| |
| | |
| Thread Tools |
|
20-Jan-2008, 04:50 PM
#1 |
| problem with some kind of a virus called "vtutu" Hi all iam new at this forum and nice to meet u. Well yesterday i was at my uncles home and searching for a no cd crack i wanted for a game when i downloaded and after that i installedit it the pc crashed i waited for about 1 min but nothing i restarted the pc and i typed the psw to log in when i loged the screen was showing only the background of the desktop and the task bar and the shortcuts were gone i waited because i thought it was a crash but nothing i restarted again and i loged again but the same thing happened i waited again but still nothing.I tried ctrl+alt+delete and it worked i tried new task and then cmd.exe after that C:\Windows\system32>explorer and it worked the task bar and shortcuts appeared.I was afraid that it could be a virus so i tried to run norton a error came up that the norton couldnt run for further information visit symantec site.I restarted again and done the same with the task manager the norton still coulnd open then a error came up after i closed the router for safety that the vtutu.exe couldnt connect with IE and i had 2 options work without conection or retry i pressed x (close) the same error mesage came up about 10 times again.Then i gone to the search and typed vtutu i found two items at the direction C:\windows\system32 called vtutu.dll and vtutu.exe i tried to delete them but the delete failed.I restarted again but this time when i used ctrl+alt+delete the task manager came up but after 2 seconds it closed and thi happened again and again so i tried something i hold down the buttons ctrl+alt+delete and it didnt disappeared when i left the buttons it closed again so i told my unce o hold down this buttons he did and i with the mouse went to processes and found 2 processes that were runing from user and were using about 20-50 cpu i ended both of them and then when my uncle left the buttons the task manager was ok and it didnt closed i went to run norton again but it failed again then i tried to remove it and install it again but the remove failed to.I decided to turn the settings of the pc back 1 day u know what i mean this option from the control panel (sorry my english is a bit bad) but it didnt let me either 1 day or 2 or 3 or even month etc. i was pissed so i decided to close the pc but b4 i close it i went to that thing called vtutu to see its properties it was saying that it created the time about instaled the game or the time i installed the no cd crack i dont remember very well.After that i closed it and opened it again and guess what that time happened BLACK scree only the mouse was showing at sceen i closed it and then i didnt try to open it again neither yesterday or today.Also today at my pc when i tried to open IE i had LOTS of pop ups that were blank pages in addition at my pc i havent installed an antivirus yet so i tried to install norton 2006 but a message appeared could not run norton antivirus setup because it was blocked from something then i tried to scan my pc from online kaspersky scan.The scan was at 25 % and found 8 viruses and 31 affected items then i got interupted by my dial up connection now iam scaning again.I would appeciate if u could help me at both situations thank you ![]() |
| |
21-Jan-2008, 10:46 PM
#2 | |||||
| Go to here and download 'Hijack This!' self installer. Save it to the desktop or other suitable place. DO NOT just press run from the website Double click on the file and it will install to C:\program files\hijackthis and create an entry in the start menu. Click on the entry in start menu to run HijackThis Click the "Scan" button, when the scan is finished the scan button will become "Save Log" click that and save the log. Go to where you saved the log and click on "Edit > Select All" then click on "Edit > Copy" then Paste the log back here in a reply. It will possibly show issues deserving our attention, but most of what it lists will be harmless or even required, so do NOT fix anything yet. |
|
22-Jan-2008, 08:29 AM
#3 |
| sorry for my delay to reply i was trying to get rid of trojan horses and trojan droopers i had on my pc with avast and i made it my pc is ok now no pop ups no errors . The problem is that my uncle can not access the IE cause of this program.Happens the same thing that was happening with task manager after 1 second was closing automaticly same here with IE.I went to the procceses at the task manager and i found 2 procceses with the name spool.exe the one uses cpu 00 and the other when i open the task manager first uses 40 then 89 and when reaches 99 the task manager is closing.If i end the proccess of this that is using cpu the other which is not using cpu (00) it startes using cp u (50) and then appears the second spool.exe then 40 then 89 and the same when goes 99 close the task manager i tried to close both of them but nothing they appear again.My uncle tried to backup some files that he needs for his work but that thing wont let him. so? what to do now? |
|
22-Jan-2008, 02:24 PM
#4 |
| Well i tried something i installed windows and seems fine the IE can be opened now but this spool.exe is still at task manager but at least i can close it also some weird errors appeared about this vtutu i done tha scan with hijack this here is the scan info Logfile of Trend Micro HijackThis v2.0.2 Scan saved at 8:17:14 μμ, on 22/1/2008 Platform: Windows XP SP2 (WinNT 5.01.2600) MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180) Boot mode: Normal Running processes: C:\WINDOWS\System32\smss.exe C:\WINDOWS\system32\winlogon.exe C:\WINDOWS\system32\services.exe C:\WINDOWS\system32\lsass.exe C:\WINDOWS\System32\svchost.exe C:\WINDOWS\system32\svchost.exe C:\Program Files\Ahead\InCD\InCDsrv.exe C:\WINDOWS\system32\spoolsv.exe C:\Program Files\Symantec\LiveUpdate\ALUSchedulerSvc.exe C:\WINDOWS\System32\svchost.exe C:\Program Files\Common Files\Microsoft Shared\VS7Debug\mdm.exe C:\WINDOWS\system32\nvsvc32.exe C:\WINDOWS\system32\svchost.exe C:\WINDOWS\system32\WFXSVC.EXE C:\Program Files\Symantec\WinFax\WFXMOD32.EXE C:\Program Files\Common Files\Symantec Shared\AppCore\AppSvc32.exe C:\WINDOWS\system32\dllhost.exe C:\WINDOWS\Explorer.EXE C:\WINDOWS\system32\drivers\spool .exe C:\WINDOWS\system32\rundll32.exe C:\Documents and Settings\User\Local Settings\Application Data\cftmon.exe C:\WINDOWS\system32\drivers\spool.exe C:\WINDOWS\system32\wfxsnt40.exe C:\WINDOWS\system32\drivers\spool .exe C:\Documents and Settings\User\Local Settings\Application Data\cftmon .exe C:\Program Files\Java\jre1.6.0_02\bin\jusched.exe C:\Program Files\Hewlett-Packard\HP Share-to-Web\hpgs2wnd.exe C:\Program Files\CyberLink\PowerDVD\PDVDServ.exe C:\Program Files\Hewlett-Packard\HP Share-to-Web\hpgs2wnf.exe C:\Program Files\Common Files\PCSuite\Services\ServiceLayer.exe C:\Program Files\Common Files\Nokia\NCLTools\NclTray.exe C:\WINDOWS\system32\rundll32.exe C:\Program Files\MessengerPlus! 3\MsgPlus.exe C:\Program Files\Logitech\Video\LogiTray.exe C:\Program Files\Common Files\PCSuite\DataLayer\DataLayer.exe C:\WINDOWS\system32\ctfmon.exe C:\WINDOWS\system32\ctfmon .exe C:\Documents and Settings\User\Local Settings\Application Data\cftmon.exe C:\WINDOWS\system32\drivers\spool.exe C:\Documents and Settings\User\Local Settings\Application Data\cftmon .exe C:\WINDOWS\system32\drivers\spool .exe C:\Program Files\Logitech\Video\FxSvr2.exe C:\PROGRA~1\COMMON~1\Nokia\MPAPI\MPAPI3s.exe C:\Program Files\Adobe\Acrobat 5.0\Distillr\AcroTray.exe C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe C:\Program Files\Internet Explorer\iexplore.exe C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLLoginProxy.exe C:\Program Files\Trend Micro\HijackThis\HijackThis.exe R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.altecnet.gr R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.altecnet.gr R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Window Title = Microsoft Internet Explorer provided by ALTECNET R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = localhost R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Συνδέσεις F3 - REG:win.ini: load=C:\WINDOWS\system32\vtutu.exe F2 - REG:system.ini: UserInit=C:\WINDOWS\system32\drivers\spool.exe C:\WINDOWS\system32\userinit.exe O3 - Toolbar: Windows Live Toolbar - {BDAD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\Program Files\Windows Live Toolbar\msntb.dll O3 - Toolbar: Show Norton Toolbar - {90222687-F593-4738-B738-FBEE9C7B26DF} - C:\Program Files\Common Files\Symantec Shared\coShared\Browser\1.0\UIBHO.dll O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup O4 - HKLM\..\Run: [type32] "C:\Program Files\Microsoft IntelliType Pro\type32.exe" O4 - HKLM\..\Run: [IntelliPoint] "C:\Program Files\Microsoft IntelliPoint\point32.exe" O4 - HKLM\..\Run: [HPDJ Taskbar Utility] C:\WINDOWS\system32\spool\drivers\w32x86\3\hpztsb04.exe O4 - HKLM\..\Run: [USB2Check] RUNDLL32.EXE "C:\WINDOWS\system32\PCLECoInst.dll",CheckUSBController O4 - HKLM\..\Run: [LVCOMSX] C:\WINDOWS\system32\LVCOMSX.EXE O4 - HKLM\..\Run: [InCD] C:\Program Files\Ahead\InCD\InCD.exe O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\WINDOWS\system32\NvMcTray.dll,NvTaskbarInit O4 - HKLM\..\Run: [osCheck] "C:\Program Files\Norton Internet Security\osCheck.exe" O4 - HKLM\..\Run: [ccApp] "C:\Program Files\Common Files\Symantec Shared\ccApp.exe" O4 - HKLM\..\Run: [Symantec PIF AlertEng] "C:\Program Files\Common Files\Symantec Shared\PIF\{B8E1DD85-8582-4c61-B58F-2F227FCA9A08}\PIFSvc.exe" /a /m "C:\Program Files\Common Files\Symantec Shared\PIF\{B8E1DD85-8582-4c61-B58F-2F227FCA9A08}\AlertEng.dll" O4 - HKLM\..\Run: [autoload] C:\Documents and Settings\User\Local Settings\Application Data\cftmon.exe O4 - HKLM\..\Run: [WorksFUD] C:\Program Files\Microsoft Works\wkfud.exe O4 - HKLM\..\Run: [WinFaxAppPortStarter] wfxsnt40.exe O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_02\bin\jusched.exe" O4 - HKLM\..\Run: [nwiz] nwiz.exe /install O4 - HKLM\..\Run: [NeroFilterCheck] C:\WINDOWS\system32\NeroCheck.exe O4 - HKLM\..\Run: [msnappau] "C:\Program Files\MSN Apps\Updater\01.02.3000.1001\el-gr\msnappau.exe" O4 - HKLM\..\Run: [Microsoft Works Update Detection] C:\Program Files\Microsoft Works\WkDetect.exe O4 - HKLM\..\Run: [Microsoft Works Portfolio] C:\Program Files\Microsoft Works\WksSb.exe /AllUsers O4 - HKLM\..\Run: [MediaGateway] C:\Program Files\MediaGateway\MediaGateway.exe O4 - HKLM\..\Run: [Default bits loud great] C:\Documents and Settings\All Users\Application Data\settings phone default bits\fast 16.exe O4 - HKLM\..\Run: [DataLayer] C:\Program Files\Common Files\PCSuite\DataLayer\DataLayer.exe O4 - HKLM\..\Run: [SoundMan] SOUNDMAN.EXE O4 - HKLM\..\Run: [MSConfig] C:\WINDOWS\PCHealth\HelpCtr\Binaries\MSConfig.exe /auto O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe O4 - HKCU\..\Run: [WMPNSCFG] C:\Program Files\Windows Media Player\WMPNSCFG.exe O4 - HKCU\..\Run: [autoload] C:\Documents and Settings\User\Local Settings\Application Data\cftmon.exe O4 - HKCU\..\Run: [ntuser] C:\WINDOWS\system32\drivers\spool.exe O4 - HKUS\S-1-5-19\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'LOCAL SERVICE') O4 - HKUS\S-1-5-20\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'NETWORK SERVICE') O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SYSTEM') O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'Default user') O6 - HKCU\Software\Policies\Microsoft\Internet Explorer\Control Panel present O8 - Extra context menu item: &Clean Traces - C:\Program Files\DAP\Privacy Package\dapcleanerie.htm O8 - Extra context menu item: &Download with &DAP - C:\Program Files\DAP\dapextie.htm O8 - Extra context menu item: &Windows Live Search - res://C:\Program Files\Windows Live Toolbar\msntb.dll/search.htm O8 - Extra context menu item: Add to Windows &Live Favorites - http://favorites.live.com/quickadd.aspx O8 - Extra context menu item: Download &all with DAP - C:\Program Files\DAP\dapextie2.htm O8 - Extra context menu item: Ε&ξαγωγή στο Microsoft Excel - res://C:\PROGRA~1\MI1933~1\Office10\EXCEL.EXE/3000 O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_02\bin\ssv.dll O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_02\bin\ssv.dll O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe O12 - Plugin for .spop: C:\Program Files\Internet Explorer\Plugins\NPDocBox.dll O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) - http://go.microsoft.com/fwlink/?linkid=39204 O16 - DPF: {62789780-B744-11D0-986B-00609731A21D} (Autodesk MapGuide ActiveX Control) - http://maps.flash.gr/inc/activex/mgaxctrl.cab O16 - DPF: {DE625294-70E6-45ED-B895-CFFA13AEB044} (AxisMediaControlEmb Class) - http://62.1.195.34:8088/activex/AMC.cab O16 - DPF: {EB387D2F-E27B-4D36-979E-847D1036C65D} (QDiagHUpdateObj Class) - http://h30043.www3.hp.com/hpdj/en/check/qdiagh.cab?326 O17 - HKLM\System\CCS\Services\Tcpip\..\{8F7B04C5-0416-4966-9B3E-347BF616FCE0}: NameServer = 213.5.41.8,213.5.17.21 O17 - HKLM\System\CCS\Services\Tcpip\..\{AEED5469-1EF7-4328-B775-2B2AC9C32BC6}: NameServer = 213.5.41.8,213.5.17.21 O23 - Service: Adobe LM Service - Adobe Systems - C:\Program Files\Common Files\Adobe Systems Shared\Service\Adobelmsvc.exe O23 - Service: Automatic LiveUpdate Scheduler - Symantec Corporation - C:\Program Files\Symantec\LiveUpdate\ALUSchedulerSvc.exe O23 - Service: Symantec Event Manager (ccEvtMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe O23 - Service: Symantec Settings Manager (ccSetMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe O23 - Service: Symantec Lic NetConnect service (CLTNetCnService) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe O23 - Service: COM Host (comHost) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\VAScanner\comHost.exe O23 - Service: InCD Helper (InCDsrv) - Nero AG - C:\Program Files\Ahead\InCD\InCDsrv.exe O23 - Service: InCD Helper (read only) (InCDsrvR) - Nero AG - C:\Program Files\Ahead\InCD\InCDsrv.exe O23 - Service: Symantec IS Password Validation (ISPwdSvc) - Symantec Corporation - C:\Program Files\Norton Internet Security\isPwdSvc.exe O23 - Service: LiveUpdate - Symantec Corporation - C:\PROGRA~1\Symantec\LIVEUP~1\LUCOMS~1.EXE O23 - Service: LiveUpdate Notice Service Ex (LiveUpdate Notice Ex) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe O23 - Service: LiveUpdate Notice Service - Unknown owner - C:\Program Files\Common Files\Symantec Shared\PIF\{B8E1DD85-8582-4c61-B58F-2F227FCA9A08}\PIFSvc.exe O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe O23 - Service: PnkBstrA - Unknown owner - C:\WINDOWS\system32\PnkBstrA.exe (file missing) O23 - Service: Χρονοδιάγραμμα εργασιών (Schedule) - Unknown owner - C:\WINDOWS\system32\drivers\spool.exe O23 - Service: ServiceLayer - Nokia. - C:\Program Files\Common Files\PCSuite\Services\ServiceLayer.exe O23 - Service: SolidWorks Licensing Service - SolidWorks - C:\Program Files\Common Files\SolidWorks Shared\Service\SolidWorksLicensing.exe O23 - Service: Symantec Core LC - Unknown owner - C:\Program Files\Common Files\Symantec Shared\CCPD-LC\symlcsvc.exe O23 - Service: Symantec AppCore Service (SymAppCore) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\AppCore\AppSvc32.exe O23 - Service: WinFax PRO (wfxsvc) - Symantec Corporation - C:\WINDOWS\system32\WFXSVC.EXE ![]() |
22-Jan-2008, 07:29 PM
#5 | |||||
| You are very infected. Download ComboFix from Here or Here to your Desktop. **Note: In the event you already have Combofix, this is a new version that I need you to download. It is important that it is saved directly to your desktop** -------------------------------------------------------------------- 1. Close any open browsers. 2. Close/disable all anti virus and anti malware programs so they do not interfere with the running of ComboFix.
Double click on combofix.exe & follow the prompts.
**Note: Do not mouseclick combofix's window while it's running. That may cause it to stall** |
|
23-Jan-2008, 02:45 PM
#6 |
| ok here we go Logfile of Trend Micro HijackThis v2.0.2 Scan saved at 20:41, on 2008-01-23 Platform: Windows XP SP2 (WinNT 5.01.2600) MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180) Boot mode: Normal Running processes: C:\WINDOWS\System32\smss.exe C:\WINDOWS\system32\winlogon.exe C:\WINDOWS\system32\services.exe C:\WINDOWS\system32\lsass.exe C:\WINDOWS\system32\svchost.exe C:\WINDOWS\System32\svchost.exe C:\Program Files\Ahead\InCD\InCDsrv.exe C:\Program Files\Symantec\LiveUpdate\ALUSchedulerSvc.exe C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe C:\WINDOWS\System32\svchost.exe C:\Program Files\Common Files\Microsoft Shared\VS7Debug\mdm.exe C:\WINDOWS\system32\svchost.exe C:\WINDOWS\system32\WFXSVC.EXE C:\Program Files\Symantec\WinFax\WFXMOD32.EXE C:\Program Files\Common Files\Symantec Shared\AppCore\AppSvc32.exe C:\WINDOWS\Explorer.EXE C:\WINDOWS\system32\msiexec.exe C:\WINDOWS\system32\wfxsnt40.exe C:\WINDOWS\system32\wuauclt.exe C:\WINDOWS\system32\rundll32.exe C:\WINDOWS\System32\svchost.exe C:\WINDOWS\System32\svchost.exe C:\Program Files\Internet Explorer\IEXPLORE.EXE C:\WINDOWS\system32\wscntfy.exe C:\Program Files\Internet Explorer\IEXPLORE.EXE C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLLoginProxy.exe C:\Program Files\Windows Live Toolbar\msn_sl.exe C:\Program Files\Trend Micro\HijackThis\HijackThis.exe R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.altecnet.gr/ R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = localhost R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Συνδέσεις O2 - BHO: DAPHelper Class - {0000CC75-ACF3-4cac-A0A9-DD3868E06852} - C:\Program Files\DAP\dapbho.dll O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 5.0\Acrobat\ActiveX\AcroIEHelper.ocx O2 - BHO: (no name) - {1E8A6170-7264-4D0F-BEAE-D42A53123C75} - C:\Program Files\Common Files\Symantec Shared\coShared\Browser\1.0\NppBho.dll O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_02\bin\ssv.dll O2 - BHO: Windows Live Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll O2 - BHO: Windows Live Toolbar Helper - {BDBD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\Program Files\Windows Live Toolbar\msntb.dll O3 - Toolbar: Windows Live Toolbar - {BDAD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\Program Files\Windows Live Toolbar\msntb.dll O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup O4 - HKLM\..\Run: [type32] "C:\Program Files\Microsoft IntelliType Pro\type32.exe" O4 - HKLM\..\Run: [IntelliPoint] "C:\Program Files\Microsoft IntelliPoint\point32.exe" O4 - HKLM\..\Run: [HPDJ Taskbar Utility] C:\WINDOWS\system32\spool\drivers\w32x86\3\hpztsb04.exe O4 - HKLM\..\Run: [USB2Check] RUNDLL32.EXE "C:\WINDOWS\system32\PCLECoInst.dll",CheckUSBController O4 - HKLM\..\Run: [LVCOMSX] C:\WINDOWS\system32\LVCOMSX.EXE O4 - HKLM\..\Run: [InCD] C:\Program Files\Ahead\InCD\InCD.exe O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\WINDOWS\system32\NvMcTray.dll,NvTaskbarInit O4 - HKLM\..\Run: [osCheck] "C:\Program Files\Norton Internet Security\osCheck.exe" O4 - HKLM\..\Run: [ccApp] "C:\Program Files\Common Files\Symantec Shared\ccApp.exe" O4 - HKLM\..\Run: [Symantec PIF AlertEng] "C:\Program Files\Common Files\Symantec Shared\PIF\{B8E1DD85-8582-4c61-B58F-2F227FCA9A08}\PIFSvc.exe" /a /m "C:\Program Files\Common Files\Symantec Shared\PIF\{B8E1DD85-8582-4c61-B58F-2F227FCA9A08}\AlertEng.dll" O4 - HKLM\..\Run: [WorksFUD] C:\Program Files\Microsoft Works\wkfud.exe O4 - HKLM\..\Run: [WinFaxAppPortStarter] wfxsnt40.exe O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_02\bin\jusched.exe" O4 - HKLM\..\Run: [nwiz] nwiz.exe /install O4 - HKLM\..\Run: [NeroFilterCheck] C:\WINDOWS\system32\NeroCheck.exe O4 - HKLM\..\Run: [msnappau] "C:\Program Files\MSN Apps\Updater\01.02.3000.1001\el-gr\msnappau.exe" O4 - HKLM\..\Run: [Microsoft Works Update Detection] C:\Program Files\Microsoft Works\WkDetect.exe O4 - HKLM\..\Run: [Microsoft Works Portfolio] C:\Program Files\Microsoft Works\WksSb.exe /AllUsers O4 - HKLM\..\Run: [MediaGateway] C:\Program Files\MediaGateway\MediaGateway.exe O4 - HKLM\..\Run: [Default bits loud great] C:\Documents and Settings\All Users\Application Data\settings phone default bits\fast 16.exe O4 - HKLM\..\Run: [DataLayer] C:\Program Files\Common Files\PCSuite\DataLayer\DataLayer.exe O4 - HKLM\..\Run: [SoundMan] SOUNDMAN.EXE O4 - HKLM\..\Run: [MSConfig] C:\WINDOWS\PCHealth\HelpCtr\Binaries\MSConfig.exe /auto O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe O4 - HKCU\..\Run: [WMPNSCFG] C:\Program Files\Windows Media Player\WMPNSCFG.exe O4 - HKUS\S-1-5-19\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'LOCAL SERVICE') O4 - HKUS\S-1-5-20\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'NETWORK SERVICE') O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SYSTEM') O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'Default user') O6 - HKCU\Software\Policies\Microsoft\Internet Explorer\Control Panel present O8 - Extra context menu item: &Clean Traces - C:\Program Files\DAP\Privacy Package\dapcleanerie.htm O8 - Extra context menu item: &Download with &DAP - C:\Program Files\DAP\dapextie.htm O8 - Extra context menu item: &Windows Live Search - res://C:\Program Files\Windows Live Toolbar\msntb.dll/search.htm O8 - Extra context menu item: Add to Windows &Live Favorites - http://favorites.live.com/quickadd.aspx O8 - Extra context menu item: Download &all with DAP - C:\Program Files\DAP\dapextie2.htm O8 - Extra context menu item: Ε&ξαγωγή στο Microsoft Excel - res://C:\PROGRA~1\MI1933~1\Office10\EXCEL.EXE/3000 O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_02\bin\ssv.dll O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_02\bin\ssv.dll O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe (file missing) O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe (file missing) O12 - Plugin for .spop: C:\Program Files\Internet Explorer\Plugins\NPDocBox.dll O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) - http://go.microsoft.com/fwlink/?linkid=39204 O16 - DPF: {62789780-B744-11D0-986B-00609731A21D} (Autodesk MapGuide ActiveX Control) - http://maps.flash.gr/inc/activex/mgaxctrl.cab O16 - DPF: {DE625294-70E6-45ED-B895-CFFA13AEB044} (AxisMediaControlEmb Class) - http://62.1.195.34:8088/activex/AMC.cab O16 - DPF: {EB387D2F-E27B-4D36-979E-847D1036C65D} (QDiagHUpdateObj Class) - http://h30043.www3.hp.com/hpdj/en/check/qdiagh.cab?326 O17 - HKLM\System\CCS\Services\Tcpip\..\{8F7B04C5-0416-4966-9B3E-347BF616FCE0}: NameServer = 213.5.41.8,213.5.17.21 O17 - HKLM\System\CCS\Services\Tcpip\..\{AEED5469-1EF7-4328-B775-2B2AC9C32BC6}: NameServer = 213.5.41.8,213.5.17.21 O23 - Service: Adobe LM Service - Adobe Systems - C:\Program Files\Common Files\Adobe Systems Shared\Service\Adobelmsvc.exe O23 - Service: Automatic LiveUpdate Scheduler - Symantec Corporation - C:\Program Files\Symantec\LiveUpdate\ALUSchedulerSvc.exe O23 - Service: Symantec Event Manager (ccEvtMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe O23 - Service: Symantec Settings Manager (ccSetMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe O23 - Service: Symantec Lic NetConnect service (CLTNetCnService) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe O23 - Service: COM Host (comHost) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\VAScanner\comHost.exe O23 - Service: InCD Helper (InCDsrv) - Nero AG - C:\Program Files\Ahead\InCD\InCDsrv.exe O23 - Service: InCD Helper (read only) (InCDsrvR) - Nero AG - C:\Program Files\Ahead\InCD\InCDsrv.exe O23 - Service: Symantec IS Password Validation (ISPwdSvc) - Symantec Corporation - C:\Program Files\Norton Internet Security\isPwdSvc.exe O23 - Service: LiveUpdate - Symantec Corporation - C:\PROGRA~1\Symantec\LIVEUP~1\LUCOMS~1.EXE O23 - Service: LiveUpdate Notice Service Ex (LiveUpdate Notice Ex) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe O23 - Service: LiveUpdate Notice Service - Unknown owner - C:\Program Files\Common Files\Symantec Shared\PIF\{B8E1DD85-8582-4c61-B58F-2F227FCA9A08}\PIFSvc.exe (file missing) O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe O23 - Service: PnkBstrA - Unknown owner - C:\WINDOWS\system32\PnkBstrA.exe (file missing) O23 - Service: ServiceLayer - Nokia. - C:\Program Files\Common Files\PCSuite\Services\ServiceLayer.exe O23 - Service: SolidWorks Licensing Service - SolidWorks - C:\Program Files\Common Files\SolidWorks Shared\Service\SolidWorksLicensing.exe O23 - Service: Symantec Core LC - Unknown owner - C:\Program Files\Common Files\Symantec Shared\CCPD-LC\symlcsvc.exe O23 - Service: Symantec AppCore Service (SymAppCore) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\AppCore\AppSvc32.exe O23 - Service: WinFax PRO (wfxsvc) - Symantec Corporation - C:\WINDOWS\system32\WFXSVC.EXE -- End of file - 9984 bytes and the combo fix ComboFix 08-01-23.2 - User 2008-01-23 13:04:08.1 - NTFSx86 Microsoft Windows XP Home Edition 5.1.2600.2.1253.1.1032.18.592 [GMT 2:00] Running from: C:\Documents and Settings\User\§**α€* ¨©ε\ComboFix.exe * Created a new restore point WARNING -THIS MACHINE DOES NOT HAVE THE RECOVERY CONSOLE INSTALLED !! . ((((((((((((((((((((((((((((((((((((((( Other Deletions ))))))))))))))))))))))))))))))))))))))))))))))))) . C:\Documents and Settings\LocalService\Local Settings\Application Data\cftmon .exe C:\Documents and Settings\User\Local Settings\Application Data\cftmon .exe C:\Documents and Settings\User\Local Settings\Application Data\cftmon.exe C:\Program Files\Ahead\InCD\InCD .exe C:\Program Files\Ahead\InCD\InCD.exe C:\Program Files\Common Files\PCSuite\DataLayer\DataLayer .exe C:\Program Files\Common Files\PCSuite\DataLayer\DataLayer.exe C:\Program Files\Common Files\Symantec Shared\ccApp .exe C:\Program Files\Common Files\Symantec Shared\ccApp.exe C:\Program Files\Common Files\Symantec Shared\PIF\{B8E1DD85-8582-4c61-B58F-2F227FCA9A08}\PIFSvc .exe C:\Program Files\Common Files\Symantec Shared\PIF\{B8E1DD85-8582-4c61-B58F-2F227FCA9A08}\PIFSvc.exe C:\Program Files\Java\jre1.6.0_02\bin\jusched .exe C:\Program Files\Java\jre1.6.0_02\bin\jusched.exe C:\Program Files\Logitech\Video\ManifestEngine .exe C:\Program Files\Logitech\Video\ManifestEngine.exe C:\Program Files\Messenger\msmsgs .exe C:\Program Files\Messenger\msmsgs.exe C:\Program Files\Microsoft IntelliPoint\point32 .exe C:\Program Files\Microsoft IntelliType Pro\type32 .exe C:\Program Files\Microsoft Works\WkDetect .exe C:\Program Files\Microsoft Works\WkDetect.exe C:\Program Files\Microsoft Works\wkfud .exe C:\Program Files\Microsoft Works\wkfud.exe C:\Program Files\Microsoft Works\WksSb .exe C:\Program Files\Microsoft Works\WksSb.exe C:\Program Files\MSN Messenger\msnmsgr .exe C:\Program Files\MSN Messenger\msnmsgr.exe C:\Program Files\Nokia\Nokia PC Suite 6\PcSync2 .exe C:\Program Files\Nokia\Nokia PC Suite 6\PcSync2.exe C:\Program Files\Norton Internet Security\osCheck .exe C:\Program Files\Norton Internet Security\osCheck.exe C:\Program Files\Skype\Phone\Skype .exe C:\Program Files\Skype\Phone\Skype.exe C:\Program Files\Windows Media Player\WMPNSCFG .exe C:\Program Files\X-Lite\X-Lite .exe C:\Program Files\X-Lite\X-Lite.exe C:\WINDOWS\pchealth\helpctr\binaries\MSConfig .exe C:\WINDOWS\PCHealth\HelpCtr\Binaries\MSConfig.exe C:\WINDOWS\SOUNDMAN .EXE C:\WINDOWS\SOUNDMAN.EXE C:\WINDOWS\system32\5_exception.nls C:\WINDOWS\system32\drivers\smtpdrv.sys C:\WINDOWS\system32\drivers\spool .exe C:\WINDOWS\system32\drivers\spool.exe C:\WINDOWS\system32\LVCOMSX .EXE C:\WINDOWS\system32\LVCOMSX.EXE C:\WINDOWS\system32\NeroCheck .exe C:\WINDOWS\system32\NeroCheck.exe C:\WINDOWS\system32\spool\drivers\w32x86\3\hpztsb04 .exe C:\WINDOWS\system32\urqnnlj.dll C:\WINDOWS\system32\ututv.ini C:\WINDOWS\system32\ututv.ini2 C:\WINDOWS\system32\vtutu.dll C:\WINDOWS\system32\vtutu.exe C:\WINDOWS\system32\wintuh32.dll Code: <pre> C:\Documents and Settings\LocalService\Local Settings\Application Data\cftmon .exe ---> QooBox C:\Documents and Settings\User\Local Settings\Application Data\cftmon .exe ---> QooBox C:\Program Files\Logitech\Video\ManifestEngine .exe ---> QooBox C:\Program Files\Messenger\msmsgs .exe ---> QooBox C:\Program Files\MSN Messenger\msnmsgr .exe ---> QooBox C:\Program Files\Nokia\Nokia PC Suite 6\PcSync2 .exe ---> QooBox C:\Program Files\Skype\Phone\Skype .exe ---> QooBox C:\Program Files\X-Lite\X-Lite .exe ---> QooBox C:\WINDOWS\system32\drivers\spool .exe ---> QooBox </pre> . ((((((((((((((((((((((((((((((((((((((( Drivers/Services ))))))))))))))))))))))))))))))))))))))))))))))))) . -------\LEGACY_RUNTIME -------\LEGACY_SMTPDRV -------\runtime -------\smtpdrv ((((((((((((((((((((((((( Files Created from 2007-12-23 to 2008-01-23 ))))))))))))))))))))))))))))))) . 2008-01-23 13:02 . 2000-08-31 08:00 58,368 --a------ C:\WINDOWS\Nircmd.exe 2008-01-22 20:11 . 2008-01-22 20:11 <DIR> d-------- C:\Program Files\Trend Micro 2008-01-22 19:44 . 2004-09-07 14:00 1,875,968 --a--c--- C:\WINDOWS\system32\dllcache\msir3jp.lex 2008-01-22 19:43 . 2004-09-07 14:00 13,463,552 --a--c--- C:\WINDOWS\system32\dllcache\hwxjpn.dll 2008-01-22 19:42 . 2004-09-07 14:00 335,872 --a--c--- C:\WINDOWS\system32\dllcache\aqueue.dll 2008-01-22 19:39 . 2008-01-22 19:39 488 -rah----- C:\WINDOWS\system32\logonui.exe.manifest 2008-01-22 19:38 . 2004-09-07 14:00 24,576 --a--c--- C:\WINDOWS\system32\dllcache\isignup.exe 2008-01-22 19:38 . 2008-01-22 19:38 749 -rah----- C:\WINDOWS\WindowsShell.Manifest 2008-01-22 19:38 . 2008-01-22 19:38 749 -rah----- C:\WINDOWS\system32\wuaucpl.cpl.manifest 2008-01-22 19:38 . 2008-01-22 19:38 749 -rah----- C:\WINDOWS\system32\sapi.cpl.manifest 2008-01-22 19:38 . 2008-01-22 19:38 749 -rah----- C:\WINDOWS\system32\ncpa.cpl.manifest 2008-01-22 19:33 . 2004-09-04 06:45 160,768 --a------ C:\WINDOWS\system32\irftp.exe 2008-01-22 19:33 . 2004-08-03 23:00 87,424 --a------ C:\WINDOWS\system32\drivers\irda.sys 2008-01-22 19:33 . 2004-09-04 06:45 28,672 --a------ C:\WINDOWS\system32\irmon.dll 2008-01-22 19:33 . 2004-09-04 06:45 8,192 --a------ C:\WINDOWS\system32\wshirda.dll 2008-01-22 18:40 . 2001-08-17 20:51 19,584 --a------ C:\WINDOWS\system32\drivers\rasirda.sys 2008-01-22 18:22 . 2004-09-07 14:00 14,043 -ra------ C:\WINDOWS\SET119.tmp 2008-01-22 18:21 . 2004-09-07 14:00 1,086,058 -ra------ C:\WINDOWS\SET10D.tmp 2008-01-22 18:21 . 2004-09-07 14:00 1,014,193 -ra------ C:\WINDOWS\SET10A.tmp 2008-01-19 15:19 . 2008-01-22 21:06 22,528 --a------ C:\WINDOWS\system32\ctfmon .exe 2008-01-19 14:03 . 2008-01-23 13:11 25,984 --a------ C:\WINDOWS\system32\drivers\Bin06.sys 2008-01-19 14:03 . 2008-01-23 11:37 4,608 --a------ C:\WINDOWS\system32\msftp.dll 2008-01-19 12:16 . 2007-07-19 18:14 3,727,720 --a------ C:\WINDOWS\system32\d3dx9_35.dll 2008-01-19 12:16 . 2007-07-19 18:14 1,358,192 --a------ C:\WINDOWS\system32\D3DCompiler_35.dll 2008-01-19 12:16 . 2007-07-19 18:14 444,776 --a------ C:\WINDOWS\system32\d3dx10_35.dll 2008-01-19 12:16 . 2007-07-20 00:57 267,112 --a------ C:\WINDOWS\system32\xactengine2_9.dll . (((((((((((((((((((((((((((((((((((((((( Find3M Report )))))))))))))))))))))))))))))))))))))))))))))))))))) . 2008-01-23 11:08 --------- d-----w C:\Program Files\X-Lite 2008-01-23 11:08 --------- d-----w C:\Program Files\Norton Internet Security 2008-01-23 11:08 --------- d-----w C:\Program Files\MSN Messenger 2008-01-23 11:08 --------- d-----w C:\Program Files\Microsoft Works 2008-01-23 11:08 --------- d-----w C:\Program Files\Microsoft IntelliType Pro 2008-01-23 11:08 --------- d-----w C:\Program Files\Microsoft IntelliPoint 2008-01-23 11:08 --------- d-----w C:\Program Files\Common Files\Symantec Shared 2008-01-22 17:58 --------- d-----w C:\Program Files\MessengerPlus! 3 2008-01-22 17:57 --------- d-----w C:\Program Files\QuickTime 2008-01-19 13:56 --------- d--h--w C:\Program Files\InstallShield Installation Information 2008-01-19 10:18 278,984 ----a-w C:\WINDOWS\system32\drivers\atksgt.sys 2008-01-18 18:58 22,328 ----a-w C:\WINDOWS\system32\drivers\PnkBstrK.sys 2007-12-06 05:03 --------- d-----w C:\Program Files\DAP 2007-12-05 07:20 805 ----a-w C:\WINDOWS\system32\drivers\SYMEVENT.INF 2007-12-05 07:20 123,952 ----a-w C:\WINDOWS\system32\drivers\SYMEVENT.SYS 2007-12-05 07:20 10,740 ----a-w C:\WINDOWS\system32\drivers\SYMEVENT.CAT 2007-12-05 07:20 --------- d-----w C:\Program Files\Symantec 2007-11-30 22:29 --------- d-----w C:\Program Files\Windows Live Toolbar 2007-11-30 21:57 43,696 ----a-w C:\WINDOWS\system32\drivers\srtspx.sys 2007-11-30 21:57 317,616 ----a-w C:\WINDOWS\system32\drivers\srtspl.sys 2007-11-30 21:57 279,088 ----a-w C:\WINDOWS\system32\drivers\srtsp.sys 2007-11-30 21:57 10,549 ----a-w C:\WINDOWS\system32\drivers\srtspx.cat 2007-11-30 21:57 10,549 ----a-w C:\WINDOWS\system32\drivers\srtspl.cat 2007-11-30 21:57 10,545 ----a-w C:\WINDOWS\system32\drivers\srtsp.cat 2007-11-30 21:57 1,430 ----a-w C:\WINDOWS\system32\drivers\srtspl.inf 2007-11-30 21:57 1,421 ----a-w C:\WINDOWS\system32\drivers\srtspx.inf 2007-11-30 21:57 1,415 ----a-w C:\WINDOWS\system32\drivers\srtsp.inf . Code: <pre> ----a-w 22,528 2008-01-22 19:06:43 C:\WINDOWS\system32\ctfmon .exe </pre> ((((((((((((((((((((((((((((((((((((( Reg Loading Points )))))))))))))))))))))))))))))))))))))))))))))))))) . . *Note* empty entries & legit default entries are not shown REGEDIT4 [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] "ctfmon.exe"="C:\WINDOWS\system32\ctfmon.exe" [ ] "WMPNSCFG"="C:\Program Files\Windows Media Player\WMPNSCFG.exe" [ ] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] "NvCplDaemon"="C:\WINDOWS\system32\NvCpl.dll" [2006-10-22 12:22 7700480] "type32"="C:\Program Files\Microsoft IntelliType Pro\type32.exe" [ ] "IntelliPoint"="C:\Program Files\Microsoft IntelliPoint\point32.exe" [ ] "HPDJ Taskbar Utility"="C:\WINDOWS\system32\spool\drivers\w32x86\3\hpztsb04.exe" [ ] "USB2Check"="C:\WINDOWS\system32\PCLECoInst.dll" [2004-09-21 12:22 73728] "LVCOMSX"="C:\WINDOWS\system32\LVCOMSX.EXE" [ ] "InCD"="C:\Program Files\Ahead\InCD\InCD.exe" [ ] "NvMediaCenter"="C:\WINDOWS\system32\NvMcTray.dll" [2006-10-22 12:22 86016] "osCheck"="C:\Program Files\Norton Internet Security\osCheck.exe" [ ] "ccApp"="C:\Program Files\Common Files\Symantec Shared\ccApp.exe" [ ] "Symantec PIF AlertEng"="C:\Program Files\Common Files\Symantec Shared\PIF\{B8E1DD85-8582-4c61-B58F-2F227FCA9A08}\PIFSvc.exe" [ ] "WorksFUD"="C:\Program Files\Microsoft Works\wkfud.exe" [ ] "WinFaxAppPortStarter"="wfxsnt40.exe" [2000-02-14 16:36 43008 C:\WINDOWS\system32\WFXSNT40.EXE] "SunJavaUpdateSched"="C:\Program Files\Java\jre1.6.0_02\bin\jusched.exe" [ ] "nwiz"="nwiz.exe" [2006-10-22 12:22 1630208 C:\WINDOWS\system32\nwiz.exe] "NeroFilterCheck"="C:\WINDOWS\system32\NeroCheck.exe" [ ] "msnappau"="C:\Program Files\MSN Apps\Updater\01.02.3000.1001\el-gr\msnappau.exe" [ ] "Microsoft Works Update Detection"="C:\Program Files\Microsoft Works\WkDetect.exe" [ ] "Microsoft Works Portfolio"="C:\Program Files\Microsoft Works\WksSb.exe" [ ] "MediaGateway"="C:\Program Files\MediaGateway\MediaGateway.exe" [ ] "Default bits loud great"="C:\Documents and Settings\All Users\Application Data\settings phone default bits\fast 16.exe" [ ] "DataLayer"="C:\Program Files\Common Files\PCSuite\DataLayer\DataLayer.exe" [ ] "SoundMan"="SOUNDMAN.EXE" [] "MSConfig"="C:\WINDOWS\PCHealth\HelpCtr\Binaries\MSConfig.exe" [ ] [HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run] "CTFMON.EXE"="C:\WINDOWS\system32\CTFMON.EXE" [ ] [HKEY_CURRENT_USER\software\microsoft\windows\currentversion\policies\explor er] "NoViewOnDrive"= 0 (0x0) [hkey_local_machine\software\microsoft\windows\currentversion\explorer\shell executehooks] "{93994DE8-8239-4655-B1D1-5F4E91300429}"= C:\Program Files\DVD Region+CSS Free\DVDShell.dll [2004-06-08 15:18 49152] "{A213B520-C6C2-11d0-AF9D-008029E1027E}"= C:\Program Files\Symantec\WinFax\WfxSeh32.Dll [1998-07-27 03:54 38400] [HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\windows] "AppInit_DLLs"=MsgPlusLoader.dll [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\Bin06. sys] @="Driver" [HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Προγράμματα^Εκκίνηση^Acrobat Assistant.lnk] path=C:\Documents and Settings\All Users\Start Menu\Προγράμματα\Εκκίνηση\Acrobat Assistant.lnk backup=C:\WINDOWS\pss\Acrobat Assistant.lnkCommon Startup [HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Προγράμματα^Εκκίνηση^Windows Desktop Search.lnk] path=C:\Documents and Settings\All Users\Start Menu\Προγράμματα\Εκκίνηση\Windows Desktop Search.lnk backup=C:\WINDOWS\pss\Windows Desktop Search.lnkCommon Startup [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\dent meow] C:\DOCUME~1\User\APPLIC~1\RDRSEN~1\Bend1.exe [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Load] C:\WINDOWS\system32\vtutu.exe [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\LogitechSoftwareUpdate] C:\Program Files\Logitech\Video\ManifestEngine.exe [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\LogitechVideoRepair] --a------ 2008-01-22 19:58 829440 C:\Program Files\Logitech\Video\ISStart.exe [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\LogitechVideoTray] --a------ 2008-01-22 19:58 564224 C:\Program Files\Logitech\Video\LogiTray.exe [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\MessengerPlus3] --a------ 2008-01-22 19:58 574976 C:\Program Files\MessengerPlus! 3\MsgPlus.exe [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\MSMSGS] C:\Program Files\Messenger\msmsgs.exe [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\msnmsgr] C:\Program Files\MSN Messenger\msnmsgr.exe [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\NetPumper] C:\Program Files\NetPumper\NetPumperIEProxy.exe [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Nokia Tray Application] --a------ 2008-01-22 19:57 964608 C:\Program Files\Common Files\Nokia\NCLTools\NclTray.exe [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Norton SystemWorks] C:\Program Files\Norton SystemWorks\cfgwiz.exe [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\ntuser] C:\WINDOWS\system32\drivers\spool.exe [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\PCLEPCI] C:\PROGRA~1\Pinnacle\PPE\PPE.EXE [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\PCSuiteTrayApplication] --a------ 2008-01-22 19:57 599552 C:\PROGRA~1\Nokia\NOKIAP~1\LAUNCH~1.exe [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\PcSync] C:\Program Files\Nokia\Nokia PC Suite 6\PcSync2.exe [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\QuickTime Task] --a------ 2008-01-22 19:57 454144 C:\Program Files\QuickTime\qttask.exe [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\RemoteControl] --a------ 2008-01-22 19:57 380416 C:\Program Files\CyberLink\PowerDVD\PDVDServ.exe [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\ServiceLayer] C:\Program Files\Common Files\Nokia\Services\ServiceLayer.exe [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Share-to-Web Namespace Daemon] --a------ 2008-01-22 19:57 416256 C:\Program Files\Hewlett-Packard\HP Share-to-Web\hpgs2wnd.exe [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Skype] C:\Program Files\Skype\Phone\Skype.exe [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Steam] [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\USBToolTip] C:\Program Files\Pinnacle\Shared Files\Programs\USBTip\USBTip.exe [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\XSC SIP Client] C:\Program Files\X-Lite\X-Lite.exe R0 Bin06;Bin06;C:\WINDOWS\system32\Drivers\Bin06.sys [2008-01-23 13:11] R2 KC180;IRXpress USB IrDA Device;C:\WINDOWS\system32\Drivers\kcirusb.sys [2001-10-04 09:23] R2 wfxsvc;WinFax PRO;C:\WINDOWS\system32\WFXSVC.EXE [2000-02-14 16:36] R3 KCIRDA;%KCIRDA.ServiceDesc%;C:\WINDOWS\system32\DRIVERS\KCIrNet.sys [2001-10-04 09:23] S3 CEDRIVER51;CEDRIVER51;C:\games\World of Warcraft\Cheat Engine\DBK32.sys [] [HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountp oints2\{c1a826d8-a64a-11db-983c-0015f20f1914}] \Shell\AutoRun\command - G:\load.exe /CDROM . Contents of the 'Scheduled Tasks' folder "2008-01-22 18:00:00 C:\WINDOWS\Tasks\B577111791A08367.job" - c:\docume~1\user\applic~1\rdrsen~1\camplogobits.exe "2008-01-23 11:22:01 C:\WINDOWS\Tasks\Check Updates for Windows Live Toolbar.job" - C:\Program Files\Windows Live Toolbar\MSNTBUP.EXE . ************************************************************************** catchme 0.3.1344 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net Rootkit scan 2008-01-23 13:31:02 Windows 5.1.2600 Service Pack 2 NTFS detected NTDLL code modification: ZwOpenFile scanning hidden processes ... scanning hidden autostart entries ... scanning hidden files ... scan completed successfully hidden files: 0 ************************************************************************** i first done the combo fix scan then the hijackthis scan |
25-Jan-2008, 11:41 AM
#8 | |||||
| Download the Trial version of Superantispyware Pro (SAS): http://www.superantispyware.com/supe....html?rid=3132 Install it and double-click the icon on your desktop to run it. · It will ask if you want to update the program definitions, click Yes. · Under Configuration and Preferences, click the Preferences button. · Click the Scanning Control tab. · Under Scanner Options make sure the following are checked: o Close browsers before scanning o Scan for tracking cookies o Terminate memory threats before quarantining. o Please leave the others unchecked. o Click the Close button to leave the control center screen. · On the main screen, under Scan for Harmful Software click Scan your computer. · On the left check C:\Fixed Drive. · On the right, under Complete Scan, choose Perform Complete Scan. · Click Next to start the scan. Please be patient while it scans your computer. · After the scan is complete a summary box will appear. Click OK. · Make sure everything in the white box has a check next to it, then click Next. · It will quarantine what it found and if it asks if you want to reboot, click Yes. · To retrieve the removal information for me please do the following: o After reboot, double-click the SUPERAntispyware icon on your desktop. o Click Preferences. Click the Statistics/Logs tab. o Under Scanner Logs, double-click SUPERAntiSpyware Scan Log. o It will open in your default text editor (such as Notepad/Wordpad). o Please highlight everything in the notepad, then right-click and choose copy. · Click close and close again to exit the program. · Please paste that information here for me with a new Hijack This log. |
|
25-Jan-2008, 06:21 PM
#9 |
| Ok before i do all these with superAntispyware and a new hijack i first done a combo fix scan because i was recieving again and again strange errors also i couldnt open IE and taskmanager i done many restarts to finaly run task manager and open the explorer.OK here we go (SUPERAntispyware scan info) SUPERAntiSpyware Scan Log http://www.superantispyware.com Generated 01/25/2008 at 11:28 PM Application Version : 3.9.1008 Core Rules Database Version : 3388 Trace Rules Database Version: 1382 Scan type : Complete Scan Total Scan Time : 02:11:40 Memory items scanned : 403 Memory threats detected : 0 Registry items scanned : 7131 Registry threats detected : 8 File items scanned : 72976 File threats detected : 431 Rootkit.RunTime3/FutureGen HKLM\System\ControlSet001\Services\Bin06 C:\WINDOWS\SYSTEM32\DRIVERS\BIN06.SYS HKLM\System\ControlSet002\Services\Bin06 HKLM\System\CurrentControlSet\Services\Bin06 C:\SYSTEM VOLUME INFORMATION\_RESTORE{7A51E4F6-A36F-4E25-8376-8DD35E81AB33}\RP2\A0000205.SYS C:\SYSTEM VOLUME INFORMATION\_RESTORE{7A51E4F6-A36F-4E25-8376-8DD35E81AB33}\RP2\A0000285.SYS C:\SYSTEM VOLUME INFORMATION\_RESTORE{7A51E4F6-A36F-4E25-8376-8DD35E81AB33}\RP2\A0001746.SYS C:\SYSTEM VOLUME INFORMATION\_RESTORE{7A51E4F6-A36F-4E25-8376-8DD35E81AB33}\RP3\A0002259.SYS C:\SYSTEM VOLUME INFORMATION\_RESTORE{7A51E4F6-A36F-4E25-8376-8DD35E81AB33}\RP6\A0002603.SYS C:\SYSTEM VOLUME INFORMATION\_RESTORE{7A51E4F6-A36F-4E25-8376-8DD35E81AB33}\RP6\A0002950.SYS C:\SYSTEM VOLUME INFORMATION\_RESTORE{7A51E4F6-A36F-4E25-8376-8DD35E81AB33}\RP6\A0003121.SYS C:\SYSTEM VOLUME INFORMATION\_RESTORE{7A51E4F6-A36F-4E25-8376-8DD35E81AB33}\RP7\A0003283.SYS C:\SYSTEM VOLUME INFORMATION\_RESTORE{7A51E4F6-A36F-4E25-8376-8DD35E81AB33}\RP7\A0005599.SYS Rootkit.SMTPDrv-Variant HKLM\System\ControlSet001\Services\smtpdrv C:\WINDOWS\SYSTEM32\DRIVERS\SMTPDRV.SYS HKLM\System\CurrentControlSet\Services\smtpdrv C:\QOOBOX\QUARANTINE\C\WINDOWS\SYSTEM32\DRIVERS\SMTPDRV.SYS.VIR C:\SYSTEM VOLUME INFORMATION\_RESTORE{7A51E4F6-A36F-4E25-8376-8DD35E81AB33}\RP3\A0002427.SYS C:\SYSTEM VOLUME INFORMATION\_RESTORE{7A51E4F6-A36F-4E25-8376-8DD35E81AB33}\RP6\A0002593.SYS C:\SYSTEM VOLUME INFORMATION\_RESTORE{7A51E4F6-A36F-4E25-8376-8DD35E81AB33}\RP6\A0002995.SYS C:\SYSTEM VOLUME INFORMATION\_RESTORE{7A51E4F6-A36F-4E25-8376-8DD35E81AB33}\RP6\A0003150.SYS C:\SYSTEM VOLUME INFORMATION\_RESTORE{7A51E4F6-A36F-4E25-8376-8DD35E81AB33}\RP7\A0003307.SYS C:\SYSTEM VOLUME INFORMATION\_RESTORE{7A51E4F6-A36F-4E25-8376-8DD35E81AB33}\RP7\A0004288.SYS C:\SYSTEM VOLUME INFORMATION\_RESTORE{7A51E4F6-A36F-4E25-8376-8DD35E81AB33}\RP7\A0005318.SYS Trojan.Vundo/Variant-Installer/A C:\PROGRAM FILES\LOGITECH\VIDEO\LOGITRAY.EXE HKLM\Software\Microsoft\Windows\CurrentVersion\App Paths\Logitray.exe HKLM\Software\Microsoft\Windows\CurrentVersion\App Paths\Logitray.exe#Path C:\DOCUMENTS AND SETTINGS\USER\LOCAL SETTINGS\TEMP\RCX1162.TMP C:\DOCUMENTS AND SETTINGS\USER\LOCAL SETTINGS\TEMP\RCX6C.TMP C:\DOCUMENTS AND SETTINGS\USER\LOCAL SETTINGS\TEMP\RCXA2.TMP C:\DOCUMENTS AND SETTINGS\USER\LOCAL SETTINGS\TEMP\RCXB1.TMP C:\DOCUMENTS AND SETTINGS\USER\LOCAL SETTINGS\TEMP\RCXB7.TMP C:\DOCUMENTS AND SETTINGS\USER\LOCAL SETTINGS\TEMP\TMP1160.TMP C:\DOCUMENTS AND SETTINGS\USER\LOCAL SETTINGS\TEMP\TMP11EC.TMP C:\DOCUMENTS AND SETTINGS\USER\LOCAL SETTINGS\TEMP\TMP12.TMP C:\DOCUMENTS AND SETTINGS\USER\LOCAL SETTINGS\TEMP\TMP1245.TMP C:\DOCUMENTS AND SETTINGS\USER\LOCAL SETTINGS\TEMP\TMP5.TMP C:\PROGRAM FILES\COMMON FILES\NOKIA\NCLTOOLS\NCLTRAY.EXE C:\PROGRAM FILES\CYBERLINK\POWERDVD\PDVDSERV.EXE C:\PROGRAM FILES\HEWLETT-PACKARD\HP SHARE-TO-WEB\HPGS2WND.EXE C:\PROGRAM FILES\LOGITECH\VIDEO\ISSTART.EXE C:\PROGRAM FILES\MESSENGERPLUS! 3\MSGPLUS.EXE C:\PROGRAM FILES\NOKIA\NOKIA PC SUITE 6\LAUNCHAPPLICATION.EXE C:\PROGRAM FILES\QUICKTIME\QTTASK.EXE C:\QOOBOX\QUARANTINE\C\PROGRAM FILES\AHEAD\INCD\INCD .EXE.VIR C:\QOOBOX\QUARANTINE\C\PROGRAM FILES\AHEAD\INCD\INCD.EXE.VIR C:\QOOBOX\QUARANTINE\C\PROGRAM FILES\COMMON FILES\PCSUITE\DATALAYER\DATALAYER .EXE.VIR C:\QOOBOX\QUARANTINE\C\PROGRAM FILES\COMMON FILES\PCSUITE\DATALAYER\DATALAYER.EXE.VIR C:\QOOBOX\QUARANTINE\C\PROGRAM FILES\COMMON FILES\SYMANTEC SHARED\CCAPP .EXE.VIR C:\QOOBOX\QUARANTINE\C\PROGRAM FILES\COMMON FILES\SYMANTEC SHARED\CCAPP.EXE.VIR C:\QOOBOX\QUARANTINE\C\PROGRAM FILES\COMMON FILES\SYMANTEC SHARED\PIF\{B8E1DD85-8582-4C61-B58F-2F227FCA9A08}\PIFSVC .EXE.VIR C:\QOOBOX\QUARANTINE\C\PROGRAM FILES\COMMON FILES\SYMANTEC SHARED\PIF\{B8E1DD85-8582-4C61-B58F-2F227FCA9A08}\PIFSVC.EXE.VIR C:\QOOBOX\QUARANTINE\C\PROGRAM FILES\JAVA\JRE1.6.0_02\BIN\JUSCHED .EXE.VIR C:\QOOBOX\QUARANTINE\C\PROGRAM FILES\JAVA\JRE1.6.0_02\BIN\JUSCHED.EXE.VIR C:\QOOBOX\QUARANTINE\C\PROGRAM FILES\LOGITECH\VIDEO\MANIFESTENGINE.EXE.VIR C:\QOOBOX\QUARANTINE\C\PROGRAM FILES\MESSENGER\MSMSGS.EXE.VIR C:\QOOBOX\QUARANTINE\C\PROGRAM FILES\MICROSOFT INTELLIPOINT\POINT32 .EXE.VIR C:\QOOBOX\QUARANTINE\C\PROGRAM FILES\MICROSOFT INTELLITYPE PRO\TYPE32 .EXE.VIR C:\QOOBOX\QUARANTINE\C\PROGRAM FILES\MICROSOFT WORKS\WKDETECT .EXE.VIR C:\QOOBOX\QUARANTINE\C\PROGRAM FILES\MICROSOFT WORKS\WKDETECT.EXE.VIR C:\QOOBOX\QUARANTINE\C\PROGRAM FILES\MICROSOFT WORKS\WKFUD .EXE.VIR C:\QOOBOX\QUARANTINE\C\PROGRAM FILES\MICROSOFT WORKS\WKFUD.EXE.VIR C:\QOOBOX\QUARANTINE\C\PROGRAM FILES\MICROSOFT WORKS\WKSSB .EXE.VIR C:\QOOBOX\QUARANTINE\C\PROGRAM FILES\MICROSOFT WORKS\WKSSB.EXE.VIR C:\QOOBOX\QUARANTINE\C\PROGRAM FILES\MSN MESSENGER\MSNMSGR.EXE.VIR C:\QOOBOX\QUARANTINE\C\PROGRAM FILES\NOKIA\NOKIA PC SUITE 6\PCSYNC2.EXE.VIR C:\QOOBOX\QUARANTINE\C\PROGRAM FILES\NORTON INTERNET SECURITY\OSCHECK .EXE.VIR C:\QOOBOX\QUARANTINE\C\PROGRAM FILES\NORTON INTERNET SECURITY\OSCHECK.EXE.VIR C:\QOOBOX\QUARANTINE\C\PROGRAM FILES\QUICKTIME\QTTASK .EXE.VIR C:\QOOBOX\QUARANTINE\C\PROGRAM FILES\QUICKTIME\QTTASK .EXE.VIR C:\QOOBOX\QUARANTINE\C\PROGRAM FILES\SKYPE\PHONE\SKYPE.EXE.VIR C:\QOOBOX\QUARANTINE\C\PROGRAM FILES\WINDOWS MEDIA PLAYER\WMPNSCFG .EXE.VIR C:\QOOBOX\QUARANTINE\C\PROGRAM FILES\X-LITE\X-LITE.EXE.VIR C:\QOOBOX\QUARANTINE\C\WINDOWS\PCHEALTH\HELPCTR\BINARIES\MSCONFIG .EXE.VIR C:\QOOBOX\QUARANTINE\C\WINDOWS\PCHEALTH\HELPCTR\BINARIES\MSCONFIG.EXE.VIR C:\QOOBOX\QUARANTINE\C\WINDOWS\SOUNDMAN .EXE.VIR C:\QOOBOX\QUARANTINE\C\WINDOWS\SOUNDMAN.EXE.VIR C:\QOOBOX\QUARANTINE\C\WINDOWS\SYSTEM32\LVCOMSX .EXE.VIR C:\QOOBOX\QUARANTINE\C\WINDOWS\SYSTEM32\LVCOMSX.EXE.VIR C:\QOOBOX\QUARANTINE\C\WINDOWS\SYSTEM32\NEROCHECK .EXE.VIR C:\QOOBOX\QUARANTINE\C\WINDOWS\SYSTEM32\NEROCHECK.EXE.VIR C:\QOOBOX\QUARANTINE\C\WINDOWS\SYSTEM32\SPOOL\DRIVERS\W32X86\3\HPZTSB04 .EXE.VIR C:\SYSTEM VOLUME INFORMATION\_RESTORE{7A51E4F6-A36F-4E25-8376-8DD35E81AB33}\RP0\A0000068.EXE C:\SYSTEM VOLUME INFORMATION\_RESTORE{7A51E4F6-A36F-4E25-8376-8DD35E81AB33}\RP0\A0000071.EXE C:\SYSTEM VOLUME INFORMATION\_RESTORE{7A51E4F6-A36F-4E25-8376-8DD35E81AB33}\RP0\A0000072.EXE C:\SYSTEM VOLUME INFORMATION\_RESTORE{7A51E4F6-A36F-4E25-8376-8DD35E81AB33}\RP0\A0000076.EXE C:\SYSTEM VOLUME INFORMATION\_RESTORE{7A51E4F6-A36F-4E25-8376-8DD35E81AB33}\RP0\A0000078.EXE C:\SYSTEM VOLUME INFORMATION\_RESTORE{7A51E4F6-A36F-4E25-8376-8DD35E81AB33}\RP0\A0000081.EXE C:\SYSTEM VOLUME INFORMATION\_RESTORE{7A51E4F6-A36F-4E25-8376-8DD35E81AB33}\RP0\A0000082.EXE C:\SYSTEM VOLUME INFORMATION\_RESTORE{7A51E4F6-A36F-4E25-8376-8DD35E81AB33}\RP0\A0000084.EXE C:\SYSTEM VOLUME INFORMATION\_RESTORE{7A51E4F6-A36F-4E25-8376-8DD35E81AB33}\RP0\A0000088.EXE C:\SYSTEM VOLUME INFORMATION\_RESTORE{7A51E4F6-A36F-4E25-8376-8DD35E81AB33}\RP0\A0000090.EXE C:\SYSTEM VOLUME INFORMATION\_RESTORE{7A51E4F6-A36F-4E25-8376-8DD35E81AB33}\RP0\A0000091.EXE C:\SYSTEM VOLUME INFORMATION\_RESTORE{7A51E4F6-A36F-4E25-8376-8DD35E81AB33}\RP0\A0000097.EXE C:\SYSTEM VOLUME INFORMATION\_RESTORE{7A51E4F6-A36F-4E25-8376-8DD35E81AB33}\RP0\A0000099.EXE C:\SYSTEM VOLUME INFORMATION\_RESTORE{7A51E4F6-A36F-4E25-8376-8DD35E81AB33}\RP0\A0000100.EXE C:\SYSTEM VOLUME INFORMATION\_RESTORE{7A51E4F6-A36F-4E25-8376-8DD35E81AB33}\RP0\A0000105.EXE C:\SYSTEM VOLUME INFORMATION\_RESTORE{7A51E4F6-A36F-4E25-8376-8DD35E81AB33}\RP0\A0000135.EXE C:\SYSTEM VOLUME INFORMATION\_RESTORE{7A51E4F6-A36F-4E25-8376-8DD35E81AB33}\RP0\A0000138.EXE C:\SYSTEM VOLUME INFORMATION\_RESTORE{7A51E4F6-A36F-4E25-8376-8DD35E81AB33}\RP0\A0000140.EXE C:\SYSTEM VOLUME INFORMATION\_RESTORE{7A51E4F6-A36F-4E25-8376-8DD35E81AB33}\RP1\A0000141.EXE C:\SYSTEM VOLUME INFORMATION\_RESTORE{7A51E4F6-A36F-4E25-8376-8DD35E81AB33}\RP1\A0000143.EXE C:\SYSTEM VOLUME INFORMATION\_RESTORE{7A51E4F6-A36F-4E25-8376-8DD35E81AB33}\RP1\A0000144.EXE C:\SYSTEM VOLUME INFORMATION\_RESTORE{7A51E4F6-A36F-4E25-8376-8DD35E81AB33}\RP1\A0000145.EXE C:\SYSTEM VOLUME INFORMATION\_RESTORE{7A51E4F6-A36F-4E25-8376-8DD35E81AB33}\RP1\A0000146.EXE C:\SYSTEM VOLUME INFORMATION\_RESTORE{7A51E4F6-A36F-4E25-8376-8DD35E81AB33}\RP1\A0000147.EXE C:\SYSTEM VOLUME INFORMATION\_RESTORE{7A51E4F6-A36F-4E25-8376-8DD35E81AB33}\RP1\A0000148.EXE C:\SYSTEM VOLUME INFORMATION\_RESTORE{7A51E4F6-A36F-4E25-8376-8DD35E81AB33}\RP1\A0000149.EXE C:\SYSTEM VOLUME INFORMATION\_RESTORE{7A51E4F6-A36F-4E25-8376-8DD35E81AB33}\RP1\A0000150.EXE C:\SYSTEM VOLUME INFORMATION\_RESTORE{7A51E4F6-A36F-4E25-8376-8DD35E81AB33}\RP1\A0000152.EXE C:\SYSTEM VOLUME INFORMATION\_RESTORE{7A51E4F6-A36F-4E25-8376-8DD35E81AB33}\RP1\A0000153.EXE C:\SYSTEM VOLUME INFORMATION\_RESTORE{7A51E4F6-A36F-4E25-8376-8DD35E81AB33}\RP1\A0000154.EXE C:\SYSTEM VOLUME INFORMATION\_RESTORE{7A51E4F6-A36F-4E25-8376-8DD35E81AB33}\RP1\A0000155.EXE C:\SYSTEM VOLUME INFORMATION\_RESTORE{7A51E4F6-A36F-4E25-8376-8DD35E81AB33}\RP1\A0000156.EXE C:\SYSTEM VOLUME INFORMATION\_RESTORE{7A51E4F6-A36F-4E25-8376-8DD35E81AB33}\RP1\A0000158.EXE C:\SYSTEM VOLUME INFORMATION\_RESTORE{7A51E4F6-A36F-4E25-8376-8DD35E81AB33}\RP2\A0000261.EXE C:\SYSTEM VOLUME INFORMATION\_RESTORE{7A51E4F6-A36F-4E25-8376-8DD35E81AB33}\RP2\A0000263.EXE C:\SYSTEM VOLUME INFORMATION\_RESTORE{7A51E4F6-A36F-4E25-8376-8DD35E81AB33}\RP2\A0000265.EXE C:\SYSTEM VOLUME INFORMATION\_RESTORE{7A51E4F6-A36F-4E25-8376-8DD35E81AB33}\RP2\A0000266.EXE C:\SYSTEM VOLUME INFORMATION\_RESTORE{7A51E4F6-A36F-4E25-8376-8DD35E81AB33}\RP2\A0000267.EXE C:\SYSTEM VOLUME INFORMATION\_RESTORE{7A51E4F6-A36F-4E25-8376-8DD35E81AB33}\RP2\A0000268.EXE C:\SYSTEM VOLUME INFORMATION\_RESTORE{7A51E4F6-A36F-4E25-8376-8DD35E81AB33}\RP2\A0000269.EXE C:\SYSTEM VOLUME INFORMATION\_RESTORE{7A51E4F6-A36F-4E25-8376-8DD35E81AB33}\RP2\A0000270.EXE C:\SYSTEM VOLUME INFORMATION\_RESTORE{7A51E4F6-A36F-4E25-8376-8DD35E81AB33}\RP2\A0000271.EXE C:\SYSTEM VOLUME INFORMATION\_RESTORE{7A51E4F6-A36F-4E25-8376-8DD35E81AB33}\RP2\A0000272.EXE C:\SYSTEM VOLUME INFORMATION\_RESTORE{7A51E4F6-A36F-4E25-8376-8DD35E81AB33}\RP2\A0000273.EXE C:\SYSTEM VOLUME INFORMATION\_RESTORE{7A51E4F6-A36F-4E25-8376-8DD35E81AB33}\RP2\A0000274.EXE C:\SYSTEM VOLUME INFORMATION\_RESTORE{7A51E4F6-A36F-4E25-8376-8DD35E81AB33}\RP2\A0000275.EXE C:\SYSTEM VOLUME INFORMATION\_RESTORE{7A51E4F6-A36F-4E25-8376-8DD35E81AB33}\RP2\A0000276.EXE C:\SYSTEM VOLUME INFORMATION\_RESTORE{7A51E4F6-A36F-4E25-8376-8DD35E81AB33}\RP2\A0000277.EXE C:\SYSTEM VOLUME INFORMATION\_RESTORE{7A51E4F6-A36F-4E25-8376-8DD35E81AB33}\RP2\A0000278.EXE C:\SYSTEM VOLUME INFORMATION\_RESTORE{7A51E4F6-A36F-4E25-8376-8DD35E81AB33}\RP2\A0000279.EXE C:\SYSTEM VOLUME INFORMATION\_RESTORE{7A51E4F6-A36F-4E25-8376-8DD35E81AB33}\RP2\A0000296.EXE C:\SYSTEM VOLUME INFORMATION\_RESTORE{7A51E4F6-A36F-4E25-8376-8DD35E81AB33}\RP2\A0000308.EXE C:\SYSTEM VOLUME INFORMATION\_RESTORE{7A51E4F6-A36F-4E25-8376-8DD35E81AB33}\RP2\A0000323.EXE C:\SYSTEM VOLUME INFORMATION\_RESTORE{7A51E4F6-A36F-4E25-8376-8DD35E81AB33}\RP2\A0000331.EXE C:\SYSTEM VOLUME INFORMATION\_RESTORE{7A51E4F6-A36F-4E25-8376-8DD35E81AB33}\RP2\A0000332.EXE C:\SYSTEM VOLUME INFORMATION\_RESTORE{7A51E4F6-A36F-4E25-8376-8DD35E81AB33}\RP2\A0000333.EXE C:\SYSTEM VOLUME INFORMATION\_RESTORE{7A51E4F6-A36F-4E25-8376-8DD35E81AB33}\RP2\A0000334.EXE C:\SYSTEM VOLUME INFORMATION\_RESTORE{7A51E4F6-A36F-4E25-8376-8DD35E81AB33}\RP2\A0000335.EXE C:\SYSTEM VOLUME INFORMATION\_RESTORE{7A51E4F6-A36F-4E25-8376-8DD35E81AB33}\RP2\A0000336.EXE C:\SYSTEM VOLUME INFORMATION\_RESTORE{7A51E4F6-A36F-4E25-8376-8DD35E81AB33}\RP2\A0000337.EXE C:\SYSTEM VOLUME INFORMATION\_RESTORE{7A51E4F6-A36F-4E25-8376-8DD35E81AB33}\RP2\A0000338.EXE C:\SYSTEM VOLUME INFORMATION\_RESTORE{7A51E4F6-A36F-4E25-8376-8DD35E81AB33}\RP2\A0000339.EXE C:\SYSTEM VOLUME INFORMATION\_RESTORE{7A51E4F6-A36F-4E25-8376-8DD35E81AB33}\RP2\A0000340.EXE C:\SYSTEM VOLUME INFORMATION\_RESTORE{7A51E4F6-A36F-4E25-8376-8DD35E81AB33}\RP2\A0000341.EXE C:\SYSTEM VOLUME INFORMATION\_RESTORE{7A51E4F6-A36F-4E25-8376-8DD35E81AB33}\RP2\A0000342.EXE C:\SYSTEM VOLUME INFORMATION\_RESTORE{7A51E4F6-A36F-4E25-8376-8DD35E81AB33}\RP2\A0000343.EXE C:\SYSTEM VOLUME INFORMATION\_RESTORE{7A51E4F6-A36F-4E25-8376-8DD35E81AB33}\RP2\A0000344.EXE C:\SYSTEM VOLUME INFORMATION\_RESTORE{7A51E4F6-A36F-4E25-8376-8DD35E81AB33}\RP2\A0000351.EXE C:\SYSTEM VOLUME INFORMATION\_RESTORE{7A51E4F6-A36F-4E25-8376-8DD35E81AB33}\RP2\A0000353.EXE C:\SYSTEM VOLUME INFORMATION\_RESTORE{7A51E4F6-A36F-4E25-8376-8DD35E81AB33}\RP2\A0000355.EXE C:\SYSTEM VOLUME INFORMATION\_RESTORE{7A51E4F6-A36F-4E25-8376-8DD35E81AB33}\RP2\A0000382.EXE C:\SYSTEM VOLUME INFORMATION\_RESTORE{7A51E4F6-A36F-4E25-8376-8DD35E81AB33}\RP2\A0000438.EXE C:\SYSTEM VOLUME INFORMATION\_RESTORE{7A51E4F6-A36F-4E25-8376-8DD35E81AB33}\RP2\A0000580.EXE C:\SYSTEM VOLUME INFORMATION\_RESTORE{7A51E4F6-A36F-4E25-8376-8DD35E81AB33}\RP2\A0000671.EXE C:\SYSTEM VOLUME INFORMATION\_RESTORE{7A51E4F6-A36F-4E25-8376-8DD35E81AB33}\RP2\A0000802.EXE C:\SYSTEM VOLUME INFORMATION\_RESTORE{7A51E4F6-A36F-4E25-8376-8DD35E81AB33}\RP2\A0000806.EXE C:\SYSTEM VOLUME INFORMATION\_RESTORE{7A51E4F6-A36F-4E25-8376-8DD35E81AB33}\RP2\A0000810.EXE C:\SYSTEM VOLUME INFORMATION\_RESTORE{7A51E4F6-A36F-4E25-8376-8DD35E81AB33}\RP2\A0000819.EXE C:\SYSTEM VOLUME INFORMATION\_RESTORE{7A51E4F6-A36F-4E25-8376-8DD35E81AB33}\RP2\A0000841.EXE C:\SYSTEM VOLUME INFORMATION\_RESTORE{7A51E4F6-A36F-4E25-8376-8DD35E81AB33}\RP2\A0000854.EXE C:\SYSTEM VOLUME INFORMATION\_RESTORE{7A51E4F6-A36F-4E25-8376-8DD35E81AB33}\RP2\A0000865.EXE C:\SYSTEM VOLUME INFORMATION\_RESTORE{7A51E4F6-A36F-4E25-8376-8DD35E81AB33}\RP2\A0001765.EXE C:\SYSTEM VOLUME INFORMATION\_RESTORE{7A51E4F6-A36F-4E25-8376-8DD35E81AB33}\RP2\A0001767.EXE C:\SYSTEM VOLUME INFORMATION\_RESTORE{7A51E4F6-A36F-4E25-8376-8DD35E81AB33}\RP2\A0001770.EXE C:\SYSTEM VOLUME INFORMATION\_RESTORE{7A51E4F6-A36F-4E25-8376-8DD35E81AB33}\RP2\A0001772.EXE C:\SYSTEM VOLUME INFORMATION\_RESTORE{7A51E4F6-A36F-4E25-8376-8DD35E81AB33}\RP2\A0001773.EXE C:\SYSTEM VOLUME INFORMATION\_RESTORE{7A51E4F6-A36F-4E25-8376-8DD35E81AB33}\RP2\A0001775.EXE C:\SYSTEM VOLUME INFORMATION\_RESTORE{7A51E4F6-A36F-4E25-8376-8DD35E81AB33}\RP2\A0001776.EXE C:\SYSTEM VOLUME INFORMATION\_RESTORE{7A51E4F6-A36F-4E25-8376-8DD35E81AB33}\RP2\A0001779.EXE C:\SYSTEM VOLUME INFORMATION\_RESTORE{7A51E4F6-A36F-4E25-8376-8DD35E81AB33}\RP2\A0001781.EXE C:\SYSTEM VOLUME INFORMATION\_RESTORE{7A51E4F6-A36F-4E25-8376-8DD35E81AB33}\RP2\A0001787.EXE C:\SYSTEM VOLUME INFORMATION\_RESTORE{7A51E4F6-A36F-4E25-8376-8DD35E81AB33}\RP2\A0001789.EXE C:\SYSTEM VOLUME INFORMATION\_RESTORE{7A51E4F6-A36F-4E25-8376-8DD35E81AB33}\RP2\A0001791.EXE C:\SYSTEM VOLUME INFORMATION\_RESTORE{7A51E4F6-A36F-4E25-8376-8DD35E81AB33}\RP2\A0001793.EXE C:\SYSTEM VOLUME INFORMATION\_RESTORE{7A51E4F6-A36F-4E25-8376-8DD35E81AB33}\RP2\A0001795.EXE C:\SYSTEM VOLUME INFORMATION\_RESTORE{7A51E4F6-A36F-4E25-8376-8DD35E81AB33}\RP2\A0001799.EXE C:\SYSTEM VOLUME INFORMATION\_RESTORE{7A51E4F6-A36F-4E25-8376-8DD35E81AB33}\RP2\A0001800.EXE C:\SYSTEM VOLUME INFORMATION\_RESTORE{7A51E4F6-A36F-4E25-8376-8DD35E81AB33}\RP2\A0001801.EXE C:\SYSTEM VOLUME INFORMATION\_RESTORE{7A51E4F6-A36F-4E25-8376-8DD35E81AB33}\RP2\A0001812.EXE C:\SYSTEM VOLUME INFORMATION\_RESTORE{7A51E4F6-A36F-4E25-8376-8DD35E81AB33}\RP2\A0001820.EXE C:\SYSTEM VOLUME INFORMATION\_RESTORE{7A51E4F6-A36F-4E25-8376-8DD35E81AB33}\RP3\A0001906.EXE C:\SYSTEM VOLUME INFORMATION\_RESTORE{7A51E4F6-A36F-4E25-8376-8DD35E81AB33}\RP3\A0001916.EXE C:\SYSTEM VOLUME INFORMATION\_RESTORE{7A51E4F6-A36F-4E25-8376-8DD35E81AB33}\RP3\A0001919.EXE C:\SYSTEM VOLUME INFORMATION\_RESTORE{7A51E4F6-A36F-4E25-8376-8DD35E81AB33}\RP3\A0001920.EXE C:\SYSTEM VOLUME INFORMATION\_RESTORE{7A51E4F6-A36F-4E25-8376-8DD35E81AB33}\RP3\A0001921.EXE C:\SYSTEM VOLUME INFORMATION\_RESTORE{7A51E4F6-A36F-4E25-8376-8DD35E81AB33}\RP3\A0001922.EXE C:\SYSTEM VOLUME INFORMATION\_RESTORE{7A51E4F6-A36F-4E25-8376-8DD35E81AB33}\RP3\A0001923.EXE C:\SYSTEM VOLUME INFORMATION\_RESTORE{7A51E4F6-A36F-4E25-8376-8DD35E81AB33}\RP3\A0001924.EXE C:\SYSTEM VOLUME INFORMATION\_RESTORE{7A51E4F6-A36F-4E25-8376-8DD35E81AB33}\RP3\A0001925.EXE C:\SYSTEM VOLUME INFORMATION\_RESTORE{7A51E4F6-A36F-4E25-8376-8DD35E81AB33}\RP3\A0001926.EXE C:\SYSTEM VOLUME INFORMATION\_RESTORE{7A51E4F6-A36F-4E25-8376-8DD35E81AB33}\RP3\A0001927.EXE C:\SYSTEM VOLUME INFORMATION\_RESTORE{7A51E4F6-A36F-4E25-8376-8DD35E81AB33}\RP3\A0001928.EXE C:\SYSTEM VOLUME INFORMATION\_RESTORE{7A51E4F6-A36F-4E25-8376-8DD35E81AB33}\RP3\A0001929.EXE C:\SYSTEM VOLUME INFORMATION\_RESTORE{7A51E4F6-A36F-4E25-8376-8DD35E81AB33}\RP3\A0001930.EXE C:\SYSTEM VOLUME INFORMATION\_RESTORE{7A51E4F6-A36F-4E25-8376-8DD35E81AB33}\RP3\A0001931.EXE C:\SYSTEM VOLUME INFORMATION\_RESTORE{7A51E4F6-A36F-4E25-8376-8DD35E81AB33}\RP3\A0001932.EXE C:\SYSTEM VOLUME INFORMATION\_RESTORE{7A51E4F6-A36F-4E25-8376-8DD35E81AB33}\RP3\A0001933.EXE C:\SYSTEM VOLUME INFORMATION\_RESTORE{7A51E4F6-A36F-4E25-8376-8DD35E81AB33}\RP3\A0001935.EXE C:\SYSTEM VOLUME INFORMATION\_RESTORE{7A51E4F6-A36F-4E25-8376-8DD35E81AB33}\RP3\A0001936.EXE C:\SYSTEM VOLUME INFORMATION\_RESTORE{7A51E4F6-A36F-4E25-8376-8DD35E81AB33}\RP3\A0001940.EXE C:\SYSTEM VOLUME INFORMATION\_RESTORE{7A51E4F6-A36F-4E25-8376-8DD35E81AB33}\RP3\A0001944.EXE C:\SYSTEM VOLUME INFORMATION\_RESTORE{7A51E4F6-A36F-4E25-8376-8DD35E81AB33}\RP3\A0001945.EXE C:\SYSTEM VOLUME INFORMATION\_RESTORE{7A51E4F6-A36F-4E25-8376-8DD35E81AB33}\RP3\A0001947.EXE C:\SYSTEM VOLUME INFORMATION\_RESTORE{7A51E4F6-A36F-4E25-8376-8DD35E81AB33}\RP3\A0001948.EXE C:\SYSTEM VOLUME INFORMATION\_RESTORE{7A51E4F6-A36F-4E25-8376-8DD35E81AB33}\RP3\A0001949.EXE C:\SYSTEM VOLUME INFORMATION\_RESTORE{7A51E4F6-A36F-4E25-8376-8DD35E81AB33}\RP3\A0001950.EXE C:\SYSTEM VOLUME INFORMATION\_RESTORE{7A51E4F6-A36F-4E25-8376-8DD35E81AB33}\RP3\A0001979.EXE C:\SYSTEM VOLUME INFORMATION\_RESTORE{7A51E4F6-A36F-4E25-8376-8DD35E81AB33}\RP3\A0001994.EXE C:\SYSTEM VOLUME INFORMATION\_RESTORE{7A51E4F6-A36F-4E25-8376-8DD35E81AB33}\RP3\A0001996.EXE C:\SYSTEM VOLUME INFORMATION\_RESTORE{7A51E4F6-A36F-4E25-8376-8DD35E81AB33}\RP3\A0002013.EXE C:\SYSTEM VOLUME INFORMATION\_RESTORE{7A51E4F6-A36F-4E25-8376-8DD35E81AB33}\RP3\A0002014.EXE C:\SYSTEM VOLUME INFORMATION\_RESTORE{7A51E4F6-A36F-4E25-8376-8DD35E81AB33}\RP3\A0002015.EXE C:\SYSTEM VOLUME INFORMATION\_RESTORE{7A51E4F6-A36F-4E25-8376-8DD35E81AB33}\RP3\A0002016.EXE C:\SYSTEM VOLUME INFORMATION\_RESTORE{7A51E4F6-A36F-4E25-8376-8DD35E81AB33}\RP3\A0002017.EXE C:\SYSTEM VOLUME INFORMATION\_RESTORE{7A51E4F6-A36F-4E25-8376-8DD35E81AB33}\RP3\A0002018.EXE C:\SYSTEM VOLUME INFORMATION\_RESTORE{7A51E4F6-A36F-4E25-8376-8DD35E81AB33}\RP3\A0002019.EXE C:\SYSTEM VOLUME INFORMATION\_RESTORE{7A51E4F6-A36F-4E25-8376-8DD35E81AB33}\RP3\A0002022.EXE at next post the continue of the scan info to many characters and it didnt let me to post |
|
25-Jan-2008, 06:23 PM
#10 |
| C:\SYSTEM VOLUME INFORMATION\_RESTORE{7A51E4F6-A36F-4E25-8376-8DD35E81AB33}\RP3\A0002025.EXE C:\SYSTEM VOLUME INFORMATION\_RESTORE{7A51E4F6-A36F-4E25-8376-8DD35E81AB33}\RP3\A0002026.EXE C:\SYSTEM VOLUME INFORMATION\_RESTORE{7A51E4F6-A36F-4E25-8376-8DD35E81AB33}\RP3\A0002027.EXE C:\SYSTEM VOLUME INFORMATION\_RESTORE{7A51E4F6-A36F-4E25-8376-8DD35E81AB33}\RP3\A0002029.EXE C:\SYSTEM VOLUME INFORMATION\_RESTORE{7A51E4F6-A36F-4E25-8376-8DD35E81AB33}\RP3\A0002032.EXE C:\SYSTEM VOLUME INFORMATION\_RESTORE{7A51E4F6-A36F-4E25-8376-8DD35E81AB33}\RP3\A0002034.EXE C:\SYSTEM VOLUME INFORMATION\_RESTORE{7A51E4F6-A36F-4E25-8376-8DD35E81AB33}\RP3\A0002036.EXE C:\SYSTEM VOLUME INFORMATION\_RESTORE{7A51E4F6-A36F-4E25-8376-8DD35E81AB33}\RP3\A0002048.EXE C:\SYSTEM VOLUME INFORMATION\_RESTORE{7A51E4F6-A36F-4E25-8376-8DD35E81AB33}\RP3\A0002056.EXE C:\SYSTEM VOLUME INFORMATION\_RESTORE{7A51E4F6-A36F-4E25-8376-8DD35E81AB33}\RP3\A0002068.EXE C:\SYSTEM VOLUME INFORMATION\_RESTORE{7A51E4F6-A36F-4E25-8376-8DD35E81AB33}\RP3\A0002169.EXE C:\SYSTEM VOLUME INFORMATION\_RESTORE{7A51E4F6-A36F-4E25-8376-8DD35E81AB33}\RP3\A0002195.EXE C:\SYSTEM VOLUME INFORMATION\_RESTORE{7A51E4F6-A36F-4E25-8376-8DD35E81AB33}\RP3\A0002215.EXE C:\SYSTEM VOLUME INFORMATION\_RESTORE{7A51E4F6-A36F-4E25-8376-8DD35E81AB33}\RP3\A0002224.EXE C:\SYSTEM VOLUME INFORMATION\_RESTORE{7A51E4F6-A36F-4E25-8376-8DD35E81AB33}\RP3\A0002225.EXE C:\SYSTEM VOLUME INFORMATION\_RESTORE{7A51E4F6-A36F-4E25-8376-8DD35E81AB33}\RP3\A0002226.EXE C:\SYSTEM VOLUME INFORMATION\_RESTORE{7A51E4F6-A36F-4E25-8376-8DD35E81AB33}\RP3\A0002227.EXE C:\SYSTEM VOLUME INFORMATION\_RESTORE{7A51E4F6-A36F-4E25-8376-8DD35E81AB33}\RP3\A0002228.EXE C:\SYSTEM VOLUME INFORMATION\_RESTORE{7A51E4F6-A36F-4E25-8376-8DD35E81AB33}\RP3\A0002229.EXE C:\SYSTEM VOLUME INFORMATION\_RESTORE{7A51E4F6-A36F-4E25-8376-8DD35E81AB33}\RP3\A0002230.EXE C:\SYSTEM VOLUME INFORMATION\_RESTORE{7A51E4F6-A36F-4E25-8376-8DD35E81AB33}\RP3\A0002231.EXE C:\SYSTEM VOLUME INFORMATION\_RESTORE{7A51E4F6-A36F-4E25-8376-8DD35E81AB33}\RP3\A0002232.EXE C:\SYSTEM VOLUME INFORMATION\_RESTORE{7A51E4F6-A36F-4E25-8376-8DD35E81AB33}\RP3\A0002233.EXE C:\SYSTEM VOLUME INFORMATION\_RESTORE{7A51E4F6-A36F-4E25-8376-8DD35E81AB33}\RP3\A0002234.EXE C:\SYSTEM VOLUME INFORMATION\_RESTORE{7A51E4F6-A36F-4E25-8376-8DD35E81AB33}\RP3\A0002235.EXE C:\SYSTEM VOLUME INFORMATION\_RESTORE{7A51E4F6-A36F-4E25-8376-8DD35E81AB33}\RP3\A0002236.EXE C:\SYSTEM VOLUME INFORMATION\_RESTORE{7A51E4F6-A36F-4E25-8376-8DD35E81AB33}\RP3\A0002237.EXE C:\SYSTEM VOLUME INFORMATION\_RESTORE{7A51E4F6-A36F-4E25-8376-8DD35E81AB33}\RP3\A0002241.EXE C:\SYSTEM VOLUME INFORMATION\_RESTORE{7A51E4F6-A36F-4E25-8376-8DD35E81AB33}\RP3\A0002242.EXE C:\SYSTEM VOLUME INFORMATION\_RESTORE{7A51E4F6-A36F-4E25-8376-8DD35E81AB33}\RP3\A0002243.EXE C:\SYSTEM VOLUME INFORMATION\_RESTORE{7A51E4F6-A36F-4E25-8376-8DD35E81AB33}\RP3\A0002244.EXE C:\SYSTEM VOLUME INFORMATION\_RESTORE{7A51E4F6-A36F-4E25-8376-8DD35E81AB33}\RP3\A0002245.EXE C:\SYSTEM VOLUME INFORMATION\_RESTORE{7A51E4F6-A36F-4E25-8376-8DD35E81AB33}\RP3\A0002247.EXE C:\SYSTEM VOLUME INFORMATION\_RESTORE{7A51E4F6-A36F-4E25-8376-8DD35E81AB33}\RP3\A0002248.EXE C:\SYSTEM VOLUME INFORMATION\_RESTORE{7A51E4F6-A36F-4E25-8376-8DD35E81AB33}\RP3\A0002249.EXE C:\SYSTEM VOLUME INFORMATION\_RESTORE{7A51E4F6-A36F-4E25-8376-8DD35E81AB33}\RP3\A0002250.EXE C:\SYSTEM VOLUME INFORMATION\_RESTORE{7A51E4F6-A36F-4E25-8376-8DD35E81AB33}\RP3\A0002251.EXE C:\SYSTEM VOLUME INFORMATION\_RESTORE{7A51E4F6-A36F-4E25-8376-8DD35E81AB33}\RP3\A0002252.EXE C:\SYSTEM VOLUME INFORMATION\_RESTORE{7A51E4F6-A36F-4E25-8376-8DD35E81AB33}\RP3\A0002253.EXE C:\SYSTEM VOLUME INFORMATION\_RESTORE{7A51E4F6-A36F-4E25-8376-8DD35E81AB33}\RP3\A0002255.EXE C:\SYSTEM VOLUME INFORMATION\_RESTORE{7A51E4F6-A36F-4E25-8376-8DD35E81AB33}\RP3\A0002269.EXE C:\SYSTEM VOLUME INFORMATION\_RESTORE{7A51E4F6-A36F-4E25-8376-8DD35E81AB33}\RP3\A0002287.EXE C:\SYSTEM VOLUME INFORMATION\_RESTORE{7A51E4F6-A36F-4E25-8376-8DD35E81AB33}\RP3\A0002311.EXE C:\SYSTEM VOLUME INFORMATION\_RESTORE{7A51E4F6-A36F-4E25-8376-8DD35E81AB33}\RP3\A0002314.EXE C:\SYSTEM VOLUME INFORMATION\_RESTORE{7A51E4F6-A36F-4E25-8376-8DD35E81AB33}\RP3\A0002316.EXE C:\SYSTEM VOLUME INFORMATION\_RESTORE{7A51E4F6-A36F-4E25-8376-8DD35E81AB33}\RP3\A0002318.EXE C:\SYSTEM VOLUME INFORMATION\_RESTORE{7A51E4F6-A36F-4E25-8376-8DD35E81AB33}\RP3\A0002319.EXE C:\SYSTEM VOLUME INFORMATION\_RESTORE{7A51E4F6-A36F-4E25-8376-8DD35E81AB33}\RP3\A0002321.EXE C:\SYSTEM VOLUME INFORMATION\_RESTORE{7A51E4F6-A36F-4E25-8376-8DD35E81AB33}\RP3\A0002322.EXE C:\SYSTEM VOLUME INFORMATION\_RESTORE{7A51E4F6-A36F-4E25-8376-8DD35E81AB33}\RP3\A0002329.EXE C:\SYSTEM VOLUME INFORMATION\_RESTORE{7A51E4F6-A36F-4E25-8376-8DD35E81AB33}\RP3\A0002331.EXE C:\SYSTEM VOLUME INFORMATION\_RESTORE{7A51E4F6-A36F-4E25-8376-8DD35E81AB33}\RP3\A0002334.EXE C:\SYSTEM VOLUME INFORMATION\_RESTORE{7A51E4F6-A36F-4E25-8376-8DD35E81AB33}\RP3\A0002335.EXE C:\SYSTEM VOLUME INFORMATION\_RESTORE{7A51E4F6-A36F-4E25-8376-8DD35E81AB33}\RP3\A0002336.EXE C:\SYSTEM VOLUME INFORMATION\_RESTORE{7A51E4F6-A36F-4E25-8376-8DD35E81AB33}\RP3\A0002338.EXE C:\SYSTEM VOLUME INFORMATION\_RESTORE{7A51E4F6-A36F-4E25-8376-8DD35E81AB33}\RP3\A0002341.EXE C:\SYSTEM VOLUME INFORMATION\_RESTORE{7A51E4F6-A36F-4E25-8376-8DD35E81AB33}\RP3\A0002342.EXE C:\SYSTEM VOLUME INFORMATION\_RESTORE{7A51E4F6-A36F-4E25-8376-8DD35E81AB33}\RP3\A0002343.EXE C:\SYSTEM VOLUME INFORMATION\_RESTORE{7A51E4F6-A36F-4E25-8376-8DD35E81AB33}\RP3\A0002349.EXE C:\SYSTEM VOLUME INFORMATION\_RESTORE{7A51E4F6-A36F-4E25-8376-8DD35E81AB33}\RP3\A0002351.EXE C:\SYSTEM VOLUME INFORMATION\_RESTORE{7A51E4F6-A36F-4E25-8376-8DD35E81AB33}\RP3\A0002352.EXE C:\SYSTEM VOLUME INFORMATION\_RESTORE{7A51E4F6-A36F-4E25-8376-8DD35E81AB33}\RP3\A0002359.EXE C:\SYSTEM VOLUME INFORMATION\_RESTORE{7A51E4F6-A36F-4E25-8376-8DD35E81AB33}\RP4\A0002482.EXE C:\SYSTEM VOLUME INFORMATION\_RESTORE{7A51E4F6-A36F-4E25-8376-8DD35E81AB33}\RP4\A0002506.EXE C:\SYSTEM VOLUME INFORMATION\_RESTORE{7A51E4F6-A36F-4E25-8376-8DD35E81AB33}\RP4\A0002531.EXE C:\SYSTEM VOLUME INFORMATION\_RESTORE{7A51E4F6-A36F-4E25-8376-8DD35E81AB33}\RP5\A0002542.EXE C:\SYSTEM VOLUME INFORMATION\_RESTORE{7A51E4F6-A36F-4E25-8376-8DD35E81AB33}\RP6\A0002556.EXE C:\SYSTEM VOLUME INFORMATION\_RESTORE{7A51E4F6-A36F-4E25-8376-8DD35E81AB33}\RP6\A0002557.EXE C:\SYSTEM VOLUME INFORMATION\_RESTORE{7A51E4F6-A36F-4E25-8376-8DD35E81AB33}\RP6\A0002558.EXE C:\SYSTEM VOLUME INFORMATION\_RESTORE{7A51E4F6-A36F-4E25-8376-8DD35E81AB33}\RP6\A0002559.EXE C:\SYSTEM VOLUME INFORMATION\_RESTORE{7A51E4F6-A36F-4E25-8376-8DD35E81AB33}\RP6\A0002560.EXE C:\SYSTEM VOLUME INFORMATION\_RESTORE{7A51E4F6-A36F-4E25-8376-8DD35E81AB33}\RP6\A0002561.EXE C:\SYSTEM VOLUME INFORMATION\_RESTORE{7A51E4F6-A36F-4E25-8376-8DD35E81AB33}\RP6\A0002562.EXE C:\SYSTEM VOLUME INFORMATION\_RESTORE{7A51E4F6-A36F-4E25-8376-8DD35E81AB33}\RP6\A0002563.EXE C:\SYSTEM VOLUME INFORMATION\_RESTORE{7A51E4F6-A36F-4E25-8376-8DD35E81AB33}\RP6\A0002564.EXE C:\SYSTEM VOLUME INFORMATION\_RESTORE{7A51E4F6-A36F-4E25-8376-8DD35E81AB33}\RP6\A0002565.EXE C:\SYSTEM VOLUME INFORMATION\_RESTORE{7A51E4F6-A36F-4E25-8376-8DD35E81AB33}\RP6\A0002566.EXE C:\SYSTEM VOLUME INFORMATION\_RESTORE{7A51E4F6-A36F-4E25-8376-8DD35E81AB33}\RP6\A0002567.EXE C:\SYSTEM VOLUME INFORMATION\_RESTORE{7A51E4F6-A36F-4E25-8376-8DD35E81AB33}\RP6\A0002568.EXE C:\SYSTEM VOLUME INFORMATION\_RESTORE{7A51E4F6-A36F-4E25-8376-8DD35E81AB33}\RP6\A0002569.EXE C:\SYSTEM VOLUME INFORMATION\_RESTORE{7A51E4F6-A36F-4E25-8376-8DD35E81AB33}\RP6\A0002570.EXE C:\SYSTEM VOLUME INFORMATION\_RESTORE{7A51E4F6-A36F-4E25-8376-8DD35E81AB33}\RP6\A0002571.EXE C:\SYSTEM VOLUME INFORMATION\_RESTORE{7A51E4F6-A36F-4E25-8376-8DD35E81AB33}\RP6\A0002572.EXE C:\SYSTEM VOLUME INFORMATION\_RESTORE{7A51E4F6-A36F-4E25-8376-8DD35E81AB33}\RP6\A0002573.EXE C:\SYSTEM VOLUME INFORMATION\_RESTORE{7A51E4F6-A36F-4E25-8376-8DD35E81AB33}\RP6\A0002574.EXE C:\SYSTEM VOLUME INFORMATION\_RESTORE{7A51E4F6-A36F-4E25-8376-8DD35E81AB33}\RP6\A0002575.EXE C:\SYSTEM VOLUME INFORMATION\_RESTORE{7A51E4F6-A36F-4E25-8376-8DD35E81AB33}\RP6\A0002576.EXE C:\SYSTEM VOLUME INFORMATION\_RESTORE{7A51E4F6-A36F-4E25-8376-8DD35E81AB33}\RP6\A0002577.EXE C:\SYSTEM VOLUME INFORMATION\_RESTORE{7A51E4F6-A36F-4E25-8376-8DD35E81AB33}\RP6\A0002578.EXE C:\SYSTEM VOLUME INFORMATION\_RESTORE{7A51E4F6-A36F-4E25-8376-8DD35E81AB33}\RP6\A0002579.EXE C:\SYSTEM VOLUME INFORMATION\_RESTORE{7A51E4F6-A36F-4E25-8376-8DD35E81AB33}\RP6\A0002580.EXE C:\SYSTEM VOLUME INFORMATION\_RESTORE{7A51E4F6-A36F-4E25-8376-8DD35E81AB33}\RP6\A0002581.EXE C:\SYSTEM VOLUME INFORMATION\_RESTORE{7A51E4F6-A36F-4E25-8376-8DD35E81AB33}\RP6\A0002582.EXE C:\SYSTEM VOLUME INFORMATION\_RESTORE{7A51E4F6-A36F-4E25-8376-8DD35E81AB33}\RP6\A0002583.EXE C:\SYSTEM VOLUME INFORMATION\_RESTORE{7A51E4F6-A36F-4E25-8376-8DD35E81AB33}\RP6\A0002584.EXE C:\SYSTEM VOLUME INFORMATION\_RESTORE{7A51E4F6-A36F-4E25-8376-8DD35E81AB33}\RP6\A0002585.EXE C:\SYSTEM VOLUME INFORMATION\_RESTORE{7A51E4F6-A36F-4E25-8376-8DD35E81AB33}\RP6\A0002586.EXE C:\SYSTEM VOLUME INFORMATION\_RESTORE{7A51E4F6-A36F-4E25-8376-8DD35E81AB33}\RP6\A0002588.EXE C:\SYSTEM VOLUME INFORMATION\_RESTORE{7A51E4F6-A36F-4E25-8376-8DD35E81AB33}\RP6\A0002589.EXE C:\SYSTEM VOLUME INFORMATION\_RESTORE{7A51E4F6-A36F-4E25-8376-8DD35E81AB33}\RP6\A0002590.EXE C:\SYSTEM VOLUME INFORMATION\_RESTORE{7A51E4F6-A36F-4E25-8376-8DD35E81AB33}\RP6\A0002591.EXE C:\SYSTEM VOLUME INFORMATION\_RESTORE{7A51E4F6-A36F-4E25-8376-8DD35E81AB33}\RP6\A0002592.EXE C:\SYSTEM VOLUME INFORMATION\_RESTORE{7A51E4F6-A36F-4E25-8376-8DD35E81AB33}\RP6\A0003006.EXE C:\SYSTEM VOLUME INFORMATION\_RESTORE{7A51E4F6-A36F-4E25-8376-8DD35E81AB33}\RP6\A0003259.EXE C:\SYSTEM VOLUME INFORMATION\_RESTORE{7A51E4F6-A36F-4E25-8376-8DD35E81AB33}\RP7\A0005289.EXE C:\SYSTEM VOLUME INFORMATION\_RESTORE{7A51E4F6-A36F-4E25-8376-8DD35E81AB33}\RP7\A0005308.EXE C:\SYSTEM VOLUME INFORMATION\_RESTORE{7A51E4F6-A36F-4E25-8376-8DD35E81AB33}\RP7\A0005471.EXE C:\SYSTEM VOLUME INFORMATION\_RESTORE{7A51E4F6-A36F-4E25-8376-8DD35E81AB33}\RP8\A0005815.EXE C:\SYSTEM VOLUME INFORMATION\_RESTORE{7A51E4F6-A36F-4E25-8376-8DD35E81AB33}\RP8\A0006066.EXE C:\SYSTEM VOLUME INFORMATION\_RESTORE{7A51E4F6-A36F-4E25-8376-8DD35E81AB33}\RP8\A0006096.EXE C:\SYSTEM VOLUME INFORMATION\_RESTORE{7A51E4F6-A36F-4E25-8376-8DD35E81AB33}\RP8\A0006155.EXE C:\SYSTEM VOLUME INFORMATION\_RESTORE{7A51E4F6-A36F-4E25-8376-8DD35E81AB33}\RP8\A0006348.EXE C:\SYSTEM VOLUME INFORMATION\_RESTORE{7A51E4F6-A36F-4E25-8376-8DD35E81AB33}\RP8\A0006355.EXE C:\SYSTEM VOLUME INFORMATION\_RESTORE{7A51E4F6-A36F-4E25-8376-8DD35E81AB33}\RP8\A0006425.EXE C:\SYSTEM VOLUME INFORMATION\_RESTORE{7A51E4F6-A36F-4E25-8376-8DD35E81AB33}\RP8\A0006462.EXE C:\WINDOWS\Prefetch\QTTASK.EXE-0337C4B9.pf Adware.Tracking Cookie C:\Documents and Settings\User\Cookies\user@stats.e-go[1].txt C:\Documents and Settings\User\Cookies\user@adultadworld[1].txt C:\Documents and Settings\User\Cookies\user@secretxxxvideo[1].txt C:\Documents and Settings\User\Cookies\user@www.crackhell[1].txt C:\Documents and Settings\User\Cookies\user@yadro[2].txt C:\Documents and Settings\User\Cookies\user@mysexgames[2].txt C:\Documents and Settings\User\Cookies\user@imrworldwide[2].txt C:\Documents and Settings\User\Cookies\user@easywarez[1].txt C:\Documents and Settings\User\Cookies\user@adult-sex-games[1].txt C:\Documents and Settings\User\Cookies\user@adecn[2].txt C:\Documents and Settings\User\Cookies\user@vclick[1].txt C:\Documents and Settings\User\Cookies\user@crackserialkeygen[2].txt C:\Documents and Settings\User\Cookies\user@www.fullreleases[1].txt C:\Documents and Settings\User\Cookies\user@xiti[1].txt C:\Documents and Settings\User\Cookies\user@srv.warez[2].txt C:\Documents and Settings\User\Cookies\user@3.adbrite[1].txt C:\Documents and Settings\User\Cookies\user@ads.worthplaying[2].txt C:\Documents and Settings\User\Cookies\user@likecrack[2].txt C:\Documents and Settings\User\Cookies\user@secretxxxvideo[2].txt C:\Documents and Settings\User\Cookies\user@warez[2].txt C:\Documents and Settings\User\Cookies\user@list[1].txt C:\Documents and Settings\User\Cookies\user@clicksor[2].txt C:\Documents and Settings\User\Cookies\user@ads.adgoto[2].txt C:\Documents and Settings\User\Cookies\user@www.tns-counter[1].txt C:\Documents and Settings\User\Cookies\user@ads.techguy[2].txt C:\Documents and Settings\User\Cookies\user@warezfactor[1].txt C:\Documents and Settings\User\Cookies\user@www7.addfreestats[1].txt C:\Documents and Settings\User\Cookies\user@ads.adbrite[2].txt C:\Documents and Settings\User\Cookies\user@crackserial[1].txt C:\Documents and Settings\User\Cookies\user@www3.addfreestats[1].txt C:\Documents and Settings\User\Cookies\user@atwola[2].txt C:\Documents and Settings\User\Cookies\user@www.sonixwarez[1].txt C:\Documents and Settings\User\Cookies\user@burstnet[1].txt C:\Documents and Settings\User\Cookies\user@www.nakedonthestreets[2].txt C:\Documents and Settings\User\Cookies\user@www.adultmovienetwork[2].txt C:\Documents and Settings\User\Cookies\user@www.crackserver[1].txt C:\Documents and Settings\User\Cookies\user@crackserver[2].txt C:\Documents and Settings\User\Cookies\user@banner.32vegas[1].txt C:\Documents and Settings\User\Cookies\user@statsadv.dada[1].txt C:\Documents and Settings\User\Cookies\user@ads.marketingweek[2].txt C:\Documents and Settings\User\Cookies\user@www.likecrack[1].txt C:\Documents and Settings\User\Cookies\user@traffic.esearchnetwork[1].txt C:\Documents and Settings\User\Cookies\user@click.cashengines[2].txt C:\Documents and Settings\User\Cookies\user@eyewonder[1].txt C:\Documents and Settings\User\Cookies\user@wtcracks[1].txt C:\Documents and Settings\User\Cookies\user@www.halstats[2].txt C:\Documents and Settings\User\Cookies\user@toplist[1].txt C:\Documents and Settings\User\Cookies\user@fishadultgames[1].txt C:\Documents and Settings\User\Cookies\user@ads.zam[2].txt C:\Documents and Settings\User\Cookies\user@ad.zanox[1].txt C:\Documents and Settings\User\Cookies\user@usenext[2].txt C:\Documents and Settings\User\Cookies\user@ad.e-go[1].txt C:\Documents and Settings\User\Cookies\user@azjmp[1].txt C:\Documents and Settings\User\Cookies\user@clickaider[1].txt C:\Documents and Settings\User\Cookies\user@banners.adultfriendfinder[2].txt C:\Documents and Settings\User\Cookies\user@2.adbrite[1].txt C:\Documents and Settings\User\Cookies\user@server.cpmstar[1].txt C:\Documents and Settings\User\Cookies\user@clicktorrent[2].txt Adware.180solutions/Search Assistant C:\Program Files\MediaGateway HKLM\Software\Microsoft\Windows\CurrentVersion\Run#MediaGateway [ C:\Program Files\MediaGateway\MediaGateway.exe ] Trojan.Unclassifed/Loader-Suspicious C:\DOCUMENTS AND SETTINGS\USER\LOCAL SETTINGS\TEMP\LOADER.EXE Trojan.Vundo/Variant-Installer C:\QOOBOX\QUARANTINE\C\DOCUMENTS AND SETTINGS\USER\LOCAL SETTINGS\APPLICATION DATA\CFTMON.EXE.VIR C:\QOOBOX\QUARANTINE\C\WINDOWS\SYSTEM32\DRIVERS\SPOOL.EXE.VIR C:\QOOBOX\QUARANTINE\C\WINDOWS\SYSTEM32\VTUTU.EXE.VIR C:\SYSTEM VOLUME INFORMATION\_RESTORE{7A51E4F6-A36F-4E25-8376-8DD35E81AB33}\RP0\A0000020.EXE C:\SYSTEM VOLUME INFORMATION\_RESTORE{7A51E4F6-A36F-4E25-8376-8DD35E81AB33}\RP0\A0000023.EXE C:\SYSTEM VOLUME INFORMATION\_RESTORE{7A51E4F6-A36F-4E25-8376-8DD35E81AB33}\RP0\A0000040.EXE C:\SYSTEM VOLUME INFORMATION\_RESTORE{7A51E4F6-A36F-4E25-8376-8DD35E81AB33}\RP2\A0000215.EXE C:\SYSTEM VOLUME INFORMATION\_RESTORE{7A51E4F6-A36F-4E25-8376-8DD35E81AB33}\RP2\A0000264.EXE C:\SYSTEM VOLUME INFORMATION\_RESTORE{7A51E4F6-A36F-4E25-8376-8DD35E81AB33}\RP2\A0000281.EXE C:\SYSTEM VOLUME INFORMATION\_RESTORE{7A51E4F6-A36F-4E25-8376-8DD35E81AB33}\RP2\A0000289.EXE C:\SYSTEM VOLUME INFORMATION\_RESTORE{7A51E4F6-A36F-4E25-8376-8DD35E81AB33}\RP2\A0000304.EXE C:\SYSTEM VOLUME INFORMATION\_RESTORE{7A51E4F6-A36F-4E25-8376-8DD35E81AB33}\RP2\A0000306.EXE C:\SYSTEM VOLUME INFORMATION\_RESTORE{7A51E4F6-A36F-4E25-8376-8DD35E81AB33}\RP2\A0000354.EXE C:\SYSTEM VOLUME INFORMATION\_RESTORE{7A51E4F6-A36F-4E25-8376-8DD35E81AB33}\RP2\A0001754.EXE C:\SYSTEM VOLUME INFORMATION\_RESTORE{7A51E4F6-A36F-4E25-8376-8DD35E81AB33}\RP2\A0001763.EXE C:\SYSTEM VOLUME INFORMATION\_RESTORE{7A51E4F6-A36F-4E25-8376-8DD35E81AB33}\RP2\A0001778.EXE C:\SYSTEM VOLUME INFORMATION\_RESTORE{7A51E4F6-A36F-4E25-8376-8DD35E81AB33}\RP3\A0001934.EXE C:\SYSTEM VOLUME INFORMATION\_RESTORE{7A51E4F6-A36F-4E25-8376-8DD35E81AB33}\RP3\A0001939.EXE C:\SYSTEM VOLUME INFORMATION\_RESTORE{7A51E4F6-A36F-4E25-8376-8DD35E81AB33}\RP3\A0002007.EXE C:\SYSTEM VOLUME INFORMATION\_RESTORE{7A51E4F6-A36F-4E25-8376-8DD35E81AB33}\RP3\A0002009.EXE C:\SYSTEM VOLUME INFORMATION\_RESTORE{7A51E4F6-A36F-4E25-8376-8DD35E81AB33}\RP3\A0002024.EXE C:\SYSTEM VOLUME INFORMATION\_RESTORE{7A51E4F6-A36F-4E25-8376-8DD35E81AB33}\RP3\A0002211.EXE C:\SYSTEM VOLUME INFORMATION\_RESTORE{7A51E4F6-A36F-4E25-8376-8DD35E81AB33}\RP3\A0002221.EXE C:\SYSTEM VOLUME INFORMATION\_RESTORE{7A51E4F6-A36F-4E25-8376-8DD35E81AB33}\RP3\A0002238.EXE C:\SYSTEM VOLUME INFORMATION\_RESTORE{7A51E4F6-A36F-4E25-8376-8DD35E81AB33}\RP3\A0002280.EXE C:\SYSTEM VOLUME INFORMATION\_RESTORE{7A51E4F6-A36F-4E25-8376-8DD35E81AB33}\RP3\A0002309.EXE C:\SYSTEM VOLUME INFORMATION\_RESTORE{7A51E4F6-A36F-4E25-8376-8DD35E81AB33}\RP3\A0002348.EXE C:\SYSTEM VOLUME INFORMATION\_RESTORE{7A51E4F6-A36F-4E25-8376-8DD35E81AB33}\RP4\A0002535.EXE C:\SYSTEM VOLUME INFORMATION\_RESTORE{7A51E4F6-A36F-4E25-8376-8DD35E81AB33}\RP4\A0002536.EXE C:\SYSTEM VOLUME INFORMATION\_RESTORE{7A51E4F6-A36F-4E25-8376-8DD35E81AB33}\RP5\A0002540.EXE C:\SYSTEM VOLUME INFORMATION\_RESTORE{7A51E4F6-A36F-4E25-8376-8DD35E81AB33}\RP5\A0002541.EXE C:\SYSTEM VOLUME INFORMATION\_RESTORE{7A51E4F6-A36F-4E25-8376-8DD35E81AB33}\RP6\A0002543.EXE C:\SYSTEM VOLUME INFORMATION\_RESTORE{7A51E4F6-A36F-4E25-8376-8DD35E81AB33}\RP6\A0002555.EXE C:\SYSTEM VOLUME INFORMATION\_RESTORE{7A51E4F6-A36F-4E25-8376-8DD35E81AB33}\RP6\A0002587.EXE C:\SYSTEM VOLUME INFORMATION\_RESTORE{7A51E4F6-A36F-4E25-8376-8DD35E81AB33}\RP7\A0003306.EXE C:\SYSTEM VOLUME INFORMATION\_RESTORE{7A51E4F6-A36F-4E25-8376-8DD35E81AB33}\RP7\A0005290.EXE C:\SYSTEM VOLUME INFORMATION\_RESTORE{7A51E4F6-A36F-4E25-8376-8DD35E81AB33}\RP7\A0005310.EXE Trojan.Downloader-Gen/DDC C:\QOOBOX\QUARANTINE\C\WINDOWS\SYSTEM32\FJQTDXTV.EXE.VIR C:\SYSTEM VOLUME INFORMATION\_RESTORE{7A51E4F6-A36F-4E25-8376-8DD35E81AB33}\RP7\A0005478.EXE Trojan.Unclassifed/AffiliateBundle C:\SYSTEM VOLUME INFORMATION\_RESTORE{7A51E4F6-A36F-4E25-8376-8DD35E81AB33}\RP6\A0002598.DLL Adware.Vundo-Variant C:\SYSTEM VOLUME INFORMATION\_RESTORE{7A51E4F6-A36F-4E25-8376-8DD35E81AB33}\RP6\A0002599.DLL C:\SYSTEM VOLUME INFORMATION\_RESTORE{7A51E4F6-A36F-4E25-8376-8DD35E81AB33}\RP7\A0005489.DLL Adware.Vundo-Variant/Small-A C:\SYSTEM VOLUME INFORMATION\_RESTORE{7A51E4F6-A36F-4E25-8376-8DD35E81AB33}\RP7\A0005479.DLL and here is the hijackthis scan info Logfile of Trend Micro HijackThis v2.0.2 Scan saved at 00:17, on 2008-01-26 Platform: Windows XP SP2 (WinNT 5.01.2600) MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180) Boot mode: Normal Running processes: C:\WINDOWS\System32\smss.exe C:\WINDOWS\system32\winlogon.exe C:\WINDOWS\system32\services.exe C:\WINDOWS\system32\lsass.exe C:\WINDOWS\system32\svchost.exe C:\WINDOWS\System32\svchost.exe C:\Program Files\Ahead\InCD\InCDsrv.exe C:\Program Files\Symantec\LiveUpdate\ALUSchedulerSvc.exe C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe C:\WINDOWS\System32\svchost.exe C:\Program Files\Common Files\Microsoft Shared\VS7Debug\mdm.exe C:\WINDOWS\system32\nvsvc32.exe C:\WINDOWS\system32\svchost.exe C:\Program Files\Common Files\Symantec Shared\AppCore\AppSvc32.exe C:\WINDOWS\system32\WFXSVC.EXE C:\Program Files\Symantec\WinFax\WFXMOD32.EXE C:\WINDOWS\System32\svchost.exe C:\WINDOWS\System32\svchost.exe C:\WINDOWS\system32\wscntfy.exe C:\WINDOWS\Explorer.EXE C:\WINDOWS\system32\wfxsnt40.exe C:\WINDOWS\system32\rundll32.exe C:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe C:\WINDOWS\system32\notepad.exe C:\Program Files\Internet Explorer\IEXPLORE.EXE C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLLoginProxy.exe C:\Program Files\Trend Micro\HijackThis\HijackThis.exe C:\Program Files\Windows Live Toolbar\msn_sl.exe R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.altecnet.gr/ R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = localhost R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Συνδέσεις O2 - BHO: DAPHelper Class - {0000CC75-ACF3-4cac-A0A9-DD3868E06852} - C:\Program Files\DAP\dapbho.dll O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 5.0\Acrobat\ActiveX\AcroIEHelper.ocx O2 - BHO: (no name) - {1E8A6170-7264-4D0F-BEAE-D42A53123C75} - C:\Program Files\Common Files\Symantec Shared\coShared\Browser\1.0\NppBho.dll O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_02\bin\ssv.dll O2 - BHO: Windows Live Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll O2 - BHO: Windows Live Toolbar Helper - {BDBD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\Program Files\Windows Live Toolbar\msntb.dll O3 - Toolbar: Windows Live Toolbar - {BDAD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\Program Files\Windows Live Toolbar\msntb.dll O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup O4 - HKLM\..\Run: [type32] "C:\Program Files\Microsoft IntelliType Pro\type32.exe" O4 - HKLM\..\Run: [IntelliPoint] "C:\Program Files\Microsoft IntelliPoint\point32.exe" O4 - HKLM\..\Run: [HPDJ Taskbar Utility] C:\WINDOWS\system32\spool\drivers\w32x86\3\hpztsb04.exe O4 - HKLM\..\Run: [LVCOMSX] C:\WINDOWS\system32\LVCOMSX.EXE O4 - HKLM\..\Run: [InCD] C:\Program Files\Ahead\InCD\InCD.exe O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\WINDOWS\system32\NvMcTray.dll,NvTaskbarInit O4 - HKLM\..\Run: [osCheck] "C:\Program Files\Norton Internet Security\osCheck.exe" O4 - HKLM\..\Run: [ccApp] "C:\Program Files\Common Files\Symantec Shared\ccApp.exe" O4 - HKLM\..\Run: [Symantec PIF AlertEng] "C:\Program Files\Common Files\Symantec Shared\PIF\{B8E1DD85-8582-4c61-B58F-2F227FCA9A08}\PIFSvc.exe" /a /m "C:\Program Files\Common Files\Symantec Shared\PIF\{B8E1DD85-8582-4c61-B58F-2F227FCA9A08}\AlertEng.dll" O4 - HKLM\..\Run: [WorksFUD] C:\Program Files\Microsoft Works\wkfud.exe O4 - HKLM\..\Run: [WinFaxAppPortStarter] wfxsnt40.exe O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_02\bin\jusched.exe" O4 - HKLM\..\Run: [nwiz] nwiz.exe /install O4 - HKLM\..\Run: [NeroFilterCheck] C:\WINDOWS\system32\NeroCheck.exe O4 - HKLM\..\Run: [msnappau] "C:\Program Files\MSN Apps\Updater\01.02.3000.1001\el-gr\msnappau.exe" O4 - HKLM\..\Run: [Microsoft Works Update Detection] C:\Program Files\Microsoft Works\WkDetect.exe O4 - HKLM\..\Run: [Microsoft Works Portfolio] C:\Program Files\Microsoft Works\WksSb.exe /AllUsers O4 - HKLM\..\Run: [Default bits loud great] C:\Documents and Settings\All Users\Application Data\settings phone default bits\fast 16.exe O4 - HKLM\..\Run: [DataLayer] C:\Program Files\Common Files\PCSuite\DataLayer\DataLayer.exe O4 - HKLM\..\Run: [SoundMan] SOUNDMAN.EXE O4 - HKLM\..\Run: [MSConfig] C:\WINDOWS\PCHealth\HelpCtr\Binaries\MSConfig.exe /auto O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask .exe" -atboottime O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe O4 - HKCU\..\Run: [WMPNSCFG] C:\Program Files\Windows Media Player\WMPNSCFG.exe O4 - HKCU\..\Run: [SUPERAntiSpyware] C:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe O4 - HKUS\S-1-5-19\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'LOCAL SERVICE') O4 - HKUS\S-1-5-20\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'NETWORK SERVICE') O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SYSTEM') O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'Default user') O6 - HKCU\Software\Policies\Microsoft\Internet Explorer\Control Panel present O8 - Extra context menu item: &Clean Traces - C:\Program Files\DAP\Privacy Package\dapcleanerie.htm O8 - Extra context menu item: &Download with &DAP - C:\Program Files\DAP\dapextie.htm O8 - Extra context menu item: &Windows Live Search - res://C:\Program Files\Windows Live Toolbar\msntb.dll/search.htm O8 - Extra context menu item: Add to Windows &Live Favorites - http://favorites.live.com/quickadd.aspx O8 - Extra context menu item: Download &all with DAP - C:\Program Files\DAP\dapextie2.htm O8 - Extra context menu item: Ε&ξαγωγή στο Microsoft Excel - res://C:\PROGRA~1\MI1933~1\Office10\EXCEL.EXE/3000 O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_02\bin\ssv.dll O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_02\bin\ssv.dll O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe (file missing) O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe (file missing) O12 - Plugin for .spop: C:\Program Files\Internet Explorer\Plugins\NPDocBox.dll O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) - http://go.microsoft.com/fwlink/?linkid=39204 O16 - DPF: {62789780-B744-11D0-986B-00609731A21D} (Autodesk MapGuide ActiveX Control) - http://maps.flash.gr/inc/activex/mgaxctrl.cab O16 - DPF: {DE625294-70E6-45ED-B895-CFFA13AEB044} (AxisMediaControlEmb Class) - http://62.1.195.34:8088/activex/AMC.cab O16 - DPF: {EB387D2F-E27B-4D36-979E-847D1036C65D} (QDiagHUpdateObj Class) - http://h30043.www3.hp.com/hpdj/en/check/qdiagh.cab?326 O17 - HKLM\System\CCS\Services\Tcpip\..\{8F7B04C5-0416-4966-9B3E-347BF616FCE0}: NameServer = 213.5.41.8,213.5.17.21 O17 - HKLM\System\CCS\Services\Tcpip\..\{AEED5469-1EF7-4328-B775-2B2AC9C32BC6}: NameServer = 213.5.41.8,213.5.17.21 O20 - Winlogon Notify: !SASWinLogon - C:\Program Files\SUPERAntiSpyware\SASWINLO.dll O23 - Service: Adobe LM Service - Adobe Systems - C:\Program Files\Common Files\Adobe Systems Shared\Service\Adobelmsvc.exe O23 - Service: Automatic LiveUpdate Scheduler - Symantec Corporation - C:\Program Files\Symantec\LiveUpdate\ALUSchedulerSvc.exe O23 - Service: Symantec Event Manager (ccEvtMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe O23 - Service: Symantec Settings Manager (ccSetMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe O23 - Service: Symantec Lic NetConnect service (CLTNetCnService) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe O23 - Service: COM Host (comHost) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\VAScanner\comHost.exe O23 - Service: InCD Helper (InCDsrv) - Nero AG - C:\Program Files\Ahead\InCD\InCDsrv.exe O23 - Service: InCD Helper (read only) (InCDsrvR) - Nero AG - C:\Program Files\Ahead\InCD\InCDsrv.exe O23 - Service: Symantec IS Password Validation (ISPwdSvc) - Symantec Corporation - C:\Program Files\Norton Internet Security\isPwdSvc.exe O23 - Service: LiveUpdate - Symantec Corporation - C:\PROGRA~1\Symantec\LIVEUP~1\LUCOMS~1.EXE O23 - Service: LiveUpdate Notice Service Ex (LiveUpdate Notice Ex) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe O23 - Service: LiveUpdate Notice Service - Unknown owner - C:\Program Files\Common Files\Symantec Shared\PIF\{B8E1DD85-8582-4c61-B58F-2F227FCA9A08}\PIFSvc.exe (file missing) O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe O23 - Service: PnkBstrA - Unknown owner - C:\WINDOWS\system32\PnkBstrA.exe (file missing) O23 - Service: ServiceLayer - Nokia. - C:\Program Files\Common Files\PCSuite\Services\ServiceLayer.exe O23 - Service: SolidWorks Licensing Service - SolidWorks - C:\Program Files\Common Files\SolidWorks Shared\Service\SolidWorksLicensing.exe O23 - Service: Symantec Core LC - Unknown owner - C:\Program Files\Common Files\Symantec Shared\CCPD-LC\symlcsvc.exe O23 - Service: Symantec AppCore Service (SymAppCore) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\AppCore\AppSvc32.exe O23 - Service: WinFax PRO (wfxsvc) - Symantec Corporation - C:\WINDOWS\system32\WFXSVC.EXE -- End of file - 10078 bytes the combo fix done really good work i first done a combo fix scan then i could access at IE and the crashes and errors were gone for a while ![]() |
|
25-Jan-2008, 07:20 PM
#11 |
| Personally, I think you should (if you can) reformat the drive and start all over. If your computer is infected with many different things over a long period of time, it can cause you major problems. It can mess up your registry and delete files that your computer needs to run properly and any number of things. I would recommend reformatting and reinstalling windows. Then, in the future, I would recommend using only Firefox for your browser and AVG Free Edition for your Anti-virus. If for some reason you need to open a page in IE, there is an extension for Firefox called IE Tab to open an IE page in a tab in Firefox. P.S. Have you ever heard of punctuation? ![]() Last edited by sihTdaeRtnaCuoY; 25-Jan-2008 at 07:21 PM.. Reason: PS Comment |
26-Jan-2008, 04:25 PM
#13 | |||||
| Reformatting is completely up to you. I would like you to rerun ComboFix and post the results. Depending on how much infection is remaining will determine the next course of action. |
|
26-Jan-2008, 04:52 PM
#14 | |
| Quote:
Opera browser + Avast antivirus would be a much better solution. Opera has a feature where you can mask a page as IE which basically loads the page in the Trident engine, almost completely eliminating the need to open Internet Explorer at all. |
|
27-Jan-2008, 04:50 AM
#15 |
| well iam not keen on the idea to reformat because the pc has a lot of files and programs about my uncles job so all will be lost. I tried to reinstall windows it succed to reinstall it but i recieved some weird errors after the install but the pc was fine no crashes i could access to IE etc. But after 1 day the pc was at the same situation as it was b4 the reinstall here is the combo fix results ill post it at more than 2 replies because there are to many characters ComboFix 08-01-23.2 - User 2008-01-27 10:03:13.3 - NTFSx86 Running from: C:\Documents and Settings\User\§**α€* ¨©ε\ComboFix.exe WARNING -THIS MACHINE DOES NOT HAVE THE RECOVERY CONSOLE INSTALLED !! . ((((((((((((((((((((((((((((((((((((((( Other Deletions ))))))))))))))))))))))))))))))))))))))))))))))))) . . ---- Previous Run ------- . C:\Documents and Settings\LocalService\Local Settings\Application Data\cftmon .exe C:\Documents and Settings\User\Local Settings\Application Data\cftmon .exe C:\Documents and Settings\User\Local Settings\Application Data\cftmon.exe C:\Documents and Settings\User\ β¨*α £¦¬\pos21F.tmp C:\Documents and Settings\User\ β¨*α £¦¬\pos220.tmp C:\Documents and Settings\User\ β¨*α £¦¬\pos221.tmp C:\Documents and Settings\User\ β¨*α £¦¬\pos222.tmp C:\Documents and Settings\User\ β¨*α £¦¬\pos223.tmp C:\Documents and Settings\User\ β¨*α £¦¬\pos224.tmp C:\Documents and Settings\User\ β¨*α £¦¬\pos225.tmp C:\Documents and Settings\User\ β¨*α £¦¬\pos226.tmp C:\Documents and Settings\User\ β¨*α £¦¬\pos227.tmp C:\Documents and Settings\User\ β¨*α £¦¬\pos228.tmp C:\Documents and Settings\User\ β¨*α £¦¬\pos229.tmp C:\Documents and Settings\User\ β¨*α £¦¬\pos22A.tmp C:\Documents and Settings\User\ β¨*α £¦¬\pos22B.tmp C:\Documents and Settings\User\ β¨*α £¦¬\pos22C.tmp C:\Documents and Settings\User\ β¨*α £¦¬\pos22D.tmp C:\Documents and Settings\User\ β¨*α £¦¬\pos22E.tmp C:\Documents and Settings\User\ β¨*α £¦¬\pos22F.tmp C:\Documents and Settings\User\ β¨*α £¦¬\pos230.tmp C:\Documents and Settings\User\ β¨*α £¦¬\pos231.tmp C:\Documents and Settings\User\ β¨*α £¦¬\pos232.tmp C:\Documents and Settings\User\ β¨*α £¦¬\pos233.tmp C:\Documents and Settings\User\ β¨*α £¦¬\pos234.tmp C:\Documents and Settings\User\ β¨*α £¦¬\pos235.tmp C:\Documents and Settings\User\ β¨*α £¦¬\pos236.tmp C:\Documents and Settings\User\ β¨*α £¦¬\pos237.tmp C:\Documents and Settings\User\ β¨*α £¦¬\pos238.tmp C:\Documents and Settings\User\ β¨*α £¦¬\pos239.tmp C:\Documents and Settings\User\ β¨*α £¦¬\pos23A.tmp C:\Documents and Settings\User\ β¨*α £¦¬\pos23B.tmp C:\Documents and Settings\User\ β¨*α £¦¬\pos23C.tmp C:\Documents and Settings\User\ β¨*α £¦¬\pos23D.tmp C:\Documents and Settings\User\ β¨*α £¦¬\pos23E.tmp C:\Documents and Settings\User\ β¨*α £¦¬\pos23F.tmp C:\Documents and Settings\User\ β¨*α £¦¬\pos240.tmp C:\Documents and Settings\User\ β¨*α £¦¬\pos241.tmp C:\Documents and Settings\User\ β¨*α £¦¬\pos242.tmp C:\Documents and Settings\User\ β¨*α £¦¬\pos243.tmp C:\Documents and Settings\User\ β¨*α £¦¬\pos244.tmp C:\Documents and Settings\User\ β¨*α £¦¬\pos245.tmp C:\Documents and Settings\User\ β¨*α £¦¬\pos246.tmp C:\Documents and Settings\User\ β¨*α £¦¬\pos247.tmp C:\Documents and Settings\User\ β¨*α £¦¬\pos248.tmp C:\Documents and Settings\User\ β¨*α £¦¬\pos249.tmp C:\Documents and Settings\User\ β¨*α £¦¬\pos24A.tmp C:\Documents and Settings\User\ β¨*α £¦¬\pos24B.tmp C:\Documents and Settings\User\ β¨*α £¦¬\pos24C.tmp C:\Documents and Settings\User\ β¨*α £¦¬\pos24D.tmp C:\Documents and Settings\User\ β¨*α £¦¬\pos24E.tmp C:\Documents and Settings\User\ β¨*α £¦¬\pos24F.tmp C:\Documents and Settings\User\ β¨*α £¦¬\pos250.tmp C:\Documents and Settings\User\ β¨*α £¦¬\pos251.tmp C:\Documents and Settings\User\ β¨*α £¦¬\pos252.tmp C:\Documents and Settings\User\ β¨*α £¦¬\pos253.tmp C:\Documents and Settings\User\ β¨*α £¦¬\pos254.tmp C:\Documents and Settings\User\ β¨*α £¦¬\pos255.tmp C:\Documents and Settings\User\ β¨*α £¦¬\pos256.tmp C:\Documents and Settings\User\ β¨*α £¦¬\pos257.tmp C:\Documents and Settings\User\ β¨*α £¦¬\pos258.tmp C:\Documents and Settings\User\ β¨*α £¦¬\pos259.tmp C:\Documents and Settings\User\ β¨*α £¦¬\pos25A.tmp C:\Documents and Settings\User\ β¨*α £¦¬\pos25B.tmp C:\Documents and Settings\User\ β¨*α £¦¬\pos25C.tmp C:\Documents and Settings\User\ β¨*α £¦¬\pos25D.tmp C:\Documents and Settings\User\ β¨*α £¦¬\pos25E.tmp C:\Documents and Settings\User\ β¨*α £¦¬\pos25F.tmp C:\Documents and Settings\User\ β¨*α £¦¬\pos260.tmp C:\Documents and Settings\User\ β¨*α £¦¬\pos261.tmp C:\Documents and Settings\User\ β¨*α £¦¬\pos262.tmp C:\Documents and Settings\User\ β¨*α £¦¬\pos263.tmp C:\Documents and Settings\User\ β¨*α £¦¬\pos264.tmp C:\Documents and Settings\User\ β¨*α £¦¬\pos265.tmp C:\Documents and Settings\User\ β¨*α £¦¬\pos266.tmp C:\Documents and Settings\User\ β¨*α £¦¬\pos267.tmp C:\Documents and Settings\User\ β¨*α £¦¬\pos268.tmp C:\Documents and Settings\User\ β¨*α £¦¬\pos269.tmp C:\Documents and Settings\User\ β¨*α £¦¬\pos26A.tmp C:\Documents and Settings\User\ β¨*α £¦¬\pos26B.tmp C:\Documents and Settings\User\ β¨*α £¦¬\pos26C.tmp C:\Documents and Settings\User\ β¨*α £¦¬\pos26D.tmp C:\Documents and Settings\User\ β¨*α £¦¬\pos26E.tmp C:\Documents and Settings\User\ β¨*α £¦¬\pos26F.tmp C:\Documents and Settings\User\ β¨*α £¦¬\pos270.tmp C:\Documents and Settings\User\ β¨*α £¦¬\pos271.tmp C:\Documents and Settings\User\ β¨*α £¦¬\pos272.tmp C:\Documents and Settings\User\ β¨*α £¦¬\pos273.tmp C:\Documents and Settings\User\ β¨*α £¦¬\pos274.tmp C:\Documents and Settings\User\ β¨*α £¦¬\pos275.tmp C:\Documents and Settings\User\ β¨*α £¦¬\pos276.tmp C:\Documents and Settings\User\ β¨*α £¦¬\pos277.tmp C:\Documents and Settings\User\ β¨*α £¦¬\pos278.tmp C:\Documents and Settings\User\ β¨*α £¦¬\pos279.tmp C:\Documents and Settings\User\ β¨*α £¦¬\pos27A.tmp C:\Documents and Settings\User\ β¨*α £¦¬\pos27B.tmp C:\Documents and Settings\User\ β¨*α £¦¬\pos27C.tmp C:\Documents and Settings\User\ β¨*α £¦¬\pos27D.tmp C:\Documents and Settings\User\ β¨*α £¦¬\pos27E.tmp C:\Documents and Settings\User\ β¨*α £¦¬\pos27F.tmp C:\Documents and Settings\User\ β¨*α £¦¬\pos280.tmp C:\Documents and Settings\User\ β¨*α £¦¬\pos281.tmp C:\Documents and Settings\User\ β¨*α £¦¬\pos282.tmp C:\Documents and Settings\User\ β¨*α £¦¬\pos283.tmp C:\Documents and Settings\User\ β¨*α £¦¬\pos284.tmp C:\Documents and Settings\User\ β¨*α £¦¬\pos285.tmp C:\Documents and Settings\User\ β¨*α £¦¬\pos286.tmp C:\Documents and Settings\User\ β¨*α £¦¬\pos287.tmp C:\Documents and Settings\User\ β¨*α £¦¬\pos288.tmp C:\Documents and Settings\User\ β¨*α £¦¬\pos289.tmp C:\Documents and Settings\User\ β¨*α £¦¬\pos28A.tmp C:\Documents and Settings\User\ β¨*α £¦¬\pos28B.tmp C:\Documents and Settings\User\ β¨*α £¦¬\pos28C.tmp C:\Documents and Settings\User\ β¨*α £¦¬\pos28D.tmp C:\Documents and Settings\User\ β¨*α £¦¬\pos28E.tmp C:\Documents and Settings\User\ β¨*α £¦¬\pos28F.tmp C:\Documents and Settings\User\ β¨*α £¦¬\pos290.tmp C:\Documents and Settings\User\ β¨*α £¦¬\pos291.tmp C:\Documents and Settings\User\ β¨*α £¦¬\pos292.tmp C:\Documents and Settings\User\ β¨*α £¦¬\pos293.tmp C:\Documents and Settings\User\ β¨*α £¦¬\pos294.tmp C:\Documents and Settings\User\ β¨*α £¦¬\pos295.tmp C:\Documents and Settings\User\ β¨*α £¦¬\pos296.tmp C:\Documents and Settings\User\ β¨*α £¦¬\pos297.tmp C:\Documents and Settings\User\ β¨*α £¦¬\pos298.tmp C:\Documents and Settings\User\ β¨*α £¦¬\pos299.tmp C:\Documents and Settings\User\ β¨*α £¦¬\pos29A.tmp C:\Documents and Settings\User\ β¨*α £¦¬\pos29B.tmp C:\Documents and Settings\User\ β¨*α £¦¬\pos29C.tmp C:\Documents and Settings\User\ β¨*α £¦¬\pos29D.tmp C:\Documents and Settings\User\ β¨*α £¦¬\pos29E.tmp C:\Documents and Settings\User\ β¨*α £¦¬\pos29F.tmp C:\Documents and Settings\User\ β¨*α £¦¬\pos2A0.tmp C:\Documents and Settings\User\ β¨*α £¦¬\pos2A1.tmp C:\Documents and Settings\User\ β¨*α £¦¬\pos2A2.tmp C:\Documents and Settings\User\ β¨*α £¦¬\pos2A3.tmp C:\Documents and Settings\User\ β¨*α £¦¬\pos2A4.tmp C:\Documents and Settings\User\ β¨*α £¦¬\pos2A5.tmp C:\Documents and Settings\User\ β¨*α £¦¬\pos2A6.tmp C:\Documents and Settings\User\ β¨*α £¦¬\pos2A7.tmp C:\Documents and Settings\User\ β¨*α £¦¬\pos2A8.tmp C:\Documents and Settings\User\ β¨*α £¦¬\pos2A9.tmp C:\Documents and Settings\User\ β¨*α £¦¬\pos2AA.tmp C:\Documents and Settings\User\ β¨*α £¦¬\pos2AB.tmp C:\Documents and Settings\User\ β¨*α £¦¬\pos2AC.tmp C:\Documents and Settings\User\ β¨*α £¦¬\pos2AD.tmp C:\Documents and Settings\User\ β¨*α £¦¬\pos2AE.tmp C:\Documents and Settings\User\ β¨*α £¦¬\pos2AF.tmp C:\Documents and Settings\User\ β¨*α £¦¬\pos2B0.tmp C:\Documents and Settings\User\ β¨*α £¦¬\pos2B1.tmp C:\Documents and Settings\User\ β¨*α £¦¬\pos2B2.tmp C:\Documents and Settings\User\ β¨*α £¦¬\pos2B3.tmp C:\Documents and Settings\User\ β¨*α £¦¬\pos2B4.tmp C:\Documents and Settings\User\ β¨*α £¦¬\pos2B5.tmp C:\Documents and Settings\User\ β¨*α £¦¬\pos2B6.tmp C:\Documents and Settings\User\ β¨*α £¦¬\pos2B7.tmp C:\Documents and Settings\User\ β¨*α £¦¬\pos2B8.tmp C:\Documents and Settings\User\ β¨*α £¦¬\pos2B9.tmp C:\Documents and Settings\User\ β¨*α £¦¬\pos2BA.tmp C:\Documents and Settings\User\ β¨*α £¦¬\pos2BB.tmp C:\Documents and Settings\User\ β¨*α £¦¬\pos2BC.tmp C:\Documents and Settings\User\ β¨*α £¦¬\pos2BD.tmp C:\Documents and Settings\User\ β¨*α £¦¬\pos2BE.tmp C:\Documents and Settings\User\ β¨*α £¦¬\pos2BF.tmp C:\Documents and Settings\User\ β¨*α £¦¬\pos2C0.tmp C:\Documents and Settings\User\ β¨*α £¦¬\pos2C1.tmp C:\Documents and Settings\User\ β¨*α £¦¬\pos2C2.tmp C:\Documents and Settings\User\ β¨*α £¦¬\pos2C3.tmp C:\Documents and Settings\User\ β¨*α £¦¬\pos2C4.tmp C:\Documents and Settings\User\ β¨*α £¦¬\pos2C5.tmp C:\Documents and Settings\User\ β¨*α £¦¬\pos2C6.tmp C:\Documents and Settings\User\ β¨*α £¦¬\pos2C7.tmp C:\Documents and Settings\User\ β¨*α £¦¬\pos2C8.tmp C:\Documents and Settings\User\ β¨*α £¦¬\pos2C9.tmp C:\Documents and Settings\User\ β¨*α £¦¬\pos2CA.tmp C:\Documents and Settings\User\ β¨*α £¦¬\pos2CB.tmp C:\Documents and Settings\User\ β¨*α £¦¬\pos2CC.tmp C:\Documents and Settings\User\ β¨*α £¦¬\pos2CD.tmp C:\Documents and Settings\User\ β¨*α £¦¬\pos2CE.tmp C:\Documents and Settings\User\ β¨*α £¦¬\pos2CF.tmp C:\Documents and Settings\User\ β¨*α £¦¬\pos2D0.tmp C:\Documents and Settings\User\ β¨*α £¦¬\pos2D1.tmp C:\Documents and Settings\User\ β¨*α £¦¬\pos2D2.tmp C:\Documents and Settings\User\ β¨*α £¦¬\pos2D3.tmp C:\Documents and Settings\User\ β¨*α £¦¬\pos2D4.tmp C:\Documents and Settings\User\ β¨*α £¦¬\pos2D5.tmp C:\Documents and Settings\User\ β¨*α £¦¬\pos2D6.tmp C:\Documents and Settings\User\ β¨*α £¦¬\pos2D7.tmp C:\Documents and Settings\User\ β¨*α £¦¬\pos2D8.tmp C:\Documents and Settings\User\ β¨*α £¦¬\pos2D9.tmp C:\Documents and Settings\User\ β¨*α £¦¬\pos2DA.tmp C:\Documents and Settings\User\ β¨*α £¦¬\pos2DB.tmp C:\Documents and Settings\User\ β¨*α £¦¬\pos2DC.tmp C:\Documents and Settings\User\ β¨*α £¦¬\pos2DD.tmp C:\Documents and Settings\User\ β¨*α £¦¬\pos2DE.tmp C:\Documents and Settings\User\ β¨*α £¦¬\pos2DF.tmp C:\Documents and Settings\User\ β¨*α £¦¬\pos2E0.tmp C:\Documents and Settings\User\ β¨*α £¦¬\pos2E1.tmp C:\Documents and Settings\User\ β¨*α £¦¬\pos2E2.tmp C:\Documents and Settings\User\ β¨*α £¦¬\pos2E3.tmp C:\Documents and Settings\User\ β¨*α £¦¬\pos2E4.tmp C:\Documents and Settings\User\ β¨*α £¦¬\pos2E5.tmp C:\Documents and Settings\User\ β¨*α £¦¬\pos2E6.tmp C:\Documents and Settings\User\ β¨*α £¦¬\pos2E7.tmp C:\Documents and Settings\User\ β¨*α £¦¬\pos2E8.tmp C:\Documents and Settings\User\ β¨*α £¦¬\pos2E9.tmp C:\Documents and Settings\User\ β¨*α £¦¬\pos2EA.tmp C:\Documents and Settings\User\ β¨*α £¦¬\pos2EB.tmp C:\Documents and Settings\User\ β¨*α £¦¬\pos2EC.tmp C:\Documents and Settings\User\ β¨*α £¦¬\pos2ED.tmp C:\Documents and Settings\User\ β¨*α £¦¬\pos2EE.tmp C:\Documents and Settings\User\ β¨*α £¦¬\pos2EF.tmp C:\Documents and Settings\User\ β¨*α £¦¬\pos2F0.tmp C:\Documents and Settings\User\ β¨*α £¦¬\pos2F1.tmp C:\Documents and Settings\User\ β¨*α £¦¬\pos2F2.tmp C:\Documents and Settings\User\ β¨*α £¦¬\pos2F3.tmp C:\Documents and Settings\User\ β¨*α £¦¬\pos2F4.tmp C:\Documents and Settings\User\ β¨*α £¦¬\pos2F5.tmp C:\Documents and Settings\User\ β¨*α £¦¬\pos2F6.tmp C:\Documents and Settings\User\ β¨*α £¦¬\pos2F7.tmp C:\Documents and Settings\User\ β¨*α £¦¬\pos2F8.tmp C:\Documents and Settings\User\ β¨*α £¦¬\pos2F9.tmp C:\Documents and Settings\User\ β¨*α £¦¬\pos2FA.tmp C:\Documents and Settings\User\ β¨*α £¦¬\pos2FB.tmp C:\Documents and Settings\User\ β¨*α £¦¬\pos2FC.tmp C:\Documents and Settings\User\ β¨*α £¦¬\pos2FD.tmp C:\Documents and Settings\User\ β¨*α £¦¬\pos2FE.tmp C:\Documents and Settings\User\ β¨*α £¦¬\pos2FF.tmp C:\Documents and Settings\User\ β¨*α £¦¬\pos300.tmp C:\Documents and Settings\User\ β¨*α £¦¬\pos301.tmp C:\Documents and Settings\User\ β¨*α £¦¬\pos302.tmp C:\Documents and Settings\User\ β¨*α £¦¬\pos303.tmp C:\Documents and Settings\User\ β¨*α £¦¬\pos304.tmp C:\Documents and Settings\User\ β¨*α £¦¬\pos305.tmp C:\Documents and Settings\User\ β¨*α £¦¬\pos306.tmp C:\Documents and Settings\User\ β¨*α £¦¬\pos307.tmp C:\Documents and Settings\User\ β¨*α £¦¬\pos308.tmp C:\Documents and Settings\User\ β¨*α £¦¬\pos309.tmp C:\Documents and Settings\User\ β¨*α £¦¬\pos30A.tmp C:\Documents and Settings\User\ β¨*α £¦¬\pos30B.tmp C:\Documents and Settings\User\ β¨*α £¦¬\pos30C.tmp C:\Documents and Settings\User\ β¨*α £¦¬\pos30D.tmp C:\Documents and Settings\User\ β¨*α £¦¬\pos30E.tmp C:\Documents and Settings\User\ β¨*α £¦¬\pos30F.tmp C:\Documents and Settings\User\ β¨*α £¦¬\pos310.tmp C:\Documents and Settings\User\ β¨*α £¦¬\pos311.tmp C:\Documents and Settings\User\ β¨*α £¦¬\pos312.tmp C:\Documents and Settings\User\ β¨*α £¦¬\pos313.tmp C:\Documents and Settings\User\ β¨*α £¦¬\pos314.tmp C:\Documents and Settings\User\ β¨*α £¦¬\pos315.tmp C:\Documents and Settings\User\ β¨*α £¦¬\pos316.tmp C:\Documents and Settings\User\ β¨*α £¦¬\pos317.tmp C:\Documents and Settings\User\ β¨*α £¦¬\pos318.tmp C:\Documents and Settings\User\ β¨*α £¦¬\pos319.tmp C:\Documents and Settings\User\ β¨*α £¦¬\pos31A.tmp C:\Documents and Settings\User\ β¨*α £¦¬\pos31B.tmp C:\Documents and Settings\User\ β¨*α £¦¬\pos31C.tmp C:\Documents and Settings\User\ β¨*α £¦¬\pos31D.tmp C:\Documents and Settings\User\ β¨*α £¦¬\pos31E.tmp C:\Documents and Settings\User\ β¨*α £¦¬\pos31F.tmp C:\Documents and Settings\User\ β¨*α £¦¬\pos320.tmp C:\Documents and Settings\User\ β¨*α £¦¬\pos321.tmp C:\Documents and Settings\User\ β¨*α £¦¬\pos322.tmp C:\Documents and Settings\User\ β¨*α £¦¬\pos323.tmp C:\Documents and Settings\User\ β¨*α £¦¬\pos324.tmp C:\Documents and Settings\User\ β¨*α £¦¬\pos325.tmp C:\Documents and Settings\User\ β¨*α £¦¬\pos326.tmp C:\Documents and Settings\User\ β¨*α £¦¬\pos327.tmp C:\Documents and Settings\User\ β¨*α £¦¬\pos328.tmp C:\Documents and Settings\User\ β¨*α £¦¬\pos329.tmp C:\Documents and Settings\User\ β¨*α £¦¬\pos32A.tmp C:\Documents and Settings\User\ β¨*α £¦¬\pos32B.tmp C:\Documents and Settings\User\ β¨*α £¦¬\pos32C.tmp C:\Documents and Settings\User\ β¨*α £¦¬\pos32D.tmp C:\Documents and Settings\User\ β¨*α £¦¬\pos32E.tmp C:\Documents and Settings\User\ β¨*α £¦¬\pos32F.tmp C:\Documents and Settings\User\ β¨*α £¦¬\pos330.tmp C:\Documents and Settings\User\ β¨*α £¦¬\pos331.tmp C:\Documents and Settings\User\ β¨*α £¦¬\pos332.tmp C:\Documents and Settings\User\ β¨*α £¦¬\pos333.tmp C:\Documents and Settings\User\ β¨*α £¦¬\pos334.tmp C:\Documents and Settings\User\ β¨*α £¦¬\pos335.tmp C:\Documents and Settings\User\ β¨*α £¦¬\pos336.tmp C:\Documents and Settings\User\ β¨*α £¦¬\pos337.tmp C:\Documents and Settings\User\ β¨*α £¦¬\pos338.tmp C:\Documents and Settings\User\ β¨*α £¦¬\pos339.tmp C:\Documents and Settings\User\ β¨*α £¦¬\pos33A.tmp C:\Documents and Settings\User\ β¨*α £¦¬\pos33B.tmp C:\Documents and Settings\User\ β¨*α £¦¬\pos33C.tmp C:\Documents and Settings\User\ β¨*α £¦¬\pos33D.tmp C:\Documents and Settings\User\ β¨*α £¦¬\pos33E.tmp C:\Documents and Settings\User\ β¨*α £¦¬\pos33F.tmp C:\Documents and Settings\User\ β¨*α £¦¬\pos340.tmp C:\Documents and Settings\User\ β¨*α £¦¬\pos341.tmp C:\Documents and Settings\User\ β¨*α £¦¬\pos342.tmp C:\Documents and Settings\User\ β¨*α £¦¬\pos343.tmp C:\Documents and Settings\User\ β¨*α £¦¬\pos344.tmp C:\Documents and Settings\User\ β¨*α £¦¬\pos345.tmp C:\Documents and Settings\User\ β¨*α £¦¬\pos346.tmp C:\Documents and Settings\User\ β¨*α £¦¬\pos347.tmp C:\Documents and Settings\User\ β¨*α £¦¬\pos348.tmp C:\Documents and Settings\User\ β¨*α £¦¬\pos349.tmp C:\Documents and Settings\User\ β¨*α £¦¬\pos34A.tmp C:\Documents and Settings\User\ β¨*α £¦¬\pos34B.tmp C:\Documents and Settings\User\ β¨*α £¦¬\pos34C.tmp C:\Documents and Settings\User\ β¨*α £¦¬\pos34D.tmp C:\Documents and Settings\User\ β¨*α £¦¬\pos34E.tmp C:\Documents and Settings\User\ β¨*α £¦¬\pos34F.tmp C:\Documents and Settings\User\ β¨*α £¦¬\pos350.tmp C:\Documents and Settings\User\ β¨*α £¦¬\pos351.tmp C:\Documents and Settings\User\ β¨*α £¦¬\pos352.tmp C:\Documents and Settings\User\ β¨*α £¦¬\pos353.tmp C:\Documents and Settings\User\ β¨*α £¦¬\pos354.tmp C:\Documents and Settings\User\ β¨*α £¦¬\pos355.tmp C:\Documents and Settings\User\ β¨*α £¦¬\pos356.tmp C:\Documents and Settings\User\ β¨*α £¦¬\pos357.tmp C:\Documents and Settings\User\ β¨*α £¦¬\pos358.tmp C:\Documents and Settings\User\ β¨*α £¦¬\pos359.tmp C:\Documents and Settings\User\ β¨*α £¦¬\pos35A.tmp C:\Documents and Settings\User\ β¨*α £¦¬\pos35B.tmp C:\Documents and Settings\User\ β¨*α £¦¬\pos35C.tmp C:\Documents and Settings\User\ β¨*α £¦¬\pos35D.tmp C:\Documents and Settings\User\ β¨*α £¦¬\pos35E.tmp C:\Documents and Settings\User\ β¨*α £¦¬\pos35F.tmp C:\Documents and Settings\User\ β¨*α £¦¬\pos360.tmp C:\Documents and Settings\User\ β¨*α £¦¬\pos361.tmp C:\Documents and Settings\User\ β¨*α £¦¬\pos362.tmp C:\Documents and Settings\User\ β¨*α £¦¬\pos363.tmp C:\Documents and Settings\User\ β¨*α £¦¬\pos364.tmp C:\Documents and Settings\User\ β¨*α £¦¬\pos365.tmp C:\Documents and Settings\User\ β¨*α £¦¬\pos366.tmp C:\Documents and Settings\User\ β¨*α £¦¬\pos367.tmp C:\Documents and Settings\User\ β¨*α £¦¬\pos368.tmp C:\Documents and Settings\User\ β¨*α £¦¬\pos369.tmp C:\Documents and Settings\User\ β¨*α £¦¬\pos36A.tmp C:\Documents and Settings\User\ β¨*α £¦¬\pos36B.tmp C:\Documents and Settings\User\ β¨*α £¦¬\pos36C.tmp C:\Documents and Settings\User\ β¨*α £¦¬\pos36D.tmp C:\Documents and Settings\User\ β¨*α £¦¬\pos36E.tmp C:\Documents and Settings\User\ β¨*α £¦¬\pos36F.tmp C:\Documents and Settings\User\ β¨*α £¦¬\pos370.tmp C:\Documents and Settings\User\ β¨*α £¦¬\pos371.tmp C:\Documents and Settings\User\ β¨*α £¦¬\pos372.tmp C:\Documents and Settings\User\ β¨*α £¦¬\pos373.tmp C:\Documents and Settings\User\ β¨*α £¦¬\pos374.tmp C:\Documents and Settings\User\ β¨*α £¦¬\pos375.tmp C:\Documents and Settings\User\ β¨*α £¦¬\pos376.tmp C:\Documents and Settings\User\ β¨*α £¦¬\pos377.tmp C:\Documents and Settings\User\ β¨*α £¦¬\pos378.tmp C:\Documents and Settings\User\ β¨*α £¦¬\pos379.tmp C:\Documents and Settings\User\ β¨*α £¦¬\pos37A.tmp C:\Documents and Settings\User\ β¨*α £¦¬\pos37B.tmp C:\Documents and Settings\User\ β¨*α £¦¬\pos37C.tmp C:\Documents and Settings\User\ β¨*α £¦¬\pos37D.tmp C:\Documents and Settings\User\ β¨*α £¦¬\pos37E.tmp C:\Documents and Settings\User\ β¨*α £¦¬\pos37F.tmp C:\Documents and Settings\User\ β¨*α £¦¬\pos380.tmp C:\Documents and Settings\User\ β¨*α £¦¬\pos381.tmp C:\Documents and Settings\User\ β¨*α £¦¬\pos382.tmp C:\Documents and Settings\User\ β¨*α £¦¬\pos383.tmp C:\Documents and Settings\User\ β¨*α £¦¬\pos384.tmp C:\Documents and Settings\User\ β¨*α £¦¬\pos385.tmp C:\Documents and Settings\User\ β¨*α £¦¬\pos386.tmp C:\Documents and Settings\User\ β¨*α £¦¬\pos387.tmp C:\Documents and Settings\User\ β¨*α £¦¬\pos388.tmp C:\Documents and Settings\User\ β¨*α £¦¬\pos389.tmp C:\Documents and Settings\User\ β¨*α £¦¬\pos38A.tmp C:\Documents and Settings\User\ β¨*α £¦¬\pos38B.tmp C:\Documents and Settings\User\ β¨*α £¦¬\pos38C.tmp C:\Documents and Settings\User\ β¨*α £¦¬\pos38D.tmp C:\Documents and Settings\User\ β¨*α £¦¬\pos38E.tmp C:\Documents and Settings\User\ β¨*α £¦¬\pos38F.tmp C:\Documents and Settings\User\ β¨*α £¦¬\pos390.tmp C:\Documents and Settings\User\ β¨*α £¦¬\pos391.tmp C:\Documents and Settings\User\ β¨*α £¦¬\pos392.tmp C:\Documents and Settings\User\ β¨*α £¦¬\pos393.tmp C:\Documents and Settings\User\ β¨*α £¦¬\pos394.tmp C:\Documents and Settings\User\ β¨*α £¦¬\pos395.tmp C:\Documents and Settings\User\ β¨*α £¦¬\pos396.tmp C:\Documents and Settings\User\ β¨*α £¦¬\pos397.tmp C:\Documents and Settings\User\ β¨*α £¦¬\pos398.tmp C:\Documents and Settings\User\ β¨*α £¦¬\pos399.tmp C:\Documents and Settings\User\ β¨*α £¦¬\pos39A.tmp C:\Documents and Settings\User\ β¨*α £¦¬\pos39B.tmp C:\Documents and Settings\User\ β¨*α £¦¬\pos39C.tmp C:\Documents and Settings\User\ β¨*α £¦¬\pos39D.tmp C:\Documents and Settings\User\ β¨*α £¦¬\pos39E.tmp C:\Documents and Settings\User\ β¨*α £¦¬\pos39F.tmp C:\Documents and Settings\User\ β¨*α £¦¬\pos3A0.tmp C:\Documents and Settings\User\ β¨*α £¦¬\pos3A1.tmp C:\Documents and Settings\User\ β¨*α £¦¬\pos3A2.tmp C:\Documents and Settings\User\ β¨*α £¦¬\pos3A3.tmp C:\Documents and Settings\User\ β¨*α £¦¬\pos3A4.tmp C:\Documents and Settings\User\ β¨*α £¦¬\pos3A5.tmp C:\Documents and Settings\User\ β¨*α £¦¬\pos3A6.tmp C:\Documents and Settings\User\ β¨*α £¦¬\pos3A7.tmp C:\Documents and Settings\User\ β¨*α £¦¬\pos3A8.tmp C:\Documents and Settings\User\ β¨*α £¦¬\pos3A9.tmp C:\Documents and Settings\User\ β¨*α £¦¬\pos3AA.tmp C:\Documents and Settings\User\ β¨*α £¦¬\pos3AB.tmp C:\Documents and Settings\User\ β¨*α £¦¬\pos3AC.tmp C:\Documents and Settings\User\ β¨*α £¦¬\pos3AD.tmp C:\Documents and Settings\User\ β¨*α £¦¬\pos3AE.tmp C:\Documents and Settings\User\ β¨*α £¦¬\pos3AF.tmp C:\Documents and Settings\User\ β¨*α £¦¬\pos3B0.tmp C:\Documents and Settings\User\ β¨*α £¦¬\pos3B1.tmp C:\Documents and Settings\User\ β¨*α £¦¬\pos3B2.tmp C:\Documents and Settings\User\ β¨*α £¦¬\pos3B3.tmp C:\Documents and Settings\User\ β¨*α £¦¬\pos3B4.tmp C:\Documents and Settings\User\ β¨*α £¦¬\pos3B5.tmp C:\Documents and Settings\User\ β¨*α £¦¬\pos3B6.tmp C:\Documents and Settings\User\ β¨*α £¦¬\pos3B7.tmp C:\Documents and Settings\User\ β¨*α £¦¬\pos3B8.tmp C:\Documents and Settings\User\ β¨*α £¦¬\pos3B9.tmp C:\Documents and Settings\User\ β¨*α £¦¬\pos3BA.tmp C:\Documents and Settings\User\ β¨*α £¦¬\pos3BB.tmp C:\Documents and Settings\User\ β¨*α £¦¬\pos3BC.tmp C:\Documents and Settings\User\ β¨*α £¦¬\pos3BD.tmp C:\Documents and Settings\User\ β¨*α £¦¬\pos3BE.tmp C:\Documents and Settings\User\ β¨*α £¦¬\pos3BF.tmp C:\Documents and Settings\User\ β¨*α £¦¬\pos3C0.tmp C:\Documents and Settings\User\ β¨*α £¦¬\pos3C1.tmp C:\Documents and Settings\User\ β¨*α £¦¬\pos3C2.tmp C:\Documents and Settings\User\ β¨*α £¦¬\pos3C3.tmp C:\Documents and Settings\User\ β¨*α £¦¬\pos3C4.tmp C:\Documents and Settings\User\ β¨*α £¦¬\pos3C5.tmp |

|
| Currently Active Users Viewing This Thread: 1 (0 members and 1 guests) | |

| Thread Tools | |
| |
| You Are Using: |
Advertisements do not imply our endorsement of that product or service. All times are GMT -4. The time now is 01:16 PM. Copyright © 1996 - 2011 TechGuy, Inc. All rights reserved. | |

