Jump to content

Welcome to Geeks to Go - Register now for FREE

Need help with your computer or device? Want to learn new tech skills? You're in the right place!
Geeks to Go is a friendly community of tech experts who can solve any problem you have. Just create a free account and post your question. Our volunteers will reply quickly and guide you through the steps. Don't let tech troubles stop you. Join Geeks to Go now and get the support you need!

How it Works Create Account
Photo

infected with Win32.Delf.rtk and others [Solved]


  • This topic is locked This topic is locked

#1
JohnnieF

JohnnieF

    Member

  • Member
  • PipPip
  • 32 posts
Well I am here to report my results and they are good and bad.

First the good. I found a bunch of malware on my computer after a month of someone else using it. I removed a bunch of stuff but could not get rid of Win32.Delf.rtk. I came here and did some reading and followed the instructions on the Malware and Spyware Cleaning Guide. When I ran Malwarebytes it found a bunch more malware that my tools did not show at all. I had to run Malwarebytes' Anti-Malware three times but it seems to have done the job. I ran everything else in the guide and am posting the logs below here. I will just post the first and last Malwarebytes logs. My system now seems to be clean. I am using AVG as antivirus and Adaware and Spybot search and Distroy to check for nasties and they all show my system as clean now. Malwarebytes also shows nothing.

The bad. This machine is still very slow. It's a 3Gig P4 with Asus motherboard. I have two 2.4Gig P4s that are way faster then this one. Anyway this was the first step in trying to find out why this computer is so slow. I will now post a message in the hardware group to see if we can figure out why this computer is so slow.

I will also check back here to see if anyone sees anything else in the logs that could slow this machine down.


================Malwarebytes' Anti-Malware 1.38 log file 1
Database version: 2372
Windows 5.1.2600 Service Pack 3

04/07/2009 12:00:39 PM
mbam-log-2009-07-04 (12-00-39).txt

Scan type: Quick Scan
Objects scanned: 95377
Time elapsed: 7 minute(s), 24 second(s)

Memory Processes Infected: 0
Memory Modules Infected: 1
Registry Keys Infected: 7
Registry Values Infected: 10
Registry Data Items Infected: 0
Folders Infected: 0
Files Infected: 7

Memory Processes Infected:
(No malicious items detected)

Memory Modules Infected:
c:\WINDOWS\system32\msncache.dll (Backdoor.Bot) -> Delete on reboot.

Registry Keys Infected:
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\msncache (Backdoor.Bot) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet003\Services\msncache (Backdoor.Bot) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\msncache (Backdoor.Bot) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\Typelib\{f3d0c92a-2063-2a0d-9256-05e3846d38b0} (Trojan.FakeAlert) -> Quarantined and deleted successfully.
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\Stats\{500bca15-57a7-4eaf-8143-8c619470b13d} (Trojan.FakeAlert) -> Quarantined and deleted successfully.
HKEY_CURRENT_USER\SOFTWARE\XML (Trojan.FakeAlert) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\dailybucks_install.exe (Security.Hijack) -> Quarantined and deleted successfully.

Registry Values Infected:
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\BuildW (Malware.Trace) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\FirstInstallFlag (Malware.Trace) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\guid (Malware.Trace) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\i (Malware.Trace) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\mms (Malware.Trace) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\mso (Malware.Trace) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\uid (Malware.Trace) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\Ulrn (Malware.Trace) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\Update (Malware.Trace) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\UpdateNew (Malware.Trace) -> Quarantined and deleted successfully.

Registry Data Items Infected:
(No malicious items detected)

Folders Infected:
(No malicious items detected)

Files Infected:
c:\WINDOWS\system32\msncache.dll (Backdoor.Bot) -> Delete on reboot.
c:\WINDOWS\system32\sopidkc.exe (Trojan.Agent) -> Quarantined and deleted successfully.
C:\WINDOWS\system32\comsa32.sys (Trojan.Agent) -> Quarantined and deleted successfully.
C:\WINDOWS\system32\FInstall.sys (Backdoor.Bot) -> Quarantined and deleted successfully.
C:\WINDOWS\system32\wiwow64.exe (Backdoor.Bot) -> Quarantined and deleted successfully.
C:\WINDOWS\system32\msxml71.dll (Trojan.FakeAlert) -> Quarantined and deleted successfully.
C:\WINDOWS\system32\wiawow32.sys (Backdoor.Bot) -> Quarantined and deleted successfully.

================Malwarebytes' Anti-Malware 1.38 log file 3
Database version: 2373
Windows 5.1.2600 Service Pack 3

04/07/2009 12:23:53 PM
mbam-log-2009-07-04 (12-23-53).txt

Scan type: Quick Scan
Objects scanned: 95406
Time elapsed: 3 minute(s), 5 second(s)

Memory Processes Infected: 0
Memory Modules Infected: 0
Registry Keys Infected: 0
Registry Values Infected: 0
Registry Data Items Infected: 0
Folders Infected: 0
Files Infected: 0

Memory Processes Infected:
(No malicious items detected)

Memory Modules Infected:
(No malicious items detected)

Registry Keys Infected:
(No malicious items detected)

Registry Values Infected:
(No malicious items detected)

Registry Data Items Infected:
(No malicious items detected)

Folders Infected:
(No malicious items detected)

Files Infected:
(No malicious items detected)

================Rooter.exe (v1.0.2) by Eric_71
.
SeDebugPrivilege granted successfully ...
.
Windows XP . (5.1.2600) Service Pack 3
[32_bits] - x86 Family 15 Model 4 Stepping 1, GenuineIntel
.
[wscsvc] (Security Center) RUNNING (state:4)
[SharedAccess] STOPPED (state:1) : Windows Firewall -> Disabled !
.
Internet Explorer 8.0.6001.18702
Mozilla Firefox 3.0.11 (en-US)
.
A:\ [Removable]
C:\ [Fixed-NTFS] .. ( Total:95 Go - Free:36 Go )
D:\ [Fixed-NTFS] .. ( Total:370 Go - Free:151 Go )
E:\ [Fixed-NTFS] .. ( Total:465 Go - Free:0 Go )
F:\ [Removable]
G:\ [CD_Rom]
.
Scan : 17:29.13
Path : C:\Documents and Settings\Johnnie\Desktop\Maintence\GEEKS to GO\! ! Malware Tools\Rooter.exe
User : Johnnie ( Administrator -> YES )
.
----------------------\\ Processes
.
Locked [System Process] (0)
______ System (4)
______ \SystemRoot\System32\smss.exe (804)
______ \??\C:\WINDOWS\system32\csrss.exe (872)
______ \??\C:\WINDOWS\system32\winlogon.exe (904)
______ C:\WINDOWS\system32\services.exe (948)
______ C:\WINDOWS\system32\lsass.exe (960)
______ C:\WINDOWS\system32\Ati2evxx.exe (1132)
______ C:\WINDOWS\system32\svchost.exe (1164)
______ C:\WINDOWS\system32\svchost.exe (1240)
______ C:\WINDOWS\system32\svchost.exe (1360)
______ C:\WINDOWS\system32\svchost.exe (1376)
______ C:\WINDOWS\system32\Ati2evxx.exe (1396)
______ C:\WINDOWS\system32\svchost.exe (1524)
______ C:\Program Files\Lavasoft\Ad-Aware\AAWService.exe (1576)
______ C:\WINDOWS\system32\spoolsv.exe (1656)
______ C:\WINDOWS\system32\svchost.exe (1860)
______ C:\Program Files\Common Files\Acronis\Schedule2\schedul2.exe (1908)
______ C:\PROGRA~1\AVG\AVG8\avgwdsvc.exe (1940)
______ C:\Program Files\Java\jre6\bin\jqs.exe (2040)
______ C:\WINDOWS\system32\oodag.exe (396)
______ C:\PROGRA~1\AVG\AVG8\avgrsx.exe (536)
______ C:\Program Files\Analog Devices\SoundMAX\SMAgent.exe (664)
______ C:\WINDOWS\system32\svchost.exe (688)
______ C:\Program Files\Common Files\Acronis\Fomatik\TrueImageTryStartService.exe (1324)
______ C:\Program Files\UPHClean\uphclean.exe (1880)
______ C:\WINDOWS\system32\wbem\unsecapp.exe (2140)
______ C:\WINDOWS\system32\wbem\wmiprvse.exe (2204)
______ C:\WINDOWS\Explorer.EXE (2660)
______ C:\Program Files\Acronis\TrueImageHome\TrueImageMonitor.exe (2928)
______ C:\Program Files\Acronis\TrueImageHome\TimounterMonitor.exe (2956)
______ C:\Program Files\Common Files\Acronis\Schedule2\schedhlp.exe (2972)
______ C:\PROGRA~1\AVG\AVG8\avgtray.exe (3012)
______ C:\Program Files\Microsoft IntelliPoint\ipoint.exe (3064)
______ C:\WINDOWS\system32\ctfmon.exe (3184)
______ C:\WINDOWS\System32\svchost.exe (3252)
______ C:\WINDOWS\explorer.exe (3368)
______ C:\Program Files\Mozilla Firefox\firefox.exe (1556)
______ C:\Documents and Settings\Johnnie\Desktop\Maintence\GEEKS to GO\! ! Malware Tools\Rooter.exe (1808)
.
----------------------\\ Device\Harddisk0\
.
\Device\Harddisk0 [Sectors : 63 x 512 Bytes]
.
\Device\Harddisk0\Partition1 (Start_Offset:102396510720 | Length:397708738560)
\Device\Harddisk0\Partition2 --[ MBR ]-- (Start_Offset:32256 | Length:102396478464)
.
----------------------\\ Scheduled Tasks
.
C:\WINDOWS\Tasks\Ad-Aware Update (Weekly).job
C:\WINDOWS\Tasks\desktop.ini
C:\WINDOWS\Tasks\Microsoft_Hardware_Launch_IPoint_exe.job
C:\WINDOWS\Tasks\Norton Security Scan for Johnnie.job
C:\WINDOWS\Tasks\SA.DAT
.
----------------------\\ Registry
.
.
----------------------\\ Files & Folders
.
----------------------\\ Scan completed at 17:31.48
.
C:\Rooter$\Rooter_1.txt - (04/07/2009 | 17:31.48)

================OTL logfile created on: 05/07/2009 9:20:06 AM - Run 1
OTL by OldTimer - Version 3.0.6.4 Folder = C:\Documents and Settings\Johnnie\Desktop\Maintence\GEEKS to GO\! ! Malware Tools
Windows XP Professional Edition Service Pack 3 (Version = 5.1.2600) - Type = NTWorkstation
Internet Explorer (Version = 8.0.6001.18702)
Locale: 00001009 | Country: Canada | Language: ENC | Date Format: dd/MM/yyyy

2.00 Gb Total Physical Memory | 2.00 Gb Available Physical Memory | 99.87% Memory free
4.00 Gb Paging File | 4.00 Gb Available in Paging File | 100.00% Paging File free
Paging file location(s): C:\pagefile.sys 3000 4000 [binary data]

%SystemDrive% = C: | %SystemRoot% = C:\WINDOWS | %ProgramFiles% = C:\Program Files
Drive C: | 95.36 Gb Total Space | 36.02 Gb Free Space | 37.77% Space Free | Partition Type: NTFS
Drive D: | 370.40 Gb Total Space | 157.69 Gb Free Space | 42.57% Space Free | Partition Type: NTFS
Drive E: | 465.76 Gb Total Space | 0.63 Gb Free Space | 0.14% Space Free | Partition Type: NTFS
Drive F: | 1.86 Gb Total Space | 1.84 Gb Free Space | 98.54% Space Free | Partition Type: FAT
G: Drive not present or media not loaded
H: Drive not present or media not loaded
I: Drive not present or media not loaded

Computer Name: LIVINGROOM
Current User Name: Johnnie
Logged in as Administrator.

Current Boot Mode: Normal
Scan Mode: Current user
Company Name Whitelist: Off
Skip Microsoft Files: Off
File Age = 30 Days
Output = Minimal

========== Processes (SafeList) ==========

PRC - C:\WINDOWS\System32\Ati2evxx.exe (ATI Technologies Inc.)
PRC - C:\WINDOWS\System32\Ati2evxx.exe (ATI Technologies Inc.)
PRC - C:\Program Files\Common Files\Acronis\Schedule2\schedul2.exe (Acronis)
PRC - C:\Program Files\AVG\AVG8\avgwdsvc.exe (AVG Technologies CZ, s.r.o.)
PRC - C:\Program Files\Java\jre6\bin\jqs.exe (Sun Microsystems, Inc.)
PRC - C:\WINDOWS\System32\oodag.exe (O&O Software GmbH)
PRC - C:\Program Files\Analog Devices\SoundMAX\SMAgent.exe (Analog Devices, Inc.)
PRC - C:\Program Files\Common Files\Acronis\Fomatik\TrueImageTryStartService.exe ()
PRC - C:\Program Files\AVG\AVG8\avgrsx.exe (AVG Technologies CZ, s.r.o.)
PRC - C:\WINDOWS\Explorer.EXE (Microsoft Corporation)
PRC - C:\Program Files\UPHClean\uphclean.exe (Microsoft Corporation)
PRC - C:\Program Files\Acronis\TrueImageHome\TrueImageMonitor.exe (Acronis)
PRC - C:\Program Files\Acronis\TrueImageHome\TimounterMonitor.exe (Acronis)
PRC - C:\Program Files\Common Files\Acronis\Schedule2\schedhlp.exe (Acronis)
PRC - C:\Program Files\AVG\AVG8\avgtray.exe (AVG Technologies CZ, s.r.o.)
PRC - C:\Program Files\Microsoft IntelliPoint\ipoint.exe (Microsoft Corporation)
PRC - C:\WINDOWS\explorer.exe (Microsoft Corporation)
PRC - C:\Program Files\Mozilla Firefox\firefox.exe (Mozilla Corporation)
PRC - C:\Documents and Settings\Johnnie\Desktop\Maintence\GEEKS to GO\! ! Malware Tools\OTL.exe (OldTimer Tools)

========== Win32 Services (SafeList) ==========

SRV - (AcrSch2Svc [Auto | Running]) -- C:\Program Files\Common Files\Acronis\Schedule2\schedul2.exe (Acronis)
SRV - (aspnet_state [On_Demand | Stopped]) -- C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\aspnet_state.exe (Microsoft Corporation)
SRV - (Ati HotKey Poller [Auto | Running]) -- C:\WINDOWS\System32\Ati2evxx.exe (ATI Technologies Inc.)
SRV - (ATI Smart [Auto | Stopped]) -- C:\WINDOWS\System32\ati2sgag.exe ()
SRV - (avg8wd [Auto | Running]) -- C:\Program Files\AVG\AVG8\avgwdsvc.exe (AVG Technologies CZ, s.r.o.)
SRV - (brmfrmps [Disabled | Stopped]) -- File not found
SRV - (Brother XP spl Service [Disabled | Stopped]) -- C:\WINDOWS\System32\brsvc01a.exe (brother Industries Ltd)
SRV - (clr_optimization_v2.0.50727_32 [On_Demand | Stopped]) -- C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\mscorsvw.exe (Microsoft Corporation)
SRV - (FLEXnet Licensing Service [On_Demand | Stopped]) -- C:\Program Files\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe (Macrovision Europe Ltd.)
SRV - (FontCache3.0.0.0 [On_Demand | Stopped]) -- C:\WINDOWS\Microsoft.NET\Framework\v3.0\WPF\PresentationFontCache.exe (Microsoft Corporation)
SRV - (helpsvc [Auto | Running]) -- C:\WINDOWS\PCHealth\HelpCtr\Binaries\pchsvc.dll (Microsoft Corporation)
SRV - (IDriverT [On_Demand | Stopped]) -- C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe (Macrovision Corporation)
SRV - (idsvc [Unknown | Stopped]) -- C:\WINDOWS\Microsoft.NET\Framework\v3.0\Windows Communication Foundation\infocard.exe (Microsoft Corporation)
SRV - (JavaQuickStarterService [Auto | Running]) -- C:\Program Files\Java\jre6\bin\jqs.exe (Sun Microsystems, Inc.)
SRV - (Lavasoft Ad-Aware Service [Auto | Stopped]) -- C:\Program Files\Lavasoft\Ad-Aware\AAWService.exe (Lavasoft)
SRV - (NetTcpPortSharing [Disabled | Stopped]) -- C:\WINDOWS\Microsoft.NET\Framework\v3.0\Windows Communication Foundation\SMSvcHost.exe (Microsoft Corporation)
SRV - (O&O Defrag [Auto | Running]) -- C:\WINDOWS\System32\oodag.exe (O&O Software GmbH)
SRV - (odserv [On_Demand | Stopped]) -- C:\Program Files\Common Files\Microsoft Shared\OFFICE12\ODSERV.EXE (Microsoft Corporation)
SRV - (ose [On_Demand | Stopped]) -- C:\Program Files\Common Files\Microsoft Shared\Source Engine\OSE.EXE (Microsoft Corporation)
SRV - (rpcapd [On_Demand | Stopped]) -- C:\Program Files\WinPcap\rpcapd.exe ()
SRV - (sdAuxService [On_Demand | Stopped]) -- C:\Program Files\Spyware Doctor\pctsAuxs.exe (PC Tools)
SRV - (sdCoreService [On_Demand | Stopped]) -- C:\Program Files\Spyware Doctor\pctsSvc.exe (PC Tools)
SRV - (SoundMAX Agent Service (default) [Auto | Running]) -- C:\Program Files\Analog Devices\SoundMAX\SMAgent.exe (Analog Devices, Inc.)
SRV - (TomTomHOMEService [On_Demand | Stopped]) -- C:\Program Files\TomTom HOME 2\TomTomHOMEService.exe (TomTom)
SRV - (TryAndDecideService [Auto | Running]) -- C:\Program Files\Common Files\Acronis\Fomatik\TrueImageTryStartService.exe ()
SRV - (UPHClean [Auto | Running]) -- C:\Program Files\UPHClean\uphclean.exe (Microsoft Corporation)
SRV - (UplinkService [Disabled | Stopped]) -- C:\Program Files\NCH Swift Sound\Uplink\uplink.exe ()

========== Driver Services (SafeList) ==========

DRV - (aeaudio [On_Demand | Running]) -- C:\WINDOWS\System32\drivers\aeaudio.sys (Andrea Electronics Corporation)
DRV - (AnyDVD [On_Demand | Running]) -- C:\WINDOWS\System32\Drivers\AnyDVD.sys (SlySoft, Inc.)
DRV - (ASPI32 [Auto | Running]) -- C:\WINDOWS\System32\drivers\aspi32.sys (Adaptec)
DRV - (ati2mtaa [On_Demand | Stopped]) -- C:\WINDOWS\System32\DRIVERS\ati2mtaa.sys (ATI Technologies Inc.)
DRV - (ati2mtag [On_Demand | Running]) -- C:\WINDOWS\System32\DRIVERS\ati2mtag.sys (ATI Technologies Inc.)
DRV - (AvgLdx86 [System | Running]) -- C:\WINDOWS\System32\Drivers\avgldx86.sys (AVG Technologies CZ, s.r.o.)
DRV - (AvgMfx86 [System | Running]) -- C:\WINDOWS\System32\Drivers\avgmfx86.sys (AVG Technologies CZ, s.r.o.)
DRV - (brfilt [On_Demand | Stopped]) -- C:\WINDOWS\System32\Drivers\Brfilt.sys (Brother Industries Ltd.)
DRV - (BrSerWDM [On_Demand | Stopped]) -- C:\WINDOWS\System32\Drivers\BrSerWdm.sys (Brother Industries Ltd.)
DRV - (BrUsbMdm [On_Demand | Stopped]) -- C:\WINDOWS\System32\Drivers\BrUsbMdm.sys (Brother Industries Ltd.)
DRV - (BrUsbScn [On_Demand | Stopped]) -- C:\WINDOWS\System32\Drivers\BrUsbScn.sys (Brother Industries Ltd.)
DRV - (cpuz132 [On_Demand | Stopped]) -- C:\WINDOWS\System32\drivers\cpuz132_x32.sys (Windows ® Codename Longhorn DDK provider)
DRV - (DgiVecp [Auto | Stopped]) -- C:\WINDOWS\System32\Drivers\DgiVecp.sys (DeviceGuys, Inc.)
DRV - (EL2000 [On_Demand | Stopped]) -- C:\WINDOWS\System32\DRIVERS\EL2K_XP.sys (3Com Corporation)
DRV - (ElbyCDIO [System | Running]) -- C:\WINDOWS\System32\Drivers\ElbyCDIO.sys (Elaborate Bytes AG)
DRV - (Lbd [Boot | Running]) -- C:\WINDOWS\system32\DRIVERS\Lbd.sys (Lavasoft AB)
DRV - (m4cxw2k3 [On_Demand | Stopped]) -- C:\WINDOWS\System32\DRIVERS\m4cxw2k3.sys (D-Link Corporation)
DRV - (mf [On_Demand | Stopped]) -- C:\WINDOWS\System32\DRIVERS\mf.sys (Microsoft Corporation)
DRV - (MidiSyn [On_Demand | Stopped]) -- C:\WINDOWS\System32\drivers\MidiSyn.sys (Analog Devices Inc)
DRV - (MPE [On_Demand | Stopped]) -- C:\WINDOWS\System32\DRIVERS\MPE.sys (Microsoft Corporation)
DRV - (NPF [On_Demand | Stopped]) -- C:\WINDOWS\System32\drivers\npf.sys (Politecnico di Torino)
DRV - (pcouffin [On_Demand | Running]) -- C:\WINDOWS\System32\Drivers\pcouffin.sys (VSO Software)
DRV - (PCTCore [Boot | Running]) -- C:\WINDOWS\system32\drivers\PCTCore.sys (PC Tools)
DRV - (Point32 [On_Demand | Running]) -- C:\WINDOWS\System32\DRIVERS\point32.sys (Microsoft Corporation)
DRV - (PQNTDrv [System | Running]) -- C:\WINDOWS\System32\drivers\PQNTDRV.sys (PowerQuest Corporation)
DRV - (Ptilink [On_Demand | Running]) -- C:\WINDOWS\System32\DRIVERS\ptilink.sys (Parallel Technologies, Inc.)
DRV - (SABProcEnum [On_Demand | Stopped]) -- C:\WINDOWS\System32\sabprocenum.sys (SuperAdBlocker.com)
DRV - (Secdrv [On_Demand | Stopped]) -- C:\WINDOWS\System32\DRIVERS\secdrv.sys (Macrovision Corporation, Macrovision Europe Limited, and Macrovision Japan and Asia K.K.)
DRV - (smwdm [On_Demand | Running]) -- C:\WINDOWS\System32\drivers\smwdm.sys (Analog Devices, Inc.)
DRV - (snapman [Boot | Running]) -- C:\WINDOWS\system32\DRIVERS\snapman.sys (Acronis)
DRV - (sptd [Boot | Running]) -- C:\WINDOWS\System32\Drivers\sptd.sys ()
DRV - (tdrpman [Boot | Running]) -- C:\WINDOWS\system32\DRIVERS\tdrpman.sys (Acronis)
DRV - (tifsfilter [Auto | Running]) -- C:\WINDOWS\System32\DRIVERS\tifsfilt.sys (Acronis)
DRV - (timounter [Boot | Running]) -- C:\WINDOWS\system32\DRIVERS\timntr.sys (Acronis)
DRV - (Uplink [On_Demand | Running]) -- C:\WINDOWS\System32\drivers\Uplink.sys (NCH Swift Sound)
DRV - (usbaudio [On_Demand | Stopped]) -- C:\WINDOWS\System32\drivers\usbaudio.sys (Microsoft Corporation)
DRV - (WmBEnum [On_Demand | Running]) -- C:\WINDOWS\System32\drivers\WmBEnum.sys (Logitech Inc.)
DRV - (WmFilter [On_Demand | Stopped]) -- C:\WINDOWS\System32\drivers\WmFilter.sys (Logitech Inc.)
DRV - (WmVirHid [On_Demand | Stopped]) -- C:\WINDOWS\System32\drivers\WmVirHid.sys (Logitech Inc.)
DRV - (WmXlCore [On_Demand | Running]) -- C:\WINDOWS\System32\drivers\WmXlCore.sys (Logitech Inc.)
DRV - (yukonwxp [On_Demand | Running]) -- C:\WINDOWS\System32\DRIVERS\yk51x86.sys (Marvell)

========== Standard Registry (SafeList) ==========


========== Internet Explorer ==========

IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft....k/?LinkId=69157
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft....k/?LinkId=54896
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Secondary_Page_URL = [binary data]
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Extensions Off Page = about:NoAdd-ons
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Local Page = C:\WINDOWS\system32\blank.htm
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft....k/?LinkId=54896
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Security Risk Page = about:SecurityRisk
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft....k/?LinkId=69157
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Search,CustomizeSearch = http://ie.search.msn...st/srchcust.htm
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Search,SearchAssistant = http://www.google.com/ie

IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Local Page = C:\WINDOWS\system32\blank.htm
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Page_Transitions = 0
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Search Page = http://www.google.com
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,SearchMigratedDefaultName = Google
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,SearchMigratedDefaultURL = http://www.google.co...m...tf8&oe=utf8
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://www.google.com/
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyOverride" = *.local

========== FireFox ==========

FF - prefs.js..browser.search.suggest.enabled: false
FF - prefs.js..browser.startup.homepage: "http://mirariver.com/"
FF - prefs.js..extensions.enabledItems: {3f963a5b-e555-4543-90e2-c3908898db71}:8.5
FF - prefs.js..extensions.enabledItems: [email protected]:3.1.2
FF - prefs.js..extensions.enabledItems: {CAFEEFAC-0016-0000-0006-ABCDEFFEDCBA}:6.0.06
FF - prefs.js..extensions.enabledItems: {CAFEEFAC-0016-0000-0013-ABCDEFFEDCBA}:6.0.13
FF - prefs.js..extensions.enabledItems: [email protected]:1.0
FF - prefs.js..extensions.enabledItems: {20a82645-c095-46ed-80e3-08825760534b}:1.1
FF - prefs.js..extensions.enabledItems: {972ce4c6-7e08-4474-a285-3208198ce6fd}:3.0.11

FF - HKLM\software\mozilla\Firefox\Extensions\\{3f963a5b-e555-4543-90e2-c3908898db71}: C:\Program Files\AVG\AVG8\Firefox [2009/06/29 08:58:09 | 00,000,000 | ---D | M]
FF - HKLM\software\mozilla\Firefox\Extensions\\{20a82645-c095-46ed-80e3-08825760534b}: C:\WINDOWS\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\DotNetAssistantExtension\ [2009/07/04 16:40:23 | 00,000,000 | ---D | M]
FF - HKLM\software\mozilla\Firefox\Extensions\\[email protected]: C:\Program Files\Java\jre6\lib\deploy\jqs\ff [2008/12/12 19:54:33 | 00,000,000 | ---D | M]
FF - HKLM\software\mozilla\Mozilla Firefox 3.0.11\extensions\\Components: C:\Program Files\Mozilla Firefox\components [2009/06/19 12:32:48 | 00,000,000 | ---D | M]
FF - HKLM\software\mozilla\Mozilla Firefox 3.0.11\extensions\\Plugins: C:\Program Files\Mozilla Firefox\plugins [2009/06/16 08:21:03 | 00,000,000 | ---D | M]

[2009/01/19 15:32:26 | 00,000,000 | ---D | M] -- C:\Documents and Settings\Johnnie\Application Data\mozilla\Extensions
[2008/07/01 12:48:45 | 00,000,000 | ---D | M] -- C:\Documents and Settings\Johnnie\Application Data\mozilla\Extensions\{ec8030f7-c20a-464f-9b0e-13a3a9e97384}
[2009/01/19 15:32:26 | 00,000,000 | ---D | M] -- C:\Documents and Settings\Johnnie\Application Data\mozilla\Extensions\[email protected]
[2009/07/05 08:11:41 | 00,000,000 | ---D | M] -- C:\Documents and Settings\Johnnie\Application Data\mozilla\Firefox\Profiles\2zi1h6xu.default\extensions
[2009/07/04 16:50:53 | 00,000,000 | ---D | M] -- C:\Documents and Settings\Johnnie\Application Data\mozilla\Firefox\Profiles\2zi1h6xu.default\extensions\{20a82645-c095-46ed-80e3-08825760534b}
[2008/12/01 21:43:04 | 00,000,000 | ---D | M] -- C:\Documents and Settings\Johnnie\Application Data\mozilla\Firefox\Profiles\2zi1h6xu.default\extensions\[email protected]
[2009/07/05 08:11:41 | 00,000,000 | ---D | M] -- C:\Program Files\mozilla firefox\extensions
[2009/06/16 08:21:03 | 00,000,000 | ---D | M] -- C:\Program Files\mozilla firefox\extensions\{972ce4c6-7e08-4474-a285-3208198ce6fd}
[2008/07/02 19:20:08 | 00,000,000 | ---D | M] -- C:\Program Files\mozilla firefox\extensions\{CAFEEFAC-0016-0000-0006-ABCDEFFEDCBA}
[2009/04/05 23:18:48 | 00,000,000 | ---D | M] -- C:\Program Files\mozilla firefox\extensions\{CAFEEFAC-0016-0000-0013-ABCDEFFEDCBA}
[2009/06/16 08:20:18 | 00,023,032 | ---- | M] (Mozilla Foundation) -- C:\Program Files\mozilla firefox\components\browserdirprovider.dll
[2009/06/16 08:20:18 | 00,134,648 | ---- | M] (Mozilla Foundation) -- C:\Program Files\mozilla firefox\components\brwsrcmp.dll
[2009/03/09 05:19:09 | 00,410,984 | ---- | M] (Sun Microsystems, Inc.) -- C:\Program Files\mozilla firefox\plugins\npdeploytk.dll
[2005/12/05 23:31:00 | 00,114,688 | ---- | M] () -- C:\Program Files\mozilla firefox\plugins\npmozax.dll
[2009/06/16 08:20:26 | 00,065,528 | ---- | M] (mozilla.org) -- C:\Program Files\mozilla firefox\plugins\npnul32.dll
[2006/10/26 20:12:16 | 00,016,192 | ---- | M] (Microsoft Corporation) -- C:\Program Files\mozilla firefox\plugins\NPOFF12.DLL
[2009/02/27 12:13:42 | 00,103,792 | ---- | M] (Adobe Systems Inc.) -- C:\Program Files\mozilla firefox\plugins\nppdf32.dll
[2006/02/02 16:56:00 | 00,225,280 | ---- | M] (Virtools SA) -- C:\Program Files\mozilla firefox\plugins\npvirtools.dll
[2009/04/24 21:44:31 | 00,001,394 | ---- | M] () -- C:\Program Files\mozilla firefox\searchplugins\amazondotcom.xml
[2009/04/24 21:44:31 | 00,002,193 | ---- | M] () -- C:\Program Files\mozilla firefox\searchplugins\answers.xml
[2009/04/24 21:44:31 | 00,001,534 | ---- | M] () -- C:\Program Files\mozilla firefox\searchplugins\creativecommons.xml
[2009/04/24 21:44:31 | 00,002,343 | ---- | M] () -- C:\Program Files\mozilla firefox\searchplugins\eBay.xml
[2009/04/24 21:44:31 | 00,001,706 | ---- | M] () -- C:\Program Files\mozilla firefox\searchplugins\google.xml
[2009/04/24 21:44:31 | 00,001,178 | ---- | M] () -- C:\Program Files\mozilla firefox\searchplugins\wikipedia.xml
[2009/04/24 21:44:31 | 00,000,792 | ---- | M] () -- C:\Program Files\mozilla firefox\searchplugins\yahoo.xml

O1 HOSTS File: (292053 bytes) - C:\WINDOWS\System32\drivers\etc\Hosts
O1 - Hosts: 127.0.0.1 localhost
O1 - Hosts: 127.0.0.1 www.007guard.com
O1 - Hosts: 127.0.0.1 007guard.com
O1 - Hosts: 127.0.0.1 008i.com
O1 - Hosts: 127.0.0.1 www.008k.com
O1 - Hosts: 127.0.0.1 008k.com
O1 - Hosts: 127.0.0.1 www.00hq.com
O1 - Hosts: 127.0.0.1 00hq.com
O1 - Hosts: 127.0.0.1 010402.com
O1 - Hosts: 127.0.0.1 www.032439.com
O1 - Hosts: 127.0.0.1 032439.com
O1 - Hosts: 127.0.0.1 www.0scan.com
O1 - Hosts: 127.0.0.1 0scan.com
O1 - Hosts: 127.0.0.1 1000gratisproben.com
O1 - Hosts: 127.0.0.1 www.1000gratisproben.com
O1 - Hosts: 127.0.0.1 www.1001namen.com
O1 - Hosts: 127.0.0.1 1001namen.com
O1 - Hosts: 127.0.0.1 www.100888290cs.com
O1 - Hosts: 127.0.0.1 100888290cs.com
O1 - Hosts: 127.0.0.1 www.100sexlinks.com
O1 - Hosts: 127.0.0.1 100sexlinks.com
O1 - Hosts: 127.0.0.1 www.10sek.com
O1 - Hosts: 127.0.0.1 10sek.com
O1 - Hosts: 127.0.0.1 www.1-2005-search.com
O1 - Hosts: 127.0.0.1 1-2005-search.com
O1 - Hosts: 10057 more lines...
O2 - BHO: (Adobe PDF Link Helper) - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll (Adobe Systems Incorporated)
O2 - BHO: (AVG Safe Search) - {3CA2F312-6F6E-4B53-A66E-4E65E497C8C0} - C:\Program Files\AVG\AVG8\avgssie.dll (AVG Technologies CZ, s.r.o.)
O2 - BHO: (Spybot-S&D IE Protection) - {53707962-6F74-2D53-2644-206D7942484F} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll (Safer Networking Limited)
O2 - BHO: (no name) - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - No CLSID value found.
O2 - BHO: (Adobe PDF Conversion Toolbar Helper) - {AE7CD045-E861-484f-8273-0445EE161910} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll (Adobe Systems Incorporated)
O2 - BHO: (Java™ Plug-In 2 SSV Helper) - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll (Sun Microsystems, Inc.)
O2 - BHO: (JQSIEStartDetectorImpl Class) - {E7E6F031-17CE-4C07-BC86-EABFE594F69C} - C:\Program Files\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll (Sun Microsystems, Inc.)
O2 - BHO: (SmartSelect Class) - {F4971EE7-DAA0-4053-9964-665D8EE6A077} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll (Adobe Systems Incorporated)
O3 - HKLM\..\Toolbar: (Adobe PDF) - {47833539-D0C5-4125-9FA8-0819E2EAAC93} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll (Adobe Systems Incorporated)
O3 - HKCU\..\Toolbar\ShellBrowser: (no name) - {73C7D5B0-7B03-444A-84C7-CE1BA03B5573} - No CLSID value found.
O3 - HKCU\..\Toolbar\WebBrowser: (Adobe PDF) - {47833539-D0C5-4125-9FA8-0819E2EAAC93} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll (Adobe Systems Incorporated)
O4 - HKLM..\Run: [Acronis Scheduler2 Service] C:\Program Files\Common Files\Acronis\Schedule2\schedhlp.exe (Acronis)
O4 - HKLM..\Run: [AcronisTimounterMonitor] C:\Program Files\Acronis\TrueImageHome\TimounterMonitor.exe (Acronis)
O4 - HKLM..\Run: [AVG8_TRAY] C:\Program Files\AVG\AVG8\avgtray.exe (AVG Technologies CZ, s.r.o.)
O4 - HKLM..\Run: [IntelliPoint] C:\Program Files\Microsoft IntelliPoint\ipoint.exe (Microsoft Corporation)
O4 - HKLM..\Run: [SoundMAX] C:\Program Files\Analog Devices\SoundMAX\Smax4.exe (Analog Devices, Inc.)
O4 - HKLM..\Run: [SoundMAXPnP] C:\Program Files\Analog Devices\SoundMAX\SMax4PNP.exe (Analog Devices, Inc.)
O4 - HKLM..\Run: [TrueImageMonitor.exe] C:\Program Files\Acronis\TrueImageHome\TrueImageMonitor.exe (Acronis)
O4 - HKCU..\Run: [DynAdvance Notifier] C:\Program Files\DynAdvance Notifier\MailNotifier.Exe (Catalin Stavaru)
O4 - HKCU..\Run: [Mailbell] C:\Program Files\MailBell\mailbell.exe ()
O6 - HKLM\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O6 - HKLM\Software\Policies\Microsoft\Internet Explorer\Infodelivery present
O6 - HKLM\Software\Policies\Microsoft\Internet Explorer\Restrictions present
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoResolveTrack = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoPropertiesMyComputer = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoViewContextMenu = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoFileAssociate = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoFind = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoRun = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoClose = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: StartMenuLogoff = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoSMHelp = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: HonorAutoRunSetting = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: dontdisplaylastusername = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: legalnoticecaption =
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: legalnoticetext =
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: undockwithoutlogon = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ShutdownWithoutLogon = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: NoDispCPL = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: NoDispBackgroundPage = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: NoDispSettingsPage = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: NoDispScrSavPage = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: DisableRegistryTools = 0
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoCDBurning = 1
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoRecentDocsHistory = 0
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: ClearRecentDocsOnExit = 0
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: HideClock = 0
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoTrayItemsDisplay = 0
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: DisableRegistryTools = 0
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: DisableTaskmgr = 0
O8 - Extra context menu item: Add to Vbuzzer RSS list - C:\Program Files\vbuzzer\addurl.htm ()
O8 - Extra context menu item: Append Link Target to Existing PDF - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll (Adobe Systems Incorporated)
O8 - Extra context menu item: Append to Existing PDF - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll (Adobe Systems Incorporated)
O8 - Extra context menu item: Convert Link Target to Adobe PDF - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll (Adobe Systems Incorporated)
O8 - Extra context menu item: Convert to Adobe PDF - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll (Adobe Systems Incorporated)
O8 - Extra context menu item: E&xport to Microsoft Excel - C:\Program Files\Microsoft Office\OFFICE11\EXCEL.EXE (Microsoft Corporation)
O9 - Extra Button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\Program Files\Microsoft Office\Office12\REFIEBAR.DLL (Microsoft Corporation)
O9 - Extra 'Tools' menuitem : Spybot - Search & Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll (Safer Networking Limited)
O9 - Extra 'Tools' menuitem : @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe (Microsoft Corporation)
O9 - Extra Button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe (Microsoft Corporation)
O9 - Extra 'Tools' menuitem : Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe (Microsoft Corporation)
O9 - Extra Button: Messenger - -{FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe (Microsoft Corporation)
O9 - Extra 'Tools' menuitem : Windows Messenger - -{FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe (Microsoft Corporation)
O9 - Extra Button: SmartWhois - {FD9DE2B4-C926-4460-81C4-FC58C6F1062E} - C:\Program Files\SmartWhois\swmsie.exe (TamoSoft)
O9 - Extra 'Tools' menuitem : SmartWhois - {FF983118-58C7-4AD4-B5A7-691C39CB7B42} - C:\Program Files\SmartWhois\swmsie.exe (TamoSoft)
O15 - HKLM\..Trusted Domains: 49 domain(s) and sub-domain(s) not assigned to a zone.
O15 - HKCU\..Trusted Domains: 49 domain(s) and sub-domain(s) not assigned to a zone.
O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} http://download.micr...heckControl.cab (Windows Genuine Advantage Validation Tool)
O16 - DPF: {2BC66F54-93A8-11D3-BEB6-00105AA9B6AE} http://security.syma...bin/AvSniff.cab (Symantec AntiVirus scanner)
O16 - DPF: {31435657-9980-0010-8000-00AA00389B71} http://download.micr...78f/wvc1dmo.cab (Reg Error: Key error.)
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} http://www.update.mi...b?1182302094468 (WUWebControl Class)
O16 - DPF: {644E432F-49D3-41A1-8DD5-E099162EEEC5} http://security.syma...n/bin/cabsa.cab (Symantec RuFSI Utility Class)
O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} http://www.update.mi...b?1182565904640 (MUWebControl Class)
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} http://java.sun.com/...indows-i586.cab (Java Plug-in 1.6.0_13)
O16 - DPF: {8FFBE65D-2C9C-4669-84BD-5829DC0B603C} http://fpdownload.ma...r/ultrashim.cab (Reg Error: Key error.)
O16 - DPF: {B1E2B96C-12FE-45E2-BEF1-44A219113CDD} http://www.superadbl...ivex/sabspx.cab (SABScanProcesses Class)
O16 - DPF: {CAFEEFAC-0016-0000-0007-ABCDEFFEDCBA} http://java.sun.com/...indows-i586.cab (Reg Error: Key error.)
O16 - DPF: {CAFEEFAC-0016-0000-0011-ABCDEFFEDCBA} Reg Error: Value error. (Reg Error: Key error.)
O16 - DPF: {CAFEEFAC-0016-0000-0013-ABCDEFFEDCBA} http://java.sun.com/...indows-i586.cab (Java Plug-in 1.6.0_13)
O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} http://java.sun.com/...indows-i586.cab (Java Plug-in 1.6.0_13)
O16 - DPF: {CCA0B877-CB5E-4ADC-AD30-457C379512DD} http://10.0.0.240/xplugLiteAL.cab (Gif89 Lite Class)
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} http://download.macr...ash/swflash.cab (Shockwave Flash Object)
O16 - DPF: {D4323BF2-006A-4440-A2F5-27E3E7AB25F8} http://a532.g.akamai...5/installer.exe (Virtools WebPlayer Class)
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 208.67.222.222 208.67.220.220 206.248.154.22
O18 - Protocol\Handler\http\0x00000001 {E1D2BF42-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files\Common Files\System\Ole DB\MSDAIPP.DLL (Microsoft Corporation)
O18 - Protocol\Handler\http\oledb {E1D2BF40-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files\Common Files\System\Ole DB\MSDAIPP.DLL (Microsoft Corporation)
O18 - Protocol\Handler\https\0x00000001 {E1D2BF42-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files\Common Files\System\Ole DB\MSDAIPP.DLL (Microsoft Corporation)
O18 - Protocol\Handler\https\oledb {E1D2BF40-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files\Common Files\System\Ole DB\MSDAIPP.DLL (Microsoft Corporation)
O18 - Protocol\Handler\ipp - No CLSID value found
O18 - Protocol\Handler\ipp\0x00000001 {E1D2BF42-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files\Common Files\System\Ole DB\MSDAIPP.DLL (Microsoft Corporation)
O18 - Protocol\Handler\linkscanner {F274614C-63F8-47D5-A4D1-FBDDE494F8D1} - C:\Program Files\AVG\AVG8\avgpp.dll (AVG Technologies CZ, s.r.o.)
O18 - Protocol\Handler\msdaipp - No CLSID value found
O18 - Protocol\Handler\msdaipp\0x00000001 {E1D2BF42-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files\Common Files\System\Ole DB\MSDAIPP.DLL (Microsoft Corporation)
O18 - Protocol\Handler\msdaipp\oledb {E1D2BF40-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files\Common Files\System\Ole DB\MSDAIPP.DLL (Microsoft Corporation)
O18 - Protocol\Handler\ms-help {314111c7-a502-11d2-bbca-00c04f8ec294} - C:\Program Files\Common Files\Microsoft Shared\Help\hxds.dll (Microsoft Corporation)
O18 - Protocol\Handler\mso-offdap {3D9F03FA-7A94-11D3-BE81-0050048385D1} - C:\Program Files\Common Files\Microsoft Shared\Web Components\10\OWC10.DLL (Microsoft Corporation)
O18 - Protocol\Handler\mso-offdap11 {32505114-5902-49B2-880A-1F7738E5A384} - C:\Program Files\Common Files\Microsoft Shared\Web Components\11\OWC11.DLL (Microsoft Corporation)
O18 - Protocol\Filter: - text/xml - C:\Program Files\Common Files\Microsoft Shared\OFFICE12\MSOXMLMF.DLL (Microsoft Corporation)
O20 - HKLM Winlogon: Shell - (Explorer.exe) - C:\WINDOWS\Explorer.exe (Microsoft Corporation)
O20 - Winlogon\Notify\AtiExtEvent: DllName - Ati2evxx.dll - C:\WINDOWS\System32\Ati2evxx.dll (ATI Technologies Inc.)
O20 - Winlogon\Notify\avgrsstarter: DllName - avgrsstx.dll - C:\WINDOWS\System32\avgrsstx.dll (AVG Technologies CZ, s.r.o.)
O24 - Desktop Components:0 (My Current Home Page) - About:Home
O28 - HKLM ShellExecuteHooks: {EDB0E980-90BD-11D4-8599-0008C7D3B6F8} - C:\Program Files\Qualcomm\Eudora\EuShlExt.dll (Qualcomm Inc.)
O30 - LSA: Authentication Packages - (relog_ap) - C:\WINDOWS\System32\relog_ap.dll (Acronis)
O31 - SafeBoot: AlternateShell - cmd.exe
O32 - HKLM CDRom: AutoRun - 1
O32 - AutoRun File - [2007/06/19 20:43:54 | 00,000,000 | ---- | M] () - C:\AUTOEXEC.BAT -- [ NTFS ]
O34 - HKLM BootExecute: (autocheck) - File not found
O34 - HKLM BootExecute: (autochk) - C:\WINDOWS\System32\autochk.exe (Microsoft Corporation)
O34 - HKLM BootExecute: (*) - File not found
O34 - HKLM BootExecute: (oodbs) - C:\WINDOWS\System32\oodbs.exe (O&O Software GmbH)
O34 - HKLM BootExecute: (lsdelete) - C:\WINDOWS\System32\lsdelete.exe ()

========== Files/Folders - Created Within 30 Days ==========

[1 C:\WINDOWS\*.tmp files]
[2009/07/05 07:26:26 | 00,000,000 | ---D | C] -- C:\Documents and Settings\Johnnie\My Documents\DVDFab
[2009/07/04 19:06:38 | 00,000,099 | ---- | C] () -- C:\Documents and Settings\Johnnie\Desktop\Info What is AGP aperture size and what should I set mine to - Overclock.net - Overclocking.net.URL
[2009/07/04 17:31:48 | 00,000,000 | ---D | C] -- C:\Rooter$
[2009/07/04 16:33:12 | 00,102,912 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\iecompat.dll
[2009/07/04 16:32:39 | 00,000,000 | ---D | C] -- C:\WINDOWS\ie8updates
[2009/07/04 16:32:06 | 00,012,800 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\xpshims.dll
[2009/07/04 16:32:05 | 00,246,272 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\ieproxy.dll
[2009/07/04 16:29:35 | 00,000,000 | -H-D | C] -- C:\WINDOWS\ie8
[2009/07/04 11:45:58 | 00,000,000 | ---D | C] -- C:\Documents and Settings\Johnnie\Application Data\Malwarebytes
[2009/07/04 11:45:52 | 00,038,160 | ---- | C] (Malwarebytes Corporation) -- C:\WINDOWS\System32\drivers\mbamswissarmy.sys
[2009/07/04 11:45:50 | 00,019,096 | ---- | C] (Malwarebytes Corporation) -- C:\WINDOWS\System32\drivers\mbam.sys
[2009/07/04 11:45:50 | 00,000,000 | ---D | C] -- C:\Program Files\Malwarebytes' Anti-Malware
[2009/07/04 11:45:50 | 00,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Application Data\Malwarebytes
[2009/07/04 11:43:36 | 00,000,000 | ---D | C] -- C:\WINDOWS\ERDNT
[2009/07/04 11:41:05 | 00,000,000 | ---D | C] -- C:\Program Files\ERUNT
[2009/07/03 23:23:48 | 00,000,000 | ---D | C] -- C:\WINDOWS\System32\LogFiles
[2009/07/03 21:49:40 | 00,000,752 | ---- | C] () -- C:\Documents and Settings\Johnnie\Desktop\SpywareBlaster.lnk
[2009/07/03 21:29:34 | 00,159,600 | ---- | C] (PC Tools) -- C:\WINDOWS\System32\drivers\pctgntdi.sys
[2009/07/03 21:29:16 | 00,130,936 | ---- | C] (PC Tools) -- C:\WINDOWS\System32\drivers\PCTCore.sys
[2009/07/03 21:29:16 | 00,073,840 | ---- | C] (PC Tools) -- C:\WINDOWS\System32\drivers\PCTAppEvent.sys
[2009/07/03 21:28:54 | 00,064,392 | ---- | C] (PC Tools) -- C:\WINDOWS\System32\drivers\pctplsg.sys
[2009/07/03 21:28:54 | 00,000,000 | ---D | C] -- C:\Program Files\Common Files\PC Tools
[2009/07/03 21:28:48 | 00,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Application Data\PC Tools
[2009/07/03 20:59:52 | 00,000,053 | ---- | C] () -- C:\Documents and Settings\Johnnie\Desktop\How To Videos on Wonder How To - Video Tutorials, DIY Lessons & Tips.URL
[2009/07/03 14:02:14 | 00,000,552 | ---- | C] () -- C:\Documents and Settings\Johnnie\Desktop\address.rtf
[2009/07/03 11:25:44 | 00,000,669 | ---- | C] () -- C:\Documents and Settings\Johnnie\Desktop\Shortcut to UnrealTournament.exe.lnk
[2009/07/02 20:24:47 | 00,000,000 | ---D | C] -- C:\Documents and Settings\Johnnie\Local Settings\Application Data\Thinstall
[2009/07/02 20:24:47 | 00,000,000 | ---D | C] -- C:\Documents and Settings\Johnnie\Application Data\Thinstall
[2009/07/02 11:51:34 | 00,048,640 | ---- | C] () -- C:\Documents and Settings\Johnnie\Desktop\Tibiet Cafe .doc
[2009/07/01 22:46:32 | 00,000,000 | ---D | C] -- C:\Documents and Settings\Johnnie\Desktop\Lynda.com - Photoshop One On One MASTERY with Deke McLelland
[2009/06/29 07:12:31 | 00,000,243 | ---- | C] () -- C:\Documents and Settings\Johnnie\Desktop\The Star.url
[2009/06/27 14:13:27 | 00,000,000 | ---D | C] -- C:\Documents and Settings\Johnnie\Desktop\09. Text
[2009/06/27 12:48:31 | 00,000,000 | ---D | C] -- C:\Documents and Settings\Johnnie\Desktop\08. App links
[2009/06/27 12:48:07 | 00,000,000 | ---D | C] -- C:\Documents and Settings\Johnnie\Desktop\07. PDF
[2009/06/27 12:47:22 | 00,000,000 | ---D | C] -- C:\Documents and Settings\Johnnie\Desktop\06. WORDPAD
[2009/06/27 12:46:48 | 00,000,000 | ---D | C] -- C:\Documents and Settings\Johnnie\Desktop\05. Word
[2009/06/27 12:46:07 | 00,000,000 | ---D | C] -- C:\Documents and Settings\Johnnie\Desktop\04.Excel
[2009/06/27 12:43:29 | 00,000,000 | ---D | C] -- C:\Documents and Settings\Johnnie\Desktop\03. WEB LINKS
[2009/06/27 12:42:53 | 00,000,000 | ---D | C] -- C:\Documents and Settings\Johnnie\Desktop\02. ICONS
[2009/06/27 12:40:16 | 00,000,000 | ---D | C] -- C:\Documents and Settings\Johnnie\Desktop\01. FOLDER
[2009/06/27 09:49:30 | 00,000,000 | R--D | C] -- C:\Documents and Settings\Johnnie\Desktop\PERSONAL
[2009/06/27 09:49:02 | 00,000,000 | ---D | C] -- C:\Documents and Settings\Johnnie\Desktop\FIX XP
[2009/06/27 09:48:40 | 00,000,000 | ---D | C] -- C:\Documents and Settings\Johnnie\Desktop\WORK
[2009/06/25 21:04:51 | 00,000,000 | ---D | C] -- C:\Documents and Settings\Johnnie\Desktop\My Invoices
[2009/06/25 12:54:56 | 00,000,000 | ---D | C] -- C:\Documents and Settings\Johnnie\Desktop\ALL pass and info from Chetan
[2009/06/24 10:43:58 | 00,000,000 | ---D | C] -- C:\Documents and Settings\Johnnie\Desktop\Posh new site demo
[2009/06/20 12:46:47 | 00,000,000 | ---D | C] -- C:\Documents and Settings\Johnnie\Local Settings\Application Data\ATI
[2009/06/20 12:46:47 | 00,000,000 | ---D | C] -- C:\Documents and Settings\Johnnie\Application Data\ATI
[2009/06/20 12:46:47 | 00,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Application Data\ATI
[2009/06/20 12:26:09 | 00,000,000 | ---D | C] -- C:\Program Files\ATI Technologies
[2009/06/20 12:24:14 | 00,000,000 | ---D | C] -- C:\ATI
[2009/06/20 12:18:44 | 00,000,000 | ---D | C] -- C:\Documents and Settings\Johnnie\Desktop\New ATI Driver and software
[2009/06/15 12:34:47 | 00,000,000 | ---D | C] -- C:\Documents and Settings\Johnnie\Desktop\VOIP Ebooks
[2009/06/15 12:08:54 | 00,000,000 | ---D | C] -- C:\Documents and Settings\Johnnie\Desktop\VICIDIAL
[2009/06/14 21:11:34 | 00,000,104 | ---- | C] () -- C:\Documents and Settings\Johnnie\Desktop\VICIDIAL - Google Search.URL
[2009/06/07 10:08:28 | 00,000,000 | ---D | C] -- C:\! VTC Assembly Language Programing
[2009/06/07 00:29:29 | 00,000,000 | ---D | C] -- C:\WINDOWS\Rarlab WinRAR v3.80
[2009/06/07 00:29:29 | 00,000,000 | ---D | C] -- C:\Program Files\Rarlab WinRAR v3.80
[2008/12/21 20:37:19 | 00,921,600 | ---- | C] () -- C:\WINDOWS\System32\vorbisenc.dll
[2008/12/21 20:37:19 | 00,237,568 | ---- | C] () -- C:\WINDOWS\System32\OggDS.dll
[2008/12/21 20:37:19 | 00,188,416 | ---- | C] () -- C:\WINDOWS\System32\vorbis.dll
[2008/12/21 20:37:19 | 00,045,056 | ---- | C] () -- C:\WINDOWS\System32\ogg.dll
[2008/07/19 19:02:50 | 00,120,200 | ---- | C] () -- C:\WINDOWS\System32\DLLDEV32i.dll
[2008/07/19 19:02:29 | 00,005,937 | ---- | C] () -- C:\WINDOWS\mgxoschk.ini
[2008/06/29 12:02:39 | 01,216,512 | ---- | C] () -- C:\WINDOWS\System32\xvidcore.dll
[2008/06/29 12:02:39 | 00,237,568 | ---- | C] () -- C:\WINDOWS\System32\xvidvfw.dll
[2008/05/26 11:35:35 | 00,000,089 | ---- | C] () -- C:\WINDOWS\wininit.ini
[2008/04/28 15:58:38 | 00,363,520 | ---- | C] () -- C:\WINDOWS\System32\psisdecd.dll
[2008/02/27 23:02:35 | 02,463,976 | ---- | C] () -- C:\WINDOWS\System32\NPSWF32.dll
[2007/12/27 10:37:10 | 00,176,235 | ---- | C] () -- C:\WINDOWS\System32\Primomonnt.dll
[2007/11/07 19:01:25 | 00,000,145 | ---- | C] () -- C:\WINDOWS\StarryNight.ini
[2007/10/17 09:42:49 | 00,000,754 | ---- | C] () -- C:\WINDOWS\WORDPAD.INI
[2007/10/16 17:24:40 | 00,034,308 | ---- | C] () -- C:\WINDOWS\System32\BASSMOD.dll
[2007/10/16 14:50:00 | 00,000,030 | ---- | C] () -- C:\WINDOWS\System32\brss01a.ini
[2007/10/16 14:49:46 | 00,002,189 | ---- | C] () -- C:\WINDOWS\BRMFBIDI.INI
[2007/10/16 14:49:36 | 00,000,267 | ---- | C] () -- C:\WINDOWS\Brpcfx.ini
[2007/10/16 14:49:30 | 00,000,419 | ---- | C] () -- C:\WINDOWS\brwmark.ini
[2007/10/16 14:49:30 | 00,000,079 | ---- | C] () -- C:\WINDOWS\BRPP2KA.INI
[2007/09/11 21:57:37 | 00,685,816 | ---- | C] () -- C:\WINDOWS\System32\drivers\sptd.sys
[2007/08/26 22:01:27 | 00,000,034 | ---- | C] () -- C:\WINDOWS\System32\oeminfo.ini
[2007/08/19 22:00:58 | 00,000,042 | ---- | C] () -- C:\WINDOWS\AlchemyMindworksUpdateList.INI
[2007/06/21 08:14:55 | 00,000,510 | ---- | C] () -- C:\WINDOWS\ODBC.INI
[2007/06/20 20:12:55 | 00,000,000 | ---- | C] () -- C:\WINDOWS\oodcnt.INI
[2007/06/20 10:35:31 | 00,000,044 | ---- | C] () -- C:\WINDOWS\System32\msssc.dll
[2007/06/20 10:24:09 | 00,002,781 | ---- | C] () -- C:\WINDOWS\Ascd_tmp.ini
[2007/06/20 10:24:07 | 00,005,824 | ---- | C] () -- C:\WINDOWS\System32\drivers\ASUSHWIO.SYS
[2006/11/06 18:49:36 | 00,000,310 | ---- | C] () -- C:\WINDOWS\primopdf.ini
[2004/08/04 08:00:00 | 00,000,622 | ---- | C] () -- C:\WINDOWS\win.ini
[2004/08/04 08:00:00 | 00,000,227 | ---- | C] () -- C:\WINDOWS\system.ini
[2003/01/07 15:05:08 | 00,002,695 | ---- | C] () -- C:\WINDOWS\System32\OUTLPERF.INI
[2002/03/19 17:30:00 | 00,141,824 | ---- | C] () -- C:\WINDOWS\System32\msvdm.dll
[2002/03/02 04:10:02 | 00,053,299 | ---- | C] () -- C:\WINDOWS\System32\pthreadVC.dll

========== Files - Modified Within 30 Days ==========

[1 C:\WINDOWS\*.tmp files]
[2009/07/05 07:50:00 | 00,012,796 | ---- | M] () -- C:\WINDOWS\System32\drivers\Avg\microavi.avg
[2009/07/05 07:49:59 | 37,774,500 | ---- | M] () -- C:\WINDOWS\System32\drivers\Avg\incavi.avm
[2009/07/04 21:40:58 | 00,002,206 | ---- | M] () -- C:\WINDOWS\System32\wpa.dbl
[2009/07/04 21:39:50 | 00,002,048 | --S- | M] () -- C:\WINDOWS\bootstat.dat
[2009/07/04 21:39:42 | 01,048,459 | ---- | M] () -- C:\WINDOWS\System32\oodbs.lor
[2009/07/04 21:31:49 | 02,737,920 | -H-- | M] () -- C:\Documents and Settings\Johnnie\Local Settings\Application Data\IconCache.db
[2009/07/04 19:06:38 | 00,000,099 | ---- | M] () -- C:\Documents and Settings\Johnnie\Desktop\Info What is AGP aperture size and what should I set mine to - Overclock.net - Overclocking.net.URL
[2009/07/04 16:39:27 | 00,000,063 | ---- | M] () -- C:\WINDOWS\vbaddin.ini
[2009/07/04 09:15:05 | 00,335,752 | ---- | M] (AVG Technologies CZ, s.r.o.) -- C:\WINDOWS\System32\drivers\avgldx86.sys
[2009/07/03 21:49:40 | 00,000,752 | ---- | M] () -- C:\Documents and Settings\Johnnie\Desktop\SpywareBlaster.lnk
[2009/07/03 21:27:03 | 00,525,946 | ---- | M] () -- C:\WINDOWS\System32\PerfStringBackup.INI
[2009/07/03 21:27:03 | 00,444,028 | ---- | M] () -- C:\WINDOWS\System32\perfh009.dat
[2009/07/03 21:27:03 | 00,071,904 | ---- | M] () -- C:\WINDOWS\System32\perfc009.dat
[2009/07/03 20:59:52 | 00,000,053 | ---- | M] () -- C:\Documents and Settings\Johnnie\Desktop\How To Videos on Wonder How To - Video Tutorials, DIY Lessons & Tips.URL
[2009/07/03 14:12:51 | 00,000,552 | ---- | M] () -- C:\Documents and Settings\Johnnie\Desktop\address.rtf
[2009/07/03 11:25:44 | 00,000,669 | ---- | M] () -- C:\Documents and Settings\Johnnie\Desktop\Shortcut to UnrealTournament.exe.lnk
[2009/07/02 21:20:45 | 00,015,688 | ---- | M] () -- C:\WINDOWS\System32\lsdelete.exe
[2009/07/02 21:20:29 | 00,064,160 | ---- | M] (Lavasoft AB) -- C:\WINDOWS\System32\drivers\Lbd.sys
[2009/07/02 13:20:56 | 00,048,640 | ---- | M] () -- C:\Documents and Settings\Johnnie\Desktop\Tibiet Cafe .doc
[2009/06/30 11:34:23 | 00,000,754 | ---- | M] () -- C:\WINDOWS\WORDPAD.INI
[2009/06/30 09:26:54 | 00,000,428 | ---- | M] () -- C:\Documents and Settings\Johnnie\Desktop\Shortcut to FTP.lnk
[2009/06/30 08:50:54 | 00,463,779 | ---- | M] () -- C:\WINDOWS\System32\drivers\Avg\miniavi.avg
[2009/06/29 08:56:16 | 00,011,952 | ---- | M] (AVG Technologies CZ, s.r.o.) -- C:\WINDOWS\System32\avgrsstx.dll
[2009/06/29 08:56:15 | 00,027,784 | ---- | M] (AVG Technologies CZ, s.r.o.) -- C:\WINDOWS\System32\drivers\avgmfx86.sys
[2009/06/27 09:52:15 | 00,205,824 | ---- | M] () -- C:\Documents and Settings\Johnnie\Local Settings\Application Data\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2009/06/17 11:27:56 | 00,038,160 | ---- | M] (Malwarebytes Corporation) -- C:\WINDOWS\System32\drivers\mbamswissarmy.sys
[2009/06/17 11:27:44 | 00,019,096 | ---- | M] (Malwarebytes Corporation) -- C:\WINDOWS\System32\drivers\mbam.sys
[2009/06/16 08:09:02 | 00,030,720 | ---- | M] () -- C:\Documents and Settings\Johnnie\My Documents\JohnFerguson.08t
[2009/06/16 08:07:47 | 00,000,243 | ---- | M] () -- C:\Documents and Settings\Johnnie\Desktop\The Star.url
[2009/06/15 17:39:27 | 00,000,237 | ---- | M] () -- C:\Documents and Settings\Johnnie\Desktop\Google.url
[2009/06/14 21:55:46 | 00,030,720 | ---- | M] () -- C:\Documents and Settings\Johnnie\My Documents\JohnFerguson.08t.backup
[2009/06/14 21:11:34 | 00,000,104 | ---- | M] () -- C:\Documents and Settings\Johnnie\Desktop\VICIDIAL - Google Search.URL
[2009/06/13 18:36:44 | 00,000,622 | ---- | M] () -- C:\WINDOWS\win.ini
[2009/06/13 05:47:34 | 01,498,808 | ---- | M] () -- C:\WINDOWS\System32\FNTCACHE.DAT

========== Alternate Data Streams ==========

@Alternate Data Stream - 164 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:DFC5A2B2
@Alternate Data Stream - 125 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:5C321E34
@Alternate Data Stream - 117 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:C8B8CEBD
< End of report >


================OTL Extras logfile created on: 05/07/2009 9:20:06 AM - Run 1
OTL by OldTimer - Version 3.0.6.4 Folder = C:\Documents and Settings\Johnnie\Desktop\Maintence\GEEKS to GO\! ! Malware Tools
Windows XP Professional Edition Service Pack 3 (Version = 5.1.2600) - Type = NTWorkstation
Internet Explorer (Version = 8.0.6001.18702)
Locale: 00001009 | Country: Canada | Language: ENC | Date Format: dd/MM/yyyy

2.00 Gb Total Physical Memory | 2.00 Gb Available Physical Memory | 99.87% Memory free
4.00 Gb Paging File | 4.00 Gb Available in Paging File | 100.00% Paging File free
Paging file location(s): C:\pagefile.sys 3000 4000 [binary data]

%SystemDrive% = C: | %SystemRoot% = C:\WINDOWS | %ProgramFiles% = C:\Program Files
Drive C: | 95.36 Gb Total Space | 36.02 Gb Free Space | 37.77% Space Free | Partition Type: NTFS
Drive D: | 370.40 Gb Total Space | 157.69 Gb Free Space | 42.57% Space Free | Partition Type: NTFS
Drive E: | 465.76 Gb Total Space | 0.63 Gb Free Space | 0.14% Space Free | Partition Type: NTFS
Drive F: | 1.86 Gb Total Space | 1.84 Gb Free Space | 98.54% Space Free | Partition Type: FAT
G: Drive not present or media not loaded
H: Drive not present or media not loaded
I: Drive not present or media not loaded

Computer Name: LIVINGROOM
Current User Name: Johnnie
Logged in as Administrator.

Current Boot Mode: Normal
Scan Mode: Current user
Company Name Whitelist: Off
Skip Microsoft Files: Off
File Age = 30 Days
Output = Minimal

========== Extra Registry (SafeList) ==========


========== File Associations ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\<extension>]
.html [@ = htmlfile] -- C:\Program Files\Internet Explorer\IEXPLORE.EXE (Microsoft Corporation)

[HKEY_CURRENT_USER\SOFTWARE\Classes\<extension>]
.html [@ = FirefoxHTML] -- C:\Program Files\Mozilla Firefox\firefox.exe (Mozilla Corporation)

========== Security Center Settings ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center]
"FirstRunDisabled" = 1
"AntiVirusDisableNotify" = 0
"FirewallDisableNotify" = 0
"UpdatesDisableNotify" = 0
"AntiVirusOverride" = 0
"FirewallOverride" = 1

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\AhnlabAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\ComputerAssociatesAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\KasperskyAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\McAfeeAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\McAfeeFirewall]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\PandaAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\PandaFirewall]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\SophosAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\SymantecAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\SymantecFirewall]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\TinyFirewall]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\TrendAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\TrendFirewall]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\ZoneLabsFirewall]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile\GloballyOpenPorts\List]
"3389:TCP" = 3389:TCP:*:Disabled:@xpsp2res.dll,-22009
"139:TCP" = 139:TCP:*:Enabled:@xpsp2res.dll,-22004
"445:TCP" = 445:TCP:*:Enabled:@xpsp2res.dll,-22005
"137:UDP" = 137:UDP:*:Enabled:@xpsp2res.dll,-22001
"138:UDP" = 138:UDP:*:Enabled:@xpsp2res.dll,-22002

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile]
"EnableFirewall" = 0
"DisableNotifications" = 0

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\GloballyOpenPorts\List]
"1900:UDP" = 1900:UDP:LocalSubNet:Enabled:@xpsp2res.dll,-22007
"2869:TCP" = 2869:TCP:LocalSubNet:Enabled:@xpsp2res.dll,-22008
"3389:TCP" = 3389:TCP:*:Disabled:@xpsp2res.dll,-22009
"139:TCP" = 139:TCP:LocalSubNet:Enabled:@xpsp2res.dll,-22004
"445:TCP" = 445:TCP:LocalSubNet:Enabled:@xpsp2res.dll,-22005
"137:UDP" = 137:UDP:LocalSubNet:Enabled:@xpsp2res.dll,-22001
"138:UDP" = 138:UDP:LocalSubNet:Enabled:@xpsp2res.dll,-22002

========== Authorized Applications List ==========

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile\AuthorizedApplications\List]
%windir%\Network Diagnostic\xpnetdiag.exe:*:Enabled:@xpsp3res.dll,-20000 (Microsoft Corporation)

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\AuthorizedApplications\List]
C:\Program Files\VoipStunt.com\VoipStunt\voipstunt.exe:*:Enabled:VoipStunt (VoipStunt)
C:\Program Files\BitTorrent\bittorrent.exe:*:Enabled:BitTorrent File not found
C:\Program Files\BitTorrent_DNA\dna.exe:*:Enabled:BitTorrent DNA File not found
C:\Program Files\SmartWhois\sw.exe:*:Enabled:SmartWhois (TamoSoft)
C:\Program Files\Bonjour\mDNSResponder.exe:*:Enabled:Bonjour File not found
%windir%\Network Diagnostic\xpnetdiag.exe:*:Enabled:@xpsp3res.dll,-20000 (Microsoft Corporation)
C:\Program Files\vbuzzer\VBuzzer.exe:*:Enabled:VBuzzer Messenger (Softroute Corporation)
C:\Program Files\AVG\AVG8\avgupd.exe:*:Enabled:avgupd.exe (AVG Technologies CZ, s.r.o.)
C:\Program Files\uTorrent\uTorrent.exe:*:Enabled:µTorrent (BitTorrent, Inc.)
C:\Program Files\Skype\Phone\Skype.exe:*:Enabled:Skype File not found


========== HKEY_LOCAL_MACHINE Uninstall List ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"{00203668-8170-44A0-BE44-B632FA4D780F}" = Adobe AIR
"{055EE59D-217B-43A7-ABFF-507B966405D8}" = ATI Catalyst Control Center
"{08094E03-AFE4-4853-9D31-6D0743DF5328}" = QuickTime
"{0AB76F69-E761-4CFA-B9B0-A1906B4E9E4B}" = WD Diagnostics
"{10CE1EA2-12E9-11D3-825E-00C04F6843FE}" = Microsoft Office Sounds
"{20585CDC-114E-4372-986A-0686B1A37A30}" = Business Plan Pro 2007
"{2300EE96-0A41-4FAB-BD03-989EC44577A0}" = Acronis Disk Director Suite
"{263CB4CF-8EC8-4FD0-99CD-3741657CDC4F}" = Microsoft Date and Phone XML Smart Tags
"{26A24AE4-039D-4CA4-87B4-2F83216011FF}" = Java™ 6 Update 13
"{27E9B845-5E9B-41CE-8C50-7F6BDC019308}" = Microsoft Captions Language Interface Pack
"{29622F4A-245C-4126-8764-897E21E888D1}" = Google Earth Pro
"{2D456CE5-01E4-4DBE-9797-77003A7C8271}" = Microsoft® Measurement Smart Tag Converter
"{3248F0A8-6813-11D6-A77B-00B0D0150000}" = J2SE Runtime Environment 5.0
"{3248F0A8-6813-11D6-A77B-00B0D0160060}" = Java™ 6 Update 6
"{3248F0A8-6813-11D6-A77B-00B0D0160070}" = Java™ 6 Update 7
"{3294DF7D-9A5B-443E-85D3-A00486AA0A92}" = DGE-530T
"{350C97B0-3D7C-4EE8-BAA9-00BCB3D54227}" = WebFldrs XP
"{36B98FCD-557C-48B0-98B8-60F8435D8492}" = Microsoft Office Word 2003 Redaction Add-in
"{388E4B09-3E71-4649-8921-F44A3A2954A7}" = Microsoft Visual Studio 2005 Tools for Office Runtime
"{4324BC93-C82F-ED16-BA86-5E34B9E05303}" = ccc-core-static
"{45EA11B5-874D-480E-89B9-2545505BBE3E}" = Microsoft OpenType Font File Properties Extension
"{4C4FC279-588A-46C9-88AA-1D62876F5F61}" = Microsoft Convert Number Smart Tag
"{4ED118EE-785C-CC18-5D2E-D5CA4BAA03F0}" = Catalyst Control Center Graphics Full New
"{53480330-E1D1-41CA-B8F8-7F78644F7F50}" = O&O Defrag Professional Edition
"{539475B7-44B7-8B0A-134C-F01B9C8B7569}" = ccc-core-preinstall
"{545E0CDC-4373-4315-9553-BA1025AF9D06}" = XML4
"{5AC7AE54-55DF-1126-076C-623F008D40B6}" = Catalyst Control Center Graphics Full Existing
"{633A06C3-B709-479A-AAB3-5EE94AD9EE4B}" = Acronis True Image Home
"{6351D217-3EE3-1967-29BE-6A77635FE485}" = Skins
"{66A9D30D-1464-4C7F-B2F3-507DADAF2595}" = Microsoft IntelliPoint 6.3
"{6855CCDD-BDF9-48E4-B80A-80DFB96FE36C}" = CmdHere Powertoy For Windows XP
"{6AB9CD3A-F91F-233B-923B-6C59BA63524D}" = Catalyst Control Center HydraVision Full
"{6BE2A4A4-99FB-48ED-AE1E-4E850389F804}" = PartitionMagic
"{6EECB283-E65F-40EF-86D3-D51BF02A8D43}" = Microsoft Office Converter Pack
"{7299052b-02a4-4627-81f2-1818da5d550d}" = Microsoft Visual C++ 2005 Redistributable
"{76C24F39-B161-498F-BD8B-C64789812D13}_is1" = ConvertXtoDVD 3.3.0.96
"{77DCDCE3-2DED-62F3-8154-05E745472D07}" = Acrobat.com
"{7E819CE5-2C41-4C8D-BAF0-B49CC65C5562}" = Norton Security Scan
"{8436DD2B-CED5-4B88-992C-25E2D24172FE}" = Microsoft Captions Language Interface Culture Pack (Alsace)
"{84F1DAC1-E1BF-4A21-9D2B-DD3E12686A2C}" = Read in Microsoft Reader Add-in for Microsoft Word
"{85A91C22-C369-FCFB-5F1F-D59EB21AD0E1}" = CCC Help English
"{885744A4-1A01-44B0-858A-0AE6738CBCF7}" = PrimoPDF Redistribution Package
"{89F4137D-6C26-4A84-BDB8-2E5A4BB71E00}" = Microsoft Silverlight
"{8DB2C22D-A23A-4C0E-9A56-7D10440B9B40}" = Microsoft Office Outlook 2003 Calendar Views Add-in
"{8F3C31C5-9C3A-4AA8-8EFA-71290A7AD533}" = TomTom HOME Visual Studio Merge Modules
"{90110409-6000-11D3-8CFE-0150048383C9}" = Microsoft Office Professional Edition 2003
"{90120000-0010-0409-0000-0000000FF1CE}" = Microsoft Software Update for Web Folders (English) 12
"{90120000-001F-0409-0000-0000000FF1CE}" = Microsoft Office Proof (English) 2007
"{90120000-001F-0409-0000-0000000FF1CE}_VISPRO_{ABDDE972-355B-4AF1-89A8-DA50B7B5C045}" = Microsoft Office Proofing Tools 2007 Service Pack 2 (SP2)
"{90120000-001F-040C-0000-0000000FF1CE}" = Microsoft Office Proof (French) 2007
"{90120000-001F-040C-0000-0000000FF1CE}_VISPRO_{F580DDD5-8D37-4998-968E-EBB76BB86787}" = Microsoft Office Proofing Tools 2007 Service Pack 2 (SP2)
"{90120000-001F-0C0A-0000-0000000FF1CE}" = Microsoft Office Proof (Spanish) 2007
"{90120000-001F-0C0A-0000-0000000FF1CE}_VISPRO_{187308AB-5FA7-4F14-9AB9-D290383A10D9}" = Microsoft Office Proofing Tools 2007 Service Pack 2 (SP2)
"{90120000-0020-0409-0000-0000000FF1CE}" = Compatibility Pack for the 2007 Office system
"{90120000-002C-0409-0000-0000000FF1CE}" = Microsoft Office Proofing (English) 2007
"{90120000-0051-0000-0000-0000000FF1CE}" = Microsoft Office Visio Professional 2007
"{90120000-0051-0000-0000-0000000FF1CE}_VISPRO_{0FD405D3-CAF8-4CA6-8BFD-911D2F8A6585}" = Microsoft Office Visio 2007 Service Pack 2 (SP2)
"{90120000-0054-0409-0000-0000000FF1CE}" = Microsoft Office Visio MUI (English) 2007
"{90120000-0054-0409-0000-0000000FF1CE}_VISPRO_{519D9F45-CBF4-4E57-B419-11F196CCA8AE}" = Microsoft Office Visio 2007 Service Pack 2 (SP2)
"{90120000-006E-0409-0000-0000000FF1CE}" = Microsoft Office Shared MUI (English) 2007
"{90120000-006E-0409-0000-0000000FF1CE}_VISPRO_{DE5A002D-8122-4278-A7EE-3121E7EA254E}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{90120000-0115-0409-0000-0000000FF1CE}" = Microsoft Office Shared Setup Metadata MUI (English) 2007
"{90120000-0115-0409-0000-0000000FF1CE}_VISPRO_{DE5A002D-8122-4278-A7EE-3121E7EA254E}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{905D0409-6000-11D3-8CFE-0150048383C9}" = Microsoft Office Visio IFilter 2003
"{90AF0409-6000-11D3-8CFE-0150048383C9}" = Microsoft Office PowerPoint Viewer 2003
"{90F80409-6000-11D3-8CFE-0150048383C9}" = Remove Hidden Data Tool
"{95120000-00B9-0409-0000-0000000FF1CE}" = Microsoft Application Error Reporting
"{98613C99-1399-416C-A07C-1EE1C585D872}" = SeaTools for Windows
"{A3051CD0-2F64-3813-A88D-B8DCCDE8F8C7}" = Microsoft .NET Framework 3.0 Service Pack 2
"{A6D0140F-E62F-9D1E-2408-9CFF91FF6FC8}" = ccc-utility
"{A99C1048-A569-4B65-A3DD-3584B0A4AA69}" = Microsoft MSN MoneyCentral Stock Quotes Add-In for Excel
"{AAF80000-22B9-4CE9-98D6-2CCF359BAC07}" = ABBYY FineReader 8.0 Professional Edition
"{AC76BA86-1033-F400-7760-000000000004}" = Adobe Acrobat 9 Pro - English, Français, Deutsch
"{AC76BA86-1033-F400-7760-000000000004}{AC76BA86-1033-F400-7760-000000000004}" = Adobe Acrobat 9 Pro - English, Français, Deutsch
"{AC76BA86-7AD7-1033-7B44-A91000000001}" = Adobe Reader 9.1
"{AC76BA86-7AD7-5464-3428-900000000004}" = Spelling Dictionaries Support For Adobe Reader 9
"{ADFBC522-0E15-4E35-B932-8CE2EE0DDEA3}" = Microsoft Office 2003 Desktop Language Settings
"{B4092C6D-E886-4CB2-BA68-FE5A88D31DE6}_is1" = Spybot - Search & Destroy
"{B6828215-1469-43A2-8BEE-F5A970F98161}" = Microsoft Office 2003 International Character Toolbar
"{B87ED12E-A95F-45AC-89E7-02CFD5BD2353}" = StudioTax 2008
"{BAF78226-3200-4DB4-BE33-4D922A799840}" = Windows Presentation Foundation
"{BD63976C-1EB5-4D85-8070-79506818C9C8}" = Microsoft® Stock Actions for the Research Task Pane
"{C09FB3CD-3D0C-3F2D-899A-6A1D67F2073F}" = Microsoft .NET Framework 2.0 Service Pack 2
"{C44A7422-E380-44BE-79FE-1C032D8A03A7}" = Catalyst Control Center Core Implementation
"{C63E7C60-25EB-11D3-8EDA-00A0C911E8E5}" = Microsoft Outlook Personal Folders Backup
"{CB2F7EDD-9D1F-43C1-90FC-4F52EAE172A1}" = Microsoft .NET Framework 1.1
"{CD95F661-A5C4-44F5-A6AA-ECDD91C240B6}" = WinZip 11.2
"{CE2CDD62-0124-36CA-84D3-9F4DCF5C5BD9}" = Microsoft .NET Framework 3.5 SP1
"{D3B1C799-CB73-42DE-BA0F-2344793A095C}" = Catalyst Control Center - Branding
"{DED53B0B-B67C-4244-AE6A-D6FD3C28D1EF}" = Ad-Aware
"{E5D24929-91A4-B0A1-DE00-AFC453921EF7}" = Catalyst Control Center Graphics Light
"{E6C09BFB-BA75-15C7-5B18-A2CE31C4F42B}" = Catalyst Control Center Graphics Previews Common
"{F0A37341-D692-11D4-A984-009027EC0A9C}" = SoundMAX
"{F251B999-08A9-4704-999C-9962F0DFD88E}" = Virtual Desktop Manager Powertoy for Windows XP
"{F333A33D-125C-32A2-8DCE-5C5D14231E27}" = Visual C++ 2008 x86 Runtime - (v9.0.30729)
"{F333A33D-125C-32A2-8DCE-5C5D14231E27}.vc_x86runtime_30729_01" = Visual C++ 2008 x86 Runtime - v9.0.30729.01
"{FF77941A-2BFA-4A18-BE2E-69B9498E4D55}" = User Profile Hive Cleanup Service
"Ad-Aware" = Ad-Aware
"Adobe AIR" = Adobe AIR
"Adobe Flash Player ActiveX" = Adobe Flash Player 10 ActiveX
"Adobe Flash Player Plugin" = Adobe Flash Player 10 Plugin
"Advanced IP Scanner v1.5" = Advanced IP Scanner v1.5
"All ATI Software" = ATI - Software Uninstall Utility
"AnyDVD" = AnyDVD
"Ashampoo Burning Studio 2008_is1" = Ashampoo Burning Studio 2008
"Ashampoo WinOptimizer 4_is1" = Ashampoo WinOptimizer 4.40
"ATI Display Driver" = ATI Display Driver
"AVG8Uninstall" = AVG Free 8.5
"AVS Video Tools 5.1_is1" = AVS Video Tools 5.1
"AVSDiscCreator_is1" = AVS Disc Creator version 2.1
"CCleaner" = CCleaner (remove only)
"com.adobe.mauby.4875E02D9FB21EE389F73B8D1702B320485DF8CE.1" = Acrobat.com
"CPUID CPU-Z_is1" = CPUID CPU-Z 1.51
"Defraggler" = Defraggler (remove only)
"Dexpot" = Dexpot
"Driver Genius Professional Edition_is1" = Driver Genius Professional Edition
"DVDFab Platinum_is1" = DVDFab Platinum 3.2.1.0
"dvdSanta 4.50 - Make your own DVD movies!_is1" = dvdSanta 4.50
"ERUNT_is1" = ERUNT 1.1j
"GrabIt_is1" = GrabIt 1.7.2 Beta 4 (build 997)
"HijackThis" = HijackThis 2.0.2
"IDNMitigationAPIs" = Microsoft Internationalized Domain Names Mitigation APIs
"ie8" = Windows Internet Explorer 8
"InstallShield_{3294DF7D-9A5B-443E-85D3-A00486AA0A92}" = DGE-530T
"InstallShield_{6BE2A4A4-99FB-48ED-AE1E-4E850389F804}" = PowerQuest PartitionMagic 8.0
"IrfanView" = IrfanView (remove only)
"MailBell" = MailBell
"Malwarebytes' Anti-Malware_is1" = Malwarebytes' Anti-Malware
"Marvell Miniport Driver" = Marvell Miniport Driver
"MasterSplitter" = MasterSplitter Program
"Microsoft .NET Framework 1.1 (1033)" = Microsoft .NET Framework 1.1
"Microsoft .NET Framework 3.5 SP1" = Microsoft .NET Framework 3.5 SP1
"Microsoft Visual Studio 2005 Tools for Office Runtime" = Visual Studio 2005 Tools for Office Second Edition Runtime
"Mozilla Firefox (3.0.11)" = Mozilla Firefox (3.0.11)
"MPEG Video Wizard DVD" = MPEG Video Wizard DVD 4.0.4.108 (03/2008)
"NetTools_is1" = NetTools 5.0
"NewzToolz_is1" = NewzToolz v2.0.2
"NLSDownlevelMapping" = Microsoft National Language Support Downlevel APIs
"NSSSetup.{7E819CE5-2C41-4C8D-BAF0-B49CC65C5562}" = Norton Security Scan (Symantec Corporation)
"PC Wizard 2008_is1" = PC Wizard 2008.1.82
"QuickPar" = QuickPar 0.9
"Recuva" = Recuva (remove only)
"Samsung ML-2010 Series" = Samsung ML-2010 Series
"SereneScreen Marine Aquarium 2_is1" = SereneScreen Marine Aquarium 2
"SmartWhois" = SmartWhois
"Spyware Doctor" = Spyware Doctor 6.0
"SpywareBlaster_is1" = SpywareBlaster 4.2
"Starry Night Pro 5" = Starry Night Pro 5
"TeamViewer 3" = TeamViewer 3
"TomTom HOME" = TomTom HOME 2.6.4.1641
"Uplink" = Uplink Skype2Sip Uninstall
"Vbuzzer" = Vbuzzer Messenger
"VISPRO" = Microsoft Office Visio Professional 2007
"VLC media player" = VLC media player 0.9.4
"VoipStunt_is1" = VoipStunt
"WIC" = Windows Imaging Component
"Windows XP Service Pack" = Windows XP Service Pack 3
"WinPcapInst" = WinPcap 3.0
"WinRAR archiver" = WinRAR archiver
"WMV9_VCM" = Microsoft Windows Media Video 9 VCM
"XpsEPSC" = XML Paper Specification Shared Components Pack 1.0

========== HKEY_CURRENT_USER Uninstall List ==========

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"Pikto ROES" = Pikto ROES
"uTorrent" = µTorrent

========== Last 10 Event Log Errors ==========

[ Application Events ]
Error - 24/06/2009 11:07:42 AM | Computer Name = LIVINGROOM | Source = Microsoft Office 11 | ID = 1000
Description = Faulting application outlook.exe, version 11.0.8217.0, stamp 480f95d9,
faulting module kernel32.dll, version 5.1.2600.5781, stamp 49c4f482, debug? 0,
fault address 0x0000980f.

Error - 24/06/2009 8:07:29 PM | Computer Name = LIVINGROOM | Source = Defrag | ID = 131078
Description = Not enough space on volume D: (NTFS). COMPLETE/Modified defragmentation
has been aborted.

Error - 25/06/2009 1:01:04 AM | Computer Name = LIVINGROOM | Source = Defrag | ID = 131078
Description = Not enough space on volume E: (NTFS). COMPLETE/Modified defragmentation
has been aborted.

Error - 29/06/2009 9:18:51 AM | Computer Name = LIVINGROOM | Source = Outlook Calendar Views | ID = 0
Description = Object reference not set to an instance of an object.... at OCV.Connect.Explorers_NewExplorer(Explorer
Explorer) at OCV.Connect.OnConnection(Object application, ext_ConnectMode connectMode,
Object addInInst, Array& custom)

Error - 29/06/2009 9:19:09 AM | Computer Name = LIVINGROOM | Source = Outlook Calendar Views | ID = 0
Description = Object reference not set to an instance of an object.... at OCV.Connect.Explorers_NewExplorer(Explorer
Explorer) at OCV.Connect.OnConnection(Object application, ext_ConnectMode connectMode,
Object addInInst, Array& custom)

Error - 30/06/2009 5:53:48 PM | Computer Name = LIVINGROOM | Source = Application Error | ID = 1000
Description = Faulting application firefox.exe, version 1.9.0.3439, faulting module
xul.dll, version 1.9.0.3439, fault address 0x00093691.

Error - 03/07/2009 4:57:59 AM | Computer Name = LIVINGROOM | Source = crypt32 | ID = 131083
Description = Failed extract of third-party root list from auto update cab at: <http://www.download....uthrootstl.cab>
with error: A required certificate is not within its validity period when verifying
against the current system clock or the timestamp in the signed file.

Error - 03/07/2009 4:57:59 AM | Computer Name = LIVINGROOM | Source = crypt32 | ID = 131083
Description = Failed extract of third-party root list from auto update cab at: <http://www.download....uthrootstl.cab>
with error: A required certificate is not within its validity period when verifying
against the current system clock or the timestamp in the signed file.

Error - 05/07/2009 7:19:53 AM | Computer Name = LIVINGROOM | Source = Microsoft Office 11 | ID = 2001
Description = Rejected Safe Mode action : Microsoft Office Outlook.

Error - 05/07/2009 9:00:49 AM | Computer Name = LIVINGROOM | Source = Application Error | ID = 1000
Description = Faulting application firefox.exe, version 1.9.0.3439, faulting module
msvcr80.dll, version 8.0.50727.3053, fault address 0x0001500a.

[ System Events ]
Error - 28/06/2009 11:10:58 AM | Computer Name = LIVINGROOM | Source = Service Control Manager | ID = 7000
Description = The TLRecAgent service failed to start due to the following error:
%%2

Error - 28/06/2009 11:53:27 AM | Computer Name = LIVINGROOM | Source = Service Control Manager | ID = 7000
Description = The TLRecAgent service failed to start due to the following error:
%%2

Error - 28/06/2009 12:03:12 PM | Computer Name = LIVINGROOM | Source = Service Control Manager | ID = 7000
Description = The TLRecAgent service failed to start due to the following error:
%%2

Error - 28/06/2009 12:30:10 PM | Computer Name = LIVINGROOM | Source = Service Control Manager | ID = 7000
Description = The TLRecAgent service failed to start due to the following error:
%%2

Error - 03/07/2009 9:11:43 AM | Computer Name = LIVINGROOM | Source = Service Control Manager | ID = 7034
Description = The sopidkc Service service terminated unexpectedly. It has done
this 1 time(s).

Error - 03/07/2009 8:58:29 PM | Computer Name = LIVINGROOM | Source = Service Control Manager | ID = 7034
Description = The sopidkc Service service terminated unexpectedly. It has done
this 1 time(s).

Error - 04/07/2009 12:05:15 PM | Computer Name = LIVINGROOM | Source = sr | ID = 1
Description = The System Restore filter encountered the unexpected error '0xC0000001'
while processing the file '' on the volume 'HarddiskVolume2'. It has stopped monitoring
the volume.

Error - 04/07/2009 12:05:28 PM | Computer Name = LIVINGROOM | Source = Service Control Manager | ID = 7026
Description = The following boot-start or system-start driver(s) failed to load:
PCIIde

Error - 04/07/2009 12:15:26 PM | Computer Name = LIVINGROOM | Source = sr | ID = 1
Description = The System Restore filter encountered the unexpected error '0xC0000001'
while processing the file '' on the volume 'HarddiskVolume2'. It has stopped monitoring
the volume.

Error - 04/07/2009 12:15:56 PM | Computer Name = LIVINGROOM | Source = Service Control Manager | ID = 7026
Description = The following boot-start or system-start driver(s) failed to load:
PCIIde


< End of report >
  • 0

Advertisements


#2
andrewuk

andrewuk

    Trusted Helper

  • Malware Removal
  • 5,297 posts
Hello JohnnieF

welcome to geekstogo :) and sorry to keep you waiting.

We will begin with ComboFix.exe. Please visit this webpage for download links, and instructions for running the tool:

http://www.bleepingc...to-use-combofix

* Ensure you have disabled all anti virus and anti malware programs so they do not interfere with the running of ComboFix.

Please include the C:\ComboFix.txt in your next reply for further review.


also:

We will run OTL , but go for a shortened log.
  • Close all windows and open it by double clicking on the icon
  • we are targetting a selective output, hence:
    • on the left hand side, in the box titled "Processes" select none
    • on the left hand side, in the box titled "Drivers" select none
    • on the left hand side, in the box titled "Extra Registry" select none
    • on the right hand side, in the box titled "Files created within" select none
    • on the right hand side, in the box titled "Files modified within" select none
    • tick both the boxes marked Purity check and Lop check
  • Click Run Scan and let the program run uninterrupted
  • It will produce one log for you called OTL.txt. Please post both that log here in reply.
  • You may need to use two posts to get it all on the forum

andrewuk
  • 0

#3
JohnnieF

JohnnieF

    Member

  • Topic Starter
  • Member
  • PipPip
  • 32 posts

Hello JohnnieF

welcome to geekstogo :) and sorry to keep you waiting.

We will begin with ComboFix.exe. Please visit this webpage for download links, and instructions for running the tool:

http://www.bleepingc...to-use-combofix

* Ensure you have disabled all anti virus and anti malware programs so they do not interfere with the running of ComboFix.

Please include the C:\ComboFix.txt in your next reply for further review.


also:

We will run OTL , but go for a shortened log.

  • Close all windows and open it by double clicking on the icon
  • we are targetting a selective output, hence:
    • on the left hand side, in the box titled "Processes" select none
    • on the left hand side, in the box titled "Drivers" select none
    • on the left hand side, in the box titled "Extra Registry" select none
    • on the right hand side, in the box titled "Files created within" select none
    • on the right hand side, in the box titled "Files modified within" select none
    • tick both the boxes marked Purity check and Lop check
  • Click Run Scan and let the program run uninterrupted
  • It will produce one log for you called OTL.txt. Please post both that log here in reply.
  • You may need to use two posts to get it all on the forum

andrewuk


Thanks for your help.

***********ComboFix.txt************
ComboFix 09-07-09.08 - Johnnie 11/07/2009 23:06.1.2 - NTFSx86
Microsoft Windows XP Professional 5.1.2600.3.1252.1.1033.18.2814.2215 [GMT -4:00]
Running from: c:\! !down 3\ComboFix.exe
AV: AVG Anti-Virus Free *On-access scanning disabled* (Updated) {17DDD097-36FF-435F-9E1B-52D74245D6BF}
.

((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.

c:\documents and settings\Johnnie\Application Data\inst.exe
c:\program files\WinPCap
c:\program files\WinPCap\daemon_mgm.exe
c:\program files\WinPCap\INSTALL.LOG
c:\program files\WinPCap\npf_mgm.exe
c:\program files\WinPCap\rpcapd.exe
c:\program files\WinPCap\Uninstall.exe
c:\windows\Install.txt
c:\windows\Installer\1a724e.msp
c:\windows\Installer\1edb826.msp
c:\windows\Installer\296d6.msi
c:\windows\Installer\299b25d.msi
c:\windows\Installer\2f2f25f.msi
c:\windows\Installer\2f2f260.msp
c:\windows\Installer\f77082f.msi
c:\windows\system32\drivers\npf.sys
c:\windows\system32\Packet.dll
c:\windows\system32\pthreadVC.dll
c:\windows\system32\wpcap.dll

.
((((((((((((((((((((((((((((((((((((((( Drivers/Services )))))))))))))))))))))))))))))))))))))))))))))))))
.

-------\Service_NPF


((((((((((((((((((((((((( Files Created from 2009-06-12 to 2009-07-12 )))))))))))))))))))))))))))))))
.

2009-07-10 13:13 . 2009-07-04 13:15 2054424 ----a-w- c:\documents and settings\All Users\Application Data\avg8\update\backup\avgcorex.dll
2009-07-10 13:13 . 2009-07-04 13:14 2167576 ----a-w- c:\documents and settings\All Users\Application Data\avg8\update\backup\avgresf.dll
2009-07-06 13:39 . 2009-07-12 03:15 117760 ----a-w- c:\documents and settings\Johnnie\Application Data\SUPERAntiSpyware.com\SUPERAntiSpyware\SDDLLS\UIREPAIR.DLL
2009-07-04 23:00 . 2009-07-04 23:00 -------- d-sh--w- c:\documents and settings\LocalService\IETldCache
2009-07-04 21:31 . 2009-07-04 22:15 -------- d-----w- C:\Rooter$
2009-07-04 20:48 . 2009-07-04 20:48 -------- d-sh--w- c:\documents and settings\Johnnie\PrivacIE
2009-07-04 20:45 . 2009-07-04 20:45 -------- d-sh--w- c:\documents and settings\NetworkService\IETldCache
2009-07-04 20:44 . 2009-07-04 20:44 -------- d-sh--w- c:\documents and settings\Johnnie\IETldCache
2009-07-04 20:33 . 2009-06-02 10:12 102912 -c----w- c:\windows\system32\dllcache\iecompat.dll
2009-07-04 20:32 . 2009-07-04 20:33 -------- d-----w- c:\windows\ie8updates
2009-07-04 20:32 . 2009-04-30 21:22 12800 -c----w- c:\windows\system32\dllcache\xpshims.dll
2009-07-04 20:32 . 2009-04-30 21:22 246272 -c----w- c:\windows\system32\dllcache\ieproxy.dll
2009-07-04 20:29 . 2009-07-04 20:31 -------- dc-h--w- c:\windows\ie8
2009-07-04 15:45 . 2009-07-04 15:45 -------- d-----w- c:\documents and settings\Johnnie\Application Data\Malwarebytes
2009-07-04 15:45 . 2009-06-17 15:27 38160 ----a-w- c:\windows\system32\drivers\mbamswissarmy.sys
2009-07-04 15:45 . 2009-07-04 15:45 -------- d-----w- c:\program files\Malwarebytes' Anti-Malware
2009-07-04 15:45 . 2009-07-04 15:45 -------- d-----w- c:\documents and settings\All Users\Application Data\Malwarebytes
2009-07-04 15:45 . 2009-06-17 15:27 19096 ----a-w- c:\windows\system32\drivers\mbam.sys
2009-07-04 15:41 . 2009-07-04 15:41 -------- d-----w- c:\program files\ERUNT
2009-07-04 03:23 . 2009-07-04 16:30 -------- d-----w- c:\windows\system32\LogFiles
2009-07-04 01:29 . 2008-12-11 12:38 159600 ----a-w- c:\windows\system32\drivers\pctgntdi.sys
2009-07-04 01:29 . 2009-04-03 15:18 130936 ----a-w- c:\windows\system32\drivers\PCTCore.sys
2009-07-04 01:29 . 2008-12-18 16:16 73840 ----a-w- c:\windows\system32\drivers\PCTAppEvent.sys
2009-07-04 01:28 . 2009-07-04 01:29 -------- d-----w- c:\program files\Common Files\PC Tools
2009-07-04 01:28 . 2008-12-10 15:36 64392 ----a-w- c:\windows\system32\drivers\pctplsg.sys
2009-07-04 01:28 . 2009-07-04 01:28 -------- d-----w- c:\documents and settings\All Users\Application Data\PC Tools
2009-07-03 00:24 . 2009-07-03 00:24 13312 ----a-w- c:\documents and settings\Johnnie\Application Data\Thinstall\Dream Aquarium\400000d600002i\Dream_Aquarium.scr
2009-07-03 00:24 . 2009-07-03 00:24 -------- d-----w- c:\documents and settings\Johnnie\Local Settings\Application Data\Thinstall
2009-07-03 00:24 . 2009-07-03 00:24 -------- d-----w- c:\documents and settings\Johnnie\Application Data\Thinstall
2009-06-20 16:46 . 2009-06-20 16:46 -------- d-----w- c:\documents and settings\Johnnie\Local Settings\Application Data\ATI
2009-06-20 16:46 . 2009-06-20 16:46 -------- d-----w- c:\documents and settings\Johnnie\Application Data\ATI
2009-06-20 16:46 . 2009-06-20 16:46 -------- d-----w- c:\documents and settings\All Users\Application Data\ATI
2009-06-20 16:26 . 2009-06-20 16:31 -------- d-----w- c:\program files\ATI Technologies
2009-06-20 16:24 . 2009-06-20 16:24 -------- d-----w- C:\ATI
2009-06-13 23:41 . 2009-03-02 18:25 4457808 ----a-w- c:\documents and settings\Johnnie\Application Data\TomTom\HOME\Profiles\6uih1u5y.default\extensions\[email protected]\8-302-9738-1.dll

.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2009-07-11 14:21 . 2008-07-02 19:24 -------- d---a-w- c:\documents and settings\All Users\Application Data\TEMP
2009-07-11 12:55 . 2007-06-20 15:51 -------- d-----w- c:\program files\Xnews
2009-07-11 04:36 . 2007-10-25 02:11 -------- d-----w- c:\program files\Net Tools
2009-07-09 16:50 . 2008-07-05 13:05 0 --sh--w- c:\windows\S033705C9.tmp
2009-07-09 16:46 . 2007-06-20 21:03 -------- d-----w- c:\documents and settings\All Users\Application Data\Spybot - Search & Destroy
2009-07-07 14:00 . 2007-06-22 01:20 -------- d-----w- c:\documents and settings\Johnnie\Application Data\dvdcss
2009-07-06 13:35 . 2008-07-02 01:07 -------- d-----w- c:\program files\SUPERAntiSpyware
2009-07-06 13:35 . 2008-07-02 01:07 -------- d-----w- c:\documents and settings\Johnnie\Application Data\SUPERAntiSpyware.com
2009-07-06 13:33 . 2007-06-20 21:09 -------- d-----w- c:\program files\Common Files\Wise Installation Wizard
2009-07-05 11:26 . 2007-10-14 21:52 -------- d-----w- c:\documents and settings\Johnnie\Application Data\Vso
2009-07-04 20:50 . 2007-09-21 22:06 -------- d-----w- c:\documents and settings\All Users\Application Data\Skype
2009-07-04 20:40 . 2008-05-12 11:48 -------- d-----w- c:\documents and settings\All Users\Application Data\Microsoft Help
2009-07-04 20:37 . 2008-05-12 11:51 -------- d-----w- c:\program files\Microsoft Works
2009-07-04 18:17 . 2008-04-12 01:54 -------- d-----w- c:\documents and settings\Johnnie\Application Data\NewzToolz
2009-07-04 14:58 . 2008-07-01 23:49 -------- d-----w- c:\program files\Hack this
2009-07-04 13:15 . 2008-11-27 23:22 335752 ----a-w- c:\windows\system32\drivers\avgldx86.sys
2009-07-04 01:51 . 2009-02-14 18:19 -------- d-----w- c:\program files\SpywareBlaster
2009-07-04 01:29 . 2008-09-13 21:39 -------- d-----w- c:\program files\Spyware Doctor
2009-06-29 12:56 . 2009-02-02 00:41 11952 ----a-w- c:\windows\system32\avgrsstx.dll
2009-06-29 12:56 . 2008-11-27 23:22 27784 ----a-w- c:\windows\system32\drivers\avgmfx86.sys
2009-06-28 22:35 . 2009-01-11 12:38 -------- d-----w- c:\documents and settings\Johnnie\Application Data\Dexpot
2009-06-20 18:03 . 2009-04-30 21:06 -------- d-----w- c:\program files\Citrix
2009-06-20 16:29 . 2007-06-20 01:03 -------- d--h--w- c:\program files\InstallShield Installation Information
2009-06-10 15:34 . 2009-05-17 13:14 -------- d-----w- c:\program files\Dexpot
2009-06-07 04:40 . 2009-06-07 04:29 -------- d-----w- c:\program files\Rarlab WinRAR v3.80
2009-06-02 14:37 . 2009-06-02 14:37 -------- d-----w- c:\program files\UPHClean
2009-05-31 11:28 . 2007-06-24 01:28 -------- d-----w- c:\program files\IrfanView
2009-05-25 18:06 . 2007-06-20 01:05 46656 ----a-w- c:\documents and settings\Johnnie\Local Settings\Application Data\GDIPFONTCACHEV1.DAT
2009-05-15 01:47 . 2008-10-11 16:30 -------- d-----w- c:\program files\GrabIt
2009-05-13 05:15 . 2004-08-04 12:00 915456 ----a-w- c:\windows\system32\wininet.dll
2009-05-07 15:32 . 2004-08-04 12:00 345600 ----a-w- c:\windows\system32\localspl.dll
2009-04-17 12:26 . 2004-08-04 12:00 1847168 ----a-w- c:\windows\system32\win32k.sys
2009-04-15 14:51 . 2004-08-04 12:00 585216 ----a-w- c:\windows\system32\rpcrt4.dll
2008-01-04 01:30 . 2008-01-04 01:30 26893 ------w- c:\program files\spamwords.log
2007-08-20 01:39 . 2007-08-20 01:39 50 ------w- c:\program files\InstallLog.txt
.

((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Mailbell"="c:\program files\MailBell\mailbell.exe" [2008-04-14 1365432]
"DynAdvance Notifier"="c:\program files\DynAdvance Notifier\MailNotifier.Exe" [2005-06-20 229376]
"ctfmon.exe"="c:\windows\system32\ctfmon.exe" [2008-04-14 15360]
"SUPERAntiSpyware"="c:\program files\SUPERAntiSpyware\SUPERAntiSpyware.exe" [2009-06-23 1830128]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"SoundMAXPnP"="c:\program files\Analog Devices\SoundMAX\SMax4PNP.exe" [2003-05-29 790528]
"TrueImageMonitor.exe"="c:\program files\Acronis\TrueImageHome\TrueImageMonitor.exe" [2008-04-10 2595792]
"AcronisTimounterMonitor"="c:\program files\Acronis\TrueImageHome\TimounterMonitor.exe" [2008-04-10 909208]
"Acronis Scheduler2 Service"="c:\program files\Common Files\Acronis\Schedule2\schedhlp.exe" [2008-04-10 136472]
"AVG8_TRAY"="c:\progra~1\AVG\AVG8\avgtray.exe" [2009-06-29 1948440]
"IntelliPoint"="c:\program files\Microsoft IntelliPoint\ipoint.exe" [2008-06-10 1406024]

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\explorer]
"NoResolveTrack"= 1 (0x1)
"NoFileAssociate"= 0 (0x0)

[hkey_local_machine\software\microsoft\windows\currentversion\explorer\ShellExecuteHooks]
"{EDB0E980-90BD-11D4-8599-0008C7D3B6F8}"= "c:\program files\Qualcomm\Eudora\EuShlExt.dll" [2001-04-12 77824]
"{5AE067D3-9AFB-48E0-853A-EBB7F4A000DA}"= "c:\program files\SUPERAntiSpyware\SASSEH.DLL" [2008-05-13 77824]

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\!SASWinLogon]
2008-12-22 16:05 356352 ----a-w- c:\program files\SUPERAntiSpyware\SASWINLO.dll

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\avgrsstarter]
2009-06-29 12:56 11952 ----a-w- c:\windows\system32\avgrsstx.dll

[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\session manager]
BootExecute REG_MULTI_SZ autocheck autochk *\0oodbs\0lsdelete

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\Lavasoft Ad-Aware Service]
@="Service"

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\sdauxservice]
@=""

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\sdcoreservice]
@=""

[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Palo Alto Software Update Manager 9.0.lnk]
path=c:\documents and settings\All Users\Start Menu\Programs\Startup\Palo Alto Software Update Manager 9.0.lnk
backup=c:\windows\pss\Palo Alto Software Update Manager 9.0.lnkCommon Startup

[HKLM\~\startupfolder\C:^Documents and Settings^Johnnie^Start Menu^Programs^Startup^ERUNT AutoBackup.lnk]
path=c:\documents and settings\Johnnie\Start Menu\Programs\Startup\ERUNT AutoBackup.lnk
backup=c:\windows\pss\ERUNT AutoBackup.lnkStartup

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run-]
"<NO NAME>"=

[HKEY_LOCAL_MACHINE\software\microsoft\security center]
"FirewallOverride"=dword:00000001

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]
"EnableFirewall"= 0 (0x0)

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"c:\\WINDOWS\\system32\\sessmgr.exe"=
"c:\\Program Files\\VoipStunt.com\\VoipStunt\\voipstunt.exe"=

R0 Lbd;Lbd;c:\windows\system32\drivers\Lbd.sys [13/02/2009 10:51 PM 64160]
R0 PCTCore;PCTools KDS;c:\windows\system32\drivers\PCTCore.sys [03/07/2009 9:29 PM 130936]
R1 AvgLdx86;AVG Free AVI Loader Driver x86;c:\windows\system32\drivers\avgldx86.sys [27/11/2008 7:22 PM 335752]
R1 SASDIFSV;SASDIFSV;c:\program files\SUPERAntiSpyware\sasdifsv.sys [23/06/2009 11:01 AM 9968]
R1 SASKUTIL;SASKUTIL;c:\program files\SUPERAntiSpyware\SASKUTIL.SYS [23/06/2009 11:01 AM 72944]
R2 avg8wd;AVG Free8 WatchDog;c:\progra~1\AVG\AVG8\avgwdsvc.exe [01/02/2009 8:41 PM 298776]
R2 Lavasoft Ad-Aware Service;Lavasoft Ad-Aware Service;c:\program files\Lavasoft\Ad-Aware\AAWService.exe [18/01/2009 5:34 PM 1029456]
R3 SASENUM;SASENUM;c:\program files\SUPERAntiSpyware\SASENUM.SYS [23/06/2009 11:01 AM 7408]
R3 Uplink;Uplink;c:\windows\system32\drivers\Uplink.sys [18/10/2007 8:48 PM 31232]
S3 BDADRVLGP;Plextor PX-HDTV500U Digital TV Tuner;c:\windows\system32\Drivers\bdadrvlgp.sys --> c:\windows\system32\Drivers\bdadrvlgp.sys [?]
S3 brfilt;Brother MFC Filter Driver;c:\windows\system32\drivers\BrFilt.sys [16/10/2007 2:49 PM 2944]
S3 BrSerWDM;Brother Serial driver;c:\windows\system32\drivers\BrSerWdm.sys [16/10/2007 2:49 PM 61952]
S3 BrUsbMdm;Brother MFC USB Fax Only Modem;c:\windows\system32\drivers\BrUsbMdm.sys [16/10/2007 2:49 PM 11008]
S3 BrUsbScn;Brother MFC USB Scanner driver;c:\windows\system32\drivers\BrUsbScn.sys [16/10/2007 2:49 PM 10368]
S3 cpuz132;cpuz132;c:\windows\system32\drivers\cpuz132_x32.sys [30/04/2009 9:24 PM 12672]
S3 m4cxw2k3;NDIS5.1 Miniport Driver for D-Link PCI Express Ethernet Controller;c:\windows\system32\drivers\m4cxw2k3.sys [10/03/2005 7:42 AM 227584]
S3 sdAuxService;PC Tools Auxiliary Service;c:\program files\Spyware Doctor\pctsAuxs.exe [13/09/2008 5:39 PM 348752]
S3 TomTomHOMEService;TomTomHOMEService;c:\program files\TomTom HOME 2\TomTomHOMEService.exe [03/06/2009 8:46 AM 92008]
S3 zlportio;ZLPORTIO - Allow user access to I/O ports;\??\e:\programs\DriverWizard\zlportio.sys --> e:\programs\DriverWizard\zlportio.sys [?]
S4 UplinkService;Uplink Skype2Sip Service;c:\program files\NCH Swift Sound\Uplink\uplink.exe [18/10/2007 8:48 PM 339972]

--- Other Services/Drivers In Memory ---

*Deregistered* - uphcleanhlp

[HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\>{60B49E34-C7CC-11D0-8953-00A0C90347FF}]
"c:\windows\system32\rundll32.exe" "c:\windows\system32\iedkcs32.dll",BrandIEActiveSetup SIGNUP

[HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{A185BBC1-0A7C-6EF7-3093-185B3CADBA08}]
c:\windows\system32:hqtray.exe
.
Contents of the 'Scheduled Tasks' folder

2009-02-14 c:\windows\Tasks\Ad-Aware Update (Weekly).job
- c:\program files\Lavasoft\Ad-Aware\Ad-AwareAdmin.exe [2009-01-18 01:20]

2009-02-02 c:\windows\Tasks\Microsoft_Hardware_Launch_IPoint_exe.job
- c:\program files\Microsoft IntelliPoint\ipoint.exe [2008-06-10 17:56]

2008-11-23 c:\windows\Tasks\Norton Security Scan for Johnnie.job
- c:\program files\Norton Security Scan\Nss.exe [2008-09-19 09:18]
.
.
------- Supplementary Scan -------
.
uStart Page = hxxp://www.google.com/
uSearchMigratedDefaultURL = hxxp://www.google.com/search?q={searchTerms}&sourceid=ie7&rls=com.microsoft:en-US&ie=utf8&oe=utf8
uInternet Settings,ProxyOverride = *.local
uSearchURL,(Default) = hxxp://www.google.com/search/?q=%s
IE: Add to Vbuzzer RSS list - c:\program files\vbuzzer\addurl.htm
IE: Append Link Target to Existing PDF - c:\program files\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll/AcroIEAppendSelLinks.html
IE: Append to Existing PDF - c:\program files\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll/AcroIEAppend.html
IE: Convert Link Target to Adobe PDF - c:\program files\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll/AcroIECaptureSelLinks.html
IE: Convert to Adobe PDF - c:\program files\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll/AcroIECapture.html
IE: E&xport to Microsoft Excel - c:\progra~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
IE: { - c:\program files\Messenger\msmsgs.exe
DPF: {CCA0B877-CB5E-4ADC-AD30-457C379512DD} - hxxp://10.0.0.240/xplugLiteAL.cab
FF - ProfilePath - c:\documents and settings\Johnnie\Application Data\Mozilla\Firefox\Profiles\2zi1h6xu.default\
FF - prefs.js: browser.startup.homepage - hxxp://mirariver.com/
FF - component: c:\program files\AVG\AVG8\Firefox\components\avgssff.dll
FF - plugin: c:\documents and settings\Johnnie\Application Data\Mozilla\Firefox\Profiles\2zi1h6xu.default\extensions\[email protected]\platform\WINNT_x86-msvc\plugins\NPInforbit32.dll
FF - plugin: c:\program files\Mozilla Firefox\plugins\npmozax.dll
FF - plugin: c:\program files\Mozilla Firefox\plugins\npvirtools.dll
FF - HiddenExtension: Microsoft .NET Framework Assistant: {20a82645-c095-46ed-80e3-08825760534b} - c:\windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\DotNetAssistantExtension\
FF - HiddenExtension: Java Console: No Registry Reference - c:\program files\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0006-ABCDEFFEDCBA}
.

**************************************************************************

catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2009-07-11 23:14
Windows 5.1.2600 Service Pack 3 NTFS

scanning hidden processes ...

scanning hidden autostart entries ...

scanning hidden files ...

scan completed successfully
hidden files: 0

**************************************************************************
.
--------------------- LOCKED REGISTRY KEYS ---------------------

[HKEY_LOCAL_MACHINE\software\Microsoft\Windows\CurrentVersion\System*]
"OODEFRAG10.00.00.01WORKSTATION"="CC7C5B6B133E1B4A7CB1BF145287671EBD043BC759E39507DBF098CF3E1D1C3AFD405435704321A134C95396B4BCE2B
FDF416C8A6E606096E59DBF1ABD1A5D2EB78AE3C36DACB59D9F6BD6972EF6762BECEA4C57A1D15779E5A0C230BBF8724C8A43
F002E5045C4CACE8763308F6FDEFD0DC6C1B4B534B62637EB771B94A3F06BFB636DEABF62E8381F8330B82A166642CD532C6B
6231FC59C1E08C033493B934F95C1CE0355D85BF4B25E434D82B1A254F65550A02549DF034AF083FEBC9E127BECC74CFEBC9E
127BECC74CFEBC9E127BECC74CFEBC9E127BECC74CFEBC9E127BECC74CFEBC9E127BECC74C8EDD5E5BE2F6E667A6171C11EC3
8DE3DA6171C11EC38DE3DC038D530D6EB3452D5E4AC86ED841478A0CCAAAE446D97459346ACAACEB259E0D2C046A6DE717050
E9CE2D32A3F1756311C16B34DF10DE2BD1D361E171ABA0016BE312D3A5ABAE9B943C48A1D710BCB40873048DEC94DEC25DD03
ACB93656C3EB74B6BC6DADC3777C10E780317599AF9FD9CE20F939F500B5A71BDFA19CD95A8A8C48972C3DAA9A34E4CCD4DA2
2C14C55B1B0C4BB3B63A85E18E03481FB3CB53A3C13B8FD65EFAE58C1EE6BA6ECA802C8173961FDCC67B3A7FA1374CF34D925
502D561193F06F0074152FC47245C8E48C34A2E28D41E45B2B3CB1A6718B0BFC9903BF1515D52A852A75BD9329E6ABDB6E6EC
124816F01FFC7051FE3E445D7DD18FCDF5BBC4A89199EECF5A846EE36399A74895A54C5660AD209AD0356231CB11358F891F3
C53EFB036E7F184D81B2795B5F09E2BDBC938D99E3109F910F07D2E2A25DE893F7FDAF09503A64157478756311DA906D7A9A8
9D3A4839F92146B8558CD6BB49FE3D3E3697A193899401548834A746280BBA879538B105E81BBCF8B56A90F8735D03D96238E
AE5F3F148B25DC78F17487224FD6651E426BD39C48C04CBE58360F22BC159EAA8DFDA047E1B0A6CF654E0407109352FFEE6B4
E93395F6A70ADDAB89F05D8316C6D75993EA5B4A942647AF5911FB2E7440294B4FBF8B4AEC561BB622F7684D125A39D01C361
35AA686D037D658FBFD330B60C4BF0839BE7A47E524EF44F3292E170167CF71B6FA7D2864BC867C03D8756795AAC68ABD9628
FE7B5C5B3FE109ABD74285128D8F73E9BD094BEA99DEF53503E34522AC8A1ABBC02D0D7E366B68421A22D9FAE0BA8C2D9D593
1B82F300E63ADFCA5C3B66894F4F5DF2429DB9B4219005CD2D7262914FE44057F59A16F60E3D8241E5456705603AC8DD7DF44
5296D1CE3FA729F99FDC0B4ECF0D6BB663310F1EB1452C9912328B93C29E586943EBFAF0AAD0A3E1B5BA6F8010F4BE1BABC5B
0B892F7DA7790802802213580A8F64A9C75188CAF43D888BE403292D95D38E78989C5D323C5029D656E5E1C75C2483D300C10
59E9674A23021A338B7671D1E74B94E1BC"
"OODI01.00.00.01PRO"="2E5DD2504F88AEAED8106EA144E2F725DB392CC5AA8B078A60403B803843E854B819F720DDB1BBCD02715A2F2344A8B
9C5B5F37A9C51E6BABB5C80627093D411920E030362F09D2A470DF1267C14EB7512FC7B0ABED33A1CE4EFCBF2606B1CF16BC5
F594A78731C8B1E2593EC497928DC52624E94AFB5FAF7544E086AE7A4EE29A6196255B0AD827F1847566D36AED29875716C4E
20A3AEBB1B546A3E4C300C71A90ECB9116179B2DA1BEFBFE278D46324CDBBF90B9134B87CB64A076E9E4AF4071AC58BBD49FD
CFE06038209384214E0A59C41A2BF6B6F2DE4CFA9E1EB84AB5245933063C54D35422A400116824B3EC4F5FFEBC9E127BECC74
CFEBC9E127BECC74CFEBC9E127BECC74CFEBC9E127BECC74CFEBC9E127BECC74CFEBC9E127BECC74C8EDD5E5BE2F6E667A617
1C11EC38DE3DA6171C11EC38DE3DC038D530D6EB34521F3589D4BC02E92E432F3F3C747235DEC568B34B16C67516186363F22
21C872F5A21281FED9C6F954C5017131C170A454FD9F78FA375419D6CAA4350646FDBFC7BE039CCCF1D51344D3E01569DD0BC
C66AE85A001444CE7D6286E5555B955FC0AB196F64E81483518D39D613EFD8B840A31701CEEE3B22C6E8D4D7FA4085CF6258A
1DFC3C1839A471CB6D82D0FE20E20489672824259641EAC240B8D4FA88F5A3387069BE8E2D2074BE02BD7760F71EB6DCB9BF6
1A0E63BE25B8552CC85DA3B8308B3FEF701E0C92B195539E2CF7B93CE8D2CD5A8DBE8E73080A6FC972F4371E0A22CE1B6C934
781A865BE5EB3A8E23DD6FA3C3032C47C1F5242F6AF94B617423CF3DAC878152D7FCE96BAC91B218E2F96C4804EA3ECE33744
426DF97B5B36ED09DCEDF930EB86CB06A2FCE46E567EE4C968965F82F72443629D3895F7122981756DF5833751C43874379B0
C402F1B4859505EE3721C3C63F31BA0495E7CABEC4A6AC50E31F478AE04B4116A290871556E199B2C1A0152460536D32C0830
19B714CC9416497A5A28E331BE83C231AF9CF99778E026C3AE32E79FE4A85037F5FB25C07AEC2DF7C4B4857767AB2BEEAB422
FD080FA4576BE80AE3AC6009911E5671326F7388D78B6781F04B18E06F7DBFD0401A4CB2C1D929E319DD445482EB4BD35136F
ED21FA52A8AA882AA8797ADB9B331538F39231DF0D0D14CAE043744FD32A4FA6DDA073DE13666A3FCC3094EC7C3DAF74EA331
FFE62211FCB8E793F48155356C6A74A484715D443449F585A721565A7757B4D49ECC692705CDCD9DB537ED45A603FDED41BA2
3BDF721AA5D474EC32083C45A583CAF749F1E430D98BCD2317BEE46E25E60CC32543E28CCE001E20EE8E2C3A8418DC4771BCB
4C0710533A9C89C2BD16543F292DE2295978D4B40602A2E0E20B3C10E98FAA17C9A9E73264B5B3FEB5A6FA0483E7C656F30A0
9BCDEFB70E0F9304B368E69924519D60F2"
.
--------------------- DLLs Loaded Under Running Processes ---------------------

- - - - - - - > 'winlogon.exe'(868)
c:\program files\SUPERAntiSpyware\SASWINLO.dll
c:\windows\system32\WININET.dll
c:\windows\system32\Ati2evxx.dll

- - - - - - - > 'lsass.exe'(924)
c:\windows\system32\relog_ap.dll

- - - - - - - > 'explorer.exe'(3648)
c:\windows\system32\WININET.dll
c:\windows\system32\ieframe.dll
c:\windows\system32\webcheck.dll
.
------------------------ Other Running Processes ------------------------
.
c:\windows\system32\ati2evxx.exe
c:\windows\system32\ati2evxx.exe
c:\program files\Common Files\Acronis\Schedule2\schedul2.exe
c:\program files\Java\jre6\bin\jqs.exe
c:\program files\Analog Devices\SoundMAX\SMAgent.exe
c:\program files\Common Files\Acronis\Fomatik\TrueImageTryStartService.exe
c:\program files\AVG\AVG8\avgrsx.exe
c:\program files\UPHClean\uphclean.exe
c:\windows\system32\wbem\unsecapp.exe
c:\windows\system32\wscntfy.exe
.
**************************************************************************
.
Completion time: 2009-07-12 23:19 - machine was rebooted
ComboFix-quarantined-files.txt 2009-07-12 03:19

Pre-Run: 43,779,276,800 bytes free
Post-Run: 43,725,893,632 bytes free

WindowsXP-KB310994-SP2-Pro-BootDisk-ENU.exe
[boot loader]
timeout=2
default=multi(0)disk(0)rdisk(0)partition(2)\WINDOWS
[operating systems]
c:\cmdcons\BOOTSECT.DAT="Microsoft Windows Recovery Console" /cmdcons
multi(0)disk(0)rdisk(0)partition(2)\WINDOWS="Microsoft Windows XP Professional" /noexecute=optin /fastdetect

269 --- E O F --- 2009-06-13 04:28

************OTL logfile****************

OTL logfile created on: 11/07/2009 11:24:42 PM - Run 2
OTL by OldTimer - Version 3.0.6.4 Folder = C:\Documents and Settings\Johnnie\Desktop\Maintence\GEEKS to GO\! ! Malware Tools
Windows XP Professional Edition Service Pack 3 (Version = 5.1.2600) - Type = NTWorkstation
Internet Explorer (Version = 8.0.6001.18702)
Locale: 00001009 | Country: Canada | Language: ENC | Date Format: dd/MM/yyyy

2.00 Gb Total Physical Memory | 2.00 Gb Available Physical Memory | 100.00% Memory free
4.00 Gb Paging File | 4.00 Gb Available in Paging File | 100.00% Paging File free
Paging file location(s): C:\pagefile.sys 3000 4000 [binary data]

%SystemDrive% = C: | %SystemRoot% = C:\WINDOWS | %ProgramFiles% = C:\Program Files
Drive C: | 95.36 Gb Total Space | 40.74 Gb Free Space | 42.72% Space Free | Partition Type: NTFS
Drive D: | 370.40 Gb Total Space | 81.70 Gb Free Space | 22.06% Space Free | Partition Type: NTFS
Drive E: | 465.76 Gb Total Space | 0.63 Gb Free Space | 0.14% Space Free | Partition Type: NTFS
F: Drive not present or media not loaded
G: Drive not present or media not loaded
H: Drive not present or media not loaded
I: Drive not present or media not loaded
Drive Z: | 370.40 Gb Total Space | 81.70 Gb Free Space | 22.06% Space Free | Partition Type: NTFS

Computer Name: LIVINGROOM
Current User Name: Johnnie
Logged in as Administrator.

Current Boot Mode: Normal
Scan Mode: Current user
Company Name Whitelist: Off
Skip Microsoft Files: Off
File Age = 30 Days
Output = Minimal

========== Win32 Services (SafeList) ==========

SRV - (AcrSch2Svc [Auto | Running]) -- C:\Program Files\Common Files\Acronis\Schedule2\schedul2.exe (Acronis)
SRV - (aspnet_state [On_Demand | Stopped]) -- C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\aspnet_state.exe (Microsoft Corporation)
SRV - (Ati HotKey Poller [Auto | Running]) -- C:\WINDOWS\System32\Ati2evxx.exe (ATI Technologies Inc.)
SRV - (ATI Smart [Auto | Stopped]) -- C:\WINDOWS\System32\ati2sgag.exe ()
SRV - (avg8wd [Auto | Running]) -- C:\Program Files\AVG\AVG8\avgwdsvc.exe (AVG Technologies CZ, s.r.o.)
SRV - (brmfrmps [Disabled | Stopped]) -- File not found
SRV - (Brother XP spl Service [Disabled | Stopped]) -- C:\WINDOWS\System32\brsvc01a.exe (brother Industries Ltd)
SRV - (clr_optimization_v2.0.50727_32 [On_Demand | Stopped]) -- C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\mscorsvw.exe (Microsoft Corporation)
SRV - (FLEXnet Licensing Service [On_Demand | Stopped]) -- C:\Program Files\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe (Macrovision Europe Ltd.)
SRV - (FontCache3.0.0.0 [On_Demand | Stopped]) -- C:\WINDOWS\Microsoft.NET\Framework\v3.0\WPF\PresentationFontCache.exe (Microsoft Corporation)
SRV - (helpsvc [Auto | Running]) -- C:\WINDOWS\PCHealth\HelpCtr\Binaries\pchsvc.dll (Microsoft Corporation)
SRV - (IDriverT [On_Demand | Stopped]) -- C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe (Macrovision Corporation)
SRV - (idsvc [Unknown | Stopped]) -- C:\WINDOWS\Microsoft.NET\Framework\v3.0\Windows Communication Foundation\infocard.exe (Microsoft Corporation)
SRV - (JavaQuickStarterService [Auto | Running]) -- C:\Program Files\Java\jre6\bin\jqs.exe (Sun Microsystems, Inc.)
SRV - (Lavasoft Ad-Aware Service [Auto | Running]) -- C:\Program Files\Lavasoft\Ad-Aware\AAWService.exe (Lavasoft)
SRV - (NetTcpPortSharing [Disabled | Stopped]) -- C:\WINDOWS\Microsoft.NET\Framework\v3.0\Windows Communication Foundation\SMSvcHost.exe (Microsoft Corporation)
SRV - (O&O Defrag [On_Demand | Stopped]) -- C:\WINDOWS\System32\oodag.exe (O&O Software GmbH)
SRV - (odserv [On_Demand | Stopped]) -- C:\Program Files\Common Files\Microsoft Shared\OFFICE12\ODSERV.EXE (Microsoft Corporation)
SRV - (ose [On_Demand | Stopped]) -- C:\Program Files\Common Files\Microsoft Shared\Source Engine\OSE.EXE (Microsoft Corporation)
SRV - (rpcapd [On_Demand | Stopped]) -- File not found
SRV - (sdAuxService [On_Demand | Stopped]) -- C:\Program Files\Spyware Doctor\pctsAuxs.exe (PC Tools)
SRV - (sdCoreService [On_Demand | Stopped]) -- C:\Program Files\Spyware Doctor\pctsSvc.exe (PC Tools)
SRV - (SoundMAX Agent Service (default) [Auto | Running]) -- C:\Program Files\Analog Devices\SoundMAX\SMAgent.exe (Analog Devices, Inc.)
SRV - (TomTomHOMEService [On_Demand | Stopped]) -- C:\Program Files\TomTom HOME 2\TomTomHOMEService.exe (TomTom)
SRV - (TryAndDecideService [Auto | Running]) -- C:\Program Files\Common Files\Acronis\Fomatik\TrueImageTryStartService.exe ()
SRV - (UPHClean [Auto | Running]) -- C:\Program Files\UPHClean\uphclean.exe (Microsoft Corporation)
SRV - (UplinkService [Disabled | Stopped]) -- C:\Program Files\NCH Swift Sound\Uplink\uplink.exe ()

========== Standard Registry (SafeList) ==========


========== Internet Explorer ==========

IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft....k/?LinkId=69157
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft....k/?LinkId=54896
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Secondary_Page_URL = [binary data]
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Extensions Off Page = about:NoAdd-ons
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Local Page = C:\WINDOWS\system32\blank.htm
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft....k/?LinkId=54896
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Security Risk Page = about:SecurityRisk
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft....k/?LinkId=69157
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Search,CustomizeSearch = http://ie.search.msn...st/srchcust.htm
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Search,SearchAssistant = http://ie.search.msn...st/srchasst.htm

IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Local Page = C:\WINDOWS\system32\blank.htm
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Page_Transitions = 0
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Search Page = http://www.microsoft...amp;ar=iesearch
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,SearchMigratedDefaultName = Google
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,SearchMigratedDefaultURL = http://www.google.co...m...tf8&oe=utf8
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://www.google.com/
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyOverride" = *.local

========== FireFox ==========

FF - prefs.js..browser.search.suggest.enabled: false
FF - prefs.js..browser.startup.homepage: "http://mirariver.com/"
FF - prefs.js..extensions.enabledItems: {3f963a5b-e555-4543-90e2-c3908898db71}:8.5
FF - prefs.js..extensions.enabledItems: [email protected]:3.1.2
FF - prefs.js..extensions.enabledItems: {CAFEEFAC-0016-0000-0006-ABCDEFFEDCBA}:6.0.06
FF - prefs.js..extensions.enabledItems: {CAFEEFAC-0016-0000-0013-ABCDEFFEDCBA}:6.0.13
FF - prefs.js..extensions.enabledItems: [email protected]:1.0
FF - prefs.js..extensions.enabledItems: {20a82645-c095-46ed-80e3-08825760534b}:1.1
FF - prefs.js..extensions.enabledItems: {972ce4c6-7e08-4474-a285-3208198ce6fd}:3.0.11

FF - HKLM\software\mozilla\Firefox\Extensions\\{3f963a5b-e555-4543-90e2-c3908898db71}: C:\Program Files\AVG\AVG8\Firefox [2009/06/29 08:58:09 | 00,000,000 | ---D | M]
FF - HKLM\software\mozilla\Firefox\Extensions\\{20a82645-c095-46ed-80e3-08825760534b}: C:\WINDOWS\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\DotNetAssistantExtension\ [2009/07/04 16:40:23 | 00,000,000 | ---D | M]
FF - HKLM\software\mozilla\Firefox\Extensions\\[email protected]: C:\Program Files\Java\jre6\lib\deploy\jqs\ff [2008/12/12 19:54:33 | 00,000,000 | ---D | M]
FF - HKLM\software\mozilla\Mozilla Firefox 3.0.11\extensions\\Components: C:\Program Files\Mozilla Firefox\components [2009/06/19 12:32:48 | 00,000,000 | ---D | M]
FF - HKLM\software\mozilla\Mozilla Firefox 3.0.11\extensions\\Plugins: C:\Program Files\Mozilla Firefox\plugins [2009/06/16 08:21:03 | 00,000,000 | ---D | M]

[2009/01/19 15:32:26 | 00,000,000 | ---D | M] -- C:\Documents and Settings\Johnnie\Application Data\mozilla\Extensions
[2008/07/01 12:48:45 | 00,000,000 | ---D | M] -- C:\Documents and Settings\Johnnie\Application Data\mozilla\Extensions\{ec8030f7-c20a-464f-9b0e-13a3a9e97384}
[2009/01/19 15:32:26 | 00,000,000 | ---D | M] -- C:\Documents and Settings\Johnnie\Application Data\mozilla\Extensions\[email protected]
[2009/07/11 10:23:02 | 00,000,000 | ---D | M] -- C:\Documents and Settings\Johnnie\Application Data\mozilla\Firefox\Profiles\2zi1h6xu.default\extensions
[2009/07/04 16:50:53 | 00,000,000 | ---D | M] -- C:\Documents and Settings\Johnnie\Application Data\mozilla\Firefox\Profiles\2zi1h6xu.default\extensions\{20a82645-c095-46ed-80e3-08825760534b}
[2008/12/01 21:43:04 | 00,000,000 | ---D | M] -- C:\Documents and Settings\Johnnie\Application Data\mozilla\Firefox\Profiles\2zi1h6xu.default\extensions\[email protected]
[2009/07/11 10:23:02 | 00,000,000 | ---D | M] -- C:\Program Files\mozilla firefox\extensions
[2009/06/16 08:21:03 | 00,000,000 | ---D | M] -- C:\Program Files\mozilla firefox\extensions\{972ce4c6-7e08-4474-a285-3208198ce6fd}
[2008/07/02 19:20:08 | 00,000,000 | ---D | M] -- C:\Program Files\mozilla firefox\extensions\{CAFEEFAC-0016-0000-0006-ABCDEFFEDCBA}
[2009/04/05 23:18:48 | 00,000,000 | ---D | M] -- C:\Program Files\mozilla firefox\extensions\{CAFEEFAC-0016-0000-0013-ABCDEFFEDCBA}
[2009/06/16 08:20:18 | 00,023,032 | ---- | M] (Mozilla Foundation) -- C:\Program Files\mozilla firefox\components\browserdirprovider.dll
[2009/06/16 08:20:18 | 00,134,648 | ---- | M] (Mozilla Foundation) -- C:\Program Files\mozilla firefox\components\brwsrcmp.dll
[2009/03/09 05:19:09 | 00,410,984 | ---- | M] (Sun Microsystems, Inc.) -- C:\Program Files\mozilla firefox\plugins\npdeploytk.dll
[2005/12/05 23:31:00 | 00,114,688 | ---- | M] () -- C:\Program Files\mozilla firefox\plugins\npmozax.dll
[2009/06/16 08:20:26 | 00,065,528 | ---- | M] (mozilla.org) -- C:\Program Files\mozilla firefox\plugins\npnul32.dll
[2006/10/26 20:12:16 | 00,016,192 | ---- | M] (Microsoft Corporation) -- C:\Program Files\mozilla firefox\plugins\NPOFF12.DLL
[2009/02/27 12:13:42 | 00,103,792 | ---- | M] (Adobe Systems Inc.) -- C:\Program Files\mozilla firefox\plugins\nppdf32.dll
[2006/02/02 16:56:00 | 00,225,280 | ---- | M] (Virtools SA) -- C:\Program Files\mozilla firefox\plugins\npvirtools.dll
[2009/04/24 21:44:31 | 00,001,394 | ---- | M] () -- C:\Program Files\mozilla firefox\searchplugins\amazondotcom.xml
[2009/04/24 21:44:31 | 00,002,193 | ---- | M] () -- C:\Program Files\mozilla firefox\searchplugins\answers.xml
[2009/04/24 21:44:31 | 00,001,534 | ---- | M] () -- C:\Program Files\mozilla firefox\searchplugins\creativecommons.xml
[2009/04/24 21:44:31 | 00,002,343 | ---- | M] () -- C:\Program Files\mozilla firefox\searchplugins\eBay.xml
[2009/04/24 21:44:31 | 00,001,706 | ---- | M] () -- C:\Program Files\mozilla firefox\searchplugins\google.xml
[2009/04/24 21:44:31 | 00,001,178 | ---- | M] () -- C:\Program Files\mozilla firefox\searchplugins\wikipedia.xml
[2009/04/24 21:44:31 | 00,000,792 | ---- | M] () -- C:\Program Files\mozilla firefox\searchplugins\yahoo.xml

O1 HOSTS File: (27 bytes) - C:\WINDOWS\System32\drivers\etc\Hosts
O1 - Hosts: 127.0.0.1 localhost
O2 - BHO: (Adobe PDF Link Helper) - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll (Adobe Systems Incorporated)
O2 - BHO: (AVG Safe Search) - {3CA2F312-6F6E-4B53-A66E-4E65E497C8C0} - C:\Program Files\AVG\AVG8\avgssie.dll (AVG Technologies CZ, s.r.o.)
O2 - BHO: (Spybot-S&D IE Protection) - {53707962-6F74-2D53-2644-206D7942484F} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll (Safer Networking Limited)
O2 - BHO: (no name) - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - No CLSID value found.
O2 - BHO: (Adobe PDF Conversion Toolbar Helper) - {AE7CD045-E861-484f-8273-0445EE161910} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll (Adobe Systems Incorporated)
O2 - BHO: (Java™ Plug-In 2 SSV Helper) - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll (Sun Microsystems, Inc.)
O2 - BHO: (JQSIEStartDetectorImpl Class) - {E7E6F031-17CE-4C07-BC86-EABFE594F69C} - C:\Program Files\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll (Sun Microsystems, Inc.)
O2 - BHO: (SmartSelect Class) - {F4971EE7-DAA0-4053-9964-665D8EE6A077} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll (Adobe Systems Incorporated)
O3 - HKLM\..\Toolbar: (Adobe PDF) - {47833539-D0C5-4125-9FA8-0819E2EAAC93} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll (Adobe Systems Incorporated)
O3 - HKCU\..\Toolbar\ShellBrowser: (no name) - {73C7D5B0-7B03-444A-84C7-CE1BA03B5573} - No CLSID value found.
O3 - HKCU\..\Toolbar\WebBrowser: (Adobe PDF) - {47833539-D0C5-4125-9FA8-0819E2EAAC93} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll (Adobe Systems Incorporated)
O4 - HKLM..\Run: [Acronis Scheduler2 Service] C:\Program Files\Common Files\Acronis\Schedule2\schedhlp.exe (Acronis)
O4 - HKLM..\Run: [AcronisTimounterMonitor] C:\Program Files\Acronis\TrueImageHome\TimounterMonitor.exe (Acronis)
O4 - HKLM..\Run: [AVG8_TRAY] C:\Program Files\AVG\AVG8\avgtray.exe (AVG Technologies CZ, s.r.o.)
O4 - HKLM..\Run: [IntelliPoint] C:\Program Files\Microsoft IntelliPoint\ipoint.exe (Microsoft Corporation)
O4 - HKLM..\Run: [SoundMAXPnP] C:\Program Files\Analog Devices\SoundMAX\SMax4PNP.exe (Analog Devices, Inc.)
O4 - HKLM..\Run: [TrueImageMonitor.exe] C:\Program Files\Acronis\TrueImageHome\TrueImageMonitor.exe (Acronis)
O4 - HKCU..\Run: [DynAdvance Notifier] C:\Program Files\DynAdvance Notifier\MailNotifier.Exe (Catalin Stavaru)
O4 - HKCU..\Run: [Mailbell] C:\Program Files\MailBell\mailbell.exe ()
O4 - HKCU..\Run: [SUPERAntiSpyware] C:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe (SUPERAntiSpyware.com)
O6 - HKLM\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O6 - HKLM\Software\Policies\Microsoft\Internet Explorer\Infodelivery present
O6 - HKLM\Software\Policies\Microsoft\Internet Explorer\Restrictions present
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoResolveTrack = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoPropertiesMyComputer = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoFileAssociate = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoSMHelp = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: HonorAutoRunSetting = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveAutoRun = 67108863
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 323
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDrives = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: dontdisplaylastusername = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: legalnoticecaption =
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: legalnoticetext =
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: undockwithoutlogon = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ShutdownWithoutLogon = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: DisableRegistryTools = 0
O7 - HKCU\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 323
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoCDBurning = 1
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoRecentDocsHistory = 0
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: ClearRecentDocsOnExit = 0
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveAutoRun = 67108863
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDrives = 0
O8 - Extra context menu item: Add to Vbuzzer RSS list - C:\Program Files\vbuzzer\addurl.htm ()
O8 - Extra context menu item: Append Link Target to Existing PDF - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll (Adobe Systems Incorporated)
O8 - Extra context menu item: Append to Existing PDF - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll (Adobe Systems Incorporated)
O8 - Extra context menu item: Convert Link Target to Adobe PDF - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll (Adobe Systems Incorporated)
O8 - Extra context menu item: Convert to Adobe PDF - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll (Adobe Systems Incorporated)
O8 - Extra context menu item: E&xport to Microsoft Excel - C:\Program Files\Microsoft Office\OFFICE11\EXCEL.EXE (Microsoft Corporation)
O9 - Extra Button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\Program Files\Microsoft Office\Office12\REFIEBAR.DLL (Microsoft Corporation)
O9 - Extra 'Tools' menuitem : Spybot - Search & Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll (Safer Networking Limited)
O9 - Extra 'Tools' menuitem : @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe (Microsoft Corporation)
O9 - Extra Button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe (Microsoft Corporation)
O9 - Extra 'Tools' menuitem : Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe (Microsoft Corporation)
O9 - Extra Button: Messenger - -{FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe (Microsoft Corporation)
O9 - Extra 'Tools' menuitem : Windows Messenger - -{FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe (Microsoft Corporation)
O9 - Extra Button: SmartWhois - {FD9DE2B4-C926-4460-81C4-FC58C6F1062E} - C:\Program Files\SmartWhois\swmsie.exe (TamoSoft)
O9 - Extra 'Tools' menuitem : SmartWhois - {FF983118-58C7-4AD4-B5A7-691C39CB7B42} - C:\Program Files\SmartWhois\swmsie.exe (TamoSoft)
O15 - HKLM\..Trusted Domains: 49 domain(s) and sub-domain(s) not assigned to a zone.
O15 - HKCU\..Trusted Domains: 49 domain(s) and sub-domain(s) not assigned to a zone.
O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} http://download.micr...heckControl.cab (Windows Genuine Advantage Validation Tool)
O16 - DPF: {2BC66F54-93A8-11D3-BEB6-00105AA9B6AE} http://security.syma...bin/AvSniff.cab (Symantec AntiVirus scanner)
O16 - DPF: {31435657-9980-0010-8000-00AA00389B71} http://download.micr...78f/wvc1dmo.cab (Reg Error: Key error.)
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} http://www.update.mi...b?1182302094468 (WUWebControl Class)
O16 - DPF: {644E432F-49D3-41A1-8DD5-E099162EEEC5} http://security.syma...n/bin/cabsa.cab (Symantec RuFSI Utility Class)
O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} http://www.update.mi...b?1182565904640 (MUWebControl Class)
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} http://java.sun.com/...indows-i586.cab (Java Plug-in 1.6.0_13)
O16 - DPF: {8FFBE65D-2C9C-4669-84BD-5829DC0B603C} http://fpdownload.ma...r/ultrashim.cab (Reg Error: Key error.)
O16 - DPF: {B1E2B96C-12FE-45E2-BEF1-44A219113CDD} http://www.superadbl...ivex/sabspx.cab (SABScanProcesses Class)
O16 - DPF: {CAFEEFAC-0016-0000-0007-ABCDEFFEDCBA} http://java.sun.com/...indows-i586.cab (Reg Error: Key error.)
O16 - DPF: {CAFEEFAC-0016-0000-0011-ABCDEFFEDCBA} Reg Error: Value error. (Reg Error: Key error.)
O16 - DPF: {CAFEEFAC-0016-0000-0013-ABCDEFFEDCBA} http://java.sun.com/...indows-i586.cab (Java Plug-in 1.6.0_13)
O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} http://java.sun.com/...indows-i586.cab (Java Plug-in 1.6.0_13)
O16 - DPF: {CCA0B877-CB5E-4ADC-AD30-457C379512DD} http://10.0.0.240/xplugLiteAL.cab (Gif89 Lite Class)
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} http://download.macr...ash/swflash.cab (Shockwave Flash Object)
O16 - DPF: {D4323BF2-006A-4440-A2F5-27E3E7AB25F8} http://a532.g.akamai...5/installer.exe (Virtools WebPlayer Class)
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 208.67.222.222 208.67.220.220 206.248.154.22
O18 - Protocol\Handler\http\0x00000001 {E1D2BF42-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files\Common Files\System\Ole DB\MSDAIPP.DLL (Microsoft Corporation)
O18 - Protocol\Handler\http\oledb {E1D2BF40-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files\Common Files\System\Ole DB\MSDAIPP.DLL (Microsoft Corporation)
O18 - Protocol\Handler\https\0x00000001 {E1D2BF42-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files\Common Files\System\Ole DB\MSDAIPP.DLL (Microsoft Corporation)
O18 - Protocol\Handler\https\oledb {E1D2BF40-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files\Common Files\System\Ole DB\MSDAIPP.DLL (Microsoft Corporation)
O18 - Protocol\Handler\ipp - No CLSID value found
O18 - Protocol\Handler\ipp\0x00000001 {E1D2BF42-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files\Common Files\System\Ole DB\MSDAIPP.DLL (Microsoft Corporation)
O18 - Protocol\Handler\linkscanner {F274614C-63F8-47D5-A4D1-FBDDE494F8D1} - C:\Program Files\AVG\AVG8\avgpp.dll (AVG Technologies CZ, s.r.o.)
O18 - Protocol\Handler\msdaipp - No CLSID value found
O18 - Protocol\Handler\msdaipp\0x00000001 {E1D2BF42-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files\Common Files\System\Ole DB\MSDAIPP.DLL (Microsoft Corporation)
O18 - Protocol\Handler\msdaipp\oledb {E1D2BF40-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files\Common Files\System\Ole DB\MSDAIPP.DLL (Microsoft Corporation)
O18 - Protocol\Handler\ms-help {314111c7-a502-11d2-bbca-00c04f8ec294} - C:\Program Files\Common Files\Microsoft Shared\Help\hxds.dll (Microsoft Corporation)
O18 - Protocol\Handler\mso-offdap {3D9F03FA-7A94-11D3-BE81-0050048385D1} - C:\Program Files\Common Files\Microsoft Shared\Web Components\10\OWC10.DLL (Microsoft Corporation)
O18 - Protocol\Handler\mso-offdap11 {32505114-5902-49B2-880A-1F7738E5A384} - C:\Program Files\Common Files\Microsoft Shared\Web Components\11\OWC11.DLL (Microsoft Corporation)
O18 - Protocol\Filter: - text/xml - C:\Program Files\Common Files\Microsoft Shared\OFFICE12\MSOXMLMF.DLL (Microsoft Corporation)
O20 - HKLM Winlogon: Shell - (Explorer.exe) - C:\WINDOWS\Explorer.exe (Microsoft Corporation)
O20 - Winlogon\Notify\!SASWinLogon: DllName - C:\Program Files\SUPERAntiSpyware\SASWINLO.dll - C:\Program Files\SUPERAntiSpyware\SASWINLO.dll (SUPERAntiSpyware.com)
O20 - Winlogon\Notify\AtiExtEvent: DllName - Ati2evxx.dll - C:\WINDOWS\System32\Ati2evxx.dll (ATI Technologies Inc.)
O20 - Winlogon\Notify\avgrsstarter: DllName - avgrsstx.dll - C:\WINDOWS\System32\avgrsstx.dll (AVG Technologies CZ, s.r.o.)
O24 - Desktop Components:0 (My Current Home Page) - About:Home
O28 - HKLM ShellExecuteHooks: {5AE067D3-9AFB-48E0-853A-EBB7F4A000DA} - C:\Program Files\SUPERAntiSpyware\SASSEH.DLL (SuperAdBlocker.com)
O28 - HKLM ShellExecuteHooks: {EDB0E980-90BD-11D4-8599-0008C7D3B6F8} - C:\Program Files\Qualcomm\Eudora\EuShlExt.dll (Qualcomm Inc.)
O30 - LSA: Authentication Packages - (relog_ap) - C:\WINDOWS\System32\relog_ap.dll (Acronis)
O31 - SafeBoot: AlternateShell - cmd.exe
O32 - HKLM CDRom: AutoRun - 1
O32 - AutoRun File - [2007/06/19 20:43:54 | 00,000,000 | ---- | M] () - C:\AUTOEXEC.BAT -- [ NTFS ]
O34 - HKLM BootExecute: (autocheck) - File not found
O34 - HKLM BootExecute: (autochk) - C:\WINDOWS\System32\autochk.exe (Microsoft Corporation)
O34 - HKLM BootExecute: (*) - File not found
O34 - HKLM BootExecute: (oodbs) - C:\WINDOWS\System32\oodbs.exe (O&O Software GmbH)
O34 - HKLM BootExecute: (lsdelete) - C:\WINDOWS\System32\lsdelete.exe ()

========== LOP Check ==========

[2009/07/04 11:45:50 | 00,000,000 | RH-D | M] -- C:\Documents and Settings\All Users\Application Data
[2009/02/13 22:29:44 | 00,000,000 | -H-D | M] -- C:\Documents and Settings\All Users\Application Data\{83C91755-2546-441D-AC40-9A6B4B860800}
[2008/08/19 20:31:17 | 00,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\Acronis
[2007/06/20 13:42:26 | 00,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\ashampoo
[2009/06/20 12:46:47 | 00,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\ATI
[2007/07/15 20:47:57 | 00,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\DeskSoft
[2007/09/14 15:27:13 | 00,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\Downloaded Installations
[2007/09/18 21:19:09 | 00,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\DVD Shrink
[2008/04/30 21:59:40 | 00,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\FlashFXP
[2007/10/16 16:29:20 | 00,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\FLEXnet
[2008/01/27 10:11:43 | 00,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\Insight Software
[2008/01/27 10:11:43 | 00,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\Insight Software Solutions
[2007/09/14 15:23:04 | 00,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\Installations
[2008/07/19 19:03:57 | 00,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\MAGIX
[2007/10/18 20:48:23 | 00,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\NCH Swift Sound
[2009/05/05 10:53:44 | 00,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\Palo Alto Software
[2009/05/05 10:51:07 | 00,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\PAS
[2008/09/07 13:43:45 | 00,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\PC Drivers HeadQuarters
[2007/09/14 15:30:59 | 00,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\PC Suite
[2008/03/22 21:56:36 | 00,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\Sierra
[2007/09/11 21:27:35 | 00,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\SlySoft
[2007/10/08 11:08:31 | 00,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\TamoSoft
[2009/07/11 10:21:47 | 00,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\TEMP
[2009/01/19 15:35:53 | 00,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\TomTom
[2008/12/22 08:46:28 | 00,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\vsosdk
[2008/09/03 11:19:55 | 00,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\WinZip
[2008/07/19 19:02:50 | 00,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\Xara
[2008/04/22 23:54:17 | 00,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\XemiComputers
[2009/07/11 23:09:59 | 00,000,000 | RH-D | M] -- C:\Documents and Settings\Johnnie\Application Data
[2008/09/28 14:53:52 | 00,000,000 | ---D | M] -- C:\Documents and Settings\Johnnie\Application Data\Accomplice
[2008/01/26 19:50:53 | 00,000,000 | ---D | M] -- C:\Documents and Settings\Johnnie\Application Data\ActiveDBSoft
[2008/11/05 16:34:40 | 00,000,000 | ---D | M] -- C:\Documents and Settings\Johnnie\Application Data\Ashampoo
[2009/06/20 12:46:47 | 00,000,000 | ---D | M] -- C:\Documents and Settings\Johnnie\Application Data\ATI
[2008/10/06 19:14:21 | 00,000,000 | ---D | M] -- C:\Documents and Settings\Johnnie\Application Data\BitTorrent
[2007/06/23 21:11:14 | 00,000,000 | ---D | M] -- C:\Documents and Settings\Johnnie\Application Data\Crystal Art Software
[2008/09/28 16:35:12 | 00,000,000 | ---D | M] -- C:\Documents and Settings\Johnnie\Application Data\CuteReminderEnt
[2007/09/11 22:14:20 | 00,000,000 | ---D | M] -- C:\Documents and Settings\Johnnie\Application Data\DAEMON Tools Pro
[2008/03/22 21:51:35 | 00,000,000 | ---D | M] -- C:\Documents and Settings\Johnnie\Application Data\DeskSoft
[2009/06/28 18:35:33 | 00,000,000 | ---D | M] -- C:\Documents and Settings\Johnnie\Application Data\Dexpot
[2009/07/07 10:00:06 | 00,000,000 | ---D | M] -- C:\Documents and Settings\Johnnie\Application Data\dvdcss
[2009/05/11 21:18:20 | 00,000,000 | ---D | M] -- C:\Documents and Settings\Johnnie\Application Data\DVDFab
[2007/06/23 21:34:27 | 00,000,000 | ---D | M] -- C:\Documents and Settings\Johnnie\Application Data\EmTec
[2008/06/03 21:01:44 | 00,000,000 | ---D | M] -- C:\Documents and Settings\Johnnie\Application Data\IrfanView
[2007/06/28 07:53:15 | 00,000,000 | ---D | M] -- C:\Documents and Settings\Johnnie\Application Data\Leadertech
[2008/07/19 19:03:57 | 00,000,000 | ---D | M] -- C:\Documents and Settings\Johnnie\Application Data\MAGIX
[2007/08/21 21:46:03 | 00,000,000 | ---D | M] -- C:\Documents and Settings\Johnnie\Application Data\MSNStockQuote
[2009/07/04 14:17:38 | 00,000,000 | ---D | M] -- C:\Documents and Settings\Johnnie\Application Data\NewzToolz
[2007/09/14 19:05:14 | 00,000,000 | ---D | M] -- C:\Documents and Settings\Johnnie\Application Data\Nokia
[2009/05/05 10:57:12 | 00,000,000 | ---D | M] -- C:\Documents and Settings\Johnnie\Application Data\Palo Alto Software
[2007/09/14 15:39:34 | 00,000,000 | ---D | M] -- C:\Documents and Settings\Johnnie\Application Data\PC Suite
[2008/01/26 19:52:25 | 00,000,000 | ---D | M] -- C:\Documents and Settings\Johnnie\Application Data\SAPIEN
[2007/09/11 21:32:39 | 00,000,000 | ---D | M] -- C:\Documents and Settings\Johnnie\Application Data\SlySoft
[2007/10/08 11:09:57 | 00,000,000 | ---D | M] -- C:\Documents and Settings\Johnnie\Application Data\TamoSoft
[2008/09/12 14:35:19 | 00,000,000 | ---D | M] -- C:\Documents and Settings\Johnnie\Application Data\TeamViewer
[2009/07/02 20:24:47 | 00,000,000 | ---D | M] -- C:\Documents and Settings\Johnnie\Application Data\Thinstall
[2009/01/19 15:32:23 | 00,000,000 | ---D | M] -- C:\Documents and Settings\Johnnie\Application Data\TomTom
[2008/08/10 19:42:11 | 00,000,000 | ---D | M] -- C:\Documents and Settings\Johnnie\Application Data\U3
[2008/12/17 18:01:34 | 00,000,000 | ---D | M] -- C:\Documents and Settings\Johnnie\Application Data\uTorrent
[2007/09/16 19:42:50 | 00,000,000 | ---D | M] -- C:\Documents and Settings\Johnnie\Application Data\Visual Money
[2007/12/16 13:29:59 | 00,000,000 | ---D | M] -- C:\Documents and Settings\Johnnie\Application Data\VoipStunt
[2009/07/05 07:26:29 | 00,000,000 | ---D | M] -- C:\Documents and Settings\Johnnie\Application Data\Vso
[2008/04/22 23:54:17 | 00,000,000 | ---D | M] -- C:\Documents and Settings\Johnnie\Application Data\XemiComputers
[2009/02/13 22:51:24 | 00,000,472 | ---- | M] () -- C:\WINDOWS\Tasks\Ad-Aware Update (Weekly).job
[2004/08/04 08:00:00 | 00,000,065 | RH-- | M] () -- C:\WINDOWS\Tasks\desktop.ini
[2009/02/01 20:18:11 | 00,000,294 | -H-- | M] () -- C:\WINDOWS\Tasks\Microsoft_Hardware_Launch_IPoint_exe.job
[2008/11/22 21:47:22 | 00,000,412 | ---- | M] () -- C:\WINDOWS\Tasks\Norton Security Scan for Johnnie.job
[2007/08/26 22:13:05 | 00,000,006 | -H-- | M] () -- C:\WINDOWS\Tasks\SA.DAT

========== Purity Check ==========



========== Alternate Data Streams ==========

@Alternate Data Stream - 164 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:DFC5A2B2
@Alternate Data Stream - 125 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:5C321E34
@Alternate Data Stream - 117 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:C8B8CEBD
< End of report >
  • 0

#4
andrewuk

andrewuk

    Trusted Helper

  • Malware Removal
  • 5,297 posts
ignore this post, see the post below . . . . . i managed to double post by mistake.

Edited by andrewuk, 12 July 2009 - 09:22 AM.

  • 0

#5
andrewuk

andrewuk

    Trusted Helper

  • Malware Removal
  • 5,297 posts
====STEP 1====
Run OTL.exe by double clicking the icon on your desktop
  • Under the Custom Scans/Fixes box at the bottom, paste in the following

    :OTL
    PRC - C:\WINDOWS\explorer.exe (Microsoft Corporation)
    O3 - HKCU\..\Toolbar\ShellBrowser: (no name) - {73C7D5B0-7B03-444A-84C7-CE1BA03B5573} - No CLSID value found.
    O16 - DPF: {2BC66F54-93A8-11D3-BEB6-00105AA9B6AE} http://security.symantec.com/sscv6/SharedC...bin/AvSniff.cab (Symantec AntiVirus scanner)
    O16 - DPF: {31435657-9980-0010-8000-00AA00389B71} http://download.microsoft.com/download/e/2...78f/wvc1dmo.cab (Reg Error: Key error.)
    O16 - DPF: {644E432F-49D3-41A1-8DD5-E099162EEEC5} http://security.symantec.com/sscv6/SharedC...n/bin/cabsa.cab (Symantec RuFSI Utility Class)
    O16 - DPF: {CAFEEFAC-0016-0000-0007-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-...indows-i586.cab (Reg Error: Key error.)
    O16 - DPF: {CAFEEFAC-0016-0000-0011-ABCDEFFEDCBA} Reg Error: Value error. (Reg Error: Key error.)
    O16 - DPF: {CCA0B877-CB5E-4ADC-AD30-457C379512DD} http://10.0.0.240/xplugLiteAL.cab (Gif89 Lite Class)
    
    :Reg
    [-HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{A185BBC1-0A7C-6EF7-3093-185B3CADBA08}]
    
    :Files
    C:\WINDOWS\Tasks\Norton Security Scan for Johnnie.job
    c:\windows\S033705C9.tmp
    c:\windows\system32:hqtray.exe
    c:\program files\Norton Security Scan
    
    :Commands
    [resethosts]
    [purity]
    [emptytemp]
    [start explorer]
    [Reboot]
  • Then click the Run Fix button at the top
  • Let the program run unhindered, reboot when it is done
  • Then post the log that it produces
====STEP 2====
Please download SystemLook from one of the links below and save it to your Desktop.
Download Mirror #1
Download Mirror #2

  • Double-click SystemLook.exe to run it.
  • Copy the content of the following codebox into the main textfield:
    :comment
    Make sure you copy *all* the text in this codebox.
    
    :filefind
    *system32:*
  • Click the Look button to start the scan.
  • When finished, a notepad window will open with the results of the scan. Please post this log in your next reply.
Note: The log can also be found on your Desktop entitled SystemLook.txt




====STEP 3====
i want to scan a file i do not recognise:
  • Please go to VirSCAN.org FREE on-line scan service
  • Copy and paste the following file path into the "Suspicious files to scan"box on the top of the page:

    • C:\Program Files\DynAdvance Notifier\MailNotifier.Exe
  • Click on the Upload button
  • Once the Scan is completed, click on the "Copy to Clipboard" button. This will copy the link of the report into the Clipboard. . . . . if the copy function does not work then copy the url link in your reply.
  • Paste the contents of the Clipboard in your next reply (you will need to paste the link onto a notepad before you do the other scans below, else the contents of your clipboard will be written over with the new links).
====STEP 4====
We will run OTL , but again go for a shortened log.
  • Close all windows and open it by double clicking on the icon
  • we are targetting a selective output, hence:
    • on the left hand side, in the box titled "Processes" select none
    • on the left hand side, in the box titled "Drivers" select none
    • on the left hand side, in the box titled "Extra Registry" select none
    • on the right hand side, in the box titled "Files created within" select none
    • on the right hand side, in the box titled "Files modified within" select none
    • tick both the boxes marked Purity check and Lop check
  • Click Run Scan and let the program run uninterrupted
  • It will produce one log for you called OTL.txt. Please post both that log here in reply.
  • You may need to use two posts to get it all on the forum
In your next reply could i see:
1. the OTL log from Step 1
2. the systemlook.txt log
3. the virscan log or link
4. the OTL log from Step 4

The text from these files may exceed the maximum post length for this forum. Hence, you may need to post the information over 2 or more posts.

andrewuk
  • 0

#6
JohnnieF

JohnnieF

    Member

  • Topic Starter
  • Member
  • PipPip
  • 32 posts
All processes killed
========== OTL ==========
No active process named explorer.exe was found!
Registry value HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Toolbar\ShellBrowser\\{73C7D5B0-7B03-444A-84C7-CE1BA03B5573} deleted successfully.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{73C7D5B0-7B03-444A-84C7-CE1BA03B5573}\ not found.
Starting removal of ActiveX control {2BC66F54-93A8-11D3-BEB6-00105AA9B6AE}
C:\WINDOWS\Downloaded Program Files\avsniff.inf moved successfully.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Code Store Database\Distribution Units\{2BC66F54-93A8-11D3-BEB6-00105AA9B6AE}\ deleted successfully.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{2BC66F54-93A8-11D3-BEB6-00105AA9B6AE}\ deleted successfully.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Active Setup\Installed Components\{2BC66F54-93A8-11D3-BEB6-00105AA9B6AE}\ not found.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{2BC66F54-93A8-11D3-BEB6-00105AA9B6AE}\ not found.
Starting removal of ActiveX control {31435657-9980-0010-8000-00AA00389B71}
C:\WINDOWS\Downloaded Program Files\wvc1dmo.inf moved successfully.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Code Store Database\Distribution Units\{31435657-9980-0010-8000-00AA00389B71}\ deleted successfully.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{31435657-9980-0010-8000-00AA00389B71}\ not found.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Active Setup\Installed Components\{31435657-9980-0010-8000-00AA00389B71}\ not found.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{31435657-9980-0010-8000-00AA00389B71}\ not found.
Starting removal of ActiveX control {644E432F-49D3-41A1-8DD5-E099162EEEC5}
C:\WINDOWS\Downloaded Program Files\CabSA.inf moved successfully.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Code Store Database\Distribution Units\{644E432F-49D3-41A1-8DD5-E099162EEEC5}\ deleted successfully.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{644E432F-49D3-41A1-8DD5-E099162EEEC5}\ deleted successfully.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Active Setup\Installed Components\{644E432F-49D3-41A1-8DD5-E099162EEEC5}\ not found.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{644E432F-49D3-41A1-8DD5-E099162EEEC5}\ not found.
Starting removal of ActiveX control {CAFEEFAC-0016-0000-0007-ABCDEFFEDCBA}
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Code Store Database\Distribution Units\{CAFEEFAC-0016-0000-0007-ABCDEFFEDCBA}\ deleted successfully.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{CAFEEFAC-0016-0000-0007-ABCDEFFEDCBA}\ not found.
Registry key HKEY_CURRENT_USER\SOFTWARE\Classes\CLSID\{CAFEEFAC-0016-0000-0007-ABCDEFFEDCBA}\ deleted successfully.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Active Setup\Installed Components\{CAFEEFAC-0016-0000-0007-ABCDEFFEDCBA}\ not found.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{CAFEEFAC-0016-0000-0007-ABCDEFFEDCBA}\ not found.
Starting removal of ActiveX control {CAFEEFAC-0016-0000-0011-ABCDEFFEDCBA} Reg Error: Value error.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Code Store Database\Distribution Units\{CAFEEFAC-0016-0000-0011-ABCDEFFEDCBA} Reg Error: Value error.\ not found.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{CAFEEFAC-0016-0000-0011-ABCDEFFEDCBA} Reg Error: Value error.\ not found.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Active Setup\Installed Components\{CAFEEFAC-0016-0000-0011-ABCDEFFEDCBA} Reg Error: Value error.\ not found.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{CAFEEFAC-0016-0000-0011-ABCDEFFEDCBA} Reg Error: Value error.\ not found.
Starting removal of ActiveX control {CCA0B877-CB5E-4ADC-AD30-457C379512DD}
C:\WINDOWS\Downloaded Program Files\xplugLiteAL.inf moved successfully.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Code Store Database\Distribution Units\{CCA0B877-CB5E-4ADC-AD30-457C379512DD}\ deleted successfully.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{CCA0B877-CB5E-4ADC-AD30-457C379512DD}\ deleted successfully.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Active Setup\Installed Components\{CCA0B877-CB5E-4ADC-AD30-457C379512DD}\ not found.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{CCA0B877-CB5E-4ADC-AD30-457C379512DD}\ not found.
========== REGISTRY ==========
Registry key HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{A185BBC1-0A7C-6EF7-3093-185B3CADBA08}\ deleted successfully.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{A185BBC1-0A7C-6EF7-3093-185B3CADBA08}\ not found.
========== FILES ==========
C:\WINDOWS\Tasks\Norton Security Scan for Johnnie.job moved successfully.
File move failed. c:\windows\S033705C9.tmp scheduled to be moved on reboot.
File\Folder c:\windows\system32:hqtray.exe not found.
c:\program files\Norton Security Scan moved successfully.
========== COMMANDS ==========
C:\WINDOWS\System32\drivers\etc\Hosts moved successfully.
HOSTS file reset successfully

[EMPTYTEMP]

User: Administrator
->Temp folder emptied: 0 bytes
->Temporary Internet Files folder emptied: 0 bytes

User: All Users

User: Default User
->Temp folder emptied: 0 bytes
->Temporary Internet Files folder emptied: 0 bytes

User: Johnnie
->Temp folder emptied: 158960 bytes
File delete failed. C:\Documents and Settings\Johnnie\Local Settings\Temporary Internet Files\Content.IE5\XUSRZF2O\00RX0CAQW462VCAFIDEQTCA4OZ6Q3CA6BB1BRCA5UYURYCA0F54MMCAEAM6M4CAGU3965CA7UAC4MCAR520SNCA62AZW3CA2Q
VVO0CAKPYP57CAYHT3X2CARFY5C9CAV7R883CAXVQFYWCAE9C1KGCA0OS9GVCA4SGN4GCA8AZYWH scheduled to be deleted on reboot.
File delete failed. C:\Documents and Settings\Johnnie\Local Settings\Temporary Internet Files\Content.IE5\XUSRZF2O\15AXTCARDKYZZCACK1VT0CARRRHRICAB4VE1TCAB3H03ECAP4MF32CAAJ1JYTCAJLI4EVCA1AGG03CA8XOD0NCAVKRJL7CA
WGRZEFCAS7UHI6CAB517ZDCACFLK44CAQXB1CICAIIMJZRCAX1B074CAL988OVCAWYYHD4CAYY56BA scheduled to be deleted on reboot.
File delete failed. C:\Documents and Settings\Johnnie\Local Settings\Temporary Internet Files\Content.IE5\XUSRZF2O\2ZMLYCAH4MU0ICAD66ZBRCAB7UY4LCAXDJQGCCA5HGZZWCAF0QONQCA1YP89SCA14PCR7CAWFJ6RLCANYYX36CASCS0BWCA
X8471OCAV973D7CAXRC0SVCAEGCOL8CA6EVMNCCAGOSQ99CAJQI6JJCACJJRV8CAKBEILKCATDG82I scheduled to be deleted on reboot.
File delete failed. C:\Documents and Settings\Johnnie\Local Settings\Temporary Internet Files\Content.IE5\XUSRZF2O\30L2XCAZA6YLZCA5HUTKKCAJQAYKHCAG70Q8QCAXLNPMXCAUXO1A0CAX2YHYACAWO7ESWCA67WJ2YCAPUS38TCA1BDQQ8CA
CCMOKPCA6TDMOFCAWAX4JGCAJVUZIUCA00L7Z9CAFUA2ZBCAC86H3SCA7NTLTICAVKMR4PCAO1VASV scheduled to be deleted on reboot.
File delete failed. C:\Documents and Settings\Johnnie\Local Settings\Temporary Internet Files\Content.IE5\XUSRZF2O\3G7QKCA7MTE0GCASDXAJYCA0242TTCABT5HWFCAGVLA9BCAPH7HISCAFO0DTGCA0AU233CAR3F80HCA421XS5CACYJ1FRCA
UF5U09CA8YE2SXCA2N2VVZCA2R2H5MCA6R3E2ICAJ60NBKCA1XZDRRCAF2DPPFCA8K4OKDCAKHSL2H scheduled to be deleted on reboot.
File delete failed. C:\Documents and Settings\Johnnie\Local Settings\Temporary Internet Files\Content.IE5\XUSRZF2O\3WFQOCARV375RCAFRDFE3CAA3SIJ6CAB6843XCA8K9NV7CA2AS32KCAOB626RCAFL37IJCAV4SZGVCAH9967JCA221EAFCA
WQCSJRCA7V84O0CAPZZFIMCAGAUU6QCAV0PK86CAJ96BBACA9AWJN1CA4SXBLXCA3IPRZXCABTHP1X scheduled to be deleted on reboot.
File delete failed. C:\Documents and Settings\Johnnie\Local Settings\Temporary Internet Files\Content.IE5\XUSRZF2O\6304JCAV5JH1VCAVJJD9NCAK47RSRCAEOF23PCA3EN04KCA225F0ECA52F0GNCAZQFHB9CABFDCGUCABITCDJCAITC15YCA
A8EB23CA2LDF1DCA5NDVT1CA1JVDJRCAOEU28KCAW4CRY3CA6L07PLCAJ3TDYLCAHKG6ZECAAAE093 scheduled to be deleted on reboot.
File delete failed. C:\Documents and Settings\Johnnie\Local Settings\Temporary Internet Files\Content.IE5\XUSRZF2O\69R3CCA0RJXDRCAS23PE9CA2QPD0YCA120OUWCA61598ZCAXVPBZ7CAZOND9QCAO2VWX0CASK3B9TCAF0WNRSCAXCI0ETCA
S6U44YCAWMDIXUCAA3KNM5CA23Z34ACAAHCF7PCAQ0BLVGCAOYQ3MOCATVZV3DCAVFC2S1CAVV3LQS scheduled to be deleted on reboot.
File delete failed. C:\Documents and Settings\Johnnie\Local Settings\Temporary Internet Files\Content.IE5\XUSRZF2O\71J4GCAHXIYL1CAQZBLBVCAEX173VCANZIA7MCAHV7RETCA111JEBCAQL89GWCA3H9CGMCA3KRPA5CATOCNOZCA6UK8AOCA
10PNRGCA5NPU3OCA6QI8V1CA8U50AUCANGCKYXCASGEWRHCANY1DQICAGBALUVCADH5I14CAVYOVR5 scheduled to be deleted on reboot.
File delete failed. C:\Documents and Settings\Johnnie\Local Settings\Temporary Internet Files\Content.IE5\XUSRZF2O\72RV5CA52T5JACA7I242XCANUCQ3BCAAQJLIDCABV0U98CA9CS65YCAIMKJJPCAWZDGK4CAK9GV2XCA0AUFBLCAICXORQCA
8XV1PECAXZRTWGCAJY1M48CAQT615MCASLX2C8CADJ51XRCA0V8WBECAMC7BNNCAWDYGJ7CA7XQFP9 scheduled to be deleted on reboot.
File delete failed. C:\Documents and Settings\Johnnie\Local Settings\Temporary Internet Files\Content.IE5\XUSRZF2O\76EHKCASO2EWHCA8UFR7LCAB4HSSWCASE1VTICABSHD3HCA04Y22ZCA1JIGKBCACY7FMACAGCMTXZCAH35NEFCA1907CMCA
YF26OACABDIMFTCA7QJCTLCA4LQ9PUCA1QZFVPCA8EWPBLCAV7CTX2CAXRNU77CA37L39FCA99587R scheduled to be deleted on reboot.
File delete failed. C:\Documents and Settings\Johnnie\Local Settings\Temporary Internet Files\Content.IE5\XUSRZF2O\7NJ74CA101QKRCA1CFFUYCAWXPFQPCA4SNQFNCALZP1NSCA64YY1SCANBASGPCAV4P0VPCAUE6QCHCAMMS31BCAH21L1BCA
BBRAZ1CA5W7R24CAVAPG9VCAN3E8NNCABMU19YCAR2XSL3CAD0FJ4ECA9T2W06CAKZPHQGCA5BFQ1V scheduled to be deleted on reboot.
File delete failed. C:\Documents and Settings\Johnnie\Local Settings\Temporary Internet Files\Content.IE5\XUSRZF2O\AAAAAAAAAAAAAAAAA6jgMAAAAAAAIAAwAAAAAAT38nPiIBAAAAAAAAAAA.CpYE2d06AAAAsJu.6yoAAADwwmFTAAAAAKibv-sqAAAAAAAAAAAAAAA=,,http%3A%2F%2Fad.harrenmedianetwork[1].com%2F,;ord=1246583291 scheduled to be deleted on reboot.
File delete failed. C:\Documents and Settings\Johnnie\Local Settings\Temporary Internet Files\Content.IE5\XUSRZF2O\AAAAAAAAAAAAAAAAAAAAADwLAQAAAAAAAIAAgAAAAAAw7ImPiIBAAAAAAAAAAC.apYECVQ8AAAAMNErnyoAAADwMsNhAAAA
ACjRK58qAAAAAAAAAAAAAAA=,,http%3A%2F%2Fad.media-servers[1].net%2F,;ord=1246583239 scheduled to be deleted on reboot.
File delete failed. C:\Documents and Settings\Johnnie\Local Settings\Temporary Internet Files\Content.IE5\XUSRZF2O\AAAAAAAAAAAAAAAABRAwQAAAAAAAIAAwAAAAAA.w8qPiIBAAAAAAAAAAAAAJYEeRE0AAAAMCFboSoAAADw8kFVAAAAACghW
6EqAAAAAAAAAAAAAAA=,,http%3A%2F%2Fad.harrenmedianetwork[1].com%2F,;ord=1246583459 scheduled to be deleted on reboot.
File delete failed. C:\Documents and Settings\Johnnie\Local Settings\Temporary Internet Files\Content.IE5\XUSRZF2O\AQYAQCAYZ7WWOCAQ75OFFCA79DZKQCA7B8I0JCA4OI7NQCAK6NKWYCAZ3YHBNCAX3F6SRCA06RRSBCAGM03UTCARVTGP9CA
5AML5LCAJ9XB6TCA8CCLAWCAAAMXG5CAXI6X2VCA4BJ3Z5CAMDMYM8CARBQ0NICA596174CAFXYB10 scheduled to be deleted on reboot.
File delete failed. C:\Documents and Settings\Johnnie\Local Settings\Temporary Internet Files\Content.IE5\XUSRZF2O\CQRULCAPQYYDDCACFANYECA3QVBQ5CAAZINDYCA7KR485CAJZEZ1RCAX0R7YRCAHX7HRICA0FZ7W2CAOPUETDCAY97VF3CA
LWEXCGCACKONQACAIXOBI7CA8AQABLCA45YWO3CA2L2AHYCA93292HCAI78Z8ACA30TPDJCA0NT6WS scheduled to be deleted on reboot.
File delete failed. C:\Documents and Settings\Johnnie\Local Settings\Temporary Internet Files\Content.IE5\XUSRZF2O\DABEDCAWFG4PNCAA4F487CAJQ7Z7DCA8B30GSCA97GH53CAYBXDO1CARKC1RKCAKHMFXTCAM4R122CAW73R8WCA8UBR6JCA
ZCQUDBCA97BRG1CA7WD09JCAE4WV7SCAL2U2ELCAGRLQXTCA059NZOCAYV6WM5CAP6AZF9CAVK4S2V scheduled to be deleted on reboot.
File delete failed. C:\Documents and Settings\Johnnie\Local Settings\Temporary Internet Files\Content.IE5\XUSRZF2O\DVY4YCAYJRMDZCAGL9L0FCAMT09CUCA0TR72XCA85MTNRCALO5LD0CA070UQZCA48RVNGCAYYXPE1CAMOCDJCCALT8LDVCA
SWKWMECAZ0HSICCAXPWGGTCACMQEPUCAWA3DETCA0HFQD0CA3YDMEOCA5Y2E06CAG1IEITCADPSLXH scheduled to be deleted on reboot.
File delete failed. C:\Documents and Settings\Johnnie\Local Settings\Temporary Internet Files\Content.IE5\XUSRZF2O\EFFT0CADUK6WHCA3HMAK0CA67XJHKCAYTCQIPCAS11JW3CA9N1RTECAM3OKY9CA8K31V6CA12SEW8CA4GGF20CAU37X6ICA
3E4LJJCA2CSPFPCAK10HWDCAQ4KXAACAAEU3SCCA9AN24SCAORZINOCAA8FJNTCA2PEKFYCABXGZ7R scheduled to be deleted on reboot.
File delete failed. C:\Documents and Settings\Johnnie\Local Settings\Temporary Internet Files\Content.IE5\XUSRZF2O\ENL6PCAX8LVR0CAW124YBCAEPYJVZCADXREY7CA1OB5C2CAWEK7WACA10OHTWCAKWH3AWCAXTSVP5CAZMM04XCAN0POJ1CA
DDG2F4CAEBXJW1CAV23LXDCAB0MDDICA4WPV7QCAB0HM8ACA8JNICZCAKTL4I4CA82WISSCAKDUVXI scheduled to be deleted on reboot.
File delete failed. C:\Documents and Settings\Johnnie\Local Settings\Temporary Internet Files\Content.IE5\XUSRZF2O\F0IGKCA7W5TV1CAL5CQM0CAIV3D5RCAWG4XXBCAIS13Y2CAJ23PPVCAVTALDSCAXE95TCCAZWUF0HCA3OZ0AECA0PSCKPCA
JO6G7ECA1JNW2KCA14OQ2SCAO500IDCA557O24CAQ20RG3CAXG85IPCA6BCAAECANSJBD7CAH3BW0E scheduled to be deleted on reboot.
File delete failed. C:\Documents and Settings\Johnnie\Local Settings\Temporary Internet Files\Content.IE5\XUSRZF2O\G7XXCCA4W0YNBCA62B0QVCAT29PTUCAC4HIJ4CAU80W0TCALSMULXCAA4OAVPCADBH9K9CA7K129BCAJ45TS0CAQ335RVCA
ZSPTEJCAS3FGW0CAFHYRHPCAGGN19PCAMQQL13CAVBV1NQCA731265CAHGTUJSCA5PJTSYCA60OIQW scheduled to be deleted on reboot.
File delete failed. C:\Documents and Settings\Johnnie\Local Settings\Temporary Internet Files\Content.IE5\XUSRZF2O\HHYA4CAZV7EU0CA9P7WX3CAFVTSVDCACLF5C3CAI8FBK9CAI6S992CA2KACT6CAQT2F3VCA72XMYDCAJQZWTKCA039V7ACA
QRXV5SCAL2OEK2CAQQS7PYCAK4WHVECAN4H6IRCASM2M6ECAVJBXZICAFA2OMNCAPT90TTCA2AVY0Q scheduled to be deleted on reboot.
File delete failed. C:\Documents and Settings\Johnnie\Local Settings\Temporary Internet Files\Content.IE5\XUSRZF2O\JJ48TCA3DOK9GCAHDWSE0CANQB0CLCAFFCLWOCAHX1MFLCAHLXU6ZCAU7RZF8CABUSCQACA7XFKN8CAWHLNJTCA1XD4G5CA
9MJ1IICA0FWWFXCA9VTW4NCA8N6YH1CA900DE4CAQ2G39ICAG9SLZDCA0QH4KMCAKL28JWCAWPU62L scheduled to be deleted on reboot.
File delete failed. C:\Documents and Settings\Johnnie\Local Settings\Temporary Internet Files\Content.IE5\XUSRZF2O\KOHRACAPCJ2VBCA925ZM6CAAPRBV1CA9HYJLTCAR2CS1DCAO1872LCAZVG7YNCAIM3L8SCA1AYB4ECA32BJUNCA9I3RVDCA
T1VFN6CA6M05G8CA7VAPAWCAOOUQ7DCA1SAQKFCATDQ88HCAV366ADCAN0UQMDCATC9VF3CA5ATHWJ scheduled to be deleted on reboot.
File delete failed. C:\Documents and Settings\Johnnie\Local Settings\Temporary Internet Files\Content.IE5\XUSRZF2O\LRM1VCA1ZKDI7CAZWXXZJCAYVTZKFCA32ZVQ8CAWK2PZWCARVE60LCAAI75PUCAPMNZRDCA7SE80ZCAVTYF5BCAS3EJQWCA
F9MPG8CATS8JE6CAX2G7A3CAZE62J9CAL17S1MCAVTWUG4CAZQDMTBCA28IS4PCAR9GA7UCATTB9A0 scheduled to be deleted on reboot.
File delete failed. C:\Documents and Settings\Johnnie\Local Settings\Temporary Internet Files\Content.IE5\XUSRZF2O\MH3QXCAXQO3PXCAH7J65QCAQVF0E3CAGAMRL5CA64FEY4CAX0FM4PCAJ8I4YMCAUQOMBWCA1MBUZGCAZ0KV0MCAOV3N8CCA
OCDXY8CAVM17AWCAQXZ3T0CAU9HWP0CAM15K0ECANN3LYTCA4TMY0ACAS80L2QCASWWE6NCA18JWUB scheduled to be deleted on reboot.
File delete failed. C:\Documents and Settings\Johnnie\Local Settings\Temporary Internet Files\Content.IE5\XUSRZF2O\NB93LCAUQABRTCA5Z1U8DCAI3OOU8CAEAUAI0CAA8J8MNCAK925X5CAYLWSXUCAPEFD5OCAXYOGEKCANZPMVMCA8DEBRECA
XTGEOACAQPS67CCAY2Z8UTCAUHV21TCAEMTBCNCAUF1O8MCA3R8ZCICA9NBGOECA63ZAFACAMH29RK scheduled to be deleted on reboot.
File delete failed. C:\Documents and Settings\Johnnie\Local Settings\Temporary Internet Files\Content.IE5\XUSRZF2O\OUUAECAXK469ZCAG4JRSQCAT5EZOQCADE9XGTCA48WKYNCAQA99BZCAQCORMUCASJ3OE4CAGAP21TCAW760KJCAHR1VBDCA
NGKSF9CA34HUQACAZLQ7AGCAXVJKYNCA3P3S3QCA30SPBCCAEJVQQVCACXRGZICA98GC14CANSSQHO scheduled to be deleted on reboot.
File delete failed. C:\Documents and Settings\Johnnie\Local Settings\Temporary Internet Files\Content.IE5\XUSRZF2O\RD41RCAGODJFDCANGF1DUCA314T4CCAE00S4JCA6X1CV7CA2J5RXKCAI6NVL9CA0QFCZYCARDFHOYCAHOZ4TQCA6TLTTGCA
WSP6R0CAIB204MCAHGFUT5CAQ1EHEGCATL6G46CAAT5WW9CAPJ0P62CAI47U5UCAFXPSJNCAGXU3NN scheduled to be deleted on reboot.
File delete failed. C:\Documents and Settings\Johnnie\Local Settings\Temporary Internet Files\Content.IE5\XUSRZF2O\RL3OJCARY97POCA5KS1I5CABEZALMCACSV6NWCAHCWLEGCA7248JECAIM50JTCALBSE74CA7QABB0CAKB4MA3CA7M5OCBCA
W33HRPCAZKKKH8CA0983I4CABKKZAMCAWA90GDCAX81VXKCASOMTSCCAWK8LTTCA92T0C3CA70ACYH scheduled to be deleted on reboot.
File delete failed. C:\Documents and Settings\Johnnie\Local Settings\Temporary Internet Files\Content.IE5\XUSRZF2O\SCBDFCAWCPN5FCAZ1WGPHCA8N781XCA5GK0R2CADUKRHCCAEU945TCANXU39QCA83TEMZCAFP6XO2CAYHELXZCAKRXGWCCA
8GFB7RCAWCOIMUCAP34U5CCAHFHKBQCAONJITZCA8GDNQFCAZZ8A7CCA9HVQ77CAV5L25VCAPDQ93M scheduled to be deleted on reboot.
File delete failed. C:\Documents and Settings\Johnnie\Local Settings\Temporary Internet Files\Content.IE5\XUSRZF2O\THXBGCAIIQLJ2CAOC6M5KCANKYBW1CACLNVUCCA1Q3ISQCA6PGAE6CAH4ENLECAIT59QFCA1SWFXRCAI8GXQTCA1ZW830CA
05MEZKCA688HL6CAE3O819CARU34MXCAPB6NNZCAGAJ9RICAPO5H2VCA2J2B0TCAPYKLQ8CA05267S scheduled to be deleted on reboot.
File delete failed. C:\Documents and Settings\Johnnie\Local Settings\Temporary Internet Files\Content.IE5\XUSRZF2O\UCJ8CCAYIIA01CAUBUN05CAG2ZHF3CA7HVAB7CAQ4UDBJCAQ1TK0RCAZ0JSGUCA9HQ2XUCAPJKGUGCAVS3U6SCAVDSG8KCA
09K6IPCA7NM3UICAW3LA1GCA974KSACAXAQ9FWCAEV42Q8CAJQI304CA1H4R3QCA2LJG0OCAWWU8GL scheduled to be deleted on reboot.
File delete failed. C:\Documents and Settings\Johnnie\Local Settings\Temporary Internet Files\Content.IE5\XUSRZF2O\UVPFCCA55KE3ECA0ZFBAKCARXB9N8CANDJLQ8CAZG02QPCAO0RZR3CA55RSYDCAIY1159CAP2Y47WCAGL1XIZCAFSZVEQCA
NTU8U3CAZ2NHCDCAB1VJ2GCAQ44I3LCAGJIZRJCAHJ7WCFCAYR8T1RCAWIEYEICAPYV46NCA5HDK1H scheduled to be deleted on reboot.
File delete failed. C:\Documents and Settings\Johnnie\Local Settings\Temporary Internet Files\Content.IE5\XUSRZF2O\V9UXICAXESVXLCAICAB3UCA4KFQMWCA11MPI6CAD53G2XCA8VN468CAE92IW1CANL24IHCAIA1OQLCAV6O2CBCA2AUENBCA
GT9YD4CAE1ND8PCA8744FUCAGWM0GSCA8MZ2V5CAY8DHS2CAQ68JKCCAT37QSRCA65FN7ECA79AW59 scheduled to be deleted on reboot.
File delete failed. C:\Documents and Settings\Johnnie\Local Settings\Temporary Internet Files\Content.IE5\XUSRZF2O\VCKPZCABM39O2CALP2SDQCA5LNP6LCA8EUHI1CABLQF70CAK8AZZGCAW32RJ1CA10ZPDYCAFGLJ3QCAP2OXAFCAPAT1VECA
SKDO11CAAFJVRPCAN9F6B3CAZ3ELY3CA4JJ3GPCAOQ9S6OCAORA9ZQCA4KYKZRCAYQBZR2CAGPE2LW scheduled to be deleted on reboot.
File delete failed. C:\Documents and Settings\Johnnie\Local Settings\Temporary Internet Files\Content.IE5\XUSRZF2O\VCNATCAY4XMO2CAPFJVTTCAB223S4CAEQEELYCAF79YS3CASHSQOVCAU7BCUICADUTPWLCAB6A07UCA23XXXCCA6PE6GSCA
25L3K7CAF17GMGCARF8JR2CAZZR53KCAMPXXIPCA71L96FCACWHF0XCA04N5D7CAZICZ3ECANJ2D8E scheduled to be deleted on reboot.
File delete failed. C:\Documents and Settings\Johnnie\Local Settings\Temporary Internet Files\Content.IE5\XUSRZF2O\W60TDCARL9ZM8CAQWHAC9CA7LCWQACAJLN0PHCACNE69CCAJ4G2KGCA7NQL72CAXU9E6JCAFZXPG6CAMQFLMRCAGRDP36CA
P4TRJYCAB70XPSCAIXBXW8CA2ED0X8CARHLAP4CAFP29I8CAXEPR1CCAIU65T8CAEKL7AMCAIKD5BO scheduled to be deleted on reboot.
File delete failed. C:\Documents and Settings\Johnnie\Local Settings\Temporary Internet Files\Content.IE5\XUSRZF2O\WK2K2CA82F3BXCABSNFVQCASKZSKNCAJI7AM4CAYR834LCATPOZBZCA0MBEQ6CAKCV220CARLBCVBCAU3JRGCCA3YS493CA
SH9BDXCAY80AEFCAN2RLWZCAPWJ7F6CAMVEHYVCA0BHF0OCAV5770KCAE3X7D8CAF654MZCAB1IGU0 scheduled to be deleted on reboot.
File delete failed. C:\Documents and Settings\Johnnie\Local Settings\Temporary Internet Files\Content.IE5\XUSRZF2O\WSMP4CA3PMMPQCAIMGG78CAENNPA8CATJCNYVCAWBR4LHCA4TB977CAONHKVICAV6JR4YCA7PCSZQCA2F5KHOCA64WWMUCA
EGPOUKCA6X3JXXCAL8Z2XOCA9SRQ5ECAAU4MCECAEQBHGJCATHVV7QCAV4KB9NCAKEPWPVCADZBU6K scheduled to be deleted on reboot.
File delete failed. C:\Documents and Settings\Johnnie\Local Settings\Temporary Internet Files\Content.IE5\XUSRZF2O\XAJO1CAS4TWU9CARGSNPLCAQFZ47LCAQXUFH5CAN4VY1JCAFXE9DBCAP6M1IZCAGAY2SWCA3WGGPNCA0D89FACA050HL5CA
9LN6DICAD9R5OBCAZLF07TCAHXKK34CAX1X7UMCA53KVTZCASZ7ZKZCATXEZT5CA1DQXZJCADNA8QC scheduled to be deleted on reboot.
File delete failed. C:\Documents and Settings\Johnnie\Local Settings\Temporary Internet Files\Content.IE5\XUSRZF2O\XIB67CAM3MH3UCAFLPZWRCA3TZPUWCAVBV2SNCAL4F22VCATK9DR5CAOQL1HGCAFLOBRQCAWWMBK1CAANXPMVCABFSGFECA
O33DQ9CANBBMQBCAS0Q3L2CALMPOBCCARJU17RCA25MW41CAQWW4MNCAE7OW22CANLM1RECA9ZW1ZC scheduled to be deleted on reboot.
File delete failed. C:\Documents and Settings\Johnnie\Local Settings\Temporary Internet Files\Content.IE5\R0CZ6CEL\02TY8CAPC6FO4CAKF69EXCAAF489TCAYI00ZECAW21RJWCAW8L72QCAAIRWC1CA8KW5BQCABN4JEJCAO9P0R7CA2IKOKZCATJ
6BWCCA2ZGBEVCAEIQAYJCALNRDAECAD9O1LCCAVTCFEACAFF8I16CA67WCX4CAX94O0FCAEXJG44 scheduled to be deleted on reboot.
File delete failed. C:\Documents and Settings\Johnnie\Local Settings\Temporary Internet Files\Content.IE5\R0CZ6CEL\131X9CAMLPH4MCA52T32RCAF4JA0FCADLPJFZCA3X9YUQCAGT05LFCAVP56U7CAMKHQZHCA3OI8J3CAKAMY66CAY1KNMDCA
V730UXCA3XY6CNCAK9V2K7CAV7750HCAZMOH5ECAOS3QRACA149C1OCAUICQ9VCAILZS7KCAEFRXX1 scheduled to be deleted on reboot.
File delete failed. C:\Documents and Settings\Johnnie\Local Settings\Temporary Internet Files\Content.IE5\R0CZ6CEL\1MQX1CADDOBU3CAEC5T59CAA44LCXCA1ZO8MJCAER26X7CAY1CCR6CA1UBEMPCAH429W8CA021Y57CA9PGC79CAZX100NCA
X9MXO0CA2TQOEXCA9AN8WGCA3V0RS6CASR1JTLCA4UA8EKCA0OBB4MCAMUZF7UCA3PFX2HCA3AAMPI scheduled to be deleted on reboot.
File delete failed. C:\Documents and Settings\Johnnie\Local Settings\Temporary Internet Files\Content.IE5\R0CZ6CEL\1SN81CAWOPO33CA05WN4MCAN21RFSCAUROZULCA9WUB3YCA2FFPR1CAX8FUDOCAKFFGUUCAWFKIGPCA0VZ6Y4CAQLZDO9CA
K4B6HZCACI3QZ2CAL91EALCAIZDHXFCA33WZ9VCA30HQ8VCACVN3HTCA3QZIVECAR7W693CATU2V9C scheduled to be deleted on reboot.
File delete failed. C:\Documents and Settings\Johnnie\Local Settings\Temporary Internet Files\Content.IE5\R0CZ6CEL\2ZTQECAR25C23CA4234C5CAUI16O1CANXI7IWCAYILPVCCABD7XPKCAOBBG50CACH79W2CABDXC1WCAZG88Y9CAMGSRLSCA
CLW0XKCA1ZX5QMCA80H607CA5UMVBDCA7PXF72CAUOCL8UCA829DQICAH8JKKOCAKXQCUMCA1GFNOZ scheduled to be deleted on reboot.
File delete failed. C:\Documents and Settings\Johnnie\Local Settings\Temporary Internet Files\Content.IE5\R0CZ6CEL\43WK8CAU6L1SPCANF1PLZCAM032CVCAIBHVIGCADJP4POCAXAW1W1CAFK5911CA15VA9GCAIDNSORCAPKWUCGCA2ZGAFTCA
LAMYI7CA0U8X1VCAYDNHC9CA3QCAXNCA23T0SXCATACRGDCAFPRMM6CARKDSTWCA4E5VIJCAK6DR9W scheduled to be deleted on reboot.
File delete failed. C:\Documents and Settings\Johnnie\Local Settings\Temporary Internet Files\Content.IE5\R0CZ6CEL\44H9GCADBKABYCAL1O1MKCAJ27ESSCAKVTG58CAQLYDVUCAV7LUBLCA0WCJV6CAFFQEDKCAKJUJRXCASAGLKNCAMT7AIGCA
B3SB43CADEDVA2CAFQPEEXCAF6PWLKCA25N3ONCAY2FU2TCAT283HDCA8U01BHCABNLSFYCA5CYLJD scheduled to be deleted on reboot.
File delete failed. C:\Documents and Settings\Johnnie\Local Settings\Temporary Internet Files\Content.IE5\R0CZ6CEL\51UN5CAYVOMFICA0F5MMZCAILPEM1CA56GE24CAIADDVMCACSK7CLCA826M5QCAGW4JKKCAIR1P79CA6C01HHCAIALL33CA
WNYB5OCAEFA1U3CAGUU3G5CA4QSDRICAIKUSXICA61C6DYCAHV4A4DCA2XR7GYCAMEXJOTCA6GR1XJ scheduled to be deleted on reboot.
File delete failed. C:\Documents and Settings\Johnnie\Local Settings\Temporary Internet Files\Content.IE5\R0CZ6CEL\8BCHECA8D0GXCCA9TFZQGCA10U5G3CAQI0FKXCANIEXNECA080YS2CAM3SX0GCA87PZXOCAYJHD56CAPZXS00CA4850H4CA
O8C0OFCA9CG1J0CABFG4TFCATKBDK8CAOJBZ3XCAYSUN4ICA3X9LE0CA3M5XIWCA3GCAKPCA63766D scheduled to be deleted on reboot.
File delete failed. C:\Documents and Settings\Johnnie\Local Settings\Temporary Internet Files\Content.IE5\R0CZ6CEL\8NDKACACOFVWYCA04SF2MCAA4U3N5CAP81IB0CAMXJ8YBCATFDX3DCAA0AYKSCAGK7WZGCAO5COVMCAPYUZEOCA1QNSLNCA
L4AOAFCAZTG8N0CAMHSUK3CAM7JMITCAH6MJ85CAAL05S4CABDTZHMCAPFTU0GCAQN04ZSCAC0C786 scheduled to be deleted on reboot.
File delete failed. C:\Documents and Settings\Johnnie\Local Settings\Temporary Internet Files\Content.IE5\R0CZ6CEL\8Y1ZRCAZMSSR9CA2CQIDVCATY914MCAENTNT2CA08KPFCCAA2Y1ITCALIRRNLCAYATL13CAFFHPKKCAX3BKJ0CA94NCXOCA
KIKQF4CAOV0UUHCA6OJEEACAZAO0R9CA2VFZ1FCAB7B533CAKCMD2RCA9D73F3CAVJ77XLCA7RY38X scheduled to be deleted on reboot.
File delete failed. C:\Documents and Settings\Johnnie\Local Settings\Temporary Internet Files\Content.IE5\R0CZ6CEL\AAAAAAAAAAAAAAAABSAwQAAAAAAAIAAwAAAAAAzr8pPiIBAAAAAAAAAADnmpYEuWo5AAAAMJH4nioAAADw4qJeAAAAACiR-J4qAAAAAAAAAAAAAAA=,,http%3A%2F%2Fad.harrenmedianetwork[1].com%2F,;ord=1246583439 scheduled to be deleted on reboot.
File delete failed. C:\Documents and Settings\Johnnie\Local Settings\Temporary Internet Files\Content.IE5\R0CZ6CEL\BPO1ZCAJZIG8OCAU4D6Z6CADQ0XT2CA99V0Z8CAWQ3G9JCA6TYDWECALAUX7CCA8RGYY8CAZTY20HCAFKXMQ2CA3WBJG0CA
V5H09YCA4S0IS7CA4HLB7CCA0D2OZGCA8UEO08CAUPA1WXCAED16LMCA9G12KHCAF7YQBFCAFLB3IA scheduled to be deleted on reboot.
File delete failed. C:\Documents and Settings\Johnnie\Local Settings\Temporary Internet Files\Content.IE5\R0CZ6CEL\BRQAHCADPPGCMCASTD3YGCAKRXJCDCARAA4HNCAV2W8VRCA6QHF1XCAWV3CFKCA32R83NCA6QUMTZCAPZB16WCADZS1X5CA
JK106TCA2T7CI5CAGO3HW7CAR66V5GCABOEM29CAI0T1SACAK3O0ACCAC362LICAJDI7DGCAUY6VW0 scheduled to be deleted on reboot.
File delete failed. C:\Documents and Settings\Johnnie\Local Settings\Temporary Internet Files\Content.IE5\R0CZ6CEL\C5MKICA6IUWSQCAI32KKZCAFKBW9ICAQ6SZCTCAE1G0S9CADY2X90CAPOFZJZCAEVMGD0CAIUVY9ZCAVU2LH2CAEZ2FVGCA
1H6W0YCAKTD6LCCA4XQKFGCAT3CS07CA73KXU1CAC1HP73CAE17139CAD7XJTTCARKEV0WCA76CJY9 scheduled to be deleted on reboot.
File delete failed. C:\Documents and Settings\Johnnie\Local Settings\Temporary Internet Files\Content.IE5\R0CZ6CEL\C8Y5FCAY6NQZTCAZWQAXXCATDDKFCCA9T8CFKCAVZFMLVCAJCXAFRCAKK5M8QCAVDATADCAMB2MZRCAGH7YATCAXU099ZCA
P74007CA4W23SCCACZJSW2CA5M7LIDCAXVBD3BCAITCQC3CA0NGV6BCAQ4MKNXCAC4A2LJCAY9PFBY scheduled to be deleted on reboot.
File delete failed. C:\Documents and Settings\Johnnie\Local Settings\Temporary Internet Files\Content.IE5\R0CZ6CEL\DZIOWCA17Y6ZMCA1E9ZHMCATJGC74CAMUFFM2CAXQ3PCMCA39YDTMCA9R6YA2CA0DC773CA07WM44CAK1KFTKCAOA250LCA
A672HICABOLY3UCAOQPUZVCA4C0D9FCAJNLYWGCAADJHA6CAAUQUG5CAU06HJTCAIIRD3MCAO7EGJG scheduled to be deleted on reboot.
File delete failed. C:\Documents and Settings\Johnnie\Local Settings\Temporary Internet Files\Content.IE5\R0CZ6CEL\GFM5UCA3VNOERCA2JLB5ZCAHF0Z1FCAJS341NCAHERG29CA6IZ8TFCAFT4E4HCAH7MOZPCARW63U8CAZ924MJCAQB3C1NCA
P147RRCAQI2E07CAIOXGIICAATCX59CAQXQHIICAQ6ULFVCAEH21W7CAE9CI17CAH6WZ3OCA1HHVIJ scheduled to be deleted on reboot.
File delete failed. C:\Documents and Settings\Johnnie\Local Settings\Temporary Internet Files\Content.IE5\R0CZ6CEL\GNC1RCAUM36SECA1W1ZHUCA5SJV42CA3O6MVCCAAYNT3MCAT50U8SCAH2RWDSCARZ0T1FCAME3IZPCAXO1H8ZCA469VBQCA
JLCYGVCAMNCOPZCAJS11PYCAPO3WD3CAMKQ21ZCADNFLBKCAH6H02BCAG140KOCAYOM2K5CAQR4MNT scheduled to be deleted on reboot.
File delete failed. C:\Documents and Settings\Johnnie\Local Settings\Temporary Internet Files\Content.IE5\R0CZ6CEL\GQRV0CA55WTY5CALU69QQCACJZS80CAKS5O0WCAUYW9JFCACQYUZVCA0AIW9YCAG8NMM0CA0BE9Z0CA46D9H4CAR0C7AZCA
8A3HQICA4H0QF6CA0QVR4LCAQSGHVRCAK6ADISCAN9VAJWCAXI1QZ0CACDJXJKCANU9NNACAGA79F0 scheduled to be deleted on reboot.
File delete failed. C:\Documents and Settings\Johnnie\Local Settings\Temporary Internet Files\Content.IE5\R0CZ6CEL\H91RMCALI87HFCAFEQBOJCAQB8TMICA0Q3W6CCAI2FO3YCAG6CN47CASFS0H3CANHKA2XCAS51NPDCAWHINVBCALP7HB2CA
ETJYT9CAT4V54NCAKFQ89CCAXBZT8JCA13DVXVCA36EXHYCAWT0EJRCAVELWRNCAMKSE1ICAR08BY5 scheduled to be deleted on reboot.
File delete failed. C:\Documents and Settings\Johnnie\Local Settings\Temporary Internet Files\Content.IE5\R0CZ6CEL\HQ22XCAR68YUCCAQNJ7C1CA9PM3YJCA6A8406CASFIZQ3CA92AVK8CAR9D8TKCA2D6KJ3CAHY59I6CAVR3Z43CALS4YFDCA
EB5TS9CAZP536BCAZSDJ3MCAIA0JPKCAVQN56GCALVW7DACA21WMENCA71F0N3CAZPF7RICA7YVEGR scheduled to be deleted on reboot.
File delete failed. C:\Documents and Settings\Johnnie\Local Settings\Temporary Internet Files\Content.IE5\R0CZ6CEL\HUL9YCAFDFOD4CAT9X1KSCAT10P6WCAZG9SHJCA1F10NXCATEGEJ2CAFUI5TCCAZ6B3ECCA4ZNG9SCAIPXT16CAWTSDHACA
1ICGECCACYIRTFCAVM2QTJCAJDZKXNCASWCOC4CAVUK59SCAQ0U01KCAWTIIJ8CA6RSC14CAYX6TRF scheduled to be deleted on reboot.
File delete failed. C:\Documents and Settings\Johnnie\Local Settings\Temporary Internet Files\Content.IE5\R0CZ6CEL\I6G3BCAVU1TS3CAVYG4BCCAEV7DLUCA50FZ3ACA2OUYE0CA0C5HTFCA7VIM74CATNR2OLCAHTGV29CAJYQ3K4CABQ32A2CA
1BOOA7CA9YLV31CAZ0HS5KCA2NQIFZCAX3L126CA6ZT8RXCAKGI7CJCA9JALVHCAIFMAE3CAG32KJB scheduled to be deleted on reboot.
File delete failed. C:\Documents and Settings\Johnnie\Local Settings\Temporary Internet Files\Content.IE5\R0CZ6CEL\KMXCCCASB4Q1SCAAKX4DNCAMHIF1HCAE5TP3ACALUCGS0CAHLK61ECAJIQVZXCAFYVJBVCAR2TSCSCADT463PCAEEB7E2CA
N0KD6RCANM0VJ2CAZSL9ZXCAN4EB5OCAN62FJ6CAFAX0L9CAP7TJFOCAM3T80PCA7078C4CAK04AKJ scheduled to be deleted on reboot.
File delete failed. C:\Documents and Settings\Johnnie\Local Settings\Temporary Internet Files\Content.IE5\R0CZ6CEL\MY98ZCAMQF32ECAC06YTACAKGAECOCAEFJHZ5CA5NMGEMCAOHU4Q4CAV237MGCAY20OCMCAV1SNEDCAV20TFJCAXT95GYCA
OYG2QLCA3TTAKJCA77DB4KCAPJSFGYCADXHU95CAXSJFL9CAOFL60ACA9KANR1CAITLFATCAXC8QYJ scheduled to be deleted on reboot.
File delete failed. C:\Documents and Settings\Johnnie\Local Settings\Temporary Internet Files\Content.IE5\R0CZ6CEL\N77NJCAW9X27ACALX7VT1CALIBA49CARNZ31FCAEZ45Y1CASV4JP3CAC4Q391CA0CUKLECAHXNA9TCA4L9DGDCA97GFG5CA
FDQBADCANW3N7BCA97WX5DCAWV10EWCA8CXYB3CA601FFWCA1BDLBKCA9IK2X5CA07KRU1CAHCLPT2 scheduled to be deleted on reboot.
File delete failed. C:\Documents and Settings\Johnnie\Local Settings\Temporary Internet Files\Content.IE5\R0CZ6CEL\NN07NCA17BXC1CAHVH0F0CAHDK8LTCAXRAPOACAVPYNOOCA01VE2OCAU2AQ2FCABL61T9CAKTCL5OCA2RW0ZLCAETJE0VCA
8J25IPCAM39TQOCA3TFJV0CA99933VCA0OFHJKCAH739Y0CA42J3EECACI3TWHCARX9S1PCAZWJ108 scheduled to be deleted on reboot.
File delete failed. C:\Documents and Settings\Johnnie\Local Settings\Temporary Internet Files\Content.IE5\R0CZ6CEL\NSQGJCA0QP5VJCAPSTAGJCA5ZV5UICARBZJJDCAZV6VPJCA7YOZM3CAU5P9GBCA692QKYCA6DCW53CAD8MNMJCA5IY3XACA
P3SDBCCA391I4TCA633T7QCAASGFODCAX79OTSCAZSPIYXCA4VBVYVCA6QWOS0CA3U51PGCAZPEJ9G scheduled to be deleted on reboot.
File delete failed. C:\Documents and Settings\Johnnie\Local Settings\Temporary Internet Files\Content.IE5\R0CZ6CEL\OHP1UCAVJL29JCA55ILW9CAT89BZKCANED0X1CA0QRYQTCACHY0BCCAAPCZCWCABY35AZCA1PXANKCA2XQNZ6CAOSHHHRCA
ACHAC7CAIP3WE1CAGLD6IPCACV0DIRCALFNYVRCATTJP4HCAWV9GRRCAILPDH2CAD5MCMYCARNNXU3 scheduled to be deleted on reboot.
File delete failed. C:\Documents and Settings\Johnnie\Local Settings\Temporary Internet Files\Content.IE5\R0CZ6CEL\PQM7ICAQ7WJ99CAGDPF0PCA2XWPPVCA5YY63FCAQLSWP4CA18H3ZZCACNP4EHCANOSIY8CAR1JVUACAMWMQFICA6ZFODUCA
DRB8KKCAMC36U3CAQUDBGICA51ZAG6CAF37H30CAA75HQYCAQVD28YCAJE60Q0CAVFL22VCAFBGGS4 scheduled to be deleted on reboot.
File delete failed. C:\Documents and Settings\Johnnie\Local Settings\Temporary Internet Files\Content.IE5\R0CZ6CEL\QEGJ0CA4IGIV9CAH0AVM3CAYBYG2UCACVZ6HMCA34R6WTCAESVFOXCA20CK8WCAE83NBUCA8N1UN3CA5AF52LCAL08YZXCA
Q0KL23CAT7FKRECASFRGRLCANK4DV3CAAO3FBICAN1ELW9CARCCNL9CAG9IA9BCASLTWH7CA0WJCAU scheduled to be deleted on reboot.
File delete failed. C:\Documents and Settings\Johnnie\Local Settings\Temporary Internet Files\Content.IE5\R0CZ6CEL\TQT2WCAM5BHANCA7HQ1RACAF7HDKICASMR5L5CAL3T4M4CA4RXKABCAT3SUFFCAQ01Z3NCAG13OF1CAZ1ZT05CAMOJQKWCA
WTQJMRCAH3O3YFCA0DGKL5CAKBPN3JCA72AJ7CCA909STMCAG86HLWCAUOK4A5CAM9V637CA4XI9YT scheduled to be deleted on reboot.
File delete failed. C:\Documents and Settings\Johnnie\Local Settings\Temporary Internet Files\Content.IE5\R0CZ6CEL\UFXJ8CA8Z0KK1CATNIGXNCAG51GX4CA04MNDDCAAK00CHCASKKNJACAJGYL4CCADZ6CRXCAAD0IU3CA9MLGLBCA64EV74CA
6QHEDACAWQD2UJCAQ1YR3OCA184VY0CA6TBD6ECA70GZN2CAM4J6QACACEASTLCAZP13A5CA6FBDYZ scheduled to be deleted on reboot.
File delete failed. C:\Documents and Settings\Johnnie\Local Settings\Temporary Internet Files\Content.IE5\R0CZ6CEL\W0FN9CAMOBL08CAR1BJE5CAPNNGG4CAFIA4WHCASE7EQZCA9ORAZ1CARHHAVGCAD5RSLSCATFOQ7HCAXXWJNCCAXUHXWACA
LBNCSZCAIL2407CA4G7PXNCA0X3G5NCAIEDWR0CAWVKWMMCACI8H6FCA8L37S9CA62SV22CA6X1WV0 scheduled to be deleted on reboot.
File delete failed. C:\Documents and Settings\Johnnie\Local Settings\Temporary Internet Files\Content.IE5\R0CZ6CEL\WGPLECAO62RN1CAAV8XCICA66IYOGCAT6G5HRCAEI5TSUCAO3O5O9CAYQ58HFCAVFSPN5CAOTET7OCAGGGJ2ICA6HE91HCA
L0SFB0CAYSM988CAXRQ033CAZ1OKDFCAH5EG47CAQEQD50CA9QU3V2CAI3R68LCAOK1YI5CAO2T1OH scheduled to be deleted on reboot.
File delete failed. C:\Documents and Settings\Johnnie\Local Settings\Temporary Internet Files\Content.IE5\R0CZ6CEL\WTGGCCA6NU9PLCAHJHYEKCA36CSHJCA8PQR0BCA7VE21DCA43SMB9CAPVVVBVCA6BB7L8CA1PQZ1MCAFOX27ZCA05MJEICA
RQ29X6CALTBFECCA17RTG1CAUIUA5VCAPSLYCLCAMYOX82CABFNVXUCA96UMUWCAHVUQWNCAC2XQAK scheduled to be deleted on reboot.
File delete failed. C:\Documents and Settings\Johnnie\Local Settings\Temporary Internet Files\Content.IE5\R0CZ6CEL\WUOK3CA3K9AQCCAAASJWWCAH99R6ACAI3TL9JCAQFRJAQCAHQ03H0CA22N5BCCAKFT1DZCAJW61LMCAY09ZU9CA1XYZ5OCA
24S1F8CAVP4X4QCASSMW2LCAY390A6CA5U9FH5CAJDGH97CAO9H0FXCAXEN9UECA8A65JUCACOFFSA scheduled to be deleted on reboot.
File delete failed. C:\Documents and Settings\Johnnie\Local Settings\Temporary Internet Files\Content.IE5\R0CZ6CEL\XW5O0CAE56F60CATTLL9YCAIDEVKHCA7RVFR4CAM21YE2CA8VGB4VCAX7T0SGCA5QUFF2CA3NZ93YCA1CM5OHCA3DAYHOCA
0O8SZKCA96PSISCAHUB7S1CADKNX02CA4RH3KUCAOWORLHCAPBIQSFCA6GD7WECAAZHXNXCA14UFTW scheduled to be deleted on reboot.
File delete failed. C:\Documents and Settings\Johnnie\Local Settings\Temporary Internet Files\Content.IE5\O9R42Z0Q\0FELLCABQ7G96CAS7UQQRCAN47Z2GCA2RGT8HCA88RL4VCA36PIXCCAEQB2UFCAGX0T9VCAMWBK6MCAQ7WJWXCA4YW4ZHCAOA
MTR6CA6JKNSJCAU4SFQGCATV9ZG1CA8LIE7ICAMACMWQCAJ3R2NDCAM8Z3KICAGCV94PCAS6SS6Z scheduled to be deleted on reboot.
File delete failed. C:\Documents and Settings\Johnnie\Local Settings\Temporary Internet Files\Content.IE5\O9R42Z0Q\0NA5PCAE5FS2WCATTYCV5CAOEB184CA1KV7QDCA7L0ZDCCAJ664BNCAD9NS9DCABD2P1HCAB41DBQCACF8FIBCA6M2H87CAAG
02QVCAKZGDP2CA7UZ7M9CA8Q6UT3CAOK4IUCCAF5TG33CAN9GX2VCA6AFZO7CA52D6J4CAZXTOZL scheduled to be deleted on reboot.
File delete failed. C:\Documents and Settings\Johnnie\Local Settings\Temporary Internet Files\Content.IE5\O9R42Z0Q\1YLB3CAGOGCQLCASQKDY5CACCLL9ACA7SCGHSCAFGOSP4CA1MWMT1CACU30T0CAMSTE8MCA9P88GOCA9E913YCAXQKX6SCA
6XLM8FCATS10DHCADHDFJGCAUBQ6WXCAO5S6X2CAW7TZ2CCA3372UXCA7FUSZECA283Q17CAKJ5PT3 scheduled to be deleted on reboot.
File delete failed. C:\Documents and Settings\Johnnie\Local Settings\Temporary Internet Files\Content.IE5\O9R42Z0Q\22CWFCAVEHEH2CAC948GFCAIOFAMPCABEPGORCAOXK4MXCA9DY170CA4TSLLFCADPR32JCAM7GX0SCAOD9364CA8844O6CA
XX29YWCAOMRIQ0CA66AHFNCAATAZ6NCAXDPTVECA00NQ80CA6A7CR0CABLXUIDCA8ICJNKCA2KD2ER scheduled to be deleted on reboot.
File delete failed. C:\Documents and Settings\Johnnie\Local Settings\Temporary Internet Files\Content.IE5\O9R42Z0Q\2ZA06CA254YZQCAYHFQ78CA9VUGV9CA9I103ZCA736M4TCA97GO3FCANR20BMCANZ09VSCA9L67F1CAKDR343CAJW7Y4ICA
2I15IICALWF3R6CAMNB6MCCABDL96JCA9SL0D5CA38AS6XCA3UI6ROCASUZY01CAWN934XCASY3OQC scheduled to be deleted on reboot.
File delete failed. C:\Documents and Settings\Johnnie\Local Settings\Temporary Internet Files\Content.IE5\O9R42Z0Q\364W2CA9P4ESMCAQZ8MP3CAUHPBCBCADW90BACAV89W93CA4X5JSYCAEDJ0KQCAPDIN1CCA4MCUPVCAOYY8ZVCAP0BSCSCA
BG75W1CA4C5H52CAIV9GE9CABIUGVBCA5AM5ZPCA9IEVV3CA9ROX24CAFXDDJQCAOVWM45CA2M2GJ0 scheduled to be deleted on reboot.
File delete failed. C:\Documents and Settings\Johnnie\Local Settings\Temporary Internet Files\Content.IE5\O9R42Z0Q\3GYZ6CAFEU82CCAXDLB53CAHCVX5ICANAJ9UDCAH853ZTCA61AGTPCAZKBRXOCA73DT7QCAU95KECCAIMWSRSCAXXAEL3CA
OGMW56CA8GCCGBCAJWVW7WCAKQCJBYCACX45LPCAYDMPD7CARVDHSWCAWC1K3JCA0PECA6CAY9U1LC scheduled to be deleted on reboot.
File delete failed. C:\Documents and Settings\Johnnie\Local Settings\Temporary Internet Files\Content.IE5\O9R42Z0Q\4LX9GCAFQTC0PCA1OBYMJCAZ9FDWBCA3WBTH2CANKNRIWCABGWUMJCA4YX8Q2CABTYZLVCAXM4P3QCAB8G30LCAIUX8LGCA
K7NVE2CA99IS9RCA7CRYBFCAL0RLULCAWC2FBHCA1UWFBYCAHK4UEMCA09EAEECAQXDWEGCARRZIH9 scheduled to be deleted on reboot.
File delete failed. C:\Documents and Settings\Johnnie\Local Settings\Temporary Internet Files\Content.IE5\O9R42Z0Q\6V7NICAB182AECA4U8XPACADRT9S7CACUM89GCA8V3LXXCABE9O6DCAVKCDU0CAH262UZCAKK06W0CALMEHHECADI5AAQCA
KPCYCBCA5IDQ7SCAQEDWHHCAR9YYPUCA292VH3CANZFI5WCAJQEOVGCABLFBPICAFIND5ECACQ2TJV scheduled to be deleted on reboot.
File delete failed. C:\Documents and Settings\Johnnie\Local Settings\Temporary Internet Files\Content.IE5\O9R42Z0Q\AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAADwLAQAAAAAAAIAAgAAAAAAw7ImPiIBAAAAAAAAAAC[1].apYEC
VQ8AAAAMNErnyoAAADwMsNhAAAAACjRK58qAAAAAAAAAAAAAAA;contx=tech;btg=;ord=1246583239 scheduled to be deleted on reboot.
File delete failed. C:\Documents and Settings\Johnnie\Local Settings\Temporary Internet Files\Content.IE5\O9R42Z0Q\AAAAAAAAAAAAAAAABRAwQAAAAAAAIAAwAAAAAAhRMoPiIBAAAAAAAAAAA.CpYE2akwAAAAUAxjmioAAADwguFQAAAAAFAGU
M8qAAAAmDJRlioAAAA=,,http%3A%2F%2Fad.harrenmedianetwork[1].com%2F,;ord=1246583329 scheduled to be deleted on reboot.
File delete failed. C:\Documents and Settings\Johnnie\Local Settings\Temporary Internet Files\Content.IE5\O9R42Z0Q\AAAAAAAAAAAAAAAABRAwQAAAAAAAIAAwAAAAAAmlInPiIBAAAAAAAAAAAAAJYE6Y42AAAAMJEjUisAAADwEoNgAAAAANAW0
MwqAAAAGOJRlioAAAA=,,http%3A%2F%2Fad.harrenmedianetwork[1].com%2F,;ord=1246583280 scheduled to be deleted on reboot.
File delete failed. C:\Documents and Settings\Johnnie\Local Settings\Temporary Internet Files\Content.IE5\O9R42Z0Q\AAAAAAAAAAAAAAAACIcgMAAAAAAAIAAwAAAAAAtConPiIBAAAAAAAAAAC.apYEiVc.AAAAgHl8pyoAAADwYqJZAAAAAHh5f
KcqAAAAAAAAAAAAAAA=,,http%3A%2F%2Fad.harrenmedianetwork[1].com%2F,;ord=1246583270 scheduled to be deleted on reboot.
File delete failed. C:\Documents and Settings\Johnnie\Local Settings\Temporary Internet Files\Content.IE5\O9R42Z0Q\AV4U9CA28Q3RPCAH9W7F0CAJPEYU3CADI8CTSCA0QAYCWCA1EQAFJCA2KU224CAUXZH05CATKPS66CA4UNJ6ZCA3MD9E2CA
9LLP6KCANKK50ICA1O7JQ2CA6KZ169CAQMYIU4CA0DK7KLCAHMIPVOCAWB6O41CAKLGHT8CARG9V78 scheduled to be deleted on reboot.
File delete failed. C:\Documents and Settings\Johnnie\Local Settings\Temporary Internet Files\Content.IE5\O9R42Z0Q\B3N01CAN796B2CA98OUJ7CAUV0IEMCA5MGJ7YCA6IP6YGCA1MPP8ECAX5KFLBCAG6X457CA9FJGNJCAVU9V0ICAXW7ZBQCA
A8JBOCCAUMGVZOCAUII2YZCAP3TBBKCAJNIF87CA1TB9CTCAODLOOVCAKJ2XY4CAVS056DCAVVPE3C scheduled to be deleted on reboot.
File delete failed. C:\Documents and Settings\Johnnie\Local Settings\Temporary Internet Files\Content.IE5\O9R42Z0Q\BVAOTCASN2OVKCA2DT4SYCASWB2J9CAIKND4QCAHF88CNCA307MLICA5RQHVICAMHI38NCA7C08TOCAVIZ37ICAISAR6XCA
SLOCNXCAN7M9ALCA7H4VVJCA522V04CAQA879UCANW8JKFCAWBT88FCAGQL8HYCAVZHF9MCA5UGJTS scheduled to be deleted on reboot.
File delete failed. C:\Documents and Settings\Johnnie\Local Settings\Temporary Internet Files\Content.IE5\O9R42Z0Q\BVTQXCAO0SPEOCAXMQ47GCADA4X2ICA4RBR4DCAT64S0SCAYVEKBFCAFW8X3SCAH19XVGCAIP1ZHZCAGYDDKUCATLM6ZNCA
0RZU1TCA6RDJLRCAHWLZ6TCASYYKQ9CAZBO4K3CAV62TGHCAV6W4VJCARLRW15CANUAZHWCADSE449 scheduled to be deleted on reboot.
File delete failed. C:\Documents and Settings\Johnnie\Local Settings\Temporary Internet Files\Content.IE5\O9R42Z0Q\C87KHCAQ4AOA1CAYLZS4KCABZCVKQCAI8AWVLCAHR6PDCCA4YQ64OCAP0KA2UCAY7SIOPCATXZI1VCAZDOBQLCAWTVF4MCA
KMYQPGCA6N1IW4CALG90RACATHELVYCAE6QHZ9CAYF3J0ZCA3RI9NKCA1SE1U1CAAW86AVCANL87RS scheduled to be deleted on reboot.
File delete failed. C:\Documents and Settings\Johnnie\Local Settings\Temporary Internet Files\Content.IE5\O9R42Z0Q\CQ1T8CA461FAYCAGW116ZCAU5RO6ZCA9TNOWKCA89WJNTCA7LTLULCA43BPBXCATDZQMJCAIG3I2HCAM5975KCAKQ7YZ6CA
721LG0CA3G37HRCAWNICTHCAJL2PAJCAJ7PUW4CANTQIZ0CAF9VE6WCAKK83BRCAA554X5CALK65NB scheduled to be deleted on reboot.
File delete failed. C:\Documents and Settings\Johnnie\Local Settings\Temporary Internet Files\Content.IE5\O9R42Z0Q\DD2GACA1QWEA3CAV43ZN6CA0GJ54MCAB3Z4VNCATZX5O9CAL2DV56CA3EUYTZCANBTCNKCA16G7GTCAVTZELUCAVE2S0NCA
3BTOA5CAZTH4PUCAK20Q59CAL5X50OCAB0PRALCAOMTNNWCALZ9KQ7CAPCEN3FCAAAYI2QCA4Q3R93 scheduled to be deleted on reboot.
File delete failed. C:\Documents and Settings\Johnnie\Local Settings\Temporary Internet Files\Content.IE5\O9R42Z0Q\IMFCDCAN45H9YCAFSPEYRCAX6VJLOCAYPDPK0CAB08P98CAAMKL5HCAGXUP1DCAXLV76CCASUCMLHCADP2XJVCAXERHN7CA
C53J3TCA8UZEJBCAQN6YRUCAS36CVYCAOF4RTYCAD2J0KECAFTYYEXCAS79UVACAFB2V1QCARYAIL2 scheduled to be deleted on reboot.
File delete failed. C:\Documents and Settings\Johnnie\Local Settings\Temporary Internet Files\Content.IE5\O9R42Z0Q\KLA8OCANATK5DCASBDGFLCACATBRSCALMMBIRCAXSJ8MECAL9C3GMCAO78XSBCAQK92D8CA459GATCAY1VJ8MCA2E3C4ICA
M8XNUWCAKQ1A1ICATPYXM5CACBQZEJCAHVHGASCA1TS4R9CAI1IVOFCACFYHXPCADHM4AQCAGWAI77 scheduled to be deleted on reboot.
File delete failed. C:\Documents and Settings\Johnnie\Local Settings\Temporary Internet Files\Content.IE5\O9R42Z0Q\LF2XZCA0UDZ9ACA5TK4KRCAE6UC2ACAMTIF8GCA1F7MKHCA0BRWVMCAGRBO7PCAB10EAUCAM8SYSECAZV26EDCA6DC11PCA
312FMCCA0U954ZCAC13C5JCAU56VCUCAMWQS3BCAU7J2AWCACROCALCAGDLGKWCAW2OUYPCAELYO61 scheduled to be deleted on reboot.
File delete failed. C:\Documents and Settings\Johnnie\Local Settings\Temporary Internet Files\Content.IE5\O9R42Z0Q\LX16TCAHRICQHCAC8DMFHCA8AI2KJCAOY2SPBCALBVR9QCAXD1P6FCADQOG7PCAY4BAQ1CAUGHNVVCAPPX9LYCA1IQPONCA
FFN3VNCAVPLQTSCAMTKWX6CA8BE223CADS18D7CA0FNODHCAR0OUXZCA5G64ADCACZRZP7CAKS9YCJ scheduled to be deleted on reboot.
File delete failed. C:\Documents and Settings\Johnnie\Local Settings\Temporary Internet Files\Content.IE5\O9R42Z0Q\MAAC5CAAIZSWGCAMZV3T0CAORE4H0CAEIZP31CAQ2U21LCAY0NIZ7CAMGSXDRCA10YMLRCA10PVM0CAPDD870CANTX23ICA
PQZ1P4CARUKNVECAPZQDVQCAZ6W8VLCAZZND5ECAKSI7DFCAYBUGBICAQJ8SWCCABZL2F0CAT12BW3 scheduled to be deleted on reboot.
File delete failed. C:\Documents and Settings\Johnnie\Local Settings\Temporary Internet Files\Content.IE5\O9R42Z0Q\MB629CA0W4AKDCAJ00DLRCAMKA9M4CAV05Y29CAAXD3V7CAQ0KWTPCAZIRMWBCADX49XBCAETF234CAQDR6BMCAUVAPX7CA
N00A65CA5ZLV0XCAZP6017CATAVZT7CAAPQ9HMCAU3560ICAHWVDUTCAH59L0MCAQYNNTACAL1HAQC scheduled to be deleted on reboot.
File delete failed. C:\Documents and Settings\Johnnie\Local Settings\Temporary Internet Files\Content.IE5\O9R42Z0Q\NA7F7CAWJC8M2CAF8VGWZCAOEHOFPCA640UWRCA10C6FRCA386AU6CAGACQUPCAJVHWT2CA6W5344CAIT6KCJCA03DH63CA
FQ5OEJCAVOTHYQCA5QKJQCCAN91NB7CAZ3P2G1CAEDQ7EECAPVYURZCA1F41KWCAAAOCH8CAFX6JPA scheduled to be deleted on reboot.
File delete failed. C:\Documents and Settings\Johnnie\Local Settings\Temporary Internet Files\Content.IE5\O9R42Z0Q\NLQQYCAUSZT0UCA73KZCKCAC3ECBMCAKF43ZMCALW18W4CAZUP0BICAZ4J4ZNCAWNLJUHCAU518A5CAHPDUJOCALEDGHECA
4XKR2TCAI0D2SGCAXNL0UECAWIKPZACAUAXH8UCAXE9MZXCAA1VHUYCAUM9HPWCAICL478CAC4WPBR scheduled to be deleted on reboot.
File delete failed. C:\Documents and Settings\Johnnie\Local Settings\Temporary Internet Files\Content.IE5\O9R42Z0Q\NYAFICAQBC6MTCAP6K25NCAS2FN27CAHZ439NCACVGIHXCARFZ7CRCATFJXVJCAXNB6W6CAQD3CWMCATVWNL7CABTR6K3CA
7W4BZ0CA2X3A7ECA1XOT4NCAN08EOUCAZV9T4XCACKEZCECAELT7AVCA3JSSBKCAP1OU2LCA0EJ41X scheduled to be deleted on reboot.
File delete failed. C:\Documents and Settings\Johnnie\Local Settings\Temporary Internet Files\Content.IE5\O9R42Z0Q\OTJ80CA3AT2TXCAK4OY44CAUO0G3JCAB0YSK9CALZPK3XCA5F2CDPCAHCA289CA3WFU85CAUOPFBACA543C8MCAAHPSFCCA
BBGDWNCATE8RTXCAK44E20CAW6F7A0CA473LZUCAAM6IASCAO7NZ6GCA77W6BFCA13CIK8CAE17KF3 scheduled to be deleted on reboot.
File delete failed. C:\Documents and Settings\Johnnie\Local Settings\Temporary Internet Files\Content.IE5\O9R42Z0Q\P1FUNCA3B880SCA1BFEX2CARIUWPHCABFPF7MCAJ6GV1BCAUE15CKCAKAABD8CA1UUTTCCAKCV1XACA4A15NJCAOAUPEDCA
8TK6ERCAWTA273CAPKENCSCAQKMMO5CA8QAU2MCAALH26TCA8PGRBJCAJW1HWVCA412S4JCAZ74GC4 scheduled to be deleted on reboot.
File delete failed. C:\Documents and Settings\Johnnie\Local Settings\Temporary Internet Files\Content.IE5\O9R42Z0Q\P3IJTCANZS8QVCAB0O2SLCA8EXXZ4CA0TMTWOCAZGAKPWCAW814PICA3BSDWGCAJROKWPCAH8Z95XCA6WQYFJCAKJ1E6YCA
VCANHVCA9DX9GICADPBCDVCAVJYV9SCAI2Y6FYCAGI81UNCA8JRU9PCADZTBCRCA96VKDFCAVCANN4 scheduled to be deleted on reboot.
File delete failed. C:\Documents and Settings\Johnnie\Local Settings\Temporary Internet Files\Content.IE5\O9R42Z0Q\PU1K7CAYOKI5ZCAGDSHU9CA0M13NHCAM5SE3OCAO2V9RECA5Q1M03CARDEAUKCADLK1STCAT8JKD4CAT72WE0CA3BRMC5CA
S8S63TCA48VMWRCAFUPLS2CADIUHENCAL0L6PBCADHHDYTCARO6PEACA1PFRSLCAAZTB41CAG361DC scheduled to be deleted on reboot.
File delete failed. C:\Documents and Settings\Johnnie\Local Settings\Temporary Internet Files\Content.IE5\O9R42Z0Q\RIC1ZCAOVOPNKCAGGZ8A3CATGK121CAKCNKBHCAZ1XPGFCA32Z0JACAXX5Z7ICAB7B6OBCAFBP912CAN6N0YVCA5HNG06CA
W1SI1YCAPRWI90CA2D5YGLCA7A9ZP7CANPXRFWCA21YDQLCABNV8S0CA388WTICACW9HQACAYIWJSC scheduled to be deleted on reboot.
File delete failed. C:\Documents and Settings\Johnnie\Local Settings\Temporary Internet Files\Content.IE5\O9R42Z0Q\RXZKTCA5XWWVNCAN6Q00BCARPZVJOCAE4EHRKCAVDY2EOCA4TBIVJCAIDKLNYCAA7MF4UCAAKLUPYCA3ABRMPCATCFH8MCA
X9U07XCACXJYK2CAYZLU10CATIL3LSCA4JHFRLCAS1F9AOCAX266E0CAXG7NPGCAWS4PY2CA3CERNY scheduled to be deleted on reboot.
File delete failed. C:\Documents and Settings\Johnnie\Local Settings\Temporary Internet Files\Content.IE5\O9R42Z0Q\S1T6UCALBOLJ6CAVERICMCAQ8C4HPCAUMEQVHCAYF00F7CALZC13WCA3Y85DBCADUNAIICAFDR48RCATN1PGSCAQOL0XJCA
LTW4TFCAJ179BMCAKQ1UVCCAI1BG2UCAQ58AZECAQEW1FCCAJL789CCA49BWTXCA6F8QG4CAQ0VHHT scheduled to be deleted on reboot.
File delete failed. C:\Documents and Settings\Johnnie\Local Settings\Temporary Internet Files\Content.IE5\O9R42Z0Q\SFBU7CATAQG0UCATPM9W1CAXUOD4HCA5VG2A2CAA31JYICA2SXCB3CAQGS4DZCAEK2ICXCAURPJPYCA7YEHF2CACEEGFXCA
AXW9KUCAO2LB1RCAYOWPRXCAX30ZF8CA7S47XNCA7OEMOECAXSUNSGCA4A1F2GCAVBNQMXCAQUS7JI scheduled to be deleted on reboot.
File delete failed. C:\Documents and Settings\Johnnie\Local Settings\Temporary Internet Files\Content.IE5\O9R42Z0Q\UDKJKCAHEHI12CAFS60FWCAXWCC87CA1XT78CCAB0IGFGCAC7E98UCA520MF4CAN6FIYHCA9548UYCAR88WLFCAO698AVCA
2M4BVICAZ2XJS8CAA8OBH1CA7Q7XQ2CAGH34WPCAO6POJ1CA365XMECAZ0VWAJCAV5CD3QCAK857JN scheduled to be deleted on reboot.
File delete failed. C:\Documents and Settings\Johnnie\Local Settings\Temporary Internet Files\Content.IE5\O9R42Z0Q\V2ADQCAEBWIIFCAH58ZG8CAQ58Y4NCAOWAE25CABDHFO6CAW3PD2GCA1LWGDXCA8BVFY8CAJFC901CAUH68SPCA1IDO69CA
87C3VVCAO4482XCAUWGX7HCAXW6D1RCAUCCT0CCAEQH6XBCA8O30M5CAFF4AB3CAT6FRWECARGLAFS scheduled to be deleted on reboot.
File delete failed. C:\Documents and Settings\Johnnie\Local Settings\Temporary Internet Files\Content.IE5\O9R42Z0Q\V7MWRCAJ0PC2VCAZR8OMOCA732Z9ZCA5W4WWHCAXGJZ5VCATI52TGCABBIN2QCAZFMPOICABGZO8NCAQVHH09CA5V80OGCA
W3TSVLCANLQBVYCAE11R7RCAA1QCVHCAMWWRWSCAYUIC1VCAP38NVGCA0BIX1SCAS7CZG4CA2NNC7M scheduled to be deleted on reboot.
File delete failed. C:\Documents and Settings\Johnnie\Local Settings\Temporary Internet Files\Content.IE5\O9R42Z0Q\V8MKECAIXVH8OCAXURC10CAYTP9PCCAK1ECN2CA6JA681CADU6PK9CAW4SZQYCA1QQO2VCASNK65MCASMGN6QCA3ILB8UCA
T3VDPRCACV70VECANC1F0CCAUZQVGYCABVUEVTCAYUMPJ5CALW3BYMCANX6PF4CA299AK6CAIF0XID scheduled to be deleted on reboot.
File delete failed. C:\Documents and Settings\Johnnie\Local Settings\Temporary Internet Files\Content.IE5\O9R42Z0Q\VQS0LCA7KVJ7NCAHIJMV3CA0BLN4NCA4LBG40CAOQTUUZCAML0MXICAU70B2HCAHSEJOUCAFKTFU3CAHUPL1ECAAKS94HCA
8G6FYBCAVBET3UCA5J1G64CATZZ7T3CABLK7VLCAZ1ENQ4CA1DXEU2CA7AZG4NCATVMTHWCAFZTJ79 scheduled to be deleted on reboot.
File delete failed. C:\Documents and Settings\Johnnie\Local Settings\Temporary Internet Files\Content.IE5\O9R42Z0Q\X3RE0CAGQS67ECAE5FQUHCAU5WWB2CAF1OWKNCABCAMTWCA7EM5SWCANLNCXKCACRTPGGCAH889PFCAM68B4ZCAV9ACKXCA
VXAHH9CASOZUMCCAMX4H2RCA0B71HFCAX8R2K0CA8414MOCAFDZ8LWCAXS3DNECAPMR030CAP27FS7 scheduled to be deleted on reboot.
File delete failed. C:\Documents and Settings\Johnnie\Local Settings\Temporary Internet Files\Content.IE5\O9R42Z0Q\XONWXCAFH2853CAMD937XCAILYWIVCA5I606VCAY9CLWHCAU0LUTFCA6FNSY9CAP2DF40CAO8TJPKCAZK0W0HCABB4D80CA
Z1NT3TCAHS2EDNCAA4CDAICAZ8FPIDCASNXVRKCAKZRAPJCANNODNYCAA2A2H1CA1D5KDXCAFHJ3Y3 scheduled to be deleted on reboot.
File delete failed. C:\Documents and Settings\Johnnie\Local Settings\Temporary Internet Files\Content.IE5\FJ612W8B\0AYYCCANKNVVVCA1HQIERCACZ1TRBCAOIO9JNCAAKA958CATRMMYWCAJEOLU4CATUYRRBCA8Q5TQ2CAKY43VSCAP73JELCAPU
PR1GCA72RXXXCA0YGRU0CAB024G3CAAZM34XCABHP7TNCAM1ENG7CAQHF1F1CA7ZPPPRCALRCD1O scheduled to be deleted on reboot.
File delete failed. C:\Documents and Settings\Johnnie\Local Settings\Temporary Internet Files\Content.IE5\FJ612W8B\21XC9CATIN265CAFK8CB3CA5JMRZMCAPMIG09CAZHOA6RCAB8UZPYCA4LQ219CA0JR33KCAGMG8U8CADDD7PSCAAFY8V4CA
HEDLGVCA68UVUHCAS5ZAMDCA0MEU1KCAVZKLEWCAK8MLMKCAPYLDK8CADUTAG0CAPN1FAKCAHSNE21 scheduled to be deleted on reboot.
File delete failed. C:\Documents and Settings\Johnnie\Local Settings\Temporary Internet Files\Content.IE5\FJ612W8B\36KMBCAI05CMLCAWF5FVTCARPBIY8CADREP0LCAXU8G21CANFA6UDCA58B5PVCA32DSVECABOA6FHCAE6MZ4JCANQV633CA
45H256CA32ESWWCABDN969CA9IQHE9CAIRW6E2CA5F3O3LCAQX2372CAY1H8JXCAYQASDHCAMS5FSG scheduled to be deleted on reboot.
File delete failed. C:\Documents and Settings\Johnnie\Local Settings\Temporary Internet Files\Content.IE5\FJ612W8B\3ZU3DCANAV7D4CAC4P9YACA1C5XWWCA5993G1CA8E6Z5NCAA93N50CAUKSV9TCADLN7TFCA54T0KGCAIZ7LTBCAJW34GLCA
XE0V4GCAXWUB3OCAFUHPBICAPRZXVGCA8T75MECALERSVXCA2A0DLTCAM0YIHTCA95Z14ECA5WFERZ scheduled to be deleted on reboot.
File delete failed. C:\Documents and Settings\Johnnie\Local Settings\Temporary Internet Files\Content.IE5\FJ612W8B\432ZRCA9HHB3MCAF3ECBRCAV9JC3FCAPM7MOOCAIBQH8WCAJM2O4DCAYSPDJ6CAG9TIWVCAWRCB1MCAZUPD9YCAQ201S7CA
G3FKTPCAHUNI74CA8US857CAAAB7L9CALKG2BSCA64J6YOCAA12292CA3OCLFLCAKBJFJSCAD1JQII scheduled to be deleted on reboot.
File delete failed. C:\Documents and Settings\Johnnie\Local Settings\Temporary Internet Files\Content.IE5\FJ612W8B\6TRJ3CA53LRKPCAX0JY5UCA3FKUCZCAPGIEHWCAWN6H66CAWOPF81CAOZSV1ZCAIQJ5Q3CABN124YCA6CSVBICAXIRBPYCA
G23CBNCA4WQMG9CAYMNWNOCAIFCE5UCA1E2HOJCA3V52ATCAL3G9J5CA2YO877CAT5OLN0CA67HA7X scheduled to be deleted on reboot.
File delete failed. C:\Documents and Settings\Johnnie\Local Settings\Temporary Internet Files\Content.IE5\FJ612W8B\89DI3CAVH7XU0CAGENE7QCAKQXOSLCAHV6Z61CASBNJ5VCA2VWS3SCAC6EMHCCALQYPJWCAMKIIW1CAG0FQTHCAWGVOTICA
39V5OBCAE3389CCA9H4HA7CAP4U6G0CAVDV736CA1QDE8KCAJWRT8HCA7PUJ9KCAZSDKXOCA0NY5QD scheduled to be deleted on reboot.
File delete failed. C:\Documents and Settings\Johnnie\Local Settings\Temporary Internet Files\Content.IE5\FJ612W8B\8M0RZCA537KXUCACTSRT8CA0UL60SCAIPL8WWCAHRT4W2CAEFQHFUCATK83T6CANSGGQ7CAFFQH6RCAEJ9CCPCA2U9220CA
XUT2OGCAABI2HCCAOFXMH2CA4KV93SCADM2P5BCANLM3O3CAMZF8VBCADHV7ZBCAWE2KN1CACAB7T2 scheduled to be deleted on reboot.
File delete failed. C:\Documents and Settings\Johnnie\Local Settings\Temporary Internet Files\Content.IE5\FJ612W8B\ALRPLCABGSD76CA7SVE3ACA1DWYKVCAT800VDCA3N5SGOCADQ1J82CAL7HYCLCA0O04XICAKJXFUFCA6F5KYUCAT6A4HHCA
NT4470CAIVOKM4CA7E5J3ECAU370YACANY3JXACAODWDWWCASDDHYACA7TRANOCA85JM00CAZ1ZK8W scheduled to be deleted on reboot.
File delete failed. C:\Documents and Settings\Johnnie\Local Settings\Temporary Internet Files\Content.IE5\FJ612W8B\CORY8CA9D0T7DCAQGLMM0CA59ZB9JCA2DRF4HCA2O31GSCA53Q7OECATJSC9ECAG0OQZZCATD196DCAQMS0M7CAGMI95CCA
LAFKVNCARHLZMLCA1NAQTHCAT3NAQ1CA9QQJN5CAWT5W1KCASOR35LCA71PPN1CAMART6YCA5HV5HK scheduled to be deleted on reboot.
File delete failed. C:\Documents and Settings\Johnnie\Local Settings\Temporary Internet Files\Content.IE5\FJ612W8B\D7V99CAFVVR09CA7N95LHCASZW2ORCAA0QX00CAFEVL10CA6YVUYDCAR7DA53CALORLJUCAERT6UOCAT75GL0CAJ6GM64CA
W57S08CA86UGHQCAFXRULOCAZJ28IQCAVCUHLNCAOCAPE0CACFQRAGCAHS7MUMCASTYIT8CAVH8PQC scheduled to be deleted on reboot.
File delete failed. C:\Documents and Settings\Johnnie\Local Settings\Temporary Internet Files\Content.IE5\FJ612W8B\D9IP1CAB4G4TQCACTHJUTCA7VQ693CAOAEUYNCACZYC1HCAXFHFU7CAZGCORBCAT0W7ISCAQR8Q5OCAPAHY2BCAVZAAJGCA
13B6F2CAYPPDFDCAXVZN84CAZFCOVGCAFQJ7RHCA4YX0NVCADAWSOZCAWIXOZZCADC6003CAKQX31J scheduled to be deleted on reboot.
File delete failed. C:\Documents and Settings\Johnnie\Local Settings\Temporary Internet Files\Content.IE5\FJ612W8B\DHM6ACAY18YIWCAE7L53UCALXZX6ICAAH5PAMCA7JE8PCCA3JZFO2CAFCM9H7CA4I92XNCAJKF20XCAJ2BF50CAA7VFRZCA
HWT7B7CAZ72VQQCASML6X2CAETYR8ACANG5CZZCAUZG23TCAD0RD7CCAJ3QN2ZCAEHEMZQCAMPVVO9 scheduled to be deleted on reboot.
File delete failed. C:\Documents and Settings\Johnnie\Local Settings\Temporary Internet Files\Content.IE5\FJ612W8B\DS74WCA3JZN3ECA4UAAK1CAV3L34GCAWSEUR1CAPVSWE0CA14KR2ICA7MSABTCAO542YXCAS0F9MOCA2JR7UTCAOKD6YSCA
NYALODCAHTSEKPCAEK1N49CAT9BH9SCAOGVR9FCAN38PWSCAIXQ1R8CAPWIFLGCAV9TUNMCASFYIXW scheduled to be deleted on reboot.
File delete failed. C:\Documents and Settings\Johnnie\Local Settings\Temporary Internet Files\Content.IE5\FJ612W8B\DSARTCA2GPFVVCADKQOVZCAP0KUIZCABSGKS0CA8197N5CABD8OE1CA96RLT3CA2ICI58CABQK5IPCAJJ3QJ8CAPVUDBLCA
LYN08YCA1B4TEDCA9CJUBKCAYF0R7VCA38505UCAEJDX1QCA3GUZ6ECAGIPEP0CAF1ISYQCAFYMKKG scheduled to be deleted on reboot.
File delete failed. C:\Documents and Settings\Johnnie\Local Settings\Temporary Internet Files\Content.IE5\FJ612W8B\EDOMOCAWIB3M1CA761K4QCAQ34CQBCANUMB2KCA33V0ZXCABRWC74CAW05QZTCAD4SZWSCA80J47XCAXISXL8CA6KX49CCA
EQPXX6CAE01MS2CA0KR7CVCAEUDJCRCA8FIG20CA8MCFHHCAGW0BN1CA9C15WXCA8JXDDBCAIE8FJT scheduled to be deleted on reboot.
File delete failed. C:\Documents and Settings\Johnnie\Local Settings\Temporary Internet Files\Content.IE5\FJ612W8B\ENQXQCAG3YFB4CAUGXLGICAAA2NEHCAR1T9NRCAM6MP9XCAMUCEI8CATJ1KZOCAVU12X5CA4O2I8DCAML9X10CA9QEME4CA
E7TH9LCAWWYXWTCA2QM0KRCAAUWBPSCAOK2NJXCA7KY1RLCACR6D5FCA0L4ICOCAI4RI45CAJS8B36 scheduled to be deleted on reboot.
File delete failed. C:\Documents and Settings\Johnnie\Local Settings\Temporary Internet Files\Content.IE5\FJ612W8B\F1QH4CAWYY65RCAUETO0HCAMWA1JWCAQS98GCCANHNTKFCAPHPOSOCAL2T50OCATL5F7LCAW6WH4ICA53P784CA7X5N2VCA
SBRZM9CAP2802SCACUSTAACA3G2U4GCAEQM3GGCA6XHFY9CAVPK3MJCAJMZF4ICAP29OPGCA1IET20 scheduled to be deleted on reboot.
File delete failed. C:\Documents and Settings\Johnnie\Local Settings\Temporary Internet Files\Content.IE5\FJ612W8B\FICO3CA8E9AO1CAM868QHCAM1YEYTCARQXSNDCAT03I4ZCA60JDQECADCBPKQCA39AWSDCA2X09WYCAOWX2VFCA137RLFCA
F19V4ECACBV5I9CAB0Z0ZRCARUBOR5CAQ6RLUDCASGTR55CAJADUWUCABLQMNKCA7F6FY3CATZ7GII scheduled to be deleted on reboot.
File delete failed. C:\Documents and Settings\Johnnie\Local Settings\Temporary Internet Files\Content.IE5\FJ612W8B\G115ICA9PFX3XCAGWSF30CAUOSFQ0CA9W272MCA4ZRH19CAUUQ4EDCAEB79V5CAGV7J7BCAW0WC3BCAIQ0JEOCAFANE1QCA
7RX5JZCA2F2ZGOCA1EG0D3CAPWCE29CA2SMV0VCA4252QICAU7IECFCA19HZWNCAR5I8RCCAL0T03Y scheduled to be deleted on reboot.
File delete failed. C:\Documents and Settings\Johnnie\Local Settings\Temporary Internet Files\Content.IE5\FJ612W8B\GKLIGCAGYMO8YCALU4IIGCAOB7HM9CAE8SF1CCA3CK4U0CA3370F6CAL6IMQQCAEU4Y8NCACPIV0GCA8S7AS3CAODJ8GUCA
JG4UK3CAZ3JCX0CA9T4LIWCA3BTCA7CAUWQPRBCAFEX8I7CAETLH0CCAK0UARUCAJB0VERCAWXJPHR scheduled to be deleted on reboot.
File delete failed. C:\Documents and Settings\Johnnie\Local Settings\Temporary Internet Files\Content.IE5\FJ612W8B\I18JCCAYZFQ4JCAR03SS5CAUGLC5RCAERTCW9CAXZTSZHCA4IFABGCAX0EURJCA7NLO16CAIL0827CA2RPO1HCAQJINNJCA
ISYZQTCAX3RZJSCAR73V47CAI78Q4ECAW2UX51CAGUO563CAS8ORG4CA5LGTIYCAXZM9L6CA13D3LU scheduled to be deleted on reboot.
File delete failed. C:\Documents and Settings\Johnnie\Local Settings\Temporary Internet Files\Content.IE5\FJ612W8B\KL13GCAYWVI6WCAF6ZQ2XCAGAHRV1CA42JD16CA8YAKHMCACLD4VKCAEA22TYCAY4KVPOCAEJZBTDCA8COPKQCAC2VITVCA
HTLMCNCA11XHFGCA9TD31KCAN2EE7HCAQ0H7C7CAYGMXVECA3H0OYFCAGOEKPZCACCLA4ACAOOI0UG scheduled to be deleted on reboot.
File delete failed. C:\Documents and Settings\Johnnie\Local Settings\Temporary Internet Files\Content.IE5\FJ612W8B\KR1FGCA8Y2RERCAUK47Y1CAKPUIH4CADTO0ABCAK5P64ZCALYSWW9CANODN1QCA42NHKECAFQ540PCAA39NMZCA99HY16CA
8V4218CAS740RICAJJ6PTQCARAHKOPCAF3WIGTCA2N4CBSCAZBEA4YCAYVBZQ7CAVX216UCAA938QR scheduled to be deleted on reboot.
File delete failed. C:\Documents and Settings\Johnnie\Local Settings\Temporary Internet Files\Content.IE5\FJ612W8B\LPGK7CAEM13KOCAL8UEXICAYHZUXNCA0G0A5BCAXT9MLTCAGN74XKCATEBWNDCA1EFR35CAD5ALCJCA52DSTPCAJ3FHBJCA
SDEPOMCAP31I1JCAOVCGIMCAF36JC0CAFM2H7KCA51MZURCAMAL9HZCA1XKACLCAR1O6ITCAB1EYDJ scheduled to be deleted on reboot.
File delete failed. C:\Documents and Settings\Johnnie\Local Settings\Temporary Internet Files\Content.IE5\FJ612W8B\MFB5DCATAX5AACA5720DCCA3Z3GC8CAL79VDRCANBKZTWCAEK1HOBCAJS5NAOCAA54CF6CA0JVKYNCABIILG4CAYD4R8VCA
B4DSKDCA4BYN0YCAW5JR0ACA1ED96OCAZV85SKCA4P35O0CA5EW8TYCADJCXCNCA048OAXCARQLBZ0 scheduled to be deleted on reboot.
File delete failed. C:\Documents and Settings\Johnnie\Local Settings\Temporary Internet Files\Content.IE5\FJ612W8B\O3TZZCA57JB5ACA294WH1CADT7QLCCAFXBI03CA7WRBZ8CAGIBHVVCAF1MDSACALEH04XCA9X40OBCAPFUGO9CAELH2MQCA
DC6K64CAC1BXIZCA170YQ5CAHCYQWRCA3NC2Q8CAJ7Q082CAF0MXGWCAU1QG73CABUTGMKCA8IPVC1 scheduled to be deleted on reboot.
File delete failed. C:\Documents and Settings\Johnnie\Local Settings\Temporary Internet Files\Content.IE5\FJ612W8B\P6XUYCA5YVL3KCA89NZY6CAW3R7YUCA64CL00CAUSPQGMCA3UYJELCAW6ZLUDCA5B2TMRCAFZHHRLCA2Y6H1WCACTK6V8CA
O3O8R2CA84FRNKCAAQI6DZCASNIY6ACA5GBSM7CA439TYUCASNO0TQCAEXHPONCAH79V6QCAK1VRH3 scheduled to be deleted on reboot.
File delete failed. C:\Documents and Settings\Johnnie\Local Settings\Temporary Internet Files\Content.IE5\FJ612W8B\PHVO5CAHCUT90CAY8XLDNCA7DS17TCA8SYJQLCAHGTLJJCAUU6W9KCA13TZJWCAXJZUWPCASO04BHCA6VH23BCAR3MY21CA
OFY8VZCAOP6XHQCA1D6J5KCAY9GCSOCAN8A58NCA0CX5N1CA6ZKG39CAV0VQBQCAHIFB30CASC0KQ3 scheduled to be deleted on reboot.
File delete failed. C:\Documents and Settings\Johnnie\Local Settings\Temporary Internet Files\Content.IE5\FJ612W8B\PLIQYCAPNO6QVCADD8KCMCA2ABNYTCAYIDLGLCAB8KU7LCAWJE0QSCAH3HPE4CAQMNPSUCA7BMBGNCARVOEOLCA4JAGNWCA
SA6NJLCATDA7G7CASI5QN3CA75QCRSCA7KU7D6CAQ0HDWACAZ8GVXJCABJWG8UCABSALRLCAK6Q159 scheduled to be deleted on reboot.
File delete failed. C:\Documents and Settings\Johnnie\Local Settings\Temporary Internet Files\Content.IE5\FJ612W8B\Q453ICAKB8Q7WCABWI09KCAYKTXN6CA2I68G7CAPGPRCPCAP1W7J4CAAQJLS2CA9A6QT6CAYOPLYICATIR2THCAQA8Z1PCA
EVIT1SCABII2VXCA0EWGWHCAY30M4XCAXBY8FDCACSUOVECAZL2Z79CA36DO4CCALS4N0GCA4F5BCT scheduled to be deleted on reboot.
File delete failed. C:\Documents and Settings\Johnnie\Local Settings\Temporary Internet Files\Content.IE5\FJ612W8B\QCTABCAJM5HAHCAFWL9O6CAR9IFC4CAZH6S0GCARLZJE3CA84TEAVCARQI1X9CA7AXUD1CA89M38OCAH5LQUSCA6QTG4LCA
WE10ZHCAMFUQEMCAZSSSRCCA4VLS6LCAIJE1H3CASRCUT8CAFUZM85CAVAL1YKCAHOBRW5CA2POHZA scheduled to be deleted on reboot.
File delete failed. C:\Documents and Settings\Johnnie\Local Settings\Temporary Internet Files\Content.IE5\FJ612W8B\QFZI0CA9KI2A1CA0GMY0KCAAB3LFUCAJV7MVTCA7UI77DCACX8KYPCAFTOL9BCA3F81ZVCAYGL8BECAHQ826DCA3KXK7ECA
DU80PPCA1NG49CCAQTBJETCA8JJG3PCAHIJBA3CA8YDSZDCASVFI69CAFNE2MGCAG1VE3QCATN4UPP scheduled to be deleted on reboot.
File delete failed. C:\Documents and Settings\Johnnie\Local Settings\Temporary Internet Files\Content.IE5\FJ612W8B\QWU68CATZ3LBOCA08MH6CCAYLPUF0CA73C7THCA9SUBXXCAX3X062CAXTLWDICAI7P31ECA028XF6CA2YQ4Z2CAZCPL19CA
F5AVRICAXDDA2KCAM066WQCAB6GU3UCAB9L3UTCAY2FTB7CAN2C9LPCA0HROCYCAHUU36HCAWPBX4K scheduled to be deleted on reboot.
File delete failed. C:\Documents and Settings\Johnnie\Local Settings\Temporary Internet Files\Content.IE5\FJ612W8B\RPRYXCA66V4BZCAQP94J4CANYZBUECA07ONBHCASVGMYBCAHAEW1ECAB7OP3LCAMVI9HLCAFLRS80CA81C851CAUD09AZCA
2HQTXVCAF7BLZKCAKGEJLZCAUSMSUUCAB49BESCAUL9QGHCAPBGXKCCAWOF012CA74GGDVCA63M6IU scheduled to be deleted on reboot.
File delete failed. C:\Documents and Settings\Johnnie\Local Settings\Temporary Internet Files\Content.IE5\FJ612W8B\RT4VDCA0XGS3PCAATO4NICA4AYWJWCAFQ0D8ZCANN0OBQCABDZTHKCAYL0LMTCACIMW3OCA6LWQ52CAUMQ4SFCAE07W2ICA
VYFX08CAY1UJV9CACF7BZLCAJGTOIGCA9FM8XGCA5EHMUJCAB7GX35CAUSJC98CAZ41JCFCAYY1SO9 scheduled to be deleted on reboot.
File delete failed. C:\Documents and Settings\Johnnie\Local Settings\Temporary Internet Files\Content.IE5\FJ612W8B\SD9EICAJ03O1ICA98LDUVCA5WB3V6CAFT4H2FCA52RB04CAUCQWX6CA421DCECA74VWPXCA8KU1RCCAQS4X1DCAZTFKS9CA
V9BY1OCA1RAN24CA4U2GDCCAB31AA0CAJXW0F8CA4SOZYICA2P82F9CA7FM22DCAULEJWOCAFKFR8J scheduled to be deleted on reboot.
File delete failed. C:\Documents and Settings\Johnnie\Local Settings\Temporary Internet Files\Content.IE5\FJ612W8B\T0R65CAY2VU0OCAY8Y17LCAH48F23CAF4Y0PCCAPKWZI5CA3JQJV2CAT63EOPCAUXT1MSCAICGXFSCA9JWXATCA0J0VGJCA
KJ4RDECAH8BLNYCA4BX5HTCAQ71YJ4CAEKOJF7CAZE7J47CAWDEHGPCAZRNAK9CAWNJXZ1CAXACVOU scheduled to be deleted on reboot.
File delete failed. C:\Documents and Settings\Johnnie\Local Settings\Temporary Internet Files\Content.IE5\FJ612W8B\UGZAVCA0IGXOPCA8JQAIWCABROZY0CA6TUUIZCAJ70CQOCAFY4T45CA7MVD17CAUFDU9ECAZRJZTQCACLBR2QCAC9JS4JCA
UQR1U5CAVIGZFKCALHB4A9CA1T1BU9CAWMO4UPCA18OBIJCARZ8DABCAVHSELUCALYU2LICAZKSOLH scheduled to be deleted on reboot.
File delete failed. C:\Documents and Settings\Johnnie\Local Settings\Temporary Internet Files\Content.IE5\FJ612W8B\UQ0X2CAZQ1JDBCABQNLYKCA4WH576CAXIRP1ACAIFAOPNCAA3TWI8CAZPPI6MCA89G2D2CA49DYNOCAZEM3Z0CA2Z6POACA
S6WLMQCA3AOW3OCASIHYBACANF069FCAYXFBGGCA8MQ7DDCAU3J0TXCANJPWB1CAAXXFFGCA6POZK2 scheduled to be deleted on reboot.
File delete failed. C:\Documents and Settings\Johnnie\Local Settings\Temporary Internet Files\Content.IE5\FJ612W8B\V4DLECAH7JPWGCAVKCKY1CA1DCUSXCA4L3ZBDCA6AYENNCA708OSSCAIKCF3GCA2CN3VHCAS1KK6VCA4T4UQ9CA496RLPCA
VV6MCQCAEWLTRICARJC1BFCA81R6TYCAS9CMLVCAD9EHAICANYVB5DCAS4TQCFCA0ZRNMOCAP1R0LC scheduled to be deleted on reboot.
File delete failed. C:\Documents and Settings\Johnnie\Local Settings\Temporary Internet Files\Content.IE5\FJ612W8B\VRAJPCAR2I9I5CA84Z96NCAJTIMHACAVRN22LCAD2UG0KCA3KN3R9CA0N5R3TCA9UF7R8CAYFXGIMCAUF5463CAXRRTSJCA
PWLML0CAPLYSLVCACT66W4CAITDACKCAD3FWQICA65Z3EUCACN8SB2CAALX3TECAOG1M34CA5A5RA8 scheduled to be deleted on reboot.
File delete failed. C:\Documents and Settings\Johnnie\Local Settings\Temporary Internet Files\Content.IE5\FJ612W8B\W9013CA0MREKBCAN1S8SQCADYWZHUCAOM371WCAQN9A5ACA8BDW9OCA71QXPQCAYINOJHCADEWBV1CAKWCQIKCA9CF2V6CA
5MW2GKCA3KW8TUCAU9XG1QCAT7JR2ACAM7RT0ZCAHVTCPHCAXMYX2HCA9IKECCCAKVIN7HCAK3BCEH scheduled to be deleted on reboot.
File delete failed. C:\Documents and Settings\Johnnie\Local Settings\Temporary Internet Files\Content.IE5\FJ612W8B\W9AKFCAZ406HWCAYRN3WLCAQZCBMRCAPRUX2JCAPYJ01VCAIMNOJICAMSLAOWCA1CZE3LCALAFMXWCA23QHPPCAUTBESOCA
330R28CAB4XYFICAEW1CUNCAHGEMGOCA2E9BWXCANZ7C05CAI5LPEMCASSOZFDCAY975OICA1W3F3F scheduled to be deleted on reboot.
File delete failed. C:\Documents and Settings\Johnnie\Local Settings\Temporary Internet Files\Content.IE5\FJ612W8B\WIGMTCAB8AI8ZCAV51BNMCAOY1361CAAQ6P5JCABE0QJSCAJBX7BTCAY1YKH2CAIJB0NKCAYU9YH9CAS1ETWJCARLE1TCCA
MUL3NPCAEQVO52CAS4UTLQCADX0KJACAF090DPCABL6EGUCAVZSSSNCA9J5YKFCA25OCA2CA8AWCFQ scheduled to be deleted on reboot.
File delete failed. C:\Documents and Settings\Johnnie\Local Settings\Temporary Internet Files\Content.IE5\FJ612W8B\YCBYJCAG3Y7AECAT3VIYICAS71C6XCABCWDK6CAKUY3QLCAQC7MA2CAYPYEMZCAUK4PSWCA0TB7LECAKWFNSSCABKO07UCA
T7MFSYCA18J5JNCAMLABSRCA2A51NRCA7UUQ3JCAI1CJF2CAC972LOCATPIPMLCAQ5RS6ECAKLA879 scheduled to be deleted on reboot.
File delete failed. C:\Documents and Settings\Johnnie\Local Settings\Temporary Internet Files\Content.IE5\FJ612W8B\YU92SCAPG6EWQCAT1SNJCCAMJZOESCASNVBTVCAJRS21ECASXNF8TCAVJP3DQCA67LH2ICAO7VG31CA2Y3HG9CAGS3WYYCA
TDPA5UCAJIGB7SCA77B72PCAEYKQQ4CA2KMFRBCAJRZC18CA5QY8LNCAZICPPYCA6RJ29MCAM7L1AD scheduled to be deleted on reboot.
File delete failed. C:\Documents and Settings\Johnnie\Local Settings\Temporary Internet Files\Content.IE5\FJ612W8B\ZJHO4CAGBCOPKCALCHN5CCAWHYLBYCA4EA9A2CAOKF2HYCAENHEG3CAF3I1KKCAK7TC19CAPOOXOJCALQ9Z4RCASI5O5MCA
E5TWE7CA1RNGIBCAIR5FHICA0FEAABCAIK5B3DCAY0XY3UCASR1VR2CAF8L44PCAJ15SLKCAK00U5X scheduled to be deleted on reboot.
->Temporary Internet Files folder emptied: 6526934 bytes
->Java cache emptied: 0 bytes
->FireFox cache emptied: 40806685 bytes
->Google Chrome cache emptied: 1132 bytes

User: LocalService
->Temp folder emptied: 0 bytes
File delete failed. C:\Documents and Settings\LocalService\Local Settings\Temporary Internet Files\Content.IE5\index.dat scheduled to be deleted on reboot.
->Temporary Internet Files folder emptied: 33170 bytes

User: NetworkService
->Temp folder emptied: 0 bytes
File delete failed. C:\Documents and Settings\NetworkService\Local Settings\Temporary Internet Files\Content.IE5\index.dat scheduled to be deleted on reboot.
->Temporary Internet Files folder emptied: 33170 bytes

%systemdrive% .tmp files removed: 0 bytes
File delete failed. C:\WINDOWS\S033705C9.tmp scheduled to be deleted on reboot.
%systemroot% .tmp files removed: 0 bytes
%systemroot%\System32 .tmp files removed: 0 bytes
Windows Temp folder emptied: 483 bytes

RecycleBin emptied: 0 bytes

Total Files Cleaned = 45.36 mb


OTL by OldTimer - Version 3.0.6.4 log created on 07122009_122206

Files\Folders moved on Reboot...
File move failed. c:\windows\S033705C9.tmp scheduled to be moved on reboot.
File\Folder C:\Documents and Settings\Johnnie\Local Settings\Temporary Internet Files\Content.IE5\XUSRZF2O\00RX0CAQW462VCAFIDEQTCA4OZ6Q3CA6BB1BRCA5UYURYCA0F54MMCAEAM6M4CAGU3965CA7UAC4MCAR520SNCA62AZW3CA2Q
VVO0CAKPYP57CAYHT3X2CARFY5C9CAV7R883CAXVQFYWCAE9C1KGCA0OS9GVCA4SGN4GCA8AZYWH not found!
File\Folder C:\Documents and Settings\Johnnie\Local Settings\Temporary Internet Files\Content.IE5\XUSRZF2O\15AXTCARDKYZZCACK1VT0CARRRHRICAB4VE1TCAB3H03ECAP4MF32CAAJ1JYTCAJLI4EVCA1AGG03CA8XOD0NCAVKRJL7CA
WGRZEFCAS7UHI6CAB517ZDCACFLK44CAQXB1CICAIIMJZRCAX1B074CAL988OVCAWYYHD4CAYY56BA not found!
File\Folder C:\Documents and Settings\Johnnie\Local Settings\Temporary Internet Files\Content.IE5\XUSRZF2O\2ZMLYCAH4MU0ICAD66ZBRCAB7UY4LCAXDJQGCCA5HGZZWCAF0QONQCA1YP89SCA14PCR7CAWFJ6RLCANYYX36CASCS0BWCA
X8471OCAV973D7CAXRC0SVCAEGCOL8CA6EVMNCCAGOSQ99CAJQI6JJCACJJRV8CAKBEILKCATDG82I not found!
File\Folder C:\Documents and Settings\Johnnie\Local Settings\Temporary Internet Files\Content.IE5\XUSRZF2O\30L2XCAZA6YLZCA5HUTKKCAJQAYKHCAG70Q8QCAXLNPMXCAUXO1A0CAX2YHYACAWO7ESWCA67WJ2YCAPUS38TCA1BDQQ8CA
CCMOKPCA6TDMOFCAWAX4JGCAJVUZIUCA00L7Z9CAFUA2ZBCAC86H3SCA7NTLTICAVKMR4PCAO1VASV not found!
File\Folder C:\Documents and Settings\Johnnie\Local Settings\Temporary Internet Files\Content.IE5\XUSRZF2O\3G7QKCA7MTE0GCASDXAJYCA0242TTCABT5HWFCAGVLA9BCAPH7HISCAFO0DTGCA0AU233CAR3F80HCA421XS5CACYJ1FRCA
UF5U09CA8YE2SXCA2N2VVZCA2R2H5MCA6R3E2ICAJ60NBKCA1XZDRRCAF2DPPFCA8K4OKDCAKHSL2H not found!
File\Folder C:\Documents and Settings\Johnnie\Local Settings\Temporary Internet Files\Content.IE5\XUSRZF2O\3WFQOCARV375RCAFRDFE3CAA3SIJ6CAB6843XCA8K9NV7CA2AS32KCAOB626RCAFL37IJCAV4SZGVCAH9967JCA221EAFCA
WQCSJRCA7V84O0CAPZZFIMCAGAUU6QCAV0PK86CAJ96BBACA9AWJN1CA4SXBLXCA3IPRZXCABTHP1X not found!
File\Folder C:\Documents and Settings\Johnnie\Local Settings\Temporary Internet Files\Content.IE5\XUSRZF2O\6304JCAV5JH1VCAVJJD9NCAK47RSRCAEOF23PCA3EN04KCA225F0ECA52F0GNCAZQFHB9CABFDCGUCABITCDJCAITC15YCA
A8EB23CA2LDF1DCA5NDVT1CA1JVDJRCAOEU28KCAW4CRY3CA6L07PLCAJ3TDYLCAHKG6ZECAAAE093 not found!
File\Folder C:\Documents and Settings\Johnnie\Local Settings\Temporary Internet Files\Content.IE5\XUSRZF2O\69R3CCA0RJXDRCAS23PE9CA2QPD0YCA120OUWCA61598ZCAXVPBZ7CAZOND9QCAO2VWX0CASK3B9TCAF0WNRSCAXCI0ETCA
S6U44YCAWMDIXUCAA3KNM5CA23Z34ACAAHCF7PCAQ0BLVGCAOYQ3MOCATVZV3DCAVFC2S1CAVV3LQS not found!
File\Folder C:\Documents and Settings\Johnnie\Local Settings\Temporary Internet Files\Content.IE5\XUSRZF2O\71J4GCAHXIYL1CAQZBLBVCAEX173VCANZIA7MCAHV7RETCA111JEBCAQL89GWCA3H9CGMCA3KRPA5CATOCNOZCA6UK8AOCA
10PNRGCA5NPU3OCA6QI8V1CA8U50AUCANGCKYXCASGEWRHCANY1DQICAGBALUVCADH5I14CAVYOVR5 not found!
File\Folder C:\Documents and Settings\Johnnie\Local Settings\Temporary Internet Files\Content.IE5\XUSRZF2O\72RV5CA52T5JACA7I242XCANUCQ3BCAAQJLIDCABV0U98CA9CS65YCAIMKJJPCAWZDGK4CAK9GV2XCA0AUFBLCAICXORQCA
8XV1PECAXZRTWGCAJY1M48CAQT615MCASLX2C8CADJ51XRCA0V8WBECAMC7BNNCAWDYGJ7CA7XQFP9 not found!
File\Folder C:\Documents and Settings\Johnnie\Local Settings\Temporary Internet Files\Content.IE5\XUSRZF2O\76EHKCASO2EWHCA8UFR7LCAB4HSSWCASE1VTICABSHD3HCA04Y22ZCA1JIGKBCACY7FMACAGCMTXZCAH35NEFCA1907CMCA
YF26OACABDIMFTCA7QJCTLCA4LQ9PUCA1QZFVPCA8EWPBLCAV7CTX2CAXRNU77CA37L39FCA99587R not found!
File\Folder C:\Documents and Settings\Johnnie\Local Settings\Temporary Internet Files\Content.IE5\XUSRZF2O\7NJ74CA101QKRCA1CFFUYCAWXPFQPCA4SNQFNCALZP1NSCA64YY1SCANBASGPCAV4P0VPCAUE6QCHCAMMS31BCAH21L1BCA
BBRAZ1CA5W7R24CAVAPG9VCAN3E8NNCABMU19YCAR2XSL3CAD0FJ4ECA9T2W06CAKZPHQGCA5BFQ1V not found!
File\Folder C:\Documents and Settings\Johnnie\Local Settings\Temporary Internet Files\Content.IE5\XUSRZF2O\AAAAAAAAAAAAAAAAA6jgMAAAAAAAIAAwAAAAAAT38nPiIBAAAAAAAAAAA.CpYE2d06AAAAsJu.6yoAAADwwmFTAAAAAKibv-sqAAAAAAAAAAAAAAA=,,http%3A%2F%2Fad.harrenmedianetwork[1].com%2F,;ord=1246583291 not found!
File\Folder C:\Documents and Settings\Johnnie\Local Settings\Temporary Internet Files\Content.IE5\XUSRZF2O\AAAAAAAAAAAAAAAAAAAAADwLAQAAAAAAAIAAgAAAAAAw7ImPiIBAAAAAAAAAAC.apYECVQ8AAAAMNErnyoAAADwMsNhAAAA
ACjRK58qAAAAAAAAAAAAAAA=,,http%3A%2F%2Fad.media-servers[1].net%2F,;ord=1246583239 not found!
File\Folder C:\Documents and Settings\Johnnie\Local Settings\Temporary Internet Files\Content.IE5\XUSRZF2O\AAAAAAAAAAAAAAAABRAwQAAAAAAAIAAwAAAAAA.w8qPiIBAAAAAAAAAAAAAJYEeRE0AAAAMCFboSoAAADw8kFVAAAAACghW
6EqAAAAAAAAAAAAAAA=,,http%3A%2F%2Fad.harrenmedianetwork[1].com%2F,;ord=1246583459 not found!
File\Folder C:\Documents and Settings\Johnnie\Local Settings\Temporary Internet Files\Content.IE5\XUSRZF2O\AQYAQCAYZ7WWOCAQ75OFFCA79DZKQCA7B8I0JCA4OI7NQCAK6NKWYCAZ3YHBNCAX3F6SRCA06RRSBCAGM03UTCARVTGP9CA
5AML5LCAJ9XB6TCA8CCLAWCAAAMXG5CAXI6X2VCA4BJ3Z5CAMDMYM8CARBQ0NICA596174CAFXYB10 not found!
File\Folder C:\Documents and Settings\Johnnie\Local Settings\Temporary Internet Files\Content.IE5\XUSRZF2O\CQRULCAPQYYDDCACFANYECA3QVBQ5CAAZINDYCA7KR485CAJZEZ1RCAX0R7YRCAHX7HRICA0FZ7W2CAOPUETDCAY97VF3CA
LWEXCGCACKONQACAIXOBI7CA8AQABLCA45YWO3CA2L2AHYCA93292HCAI78Z8ACA30TPDJCA0NT6WS not found!
File\Folder C:\Documents and Settings\Johnnie\Local Settings\Temporary Internet Files\Content.IE5\XUSRZF2O\DABEDCAWFG4PNCAA4F487CAJQ7Z7DCA8B30GSCA97GH53CAYBXDO1CARKC1RKCAKHMFXTCAM4R122CAW73R8WCA8UBR6JCA
ZCQUDBCA97BRG1CA7WD09JCAE4WV7SCAL2U2ELCAGRLQXTCA059NZOCAYV6WM5CAP6AZF9CAVK4S2V not found!
File\Folder C:\Documents and Settings\Johnnie\Local Settings\Temporary Internet Files\Content.IE5\XUSRZF2O\DVY4YCAYJRMDZCAGL9L0FCAMT09CUCA0TR72XCA85MTNRCALO5LD0CA070UQZCA48RVNGCAYYXPE1CAMOCDJCCALT8LDVCA
SWKWMECAZ0HSICCAXPWGGTCACMQEPUCAWA3DETCA0HFQD0CA3YDMEOCA5Y2E06CAG1IEITCADPSLXH not found!
File\Folder C:\Documents and Settings\Johnnie\Local Settings\Temporary Internet Files\Content.IE5\XUSRZF2O\EFFT0CADUK6WHCA3HMAK0CA67XJHKCAYTCQIPCAS11JW3CA9N1RTECAM3OKY9CA8K31V6CA12SEW8CA4GGF20CAU37X6ICA
3E4LJJCA2CSPFPCAK10HWDCAQ4KXAACAAEU3SCCA9AN24SCAORZINOCAA8FJNTCA2PEKFYCABXGZ7R not found!
File\Folder C:\Documents and Settings\Johnnie\Local Settings\Temporary Internet Files\Content.IE5\XUSRZF2O\ENL6PCAX8LVR0CAW124YBCAEPYJVZCADXREY7CA1OB5C2CAWEK7WACA10OHTWCAKWH3AWCAXTSVP5CAZMM04XCAN0POJ1CA
DDG2F4CAEBXJW1CAV23LXDCAB0MDDICA4WPV7QCAB0HM8ACA8JNICZCAKTL4I4CA82WISSCAKDUVXI not found!
File\Folder C:\Documents and Settings\Johnnie\Local Settings\Temporary Internet Files\Content.IE5\XUSRZF2O\F0IGKCA7W5TV1CAL5CQM0CAIV3D5RCAWG4XXBCAIS13Y2CAJ23PPVCAVTALDSCAXE95TCCAZWUF0HCA3OZ0AECA0PSCKPCA
JO6G7ECA1JNW2KCA14OQ2SCAO500IDCA557O24CAQ20RG3CAXG85IPCA6BCAAECANSJBD7CAH3BW0E not found!
File\Folder C:\Documents and Settings\Johnnie\Local Settings\Temporary Internet Files\Content.IE5\XUSRZF2O\G7XXCCA4W0YNBCA62B0QVCAT29PTUCAC4HIJ4CAU80W0TCALSMULXCAA4OAVPCADBH9K9CA7K129BCAJ45TS0CAQ335RVCA
ZSPTEJCAS3FGW0CAFHYRHPCAGGN19PCAMQQL13CAVBV1NQCA731265CAHGTUJSCA5PJTSYCA60OIQW not found!
File\Folder C:\Documents and Settings\Johnnie\Local Settings\Temporary Internet Files\Content.IE5\XUSRZF2O\HHYA4CAZV7EU0CA9P7WX3CAFVTSVDCACLF5C3CAI8FBK9CAI6S992CA2KACT6CAQT2F3VCA72XMYDCAJQZWTKCA039V7ACA
QRXV5SCAL2OEK2CAQQS7PYCAK4WHVECAN4H6IRCASM2M6ECAVJBXZICAFA2OMNCAPT90TTCA2AVY0Q not found!
File\Folder C:\Documents and Settings\Johnnie\Local Settings\Temporary Internet Files\Content.IE5\XUSRZF2O\JJ48TCA3DOK9GCAHDWSE0CANQB0CLCAFFCLWOCAHX1MFLCAHLXU6ZCAU7RZF8CABUSCQACA7XFKN8CAWHLNJTCA1XD4G5CA
9MJ1IICA0FWWFXCA9VTW4NCA8N6YH1CA900DE4CAQ2G39ICAG9SLZDCA0QH4KMCAKL28JWCAWPU62L not found!
File\Folder C:\Documents and Settings\Johnnie\Local Settings\Temporary Internet Files\Content.IE5\XUSRZF2O\KOHRACAPCJ2VBCA925ZM6CAAPRBV1CA9HYJLTCAR2CS1DCAO1872LCAZVG7YNCAIM3L8SCA1AYB4ECA32BJUNCA9I3RVDCA
T1VFN6CA6M05G8CA7VAPAWCAOOUQ7DCA1SAQKFCATDQ88HCAV366ADCAN0UQMDCATC9VF3CA5ATHWJ not found!
File\Folder C:\Documents and Settings\Johnnie\Local Settings\Temporary Internet Files\Content.IE5\XUSRZF2O\LRM1VCA1ZKDI7CAZWXXZJCAYVTZKFCA32ZVQ8CAWK2PZWCARVE60LCAAI75PUCAPMNZRDCA7SE80ZCAVTYF5BCAS3EJQWCA
F9MPG8CATS8JE6CAX2G7A3CAZE62J9CAL17S1MCAVTWUG4CAZQDMTBCA28IS4PCAR9GA7UCATTB9A0 not found!
File\Folder C:\Documents and Settings\Johnnie\Local Settings\Temporary Internet Files\Content.IE5\XUSRZF2O\MH3QXCAXQO3PXCAH7J65QCAQVF0E3CAGAMRL5CA64FEY4CAX0FM4PCAJ8I4YMCAUQOMBWCA1MBUZGCAZ0KV0MCAOV3N8CCA
OCDXY8CAVM17AWCAQXZ3T0CAU9HWP0CAM15K0ECANN3LYTCA4TMY0ACAS80L2QCASWWE6NCA18JWUB not found!
File\Folder C:\Documents and Settings\Johnnie\Local Settings\Temporary Internet Files\Content.IE5\XUSRZF2O\NB93LCAUQABRTCA5Z1U8DCAI3OOU8CAEAUAI0CAA8J8MNCAK925X5CAYLWSXUCAPEFD5OCAXYOGEKCANZPMVMCA8DEBRECA
XTGEOACAQPS67CCAY2Z8UTCAUHV21TCAEMTBCNCAUF1O8MCA3R8ZCICA9NBGOECA63ZAFACAMH29RK not found!
File\Folder C:\Documents and Settings\Johnnie\Local Settings\Temporary Internet Files\Content.IE5\XUSRZF2O\OUUAECAXK469ZCAG4JRSQCAT5EZOQCADE9XGTCA48WKYNCAQA99BZCAQCORMUCASJ3OE4CAGAP21TCAW760KJCAHR1VBDCA
NGKSF9CA34HUQACAZLQ7AGCAXVJKYNCA3P3S3QCA30SPBCCAEJVQQVCACXRGZICA98GC14CANSSQHO not found!
File\Folder C:\Documents and Settings\Johnnie\Local Settings\Temporary Internet Files\Content.IE5\XUSRZF2O\RD41RCAGODJFDCANGF1DUCA314T4CCAE00S4JCA6X1CV7CA2J5RXKCAI6NVL9CA0QFCZYCARDFHOYCAHOZ4TQCA6TLTTGCA
WSP6R0CAIB204MCAHGFUT5CAQ1EHEGCATL6G46CAAT5WW9CAPJ0P62CAI47U5UCAFXPSJNCAGXU3NN not found!
File\Folder C:\Documents and Settings\Johnnie\Local Settings\Temporary Internet Files\Content.IE5\XUSRZF2O\RL3OJCARY97POCA5KS1I5CABEZALMCACSV6NWCAHCWLEGCA7248JECAIM50JTCALBSE74CA7QABB0CAKB4MA3CA7M5OCBCA
W33HRPCAZKKKH8CA0983I4CABKKZAMCAWA90GDCAX81VXKCASOMTSCCAWK8LTTCA92T0C3CA70ACYH not found!
File\Folder C:\Documents and Settings\Johnnie\Local Settings\Temporary Internet Files\Content.IE5\XUSRZF2O\SCBDFCAWCPN5FCAZ1WGPHCA8N781XCA5GK0R2CADUKRHCCAEU945TCANXU39QCA83TEMZCAFP6XO2CAYHELXZCAKRXGWCCA
8GFB7RCAWCOIMUCAP34U5CCAHFHKBQCAONJITZCA8GDNQFCAZZ8A7CCA9HVQ77CAV5L25VCAPDQ93M not found!
File\Folder C:\Documents and Settings\Johnnie\Local Settings\Temporary Internet Files\Content.IE5\XUSRZF2O\THXBGCAIIQLJ2CAOC6M5KCANKYBW1CACLNVUCCA1Q3ISQCA6PGAE6CAH4ENLECAIT59QFCA1SWFXRCAI8GXQTCA1ZW830CA
05MEZKCA688HL6CAE3O819CARU34MXCAPB6NNZCAGAJ9RICAPO5H2VCA2J2B0TCAPYKLQ8CA05267S not found!
File\Folder C:\Documents and Settings\Johnnie\Local Settings\Temporary Internet Files\Content.IE5\XUSRZF2O\UCJ8CCAYIIA01CAUBUN05CAG2ZHF3CA7HVAB7CAQ4UDBJCAQ1TK0RCAZ0JSGUCA9HQ2XUCAPJKGUGCAVS3U6SCAVDSG8KCA
09K6IPCA7NM3UICAW3LA1GCA974KSACAXAQ9FWCAEV42Q8CAJQI304CA1H4R3QCA2LJG0OCAWWU8GL not found!
File\Folder C:\Documents and Settings\Johnnie\Local Settings\Temporary Internet Files\Content.IE5\XUSRZF2O\UVPFCCA55KE3ECA0ZFBAKCARXB9N8CANDJLQ8CAZG02QPCAO0RZR3CA55RSYDCAIY1159CAP2Y47WCAGL1XIZCAFSZVEQCA
NTU8U3CAZ2NHCDCAB1VJ2GCAQ44I3LCAGJIZRJCAHJ7WCFCAYR8T1RCAWIEYEICAPYV46NCA5HDK1H not found!
File\Folder C:\Documents and Settings\Johnnie\Local Settings\Temporary Internet Files\Content.IE5\XUSRZF2O\V9UXICAXESVXLCAICAB3UCA4KFQMWCA11MPI6CAD53G2XCA8VN468CAE92IW1CANL24IHCAIA1OQLCAV6O2CBCA2AUENBCA
GT9YD4CAE1ND8PCA8744FUCAGWM0GSCA8MZ2V5CAY8DHS2CAQ68JKCCAT37QSRCA65FN7ECA79AW59 not found!
File\Folder C:\Documents and Settings\Johnnie\Local Settings\Temporary Internet Files\Content.IE5\XUSRZF2O\VCKPZCABM39O2CALP2SDQCA5LNP6LCA8EUHI1CABLQF70CAK8AZZGCAW32RJ1CA10ZPDYCAFGLJ3QCAP2OXAFCAPAT1VECA
SKDO11CAAFJVRPCAN9F6B3CAZ3ELY3CA4JJ3GPCAOQ9S6OCAORA9ZQCA4KYKZRCAYQBZR2CAGPE2LW not found!
File\Folder C:\Documents and Settings\Johnnie\Local Settings\Temporary Internet Files\Content.IE5\XUSRZF2O\VCNATCAY4XMO2CAPFJVTTCAB223S4CAEQEELYCAF79YS3CASHSQOVCAU7BCUICADUTPWLCAB6A07UCA23XXXCCA6PE6GSCA
25L3K7CAF17GMGCARF8JR2CAZZR53KCAMPXXIPCA71L96FCACWHF0XCA04N5D7CAZICZ3ECANJ2D8E not found!
File\Folder C:\Documents and Settings\Johnnie\Local Settings\Temporary Internet Files\Content.IE5\XUSRZF2O\W60TDCARL9ZM8CAQWHAC9CA7LCWQACAJLN0PHCACNE69CCAJ4G2KGCA7NQL72CAXU9E6JCAFZXPG6CAMQFLMRCAGRDP36CA
P4TRJYCAB70XPSCAIXBXW8CA2ED0X8CARHLAP4CAFP29I8CAXEPR1CCAIU65T8CAEKL7AMCAIKD5BO not found!
File\Folder C:\Documents and Settings\Johnnie\Local Settings\Temporary Internet Files\Content.IE5\XUSRZF2O\WK2K2CA82F3BXCABSNFVQCASKZSKNCAJI7AM4CAYR834LCATPOZBZCA0MBEQ6CAKCV220CARLBCVBCAU3JRGCCA3YS493CA
SH9BDXCAY80AEFCAN2RLWZCAPWJ7F6CAMVEHYVCA0BHF0OCAV5770KCAE3X7D8CAF654MZCAB1IGU0 not found!
File\Folder C:\Documents and Settings\Johnnie\Local Settings\Temporary Internet Files\Content.IE5\XUSRZF2O\WSMP4CA3PMMPQCAIMGG78CAENNPA8CATJCNYVCAWBR4LHCA4TB977CAONHKVICAV6JR4YCA7PCSZQCA2F5KHOCA64WWMUCA
EGPOUKCA6X3JXXCAL8Z2XOCA9SRQ5ECAAU4MCECAEQBHGJCATHVV7QCAV4KB9NCAKEPWPVCADZBU6K not found!
File\Folder C:\Documents and Settings\Johnnie\Local Settings\Temporary Internet Files\Content.IE5\XUSRZF2O\XAJO1CAS4TWU9CARGSNPLCAQFZ47LCAQXUFH5CAN4VY1JCAFXE9DBCAP6M1IZCAGAY2SWCA3WGGPNCA0D89FACA050HL5CA
9LN6DICAD9R5OBCAZLF07TCAHXKK34CAX1X7UMCA53KVTZCASZ7ZKZCATXEZT5CA1DQXZJCADNA8QC not found!
File\Folder C:\Documents and Settings\Johnnie\Local Settings\Temporary Internet Files\Content.IE5\XUSRZF2O\XIB67CAM3MH3UCAFLPZWRCA3TZPUWCAVBV2SNCAL4F22VCATK9DR5CAOQL1HGCAFLOBRQCAWWMBK1CAANXPMVCABFSGFECA
O33DQ9CANBBMQBCAS0Q3L2CALMPOBCCARJU17RCA25MW41CAQWW4MNCAE7OW22CANLM1RECA9ZW1ZC not found!
File\Folder C:\Documents and Settings\Johnnie\Local Settings\Temporary Internet Files\Content.IE5\R0CZ6CEL\02TY8CAPC6FO4CAKF69EXCAAF489TCAYI00ZECAW21RJWCAW8L72QCAAIRWC1CA8KW5BQCABN4JEJCAO9P0R7CA2IKOKZCATJ
6BWCCA2ZGBEVCAEIQAYJCALNRDAECAD9O1LCCAVTCFEACAFF8I16CA67WCX4CAX94O0FCAEXJG44 not found!
File\Folder C:\Documents and Settings\Johnnie\Local Settings\Temporary Internet Files\Content.IE5\R0CZ6CEL\131X9CAMLPH4MCA52T32RCAF4JA0FCADLPJFZCA3X9YUQCAGT05LFCAVP56U7CAMKHQZHCA3OI8J3CAKAMY66CAY1KNMDCA
V730UXCA3XY6CNCAK9V2K7CAV7750HCAZMOH5ECAOS3QRACA149C1OCAUICQ9VCAILZS7KCAEFRXX1 not found!
File\Folder C:\Documents and Settings\Johnnie\Local Settings\Temporary Internet Files\Content.IE5\R0CZ6CEL\1MQX1CADDOBU3CAEC5T59CAA44LCXCA1ZO8MJCAER26X7CAY1CCR6CA1UBEMPCAH429W8CA021Y57CA9PGC79CAZX100NCA
X9MXO0CA2TQOEXCA9AN8WGCA3V0RS6CASR1JTLCA4UA8EKCA0OBB4MCAMUZF7UCA3PFX2HCA3AAMPI not found!
File\Folder C:\Documents and Settings\Johnnie\Local Settings\Temporary Internet Files\Content.IE5\R0CZ6CEL\1SN81CAWOPO33CA05WN4MCAN21RFSCAUROZULCA9WUB3YCA2FFPR1CAX8FUDOCAKFFGUUCAWFKIGPCA0VZ6Y4CAQLZDO9CA
K4B6HZCACI3QZ2CAL91EALCAIZDHXFCA33WZ9VCA30HQ8VCACVN3HTCA3QZIVECAR7W693CATU2V9C not found!
File\Folder C:\Documents and Settings\Johnnie\Local Settings\Temporary Internet Files\Content.IE5\R0CZ6CEL\2ZTQECAR25C23CA4234C5CAUI16O1CANXI7IWCAYILPVCCABD7XPKCAOBBG50CACH79W2CABDXC1WCAZG88Y9CAMGSRLSCA
CLW0XKCA1ZX5QMCA80H607CA5UMVBDCA7PXF72CAUOCL8UCA829DQICAH8JKKOCAKXQCUMCA1GFNOZ not found!
File\Folder C:\Documents and Settings\Johnnie\Local Settings\Temporary Internet Files\Content.IE5\R0CZ6CEL\43WK8CAU6L1SPCANF1PLZCAM032CVCAIBHVIGCADJP4POCAXAW1W1CAFK5911CA15VA9GCAIDNSORCAPKWUCGCA2ZGAFTCA
LAMYI7CA0U8X1VCAYDNHC9CA3QCAXNCA23T0SXCATACRGDCAFPRMM6CARKDSTWCA4E5VIJCAK6DR9W not found!
File\Folder C:\Documents and Settings\Johnnie\Local Settings\Temporary Internet Files\Content.IE5\R0CZ6CEL\44H9GCADBKABYCAL1O1MKCAJ27ESSCAKVTG58CAQLYDVUCAV7LUBLCA0WCJV6CAFFQEDKCAKJUJRXCASAGLKNCAMT7AIGCA
B3SB43CADEDVA2CAFQPEEXCAF6PWLKCA25N3ONCAY2FU2TCAT283HDCA8U01BHCABNLSFYCA5CYLJD not found!
File\Folder C:\Documents and Settings\Johnnie\Local Settings\Temporary Internet Files\Content.IE5\R0CZ6CEL\51UN5CAYVOMFICA0F5MMZCAILPEM1CA56GE24CAIADDVMCACSK7CLCA826M5QCAGW4JKKCAIR1P79CA6C01HHCAIALL33CA
WNYB5OCAEFA1U3CAGUU3G5CA4QSDRICAIKUSXICA61C6DYCAHV4A4DCA2XR7GYCAMEXJOTCA6GR1XJ not found!
File\Folder C:\Documents and Settings\Johnnie\Local Settings\Temporary Internet Files\Content.IE5\R0CZ6CEL\8BCHECA8D0GXCCA9TFZQGCA10U5G3CAQI0FKXCANIEXNECA080YS2CAM3SX0GCA87PZXOCAYJHD56CAPZXS00CA4850H4CA
O8C0OFCA9CG1J0CABFG4TFCATKBDK8CAOJBZ3XCAYSUN4ICA3X9LE0CA3M5XIWCA3GCAKPCA63766D not found!
File\Folder C:\Documents and Settings\Johnnie\Local Settings\Temporary Internet Files\Content.IE5\R0CZ6CEL\8NDKACACOFVWYCA04SF2MCAA4U3N5CAP81IB0CAMXJ8YBCATFDX3DCAA0AYKSCAGK7WZGCAO5COVMCAPYUZEOCA1QNSLNCA
L4AOAFCAZTG8N0CAMHSUK3CAM7JMITCAH6MJ85CAAL05S4CABDTZHMCAPFTU0GCAQN04ZSCAC0C786 not found!
File\Folder C:\Documents and Settings\Johnnie\Local Settings\Temporary Internet Files\Content.IE5\R0CZ6CEL\8Y1ZRCAZMSSR9CA2CQIDVCATY914MCAENTNT2CA08KPFCCAA2Y1ITCALIRRNLCAYATL13CAFFHPKKCAX3BKJ0CA94NCXOCA
KIKQF4CAOV0UUHCA6OJEEACAZAO0R9CA2VFZ1FCAB7B533CAKCMD2RCA9D73F3CAVJ77XLCA7RY38X not found!
File\Folder C:\Documents and Settings\Johnnie\Local Settings\Temporary Internet Files\Content.IE5\R0CZ6CEL\AAAAAAAAAAAAAAAABSAwQAAAAAAAIAAwAAAAAAzr8pPiIBAAAAAAAAAADnmpYEuWo5AAAAMJH4nioAAADw4qJeAAAAACiR-J4qAAAAAAAAAAAAAAA=,,http%3A%2F%2Fad.harrenmedianetwork[1].com%2F,;ord=1246583439 not found!
File\Folder C:\Documents and Settings\Johnnie\Local Settings\Temporary Internet Files\Content.IE5\R0CZ6CEL\BPO1ZCAJZIG8OCAU4D6Z6CADQ0XT2CA99V0Z8CAWQ3G9JCA6TYDWECALAUX7CCA8RGYY8CAZTY20HCAFKXMQ2CA3WBJG0CA
V5H09YCA4S0IS7CA4HLB7CCA0D2OZGCA8UEO08CAUPA1WXCAED16LMCA9G12KHCAF7YQBFCAFLB3IA not found!
File\Folder C:\Documents and Settings\Johnnie\Local Settings\Temporary Internet Files\Content.IE5\R0CZ6CEL\BRQAHCADPPGCMCASTD3YGCAKRXJCDCARAA4HNCAV2W8VRCA6QHF1XCAWV3CFKCA32R83NCA6QUMTZCAPZB16WCADZS1X5CA
JK106TCA2T7CI5CAGO3HW7CAR66V5GCABOEM29CAI0T1SACAK3O0ACCAC362LICAJDI7DGCAUY6VW0 not found!
File\Folder C:\Documents and Settings\Johnnie\Local Settings\Temporary Internet Files\Content.IE5\R0CZ6CEL\C5MKICA6IUWSQCAI32KKZCAFKBW9ICAQ6SZCTCAE1G0S9CADY2X90CAPOFZJZCAEVMGD0CAIUVY9ZCAVU2LH2CAEZ2FVGCA
1H6W0YCAKTD6LCCA4XQKFGCAT3CS07CA73KXU1CAC1HP73CAE17139CAD7XJTTCARKEV0WCA76CJY9 not found!
File\Folder C:\Documents and Settings\Johnnie\Local Settings\Temporary Internet Files\Content.IE5\R0CZ6CEL\C8Y5FCAY6NQZTCAZWQAXXCATDDKFCCA9T8CFKCAVZFMLVCAJCXAFRCAKK5M8QCAVDATADCAMB2MZRCAGH7YATCAXU099ZCA
P74007CA4W23SCCACZJSW2CA5M7LIDCAXVBD3BCAITCQC3CA0NGV6BCAQ4MKNXCAC4A2LJCAY9PFBY not found!
File\Folder C:\Documents and Settings\Johnnie\Local Settings\Temporary Internet Files\Content.IE5\R0CZ6CEL\DZIOWCA17Y6ZMCA1E9ZHMCATJGC74CAMUFFM2CAXQ3PCMCA39YDTMCA9R6YA2CA0DC773CA07WM44CAK1KFTKCAOA250LCA
A672HICABOLY3UCAOQPUZVCA4C0D9FCAJNLYWGCAADJHA6CAAUQUG5CAU06HJTCAIIRD3MCAO7EGJG not found!
File\Folder C:\Documents and Settings\Johnnie\Local Settings\Temporary Internet Files\Content.IE5\R0CZ6CEL\GFM5UCA3VNOERCA2JLB5ZCAHF0Z1FCAJS341NCAHERG29CA6IZ8TFCAFT4E4HCAH7MOZPCARW63U8CAZ924MJCAQB3C1NCA
P147RRCAQI2E07CAIOXGIICAATCX59CAQXQHIICAQ6ULFVCAEH21W7CAE9CI17CAH6WZ3OCA1HHVIJ not found!
File\Folder C:\Documents and Settings\Johnnie\Local Settings\Temporary Internet Files\Content.IE5\R0CZ6CEL\GNC1RCAUM36SECA1W1ZHUCA5SJV42CA3O6MVCCAAYNT3MCAT50U8SCAH2RWDSCARZ0T1FCAME3IZPCAXO1H8ZCA469VBQCA
JLCYGVCAMNCOPZCAJS11PYCAPO3WD3CAMKQ21ZCADNFLBKCAH6H02BCAG140KOCAYOM2K5CAQR4MNT not found!
File\Folder C:\Documents and Settings\Johnnie\Local Settings\Temporary Internet Files\Content.IE5\R0CZ6CEL\GQRV0CA55WTY5CALU69QQCACJZS80CAKS5O0WCAUYW9JFCACQYUZVCA0AIW9YCAG8NMM0CA0BE9Z0CA46D9H4CAR0C7AZCA
8A3HQICA4H0QF6CA0QVR4LCAQSGHVRCAK6ADISCAN9VAJWCAXI1QZ0CACDJXJKCANU9NNACAGA79F0 not found!
File\Folder C:\Documents and Settings\Johnnie\Local Settings\Temporary Internet Files\Content.IE5\R0CZ6CEL\H91RMCALI87HFCAFEQBOJCAQB8TMICA0Q3W6CCAI2FO3YCAG6CN47CASFS0H3CANHKA2XCAS51NPDCAWHINVBCALP7HB2CA
ETJYT9CAT4V54NCAKFQ89CCAXBZT8JCA13DVXVCA36EXHYCAWT0EJRCAVELWRNCAMKSE1ICAR08BY5 not found!
File\Folder C:\Documents and Settings\Johnnie\Local Settings\Temporary Internet Files\Content.IE5\R0CZ6CEL\HQ22XCAR68YUCCAQNJ7C1CA9PM3YJCA6A8406CASFIZQ3CA92AVK8CAR9D8TKCA2D6KJ3CAHY59I6CAVR3Z43CALS4YFDCA
EB5TS9CAZP536BCAZSDJ3MCAIA0JPKCAVQN56GCALVW7DACA21WMENCA71F0N3CAZPF7RICA7YVEGR not found!
File\Folder C:\Documents and Settings\Johnnie\Local Settings\Temporary Internet Files\Content.IE5\R0CZ6CEL\HUL9YCAFDFOD4CAT9X1KSCAT10P6WCAZG9SHJCA1F10NXCATEGEJ2CAFUI5TCCAZ6B3ECCA4ZNG9SCAIPXT16CAWTSDHACA
1ICGECCACYIRTFCAVM2QTJCAJDZKXNCASWCOC4CAVUK59SCAQ0U01KCAWTIIJ8CA6RSC14CAYX6TRF not found!
File\Folder C:\Documents and Settings\Johnnie\Local Settings\Temporary Internet Files\Content.IE5\R0CZ6CEL\I6G3BCAVU1TS3CAVYG4BCCAEV7DLUCA50FZ3ACA2OUYE0CA0C5HTFCA7VIM74CATNR2OLCAHTGV29CAJYQ3K4CABQ32A2CA
1BOOA7CA9YLV31CAZ0HS5KCA2NQIFZCAX3L126CA6ZT8RXCAKGI7CJCA9JALVHCAIFMAE3CAG32KJB not found!
File\Folder C:\Documents and Settings\Johnnie\Local Settings\Temporary Internet Files\Content.IE5\R0CZ6CEL\KMXCCCASB4Q1SCAAKX4DNCAMHIF1HCAE5TP3ACALUCGS0CAHLK61ECAJIQVZXCAFYVJBVCAR2TSCSCADT463PCAEEB7E2CA
N0KD6RCANM0VJ2CAZSL9ZXCAN4EB5OCAN62FJ6CAFAX0L9CAP7TJFOCAM3T80PCA7078C4CAK04AKJ not found!
File\Folder C:\Documents and Settings\Johnnie\Local Settings\Temporary Internet Files\Content.IE5\R0CZ6CEL\MY98ZCAMQF32ECAC06YTACAKGAECOCAEFJHZ5CA5NMGEMCAOHU4Q4CAV237MGCAY20OCMCAV1SNEDCAV20TFJCAXT95GYCA
OYG2QLCA3TTAKJCA77DB4KCAPJSFGYCADXHU95CAXSJFL9CAOFL60ACA9KANR1CAITLFATCAXC8QYJ not found!
File\Folder C:\Documents and Settings\Johnnie\Local Settings\Temporary Internet Files\Content.IE5\R0CZ6CEL\N77NJCAW9X27ACALX7VT1CALIBA49CARNZ31FCAEZ45Y1CASV4JP3CAC4Q391CA0CUKLECAHXNA9TCA4L9DGDCA97GFG5CA
FDQBADCANW3N7BCA97WX5DCAWV10EWCA8CXYB3CA601FFWCA1BDLBKCA9IK2X5CA07KRU1CAHCLPT2 not found!
File\Folder C:\Documents and Settings\Johnnie\Local Settings\Temporary Internet Files\Content.IE5\R0CZ6CEL\NN07NCA17BXC1CAHVH0F0CAHDK8LTCAXRAPOACAVPYNOOCA01VE2OCAU2AQ2FCABL61T9CAKTCL5OCA2RW0ZLCAETJE0VCA
8J25IPCAM39TQOCA3TFJV0CA99933VCA0OFHJKCAH739Y0CA42J3EECACI3TWHCARX9S1PCAZWJ108 not found!
File\Folder C:\Documents and Settings\Johnnie\Local Settings\Temporary Internet Files\Content.IE5\R0CZ6CEL\NSQGJCA0QP5VJCAPSTAGJCA5ZV5UICARBZJJDCAZV6VPJCA7YOZM3CAU5P9GBCA692QKYCA6DCW53CAD8MNMJCA5IY3XACA
P3SDBCCA391I4TCA633T7QCAASGFODCAX79OTSCAZSPIYXCA4VBVYVCA6QWOS0CA3U51PGCAZPEJ9G not found!
File\Folder C:\Documents and Settings\Johnnie\Local Settings\Temporary Internet Files\Content.IE5\R0CZ6CEL\OHP1UCAVJL29JCA55ILW9CAT89BZKCANED0X1CA0QRYQTCACHY0BCCAAPCZCWCABY35AZCA1PXANKCA2XQNZ6CAOSHHHRCA
ACHAC7CAIP3WE1CAGLD6IPCACV0DIRCALFNYVRCATTJP4HCAWV9GRRCAILPDH2CAD5MCMYCARNNXU3 not found!
File\Folder C:\Documents and Settings\Johnnie\Local Settings\Temporary Internet Files\Content.IE5\R0CZ6CEL\PQM7ICAQ7WJ99CAGDPF0PCA2XWPPVCA5YY63FCAQLSWP4CA18H3ZZCACNP4EHCANOSIY8CAR1JVUACAMWMQFICA6ZFODUCA
DRB8KKCAMC36U3CAQUDBGICA51ZAG6CAF37H30CAA75HQYCAQVD28YCAJE60Q0CAVFL22VCAFBGGS4 not found!
File\Folder C:\Documents and Settings\Johnnie\Local Settings\Temporary Internet Files\Content.IE5\R0CZ6CEL\QEGJ0CA4IGIV9CAH0AVM3CAYBYG2UCACVZ6HMCA34R6WTCAESVFOXCA20CK8WCAE83NBUCA8N1UN3CA5AF52LCAL08YZXCA
Q0KL23CAT7FKRECASFRGRLCANK4DV3CAAO3FBICAN1ELW9CARCCNL9CAG9IA9BCASLTWH7CA0WJCAU not found!
File\Folder C:\Documents and Settings\Johnnie\Local Settings\Temporary Internet Files\Content.IE5\R0CZ6CEL\TQT2WCAM5BHANCA7HQ1RACAF7HDKICASMR5L5CAL3T4M4CA4RXKABCAT3SUFFCAQ01Z3NCAG13OF1CAZ1ZT05CAMOJQKWCA
WTQJMRCAH3O3YFCA0DGKL5CAKBPN3JCA72AJ7CCA909STMCAG86HLWCAUOK4A5CAM9V637CA4XI9YT not found!
File\Folder C:\Documents and Settings\Johnnie\Local Settings\Temporary Internet Files\Content.IE5\R0CZ6CEL\UFXJ8CA8Z0KK1CATNIGXNCAG51GX4CA04MNDDCAAK00CHCASKKNJACAJGYL4CCADZ6CRXCAAD0IU3CA9MLGLBCA64EV74CA
6QHEDACAWQD2UJCAQ1YR3OCA184VY0CA6TBD6ECA70GZN2CAM4J6QACACEASTLCAZP13A5CA6FBDYZ not found!
File\Folder C:\Documents and Settings\Johnnie\Local Settings\Temporary Internet Files\Content.IE5\R0CZ6CEL\W0FN9CAMOBL08CAR1BJE5CAPNNGG4CAFIA4WHCASE7EQZCA9ORAZ1CARHHAVGCAD5RSLSCATFOQ7HCAXXWJNCCAXUHXWACA
LBNCSZCAIL2407CA4G7PXNCA0X3G5NCAIEDWR0CAWVKWMMCACI8H6FCA8L37S9CA62SV22CA6X1WV0 not found!
File\Folder C:\Documents and Settings\Johnnie\Local Settings\Temporary Internet Files\Content.IE5\R0CZ6CEL\WGPLECAO62RN1CAAV8XCICA66IYOGCAT6G5HRCAEI5TSUCAO3O5O9CAYQ58HFCAVFSPN5CAOTET7OCAGGGJ2ICA6HE91HCA
L0SFB0CAYSM988CAXRQ033CAZ1OKDFCAH5EG47CAQEQD50CA9QU3V2CAI3R68LCAOK1YI5CAO2T1OH not found!
File\Folder C:\Documents and Settings\Johnnie\Local Settings\Temporary Internet Files\Content.IE5\R0CZ6CEL\WTGGCCA6NU9PLCAHJHYEKCA36CSHJCA8PQR0BCA7VE21DCA43SMB9CAPVVVBVCA6BB7L8CA1PQZ1MCAFOX27ZCA05MJEICA
RQ29X6CALTBFECCA17RTG1CAUIUA5VCAPSLYCLCAMYOX82CABFNVXUCA96UMUWCAHVUQWNCAC2XQAK not found!
File\Folder C:\Documents and Settings\Johnnie\Local Settings\Temporary Internet Files\Content.IE5\R0CZ6CEL\WUOK3CA3K9AQCCAAASJWWCAH99R6ACAI3TL9JCAQFRJAQCAHQ03H0CA22N5BCCAKFT1DZCAJW61LMCAY09ZU9CA1XYZ5OCA
24S1F8CAVP4X4QCASSMW2LCAY390A6CA5U9FH5CAJDGH97CAO9H0FXCAXEN9UECA8A65JUCACOFFSA not found!
File\Folder C:\Documents and Settings\Johnnie\Local Settings\Temporary Internet Files\Content.IE5\R0CZ6CEL\XW5O0CAE56F60CATTLL9YCAIDEVKHCA7RVFR4CAM21YE2CA8VGB4VCAX7T0SGCA5QUFF2CA3NZ93YCA1CM5OHCA3DAYHOCA
0O8SZKCA96PSISCAHUB7S1CADKNX02CA4RH3KUCAOWORLHCAPBIQSFCA6GD7WECAAZHXNXCA14UFTW not found!
File\Folder C:\Documents and Settings\Johnnie\Local Settings\Temporary Internet Files\Content.IE5\O9R42Z0Q\0FELLCABQ7G96CAS7UQQRCAN47Z2GCA2RGT8HCA88RL4VCA36PIXCCAEQB2UFCAGX0T9VCAMWBK6MCAQ7WJWXCA4YW4ZHCAOA
MTR6CA6JKNSJCAU4SFQGCATV9ZG1CA8LIE7ICAMACMWQCAJ3R2NDCAM8Z3KICAGCV94PCAS6SS6Z not found!
File\Folder C:\Documents and Settings\Johnnie\Local Settings\Temporary Internet Files\Content.IE5\O9R42Z0Q\0NA5PCAE5FS2WCATTYCV5CAOEB184CA1KV7QDCA7L0ZDCCAJ664BNCAD9NS9DCABD2P1HCAB41DBQCACF8FIBCA6M2H87CAAG
02QVCAKZGDP2CA7UZ7M9CA8Q6UT3CAOK4IUCCAF5TG33CAN9GX2VCA6AFZO7CA52D6J4CAZXTOZL not found!
File\Folder C:\Documents and Settings\Johnnie\Local Settings\Temporary Internet Files\Content.IE5\O9R42Z0Q\1YLB3CAGOGCQLCASQKDY5CACCLL9ACA7SCGHSCAFGOSP4CA1MWMT1CACU30T0CAMSTE8MCA9P88GOCA9E913YCAXQKX6SCA
6XLM8FCATS10DHCADHDFJGCAUBQ6WXCAO5S6X2CAW7TZ2CCA3372UXCA7FUSZECA283Q17CAKJ5PT3 not found!
File\Folder C:\Documents and Settings\Johnnie\Local Settings\Temporary Internet Files\Content.IE5\O9R42Z0Q\22CWFCAVEHEH2CAC948GFCAIOFAMPCABEPGORCAOXK4MXCA9DY170CA4TSLLFCADPR32JCAM7GX0SCAOD9364CA8844O6CA
XX29YWCAOMRIQ0CA66AHFNCAATAZ6NCAXDPTVECA00NQ80CA6A7CR0CABLXUIDCA8ICJNKCA2KD2ER not found!
File\Folder C:\Documents and Settings\Johnnie\Local Settings\Temporary Internet Files\Content.IE5\O9R42Z0Q\2ZA06CA254YZQCAYHFQ78CA9VUGV9CA9I103ZCA736M4TCA97GO3FCANR20BMCANZ09VSCA9L67F1CAKDR343CAJW7Y4ICA
2I15IICALWF3R6CAMNB6MCCABDL96JCA9SL0D5CA38AS6XCA3UI6ROCASUZY01CAWN934XCASY3OQC not found!
File\Folder C:\Documents and Settings\Johnnie\Local Settings\Temporary Internet Files\Content.IE5\O9R42Z0Q\364W2CA9P4ESMCAQZ8MP3CAUHPBCBCADW90BACAV89W93CA4X5JSYCAEDJ0KQCAPDIN1CCA4MCUPVCAOYY8ZVCAP0BSCSCA
BG75W1CA4C5H52CAIV9GE9CABIUGVBCA5AM5ZPCA9IEVV3CA9ROX24CAFXDDJQCAOVWM45CA2M2GJ0 not found!
File\Folder C:\Documents and Settings\Johnnie\Local Settings\Temporary Internet Files\Content.IE5\O9R42Z0Q\3GYZ6CAFEU82CCAXDLB53CAHCVX5ICANAJ9UDCAH853ZTCA61AGTPCAZKBRXOCA73DT7QCAU95KECCAIMWSRSCAXXAEL3CA
OGMW56CA8GCCGBCAJWVW7WCAKQCJBYCACX45LPCAYDMPD7CARVDHSWCAWC1K3JCA0PECA6CAY9U1LC not found!
File\Folder C:\Documents and Settings\Johnnie\Local Settings\Temporary Internet Files\Content.IE5\O9R42Z0Q\4LX9GCAFQTC0PCA1OBYMJCAZ9FDWBCA3WBTH2CANKNRIWCABGWUMJCA4YX8Q2CABTYZLVCAXM4P3QCAB8G30LCAIUX8LGCA
K7NVE2CA99IS9RCA7CRYBFCAL0RLULCAWC2FBHCA1UWFBYCAHK4UEMCA09EAEECAQXDWEGCARRZIH9 not found!
File\Folder C:\Documents and Settings\Johnnie\Local Settings\Temporary Internet Files\Content.IE5\O9R42Z0Q\6V7NICAB182AECA4U8XPACADRT9S7CACUM89GCA8V3LXXCABE9O6DCAVKCDU0CAH262UZCAKK06W0CALMEHHECADI5AAQCA
KPCYCBCA5IDQ7SCAQEDWHHCAR9YYPUCA292VH3CANZFI5WCAJQEOVGCABLFBPICAFIND5ECACQ2TJV not found!
File\Folder C:\Documents and Settings\Johnnie\Local Settings\Temporary Internet Files\Content.IE5\O9R42Z0Q\AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAADwLAQAAAAAAAIAAgAAAAAAw7ImPiIBAAAAAAAAAAC[1].apYEC
VQ8AAAAMNErnyoAAADwMsNhAAAAACjRK58qAAAAAAAAAAAAAAA;contx=tech;btg=;ord=1246583239 not found!
File\Folder C:\Documents and Settings\Johnnie\Local Settings\Temporary Internet Files\Content.IE5\O9R42Z0Q\AAAAAAAAAAAAAAAABRAwQAAAAAAAIAAwAAAAAAhRMoPiIBAAAAAAAAAAA.CpYE2akwAAAAUAxjmioAAADwguFQAAAAAFAGU
M8qAAAAmDJRlioAAAA=,,http%3A%2F%2Fad.harrenmedianetwork[1].com%2F,;ord=1246583329 not found!
File\Folder C:\Documents and Settings\Johnnie\Local Settings\Temporary Internet Files\Content.IE5\O9R42Z0Q\AAAAAAAAAAAAAAAABRAwQAAAAAAAIAAwAAAAAAmlInPiIBAAAAAAAAAAAAAJYE6Y42AAAAMJEjUisAAADwEoNgAAAAANAW0
MwqAAAAGOJRlioAAAA=,,http%3A%2F%2Fad.harrenmedianetwork[1].com%2F,;ord=1246583280 not found!
File\Folder C:\Documents and Settings\Johnnie\Local Settings\Temporary Internet Files\Content.IE5\O9R42Z0Q\AAAAAAAAAAAAAAAACIcgMAAAAAAAIAAwAAAAAAtConPiIBAAAAAAAAAAC.apYEiVc.AAAAgHl8pyoAAADwYqJZAAAAAHh5f
KcqAAAAAAAAAAAAAAA=,,http%3A%2F%2Fad.harrenmedianetwork[1].com%2F,;ord=1246583270 not found!
File\Folder C:\Documents and Settings\Johnnie\Local Settings\Temporary Internet Files\Content.IE5\O9R42Z0Q\AV4U9CA28Q3RPCAH9W7F0CAJPEYU3CADI8CTSCA0QAYCWCA1EQAFJCA2KU224CAUXZH05CATKPS66CA4UNJ6ZCA3MD9E2CA
9LLP6KCANKK50ICA1O7JQ2CA6KZ169CAQMYIU4CA0DK7KLCAHMIPVOCAWB6O41CAKLGHT8CARG9V78 not found!
File\Folder C:\Documents and Settings\Johnnie\Local Settings\Temporary Internet Files\Content.IE5\O9R42Z0Q\B3N01CAN796B2CA98OUJ7CAUV0IEMCA5MGJ7YCA6IP6YGCA1MPP8ECAX5KFLBCAG6X457CA9FJGNJCAVU9V0ICAXW7ZBQCA
A8JBOCCAUMGVZOCAUII2YZCAP3TBBKCAJNIF87CA1TB9CTCAODLOOVCAKJ2XY4CAVS056DCAVVPE3C not found!
File\Folder C:\Documents and Settings\Johnnie\Local Settings\Temporary Internet Files\Content.IE5\O9R42Z0Q\BVAOTCASN2OVKCA2DT4SYCASWB2J9CAIKND4QCAHF88CNCA307MLICA5RQHVICAMHI38NCA7C08TOCAVIZ37ICAISAR6XCA
SLOCNXCAN7M9ALCA7H4VVJCA522V04CAQA879UCANW8JKFCAWBT88FCAGQL8HYCAVZHF9MCA5UGJTS not found!
File\Folder C:\Documents and Settings\Johnnie\Local Settings\Temporary Internet Files\Content.IE5\O9R42Z0Q\BVTQXCAO0SPEOCAXMQ47GCADA4X2ICA4RBR4DCAT64S0SCAYVEKBFCAFW8X3SCAH19XVGCAIP1ZHZCAGYDDKUCATLM6ZNCA
0RZU1TCA6RDJLRCAHWLZ6TCASYYKQ9CAZBO4K3CAV62TGHCAV6W4VJCARLRW15CANUAZHWCADSE449 not found!
File\Folder C:\Documents and Settings\Johnnie\Local Settings\Temporary Internet Files\Content.IE5\O9R42Z0Q\C87KHCAQ4AOA1CAYLZS4KCABZCVKQCAI8AWVLCAHR6PDCCA4YQ64OCAP0KA2UCAY7SIOPCATXZI1VCAZDOBQLCAWTVF4MCA
KMYQPGCA6N1IW4CALG90RACATHELVYCAE6QHZ9CAYF3J0ZCA3RI9NKCA1SE1U1CAAW86AVCANL87RS not found!
File\Folder C:\Documents and Settings\Johnnie\Local Settings\Temporary Internet Files\Content.IE5\O9R42Z0Q\CQ1T8CA461FAYCAGW116ZCAU5RO6ZCA9TNOWKCA89WJNTCA7LTLULCA43BPBXCATDZQMJCAIG3I2HCAM5975KCAKQ7YZ6CA
721LG0CA3G37HRCAWNICTHCAJL2PAJCAJ7PUW4CANTQIZ0CAF9VE6WCAKK83BRCAA554X5CALK65NB not found!
File\Folder C:\Documents and Settings\Johnnie\Local Settings\Temporary Internet Files\Content.IE5\O9R42Z0Q\DD2GACA1QWEA3CAV43ZN6CA0GJ54MCAB3Z4VNCATZX5O9CAL2DV56CA3EUYTZCANBTCNKCA16G7GTCAVTZELUCAVE2S0NCA
3BTOA5CAZTH4PUCAK20Q59CAL5X50OCAB0PRALCAOMTNNWCALZ9KQ7CAPCEN3FCAAAYI2QCA4Q3R93 not found!
File\Folder C:\Documents and Settings\Johnnie\Local Settings\Temporary Internet Files\Content.IE5\O9R42Z0Q\IMFCDCAN45H9YCAFSPEYRCAX6VJLOCAYPDPK0CAB08P98CAAMKL5HCAGXUP1DCAXLV76CCASUCMLHCADP2XJVCAXERHN7CA
C53J3TCA8UZEJBCAQN6YRUCAS36CVYCAOF4RTYCAD2J0KECAFTYYEXCAS79UVACAFB2V1QCARYAIL2 not found!
File\Folder C:\Documents and Settings\Johnnie\Local Settings\Temporary Internet Files\Content.IE5\O9R42Z0Q\KLA8OCANATK5DCASBDGFLCACATBRSCALMMBIRCAXSJ8MECAL9C3GMCAO78XSBCAQK92D8CA459GATCAY1VJ8MCA2E3C4ICA
M8XNUWCAKQ1A1ICATPYXM5CACBQZEJCAHVHGASCA1TS4R9CAI1IVOFCACFYHXPCADHM4AQCAGWAI77 not found!
File\Folder C:\Documents and Settings\Johnnie\Local Settings\Temporary Internet Files\Content.IE5\O9R42Z0Q\LF2XZCA0UDZ9ACA5TK4KRCAE6UC2ACAMTIF8GCA1F7MKHCA0BRWVMCAGRBO7PCAB10EAUCAM8SYSECAZV26EDCA6DC11PCA
312FMCCA0U954ZCAC13C5JCAU56VCUCAMWQS3BCAU7J2AWCACROCALCAGDLGKWCAW2OUYPCAELYO61 not found!
File\Folder C:\Documents and Settings\Johnnie\Local Settings\Temporary Internet Files\Content.IE5\O9R42Z0Q\LX16TCAHRICQHCAC8DMFHCA8AI2KJCAOY2SPBCALBVR9QCAXD1P6FCADQOG7PCAY4BAQ1CAUGHNVVCAPPX9LYCA1IQPONCA
FFN3VNCAVPLQTSCAMTKWX6CA8BE223CADS18D7CA0FNODHCAR0OUXZCA5G64ADCACZRZP7CAKS9YCJ not found!
File\Folder C:\Documents and Settings\Johnnie\Local Settings\Temporary Internet Files\Content.IE5\O9R42Z0Q\MAAC5CAAIZSWGCAMZV3T0CAORE4H0CAEIZP31CAQ2U21LCAY0NIZ7CAMGSXDRCA10YMLRCA10PVM0CAPDD870CANTX23ICA
PQZ1P4CARUKNVECAPZQDVQCAZ6W8VLCAZZND5ECAKSI7DFCAYBUGBICAQJ8SWCCABZL2F0CAT12BW3 not found!
File\Folder C:\Documents and Settings\Johnnie\Local Settings\Temporary Internet Files\Content.IE5\O9R42Z0Q\MB629CA0W4AKDCAJ00DLRCAMKA9M4CAV05Y29CAAXD3V7CAQ0KWTPCAZIRMWBCADX49XBCAETF234CAQDR6BMCAUVAPX7CA
N00A65CA5ZLV0XCAZP6017CATAVZT7CAAPQ9HMCAU3560ICAHWVDUTCAH59L0MCAQYNNTACAL1HAQC not found!
File\Folder C:\Documents and Settings\Johnnie\Local Settings\Temporary Internet Files\Content.IE5\O9R42Z0Q\NA7F7CAWJC8M2CAF8VGWZCAOEHOFPCA640UWRCA10C6FRCA386AU6CAGACQUPCAJVHWT2CA6W5344CAIT6KCJCA03DH63CA
FQ5OEJCAVOTHYQCA5QKJQCCAN91NB7CAZ3P2G1CAEDQ7EECAPVYURZCA1F41KWCAAAOCH8CAFX6JPA not found!
File\Folder C:\Documents and Settings\Johnnie\Local Settings\Temporary Internet Files\Content.IE5\O9R42Z0Q\NLQQYCAUSZT0UCA73KZCKCAC3ECBMCAKF43ZMCALW18W4CAZUP0BICAZ4J4ZNCAWNLJUHCAU518A5CAHPDUJOCALEDGHECA
4XKR2TCAI0D2SGCAXNL0UECAWIKPZACAUAXH8UCAXE9MZXCAA1VHUYCAUM9HPWCAICL478CAC4WPBR not found!
File\Folder C:\Documents and Settings\Johnnie\Local Settings\Temporary Internet Files\Content.IE5\O9R42Z0Q\NYAFICAQBC6MTCAP6K25NCAS2FN27CAHZ439NCACVGIHXCARFZ7CRCATFJXVJCAXNB6W6CAQD3CWMCATVWNL7CABTR6K3CA
7W4BZ0CA2X3A7ECA1XOT4NCAN08EOUCAZV9T4XCACKEZCECAELT7AVCA3JSSBKCAP1OU2LCA0EJ41X not found!
File\Folder C:\Documents and Settings\Johnnie\Local Settings\Temporary Internet Files\Content.IE5\O9R42Z0Q\OTJ80CA3AT2TXCAK4OY44CAUO0G3JCAB0YSK9CALZPK3XCA5F2CDPCAHCA289CA3WFU85CAUOPFBACA543C8MCAAHPSFCCA
BBGDWNCATE8RTXCAK44E20CAW6F7A0CA473LZUCAAM6IASCAO7NZ6GCA77W6BFCA13CIK8CAE17KF3 not found!
File\Folder C:\Documents and Settings\Johnnie\Local Settings\Temporary Internet Files\Content.IE5\O9R42Z0Q\P1FUNCA3B880SCA1BFEX2CARIUWPHCABFPF7MCAJ6GV1BCAUE15CKCAKAABD8CA1UUTTCCAKCV1XACA4A15NJCAOAUPEDCA
8TK6ERCAWTA273CAPKENCSCAQKMMO5CA8QAU2MCAALH26TCA8PGRBJCAJW1HWVCA412S4JCAZ74GC4 not found!
File\Folder C:\Documents and Settings\Johnnie\Local Settings\Temporary Internet Files\Content.IE5\O9R42Z0Q\P3IJTCANZS8QVCAB0O2SLCA8EXXZ4CA0TMTWOCAZGAKPWCAW814PICA3BSDWGCAJROKWPCAH8Z95XCA6WQYFJCAKJ1E6YCA
VCANHVCA9DX9GICADPBCDVCAVJYV9SCAI2Y6FYCAGI81UNCA8JRU9PCADZTBCRCA96VKDFCAVCANN4 not found!
File\Folder C:\Documents and Settings\Johnnie\Local Settings\Temporary Internet Files\Content.IE5\O9R42Z0Q\PU1K7CAYOKI5ZCAGDSHU9CA0M13NHCAM5SE3OCAO2V9RECA5Q1M03CARDEAUKCADLK1STCAT8JKD4CAT72WE0CA3BRMC5CA
S8S63TCA48VMWRCAFUPLS2CADIUHENCAL0L6PBCADHHDYTCARO6PEACA1PFRSLCAAZTB41CAG361DC not found!
File\Folder C:\Documents and Settings\Johnnie\Local Settings\Temporary Internet Files\Content.IE5\O9R42Z0Q\RIC1ZCAOVOPNKCAGGZ8A3CATGK121CAKCNKBHCAZ1XPGFCA32Z0JACAXX5Z7ICAB7B6OBCAFBP912CAN6N0YVCA5HNG06CA
W1SI1YCAPRWI90CA2D5YGLCA7A9ZP7CANPXRFWCA21YDQLCABNV8S0CA388WTICACW9HQACAYIWJSC not found!
File\Folder C:\Documents and Settings\Johnnie\Local Settings\Temporary Internet Files\Content.IE5\O9R42Z0Q\RXZKTCA5XWWVNCAN6Q00BCARPZVJOCAE4EHRKCAVDY2EOCA4TBIVJCAIDKLNYCAA7MF4UCAAKLUPYCA3ABRMPCATCFH8MCA
X9U07XCACXJYK2CAYZLU10CATIL3LSCA4JHFRLCAS1F9AOCAX266E0CAXG7NPGCAWS4PY2CA3CERNY not found!
File\Folder C:\Documents and Settings\Johnnie\Local Settings\Temporary Internet Files\Content.IE5\O9R42Z0Q\S1T6UCALBOLJ6CAVERICMCAQ8C4HPCAUMEQVHCAYF00F7CALZC13WCA3Y85DBCADUNAIICAFDR48RCATN1PGSCAQOL0XJCA
LTW4TFCAJ179BMCAKQ1UVCCAI1BG2UCAQ58AZECAQEW1FCCAJL789CCA49BWTXCA6F8QG4CAQ0VHHT not found!
File\Folder C:\Documents and Settings\Johnnie\Local Settings\Temporary Internet Files\Content.IE5\O9R42Z0Q\SFBU7CATAQG0UCATPM9W1CAXUOD4HCA5VG2A2CAA31JYICA2SXCB3CAQGS4DZCAEK2ICXCAURPJPYCA7YEHF2CACEEGFXCA
AXW9KUCAO2LB1RCAYOWPRXCAX30ZF8CA7S47XNCA7OEMOECAXSUNSGCA4A1F2GCAVBNQMXCAQUS7JI not found!
File\Folder C:\Documents and Settings\Johnnie\Local Settings\Temporary Internet Files\Content.IE5\O9R42Z0Q\UDKJKCAHEHI12CAFS60FWCAXWCC87CA1XT78CCAB0IGFGCAC7E98UCA520MF4CAN6FIYHCA9548UYCAR88WLFCAO698AVCA
2M4BVICAZ2XJS8CAA8OBH1CA7Q7XQ2CAGH34WPCAO6POJ1CA365XMECAZ0VWAJCAV5CD3QCAK857JN not found!
File\Folder C:\Documents and Settings\Johnnie\Local Settings\Temporary Internet Files\Content.IE5\O9R42Z0Q\V2ADQCAEBWIIFCAH58ZG8CAQ58Y4NCAOWAE25CABDHFO6CAW3PD2GCA1LWGDXCA8BVFY8CAJFC901CAUH68SPCA1IDO69CA
87C3VVCAO4482XCAUWGX7HCAXW6D1RCAUCCT0CCAEQH6XBCA8O30M5CAFF4AB3CAT6FRWECARGLAFS not found!
File\Folder C:\Documents and Settings\Johnnie\Local Settings\Temporary Internet Files\Content.IE5\O9R42Z0Q\V7MWRCAJ0PC2VCAZR8OMOCA732Z9ZCA5W4WWHCAXGJZ5VCATI52TGCABBIN2QCAZFMPOICABGZO8NCAQVHH09CA5V80OGCA
W3TSVLCANLQBVYCAE11R7RCAA1QCVHCAMWWRWSCAYUIC1VCAP38NVGCA0BIX1SCAS7CZG4CA2NNC7M not found!
File\Folder C:\Documents and Settings\Johnnie\Local Settings\Temporary Internet Files\Content.IE5\O9R42Z0Q\V8MKECAIXVH8OCAXURC10CAYTP9PCCAK1ECN2CA6JA681CADU6PK9CAW4SZQYCA1QQO2VCASNK65MCASMGN6QCA3ILB8UCA
T3VDPRCACV70VECANC1F0CCAUZQVGYCABVUEVTCAYUMPJ5CALW3BYMCANX6PF4CA299AK6CAIF0XID not found!
File\Folder C:\Documents and Settings\Johnnie\Local Settings\Temporary Internet Files\Content.IE5\O9R42Z0Q\VQS0LCA7KVJ7NCAHIJMV3CA0BLN4NCA4LBG40CAOQTUUZCAML0MXICAU70B2HCAHSEJOUCAFKTFU3CAHUPL1ECAAKS94HCA
8G6FYBCAVBET3UCA5J1G64CATZZ7T3CABLK7VLCAZ1ENQ4CA1DXEU2CA7AZG4NCATVMTHWCAFZTJ79 not found!
File\Folder C:\Documents and Settings\Johnnie\Local Settings\Temporary Internet Files\Content.IE5\O9R42Z0Q\X3RE0CAGQS67ECAE5FQUHCAU5WWB2CAF1OWKNCABCAMTWCA7EM5SWCANLNCXKCACRTPGGCAH889PFCAM68B4ZCAV9ACKXCA
VXAHH9CASOZUMCCAMX4H2RCA0B71HFCAX8R2K0CA8414MOCAFDZ8LWCAXS3DNECAPMR030CAP27FS7 not found!
File\Folder C:\Documents and Settings\Johnnie\Local Settings\Temporary Internet Files\Content.IE5\O9R42Z0Q\XONWXCAFH2853CAMD937XCAILYWIVCA5I606VCAY9CLWHCAU0LUTFCA6FNSY9CAP2DF40CAO8TJPKCAZK0W0HCABB4D80CA
Z1NT3TCAHS2EDNCAA4CDAICAZ8FPIDCASNXVRKCAKZRAPJCANNODNYCAA2A2H1CA1D5KDXCAFHJ3Y3 not found!
File\Folder C:\Documents and Settings\Johnnie\Local Settings\Temporary Internet Files\Content.IE5\FJ612W8B\0AYYCCANKNVVVCA1HQIERCACZ1TRBCAOIO9JNCAAKA958CATRMMYWCAJEOLU4CATUYRRBCA8Q5TQ2CAKY43VSCAP73JELCAPU
PR1GCA72RXXXCA0YGRU0CAB024G3CAAZM34XCABHP7TNCAM1ENG7CAQHF1F1CA7ZPPPRCALRCD1O not found!
File\Folder C:\Documents and Settings\Johnnie\Local Settings\Temporary Internet Files\Content.IE5\FJ612W8B\21XC9CATIN265CAFK8CB3CA5JMRZMCAPMIG09CAZHOA6RCAB8UZPYCA4LQ219CA0JR33KCAGMG8U8CADDD7PSCAAFY8V4CA
HEDLGVCA68UVUHCAS5ZAMDCA0MEU1KCAVZKLEWCAK8MLMKCAPYLDK8CADUTAG0CAPN1FAKCAHSNE21 not found!
File\Folder C:\Documents and Settings\Johnnie\Local Settings\Temporary Internet Files\Content.IE5\FJ612W8B\36KMBCAI05CMLCAWF5FVTCARPBIY8CADREP0LCAXU8G21CANFA6UDCA58B5PVCA32DSVECABOA6FHCAE6MZ4JCANQV633CA
45H256CA32ESWWCABDN969CA9IQHE9CAIRW6E2CA5F3O3LCAQX2372CAY1H8JXCAYQASDHCAMS5FSG not found!
File\Folder C:\Documents and Settings\Johnnie\Local Settings\Temporary Internet Files\Content.IE5\FJ612W8B\3ZU3DCANAV7D4CAC4P9YACA1C5XWWCA5993G1CA8E6Z5NCAA93N50CAUKSV9TCADLN7TFCA54T0KGCAIZ7LTBCAJW34GLCA
XE0V4GCAXWUB3OCAFUHPBICAPRZXVGCA8T75MECALERSVXCA2A0DLTCAM0YIHTCA95Z14ECA5WFERZ not found!
File\Folder C:\Documents and Settings\Johnnie\Local Settings\Temporary Internet Files\Content.IE5\FJ612W8B\432ZRCA9HHB3MCAF3ECBRCAV9JC3FCAPM7MOOCAIBQH8WCAJM2O4DCAYSPDJ6CAG9TIWVCAWRCB1MCAZUPD9YCAQ201S7CA
G3FKTPCAHUNI74CA8US857CAAAB7L9CALKG2BSCA64J6YOCAA12292CA3OCLFLCAKBJFJSCAD1JQII not found!
File\Folder C:\Documents and Settings\Johnnie\Local Settings\Temporary Internet Files\Content.IE5\FJ612W8B\6TRJ3CA53LRKPCAX0JY5UCA3FKUCZCAPGIEHWCAWN6H66CAWOPF81CAOZSV1ZCAIQJ5Q3CABN124YCA6CSVBICAXIRBPYCA
G23CBNCA4WQMG9CAYMNWNOCAIFCE5UCA1E2HOJCA3V52ATCAL3G9J5CA2YO877CAT5OLN0CA67HA7X not found!
File\Folder C:\Documents and Settings\Johnnie\Local Settings\Temporary Internet Files\Content.IE5\FJ612W8B\89DI3CAVH7XU0CAGENE7QCAKQXOSLCAHV6Z61CASBNJ5VCA2VWS3SCAC6EMHCCALQYPJWCAMKIIW1CAG0FQTHCAWGVOTICA
39V5OBCAE3389CCA9H4HA7CAP4U6G0CAVDV736CA1QDE8KCAJWRT8HCA7PUJ9KCAZSDKXOCA0NY5QD not found!
File\Folder C:\Documents and Settings\Johnnie\Local Settings\Temporary Internet Files\Content.IE5\FJ612W8B\8M0RZCA537KXUCACTSRT8CA0UL60SCAIPL8WWCAHRT4W2CAEFQHFUCATK83T6CANSGGQ7CAFFQH6RCAEJ9CCPCA2U9220CA
XUT2OGCAABI2HCCAOFXMH2CA4KV93SCADM2P5BCANLM3O3CAMZF8VBCADHV7ZBCAWE2KN1CACAB7T2 not found!
File\Folder C:\Documents and Settings\Johnnie\Local Settings\Temporary Internet Files\Content.IE5\FJ612W8B\ALRPLCABGSD76CA7SVE3ACA1DWYKVCAT800VDCA3N5SGOCADQ1J82CAL7HYCLCA0O04XICAKJXFUFCA6F5KYUCAT6A4HHCA
NT4470CAIVOKM4CA7E5J3ECAU370YACANY3JXACAODWDWWCASDDHYACA7TRANOCA85JM00CAZ1ZK8W not found!
File\Folder C:\Documents and Settings\Johnnie\Local Settings\Temporary Internet Files\Content.IE5\FJ612W8B\CORY8CA9D0T7DCAQGLMM0CA59ZB9JCA2DRF4HCA2O31GSCA53Q7OECATJSC9ECAG0OQZZCATD196DCAQMS0M7CAGMI95CCA
LAFKVNCARHLZMLCA1NAQTHCAT3NAQ1CA9QQJN5CAWT5W1KCASOR35LCA71PPN1CAMART6YCA5HV5HK not found!
File\Folder C:\Documents and Settings\Johnnie\Local Settings\Temporary Internet Files\Content.IE5\FJ612W8B\D7V99CAFVVR09CA7N95LHCASZW2ORCAA0QX00CAFEVL10CA6YVUYDCAR7DA53CALORLJUCAERT6UOCAT75GL0CAJ6GM64CA
W57S08CA86UGHQCAFXRULOCAZJ28IQCAVCUHLNCAOCAPE0CACFQRAGCAHS7MUMCASTYIT8CAVH8PQC not found!
File\Folder C:\Documents and Settings\Johnnie\Local Settings\Temporary Internet Files\Content.IE5\FJ612W8B\D9IP1CAB4G4TQCACTHJUTCA7VQ693CAOAEUYNCACZYC1HCAXFHFU7CAZGCORBCAT0W7ISCAQR8Q5OCAPAHY2BCAVZAAJGCA
13B6F2CAYPPDFDCAXVZN84CAZFCOVGCAFQJ7RHCA4YX0NVCADAWSOZCAWIXOZZCADC6003CAKQX31J not found!
File\Folder C:\Documents and Settings\Johnnie\Local Settings\Temporary Internet Files\Content.IE5\FJ612W8B\DHM6ACAY18YIWCAE7L53UCALXZX6ICAAH5PAMCA7JE8PCCA3JZFO2CAFCM9H7CA4I92XNCAJKF20XCAJ2BF50CAA7VFRZCA
HWT7B7CAZ72VQQCASML6X2CAETYR8ACANG5CZZCAUZG23TCAD0RD7CCAJ3QN2ZCAEHEMZQCAMPVVO9 not found!
File\Folder C:\Documents and Settings\Johnnie\Local Settings\Temporary Internet Files\Content.IE5\FJ612W8B\DS74WCA3JZN3ECA4UAAK1CAV3L34GCAWSEUR1CAPVSWE0CA14KR2ICA7MSABTCAO542YXCAS0F9MOCA2JR7UTCAOKD6YSCA
NYALODCAHTSEKPCAEK1N49CAT9BH9SCAOGVR9FCAN38PWSCAIXQ1R8CAPWIFLGCAV9TUNMCASFYIXW not found!
File\Folder C:\Documents and Settings\Johnnie\Local Settings\Temporary Internet Files\Content.IE5\FJ612W8B\DSARTCA2GPFVVCADKQOVZCAP0KUIZCABSGKS0CA8197N5CABD8OE1CA96RLT3CA2ICI58CABQK5IPCAJJ3QJ8CAPVUDBLCA
LYN08YCA1B4TEDCA9CJUBKCAYF0R7VCA38505UCAEJDX1QCA3GUZ6ECAGIPEP0CAF1ISYQCAFYMKKG not found!
File\Folder C:\Documents and Settings\Johnnie\Local Settings\Temporary Internet Files\Content.IE5\FJ612W8B\EDOMOCAWIB3M1CA761K4QCAQ34CQBCANUMB2KCA33V0ZXCABRWC74CAW05QZTCAD4SZWSCA80J47XCAXISXL8CA6KX49CCA
EQPXX6CAE01MS2CA0KR7CVCAEUDJCRCA8FIG20CA8MCFHHCAGW0BN1CA9C15WXCA8JXDDBCAIE8FJT not found!
File\Folder C:\Documents and Settings\Johnnie\Local Settings\Temporary Internet Files\Content.IE5\FJ612W8B\ENQXQCAG3YFB4CAUGXLGICAAA2NEHCAR1T9NRCAM6MP9XCAMUCEI8CATJ1KZOCAVU12X5CA4O2I8DCAML9X10CA9QEME4CA
E7TH9LCAWWYXWTCA2QM0KRCAAUWBPSCAOK2NJXCA7KY1RLCACR6D5FCA0L4ICOCAI4RI45CAJS8B36 not found!
File\Folder C:\Documents and Settings\Johnnie\Local Settings\Temporary Internet Files\Content.IE5\FJ612W8B\F1QH4CAWYY65RCAUETO0HCAMWA1JWCAQS98GCCANHNTKFCAPHPOSOCAL2T50OCATL5F7LCAW6WH4ICA53P784CA7X5N2VCA
SBRZM9CAP2802SCACUSTAACA3G2U4GCAEQM3GGCA6XHFY9CAVPK3MJCAJMZF4ICAP29OPGCA1IET20 not found!
File\Folder C:\Documents and Settings\Johnnie\Local Settings\Temporary Internet Files\Content.IE5\FJ612W8B\FICO3CA8E9AO1CAM868QHCAM1YEYTCARQXSNDCAT03I4ZCA60JDQECADCBPKQCA39AWSDCA2X09WYCAOWX2VFCA137RLFCA
F19V4ECACBV5I9CAB0Z0ZRCARUBOR5CAQ6RLUDCASGTR55CAJADUWUCABLQMNKCA7F6FY3CATZ7GII not found!
File\Folder C:\Documents and Settings\Johnnie\Local Settings\Temporary Internet Files\Content.IE5\FJ612W8B\G115ICA9PFX3XCAGWSF30CAUOSFQ0CA9W272MCA4ZRH19CAUUQ4EDCAEB79V5CAGV7J7BCAW0WC3BCAIQ0JEOCAFANE1QCA
7RX5JZCA2F2ZGOCA1EG0D3CAPWCE29CA2SMV0VCA4252QICAU7IECFCA19HZWNCAR5I8RCCAL0T03Y not found!
File\Folder C:\Documents and Settings\Johnnie\Local Settings\Temporary Internet Files\Content.IE5\FJ612W8B\GKLIGCAGYMO8YCALU4IIGCAOB7HM9CAE8SF1CCA3CK4U0CA3370F6CAL6IMQQCAEU4Y8NCACPIV0GCA8S7AS3CAODJ8GUCA
JG4UK3CAZ3JCX0CA9T4LIWCA3BTCA7CAUWQPRBCAFEX8I7CAETLH0CCAK0UARUCAJB0VERCAWXJPHR not found!
File\Folder C:\Documents and Settings\Johnnie\Local Settings\Temporary Internet Files\Content.IE5\FJ612W8B\I18JCCAYZFQ4JCAR03SS5CAUGLC5RCAERTCW9CAXZTSZHCA4IFABGCAX0EURJCA7NLO16CAIL0827CA2RPO1HCAQJINNJCA
ISYZQTCAX3RZJSCAR73V47CAI78Q4ECAW2UX51CAGUO563CAS8ORG4CA5LGTIYCAXZM9L6CA13D3LU not found!
File\Folder C:\Documents and Settings\Johnnie\Local Settings\Temporary Internet Files\Content.IE5\FJ612W8B\KL13GCAYWVI6WCAF6ZQ2XCAGAHRV1CA42JD16CA8YAKHMCACLD4VKCAEA22TYCAY4KVPOCAEJZBTDCA8COPKQCAC2VITVCA
HTLMCNCA11XHFGCA9TD31KCAN2EE7HCAQ0H7C7CAYGMXVECA3H0OYFCAGOEKPZCACCLA4ACAOOI0UG not found!
File\Folder C:\Documents and Settings\Johnnie\Local Settings\Temporary Internet Files\Content.IE5\FJ612W8B\KR1FGCA8Y2RERCAUK47Y1CAKPUIH4CADTO0ABCAK5P64ZCALYSWW9CANODN1QCA42NHKECAFQ540PCAA39NMZCA99HY16CA
8V4218CAS740RICAJJ6PTQCARAHKOPCAF3WIGTCA2N4CBSCAZBEA4YCAYVBZQ7CAVX216UCAA938QR not found!
File\Folder C:\Documents and Settings\Johnnie\Local Settings\Temporary Internet Files\Content.IE5\FJ612W8B\LPGK7CAEM13KOCAL8UEXICAYHZUXNCA0G0A5BCAXT9MLTCAGN74XKCATEBWNDCA1EFR35CAD5ALCJCA52DSTPCAJ3FHBJCA
SDEPOMCAP31I1JCAOVCGIMCAF36JC0CAFM2H7KCA51MZURCAMAL9HZCA1XKACLCAR1O6ITCAB1EYDJ not found!
File\Folder C:\Documents and Settings\Johnnie\Local Settings\Temporary Internet Files\Content.IE5\FJ612W8B\MFB5DCATAX5AACA5720DCCA3Z3GC8CAL79VDRCANBKZTWCAEK1HOBCAJS5NAOCAA54CF6CA0JVKYNCABIILG4CAYD4R8VCA
B4DSKDCA4BYN0YCAW5JR0ACA1ED96OCAZV85SKCA4P35O0CA5EW8TYCADJCXCNCA048OAXCARQLBZ0 not found!
File\Folder C:\Documents and Settings\Johnnie\Local Settings\Temporary Internet Files\Content.IE5\FJ612W8B\O3TZZCA57JB5ACA294WH1CADT7QLCCAFXBI03CA7WRBZ8CAGIBHVVCAF1MDSACALEH04XCA9X40OBCAPFUGO9CAELH2MQCA
DC6K64CAC1BXIZCA170YQ5CAHCYQWRCA3NC2Q8CAJ7Q082CAF0MXGWCAU1QG73CABUTGMKCA8IPVC1 not found!
File\Folder C:\Documents and Settings\Johnnie\Local Settings\Temporary Internet Files\Content.IE5\FJ612W8B\P6XUYCA5YVL3KCA89NZY6CAW3R7YUCA64CL00CAUSPQGMCA3UYJELCAW6ZLUDCA5B2TMRCAFZHHRLCA2Y6H1WCACTK6V8CA
O3O8R2CA84FRNKCAAQI6DZCASNIY6ACA5GBSM7CA439TYUCASNO0TQCAEXHPONCAH79V6QCAK1VRH3 not found!
File\Folder C:\Documents and Settings\Johnnie\Local Settings\Temporary Internet Files\Content.IE5\FJ612W8B\PHVO5CAHCUT90CAY8XLDNCA7DS17TCA8SYJQLCAHGTLJJCAUU6W9KCA13TZJWCAXJZUWPCASO04BHCA6VH23BCAR3MY21CA
OFY8VZCAOP6XHQCA1D6J5KCAY9GCSOCAN8A58NCA0CX5N1CA6ZKG39CAV0VQBQCAHIFB30CASC0KQ3 not found!
File\Folder C:\Documents and Settings\Johnnie\Local Settings\Temporary Internet Files\Content.IE5\FJ612W8B\PLIQYCAPNO6QVCADD8KCMCA2ABNYTCAYIDLGLCAB8KU7LCAWJE0QSCAH3HPE4CAQMNPSUCA7BMBGNCARVOEOLCA4JAGNWCA
SA6NJLCATDA7G7CASI5QN3CA75QCRSCA7KU7D6CAQ0HDWACAZ8GVXJCABJWG8UCABSALRLCAK6Q159 not found!
File\Folder C:\Documents and Settings\Johnnie\Local Settings\Temporary Internet Files\Content.IE5\FJ612W8B\Q453ICAKB8Q7WCABWI09KCAYKTXN6CA2I68G7CAPGPRCPCAP1W7J4CAAQJLS2CA9A6QT6CAYOPLYICATIR2THCAQA8Z1PCA
EVIT1SCABII2VXCA0EWGWHCAY30M4XCAXBY8FDCACSUOVECAZL2Z79CA36DO4CCALS4N0GCA4F5BCT not found!
File\Folder C:\Documents and Settings\Johnnie\Local Settings\Temporary Internet Files\Content.IE5\FJ612W8B\QCTABCAJM5HAHCAFWL9O6CAR9IFC4CAZH6S0GCARLZJE3CA84TEAVCARQI1X9CA7AXUD1CA89M38OCAH5LQUSCA6QTG4LCA
WE10ZHCAMFUQEMCAZSSSRCCA4VLS6LCAIJE1H3CASRCUT8CAFUZM85CAVAL1YKCAHOBRW5CA2POHZA not found!
File\Folder C:\Documents and Settings\Johnnie\Local Settings\Temporary Internet Files\Content.IE5\FJ612W8B\QFZI0CA9KI2A1CA0GMY0KCAAB3LFUCAJV7MVTCA7UI77DCACX8KYPCAFTOL9BCA3F81ZVCAYGL8BECAHQ826DCA3KXK7ECA
DU80PPCA1NG49CCAQTBJETCA8JJG3PCAHIJBA3CA8YDSZDCASVFI69CAFNE2MGCAG1VE3QCATN4UPP not found!
File\Folder C:\Documents and Settings\Johnnie\Local Settings\Temporary Internet Files\Content.IE5\FJ612W8B\QWU68CATZ3LBOCA08MH6CCAYLPUF0CA73C7THCA9SUBXXCAX3X062CAXTLWDICAI7P31ECA028XF6CA2YQ4Z2CAZCPL19CA
F5AVRICAXDDA2KCAM066WQCAB6GU3UCAB9L3UTCAY2FTB7CAN2C9LPCA0HROCYCAHUU36HCAWPBX4K not found!
File\Folder C:\Documents and Settings\Johnnie\Local Settings\Temporary Internet Files\Content.IE5\FJ612W8B\RPRYXCA66V4BZCAQP94J4CANYZBUECA07ONBHCASVGMYBCAHAEW1ECAB7OP3LCAMVI9HLCAFLRS80CA81C851CAUD09AZCA
2HQTXVCAF7BLZKCAKGEJLZCAUSMSUUCAB49BESCAUL9QGHCAPBGXKCCAWOF012CA74GGDVCA63M6IU not found!
File\Folder C:\Documents and Settings\Johnnie\Local Settings\Temporary Internet Files\Content.IE5\FJ612W8B\RT4VDCA0XGS3PCAATO4NICA4AYWJWCAFQ0D8ZCANN0OBQCABDZTHKCAYL0LMTCACIMW3OCA6LWQ52CAUMQ4SFCAE07W2ICA
VYFX08CAY1UJV9CACF7BZLCAJGTOIGCA9FM8XGCA5EHMUJCAB7GX35CAUSJC98CAZ41JCFCAYY1SO9 not found!
File\Folder C:\Documents and Settings\Johnnie\Local Settings\Temporary Internet Files\Content.IE5\FJ612W8B\SD9EICAJ03O1ICA98LDUVCA5WB3V6CAFT4H2FCA52RB04CAUCQWX6CA421DCECA74VWPXCA8KU1RCCAQS4X1DCAZTFKS9CA
V9BY1OCA1RAN24CA4U2GDCCAB31AA0CAJXW0F8CA4SOZYICA2P82F9CA7FM22DCAULEJWOCAFKFR8J not found!
File\Folder C:\Documents and Settings\Johnnie\Local Settings\Temporary Internet Files\Content.IE5\FJ612W8B\T0R65CAY2VU0OCAY8Y17LCAH48F23CAF4Y0PCCAPKWZI5CA3JQJV2CAT63EOPCAUXT1MSCAICGXFSCA9JWXATCA0J0VGJCA
KJ4RDECAH8BLNYCA4BX5HTCAQ71YJ4CAEKOJF7CAZE7J47CAWDEHGPCAZRNAK9CAWNJXZ1CAXACVOU not found!
File\Folder C:\Documents and Settings\Johnnie\Local Settings\Temporary Internet Files\Content.IE5\FJ612W8B\UGZAVCA0IGXOPCA8JQAIWCABROZY0CA6TUUIZCAJ70CQOCAFY4T45CA7MVD17CAUFDU9ECAZRJZTQCACLBR2QCAC9JS4JCA
UQR1U5CAVIGZFKCALHB4A9CA1T1BU9CAWMO4UPCA18OBIJCARZ8DABCAVHSELUCALYU2LICAZKSOLH not found!
File\Folder C:\Documents and Settings\Johnnie\Local Settings\Temporary Internet Files\Content.IE5\FJ612W8B\UQ0X2CAZQ1JDBCABQNLYKCA4WH576CAXIRP1ACAIFAOPNCAA3TWI8CAZPPI6MCA89G2D2CA49DYNOCAZEM3Z0CA2Z6POACA
S6WLMQCA3AOW3OCASIHYBACANF069FCAYXFBGGCA8MQ7DDCAU3J0TXCANJPWB1CAAXXFFGCA6POZK2 not found!
File\Folder C:\Documents and Settings\Johnnie\Local Settings\Temporary Internet Files\Content.IE5\FJ612W8B\V4DLECAH7JPWGCAVKCKY1CA1DCUSXCA4L3ZBDCA6AYENNCA708OSSCAIKCF3GCA2CN3VHCAS1KK6VCA4T4UQ9CA496RLPCA
VV6MCQCAEWLTRICARJC1BFCA81R6TYCAS9CMLVCAD9EHAICANYVB5DCAS4TQCFCA0ZRNMOCAP1R0LC not found!
File\Folder C:\Documents and Settings\Johnnie\Local Settings\Temporary Internet Files\Content.IE5\FJ612W8B\VRAJPCAR2I9I5CA84Z96NCAJTIMHACAVRN22LCAD2UG0KCA3KN3R9CA0N5R3TCA9UF7R8CAYFXGIMCAUF5463CAXRRTSJCA
PWLML0CAPLYSLVCACT66W4CAITDACKCAD3FWQICA65Z3EUCACN8SB2CAALX3TECAOG1M34CA5A5RA8 not found!
File\Folder C:\Documents and Settings\Johnnie\Local Settings\Temporary Internet Files\Content.IE5\FJ612W8B\W9013CA0MREKBCAN1S8SQCADYWZHUCAOM371WCAQN9A5ACA8BDW9OCA71QXPQCAYINOJHCADEWBV1CAKWCQIKCA9CF2V6CA
5MW2GKCA3KW8TUCAU9XG1QCAT7JR2ACAM7RT0ZCAHVTCPHCAXMYX2HCA9IKECCCAKVIN7HCAK3BCEH not found!
File\Folder C:\Documents and Settings\Johnnie\Local Settings\Temporary Internet Files\Content.IE5\FJ612W8B\W9AKFCAZ406HWCAYRN3WLCAQZCBMRCAPRUX2JCAPYJ01VCAIMNOJICAMSLAOWCA1CZE3LCALAFMXWCA23QHPPCAUTBESOCA
330R28CAB4XYFICAEW1CUNCAHGEMGOCA2E9BWXCANZ7C05CAI5LPEMCASSOZFDCAY975OICA1W3F3F not found!
File\Folder C:\Documents and Settings\Johnnie\Local Settings\Temporary Internet Files\Content.IE5\FJ612W8B\WIGMTCAB8AI8ZCAV51BNMCAOY1361CAAQ6P5JCABE0QJSCAJBX7BTCAY1YKH2CAIJB0NKCAYU9YH9CAS1ETWJCARLE1TCCA
MUL3NPCAEQVO52CAS4UTLQCADX0KJACAF090DPCABL6EGUCAVZSSSNCA9J5YKFCA25OCA2CA8AWCFQ not found!
File\Folder C:\Documents and Settings\Johnnie\Local Settings\Temporary Internet Files\Content.IE5\FJ612W8B\YCBYJCAG3Y7AECAT3VIYICAS71C6XCABCWDK6CAKUY3QLCAQC7MA2CAYPYEMZCAUK4PSWCA0TB7LECAKWFNSSCABKO07UCA
T7MFSYCA18J5JNCAMLABSRCA2A51NRCA7UUQ3JCAI1CJF2CAC972LOCATPIPMLCAQ5RS6ECAKLA879 not found!
File\Folder C:\Documents and Settings\Johnnie\Local Settings\Temporary Internet Files\Content.IE5\FJ612W8B\YU92SCAPG6EWQCAT1SNJCCAMJZOESCASNVBTVCAJRS21ECASXNF8TCAVJP3DQCA67LH2ICAO7VG31CA2Y3HG9CAGS3WYYCA
TDPA5UCAJIGB7SCA77B72PCAEYKQQ4CA2KMFRBCAJRZC18CA5QY8LNCAZICPPYCA6RJ29MCAM7L1AD not found!
File\Folder C:\Documents and Settings\Johnnie\Local Settings\Temporary Internet Files\Content.IE5\FJ612W8B\ZJHO4CAGBCOPKCALCHN5CCAWHYLBYCA4EA9A2CAOKF2HYCAENHEG3CAF3I1KKCAK7TC19CAPOOXOJCALQ9Z4RCASI5O5MCA
E5TWE7CA1RNGIBCAIR5FHICA0FEAABCAIK5B3DCAY0XY3UCASR1VR2CAF8L44PCAJ15SLKCAK00U5X not found!

Registry entries deleted on Reboot...

-----end-------------------------------------

SystemLook v1.0 by jpshortstuff (22.05.09)
Log created at 12:29 on 12/07/2009 by Johnnie (Administrator - Elevation successful)

========== filefind ==========

Searching for "*system32:*"
No files found.

-=End Of File=-

NOTE: The copy to clipboard button is not working here, so I just copied the content and pasted it here. The file is actually an old program I have used for years on several different computers to check email on some web based email sites.

Scanner results : All Scanners reported not find malware!
Time : 2009/07/13 00:34:52 (CST)
Scanner ↓ Engine Ver Sig Ver Sig Date Scan result Time
a-squared 4.5.0.1 20090712174300 2009-07-12
-
0.603
AhnLab V3 2009.07.11.00 2009.07.11 2009-07-11
-
0.883
AntiVir 8.2.0.204 7.1.4.220 2009-07-11
-
0.511
Antiy 2.0.18 20090712.2613979 2009-07-12
-
0.121
Arcavir 2009 200907120836 2009-07-12
-
0.070
Authentium 5.1.1 200907111559 2009-07-11
-
1.274
AVAST! 4.7.4 090711-0 2009-07-11
-
0.028
AVG 8.5.288 270.13.12/2233 2009-07-12
-
0.452
BitDefender 7.81008.3682633 7.26543 2009-07-12
-
3.516
CA (VET) 9.0.0.143 31.6.6607 2009-07-10
-
6.764
ClamAV 0.95.2 9555 2009-07-11
-
0.042
Comodo 3.10 1627 2009-07-12
-
0.686
CP Secure 1.1.0.715 2009.07.08 2009-07-08
-
11.073
Dr.Web 4.44.0.9170 2009.07.12 2009-07-12
-
4.892
F-Prot 4.4.4.56 20090711 2009-07-11
-
1.273
F-Secure 5.51.6100 2009.07.12.02 2009-07-12
-
0.098
Fortinet 2.81-3.120 10.598 2009-07-12
-
0.273
GData 19.6408/19.393 20090712 2009-07-12
-
4.555
Ikarus T3.1.01.64 2009.07.12.73021 2009-07-12
-
3.603
JiangMin 11.0.800 2009.07.12 2009-07-12
-
3.425
Kaspersky 5.5.10 2009.07.12 2009-07-12
-
0.083
KingSoft 2009.2.5.15 2009.7.12.21 2009-07-12
-
0.570
McAfee 5.3.00 5674 2009-07-12
-
3.043
Microsoft 1.4803 2009.07.12 2009-07-12
-
6.244
mks_vir 2.01 2009.07.11 2009-07-11
-
3.217
Norman 6.01.09 6.01.00 2009-07-09
-
4.009
nProtect 20090712.01 4706000 2009-07-12
-
7.108
Panda 9.05.01 2009.07.12 2009-07-12
-
2.821
Quick Heal 10.00 2009.07.10 2009-07-10
-
1.482
Rising 20.0 21.37.62.00 2009-07-12
-
0.852
Sophos 2.88.0 4.43 2009-07-12
-
3.679
Sunbelt 5245 5245 2009-07-11
-
1.240
Symantec 1.3.0.24 20090712.003 2009-07-12
-
0.074
The Hacker 6.3.4.3 v00366 2009-07-11
-
0.679
Trend Micro 8.700-1004 6.266.20 2009-07-12
-
0.032
VBA32 3.12.10.8 20090711.1835 2009-07-11
-
2.256
ViRobot 20090711 2009.07.11 2009-07-11
-
0.476
VirusBuster 4.5.11.10 10.108.4/1852272 2009-07-11
-
2.460

------------end--------------------------------------------------------

OTL logfile created on: 12/07/2009 12:54:08 PM - Run 3
OTL by OldTimer - Version 3.0.6.4 Folder = C:\Documents and Settings\Johnnie\Desktop\Maintence\GEEKS to GO\! ! Malware Tools
Windows XP Professional Edition Service Pack 3 (Version = 5.1.2600) - Type = NTWorkstation
Internet Explorer (Version = 8.0.6001.18702)
Locale: 00001009 | Country: Canada | Language: ENC | Date Format: dd/MM/yyyy

2.00 Gb Total Physical Memory | 2.00 Gb Available Physical Memory | 100.00% Memory free
4.00 Gb Paging File | 4.00 Gb Available in Paging File | 100.00% Paging File free
Paging file location(s): C:\pagefile.sys 3000 4000 [binary data]

%SystemDrive% = C: | %SystemRoot% = C:\WINDOWS | %ProgramFiles% = C:\Program Files
Drive C: | 95.36 Gb Total Space | 40.80 Gb Free Space | 42.78% Space Free | Partition Type: NTFS
Drive D: | 370.40 Gb Total Space | 79.87 Gb Free Space | 21.56% Space Free | Partition Type: NTFS
Drive E: | 465.76 Gb Total Space | 0.63 Gb Free Space | 0.14% Space Free | Partition Type: NTFS
Drive F: | 298.09 Gb Total Space | 296.66 Gb Free Space | 99.52% Space Free | Partition Type: NTFS
G: Drive not present or media not loaded
H: Drive not present or media not loaded
I: Drive not present or media not loaded
Drive Y: | 457.47 Gb Total Space | 12.00 Gb Free Space | 2.62% Space Free | Partition Type: NTFS

Computer Name: LIVINGROOM
Current User Name: Johnnie
Logged in as Administrator.

Current Boot Mode: Normal
Scan Mode: Current user
Company Name Whitelist: Off
Skip Microsoft Files: Off
File Age = 30 Days
Output = Minimal

========== Win32 Services (SafeList) ==========

SRV - (AcrSch2Svc [Auto | Running]) -- C:\Program Files\Common Files\Acronis\Schedule2\schedul2.exe (Acronis)
SRV - (aspnet_state [On_Demand | Stopped]) -- C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\aspnet_state.exe (Microsoft Corporation)
SRV - (Ati HotKey Poller [Auto | Running]) -- C:\WINDOWS\System32\Ati2evxx.exe (ATI Technologies Inc.)
SRV - (ATI Smart [Auto | Stopped]) -- C:\WINDOWS\System32\ati2sgag.exe ()
SRV - (avg8wd [Auto | Running]) -- C:\Program Files\AVG\AVG8\avgwdsvc.exe (AVG Technologies CZ, s.r.o.)
SRV - (brmfrmps [Disabled | Stopped]) -- File not found
SRV - (Brother XP spl Service [Disabled | Stopped]) -- C:\WINDOWS\System32\brsvc01a.exe (brother Industries Ltd)
SRV - (clr_optimization_v2.0.50727_32 [On_Demand | Stopped]) -- C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\mscorsvw.exe (Microsoft Corporation)
SRV - (FLEXnet Licensing Service [On_Demand | Stopped]) -- C:\Program Files\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe (Macrovision Europe Ltd.)
SRV - (FontCache3.0.0.0 [On_Demand | Stopped]) -- C:\WINDOWS\Microsoft.NET\Framework\v3.0\WPF\PresentationFontCache.exe (Microsoft Corporation)
SRV - (helpsvc [Auto | Running]) -- C:\WINDOWS\PCHealth\HelpCtr\Binaries\pchsvc.dll (Microsoft Corporation)
SRV - (IDriverT [On_Demand | Stopped]) -- C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe (Macrovision Corporation)
SRV - (idsvc [Unknown | Stopped]) -- C:\WINDOWS\Microsoft.NET\Framework\v3.0\Windows Communication Foundation\infocard.exe (Microsoft Corporation)
SRV - (JavaQuickStarterService [Auto | Running]) -- C:\Program Files\Java\jre6\bin\jqs.exe (Sun Microsystems, Inc.)
SRV - (Lavasoft Ad-Aware Service [Auto | Stopped]) -- C:\Program Files\Lavasoft\Ad-Aware\AAWService.exe (Lavasoft)
SRV - (NetTcpPortSharing [Disabled | Stopped]) -- C:\WINDOWS\Microsoft.NET\Framework\v3.0\Windows Communication Foundation\SMSvcHost.exe (Microsoft Corporation)
SRV - (O&O Defrag [On_Demand | Stopped]) -- C:\WINDOWS\System32\oodag.exe (O&O Software GmbH)
SRV - (odserv [On_Demand | Stopped]) -- C:\Program Files\Common Files\Microsoft Shared\OFFICE12\ODSERV.EXE (Microsoft Corporation)
SRV - (ose [On_Demand | Stopped]) -- C:\Program Files\Common Files\Microsoft Shared\Source Engine\OSE.EXE (Microsoft Corporation)
SRV - (rpcapd [On_Demand | Stopped]) -- File not found
SRV - (sdAuxService [On_Demand | Stopped]) -- C:\Program Files\Spyware Doctor\pctsAuxs.exe (PC Tools)
SRV - (sdCoreService [On_Demand | Stopped]) -- C:\Program Files\Spyware Doctor\pctsSvc.exe (PC Tools)
SRV - (SoundMAX Agent Service (default) [Auto | Running]) -- C:\Program Files\Analog Devices\SoundMAX\SMAgent.exe (Analog Devices, Inc.)
SRV - (TomTomHOMEService [On_Demand | Stopped]) -- C:\Program Files\TomTom HOME 2\TomTomHOMEService.exe (TomTom)
SRV - (TryAndDecideService [Auto | Running]) -- C:\Program Files\Common Files\Acronis\Fomatik\TrueImageTryStartService.exe ()
SRV - (UPHClean [Auto | Running]) -- C:\Program Files\UPHClean\uphclean.exe (Microsoft Corporation)
SRV - (UplinkService [Disabled | Stopped]) -- C:\Program Files\NCH Swift Sound\Uplink\uplink.exe ()

========== Standard Registry (SafeList) ==========


========== Internet Explorer ==========

IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft....k/?LinkId=69157
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft....k/?LinkId=54896
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Secondary_Page_URL = [binary data]
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Extensions Off Page = about:NoAdd-ons
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Local Page = C:\WINDOWS\system32\blank.htm
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft....k/?LinkId=54896
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Security Risk Page = about:SecurityRisk
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft....k/?LinkId=69157
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Search,CustomizeSearch = http://ie.search.msn...st/srchcust.htm
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Search,SearchAssistant = http://ie.search.msn...st/srchasst.htm

IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Local Page = C:\WINDOWS\system32\blank.htm
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Page_Transitions = 0
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Search Page = http://www.microsoft...amp;ar=iesearch
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,SearchMigratedDefaultName = Google
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,SearchMigratedDefaultURL = http://www.google.co...m...tf8&oe=utf8
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://www.google.com/
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyOverride" = *.local

========== FireFox ==========

FF - prefs.js..browser.search.suggest.enabled: false
FF - prefs.js..browser.startup.homepage: "http://mirariver.com/"
FF - prefs.js..extensions.enabledItems: {3f963a5b-e555-4543-90e2-c3908898db71}:8.5
FF - prefs.js..extensions.enabledItems: [email protected]:3.1.2
FF - prefs.js..extensions.enabledItems: {CAFEEFAC-0016-0000-0006-ABCDEFFEDCBA}:6.0.06
FF - prefs.js..extensions.enabledItems: {CAFEEFAC-0016-0000-0013-ABCDEFFEDCBA}:6.0.13
FF - prefs.js..extensions.enabledItems: [email protected]:1.0
FF - prefs.js..extensions.enabledItems: {20a82645-c095-46ed-80e3-08825760534b}:1.1
FF - prefs.js..extensions.enabledItems: {972ce4c6-7e08-4474-a285-3208198ce6fd}:3.0.11

FF - HKLM\software\mozilla\Firefox\Extensions\\{3f963a5b-e555-4543-90e2-c3908898db71}: C:\Program Files\AVG\AVG8\Firefox [2009/06/29 08:58:09 | 00,000,000 | ---D | M]
FF - HKLM\software\mozilla\Firefox\Extensions\\{20a82645-c095-46ed-80e3-08825760534b}: C:\WINDOWS\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\DotNetAssistantExtension\ [2009/07/04 16:40:23 | 00,000,000 | ---D | M]
FF - HKLM\software\mozilla\Firefox\Extensions\\[email protected]: C:\Program Files\Java\jre6\lib\deploy\jqs\ff [2008/12/12 19:54:33 | 00,000,000 | ---D | M]
FF - HKLM\software\mozilla\Mozilla Firefox 3.0.11\extensions\\Components: C:\Program Files\Mozilla Firefox\components [2009/06/19 12:32:48 | 00,000,000 | ---D | M]
FF - HKLM\software\mozilla\Mozilla Firefox 3.0.11\extensions\\Plugins: C:\Program Files\Mozilla Firefox\plugins [2009/06/16 08:21:03 | 00,000,000 | ---D | M]

[2009/01/19 15:32:26 | 00,000,000 | ---D | M] -- C:\Documents and Settings\Johnnie\Application Data\mozilla\Extensions
[2008/07/01 12:48:45 | 00,000,000 | ---D | M] -- C:\Documents and Settings\Johnnie\Application Data\mozilla\Extensions\{ec8030f7-c20a-464f-9b0e-13a3a9e97384}
[2009/01/19 15:32:26 | 00,000,000 | ---D | M] -- C:\Documents and Settings\Johnnie\Application Data\mozilla\Extensions\[email protected]
[2009/07/12 10:35:04 | 00,000,000 | ---D | M] -- C:\Documents and Settings\Johnnie\Application Data\mozilla\Firefox\Profiles\2zi1h6xu.default\extensions
[2009/07/04 16:50:53 | 00,000,000 | ---D | M] -- C:\Documents and Settings\Johnnie\Application Data\mozilla\Firefox\Profiles\2zi1h6xu.default\extensions\{20a82645-c095-46ed-80e3-08825760534b}
[2008/12/01 21:43:04 | 00,000,000 | ---D | M] -- C:\Documents and Settings\Johnnie\Application Data\mozilla\Firefox\Profiles\2zi1h6xu.default\extensions\[email protected]
[2009/07/12 10:35:04 | 00,000,000 | ---D | M] -- C:\Program Files\mozilla firefox\extensions
[2009/06/16 08:21:03 | 00,000,000 | ---D | M] -- C:\Program Files\mozilla firefox\extensions\{972ce4c6-7e08-4474-a285-3208198ce6fd}
[2008/07/02 19:20:08 | 00,000,000 | ---D | M] -- C:\Program Files\mozilla firefox\extensions\{CAFEEFAC-0016-0000-0006-ABCDEFFEDCBA}
[2009/04/05 23:18:48 | 00,000,000 | ---D | M] -- C:\Program Files\mozilla firefox\extensions\{CAFEEFAC-0016-0000-0013-ABCDEFFEDCBA}
[2009/06/16 08:20:18 | 00,023,032 | ---- | M] (Mozilla Foundation) -- C:\Program Files\mozilla firefox\components\browserdirprovider.dll
[2009/06/16 08:20:18 | 00,134,648 | ---- | M] (Mozilla Foundation) -- C:\Program Files\mozilla firefox\components\brwsrcmp.dll
[2009/03/09 05:19:09 | 00,410,984 | ---- | M] (Sun Microsystems, Inc.) -- C:\Program Files\mozilla firefox\plugins\npdeploytk.dll
[2005/12/05 23:31:00 | 00,114,688 | ---- | M] () -- C:\Program Files\mozilla firefox\plugins\npmozax.dll
[2009/06/16 08:20:26 | 00,065,528 | ---- | M] (mozilla.org) -- C:\Program Files\mozilla firefox\plugins\npnul32.dll
[2006/10/26 20:12:16 | 00,016,192 | ---- | M] (Microsoft Corporation) -- C:\Program Files\mozilla firefox\plugins\NPOFF12.DLL
[2009/02/27 12:13:42 | 00,103,792 | ---- | M] (Adobe Systems Inc.) -- C:\Program Files\mozilla firefox\plugins\nppdf32.dll
[2006/02/02 16:56:00 | 00,225,280 | ---- | M] (Virtools SA) -- C:\Program Files\mozilla firefox\plugins\npvirtools.dll
[2009/04/24 21:44:31 | 00,001,394 | ---- | M] () -- C:\Program Files\mozilla firefox\searchplugins\amazondotcom.xml
[2009/04/24 21:44:31 | 00,002,193 | ---- | M] () -- C:\Program Files\mozilla firefox\searchplugins\answers.xml
[2009/04/24 21:44:31 | 00,001,534 | ---- | M] () -- C:\Program Files\mozilla firefox\searchplugins\creativecommons.xml
[2009/04/24 21:44:31 | 00,002,343 | ---- | M] () -- C:\Program Files\mozilla firefox\searchplugins\eBay.xml
[2009/04/24 21:44:31 | 00,001,706 | ---- | M] () -- C:\Program Files\mozilla firefox\searchplugins\google.xml
[2009/04/24 21:44:31 | 00,001,178 | ---- | M] () -- C:\Program Files\mozilla firefox\searchplugins\wikipedia.xml
[2009/04/24 21:44:31 | 00,000,792 | ---- | M] () -- C:\Program Files\mozilla firefox\searchplugins\yahoo.xml

O1 HOSTS File: (56 bytes) - C:\WINDOWS\System32\drivers\etc\Hosts
O1 - Hosts: 127.0.0.1 localhost
O2 - BHO: (Adobe PDF Link Helper) - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll (Adobe Systems Incorporated)
O2 - BHO: (AVG Safe Search) - {3CA2F312-6F6E-4B53-A66E-4E65E497C8C0} - C:\Program Files\AVG\AVG8\avgssie.dll (AVG Technologies CZ, s.r.o.)
O2 - BHO: (Spybot-S&D IE Protection) - {53707962-6F74-2D53-2644-206D7942484F} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll (Safer Networking Limited)
O2 - BHO: (no name) - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - No CLSID value found.
O2 - BHO: (Adobe PDF Conversion Toolbar Helper) - {AE7CD045-E861-484f-8273-0445EE161910} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll (Adobe Systems Incorporated)
O2 - BHO: (Java™ Plug-In 2 SSV Helper) - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll (Sun Microsystems, Inc.)
O2 - BHO: (JQSIEStartDetectorImpl Class) - {E7E6F031-17CE-4C07-BC86-EABFE594F69C} - C:\Program Files\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll (Sun Microsystems, Inc.)
O2 - BHO: (SmartSelect Class) - {F4971EE7-DAA0-4053-9964-665D8EE6A077} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll (Adobe Systems Incorporated)
O3 - HKLM\..\Toolbar: (Adobe PDF) - {47833539-D0C5-4125-9FA8-0819E2EAAC93} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll (Adobe Systems Incorporated)
O3 - HKCU\..\Toolbar\WebBrowser: (Adobe PDF) - {47833539-D0C5-4125-9FA8-0819E2EAAC93} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll (Adobe Systems Incorporated)
O4 - HKLM..\Run: [AVG8_TRAY] C:\Program Files\AVG\AVG8\avgtray.exe (AVG Technologies CZ, s.r.o.)
O4 - HKLM..\Run: [IntelliPoint] C:\Program Files\Microsoft IntelliPoint\ipoint.exe (Microsoft Corporation)
O4 - HKLM..\Run: [SoundMAXPnP] C:\Program Files\Analog Devices\SoundMAX\SMax4PNP.exe (Analog Devices, Inc.)
O6 - HKLM\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O6 - HKLM\Software\Policies\Microsoft\Internet Explorer\Infodelivery present
O6 - HKLM\Software\Policies\Microsoft\Internet Explorer\Restrictions present
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoResolveTrack = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoPropertiesMyComputer = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoFileAssociate = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoSMHelp = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: HonorAutoRunSetting = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveAutoRun = 67108863
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 323
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDrives = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: dontdisplaylastusername = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: legalnoticecaption =
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: legalnoticetext =
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: undockwithoutlogon = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ShutdownWithoutLogon = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: DisableRegistryTools = 0
O7 - HKCU\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 323
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoCDBurning = 1
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoRecentDocsHistory = 0
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: ClearRecentDocsOnExit = 0
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveAutoRun = 67108863
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDrives = 0
O8 - Extra context menu item: Add to Vbuzzer RSS list - C:\Program Files\vbuzzer\addurl.htm ()
O8 - Extra context menu item: Append Link Target to Existing PDF - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll (Adobe Systems Incorporated)
O8 - Extra context menu item: Append to Existing PDF - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll (Adobe Systems Incorporated)
O8 - Extra context menu item: Convert Link Target to Adobe PDF - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll (Adobe Systems Incorporated)
O8 - Extra context menu item: Convert to Adobe PDF - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll (Adobe Systems Incorporated)
O8 - Extra context menu item: E&xport to Microsoft Excel - C:\Program Files\Microsoft Office\OFFICE11\EXCEL.EXE (Microsoft Corporation)
O9 - Extra Button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\Program Files\Microsoft Office\Office12\REFIEBAR.DLL (Microsoft Corporation)
O9 - Extra 'Tools' menuitem : Spybot - Search & Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll (Safer Networking Limited)
O9 - Extra 'Tools' menuitem : @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe (Microsoft Corporation)
O9 - Extra Button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe (Microsoft Corporation)
O9 - Extra 'Tools' menuitem : Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe (Microsoft Corporation)
O9 - Extra Button: Messenger - -{FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe (Microsoft Corporation)
O9 - Extra 'Tools' menuitem : Windows Messenger - -{FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe (Microsoft Corporation)
O9 - Extra Button: SmartWhois - {FD9DE2B4-C926-4460-81C4-FC58C6F1062E} - C:\Program Files\SmartWhois\swmsie.exe (TamoSoft)
O9 - Extra 'Tools' menuitem : SmartWhois - {FF983118-58C7-4AD4-B5A7-691C39CB7B42} - C:\Program Files\SmartWhois\swmsie.exe (TamoSoft)
O15 - HKLM\..Trusted Domains: 49 domain(s) and sub-domain(s) not assigned to a zone.
O15 - HKCU\..Trusted Domains: 49 domain(s) and sub-domain(s) not assigned to a zone.
O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} http://download.micr...heckControl.cab (Windows Genuine Advantage Validation Tool)
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} http://www.update.mi...b?1182302094468 (WUWebControl Class)
O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} http://www.update.mi...b?1182565904640 (MUWebControl Class)
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} http://java.sun.com/...indows-i586.cab (Java Plug-in 1.6.0_13)
O16 - DPF: {8FFBE65D-2C9C-4669-84BD-5829DC0B603C} http://fpdownload.ma...r/ultrashim.cab (Reg Error: Key error.)
O16 - DPF: {B1E2B96C-12FE-45E2-BEF1-44A219113CDD} http://www.superadbl...ivex/sabspx.cab (SABScanProcesses Class)
O16 - DPF: {CAFEEFAC-0016-0000-0011-ABCDEFFEDCBA} Reg Error: Value error. (Reg Error: Key error.)
O16 - DPF: {CAFEEFAC-0016-0000-0013-ABCDEFFEDCBA} http://java.sun.com/...indows-i586.cab (Java Plug-in 1.6.0_13)
O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} http://java.sun.com/...indows-i586.cab (Java Plug-in 1.6.0_13)
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} http://download.macr...ash/swflash.cab (Shockwave Flash Object)
O16 - DPF: {D4323BF2-006A-4440-A2F5-27E3E7AB25F8} http://a532.g.akamai...5/installer.exe (Virtools WebPlayer Class)
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 208.67.222.222 208.67.220.220 206.248.154.22
O18 - Protocol\Handler\http\0x00000001 {E1D2BF42-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files\Common Files\System\Ole DB\MSDAIPP.DLL (Microsoft Corporation)
O18 - Protocol\Handler\http\oledb {E1D2BF40-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files\Common Files\System\Ole DB\MSDAIPP.DLL (Microsoft Corporation)
O18 - Protocol\Handler\https\0x00000001 {E1D2BF42-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files\Common Files\System\Ole DB\MSDAIPP.DLL (Microsoft Corporation)
O18 - Protocol\Handler\https\oledb {E1D2BF40-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files\Common Files\System\Ole DB\MSDAIPP.DLL (Microsoft Corporation)
O18 - Protocol\Handler\ipp - No CLSID value found
O18 - Protocol\Handler\ipp\0x00000001 {E1D2BF42-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files\Common Files\System\Ole DB\MSDAIPP.DLL (Microsoft Corporation)
O18 - Protocol\Handler\linkscanner {F274614C-63F8-47D5-A4D1-FBDDE494F8D1} - C:\Program Files\AVG\AVG8\avgpp.dll (AVG Technologies CZ, s.r.o.)
O18 - Protocol\Handler\msdaipp - No CLSID value found
O18 - Protocol\Handler\msdaipp\0x00000001 {E1D2BF42-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files\Common Files\System\Ole DB\MSDAIPP.DLL (Microsoft Corporation)
O18 - Protocol\Handler\msdaipp\oledb {E1D2BF40-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files\Common Files\System\Ole DB\MSDAIPP.DLL (Microsoft Corporation)
O18 - Protocol\Handler\ms-help {314111c7-a502-11d2-bbca-00c04f8ec294} - C:\Program Files\Common Files\Microsoft Shared\Help\hxds.dll (Microsoft Corporation)
O18 - Protocol\Handler\mso-offdap {3D9F03FA-7A94-11D3-BE81-0050048385D1} - C:\Program Files\Common Files\Microsoft Shared\Web Components\10\OWC10.DLL (Microsoft Corporation)
O18 - Protocol\Handler\mso-offdap11 {32505114-5902-49B2-880A-1F7738E5A384} - C:\Program Files\Common Files\Microsoft Shared\Web Components\11\OWC11.DLL (Microsoft Corporation)
O18 - Protocol\Filter: - text/xml - C:\Program Files\Common Files\Microsoft Shared\OFFICE12\MSOXMLMF.DLL (Microsoft Corporation)
O20 - HKLM Winlogon: Shell - (Explorer.exe) - C:\WINDOWS\Explorer.exe (Microsoft Corporation)
O20 - Winlogon\Notify\!SASWinLogon: DllName - C:\Program Files\SUPERAntiSpyware\SASWINLO.dll - C:\Program Files\SUPERAntiSpyware\SASWINLO.dll (SUPERAntiSpyware.com)
O20 - Winlogon\Notify\AtiExtEvent: DllName - Ati2evxx.dll - C:\WINDOWS\System32\Ati2evxx.dll (ATI Technologies Inc.)
O20 - Winlogon\Notify\avgrsstarter: DllName - avgrsstx.dll - C:\WINDOWS\System32\avgrsstx.dll (AVG Technologies CZ, s.r.o.)
O24 - Desktop Components:0 (My Current Home Page) - About:Home
O28 - HKLM ShellExecuteHooks: {5AE067D3-9AFB-48E0-853A-EBB7F4A000DA} - C:\Program Files\SUPERAntiSpyware\SASSEH.DLL (SuperAdBlocker.com)
O28 - HKLM ShellExecuteHooks: {EDB0E980-90BD-11D4-8599-0008C7D3B6F8} - C:\Program Files\Qualcomm\Eudora\EuShlExt.dll (Qualcomm Inc.)
O30 - LSA: Authentication Packages - (relog_ap) - C:\WINDOWS\System32\relog_ap.dll (Acronis)
O31 - SafeBoot: AlternateShell - cmd.exe
O32 - HKLM CDRom: AutoRun - 1
O32 - AutoRun File - [2007/06/19 20:43:54 | 00,000,000 | ---- | M] () - C:\AUTOEXEC.BAT -- [ NTFS ]
O34 - HKLM BootExecute: (autocheck) - File not found
O34 - HKLM BootExecute: (autochk) - C:\WINDOWS\System32\autochk.exe (Microsoft Corporation)
O34 - HKLM BootExecute: (*) - File not found
O34 - HKLM BootExecute: (oodbs) - C:\WINDOWS\System32\oodbs.exe (O&O Software GmbH)
O34 - HKLM BootExecute: (lsdelete) - C:\WINDOWS\System32\lsdelete.exe ()

========== LOP Check ==========

[2009/07/04 11:45:50 | 00,000,000 | RH-D | M] -- C:\Documents and Settings\All Users\Application Data
[2009/02/13 22:29:44 | 00,000,000 | -H-D | M] -- C:\Documents and Settings\All Users\Application Data\{83C91755-2546-441D-AC40-9A6B4B860800}
[2008/08/19 20:31:17 | 00,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\Acronis
[2007/06/20 13:42:26 | 00,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\ashampoo
[2009/06/20 12:46:47 | 00,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\ATI
[2007/07/15 20:47:57 | 00,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\DeskSoft
[2007/09/14 15:27:13 | 00,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\Downloaded Installations
[2007/09/18 21:19:09 | 00,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\DVD Shrink
[2008/04/30 21:59:40 | 00,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\FlashFXP
[2007/10/16 16:29:20 | 00,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\FLEXnet
[2008/01/27 10:11:43 | 00,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\Insight Software
[2008/01/27 10:11:43 | 00,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\Insight Software Solutions
[2007/09/14 15:23:04 | 00,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\Installations
[2008/07/19 19:03:57 | 00,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\MAGIX
[2007/10/18 20:48:23 | 00,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\NCH Swift Sound
[2009/05/05 10:53:44 | 00,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\Palo Alto Software
[2009/05/05 10:51:07 | 00,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\PAS
[2008/09/07 13:43:45 | 00,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\PC Drivers HeadQuarters
[2007/09/14 15:30:59 | 00,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\PC Suite
[2008/03/22 21:56:36 | 00,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\Sierra
[2007/09/11 21:27:35 | 00,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\SlySoft
[2007/10/08 11:08:31 | 00,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\TamoSoft
[2009/07/11 10:21:47 | 00,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\TEMP
[2009/01/19 15:35:53 | 00,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\TomTom
[2008/12/22 08:46:28 | 00,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\vsosdk
[2008/09/03 11:19:55 | 00,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\WinZip
[2008/07/19 19:02:50 | 00,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\Xara
[2008/04/22 23:54:17 | 00,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\XemiComputers
[2009/07/11 23:09:59 | 00,000,000 | RH-D | M] -- C:\Documents and Settings\Johnnie\Application Data
[2008/09/28 14:53:52 | 00,000,000 | ---D | M] -- C:\Documents and Settings\Johnnie\Application Data\Accomplice
[2008/01/26 19:50:53 | 00,000,000 | ---D | M] -- C:\Documents and Settings\Johnnie\Application Data\ActiveDBSoft
[2008/11/05 16:34:40 | 00,000,000 | ---D | M] -- C:\Documents and Settings\Johnnie\Application Data\Ashampoo
[2009/06/20 12:46:47 | 00,000,000 | ---D | M] -- C:\Documents and Settings\Johnnie\Application Data\ATI
[2008/10/06 19:14:21 | 00,000,000 | ---D | M] -- C:\Documents and Settings\Johnnie\Application Data\BitTorrent
[2007/06/23 21:11:14 | 00,000,000 | ---D | M] -- C:\Documents and Settings\Johnnie\Application Data\Crystal Art Software
[2008/09/28 16:35:12 | 00,000,000 | ---D | M] -- C:\Documents and Settings\Johnnie\Application Data\CuteReminderEnt
[2007/09/11 22:14:20 | 00,000,000 | ---D | M] -- C:\Documents and Settings\Johnnie\Application Data\DAEMON Tools Pro
[2008/03/22 21:51:35 | 00,000,000 | ---D | M] -- C:\Documents and Settings\Johnnie\Application Data\DeskSoft
[2009/06/28 18:35:33 | 00,000,000 | ---D | M] -- C:\Documents and Settings\Johnnie\Application Data\Dexpot
[2009/07/07 10:00:06 | 00,000,000 | ---D | M] -- C:\Documents and Settings\Johnnie\Application Data\dvdcss
[2009/05/11 21:18:20 | 00,000,000 | ---D | M] -- C:\Documents and Settings\Johnnie\Application Data\DVDFab
[2007/06/23 21:34:27 | 00,000,000 | ---D | M] -- C:\Documents and Settings\Johnnie\Application Data\EmTec
[2008/06/03 21:01:44 | 00,000,000 | ---D | M] -- C:\Documents and Settings\Johnnie\Application Data\IrfanView
[2007/06/28 07:53:15 | 00,000,000 | ---D | M] -- C:\Documents and Settings\Johnnie\Application Data\Leadertech
[2008/07/19 19:03:57 | 00,000,000 | ---D | M] -- C:\Documents and Settings\Johnnie\Application Data\MAGIX
[2007/08/21 21:46:03 | 00,000,000 | ---D | M] -- C:\Documents and Settings\Johnnie\Application Data\MSNStockQuote
[2009/07/04 14:17:38 | 00,000,000 | ---D | M] -- C:\Documents and Settings\Johnnie\Application Data\NewzToolz
[2007/09/14 19:05:14 | 00,000,000 | ---D | M] -- C:\Documents and Settings\Johnnie\Application Data\Nokia
[2009/05/05 10:57:12 | 00,000,000 | ---D | M] -- C:\Documents and Settings\Johnnie\Application Data\Palo Alto Software
[2007/09/14 15:39:34 | 00,000,000 | ---D | M] -- C:\Documents and Settings\Johnnie\Application Data\PC Suite
[2008/01/26 19:52:25 | 00,000,000 | ---D | M] -- C:\Documents and Settings\Johnnie\Application Data\SAPIEN
[2007/09/11 21:32:39 | 00,000,000 | ---D | M] -- C:\Documents and Settings\Johnnie\Application Data\SlySoft
[2007/10/08 11:09:57 | 00,000,000 | ---D | M] -- C:\Documents and Settings\Johnnie\Application Data\TamoSoft
[2008/09/12 14:35:19 | 00,000,000 | ---D | M] -- C:\Documents and Settings\Johnnie\Application Data\TeamViewer
[2009/07/02 20:24:47 | 00,000,000 | ---D | M] -- C:\Documents and Settings\Johnnie\Application Data\Thinstall
[2009/01/19 15:32:23 | 00,000,000 | ---D | M] -- C:\Documents and Settings\Johnnie\Application Data\TomTom
[2008/08/10 19:42:11 | 00,000,000 | ---D | M] -- C:\Documents and Settings\Johnnie\Application Data\U3
[2008/12/17 18:01:34 | 00,000,000 | ---D | M] -- C:\Documents and Settings\Johnnie\Application Data\uTorrent
[2007/09/16 19:42:50 | 00,000,000 | ---D | M] -- C:\Documents and Settings\Johnnie\Application Data\Visual Money
[2007/12/16 13:29:59 | 00,000,000 | ---D | M] -- C:\Documents and Settings\Johnnie\Application Data\VoipStunt
[2009/07/05 07:26:29 | 00,000,000 | ---D | M] -- C:\Documents and Settings\Johnnie\Application Data\Vso
[2008/04/22 23:54:17 | 00,000,000 | ---D | M] -- C:\Documents and Settings\Johnnie\Application Data\XemiComputers
[2009/02/13 22:51:24 | 00,000,472 | ---- | M] () -- C:\WINDOWS\Tasks\Ad-Aware Update (Weekly).job
[2004/08/04 08:00:00 | 00,000,065 | RH-- | M] () -- C:\WINDOWS\Tasks\desktop.ini
[2009/02/01 20:18:11 | 00,000,294 | -H-- | M] () -- C:\WINDOWS\Tasks\Microsoft_Hardware_Launch_IPoint_exe.job
[2007/08/26 22:13:05 | 00,000,006 | -H-- | M] () -- C:\WINDOWS\Tasks\SA.DAT

========== Purity Check ==========



========== Alternate Data Streams ==========

@Alternate Data Stream - 164 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:DFC5A2B2
@Alternate Data Stream - 125 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:5C321E34
@Alternate Data Stream - 117 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:C8B8CEBD
< End of report >
  • 0

#7
andrewuk

andrewuk

    Trusted Helper

  • Malware Removal
  • 5,297 posts
not really seeing what could be slowing down your machine at this stage:

in this post we will do some general scans to clear out the remnants and ensure nothing else sneaked onto your machine.

the scans will likely take 4 hours, quite possibly much longer. so just let them run.


====STEP 1====
Please download ATF Cleaner by Atribune.

Caution: This program is for Windows 2000, XP and Vista only
Double-click ATF-Cleaner.exe to run the program.
Under Main choose: Select All
Click the Empty Selected button.
If you use Firefox browserClick Firefox at the top and choose: Select All
Click the Empty Selected button.
NOTE: If you would like to keep your saved passwords, please click No at the prompt.
If you use Opera browserClick Opera at the top and choose: Select All
Click the Empty Selected button.
NOTE: If you would like to keep your saved passwords, please click No at the prompt.
Click Exit on the Main menu to close the program.
For Technical Support, double-click the e-mail address located at the bottom of each menu.



====STEP 2====
we will update and re-run your malwarebytes:

double click the malwarebytes icon on your desktop to open the program
  • on the tabs at the top, select Update and then press the Check for Updates button on that page. If an update is found, it will download and install the latest version.
  • once complete (a new version of malwarebytes may download) select the tab Scanner
  • select "Perform Full Scan", then click Scan.
  • The scan may take some time to finish,so please be patient.
  • When the scan is complete, click OK, then Show Results to view the results.
  • Make sure that everything is checked, and click Remove Selected.
  • When disinfection is completed, a log will open in Notepad and you may be prompted to Restart.(See Extra Note)
  • The log is automatically saved by MBAM and can be viewed by clicking the Logs tab in MBAM.
  • Copy&Paste the entire report in your next reply.
Extra Note:
If MBAM encounters a file that is difficult to remove,you will be presented with 1 of 2 prompts,click OK to either and let MBAM proceed with the disinfection process,if asked to restart the computer,please do so immediatly.



====STEP 3====
we will also update and re-run your superantispyware.

  • Double-click the superantispyware icon on your desktop to launch the program.
  • If asked to update the program definitions, click "Yes". If not, update the definitions before scanning by selecting "Check for Updates". (If you encounter any problems while downloading the updates, manually download and unzip them from here.)
  • Under "Configuration and Preferences", click the Preferences button.
  • Click the Scanning Control tab.
  • Under Scanner Options make sure the following are checked (leave all others unchecked):
    • Close browsers before scanning.
    • Scan for tracking cookies.
    • Terminate memory threats before quarantining.
  • Click the "Close" button to leave the control center screen.
  • Back on the main screen, under "Scan for Harmful Software" click Scan your computer.
  • On the left, make sure you check C:\Fixed Drive.
  • On the right, under "Complete Scan", choose Perform Complete Scan.
  • Click "Next" to start the scan. Please be patient while it scans your computer.
  • After the scan is complete, a Scan Summary box will appear with potentially harmful items that were detected. Click "OK".
  • Make sure everything has a checkmark next to it and click "Next".
  • A notification will appear that "Quarantine and Removal is Complete". Click "OK" and then click the "Finish" button to return to the main menu.
  • If asked if you want to reboot, click "Yes".
  • To retrieve the removal information after reboot, launch SUPERAntispyware again.
    • Click Preferences, then click the Statistics/Logs tab.
    • Under Scanner Logs, double-click SUPERAntiSpyware Scan Log.
    • If there are several logs, click the current dated log and press View log. A text file will open in your default text editor.
    • Please copy and paste the Scan Log results in your next reply.
  • Click Close to exit the program.
====STEP 4====
Please do an online scan with Kaspersky WebScanner (this will identify any issues, we will clear them in the following post)

Kaspersky online scanner uses JAVA tecnology to perform the scan. If you do not have the latest JAVA version, follow the instrutions below under Upgrading Java, to download and install the latest vesion.

  • Read through the requirements and privacy statement and click on Accept button.
  • It will start downloading and installing the scanner and virus definitions. You will be prompted to install an application from Kaspersky. Click Run.
  • When the downloads have finished, click on Settings.
  • Make sure the following is checked.
    • Spyware, Adware, Dialers, and other potentially dangerous programs
      Archives
      Mail databases
  • Click on My Computer under Scan.
  • Once the scan is complete, it will display the results. Click on View Scan Report.
  • You will see a list of infected items there. Click on Save Report As....
  • Save this report to a convenient place. Change the Files of type to Text file (.txt) before clicking on the Save button.
  • Please post this log in your next reply.
Upgrading Java, if required:
  • Download the latest version of Java SE Runtime Environment (JRE)JRE 6 Update 14.
  • Click the "Download" button to the right.
  • Select your Platform and check the box that says: "I agree to the Java SE Runtime Environment 6 License Agreement.".
  • Click on Continue.
  • Click on the link to download Windows Offline Installation (jre-6u14-windows-i586.exe) and save it to your desktop. Do NOT use the Sun Download Manager..
  • Close any programs you may have running - especially your web browser.
  • Go to Start > Control Panel, double-click on Add/Remove programs and remove all older versions of Java.
  • Check any item with Java Runtime Environment (JRE or J2SE) in the name.
  • Click the Remove or Change/Remove button.
  • Repeat as many times as necessary to remove each Java version.
  • Reboot your computer once all Java components are removed.
  • Then from your desktop double-click on the download to install the newest version.(Vista users, right click on the jre-6u14-windows-i586.exe and select "Run as an Administrator.")
In your next reply could i see:
1. the malwarebytes log
2. the superantispyware log
3. the kaspersky log
4. some idea of how your machine is running now

The text from these files may exceed the maximum post length for this forum. Hence, you may need to post the information over 2 or more posts.

andrewuk
  • 0

#8
JohnnieF

JohnnieF

    Member

  • Topic Starter
  • Member
  • PipPip
  • 32 posts
In your next reply could i see:
1. the malwarebytes log
2. the superantispyware log
3. the kaspersky log
4. some idea of how your machine is running now

The malwarebytes and superantispyware logs are included but I could not get the Kaspersky scan to work. I tried it 5 times. It will download some of the updates and then just stop downloading and will not continue. I could not access anything on the page such as settings but the page was not locked up. I had disabled my antivirus and updated the Java. I ran CCleaner in between attempts.

As far as my computer, it is still very slow. If I click on a desktop shortcut it takes 15 - 30 seconds before the site or app opens. Right click on something in Windows explorer and takes 30 seconds most times before the right click menu pops up. Unraring an ISO takes twice as long as my smaller P4 machine here and although I did not do a direct comparison right now, I can tell it is still very slow. Of course this may have nothing to do with malware. I have always found this computer slow from the start.

If you think there is nothing else maybe I should post in the hardware group and see if there might be some other solution to

this.

Thanks for your help andrewuk.

*********************************************************************

Malwarebytes' Anti-Malware 1.38
Database version: 2413
Windows 5.1.2600 Service Pack 3

12/07/2009 5:26:51 PM
mbam-log-2009-07-12 (17-26-51).txt

Scan type: Full Scan (C:\|)
Objects scanned: 247039
Time elapsed: 37 minute(s), 53 second(s)

Memory Processes Infected: 0
Memory Modules Infected: 0
Registry Keys Infected: 0
Registry Values Infected: 0
Registry Data Items Infected: 0
Folders Infected: 0
Files Infected: 0

Memory Processes Infected:
(No malicious items detected)

Memory Modules Infected:
(No malicious items detected)

Registry Keys Infected:
(No malicious items detected)

Registry Values Infected:
(No malicious items detected)

Registry Data Items Infected:
(No malicious items detected)

Folders Infected:
(No malicious items detected)

Files Infected:
(No malicious items detected)

*****************************************

SUPERAntiSpyware Scan Log
http://www.superantispyware.com

Generated 07/12/2009 at 06:50 PM

Application Version : 4.26.1006

Core Rules Database Version : 3988
Trace Rules Database Version: 1928

Scan type : Complete Scan
Total Scan Time : 01:16:18

Memory items scanned : 562
Memory threats detected : 0
Registry items scanned : 6221
Registry threats detected : 0
File items scanned : 130286
File threats detected : 0
  • 0

#9
JohnnieF

JohnnieF

    Member

  • Topic Starter
  • Member
  • PipPip
  • 32 posts
I just noticed something else here. There are several new folders off the root on my C drive. I was able to figure out all of them, as used by apps we were using and deleted them, except for one folder. The folder is "cmdcons" and it has a folder inside of it called "SYSTEM32". The "SYSTEM32" folder has two files inside, NTDLL.DLL and SMSS.EXE. The "cmdcons" folder has 223 objects totaling 6.93 MB. I can not delete these folders. I get the access denied and make sure disk is not write protected or the file is not in use notice. I have no idea what this is or where it came from. They look like operating system files. This structure was not there last week for sure. Did one of the programs we ran move or copy this stuff there?

Johnnie F
  • 0

#10
andrewuk

andrewuk

    Trusted Helper

  • Malware Removal
  • 5,297 posts

There are several new folders off the root on my C drive. I was able to figure out all of them, as used by apps we were using and deleted them,

hmm . . . . .that will make clearing them off somewhat trickier, but we will do that later

. . . . except for one folder. The folder is "cmdcons"

that is part of the Recovery Console and is ok

i suspect the slowness of your machine is not malware related. but lets try and get an online scan done, in case it picks anything up, then wrap up the malware cleaning part before we move on.

Please go HERE to run Panda's TotalScan
  • Select the bubble for Scan now
  • It will start downloading the files it requires for the scan (Note: It may take a couple of minutes)
  • Then the scan will begin
  • When the scan completes, click the Save button on the right of Scan details
  • Save it to a convenient location. Post the contents of the TotalScan report

  • 0

#11
JohnnieF

JohnnieF

    Member

  • Topic Starter
  • Member
  • PipPip
  • 32 posts
;***************************************************************************************************
********************************************************************************
ANALYSIS: 2009-07-14 18:28:57
PROTECTIONS: 1
MALWARE: 12
SUSPECTS: 10
;***************************************************************************************************
********************************************************************************
PROTECTIONS
Description Version Active Updated
;===================================================================================================
================================================================================
AVG Anti-Virus Free 8.5 Yes Yes
;===================================================================================================
================================================================================
MALWARE
Id Description Type Active Severity Disinfectable Disinfected Location
;===================================================================================================
================================================================================
00020994 W32/Bagle.pwdzip Virus No 0 Yes No C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\Virtumondesdn2.zip
00020994 W32/Bagle.pwdzip Virus No 0 Yes No C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\Virtumondesdn.zip
00121425 Hacktool/NMap HackTools No 0 Yes No C:\WINDOWS\system32\CCGNU32.dll
01049080 Generic Malware Virus/Trojan No 0 Yes No C:\WINDOWS\system32\nmapserv.exe
01049080 Generic Malware Virus/Trojan No 0 Yes No C:\Program Files\Net Tools\nmapserv.exe
02097168 Generic Malware Virus/Trojan No 0 Yes No C:\Program Files\Net Tools\nmapwin.exe
02097168 Generic Malware Virus/Trojan No 0 Yes No C:\WINDOWS\system32\nmapwin.exe
02885963 Rootkit/Booto.C Virus/Worm No 0 Yes No C:\System Volume Information\_restore{E2249E8D-D899-4314-8C07-E5BCECBC137E}\RP96\A0017139.sys
02940722 Trj/Downloader.MDW Virus/Trojan No 1 No No E:\!APPS\! APPS 04 15 2009\Photomatix Pro 3.03.1.rar[Photomatix Pro 3.03\PP_v3.0.3\Keygen - Photomatix Pro v3.0.x.exe]
02940722 Trj/Downloader.MDW Virus/Trojan No 1 No No E:\!APPS\! APPS 04 15 2009\Photomatix Pro 3.03.rar[Photomatix Pro 3.03\Keygen - Photomatix Pro v3.0.x.exe]
03074964 Trj/CI.A Virus/Trojan No 0 No No D:\grabit downloads\nfo's\bws-0287.rar[brewers.exe]
03763777 Trj/Raiden.B Virus/Trojan No 1 No No E:\!APPS\! APPS 04 15 2009\RaidenFTPD FTP Server v2 4 build 3501.rar[RaidenFTPD FTP Server v2 4 build 3501\Setup\raidenftpd.2.4.3501.exe][rftpdservice.exe]
03867875 Generic Trojan Virus/Trojan No 0 No No E:\!APPS\Quick Tax 2008 For Canadians\QuickTax 2008.part01.rar[QuickTax 2008\keygen.exe]
04155725 Generic Trojan Virus/Trojan No 0 No No E:\!APPS\! APPS 04 15 2009\SolarWinds Orion NetFlow Traffic Analyzer v3.part1.rar[SolarWinds Orion NetFlow Traffic Analyzer v3\keygen.exe]
04276149 Generic Trojan Virus/Trojan No 0 No No D:\! APPs\Apps June 15 2009\Stardock Object Dock PLUS v1.90.535u\e-odp19f.zip[embrace.rar][keygen.exe]
04946224 Generic Trojan Virus/Trojan No 0 No No E:\!APPS\! APPS 04 15 2009\CyberLink.PowerCinema.v6.0.0.1309.Multilingual.Incl.Keymaker-CORE.part01.rar[CyberLink.PowerCinema.v6.0.0.1309.Multilingual.Incl.Keymaker-CORE\keygen.exe]
;===================================================================================================
================================================================================
SUSPECTS
Sent Location Q
;===================================================================================================
================================================================================
No C:\Documents and Settings\Johnnie\Desktop\FMA FTP SITE\Over Night 02 26 2k9\Fast_Money\MIsc\FlashFXP Portable\App\FlashFXP\FlashFXP.exe
No C:\Documents and Settings\Johnnie\Desktop\FMA FTP SITE\Over Night 05 05 2k9\OLD\Fast_Money\MIsc\FlashFXP Portable\App\FlashFXP\FlashFXP.exe
No C:\Documents and Settings\Johnnie\Desktop\FMA FTP SITE\Over Night 05 20 2k9\OLD\Fast_Money\MIsc\FlashFXP Portable\App\FlashFXP\FlashFXP.exe
No C:\Documents and Settings\Johnnie\My Documents\OLD\Fast_Money\MIsc\FlashFXP Portable\App\FlashFXP\FlashFXP.exe
No C:\Program Files\FlashFXP\FlashFXP old version backup.zip[FlashFXP/BACKUP/FlashFXP.exe] Q
No C:\Program Files\FlashFXP\FlashFXPlast versin feb 19 08.rar[FlashFXP\FlashFXP old version backup.zip][FlashFXP/BACKUP/FlashFXP.exe]
No C:\Program Files\FlashFXP\store\FlashFXP old version backup.zip[FlashFXP/BACKUP/FlashFXP.exe] Q
No C:\Program Files\FlashFXP\store\FlashFXPlast versin feb 19 08.rar[FlashFXP\FlashFXP old version backup.zip][FlashFXP/BACKUP/FlashFXP.exe]
No C:\Program Files\Net Tools\PortScanner.exe Q
No D:\! APPs\apps July 15 2009\Everest Ultimate 4.50.1330 Multilangage.rar[OpteroneT Keygen.exe] Q
;===================================================================================================
================================================================================
VULNERABILITIES
Id Severity Description Q
;===================================================================================================
================================================================================
;===================================================================================================
================================================================================
  • 0

#12
andrewuk

andrewuk

    Trusted Helper

  • Malware Removal
  • 5,297 posts
the scan only found false positives and some keygens/cracks - which are a likely source of infection, i would delete them all (look through the panda scan for guidance on the file names. otherwise, you are likely to be chasing your tail as you become reinfected.

i suspect in your prior attempt to clear the virus, you may have removed some system files or the prior infections have done some damage on their way through. hence, in this post we will clear away the fix tools and i will point you in the direction of another part of this forum.

from a malware point of view your logs are clean.

once you have followed the steps below, go to this part of the forum here and describe your problem. say your machine is clean of malware.


====STEP 1====
we will have to download combofix again and then uninstall it - this all allow the uninstall process to complete. we dont need to run it.

go to this page http://www.bleepingc...to-use-combofix and download combofix from one of the links provided.

Follow these steps to uninstall Combofix which will also remove some of the tools used in the removal of malware and flush your system restore points
  • Click START then RUN
  • Now type Combofix /u in the runbox and click OK. Note the space between the X and the U, it needs to be there.
    Posted Image


====STEP 2====
Please download the OTC (OTCleanIT) by OldTimer.
  • Save it to your desktop.
  • Please double-click OTC.exe to run it. (Vista users, please right click on OTMoveit2.exe and select "Run as an Administrator")
  • Click on the CleanUp! button to begin the Cleanup process and remove these components, including this application.
  • You will be asked to reboot the machine to finish the Cleanup process. If you are asked to reboot the machine choose Yes.
you can also clear away any other tools we used.


====IDEAS TO SPEED UP YOUR MACHINE====
this page http://users.telenet...owcomputer.html gives some good ideas on how to improve the efficiency of your machine and has one or two useful links to help you further.


====AND FINALLY====
The following is a list of free tools and utilities that I like to suggest to people. This list is full of great tools and utilities to help you understand how you got infected and how to keep from getting infected again.
  • MBAM - Malware Bytes Anti Malware is an excellent tool for anyone's antimalware arsenal. This program should be updated and run often.
  • SpywareBlaster - Great prevention tool to keep nasties from installing on your system.
  • SpywareGuard - Works as a Spyware "Shield" to protect your computer from getting malware in the first place.
  • IE-SpyAd - puts over 5000 sites in your restricted zone so you'll be protected when you visit innocent-looking sites that aren't actually innocent at all.
  • ATF Cleaner - Cleans temporary files from IE and Windows, empties the recycle bin and more. Great tool to help speed up your computer and knock out those nasties that like to reside in the temp folders.
  • Windows Updates - It is very important to make sure that both Internet Explorer and Windows are kept current with the latest critical security patches from Microsoft. To do this just start Internet Explorer and select Tools > Windows Update, and follow the online instructions from there.
  • Comodo Firewall - The use of a firewall is a personal preference, but its certainly a good idea. Comodo is free and light. Remember, never install more than 1 firewall. also remember, do not download the comodo antivirus program if you already have an antivirus program on your machine.
  • Digsby or Miranda-IM - These are Malware free Instant Messenger programs which allow you to connect to multiple IM services in one program! (AOL, Yahoo, ICQ, IRC, MSN)
  • Keep a backup of your important files - Now, more than ever, it's especially important to protect your digital files and memories. This article is full of good information on alternatives for home backup solutions.
  • FireFox - Alternate web browser. Open source and quick, Firefox is usually the first thing I install on a new system.
  • NoScript - Addon for Firefox that stops all scripts from running on websites. Stops malicious software from invading via flash, java, javascript, and many other entry points.
To find out more information about how you got infected in the first place and some great guidelines to follow to prevent future infections you can read this article by Tony Klein

best wishes

andrewuk
  • 0

#13
andrewuk

andrewuk

    Trusted Helper

  • Malware Removal
  • 5,297 posts
Since this issue appears to be resolved ... this Topic has been closed. Glad we could help. :)

If you're the topic starter, and need this topic reopened, please contact a staff member with the address of the thread.

Everyone else please begin a New Topic.
  • 0






Similar Topics

0 user(s) are reading this topic

0 members, 0 guests, 0 anonymous users

As Featured On:

Microsoft Yahoo BBC MSN PC Magazine Washington Post HP