View Full Version : Possible Vundo infection
Im pretty sure Ive got the Vundo virus going around after reading up on some problems other people have had but I honestly have no idea. My system sometimes freezes and my computer needs to be restarted to get it back and my taskbar sometimes dissapears sometimes aswell. So far Ive tried Combofix, Kaspersky, Pandascan, AVG Free, and Vundofix to remove it and none have worked.
Any help getting rid of this thing would be awesome.
HJT Log:
Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 6:12:00 PM, on 18/01/2008
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.5730.0013)
Boot mode: Normal
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
c:\program files\common files\logishrd\lvmvfm\LVPrcSrv.exe
C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
C:\PROGRA~1\Grisoft\AVG7\avgamsvr.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\PROGRA~1\Grisoft\AVG7\avgupsvc.exe
C:\PROGRA~1\Grisoft\AVG7\avgemc.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Bonjour\mDNSResponder.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Ventrilo\Ventrilo.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\wuauclt.exe
C:\WINDOWS\SOUNDMAN.EXE
C:\WINDOWS\ALCWZRD.EXE
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe
C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe
C:\WINDOWS\LMI1C.tmp\lmi_rescue.exe
C:\Program Files\Opera\Opera.exe
C:\Program Files\MSN Messenger\msnmsgr.exe
C:\Program Files\MSN Messenger\usnsvc.exe
C:\Program Files\Skype\Phone\Skype.exe
C:\Program Files\iPod\bin\iPodService.exe
C:\Program Files\iTunes\iTunesHelper.exe
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://ie.redirect.hp.com/svs/rdr?TYPE=3&tp=iesearch&locale=EN_AU&c=Q404&bd=pavilion&pf=desktop
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar = http://ie.redirect.hp.com/svs/rdr?TYPE=3&tp=iesearch&locale=EN_AU&c=Q404&bd=pavilion&pf=desktop
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = *.local
F3 - REG:win.ini: load=C:\WINDOWS\system32\vtuts.exe
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 6.0\Reader\ActiveX\AcroIEHelper.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll
O2 - BHO: (no name) - {CBFA0E8E-7489-4A16-8D6E-0D58BFFB6134} - C:\WINDOWS\system32\nnnomnm.dll (file missing)
O3 - Toolbar: HP view - {B2847E28-5D7D-4DEB-8B67-05D28BCF79F5} - c:\Program Files\HP\Digital Imaging\bin\HPDTLK02.dll
O4 - HKLM\..\Run: [IMJPMIG8.1] "C:\WINDOWS\IME\imjp8_1\IMJPMIG.EXE" /Spoil /RemAdvDef /Migration32
O4 - HKLM\..\Run: [MSPY2002] C:\WINDOWS\system32\IME\PINTLGNT\ImScInst.exe /SYNC
O4 - HKLM\..\Run: [PHIME2002ASync] C:\WINDOWS\system32\IME\TINTLGNT\TINTSETP.EXE /SYNC
O4 - HKLM\..\Run: [PHIME2002A] C:\WINDOWS\system32\IME\TINTLGNT\TINTSETP.EXE /IMEName
O4 - HKLM\..\Run: [AlcxMonitor] ALCXMNTR.EXE
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
O4 - HKLM\..\Run: [SoundMan] SOUNDMAN.EXE
O4 - HKLM\..\Run: [ATIPTA] C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe
O4 - HKLM\..\Run: [AlcWzrd] ALCWZRD.EXE
O4 - HKLM\..\Run: [AVG7_CC] C:\PROGRA~1\Grisoft\AVG7\avgcc.exe /STARTUP
O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
O4 - HKCU\..\Run: [SUPERAntiSpyware] C:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe
O4 - HKUS\S-1-5-19\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-19\..\Run: [AVG7_Run] C:\PROGRA~1\Grisoft\AVG7\avgw.exe /RUNONCE (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-20\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'NETWORK SERVICE')
O4 - HKUS\S-1-5-18\..\Run: [AVG7_Run] C:\PROGRA~1\Grisoft\AVG7\avgw.exe /RUNONCE (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [AVG7_Run] C:\PROGRA~1\Grisoft\AVG7\avgw.exe /RUNONCE (User 'Default user')
O4 - Startup: Xfire.lnk = C:\Program Files\Xfire\xfire.exe
O4 - Global Startup: HP Digital Imaging Monitor.lnk = C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe
O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office10\OSA.EXE
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MI1933~1\Office10\EXCEL.EXE/3000
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe (file missing)
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe (file missing)
O16 - DPF: {0EB0E74A-2A76-4AB3-A7FB-9BD8C29F7F75} (CKAVWebScan Object) - http://www.kaspersky.com/kos/english/kavwebscan_unicode.cab
O16 - DPF: {56762DEC-6B0D-4AB4-A8AD-989993B5D08B} (OnlineScanner Control) - http://www.eset.eu/buxus/docs/OnlineScanner.cab
O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~1\COMMON~1\Skype\SKYPE4~1.DLL
O20 - Winlogon Notify: !SASWinLogon - C:\Program Files\SUPERAntiSpyware\SASWINLO.dll
O23 - Service: Adobe LM Service - Adobe Systems - C:\Program Files\Common Files\Adobe Systems Shared\Service\Adobelmsvc.exe
O23 - Service: Apple Mobile Device - Apple, Inc. - C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
O23 - Service: Ati HotKey Poller - Unknown owner - C:\WINDOWS\system32\Ati2evxx.exe
O23 - Service: AVG7 Alert Manager Server (Avg7Alrt) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVG7\avgamsvr.exe
O23 - Service: AVG7 Update Service (Avg7UpdSvc) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVG7\avgupsvc.exe
O23 - Service: AVG E-mail Scanner (AVGEMS) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVG7\avgemc.exe
O23 - Service: ##Id_String1.6844F930_1628_4223_B5CC_5BB94B879762## (Bonjour Service) - Apple Computer, Inc. - C:\Program Files\Bonjour\mDNSResponder.exe
O23 - Service: FLEXnet Licensing Service - Macrovision Europe Ltd. - C:\Program Files\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe
O23 - Service: iPod Service - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: Process Monitor (LVPrcSrv) - Logitech Inc. - c:\program files\common files\logishrd\lvmvfm\LVPrcSrv.exe
O23 - Service: LVSrvLauncher - Logitech Inc. - C:\Program Files\Common Files\LogiShrd\SrvLnch\SrvLnch.exe
--
End of file - 7054 bytes
I can post the Kaspersky log if needed.
Hello
Welcome to Safer Networking.
Please read Before YouPost (http://forums.spybot.info/showthread.php?t=288)
That said, All advice given by anyone volunteering here, is taken at own risk.
While best efforts are made to assist in removing infections safely, unexpected stuff can happen.
It appears that you may be infected with the Vundo Trojan, lets do this....
Open HijackThis > Do a System Scan Only, close your browser and all open windows including this one, the only program or window you should have open is HijackThis, check the following entries and click on Fix Checked.
F3 - REG:win.ini: load=C:\WINDOWS\system32\vtuts.exe
O2 - BHO: (no name) - {CBFA0E8E-7489-4A16-8D6E-0D58BFFB6134} - C:\WINDOWS\system32\nnnomnm.dll (file missing)
O4 - HKLM\..\Run: [AlcxMonitor] ALCXMNTR.EXE
Download VundoFix (http://www.atribune.org/ccount/click.php?id=4 ) to your desktop
Double-click VundoFix.exe to run it.
Click the Scan for Vundo button.
Once it's done scanning, click the Remove Vundo button.
You will receive a prompt asking if you want to remove the files, click YES
Once you click yes, your desktop will go blank as it starts removing Vundo.
When completed, it will prompt that it will reboot your computer, click OK.
Please post the contents of C:\vundofix.txt and a new HiJackThis log in a reply to this thread.
Note: It is possible that VundoFix encountered a file it could not remove. In this case, VundoFix will run on reboot, simply follow the above instructions starting from "Click the Scan for Vundo button" when VundoFix appears upon rebooting.
Download ComboFix from Here (http://www.techsupportforum.com/sectools/sUBs/ComboFix.exe) or Here (http://download.bleepingcomputer.com/sUBs/ComboFix.exe) to your Desktop.
Double click combofix.exe and follow the prompts.
When finished, it shall produce a log for you. Post the Combofix log and a HiJackthis log in your next reply
Note: Do not mouseclick combofix's window while its running. That may cause it to stall
Post the Vundofix log, the Combofix log and a New HJT log please
There were no files found to delete when I ran Vundofix so I dont have a log file for that.
HJT:
Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 12:59:01 PM, on 20/01/2008
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.5730.0013)
Boot mode: Normal
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
c:\program files\common files\logishrd\lvmvfm\LVPrcSrv.exe
C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
C:\PROGRA~1\Grisoft\AVG7\avgamsvr.exe
C:\PROGRA~1\Grisoft\AVG7\avgupsvc.exe
C:\PROGRA~1\Grisoft\AVG7\avgemc.exe
C:\Program Files\Bonjour\mDNSResponder.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\SOUNDMAN.EXE
C:\WINDOWS\ALCWZRD.EXE
C:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe
C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Xfire\xfire.exe
C:\WINDOWS\system32\ctfmon.exe
C:\WINDOWS\system32\wuauclt.exe
C:\WINDOWS\system32\wuauclt.exe
C:\WINDOWS\system32\notepad.exe
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://ie.redirect.hp.com/svs/rdr?TYPE=3&tp=iesearch&locale=EN_AU&c=Q404&bd=pavilion&pf=desktop
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar = http://ie.redirect.hp.com/svs/rdr?TYPE=3&tp=iesearch&locale=EN_AU&c=Q404&bd=pavilion&pf=desktop
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = *.local
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 6.0\Reader\ActiveX\AcroIEHelper.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll
O3 - Toolbar: HP view - {B2847E28-5D7D-4DEB-8B67-05D28BCF79F5} - c:\Program Files\HP\Digital Imaging\bin\HPDTLK02.dll
O4 - HKLM\..\Run: [IMJPMIG8.1] "C:\WINDOWS\IME\imjp8_1\IMJPMIG.EXE" /Spoil /RemAdvDef /Migration32
O4 - HKLM\..\Run: [MSPY2002] C:\WINDOWS\system32\IME\PINTLGNT\ImScInst.exe /SYNC
O4 - HKLM\..\Run: [PHIME2002ASync] C:\WINDOWS\system32\IME\TINTLGNT\TINTSETP.EXE /SYNC
O4 - HKLM\..\Run: [PHIME2002A] C:\WINDOWS\system32\IME\TINTLGNT\TINTSETP.EXE /IMEName
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
O4 - HKLM\..\Run: [SoundMan] SOUNDMAN.EXE
O4 - HKLM\..\Run: [ATIPTA] C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe
O4 - HKLM\..\Run: [AlcWzrd] ALCWZRD.EXE
O4 - HKLM\..\Run: [AVG7_CC] C:\PROGRA~1\Grisoft\AVG7\avgcc.exe /STARTUP
O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
O4 - HKCU\..\Run: [SUPERAntiSpyware] C:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKUS\S-1-5-19\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-19\..\Run: [AVG7_Run] C:\PROGRA~1\Grisoft\AVG7\avgw.exe /RUNONCE (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-20\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'NETWORK SERVICE')
O4 - HKUS\S-1-5-18\..\Run: [AVG7_Run] C:\PROGRA~1\Grisoft\AVG7\avgw.exe /RUNONCE (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [AVG7_Run] C:\PROGRA~1\Grisoft\AVG7\avgw.exe /RUNONCE (User 'Default user')
O4 - Startup: Xfire.lnk = C:\Program Files\Xfire\xfire.exe
O4 - Global Startup: HP Digital Imaging Monitor.lnk = C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe
O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office10\OSA.EXE
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MI1933~1\Office10\EXCEL.EXE/3000
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe (file missing)
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe (file missing)
O16 - DPF: {0EB0E74A-2A76-4AB3-A7FB-9BD8C29F7F75} (CKAVWebScan Object) - http://www.kaspersky.com/kos/english/kavwebscan_unicode.cab
O16 - DPF: {56762DEC-6B0D-4AB4-A8AD-989993B5D08B} (OnlineScanner Control) - http://www.eset.eu/buxus/docs/OnlineScanner.cab
O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~1\COMMON~1\Skype\SKYPE4~1.DLL
O20 - Winlogon Notify: !SASWinLogon - C:\Program Files\SUPERAntiSpyware\SASWINLO.dll
O23 - Service: Adobe LM Service - Adobe Systems - C:\Program Files\Common Files\Adobe Systems Shared\Service\Adobelmsvc.exe
O23 - Service: Apple Mobile Device - Apple, Inc. - C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
O23 - Service: Ati HotKey Poller - Unknown owner - C:\WINDOWS\system32\Ati2evxx.exe
O23 - Service: AVG7 Alert Manager Server (Avg7Alrt) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVG7\avgamsvr.exe
O23 - Service: AVG7 Update Service (Avg7UpdSvc) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVG7\avgupsvc.exe
O23 - Service: AVG E-mail Scanner (AVGEMS) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVG7\avgemc.exe
O23 - Service: ##Id_String1.6844F930_1628_4223_B5CC_5BB94B879762## (Bonjour Service) - Apple Computer, Inc. - C:\Program Files\Bonjour\mDNSResponder.exe
O23 - Service: FLEXnet Licensing Service - Macrovision Europe Ltd. - C:\Program Files\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe
O23 - Service: iPod Service - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: Process Monitor (LVPrcSrv) - Logitech Inc. - c:\program files\common files\logishrd\lvmvfm\LVPrcSrv.exe
O23 - Service: LVSrvLauncher - Logitech Inc. - C:\Program Files\Common Files\LogiShrd\SrvLnch\SrvLnch.exe
--
End of file - 6684 bytes
The Combofix log is about 3 posts long, do you want all of it?
Yep, take as many posts as you need
ComboFix 08-01-20.1 - HP_Owner 2008-01-20 12:33:00.2 - NTFSx86
Microsoft Windows XP Home Edition 5.1.2600.2.1252.1.1033.18.1926 [GMT 10:00]
Running from: C:\Documents and Settings\HP_Owner\Desktop\ComboFix.exe
* Created a new restore point
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
C:\Documents and Settings\All Users\Application Data\storageprotector
C:\Documents and Settings\All Users\Application Data\storageprotector\Data\em
C:\Documents and Settings\All Users\Application Data\storageprotector\Data\oid
C:\Documents and Settings\All Users\Application Data\storageprotector\Data\user
C:\Documents and Settings\HP_Owner\My Documents\pos1000.tmp
C:\Documents and Settings\HP_Owner\My Documents\pos1001.tmp
C:\Documents and Settings\HP_Owner\My Documents\pos1002.tmp
C:\Documents and Settings\HP_Owner\My Documents\pos1003.tmp
C:\Documents and Settings\HP_Owner\My Documents\pos1004.tmp
C:\Documents and Settings\HP_Owner\My Documents\pos1005.tmp
C:\Documents and Settings\HP_Owner\My Documents\pos1006.tmp
C:\Documents and Settings\HP_Owner\My Documents\pos1007.tmp
C:\Documents and Settings\HP_Owner\My Documents\pos1008.tmp
C:\Documents and Settings\HP_Owner\My Documents\pos1009.tmp
C:\Documents and Settings\HP_Owner\My Documents\pos100A.tmp
C:\Documents and Settings\HP_Owner\My Documents\pos100B.tmp
C:\Documents and Settings\HP_Owner\My Documents\pos100C.tmp
C:\Documents and Settings\HP_Owner\My Documents\pos100D.tmp
C:\Documents and Settings\HP_Owner\My Documents\pos100E.tmp
C:\Documents and Settings\HP_Owner\My Documents\pos100F.tmp
C:\Documents and Settings\HP_Owner\My Documents\pos1010.tmp
C:\Documents and Settings\HP_Owner\My Documents\pos1011.tmp
C:\Documents and Settings\HP_Owner\My Documents\pos1012.tmp
C:\Documents and Settings\HP_Owner\My Documents\pos1013.tmp
C:\Documents and Settings\HP_Owner\My Documents\pos1014.tmp
C:\Documents and Settings\HP_Owner\My Documents\pos1015.tmp
C:\Documents and Settings\HP_Owner\My Documents\pos1016.tmp
C:\Documents and Settings\HP_Owner\My Documents\pos1017.tmp
C:\Documents and Settings\HP_Owner\My Documents\pos1018.tmp
C:\Documents and Settings\HP_Owner\My Documents\pos1019.tmp
C:\Documents and Settings\HP_Owner\My Documents\pos101A.tmp
C:\Documents and Settings\HP_Owner\My Documents\pos101B.tmp
C:\Documents and Settings\HP_Owner\My Documents\pos101C.tmp
C:\Documents and Settings\HP_Owner\My Documents\pos101D.tmp
C:\Documents and Settings\HP_Owner\My Documents\pos101E.tmp
C:\Documents and Settings\HP_Owner\My Documents\pos101F.tmp
C:\Documents and Settings\HP_Owner\My Documents\pos1020.tmp
C:\Documents and Settings\HP_Owner\My Documents\pos1021.tmp
C:\Documents and Settings\HP_Owner\My Documents\pos1022.tmp
C:\Documents and Settings\HP_Owner\My Documents\pos1023.tmp
C:\Documents and Settings\HP_Owner\My Documents\pos1024.tmp
C:\Documents and Settings\HP_Owner\My Documents\pos1025.tmp
C:\Documents and Settings\HP_Owner\My Documents\pos1026.tmp
C:\Documents and Settings\HP_Owner\My Documents\pos1027.tmp
C:\Documents and Settings\HP_Owner\My Documents\pos1028.tmp
C:\Documents and Settings\HP_Owner\My Documents\pos1029.tmp
C:\Documents and Settings\HP_Owner\My Documents\pos102A.tmp
C:\Documents and Settings\HP_Owner\My Documents\pos102B.tmp
C:\Documents and Settings\HP_Owner\My Documents\pos102C.tmp
C:\Documents and Settings\HP_Owner\My Documents\pos102D.tmp
C:\Documents and Settings\HP_Owner\My Documents\pos102E.tmp
C:\Documents and Settings\HP_Owner\My Documents\pos102F.tmp
C:\Documents and Settings\HP_Owner\My Documents\pos1030.tmp
C:\Documents and Settings\HP_Owner\My Documents\pos1031.tmp
C:\Documents and Settings\HP_Owner\My Documents\pos1032.tmp
C:\Documents and Settings\HP_Owner\My Documents\pos1033.tmp
C:\Documents and Settings\HP_Owner\My Documents\pos1034.tmp
C:\Documents and Settings\HP_Owner\My Documents\pos1035.tmp
C:\Documents and Settings\HP_Owner\My Documents\pos1036.tmp
C:\Documents and Settings\HP_Owner\My Documents\pos1037.tmp
C:\Documents and Settings\HP_Owner\My Documents\pos1038.tmp
C:\Documents and Settings\HP_Owner\My Documents\pos1039.tmp
C:\Documents and Settings\HP_Owner\My Documents\pos103A.tmp
C:\Documents and Settings\HP_Owner\My Documents\pos103B.tmp
C:\Documents and Settings\HP_Owner\My Documents\pos103C.tmp
C:\Documents and Settings\HP_Owner\My Documents\pos103D.tmp
C:\Documents and Settings\HP_Owner\My Documents\pos103E.tmp
C:\Documents and Settings\HP_Owner\My Documents\pos103F.tmp
C:\Documents and Settings\HP_Owner\My Documents\pos1040.tmp
C:\Documents and Settings\HP_Owner\My Documents\pos1041.tmp
C:\Documents and Settings\HP_Owner\My Documents\pos1042.tmp
C:\Documents and Settings\HP_Owner\My Documents\pos1043.tmp
C:\Documents and Settings\HP_Owner\My Documents\pos1044.tmp
C:\Documents and Settings\HP_Owner\My Documents\pos1045.tmp
C:\Documents and Settings\HP_Owner\My Documents\pos1046.tmp
C:\Documents and Settings\HP_Owner\My Documents\pos1047.tmp
C:\Documents and Settings\HP_Owner\My Documents\pos1048.tmp
C:\Documents and Settings\HP_Owner\My Documents\pos1049.tmp
C:\Documents and Settings\HP_Owner\My Documents\pos104A.tmp
C:\Documents and Settings\HP_Owner\My Documents\pos104B.tmp
C:\Documents and Settings\HP_Owner\My Documents\pos104C.tmp
C:\Documents and Settings\HP_Owner\My Documents\pos104D.tmp
C:\Documents and Settings\HP_Owner\My Documents\pos104E.tmp
C:\Documents and Settings\HP_Owner\My Documents\pos104F.tmp
C:\Documents and Settings\HP_Owner\My Documents\pos1050.tmp
C:\Documents and Settings\HP_Owner\My Documents\pos1051.tmp
C:\Documents and Settings\HP_Owner\My Documents\pos1052.tmp
C:\Documents and Settings\HP_Owner\My Documents\pos1053.tmp
C:\Documents and Settings\HP_Owner\My Documents\pos1054.tmp
C:\Documents and Settings\HP_Owner\My Documents\pos1055.tmp
C:\Documents and Settings\HP_Owner\My Documents\pos1056.tmp
C:\Documents and Settings\HP_Owner\My Documents\pos1057.tmp
C:\Documents and Settings\HP_Owner\My Documents\pos1058.tmp
C:\Documents and Settings\HP_Owner\My Documents\pos1059.tmp
C:\Documents and Settings\HP_Owner\My Documents\pos105A.tmp
C:\Documents and Settings\HP_Owner\My Documents\pos105B.tmp
C:\Documents and Settings\HP_Owner\My Documents\pos105C.tmp
C:\Documents and Settings\HP_Owner\My Documents\pos105D.tmp
C:\Documents and Settings\HP_Owner\My Documents\pos105E.tmp
C:\Documents and Settings\HP_Owner\My Documents\pos105F.tmp
C:\Documents and Settings\HP_Owner\My Documents\pos1060.tmp
C:\Documents and Settings\HP_Owner\My Documents\pos1061.tmp
C:\Documents and Settings\HP_Owner\My Documents\pos1062.tmp
C:\Documents and Settings\HP_Owner\My Documents\pos1063.tmp
C:\Documents and Settings\HP_Owner\My Documents\pos1064.tmp
C:\Documents and Settings\HP_Owner\My Documents\pos1065.tmp
C:\Documents and Settings\HP_Owner\My Documents\pos1066.tmp
C:\Documents and Settings\HP_Owner\My Documents\pos1067.tmp
C:\Documents and Settings\HP_Owner\My Documents\pos1068.tmp
C:\Documents and Settings\HP_Owner\My Documents\pos1069.tmp
C:\Documents and Settings\HP_Owner\My Documents\pos106A.tmp
C:\Documents and Settings\HP_Owner\My Documents\pos106B.tmp
C:\Documents and Settings\HP_Owner\My Documents\pos106C.tmp
C:\Documents and Settings\HP_Owner\My Documents\pos106D.tmp
C:\Documents and Settings\HP_Owner\My Documents\pos106E.tmp
C:\Documents and Settings\HP_Owner\My Documents\pos106F.tmp
C:\Documents and Settings\HP_Owner\My Documents\pos1070.tmp
C:\Documents and Settings\HP_Owner\My Documents\pos1071.tmp
C:\Documents and Settings\HP_Owner\My Documents\pos1072.tmp
C:\Documents and Settings\HP_Owner\My Documents\pos1073.tmp
C:\Documents and Settings\HP_Owner\My Documents\pos1074.tmp
C:\Documents and Settings\HP_Owner\My Documents\pos1075.tmp
C:\Documents and Settings\HP_Owner\My Documents\pos1076.tmp
C:\Documents and Settings\HP_Owner\My Documents\pos1077.tmp
C:\Documents and Settings\HP_Owner\My Documents\pos1078.tmp
C:\Documents and Settings\HP_Owner\My Documents\pos1079.tmp
C:\Documents and Settings\HP_Owner\My Documents\pos107A.tmp
C:\Documents and Settings\HP_Owner\My Documents\pos107B.tmp
C:\Documents and Settings\HP_Owner\My Documents\pos107C.tmp
C:\Documents and Settings\HP_Owner\My Documents\pos107D.tmp
C:\Documents and Settings\HP_Owner\My Documents\pos107E.tmp
C:\Documents and Settings\HP_Owner\My Documents\pos107F.tmp
C:\Documents and Settings\HP_Owner\My Documents\pos1080.tmp
C:\Documents and Settings\HP_Owner\My Documents\pos1081.tmp
C:\Documents and Settings\HP_Owner\My Documents\pos1082.tmp
C:\Documents and Settings\HP_Owner\My Documents\pos1083.tmp
C:\Documents and Settings\HP_Owner\My Documents\pos1084.tmp
C:\Documents and Settings\HP_Owner\My Documents\pos1085.tmp
C:\Documents and Settings\HP_Owner\My Documents\pos1086.tmp
C:\Documents and Settings\HP_Owner\My Documents\pos1087.tmp
C:\Documents and Settings\HP_Owner\My Documents\pos1088.tmp
C:\Documents and Settings\HP_Owner\My Documents\pos1089.tmp
C:\Documents and Settings\HP_Owner\My Documents\pos108A.tmp
C:\Documents and Settings\HP_Owner\My Documents\pos108B.tmp
C:\Documents and Settings\HP_Owner\My Documents\pos108C.tmp
C:\Documents and Settings\HP_Owner\My Documents\pos108D.tmp
C:\Documents and Settings\HP_Owner\My Documents\pos108E.tmp
C:\Documents and Settings\HP_Owner\My Documents\pos108F.tmp
C:\Documents and Settings\HP_Owner\My Documents\pos1090.tmp
C:\Documents and Settings\HP_Owner\My Documents\pos1091.tmp
C:\Documents and Settings\HP_Owner\My Documents\pos1092.tmp
C:\Documents and Settings\HP_Owner\My Documents\pos1093.tmp
C:\Documents and Settings\HP_Owner\My Documents\pos1094.tmp
C:\Documents and Settings\HP_Owner\My Documents\pos1095.tmp
C:\Documents and Settings\HP_Owner\My Documents\pos1096.tmp
C:\Documents and Settings\HP_Owner\My Documents\pos1097.tmp
C:\Documents and Settings\HP_Owner\My Documents\pos1098.tmp
C:\Documents and Settings\HP_Owner\My Documents\pos1099.tmp
C:\Documents and Settings\HP_Owner\My Documents\pos109A.tmp
C:\Documents and Settings\HP_Owner\My Documents\pos109B.tmp
C:\Documents and Settings\HP_Owner\My Documents\pos109C.tmp
C:\Documents and Settings\HP_Owner\My Documents\pos109D.tmp
C:\Documents and Settings\HP_Owner\My Documents\pos109E.tmp
C:\Documents and Settings\HP_Owner\My Documents\pos109F.tmp
C:\Documents and Settings\HP_Owner\My Documents\pos10A0.tmp
C:\Documents and Settings\HP_Owner\My Documents\pos10A1.tmp
C:\Documents and Settings\HP_Owner\My Documents\pos10A2.tmp
C:\Documents and Settings\HP_Owner\My Documents\pos10A3.tmp
C:\Documents and Settings\HP_Owner\My Documents\pos10A4.tmp
C:\Documents and Settings\HP_Owner\My Documents\pos10A5.tmp
C:\Documents and Settings\HP_Owner\My Documents\pos10A6.tmp
C:\Documents and Settings\HP_Owner\My Documents\pos10A7.tmp
C:\Documents and Settings\HP_Owner\My Documents\pos10A8.tmp
C:\Documents and Settings\HP_Owner\My Documents\pos10A9.tmp
C:\Documents and Settings\HP_Owner\My Documents\pos10AA.tmp
C:\Documents and Settings\HP_Owner\My Documents\pos10AB.tmp
C:\Documents and Settings\HP_Owner\My Documents\pos10AC.tmp
C:\Documents and Settings\HP_Owner\My Documents\pos10AD.tmp
C:\Documents and Settings\HP_Owner\My Documents\pos10AE.tmp
C:\Documents and Settings\HP_Owner\My Documents\pos10AF.tmp
C:\Documents and Settings\HP_Owner\My Documents\pos10B0.tmp
C:\Documents and Settings\HP_Owner\My Documents\pos10B1.tmp
C:\Documents and Settings\HP_Owner\My Documents\pos10B2.tmp
C:\Documents and Settings\HP_Owner\My Documents\pos10B3.tmp
C:\Documents and Settings\HP_Owner\My Documents\pos10B4.tmp
C:\Documents and Settings\HP_Owner\My Documents\pos10B5.tmp
C:\Documents and Settings\HP_Owner\My Documents\pos10B6.tmp
C:\Documents and Settings\HP_Owner\My Documents\pos10B7.tmp
C:\Documents and Settings\HP_Owner\My Documents\pos10B8.tmp
C:\Documents and Settings\HP_Owner\My Documents\pos10B9.tmp
C:\Documents and Settings\HP_Owner\My Documents\pos10BA.tmp
C:\Documents and Settings\HP_Owner\My Documents\pos10BB.tmp
C:\Documents and Settings\HP_Owner\My Documents\pos10BC.tmp
C:\Documents and Settings\HP_Owner\My Documents\pos10BD.tmp
C:\Documents and Settings\HP_Owner\My Documents\pos10BE.tmp
C:\Documents and Settings\HP_Owner\My Documents\pos10BF.tmp
C:\Documents and Settings\HP_Owner\My Documents\pos10C0.tmp
C:\Documents and Settings\HP_Owner\My Documents\pos10C1.tmp
C:\Documents and Settings\HP_Owner\My Documents\pos10C2.tmp
C:\Documents and Settings\HP_Owner\My Documents\pos10C3.tmp
C:\Documents and Settings\HP_Owner\My Documents\pos10C4.tmp
C:\Documents and Settings\HP_Owner\My Documents\pos10C5.tmp
C:\Documents and Settings\HP_Owner\My Documents\pos10C6.tmp
C:\Documents and Settings\HP_Owner\My Documents\pos10C7.tmp
C:\Documents and Settings\HP_Owner\My Documents\pos10C8.tmp
C:\Documents and Settings\HP_Owner\My Documents\pos10C9.tmp
C:\Documents and Settings\HP_Owner\My Documents\pos10CA.tmp
C:\Documents and Settings\HP_Owner\My Documents\pos10CB.tmp
C:\Documents and Settings\HP_Owner\My Documents\pos10CC.tmp
C:\Documents and Settings\HP_Owner\My Documents\pos10CD.tmp
C:\Documents and Settings\HP_Owner\My Documents\pos10CE.tmp
C:\Documents and Settings\HP_Owner\My Documents\pos10CF.tmp
C:\Documents and Settings\HP_Owner\My Documents\pos10D0.tmp
C:\Documents and Settings\HP_Owner\My Documents\pos10D1.tmp
C:\Documents and Settings\HP_Owner\My Documents\pos10D2.tmp
C:\Documents and Settings\HP_Owner\My Documents\pos10D3.tmp
C:\Documents and Settings\HP_Owner\My Documents\pos10D4.tmp
C:\Documents and Settings\HP_Owner\My Documents\pos10D5.tmp
C:\Documents and Settings\HP_Owner\My Documents\pos10D6.tmp
C:\Documents and Settings\HP_Owner\My Documents\pos10D7.tmp
C:\Documents and Settings\HP_Owner\My Documents\pos10D8.tmp
C:\Documents and Settings\HP_Owner\My Documents\pos10D9.tmp
C:\Documents and Settings\HP_Owner\My Documents\pos10DA.tmp
C:\Documents and Settings\HP_Owner\My Documents\pos10DB.tmp
C:\Documents and Settings\HP_Owner\My Documents\pos10DC.tmp
C:\Documents and Settings\HP_Owner\My Documents\pos10DD.tmp
C:\Documents and Settings\HP_Owner\My Documents\pos10DE.tmp
C:\Documents and Settings\HP_Owner\My Documents\pos10DF.tmp
C:\Documents and Settings\HP_Owner\My Documents\pos10E0.tmp
C:\Documents and Settings\HP_Owner\My Documents\pos10E1.tmp
C:\Documents and Settings\HP_Owner\My Documents\pos10E2.tmp
C:\Documents and Settings\HP_Owner\My Documents\pos10E3.tmp
C:\Documents and Settings\HP_Owner\My Documents\pos10E4.tmp
C:\Documents and Settings\HP_Owner\My Documents\pos10E5.tmp
C:\Documents and Settings\HP_Owner\My Documents\pos10E6.tmp
C:\Documents and Settings\HP_Owner\My Documents\pos10E7.tmp
C:\Documents and Settings\HP_Owner\My Documents\pos10E8.tmp
C:\Documents and Settings\HP_Owner\My Documents\pos10E9.tmp
C:\Documents and Settings\HP_Owner\My Documents\pos10EA.tmp
C:\Documents and Settings\HP_Owner\My Documents\pos10EB.tmp
C:\Documents and Settings\HP_Owner\My Documents\pos10EC.tmp
C:\Documents and Settings\HP_Owner\My Documents\pos10ED.tmp
C:\Documents and Settings\HP_Owner\My Documents\pos10EE.tmp
C:\Documents and Settings\HP_Owner\My Documents\pos10EF.tmp
C:\Documents and Settings\HP_Owner\My Documents\pos10F0.tmp
C:\Documents and Settings\HP_Owner\My Documents\pos10F1.tmp
C:\Documents and Settings\HP_Owner\My Documents\pos10F2.tmp
C:\Documents and Settings\HP_Owner\My Documents\pos10F3.tmp
C:\Documents and Settings\HP_Owner\My Documents\pos10F4.tmp
C:\Documents and Settings\HP_Owner\My Documents\pos10F5.tmp
C:\Documents and Settings\HP_Owner\My Documents\pos10F6.tmp
C:\Documents and Settings\HP_Owner\My Documents\pos10F7.tmp
C:\Documents and Settings\HP_Owner\My Documents\pos10F8.tmp
C:\Documents and Settings\HP_Owner\My Documents\pos10F9.tmp
C:\Documents and Settings\HP_Owner\My Documents\pos10FA.tmp
C:\Documents and Settings\HP_Owner\My Documents\pos10FB.tmp
C:\Documents and Settings\HP_Owner\My Documents\pos10FC.tmp
C:\Documents and Settings\HP_Owner\My Documents\pos10FD.tmp
C:\Documents and Settings\HP_Owner\My Documents\pos10FE.tmp
C:\Documents and Settings\HP_Owner\My Documents\pos10FF.tmp
C:\Documents and Settings\HP_Owner\My Documents\pos1100.tmp
C:\Documents and Settings\HP_Owner\My Documents\pos1101.tmp
C:\Documents and Settings\HP_Owner\My Documents\pos1102.tmp
C:\Documents and Settings\HP_Owner\My Documents\pos1103.tmp
C:\Documents and Settings\HP_Owner\My Documents\pos1104.tmp
C:\Documents and Settings\HP_Owner\My Documents\pos1105.tmp
C:\Documents and Settings\HP_Owner\My Documents\pos1106.tmp
C:\Documents and Settings\HP_Owner\My Documents\pos1107.tmp
C:\Documents and Settings\HP_Owner\My Documents\pos1108.tmp
C:\Documents and Settings\HP_Owner\My Documents\pos1109.tmp
C:\Documents and Settings\HP_Owner\My Documents\pos110A.tmp
C:\Documents and Settings\HP_Owner\My Documents\pos110B.tmp
C:\Documents and Settings\HP_Owner\My Documents\pos110C.tmp
C:\Documents and Settings\HP_Owner\My Documents\pos110D.tmp
C:\Documents and Settings\HP_Owner\My Documents\pos110E.tmp
C:\Documents and Settings\HP_Owner\My Documents\pos110F.tmp
C:\Documents and Settings\HP_Owner\My Documents\pos1110.tmp
C:\Documents and Settings\HP_Owner\My Documents\pos1111.tmp
C:\Documents and Settings\HP_Owner\My Documents\pos1112.tmp
C:\Documents and Settings\HP_Owner\My Documents\pos1113.tmp
C:\Documents and Settings\HP_Owner\My Documents\pos1114.tmp
C:\Documents and Settings\HP_Owner\My Documents\pos1115.tmp
C:\Documents and Settings\HP_Owner\My Documents\pos1116.tmp
C:\Documents and Settings\HP_Owner\My Documents\pos1117.tmp
C:\Documents and Settings\HP_Owner\My Documents\pos1118.tmp
C:\Documents and Settings\HP_Owner\My Documents\pos1119.tmp
C:\Documents and Settings\HP_Owner\My Documents\pos111A.tmp
C:\Documents and Settings\HP_Owner\My Documents\pos111B.tmp
C:\Documents and Settings\HP_Owner\My Documents\pos111C.tmp
C:\Documents and Settings\HP_Owner\My Documents\pos111D.tmp
C:\Documents and Settings\HP_Owner\My Documents\pos111E.tmp
C:\Documents and Settings\HP_Owner\My Documents\pos111F.tmp
C:\Documents and Settings\HP_Owner\My Documents\pos1120.tmp
C:\Documents and Settings\HP_Owner\My Documents\pos1121.tmp
C:\Documents and Settings\HP_Owner\My Documents\pos1122.tmp
C:\Documents and Settings\HP_Owner\My Documents\pos1123.tmp
C:\Documents and Settings\HP_Owner\My Documents\pos1124.tmp
C:\Documents and Settings\HP_Owner\My Documents\pos1125.tmp
C:\Documents and Settings\HP_Owner\My Documents\pos1126.tmp
C:\Documents and Settings\HP_Owner\My Documents\pos1127.tmp
C:\Documents and Settings\HP_Owner\My Documents\pos1128.tmp
C:\Documents and Settings\HP_Owner\My Documents\pos1129.tmp
C:\Documents and Settings\HP_Owner\My Documents\pos112A.tmp
C:\Documents and Settings\HP_Owner\My Documents\pos112B.tmp
C:\Documents and Settings\HP_Owner\My Documents\pos112C.tmp
C:\Documents and Settings\HP_Owner\My Documents\pos112D.tmp
C:\Documents and Settings\HP_Owner\My Documents\pos112E.tmp
C:\Documents and Settings\HP_Owner\My Documents\pos112F.tmp
C:\Documents and Settings\HP_Owner\My Documents\pos1130.tmp
C:\Documents and Settings\HP_Owner\My Documents\pos1131.tmp
C:\Documents and Settings\HP_Owner\My Documents\pos1132.tmp
C:\Documents and Settings\HP_Owner\My Documents\pos1133.tmp
C:\Documents and Settings\HP_Owner\My Documents\pos1134.tmp
C:\Documents and Settings\HP_Owner\My Documents\pos1135.tmp
C:\Documents and Settings\HP_Owner\My Documents\pos1136.tmp
C:\Documents and Settings\HP_Owner\My Documents\pos1137.tmp
C:\Documents and Settings\HP_Owner\My Documents\pos1138.tmp
C:\Documents and Settings\HP_Owner\My Documents\pos1139.tmp
C:\Documents and Settings\HP_Owner\My Documents\pos113A.tmp
C:\Documents and Settings\HP_Owner\My Documents\pos113B.tmp
C:\Documents and Settings\HP_Owner\My Documents\pos113C.tmp
C:\Documents and Settings\HP_Owner\My Documents\pos113D.tmp
C:\Documents and Settings\HP_Owner\My Documents\pos113E.tmp
C:\Documents and Settings\HP_Owner\My Documents\pos113F.tmp
C:\Documents and Settings\HP_Owner\My Documents\pos1140.tmp
C:\Documents and Settings\HP_Owner\My Documents\pos1141.tmp
C:\Documents and Settings\HP_Owner\My Documents\pos1142.tmp
C:\Documents and Settings\HP_Owner\My Documents\pos1143.tmp
C:\Documents and Settings\HP_Owner\My Documents\pos1144.tmp
C:\Documents and Settings\HP_Owner\My Documents\pos1145.tmp
C:\Documents and Settings\HP_Owner\My Documents\pos1146.tmp
C:\Documents and Settings\HP_Owner\My Documents\pos1147.tmp
C:\Documents and Settings\HP_Owner\My Documents\pos1148.tmp
C:\Documents and Settings\HP_Owner\My Documents\pos1149.tmp
C:\Documents and Settings\HP_Owner\My Documents\pos114A.tmp
C:\Documents and Settings\HP_Owner\My Documents\pos114B.tmp
C:\Documents and Settings\HP_Owner\My Documents\pos114C.tmp
C:\Documents and Settings\HP_Owner\My Documents\pos114D.tmp
C:\Documents and Settings\HP_Owner\My Documents\pos114E.tmp
C:\Documents and Settings\HP_Owner\My Documents\pos114F.tmp
C:\Documents and Settings\HP_Owner\My Documents\pos1150.tmp
C:\Documents and Settings\HP_Owner\My Documents\pos1151.tmp
C:\Documents and Settings\HP_Owner\My Documents\pos1152.tmp
C:\Documents and Settings\HP_Owner\My Documents\pos1153.tmp
C:\Documents and Settings\HP_Owner\My Documents\pos1154.tmp
C:\Documents and Settings\HP_Owner\My Documents\pos1155.tmp
C:\Documents and Settings\HP_Owner\My Documents\pos1156.tmp
C:\Documents and Settings\HP_Owner\My Documents\pos1157.tmp
C:\Documents and Settings\HP_Owner\My Documents\pos1158.tmp
C:\Documents and Settings\HP_Owner\My Documents\pos1159.tmp
C:\Documents and Settings\HP_Owner\My Documents\pos115A.tmp
C:\Documents and Settings\HP_Owner\My Documents\pos115B.tmp
C:\Documents and Settings\HP_Owner\My Documents\pos115C.tmp
C:\Documents and Settings\HP_Owner\My Documents\pos115D.tmp
C:\Documents and Settings\HP_Owner\My Documents\pos115E.tmp
C:\Documents and Settings\HP_Owner\My Documents\pos115F.tmp
C:\Documents and Settings\HP_Owner\My Documents\pos1160.tmp
C:\Documents and Settings\HP_Owner\My Documents\pos1161.tmp
C:\Documents and Settings\HP_Owner\My Documents\pos1162.tmp
C:\Documents and Settings\HP_Owner\My Documents\pos1163.tmp
C:\Documents and Settings\HP_Owner\My Documents\pos1164.tmp
C:\Documents and Settings\HP_Owner\My Documents\pos1165.tmp
C:\Documents and Settings\HP_Owner\My Documents\pos1166.tmp
C:\Documents and Settings\HP_Owner\My Documents\pos1167.tmp
C:\Documents and Settings\HP_Owner\My Documents\pos1168.tmp
C:\Documents and Settings\HP_Owner\My Documents\pos1169.tmp
C:\Documents and Settings\HP_Owner\My Documents\pos116A.tmp
C:\Documents and Settings\HP_Owner\My Documents\pos116B.tmp
C:\Documents and Settings\HP_Owner\My Documents\pos116C.tmp
C:\Documents and Settings\HP_Owner\My Documents\pos116D.tmp
C:\Documents and Settings\HP_Owner\My Documents\pos116E.tmp
C:\Documents and Settings\HP_Owner\My Documents\pos116F.tmp
C:\Documents and Settings\HP_Owner\My Documents\pos1170.tmp
C:\Documents and Settings\HP_Owner\My Documents\pos1171.tmp
C:\Documents and Settings\HP_Owner\My Documents\pos1172.tmp
C:\Documents and Settings\HP_Owner\My Documents\pos1173.tmp
C:\Documents and Settings\HP_Owner\My Documents\pos1174.tmp
C:\Documents and Settings\HP_Owner\My Documents\pos1175.tmp
C:\Documents and Settings\HP_Owner\My Documents\pos1176.tmp
C:\Documents and Settings\HP_Owner\My Documents\pos1177.tmp
C:\Documents and Settings\HP_Owner\My Documents\pos1178.tmp
C:\Documents and Settings\HP_Owner\My Documents\pos1179.tmp
C:\Documents and Settings\HP_Owner\My Documents\pos117A.tmp
C:\Documents and Settings\HP_Owner\My Documents\pos117B.tmp
C:\Documents and Settings\HP_Owner\My Documents\pos117C.tmp
C:\Documents and Settings\HP_Owner\My Documents\pos117D.tmp
C:\Documents and Settings\HP_Owner\My Documents\pos117E.tmp
C:\Documents and Settings\HP_Owner\My Documents\pos117F.tmp
C:\Documents and Settings\HP_Owner\My Documents\pos1180.tmp
C:\Documents and Settings\HP_Owner\My Documents\pos1181.tmp
C:\Documents and Settings\HP_Owner\My Documents\pos1182.tmp
C:\Documents and Settings\HP_Owner\My Documents\pos1183.tmp
C:\Documents and Settings\HP_Owner\My Documents\pos1184.tmp
C:\Documents and Settings\HP_Owner\My Documents\pos1185.tmp
C:\Documents and Settings\HP_Owner\My Documents\pos1186.tmp
C:\Documents and Settings\HP_Owner\My Documents\pos1187.tmp
C:\Documents and Settings\HP_Owner\My Documents\pos1188.tmp
C:\Documents and Settings\HP_Owner\My Documents\pos1189.tmp
C:\Documents and Settings\HP_Owner\My Documents\pos118A.tmp
C:\Documents and Settings\HP_Owner\My Documents\pos118B.tmp
C:\Documents and Settings\HP_Owner\My Documents\pos118C.tmp
C:\Documents and Settings\HP_Owner\My Documents\pos118D.tmp
C:\Documents and Settings\HP_Owner\My Documents\pos118E.tmp
C:\Documents and Settings\HP_Owner\My Documents\pos118F.tmp
C:\Documents and Settings\HP_Owner\My Documents\pos1190.tmp
C:\Documents and Settings\HP_Owner\My Documents\pos1191.tmp
C:\Documents and Settings\HP_Owner\My Documents\pos1192.tmp
C:\Documents and Settings\HP_Owner\My Documents\pos1193.tmp
C:\Documents and Settings\HP_Owner\My Documents\pos1194.tmp
C:\Documents and Settings\HP_Owner\My Documents\pos1195.tmp
C:\Documents and Settings\HP_Owner\My Documents\pos1196.tmp
C:\Documents and Settings\HP_Owner\My Documents\pos1197.tmp
C:\Documents and Settings\HP_Owner\My Documents\pos1198.tmp
C:\Documents and Settings\HP_Owner\My Documents\pos1199.tmp
C:\Documents and Settings\HP_Owner\My Documents\pos119A.tmp
C:\Documents and Settings\HP_Owner\My Documents\pos119B.tmp
C:\Documents and Settings\HP_Owner\My Documents\pos119C.tmp
C:\Documents and Settings\HP_Owner\My Documents\pos119D.tmp
C:\Documents and Settings\HP_Owner\My Documents\pos119E.tmp
C:\Documents and Settings\HP_Owner\My Documents\pos119F.tmp
C:\Documents and Settings\HP_Owner\My Documents\pos11A0.tmp
C:\Documents and Settings\HP_Owner\My Documents\pos11A1.tmp
C:\Documents and Settings\HP_Owner\My Documents\pos11A2.tmp
C:\Documents and Settings\HP_Owner\My Documents\pos11A3.tmp
C:\Documents and Settings\HP_Owner\My Documents\pos11A4.tmp
C:\Documents and Settings\HP_Owner\My Documents\pos11A5.tmp
C:\Documents and Settings\HP_Owner\My Documents\pos11A6.tmp
C:\Documents and Settings\HP_Owner\My Documents\pos11A7.tmp
C:\Documents and Settings\HP_Owner\My Documents\pos11A8.tmp
C:\Documents and Settings\HP_Owner\My Documents\pos11A9.tmp
C:\Documents and Settings\HP_Owner\My Documents\pos11AA.tmp
C:\Documents and Settings\HP_Owner\My Documents\pos11AB.tmp
C:\Documents and Settings\HP_Owner\My Documents\pos11AC.tmp
C:\Documents and Settings\HP_Owner\My Documents\pos11AD.tmp
C:\Documents and Settings\HP_Owner\My Documents\pos11AE.tmp
C:\Documents and Settings\HP_Owner\My Documents\pos11AF.tmp
C:\Documents and Settings\HP_Owner\My Documents\pos11B0.tmp
C:\Documents and Settings\HP_Owner\My Documents\pos11B1.tmp
C:\Documents and Settings\HP_Owner\My Documents\pos11B2.tmp
C:\Documents and Settings\HP_Owner\My Documents\pos11B3.tmp
C:\Documents and Settings\HP_Owner\My Documents\pos11B4.tmp
C:\Documents and Settings\HP_Owner\My Documents\pos11B5.tmp
C:\Documents and Settings\HP_Owner\My Documents\pos11B6.tmp
C:\Documents and Settings\HP_Owner\My Documents\pos11B7.tmp
C:\Documents and Settings\HP_Owner\My Documents\pos11B8.tmp
C:\Documents and Settings\HP_Owner\My Documents\pos11B9.tmp
C:\Documents and Settings\HP_Owner\My Documents\pos11BA.tmp
C:\Documents and Settings\HP_Owner\My Documents\pos11BB.tmp
C:\Documents and Settings\HP_Owner\My Documents\pos11BC.tmp
C:\Documents and Settings\HP_Owner\My Documents\pos11BD.tmp
C:\Documents and Settings\HP_Owner\My Documents\pos11BE.tmp
C:\Documents and Settings\HP_Owner\My Documents\pos11BF.tmp
C:\Documents and Settings\HP_Owner\My Documents\pos11C0.tmp
C:\Documents and Settings\HP_Owner\My Documents\pos11C1.tmp
C:\Documents and Settings\HP_Owner\My Documents\pos11C2.tmp
C:\Documents and Settings\HP_Owner\My Documents\pos11C3.tmp
C:\Documents and Settings\HP_Owner\My Documents\pos11C4.tmp
C:\Documents and Settings\HP_Owner\My Documents\pos11C5.tmp
C:\Documents and Settings\HP_Owner\My Documents\pos11C6.tmp
C:\Documents and Settings\HP_Owner\My Documents\pos11C7.tmp
C:\Documents and Settings\HP_Owner\My Documents\pos11C8.tmp
C:\Documents and Settings\HP_Owner\My Documents\pos11C9.tmp
C:\Documents and Settings\HP_Owner\My Documents\pos11CA.tmp
C:\Documents and Settings\HP_Owner\My Documents\pos11CB.tmp
C:\Documents and Settings\HP_Owner\My Documents\pos11CC.tmp
C:\Documents and Settings\HP_Owner\My Documents\pos11CD.tmp
C:\Documents and Settings\HP_Owner\My Documents\pos11CE.tmp
C:\Documents and Settings\HP_Owner\My Documents\pos11CF.tmp
C:\Documents and Settings\HP_Owner\My Documents\pos11D0.tmp
C:\Documents and Settings\HP_Owner\My Documents\pos11D1.tmp
C:\Documents and Settings\HP_Owner\My Documents\pos11D2.tmp
C:\Documents and Settings\HP_Owner\My Documents\pos11D3.tmp
C:\Documents and Settings\HP_Owner\My Documents\pos11D4.tmp
C:\Documents and Settings\HP_Owner\My Documents\pos11D5.tmp
C:\Documents and Settings\HP_Owner\My Documents\pos11D6.tmp
C:\Documents and Settings\HP_Owner\My Documents\pos11D7.tmp
C:\Documents and Settings\HP_Owner\My Documents\pos11D8.tmp
C:\Documents and Settings\HP_Owner\My Documents\pos11D9.tmp
C:\Documents and Settings\HP_Owner\My Documents\pos11DA.tmp
C:\Documents and Settings\HP_Owner\My Documents\pos11DB.tmp
C:\Documents and Settings\HP_Owner\My Documents\pos11DC.tmp
C:\Documents and Settings\HP_Owner\My Documents\pos11DD.tmp
C:\Documents and Settings\HP_Owner\My Documents\pos11DE.tmp
C:\Documents and Settings\HP_Owner\My Documents\pos11DF.tmp
C:\Documents and Settings\HP_Owner\My Documents\pos11E0.tmp
C:\Documents and Settings\HP_Owner\My Documents\pos11E1.tmp
C:\Documents and Settings\HP_Owner\My Documents\pos11E2.tmp
C:\Documents and Settings\HP_Owner\My Documents\pos11E3.tmp
C:\Documents and Settings\HP_Owner\My Documents\pos11E4.tmp
C:\Documents and Settings\HP_Owner\My Documents\pos11E5.tmp
C:\Documents and Settings\HP_Owner\My Documents\pos11E6.tmp
C:\Documents and Settings\HP_Owner\My Documents\pos11E7.tmp
C:\Documents and Settings\HP_Owner\My Documents\pos11E8.tmp
C:\Documents and Settings\HP_Owner\My Documents\pos11E9.tmp
C:\Documents and Settings\HP_Owner\My Documents\pos11EA.tmp
C:\Documents and Settings\HP_Owner\My Documents\pos11EB.tmp
C:\Documents and Settings\HP_Owner\My Documents\pos11EC.tmp
C:\Documents and Settings\HP_Owner\My Documents\pos11ED.tmp
C:\Documents and Settings\HP_Owner\My Documents\pos11EE.tmp
C:\Documents and Settings\HP_Owner\My Documents\pos11EF.tmp
C:\Documents and Settings\HP_Owner\My Documents\pos11F0.tmp
C:\Documents and Settings\HP_Owner\My Documents\pos11F1.tmp
C:\Documents and Settings\HP_Owner\My Documents\pos11F2.tmp
C:\Documents and Settings\HP_Owner\My Documents\pos11F3.tmp
C:\Documents and Settings\HP_Owner\My Documents\pos11F4.tmp
C:\Documents and Settings\HP_Owner\My Documents\pos11F5.tmp
C:\Documents and Settings\HP_Owner\My Documents\pos11F6.tmp
C:\Documents and Settings\HP_Owner\My Documents\pos11F7.tmp
C:\Documents and Settings\HP_Owner\My Documents\pos11F8.tmp
C:\Documents and Settings\HP_Owner\My Documents\pos11F9.tmp
C:\Documents and Settings\HP_Owner\My Documents\pos11FA.tmp
C:\Documents and Settings\HP_Owner\My Documents\pos11FB.tmp
C:\Documents and Settings\HP_Owner\My Documents\pos11FC.tmp
C:\Documents and Settings\HP_Owner\My Documents\pos11FD.tmp
C:\Documents and Settings\HP_Owner\My Documents\pos11FE.tmp
C:\Documents and Settings\HP_Owner\My Documents\pos11FF.tmp
C:\Documents and Settings\HP_Owner\My Documents\pos1200.tmp
C:\Documents and Settings\HP_Owner\My Documents\pos1201.tmp
C:\Documents and Settings\HP_Owner\My Documents\pos1202.tmp
C:\Documents and Settings\HP_Owner\My Documents\pos1203.tmp
C:\Documents and Settings\HP_Owner\My Documents\pos1204.tmp
C:\Documents and Settings\HP_Owner\My Documents\pos1205.tmp
C:\Documents and Settings\HP_Owner\My Documents\pos1206.tmp
C:\Documents and Settings\HP_Owner\My Documents\pos1207.tmp
C:\Documents and Settings\HP_Owner\My Documents\pos1208.tmp
C:\Documents and Settings\HP_Owner\My Documents\pos1209.tmp
C:\Documents and Settings\HP_Owner\My Documents\pos120A.tmp
C:\Documents and Settings\HP_Owner\My Documents\pos120B.tmp
C:\Documents and Settings\HP_Owner\My Documents\pos120C.tmp
C:\Documents and Settings\HP_Owner\My Documents\pos120D.tmp
C:\Documents and Settings\HP_Owner\My Documents\pos120E.tmp
C:\Documents and Settings\HP_Owner\My Documents\pos120F.tmp
C:\Documents and Settings\HP_Owner\My Documents\pos1210.tmp
C:\Documents and Settings\HP_Owner\My Documents\pos1211.tmp
C:\Documents and Settings\HP_Owner\My Documents\pos1212.tmp
C:\Documents and Settings\HP_Owner\My Documents\pos1213.tmp
C:\Documents and Settings\HP_Owner\My Documents\pos1214.tmp
C:\Documents and Settings\HP_Owner\My Documents\pos1215.tmp
C:\Documents and Settings\HP_Owner\My Documents\pos1216.tmp
C:\Documents and Settings\HP_Owner\My Documents\pos1217.tmp
C:\Documents and Settings\HP_Owner\My Documents\pos1218.tmp
C:\Documents and Settings\HP_Owner\My Documents\pos1219.tmp
C:\Documents and Settings\HP_Owner\My Documents\pos121A.tmp
C:\Documents and Settings\HP_Owner\My Documents\pos121B.tmp
C:\Documents and Settings\HP_Owner\My Documents\pos121C.tmp
C:\Documents and Settings\HP_Owner\My Documents\pos121D.tmp
C:\Documents and Settings\HP_Owner\My Documents\pos121E.tmp
C:\Documents and Settings\HP_Owner\My Documents\pos121F.tmp
C:\Documents and Settings\HP_Owner\My Documents\pos1220.tmp
C:\Documents and Settings\HP_Owner\My Documents\pos1221.tmp
C:\Documents and Settings\HP_Owner\My Documents\pos1222.tmp
C:\Documents and Settings\HP_Owner\My Documents\pos1223.tmp
C:\Documents and Settings\HP_Owner\My Documents\pos1224.tmp
C:\Documents and Settings\HP_Owner\My Documents\pos1225.tmp
C:\Documents and Settings\HP_Owner\My Documents\pos1226.tmp
C:\Documents and Settings\HP_Owner\My Documents\pos1227.tmp
C:\Documents and Settings\HP_Owner\My Documents\pos1228.tmp
C:\Documents and Settings\HP_Owner\My Documents\pos1229.tmp
C:\Documents and Settings\HP_Owner\My Documents\pos122A.tmp
C:\Documents and Settings\HP_Owner\My Documents\pos122B.tmp
C:\Documents and Settings\HP_Owner\My Documents\pos122C.tmp
C:\Documents and Settings\HP_Owner\My Documents\pos122D.tmp
C:\Documents and Settings\HP_Owner\My Documents\pos122E.tmp
C:\Documents and Settings\HP_Owner\My Documents\pos122F.tmp
C:\Documents and Settings\HP_Owner\My Documents\pos1230.tmp
C:\Documents and Settings\HP_Owner\My Documents\pos1231.tmp
C:\Documents and Settings\HP_Owner\My Documents\pos1232.tmp
C:\Documents and Settings\HP_Owner\My Documents\pos1233.tmp
C:\Documents and Settings\HP_Owner\My Documents\pos1234.tmp
C:\Documents and Settings\HP_Owner\My Documents\pos1235.tmp
C:\Documents and Settings\HP_Owner\My Documents\pos1236.tmp
C:\Documents and Settings\HP_Owner\My Documents\pos1237.tmp
C:\Documents and Settings\HP_Owner\My Documents\pos1238.tmp
C:\Documents and Settings\HP_Owner\My Documents\pos1239.tmp
C:\Documents and Settings\HP_Owner\My Documents\pos123A.tmp
C:\Documents and Settings\HP_Owner\My Documents\pos123B.tmp
C:\Documents and Settings\HP_Owner\My Documents\pos123C.tmp
C:\Documents and Settings\HP_Owner\My Documents\pos123D.tmp
C:\Documents and Settings\HP_Owner\My Documents\pos123E.tmp
C:\Documents and Settings\HP_Owner\My Documents\pos123F.tmp
C:\Documents and Settings\HP_Owner\My Documents\pos1240.tmp
C:\Documents and Settings\HP_Owner\My Documents\pos1241.tmp
C:\Documents and Settings\HP_Owner\My Documents\pos1242.tmp
C:\Documents and Settings\HP_Owner\My Documents\pos1243.tmp
C:\Documents and Settings\HP_Owner\My Documents\pos1244.tmp
C:\Documents and Settings\HP_Owner\My Documents\pos1245.tmp
C:\Documents and Settings\HP_Owner\My Documents\pos1246.tmp
C:\Documents and Settings\HP_Owner\My Documents\pos1247.tmp
C:\Documents and Settings\HP_Owner\My Documents\pos1248.tmp
C:\Documents and Settings\HP_Owner\My Documents\pos1249.tmp
C:\Documents and Settings\HP_Owner\My Documents\pos124A.tmp
C:\Documents and Settings\HP_Owner\My Documents\pos124B.tmp
C:\Documents and Settings\HP_Owner\My Documents\pos124C.tmp
C:\Documents and Settings\HP_Owner\My Documents\pos124D.tmp
C:\Documents and Settings\HP_Owner\My Documents\pos124E.tmp
C:\Documents and Settings\HP_Owner\My Documents\pos124F.tmp
C:\Documents and Settings\HP_Owner\My Documents\pos1250.tmp
C:\Documents and Settings\HP_Owner\My Documents\pos1251.tmp
C:\Documents and Settings\HP_Owner\My Documents\pos1252.tmp
C:\Documents and Settings\HP_Owner\My Documents\pos1253.tmp
C:\Documents and Settings\HP_Owner\My Documents\pos1254.tmp
C:\Documents and Settings\HP_Owner\My Documents\pos1255.tmp
C:\Documents and Settings\HP_Owner\My Documents\pos1256.tmp
C:\Documents and Settings\HP_Owner\My Documents\pos1257.tmp
C:\Documents and Settings\HP_Owner\My Documents\pos1258.tmp
C:\Documents and Settings\HP_Owner\My Documents\pos1259.tmp
C:\Documents and Settings\HP_Owner\My Documents\pos125A.tmp
C:\Documents and Settings\HP_Owner\My Documents\pos125B.tmp
C:\Documents and Settings\HP_Owner\My Documents\pos125C.tmp
C:\Documents and Settings\HP_Owner\My Documents\pos125D.tmp
C:\Documents and Settings\HP_Owner\My Documents\pos125E.tmp
C:\Documents and Settings\HP_Owner\My Documents\pos125F.tmp
C:\Documents and Settings\HP_Owner\My Documents\pos1260.tmp
C:\Documents and Settings\HP_Owner\My Documents\pos1261.tmp
C:\Documents and Settings\HP_Owner\My Documents\pos1262.tmp
C:\Documents and Settings\HP_Owner\My Documents\pos1263.tmp
C:\Documents and Settings\HP_Owner\My Documents\pos1264.tmp
C:\Documents and Settings\HP_Owner\My Documents\pos1265.tmp
C:\Documents and Settings\HP_Owner\My Documents\pos1266.tmp
C:\Documents and Settings\HP_Owner\My Documents\pos1267.tmp
C:\Documents and Settings\HP_Owner\My Documents\pos1268.tmp
C:\Documents and Settings\HP_Owner\My Documents\pos1269.tmp
C:\Documents and Settings\HP_Owner\My Documents\pos126A.tmp
C:\Documents and Settings\HP_Owner\My Documents\pos126B.tmp
C:\Documents and Settings\HP_Owner\My Documents\pos126C.tmp
C:\Documents and Settings\HP_Owner\My Documents\pos126D.tmp
C:\Documents and Settings\HP_Owner\My Documents\pos126E.tmp
C:\Documents and Settings\HP_Owner\My Documents\pos126F.tmp
C:\Documents and Settings\HP_Owner\My Documents\pos1270.tmp
C:\Documents and Settings\HP_Owner\My Documents\pos1271.tmp
C:\Documents and Settings\HP_Owner\My Documents\pos1272.tmp
C:\Documents and Settings\HP_Owner\My Documents\pos1273.tmp
C:\Documents and Settings\HP_Owner\My Documents\pos1274.tmp
C:\Documents and Settings\HP_Owner\My Documents\pos1275.tmp
C:\Documents and Settings\HP_Owner\My Documents\pos1276.tmp
C:\Documents and Settings\HP_Owner\My Documents\pos1277.tmp
C:\Documents and Settings\HP_Owner\My Documents\pos1278.tmp
C:\Documents and Settings\HP_Owner\My Documents\pos1279.tmp
C:\Documents and Settings\HP_Owner\My Documents\pos127A.tmp
C:\Documents and Settings\HP_Owner\My Documents\pos127B.tmp
C:\Documents and Settings\HP_Owner\My Documents\pos127C.tmp
C:\Documents and Settings\HP_Owner\My Documents\pos127D.tmp
C:\Documents and Settings\HP_Owner\My Documents\pos127E.tmp
C:\Documents and Settings\HP_Owner\My Documents\pos127F.tmp
C:\Documents and Settings\HP_Owner\My Documents\pos1280.tmp
C:\Documents and Settings\HP_Owner\My Documents\pos1281.tmp
C:\Documents and Settings\HP_Owner\My Documents\pos1282.tmp
C:\Documents and Settings\HP_Owner\My Documents\pos1283.tmp
C:\Documents and Settings\HP_Owner\My Documents\pos1284.tmp
C:\Documents and Settings\HP_Owner\My Documents\pos1285.tmp
C:\Documents and Settings\HP_Owner\My Documents\pos1286.tmp
C:\Documents and Settings\HP_Owner\My Documents\pos1287.tmp
C:\Documents and Settings\HP_Owner\My Documents\pos1288.tmp
C:\Documents and Settings\HP_Owner\My Documents\pos1289.tmp
C:\Documents and Settings\HP_Owner\My Documents\pos128A.tmp
C:\Documents and Settings\HP_Owner\My Documents\pos128B.tmp
C:\Documents and Settings\HP_Owner\My Documents\pos128C.tmp
C:\Documents and Settings\HP_Owner\My Documents\pos128D.tmp
C:\Documents and Settings\HP_Owner\My Documents\pos128E.tmp
C:\Documents and Settings\HP_Owner\My Documents\pos128F.tmp
C:\Documents and Settings\HP_Owner\My Documents\pos1290.tmp
C:\Documents and Settings\HP_Owner\My Documents\pos1291.tmp
C:\Documents and Settings\HP_Owner\My Documents\pos1292.tmp
C:\Documents and Settings\HP_Owner\My Documents\pos1293.tmp
C:\Documents and Settings\HP_Owner\My Documents\pos1294.tmp
C:\Documents and Settings\HP_Owner\My Documents\pos1295.tmp
C:\Documents and Settings\HP_Owner\My Documents\pos1296.tmp
C:\Documents and Settings\HP_Owner\My Documents\pos1297.tmp
C:\Documents and Settings\HP_Owner\My Documents\pos1298.tmp
C:\Documents and Settings\HP_Owner\My Documents\pos1299.tmp
C:\Documents and Settings\HP_Owner\My Documents\pos129A.tmp
C:\Documents and Settings\HP_Owner\My Documents\pos129B.tmp
C:\Documents and Settings\HP_Owner\My Documents\pos129C.tmp
C:\Documents and Settings\HP_Owner\My Documents\pos129D.tmp
C:\Documents and Settings\HP_Owner\My Documents\pos129E.tmp
C:\Documents and Settings\HP_Owner\My Documents\pos129F.tmp
C:\Documents and Settings\HP_Owner\My Documents\pos12A0.tmp
C:\Documents and Settings\HP_Owner\My Documents\pos12A1.tmp
C:\Documents and Settings\HP_Owner\My Documents\pos12A2.tmp
C:\Documents and Settings\HP_Owner\My Documents\pos12A3.tmp
C:\Documents and Settings\HP_Owner\My Documents\pos12A4.tmp
C:\Documents and Settings\HP_Owner\My Documents\pos12A5.tmp
C:\Documents and Settings\HP_Owner\My Documents\pos12A6.tmp
C:\Documents and Settings\HP_Owner\My Documents\pos12A7.tmp
C:\Documents and Settings\HP_Owner\My Documents\pos12A8.tmp
C:\Documents and Settings\HP_Owner\My Documents\pos12A9.tmp
C:\Documents and Settings\HP_Owner\My Documents\pos12AA.tmp
C:\Documents and Settings\HP_Owner\My Documents\pos12AB.tmp
C:\Documents and Settings\HP_Owner\My Documents\pos12AC.tmp
C:\Documents and Settings\HP_Owner\My Documents\pos12AD.tmp
C:\Documents and Settings\HP_Owner\My Documents\pos12AE.tmp
C:\Documents and Settings\HP_Owner\My Documents\pos12AF.tmp
C:\Documents and Settings\HP_Owner\My Documents\pos12B0.tmp
C:\Documents and Settings\HP_Owner\My Documents\pos12B1.tmp
C:\Documents and Settings\HP_Owner\My Documents\pos12B2.tmp
C:\Documents and Settings\HP_Owner\My Documents\pos12B3.tmp
C:\Documents and Settings\HP_Owner\My Documents\pos12B4.tmp
C:\Documents and Settings\HP_Owner\My Documents\pos12B5.tmp
C:\Documents and Settings\HP_Owner\My Documents\pos12B6.tmp
C:\Documents and Settings\HP_Owner\My Documents\pos12B7.tmp
C:\Documents and Settings\HP_Owner\My Documents\pos12B8.tmp
C:\Documents and Settings\HP_Owner\My Documents\pos12B9.tmp
C:\Documents and Settings\HP_Owner\My Documents\pos12BA.tmp
C:\Documents and Settings\HP_Owner\My Documents\pos12BB.tmp
C:\Documents and Settings\HP_Owner\My Documents\pos12BC.tmp
C:\Documents and Settings\HP_Owner\My Documents\pos12BD.tmp
C:\Documents and Settings\HP_Owner\My Documents\pos12BE.tmp
C:\Documents and Settings\HP_Owner\My Documents\pos12BF.tmp
C:\Documents and Settings\HP_Owner\My Documents\pos12C0.tmp
C:\Documents and Settings\HP_Owner\My Documents\pos12C1.tmp
C:\Documents and Settings\HP_Owner\My Documents\pos12C2.tmp
C:\Documents and Settings\HP_Owner\My Documents\pos12C3.tmp
C:\Documents and Settings\HP_Owner\My Documents\pos12C4.tmp
C:\Documents and Settings\HP_Owner\My Documents\pos12C5.tmp
C:\Documents and Settings\HP_Owner\My Documents\pos12C6.tmp
C:\Documents and Settings\HP_Owner\My Documents\pos12C7.tmp
C:\Documents and Settings\HP_Owner\My Documents\pos12C8.tmp
C:\Documents and Settings\HP_Owner\My Documents\pos12C9.tmp
C:\Documents and Settings\HP_Owner\My Documents\pos12CA.tmp
C:\Documents and Settings\HP_Owner\My Documents\pos12CB.tmp
C:\Documents and Settings\HP_Owner\My Documents\pos12CC.tmp
C:\Documents and Settings\HP_Owner\My Documents\pos12CD.tmp
C:\Documents and Settings\HP_Owner\My Documents\pos12CE.tmp
C:\Documents and Settings\HP_Owner\My Documents\pos12CF.tmp
C:\Documents and Settings\HP_Owner\My Documents\pos12D0.tmp
C:\Documents and Settings\HP_Owner\My Documents\pos12D1.tmp
C:\Documents and Settings\HP_Owner\My Documents\pos12D2.tmp
C:\Documents and Settings\HP_Owner\My Documents\pos12D3.tmp
C:\Documents and Settings\HP_Owner\My Documents\pos12D4.tmp
C:\Documents and Settings\HP_Owner\My Documents\pos12D5.tmp
C:\Documents and Settings\HP_Owner\My Documents\pos12D6.tmp
C:\Documents and Settings\HP_Owner\My Documents\pos12D7.tmp
C:\Documents and Settings\HP_Owner\My Documents\pos12D8.tmp
C:\Documents and Settings\HP_Owner\My Documents\pos12D9.tmp
C:\Documents and Settings\HP_Owner\My Documents\pos12DA.tmp
C:\Documents and Settings\HP_Owner\My Documents\pos12DB.tmp
C:\Documents and Settings\HP_Owner\My Documents\pos12DC.tmp
C:\Documents and Settings\HP_Owner\My Documents\pos12DD.tmp
C:\Documents and Settings\HP_Owner\My Documents\pos12DE.tmp
C:\Documents and Settings\HP_Owner\My Documents\pos12DF.tmp
C:\Documents and Settings\HP_Owner\My Documents\pos12E0.tmp
C:\Documents and Settings\HP_Owner\My Documents\pos12E1.tmp
C:\Documents and Settings\HP_Owner\My Documents\pos12E2.tmp
C:\Documents and Settings\HP_Owner\My Documents\pos12E3.tmp
C:\Documents and Settings\HP_Owner\My Documents\pos12E4.tmp
C:\Documents and Settings\HP_Owner\My Documents\pos12E5.tmp
C:\Documents and Settings\HP_Owner\My Documents\pos12E6.tmp
C:\Documents and Settings\HP_Owner\My Documents\pos12E7.tmp
C:\Documents and Settings\HP_Owner\My Documents\pos12E8.tmp
C:\Documents and Settings\HP_Owner\My Documents\pos12E9.tmp
C:\Documents and Settings\HP_Owner\My Documents\pos12EA.tmp
C:\Documents and Settings\HP_Owner\My Documents\pos12EB.tmp
C:\Documents and Settings\HP_Owner\My Documents\pos12EC.tmp
C:\Documents and Settings\HP_Owner\My Documents\pos12ED.tmp
C:\Documents and Settings\HP_Owner\My Documents\pos12EE.tmp
C:\Documents and Settings\HP_Owner\My Documents\pos12EF.tmp
C:\Documents and Settings\HP_Owner\My Documents\pos12F0.tmp
C:\Documents and Settings\HP_Owner\My Documents\pos12F1.tmp
C:\Documents and Settings\HP_Owner\My Documents\pos12F2.tmp
C:\Documents and Settings\HP_Owner\My Documents\pos12F3.tmp
C:\Documents and Settings\HP_Owner\My Documents\pos12F4.tmp
C:\Documents and Settings\HP_Owner\My Documents\pos12F5.tmp
C:\Documents and Settings\HP_Owner\My Documents\pos12F6.tmp
C:\Documents and Settings\HP_Owner\My Documents\pos12F7.tmp
C:\Documents and Settings\HP_Owner\My Documents\pos12F8.tmp
C:\Documents and Settings\HP_Owner\My Documents\pos12F9.tmp
C:\Documents and Settings\HP_Owner\My Documents\pos12FA.tmp
C:\Documents and Settings\HP_Owner\My Documents\pos12FB.tmp
C:\Documents and Settings\HP_Owner\My Documents\pos12FC.tmp
C:\Documents and Settings\HP_Owner\My Documents\pos12FD.tmp
C:\Documents and Settings\HP_Owner\My Documents\pos12FE.tmp
C:\Documents and Settings\HP_Owner\My Documents\pos12FF.tmp
C:\Documents and Settings\HP_Owner\My Documents\pos1300.tmp
C:\Documents and Settings\HP_Owner\My Documents\pos1301.tmp
C:\Documents and Settings\HP_Owner\My Documents\pos1302.tmp
C:\Documents and Settings\HP_Owner\My Documents\pos1303.tmp
C:\Documents and Settings\HP_Owner\My Documents\pos1304.tmp
C:\Documents and Settings\HP_Owner\My Documents\pos1305.tmp
C:\Documents and Settings\HP_Owner\My Documents\pos1306.tmp
C:\Documents and Settings\HP_Owner\My Documents\pos1307.tmp
C:\Documents and Settings\HP_Owner\My Documents\pos1308.tmp
C:\Documents and Settings\HP_Owner\My Documents\pos1309.tmp
C:\Documents and Settings\HP_Owner\My Documents\pos130A.tmp
C:\Documents and Settings\HP_Owner\My Documents\pos130B.tmp
C:\Documents and Settings\HP_Owner\My Documents\pos130C.tmp
C:\Documents and Settings\HP_Owner\My Documents\pos130D.tmp
C:\Documents and Settings\HP_Owner\My Documents\pos130E.tmp
C:\Documents and Settings\HP_Owner\My Documents\pos130F.tmp
C:\Documents and Settings\HP_Owner\My Documents\pos1310.tmp
C:\Documents and Settings\HP_Owner\My Documents\pos1311.tmp
C:\Documents and Settings\HP_Owner\My Documents\pos1312.tmp
C:\Documents and Settings\HP_Owner\My Documents\pos1313.tmp
C:\Documents and Settings\HP_Owner\My Documents\pos1314.tmp
C:\Documents and Settings\HP_Owner\My Documents\pos1315.tmp
C:\Documents and Settings\HP_Owner\My Documents\pos1316.tmp
C:\Documents and Settings\HP_Owner\My Documents\pos1317.tmp
C:\Documents and Settings\HP_Owner\My Documents\pos1318.tmp
C:\Documents and Settings\HP_Owner\My Documents\pos1319.tmp
C:\Documents and Settings\HP_Owner\My Documents\pos131A.tmp
C:\Documents and Settings\HP_Owner\My Documents\pos131B.tmp
C:\Documents and Settings\HP_Owner\My Documents\pos131C.tmp
C:\Documents and Settings\HP_Owner\My Documents\pos131D.tmp
C:\Documents and Settings\HP_Owner\My Documents\pos131E.tmp
C:\Documents and Settings\HP_Owner\My Documents\pos131F.tmp
C:\Documents and Settings\HP_Owner\My Documents\pos1320.tmp
C:\Documents and Settings\HP_Owner\My Documents\pos1321.tmp
C:\Documents and Settings\HP_Owner\My Documents\pos1322.tmp
C:\Documents and Settings\HP_Owner\My Documents\pos1323.tmp
C:\Documents and Settings\HP_Owner\My Documents\pos1324.tmp
C:\Documents and Settings\HP_Owner\My Documents\pos1325.tmp
C:\Documents and Settings\HP_Owner\My Documents\pos1326.tmp
C:\Documents and Settings\HP_Owner\My Documents\pos1327.tmp
C:\Documents and Settings\HP_Owner\My Documents\pos1328.tmp
C:\Documents and Settings\HP_Owner\My Documents\pos1329.tmp
C:\Documents and Settings\HP_Owner\My Documents\pos132A.tmp
C:\Documents and Settings\HP_Owner\My Documents\pos132B.tmp
C:\Documents and Settings\HP_Owner\My Documents\pos132C.tmp
C:\Documents and Settings\HP_Owner\My Documents\pos132D.tmp
C:\Documents and Settings\HP_Owner\My Documents\pos132E.tmp
C:\Documents and Settings\HP_Owner\My Documents\pos132F.tmp
C:\Documents and Settings\HP_Owner\My Documents\pos1330.tmp
C:\Documents and Settings\HP_Owner\My Documents\pos1331.tmp
C:\Documents and Settings\HP_Owner\My Documents\pos1332.tmp
C:\Documents and Settings\HP_Owner\My Documents\pos1333.tmp
C:\Documents and Settings\HP_Owner\My Documents\pos1334.tmp
C:\Documents and Settings\HP_Owner\My Documents\pos1335.tmp
C:\Documents and Settings\HP_Owner\My Documents\pos1336.tmp
C:\Documents and Settings\HP_Owner\My Documents\pos1337.tmp
C:\Documents and Settings\HP_Owner\My Documents\pos1338.tmp
C:\Documents and Settings\HP_Owner\My Documents\pos1339.tmp
C:\Documents and Settings\HP_Owner\My Documents\pos133A.tmp
C:\Documents and Settings\HP_Owner\My Documents\pos133B.tmp
C:\Documents and Settings\HP_Owner\My Documents\pos133C.tmp
C:\Documents and Settings\HP_Owner\My Documents\pos133D.tmp
C:\Documents and Settings\HP_Owner\My Documents\pos133E.tmp
C:\Documents and Settings\HP_Owner\My Documents\pos133F.tmp
C:\Documents and Settings\HP_Owner\My Documents\pos1340.tmp
C:\Documents and Settings\HP_Owner\My Documents\pos1341.tmp
C:\Documents and Settings\HP_Owner\My Documents\pos1342.tmp
C:\Documents and Settings\HP_Owner\My Documents\pos1343.tmp
C:\Documents and Settings\HP_Owner\My Documents\pos1344.tmp
C:\Documents and Settings\HP_Owner\My Documents\pos1345.tmp
C:\Documents and Settings\HP_Owner\My Documents\pos1346.tmp
C:\Documents and Settings\HP_Owner\My Documents\pos1347.tmp
C:\Documents and Settings\HP_Owner\My Documents\pos1348.tmp
C:\Documents and Settings\HP_Owner\My Documents\pos1349.tmp
C:\Documents and Settings\HP_Owner\My Documents\pos134A.tmp
C:\Documents and Settings\HP_Owner\My Documents\pos134B.tmp
C:\Documents and Settings\HP_Owner\My Documents\pos134C.tmp
C:\Documents and Settings\HP_Owner\My Documents\pos134D.tmp
C:\Documents and Settings\HP_Owner\My Documents\pos134E.tmp
C:\Documents and Settings\HP_Owner\My Documents\pos134F.tmp
C:\Documents and Settings\HP_Owner\My Documents\pos1350.tmp
C:\Documents and Settings\HP_Owner\My Documents\pos1351.tmp
C:\Documents and Settings\HP_Owner\My Documents\pos1352.tmp
C:\Documents and Settings\HP_Owner\My Documents\pos1353.tmp
C:\Documents and Settings\HP_Owner\My Documents\pos1354.tmp
C:\Documents and Settings\HP_Owner\My Documents\pos1355.tmp
C:\Documents and Settings\HP_Owner\My Documents\pos1356.tmp
C:\Documents and Settings\HP_Owner\My Documents\pos1357.tmp
C:\Documents and Settings\HP_Owner\My Documents\pos1358.tmp
C:\Documents and Settings\HP_Owner\My Documents\pos1359.tmp
C:\Documents and Settings\HP_Owner\My Documents\pos135A.tmp
C:\Documents and Settings\HP_Owner\My Documents\pos135B.tmp
C:\Documents and Settings\HP_Owner\My Documents\pos135C.tmp
C:\Documents and Settings\HP_Owner\My Documents\pos135D.tmp
C:\Documents and Settings\HP_Owner\My Documents\pos135E.tmp
C:\Documents and Settings\HP_Owner\My Documents\pos135F.tmp
C:\Documents and Settings\HP_Owner\My Documents\pos1360.tmp
C:\Documents and Settings\HP_Owner\My Documents\pos1361.tmp
C:\Documents and Settings\HP_Owner\My Documents\pos1362.tmp
C:\Documents and Settings\HP_Owner\My Documents\pos1363.tmp
C:\Documents and Settings\HP_Owner\My Documents\pos1364.tmp
C:\Documents and Settings\HP_Owner\My Documents\pos1365.tmp
C:\Documents and Settings\HP_Owner\My Documents\pos1366.tmp
C:\Documents and Settings\HP_Owner\My Documents\pos1367.tmp
C:\Documents and Settings\HP_Owner\My Documents\pos1368.tmp
C:\Documents and Settings\HP_Owner\My Documents\pos1369.tmp
C:\Documents and Settings\HP_Owner\My Documents\pos136A.tmp
C:\Documents and Settings\HP_Owner\My Documents\pos136B.tmp
C:\Documents and Settings\HP_Owner\My Documents\pos136C.tmp
C:\Documents and Settings\HP_Owner\My Documents\pos136D.tmp
C:\Documents and Settings\HP_Owner\My Documents\pos136E.tmp
C:\Documents and Settings\HP_Owner\My Documents\pos136F.tmp
C:\Documents and Settings\HP_Owner\My Documents\pos1370.tmp
C:\Documents and Settings\HP_Owner\My Documents\pos1371.tmp
C:\Documents and Settings\HP_Owner\My Documents\pos1372.tmp
C:\Documents and Settings\HP_Owner\My Documents\pos1373.tmp
C:\Documents and Settings\HP_Owner\My Documents\pos1374.tmp
C:\Documents and Settings\HP_Owner\My Documents\pos1375.tmp
C:\Documents and Settings\HP_Owner\My Documents\pos1376.tmp
C:\Documents and Settings\HP_Owner\My Documents\pos1377.tmp
C:\Documents and Settings\HP_Owner\My Documents\pos1378.tmp
C:\Documents and Settings\HP_Owner\My Documents\pos1379.tmp
C:\Documents and Settings\HP_Owner\My Documents\pos137A.tmp
C:\Documents and Settings\HP_Owner\My Documents\pos137B.tmp
C:\Documents and Settings\HP_Owner\My Documents\pos137C.tmp
C:\Documents and Settings\HP_Owner\My Documents\pos137D.tmp
C:\Documents and Settings\HP_Owner\My Documents\pos137E.tmp
C:\Documents and Settings\HP_Owner\My Documents\pos137F.tmp
C:\Documents and Settings\HP_Owner\My Documents\pos1380.tmp
C:\Documents and Settings\HP_Owner\My Documents\pos1381.tmp
C:\Documents and Settings\HP_Owner\My Documents\pos1382.tmp
C:\Documents and Settings\HP_Owner\My Documents\pos1383.tmp
C:\Documents and Settings\HP_Owner\My Documents\pos1384.tmp
C:\Documents and Settings\HP_Owner\My Documents\pos1385.tmp
C:\Documents and Settings\HP_Owner\My Documents\pos1386.tmp
C:\Documents and Settings\HP_Owner\My Documents\pos1387.tmp
C:\Documents and Settings\HP_Owner\My Documents\pos1388.tmp
C:\Documents and Settings\HP_Owner\My Documents\pos1389.tmp
C:\Documents and Settings\HP_Owner\My Documents\pos138A.tmp
C:\Documents and Settings\HP_Owner\My Documents\pos138B.tmp
C:\Documents and Settings\HP_Owner\My Documents\pos138C.tmp
C:\Documents and Settings\HP_Owner\My Documents\pos138D.tmp
C:\Documents and Settings\HP_Owner\My Documents\pos138E.tmp
C:\Documents and Settings\HP_Owner\My Documents\pos138F.tmp
C:\Documents and Settings\HP_Owner\My Documents\pos1390.tmp
C:\Documents and Settings\HP_Owner\My Documents\pos1391.tmp
C:\Documents and Settings\HP_Owner\My Documents\pos1392.tmp
C:\Documents and Settings\HP_Owner\My Documents\pos1393.tmp
C:\Documents and Settings\HP_Owner\My Documents\pos1394.tmp
C:\Documents and Settings\HP_Owner\My Documents\pos1395.tmp
C:\Documents and Settings\HP_Owner\My Documents\pos1396.tmp
C:\Documents and Settings\HP_Owner\My Documents\pos1397.tmp
C:\Documents and Settings\HP_Owner\My Documents\pos1398.tmp
C:\Documents and Settings\HP_Owner\My Documents\pos1399.tmp
C:\Documents and Settings\HP_Owner\My Documents\pos139A.tmp
C:\Documents and Settings\HP_Owner\My Documents\pos139B.tmp
C:\Documents and Settings\HP_Owner\My Documents\pos139C.tmp
C:\Documents and Settings\HP_Owner\My Documents\pos139D.tmp
C:\Documents and Settings\HP_Owner\My Documents\pos139E.tmp
C:\Documents and Settings\HP_Owner\My Documents\pos139F.tmp
C:\Documents and Settings\HP_Owner\My Documents\pos13A0.tmp
C:\Documents and Settings\HP_Owner\My Documents\pos13A1.tmp
C:\Documents and Settings\HP_Owner\My Documents\pos13A2.tmp
C:\Documents and Settings\HP_Owner\My Documents\pos13A3.tmp
C:\Documents and Settings\HP_Owner\My Documents\pos13A4.tmp
C:\Documents and Settings\HP_Owner\My Documents\pos13A5.tmp
C:\Documents and Settings\HP_Owner\My Documents\pos13A6.tmp
C:\Documents and Settings\HP_Owner\My Documents\pos13A7.tmp
C:\Documents and Settings\HP_Owner\My Documents\pos13A8.tmp
C:\Documents and Settings\HP_Owner\My Documents\pos13A9.tmp
C:\Documents and Settings\HP_Owner\My Documents\pos13AA.tmp
C:\Documents and Settings\HP_Owner\My Documents\pos13AB.tmp
C:\Documents and Settings\HP_Owner\My Documents\pos13AC.tmp
C:\Documents and Settings\HP_Owner\My Documents\pos13AD.tmp
C:\Documents and Settings\HP_Owner\My Documents\pos13AE.tmp
C:\Documents and Settings\HP_Owner\My Documents\pos13AF.tmp
C:\Documents and Settings\HP_Owner\My Documents\pos13B0.tmp
C:\Documents and Settings\HP_Owner\My Documents\pos13B1.tmp
C:\Documents and Settings\HP_Owner\My Documents\pos13B2.tmp
C:\Documents and Settings\HP_Owner\My Documents\pos13B3.tmp
C:\Documents and Settings\HP_Owner\My Documents\pos13B4.tmp
C:\Documents and Settings\HP_Owner\My Documents\pos13B5.tmp
C:\Documents and Settings\HP_Owner\My Documents\pos13B6.tmp
C:\Documents and Settings\HP_Owner\My Documents\pos13B7.tmp
C:\Documents and Settings\HP_Owner\My Documents\pos13B8.tmp
C:\Documents and Settings\HP_Owner\My Documents\pos13B9.tmp
C:\Documents and Settings\HP_Owner\My Documents\pos13BA.tmp
C:\Documents and Settings\HP_Owner\My Documents\pos13BB.tmp
C:\Documents and Settings\HP_Owner\My Documents\pos13BC.tmp
C:\Documents and Settings\HP_Owner\My Documents\pos13BD.tmp
C:\Documents and Settings\HP_Owner\My Documents\pos13BE.tmp
C:\Documents and Settings\HP_Owner\My Documents\pos13BF.tmp
C:\Documents and Settings\HP_Owner\My Documents\pos13C0.tmp
C:\Documents and Settings\HP_Owner\My Documents\pos13C1.tmp
C:\Documents and Settings\HP_Owner\My Documents\pos13C2.tmp
C:\Documents and Settings\HP_Owner\My Documents\pos13C3.tmp
C:\Documents and Settings\HP_Owner\My Documents\pos13C4.tmp
C:\Documents and Settings\HP_Owner\My Documents\pos13C5.tmp
C:\Documents and Settings\HP_Owner\My Documents\pos13C6.tmp
C:\Documents and Settings\HP_Owner\My Documents\pos13C7.tmp
C:\Documents and Settings\HP_Owner\My Documents\pos13C8.tmp
C:\Documents and Settings\HP_Owner\My Documents\pos13C9.tmp
C:\Documents and Settings\HP_Owner\My Documents\pos13CA.tmp
C:\Documents and Settings\HP_Owner\My Documents\pos13CB.tmp
C:\Documents and Settings\HP_Owner\My Documents\pos13CC.tmp
C:\Documents and Settings\HP_Owner\My Documents\pos13CD.tmp
C:\Documents and Settings\HP_Owner\My Documents\pos13CE.tmp
C:\Documents and Settings\HP_Owner\My Documents\pos13CF.tmp
C:\Documents and Settings\HP_Owner\My Documents\pos13D0.tmp
C:\Documents and Settings\HP_Owner\My Documents\pos13D1.tmp
C:\Documents and Settings\HP_Owner\My Documents\pos13D2.tmp
C:\Documents and Settings\HP_Owner\My Documents\pos13D3.tmp
C:\Documents and Settings\HP_Owner\My Documents\pos13D4.tmp
C:\Documents and Settings\HP_Owner\My Documents\pos13D5.tmp
C:\Documents and Settings\HP_Owner\My Documents\pos13D6.tmp
C:\Documents and Settings\HP_Owner\My Documents\pos13D7.tmp
C:\Documents and Settings\HP_Owner\My Documents\pos13D8.tmp
C:\Documents and Settings\HP_Owner\My Documents\pos13D9.tmp
C:\Documents and Settings\HP_Owner\My Documents\pos13DA.tmp
C:\Documents and Settings\HP_Owner\My Documents\pos13DB.tmp
C:\Documents and Settings\HP_Owner\My Documents\pos13DC.tmp
C:\Documents and Settings\HP_Owner\My Documents\pos13DD.tmp
C:\Documents and Settings\HP_Owner\My Documents\pos13DE.tmp
C:\Documents and Settings\HP_Owner\My Documents\pos13DF.tmp
C:\Documents and Settings\HP_Owner\My Documents\pos13E0.tmp
C:\Documents and Settings\HP_Owner\My Documents\pos13E1.tmp
C:\Documents and Settings\HP_Owner\My Documents\pos13E2.tmp
C:\Documents and Settings\HP_Owner\My Documents\pos13E3.tmp
C:\Documents and Settings\HP_Owner\My Documents\pos13E4.tmp
C:\Documents and Settings\HP_Owner\My Documents\pos13E5.tmp
C:\Documents and Settings\HP_Owner\My Documents\pos13E6.tmp
C:\Documents and Settings\HP_Owner\My Documents\pos13E7.tmp
C:\Documents and Settings\HP_Owner\My Documents\pos13E8.tmp
C:\Documents and Settings\HP_Owner\My Documents\pos13E9.tmp
C:\Documents and Settings\HP_Owner\My Documents\pos13EA.tmp
C:\Documents and Settings\HP_Owner\My Documents\pos13EB.tmp
C:\Documents and Settings\HP_Owner\My Documents\pos13EC.tmp
C:\Documents and Settings\HP_Owner\My Documents\pos13ED.tmp
C:\Documents and Settings\HP_Owner\My Documents\pos13EE.tmp
C:\Documents and Settings\HP_Owner\My Documents\pos13EF.tmp
C:\Documents and Settings\HP_Owner\My Documents\pos13F0.tmp
C:\Documents and Settings\HP_Owner\My Documents\pos13F1.tmp
C:\Documents and Settings\HP_Owner\My Documents\pos13F2.tmp
C:\Documents and Settings\HP_Owner\My Documents\pos13F3.tmp
C:\Documents and Settings\HP_Owner\My Documents\pos13F4.tmp
C:\Documents and Settings\HP_Owner\My Documents\pos13F5.tmp
C:\Documents and Settings\HP_Owner\My Documents\pos13F6.tmp
C:\Documents and Settings\HP_Owner\My Documents\pos13F7.tmp
C:\Documents and Settings\HP_Owner\My Documents\pos13F8.tmp
C:\Documents and Settings\HP_Owner\My Documents\pos13F9.tmp
C:\Documents and Settings\HP_Owner\My Documents\pos13FA.tmp
C:\Documents and Settings\HP_Owner\My Documents\pos13FB.tmp
C:\Documents and Settings\HP_Owner\My Documents\pos13FC.tmp
C:\Documents and Settings\HP_Owner\My Documents\pos13FD.tmp
C:\Documents and Settings\HP_Owner\My Documents\pos13FE.tmp
C:\Documents and Settings\HP_Owner\My Documents\pos13FF.tmp
C:\Documents and Settings\HP_Owner\My Documents\pos1400.tmp
C:\Documents and Settings\HP_Owner\My Documents\pos1401.tmp
C:\Documents and Settings\HP_Owner\My Documents\pos1402.tmp
C:\Documents and Settings\HP_Owner\My Documents\pos1403.tmp
C:\Documents and Settings\HP_Owner\My Documents\pos1404.tmp
C:\Documents and Settings\HP_Owner\My Documents\pos1405.tmp
C:\Documents and Settings\HP_Owner\My Documents\pos1406.tmp
C:\Documents and Settings\HP_Owner\My Documents\pos1407.tmp
C:\Documents and Settings\HP_Owner\My Documents\pos1408.tmp
C:\Documents and Settings\HP_Owner\My Documents\pos1409.tmp
C:\Documents and Settings\HP_Owner\My Documents\pos140A.tmp
C:\Documents and Settings\HP_Owner\My Documents\pos140B.tmp
C:\Documents and Settings\HP_Owner\My Documents\pos140C.tmp
C:\Documents and Settings\HP_Owner\My Documents\pos140D.tmp
C:\Documents and Settings\HP_Owner\My Documents\pos140E.tmp
C:\Documents and Settings\HP_Owner\My Documents\pos140F.tmp
C:\Documents and Settings\HP_Owner\My Documents\pos1410.tmp
C:\Documents and Settings\HP_Owner\My Documents\pos1411.tmp
C:\Documents and Settings\HP_Owner\My Documents\pos1412.tmp
C:\Documents and Settings\HP_Owner\My Documents\pos1413.tmp
C:\Documents and Settings\HP_Owner\My Documents\pos1414.tmp
C:\Documents and Settings\HP_Owner\My Documents\pos1415.tmp
C:\Documents and Settings\HP_Owner\My Documents\pos1416.tmp
C:\Documents and Settings\HP_Owner\My Documents\pos1417.tmp
C:\Documents and Settings\HP_Owner\My Documents\pos1418.tmp
C:\Documents and Settings\HP_Owner\My Documents\pos1419.tmp
C:\Documents and Settings\HP_Owner\My Documents\pos141A.tmp
C:\Documents and Settings\HP_Owner\My Documents\pos141B.tmp
C:\Documents and Settings\HP_Owner\My Documents\pos141C.tmp
C:\Documents and Settings\HP_Owner\My Documents\pos141D.tmp
C:\Documents and Settings\HP_Owner\My Documents\pos141E.tmp
C:\Documents and Settings\HP_Owner\My Documents\pos141F.tmp
C:\Documents and Settings\HP_Owner\My Documents\pos1420.tmp
C:\Documents and Settings\HP_Owner\My Documents\pos1421.tmp
C:\Documents and Settings\HP_Owner\My Documents\pos1422.tmp
C:\Documents and Settings\HP_Owner\My Documents\pos1423.tmp
C:\Documents and Settings\HP_Owner\My Documents\pos1424.tmp
C:\Documents and Settings\HP_Owner\My Documents\pos1425.tmp
C:\Documents and Settings\HP_Owner\My Documents\pos1426.tmp
C:\Documents and Settings\HP_Owner\My Documents\pos1427.tmp
C:\Documents and Settings\HP_Owner\My Documents\pos1428.tmp
C:\Documents and Settings\HP_Owner\My Documents\pos1429.tmp
C:\Documents and Settings\HP_Owner\My Documents\pos142A.tmp
C:\Documents and Settings\HP_Owner\My Documents\pos142B.tmp
C:\Documents and Settings\HP_Owner\My Documents\pos142C.tmp
C:\Documents and Settings\HP_Owner\My Documents\pos142D.tmp
C:\Documents and Settings\HP_Owner\My Documents\pos142E.tmp
C:\Documents and Settings\HP_Owner\My Documents\pos142F.tmp
C:\Documents and Settings\HP_Owner\My Documents\pos1430.tmp
C:\Documents and Settings\HP_Owner\My Documents\pos1431.tmp
C:\Documents and Settings\HP_Owner\My Documents\pos1432.tmp
C:\Documents and Settings\HP_Owner\My Documents\pos1433.tmp
C:\Documents and Settings\HP_Owner\My Documents\pos1434.tmp
C:\Documents and Settings\HP_Owner\My Documents\pos1435.tmp
C:\Documents and Settings\HP_Owner\My Documents\pos1436.tmp
C:\Documents and Settings\HP_Owner\My Documents\pos1437.tmp
C:\Documents and Settings\HP_Owner\My Documents\pos1438.tmp
C:\Documents and Settings\HP_Owner\My Documents\pos1439.tmp
C:\Documents and Settings\HP_Owner\My Documents\pos143A.tmp
C:\Documents and Settings\HP_Owner\My Documents\pos143B.tmp
C:\Documents and Settings\HP_Owner\My Documents\pos143C.tmp
C:\Documents and Settings\HP_Owner\My Documents\pos143D.tmp
C:\Documents and Settings\HP_Owner\My Documents\pos143E.tmp
C:\Documents and Settings\HP_Owner\My Documents\pos143F.tmp
C:\Documents and Settings\HP_Owner\My Documents\pos1440.tmp
C:\Documents and Settings\HP_Owner\My Documents\pos1441.tmp
C:\Documents and Settings\HP_Owner\My Documents\pos1442.tmp
C:\Documents and Settings\HP_Owner\My Documents\pos1443.tmp
C:\Documents and Settings\HP_Owner\My Documents\pos1444.tmp
C:\Documents and Settings\HP_Owner\My Documents\pos1445.tmp
C:\Documents and Settings\HP_Owner\My Documents\pos1446.tmp
C:\Documents and Settings\HP_Owner\My Documents\pos1447.tmp
C:\Documents and Settings\HP_Owner\My Documents\pos1448.tmp
C:\Documents and Settings\HP_Owner\My Documents\pos1449.tmp
C:\Documents and Settings\HP_Owner\My Documents\pos144A.tmp
C:\Documents and Settings\HP_Owner\My Documents\pos144B.tmp
C:\Documents and Settings\HP_Owner\My Documents\pos144C.tmp
C:\Documents and Settings\HP_Owner\My Documents\pos144D.tmp
C:\Documents and Settings\HP_Owner\My Documents\pos144E.tmp
C:\Documents and Settings\HP_Owner\My Documents\pos144F.tmp
C:\Documents and Settings\HP_Owner\My Documents\pos1450.tmp
C:\Documents and Settings\HP_Owner\My Documents\pos1451.tmp
C:\Documents and Settings\HP_Owner\My Documents\pos1452.tmp
C:\Documents and Settings\HP_Owner\My Documents\pos1453.tmp
C:\Documents and Settings\HP_Owner\My Documents\pos1454.tmp
C:\Documents and Settings\HP_Owner\My Documents\pos1455.tmp
C:\Documents and Settings\HP_Owner\My Documents\pos1456.tmp
C:\Documents and Settings\HP_Owner\My Documents\pos1457.tmp
C:\Documents and Settings\HP_Owner\My Documents\pos1458.tmp
C:\Documents and Settings\HP_Owner\My Documents\pos1459.tmp
C:\Documents and Settings\HP_Owner\My Documents\pos145A.tmp
C:\Documents and Settings\HP_Owner\My Documents\pos145B.tmp
C:\Documents and Settings\HP_Owner\My Documents\pos145C.tmp
C:\Documents and Settings\HP_Owner\My Documents\pos145D.tmp
C:\Documents and Settings\HP_Owner\My Documents\pos145E.tmp
C:\Documents and Settings\HP_Owner\My Documents\pos145F.tmp
C:\Documents and Settings\HP_Owner\My Documents\pos1460.tmp
C:\Documents and Settings\HP_Owner\My Documents\pos1461.tmp
C:\Documents and Settings\HP_Owner\My Documents\pos1462.tmp
C:\Documents and Settings\HP_Owner\My Documents\pos1463.tmp
C:\Documents and Settings\HP_Owner\My Documents\pos1464.tmp
C:\Documents and Settings\HP_Owner\My Documents\pos1465.tmp
C:\Documents and Settings\HP_Owner\My Documents\pos1466.tmp
C:\Documents and Settings\HP_Owner\My Documents\pos1467.tmp
C:\Documents and Settings\HP_Owner\My Documents\pos1468.tmp
C:\Documents and Settings\HP_Owner\My Documents\pos1469.tmp
C:\Documents and Settings\HP_Owner\My Documents\pos146A.tmp
C:\Documents and Settings\HP_Owner\My Documents\pos146B.tmp
C:\Documents and Settings\HP_Owner\My Documents\pos146C.tmp
C:\Documents and Settings\HP_Owner\My Documents\pos146D.tmp
C:\Documents and Settings\HP_Owner\My Documents\pos146E.tmp
C:\Documents and Settings\HP_Owner\My Documents\pos146F.tmp
C:\Documents and Settings\HP_Owner\My Documents\pos1470.tmp
C:\Documents and Settings\HP_Owner\My Documents\pos1471.tmp
C:\Documents and Settings\HP_Owner\My Documents\pos1472.tmp
C:\Documents and Settings\HP_Owner\My Documents\pos1473.tmp
C:\Documents and Settings\HP_Owner\My Documents\pos1474.tmp
C:\Documents and Settings\HP_Owner\My Documents\pos1475.tmp
C:\Documents and Settings\HP_Owner\My Documents\pos1476.tmp
C:\Documents and Settings\HP_Owner\My Documents\pos1477.tmp
C:\Documents and Settings\HP_Owner\My Documents\pos1478.tmp
C:\Documents and Settings\HP_Owner\My Documents\pos1479.tmp
C:\Documents and Settings\HP_Owner\My Documents\pos147A.tmp
C:\Documents and Settings\HP_Owner\My Documents\pos147B.tmp
C:\Documents and Settings\HP_Owner\My Documents\pos147C.tmp
C:\Documents and Settings\HP_Owner\My Documents\pos147D.tmp
C:\Documents and Settings\HP_Owner\My Documents\pos147E.tmp
C:\Documents and Settings\HP_Owner\My Documents\pos147F.tmp
C:\Documents and Settings\HP_Owner\My Documents\pos1480.tmp
C:\Documents and Settings\HP_Owner\My Documents\pos1481.tmp
C:\Documents and Settings\HP_Owner\My Documents\pos1482.tmp
C:\Documents and Settings\HP_Owner\My Documents\pos1483.tmp
C:\Documents and Settings\HP_Owner\My Documents\pos1484.tmp
C:\Documents and Settings\HP_Owner\My Documents\pos1485.tmp
C:\Documents and Settings\HP_Owner\My Documents\pos1486.tmp
C:\Documents and Settings\HP_Owner\My Documents\pos1487.tmp
C:\Documents and Settings\HP_Owner\My Documents\pos1488.tmp
C:\Documents and Settings\HP_Owner\My Documents\pos1489.tmp
C:\Documents and Settings\HP_Owner\My Documents\pos148A.tmp
C:\Documents and Settings\HP_Owner\My Documents\pos148B.tmp
C:\Documents and Settings\HP_Owner\My Documents\pos148C.tmp
C:\Documents and Settings\HP_Owner\My Documents\pos148D.tmp
C:\Documents and Settings\HP_Owner\My Documents\pos148E.tmp
C:\Documents and Settings\HP_Owner\My Documents\pos148F.tmp
C:\Documents and Settings\HP_Owner\My Documents\pos1490.tmp
C:\Documents and Settings\HP_Owner\My Documents\pos1491.tmp
C:\Documents and Settings\HP_Owner\My Documents\pos1492.tmp
C:\Documents and Settings\HP_Owner\My Documents\pos1493.tmp
C:\Documents and Settings\HP_Owner\My Documents\pos1494.tmp
C:\Documents and Settings\HP_Owner\My Documents\pos1495.tmp
C:\Documents and Settings\HP_Owner\My Documents\pos1496.tmp
C:\Documents and Settings\HP_Owner\My Documents\pos1497.tmp
C:\Documents and Settings\HP_Owner\My Documents\pos1498.tmp
C:\Documents and Settings\HP_Owner\My Documents\pos1499.tmp
C:\Documents and Settings\HP_Owner\My Documents\pos149A.tmp
C:\Documents and Settings\HP_Owner\My Documents\pos149B.tmp
C:\Documents and Settings\HP_Owner\My Documents\pos149C.tmp
C:\Documents and Settings\HP_Owner\My Documents\pos149D.tmp
C:\Documents and Settings\HP_Owner\My Documents\pos149E.tmp
C:\Documents and Settings\HP_Owner\My Documents\pos149F.tmp
C:\Documents and Settings\HP_Owner\My Documents\pos14A0.tmp
C:\Documents and Settings\HP_Owner\My Documents\pos14A1.tmp
C:\Documents and Settings\HP_Owner\My Documents\pos14A2.tmp
C:\Documents and Settings\HP_Owner\My Documents\pos14A3.tmp
C:\Documents and Settings\HP_Owner\My Documents\pos14A4.tmp
C:\Documents and Settings\HP_Owner\My Documents\pos14A5.tmp
C:\Documents and Settings\HP_Owner\My Documents\pos14A6.tmp
C:\Documents and Settings\HP_Owner\My Documents\pos14A7.tmp
C:\Documents and Settings\HP_Owner\My Documents\pos14A8.tmp
C:\Documents and Settings\HP_Owner\My Documents\pos14A9.tmp
C:\Documents and Settings\HP_Owner\My Documents\pos14AA.tmp
C:\Documents and Settings\HP_Owner\My Documents\pos14AB.tmp
C:\Documents and Settings\HP_Owner\My Documents\pos14AC.tmp
C:\Documents and Settings\HP_Owner\My Documents\pos14AD.tmp
C:\Documents and Settings\HP_Owner\My Documents\pos14AE.tmp
C:\Documents and Settings\HP_Owner\My Documents\pos14AF.tmp
C:\Documents and Settings\HP_Owner\My Documents\pos14B0.tmp
C:\Documents and Settings\HP_Owner\My Documents\pos14B1.tmp
C:\Documents and Settings\HP_Owner\My Documents\pos14B2.tmp
C:\Documents and Settings\HP_Owner\My Documents\pos14B3.tmp
C:\Documents and Settings\HP_Owner\My Documents\pos14B4.tmp
C:\Documents and Settings\HP_Owner\My Documents\pos14B5.tmp
C:\Documents and Settings\HP_Owner\My Documents\pos14B6.tmp
C:\Documents and Settings\HP_Owner\My Documents\pos14B7.tmp
C:\Documents and Settings\HP_Owner\My Documents\pos14B8.tmp
C:\Documents and Settings\HP_Owner\My Documents\pos14B9.tmp
C:\Documents and Settings\HP_Owner\My Documents\pos14BA.tmp
C:\Documents and Settings\HP_Owner\My Documents\pos14BB.tmp
C:\Documents and Settings\HP_Owner\My Documents\pos14BC.tmp
C:\Documents and Settings\HP_Owner\My Documents\pos14BD.tmp
C:\Documents and Settings\HP_Owner\My Documents\pos14BE.tmp
C:\Documents and Settings\HP_Owner\My Documents\pos14BF.tmp
C:\Documents and Settings\HP_Owner\My Documents\pos14C0.tmp
C:\Documents and Settings\HP_Owner\My Documents\pos14C1.tmp
C:\Documents and Settings\HP_Owner\My Documents\pos14C2.tmp
C:\Documents and Settings\HP_Owner\My Documents\pos14C3.tmp
C:\Documents and Settings\HP_Owner\My Documents\pos14C4.tmp
C:\Documents and Settings\HP_Owner\My Documents\pos14C5.tmp
C:\Documents and Settings\HP_Owner\My Documents\pos14C6.tmp
C:\Documents and Settings\HP_Owner\My Documents\pos14C7.tmp
C:\Documents and Settings\HP_Owner\My Documents\pos14C8.tmp
C:\Documents and Settings\HP_Owner\My Documents\pos14C9.tmp
C:\Documents and Settings\HP_Owner\My Documents\pos14CA.tmp
C:\Documents and Settings\HP_Owner\My Documents\pos14CB.tmp
C:\Documents and Settings\HP_Owner\My Documents\pos14CC.tmp
C:\Documents and Settings\HP_Owner\My Documents\pos14CD.tmp
C:\Documents and Settings\HP_Owner\My Documents\pos14CE.tmp
C:\Documents and Settings\HP_Owner\My Documents\pos14CF.tmp
C:\Documents and Settings\HP_Owner\My Documents\pos14D0.tmp
C:\Documents and Settings\HP_Owner\My Documents\pos14D1.tmp
C:\Documents and Settings\HP_Owner\My Documents\pos14D2.tmp
C:\Documents and Settings\HP_Owner\My Documents\pos14D3.tmp
C:\Documents and Settings\HP_Owner\My Documents\pos14D4.tmp
C:\Documents and Settings\HP_Owner\My Documents\pos14D5.tmp
C:\Documents and Settings\HP_Owner\My Documents\pos14D6.tmp
C:\Documents and Settings\HP_Owner\My Documents\pos14D7.tmp
C:\Documents and Settings\HP_Owner\My Documents\pos14D8.tmp
C:\Documents and Settings\HP_Owner\My Documents\pos14D9.tmp
C:\Documents and Settings\HP_Owner\My Documents\pos14DA.tmp
C:\Documents and Settings\HP_Owner\My Documents\pos14DB.tmp
C:\Documents and Settings\HP_Owner\My Documents\pos14DC.tmp
C:\Documents and Settings\HP_Owner\My Documents\pos14DD.tmp
C:\Documents and Settings\HP_Owner\My Documents\pos14DE.tmp
C:\Documents and Settings\HP_Owner\My Documents\pos14DF.tmp
C:\Documents and Settings\HP_Owner\My Documents\pos14E0.tmp
C:\Documents and Settings\HP_Owner\My Documents\pos14E1.tmp
C:\Documents and Settings\HP_Owner\My Documents\pos14E2.tmp
C:\Documents and Settings\HP_Owner\My Documents\pos14E3.tmp
C:\Documents and Settings\HP_Owner\My Documents\pos14E4.tmp
C:\Documents and Settings\HP_Owner\My Documents\pos14E5.tmp
C:\Documents and Settings\HP_Owner\My Documents\pos14E6.tmp
C:\Documents and Settings\HP_Owner\My Documents\pos14E7.tmp
C:\Documents and Settings\HP_Owner\My Documents\pos14E8.tmp
C:\Documents and Settings\HP_Owner\My Documents\pos14E9.tmp
C:\Documents and Settings\HP_Owner\My Documents\pos14EA.tmp
C:\Documents and Settings\HP_Owner\My Documents\pos14EB.tmp
C:\Documents and Settings\HP_Owner\My Documents\pos14EC.tmp
C:\Documents and Settings\HP_Owner\My Documents\pos14ED.tmp
C:\Documents and Settings\HP_Owner\My Documents\pos14EE.tmp
C:\Documents and Settings\HP_Owner\My Documents\pos14EF.tmp
C:\Documents and Settings\HP_Owner\My Documents\pos14F0.tmp
C:\Documents and Settings\HP_Owner\My Documents\pos14F1.tmp
C:\Documents and Settings\HP_Owner\My Documents\pos14F2.tmp
C:\Documents and Settings\HP_Owner\My Documents\pos14F3.tmp
C:\Documents and Settings\HP_Owner\My Documents\pos14F4.tmp
C:\Documents and Settings\HP_Owner\My Documents\pos14F5.tmp
C:\Documents and Settings\HP_Owner\My Documents\pos14F6.tmp
C:\Documents and Settings\HP_Owner\My Documents\pos14F7.tmp
C:\Documents and Settings\HP_Owner\My Documents\pos14F8.tmp
C:\Documents and Settings\HP_Owner\My Documents\pos14F9.tmp
C:\Documents and Settings\HP_Owner\My Documents\pos14FA.tmp
C:\Documents and Settings\HP_Owner\My Documents\pos14FB.tmp
C:\Documents and Settings\HP_Owner\My Documents\pos14FC.tmp
C:\Documents and Settings\HP_Owner\My Documents\pos14FD.tmp
C:\Documents and Settings\HP_Owner\My Documents\pos14FE.tmp
C:\Documents and Settings\HP_Owner\My Documents\pos14FF.tmp
C:\Documents and Settings\HP_Owner\My Documents\pos1500.tmp
C:\Documents and Settings\HP_Owner\My Documents\pos1501.tmp
C:\Documents and Settings\HP_Owner\My Documents\pos1502.tmp
C:\Documents and Settings\HP_Owner\My Documents\pos1503.tmp
C:\Documents and Settings\HP_Owner\My Documents\pos1504.tmp
C:\Documents and Settings\HP_Owner\My Documents\pos1505.tmp
C:\Documents and Settings\HP_Owner\My Documents\pos1506.tmp
C:\Documents and Settings\HP_Owner\My Documents\pos1507.tmp
C:\Documents and Settings\HP_Owner\My Documents\pos1508.tmp
C:\Documents and Settings\HP_Owner\My Documents\pos1509.tmp
C:\Documents and Settings\HP_Owner\My Documents\pos150A.tmp
C:\Documents and Settings\HP_Owner\My Documents\pos150B.tmp
C:\Documents and Settings\HP_Owner\My Documents\pos150C.tmp
C:\Documents and Settings\HP_Owner\My Documents\pos150D.tmp
C:\Documents and Settings\HP_Owner\My Documents\pos150E.tmp
C:\Documents and Settings\HP_Owner\My Documents\pos150F.tmp
C:\Documents and Settings\HP_Owner\My Documents\pos1510.tmp
C:\Documents and Settings\HP_Owner\My Documents\pos1511.tmp
C:\Documents and Settings\HP_Owner\My Documents\pos1512.tmp
C:\Documents and Settings\HP_Owner\My Documents\pos1513.tmp
C:\Documents and Settings\HP_Owner\My Documents\pos1514.tmp
C:\Documents and Settings\HP_Owner\My Documents\pos1515.tmp
C:\Documents and Settings\HP_Owner\My Documents\pos1516.tmp
C:\Documents and Settings\HP_Owner\My Documents\pos1517.tmp
C:\Documents and Settings\HP_Owner\My Documents\pos1518.tmp
C:\Documents and Settings\HP_Owner\My Documents\pos1519.tmp
C:\Documents and Settings\HP_Owner\My Documents\pos151A.tmp
C:\Documents and Settings\HP_Owner\My Documents\pos151B.tmp
C:\Documents and Settings\HP_Owner\My Documents\pos151C.tmp
C:\Documents and Settings\HP_Owner\My Documents\pos151D.tmp
C:\Documents and Settings\HP_Owner\My Documents\pos151E.tmp
C:\Documents and Settings\HP_Owner\My Documents\pos151F.tmp
C:\Documents and Settings\HP_Owner\My Documents\pos1520.tmp
C:\Documents and Settings\HP_Owner\My Documents\pos1521.tmp
C:\Documents and Settings\HP_Owner\My Documents\pos1522.tmp
C:\Documents and Settings\HP_Owner\My Documents\pos1523.tmp
C:\Documents and Settings\HP_Owner\My Documents\pos1524.tmp
C:\Documents and Settings\HP_Owner\My Documents\pos1525.tmp
C:\Documents and Settings\HP_Owner\My Documents\pos1526.tmp
C:\Documents and Settings\HP_Owner\My Documents\pos1527.tmp
C:\Documents and Settings\HP_Owner\My Documents\pos1528.tmp
C:\Documents and Settings\HP_Owner\My Documents\pos1529.tmp
C:\Documents and Settings\HP_Owner\My Documents\pos152A.tmp
C:\Documents and Settings\HP_Owner\My Documents\pos152B.tmp
C:\Documents and Settings\HP_Owner\My Documents\pos152C.tmp
C:\Documents and Settings\HP_Owner\My Documents\pos152D.tmp
C:\Documents and Settings\HP_Owner\My Documents\pos152E.tmp
C:\Documents and Settings\HP_Owner\My Documents\pos152F.tmp
C:\Documents and Settings\HP_Owner\My Documents\pos1530.tmp
C:\Documents and Settings\HP_Owner\My Documents\pos1531.tmp
C:\Documents and Settings\HP_Owner\My Documents\pos1532.tmp
C:\Documents and Settings\HP_Owner\My Documents\pos1533.tmp
C:\Documents and Settings\HP_Owner\My Documents\pos1534.tmp
C:\Documents and Settings\HP_Owner\My Documents\pos1535.tmp
C:\Documents and Settings\HP_Owner\My Documents\pos1536.tmp
C:\Documents and Settings\HP_Owner\My Documents\pos1537.tmp
C:\Documents and Settings\HP_Owner\My Documents\pos1538.tmp
C:\Documents and Settings\HP_Owner\My Documents\pos1539.tmp
C:\Documents and Settings\HP_Owner\My Documents\pos153A.tmp
C:\Documents and Settings\HP_Owner\My Documents\pos153B.tmp
C:\Documents and Settings\HP_Owner\My Documents\pos153C.tmp
C:\Documents and Settings\HP_Owner\My Documents\pos153D.tmp
C:\Documents and Settings\HP_Owner\My Documents\pos153E.tmp
C:\Documents and Settings\HP_Owner\My Documents\pos153F.tmp
C:\Documents and Settings\HP_Owner\My Documents\pos1540.tmp
C:\Documents and Settings\HP_Owner\My Documents\pos1541.tmp
C:\Documents and Settings\HP_Owner\My Documents\pos1542.tmp
C:\Documents and Settings\HP_Owner\My Documents\pos1543.tmp
C:\Documents and Settings\HP_Owner\My Documents\pos1544.tmp
C:\Documents and Settings\HP_Owner\My Documents\pos1545.tmp
C:\Documents and Settings\HP_Owner\My Documents\pos1546.tmp
C:\Documents and Settings\HP_Owner\My Documents\pos1547.tmp
C:\Documents and Settings\HP_Owner\My Documents\pos1548.tmp
C:\Documents and Settings\HP_Owner\My Documents\pos1549.tmp
C:\Documents and Settings\HP_Owner\My Documents\pos154A.tmp
C:\Documents and Settings\HP_Owner\My Documents\pos154B.tmp
C:\Documents and Settings\HP_Owner\My Documents\pos154C.tmp
C:\Documents and Settings\HP_Owner\My Documents\pos154D.tmp
C:\Documents and Settings\HP_Owner\My Documents\pos154E.tmp
C:\Documents and Settings\HP_Owner\My Documents\pos154F.tmp
C:\Documents and Settings\HP_Owner\My Documents\pos1550.tmp
C:\Documents and Settings\HP_Owner\My Documents\pos1551.tmp
C:\Documents and Settings\HP_Owner\My Documents\pos1552.tmp
C:\Documents and Settings\HP_Owner\My Documents\pos1553.tmp
C:\Documents and Settings\HP_Owner\My Documents\pos1554.tmp
C:\Documents and Settings\HP_Owner\My Documents\pos1555.tmp
C:\Documents and Settings\HP_Owner\My Documents\pos1556.tmp
C:\Documents and Settings\HP_Owner\My Documents\pos1557.tmp
C:\Documents and Settings\HP_Owner\My Documents\pos1558.tmp
C:\Documents and Settings\HP_Owner\My Documents\pos1559.tmp
C:\Documents and Settings\HP_Owner\My Documents\pos155A.tmp
C:\Documents and Settings\HP_Owner\My Documents\pos155B.tmp
C:\Documents and Settings\HP_Owner\My Documents\pos155C.tmp
C:\Documents and Settings\HP_Owner\My Documents\pos155D.tmp
C:\Documents and Settings\HP_Owner\My Documents\pos155E.tmp
C:\Documents and Settings\HP_Owner\My Documents\pos155F.tmp
C:\Documents and Settings\HP_Owner\My Documents\pos1560.tmp
C:\Documents and Settings\HP_Owner\My Documents\pos1561.tmp
C:\Documents and Settings\HP_Owner\My Documents\pos1562.tmp
C:\Documents and Settings\HP_Owner\My Documents\pos1563.tmp
C:\Documents and Settings\HP_Owner\My Documents\pos1564.tmp
C:\Documents and Settings\HP_Owner\My Documents\pos1565.tmp
C:\Documents and Settings\HP_Owner\My Documents\pos1566.tmp
C:\Documents and Settings\HP_Owner\My Documents\pos1567.tmp
C:\Documents and Settings\HP_Owner\My Documents\pos1568.tmp
C:\Documents and Settings\HP_Owner\My Documents\pos1569.tmp
C:\Documents and Settings\HP_Owner\My Documents\pos156A.tmp
C:\Documents and Settings\HP_Owner\My Documents\pos156B.tmp
C:\Documents and Settings\HP_Owner\My Documents\pos156C.tmp
C:\Documents and Settings\HP_Owner\My Documents\pos156D.tmp
C:\Documents and Settings\HP_Owner\My Documents\pos156E.tmp
C:\Documents and Settings\HP_Owner\My Documents\pos156F.tmp
C:\Documents and Settings\HP_Owner\My Documents\pos1570.tmp
C:\Documents and Settings\HP_Owner\My Documents\pos1571.tmp
C:\Documents and Settings\HP_Owner\My Documents\pos1572.tmp
C:\Documents and Settings\HP_Owner\My Documents\pos1573.tmp
C:\Documents and Settings\HP_Owner\My Documents\pos1574.tmp
C:\Documents and Settings\HP_Owner\My Documents\pos1575.tmp
C:\Documents and Settings\HP_Owner\My Documents\pos1576.tmp
C:\Documents and Settings\HP_Owner\My Documents\pos1577.tmp
C:\Documents and Settings\HP_Owner\My Documents\pos1578.tmp
C:\Documents and Settings\HP_Owner\My Documents\pos1579.tmp
C:\Documents and Settings\HP_Owner\My Documents\pos157A.tmp
C:\Documents and Settings\HP_Owner\My Documents\pos157B.tmp
C:\Documents and Settings\HP_Owner\My Documents\pos157C.tmp
C:\Documents and Settings\HP_Owner\My Documents\pos157D.tmp
C:\Documents and Settings\HP_Owner\My Documents\pos157E.tmp
C:\Documents and Settings\HP_Owner\My Documents\pos157F.tmp
C:\Documents and Settings\HP_Owner\My Documents\pos1580.tmp
C:\Documents and Settings\HP_Owner\My Documents\pos1581.tmp
C:\Documents and Settings\HP_Owner\My Documents\pos1582.tmp
C:\Documents and Settings\HP_Owner\My Documents\pos1583.tmp
C:\Documents and Settings\HP_Owner\My Documents\pos1584.tmp
C:\Documents and Settings\HP_Owner\My Documents\pos1585.tmp
C:\Documents and Settings\HP_Owner\My Documents\pos1586.tmp
C:\Documents and Settings\HP_Owner\My Documents\pos1587.tmp
C:\Documents and Settings\HP_Owner\My Documents\pos1588.tmp
C:\Documents and Settings\HP_Owner\My Documents\pos1589.tmp
C:\Documents and Settings\HP_Owner\My Documents\pos158A.tmp
C:\Documents and Settings\HP_Owner\My Documents\pos158B.tmp
C:\Documents and Settings\HP_Owner\My Documents\pos158C.tmp
C:\Documents and Settings\HP_Owner\My Documents\pos158D.tmp
C:\Documents and Settings\HP_Owner\My Documents\pos158E.tmp
C:\Documents and Settings\HP_Owner\My Documents\pos158F.tmp
C:\Documents and Settings\HP_Owner\My Documents\pos207.tmp
C:\Documents and Settings\HP_Owner\My Documents\pos208.tmp
C:\Documents and Settings\HP_Owner\My Documents\pos209.tmp
C:\Documents and Settings\HP_Owner\My Documents\pos20A.tmp
C:\Documents and Settings\HP_Owner\My Documents\pos20B.tmp
C:\Documents and Settings\HP_Owner\My Documents\pos20C.tmp
C:\Documents and Settings\HP_Owner\My Documents\pos20D.tmp
C:\Documents and Settings\HP_Owner\My Documents\pos20E.tmp
C:\Documents and Settings\HP_Owner\My Documents\pos20F.tmp
C:\Documents and Settings\HP_Owner\My Documents\pos210.tmp
C:\Documents and Settings\HP_Owner\My Documents\pos211.tmp
C:\Documents and Settings\HP_Owner\My Documents\pos212.tmp
C:\Documents and Settings\HP_Owner\My Documents\pos213.tmp
C:\Documents and Settings\HP_Owner\My Documents\pos214.tmp
C:\Documents and Settings\HP_Owner\My Documents\pos215.tmp
C:\Documents and Settings\HP_Owner\My Documents\pos216.tmp
C:\Documents and Settings\HP_Owner\My Documents\pos217.tmp
C:\Documents and Settings\HP_Owner\My Documents\pos218.tmp
C:\Documents and Settings\HP_Owner\My Documents\pos219.tmp
C:\Documents and Settings\HP_Owner\My Documents\pos21A.tmp
C:\Documents and Settings\HP_Owner\My Documents\pos21B.tmp
C:\Documents and Settings\HP_Owner\My Documents\pos21C.tmp
C:\Documents and Settings\HP_Owner\My Documents\pos21D.tmp
C:\Documents and Settings\HP_Owner\My Documents\pos21E.tmp
C:\Documents and Settings\HP_Owner\My Documents\pos21F.tmp
C:\Documents and Settings\HP_Owner\My Documents\pos220.tmp
C:\Documents and Settings\HP_Owner\My Documents\pos221.tmp
C:\Documents and Settings\HP_Owner\My Documents\pos222.tmp
C:\Documents and Settings\HP_Owner\My Documents\pos223.tmp
C:\Documents and Settings\HP_Owner\My Documents\pos224.tmp
C:\Documents and Settings\HP_Owner\My Documents\pos225.tmp
C:\Documents and Settings\HP_Owner\My Documents\pos226.tmp
C:\Documents and Settings\HP_Owner\My Documents\pos227.tmp
C:\Documents and Settings\HP_Owner\My Documents\pos228.tmp
C:\Documents and Settings\HP_Owner\My Documents\pos229.tmp
C:\Documents and Settings\HP_Owner\My Documents\pos22A.tmp
C:\Documents and Settings\HP_Owner\My Documents\pos22B.tmp
C:\Documents and Settings\HP_Owner\My Documents\pos22C.tmp
C:\Documents and Settings\HP_Owner\My Documents\pos22D.tmp
C:\Documents and Settings\HP_Owner\My Documents\pos22E.tmp
C:\Documents and Settings\HP_Owner\My Documents\pos22F.tmp
C:\Documents and Settings\HP_Owner\My Documents\pos230.tmp
C:\Documents and Settings\HP_Owner\My Documents\pos231.tmp
C:\Documents and Settings\HP_Owner\My Documents\pos232.tmp
C:\Documents and Settings\HP_Owner\My Documents\pos233.tmp
C:\Documents and Settings\HP_Owner\My Documents\pos234.tmp
C:\Documents and Settings\HP_Owner\My Documents\pos235.tmp
C:\Documents and Settings\HP_Owner\My Documents\pos236.tmp
C:\Documents and Settings\HP_Owner\My Documents\pos237.tmp
C:\Documents and Settings\HP_Owner\My Documents\pos238.tmp
C:\Documents and Settings\HP_Owner\My Documents\pos239.tmp
C:\Documents and Settings\HP_Owner\My Documents\pos23A.tmp
C:\Documents and Settings\HP_Owner\My Documents\pos23B.tmp
C:\Documents and Settings\HP_Owner\My Documents\pos23C.tmp
C:\Documents and Settings\HP_Owner\My Documents\pos23D.tmp
C:\Documents and Settings\HP_Owner\My Documents\pos23E.tmp
C:\Documents and Settings\HP_Owner\My Documents\pos23F.tmp
C:\Documents and Settings\HP_Owner\My Documents\pos240.tmp
C:\Documents and Settings\HP_Owner\My Documents\pos241.tmp
C:\Documents and Settings\HP_Owner\My Documents\pos242.tmp
C:\Documents and Settings\HP_Owner\My Documents\pos243.tmp
C:\Documents and Settings\HP_Owner\My Documents\pos244.tmp
C:\Documents and Settings\HP_Owner\My Documents\pos245.tmp
C:\Documents and Settings\HP_Owner\My Documents\pos246.tmp
C:\Documents and Settings\HP_Owner\My Documents\pos247.tmp
C:\Documents and Settings\HP_Owner\My Documents\pos248.tmp
C:\Documents and Settings\HP_Owner\My Documents\pos249.tmp
C:\Documents and Settings\HP_Owner\My Documents\pos24A.tmp
C:\Documents and Settings\HP_Owner\My Documents\pos24B.tmp
C:\Documents and Settings\HP_Owner\My Documents\pos24C.tmp
C:\Documents and Settings\HP_Owner\My Documents\pos24D.tmp
C:\Documents and Settings\HP_Owner\My Documents\pos24E.tmp
C:\Documents and Settings\HP_Owner\My Documents\pos24F.tmp
C:\Documents and Settings\HP_Owner\My Documents\pos250.tmp
C:\Documents and Settings\HP_Owner\My Documents\pos251.tmp
C:\Documents and Settings\HP_Owner\My Documents\pos252.tmp
C:\Documents and Settings\HP_Owner\My Documents\pos253.tmp
C:\Documents and Settings\HP_Owner\My Documents\pos254.tmp
C:\Documents and Settings\HP_Owner\My Documents\pos255.tmp
C:\Documents and Settings\HP_Owner\My Documents\pos256.tmp
C:\Documents and Settings\HP_Owner\My Documents\pos257.tmp
C:\Documents and Settings\HP_Owner\My Documents\pos258.tmp
C:\Documents and Settings\HP_Owner\My Documents\pos259.tmp
C:\Documents and Settings\HP_Owner\My Documents\pos25A.tmp
C:\Documents and Settings\HP_Owner\My Documents\pos25B.tmp
C:\Documents and Settings\HP_Owner\My Documents\pos25C.tmp
C:\Documents and Settings\HP_Owner\My Documents\pos25D.tmp
C:\Documents and Settings\HP_Owner\My Documents\pos25E.tmp
C:\Documents and Settings\HP_Owner\My Documents\pos25F.tmp
C:\Documents and Settings\HP_Owner\My Documents\pos260.tmp
C:\Documents and Settings\HP_Owner\My Documents\pos261.tmp
C:\Documents and Settings\HP_Owner\My Documents\pos262.tmp
C:\Documents and Settings\HP_Owner\My Documents\pos263.tmp
C:\Documents and Settings\HP_Owner\My Documents\pos264.tmp
C:\Documents and Settings\HP_Owner\My Documents\pos265.tmp
C:\Documents and Settings\HP_Owner\My Documents\pos266.tmp
C:\Documents and Settings\HP_Owner\My Documents\pos267.tmp
C:\Documents and Settings\HP_Owner\My Documents\pos268.tmp
C:\Documents and Settings\HP_Owner\My Documents\pos269.tmp
C:\Documents and Settings\HP_Owner\My Documents\pos26A.tmp
C:\Documents and Settings\HP_Owner\My Documents\pos26B.tmp
C:\Documents and Settings\HP_Owner\My Documents\pos26C.tmp
C:\Documents and Settings\HP_Owner\My Documents\pos26D.tmp
C:\Documents and Settings\HP_Owner\My Documents\pos26E.tmp
C:\Documents and Settings\HP_Owner\My Documents\pos26F.tmp
C:\Documents and Settings\HP_Owner\My Documents\pos270.tmp
C:\Documents and Settings\HP_Owner\My Documents\pos271.tmp
C:\Documents and Settings\HP_Owner\My Documents\pos272.tmp
C:\Documents and Settings\HP_Owner\My Documents\pos273.tmp
C:\Documents and Settings\HP_Owner\My Documents\pos274.tmp
C:\Documents and Settings\HP_Owner\My Documents\pos275.tmp
C:\Documents and Settings\HP_Owner\My Documents\pos276.tmp
C:\Documents and Settings\HP_Owner\My Documents\pos277.tmp
C:\Documents and Settings\HP_Owner\My Documents\pos278.tmp
C:\Documents and Settings\HP_Owner\My Documents\pos279.tmp
C:\Documents and Settings\HP_Owner\My Documents\pos27A.tmp
C:\Documents and Settings\HP_Owner\My Documents\pos27B.tmp
C:\Documents and Settings\HP_Owner\My Documents\pos27C.tmp
C:\Documents and Settings\HP_Owner\My Documents\pos27D.tmp
C:\Documents and Settings\HP_Owner\My Documents\pos27E.tmp
C:\Documents and Settings\HP_Owner\My Documents\pos27F.tmp
C:\Documents and Settings\HP_Owner\My Documents\pos280.tmp
C:\Documents and Settings\HP_Owner\My Documents\pos281.tmp
C:\Documents and Settings\HP_Owner\My Documents\pos282.tmp
C:\Documents and Settings\HP_Owner\My Documents\pos283.tmp
C:\Documents and Settings\HP_Owner\My Documents\pos284.tmp
C:\Documents and Settings\HP_Owner\My Documents\pos285.tmp
C:\Documents and Settings\HP_Owner\My Documents\pos286.tmp
C:\Documents and Settings\HP_Owner\My Documents\pos287.tmp
C:\Documents and Settings\HP_Owner\My Documents\pos288.tmp
C:\Documents and Settings\HP_Owner\My Documents\pos289.tmp
C:\Documents and Settings\HP_Owner\My Documents\pos28A.tmp
C:\Documents and Settings\HP_Owner\My Documents\pos28B.tmp
C:\Documents and Settings\HP_Owner\My Documents\pos28C.tmp
C:\Documents and Settings\HP_Owner\My Documents\pos28D.tmp
C:\Documents and Settings\HP_Owner\My Documents\pos28E.tmp
C:\Documents and Settings\HP_Owner\My Documents\pos28F.tmp
C:\Documents and Settings\HP_Owner\My Documents\pos290.tmp
C:\Documents and Settings\HP_Owner\My Documents\pos291.tmp
C:\Documents and Settings\HP_Owner\My Documents\pos292.tmp
C:\Documents and Settings\HP_Owner\My Documents\pos293.tmp
C:\Documents and Settings\HP_Owner\My Documents\pos294.tmp
C:\Documents and Settings\HP_Owner\My Documents\pos295.tmp
C:\Documents and Settings\HP_Owner\My Documents\pos296.tmp
C:\Documents and Settings\HP_Owner\My Documents\pos297.tmp
C:\Documents and Settings\HP_Owner\My Documents\pos298.tmp
C:\Documents and Settings\HP_Owner\My Documents\pos299.tmp
C:\Documents and Settings\HP_Owner\My Documents\pos29A.tmp
C:\Documents and Settings\HP_Owner\My Documents\pos29B.tmp
C:\Documents and Settings\HP_Owner\My Documents\pos29C.tmp
C:\Documents and Settings\HP_Owner\My Documents\pos29D.tmp
C:\Documents and Settings\HP_Owner\My Documents\pos29E.tmp
C:\Documents and Settings\HP_Owner\My Documents\pos29F.tmp
C:\Documents and Settings\HP_Owner\My Documents\pos2A0.tmp
C:\Documents and Settings\HP_Owner\My Documents\pos2A1.tmp
C:\Documents and Settings\HP_Owner\My Documents\pos2A2.tmp
C:\Documents and Settings\HP_Owner\My Documents\pos2A4.tmp
C:\Documents and Settings\HP_Owner\My Documents\pos2A5.tmp
C:\Documents and Settings\HP_Owner\My Documents\pos2A6.tmp
C:\Documents and Settings\HP_Owner\My Documents\pos2A7.tmp
C:\Documents and Settings\HP_Owner\My Documents\pos2A8.tmp
C:\Documents and Settings\HP_Owner\My Documents\pos2A9.tmp
C:\Documents and Settings\HP_Owner\My Documents\pos2AA.tmp
C:\Documents and Settings\HP_Owner\My Documents\pos2AB.tmp
C:\Documents and Settings\HP_Owner\My Documents\pos2AC.tmp
C:\Documents and Settings\HP_Owner\My Documents\pos2AD.tmp
C:\Documents and Settings\HP_Owner\My Documents\pos2AE.tmp
C:\Documents and Settings\HP_Owner\My Documents\pos2AF.tmp
C:\Documents and Settings\HP_Owner\My Documents\pos2B0.tmp
C:\Documents and Settings\HP_Owner\My Documents\pos2B1.tmp
C:\Documents and Settings\HP_Owner\My Documents\pos2B2.tmp
C:\Documents and Settings\HP_Owner\My Documents\pos2B3.tmp
C:\Documents and Settings\HP_Owner\My Documents\pos2B4.tmp
C:\Documents and Settings\HP_Owner\My Documents\pos2B5.tmp
C:\Documents and Settings\HP_Owner\My Documents\pos2B6.tmp
C:\Documents and Settings\HP_Owner\My Documents\pos2B7.tmp
C:\Documents and Settings\HP_Owner\My Documents\pos2B8.tmp
C:\Documents and Settings\HP_Owner\My Documents\pos2B9.tmp
C:\Documents and Settings\HP_Owner\My Documents\pos2BA.tmp
C:\Documents and Settings\HP_Owner\My Documents\pos2BB.tmp
C:\Documents and Settings\HP_Owner\My Documents\pos2BC.tmp
C:\Documents and Settings\HP_Owner\My Documents\pos2BD.tmp
C:\Documents and Settings\HP_Owner\My Documents\pos2BE.tmp
C:\Documents and Settings\HP_Owner\My Documents\pos2BF.tmp
C:\Documents and Settings\HP_Owner\My Documents\pos2C0.tmp
C:\Documents and Settings\HP_Owner\My Documents\pos2C1.tmp
C:\Documents and Settings\HP_Owner\My Documents\pos2C2.tmp
C:\Documents and Settings\HP_Owner\My Documents\pos2C3.tmp
C:\Documents and Settings\HP_Owner\My Documents\pos2C4.tmp
C:\Documents and Settings\HP_Owner\My Documents\pos2C5.tmp
C:\Documents and Settings\HP_Owner\My Documents\pos2C6.tmp
C:\Documents and Settings\HP_Owner\My Documents\pos2C7.tmp
C:\Documents and Settings\HP_Owner\My Documents\pos2C8.tmp
C:\Documents and Settings\HP_Owner\My Documents\pos2C9.tmp
C:\Documents and Settings\HP_Owner\My Documents\pos2CA.tmp
C:\Documents and Settings\HP_Owner\My Documents\pos2CB.tmp
C:\Documents and Settings\HP_Owner\My Documents\pos2CC.tmp
C:\Documents and Settings\HP_Owner\My Documents\pos2CD.tmp
C:\Documents and Settings\HP_Owner\My Documents\pos2CE.tmp
C:\Documents and Settings\HP_Owner\My Documents\pos2CF.tmp
C:\Documents and Settings\HP_Owner\My Documents\pos2D0.tmp
C:\Documents and Settings\HP_Owner\My Documents\pos2D1.tmp
C:\Documents and Settings\HP_Owner\My Documents\pos2D2.tmp
C:\Documents and Settings\HP_Owner\My Documents\pos2D3.tmp
C:\Documents and Settings\HP_Owner\My Documents\pos2D4.tmp
C:\Documents and Settings\HP_Owner\My Documents\pos2D5.tmp
C:\Documents and Settings\HP_Owner\My Documents\pos2D6.tmp
C:\Documents and Settings\HP_Owner\My Documents\pos2D7.tmp
C:\Documents and Settings\HP_Owner\My Documents\pos2D8.tmp
C:\Documents and Settings\HP_Owner\My Documents\pos2D9.tmp
C:\Documents and Settings\HP_Owner\My Documents\pos2DA.tmp
C:\Documents and Settings\HP_Owner\My Documents\pos2DB.tmp
C:\Documents and Settings\HP_Owner\My Documents\pos2DC.tmp
C:\Documents and Settings\HP_Owner\My Documents\pos2DD.tmp
C:\Documents and Settings\HP_Owner\My Documents\pos2DE.tmp
C:\Documents and Settings\HP_Owner\My Documents\pos2DF.tmp
C:\Documents and Settings\HP_Owner\My Documents\pos2E0.tmp
C:\Documents and Settings\HP_Owner\My Documents\pos2E1.tmp
C:\Documents and Settings\HP_Owner\My Documents\pos2E2.tmp
C:\Documents and Settings\HP_Owner\My Documents\pos2E3.tmp
C:\Documents and Settings\HP_Owner\My Documents\pos2E4.tmp
C:\Documents and Settings\HP_Owner\My Documents\pos2E5.tmp
C:\Documents and Settings\HP_Owner\My Documents\pos2E6.tmp
C:\Documents and Settings\HP_Owner\My Documents\pos2E7.tmp
C:\Documents and Settings\HP_Owner\My Documents\pos2E8.tmp
C:\Documents and Settings\HP_Owner\My Documents\pos2E9.tmp
C:\Documents and Settings\HP_Owner\My Documents\pos2EA.tmp
C:\Documents and Settings\HP_Owner\My Documents\pos2EB.tmp
C:\Documents and Settings\HP_Owner\My Documents\pos2EC.tmp
C:\Documents and Settings\HP_Owner\My Documents\pos2ED.tmp
C:\Documents and Settings\HP_Owner\My Documents\pos2EE.tmp
C:\Documents and Settings\HP_Owner\My Documents\pos2EF.tmp
C:\Documents and Settings\HP_Owner\My Documents\pos2F0.tmp
C:\Documents and Settings\HP_Owner\My Documents\pos2F1.tmp
C:\Documents and Settings\HP_Owner\My Documents\pos2F2.tmp
C:\Documents and Settings\HP_Owner\My Documents\pos2F3.tmp
C:\Documents and Settings\HP_Owner\My Documents\pos2F4.tmp
C:\Documents and Settings\HP_Owner\My Documents\pos2F5.tmp
C:\Documents and Settings\HP_Owner\My Documents\pos2F6.tmp
C:\Documents and Settings\HP_Owner\My Documents\pos2F7.tmp
It goes on like that for ages just with different numbers..
C:\WINDOWS\system32\stutv.ini2
is the last file.
.
((((((((((((((((((((((((( Files Created from 2007-12-20 to 2008-01-20 )))))))))))))))))))))))))))))))
.
2008-01-18 13:48 . 2008-01-18 13:48 54,156 --ah----- C:\WINDOWS\QTFont.qfn
2008-01-18 13:48 . 2008-01-18 13:48 1,409 --a------ C:\WINDOWS\QTFont.for
2008-01-16 03:26 . 2008-01-16 03:59 <DIR> d-------- C:\Program Files\SUPERAntiSpyware
2008-01-16 03:26 . 2008-01-16 03:26 <DIR> d-------- C:\Documents and Settings\HP_Owner\Application Data\SUPERAntiSpyware.com
2008-01-16 03:26 . 2008-01-16 03:26 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\SUPERAntiSpyware.com
2008-01-16 02:26 . 2008-01-20 12:54 <DIR> d-------- C:\WINDOWS\LMI1C.tmp
2008-01-16 01:47 . 2008-01-20 12:54 <DIR> d-------- C:\WINDOWS\LMI189.tmp
2008-01-15 11:20 . 2008-01-15 11:20 <DIR> d-------- C:\Program Files\Trend Micro
2008-01-15 09:06 . 2008-01-16 00:22 <DIR> d-------- C:\VundoFix Backups
2008-01-14 05:40 . 2008-01-14 05:40 <DIR> d-------- C:\nup
2008-01-14 04:33 . 2008-01-14 05:28 <DIR> d-------- C:\Program Files\EsetOnlineScanner
2008-01-13 02:54 . 2008-01-13 02:54 <DIR> d-------- C:\WINDOWS\system32\Kaspersky Lab
2008-01-13 02:54 . 2008-01-13 02:54 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\Kaspersky Lab
2008-01-13 02:15 . 2000-08-31 08:00 51,200 --a------ C:\WINDOWS\NirCmd.exe
2008-01-11 04:14 . 2008-01-11 04:14 7,168 --ahs---- C:\WINDOWS\Thumbs.db
2008-01-11 04:11 . 2008-01-11 04:11 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\FLEXnet
2008-01-11 04:04 . 2008-01-11 04:04 <DIR> d-------- C:\Program Files\Bonjour
2008-01-11 03:49 . 2008-01-11 03:49 <DIR> d-------- C:\Program Files\Common Files\Macrovision Shared
2008-01-11 03:40 . 2008-01-12 11:58 <DIR> d-------- C:\Program Files\PowerISO
2008-01-10 03:39 . 2008-01-10 03:39 <DIR> d-------- C:\Program Files\uTorrent
2008-01-10 03:39 . 2008-01-10 17:19 <DIR> d-------- C:\Documents and Settings\HP_Owner\Application Data\uTorrent
2008-01-09 04:05 . 2008-01-09 04:05 <DIR> d-------- C:\Program Files\Common Files\Adobe Systems Shared
2008-01-09 00:07 . 2008-01-09 00:07 <DIR> d-------- C:\Program Files\Microsoft ActiveSync
2008-01-09 00:07 . 2008-01-09 00:07 376 --a------ C:\WINDOWS\ODBC.INI
2008-01-09 00:06 . 2008-01-09 00:06 <DIR> d-------- C:\WINDOWS\ShellNew
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2008-01-20 02:54 --------- d-----w C:\Program Files\iTunes
2008-01-20 02:50 --------- d-----w C:\Documents and Settings\HP_Owner\Application Data\Skype
2008-01-16 23:08 --------- d-----w C:\Documents and Settings\HP_Owner\Application Data\AVG7
2008-01-15 17:25 --------- d-----w C:\Program Files\Common Files\Wise Installation Wizard
2008-01-15 16:37 --------- d-----w C:\Documents and Settings\HP_Owner\Application Data\Xfire
2008-01-10 18:14 --------- d-----w C:\Program Files\DivX
2008-01-10 18:14 --------- d-----w C:\Program Files\Combined Community Codec Pack
2008-01-10 18:04 --------- d-----w C:\Program Files\Common Files\Adobe
2008-01-09 06:47 --------- d-----w C:\Program Files\World of Warcraft
2008-01-08 18:25 --------- d-----w C:\Program Files\QuickTime
2008-01-08 14:03 --------- d-----w C:\Program Files\Xfire
2007-11-27 23:34 --------- d-----w C:\Program Files\Soulseek
2007-11-27 13:57 --------- d-----w C:\Documents and Settings\All Users\Application Data\InterVideo
.
((((((((((((((((((((((((((((( snapshot@2008-01-13_ 2.47.51.75 )))))))))))))))))))))))))))))))))))))))))
.
- 2004-08-25 09:06:00 7,168 ----a-w C:\WINDOWS\assembly\GAC\IEExecRemote\1.0.5000.0__b03f5f7f11d50a3a\IEExecRemote.dll
+ 2008-01-15 16:34:19 8,192 ----a-w C:\WINDOWS\assembly\GAC\IEExecRemote\1.0.5000.0__b03f5f7f11d50a3a\IEExecRemote.dll
- 2004-08-25 09:05:58 32,768 ----a-w C:\WINDOWS\assembly\GAC\IEHost\1.0.5000.0__b03f5f7f11d50a3a\IEHost.dll
+ 2008-01-15 16:34:22 32,768 ----a-w C:\WINDOWS\assembly\GAC\IEHost\1.0.5000.0__b03f5f7f11d50a3a\IEHost.dll
- 2004-08-25 09:05:54 716,800 ----a-w C:\WINDOWS\assembly\GAC\Microsoft.JScript\7.0.5000.0__b03f5f7f11d50a3a\Microsoft.JScript.dll
+ 2008-01-15 16:34:33 720,896 ----a-w C:\WINDOWS\assembly\GAC\Microsoft.JScript\7.0.5000.0__b03f5f7f11d50a3a\Microsoft.JScript.dll
- 2004-08-25 09:05:55 299,008 ----a-w C:\WINDOWS\assembly\GAC\Microsoft.VisualBasic\7.0.5000.0__b03f5f7f11d50a3a\Microsoft.VisualBasic.dll
+ 2008-01-15 16:34:22 299,008 ----a-w C:\WINDOWS\assembly\GAC\Microsoft.VisualBasic\7.0.5000.0__b03f5f7f11d50a3a\Microsoft.VisualBasic.dll
- 2004-08-25 09:06:00 32,768 ----a-w C:\WINDOWS\assembly\GAC\Regcode\1.0.5000.0__b03f5f7f11d50a3a\RegCode.dll
+ 2008-01-15 16:34:29 32,768 ----a-w C:\WINDOWS\assembly\GAC\Regcode\1.0.5000.0__b03f5f7f11d50a3a\RegCode.dll
- 2004-08-25 09:06:01 299,008 ----a-w C:\WINDOWS\assembly\GAC\System.Data.OracleClient\1.0.5000.0__b77a5c561934e089\System.Data.OracleClient.dll
+ 2008-01-15 16:34:27 303,104 ----a-w C:\WINDOWS\assembly\GAC\System.Data.OracleClient\1.0.5000.0__b77a5c561934e089\System.Data.OracleClient.dll
- 2004-08-25 09:05:59 1,290,240 ----a-w C:\WINDOWS\assembly\GAC\System.Data\1.0.5000.0__b77a5c561934e089\System.Data.dll
+ 2008-01-15 16:34:30 1,294,336 ----a-w C:\WINDOWS\assembly\GAC\System.Data\1.0.5000.0__b77a5c561934e089\System.Data.dll
- 2004-08-25 09:05:59 1,699,840 ----a-w C:\WINDOWS\assembly\GAC\System.Design\1.0.5000.0__b03f5f7f11d50a3a\System.Design.dll
+ 2008-01-15 16:34:20 1,703,936 ----a-w C:\WINDOWS\assembly\GAC\System.Design\1.0.5000.0__b03f5f7f11d50a3a\System.Design.dll
- 2004-08-25 09:05:59 86,016 ----a-w C:\WINDOWS\assembly\GAC\System.DirectoryServices\1.0.5000.0__b03f5f7f11d50a3a\System.DirectoryServices.dll
+ 2008-01-15 16:34:32 90,112 ----a-w C:\WINDOWS\assembly\GAC\System.DirectoryServices\1.0.5000.0__b03f5f7f11d50a3a\System.DirectoryServices.dll
- 2004-08-25 09:05:59 466,944 ----a-w C:\WINDOWS\assembly\GAC\System.Drawing\1.0.5000.0__b03f5f7f11d50a3a\System.Drawing.dll
+ 2008-01-15 16:34:26 466,944 ----a-w C:\WINDOWS\assembly\GAC\System.Drawing\1.0.5000.0__b03f5f7f11d50a3a\System.Drawing.dll
- 2004-08-25 09:05:59 241,664 ----a-w C:\WINDOWS\assembly\GAC\System.EnterpriseServices\1.0.5000.0__b03f5f7f11d50a3a\System.EnterpriseServices.dll
+ 2008-01-15 16:34:24 241,664 ----a-w C:\WINDOWS\assembly\GAC\System.EnterpriseServices\1.0.5000.0__b03f5f7f11d50a3a\System.EnterpriseServices.dll
- 2004-08-25 09:05:59 64,000 ----a-w C:\WINDOWS\assembly\GAC\System.EnterpriseServices\1.0.5000.0__b03f5f7f11d50a3a\System.EnterpriseServices.Thunk.dll
+ 2008-01-15 16:34:24 66,560 ----a-w C:\WINDOWS\assembly\GAC\System.EnterpriseServices\1.0.5000.0__b03f5f7f11d50a3a\System.EnterpriseServices.Thunk.dll
- 2004-08-25 09:05:59 368,640 ----a-w C:\WINDOWS\assembly\GAC\System.Management\1.0.5000.0__b03f5f7f11d50a3a\System.Management.dll
+ 2008-01-15 16:34:29 372,736 ----a-w C:\WINDOWS\assembly\GAC\System.Management\1.0.5000.0__b03f5f7f11d50a3a\System.Management.dll
- 2004-08-25 09:05:59 241,664 ----a-w C:\WINDOWS\assembly\GAC\System.Messaging\1.0.5000.0__b03f5f7f11d50a3a\System.Messaging.dll
+ 2008-01-15 16:34:33 241,664 ----a-w C:\WINDOWS\assembly\GAC\System.Messaging\1.0.5000.0__b03f5f7f11d50a3a\System.Messaging.dll
- 2004-08-25 09:05:59 323,584 ----a-w C:\WINDOWS\assembly\GAC\System.Runtime.Remoting\1.0.5000.0__b77a5c561934e089\System.Runtime.Remoting.dll
+ 2008-01-15 16:34:27 323,584 ----a-w C:\WINDOWS\assembly\GAC\System.Runtime.Remoting\1.0.5000.0__b77a5c561934e089\System.Runtime.Remoting.dll
- 2004-08-25 09:05:59 131,072 ----a-w C:\WINDOWS\assembly\GAC\System.Runtime.Serialization.Formatters.Soap\1.0.5000.0__b03f5f7f11d50a3a\System.Runtime.Serialization.Formatters.Soap.dll
+ 2008-01-15 16:34:24 131,072 ----a-w C:\WINDOWS\assembly\GAC\System.Runtime.Serialization.Formatters.Soap\1.0.5000.0__b03f5f7f11d50a3a\System.Runtime.Serialization.Formatters.Soap.dll
- 2004-08-25 09:05:59 77,824 ----a-w C:\WINDOWS\assembly\GAC\System.Security\1.0.5000.0__b03f5f7f11d50a3a\System.Security.dll
+ 2008-01-15 16:34:25 77,824 ----a-w C:\WINDOWS\assembly\GAC\System.Security\1.0.5000.0__b03f5f7f11d50a3a\System.Security.dll
- 2004-08-25 09:05:59 126,976 ----a-w C:\WINDOWS\assembly\GAC\System.ServiceProcess\1.0.5000.0__b03f5f7f11d50a3a\System.ServiceProcess.dll
+ 2008-01-15 16:34:31 126,976 ----a-w C:\WINDOWS\assembly\GAC\System.ServiceProcess\1.0.5000.0__b03f5f7f11d50a3a\System.ServiceProcess.dll
- 2004-08-25 09:06:01 819,200 ----a-w C:\WINDOWS\assembly\GAC\System.Web.Mobile\1.0.5000.0__b03f5f7f11d50a3a\System.Web.Mobile.dll
+ 2008-01-15 16:34:19 819,200 ----a-w C:\WINDOWS\assembly\GAC\System.Web.Mobile\1.0.5000.0__b03f5f7f11d50a3a\System.Web.Mobile.dll
- 2004-08-25 09:06:00 57,344 ----a-w C:\WINDOWS\assembly\GAC\System.Web.RegularExpressions\1.0.5000.0__b03f5f7f11d50a3a\System.Web.RegularExpressions.dll
+ 2008-01-15 16:34:23 57,344 ----a-w C:\WINDOWS\assembly\GAC\System.Web.RegularExpressions\1.0.5000.0__b03f5f7f11d50a3a\System.Web.RegularExpressions.dll
- 2004-08-25 09:06:00 569,344 ----a-w C:\WINDOWS\assembly\GAC\System.Web.Services\1.0.5000.0__b03f5f7f11d50a3a\System.Web.Services.dll
+ 2008-01-15 16:34:21 573,440 ----a-w C:\WINDOWS\assembly\GAC\System.Web.Services\1.0.5000.0__b03f5f7f11d50a3a\System.Web.Services.dll
- 2004-08-25 09:06:00 1,245,184 ----a-w C:\WINDOWS\assembly\GAC\System.Web\1.0.5000.0__b03f5f7f11d50a3a\System.Web.dll
+ 2008-01-15 16:34:31 1,257,472 ----a-w C:\WINDOWS\assembly\GAC\System.Web\1.0.5000.0__b03f5f7f11d50a3a\System.Web.dll
- 2004-08-25 09:06:00 2,039,808 ----a-w C:\WINDOWS\assembly\GAC\System.Windows.Forms\1.0.5000.0__b77a5c561934e089\System.Windows.Forms.dll
+ 2008-01-15 16:34:25 2,052,096 ----a-w C:\WINDOWS\assembly\GAC\System.Windows.Forms\1.0.5000.0__b77a5c561934e089\System.Windows.Forms.dll
- 2004-08-25 09:06:00 1,335,296 ----a-w C:\WINDOWS\assembly\GAC\System.Xml\1.0.5000.0__b77a5c561934e089\System.Xml.dll
+ 2008-01-15 16:34:28 1,339,392 ----a-w C:\WINDOWS\assembly\GAC\System.Xml\1.0.5000.0__b77a5c561934e089\System.XML.dll
- 2004-08-25 09:05:59 1,216,512 ----a-w C:\WINDOWS\assembly\GAC\System\1.0.5000.0__b77a5c561934e089\System.dll
+ 2008-01-15 16:34:34 1,224,704 ----a-w C:\WINDOWS\assembly\GAC\System\1.0.5000.0__b77a5c561934e089\System.dll
+ 2008-01-15 16:34:46 61,440 ----a-w C:\WINDOWS\assembly\NativeImages1_v1.1.4322\CustomMarshalers\1.0.5000.0__b03f5f7f11d50a3a_8281743e\CustomMarshalers.dll
+ 2008-01-15 16:35:06 3,379,200 ----a-w C:\WINDOWS\assembly\NativeImages1_v1.1.4322\mscorlib\1.0.5000.0__b77a5c561934e089_f3fa0af8\mscorlib.dll
+ 2008-01-15 16:35:00 1,466,368 ----a-w C:\WINDOWS\assembly\NativeImages1_v1.1.4322\System.Design\1.0.5000.0__b03f5f7f11d50a3a_a99b6f0a\System.Design.dll
+ 2008-01-15 16:34:47 90,112 ----a-w C:\WINDOWS\assembly\NativeImages1_v1.1.4322\System.Drawing.Design\1.0.5000.0__b03f5f7f11d50a3a_9fb6dc72\System.Drawing.Design.dll
+ 2008-01-15 16:35:03 835,584 ----a-w C:\WINDOWS\assembly\NativeImages1_v1.1.4322\System.Drawing\1.0.5000.0__b03f5f7f11d50a3a_290beafe\System.Drawing.dll
+ 2008-01-15 16:34:52 3,014,656 ----a-w C:\WINDOWS\assembly\NativeImages1_v1.1.4322\System.Windows.Forms\1.0.5000.0__b77a5c561934e089_ad8cd407\System.Windows.Forms.dll
+ 2008-01-15 16:34:57 2,088,960 ----a-w C:\WINDOWS\assembly\NativeImages1_v1.1.4322\System.Xml\1.0.5000.0__b77a5c561934e089_c389602d\System.Xml.dll
+ 2008-01-15 16:34:45 1,953,792 ----a-w C:\WINDOWS\assembly\NativeImages1_v1.1.4322\System\1.0.5000.0__b77a5c561934e089_82fffed3\System.dll
+ 2008-01-15 16:35:09 69,632 ----a-w C:\WINDOWS\assembly\NativeImages1_v1.1.4322\VJSharpCodeProvider\7.0.5000.0__b03f5f7f11d50a3a_70ec7ee8\VJSharpCodeProvider.dll
- 2008-01-12 16:16:12 237,568 ----a-w C:\WINDOWS\erdnt\Hiv-backup\Users\00000001\NTUSER.DAT
+ 2008-01-20 02:32:50 237,568 ----a-w C:\WINDOWS\erdnt\Hiv-backup\Users\00000001\NTUSER.DAT
- 2008-01-12 16:16:12 8,192 ----a-w C:\WINDOWS\erdnt\Hiv-backup\Users\00000002\UsrClass.dat
+ 2008-01-20 02:32:50 8,192 ----a-w C:\WINDOWS\erdnt\Hiv-backup\Users\00000002\UsrClass.dat
- 2008-01-12 16:16:12 237,568 ----a-w C:\WINDOWS\erdnt\Hiv-backup\Users\00000003\NTUSER.DAT
+ 2008-01-20 02:32:50 237,568 ----a-w C:\WINDOWS\erdnt\Hiv-backup\Users\00000003\NTUSER.DAT
- 2008-01-12 16:16:12 8,192 ----a-w C:\WINDOWS\erdnt\Hiv-backup\Users\00000004\UsrClass.dat
+ 2008-01-20 02:32:50 8,192 ----a-w C:\WINDOWS\erdnt\Hiv-backup\Users\00000004\UsrClass.dat
- 2008-01-12 16:16:12 2,252,800 ----a-w C:\WINDOWS\erdnt\Hiv-backup\Users\00000005\NTUSER.DAT
+ 2008-01-20 02:32:50 3,006,464 ----a-w C:\WINDOWS\erdnt\Hiv-backup\Users\00000005\NTUSER.DAT
- 2008-01-12 16:16:13 172,032 ----a-w C:\WINDOWS\erdnt\Hiv-backup\Users\00000006\UsrClass.dat
+ 2008-01-20 02:32:50 172,032 ----a-w C:\WINDOWS\erdnt\Hiv-backup\Users\00000006\UsrClass.dat
+ 2004-08-04 12:00:00 61,440 -c--a-w C:\WINDOWS\ie7\admparse.dll
+ 2004-08-04 12:00:00 99,840 -c--a-w C:\WINDOWS\ie7\advpack.dll
+ 2004-08-04 12:00:00 35,328 -c--a-w C:\WINDOWS\ie7\corpol.dll
+ 2004-08-04 12:00:00 28,672 -c--a-w C:\WINDOWS\ie7\custsat.dll
+ 2007-08-22 13:12:16 357,888 -c--a-w C:\WINDOWS\ie7\dxtmsft.dll
+ 2007-08-22 13:12:16 205,312 -c--a-w C:\WINDOWS\ie7\dxtrans.dll
+ 2007-08-22 13:12:16 55,808 -c--a-w C:\WINDOWS\ie7\extmgr.dll
+ 2004-08-04 12:00:00 38,912 -c--a-w C:\WINDOWS\ie7\hmmapi.dll
+ 2004-08-04 12:00:00 34,304 -c--a-w C:\WINDOWS\ie7\ie4uinit.exe
+ 2004-08-04 12:00:00 139,264 -c--a-w C:\WINDOWS\ie7\ieakeng.dll
+ 2004-08-04 12:00:00 216,576 -c--a-w C:\WINDOWS\ie7\ieaksie.dll
+ 2004-08-04 12:00:00 221,184 -c--a-w C:\WINDOWS\ie7\ieakui.dll
+ 2004-08-04 12:00:00 323,584 -c--a-w C:\WINDOWS\ie7\iedkcs32.dll
+ 2007-08-21 10:30:45 18,432 -c--a-w C:\WINDOWS\ie7\iedw.exe
+ 2004-08-04 12:00:00 81,920 -c--a-w C:\WINDOWS\ie7\ieencode.dll
+ 2007-08-22 13:12:16 251,392 -c--a-w C:\WINDOWS\ie7\iepeers.dll
+ 2004-08-04 12:00:00 48,640 -c--a-w C:\WINDOWS\ie7\iernonce.dll
+ 2004-08-04 12:00:00 62,976 -c--a-w C:\WINDOWS\ie7\iesetup.dll
+ 2004-08-04 12:00:00 93,184 -c--a-w C:\WINDOWS\ie7\iexplore.exe
+ 2004-08-04 12:00:00 35,840 -c--a-w C:\WINDOWS\ie7\imgutil.dll
+ 2007-08-22 13:12:16 96,256 -c--a-w C:\WINDOWS\ie7\inseng.dll
+ 2006-05-18 05:24:25 450,560 -c--a-w C:\WINDOWS\ie7\jscript.dll
+ 2007-08-22 13:12:16 16,384 -c--a-w C:\WINDOWS\ie7\jsproxy.dll
+ 2004-08-04 12:00:00 22,016 -c--a-w C:\WINDOWS\ie7\licmgr10.dll
+ 2004-08-04 12:00:00 29,184 -c--a-w C:\WINDOWS\ie7\mshta.exe
+ 2007-08-22 13:12:17 3,058,176 -c--a-w C:\WINDOWS\ie7\mshtml.dll
+ 2007-08-22 13:12:17 449,024 -c--a-w C:\WINDOWS\ie7\mshtmled.dll
+ 2004-08-04 12:00:00 56,832 -c--a-w C:\WINDOWS\ie7\mshtmler.dll
+ 2004-08-04 12:00:00 146,432 -c--a-w C:\WINDOWS\ie7\msls31.dll
+ 2007-08-22 13:12:17 146,432 -c--a-w C:\WINDOWS\ie7\msrating.dll
+ 2007-08-22 13:12:17 532,480 -c--a-w C:\WINDOWS\ie7\mstime.dll
+ 2004-08-04 12:00:00 96,256 -c--a-w C:\WINDOWS\ie7\occache.dll
+ 2007-08-22 13:12:17 39,424 -c--a-w C:\WINDOWS\ie7\pngfilt.dll
+ 2007-08-13 08:54:42 32,960 -c--a-w C:\WINDOWS\ie7\spuninst\iecustom.dll
+ 2007-08-13 08:52:06 66,048 -c--a-w C:\WINDOWS\ie7\spuninst\ieResetIcons.exe
+ 2006-09-06 07:43:16 213,216 -c--a-w C:\WINDOWS\ie7\spuninst\spuninst.exe
+ 2006-09-06 07:43:18 371,424 -c--a-w C:\WINDOWS\ie7\spuninst\updspapi.dll
+ 2004-08-04 12:00:00 37,888 -c--a-w C:\WINDOWS\ie7\url.dll
+ 2007-08-22 13:12:18 615,424 -c--a-w C:\WINDOWS\ie7\urlmon.dll
+ 2004-08-04 12:00:00 417,792 -c--a-w C:\WINDOWS\ie7\vbscript.dll
+ 2007-06-26 15:13:22 851,968 -c--a-w C:\WINDOWS\ie7\vgx.dll
+ 2004-08-04 12:00:00 276,480 -c--a-w C:\WINDOWS\ie7\webcheck.dll
+ 2007-08-22 13:12:18 658,944 -c--a-w C:\WINDOWS\ie7\wininet.dll
- 2008-01-09 18:25:37 102,400 ----a-r C:\WINDOWS\Installer\{B045B608-4A47-4C77-9EAD-06C394503306}\iTunesIco.exe
+ 2008-01-18 03:48:13 102,400 ----a-r C:\WINDOWS\Installer\{B045B608-4A47-4C77-9EAD-06C394503306}\iTunesIco.exe
+ 2008-01-15 17:26:22 29,696 ----a-r C:\WINDOWS\Installer\{CDDCBBF1-2703-46BC-938B-BCC81A1EEAAA}\IconCDDCBBF11.exe
+ 2008-01-15 17:26:22 18,944 ----a-r C:\WINDOWS\Installer\{CDDCBBF1-2703-46BC-938B-BCC81A1EEAAA}\IconCDDCBBF13.exe
+ 2008-01-15 17:26:22 65,024 ----a-r C:\WINDOWS\Installer\{CDDCBBF1-2703-46BC-938B-BCC81A1EEAAA}\IconCDDCBBF15.exe
- 2003-02-20 16:19:32 253,952 ----a-w C:\WINDOWS\Microsoft.NET\Framework\v1.1.4322\aspnet_isapi.dll
+ 2004-07-14 15:49:16 258,048 ----a-w C:\WINDOWS\Microsoft.NET\Framework\v1.1.4322\aspnet_isapi.dll
- 2003-02-20 16:19:34 20,480 ----a-w C:\WINDOWS\Microsoft.NET\Framework\v1.1.4322\aspnet_regiis.exe
+ 2004-07-14 15:49:18 20,480 ----a-w C:\WINDOWS\Microsoft.NET\Framework\v1.1.4322\aspnet_regiis.exe
- 2003-02-20 16:19:38 32,768 ----a-w C:\WINDOWS\Microsoft.NET\Framework\v1.1.4322\aspnet_state.exe
+ 2004-07-14 15:49:26 32,768 ----a-w C:\WINDOWS\Microsoft.NET\Framework\v1.1.4322\aspnet_state.exe
- 2003-02-20 16:19:36 32,768 ----a-w C:\WINDOWS\Microsoft.NET\Framework\v1.1.4322\aspnet_wp.exe
+ 2004-07-14 15:49:22 32,768 ----a-w C:\WINDOWS\Microsoft.NET\Framework\v1.1.4322\aspnet_wp.exe
- 2003-02-20 16:09:08 77,824 ----a-w C:\WINDOWS\Microsoft.NET\Framework\v1.1.4322\CORPerfMonExt.dll
+ 2004-07-14 14:32:22 81,920 ----a-w C:\WINDOWS\Microsoft.NET\Framework\v1.1.4322\CORPerfMonExt.dll
- 2003-02-21 07:20:44 49,152 ----a-w C:\WINDOWS\Microsoft.NET\Framework\v1.1.4322\csc.exe
+ 2004-07-15 01:23:28 49,152 ----a-w C:\WINDOWS\Microsoft.NET\Framework\v1.1.4322\csc.exe
- 2003-02-21 07:21:00 626,688 ----a-w C:\WINDOWS\Microsoft.NET\Framework\v1.1.4322\cscomp.dll
+ 2004-07-15 01:23:44 626,688 ----a-w C:\WINDOWS\Microsoft.NET\Framework\v1.1.4322\cscomp.dll
- 2003-02-20 16:06:20 282,624 ----a-w C:\WINDOWS\Microsoft.NET\Framework\v1.1.4322\fusion.dll
+ 2004-07-14 14:24:30 282,624 ----a-w C:\WINDOWS\Microsoft.NET\Framework\v1.1.4322\fusion.dll
+ 2003-10-08 04:30:14 81,920 ----a-w C:\WINDOWS\Microsoft.NET\Framework\v1.1.4322\gacutil.exe
- 2003-02-21 04:24:38 7,168 ----a-w C:\WINDOWS\Microsoft.NET\Framework\v1.1.4322\IEExecRemote.dll
+ 2004-07-15 04:31:00 8,192 ----a-w C:\WINDOWS\Microsoft.NET\Framework\v1.1.4322\IEExecRemote.dll
- 2003-02-21 04:24:40 32,768 ----a-w C:\WINDOWS\Microsoft.NET\Framework\v1.1.4322\IEHost.dll
+ 2004-07-15 04:31:04 32,768 ----a-w C:\WINDOWS\Microsoft.NET\Framework\v1.1.4322\IEHost.dll
- 2003-02-20 16:09:40 196,608 ----a-w C:\WINDOWS\Microsoft.NET\Framework\v1.1.4322\ilasm.exe
+ 2004-07-14 14:35:30 196,608 ----a-w C:\WINDOWS\Microsoft.NET\Framework\v1.1.4322\ilasm.exe
- 2003-02-21 04:26:36 716,800 ----a-w C:\WINDOWS\Microsoft.NET\Framework\v1.1.4322\Microsoft.JScript.dll
+ 2004-07-15 04:28:58 720,896 ----a-w C:\WINDOWS\Microsoft.NET\Framework\v1.1.4322\Microsoft.JScript.dll
- 2003-02-21 04:26:38 299,008 ----a-w C:\WINDOWS\Microsoft.NET\Framework\v1.1.4322\Microsoft.VisualBasic.dll
+ 2004-07-15 04:28:56 299,008 ----a-w C:\WINDOWS\Microsoft.NET\Framework\v1.1.4322\Microsoft.VisualBasic.dll
- 2003-02-21 04:25:04 49,152 ----a-w C:\WINDOWS\Microsoft.NET\Framework\v1.1.4322\MigPol.exe
+ 2004-07-15 04:28:50 49,152 ----a-w C:\WINDOWS\Microsoft.NET\Framework\v1.1.4322\MigPol.exe
- 2003-02-21 04:25:04 49,152 ----a-w C:\WINDOWS\Microsoft.NET\Framework\v1.1.4322\MigPolWin.exe
+ 2004-07-15 04:28:50 49,152 ----a-w C:\WINDOWS\Microsoft.NET\Framework\v1.1.4322\MigPolWin.exe
- 2003-02-20 16:09:12 77,824 ----a-w C:\WINDOWS\Microsoft.NET\Framework\v1.1.4322\mscordbc.dll
+ 2004-07-14 14:32:44 86,016 ----a-w C:\WINDOWS\Microsoft.NET\Framework\v1.1.4322\mscordbc.dll
- 2003-02-20 16:09:12 233,472 ----a-w C:\WINDOWS\Microsoft.NET\Framework\v1.1.4322\mscordbi.dll
+ 2004-07-14 14:32:46 233,472 ----a-w C:\WINDOWS\Microsoft.NET\Framework\v1.1.4322\mscordbi.dll
- 2003-02-20 16:06:32 311,296 ----a-w C:\WINDOWS\Microsoft.NET\Framework\v1.1.4322\mscorjit.dll
+ 2004-07-14 14:25:06 315,392 ----a-w C:\WINDOWS\Microsoft.NET\Framework\v1.1.4322\mscorjit.dll
- 2003-02-20 16:09:16 98,304 ----a-w C:\WINDOWS\Microsoft.NET\Framework\v1.1.4322\mscorld.dll
+ 2004-07-14 14:33:04 102,400 ----a-w C:\WINDOWS\Microsoft.NET\Framework\v1.1.4322\mscorld.dll
- 2003-02-21 04:26:34 2,088,960 ----a-w C:\WINDOWS\Microsoft.NET\Framework\v1.1.4322\mscorlib.dll
+ 2004-07-15 04:29:02 2,138,112 ----a-w C:\WINDOWS\Microsoft.NET\Framework\v1.1.4322\mscorlib.dll
- 2003-02-20 16:09:18 143,360 ----a-w C:\WINDOWS\Microsoft.NET\Framework\v1.1.4322\mscorrc.dll
+ 2004-07-14 14:33:22 143,360 ----a-w C:\WINDOWS\Microsoft.NET\Framework\v1.1.4322\mscorrc.dll
- 2003-02-20 16:09:18 81,920 ----a-w C:\WINDOWS\Microsoft.NET\Framework\v1.1.4322\mscorsec.dll
+ 2004-07-14 14:33:24 81,920 ----a-w C:\WINDOWS\Microsoft.NET\Framework\v1.1.4322\mscorsec.dll
- 2003-02-20 16:07:34 2,494,464 ----a-w C:\WINDOWS\Microsoft.NET\Framework\v1.1.4322\mscorsvr.dll
+ 2004-07-14 14:26:52 2,510,848 ----a-w C:\WINDOWS\Microsoft.NET\Framework\v1.1.4322\mscorsvr.dll
- 2003-02-20 16:08:32 2,482,176 ----a-w C:\WINDOWS\Microsoft.NET\Framework\v1.1.4322\mscorwks.dll
+ 2004-07-14 14:28:34 2,502,656 ----a-w C:\WINDOWS\Microsoft.NET\Framework\v1.1.4322\mscorwks.dll
- 2003-02-20 16:09:30 90,112 ----a-w C:\WINDOWS\Microsoft.NET\Framework\v1.1.4322\PerfCounter.dll
+ 2004-07-14 14:34:50 94,208 ----a-w C:\WINDOWS\Microsoft.NET\Framework\v1.1.4322\PerfCounter.dll
- 2003-02-21 04:26:46 32,768 ----a-w C:\WINDOWS\Microsoft.NET\Framework\v1.1.4322\RegCode.dll
+ 2004-07-15 04:28:48 32,768 ----a-w C:\WINDOWS\Microsoft.NET\Framework\v1.1.4322\RegCode.dll
- 2003-02-20 16:09:34 319,488 ----a-w C:\WINDOWS\Microsoft.NET\Framework\v1.1.4322\SOS.dll
+ 2004-07-14 14:35:04 319,488 ----a-w C:\WINDOWS\Microsoft.NET\Framework\v1.1.4322\SOS.dll
- 2003-02-21 04:26:38 1,290,240 ----a-w C:\WINDOWS\Microsoft.NET\Framework\v1.1.4322\System.Data.dll
+ 2004-07-15 04:32:00 1,294,336 ----a-w C:\WINDOWS\Microsoft.NET\Framework\v1.1.4322\System.Data.dll
- 2003-02-21 04:25:42 299,008 ----a-w C:\WINDOWS\Microsoft.NET\Framework\v1.1.4322\System.Data.OracleClient.dll
+ 2004-07-15 04:31:14 303,104 ----a-w C:\WINDOWS\Microsoft.NET\Framework\v1.1.4322\System.Data.OracleClient.dll
- 2003-02-21 04:26:42 1,699,840 ----a-w C:\WINDOWS\Microsoft.NET\Framework\v1.1.4322\System.Design.dll
+ 2004-07-15 04:29:02 1,703,936 ----a-w C:\WINDOWS\Microsoft.NET\Framework\v1.1.4322\System.Design.dll
- 2003-02-21 04:26:44 86,016 ----a-w C:\WINDOWS\Microsoft.NET\Framework\v1.1.4322\System.DirectoryServices.dll
+ 2004-07-15 04:28:54 90,112 ----a-w C:\WINDOWS\Microsoft.NET\Framework\v1.1.4322\System.DirectoryServices.dll
- 2003-02-21 04:26:46 1,216,512 ----a-w C:\WINDOWS\Microsoft.NET\Framework\v1.1.4322\System.dll
+ 2004-07-15 04:31:16 1,224,704 ----a-w C:\WINDOWS\Microsoft.NET\Framework\v1.1.4322\System.dll
- 2003-02-21 04:26:50 466,944 ----a-w C:\WINDOWS\Microsoft.NET\Framework\v1.1.4322\System.Drawing.dll
+ 2004-07-15 04:28:58 466,944 ----a-w C:\WINDOWS\Microsoft.NET\Framework\v1.1.4322\System.Drawing.dll
- 2003-02-21 04:26:50 241,664 ----a-w C:\WINDOWS\Microsoft.NET\Framework\v1.1.4322\System.EnterpriseServices.dll
+ 2004-07-15 04:28:56 241,664 ----a-w C:\WINDOWS\Microsoft.NET\Framework\v1.1.4322\System.EnterpriseServices.dll
- 2003-02-20 16:09:36 64,000 ----a-w C:\WINDOWS\Microsoft.NET\Framework\v1.1.4322\System.EnterpriseServices.Thunk.dll
+ 2004-07-14 14:35:12 66,560 ----a-w C:\WINDOWS\Microsoft.NET\Framework\v1.1.4322\System.EnterpriseServices.Thunk.dll
- 2003-02-21 04:26:52 368,640 ----a-w C:\WINDOWS\Microsoft.NET\Framework\v1.1.4322\System.Management.dll
+ 2004-07-15 04:31:58 372,736 ----a-w C:\WINDOWS\Microsoft.NET\Framework\v1.1.4322\System.Management.dll
- 2003-02-21 04:26:54 241,664 ----a-w C:\WINDOWS\Microsoft.NET\Framework\v1.1.4322\System.Messaging.dll
+ 2004-07-15 04:31:12 241,664 ----a-w C:\WINDOWS\Microsoft.NET\Framework\v1.1.4322\System.Messaging.dll
- 2003-02-21 04:26:56 323,584 ----a-w C:\WINDOWS\Microsoft.NET\Framework\v1.1.4322\System.Runtime.Remoting.dll
+ 2004-07-15 04:28:58 323,584 ----a-w C:\WINDOWS\Microsoft.NET\Framework\v1.1.4322\System.Runtime.Remoting.dll
- 2003-02-21 04:26:56 131,072 ----a-w C:\WINDOWS\Microsoft.NET\Framework\v1.1.4322\System.Runtime.Serialization.Formatters.Soap.dll
+ 2004-07-15 04:31:54 131,072 ----a-w C:\WINDOWS\Microsoft.NET\Framework\v1.1.4322\System.Runtime.Serialization.Formatters.Soap.dll
- 2003-02-21 04:26:58 77,824 ----a-w C:\WINDOWS\Microsoft.NET\Framework\v1.1.4322\System.Security.dll
+ 2004-07-15 04:28:52 77,824 ----a-w C:\WINDOWS\Microsoft.NET\Framework\v1.1.4322\System.Security.dll
- 2003-02-21 04:27:00 126,976 ----a-w C:\WINDOWS\Microsoft.NET\Framework\v1.1.4322\System.ServiceProcess.dll
+ 2004-07-15 04:28:54 126,976 ----a-w C:\WINDOWS\Microsoft.NET\Framework\v1.1.4322\System.ServiceProcess.dll
- 2003-02-21 04:27:02 1,245,184 ----a-w C:\WINDOWS\Microsoft.NET\Framework\v1.1.4322\System.Web.dll
+ 2004-07-15 04:29:00 1,257,472 ----a-w C:\WINDOWS\Microsoft.NET\Framework\v1.1.4322\System.Web.dll
- 2003-02-21 04:27:06 819,200 ----a-w C:\WINDOWS\Microsoft.NET\Framework\v1.1.4322\System.Web.Mobile.dll
+ 2004-07-15 04:28:58 819,200 ----a-w C:\WINDOWS\Microsoft.NET\Framework\v1.1.4322\System.Web.Mobile.dll
- 2003-02-21 04:24:18 57,344 ----a-w C:\WINDOWS\Microsoft.NET\Framework\v1.1.4322\System.Web.RegularExpressions.dll
+ 2004-07-15 04:28:52 57,344 ----a-w C:\WINDOWS\Microsoft.NET\Framework\v1.1.4322\System.Web.RegularExpressions.dll
- 2003-02-21 04:27:06 569,344 ----a-w C:\WINDOWS\Microsoft.NET\Framework\v1.1.4322\System.Web.Services.dll
+ 2004-07-15 04:31:16 573,440 ----a-w C:\WINDOWS\Microsoft.NET\Framework\v1.1.4322\System.Web.Services.dll
- 2003-02-21 04:27:08 2,039,808 ----a-w C:\WINDOWS\Microsoft.NET\Framework\v1.1.4322\System.Windows.Forms.dll
+ 2004-07-15 04:32:02 2,052,096 ----a-w C:\WINDOWS\Microsoft.NET\Framework\v1.1.4322\System.Windows.Forms.dll
- 2003-02-21 04:27:10 1,335,296 ----a-w C:\WINDOWS\Microsoft.NET\Framework\v1.1.4322\System.XML.dll
+ 2004-07-15 04:29:00 1,339,392 ----a-w C:\WINDOWS\Microsoft.NET\Framework\v1.1.4322\System.XML.dll
+ 2004-06-22 03:51:38 53,248 ----a-w C:\WINDOWS\Microsoft.NET\Framework\v1.1.4322\Updates\hotfix.exe
- 2003-02-21 07:20:38 737,280 ----a-w C:\WINDOWS\Microsoft.NET\Framework\v1.1.4322\vbc.exe
+ 2004-07-15 01:23:20 737,280 ----a-w C:\WINDOWS\Microsoft.NET\Framework\v1.1.4322\vbc.exe
- 2003-02-21 02:04:18 1,032,192 ----a-w C:\WINDOWS\Microsoft.NET\Framework\v1.1.4322\VsaVb7rt.dll
+ 2004-07-14 22:15:14 1,032,192 ----a-w C:\WINDOWS\Microsoft.NET\Framework\v1.1.4322\VsaVb7rt.dll
- 2003-02-20 17:10:40 31,744 ----a-w C:\WINDOWS\Microsoft.NET\Framework\v1.1.4322\WMINet_Utils.dll
+ 2004-07-14 16:11:56 31,744 ----a-w C:\WINDOWS\Microsoft.NET\Framework\v1.1.4322\WMINet_Utils.dll
- 2004-08-04 12:00:00 61,440 ----a-w C:\WINDOWS\system32\admparse.dll
+ 2007-08-13 08:39:20 71,680 ----a-w C:\WINDOWS\system32\admparse.dll
- 2004-08-04 12:00:00 99,840 ----a-w C:\WINDOWS\system32\advpack.dll
+ 2007-08-13 08:39:00 123,904 ----a-w C:\WINDOWS\system32\advpack.dll
- 2007-08-22 13:12:15 1,022,976 ----a-w C:\WINDOWS\system32\browseui.dll
+ 2007-10-11 06:13:44 1,023,488 ----a-w C:\WINDOWS\system32\browseui.dll
- 2007-08-22 13:12:15 151,040 ----a-w C:\WINDOWS\system32\cdfview.dll
+ 2007-10-11 06:13:44 151,040 ----a-w C:\WINDOWS\system32\cdfview.dll
- 2007-08-22 13:12:16 1,054,208 ----a-w C:\WINDOWS\system32\danim.dll
+ 2007-10-11 06:13:44 1,054,208 ----a-w C:\WINDOWS\system32\danim.dll
- 2004-08-04 12:00:00 61,440 -c--a-w C:\WINDOWS\system32\dllcache\admparse.dll
+ 2007-08-13 08:39:20 71,680 -c--a-w C:\WINDOWS\system32\dllcache\admparse.dll
- 2004-08-04 12:00:00 99,840 -c--a-w C:\WINDOWS\system32\dllcache\advpack.dll
+ 2007-08-13 08:39:00 123,904 -c--a-w C:\WINDOWS\system32\dllcache\advpack.dll
- 2007-08-22 13:12:15 1,022,976 -c--a-w C:\WINDOWS\system32\dllcache\browseui.dll
+ 2007-10-11 06:13:44 1,023,488 -c--a-w C:\WINDOWS\system32\dllcache\browseui.dll
- 2007-08-22 13:12:15 151,040 -c--a-w C:\WINDOWS\system32\dllcache\cdfview.dll
+ 2007-10-11 06:13:44 151,040 -c--a-w C:\WINDOWS\system32\dllcache\cdfview.dll
- 2004-08-04 12:00:00 28,672 -c--a-w C:\WINDOWS\system32\dllcache\custsat.dll
+ 2007-08-13 08:54:10 33,792 -c--a-w C:\WINDOWS\system32\dllcache\custsat.dll
- 2007-08-22 13:12:16 1,054,208 -c--a-w C:\WINDOWS\system32\dllcache\danim.dll
+ 2007-10-11 06:13:44 1,054,208 -c--a-w C:\WINDOWS\system32\dllcache\danim.dll
- 2007-08-22 13:12:16 357,888 -c--a-w C:\WINDOWS\system32\dllcache\dxtmsft.dll
+ 2007-08-13 08:35:46 346,624 -c--a-w C:\WINDOWS\system32\dllcache\dxtmsft.dll
- 2007-08-22 13:12:16 205,312 -c--a-w C:\WINDOWS\system32\dllcache\dxtrans.dll
+ 2007-08-13 08:35:38 214,528 -c--a-w C:\WINDOWS\system32\dllcache\dxtrans.dll
- 2007-08-22 13:12:16 55,808 -c--a-w C:\WINDOWS\system32\dllcache\extmgr.dll
+ 2007-08-13 08:54:10 131,584 -c--a-w C:\WINDOWS\system32\dllcache\extmgr.dll
- 2004-08-04 12:00:00 38,912 -c--a-w C:\WINDOWS\system32\dllcache\hmmapi.dll
+ 2007-08-13 08:18:02 60,416 -c--a-w C:\WINDOWS\system32\dllcache\hmmapi.dll
- 2004-08-04 12:00:00 34,304 -c--a-w C:\WINDOWS\system32\dllcache\ie4uinit.exe
+ 2007-08-13 08:39:06 54,784 -c--a-w C:\WINDOWS\system32\dllcache\ie4uinit.exe
- 2004-08-04 12:00:00 139,264 -c--a-w C:\WINDOWS\system32\dllcache\ieakeng.dll
+ 2007-08-13 08:39:26 152,064 -c--a-w C:\WINDOWS\system32\dllcache\ieakeng.dll
- 2004-08-04 12:00:00 216,576 -c--a-w C:\WINDOWS\system32\dllcache\ieaksie.dll
+ 2007-08-13 08:39:54 229,376 -c--a-w C:\WINDOWS\system32\dllcache\ieaksie.dll
- 2004-08-04 12:00:00 221,184 -c--a-w C:\WINDOWS\system32\dllcache\ieakui.dll
+ 2007-08-13 07:56:54 161,792 -c--a-w C:\WINDOWS\system32\dllcache\ieakui.dll
- 2004-08-04 12:00:00 323,584 -c--a-w C:\WINDOWS\system32\dllcache\iedkcs32.dll
+ 2007-08-13 08:39:50 382,976 -c--a-w C:\WINDOWS\system32\dllcache\iedkcs32.dll
- 2007-08-21 10:30:45 18,432 -c--a-w C:\WINDOWS\system32\dllcache\iedw.exe
+ 2007-08-13 08:44:02 69,120 -c--a-w C:\WINDOWS\system32\dllcache\iedw.exe
- 2004-08-04 12:00:00 81,920 -c--a-w C:\WINDOWS\system32\dllcache\ieencode.dll
+ 2007-08-13 08:45:18 78,336 -c--a-w C:\WINDOWS\system32\dllcache\ieencode.dll
- 2007-08-22 13:12:16 251,392 -c--a-w C:\WINDOWS\system32\dllcache\iepeers.dll
+ 2007-08-13 08:54:10 191,488 -c--a-w C:\WINDOWS\system32\dllcache\iepeers.dll
- 2004-08-04 12:00:00 48,640 -c--a-w C:\WINDOWS\system32\dllcache\iernonce.dll
+ 2007-08-13 08:39:10 43,008 -c--a-w C:\WINDOWS\system32\dllcache\iernonce.dll
- 2004-08-04 12:00:00 62,976 -c--a-w C:\WINDOWS\system32\dllcache\iesetup.dll
+ 2007-08-13 08:39:12 55,296 -c--a-w C:\WINDOWS\system32\dllcache\iesetup.dll
- 2004-08-04 12:00:00 93,184 -c--a-w C:\WINDOWS\system32\dllcache\iexplore.exe
+ 2007-08-13 08:43:56 622,080 -c--a-w C:\WINDOWS\system32\dllcache\iexplore.exe
- 2004-08-04 12:00:00 35,840 -c--a-w C:\WINDOWS\system32\dllcache\imgutil.dll
+ 2007-08-13 08:36:06 36,352 -c--a-w C:\WINDOWS\system32\dllcache\imgutil.dll
- 2007-08-22 13:12:16 96,256 -c--a-w C:\WINDOWS\system32\dllcache\inseng.dll
+ 2007-08-13 08:39:02 92,672 -c--a-w C:\WINDOWS\system32\dllcache\inseng.dll
- 2006-05-18 05:24:25 450,560 -c--a-w C:\WINDOWS\system32\dllcache\jscript.dll
+ 2007-08-13 08:38:04 491,520 -c--a-w C:\WINDOWS\system32\dllcache\jscript.dll
- 2007-08-22 13:12:16 16,384 -c--a-w C:\WINDOWS\system32\dllcache\jsproxy.dll
+ 2007-08-13 08:54:10 27,136 -c--a-w C:\WINDOWS\system32\dllcache\jsproxy.dll
- 2004-08-04 12:00:00 22,016 -c--a-w C:\WINDOWS\system32\dllcache\licmgr10.dll
+ 2007-08-13 08:44:18 40,960 -c--a-w C:\WINDOWS\system32\dllcache\licmgr10.dll
- 2006-08-17 12:28:27 721,920 -c--a-w C:\WINDOWS\system32\dllcache\lsasrv.dll
+ 2007-11-07 09:26:56 721,920 -c--a-w C:\WINDOWS\system32\dllcache\lsasrv.dll
- 2004-08-04 12:00:00 29,184 -c--a-w C:\WINDOWS\system32\dllcache\mshta.exe
+ 2007-08-13 08:32:30 45,568 -c--a-w C:\WINDOWS\system32\dllcache\mshta.exe
- 2007-08-22 13:12:17 3,058,176 -c--a-w C:\WINDOWS\system32\dllcache\mshtml.dll
+ 2007-08-13 08:54:12 3,578,368 -c--a-w C:\WINDOWS\system32\dllcache\mshtml.dll
- 2007-08-22 13:12:17 449,024 -c--a-w C:\WINDOWS\system32\dllcache\mshtmled.dll
+ 2007-08-13 08:54:10 475,648 -c--a-w C:\WINDOWS\system32\dllcache\mshtmled.dll
- 2004-08-04 12:00:00 56,832 -c--a-w C:\WINDOWS\system32\dllcache\mshtmler.dll
+ 2007-08-13 08:01:12 48,128 -c--a-w C:\WINDOWS\system32\dllcache\mshtmler.dll
- 2004-08-04 12:00:00 146,432 -c--a-w C:\WINDOWS\system32\dllcache\msls31.dll
+ 2007-08-13 08:54:10 156,160 -c--a-w C:\WINDOWS\system32\dllcache\msls31.dll
- 2007-08-22 13:12:17 146,432 -c--a-w C:\WINDOWS\system32\dllcache\msrating.dll
+ 2007-08-13 08:44:26 192,000 -c--a-w C:\WINDOWS\system32\dllcache\msrating.dll
- 2007-08-22 13:12:17 532,480 -c--a-w C:\WINDOWS\system32\dllcache\mstime.dll
+ 2007-08-13 08:54:10 670,720 -c--a-w C:\WINDOWS\system32\dllcache\mstime.dll
- 2004-08-04 12:00:00 96,256 -c--a-w C:\WINDOWS\system32\dllcache\occache.dll
+ 2007-08-13 08:44:06 101,376 -c--a-w C:\WINDOWS\system32\dllcache\occache.dll
- 2007-08-22 13:12:17 39,424 -c--a-w C:\WINDOWS\system32\dllcache\pngfilt.dll
+ 2007-08-13 08:36:12 44,544 -c--a-w C:\WINDOWS\system32\dllcache\pngfilt.dll
- 2005-08-30 03:54:26 1,287,168 -c--a-w C:\WINDOWS\system32\dllcache\quartz.dll
+ 2007-10-29 22:43:03 1,287,680 -c--a-w C:\WINDOWS\system32\dllcache\quartz.dll
- 2007-08-22 13:12:18 1,494,528 -c--a-w C:\WINDOWS\system32\dllcache\shdocvw.dll
+ 2007-10-11 06:13:45 1,494,528 -c--a-w C:\WINDOWS\system32\dllcache\shdocvw.dll
- 2007-08-22 13:12:18 474,112 -c--a-w C:\WINDOWS\system32\dllcache\shlwapi.dll
+ 2007-10-11 06:13:45 474,112 -c--a-w C:\WINDOWS\system32\dllcache\shlwapi.dll
- 2006-04-20 11:51:50 359,808 -c--a-w C:\WINDOWS\system32\dllcache\tcpip.sys
+ 2007-10-30 17:20:55 360,064 -c--a-w C:\WINDOWS\system32\dllcache\tcpip.sys
- 2004-08-04 12:00:00 37,888 -c--a-w C:\WINDOWS\system32\dllcache\url.dll
+ 2007-08-13 08:44:30 105,984 -c--a-w C:\WINDOWS\system32\dllcache\url.dll
- 2007-08-22 13:12:18 615,424 -c--a-w C:\WINDOWS\system32\dllcache\urlmon.dll
+ 2007-08-13 08:54:10 1,162,240 -c--a-w C:\WINDOWS\system32\dllcache\urlmon.dll
- 2004-08-04 12:00:00 417,792 -c--a-w C:\WINDOWS\system32\dllcache\vbscript.dll
+ 2007-08-13 08:54:10 413,696 -c--a-w C:\WINDOWS\system32\dllcache\vbscript.dll
- 2007-06-26 15:13:22 851,968 -c--a-w C:\WINDOWS\system32\dllcache\vgx.dll
+ 2007-08-13 08:54:10 765,952 -c--a-w C:\WINDOWS\system32\dllcache\VGX.dll
- 2004-08-04 12:00:00 276,480 -c--a-w C:\WINDOWS\system32\dllcache\webcheck.dll
+ 2007-08-13 08:54:10 231,424 -c--a-w C:\WINDOWS\system32\dllcache\webcheck.dll
- 2007-08-22 13:12:18 658,944 -c--a-w C:\WINDOWS\system32\dllcache\wininet.dll
+ 2007-08-13 08:54:10 818,688 -c--a-w C:\WINDOWS\system32\dllcache\wininet.dll
- 2004-08-04 12:00:00 230,400 -c--a-w C:\WINDOWS\system32\dllcache\wmasf.dll
+ 2007-10-27 07:39:20 230,912 -c--a-w C:\WINDOWS\system32\dllcache\wmasf.dll
- 2006-12-07 07:02:24 2,174,976 -c--a-w C:\WINDOWS\system32\dllcache\wmvcore.dll
+ 2007-10-27 07:37:38 2,109,440 -c--a-w C:\WINDOWS\system32\dllcache\wmvcore.dll
- 2004-08-04 12:00:00 27,440 ----a-w C:\WINDOWS\system32\drivers\secdrv.sys
+ 2007-11-13 10:25:53 20,480 ----a-w C:\WINDOWS\system32\drivers\secdrv.sys
- 2006-04-20 11:51:50 359,808 ----a-w C:\WINDOWS\system32\drivers\tcpip.sys
+ 2007-10-30 17:20:55 360,064 ----a-w C:\WINDOWS\system32\drivers\tcpip.sys
- 2007-08-22 13:12:16 357,888 ----a-w C:\WINDOWS\system32\dxtmsft.dll
+ 2007-08-13 08:35:46 346,624 ----a-w C:\WINDOWS\system32\dxtmsft.dll
- 2007-08-22 13:12:16 205,312 ----a-w C:\WINDOWS\system32\dxtrans.dll
+ 2007-08-13 08:35:38 214,528 ----a-w C:\WINDOWS\system32\dxtrans.dll
- 2007-08-22 13:12:16 55,808 ----a-w C:\WINDOWS\system32\extmgr.dll
+ 2007-08-13 08:54:10 131,584 ----a-w C:\WINDOWS\system32\extmgr.dll
+ 2007-08-13 08:36:26 61,952 ------w C:\WINDOWS\system32\icardie.dll
+ 2006-06-28 22:05:44 26,112 ------w C:\WINDOWS\system32\idndl.dll
- 2004-08-04 12:00:00 34,304 ----a-w C:\WINDOWS\system32\ie4uinit.exe
+ 2007-08-13 08:39:06 54,784 ----a-w C:\WINDOWS\system32\ie4uinit.exe
- 2004-08-04 12:00:00 139,264 ----a-w C:\WINDOWS\system32\ieakeng.dll
+ 2007-08-13 08:39:26 152,064 ----a-w C:\WINDOWS\system32\ieakeng.dll
- 2004-08-04 12:00:00 216,576 ----a-w C:\WINDOWS\system32\ieaksie.dll
+ 2007-08-13 08:39:54 229,376 ----a-w C:\WINDOWS\system32\ieaksie.dll
- 2004-08-04 12:00:00 221,184 ----a-w C:\WINDOWS\system32\ieakui.dll
+ 2007-08-13 07:56:54 161,792 ----a-w C:\WINDOWS\system32\ieakui.dll
+ 2007-02-12 06:10:12 2,451,312 ------w C:\WINDOWS\system32\ieapfltr.dat
+ 2007-07-11 02:27:48 383,488 ------w C:\WINDOWS\system32\ieapfltr.dll
- 2004-08-04 12:00:00 323,584 ----a-w C:\WINDOWS\system32\iedkcs32.dll
+ 2007-08-13 08:39:50 382,976 ----a-w C:\WINDOWS\system32\iedkcs32.dll
- 2004-08-04 12:00:00 81,920 ----a-w C:\WINDOWS\system32\ieencode.dll
+ 2007-08-13 08:45:18 78,336 ----a-w C:\WINDOWS\system32\ieencode.dll
+ 2007-08-13 08:54:10 6,049,280 ------w C:\WINDOWS\system32\ieframe.dll
- 2007-08-22 13:12:16 251,392 ----a-w C:\WINDOWS\system32\iepeers.dll
+ 2007-08-13 08:54:10 191,488 ----a-w C:\WINDOWS\system32\iepeers.dll
- 2004-08-04 12:00:00 48,640 ----a-w C:\WINDOWS\system32\iernonce.dll
+ 2007-08-13 08:39:10 43,008 ----a-w C:\WINDOWS\system32\iernonce.dll
+ 2007-08-13 08:34:04 266,752 ------w C:\WINDOWS\system32\iertutil.dll
- 2004-08-04 12:00:00 62,976 ----a-w C:\WINDOWS\system32\iesetup.dll
+ 2007-08-13 08:39:12 55,296 ----a-w C:\WINDOWS\system32\iesetup.dll
+ 2007-08-13 08:39:10 13,312 ----a-w C:\WINDOWS\system32\ieudinit.exe
+ 2007-08-13 08:54:10 180,736 ------w C:\WINDOWS\system32\ieui.dll
- 2004-08-04 12:00:00 35,840 ----a-w C:\WINDOWS\system32\imgutil.dll
+ 2007-08-13 08:36:06 36,352 ----a-w C:\WINDOWS\system32\imgutil.dll
- 2007-08-22 13:12:16 96,256 ----a-w C:\WINDOWS\system32\inseng.dll
+ 2007-08-13 08:39:02 92,672 ----a-w C:\WINDOWS\system32\inseng.dll
- 2006-05-18 05:24:25 450,560 ----a-w C:\WINDOWS\system32\jscript.dll
+ 2007-08-13 08:38:04 491,520 ----a-w C:\WINDOWS\system32\jscript.dll
- 2007-08-22 13:12:16 16,384 ----a-w C:\WINDOWS\system32\jsproxy.dll
+ 2007-08-13 08:54:10 27,136 ----a-w C:\WINDOWS\system32\jsproxy.dll
+ 2005-05-24 02:27:16 213,048 ----a-w C:\WINDOWS\system32\Kaspersky Lab\Kaspersky Online Scanner\kavss.dll
+ 2007-08-29 05:47:20 94,208 ----a-w C:\WINDOWS\system32\Kaspersky Lab\Kaspersky Online Scanner\kavuninstall.exe
+ 2007-08-29 05:49:54 950,272 ----a-w C:\WINDOWS\system32\Kaspersky Lab\Kaspersky Online Scanner\kavwebscan.dll
+ 2007-10-11 04:12:48 1,468,968 ------w C:\WINDOWS\system32\LegitCheckControl.dll
- 2004-08-04 12:00:00 22,016 ----a-w C:\WINDOWS\system32\licmgr10.dll
+ 2007-08-13 08:44:18 40,960 ----a-w C:\WINDOWS\system32\licmgr10.dll
+ 2007-07-27 05:49:02 196,683 ----a-w C:\WINDOWS\system32\lnod32apiA.dll
+ 2007-07-27 05:49:02 225,355 ----a-w C:\WINDOWS\system32\lnod32apiW.dll
+ 2005-12-05 10:25:22 139,264 ----a-w C:\WINDOWS\system32\lnod32umc.dll
+ 2005-12-05 03:37:10 106,496 ----a-w C:\WINDOWS\system32\lnod32upd.dll
- 2006-08-17 12:28:27 721,920 ----a-w C:\WINDOWS\system32\lsasrv.dll
+ 2007-11-07 09:26:56 721,920 ----a-w C:\WINDOWS\system32\lsasrv.dll
+ 2008-01-02 00:21:38 17,642,616 ----a-w C:\WINDOWS\system32\MRT.exe
- 2003-02-20 16:06:24 155,648 ----a-w C:\WINDOWS\system32\mscoree.dll
+ 2004-07-14 14:24:50 155,648 ----a-w C:\WINDOWS\system32\mscoree.dll
- 2003-02-20 15:43:38 16,896 ----a-w C:\WINDOWS\system32\mscorier.dll
+ 2004-07-14 13:34:06 16,896 ----a-w C:\WINDOWS\system32\mscorier.dll
+ 2007-08-13 08:54:10 458,752 ------w C:\WINDOWS\system32\msfeeds.dll
+ 2007-08-13 08:54:10 50,688 ------w C:\WINDOWS\system32\msfeedsbs.dll
+ 2007-08-13 08:36:40 12,288 ------w C:\WINDOWS\system32\msfeedssync.exe
- 2004-08-04 12:00:00 29,184 ----a-w C:\WINDOWS\system32\mshta.exe
+ 2007-08-13 08:32:30 45,568 ----a-w C:\WINDOWS\system32\mshta.exe
- 2007-08-22 13:12:17 3,058,176 ----a-w C:\WINDOWS\system32\mshtml.dll
+ 2007-08-13 08:54:12 3,578,368 ----a-w C:\WINDOWS\system32\mshtml.dll
- 2007-08-22 13:12:17 449,024 ----a-w C:\WINDOWS\system32\mshtmled.dll
+ 2007-08-13 08:54:10 475,648 ----a-w C:\WINDOWS\system32\mshtmled.dll
- 2004-08-04 12:00:00 56,832 ----a-w C:\WINDOWS\system32\mshtmler.dll
+ 2007-08-13 08:01:12 48,128 ----a-w C:\WINDOWS\system32\mshtmler.dll
- 2004-08-04 12:00:00 146,432 ----a-w C:\WINDOWS\system32\msls31.dll
+ 2007-08-13 08:54:10 156,160 ----a-w C:\WINDOWS\system32\msls31.dll
- 2007-08-22 13:12:17 146,432 ----a-w C:\WINDOWS\system32\msrating.dll
+ 2007-08-13 08:44:26 192,000 ----a-w C:\WINDOWS\system32\msrating.dll
- 2007-08-22 13:12:17 532,480 ----a-w C:\WINDOWS\system32\mstime.dll
+ 2007-08-13 08:54:10 670,720 ----a-w C:\WINDOWS\system32\mstime.dll
+ 2006-06-28 07:59:26 24,576 ------w C:\WINDOWS\system32\nlsdl.dll
+ 2006-06-28 22:05:44 23,552 ------w C:\WINDOWS\system32\normaliz.dll
- 2004-08-04 12:00:00 96,256 ----a-w C:\WINDOWS\system32\occache.dll
+ 2007-08-13 08:44:06 101,376 ----a-w C:\WINDOWS\system32\occache.dll
+ 2007-08-02 08:11:28 253,952 ----a-w C:\WINDOWS\system32\OnlineScannerDLLA.dll
+ 2007-08-02 08:11:14 241,664 ----a-w C:\WINDOWS\system32\OnlineScannerDLLW.dll
+ 2007-08-08 06:30:12 19,456 ----a-w C:\WINDOWS\system32\OnlineScannerLang.dll
+ 2007-06-13 01:10:34 77,824 ----a-w C:\WINDOWS\system32\OnlineScannerUninstaller.exe
- 2007-10-01 10:25:52 53,436 ----a-w C:\WINDOWS\system32\perfc009.dat
+ 2008-01-15 16:34:10 53,436 ----a-w C:\WINDOWS\system32\perfc009.dat
- 2007-10-01 10:25:52 381,692 ----a-w C:\WINDOWS\system32\perfh009.dat
+ 2008-01-15 16:34:10 381,692 ----a-w C:\WINDOWS\system32\perfh009.dat
- 2007-08-22 13:12:17 39,424 ----a-w C:\WINDOWS\system32\pngfilt.dll
+ 2007-08-13 08:36:12 44,544 ----a-w C:\WINDOWS\system32\pngfilt.dll
- 2005-08-30 03:54:26 1,287,168 ----a-w C:\WINDOWS\system32\quartz.dll
+ 2007-10-29 22:43:03 1,287,680 ----a-w C:\WINDOWS\system32\quartz.dll
- 2007-08-22 13:12:18 1,494,528 ----a-w C:\WINDOWS\system32\shdocvw.dll
+ 2007-10-11 06:13:45 1,494,528 ----a-w C:\WINDOWS\system32\shdocvw.dll
- 2007-08-22 13:12:18 474,112 ----a-w C:\WINDOWS\system32\shlwapi.dll
+ 2007-10-11 06:13:45 474,112 ----a-w C:\WINDOWS\system32\shlwapi.dll
- 2007-03-06 01:22:33 14,048 ----a-w C:\WINDOWS\system32\spmsg.dll
+ 2007-10-08 04:46:18 14,640 ------w C:\WINDOWS\system32\spmsg.dll
- 2005-06-28 00:21:34 22,752 ----a-w C:\WINDOWS\system32\spupdsvc.exe
+ 2006-09-06 07:43:16 22,752 ----a-w C:\WINDOWS\system32\spupdsvc.exe
- 2007-07-18 12:42:22 60,416 ----a-w C:\WINDOWS\system32\tzchange.exe
+ 2007-11-13 11:31:11 60,416 ----a-w C:\WINDOWS\system32\tzchange.exe
+ 2004-12-07 01:11:34 258,352 ----a-w C:\WINDOWS\system32\unicows.dll
- 2004-08-04 12:00:00 37,888 ----a-w C:\WINDOWS\system32\url.dll
+ 2007-08-13 08:44:30 105,984 ----a-w C:\WINDOWS\system32\url.dll
- 2007-08-22 13:12:18 615,424 ----a-w C:\WINDOWS\system32\urlmon.dll
+ 2007-08-13 08:54:10 1,162,240 ----a-w C:\WINDOWS\system32\urlmon.dll
- 2004-08-04 12:00:00 417,792 ----a-w C:\WINDOWS\system32\vbscript.dll
+ 2007-08-13 08:54:10 413,696 ----a-w C:\WINDOWS\system32\vbscript.dll
- 2004-08-04 12:00:00 276,480 ----a-w C:\WINDOWS\system32\webcheck.dll
+ 2007-08-13 08:54:10 231,424 ----a-w C:\WINDOWS\system32\webcheck.dll
+ 2007-08-13 08:45:16 206,336 ------w C:\WINDOWS\system32\WinFXDocObj.exe
- 2007-08-22 13:12:18 658,944 ----a-w C:\WINDOWS\system32\wininet.dll
+ 2007-08-13 08:54:10 818,688 ----a-w C:\WINDOWS\system32\wininet.dll
- 2004-08-04 12:00:00 230,400 ----a-w C:\WINDOWS\system32\wmasf.dll
+ 2007-10-27 07:39:20 230,912 ----a-w C:\WINDOWS\system32\wmasf.dll
- 2006-12-07 07:02:24 2,174,976 ----a-w C:\WINDOWS\system32\wmvcore.dll
+ 2007-10-27 07:37:38 2,109,440 ----a-w C:\WINDOWS\system32\wmvcore.dll
+ 2006-07-14 15:51:51 121,856 ------w C:\WINDOWS\system32\xmllite.dll
.
-- Snapshot reset to current date --
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"SUPERAntiSpyware"="C:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe" [2007-06-21 14:06 1318912]
"ctfmon.exe"="C:\WINDOWS\system32\ctfmon.exe" [2004-08-04 22:00 15360]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"IMJPMIG8.1"="C:\WINDOWS\IME\imjp8_1\IMJPMIG.exe" [2004-08-05 05:00 208952]
"MSPY2002"="C:\WINDOWS\system32\IME\PINTLGNT\ImScInst.exe" [ ]
"PHIME2002ASync"="C:\WINDOWS\system32\IME\TINTLGNT\TINTSETP.exe" [2004-08-05 05:00 455168]
"PHIME2002A"="C:\WINDOWS\system32\IME\TINTLGNT\TINTSETP.exe" [2004-08-05 05:00 455168]
"TkBellExe"="C:\Program Files\Common Files\Real\Update_OB\realsched.exe" [ ]
"SoundMan"="SOUNDMAN.EXE" [2004-07-01 18:58 73728 C:\WINDOWS\SOUNDMAN.EXE]
"ATIPTA"="C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe" [ ]
"AlcWzrd"="ALCWZRD.EXE" [2004-07-06 01:05 2550272 C:\WINDOWS\ALCWZRD.EXE]
"AVG7_CC"="C:\PROGRA~1\Grisoft\AVG7\avgcc.exe" [ ]
"iTunesHelper"="C:\Program Files\iTunes\iTunesHelper.exe" [ ]
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"AVG7_Run"="C:\PROGRA~1\Grisoft\AVG7\avgw.exe" [2007-10-25 09:58 219136]
C:\Documents and Settings\HP_Owner\Start Menu\Programs\Startup\
Xfire.lnk - C:\Program Files\Xfire\xfire.exe [2007-12-05 12:25:52 2858832]
C:\Documents and Settings\All Users\Start Menu\Programs\Startup\
HP Digital Imaging Monitor.lnk - C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe [2004-05-29 05:31:38 241664]
Microsoft Office.lnk - C:\Program Files\Microsoft Office\Office10\OSA.EXE [2001-02-13 01:01:04 83360]
[hkey_local_machine\software\microsoft\windows\currentversion\explorer\shellexecutehooks]
"{5AE067D3-9AFB-48E0-853A-EBB7F4A000DA}"= C:\Program Files\SUPERAntiSpyware\SASSEH.DLL [2006-12-20 13:55 77824]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\!SASWinLogon]
C:\Program Files\SUPERAntiSpyware\SASWINLO.dll 2007-04-19 13:41 294912 C:\Program Files\SUPERAntiSpyware\SASWINLO.dll
R3 Cap7134;ASUS TV7134 WDM Video Capture;C:\WINDOWS\system32\DRIVERS\Cap7134.sys [2004-06-23 20:34]
R3 PhTVTune;ASUS WDM TV Tuner;C:\WINDOWS\system32\DRIVERS\PhTVTune.sys [2004-05-27 18:49]
.
Contents of the 'Scheduled Tasks' folder
"2008-01-18 23:17:01 C:\WINDOWS\Tasks\AppleSoftwareUpdate.job"
- C:\Program Files\Apple Software Update\SoftwareUpdate.exe
.
**************************************************************************
catchme 0.3.1344 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2008-01-20 12:55:13
Windows 5.1.2600 Service Pack 2 NTFS
scanning hidden processes ...
scanning hidden autostart entries ...
scanning hidden files ...
scan completed successfully
hidden files: 0
**************************************************************************
.
Completion time: 2008-01-20 12:57:46 - machine was rebooted
ComboFix-quarantined-files.txt 2008-01-20 02:57:43
ComboFix2.txt 2008-01-12 16:48:19
.
2008-01-15 16:34:41 --- E O F ---
Good Morning,
This will run Combofix again but the report wont be so long.
Open Notepad and copy all the text inside the quote box by highlighting it all and pressing CTRL C on your keyboard, then paste it into Notepad, make sure there is no space before and above File::
File::
C:\WINDOWS\LMI1C.tmp
C:\WINDOWS\LMI189.tmp
Folder::
C:\VundoFix Backups
Save this as CFScript to your desktop.
Then drag the CFScript into ComboFix.exe as you see in the screenshot below.
http://i24.photobucket.com/albums/c30/ken545/CFScript.gif
This will start ComboFix again. After reboot, (in case it asks to reboot), post the contents of Combofix.txt in your next reply together with a new HijackThis log.
Run this system cleaner
Please download ATF Cleaner (http://www.atribune.org/ccount/click.php?id=1) by Atribune to your desktop.
This program is for XP and Windows 2000 only
Double-click ATF-Cleaner.exe to run the program.
Under Main choose: Select All
Click the Empty Selected button.
Your system may start up slower after running ATF Cleaner, this is expected but will be back to normal after the first or second boot up
You have Super Anti Spyware installed, set it up this way , run it and post the report. This is just precaution because at this time your HJT log looks fine, but lets make sure.
Run SuperAntiSpyware and click: Check for updates
Once the update is finished, on the main screen, click: Scan your computer
Check: Perform Complete Scan
Click Next to start the scan.
Superantispyware scans the computer, and when finished, lists all the infections found.
Make sure everything found has a check next to it, and press: Next
Then, click Finish
It is possible that the program asks to reboot in order to delete some files.
Obtain the SuperAntiSpyware log as follows:
Click: Preferences
Click the Statistics/Logs tab
Under Scanner Logs, double-click SuperAntiSpyware Scan Log
It opens in your default text editor (such as Notepad)
Please provide the SuperAntiSpyware log in your reply, as well as a new HijackThis log.
Let me see the New Combofix log, the SAS log and a New HJT log please
Combofix:
ComboFix 08-01-20.1 - HP_Owner 2008-01-20 23:04:01.3 - NTFSx86
Microsoft Windows XP Home Edition 5.1.2600.2.1252.1.1033.18.1981 [GMT 10:00]
Running from: C:\Documents and Settings\HP_Owner\Desktop\ComboFix.exe
Command switches used :: C:\Documents and Settings\HP_Owner\Desktop\CFScript.txt
* Created a new restore point
FILE
C:\WINDOWS\LMI189.tmp
C:\WINDOWS\LMI1C.tmp
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
C:\VundoFix Backups
.
((((((((((((((((((((((((( Files Created from 2007-12-20 to 2008-01-20 )))))))))))))))))))))))))))))))
.
2008-01-18 13:48 . 2008-01-20 13:57 54,156 --ah----- C:\WINDOWS\QTFont.qfn
2008-01-18 13:48 . 2008-01-20 13:57 1,409 --a------ C:\WINDOWS\QTFont.for
2008-01-16 03:26 . 2008-01-16 03:59 <DIR> d-------- C:\Program Files\SUPERAntiSpyware
2008-01-16 03:26 . 2008-01-16 03:26 <DIR> d-------- C:\Documents and Settings\HP_Owner\Application Data\SUPERAntiSpyware.com
2008-01-16 03:26 . 2008-01-16 03:26 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\SUPERAntiSpyware.com
2008-01-16 02:26 . 2008-01-20 12:54 <DIR> d-------- C:\WINDOWS\LMI1C.tmp
2008-01-16 01:47 . 2008-01-20 12:54 <DIR> d-------- C:\WINDOWS\LMI189.tmp
2008-01-15 11:20 . 2008-01-15 11:20 <DIR> d-------- C:\Program Files\Trend Micro
2008-01-14 05:40 . 2008-01-14 05:40 <DIR> d-------- C:\nup
2008-01-14 04:33 . 2008-01-14 05:28 <DIR> d-------- C:\Program Files\EsetOnlineScanner
2008-01-13 02:54 . 2008-01-13 02:54 <DIR> d-------- C:\WINDOWS\system32\Kaspersky Lab
2008-01-13 02:54 . 2008-01-13 02:54 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\Kaspersky Lab
2008-01-13 02:15 . 2000-08-31 08:00 51,200 --a------ C:\WINDOWS\NirCmd.exe
2008-01-11 04:14 . 2008-01-11 04:14 7,168 --ahs---- C:\WINDOWS\Thumbs.db
2008-01-11 04:11 . 2008-01-11 04:11 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\FLEXnet
2008-01-11 04:04 . 2008-01-11 04:04 <DIR> d-------- C:\Program Files\Bonjour
2008-01-11 03:49 . 2008-01-11 03:49 <DIR> d-------- C:\Program Files\Common Files\Macrovision Shared
2008-01-11 03:40 . 2008-01-12 11:58 <DIR> d-------- C:\Program Files\PowerISO
2008-01-10 03:39 . 2008-01-10 03:39 <DIR> d-------- C:\Program Files\uTorrent
2008-01-10 03:39 . 2008-01-10 17:19 <DIR> d-------- C:\Documents and Settings\HP_Owner\Application Data\uTorrent
2008-01-09 04:05 . 2008-01-09 04:05 <DIR> d-------- C:\Program Files\Common Files\Adobe Systems Shared
2008-01-09 00:07 . 2008-01-09 00:07 <DIR> d-------- C:\Program Files\Microsoft ActiveSync
2008-01-09 00:07 . 2008-01-09 00:07 376 --a------ C:\WINDOWS\ODBC.INI
2008-01-09 00:06 . 2008-01-09 00:06 <DIR> d-------- C:\WINDOWS\ShellNew
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2008-01-20 13:01 --------- d-----w C:\Documents and Settings\HP_Owner\Application Data\Skype
2008-01-20 03:57 --------- d-----w C:\Program Files\iTunes
2008-01-20 02:59 --------- d-----w C:\Documents and Settings\HP_Owner\Application Data\Xfire
2008-01-16 23:08 --------- d-----w C:\Documents and Settings\HP_Owner\Application Data\AVG7
2008-01-15 17:25 --------- d-----w C:\Program Files\Common Files\Wise Installation Wizard
2008-01-10 18:14 --------- d-----w C:\Program Files\DivX
2008-01-10 18:14 --------- d-----w C:\Program Files\Combined Community Codec Pack
2008-01-10 18:04 --------- d-----w C:\Program Files\Common Files\Adobe
2008-01-09 06:47 --------- d-----w C:\Program Files\World of Warcraft
2008-01-08 18:25 --------- d-----w C:\Program Files\QuickTime
2008-01-08 14:03 --------- d-----w C:\Program Files\Xfire
2007-11-27 23:34 --------- d-----w C:\Program Files\Soulseek
2007-11-27 13:57 --------- d-----w C:\Documents and Settings\All Users\Application Data\InterVideo
2007-11-07 09:26 721,920 ----a-w C:\WINDOWS\system32\lsasrv.dll
2007-10-29 22:43 1,287,680 ----a-w C:\WINDOWS\system32\quartz.dll
2007-10-27 07:39 230,912 ----a-w C:\WINDOWS\system32\wmasf.dll
2007-10-26 11:16 7,680 ----a-w C:\WINDOWS\system32\ff_vfw.dll
2007-10-21 17:39 267,272 ----a-w C:\WINDOWS\system32\xactengine2_10.dll
2007-10-21 17:37 17,928 ----a-w C:\WINDOWS\system32\X3DAudio1_2.dll
.
((((((((((((((((((((((((((((( snapshot_2008-01-20_12.57.14.18 )))))))))))))))))))))))))))))))))))))))))
.
- 2008-01-20 02:32:50 237,568 ----a-w C:\WINDOWS\erdnt\Hiv-backup\Users\00000001\NTUSER.DAT
+ 2008-01-20 13:03:56 237,568 ----a-w C:\WINDOWS\erdnt\Hiv-backup\Users\00000001\NTUSER.DAT
- 2008-01-20 02:32:50 8,192 ----a-w C:\WINDOWS\erdnt\Hiv-backup\Users\00000002\UsrClass.dat
+ 2008-01-20 13:03:56 8,192 ----a-w C:\WINDOWS\erdnt\Hiv-backup\Users\00000002\UsrClass.dat
- 2008-01-20 02:32:50 237,568 ----a-w C:\WINDOWS\erdnt\Hiv-backup\Users\00000003\NTUSER.DAT
+ 2008-01-20 13:03:56 237,568 ----a-w C:\WINDOWS\erdnt\Hiv-backup\Users\00000003\NTUSER.DAT
- 2008-01-20 02:32:50 8,192 ----a-w C:\WINDOWS\erdnt\Hiv-backup\Users\00000004\UsrClass.dat
+ 2008-01-20 13:03:56 8,192 ----a-w C:\WINDOWS\erdnt\Hiv-backup\Users\00000004\UsrClass.dat
- 2008-01-20 02:32:50 3,006,464 ----a-w C:\WINDOWS\erdnt\Hiv-backup\Users\00000005\NTUSER.DAT
+ 2008-01-20 13:03:56 3,006,464 ----a-w C:\WINDOWS\erdnt\Hiv-backup\Users\00000005\NTUSER.DAT
- 2008-01-20 02:32:50 172,032 ----a-w C:\WINDOWS\erdnt\Hiv-backup\Users\00000006\UsrClass.dat
+ 2008-01-20 13:03:57 172,032 ----a-w C:\WINDOWS\erdnt\Hiv-backup\Users\00000006\UsrClass.dat
- 2008-01-18 03:48:13 102,400 ----a-r C:\WINDOWS\Installer\{B045B608-4A47-4C77-9EAD-06C394503306}\iTunesIco.exe
+ 2008-01-20 03:57:41 102,400 ----a-r C:\WINDOWS\Installer\{B045B608-4A47-4C77-9EAD-06C394503306}\iTunesIco.exe
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"SUPERAntiSpyware"="C:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe" [2007-06-21 14:06 1318912]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"IMJPMIG8.1"="C:\WINDOWS\IME\imjp8_1\IMJPMIG.exe" [2004-08-05 05:00 208952]
"MSPY2002"="C:\WINDOWS\system32\IME\PINTLGNT\ImScInst.exe" [ ]
"PHIME2002ASync"="C:\WINDOWS\system32\IME\TINTLGNT\TINTSETP.exe" [2004-08-05 05:00 455168]
"PHIME2002A"="C:\WINDOWS\system32\IME\TINTLGNT\TINTSETP.exe" [2004-08-05 05:00 455168]
"TkBellExe"="C:\Program Files\Common Files\Real\Update_OB\realsched.exe" [ ]
"SoundMan"="SOUNDMAN.EXE" [2004-07-01 18:58 73728 C:\WINDOWS\SOUNDMAN.EXE]
"ATIPTA"="C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe" [ ]
"AlcWzrd"="ALCWZRD.EXE" [2004-07-06 01:05 2550272 C:\WINDOWS\ALCWZRD.EXE]
"AVG7_CC"="C:\PROGRA~1\Grisoft\AVG7\avgcc.exe" [ ]
"iTunesHelper"="C:\Program Files\iTunes\iTunesHelper.exe" [2007-09-26 14:42 267064]
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"AVG7_Run"="C:\PROGRA~1\Grisoft\AVG7\avgw.exe" [2007-10-25 09:58 219136]
C:\Documents and Settings\HP_Owner\Start Menu\Programs\Startup\
Xfire.lnk - C:\Program Files\Xfire\xfire.exe [2007-12-05 12:25:52 2858832]
C:\Documents and Settings\All Users\Start Menu\Programs\Startup\
HP Digital Imaging Monitor.lnk - C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe [2004-05-29 05:31:38 241664]
Microsoft Office.lnk - C:\Program Files\Microsoft Office\Office10\OSA.EXE [2001-02-13 01:01:04 83360]
[hkey_local_machine\software\microsoft\windows\currentversion\explorer\shellexecutehooks]
"{5AE067D3-9AFB-48E0-853A-EBB7F4A000DA}"= C:\Program Files\SUPERAntiSpyware\SASSEH.DLL [2006-12-20 13:55 77824]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\!SASWinLogon]
C:\Program Files\SUPERAntiSpyware\SASWINLO.dll 2007-04-19 13:41 294912 C:\Program Files\SUPERAntiSpyware\SASWINLO.dll
R3 Cap7134;ASUS TV7134 WDM Video Capture;C:\WINDOWS\system32\DRIVERS\Cap7134.sys [2004-06-23 20:34]
R3 PhTVTune;ASUS WDM TV Tuner;C:\WINDOWS\system32\DRIVERS\PhTVTune.sys [2004-05-27 18:49]
.
Contents of the 'Scheduled Tasks' folder
"2008-01-18 23:17:01 C:\WINDOWS\Tasks\AppleSoftwareUpdate.job"
- C:\Program Files\Apple Software Update\SoftwareUpdate.exe
.
**************************************************************************
catchme 0.3.1344 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2008-01-20 23:08:05
Windows 5.1.2600 Service Pack 2 NTFS
scanning hidden processes ...
scanning hidden autostart entries ...
scanning hidden files ...
scan completed successfully
hidden files: 0
**************************************************************************
.
Completion time: 2008-01-20 23:08:57
ComboFix-quarantined-files.txt 2008-01-20 13:08:55
ComboFix2.txt 2008-01-20 02:57:46
ComboFix3.txt 2008-01-12 16:48:19
.
2008-01-15 16:34:41 --- E O F ---
Hijackthis:
Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 11:53:12 PM, on 20/01/2008
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.5730.0013)
Boot mode: Normal
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
c:\program files\common files\logishrd\lvmvfm\LVPrcSrv.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
C:\PROGRA~1\Grisoft\AVG7\avgamsvr.exe
C:\PROGRA~1\Grisoft\AVG7\avgupsvc.exe
C:\PROGRA~1\Grisoft\AVG7\avgemc.exe
C:\WINDOWS\SOUNDMAN.EXE
C:\WINDOWS\ALCWZRD.EXE
C:\Program Files\iTunes\iTunesHelper.exe
C:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe
C:\Program Files\Bonjour\mDNSResponder.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe
C:\Program Files\iPod\bin\iPodService.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Ventrilo\Ventrilo.exe
C:\Program Files\MSN Messenger\msnmsgr.exe
C:\WINDOWS\system32\wuauclt.exe
C:\WINDOWS\system32\wuauclt.exe
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://ie.redirect.hp.com/svs/rdr?TYPE=3&tp=iesearch&locale=EN_AU&c=Q404&bd=pavilion&pf=desktop
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar = http://ie.redirect.hp.com/svs/rdr?TYPE=3&tp=iesearch&locale=EN_AU&c=Q404&bd=pavilion&pf=desktop
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = *.local
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 6.0\Reader\ActiveX\AcroIEHelper.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll
O3 - Toolbar: HP view - {B2847E28-5D7D-4DEB-8B67-05D28BCF79F5} - c:\Program Files\HP\Digital Imaging\bin\HPDTLK02.dll
O4 - HKLM\..\Run: [IMJPMIG8.1] "C:\WINDOWS\IME\imjp8_1\IMJPMIG.EXE" /Spoil /RemAdvDef /Migration32
O4 - HKLM\..\Run: [MSPY2002] C:\WINDOWS\system32\IME\PINTLGNT\ImScInst.exe /SYNC
O4 - HKLM\..\Run: [PHIME2002ASync] C:\WINDOWS\system32\IME\TINTLGNT\TINTSETP.EXE /SYNC
O4 - HKLM\..\Run: [PHIME2002A] C:\WINDOWS\system32\IME\TINTLGNT\TINTSETP.EXE /IMEName
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
O4 - HKLM\..\Run: [SoundMan] SOUNDMAN.EXE
O4 - HKLM\..\Run: [ATIPTA] C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe
O4 - HKLM\..\Run: [AlcWzrd] ALCWZRD.EXE
O4 - HKLM\..\Run: [AVG7_CC] C:\PROGRA~1\Grisoft\AVG7\avgcc.exe /STARTUP
O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
O4 - HKCU\..\Run: [SUPERAntiSpyware] C:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKUS\S-1-5-19\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-19\..\Run: [AVG7_Run] C:\PROGRA~1\Grisoft\AVG7\avgw.exe /RUNONCE (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-20\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'NETWORK SERVICE')
O4 - HKUS\S-1-5-18\..\Run: [AVG7_Run] C:\PROGRA~1\Grisoft\AVG7\avgw.exe /RUNONCE (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [AVG7_Run] C:\PROGRA~1\Grisoft\AVG7\avgw.exe /RUNONCE (User 'Default user')
O4 - Startup: Xfire.lnk = C:\Program Files\Xfire\xfire.exe
O4 - Global Startup: HP Digital Imaging Monitor.lnk = C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe
O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office10\OSA.EXE
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MI1933~1\Office10\EXCEL.EXE/3000
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe (file missing)
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe (file missing)
O16 - DPF: {0EB0E74A-2A76-4AB3-A7FB-9BD8C29F7F75} (CKAVWebScan Object) - http://www.kaspersky.com/kos/english/kavwebscan_unicode.cab
O16 - DPF: {56762DEC-6B0D-4AB4-A8AD-989993B5D08B} (OnlineScanner Control) - http://www.eset.eu/buxus/docs/OnlineScanner.cab
O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~1\COMMON~1\Skype\SKYPE4~1.DLL
O20 - Winlogon Notify: !SASWinLogon - C:\Program Files\SUPERAntiSpyware\SASWINLO.dll
O23 - Service: Adobe LM Service - Adobe Systems - C:\Program Files\Common Files\Adobe Systems Shared\Service\Adobelmsvc.exe
O23 - Service: Apple Mobile Device - Apple, Inc. - C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
O23 - Service: Ati HotKey Poller - Unknown owner - C:\WINDOWS\system32\Ati2evxx.exe
O23 - Service: AVG7 Alert Manager Server (Avg7Alrt) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVG7\avgamsvr.exe
O23 - Service: AVG7 Update Service (Avg7UpdSvc) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVG7\avgupsvc.exe
O23 - Service: AVG E-mail Scanner (AVGEMS) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVG7\avgemc.exe
O23 - Service: ##Id_String1.6844F930_1628_4223_B5CC_5BB94B879762## (Bonjour Service) - Apple Computer, Inc. - C:\Program Files\Bonjour\mDNSResponder.exe
O23 - Service: FLEXnet Licensing Service - Macrovision Europe Ltd. - C:\Program Files\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe
O23 - Service: iPod Service - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: Process Monitor (LVPrcSrv) - Logitech Inc. - c:\program files\common files\logishrd\lvmvfm\LVPrcSrv.exe
O23 - Service: LVSrvLauncher - Logitech Inc. - C:\Program Files\Common Files\LogiShrd\SrvLnch\SrvLnch.exe
--
End of file - 6786 bytes
SuperAntiSpyware:
SUPERAntiSpyware Scan Log
http://www.superantispyware.com
Generated 01/20/2008 at 11:48 PM
Application Version : 3.9.1008
Core Rules Database Version : 3384
Trace Rules Database Version: 1378
Scan type : Complete Scan
Total Scan Time : 00:34:04
Memory items scanned : 438
Memory threats detected : 0
Registry items scanned : 6421
Registry threats detected : 0
File items scanned : 39648
File threats detected : 3
Malware.LocusSoftware Inc/StorageProtector
C:\SYSTEM VOLUME INFORMATION\_RESTORE{BC8E6A4E-6A7A-4B39-BB3E-1006C7C819B6}\RP113\A0011991.EXE
Adware.Vundo-Variant
C:\SYSTEM VOLUME INFORMATION\_RESTORE{BC8E6A4E-6A7A-4B39-BB3E-1006C7C819B6}\RP114\A0014071.DLL
C:\SYSTEM VOLUME INFORMATION\_RESTORE{BC8E6A4E-6A7A-4B39-BB3E-1006C7C819B6}\RP122\A0014559.DLL
All SAS found where entires in your System Restore and removed them
These were not deleted, lets check them.
Go to this site Jotti Upload (http://virusscan.jotti.org/) and under the browse feature, browse to these files
C:\WINDOWS\LMI1C.tmp
C:\WINDOWS\LMI189.tmp
Then click on Submit and it will give you a report, post the report in your next reply.
I went to the website and tried to locate the files you mentioned but they dont appear in the location it says theyre in.
They may be hidden. If there still not there after you do this then we won't worry about them.
We need to make sure all hidden files are showing :
Click Start.
Open My Computer.
Select the Tools menu and click Folder Options.
Select the View tab.
Under the Hidden files and folders heading select Show hidden files and folders.
Uncheck the Hide file extensions for known types option.
Uncheck the Hide protected operating system files (recommended) option.
Click Yes to confirm.
Click OK.
Once your system is clean, we suggest that you reverse this to keep critical windows files from accidently being deleted.
I changed the settings but theyre still not showing up. I heard that files like that can sometimes be Keyloggers, is that true?
Hello,
I heard that files like that can sometimes be Keyloggers, is that true? Not sure what they are, doing various searches is coming up with nothing. If enabling your system to see hidden files and there not present most likely means there gone.
I would like you to run this free online virus scanner, it won't remove any thing but give a excellent report as far as any bad files on your system.
Run this online scan using Internet Explorer:
Kaspersky Online Scanner from Kaspersky Online Virus Scanner (http://www.kaspersky.com/kos/english/kavwebscan.html)
Next Click on Launch Kaspersky Online Scanner
You will be prompted to install an ActiveX component from Kaspersky, Click Yes.
The program will launch and then begin downloading the latest definition files:
Once the files have been downloaded click on NEXT
Now click on Scan Settings
In the scan settings make that the following are selected:
Scan using the following Anti-Virus database:
Standard
Scan Options:
Scan Archives
Scan Mail Bases
Click OK
Now under select a target to scan: Select My Computer
This will program will start and scan your system.
The scan will take a while so be patient and let it run.
Once the scan is complete it will display if your system has been infected.
Now click on the Save as Text button:
Save the file to your desktop.
Post the log along with a New HJT Log into your next reply.
Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 9:02:03 PM, on 21/01/2008
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.5730.0013)
Boot mode: Normal
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
c:\program files\common files\logishrd\lvmvfm\LVPrcSrv.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
C:\PROGRA~1\Grisoft\AVG7\avgamsvr.exe
C:\PROGRA~1\Grisoft\AVG7\avgupsvc.exe
C:\PROGRA~1\Grisoft\AVG7\avgemc.exe
C:\WINDOWS\SOUNDMAN.EXE
C:\WINDOWS\ALCWZRD.EXE
C:\Program Files\iTunes\iTunesHelper.exe
C:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe
C:\Program Files\Bonjour\mDNSResponder.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe
C:\Program Files\iPod\bin\iPodService.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Ventrilo\Ventrilo.exe
C:\Program Files\MSN Messenger\msnmsgr.exe
C:\WINDOWS\system32\wuauclt.exe
C:\Program Files\Opera\Opera.exe
C:\WINDOWS\system32\wscntfy.exe
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://ie.redirect.hp.com/svs/rdr?TYPE=3&tp=iesearch&locale=EN_AU&c=Q404&bd=pavilion&pf=desktop
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar = http://ie.redirect.hp.com/svs/rdr?TYPE=3&tp=iesearch&locale=EN_AU&c=Q404&bd=pavilion&pf=desktop
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = *.local
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 6.0\Reader\ActiveX\AcroIEHelper.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll
O3 - Toolbar: HP view - {B2847E28-5D7D-4DEB-8B67-05D28BCF79F5} - c:\Program Files\HP\Digital Imaging\bin\HPDTLK02.dll
O4 - HKLM\..\Run: [IMJPMIG8.1] "C:\WINDOWS\IME\imjp8_1\IMJPMIG.EXE" /Spoil /RemAdvDef /Migration32
O4 - HKLM\..\Run: [MSPY2002] C:\WINDOWS\system32\IME\PINTLGNT\ImScInst.exe /SYNC
O4 - HKLM\..\Run: [PHIME2002ASync] C:\WINDOWS\system32\IME\TINTLGNT\TINTSETP.EXE /SYNC
O4 - HKLM\..\Run: [PHIME2002A] C:\WINDOWS\system32\IME\TINTLGNT\TINTSETP.EXE /IMEName
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
O4 - HKLM\..\Run: [SoundMan] SOUNDMAN.EXE
O4 - HKLM\..\Run: [ATIPTA] C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe
O4 - HKLM\..\Run: [AlcWzrd] ALCWZRD.EXE
O4 - HKLM\..\Run: [AVG7_CC] C:\PROGRA~1\Grisoft\AVG7\avgcc.exe /STARTUP
O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
O4 - HKCU\..\Run: [SUPERAntiSpyware] C:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKUS\S-1-5-19\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-19\..\Run: [AVG7_Run] C:\PROGRA~1\Grisoft\AVG7\avgw.exe /RUNONCE (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-20\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'NETWORK SERVICE')
O4 - HKUS\S-1-5-18\..\Run: [AVG7_Run] C:\PROGRA~1\Grisoft\AVG7\avgw.exe /RUNONCE (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [AVG7_Run] C:\PROGRA~1\Grisoft\AVG7\avgw.exe /RUNONCE (User 'Default user')
O4 - Startup: Xfire.lnk = C:\Program Files\Xfire\xfire.exe
O4 - Global Startup: HP Digital Imaging Monitor.lnk = C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe
O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office10\OSA.EXE
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MI1933~1\Office10\EXCEL.EXE/3000
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe (file missing)
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe (file missing)
O16 - DPF: {0EB0E74A-2A76-4AB3-A7FB-9BD8C29F7F75} (CKAVWebScan Object) - http://www.kaspersky.com/kos/english/kavwebscan_unicode.cab
O16 - DPF: {56762DEC-6B0D-4AB4-A8AD-989993B5D08B} (OnlineScanner Control) - http://www.eset.eu/buxus/docs/OnlineScanner.cab
O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~1\COMMON~1\Skype\SKYPE4~1.DLL
O20 - Winlogon Notify: !SASWinLogon - C:\Program Files\SUPERAntiSpyware\SASWINLO.dll
O23 - Service: Adobe LM Service - Adobe Systems - C:\Program Files\Common Files\Adobe Systems Shared\Service\Adobelmsvc.exe
O23 - Service: Apple Mobile Device - Apple, Inc. - C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
O23 - Service: Ati HotKey Poller - Unknown owner - C:\WINDOWS\system32\Ati2evxx.exe
O23 - Service: AVG7 Alert Manager Server (Avg7Alrt) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVG7\avgamsvr.exe
O23 - Service: AVG7 Update Service (Avg7UpdSvc) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVG7\avgupsvc.exe
O23 - Service: AVG E-mail Scanner (AVGEMS) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVG7\avgemc.exe
O23 - Service: ##Id_String1.6844F930_1628_4223_B5CC_5BB94B879762## (Bonjour Service) - Apple Computer, Inc. - C:\Program Files\Bonjour\mDNSResponder.exe
O23 - Service: FLEXnet Licensing Service - Macrovision Europe Ltd. - C:\Program Files\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe
O23 - Service: iPod Service - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: Process Monitor (LVPrcSrv) - Logitech Inc. - c:\program files\common files\logishrd\lvmvfm\LVPrcSrv.exe
O23 - Service: LVSrvLauncher - Logitech Inc. - C:\Program Files\Common Files\LogiShrd\SrvLnch\SrvLnch.exe
--
End of file - 6819 bytes
-------------------------------------------------------------------------------
KASPERSKY ONLINE SCANNER REPORT
Monday, January 21, 2008 5:50:06 PM
Operating System: Microsoft Windows XP Home Edition, Service Pack 2 (Build 2600)
Kaspersky Online Scanner version: 5.0.98.0
Kaspersky Anti-Virus database last update: 21/01/2008
Kaspersky Anti-Virus database records: 490968
-------------------------------------------------------------------------------
Scan Settings:
Scan using the following antivirus database: standard
Scan Archives: true
Scan Mail Bases: true
Scan Target - My Computer:
C:\
D:\
E:\
F:\
G:\
H:\
I:\
Scan Statistics:
Total number of scanned objects: 109523
Number of viruses found: 0
Number of infected objects: 0
Number of suspicious objects: 0
Duration of the scan process: 01:41:03
Infected Object Name / Virus Name / Last Action
C:\Documents and Settings\All Users\Application Data\avg7\Log\emc.log Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Grisoft\Avg7Data\avg7log.log Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Grisoft\Avg7Data\avg7log.log.lck Object is locked skipped
C:\Documents and Settings\HP_Owner\Application Data\Opera\Opera\mail\indexer\indexer.dat Object is locked skipped
C:\Documents and Settings\HP_Owner\Application Data\Opera\Opera\mail\lexicon\lexicon.dat Object is locked skipped
C:\Documents and Settings\HP_Owner\Application Data\Opera\Opera\mail\mailbase.dat Object is locked skipped
C:\Documents and Settings\HP_Owner\Application Data\SUPERAntiSpyware.com\SUPERAntiSpyware\SUPERANTISPYWARE.LOG Object is locked skipped
C:\Documents and Settings\HP_Owner\Cookies\index.dat Object is locked skipped
C:\Documents and Settings\HP_Owner\Local Settings\Application Data\Microsoft\Feeds Cache\index.dat Object is locked skipped
C:\Documents and Settings\HP_Owner\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat Object is locked skipped
C:\Documents and Settings\HP_Owner\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat.LOG Object is locked skipped
C:\Documents and Settings\HP_Owner\Local Settings\Application Data\Microsoft\Windows Live Contacts\brat100percent@hotmail.com\real\members.stg Object is locked skipped
C:\Documents and Settings\HP_Owner\Local Settings\Application Data\Microsoft\Windows Live Contacts\brat100percent@hotmail.com\shadow\members.stg Object is locked skipped
C:\Documents and Settings\HP_Owner\Local Settings\History\History.IE5\index.dat Object is locked skipped
C:\Documents and Settings\HP_Owner\Local Settings\History\History.IE5\MSHist012008012120080122\index.dat Object is locked skipped
C:\Documents and Settings\HP_Owner\Local Settings\Temp\hpodvd09.log Object is locked skipped
C:\Documents and Settings\HP_Owner\Local Settings\Temp\~DF18FF.tmp Object is locked skipped
C:\Documents and Settings\HP_Owner\Local Settings\Temp\~DF7255.tmp Object is locked skipped
C:\Documents and Settings\HP_Owner\Local Settings\Temp\~DF72E6.tmp Object is locked skipped
C:\Documents and Settings\HP_Owner\Local Settings\Temp\~DFD25.tmp Object is locked skipped
C:\Documents and Settings\HP_Owner\Local Settings\Temporary Internet Files\AntiPhishing\B3BB5BBA-E7D5-40AB-A041-A5B1C0B26C8F.dat Object is locked skipped
C:\Documents and Settings\HP_Owner\Local Settings\Temporary Internet Files\Content.IE5\index.dat Object is locked skipped
C:\Documents and Settings\HP_Owner\NTUSER.DAT Object is locked skipped
C:\Documents and Settings\HP_Owner\ntuser.dat.LOG Object is locked skipped
C:\Documents and Settings\LocalService\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat Object is locked skipped
C:\Documents and Settings\LocalService\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat.LOG Object is locked skipped
C:\Documents and Settings\LocalService\Local Settings\Temp\Cookies\index.dat Object is locked skipped
C:\Documents and Settings\LocalService\Local Settings\Temp\History\History.IE5\index.dat Object is locked skipped
C:\Documents and Settings\LocalService\Local Settings\Temp\Temporary Internet Files\Content.IE5\index.dat Object is locked skipped
C:\Documents and Settings\LocalService\NTUSER.DAT Object is locked skipped
C:\Documents and Settings\LocalService\ntuser.dat.LOG Object is locked skipped
C:\Documents and Settings\NetworkService\Cookies\index.dat Object is locked skipped
C:\Documents and Settings\NetworkService\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat Object is locked skipped
C:\Documents and Settings\NetworkService\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat.LOG Object is locked skipped
C:\Documents and Settings\NetworkService\Local Settings\History\History.IE5\index.dat Object is locked skipped
C:\Documents and Settings\NetworkService\Local Settings\Temporary Internet Files\Content.IE5\index.dat Object is locked skipped
C:\Documents and Settings\NetworkService\NTUSER.DAT Object is locked skipped
C:\Documents and Settings\NetworkService\ntuser.dat.LOG Object is locked skipped
C:\Program Files\World of Warcraft\Logs\gx.log Object is locked skipped
C:\Program Files\World of Warcraft\Logs\SESound.log Object is locked skipped
C:\Program Files\World of Warcraft\Logs\WoWChatLog.txt Object is locked skipped
C:\Program Files\World of Warcraft\Logs\WoWCombatLog.txt Object is locked skipped
C:\System Volume Information\MountPointManagerRemoteDatabase Object is locked skipped
C:\System Volume Information\_restore{BC8E6A4E-6A7A-4B39-BB3E-1006C7C819B6}\RP105\A0007604.exe Object is locked skipped
C:\System Volume Information\_restore{BC8E6A4E-6A7A-4B39-BB3E-1006C7C819B6}\RP105\A0007606.exe Object is locked skipped
C:\System Volume Information\_restore{BC8E6A4E-6A7A-4B39-BB3E-1006C7C819B6}\RP105\A0007612.exe Object is locked skipped
C:\System Volume Information\_restore{BC8E6A4E-6A7A-4B39-BB3E-1006C7C819B6}\RP105\A0007613.exe Object is locked skipped
C:\System Volume Information\_restore{BC8E6A4E-6A7A-4B39-BB3E-1006C7C819B6}\RP105\A0007614.exe Object is locked skipped
C:\System Volume Information\_restore{BC8E6A4E-6A7A-4B39-BB3E-1006C7C819B6}\RP105\A0007615.EXE Object is locked skipped
C:\System Volume Information\_restore{BC8E6A4E-6A7A-4B39-BB3E-1006C7C819B6}\RP105\A0007616.exe Object is locked skipped
C:\System Volume Information\_restore{BC8E6A4E-6A7A-4B39-BB3E-1006C7C819B6}\RP105\A0007617.exe Object is locked skipped
C:\System Volume Information\_restore{BC8E6A4E-6A7A-4B39-BB3E-1006C7C819B6}\RP105\A0007618.exe Object is locked skipped
C:\System Volume Information\_restore{BC8E6A4E-6A7A-4B39-BB3E-1006C7C819B6}\RP105\A0007619.exe Object is locked skipped
C:\System Volume Information\_restore{BC8E6A4E-6A7A-4B39-BB3E-1006C7C819B6}\RP105\A0007620.exe Object is locked skipped
C:\System Volume Information\_restore{BC8E6A4E-6A7A-4B39-BB3E-1006C7C819B6}\RP105\A0007621.EXE Object is locked skipped
C:\System Volume Information\_restore{BC8E6A4E-6A7A-4B39-BB3E-1006C7C819B6}\RP105\A0007622.exe Object is locked skipped
C:\System Volume Information\_restore{BC8E6A4E-6A7A-4B39-BB3E-1006C7C819B6}\RP105\A0007623.exe Object is locked skipped
C:\System Volume Information\_restore{BC8E6A4E-6A7A-4B39-BB3E-1006C7C819B6}\RP105\A0007624.exe Object is locked skipped
C:\System Volume Information\_restore{BC8E6A4E-6A7A-4B39-BB3E-1006C7C819B6}\RP105\A0007625.exe Object is locked skipped
C:\System Volume Information\_restore{BC8E6A4E-6A7A-4B39-BB3E-1006C7C819B6}\RP105\A0007697.exe Object is locked skipped
C:\System Volume Information\_restore{BC8E6A4E-6A7A-4B39-BB3E-1006C7C819B6}\RP108\A0008796.exe Object is locked skipped
C:\System Volume Information\_restore{BC8E6A4E-6A7A-4B39-BB3E-1006C7C819B6}\RP108\A0008852.exe Object is locked skipped
C:\System Volume Information\_restore{BC8E6A4E-6A7A-4B39-BB3E-1006C7C819B6}\RP108\A0009848.exe Object is locked skipped
C:\System Volume Information\_restore{BC8E6A4E-6A7A-4B39-BB3E-1006C7C819B6}\RP109\A0009909.exe Object is locked skipped
C:\System Volume Information\_restore{BC8E6A4E-6A7A-4B39-BB3E-1006C7C819B6}\RP109\A0009910.EXE Object is locked skipped
C:\System Volume Information\_restore{BC8E6A4E-6A7A-4B39-BB3E-1006C7C819B6}\RP110\A0010848.exe Object is locked skipped
C:\System Volume Information\_restore{BC8E6A4E-6A7A-4B39-BB3E-1006C7C819B6}\RP110\A0010849.EXE Object is locked skipped
C:\System Volume Information\_restore{BC8E6A4E-6A7A-4B39-BB3E-1006C7C819B6}\RP110\A0010880.exe Object is locked skipped
C:\System Volume Information\_restore{BC8E6A4E-6A7A-4B39-BB3E-1006C7C819B6}\RP110\A0010881.EXE Object is locked skipped
C:\System Volume Information\_restore{BC8E6A4E-6A7A-4B39-BB3E-1006C7C819B6}\RP112\A0010941.dll Object is locked skipped
C:\System Volume Information\_restore{BC8E6A4E-6A7A-4B39-BB3E-1006C7C819B6}\RP112\A0010947.dll Object is locked skipped
C:\System Volume Information\_restore{BC8E6A4E-6A7A-4B39-BB3E-1006C7C819B6}\RP112\A0010948.dll Object is locked skipped
C:\System Volume Information\_restore{BC8E6A4E-6A7A-4B39-BB3E-1006C7C819B6}\RP112\A0010952.dll Object is locked skipped
C:\System Volume Information\_restore{BC8E6A4E-6A7A-4B39-BB3E-1006C7C819B6}\RP113\A0011006.exe Object is locked skipped
C:\System Volume Information\_restore{BC8E6A4E-6A7A-4B39-BB3E-1006C7C819B6}\RP113\A0011007.exe Object is locked skipped
C:\System Volume Information\_restore{BC8E6A4E-6A7A-4B39-BB3E-1006C7C819B6}\RP113\A0011992.exe Object is locked skipped
C:\System Volume Information\_restore{BC8E6A4E-6A7A-4B39-BB3E-1006C7C819B6}\RP113\A0012001.EXE Object is locked skipped
C:\System Volume Information\_restore{BC8E6A4E-6A7A-4B39-BB3E-1006C7C819B6}\RP113\A0012003.exe Object is locked skipped
C:\System Volume Information\_restore{BC8E6A4E-6A7A-4B39-BB3E-1006C7C819B6}\RP113\A0012004.EXE Object is locked skipped
C:\System Volume Information\_restore{BC8E6A4E-6A7A-4B39-BB3E-1006C7C819B6}\RP113\A0012005.exe Object is locked skipped
C:\System Volume Information\_restore{BC8E6A4E-6A7A-4B39-BB3E-1006C7C819B6}\RP113\A0012006.exe Object is locked skipped
C:\System Volume Information\_restore{BC8E6A4E-6A7A-4B39-BB3E-1006C7C819B6}\RP113\A0012027.exe Object is locked skipped
C:\System Volume Information\_restore{BC8E6A4E-6A7A-4B39-BB3E-1006C7C819B6}\RP113\A0012028.exe Object is locked skipped
C:\System Volume Information\_restore{BC8E6A4E-6A7A-4B39-BB3E-1006C7C819B6}\RP113\A0012029.exe Object is locked skipped
C:\System Volume Information\_restore{BC8E6A4E-6A7A-4B39-BB3E-1006C7C819B6}\RP113\A0012035.dll Object is locked skipped
C:\System Volume Information\_restore{BC8E6A4E-6A7A-4B39-BB3E-1006C7C819B6}\RP113\A0012036.dll Object is locked skipped
C:\System Volume Information\_restore{BC8E6A4E-6A7A-4B39-BB3E-1006C7C819B6}\RP113\A0012037.dll Object is locked skipped
C:\System Volume Information\_restore{BC8E6A4E-6A7A-4B39-BB3E-1006C7C819B6}\RP113\A0012038.dll Object is locked skipped
C:\System Volume Information\_restore{BC8E6A4E-6A7A-4B39-BB3E-1006C7C819B6}\RP113\A0012042.dll Object is locked skipped
C:\System Volume Information\_restore{BC8E6A4E-6A7A-4B39-BB3E-1006C7C819B6}\RP113\A0012050.EXE Object is locked skipped
C:\System Volume Information\_restore{BC8E6A4E-6A7A-4B39-BB3E-1006C7C819B6}\RP113\A0012051.EXE Object is locked skipped
C:\System Volume Information\_restore{BC8E6A4E-6A7A-4B39-BB3E-1006C7C819B6}\RP113\A0012052.exe Object is locked skipped
C:\System Volume Information\_restore{BC8E6A4E-6A7A-4B39-BB3E-1006C7C819B6}\RP113\A0012053.exe Object is locked skipped
C:\System Volume Information\_restore{BC8E6A4E-6A7A-4B39-BB3E-1006C7C819B6}\RP113\A0012080.exe Object is locked skipped
C:\System Volume Information\_restore{BC8E6A4E-6A7A-4B39-BB3E-1006C7C819B6}\RP113\A0012083.exe Object is locked skipped
C:\System Volume Information\_restore{BC8E6A4E-6A7A-4B39-BB3E-1006C7C819B6}\RP113\A0012084.exe Object is locked skipped
C:\System Volume Information\_restore{BC8E6A4E-6A7A-4B39-BB3E-1006C7C819B6}\RP114\A0012111.exe Object is locked skipped
C:\System Volume Information\_restore{BC8E6A4E-6A7A-4B39-BB3E-1006C7C819B6}\RP114\A0014069.dll Object is locked skipped
C:\System Volume Information\_restore{BC8E6A4E-6A7A-4B39-BB3E-1006C7C819B6}\RP114\A0014070.dll Object is locked skipped
C:\System Volume Information\_restore{BC8E6A4E-6A7A-4B39-BB3E-1006C7C819B6}\RP114\A0014097.exe Object is locked skipped
C:\System Volume Information\_restore{BC8E6A4E-6A7A-4B39-BB3E-1006C7C819B6}\RP114\A0014122.EXE Object is locked skipped
C:\System Volume Information\_restore{BC8E6A4E-6A7A-4B39-BB3E-1006C7C819B6}\RP114\A0014123.EXE Object is locked skipped
C:\System Volume Information\_restore{BC8E6A4E-6A7A-4B39-BB3E-1006C7C819B6}\RP114\A0014124.exe Object is locked skipped
C:\System Volume Information\_restore{BC8E6A4E-6A7A-4B39-BB3E-1006C7C819B6}\RP120\A0014523.exe Object is locked skipped
C:\System Volume Information\_restore{BC8E6A4E-6A7A-4B39-BB3E-1006C7C819B6}\RP123\A0014597.exe Object is locked skipped
C:\System Volume Information\_restore{BC8E6A4E-6A7A-4B39-BB3E-1006C7C819B6}\RP123\A0014598.dll Object is locked skipped
C:\System Volume Information\_restore{BC8E6A4E-6A7A-4B39-BB3E-1006C7C819B6}\RP123\A0014599.exe Object is locked skipped
C:\System Volume Information\_restore{BC8E6A4E-6A7A-4B39-BB3E-1006C7C819B6}\RP128\change.log Object is locked skipped
C:\WINDOWS\Debug\PASSWD.LOG Object is locked skipped
C:\WINDOWS\SchedLgU.Txt Object is locked skipped
C:\WINDOWS\SoftwareDistribution\EventCache\{475103BB-596F-4AD7-8EE8-0622FEB62ACA}.bin Object is locked skipped
C:\WINDOWS\SoftwareDistribution\ReportingEvents.log Object is locked skipped
C:\WINDOWS\Sti_Trace.log Object is locked skipped
C:\WINDOWS\system32\config\AppEvent.Evt Object is locked skipped
C:\WINDOWS\system32\config\default Object is locked skipped
C:\WINDOWS\system32\config\default.LOG Object is locked skipped
C:\WINDOWS\system32\config\Internet.evt Object is locked skipped
C:\WINDOWS\system32\config\SAM Object is locked skipped
C:\WINDOWS\system32\config\SAM.LOG Object is locked skipped
C:\WINDOWS\system32\config\SecEvent.Evt Object is locked skipped
C:\WINDOWS\system32\config\SECURITY Object is locked skipped
C:\WINDOWS\system32\config\SECURITY.LOG Object is locked skipped
C:\WINDOWS\system32\config\software Object is locked skipped
C:\WINDOWS\system32\config\software.LOG Object is locked skipped
C:\WINDOWS\system32\config\SysEvent.Evt Object is locked skipped
C:\WINDOWS\system32\config\system Object is locked skipped
C:\WINDOWS\system32\config\system.LOG Object is locked skipped
C:\WINDOWS\system32\h323log.txt Object is locked skipped
C:\WINDOWS\system32\wbem\Repository\FS\INDEX.BTR Object is locked skipped
C:\WINDOWS\system32\wbem\Repository\FS\INDEX.MAP Object is locked skipped
C:\WINDOWS\system32\wbem\Repository\FS\MAPPING.VER Object is locked skipped
C:\WINDOWS\system32\wbem\Repository\FS\MAPPING1.MAP Object is locked skipped
C:\WINDOWS\system32\wbem\Repository\FS\MAPPING2.MAP Object is locked skipped
C:\WINDOWS\system32\wbem\Repository\FS\OBJECTS.DATA Object is locked skipped
C:\WINDOWS\system32\wbem\Repository\FS\OBJECTS.MAP Object is locked skipped
C:\WINDOWS\wiadebug.log Object is locked skipped
C:\WINDOWS\wiaservc.log Object is locked skipped
C:\WINDOWS\WindowsUpdate.log Object is locked skipped
Scan process completed.
Good Morning,
Kaspersky found no viruses and your HJT log looks fine :bigthumb:
But you do need to flush out your System Restore Program as to not take the chance of reinfecting yourself.
System Restore makes regular backups of all your settings, if you ever had to use this program to restore your system to a previous date, you will be infected all over again so we need to clean out the previous Restore Points
Turn off System Restore.
Right-click My Computer.
Click Properties.
Click the System Restore tab.
Check Turn off System Restore on all Drives.
Click Apply, and then click OK.
Reboot your computer
Turn ON System Restore.
Right-click My Computer.
ClickProperties.
Click the System Restore tab.
UN-Check Turn off System Restore on all Drives.
Click Apply, and then click OK.
Create a new Restore Point <-- Very Important
Go to Start/ Control Panel/ Performance and Maintenance/ System Restore/ Create a New Restore Point
You need to go into the Control Panel and switch to Catagory View to be able to Create a New Restore Point
System Restore Tutorial (http://www.bleepingcomputer.com/tutorials/tutorial56.html) <-- If you need it
How are things running now ??
Everything seems to be running perfectly. I used to get annoying popups on rebooting saying it couldnt find certain files or I didnt have access to them and theyre gone now. Looks good.
Thats great :bigthumb:
Malware Complaints (http://malwarecomplaints.info/index.php)
Are you mad ? I mean really mad, seething mad, so mad your ready to spit, mad that you have taken your hard earned dollars to buy a computer only to have some Miscredents, Dirt Bags and Cyber Criminals install a malicious program on your computer without your knowledge or consent. You can post your complaint at the above site. If you live in the U.S.A. you can also report your grievance to your State Attorney Generals Office and the Federal Trade Commission's Bureau of Consumer Protection.
How did I get infected in the first place ? Read these links and find out how to prevent getting infected again.
Tutorial for System Restore (http://www.bleepingcomputer.com/tutorials/tutorial56.html) <-- Do this first to prevent yourself from being reinfected.
WhattheTech (http://forums.whatthetech.com/So_how_did_I_get_infected_in_the_first_place_t57817.html)
TonyKlein CastleCops (http://www.castlecops.com/postlite7736-.html)
Grinler BleepingComputer (http://www.bleepingcomputer.com/forums/topic2520.html)
Geeks To Go (http://www.geekstogo.com/forum/index.php?autocom=custom&page=How_did_I)
Dslreports (http://www.dslreports.com/faq/10002)
If you install Spyware Blaster and Spyware Guard, do not enable the Tea Timer in Spybot Search and Destroy or they will conflict.
Here are some free programs to install, don't leave home without them
Spybot Search and Destroy 1.5 (http://www.safer-networking.org/en/download/)
Check for Updates/ Immunize and run a Full System Scan on a regular basis.
Spyware Blaster (http://www.javacoolsoftware.com/spywareblaster.html) It will prevent most spyware from ever being installed.
Spyware Guard (http://www.javacoolsoftware.com/spywareguard.html) It offers realtime protection from spyware installation attempts.
Win Patrol (http://www.winpatrol.com/download.html) This program will warn you when any changes are being made to your system and give
you the option to deny the change.
IE-Spyad (http://forums.windowsforum.org/index.php?showtopic=6640)
IE-Spyad places over 4000 web sites and domains in the IE Restricted list which will severely impair attempts to infect your system. It basically prevents any downloads
(cookies etc) from the sites listed, although you will still be able to connect to the sites.
Firefox 2.0 (http://www.mozilla.org/products/firefox/) It has more features and is a lot more secure than IE. It is a very easy and
painless download and install, it will no way interfere with IE, you can use them both.
Zone Alarm (http://www.pcworld.com/downloads/file_description/0,fid,7228,00.asp) Here is a free Firewall from Zone Labs,
Glad we could help.
Safe Surfn
Ken
Thanks so much for your help, greatly appreciate it.
Your most welcome :bigthumb: