ettings\All Users\Application Data\Apple
[2007/10/29 03:38:17 | 00,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\Apple Computer
[2006/04/24 23:29:35 | 00,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\BVRP Software
[2007/11/11 16:35:04 | 00,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\CyberLink
[2005/06/12 14:13:27 | 00,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\Dell
[2007/09/07 17:07:41 | 00,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\FLEXnet
[2009/01/09 17:00:42 | 00,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\Google
[2009/02/24 12:05:54 | 00,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\Google Updater
[2005/06/10 15:25:42 | 00,000,000 | -H-D | M] -- C:\Documents and Settings\All Users\Application Data\GTek
[2008/01/11 23:03:34 | 00,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\Hewlett-Packard
[2009/01/03 01:06:38 | 00,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\HP
[2008/11/27 21:13:57 | 00,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\HP Product Assistant
[2007/08/28 02:08:08 | 00,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\Infospace
[2005/07/02 13:08:55 | 00,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\Kaspersky Lab
[2008/11/16 02:39:54 | 00,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\Lavasoft
[2008/08/09 20:17:18 | 00,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\Logishrd
[2009/02/04 18:47:58 | 00,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\Logitech
[2007/10/21 20:44:50 | 00,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\Macrovision
[2009/02/21 20:00:12 | 00,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\Malwarebytes
[2005/10/26 22:34:48 | 00,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\McAfee.com
[2006/07/26 17:48:03 | 00,000,000 | --SD | M] -- C:\Documents and Settings\All Users\Application Data\Microsoft
[2005/06/27 19:01:39 | 00,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\MSN Search Toolbar
[2004/09/23 17:12:41 | 00,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\MSN6
[2008/09/20 16:54:37 | 00,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\NCH Swift Sound
[2008/11/18 13:49:57 | 00,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\NOS
[2007/01/17 19:51:48 | 00,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\Office Genuine Advantage
[2008/11/16 22:06:52 | 00,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\PC Drivers HeadQuarters
[2007/09/18 17:33:32 | 00,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\Protexis
[2006/01/30 15:01:13 | 00,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\Pure Networks
[2004/09/21 10:56:55 | 00,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\QuickTime
[2007/10/10 22:13:17 | 00,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\RoboForm
[2004/09/21 10:26:46 | 00,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\SBSI
[2009/02/19 16:11:00 | 00,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy
[2007/07/08 14:37:29 | 00,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\SUPERAntiSpyware.com
[2004/10/06 18:07:03 | 00,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\Support.com
[2007/08/02 23:36:16 | 00,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\TEMP
[2005/12/15 23:04:14 | 00,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\Tenebril
[2005/07/14 23:07:21 | 00,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\Trymedia
[2007/09/06 19:26:19 | 00,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\Ulead Systems
[2005/01/04 13:50:43 | 00,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\Viewpoint
[2008/01/11 23:05:29 | 00,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\WEBREG
[2008/11/15 11:14:25 | 00,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\WholeSecurity
[2006/06/27 23:08:24 | 00,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\Windows Genuine Advantage
[2007/08/28 02:24:54 | 00,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\Windows Live Toolbar
[2005/12/15 23:34:54 | 00,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\WinSoftware
[2007/09/24 19:05:20 | 00,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\WinZip
[2007/01/13 21:33:30 | 00,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\yahoo!
[2008/08/09 01:45:31 | 00,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\Yahoo! Companion
[2009/02/24 18:27:05 | 00,000,000 | -H-D | M] -- C:\Documents and Settings\Jon\Application Data
[2006/01/28 00:11:19 | 00,000,000 | ---D | M] -- C:\Documents and Settings\Jon\Application Data\acccore
[2009/01/23 03:59:32 | 00,000,000 | ---D | M] -- C:\Documents and Settings\Jon\Application Data\Adobe
[2008/05/24 16:25:21 | 00,000,000 | ---D | M] -- C:\Documents and Settings\Jon\Application Data\AdobeUM
[2005/05/19 20:19:33 | 00,000,000 | ---D | M] -- C:\Documents and Settings\Jon\Application Data\Aim
[2007/10/29 03:46:02 | 00,000,000 | ---D | M] -- C:\Documents and Settings\Jon\Application Data\Apple Computer
[2008/11/02 00:30:35 | 00,000,000 | ---D | M] -- C:\Documents and Settings\Jon\Application Data\ArcSoft
[2009/02/24 17:36:04 | 00,000,000 | ---D | M] -- C:\Documents and Settings\Jon\Application Data\BitTorrent
[2009/01/23 03:59:34 | 00,000,000 | ---D | M] -- C:\Documents and Settings\Jon\Application Data\com.adobe.mauby.4875E02D9FB21EE389F73B8D1702B320485DF8CE.1
[2007/11/16 00:05:00 | 00,000,000 | ---D | M] -- C:\Documents and Settings\Jon\Application Data\Corel
[2005/01/09 20:26:06 | 00,000,000 | ---D | M] -- C:\Documents and Settings\Jon\Application Data\CyberLink
[2007/11/11 15:18:58 | 00,000,000 | ---D | M] -- C:\Documents and Settings\Jon\Application Data\DivX
[2008/07/19 13:16:20 | 00,000,000 | ---D | M] -- C:\Documents and Settings\Jon\Application Data\DNA
[2009/02/24 02:12:00 | 00,000,000 | ---D | M] -- C:\Documents and Settings\Jon\Application Data\dvdcss
[2005/10/26 00:05:45 | 00,000,000 | ---D | M] -- C:\Documents and Settings\Jon\Application Data\funkitron
[2007/01/08 18:07:30 | 00,000,000 | ---D | M] -- C:\Documents and Settings\Jon\Application Data\Google
[2007/07/08 14:57:48 | 00,000,000 | -H-D | M] -- C:\Documents and Settings\Jon\Application Data\Gtek
[2004/10/09 02:41:19 | 00,000,000 | ---D | M] -- C:\Documents and Settings\Jon\Application Data\Help
[2008/01/11 23:12:40 | 00,000,000 | ---D | M] -- C:\Documents and Settings\Jon\Application Data\HP
[2009/02/04 23:34:27 | 00,000,000 | ---D | M] -- C:\Documents and Settings\Jon\Application Data\HPAppData
[2004/09/21 10:26:48 | 00,000,000 | ---D | M] -- C:\Documents and Settings\Jon\Application Data\Identities
[2008/01/04 18:14:56 | 00,000,000 | ---D | M] -- C:\Documents and Settings\Jon\Application Data\IE7Pro
[2008/09/07 11:50:13 | 00,000,000 | ---D | M] -- C:\Documents and Settings\Jon\Application Data\IEPro
[2007/08/28 02:08:12 | 00,000,000 | ---D | M] -- C:\Documents and Settings\Jon\Application Data\Infospace
[2009/02/04 18:47:26 | 00,000,000 | ---D | M] -- C:\Documents and Settings\Jon\Application Data\InstallShield
[2004/09/21 11:00:44 | 00,000,000 | ---D | M] -- C:\Documents and Settings\Jon\Application Data\Jasc Software Inc
[2005/12/15 23:02:47 | 00,000,000 | ---D | M] -- C:\Documents and Settings\Jon\Application Data\Lavasoft
[2004/09/23 16:56:19 | 00,000,000 | ---D | M] -- C:\Documents and Settings\Jon\Application Data\Leadertech
[2008/09/16 17:50:36 | 00,000,000 | ---D | M] -- C:\Documents and Settings\Jon\Application Data\LimeWire
[2009/02/04 18:57:20 | 00,000,000 | ---D | M] -- C:\Documents and Settings\Jon\Application Data\Logitech
[2005/04/16 16:51:40 | 00,000,000 | ---D | M] -- C:\Documents and Settings\Jon\Application Data\Macromedia
[2009/02/21 20:00:25 | 00,000,000 | ---D | M] -- C:\Documents and Settings\Jon\Application Data\Malwarebytes
[2007/11/11 15:19:05 | 00,000,000 | ---D | M] -- C:\Documents and Settings\Jon\Application Data\Media Player Classic
[2009/02/21 20:18:55 | 00,000,000 | --SD | M] -- C:\Documents and Settings\Jon\Application Data\Microsoft
[2008/01/12 15:11:51 | 00,000,000 | ---D | M] -- C:\Documents and Settings\Jon\Application Data\MiniDm
[2009/01/07 18:19:56 | 00,000,000 | ---D | M] -- C:\Documents and Settings\Jon\Application Data\Move Networks
[2007/08/28 02:36:36 | 00,000,000 | ---D | M] -- C:\Documents and Settings\Jon\Application Data\Mozilla
[2007/08/28 23:38:42 | 00,000,000 | ---D | M] -- C:\Documents and Settings\Jon\Application Data\MSN Search Toolbar
[2007/12/22 16:28:05 | 00,000,000 | ---D | M] -- C:\Documents and Settings\Jon\Application Data\MSN6
[2007/02/02 19:12:26 | 00,000,000 | ---D | M] -- C:\Documents and Settings\Jon\Application Data\MySpace
[2008/11/15 12:41:06 | 00,000,000 | ---D | M] -- C:\Documents and Settings\Jon\Application Data\NCH Swift Sound
[2008/12/25 18:41:38 | 00,000,000 | ---D | M] -- C:\Documents and Settings\Jon\Application Data\OpenOffice.org
[2005/07/02 13:06:42 | 00,000,000 | ---D | M] -- C:\Documents and Settings\Jon\Application Data\Protexis
[2009/01/04 03:01:50 | 00,000,000 | ---D | M] -- C:\Documents and Settings\Jon\Application Data\Real
[2008/09/20 16:54:37 | 00,000,000 | ---D | M] -- C:\Documents and Settings\Jon\Application Data\Recordpad
[2008/10/04 01:24:45 | 00,000,000 | ---D | M] -- C:\Documents and Settings\Jon\Application Data\Smith Micro
[2004/09/23 16:56:37 | 00,000,000 | ---D | M] -- C:\Documents and Settings\Jon\Application Data\Sonic
[2008/09/06 21:30:08 | 00,000,000 | ---D | M] -- C:\Documents and Settings\Jon\Application Data\Sprint Desktop Sync
[2004/09/21 10:51:46 | 00,000,000 | ---D | M] -- C:\Documents and Settings\Jon\Application Data\Sun
[2007/07/08 14:36:42 | 00,000,000 | ---D | M] -- C:\Documents and Settings\Jon\Application Data\SUPERAntiSpyware.com
[2007/01/08 11:18:10 | 00,000,000 | ---D | M] -- C:\Documents and Settings\Jon\Application Data\Support.com
[2005/12/14 21:28:42 | 00,000,000 | ---D | M] -- C:\Documents and Settings\Jon\Application Data\Tenebril
[2008/11/04 22:03:20 | 00,000,000 | ---D | M] -- C:\Documents and Settings\Jon\Application Data\Viewpoint
[2008/11/26 01:17:00 | 00,000,000 | ---D | M] -- C:\Documents and Settings\Jon\Application Data\vlc
[2008/08/09 19:36:59 | 00,000,000 | ---D | M] -- C:\Documents and Settings\Jon\Application Data\Vso
[2007/08/28 23:38:42 | 00,000,000 | ---D | M] -- C:\Documents and Settings\Jon\Application Data\Windows Desktop Search
[2008/02/05 19:46:07 | 00,000,000 | ---D | M] -- C:\Documents and Settings\Jon\Application Data\WinRAR
[2009/02/21 19:39:08 | 00,000,000 | ---D | M] -- C:\Documents and Settings\Jon\Application Data\wsInspector
[2007/10/19 14:16:42 | 00,000,000 | ---D | M] -- C:\Documents and Settings\Jon\Application Data\Yahoo!
[2004/10/20 20:10:22 | 00,000,000 | ---D | M] -- C:\Documents and Settings\Jon\Application Data\Yahoo! Messenger
[2009/02/24 08:01:06 | 00,000,284 | ---- | M] () -- C:\WINDOWS\Tasks\AppleSoftwareUpdate.job
[2002/08/29 05:00:00 | 00,000,065 | RH-- | M] () -- C:\WINDOWS\Tasks\DESKTOP.INI
[2009/02/24 18:32:22 | 00,000,006 | -H-- | M] () -- C:\WINDOWS\Tasks\SA.DAT
[2009/02/24 18:08:21 | 00,000,532 | ---- | M] () -- C:\WINDOWS\Tasks\SmitFraudFixTool Scheduled Scan.job
[2009/02/24 18:53:31 | 00,000,418 | -H-- | M] () -- C:\WINDOWS\Tasks\User_Feed_Synchronization-{BD8ADFCA-EBA3-4BDE-8BD2-D9A7A0FDD939}.job
========== Purity Check ========== ========== Alternate Data Streams ========== @Alternate Data Stream - 68 bytes -> C:\WINDOWS\System32\XPSP1HFM.EXE:KAVICHS
@Alternate Data Stream - 68 bytes -> C:\WINDOWS\System32\wuaueng1.dll:KAVICHS
@Alternate Data Stream - 68 bytes -> C:\WINDOWS\System32\VGA.DLL:KAVICHS
@Alternate Data Stream - 68 bytes -> C:\WINDOWS\System32\TSSOFT32.ACM:KAVICHS
@Alternate Data Stream - 68 bytes -> C:\WINDOWS\System32\TRAFFIC.DLL:KAVICHS
@Alternate Data Stream - 68 bytes -> C:\WINDOWS\System32\tfswapi.dll:KAVICHS
@Alternate Data Stream - 68 bytes -> C:\WINDOWS\System32\STDOLE32.TLB:KAVICHS
@Alternate Data Stream - 68 bytes -> C:\WINDOWS\System32\SNDVOL32.EXE:KAVICHS
@Alternate Data Stream - 68 bytes -> C:\WINDOWS\System32\SERWVDRV.DLL:KAVICHS
@Alternate Data Stream - 68 bytes -> C:\WINDOWS\System32\rsvp.exe:KAVICHS
@Alternate Data Stream - 68 bytes -> C:\WINDOWS\System32\RICHED32.DLL:KAVICHS
@Alternate Data Stream - 68 bytes -> C:\WINDOWS\System32\OEMLOGO.BMP:KAVICHS
@Alternate Data Stream - 68 bytes -> C:\WINDOWS\System32\OEMBIOS.BIN:KAVICHS
@Alternate Data Stream - 68 bytes -> C:\WINDOWS\System32\NTSDEXTS.DLL:KAVICHS
@Alternate Data Stream - 68 bytes -> C:\WINDOWS\System32\NETMSG.DLL:KAVICHS
@Alternate Data Stream - 68 bytes -> C:\WINDOWS\System32\netfxperf.dll:KAVICHS
@Alternate Data Stream - 68 bytes -> C:\WINDOWS\System32\MYCOMPUT.DLL:KAVICHS
@Alternate Data Stream - 68 bytes -> C:\WINDOWS\System32\MSXMLR.DLL:KAVICHS
@Alternate Data Stream - 68 bytes -> C:\WINDOWS\System32\MSXML3R.DLL:KAVICHS
@Alternate Data Stream - 68 bytes -> C:\WINDOWS\System32\MSVIDC32.DLL:KAVICHS
@Alternate Data Stream - 68 bytes -> C:\WINDOWS\System32\MSRATELC.DLL:KAVICHS
@Alternate Data Stream - 68 bytes -> C:\WINDOWS\System32\MSHEARTS.EXE:KAVICHS
@Alternate Data Stream - 68 bytes -> C:\WINDOWS\System32\MSGSM32.ACM:KAVICHS
@Alternate Data Stream - 68 bytes -> C:\WINDOWS\System32\MSG723.ACM:KAVICHS
@Alternate Data Stream - 68 bytes -> C:\WINDOWS\System32\MSG711.ACM:KAVICHS
@Alternate Data Stream - 68 bytes -> C:\WINDOWS\System32\MSACM32.DRV:KAVICHS
@Alternate Data Stream - 68 bytes -> C:\WINDOWS\System32\Mpeg2Decoder.ax:KAVICHS
@Alternate Data Stream - 68 bytes -> C:\WINDOWS\System32\mmsystem.dll:KAVICHS
@Alternate Data Stream - 68 bytes -> C:\WINDOWS\System32\MLANG.DAT:KAVICHS
@Alternate Data Stream - 68 bytes -> C:\WINDOWS\System32\MAPI32.DLL:KAVICHS
@Alternate Data Stream - 68 bytes -> C:\WINDOWS\System32\MAIN.CPL:KAVICHS
@Alternate Data Stream - 68 bytes -> C:\WINDOWS\System32\libmcl-3.1.1.dll:KAVICHS
@Alternate Data Stream - 68 bytes -> C:\WINDOWS\System32\libfilefmt-1.1.0.dll:KAVICHS
@Alternate Data Stream - 68 bytes -> C:\WINDOWS\System32\libavi-dd-1.2.0.dll:KAVICHS
@Alternate Data Stream - 68 bytes -> C:\WINDOWS\System32\LANGWRBK.DLL:KAVICHS
@Alternate Data Stream - 68 bytes -> C:\WINDOWS\System32\l3codecx.ax:KAVICHS
@Alternate Data Stream - 68 bytes -> C:\WINDOWS\System32\L_INTL.NLS:KAVICHS
@Alternate Data Stream - 68 bytes -> C:\WINDOWS\System32\KDCOM.DLL:KAVICHS
@Alternate Data Stream - 68 bytes -> C:\WINDOWS\System32\IR32_32.DLL:KAVICHS
@Alternate Data Stream - 68 bytes -> C:\WINDOWS\System32\IPROP.DLL:KAVICHS
@Alternate Data Stream - 68 bytes -> C:\WINDOWS\System32\INFOSOFT.DLL:KAVICHS
@Alternate Data Stream - 68 bytes -> C:\WINDOWS\System32\INETCPLC.DLL:KAVICHS
@Alternate Data Stream - 68 bytes -> C:\WINDOWS\System32\ICMUI.DLL:KAVICHS
@Alternate Data Stream - 68 bytes -> C:\WINDOWS\System32\HTICONS.DLL:KAVICHS
@Alternate Data Stream - 68 bytes -> C:\WINDOWS\System32\fxssend.exe:KAVICHS
@Alternate Data Stream - 68 bytes -> C:\WINDOWS\System32\fxsroute.dll:KAVICHS
@Alternate Data Stream - 68 bytes -> C:\WINDOWS\System32\FREECELL.EXE:KAVICHS
@Alternate Data Stream - 68 bytes -> C:\WINDOWS\System32\EGA.CPI:KAVICHS
@Alternate Data Stream - 68 bytes -> C:\WINDOWS\System32\DRIVERS\wVchNTxx.sys:KAVICHS
@Alternate Data Stream - 68 bytes -> C:\WINDOWS\System32\DRIVERS\wSiINTxx.sys:KAVICHS
@Alternate Data Stream - 68 bytes -> C:\WINDOWS\System32\DRIVERS\wCh7xxNT.sys:KAVICHS
@Alternate Data Stream - 68 bytes -> C:\WINDOWS\System32\DRIVERS\wATV04nt.sys:KAVICHS
@Alternate Data Stream - 68 bytes -> C:\WINDOWS\System32\DRIVERS\wATV02NT.sys:KAVICHS
@Alternate Data Stream - 68 bytes -> C:\WINDOWS\System32\DRIVERS\wATV01nt.sys:KAVICHS
@Alternate Data Stream - 68 bytes -> C:\WINDOWS\System32\DRIVERS\wADV05NT.sys:KAVICHS
@Alternate Data Stream - 68 bytes -> C:\WINDOWS\System32\DRIVERS\wADV02NT.sys:KAVICHS
@Alternate Data Stream - 68 bytes -> C:\WINDOWS\System32\DRIVERS\wADV01nt.sys:KAVICHS
@Alternate Data Stream - 68 bytes -> C:\WINDOWS\system32\drivers\ssrtln.sys:KAVICHS
@Alternate Data Stream - 68 bytes -> C:\WINDOWS\system32\drivers\sscdbhk5.sys:KAVICHS
@Alternate Data Stream - 68 bytes -> C:\WINDOWS\system32\drivers\smwdm.sys:KAVICHS
@Alternate Data Stream - 68 bytes -> C:\WINDOWS\System32\DRIVERS\pciide.sys:KAVICHS
@Alternate Data Stream - 68 bytes -> C:\WINDOWS\System32\DRIVERS\nv4_mini.sys:KAVICHS
@Alternate Data Stream - 68 bytes -> C:\WINDOWS\System32\DRIVERS\mohfilt.sys:KAVICHS
@Alternate Data Stream - 68 bytes -> C:\WINDOWS\system32\drivers\MODEMCSA.sys:KAVICHS
@Alternate Data Stream - 68 bytes -> C:\WINDOWS\System32\DRIVERS\IntelC53.sys:KAVICHS
@Alternate Data Stream - 68 bytes -> C:\WINDOWS\System32\DRIVERS\IntelC52.sys:KAVICHS
@Alternate Data Stream - 68 bytes -> C:\WINDOWS\System32\DRIVERS\IntelC51.sys:KAVICHS
@Alternate Data Stream - 68 bytes -> C:\WINDOWS\System32\DRIVERS\i81xnt5.sys:KAVICHS
@Alternate Data Stream - 68 bytes -> C:\WINDOWS\System32\DRIVERS\ftdisk.sys:KAVICHS
@Alternate Data Stream - 68 bytes -> C:\WINDOWS\system32\drivers\drvnddm.sys:KAVICHS
@Alternate Data Stream - 68 bytes -> C:\WINDOWS\system32\drivers\drvmcdb.sys:KAVICHS
@Alternate Data Stream - 68 bytes -> C:\WINDOWS\System32\Drivers\Ca536av.sys:KAVICHS
@Alternate Data Stream - 68 bytes -> C:\WINDOWS\System32\Drivers\Bulk536.sys:KAVICHS
@Alternate Data Stream - 68 bytes -> C:\WINDOWS\System32\DRIVERS\ati2mtag.sys:KAVICHS
@Alternate Data Stream - 68 bytes -> C:\WINDOWS\system32\drivers\aeaudio.sys:KAVICHS
@Alternate Data Stream - 68 bytes -> C:\WINDOWS\System32\DOCPROP.DLL:KAVICHS
@Alternate Data Stream - 68 bytes -> C:\WINDOWS\system32\dla\tfswshx.dll:KAVICHS
@Alternate Data Stream - 68 bytes -> C:\WINDOWS\system32\dla\tfswctrl.exe:KAVICHS
@Alternate Data Stream - 68 bytes -> C:\WINDOWS\system32\dla\tfsnudfa.sys:KAVICHS
@Alternate Data Stream - 68 bytes -> C:\WINDOWS\system32\dla\tfsnudf.sys:KAVICHS
@Alternate Data Stream - 68 bytes -> C:\WINDOWS\system32\dla\tfsnpool.sys:KAVICHS
@Alternate Data Stream - 68 bytes -> C:\WINDOWS\system32\dla\tfsnopio.sys:KAVICHS
@Alternate Data Stream - 68 bytes -> C:\WINDOWS\system32\dla\tfsnifs.sys:KAVICHS
@Alternate Data Stream - 68 bytes -> C:\WINDOWS\system32\dla\tfsndres.sys:KAVICHS
@Alternate Data Stream - 68 bytes -> C:\WINDOWS\system32\dla\tfsndrct.sys:KAVICHS
@Alternate Data Stream - 68 bytes -> C:\WINDOWS\system32\dla\tfsncofs.sys:KAVICHS
@Alternate Data Stream - 68 bytes -> C:\WINDOWS\system32\dla\tfsnboio.sys:KAVICHS
@Alternate Data Stream - 68 bytes -> C:\WINDOWS\System32\DFRGRES.DLL:KAVICHS
@Alternate Data Stream - 68 bytes -> C:\WINDOWS\System32\DFRG.MSC:KAVICHS
@Alternate Data Stream - 68 bytes -> C:\WINDOWS\System32\DBGENG.DLL:KAVICHS
@Alternate Data Stream - 68 bytes -> C:\WINDOWS\System32\CHARMAP.EXE:KAVICHS
@Alternate Data Stream - 68 bytes -> C:\WINDOWS\System32\CARDS.DLL:KAVICHS
@Alternate Data Stream - 68 bytes -> C:\WINDOWS\System32\C_950.NLS:KAVICHS
@Alternate Data Stream - 68 bytes -> C:\WINDOWS\System32\C_949.NLS:KAVICHS
@Alternate Data Stream - 68 bytes -> C:\WINDOWS\System32\C_936.NLS:KAVICHS
@Alternate Data Stream - 68 bytes -> C:\WINDOWS\System32\C_932.NLS:KAVICHS
@Alternate Data Stream - 68 bytes -> C:\WINDOWS\System32\C_874.NLS:KAVICHS
@Alternate Data Stream - 68 bytes -> C:\WINDOWS\System32\C_437.NLS:KAVICHS
@Alternate Data Stream - 68 bytes -> C:\WINDOWS\System32\C_1257.NLS:KAVICHS
@Alternate Data Stream - 68 bytes -> C:\WINDOWS\System32\C_1256.NLS:KAVICHS
@Alternate Data Stream - 68 bytes -> C:\WINDOWS\System32\C_1255.NLS:KAVICHS
@Alternate Data Stream - 68 bytes -> C:\WINDOWS\System32\C_1254.NLS:KAVICHS
@Alternate Data Stream - 68 bytes -> C:\WINDOWS\System32\C_1252.NLS:KAVICHS
@Alternate Data Stream - 68 bytes -> C:\WINDOWS\System32\BOOTVID.DLL:KAVICHS
@Alternate Data Stream - 68 bytes -> C:\WINDOWS\System32\AVICAP32.DLL:KAVICHS
@Alternate Data Stream - 68 bytes -> C:\WINDOWS\System32\ACELPDEC.AX:KAVICHS
@Alternate Data Stream - 68 bytes -> C:\WINDOWS\System32\$WINNT$.INF:KAVICHS
@Alternate Data Stream - 68 bytes -> C:\WINDOWS\SYSTEM.UNV:KAVICHS
@Alternate Data Stream - 68 bytes -> C:\WINDOWS\SchedLgU.Txt:KAVICHS
@Alternate Data Stream - 68 bytes -> C:\WINDOWS\dellstat.ini:KAVICHS
@Alternate Data Stream - 68 bytes -> C:\SystemInfo.ini:KAVICHS
@Alternate Data Stream - 68 bytes -> C:\Program Files\Intel\PROSetWired\NCS\Sync\NetSvc.exe:KAVICHS
@Alternate Data Stream - 68 bytes -> C:\LgDSetup.log:KAVICHS
@Alternate Data Stream - 68 bytes -> C:\h.txt:KAVICHS
@Alternate Data Stream - 68 bytes -> C:\graph.txt:KAVICHS
@Alternate Data Stream - 68 bytes -> C:\dvdlog.txt:KAVICHS
@Alternate Data Stream - 68 bytes -> C:\Documents and Settings\Jon\My Documents\DESKTOP.INI:KAVICHS
@Alternate Data Stream - 68 bytes -> C:\Documents and Settings\Jon\Application Data\DESKTOP.INI:KAVICHS
@Alternate Data Stream - 68 bytes -> C:\Documents and Settings\All Users\Application Data\DESKTOP.INI:KAVICHS
@Alternate Data Stream - 68 bytes -> C:\dlbt.log:KAVICHS
@Alternate Data Stream - 68 bytes -> C:\DeleteAtReboot.bat:KAVICHS
@Alternate Data Stream - 36 bytes -> C:\WINDOWS\zodiac.ico:KAVICHS
@Alternate Data Stream - 36 bytes -> C:\WINDOWS\Zapotec.bmp:KAVICHS
@Alternate Data Stream - 36 bytes -> C:\WINDOWS\YAHELITE.INI:KAVICHS
@Alternate Data Stream - 36 bytes -> C:\WINDOWS\WMSysPrx.prx:KAVICHS
@Alternate Data Stream - 36 bytes -> C:\WINDOWS\WINNT256.BMP:KAVICHS
@Alternate Data Stream - 36 bytes -> C:\WINDOWS\WINNT.BMP:KAVICHS
@Alternate Data Stream - 36 bytes -> C:\WINDOWS\wininit.ini:KAVICHS
@Alternate Data Stream - 36 bytes -> C:\WINDOWS\WINHELP.EXE:KAVICHS
@Alternate Data Stream - 36 bytes -> C:\WINDOWS\VMMREG32.DLL:KAVICHS
@Alternate Data Stream - 36 bytes -> C:\WINDOWS\VBADDIN.INI:KAVICHS
@Alternate Data Stream - 36 bytes -> C:\WINDOWS\VB.INI:KAVICHS
@Alternate Data Stream - 36 bytes -> C:\WINDOWS\Ulead32.ini:KAVICHS
@Alternate Data Stream - 36 bytes -> C:\WINDOWS\TWUNK_32.EXE:KAVICHS
@Alternate Data Stream - 36 bytes -> C:\WINDOWS\TWUNK_16.EXE:KAVICHS
@Alternate Data Stream - 36 bytes -> C:\WINDOWS\TWAIN.DLL:KAVICHS
@Alternate Data Stream - 36 bytes -> C:\WINDOWS\TMPG001.TMP:KAVICHS
@Alternate Data Stream - 36 bytes -> C:\WINDOWS\TASKMAN.EXE:KAVICHS
@Alternate Data Stream - 36 bytes -> C:\WINDOWS\System32\zipfldr(2).dll:KAVICHS
@Alternate Data Stream - 36 bytes -> C:\WINDOWS\System32\xenroll.dll:KAVICHS
@Alternate Data Stream - 36 bytes -> C:\WINDOWS\System32\XceedFtp.dll:KAVICHS
@Alternate Data Stream - 36 bytes -> C:\WINDOWS\System32\Xcdzpsfx.lic:KAVICHS
@Alternate Data Stream - 36 bytes -> C:\WINDOWS\System32\Xcdzpocx.lic:KAVICHS
@Alternate Data Stream - 36 bytes -> C:\WINDOWS\System32\Xcdzip35.ocx:KAVICHS
@Alternate Data Stream - 36 bytes -> C:\WINDOWS\System32\Xcdsfx32.bin:KAVICHS
@Alternate Data Stream - 36 bytes -> C:\WINDOWS\System32\WZCSVC(3).DLL:KAVICHS
@Alternate Data Stream - 36 bytes -> C:\WINDOWS\System32\WUPDMGR.EXE:KAVICHS
@Alternate Data Stream - 36 bytes -> C:\WINDOWS\System32\WUAUSERV(3).DLL:KAVICHS
@Alternate Data Stream - 36 bytes -> C:\WINDOWS\System32\wuauclt1.exe:KAVICHS
@Alternate Data Stream - 36 bytes -> C:\WINDOWS\System32\WTSAPI32(3).DLL:KAVICHS
@Alternate Data Stream - 36 bytes -> C:\WINDOWS\System32\WSOCK32(3).DLL:KAVICHS
@Alternate Data Stream - 36 bytes -> C:\WINDOWS\System32\WSHTCPIP(3).DLL:KAVICHS
@Alternate Data Stream - 36 bytes -> C:\WINDOWS\System32\WSHNETBS.DLL:KAVICHS
@Alternate Data Stream - 36 bytes -> C:\WINDOWS\System32\WSHISN.DLL:KAVICHS
@Alternate Data Stream - 36 bytes -> C:\WINDOWS\System32\WSHATM.DLL:KAVICHS
@Alternate Data Stream - 36 bytes -> C:\WINDOWS\System32\WS2HELP(3).DLL:KAVICHS
@Alternate Data Stream - 36 bytes -> C:\WINDOWS\System32\WS2_32(3).DLL:KAVICHS
@Alternate Data Stream - 36 bytes -> C:\WINDOWS\System32\WRITE.EXE:KAVICHS
@Alternate Data Stream - 36 bytes -> C:\WINDOWS\System32\WOWFAXUI.DLL:KAVICHS
@Alternate Data Stream - 36 bytes -> C:\WINDOWS\System32\WOWFAX.DLL:KAVICHS
@Alternate Data Stream - 36 bytes -> C:\WINDOWS\System32\WOWEXEC.EXE:KAVICHS
@Alternate Data Stream - 36 bytes -> C:\WINDOWS\System32\WOWDEB.EXE:KAVICHS
@Alternate Data Stream - 36 bytes -> C:\WINDOWS\System32\WOW32(3).DLL:KAVICHS
@Alternate Data Stream - 36 bytes -> C:\WINDOWS\System32\WMVDMOE.DLL:KAVICHS
@Alternate Data Stream - 36 bytes -> C:\WINDOWS\System32\WMVCORE2.DLL:KAVICHS
@Alternate Data Stream - 36 bytes -> C:\WINDOWS\System32\wmv8dmoe.dll:KAVICHS
@Alternate Data Stream - 36 bytes -> C:\WINDOWS\System32\WMV8DMOD.DLL:KAVICHS
@Alternate Data Stream - 36 bytes -> C:\WINDOWS\System32\WMPSTUB.EXE:KAVICHS
@Alternate Data Stream - 36 bytes -> C:\WINDOWS\System32\wmpscheme.xml:KAVICHS
@Alternate Data Stream - 36 bytes -> C:\WINDOWS\System32\wmpns.dll:KAVICHS
@Alternate Data Stream - 36 bytes -> C:\WINDOWS\System32\WMPLOC(2).DLL:KAVICHS
@Alternate Data Stream - 36 bytes -> C:\WINDOWS\System32\WMPCD(2).DLL:KAVICHS
@Alternate Data Stream - 36 bytes -> C:\WINDOWS\System32\WMIPROP.DLL:KAVICHS
@Alternate Data Stream - 36 bytes -> C:\WINDOWS\System32\WMIMGMT.MSC:KAVICHS
@Alternate Data Stream - 36 bytes -> C:\WINDOWS\System32\WMIDX.OCX:KAVICHS
@Alternate Data Stream - 36 bytes -> C:\WINDOWS\System32\WMI(3).DLL:KAVICHS
@Alternate Data Stream - 36 bytes -> C:\WINDOWS\System32\WMERRENU.DLL:KAVICHS
@Alternate Data Stream - 36 bytes -> C:\WINDOWS\System32\WLNOTIFY(3).DLL:KAVICHS
@Alternate Data Stream - 36 bytes -> C:\WINDOWS\System32\WLDAP32(3).DLL:KAVICHS
@Alternate Data Stream - 36 bytes -> C:\WINDOWS\System32\WINTRUST(3).DLL:KAVICHS
@Alternate Data Stream - 36 bytes -> C:\WINDOWS\System32\winsusrm.dll:KAVICHS
@Alternate Data Stream - 36 bytes -> C:\WINDOWS\System32\WINSTRM.DLL:KAVICHS
@Alternate Data Stream - 36 bytes -> C:\WINDOWS\System32\WINSPOOL.EXE:KAVICHS
@Alternate Data Stream - 36 bytes -> C:\WINDOWS\System32\WINSOCK.DLL:KAVICHS
@Alternate Data Stream - 36 bytes -> C:\WINDOWS\System32\WINSCARD(3).DLL:KAVICHS
@Alternate Data Stream - 36 bytes -> C:\WINDOWS\System32\WINRNR(3).DLL:KAVICHS
@Alternate Data Stream - 36 bytes -> C:\WINDOWS\System32\WINOLDAP.MOD:KAVICHS
@Alternate Data Stream - 36 bytes -> C:\WINDOWS\System32\WINNLS.DLL:KAVICHS
@Alternate Data Stream - 36 bytes -> C:\WINDOWS\System32\WINMSD.EXE:KAVICHS
@Alternate Data Stream - 36 bytes -> C:\WINDOWS\System32\WINMM(3).DLL:KAVICHS
@Alternate Data Stream - 36 bytes -> C:\WINDOWS\System32\WINMINE.EXE:KAVICHS
@Alternate Data Stream - 36 bytes -> C:\WINDOWS\System32\WINIPSEC(3).DLL:KAVICHS
@Alternate Data Stream - 36 bytes -> C:\WINDOWS\System32\WININET(3).DLL:KAVICHS
@Alternate Data Stream - 36 bytes -> C:\WINDOWS\System32\WINHTTP(4).DLL:KAVICHS
@Alternate Data Stream - 36 bytes -> C:\WINDOWS\System32\winhttp(3).dll:KAVICHS
@Alternate Data Stream - 36 bytes -> C:\WINDOWS\System32\WINHLP32.EXE:KAVICHS
@Alternate Data Stream - 36 bytes -> C:\WINDOWS\System32\WINHELP.HLP:KAVICHS
@Alternate Data Stream - 36 bytes -> C:\WINDOWS\System32\WINFAX.DLL:KAVICHS
@Alternate Data Stream - 36 bytes -> C:\WINDOWS\System32\WINCHAT.EXE:KAVICHS
@Alternate Data Stream - 36 bytes -> C:\WINDOWS\System32\WIN87EM.DLL:KAVICHS
@Alternate Data Stream - 36 bytes -> C:\WINDOWS\System32\WIN.COM:KAVICHS
@Alternate Data Stream - 36 bytes -> C:\WINDOWS\System32\WIFEMAN.DLL:KAVICHS
@Alternate Data Stream - 36 bytes -> C:\WINDOWS\System32\WIAVUSD.DLL:KAVICHS
@Alternate Data Stream - 36 bytes -> C:\WINDOWS\System32\WIASHEXT(2).DLL:KAVICHS
@Alternate Data Stream - 36 bytes -> C:\WINDOWS\System32\WIASF.AX:KAVICHS
@Alternate Data Stream - 36 bytes -> C:\WINDOWS\System32\WIASERVC(2).DLL:KAVICHS
@Alternate Data Stream - 36 bytes -> C:\WINDOWS\System32\WFWNET.DRV:KAVICHS
@Alternate Data Stream - 36 bytes -> C:\WINDOWS\System32\WEBHITS.DLL:KAVICHS
@Alternate Data Stream - 36 bytes -> C:\WINDOWS\System32\webfldrs.msi:KAVICHS
@Alternate Data Stream - 36 bytes -> C:\WINDOWS\System32\WEBCLNT(3).DLL:KAVICHS
@Alternate Data Stream - 36 bytes -> C:\WINDOWS\System32\WEBCHECK(2).DLL:KAVICHS
@Alternate Data Stream - 36 bytes -> C:\WINDOWS\System32\WDMAUD(3).DRV:KAVICHS
@Alternate Data Stream - 36 bytes -> C:\WINDOWS\System32\WDL.TRM:KAVICHS
@Alternate Data Stream - 36 bytes -> C:\WINDOWS\System32\WDIGEST(3).DLL:KAVICHS
@Alternate Data Stream - 36 bytes -> C:\WINDOWS\System32\WBDBASE.SVE:KAVICHS
@Alternate Data Stream - 36 bytes -> C:\WINDOWS\System32\WBDBASE.NLD:KAVICHS
@Alternate Data Stream - 36 bytes -> C:\WINDOWS\System32\WBDBASE.ITA:KAVICHS
@Alternate Data Stream - 36 bytes -> C:\WINDOWS\System32\WBDBASE.FRA:KAVICHS
@Alternate Data Stream - 36 bytes -> C:\WINDOWS\System32\WBDBASE.ESN:KAVICHS
@Alternate Data Stream - 36 bytes -> C:\WINDOWS\System32\WBDBASE.ENU:KAVICHS
@Alternate Data Stream - 36 bytes -> C:\WINDOWS\System32\WBDBASE.DEU:KAVICHS
@Alternate Data Stream - 36 bytes -> C:\WINDOWS\System32\WBCACHE.SVE:KAVICHS
@Alternate Data Stream - 36 bytes -> C:\WINDOWS\System32\WBCACHE.NLD:KAVICHS
@Alternate Data Stream - 36 bytes -> C:\WINDOWS\System32\WBCACHE.ITA:KAVICHS
@Alternate Data Stream - 36 bytes -> C:\WINDOWS\System32\WBCACHE.FRA:KAVICHS
@Alternate Data Stream - 36 bytes -> C:\WINDOWS\System32\WBCACHE.ESN:KAVICHS
@Alternate Data Stream - 36 bytes -> C:\WINDOWS\System32\WBCACHE.ENU:KAVICHS
@Alternate Data Stream - 36 bytes -> C:\WINDOWS\System32\WBCACHE.DEU:KAVICHS
@Alternate Data Stream - 36 bytes -> C:\WINDOWS\System32\W32TOPL.DLL:KAVICHS
@Alternate Data Stream - 36 bytes -> C:\WINDOWS\System32\W32TM.EXE:KAVICHS
@Alternate Data Stream - 36 bytes -> C:\WINDOWS\System32\W32TIME(3).DLL:KAVICHS
@Alternate Data Stream - 36 bytes -> C:\WINDOWS\System32\vxdmdcdlg.dll:KAVICHS
@Alternate Data Stream - 36 bytes -> C:\WINDOWS\System32\VSSAPI(3).DLL:KAVICHS
@Alternate Data Stream - 36 bytes -> C:\WINDOWS\System32\VSSADMIN.EXE:KAVICHS
@Alternate Data Stream - 36 bytes -> C:\WINDOWS\System32\VSS_PS.DLL:KAVICHS
@Alternate Data Stream - 36 bytes -> C:\WINDOWS\System32\VJOY.DLL:KAVICHS
@Alternate Data Stream - 36 bytes -> C:\WINDOWS\System32\View Channels.scf:KAVICHS
@Alternate Data Stream - 36 bytes -> C:\WINDOWS\System32\VGA64K.DLL:KAVICHS
@Alternate Data Stream - 36 bytes -> C:\WINDOWS\System32\VGA256.DLL:KAVICHS
@Alternate Data Stream - 36 bytes -> C:\WINDOWS\System32\VGA.DRV:KAVICHS
@Alternate Data Stream - 36 bytes -> C:\WINDOWS\System32\VFPODBC.DLL:KAVICHS
@Alternate Data Stream - 36 bytes -> C:\WINDOWS\System32\VERSION(3).DLL:KAVICHS
@Alternate Data Stream - 36 bytes -> C:\WINDOWS\System32\VERIFIER.EXE:KAVICHS
@Alternate Data Stream - 36 bytes -> C:\WINDOWS\System32\VER.DLL:KAVICHS
@Alternate Data Stream - 36 bytes -> C:\WINDOWS\System32\VCDEX.DLL:KAVICHS
@Alternate Data Stream - 36 bytes -> C:\WINDOWS\System32\VB5DB.DLL:KAVICHS
@Alternate Data Stream - 36 bytes -> C:\WINDOWS\System32\V7VGA.ROM:KAVICHS
@Alternate Data Stream - 36 bytes -> C:\WINDOWS\System32\UXTHEME(3).DLL:KAVICHS
@Alternate Data Stream - 36 bytes -> C:\WINDOWS\System32\UTILDLL.DLL:KAVICHS
@Alternate Data Stream - 36 bytes -> C:\WINDOWS\System32\USRVPA.DLL:KAVICHS
@Alternate Data Stream - 36 bytes -> C:\WINDOWS\System32\USRVOICA.DLL:KAVICHS
@Alternate Data Stream - 36 bytes -> C:\WINDOWS\System32\USRV80A.DLL:KAVICHS
@Alternate Data Stream - 36 bytes -> C:\WINDOWS\System32\USRV42A.DLL:KAVICHS
@Alternate Data Stream - 36 bytes -> C:\WINDOWS\System32\USRSVPIA.DLL:KAVICHS
@Alternate Data Stream - 36 bytes -> C:\WINDOWS\System32\USRSHUTA.EXE:KAVICHS
@Alternate Data Stream - 36 bytes -> C:\WINDOWS\System32\USRSDPIA.DLL:KAVICHS
@Alternate Data Stream - 36 bytes -> C:\WINDOWS\System32\USRRTOSA.DLL:KAVICHS
@Alternate Data Stream - 36 bytes -> C:\WINDOWS\System32\USRPRBDA.EXE:KAVICHS
@Alternate Data Stream - 36 bytes -> C:\WINDOWS\System32\USRMLNKA.EXE:KAVICHS
@Alternate Data Stream - 36 bytes -> C:\WINDOWS\System32\USRLOGON.CMD:KAVICHS
@Alternate Data Stream - 36 bytes -> C:\WINDOWS\System32\USRLBVA.DLL:KAVICHS
@Alternate Data Stream - 36 bytes -> C:\WINDOWS\System32\USRFAXA.DLL:KAVICHS
@Alternate Data Stream - 36 bytes -> C:\WINDOWS\System32\USRDTEA.DLL:KAVICHS
@Alternate Data Stream - 36 bytes -> C:\WINDOWS\System32\USRDPA.DLL:KAVICHS
@Alternate Data Stream - 36 bytes -> C:\WINDOWS\System32\USRCOINA.DLL:KAVICHS
@Alternate Data Stream - 36 bytes -> C:\WINDOWS\System32\USRCNTRA.DLL:KAVICHS
@Alternate Data Stream - 36 bytes -> C:\WINDOWS\System32\USER.EXE:KAVICHS
@Alternate Data Stream - 36 bytes -> C:\WINDOWS\System32\USBMON(2).DLL:KAVICHS
@Alternate Data Stream - 36 bytes -> C:\WINDOWS\System32\URLMON(3).DLL:KAVICHS
@Alternate Data Stream - 36 bytes -> C:\WINDOWS\System32\URL(3).DLL:KAVICHS
@Alternate Data Stream - 36 bytes -> C:\WINDOWS\System32\UREG.DLL:KAVICHS
@Alternate Data Stream - 36 bytes -> C:\WINDOWS\System32\UPNPHOST(2).DLL:KAVICHS
@Alternate Data Stream - 36 bytes -> C:\WINDOWS\System32\UPNP(3).DLL:KAVICHS
@Alternate Data Stream - 36 bytes -> C:\WINDOWS\System32\UNLODCTR.EXE:KAVICHS
@Alternate Data Stream - 36 bytes -> C:\WINDOWS\System32\UNICODE.NLS:KAVICHS
@Alternate Data Stream - 36 bytes -> C:\WINDOWS\System32\UMPNPMGR(3).DLL:KAVICHS
@Alternate Data Stream - 36 bytes -> C:\WINDOWS\System32\umloader.dll:KAVICHS
@Alternate Data Stream - 36 bytes -> C:\WINDOWS\System32\UMDMXFRM.DLL:KAVICHS
@Alternate Data Stream - 36 bytes -> C:\WINDOWS\System32\Ulead Photo Explorer.scr:KAVICHS
@Alternate Data Stream - 36 bytes -> C:\WINDOWS\System32\UFAT.DLL:KAVICHS
@Alternate Data Stream - 36 bytes -> C:\WINDOWS\System32\TYPELIB.DLL:KAVICHS
@Alternate Data Stream - 36 bytes -> C:\WINDOWS\System32\TwnLib20.dll:KAVICHS
@Alternate Data Stream - 36 bytes -> C:\WINDOWS\System32\TSSHUTDN.EXE:KAVICHS
@Alternate Data Stream - 36 bytes -> C:\WINDOWS\System32\TSLABELS.INI:KAVICHS
@Alternate Data Stream - 36 bytes -> C:\WINDOWS\System32\TSLABELS.H:KAVICHS
@Alternate Data Stream - 36 bytes -> C:\WINDOWS\System32\TSKILL.EXE:KAVICHS
@Alternate Data Stream - 36 bytes -> C:\WINDOWS\System32\TSDISCON.EXE:KAVICHS
@Alternate Data Stream - 36 bytes -> C:\WINDOWS\System32\TSDDD(2).DLL:KAVICHS
@Alternate Data Stream - 36 bytes -> C:\WINDOWS\System32\TSD32.DLL:KAVICHS
@Alternate Data Stream - 36 bytes -> C:\WINDOWS\System32\tscupgrd.exe:KAVICHS
@Alternate Data Stream - 36 bytes -> C:\WINDOWS\System32\TSCON.EXE:KAVICHS
@Alternate Data Stream - 36 bytes -> C:\WINDOWS\System32\TSAPPCMP.DLL:KAVICHS
@Alternate Data Stream - 36 bytes -> C:\WINDOWS\System32\TRKWKS(3).DLL:KAVICHS
@Alternate Data Stream - 36 bytes -> C:\WINDOWS\System32\TRACERT6.EXE:KAVICHS
@Alternate Data Stream - 36 bytes -> C:\WINDOWS\System32\TOOLHELP.DLL:KAVICHS
@Alternate Data Stream - 36 bytes -> C:\WINDOWS\System32\TIMER.DRV:KAVICHS
@Alternate Data Stream - 36 bytes -> C:\WINDOWS\System32\THEMEUI(2).DLL:KAVICHS
@Alternate Data Stream - 36 bytes -> C:\WINDOWS\System32\TFTP.EXE:KAVICHS
@Alternate Data Stream - 36 bytes -> C:\WINDOWS\System32\TERMSRV(3).DLL:KAVICHS
@Alternate Data Stream - 36 bytes -> C:\WINDOWS\System32\TELEPHON.CPL:KAVICHS
@Alternate Data Stream - 36 bytes -> C:\WINDOWS\System32\TCPSVCS.EXE:KAVICHS
@Alternate Data Stream - 36 bytes -> C:\WINDOWS\System32\tcpmon.ini:KAVICHS
@Alternate Data Stream - 36 bytes -> C:\WINDOWS\System32\TCPMON(2).DLL:KAVICHS
@Alternate Data Stream - 36 bytes -> C:\WINDOWS\System32\TCMSETUP.EXE:KAVICHS
@Alternate Data Stream - 36 bytes -> C:\WINDOWS\System32\TASKMAN.EXE:KAVICHS
@Alternate Data Stream - 36 bytes -> C:\WINDOWS\System32\TAPIUI.DLL:KAVICHS
@Alternate Data Stream - 36 bytes -> C:\WINDOWS\System32\TAPISRV(3).DLL:KAVICHS
@Alternate Data Stream - 36 bytes -> C:\WINDOWS\System32\TAPIPERF.DLL:KAVICHS
@Alternate Data Stream - 36 bytes -> C:\WINDOWS\System32\TAPI32(3).DLL:KAVICHS
@Alternate Data Stream - 36 bytes -> C:\WINDOWS\System32\TAPI.DLL:KAVICHS
@Alternate Data Stream - 36 bytes -> C:\WINDOWS\System32\SYSTRAY.EXE:KAVICHS
@Alternate Data Stream - 36 bytes -> C:\WINDOWS\System32\SYSTEM.DRV:KAVICHS
@Alternate Data Stream - 36 bytes -> C:\WINDOWS\System32\SYSPRTJ.SEP:KAVICHS
@Alternate Data Stream - 36 bytes -> C:\WINDOWS\System32\SYSPRINT.SEP:KAVICHS
@Alternate Data Stream - 36 bytes -> C:\WINDOWS\System32\SYSKEY.EXE:KAVICHS
@Alternate Data Stream - 36 bytes -> C:\WINDOWS\System32\SYSINV.DLL:KAVICHS
@Alternate Data Stream - 36 bytes -> C:\WINDOWS\System32\SYSEDIT.EXE:KAVICHS
@Alternate Data Stream - 36 bytes -> C:\WINDOWS\System32\SYNCAPP.EXE:KAVICHS
@Alternate Data Stream - 36 bytes -> C:\WINDOWS\System32\SXS(3).DLL:KAVICHS
@Alternate Data Stream - 36 bytes -> C:\WINDOWS\System32\SWPRV.DLL:KAVICHS
@Alternate Data Stream - 36 bytes -> C:\WINDOWS\System32\SVCPACK.DLL:KAVICHS
@Alternate Data Stream - 36 bytes -> C:\WINDOWS\System32\SVCHOST(3).EXE:KAVICHS
@Alternate Data Stream - 36 bytes -> C:\WINDOWS\System32\SUBST.EXE:KAVICHS
@Alternate Data Stream - 36 bytes -> C:\WINDOWS\System32\SUBRANGE.UCE:KAVICHS
@Alternate Data Stream - 36 bytes -> C:\WINDOWS\System32\STREAMCI.DLL:KAVICHS
@Alternate Data Stream - 36 bytes -> C:\WINDOWS\System32\STORAGE.DLL:KAVICHS
@Alternate Data Stream - 36 bytes -> C:\WINDOWS\System32\STOBJECT(2).DLL:KAVICHS
@Alternate Data Stream - 36 bytes -> C:\WINDOWS\System32\STI(2).DLL:KAVICHS
@Alternate Data Stream - 36 bytes -> C:\WINDOWS\System32\SSDPSRV(3).DLL:KAVICHS
@Alternate Data Stream - 36 bytes -> C:\WINDOWS\System32\SSDPAPI(3).DLL:KAVICHS
@Alternate Data Stream - 36 bytes -> C:\WINDOWS\System32\SRSVC(3).DLL:KAVICHS
@Alternate Data Stream - 36 bytes -> C:\WINDOWS\System32\SQLWOA.DLL:KAVICHS
@Alternate Data Stream - 36 bytes -> C:\WINDOWS\System32\SQLWID.DLL:KAVICHS
@Alternate Data Stream - 36 bytes -> C:\WINDOWS\System32\SQLSODBC.CHM:KAVICHS
@Alternate Data Stream - 36 bytes -> C:\WINDOWS\System32\SPXCOINS.DLL:KAVICHS
@Alternate Data Stream - 36 bytes -> C:\WINDOWS\System32\SPRIO800.DLL:KAVICHS
@Alternate Data Stream - 36 bytes -> C:\WINDOWS\System32\SPRIO600.DLL:KAVICHS
@Alternate Data Stream - 36 bytes -> C:\WINDOWS\System32\SPRESTRT.EXE:KAVICHS
@Alternate Data Stream - 36 bytes -> C:\WINDOWS\System32\SpotSaver.scr:KAVICHS
@Alternate Data Stream - 36 bytes -> C:\WINDOWS\System32\SPOOLSV(2).EXE:KAVICHS
@Alternate Data Stream - 36 bytes -> C:\WINDOWS\System32\SPOOLSS(2).DLL:KAVICHS
@Alternate Data Stream - 36 bytes -> C:\WINDOWS\System32\SPNIKE.DLL:KAVICHS
@Alternate Data Stream - 36 bytes -> C:\WINDOWS\System32\SOUND.DRV:KAVICHS
@Alternate Data Stream - 36 bytes -> C:\WINDOWS\System32\SORTKEY.NLS:KAVICHS
@Alternate Data Stream - 36 bytes -> C:\WINDOWS\System32\SOL.EXE:KAVICHS
@Alternate Data Stream - 36 bytes -> C:\WINDOWS\System32\SOFTPUB.DLL:KAVICHS
@Alternate Data Stream - 36 bytes -> C:\WINDOWS\System32\SNMPAPI(3).DLL:KAVICHS
@Alternate Data Stream - 36 bytes -> C:\WINDOWS\System32\SLBRCCSP.DLL:KAVICHS
@Alternate Data Stream - 36 bytes -> C:\WINDOWS\System32\slbcsp.dll:KAVICHS
@Alternate Data Stream - 36 bytes -> C:\WINDOWS\System32\SKDLL.DLL:KAVICHS
@Alternate Data Stream - 36 bytes -> C:\WINDOWS\System32\SISBKUP.DLL:KAVICHS
@Alternate Data Stream - 36 bytes -> C:\WINDOWS\System32\SHW32.DLL:KAVICHS
@Alternate Data Stream - 36 bytes -> C:\WINDOWS\System32\SHSVCS(3).DLL:KAVICHS
@Alternate Data Stream - 36 bytes -> C:\WINDOWS\System32\SHLWAPI(3).DLL:KAVICHS
@Alternate Data Stream - 36 bytes -> C:\WINDOWS\System32\SHIFTJIS.UCE:KAVICHS
@Alternate Data Stream - 36 bytes -> C:\WINDOWS\System32\SHGINA(3).DLL:KAVICHS
@Alternate Data Stream - 36 bytes -> C:\WINDOWS\System32\SHFOLDER(3).DLL:KAVICHS
@Alternate Data Stream - 36 bytes -> C:\WINDOWS\System32\shellstyle.dll:KAVICHS
@Alternate Data Stream - 36 bytes -> C:\WINDOWS\System32\shell32(3).dll:KAVICHS
@Alternate Data Stream - 36 bytes -> C:\WINDOWS\System32\SHELL.DLL:KAVICHS
@Alternate Data Stream - 36 bytes -> C:\WINDOWS\System32\shdocvw.bak:KAVICHS
@Alternate Data Stream - 36 bytes -> C:\WINDOWS\System32\SHDOCLC(2).DLL:KAVICHS
@Alternate Data Stream - 36 bytes -> C:\WINDOWS\System32\SHARE.EXE:KAVICHS
@Alternate Data Stream - 36 bytes -> C:\WINDOWS\System32\SHADOW.EXE:KAVICHS
@Alternate Data Stream - 36 bytes -> C:\WINDOWS\System32\SFMAPI.DLL:KAVICHS
@Alternate Data Stream - 36 bytes -> C:\WINDOWS\System32\SFC_OS(3).DLL:KAVICHS
@Alternate Data Stream - 36 bytes -> C:\WINDOWS\System32\SFC.EXE:KAVICHS
@Alternate Data Stream - 36 bytes -> C:\WINDOWS\System32\SFC(3).DLL:KAVICHS
@Alternate Data Stream - 36 bytes -> C:\WINDOWS\System32\SETVER.EXE:KAVICHS
@Alternate Data Stream - 36 bytes -> C:\WINDOWS\System32\SETUPDLL.DLL:KAVICHS
@Alternate Data Stream - 36 bytes -> C:\WINDOWS\System32\SETUP.BMP:KAVICHS
@Alternate Data Stream - 36 bytes -> C:\WINDOWS\System32\setb5.tmp:KAVICHS
@Alternate Data Stream - 36 bytes -> C:\WINDOWS\System32\SERVICES.MSC:KAVICHS
@Alternate Data Stream - 36 bytes -> C:\WINDOWS\System32\SERIALUI.DLL:KAVICHS
@Alternate Data Stream - 36 bytes -> C:\WINDOWS\System32\SENSCFG.DLL:KAVICHS
@Alternate Data Stream - 36 bytes -> C:\WINDOWS\System32\SENSAPI(3).DLL:KAVICHS
@Alternate Data Stream - 36 bytes -> C:\WINDOWS\System32\SENS(3).DLL:KAVICHS
@Alternate Data Stream - 36 bytes -> C:\WINDOWS\System32\SENDMAIL(2).DLL:KAVICHS
@Alternate Data Stream - 36 bytes -> C:\WINDOWS\System32\SECUR32(3).DLL:KAVICHS
@Alternate Data Stream - 36 bytes -> C:\WINDOWS\System32\secupd.sig:KAVICHS
@Alternate Data Stream - 36 bytes -> C:\WINDOWS\System32\secupd.dat:KAVICHS
@Alternate Data Stream - 36 bytes -> C:\WINDOWS\System32\SECLOGON(3).DLL:KAVICHS
@Alternate Data Stream - 36 bytes -> C:\WINDOWS\System32\SDPBLB.DLL:KAVICHS
@Alternate Data Stream - 36 bytes -> C:\WINDOWS\System32\SCRIPTO.DLL:KAVICHS
@Alternate Data Stream - 36 bytes -> C:\WINDOWS\System32\SCREDIR.DLL:KAVICHS
@Alternate Data Stream - 36 bytes -> C:\WINDOWS\System32\SCLGNTFY(3).DLL:KAVICHS
@Alternate Data Stream - 36 bytes -> C:\WINDOWS\System32\SCHEDSVC(3).DLL:KAVICHS
@Alternate Data Stream - 36 bytes -> C:\WINDOWS\System32\SCESRV(3).DLL:KAVICHS
@Alternate Data Stream - 36 bytes -> C:\WINDOWS\System32\SCECLI(3).DLL:KAVICHS
@Alternate Data Stream - 36 bytes -> C:\WINDOWS\System32\SCCBASE.DLL:KAVICHS
@Alternate Data Stream - 36 bytes -> C:\WINDOWS\System32\SCARDSSP.DLL:KAVICHS
@Alternate Data Stream - 36 bytes -> C:\WINDOWS\System32\SC.EXE:KAVICHS
@Alternate Data Stream - 36 bytes -> C:\WINDOWS\System32\RWINSTA.EXE:KAVICHS
@Alternate Data Stream - 36 bytes -> C:\WINDOWS\System32\RUNAS.EXE:KAVICHS
@Alternate Data Stream - 36 bytes -> C:\WINDOWS\System32\RTUTILS(3).DLL:KAVICHS
@Alternate Data Stream - 36 bytes -> C:\WINDOWS\System32\RTM.DLL:KAVICHS
@Alternate Data Stream - 36 bytes -> C:\WINDOWS\System32\RTCRES.dll:KAVICHS
@Alternate Data Stream - 36 bytes -> C:\WINDOWS\System32\RSVPPERF.DLL:KAVICHS
@Alternate Data Stream - 36 bytes -> C:\WINDOWS\System32\RSVPMSG.DLL:KAVICHS
@Alternate Data Stream - 36 bytes -> C:\WINDOWS\System32\RSVPCNTS.H:KAVICHS
@Alternate Data Stream - 36 bytes -> C:\WINDOWS\System32\RSVP.INI:KAVICHS
@Alternate Data Stream - 36 bytes -> C:\WINDOWS\System32\RSMUI.EXE:KAVICHS
@Alternate Data Stream - 36 bytes -> C:\WINDOWS\System32\RSMSINK.EXE:KAVICHS
@Alternate Data Stream - 36 bytes -> C:\WINDOWS\System32\RSM.EXE:KAVICHS
@Alternate Data Stream - 36 bytes -> C:\WINDOWS\System32\RSAENH(3).DLL:KAVICHS
@Alternate Data Stream - 36 bytes -> C:\WINDOWS\System32\RSACI.RAT:KAVICHS
@Alternate Data Stream - 36 bytes -> C:\WINDOWS\System32\RPCSS(3).DLL:KAVICHS
@Alternate Data Stream - 36 bytes -> C:\WINDOWS\System32\RPCRT4(3).DLL:KAVICHS
@Alternate Data Stream - 36 bytes -> C:\WINDOWS\System32\RPCNS4.DLL:KAVICHS
@Alternate Data Stream - 36 bytes -> C:\WINDOWS\System32\ROUTETAB.DLL:KAVICHS
@Alternate Data Stream - 36 bytes -> C:\WINDOWS\System32\ROUTEMON.EXE:KAVICHS
@Alternate Data Stream - 36 bytes -> C:\WINDOWS\System32\ROUTE.EXE:KAVICHS
@Alternate Data Stream - 36 bytes -> C:\WINDOWS\System32\ROBOEX32.DLL:KAVICHS
@Alternate Data Stream - 36 bytes -> C:\WINDOWS\System32\RNR20.DLL:KAVICHS
@Alternate Data Stream - 36 bytes -> C:\WINDOWS\System32\RICHED20(2).DLL:KAVICHS
@Alternate Data Stream - 36 bytes -> C:\WINDOWS\System32\RESUTILS(3).DLL:KAVICHS
@Alternate Data Stream - 36 bytes -> C:\WINDOWS\System32\RESET.EXE:KAVICHS
@Alternate Data Stream - 36 bytes -> C:\WINDOWS\System32\REPLACE.EXE:KAVICHS
@Alternate Data Stream - 36 bytes -> C:\WINDOWS\System32\REND.DLL:KAVICHS
@Alternate Data Stream - 36 bytes -> C:\WINDOWS\System32\REGWIZ.EXE:KAVICHS
@Alternate Data Stream - 36 bytes -> C:\WINDOWS\System32\REGINI.EXE:KAVICHS
@Alternate Data Stream - 36 bytes -> C:\WINDOWS\System32\REGEDT32.EXE:KAVICHS
@Alternate Data Stream - 36 bytes -> C:\WINDOWS\System32\REGAPI(3).DLL:KAVICHS
@Alternate Data Stream - 36 bytes -> C:\WINDOWS\System32\redir.exe:KAVICHS
@Alternate Data Stream - 36 bytes -> C:\WINDOWS\System32\RECOVER.EXE:KAVICHS
@Alternate Data Stream - 36 bytes -> C:\WINDOWS\System32\RDPCFGEX.DLL:KAVICHS
@Alternate Data Stream - 36 bytes -> C:\WINDOWS\System32\RASTLS(3).DLL:KAVICHS
@Alternate Data Stream - 36 bytes -> C:\WINDOWS\System32\RASSER.DLL:KAVICHS
@Alternate Data Stream - 36 bytes -> C:\WINDOWS\System32\RASRAD.DLL:KAVICHS
@Alternate Data Stream - 36 bytes -> C:\WINDOWS\System32\RASPPP(3).DLL:KAVICHS
@Alternate Data Stream - 36 bytes -> C:\WINDOWS\System32\RASMXS.DLL:KAVICHS
@Alternate Data Stream - 36 bytes -> C:\WINDOWS\System32\RASMONTR.DLL:KAVICHS
@Alternate Data Stream - 36 bytes -> C:\WINDOWS\System32\RASMANS(3).DLL:KAVICHS
@Alternate Data Stream - 36 bytes -> C:\WINDOWS\System32\RASDIAL.EXE:KAVICHS
@Alternate Data Stream - 36 bytes -> C:\WINDOWS\System32\RASCTRS.INI:KAVICHS
@Alternate Data Stream - 36 bytes -> C:\WINDOWS\System32\RASCTRS.DLL:KAVICHS
@Alternate Data Stream - 36 bytes -> C:\WINDOWS\System32\RASCTRNM.H:KAVICHS
@Alternate Data Stream - 36 bytes -> C:\WINDOWS\System32\RASCHAP(3).DLL:KAVICHS
@Alternate Data Stream - 36 bytes -> C:\WINDOWS\System32\RASAUTOU.EXE:KAVICHS
@Alternate Data Stream - 36 bytes -> C:\WINDOWS\System32\RASADHLP(3).DLL:KAVICHS
@Alternate Data Stream - 36 bytes -> C:\WINDOWS\System32\QWINSTA.EXE:KAVICHS
@Alternate Data Stream - 36 bytes -> C:\WINDOWS\System32\QUERY(2).DLL:KAVICHS
@Alternate Data Stream - 36 bytes -> C:\WINDOWS\System32\QOSNAME.DLL:KAVICHS
@Alternate Data Stream - 36 bytes -> C:\WINDOWS\System32\qmgrprxy(3).dll:KAVICHS
@Alternate Data Stream - 36 bytes -> C:\WINDOWS\System32\qmgr(3).dll:KAVICHS
@Alternate Data Stream - 36 bytes -> C:\WINDOWS\System32\qmgr(2).dll:KAVICHS
@Alternate Data Stream - 36 bytes -> C:\WINDOWS\System32\QAPPSRV.EXE:KAVICHS
@Alternate Data Stream - 36 bytes -> C:\WINDOWS\System32\PXWMA.dll:KAVICHS
@Alternate Data Stream - 36 bytes -> C:\WINDOWS\System32\PuzzSaver.scr:KAVICHS
@Alternate Data Stream - 36 bytes -> C:\WINDOWS\System32\PUBPRN.VBS:KAVICHS
@Alternate Data Stream - 36 bytes -> C:\WINDOWS\System32\ptpusd.dll:KAVICHS
@Alternate Data Stream - 36 bytes -> C:\WINDOWS\System32\ptpusb.dll:KAVICHS
@Alternate Data Stream - 36 bytes -> C:\WINDOWS\System32\PSTORSVC(3).DLL:KAVICHS
@Alternate Data Stream - 36 bytes -> C:\WINDOWS\System32\pspascrrc.dll:KAVICHS
@Alternate Data Stream - 36 bytes -> C:\WINDOWS\System32\PSNPPAGN.DLL:KAVICHS
@Alternate Data Stream - 36 bytes -> C:\WINDOWS\System32\PSCRIPT.SEP:KAVICHS
@Alternate Data Stream - 36 bytes -> C:\WINDOWS\System32\PSCHDPRF.INI:KAVICHS
@Alternate Data Stream - 36 bytes -> C:\WINDOWS\System32\PSCHDPRF.DLL:KAVICHS
@Alternate Data Stream - 36 bytes -> C:\WINDOWS\System32\PSCHDCNT.H:KAVICHS
@Alternate Data Stream - 36 bytes -> C:\WINDOWS\System32\PSBASE(3).DLL:KAVICHS
@Alternate Data Stream - 36 bytes -> C:\WINDOWS\System32\PSAPI(3).DLL:KAVICHS
@Alternate Data Stream - 36 bytes -> C:\WINDOWS\System32\PRONtObj.dll:KAVICHS
@Alternate Data Stream - 36 bytes -> C:\WINDOWS\System32\PROFMAP(3).DLL:KAVICHS
@Alternate Data Stream - 36 bytes -> C:\WINDOWS\System32\PRODSPEC.INI:KAVICHS
@Alternate Data Stream - 36 bytes -> C:\WINDOWS\System32\PRINT.EXE:KAVICHS
@Alternate Data Stream - 36 bytes -> C:\WINDOWS\System32\PRFLBMSG.DLL:KAVICHS
@Alternate Data Stream - 36 bytes -> C:\WINDOWS\System32\PRApplet.cpl:KAVICHS
@Alternate Data Stream - 36 bytes -> C:\WINDOWS\System32\POWRPROF(3).DLL:KAVICHS
@Alternate Data Stream - 36 bytes -> C:\WINDOWS\System32\popup.ocx:KAVICHS
@Alternate Data Stream - 36 bytes -> C:\WINDOWS\System32\PNGFILT(2).DLL:KAVICHS
@Alternate Data Stream - 36 bytes -> C:\WINDOWS\System32\PMSPL.DLL:KAVICHS
@Alternate Data Stream - 36 bytes -> C:\WINDOWS\System32\PLUSTAB.DLL:KAVICHS
@Alternate Data Stream - 36 bytes -> C:\WINDOWS\System32\PJLMON(2).DLL:KAVICHS
@Alternate Data Stream - 36 bytes -> C:\WINDOWS\System32\PING6.EXE:KAVICHS
@Alternate Data Stream - 36 bytes -> C:\WINDOWS\System32\PIFMGR.DLL:KAVICHS
@Alternate Data Stream - 36 bytes -> C:\WINDOWS\System32\PERFWCI.INI:KAVICHS
@Alternate Data Stream - 36 bytes -> C:\WINDOWS\System32\PERFWCI.H:KAVICHS
@Alternate Data Stream - 36 bytes -> C:\WINDOWS\System32\PERFTS.DLL:KAVICHS
@Alternate Data Stream - 36 bytes -> C:\WINDOWS\System32\PERFPROC(2).DLL:KAVICHS
@Alternate Data Stream - 36 bytes -> C:\WINDOWS\System32\PERFOS(2).DLL:KAVICHS
@Alternate Data Stream - 36 bytes -> C:\WINDOWS\System32\PERFI009.DAT:KAVICHS
@Alternate Data Stream - 36 bytes -> C:\WINDOWS\System32\PERFFILT.INI:KAVICHS
@Alternate Data Stream - 36 bytes -> C:\WINDOWS\System32\PERFFILT.H:KAVICHS
@Alternate Data Stream - 36 bytes -> C:\WINDOWS\System32\PERFDISK(2).DLL:KAVICHS
@Alternate Data Stream - 36 bytes -> C:\WINDOWS\System32\PERFD009.DAT:KAVICHS
@Alternate Data Stream - 36 bytes -> C:\WINDOWS\System32\PERFCI.INI:KAVICHS
@Alternate Data Stream - 36 bytes -> C:\WINDOWS\System32\PERFCI.H:KAVICHS
@Alternate Data Stream - 36 bytes -> C:\WINDOWS\System32\PENTNT.EXE:KAVICHS
@Alternate Data Stream - 36 bytes -> C:\WINDOWS\System32\PCL.SEP:KAVICHS
@Alternate Data Stream - 36 bytes -> C:\WINDOWS\System32\Pcdlib32.dll:KAVICHS
@Alternate Data Stream - 36 bytes -> C:\WINDOWS\System32\PATHPING.EXE:KAVICHS
@Alternate Data Stream - 36 bytes -> C:\WINDOWS\System32\ParaSaver.scr:KAVICHS
@Alternate Data Stream - 36 bytes -> C:\WINDOWS\System32\PAQSP.DLL:KAVICHS
@Alternate Data Stream - 36 bytes -> C:\WINDOWS\System32\PANMAP.DLL:KAVICHS
@Alternate Data Stream - 36 bytes -> C:\WINDOWS\System32\OSUNINST.EXE:KAVICHS
@Alternate Data Stream - 36 bytes -> C:\WINDOWS\System32\OLETHK32.DLL:KAVICHS
@Alternate Data Stream - 36 bytes -> C:\WINDOWS\System
Edited by mottern202, 24 February 2009 - 06:36 PM.