Jump to content

Welcome to Geeks to Go - Register now for FREE

Geeks To Go is a helpful hub, where thousands of volunteer geeks quickly serve friendly answers and support. Check out the forums and get free advice from the experts. Register now to gain access to all of our features, it's FREE and only takes one minute. Once registered and logged in, you will be able to create topics, post replies to existing threads, give reputation to your fellow members, get your own private messenger, post status updates, manage your profile and so much more.

Create Account How it Works
Photo

Vundo infection [RESOLVED]


  • This topic is locked This topic is locked

#1
moshelby

moshelby

    New Member

  • Member
  • Pip
  • 7 posts
My computer has a vundo infection. I've tried running vundofix, fixvundo, and virtuomondebegone to no avail. Here is the hijackthis log:
Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 9:56:11 AM, on 9/16/2008
Platform: Windows XP SP3 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16705)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Intel\Wireless\Bin\EvtEng.exe
C:\Program Files\Intel\Wireless\Bin\S24EvMon.exe
C:\Program Files\Sygate\SPF\smc.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Lavasoft\Ad-Aware 2007\aawservice.exe
C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
C:\WINDOWS\system32\bgsvcgen.exe
C:\Program Files\Bonjour\mDNSResponder.exe
C:\WINDOWS\eHome\ehRecvr.exe
C:\WINDOWS\eHome\ehSched.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Network Associates\Common Framework\FrameworkService.exe
C:\Program Files\Network Associates\VirusScan\mcshield.exe
C:\Program Files\Network Associates\VirusScan\vstskmgr.exe
C:\Program Files\Microsoft SQL Server\MSSQL$VAIO_VEDB\Binn\sqlservr.exe
C:\Program Files\Intel\Wireless\Bin\RegSrvc.exe
C:\Program Files\Common Files\Sony Shared\WMPlugIn\SonicStageMonitoring.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Sony\VAIO Event Service\VESMgr.exe
C:\Program Files\Common Files\Sony Shared\VAIO Entertainment Platform\VCSW\VCSW.exe
C:\Program Files\Webroot\Spy Sweeper\SpySweeper.exe
C:\Program Files\Common Files\Sony Shared\VAIO Entertainment Platform\VzCdb\VzCdbSvc.exe
C:\Program Files\Common Files\Sony Shared\VAIO Entertainment Platform\VzCdb\VzFw.exe
C:\WINDOWS\system32\dllhost.exe
C:\WINDOWS\system32\wscntfy.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Sony\VAIO Power Management\SPMgr.exe
C:\Program Files\Sony\ISB Utility\ISBMgr.exe
C:\WINDOWS\system32\wuauclt.exe
C:\Program Files\Sony\Wireless Switch Setting Utility\Switcher.exe
C:\Program Files\Sony\VAIO Camera Utility\VCUServe.exe
C:\Program Files\Java\jre1.5.0_07\bin\jusched.exe
C:\Program Files\Hewlett-Packard\Toolbox2.0\Apache Tomcat 4.0\webapps\Toolbox\StatusClient\StatusClient.exe
C:\Program Files\Network Associates\Common Framework\UpdaterUI.exe
C:\Program Files\Network Associates\VirusScan\SHSTAT.EXE
C:\Program Files\Common Files\Network Associates\TalkBack\tbmon.exe
C:\WINDOWS\system32\ICO.EXE
C:\WINDOWS\system32\igfxtray.exe
C:\WINDOWS\system32\igfxpers.exe
C:\WINDOWS\system32\hkcmd.exe
C:\Program Files\Common Files\AOL\1154548953\ee\AOLSoftware.exe
C:\WINDOWS\ehome\ehtray.exe
C:\Program Files\Hewlett-Packard\Toolbox2.0\Javasoft\JRE\1.3.1\bin\javaw.exe
C:\Program Files\Apoint\Apoint.exe
C:\WINDOWS\eHome\ehmsas.exe
C:\Program Files\Webroot\Spy Sweeper\SpySweeperUI.exe
C:\Program Files\Apoint\Apntex.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.sony.com/vaiopeople
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft....k/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft....k/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft....k/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft....k/?LinkId=69157
R3 - URLSearchHook: AOLTBSearch Class - {EA756889-2338-43DB-8F07-D1CA6FB9C90D} - C:\Program Files\AOL\AOL Toolbar 3.0\aoltb.dll
R3 - URLSearchHook: AOLSearchHook Class - {54EB34EA-E6BE-4CFD-9F4F-C4A0C2EAFA22} - C:\Program Files\AOL\AOL Search Enhancement\AOLSearch.dll
N3 - Netscape 7: user_pref("browser.search.defaultengine", "engine://C%3A%5CProgram%20Files%5CNetscape%5CNetscape%5Csearchplugins%5CSBWeb_01.src"); (C:\Documents and Settings\OWNER\Application Data\Mozilla\Profiles\default\twwsfut9.slt\prefs.js)
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
O2 - BHO: AOL Search Enhancement - {54EB34EA-E6BE-4CFD-9F4F-C4A0C2EAFA22} - C:\Program Files\AOL\AOL Search Enhancement\AOLSearch.dll
O2 - BHO: AOL Toolbar Launcher - {7C554162-8CB7-45A4-B8F4-8EA1C75885F9} - C:\Program Files\AOL\AOL Toolbar 3.0\aoltb.dll
O3 - Toolbar: AOL Toolbar - {DE9C389F-3316-41A7-809B-AA305ED9D922} - C:\Program Files\AOL\AOL Toolbar 3.0\aoltb.dll
O4 - HKLM\..\Run: [SonyPowerCfg] "C:\Program Files\Sony\VAIO Power Management\SPMgr.exe"
O4 - HKLM\..\Run: [ISBMgr.exe] "C:\Program Files\Sony\ISB Utility\ISBMgr.exe"
O4 - HKLM\..\Run: [VAIO Update 2] "C:\Program Files\Sony\VAIO Update 2\VAIOUpdt.exe" /Stationary
O4 - HKLM\..\Run: [Switcher.exe] "C:\Program Files\Sony\Wireless Switch Setting Utility\Switcher.exe"
O4 - HKLM\..\Run: [VAIOCameraUtility] "C:\Program Files\Sony\VAIO Camera Utility\VCUServe.exe"
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.5.0_07\bin\jusched.exe"
O4 - HKLM\..\Run: [StatusClient] "C:\Program Files\Hewlett-Packard\Toolbox2.0\Apache Tomcat 4.0\webapps\Toolbox\StatusClient\StatusClient.exe" /auto
O4 - HKLM\..\Run: [TomcatStartup] "C:\Program Files\Hewlett-Packard\Toolbox2.0\hpbpsttp.exe"
O4 - HKLM\..\Run: [McAfeeUpdaterUI] "C:\Program Files\Network Associates\Common Framework\UpdaterUI.exe" /StartedFromRunKey
O4 - HKLM\..\Run: [ShStatEXE] "C:\Program Files\Network Associates\VirusScan\SHSTAT.EXE" /STANDALONE
O4 - HKLM\..\Run: [Network Associates Error Reporting Service] "C:\Program Files\Common Files\Network Associates\TalkBack\tbmon.exe"
O4 - HKLM\..\Run: [OM_Monitor] "C:\Program Files\OLYMPUS\OLYMPUS Master\FirstStart.exe"
O4 - HKLM\..\Run: [SmcService] "C:\PROGRA~1\Sygate\SPF\smc.exe" -startgui
O4 - HKLM\..\Run: [URLLSTCK.exe] C:\Program Files\Norton Internet Security\UrlLstCk.exe
O4 - HKLM\..\Run: [NvCplDaemon] "RUNDLL32.EXE" C:\WINDOWS\system32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [Mouse Suite 98 Daemon] ICO.EXE
O4 - HKLM\..\Run: [igfxtray] C:\WINDOWS\system32\igfxtray.exe
O4 - HKLM\..\Run: [igfxpers] C:\WINDOWS\system32\igfxpers.exe
O4 - HKLM\..\Run: [igfxhkcmd] C:\WINDOWS\system32\hkcmd.exe
O4 - HKLM\..\Run: [HostManager] "C:\Program Files\Common Files\AOL\1154548953\ee\AOLSoftware.exe"
O4 - HKLM\..\Run: [ehTray] C:\WINDOWS\ehome\ehtray.exe
O4 - HKLM\..\Run: [ccApp] "C:\Program Files\Common Files\Symantec Shared\ccApp.exe"
O4 - HKLM\..\Run: [Apoint] "C:\Program Files\Apoint\Apoint.exe"
O4 - HKLM\..\Run: [MSConfig] "C:\WINDOWS\PCHealth\HelpCtr\Binaries\MSConfig.exe" /auto
O4 - HKLM\..\Run: [SpySweeper] "C:\Program Files\Webroot\Spy Sweeper\SpySweeperUI.exe" /startintray
O4 - HKCU\..\Run: [OM_Monitor] "C:\Program Files\OLYMPUS\OLYMPUS Master\Monitor.exe" -NoStart
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [updateMgr] "C:\Program Files\Adobe\Acrobat 7.0\Reader\AdobeUpdateManager.exe" AcRdB7_0_9 -reboot 1
O4 - HKCU\..\Run: [A00F1EBE1342.exe] C:\DOCUME~1\Owner\LOCALS~1\Temp\_A00F1EBE1342.exe
O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office10\OSA.EXE
O8 - Extra context menu item: &AOL Toolbar Search - c:\program files\aol\aol toolbar 3.0\resources\en-US\local\search.html
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~4\Office10\EXCEL.EXE/3000
O9 - Extra button: AOL Toolbar - {3369AF0D-62E9-4bda-8103-B4C75499B578} - C:\Program Files\AOL\AOL Toolbar 3.0\aoltb.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~4\OFFICE11\REFIEBAR.DLL
O9 - Extra button: AIM - {AC9E2541-2814-11d5-BC6D-00B0D0A1DE45} - C:\Program Files\AIM\aim.exe
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O14 - IERESET.INF: START_PAGE_URL=http://www.sony.com/vaiopeople
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://update.micros...b?1160787064059
O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - http://www.update.mi...b?1218849171063
O16 - DPF: {9600F64D-755F-11D4-A47F-0001023E6D5A} (Shutterfly Picture Upload Plugin) - http://web1.shutterf...ds/Uploader.cab
O20 - Winlogon Notify: __c0072204 - C:\WINDOWS\system32\__c0072204.dat (file missing)
O23 - Service: Ad-Aware 2007 Service (aawservice) - Lavasoft AB - C:\Program Files\Lavasoft\Ad-Aware 2007\aawservice.exe
O23 - Service: Apple Mobile Device - Apple, Inc. - C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
O23 - Service: B's Recorder GOLD Library General Service (bgsvcgen) - B.H.A Corporation - C:\WINDOWS\system32\bgsvcgen.exe
O23 - Service: Bonjour Service - Apple Computer, Inc. - C:\Program Files\Bonjour\mDNSResponder.exe
O23 - Service: Intel® PROSet/Wireless Event Log (EvtEng) - Intel Corporation - C:\Program Files\Intel\Wireless\Bin\EvtEng.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: Image Converter video recording monitor for VAIO Entertainment - Sony Corporation - C:\Program Files\Sony\Image Converter 2\IcVzMon.exe
O23 - Service: iPod Service - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: McAfee Framework Service (McAfeeFramework) - McAfee, Inc. - C:\Program Files\Network Associates\Common Framework\FrameworkService.exe
O23 - Service: Network Associates McShield (McShield) - Network Associates, Inc. - C:\Program Files\Network Associates\VirusScan\mcshield.exe
O23 - Service: Network Associates Task Manager (McTaskManager) - Network Associates, Inc. - C:\Program Files\Network Associates\VirusScan\vstskmgr.exe
O23 - Service: MSCSPTISRV - Sony Corporation - C:\Program Files\Common Files\Sony Shared\AVLib\MSCSPTISRV.exe
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe
O23 - Service: PACSPTISVR - Sony Corporation - C:\Program Files\Common Files\Sony Shared\AVLib\PACSPTISVR.exe
O23 - Service: Pml Driver HPZ12 - HP - C:\WINDOWS\system32\HPZipm12.exe
O23 - Service: Intel® PROSet/Wireless Registry Service (RegSrvc) - Intel Corporation - C:\Program Files\Intel\Wireless\Bin\RegSrvc.exe
O23 - Service: Intel® PROSet/Wireless Service (S24EventMonitor) - Intel Corporation - C:\Program Files\Intel\Wireless\Bin\S24EvMon.exe
O23 - Service: Sygate Personal Firewall (SmcService) - Sygate Technologies, Inc. - C:\Program Files\Sygate\SPF\smc.exe
O23 - Service: SonicStageMonitoring - Sony Corporation - C:\Program Files\Common Files\Sony Shared\WMPlugIn\SonicStageMonitoring.exe
O23 - Service: Sony SPTI Service (SPTISRV) - Sony Corporation - C:\Program Files\Common Files\Sony Shared\AVLib\SPTISRV.exe
O23 - Service: SonicStage SCSI Service (SSScsiSV) - Sony Corporation - C:\Program Files\Common Files\Sony Shared\AVLib\SSScsiSV.exe
O23 - Service: VAIO Entertainment TV Device Arbitration Service - Sony Corporation - C:\Program Files\Common Files\Sony Shared\VAIO Entertainment Platform\VzCs\VzHardwareResourceManager\VzHardwareResourceManager.exe
O23 - Service: VAIO Event Service - Sony Corporation - C:\Program Files\Sony\VAIO Event Service\VESMgr.exe
O23 - Service: VAIO Media Integrated Server (VAIOMediaPlatform-IntegratedServer-AppServer) - Sony Corporation - C:\Program Files\Sony\VAIO Media Integrated Server\VMISrv.exe
O23 - Service: VAIO Media Integrated Server (HTTP) (VAIOMediaPlatform-IntegratedServer-HTTP) - Sony Corporation - C:\Program Files\Sony\VAIO Media Integrated Server\Platform\SV_Httpd.exe
O23 - Service: VAIO Media Integrated Server (UPnP) (VAIOMediaPlatform-IntegratedServer-UPnP) - Sony Corporation - C:\Program Files\Sony\VAIO Media Integrated Server\Platform\UPnPFramework.exe
O23 - Service: VAIO Media Gateway Server (VAIOMediaPlatform-Mobile-Gateway) - Sony Corporation - C:\Program Files\Sony\VAIO Media Integrated Server\Platform\VmGateway.exe
O23 - Service: VAIO Entertainment UPnP Client Adapter (Vcsw) - Sony Corporation - C:\Program Files\Common Files\Sony Shared\VAIO Entertainment Platform\VCSW\VCSW.exe
O23 - Service: VAIO Entertainment Database Service (VzCdbSvc) - Sony Corporation - C:\Program Files\Common Files\Sony Shared\VAIO Entertainment Platform\VzCdb\VzCdbSvc.exe
O23 - Service: VAIO Entertainment File Import Service (VzFw) - Sony Corporation - C:\Program Files\Common Files\Sony Shared\VAIO Entertainment Platform\VzCdb\VzFw.exe
O23 - Service: Webroot Spy Sweeper Engine (WebrootSpySweeperService) - Webroot Software, Inc. - C:\Program Files\Webroot\Spy Sweeper\SpySweeper.exe

--
End of file - 13425 bytes


Thanks for your help, you guys rock.
Evan
  • 0

Advertisements


#2
BHowett

BHowett

    OT Moderator

  • Moderator
  • 4,642 posts
Hello moshelby, and welcome to Geeks To Go! My name is BHowett and I will be helping you to get sorted. If for any reason you do not understand any of the instructions, or are just unsure then please do not guess , simply post back with your question, and we will go through it again.

Sorry for the delay, as you can tell we are pretty busy here :)



ComboFix

Please visit below webpage for instructions for downloading and running ComboFix

http://www.bleepingc...to-use-combofix

This includes installing the Windows XP Recovery Console in case you have not installed it yet.

For more information on the Windows XP Recovery Console read http://support.microsoft.com/kb/314058.

Once you install the Recovery Console, when you reboot your computer, you'll see the option for the Recovery Console now as well. DO NOT select Recovery Console as we don't need it. By default, your main OS is selected there. The screen stays for 2 seconds and then it proceeds to load Windows. That is normal.

Post the log from ComboFix (located in C:\combofix.txt) when you've accomplished that, along with a new HijackThis log.
  • 0

#3
moshelby

moshelby

    New Member

  • Topic Starter
  • Member
  • Pip
  • 7 posts
Here is the combofix log:
ComboFix 08-08-19.02 - Owner 2008-08-20 11:40:16.3 - NTFSx86
Microsoft Windows XP Professional 5.1.2600.3.1252.1.1033.18.520 [GMT -5:00]
Running from: C:\Documents and Settings\Owner\Desktop\ComboFix.exe
Command switches used :: C:\Documents and Settings\Owner\Desktop\WindowsXP-KB310994-SP2-Home-BootDisk-ENU.exe
* Created a new restore point
.

((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.

C:\Documents and Settings\Owner\Application Data\macromedia\Flash Player\#SharedObjects\NEZ4AY89\interclick.com
C:\Documents and Settings\Owner\Application Data\macromedia\Flash Player\#SharedObjects\NEZ4AY89\interclick.com\ud.sol
C:\Documents and Settings\Owner\Application Data\macromedia\Flash Player\macromedia.com\support\flashplayer\sys\#interclick.com
C:\Documents and Settings\Owner\Application Data\macromedia\Flash Player\macromedia.com\support\flashplayer\sys\#interclick.com\settings.sol
C:\WINDOWS\system32\efhkj.ini
C:\WINDOWS\system32\MSINET.oca
C:\WINDOWS\system32\rtutv.ini
C:\WINDOWS\system32\xkildevf.ini
C:\WINDOWS\system32\ycqomkvq.ini

.
((((((((((((((((((((((((( Files Created from 2008-07-20 to 2008-08-20 )))))))))))))))))))))))))))))))
.

2008-09-16 03:02 . 2008-09-16 03:02 <DIR> d-------- C:\Program Files\Microsoft CAPICOM 2.1.0.2
2008-09-15 21:30 . 2007-07-30 19:19 271,224 --a------ C:\WINDOWS\system32\mucltui.dll
2008-09-15 21:30 . 2007-07-30 19:19 30,072 --a------ C:\WINDOWS\system32\mucltui.dll.mui
2008-09-15 17:12 . 2008-09-15 17:12 <DIR> d-------- C:\Program Files\Malwarebytes' Anti-Malware
2008-09-15 17:12 . 2008-07-30 20:07 38,472 --a------ C:\WINDOWS\system32\drivers\mbamswissarmy.sys
2008-09-15 17:12 . 2008-07-30 20:07 17,144 --a------ C:\WINDOWS\system32\drivers\mbam.sys
2008-09-14 12:34 . 2008-05-01 09:33 331,776 -----c--- C:\WINDOWS\system32\dllcache\msadce.dll
2008-09-14 12:33 . 2008-04-11 14:04 691,712 -----c--- C:\WINDOWS\system32\dllcache\inetcomm.dll
2008-08-15 20:58 . 2006-12-29 00:31 19,569 --a------ C:\WINDOWS\000001_.tmp
2008-08-15 20:30 . 2008-08-15 20:32 <DIR> d-------- C:\04716a85cafaab720152e9427e
2008-08-15 19:19 . 2008-08-15 19:19 <DIR> d-------- C:\WINDOWS\system32\scripting
2008-08-15 19:19 . 2008-08-15 19:19 <DIR> d-------- C:\WINDOWS\system32\en
2008-08-15 19:19 . 2008-08-15 19:19 <DIR> d-------- C:\WINDOWS\system32\bits
2008-08-15 19:19 . 2008-08-15 19:19 <DIR> d-------- C:\WINDOWS\l2schemas
2008-08-15 19:04 . 2008-08-15 19:21 <DIR> d-------- C:\WINDOWS\ServicePackFiles
2008-08-15 18:32 . 2004-08-03 22:41 404,990 --------- C:\WINDOWS\system32\drivers\slntamr.sys
2008-08-15 18:31 . 2008-04-13 19:12 412,160 --------- C:\WINDOWS\system32\photometadatahandler.dll
2008-08-15 18:30 . 2008-04-13 19:12 1,737,856 --------- C:\WINDOWS\system32\mtxparhd.dll
2008-08-15 18:29 . 2008-04-13 19:11 61,440 --------- C:\WINDOWS\system32\kmsvc.dll
2008-08-15 18:29 . 2008-04-13 19:11 37,376 --------- C:\WINDOWS\system32\l2gpstore.dll
2008-08-15 18:29 . 2008-04-13 19:09 6,144 --------- C:\WINDOWS\system32\kbdpash.dll
2008-08-15 18:29 . 2008-04-13 19:09 6,144 --------- C:\WINDOWS\system32\kbdnepr.dll
2008-08-15 18:29 . 2008-04-13 19:09 6,144 --------- C:\WINDOWS\system32\kbdiultn.dll
2008-08-15 18:29 . 2008-04-13 19:09 6,144 --------- C:\WINDOWS\system32\kbdbhc.dll
2008-08-15 18:27 . 2008-04-13 19:11 1,888,992 --------- C:\WINDOWS\system32\ati3duag.dll
2008-08-15 18:26 . 2008-04-13 19:11 136,192 --------- C:\WINDOWS\system32\aaclient.dll
2008-08-15 18:26 . 2008-04-13 13:36 44,928 --------- C:\WINDOWS\system32\drivers\agpcpq.sys
2008-08-15 18:26 . 2008-04-13 13:36 42,368 --------- C:\WINDOWS\system32\drivers\agp440.sys
2008-08-15 18:26 . 2008-04-13 19:11 4,255 --------- C:\WINDOWS\system32\drivers\adv01nt5.dll
2008-08-15 18:26 . 2008-04-13 19:11 3,967 --------- C:\WINDOWS\system32\drivers\adv02nt5.dll
2008-08-15 18:26 . 2008-04-13 19:11 3,775 --------- C:\WINDOWS\system32\drivers\adv11nt5.dll
2008-08-15 18:26 . 2008-04-13 19:11 3,711 --------- C:\WINDOWS\system32\drivers\adv09nt5.dll
2008-08-15 18:26 . 2008-04-13 19:11 3,647 --------- C:\WINDOWS\system32\drivers\adv07nt5.dll
2008-08-15 18:26 . 2008-04-13 19:11 3,615 --------- C:\WINDOWS\system32\drivers\adv05nt5.dll
2008-08-15 18:26 . 2008-04-13 19:11 3,135 --------- C:\WINDOWS\system32\drivers\adv08nt5.dll

.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2008-09-16 08:19 --------- d-----w C:\Program Files\Steam
2008-09-15 22:12 --------- d-----w C:\Program Files\Common Files\Download Manager
2008-09-15 22:12 --------- d-----w C:\Documents and Settings\Owner\Application Data\Malwarebytes
2008-09-15 22:12 --------- d-----w C:\Documents and Settings\All Users\Application Data\Malwarebytes
2008-08-15 22:39 --------- d-----w C:\Program Files\Java
2008-08-03 23:52 --------- d-----w C:\Documents and Settings\Owner\Application Data\AdobeUM
2008-07-07 20:26 253,952 ----a-w C:\WINDOWS\system32\es.dll
2008-06-24 16:43 74,240 ----a-w C:\WINDOWS\system32\mscms.dll
2008-06-24 16:43 74,240 ------w C:\WINDOWS\system32\SET176D.tmp
2008-06-23 16:57 826,368 ----a-w C:\WINDOWS\system32\wininet.dll
2008-06-20 21:03 --------- d--h--w C:\Program Files\InstallShield Installation Information
2008-06-20 17:46 245,248 ----a-w C:\WINDOWS\system32\mswsock.dll
2008-06-20 11:51 361,600 ----a-w C:\WINDOWS\system32\drivers\tcpip.sys
2008-06-20 11:40 138,496 ----a-w C:\WINDOWS\system32\drivers\afd.sys
2008-06-20 11:08 225,856 ----a-w C:\WINDOWS\system32\drivers\tcpip6.sys
.

((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"OM_Monitor"="C:\Program Files\OLYMPUS\OLYMPUS Master\Monitor.exe" [2006-05-16 17:51 57344]
"ctfmon.exe"="C:\WINDOWS\system32\ctfmon.exe" [2008-04-13 19:12 15360]
"updateMgr"="C:\Program Files\Adobe\Acrobat 7.0\Reader\AdobeUpdateManager.exe" [2006-03-30 17:45 313472]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"SonyPowerCfg"="C:\Program Files\Sony\VAIO Power Management\SPMgr.exe" [2006-06-27 20:24 217088]
"ISBMgr.exe"="C:\Program Files\Sony\ISB Utility\ISBMgr.exe" [2004-02-20 16:12 32768]
"VAIO Update 2"="C:\Program Files\Sony\VAIO Update 2\VAIOUpdt.exe" [2005-10-11 23:36 151552]
"Switcher.exe"="C:\Program Files\Sony\Wireless Switch Setting Utility\Switcher.exe" [2006-02-14 14:11 176128]
"VAIOCameraUtility"="C:\Program Files\Sony\VAIO Camera Utility\VCUServe.exe" [2005-12-27 15:58 69632]
"SunJavaUpdateSched"="C:\Program Files\Java\jre1.5.0_07\bin\jusched.exe" [2006-05-03 04:56 36975]
"StatusClient"="C:\Program Files\Hewlett-Packard\Toolbox2.0\Apache Tomcat 4.0\webapps\Toolbox\StatusClient\StatusClient.exe" [2002-12-16 17:51 36864]
"TomcatStartup"="C:\Program Files\Hewlett-Packard\Toolbox2.0\hpbpsttp.exe" [2003-03-31 20:28 155648]
"McAfeeUpdaterUI"="C:\Program Files\Network Associates\Common Framework\UpdaterUI.exe" [2005-12-07 04:55 131072]
"ShStatEXE"="C:\Program Files\Network Associates\VirusScan\SHSTAT.EXE" [2004-09-22 09:00 94208]
"Network Associates Error Reporting Service"="C:\Program Files\Common Files\Network Associates\TalkBack\tbmon.exe" [2003-10-07 10:48 147514]
"OM_Monitor"="C:\Program Files\OLYMPUS\OLYMPUS Master\FirstStart.exe" [2006-05-16 17:50 40960]
"SmcService"="C:\PROGRA~1\Sygate\SPF\smc.exe" [2004-10-15 19:40 2577632]
"NvCplDaemon"="C:\WINDOWS\system32\NvCpl.dll" [2006-05-08 12:50 7561216]
"igfxtray"="C:\WINDOWS\system32\igfxtray.exe" [2006-10-06 13:11 98304]
"igfxpers"="C:\WINDOWS\system32\igfxpers.exe" [2006-10-06 13:10 94208]
"igfxhkcmd"="C:\WINDOWS\system32\hkcmd.exe" [2006-10-06 13:13 114688]
"HostManager"="C:\Program Files\Common Files\AOL\1154548953\ee\AOLSoftware.exe" [2006-04-13 15:36 50792]
"ehTray"="C:\WINDOWS\ehome\ehtray.exe" [2005-08-05 15:56 64512]
"Apoint"="C:\Program Files\Apoint\Apoint.exe" [2004-11-17 22:47 118784]
"MSConfig"="C:\WINDOWS\PCHealth\HelpCtr\Binaries\MSConfig.exe" [2008-04-13 19:12 169984]
"SpySweeper"="C:\Program Files\Webroot\Spy Sweeper\SpySweeperUI.exe" [2008-01-04 21:56 5367664]
"Mouse Suite 98 Daemon"="ICO.EXE" [2002-03-14 18:46 45056 C:\WINDOWS\system32\ico.exe]

C:\Documents and Settings\All Users\Start Menu\Programs\Startup\
Microsoft Office.lnk - C:\Program Files\Microsoft Office\Office10\OSA.EXE [2001-02-13 02:01:04 83360]

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"InstallVisualStyle"= C:\WINDOWS\Resources\Themes\Royale\Royale.msstyles
"InstallTheme"= C:\WINDOWS\Resources\Themes\Royale.theme

[hkey_local_machine\software\microsoft\windows\currentversion\explorer\ShellExecuteHooks]
"{03A80B1D-5C6A-42c2-9DFB-81B6005D8023}"= "C:\Program Files\Trend Micro\Tmas\sshook.dll" [2006-08-02 15:15 77824]

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\VESWinlogon]
2006-03-09 16:51 73728 C:\WINDOWS\system32\VESWinlogon.dll

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\drivers32]
"VIDC.dvsd"= C:\PROGRA~1\COMMON~1\SONYSH~1\VideoLib\sonydv.dll
"VIDC.MJPG"= pvmjpg21.dll

[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Adobe Reader Speed Launch.lnk]
path=C:\Documents and Settings\All Users\Start Menu\Programs\Startup\Adobe Reader Speed Launch.lnk
backup=C:\WINDOWS\pss\Adobe Reader Speed Launch.lnkCommon Startup

[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Trend Micro Anti-Spyware.lnk]
path=C:\Documents and Settings\All Users\Start Menu\Programs\Startup\Trend Micro Anti-Spyware.lnk
backup=C:\WINDOWS\pss\Trend Micro Anti-Spyware.lnkCommon Startup

[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^WinZip Quick Pick.lnk]
path=C:\Documents and Settings\All Users\Start Menu\Programs\Startup\WinZip Quick Pick.lnk
backup=C:\WINDOWS\pss\WinZip Quick Pick.lnkCommon Startup

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\DISCover]
--a------ 2006-06-01 19:55 1077248 C:\Program Files\DISC\DISCover.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\iTunesHelper]
--a------ 2007-09-26 14:42 267064 C:\Program Files\iTunes\iTunesHelper.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\MSMSGS]
--------- 2008-04-13 19:12 1695232 C:\Program Files\Messenger\msmsgs.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\NapsterShell]
--a------ 2006-06-29 16:17 319488 C:\Program Files\Napster\napster.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\QuickTime Task]
--a------ 2007-06-29 06:24 286720 C:\Program Files\QuickTime\QTTask.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Steam]
--a------ 2008-08-02 18:03 1271032 C:\Program Files\Steam\steam.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\WMPNSCFG]
--------- 2006-10-18 21:05 204288 C:\Program Files\Windows Media Player\wmpnscfg.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\services]
"ccSetMgr"=2 (0x2)
"SPBBCSvc"=2 (0x2)
"ccProxy"=2 (0x2)
"SNDSrvc"=2 (0x2)
"ccISPwdSvc"=3 (0x3)
"ccEvtMgr"=2 (0x2)
"Symantec Core LC"=2 (0x2)
"SAVScan"=3 (0x3)
"NSCService"=3 (0x3)
"navapsvc"=2 (0x2)

[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecAntiVirus]
"DisableMonitoring"=dword:00000001

[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecFirewall]
"DisableMonitoring"=dword:00000001

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"C:\\Program Files\\Hewlett-Packard\\Toolbox2.0\\Javasoft\\JRE\\1.3.1\\bin\\javaw.exe"=
"C:\\Program Files\\AIM\\aim.exe"=
"C:\\Program Files\\iTunes\\iTunes.exe"=
"C:\\Program Files\\Microsoft Games\\Age of Empires II\\age2_x1\\age2_x1.icd"=
"C:\\Program Files\\Bonjour\\mDNSResponder.exe"=
"C:\\Program Files\\EA Games\\The Battle for Middle-earth ™\\game.dat"=
"C:\\Program Files\\Steam\\steamapps\\moshelby\\counter-strike source\\hl2.exe"=
"C:\\Program Files\\Electronic Arts\\The Battle for Middle-earth ™ II\\game.dat"=
"C:\\Program Files\\DISC\\DiscStreamHub.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"%windir%\\system32\\sessmgr.exe"=

R2 MSSQL$VAIO_VEDB;MSSQL$VAIO_VEDB;C:\Program Files\Microsoft SQL Server\MSSQL$VAIO_VEDB\Binn\sqlservr.exe [2002-12-17 19:26]
R3 SonyImgF;Sony Image Conversion Filter Driver;C:\WINDOWS\system32\DRIVERS\SonyImgF.sys [2006-03-06 21:39]
R3 ti21sony;ti21sony;C:\WINDOWS\system32\drivers\ti21sony.sys [2006-02-21 21:32]
S3 bfastfao;bfastfao;C:\DOCUME~1\Owner\LOCALS~1\Temp\bfastfao.sys []
S3 EraserUtilDrv10633;EraserUtilDrv10633;C:\Program Files\Common Files\Symantec Shared\EENGINE\EraserUtilDrv10633.sys []
S3 Image Converter video recording monitor for VAIO Entertainment;Image Converter video recording monitor for VAIO Entertainment;C:\Program Files\Sony\Image Converter 2\IcVzMon.exe [2005-07-14 21:10]
S3 pelmouse;Mouse Suite Driver;C:\WINDOWS\system32\DRIVERS\pelmouse.sys [2002-06-28 20:21]
S3 pelusblf;USB Mouse Low Filter Driver;C:\WINDOWS\system32\DRIVERS\pelusblf.sys [2001-07-24 12:34]
S3 SQLAgent$VAIO_VEDB;SQLAgent$VAIO_VEDB;C:\Program Files\Microsoft SQL Server\MSSQL$VAIO_VEDB\Binn\sqlagent.EXE [2002-12-17 19:23]

[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{d8435c48-225e-11db-b383-806d6172696f}]
\Shell\AutoRun\command - E:\sony\Autorun.exe
.
Contents of the 'Scheduled Tasks' folder

2008-09-19 C:\WINDOWS\Tasks\AppleSoftwareUpdate.job
- C:\Program Files\Apple Software Update\SoftwareUpdate.exe [2007-08-29 14:57]

2008-09-15 C:\WINDOWS\Tasks\wrSpySweeperTrialSweep.job
- C:\Program Files\Webroot\Spy Sweeper\SpySweeperUI.exe [2008-01-04 21:56]

2008-09-15 C:\WINDOWS\Tasks\wrSpySweeperTrialSweep.job
- C:\Program Files\Webroot\Spy Sweeper\SpySweeperUI.exe [2008-01-04 21:56]

2008-09-15 C:\WINDOWS\Tasks\wrSpySweeperTrialSweep.job
- C:\","D:\","E:\" []
.
- - - - ORPHANS REMOVED - - - -

HKLM-Run-URLLSTCK.exe - C:\Program Files\Norton Internet Security\UrlLstCk.exe
HKLM-Run-ccApp - C:\Program Files\Common Files\Symantec Shared\ccApp.exe
Notify-__c0072204 - C:\WINDOWS\system32\__c0072204.dat
MSConfigStartUp-hcsystray - C:\Program Files\Kuma Games\hcsystray\hc_tray.exe


.
------- Supplementary Scan -------
.
FireFox -: Profile - C:\Documents and Settings\Owner\Application Data\Mozilla\Firefox\Profiles\1v9b44sr.default\
.

**************************************************************************

catchme 0.3.1361 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2008-08-20 11:44:13
Windows 5.1.2600 Service Pack 3 NTFS

scanning hidden processes ...

scanning hidden autostart entries ...

scanning hidden files ...

scan completed successfully
hidden files: 0

**************************************************************************

[HKEY_LOCAL_MACHINE\system\ControlSet001\Services\vsdatant]
"ImagePath"=""
.
Completion time: 2008-08-20 11:46:52
ComboFix-quarantined-files.txt 2008-08-20 16:46:05

Pre-Run: 55,663,607,808 bytes free
Post-Run: 56,118,571,008 bytes free

WindowsXP-KB310994-SP2-Home-BootDisk-ENU.exe
[boot loader]
timeout=2
default=multi(0)disk(0)rdisk(0)partition(2)\WINDOWS
[operating systems]
C:\CMDCONS\BOOTSECT.DAT="Microsoft Windows Recovery Console" /cmdcons
multi(0)disk(0)rdisk(0)partition(2)\WINDOWS="Windows XP Media Center Edition" /noexecute=optin /fastdetect

225 --- E O F --- 2008-09-20 08:10:53


And here is the highjackthis log:
Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 11:48:24 AM, on 8/20/2008
Platform: Windows XP SP3 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16705)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Intel\Wireless\Bin\EvtEng.exe
C:\Program Files\Intel\Wireless\Bin\S24EvMon.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Lavasoft\Ad-Aware 2007\aawservice.exe
C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
C:\WINDOWS\system32\bgsvcgen.exe
C:\Program Files\Bonjour\mDNSResponder.exe
C:\WINDOWS\eHome\ehRecvr.exe
C:\WINDOWS\eHome\ehSched.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Network Associates\Common Framework\FrameworkService.exe
C:\Program Files\Network Associates\VirusScan\mcshield.exe
C:\Program Files\Network Associates\VirusScan\vstskmgr.exe
C:\Program Files\Microsoft SQL Server\MSSQL$VAIO_VEDB\Binn\sqlservr.exe
C:\Program Files\Intel\Wireless\Bin\RegSrvc.exe
C:\Program Files\Common Files\Sony Shared\WMPlugIn\SonicStageMonitoring.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Sony\VAIO Event Service\VESMgr.exe
C:\Program Files\Common Files\Sony Shared\VAIO Entertainment Platform\VCSW\VCSW.exe
C:\Program Files\Webroot\Spy Sweeper\SpySweeper.exe
C:\Program Files\Common Files\Sony Shared\VAIO Entertainment Platform\VzCdb\VzCdbSvc.exe
C:\Program Files\Common Files\Sony Shared\VAIO Entertainment Platform\VzCdb\VzFw.exe
C:\WINDOWS\system32\dllhost.exe
C:\Program Files\Sony\VAIO Power Management\SPMgr.exe
C:\Program Files\Sony\ISB Utility\ISBMgr.exe
C:\Program Files\Sony\VAIO Camera Utility\VCUServe.exe
C:\Program Files\Java\jre1.5.0_07\bin\jusched.exe
C:\Program Files\Hewlett-Packard\Toolbox2.0\Apache Tomcat 4.0\webapps\Toolbox\StatusClient\StatusClient.exe
C:\Program Files\Network Associates\Common Framework\UpdaterUI.exe
C:\Program Files\Network Associates\VirusScan\SHSTAT.EXE
C:\Program Files\Common Files\Network Associates\TalkBack\tbmon.exe
C:\WINDOWS\system32\ICO.EXE
C:\WINDOWS\system32\igfxtray.exe
C:\WINDOWS\system32\igfxpers.exe
C:\WINDOWS\system32\hkcmd.exe
C:\Program Files\Common Files\AOL\1154548953\ee\AOLSoftware.exe
C:\WINDOWS\ehome\ehtray.exe
C:\Program Files\Hewlett-Packard\Toolbox2.0\Javasoft\JRE\1.3.1\bin\javaw.exe
C:\Program Files\Apoint\Apoint.exe
C:\WINDOWS\eHome\ehmsas.exe
C:\Program Files\Apoint\Apntex.exe
C:\WINDOWS\system32\ctfmon.exe
C:\WINDOWS\system32\wscntfy.exe
C:\WINDOWS\system32\notepad.exe
C:\WINDOWS\explorer.exe
C:\Program Files\Internet Explorer\IEXPLORE.EXE
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.sony.com/vaiopeople
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft....k/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft....k/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft....k/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft....k/?LinkId=69157
R3 - URLSearchHook: AOLSearchHook Class - {54EB34EA-E6BE-4CFD-9F4F-C4A0C2EAFA22} - C:\Program Files\AOL\AOL Search Enhancement\AOLSearch.dll
N3 - Netscape 7: user_pref("browser.search.defaultengine", "engine://C%3A%5CProgram%20Files%5CNetscape%5CNetscape%5Csearchplugins%5CSBWeb_01.src"); (C:\Documents and Settings\OWNER\Application Data\Mozilla\Profiles\default\twwsfut9.slt\prefs.js)
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
O2 - BHO: AOL Search Enhancement - {54EB34EA-E6BE-4CFD-9F4F-C4A0C2EAFA22} - C:\Program Files\AOL\AOL Search Enhancement\AOLSearch.dll
O2 - BHO: AOL Toolbar Launcher - {7C554162-8CB7-45A4-B8F4-8EA1C75885F9} - C:\Program Files\AOL\AOL Toolbar 3.0\aoltb.dll
O3 - Toolbar: AOL Toolbar - {DE9C389F-3316-41A7-809B-AA305ED9D922} - C:\Program Files\AOL\AOL Toolbar 3.0\aoltb.dll
O4 - HKLM\..\Run: [SonyPowerCfg] "C:\Program Files\Sony\VAIO Power Management\SPMgr.exe"
O4 - HKLM\..\Run: [ISBMgr.exe] "C:\Program Files\Sony\ISB Utility\ISBMgr.exe"
O4 - HKLM\..\Run: [VAIO Update 2] "C:\Program Files\Sony\VAIO Update 2\VAIOUpdt.exe" /Stationary
O4 - HKLM\..\Run: [Switcher.exe] "C:\Program Files\Sony\Wireless Switch Setting Utility\Switcher.exe"
O4 - HKLM\..\Run: [VAIOCameraUtility] "C:\Program Files\Sony\VAIO Camera Utility\VCUServe.exe"
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.5.0_07\bin\jusched.exe"
O4 - HKLM\..\Run: [StatusClient] "C:\Program Files\Hewlett-Packard\Toolbox2.0\Apache Tomcat 4.0\webapps\Toolbox\StatusClient\StatusClient.exe" /auto
O4 - HKLM\..\Run: [TomcatStartup] "C:\Program Files\Hewlett-Packard\Toolbox2.0\hpbpsttp.exe"
O4 - HKLM\..\Run: [McAfeeUpdaterUI] "C:\Program Files\Network Associates\Common Framework\UpdaterUI.exe" /StartedFromRunKey
O4 - HKLM\..\Run: [ShStatEXE] "C:\Program Files\Network Associates\VirusScan\SHSTAT.EXE" /STANDALONE
O4 - HKLM\..\Run: [Network Associates Error Reporting Service] "C:\Program Files\Common Files\Network Associates\TalkBack\tbmon.exe"
O4 - HKLM\..\Run: [OM_Monitor] "C:\Program Files\OLYMPUS\OLYMPUS Master\FirstStart.exe"
O4 - HKLM\..\Run: [SmcService] "C:\PROGRA~1\Sygate\SPF\smc.exe" -startgui
O4 - HKLM\..\Run: [NvCplDaemon] "RUNDLL32.EXE" C:\WINDOWS\system32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [Mouse Suite 98 Daemon] ICO.EXE
O4 - HKLM\..\Run: [igfxtray] C:\WINDOWS\system32\igfxtray.exe
O4 - HKLM\..\Run: [igfxpers] C:\WINDOWS\system32\igfxpers.exe
O4 - HKLM\..\Run: [igfxhkcmd] C:\WINDOWS\system32\hkcmd.exe
O4 - HKLM\..\Run: [HostManager] "C:\Program Files\Common Files\AOL\1154548953\ee\AOLSoftware.exe"
O4 - HKLM\..\Run: [ehTray] C:\WINDOWS\ehome\ehtray.exe
O4 - HKLM\..\Run: [Apoint] "C:\Program Files\Apoint\Apoint.exe"
O4 - HKLM\..\Run: [MSConfig] "C:\WINDOWS\PCHealth\HelpCtr\Binaries\MSConfig.exe" /auto
O4 - HKLM\..\Run: [SpySweeper] "C:\Program Files\Webroot\Spy Sweeper\SpySweeperUI.exe" /startintray
O4 - HKCU\..\Run: [OM_Monitor] "C:\Program Files\OLYMPUS\OLYMPUS Master\Monitor.exe" -NoStart
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [updateMgr] "C:\Program Files\Adobe\Acrobat 7.0\Reader\AdobeUpdateManager.exe" AcRdB7_0_9 -reboot 1
O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office10\OSA.EXE
O8 - Extra context menu item: &AOL Toolbar Search - c:\program files\aol\aol toolbar 3.0\resources\en-US\local\search.html
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~4\Office10\EXCEL.EXE/3000
O9 - Extra button: AOL Toolbar - {3369AF0D-62E9-4bda-8103-B4C75499B578} - C:\Program Files\AOL\AOL Toolbar 3.0\aoltb.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~4\OFFICE11\REFIEBAR.DLL
O9 - Extra button: AIM - {AC9E2541-2814-11d5-BC6D-00B0D0A1DE45} - C:\Program Files\AIM\aim.exe
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O14 - IERESET.INF: START_PAGE_URL=http://www.sony.com/vaiopeople
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://update.micros...b?1160787064059
O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - http://www.update.mi...b?1218849171063
O16 - DPF: {9600F64D-755F-11D4-A47F-0001023E6D5A} (Shutterfly Picture Upload Plugin) - http://web1.shutterf...ds/Uploader.cab
O23 - Service: Ad-Aware 2007 Service (aawservice) - Lavasoft AB - C:\Program Files\Lavasoft\Ad-Aware 2007\aawservice.exe
O23 - Service: Apple Mobile Device - Apple, Inc. - C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
O23 - Service: B's Recorder GOLD Library General Service (bgsvcgen) - B.H.A Corporation - C:\WINDOWS\system32\bgsvcgen.exe
O23 - Service: Bonjour Service - Apple Computer, Inc. - C:\Program Files\Bonjour\mDNSResponder.exe
O23 - Service: Intel® PROSet/Wireless Event Log (EvtEng) - Intel Corporation - C:\Program Files\Intel\Wireless\Bin\EvtEng.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: Image Converter video recording monitor for VAIO Entertainment - Sony Corporation - C:\Program Files\Sony\Image Converter 2\IcVzMon.exe
O23 - Service: iPod Service - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: McAfee Framework Service (McAfeeFramework) - McAfee, Inc. - C:\Program Files\Network Associates\Common Framework\FrameworkService.exe
O23 - Service: Network Associates McShield (McShield) - Network Associates, Inc. - C:\Program Files\Network Associates\VirusScan\mcshield.exe
O23 - Service: Network Associates Task Manager (McTaskManager) - Network Associates, Inc. - C:\Program Files\Network Associates\VirusScan\vstskmgr.exe
O23 - Service: MSCSPTISRV - Sony Corporation - C:\Program Files\Common Files\Sony Shared\AVLib\MSCSPTISRV.exe
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe
O23 - Service: PACSPTISVR - Sony Corporation - C:\Program Files\Common Files\Sony Shared\AVLib\PACSPTISVR.exe
O23 - Service: Pml Driver HPZ12 - HP - C:\WINDOWS\system32\HPZipm12.exe
O23 - Service: Intel® PROSet/Wireless Registry Service (RegSrvc) - Intel Corporation - C:\Program Files\Intel\Wireless\Bin\RegSrvc.exe
O23 - Service: Intel® PROSet/Wireless Service (S24EventMonitor) - Intel Corporation - C:\Program Files\Intel\Wireless\Bin\S24EvMon.exe
O23 - Service: Sygate Personal Firewall (SmcService) - Sygate Technologies, Inc. - C:\Program Files\Sygate\SPF\smc.exe
O23 - Service: SonicStageMonitoring - Sony Corporation - C:\Program Files\Common Files\Sony Shared\WMPlugIn\SonicStageMonitoring.exe
O23 - Service: Sony SPTI Service (SPTISRV) - Sony Corporation - C:\Program Files\Common Files\Sony Shared\AVLib\SPTISRV.exe
O23 - Service: SonicStage SCSI Service (SSScsiSV) - Sony Corporation - C:\Program Files\Common Files\Sony Shared\AVLib\SSScsiSV.exe
O23 - Service: VAIO Entertainment TV Device Arbitration Service - Sony Corporation - C:\Program Files\Common Files\Sony Shared\VAIO Entertainment Platform\VzCs\VzHardwareResourceManager\VzHardwareResourceManager.exe
O23 - Service: VAIO Event Service - Sony Corporation - C:\Program Files\Sony\VAIO Event Service\VESMgr.exe
O23 - Service: VAIO Media Integrated Server (VAIOMediaPlatform-IntegratedServer-AppServer) - Sony Corporation - C:\Program Files\Sony\VAIO Media Integrated Server\VMISrv.exe
O23 - Service: VAIO Media Integrated Server (HTTP) (VAIOMediaPlatform-IntegratedServer-HTTP) - Sony Corporation - C:\Program Files\Sony\VAIO Media Integrated Server\Platform\SV_Httpd.exe
O23 - Service: VAIO Media Integrated Server (UPnP) (VAIOMediaPlatform-IntegratedServer-UPnP) - Sony Corporation - C:\Program Files\Sony\VAIO Media Integrated Server\Platform\UPnPFramework.exe
O23 - Service: VAIO Media Gateway Server (VAIOMediaPlatform-Mobile-Gateway) - Sony Corporation - C:\Program Files\Sony\VAIO Media Integrated Server\Platform\VmGateway.exe
O23 - Service: VAIO Entertainment UPnP Client Adapter (Vcsw) - Sony Corporation - C:\Program Files\Common Files\Sony Shared\VAIO Entertainment Platform\VCSW\VCSW.exe
O23 - Service: VAIO Entertainment Database Service (VzCdbSvc) - Sony Corporation - C:\Program Files\Common Files\Sony Shared\VAIO Entertainment Platform\VzCdb\VzCdbSvc.exe
O23 - Service: VAIO Entertainment File Import Service (VzFw) - Sony Corporation - C:\Program Files\Common Files\Sony Shared\VAIO Entertainment Platform\VzCdb\VzFw.exe
O23 - Service: Webroot Spy Sweeper Engine (WebrootSpySweeperService) - Webroot Software, Inc. - C:\Program Files\Webroot\Spy Sweeper\SpySweeper.exe

--
End of file - 12742 bytes


Thanks
  • 0

#4
BHowett

BHowett

    OT Moderator

  • Moderator
  • 4,642 posts
Combofix Script.txt
1. Please open Notepad
  • Click Start , then Run
  • Type notepad .exe in the Run Box.

2. Now copy/paste the entire content of the codebox below into the Notepad window:

File::
C:\WINDOWS\000001_.tmp
Folder::
C:\04716a85cafaab720152e9427e


3. Save the above as CFScript.txt

4. Then drag the CFScript.txt into ComboFix.exe as depicted in the animation below. This will start ComboFix again.

Posted Image


5. After reboot, (in case it asks to reboot), please post the following reports/logs into your next reply:
  • Combofix.txt .

===============================================

ATF Cleaner

Please download ATF Cleaner by Atribune.
This program is for XP and Windows 2000 onlyDouble-click ATF-Cleaner.exe to run the program.
Under Main choose: Select All
Click the Empty Selected button.
If you use Firefox browserClick Firefox at the top and choose: Select All
Click the Empty Selected button.
NOTE: If you would like to keep your saved passwords, please click No at the prompt.
If you use Opera browserClick Opera at the top and choose: Select All
Click the Empty Selected button.
NOTE: If you would like to keep your saved passwords, please click No at the prompt.
Click Exit on the Main menu to close the program.
For Technical Support, double-click the e-mail address located at the bottom of each menu.

===============================================

Kaspersky WebScanner

please go to Kaspersky website and perform an online antivirus scan.

  • Read through the requirements and privacy statement and click on Accept button.
  • It will start downloading and installing the scanner and virus definitions. You will be prompted to install an application from Kaspersky. Click Run.
  • When the downloads have finished, click on Settings.
  • Make sure these boxes are checked (ticked). If they are not, please tick them and click on the Save button:
    • Spyware, Adware, Dialers, and other potentially dangerous programs
      Archives
      Mail databases
  • Click on My Computer under Scan.
  • Once the scan is complete, it will display the results. Click on View Scan Report.
  • You will see a list of infected items there. Click on Save Report As....
  • Save this report to a convenient place. Change the Files of type to Text file (.txt) before clicking on the Save button.
  • Please post this log in your next reply.

===============================================

Needed in your next reply:

Combofix log
Kaspersky WebScanner results

And let me know how your system is running now :)

Edited by BHowett, 21 August 2008 - 10:39 AM.

  • 0

#5
moshelby

moshelby

    New Member

  • Topic Starter
  • Member
  • Pip
  • 7 posts
The computer is running more smoothly. Thanks for your help so far. Combofix log:
ComboFix 08-08-19.02 - Owner 2008-08-22 12:16:56.4 - NTFSx86
Microsoft Windows XP Professional 5.1.2600.3.1252.1.1033.18.354 [GMT -5:00]
Running from: C:\Documents and Settings\Owner\Desktop\ComboFix.exe
Command switches used :: C:\Documents and Settings\Owner\Desktop\CFScript.txt
* Created a new restore point
* Resident AV is active


FILE ::
C:\WINDOWS\000001_.tmp
.

((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.

C:\04716a85cafaab720152e9427e
C:\04716a85cafaab720152e9427e\$shtdwn$.req
C:\04716a85cafaab720152e9427e\i386\_networkingperfcounters.ini
C:\04716a85cafaab720152e9427e\i386\1394bus.sy_
C:\04716a85cafaab720152e9427e\i386\4mmdat.sy_
C:\04716a85cafaab720152e9427e\i386\61883.sy_
C:\04716a85cafaab720152e9427e\i386\6to4svc.dl_
C:\04716a85cafaab720152e9427e\i386\aaclient.dl_
C:\04716a85cafaab720152e9427e\i386\aaclient.mu_
C:\04716a85cafaab720152e9427e\i386\ac97ali.sy_
C:\04716a85cafaab720152e9427e\i386\ac97via.sy_
C:\04716a85cafaab720152e9427e\i386\acadproc.dl_
C:\04716a85cafaab720152e9427e\i386\access.cp_
C:\04716a85cafaab720152e9427e\i386\accwiz.ex_
C:\04716a85cafaab720152e9427e\i386\acgenral.dl_
C:\04716a85cafaab720152e9427e\i386\aclayers.dl_
C:\04716a85cafaab720152e9427e\i386\aclua.dl_
C:\04716a85cafaab720152e9427e\i386\aclui.dl_
C:\04716a85cafaab720152e9427e\i386\acpi.sy_
C:\04716a85cafaab720152e9427e\i386\acspecfc.dl_
C:\04716a85cafaab720152e9427e\i386\act_plcy.ht_
C:\04716a85cafaab720152e9427e\i386\actconn.ht_
C:\04716a85cafaab720152e9427e\i386\actdone.ht_
C:\04716a85cafaab720152e9427e\i386\acterror.ht_
C:\04716a85cafaab720152e9427e\i386\activ.ht_
C:\04716a85cafaab720152e9427e\i386\activate.ht_
C:\04716a85cafaab720152e9427e\i386\activeds.dl_
C:\04716a85cafaab720152e9427e\i386\activerr.ht_
C:\04716a85cafaab720152e9427e\i386\activsvc.ht_
C:\04716a85cafaab720152e9427e\i386\actlan.ht_
C:\04716a85cafaab720152e9427e\i386\actmovie.ex_
C:\04716a85cafaab720152e9427e\i386\actshell.ht_
C:\04716a85cafaab720152e9427e\i386\actxprxy.dl_
C:\04716a85cafaab720152e9427e\i386\acxtrnal.dl_
C:\04716a85cafaab720152e9427e\i386\adcjavas.in_
C:\04716a85cafaab720152e9427e\i386\adcvbs.in_
C:\04716a85cafaab720152e9427e\i386\adeskerr.ht_
C:\04716a85cafaab720152e9427e\i386\admexs.dl_
C:\04716a85cafaab720152e9427e\i386\admin.dll
C:\04716a85cafaab720152e9427e\i386\admin.exe
C:\04716a85cafaab720152e9427e\i386\admjoy.sy_
C:\04716a85cafaab720152e9427e\i386\admparse.dl_
C:\04716a85cafaab720152e9427e\i386\admwprox.dl_
C:\04716a85cafaab720152e9427e\i386\adojavas.in_
C:\04716a85cafaab720152e9427e\i386\adovbs.in_
C:\04716a85cafaab720152e9427e\i386\adrdyreg.ht_
C:\04716a85cafaab720152e9427e\i386\adsiis51.dl_
C:\04716a85cafaab720152e9427e\i386\adsldp.dl_
C:\04716a85cafaab720152e9427e\i386\adsldpc.dl_
C:\04716a85cafaab720152e9427e\i386\adsmsext.dl_
C:\04716a85cafaab720152e9427e\i386\adsnt.dl_
C:\04716a85cafaab720152e9427e\i386\adsnw.dl_
C:\04716a85cafaab720152e9427e\i386\adv01nt5.dl_
C:\04716a85cafaab720152e9427e\i386\adv02nt5.dl_
C:\04716a85cafaab720152e9427e\i386\adv05nt5.dl_
C:\04716a85cafaab720152e9427e\i386\adv07nt5.dl_
C:\04716a85cafaab720152e9427e\i386\adv08nt5.dl_
C:\04716a85cafaab720152e9427e\i386\adv09nt5.dl_
C:\04716a85cafaab720152e9427e\i386\adv11nt5.dl_
C:\04716a85cafaab720152e9427e\i386\advapi32.dl_
C:\04716a85cafaab720152e9427e\i386\advpack.dl_
C:\04716a85cafaab720152e9427e\i386\aec.sy_
C:\04716a85cafaab720152e9427e\i386\afd.sy_
C:\04716a85cafaab720152e9427e\i386\agentanm.dl_
C:\04716a85cafaab720152e9427e\i386\agentctl.dl_
C:\04716a85cafaab720152e9427e\i386\agentdp2.dl_
C:\04716a85cafaab720152e9427e\i386\agentdpv.dl_
C:\04716a85cafaab720152e9427e\i386\agentmpx.dl_
C:\04716a85cafaab720152e9427e\i386\agentpsh.dl_
C:\04716a85cafaab720152e9427e\i386\agentsr.dl_
C:\04716a85cafaab720152e9427e\i386\agentsvr.ex_
C:\04716a85cafaab720152e9427e\i386\agp440.sy_
C:\04716a85cafaab720152e9427e\i386\agpcpq.sy_
C:\04716a85cafaab720152e9427e\i386\agt0401.dl_
C:\04716a85cafaab720152e9427e\i386\agt0401.hl_
C:\04716a85cafaab720152e9427e\i386\agt0404.dl_
C:\04716a85cafaab720152e9427e\i386\agt0404.hl_
C:\04716a85cafaab720152e9427e\i386\agt0405.dl_
C:\04716a85cafaab720152e9427e\i386\agt0405.hl_
C:\04716a85cafaab720152e9427e\i386\agt0406.dl_
C:\04716a85cafaab720152e9427e\i386\agt0406.hl_
C:\04716a85cafaab720152e9427e\i386\agt0407.dl_
C:\04716a85cafaab720152e9427e\i386\agt0407.hl_
C:\04716a85cafaab720152e9427e\i386\agt0408.dl_
C:\04716a85cafaab720152e9427e\i386\agt0408.hl_
C:\04716a85cafaab720152e9427e\i386\agt0409.dl_
C:\04716a85cafaab720152e9427e\i386\agt0409.hl_
C:\04716a85cafaab720152e9427e\i386\agt040b.dl_
C:\04716a85cafaab720152e9427e\i386\agt040b.hl_
C:\04716a85cafaab720152e9427e\i386\agt040c.dl_
C:\04716a85cafaab720152e9427e\i386\agt040c.hl_
C:\04716a85cafaab720152e9427e\i386\agt040d.dl_
C:\04716a85cafaab720152e9427e\i386\agt040d.hl_
C:\04716a85cafaab720152e9427e\i386\agt040e.dl_
C:\04716a85cafaab720152e9427e\i386\agt040e.hl_
C:\04716a85cafaab720152e9427e\i386\agt0410.dl_
C:\04716a85cafaab720152e9427e\i386\agt0410.hl_
C:\04716a85cafaab720152e9427e\i386\agt0411.dl_
C:\04716a85cafaab720152e9427e\i386\agt0411.hl_
C:\04716a85cafaab720152e9427e\i386\agt0412.dl_
C:\04716a85cafaab720152e9427e\i386\agt0412.hl_
C:\04716a85cafaab720152e9427e\i386\agt0413.dl_
C:\04716a85cafaab720152e9427e\i386\agt0413.hl_
C:\04716a85cafaab720152e9427e\i386\agt0414.dl_
C:\04716a85cafaab720152e9427e\i386\agt0414.hl_
C:\04716a85cafaab720152e9427e\i386\agt0415.dl_
C:\04716a85cafaab720152e9427e\i386\agt0415.hl_
C:\04716a85cafaab720152e9427e\i386\agt0416.dl_
C:\04716a85cafaab720152e9427e\i386\agt0416.hl_
C:\04716a85cafaab720152e9427e\i386\agt0419.dl_
C:\04716a85cafaab720152e9427e\i386\agt0419.hl_
C:\04716a85cafaab720152e9427e\i386\agt041d.dl_
C:\04716a85cafaab720152e9427e\i386\agt041d.hl_
C:\04716a85cafaab720152e9427e\i386\agt041f.dl_
C:\04716a85cafaab720152e9427e\i386\agt041f.hl_
C:\04716a85cafaab720152e9427e\i386\agt0804.dl_
C:\04716a85cafaab720152e9427e\i386\agt0804.hl_
C:\04716a85cafaab720152e9427e\i386\agt0816.dl_
C:\04716a85cafaab720152e9427e\i386\agt0816.hl_
C:\04716a85cafaab720152e9427e\i386\agt0c0a.dl_
C:\04716a85cafaab720152e9427e\i386\agt0c0a.hl_
C:\04716a85cafaab720152e9427e\i386\agtcore.js_
C:\04716a85cafaab720152e9427e\i386\agtctl15.tl_
C:\04716a85cafaab720152e9427e\i386\agtinst.in_
C:\04716a85cafaab720152e9427e\i386\agtintl.dl_
C:\04716a85cafaab720152e9427e\i386\agtscrp2.js_
C:\04716a85cafaab720152e9427e\i386\agtscrpt.js_
C:\04716a85cafaab720152e9427e\i386\ahui.ex_
C:\04716a85cafaab720152e9427e\i386\alg.ex_
C:\04716a85cafaab720152e9427e\i386\alim1541.sy_
C:\04716a85cafaab720152e9427e\i386\alrsvc.dl_
C:\04716a85cafaab720152e9427e\i386\amdagp.sy_
C:\04716a85cafaab720152e9427e\i386\amdk6.sy_
C:\04716a85cafaab720152e9427e\i386\amdk7.sy_
C:\04716a85cafaab720152e9427e\i386\amstream.dl_
C:\04716a85cafaab720152e9427e\i386\an983.sy_
C:\04716a85cafaab720152e9427e\i386\apolicy.ht_
C:\04716a85cafaab720152e9427e\i386\appconf.dl_
C:\04716a85cafaab720152e9427e\i386\apph_sp.sd_
C:\04716a85cafaab720152e9427e\i386\apphelp.dl_
C:\04716a85cafaab720152e9427e\i386\apphelp.sd_
C:\04716a85cafaab720152e9427e\i386\appmgmts.dl_
C:\04716a85cafaab720152e9427e\i386\appmgr.dl_
C:\04716a85cafaab720152e9427e\i386\apps.ch_
C:\04716a85cafaab720152e9427e\i386\apps_sp.ch_
C:\04716a85cafaab720152e9427e\i386\appwiz.cp_
C:\04716a85cafaab720152e9427e\i386\aprvcyms.ht_
C:\04716a85cafaab720152e9427e\i386\aqueue.dl_
C:\04716a85cafaab720152e9427e\i386\archvapp.in_
C:\04716a85cafaab720152e9427e\i386\areg1.ht_
C:\04716a85cafaab720152e9427e\i386\aregdial.ht_
C:\04716a85cafaab720152e9427e\i386\aregdone.ht_
C:\04716a85cafaab720152e9427e\i386\aregsty2.cs_
C:\04716a85cafaab720152e9427e\i386\aregstyl.cs_
C:\04716a85cafaab720152e9427e\i386\arial.tt_
C:\04716a85cafaab720152e9427e\i386\arialbd.tt_
C:\04716a85cafaab720152e9427e\i386\ariblk.tt_
C:\04716a85cafaab720152e9427e\i386\arp1394.sy_
C:\04716a85cafaab720152e9427e\i386\arrow.gi_
C:\04716a85cafaab720152e9427e\i386\asctrls.oc_
C:\04716a85cafaab720152e9427e\i386\asferror.dl_
C:\04716a85cafaab720152e9427e\i386\asms\10\msft\windows\gdiplus\gdiplus.cat
C:\04716a85cafaab720152e9427e\i386\asms\10\msft\windows\gdiplus\gdiplus.dll
C:\04716a85cafaab720152e9427e\i386\asms\10\msft\windows\gdiplus\gdiplus.man
C:\04716a85cafaab720152e9427e\i386\asms\10\policy\msft\windows\gdiplus\gdiplus.cat
C:\04716a85cafaab720152e9427e\i386\asms\10\policy\msft\windows\gdiplus\gdiplus.man
C:\04716a85cafaab720152e9427e\i386\asms\51\msft\windows\system\default\default.cat
C:\04716a85cafaab720152e9427e\i386\asms\51\msft\windows\system\default\default.man
C:\04716a85cafaab720152e9427e\i386\asms\51\policy\msft\windows\system\default\default.cat
C:\04716a85cafaab720152e9427e\i386\asms\51\policy\msft\windows\system\default\default.man
C:\04716a85cafaab720152e9427e\i386\asms\52\msft\windows\net\dxmrtp\dxmrtp.cat
C:\04716a85cafaab720152e9427e\i386\asms\52\msft\windows\net\dxmrtp\dxmrtp.dll
C:\04716a85cafaab720152e9427e\i386\asms\52\msft\windows\net\dxmrtp\dxmrtp.man
C:\04716a85cafaab720152e9427e\i386\asms\52\msft\windows\net\rtcdll\rtcdll.cat
C:\04716a85cafaab720152e9427e\i386\asms\52\msft\windows\net\rtcdll\rtcdll.dll
C:\04716a85cafaab720152e9427e\i386\asms\52\msft\windows\net\rtcdll\rtcdll.man
C:\04716a85cafaab720152e9427e\i386\asms\52\msft\windows\net\rtcres\rtcres.cat
C:\04716a85cafaab720152e9427e\i386\asms\52\msft\windows\net\rtcres\rtcres.dll
C:\04716a85cafaab720152e9427e\i386\asms\52\msft\windows\net\rtcres\rtcres.man
C:\04716a85cafaab720152e9427e\i386\asms\52\policy\msft\windows\networking\dxmrtp\dxmrtp.cat
C:\04716a85cafaab720152e9427e\i386\asms\52\policy\msft\windows\networking\dxmrtp\dxmrtp.man
C:\04716a85cafaab720152e9427e\i386\asms\52\policy\msft\windows\networking\rtcdll\rtcdll.cat
C:\04716a85cafaab720152e9427e\i386\asms\52\policy\msft\windows\networking\rtcdll\rtcdll.man
C:\04716a85cafaab720152e9427e\i386\asms\60\msft\vcrtl\atl.dll
C:\04716a85cafaab720152e9427e\i386\asms\60\msft\vcrtl\mfc42.dll
C:\04716a85cafaab720152e9427e\i386\asms\60\msft\vcrtl\mfc42u.dll
C:\04716a85cafaab720152e9427e\i386\asms\60\msft\vcrtl\msvcp60.dll
C:\04716a85cafaab720152e9427e\i386\asms\60\msft\vcrtl\vcrtl.cat
C:\04716a85cafaab720152e9427e\i386\asms\60\msft\vcrtl\vcrtl.man
C:\04716a85cafaab720152e9427e\i386\asms\60\msft\windows\common\controls\comctl32.dll
C:\04716a85cafaab720152e9427e\i386\asms\60\msft\windows\common\controls\controls.cat
C:\04716a85cafaab720152e9427e\i386\asms\60\msft\windows\common\controls\controls.man
C:\04716a85cafaab720152e9427e\i386\asms\60\policy\60\comctl\comctl.cat
C:\04716a85cafaab720152e9427e\i386\asms\60\policy\60\comctl\comctl.man
C:\04716a85cafaab720152e9427e\i386\asms\60\policy\msft\vcrtl\vcrtl.cat
C:\04716a85cafaab720152e9427e\i386\asms\60\policy\msft\vcrtl\vcrtl.man
C:\04716a85cafaab720152e9427e\i386\asms\70\msft\windows\mswincrt\msvcirt.dll
C:\04716a85cafaab720152e9427e\i386\asms\70\msft\windows\mswincrt\msvcrt.dll
C:\04716a85cafaab720152e9427e\i386\asms\70\msft\windows\mswincrt\mswincrt.cat
C:\04716a85cafaab720152e9427e\i386\asms\70\msft\windows\mswincrt\mswincrt.man
C:\04716a85cafaab720152e9427e\i386\asms\70\policy\msft\mswincrt\mswincrt.cat
C:\04716a85cafaab720152e9427e\i386\asms\70\policy\msft\mswincrt\mswincrt.man
C:\04716a85cafaab720152e9427e\i386\asp51.dl_
C:\04716a85cafaab720152e9427e\i386\aspnet_filter.dll
C:\04716a85cafaab720152e9427e\i386\aspnet_isapi.dll
C:\04716a85cafaab720152e9427e\i386\aspnet_perf.h
C:\04716a85cafaab720152e9427e\i386\aspnet_perf.ini
C:\04716a85cafaab720152e9427e\i386\aspnet_perf2.ini
C:\04716a85cafaab720152e9427e\i386\aspnet_regiis.exe
C:\04716a85cafaab720152e9427e\i386\aspnet_state.exe
C:\04716a85cafaab720152e9427e\i386\aspnet_wp.exe
C:\04716a85cafaab720152e9427e\i386\asr_fmt.ex_
C:\04716a85cafaab720152e9427e\i386\asycfilt.dl_
C:\04716a85cafaab720152e9427e\i386\asyncmac.sy_
C:\04716a85cafaab720152e9427e\i386\at.ex_
C:\04716a85cafaab720152e9427e\i386\atapi.sy_
C:\04716a85cafaab720152e9427e\i386\ati1btxx.sy_
C:\04716a85cafaab720152e9427e\i386\ati1mdxx.sy_
C:\04716a85cafaab720152e9427e\i386\ati1pdxx.sy_
C:\04716a85cafaab720152e9427e\i386\ati1raxx.sy_
C:\04716a85cafaab720152e9427e\i386\ati1rvxx.sy_
C:\04716a85cafaab720152e9427e\i386\ati1snxx.sy_
C:\04716a85cafaab720152e9427e\i386\ati1ttxx.sy_
C:\04716a85cafaab720152e9427e\i386\ati1tuxx.sy_
C:\04716a85cafaab720152e9427e\i386\ati1xbxx.sy_
C:\04716a85cafaab720152e9427e\i386\ati1xsxx.sy_
C:\04716a85cafaab720152e9427e\i386\ati1xwdm.in_
C:\04716a85cafaab720152e9427e\i386\ati2cqag.dl_
C:\04716a85cafaab720152e9427e\i386\ati2dvaa.dl_
C:\04716a85cafaab720152e9427e\i386\ati2dvag.dl_
C:\04716a85cafaab720152e9427e\i386\ati2mtaa.sy_
C:\04716a85cafaab720152e9427e\i386\ati2mtag.sy_
C:\04716a85cafaab720152e9427e\i386\ati3d1ag.dl_
C:\04716a85cafaab720152e9427e\i386\ati3d2ag.dl_
C:\04716a85cafaab720152e9427e\i386\ati3duag.dl_
C:\04716a85cafaab720152e9427e\i386\atiixpaa.in_
C:\04716a85cafaab720152e9427e\i386\atiixpag.in_
C:\04716a85cafaab720152e9427e\i386\atinbtxx.sy_
C:\04716a85cafaab720152e9427e\i386\atinmdxx.sy_
C:\04716a85cafaab720152e9427e\i386\atinpdxx.sy_
C:\04716a85cafaab720152e9427e\i386\atinraxx.sy_
C:\04716a85cafaab720152e9427e\i386\atinrvxx.sy_
C:\04716a85cafaab720152e9427e\i386\atinsnxx.sy_
C:\04716a85cafaab720152e9427e\i386\atinttxx.sy_
C:\04716a85cafaab720152e9427e\i386\atintuxx.sy_
C:\04716a85cafaab720152e9427e\i386\atinxbxx.sy_
C:\04716a85cafaab720152e9427e\i386\atinxsxx.sy_
C:\04716a85cafaab720152e9427e\i386\ativdaxx.ax_
C:\04716a85cafaab720152e9427e\i386\ativmc20.co_
C:\04716a85cafaab720152e9427e\i386\ativmvxx.ax_
C:\04716a85cafaab720152e9427e\i386\ativtmxx.dl_
C:\04716a85cafaab720152e9427e\i386\ativvaxx.dl_
C:\04716a85cafaab720152e9427e\i386\atixpwdm.in_
C:\04716a85cafaab720152e9427e\i386\atl.dl_
C:\04716a85cafaab720152e9427e\i386\atm.ch_
C:\04716a85cafaab720152e9427e\i386\atmadm.ex_
C:\04716a85cafaab720152e9427e\i386\atmarpc.sy_
C:\04716a85cafaab720152e9427e\i386\atmfd.dl_
C:\04716a85cafaab720152e9427e\i386\atmlane.sy_
C:\04716a85cafaab720152e9427e\i386\atmlib.dl_
C:\04716a85cafaab720152e9427e\i386\attrib.ex_
C:\04716a85cafaab720152e9427e\i386\atv01nt5.dl_
C:\04716a85cafaab720152e9427e\i386\atv02nt5.dl_
C:\04716a85cafaab720152e9427e\i386\atv04nt5.dl_
C:\04716a85cafaab720152e9427e\i386\atv06nt5.dl_
C:\04716a85cafaab720152e9427e\i386\atv10nt5.dl_
C:\04716a85cafaab720152e9427e\i386\au_plcy.ht_
C:\04716a85cafaab720152e9427e\i386\audiosrv.dl_
C:\04716a85cafaab720152e9427e\i386\auditusr.ex_
C:\04716a85cafaab720152e9427e\i386\ausrinfo.ht_
C:\04716a85cafaab720152e9427e\i386\author.dll
C:\04716a85cafaab720152e9427e\i386\author.exe
C:\04716a85cafaab720152e9427e\i386\authz.dl_
C:\04716a85cafaab720152e9427e\i386\autochk.exe
C:\04716a85cafaab720152e9427e\i386\autoconv.ex_
C:\04716a85cafaab720152e9427e\i386\autofmt.exe
C:\04716a85cafaab720152e9427e\i386\autolfn.ex_
C:\04716a85cafaab720152e9427e\i386\autoupdt.ht_
C:\04716a85cafaab720152e9427e\i386\avc.sy_
C:\04716a85cafaab720152e9427e\i386\avcstrm.sy_
C:\04716a85cafaab720152e9427e\i386\avifil32.dl_
C:\04716a85cafaab720152e9427e\i386\azroles.dl_
C:\04716a85cafaab720152e9427e\i386\backdown.jp_
C:\04716a85cafaab720152e9427e\i386\backoff.jp_
C:\04716a85cafaab720152e9427e\i386\backover.jp_
C:\04716a85cafaab720152e9427e\i386\backup.jp_
C:\04716a85cafaab720152e9427e\i386\badeula.ht_
C:\04716a85cafaab720152e9427e\i386\badpkey.ht_
C:\04716a85cafaab720152e9427e\i386\basecred.xs_
C:\04716a85cafaab720152e9427e\i386\baseeap.xs_
C:\04716a85cafaab720152e9427e\i386\baseeap0.xs_
C:\04716a85cafaab720152e9427e\i386\baseeap1.xs_
C:\04716a85cafaab720152e9427e\i386\basesrv.dl_
C:\04716a85cafaab720152e9427e\i386\batmeter.dl_
C:\04716a85cafaab720152e9427e\i386\batt.dl_
C:\04716a85cafaab720152e9427e\i386\battc.sy_
C:\04716a85cafaab720152e9427e\i386\bdaplgin.ax_
C:\04716a85cafaab720152e9427e\i386\bdasup.sy_
C:\04716a85cafaab720152e9427e\i386\beethov9.wm_
C:\04716a85cafaab720152e9427e\i386\bidispl.dl_
C:\04716a85cafaab720152e9427e\i386\bitsprx2.dl_
C:\04716a85cafaab720152e9427e\i386\bitsprx3.dl_
C:\04716a85cafaab720152e9427e\i386\bitsprx4.dl_
C:\04716a85cafaab720152e9427e\i386\bktr.gi_
C:\04716a85cafaab720152e9427e\i386\bktrh.gi_
C:\04716a85cafaab720152e9427e\i386\blackbox.dl_
C:\04716a85cafaab720152e9427e\i386\blank.txt
C:\04716a85cafaab720152e9427e\i386\blastcln.ex_
C:\04716a85cafaab720152e9427e\i386\blutooth.ch_
C:\04716a85cafaab720152e9427e\i386\bootcfg.ex_
C:\04716a85cafaab720152e9427e\i386\bridge.sy_
C:\04716a85cafaab720152e9427e\i386\browselc.dl_
C:\04716a85cafaab720152e9427e\i386\browser.dl_
C:\04716a85cafaab720152e9427e\i386\browseui.dl_
C:\04716a85cafaab720152e9427e\i386\browsewm.dl_
C:\04716a85cafaab720152e9427e\i386\bth.in_
C:\04716a85cafaab720152e9427e\i386\bthci.dl_
C:\04716a85cafaab720152e9427e\i386\bthenum.sy_
C:\04716a85cafaab720152e9427e\i386\bthmodem.sy_
C:\04716a85cafaab720152e9427e\i386\bthpan.in_
C:\04716a85cafaab720152e9427e\i386\bthpan.sy_
C:\04716a85cafaab720152e9427e\i386\bthport.sy_
C:\04716a85cafaab720152e9427e\i386\bthprint.in_
C:\04716a85cafaab720152e9427e\i386\bthprint.sy_
C:\04716a85cafaab720152e9427e\i386\bthprops.cp_
C:\04716a85cafaab720152e9427e\i386\bthserv.dl_
C:\04716a85cafaab720152e9427e\i386\bthspp.in_
C:\04716a85cafaab720152e9427e\i386\bthusb.sy_
C:\04716a85cafaab720152e9427e\i386\btn1.gi_
C:\04716a85cafaab720152e9427e\i386\btn2.gi_
C:\04716a85cafaab720152e9427e\i386\btn3.gi_
C:\04716a85cafaab720152e9427e\i386\btpanui.dl_
C:\04716a85cafaab720152e9427e\i386\bullet1.gi_
C:\04716a85cafaab720152e9427e\i386\bulzano.jp_
C:\04716a85cafaab720152e9427e\i386\bulzanom.jp_
C:\04716a85cafaab720152e9427e\i386\but1_dwn.gi_
C:\04716a85cafaab720152e9427e\i386\but1_idl.gi_
C:\04716a85cafaab720152e9427e\i386\but1_up.gi_
C:\04716a85cafaab720152e9427e\i386\but2_dwn.gi_
C:\04716a85cafaab720152e9427e\i386\but2_idl.gi_
C:\04716a85cafaab720152e9427e\i386\but2_up.gi_
C:\04716a85cafaab720152e9427e\i386\but3_dwn.gi_
C:\04716a85cafaab720152e9427e\i386\but3_idl.gi_
C:\04716a85cafaab720152e9427e\i386\but3_up.gi_
C:\04716a85cafaab720152e9427e\i386\but4_dwn.gi_
C:\04716a85cafaab720152e9427e\i386\but4_idl.gi_
C:\04716a85cafaab720152e9427e\i386\but4_up.gi_
C:\04716a85cafaab720152e9427e\i386\c_28603.nl_
C:\04716a85cafaab720152e9427e\i386\c_g18030.dl_
C:\04716a85cafaab720152e9427e\i386\cabinet.dll
C:\04716a85cafaab720152e9427e\i386\cabview.dl_
C:\04716a85cafaab720152e9427e\i386\cacls.ex_
C:\04716a85cafaab720152e9427e\i386\callcont.dl_
C:\04716a85cafaab720152e9427e\i386\camext30.dl_
C:\04716a85cafaab720152e9427e\i386\camocx.dl_
C:\04716a85cafaab720152e9427e\i386\capesnpn.dl_
C:\04716a85cafaab720152e9427e\i386\caspol.exe
C:\04716a85cafaab720152e9427e\i386\catsrv.dl_
C:\04716a85cafaab720152e9427e\i386\catsrvps.dl_
C:\04716a85cafaab720152e9427e\i386\catsrvut.dl_
C:\04716a85cafaab720152e9427e\i386\ccdecode.sy_
C:\04716a85cafaab720152e9427e\i386\cdfs.sy_
C:\04716a85cafaab720152e9427e\i386\cdfview.dl_
C:\04716a85cafaab720152e9427e\i386\cdm.dl_
C:\04716a85cafaab720152e9427e\i386\cdosys.dl_
C:\04716a85cafaab720152e9427e\i386\cdrom.sy_
C:\04716a85cafaab720152e9427e\i386\certcli.dl_
C:\04716a85cafaab720152e9427e\i386\certmgr.dl_
C:\04716a85cafaab720152e9427e\i386\certwiz.oc_
C:\04716a85cafaab720152e9427e\i386\cewmdm.dl_
C:\04716a85cafaab720152e9427e\i386\cfgbkend.dl_
C:\04716a85cafaab720152e9427e\i386\cfgmgr32.dl_
C:\04716a85cafaab720152e9427e\i386\cfgwiz.exe
C:\04716a85cafaab720152e9427e\i386\ch7xxnt5.dl_
C:\04716a85cafaab720152e9427e\i386\changer.sy_
C:\04716a85cafaab720152e9427e\i386\chimes.wa_
C:\04716a85cafaab720152e9427e\i386\chord.wa_
C:\04716a85cafaab720152e9427e\i386\cic.dl_
C:\04716a85cafaab720152e9427e\i386\cimwin32.dl_
C:\04716a85cafaab720152e9427e\i386\cimwin32.mf_
C:\04716a85cafaab720152e9427e\i386\cimwin32.mo_
C:\04716a85cafaab720152e9427e\i386\cinfo.xm_
C:\04716a85cafaab720152e9427e\i386\ciodm.dl_
C:\04716a85cafaab720152e9427e\i386\cipher.ex_
C:\04716a85cafaab720152e9427e\i386\cisvc.ex_
C:\04716a85cafaab720152e9427e\i386\classpnp.sy_
C:\04716a85cafaab720152e9427e\i386\clbcatex.dl_
C:\04716a85cafaab720152e9427e\i386\clbcatq.dl_
C:\04716a85cafaab720152e9427e\i386\cleanmgr.ex_
C:\04716a85cafaab720152e9427e\i386\cli.mo_
C:\04716a85cafaab720152e9427e\i386\clickerx.wa_
C:\04716a85cafaab720152e9427e\i386\clickhr.gi_
C:\04716a85cafaab720152e9427e\i386\clicking.gi_
C:\04716a85cafaab720152e9427e\i386\cliconfg.dl_
C:\04716a85cafaab720152e9427e\i386\cliconfg.ex_
C:\04716a85cafaab720152e9427e\i386\cliconfg.rl_
C:\04716a85cafaab720152e9427e\i386\cliegali.mf_
C:\04716a85cafaab720152e9427e\i386\cliegali.mo_
C:\04716a85cafaab720152e9427e\i386\clipbrd.ex_
C:\04716a85cafaab720152e9427e\i386\clipsrv.ex_
C:\04716a85cafaab720152e9427e\i386\cloapp.gi_
C:\04716a85cafaab720152e9427e\i386\cloapph.gi_
C:\04716a85cafaab720152e9427e\i386\clusapi.dl_
C:\04716a85cafaab720152e9427e\i386\cmbatt.sy_
C:\04716a85cafaab720152e9427e\i386\cmcfg32.dl_
C:\04716a85cafaab720152e9427e\i386\cmd.ex_
C:\04716a85cafaab720152e9427e\i386\cmdial32.dl_
C:\04716a85cafaab720152e9427e\i386\cmdl32.ex_
C:\04716a85cafaab720152e9427e\i386\cmmon32.ex_
C:\04716a85cafaab720152e9427e\i386\cmprops.dl_
C:\04716a85cafaab720152e9427e\i386\cmsetacl.dl_
C:\04716a85cafaab720152e9427e\i386\cmstp.ex_
C:\04716a85cafaab720152e9427e\i386\cmutil.dl_
C:\04716a85cafaab720152e9427e\i386\cnbjmon.dl_
C:\04716a85cafaab720152e9427e\i386\cnbjmon2.dl_
C:\04716a85cafaab720152e9427e\i386\cnfgprts.oc_
C:\04716a85cafaab720152e9427e\i386\cnncterr.ht_
C:\04716a85cafaab720152e9427e\i386\cnt.gi_
C:\04716a85cafaab720152e9427e\i386\cntd.gi_
C:\04716a85cafaab720152e9427e\i386\cnth.gi_
C:\04716a85cafaab720152e9427e\i386\coadmin.dl_
C:\04716a85cafaab720152e9427e\i386\cobramsg.dl_
C:\04716a85cafaab720152e9427e\i386\colbact.dl_
C:\04716a85cafaab720152e9427e\i386\comaddin.dl_
C:\04716a85cafaab720152e9427e\i386\comadmin.dl_
C:\04716a85cafaab720152e9427e\i386\comctl32.dl_
C:\04716a85cafaab720152e9427e\i386\comdlg32.dl_
C:\04716a85cafaab720152e9427e\i386\comexp.ch_
C:\04716a85cafaab720152e9427e\i386\comic.tt_
C:\04716a85cafaab720152e9427e\i386\comntwks.in_
C:\04716a85cafaab720152e9427e\i386\compact.wm_
C:\04716a85cafaab720152e9427e\i386\compatui.dl_
C:\04716a85cafaab720152e9427e\i386\compbatt.sy_
C:\04716a85cafaab720152e9427e\i386\compdata\drvmain.chm
C:\04716a85cafaab720152e9427e\i386\compdata\drvmain.inf
C:\04716a85cafaab720152e9427e\i386\compdata\krnlchk.htm
C:\04716a85cafaab720152e9427e\i386\compdata\krnlchk.txt
C:\04716a85cafaab720152e9427e\i386\compdata\nv_agp.htm
C:\04716a85cafaab720152e9427e\i386\compdata\nv_agp.txt
C:\04716a85cafaab720152e9427e\i386\compdata\powershell.htm
C:\04716a85cafaab720152e9427e\i386\compdata\powershell.txt
C:\04716a85cafaab720152e9427e\i386\compdata\rdpmui.htm
C:\04716a85cafaab720152e9427e\i386\compdata\rdpmui.txt
C:\04716a85cafaab720152e9427e\i386\compdata\sharedct.htm
C:\04716a85cafaab720152e9427e\i386\compdata\sharedct.txt
C:\04716a85cafaab720152e9427e\i386\compdata\wepos.htm
C:\04716a85cafaab720152e9427e\i386\compdata\wepos.txt
C:\04716a85cafaab720152e9427e\i386\compdata\winflp.htm
C:\04716a85cafaab720152e9427e\i386\compdata\winflp.txt
C:\04716a85cafaab720152e9427e\i386\compfilt.dl_
C:\04716a85cafaab720152e9427e\i386\compname.ht_
C:\04716a85cafaab720152e9427e\i386\compstui.dl_
C:\04716a85cafaab720152e9427e\i386\comrepl.dl_
C:\04716a85cafaab720152e9427e\i386\comrepl.ex_
C:\04716a85cafaab720152e9427e\i386\comrereg.ex_
C:\04716a85cafaab720152e9427e\i386\comres.dl_
C:\04716a85cafaab720152e9427e\i386\comsetup.dl_
C:\04716a85cafaab720152e9427e\i386\comsnap.dl_
C:\04716a85cafaab720152e9427e\i386\comsvcs.dl_
C:\04716a85cafaab720152e9427e\i386\comuid.dl_
C:\04716a85cafaab720152e9427e\i386\conf.ad_
C:\04716a85cafaab720152e9427e\i386\conf.ch_
C:\04716a85cafaab720152e9427e\i386\conf.ex_
C:\04716a85cafaab720152e9427e\i386\conf.hl_
C:\04716a85cafaab720152e9427e\i386\conf1.ch_
C:\04716a85cafaab720152e9427e\i386\confmrsl.dl_
C:\04716a85cafaab720152e9427e\i386\confmsp.dl_
C:\04716a85cafaab720152e9427e\i386\conime.ex_
C:\04716a85cafaab720152e9427e\i386\connect.cn_
C:\04716a85cafaab720152e9427e\i386\connect.hl_
C:\04716a85cafaab720152e9427e\i386\contents.ht_
C:\04716a85cafaab720152e9427e\i386\controls.cs_
C:\04716a85cafaab720152e9427e\i386\controls.js_
C:\04716a85cafaab720152e9427e\i386\copycd.wm_
C:\04716a85cafaab720152e9427e\i386\corperfmonext.dll
C:\04716a85cafaab720152e9427e\i386\corperfmonsymbols.ini
C:\04716a85cafaab720152e9427e\i386\corpol.dl_
C:\04716a85cafaab720152e9427e\i386\courtney.ac_
C:\04716a85cafaab720152e9427e\i386\credssp.dl_
C:\04716a85cafaab720152e9427e\i386\credui.dl_
C:\04716a85cafaab720152e9427e\i386\crusoe.sy_
C:\04716a85cafaab720152e9427e\i386\crypt32.dl_
C:\04716a85cafaab720152e9427e\i386\cryptdlg.dl_
C:\04716a85cafaab720152e9427e\i386\cryptdll.dl_
C:\04716a85cafaab720152e9427e\i386\cryptext.dl_
C:\04716a85cafaab720152e9427e\i386\cryptnet.dl_
C:\04716a85cafaab720152e9427e\i386\cryptsvc.dl_
C:\04716a85cafaab720152e9427e\i386\cryptui.dl_
C:\04716a85cafaab720152e9427e\i386\csc.exe
C:\04716a85cafaab720152e9427e\i386\cscdll.dl_
C:\04716a85cafaab720152e9427e\i386\cscomp.dll
C:\04716a85cafaab720152e9427e\i386\cscript.ex_
C:\04716a85cafaab720152e9427e\i386\cscript.mu_
C:\04716a85cafaab720152e9427e\i386\cscui.dl_
C:\04716a85cafaab720152e9427e\i386\csrsrv.dl_
C:\04716a85cafaab720152e9427e\i386\csrss.ex_
C:\04716a85cafaab720152e9427e\i386\csv.xs_
C:\04716a85cafaab720152e9427e\i386\ctfmon.ex_
C:\04716a85cafaab720152e9427e\i386\ctmasetp.dl_
C:\04716a85cafaab720152e9427e\i386\cu52178.nlp
C:\[u]0[/u]4716a85cafaab720152e9427e\i386\custsat.dl_
C:\[u]0[/u]4716a85cafaab720152e9427e\i386\cwrwdm.sy_
C:\[u]0[/u]4716a85cafaab720152e9427e\i386\cxthsfs2.ct_
C:\[u]0[/u]4716a85cafaab720152e9427e\i386\d3d8.dl_
C:\[u]0[/u]4716a85cafaab720152e9427e\i386\d3d8thk.dl_
C:\[u]0[/u]4716a85cafaab720152e9427e\i386\d3d9.dl_
C:\[u]0[/u]4716a85cafaab720152e9427e\i386\d3dim700.dl_
C:\[u]0[/u]4716a85cafaab720152e9427e\i386\danim.dl_
C:\[u]0[/u]4716a85cafaab720152e9427e\i386\dao360.dl_
C:\[u]0[/u]4716a85cafaab720152e9427e\i386\dataclen.dl_
C:\[u]0[/u]4716a85cafaab720152e9427e\i386\dataspec.xm_
C:\[u]0[/u]4716a85cafaab720152e9427e\i386\datetime.ch_
C:\[u]0[/u]4716a85cafaab720152e9427e\i386\datime.dl_
C:\[u]0[/u]4716a85cafaab720152e9427e\i386\davcdata.ex_
C:\[u]0[/u]4716a85cafaab720152e9427e\i386\davclnt.dl_
C:\[u]0[/u]4716a85cafaab720152e9427e\i386\daxctle.oc_
C:\[u]0[/u]4716a85cafaab720152e9427e\i386\dbghelp.dll
C:\[u]0[/u]4716a85cafaab720152e9427e\i386\dbmsrpcn.dl_
C:\[u]0[/u]4716a85cafaab720152e9427e\i386\dbnetlib.dl_
C:\[u]0[/u]4716a85cafaab720152e9427e\i386\dbnmpntw.dl_
C:\[u]0[/u]4716a85cafaab720152e9427e\i386\dcache.bi_
C:\[u]0[/u]4716a85cafaab720152e9427e\i386\dcap32.dl_
C:\[u]0[/u]4716a85cafaab720152e9427e\i386\dciman32.dl_
C:\[u]0[/u]4716a85cafaab720152e9427e\i386\dcomcnfg.ex_
C:\[u]0[/u]4716a85cafaab720152e9427e\i386\ddeshare.ex_
C:\[u]0[/u]4716a85cafaab720152e9427e\i386\ddraw.dl_
C:\[u]0[/u]4716a85cafaab720152e9427e\i386\ddrawex.dl_
C:\[u]0[/u]4716a85cafaab720152e9427e\i386\defrag.ex_
C:\[u]0[/u]4716a85cafaab720152e9427e\i386\desk.cp_
C:\[u]0[/u]4716a85cafaab720152e9427e\i386\desktop3.gi_
C:\[u]0[/u]4716a85cafaab720152e9427e\i386\devenum.dl_
C:\[u]0[/u]4716a85cafaab720152e9427e\i386\devmgr.dl_
C:\[u]0[/u]4716a85cafaab720152e9427e\i386\dfrgfat.ex_
C:\[u]0[/u]4716a85cafaab720152e9427e\i386\dfrgntfs.ex_
C:\[u]0[/u]4716a85cafaab720152e9427e\i386\dfrgsnap.dl_
C:\[u]0[/u]4716a85cafaab720152e9427e\i386\dfrgui.dl_
C:\[u]0[/u]4716a85cafaab720152e9427e\i386\dfsshlex.dl_
C:\[u]0[/u]4716a85cafaab720152e9427e\i386\dgnet.dl_
C:\[u]0[/u]4716a85cafaab720152e9427e\i386\dhcpcsvc.dl_
C:\[u]0[/u]4716a85cafaab720152e9427e\i386\dhcpmon.dl_
C:\[u]0[/u]4716a85cafaab720152e9427e\i386\dhcpqec.dl_
C:\[u]0[/u]4716a85cafaab720152e9427e\i386\dhtmled.oc_
C:\[u]0[/u]4716a85cafaab720152e9427e\i386\dialer.ex_
C:\[u]0[/u]4716a85cafaab720152e9427e\i386\dialmgr.js_
C:\[u]0[/u]4716a85cafaab720152e9427e\i386\dialtone.gi_
C:\[u]0[/u]4716a85cafaab720152e9427e\i386\dialtone.ht_
C:\[u]0[/u]4716a85cafaab720152e9427e\i386\dialup.gi_
C:\[u]0[/u]4716a85cafaab720152e9427e\i386\dialup.ht_
C:\[u]0[/u]4716a85cafaab720152e9427e\i386\diantz.ex_
C:\[u]0[/u]4716a85cafaab720152e9427e\i386\digcore.ex_
C:\[u]0[/u]4716a85cafaab720152e9427e\i386\digest.dl_
C:\[u]0[/u]4716a85cafaab720152e9427e\i386\digopt.ms_
C:\[u]0[/u]4716a85cafaab720152e9427e\i386\digreqex.ms_
C:\[u]0[/u]4716a85cafaab720152e9427e\i386\dimsntfy.dl_
C:\[u]0[/u]4716a85cafaab720152e9427e\i386\dimsroam.dl_
C:\[u]0[/u]4716a85cafaab720152e9427e\i386\ding.wa_
C:\[u]0[/u]4716a85cafaab720152e9427e\i386\dinput.dl_
C:\[u]0[/u]4716a85cafaab720152e9427e\i386\dinput8.dl_
C:\[u]0[/u]4716a85cafaab720152e9427e\i386\directdb.dl_
C:\[u]0[/u]4716a85cafaab720152e9427e\i386\disk.sy_
C:\[u]0[/u]4716a85cafaab720152e9427e\i386\diskcopy.dl_
C:\[u]0[/u]4716a85cafaab720152e9427e\i386\diskdump.sy_
C:\[u]0[/u]4716a85cafaab720152e9427e\i386\diskpart.ex_
C:\[u]0[/u]4716a85cafaab720152e9427e\i386\dispex.dl_
C:\[u]0[/u]4716a85cafaab720152e9427e\i386\dlimport.ex_
C:\[u]0[/u]4716a85cafaab720152e9427e\i386\dllhost.ex_
C:\[u]0[/u]4716a85cafaab720152e9427e\i386\dlttape.sy_
C:\[u]0[/u]4716a85cafaab720152e9427e\i386\dmadmin.ex_
C:\[u]0[/u]4716a85cafaab720152e9427e\i386\dmband.dl_
C:\[u]0[/u]4716a85cafaab720152e9427e\i386\dmboot.sy_
C:\[u]0[/u]4716a85cafaab720152e9427e\i386\dmcompos.dl_
C:\[u]0[/u]4716a85cafaab720152e9427e\i386\dmdlgs.dl_
C:\[u]0[/u]4716a85cafaab720152e9427e\i386\dmdskmgr.dl_
C:\[u]0[/u]4716a85cafaab720152e9427e\i386\dmime.dl_
C:\[u]0[/u]4716a85cafaab720152e9427e\i386\dmio.sy_
C:\[u]0[/u]4716a85cafaab720152e9427e\i386\dmloader.dl_
C:\[u]0[/u]4716a85cafaab720152e9427e\i386\dmremote.ex_
C:\[u]0[/u]4716a85cafaab720152e9427e\i386\dmscript.dl_
C:\[u]0[/u]4716a85cafaab720152e9427e\i386\dmserver.dl_
C:\[u]0[/u]4716a85cafaab720152e9427e\i386\dmstyle.dl_
C:\[u]0[/u]4716a85cafaab720152e9427e\i386\dmsynth.dl_
C:\[u]0[/u]4716a85cafaab720152e9427e\i386\dmusic.dl_
C:\[u]0[/u]4716a85cafaab720152e9427e\i386\dmusic.sy_
C:\[u]0[/u]4716a85cafaab720152e9427e\i386\dmutil.dl_
C:\[u]0[/u]4716a85cafaab720152e9427e\i386\dnsapi.dl_
C:\[u]0[/u]4716a85cafaab720152e9427e\i386\dnsrslvr.dl_
C:\[u]0[/u]4716a85cafaab720152e9427e\i386\docprop2.dl_
C:\[u]0[/u]4716a85cafaab720152e9427e\i386\dosx.ex_
C:\[u]0[/u]4716a85cafaab720152e9427e\i386\dot3api.dl_
C:\[u]0[/u]4716a85cafaab720152e9427e\i386\dot3cfg.dl_
C:\[u]0[/u]4716a85cafaab720152e9427e\i386\dot3clnt.dl_
C:\[u]0[/u]4716a85cafaab720152e9427e\i386\dot3dlg.dl_
C:\[u]0[/u]4716a85cafaab720152e9427e\i386\dot3msm.dl_
C:\[u]0[/u]4716a85cafaab720152e9427e\i386\dot3svc.dl_
C:\[u]0[/u]4716a85cafaab720152e9427e\i386\dot3ui.dl_
C:\[u]0[/u]4716a85cafaab720152e9427e\i386\dot4.sy_
C:\[u]0[/u]4716a85cafaab720152e9427e\i386\dplaysvr.ex_
C:\[u]0[/u]4716a85cafaab720152e9427e\i386\dplayx.dl_
C:\[u]0[/u]4716a85cafaab720152e9427e\i386\dpmodemx.dl_
C:\[u]0[/u]4716a85cafaab720152e9427e\i386\dpnaddr.dl_
C:\[u]0[/u]4716a85cafaab720152e9427e\i386\dpnet.dl_
C:\[u]0[/u]4716a85cafaab720152e9427e\i386\dpnhpast.dl_
C:\[u]0[/u]4716a85cafaab720152e9427e\i386\dpnhupnp.dl_
C:\[u]0[/u]4716a85cafaab720152e9427e\i386\dpnlobby.dl_
C:\[u]0[/u]4716a85cafaab720152e9427e\i386\dpnsvr.ex_
C:\[u]0[/u]4716a85cafaab720152e9427e\i386\dpvacm.dl_
C:\[u]0[/u]4716a85cafaab720152e9427e\i386\dpvoice.dl_
C:\[u]0[/u]4716a85cafaab720152e9427e\i386\dpvsetup.ex_
C:\[u]0[/u]4716a85cafaab720152e9427e\i386\dpvvox.dl_
C:\[u]0[/u]4716a85cafaab720152e9427e\i386\dpwsockx.dl_
C:\[u]0[/u]4716a85cafaab720152e9427e\i386\drdyisp.ht_
C:\[u]0[/u]4716a85cafaab720152e9427e\i386\drdymig.ht_
C:\[u]0[/u]4716a85cafaab720152e9427e\i386\drdyoem.ht_
C:\[u]0[/u]4716a85cafaab720152e9427e\i386\drdyref.ht_
C:\[u]0[/u]4716a85cafaab720152e9427e\i386\drm.in_
C:\[u]0[/u]4716a85cafaab720152e9427e\i386\drmclien.dl_
C:\[u]0[/u]4716a85cafaab720152e9427e\i386\drmk.sy_
C:\[u]0[/u]4716a85cafaab720152e9427e\i386\drmkaud.sy_
C:\[u]0[/u]4716a85cafaab720152e9427e\i386\drmstor.dl_
C:\[u]0[/u]4716a85cafaab720152e9427e\i386\drmv2clt.dl_
C:\[u]0[/u]4716a85cafaab720152e9427e\i386\drprov.dl_
C:\[u]0[/u]4716a85cafaab720152e9427e\i386\drvmain.sdb
C:\[u]0[/u]4716a85cafaab720152e9427e\i386\drvqry.ex_
C:\[u]0[/u]4716a85cafaab720152e9427e\i386\drw\dwwin.exe
C:\[u]0[/u]4716a85cafaab720152e9427e\i386\ds16gt.dl_
C:\[u]0[/u]4716a85cafaab720152e9427e\i386\ds32gt.dl_
C:\[u]0[/u]4716a85cafaab720152e9427e\i386\dsdmo.dl_
C:\[u]0[/u]4716a85cafaab720152e9427e\i386\dsdmoprp.dl_
C:\[u]0[/u]4716a85cafaab720152e9427e\i386\dshowext.ax_
C:\[u]0[/u]4716a85cafaab720152e9427e\i386\dskquop.ch_
C:\[u]0[/u]4716a85cafaab720152e9427e\i386\dskquota.dl_
C:\[u]0[/u]4716a85cafaab720152e9427e\i386\dskquoui.dl_
C:\[u]0[/u]4716a85cafaab720152e9427e\i386\dsl_a.ht_
C:\[u]0[/u]4716a85cafaab720152e9427e\i386\dsl_b.ht_
C:\[u]0[/u]4716a85cafaab720152e9427e\i386\dslmain.ht_
C:\[u]0[/u]4716a85cafaab720152e9427e\i386\dslmain.js_
C:\[u]0[/u]4716a85cafaab720152e9427e\i386\dsound.dl_
C:\[u]0[/u]4716a85cafaab720152e9427e\i386\dsound3d.dl_
C:\[u]0[/u]4716a85cafaab720152e9427e\i386\dsprop.dl_
C:\[u]0[/u]4716a85cafaab720152e9427e\i386\dsprpres.dl_
C:\[u]0[/u]4716a85cafaab720152e9427e\i386\dsquery.dl_
C:\[u]0[/u]4716a85cafaab720152e9427e\i386\dssec.dl_
C:\[u]0[/u]4716a85cafaab720152e9427e\i386\dssenh.dl_
C:\[u]0[/u]4716a85cafaab720152e9427e\i386\dsuiext.dl_
C:\[u]0[/u]4716a85cafaab720152e9427e\i386\dswave.dl_
C:\[u]0[/u]4716a85cafaab720152e9427e\i386\dtcntwks.in_
C:\[u]0[/u]4716a85cafaab720152e9427e\i386\dtiwait.ht_
C:\[u]0[/u]4716a85cafaab720152e9427e\i386\dtsgnup.ht_
C:\[u]0[/u]4716a85cafaab720152e9427e\i386\dumprep.ex_
C:\[u]0[/u]4716a85cafaab720152e9427e\i386\duser.dl_
C:\[u]0[/u]4716a85cafaab720152e9427e\i386\dvdupgrd.ex_
C:\[u]0[/u]4716a85cafaab720152e9427e\i386\dwwin.ex_
C:\[u]0[/u]4716a85cafaab720152e9427e\i386\dx7vb.dl_
C:\[u]0[/u]4716a85cafaab720152e9427e\i386\dx8vb.dl_
C:\[u]0[/u]4716a85cafaab720152e9427e\i386\dxdiag.ch_
C:\[u]0[/u]4716a85cafaab720152e9427e\i386\dxdiag.ex_
C:\[u]0[/u]4716a85cafaab720152e9427e\i386\dxdiagn.dl_
C:\[u]0[/u]4716a85cafaab720152e9427e\i386\dxg.sy_
C:\[u]0[/u]4716a85cafaab720152e9427e\i386\dxmasf.dl_
C:\[u]0[/u]4716a85cafaab720152e9427e\i386\dxtmsft.dl_
C:\[u]0[/u]4716a85cafaab720152e9427e\i386\dxtrans.dl_
C:\[u]0[/u]4716a85cafaab720152e9427e\i386\eapcom.xs_
C:\[u]0[/u]4716a85cafaab720152e9427e\i386\eapcon1.xs_
C:\[u]0[/u]4716a85cafaab720152e9427e\i386\eapconf.xs_
C:\[u]0[/u]4716a85cafaab720152e9427e\i386\eapcred.xs_
C:\[u]0[/u]4716a85cafaab720152e9427e\i386\eapgen.xs_
C:\[u]0[/u]4716a85cafaab720152e9427e\i386\eapolqec.dl_
C:\[u]0[/u]4716a85cafaab720152e9427e\i386\eapp3hst.dl_
C:\[u]0[/u]4716a85cafaab720152e9427e\i386\eappcfg.dl_
C:\[u]0[/u]4716a85cafaab720152e9427e\i386\eappgnui.dl_
C:\[u]0[/u]4716a85cafaab720152e9427e\i386\eapphost.dl_
C:\[u]0[/u]4716a85cafaab720152e9427e\i386\eappprxy.dl_
C:\[u]0[/u]4716a85cafaab720152e9427e\i386\eapqec.dl_
C:\[u]0[/u]4716a85cafaab720152e9427e\i386\eapsvc.dl_
C:\[u]0[/u]4716a85cafaab720152e9427e\i386\eaptls1.xs_
C:\[u]0[/u]4716a85cafaab720152e9427e\i386\eaptlsv1.xs_
C:\[u]0[/u]4716a85cafaab720152e9427e\i386\eapuser1.xs_
C:\[u]0[/u]4716a85cafaab720152e9427e\i386\earl.ac_
C:\[u]0[/u]4716a85cafaab720152e9427e\i386\ediskeer.dll
C:\[u]0[/u]4716a85cafaab720152e9427e\i386\efsadu.dl_
C:\[u]0[/u]4716a85cafaab720152e9427e\i386\els.dl_
C:\[u]0[/u]4716a85cafaab720152e9427e\i386\empty.cat
C:\[u]0[/u]4716a85cafaab720152e9427e\i386\empty.txt
C:\[u]0[/u]4716a85cafaab720152e9427e\i386\encapi.dl_
C:\[u]0[/u]4716a85cafaab720152e9427e\i386\encdec.dl_
C:\[u]0[/u]4716a85cafaab720152e9427e\i386\ep9res.dl_
C:\[u]0[/u]4716a85cafaab720152e9427e\i386\epcl5res.dl_
C:\[u]0[/u]4716a85cafaab720152e9427e\i386\epn1600.gp_
C:\[u]0[/u]4716a85cafaab720152e9427e\i386\error.js_
C:\[u]0[/u]4716a85cafaab720152e9427e\i386\ersvc.dl_
C:\[u]0[/u]4716a85cafaab720152e9427e\i386\es.dl_
C:\[u]0[/u]4716a85cafaab720152e9427e\i386\esent.dl_
C:\[u]0[/u]4716a85cafaab720152e9427e\i386\esscli.dl_
C:\[u]0[/u]4716a85cafaab720152e9427e\i386\essm2e.sy_
C:\[u]0[/u]4716a85cafaab720152e9427e\i386\eudcedit.ex_
C:\[u]0[/u]4716a85cafaab720152e9427e\i386\evcon.ch_
C:\[u]0[/u]4716a85cafaab720152e9427e\i386\evcreate.ex_
C:\[u]0[/u]4716a85cafaab720152e9427e\i386\eventlog.dl_
C:\[u]0[/u]4716a85cafaab720152e9427e\i386\eventlogmessages.dll
C:\[u]0[/u]4716a85cafaab720152e9427e\i386\events.js_
C:\[u]0[/u]4716a85cafaab720152e9427e\i386\evntagnt.dl_
C:\[u]0[/u]4716a85cafaab720152e9427e\i386\evntcmd.ex_
C:\[u]0[/u]4716a85cafaab720152e9427e\i386\evntrprv.dl_
C:\[u]0[/u]4716a85cafaab720152e9427e\i386\evntwin.ex_
C:\[u]0[/u]4716a85cafaab720152e9427e\i386\evtgprov.dl_
C:\[u]0[/u]4716a85cafaab720152e9427e\i386\evtgprov.mo_
C:\[u]0[/u]4716a85cafaab720152e9427e\i386\evtrig.ex_
C:\[u]0[/u]4716a85cafaab720152e9427e\i386\explorer.ex_
C:\[u]0[/u]4716a85cafaab720152e9427e\i386\expsrv.dl_
C:\[u]0[/u]4716a85cafaab720152e9427e\i386\exstrace.dl_
C:\[u]0[/u]4716a85cafaab720152e9427e\i386\extmgr.dl_
C:\[u]0[/u]4716a85cafaab720152e9427e\i386\extrac32.ex_
C:\[u]0[/u]4716a85cafaab720152e9427e\i386\exts.dll
C:\[u]0[/u]4716a85cafaab720152e9427e\i386\f3ahvoas.dl_
C:\[u]0[/u]4716a85cafaab720152e9427e\i386\faq.htm
C:\[u]0[/u]4716a85cafaab720152e9427e\i386\fastfat.sy_
C:\[u]0[/u]4716a85cafaab720152e9427e\i386\fastprox.dl_
C:\[u]0[/u]4716a85cafaab720152e9427e\i386\faultrep.dl_
C:\[u]0[/u]4716a85cafaab720152e9427e\i386\faxpatch.exe
C:\[u]0[/u]4716a85cafaab720152e9427e\i386\fdc.sy_
C:\[u]0[/u]4716a85cafaab720152e9427e\i386\fde.dl_
C:\[u]0[/u]4716a85cafaab720152e9427e\i386\fdeploy.dl_
C:\[u]0[/u]4716a85cafaab720152e9427e\i386\feclient.dl_
C:\[u]0[/u]4716a85cafaab720152e9427e\i386\file_srv.ch_
C:\[u]0[/u]4716a85cafaab720152e9427e\i386\filelist.xm_
C:\[u]0[/u]4716a85cafaab720152e9427e\i386\filemgmt.dl_
C:\[u]0[/u]4716a85cafaab720152e9427e\i386\filters.xm_
C:\[u]0[/u]4716a85cafaab720152e9427e\i386\findstr.ex_
C:\[u]0[/u]4716a85cafaab720152e9427e\i386\fini.ht_
C:\[u]0[/u]4716a85cafaab720152e9427e\i386\fips.sy_
C:\[u]0[/u]4716a85cafaab720152e9427e\i386\firewall.cp_
C:\[u]0[/u]4716a85cafaab720152e9427e\i386\flash.oc_
C:\[u]0[/u]4716a85cafaab720152e9427e\i386\fldrclnr.dl_
C:\[u]0[/u]4716a85cafaab720152e9427e\i386\flpydisk.sy_
C:\[u]0[/u]4716a85cafaab720152e9427e\i386\fltlib.dl_
C:\[u]0[/u]4716a85cafaab720152e9427e\i386\fltmc.ex_
C:\[u]0[/u]4716a85cafaab720152e9427e\i386\fltmgr.sy_
C:\[u]0[/u]4716a85cafaab720152e9427e\i386\fontext.dl_
C:\[u]0[/u]4716a85cafaab720152e9427e\i386\fontsub.dl_
C:\[u]0[/u]4716a85cafaab720152e9427e\i386\fontview.ex_
C:\[u]0[/u]4716a85cafaab720152e9427e\i386\forcedos.ex_
C:\[u]0[/u]4716a85cafaab720152e9427e\i386\forehe.sy_
C:\[u]0[/u]4716a85cafaab720152e9427e\i386\format.co_
C:\[u]0[/u]4716a85cafaab720152e9427e\i386\fp4.ca_
C:\[u]0[/u]4716a85cafaab720152e9427e\i386\fp40ext.cab
C:\[u]0[/u]4716a85cafaab720152e9427e\i386\fp40ext.dl_
C:\[u]0[/u]4716a85cafaab720152e9427e\i386\fp40ext.in_
C:\[u]0[/u]4716a85cafaab720152e9427e\i386\fp4amsft.dll
C:\[u]0[/u]4716a85cafaab720152e9427e\i386\fp4anscp.dll
C:\[u]0[/u]4716a85cafaab720152e9427e\i386\fp4apws.dll
C:\[u]0[/u]4716a85cafaab720152e9427e\i386\fp4areg.dll
C:\[u]0[/u]4716a85cafaab720152e9427e\i386\fp4atxt.dll
C:\[u]0[/u]4716a85cafaab720152e9427e\i386\fp4autl.dll
C:\[u]0[/u]4716a85cafaab720152e9427e\i386\fp4avnb.dll
C:\[u]0[/u]4716a85cafaab720152e9427e\i386\fp4avss.dll
C:\[u]0[/u]4716a85cafaab720152e9427e\i386\fp4awebs.dll
C:\[u]0[/u]4716a85cafaab720152e9427e\i386\fp4awel.dll
C:\[u]0[/u]4716a85cafaab720152e9427e\i386\fp98sadm.exe
C:\[u]0[/u]4716a85cafaab720152e9427e\i386\fp98swin.exe
C:\[u]0[/u]4716a85cafaab720152e9427e\i386\fpadmcgi.exe
C:\[u]0[/u]4716a85cafaab720152e9427e\i386\fpadmdll.dll
C:\[u]0[/u]4716a85cafaab720152e9427e\i386\fpcount.exe
C:\[u]0[/u]4716a85cafaab720152e9427e\i386\fpencode.dll
C:\[u]0[/u]4716a85cafaab720152e9427e\i386\fpexedll.dll
C:\[u]0[/u]4716a85cafaab720152e9427e\i386\fpmmc.dll
C:\[u]0[/u]4716a85cafaab720152e9427e\i386\fpmmcsat.dll
C:\[u]0[/u]4716a85cafaab720152e9427e\i386\fpremadm.exe
C:\[u]0[/u]4716a85cafaab720152e9427e\i386\fpsrvadm.exe
C:\[u]0[/u]4716a85cafaab720152e9427e\i386\framebuf.dl_
C:\[u]0[/u]4716a85cafaab720152e9427e\i386\framedyn.dl_
C:\[u]0[/u]4716a85cafaab720152e9427e\i386\fsquirt.ex_
C:\[u]0[/u]4716a85cafaab720152e9427e\i386\ftp.ex_
C:\[u]0[/u]4716a85cafaab720152e9427e\i386\ftpmib.dl_
C:\[u]0[/u]4716a85cafaab720152e9427e\i386\ftpsv251.dl_
C:\[u]0[/u]4716a85cafaab720152e9427e\i386\fusion.dll
C:\[u]0[/u]4716a85cafaab720152e9427e\i386\fwcfg.dl_
C:\[u]0[/u]4716a85cafaab720152e9427e\i386\fxsapi.dl_
C:\[u]0[/u]4716a85cafaab720152e9427e\i386\fxsclnt.ex_
C:\[u]0[/u]4716a85cafaab720152e9427e\i386\fxscom.dl_
C:\[u]0[/u]4716a85cafaab720152e9427e\i386\fxscomex.dl_
C:\[u]0[/u]4716a85cafaab720152e9427e\i386\fxscover.ex_
C:\[u]0[/u]4716a85cafaab720152e9427e\i386\fxsdrv.dl_
C:\[u]0[/u]4716a85cafaab720152e9427e\i386\fxsevent.dl_
C:\[u]0[/u]4716a85cafaab720152e9427e\i386\fxsext32.dl_
C:\[u]0[/u]4716a85cafaab720152e9427e\i386\fxsmon.dl_
C:\[u]0[/u]4716a85cafaab720152e9427e\i386\fxsocm.dl_
C:\[u]0[/u]4716a85cafaab720152e9427e\i386\fxsocm.in_
C:\[u]0[/u]4716a85cafaab720152e9427e\i386\fxsperf.dl_
C:\[u]0[/u]4716a85cafaab720152e9427e\i386\fxsres.dl_
C:\[u]0[/u]4716a85cafaab720152e9427e\i386\fxsst.dl_
C:\[u]0[/u]4716a85cafaab720152e9427e\i386\fxssvc.ex_
C:\[u]0[/u]4716a85cafaab720152e9427e\i386\fxst30.dl_
C:\[u]0[/u]4716a85cafaab720152e9427e\i386\fxstiff.dl_
C:\[u]0[/u]4716a85cafaab720152e9427e\i386\fxsui.dl_
C:\[u]0[/u]4716a85cafaab720152e9427e\i386\fxswzrd.dl_
C:\[u]0[/u]4716a85cafaab720152e9427e\i386\fxsxp32.dl_
C:\[u]0[/u]4716a85cafaab720152e9427e\i386\g400.in_
C:\[u]0[/u]4716a85cafaab720152e9427e\i386\gagp30kx.sy_
C:\[u]0[/u]4716a85cafaab720152e9427e\i386\gameenum.sy_
C:\[u]0[/u]4716a85cafaab720152e9427e\i386\gckernel.sy_
C:\[u]0[/u]4716a85cafaab720152e9427e\i386\gdi32.dl_
C:\[u]0[/u]4716a85cafaab720152e9427e\i386\georgia.tt_
C:\[u]0[/u]4716a85cafaab720152e9427e\i386\getmac.ex_
C:\[u]0[/u]4716a85cafaab720152e9427e\i386\glu32.dl_
C:\[u]0[/u]4716a85cafaab720152e9427e\i386\gpedit.dl_
C:\[u]0[/u]4716a85cafaab720152e9427e\i386\gpkcsp.dl_
C:\[u]0[/u]4716a85cafaab720152e9427e\i386\gpkrsrc.dl_
C:\[u]0[/u]4716a85cafaab720152e9427e\i386\gprslt.ex_
C:\[u]0[/u]4716a85cafaab720152e9427e\i386\gptext.dl_
C:\[u]0[/u]4716a85cafaab720152e9427e\i386\greenshd.gi_
C:\[u]0[/u]4716a85cafaab720152e9427e\i386\grn_btn.gi_
C:\[u]0[/u]4716a85cafaab720152e9427e\i386\grpconv.ex_
C:\[u]0[/u]4716a85cafaab720152e9427e\i386\grserial.sy_
C:\[u]0[/u]4716a85cafaab720152e9427e\i386\guitrn.dl_
C:\[u]0[/u]4716a85cafaab720152e9427e\i386\guitrna.dl_
C:\[u]0[/u]4716a85cafaab720152e9427e\i386\gzip.dl_
C:\[u]0[/u]4716a85cafaab720152e9427e\i386\h323.ts_
C:\[u]0[/u]4716a85cafaab720152e9427e\i386\h323cc.dl_
C:\[u]0[/u]4716a85cafaab720152e9427e\i386\h323msp.dl_
C:\[u]0[/u]4716a85cafaab720152e9427e\i386\hal.dl_
C:\[u]0[/u]4716a85cafaab720152e9427e\i386\halaacpi.dl_
C:\[u]0[/u]4716a85cafaab720152e9427e\i386\halacpi.dl_
C:\[u]0[/u]4716a85cafaab720152e9427e\i386\halapic.dl_
C:\[u]0[/u]4716a85cafaab720152e9427e\i386\halmacpi.dl_
C:\[u]0[/u]4716a85cafaab720152e9427e\i386\halmps.dl_
C:\[u]0[/u]4716a85cafaab720152e9427e\i386\halsp.dl_
C:\[u]0[/u]4716a85cafaab720152e9427e\i386\hand1.gi_
C:\[u]0[/u]4716a85cafaab720152e9427e\i386\hand2.gi_
C:\[u]0[/u]4716a85cafaab720152e9427e\i386\hardware.ch_
C:\[u]0[/u]4716a85cafaab720152e9427e\i386\hardware.hl_
C:\[u]0[/u]4716a85cafaab720152e9427e\i386\hccoin.dl_
C:\[u]0[/u]4716a85cafaab720152e9427e\i386\hdaudbus.in_
C:\[u]0[/u]4716a85cafaab720152e9427e\i386\hdaudbus.sy_
C:\[u]0[/u]4716a85cafaab720152e9427e\i386\hdwwiz.cp_
C:\[u]0[/u]4716a85cafaab720152e9427e\i386\heidelb.jp_
C:\[u]0[/u]4716a85cafaab720152e9427e\i386\heidelbm.jp_
C:\[u]0[/u]4716a85cafaab720152e9427e\i386\help.ex_
C:\[u]0[/u]4716a85cafaab720152e9427e\i386\helpctr.ex_
C:\[u]0[/u]4716a85cafaab720152e9427e\i386\helpsvc.ex_
C:\[u]0[/u]4716a85cafaab720152e9427e\i386\hform.xs_
C:\[u]0[/u]4716a85cafaab720152e9427e\i386\hh.ex_
C:\[u]0[/u]4716a85cafaab720152e9427e\i386\hhctrl.oc_
  • 0

#6
moshelby

moshelby

    New Member

  • Topic Starter
  • Member
  • Pip
  • 7 posts
combofix log cont'd:
C:\04716a85cafaab720152e9427e\i386\hhsetup.dl_
C:\04716a85cafaab720152e9427e\i386\hid.dl_
C:\04716a85cafaab720152e9427e\i386\hidbatt.sy_
C:\04716a85cafaab720152e9427e\i386\hidbth.in_
C:\04716a85cafaab720152e9427e\i386\hidbth.sy_
C:\04716a85cafaab720152e9427e\i386\hidclass.sy_
C:\04716a85cafaab720152e9427e\i386\hidir.sy_
C:\04716a85cafaab720152e9427e\i386\hidparse.sy_
C:\04716a85cafaab720152e9427e\i386\hidphone.ts_
C:\04716a85cafaab720152e9427e\i386\hidserv.dl_
C:\04716a85cafaab720152e9427e\i386\hidusb.sy_
C:\04716a85cafaab720152e9427e\i386\hlink.dl_
C:\04716a85cafaab720152e9427e\i386\hmmapi.dl_
C:\04716a85cafaab720152e9427e\i386\hndshake.ht_
C:\04716a85cafaab720152e9427e\i386\hnetcfg.dl_
C:\04716a85cafaab720152e9427e\i386\hnetwiz.dl_
C:\04716a85cafaab720152e9427e\i386\hnwprmpt.ht_
C:\04716a85cafaab720152e9427e\i386\homepage.in_
C:\04716a85cafaab720152e9427e\i386\hostmib.dl_
C:\04716a85cafaab720152e9427e\i386\hotplug.dl_
C:\04716a85cafaab720152e9427e\i386\hp5000_7.pp_
C:\04716a85cafaab720152e9427e\i386\hpcjrr.dl_
C:\04716a85cafaab720152e9427e\i386\hpcjrrps.dl_
C:\04716a85cafaab720152e9427e\i386\hpfud50.dl_
C:\04716a85cafaab720152e9427e\i386\hpwm5250.gp_
C:\04716a85cafaab720152e9427e\i386\hschelpp.ch_
C:\04716a85cafaab720152e9427e\i386\hschelpw.ch_
C:\04716a85cafaab720152e9427e\i386\hscupd.ex_
C:\04716a85cafaab720152e9427e\i386\hsfbs2s2.sy_
C:\04716a85cafaab720152e9427e\i386\hsfcisp2.dl_
C:\04716a85cafaab720152e9427e\i386\hsfcxts2.sy_
C:\04716a85cafaab720152e9427e\i386\hsfdpsp2.sy_
C:\04716a85cafaab720152e9427e\i386\htable.xs_
C:\04716a85cafaab720152e9427e\i386\html.ie_
C:\04716a85cafaab720152e9427e\i386\html32.cn_
C:\04716a85cafaab720152e9427e\i386\http.sy_
C:\04716a85cafaab720152e9427e\i386\httpapi.dl_
C:\04716a85cafaab720152e9427e\i386\httpext.dl_
C:\04716a85cafaab720152e9427e\i386\httpmb51.dl_
C:\04716a85cafaab720152e9427e\i386\httpod51.dl_
C:\04716a85cafaab720152e9427e\i386\htui.dl_
C:\04716a85cafaab720152e9427e\i386\hypertrm.dl_
C:\04716a85cafaab720152e9427e\i386\i2omgmt.sy_
C:\04716a85cafaab720152e9427e\i386\i2omp.sy_
C:\04716a85cafaab720152e9427e\i386\i8042prt.sy_
C:\04716a85cafaab720152e9427e\i386\i81xdnt5.dl_
C:\04716a85cafaab720152e9427e\i386\i81xnt5.in_
C:\04716a85cafaab720152e9427e\i386\i81xnt5.sy_
C:\04716a85cafaab720152e9427e\i386\iac25_32.ax_
C:\04716a85cafaab720152e9427e\i386\iasrad.dl_
C:\04716a85cafaab720152e9427e\i386\ic\accessor.in_
C:\04716a85cafaab720152e9427e\i386\ic\acpi.in_
C:\04716a85cafaab720152e9427e\i386\ic\agp.in_
C:\04716a85cafaab720152e9427e\i386\ic\au.in_
C:\04716a85cafaab720152e9427e\i386\ic\battery.in_
C:\04716a85cafaab720152e9427e\i386\ic\bda.in_
C:\04716a85cafaab720152e9427e\i386\ic\biosinfo.inf
C:\04716a85cafaab720152e9427e\i386\ic\ccdecode.in_
C:\04716a85cafaab720152e9427e\i386\ic\cdrom.in_
C:\04716a85cafaab720152e9427e\i386\ic\compdata\drvmain.chm
C:\04716a85cafaab720152e9427e\i386\ic\compdata\drvmain.inf
C:\04716a85cafaab720152e9427e\i386\ic\compdata\ntcompat.inf
C:\04716a85cafaab720152e9427e\i386\ic\cpanel_p.ch_
C:\04716a85cafaab720152e9427e\i386\ic\cpu.in_
C:\04716a85cafaab720152e9427e\i386\ic\defltp.in_
C:\04716a85cafaab720152e9427e\i386\ic\devxprop.in_
C:\04716a85cafaab720152e9427e\i386\ic\disk.in_
C:\04716a85cafaab720152e9427e\i386\ic\dosnet.inf
C:\04716a85cafaab720152e9427e\i386\ic\dpcdll.dl_
C:\04716a85cafaab720152e9427e\i386\ic\dpup.in_
C:\04716a85cafaab720152e9427e\i386\ic\drvindex.inf
C:\04716a85cafaab720152e9427e\i386\ic\filefldp.ch_
C:\04716a85cafaab720152e9427e\i386\ic\fltmgr.in_
C:\04716a85cafaab720152e9427e\i386\ic\hiddigi.in_
C:\04716a85cafaab720152e9427e\i386\ic\hidserv.in_
C:\04716a85cafaab720152e9427e\i386\ic\hivecls.inf
C:\04716a85cafaab720152e9427e\i386\ic\hivedef.inf
C:\04716a85cafaab720152e9427e\i386\ic\hivesft.inf
C:\04716a85cafaab720152e9427e\i386\ic\hivesys.inf
C:\04716a85cafaab720152e9427e\i386\ic\howtop.ch_
C:\04716a85cafaab720152e9427e\i386\ic\hscsp_p3.ca_
C:\04716a85cafaab720152e9427e\i386\ic\hwcomp.dat
C:\04716a85cafaab720152e9427e\i386\ic\ie.in_
C:\04716a85cafaab720152e9427e\i386\ic\ieaccess.in_
C:\04716a85cafaab720152e9427e\i386\ic\iis.in_
C:\04716a85cafaab720152e9427e\i386\ic\ims.in_
C:\04716a85cafaab720152e9427e\i386\ic\input.in_
C:\04716a85cafaab720152e9427e\i386\ic\intl.inf
C:\04716a85cafaab720152e9427e\i386\ic\keyboard.in_
C:\04716a85cafaab720152e9427e\i386\ic\koc.in_
C:\04716a85cafaab720152e9427e\i386\ic\ks.in_
C:\04716a85cafaab720152e9427e\i386\ic\kscaptur.in_
C:\04716a85cafaab720152e9427e\i386\ic\ksfilter.in_
C:\04716a85cafaab720152e9427e\i386\ic\layout.inf
C:\04716a85cafaab720152e9427e\i386\ic\machine.in_
C:\04716a85cafaab720152e9427e\i386\ic\mchgr.in_
C:\04716a85cafaab720152e9427e\i386\ic\mdac.in_
C:\04716a85cafaab720152e9427e\i386\ic\miscp.ch_
C:\04716a85cafaab720152e9427e\i386\ic\mmopt.in_
C:\04716a85cafaab720152e9427e\i386\ic\mpe.in_
C:\04716a85cafaab720152e9427e\i386\ic\mshdc.in_
C:\04716a85cafaab720152e9427e\i386\ic\msoe50.in_
C:\04716a85cafaab720152e9427e\i386\ic\mstape.in_
C:\04716a85cafaab720152e9427e\i386\ic\multimed.in_
C:\04716a85cafaab720152e9427e\i386\ic\nabtsfec.in_
C:\04716a85cafaab720152e9427e\i386\ic\ndisip.in_
C:\04716a85cafaab720152e9427e\i386\ic\netfw.in_
C:\04716a85cafaab720152e9427e\i386\ic\netip6.in_
C:\04716a85cafaab720152e9427e\i386\ic\netmscli.in_
C:\04716a85cafaab720152e9427e\i386\ic\netoc.in_
C:\04716a85cafaab720152e9427e\i386\ic\netrass.in_
C:\04716a85cafaab720152e9427e\i386\ic\nettcpip.in_
C:\04716a85cafaab720152e9427e\i386\ic\netupnph.in_
C:\04716a85cafaab720152e9427e\i386\ic\netwzc.in_
C:\04716a85cafaab720152e9427e\i386\ic\nt5inf.ca_
C:\04716a85cafaab720152e9427e\i386\ic\ntprint.inf
C:\04716a85cafaab720152e9427e\i386\ic\oobe.in_
C:\04716a85cafaab720152e9427e\i386\ic\p2p.in_
C:\04716a85cafaab720152e9427e\i386\ic\pchealth.in_
C:\04716a85cafaab720152e9427e\i386\ic\pid.inf
C:\04716a85cafaab720152e9427e\i386\ic\pidgen.dll
C:\04716a85cafaab720152e9427e\i386\ic\pnpscsi.in_
C:\04716a85cafaab720152e9427e\i386\ic\rinorprt.si_
C:\04716a85cafaab720152e9427e\i386\ic\ristndrd.si_
C:\04716a85cafaab720152e9427e\i386\ic\sceregvl.in_
C:\04716a85cafaab720152e9427e\i386\ic\scsi.in_
C:\04716a85cafaab720152e9427e\i386\ic\sdbus.in_
C:\04716a85cafaab720152e9427e\i386\ic\secrecs.in_
C:\04716a85cafaab720152e9427e\i386\ic\setupreg.hiv
C:\04716a85cafaab720152e9427e\i386\ic\sffdisk.in_
C:\04716a85cafaab720152e9427e\i386\ic\shell.in_
C:\04716a85cafaab720152e9427e\i386\ic\shl_img.in_
C:\04716a85cafaab720152e9427e\i386\ic\slip.in_
C:\04716a85cafaab720152e9427e\i386\ic\smartcrd.in_
C:\04716a85cafaab720152e9427e\i386\ic\startoc.ca_
C:\04716a85cafaab720152e9427e\i386\ic\startoc.dl_
C:\04716a85cafaab720152e9427e\i386\ic\streamip.in_
C:\04716a85cafaab720152e9427e\i386\ic\swflash.in_
C:\04716a85cafaab720152e9427e\i386\ic\sysoc.in_
C:\04716a85cafaab720152e9427e\i386\ic\syssetup.in_
C:\04716a85cafaab720152e9427e\i386\ic\tape.in_
C:\04716a85cafaab720152e9427e\i386\ic\tsoc.in_
C:\04716a85cafaab720152e9427e\i386\ic\txtsetup.sif
C:\04716a85cafaab720152e9427e\i386\ic\unattend.txt
C:\04716a85cafaab720152e9427e\i386\ic\update1p.ch_
C:\04716a85cafaab720152e9427e\i386\ic\usbport.in_
C:\04716a85cafaab720152e9427e\i386\ic\usbvideo.in_
C:\04716a85cafaab720152e9427e\i386\ic\wbemoc.in_
C:\04716a85cafaab720152e9427e\i386\ic\whatnewp.ch_
C:\04716a85cafaab720152e9427e\i386\ic\win9xupg\migdb.inf
C:\04716a85cafaab720152e9427e\i386\ic\win9xupg\vscandb.inf
C:\04716a85cafaab720152e9427e\i386\ic\win9xupg\win95upg.inf
C:\04716a85cafaab720152e9427e\i386\ic\wind_p.ch_
C:\04716a85cafaab720152e9427e\i386\ic\winnt32.msi
C:\04716a85cafaab720152e9427e\i386\ic\wkstamig.in_
C:\04716a85cafaab720152e9427e\i386\ic\wordpad.in_
C:\04716a85cafaab720152e9427e\i386\ic\wstcodec.in_
C:\04716a85cafaab720152e9427e\i386\icaapi.dl_
C:\04716a85cafaab720152e9427e\i386\iccvid.dl_
C:\04716a85cafaab720152e9427e\i386\icm32.dl_
C:\04716a85cafaab720152e9427e\i386\icmp.dl_
C:\04716a85cafaab720152e9427e\i386\icntlast.ht_
C:\04716a85cafaab720152e9427e\i386\iconlib.dl_
C:\04716a85cafaab720152e9427e\i386\iconn.ht_
C:\04716a85cafaab720152e9427e\i386\iconnect.ht_
C:\04716a85cafaab720152e9427e\i386\iconnect.js_
C:\04716a85cafaab720152e9427e\i386\ics.ht_
C:\04716a85cafaab720152e9427e\i386\icsdc.ht_
C:\04716a85cafaab720152e9427e\i386\icsmgr.js_
C:\04716a85cafaab720152e9427e\i386\icwconn.dl_
C:\04716a85cafaab720152e9427e\i386\icwconn1.ex_
C:\04716a85cafaab720152e9427e\i386\icwconn2.ex_
C:\04716a85cafaab720152e9427e\i386\icwdial.ch_
C:\04716a85cafaab720152e9427e\i386\icwdial.dl_
C:\04716a85cafaab720152e9427e\i386\icwdl.dl_
C:\04716a85cafaab720152e9427e\i386\icwhelp.dl_
C:\04716a85cafaab720152e9427e\i386\icwip.du_
C:\04716a85cafaab720152e9427e\i386\icwphbk.dl_
C:\04716a85cafaab720152e9427e\i386\icwrmind.ex_
C:\04716a85cafaab720152e9427e\i386\icwutil.dl_
C:\04716a85cafaab720152e9427e\i386\icwx25a.du_
C:\04716a85cafaab720152e9427e\i386\icwx25b.du_
C:\04716a85cafaab720152e9427e\i386\icwx25c.du_
C:\04716a85cafaab720152e9427e\i386\ident1.ht_
C:\04716a85cafaab720152e9427e\i386\ident2.ht_
C:\04716a85cafaab720152e9427e\i386\idq.dl_
C:\04716a85cafaab720152e9427e\i386\ie4uinit.ex_
C:\04716a85cafaab720152e9427e\i386\ieakeng.dl_
C:\04716a85cafaab720152e9427e\i386\ieaksie.dl_
C:\04716a85cafaab720152e9427e\i386\iedkcs32.dl_
C:\04716a85cafaab720152e9427e\i386\iedw.ex_
C:\04716a85cafaab720152e9427e\i386\ieencode.dl_
C:\04716a85cafaab720152e9427e\i386\ieexec.exe
C:\04716a85cafaab720152e9427e\i386\ieexecremote.dll
C:\04716a85cafaab720152e9427e\i386\iehost.dll
C:\04716a85cafaab720152e9427e\i386\iepeers.dl_
C:\04716a85cafaab720152e9427e\i386\iernonce.dl_
C:\04716a85cafaab720152e9427e\i386\iesetup.dl_
C:\04716a85cafaab720152e9427e\i386\ieuinit.in_
C:\04716a85cafaab720152e9427e\i386\iexplore.ch_
C:\04716a85cafaab720152e9427e\i386\iexplore.ex_
C:\04716a85cafaab720152e9427e\i386\iexpress.ex_
C:\04716a85cafaab720152e9427e\i386\ifmon.dl_
C:\04716a85cafaab720152e9427e\i386\igmpagnt.dl_
C:\04716a85cafaab720152e9427e\i386\iis.dl_
C:\04716a85cafaab720152e9427e\i386\iisadmin.dl_
C:\04716a85cafaab720152e9427e\i386\iische51.dl_
C:\04716a85cafaab720152e9427e\i386\iisext51.dl_
C:\04716a85cafaab720152e9427e\i386\iisfecnv.dl_
C:\04716a85cafaab720152e9427e\i386\iislog51.dl_
C:\04716a85cafaab720152e9427e\i386\iismap.dl_
C:\04716a85cafaab720152e9427e\i386\iisntw.ch_
C:\04716a85cafaab720152e9427e\i386\iisrstas.ex_
C:\04716a85cafaab720152e9427e\i386\iisrtl.dl_
C:\04716a85cafaab720152e9427e\i386\ikc\dosnet.inf
C:\04716a85cafaab720152e9427e\i386\ikc\layout.inf
C:\04716a85cafaab720152e9427e\i386\ikc\nt5inf.ca_
C:\04716a85cafaab720152e9427e\i386\ikc\pid.inf
C:\04716a85cafaab720152e9427e\i386\ikc\sysoc.in_
C:\04716a85cafaab720152e9427e\i386\ikc\syssetup.in_
C:\04716a85cafaab720152e9427e\i386\ikc\txtsetup.sif
C:\04716a85cafaab720152e9427e\i386\iknc\dosnet.inf
C:\04716a85cafaab720152e9427e\i386\iknc\hivedef.inf
C:\04716a85cafaab720152e9427e\i386\iknc\layout.inf
C:\04716a85cafaab720152e9427e\i386\iknc\multimed.in_
C:\04716a85cafaab720152e9427e\i386\iknc\nt5inf.ca_
C:\04716a85cafaab720152e9427e\i386\iknc\oobe.in_
C:\04716a85cafaab720152e9427e\i386\iknc\pid.inf
C:\04716a85cafaab720152e9427e\i386\iknc\shl_img.in_
C:\04716a85cafaab720152e9427e\i386\iknc\sysoc.in_
C:\04716a85cafaab720152e9427e\i386\iknc\syssetup.in_
C:\04716a85cafaab720152e9427e\i386\iknc\txtsetup.sif
C:\04716a85cafaab720152e9427e\i386\iknp\dosnet.inf
C:\04716a85cafaab720152e9427e\i386\iknp\hivedef.inf
C:\04716a85cafaab720152e9427e\i386\iknp\layout.inf
C:\04716a85cafaab720152e9427e\i386\iknp\multimed.in_
C:\04716a85cafaab720152e9427e\i386\iknp\nt5inf.ca_
C:\04716a85cafaab720152e9427e\i386\iknp\oobe.in_
C:\04716a85cafaab720152e9427e\i386\iknp\pid.inf
C:\04716a85cafaab720152e9427e\i386\iknp\shl_img.in_
C:\04716a85cafaab720152e9427e\i386\iknp\sysoc.in_
C:\04716a85cafaab720152e9427e\i386\iknp\syssetup.in_
C:\04716a85cafaab720152e9427e\i386\iknp\txtsetup.sif
C:\04716a85cafaab720152e9427e\i386\ikp\dosnet.inf
C:\04716a85cafaab720152e9427e\i386\ikp\layout.inf
C:\04716a85cafaab720152e9427e\i386\ikp\nt5inf.ca_
C:\04716a85cafaab720152e9427e\i386\ikp\pid.inf
C:\04716a85cafaab720152e9427e\i386\ikp\sysoc.in_
C:\04716a85cafaab720152e9427e\i386\ikp\syssetup.in_
C:\04716a85cafaab720152e9427e\i386\ikp\txtsetup.sif
C:\04716a85cafaab720152e9427e\i386\ilasm.exe
C:\04716a85cafaab720152e9427e\i386\ils.dl_
C:\04716a85cafaab720152e9427e\i386\imaadp32.ac_
C:\04716a85cafaab720152e9427e\i386\imagehlp.dll
C:\04716a85cafaab720152e9427e\i386\images\faq_arup.gif
C:\04716a85cafaab720152e9427e\i386\images\faq_atpl.css
C:\04716a85cafaab720152e9427e\i386\images\faq_bg2.jpg
C:\04716a85cafaab720152e9427e\i386\images\faq_frwl.gif
C:\04716a85cafaab720152e9427e\i386\images\faq_inex.gif
C:\04716a85cafaab720152e9427e\i386\images\faq_mply.gif
C:\04716a85cafaab720152e9427e\i386\images\faq_ouex.gif
C:\04716a85cafaab720152e9427e\i386\images\faq_pblk.gif
C:\04716a85cafaab720152e9427e\i386\images\faq_prgs.jpg
C:\04716a85cafaab720152e9427e\i386\images\faq_shld.gif
C:\04716a85cafaab720152e9427e\i386\images\faq_wupd.gif
C:\04716a85cafaab720152e9427e\i386\imapi.ex_
C:\04716a85cafaab720152e9427e\i386\imapi.sy_
C:\04716a85cafaab720152e9427e\i386\imeshare.dl_
C:\04716a85cafaab720152e9427e\i386\imgutil.dl_
C:\04716a85cafaab720152e9427e\i386\imm32.dl_
C:\04716a85cafaab720152e9427e\i386\impact.tt_
C:\04716a85cafaab720152e9427e\i386\ims.cat
C:\04716a85cafaab720152e9427e\i386\imsinsnt.dl_
C:\04716a85cafaab720152e9427e\i386\inc\dosnet.inf
C:\04716a85cafaab720152e9427e\i386\inc\layout.inf
C:\04716a85cafaab720152e9427e\i386\inc\multimed.in_
C:\04716a85cafaab720152e9427e\i386\inc\nt5inf.ca_
C:\04716a85cafaab720152e9427e\i386\inc\oobe.in_
C:\04716a85cafaab720152e9427e\i386\inc\shl_img.in_
C:\04716a85cafaab720152e9427e\i386\inc\sysoc.in_
C:\04716a85cafaab720152e9427e\i386\inc\syssetup.in_
C:\04716a85cafaab720152e9427e\i386\inc\txtsetup.sif
C:\04716a85cafaab720152e9427e\i386\inetcfg.dl_
C:\04716a85cafaab720152e9427e\i386\inetcomm.dl_
C:\04716a85cafaab720152e9427e\i386\inetcpl.cp_
C:\04716a85cafaab720152e9427e\i386\inetin51.ex_
C:\04716a85cafaab720152e9427e\i386\inetmgr.dl_
C:\04716a85cafaab720152e9427e\i386\inetmib1.dl_
C:\04716a85cafaab720152e9427e\i386\inetpp.dl_
C:\04716a85cafaab720152e9427e\i386\inetppui.dl_
C:\04716a85cafaab720152e9427e\i386\inetpref.xm_
C:\04716a85cafaab720152e9427e\i386\inetres.dl_
C:\04716a85cafaab720152e9427e\i386\inetset.ad_
C:\04716a85cafaab720152e9427e\i386\inetwiz.ex_
C:\04716a85cafaab720152e9427e\i386\infoadmn.dl_
C:\04716a85cafaab720152e9427e\i386\infocomm.dl_
C:\04716a85cafaab720152e9427e\i386\infrared.ch_
C:\04716a85cafaab720152e9427e\i386\initpki.dl_
C:\04716a85cafaab720152e9427e\i386\inp\cpanel_p.chq
C:\04716a85cafaab720152e9427e\i386\inp\cpanel_w.chq
C:\04716a85cafaab720152e9427e\i386\inp\dosnet.inf
C:\04716a85cafaab720152e9427e\i386\inp\filefldp.chm
C:\04716a85cafaab720152e9427e\i386\inp\filefldw.chm
C:\04716a85cafaab720152e9427e\i386\inp\howtop.chm
C:\04716a85cafaab720152e9427e\i386\inp\howtow.chm
C:\04716a85cafaab720152e9427e\i386\inp\inetres.chm
C:\04716a85cafaab720152e9427e\i386\inp\layout.inf
C:\04716a85cafaab720152e9427e\i386\inp\miscp.chm
C:\04716a85cafaab720152e9427e\i386\inp\miscw.chm
C:\04716a85cafaab720152e9427e\i386\inp\msinfo32.chm
C:\04716a85cafaab720152e9427e\i386\inp\mstaskw.chm
C:\04716a85cafaab720152e9427e\i386\inp\multimed.in_
C:\04716a85cafaab720152e9427e\i386\inp\nt5inf.ca_
C:\04716a85cafaab720152e9427e\i386\inp\ntchowto.chm
C:\04716a85cafaab720152e9427e\i386\inp\oobe.in_
C:\04716a85cafaab720152e9427e\i386\inp\shl_img.in_
C:\04716a85cafaab720152e9427e\i386\inp\spad.chm
C:\04716a85cafaab720152e9427e\i386\inp\spconw.chm
C:\04716a85cafaab720152e9427e\i386\inp\sysoc.in_
C:\04716a85cafaab720152e9427e\i386\inp\syssetup.in_
C:\04716a85cafaab720152e9427e\i386\inp\tshoot.chm
C:\04716a85cafaab720152e9427e\i386\inp\txtsetup.sif
C:\04716a85cafaab720152e9427e\i386\inp\whatnewp.chm
C:\04716a85cafaab720152e9427e\i386\inp\whatneww.chm
C:\04716a85cafaab720152e9427e\i386\inp\wind_p.chq
C:\04716a85cafaab720152e9427e\i386\inp\wind_w.chq
C:\04716a85cafaab720152e9427e\i386\input.ch_
C:\04716a85cafaab720152e9427e\i386\input.dl_
C:\04716a85cafaab720152e9427e\i386\input.hl_
C:\04716a85cafaab720152e9427e\i386\inseng.dl_
C:\04716a85cafaab720152e9427e\i386\installpersistsqlstate.sql
C:\04716a85cafaab720152e9427e\i386\installsqlstate.sql
C:\04716a85cafaab720152e9427e\i386\installsqlstatetemplate.sql
C:\04716a85cafaab720152e9427e\i386\installutil.exe
C:\04716a85cafaab720152e9427e\i386\instcat.sq_
C:\04716a85cafaab720152e9427e\i386\intelide.sy_
C:\04716a85cafaab720152e9427e\i386\intelppm.sy_
C:\04716a85cafaab720152e9427e\i386\intl.cp_
C:\04716a85cafaab720152e9427e\i386\intro.wm_
C:\04716a85cafaab720152e9427e\i386\ip\accessor.in_
C:\04716a85cafaab720152e9427e\i386\ip\acpi.in_
C:\04716a85cafaab720152e9427e\i386\ip\adsutil.vb_
C:\04716a85cafaab720152e9427e\i386\ip\agp.in_
C:\04716a85cafaab720152e9427e\i386\ip\asr_pfu.ex_
C:\04716a85cafaab720152e9427e\i386\ip\au.in_
C:\04716a85cafaab720152e9427e\i386\ip\battery.in_
C:\04716a85cafaab720152e9427e\i386\ip\bda.in_
C:\04716a85cafaab720152e9427e\i386\ip\biosinfo.inf
C:\04716a85cafaab720152e9427e\i386\ip\ccdecode.in_
C:\04716a85cafaab720152e9427e\i386\ip\cdrom.in_
C:\04716a85cafaab720152e9427e\i386\ip\compdata\drvmain.chm
C:\04716a85cafaab720152e9427e\i386\ip\compdata\drvmain.inf
C:\04716a85cafaab720152e9427e\i386\ip\compdata\ntcompat.inf
C:\04716a85cafaab720152e9427e\i386\ip\comsdupd.ex_
C:\04716a85cafaab720152e9427e\i386\ip\cpanel_w.ch_
C:\04716a85cafaab720152e9427e\i386\ip\cpu.in_
C:\04716a85cafaab720152e9427e\i386\ip\default.as_
C:\04716a85cafaab720152e9427e\i386\ip\defltwk.in_
C:\04716a85cafaab720152e9427e\i386\ip\devxprop.in_
C:\04716a85cafaab720152e9427e\i386\ip\disk.in_
C:\04716a85cafaab720152e9427e\i386\ip\dosnet.inf
C:\04716a85cafaab720152e9427e\i386\ip\dpcdll.dl_
C:\04716a85cafaab720152e9427e\i386\ip\drvindex.inf
C:\04716a85cafaab720152e9427e\i386\ip\dwup.in_
C:\04716a85cafaab720152e9427e\i386\ip\filefldw.ch_
C:\04716a85cafaab720152e9427e\i386\ip\fltmgr.in_
C:\04716a85cafaab720152e9427e\i386\ip\hiddigi.in_
C:\04716a85cafaab720152e9427e\i386\ip\hidserv.in_
C:\04716a85cafaab720152e9427e\i386\ip\hivecls.inf
C:\04716a85cafaab720152e9427e\i386\ip\hivedef.inf
C:\04716a85cafaab720152e9427e\i386\ip\hivesft.inf
C:\04716a85cafaab720152e9427e\i386\ip\hivesys.inf
C:\04716a85cafaab720152e9427e\i386\ip\howtow.ch_
C:\04716a85cafaab720152e9427e\i386\ip\hscmui.ca_
C:\04716a85cafaab720152e9427e\i386\ip\hscsp_w3.ca_
C:\04716a85cafaab720152e9427e\i386\ip\hwcomp.dat
C:\04716a85cafaab720152e9427e\i386\ip\ie.in_
C:\04716a85cafaab720152e9427e\i386\ip\ieaccess.in_
C:\04716a85cafaab720152e9427e\i386\ip\iis.in_
C:\04716a85cafaab720152e9427e\i386\ip\ims.in_
C:\04716a85cafaab720152e9427e\i386\ip\inetres.ad_
C:\04716a85cafaab720152e9427e\i386\ip\inetres.ch_
C:\04716a85cafaab720152e9427e\i386\ip\input.in_
C:\04716a85cafaab720152e9427e\i386\ip\intl.inf
C:\04716a85cafaab720152e9427e\i386\ip\irbus.in_
C:\04716a85cafaab720152e9427e\i386\ip\irbus.sy_
C:\04716a85cafaab720152e9427e\i386\ip\keyboard.in_
C:\04716a85cafaab720152e9427e\i386\ip\koc.in_
C:\04716a85cafaab720152e9427e\i386\ip\ks.in_
C:\04716a85cafaab720152e9427e\i386\ip\kscaptur.in_
C:\04716a85cafaab720152e9427e\i386\ip\ksfilter.in_
C:\04716a85cafaab720152e9427e\i386\ip\layout.inf
C:\04716a85cafaab720152e9427e\i386\ip\lsans.tt_
C:\04716a85cafaab720152e9427e\i386\ip\lsansd.tt_
C:\04716a85cafaab720152e9427e\i386\ip\lsansdi.tt_
C:\04716a85cafaab720152e9427e\i386\ip\lsansi.tt_
C:\04716a85cafaab720152e9427e\i386\ip\machine.in_
C:\04716a85cafaab720152e9427e\i386\ip\mchgr.in_
C:\04716a85cafaab720152e9427e\i386\ip\mdac.in_
C:\04716a85cafaab720152e9427e\i386\ip\medctroc.dl_
C:\04716a85cafaab720152e9427e\i386\ip\medctroc.in_
C:\04716a85cafaab720152e9427e\i386\ip\mediactr.ca_
C:\04716a85cafaab720152e9427e\i386\ip\miscw.ch_
C:\04716a85cafaab720152e9427e\i386\ip\mmopt.in_
C:\04716a85cafaab720152e9427e\i386\ip\mpe.in_
C:\04716a85cafaab720152e9427e\i386\ip\mshdc.in_
C:\04716a85cafaab720152e9427e\i386\ip\msoe50.in_
C:\04716a85cafaab720152e9427e\i386\ip\mstape.in_
C:\04716a85cafaab720152e9427e\i386\ip\multimed.in_
C:\04716a85cafaab720152e9427e\i386\ip\nabtsfec.in_
C:\04716a85cafaab720152e9427e\i386\ip\ndisip.in_
C:\04716a85cafaab720152e9427e\i386\ip\netfw.in_
C:\04716a85cafaab720152e9427e\i386\ip\netfx.ca_
C:\04716a85cafaab720152e9427e\i386\ip\netfxocm.dl_
C:\04716a85cafaab720152e9427e\i386\ip\netfxocm.in_
C:\04716a85cafaab720152e9427e\i386\ip\netip6.in_
C:\04716a85cafaab720152e9427e\i386\ip\netmscli.in_
C:\04716a85cafaab720152e9427e\i386\ip\netoc.in_
C:\04716a85cafaab720152e9427e\i386\ip\netrass.in_
C:\04716a85cafaab720152e9427e\i386\ip\nettcpip.in_
C:\04716a85cafaab720152e9427e\i386\ip\netupnph.in_
C:\04716a85cafaab720152e9427e\i386\ip\netwzc.in_
C:\04716a85cafaab720152e9427e\i386\ip\nt5inf.ca_
C:\04716a85cafaab720152e9427e\i386\ip\ntprint.inf
C:\04716a85cafaab720152e9427e\i386\ip\obrb0401.dl_
C:\04716a85cafaab720152e9427e\i386\ip\obrb0404.dl_
C:\04716a85cafaab720152e9427e\i386\ip\obrb0405.dl_
C:\04716a85cafaab720152e9427e\i386\ip\obrb0406.dl_
C:\04716a85cafaab720152e9427e\i386\ip\obrb0407.dl_
C:\04716a85cafaab720152e9427e\i386\ip\obrb0408.dl_
C:\04716a85cafaab720152e9427e\i386\ip\obrb040b.dl_
C:\04716a85cafaab720152e9427e\i386\ip\obrb040c.dl_
C:\04716a85cafaab720152e9427e\i386\ip\obrb040d.dl_
C:\04716a85cafaab720152e9427e\i386\ip\obrb040e.dl_
C:\04716a85cafaab720152e9427e\i386\ip\obrb0410.dl_
C:\04716a85cafaab720152e9427e\i386\ip\obrb0411.dl_
C:\04716a85cafaab720152e9427e\i386\ip\obrb0412.dl_
C:\04716a85cafaab720152e9427e\i386\ip\obrb0413.dl_
C:\04716a85cafaab720152e9427e\i386\ip\obrb0414.dl_
C:\04716a85cafaab720152e9427e\i386\ip\obrb0415.dl_
C:\04716a85cafaab720152e9427e\i386\ip\obrb0416.dl_
C:\04716a85cafaab720152e9427e\i386\ip\obrb0419.dl_
C:\04716a85cafaab720152e9427e\i386\ip\obrb041d.dl_
C:\04716a85cafaab720152e9427e\i386\ip\obrb041f.dl_
C:\04716a85cafaab720152e9427e\i386\ip\obrb0804.dl_
C:\04716a85cafaab720152e9427e\i386\ip\obrb0816.dl_
C:\04716a85cafaab720152e9427e\i386\ip\obrb0c0a.dl_
C:\04716a85cafaab720152e9427e\i386\ip\oobe.in_
C:\04716a85cafaab720152e9427e\i386\ip\p2p.in_
C:\04716a85cafaab720152e9427e\i386\ip\pchealth.in_
C:\04716a85cafaab720152e9427e\i386\ip\pid.inf
C:\04716a85cafaab720152e9427e\i386\ip\pidgen.dll
C:\04716a85cafaab720152e9427e\i386\ip\pnpscsi.in_
C:\04716a85cafaab720152e9427e\i386\ip\query.as_
C:\04716a85cafaab720152e9427e\i386\ip\rinorprt.si_
C:\04716a85cafaab720152e9427e\i386\ip\ristndrd.si_
C:\04716a85cafaab720152e9427e\i386\ip\rwnh.dl_
C:\04716a85cafaab720152e9427e\i386\ip\sceregvl.in_
C:\04716a85cafaab720152e9427e\i386\ip\scsi.in_
C:\04716a85cafaab720152e9427e\i386\ip\sdbus.in_
C:\04716a85cafaab720152e9427e\i386\ip\search.as_
C:\04716a85cafaab720152e9427e\i386\ip\secedit.ex_
C:\04716a85cafaab720152e9427e\i386\ip\secrecs.in_
C:\04716a85cafaab720152e9427e\i386\ip\seo.dl_
C:\04716a85cafaab720152e9427e\i386\ip\setupreg.hiv
C:\04716a85cafaab720152e9427e\i386\ip\sffdisk.in_
C:\04716a85cafaab720152e9427e\i386\ip\shell.in_
C:\04716a85cafaab720152e9427e\i386\ip\shl_img.in_
C:\04716a85cafaab720152e9427e\i386\ip\slip.in_
C:\04716a85cafaab720152e9427e\i386\ip\smartcrd.in_
C:\04716a85cafaab720152e9427e\i386\ip\smtpadm.dl_
C:\04716a85cafaab720152e9427e\i386\ip\smtpapi.dl_
C:\04716a85cafaab720152e9427e\i386\ip\smtpsnap.cn_
C:\04716a85cafaab720152e9427e\i386\ip\smtpsnap.dl_
C:\04716a85cafaab720152e9427e\i386\ip\smtpsnap.hl_
C:\04716a85cafaab720152e9427e\i386\ip\spconw.ch_
C:\04716a85cafaab720152e9427e\i386\ip\spiisupd.ex_
C:\04716a85cafaab720152e9427e\i386\ip\spra0401.dl_
C:\04716a85cafaab720152e9427e\i386\ip\spra0402.dl_
C:\04716a85cafaab720152e9427e\i386\ip\spra0404.dl_
C:\04716a85cafaab720152e9427e\i386\ip\spra0405.dl_
C:\04716a85cafaab720152e9427e\i386\ip\spra0406.dl_
C:\04716a85cafaab720152e9427e\i386\ip\spra0407.dl_
C:\04716a85cafaab720152e9427e\i386\ip\spra0408.dl_
C:\04716a85cafaab720152e9427e\i386\ip\spra040b.dl_
C:\04716a85cafaab720152e9427e\i386\ip\spra040c.dl_
C:\04716a85cafaab720152e9427e\i386\ip\spra040d.dl_
C:\04716a85cafaab720152e9427e\i386\ip\spra040e.dl_
C:\04716a85cafaab720152e9427e\i386\ip\spra0410.dl_
C:\04716a85cafaab720152e9427e\i386\ip\spra0411.dl_
C:\04716a85cafaab720152e9427e\i386\ip\spra0412.dl_
C:\04716a85cafaab720152e9427e\i386\ip\spra0413.dl_
C:\04716a85cafaab720152e9427e\i386\ip\spra0414.dl_
C:\04716a85cafaab720152e9427e\i386\ip\spra0415.dl_
C:\04716a85cafaab720152e9427e\i386\ip\spra0416.dl_
C:\04716a85cafaab720152e9427e\i386\ip\spra0418.dl_
C:\04716a85cafaab720152e9427e\i386\ip\spra0419.dl_
C:\04716a85cafaab720152e9427e\i386\ip\spra041a.dl_
C:\04716a85cafaab720152e9427e\i386\ip\spra041d.dl_
C:\04716a85cafaab720152e9427e\i386\ip\spra041e.dl_
C:\04716a85cafaab720152e9427e\i386\ip\spra041f.dl_
C:\[u]0[/u]4716a85cafaab720152e9427e\i386\ip\spra0425.dl_
C:\[u]0[/u]4716a85cafaab720152e9427e\i386\ip\spra0426.dl_
C:\[u]0[/u]4716a85cafaab720152e9427e\i386\ip\spra0427.dl_
C:\[u]0[/u]4716a85cafaab720152e9427e\i386\ip\spra0804.dl_
C:\[u]0[/u]4716a85cafaab720152e9427e\i386\ip\spra0816.dl_
C:\[u]0[/u]4716a85cafaab720152e9427e\i386\ip\spra0c0a.dl_
C:\[u]0[/u]4716a85cafaab720152e9427e\i386\ip\sprb0401.dl_
C:\[u]0[/u]4716a85cafaab720152e9427e\i386\ip\sprb0404.dl_
C:\[u]0[/u]4716a85cafaab720152e9427e\i386\ip\sprb0405.dl_
C:\[u]0[/u]4716a85cafaab720152e9427e\i386\ip\sprb0406.dl_
C:\[u]0[/u]4716a85cafaab720152e9427e\i386\ip\sprb0407.dl_
C:\[u]0[/u]4716a85cafaab720152e9427e\i386\ip\sprb0408.dl_
C:\[u]0[/u]4716a85cafaab720152e9427e\i386\ip\sprb040b.dl_
C:\[u]0[/u]4716a85cafaab720152e9427e\i386\ip\sprb040c.dl_
C:\[u]0[/u]4716a85cafaab720152e9427e\i386\ip\sprb040d.dl_
C:\[u]0[/u]4716a85cafaab720152e9427e\i386\ip\sprb040e.dl_
C:\[u]0[/u]4716a85cafaab720152e9427e\i386\ip\sprb0410.dl_
C:\[u]0[/u]4716a85cafaab720152e9427e\i386\ip\sprb0411.dl_
C:\[u]0[/u]4716a85cafaab720152e9427e\i386\ip\sprb0412.dl_
C:\[u]0[/u]4716a85cafaab720152e9427e\i386\ip\sprb0413.dl_
C:\[u]0[/u]4716a85cafaab720152e9427e\i386\ip\sprb0414.dl_
C:\[u]0[/u]4716a85cafaab720152e9427e\i386\ip\sprb0415.dl_
C:\[u]0[/u]4716a85cafaab720152e9427e\i386\ip\sprb0416.dl_
C:\[u]0[/u]4716a85cafaab720152e9427e\i386\ip\sprb0419.dl_
C:\[u]0[/u]4716a85cafaab720152e9427e\i386\ip\sprb041d.dl_
C:\[u]0[/u]4716a85cafaab720152e9427e\i386\ip\sprb041f.dl_
C:\[u]0[/u]4716a85cafaab720152e9427e\i386\ip\sprb0804.dl_
C:\[u]0[/u]4716a85cafaab720152e9427e\i386\ip\sprb0816.dl_
C:\[u]0[/u]4716a85cafaab720152e9427e\i386\ip\sprb0c0a.dl_
C:\[u]0[/u]4716a85cafaab720152e9427e\i386\ip\sprc0401.dl_
C:\[u]0[/u]4716a85cafaab720152e9427e\i386\ip\sprc0404.dl_
C:\[u]0[/u]4716a85cafaab720152e9427e\i386\ip\sprc0405.dl_
C:\[u]0[/u]4716a85cafaab720152e9427e\i386\ip\sprc0406.dl_
C:\[u]0[/u]4716a85cafaab720152e9427e\i386\ip\sprc0407.dl_
C:\[u]0[/u]4716a85cafaab720152e9427e\i386\ip\sprc0408.dl_
C:\[u]0[/u]4716a85cafaab720152e9427e\i386\ip\sprc040b.dl_
C:\[u]0[/u]4716a85cafaab720152e9427e\i386\ip\sprc040c.dl_
C:\[u]0[/u]4716a85cafaab720152e9427e\i386\ip\sprc040d.dl_
C:\[u]0[/u]4716a85cafaab720152e9427e\i386\ip\sprc040e.dl_
C:\[u]0[/u]4716a85cafaab720152e9427e\i386\ip\sprc0410.dl_
C:\[u]0[/u]4716a85cafaab720152e9427e\i386\ip\sprc0411.dl_
C:\[u]0[/u]4716a85cafaab720152e9427e\i386\ip\sprc0412.dl_
C:\[u]0[/u]4716a85cafaab720152e9427e\i386\ip\sprc0413.dl_
C:\[u]0[/u]4716a85cafaab720152e9427e\i386\ip\sprc0414.dl_
C:\[u]0[/u]4716a85cafaab720152e9427e\i386\ip\sprc0415.dl_
C:\[u]0[/u]4716a85cafaab720152e9427e\i386\ip\sprc0416.dl_
C:\[u]0[/u]4716a85cafaab720152e9427e\i386\ip\sprc0419.dl_
C:\[u]0[/u]4716a85cafaab720152e9427e\i386\ip\sprc041d.dl_
C:\[u]0[/u]4716a85cafaab720152e9427e\i386\ip\sprc041f.dl_
C:\[u]0[/u]4716a85cafaab720152e9427e\i386\ip\sprc0804.dl_
C:\[u]0[/u]4716a85cafaab720152e9427e\i386\ip\sprc0816.dl_
C:\[u]0[/u]4716a85cafaab720152e9427e\i386\ip\sprc0c0a.dl_
C:\[u]0[/u]4716a85cafaab720152e9427e\i386\ip\streamip.in_
C:\[u]0[/u]4716a85cafaab720152e9427e\i386\ip\swflash.in_
C:\[u]0[/u]4716a85cafaab720152e9427e\i386\ip\sysoc.in_
C:\[u]0[/u]4716a85cafaab720152e9427e\i386\ip\syssetup.in_
C:\[u]0[/u]4716a85cafaab720152e9427e\i386\ip\tabletoc.dl_
C:\[u]0[/u]4716a85cafaab720152e9427e\i386\ip\tabletpc.ca_
C:\[u]0[/u]4716a85cafaab720152e9427e\i386\ip\tabletpc.in_
C:\[u]0[/u]4716a85cafaab720152e9427e\i386\ip\tape.in_
C:\[u]0[/u]4716a85cafaab720152e9427e\i386\ip\tsoc.in_
C:\[u]0[/u]4716a85cafaab720152e9427e\i386\ip\txtsetup.sif
C:\[u]0[/u]4716a85cafaab720152e9427e\i386\ip\unattend.txt
C:\[u]0[/u]4716a85cafaab720152e9427e\i386\ip\update1w.ch_
C:\[u]0[/u]4716a85cafaab720152e9427e\i386\ip\usbport.in_
C:\[u]0[/u]4716a85cafaab720152e9427e\i386\ip\usbvideo.in_
C:\[u]0[/u]4716a85cafaab720152e9427e\i386\ip\vbicodec.ax_
C:\[u]0[/u]4716a85cafaab720152e9427e\i386\ip\wbemoc.in_
C:\[u]0[/u]4716a85cafaab720152e9427e\i386\ip\whatneww.ch_
C:\[u]0[/u]4716a85cafaab720152e9427e\i386\ip\win9xupg\migdb.inf
C:\[u]0[/u]4716a85cafaab720152e9427e\i386\ip\win9xupg\vscandb.inf
C:\[u]0[/u]4716a85cafaab720152e9427e\i386\ip\win9xupg\win95upg.inf
C:\[u]0[/u]4716a85cafaab720152e9427e\i386\ip\wind_w.ch_
C:\[u]0[/u]4716a85cafaab720152e9427e\i386\ip\winnt32.msi
C:\[u]0[/u]4716a85cafaab720152e9427e\i386\ip\wkstamig.in_
C:\[u]0[/u]4716a85cafaab720152e9427e\i386\ip\wordpad.in_
C:\[u]0[/u]4716a85cafaab720152e9427e\i386\ip\wstcodec.in_
C:\[u]0[/u]4716a85cafaab720152e9427e\i386\ip\wstpager.ax_
C:\[u]0[/u]4716a85cafaab720152e9427e\i386\ip\wstrendr.ax_
C:\[u]0[/u]4716a85cafaab720152e9427e\i386\ip6fw.sy_
C:\[u]0[/u]4716a85cafaab720152e9427e\i386\ipconf.ts_
C:\[u]0[/u]4716a85cafaab720152e9427e\i386\ipconfig.ex_
C:\[u]0[/u]4716a85cafaab720152e9427e\i386\ipevldpc.dl_
C:\[u]0[/u]4716a85cafaab720152e9427e\i386\ipevlpid.dll
C:\[u]0[/u]4716a85cafaab720152e9427e\i386\iphlpapi.dl_
C:\[u]0[/u]4716a85cafaab720152e9427e\i386\ipinip.sy_
C:\[u]0[/u]4716a85cafaab720152e9427e\i386\ipmontr.dl_
C:\[u]0[/u]4716a85cafaab720152e9427e\i386\ipnat.sy_
C:\[u]0[/u]4716a85cafaab720152e9427e\i386\ipnathlp.dl_
C:\[u]0[/u]4716a85cafaab720152e9427e\i386\ipp_0001.as_
C:\[u]0[/u]4716a85cafaab720152e9427e\i386\ipp_0002.as_
C:\[u]0[/u]4716a85cafaab720152e9427e\i386\ipp_0004.as_
C:\[u]0[/u]4716a85cafaab720152e9427e\i386\ipp_0005.as_
C:\[u]0[/u]4716a85cafaab720152e9427e\i386\ipp_0006.as_
C:\[u]0[/u]4716a85cafaab720152e9427e\i386\ipp_0007.as_
C:\[u]0[/u]4716a85cafaab720152e9427e\i386\ipp_0010.as_
C:\[u]0[/u]4716a85cafaab720152e9427e\i386\ipp_0013.as_
C:\[u]0[/u]4716a85cafaab720152e9427e\i386\ipp_0014.as_
C:\[u]0[/u]4716a85cafaab720152e9427e\i386\ipp_util.in_
C:\[u]0[/u]4716a85cafaab720152e9427e\i386\ippromon.dl_
C:\[u]0[/u]4716a85cafaab720152e9427e\i386\iprip.dl_
C:\[u]0[/u]4716a85cafaab720152e9427e\i386\iprtrmgr.dl_
C:\[u]0[/u]4716a85cafaab720152e9427e\i386\ipsec.sy_
C:\[u]0[/u]4716a85cafaab720152e9427e\i386\ipseconp.ch_
C:\[u]0[/u]4716a85cafaab720152e9427e\i386\ipseconw.ch_
C:\[u]0[/u]4716a85cafaab720152e9427e\i386\ipsecsnp.dl_
C:\[u]0[/u]4716a85cafaab720152e9427e\i386\ipsecsvc.dl_
C:\[u]0[/u]4716a85cafaab720152e9427e\i386\ipseldpc.dl_
C:\[u]0[/u]4716a85cafaab720152e9427e\i386\ipselpid.dll
C:\[u]0[/u]4716a85cafaab720152e9427e\i386\ipsink.ax_
C:\[u]0[/u]4716a85cafaab720152e9427e\i386\ipsmsnap.dl_
C:\[u]0[/u]4716a85cafaab720152e9427e\i386\ipv6.ex_
C:\[u]0[/u]4716a85cafaab720152e9427e\i386\ipv6mon.dl_
C:\[u]0[/u]4716a85cafaab720152e9427e\i386\ipv6p.ch_
C:\[u]0[/u]4716a85cafaab720152e9427e\i386\ipxroute.ex_
C:\[u]0[/u]4716a85cafaab720152e9427e\i386\ipxwan.dl_
C:\[u]0[/u]4716a85cafaab720152e9427e\i386\ir41_32.ax_
C:\[u]0[/u]4716a85cafaab720152e9427e\i386\ir41_qc.dl_
C:\[u]0[/u]4716a85cafaab720152e9427e\i386\ir41_qcx.dl_
C:\[u]0[/u]4716a85cafaab720152e9427e\i386\ir50_32.dl_
C:\[u]0[/u]4716a85cafaab720152e9427e\i386\ir50_qc.dl_
C:\[u]0[/u]4716a85cafaab720152e9427e\i386\ir50_qcx.dl_
C:\[u]0[/u]4716a85cafaab720152e9427e\i386\irda.sy_
C:\[u]0[/u]4716a85cafaab720152e9427e\i386\irenum.sy_
C:\[u]0[/u]4716a85cafaab720152e9427e\i386\irftp.ex_
C:\[u]0[/u]4716a85cafaab720152e9427e\i386\irmon.dl_
C:\[u]0[/u]4716a85cafaab720152e9427e\i386\irprops.cp_
C:\[u]0[/u]4716a85cafaab720152e9427e\i386\isapnp.sy_
C:\[u]0[/u]4716a85cafaab720152e9427e\i386\isatq.dl_
C:\[u]0[/u]4716a85cafaab720152e9427e\i386\iscomlog.dl_
C:\[u]0[/u]4716a85cafaab720152e9427e\i386\isdpc.dl_
C:\[u]0[/u]4716a85cafaab720152e9427e\i386\isendpc.dl_
C:\[u]0[/u]4716a85cafaab720152e9427e\i386\isenpid.dll
C:\[u]0[/u]4716a85cafaab720152e9427e\i386\isign32.dl_
C:\[u]0[/u]4716a85cafaab720152e9427e\i386\isp.ht_
C:\[u]0[/u]4716a85cafaab720152e9427e\i386\isp2busy.ht_
C:\[u]0[/u]4716a85cafaab720152e9427e\i386\ispcnerr.ht_
C:\[u]0[/u]4716a85cafaab720152e9427e\i386\ispdtone.ht_
C:\[u]0[/u]4716a85cafaab720152e9427e\i386\isphdshk.ht_
C:\[u]0[/u]4716a85cafaab720152e9427e\i386\ispid.dll
C:\[u]0[/u]4716a85cafaab720152e9427e\i386\ispins.ht_
C:\[u]0[/u]4716a85cafaab720152e9427e\i386\ispnoanw.ht_
C:\[u]0[/u]4716a85cafaab720152e9427e\i386\isppberr.ht_
C:\[u]0[/u]4716a85cafaab720152e9427e\i386\ispphbsy.ht_
C:\[u]0[/u]4716a85cafaab720152e9427e\i386\ispsbusy.ht_
C:\[u]0[/u]4716a85cafaab720152e9427e\i386\isptype.ht_
C:\[u]0[/u]4716a85cafaab720152e9427e\i386\isptype.js_
C:\[u]0[/u]4716a85cafaab720152e9427e\i386\ispwait.ht_
C:\[u]0[/u]4716a85cafaab720152e9427e\i386\isrdbg32.dl_
C:\[u]0[/u]4716a85cafaab720152e9427e\i386\istart\dosnet.inf
C:\[u]0[/u]4716a85cafaab720152e9427e\i386\istart\duass.dl_
C:\[u]0[/u]4716a85cafaab720152e9427e\i386\istart\ediskeer.dl_
C:\[u]0[/u]4716a85cafaab720152e9427e\i386\istart\layout.inf
C:\[u]0[/u]4716a85cafaab720152e9427e\i386\istart\nt5inf.ca_
C:\[u]0[/u]4716a85cafaab720152e9427e\i386\istart\starterlcw.ex_
C:\[u]0[/u]4716a85cafaab720152e9427e\i386\istart\sysoc.in_
C:\[u]0[/u]4716a85cafaab720152e9427e\i386\istart\syssetup.in_
C:\[u]0[/u]4716a85cafaab720152e9427e\i386\istart\txtsetup.sif
C:\[u]0[/u]4716a85cafaab720152e9427e\i386\itircl.dl_
C:\[u]0[/u]4716a85cafaab720152e9427e\i386\itss.dl_
C:\[u]0[/u]4716a85cafaab720152e9427e\i386\iuengine.dl_
C:\[u]0[/u]4716a85cafaab720152e9427e\i386\ivfsrc.ax_
C:\[u]0[/u]4716a85cafaab720152e9427e\i386\ixsso.dl_
C:\[u]0[/u]4716a85cafaab720152e9427e\i386\iyuv_32.dl_
C:\[u]0[/u]4716a85cafaab720152e9427e\i386\jgdw400.dl_
C:\[u]0[/u]4716a85cafaab720152e9427e\i386\jgpl400.dl_
C:\[u]0[/u]4716a85cafaab720152e9427e\i386\jndom_a.ht_
C:\[u]0[/u]4716a85cafaab720152e9427e\i386\jndomain.ht_
C:\[u]0[/u]4716a85cafaab720152e9427e\i386\joy.cp_
C:\[u]0[/u]4716a85cafaab720152e9427e\i386\jsc.exe
C:\[u]0[/u]4716a85cafaab720152e9427e\i386\jscript.dl_
C:\[u]0[/u]4716a85cafaab720152e9427e\i386\jscript.mu_
C:\[u]0[/u]4716a85cafaab720152e9427e\i386\jsproxy.dl_
C:\[u]0[/u]4716a85cafaab720152e9427e\i386\kartika.tt_
C:\[u]0[/u]4716a85cafaab720152e9427e\i386\kbd101.dl_
C:\[u]0[/u]4716a85cafaab720152e9427e\i386\kbd106.dl_
C:\[u]0[/u]4716a85cafaab720152e9427e\i386\kbd106n.dl_
C:\[u]0[/u]4716a85cafaab720152e9427e\i386\kbdax2.dl_
C:\[u]0[/u]4716a85cafaab720152e9427e\i386\kbdbhc.dl_
C:\[u]0[/u]4716a85cafaab720152e9427e\i386\kbdclass.sy_
C:\[u]0[/u]4716a85cafaab720152e9427e\i386\kbdfi1.dl_
C:\[u]0[/u]4716a85cafaab720152e9427e\i386\kbdhid.sy_
C:\[u]0[/u]4716a85cafaab720152e9427e\i386\kbdibm02.dl_
C:\[u]0[/u]4716a85cafaab720152e9427e\i386\kbdinbe1.dl_
C:\[u]0[/u]4716a85cafaab720152e9427e\i386\kbdinben.dl_
C:\[u]0[/u]4716a85cafaab720152e9427e\i386\kbdinmal.dl_
C:\[u]0[/u]4716a85cafaab720152e9427e\i386\kbdiultn.dl_
C:\[u]0[/u]4716a85cafaab720152e9427e\i386\kbdlk41a.dl_
C:\[u]0[/u]4716a85cafaab720152e9427e\i386\kbdlk41j.dl_
C:\[u]0[/u]4716a85cafaab720152e9427e\i386\kbdmaori.dl_
C:\[u]0[/u]4716a85cafaab720152e9427e\i386\kbdmlt47.dl_
C:\[u]0[/u]4716a85cafaab720152e9427e\i386\kbdmlt48.dl_
C:\[u]0[/u]4716a85cafaab720152e9427e\i386\kbdnec.dll
C:\[u]0[/u]4716a85cafaab720152e9427e\i386\kbdnepr.dl_
C:\[u]0[/u]4716a85cafaab720152e9427e\i386\kbdno1.dl_
C:\[u]0[/u]4716a85cafaab720152e9427e\i386\kbdpash.dl_
C:\[u]0[/u]4716a85cafaab720152e9427e\i386\kbdsmsfi.dl_
C:\[u]0[/u]4716a85cafaab720152e9427e\i386\kbdsmsno.dl_
C:\[u]0[/u]4716a85cafaab720152e9427e\i386\kbdukx.dl_
C:\[u]0[/u]4716a85cafaab720152e9427e\i386\kd1394.dl_
C:\[u]0[/u]4716a85cafaab720152e9427e\i386\kdcsvc.dl_
C:\[u]0[/u]4716a85cafaab720152e9427e\i386\kdsui.dl_
C:\[u]0[/u]4716a85cafaab720152e9427e\i386\kdsusd.dl_
C:\[u]0[/u]4716a85cafaab720152e9427e\i386\kerberos.dl_
C:\[u]0[/u]4716a85cafaab720152e9427e\i386\kernel32.dl_
C:\[u]0[/u]4716a85cafaab720152e9427e\i386\keybd.ht_
C:\[u]0[/u]4716a85cafaab720152e9427e\i386\keybdcmt.ht_
C:\[u]0[/u]4716a85cafaab720152e9427e\i386\keyboard.sy_
C:\[u]0[/u]4716a85cafaab720152e9427e\i386\keymgr.dl_
C:\[u]0[/u]4716a85cafaab720152e9427e\i386\kmddsp.ts_
C:\[u]0[/u]4716a85cafaab720152e9427e\i386\kmixer.sy_
C:\[u]0[/u]4716a85cafaab720152e9427e\i386\kmsvc.dl_
C:\[u]0[/u]4716a85cafaab720152e9427e\i386\knhowtok.chm
C:\[u]0[/u]4716a85cafaab720152e9427e\i386\knnewpk.chm
C:\[u]0[/u]4716a85cafaab720152e9427e\i386\knnewwk.chm
C:\[u]0[/u]4716a85cafaab720152e9427e\i386\knperdpc.dl_
C:\[u]0[/u]4716a85cafaab720152e9427e\i386\knperpid.dll
C:\[u]0[/u]4716a85cafaab720152e9427e\i386\knprodpc.dl_
C:\[u]0[/u]4716a85cafaab720152e9427e\i386\knpropid.dll
C:\[u]0[/u]4716a85cafaab720152e9427e\i386\knupdpk.chm
C:\[u]0[/u]4716a85cafaab720152e9427e\i386\knupdwk.chm
C:\[u]0[/u]4716a85cafaab720152e9427e\i386\koc.dl_
C:\[u]0[/u]4716a85cafaab720152e9427e\i386\kperdpc.dl_
C:\[u]0[/u]4716a85cafaab720152e9427e\i386\kperpid.dll
C:\[u]0[/u]4716a85cafaab720152e9427e\i386\kprodpc.dl_
C:\[u]0[/u]4716a85cafaab720152e9427e\i386\kpropid.dll
C:\[u]0[/u]4716a85cafaab720152e9427e\i386\krnl386.ex_
C:\[u]0[/u]4716a85cafaab720152e9427e\i386\krnlprov.dl_
C:\[u]0[/u]4716a85cafaab720152e9427e\i386\ks.sy_
C:\[u]0[/u]4716a85cafaab720152e9427e\i386\ksecdd.sys
C:\[u]0[/u]4716a85cafaab720152e9427e\i386\ksproxy.ax_
C:\[u]0[/u]4716a85cafaab720152e9427e\i386\kstvtune.ax_
C:\[u]0[/u]4716a85cafaab720152e9427e\i386\ksuser.dl_
C:\[u]0[/u]4716a85cafaab720152e9427e\i386\kswdmcap.ax_
C:\[u]0[/u]4716a85cafaab720152e9427e\i386\ksxbar.ax_
C:\[u]0[/u]4716a85cafaab720152e9427e\i386\l2store.dl_
C:\[u]0[/u]4716a85cafaab720152e9427e\i386\l3codeca.ac_
C:\[u]0[/u]4716a85cafaab720152e9427e\i386\lang\chajei.im_
C:\[u]0[/u]4716a85cafaab720152e9427e\i386\lang\chtmbx.dl_
C:\[u]0[/u]4716a85cafaab720152e9427e\i386\lang\chtskdic.dl_
C:\[u]0[/u]4716a85cafaab720152e9427e\i386\lang\chtskf.dl_
C:\[u]0[/u]4716a85cafaab720152e9427e\i386\lang\cintime.dl_
C:\[u]0[/u]4716a85cafaab720152e9427e\i386\lang\cintlgnt.im_
C:\[u]0[/u]4716a85cafaab720152e9427e\i386\lang\cintsetp.ex_
C:\[u]0[/u]4716a85cafaab720152e9427e\i386\lang\cplexe.ex_
C:\[u]0[/u]4716a85cafaab720152e9427e\i386\lang\dayi.im_
C:\[u]0[/u]4716a85cafaab720152e9427e\i386\lang\hwxjpn.dl_
C:\[u]0[/u]4716a85cafaab720152e9427e\i386\lang\imekr61.im_
C:\[u]0[/u]4716a85cafaab720152e9427e\i386\lang\imekrcic.dl_
C:\[u]0[/u]4716a85cafaab720152e9427e\i386\lang\imekrmbx.dl_
C:\[u]0[/u]4716a85cafaab720152e9427e\i386\lang\imjp81.im_
C:\[u]0[/u]4716a85cafaab720152e9427e\i386\lang\imjp81k.dl_
C:\[u]0[/u]4716a85cafaab720152e9427e\i386\lang\imjpcd.di_
C:\[u]0[/u]4716a85cafaab720152e9427e\i386\lang\imjpcic.dl_
C:\[u]0[/u]4716a85cafaab720152e9427e\i386\lang\imjpcus.dl_
C:\[u]0[/u]4716a85cafaab720152e9427e\i386\lang\imjpdct.dl_
C:\[u]0[/u]4716a85cafaab720152e9427e\i386\lang\imjpdct.ex_
C:\[u]0[/u]4716a85cafaab720152e9427e\i386\lang\imjpdsvr.ex_
C:\[u]0[/u]4716a85cafaab720152e9427e\i386\lang\imjpinst.ex_
C:\[u]0[/u]4716a85cafaab720152e9427e\i386\lang\imjpinst.in_
C:\[u]0[/u]4716a85cafaab720152e9427e\i386\lang\imjpmig.ex_
C:\[u]0[/u]4716a85cafaab720152e9427e\i386\lang\imjprw.ex_
C:\[u]0[/u]4716a85cafaab720152e9427e\i386\lang\imjputy.ex_
C:\[u]0[/u]4716a85cafaab720152e9427e\i386\lang\imjputyc.dl_
C:\[u]0[/u]4716a85cafaab720152e9427e\i386\lang\imlang.dl_
C:\[u]0[/u]4716a85cafaab720152e9427e\i386\lang\imscinst.ex_
C:\[u]0[/u]4716a85cafaab720152e9427e\i386\lang\imskf.dl_
C:\[u]0[/u]4716a85cafaab720152e9427e\i386\lang\miniime.tp_
C:\[u]0[/u]4716a85cafaab720152e9427e\i386\lang\padrs404.dl_
C:\[u]0[/u]4716a85cafaab720152e9427e\i386\lang\padrs804.dl_
C:\[u]0[/u]4716a85cafaab720152e9427e\i386\lang\phon.im_
C:\[u]0[/u]4716a85cafaab720152e9427e\i386\lang\pintlcsa.dl_
C:\[u]0[/u]4716a85cafaab720152e9427e\i386\lang\pintlcsd.di_
C:\[u]0[/u]4716a85cafaab720152e9427e\i386\lang\pintlcsd.dl_
C:\[u]0[/u]4716a85cafaab720152e9427e\i386\lang\pintlcsk.di_
C:\[u]0[/u]4716a85cafaab720152e9427e\i386\lang\pintlgc.im_
C:\[u]0[/u]4716a85cafaab720152e9427e\i386\lang\pintlgd.im_
C:\[u]0[/u]4716a85cafaab720152e9427e\i386\lang\pintlgdx.im_
C:\[u]0[/u]4716a85cafaab720152e9427e\i386\lang\pintlgi.im_
C:\[u]0[/u]4716a85cafaab720152e9427e\i386\lang\pintlgix.im_
C:\[u]0[/u]4716a85cafaab720152e9427e\i386\lang\pintlgl.im_
C:\[u]0[/u]4716a85cafaab720152e9427e\i386\lang\pintlgne.ch_
C:\[u]0[/u]4716a85cafaab720152e9427e\i386\lang\pintlgnt.ch_
C:\[u]0[/u]4716a85cafaab720152e9427e\i386\lang\pintlgnt.im_
C:\[u]0[/u]4716a85cafaab720152e9427e\i386\lang\pintlgr.im_
C:\[u]0[/u]4716a85cafaab720152e9427e\i386\lang\pintlgs.im_
C:\[u]0[/u]4716a85cafaab720152e9427e\i386\lang\pintlphr.ex_
C:\[u]0[/u]4716a85cafaab720152e9427e\i386\lang\pmigrate.dl_
C:\[u]0[/u]4716a85cafaab720152e9427e\i386\lang\quick.im_
C:\[u]0[/u]4716a85cafaab720152e9427e\i386\lang\romanime.im_
C:\[u]0[/u]4716a85cafaab720152e9427e\i386\lang\simsun.tt_
C:\[u]0[/u]4716a85cafaab720152e9427e\i386\lang\tintlgnt.im_
C:\[u]0[/u]4716a85cafaab720152e9427e\i386\lang\tintlphr.ex_
C:\[u]0[/u]4716a85cafaab720152e9427e\i386\lang\tintsetp.ex_
C:\[u]0[/u]4716a85cafaab720152e9427e\i386\lang\tmigrate.dl_
C:\[u]0[/u]4716a85cafaab720152e9427e\i386\lang\unicdime.im_
C:\[u]0[/u]4716a85cafaab720152e9427e\i386\lang\uniime.dl_
C:\[u]0[/u]4716a85cafaab720152e9427e\i386\lang\voicepad.dl_
C:\[u]0[/u]4716a85cafaab720152e9427e\i386\lang\voicesub.dl_
C:\[u]0[/u]4716a85cafaab720152e9427e\i386\lang\winar30.im_
C:\[u]0[/u]4716a85cafaab720152e9427e\i386\lang\wingb.im_
C:\[u]0[/u]4716a85cafaab720152e9427e\i386\lang\winime.im_
C:\[u]0[/u]4716a85cafaab720152e9427e\i386\lang\winpy.im_
C:\[u]0[/u]4716a85cafaab720152e9427e\i386\lang\winsp.im_
C:\[u]0[/u]4716a85cafaab720152e9427e\i386\lang\winzm.im_
C:\[u]0[/u]4716a85cafaab720152e9427e\i386\langbar.ch_
C:\[u]0[/u]4716a85cafaab720152e9427e\i386\lanpol.xs_
C:\[u]0[/u]4716a85cafaab720152e9427e\i386\lanv1.xs_
C:\[u]0[/u]4716a85cafaab720152e9427e\i386\laprxy.dl_
C:\[u]0[/u]4716a85cafaab720152e9427e\i386\lbrtfdc.sy_
C:\[u]0[/u]4716a85cafaab720152e9427e\i386\lcladvd.xm_
C:\[u]0[/u]4716a85cafaab720152e9427e\i386\lcldocs.xm_
C:\[u]0[/u]4716a85cafaab720152e9427e\i386\lclmm.xm_
C:\[u]0[/u]4716a85cafaab720152e9427e\i386\lhmstsc.ch_
C:\[u]0[/u]4716a85cafaab720152e9427e\i386\lhmstsc.ex_
C:\[u]0[/u]4716a85cafaab720152e9427e\i386\lhmstsc.mui
C:\[u]0[/u]4716a85cafaab720152e9427e\i386\lhmstscx.dl_
C:\[u]0[/u]4716a85cafaab720152e9427e\i386\lhmstscx.mu_
C:\[u]0[/u]4716a85cafaab720152e9427e\i386\lhrdesk.ch_
C:\[u]0[/u]4716a85cafaab720152e9427e\i386\licdll.dl_
C:\[u]0[/u]4716a85cafaab720152e9427e\i386\licdll.dll
C:\[u]0[/u]4716a85cafaab720152e9427e\i386\license.ch_
C:\[u]0[/u]4716a85cafaab720152e9427e\i386\licmgr10.dl_
C:\[u]0[/u]4716a85cafaab720152e9427e\i386\licwmi.dl_
C:\[u]0[/u]4716a85cafaab720152e9427e&
  • 0

#7
moshelby

moshelby

    New Member

  • Topic Starter
  • Member
  • Pip
  • 7 posts
So this combofix log isn't posting all in one go. I may be posting the wrong thing. When I ran combofix this morning, it gave a log report and then my computer froze up and wouldn't respond so I had to force restart. Let me know if I need to re-run combofix or just continuing posting this log in multiple posts. Here is my kaspersky log:
--------------------------------------------------------------------------------
KASPERSKY ONLINE SCANNER 7 REPORT
Monday, September 22, 2008
Operating System: Microsoft Windows XP Professional Service Pack 3 (build 2600)
Kaspersky Online Scanner 7 version: 7.0.25.0
Program database last update: Friday, August 22, 2008 18:44:27
Records in database: 1124860
--------------------------------------------------------------------------------

Scan settings:
Scan using the following database: extended
Scan archives: yes
Scan mail databases: yes

Scan area - My Computer:
C:\
D:\
E:\

Scan statistics:
Files scanned: 99806
Threat name: 2
Infected objects: 4
Suspicious objects: 0
Duration of the scan: 02:00:13


File name / Threat name / Threats count
C:\Documents and Settings\Owner\.jpi_cache\jar\1.0\jvmsecman.jar-69ee0e0e-1430ac2a.zip Infected: Trojan-Downloader.Java.Agent.f 1
C:\Documents and Settings\Owner\.jpi_cache\jar\1.0\jvmsecman.jar-69ee0e0e-4b4d405c.zip Infected: Trojan-Downloader.Java.Agent.f 1
C:\Documents and Settings\Owner\.jpi_cache\jar\1.0\jvmsecman.jar-6b26dca8-72ee1482.zip Infected: Trojan-Downloader.Java.Agent.f 1
C:\quarantine\Av-test.txt.Vir Infected: EICAR-Test-File 1

The selected area was scanned.
  • 0

#8
BHowett

BHowett

    OT Moderator

  • Moderator
  • 4,642 posts
Hello again,

Please do the following:


Combofix Script.txt

1. Please open Notepad
  • Click Start , then Run
  • Type notepad .exe in the Run Box.

2. Now copy/paste the entire content of the codebox below into the Notepad window:

File::
C:\Documents and Settings\Owner\.jpi_cache\jar\1.0\jvmsecman.jar-69ee0e0e-1430ac2a.zip 
C:\Documents and Settings\Owner\.jpi_cache\jar\1.0\jvmsecman.jar-69ee0e0e-4b4d405c.zip 
C:\Documents and Settings\Owner\.jpi_cache\jar\1.0\jvmsecman.jar-6b26dca8-72ee1482.zip


3. Save the above as CFScript.txt

4. Then drag the CFScript.txt into ComboFix.exe as depicted in the animation below. This will start ComboFix again.

Posted Image


5. After reboot, (in case it asks to reboot), please post the following reports/logs into your next reply:
  • Combofix.txt .
  • HijackThis log .

Also let me know how things are running now?
  • 0

#9
moshelby

moshelby

    New Member

  • Topic Starter
  • Member
  • Pip
  • 7 posts
The computer is running better than it was, more smoothly.
Combofix:
ComboFix 08-08-21.02 - Owner 2008-08-22 23:51:17.5 - NTFSx86
Microsoft Windows XP Professional 5.1.2600.3.1252.1.1033.18.567 [GMT -5:00]
Running from: C:\Documents and Settings\Owner\Desktop\ComboFix.exe
Command switches used :: C:\Documents and Settings\Owner\Desktop\cfscript.txt
* Created a new restore point

FILE ::
C:\Documents and Settings\Owner\.jpi_cache\jar\1.0\jvmsecman.jar-69ee0e0e-1430ac2a.zip
C:\Documents and Settings\Owner\.jpi_cache\jar\1.0\jvmsecman.jar-69ee0e0e-4b4d405c.zip
C:\Documents and Settings\Owner\.jpi_cache\jar\1.0\jvmsecman.jar-6b26dca8-72ee1482.zip
.

((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.

C:\Documents and Settings\Owner\.jpi_cache\jar\1.0\jvmsecman.jar-69ee0e0e-1430ac2a.zip
C:\Documents and Settings\Owner\.jpi_cache\jar\1.0\jvmsecman.jar-69ee0e0e-4b4d405c.zip
C:\Documents and Settings\Owner\.jpi_cache\jar\1.0\jvmsecman.jar-6b26dca8-72ee1482.zip

.
((((((((((((((((((((((((( Files Created from 2008-07-23 to 2008-08-23 )))))))))))))))))))))))))))))))
.

2008-09-16 03:02 . 2008-09-16 03:02 <DIR> d-------- C:\Program Files\Microsoft CAPICOM 2.1.0.2
2008-09-15 21:30 . 2008-07-18 22:07 270,880 --a------ C:\WINDOWS\system32\mucltui.dll
2008-09-15 21:30 . 2008-07-18 22:07 29,728 --a------ C:\WINDOWS\system32\mucltui.dll.mui
2008-09-15 17:12 . 2008-09-15 17:12 <DIR> d-------- C:\Program Files\Malwarebytes' Anti-Malware
2008-09-15 17:12 . 2008-07-30 20:07 38,472 --a------ C:\WINDOWS\system32\drivers\mbamswissarmy.sys
2008-09-15 17:12 . 2008-07-30 20:07 17,144 --a------ C:\WINDOWS\system32\drivers\mbam.sys
2008-09-14 12:34 . 2008-05-01 09:33 331,776 -----c--- C:\WINDOWS\system32\dllcache\msadce.dll
2008-09-14 12:33 . 2008-04-11 14:04 691,712 -----c--- C:\WINDOWS\system32\dllcache\inetcomm.dll
2008-08-15 19:19 . 2008-08-15 19:19 <DIR> d-------- C:\WINDOWS\system32\scripting
2008-08-15 19:19 . 2008-08-15 19:19 <DIR> d-------- C:\WINDOWS\system32\en
2008-08-15 19:19 . 2008-08-15 19:19 <DIR> d-------- C:\WINDOWS\system32\bits
2008-08-15 19:19 . 2008-08-15 19:19 <DIR> d-------- C:\WINDOWS\l2schemas
2008-08-15 19:04 . 2008-08-15 19:21 <DIR> d-------- C:\WINDOWS\ServicePackFiles
2008-08-15 18:32 . 2004-08-03 22:41 404,990 --------- C:\WINDOWS\system32\drivers\slntamr.sys
2008-08-15 18:31 . 2008-04-13 19:12 412,160 --------- C:\WINDOWS\system32\photometadatahandler.dll
2008-08-15 18:30 . 2008-04-13 19:12 1,737,856 --------- C:\WINDOWS\system32\mtxparhd.dll
2008-08-15 18:29 . 2008-04-13 19:11 61,440 --------- C:\WINDOWS\system32\kmsvc.dll
2008-08-15 18:29 . 2008-04-13 19:11 37,376 --------- C:\WINDOWS\system32\l2gpstore.dll
2008-08-15 18:29 . 2008-04-13 19:09 6,144 --------- C:\WINDOWS\system32\kbdpash.dll
2008-08-15 18:29 . 2008-04-13 19:09 6,144 --------- C:\WINDOWS\system32\kbdnepr.dll
2008-08-15 18:29 . 2008-04-13 19:09 6,144 --------- C:\WINDOWS\system32\kbdiultn.dll
2008-08-15 18:29 . 2008-04-13 19:09 6,144 --------- C:\WINDOWS\system32\kbdbhc.dll
2008-08-15 18:27 . 2008-04-13 19:11 1,888,992 --------- C:\WINDOWS\system32\ati3duag.dll
2008-08-15 18:26 . 2008-04-13 19:11 136,192 --------- C:\WINDOWS\system32\aaclient.dll
2008-08-15 18:26 . 2008-04-13 13:36 44,928 --------- C:\WINDOWS\system32\drivers\agpcpq.sys
2008-08-15 18:26 . 2008-04-13 13:36 42,368 --------- C:\WINDOWS\system32\drivers\agp440.sys
2008-08-15 18:26 . 2008-04-13 19:11 4,255 --------- C:\WINDOWS\system32\drivers\adv01nt5.dll
2008-08-15 18:26 . 2008-04-13 19:11 3,967 --------- C:\WINDOWS\system32\drivers\adv02nt5.dll
2008-08-15 18:26 . 2008-04-13 19:11 3,775 --------- C:\WINDOWS\system32\drivers\adv11nt5.dll
2008-08-15 18:26 . 2008-04-13 19:11 3,711 --------- C:\WINDOWS\system32\drivers\adv09nt5.dll
2008-08-15 18:26 . 2008-04-13 19:11 3,647 --------- C:\WINDOWS\system32\drivers\adv07nt5.dll
2008-08-15 18:26 . 2008-04-13 19:11 3,615 --------- C:\WINDOWS\system32\drivers\adv05nt5.dll
2008-08-15 18:26 . 2008-04-13 19:11 3,135 --------- C:\WINDOWS\system32\drivers\adv08nt5.dll

.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2008-09-16 08:19 --------- d-----w C:\Program Files\Steam
2008-09-15 22:12 --------- d-----w C:\Program Files\Common Files\Download Manager
2008-09-15 22:12 --------- d-----w C:\Documents and Settings\Owner\Application Data\Malwarebytes
2008-09-15 22:12 --------- d-----w C:\Documents and Settings\All Users\Application Data\Malwarebytes
2008-08-15 22:39 --------- d-----w C:\Program Files\Java
2008-08-03 23:52 --------- d-----w C:\Documents and Settings\Owner\Application Data\AdobeUM
2008-07-19 03:10 94,920 ----a-w C:\WINDOWS\system32\cdm.dll
2008-07-19 03:10 53,448 ----a-w C:\WINDOWS\system32\wuauclt.exe
2008-07-19 03:10 45,768 ----a-w C:\WINDOWS\system32\wups2.dll
2008-07-19 03:10 36,552 ----a-w C:\WINDOWS\system32\wups.dll
2008-07-19 03:09 563,912 ----a-w C:\WINDOWS\system32\wuapi.dll
2008-07-19 03:09 325,832 ----a-w C:\WINDOWS\system32\wucltui.dll
2008-07-19 03:09 205,000 ----a-w C:\WINDOWS\system32\wuweb.dll
2008-07-19 03:09 1,811,656 ----a-w C:\WINDOWS\system32\wuaueng.dll
2008-07-19 03:07 210,976 ----a-w C:\WINDOWS\system32\muweb.dll
2008-07-07 20:26 253,952 ----a-w C:\WINDOWS\system32\es.dll
2008-06-24 16:43 74,240 ----a-w C:\WINDOWS\system32\mscms.dll
2008-06-24 16:43 74,240 ------w C:\WINDOWS\system32\SET176D.tmp
2008-06-23 16:57 826,368 ----a-w C:\WINDOWS\system32\wininet.dll
2008-06-20 17:46 245,248 ----a-w C:\WINDOWS\system32\mswsock.dll
.

((((((((((((((((((((((((((((( snapshot_2008-08-22_12.42.58.45 )))))))))))))))))))))))))))))))))))))))))
.
- 2007-07-31 00:18:40 33,624 -c--a-w C:\WINDOWS\system32\dllcache\wups.dll
+ 2008-07-19 03:10:20 36,552 -c--a-w C:\WINDOWS\system32\dllcache\wups.dll
- 2008-09-16 08:10:27 227,208 ----a-w C:\WINDOWS\system32\FNTCACHE.DAT
+ 2008-08-22 17:51:03 227,208 ----a-w C:\WINDOWS\system32\FNTCACHE.DAT
+ 2008-08-22 17:51:12 16,384 ----atw C:\WINDOWS\Temp\Perflib_Perfdata_478.dat
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"OM_Monitor"="C:\Program Files\OLYMPUS\OLYMPUS Master\Monitor.exe" [2006-05-16 17:51 57344]
"ctfmon.exe"="C:\WINDOWS\system32\ctfmon.exe" [2008-04-13 19:12 15360]
"updateMgr"="C:\Program Files\Adobe\Acrobat 7.0\Reader\AdobeUpdateManager.exe" [2006-03-30 17:45 313472]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"SonyPowerCfg"="C:\Program Files\Sony\VAIO Power Management\SPMgr.exe" [2006-06-27 20:24 217088]
"ISBMgr.exe"="C:\Program Files\Sony\ISB Utility\ISBMgr.exe" [2004-02-20 16:12 32768]
"VAIO Update 2"="C:\Program Files\Sony\VAIO Update 2\VAIOUpdt.exe" [2005-10-11 23:36 151552]
"Switcher.exe"="C:\Program Files\Sony\Wireless Switch Setting Utility\Switcher.exe" [2006-02-14 14:11 176128]
"VAIOCameraUtility"="C:\Program Files\Sony\VAIO Camera Utility\VCUServe.exe" [2005-12-27 15:58 69632]
"SunJavaUpdateSched"="C:\Program Files\Java\jre1.5.0_07\bin\jusched.exe" [2006-05-03 04:56 36975]
"StatusClient"="C:\Program Files\Hewlett-Packard\Toolbox2.0\Apache Tomcat 4.0\webapps\Toolbox\StatusClient\StatusClient.exe" [2002-12-16 17:51 36864]
"TomcatStartup"="C:\Program Files\Hewlett-Packard\Toolbox2.0\hpbpsttp.exe" [2003-03-31 20:28 155648]
"McAfeeUpdaterUI"="C:\Program Files\Network Associates\Common Framework\UpdaterUI.exe" [2005-12-07 04:55 131072]
"ShStatEXE"="C:\Program Files\Network Associates\VirusScan\SHSTAT.EXE" [2004-09-22 09:00 94208]
"Network Associates Error Reporting Service"="C:\Program Files\Common Files\Network Associates\TalkBack\tbmon.exe" [2003-10-07 10:48 147514]
"OM_Monitor"="C:\Program Files\OLYMPUS\OLYMPUS Master\FirstStart.exe" [2006-05-16 17:50 40960]
"SmcService"="C:\PROGRA~1\Sygate\SPF\smc.exe" [2004-10-15 19:40 2577632]
"NvCplDaemon"="C:\WINDOWS\system32\NvCpl.dll" [2006-05-08 12:50 7561216]
"igfxtray"="C:\WINDOWS\system32\igfxtray.exe" [2006-10-06 13:11 98304]
"igfxpers"="C:\WINDOWS\system32\igfxpers.exe" [2006-10-06 13:10 94208]
"igfxhkcmd"="C:\WINDOWS\system32\hkcmd.exe" [2006-10-06 13:13 114688]
"HostManager"="C:\Program Files\Common Files\AOL\1154548953\ee\AOLSoftware.exe" [2006-04-13 15:36 50792]
"ehTray"="C:\WINDOWS\ehome\ehtray.exe" [2005-08-05 15:56 64512]
"Apoint"="C:\Program Files\Apoint\Apoint.exe" [2004-11-17 22:47 118784]
"SpySweeper"="C:\Program Files\Webroot\Spy Sweeper\SpySweeperUI.exe" [2008-01-04 21:56 5367664]
"Mouse Suite 98 Daemon"="ICO.EXE" [2002-03-14 18:46 45056 C:\WINDOWS\system32\ico.exe]

C:\Documents and Settings\All Users\Start Menu\Programs\Startup\
Microsoft Office.lnk - C:\Program Files\Microsoft Office\Office10\OSA.EXE [2001-02-13 02:01:04 83360]

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"InstallVisualStyle"= C:\WINDOWS\Resources\Themes\Royale\Royale.msstyles
"InstallTheme"= C:\WINDOWS\Resources\Themes\Royale.theme

[hkey_local_machine\software\microsoft\windows\currentversion\explorer\ShellExecuteHooks]
"{03A80B1D-5C6A-42c2-9DFB-81B6005D8023}"= "C:\Program Files\Trend Micro\Tmas\sshook.dll" [2006-08-02 15:15 77824]

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\VESWinlogon]
2006-03-09 16:51 73728 C:\WINDOWS\system32\VESWinlogon.dll

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\drivers32]
"VIDC.dvsd"= C:\PROGRA~1\COMMON~1\SONYSH~1\VideoLib\sonydv.dll
"VIDC.MJPG"= pvmjpg21.dll

[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Adobe Reader Speed Launch.lnk]
path=C:\Documents and Settings\All Users\Start Menu\Programs\Startup\Adobe Reader Speed Launch.lnk
backup=C:\WINDOWS\pss\Adobe Reader Speed Launch.lnkCommon Startup

[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Trend Micro Anti-Spyware.lnk]
path=C:\Documents and Settings\All Users\Start Menu\Programs\Startup\Trend Micro Anti-Spyware.lnk
backup=C:\WINDOWS\pss\Trend Micro Anti-Spyware.lnkCommon Startup

[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^WinZip Quick Pick.lnk]
path=C:\Documents and Settings\All Users\Start Menu\Programs\Startup\WinZip Quick Pick.lnk
backup=C:\WINDOWS\pss\WinZip Quick Pick.lnkCommon Startup

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\DISCover]
--a------ 2006-06-01 19:55 1077248 C:\Program Files\DISC\DISCover.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\iTunesHelper]
--a------ 2007-09-26 14:42 267064 C:\Program Files\iTunes\iTunesHelper.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\MSMSGS]
--------- 2008-04-13 19:12 1695232 C:\Program Files\Messenger\msmsgs.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\NapsterShell]
--a------ 2006-06-29 16:17 319488 C:\Program Files\Napster\napster.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\QuickTime Task]
--a------ 2007-06-29 06:24 286720 C:\Program Files\QuickTime\QTTask.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Steam]
--a------ 2008-08-02 18:03 1271032 C:\Program Files\Steam\steam.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\WMPNSCFG]
--------- 2006-10-18 21:05 204288 C:\Program Files\Windows Media Player\wmpnscfg.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\services]
"ccSetMgr"=2 (0x2)
"SPBBCSvc"=2 (0x2)
"ccProxy"=2 (0x2)
"SNDSrvc"=2 (0x2)
"ccISPwdSvc"=3 (0x3)
"ccEvtMgr"=2 (0x2)
"Symantec Core LC"=2 (0x2)
"SAVScan"=3 (0x3)
"NSCService"=3 (0x3)
"navapsvc"=2 (0x2)

[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecAntiVirus]
"DisableMonitoring"=dword:00000001

[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecFirewall]
"DisableMonitoring"=dword:00000001

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"C:\\Program Files\\Hewlett-Packard\\Toolbox2.0\\Javasoft\\JRE\\1.3.1\\bin\\javaw.exe"=
"C:\\Program Files\\AIM\\aim.exe"=
"C:\\Program Files\\iTunes\\iTunes.exe"=
"C:\\Program Files\\Microsoft Games\\Age of Empires II\\age2_x1\\age2_x1.icd"=
"C:\\Program Files\\Bonjour\\mDNSResponder.exe"=
"C:\\Program Files\\EA Games\\The Battle for Middle-earth ™\\game.dat"=
"C:\\Program Files\\Steam\\steamapps\\moshelby\\counter-strike source\\hl2.exe"=
"C:\\Program Files\\Electronic Arts\\The Battle for Middle-earth ™ II\\game.dat"=
"C:\\Program Files\\DISC\\DiscStreamHub.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"%windir%\\system32\\sessmgr.exe"=

R2 MSSQL$VAIO_VEDB;MSSQL$VAIO_VEDB;C:\Program Files\Microsoft SQL Server\MSSQL$VAIO_VEDB\Binn\sqlservr.exe [2002-12-17 19:26]
R3 SonyImgF;Sony Image Conversion Filter Driver;C:\WINDOWS\system32\DRIVERS\SonyImgF.sys [2006-03-06 21:39]
R3 ti21sony;ti21sony;C:\WINDOWS\system32\drivers\ti21sony.sys [2006-02-21 21:32]
S3 bfastfao;bfastfao;C:\DOCUME~1\Owner\LOCALS~1\Temp\bfastfao.sys []
S3 EraserUtilDrv10633;EraserUtilDrv10633;C:\Program Files\Common Files\Symantec Shared\EENGINE\EraserUtilDrv10633.sys []
S3 Image Converter video recording monitor for VAIO Entertainment;Image Converter video recording monitor for VAIO Entertainment;C:\Program Files\Sony\Image Converter 2\IcVzMon.exe [2005-07-14 21:10]
S3 pelmouse;Mouse Suite Driver;C:\WINDOWS\system32\DRIVERS\pelmouse.sys [2002-06-28 20:21]
S3 pelusblf;USB Mouse Low Filter Driver;C:\WINDOWS\system32\DRIVERS\pelusblf.sys [2001-07-24 12:34]
S3 SQLAgent$VAIO_VEDB;SQLAgent$VAIO_VEDB;C:\Program Files\Microsoft SQL Server\MSSQL$VAIO_VEDB\Binn\sqlagent.EXE [2002-12-17 19:23]

[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{d8435c48-225e-11db-b383-806d6172696f}]
\Shell\AutoRun\command - E:\sony\Autorun.exe

*Newly Created Service* - ENTDRV51
.
Contents of the 'Scheduled Tasks' folder

2008-09-19 C:\WINDOWS\Tasks\AppleSoftwareUpdate.job
- C:\Program Files\Apple Software Update\SoftwareUpdate.exe [2007-08-29 14:57]

2008-09-22 C:\WINDOWS\Tasks\wrSpySweeperTrialSweep.job
- C:\Program Files\Webroot\Spy Sweeper\SpySweeperUI.exe [2008-01-04 21:56]

2008-09-22 C:\WINDOWS\Tasks\wrSpySweeperTrialSweep.job
- C:\Program Files\Webroot\Spy Sweeper\SpySweeperUI.exe [2008-01-04 21:56]

2008-09-22 C:\WINDOWS\Tasks\wrSpySweeperTrialSweep.job
- C:\","D:\","E:\" []
.

**************************************************************************

catchme 0.3.1361 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2008-08-22 23:55:07
Windows 5.1.2600 Service Pack 3 NTFS

scanning hidden processes ...

scanning hidden autostart entries ...

scanning hidden files ...

scan completed successfully
hidden files: 0

**************************************************************************

[HKEY_LOCAL_MACHINE\system\ControlSet001\Services\vsdatant]
"ImagePath"=""
.
Completion time: 2008-08-22 23:57:14
ComboFix-quarantined-files.txt 2008-08-23 04:56:41
ComboFix2.txt 2008-08-22 17:44:09
ComboFix3.txt 2008-08-20 16:46:53

Pre-Run: 55,491,944,448 bytes free
Post-Run: 55,568,932,864 bytes free

219 --- E O F --- 2008-09-21 08:06:16



And Hijackthis:
Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 11:59:23 PM, on 8/22/2008
Platform: Windows XP SP3 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16705)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Intel\Wireless\Bin\EvtEng.exe
C:\Program Files\Intel\Wireless\Bin\S24EvMon.exe
C:\Program Files\Sygate\SPF\smc.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Lavasoft\Ad-Aware 2007\aawservice.exe
C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
C:\WINDOWS\system32\bgsvcgen.exe
C:\Program Files\Bonjour\mDNSResponder.exe
C:\WINDOWS\eHome\ehRecvr.exe
C:\WINDOWS\eHome\ehSched.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Network Associates\Common Framework\FrameworkService.exe
C:\Program Files\Network Associates\VirusScan\mcshield.exe
C:\Program Files\Network Associates\VirusScan\vstskmgr.exe
C:\Program Files\Microsoft SQL Server\MSSQL$VAIO_VEDB\Binn\sqlservr.exe
C:\Program Files\Intel\Wireless\Bin\RegSrvc.exe
C:\Program Files\Common Files\Sony Shared\WMPlugIn\SonicStageMonitoring.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Sony\VAIO Event Service\VESMgr.exe
C:\Program Files\Common Files\Sony Shared\VAIO Entertainment Platform\VCSW\VCSW.exe
C:\Program Files\Webroot\Spy Sweeper\SpySweeper.exe
C:\Program Files\Common Files\Sony Shared\VAIO Entertainment Platform\VzCdb\VzCdbSvc.exe
C:\Program Files\Common Files\Sony Shared\VAIO Entertainment Platform\VzCdb\VzFw.exe
C:\WINDOWS\system32\dllhost.exe
C:\Program Files\Sony\VAIO Power Management\SPMgr.exe
C:\Program Files\Sony\ISB Utility\ISBMgr.exe
C:\Program Files\Sony\VAIO Update 2\VAIOUpdt.exe
C:\Program Files\Sony\Wireless Switch Setting Utility\Switcher.exe
C:\Program Files\Sony\VAIO Camera Utility\VCUServe.exe
C:\Program Files\Java\jre1.5.0_07\bin\jusched.exe
C:\Program Files\Hewlett-Packard\Toolbox2.0\Apache Tomcat 4.0\webapps\Toolbox\StatusClient\StatusClient.exe
C:\Program Files\Network Associates\Common Framework\UpdaterUI.exe
C:\Program Files\Network Associates\VirusScan\SHSTAT.EXE
C:\Program Files\Common Files\Network Associates\TalkBack\tbmon.exe
C:\WINDOWS\system32\ICO.EXE
C:\WINDOWS\system32\igfxtray.exe
C:\WINDOWS\system32\igfxpers.exe
C:\WINDOWS\system32\hkcmd.exe
C:\Program Files\Common Files\AOL\1154548953\ee\AOLSoftware.exe
C:\WINDOWS\ehome\ehtray.exe
C:\Program Files\Apoint\Apoint.exe
C:\WINDOWS\eHome\ehmsas.exe
C:\Program Files\Hewlett-Packard\Toolbox2.0\Javasoft\JRE\1.3.1\bin\javaw.exe
C:\Program Files\Webroot\Spy Sweeper\SpySweeperUI.exe
C:\Program Files\Apoint\Apntex.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Webroot\Spy Sweeper\SSU.EXE
C:\WINDOWS\system32\wscntfy.exe
C:\Program Files\AIM\aim.exe
C:\WINDOWS\explorer.exe
C:\Program Files\internet explorer\iexplore.exe
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.sony.com/vaiopeople
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft....k/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft....k/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft....k/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft....k/?LinkId=69157
R3 - URLSearchHook: AOLSearchHook Class - {54EB34EA-E6BE-4CFD-9F4F-C4A0C2EAFA22} - C:\Program Files\AOL\AOL Search Enhancement\AOLSearch.dll
N3 - Netscape 7: user_pref("browser.search.defaultengine", "engine://C%3A%5CProgram%20Files%5CNetscape%5CNetscape%5Csearchplugins%5CSBWeb_01.src"); (C:\Documents and Settings\OWNER\Application Data\Mozilla\Profiles\default\twwsfut9.slt\prefs.js)
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
O2 - BHO: AOL Search Enhancement - {54EB34EA-E6BE-4CFD-9F4F-C4A0C2EAFA22} - C:\Program Files\AOL\AOL Search Enhancement\AOLSearch.dll
O2 - BHO: AOL Toolbar Launcher - {7C554162-8CB7-45A4-B8F4-8EA1C75885F9} - C:\Program Files\AOL\AOL Toolbar 3.0\aoltb.dll
O3 - Toolbar: AOL Toolbar - {DE9C389F-3316-41A7-809B-AA305ED9D922} - C:\Program Files\AOL\AOL Toolbar 3.0\aoltb.dll
O4 - HKLM\..\Run: [SonyPowerCfg] "C:\Program Files\Sony\VAIO Power Management\SPMgr.exe"
O4 - HKLM\..\Run: [ISBMgr.exe] "C:\Program Files\Sony\ISB Utility\ISBMgr.exe"
O4 - HKLM\..\Run: [VAIO Update 2] "C:\Program Files\Sony\VAIO Update 2\VAIOUpdt.exe" /Stationary
O4 - HKLM\..\Run: [Switcher.exe] "C:\Program Files\Sony\Wireless Switch Setting Utility\Switcher.exe"
O4 - HKLM\..\Run: [VAIOCameraUtility] "C:\Program Files\Sony\VAIO Camera Utility\VCUServe.exe"
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.5.0_07\bin\jusched.exe"
O4 - HKLM\..\Run: [StatusClient] "C:\Program Files\Hewlett-Packard\Toolbox2.0\Apache Tomcat 4.0\webapps\Toolbox\StatusClient\StatusClient.exe" /auto
O4 - HKLM\..\Run: [TomcatStartup] "C:\Program Files\Hewlett-Packard\Toolbox2.0\hpbpsttp.exe"
O4 - HKLM\..\Run: [McAfeeUpdaterUI] "C:\Program Files\Network Associates\Common Framework\UpdaterUI.exe" /StartedFromRunKey
O4 - HKLM\..\Run: [ShStatEXE] "C:\Program Files\Network Associates\VirusScan\SHSTAT.EXE" /STANDALONE
O4 - HKLM\..\Run: [Network Associates Error Reporting Service] "C:\Program Files\Common Files\Network Associates\TalkBack\tbmon.exe"
O4 - HKLM\..\Run: [OM_Monitor] "C:\Program Files\OLYMPUS\OLYMPUS Master\FirstStart.exe"
O4 - HKLM\..\Run: [SmcService] "C:\PROGRA~1\Sygate\SPF\smc.exe" -startgui
O4 - HKLM\..\Run: [NvCplDaemon] "RUNDLL32.EXE" C:\WINDOWS\system32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [Mouse Suite 98 Daemon] ICO.EXE
O4 - HKLM\..\Run: [igfxtray] C:\WINDOWS\system32\igfxtray.exe
O4 - HKLM\..\Run: [igfxpers] C:\WINDOWS\system32\igfxpers.exe
O4 - HKLM\..\Run: [igfxhkcmd] C:\WINDOWS\system32\hkcmd.exe
O4 - HKLM\..\Run: [HostManager] "C:\Program Files\Common Files\AOL\1154548953\ee\AOLSoftware.exe"
O4 - HKLM\..\Run: [ehTray] C:\WINDOWS\ehome\ehtray.exe
O4 - HKLM\..\Run: [Apoint] "C:\Program Files\Apoint\Apoint.exe"
O4 - HKLM\..\Run: [SpySweeper] "C:\Program Files\Webroot\Spy Sweeper\SpySweeperUI.exe" /startintray
O4 - HKCU\..\Run: [OM_Monitor] "C:\Program Files\OLYMPUS\OLYMPUS Master\Monitor.exe" -NoStart
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [updateMgr] "C:\Program Files\Adobe\Acrobat 7.0\Reader\AdobeUpdateManager.exe" AcRdB7_0_9 -reboot 1
O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office10\OSA.EXE
O8 - Extra context menu item: &AOL Toolbar Search - c:\program files\aol\aol toolbar 3.0\resources\en-US\local\search.html
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~4\Office10\EXCEL.EXE/3000
O9 - Extra button: AOL Toolbar - {3369AF0D-62E9-4bda-8103-B4C75499B578} - C:\Program Files\AOL\AOL Toolbar 3.0\aoltb.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~4\OFFICE11\REFIEBAR.DLL
O9 - Extra button: AIM - {AC9E2541-2814-11d5-BC6D-00B0D0A1DE45} - C:\Program Files\AIM\aim.exe
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O14 - IERESET.INF: START_PAGE_URL=http://www.sony.com/vaiopeople
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://update.micros...b?1160787064059
O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - http://www.update.mi...b?1218849171063
O16 - DPF: {9600F64D-755F-11D4-A47F-0001023E6D5A} (Shutterfly Picture Upload Plugin) - http://web1.shutterf...ds/Uploader.cab
O23 - Service: Ad-Aware 2007 Service (aawservice) - Lavasoft AB - C:\Program Files\Lavasoft\Ad-Aware 2007\aawservice.exe
O23 - Service: Apple Mobile Device - Apple, Inc. - C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
O23 - Service: B's Recorder GOLD Library General Service (bgsvcgen) - B.H.A Corporation - C:\WINDOWS\system32\bgsvcgen.exe
O23 - Service: Bonjour Service - Apple Computer, Inc. - C:\Program Files\Bonjour\mDNSResponder.exe
O23 - Service: Intel® PROSet/Wireless Event Log (EvtEng) - Intel Corporation - C:\Program Files\Intel\Wireless\Bin\EvtEng.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: Image Converter video recording monitor for VAIO Entertainment - Sony Corporation - C:\Program Files\Sony\Image Converter 2\IcVzMon.exe
O23 - Service: iPod Service - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: McAfee Framework Service (McAfeeFramework) - McAfee, Inc. - C:\Program Files\Network Associates\Common Framework\FrameworkService.exe
O23 - Service: Network Associates McShield (McShield) - Network Associates, Inc. - C:\Program Files\Network Associates\VirusScan\mcshield.exe
O23 - Service: Network Associates Task Manager (McTaskManager) - Network Associates, Inc. - C:\Program Files\Network Associates\VirusScan\vstskmgr.exe
O23 - Service: MSCSPTISRV - Sony Corporation - C:\Program Files\Common Files\Sony Shared\AVLib\MSCSPTISRV.exe
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe
O23 - Service: PACSPTISVR - Sony Corporation - C:\Program Files\Common Files\Sony Shared\AVLib\PACSPTISVR.exe
O23 - Service: Pml Driver HPZ12 - HP - C:\WINDOWS\system32\HPZipm12.exe
O23 - Service: Intel® PROSet/Wireless Registry Service (RegSrvc) - Intel Corporation - C:\Program Files\Intel\Wireless\Bin\RegSrvc.exe
O23 - Service: Intel® PROSet/Wireless Service (S24EventMonitor) - Intel Corporation - C:\Program Files\Intel\Wireless\Bin\S24EvMon.exe
O23 - Service: Sygate Personal Firewall (SmcService) - Sygate Technologies, Inc. - C:\Program Files\Sygate\SPF\smc.exe
O23 - Service: SonicStageMonitoring - Sony Corporation - C:\Program Files\Common Files\Sony Shared\WMPlugIn\SonicStageMonitoring.exe
O23 - Service: Sony SPTI Service (SPTISRV) - Sony Corporation - C:\Program Files\Common Files\Sony Shared\AVLib\SPTISRV.exe
O23 - Service: SonicStage SCSI Service (SSScsiSV) - Sony Corporation - C:\Program Files\Common Files\Sony Shared\AVLib\SSScsiSV.exe
O23 - Service: VAIO Entertainment TV Device Arbitration Service - Sony Corporation - C:\Program Files\Common Files\Sony Shared\VAIO Entertainment Platform\VzCs\VzHardwareResourceManager\VzHardwareResourceManager.exe
O23 - Service: VAIO Event Service - Sony Corporation - C:\Program Files\Sony\VAIO Event Service\VESMgr.exe
O23 - Service: VAIO Media Integrated Server (VAIOMediaPlatform-IntegratedServer-AppServer) - Sony Corporation - C:\Program Files\Sony\VAIO Media Integrated Server\VMISrv.exe
O23 - Service: VAIO Media Integrated Server (HTTP) (VAIOMediaPlatform-IntegratedServer-HTTP) - Sony Corporation - C:\Program Files\Sony\VAIO Media Integrated Server\Platform\SV_Httpd.exe
O23 - Service: VAIO Media Integrated Server (UPnP) (VAIOMediaPlatform-IntegratedServer-UPnP) - Sony Corporation - C:\Program Files\Sony\VAIO Media Integrated Server\Platform\UPnPFramework.exe
O23 - Service: VAIO Media Gateway Server (VAIOMediaPlatform-Mobile-Gateway) - Sony Corporation - C:\Program Files\Sony\VAIO Media Integrated Server\Platform\VmGateway.exe
O23 - Service: VAIO Entertainment UPnP Client Adapter (Vcsw) - Sony Corporation - C:\Program Files\Common Files\Sony Shared\VAIO Entertainment Platform\VCSW\VCSW.exe
O23 - Service: VAIO Entertainment Database Service (VzCdbSvc) - Sony Corporation - C:\Program Files\Common Files\Sony Shared\VAIO Entertainment Platform\VzCdb\VzCdbSvc.exe
O23 - Service: VAIO Entertainment File Import Service (VzFw) - Sony Corporation - C:\Program Files\Common Files\Sony Shared\VAIO Entertainment Platform\VzCdb\VzFw.exe
O23 - Service: Webroot Spy Sweeper Engine (WebrootSpySweeperService) - Webroot Software, Inc. - C:\Program Files\Webroot\Spy Sweeper\SpySweeper.exe

--
End of file - 12907 bytes
  • 0

#10
BHowett

BHowett

    OT Moderator

  • Moderator
  • 4,642 posts
Hi moshelby,

Your logs are looking good :)

ComboFix Removal
Follow these steps to uninstall Combofix and tools used in the removal of malware
  • Click START then RUN
  • Now type Combofix /u in the runbox and click OK. Note the space between the X and the U, it needs to be there.
    Posted Image

===============================================

This is my standard post for when you are clear - which you now are - or seem to be. Please advise me of any problems you still have. . I know you already have some of these items like antivirus or firewall, but I like to include them anyway incase you ever need them or want to change them.

Now that you are clean, please follow these simple steps in order to keep your computer clean and secure:

Posted Image 1.) Watch what you download!
Many freeware programs, and P2P programs like Grokster, Imesh, Kazaa and others are amongst the most notorious, come with an enormous amount of bundled spyware that will eat system resources, slow down your system, clash with other installed software, or just plain crash your browser or even Windows itself. If you insist on using a P2P program, please read This Article written by Mike Healan of Spywareinfo.com fame. It is an updated and comprehensive article that gives in-depth detail about which P2P programs are "safe" to use.

Posted Image 2.) Go to Intenet Explorer > Tools > Windows Update > Product Updates, and install ALL High-Priority Security Updates listed. If you're running Windows XP, that of course includes the Service Pack 2! If you suspect your computer is infected with Malware of any type, we advise you to not install SP2 if you don't already have it. You can post a HijackThis log on our Forums to get free Expert help cleaning your machine. Once you are sure you have a clean system, it is highly recommended to install SP2 to help prevent against future infections.

It's important to always keep current with the latest security fixes from Microsoft.
Install those patches for Internet Explorer, and make sure your installation of Java VM is up-to-date. There are some well known security bugs with Microsoft Java VM which are exploited regularly by browser hijackers.

Posted Image 3.) Open Intenet Explorer and go to Internet Options > Security > Internet, then press "Default Level", then OK. Now press "Custom Level." In the ActiveX section, set the first two options ("Download signed and unsigned ActiveX controls) to "Prompt", and ("Initialize and Script ActiveX controls not marked as safe") to "Disable".

Now you will be asked whether you want ActiveX objects to be executed and whether you want software to be installed.
Sites that you know for sure are above suspicion can be moved to the Trusted Zone in Internet Option > Security.

So why is ActiveX so dangerous that you have to increase the security for it?
When your browser runs an activex control, it is running an executable program. It's no different from doubleclicking an exe file on your hard drive.
Would you run just any random file downloaded off a web site without knowing what it is and what it does?

Posted Image 4.) Install Javacool's SpywareBlaster

It will protect you from most spy/foistware in it's database by blocking installation of their ActiveX objects.

Download and install, download the latest updates, and you'll see a list of all spyware programs covered by the program (NOTE: this is NOT spyware found on your computer) Press "Enable All Protection", and you're done.
The spyware that you told Spywareblaster to set the "kill bit" for won't be a hazard to you any longer. Although it won't protect you from every form of spyware known to man, it is a very potent extra layer of protection.
Don't forget to check for updates every week or so.

Posted Image 5.) Let's also not forget that Spybot Search & Destroy has the Immunize feature which works roughly the same way. Another feature within Spybot is the TeaTimer option. This option immediately detects known malicious processes wanting to start and terminates them. TeaTimer also detects when something wants to change some critical registry keys and gives you an option to allow them or not.

Posted Image 6.) Microsoft now offers their own free malicious software blocking tool. Windows Defender improves Internet browsing safety by guarding over fifty (50) ways spyware can enter your PC.

Posted Image 7.) Another excellent program by Javacool we recommend is SpywareGuard.
It provides a degree of real-time protection solution against spyware that is a great addition to SpywareBlaster's protection method.

Posted Image 8.) IE-SPYAD puts over 5000 sites in your restricted zone, so you'll be protected when you visit innocent-looking sites that aren't actually innocent at all. Another good hosts program is mvpshosts. This little program packs a powerful punch as it block ads, banners, 3rd party Cookies, 3rd party page counters, web bugs, and many hijackers. For information on how to download and install, please read this tutorial.

*It is important to note that all of the above programs/files can be run simultaneously on your system. They will work together in layers, so to speak, to help protect your computer. However, the following suggestions are designed to only run one of each. It is not a good idea to run more than one firewall, and one anti-virus program. Running more than one of these at a time can cause system crashes, high system usage and/or conflicts with each other.*

Posted Image 9.) It is critical that you use a firewall to protect your computer from hackers. We don't recommend the firewall that comes built in to Windows. It doesn't block everything that may try to get in, and the entire firewall is written to the registry. As various kinds of malware hack the Registry in order to disable the Windows firewall, it's far preferable to install one of the excellent third party solutions. Three good ones that are freeware to boot are ZoneAlarm, Kerio and Sygate

Posted Image 10.) An Anti-Virus product is a necessity. There are many excellent programs that you can purchase. However, we choose to advocate the use of free programs whenever possible. Some very good and easy-to-use free A/V programs are AVG, Avast, and AntiVir. It's a good idea to set these to receive automatic updates so you are always as fully protected as possible from the newest virus threats.

NOTE: DO NOT install more than one anti-virus program. They will conflict, and provide less protection, not more.


Update all these programs regularly - Make sure you update all the programs I have listed regularly. Without regular updates you WILL NOT be protected when new malicious programs are released.

Follow this list and your potential for being infected again will reduce dramatically.

Thanks for letting us help you!
  • 0

#11
BHowett

BHowett

    OT Moderator

  • Moderator
  • 4,642 posts
Since this issue appears to be resolved ... this Topic has been closed. Glad we could help. :)

If you're the topic starter, and need this topic reopened, please contact a staff member with the address of the thread.

Everyone else please begin a New Topic.
  • 0






Similar Topics

0 user(s) are reading this topic

0 members, 0 guests, 0 anonymous users

As Featured On:

Microsoft Yahoo BBC MSN PC Magazine Washington Post HP