here is the second part of the otl txt
========== Files Created - No Company Name ========== [2010/04/03 20:12:54 | 000,147,832 | ---- | C] () -- C:\Documents and Settings\Chris\Desktop\profiles.exe
[2010/04/02 14:49:43 | 000,261,632 | ---- | C] () -- C:\WINDOWS\PEV.exe
[2010/04/02 14:49:43 | 000,098,816 | ---- | C] () -- C:\WINDOWS\sed.exe
[2010/04/02 14:49:43 | 000,080,412 | ---- | C] () -- C:\WINDOWS\grep.exe
[2010/04/02 14:49:43 | 000,077,312 | ---- | C] () -- C:\WINDOWS\MBR.exe
[2010/04/02 14:49:43 | 000,068,096 | ---- | C] () -- C:\WINDOWS\zip.exe
[2010/04/02 14:43:57 | 003,911,676 | R--- | C] () -- C:\Documents and Settings\Chris\Desktop\commy.exe
[2010/03/23 14:01:18 | 000,001,310 | ---- | C] () -- C:\Documents and Settings\Chris\Desktop\Facebook.url
[2010/03/12 09:31:08 | 000,721,904 | ---- | C] () -- C:\WINDOWS\System32\drivers\sptd.sys
[2009/12/23 00:54:28 | 000,000,256 | R--- | C] () -- C:\Documents and Settings\Chris\BRMSI04.BIN
[2009/12/20 11:00:17 | 011,534,336 | ---- | C] () -- C:\Documents and Settings\Chris\ntuser.dat
[2009/10/16 12:10:47 | 000,001,536 | -HS- | C] () -- C:\Program Files\ehthumbs.db
[2009/10/16 12:08:10 | 000,001,536 | -HS- | C] () -- C:\Documents and Settings\All Users\ehthumbs.db
[2009/10/16 02:55:26 | 000,000,000 | ---- | C] () -- C:\WINDOWS\AoADVDRipper.INI
[2009/09/04 19:03:28 | 000,000,128 | ---- | C] () -- C:\Documents and Settings\Chris\Local Settings\Application Data\fusioncache.dat
[2009/07/22 16:53:27 | 000,049,152 | ---- | C] () -- C:\Documents and Settings\Chris\Local Settings\Application Data\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2009/07/10 22:19:43 | 000,765,952 | ---- | C] () -- C:\WINDOWS\System32\xvidcore.dll
[2009/07/10 22:19:43 | 000,180,224 | ---- | C] () -- C:\WINDOWS\System32\xvidvfw.dll
[2009/06/20 13:12:02 | 000,057,344 | ---- | C] () -- C:\WINDOWS\System32\ff_vfw.dll
[2009/06/20 13:12:02 | 000,000,547 | ---- | C] () -- C:\WINDOWS\System32\ff_vfw.dll.manifest
[2009/06/13 05:57:31 | 000,074,703 | ---- | C] () -- C:\WINDOWS\System32\mfc45.dll
[2009/06/09 08:19:42 | 000,299,008 | ---- | C] () -- C:\Documents and Settings\LocalService\Local Settings\Application Data\FontCache3.0.0.0.dat
[2009/06/06 15:19:07 | 000,000,030 | ---- | C] () -- C:\WINDOWS\System32\brss01a.ini
[2009/06/06 15:19:07 | 000,000,027 | ---- | C] () -- C:\WINDOWS\BRPP2KA.INI
[2009/06/06 15:19:06 | 000,000,419 | ---- | C] () -- C:\WINDOWS\BRWMARK.INI
[2009/05/19 22:39:27 | 000,000,390 | ---- | C] () -- C:\WINDOWS\BRMFBIDI.INI
[2009/05/12 20:40:21 | 000,000,023 | ---- | C] () -- C:\WINDOWS\Mahjongg Variations.INI
[2008/10/24 17:52:31 | 000,000,000 | ---- | C] () -- C:\Documents and Settings\All Users\Application Data\N360BUOptions.ini
[2008/07/19 15:59:46 | 000,086,304 | ---- | C] () -- C:\WINDOWS\RHVIDEO.DLL
[2008/05/10 02:47:44 | 000,000,048 | ---- | C] () -- C:\WINDOWS\Hypnosis.ini
[2008/03/28 06:46:59 | 000,001,458 | ---- | C] () -- C:\WINDOWS\FiveCardFrenzy.ini
[2008/03/17 13:33:06 | 000,000,136 | ---- | C] () -- C:\WINDOWS\cdplayer.ini
[2008/03/06 07:19:56 | 000,000,000 | ---- | C] () -- C:\WINDOWS\pool.INI
[2008/01/20 23:53:50 | 000,000,148 | ---- | C] () -- C:\WINDOWS\System32\acmeinc.ini
[2008/01/20 23:53:50 | 000,000,116 | ---- | C] () -- C:\WINDOWS\System32\vxdtgm.ini
[2008/01/01 22:42:44 | 000,000,048 | ---- | C] () -- C:\WINDOWS\KPCMS.INI
[2007/12/28 22:49:25 | 001,936,528 | ---- | C] () -- C:\WINDOWS\System32\ltmm15.dll
[2007/12/17 03:52:08 | 000,063,488 | ---- | C] () -- C:\WINDOWS\xobglu16.dll
[2007/12/17 03:52:08 | 000,023,552 | ---- | C] () -- C:\WINDOWS\xobglu32.dll
[2007/12/02 21:12:20 | 000,000,092 | ---- | C] () -- C:\WINDOWS\QTW.INI
[2007/12/02 21:11:28 | 000,027,136 | ---- | C] () -- C:\WINDOWS\System32\QTUninst.dll
[2007/11/19 18:48:23 | 000,000,514 | ---- | C] () -- C:\WINDOWS\hegames.ini
[2007/11/16 00:36:40 | 000,000,976 | ---- | C] () -- C:\WINDOWS\yahtzee.ini
[2007/10/20 23:47:06 | 000,100,864 | ---- | C] () -- C:\WINDOWS\System32\Dc50ip32.dll
[2007/10/20 23:47:06 | 000,065,864 | ---- | C] () -- C:\WINDOWS\System32\Digita.sys
[2007/10/20 23:47:06 | 000,007,808 | ---- | C] () -- C:\WINDOWS\System32\dc240u.sys
[2007/10/20 23:47:06 | 000,006,144 | ---- | C] () -- C:\WINDOWS\System32\ImgLibLead.dll
[2007/10/20 23:46:52 | 000,210,944 | ---- | C] () -- C:\WINDOWS\System32\MSVCRT10.DLL
[2007/10/13 23:42:35 | 000,000,041 | ---- | C] () -- C:\WINDOWS\Tetris.ini
[2007/10/13 20:54:54 | 000,000,056 | ---- | C] () -- C:\WINDOWS\TZAPCOM.INI
[2007/10/05 12:48:49 | 000,000,080 | ---- | C] () -- C:\WINDOWS\fpg.INI
[2007/09/30 11:40:04 | 000,006,127 | ---- | C] () -- C:\Documents and Settings\All Users\Application Data\hpzinstall.log
[2007/09/18 22:16:00 | 000,000,767 | ---- | C] () -- C:\WINDOWS\SIERRA.INI
[2007/09/17 16:48:20 | 000,000,000 | ---- | C] () -- C:\WINDOWS\iPlayer.INI
[2007/09/07 01:48:25 | 000,000,000 | ---- | C] () -- C:\WINDOWS\FoneSync.INI
[2007/09/06 16:47:06 | 000,000,376 | ---- | C] () -- C:\WINDOWS\ODBC.INI
[2007/09/02 20:15:27 | 000,000,187 | ---- | C] () -- C:\Documents and Settings\Chris\Application Data\G-Force Prefs (WindowsMediaPlayer).txt
[2007/08/22 23:16:34 | 000,123,888 | ---- | C] () -- C:\Documents and Settings\All Users\Application Data\Svclog.log
[2007/07/20 22:52:29 | 000,000,000 | ---- | C] () -- C:\WINDOWS\Textart.INI
[2007/03/27 11:45:22 | 000,004,096 | ---- | C] () -- C:\WINDOWS\System32\sysres.dll
[2006/12/12 12:33:37 | 000,000,056 | RHS- | C] () -- C:\WINDOWS\System32\0E91058025.sys
[2006/12/11 00:13:45 | 000,000,111 | ---- | C] () -- C:\WINDOWS\Sansa Media Converter.INI
[2006/11/17 13:23:20 | 000,000,793 | ---- | C] () -- C:\WINDOWS\dellstat.ini
[2006/11/17 00:26:54 | 000,000,000 | ---- | C] () -- C:\Documents and Settings\Chris\NULL
[2006/10/26 08:56:48 | 000,003,454 | -HS- | C] () -- C:\WINDOWS\System32\KGyGaAvL.sys
[2006/10/26 08:56:48 | 000,000,056 | RHS- | C] () -- C:\WINDOWS\System32\11C6F2E73F.sys
[2006/10/14 20:57:35 | 000,000,583 | ---- | C] () -- C:\WINDOWS\Q3TA.INI
[2006/10/13 16:46:31 | 000,061,678 | ---- | C] () -- C:\Documents and Settings\Chris\Application Data\PFP120JPR.{PB
[2006/10/13 16:46:31 | 000,012,358 | ---- | C] () -- C:\Documents and Settings\Chris\Application Data\PFP120JCM.{PB
[2006/10/11 10:49:04 | 000,000,002 | ---- | C] () -- C:\WINDOWS\msoffice.ini
[2006/08/27 11:04:22 | 000,001,024 | -H-- | C] () -- C:\Documents and Settings\Chris\ntuser.dat.LOG
[2006/08/27 11:04:22 | 000,000,278 | -HS- | C] () -- C:\Documents and Settings\Chris\ntuser.ini
[2006/08/27 11:04:04 | 000,262,144 | ---- | C] () -- C:\Documents and Settings\All Users\NTUSER.DAT
[2006/08/27 11:04:04 | 000,001,024 | -H-- | C] () -- C:\Documents and Settings\All Users\NTUSER.DAT.LOG
[2006/07/07 12:30:22 | 000,073,728 | ---- | C] () -- C:\WINDOWS\System32\ts.dll
[2005/12/11 10:12:10 | 000,000,061 | ---- | C] () -- C:\WINDOWS\smscfg.ini
[2005/12/11 10:04:26 | 000,000,592 | ---- | C] () -- C:\WINDOWS\wininit.ini
[2005/12/11 09:41:50 | 000,000,200 | ---- | C] () -- C:\WINDOWS\System32\dlbcplc.ini
[2005/12/11 09:41:14 | 000,000,392 | ---- | C] () -- C:\WINDOWS\System32\OEMINFO.INI
[2005/08/05 13:01:54 | 000,235,008 | ---- | C] () -- C:\WINDOWS\System32\psisdecd.dll
[2005/07/12 15:44:42 | 000,015,872 | ---- | C] () -- C:\WINDOWS\System32\InsDrvZD64.DLL
[2005/04/09 16:04:54 | 000,000,000 | ---- | C] () -- C:\WINDOWS\System32\px.ini
[2004/03/23 17:38:00 | 000,028,672 | ---- | C] () -- C:\WINDOWS\System32\InsDrvZD.dll
[2003/03/09 22:31:04 | 000,561,152 | ---- | C] () -- C:\WINDOWS\System32\hpotscl.dll
[2000/01/28 00:00:00 | 000,012,288 | ---- | C] () -- C:\WINDOWS\System32\HLINKPRX.DLL
[1999/01/22 19:46:58 | 000,065,536 | ---- | C] () -- C:\WINDOWS\System32\MSRTEDIT.DLL
========== Custom Scans ========== < %systemroot%\*. /mp /s > < %systemroot%\system32\*.dll /lockedfiles >[2008/04/13 17:11:51 | 001,267,200 | ---- | M] (Microsoft Corporation)
Unable to obtain MD5 -- C:\WINDOWS\system32\comsvcs.dll
< %systemroot%\system32\*.exe /lockedfiles > < %systemroot%\Tasks\*.job /lockedfiles > < %systemroot%\system32\drivers\*.sys /lockedfiles >[2010/03/12 09:31:09 | 000,721,904 | ---- | M] ()
Unable to obtain MD5 -- C:\WINDOWS\system32\drivers\sptd.sys
< %systemroot%\System32\config\*.sav >[2005/08/16 03:27:08 | 000,094,208 | ---- | M] () -- C:\WINDOWS\system32\config\default.sav
[2005/08/16 03:27:08 | 000,659,456 | ---- | M] () -- C:\WINDOWS\system32\config\software.sav
[2005/08/16 03:27:08 | 000,876,544 | ---- | M] () -- C:\WINDOWS\system32\config\system.sav
< %systemroot%\system32\*.sys >[2006/12/12 12:33:37 | 000,000,056 | RHS- | M] () -- C:\WINDOWS\system32\0E91058025.sys
[2007/07/24 01:02:46 | 000,000,056 | RHS- | M] () -- C:\WINDOWS\system32\11C6F2E73F.sys
[2004/08/10 04:00:00 | 000,009,029 | ---- | M] () -- C:\WINDOWS\system32\ansi.sys
[2004/08/10 04:00:00 | 000,027,097 | ---- | M] () -- C:\WINDOWS\system32\country.sys
[1999/11/05 14:18:58 | 000,007,808 | ---- | M] () -- C:\WINDOWS\system32\dc240u.sys
[2004/06/09 09:29:56 | 000,006,977 | ---- | M] (Gteko Ltd.) -- C:\WINDOWS\system32\DDMI2.sys
[1999/11/05 14:19:00 | 000,065,864 | ---- | M] () -- C:\WINDOWS\system32\Digita.sys
[2005/03/13 15:54:00 | 000,006,656 | ---- | M] (GTek Technologies Ltd.) -- C:\WINDOWS\system32\DLPT2.sys
[2005/02/08 11:37:52 | 000,007,626 | ---- | M] (Gteko Ltd.) -- C:\WINDOWS\system32\GPCIEnum.sys
[2004/06/15 15:55:56 | 000,007,882 | ---- | M] (Gteko Ltd.) -- C:\WINDOWS\system32\GTKCMOS.sys
[2004/08/10 04:00:00 | 000,004,768 | ---- | M] () -- C:\WINDOWS\system32\himem.sys
[2005/09/20 18:27:20 | 000,010,368 | ---- | M] (InterVideo, Inc.) -- C:\WINDOWS\system32\iviaspi.sys
[2004/08/10 04:00:00 | 000,042,809 | ---- | M] () -- C:\WINDOWS\system32\key01.sys
[2004/08/10 04:00:00 | 000,042,537 | ---- | M] () -- C:\WINDOWS\system32\keyboard.sys
[2007/07/24 01:02:46 | 000,003,454 | -HS- | M] () -- C:\WINDOWS\system32\KGyGaAvL.sys
[2004/08/10 04:00:00 | 000,027,866 | ---- | M] () -- C:\WINDOWS\system32\ntdos.sys
[2004/08/10 04:00:00 | 000,029,146 | ---- | M] () -- C:\WINDOWS\system32\ntdos404.sys
[2004/08/10 04:00:00 | 000,029,370 | ---- | M] () -- C:\WINDOWS\system32\ntdos411.sys
[2004/08/10 04:00:00 | 000,029,274 | ---- | M] () -- C:\WINDOWS\system32\ntdos412.sys
[2004/08/10 04:00:00 | 000,029,146 | ---- | M] () -- C:\WINDOWS\system32\ntdos804.sys
[2004/08/10 04:00:00 | 000,033,840 | ---- | M] () -- C:\WINDOWS\system32\ntio.sys
[2004/08/10 04:00:00 | 000,034,560 | ---- | M] () -- C:\WINDOWS\system32\ntio404.sys
[2004/08/10 04:00:00 | 000,035,648 | ---- | M] () -- C:\WINDOWS\system32\ntio411.sys
[2004/08/10 04:00:00 | 000,035,424 | ---- | M] () -- C:\WINDOWS\system32\ntio412.sys
[2004/08/10 04:00:00 | 000,034,560 | ---- | M] () -- C:\WINDOWS\system32\ntio804.sys
[2008/04/13 11:44:59 | 000,017,664 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\system32\watchdog.sys
[2009/08/14 06:21:25 | 001,850,624 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\system32\win32k.sys
[2004/01/14 12:30:00 | 000,017,151 | ---- | M] (Printing Communications Assoc., Inc. (PCAUSA)) -- C:\WINDOWS\system32\ZDPNDIS5.SYS
< %systemroot%\system32\drivers\*.dll >[2008/04/13 17:11:48 | 000,004,255 | ---- | M] (Intel(R) Corporation) -- C:\WINDOWS\system32\drivers\adv01nt5.dll
[2008/04/13 17:11:48 | 000,003,967 | ---- | M] (Intel(R) Corporation) -- C:\WINDOWS\system32\drivers\adv02nt5.dll
[2008/04/13 17:11:48 | 000,003,615 | ---- | M] (Intel(R) Corporation) -- C:\WINDOWS\system32\drivers\adv05nt5.dll
[2008/04/13 17:11:48 | 000,003,647 | ---- | M] (Intel(R) Corporation) -- C:\WINDOWS\system32\drivers\adv07nt5.dll
[2008/04/13 17:11:48 | 000,003,135 | ---- | M] (Intel(R) Corporation) -- C:\WINDOWS\system32\drivers\adv08nt5.dll
[2008/04/13 17:11:48 | 000,003,711 | ---- | M] (Intel(R) Corporation) -- C:\WINDOWS\system32\drivers\adv09nt5.dll
[2008/04/13 17:11:48 | 000,003,775 | ---- | M] (Intel(R) Corporation) -- C:\WINDOWS\system32\drivers\adv11nt5.dll
[2008/04/13 17:11:50 | 000,021,183 | ---- | M] (Intel(R) Corporation) -- C:\WINDOWS\system32\drivers\atv01nt5.dll
[2008/04/13 17:11:50 | 000,011,359 | ---- | M] (Intel(R) Corporation) -- C:\WINDOWS\system32\drivers\atv02nt5.dll
[2008/04/13 17:11:50 | 000,025,471 | ---- | M] (Intel(R) Corporation) -- C:\WINDOWS\system32\drivers\atv04nt5.dll
[2008/04/13 17:11:50 | 000,014,143 | ---- | M] (Intel(R) Corporation) -- C:\WINDOWS\system32\drivers\atv06nt5.dll
[2008/04/13 17:11:50 | 000,017,279 | ---- | M] (Intel(R) Corporation) -- C:\WINDOWS\system32\drivers\atv10nt5.dll
[2008/04/13 17:11:50 | 000,015,423 | ---- | M] (Intel(R) Corporation) -- C:\WINDOWS\system32\drivers\ch7xxnt5.dll
[2008/04/13 17:12:05 | 000,003,901 | ---- | M] (Intel(R) Corporation) -- C:\WINDOWS\system32\drivers\siint5.dll
[2008/04/13 17:12:08 | 000,011,325 | ---- | M] (Intel(R) Corporation) -- C:\WINDOWS\system32\drivers\vchnt5.dll
< %systemroot%\system32\drivers\*.ini > < %systemroot%\system32\drivers\*.exe > < %SYSTEMDRIVE%\*.* >[2009/09/29 19:00:52 | 000,000,000 | ---- | M] () -- C:\AdobeDebug.txt
[2005/08/16 03:43:04 | 000,000,000 | ---- | M] () -- C:\AUTOEXEC.BAT
[2006/10/11 10:43:15 | 000,000,276 | ---- | M] () -- C:\BDELog.txt
[2010/01/15 23:35:01 | 000,000,209 | ---- | M] () -- C:\Boot.bak
[2010/04/10 19:52:01 | 000,000,279 | RHS- | M] () -- C:\boot.ini
[2004/08/04 00:00:00 | 000,260,272 | ---- | M] () -- C:\cmldr
[2010/01/15 23:12:39 | 000,000,013 | -H-- | M] () -- C:\cmsstorage.lst
[2010/04/11 13:39:57 | 000,014,329 | ---- | M] () -- C:\ComboFix.txt
[2005/08/16 03:43:04 | 000,000,000 | ---- | M] () -- C:\CONFIG.SYS
[2008/11/04 19:14:26 | 000,066,052 | ---- | M] () -- C:\consoledebug.txt
[2009/01/23 07:55:22 | 000,000,710 | ---- | M] () -- C:\coredw.log
[2009/03/30 22:54:01 | 000,000,000 | ---- | M] () -- C:\data.cph
[2009/01/23 07:55:23 | 000,000,466 | ---- | M] () -- C:\datawriter.log
[2005/12/11 09:44:30 | 000,005,657 | RH-- | M] () -- C:\dell.sdr
[2008/05/28 20:34:16 | 000,000,097 | ---- | M] () -- C:\DownloadLog.txt
[2008/01/26 04:42:45 | 000,007,667 | ---- | M] () -- C:\DTLog.txt
[2009/10/16 11:48:54 | 001,912,320 | -HS- | M] () -- C:\ehthumbs.db
[2009/06/27 17:04:32 | 000,000,153 | ---- | M] () -- C:\EventLOG.txt
[2007/12/27 09:29:31 | 000,000,016 | ---- | M] () -- C:\h.txt
[2010/04/11 22:31:07 | 526,536,704 | -HS- | M] () -- C:\hiberfil.sys
[2008/05/08 16:35:14 | 000,000,752 | ---- | M] () -- C:\hpfr3420.log
[2008/08/29 12:48:24 | 000,000,527 | ---- | M] () -- C:\hpfr3420.xml
[2008/08/29 12:48:24 | 000,277,012 | ---- | M] () -- C:\hpfr3425.log
[2006/08/27 19:14:43 | 000,004,128 | ---- | M] () -- C:\INFCACHE.1
[2008/06/07 15:47:30 | 000,000,424 | ---- | M] () -- C:\INSTALL.LOG
[2005/08/16 03:43:04 | 000,000,000 | -H-- | M] () -- C:\IO.SYS
[2008/03/14 04:00:00 | 000,000,125 | ---- | M] () -- C:\ioSpecial.ini
[2005/12/11 10:04:14 | 000,000,839 | -H-- | M] () -- C:\IPH.PH
[2008/03/31 06:43:26 | 000,000,218 | -H-- | M] () -- C:\l81.i
[2009/12/13 17:11:46 | 000,000,005 | ---- | M] () -- C:\lcl.txt
[2010/04/01 08:08:56 | 000,000,109 | ---- | M] () -- C:\mbam-error.txt
[2005/08/16 03:43:04 | 000,000,000 | -H-- | M] () -- C:\MSDOS.SYS
[2004/08/10 04:00:00 | 000,047,564 | RHS- | M] () -- C:\NTDETECT.COM
[2008/09/05 20:27:04 | 000,250,048 | RHS- | M] () -- C:\ntldr
[2008/10/16 01:00:59 | 000,262,144 | ---- | M] () -- C:\ntuser.dat
[2009/01/25 11:07:49 | 000,001,024 | -H-- | M] () -- C:\ntuser.dat.LOG
[2010/04/11 22:31:06 | 789,696,512 | -HS- | M] () -- C:\pagefile.sys
[2008/03/01 18:13:20 | 000,038,484 | ---- | M] () -- C:\playground.log
[2009/10/16 11:46:20 | 000,000,189 | ---- | M] () -- C:\Shortcut (2) to CD Drive.lnk
[2008/05/14 07:30:30 | 000,000,145 | ---- | M] () -- C:\Shortcut to CD Drive.lnk
[2005/10/31 08:56:00 | 000,700,416 | ---- | M] (LimeWire) -- C:\StubInstaller.exe
[2005/12/11 10:04:24 | 000,000,087 | ---- | M] () -- C:\SystemInfo.ini
[2008/03/31 06:43:26 | 000,000,218 | -H-- | M] () -- C:\t8101.le
[2010/04/03 07:18:56 | 000,019,456 | ---- | M] () -- C:\TDSSKiller.2.2.8.1_03.04.2010_07.18.56_log.txt
[2010/04/03 07:19:26 | 000,019,456 | ---- | M] () -- C:\TDSSKiller.txt
[2008/06/03 14:46:14 | 000,005,384 | ---- | M] () -- C:\tv3d_debug.txt
[2006/11/17 10:09:31 | 000,002,824 | -HS- | M] () -- C:\vm404.log
[2009/07/21 18:46:43 | 000,058,368 | ---- | M] () -- C:\wonderland doc 1.doc
[2009/07/21 18:48:38 | 000,066,048 | ---- | M] () -- C:\wonderland doc2.doc
[2009/04/25 00:13:22 | 001,054,728 | ---- | M] () -- C:\
www.yahoo.htm[2007/11/27 16:48:43 | 000,001,167 | ---- | M] () -- C:\_Sid.txt
< %PROGRAMFILES%\*. >[2010/01/17 14:04:03 | 000,000,000 | ---D | M] -- C:\Program Files\Adobe
[2007/01/16 00:30:02 | 000,000,000 | ---D | M] -- C:\Program Files\Belkin
[2009/06/27 04:54:17 | 000,000,000 | ---D | M] -- C:\Program Files\Bonjour
[2010/04/11 13:31:30 | 000,000,000 | ---D | M] -- C:\Program Files\Common Files
[2005/08/16 03:38:36 | 000,000,000 | ---D | M] -- C:\Program Files\ComPlus Applications
[2008/03/14 03:51:22 | 000,000,000 | ---D | M] -- C:\Program Files\Conduit
[2009/06/20 13:11:52 | 000,000,000 | ---D | M] -- C:\Program Files\Cucusoft
[2005/12/11 10:01:18 | 000,000,000 | ---D | M] -- C:\Program Files\CyberLink
[2010/04/03 13:41:30 | 000,000,000 | ---D | M] -- C:\Program Files\DivX
[2007/10/23 14:37:14 | 000,000,000 | ---D | M] -- C:\Program Files\eGames
[2007/10/05 13:09:18 | 000,000,000 | ---D | M] -- C:\Program Files\First Principle Group
[2007/09/06 16:42:37 | 000,000,000 | ---D | M] -- C:\Program Files\FoneSync
[2008/12/25 15:40:56 | 000,000,000 | ---D | M] -- C:\Program Files\GameFiesta
[2008/07/01 11:24:12 | 000,000,000 | ---D | M] -- C:\Program Files\GameHouse(2)
[2010/04/02 08:33:52 | 000,000,000 | ---D | M] -- C:\Program Files\Google
[2010/03/18 02:03:27 | 000,000,000 | ---D | M] -- C:\Program Files\Graboid
[2007/07/25 06:55:22 | 000,000,000 | ---D | M] -- C:\Program Files\Greedy Words
[2007/10/23 21:45:08 | 000,000,000 | ---D | M] -- C:\Program Files\IEForge
[2007/10/23 21:42:07 | 000,000,000 | ---D | M] -- C:\Program Files\ieSpell
[2009/01/28 15:16:53 | 000,000,000 | ---D | M] -- C:\Program Files\Incomplete
[2009/06/27 21:07:25 | 000,000,000 | ---D | M] -- C:\Program Files\Infogrames Interactive
[2009/10/16 01:42:08 | 000,000,000 | -H-D | M] -- C:\Program Files\InstallShield Installation Information
[2007/11/27 23:03:36 | 000,000,000 | ---D | M] -- C:\Program Files\Intel
[2008/02/19 18:51:11 | 000,000,000 | ---D | M] -- C:\Program Files\InterActual
[2010/03/31 15:24:30 | 000,000,000 | ---D | M] -- C:\Program Files\Internet Explorer
[2010/01/20 18:26:43 | 000,000,000 | ---D | M] -- C:\Program Files\Java
[2007/10/20 23:48:55 | 000,000,000 | ---D | M] -- C:\Program Files\LightWork Design
[2010/01/20 18:27:08 | 000,000,000 | ---D | M] -- C:\Program Files\LimeWire
[2008/10/13 19:27:34 | 000,000,000 | ---D | M] -- C:\Program Files\Media Manager
[2009/06/17 17:58:25 | 000,000,000 | ---D | M] -- C:\Program Files\Messenger
[2009/01/13 18:11:20 | 000,000,000 | ---D | M] -- C:\Program Files\Microsoft
[2007/08/23 15:14:58 | 000,000,000 | ---D | M] -- C:\Program Files\Microsoft CAPICOM 2.1.0.2
[2009/03/10 22:16:17 | 000,000,000 | ---D | M] -- C:\Program Files\microsoft frontpage
[2009/07/23 12:29:48 | 000,000,000 | ---D | M] -- C:\Program Files\Microsoft Office
[2005/12/11 10:02:59 | 000,000,000 | ---D | M] -- C:\Program Files\Microsoft Plus! Digital Media Edition
[2010/01/20 16:02:54 | 000,000,000 | ---D | M] -- C:\Program Files\Microsoft Silverlight
[2009/10/16 07:48:12 | 000,000,000 | ---D | M] -- C:\Program Files\Microsoft Works
[2007/10/25 21:56:15 | 000,000,000 | ---D | M] -- C:\Program Files\MICROS~1.SH!
[2008/03/14 03:51:22 | 000,000,000 | ---D | M] -- C:\Program Files\Mininova
[2005/12/11 10:00:57 | 000,000,000 | ---D | M] -- C:\Program Files\Modem Helper
[2005/12/11 10:01:10 | 000,000,000 | ---D | M] -- C:\Program Files\Modem On Hold
[2009/06/27 21:07:25 | 000,000,000 | ---D | M] -- C:\Program Files\Morpheus
[2010/03/10 05:04:11 | 000,000,000 | ---D | M] -- C:\Program Files\Movie Maker
[2009/08/11 23:15:31 | 000,000,000 | ---D | M] -- C:\Program Files\Mozilla ActiveX Control v1.7.12
[2007/11/13 01:10:54 | 000,000,000 | ---D | M] -- C:\Program Files\MSBuild
[2009/01/25 14:55:32 | 000,000,000 | ---D | M] -- C:\Program Files\MSECACHE
[2009/04/24 22:31:32 | 000,000,000 | ---D | M] -- C:\Program Files\MSN
[2007/11/02 21:22:00 | 000,000,000 | ---D | M] -- C:\Program Files\MSN Games
[2005/08/16 03:37:30 | 000,000,000 | ---D | M] -- C:\Program Files\MSN Gaming Zone
[2006/11/17 13:30:48 | 000,000,000 | ---D | M] -- C:\Program Files\MSXML 4.0
[2007/11/13 00:57:34 | 000,000,000 | ---D | M] -- C:\Program Files\MSXML 6.0
[2008/09/05 20:29:01 | 000,000,000 | ---D | M] -- C:\Program Files\NetMeeting
[2008/03/03 21:35:54 | 000,000,000 | ---D | M] -- C:\Program Files\Oberon Media
[2009/07/23 12:29:50 | 000,000,000 | ---D | M] -- C:\Program Files\Office2K
[2006/12/11 08:20:47 | 000,000,000 | ---D | M] -- C:\Program Files\Online Services
[2009/09/25 10:12:42 | 000,000,000 | ---D | M] -- C:\Program Files\Outlook Express
[2008/03/01 19:48:04 | 000,000,000 | ---D | M] -- C:\Program Files\PiratePoppers_at
[2007/10/14 00:35:42 | 000,000,000 | ---D | M] -- C:\Program Files\Plus!
[2009/12/26 16:53:23 | 000,000,000 | ---D | M] -- C:\Program Files\PopCap Games
[2007/09/28 06:22:50 | 000,000,000 | ---D | M] -- C:\Program Files\Poppit To Go
[2008/07/01 03:54:36 | 000,000,000 | ---D | M] -- C:\Program Files\QBeez2_at
[2009/09/22 16:38:32 | 000,000,000 | ---D | M] -- C:\Program Files\QuickTime
[2008/10/26 17:07:11 | 000,000,000 | ---D | M] -- C:\Program Files\Real
[2010/03/18 02:02:07 | 000,000,000 | ---D | M] -- C:\Program Files\RealArcade
[2007/11/13 01:04:50 | 000,000,000 | ---D | M] -- C:\Program Files\Reference Assemblies
[2007/07/25 04:45:13 | 000,000,000 | ---D | M] -- C:\Program Files\ReflexiveArcade
[2007/07/24 01:11:56 | 000,000,000 | ---D | M] -- C:\Program Files\RGB
[2009/07/27 15:27:40 | 000,000,000 | ---D | M] -- C:\Program Files\Riva
[2010/03/30 05:14:38 | 000,000,000 | ---D | M] -- C:\Program Files\Rumo
[2009/06/02 00:57:01 | 000,000,000 | ---D | M] -- C:\Program Files\Safer Networking
[2008/05/31 23:25:24 | 000,000,000 | ---D | M] -- C:\Program Files\Sandisk
[2009/06/06 14:42:41 | 000,000,000 | ---D | M] -- C:\Program Files\ScanSoft(2)
[2010/01/15 23:12:57 | 000,000,000 | ---D | M] -- C:\Program Files\Security Task Manager
[2006/11/17 13:17:32 | 000,000,000 | ---D | M] -- C:\Program Files\Shockwave.com
[2007/08/22 22:02:23 | 000,000,000 | ---D | M] -- C:\Program Files\Siber Systems
[2007/09/18 22:16:38 | 000,000,000 | ---D | M] -- C:\Program Files\Sierra On-Line
[2005/12/11 09:59:18 | 000,000,000 | ---D | M] -- C:\Program Files\Sigmatel
[2009/01/26 22:57:34 | 000,000,000 | ---D | M] -- C:\Program Files\SiteAdvisor
[2009/10/25 11:03:41 | 000,000,000 | ---D | M] -- C:\Program Files\Smilebox
[2010/02/04 10:29:46 | 000,000,000 | ---D | M] -- C:\Program Files\Spybot - Search & Destroy
[2009/06/27 21:07:23 | 000,000,000 | ---D | M] -- C:\Program Files\Star Defender 3
[2010/03/30 04:55:13 | 000,000,000 | ---D | M] -- C:\Program Files\Trend Micro
[2010/01/12 22:11:26 | 000,000,000 | ---D | M] -- C:\Program Files\TrendMicro
[2009/09/22 16:38:41 | 000,000,000 | ---D | M] -- C:\Program Files\UltraPlayer
[2005/08/16 03:50:18 | 000,000,000 | -H-D | M] -- C:\Program Files\Uninstall Information
[2010/04/03 16:36:02 | 000,000,000 | ---D | M] -- C:\Program Files\Veoh Networks
[2009/07/13 12:55:56 | 000,000,000 | ---D | M] -- C:\Program Files\VideoLAN
[2005/12/11 10:06:28 | 000,000,000 | ---D | M] -- C:\Program Files\WebCyberCoach
[2009/06/27 21:07:26 | 000,000,000 | ---D | M] -- C:\Program Files\Winamp
[2010/02/10 23:32:35 | 000,000,000 | ---D | M] -- C:\Program Files\Windows Defender
[2009/09/29 09:47:30 | 000,000,000 | ---D | M] -- C:\Program Files\Windows Installer Clean Up
[2009/06/27 21:07:26 | 000,000,000 | ---D | M] -- C:\Program Files\Windows Live
[2007/09/30 14:18:36 | 000,000,000 | ---D | M] -- C:\Program Files\Windows Media Connect 2
[2007/09/30 19:24:28 | 000,000,000 | ---D | M] -- C:\Program Files\Windows Media Player
[2008/09/05 20:28:55 | 000,000,000 | ---D | M] -- C:\Program Files\Windows NT
[2005/08/16 03:37:56 | 000,000,000 | ---D | M] -- C:\Program Files\Windows Plus
[2005/08/16 03:40:46 | 000,000,000 | -H-D | M] -- C:\Program Files\WindowsUpdate
[2010/04/03 07:16:00 | 000,000,000 | ---D | M] -- C:\Program Files\WinZip
[2005/08/16 03:43:46 | 000,000,000 | ---D | M] -- C:\Program Files\xerox
[2009/12/27 11:14:14 | 000,000,000 | ---D | M] -- C:\Program Files\Xvid
[2010/03/18 01:51:34 | 000,000,000 | ---D | M] -- C:\Program Files\Yahoo!
[2010/01/26 09:00:16 | 000,000,000 | ---D | M] -- C:\Program Files\Zune
[2009/09/29 00:06:46 | 000,000,000 | ---D | M] -- C:\Program Files\zune.old
[2008/12/29 23:24:20 | 000,000,000 | ---D | M] -- C:\Program Files\_uninstallation_info
< %appdata%\*.* >[2005/08/16 03:33:26 | 000,000,062 | -HS- | M] () -- C:\Documents and Settings\Chris\Application Data\desktop.ini
[2008/03/30 20:23:06 | 000,000,187 | ---- | M] () -- C:\Documents and Settings\Chris\Application Data\G-Force Prefs (WindowsMediaPlayer).txt
[2006/10/13 16:46:31 | 000,012,358 | ---- | M] () -- C:\Documents and Settings\Chris\Application Data\PFP120JCM.{PB
[2006/10/13 16:46:31 | 000,061,678 | ---- | M] () -- C:\Documents and Settings\Chris\Application Data\PFP120JPR.{PB
< MD5 for: AGP440.SYS >[2004/08/10 04:00:00 | 016,971,599 | ---- | M] () .cab file -- C:\i386\sp2.cab:AGP440.sys
[2004/08/10 04:00:00 | 016,971,599 | ---- | M] () .cab file -- C:\WINDOWS\Driver Cache\i386\sp2.cab:AGP440.sys
[2008/09/05 20:22:39 | 023,852,652 | ---- | M] () .cab file -- C:\WINDOWS\Driver Cache\i386\sp3.cab:AGP440.sys
[2008/09/05 20:22:39 | 023,852,652 | ---- | M] () .cab file -- C:\WINDOWS\ServicePackFiles\i386\sp3.cab:AGP440.sys
[2008/04/13 11:36:38 | 000,042,368 | ---- | M] (Microsoft Corporation) MD5=08FD04AA961BDC77FB983F328334E3D7 -- C:\WINDOWS\ERDNT\cache\agp440.sys
[2008/04/13 11:36:38 | 000,042,368 | ---- | M] (Microsoft Corporation) MD5=08FD04AA961BDC77FB983F328334E3D7 -- C:\WINDOWS\ServicePackFiles\i386\agp440.sys
[2008/04/13 11:36:38 | 000,042,368 | ---- | M] (Microsoft Corporation) MD5=08FD04AA961BDC77FB983F328334E3D7 -- C:\WINDOWS\system32\drivers\agp440.sys
[2004/08/03 22:07:42 | 000,042,368 | ---- | M] (Microsoft Corporation) MD5=2C428FA0C3E3A01ED93C9B2A27D8D4BB -- C:\i386\AGP440.SYS
[2004/08/03 22:07:42 | 000,042,368 | ---- | M] (Microsoft Corporation) MD5=2C428FA0C3E3A01ED93C9B2A27D8D4BB -- C:\WINDOWS\$NtServicePackUninstall$\agp440.sys
< MD5 for: ATAPI.SYS >[2004/08/10 04:00:00 | 016,971,599 | ---- | M] () .cab file -- C:\i386\sp2.cab:atapi.sys
[2004/08/10 04:00:00 | 016,971,599 | ---- | M] () .cab file -- C:\WINDOWS\Driver Cache\i386\sp2.cab:atapi.sys
[2008/09/05 20:22:39 | 023,852,652 | ---- | M] () .cab file -- C:\WINDOWS\Driver Cache\i386\sp3.cab:atapi.sys
[2008/09/05 20:22:39 | 023,852,652 | ---- | M] () .cab file -- C:\WINDOWS\ServicePackFiles\i386\sp3.cab:atapi.sys
[2008/04/13 11:40:30 | 000,096,512 | ---- | M] (Microsoft Corporation) MD5=9F3A2F5AA6875C72BF062C712CFA2674 -- C:\WINDOWS\ERDNT\cache\atapi.sys
[2008/04/13 11:40:30 | 000,096,512 | ---- | M] (Microsoft Corporation) MD5=9F3A2F5AA6875C72BF062C712CFA2674 -- C:\WINDOWS\ServicePackFiles\i386\atapi.sys
[2008/04/13 11:40:30 | 000,096,512 | ---- | M] (Microsoft Corporation) MD5=9F3A2F5AA6875C72BF062C712CFA2674 -- C:\WINDOWS\system32\drivers\atapi.sys
[2004/08/03 21:59:44 | 000,095,360 | ---- | M] (Microsoft Corporation) MD5=CDFE4411A69C224BD1D11B2DA92DAC51 -- C:\i386\atapi.sys
[2004/08/03 21:59:44 | 000,095,360 | ---- | M] (Microsoft Corporation) MD5=CDFE4411A69C224BD1D11B2DA92DAC51 -- C:\WINDOWS\$NtServicePackUninstall$\atapi.sys
[2004/08/03 21:59:44 | 000,095,360 | ---- | M] (Microsoft Corporation) MD5=CDFE4411A69C224BD1D11B2DA92DAC51 -- C:\WINDOWS\system32\ReinstallBackups\0003\DriverFiles\i386\atapi.sys
[2004/08/03 21:59:44 | 000,095,360 | ---- | M] (Microsoft Corporation) MD5=CDFE4411A69C224BD1D11B2DA92DAC51 -- C:\WINDOWS\system32\ReinstallBackups\0012\DriverFiles\i386\atapi.sys
< MD5 for: DISK.SYS >[2004/08/10 04:00:00 | 016,971,599 | ---- | M] () .cab file -- C:\i386\sp2.cab:disk.sys
[2004/08/10 04:00:00 | 016,971,599 | ---- | M] () .cab file -- C:\WINDOWS\Driver Cache\i386\sp2.cab:disk.sys
[2008/09/05 20:22:39 | 023,852,652 | ---- | M] () .cab file -- C:\WINDOWS\Driver Cache\i386\sp3.cab:disk.sys
[2008/09/05 20:22:39 | 023,852,652 | ---- | M] () .cab file -- C:\WINDOWS\ServicePackFiles\i386\sp3.cab:disk.sys
[2004/08/10 04:00:00 | 000,036,352 | ---- | M] (Microsoft Corporation) MD5=00CA44E4534865F8A3B64F7C0984BFF0 -- C:\i386\disk.sys
[2004/08/10 04:00:00 | 000,036,352 | ---- | M] (Microsoft Corporation) MD5=00CA44E4534865F8A3B64F7C0984BFF0 -- C:\WINDOWS\$NtServicePackUninstall$\disk.sys
[2008/04/13 11:40:47 | 000,036,352 | ---- | M] (Microsoft Corporation) MD5=044452051F3E02E7963599FC8F4F3E25 -- C:\WINDOWS\ServicePackFiles\i386\disk.sys
[2008/04/13 11:40:47 | 000,036,352 | ---- | M] (Microsoft Corporation) MD5=044452051F3E02E7963599FC8F4F3E25 -- C:\WINDOWS\system32\drivers\disk.sys
< MD5 for: EVENTLOG.DLL >[2008/04/13 17:11:53 | 000,056,320 | ---- | M] (Microsoft Corporation) MD5=6D4FEB43EE538FC5428CC7F0565AA656 -- C:\WINDOWS\ERDNT\cache\eventlog.dll
[2008/04/13 17:11:53 | 000,056,320 | ---- | M] (Microsoft Corporation) MD5=6D4FEB43EE538FC5428CC7F0565AA656 -- C:\WINDOWS\ServicePackFiles\i386\eventlog.dll
[2008/04/13 17:11:53 | 000,056,320 | ---- | M] (Microsoft Corporation) MD5=6D4FEB43EE538FC5428CC7F0565AA656 -- C:\WINDOWS\system32\eventlog.dll
[2004/08/10 04:00:00 | 000,055,808 | ---- | M] (Microsoft Corporation) MD5=82B24CB70E5944E6E34662205A2A5B78 -- C:\i386\eventlog.dll
[2004/08/10 04:00:00 | 000,055,808 | ---- | M] (Microsoft Corporation) MD5=82B24CB70E5944E6E34662205A2A5B78 -- C:\WINDOWS\$NtServicePackUninstall$\eventlog.dll
< MD5 for: NETLOGON.DLL >[2008/04/13 17:12:01 | 000,407,040 | ---- | M] (Microsoft Corporation) MD5=1B7F071C51B77C272875C3A23E1E4550 -- C:\WINDOWS\ERDNT\cache\netlogon.dll
[2008/04/13 17:12:01 | 000,407,040 | ---- | M] (Microsoft Corporation) MD5=1B7F071C51B77C272875C3A23E1E4550 -- C:\WINDOWS\ServicePackFiles\i386\netlogon.dll
[2008/04/13 17:12:01 | 000,407,040 | ---- | M] (Microsoft Corporation) MD5=1B7F071C51B77C272875C3A23E1E4550 -- C:\WINDOWS\system32\netlogon.dll
[2004/08/10 04:00:00 | 000,407,040 | ---- | M] (Microsoft Corporation) MD5=96353FCECBA774BB8DA74A1C6507015A -- C:\i386\netlogon.dll
[2004/08/10 04:00:00 | 000,407,040 | ---- | M] (Microsoft Corporation) MD5=96353FCECBA774BB8DA74A1C6507015A -- C:\WINDOWS\$NtServicePackUninstall$\netlogon.dll
< MD5 for: SCECLI.DLL >[2004/08/10 04:00:00 | 000,180,224 | ---- | M] (Microsoft Corporation) MD5=0F78E27F563F2AAF74B91A49E2ABF19A -- C:\i386\scecli.dll
[2004/08/10 04:00:00 | 000,180,224 | ---- | M] (Microsoft Corporation) MD5=0F78E27F563F2AAF74B91A49E2ABF19A -- C:\WINDOWS\$NtServicePackUninstall$\scecli.dll
[2008/04/13 17:12:05 | 000,181,248 | ---- | M] (Microsoft Corporation) MD5=A86BB5E61BF3E39B62AB4C7E7085A084 -- C:\WINDOWS\ERDNT\cache\scecli.dll
[2008/04/13 17:12:05 | 000,181,248 | ---- | M] (Microsoft Corporation) MD5=A86BB5E61BF3E39B62AB4C7E7085A084 -- C:\WINDOWS\ServicePackFiles\i386\scecli.dll
[2008/04/13 17:12:05 | 000,181,248 | ---- | M] (Microsoft Corporation) MD5=A86BB5E61BF3E39B62AB4C7E7085A084 -- C:\WINDOWS\system32\scecli.dll
< MD5 for: USBSTOR.SYS >[2004/08/10 04:00:00 | 016,971,599 | ---- | M] () .cab file -- C:\i386\sp2.cab:usbstor.sys
[2004/08/10 04:00:00 | 016,971,599 | ---- | M] () .cab file -- C:\WINDOWS\Driver Cache\i386\sp2.cab:usbstor.sys
[2008/09/05 20:22:39 | 023,852,652 | ---- | M] () .cab file -- C:\WINDOWS\Driver Cache\i386\sp3.cab:usbstor.sys
[2008/09/05 20:22:39 | 023,852,652 | ---- | M] () .cab file -- C:\WINDOWS\ServicePackFiles\i386\sp3.cab:usbstor.sys
[2004/08/04 00:08:48 | 000,026,496 | ---- | M] (Microsoft Corporation) MD5=6CD7B22193718F1D17A47A1CD6D37E75 -- C:\WINDOWS\$NtServicePackUninstall$\usbstor.sys
[2008/04/13 11:45:38 | 000,026,368 | ---- | M] (Microsoft Corporation) MD5=A32426D9B14A089EAA1D922E0C5801A9 -- C:\WINDOWS\ServicePackFiles\i386\usbstor.sys
[2008/04/13 11:45:38 | 000,026,368 | ---- | M] (Microsoft Corporation) MD5=A32426D9B14A089EAA1D922E0C5801A9 -- C:\WINDOWS\system32\drivers\usbstor.sys
< HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\WindowsUpdate\Auto Update\Results\Install|LastSuccessTime /rs >HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\WindowsUpdate\Auto Update\Results\Install\\LastSuccessTime: 2010-04-11 23:39:37
< > < > ========== Alternate Data Streams ========== @Alternate Data Stream - 96 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:1A44AF1B
@Alternate Data Stream - 217 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:260575F1
@Alternate Data Stream - 216 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:89C6F032
@Alternate Data Stream - 212 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:072F1F69
@Alternate Data Stream - 131 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:EF5B3572
@Alternate Data Stream - 130 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:47BC930A
@Alternate Data Stream - 130 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:43A31AEA
@Alternate Data Stream - 129 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:15552B00
@Alternate Data Stream - 128 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:437B9941
@Alternate Data Stream - 124 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:DE0ED846
@Alternate Data Stream - 124 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:3FD496E1
@Alternate Data Stream - 123 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:A18D1A5B
@Alternate Data Stream - 123 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:1F0C9230
@Alternate Data Stream - 123 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:0B3B557D
@Alternate Data Stream - 122 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:A60E1551
@Alternate Data Stream - 122 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:5EC637CB
@Alternate Data Stream - 121 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:45E9EFF4
@Alternate Data Stream - 120 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:D8AE60A7
@Alternate Data Stream - 120 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:1B3349CB
@Alternate Data Stream - 118 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:BA05E0C4
@Alternate Data Stream - 117 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:BB6ECE53
@Alternate Data Stream - 115 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:D48500F8
@Alternate Data Stream - 115 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:6E2A6B4A
@Alternate Data Stream - 114 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:D1713795
@Alternate Data Stream - 113 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:3D36932D
@Alternate Data Stream - 111 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:F1175E1D
@Alternate Data Stream - 111 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:D09AEE3D
@Alternate Data Stream - 111 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:60A4BB64
@Alternate Data Stream - 110 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:55E1514E
@Alternate Data Stream - 110 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:45F3AD49
@Alternate Data Stream - 108 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:A31B5E9B
@Alternate Data Stream - 108 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:81E7CF6A
@Alternate Data Stream - 105 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:F02F4882
@Alternate Data Stream - 103 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:429EC15A
@Alternate Data Stream - 103 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:4220A65C
@Alternate Data Stream - 102 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:D49F2659
@Alternate Data Stream - 102 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:C07A6A6B
@Alternate Data Stream - 101 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:31D2961C
@Alternate Data Stream - 101 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:2FC7B9E4
@Alternate Data Stream - 100 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:CF61CE5A
< End of report >