Jump to content

Welcome to Geeks to Go - Register now for FREE

Need help with your computer or device? Want to learn new tech skills? You're in the right place!
Geeks to Go is a friendly community of tech experts who can solve any problem you have. Just create a free account and post your question. Our volunteers will reply quickly and guide you through the steps. Don't let tech troubles stop you. Join Geeks to Go now and get the support you need!

How it Works Create Account
Photo

winfixer


  • Please log in to reply

#16
Wizard

Wizard

    Retired Staff

  • Retired Staff
  • 5,661 posts
Have Pocket Killbox delete these files and confirm for me that they are gone

C:\WINDOWS\pqHxe

C:\Documents and Settings\steve pierce\Application Data\Sun\Java\Deployment\cache\javapi\v1.0\jar\ar3.jar-ac68ab9-44ab08e8.zip


1) Dump the contents of your IE cache -
Start --> settings --> control panel --> Internet options --> delete files

2) Dump the contents of the Mozilla FireFox Cache { if you use FireFox }
Tools --> Options --> Privacy --> Cache --> Clear

3) Dump the contents of your Sun Java cache -
Start --> settings --> control panel --> Java applet --> cache --> clear
or
Start --> settings --> control panel --> Java applet --> general --> settings -->
delete files


Download the Hoster from here:
http://www.funkytoad...load/hoster.zip
Press "Restore Original Hosts" and press "OK"
Exit Program


After all this,go to Safe Mode and scan again with WinPFind


Post back with a fresh HijackThis log and the results of WinPFind.
  • 0

Advertisements


#17
SP1969

SP1969

    Member

  • Topic Starter
  • Member
  • PipPip
  • 46 posts
Hijack this log....


Logfile of HijackThis v1.99.1
Scan saved at 10:26:13, on 03/11/2005
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\Explorer.EXE
C:\Documents and Settings\steve pierce\Desktop\HijackThis.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://www.google.co.uk
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.google.co.uk
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://www.google.co.uk
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.google.co.uk
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Window Title = Microsoft Internet Explorer provided by blueyonder
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyServer = http=webcache.blueyonder.co.uk:8080
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 6.0\Reader\ActiveX\AcroIEHelper.dll
O2 - BHO: BHOPopupSmasher Class - {702EA91C-1ACF-4772-8078-18F2B2EE1031} - C:\WINDOWS\system32\BlockActivex.dll
O2 - BHO: NAV Helper - {BDF3E430-B101-42AD-A544-FADC6B084872} - C:\Program Files\Norton AntiVirus\NavShExt.dll
O3 - Toolbar: Norton AntiVirus - {42CDD1BF-3FFB-4238-8AD1-7859DF00B1D6} - C:\Program Files\Norton AntiVirus\NavShExt.dll
O4 - HKLM\..\Run: [Apoint] C:\Program Files\Apoint2K\Apoint.exe
O4 - HKLM\..\Run: [AGRSMMSG] AGRSMMSG.exe
O4 - HKLM\..\Run: [ATIModeChange] Ati2mdxx.exe
O4 - HKLM\..\Run: [Cpqset] C:\Program Files\HPQ\Default Settings\cpqset.exe
O4 - HKLM\..\Run: [ATIPTA] C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe
O4 - HKLM\..\Run: [SunJavaUpdateSched] C:\Program Files\Java\j2re1.4.2_03\bin\jusched.exe
O4 - HKLM\..\Run: [CamMonitor] C:\Program Files\Hewlett-Packard\Digital Imaging\Unload\hpqcmon.exe
O4 - HKLM\..\Run: [eabconfg.cpl] C:\Program Files\HPQ\Quick Launch Buttons\EabServr.exe /Start
O4 - HKLM\..\Run: [RoxioEngineUtility] "C:\Program Files\Common Files\Roxio Shared\System\EngUtil.exe"
O4 - HKLM\..\Run: [RoxioDragToDisc] "C:\Program Files\Roxio\Easy CD Creator 6\DragToDisc\DrgToDsc.exe"
O4 - HKLM\..\Run: [HPHUPD05] C:\Program Files\Hewlett-Packard\{45B6180B-DCAB-4093-8EE8-6164457517F0}\hphupd05.exe
O4 - HKLM\..\Run: [HPHmon05] C:\WINDOWS\System32\hphmon05.exe
O4 - HKLM\..\Run: [ccApp] "C:\Program Files\Common Files\Symantec Shared\ccApp.exe"
O4 - HKLM\..\Run: [IntelliPoint] "C:\Program Files\Microsoft IntelliPoint\point32.exe"
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [Symantec NetDriver Monitor] C:\PROGRA~1\SYMNET~1\SNDMon.exe /Consumer
O4 - HKLM\..\Run: [HP Software Update] C:\Program Files\Hewlett-Packard\HP Software Update\HPWuSchd2.exe
O4 - HKLM\..\Run: [BluetoothAuthenticationAgent] rundll32.exe bthprops.cpl,,BluetoothAuthenticationAgent
O4 - HKLM\..\Run: [SystemTraySD] C:\WINDOWS\system32\SDSystemTray.exe
O4 - HKLM\..\Run: [SDAutoLiveupdate] C:\WINDOWS\system32\LiveUpdateSD.exe -AUTO
O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
O4 - Global Startup: BTTray.lnk = ?
O4 - Global Startup: EPSON Status Monitor 3 Environment Check 2.lnk = C:\WINDOWS\system32\spool\drivers\w32x86\3\E_SRCV02.EXE
O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office10\OSA.EXE
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~3\Office10\EXCEL.EXE/3000
O8 - Extra context menu item: Send To &Bluetooth - C:\Program Files\Belkin\Bluetooth Software\btsendto_ie_ctx.htm
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\WINDOWS\System32\msjava.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\WINDOWS\System32\msjava.dll
O9 - Extra button: @btrez.dll,-4015 - {CCA281CA-C863-46ef-9331-5C8D4460577F} - C:\Program Files\Belkin\Bluetooth Software\btsendto_ie.htm
O9 - Extra 'Tools' menuitem: @btrez.dll,-4017 - {CCA281CA-C863-46ef-9331-5C8D4460577F} - C:\Program Files\Belkin\Bluetooth Software\btsendto_ie.htm
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O14 - IERESET.INF: START_PAGE_URL=http://www.blueyonder.co.uk/dial
O16 - DPF: {0EB0E74A-2A76-4AB3-A7FB-9BD8C29F7F75} (CKAVWebScan Object) - http://www.kaspersky...can_unicode.cab
O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage) - http://go.microsoft....k/?linkid=39204
O16 - DPF: {7ED7005B-4AF6-4CFF-9AE0-F243C4B8260F} (HouseCallButton.setup) - http://de.trendmicro...eCallButton.CAB
O16 - DPF: {8EB3FF4E-86A1-4717-884D-7BA2D38272CB} (F-Secure Online Scanner) - http://support.f-sec...m/ols/fscax.cab
O16 - DPF: {9A9307A0-7DA4-4DAF-B042-5009F29E09E1} (ActiveScan Installer Class) - http://acs.pandasoft...free/asinst.cab
O16 - DPF: {D6376DD2-C2BD-49B2-A1B1-138F869633F3} (ASPRO Installer Class) - http://acs.pandasoft...5/ASPROinst.cab
O18 - Protocol: widimg - {EE7C2AFF-5742-44FF-BD0E-E521B0D3C3BA} - C:\WINDOWS\system32\btxppanel.dll
O23 - Service: Ati HotKey Poller - Unknown owner - C:\WINDOWS\System32\Ati2evxx.exe
O23 - Service: Bluetooth Service (btwdins) - Broadcom Corporation - C:\Program Files\Belkin\Bluetooth Software\bin\btwdins.exe
O23 - Service: Symantec Event Manager (ccEvtMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
O23 - Service: Symantec Password Validation (ccPwdSvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccPwdSvc.exe
O23 - Service: Symantec Settings Manager (ccSetMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe
O23 - Service: EPSON Printer Status Agent2 (EPSONStatusAgent2) - SEIKO EPSON CORPORATION - C:\Program Files\Common Files\EPSON\EBAPI\SAgent2.exe
O23 - Service: Norton AntiVirus Auto Protect Service (navapsvc) - Symantec Corporation - C:\Program Files\Norton AntiVirus\navapsvc.exe
O23 - Service: SAVScan - Symantec Corporation - C:\Program Files\Norton AntiVirus\SAVScan.exe
O23 - Service: ScriptBlocking Service (SBService) - Symantec Corporation - C:\PROGRA~1\COMMON~1\SYMANT~1\SCRIPT~1\SBServ.exe
O23 - Service: Symantec Network Drivers Service (SNDSrvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\SNDSrvc.exe
O23 - Service: SoundMAX Agent Service (SoundMAX Agent Service (default)) - Analog Devices, Inc. - C:\Program Files\Analog Devices\SoundMAX\SMAgent.exe
O23 - Service: SpyDetectSVC - Max Secure Technologies - C:\WINDOWS\system32\SpywareDetectorSVC.exe
O23 - Service: SymWMI Service (SymWSC) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\Security Center\SymWSC.exe
  • 0

#18
SP1969

SP1969

    Member

  • Topic Starter
  • Member
  • PipPip
  • 46 posts
WARNING: not all files found by this scanner are bad. Consult with a knowledgable person before proceeding.

If you see a message in the titlebar saying "Not responding..." you can ignore it. Windows somethimes displays this message due to the high volume of disk I/O. As long as the hard disk light is flashing, the program is still working properly.

»»»»»»»»»»»»»»»»» Windows OS and Versions »»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»
Product Name: Microsoft Windows XP Current Build: Service Pack 2 Current Build Number: 2600
Internet Explorer Version: 6.0.2900.2180

»»»»»»»»»»»»»»»»» Checking Selected Standard Folders »»»»»»»»»»»»»»»»»»»»

Checking %SystemDrive% folder...

Checking %ProgramFilesDir% folder...

Checking %WinDir% folder...
qoologic 31/10/2005 18:20:24 14342418 C:\WINDOWS\pav.sig
aspack 31/10/2005 18:20:24 14342418 C:\WINDOWS\pav.sig
SAHAgent 31/10/2005 18:20:24 14342418 C:\WINDOWS\pav.sig
winsync 31/10/2005 18:20:24 14342418 C:\WINDOWS\pav.sig

Checking %System% folder...
PEC2 31/03/2003 02:00:00 41397 C:\WINDOWS\SYSTEM32\dfrg.msc
PTech 29/08/2005 13:27:12 520968 C:\WINDOWS\SYSTEM32\LegitCheckControl.DLL
PECompact2 05/10/2005 02:09:08 2293088 C:\WINDOWS\SYSTEM32\MRT.exe
aspack 05/10/2005 02:09:08 2293088 C:\WINDOWS\SYSTEM32\MRT.exe
aspack 04/08/2004 00:56:38 708096 C:\WINDOWS\SYSTEM32\ntdll.dll
Umonitor 04/08/2004 00:56:46 657920 C:\WINDOWS\SYSTEM32\rasdlg.dll
winsync 31/03/2003 02:00:00 1309184 C:\WINDOWS\SYSTEM32\wbdbase.deu
UPX! 08/06/2005 17:06:32 61440 C:\WINDOWS\SYSTEM32\winstyle2.dll

Checking %System%\Drivers folder and sub-folders...
PTech 03/08/2004 22:41:38 1309184 C:\WINDOWS\SYSTEM32\drivers\mtlstrm.sys

Items found in C:\WINDOWS\SYSTEM32\drivers\etc\hosts


Checking the Windows folder and sub-folders for system and hidden files within the last 60 days...
03/11/2005 10:23:20 S 2048 C:\WINDOWS\bootstat.dat
03/11/2005 10:21:58 H 24 C:\WINDOWS\pqHxe
10/09/2005 22:17:52 H 54156 C:\WINDOWS\QTFont.qfn
05/10/2005 01:17:40 S 21737 C:\WINDOWS\system32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\KB896688.cat
28/09/2005 10:53:30 S 17402 C:\WINDOWS\system32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\KB900725.cat
09/09/2005 18:15:08 S 11084 C:\WINDOWS\system32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\KB901017.cat
03/11/2005 10:23:06 H 8192 C:\WINDOWS\system32\config\default.LOG
03/11/2005 10:23:40 H 1024 C:\WINDOWS\system32\config\SAM.LOG
03/11/2005 10:23:22 H 12288 C:\WINDOWS\system32\config\SECURITY.LOG
03/11/2005 10:27:24 H 73728 C:\WINDOWS\system32\config\software.LOG
03/11/2005 10:23:32 H 1101824 C:\WINDOWS\system32\config\system.LOG
15/10/2005 10:55:26 H 1024 C:\WINDOWS\system32\config\systemprofile\NTUSER.DAT.LOG
31/10/2005 12:13:24 HS 67 C:\WINDOWS\system32\config\systemprofile\Local Settings\Temporary Internet Files\Content.IE5\JAQXKMYX\desktop.ini
31/10/2005 12:13:24 HS 67 C:\WINDOWS\system32\config\systemprofile\Local Settings\Temporary Internet Files\Content.IE5\PBOSKXP8\desktop.ini
31/10/2005 12:13:24 HS 67 C:\WINDOWS\system32\config\systemprofile\Local Settings\Temporary Internet Files\Content.IE5\W9ABCP2F\desktop.ini
31/10/2005 12:13:24 HS 67 C:\WINDOWS\system32\config\systemprofile\Local Settings\Temporary Internet Files\Content.IE5\WXEJGT2Z\desktop.ini
23/10/2005 13:12:16 HS 388 C:\WINDOWS\system32\Microsoft\Protect\S-1-5-18\User\61f3bae5-cbe8-487c-92d3-fe9aeb746590
23/10/2005 13:12:16 HS 24 C:\WINDOWS\system32\Microsoft\Protect\S-1-5-18\User\Preferred
03/11/2005 10:22:16 H 6 C:\WINDOWS\Tasks\SA.DAT

Checking for CPL files...
Microsoft Corporation 04/08/2004 00:56:58 68608 C:\WINDOWS\SYSTEM32\access.cpl
Microsoft Corporation 04/08/2004 00:56:58 549888 C:\WINDOWS\SYSTEM32\appwiz.cpl
Broadcom Corporation 01/10/2004 14:40:16 266299 C:\WINDOWS\SYSTEM32\btcpl.cpl
Microsoft Corporation 04/08/2004 00:56:58 110592 C:\WINDOWS\SYSTEM32\bthprops.cpl
Microsoft Corporation 04/08/2004 00:56:58 135168 C:\WINDOWS\SYSTEM32\desk.cpl
Teleca Software Solutions AB 08/10/2003 10:54:36 339968 C:\WINDOWS\SYSTEM32\ecsepm.cpl
Microsoft Corporation 04/08/2004 00:56:58 80384 C:\WINDOWS\SYSTEM32\firewall.cpl
Microsoft Corporation 04/08/2004 00:56:58 155136 C:\WINDOWS\SYSTEM32\hdwwiz.cpl
Microsoft Corporation 04/08/2004 00:56:58 358400 C:\WINDOWS\SYSTEM32\inetcpl.cpl
Microsoft Corporation 04/08/2004 00:56:58 129536 C:\WINDOWS\SYSTEM32\intl.cpl
Microsoft Corporation 04/08/2004 00:56:58 380416 C:\WINDOWS\SYSTEM32\irprops.cpl
Microsoft Corporation 04/08/2004 00:56:58 68608 C:\WINDOWS\SYSTEM32\joy.cpl
Sun Microsystems 11/02/2004 13:50:44 61555 C:\WINDOWS\SYSTEM32\jpicpl32.cpl
Microsoft Corporation 31/03/2003 02:00:00 187904 C:\WINDOWS\SYSTEM32\main.cpl
Microsoft Corporation 04/08/2004 00:56:58 618496 C:\WINDOWS\SYSTEM32\mmsys.cpl
Microsoft Corporation 31/03/2003 02:00:00 35840 C:\WINDOWS\SYSTEM32\ncpa.cpl
Microsoft Corporation 04/08/2004 00:56:58 25600 C:\WINDOWS\SYSTEM32\netsetup.cpl
Microsoft Corporation 04/08/2004 00:56:58 257024 C:\WINDOWS\SYSTEM32\nusrmgr.cpl
Microsoft Corporation 04/08/2004 00:56:58 32768 C:\WINDOWS\SYSTEM32\odbccp32.cpl
Microsoft Corporation 04/08/2004 00:56:58 114688 C:\WINDOWS\SYSTEM32\powercfg.cpl
Apple Computer, Inc. 23/09/2004 18:57:40 323072 C:\WINDOWS\SYSTEM32\QuickTime.cpl
Microsoft Corporation 04/08/2004 00:56:58 298496 C:\WINDOWS\SYSTEM32\sysdm.cpl
Microsoft Corporation 31/03/2003 02:00:00 28160 C:\WINDOWS\SYSTEM32\telephon.cpl
Microsoft Corporation 04/08/2004 00:56:58 94208 C:\WINDOWS\SYSTEM32\timedate.cpl
Microsoft Corporation 04/08/2004 00:56:58 148480 C:\WINDOWS\SYSTEM32\wscui.cpl
Microsoft Corporation 26/05/2005 03:16:30 174360 C:\WINDOWS\SYSTEM32\wuaucpl.cpl
Microsoft Corporation 26/05/2005 03:16:30 174360 C:\WINDOWS\SYSTEM32\dllcache\wuaucpl.cpl

»»»»»»»»»»»»»»»»» Checking Selected Startup Folders »»»»»»»»»»»»»»»»»»»»»

Checking files in %ALLUSERSPROFILE%\Startup folder...
28/06/2005 22:22:56 677 C:\Documents and Settings\All Users\Start Menu\Programs\Startup\BTTray.lnk
16/07/2003 13:09:48 HS 84 C:\Documents and Settings\All Users\Start Menu\Programs\Startup\desktop.ini
02/12/2004 12:07:50 893 C:\Documents and Settings\All Users\Start Menu\Programs\Startup\EPSON Status Monitor 3 Environment Check 2.lnk
29/07/2004 17:40:20 1730 C:\Documents and Settings\All Users\Start Menu\Programs\Startup\Microsoft Office.lnk

Checking files in %ALLUSERSPROFILE%\Application Data folder...
16/07/2003 06:00:28 HS 62 C:\Documents and Settings\All Users\Application Data\desktop.ini
31/10/2005 00:31:08 12 C:\Documents and Settings\All Users\Application Data\DragToDiscUserNameD.txt
11/02/2004 14:19:30 237 C:\Documents and Settings\All Users\Application Data\hpzinstall.log

Checking files in %USERPROFILE%\Startup folder...
16/07/2003 13:09:48 HS 84 C:\Documents and Settings\steve pierce\Start Menu\Programs\Startup\desktop.ini

Checking files in %USERPROFILE%\Application Data folder...
16/07/2003 06:00:28 HS 62 C:\Documents and Settings\steve pierce\Application Data\desktop.ini
09/11/2004 18:36:02 0 C:\Documents and Settings\steve pierce\Application Data\dm.ini
12/07/2005 23:10:18 94176 C:\Documents and Settings\steve pierce\Application Data\GDIPFONTCACHEV1.DAT

»»»»»»»»»»»»»»»»» Checking Selected Registry Keys »»»»»»»»»»»»»»»»»»»»»»»

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\User Agent\Post Platform]
Supplied by blueyonder = IEAKblueyonder
SV1 =

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved]
=

[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved]

[HKEY_CLASSES_ROOT\*\shellex\ContextMenuHandlers]
HKEY_CLASSES_ROOT\*\shellex\ContextMenuHandlers\Max PC Safe
{EDE89C5C-EC11-4714-9EFB-B0E5AE0CB039} = C:\WINDOWS\system32\ShellWindowSecure.dll
HKEY_CLASSES_ROOT\*\shellex\ContextMenuHandlers\Offline Files
{750fdf0e-2a26-11d1-a3ea-080036587f03} = %SystemRoot%\System32\cscui.dll
HKEY_CLASSES_ROOT\*\shellex\ContextMenuHandlers\Open With
{09799AFB-AD67-11d1-ABCD-00C04FC30936} = %SystemRoot%\system32\SHELL32.dll
HKEY_CLASSES_ROOT\*\shellex\ContextMenuHandlers\Open With EncryptionMenu
{A470F8CF-A1E8-4f65-8335-227475AA5C46} = %SystemRoot%\system32\SHELL32.dll
HKEY_CLASSES_ROOT\*\shellex\ContextMenuHandlers\Symantec.Norton.Antivirus.IEContextMenu
{5345A4D5-41EB-4A2F-9616-CE1D4F6C35B2} = C:\Program Files\Norton AntiVirus\NavShExt.dll
HKEY_CLASSES_ROOT\*\shellex\ContextMenuHandlers\{a2a9545d-a0c2-42b4-9708-a0b2badd77c8}
Start Menu Pin = %SystemRoot%\system32\SHELL32.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Folder\shellex\ContextMenuHandlers]
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Folder\shellex\ContextMenuHandlers\Max PC Safe
{EDE89C5C-EC11-4714-9EFB-B0E5AE0CB039} = C:\WINDOWS\system32\ShellWindowSecure.dll
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Folder\shellex\ContextMenuHandlers\Symantec.Norton.Antivirus.IEContextMenu
{5345A4D5-41EB-4A2F-9616-CE1D4F6C35B2} = C:\Program Files\Norton AntiVirus\NavShExt.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Directory\shellex\ContextMenuHandlers]
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Directory\shellex\ContextMenuHandlers\EncryptionMenu
{A470F8CF-A1E8-4f65-8335-227475AA5C46} = %SystemRoot%\system32\SHELL32.dll
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Directory\shellex\ContextMenuHandlers\Offline Files
{750fdf0e-2a26-11d1-a3ea-080036587f03} = %SystemRoot%\System32\cscui.dll
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Directory\shellex\ContextMenuHandlers\Sharing
{f81e9010-6ea4-11ce-a7ff-00aa003ca9f6} = ntshrui.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Folder\shellex\ColumnHandlers]
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Folder\shellex\ColumnHandlers\{0D2E74C4-3C34-11d2-A27E-00C04FC30871}
= %SystemRoot%\system32\SHELL32.dll
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Folder\shellex\ColumnHandlers\{24F14F01-7B1C-11d1-838f-0000F80461CF}
= %SystemRoot%\system32\SHELL32.dll
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Folder\shellex\ColumnHandlers\{24F14F02-7B1C-11d1-838f-0000F80461CF}
= %SystemRoot%\system32\SHELL32.dll
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Folder\shellex\ColumnHandlers\{66742402-F9B9-11D1-A202-0000F81FEDEE}
= %SystemRoot%\system32\SHELL32.dll

[HKLM\Software\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects]
HKLM\Software\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{06849E9F-C8D7-4D59-B87D-784B7D6BE0B3}
AcroIEHlprObj Class = C:\Program Files\Adobe\Acrobat 6.0\Reader\ActiveX\AcroIEHelper.dll
HKLM\Software\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{702EA91C-1ACF-4772-8078-18F2B2EE1031}
BHOPopupSmasher Class = C:\WINDOWS\system32\BlockActivex.dll
HKLM\Software\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{BDF3E430-B101-42AD-A544-FADC6B084872}
CNavExtBho Class = C:\Program Files\Norton AntiVirus\NavShExt.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Explorer Bars]
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Explorer Bars\{4D5C8C25-D075-11d0-B416-00C04FB90376}
&Tip of the Day = %SystemRoot%\System32\shdocvw.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\ToolBar]
{42CDD1BF-3FFB-4238-8AD1-7859DF00B1D6} = Norton AntiVirus : C:\Program Files\Norton AntiVirus\NavShExt.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Extensions]
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Extensions\{08B0E5C0-4FCB-11CF-AAA5-00401C608501}
MenuText = Sun Java Console : C:\WINDOWS\System32\msjava.dll
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Extensions\{CCA281CA-C863-46ef-9331-5C8D4460577F}
ButtonText = @btrez.dll,-4015 :
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Extensions\{FB5F1910-F110-11d2-BB9E-00C04F795683}
ButtonText = Messenger : C:\Program Files\Messenger\msmsgs.exe

[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Explorer Bars]
HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Explorer Bars\{32683183-48a0-441b-a342-7c2a440a9478}
=
HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Explorer Bars\{BDEADE7F-C265-11D0-BCED-00A0C90AB50F}
&Discuss = shdocvw.dll
HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Explorer Bars\{EFA24E61-B078-11D0-89E4-00C04FC9E26E}
Favorites Band = %SystemRoot%\System32\shdocvw.dll
HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Explorer Bars\{EFA24E62-B078-11D0-89E4-00C04FC9E26E}
History Band = %SystemRoot%\System32\shdocvw.dll

[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Toolbar]
HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Toolbar\ShellBrowser
{42CDD1BF-3FFB-4238-8AD1-7859DF00B1D6} = Norton AntiVirus : C:\Program Files\Norton AntiVirus\NavShExt.dll
{01E04581-4EEE-11D0-BFE9-00AA005B4383} = &Address : %SystemRoot%\System32\browseui.dll
HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Toolbar\WebBrowser
{01E04581-4EEE-11D0-BFE9-00AA005B4383} = &Address : %SystemRoot%\System32\browseui.dll
{0E5CBF21-D15F-11D0-8301-00AA005B4383} = &Links : %SystemRoot%\system32\SHELL32.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
Apoint C:\Program Files\Apoint2K\Apoint.exe
AGRSMMSG AGRSMMSG.exe
ATIModeChange Ati2mdxx.exe
Cpqset C:\Program Files\HPQ\Default Settings\cpqset.exe
ATIPTA C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe
SunJavaUpdateSched C:\Program Files\Java\j2re1.4.2_03\bin\jusched.exe
CamMonitor C:\Program Files\Hewlett-Packard\Digital Imaging\Unload\hpqcmon.exe
eabconfg.cpl C:\Program Files\HPQ\Quick Launch Buttons\EabServr.exe /Start
RoxioEngineUtility "C:\Program Files\Common Files\Roxio Shared\System\EngUtil.exe"
RoxioDragToDisc "C:\Program Files\Roxio\Easy CD Creator 6\DragToDisc\DrgToDsc.exe"
HPHUPD05 C:\Program Files\Hewlett-Packard\{45B6180B-DCAB-4093-8EE8-6164457517F0}\hphupd05.exe
HPHmon05 C:\WINDOWS\System32\hphmon05.exe
ccApp "C:\Program Files\Common Files\Symantec Shared\ccApp.exe"
IntelliPoint "C:\Program Files\Microsoft IntelliPoint\point32.exe"
QuickTime Task "C:\Program Files\QuickTime\qttask.exe" -atboottime
Symantec NetDriver Monitor C:\PROGRA~1\SYMNET~1\SNDMon.exe /Consumer
HP Software Update C:\Program Files\Hewlett-Packard\HP Software Update\HPWuSchd2.exe
BluetoothAuthenticationAgent rundll32.exe bthprops.cpl,,BluetoothAuthenticationAgent
SystemTraySD C:\WINDOWS\system32\SDSystemTray.exe
SDAutoLiveupdate C:\WINDOWS\system32\LiveUpdateSD.exe -AUTO
SDAutoScan

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\OptionalComponents]
IMAIL Installed = 1
MAPI Installed = 1
MSFS Installed = 1

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\RunOnce]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\RunOnceEx]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\RunServices]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\RunServicesOnce]

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
MSMSGS "C:\Program Files\Messenger\msmsgs.exe" /background

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\RunOnce]

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\RunServices]

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\RunServicesOnce]

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows\load]

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows\run]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Shared Tools\MSConfig]

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Shared Tools\MSConfig\services

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Shared Tools\MSConfig\startupfolder

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Shared Tools\MSConfig\startupreg

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Shared Tools\MSConfig\state
system.ini 0
win.ini 0
bootini 0
services 0
startup 0


[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\policies]

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\NonEnum
{BDEADF00-C265-11D0-BCED-00A0C90AB50F} = C:\PROGRA~1\COMMON~1\MICROS~1\WEBFOL~1\MSONSEXT.DLL
{6DFD7C5C-2451-11d3-A299-00C04F8EF6AF} =
{0DF44EAA-FF21-4412-828E-260A8728E7F1} =


HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Ratings

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\system
dontdisplaylastusername 0
legalnoticecaption
legalnoticetext
shutdownwithoutlogon 1
undockwithoutlogon 1


[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\policies]

HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer
NoDriveTypeAutoRun 145


[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad]
PostBootReminder {7849596a-48ea-486e-8937-a2a3009f31a9} = %SystemRoot%\system32\SHELL32.dll
CDBurn {fbeb8a05-beee-4442-804e-409d6c4515e9} = %SystemRoot%\system32\SHELL32.dll
WebCheck {E6FB5E20-DE35-11CF-9C87-00AA005127ED} = %SystemRoot%\System32\webcheck.dll
SysTray {35CEC8A3-2BE6-11D2-8773-92E220524153} = C:\WINDOWS\System32\stobject.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon]
UserInit = C:\WINDOWS\system32\userinit.exe,
Shell = Explorer.exe
System =

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\AtiExtEvent
= Ati2evxx.dll

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\crypt32chain
= crypt32.dll

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\cryptnet
= cryptnet.dll

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\cscdll
= cscdll.dll

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\ScCertProp
= wlnotify.dll

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\Schedule
= wlnotify.dll

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\sclgntfy
= sclgntfy.dll

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\SensLogn
= WlNotify.dll

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\termsrv
= wlnotify.dll

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\wlballoon
= wlnotify.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options]
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\Your Image File Name Here without a path
Debugger = ntsd -d

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows]
AppInit_DLLs


»»»»»»»»»»»»»»»»»»»»»»»» Scan Complete »»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»
WinPFind v1.4.1 - Log file written to "WinPFind.Txt" in the WinPFind folder.
Scan completed on 03/11/2005 10:36:29
  • 0

#19
SP1969

SP1969

    Member

  • Topic Starter
  • Member
  • PipPip
  • 46 posts
Hi CM
I did all the steps

Killbox confirms the deletion of both files but when I re run killbox C:WINDOWS\pqHxe keeps deleting ie it doesnt say 'file not present' but 'delete successful'. The fact that I can delete it over and over again must mean that it is reinstalling itself, or does it?
Also Start ---Settings-----Java Applet---general----settings----delete---files doesnt exist?
there is no general tab, or anything like it.

Hope this is all OK.

Cheers

Steve
  • 0

#20
SP1969

SP1969

    Member

  • Topic Starter
  • Member
  • PipPip
  • 46 posts
I have looked in the windows folder and C:\WINDOWS\pqHxe is still there. Should I try to delete it manually????
  • 0

#21
Wizard

Wizard

    Retired Staff

  • Retired Staff
  • 5,661 posts
Well aint this being a real bugger to kill!


Lets see what else we can find.


Please download Rootkit Revealer (link is at the very bottom of the page)
  • Unzip it to your desktop.
  • Open the rootkitrevealer folder and double-click rootkitrevealer.exe
  • Click the Scan button (bottom right)
  • It may take a while to scan (don't do anything while it's running)
  • When it's done, go up to File > Save.
  • Save it as RKR.log and Save it to your desktop.
  • Open RKR.log on your desktop and copy the entire contents and paste them here

Download and Save Blacklight to your desktop:

Double-click blbeta.exe then accept the agreement, leave [X]scan through Windows Explorer checked, click > scan then > next

You'll see a list of all items found. There will also be a log on your desktop with the name fsbl.xxxxxxx.log (the xxxxxxx stand for numbers).

Copy and paste this log in your next reply. Don't choose the rename option yet! I want to see the log first, because legitimate items can also be present there, such as "wbemtest.exe"


Post the results of those 2 Scans please.
  • 0

#22
SP1969

SP1969

    Member

  • Topic Starter
  • Member
  • PipPip
  • 46 posts
cm
heres my rkr.log
thanks
steve


HKLM\SOFTWARE\CqkO9AAmhe6o 01/11/2005 00:39 0 bytes Hidden from Windows API.
HKLM\SYSTEM\ControlSet001\Enum\Root\LEGACY_RDPNP 16/07/2003 18:13 0 bytes Hidden from Windows API.
HKLM\SYSTEM\ControlSet001\Enum\Root\LEGACY_RFC1280 21/10/2005 10:21 0 bytes Hidden from Windows API.
HKLM\SYSTEM\ControlSet001\Services\RemoteAccess 12/11/2004 19:43 0 bytes Hidden from Windows API.
HKLM\SYSTEM\ControlSet001\Services\RFC1280 03/11/2005 11:02 0 bytes Hidden from Windows API.
C:\Program Files\Common Files\Symantec Shared\VirusDefs\20051102.019\vscanmsx.dat 03/11/2005 23:08 2.02 KB Hidden from Windows API.
C:\Program Files\Onlasoft 03/11/2005 09:03 0 bytes Hidden from Windows API.
C:\Program Files\Onlasoft\ace.dll 21/10/2005 10:21 568.00 KB Hidden from Windows API.
C:\Program Files\Onlasoft\AI_01-11-2005.log 01/11/2005 00:15 3 bytes Hidden from Windows API.
C:\Program Files\Onlasoft\AI_02-11-2005.log 02/11/2005 10:11 3 bytes Hidden from Windows API.
C:\Program Files\Onlasoft\AI_03-11-2005.log 03/11/2005 09:03 3 bytes Hidden from Windows API.
C:\Program Files\Onlasoft\AI_28-10-2005.log 28/10/2005 08:29 3 bytes Hidden from Windows API.
C:\Program Files\Onlasoft\AI_29-10-2005.log 28/10/2005 23:59 3 bytes Hidden from Windows API.
C:\Program Files\Onlasoft\AI_30-10-2005.log 30/10/2005 10:12 3 bytes Hidden from Windows API.
C:\Program Files\Onlasoft\AI_31-10-2005.log 31/10/2005 00:00 3 bytes Hidden from Windows API.
C:\Program Files\Onlasoft\Cache 03/11/2005 22:57 0 bytes Hidden from Windows API.
C:\Program Files\Onlasoft\Cache\00000029_4358eccd_0001312d 03/11/2005 16:38 3.05 KB Hidden from Windows API.
C:\Program Files\Onlasoft\Cache\00000029_4359f7db_0003567e 22/10/2005 08:27 6 bytes Hidden from Windows API.
C:\Program Files\Onlasoft\Cache\00000029_435a265a_0000b71b 03/11/2005 11:27 1.13 KB Hidden from Windows API.
C:\Program Files\Onlasoft\Cache\00000029_435ba7bc_0007270e 23/10/2005 15:09 6.26 KB Hidden from Windows API.
C:\Program Files\Onlasoft\Cache\00000029_435c97f5_00057bcf 30/10/2005 13:56 1.08 KB Hidden from Windows API.
C:\Program Files\Onlasoft\Cache\00000029_435cbcff_000dd40a 24/10/2005 10:52 32.30 KB Hidden from Windows API.
C:\Program Files\Onlasoft\Cache\00000029_435cd12c_00089544 02/11/2005 10:20 3.16 KB Hidden from Windows API.
C:\Program Files\Onlasoft\Cache\00000029_435ce2b4_0004c4b4 24/10/2005 13:33 70.70 KB Hidden from Windows API.
C:\Program Files\Onlasoft\Cache\00000029_435dfbea_000ca2dd 01/11/2005 01:25 38 bytes Hidden from Windows API.
C:\Program Files\Onlasoft\Cache\00000029_435e005c_0004c4b4 25/10/2005 09:52 54.83 KB Hidden from Windows API.
C:\Program Files\Onlasoft\Cache\00000029_435e1d1f_0008583b 25/10/2005 11:55 2.64 KB Hidden from Windows API.
C:\Program Files\Onlasoft\Cache\00000029_435e30db_0001312d 25/10/2005 13:19 52.95 KB Hidden from Windows API.
C:\Program Files\Onlasoft\Cache\00000029_435e45a3_000e4e1c 25/10/2005 14:48 298 bytes Hidden from Windows API.
C:\Program Files\Onlasoft\Cache\00000029_435e6fa9_00090f56 25/10/2005 17:47 6.71 KB Hidden from Windows API.
C:\Program Files\Onlasoft\Cache\00000029_435e88d6_000baeb9 25/10/2005 19:34 6.87 KB Hidden from Windows API.
C:\Program Files\Onlasoft\Cache\00000029_435ff3fc_0005f5e1 26/10/2005 21:24 64.28 KB Hidden from Windows API.
C:\Program Files\Onlasoft\Cache\00000029_435ff477_0002dc6c 26/10/2005 21:26 10.30 KB Hidden from Windows API.
C:\Program Files\Onlasoft\Cache\00000029_435ffb52_000ca2dd 28/10/2005 14:56 15 bytes Hidden from Windows API.
C:\Program Files\Onlasoft\Cache\00000029_4360065d_000d9701 26/10/2005 22:42 14.10 KB Hidden from Windows API.
C:\Program Files\Onlasoft\Cache\00000029_4360d436_00076417 27/10/2005 13:20 6 bytes Hidden from Windows API.
C:\Program Files\Onlasoft\Cache\00000029_4361e1cb_000b1555 28/10/2005 08:31 6 bytes Hidden from Windows API.
C:\Program Files\Onlasoft\Cache\00000029_43635889_00039387 29/10/2005 11:10 7.85 KB Hidden from Windows API.
C:\Program Files\Onlasoft\Cache\00000029_43649cf0_00098968 30/10/2005 10:14 6 bytes Hidden from Windows API.
C:\Program Files\Onlasoft\Cache\00000029_4364cd05_000a4083 30/10/2005 13:39 60.79 KB Hidden from Windows API.
C:\Program Files\Onlasoft\Cache\00000029_43655bfd_00029f63 31/10/2005 01:06 257.34 KB Hidden from Windows API.
C:\Program Files\Onlasoft\Cache\00000029_43655ccc_0006acfc 30/10/2005 23:52 54.71 KB Hidden from Windows API.
C:\Program Files\Onlasoft\Cache\00000029_43655db6_0007de29 30/10/2005 23:56 19.13 KB Hidden from Windows API.
C:\Program Files\Onlasoft\Cache\00000029_43656e28_0001ab3f 31/10/2005 01:06 6.86 KB Hidden from Windows API.
C:\Program Files\Onlasoft\Cache\00000029_436582c2_00016e36 31/10/2005 02:34 56.18 KB Hidden from Windows API.
C:\Program Files\Onlasoft\Cache\00000029_4365f143_0007270e 31/10/2005 10:26 6 bytes Hidden from Windows API.
C:\Program Files\Onlasoft\Cache\00000029_4365f1b5_00040d99 31/10/2005 10:28 7.05 KB Hidden from Windows API.
C:\Program Files\Onlasoft\Cache\00000029_4365fdae_00029f63 31/10/2005 11:19 7.05 KB Hidden from Windows API.
C:\Program Files\Onlasoft\Cache\00000029_43660b81_0002625a 31/10/2005 12:18 21.51 KB Hidden from Windows API.
C:\Program Files\Onlasoft\Cache\00000029_4366b472_000baeb9 01/11/2005 00:18 0 bytes Hidden from Windows API.
C:\Program Files\Onlasoft\Cache\00000029_4366c596_000f0537 01/11/2005 01:32 7.88 KB Hidden from Windows API.
C:\Program Files\Onlasoft\Cache\00000029_43691c69_000a7d8c 02/11/2005 20:07 226.10 KB Hidden from Windows API.
C:\Program Files\Onlasoft\Cache\00000029_4369f428_00057bcf 03/11/2005 11:27 60.25 KB Hidden from Windows API.
C:\Program Files\Onlasoft\Cache\00000029_436a22bc_000632ea 03/11/2005 14:46 15.49 KB Hidden from Windows API.
C:\Program Files\Onlasoft\Cache\00000099_4358f940_00029f63 21/10/2005 14:20 9.87 KB Hidden from Windows API.
C:\Program Files\Onlasoft\Cache\00000099_435bbef2_000d1cef 23/10/2005 16:48 67.97 KB Hidden from Windows API.
C:\Program Files\Onlasoft\Cache\00000099_435e1da0_000c28cb 25/10/2005 11:57 1.64 KB Hidden from Windows API.
C:\Program Files\Onlasoft\Cache\00000099_435e490b_0005b8d8 25/10/2005 15:02 7.11 KB Hidden from Windows API.
C:\Program Files\Onlasoft\Cache\00000099_435e7c32_00053ec6 25/10/2005 18:40 124.18 KB Hidden from Windows API.
C:\Program Files\Onlasoft\Cache\00000099_43612e5b_0008583b 27/10/2005 19:45 8.58 KB Hidden from Windows API.
C:\Program Files\Onlasoft\Cache\00000099_436573da_000a7d8c 31/10/2005 01:31 8.12 KB Hidden from Windows API.
C:\Program Files\Onlasoft\Cache\00000099_4365f5ac_0005b8d8 31/10/2005 10:45 56.43 KB Hidden from Windows API.
C:\Program Files\Onlasoft\Cache\00000099_43663ac9_000e8b25 31/10/2005 15:39 49.12 KB Hidden from Windows API.
C:\Program Files\Onlasoft\Cache\00000099_4369f741_0003567e 03/11/2005 11:40 66.56 KB Hidden from Windows API.
C:\Program Files\Onlasoft\Cache\00000099_436a2517_000a4083 03/11/2005 14:56 67.71 KB Hidden from Windows API.
C:\Program Files\Onlasoft\Cache\00000120_435bcc0c_00040d99 23/10/2005 17:44 8.85 KB Hidden from Windows API.
C:\Program Files\Onlasoft\Cache\00000120_435cb1b5_000dd40a 24/10/2005 10:04 14.98 KB Hidden from Windows API.
C:\Program Files\Onlasoft\Cache\00000120_436a02ad_000487ab 03/11/2005 12:29 1.96 KB Hidden from Windows API.
C:\Program Files\Onlasoft\Cache\00000120_436a27d2_0002625a 03/11/2005 15:08 111.16 KB Hidden from Windows API.
C:\Program Files\Onlasoft\Cache\00000124_4358fa41_0000f424 21/10/2005 14:25 85.47 KB Hidden from Windows API.
C:\Program Files\Onlasoft\Cache\00000124_435ca627_0007de29 24/10/2005 09:15 332 bytes Hidden from Windows API.
C:\Program Files\Onlasoft\Cache\00000124_435e1dae_00094c5f 25/10/2005 11:57 72.17 KB Hidden from Windows API.
C:\Program Files\Onlasoft\Cache\00000124_435e7c4e_00003d09 25/10/2005 18:41 6.87 KB Hidden from Windows API.
C:\Program Files\Onlasoft\Cache\00000124_43612e94_0001ab3f 27/10/2005 19:46 391.86 KB Hidden from Windows API.
C:\Program Files\Onlasoft\Cache\00000124_436561ed_0001ab3f 31/10/2005 00:14 6.88 KB Hidden from Windows API.
C:\Program Files\Onlasoft\Cache\00000124_436573db_00040d99 31/10/2005 01:31 8.34 KB Hidden from Windows API.
C:\Program Files\Onlasoft\Cache\00000124_4365f5ac_000baeb9 31/10/2005 10:45 8.14 KB Hidden from Windows API.
C:\Program Files\Onlasoft\Cache\00000124_43663ad5_000b71b0 31/10/2005 15:40 58.13 KB Hidden from Windows API.
C:\Program Files\Onlasoft\Cache\00000124_4369f747_0006ea05 03/11/2005 11:40 4.48 KB Hidden from Windows API.
C:\Program Files\Onlasoft\Cache\00000124_436a2527_000af79e 03/11/2005 14:56 1.04 KB Hidden from Windows API.
C:\Program Files\Onlasoft\Cache\000001eb_4358f3ad_00089544 21/10/2005 13:57 267.69 KB Hidden from Windows API.
C:\Program Files\Onlasoft\Cache\000001eb_435bbeed_0008583b 23/10/2005 16:48 448 bytes Hidden from Windows API.
C:\Program Files\Onlasoft\Cache\000001eb_435ca520_000c65d4 24/10/2005 09:10 51.78 KB Hidden from Windows API.
C:\Program Files\Onlasoft\Cache\000001eb_435e05a6_0008d24d 25/10/2005 10:15 20 bytes Hidden from Windows API.
C:\Program Files\Onlasoft\Cache\000001eb_435e1d86_000f0537 25/10/2005 11:57 12.83 KB Hidden from Windows API.
C:\Program Files\Onlasoft\Cache\000001eb_435e4702_00053ec6 25/10/2005 14:53 4.23 KB Hidden from Windows API.
C:\Program Files\Onlasoft\Cache\000001eb_43612de6_0008d24d 27/10/2005 19:43 5.54 KB Hidden from Windows API.
C:\Program Files\Onlasoft\Cache\000001eb_43655f02_00040d99 31/10/2005 00:02 7.69 KB Hidden from Windows API.
C:\Program Files\Onlasoft\Cache\000001eb_4365861d_000bebc2 31/10/2005 02:49 12.86 KB Hidden from Windows API.
C:\Program Files\Onlasoft\Cache\000001eb_4365f51e_000c65d4 31/10/2005 10:42 8.42 KB Hidden from Windows API.
C:\Program Files\Onlasoft\Cache\000001eb_4366398a_000d1cef 31/10/2005 15:34 7.88 KB Hidden from Windows API.
C:\Program Files\Onlasoft\Cache\000001eb_4368ab9c_00081b32 02/11/2005 12:05 49.75 KB Hidden from Windows API.
C:\Program Files\Onlasoft\Cache\000001eb_436a24b8_0000f424 03/11/2005 14:54 157.22 KB Hidden from Windows API.
C:\Program Files\Onlasoft\Cache\0000030a_43593619_00094c5f 21/10/2005 18:40 21.06 KB Hidden from Windows API.
C:\Program Files\Onlasoft\Cache\0000030a_435bcbf9_00039387 23/10/2005 17:44 11.45 KB Hidden from Windows API.
C:\Program Files\Onlasoft\Cache\0000030a_435cadbe_000bebc2 24/10/2005 09:47 6.28 KB Hidden from Windows API.
C:\Program Files\Onlasoft\Cache\0000030a_436a02ac_00007a12 03/11/2005 12:29 52.16 KB Hidden from Windows API.
C:\Program Files\Onlasoft\Cache\0000030a_436a269f_000ec82e 03/11/2005 15:02 47 bytes Hidden from Windows API.
C:\Program Files\Onlasoft\Cache\0000047e_435beaf5_000b34a7 31/10/2005 11:19 16.49 KB Hidden from Windows API.
C:\Program Files\Onlasoft\Cache\00000732_435bcc03_00066ff3 23/10/2005 17:44 3.58 KB Hidden from Windows API.
C:\Program Files\Onlasoft\Cache\00000732_436a02ad_0000b71b 03/11/2005 12:29 244.45 KB Hidden from Windows API.
C:\Program Files\Onlasoft\Cache\00000732_436a27ce_000dd40a 03/11/2005 15:07 470 bytes Hidden from Windows API.
C:\Program Files\Onlasoft\Cache\0000074d_43591590_00044aa2 21/10/2005 16:21 316 bytes Hidden from Windows API.
C:\Program Files\Onlasoft\Cache\0000074d_435bc15c_0003567e 23/10/2005 16:59 72.31 KB Hidden from Windows API.
C:\Program Files\Onlasoft\Cache\0000074d_435caa15_000ca2dd 30/10/2005 13:53 4.19 KB Hidden from Windows API.
C:\Program Files\Onlasoft\Cache\0000074d_435e1dde_000bebc2 25/10/2005 11:58 14.30 KB Hidden from Windows API.
C:\Program Files\Onlasoft\Cache\0000074d_435e4bd6_000bebc2 25/10/2005 15:14 8.55 KB Hidden from Windows API.
C:\Program Files\Onlasoft\Cache\0000074d_43665dbc_00016e36 31/10/2005 18:09 9.51 KB Hidden from Windows API.
C:\Program Files\Onlasoft\Cache\0000074d_4368b2b2_0007a120 02/11/2005 12:36 6.41 KB Hidden from Windows API.
C:\Program Files\Onlasoft\Cache\0000074d_4369fe25_0009c671 03/11/2005 12:10 86.92 KB Hidden from Windows API.
C:\Program Files\Onlasoft\Cache\0000074d_436a25b7_000dd40a 03/11/2005 14:59 30.71 KB Hidden from Windows API.
C:\Program Files\Onlasoft\Cache\00000822_435bde02_0004c4b4 23/10/2005 19:01 7.47 KB Hidden from Windows API.
C:\Program Files\Onlasoft\Cache\00000822_436a2164_000e1113 03/11/2005 14:40 27.67 KB Hidden from Windows API.
C:\Program Files\Onlasoft\Cache\00000822_436a95f6_00044aa2 03/11/2005 22:57 20.68 KB Hidden from Windows API.
C:\Program Files\Onlasoft\Cache\00000902_435be00b_0009c671 23/10/2005 19:10 11.53 KB Hidden from Windows API.
C:\Program Files\Onlasoft\Cache\00000902_436a2258_0000b71b 03/11/2005 14:56 13.79 KB Hidden from Windows API.
C:\Program Files\Onlasoft\Cache\00000bb3_4358f40c_00053ec6 21/10/2005 13:58 67.70 KB Hidden from Windows API.
C:\Program Files\Onlasoft\Cache\00000bb3_435bbeed_0008d24d 23/10/2005 16:48 1.99 KB Hidden from Windows API.
C:\Program Files\Onlasoft\Cache\00000bb3_435ca54e_000baeb9 24/10/2005 09:11 47.79 KB Hidden from Windows API.
C:\Program Files\Onlasoft\Cache\00000bb3_435e05a7_000632ea 25/10/2005 10:15 38 bytes Hidden from Windows API.
C:\Program Files\Onlasoft\Cache\00000bb3_435e1d87_00022551 25/10/2005 11:57 944 bytes Hidden from Windows API.
C:\Program Files\Onlasoft\Cache\00000bb3_435e4705_000c65d4 25/10/2005 14:53 5.59 KB Hidden from Windows API.
C:\Program Files\Onlasoft\Cache\00000bb3_435e7597_0004c4b4 25/10/2005 18:12 11.97 KB Hidden from Windows API.
C:\Program Files\Onlasoft\Cache\00000bb3_43655f61_000baeb9 31/10/2005 00:03 7.24 KB Hidden from Windows API.
C:\Program Files\Onlasoft\Cache\00000bb3_43657370_000f0537 31/10/2005 01:29 7.57 KB Hidden from Windows API.
C:\Program Files\Onlasoft\Cache\00000bb3_4365f526_000ec82e 31/10/2005 10:42 8.16 KB Hidden from Windows API.
C:\Program Files\Onlasoft\Cache\00000bb3_436639e4_00094c5f 31/10/2005 15:36 7.93 KB Hidden from Windows API.
C:\Program Files\Onlasoft\Cache\00000bb3_4368ac81_000cdfe6 02/11/2005 12:09 64.63 KB Hidden from Windows API.
C:\Program Files\Onlasoft\Cache\00000bb3_4369f4df_00007a12 03/11/2005 11:30 103.13 KB Hidden from Windows API.
C:\Program Files\Onlasoft\Cache\00000bb3_436a24be_000dd40a 03/11/2005 14:54 67.37 KB Hidden from Windows API.
C:\Program Files\Onlasoft\Cache\00000bdb_4359363b_0005f5e1 21/10/2005 18:40 0 bytes Hidden from Windows API.
C:\Program Files\Onlasoft\Cache\00000bdb_435bcc03_00022551 23/10/2005 17:44 7.09 KB Hidden from Windows API.
C:\Program Files\Onlasoft\Cache\00000bdb_435cadda_00053ec6 24/10/2005 09:48 6.15 KB Hidden from Windows API.
C:\Program Files\Onlasoft\Cache\00000bdb_436a02ac_000baeb9 03/11/2005 12:29 2.07 KB Hidden from Windows API.
C:\Program Files\Onlasoft\Cache\00000bdb_436a26a9_000dd40a 03/11/2005 15:03 1.50 KB Hidden from Windows API.
C:\Program Files\Onlasoft\Cache\00000ddc_435bd984_00040d99 23/10/2005 18:42 25.32 KB Hidden from Windows API.
C:\Program Files\Onlasoft\Cache\00000ddc_436a0784_0001ab3f 03/11/2005 12:50 18.67 KB Hidden from Windows API.
C:\Program Files\Onlasoft\Cache\00000ddc_436a28db_000e1113 03/11/2005 15:12 63.67 KB Hidden from Windows API.
C:\Program Files\Onlasoft\Cache\00000f3e_4358f935_000ca2dd 23/10/2005 18:59 116.75 KB Hidden from Windows API.
C:\Program Files\Onlasoft\Cache\00000f3e_435bbef1_0006ea05 23/10/2005 16:48 700 bytes Hidden from Windows API.
C:\Program Files\Onlasoft\Cache\00000f3e_435e1da0_000a4083 25/10/2005 11:57 830 bytes Hidden from Windows API.
C:\Program Files\Onlasoft\Cache\00000f3e_435e48d2_0003d090 25/10/2005 15:01 311 bytes Hidden from Windows API.
C:\Program Files\Onlasoft\Cache\00000f3e_435e7c31_00031975 25/10/2005 18:40 7.10 KB Hidden from Windows API.
C:\Program Files\Onlasoft\Cache\00000f3e_43612e5b_00044aa2 27/10/2005 19:45 7.15 KB Hidden from Windows API.
C:\Program Files\Onlasoft\Cache\00000f3e_436573da_00090f56 31/10/2005 01:31 624.19 KB Hidden from Windows API.
C:\Program Files\Onlasoft\Cache\00000f3e_4365f5a2_000ca2dd 31/10/2005 10:44 4.14 KB Hidden from Windows API.
C:\Program Files\Onlasoft\Cache\00000f3e_43663a8a_000baeb9 31/10/2005 15:38 8.27 KB Hidden from Windows API.
C:\Program Files\Onlasoft\Cache\00000f3e_4368ade3_0005b8d8 02/11/2005 12:15 355 bytes Hidden from Windows API.
C:\Program Files\Onlasoft\Cache\00000f3e_4369f61d_000a4083 03/11/2005 11:35 72.34 KB Hidden from Windows API.
C:\Program Files\Onlasoft\Cache\00000f3e_436a24dc_00039387 03/11/2005 14:55 4.41 KB Hidden from Windows API.
C:\Program Files\Onlasoft\Cache\00000fbf_435bea67_000ec82e 23/10/2005 19:54 6.61 KB Hidden from Windows API.
C:\Program Files\Onlasoft\Cache\0000121f_435bde63_000baeb9 23/10/2005 19:02 178.14 KB Hidden from Windows API.
C:\Program Files\Onlasoft\Cache\00001238_435935bc_000e1113 21/10/2005 18:38 3.07 KB Hidden from Windows API.
C:\Program Files\Onlasoft\Cache\00001238_435bc1af_00057bcf 23/10/2005 17:00 36.15 KB Hidden from Windows API.
C:\Program Files\Onlasoft\Cache\00001238_435cab74_00040d99 24/10/2005 09:37 208.00 KB Hidden from Windows API.
C:\Program Files\Onlasoft\Cache\00001238_435e1e36_0002dc6c 25/10/2005 11:59 3.27 KB Hidden from Windows API.
C:\Program Files\Onlasoft\Cache\00001238_435e5110_00022551 25/10/2005 15:36 4.26 KB Hidden from Windows API.
C:\Program Files\Onlasoft\Cache\00001238_43691631_00094c5f 02/11/2005 19:40 379.27 KB Hidden from Windows API.
C:\Program Files\Onlasoft\Cache\00001238_4369ff2f_0005b8d8 03/11/2005 12:14 45.86 KB Hidden from Windows API.
C:\Program Files\Onlasoft\Cache\00001238_436a267f_000b71b0 03/11/2005 15:02 714 bytes Hidden from Windows API.
C:\Program Files\Onlasoft\Cache\000012db_4358f42f_000a7d8c 21/10/2005 13:59 9.96 KB Hidden from Windows API.
C:\Program Files\Onlasoft\Cache\000012db_435bbeed_000b71b0 23/10/2005 16:48 3.67 KB Hidden from Windows API.
C:\Program Files\Onlasoft\Cache\000012db_435ca57d_00066ff3 24/10/2005 09:12 7.73 KB Hidden from Windows API.
C:\Program Files\Onlasoft\Cache\000012db_435e1d87_00089544 25/10/2005 11:57 0 bytes Hidden from Windows API.
C:\Program Files\Onlasoft\Cache\000012db_435e4726_0004c4b4 25/10/2005 14:54 6.08 KB Hidden from Windows API.
C:\Program Files\Onlasoft\Cache\000012db_435e75b3_0005f5e1 25/10/2005 18:13 20.23 KB Hidden from Windows API.
C:\Program Files\Onlasoft\Cache\000012db_43612df6_0008d24d 27/10/2005 19:43 4.24 KB Hidden from Windows API.
C:\Program Files\Onlasoft\Cache\000012db_43655f6b_0007270e 31/10/2005 00:03 57.12 KB Hidden from Windows API.
C:\Program Files\Onlasoft\Cache\000012db_43657389_00007a12 31/10/2005 01:29 262.32 KB Hidden from Windows API.
C:\Program Files\Onlasoft\Cache\000012db_4365f591_000d59f8 31/10/2005 10:44 7.84 KB Hidden from Windows API.
C:\Program Files\Onlasoft\Cache\000012db_436639f9_000e8b25 31/10/2005 15:36 7.12 KB Hidden from Windows API.
C:\Program Files\Onlasoft\Cache\000012db_4369f590_000bebc2 03/11/2005 11:33 0 bytes Hidden from Windows API.
C:\Program Files\Onlasoft\Cache\000012e1_435bde41_000632ea 23/10/2005 19:02 142.52 KB Hidden from Windows API.
C:\Program Files\Onlasoft\Cache\000012e1_436a21fa_000501bd 03/11/2005 14:43 17.42 KB Hidden from Windows API.
C:\Program Files\Onlasoft\Cache\00001366_435bdac8_000f0537 23/10/2005 18:47 53.82 KB Hidden from Windows API.
C:\Program Files\Onlasoft\Cache\00001366_436a0970_000e8b25 03/11/2005 12:58 303 bytes Hidden from Windows API.
C:\Program Files\Onlasoft\Cache\00001366_436a3d39_00040d99 03/11/2005 16:39 21.23 KB Hidden from Windows API.
C:\Program Files\Onlasoft\Cache\0000139d_435be0b4_00057bcf 23/10/2005 19:12 7.84 KB Hidden from Windows API.
C:\Program Files\Onlasoft\Cache\000013e9_435be7d0_00039387 23/10/2005 19:43 129.48 KB Hidden from Windows API.
C:\Program Files\Onlasoft\Cache\0000153c_4358f904_000c65d4 23/10/2005 19:53 117.64 KB Hidden from Windows API.
C:\Program Files\Onlasoft\Cache\0000153c_435bbeed_000bebc2 23/10/2005 16:48 3.85 KB Hidden from Windows API.
C:\Program Files\Onlasoft\Cache\0000153c_435e1d87_000e4e1c 25/10/2005 11:56 15.37 KB Hidden from Windows API.
C:\Program Files\Onlasoft\Cache\0000153c_435e473f_00031975 25/10/2005 14:54 0 bytes Hidden from Windows API.
C:\Program Files\Onlasoft\Cache\0000153c_435e762a_000f0537 25/10/2005 18:15 62.19 KB Hidden from Windows API.
C:\Program Files\Onlasoft\Cache\0000153c_43612e34_000d9701 31/10/2005 01:30 291.48 KB Hidden from Windows API.
C:\Program Files\Onlasoft\Cache\0000153c_43655f6b_00098968 31/10/2005 00:03 4.26 KB Hidden from Windows API.
C:\Program Files\Onlasoft\Cache\0000153c_436573a7_000e8b25 31/10/2005 01:30 7.99 KB Hidden from Windows API.
C:\Program Files\Onlasoft\Cache\0000153c_4365f597_0009c671 31/10/2005 10:44 359 bytes Hidden from Windows API.
C:\Program Files\Onlasoft\Cache\0000153c_436639fa_000487ab 31/10/2005 15:36 327.28 KB Hidden from Windows API.
C:\Program Files\Onlasoft\Cache\0000153c_4368ad49_000b34a7 02/11/2005 12:12 8.66 KB Hidden from Windows API.
C:\Program Files\Onlasoft\Cache\0000153c_4369f5a6_000d59f8 03/11/2005 11:33 41.23 KB Hidden from Windows API.
C:\Program Files\Onlasoft\Cache\0000153c_436a24d9_0006ea05 03/11/2005 14:55 4.86 KB Hidden from Windows API.
C:\Program Files\Onlasoft\Cache\00001547_43591570_00029f63 21/10/2005 16:21 163 bytes Hidden from Windows API.
C:\Program Files\Onlasoft\Cache\00001547_435bbf29_00022551 23/10/2005 16:49 67.73 KB Hidden from Windows API.
C:\Program Files\Onlasoft\Cache\00001547_435e1dc0_000b34a7 25/10/2005 11:57 5.21 KB Hidden from Windows API.
C:\Program Files\Onlasoft\Cache\00001547_435e4b38_000b71b0 25/10/2005 15:11 7.21 KB Hidden from Windows API.
C:\Program Files\Onlasoft\Cache\00001547_435e7ccf_0006ea05 25/10/2005 18:43 8.56 KB Hidden from Windows API.
C:\Program Files\Onlasoft\Cache\00001547_43657483_000d59f8 31/10/2005 01:33 59.85 KB Hidden from Windows API.
C:\Program Files\Onlasoft\Cache\00001547_4365fb2e_00081b32 31/10/2005 11:08 8.11 KB Hidden from Windows API.
C:\Program Files\Onlasoft\Cache\00001547_4368b2a6_00057bcf 02/11/2005 12:35 15.05 KB Hidden from Windows API.
C:\Program Files\Onlasoft\Cache\00001547_4369fdf4_00089544 03/11/2005 12:09 65.91 KB Hidden from Windows API.
C:\Program Files\Onlasoft\Cache\00001547_436a2589_00044aa2 03/11/2005 14:58 50.90 KB Hidden from Windows API.
C:\Program Files\Onlasoft\Cache\000015a1_435bddea_0008583b 23/10/2005 19:00 113.10 KB Hidden from Windows API.
C:\Program Files\Onlasoft\Cache\000015a1_436a09f5_00031975 03/11/2005 13:00 84.99 KB Hidden from Windows API.
C:\Program Files\Onlasoft\Cache\000015a1_436a95d7_000a037a 03/11/2005 22:57 240 bytes Hidden from Windows API.
C:\Program Files\Onlasoft\Cache\00001649_4358f3a5_0001e848 21/10/2005 13:56 856 bytes Hidden from Windows API.
C:\Program Files\Onlasoft\Cache\00001649_435a0243_0004c4b4 22/10/2005 09:11 1.86 KB Hidden from Windows API.
C:\Program Files\Onlasoft\Cache\00001649_435bbec8_0001ab3f 23/10/2005 16:48 71.71 KB Hidden from Windows API.
C:\Program Files\Onlasoft\Cache\00001649_435cc32f_000b34a7 24/10/2005 11:19 884 bytes Hidden from Windows API.
C:\Program Files\Onlasoft\Cache\00001649_435cd13d_00029f63 02/11/2005 12:15 5.16 KB Hidden from Windows API.
C:\Program Files\Onlasoft\Cache\00001649_435ce3f7_00066ff3 24/10/2005 13:39 12.48 KB Hidden from Windows API.
C:\Program Files\Onlasoft\Cache\00001649_435e1d6f_000d59f8 25/10/2005 11:56 2.89 KB Hidden from Windows API.
C:\Program Files\Onlasoft\Cache\00001649_435e46ea_00094c5f 25/10/2005 14:53 68.63 KB Hidden from Windows API.
C:\Program Files\Onlasoft\Cache\00001649_435e7001_0008d24d 25/10/2005 17:48 240 bytes Hidden from Windows API.
C:\Program Files\Onlasoft\Cache\00001649_435ff30e_000a7d8c 26/10/2005 21:20 7.11 KB Hidden from Windows API.
C:\Program Files\Onlasoft\Cache\00001649_43612c1d_0007de29 27/10/2005 19:35 7.03 KB Hidden from Windows API.
C:\Program Files\Onlasoft\Cache\00001649_43655ecc_00016e36 31/10/2005 00:01 4.24 KB Hidden from Windows API.
C:\Program Files\Onlasoft\Cache\00001649_43656ebe_000aba95 31/10/2005 01:09 4.25 KB Hidden from Windows API.
C:\Program Files\Onlasoft\Cache\00001649_43658569_00094c5f 31/10/2005 02:48 19.20 KB Hidden from Windows API.
C:\Program Files\Onlasoft\Cache\00001649_4365f491_000d59f8 31/10/2005 10:40 8.07 KB Hidden from Windows API.
C:\Program Files\Onlasoft\Cache\00001649_4369f442_00000000 03/11/2005 11:28 5.65 KB Hidden from Windows API.
C:\Program Files\Onlasoft\Cache\00001649_436a2447_000c65d4 03/11/2005 14:52 86.61 KB Hidden from Windows API.
C:\Program Files\Onlasoft\Cache\000016c5_435be759_0008d24d 23/10/2005 19:41 11.69 KB Hidden from Windows API.
C:\Program Files\Onlasoft\Cache\0000187e_435be74b_000f0537 23/10/2005 19:41 177.05 KB Hidden from Windows API.
C:\Program Files\Onlasoft\Cache\000018be_4358ecd6_00044aa2 31/10/2005 12:18 254 bytes Hidden from Windows API.
C:\Program Files\Onlasoft\Cache\000018be_4359ffe9_000ca2dd 03/11/2005 14:44 15.80 KB Hidden from Windows API.
C:\Program Files\Onlasoft\Cache\000018be_435a266f_00007a12 03/11/2005 14:56 525 bytes Hidden from Windows API.
C:\Program Files\Onlasoft\Cache\000018be_435bb814_00007a12 23/10/2005 16:19 1.15 KB Hidden from Windows API.
C:\Program Files\Onlasoft\Cache\000018be_435ca458_0003d090 24/10/2005 09:07 39.69 KB Hidden from Windows API.
C:\Program Files\Onlasoft\Cache\000018be_435cbfff_000ca2dd 24/10/2005 11:05 3 bytes Hidden from Windows API.
C:\Program Files\Onlasoft\Cache\000018be_435cd12f_000c65d4 02/11/2005 10:20 113 bytes Hidden from Windows API.
C:\Program Files\Onlasoft\Cache\000018be_435ce2cf_000cdfe6 24/10/2005 13:34 29.04 KB Hidden from Windows API.
C:\Program Files\Onlasoft\Cache\000018be_435e0068_00022551 25/10/2005 09:52 16.38 KB Hidden from Windows API.
C:\Program Files\Onlasoft\Cache\000018be_435e1d37_00053ec6 25/10/2005 11:55 69.02 KB Hidden from Windows API.
C:\Program Files\Onlasoft\Cache\000018be_435e27e3_000d59f8 25/10/2005 12:41 61.50 KB Hidden from Windows API.
C:\Program Files\Onlasoft\Cache\000018be_435e3131_0007a120 25/10/2005 13:21 32.85 KB Hidden from Windows API.
C:\Program Files\Onlasoft\Cache\000018be_435e45f0_00040d99 25/10/2005 18:13 54.06 KB Hidden from Windows API.
C:\Program Files\Onlasoft\Cache\000018be_435e6fb8_000ec82e 25/10/2005 17:53 35.43 KB Hidden from Windows API.
C:\Program Files\Onlasoft\Cache\000018be_435e88e6_000cdfe6 25/10/2005 19:35 7.06 KB Hidden from Windows API.
C:\Program Files\Onlasoft\Cache\000018be_435ff530_000af79e 31/10/2005 12:21 20.16 KB Hidden from Windows API.
C:\Program Files\Onlasoft\Cache\000018be_4360067f_00029f63 26/10/2005 22:43 38.99 KB Hidden from Windows API.
C:\Program Files\Onlasoft\Cache\000018be_43635895_0001ab3f 29/10/2005 11:10 124.10 KB Hidden from Windows API.
C:\Program Files\Onlasoft\Cache\000018be_4363598d_00090f56 29/10/2005 11:14 5.65 KB Hidden from Windows API.
C:\Program Files\Onlasoft\Cache\000018be_4364cd52_00022551 30/10/2005 13:40 5.65 KB Hidden from Windows API.
C:\Program Files\Onlasoft\Cache\000018be_43655a09_000dd40a 30/10/2005 23:40 7.11 KB Hidden from Windows API.
C:\Program Files\Onlasoft\Cache\000018be_43655bff_0002625a 30/10/2005 23:49 8.41 KB Hidden from Windows API.
C:\Program Files\Onlasoft\Cache\000018be_43655ceb_00076417 30/10/2005 23:53 240 bytes Hidden from Windows API.
C:\Program Files\Onlasoft\Cache\000018be_43655deb_00094c5f 30/10/2005 23:57 8.45 KB Hidden from Windows API.
C:\Program Files\Onlasoft\Cache\000018be_43656e34_000bebc2 31/10/2005 01:07 7.86 KB Hidden from Windows API.
C:\Program Files\Onlasoft\Cache\000018be_436582cc_0000b71b 31/10/2005 02:34 9.48 KB Hidden from Windows API.
C:\Program Files\Onlasoft\Cache\000018be_4365f176_000b71b0 31/10/2005 10:27 7.05 KB Hidden from Windows API.
C:\Program Files\Onlasoft\Cache\000018be_4365f21e_0002dc6c 31/10/2005 10:29 248.77 KB Hidden from Windows API.
C:\Program Files\Onlasoft\Cache\000018be_43660c5a_0000b71b 31/10/2005 12:21 54.95 KB Hidden from Windows API.
C:\Program Files\Onlasoft\Cache\000018be_43667b29_0001312d 31/10/2005 20:17 14.94 KB Hidden from Windows API.
C:\Program Files\Onlasoft\Cache\000018be_4366c5a3_000e1113 01/11/2005 01:32 34.37 KB Hidden from Windows API.
C:\Program Files\Onlasoft\Cache\000018be_436935aa_00094c5f 02/11/2005 21:54 63.95 KB Hidden from Windows API.
C:\Program Files\Onlasoft\Cache\000018be_436a23ea_000bebc2 03/11/2005 14:51 61.61 KB Hidden from Windows API.
C:\Program Files\Onlasoft\Cache\00001a49_435bd554_0002dc6c 23/10/2005 18:24 54.23 KB Hidden from Windows API.
C:\Program Files\Onlasoft\Cache\00001a49_435cb346_000aba95 24/10/2005 10:11 32.42 KB Hidden from Windows API.
C:\Program Files\Onlasoft\Cache\00001a49_436a0720_0005b8d8 03/11/2005 12:48 0 bytes Hidden from Windows API.
C:\Program Files\Onlasoft\Cache\00001a49_436a284e_0007270e 03/11/2005 15:10 16.14 KB Hidden from Windows API.
C:\Program Files\Onlasoft\Cache\00001ad4_435935be_00016e36 21/10/2005 18:38 1.12 KB Hidden from Windows API.
C:\Program Files\Onlasoft\Cache\00001ad4_435bc240_000d1cef 23/10/2005 17:02 63.06 KB Hidden from Windows API.
C:\Program Files\Onlasoft\Cache\00001ad4_435cabc9_000baeb9 24/10/2005 09:39 7.35 KB Hidden from Windows API.
C:\Program Files\Onlasoft\Cache\00001ad4_43657f5e_00094c5f 31/10/2005 02:20 8.90 KB Hidden from Windows API.
C:\Program Files\Onlasoft\Cache\00001ad4_4369167d_000d1cef 02/11/2005 19:41 238.18 KB Hidden from Windows API.
C:\Program Files\Onlasoft\Cache\00001ad4_436a0020_0001312d 03/11/2005 12:18 29.16 KB Hidden from Windows API.
C:\Program Files\Onlasoft\Cache\00001ad4_436a2680_000d59f8 03/11/2005 15:02 602 bytes Hidden from Windows API.
C:\Program Files\Onlasoft\Cache\00001cd0_435bdadd_00007a12 23/10/2005 18:47 27.90 KB Hidden from Windows API.
C:\Program Files\Onlasoft\Cache\00001cd0_436a95ab_0006ea05 03/11/2005 22:56 4.24 KB Hidden from Windows API.
C:\Program Files\Onlasoft\Cache\00001e1f_435935bd_00007a12 21/10/2005 18:38 2.22 KB Hidden from Windows API.
C:\Program Files\Onlasoft\Cache\00001e1f_435bc240_00022551 23/10/2005 17:02 2.95 KB Hidden from Windows API.
C:\Program Files\Onlasoft\Cache\00001e1f_435cab74_000aba95 24/10/2005 09:37 8.94 KB Hidden from Windows API.
C:\Program Files\Onlasoft\Cache\00001e1f_435e566b_0000b71b 25/10/2005 15:59 4.28 KB Hidden from Windows API.
C:\Program Files\Onlasoft\Cache\00001e1f_4369163e_0007de29 02/11/2005 19:40 211.02 KB Hidden from Windows API.
C:\Program Files\Onlasoft\Cache\00001e1f_436a000c_00000000 03/11/2005 12:18 31.47 KB Hidden from Windows API.
C:\Program Files\Onlasoft\Cache\00002213_435935e7_000c65d4 21/10/2005 18:39 41.92 KB Hidden from Windows API.
C:\Program Files\Onlasoft\Cache\00002213_435bcbcf_00066ff3 23/10/2005 17:43 5.15 KB Hidden from Windows API.
C:\Program Files\Onlasoft\Cache\00002213_435cad4d_000c28cb 24/10/2005 09:45 20.18 KB Hidden from Windows API.
C:\Program Files\Onlasoft\Cache\00002213_436917c9_00066ff3 02/11/2005 19:47 199.50 KB Hidden from Windows API.
C:\Program Files\Onlasoft\Cache\00002213_436a02a7_00076417 03/11/2005 12:29 119.52 KB Hidden from Windows API.
C:\Program Files\Onlasoft\Cache\00002213_436a269f_00003d09 03/11/2005 15:02 2.81 KB Hidden from Windows API.
C:\Program Files\Onlasoft\Cache\000022ee_435bd201_0009c671 23/10/2005 18:10 49.35 KB Hidden from Windows API.
C:\Program Files\Onlasoft\Cache\000022ee_436a02ad_000aba95 03/11/2005 12:29 1.97 KB Hidden from Windows API.
C:\Program Files\Onlasoft\Cache\000022ee_436a2808_0005f5e1 03/11/2005 15:08 60.86 KB Hidden from Windows API.
C:\Program Files\Onlasoft\Cache\00002350_435bcc0c_00098968 23/10/2005 17:44 8.20 KB Hidden from Windows API.
C:\Program Files\Onlasoft\Cache\00002350_435cb228_000e1113 24/10/2005 10:06 612 bytes Hidden from Windows API.
C:\Program Files\Onlasoft\Cache\00002350_436a02ad_0007270e 03/11/2005 12:29 2.00 KB Hidden from Windows API.
C:\Program Files\Onlasoft\Cache\00002350_436a27f0_0001e848 03/11/2005 15:08 41.96 KB Hidden from Windows API.
C:\Program Files\Onlasoft\Cache\000023c9_435bea00_0005b8d8 23/10/2005 19:52 15.93 KB Hidden from Windows API.
C:\Program Files\Onlasoft\Cache\0000260d_435935e9_000c28cb 21/10/2005 18:40 0 bytes Hidden from Windows API.
C:\Program Files\Onlasoft\Cache\0000260d_435bcbcf_000b34a7 23/10/2005 17:43 8.07 KB Hidden from Windows API.
C:\Program Files\Onlasoft\Cache\0000260d_435cad7d_000a4083 24/10/2005 10:01 25.47 KB Hidden from Windows API.
C:\Program Files\Onlasoft\Cache\0000260d_435e6863_0005b8d8 31/10/2005 19:03 0 bytes Hidden from Windows API.
C:\Program Files\Onlasoft\Cache\0000260d_4369180a_000d1cef 02/11/2005 19:48 186.91 KB Hidden from Windows API.
C:\Program Files\Onlasoft\Cache\0000260d_436a02a8_00022551 03/11/2005 12:29 5.89 KB Hidden from Windows API.
C:\Program Files\Onlasoft\Cache\0000260d_436a269f_000c28cb 03/11/2005 15:02 430 bytes Hidden from Windows API.
C:\Program Files\Onlasoft\Cache\000026a6_4359358b_000d1cef 21/10/2005 18:38 719 bytes Hidden from Windows API.
C:\Program Files\Onlasoft\Cache\000026a6_435bc188_000632ea 23/10/2005 16:59 24.02 KB Hidden from Windows API.
C:\Program Files\Onlasoft\Cache\000026a6_435e1e15_000a7d8c 25/10/2005 11:59 1.68 KB Hidden from Windows API.
C:\Program Files\Onlasoft\Cache\000026a6_435e4dd8_00081b32 25/10/2005 15:23 8.65 KB Hidden from Windows API.
C:\Program Files\Onlasoft\Cache\000026a6_436575a2_00039387 31/10/2005 01:38 4.23 KB Hidden from Windows API.
C:\Program Files\Onlasoft\Cache\000026a6_43666074_0002625a 01/11/2005 00:20 37.78 KB Hidden from Windows API.
C:\Program Files\Onlasoft\Cache\000026a6_4368b60a_000af79e 02/11/2005 12:50 48.44 KB Hidden from Windows API.
C:\Program Files\Onlasoft\Cache\000026a6_4369feb6_000d1cef 03/11/2005 12:12 84.92 KB Hidden from Windows API.
C:\Program Files\Onlasoft\Cache\000026a6_436a260b_00022551 03/11/2005 15:00 3.70 KB Hidden from Windows API.
C:\Program Files\Onlasoft\Cache\000026ca_435bde9b_00081b32 23/10/2005 19:03 28.57 KB Hidden from Windows API.
C:\Program Files\Onlasoft\Cache\000026ca_436a2248_00089544 03/11/2005 14:56 11.47 KB Hidden from Windows API.
C:\Program Files\Onlasoft\Cache\000026e9_4358f3a9_0008583b 21/10/2005 13:56 1.70 KB Hidden from Windows API.
C:\Program Files\Onlasoft\Cache\000026e9_435bbeed_0005f5e1 23/10/2005 16:48 953 bytes Hidden from Windows API.
C:\Program Files\Onlasoft\Cache\000026e9_435ca51f_0008d24d 24/10/2005 09:10 332 bytes Hidden from Windows API.
C:\Program Files\Onlasoft\Cache\000026e9_435cd369_0001e848 24/10/2005 12:28 11.34 KB Hidden from Windows API.
C:\Program Files\Onlasoft\Cache\000026e9_435e02a4_0001e848 25/10/2005 10:02 133.31 KB Hidden from Windows API.
C:\Program Files\Onlasoft\Cache\000026e9_435e1d86_000e4e1c 25/10/2005 11:57 626 bytes Hidden from Windows API.
C:\Program Files\Onlasoft\Cache\000026e9_435e46ff_000bebc2 25/10/2005 14:53 11.94 KB Hidden from Windows API.
C:\Program Files\Onlasoft\Cache\000026e9_435e7199_000af79e 25/10/2005 17:55 23.60 KB Hidden from Windows API.
C:\Program Files\Onlasoft\Cache\000026e9_43612c4b_000b34a7 27/10/2005 19:36 8.60 KB Hidden from Windows API.
C:\Program Files\Onlasoft\Cache\000026e9_43655ef5_00029f63 31/10/2005 00:01 8.00 KB Hidden from Windows API.
C:\Program Files\Onlasoft\Cache\000026e9_43657366_00081b32 31/10/2005 01:29 5.69 KB Hidden from Windows API.
C:\Program Files\Onlasoft\Cache\000026e9_43658616_00016e36 31/10/2005 02:48 21.15 KB Hidden from Windows API.
C:\Program Files\Onlasoft\Cache\000026e9_4365f51d_00094c5f 31/10/2005 10:42 6.87 KB Hidden from Windows API.
C:\Program Files\Onlasoft\Cache\000026e9_4366397c_000cdfe6 31/10/2005 15:34 124.10 KB Hidden from Windows API.
C:\Program Files\Onlasoft\Cache\000026e9_436896f0_00003d09 02/11/2005 10:37 7.47 KB Hidden from Windows API.
C:\Program Files\Onlasoft\Cache\000026e9_4369f4ca_00076417 03/11/2005 11:30 43.73 KB Hidden from Windows API.
C:\Program Files\Onlasoft\Cache\000026e9_436a2495_000e4e1c 03/11/2005 14:54 61.96 KB Hidden from Windows API.
C:\Program Files\Onlasoft\Cache\00002c3b_435bddcc_000b34a7 23/10/2005 19:00 11.32 KB Hidden from Windows API.
C:\Program Files\Onlasoft\Cache\00002c3b_436a09ec_0009c671 03/11/2005 13:00 77.49 KB Hidden from Windows API.
C:\Program Files\Onlasoft\Cache\00002c3b_436a95d0_000a4083 03/11/2005 22:57 21.39 KB Hidden from Windows API.
C:\Program Files\Onlasoft\Cache\00002cd6_4358ecde_000baeb9 31/10/2005 12:18 786 bytes Hidden from Windows API.
C:\Program Files\Onlasoft\Cache\00002cd6_435a023a_000e4e1c 22/10/2005 09:11 1.48 KB Hidden from Windows API.
C:\Program Files\Onlasoft\Cache\00002cd6_435bb89e_000c28cb 23/10/2005 16:21 147.24 KB Hidden from Windows API.
C:\Program Files\Onlasoft\Cache\00002cd6_435ca4a1_00007a12 24/10/2005 09:08 332 bytes Hidden from Windows API.
C:\Program Files\Onlasoft\Cache\00002cd6_435cc17e_0007270e 25/10/2005 12:44 924 bytes Hidden from Windows API.
C:\Program Files\Onlasoft\Cache\00002cd6_435cd135_000501bd 02/11/2005 12:15 74 bytes Hidden from Windows API.
C:\Program Files\Onlasoft\Cache\00002cd6_435ce3dd_000aba95 24/10/2005 13:38 15.51 KB Hidden from Windows API.
C:\Program Files\Onlasoft\Cache\00002cd6_435e006c_000baeb9 25/10/2005 09:52 970 bytes Hidden from Windows API.
C:\Program Files\Onlasoft\Cache\00002cd6_435e1d5e_00081b32 25/10/2005 11:56 70.93 KB Hidden from Windows API.
C:\Program Files\Onlasoft\Cache\00002cd6_435e28c6_00090f56 25/10/2005 12:44 20.17 KB Hidden from Windows API.
C:\Program Files\Onlasoft\Cache\00002cd6_435e45f7_0001ab3f 25/10/2005 14:49 446 bytes Hidden from Windows API.
C:\Program Files\Onlasoft\Cache\00002cd6_435e6fed_00029f63 25/10/2005 17:53 10.50 KB Hidden from Windows API.
C:\Program Files\Onlasoft\Cache\00002cd6_435ff2d7_0001312d 26/10/2005 21:19 240 bytes Hidden from Windows API.
C:\Program Files\Onlasoft\Cache\00002cd6_435ff73b_0003d090 26/10/2005 21:38 64 bytes Hidden from Windows API.
C:\Program Files\Onlasoft\Cache\00002cd6_436008bb_000a037a 26/10/2005 22:52 5.26 KB Hidden from Windows API.
C:\Program Files\Onlasoft\Cache\00002cd6_43612bf0_0008583b 27/10/2005 19:35 124.79 KB Hidden from Windows API.
C:\Program Files\Onlasoft\Cache\00002cd6_436358d0_0006ea05 29/10/2005 11:11 221.07 KB Hidden from Windows API.
C:\Program Files\Onlasoft\Cache\00002cd6_43655ea2_000baeb9 31/10/2005 00:00 7.91 KB Hidden from Windows API.
C:\Program Files\Onlasoft\Cache\00002cd6_43656e54_000d59f8 31/10/2005 01:07 8.84 KB Hidden from Windows API.
C:\Program Files\Onlasoft\Cache\00002cd6_4366b842_0006acfc 01/11/2005 00:35 7.87 KB Hidden from Windows API.
C:\Program Files\Onlasoft\Cache\00002cd6_4366c5c8_000ca2dd 01/11/2005 01:32 16.01 KB Hidden from Windows API.
C:\Program Files\Onlasoft\Cache\00002cd6_436935f9_00053ec6 02/11/2005 21:56 41.31 KB Hidden from Windows API.
C:\Program Files\Onlasoft\Cache\00002cd6_4369f433_000baeb9 03/11/2005 11:27 461 bytes Hidden from Windows API.
C:\Program Files\Onlasoft\Cache\00002cd6_436a242d_0008583b 03/11/2005 14:52 245.43 KB Hidden from Windows API.
C:\Program Files\Onlasoft\Cache\00002d12_4359158d_0006acfc 21/10/2005 16:21 841 bytes Hidden from Windows API.
C:\Program Files\Onlasoft\Cache\00002d12_435bc153_000baeb9 23/10/2005 16:58 69.54 KB Hidden from Windows API.
C:\Program Files\Onlasoft\Cache\00002d12_435caa15_00031975 30/10/2005 13:53 16.48 KB Hidden from Windows API.
C:\Program Files\Onlasoft\Cache\00002d12_435e1dde_0004c4b4 25/10/2005 11:58 1.71 KB Hidden from Windows API.
C:\Program Files\Onlasoft\Cache\00002d12_435e4bd5_00066ff3 25/10/2005 15:14 6.98 KB Hidden from Windows API.
C:\Program Files\Onlasoft\Cache\00002d12_4365748c_000af79e 31/10/2005 01:34 5.74 KB Hidden from Windows API.
C:\Program Files\Onlasoft\Cache\00002d12_43665dba_00022551 31/10/2005 18:08 8.91 KB Hidden from Windows API.
C:\Program Files\Onlasoft\Cache\00002d12_4368b2b2_00057bcf 02/11/2005 12:36 8.05 KB Hidden from Windows API.
C:\Program Files\Onlasoft\Cache\00002d12_4369fe1d_00076417 03/11/2005 12:10 79.02 KB Hidden from Windows API.
C:\Program Files\Onlasoft\Cache\00002d12_436a25b2_0003d090 03/11/2005 14:58 31.12 KB Hidden from Windows API.
C:\Program Files\Onlasoft\Cache\00002e40_435bdaa6_0006ea05 23/10/2005 18:47 11.47 KB Hidden from Windows API.
C:\Program Files\Onlasoft\Cache\00002e40_436a096e_000e8b25 03/11/2005 12:58 47.87 KB Hidden from Windows API.
C:\Program Files\Onlasoft\Cache\00002ea6_4358f423_00003d09 21/10/2005 13:58 78.24 KB Hidden from Windows API.
C:\Program Files\Onlasoft\Cache\00002ea6_435bbeed_000a4083 23/10/2005 16:48 803 bytes Hidden from Windows API.
C:\Program Files\Onlasoft\Cache\00002ea6_435ca575_000487ab 24/10/2005 09:12 59.82 KB Hidden from Windows API.
C:\Program Files\Onlasoft\Cache\00002ea6_435e1d87_0003567e 25/10/2005 11:57 12.40 KB Hidden from Windows API.
C:\Program Files\Onlasoft\Cache\00002ea6_435e4725_0008d24d 25/10/2005 14:54 9.69 KB Hidden from Windows API.
C:\Program Files\Onlasoft\Cache\00002ea6_435e75b2_000a7d8c 25/10/2005 18:13 24.70 KB Hidden from Windows API.
C:\Program Files\Onlasoft\Cache\00002ea6_43655f68_000ec82e 31/10/2005 00:03 7.96 KB Hidden from Windows API.
C:\Program Files\Onlasoft\Cache\00002ea6_4365737d_0001ab3f 31/10/2005 01:29 7.75 KB Hidden from Windows API.
C:\Program Files\Onlasoft\Cache\00002ea6_4365f591_000baeb9 31/10/2005 10:44 56.76 KB Hidden from Windows API.
C:\Program Files\Onlasoft\Cache\00002ea6_436639e6_00081b32 31/10/2005 15:36 8.94 KB Hidden from Windows API.
C:\Program Files\Onlasoft\Cache\00002ea6_4369f58f_00007a12 03/11/2005 11:33 48.79 KB Hidden from Windows API.
C:\Program Files\Onlasoft\Cache\00002ea6_436a24d8_00094c5f 03/11/2005 14:56 226.68 KB Hidden from Windows API.
C:\Program Files\Onlasoft\Cache\00002f14_435bea8b_000632ea 23/10/2005 19:54 22.83 KB Hidden from Windows API.
C:\Program Files\Onlasoft\Cache\0000301c_43593630_0008d24d 21/10/2005 18:40 25.51 KB Hidden from Windows API.
C:\Program Files\Onlasoft\Cache\0000301c_435bcbf9_000487ab 23/10/2005 17:44 7.99 KB Hidden from Windows API.
C:\Program Files\Onlasoft\Cache\0000301c_435cadd9_000b34a7 25/10/2005 14:54 47.11 KB Hidden from Windows API.
C:\Program Files\Onlasoft\Cache\0000301c_436a02ac_0007de29 03/11/2005 12:29 9.90 KB Hidden from Windows API.
C:\Program Files\Onlasoft\Cache\0000301c_436a26a9_000c28cb 03/11/2005 15:03 429 bytes Hidden from Windows API.
C:\Program Files\Onlasoft\Cache\0000305e_4358fa57_0000b71b 23/10/2005 19:46 0 bytes Hidden from Windows API.
C:\Program Files\Onlasoft\Cache\0000305e_435bbf15_000ca2dd 23/10/2005 16:49 803 bytes Hidden from Windows API.
C:\Program Files\Onlasoft\Cache\0000305e_435ca628_000bebc2 24/10/2005 09:15 52.16 KB Hidden from Windows API.
C:\Program Files\Onlasoft\Cache\0000305e_435e1db0_0007a120 25/10/2005 11:57 1006 bytes Hidden from Windows API.
C:\Program Files\Onlasoft\Cache\0000305e_435e49b9_0007270e 25/10/2005 15:05 6.79 KB Hidden from Windows API.
C:\Program Files\Onlasoft\Cache\0000305e_43612e94_000501bd 27/10/2005 19:46 7.83 KB Hidden from Windows API.
C:\Program Files\Onlasoft\Cache\0000305e_436561ef_0000b71b 31/10/2005 00:14 8.46 KB Hidden from Windows API.
C:\Program Files\Onlasoft\Cache\0000305e_436573f3_0001312d 31/10/2005 01:31 294.17 KB Hidden from Windows API.
C:\Program Files\Onlasoft\Cache\0000305e_4365f71a_000f0537 31/10/2005 10:51 125.02 KB Hidden from Windows API.
C:\Program Files\Onlasoft\Cache\0000305e_43665c33_0003567e 31/10/2005 18:02 9.16 KB Hidden from Windows API.
C:\Program Files\Onlasoft\Cache\0000305e_4368ae32_0007de29 02/11/2005 12:16 22.33 KB Hidden from Windows API.
C:\Program Files\Onlasoft\Cache\0000305e_4369f797_0006ea05 03/11/2005 11:42 57.09 KB Hidden from Windows API.
C:\Program Files\Onlasoft\Cache\0000305e_436a2527_000d59f8 03/11/2005 14:56 1.08 KB Hidden from Windows API.
C:\Program Files\Onlasoft\Cache\0000314f_435bda16_0001ab3f 23/10/2005 18:44 41.30 KB Hidden from Windows API.
C:\Program Files\Onlasoft\Cache\0000314f_436a07a3_0007de29 03/11/2005 12:50 29.34 KB Hidden from Windows API.
C:\Program Files\Onlasoft\Cache\0000314f_436a2908_00029f63 03/11/2005 15:13 148 bytes Hidden from Windows API.
C:\Program Files\Onlasoft\Cache\0000323b_435935db_0005f5e1 21/10/2005 18:39 23.47 KB Hidden from Windows API.
C:\Program Files\Onlasoft\Cache\0000323b_435bcbce_0006ea05 23/10/2005 17:43 21.42 KB Hidden from Windows API.
C:\Program Files\Onlasoft\Cache\0000323b_435cac3b_00031975 24/10/2005 09:41 13.35 KB Hidden from Windows API.
C:\Program Files\Onlasoft\Cache\0000323b_435e684d_000e8b25 25/10/2005 17:15 5.54 KB Hidden from Windows API.
C:\Program Files\Onlasoft\Cache\0000323b_436917c0_000d9701 02/11/2005 19:47 180.01 KB Hidden from Windows API.
C:\Program Files\Onlasoft\Cache\0000323b_436a028d_0005b8d8 03/11/2005 12:29 71.83 KB Hidden from Windows API.
C:\Program Files\Onlasoft\Cache\0000323b_436a2697_0007de29 03/11/2005 15:02 602 bytes Hidden from Windows API.
C:\Program Files\Onlasoft\Cache\000033ea_435be85d_000aba95 23/10/2005 19:45 8.51 KB Hidden from Windows API.
C:\Program Files\Onlasoft\Cache\0000366b_435bdc6c_000c65d4 23/10/2005 18:54 176.52 KB Hidden from Windows API.
C:\Program Files\Onlasoft\Cache\0000366b_436a0976_00094c5f 03/11/2005 12:58 62.59 KB Hidden from Windows API.
C:\Program Files\Onlasoft\Cache\0000366b_436a95ad_000bebc2 03/11/2005 22:56 8.91 KB Hidden from Windows API.
C:\Program Files\Onlasoft\Cache\00003699_435bdeba_00040d99 23/10/2005 19:04 11.53 KB Hidden from Windows API.
C:\Program Files\Onlasoft\Cache\00003699_436a2250_00000000 03/11/2005 14:44 139.84 KB Hidden from Windows API.
C:\Program Files\Onlasoft\Cache\0000390c_4358f91d_000a4083 21/10/2005 14:20 37.33 KB Hidden from Windows API.
C:\Program Files\Onlasoft\Cache\0000390c_435ca5ee_0006ea05 24/10/2005 09:14 52.02 KB Hidden from Windows API.
C:\Program Files\Onlasoft\Cache\0000390c_435ccb32_0000f424 24/10/2005 11:53 4 bytes Hidden from Windows API.
C:\Program Files\Onlasoft\Cache\0000390c_435e1d9d_000aba95 25/10/2005 11:57 0 bytes Hidden from Windows API.
C:\Program Files\Onlasoft\Cache\0000390c_435e48a8_00003d09 25/10/2005 15:00 384 bytes Hidden from Windows API.
C:\Program Files\Onlasoft\Cache\0000390c_43612e5b_00003d09 27/10/2005 19:45 444.60 KB Hidden from Windows API.
C:\Program Files\Onlasoft\Cache\0000390c_436561c3_0000b71b 31/10/2005 00:13 6.88 KB Hidden from Windows API.
C:\Program Files\Onlasoft\Cache\0000390c_436573b7_00007a12 31/10/2005 01:30 4.27 KB Hidden from Windows API.
C:\Program Files\Onlasoft\Cache\0000390c_4365f59d_0002625a 31/10/2005 10:44 4.20 KB Hidden from Windows API.
C:\Program Files\Onlasoft\Cache\0000390c_43663a89_000e8b25 31/10/2005 15:38 393.06 KB Hidden from Windows API.
C:\Program Files\Onlasoft\Cache\0000390c_4369f5ef_0005f5e1 03/11/2005 11:35 47.43 KB Hidden from Windows API.
C:\Program Files\Onlasoft\Cache\0000390c_436a24dc_0001e848 03/11/2005 14:55 1.08 KB Hidden from Windows API.
C:\Program Files\Onlasoft\Cache\000039b3_43591584_000c28cb 21/10/2005 16:21 1.01 KB Hidden from Windows API.
C:\Program Files\Onlasoft\Cache\000039b3_435bc14f_000501bd 23/10/2005 16:58 2.63 KB Hidden from Windows API.
C:\Program Files\Onlasoft\Cache\000039b3_435ca9f8_000b71b0 24/10/2005 09:31 332 bytes Hidden from Windows API.
C:\Program Files\Onlasoft\Cache\000039b3_435e1dde_00029f63 25/10/2005 11:58 892 bytes Hidden from Windows API.
C:\Program Files\Onlasoft\Cache\000039b3_435e4b39_000c28cb 25/10/2005 15:11 8.65 KB Hidden from Windows API.
C:\Program Files\Onlasoft\Cache\000039b3_43657484_00066ff3 31/10/2005 01:33 3.62 KB Hidden from Windows API.
C:\Program Files\Onlasoft\Cache\000039b3_43665db8_0000f424 31/10/2005 18:08 7.10 KB Hidden from Windows API.
C:\Program Files\Onlasoft\Cache\000039b3_4368b2a7_000b34a7 02/11/2005 12:35 17.48 KB Hidden from Windows API.
C:\Program Files\Onlasoft\Cache\000039b3_4369fe13_000dd40a 03/11/2005 12:09 65.17 KB Hidden from Windows API.
C:\Program Files\Onlasoft\Cache\000039b3_436a259a_000501bd 03/11/2005 14:58 66.25 KB Hidden from Windows API.
C:\Program Files\Onlasoft\Cache\00003a9e_435bd961_00094c5f 23/10/2005 18:41 11.66 KB Hidden from Windows API.
C:\Program Files\Onlasoft\Cache\00003a9e_435cb378_00094c5f 24/10/2005 10:12 45.73 KB Hidden from Windows API.
C:\Program Files\Onlasoft\Cache\00003a9e_436a285c_0007270e 03/11/2005 15:10 5.94 KB Hidden from Windows API.
C:\Program Files\Onlasoft\Cache\00003b25_435935bd_00000000 21/10/2005 18:38 6.10 KB Hidden from Windows API.
C:\Program Files\Onlasoft\Cache\00003b25_435bc1af_0006acfc 23/10/2005 17:00 8.11 KB Hidden from Windows API.
C:\Program Files\Onlasoft\Cache\00003b25_435cab74_00094c5f 24/10/2005 09:37 4.32 KB Hidden from Windows API.
C:\Program Files\Onlasoft\Cache\00003b25_435e1e39_00089544 25/10/2005 11:59 3.66 KB Hidden from Windows API.
C:\Program Files\Onlasoft\Cache\00003b25_435e5110_000cdfe6 25/10/2005 15:36 8.36 KB Hidden from Windows API.
C:\Program Files\Onlasoft\Cache\00003b25_43657f4d_00076417 31/10/2005 02:19 5.67 KB Hidden from Windows API.
C:\Program Files\Onlasoft\Cache\00003b25_4369163b_000c65d4 02/11/2005 19:40 9.54 KB Hidden from Windows API.
C:\Program Files\Onlasoft\Cache\00003b25_4369ff45_0007270e 03/11/2005 12:15 46.36 KB Hidden from Windows API.
C:\Program Files\Onlasoft\Cache\00003b25_436a267f_000c65d4 03/11/2005 15:02 1.43 KB Hidden from Windows API.
C:\Program Files\Onlasoft\Cache\00003bf6_435bd958_000a7d8c 23/10/2005 18:41 15.87 KB Hidden from Windows API.
C:\Program Files\Onlasoft\Cache\00003bf6_436a2859_0007de29 03/11/2005 15:10 65.99 KB Hidden from Windows API.
C:\Program Files\Onlasoft\Cache\00003cd5_435be7a0_000e4e1c 23/10/2005 19:42 7.51 KB Hidden from Windows API.
C:\Program Files\Onlasoft\Cache\00003d6c_4358ecde_0003d090 31/10/2005 12:18 548 bytes Hidden from Windows API.
C:\Program Files\Onlasoft\Cache\00003d6c_4359fffd_000487ab 22/10/2005 09:01 133.31 KB Hidden from Windows API.
C:\Program Files\Onlasoft\Cache\00003d6c_435bb87c_0009c671 02/11/2005 12:05 6.46 KB Hidden from Windows API.
C:\Program Files\Onlasoft\Cache\00003d6c_435ca49e_0007270e 24/10/2005 09:08 30 bytes Hidden from Windows API.
C:\Program Files\Onlasoft\Cache\00003d6c_435cbddf_000d59f8 24/10/2005 10:56 4.11 KB Hidden from Windows API.
C:\Program Files\Onlasoft\Cache\00003d6c_435cc17c_000501bd 25/10/2005 12:44 28.60 KB Hidden from Windows API.
C:\Program Files\Onlasoft\Cache\00003d6c_435cd135_00007a12 02/11/2005 12:15 170 bytes Hidden from Windows API.
C:\Program Files\Onlasoft\Cache\00003d6c_435ce3bf_0005f5e1 24/10/2005 13:38 8.04 KB Hidden from Windows API.
C:\Program Files\Onlasoft\Cache\00003d6c_435e0069_000632ea 03/11/2005 14:56 2.21 KB Hidden from Windows API.
C:\Program Files\Onlasoft\Cache\00003d6c_435e1d3f_00016e36 25/10/2005 11:55 24.26 KB Hidden from Windows API.
C:\Program Files\Onlasoft\Cache\00003d6c_435e2805_000af79e 30/10/2005 13:53 3.52 KB Hidden from Windows API.
C:\Program Files\Onlasoft\Cache\00003d6c_435e318e_00022551 25/10/2005 13:22 10.53 KB Hidden from Windows API.
C:\Program Files\Onlasoft\Cache\00003d6c_435e45f6_00040d99 25/10/2005 14:49 561 bytes Hidden from Windows API.
C:\Program Files\Onlasoft\Cache\00003d6c_435e8928_0007270e 25/10/2005 19:36 8.26 KB Hidden from Windows API.
C:\Program Files\Onlasoft\Cache\00003d6c_435ff738_0005f5e1 31/10/2005 12:21 25.26 KB Hidden from Windows API.
C:\Program Files\Onlasoft\Cache\00003d6c_436008b3_000aba95 26/10/2005 22:53 34.45 KB Hidden from Windows API.
C:\Program Files\Onlasoft\Cache\00003d6c_436358a7_00098968 29/10/2005 11:10 262.13 KB Hidden from Windows API.
C:\Program Files\Onlasoft\Cache\00003d6c_43655a2d_00003d09 30/10/2005 23:41 4.30 KB Hidden from Windows API.
C:\Program Files\Onlasoft\Cache\00003d6c_43655d67_00000000 30/10/2005 23:55 326 bytes Hidden from Windows API.
C:\Program Files\Onlasoft\Cache\00003d6c_43655ea2_000a4083 31/10/2005 00:03 44.83 KB Hidden from Windows API.
C:\Program Files\Onlasoft\Cache\00003d6c_43656e53_000ec82e 31/10/2005 01:07 7.99 KB Hidden from Windows API.
C:\Program Files\Onlasoft\Cache\00003d6c_4365f17b_000d1cef 01/11/2005 00:29 4.27 KB Hidden from Windows API.
C:\Program Files\Onlasoft\Cache\00003d6c_4365f394_000d1cef 31/10/2005 10:36 6.78 KB Hidden from Windows API.
C:\Program Files\Onlasoft\Cache\00003d6c_43667cd3_000d9701 31/10/2005 21:33 33.82 KB Hidden from Windows API.
C:\Program Files\Onlasoft\Cache\00003d6c_4366b6ed_00057bcf 01/11/2005 00:29 3.52 KB Hidden from Windows API.
C:\Program Files\Onlasoft\Cache\00003d6c_4366c5c8_0007de29 01/11/2005 01:32 1.95 KB Hidden from Windows API.
C:\Program Files\Onlasoft\Cache\00003d6c_436935be_000f0537 02/11/2005 21:55 35.15 KB Hidden from Windows API.
C:\Program Files\Onlasoft\Cache\00003d6c_4369f433_000b34a7 03/11/2005 11:27 4.89 KB Hidden from Windows API.
C:\Program Files\Onlasoft\Cache\00003d6c_436a2416_0003567e 03/11/2005 14:52 65.79 KB Hidden from Windows API.
C:\Program Files\Onlasoft\Cache\00003e12_435bd32c_000487ab 23/10/2005 18:15 62.92 KB Hidden from Windows API.
C:\Program Files\Onlasoft\Cache\00003e12_435cb32f_0001ab3f 24/10/2005 10:10 6.86 KB Hidden from Windows API.
C:\Program Files\Onlasoft\Cache\00003e12_436a071c_00098968 03/11/2005 12:48 19.74 KB Hidden from Windows API.
C:\Program Files\Onlasoft\Cache\00003e12_436a282b_0005b8d8 03/11/2005 15:09 1.21 KB Hidden from Windows API.
C:\Program Files\Onlasoft\Cache\00003ef6_435bde00_00039387 23/10/2005 19:01 187.46 KB Hidden from Windows API.
C:\Program Files\Onlasoft\Cache\00003ef6_436a2160_00098968 03/11/2005 14:40 7.69 KB Hidden from Windows API.
C:\Program Files\Onlasoft\Cache\00003ef6_436a95f6_00000000 03/11/2005 22:57 147 bytes Hidden from Windows API.
C:\Program Files\Onlasoft\Cache\00004080_435be7e1_000f0537 23/10/2005 19:43 9.20 KB Hidden from Windows API.
C:\Program Files\Onlasoft\Cache\0000409d_435bde29_0000f424 23/10/2005 19:02 112.75 KB Hidden from Windows API.
C:\Program Files\Onlasoft\Cache\0000409d_436a21e5_00094c5f 03/11/2005 14:42 45.65 KB Hidden from Windows API.
C:\Program Files\Onlasoft\Cache\000041bb_4358f3a9_00057bcf 21/10/2005 13:56 894 bytes Hidden from Windo
  • 0

#23
SP1969

SP1969

    Member

  • Topic Starter
  • Member
  • PipPip
  • 46 posts
see attachments

Steve
  • 0

#24
SP1969

SP1969

    Member

  • Topic Starter
  • Member
  • PipPip
  • 46 posts
CM
I tried to attach the same logs again as I cant see whether they actually attached??
SteveAttached File  RKRlog.txt   106.41KB   1 downloadsAttached File  RKRlog.txt   106.41KB   1 downloads
  • 0

#25
SP1969

SP1969

    Member

  • Topic Starter
  • Member
  • PipPip
  • 46 posts
Attached File  fsbl_20051103234216.txt   453.6KB   1 downloads
  • 0

Advertisements


#26
Wizard

Wizard

    Retired Staff

  • Retired Staff
  • 5,661 posts
As much as I hate to ask,I need to see one other scan log.

A HijackThis Startup List log.


Hijackthis StartUp Log:
Open HijackThis,Select Config(Bottom Right)>>>Select Misc Tools>>> Select Generate StartUpList log and make sure that both Boxes beside it are checked:

Put a check by:
List all minor sections(Full)
and
List Empty Sections(Complete)

It will produce a NotePad Page,I need you to post the entire contents of that page to the next post!
  • 0

#27
SP1969

SP1969

    Member

  • Topic Starter
  • Member
  • PipPip
  • 46 posts
Attached File  startuplist.txt   36.05KB   0 downloads
  • 0

#28
Wizard

Wizard

    Retired Staff

  • Retired Staff
  • 5,661 posts
Just Copy and Paste the HJT Startup log into the next reply,the Attachment didnt work.
  • 0

#29
SP1969

SP1969

    Member

  • Topic Starter
  • Member
  • PipPip
  • 46 posts
Attached File  startuplist.txt   36.05KB   123 downloads
  • 0

#30
Wizard

Wizard

    Retired Staff

  • Retired Staff
  • 5,661 posts
I Pmed you a while ago and then I think we had issues with the forum.

See if my Private Message made it??
  • 0






Similar Topics

0 user(s) are reading this topic

0 members, 0 guests, 0 anonymous users

As Featured On:

Microsoft Yahoo BBC MSN PC Magazine Washington Post HP