2011/06/08 17:22:16 | 000,580,096 | ---- | C] (OldTimer Tools) -- C:\Documents and Settings\HP_Administrator.SOPHIA\Desktop\OTL.com
[2011/06/07 21:40:41 | 000,000,000 | -H-D | C] -- C:\WINDOWS\PIF
[2011/05/22 09:52:52 | 000,404,640 | ---- | C] (Adobe Systems Incorporated) -- C:\WINDOWS\System32\FlashPlayerCPLApp.cpl
[2008/12/27 22:39:26 | 000,098,304 | R--- | C] ( ) -- C:\WINDOWS\System32\rsnpstd.dll
[2008/12/27 22:39:25 | 000,061,440 | R--- | C] ( ) -- C:\WINDOWS\System32\csnpstd.dll
[2008/12/27 22:38:55 | 000,036,864 | R--- | C] ( ) -- C:\WINDOWS\System32\vsnpstd.dll
[2008/03/02 12:04:35 | 000,774,144 | ---- | C] (RealNetworks, Inc.) -- C:\Program Files\RngInterstitial.dll
[1 C:\WINDOWS\System32\*.tmp files -> C:\WINDOWS\System32\*.tmp -> ]
[1 C:\WINDOWS\*.tmp files -> C:\WINDOWS\*.tmp -> ]
========== Files - Modified Within 30 Days ==========
[2011/06/08 17:22:16 | 000,580,096 | ---- | M] (OldTimer Tools) -- C:\Documents and Settings\HP_Administrator.SOPHIA\Desktop\OTL.com
[2011/06/08 17:17:01 | 000,002,048 | --S- | M] () -- C:\WINDOWS\bootstat.dat
[2011/06/07 22:15:07 | 000,054,156 | -H-- | M] () -- C:\WINDOWS\QTFont.qfn
[2011/06/07 22:08:44 | 000,002,855 | ---- | M] () -- C:\Documents and Settings\HP_Administrator.SOPHIA\Desktop\Shortcut to OTL.com.pif
[2011/06/07 21:27:54 | 000,000,902 | ---- | M] () -- C:\WINDOWS\tasks\GoogleUpdateTaskMachineCore.job
[2011/06/07 21:27:51 | 000,000,410 | ---- | M] () -- C:\WINDOWS\tasks\AVG PC Tuneup 2011 Integrator Start On Windows Logon.job
[2011/06/06 20:10:55 | 000,000,552 | ---- | M] () -- C:\WINDOWS\System32\d3d8caps.dat
[2011/06/05 22:51:36 | 000,000,906 | ---- | M] () -- C:\WINDOWS\tasks\GoogleUpdateTaskMachineUA.job
[2011/06/05 19:53:47 | 000,000,452 | ---- | M] () -- C:\Documents and Settings\HP_Administrator.SOPHIA\My Documents\spider.sav
[2011/06/05 17:44:53 | 117,308,668 | ---- | M] () -- C:\WINDOWS\System32\drivers\AVG\incavi.avm
[2011/06/05 13:25:00 | 000,000,350 | ---- | M] () -- C:\WINDOWS\tasks\Norton PC Checkup Weekend Scanner.job
[2011/06/01 20:07:00 | 000,000,350 | ---- | M] () -- C:\WINDOWS\tasks\Norton PC Checkup WeekDay Scanner.job
[2011/05/29 09:11:30 | 000,039,984 | ---- | M] (Malwarebytes Corporation) -- C:\WINDOWS\System32\drivers\mbamswissarmy.sys
[2011/05/29 09:11:20 | 000,022,712 | ---- | M] (Malwarebytes Corporation) -- C:\WINDOWS\System32\drivers\mbam.sys
[2011/05/25 22:39:29 | 000,001,824 | ---- | M] () -- C:\Documents and Settings\All Users\Desktop\Google Chrome.lnk
[2011/05/25 18:00:44 | 000,002,709 | ---- | M] () -- C:\Documents and Settings\All Users\Desktop\Start WordPerfect Office X3 - Home Edition.lnk
[2011/05/23 18:29:38 | 000,001,682 | -HS- | M] () -- C:\WINDOWS\System32\KGyGaAvL.sys
[2011/05/22 09:52:52 | 000,404,640 | ---- | M] (Adobe Systems Incorporated) -- C:\WINDOWS\System32\FlashPlayerCPLApp.cpl
[2011/05/14 20:38:12 | 000,001,438 | -HS- | M] () -- C:\Documents and Settings\HP_Administrator.SOPHIA\Local Settings\Application Data\5lnfw71gfl5222x1d77ctwk735dv1vk6wbh2s67hy78q7
[2011/05/14 20:38:12 | 000,001,438 | -HS- | M] () -- C:\Documents and Settings\All Users\Application Data\5lnfw71gfl5222x1d77ctwk735dv1vk6wbh2s67hy78q7
[1 C:\WINDOWS\System32\*.tmp files -> C:\WINDOWS\System32\*.tmp -> ]
[1 C:\WINDOWS\*.tmp files -> C:\WINDOWS\*.tmp -> ]
========== Files Created - No Company Name ==========
[2011/06/07 21:40:41 | 000,002,855 | ---- | C] () -- C:\Documents and Settings\HP_Administrator.SOPHIA\Desktop\Shortcut to OTL.com.pif
[2011/06/06 20:10:55 | 000,000,552 | ---- | C] () -- C:\WINDOWS\System32\d3d8caps.dat
[2011/05/14 20:26:20 | 000,001,438 | -HS- | C] () -- C:\Documents and Settings\HP_Administrator.SOPHIA\Local Settings\Application Data\5lnfw71gfl5222x1d77ctwk735dv1vk6wbh2s67hy78q7
[2011/05/14 20:26:20 | 000,001,438 | -HS- | C] () -- C:\Documents and Settings\All Users\Application Data\5lnfw71gfl5222x1d77ctwk735dv1vk6wbh2s67hy78q7
[2011/04/09 14:22:28 | 000,014,424 | -HS- | C] () -- C:\Documents and Settings\HP_Administrator.SOPHIA\Local Settings\Application Data\178748ryx4
[2011/04/09 14:22:28 | 000,014,424 | -HS- | C] () -- C:\Documents and Settings\All Users\Application Data\178748ryx4
[2011/01/11 19:37:30 | 000,000,000 | ---- | C] () -- C:\WINDOWS\Textart.INI
[2010/04/09 12:10:06 | 000,000,000 | ---- | C] () -- C:\Documents and Settings\HP_Administrator.SOPHIA\Local Settings\Application Data\prvlcl.dat
[2010/03/31 14:07:57 | 000,000,064 | ---- | C] () -- C:\WINDOWS\System32\rp_stats.dat
[2010/03/31 14:07:57 | 000,000,044 | ---- | C] () -- C:\WINDOWS\System32\rp_rules.dat
[2010/01/29 19:40:34 | 000,012,252 | -HS- | C] () -- C:\Documents and Settings\HP_Administrator.SOPHIA\Local Settings\Application Data\yq26
[2009/10/18 15:00:25 | 000,008,704 | ---- | C] () -- C:\WINDOWS\System32\CNMVS75.DLL
[2009/01/03 00:31:35 | 000,001,682 | -HS- | C] () -- C:\WINDOWS\System32\KGyGaAvL.sys
[2009/01/01 20:52:36 | 000,009,728 | ---- | C] () -- C:\Documents and Settings\HP_Administrator.SOPHIA\Local Settings\Application Data\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2008/12/27 22:39:23 | 000,053,248 | R--- | C] () -- C:\WINDOWS\System32\dsnpstd.dll
[2008/12/27 22:38:53 | 000,387,840 | R--- | C] () -- C:\WINDOWS\System32\drivers\snpstd.sys
[2008/12/27 22:35:18 | 000,000,146 | ---- | C] () -- C:\Documents and Settings\HP_Administrator.SOPHIA\Local Settings\Application Data\fusioncache.dat
[2008/03/28 19:29:41 | 000,000,165 | ---- | C] () -- C:\WINDOWS\popcinfo.dat
[2008/02/01 22:26:54 | 000,000,263 | ---- | C] () -- C:\WINDOWS\cncscore.ini
[2007/09/24 19:53:09 | 000,000,025 | ---- | C] () -- C:\WINDOWS\cdplayer.ini
[2007/09/21 16:32:57 | 000,004,096 | ---- | C] () -- C:\WINDOWS\d3dx.dat
[2007/05/12 14:24:23 | 000,131,072 | ---- | C] () -- C:\WINDOWS\SNVerifyDLL.dll
[2007/05/12 13:43:27 | 000,000,004 | ---- | C] () -- C:\WINDOWS\msoffice.ini
[2006/12/03 18:44:02 | 000,003,584 | ---- | C] () -- C:\WINDOWS\mozver.dat
[2006/12/03 18:42:27 | 000,000,083 | ---- | C] () -- C:\WINDOWS\gbsaver.ini
[2006/07/20 17:43:19 | 000,000,047 | ---- | C] () -- C:\WINDOWS\NeroDigital.ini
[2006/06/08 12:16:11 | 000,000,251 | ---- | C] () -- C:\Program Files\wt3d.ini
[2006/06/08 09:26:48 | 000,006,550 | ---- | C] () -- C:\WINDOWS\jautoexp.dat
[2006/05/30 16:12:33 | 000,000,335 | ---- | C] () -- C:\WINDOWS\nsreg.dat
[2006/05/30 16:06:33 | 000,015,541 | R--- | C] () -- C:\WINDOWS\snpstd.ini
[2006/05/23 19:52:14 | 000,286,720 | R--- | C] () -- C:\WINDOWS\vsnpstd.exe
[2005/12/15 22:44:17 | 000,159,743 | ---- | C] () -- C:\WINDOWS\Google Pack Screensaver Uninstaller.exe
[2005/05/26 14:10:37 | 000,000,061 | ---- | C] () -- C:\WINDOWS\smscfg.ini
[2005/05/26 14:08:00 | 000,204,800 | ---- | C] () -- C:\WINDOWS\System32\IVIresizeW7.dll
[2005/05/26 14:08:00 | 000,200,704 | ---- | C] () -- C:\WINDOWS\System32\IVIresizeA6.dll
[2005/05/26 14:08:00 | 000,192,512 | ---- | C] () -- C:\WINDOWS\System32\IVIresizeP6.dll
[2005/05/26 14:08:00 | 000,192,512 | ---- | C] () -- C:\WINDOWS\System32\IVIresizeM6.dll
[2005/05/26 14:08:00 | 000,188,416 | ---- | C] () -- C:\WINDOWS\System32\IVIresizePX.dll
[2005/05/26 14:08:00 | 000,020,480 | ---- | C] () -- C:\WINDOWS\System32\IVIresize.dll
[2005/05/26 14:07:27 | 000,001,040 | ---- | C] () -- C:\WINDOWS\System32\drivers\alcxinit.dat
[2005/05/26 13:40:25 | 000,118,784 | R--- | C] () -- C:\WINDOWS\bwUnin-6.3.2.62.exe
[2005/05/26 13:39:53 | 000,015,328 | ---- | C] () -- C:\WINDOWS\System32\CHODDI.SYS
[2005/05/26 13:39:48 | 000,045,056 | ---- | C] () -- C:\WINDOWS\System32\hpreg.dll
[2005/05/26 13:39:34 | 000,002,150 | ---- | C] () -- C:\WINDOWS\System32\ssmute.ini
[2005/05/26 13:36:41 | 000,000,376 | ---- | C] () -- C:\WINDOWS\ODBC.INI
[2005/05/26 13:23:39 | 000,047,832 | ---- | C] () -- C:\WINDOWS\hpiins01.dat
[2005/05/26 13:23:39 | 000,000,000 | ---- | C] () -- C:\WINDOWS\hpimdl01.dat
[2005/05/26 13:22:30 | 000,094,364 | ---- | C] () -- C:\WINDOWS\HPHins03.dat
[2005/05/26 13:22:30 | 000,002,655 | ---- | C] () -- C:\WINDOWS\hphmdl03.dat
[2005/05/26 13:20:45 | 000,069,000 | ---- | C] () -- C:\WINDOWS\hpoins05.dat
[2005/05/26 13:20:45 | 000,019,696 | ---- | C] () -- C:\WINDOWS\hpomdl05.dat
[2005/05/26 13:17:16 | 000,050,500 | ---- | C] () -- C:\WINDOWS\hpdins05.dat
[2005/05/26 13:17:16 | 000,000,000 | ---- | C] () -- C:\WINDOWS\hpdmdl01.dat
[2005/05/26 13:16:03 | 000,001,793 | ---- | C] () -- C:\WINDOWS\System32\fxsperf.ini
[2005/05/26 13:10:00 | 000,079,320 | ---- | C] () -- C:\WINDOWS\System32\atiicdxx.dat
[2005/05/26 12:58:07 | 000,000,791 | ---- | C] () -- C:\WINDOWS\orun32.ini
[2005/05/26 12:56:13 | 000,323,584 | ---- | C] () -- C:\WINDOWS\System32\pythoncom22.dll
[2005/05/26 12:56:13 | 000,094,208 | ---- | C] () -- C:\WINDOWS\System32\pywintypes22.dll
[2005/05/26 12:55:53 | 000,016,896 | ---- | C] () -- C:\WINDOWS\System32\bcbmm.dll
[2005/02/18 13:56:18 | 000,000,000 | ---- | C] () -- C:\WINDOWS\System32\px.ini
[2005/01/28 05:55:32 | 000,002,048 | --S- | C] () -- C:\WINDOWS\bootstat.dat
[2005/01/28 05:47:28 | 000,442,796 | ---- | C] () -- C:\WINDOWS\System32\perfh009.dat
[2005/01/28 05:47:28 | 000,071,936 | ---- | C] () -- C:\WINDOWS\System32\perfc009.dat
[2005/01/28 05:45:04 | 000,213,672 | ---- | C] () -- C:\WINDOWS\System32\FNTCACHE.DAT
[2005/01/28 05:41:00 | 000,004,161 | ---- | C] () -- C:\WINDOWS\ODBCINST.INI
[2005/01/28 05:36:46 | 000,021,640 | ---- | C] () -- C:\WINDOWS\System32\emptyregdb.dat
[2005/01/20 01:45:40 | 000,090,112 | ---- | C] () -- C:\WINDOWS\System32\PcdrKernelModeServices.dll
[2005/01/20 01:45:40 | 000,065,536 | ---- | C] () -- C:\WINDOWS\System32\ProgressTrace.dll
[2004/08/10 14:00:00 | 000,004,569 | ---- | C] () -- C:\WINDOWS\System32\secupd.dat
[2004/08/10 08:00:00 | 000,673,088 | ---- | C] () -- C:\WINDOWS\System32\mlang.dat
[2004/08/10 08:00:00 | 000,272,128 | ---- | C] () -- C:\WINDOWS\System32\perfi009.dat
[2004/08/10 08:00:00 | 000,218,003 | ---- | C] () -- C:\WINDOWS\System32\dssec.dat
[2004/08/10 08:00:00 | 000,046,258 | ---- | C] () -- C:\WINDOWS\System32\mib.bin
[2004/08/10 08:00:00 | 000,028,626 | ---- | C] () -- C:\WINDOWS\System32\perfd009.dat
[2004/08/10 08:00:00 | 000,001,788 | ---- | C] () -- C:\WINDOWS\System32\Dcache.bin
[2004/08/10 08:00:00 | 000,000,741 | ---- | C] () -- C:\WINDOWS\System32\noise.dat
[2004/07/26 17:51:38 | 000,000,560 | ---- | C] () -- C:\WINDOWS\System32\oeminfo.ini
[2004/06/07 14:32:52 | 000,009,505 | ---- | C] () -- C:\WINDOWS\System32\hphmon06.dat
[2004/03/18 08:44:29 | 001,663,068 | ---- | C] () -- C:\WINDOWS\System32\libmmd.dll
[2003/11/10 17:06:08 | 000,406,016 | ---- | C] () -- C:\WINDOWS\System32\PSDrvCheck.exe
[2003/04/11 01:04:00 | 000,028,672 | ---- | C] () -- C:\WINDOWS\System32\JAWTAccessBridge.dll
[2003/01/08 01:05:08 | 000,002,695 | ---- | C] () -- C:\WINDOWS\System32\OUTLPERF.INI
[2001/08/23 19:12:28 | 013,107,200 | ---- | C] () -- C:\WINDOWS\System32\oembios.bin
[2001/08/23 19:11:02 | 000,004,490 | ---- | C] () -- C:\WINDOWS\System32\oembios.dat
========== Custom Scans ==========
< %systemroot%\*. /mp /s >
< %systemroot%\system32\*.dll /lockedfiles >
[1 C:\WINDOWS\system32\*.tmp files -> C:\WINDOWS\system32\*.tmp -> ]
< %systemroot%\system32\*.exe /lockedfiles >
[1 C:\WINDOWS\system32\*.tmp files -> C:\WINDOWS\system32\*.tmp -> ]
< %systemroot%\Tasks\*.job /lockedfiles >
< %systemroot%\system32\drivers\*.sys /lockedfiles >
< %systemroot%\System32\config\*.sav >
[2005/01/27 21:28:56 | 000,094,208 | ---- | M] () -- C:\WINDOWS\system32\config\default.sav
[2005/01/27 21:28:56 | 000,659,456 | ---- | M] () -- C:\WINDOWS\system32\config\software.sav
[2005/01/27 21:28:56 | 000,872,448 | ---- | M] () -- C:\WINDOWS\system32\config\system.sav
< %systemroot%\system32\*.sys >
[2004/08/10 08:00:00 | 000,009,029 | ---- | M] () -- C:\WINDOWS\system32\ansi.sys
[2005/05/26 13:39:53 | 000,015,328 | ---- | M] () -- C:\WINDOWS\system32\CHODDI.SYS
[2004/08/10 08:00:00 | 000,027,097 | ---- | M] () -- C:\WINDOWS\system32\country.sys
[2004/08/10 08:00:00 | 000,004,768 | ---- | M] () -- C:\WINDOWS\system32\himem.sys
[2004/08/10 08:00:00 | 000,042,809 | ---- | M] () -- C:\WINDOWS\system32\key01.sys
[2004/08/10 08:00:00 | 000,042,537 | ---- | M] () -- C:\WINDOWS\system32\keyboard.sys
[2011/05/23 18:29:38 | 000,001,682 | -HS- | M] () -- C:\WINDOWS\system32\KGyGaAvL.sys
[2004/08/10 08:00:00 | 000,027,866 | ---- | M] () -- C:\WINDOWS\system32\ntdos.sys
[2004/08/10 08:00:00 | 000,029,146 | ---- | M] () -- C:\WINDOWS\system32\ntdos404.sys
[2004/08/10 08:00:00 | 000,029,370 | ---- | M] () -- C:\WINDOWS\system32\ntdos411.sys
[2004/08/10 08:00:00 | 000,029,274 | ---- | M] () -- C:\WINDOWS\system32\ntdos412.sys
[2004/08/10 08:00:00 | 000,029,146 | ---- | M] () -- C:\WINDOWS\system32\ntdos804.sys
[2004/08/10 08:00:00 | 000,033,840 | ---- | M] () -- C:\WINDOWS\system32\ntio.sys
[2004/08/10 08:00:00 | 000,034,560 | ---- | M] () -- C:\WINDOWS\system32\ntio404.sys
[2004/08/10 08:00:00 | 000,035,648 | ---- | M] () -- C:\WINDOWS\system32\ntio411.sys
[2004/08/10 08:00:00 | 000,035,424 | ---- | M] () -- C:\WINDOWS\system32\ntio412.sys
[2004/08/10 08:00:00 | 000,034,560 | ---- | M] () -- C:\WINDOWS\system32\ntio804.sys
[2004/08/10 08:00:00 | 000,017,664 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\system32\watchdog.sys
[2010/05/02 01:56:34 | 001,850,880 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\system32\win32k.sys
[1 C:\WINDOWS\system32\*.tmp files -> C:\WINDOWS\system32\*.tmp -> ]
< %systemroot%\system32\drivers\*.dll >
[2005/03/15 00:26:22 | 000,036,864 | ---- | M] (ATI Technologies Inc.) -- C:\WINDOWS\system32\drivers\ati2erec.dll
< %systemroot%\system32\drivers\*.ini >
< %systemroot%\system32\drivers\*.exe >
< %SYSTEMDRIVE%\*.* >
[2010/12/05 18:38:23 | 000,168,276 | ---- | M] () -- C:\aaw7boot.log
[2005/05/26 14:08:45 | 000,000,100 | ---- | M] () -- C:\AUTOEXEC.BAT
[2008/12/27 22:32:44 | 000,000,211 | RHS- | M] () -- C:\BOOT.BAK
[2008/12/27 21:11:29 | 000,000,279 | RHS- | M] () -- C:\boot.ini
[2004/08/10 08:00:00 | 000,260,272 | RHS- | M] () -- C:\cmldr
[2010/02/23 20:38:56 | 000,018,856 | ---- | M] () -- C:\ComboFix.txt
[2005/01/28 05:41:28 | 000,000,000 | ---- | M] () -- C:\CONFIG.SYS
[2005/01/28 05:41:28 | 000,000,000 | RHS- | M] () -- C:\IO.SYS
[2007/07/23 11:56:00 | 000,002,281 | -H-- | M] () -- C:\IPH.PH
[2005/01/28 05:41:28 | 000,000,000 | RHS- | M] () -- C:\MSDOS.SYS
[2004/08/10 08:00:00 | 000,047,564 | RHS- | M] () -- C:\NTDETECT.COM
[2004/08/10 08:00:00 | 000,250,032 | RHS- | M] () -- C:\ntldr
[2011/06/08 17:16:54 | 1409,286,144 | -HS- | M] () -- C:\pagefile.sys
[2010/04/24 19:09:06 | 000,020,387 | ---- | M] () -- C:\time linr.wpd
[2008/12/28 01:10:21 | 000,000,595 | ---- | M] () -- C:\YServer.txt
< %PROGRAMFILES%\*. >
[2007/03/12 22:15:08 | 000,000,000 | ---D | M] -- C:\Program Files\3DGroove
[2010/11/26 09:52:13 | 000,000,000 | ---D | M] -- C:\Program Files\Adobe
[2008/03/02 15:32:57 | 000,000,000 | ---D | M] -- C:\Program Files\Alice Greenfingers
[2009/08/11 23:06:09 | 000,000,000 | ---D | M] -- C:\Program Files\Angle Interactive
[2006/05/23 19:53:05 | 000,000,000 | ---D | M] -- C:\Program Files\ArcSoft
[2006/11/11 19:30:09 | 000,000,000 | ---D | M] -- C:\Program Files\Atari
[2005/05/26 14:07:08 | 000,000,000 | ---D | M] -- C:\Program Files\ATI Technologies
[2011/02/05 13:04:57 | 000,000,000 | ---D | M] -- C:\Program Files\AVG
[2005/05/26 13:40:25 | 000,000,000 | ---D | M] -- C:\Program Files\BackWeb
[2006/05/23 20:32:18 | 000,000,000 | ---D | M] -- C:\Program Files\Canon
[2008/01/25 22:26:31 | 000,000,000 | ---D | M] -- C:\Program Files\Coin World
[2010/02/23 20:34:07 | 000,000,000 | ---D | M] -- C:\Program Files\Common Files
[2005/01/27 17:38:38 | 000,000,000 | ---D | M] -- C:\Program Files\ComPlus Applications
[2006/05/23 19:37:22 | 000,000,000 | ---D | M] -- C:\Program Files\Corel
[2007/05/12 13:59:12 | 000,000,000 | ---D | M] -- C:\Program Files\DivX
[2010/04/22 17:15:37 | 000,000,000 | ---D | M] -- C:\Program Files\Easy Internet signup
[2007/04/12 23:11:19 | 000,000,000 | ---D | M] -- C:\Program Files\Easy Video Joiner
[2010/03/07 11:33:07 | 000,000,000 | ---D | M] -- C:\Program Files\FileHippo.com
[2008/12/22 20:09:02 | 000,000,000 | ---D | M] -- C:\Program Files\FlashGet
[2007/05/12 14:24:23 | 000,000,000 | ---D | M] -- C:\Program Files\Formosoft
[2010/03/01 19:08:04 | 000,000,000 | ---D | M] -- C:\Program Files\Google
[2007/09/09 16:13:56 | 000,000,000 | ---D | M] -- C:\Program Files\Grisoft
[2008/12/27 18:49:23 | 000,000,000 | ---D | M] -- C:\Program Files\Hasbro
[2005/05/26 13:21:42 | 000,000,000 | ---D | M] -- C:\Program Files\Hewlett-Packard
[2005/05/26 13:22:41 | 000,000,000 | ---D | M] -- C:\Program Files\HP
[2005/05/26 13:42:28 | 000,000,000 | ---D | M] -- C:\Program Files\HPQ
[2008/07/12 19:35:16 | 000,000,000 | ---D | M] -- C:\Program Files\iConcepts Music Express
[2006/07/20 17:41:48 | 000,000,000 | ---D | M] -- C:\Program Files\illiminable
[2010/03/14 13:57:14 | 000,000,000 | -H-D | M] -- C:\Program Files\InstallShield Installation Information
[2009/08/11 19:47:05 | 000,000,000 | ---D | M] -- C:\Program Files\IntelliMover Data Transfer Demo
[2005/05/26 13:39:32 | 000,000,000 | ---D | M] -- C:\Program Files\InterMute
[2010/03/02 23:04:14 | 000,000,000 | ---D | M] -- C:\Program Files\Internet Explorer
[2005/05/26 14:07:53 | 000,000,000 | ---D | M] -- C:\Program Files\InterVideo
[2005/05/26 13:37:12 | 000,000,000 | ---D | M] -- C:\Program Files\iPod
[2005/05/26 13:37:12 | 000,000,000 | ---D | M] -- C:\Program Files\iTunes
[2010/02/18 20:18:42 | 000,000,000 | ---D | M] -- C:\Program Files\Java
[2010/12/05 18:46:22 | 000,000,000 | ---D | M] -- C:\Program Files\Lavasoft
[2006/06/01 12:26:10 | 000,000,000 | ---D | M] -- C:\Program Files\Learn2.com
[2011/06/05 17:05:44 | 000,000,000 | ---D | M] -- C:\Program Files\Malwarebytes' Anti-Malware
[2008/12/30 01:32:59 | 000,000,000 | ---D | M] -- C:\Program Files\Messenger
[2005/05/26 13:36:01 | 000,000,000 | ---D | M] -- C:\Program Files\Microsoft ActiveSync
[2007/09/09 17:37:21 | 000,000,000 | ---D | M] -- C:\Program Files\Microsoft CAPICOM 2.1.0.2
[2005/01/27 21:46:42 | 000,000,000 | ---D | M] -- C:\Program Files\microsoft frontpage
[2005/05/26 13:35:50 | 000,000,000 | ---D | M] -- C:\Program Files\Microsoft Office
[2005/05/26 13:34:31 | 000,000,000 | ---D | M] -- C:\Program Files\Microsoft Plus! Dancer LE
[2005/05/26 13:34:42 | 000,000,000 | ---D | M] -- C:\Program Files\Microsoft Plus! Digital Media Edition
[2005/05/26 13:34:38 | 000,000,000 | ---D | M] -- C:\Program Files\Microsoft Plus! Photo Story 2 LE
[2011/03/03 23:14:07 | 000,000,000 | ---D | M] -- C:\Program Files\Microsoft Silverlight
[2005/05/26 13:35:50 | 000,000,000 | ---D | M] -- C:\Program Files\Microsoft Visual Studio
[2005/05/26 13:35:15 | 000,000,000 | ---D | M] -- C:\Program Files\Microsoft Works
[2005/05/26 13:35:37 | 000,000,000 | ---D | M] -- C:\Program Files\Microsoft.NET
[2010/03/11 23:22:11 | 000,000,000 | ---D | M] -- C:\Program Files\Movie Maker
[2011/05/08 21:32:50 | 000,000,000 | ---D | M] -- C:\Program Files\Mozilla Firefox
[2010/03/02 23:09:38 | 000,000,000 | ---D | M] -- C:\Program Files\MSBuild
[2005/01/27 21:46:48 | 000,000,000 | ---D | M] -- C:\Program Files\MSN
[2005/05/26 13:27:20 | 000,000,000 | ---D | M] -- C:\Program Files\MSN Encarta Standard
[2005/01/27 21:47:00 | 000,000,000 | ---D | M] -- C:\Program Files\MSN Gaming Zone
[2007/08/15 03:00:59 | 000,000,000 | ---D | M] -- C:\Program Files\MSXML 4.0
[2010/03/02 23:01:39 | 000,000,000 | ---D | M] -- C:\Program Files\MSXML 6.0
[2010/03/14 13:55:17 | 000,000,000 | ---D | M] -- C:\Program Files\muvee Technologies
[2008/12/27 22:22:51 | 000,000,000 | ---D | M] -- C:\Program Files\NetMeeting
[2008/12/17 20:13:21 | 000,000,000 | ---D | M] -- C:\Program Files\Norton PC Checkup
[2005/05/26 13:49:06 | 000,000,000 | ---D | M] -- C:\Program Files\Online Services
[2010/05/12 20:04:20 | 000,000,000 | ---D | M] -- C:\Program Files\Outlook Express
[2005/05/26 13:45:43 | 000,000,000 | ---D | M] -- C:\Program Files\PC-Doctor for DOS
[2005/05/26 13:45:33 | 000,000,000 | ---D | M] -- C:\Program Files\PC-Doctor for Windows
[2008/10/05 21:20:22 | 000,000,000 | ---D | M] -- C:\Program Files\Picasa2
[2008/12/03 18:17:41 | 000,000,000 | ---D | M] -- C:\Program Files\Platypus II
[2008/12/27 19:10:44 | 000,000,000 | ---D | M] -- C:\Program Files\Pogo
[2005/05/26 13:37:22 | 000,000,000 | ---D | M] -- C:\Program Files\QuickTime
[2005/05/26 13:27:50 | 000,000,000 | ---D | M] -- C:\Program Files\Real
[2010/03/02 23:09:23 | 000,000,000 | ---D | M] -- C:\Program Files\Reference Assemblies
[2007/09/07 09:42:13 | 000,000,000 | ---D | M] -- C:\Program Files\ReflexiveArcade
[2007/05/12 13:49:39 | 000,000,000 | ---D | M] -- C:\Program Files\RSSoft
[2008/12/03 18:17:36 | 000,000,000 | ---D | M] -- C:\Program Files\Sallys Salon
[2007/09/21 17:33:20 | 000,000,000 | ---D | M] -- C:\Program Files\SallysSalon_at
[2005/05/26 13:31:35 | 000,000,000 | ---D | M] -- C:\Program Files\Sonic
[2009/10/18 11:01:37 | 000,000,000 | ---D | M] -- C:\Program Files\Symantec
[2006/06/15 13:21:20 | 000,000,000 | ---D | M] -- C:\Program Files\SymNetDrv
[2005/01/27 17:38:48 | 000,000,000 | -H-D | M] -- C:\Program Files\Uninstall Information
[2005/05/26 13:40:23 | 000,000,000 | ---D | M] -- C:\Program Files\Updates from HP
[2009/03/10 15:28:32 | 000,000,000 | ---D | M] -- C:\Program Files\Veoh Networks
[2006/06/01 12:26:07 | 000,000,000 | ---D | M] -- C:\Program Files\Viewpoint
[2005/05/26 13:29:38 | 000,000,000 | ---D | M] -- C:\Program Files\WildTangent
[2008/12/27 22:22:52 | 000,000,000 | ---D | M] -- C:\Program Files\Windows Media Player
[2008/12/27 22:22:55 | 000,000,000 | ---D | M] -- C:\Program Files\Windows NT
[2005/01/27 21:47:50 | 000,000,000 | ---D | M] -- C:\Program Files\Windows Plus
[2005/01/27 17:38:56 | 000,000,000 | -H-D | M] -- C:\Program Files\WindowsUpdate
[2008/12/27 18:43:31 | 000,000,000 | ---D | M] -- C:\Program Files\WinRAR
[2006/05/23 19:36:05 | 000,000,000 | ---D | M] -- C:\Program Files\WordPerfect Office X3 - Home Edition
[2006/05/23 19:36:50 | 000,000,000 | ---D | M] -- C:\Program Files\WordPerfect OfficeReady 1.5
[2005/01/27 21:48:00 | 000,000,000 | ---D | M] -- C:\Program Files\xerox
[2010/07/16 21:55:20 | 000,000,000 | ---D | M] -- C:\Program Files\Yahoo!
< %appdata%\*.* >
[2005/01/27 21:30:22 | 000,000,062 | -HS- | M] () -- C:\Documents and Settings\HP_Administrator.SOPHIA\Application Data\desktop.ini
< MD5 for: AGP440.SYS >
[2004/08/10 14:00:00 | 016,971,599 | ---- | M] () .cab file -- C:\WINDOWS\Driver Cache\i386\sp2.cab:AGP440.sys
[2008/12/27 19:08:52 | 023,852,652 | ---- | M] () .cab file -- C:\WINDOWS\Driver Cache\i386\sp3.cab:AGP440.sys
[2004/08/10 08:00:00 | 016,971,599 | ---- | M] () .cab file -- C:\WINDOWS\I386\sp2.cab:AGP440.sys
[2008/12/27 19:08:52 | 023,852,652 | ---- | M] () .cab file -- C:\WINDOWS\ServicePackFiles\i386\sp3.cab:AGP440.sys
[2008/12/27 19:08:52 | 023,852,652 | ---- | M] () .cab file -- C:\WINDOWS\SoftwareDistribution\Download\79123dd72d0f61d4ed8c7a816ed338d7\sp3.cab:AGP440.sys
[2008/04/13 14:36:38 | 000,042,368 | ---- | M] (Microsoft Corporation) MD5=08FD04AA961BDC77FB983F328334E3D7 -- C:\WINDOWS\ServicePackFiles\i386\agp440.sys
[2008/04/13 14:36:38 | 000,042,368 | ---- | M] (Microsoft Corporation) MD5=08FD04AA961BDC77FB983F328334E3D7 -- C:\WINDOWS\SoftwareDistribution\Download\79123dd72d0f61d4ed8c7a816ed338d7\agp440.sys
[2008/04/13 14:36:38 | 000,042,368 | ---- | M] (Microsoft Corporation) MD5=08FD04AA961BDC77FB983F328334E3D7 -- C:\WINDOWS\SoftwareDistribution\Download\dd9ab5193501484cf5e6884fa1d22f9e\agp440.sys
< MD5 for: ATAPI.SYS >
[2004/08/10 14:00:00 | 016,971,599 | ---- | M] () .cab file -- C:\WINDOWS\Driver Cache\i386\sp2.cab:atapi.sys
[2008/12/27 19:08:52 | 023,852,652 | ---- | M] () .cab file -- C:\WINDOWS\Driver Cache\i386\sp3.cab:atapi.sys
[2004/08/10 08:00:00 | 016,971,599 | ---- | M] () .cab file -- C:\WINDOWS\I386\sp2.cab:atapi.sys
[2008/12/27 19:08:52 | 023,852,652 | ---- | M] () .cab file -- C:\WINDOWS\ServicePackFiles\i386\sp3.cab:atapi.sys
[2008/12/27 19:08:52 | 023,852,652 | ---- | M] () .cab file -- C:\WINDOWS\SoftwareDistribution\Download\79123dd72d0f61d4ed8c7a816ed338d7\sp3.cab:atapi.sys
[2008/04/13 14:40:30 | 000,096,512 | ---- | M] (Microsoft Corporation) MD5=9F3A2F5AA6875C72BF062C712CFA2674 -- C:\WINDOWS\ServicePackFiles\i386\atapi.sys
[2008/04/13 14:40:30 | 000,096,512 | ---- | M] (Microsoft Corporation) MD5=9F3A2F5AA6875C72BF062C712CFA2674 -- C:\WINDOWS\SoftwareDistribution\Download\79123dd72d0f61d4ed8c7a816ed338d7\atapi.sys
[2008/04/13 14:40:30 | 000,096,512 | ---- | M] (Microsoft Corporation) MD5=9F3A2F5AA6875C72BF062C712CFA2674 -- C:\WINDOWS\SoftwareDistribution\Download\dd9ab5193501484cf5e6884fa1d22f9e\atapi.sys
[2004/08/10 08:00:00 | 000,095,360 | ---- | M] (Microsoft Corporation) MD5=CDFE4411A69C224BD1D11B2DA92DAC51 -- C:\WINDOWS\$NtServicePackUninstall$\atapi.sys
[2004/08/10 08:00:00 | 000,095,360 | ---- | M] (Microsoft Corporation) MD5=CDFE4411A69C224BD1D11B2DA92DAC51 -- C:\WINDOWS\ERDNT\cache\atapi.sys
[2004/08/10 08:00:00 | 000,095,360 | ---- | M] (Microsoft Corporation) MD5=CDFE4411A69C224BD1D11B2DA92DAC51 -- C:\WINDOWS\system32\dllcache\atapi.sys
[2004/08/10 08:00:00 | 000,095,360 | ---- | M] (Microsoft Corporation) MD5=CDFE4411A69C224BD1D11B2DA92DAC51 -- C:\WINDOWS\system32\drivers\atapi.sys
[2004/08/10 08:00:00 | 000,095,360 | ---- | M] (Microsoft Corporation) MD5=CDFE4411A69C224BD1D11B2DA92DAC51 -- C:\WINDOWS\system32\ReinstallBackups\0000\DriverFiles\i386\atapi.sys
< MD5 for: DISK.SYS >
[2004/08/10 14:00:00 | 016,971,599 | ---- | M] () .cab file -- C:\WINDOWS\Driver Cache\i386\sp2.cab:disk.sys
[2008/12/27 19:08:52 | 023,852,652 | ---- | M] () .cab file -- C:\WINDOWS\Driver Cache\i386\sp3.cab:disk.sys
[2004/08/10 08:00:00 | 016,971,599 | ---- | M] () .cab file -- C:\WINDOWS\I386\sp2.cab:disk.sys
[2008/12/27 19:08:52 | 023,852,652 | ---- | M] () .cab file -- C:\WINDOWS\ServicePackFiles\i386\sp3.cab:disk.sys
[2008/12/27 19:08:52 | 023,852,652 | ---- | M] () .cab file -- C:\WINDOWS\SoftwareDistribution\Download\79123dd72d0f61d4ed8c7a816ed338d7\sp3.cab:disk.sys
[2004/08/10 08:00:00 | 000,036,352 | ---- | M] (Microsoft Corporation) MD5=00CA44E4534865F8A3B64F7C0984BFF0 -- C:\WINDOWS\$NtServicePackUninstall$\disk.sys
[2004/08/10 08:00:00 | 000,036,352 | ---- | M] (Microsoft Corporation) MD5=00CA44E4534865F8A3B64F7C0984BFF0 -- C:\WINDOWS\system32\drivers\disk.sys
[2008/04/13 14:40:47 | 000,036,352 | ---- | M] (Microsoft Corporation) MD5=044452051F3E02E7963599FC8F4F3E25 -- C:\WINDOWS\ServicePackFiles\i386\disk.sys
[2008/04/13 14:40:47 | 000,036,352 | ---- | M] (Microsoft Corporation) MD5=044452051F3E02E7963599FC8F4F3E25 -- C:\WINDOWS\SoftwareDistribution\Download\79123dd72d0f61d4ed8c7a816ed338d7\disk.sys
[2008/04/13 14:40:47 | 000,036,352 | ---- | M] (Microsoft Corporation) MD5=044452051F3E02E7963599FC8F4F3E25 -- C:\WINDOWS\SoftwareDistribution\Download\dd9ab5193501484cf5e6884fa1d22f9e\disk.sys
< MD5 for: EVENTLOG.DLL >
[2008/04/13 20:11:53 | 000,056,320 | ---- | M] (Microsoft Corporation) MD5=6D4FEB43EE538FC5428CC7F0565AA656 -- C:\WINDOWS\ServicePackFiles\i386\eventlog.dll
[2008/04/13 20:11:53 | 000,056,320 | ---- | M] (Microsoft Corporation) MD5=6D4FEB43EE538FC5428CC7F0565AA656 -- C:\WINDOWS\SoftwareDistribution\Download\79123dd72d0f61d4ed8c7a816ed338d7\eventlog.dll
[2008/04/13 20:11:53 | 000,056,320 | ---- | M] (Microsoft Corporation) MD5=6D4FEB43EE538FC5428CC7F0565AA656 -- C:\WINDOWS\SoftwareDistribution\Download\dd9ab5193501484cf5e6884fa1d22f9e\eventlog.dll
[2004/08/10 08:00:00 | 000,055,808 | ---- | M] (Microsoft Corporation) MD5=82B24CB70E5944E6E34662205A2A5B78 -- C:\WINDOWS\$NtServicePackUninstall$\eventlog.dll
[2004/08/10 08:00:00 | 000,055,808 | ---- | M] (Microsoft Corporation) MD5=82B24CB70E5944E6E34662205A2A5B78 -- C:\WINDOWS\ERDNT\cache\eventlog.dll
[2004/08/10 08:00:00 | 000,055,808 | ---- | M] (Microsoft Corporation) MD5=82B24CB70E5944E6E34662205A2A5B78 -- C:\WINDOWS\system32\dllcache\eventlog.dll
[2004/08/10 08:00:00 | 000,055,808 | ---- | M] (Microsoft Corporation) MD5=82B24CB70E5944E6E34662205A2A5B78 -- C:\WINDOWS\system32\eventlog.dll
< MD5 for: NETLOGON.DLL >
[2008/04/13 20:12:01 | 000,407,040 | ---- | M] (Microsoft Corporation) MD5=1B7F071C51B77C272875C3A23E1E4550 -- C:\WINDOWS\ServicePackFiles\i386\netlogon.dll
[2008/04/13 20:12:01 | 000,407,040 | ---- | M] (Microsoft Corporation) MD5=1B7F071C51B77C272875C3A23E1E4550 -- C:\WINDOWS\SoftwareDistribution\Download\79123dd72d0f61d4ed8c7a816ed338d7\netlogon.dll
[2008/04/13 20:12:01 | 000,407,040 | ---- | M] (Microsoft Corporation) MD5=1B7F071C51B77C272875C3A23E1E4550 -- C:\WINDOWS\SoftwareDistribution\Download\dd9ab5193501484cf5e6884fa1d22f9e\netlogon.dll
[2009/02/06 14:46:09 | 000,408,064 | ---- | M] (Microsoft Corporation) MD5=6C476D33D82F1054849790181E8F7772 -- C:\WINDOWS\$hf_mig$\KB968389\SP2QFE\netlogon.dll
[2009/02/06 14:46:09 | 000,408,064 | ---- | M] (Microsoft Corporation) MD5=6C476D33D82F1054849790181E8F7772 -- C:\WINDOWS\$hf_mig$\KB975467\SP2QFE\netlogon.dll
[2004/08/10 08:00:00 | 000,407,040 | ---- | M] (Microsoft Corporation) MD5=96353FCECBA774BB8DA74A1C6507015A -- C:\WINDOWS\$NtServicePackUninstall$\netlogon.dll
[2004/08/10 08:00:00 | 000,407,040 | ---- | M] (Microsoft Corporation) MD5=96353FCECBA774BB8DA74A1C6507015A -- C:\WINDOWS\ERDNT\cache\netlogon.dll
[2004/08/10 08:00:00 | 000,407,040 | ---- | M] (Microsoft Corporation) MD5=96353FCECBA774BB8DA74A1C6507015A -- C:\WINDOWS\system32\dllcache\netlogon.dll
[2004/08/10 08:00:00 | 000,407,040 | ---- | M] (Microsoft Corporation) MD5=96353FCECBA774BB8DA74A1C6507015A -- C:\WINDOWS\system32\netlogon.dll
< MD5 for: SCECLI.DLL >
[2004/08/10 08:00:00 | 000,180,224 | ---- | M] (Microsoft Corporation) MD5=0F78E27F563F2AAF74B91A49E2ABF19A -- C:\WINDOWS\$NtServicePackUninstall$\scecli.dll
[2004/08/10 08:00:00 | 000,180,224 | ---- | M] (Microsoft Corporation) MD5=0F78E27F563F2AAF74B91A49E2ABF19A -- C:\WINDOWS\ERDNT\cache\scecli.dll
[2004/08/10 08:00:00 | 000,180,224 | ---- | M] (Microsoft Corporation) MD5=0F78E27F563F2AAF74B91A49E2ABF19A -- C:\WINDOWS\system32\dllcache\scecli.dll
[2004/08/10 08:00:00 | 000,180,224 | ---- | M] (Microsoft Corporation) MD5=0F78E27F563F2AAF74B91A49E2ABF19A -- C:\WINDOWS\system32\scecli.dll
[2008/04/13 20:12:05 | 000,181,248 | ---- | M] (Microsoft Corporation) MD5=A86BB5E61BF3E39B62AB4C7E7085A084 -- C:\WINDOWS\ServicePackFiles\i386\scecli.dll
[2008/04/13 20:12:05 | 000,181,248 | ---- | M] (Microsoft Corporation) MD5=A86BB5E61BF3E39B62AB4C7E7085A084 -- C:\WINDOWS\SoftwareDistribution\Download\79123dd72d0f61d4ed8c7a816ed338d7\scecli.dll
[2008/04/13 20:12:05 | 000,181,248 | ---- | M] (Microsoft Corporation) MD5=A86BB5E61BF3E39B62AB4C7E7085A084 -- C:\WINDOWS\SoftwareDistribution\Download\dd9ab5193501484cf5e6884fa1d22f9e\scecli.dll
< MD5 for: USBSTOR.SYS >
[2004/08/10 14:00:00 | 016,971,599 | ---- | M] () .cab file -- C:\WINDOWS\Driver Cache\i386\sp2.cab:usbstor.sys
[2008/12/27 19:08:52 | 023,852,652 | ---- | M] () .cab file -- C:\WINDOWS\Driver Cache\i386\sp3.cab:usbstor.sys
[2004/08/10 08:00:00 | 016,971,599 | ---- | M] () .cab file -- C:\WINDOWS\I386\sp2.cab:usbstor.sys
[2008/12/27 19:08:52 | 023,852,652 | ---- | M] () .cab file -- C:\WINDOWS\ServicePackFiles\i386\sp3.cab:usbstor.sys
[2008/12/27 19:08:52 | 023,852,652 | ---- | M] () .cab file -- C:\WINDOWS\SoftwareDistribution\Download\79123dd72d0f61d4ed8c7a816ed338d7\sp3.cab:usbstor.sys
[2004/08/10 08:00:00 | 000,026,496 | ---- | M] (Microsoft Corporation) MD5=6CD7B22193718F1D17A47A1CD6D37E75 -- C:\WINDOWS\$NtServicePackUninstall$\usbstor.sys
[2004/08/10 08:00:00 | 000,026,496 | ---- | M] (Microsoft Corporation) MD5=6CD7B22193718F1D17A47A1CD6D37E75 -- C:\WINDOWS\system32\dllcache\usbstor.sys
[2004/08/10 08:00:00 | 000,026,496 | ---- | M] (Microsoft Corporation) MD5=6CD7B22193718F1D17A47A1CD6D37E75 -- C:\WINDOWS\system32\drivers\USBSTOR.SYS
[2008/04/13 14:45:38 | 000,026,368 | ---- | M] (Microsoft Corporation) MD5=A32426D9B14A089EAA1D922E0C5801A9 -- C:\WINDOWS\ServicePackFiles\i386\usbstor.sys
[2008/04/13 14:45:38 | 000,026,368 | ---- | M] (Microsoft Corporation) MD5=A32426D9B14A089EAA1D922E0C5801A9 -- C:\WINDOWS\SoftwareDistribution\Download\79123dd72d0f61d4ed8c7a816ed338d7\usbstor.sys
[2008/04/13 14:45:38 | 000,026,368 | ---- | M] (Microsoft Corporation) MD5=A32426D9B14A089EAA1D922E0C5801A9 -- C:\WINDOWS\SoftwareDistribution\Download\dd9ab5193501484cf5e6884fa1d22f9e\usbstor.sys
< HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\WindowsUpdate\Auto Update\Results\Install|LastSuccessTime /rs >
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\WindowsUpdate\Auto Update\Results\Install\\LastSuccessTime: 2011-03-10 00:27:00
========== Alternate Data Streams ==========
@Alternate Data Stream - 147 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:86FF9755
@Alternate Data Stream - 144 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:D4C4443E
@Alternate Data Stream - 143 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:7210ACCB
@Alternate Data Stream - 139 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:E65420D3
@Alternate Data Stream - 134 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:5EE6D8DC
@Alternate Data Stream - 133 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:C0BCD7D4
@Alternate Data Stream - 133 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:829FC82B
@Alternate Data Stream - 132 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:7877A7F7
@Alternate Data Stream - 132 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:70EB7261
@Alternate Data Stream - 131 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:0C85CAF3
@Alternate Data Stream - 129 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:884D7B63
@Alternate Data Stream - 129 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:26CA527D
@Alternate Data Stream - 128 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:C778152F
@Alternate Data Stream - 128 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:8C0375AE
@Alternate Data Stream - 128 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:58FB5187
@Alternate Data Stream - 127 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:B23FF50F
@Alternate Data Stream - 126 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:4A6AD8EC
@Alternate Data Stream - 126 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:341B6EF1
@Alternate Data Stream - 124 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:D3BEF2E1
@Alternate Data Stream - 124 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:D0030B7B
@Alternate Data Stream - 124 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:0B4227B4
@Alternate Data Stream - 123 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:D1640D77
@Alternate Data Stream - 123 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:6EBDE0D4
@Alternate Data Stream - 123 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:37724E88
@Alternate Data Stream - 122 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:A71D3858
@Alternate Data Stream - 122 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:59FC1BE7
@Alternate Data Stream - 121 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:771E6DA1
@Alternate Data Stream - 119 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:EB358C65
@Alternate Data Stream - 119 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:96F4AB89
@Alternate Data Stream - 117 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:72211901
@Alternate Data Stream - 115 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:6FA38600
@Alternate Data Stream - 115 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:63A620D8
@Alternate Data Stream - 115 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:027B8698
@Alternate Data Stream - 114 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:48F5D95B
@Alternate Data Stream - 114 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:48D45EF0
@Alternate Data Stream - 114 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:1538E964
@Alternate Data Stream - 112 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:DFC5A2B2
@Alternate Data Stream - 112 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:5886DCB8
@Alternate Data Stream - 112 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:1F3CCB4F
@Alternate Data Stream - 112 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:0745BF73
@Alternate Data Stream - 111 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:E5D28A2A
@Alternate Data Stream - 111 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:9FC06D35
@Alternate Data Stream - 109 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:B1D4545A
@Alternate Data Stream - 109 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:996B0578
@Alternate Data Stream - 108 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:81E7CF6A
@Alternate Data Stream - 107 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:07F32517
@Alternate Data Stream - 105 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:36E20A37
< End of report >