\Local Settings\Temp\cmd .exe () O4 - HKU\Tamara_x_x_ON_C..\Run: [HNUIQOXRnEgc] C:\Documents and Settings\Tamara x x\Local Settings\Temp\cmd .exe () O4 - HKU\Tamara_x_x_ON_C..\Run: [HNUIQOXRnEgg0] C:\Documents and Settings\Tamara x x\Local Settings\Temp\cmd .exe () O4 - HKU\Tamara_x_x_ON_C..\Run: [HNUIQOXRnEggc] C:\Documents and Settings\Tamara x x\Local Settings\Temp\cmd .exe () O4 - HKU\Tamara_x_x_ON_C..\Run: [HNUIQOXRnEggj] C:\Documents and Settings\Tamara x x\Local Settings\Temp\cmd .exe () O4 - HKU\Tamara_x_x_ON_C..\Run: [HNUIQOXRnEggK] C:\Documents and Settings\Tamara x x\Local Settings\Temp\cmd .exe () O4 - HKU\Tamara_x_x_ON_C..\Run: [HNUIQOXRnEgj] C:\Documents and Settings\Tamara x x\Local Settings\Temp\cmd .exe () O4 - HKU\Tamara_x_x_ON_C..\Run: [HNUIQOXRnEgK] C:\Documents and Settings\Tamara x x\Local Settings\Temp\cmd .exe () O4 - HKU\Tamara_x_x_ON_C..\Run: [HNUIQOXRnEj] C:\Documents and Settings\Tamara x x\Local Settings\Temp\cmd .exe () O4 - HKU\Tamara_x_x_ON_C..\Run: [HNUIQOXRnEK] C:\Documents and Settings\Tamara x x\Local Settings\Temp\cmd .exe () O4 - HKU\Tamara_x_x_ON_C..\Run: [HNUIQOXRnH] C:\Documents and Settings\Tamara x x\Local Settings\Temp\cmd .exe () O4 - HKU\Tamara_x_x_ON_C..\Run: [HNUIQOXRnsc] C:\Documents and Settings\Tamara x x\Local Settings\Temp\drweb.exe (Microsoft Corporation) O4 - HKU\Tamara_x_x_ON_C..\Run: [HNUIQOXRny0] C:\Documents and Settings\Tamara x x\Local Settings\Temp\csrss .exe () O4 - HKU\Tamara_x_x_ON_C..\Run: [HNUIQOXRnyc] C:\Documents and Settings\Tamara x x\Local Settings\Temp\csrss.exe () O4 - HKU\Tamara_x_x_ON_C..\Run: [HNUIQOXRnyg0] C:\Documents and Settings\Tamara x x\Local Settings\Temp\csrss .exe () O4 - HKU\Tamara_x_x_ON_C..\Run: [HNUIQOXRnygc] C:\Documents and Settings\Tamara x x\Local Settings\Temp\csrss .exe () O4 - HKU\Tamara_x_x_ON_C..\Run: [HNUIQOXRnygg0] C:\Documents and Settings\Tamara x x\Local Settings\Temp\csrss .exe () O4 - HKU\Tamara_x_x_ON_C..\Run: [HNUIQOXRnyggc] C:\Documents and Settings\Tamara x x\Local Settings\Temp\csrss .exe () O4 - HKU\Tamara_x_x_ON_C..\Run: [HNUIQOXRnyggK] C:\Documents and Settings\Tamara x x\Local Settings\Temp\csrss .exe () O4 - HKU\Tamara_x_x_ON_C..\Run: [HNUIQOXRnygj] C:\Documents and Settings\Tamara x x\Local Settings\Temp\csrss .exe () O4 - HKU\Tamara_x_x_ON_C..\Run: [HNUIQOXRnygK] C:\Documents and Settings\Tamara x x\Local Settings\Temp\csrss .exe () O4 - HKU\Tamara_x_x_ON_C..\Run: [HNUIQOXRnyj] C:\Documents and Settings\Tamara x x\Local Settings\Temp\csrss .exe () O4 - HKU\Tamara_x_x_ON_C..\Run: [HNUIQOXRnyK] C:\Documents and Settings\Tamara x x\Local Settings\Temp\csrss .exe () O4 - HKU\Tamara_x_x_ON_C..\Run: [HNUIQOXRnZ] C:\Documents and Settings\Tamara x x\Local Settings\Temp\cmd.exe () O4 - HKU\Tamara_x_x_ON_C..\Run: [HNUIQOXRota] C:\Documents and Settings\Tamara x x\Local Settings\Temp\install.exe () O4 - HKU\Tamara_x_x_ON_C..\Run: [HNUIQOXRotc] C:\Documents and Settings\Tamara x x\Local Settings\Temp\hexdump.exe () O4 - HKU\Tamara_x_x_ON_C..\Run: [HNUIQOXRotGc] C:\Documents and Settings\Tamara x x\Local Settings\Temp\install .exe () O4 - HKU\Tamara_x_x_ON_C..\Run: [HNUIQOXRotGK] C:\Documents and Settings\Tamara x x\Local Settings\Temp\install .exe () O4 - HKU\Tamara_x_x_ON_C..\Run: [HNUIQOXRotH0] C:\Documents and Settings\Tamara x x\Local Settings\Temp\hexdump .exe () O4 - HKU\Tamara_x_x_ON_C..\Run: [HNUIQOXRotHc] C:\Documents and Settings\Tamara x x\Local Settings\Temp\hexdump .exe () O4 - HKU\Tamara_x_x_ON_C..\Run: [HNUIQOXRotHg0] C:\Documents and Settings\Tamara x x\Local Settings\Temp\hexdump .exe () O4 - HKU\Tamara_x_x_ON_C..\Run: [HNUIQOXRotHgc] C:\Documents and Settings\Tamara x x\Local Settings\Temp\hexdump .exe () O4 - HKU\Tamara_x_x_ON_C..\Run: [HNUIQOXRotHggc] C:\Documents and Settings\Tamara x x\Local Settings\Temp\hexdump .exe () O4 - HKU\Tamara_x_x_ON_C..\Run: [HNUIQOXRotHgj] C:\Documents and Settings\Tamara x x\Local Settings\Temp\hexdump .exe () O4 - HKU\Tamara_x_x_ON_C..\Run: [HNUIQOXRotHgK] C:\Documents and Settings\Tamara x x\Local Settings\Temp\hexdump .exe () O4 - HKU\Tamara_x_x_ON_C..\Run: [HNUIQOXRotHj] C:\Documents and Settings\Tamara x x\Local Settings\Temp\hexdump .exe () O4 - HKU\Tamara_x_x_ON_C..\Run: [HNUIQOXRotHK] C:\Documents and Settings\Tamara x x\Local Settings\Temp\hexdump .exe () O4 - HKU\Tamara_x_x_ON_C..\Run: [HNUIQOXRotJ] C:\Documents and Settings\Tamara x x\Local Settings\Temp\install .exe () O4 - HKU\Tamara_x_x_ON_C..\Run: [HNUIQOXRouqc] C:\Documents and Settings\Tamara x x\Local Settings\Temp\iexplarer.exe (Microsoft Corporation) O4 - HKU\Tamara_x_x_ON_C..\Run: [HNUIQOXRpc70] C:\Documents and Settings\Tamara x x\Local Settings\Temp\n2mih8u .exe () O4 - HKU\Tamara_x_x_ON_C..\Run: [HNUIQOXRpc7c] C:\Documents and Settings\Tamara x x\Local Settings\Temp\n2mih8u .exe () O4 - HKU\Tamara_x_x_ON_C..\Run: [HNUIQOXRpc7g0] C:\Documents and Settings\Tamara x x\Local Settings\Temp\n2mih8u .exe () O4 - HKU\Tamara_x_x_ON_C..\Run: [HNUIQOXRpc7gc] C:\Documents and Settings\Tamara x x\Local Settings\Temp\n2mih8u .exe () O4 - HKU\Tamara_x_x_ON_C..\Run: [HNUIQOXRpc7gj] C:\Documents and Settings\Tamara x x\Local Settings\Temp\n2mih8u .exe () O4 - HKU\Tamara_x_x_ON_C..\Run: [HNUIQOXRpc7gK] C:\Documents and Settings\Tamara x x\Local Settings\Temp\n2mih8u .exe () O4 - HKU\Tamara_x_x_ON_C..\Run: [HNUIQOXRpc7j] C:\Documents and Settings\Tamara x x\Local Settings\Temp\n2mih8u .exe () O4 - HKU\Tamara_x_x_ON_C..\Run: [HNUIQOXRpc7K] C:\Documents and Settings\Tamara x x\Local Settings\Temp\n2mih8u .exe () O4 - HKU\Tamara_x_x_ON_C..\Run: [HNUIQOXRpcQ] C:\Documents and Settings\Tamara x x\Local Settings\Temp\n2mih8u.exe () O4 - HKU\Tamara_x_x_ON_C..\Run: [HNUIQOXRpr0] C:\Documents and Settings\Tamara x x\Local Settings\Temp\login .exe () O4 - HKU\Tamara_x_x_ON_C..\Run: [HNUIQOXRprc] C:\Documents and Settings\Tamara x x\Local Settings\Temp\login.exe () O4 - HKU\Tamara_x_x_ON_C..\Run: [HNUIQOXRprg0] C:\Documents and Settings\Tamara x x\Local Settings\Temp\login .exe () O4 - HKU\Tamara_x_x_ON_C..\Run: [HNUIQOXRprgc] C:\Documents and Settings\Tamara x x\Local Settings\Temp\login .exe () O4 - HKU\Tamara_x_x_ON_C..\Run: [HNUIQOXRprgg0] C:\Documents and Settings\Tamara x x\Local Settings\Temp\login .exe () O4 - HKU\Tamara_x_x_ON_C..\Run: [HNUIQOXRprggc] C:\Documents and Settings\Tamara x x\Local Settings\Temp\login .exe () O4 - HKU\Tamara_x_x_ON_C..\Run: [HNUIQOXRprggg0] C:\Documents and Settings\Tamara x x\Local Settings\Temp\login .exe () O4 - HKU\Tamara_x_x_ON_C..\Run: [HNUIQOXRprgggc] C:\Documents and Settings\Tamara x x\Local Settings\Temp\login .exe () O4 - HKU\Tamara_x_x_ON_C..\Run: [HNUIQOXRprgggj] C:\Documents and Settings\Tamara x x\Local Settings\Temp\login .exe () O4 - HKU\Tamara_x_x_ON_C..\Run: [HNUIQOXRprgggK] C:\Documents and Settings\Tamara x x\Local Settings\Temp\login .exe () O4 - HKU\Tamara_x_x_ON_C..\Run: [HNUIQOXRprggj] C:\Documents and Settings\Tamara x x\Local Settings\Temp\login .exe () O4 - HKU\Tamara_x_x_ON_C..\Run: [HNUIQOXRprggK] C:\Documents and Settings\Tamara x x\Local Settings\Temp\login .exe () O4 - HKU\Tamara_x_x_ON_C..\Run: [HNUIQOXRprgj] C:\Documents and Settings\Tamara x x\Local Settings\Temp\login .exe () O4 - HKU\Tamara_x_x_ON_C..\Run: [HNUIQOXRprgK] C:\Documents and Settings\Tamara x x\Local Settings\Temp\login .exe () O4 - HKU\Tamara_x_x_ON_C..\Run: [HNUIQOXRprj] C:\Documents and Settings\Tamara x x\Local Settings\Temp\login .exe () O4 - HKU\Tamara_x_x_ON_C..\Run: [HNUIQOXRprK] C:\Documents and Settings\Tamara x x\Local Settings\Temp\login .exe () O4 - HKU\Tamara_x_x_ON_C..\Run: [HNUIQOXRpSg2c] C:\Documents and Settings\Tamara x x\Local Settings\Temp\l42muyf1sx .exe () O4 - HKU\Tamara_x_x_ON_C..\Run: [HNUIQOXRpSg2K] C:\Documents and Settings\Tamara x x\Local Settings\Temp\l42muyf1sx .exe () O4 - HKU\Tamara_x_x_ON_C..\Run: [HNUIQOXRpSg5] C:\Documents and Settings\Tamara x x\Local Settings\Temp\l42muyf1sx .exe () O4 - HKU\Tamara_x_x_ON_C..\Run: [HNUIQOXRpSgg] C:\Documents and Settings\Tamara x x\Local Settings\Temp\l42muyf1sx.exe () O4 - HKU\Tamara_x_x_ON_C..\Run: [HNUIQOXRpZ] C:\Documents and Settings\Tamara x x\Local Settings\Temp\mdm.exe (Microsoft Corporation) O4 - HKU\Tamara_x_x_ON_C..\Run: [HNUIQOXRrc0] C:\Documents and Settings\Tamara x x\Local Settings\Temp\smss .exe () O4 - HKU\Tamara_x_x_ON_C..\Run: [HNUIQOXRrcj] C:\Documents and Settings\Tamara x x\Local Settings\Temp\smss .exe () O4 - HKU\Tamara_x_x_ON_C..\Run: [HNUIQOXRrcK] C:\Documents and Settings\Tamara x x\Local Settings\Temp\smss .exe () O4 - HKU\Tamara_x_x_ON_C..\Run: [HNUIQOXRrg] C:\Documents and Settings\Tamara x x\Local Settings\Temp\smss.exe () O4 - HKU\Tamara_x_x_ON_C..\Run: [HNUIQOXRrta] C:\Documents and Settings\Tamara x x\Local Settings\Temp\services.exe (Microsoft Corporation) O4 - HKU\Tamara_x_x_ON_C..\Run: [HNUIQOXRrv0] C:\Documents and Settings\Tamara x x\Local Settings\Temp\setup .exe () O4 - HKU\Tamara_x_x_ON_C..\Run: [HNUIQOXRrvc] C:\Documents and Settings\Tamara x x\Local Settings\Temp\setup.exe () O4 - HKU\Tamara_x_x_ON_C..\Run: [HNUIQOXRrvg0] C:\Documents and Settings\Tamara x x\Local Settings\Temp\setup .exe () O4 - HKU\Tamara_x_x_ON_C..\Run: [HNUIQOXRrvgc] C:\Documents and Settings\Tamara x x\Local Settings\Temp\setup .exe () O4 - HKU\Tamara_x_x_ON_C..\Run: [HNUIQOXRrvgg0] C:\Documents and Settings\Tamara x x\Local Settings\Temp\setup .exe () O4 - HKU\Tamara_x_x_ON_C..\Run: [HNUIQOXRrvggc] C:\Documents and Settings\Tamara x x\Local Settings\Temp\setup .exe () O4 - HKU\Tamara_x_x_ON_C..\Run: [HNUIQOXRrvggj] C:\Documents and Settings\Tamara x x\Local Settings\Temp\setup .exe () O4 - HKU\Tamara_x_x_ON_C..\Run: [HNUIQOXRrvggK] C:\Documents and Settings\Tamara x x\Local Settings\Temp\setup .exe () O4 - HKU\Tamara_x_x_ON_C..\Run: [HNUIQOXRrvgj] C:\Documents and Settings\Tamara x x\Local Settings\Temp\setup .exe () O4 - HKU\Tamara_x_x_ON_C..\Run: [HNUIQOXRrvgK] C:\Documents and Settings\Tamara x x\Local Settings\Temp\setup .exe () O4 - HKU\Tamara_x_x_ON_C..\Run: [HNUIQOXRrvj] C:\Documents and Settings\Tamara x x\Local Settings\Temp\setup .exe () O4 - HKU\Tamara_x_x_ON_C..\Run: [HNUIQOXRsa] C:\Documents and Settings\Tamara x x\Local Settings\Temp\win.exe (Microsoft Corporation) O4 - HKU\Tamara_x_x_ON_C..\Run: [HNUIQOXRsPc] C:\Documents and Settings\Tamara x x\Local Settings\Temp\win16.exe (Microsoft Corporation) O4 - HKU\Tamara_x_x_ON_C..\Run: [HNUIQOXRsPK] C:\Documents and Settings\Tamara x x\Local Settings\Temp\win32 .exe () O4 - HKU\Tamara_x_x_ON_C..\Run: [HNUIQOXRsre] C:\Documents and Settings\Tamara x x\Local Settings\Temp\wininst.exe () O4 - HKU\Tamara_x_x_ON_C..\Run: [HNUIQOXRsrJ0] C:\Documents and Settings\Tamara x x\Local Settings\Temp\wininst .exe () O4 - HKU\Tamara_x_x_ON_C..\Run: [HNUIQOXRsrJc] C:\Documents and Settings\Tamara x x\Local Settings\Temp\wininst .exe () O4 - HKU\Tamara_x_x_ON_C..\Run: [HNUIQOXRsrJg0] C:\Documents and Settings\Tamara x x\Local Settings\Temp\wininst .exe () O4 - HKU\Tamara_x_x_ON_C..\Run: [HNUIQOXRsrJgc] C:\Documents and Settings\Tamara x x\Local Settings\Temp\wininst .exe () O4 - HKU\Tamara_x_x_ON_C..\Run: [HNUIQOXRsrJgj] C:\Documents and Settings\Tamara x x\Local Settings\Temp\wininst .exe () O4 - HKU\Tamara_x_x_ON_C..\Run: [HNUIQOXRsrJgK] C:\Documents and Settings\Tamara x x\Local Settings\Temp\wininst .exe () O4 - HKU\Tamara_x_x_ON_C..\Run: [HNUIQOXRsrJj] C:\Documents and Settings\Tamara x x\Local Settings\Temp\wininst .exe () O4 - HKU\Tamara_x_x_ON_C..\Run: [HNUIQOXRsrJK] C:\Documents and Settings\Tamara x x\Local Settings\Temp\wininst .exe () O4 - HKU\Tamara_x_x_ON_C..\Run: [MKbMc] C:\WINDOWS\gdi32.exe (Microsoft Corporation) O4 - HKU\Tamara_x_x_ON_C..\Run: [MKbtc] C:\WINDOWS\hexdump.exe () O4 - HKU\Tamara_x_x_ON_C..\Run: [MKbtH0] C:\WINDOWS\hexdump .exe () O4 - HKU\Tamara_x_x_ON_C..\Run: [MKbtHc] C:\WINDOWS\hexdump .exe () O4 - HKU\Tamara_x_x_ON_C..\Run: [MKbtHg0] C:\WINDOWS\hexdump .exe () O4 - HKU\Tamara_x_x_ON_C..\Run: [MKbtHgc] C:\WINDOWS\hexdump .exe () O4 - HKU\Tamara_x_x_ON_C..\Run: [MKbtHgK] C:\WINDOWS\hexdump .exe () O4 - HKU\Tamara_x_x_ON_C..\Run: [MKbtHj] C:\WINDOWS\hexdump .exe () O4 - HKU\Tamara_x_x_ON_C..\Run: [MKbtHK] C:\WINDOWS\hexdump .exe () O4 - HKU\Tamara_x_x_ON_C..\Run: [MKbuqc] C:\WINDOWS\iexplarer.exe (Microsoft Corporation) O4 - HKU\Tamara_x_x_ON_C..\Run: [MKcrc] C:\WINDOWS\login.exe () O4 - HKU\Tamara_x_x_ON_C..\Run: [MKcrgg0] C:\WINDOWS\login .exe () O4 - HKU\Tamara_x_x_ON_C..\Run: [MKcrggg0] C:\WINDOWS\login .exe () O4 - HKU\Tamara_x_x_ON_C..\Run: [MKcrgggc] C:\WINDOWS\login .exe () O4 - HKU\Tamara_x_x_ON_C..\Run: [MKcrgggg0] C:\WINDOWS\login .exe () O4 - HKU\Tamara_x_x_ON_C..\Run: [MKcrggggc] C:\WINDOWS\login .exe () O4 - HKU\Tamara_x_x_ON_C..\Run: [MKcrggggg0] C:\WINDOWS\login .exe () O4 - HKU\Tamara_x_x_ON_C..\Run: [MKcrgggggc] C:\WINDOWS\login .exe () O4 - HKU\Tamara_x_x_ON_C..\Run: [MKcrgggggg0] C:\WINDOWS\login .exe () O4 - HKU\Tamara_x_x_ON_C..\Run: [MKcrggggggc] C:\WINDOWS\login .exe () O4 - HKU\Tamara_x_x_ON_C..\Run: [MKcrggggggg0] C:\WINDOWS\login .exe () O4 - HKU\Tamara_x_x_ON_C..\Run: [MKcrgggggggc] C:\WINDOWS\login .exe () O4 - HKU\Tamara_x_x_ON_C..\Run: [MKcrgggggggg0] C:\WINDOWS\login .exe () O4 - HKU\Tamara_x_x_ON_C..\Run: [MKcrggggggggc] C:\WINDOWS\login .exe () O4 - HKU\Tamara_x_x_ON_C..\Run: [MKcrgggggggggc] C:\WINDOWS\login .exe () O4 - HKU\Tamara_x_x_ON_C..\Run: [MKcrgggggggggK] C:\WINDOWS\login .exe () O4 - HKU\Tamara_x_x_ON_C..\Run: [MKcrggggggggj] C:\WINDOWS\login .exe () O4 - HKU\Tamara_x_x_ON_C..\Run: [MKcrggggggggK] C:\WINDOWS\login .exe () O4 - HKU\Tamara_x_x_ON_C..\Run: [MKcrgggggggj] C:\WINDOWS\login .exe () O4 - HKU\Tamara_x_x_ON_C..\Run: [MKcrgggggggK] C:\WINDOWS\login .exe () O4 - HKU\Tamara_x_x_ON_C..\Run: [MKcrggggggj] C:\WINDOWS\login .exe () O4 - HKU\Tamara_x_x_ON_C..\Run: [MKcrggggggK] C:\WINDOWS\login .exe () O4 - HKU\Tamara_x_x_ON_C..\Run: [MKcrgggggj] C:\WINDOWS\login .exe () O4 - HKU\Tamara_x_x_ON_C..\Run: [MKcrgggggK] C:\WINDOWS\login .exe () O4 - HKU\Tamara_x_x_ON_C..\Run: [MKcrggggj] C:\WINDOWS\login .exe () O4 - HKU\Tamara_x_x_ON_C..\Run: [MKcrggggK] C:\WINDOWS\login .exe () O4 - HKU\Tamara_x_x_ON_C..\Run: [MKcrgggj] C:\WINDOWS\login .exe () O4 - HKU\Tamara_x_x_ON_C..\Run: [MKcrgggK] C:\WINDOWS\login .exe () O4 - HKU\Tamara_x_x_ON_C..\Run: [MKcrggj] C:\WINDOWS\login .exe () O4 - HKU\Tamara_x_x_ON_C..\Run: [MKcuc] C:\WINDOWS\lsass.exe () O4 - HKU\Tamara_x_x_ON_C..\Run: [MKcZ] C:\WINDOWS\mdm.exe (Microsoft Corporation) O4 - HKU\Tamara_x_x_ON_C..\Run: [MKdw+] C:\WINDOWS\nvsvc32.exe () O4 - HKU\Tamara_x_x_ON_C..\Run: [MKdws] C:\WINDOWS\nvsvc32 .exe () O4 - HKU\Tamara_x_x_ON_C..\Run: [MKeta] C:\WINDOWS\services.exe () O4 - HKU\Tamara_x_x_ON_C..\Run: [MKetWgg0] C:\WINDOWS\services .exe () O4 - HKU\Tamara_x_x_ON_C..\Run: [MKetWggc] C:\WINDOWS\services .exe () O4 - HKU\Tamara_x_x_ON_C..\Run: [MKetWggg0] C:\WINDOWS\services .exe () O4 - HKU\Tamara_x_x_ON_C..\Run: [MKetWgggc] C:\WINDOWS\services .exe () O4 - HKU\Tamara_x_x_ON_C..\Run: [MKetWgggK] C:\WINDOWS\services .exe () O4 - HKU\Tamara_x_x_ON_C..\Run: [MKetWggj] C:\WINDOWS\services .exe () O4 - HKU\Tamara_x_x_ON_C..\Run: [MKetWggK] C:\WINDOWS\services .exe () O4 - HKU\Tamara_x_x_ON_C..\Run: [MKetWggKWS\services .exe] C:\WINDOWS\services .exe () O4 - HKU\Tamara_x_x_ON_C..\Run: [MKeuK0] C:\WINDOWS\spoolsv .exe () O4 - HKU\Tamara_x_x_ON_C..\Run: [MKeuKc] C:\WINDOWS\spoolsv .exe () O4 - HKU\Tamara_x_x_ON_C..\Run: [MKeuKK] C:\WINDOWS\spoolsv .exe () O4 - HKU\Tamara_x_x_ON_C..\Run: [MKeuN] C:\WINDOWS\spoolsv .exe () O4 - HKU\Tamara_x_x_ON_C..\Run: [MKev0] C:\WINDOWS\setup .exe () O4 - HKU\Tamara_x_x_ON_C..\Run: [MKevc] C:\WINDOWS\setup.exe () O4 - HKU\Tamara_x_x_ON_C..\Run: [MKevj] C:\WINDOWS\setup .exe () O4 - HKU\Tamara_x_x_ON_C..\Run: [MKevK] C:\WINDOWS\setup .exe () O4 - HKU\Tamara_x_x_ON_C..\Run: [MKexe] C:\WINDOWS\system.exe (Microsoft Corporation) O4 - HKU\Tamara_x_x_ON_C..\Run: [MKfa] C:\WINDOWS\win.exe (Microsoft Corporation) O4 - HKU\Tamara_x_x_ON_C..\Run: [MKfPc] C:\WINDOWS\win16.exe () O4 - HKU\Tamara_x_x_ON_C..\Run: [MKfPg0] C:\WINDOWS\win16 .exe () O4 - HKU\Tamara_x_x_ON_C..\Run: [MKfPgc] C:\WINDOWS\win16 .exe () O4 - HKU\Tamara_x_x_ON_C..\Run: [MKfPgg0] C:\WINDOWS\win16 .exe () O4 - HKU\Tamara_x_x_ON_C..\Run: [MKfPggc] C:\WINDOWS\win16 .exe () O4 - HKU\Tamara_x_x_ON_C..\Run: [MKfPggg0] C:\WINDOWS\win16 .exe () O4 - HKU\Tamara_x_x_ON_C..\Run: [MKfPgggc] C:\WINDOWS\win16 .exe () O4 - HKU\Tamara_x_x_ON_C..\Run: [MKfPgggg0] C:\WINDOWS\win16 .exe () O4 - HKU\Tamara_x_x_ON_C..\Run: [MKfPggggc] C:\WINDOWS\win16 .exe () O4 - HKU\Tamara_x_x_ON_C..\Run: [MKfPggggg0] C:\WINDOWS\win16 .exe () O4 - HKU\Tamara_x_x_ON_C..\Run: [MKfPgggggc] C:\WINDOWS\win16 .exe () O4 - HKU\Tamara_x_x_ON_C..\Run: [MKfPgggggg0] C:\WINDOWS\win16 .exe () O4 - HKU\Tamara_x_x_ON_C..\Run: [MKfPggggggc] C:\WINDOWS\win16 .exe () O4 - HKU\Tamara_x_x_ON_C..\Run: [MKfPggggggg0] C:\WINDOWS\win16 .exe () O4 - HKU\Tamara_x_x_ON_C..\Run: [MKfPgggggggc] C:\WINDOWS\win16 .exe () O4 - HKU\Tamara_x_x_ON_C..\Run: [MKfPggggggggc] C:\WINDOWS\win16 .exe () O4 - HKU\Tamara_x_x_ON_C..\Run: [MKfPgggggggj] C:\WINDOWS\win16 .exe () O4 - HKU\Tamara_x_x_ON_C..\Run: [MKfPgggggggK] C:\WINDOWS\win16 .exe () O4 - HKU\Tamara_x_x_ON_C..\Run: [MKfPggggggj] C:\WINDOWS\win16 .exe () O4 - HKU\Tamara_x_x_ON_C..\Run: [MKfPggggggK] C:\WINDOWS\win16 .exe () O4 - HKU\Tamara_x_x_ON_C..\Run: [MKfPgggggj] C:\WINDOWS\win16 .exe () O4 - HKU\Tamara_x_x_ON_C..\Run: [MKfPgggggK] C:\WINDOWS\win16 .exe () O4 - HKU\Tamara_x_x_ON_C..\Run: [MKfPggggj] C:\WINDOWS\win16 .exe () O4 - HKU\Tamara_x_x_ON_C..\Run: [MKfPggggK] C:\WINDOWS\win16 .exe () O4 - HKU\Tamara_x_x_ON_C..\Run: [MKfPgggj] C:\WINDOWS\win16 .exe () O4 - HKU\Tamara_x_x_ON_C..\Run: [MKfPgggK] C:\WINDOWS\win16 .exe () O4 - HKU\Tamara_x_x_ON_C..\Run: [MKfPggj] C:\WINDOWS\win16 .exe () O4 - HKU\Tamara_x_x_ON_C..\Run: [MKfPggK] C:\WINDOWS\win16 .exe () O4 - HKU\Tamara_x_x_ON_C..\Run: [MKfPgj] C:\WINDOWS\win16 .exe () O4 - HKU\Tamara_x_x_ON_C..\Run: [MKfPgK] C:\WINDOWS\win16 .exe () O4 - HKU\Tamara_x_x_ON_C..\Run: [MKfPj] C:\WINDOWS\win16 .exe () O4 - HKU\Tamara_x_x_ON_C..\Run: [MKfPK] C:\WINDOWS\win16 .exe () O4 - HKU\Tamara_x_x_ON_C..\Run: [MKfre] C:\WINDOWS\wininst.exe (Microsoft Corporation) O4 - HKU\Tamara_x_x_ON_C..\Run: [MKfsc] C:\WINDOWS\winlogon.exe () O4 - HKU\Tamara_x_x_ON_C..\Run: [MKWPeP] C:\WINDOWS\temp\avp32.exe (Microsoft Corporation) O4 - HKU\Tamara_x_x_ON_C..\Run: [MKWPf6] C:\WINDOWS\temp\win16 .exe () O4 - HKU\Tamara_x_x_ON_C..\Run: [MKWPsJ] C:\WINDOWS\temp\lsass .exe () O4 - HKU\Tamara_x_x_ON_C..\Run: [MKWPtd0] C:\WINDOWS\temp\wininst .exe () O4 - HKU\Tamara_x_x_ON_C..\Run: [MKWPtdc] C:\WINDOWS\temp\wininst .exe () O4 - HKU\Tamara_x_x_ON_C..\Run: [MKWPtdgc] C:\WINDOWS\temp\wininst .exe () O4 - HKU\Tamara_x_x_ON_C..\Run: [MKWPtdj] C:\WINDOWS\temp\wininst .exe () O4 - HKU\Tamara_x_x_ON_C..\Run: [MKWPtdK] C:\WINDOWS\temp\wininst .exe () O4 - HKU\Tamara_x_x_ON_C..\Run: [MKWPtp0c] C:\WINDOWS\temp\iexplarer .exe () O4 - HKU\Tamara_x_x_ON_C..\Run: [MKWPtp0K] C:\WINDOWS\temp\iexplarer .exe () O4 - HKU\Tamara_x_x_ON_C..\Run: [MKWPvZ] C:\WINDOWS\temp\install.exe () O4 - HKU\Tamara_x_x_ON_C..\Run: [MKWPwI] C:\WINDOWS\temp\setup .exe () O4 - HKU\Tamara_x_x_ON_C..\Run: [MKZe] C:\WINDOWS\avp.exe (Microsoft Corporation) O4 - HKU\Tamara_x_x_ON_C..\Run: [MKZSc] C:\WINDOWS\avp32.exe () O4 - HKU\Tamara_x_x_ON_C..\Run: [MKZSK] C:\WINDOWS\avp32 .exe () O4 - HKU\Tamara_x_x_ON_C..\Run: [MyWebSearch Email Plugin] C:\Program Files\MyWebSearch\bar\2.bin\mwsoemon.exe () O4 - HKU\Tamara_x_x_ON_C..\Run: [Osemadavakule] C:\WINDOWS\wmumelog.DLL () O4 - HKU\Tamara_x_x_ON_C..\Run: [uPc+MV0NdhaGuo] C:\WINDOWS\System32\n3xy5nh.DLL () O4 - HKU\Tamara_x_x_ON_C..\Run: [uPc+MV0NmQaXms] C:\WINDOWS\System32\foj6mp.DLL () O4 - Startup: C:\Documents and Settings\All Users\Start Menu\Programs\Startup\Bluetooth.lnk = C:\Program Files\WIDCOMM\Bluetooth Software\BTTray.exe (Broadcom Corporation.) O4 - Startup: C:\Documents and Settings\Default User\Start Menu\Programs\Startup\depabi.exe () O4 - Startup: C:\Documents and Settings\Default User\Start Menu\Programs\Startup\eqysop.exe () O4 - Startup: C:\Documents and Settings\Default User\Start Menu\Programs\Startup\faxuo.exe () O4 - Startup: C:\Documents and Settings\Default User\Start Menu\Programs\Startup\hosa.exe (Hex-Rays SA) O4 - Startup: C:\Documents and Settings\Default User\Start Menu\Programs\Startup\ikcesy.exe () O4 - Startup: C:\Documents and Settings\Default User\Start Menu\Programs\Startup\ipcuad.exe () O4 - Startup: C:\Documents and Settings\Default User\Start Menu\Programs\Startup\kaxi.exe () O4 - Startup: C:\Documents and Settings\Default User\Start Menu\Programs\Startup\nioh.exe () O4 - Startup: C:\Documents and Settings\Default User\Start Menu\Programs\Startup\uhen.exe () O4 - Startup: C:\Documents and Settings\Default User\Start Menu\Programs\Startup\wogee.exe () O4 - Startup: C:\Documents and Settings\Default User\Start Menu\Programs\Startup\xoymho.exe () O4 - Startup: C:\Documents and Settings\Default User\Start Menu\Programs\Startup\yrezyq.exe () O4 - Startup: C:\Documents and Settings\dion\Start Menu\Programs\Startup\ceaf.exe () O4 - Startup: C:\Documents and Settings\dion\Start Menu\Programs\Startup\daikn.exe () O4 - Startup: C:\Documents and Settings\dion\Start Menu\Programs\Startup\ecyri.exe (Hex-Rays SA) O4 - Startup: C:\Documents and Settings\dion\Start Menu\Programs\Startup\fumi.exe () O4 - Startup: C:\Documents and Settings\dion\Start Menu\Programs\Startup\imte.exe () O4 - Startup: C:\Documents and Settings\dion\Start Menu\Programs\Startup\liug.exe () O4 - Startup: C:\Documents and Settings\dion\Start Menu\Programs\Startup\nyur.exe () O4 - Startup: C:\Documents and Settings\dion\Start Menu\Programs\Startup\ocami.exe () O4 - Startup: C:\Documents and Settings\dion\Start Menu\Programs\Startup\oryte.exe () O4 - Startup: C:\Documents and Settings\dion\Start Menu\Programs\Startup\ovqe.exe () O4 - Startup: C:\Documents and Settings\dion\Start Menu\Programs\Startup\xeitab.exe () O4 - Startup: C:\Documents and Settings\dion\Start Menu\Programs\Startup\ysdy.exe () O4 - Startup: C:\Documents and Settings\Tamara x x\Start Menu\Programs\Startup\logtec32.exe () O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: DisableTaskMgr = 1 O7 - HKU\.DEFAULT\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoFolderOptions = 1 O7 - HKU\.DEFAULT\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: DisableRegistryTools = 1 O7 - HKU\Tamara_x_x_ON_C\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoFolderOptions = 1 O7 - HKU\Tamara_x_x_ON_C\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: DisableTaskMgr = 1 O7 - HKU\Tamara_x_x_ON_C\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: DisableRegistryTools = 1 O16 - DPF: {1D4DB7D2-6EC9-47A3-BD87-1E41684E07BB} http://ak.exe.imgfar...etup1.0.1.3.cab (Reg Error: Key error.) O20 - HKLM Winlogon: UserInit - (c:\program files\microsoft\desktoplayer.exe) - C:\Program Files\Microsoft\DesktopLayer.exe () O20 - HKU\.DEFAULT Winlogon: Shell - (C:\Documents and Settings\NetworkService\Application Data\hotfix.exe) - C:\Documents and Settings\NetworkService\Application Data\hotfix.exe File not found O20 - HKU\dion_ON_C Winlogon: Shell - (C:\Documents and Settings\dion\Application Data\antispy.exe) - C:\Documents and Settings\dion\Application Data\antispy.exe (Inclusen shild AG) O20 - HKU\Tamara_x_x_ON_C Winlogon: Shell - (C:\Documents and Settings\Tamara x x\Application Data\hotfix.exe) - C:\Documents and Settings\Tamara x x\Application Data\hotfix.exe () O22 - SharedTaskScheduler: {D6BA40A1-A502-59BD-F413-04B03A2C8953} - iskjsfuwajiduhf87sfydudhnf - C:\WINDOWS\system32\mzmddj1nar.dll () [2010/10/28 15:29:12 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Tamara x x\Local Settings\Application Data\Temp [2010/10/28 15:28:17 | 000,021,636 | -H-- | C] (Microsoft Corporation) -- C:\WINDOWS\winlogon .exe [2010/10/28 15:27:44 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Tamara x x\Application Data\Voukom [2010/10/28 15:27:44 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Tamara x x\Application Data\Izkoo [2010/09/18 04:28:55 | 000,745,472 | ---- | C] (Inclusen shild AG) -- C:\Documents and Settings\dion\Application Data\antispy.exe [2 C:\WINDOWS\System32\*.tmp files -> C:\WINDOWS\System32\*.tmp -> ] [1 C:\WINDOWS\System32\drivers\*.tmp files -> C:\WINDOWS\System32\drivers\*.tmp -> ] [2010/10/28 15:47:52 | 000,000,000 | ---- | M] () -- C:\WINDOWS\System32\drivers\ccxucg.sys [2010/10/28 15:47:40 | 000,000,016 | ---- | M] () -- C:\WINDOWS\System32\dmlconf.dat [2010/10/28 15:46:35 | 000,035,596 | ---- | M] () -- C:\WINDOWS\login .exe [2010/10/28 15:46:24 | 000,035,592 | ---- | M] () -- C:\WINDOWS\win16 .exe [2010/10/28 15:46:13 | 000,035,588 | ---- | M] () -- C:\WINDOWS\login .exe [2010/10/28 15:46:02 | 000,035,584 | ---- | M] () -- C:\WINDOWS\win16 .exe [2010/10/28 15:45:51 | 000,035,580 | ---- | M] () -- C:\WINDOWS\login .exe [2010/10/28 15:45:41 | 000,035,576 | ---- | M] () -- C:\WINDOWS\win16 .exe [2010/10/28 15:45:30 | 000,035,572 | ---- | M] () -- C:\WINDOWS\login .exe [2010/10/28 15:45:19 | 000,035,568 | ---- | M] () -- C:\WINDOWS\win16 .exe [2010/10/28 15:45:08 | 000,035,564 | ---- | M] () -- C:\WINDOWS\login .exe [2010/10/28 15:44:58 | 000,035,560 | ---- | M] () -- C:\WINDOWS\win16 .exe [2010/10/28 15:44:47 | 000,035,556 | ---- | M] () -- C:\WINDOWS\login .exe [2010/10/28 15:44:36 | 000,035,552 | ---- | M] () -- C:\WINDOWS\win16 .exe [2010/10/28 15:44:25 | 000,035,548 | ---- | M] () -- C:\WINDOWS\login .exe [2010/10/28 15:44:14 | 000,035,544 | ---- | M] () -- C:\WINDOWS\win16 .exe [2010/10/28 15:44:03 | 000,035,540 | ---- | M] () -- C:\WINDOWS\login .exe [2010/10/28 15:43:52 | 000,035,536 | ---- | M] () -- C:\WINDOWS\win16 .exe [2010/10/28 15:43:40 | 000,035,532 | ---- | M] () -- C:\WINDOWS\login .exe [2010/10/28 15:43:28 | 000,035,528 | ---- | M] () -- C:\WINDOWS\win16 .exe [2010/10/28 15:43:17 | 000,035,524 | ---- | M] () -- C:\WINDOWS\login .exe [2010/10/28 15:43:05 | 000,035,520 | ---- | M] () -- C:\WINDOWS\win16 .exe [2010/10/28 15:42:54 | 000,035,516 | ---- | M] () -- C:\WINDOWS\login .exe [2010/10/28 15:42:44 | 000,035,512 | ---- | M] () -- C:\WINDOWS\win16 .exe [2010/10/28 15:42:33 | 000,035,508 | ---- | M] () -- C:\WINDOWS\login .exe [2010/10/28 15:42:22 | 000,035,504 | ---- | M] () -- C:\WINDOWS\win16 .exe [2010/10/28 15:42:11 | 000,035,500 | ---- | M] () -- C:\WINDOWS\login .exe [2010/10/28 15:42:00 | 000,035,496 | ---- | M] () -- C:\WINDOWS\win16 .exe [2010/10/28 15:41:50 | 000,035,492 | ---- | M] () -- C:\WINDOWS\login .exe [2010/10/28 15:41:39 | 000,035,488 | ---- | M] () -- C:\WINDOWS\win16 .exe [2010/10/28 15:41:34 | 000,158,208 | ---- | M] () -- C:\Documents and Settings\Tamara x x\Application Data\hotfixSrv.exe [2010/10/28 15:41:28 | 000,035,484 | ---- | M] () -- C:\WINDOWS\login .exe [2010/10/28 15:41:17 | 000,035,480 | ---- | M] () -- C:\WINDOWS\win16 .exe [2010/10/28 15:41:06 | 000,035,476 | ---- | M] () -- C:\WINDOWS\login .exe [2010/10/28 15:40:55 | 000,035,472 | ---- | M] () -- C:\WINDOWS\win16 .exe [2010/10/28 15:40:45 | 000,035,468 | ---- | M] () -- C:\WINDOWS\login .exe [2010/10/28 15:40:34 | 000,035,464 | ---- | M] () -- C:\WINDOWS\win16 .exe [2010/10/28 15:40:23 | 000,275,968 | ---- | M] (Hex-Rays SA) -- C:\Documents and Settings\Default User\Start Menu\Programs\StartUp\hosa.exe [2010/10/28 15:40:23 | 000,035,460 | ---- | M] () -- C:\WINDOWS\login .exe [2010/10/28 15:40:12 | 000,035,456 | ---- | M] () -- C:\WINDOWS\win16 .exe [2010/10/28 15:40:01 | 000,035,452 | ---- | M] () -- C:\WINDOWS\login .exe [2010/10/28 15:39:50 | 000,035,448 | ---- | M] () -- C:\WINDOWS\win16 .exe [2010/10/28 15:39:39 | 000,035,444 | ---- | M] () -- C:\WINDOWS\login .exe [2010/10/28 15:39:28 | 000,035,440 | ---- | M] () -- C:\WINDOWS\win16 .exe [2010/10/28 15:39:18 | 000,035,436 | ---- | M] () -- C:\WINDOWS\login .exe [2010/10/28 15:39:07 | 000,035,432 | ---- | M] () -- C:\WINDOWS\win16 .exe [2010/10/28 15:38:55 | 000,035,428 | ---- | M] () -- C:\WINDOWS\login .exe [2010/10/28 15:38:41 | 000,035,424 | ---- | M] () -- C:\WINDOWS\win16 .exe [2010/10/28 15:38:30 | 000,035,420 | ---- | M] () -- C:\WINDOWS\login .exe [2010/10/28 15:38:19 | 000,035,416 | ---- | M] () -- C:\WINDOWS\win16 .exe [2010/10/28 15:38:08 | 000,035,412 | ---- | M] () -- C:\WINDOWS\login .exe [2010/10/28 15:37:57 | 000,035,408 | ---- | M] () -- C:\WINDOWS\win16 .exe [2010/10/28 15:37:45 | 000,035,404 | ---- | M] () -- C:\WINDOWS\login .exe [2010/10/28 15:37:33 | 000,035,400 | ---- | M] () -- C:\WINDOWS\win16 .exe [2010/10/28 15:37:22 | 000,035,396 | ---- | M] () -- C:\WINDOWS\login .exe [2010/10/28 15:37:04 | 000,035,392 | ---- | M] () -- C:\WINDOWS\win16 .exe [2010/10/28 15:36:42 | 000,035,384 | ---- | M] () -- C:\WINDOWS\win16 .exe [2010/10/28 15:36:42 | 000,035,384 | ---- | M] () -- C:\WINDOWS\login .exe [2010/10/28 15:36:10 | 000,035,384 | ---- | M] () -- C:\WINDOWS\login .exe [2010/10/28 15:36:09 | 000,035,376 | ---- | M] () -- C:\WINDOWS\win16 .exe [2010/10/28 15:35:47 | 000,035,372 | ---- | M] () -- C:\WINDOWS\win16 .exe [2010/10/28 15:35:47 | 000,035,372 | ---- | M] () -- C:\WINDOWS\login .exe [2010/10/28 15:35:27 | 000,035,380 | ---- | M] () -- C:\WINDOWS\login .exe [2010/10/28 15:35:26 | 000,035,380 | ---- | M] () -- C:\WINDOWS\win16 .exe [2010/10/28 15:35:07 | 000,035,376 | ---- | M] () -- C:\WINDOWS\win16 .exe [2010/10/28 15:35:07 | 000,035,376 | ---- | M] () -- C:\WINDOWS\services .exe [2010/10/28 15:35:07 | 000,035,376 | ---- | M] () -- C:\WINDOWS\login .exe [2010/10/28 15:34:36 | 000,035,372 | ---- | M] () -- C:\WINDOWS\login .exe [2010/10/28 15:34:22 | 000,035,380 | ---- | M] () -- C:\WINDOWS\services .exe [2010/10/28 15:34:18 | 000,035,364 | ---- | M] () -- C:\WINDOWS\win16 .exe [2010/10/28 15:34:04 | 000,035,368 | ---- | M] () -- C:\WINDOWS\login .exe [2010/10/28 15:33:56 | 000,035,372 | ---- | M] () -- C:\WINDOWS\services .exe [2010/10/28 15:33:52 | 000,035,380 | ---- | M] () -- C:\WINDOWS\win16 .exe [2010/10/28 15:33:25 | 000,035,364 | -H-- | M] () -- C:\WINDOWS\debug.exe [2010/10/28 15:33:23 | 000,035,364 | -H-- | M] () -- C:\WINDOWS\taskmgr.exe [2010/10/28 15:33:16 | 000,035,360 | ---- | M] () -- C:\WINDOWS\services .exe [2010/10/28 15:33:16 | 000,035,360 | ---- | M] () -- C:\WINDOWS\hexdump .exe [2010/10/28 15:33:06 | 000,035,392 | ---- | M] () -- C:\WINDOWS\win16 .exe [2010/10/28 15:32:35 | 000,035,348 | ---- | M] () -- C:\WINDOWS\nvsvc32 .exe [2010/10/28 15:32:32 | 000,035,348 | ---- | M] () -- C:\WINDOWS\services .exe [2010/10/28 15:32:31 | 000,035,368 | ---- | M] () -- C:\WINDOWS\hexdump .exe [2010/10/28 15:32:22 | 000,035,372 | ---- | M] () -- C:\WINDOWS\win16 .exe [2010/10/28 15:32:07 | 000,035,348 | -H-- | M] () -- C:\WINDOWS\winamp.exe [2010/10/28 15:32:06 | 000,035,348 | -H-- | M] () -- C:\Documents and Settings\Tamara x x\Local Settings\Application Data\HIdgf2CLF.exe [2010/10/28 15:32:05 | 000,035,348 | -H-- | M] () -- C:\WINDOWS\svchost.exe [2010/10/28 15:32:05 | 000,035,348 | -H-- | M] () -- C:\WINDOWS\System32\HIdgf2CLF.com [2010/10/28 15:32:04 | 000,035,348 | -H-- | M] () -- C:\WINDOWS\nvsvc32.exe [2010/10/28 15:32:02 | 000,035,348 | -H-- | M] () -- C:\WINDOWS\drweb.exe [2010/10/28 15:31:57 | 000,035,344 | ---- | M] () -- C:\WINDOWS\services .exe [2010/10/28 15:31:55 | 000,035,368 | ---- | M] () -- C:\WINDOWS\login .exe [2010/10/28 15:31:40 | 000,035,380 | ---- | M] () -- C:\WINDOWS\hexdump .exe [2010/10/28 15:31:34 | 000,035,380 | ---- | M] () -- C:\WINDOWS\win16 .exe [2010/10/28 15:31:14 | 000,035,376 | ---- | M] () -- C:\WINDOWS\services .exe [2010/10/28 15:30:56 | 000,035,376 | ---- | M] () -- C:\WINDOWS\login .exe [2010/10/28 15:30:49 | 000,035,348 | ---- | M] () -- C:\WINDOWS\hexdump .exe [2010/10/28 15:30:48 | 000,035,356 | -H-- | M] () -- C:\WINDOWS\cmd.exe [2010/10/28 15:30:46 | 000,035,356 | -H-- | M] () -- C:\WINDOWS\user.exe [2010/10/28 15:30:41 | 000,035,352 | ---- | M] () -- C:\WINDOWS\win16 .exe [2010/10/28 15:30:24 | 000,035,388 | ---- | M] () -- C:\WINDOWS\login .exe [2010/10/28 15:30:21 | 000,035,344 | ---- | M] () -- C:\WINDOWS\spoolsv .exe [2010/10/28 15:30:15 | 000,035,344 | ---- | M] () -- C:\WINDOWS\hexdump .exe [2010/10/28 15:30:11 | 000,035,348 | ---- | M] () -- C:\WINDOWS\setup .exe [2010/10/28 15:29:35 | 000,035,368 | -H-- | M] () -- C:\WINDOWS\setup .exe [2010/10/28 15:29:35 | 000,035,340 | ---- | M] () -- C:\WINDOWS\spoolsv .exe [2010/10/28 15:29:21 | 000,035,380 | -H-- | M] () -- C:\WINDOWS\sysedit.exe [2010/10/28 15:29:17 | 000,035,364 | -H-- | M] () -- C:\WINDOWS\install.exe [2010/10/28 15:29:16 | 000,035,376 | ---- | M] () -- C:\WINDOWS\win16 .exe [2010/10/28 15:29:15 | 000,035,364 | ---- | M] () -- C:\WINDOWS\login .exe [2010/10/28 15:29:14 | 000,035,364 | -H-- | M] () -- C:\WINDOWS\smss.exe [2010/10/28 15:28:58 | 000,035,340 | ---- | M] () -- C:\WINDOWS\spoolsv .exe [2010/10/28 15:28:45 | 000,035,364 | ---- | M] () -- C:\WINDOWS\setup .exe [2010/10/28 15:28:45 | 000,035,364 | ---- | M] () -- C:\WINDOWS\hexdump .exe [2010/10/28 15:28:45 | 000,035,364 | ---- | M] () -- C:\WINDOWS\avp32 .exe [2010/10/28 15:28:31 | 000,035,356 | ---- | M] () -- C:\WINDOWS\win16 .exe [2010/10/28 15:28:29 | 000,035,356 | ---- | M] () -- C:\WINDOWS\winlogon.exe [2010/10/28 15:28:29 | 000,035,356 | ---- | M] () -- C:\WINDOWS\login .exe [2010/10/28 15:28:20 | 000,021,636 | -H-- | M] (Microsoft Corporation) -- C:\WINDOWS\nvsvc32 .exe [2010/10/28 15:28:17 | 000,021,636 | -H-- | M] (Microsoft Corporation) -- C:\WINDOWS\winlogon .exe [2010/10/28 15:28:02 | 000,035,360 | ---- | M] () -- C:\WINDOWS\spoolsv .exe [2010/10/28 15:28:02 | 000,035,360 | ---- | M] () -- C:\WINDOWS\hexdump .exe [2010/10/28 15:27:37 | 000,000,108 | ---- | M] () -- C:\WINDOWS\System32\complete.dat [2010/10/28 15:27:30 | 000,035,364 | ---- | M] () -- C:\WINDOWS\login .exe [2010/10/28 15:27:28 | 000,035,352 | ---- | M] () -- C:\WINDOWS\setup.exe [2010/10/28 15:27:28 | 000,035,352 | ---- | M] () -- C:\WINDOWS\lsass.exe [2010/10/28 15:27:28 | 000,035,352 | ---- | M] () -- C:\WINDOWS\avp32.exe [2010/10/28 15:27:26 | 000,000,004 | ---- | M] () -- C:\Documents and Settings\LocalService\Application Data\cxnojk.dat [2010/10/28 15:27:24 | 000,000,004 | ---- | M] () -- C:\Documents and Settings\Tamara x x\Application Data\avdrn.dat [2010/10/28 15:27:05 | 000,021,636 | -H-- | M] (Microsoft Corporation) -- C:\WINDOWS\wininst.exe [2010/10/28 15:27:04 | 000,021,636 | -H-- | M] (Microsoft Corporation) -- C:\WINDOWS\win.exe [2010/10/28 15:27:02 | 000,000,120 | ---- | M] () -- C:\WINDOWS\Ihudaguzeyawebe.dat [2010/10/28 15:27:02 | 000,000,000 | ---- | M] () -- C:\WINDOWS\Xlaqozofu.bin [2 C:\WINDOWS\System32\*.tmp files -> C:\WINDOWS\System32\*.tmp -> ] [1 C:\WINDOWS\System32\drivers\*.tmp files -> C:\WINDOWS\System32\drivers\*.tmp -> ] [2010/10/28 15:33:25 | 000,035,364 | -H-- | C] () -- C:\WINDOWS\debug.exe [2010/10/28 15:32:02 | 000,035,348 | -H-- | C] () -- C:\WINDOWS\drweb.exe [2010/10/28 15:31:36 | 000,035,348 | -H-- | C] () -- C:\WINDOWS\winamp.exe [2010/10/28 15:30:48 | 000,035,356 | -H-- | C] () -- C:\WINDOWS\cmd.exe [2010/10/28 15:29:37 | 000,035,348 | -H-- | C] () -- C:\Documents and Settings\Tamara x x\Local Settings\Application Data\HIdgf2CLF.exe [2010/10/28 15:29:35 | 000,035,348 | -H-- | C] () -- C:\WINDOWS\System32\HIdgf2CLF.com [2010/10/28 15:29:35 | 000,000,352 | ---- | C] () -- C:\WINDOWS\tasks\At769.job [2010/10/28 15:29:21 | 000,035,380 | -H-- | C] () -- C:\WINDOWS\sysedit.exe [2010/10/28 15:29:17 | 000,035,364 | -H-- | C] () -- C:\WINDOWS\install.exe [2010/10/28 15:29:14 | 000,035,364 | -H-- | C] () -- C:\WINDOWS\smss.exe [2010/10/28 15:28:36 | 000,035,364 | -H-- | C] () -- C:\WINDOWS\Fonts\HIdgf2CLF.com [2010/10/28 15:28:17 | 000,035,356 | ---- | C] () -- C:\WINDOWS\winlogon.exe [2010/10/28 15:27:26 | 000,000,004 | ---- | C] () -- C:\Documents and Settings\LocalService\Application Data\cxnojk.dat [2010/10/28 15:27:24 | 000,000,004 | ---- | C] () -- C:\Documents and Settings\Tamara x x\Application Data\avdrn.dat [2010/10/28 15:26:43 | 000,158,208 | ---- | C] () -- C:\Documents and Settings\Tamara x x\Application Data\hotfixSrv.exe [2010/10/10 16:24:23 | 000,030,000 | ---- | C] () -- C:\WINDOWS\System32\n3xy5nh.dll [2010/10/10 16:24:22 | 000,030,000 | ---- | C] () -- C:\WINDOWS\System32\mzmddj1nar.dll [2010/10/10 16:21:40 | 000,030,000 | ---- | C] () -- C:\WINDOWS\System32\m69lbmmxi.dll [2010/10/10 16:21:40 | 000,030,000 | ---- | C] () -- C:\WINDOWS\System32\foj6mp.dll [2010/10/10 16:19:59 | 000,000,000 | ---- | C] () -- C:\WINDOWS\System32\drivers\ccxucg.sys [2010/10/10 16:19:35 | 000,734,208 | ---- | C] () -- C:\Documents and Settings\Tamara x x\Application Data\hotfix.exe [2010/10/10 16:19:35 | 000,002,256 | ---- | C] () -- C:\Documents and Settings\Tamara x x\Application Data\444.bat [2010/10/10 16:19:35 | 000,000,135 | ---- | C] () -- C:\Documents and Settings\Tamara x x\Application Data\asdsada.bat [2008/04/15 07:00:00 | 000,208,384 | ---- | C] () -- C:\WINDOWS\idohokofa.dll [2010/10/03 13:54:19 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Tamara x x\Application Data\Acapqe [2010/09/25 15:29:45 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Tamara x x\Application Data\Cuas [2010/09/22 05:49:40 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Tamara x x\Application Data\Ecutq [2010/10/28 15:29:21 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Tamara x x\Application Data\Edwy [2010/09/17 03:45:05 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Tamara x x\Application Data\Fuuro [2010/10/01 03:01:43 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Tamara x x\Application Data\Hecioh [2010/09/15 01:51:32 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Tamara x x\Application Data\Igiw [2010/09/22 21:18:55 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Tamara x x\Application Data\Ihopfo [2010/10/06 19:46:50 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Tamara x x\Application Data\Irce [2010/10/28 15:28:01 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Tamara x x\Application Data\Izkoo [2010/10/03 12:33:10 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Tamara x x\Application Data\Kygaw [2010/09/02 06:55:55 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Tamara x x\Application Data\Lauz [2010/10/12 21:32:49 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Tamara x x\Application Data\Luibu [2010/10/03 12:32:13 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Tamara x x\Application Data\Redoyb [2010/09/07 22:34:46 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Tamara x x\Application Data\Royxic [2010/10/11 02:53:19 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Tamara x x\Application Data\Unanp [2010/10/13 01:26:29 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Tamara x x\Application Data\Usraap [2010/09/16 14:05:47 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Tamara x x\Application Data\Uwqoel [2010/08/29 14:34:40 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Tamara x x\Application Data\Uzlik [2010/10/28 15:29:41 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Tamara x x\Application Data\Voukom [2010/10/10 13:40:55 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Tamara x x\Application Data\Wuwa [2010/09/20 07:44:22 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Tamara x x\Application Data\Xiwoci [2010/09/11 22:53:40 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Tamara x x\Application Data\Xuiz [2010/10/03 12:51:12 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Tamara x x\Application Data\Ysryob :Services :Reg :Files :Commands [purity] [resethosts] [emptytemp] [EMPTYFLASH] [CREATERESTOREPOINT] [Reboot]