Jump to content

Welcome to Geeks to Go - Register now for FREE

Geeks To Go is a helpful hub, where thousands of volunteer geeks quickly serve friendly answers and support. Check out the forums and get free advice from the experts. Register now to gain access to all of our features, it's FREE and only takes one minute. Once registered and logged in, you will be able to create topics, post replies to existing threads, give reputation to your fellow members, get your own private messenger, post status updates, manage your profile and so much more.

Create Account How it Works
Photo

rdsndin, clicker.fr, 'baloon' (sic) [RESOLVED]


  • This topic is locked This topic is locked

#1
drpepperpdx

drpepperpdx

    New Member

  • Member
  • Pip
  • 7 posts
Symptoms are: massively slow system, frequent appearance of a yellow balloon "...status is bad click the baloon", and frequent appearance of a 'Windows Firewall' message.

I have run Ad-Aware, CWS Shredder, Spybot S&D, Spy Sweeper, and AVG. Of these, only AVG shows anything. And not on regular scans. It sporadically pops up, saying clicker.fr, and rdsndin.exe have been found. AVG isn't capable of quarantining or deleting the file.

Something odd hapened when I ran Spybot. It came up with this message: The parameter is incorrect. Access violation at address BFF7B9A6 in module KERNEL32.DLL. Write of address 05FF8099.

This is my SilentRunners log:

"Silent Runners.vbs", revision 39, http://www.silentrunners.org/
Operating System: Windows 98
Output limited to non-default values, except where indicated by "{++}"


Startup items buried in registry:
---------------------------------

HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\ {++}
"nView" = (empty string)

HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\ {++}
"SystemTray" = "SysTray.Exe" [MS]
"LoadPowerProfile" = "Rundll32.exe powrprof.dll,LoadCurrentPwrScheme" [MS]
"DisplayTrayIcon" = "C:\WINDOWS\System\TrayIcon.exe" ["4"]
"NvCplDaemon" = "RUNDLL32.EXE NvQTwk,NvCplDaemon initialize" [MS]
"EM_EXEC" = "C:\PROGRA~1\LOGITECH\MOUSEW~1\SYSTEM\EM_EXEC.EXE" ["Logitech Inc. "]
"LoadQM" = "loadqm.exe" [MS]
"3Cmlink" = "C:\WINDOWS\SYSTEM\3cmlnkW.exe" ["U.S. Robotics Corporation"]
"IntelliType" = ""C:\Program Files\Microsoft Hardware\Keyboard\type32.exe"" [MS]
"SoundMan" = "SOUNDMAN.EXE" ["Realtek Semiconductor Corp."]
"SpySweeper" = ""C:\PROGRAM FILES\WEBROOT\SPY SWEEPER\SPYSWEEPER.EXE" /startintray" ["Webroot Software, Inc."]
"AVG7_CC" = "C:\PROGRA~1\GRISOFT\AVGFRE~1\AVGCC.EXE /STARTUP" ["GRISOFT, s.r.o."]
"AVG7_EMC" = "C:\PROGRA~1\GRISOFT\AVGFRE~1\AVGEMC.EXE" ["GRISOFT, s.r.o."]
"AVG7_AMSVR" = "C:\PROGRA~1\GRISOFT\AVGFRE~1\AVGAMSVR.EXE" ["GRISOFT, s.r.o."]

HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\RunServices\ {++}
"LoadPowerProfile" = "Rundll32.exe powrprof.dll,LoadCurrentPwrScheme" [MS]
"KB891711" = "C:\WINDOWS\SYSTEM\KB891711\KB891711.EXE" [MS]

HKLM\Software\Microsoft\Active Setup\Installed Components\
{44BBA840-CC51-11CF-AAFA-00AA00B6015C}\(Default) = "Microsoft Outlook Express 5"
\StubPath = ""C:\PROGRA~1\OUTLOO~1\setup50.exe" /APP:OE /CALLER:IE50 /user /uninstall" [file not found]
{44BBA851-CC51-11CF-AAFA-00AA00B6015C}\(Default) = "Microsoft Web Publishing Wizard 1.6"
\StubPath = "rundll32.exe advpack.dll,LaunchINFSection C:\WINDOWS\INF\wpie5x86.inf,PerUserRemove" [MS]

HKLM\Software\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\
{53707962-6F74-2D53-2644-206D7942484F}\(Default) = (no title provided)
-> {CLSID}\InProcServer32\(Default) = "C:\Program Files\Spybot - Search & Destroy\SDHelper.dll" ["Safer Networking Limited"]

HKLM\Software\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved\
"{1CDB2949-8F65-4355-8456-263E7C208A5D}" = "Desktop Explorer"
-> {CLSID}\InProcServer32\(Default) = "C:\WINDOWS\SYSTEM\NVSHELL.DLL" ["NVIDIA Corporation"]
"{1E9B04FB-F9E5-4718-997B-B8DA88302A47}" = "Desktop Explorer Menu"
-> {CLSID}\InProcServer32\(Default) = "C:\WINDOWS\SYSTEM\NVSHELL.DLL" ["NVIDIA Corporation"]
"{1CAA843A-6DBD-40EF-AB71-8F7B209997C0}" = "IntelliType Pro Key Settings Control Panel Property Page"
-> {CLSID}\InProcServer32\(Default) = "C:\Program Files\Microsoft Hardware\Keyboard\itcpl.dll" [MS]
"{2E9D3540-211C-11d0-A5F2-00A0248C37BE}" = "Nero Shell Extension Property Sheet"
-> {CLSID}\InProcServer32\(Default) = "C:\Program Files\Ahead\Nero\neroshx.dll" ["ahead software gmbh im stoeckmaedle 6 76307 karlsbad, germany Fax: ++49-7248-911-888 e-mail: info@ahead.de"]
"{9F97547E-4609-42C5-AE0C-81C61FFAEBC3}" = "AVG7 Shell Extension"
-> {CLSID}\InProcServer32\(Default) = "C:\Program Files\Grisoft\AVG Free\avgse.dll" ["GRISOFT, s.r.o."]
"{9F97547E-460A-42C5-AE0C-81C61FFAEBC3}" = "AVG7 Find Extension"
-> {CLSID}\InProcServer32\(Default) = "C:\Program Files\Grisoft\AVG Free\avgse.dll" ["GRISOFT, s.r.o."]

HKLM\Software\Classes\*\shellex\ContextMenuHandlers\
WinZip\(Default) = "{E0D79304-84BE-11CE-9641-444553540000}"
-> {CLSID}\InProcServer32\(Default) = "C:\PROGRA~1\WINZIP\WZSHLSTB.DLL" ["WinZip Computing, Inc."]
AVG7 Shell Extension\(Default) = "{9F97547E-4609-42C5-AE0C-81C61FFAEBC3}"
-> {CLSID}\InProcServer32\(Default) = "C:\Program Files\Grisoft\AVG Free\avgse.dll" ["GRISOFT, s.r.o."]

HKLM\Software\Classes\Directory\shellex\ContextMenuHandlers\
WinZip\(Default) = "{E0D79304-84BE-11CE-9641-444553540000}"
-> {CLSID}\InProcServer32\(Default) = "C:\PROGRA~1\WINZIP\WZSHLSTB.DLL" ["WinZip Computing, Inc."]

HKLM\Software\Classes\Folder\shellex\ContextMenuHandlers\
WinZip\(Default) = "{E0D79304-84BE-11CE-9641-444553540000}"
-> {CLSID}\InProcServer32\(Default) = "C:\PROGRA~1\WINZIP\WZSHLSTB.DLL" ["WinZip Computing, Inc."]
SpySweeper\(Default) = "{7C9D5882-CB4A-4090-96C8-430BFE8B795B}"
-> {CLSID}\InProcServer32\(Default) = "C:\PROGRA~1\WEBROOT\SPYSWE~1\SSCTXMNU.DLL" ["Webroot Software, Inc."]
AVG7 Shell Extension\(Default) = "{9F97547E-4609-42C5-AE0C-81C61FFAEBC3}"
-> {CLSID}\InProcServer32\(Default) = "C:\Program Files\Grisoft\AVG Free\avgse.dll" ["GRISOFT, s.r.o."]


Active Desktop and Wallpaper:
-----------------------------

Active Desktop is enabled at this entry:
HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\ShellState


WIN.INI & SYSTEM.INI launch points:
-----------------------------------

SYSTEM.INI
[boot]
"SCRNSAVE.EXE=C:\WINDOWS\JOURNE~1.SCR" (JOURNEY UNIVERSE.scr) [null data]


Winsock2 Service Provider DLLs:
-------------------------------

Namespace Service Providers

HKLM\System\CurrentControlSet\Services\Winsock2\Parameters\NameSpace_Catalog5\Catalog_Entries\ {++}
000000000001\LibraryPath = "C:\WINDOWS\SYSTEM\rnr20.dll" [MS]

Transport Service Providers

HKLM\System\CurrentControlSet\Services\Winsock2\Parameters\Protocol_Catalog9\Catalog_Entries\ {++}
00000000000#\PackedCatalogItem (contains) DLL [Company Name], (at) # range:
C:\WINDOWS\SYSTEM\mswsosp.dll [MS], 1
C:\WINDOWS\SYSTEM\msafd.dll [MS], 2 - 4
C:\WINDOWS\SYSTEM\rsvpsp.dll [MS], 5 - 6


Toolbars, Explorer Bars, Extensions:
------------------------------------

Extensions (Tools menu items, main toolbar menu buttons)

HKLM\Software\Microsoft\Internet Explorer\Extensions\
{08B0E5C0-4FCB-11CF-AAA5-00401C608501}\
"MenuText" = "Sun Java Console"
"CLSIDExtension" = "{CAFEEFAC-0015-0000-0004-ABCDEFFEDCBC}"
-> {CLSID}\InProcServer32\(Default) = "C:\Program Files\Java\jre1.5.0_04\bin\npjpi150_04.dll" ["Sun Microsystems, Inc."]


----------
+ This report excludes default entries except where indicated.
+ To see *everywhere* the script checks and *everything* it finds,
launch it from a command prompt or a shortcut with the -all parameter.
+ The search for DESKTOP.INI DLL launch points on all local fixed drives
took 4 seconds.
+ The search for all Registry CLSIDs containing dormant Explorer Bars
took 60 seconds.
---------- (total run time: 73 seconds)

____________________________________________________________________________________________________________________________________________________________________________________________________________________________________________________________________________________________________________________________________________________


This is my HJT log:

Logfile of HijackThis v1.99.1
Scan saved at 4:09:52 AM, on 8/6/05
Platform: Windows 98 SE (Win9x 4.10.2222A)
MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)

Running processes:
C:\WINDOWS\SYSTEM\KERNEL32.DLL
C:\WINDOWS\SYSTEM\MSGSRV32.EXE
C:\WINDOWS\SYSTEM\MPREXE.EXE
C:\WINDOWS\SYSTEM\KB891711\KB891711.EXE
C:\WINDOWS\SYSTEM\mmtask.tsk
C:\WINDOWS\EXPLORER.EXE
C:\WINDOWS\SYSTEM\DDHELP.EXE
C:\WINDOWS\SYSTEM\SYSTRAY.EXE
C:\PROGRAM FILES\LOGITECH\MOUSEWARE\SYSTEM\EM_EXEC.EXE
C:\WINDOWS\LOADQM.EXE
C:\WINDOWS\SYSTEM\3CMLNKW.EXE
C:\PROGRAM FILES\MICROSOFT HARDWARE\KEYBOARD\TYPE32.EXE
C:\WINDOWS\SOUNDMAN.EXE
C:\PROGRAM FILES\GRISOFT\AVG FREE\AVGAMSVR.EXE
C:\WINDOWS\SYSTEM\WMIEXE.EXE
C:\WINDOWS\SYSTEM\WBEM\WINMGMT.EXE
C:\PROGRAM FILES\YAHOO!\MESSENGER\YPAGER.EXE
C:\PROGRAM FILES\JUNO\BIN\JUNO.EXE
C:\WINDOWS\SYSTEM\TAPISRV.EXE
C:\WINDOWS\SYSTEM\RNAAPP.EXE
C:\PROGRAM FILES\INTERNET EXPLORER\IEXPLORE.EXE
C:\MY DOCUMENTS\HIJACKTHIS.EXE

O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll
O4 - HKLM\..\Run: [SystemTray] SysTray.Exe
O4 - HKLM\..\Run: [LoadPowerProfile] Rundll32.exe powrprof.dll,LoadCurrentPwrScheme
O4 - HKLM\..\Run: [DisplayTrayIcon] C:\WINDOWS\System\TrayIcon.exe
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE NvQTwk,NvCplDaemon initialize
O4 - HKLM\..\Run: [EM_EXEC] C:\PROGRA~1\LOGITECH\MOUSEW~1\SYSTEM\EM_EXEC.EXE
O4 - HKLM\..\Run: [LoadQM] loadqm.exe
O4 - HKLM\..\Run: [3Cmlink] C:\WINDOWS\SYSTEM\3cmlnkW.exe
O4 - HKLM\..\Run: [IntelliType] "C:\Program Files\Microsoft Hardware\Keyboard\type32.exe"
O4 - HKLM\..\Run: [SoundMan] SOUNDMAN.EXE
O4 - HKLM\..\Run: [SpySweeper] "C:\PROGRAM FILES\WEBROOT\SPY SWEEPER\SPYSWEEPER.EXE" /startintray
O4 - HKLM\..\Run: [AVG7_CC] C:\PROGRA~1\GRISOFT\AVGFRE~1\AVGCC.EXE /STARTUP
O4 - HKLM\..\Run: [AVG7_EMC] C:\PROGRA~1\GRISOFT\AVGFRE~1\AVGEMC.EXE
O4 - HKLM\..\Run: [AVG7_AMSVR] C:\PROGRA~1\GRISOFT\AVGFRE~1\AVGAMSVR.EXE
O4 - HKLM\..\RunServices: [LoadPowerProfile] Rundll32.exe powrprof.dll,LoadCurrentPwrScheme
O4 - HKLM\..\RunServices: [KB891711] C:\WINDOWS\SYSTEM\KB891711\KB891711.EXE
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_04\bin\npjpi150_04.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_04\bin\npjpi150_04.dll
  • 0

Advertisements


#2
Metallica

Metallica

    Spyware Veteran

  • GeekU Moderator
  • 31,676 posts
Download WinPFind.zip and unzip the contents to the C:\ folder.

Start in Safe Mode Using the F8 method:
  • Restart the computer.
  • As soon as the BIOS is loaded begin tapping the F8 key until the boot menu appears.
  • Use the arrow keys to select the Safe Mode menu item.
  • Press the Enter key.
Locate the c:\winpfind\winpfind.exe file and double-click it to run it. Now click the Start Scan button to begin the scan.

When the scan is complete reboot normally and post the WinPFind.txt file (located in the WinPFind folder)
  • 0

#3
drpepperpdx

drpepperpdx

    New Member

  • Topic Starter
  • Member
  • Pip
  • 7 posts
WinPFind log


WARNING: not all files found by this scanner are bad. Consult with a knowledgable person before proceeding.

If you see a message in the titlebar saying "Not responding..." you can ignore it. Windows somethimes displays this message due to the high volume of disk I/O. As long as the hard disk light is flashing, the program is still working properly.

»»»»»»»»»»»»»»»»» Checking Selected Standard Folders »»»»»»»»»»»»»»»»»»»»

Checking %SystemDrive% folder...

Checking %ProgramFilesDir% folder...

Checking %WinDir% folder...
UPX! 5/19/05 6:02:12 AM 18432 C:\WINDOWS\ss3unstl.exe

Checking %System% folder...
UPX! 8/6/05 12:03:22 PM 4608 C:\WINDOWS\SYSTEM\rdsndin.exe
UPX! 8/6/05 12:03:22 PM 45568 C:\WINDOWS\SYSTEM\ntfsnlpa.exe
UPX! 3/19/04 8:11:42 AM 119808 C:\WINDOWS\SYSTEM\bH.dll
UPX! 3/20/04 6:32:36 PM 97280 C:\WINDOWS\SYSTEM\msbb321.dll
PTech 11/9/99 3:55:54 PM 88571 C:\WINDOWS\SYSTEM\MDACRDME.HTM
UPX! 7/13/03 12:15:54 PM 287744 C:\WINDOWS\SYSTEM\DCDSPFilter.ax
UPX! 7/14/03 11:25:22 AM 335360 C:\WINDOWS\SYSTEM\GnucDNA.dll
aspack 3/15/05 12:30:32 AM 197120 C:\WINDOWS\SYSTEM\Huck_ScreenSaver.scr

Checking %System%\Drivers folder and sub-folders...

Checking the Windows folder for system and hidden files within the last 60 days...
8/6/05 12:19:06 PM 995360 C:\WINDOWS\USER.DAT
8/6/05 12:15:50 PM 7000096 C:\WINDOWS\SYSTEM.DAT
8/6/05 4:28:08 AM 11371 C:\WINDOWS\ttfCache
8/6/05 12:13:06 PM 1105073 C:\WINDOWS\ShellIconCache
8/5/05 12:59:32 AM 0 C:\WINDOWS\TEMP\CS2D807E61-054C-11DA-96D4-00508D472018.tmp
8/5/05 12:59:32 AM 0 C:\WINDOWS\TEMP\CS2D807E62-054C-11DA-96D4-00508D472018.tmp
8/5/05 12:59:32 AM 0 C:\WINDOWS\TEMP\CS2D807E63-054C-11DA-96D4-00508D472018.tmp
8/5/05 12:59:32 AM 0 C:\WINDOWS\TEMP\CS2D807E64-054C-11DA-96D4-00508D472018.tmp
7/18/05 9:40:28 PM 30 C:\WINDOWS\TEMP\CS3D067841-F7D1-11D9-96D3-00508D472018.tmp
7/18/05 9:40:28 PM 0 C:\WINDOWS\TEMP\CS3D067842-F7D1-11D9-96D3-00508D472018.tmp
7/18/05 9:40:28 PM 0 C:\WINDOWS\TEMP\CS3D067843-F7D1-11D9-96D3-00508D472018.tmp
7/18/05 9:40:28 PM 1898904 C:\WINDOWS\TEMP\CS3D067844-F7D1-11D9-96D3-00508D472018.tmp
7/18/05 9:40:28 PM 1143806 C:\WINDOWS\TEMP\CS3D067845-F7D1-11D9-96D3-00508D472018.tmp
7/18/05 9:40:28 PM 1474562 C:\WINDOWS\TEMP\CS3D067846-F7D1-11D9-96D3-00508D472018.tmp
7/18/05 9:40:28 PM 80360 C:\WINDOWS\TEMP\CS3D067847-F7D1-11D9-96D3-00508D472018.tmp
7/18/05 9:40:28 PM 101742 C:\WINDOWS\TEMP\CS3D067848-F7D1-11D9-96D3-00508D472018.tmp
7/18/05 9:40:28 PM 22032 C:\WINDOWS\TEMP\CS3D067849-F7D1-11D9-96D3-00508D472018.tmp
7/18/05 9:40:28 PM 67418 C:\WINDOWS\TEMP\CS3D06784A-F7D1-11D9-96D3-00508D472018.tmp
7/18/05 9:40:28 PM 1193738 C:\WINDOWS\TEMP\CS3D06784B-F7D1-11D9-96D3-00508D472018.tmp
7/18/05 9:40:28 PM 682 C:\WINDOWS\TEMP\CS3D06784C-F7D1-11D9-96D3-00508D472018.tmp
7/18/05 9:40:28 PM 228 C:\WINDOWS\TEMP\CS3D06784D-F7D1-11D9-96D3-00508D472018.tmp
7/18/05 9:40:28 PM 516 C:\WINDOWS\TEMP\CS3D06784E-F7D1-11D9-96D3-00508D472018.tmp
7/18/05 9:40:28 PM 3249 C:\WINDOWS\TEMP\CS3D06784F-F7D1-11D9-96D3-00508D472018.tmp
7/18/05 9:40:28 PM 160 C:\WINDOWS\TEMP\CS3D067850-F7D1-11D9-96D3-00508D472018.tmp
7/18/05 9:40:28 PM 5568 C:\WINDOWS\TEMP\CS3D067851-F7D1-11D9-96D3-00508D472018.tmp
7/18/05 9:40:28 PM 63296 C:\WINDOWS\TEMP\CS3D067852-F7D1-11D9-96D3-00508D472018.tmp
7/18/05 9:40:28 PM 180 C:\WINDOWS\TEMP\CS3D067853-F7D1-11D9-96D3-00508D472018.tmp
7/18/05 9:40:28 PM 1062 C:\WINDOWS\TEMP\CS3D067854-F7D1-11D9-96D3-00508D472018.tmp
7/18/05 9:40:28 PM 126 C:\WINDOWS\TEMP\CS3D067855-F7D1-11D9-96D3-00508D472018.tmp
7/18/05 9:40:28 PM 32 C:\WINDOWS\TEMP\CS3D067856-F7D1-11D9-96D3-00508D472018.tmp
7/18/05 9:40:28 PM 934 C:\WINDOWS\TEMP\CS3D067857-F7D1-11D9-96D3-00508D472018.tmp
7/18/05 9:40:28 PM 1276830 C:\WINDOWS\TEMP\CS3D067858-F7D1-11D9-96D3-00508D472018.tmp
7/18/05 9:40:28 PM 591862 C:\WINDOWS\TEMP\CS3D067859-F7D1-11D9-96D3-00508D472018.tmp
7/18/05 9:40:28 PM 998134 C:\WINDOWS\TEMP\CS3D06785A-F7D1-11D9-96D3-00508D472018.tmp
7/18/05 9:40:28 PM 512876 C:\WINDOWS\TEMP\CS3D06785B-F7D1-11D9-96D3-00508D472018.tmp
7/18/05 9:40:28 PM 35638 C:\WINDOWS\TEMP\CS3D06785C-F7D1-11D9-96D3-00508D472018.tmp
7/18/05 9:40:28 PM 91830 C:\WINDOWS\TEMP\CS3D06785D-F7D1-11D9-96D3-00508D472018.tmp
7/18/05 9:40:28 PM 35144 C:\WINDOWS\TEMP\CS3D06785E-F7D1-11D9-96D3-00508D472018.tmp
7/18/05 9:40:28 PM 5044 C:\WINDOWS\TEMP\CS3D06785F-F7D1-11D9-96D3-00508D472018.tmp
7/18/05 9:40:28 PM 168 C:\WINDOWS\TEMP\CS3D067860-F7D1-11D9-96D3-00508D472018.tmp
7/18/05 9:40:28 PM 10 C:\WINDOWS\TEMP\CS3D067861-F7D1-11D9-96D3-00508D472018.tmp
7/18/05 9:40:28 PM 40 C:\WINDOWS\TEMP\CS3D067862-F7D1-11D9-96D3-00508D472018.tmp
7/18/05 9:40:28 PM 14 C:\WINDOWS\TEMP\CS3D067863-F7D1-11D9-96D3-00508D472018.tmp
7/18/05 9:40:28 PM 30 C:\WINDOWS\TEMP\CS3D067864-F7D1-11D9-96D3-00508D472018.tmp
7/18/05 9:40:28 PM 44 C:\WINDOWS\TEMP\CS3D067865-F7D1-11D9-96D3-00508D472018.tmp
7/18/05 9:40:28 PM 46 C:\WINDOWS\TEMP\CS3D067866-F7D1-11D9-96D3-00508D472018.tmp
7/18/05 9:40:28 PM 530 C:\WINDOWS\TEMP\CS3D067867-F7D1-11D9-96D3-00508D472018.tmp
7/18/05 9:40:28 PM 70 C:\WINDOWS\TEMP\CS3D067868-F7D1-11D9-96D3-00508D472018.tmp
7/18/05 9:40:28 PM 530 C:\WINDOWS\TEMP\CS3D067869-F7D1-11D9-96D3-00508D472018.tmp
7/18/05 9:40:28 PM 530 C:\WINDOWS\TEMP\CS3D06786A-F7D1-11D9-96D3-00508D472018.tmp
7/18/05 9:40:28 PM 40 C:\WINDOWS\TEMP\CS3D06786B-F7D1-11D9-96D3-00508D472018.tmp
7/18/05 9:40:28 PM 50 C:\WINDOWS\TEMP\CS3D06786C-F7D1-11D9-96D3-00508D472018.tmp
7/18/05 9:40:28 PM 86 C:\WINDOWS\TEMP\CS3D06786D-F7D1-11D9-96D3-00508D472018.tmp
7/18/05 9:40:28 PM 44 C:\WINDOWS\TEMP\CS3D06786E-F7D1-11D9-96D3-00508D472018.tmp
7/18/05 9:40:28 PM 44 C:\WINDOWS\TEMP\CS3D06786F-F7D1-11D9-96D3-00508D472018.tmp
7/18/05 9:40:28 PM 530 C:\WINDOWS\TEMP\CS3D067870-F7D1-11D9-96D3-00508D472018.tmp
7/18/05 9:40:28 PM 52 C:\WINDOWS\TEMP\CS3D067871-F7D1-11D9-96D3-00508D472018.tmp
7/18/05 9:40:28 PM 10 C:\WINDOWS\TEMP\CS3D067872-F7D1-11D9-96D3-00508D472018.tmp
7/18/05 9:40:28 PM 10 C:\WINDOWS\TEMP\CS3D067873-F7D1-11D9-96D3-00508D472018.tmp
7/18/05 9:40:28 PM 10 C:\WINDOWS\TEMP\CS3D067874-F7D1-11D9-96D3-00508D472018.tmp
7/18/05 9:40:28 PM 10 C:\WINDOWS\TEMP\CS3D067875-F7D1-11D9-96D3-00508D472018.tmp
7/18/05 9:40:28 PM 46 C:\WINDOWS\TEMP\CS3D067876-F7D1-11D9-96D3-00508D472018.tmp
7/18/05 9:40:28 PM 530 C:\WINDOWS\TEMP\CS3D067877-F7D1-11D9-96D3-00508D472018.tmp
7/18/05 9:40:28 PM 530 C:\WINDOWS\TEMP\CS3D067878-F7D1-11D9-96D3-00508D472018.tmp
7/18/05 9:40:28 PM 46 C:\WINDOWS\TEMP\CS3D067879-F7D1-11D9-96D3-00508D472018.tmp
7/18/05 9:40:28 PM 42 C:\WINDOWS\TEMP\CS3D06787A-F7D1-11D9-96D3-00508D472018.tmp
7/18/05 9:40:28 PM 48 C:\WINDOWS\TEMP\CS3D06787B-F7D1-11D9-96D3-00508D472018.tmp
7/18/05 9:40:28 PM 10 C:\WINDOWS\TEMP\CS3D06787C-F7D1-11D9-96D3-00508D472018.tmp
7/18/05 9:40:28 PM 10 C:\WINDOWS\TEMP\CS3D06787D-F7D1-11D9-96D3-00508D472018.tmp
7/18/05 9:40:28 PM 10 C:\WINDOWS\TEMP\CS3D06787E-F7D1-11D9-96D3-00508D472018.tmp
7/18/05 9:40:28 PM 10 C:\WINDOWS\TEMP\CS3D06787F-F7D1-11D9-96D3-00508D472018.tmp
7/18/05 9:40:28 PM 64 C:\WINDOWS\TEMP\CS3D067880-F7D1-11D9-96D3-00508D472018.tmp
7/18/05 9:40:28 PM 50 C:\WINDOWS\TEMP\CS3D067881-F7D1-11D9-96D3-00508D472018.tmp
7/18/05 9:40:28 PM 94 C:\WINDOWS\TEMP\CS3D067882-F7D1-11D9-96D3-00508D472018.tmp
7/18/05 9:40:28 PM 10 C:\WINDOWS\TEMP\CS3D067883-F7D1-11D9-96D3-00508D472018.tmp
7/18/05 9:40:28 PM 10 C:\WINDOWS\TEMP\CS3D067884-F7D1-11D9-96D3-00508D472018.tmp
7/18/05 9:40:28 PM 10 C:\WINDOWS\TEMP\CS3D067885-F7D1-11D9-96D3-00508D472018.tmp
7/18/05 9:40:28 PM 80 C:\WINDOWS\TEMP\CS3D067886-F7D1-11D9-96D3-00508D472018.tmp
7/18/05 9:40:28 PM 46 C:\WINDOWS\TEMP\CS3D067887-F7D1-11D9-96D3-00508D472018.tmp
7/18/05 9:40:28 PM 46 C:\WINDOWS\TEMP\CS3D067888-F7D1-11D9-96D3-00508D472018.tmp
7/18/05 9:40:28 PM 10 C:\WINDOWS\TEMP\CS3D067889-F7D1-11D9-96D3-00508D472018.tmp
7/18/05 9:40:28 PM 30 C:\WINDOWS\TEMP\CS3D06788A-F7D1-11D9-96D3-00508D472018.tmp
7/18/05 9:40:28 PM 44 C:\WINDOWS\TEMP\CS3D06788B-F7D1-11D9-96D3-00508D472018.tmp
7/18/05 9:40:28 PM 42 C:\WINDOWS\TEMP\CS3D06788C-F7D1-11D9-96D3-00508D472018.tmp
7/18/05 9:40:28 PM 10 C:\WINDOWS\TEMP\CS3D06788D-F7D1-11D9-96D3-00508D472018.tmp
7/18/05 9:40:28 PM 10 C:\WINDOWS\TEMP\CS3D06788E-F7D1-11D9-96D3-00508D472018.tmp
7/18/05 9:40:28 PM 10 C:\WINDOWS\TEMP\CS3D06788F-F7D1-11D9-96D3-00508D472018.tmp
7/18/05 9:40:28 PM 10 C:\WINDOWS\TEMP\CS3D067890-F7D1-11D9-96D3-00508D472018.tmp
7/18/05 9:40:28 PM 10 C:\WINDOWS\TEMP\CS3D067891-F7D1-11D9-96D3-00508D472018.tmp
7/18/05 9:40:28 PM 10 C:\WINDOWS\TEMP\CS3D067892-F7D1-11D9-96D3-00508D472018.tmp
7/18/05 9:40:28 PM 10 C:\WINDOWS\TEMP\CS3D067893-F7D1-11D9-96D3-00508D472018.tmp
7/18/05 9:40:28 PM 10 C:\WINDOWS\TEMP\CS3D067894-F7D1-11D9-96D3-00508D472018.tmp
7/18/05 9:40:28 PM 10 C:\WINDOWS\TEMP\CS3D067895-F7D1-11D9-96D3-00508D472018.tmp
7/18/05 9:40:28 PM 10 C:\WINDOWS\TEMP\CS3D067896-F7D1-11D9-96D3-00508D472018.tmp
7/18/05 9:40:28 PM 10 C:\WINDOWS\TEMP\CS3D067897-F7D1-11D9-96D3-00508D472018.tmp
7/18/05 9:40:28 PM 10 C:\WINDOWS\TEMP\CS3D067898-F7D1-11D9-96D3-00508D472018.tmp
7/18/05 9:40:28 PM 10 C:\WINDOWS\TEMP\CS3D067899-F7D1-11D9-96D3-00508D472018.tmp
7/18/05 9:40:28 PM 10 C:\WINDOWS\TEMP\CS3D06789A-F7D1-11D9-96D3-00508D472018.tmp
7/18/05 9:40:28 PM 10 C:\WINDOWS\TEMP\CS3D06789B-F7D1-11D9-96D3-00508D472018.tmp
7/18/05 9:40:28 PM 10 C:\WINDOWS\TEMP\CS3D06789C-F7D1-11D9-96D3-00508D472018.tmp
7/18/05 9:40:28 PM 10 C:\WINDOWS\TEMP\CS3D06789D-F7D1-11D9-96D3-00508D472018.tmp
7/18/05 9:40:28 PM 10 C:\WINDOWS\TEMP\CS3D06789E-F7D1-11D9-96D3-00508D472018.tmp
7/18/05 9:40:28 PM 10 C:\WINDOWS\TEMP\CS3D06789F-F7D1-11D9-96D3-00508D472018.tmp
7/18/05 9:40:28 PM 10 C:\WINDOWS\TEMP\CS3D0678A0-F7D1-11D9-96D3-00508D472018.tmp
7/18/05 9:40:28 PM 10 C:\WINDOWS\TEMP\CS3D0678A1-F7D1-11D9-96D3-00508D472018.tmp
7/18/05 9:40:28 PM 10 C:\WINDOWS\TEMP\CS3D0678A2-F7D1-11D9-96D3-00508D472018.tmp
7/18/05 9:40:28 PM 10 C:\WINDOWS\TEMP\CS3D0678A3-F7D1-11D9-96D3-00508D472018.tmp
7/18/05 9:40:28 PM 10 C:\WINDOWS\TEMP\CS3D0678A4-F7D1-11D9-96D3-00508D472018.tmp
7/18/05 9:40:28 PM 10 C:\WINDOWS\TEMP\CS3D0678A5-F7D1-11D9-96D3-00508D472018.tmp
7/19/05 5:13:52 PM 30 C:\WINDOWS\TEMP\CS1AB98181-F874-11D9-96D3-00508D472018.tmp
7/19/05 5:13:52 PM 0 C:\WINDOWS\TEMP\CS1AB98182-F874-11D9-96D3-00508D472018.tmp
7/19/05 5:13:52 PM 0 C:\WINDOWS\TEMP\CS1AB98183-F874-11D9-96D3-00508D472018.tmp
7/19/05 5:13:52 PM 1898904 C:\WINDOWS\TEMP\CS1AB98184-F874-11D9-96D3-00508D472018.tmp
7/19/05 5:13:52 PM 1143806 C:\WINDOWS\TEMP\CS1AB98185-F874-11D9-96D3-00508D472018.tmp
7/19/05 5:13:52 PM 1474562 C:\WINDOWS\TEMP\CS1AB98186-F874-11D9-96D3-00508D472018.tmp
7/19/05 5:13:52 PM 80360 C:\WINDOWS\TEMP\CS1AB98187-F874-11D9-96D3-00508D472018.tmp
7/19/05 5:13:52 PM 101742 C:\WINDOWS\TEMP\CS1AB98188-F874-11D9-96D3-00508D472018.tmp
7/19/05 5:13:52 PM 22032 C:\WINDOWS\TEMP\CS1AB98189-F874-11D9-96D3-00508D472018.tmp
7/19/05 5:13:52 PM 67418 C:\WINDOWS\TEMP\CS1AB9818A-F874-11D9-96D3-00508D472018.tmp
7/19/05 5:13:52 PM 1193738 C:\WINDOWS\TEMP\CS1AB9818B-F874-11D9-96D3-00508D472018.tmp
7/19/05 5:13:52 PM 682 C:\WINDOWS\TEMP\CS1AB9818C-F874-11D9-96D3-00508D472018.tmp
7/19/05 5:13:52 PM 228 C:\WINDOWS\TEMP\CS1AB9818D-F874-11D9-96D3-00508D472018.tmp
7/19/05 5:13:52 PM 516 C:\WINDOWS\TEMP\CS1AB9818E-F874-11D9-96D3-00508D472018.tmp
7/19/05 5:13:52 PM 3249 C:\WINDOWS\TEMP\CS1AB9818F-F874-11D9-96D3-00508D472018.tmp
7/19/05 5:13:52 PM 160 C:\WINDOWS\TEMP\CS1AB98190-F874-11D9-96D3-00508D472018.tmp
7/19/05 5:13:52 PM 5568 C:\WINDOWS\TEMP\CS1AB98191-F874-11D9-96D3-00508D472018.tmp
7/19/05 5:13:52 PM 63296 C:\WINDOWS\TEMP\CS1AB98192-F874-11D9-96D3-00508D472018.tmp
7/19/05 5:13:52 PM 180 C:\WINDOWS\TEMP\CS1AB98193-F874-11D9-96D3-00508D472018.tmp
7/19/05 5:13:52 PM 1062 C:\WINDOWS\TEMP\CS1AB98194-F874-11D9-96D3-00508D472018.tmp
7/19/05 5:13:52 PM 126 C:\WINDOWS\TEMP\CS1AB98195-F874-11D9-96D3-00508D472018.tmp
7/19/05 5:13:52 PM 32 C:\WINDOWS\TEMP\CS1AB98196-F874-11D9-96D3-00508D472018.tmp
7/19/05 5:13:52 PM 934 C:\WINDOWS\TEMP\CS1AB98197-F874-11D9-96D3-00508D472018.tmp
7/19/05 5:13:52 PM 1276830 C:\WINDOWS\TEMP\CS1AB98198-F874-11D9-96D3-00508D472018.tmp
7/19/05 5:13:52 PM 591862 C:\WINDOWS\TEMP\CS1AB98199-F874-11D9-96D3-00508D472018.tmp
7/19/05 5:13:52 PM 998134 C:\WINDOWS\TEMP\CS1AB9819A-F874-11D9-96D3-00508D472018.tmp
7/19/05 5:13:52 PM 512876 C:\WINDOWS\TEMP\CS1AB9819B-F874-11D9-96D3-00508D472018.tmp
7/19/05 5:13:52 PM 35638 C:\WINDOWS\TEMP\CS1AB9819C-F874-11D9-96D3-00508D472018.tmp
7/19/05 5:13:52 PM 91830 C:\WINDOWS\TEMP\CS1AB9819D-F874-11D9-96D3-00508D472018.tmp
7/19/05 5:13:52 PM 35144 C:\WINDOWS\TEMP\CS1AB9819E-F874-11D9-96D3-00508D472018.tmp
7/19/05 5:13:52 PM 5044 C:\WINDOWS\TEMP\CS1AB9819F-F874-11D9-96D3-00508D472018.tmp
7/19/05 5:13:52 PM 168 C:\WINDOWS\TEMP\CS1AB981A0-F874-11D9-96D3-00508D472018.tmp
7/19/05 5:13:52 PM 10 C:\WINDOWS\TEMP\CS1AB981A1-F874-11D9-96D3-00508D472018.tmp
7/19/05 5:13:52 PM 40 C:\WINDOWS\TEMP\CS1AB981A2-F874-11D9-96D3-00508D472018.tmp
7/19/05 5:13:52 PM 14 C:\WINDOWS\TEMP\CS1AB981A3-F874-11D9-96D3-00508D472018.tmp
7/19/05 5:13:52 PM 30 C:\WINDOWS\TEMP\CS1AB981A4-F874-11D9-96D3-00508D472018.tmp
7/19/05 5:13:52 PM 44 C:\WINDOWS\TEMP\CS1AB981A5-F874-11D9-96D3-00508D472018.tmp
7/19/05 5:13:52 PM 46 C:\WINDOWS\TEMP\CS1AB981A6-F874-11D9-96D3-00508D472018.tmp
7/19/05 5:13:52 PM 530 C:\WINDOWS\TEMP\CS1AB981A7-F874-11D9-96D3-00508D472018.tmp
7/19/05 5:13:52 PM 70 C:\WINDOWS\TEMP\CS1AB981A8-F874-11D9-96D3-00508D472018.tmp
7/19/05 5:13:52 PM 530 C:\WINDOWS\TEMP\CS1AB981A9-F874-11D9-96D3-00508D472018.tmp
7/19/05 5:13:52 PM 530 C:\WINDOWS\TEMP\CS1AB981AA-F874-11D9-96D3-00508D472018.tmp
7/19/05 5:13:52 PM 40 C:\WINDOWS\TEMP\CS1AB981AB-F874-11D9-96D3-00508D472018.tmp
7/19/05 5:13:52 PM 50 C:\WINDOWS\TEMP\CS1AB981AC-F874-11D9-96D3-00508D472018.tmp
7/19/05 5:13:52 PM 86 C:\WINDOWS\TEMP\CS1AB981AD-F874-11D9-96D3-00508D472018.tmp
7/19/05 5:13:52 PM 44 C:\WINDOWS\TEMP\CS1AB981AE-F874-11D9-96D3-00508D472018.tmp
7/19/05 5:13:52 PM 44 C:\WINDOWS\TEMP\CS1AB981AF-F874-11D9-96D3-00508D472018.tmp
7/19/05 5:13:52 PM 530 C:\WINDOWS\TEMP\CS1AB981B0-F874-11D9-96D3-00508D472018.tmp
7/19/05 5:13:52 PM 52 C:\WINDOWS\TEMP\CS1AB981B1-F874-11D9-96D3-00508D472018.tmp
7/19/05 5:13:52 PM 10 C:\WINDOWS\TEMP\CS1AB981B2-F874-11D9-96D3-00508D472018.tmp
7/19/05 5:13:52 PM 10 C:\WINDOWS\TEMP\CS1AB981B3-F874-11D9-96D3-00508D472018.tmp
7/19/05 5:13:52 PM 10 C:\WINDOWS\TEMP\CS1AB981B4-F874-11D9-96D3-00508D472018.tmp
7/19/05 5:13:52 PM 10 C:\WINDOWS\TEMP\CS1AB981B5-F874-11D9-96D3-00508D472018.tmp
7/19/05 5:13:52 PM 46 C:\WINDOWS\TEMP\CS1AB981B6-F874-11D9-96D3-00508D472018.tmp
7/19/05 5:13:52 PM 530 C:\WINDOWS\TEMP\CS1AB981B7-F874-11D9-96D3-00508D472018.tmp
7/19/05 5:13:52 PM 530 C:\WINDOWS\TEMP\CS1AB981B8-F874-11D9-96D3-00508D472018.tmp
7/19/05 5:13:52 PM 46 C:\WINDOWS\TEMP\CS1AB981B9-F874-11D9-96D3-00508D472018.tmp
7/19/05 5:13:52 PM 42 C:\WINDOWS\TEMP\CS1AB981BA-F874-11D9-96D3-00508D472018.tmp
7/19/05 5:13:52 PM 48 C:\WINDOWS\TEMP\CS1AB981BB-F874-11D9-96D3-00508D472018.tmp
7/19/05 5:13:52 PM 10 C:\WINDOWS\TEMP\CS1AB981BC-F874-11D9-96D3-00508D472018.tmp
7/19/05 5:13:52 PM 10 C:\WINDOWS\TEMP\CS1AB981BD-F874-11D9-96D3-00508D472018.tmp
7/19/05 5:13:52 PM 10 C:\WINDOWS\TEMP\CS1AB981BE-F874-11D9-96D3-00508D472018.tmp
7/19/05 5:13:52 PM 10 C:\WINDOWS\TEMP\CS1AB981BF-F874-11D9-96D3-00508D472018.tmp
7/19/05 5:13:52 PM 64 C:\WINDOWS\TEMP\CS1AB981C0-F874-11D9-96D3-00508D472018.tmp
7/19/05 5:13:52 PM 50 C:\WINDOWS\TEMP\CS1AB981C1-F874-11D9-96D3-00508D472018.tmp
7/19/05 5:13:52 PM 94 C:\WINDOWS\TEMP\CS1AB981C2-F874-11D9-96D3-00508D472018.tmp
7/19/05 5:13:52 PM 10 C:\WINDOWS\TEMP\CS1AB981C3-F874-11D9-96D3-00508D472018.tmp
7/19/05 5:13:52 PM 10 C:\WINDOWS\TEMP\CS1AB981C4-F874-11D9-96D3-00508D472018.tmp
7/19/05 5:13:52 PM 10 C:\WINDOWS\TEMP\CS1AB981C5-F874-11D9-96D3-00508D472018.tmp
7/19/05 5:13:52 PM 80 C:\WINDOWS\TEMP\CS1AB981C6-F874-11D9-96D3-00508D472018.tmp
7/19/05 5:13:52 PM 46 C:\WINDOWS\TEMP\CS1AB981C7-F874-11D9-96D3-00508D472018.tmp
7/19/05 5:13:52 PM 46 C:\WINDOWS\TEMP\CS1AB981C8-F874-11D9-96D3-00508D472018.tmp
7/19/05 5:13:52 PM 10 C:\WINDOWS\TEMP\CS1AB981C9-F874-11D9-96D3-00508D472018.tmp
7/19/05 5:13:52 PM 30 C:\WINDOWS\TEMP\CS1AB981CA-F874-11D9-96D3-00508D472018.tmp
7/19/05 5:13:52 PM 44 C:\WINDOWS\TEMP\CS1AB981CB-F874-11D9-96D3-00508D472018.tmp
7/19/05 5:13:52 PM 42 C:\WINDOWS\TEMP\CS1AB981CC-F874-11D9-96D3-00508D472018.tmp
7/19/05 5:13:52 PM 10 C:\WINDOWS\TEMP\CS1AB981CD-F874-11D9-96D3-00508D472018.tmp
7/19/05 5:13:52 PM 10 C:\WINDOWS\TEMP\CS1AB981CE-F874-11D9-96D3-00508D472018.tmp
7/19/05 5:13:52 PM 10 C:\WINDOWS\TEMP\CS1AB981CF-F874-11D9-96D3-00508D472018.tmp
7/19/05 5:13:52 PM 10 C:\WINDOWS\TEMP\CS1AB981D0-F874-11D9-96D3-00508D472018.tmp
7/19/05 5:13:52 PM 10 C:\WINDOWS\TEMP\CS1AB981D1-F874-11D9-96D3-00508D472018.tmp
7/19/05 5:13:52 PM 10 C:\WINDOWS\TEMP\CS1AB981D2-F874-11D9-96D3-00508D472018.tmp
7/19/05 5:13:52 PM 10 C:\WINDOWS\TEMP\CS1AB981D3-F874-11D9-96D3-00508D472018.tmp
7/19/05 5:13:52 PM 10 C:\WINDOWS\TEMP\CS1AB981D4-F874-11D9-96D3-00508D472018.tmp
7/19/05 5:13:52 PM 10 C:\WINDOWS\TEMP\CS1AB981D5-F874-11D9-96D3-00508D472018.tmp
7/19/05 5:13:52 PM 10 C:\WINDOWS\TEMP\CS1AB981D6-F874-11D9-96D3-00508D472018.tmp
7/19/05 5:13:52 PM 10 C:\WINDOWS\TEMP\CS1AB981D7-F874-11D9-96D3-00508D472018.tmp
7/19/05 5:13:52 PM 10 C:\WINDOWS\TEMP\CS1AB981D8-F874-11D9-96D3-00508D472018.tmp
7/19/05 5:13:52 PM 10 C:\WINDOWS\TEMP\CS1AB981D9-F874-11D9-96D3-00508D472018.tmp
7/19/05 5:13:52 PM 10 C:\WINDOWS\TEMP\CS1AB981DA-F874-11D9-96D3-00508D472018.tmp
7/19/05 5:13:52 PM 10 C:\WINDOWS\TEMP\CS1AB981DB-F874-11D9-96D3-00508D472018.tmp
7/19/05 5:13:52 PM 10 C:\WINDOWS\TEMP\CS1AB981DC-F874-11D9-96D3-00508D472018.tmp
7/19/05 5:13:52 PM 10 C:\WINDOWS\TEMP\CS1AB981DD-F874-11D9-96D3-00508D472018.tmp
7/19/05 5:13:52 PM 10 C:\WINDOWS\TEMP\CS1AB981DE-F874-11D9-96D3-00508D472018.tmp
7/19/05 5:13:52 PM 10 C:\WINDOWS\TEMP\CS1AB981DF-F874-11D9-96D3-00508D472018.tmp
7/19/05 5:13:52 PM 10 C:\WINDOWS\TEMP\CS1AB981E0-F874-11D9-96D3-00508D472018.tmp
7/19/05 5:13:52 PM 10 C:\WINDOWS\TEMP\CS1AB981E1-F874-11D9-96D3-00508D472018.tmp
7/19/05 5:13:52 PM 10 C:\WINDOWS\TEMP\CS1AB981E2-F874-11D9-96D3-00508D472018.tmp
7/19/05 5:13:52 PM 10 C:\WINDOWS\TEMP\CS1AB981E3-F874-11D9-96D3-00508D472018.tmp
7/19/05 5:13:52 PM 10 C:\WINDOWS\TEMP\CS1AB981E4-F874-11D9-96D3-00508D472018.tmp
7/19/05 5:13:52 PM 10 C:\WINDOWS\TEMP\CS1AB981E5-F874-11D9-96D3-00508D472018.tmp
7/21/05 12:30:32 AM 30 C:\WINDOWS\TEMP\CSF7313B41-F97C-11D9-96D3-00508D472018.tmp
7/21/05 12:30:32 AM 0 C:\WINDOWS\TEMP\CSF7313B42-F97C-11D9-96D3-00508D472018.tmp
7/21/05 12:30:32 AM 0 C:\WINDOWS\TEMP\CSF7313B43-F97C-11D9-96D3-00508D472018.tmp
7/21/05 12:30:32 AM 1898904 C:\WINDOWS\TEMP\CSF7313B44-F97C-11D9-96D3-00508D472018.tmp
7/21/05 12:30:32 AM 1143806 C:\WINDOWS\TEMP\CSF7313B45-F97C-11D9-96D3-00508D472018.tmp
7/21/05 12:30:32 AM 1474562 C:\WINDOWS\TEMP\CSF7313B46-F97C-11D9-96D3-00508D472018.tmp
7/21/05 12:30:32 AM 80360 C:\WINDOWS\TEMP\CSF7313B47-F97C-11D9-96D3-00508D472018.tmp
7/21/05 12:30:32 AM 101742 C:\WINDOWS\TEMP\CSF7313B48-F97C-11D9-96D3-00508D472018.tmp
7/21/05 12:30:32 AM 22032 C:\WINDOWS\TEMP\CSF7313B49-F97C-11D9-96D3-00508D472018.tmp
7/21/05 12:30:32 AM 67418 C:\WINDOWS\TEMP\CSF7313B4A-F97C-11D9-96D3-00508D472018.tmp
7/21/05 12:30:32 AM 1193738 C:\WINDOWS\TEMP\CSF7313B4B-F97C-11D9-96D3-00508D472018.tmp
7/21/05 12:30:32 AM 682 C:\WINDOWS\TEMP\CSF7313B4C-F97C-11D9-96D3-00508D472018.tmp
7/21/05 12:30:32 AM 228 C:\WINDOWS\TEMP\CSF7313B4D-F97C-11D9-96D3-00508D472018.tmp
7/21/05 12:30:32 AM 516 C:\WINDOWS\TEMP\CSF7313B4E-F97C-11D9-96D3-00508D472018.tmp
7/21/05 12:30:32 AM 3249 C:\WINDOWS\TEMP\CSF7313B4F-F97C-11D9-96D3-00508D472018.tmp
7/21/05 12:30:32 AM 160 C:\WINDOWS\TEMP\CSF7313B50-F97C-11D9-96D3-00508D472018.tmp
7/21/05 12:30:32 AM 5568 C:\WINDOWS\TEMP\CSF7313B51-F97C-11D9-96D3-00508D472018.tmp
7/21/05 12:30:32 AM 63296 C:\WINDOWS\TEMP\CSF7313B52-F97C-11D9-96D3-00508D472018.tmp
7/21/05 12:30:32 AM 180 C:\WINDOWS\TEMP\CSF7313B53-F97C-11D9-96D3-00508D472018.tmp
7/21/05 12:30:32 AM 1062 C:\WINDOWS\TEMP\CSF7313B54-F97C-11D9-96D3-00508D472018.tmp
7/21/05 12:30:32 AM 126 C:\WINDOWS\TEMP\CSF7313B55-F97C-11D9-96D3-00508D472018.tmp
7/21/05 12:30:32 AM 32 C:\WINDOWS\TEMP\CSF7313B56-F97C-11D9-96D3-00508D472018.tmp
7/21/05 12:30:32 AM 934 C:\WINDOWS\TEMP\CSF7313B57-F97C-11D9-96D3-00508D472018.tmp
7/21/05 12:30:32 AM 1276830 C:\WINDOWS\TEMP\CSF7313B58-F97C-11D9-96D3-00508D472018.tmp
7/21/05 12:30:32 AM 591862 C:\WINDOWS\TEMP\CSF7313B59-F97C-11D9-96D3-00508D472018.tmp
7/21/05 12:30:32 AM 998134 C:\WINDOWS\TEMP\CSF7313B5A-F97C-11D9-96D3-00508D472018.tmp
7/21/05 12:30:32 AM 512876 C:\WINDOWS\TEMP\CSF7313B5B-F97C-11D9-96D3-00508D472018.tmp
7/21/05 12:30:32 AM 35638 C:\WINDOWS\TEMP\CSF7313B5C-F97C-11D9-96D3-00508D472018.tmp
7/21/05 12:30:32 AM 91830 C:\WINDOWS\TEMP\CSF7313B5D-F97C-11D9-96D3-00508D472018.tmp
7/21/05 12:30:32 AM 35144 C:\WINDOWS\TEMP\CSF7313B5E-F97C-11D9-96D3-00508D472018.tmp
7/21/05 12:30:32 AM 5044 C:\WINDOWS\TEMP\CSF7313B5F-F97C-11D9-96D3-00508D472018.tmp
7/21/05 12:30:32 AM 168 C:\WINDOWS\TEMP\CSF7313B60-F97C-11D9-96D3-00508D472018.tmp
7/21/05 12:30:32 AM 10 C:\WINDOWS\TEMP\CSF7313B61-F97C-11D9-96D3-00508D472018.tmp
7/21/05 12:30:32 AM 40 C:\WINDOWS\TEMP\CSF7313B62-F97C-11D9-96D3-00508D472018.tmp
7/21/05 12:30:32 AM 14 C:\WINDOWS\TEMP\CSF7313B63-F97C-11D9-96D3-00508D472018.tmp
7/21/05 12:30:32 AM 30 C:\WINDOWS\TEMP\CSF7313B64-F97C-11D9-96D3-00508D472018.tmp
7/21/05 12:30:32 AM 44 C:\WINDOWS\TEMP\CSF7313B65-F97C-11D9-96D3-00508D472018.tmp
7/21/05 12:30:32 AM 46 C:\WINDOWS\TEMP\CSF7313B66-F97C-11D9-96D3-00508D472018.tmp
7/21/05 12:30:32 AM 530 C:\WINDOWS\TEMP\CSF7313B67-F97C-11D9-96D3-00508D472018.tmp
7/21/05 12:30:32 AM 70 C:\WINDOWS\TEMP\CSF7313B68-F97C-11D9-96D3-00508D472018.tmp
7/21/05 12:30:32 AM 530 C:\WINDOWS\TEMP\CSF7313B69-F97C-11D9-96D3-00508D472018.tmp
7/21/05 12:30:32 AM 530 C:\WINDOWS\TEMP\CSF7313B6A-F97C-11D9-96D3-00508D472018.tmp
7/21/05 12:30:32 AM 40 C:\WINDOWS\TEMP\CSF7313B6B-F97C-11D9-96D3-00508D472018.tmp
7/21/05 12:30:32 AM 50 C:\WINDOWS\TEMP\CSF7313B6C-F97C-11D9-96D3-00508D472018.tmp
7/21/05 12:30:32 AM 86 C:\WINDOWS\TEMP\CSF7313B6D-F97C-11D9-96D3-00508D472018.tmp
7/21/05 12:30:32 AM 44 C:\WINDOWS\TEMP\CSF7313B6E-F97C-11D9-96D3-00508D472018.tmp
7/21/05 12:30:32 AM 44 C:\WINDOWS\TEMP\CSF7313B6F-F97C-11D9-96D3-00508D472018.tmp
7/21/05 12:30:32 AM 530 C:\WINDOWS\TEMP\CSF7313B70-F97C-11D9-96D3-00508D472018.tmp
7/21/05 12:30:32 AM 52 C:\WINDOWS\TEMP\CSF7313B71-F97C-11D9-96D3-00508D472018.tmp
7/21/05 12:30:32 AM 10 C:\WINDOWS\TEMP\CSF7313B72-F97C-11D9-96D3-00508D472018.tmp
7/21/05 12:30:32 AM 10 C:\WINDOWS\TEMP\CSF7313B73-F97C-11D9-96D3-00508D472018.tmp
7/21/05 12:30:32 AM 10 C:\WINDOWS\TEMP\CSF7313B74-F97C-11D9-96D3-00508D472018.tmp
7/21/05 12:30:32 AM 10 C:\WINDOWS\TEMP\CSF7313B75-F97C-11D9-96D3-00508D472018.tmp
7/21/05 12:30:32 AM 46 C:\WINDOWS\TEMP\CSF7313B76-F97C-11D9-96D3-00508D472018.tmp
7/21/05 12:30:32 AM 530 C:\WINDOWS\TEMP\CSF7313B77-F97C-11D9-96D3-00508D472018.tmp
7/21/05 12:30:32 AM 530 C:\WINDOWS\TEMP\CSF7313B78-F97C-11D9-96D3-00508D472018.tmp
7/21/05 12:30:32 AM 46 C:\WINDOWS\TEMP\CSF7313B79-F97C-11D9-96D3-00508D472018.tmp
7/21/05 12:30:32 AM 42 C:\WINDOWS\TEMP\CSF7313B7A-F97C-11D9-96D3-00508D472018.tmp
7/21/05 12:30:32 AM 48 C:\WINDOWS\TEMP\CSF7313B7B-F97C-11D9-96D3-00508D472018.tmp
7/21/05 12:30:32 AM 10 C:\WINDOWS\TEMP\CSF7313B7C-F97C-11D9-96D3-00508D472018.tmp
7/21/05 12:30:32 AM 10 C:\WINDOWS\TEMP\CSF7313B7D-F97C-11D9-96D3-00508D472018.tmp
7/21/05 12:30:32 AM 10 C:\WINDOWS\TEMP\CSF7313B7E-F97C-11D9-96D3-00508D472018.tmp
7/21/05 12:30:32 AM 10 C:\WINDOWS\TEMP\CSF7313B7F-F97C-11D9-96D3-00508D472018.tmp
7/21/05 12:30:32 AM 64 C:\WINDOWS\TEMP\CSF7313B80-F97C-11D9-96D3-00508D472018.tmp
7/21/05 12:30:32 AM 50 C:\WINDOWS\TEMP\CSF7313B81-F97C-11D9-96D3-00508D472018.tmp
7/21/05 12:30:32 AM 94 C:\WINDOWS\TEMP\CSF7313B82-F97C-11D9-96D3-00508D472018.tmp
7/21/05 12:30:32 AM 10 C:\WINDOWS\TEMP\CSF7313B83-F97C-11D9-96D3-00508D472018.tmp
7/21/05 12:30:32 AM 10 C:\WINDOWS\TEMP\CSF7313B84-F97C-11D9-96D3-00508D472018.tmp
7/21/05 12:30:32 AM 10 C:\WINDOWS\TEMP\CSF7313B85-F97C-11D9-96D3-00508D472018.tmp
7/21/05 12:30:32 AM 80 C:\WINDOWS\TEMP\CSF7313B86-F97C-11D9-96D3-00508D472018.tmp
7/21/05 12:30:32 AM 46 C:\WINDOWS\TEMP\CSF7313B87-F97C-11D9-96D3-00508D472018.tmp
7/21/05 12:30:32 AM 46 C:\WINDOWS\TEMP\CSF7313B88-F97C-11D9-96D3-00508D472018.tmp
7/21/05 12:30:32 AM 10 C:\WINDOWS\TEMP\CSF7313B89-F97C-11D9-96D3-00508D472018.tmp
7/21/05 12:30:32 AM 30 C:\WINDOWS\TEMP\CSF7313B8A-F97C-11D9-96D3-00508D472018.tmp
7/21/05 12:30:32 AM 44 C:\WINDOWS\TEMP\CSF7313B8B-F97C-11D9-96D3-00508D472018.tmp
7/21/05 12:30:32 AM 42 C:\WINDOWS\TEMP\CSF7313B8C-F97C-11D9-96D3-00508D472018.tmp
7/21/05 12:30:32 AM 10 C:\WINDOWS\TEMP\CSF7313B8D-F97C-11D9-96D3-00508D472018.tmp
7/21/05 12:30:32 AM 10 C:\WINDOWS\TEMP\CSF7313B8E-F97C-11D9-96D3-00508D472018.tmp
7/21/05 12:30:32 AM 10 C:\WINDOWS\TEMP\CSF7313B8F-F97C-11D9-96D3-00508D472018.tmp
7/21/05 12:30:32 AM 10 C:\WINDOWS\TEMP\CSF7313B90-F97C-11D9-96D3-00508D472018.tmp
7/21/05 12:30:32 AM 10 C:\WINDOWS\TEMP\CSF7313B91-F97C-11D9-96D3-00508D472018.tmp
7/21/05 12:30:32 AM 10 C:\WINDOWS\TEMP\CSF7313B92-F97C-11D9-96D3-00508D472018.tmp
7/21/05 12:30:32 AM 10 C:\WINDOWS\TEMP\CSF7313B93-F97C-11D9-96D3-00508D472018.tmp
7/21/05 12:30:32 AM 10 C:\WINDOWS\TEMP\CSF7313B94-F97C-11D9-96D3-00508D472018.tmp
7/21/05 12:30:32 AM 10 C:\WINDOWS\TEMP\CSF7313B95-F97C-11D9-96D3-00508D472018.tmp
7/21/05 12:30:32 AM 10 C:\WINDOWS\TEMP\CSF7313B96-F97C-11D9-96D3-00508D472018.tmp
7/21/05 12:30:32 AM 10 C:\WINDOWS\TEMP\CSF7313B97-F97C-11D9-96D3-00508D472018.tmp
7/21/05 12:30:32 AM 10 C:\WINDOWS\TEMP\CSF7313B98-F97C-11D9-96D3-00508D472018.tmp
7/21/05 12:30:32 AM 10 C:\WINDOWS\TEMP\CSF7313B99-F97C-11D9-96D3-00508D472018.tmp
7/21/05 12:30:32 AM 10 C:\WINDOWS\TEMP\CSF7313B9A-F97C-11D9-96D3-00508D472018.tmp
7/21/05 12:30:32 AM 10 C:\WINDOWS\TEMP\CSF7313B9B-F97C-11D9-96D3-00508D472018.tmp
7/21/05 12:30:32 AM 10 C:\WINDOWS\TEMP\CSF7313B9C-F97C-11D9-96D3-00508D472018.tmp
7/21/05 12:30:32 AM 10 C:\WINDOWS\TEMP\CSF7313B9D-F97C-11D9-96D3-00508D472018.tmp
7/21/05 12:30:32 AM 10 C:\WINDOWS\TEMP\CSF7313B9E-F97C-11D9-96D3-00508D472018.tmp
7/21/05 12:30:32 AM 10 C:\WINDOWS\TEMP\CSF7313B9F-F97C-11D9-96D3-00508D472018.tmp
7/21/05 12:30:32 AM 10 C:\WINDOWS\TEMP\CSF7313BA0-F97C-11D9-96D3-00508D472018.tmp
7/21/05 12:30:32 AM 10 C:\WINDOWS\TEMP\CSF7313BA1-F97C-11D9-96D3-00508D472018.tmp
7/21/05 12:30:32 AM 10 C:\WINDOWS\TEMP\CSF7313BA2-F97C-11D9-96D3-00508D472018.tmp
7/21/05 12:30:32 AM 10 C:\WINDOWS\TEMP\CSF7313BA3-F97C-11D9-96D3-00508D472018.tmp
7/21/05 12:30:32 AM 10 C:\WINDOWS\TEMP\CSF7313BA4-F97C-11D9-96D3-00508D472018.tmp
7/21/05 12:30:32 AM 10 C:\WINDOWS\TEMP\CSF7313BA5-F97C-11D9-96D3-00508D472018.tmp
8/2/05 6:25:18 AM 0 C:\WINDOWS\TEMP\CS3114CD41-031E-11DA-96D4-00508D472018.tmp
8/2/05 6:25:18 AM 0 C:\WINDOWS\TEMP\CS3114CD42-031E-11DA-96D4-00508D472018.tmp
8/2/05 6:25:18 AM 0 C:\WINDOWS\TEMP\CS3114CD43-031E-11DA-96D4-00508D472018.tmp
8/2/05 6:25:18 AM 0 C:\WINDOWS\TEMP\CS3114CD44-031E-11DA-96D4-00508D472018.tmp
8/2/05 6:25:18 AM 0 C:\WINDOWS\TEMP\CS3114CD45-031E-11DA-96D4-00508D472018.tmp
8/2/05 6:25:18 AM 0 C:\WINDOWS\TEMP\CS3114CD46-031E-11DA-96D4-00508D472018.tmp
8/2/05 6:25:18 AM 0 C:\WINDOWS\TEMP\CS3114CD47-031E-11DA-96D4-00508D472018.tmp
8/2/05 6:25:18 AM 0 C:\WINDOWS\TEMP\CS3114CD48-031E-11DA-96D4-00508D472018.tmp
8/2/05 6:25:18 AM 0 C:\WINDOWS\TEMP\CS3114CD49-031E-11DA-96D4-00508D472018.tmp
8/2/05 6:25:18 AM 0 C:\WINDOWS\TEMP\CS3114CD4A-031E-11DA-96D4-00508D472018.tmp
8/2/05 6:25:18 AM 0 C:\WINDOWS\TEMP\CS3114CD4B-031E-11DA-96D4-00508D472018.tmp
8/2/05 6:25:18 AM 0 C:\WINDOWS\TEMP\CS3114CD4C-031E-11DA-96D4-00508D472018.tmp
8/2/05 6:25:18 AM 0 C:\WINDOWS\TEMP\CS3114CD4D-031E-11DA-96D4-00508D472018.tmp
8/2/05 6:25:18 AM 0 C:\WINDOWS\TEMP\CS3114CD4E-031E-11DA-96D4-00508D472018.tmp
8/2/05 6:25:18 AM 0 C:\WINDOWS\TEMP\CS3114CD4F-031E-11DA-96D4-00508D472018.tmp
8/2/05 6:25:18 AM 0 C:\WINDOWS\TEMP\CS3114CD50-031E-11DA-96D4-00508D472018.tmp
8/2/05 6:25:18 AM 0 C:\WINDOWS\TEMP\CS3114CD51-031E-11DA-96D4-00508D472018.tmp
8/2/05 6:25:18 AM 0 C:\WINDOWS\TEMP\CS3114CD52-031E-11DA-96D4-00508D472018.tmp
8/2/05 6:25:18 AM 0 C:\WINDOWS\TEMP\CS3114CD53-031E-11DA-96D4-00508D472018.tmp
8/2/05 6:25:18 AM 0 C:\WINDOWS\TEMP\CS3114CD54-031E-11DA-96D4-00508D472018.tmp
8/2/05 6:25:18 AM 0 C:\WINDOWS\TEMP\CS3114CD55-031E-11DA-96D4-00508D472018.tmp
8/2/05 6:25:18 AM 0 C:\WINDOWS\TEMP\CS3114CD56-031E-11DA-96D4-00508D472018.tmp
8/2/05 6:25:18 AM 0 C:\WINDOWS\TEMP\CS3114CD57-031E-11DA-96D4-00508D472018.tmp
8/2/05 6:25:18 AM 0 C:\WINDOWS\TEMP\CS3114CD58-031E-11DA-96D4-00508D472018.tmp
8/2/05 6:25:18 AM 0 C:\WINDOWS\TEMP\CS3114CD59-031E-11DA-96D4-00508D472018.tmp
8/2/05 6:25:18 AM 0 C:\WINDOWS\TEMP\CS3114CD5A-031E-11DA-96D4-00508D472018.tmp
8/2/05 6:25:18 AM 0 C:\WINDOWS\TEMP\CS3114CD5B-031E-11DA-96D4-00508D472018.tmp
8/2/05 6:25:18 AM 0 C:\WINDOWS\TEMP\CS3114CD5C-031E-11DA-96D4-00508D472018.tmp
8/2/05 6:25:18 AM 0 C:\WINDOWS\TEMP\CS3114CD5D-031E-11DA-96D4-00508D472018.tmp
8/2/05 6:25:18 AM 0 C:\WINDOWS\TEMP\CS3114CD5E-031E-11DA-96D4-00508D472018.tmp
8/2/05 6:25:18 AM 0 C:\WINDOWS\TEMP\CS3114CD5F-031E-11DA-96D4-00508D472018.tmp
8/2/05 6:25:18 AM 0 C:\WINDOWS\TEMP\CS3114CD60-031E-11DA-96D4-00508D472018.tmp
8/2/05 6:31:22 AM 0 C:\WINDOWS\TEMP\CS3114CD61-031E-11DA-96D4-00508D472018.tmp
8/2/05 6:31:22 AM 0 C:\WINDOWS\TEMP\CS3114CD62-031E-11DA-96D4-00508D472018.tmp
8/2/05 6:31:22 AM 0 C:\WINDOWS\TEMP\CS3114CD63-031E-11DA-96D4-00508D472018.tmp
8/2/05 6:31:22 AM 0 C:\WINDOWS\TEMP\CS3114CD64-031E-11DA-96D4-00508D472018.tmp
8/2/05 6:31:22 AM 0 C:\WINDOWS\TEMP\CS3114CD65-031E-11DA-96D4-00508D472018.tmp
8/2/05 6:31:22 AM 0 C:\WINDOWS\TEMP\CS3114CD66-031E-11DA-96D4-00508D472018.tmp
8/2/05 6:31:22 AM 0 C:\WINDOWS\TEMP\CS3114CD67-031E-11DA-96D4-00508D472018.tmp
8/2/05 6:31:22 AM 0 C:\WINDOWS\TEMP\CS3114CD68-031E-11DA-96D4-00508D472018.tmp
8/2/05 6:31:22 AM 0 C:\WINDOWS\TEMP\CS3114CD69-031E-11DA-96D4-00508D472018.tmp
8/2/05 6:31:22 AM 0 C:\WINDOWS\TEMP\CS3114CD6A-031E-11DA-96D4-00508D472018.tmp
8/2/05 6:31:22 AM 0 C:\WINDOWS\TEMP\CS3114CD6B-031E-11DA-96D4-00508D472018.tmp
8/2/05 6:31:22 AM 0 C:\WINDOWS\TEMP\CS3114CD6C-031E-11DA-96D4-00508D472018.tmp
8/2/05 6:31:22 AM 0 C:\WINDOWS\TEMP\CS3114CD6D-031E-11DA-96D4-00508D472018.tmp
8/2/05 6:31:22 AM 0 C:\WINDOWS\TEMP\CS3114CD6E-031E-11DA-96D4-00508D472018.tmp
8/2/05 6:31:22 AM 0 C:\WINDOWS\TEMP\CS3114CD6F-031E-11DA-96D4-00508D472018.tmp
8/2/05 6:31:22 AM 0 C:\WINDOWS\TEMP\CS3114CD70-031E-11DA-96D4-00508D472018.tmp
8/2/05 6:31:22 AM 0 C:\WINDOWS\TEMP\CS3114CD71-031E-11DA-96D4-00508D472018.tmp
8/2/05 6:31:22 AM 0 C:\WINDOWS\TEMP\CS3114CD72-031E-11DA-96D4-00508D472018.tmp
8/2/05 6:31:22 AM 0 C:\WINDOWS\TEMP\CS3114CD73-031E-11DA-96D4-00508D472018.tmp
8/2/05 6:31:22 AM 0 C:\WINDOWS\TEMP\CS3114CD74-031E-11DA-96D4-00508D472018.tmp
8/2/05 6:31:22 AM 0 C:\WINDOWS\TEMP\CS3114CD75-031E-11DA-96D4-00508D472018.tmp
8/2/05 6:31:22 AM 0 C:\WINDOWS\TEMP\CS3114CD76-031E-11DA-96D4-00508D472018.tmp
8/2/05 6:31:22 AM 0 C:\WINDOWS\TEMP\CS3114CD77-031E-11DA-96D4-00508D472018.tmp
8/2/05 6:31:22 AM 0 C:\WINDOWS\TEMP\CS3114CD78-031E-11DA-96D4-00508D472018.tmp
8/2/05 6:31:22 AM 0 C:\WINDOWS\TEMP\CS3114CD79-031E-11DA-96D4-00508D472018.tmp
8/2/05 6:31:22 AM 0 C:\WINDOWS\TEMP\CS3114CD7A-031E-11DA-96D4-00508D472018.tmp
8/2/05 6:31:22 AM 0 C:\WINDOWS\TEMP\CS3114CD7B-031E-11DA-96D4-00508D472018.tmp
8/2/05 6:31:22 AM 0 C:\WINDOWS\TEMP\CS3114CD7C-031E-11DA-96D4-00508D472018.tmp
8/2/05 6:31:22 AM 0 C:\WINDOWS\TEMP\CS3114CD7D-031E-11DA-96D4-00508D472018.tmp
8/2/05 6:31:22 AM 0 C:\WINDOWS\TEMP\CS3114CD7E-031E-11DA-96D4-00508D472018.tmp
8/2/05 6:31:22 AM 0 C:\WINDOWS\TEMP\CS3114CD7F-031E-11DA-96D4-00508D472018.tmp
8/2/05 6:31:22 AM 0 C:\WINDOWS\TEMP\CS3114CD80-031E-11DA-96D4-00508D472018.tmp
8/2/05 6:31:22 AM 0 C:\WINDOWS\TEMP\CS3114CD81-031E-11DA-96D4-00508D472018.tmp
8/2/05 6:31:22 AM 0 C:\WINDOWS\TEMP\CS3114CD82-031E-11DA-96D4-00508D472018.tmp
8/2/05 6:31:22 AM 0 C:\WINDOWS\TEMP\CS3114CD83-031E-11DA-96D4-00508D472018.tmp
8/2/05 6:31:22 AM 0 C:\WINDOWS\TEMP\CS3114CD84-031E-11DA-96D4-00508D472018.tmp
8/2/05 6:31:22 AM 0 C:\WINDOWS\TEMP\CS3114CD85-031E-11DA-96D4-00508D472018.tmp
8/2/05 6:31:22 AM 0 C:\WINDOWS\TEMP\CS3114CD86-031E-11DA-96D4-00508D472018.tmp
8/2/05 6:31:22 AM 0 C:\WINDOWS\TEMP\CS3114CD87-031E-11DA-96D4-00508D472018.tmp
8/2/05 6:31:22 AM 0 C:\WINDOWS\TEMP\CS3114CD88-031E-11DA-96D4-00508D472018.tmp
8/2/05 6:31:22 AM 0 C:\WINDOWS\TEMP\CS3114CD89-031E-11DA-96D4-00508D472018.tmp
8/2/05 6:31:22 AM 0 C:\WINDOWS\TEMP\CS3114CD8A-031E-11DA-96D4-00508D472018.tmp
8/2/05 6:31:22 AM 0 C:\WINDOWS\TEMP\CS3114CD8B-031E-11DA-96D4-00508D472018.tmp
8/2/05 6:31:22 AM 0 C:\WINDOWS\TEMP\CS3114CD8C-031E-11DA-96D4-00508D472018.tmp
8/2/05 6:31:22 AM 0 C:\WINDOWS\TEMP\CS3114CD8D-031E-11DA-96D4-00508D472018.tmp
8/2/05 6:31:22 AM 0 C:\WINDOWS\TEMP\CS3114CD8E-031E-11DA-96D4-00508D472018.tmp
8/2/05 6:31:22 AM 0 C:\WINDOWS\TEMP\CS3114CD8F-031E-11DA-96D4-00508D472018.tmp
8/2/05 6:31:22 AM 0 C:\WINDOWS\TEMP\CS3114CD90-031E-11DA-96D4-00508D472018.tmp
8/2/05 6:31:22 AM 0 C:\WINDOWS\TEMP\CS3114CD91-031E-11DA-96D4-00508D472018.tmp
8/2/05 6:31:22 AM 0 C:\WINDOWS\TEMP\CS3114CD92-031E-11DA-96D4-00508D472018.tmp
8/2/05 6:31:22 AM 0 C:\WINDOWS\TEMP\CS3114CD93-031E-11DA-96D4-00508D472018.tmp
8/2/05 6:31:22 AM 0 C:\WINDOWS\TEMP\CS3114CD94-031E-11DA-96D4-00508D472018.tmp
8/2/05 6:31:22 AM 0 C:\WINDOWS\TEMP\CS3114CD95-031E-11DA-96D4-00508D472018.tmp
8/2/05 6:31:22 AM 0 C:\WINDOWS\TEMP\CS3114CD96-031E-11DA-96D4-00508D472018.tmp
8/2/05 6:31:22 AM 0 C:\WINDOWS\TEMP\CS3114CD97-031E-11DA-96D4-00508D472018.tmp
8/2/05 6:31:22 AM 0 C:\WINDOWS\TEMP\CS3114CD98-031E-11DA-96D4-00508D472018.tmp
8/2/05 6:31:22 AM 0 C:\WINDOWS\TEMP\CS3114CD99-031E-11DA-96D4-00508D472018.tmp
8/2/05 6:31:22 AM 0 C:\WINDOWS\TEMP\CS3114CD9A-031E-11DA-96D4-00508D472018.tmp
8/2/05 6:31:22 AM 0 C:\WINDOWS\TEMP\CS3114CD9B-031E-11DA-96D4-00508D472018.tmp
8/2/05 6:31:22 AM 0 C:\WINDOWS\TEMP\CS3114CD9C-031E-11DA-96D4-00508D472018.tmp
8/2/05 6:31:22 AM 0 C:\WINDOWS\TEMP\CS3114CD9D-031E-11DA-96D4-00508D472018.tmp
8/2/05 6:31:22 AM 0 C:\WINDOWS\TEMP\CS3114CD9E-031E-11DA-96D4-00508D472018.tmp
8/2/05 6:31:22 AM 0 C:\WINDOWS\TEMP\CS3114CD9F-031E-11DA-96D4-00508D472018.tmp
8/2/05 6:31:22 AM 0 C:\WINDOWS\TEMP\CS3114CDA0-031E-11DA-96D4-00508D472018.tmp
8/2/05 6:31:22 AM 0 C:\WINDOWS\TEMP\CS3114CDA1-031E-11DA-96D4-00508D472018.tmp
8/2/05 6:31:22 AM 0 C:\WINDOWS\TEMP\CS3114CDA2-031E-11DA-96D4-00508D472018.tmp
8/2/05 6:31:22 AM 0 C:\WINDOWS\TEMP\CS3114CDA3-031E-11DA-96D4-00508D472018.tmp
8/2/05 6:31:22 AM 0 C:\WINDOWS\TEMP\CS3114CDA4-031E-11DA-96D4-00508D472018.tmp
8/2/05 6:31:22 AM 0 C:\WINDOWS\TEMP\CS3114CDA5-031E-11DA-96D4-00508D472018.tmp
8/5/05 12:59:32 AM 0 C:\WINDOWS\TEMP\CS2D807E65-054C-11DA-96D4-00508D472018.tmp
8/5/05 12:59:32 AM 0 C:\WINDOWS\TEMP\CS2D807E66-054C-11DA-96D4-00508D472018.tmp
8/5/05 12:59:32 AM 0 C:\WINDOWS\TEMP\CS2D807E67-054C-11DA-96D4-00508D472018.tmp
8/5/05 12:59:32 AM 0 C:\WINDOWS\TEMP\CS2D807E68-054C-11DA-96D4-00508D472018.tmp
8/5/05 12:59:32 AM 0 C:\WINDOWS\TEMP\CS2D807E69-054C-11DA-96D4-00508D472018.tmp
8/5/05 12:59:32 AM 0 C:\WINDOWS\TEMP\CS2D807E6A-054C-11DA-96D4-00508D472018.tmp
8/5/05 12:59:32 AM 0 C:\WINDOWS\TEMP\CS2D807E6B-054C-11DA-96D4-00508D472018.tmp
8/5/05 12:59:32 AM 0 C:\WINDOWS\TEMP\CS2D807E6C-054C-11DA-96D4-00508D472018.tmp
8/5/05 12:59:32 AM 0 C:\WINDOWS\TEMP\CS2D807E6D-054C-11DA-96D4-00508D472018.tmp
8/5/05 12:59:32 AM 0 C:\WINDOWS\TEMP\CS2D807E6E-054C-11DA-96D4-00508D472018.tmp
8/5/05 12:59:32 AM 0 C:\WINDOWS\TEMP\CS2D807E6F-054C-11DA-96D4-00508D472018.tmp
8/5/05 12:59:32 AM 0 C:\WINDOWS\TEMP\CS2D807E70-054C-11DA-96D4-00508D472018.tmp
8/5/05 12:59:32 AM 0 C:\WINDOWS\TEMP\CS2D807E71-054C-11DA-96D4-00508D472018.tmp
8/5/05 12:59:32 AM 0 C:\WINDOWS\TEMP\CS2D807E72-054C-11DA-96D4-00508D472018.tmp
8/5/05 12:59:32 AM 0 C:\WINDOWS\TEMP\CS2D807E73-054C-11DA-96D4-00508D472018.tmp
8/5/05 12:59:32 AM 0 C:\WINDOWS\TEMP\CS2D807E74-054C-11DA-96D4-00508D472018.tmp
8/5/05 12:59:32 AM 0 C:\WINDOWS\TEMP\CS2D807E75-054C-11DA-96D4-00508D472018.tmp
8/5/05 12:59:32 AM 0 C:\WINDOWS\TEMP\CS2D807E76-054C-11DA-96D4-00508D472018.tmp
8/5/05 12:59:32 AM 0 C:\WINDOWS\TEMP\CS2D807E77-054C-11DA-96D4-00508D472018.tmp
8/5/05 12:59:32 AM 0 C:\WINDOWS\TEMP\CS2D807E78-054C-11DA-96D4-00508D472018.tmp
8/5/05 12:59:32 AM 0 C:\WINDOWS\TEMP\CS2D807E79-054C-11DA-96D4-00508D472018.tmp
8/5/05 12:59:32 AM 0 C:\WINDOWS\TEMP\CS2D807E7A-054C-11DA-96D4-00508D472018.tmp
8/5/05 12:59:32 AM 0 C:\WINDOWS\TEMP\CS2D807E7B-054C-11DA-96D4-00508D472018.tmp
8/5/05 12:59:32 AM 0 C:\WINDOWS\TEMP\CS2D807E7C-054C-11DA-96D4-00508D472018.tmp
8/5/05 12:59:32 AM 0 C:\WINDOWS\TEMP\CS2D807E7D-054C-11DA-96D4-00508D472018.tmp
8/5/05 12:59:32 AM 0 C:\WINDOWS\TEMP\CS2D807E7E-054C-11DA-96D4-00508D472018.tmp
8/5/05 12:59:32 AM 0 C:\WINDOWS\TEMP\CS2D807E7F-054C-11DA-96D4-00508D472018.tmp
8/5/05 12:59:32 AM 0 C:\WINDOWS\TEMP\CS2D807E80-054C-11DA-96D4-00508D472018.tmp
8/5/05 1:04:34 AM 0 C:\WINDOWS\TEMP\CS2D807E81-054C-11DA-96D4-00508D472018.tmp
8/5/05 1:04:34 AM 0 C:\WINDOWS\TEMP\CS2D807E82-054C-11DA-96D4-00508D472018.tmp
8/5/05 1:04:34 AM 0 C:\WINDOWS\TEMP\CS2D807E83-054C-11DA-96D4-00508D472018.tmp
8/5/05 1:04:34 AM 0 C:\WINDOWS\TEMP\CS2D807E84-054C-11DA-96D4-00508D472018.tmp
8/5/05 1:04:34 AM 0 C:\WINDOWS\TEMP\CS2D807E85-054C-11DA-96D4-00508D472018.tmp
8/5/05 1:04:34 AM 0 C:\WINDOWS\TEMP\CS2D807E86-054C-11DA-96D4-00508D472018.tmp
8/5/05 1:04:34 AM 0 C:\WINDOWS\TEMP\CS2D807E87-054C-11DA-96D4-00508D472018.tmp
8/5/05 1:04:34 AM 0 C:\WINDOWS\TEMP\CS2D807E88-054C-11DA-96D4-00508D472018.tmp
8/5/05 1:04:34 AM 0 C:\WINDOWS\TEMP\CS2D807E89-054C-11DA-96D4-00508D472018.tmp
8/5/05 1:04:34 AM 0 C:\WINDOWS\TEMP\CS2D807E8A-054C-11DA-96D4-00508D472018.tmp
8/5/05 1:04:34 AM 0 C:\WINDOWS\TEMP\CS2D807E8B-054C-11DA-96D4-00508D472018.tmp
8/5/05 1:04:34 AM 0 C:\WINDOWS\TEMP\CS2D807E8C-054C-11DA-96D4-00508D472018.tmp
8/5/05 1:04:34 AM 0 C:\WINDOWS\TEMP\CS2D807E8D-054C-11DA-96D4-00508D472018.tmp
8/5/05 1:04:34 AM 0 C:\WINDOWS\TEMP\CS2D807E8E-054C-11DA-96D4-00508D472018.tmp
8/5/05 1:04:34 AM 0 C:\WINDOWS\TEMP\CS2D807E8F-054C-11DA-96D4-00508D472018.tmp
8/5/05 1:04:34 AM 0 C:\WINDOWS\TEMP\CS2D807E90-054C-11DA-96D4-00508D472018.tmp
8/5/05 1:04:34 AM 0 C:\WINDOWS\TEMP\CS2D807E91-054C-11DA-96D4-00508D472018.tmp
8/5/05 1:04:34 AM 0 C:\WINDOWS\TEMP\CS2D807E92-054C-11DA-96D4-00508D472018.tmp
8/5/05 1:04:34 AM 0 C:\WINDOWS\TEMP\CS2D807E93-054C-11DA-96D4-00508D472018.tmp














=
  • 0

#4
Metallica

Metallica

    Spyware Veteran

  • GeekU Moderator
  • 31,676 posts
Wow. Good job :tazz:

*Click Here to download Killbox by Option^Explicit.
*Extract the program to your desktop and double-click on its folder, then double-click on Killbox.exe to start the program.
*In the killbox program, select the Standard File Kill option.
*Copy the file names below one by one into the "Full Path for File to Delete" box

C:\WINDOWS\SYSTEM\rdsndin.exe
C:\WINDOWS\SYSTEM\ntfsnlpa.exe
C:\WINDOWS\SYSTEM\bH.dll
C:\WINDOWS\SYSTEM\msbb321.dll
C:\WINDOWS\SYSTEM\GnucDNA.dll

*After each file click the red-and-white "Delete File" button.
*Click Yes at the First prompt and wait for the confirmation prompt.

Let me know if any of them can not be deleted this way.

Reboot into safe mode and use the DiskCleanup Tool to empty all your Temp folders.

Boot back to normal and let me know how it went and how the computer is behaving.

Regards,

Edited by Metallica, 07 August 2005 - 04:14 AM.

  • 0

#5
drpepperpdx

drpepperpdx

    New Member

  • Topic Starter
  • Member
  • Pip
  • 7 posts
Ok, I installed and ran Killbox as you directed. 2 of the 5 files would not delete. They were: C:\WINDOWS\SYSTEM\rdsndin.exe and C:\WINDOWS\SYSTEM\ntfsnlpa.exe.

Do you still want me to reboot into safe mode / run the disk cleanup tool? Update: --> I did the above two steps. The cleanup tool cleared 28.5 MB from my recycle bin, but didn't clean up any temp files.

I really appreciate you taking the time to help me fix my computer. :tazz:

Edited by drpepperpdx, 07 August 2005 - 07:27 AM.

  • 0

#6
Metallica

Metallica

    Spyware Veteran

  • GeekU Moderator
  • 31,676 posts
Download CleanUp
Install the program, dont run it yet, we will later.

*In the killbox program, select the Delete on Reboot option.
*Copy the file names below to the clipboard by highlighting them and pressing Control-C:

C:\WINDOWS\SYSTEM\rdsndin.exe
C:\WINDOWS\SYSTEM\ntfsnlpa.exe

*Return to Killbox, go to the File menu, and choose "Paste from Clipboard".
*Click the red-and-white "Delete File" button. Click "Yes" at the Delete on Reboot prompt. Click "No" at the Pending Operations prompt.

While your computer is restarting, tap the F8 key continually until a menu appears. Use your up arrow key to highlight Safe Mode, then hit enter.

Running CleanUp
  • Start CleanUp by double-clicking the icon on your desktop (or from the Start > All Programs menu).
  • When CleanUp starts go to the Options button (right side of CleanUp screen)
  • Move the arrow down to "Custom CleanUp!"
  • Now place a checkmark next to the following (Make sure nothing else is checked!):
    • Delete Cookies
      This is optional, if you leave the box checked it will remove all of your cookies, at this point removing cookies is a good idea
    • Empty Recycle Bins
    • Delete Prefetch files
    • Cleanup! All Users
  • Click OK
  • Then click on the CleanUp button. This will take a short while, let it do its thing.
  • When asked to reboot system select No
  • Close CleanUp
Finally, restart your computer back into Normal Mode and please post a new HJT log.

Regards,
  • 0

#7
drpepperpdx

drpepperpdx

    New Member

  • Topic Starter
  • Member
  • Pip
  • 7 posts
I followed all of your instructions. Here's the HJT log:

Logfile of HijackThis v1.99.1
Scan saved at 2:37:52 PM, on 8/7/05
Platform: Windows 98 SE (Win9x 4.10.2222A)
MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)

Running processes:
C:\WINDOWS\SYSTEM\KERNEL32.DLL
C:\WINDOWS\SYSTEM\MSGSRV32.EXE
C:\WINDOWS\SYSTEM\MPREXE.EXE
C:\WINDOWS\SYSTEM\KB891711\KB891711.EXE
C:\WINDOWS\SYSTEM\mmtask.tsk
C:\WINDOWS\EXPLORER.EXE
C:\WINDOWS\SYSTEM\DDHELP.EXE
C:\WINDOWS\SYSTEM\SYSTRAY.EXE
C:\WINDOWS\SYSTEM\TRAYICON.EXE
C:\PROGRAM FILES\LOGITECH\MOUSEWARE\SYSTEM\EM_EXEC.EXE
C:\WINDOWS\LOADQM.EXE
C:\WINDOWS\SYSTEM\3CMLNKW.EXE
C:\PROGRAM FILES\MICROSOFT HARDWARE\KEYBOARD\TYPE32.EXE
C:\WINDOWS\SOUNDMAN.EXE
C:\PROGRAM FILES\GRISOFT\AVG FREE\AVGAMSVR.EXE
C:\WINDOWS\SYSTEM\WMIEXE.EXE
C:\MY DOCUMENTS\HIJACKTHIS.EXE

O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHELPER.DLL
O4 - HKLM\..\Run: [SystemTray] SysTray.Exe
O4 - HKLM\..\Run: [LoadPowerProfile] Rundll32.exe powrprof.dll,LoadCurrentPwrScheme
O4 - HKLM\..\Run: [DisplayTrayIcon] C:\WINDOWS\System\TrayIcon.exe
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE NvQTwk,NvCplDaemon initialize
O4 - HKLM\..\Run: [EM_EXEC] C:\PROGRA~1\LOGITECH\MOUSEW~1\SYSTEM\EM_EXEC.EXE
O4 - HKLM\..\Run: [LoadQM] loadqm.exe
O4 - HKLM\..\Run: [3Cmlink] C:\WINDOWS\SYSTEM\3cmlnkW.exe
O4 - HKLM\..\Run: [IntelliType] "C:\Program Files\Microsoft Hardware\Keyboard\type32.exe"
O4 - HKLM\..\Run: [SoundMan] SOUNDMAN.EXE
O4 - HKLM\..\Run: [AVG7_CC] C:\PROGRA~1\GRISOFT\AVGFRE~1\AVGCC.EXE /STARTUP
O4 - HKLM\..\Run: [AVG7_EMC] C:\PROGRA~1\GRISOFT\AVGFRE~1\AVGEMC.EXE
O4 - HKLM\..\Run: [AVG7_AMSVR] C:\PROGRA~1\GRISOFT\AVGFRE~1\AVGAMSVR.EXE
O4 - HKLM\..\RunServices: [LoadPowerProfile] Rundll32.exe powrprof.dll,LoadCurrentPwrScheme
O4 - HKLM\..\RunServices: [KB891711] C:\WINDOWS\SYSTEM\KB891711\KB891711.EXE
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_04\bin\npjpi150_04.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_04\bin\npjpi150_04.dll
O16 - DPF: {9A9307A0-7DA4-4DAF-B042-5009F29E09E1} (ActiveScan Installer Class) - http://www.pandasoft...free/asinst.cab

Forgot to add: my system is running faster. When I scroll for a lengthy period and then release the mouse button, it used to keep on scrolling for a while. Now it stops immediately.

Update: AVG has popped up several warnings about Clicker.FR and rdsndin.exe, and the pesky 'baloon' is making regular appearances.

Edited by drpepperpdx, 07 August 2005 - 04:53 PM.

  • 0

#8
Metallica

Metallica

    Spyware Veteran

  • GeekU Moderator
  • 31,676 posts
Can you see if rdsndin.exe is actually back?

In that case we will have to figure out what is putting it back.
Are you using any kind of firewall?

Regards,
  • 0

#9
drpepperpdx

drpepperpdx

    New Member

  • Topic Starter
  • Member
  • Pip
  • 7 posts
Spybot S&D has started picking up FindSpy.A, AVG has started reporting rdsndin and clicker.fr on scans. Spysweeper reported three trojans today: yaemu, dmtaz, and trojan-downloader-ruin.

Spybot and AVG fix the problems just fine, but they reappear quickly.

No firewall. Yes I know. Stupid stupid. And yes, my ailing computer is my fault. No lecture necessary. Any recommendations on a free firewall that will work with Win98?
  • 0

#10
Metallica

Metallica

    Spyware Veteran

  • GeekU Moderator
  • 31,676 posts
Please read here:
http://www.wilders.org/firewalls.htm

I think for Windows 98 I'd recommend ZA or Sygate.

Can you post another WinPFind log?
Maybe we can see what's being stubborn.

Regards,
  • 0

#11
drpepperpdx

drpepperpdx

    New Member

  • Topic Starter
  • Member
  • Pip
  • 7 posts
WARNING: not all files found by this scanner are bad. Consult with a knowledgable person before proceeding.

If you see a message in the titlebar saying "Not responding..." you can ignore it. Windows somethimes displays this message due to the high volume of disk I/O. As long as the hard disk light is flashing, the program is still working properly.

»»»»»»»»»»»»»»»»» Checking Selected Standard Folders »»»»»»»»»»»»»»»»»»»»

Checking %SystemDrive% folder...

Checking %ProgramFilesDir% folder...

Checking %WinDir% folder...
PECompact2 8/10/05 1:59:06 PM 15616241 C:\WINDOWS\VPTNFILE.771
qoologic 8/10/05 1:59:06 PM 15616241 C:\WINDOWS\VPTNFILE.771
SAHAgent 8/10/05 1:59:06 PM 15616241 C:\WINDOWS\VPTNFILE.771
UPX! 5/3/05 11:44:44 AM 25157 C:\WINDOWS\RMAgentOutput.dll
UPX! 5/19/05 6:02:12 AM 18432 C:\WINDOWS\ss3unstl.exe
UPX! 1/10/05 4:17:24 PM 170053 C:\WINDOWS\tsc.exe
PECompact2 8/10/05 1:59:06 PM 15616241 C:\WINDOWS\lpt$vpn.771
qoologic 8/10/05 1:59:06 PM 15616241 C:\WINDOWS\lpt$vpn.771
SAHAgent 8/10/05 1:59:06 PM 15616241 C:\WINDOWS\lpt$vpn.771
UPX! 2/18/05 6:40:14 PM 1044560 C:\WINDOWS\vsapi32.dll
aspack 2/18/05 6:40:14 PM 1044560 C:\WINDOWS\vsapi32.dll

Checking %System% folder...
PTech 11/9/99 3:55:54 PM 88571 C:\WINDOWS\SYSTEM\MDACRDME.HTM
UPX! 7/13/03 12:15:54 PM 287744 C:\WINDOWS\SYSTEM\DCDSPFilter.ax
aspack 3/15/05 12:30:32 AM 197120 C:\WINDOWS\SYSTEM\Huck_ScreenSaver.scr

Checking %System%\Drivers folder and sub-folders...

Checking the Windows folder for system and hidden files within the last 60 days...
8/12/05 2:09:10 AM 999456 C:\WINDOWS\USER.DAT
8/12/05 2:09:10 AM 7000096 C:\WINDOWS\SYSTEM.DAT
8/11/05 5:22:14 AM 738519 C:\WINDOWS\ShellIconCache
8/11/05 5:22:28 AM 11530 C:\WINDOWS\ttfCache
8/12/05 12:23:14 AM 1092 C:\WINDOWS\Application Data\Microsoft\Internet Explorer\Desktop.htt
6/24/05 2:29:34 AM 19456 C:\WINDOWS\Application Data\Microsoft\Word\~WRL3107.tmp
7/30/05 8:38:26 PM 67 C:\WINDOWS\Temporary Internet Files\Content.IE5\desktop.ini
7/30/05 8:38:38 PM 67 C:\WINDOWS\Temporary Internet Files\Content.IE5\0NYD210P\desktop.ini
8/7/05 2:28:58 PM 67 C:\WINDOWS\Temporary Internet Files\Content.IE5\V0MROKSC\desktop.ini
7/30/05 8:38:40 PM 67 C:\WINDOWS\Temporary Internet Files\Content.IE5\D63CODFC\desktop.ini
8/7/05 2:29:02 PM 67 C:\WINDOWS\Temporary Internet Files\Content.IE5\UHS9SB8Z\desktop.ini
7/30/05 8:40:26 PM 67 C:\WINDOWS\Temporary Internet Files\Content.IE5\KLM701UH\desktop.ini
7/30/05 8:40:26 PM 67 C:\WINDOWS\Temporary Internet Files\Content.IE5\01QF8HEB\desktop.ini
7/30/05 8:40:26 PM 67 C:\WINDOWS\Temporary Internet Files\Content.IE5\WHEFS92F\desktop.ini
8/7/05 2:29:02 PM 67 C:\WINDOWS\Temporary Internet Files\Content.IE5\1NR46RR6\desktop.ini
7/30/05 8:40:42 PM 67 C:\WINDOWS\Temporary Internet Files\Content.IE5\OFXRV0OQ\desktop.ini
7/30/05 8:40:44 PM 67 C:\WINDOWS\Temporary Internet Files\Content.IE5\WD2VWXQ7\desktop.ini
7/30/05 8:40:50 PM 67 C:\WINDOWS\Temporary Internet Files\Content.IE5\EQAPPZCA\desktop.ini
8/7/05 2:29:20 PM 67 C:\WINDOWS\Temporary Internet Files\Content.IE5\QRQT6VWX\desktop.ini
7/30/05 8:40:50 PM 67 C:\WINDOWS\Temporary Internet Files\Content.IE5\CJYPC7CR\desktop.ini
7/30/05 8:40:52 PM 67 C:\WINDOWS\Temporary Internet Files\Content.IE5\D132IWCO\desktop.ini
7/30/05 8:40:58 PM 67 C:\WINDOWS\Temporary Internet Files\Content.IE5\WVKFSC51\desktop.ini
7/30/05 8:41:00 PM 67 C:\WINDOWS\Temporary Internet Files\Content.IE5\JNB9L66Z\desktop.ini
7/30/05 8:41:00 PM 67 C:\WINDOWS\Temporary Internet Files\Content.IE5\8SF4C9LV\desktop.ini
7/30/05 8:41:02 PM 67 C:\WINDOWS\Temporary Internet Files\Content.IE5\0H4HYRGB\desktop.ini
7/30/05 8:42:10 PM 67 C:\WINDOWS\Temporary Internet Files\Content.IE5\OD4L2X2J\desktop.ini
8/7/05 2:29:20 PM 67 C:\WINDOWS\Temporary Internet Files\Content.IE5\UF270RWD\desktop.ini
7/30/05 8:42:10 PM 67 C:\WINDOWS\Temporary Internet Files\Content.IE5\A4YL76NA\desktop.ini
7/30/05 8:42:12 PM 67 C:\WINDOWS\Temporary Internet Files\Content.IE5\018J2RYN\desktop.ini
7/31/05 2:16:32 AM 67 C:\WINDOWS\Temporary Internet Files\Content.IE5\4HUNG527\desktop.ini
8/7/05 2:29:38 PM 67 C:\WINDOWS\Temporary Internet Files\Content.IE5\O16VKT67\desktop.ini
7/31/05 2:16:38 AM 67 C:\WINDOWS\Temporary Internet Files\Content.IE5\WL6VK1QR\desktop.ini
7/31/05 2:16:52 AM 67 C:\WINDOWS\Temporary Internet Files\Content.IE5\4XUV4P6B\desktop.ini
7/31/05 2:17:48 AM 67 C:\WINDOWS\Temporary Internet Files\Content.IE5\70VIBHTJ\desktop.ini
7/31/05 2:18:00 AM 67 C:\WINDOWS\Temporary Internet Files\Content.IE5\LBR1W0UT\desktop.ini
7/31/05 2:18:02 AM 67 C:\WINDOWS\Temporary Internet Files\Content.IE5\8LMJOPIR\desktop.ini
7/31/05 2:18:06 AM 67 C:\WINDOWS\Temporary Internet Files\Content.IE5\ODOH4FQB\desktop.ini
7/31/05 2:18:06 AM 67 C:\WINDOWS\Temporary Internet Files\Content.IE5\Y3ZWVK27\desktop.ini
7/31/05 4:54:42 AM 67 C:\WINDOWS\Temporary Internet Files\Content.IE5\OORIQPUY\desktop.ini

»»»»»»»»»»»»»»»»» Checking Selected Startup Folders »»»»»»»»»»»»»»»»»»»»»

Checking files in %ALLUSERSPROFILE%\Startup folder...

Checking files in %ALLUSERSPROFILE%\Application Data folder...

Checking files in %USERPROFILE%\Startup folder...

Checking files in %USERPROFILE%\Application Data folder...
8/5/05 12:50:04 AM 2180 C:\WINDOWS\Application Data\dw.log
2/23/04 7:25:48 PM 22376 C:\WINDOWS\Application Data\GDIPFONTCACHEV1.DAT
12/22/04 7:43:14 PM 4713 C:\WINDOWS\Application Data\wo.tmp

»»»»»»»»»»»»»»»»» Checking Selected Registry Keys »»»»»»»»»»»»»»»»»»»»»»

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\User Agent\Post Platform]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved]

[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved]

[HKEY_CLASSES_ROOT\*\shellex\ContextMenuHandlers]
HKEY_CLASSES_ROOT\*\shellex\ContextMenuHandlers\WinZip
{E0D79304-84BE-11CE-9641-444553540000} = C:\PROGRA~1\WINZIP\WZSHLSTB.DLL
HKEY_CLASSES_ROOT\*\shellex\ContextMenuHandlers\AVG Shell Extension
{1E2CDF40-419B-11D2-A5A1-002018648BA7} =
HKEY_CLASSES_ROOT\*\shellex\ContextMenuHandlers\AVG7 Shell Extension
{9F97547E-4609-42C5-AE0C-81C61FFAEBC3} = C:\Program Files\Grisoft\AVG Free\avgse.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Folder\shellex\ContextMenuHandlers]
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Folder\shellex\ContextMenuHandlers\WinZip
{E0D79304-84BE-11CE-9641-444553540000} = C:\PROGRA~1\WINZIP\WZSHLSTB.DLL
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Folder\shellex\ContextMenuHandlers\AVG Shell Extension
{1E2CDF40-419B-11D2-A5A1-002018648BA7} =
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Folder\shellex\ContextMenuHandlers\SpySweeper
{7C9D5882-CB4A-4090-96C8-430BFE8B795B} = C:\PROGRA~1\WEBROOT\SPYSWE~1\SSCTXMNU.DLL
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Folder\shellex\ContextMenuHandlers\AVG7 Shell Extension
{9F97547E-4609-42C5-AE0C-81C61FFAEBC3} = C:\Program Files\Grisoft\AVG Free\avgse.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Directory\shellex\ContextMenuHandlers]
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Directory\shellex\ContextMenuHandlers\WinZip
{E0D79304-84BE-11CE-9641-444553540000} = C:\PROGRA~1\WINZIP\WZSHLSTB.DLL
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Directory\shellex\ContextMenuHandlers\ICQLiteMenu
{73B24247-042E-4EF5-ADC2-42F62E6FD654} =

[HKLM\Software\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects]
HKLM\Software\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{53707962-6F74-2D53-2644-206D7942484F}
= C:\PROGRA~1\SPYBOT~1\SDHELPER.DLL

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Explorer Bars]
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Explorer Bars\{4D5C8C25-D075-11d0-B416-00C04FB90376}
&Tip of the Day = C:\WINDOWS\SYSTEM\SHDOCVW.DLL
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Explorer Bars\{4528BBE0-4E08-11D5-AD55-00010333D0AD}
=

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\ToolBar]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Extensions]
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Extensions\{08B0E5C0-4FCB-11CF-AAA5-00401C608501}
MenuText = Sun Java Console : C:\Program Files\Java\jre1.5.0_04\bin\npjpi150_04.dll

[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Explorer Bars]
HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Explorer Bars\{4528BBE0-4E08-11D5-AD55-00010333D0AD}
=
HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Explorer Bars\{32683183-48a0-441b-a342-7c2a440a9478}
Media Band = C:\WINDOWS\SYSTEM\BROWSEUI.DLL
HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Explorer Bars\{EFA24E64-B078-11D0-89E4-00C04FC9E26E}
Explorer Band = C:\WINDOWS\SYSTEM\SHDOCVW.DLL
HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Explorer Bars\{EFA24E62-B078-11D0-89E4-00C04FC9E26E}
History Band = C:\WINDOWS\SYSTEM\SHDOCVW.DLL
HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Explorer Bars\{EFA24E61-B078-11D0-89E4-00C04FC9E26E}
Favorites Band = C:\WINDOWS\SYSTEM\SHDOCVW.DLL

[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Toolbar]
HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Toolbar\WebBrowser
{01E04581-4EEE-11D0-BFE9-00AA005B4383} = &Address : C:\WINDOWS\SYSTEM\BROWSEUI.DLL
{0E5CBF21-D15F-11D0-8301-00AA005B4383} = &Links : C:\WINDOWS\SYSTEM\BROWSEUI.DLL
{2318C2B1-4965-11D4-9B18-009027A5CD4F} = :
HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Toolbar\ShellBrowser
{01E04581-4EEE-11D0-BFE9-00AA005B4383} = &Address : C:\WINDOWS\SYSTEM\BROWSEUI.DLL
{0E5CBF21-D15F-11D0-8301-00AA005B4383} = &Links : C:\WINDOWS\SYSTEM\BROWSEUI.DLL
{2318C2B1-4965-11D4-9B18-009027A5CD4F} = :

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
SystemTray SysTray.Exe
LoadPowerProfile Rundll32.exe powrprof.dll,LoadCurrentPwrScheme
DisplayTrayIcon C:\WINDOWS\System\TrayIcon.exe
NvCplDaemon RUNDLL32.EXE NvQTwk,NvCplDaemon initialize
EM_EXEC C:\PROGRA~1\LOGITECH\MOUSEW~1\SYSTEM\EM_EXEC.EXE
LoadQM loadqm.exe
3Cmlink C:\WINDOWS\SYSTEM\3cmlnkW.exe
IntelliType "C:\Program Files\Microsoft Hardware\Keyboard\type32.exe"
SoundMan SOUNDMAN.EXE
AVG7_CC C:\PROGRA~1\GRISOFT\AVGFRE~1\AVGCC.EXE /STARTUP
AVG7_EMC C:\PROGRA~1\GRISOFT\AVGFRE~1\AVGEMC.EXE
AVG7_AMSVR C:\PROGRA~1\GRISOFT\AVGFRE~1\AVGAMSVR.EXE

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\OptionalComponents]
MSFS Installed = 1
MAPI Installed = 1
IMAIL Installed = 1

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\RunOnce]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\RunOnceEx]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\RunServices]
LoadPowerProfile Rundll32.exe powrprof.dll,LoadCurrentPwrScheme
KB891711 C:\WINDOWS\SYSTEM\KB891711\KB891711.EXE

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\RunServicesOnce]

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
nView

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\RunOnce]

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\RunServices]

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\RunServicesOnce]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\policies]

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Network

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Ratings

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\policies]

HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer
NoDriveTypeAutoRun •
NoBandCustomize 0
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System

HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Network


[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad]
WebCheck {E6FB5E20-DE35-11CF-9C87-00AA005127ED} = C:\WINDOWS\SYSTEM\WEBCHECK.DLL


»»»»»»»»»»»»»»»»»»»»»»»» Scan Complete »»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»
WinPFind v1.2.8 - Log file written to "WinPFind.Txt" in the WinPFind folder.
Scan completed on 8/12/05 2:10:59 AM
  • 0

#12
Metallica

Metallica

    Spyware Veteran

  • GeekU Moderator
  • 31,676 posts
Just to make sure, can you surf to:
http://virusscan.jotti.org/
and upload this file:
C:\WINDOWS\ss3unstl.exe

Let me know the results.

Once you have the firewall installed and configured we'll take another look.

Regards,
  • 0

#13
drpepperpdx

drpepperpdx

    New Member

  • Topic Starter
  • Member
  • Pip
  • 7 posts
Great news! AVG Anti-Virus detected and and destroyed rdsndin. No further evidence of trojans or viruses. And no appearance of the 'baloon' for weeks. This all happened after a recent definitions upgrade that AVG offered.

Thanks for your time and effort. You rock.
  • 0

#14
Metallica

Metallica

    Spyware Veteran

  • GeekU Moderator
  • 31,676 posts
Since this issue appears to be resolved ... this Topic has been closed. Glad we could help. :tazz:

If you're the topic starter, and need this topic reopened, please contact a staff member with the address of the thread.

Everyone else please begin a New Topic.
  • 0






Similar Topics

0 user(s) are reading this topic

0 members, 0 guests, 0 anonymous users

As Featured On:

Microsoft Yahoo BBC MSN PC Magazine Washington Post HP