OTL log is from this morning, but I have GMER from early this morning/late last night and no changes have been made to system since they were run.
OTL logfile created on: 1/30/2010 12:18:43 PM - Run 1
OTL by OldTimer - Version 3.1.27.1 Folder = C:\Documents and Settings\Rebecca Cooper\Desktop
Windows XP Home Edition Service Pack 3 (Version = 5.1.2600) - Type = NTWorkstation
Internet Explorer (Version = 8.0.6001.18702)
Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy
382.00 Mb Total Physical Memory | 83.00 Mb Available Physical Memory | 22.00% Memory free
920.00 Mb Paging File | 432.00 Mb Available in Paging File | 47.00% Paging File free
Paging file location(s): c:\pagefile.sys 576 1152 [binary data]
%SystemDrive% = C: | %SystemRoot% = C:\WINDOWS | %ProgramFiles% = C:\Program Files
Drive C: | 111.78 Gb Total Space | 90.78 Gb Free Space | 81.21% Space Free | Partition Type: NTFS
D: Drive not present or media not loaded
E: Drive not present or media not loaded
F: Drive not present or media not loaded
G: Drive not present or media not loaded
H: Drive not present or media not loaded
I: Drive not present or media not loaded
Computer Name: RCOOPER
Current User Name: Rebecca Cooper
Logged in as Administrator.
Current Boot Mode: Normal
Scan Mode: Current user
Company Name Whitelist: On
Skip Microsoft Files: On
File Age = 14 Days
Output = Standard
Quick Scan
========== Processes (SafeList) ==========
PRC - [2010/01/30 12:15:37 | 000,548,864 | ---- | M] (OldTimer Tools) -- C:\Documents and Settings\Rebecca Cooper\Desktop\OTL.exe
PRC - [2010/01/06 18:46:07 | 000,908,248 | ---- | M] (Mozilla Corporation) -- C:\Program Files\Mozilla Firefox\firefox.exe
PRC - [2009/07/25 04:23:10 | 000,153,376 | ---- | M] (Sun Microsystems, Inc.) -- C:\Program Files\Java\jre6\bin\jqs.exe
PRC - [2009/07/21 13:34:33 | 000,185,089 | ---- | M] (Avira GmbH) -- C:\Program Files\Avira\AntiVir Desktop\avguard.exe
PRC - [2009/05/13 15:48:22 | 000,108,289 | ---- | M] (Avira GmbH) -- C:\Program Files\Avira\AntiVir Desktop\sched.exe
PRC - [2009/03/08 13:09:26 | 000,638,816 | ---- | M] (Microsoft Corporation) -- C:\Program Files\Internet Explorer\iexplore.exe
PRC - [2009/03/02 12:08:47 | 000,209,153 | ---- | M] (Avira GmbH) -- C:\Program Files\Avira\AntiVir Desktop\avgnt.exe
PRC - [2009/02/06 16:07:48 | 000,027,512 | ---- | M] (Microsoft Corporation) -- C:\Program Files\Windows Live\Contacts\wlcomm.exe
PRC - [2008/11/07 15:40:52 | 017,421,824 | ---- | M] (Realtek Semiconductor Corp.) -- C:\WINDOWS\RTHDCPL.EXE
PRC - [2008/04/13 19:12:19 | 001,033,728 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\explorer.exe
PRC - [2004/08/04 07:00:00 | 000,008,192 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\system32\cidaemon.exe
========== Modules (SafeList) ==========
MOD - [2010/01/30 12:15:37 | 000,548,864 | ---- | M] (OldTimer Tools) -- C:\Documents and Settings\Rebecca Cooper\Desktop\OTL.exe
MOD - [2008/04/13 19:12:08 | 000,149,504 | ---- | M] () -- C:\WINDOWS\ureconisixe.dll
========== Win32 Services (SafeList) ==========
SRV - [2009/07/25 04:23:10 | 000,153,376 | ---- | M] (Sun Microsystems, Inc.) [Auto | Running] -- C:\Program Files\Java\jre6\bin\jqs.exe -- (JavaQuickStarterService)
SRV - [2009/07/21 13:34:33 | 000,185,089 | ---- | M] (Avira GmbH) [Auto | Running] -- C:\Program Files\Avira\AntiVir Desktop\avguard.exe -- (AntiVirService)
SRV - [2009/07/16 18:16:44 | 000,250,616 | ---- | M] (WildTangent, Inc.) [On_Demand | Stopped] -- C:\Program Files\WildGames\Game Console - WildGames\GameConsoleService.exe -- (GameConsoleService)
SRV - [2009/05/13 15:48:22 | 000,108,289 | ---- | M] (Avira GmbH) [Auto | Running] -- C:\Program Files\Avira\AntiVir Desktop\sched.exe -- (AntiVirSchedulerService)
========== Standard Registry (SafeList) ==========
========== Internet Explorer ==========
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Search Page = http://www.google.com
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://www.google.com/
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
========== FireFox ==========
FF - prefs.js..browser.startup.homepage: "http://www.google.com/"
FF - prefs.js..extensions.enabledItems: [email protected]:1.0
FF - prefs.js..extensions.enabledItems: {CE436162-C178-4635-BFA4-F00E8FBFEF6C}:1.9.1
FF - HKLM\software\mozilla\Firefox\Extensions\\{CE436162-C178-4635-BFA4-F00E8FBFEF6C}: C:\Documents and Settings\Rebecca Cooper\Local Settings\Application Data\{CE436162-C178-4635-BFA4-F00E8FBFEF6C} [2010/01/29 18:26:44 | 000,000,000 | ---D | M]
FF - HKLM\software\mozilla\Mozilla Firefox 3.5.7\extensions\\Components: C:\Program Files\Mozilla Firefox\components [2010/01/06 18:46:18 | 000,000,000 | ---D | M]
FF - HKLM\software\mozilla\Mozilla Firefox 3.5.7\extensions\\Plugins: C:\Program Files\Mozilla Firefox\plugins [2010/01/29 18:39:56 | 000,000,000 | ---D | M]
[2009/06/28 23:33:40 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Rebecca Cooper\Application Data\Mozilla\Extensions
[2010/01/29 20:28:22 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Rebecca Cooper\Application Data\Mozilla\Firefox\Profiles\im81q534.default\extensions
[2010/01/29 20:28:22 | 000,000,000 | ---D | M] -- C:\Program Files\Mozilla Firefox\extensions
[2009/07/01 23:21:55 | 000,239,432 | ---- | M] (Pando Networks) -- C:\Program Files\Mozilla Firefox\plugins\npPandoWebInst.dll
O1 HOSTS File: ([2004/08/04 07:00:00 | 000,000,734 | ---- | M]) - C:\WINDOWS\system32\drivers\etc\hosts
O1 - Hosts: 127.0.0.1 localhost
O2 - BHO: (Java Plug-In 2 SSV Helper) - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll (Sun Microsystems, Inc.)
O2 - BHO: (JQSIEStartDetectorImpl Class) - {E7E6F031-17CE-4C07-BC86-EABFE594F69C} - C:\Program Files\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll (Sun Microsystems, Inc.)
O3 - HKLM\..\Toolbar: (no name) - Locked - No CLSID value found.
O3 - HKLM\..\Toolbar: (no name) - SITEguard - No CLSID value found.
O3 - HKCU\..\Toolbar\WebBrowser: (no name) - {472734EA-242A-422B-ADF8-83D1E48CC825} - No CLSID value found.
O4 - HKLM..\Run: [Adobe ARM] C:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe (Adobe Systems Incorporated)
O4 - HKLM..\Run: [Adobe Reader Speed Launcher] C:\Program Files\Adobe\Reader 9.0\Reader\Reader_sl.exe (Adobe Systems Incorporated)
O4 - HKLM..\Run: [Alcmtr] C:\WINDOWS\ALCMTR.EXE (Realtek Semiconductor Corp.)
O4 - HKLM..\Run: [avgnt] C:\Program Files\Avira\AntiVir Desktop\avgnt.exe (Avira GmbH)
O4 - HKLM..\Run: [KernelFaultCheck] File not found
O4 - HKLM..\Run: [RTHDCPL] C:\WINDOWS\RTHDCPL.EXE (Realtek Semiconductor Corp.)
O4 - HKLM..\Run: [SunJavaUpdateSched] C:\Program Files\Java\jre6\bin\jusched.exe (Sun Microsystems, Inc.)
O4 - HKLM..\Run: [Tnadecaguh] C:\WINDOWS\ureconisixe.DLL ()
O4 - HKCU..\Run: [F5JMWNZTHI] C:\DOCUME~1\REBECC~1\LOCALS~1\Temp\Njg.exe File not found
O6 - HKLM\Software\Policies\Microsoft\Internet Explorer\control panel present
O6 - HKLM\Software\Policies\Microsoft\Internet Explorer\Main present
O6 - HKLM\Software\Policies\Microsoft\Internet Explorer\restrictions present
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: HonorAutoRunSetting = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: EnableLUA = 0
O7 - HKCU\Software\Policies\Microsoft\Internet Explorer\control panel present
O7 - HKCU\Software\Policies\Microsoft\Internet Explorer\restrictions present
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145
O15 - HKCU\..Trusted Domains: 5 domain(s) and sub-domain(s) not assigned to a zone.
O16 - DPF: {055B4212-4C81-448E-AFA9-C3CA4AAE8F95} http://games.bigfish...eb.1.0.0.15.cab (CPlayFirstDairyDashWControl Object)
O16 - DPF: {195B4BBF-E1E4-4020-9773-0A8C6F65EA35} http://games.bigfish...Web.1.0.0.9.cab (CPlayFirstCookingDasControl Object)
O16 - DPF: {1CDFA4E8-3396-439D-8C9D-AD0E32DE94B6} http://www.arcadetow...net.1.0.0.4.cab (CPlayFirsttastyplanetControl Object)
O16 - DPF: {8100D56A-5661-482C-BEE8-AFECE305D968} http://upload.facebo...oUploader55.cab (Facebook Photo Uploader 5 Control)
O16 - DPF: {8ADC4409-4FBF-4224-B73F-2392C721BCB4} http://games.bigfish...amesControl.cab (GenimoWebGames Control)
O16 - DPF: {B516CA4E-A5BA-405C-AFCF-A97F08CC7429} http://games.bigfish...esPlayer_v4.cab (GoBit Games Player)
O16 - DPF: {E2883E8F-472F-4FB0-9522-AC9BF37916A7} http://platformdl.ad...Plus/1.6/gp.cab (Reg Error: Key error.)
O16 - DPF: {E9B80D94-D8BC-43DE-9138-75605A8D9666} http://zone.msn.com/...sh.1.0.0.50.cab (CPlayFirstWeddingDasControl Object)
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 192.168.2.1
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: NameServer = 93.188.162.14,93.188.166.53
O20 - AppInit_DLLs: (C:\WINDOWS\system32\kbdsock.dll c:\windows\system32\zomejuhe.dll) - C:\WINDOWS\System32\kbdsock.dll File not found
O20 - AppInit_DLLs: (tuvikize.dll) - File not found
O20 - HKLM Winlogon: Shell - (Explorer.exe) - C:\WINDOWS\explorer.exe (Microsoft Corporation)
O21 - SSODL: sumonapuj - {fd133537-5e84-4609-b87c-f7eb084b7b27} - C:\WINDOWS\System32\zomejuhe.dll File not found
O22 - SharedTaskScheduler: {fd133537-5e84-4609-b87c-f7eb084b7b27} - kupuhivus - C:\WINDOWS\System32\zomejuhe.dll File not found
O24 - Desktop WallPaper: C:\Documents and Settings\Rebecca Cooper\Desktop\Internet Explorer Wallpaper.bmp
O24 - Desktop BackupWallPaper: C:\Documents and Settings\Rebecca Cooper\Desktop\Internet Explorer Wallpaper.bmp
O32 - HKLM CDRom: AutoRun - 1
O32 - AutoRun File - [2009/03/29 22:13:24 | 000,000,000 | ---- | M] () - C:\AUTOEXEC.BAT -- [ NTFS ]
O34 - HKLM BootExecute: (autocheck autochk *) - File not found
O35 - comfile [open] -- "%1" %*
O35 - exefile [open] -- "%1" %*
NetSvcs: 6to4 - File not found
NetSvcs: Ias - C:\WINDOWS\system32\ias [2010/01/01 22:43:39 | 000,000,000 | ---D | M]
NetSvcs: Iprip - File not found
NetSvcs: Irmon - File not found
NetSvcs: NWCWorkstation - File not found
NetSvcs: Nwsapagent - File not found
NetSvcs: Wmi - C:\WINDOWS\system32\wmi.dll (Microsoft Corporation)
NetSvcs: WmdmPmSp - File not found
CREATERESTOREPOINT
Restore point Set: OTL Restore Point (16891891626803200)
========== Files/Folders - Created Within 14 Days ==========
[2010/01/30 12:15:34 | 000,548,864 | ---- | C] (OldTimer Tools) -- C:\Documents and Settings\Rebecca Cooper\Desktop\OTL.exe
[2010/01/29 22:01:23 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Rebecca Cooper\Desktop\gmer
[2010/01/29 19:37:03 | 000,439,808 | ---- | C] (OldTimer Tools) -- C:\Documents and Settings\Rebecca Cooper\Desktop\TFC.exe
[2010/01/29 18:26:44 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Rebecca Cooper\Local Settings\Application Data\{CE436162-C178-4635-BFA4-F00E8FBFEF6C}
[2010/01/26 18:12:18 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Rebecca Cooper\Local Settings\Application Data\Yahoo!
[2010/01/22 14:47:27 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Rebecca Cooper\Desktop\irishTexting
[2010/01/21 18:05:19 | 000,000,000 | ---D | C] -- C:\Program Files\Avenue Flo
[2009/03/29 22:36:34 | 000,000,000 | --SD | M] -- C:\Documents and Settings\NetworkService\Application Data\Microsoft
[2009/03/29 22:36:34 | 000,000,000 | --SD | M] -- C:\Documents and Settings\LocalService\Application Data\Microsoft
[2009/03/29 22:36:34 | 000,000,000 | ---D | M] -- C:\Documents and Settings\LocalService\Local Settings\Application Data\Microsoft
[2009/03/29 22:36:33 | 000,000,000 | ---D | M] -- C:\Documents and Settings\NetworkService\Local Settings\Application Data\Microsoft
[2007/06/01 04:37:48 | 000,774,144 | ---- | C] (RealNetworks, Inc.) -- C:\Program Files\RngInterstitial.dll
========== Files - Modified Within 14 Days ==========
[2010/01/30 12:15:37 | 000,548,864 | ---- | M] (OldTimer Tools) -- C:\Documents and Settings\Rebecca Cooper\Desktop\OTL.exe
[2010/01/30 11:39:46 | 000,000,120 | ---- | M] () -- C:\WINDOWS\Tlasac.dat
[2010/01/30 02:00:01 | 000,000,312 | ---- | M] () -- C:\WINDOWS\tasks\cjtermla.job
[2010/01/30 01:36:25 | 000,000,000 | ---- | M] () -- C:\WINDOWS\Jcufivolupufax.bin
[2010/01/30 01:35:42 | 000,013,740 | ---- | M] () -- C:\WINDOWS\System32\wpa.dbl
[2010/01/30 01:35:41 | 000,000,006 | -H-- | M] () -- C:\WINDOWS\tasks\SA.DAT
[2010/01/30 01:35:38 | 000,002,048 | --S- | M] () -- C:\WINDOWS\bootstat.dat
[2010/01/30 01:35:37 | 401,068,032 | -HS- | M] () -- C:\hiberfil.sys
[2010/01/30 00:22:49 | 000,008,468 | ---- | M] () -- C:\Documents and Settings\Rebecca Cooper\Desktop\mbam-log-2010-01-29 (19-57-10).zip
[2010/01/29 22:01:05 | 000,002,610 | ---- | M] () -- C:\Documents and Settings\Rebecca Cooper\Desktop\Attach.zip
[2010/01/29 21:59:16 | 000,524,288 | ---- | M] () -- C:\Documents and Settings\Rebecca Cooper\Desktop\dds.scr
[2010/01/29 21:53:38 | 000,000,000 | ---- | M] () -- C:\Documents and Settings\Rebecca Cooper\defogger_reenable
[2010/01/29 21:52:49 | 000,050,477 | ---- | M] () -- C:\Documents and Settings\Rebecca Cooper\Desktop\Defogger.exe
[2010/01/29 20:25:25 | 000,000,440 | -H-- | M] () -- C:\WINDOWS\tasks\User_Feed_Synchronization-{EC79BCE9-184A-4DA4-9F19-ABE785C004AC}.job
[2010/01/29 20:13:00 | 401,096,704 | ---- | M] () -- C:\WINDOWS\MEMORY.DMP
[2010/01/29 19:58:27 | 000,284,915 | ---- | M] () -- C:\Documents and Settings\Rebecca Cooper\Desktop\gmer.zip
[2010/01/29 19:46:08 | 002,621,440 | ---- | M] () -- C:\Documents and Settings\Rebecca Cooper\ntuser.dat
[2010/01/29 19:46:08 | 000,000,178 | -HS- | M] () -- C:\Documents and Settings\Rebecca Cooper\ntuser.ini
[2010/01/29 19:37:04 | 000,439,808 | ---- | M] (OldTimer Tools) -- C:\Documents and Settings\Rebecca Cooper\Desktop\TFC.exe
[2010/01/25 21:51:19 | 000,001,374 | ---- | M] () -- C:\WINDOWS\imsins.BAK
[2010/01/25 21:51:03 | 000,023,392 | ---- | M] () -- C:\WINDOWS\System32\nscompat.tlb
[2010/01/25 21:51:03 | 000,016,832 | ---- | M] () -- C:\WINDOWS\System32\amcompat.tlb
[2010/01/25 21:49:52 | 000,316,640 | ---- | M] () -- C:\WINDOWS\WMSysPr9.prx
[2010/01/23 20:13:13 | 000,000,008 | ---- | M] () -- C:\Documents and Settings\All Users.WINDOWS\Application Data\sysReserve.ini
[2010/01/21 18:05:54 | 000,001,572 | ---- | M] () -- C:\Documents and Settings\All Users.WINDOWS\Desktop\Play Avenue Flo.lnk
[2010/01/21 18:02:45 | 000,001,578 | ---- | M] () -- C:\Documents and Settings\All Users.WINDOWS\Desktop\Game Manager.lnk
[2010/01/19 23:58:06 | 000,001,255 | ---- | M] () -- C:\Documents and Settings\Rebecca Cooper\Desktop\JonaieResume.rtf
========== Files Created - No Company Name ==========
[2010/01/30 00:22:49 | 000,008,468 | ---- | C] () -- C:\Documents and Settings\Rebecca Cooper\Desktop\mbam-log-2010-01-29 (19-57-10).zip
[2010/01/29 22:01:05 | 000,002,610 | ---- | C] () -- C:\Documents and Settings\Rebecca Cooper\Desktop\Attach.zip
[2010/01/29 21:59:14 | 000,524,288 | ---- | C] () -- C:\Documents and Settings\Rebecca Cooper\Desktop\dds.scr
[2010/01/29 21:53:38 | 000,000,000 | ---- | C] () -- C:\Documents and Settings\Rebecca Cooper\defogger_reenable
[2010/01/29 21:52:48 | 000,050,477 | ---- | C] () -- C:\Documents and Settings\Rebecca Cooper\Desktop\Defogger.exe
[2010/01/29 20:25:25 | 000,000,440 | -H-- | C] () -- C:\WINDOWS\tasks\User_Feed_Synchronization-{EC79BCE9-184A-4DA4-9F19-ABE785C004AC}.job
[2010/01/29 19:58:25 | 000,284,915 | ---- | C] () -- C:\Documents and Settings\Rebecca Cooper\Desktop\gmer.zip
[2010/01/29 18:26:47 | 000,000,000 | ---- | C] () -- C:\WINDOWS\Jcufivolupufax.bin
[2010/01/29 18:26:46 | 000,000,120 | ---- | C] () -- C:\WINDOWS\Tlasac.dat
[2010/01/23 20:13:13 | 000,000,008 | ---- | C] () -- C:\Documents and Settings\All Users.WINDOWS\Application Data\sysReserve.ini
[2010/01/21 18:05:54 | 000,001,572 | ---- | C] () -- C:\Documents and Settings\All Users.WINDOWS\Desktop\Play Avenue Flo.lnk
[2010/01/21 18:02:45 | 000,001,578 | ---- | C] () -- C:\Documents and Settings\All Users.WINDOWS\Desktop\Game Manager.lnk
[2010/01/19 23:58:06 | 000,001,255 | ---- | C] () -- C:\Documents and Settings\Rebecca Cooper\Desktop\JonaieResume.rtf
[2009/12/27 20:37:36 | 000,000,024 | ---- | C] () -- C:\WINDOWS\wivrs.ini
[2009/11/04 13:05:52 | 000,000,022 | ---- | C] () -- C:\WINDOWS\iexplore.ini
[2009/03/30 01:20:32 | 000,012,288 | ---- | C] () -- C:\Documents and Settings\Rebecca Cooper\Local Settings\Application Data\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2007/05/15 06:43:50 | 000,013,765 | ---- | C] () -- C:\WINDOWS\System32\drivers\UCharger.sys
[2006/11/02 08:27:46 | 000,000,518 | ---- | C] () -- C:\WINDOWS\System32\SP207.ini
[2004/09/01 10:49:17 | 003,375,104 | ---- | C] () -- C:\WINDOWS\System32\qt-mt331.dll
[2004/08/04 07:00:00 | 000,149,504 | ---- | C] () -- C:\WINDOWS\ureconisixe.dll
[2002/10/06 13:42:57 | 000,237,568 | ---- | C] () -- C:\WINDOWS\System32\OggDS.dll
[2002/10/04 18:04:25 | 000,921,600 | ---- | C] () -- C:\WINDOWS\System32\vorbisenc.dll
[2002/10/04 18:04:24 | 000,188,416 | ---- | C] () -- C:\WINDOWS\System32\vorbis.dll
[2002/10/04 18:04:17 | 000,045,056 | ---- | C] () -- C:\WINDOWS\System32\ogg.dll
========== LOP Check ==========
[2009/04/08 22:09:03 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users.WINDOWS\Application Data\Aveyond I
[2009/04/09 08:16:19 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users.WINDOWS\Application Data\Azureus
[2009/08/08 20:22:27 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users.WINDOWS\Application Data\CasualForge
[2009/06/08 01:31:29 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users.WINDOWS\Application Data\CaveDays
[2009/09/13 21:04:27 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users.WINDOWS\Application Data\EscapeFromParadise2
[2009/06/21 09:32:48 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users.WINDOWS\Application Data\EscapeTheMuseum
[2009/06/21 23:48:30 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users.WINDOWS\Application Data\FreshGames
[2009/06/03 23:08:02 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users.WINDOWS\Application Data\Fugazo
[2009/08/18 22:42:34 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users.WINDOWS\Application Data\GameHouse
[2010/01/11 09:20:09 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users.WINDOWS\Application Data\Genimo
[2010/01/20 03:37:06 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users.WINDOWS\Application Data\GoBit Games
[2009/06/21 00:15:34 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users.WINDOWS\Application Data\Gogii
[2009/04/20 22:51:04 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users.WINDOWS\Application Data\HiddenSecretsNightmare
[2010/01/11 22:33:29 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users.WINDOWS\Application Data\Hot Lava Games
[2009/06/10 15:26:04 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users.WINDOWS\Application Data\InterAction studios
[2009/05/31 22:01:02 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users.WINDOWS\Application Data\iWin
[2009/05/31 17:10:40 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users.WINDOWS\Application Data\iWin Games
[2009/06/08 14:24:38 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users.WINDOWS\Application Data\Ludia
[2009/04/11 17:27:37 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users.WINDOWS\Application Data\Mandragora
[2009/06/06 11:04:39 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users.WINDOWS\Application Data\Mean Hamster
[2009/11/04 13:05:09 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users.WINDOWS\Application Data\MumboJumbo
[2009/06/17 19:14:23 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users.WINDOWS\Application Data\MysteryChronicles
[2009/06/10 22:58:23 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users.WINDOWS\Application Data\MythPeople
[2009/10/19 20:36:03 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users.WINDOWS\Application Data\Namco
[2009/06/09 22:54:47 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users.WINDOWS\Application Data\NevoSoft Games
[2009/11/29 00:53:47 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users.WINDOWS\Application Data\PlayFirst
[2009/07/01 23:22:38 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users.WINDOWS\Application Data\PMB Files
[2009/04/11 17:36:40 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users.WINDOWS\Application Data\Questtracers
[2009/11/22 22:03:45 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users.WINDOWS\Application Data\Sandlot Games
[2009/12/30 02:11:22 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users.WINDOWS\Application Data\SITEguard
[2009/08/18 13:37:30 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users.WINDOWS\Application Data\SpecialBit
[2010/01/24 13:03:18 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users.WINDOWS\Application Data\TEMP
[2009/07/28 00:29:33 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users.WINDOWS\Application Data\VirtualFarm
[2009/04/24 07:43:52 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users.WINDOWS\Application Data\WildTangent
[2009/05/31 19:30:20 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users.WINDOWS\Application Data\WildWestQuest2
[2009/04/05 19:45:34 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Rebecca Cooper\Application Data\Aveyond II
[2009/12/28 11:46:19 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Rebecca Cooper\Application Data\Azureus
[2009/06/06 12:49:15 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Rebecca Cooper\Application Data\Balloon Express
[2009/06/21 01:39:45 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Rebecca Cooper\Application Data\BeachPartyCraze
[2009/12/18 10:17:10 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Rebecca Cooper\Application Data\Big Fish Games
[2009/08/08 20:22:27 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Rebecca Cooper\Application Data\CasualForge
[2009/06/05 23:52:12 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Rebecca Cooper\Application Data\CupcakeCafe
[2009/06/10 20:26:31 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Rebecca Cooper\Application Data\EleFun Games
[2009/04/10 07:39:18 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Rebecca Cooper\Application Data\FrimaStudio
[2009/11/24 23:20:14 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Rebecca Cooper\Application Data\Gaijin Ent
[2009/04/08 22:22:08 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Rebecca Cooper\Application Data\Gamelab
[2009/12/30 02:51:46 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Rebecca Cooper\Application Data\GetRightToGo
[2009/06/09 00:30:34 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Rebecca Cooper\Application Data\Home Sweet Home
[2009/06/10 00:59:42 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Rebecca Cooper\Application Data\Home Sweet Home 2
[2009/04/11 08:53:15 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Rebecca Cooper\Application Data\ITTNord
[2009/07/28 16:47:16 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Rebecca Cooper\Application Data\iWin
[2009/06/08 14:24:38 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Rebecca Cooper\Application Data\Ludia
[2009/10/09 22:56:26 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Rebecca Cooper\Application Data\Magic Seeds
[2009/04/11 17:31:48 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Rebecca Cooper\Application Data\Magus
[2009/06/06 11:04:39 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Rebecca Cooper\Application Data\Mean Hamster
[2009/06/11 18:44:42 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Rebecca Cooper\Application Data\Meridian93
[2009/10/19 20:36:03 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Rebecca Cooper\Application Data\Namco
[2009/03/31 11:19:31 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Rebecca Cooper\Application Data\Nexon
[2009/11/22 23:47:25 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Rebecca Cooper\Application Data\Peace Craft
[2009/11/29 00:53:47 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Rebecca Cooper\Application Data\PlayFirst
[2009/04/05 21:56:56 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Rebecca Cooper\Application Data\ScreenSeven
[2009/06/10 16:36:38 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Rebecca Cooper\Application Data\Shape games
[2009/04/25 16:30:24 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Rebecca Cooper\Application Data\SpinTop
[2009/06/08 11:42:37 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Rebecca Cooper\Application Data\SulusGames
[2009/06/11 20:40:33 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Rebecca Cooper\Application Data\Super-Cow
[2009/06/09 17:51:00 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Rebecca Cooper\Application Data\Teggo
[2009/06/11 21:32:17 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Rebecca Cooper\Application Data\Turtle Odyssey II
[2009/04/10 11:17:52 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Rebecca Cooper\Application Data\Ubisoft
[2009/06/18 01:35:45 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Rebecca Cooper\Application Data\ViquaSoft
[2009/04/24 07:42:35 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Rebecca Cooper\Application Data\WildTangent
[2009/06/08 13:59:54 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Rebecca Cooper\Application Data\World-LooM
[2009/07/11 22:34:19 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Rebecca Cooper\Application Data\YoudaGames
[2010/01/30 02:00:01 | 000,000,312 | ---- | M] () -- C:\WINDOWS\Tasks\cjtermla.job
[2010/01/29 20:25:25 | 000,000,440 | -H-- | M] () -- C:\WINDOWS\Tasks\User_Feed_Synchronization-{EC79BCE9-184A-4DA4-9F19-ABE785C004AC}.job
========== Purity Check ==========
========== Custom Scans ==========
< %SYSTEMDRIVE%\*.exe >
< MD5 for: AGP440.SYS >
[2004/08/04 07:00:00 | 018,738,937 | ---- | M] () .cab file -- C:\WINDOWS\Driver Cache\i386\sp2.cab:AGP440.sys
[2010/01/07 09:34:19 | 023,852,652 | ---- | M] () .cab file -- C:\WINDOWS\Driver Cache\i386\sp3.cab:AGP440.sys
[2010/01/07 09:34:19 | 023,852,652 | ---- | M] () .cab file -- C:\WINDOWS\ServicePackFiles\i386\sp3.cab:AGP440.sys
[2008/04/13 13:36:38 | 000,042,368 | ---- | M] (Microsoft Corporation) MD5=08FD04AA961BDC77FB983F328334E3D7 -- C:\WINDOWS\ServicePackFiles\i386\agp440.sys
[2008/04/13 13:36:38 | 000,042,368 | ---- | M] (Microsoft Corporation) MD5=08FD04AA961BDC77FB983F328334E3D7 -- C:\WINDOWS\system32\drivers\agp440.sys
< MD5 for: ATAPI.SYS >
[2004/08/04 07:00:00 | 018,738,937 | ---- | M] () .cab file -- C:\WINDOWS\Driver Cache\i386\sp2.cab:atapi.sys
[2010/01/07 09:34:19 | 023,852,652 | ---- | M] () .cab file -- C:\WINDOWS\Driver Cache\i386\sp3.cab:atapi.sys
[2010/01/07 09:34:19 | 023,852,652 | ---- | M] () .cab file -- C:\WINDOWS\ServicePackFiles\i386\sp3.cab:atapi.sys
[2008/04/13 13:40:30 | 000,096,512 | ---- | M] (Microsoft Corporation) MD5=9F3A2F5AA6875C72BF062C712CFA2674 -- C:\WINDOWS\ServicePackFiles\i386\atapi.sys
[2004/08/04 07:00:00 | 000,095,360 | ---- | M] (Microsoft Corporation) MD5=CDFE4411A69C224BD1D11B2DA92DAC51 -- C:\WINDOWS\$NtServicePackUninstall$\atapi.sys
[2008/04/13 13:40:30 | 000,096,512 | ---- | M] (Microsoft Corporation) Unable to obtain MD5 -- C:\WINDOWS\system32\drivers\atapi.sys
< MD5 for: EVENTLOG.DLL >
[2008/04/13 19:11:53 | 000,056,320 | ---- | M] (Microsoft Corporation) MD5=6D4FEB43EE538FC5428CC7F0565AA656 -- C:\WINDOWS\ServicePackFiles\i386\eventlog.dll
[2008/04/13 19:11:53 | 000,056,320 | ---- | M] (Microsoft Corporation) MD5=6D4FEB43EE538FC5428CC7F0565AA656 -- C:\WINDOWS\system32\eventlog.dll
[2004/08/04 07:00:00 | 000,055,808 | ---- | M] (Microsoft Corporation) MD5=82B24CB70E5944E6E34662205A2A5B78 -- C:\WINDOWS\$NtServicePackUninstall$\eventlog.dll
< MD5 for: NETLOGON.DLL >
[2008/04/13 19:12:01 | 000,407,040 | ---- | M] (Microsoft Corporation) MD5=1B7F071C51B77C272875C3A23E1E4550 -- C:\WINDOWS\ServicePackFiles\i386\netlogon.dll
[2008/04/13 19:12:01 | 000,407,040 | ---- | M] (Microsoft Corporation) MD5=1B7F071C51B77C272875C3A23E1E4550 -- C:\WINDOWS\system32\netlogon.dll
[2009/02/06 13:46:09 | 000,408,064 | ---- | M] (Microsoft Corporation) MD5=6C476D33D82F1054849790181E8F7772 -- C:\WINDOWS\$hf_mig$\KB968389\SP2QFE\netlogon.dll
[2009/02/06 13:46:09 | 000,408,064 | ---- | M] (Microsoft Corporation) MD5=6C476D33D82F1054849790181E8F7772 -- C:\WINDOWS\$hf_mig$\KB975467\SP2QFE\netlogon.dll
[2004/08/04 07:00:00 | 000,407,040 | ---- | M] (Microsoft Corporation) MD5=96353FCECBA774BB8DA74A1C6507015A -- C:\WINDOWS\$NtServicePackUninstall$\netlogon.dll
< MD5 for: SCECLI.DLL >
[2004/08/04 07:00:00 | 000,180,224 | ---- | M] (Microsoft Corporation) MD5=0F78E27F563F2AAF74B91A49E2ABF19A -- C:\WINDOWS\$NtServicePackUninstall$\scecli.dll
[2008/04/13 19:12:05 | 000,181,248 | ---- | M] (Microsoft Corporation) MD5=A86BB5E61BF3E39B62AB4C7E7085A084 -- C:\WINDOWS\ServicePackFiles\i386\scecli.dll
[2008/04/13 19:12:05 | 000,181,248 | ---- | M] (Microsoft Corporation) MD5=A86BB5E61BF3E39B62AB4C7E7085A084 -- C:\WINDOWS\system32\scecli.dll
< MD5 for: VIAMRAID.SYS >
[2007/07/17 12:35:20 | 000,114,944 | ---- | M] (VIA Technologies inc,.ltd) MD5=1B7B0954AF54E716F697C511D68C150E -- C:\Documents and Settings\Administrator\Desktop\Winxp\RAID\drvdisk\x86\NT5\viamraid.sys
[2007/07/17 12:35:20 | 000,114,944 | ---- | M] (VIA Technologies inc,.ltd) MD5=1B7B0954AF54E716F697C511D68C150E -- C:\Documents and Settings\Administrator\Desktop\Winxp\VIA_HyperionPro_V514A\VRAIDDrv\2K\viamraid.sys
[2007/07/17 12:35:20 | 000,114,944 | ---- | M] (VIA Technologies inc,.ltd) MD5=1B7B0954AF54E716F697C511D68C150E -- C:\Documents and Settings\Administrator\Desktop\Winxp\VIA_HyperionPro_V514A\VRAIDDrv\drvdisk\x86\NT5\viamraid.sys
[2007/07/17 12:35:20 | 000,114,944 | ---- | M] (VIA Technologies inc,.ltd) MD5=1B7B0954AF54E716F697C511D68C150E -- C:\Documents and Settings\Administrator\Desktop\Winxp\VIA_HyperionPro_V514A\VRAIDDrv\SRV2003\x86\viamraid.sys
[2007/07/17 12:35:20 | 000,114,944 | ---- | M] (VIA Technologies inc,.ltd) MD5=1B7B0954AF54E716F697C511D68C150E -- C:\Documents and Settings\Administrator\Desktop\Winxp\VIA_HyperionPro_V514A\VRAIDDrv\XP\x86\viamraid.sys
[2007/07/12 18:35:36 | 000,118,184 | ---- | M] (VIA Technologies inc,.ltd) MD5=7352A2B1CA928AD8A95F75A1D868A0B5 -- C:\Documents and Settings\Administrator\Desktop\Winxp\RAID\drvdisk\x86\NT4\viamraid.sys
[2007/07/12 18:35:36 | 000,118,184 | ---- | M] (VIA Technologies inc,.ltd) MD5=7352A2B1CA928AD8A95F75A1D868A0B5 -- C:\Documents and Settings\Administrator\Desktop\Winxp\VIA_HyperionPro_V514A\VRAIDDrv\drvdisk\x86\NT4\viamraid.sys
[2007/07/12 18:35:36 | 000,118,184 | ---- | M] (VIA Technologies inc,.ltd) MD5=7352A2B1CA928AD8A95F75A1D868A0B5 -- C:\Documents and Settings\Administrator\Desktop\Winxp\VIA_HyperionPro_V514A\VRAIDDrv\NT4\viamraid.sys
[2007/07/13 13:05:28 | 000,120,832 | ---- | M] (VIA Technologies Inc.,Ltd) MD5=9E897F955AB8F912E4C1C9ADAF35762C -- C:\Documents and Settings\Administrator\Desktop\Winxp\RAID\drvdisk\VISTA\x86\viamraid.sys
[2007/07/13 13:05:28 | 000,120,832 | ---- | M] (VIA Technologies Inc.,Ltd) MD5=9E897F955AB8F912E4C1C9ADAF35762C -- C:\Documents and Settings\Administrator\Desktop\Winxp\VIA_HyperionPro_V514A\VRAIDDrv\drvdisk\VISTA\x86\viamraid.sys
[2007/07/13 13:05:28 | 000,120,832 | ---- | M] (VIA Technologies Inc.,Ltd) MD5=9E897F955AB8F912E4C1C9ADAF35762C -- C:\Documents and Settings\Administrator\Desktop\Winxp\VIA_HyperionPro_V514A\VRAIDDrv\VISTA\x86\viamraid.sys
< MD5 for: VIPRT.SYS >
[2007/10/18 17:28:52 | 000,052,224 | ---- | M] (VIA Technologies, Inc.) MD5=020EB647FEA9187541827231CB236DCE -- C:\Documents and Settings\Administrator\Desktop\Winxp\VIA_HyperionPro_V514A\SATAIDE\SRV2003\ViPrt.sys
[2007/10/18 17:28:52 | 000,052,224 | ---- | M] (VIA Technologies, Inc.) MD5=020EB647FEA9187541827231CB236DCE -- C:\Documents and Settings\Administrator\Desktop\Winxp\VIA_HyperionPro_V514A\SATAIDE\W2K\ViPrt.sys
[2007/10/18 17:28:52 | 000,052,224 | ---- | M] (VIA Technologies, Inc.) MD5=020EB647FEA9187541827231CB236DCE -- C:\Documents and Settings\Administrator\Desktop\Winxp\VIA_HyperionPro_V514A\SATAIDE\WXP\ViPrt.sys
[2007/10/19 17:03:14 | 000,053,192 | ---- | M] (VIA Technologies, Inc.) MD5=95155D0F72CE3C23C50A6E3B07BF1C71 -- C:\Documents and Settings\Administrator\Desktop\Winxp\VIA_HyperionPro_V514A\SATAIDE\VISTA\ViPrt.sys
< %systemroot%\*. /mp /s >
< %systemroot%\system32\*.dll /lockedfiles >
[2009/03/08 04:31:44 | 000,348,160 | ---- | M] (Microsoft Corporation) Unable to obtain MD5 -- C:\WINDOWS\system32\dxtmsft.dll
[2009/03/08 04:31:38 | 000,216,064 | ---- | M] (Microsoft Corporation) Unable to obtain MD5 -- C:\WINDOWS\system32\dxtrans.dll
< %systemroot%\Tasks\*.job /lockedfiles >
========== Alternate Data Streams ==========
@Alternate Data Stream - 99 bytes -> C:\Documents and Settings\All Users.WINDOWS\Application Data\TEMP:E866ED4D
@Alternate Data Stream - 99 bytes -> C:\Documents and Settings\All Users.WINDOWS\Application Data\TEMP:587AA004
@Alternate Data Stream - 98 bytes -> C:\Documents and Settings\All Users.WINDOWS\Application Data\TEMP:BF09BC9E
@Alternate Data Stream - 95 bytes -> C:\Documents and Settings\All Users.WINDOWS\Application Data\TEMP:E2C9E369
@Alternate Data Stream - 94 bytes -> C:\Documents and Settings\All Users.WINDOWS\Application Data\TEMP:71441FEF
@Alternate Data Stream - 94 bytes -> C:\Documents and Settings\All Users.WINDOWS\Application Data\TEMP:64EEA19D
@Alternate Data Stream - 398 bytes -> C:\Documents and Settings\All Users.WINDOWS\Application Data\TEMP:141BCC26
@Alternate Data Stream - 339 bytes -> C:\Documents and Settings\All Users.WINDOWS\Application Data\TEMP:995B275C
@Alternate Data Stream - 322 bytes -> C:\Documents and Settings\All Users.WINDOWS\Application Data\TEMP:1387592D
@Alternate Data Stream - 320 bytes -> C:\Documents and Settings\All Users.WINDOWS\Application Data\TEMP:B72729D8
@Alternate Data Stream - 311 bytes -> C:\Documents and Settings\All Users.WINDOWS\Application Data\TEMP:A7FB9004
@Alternate Data Stream - 308 bytes -> C:\Documents and Settings\All Users.WINDOWS\Application Data\TEMP:202A6D97
@Alternate Data Stream - 307 bytes -> C:\Documents and Settings\All Users.WINDOWS\Application Data\TEMP:4EDC977B
@Alternate Data Stream - 303 bytes -> C:\Documents and Settings\All Users.WINDOWS\Application Data\TEMP:90281753
@Alternate Data Stream - 297 bytes -> C:\Documents and Settings\All Users.WINDOWS\Application Data\TEMP:72E74C26
@Alternate Data Stream - 293 bytes -> C:\Documents and Settings\All Users.WINDOWS\Application Data\TEMP:9AF3A05F
@Alternate Data Stream - 215 bytes -> C:\Documents and Settings\All Users.WINDOWS\Application Data\TEMP:D8F9D810
@Alternate Data Stream - 208 bytes -> C:\Documents and Settings\All Users.WINDOWS\Application Data\TEMP:BDCD0530
@Alternate Data Stream - 194 bytes -> C:\Documents and Settings\All Users.WINDOWS\Application Data\TEMP:059167AF
@Alternate Data Stream - 181 bytes -> C:\Documents and Settings\All Users.WINDOWS\Application Data\TEMP:A708668B
@Alternate Data Stream - 152 bytes -> C:\Documents and Settings\All Users.WINDOWS\Application Data\TEMP:07E8CA28
@Alternate Data Stream - 151 bytes -> C:\Documents and Settings\All Users.WINDOWS\Application Data\TEMP:7B60301F
@Alternate Data Stream - 150 bytes -> C:\Documents and Settings\All Users.WINDOWS\Application Data\TEMP:03033228
@Alternate Data Stream - 148 bytes -> C:\Documents and Settings\All Users.WINDOWS\Application Data\TEMP:4C97EF04
@Alternate Data Stream - 147 bytes -> C:\Documents and Settings\All Users.WINDOWS\Application Data\TEMP:4F29F38D
@Alternate Data Stream - 146 bytes -> C:\Documents and Settings\All Users.WINDOWS\Application Data\TEMP:A2F5F542
@Alternate Data Stream - 146 bytes -> C:\Documents and Settings\All Users.WINDOWS\Application Data\TEMP:8B1249CD
@Alternate Data Stream - 146 bytes -> C:\Documents and Settings\All Users.WINDOWS\Application Data\TEMP:5466F106
@Alternate Data Stream - 145 bytes -> C:\Documents and Settings\All Users.WINDOWS\Application Data\TEMP:68800D8A
@Alternate Data Stream - 145 bytes -> C:\Documents and Settings\All Users.WINDOWS\Application Data\TEMP:1FA51BA6
@Alternate Data Stream - 144 bytes -> C:\Documents and Settings\All Users.WINDOWS\Application Data\TEMP:9AB338B9
@Alternate Data Stream - 143 bytes -> C:\Documents and Settings\All Users.WINDOWS\Application Data\TEMP:DEDAEF90
@Alternate Data Stream - 143 bytes -> C:\Documents and Settings\All Users.WINDOWS\Application Data\TEMP:38849DE5
@Alternate Data Stream - 142 bytes -> C:\Documents and Settings\All Users.WINDOWS\Application Data\TEMP:D20FFA63
@Alternate Data Stream - 142 bytes -> C:\Documents and Settings\All Users.WINDOWS\Application Data\TEMP:C0A4F645
@Alternate Data Stream - 142 bytes -> C:\Documents and Settings\All Users.WINDOWS\Application Data\TEMP:8CD95DE0
@Alternate Data Stream - 142 bytes -> C:\Documents and Settings\All Users.WINDOWS\Application Data\TEMP:60D735B2
@Alternate Data Stream - 142 bytes -> C:\Documents and Settings\All Users.WINDOWS\Application Data\TEMP:589743E1
@Alternate Data Stream - 142 bytes -> C:\Documents and Settings\All Users.WINDOWS\Application Data\TEMP:250A84D5
@Alternate Data Stream - 142 bytes -> C:\Documents and Settings\All Users.WINDOWS\Application Data\TEMP:0AEAE3CC
@Alternate Data Stream - 141 bytes -> C:\Documents and Settings\All Users.WINDOWS\Application Data\TEMP:741CA49D
@Alternate Data Stream - 141 bytes -> C:\Documents and Settings\All Users.WINDOWS\Application Data\TEMP:5425B7F5
@Alternate Data Stream - 141 bytes -> C:\Documents and Settings\All Users.WINDOWS\Application Data\TEMP:3DAC3B29
@Alternate Data Stream - 141 bytes -> C:\Documents and Settings\All Users.WINDOWS\Application Data\TEMP:30376ACC
@Alternate Data Stream - 140 bytes -> C:\Documents and Settings\All Users.WINDOWS\Application Data\TEMP:EB603FE4
@Alternate Data Stream - 140 bytes -> C:\Documents and Settings\All Users.WINDOWS\Application Data\TEMP:A8E864AC
@Alternate Data Stream - 140 bytes -> C:\Documents and Settings\All Users.WINDOWS\Application Data\TEMP:79108DDD
@Alternate Data Stream - 139 bytes -> C:\Documents and Settings\All Users.WINDOWS\Application Data\TEMP:FFE4BAC7
@Alternate Data Stream - 139 bytes -> C:\Documents and Settings\All Users.WINDOWS\Application Data\TEMP:93C494CA
@Alternate Data Stream - 139 bytes -> C:\Documents and Settings\All Users.WINDOWS\Application Data\TEMP:1B79AEF3
@Alternate Data Stream - 138 bytes -> C:\Documents and Settings\All Users.WINDOWS\Application Data\TEMP:F5E0AE16
@Alternate Data Stream - 138 bytes -> C:\Documents and Settings\All Users.WINDOWS\Application Data\TEMP:A94968B5
@Alternate Data Stream - 138 bytes -> C:\Documents and Settings\All Users.WINDOWS\Application Data\TEMP:399509A6
@Alternate Data Stream - 136 bytes -> C:\Documents and Settings\All Users.WINDOWS\Application Data\TEMP:EB170088
@Alternate Data Stream - 136 bytes -> C:\Documents and Settings\All Users.WINDOWS\Application Data\TEMP:C76BA037
@Alternate Data Stream - 135 bytes -> C:\Documents and Settings\All Users.WINDOWS\Application Data\TEMP:703CE963
@Alternate Data Stream - 135 bytes -> C:\Documents and Settings\All Users.WINDOWS\Application Data\TEMP:037C8A9E
@Alternate Data Stream - 134 bytes -> C:\Documents and Settings\All Users.WINDOWS\Application Data\TEMP:DAFD38AE
@Alternate Data Stream - 134 bytes -> C:\Documents and Settings\All Users.WINDOWS\Application Data\TEMP:95B7F1EC
@Alternate Data Stream - 134 bytes -> C:\Documents and Settings\All Users.WINDOWS\Application Data\TEMP:615435BE
@Alternate Data Stream - 133 bytes -> C:\Documents and Settings\All Users.WINDOWS\Application Data\TEMP:EBFD4E6F
@Alternate Data Stream - 133 bytes -> C:\Documents and Settings\All Users.WINDOWS\Application Data\TEMP:98C1E88D
@Alternate Data Stream - 132 bytes -> C:\Documents and Settings\All Users.WINDOWS\Application Data\TEMP:B6FA1F20
@Alternate Data Stream - 132 bytes -> C:\Documents and Settings\All Users.WINDOWS\Application Data\TEMP:0651F96C
@Alternate Data Stream - 131 bytes -> C:\Documents and Settings\All Users.WINDOWS\Application Data\TEMP:74B502CB
@Alternate Data Stream - 131 bytes -> C:\Documents and Settings\All Users.WINDOWS\Application Data\TEMP:47BE4EDF
@Alternate Data Stream - 131 bytes -> C:\Documents and Settings\All Users.WINDOWS\Application Data\TEMP:2F8DACDA
@Alternate Data Stream - 130 bytes -> C:\Documents and Settings\All Users.WINDOWS\Application Data\TEMP:D23AE9EA
@Alternate Data Stream - 129 bytes -> C:\Documents and Settings\All Users.WINDOWS\Application Data\TEMP:B54102AD
@Alternate Data Stream - 129 bytes -> C:\Documents and Settings\All Users.WINDOWS\Application Data\TEMP:ABE89FFE
@Alternate Data Stream - 129 bytes -> C:\Documents and Settings\All Users.WINDOWS\Application Data\TEMP:8CCDAB14
@Alternate Data Stream - 129 bytes -> C:\Documents and Settings\All Users.WINDOWS\Application Data\TEMP:0860D6D6
@Alternate Data Stream - 128 bytes -> C:\Documents and Settings\All Users.WINDOWS\Application Data\TEMP:D31BE97C
@Alternate Data Stream - 127 bytes -> C:\Documents and Settings\All Users.WINDOWS\Application Data\TEMP:A6253983
@Alternate Data Stream - 127 bytes -> C:\Documents and Settings\All Users.WINDOWS\Application Data\TEMP:A02025CE
@Alternate Data Stream - 127 bytes -> C:\Documents and Settings\All Users.WINDOWS\Application Data\TEMP:9AB56A06
@Alternate Data Stream - 127 bytes -> C:\Documents and Settings\All Users.WINDOWS\Application Data\TEMP:6F1F1DBC
@Alternate Data Stream - 126 bytes -> C:\Documents and Settings\All Users.WINDOWS\Application Data\TEMP:8E60033F
@Alternate Data Stream - 125 bytes -> C:\Documents and Settings\All Users.WINDOWS\Application Data\TEMP:FF818E2B
@Alternate Data Stream - 124 bytes -> C:\Documents and Settings\All Users.WINDOWS\Application Data\TEMP:F1DEA771
@Alternate Data Stream - 124 bytes -> C:\Documents and Settings\All Users.WINDOWS\Application Data\TEMP:6DD87D86
@Alternate Data Stream - 124 bytes -> C:\Documents and Settings\All Users.WINDOWS\Application Data\TEMP:666FB4AA
@Alternate Data Stream - 124 bytes -> C:\Documents and Settings\All Users.WINDOWS\Application Data\TEMP:5D351BC6
@Alternate Data Stream - 124 bytes -> C:\Documents and Settings\All Users.WINDOWS\Application Data\TEMP:46ADD59D
@Alternate Data Stream - 124 bytes -> C:\Documents and Settings\All Users.WINDOWS\Application Data\TEMP:2F93516B
@Alternate Data Stream - 123 bytes -> C:\Documents and Settings\All Users.WINDOWS\Application Data\TEMP:710F4DBF
@Alternate Data Stream - 123 bytes -> C:\Documents and Settings\All Users.WINDOWS\Application Data\TEMP:5C826C73
@Alternate Data Stream - 122 bytes -> C:\Documents and Settings\All Users.WINDOWS\Application Data\TEMP:EA983230
@Alternate Data Stream - 121 bytes -> C:\Documents and Settings\All Users.WINDOWS\Application Data\TEMP:96EE29A3
@Alternate Data Stream - 121 bytes -> C:\Documents and Settings\All Users.WINDOWS\Application Data\TEMP:385BC52C
@Alternate Data Stream - 121 bytes -> C:\Documents and Settings\All Users.WINDOWS\Application Data\TEMP:34B9286E
@Alternate Data Stream - 120 bytes -> C:\Documents and Settings\All Users.WINDOWS\Application Data\TEMP:E66B6127
@Alternate Data Stream - 120 bytes -> C:\Documents and Settings\All Users.WINDOWS\Application Data\TEMP:D29B16C5
@Alternate Data Stream - 120 bytes -> C:\Documents and Settings\All Users.WINDOWS\Application Data\TEMP:94124B85
@Alternate Data Stream - 120 bytes -> C:\Documents and Settings\All Users.WINDOWS\Application Data\TEMP:51A22C60
@Alternate Data Stream - 120 bytes -> C:\Documents and Settings\All Users.WINDOWS\Application Data\TEMP:2B4FA895
@Alternate Data Stream - 119 bytes -> C:\Documents and Settings\All Users.WINDOWS\Application Data\TEMP:91A1C0FC
@Alternate Data Stream - 119 bytes -> C:\Documents and Settings\All Users.WINDOWS\Application Data\TEMP:3FC4A10A
@Alternate Data Stream - 118 bytes -> C:\Documents and Settings\All Users.WINDOWS\Application Data\TEMP:19F494DE
@Alternate Data Stream - 118 bytes -> C:\Documents and Settings\All Users.WINDOWS\Application Data\TEMP:16B49C20
@Alternate Data Stream - 118 bytes -> C:\Documents and Settings\All Users.WINDOWS\Application Data\TEMP:052E15C3
@Alternate Data Stream - 117 bytes -> C:\Documents and Settings\All Users.WINDOWS\Application Data\TEMP:D8DB81DC
@Alternate Data Stream - 116 bytes -> C:\Documents and Settings\All Users.WINDOWS\Application Data\TEMP:B1EEADE7
@Alternate Data Stream - 116 bytes -> C:\Documents and Settings\All Users.WINDOWS\Application Data\TEMP:898C038B
@Alternate Data Stream - 116 bytes -> C:\Documents and Settings\All Users.WINDOWS\Application Data\TEMP:375FC7E7
@Alternate Data Stream - 115 bytes -> C:\Documents and Settings\All Users.WINDOWS\Application Data\TEMP:DF0BC727
@Alternate Data Stream - 115 bytes -> C:\Documents and Settings\All Users.WINDOWS\Application Data\TEMP:A8ADE5D8
@Alternate Data Stream - 114 bytes -> C:\Documents and Settings\All Users.WINDOWS\Application Data\TEMP:C3B5FCD5
@Alternate Data Stream - 113 bytes -> C:\Documents and Settings\All Users.WINDOWS\Application Data\TEMP:EC7C9796
@Alternate Data Stream - 112 bytes -> C:\Documents and Settings\All Users.WINDOWS\Application Data\TEMP:EC0A74A1
@Alternate Data Stream - 112 bytes -> C:\Documents and Settings\All Users.WINDOWS\Application Data\TEMP:E5F8E280
@Alternate Data Stream - 112 bytes -> C:\Documents and Settings\All Users.WINDOWS\Application Data\TEMP:669764DD
@Alternate Data Stream - 111 bytes -> C:\Documents and Settings\All Users.WINDOWS\Application Data\TEMP:D28EBF99
@Alternate Data Stream - 111 bytes -> C:\Documents and Settings\All Users.WINDOWS\Application Data\TEMP:C22674B6
@Alternate Data Stream - 111 bytes -> C:\Documents and Settings\All Users.WINDOWS\Application Data\TEMP:24FECE50
@Alternate Data Stream - 111 bytes -> C:\Documents and Settings\All Users.WINDOWS\Application Data\TEMP:172EB9B5
@Alternate Data Stream - 110 bytes -> C:\Documents and Settings\All Users.WINDOWS\Application Data\TEMP:A688EF17
@Alternate Data Stream - 110 bytes -> C:\Documents and Settings\All Users.WINDOWS\Application Data\TEMP:8EEDCEA2
@Alternate Data Stream - 109 bytes -> C:\Documents and Settings\All Users.WINDOWS\Application Data\TEMP:98AE08EA
@Alternate Data Stream - 108 bytes -> C:\Documents and Settings\All Users.WINDOWS\Application Data\TEMP:BBF60A29
@Alternate Data Stream - 108 bytes -> C:\Documents and Settings\All Users.WINDOWS\Application Data\TEMP:79A70C33
@Alternate Data Stream - 107 bytes -> C:\Documents and Settings\All Users.WINDOWS\Application Data\TEMP:A9E9471A
@Alternate Data Stream - 105 bytes -> C:\Documents and Settings\All Users.WINDOWS\Application Data\TEMP:BF07EA98
@Alternate Data Stream - 105 bytes -> C:\Documents and Settings\All Users.WINDOWS\Application Data\TEMP:33611CFB
@Alternate Data Stream - 103 bytes -> C:\Documents and Settings\All Users.WINDOWS\Application Data\TEMP:DFC5A2B2
@Alternate Data Stream - 101 bytes -> C:\Documents and Settings\All Users.WINDOWS\Application Data\TEMP:5FB7A2BD
@Alternate Data Stream - 101 bytes -> C:\Documents and Settings\All Users.WINDOWS\Application Data\TEMP:561B1D2B
< End of report >