problem wish A.exe on my friends laptop, please help

didsburydan

New member
i need to get rid of this urgently as it is on a friends laptop which i borrowed and he will not be happy if i return it like this.

I basically have an A.exe process running which i can't get rid of. it is making browsing the internet very slow and i encounter crashes of google chrome and internet explorer. It can on occasion also use a very high % of my CPU which makes everything slow. Norton anti-protect is constantly telling me that it has blocked a worm. I have tried scanning with AVG but that returned nothing. I have also tried scanning with Malwarebytes but this crashes which trying to remove selected (namely when trying to remove twext.exe). I have also tried ad-aware but this closes itself after a few seconds of starting a scan.

PLEASE HELP, here is my HJT log

Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 23:00:33, on 14/09/2009
Platform: Windows XP SP3 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP3 (6.00.2900.5512)
Boot mode: Normal

Running processes:
C:\WINDOWS\system32\csrss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe
C:\Program Files\Common Files\Symantec Shared\SNDSrvc.exe
C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
C:\Program Files\Lavasoft\Ad-Aware\AAWService.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\system32\svchost.exe
C:\Acer\eManager\anbmServ.exe
C:\WINDOWS\msa.exe
C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
C:\Program Files\Symantec\LiveUpdate\ALUSchedulerSvc.exe
C:\WINDOWS\system32\ctfmon.exe
C:\PROGRA~1\AVG\AVG8\avgwdsvc.exe
C:\Program Files\Bonjour\mDNSResponder.exe
C:\Program Files\Java\jre6\bin\jqs.exe
C:\Program Files\Kontiki\KService.exe
C:\Program Files\Norton AntiVirus\navapsvc.exe
C:\Program Files\Norton AntiVirus\IWP\NPFMntor.exe
C:\WINDOWS\system32\svchost.exe
C:\PROGRA~1\AVG\AVG8\avgam.exe
C:\WINDOWS\system32\wbem\unsecapp.exe
C:\WINDOWS\System32\alg.exe
C:\PROGRA~1\AVG\AVG8\avgrsx.exe
C:\PROGRA~1\AVG\AVG8\avgnsx.exe
C:\WINDOWS\system32\wbem\wmiprvse.exe
C:\WINDOWS\system32\igfxtray.exe
C:\WINDOWS\system32\hkcmd.exe
C:\WINDOWS\system32\igfxpers.exe
C:\Program Files\Acer\eRecovery\Monitor.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Synaptics\SynTP\SynTPLpr.exe
C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
C:\WINDOWS\RTHDCPL.EXE
C:\acer\epm\epm-dm.exe
C:\Program Files\Common Files\Symantec Shared\ccApp.exe
C:\PROGRA~1\LAUNCH~1\QtZgAcer.EXE
C:\Program Files\Java\jre6\bin\jusched.exe
C:\Program Files\Common Files\Real\Update_OB\realsched.exe
C:\Program Files\iTunes\iTunesHelper.exe
C:\Program Files\Microsoft Office\Office12\GrooveMonitor.exe
C:\PROGRA~1\AVG\AVG8\avgtray.exe
C:\Program Files\Windows Live\Messenger\MsnMsgr.Exe
C:\Program Files\Kontiki\KHost.exe
C:\Documents and Settings\robert holwett\Local Settings\Application Data\Google\Update\GoogleUpdate.exe
C:\Documents and Settings\robert holwett\tiuopu.exe
C:\Program Files\iPod\bin\iPodService.exe
C:\Documents and Settings\robert holwett\Local Settings\Application Data\Google\Chrome\Application\chrome.exe
C:\Documents and Settings\robert holwett\Local Settings\Application Data\Google\Chrome\Application\chrome.exe
C:\DOCUME~1\ROBERT~1\LOCALS~1\Temp\a.exe
C:\Program Files\Messenger\msmsgs.exe
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe
C:\WINDOWS\system32\wbem\wmiprvse.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://news.bbc.co.uk/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://global.acer.com
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = *.local
R3 - URLSearchHook: AVG Security Toolbar BHO - {A3BC75A2-1F87-4686-AA43-5347D756017C} - C:\Program Files\AVG\AVG8\Toolbar\IEToolbar.dll
R3 - URLSearchHook: (no name) - *{CFBFAE00-17A6-11D0-99CB-00C04FD64497} - (no file)
F2 - REG:system.ini: UserInit=C:\WINDOWS\system32\userinit.exe,C:\WINDOWS\system32\twext.exe,C:\WINDOWS\system32\sdra64.exe,
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
O2 - BHO: WormRadar.com IESiteBlocker.NavFilter - {3CA2F312-6F6E-4B53-A66E-4E65E497C8C0} - C:\Program Files\AVG\AVG8\avgssie.dll
O2 - BHO: (no name) - {5C255C8A-E604-49b4-9D64-90988571CECB} - (no file)
O2 - BHO: Groove GFS Browser Helper - {72853161-30C5-4D22-B7F9-0BBC1D38A37E} - C:\PROGRA~1\MICROS~2\Office12\GRA8E1~1.DLL
O2 - BHO: Windows Live Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
O2 - BHO: AVG Security Toolbar BHO - {A3BC75A2-1F87-4686-AA43-5347D756017C} - C:\Program Files\AVG\AVG8\Toolbar\IEToolbar.dll
O2 - BHO: NAV Helper - {BDF3E430-B101-42AD-A544-FADC6B084872} - C:\Program Files\Norton AntiVirus\NavShExt.dll
O2 - BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll
O2 - BHO: JQSIEStartDetectorImpl - {E7E6F031-17CE-4C07-BC86-EABFE594F69C} - C:\Program Files\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll
O3 - Toolbar: Norton AntiVirus - {42CDD1BF-3FFB-4238-8AD1-7859DF00B1D6} - C:\Program Files\Norton AntiVirus\NavShExt.dll
O3 - Toolbar: AVG Security Toolbar - {CCC7A320-B3CA-4199-B1A6-9F516DD69829} - C:\Program Files\AVG\AVG8\Toolbar\IEToolbar.dll
O4 - HKLM\..\Run: [LaunchApp] Alaunch
O4 - HKLM\..\Run: [IgfxTray] C:\WINDOWS\system32\igfxtray.exe
O4 - HKLM\..\Run: [HotKeysCmds] C:\WINDOWS\system32\hkcmd.exe
O4 - HKLM\..\Run: [Persistence] C:\WINDOWS\system32\igfxpers.exe
O4 - HKLM\..\Run: [High Definition Audio Property Page Shortcut] HDAShCut.exe
O4 - HKLM\..\Run: [AzMixerSel] C:\Program Files\Realtek\InstallShield\AzMixerSel.exe
O4 - HKLM\..\Run: [SynTPLpr] C:\Program Files\Synaptics\SynTP\SynTPLpr.exe
O4 - HKLM\..\Run: [SynTPEnh] C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
O4 - HKLM\..\Run: [IMJPMIG8.1] "C:\WINDOWS\IME\imjp8_1\IMJPMIG.EXE" /Spoil /RemAdvDef /Migration32
O4 - HKLM\..\Run: [MSPY2002] C:\WINDOWS\system32\IME\PINTLGNT\ImScInst.exe /SYNC
O4 - HKLM\..\Run: [PHIME2002ASync] C:\WINDOWS\system32\IME\TINTLGNT\TINTSETP.EXE /SYNC
O4 - HKLM\..\Run: [PHIME2002A] C:\WINDOWS\system32\IME\TINTLGNT\TINTSETP.EXE /IMEName
O4 - HKLM\..\Run: [RTHDCPL] RTHDCPL.EXE
O4 - HKLM\..\Run: [Alcmtr] ALCMTR.EXE
O4 - HKLM\..\Run: [EPM-DM] c:\acer\epm\epm-dm.exe
O4 - HKLM\..\Run: [ePowerManagement] C:\Acer\ePM\ePM.exe boot
O4 - HKLM\..\Run: [ccApp] "C:\Program Files\Common Files\Symantec Shared\ccApp.exe"
O4 - HKLM\..\Run: [LManager] C:\PROGRA~1\LAUNCH~1\QtZgAcer.EXE
O4 - HKLM\..\Run: [eRecoveryService] C:\Program Files\Acer\eRecovery\Monitor.exe
O4 - HKLM\..\Run: [Symantec NetDriver Monitor] C:\PROGRA~1\SYMNET~1\SNDMon.exe /Consumer
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre6\bin\jusched.exe"
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
O4 - HKLM\..\Run: [GrooveMonitor] "C:\Program Files\Microsoft Office\Office12\GrooveMonitor.exe"
O4 - HKLM\..\Run: [AVG8_TRAY] C:\PROGRA~1\AVG\AVG8\avgtray.exe
O4 - HKCU\..\Run: [MsnMsgr] "C:\Program Files\Windows Live\Messenger\MsnMsgr.Exe" /background
O4 - HKCU\..\Run: [kdx] C:\Program Files\Kontiki\KHost.exe -all
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [Google Update] "C:\Documents and Settings\robert holwett\Local Settings\Application Data\Google\Update\GoogleUpdate.exe" /c
O4 - HKCU\..\Run: [tiuopu] C:\Documents and Settings\robert holwett\tiuopu.exe
O4 - HKCU\..\Run: [PopRock] C:\DOCUME~1\ROBERT~1\LOCALS~1\Temp\a.exe
O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'Default user')
O4 - Global Startup: Adobe Reader Speed Launch.lnk = C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office12\EXCEL.EXE/3000
O9 - Extra button: Send to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~2\Office12\ONBttnIE.dll
O9 - Extra 'Tools' menuitem: S&end to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~2\Office12\ONBttnIE.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\Office12\REFIEBAR.DLL
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O16 - DPF: {0CCA191D-13A6-4E29-B746-314DEE697D83} (Facebook Photo Uploader 5 Control) - http://upload.facebook.com/controls/2008.10.10_v5.5.8/FacebookPhotoUploader5.cab
O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) - http://go.microsoft.com/fwlink/?linkid=39204
O18 - Protocol: grooveLocalGWS - {88FED34C-F0CA-4636-A375-3CB6248B04CD} - C:\PROGRA~1\MICROS~2\Office12\GR99D3~1.DLL
O18 - Protocol: linkscanner - {F274614C-63F8-47D5-A4D1-FBDDE494F8D1} - C:\Program Files\AVG\AVG8\avgpp.dll
O20 - Winlogon Notify: avgrsstarter - C:\WINDOWS\SYSTEM32\avgrsstx.dll
O23 - Service: Notebook Manager Service (anbmService) - OSA Technologies Inc. - C:\Acer\eManager\anbmServ.exe
O23 - Service: Apple Mobile Device - Apple, Inc. - C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
O23 - Service: Automatic LiveUpdate Scheduler - Symantec Corporation - C:\Program Files\Symantec\LiveUpdate\ALUSchedulerSvc.exe
O23 - Service: AVG8 WatchDog (avg8wd) - AVG Technologies CZ, s.r.o. - C:\PROGRA~1\AVG\AVG8\avgwdsvc.exe
O23 - Service: Bonjour Service - Apple Inc. - C:\Program Files\Bonjour\mDNSResponder.exe
O23 - Service: Symantec Event Manager (ccEvtMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
O23 - Service: Symantec Password Validation (ccPwdSvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccPwdSvc.exe
O23 - Service: Symantec Settings Manager (ccSetMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe
O23 - Service: iPod Service - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: Java Quick Starter (JavaQuickStarterService) - Sun Microsystems, Inc. - C:\Program Files\Java\jre6\bin\jqs.exe
O23 - Service: KService - Kontiki Inc. - C:\Program Files\Kontiki\KService.exe
O23 - Service: Lavasoft Ad-Aware Service - Lavasoft - C:\Program Files\Lavasoft\Ad-Aware\AAWService.exe
O23 - Service: LiveUpdate - Symantec Corporation - C:\PROGRA~1\Symantec\LIVEUP~1\LUCOMS~1.EXE
O23 - Service: Norton AntiVirus Auto-Protect Service (navapsvc) - Symantec Corporation - C:\Program Files\Norton AntiVirus\navapsvc.exe
O23 - Service: Norton AntiVirus Firewall Monitor Service (NPFMntor) - Symantec Corporation - C:\Program Files\Norton AntiVirus\IWP\NPFMntor.exe
O23 - Service: Cyberlink RichVideo Service(CRVS) (RichVideo) - Unknown owner - C:\Program Files\CyberLink\Shared Files\RichVideo.exe (file missing)
O23 - Service: SAVScan - Symantec Corporation - C:\Program Files\Norton AntiVirus\SAVScan.exe
O23 - Service: ScriptBlocking Service (SBService) - Symantec Corporation - C:\PROGRA~1\COMMON~1\SYMANT~1\SCRIPT~1\SBServ.exe
O23 - Service: Symantec Network Drivers Service (SNDSrvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\SNDSrvc.exe
O23 - Service: Symantec SPBBCSvc (SPBBCSvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\SPBBC\SPBBCSvc.exe

--
End of file - 11719 bytes
=================
No response:
http://forums.techguy.org/malware-removal-hijackthis-logs/860580-trouble-exe-please-help.html

Waiting Room: http://forums.spybot.info/showthread.php?t=52004
 
Last edited by a moderator:
hi didsburydan,

Your log is several days old, if you still need help with the malware problem simply reply back.
 
ok. Try running malwarebytes (after checking for updates) in safe mode.
To reach safe mode you would tap the f8 key during a computer restart, chose the first option: safe mode. Once at the safe mode desktop run MBAM and post the log;


Perform FULL SCAN, then click Scan.
When the scan is complete, click OK, then Show Results to view the results.

Be sure that everything is checked, and click *Remove Selected.*

*A restart of your computer may be required to remove some items.*

When completed, a log will open in Notepad. Please save it to a convenient location. The log can also be opened by going to Start > All Programs > Malwarebytes' Anti-Malware > Logs > log-date.txt
Post the log in your reply.
 
ok, i left my friend to save a log last night as i had to go to work while MB was running. I'm fairly sure he let the scan complete but i can't find a log anywhere. i've gone into the logs tab in MB but there is nothing listed. would it be ok to run a full scan again and post the log i get from that?
 
... there is a log when i logged into safe mode as admin, but it not visible where i saved it when i logged back into windows normally on a profile with admin priviledges.
 
ignore last two posts, here is the log:

Malwarebytes' Anti-Malware 1.41
Database version: 2792
Windows 5.1.2600 Service Pack 3 (Safe Mode)

22/09/2009 20:39:23
mbam-log-2009-09-22 (20-39-23).txt

Scan type: Full Scan (C:\|D:\|)
Objects scanned: 174815
Time elapsed: 1 hour(s), 16 minute(s), 59 second(s)

Memory Processes Infected: 0
Memory Modules Infected: 0
Registry Keys Infected: 7
Registry Values Infected: 7
Registry Data Items Infected: 7
Folders Infected: 4
Files Infected: 21

Memory Processes Infected:
(No malicious items detected)

Memory Modules Infected:
(No malicious items detected)

Registry Keys Infected:
HKEY_USERS\.DEFAULT\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\{19127ad2-394b-70f5-c650-b97867baa1f7} (Backdoor.Bot) -> Quarantined and deleted successfully.
HKEY_USERS\.DEFAULT\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\{43bf8cd1-c5d5-2230-7bb2-98f22c2b7dc6} (Backdoor.Bot) -> Quarantined and deleted successfully.
HKEY_USERS\S-1-5-18\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\{19127ad2-394b-70f5-c650-b97867baa1f7} (Backdoor.Bot) -> Quarantined and deleted successfully.
HKEY_USERS\S-1-5-18\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\{43bf8cd1-c5d5-2230-7bb2-98f22c2b7dc6} (Backdoor.Bot) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\Setup.exe (Adware.Zango) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{c3d409df-0316-4fc0-89e2-dbdd885232a0} (Trojan.BHO) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\CLSID\{c3d409df-0316-4fc0-89e2-dbdd885232a0} (Trojan.BHO) -> Quarantined and deleted successfully.

Registry Values Infected:
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Network\UID (Malware.Trace) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\MSN\BN (Trojan.Ambler) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\MSN\D1 (Trojan.Ambler) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\MSN\D2 (Trojan.Ambler) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\MSN\D3 (Trojan.Ambler) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\MSN\gd (Trojan.Ambler) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\MSN\pr (Trojan.Ambler) -> Quarantined and deleted successfully.

Registry Data Items Infected:
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Userinit (Trojan.FakeAlert) -> Data: c:\windows\system32\sdra64.exe -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Userinit (Trojan.FakeAlert) -> Data: system32\sdra64.exe -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Userinit (Backdoor.Bot) -> Data: c:\windows\system32\twext.exe -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Userinit (Backdoor.Bot) -> Data: system32\twext.exe -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\AntiVirusDisableNotify (Disabled.SecurityCenter) -> Bad: (1) Good: (0) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\FirewallDisableNotify (Disabled.SecurityCenter) -> Bad: (1) Good: (0) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Userinit (Hijack.Userinit) -> Bad: (C:\WINDOWS\system32\userinit.exe,C:\WINDOWS\system32\twext.exe,C:\WINDOWS\system32\sdra64.exe,) Good: (Userinit.exe) -> Quarantined and deleted successfully.

Folders Infected:
C:\Documents and Settings\LocalService\Application Data\twain_32 (Trojan.Zbot) -> Quarantined and deleted successfully.
C:\Documents and Settings\robert holwett\Application Data\twain_32 (Trojan.Zbot) -> Quarantined and deleted successfully.
C:\WINDOWS\system32\lowsec (Stolen.data) -> Delete on reboot.
C:\WINDOWS\system32\twain_32 (Backdoor.Bot) -> Delete on reboot.

Files Infected:
C:\WINDOWS\msa.exe (Trojan.Downloader) -> Quarantined and deleted successfully.
C:\WINDOWS\Temp\fceqtgyosm.exe (Trojan.Downloader) -> Quarantined and deleted successfully.
C:\Documents and Settings\robert holwett\Local Settings\Temp\a.exe (Trojan.Downloader) -> Quarantined and deleted successfully.
C:\Documents and Settings\robert holwett\Local Settings\Temp\b.exe (Trojan.Downloader) -> Quarantined and deleted successfully.
C:\Documents and Settings\robert holwett\My Documents\Setup.exe (Adware.Zango) -> Quarantined and deleted successfully.
C:\Documents and Settings\LocalService\Application Data\twain_32\user.ds (Trojan.Zbot) -> Quarantined and deleted successfully.
C:\Documents and Settings\robert holwett\Application Data\twain_32\user.ds (Trojan.Zbot) -> Quarantined and deleted successfully.
C:\WINDOWS\system32\lowsec\user.ds (Stolen.data) -> Delete on reboot.
C:\WINDOWS\system32\lowsec\local.ds (Stolen.data) -> Delete on reboot.
C:\WINDOWS\system32\twain_32\local.ds (Backdoor.Bot) -> Delete on reboot.
C:\WINDOWS\system32\twain_32\user.ds (Backdoor.Bot) -> Delete on reboot.
C:\WINDOWS\system32\c2d.dat (Malware.Trace) -> Quarantined and deleted successfully.
C:\WINDOWS\system32\ca.dat (Malware.Trace) -> Quarantined and deleted successfully.
C:\WINDOWS\system32\idm.dat (Malware.Trace) -> Quarantined and deleted successfully.
C:\WINDOWS\system32\jc.dat (Malware.Trace) -> Quarantined and deleted successfully.
C:\WINDOWS\system32\q1.dat (Malware.Trace) -> Quarantined and deleted successfully.
C:\WINDOWS\system32\sdra64.exe (Trojan.FakeAlert) -> Delete on reboot.
C:\WINDOWS\system32\twext.exe (Backdoor.Bot) -> Delete on reboot.
C:\WINDOWS\system32\xd.dat (Malware.Trace) -> Quarantined and deleted successfully.
C:\WINDOWS\Tasks\{7B02EF0B-A410-4938-8480-9BA26420A627}.job (Trojan.Downloader) -> Quarantined and deleted successfully.
C:\WINDOWS\Tasks\{BB65B0FB-5712-401b-B616-E69AC55E2757}.job (Trojan.Downloader) -> Quarantined and deleted successfully.
=======================
Edit
http://forums.techguy.org/malware-removal-hijackthis-logs/860580-trouble-exe-please-help.html

Please let the techguy know you are already being assisted so they close that topic, thank you.
 
Last edited by a moderator:
ok good. We will get one more tool to use. Your friend should for sure change all passwords and monitor financial transactions if you did any on the computer.
The tool is SDFix. Only runs in safe mode. link and directions:


Download SDFix and save it to your Desktop.

http://downloads.andymanchesta.com/RemovalTools/SDFix.exe


Double click SDFix.exe and it will extract the files to %systemdrive%
(Drive that contains the Windows Directory, typically C:\SDFix)

Please then reboot your computer in Safe Mode by doing the following :

* Restart your computer
* After hearing your computer beep once during startup, but before the Windows icon appears, tap the F8 key continually;
* Instead of Windows loading as normal, the Advanced Options Menu should appear;
* Select the first option, to run Windows in Safe Mode, then press Enter.
* Choose your usual account.

* Open the extracted SDFix folder and double click RunThis.bat to start the script.
* Type Y to begin the cleanup process.
* It will remove any Trojan Services and Registry Entries that it finds then prompt you to press any key to Reboot.
* Press any Key and it will restart the PC.
* When the PC restarts the Fixtool will run again and complete the removal process then display Finished, press any key to end the script and load your desktop icons.
* Once the desktop icons load the SDFix report will open on screen and also save into the SDFix folder as Report.txt
(Report.txt will also be copied to Clipboard ready for posting back on the forum).
* Finally paste the contents of the Report.txt in your reply.
 
log is as follows

NB i encountered various error messages throughout this process. when trying to boot into safemode i got

Windows could not start because the following file is missin or corrupt <Windows root>\system32\ntoskrnl.exe

When i managed to get into safe mode and run SDFix i got several error messages when it was finishing, including:

CMD.exe - Corrupt File
The file or directory \Documents and Settings\robert holwett\Local Settings\Temp\etilqs_PYYy2ImQ8CQQvxY7ufGV is corrupt or unreadable. Please run Chkdsk utility
also \T2xxfhgGc0eCwyhrSqUe
also \fla39F.tmp

When i restarted into normal windows and SDFix was finishing and generating report is got CMD.exe - Corrupt file \SDFix\editreg.exe

When trying to get onto google chrome to post this i get a constant popup in my taskbar saying Windows -Corrupt file \Windows\Prefetch\CHROME.EXE-OO6D05A3.pf

don't know if any of this i important but i thought i'd mention it. here is log

SDFix: Version 1.240
Run by robert holwett on 23/09/2009 at 23:03

Microsoft Windows XP [Version 5.1.2600]
Running From: C:\SDFix

Checking Services :


Restoring Default Security Values
Restoring Default Hosts File

Rebooting


Checking Files :

Trojan Files Found:

C:\WINDOWS\antiv.exe - Deleted





Removing Temp Files

ADS Check :



Final Check :

catchme 0.3.1361.2 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2009-09-23 23:14:12
Windows 5.1.2600 Service Pack 3 FAT NTAPI

scanning hidden processes ...

scanning hidden services ...

HKLM\SYSTEM\CurrentControlSet\Services\GEARAspiWDMuvj

scanning hidden autostart entries ...

scanning hidden files ...


scan completed successfully
hidden processes: 0
hidden services: 1
hidden files: 0


Remaining Services :




Authorized Application Key Export:

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\standardprofile\authorizedapplications\list]
"%windir%\\system32\\sessmgr.exe"="%windir%\\system32\\sessmgr.exe:*:enabled:@xpsp2res.dll,-22019"
"C:\\Program Files\\Acer\\Acer Arcade\\PCMService.exe"="C:\\Program Files\\Acer\\Acer Arcade\\PCMService.exe:*:Enabled:CyberLink PowerCinema Resident Program"
"C:\\Program Files\\Messenger\\msmsgs.exe"="C:\\Program Files\\Messenger\\msmsgs.exe:*:Enabled:Windows Messenger"
"C:\\Program Files\\Kontiki\\KService.exe"="C:\\Program Files\\Kontiki\\KService.exe:*:Enabled:Delivery Manager Service"
"C:\\Program Files\\Bonjour\\mDNSResponder.exe"="C:\\Program Files\\Bonjour\\mDNSResponder.exe:*:Enabled:Bonjour"
"C:\\Program Files\\iTunes\\iTunes.exe"="C:\\Program Files\\iTunes\\iTunes.exe:*:Enabled:iTunes"
"%windir%\\Network Diagnostic\\xpnetdiag.exe"="%windir%\\Network Diagnostic\\xpnetdiag.exe:*:Enabled:@xpsp3res.dll,-20000"
"C:\\Program Files\\uTorrent\\uTorrent.exe"="C:\\Program Files\\uTorrent\\uTorrent.exe:*:Enabled:æTorrent"
"C:\\Program Files\\Microsoft Office\\Office12\\OUTLOOK.EXE"="C:\\Program Files\\Microsoft Office\\Office12\\OUTLOOK.EXE:*:Enabled:Microsoft Office Outlook"
"C:\\Program Files\\Microsoft Office\\Office12\\groove.exe"="C:\\Program Files\\Microsoft Office\\Office12\\groove.exe:*:Enabled:Microsoft Office Groove"
"C:\\Program Files\\Microsoft Office\\Office12\\ONENOTE.EXE"="C:\\Program Files\\Microsoft Office\\Office12\\ONENOTE.EXE:*:Enabled:Microsoft Office OneNote"
"C:\\Program Files\\Windows Live\\Messenger\\wlcsdk.exe"="C:\\Program Files\\Windows Live\\Messenger\\wlcsdk.exe:*:Enabled:Windows Live Call"
"C:\\Program Files\\Windows Live\\Messenger\\msnmsgr.exe"="C:\\Program Files\\Windows Live\\Messenger\\msnmsgr.exe:*:Enabled:Windows Live Messenger"
"C:\\Program Files\\AVG\\AVG8\\avgam.exe"="C:\\Program Files\\AVG\\AVG8\\avgam.exe:*:Enabled:avgam.exe"
"C:\\Program Files\\AVG\\AVG8\\avgdiag.exe"="C:\\Program Files\\AVG\\AVG8\\avgdiag.exe:*:Enabled:avgdiag.exe"
"C:\\Program Files\\AVG\\AVG8\\avgdiagex.exe"="C:\\Program Files\\AVG\\AVG8\\avgdiagex.exe:*:Enabled:avgdiagex.exe"
"C:\\Program Files\\AVG\\AVG8\\avgupd.exe"="C:\\Program Files\\AVG\\AVG8\\avgupd.exe:*:Enabled:avgupd.exe"
"C:\\Program Files\\AVG\\AVG8\\avgnsx.exe"="C:\\Program Files\\AVG\\AVG8\\avgnsx.exe:*:Enabled:avgnsx.exe"

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\domainprofile\authorizedapplications\list]
"%windir%\\system32\\sessmgr.exe"="%windir%\\system32\\sessmgr.exe:*:enabled:@xpsp2res.dll,-22019"
"%windir%\\Network Diagnostic\\xpnetdiag.exe"="%windir%\\Network Diagnostic\\xpnetdiag.exe:*:Enabled:@xpsp3res.dll,-20000"
"C:\\Program Files\\Windows Live\\Messenger\\wlcsdk.exe"="C:\\Program Files\\Windows Live\\Messenger\\wlcsdk.exe:*:Enabled:Windows Live Call"
"C:\\Program Files\\Windows Live\\Messenger\\msnmsgr.exe"="C:\\Program Files\\Windows Live\\Messenger\\msnmsgr.exe:*:Enabled:Windows Live Messenger"

Remaining Files :


File Backups: - C:\SDFix\backups\backups.zip

Files with Hidden Attributes :

Wed 17 Aug 2005 1,024 ...HR --- "C:\WINDOWS\system32\NTICDMK7.dll"
Wed 17 Aug 2005 1,024 ...HR --- "C:\WINDOWS\system32\NTIMPEG2.dll"
Wed 17 Aug 2005 1,024 ...HR --- "C:\WINDOWS\system32\NTIMP3.dll"
Wed 17 Aug 2005 1,024 ...HR --- "C:\WINDOWS\system32\NTIFCD3.dll"
Wed 17 Aug 2005 1,024 ...HR --- "C:\WINDOWS\system32\NTIBUN4.dll"
Sat 12 Sep 2009 49,152 ..SHR --- "C:\Documents and Settings\robert holwett\tiuopu.exe"
Sun 26 Aug 2007 4,348 A.SH. --- "C:\Documents and Settings\All Users\DRM\DRMv1.bak"
Mon 4 Jun 2007 0 A.SH. --- "C:\Documents and Settings\All Users\DRM\Cache\Indiv01.tmp"
Tue 2 Dec 2008 137,216 A..H. --- "C:\Documents and Settings\robert holwett\Desktop\SdaA-\~WRL3876.tmp"
Thu 19 Mar 2009 136,704 A..H. --- "C:\Documents and Settings\robert holwett\Desktop\SdaA-\~WRL1663.tmp"
Sun 27 Apr 2008 82,944 A..H. --- "C:\Documents and Settings\robert holwett\My Documents\ROB\Lab project\~WRL0002.tmp"

Finished!
 
ok thanks for the info. You can delete the SDfix folder located at C:/
not sure what all the corrupt files are about. You should back up anything you cant afford to lose, just in case.

RE:uTorrent, There is plenty of malware that is distributed via p2p networks one can download and install. Files can be named anything and/or have malware payloads bundled in them.

Please do a online scan:

ESET online scanner:

http://www.eset.com/onlinescan/

uses Internet Explorer only
check "YES" to accept terms
click start button
allow the ActiveX component to install
click the start button. the Scanner will update.
check both "Remove found threats" and "Scan unwanted applications"
click scan
when done you can find the scan log at:C:\Program Files\EsetOnlineScanner\log.txt
please copy/paste that log in next reply.
 
Ok, here's the log but fyi the scan crashed at about 28% with the message OnlineCmdLineScanner.exe has encountered a problem and needs to close.

ESETSmartInstaller@High as CAB hook log:
OnlineScanner.ocx - registred OK
# version=6
# iexplore.exe=6.00.2900.5512 (xpsp.080413-2105)
# OnlineScanner.ocx=1.0.0.6050
# api_version=3.0.2
# EOSSerial=0c61988a6a891746a2f8949284fc1d93
# end=finished
# remove_checked=true
# archives_checked=true
# unwanted_checked=true
# unsafe_checked=false
# antistealth_checked=true
# utc_time=2009-09-24 06:38:00
# local_time=2009-09-24 07:38:00 (+0000, GMT Daylight Time)
# country="United Kingdom"
# lang=1033
# osver=5.1.2600 NT Service Pack 3
# compatibility_mode=1027 21 83 59 28626406250
# scanned=28560
# found=2
# cleaned=2
# scan_time=1204
C:\WINDOWS\system32\yxhl0.dll a variant of Win32/Spy.Ambler.AD trojan (cleaned by deleting - quarantined) 00000000000000000000000000000000 C
C:\WINDOWS\system32\ixyp1.dll a variant of Win32/Spy.Ambler.AD trojan (cleaned by deleting - quarantined) 00000000000000000000000000000000 C
 
Ok.One more tool to download and run. Its called Combofix. There is a guide to read first. Read through the entire guide- make sure you understand what you need to do in preparation for using Combofix. Download combofix to your desktop, disable any AV etc as explained in the guide, double click the icon and follow the prompts as shown in the guide:

Preparation Guide for using Combofix.
 
combofix is not working. I got it running and it found first file C:\WINDOWS\system32\sfcfiles.dll but then i kept getting repeated error messages such as PV.cfxxe and Nircmd have encountered a problem and need to close. I clicked on don't send error report on all of these messages in order for combofix to continue running, but it hangs on sfcfiles.dll.
 
ok, no error messages this time but combofix is still hanging on
"System file in infected!! Attempting to restore C:\WINDOWS\system32\sfcfiles.dll

pretty sure i'm not just being impatient, i left it running while i was watching an hour long episode of the sopranos and it didn't move from that message. all anti virus stuff is disabled as per the guide instructions.
 
dosnt sound good. lets try this:

Download Dr.Web CureIt to the desktop:

ftp://ftp.drweb.com/pub/drweb/cureit/drweb-cureit.exe

* Doubleclick the drweb-cureit icon to start the program.
* press start
* Allow the program to run the initial express scan
* This will scan the files currently running in memory. If something is found, click the YES button when it asks you if you want to cure it. This is only a short scan.
Note: A pop up may appear during this phase suggesting you purchase their program - click the X at the top right corner of this pop-up to close it.
* Once the short scan has finished, check the Complete scan box on the left side, even if nothing was found on the initial scan.
* Then click the small green arrow button on the right under the Dr.Web Antivirus picture to start the complete scan. (This scan will take several hours)
* During this complete scan - if Dr.Web finds an infection a window will pop up requesting your attention. Select the Cure button.
Note:(If the file cannot be cured, Dr.Web will automatically delete the file)
* Once the scan is complete, on the menu bar, click file and choose report list.
* Save the report to your desktop. The report will be called DrWeb.csv
* Note:this report will need to be renamed to Dr.Web.txt in order to post it on the forum.
* Close Dr.Web Cureit.
* Please post the Dr.Web.txt report in your next reply
 
ok, this also doesn't work. i think i may have a deeper rooted problem with my computer than malware, although it was fine before i got infected.
i tried it the program once and it started up ok and then crashed, went to safe mode to try it and got IO error on "Autorun BMP" and a message on taskbar saying 93.gu83.exe - corrupt file.
 
hi,

i think i may have a deeper rooted problem with my computer than malware
malware can cause deep rooted problems on a machine.

Try uninstalling combofix like this:
start>run and type in combofix /u
click ok or enter
Note; there is a space after the x and before the /

Try downloading a new copy of combofix but this time before you save it to your desktop, rename it to combofix1.exe. Then try running it. dont forget to disable any AV etc first.
 
ok,despite warning messages telling me numerous file were corrupt and unreadable i'm pretty sure combfix ran fully. here's my log:

ComboFix 09-10-05.01 - robert holwett 06/10/2009 16:01.1.1 - FAT32x86
Microsoft Windows XP Home Edition 5.1.2600.3.1252.1.1033.18.1014.640 [GMT 1:00]
Running from: c:\documents and settings\robert holwett\Desktop\ComboFix1.exe
AV: AVG Anti-Virus *On-access scanning disabled* (Updated) {17DDD097-36FF-435F-9E1B-52D74245D6BF}
.

Overlay aborted ... Please run ComboFix once more
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.

c:\docume~1\ROBERT~1\LOCALS~1\Temp\dc62710146\93gu83.exe
c:\documents and settings\robert holwett\autorun.inf
c:\documents and settings\robert holwett\Local Settings\Temp\dc62710146\93gu83.exe
c:\documents and settings\robert holwett\tiuopu.exe
c:\documents and settings\robert holwett\tiuopu.scr
c:\program files\WinPCap
c:\windows\Installer\2a3c8f.msi
c:\windows\Installer\3051656.msp
c:\windows\Installer\417708.msi
c:\windows\Installer\41770b.msi
c:\windows\Installer\826eb.msp
c:\windows\Installer\826ec.msp
c:\windows\Installer\826ed.msp
c:\windows\Installer\826ee.msp
c:\windows\Installer\826ef.msp
c:\windows\Installer\826f0.msp
c:\windows\Installer\826f1.msp
c:\windows\Installer\826f2.msp
c:\windows\Installer\826f3.msp
c:\windows\Installer\87f8d1.msp
c:\windows\system32\mscomct2.dat
c:\windows\system32\mscorewr.dll
c:\windows\system32\msrfcint.dat
c:\windows\system32\ntrdectr.dat
c:\windows\system32\pthreadVC.dll

.
((((((((((((((((((((((((((((((((((((((( Drivers/Services )))))))))))))))))))))))))))))))))))))))))))))))))
.

-------\Legacy_NPF
-------\Legacy_SFC
-------\Service_sfc


((((((((((((((((((((((((( Files Created from 2009-09-06 to 2009-10-06 )))))))))))))))))))))))))))))))
.

2009-10-05 09:18 . 2009-10-05 09:18 -------- d-----w- C:\ComboFix119319C
2009-10-05 09:13 . 2009-10-05 09:13 -------- d-----w- C:\ComboFix1
2009-09-28 13:40 . 2009-09-28 13:40 -------- d-----w- c:\documents and settings\robert holwett\Application Data\Jasc Software Inc
2009-09-28 13:40 . 2009-09-28 13:40 -------- d-----w- c:\documents and settings\All Users\Application Data\InstallShield
2009-09-28 13:39 . 2009-09-28 13:39 -------- d-----w- c:\program files\Common Files\Jasc Software Inc
2009-09-28 13:39 . 2009-09-28 13:39 -------- d-----w- c:\program files\Jasc Software Inc
2009-09-28 13:38 . 2009-09-28 13:38 -------- d-----w- c:\program files\Abbyy FineReader 6.0 Sprint
2009-09-28 13:37 . 2004-08-04 04:00 31744 ----a-w- c:\windows\system32\fxsroute.dll
2009-09-28 13:37 . 2004-08-04 04:00 132608 ----a-w- c:\windows\system32\fxsclntR.dll
2009-09-28 13:37 . 2004-08-04 04:00 11264 ----a-w- c:\windows\system32\fxssend.exe
2009-09-28 13:37 . 2004-08-04 04:00 111104 ----a-w- c:\windows\system32\fxscfgwz.dll
2009-09-28 13:36 . 2009-09-28 13:36 -------- d-----w- c:\program files\Dl_cats
2009-09-28 13:36 . 2004-08-04 04:00 9600 ----a-w- c:\windows\system32\drivers\hidusb.sys
2009-09-28 13:35 . 2001-08-17 21:36 87040 ----a-w- c:\windows\system32\wiafbdrv.dll
2009-09-28 13:33 . 2009-09-28 13:33 -------- d-----w- c:\temp\{9F5FBC24-EFE2-4f90-B498-EC0FB7D47D15}
2009-09-28 13:33 . 2009-09-28 13:33 -------- d-----w- C:\Temp
2009-09-28 13:31 . 2008-04-13 18:47 25856 ----a-w- c:\windows\system32\drivers\usbprint.sys
2009-09-28 13:30 . 2004-08-04 04:00 31616 ----a-w- c:\windows\system32\drivers\usbccgp.sys
2009-09-28 02:01 . 2009-09-28 02:01 -------- d-----w- c:\documents and settings\robert holwett\DoctorWeb
2009-09-24 18:14 . 2009-09-24 18:15 -------- d-----w- c:\program files\ESET
2009-09-23 22:01 . 2009-09-23 22:01 578560 ----a-w- c:\windows\system32\dllcache\user32.dll
2009-09-23 21:56 . 2009-09-23 21:56 -------- d-----w- c:\windows\ERUNT
2009-09-22 18:12 . 2009-09-22 18:12 -------- d-----w- c:\documents and settings\Administrator\Application Data\Malwarebytes
2009-09-20 18:17 . 2009-09-20 18:17 -------- d-----w- c:\program files\CCleaner
2009-09-15 00:13 . 2009-09-15 00:13 27656 ----a-w- c:\windows\system32\drivers\pxsec.sys
2009-09-15 00:13 . 2009-09-15 00:13 22024 ----a-w- c:\windows\system32\drivers\pxscan.sys
2009-09-15 00:13 . 2009-09-15 00:13 -------- d-----w- c:\program files\Prevx
2009-09-15 00:13 . 2009-09-15 00:13 -------- d-----w- c:\documents and settings\All Users\Application Data\PrevxCSI
2009-09-13 22:07 . 2009-09-13 22:07 -------- d-----w- c:\program files\Trend Micro
2009-09-13 20:42 . 2009-09-13 20:42 -------- d-----w- c:\documents and settings\robert holwett\Application Data\Malwarebytes
2009-09-13 20:42 . 2009-09-10 13:54 38224 ----a-w- c:\windows\system32\drivers\mbamswissarmy.sys
2009-09-13 20:42 . 2009-09-13 20:42 -------- d-----w- c:\program files\Malwarebytes' Anti-Malware
2009-09-13 20:42 . 2009-09-13 20:42 -------- d-----w- c:\documents and settings\All Users\Application Data\Malwarebytes
2009-09-13 20:42 . 2009-09-10 13:53 19160 ----a-w- c:\windows\system32\drivers\mbam.sys
2009-09-13 18:45 . 2009-09-13 18:45 -------- d-----w- C:\$AVG8.VAULT$
2009-09-13 18:43 . 2009-09-13 18:43 12552 ----a-w- c:\windows\system32\drivers\avgrkx86.sys
2009-09-13 18:43 . 2009-09-13 18:43 11952 ----a-w- c:\windows\system32\avgrsstx.dll
2009-09-13 18:43 . 2009-09-13 18:43 108552 ----a-w- c:\windows\system32\drivers\avgtdix.sys
2009-09-13 18:42 . 2009-09-13 18:42 335240 ----a-w- c:\windows\system32\drivers\avgldx86.sys
2009-09-13 18:42 . 2009-09-13 18:42 27784 ----a-w- c:\windows\system32\drivers\avgmfx86.sys
2009-09-13 18:42 . 2009-09-13 18:42 -------- d-----w- c:\windows\system32\drivers\Avg
2009-09-13 18:42 . 2009-09-13 18:42 -------- d-----w- c:\documents and settings\All Users\Application Data\AVG Security Toolbar
2009-09-13 18:42 . 2009-09-13 18:42 -------- d-----w- c:\program files\AVG
2009-09-13 18:42 . 2009-09-13 18:42 -------- d-----w- c:\documents and settings\All Users\Application Data\avg8
2009-09-13 18:35 . 2009-09-13 18:35 -------- d-----w- c:\documents and settings\robert holwett\Application Data\AVG8
2009-09-13 17:46 . 2009-07-03 14:49 64160 ----a-w- c:\windows\system32\drivers\Lbd.sys
2009-09-13 17:45 . 2009-09-13 17:45 -------- d--h--w- c:\documents and settings\All Users\Application Data\{EF63305C-BAD7-4144-9208-D65528260864}
2009-09-13 17:45 . 2009-09-13 17:45 -------- d-----w- c:\program files\Lavasoft
2009-09-13 17:45 . 2009-09-13 17:45 -------- d-----w- c:\documents and settings\All Users\Application Data\Lavasoft
2009-09-09 09:37 . 2009-06-21 21:44 153088 ------w- c:\windows\system32\dllcache\triedit.dll

.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2009-09-28 13:34 . 2009-09-28 13:34 -------- d-----w- c:\program files\Dell Photo AIO Printer 924
2009-09-27 23:03 . 2007-05-25 15:54 90112 ----a-w- c:\windows\DUMP3cf9.tmp
2009-09-27 22:03 . 2007-05-25 15:54 90112 ----a-w- c:\windows\DUMP3c5d.tmp
2009-09-27 13:59 . 2007-05-25 15:54 90112 ----a-w- c:\windows\DUMP3c8c.tmp
2009-09-23 19:50 . 2007-05-25 15:54 90112 ----a-w- c:\windows\DUMP3d28.tmp
2009-09-23 18:44 . 2007-05-25 15:54 90112 ----a-w- c:\windows\DUMP48b1.tmp
2009-09-22 21:40 . 2007-05-25 15:54 90112 ----a-w- c:\windows\DUMP50ee.tmp
2009-09-22 16:57 . 2007-05-25 15:54 90112 ----a-w- c:\windows\DUMP3cab.tmp
2009-08-21 05:18 . 2009-08-21 05:18 -------- d-----w- c:\program files\PeerGuardian2
2009-08-20 17:53 . 2009-08-20 17:53 411368 ----a-w- c:\windows\system32\deploytk.dll
2009-08-18 22:57 . 2007-05-26 00:02 90416 ----a-w- c:\documents and settings\robert holwett\Local Settings\Application Data\GDIPFONTCACHEV1.DAT
2009-08-09 06:21 . 2009-08-09 06:21 -------- d-----w- c:\program files\Reference Assemblies
2009-08-08 18:33 . 2009-08-08 18:33 -------- d-----w- c:\documents and settings\robert holwett\Application Data\vlc
2009-08-08 18:32 . 2009-08-08 18:32 -------- d-----w- c:\program files\VideoLAN
2009-08-08 18:10 . 2009-08-08 18:10 -------- d-----w- c:\program files\Common Files\DivX Shared
2009-08-05 09:01 . 2005-08-16 15:57 204800 ----a-w- c:\windows\system32\mswebdvd.dll
2009-07-17 19:01 . 2005-08-16 15:57 58880 ----a-w- c:\windows\system32\atl.dll
2009-07-13 22:43 . 2005-08-16 15:58 286208 ----a-w- c:\windows\system32\wmpdxm.dll
.

((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4

[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\URLSearchHooks]
"{A3BC75A2-1F87-4686-AA43-5347D756017C}"= "c:\program files\AVG\AVG8\Toolbar\IEToolbar.dll" [2009-09-02 1107200]

[HKEY_CLASSES_ROOT\clsid\{a3bc75a2-1f87-4686-aa43-5347d756017c}]

[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{A3BC75A2-1F87-4686-AA43-5347D756017C}]
2009-09-02 10:58 1107200 ----a-w- c:\program files\AVG\AVG8\Toolbar\IEToolbar.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar]
"{CCC7A320-B3CA-4199-B1A6-9F516DD69829}"= "c:\program files\AVG\AVG8\Toolbar\IEToolbar.dll" [2009-09-02 1107200]

[HKEY_CLASSES_ROOT\clsid\{ccc7a320-b3ca-4199-b1a6-9f516dd69829}]

[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Toolbar\Webbrowser]
"{CCC7A320-B3CA-4199-B1A6-9F516DD69829}"= "c:\program files\AVG\AVG8\Toolbar\IEToolbar.dll" [2009-09-02 1107200]

[HKEY_CLASSES_ROOT\clsid\{ccc7a320-b3ca-4199-b1a6-9f516dd69829}]

c:\documents and settings\All Users\Start Menu\Programs\Startup\
Adobe Reader Speed Launch.lnk - c:\program files\Adobe\Acrobat 7.0\Reader\reader_sl.exe [2008-4-23 29696]

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\avgrsstarter]
2009-09-13 18:43 11952 ----a-w- c:\windows\system32\avgrsstx.dll

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\Lavasoft Ad-Aware Service]
@="Service"

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"c:\\Program Files\\Acer\\Acer Arcade\\PCMService.exe"=
"c:\\Program Files\\Messenger\\msmsgs.exe"=
"c:\\Program Files\\Kontiki\\KService.exe"=
"c:\\Program Files\\Bonjour\\mDNSResponder.exe"=
"c:\\Program Files\\iTunes\\iTunes.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"c:\\Program Files\\uTorrent\\uTorrent.exe"=
"c:\\Program Files\\Microsoft Office\\Office12\\OUTLOOK.EXE"=
"c:\\Program Files\\Microsoft Office\\Office12\\groove.exe"=
"c:\\Program Files\\Microsoft Office\\Office12\\ONENOTE.EXE"=
"c:\\Program Files\\Windows Live\\Messenger\\wlcsdk.exe"=
"c:\\Program Files\\Windows Live\\Messenger\\msnmsgr.exe"=
"c:\\Program Files\\AVG\\AVG8\\avgam.exe"=
"c:\\Program Files\\AVG\\AVG8\\avgdiag.exe"=
"c:\\Program Files\\AVG\\AVG8\\avgdiagex.exe"=
"c:\\Program Files\\AVG\\AVG8\\avgupd.exe"=
"c:\\Program Files\\AVG\\AVG8\\avgnsx.exe"=

R0 AvgRkx86;avgrkx86.sys;c:\windows\system32\drivers\avgrkx86.sys [13/09/2009 19:43 12552]
R0 Lbd;Lbd;c:\windows\system32\drivers\Lbd.sys [13/09/2009 18:46 64160]
R0 pxscan;pxscan;c:\windows\system32\drivers\pxscan.sys [15/09/2009 01:13 22024]
R0 pxsec;pxsec;c:\windows\system32\drivers\pxsec.sys [15/09/2009 01:13 27656]
R1 AvgLdx86;AVG AVI Loader Driver x86;c:\windows\system32\drivers\avgldx86.sys [13/09/2009 19:42 335240]
R1 AvgTdiX;AVG8 Network Redirector;c:\windows\system32\drivers\avgtdix.sys [13/09/2009 19:43 108552]
R2 CSIScanner;CSIScanner;c:\program files\Prevx\prevx.exe [15/09/2009 01:13 4368952]
S2 avg8wd;AVG8 WatchDog;c:\progra~1\AVG\AVG8\avgwdsvc.exe [13/09/2009 19:42 297752]
S3 Lavasoft Ad-Aware Service;Lavasoft Ad-Aware Service;c:\program files\Lavasoft\Ad-Aware\AAWService.exe [03/07/2009 15:49 1028432]

--- Other Services/Drivers In Memory ---

*NewlyCreated* - INT15.SYS
.
Contents of the 'Scheduled Tasks' folder

2009-10-05 c:\windows\Tasks\Ad-Aware Update (Weekly).job
- c:\program files\Lavasoft\Ad-Aware\Ad-AwareAdmin.exe [2009-07-03 17:48]

2009-10-05 c:\windows\Tasks\GoogleUpdateTaskUserS-1-5-21-651552052-1045895897-2323511181-1005Core.job
- c:\documents and settings\robert holwett\Local Settings\Application Data\Google\Update\GoogleUpdate.exe [2009-07-29 19:59]
.
.
------- Supplementary Scan -------
.
uStart Page = hxxp://news.bbc.co.uk/
uInternet Settings,ProxyOverride = *.local
IE: E&xport to Microsoft Excel - c:\progra~1\MICROS~2\Office12\EXCEL.EXE/3000
DPF: {7530BFB8-7293-4D34-9923-61A11451AFC5} - hxxp://download.eset.com/special/eos/OnlineScanner.cab
.

**************************************************************************

catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2009-10-06 16:13
Windows 5.1.2600 Service Pack 3 FAT NTAPI

scanning hidden processes ...

scanning hidden autostart entries ...

HKLM\Software\Microsoft\Windows\CurrentVersion\Run
DLCCCATS = rundll32 c:\windows\System32\spool\DRIVERS\W32X86\3\DLCCtime.dll,_RunDLLEntry@16???????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????

scanning hidden files ...


c:\docume~1\ROBERT~1\LOCALS~1\Temp\WPDNSE\. 16941056 bytes
c:\docume~1\ROBERT~1\LOCALS~1\Temp\WPDNSE\. 16875520 bytes
c:\docume~1\ROBERT~1\LOCALS~1\Temp\WPDNSE\. 33718272 bytes
c:\docume~1\ROBERT~1\LOCALS~1\Temp\WPDNSE\. -1056997376 bytes
c:\windows\TEMP\Temporary Internet Files\Content.IE5\s 2981888 bytes
c:\windows\TEMP\Temporary Internet Files\Content.IE5\0 2129920 bytes
c:\windows\TEMP\Temporary Internet Files\Content.IE5\p 3178496 bytes
c:\windows\TEMP\Temporary Internet Files\Content.IE5\8 3637248 bytes
c:\windows\TEMP\Temporary Internet Files\Content.IE5\F 3244032 bytes
c:\windows\TEMP\Temporary Internet Files\Content.IE5\c 3440640 bytes
c:\windows\TEMP\Temporary Internet Files\Content.IE5\0 4292608 bytes
c:\windows\TEMP\Temporary Internet Files\Content.IE5\8 3637248 bytes
c:\windows\TEMP\Temporary Internet Files\Content.IE5\T 884736 bytes
c:\windows\TEMP\Temporary Internet Files\Content.IE5\
c:\windows\TEMP\Temporary Internet Files\Content.IE5\O 4947968 bytes
c:\windows\TEMP\Temporary Internet Files\Content.IE5\s 2981888 bytes
c:\windows\TEMP\Temporary Internet Files\Content.IE5\0 2129920 bytes
c:\windows\TEMP\Temporary Internet Files\Content.IE5\p 3178496 bytes
c:\windows\TEMP\Temporary Internet Files\Content.IE5\8 3637248 bytes
c:\windows\TEMP\Temporary Internet Files\Content.IE5\F 3244032 bytes
c:\windows\TEMP\Temporary Internet Files\Content.IE5\c 3440640 bytes
c:\windows\TEMP\Temporary Internet Files\Content.IE5\0 4292608 bytes
c:\windows\TEMP\Temporary Internet Files\Content.IE5\L 3768320 bytes
c:\windows\TEMP\Temporary Internet Files\Content.IE5\0 884736 bytes
c:\windows\TEMP\Temporary Internet Files\Content.IE5\
c:\windows\TEMP\Temporary Internet Files\Content.IE5\4 3768320 bytes
c:\windows\TEMP\Temporary Internet Files\Content.IE5\N 5406720 bytes
c:\windows\TEMP\Temporary Internet Files\Content.IE5\s 2981888 bytes
c:\windows\TEMP\Temporary Internet Files\Content.IE5\0 2129920 bytes
c:\windows\TEMP\Temporary Internet Files\Content.IE5\p 3178496 bytes
c:\windows\TEMP\Temporary Internet Files\Content.IE5\8 3637248 bytes
c:\windows\TEMP\Temporary Internet Files\Content.IE5\F 3244032 bytes
c:\windows\TEMP\Temporary Internet Files\Content.IE5\c 3440640 bytes
c:\windows\TEMP\Temporary Internet Files\Content.IE5\0 4489216 bytes
c:\windows\TEMP\Temporary Internet Files\Content.IE5\/ 6717440 bytes
c:\windows\TEMP\Temporary Internet Files\Content.IE5\6 884736 bytes
c:\windows\TEMP\Temporary Internet Files\Content.IE5\
c:\windows\TEMP\Temporary Internet Files\Content.IE5\p 8028160 bytes
c:\windows\TEMP\Temporary Internet Files\Content.IE5\8 5406720 bytes
c:\windows\TEMP\Temporary Internet Files\Content.IE5\s 2981888 bytes
c:\windows\TEMP\Temporary Internet Files\Content.IE5\0 2129920 bytes
c:\windows\TEMP\Temporary Internet Files\Content.IE5\p 3178496 bytes
c:\windows\TEMP\Temporary Internet Files\Content.IE5\8 3637248 bytes
c:\windows\TEMP\Temporary Internet Files\Content.IE5\F 3244032 bytes
c:\windows\TEMP\Temporary Internet Files\Content.IE5\c 3440640 bytes
c:\windows\TEMP\Temporary Internet Files\Content.IE5\0 4358144 bytes
c:\windows\TEMP\Temporary Internet Files\Content.IE5\t 5406720 bytes
c:\windows\TEMP\Temporary Internet Files\Content.IE5\i 884736 bytes
c:\windows\TEMP\Temporary Internet Files\Content.IE5\
c:\windows\TEMP\Temporary Internet Files\Content.IE5\W 3637248 bytes
c:\windows\TEMP\Temporary Internet Files\Content.IE5\n 5406720 bytes
c:\windows\TEMP\Temporary Internet Files\Content.IE5\s 2981888 bytes
c:\windows\TEMP\Temporary Internet Files\Content.IE5\0 2129920 bytes
c:\windows\TEMP\Temporary Internet Files\Content.IE5\p 3178496 bytes
c:\windows\TEMP\Temporary Internet Files\Content.IE5\8 3637248 bytes
c:\windows\TEMP\Temporary Internet Files\Content.IE5\F 3244032 bytes
c:\windows\TEMP\Temporary Internet Files\Content.IE5\c 3440640 bytes
c:\windows\TEMP\Temporary Internet Files\Content.IE5\0 4423680 bytes
c:\windows\TEMP\Temporary Internet Files\Content.IE5\y 5144576 bytes
c:\windows\TEMP\Temporary Internet Files\Content.IE5\B 884736 bytes
c:\windows\TEMP\Temporary Internet Files\Content.IE5\
c:\windows\TEMP\Temporary Internet Files\Content.IE5\p 8028160 bytes
c:\windows\TEMP\Temporary Internet Files\Content.IE5\8 5406720 bytes
c:\windows\TEMP\Temporary Internet Files\Content.IE5\s 2981888 bytes
c:\windows\TEMP\Temporary Internet Files\Content.IE5\0 2129920 bytes
c:\windows\TEMP\Temporary Internet Files\Content.IE5\p 3178496 bytes
c:\windows\TEMP\Temporary Internet Files\Content.IE5\8 3637248 bytes
c:\windows\TEMP\Temporary Internet Files\Content.IE5\F 3244032 bytes
c:\windows\TEMP\Temporary Internet Files\Content.IE5\c 3440640 bytes
c:\windows\TEMP\Temporary Internet Files\Content.IE5\0 4358144 bytes
c:\windows\TEMP\Temporary Internet Files\Content.IE5\O 4358144 bytes
c:\windows\TEMP\Temporary Internet Files\Content.IE5\X 884736 bytes
c:\windows\TEMP\Temporary Internet Files\Content.IE5\
c:\windows\TEMP\Temporary Internet Files\Content.IE5\s 2981888 bytes
c:\windows\TEMP\Temporary Internet Files\Content.IE5\0 2129920 bytes
c:\windows\TEMP\Temporary Internet Files\Content.IE5\p 3178496 bytes
c:\windows\TEMP\Temporary Internet Files\Content.IE5\8 3637248 bytes
c:\windows\TEMP\Temporary Internet Files\Content.IE5\F 3244032 bytes
c:\windows\TEMP\Temporary Internet Files\Content.IE5\c 3440640 bytes
c:\windows\TEMP\Temporary Internet Files\Content.IE5\0 4423680 bytes
c:\windows\TEMP\Temporary Internet Files\Content.IE5\y 3506176 bytes
c:\windows\TEMP\Temporary Internet Files\Content.IE5\E 884736 bytes
c:\windows\TEMP\Temporary Internet Files\Content.IE5\
c:\windows\TEMP\Temporary Internet Files\Content.IE5\n 5603328 bytes
c:\windows\TEMP\Temporary Internet Files\Content.IE5\s 2981888 bytes
c:\windows\TEMP\Temporary Internet Files\Content.IE5\0 2129920 bytes
c:\windows\TEMP\Temporary Internet Files\Content.IE5\p 3178496 bytes
c:\windows\TEMP\Temporary Internet Files\Content.IE5\8 3637248 bytes
c:\windows\TEMP\Temporary Internet Files\Content.IE5\F 3244032 bytes
c:\windows\TEMP\Temporary Internet Files\Content.IE5\c 3440640 bytes
c:\windows\TEMP\Temporary Internet Files\Content.IE5\0 4358144 bytes
c:\windows\TEMP\Temporary Internet Files\Content.IE5\w 4423680 bytes
c:\windows\TEMP\Temporary Internet Files\Content.IE5\l 884736 bytes
c:\windows\TEMP\Temporary Internet Files\Content.IE5\
c:\windows\TEMP\Temporary Internet Files\Content.IE5\Y 7372800 bytes
c:\windows\TEMP\Temporary Internet Files\Content.IE5\k 5406720 bytes
c:\windows\TEMP\Temporary Internet Files\Content.IE5\s 2981888 bytes
c:\windows\TEMP\Temporary Internet Files\Content.IE5\0 2129920 bytes
c:\windows\TEMP\Temporary Internet Files\Content.IE5\p 3178496 bytes
c:\windows\TEMP\Temporary Internet Files\Content.IE5\8 3637248 bytes
c:\windows\TEMP\Temporary Internet Files\Content.IE5\F 3244032 bytes
c:\windows\TEMP\Temporary Internet Files\Content.IE5\c 3440640 bytes
c:\windows\TEMP\Temporary Internet Files\Content.IE5\0 4423680 bytes
c:\windows\TEMP\Temporary Internet Files\Content.IE5\y 5144576 bytes
c:\windows\TEMP\Temporary Internet Files\Content.IE5\B 884736 bytes
c:\windows\TEMP\Temporary Internet Files\Content.IE5\
c:\windows\TEMP\Temporary Internet Files\Content.IE5\O 4947968 bytes
c:\windows\TEMP\Temporary Internet Files\Content.IE5\s 2981888 bytes
c:\windows\TEMP\Temporary Internet Files\Content.IE5\0 2129920 bytes
c:\windows\TEMP\Temporary Internet Files\Content.IE5\p 3178496 bytes
c:\windows\TEMP\Temporary Internet Files\Content.IE5\8 3637248 bytes
c:\windows\TEMP\Temporary Internet Files\Content.IE5\F 3244032 bytes
c:\windows\TEMP\Temporary Internet Files\Content.IE5\c 3440640 bytes
c:\windows\TEMP\Temporary Internet Files\Content.IE5\0 4292608 bytes
c:\windows\TEMP\Temporary Internet Files\Content.IE5\8 3637248 bytes
c:\windows\TEMP\Temporary Internet Files\Content.IE5\T 884736 bytes
c:\windows\TEMP\Temporary Internet Files\Content.IE5\
c:\windows\TEMP\Temporary Internet Files\Content.IE5\z 5210112 bytes
c:\windows\TEMP\Temporary Internet Files\Content.IE5\n 5406720 bytes
c:\windows\TEMP\Temporary Internet Files\Content.IE5\s 2981888 bytes
c:\windows\TEMP\Temporary Internet Files\Content.IE5\0 2129920 bytes
c:\windows\TEMP\Temporary Internet Files\Content.IE5\p 3178496 bytes
c:\windows\TEMP\Temporary Internet Files\Content.IE5\8 3637248 bytes
c:\windows\TEMP\Temporary Internet Files\Content.IE5\F 3244032 bytes
c:\windows\TEMP\Temporary Internet Files\Content.IE5\c 3440640 bytes
c:\windows\TEMP\Temporary Internet Files\Content.IE5\0 4358144 bytes
c:\windows\TEMP\Temporary Internet Files\Content.IE5\t 5406720 bytes
c:\windows\TEMP\Temporary Internet Files\Content.IE5\i 884736 bytes
c:\windows\TEMP\Temporary Internet Files\Content.IE5\
c:\windows\TEMP\Temporary Internet Files\Content.IE5\z 7700480 bytes
c:\windows\TEMP\Temporary Internet Files\Content.IE5\l 5406720 bytes
c:\windows\TEMP\Temporary Internet Files\Content.IE5\s 2981888 bytes
c:\windows\TEMP\Temporary Internet Files\Content.IE5\0 2129920 bytes
c:\windows\TEMP\Temporary Internet Files\Content.IE5\p 3178496 bytes
c:\windows\TEMP\Temporary Internet Files\Content.IE5\8 3637248 bytes
c:\windows\TEMP\Temporary Internet Files\Content.IE5\F 3244032 bytes
c:\windows\TEMP\Temporary Internet Files\Content.IE5\c 3440640 bytes
c:\windows\TEMP\Temporary Internet Files\Content.IE5\0 4358144 bytes
c:\windows\TEMP\Temporary Internet Files\Content.IE5\U 7045120 bytes
c:\windows\TEMP\Temporary Internet Files\Content.IE5\e 884736 bytes
c:\windows\TEMP\Temporary Internet Files\Content.IE5\
c:\windows\TEMP\Temporary Internet Files\Content.IE5\z 5210112 bytes
c:\windows\TEMP\Temporary Internet Files\Content.IE5\n 5406720 bytes
c:\windows\TEMP\Temporary Internet Files\Content.IE5\s 2981888 bytes
c:\windows\TEMP\Temporary Internet Files\Content.IE5\0 2129920 bytes
c:\windows\TEMP\Temporary Internet Files\Content.IE5\p 3178496 bytes
c:\windows\TEMP\Temporary Internet Files\Content.IE5\8 3637248 bytes
c:\windows\TEMP\Temporary Internet Files\Content.IE5\F 3244032 bytes
c:\windows\TEMP\Temporary Internet Files\Content.IE5\c 3440640 bytes
c:\windows\TEMP\Temporary Internet Files\Content.IE5\0 4423680 bytes
c:\windows\TEMP\Temporary Internet Files\Content.IE5\y 3506176 bytes
c:\windows\TEMP\Temporary Internet Files\Content.IE5\E 884736 bytes
c:\windows\TEMP\Temporary Internet Files\Content.IE5\
c:\windows\TEMP\Temporary Internet Files\Content.IE5\x 3702784 bytes
c:\windows\TEMP\Temporary Internet Files\Content.IE5\6 5406720 bytes
c:\windows\TEMP\Temporary Internet Files\Content.IE5\s 2981888 bytes
c:\windows\TEMP\Temporary Internet Files\Content.IE5\0 2129920 bytes
c:\windows\TEMP\Temporary Internet Files\Content.IE5\p 3178496 bytes
c:\windows\TEMP\Temporary Internet Files\Content.IE5\8 3637248 bytes
c:\windows\TEMP\Temporary Internet Files\Content.IE5\F 3244032 bytes
c:\windows\TEMP\Temporary Internet Files\Content.IE5\c 3440640 bytes
c:\windows\TEMP\Temporary Internet Files\Content.IE5\0 4423680 bytes
c:\windows\TEMP\Temporary Internet Files\Content.IE5\r 6389760 bytes
c:\windows\TEMP\Temporary Internet Files\Content.IE5\c 884736 bytes
c:\windows\TEMP\Temporary Internet Files\Content.IE5\
c:\windows\TEMP\Temporary Internet Files\Content.IE5\O 4947968 bytes
c:\windows\TEMP\Temporary Internet Files\Content.IE5\s 2981888 bytes
c:\windows\TEMP\Temporary Internet Files\Content.IE5\0 2129920 bytes
c:\windows\TEMP\Temporary Internet Files\Content.IE5\p 3178496 bytes
c:\windows\TEMP\Temporary Internet Files\Content.IE5\8 3637248 bytes
c:\windows\TEMP\Temporary Internet Files\Content.IE5\F 3244032 bytes
c:\windows\TEMP\Temporary Internet Files\Content.IE5\c 3440640 bytes
c:\windows\TEMP\Temporary Internet Files\Content.IE5\0 4423680 bytes
c:\windows\TEMP\Temporary Internet Files\Content.IE5\r 6389760 bytes
c:\windows\TEMP\Temporary Internet Files\Content.IE5\c 884736 bytes
c:\windows\TEMP\Temporary Internet Files\Content.IE5\
c:\windows\TEMP\Temporary Internet Files\Content.IE5\y 7110656 bytes
c:\windows\TEMP\Temporary Internet Files\Content.IE5\6 5406720 bytes
c:\windows\TEMP\Temporary Internet Files\Content.IE5\s 2981888 bytes
c:\windows\TEMP\Temporary Internet Files\Content.IE5\0 2129920 bytes
c:\windows\TEMP\Temporary Internet Files\Content.IE5\p 3178496 bytes
c:\windows\TEMP\Temporary Internet Files\Content.IE5\8 3637248 bytes
c:\windows\TEMP\Temporary Internet Files\Content.IE5\F 3244032 bytes
c:\windows\TEMP\Temporary Internet Files\Content.IE5\c 3440640 bytes
c:\windows\TEMP\Temporary Internet Files\Content.IE5\0 4292608 bytes
c:\windows\TEMP\Temporary Internet Files\Content.IE5\q 4358144 bytes
c:\windows\TEMP\Temporary Internet Files\Content.IE5\i 884736 bytes
c:\windows\TEMP\Temporary Internet Files\Content.IE5\
c:\windows\TEMP\Temporary Internet Files\Content.IE5\M 7307264 bytes
c:\windows\TEMP\Temporary Internet Files\Content.IE5\b 5406720 bytes
c:\windows\TEMP\Temporary Internet Files\Content.IE5\s 2981888 bytes
c:\windows\TEMP\Temporary Internet Files\Content.IE5\0 2129920 bytes
c:\windows\TEMP\Temporary Internet Files\Content.IE5\p 3178496 bytes
c:\windows\TEMP\Temporary Internet Files\Content.IE5\8 3637248 bytes
c:\windows\TEMP\Temporary Internet Files\Content.IE5\F 3244032 bytes
c:\windows\TEMP\Temporary Internet Files\Content.IE5\c 3440640 bytes
c:\windows\TEMP\Temporary Internet Files\Content.IE5\0 4489216 bytes
c:\windows\TEMP\Temporary Internet Files\Content.IE5\/ 6717440 bytes
c:\windows\TEMP\Temporary Internet Files\Content.IE5\6 884736 bytes
c:\windows\TEMP\Temporary Internet Files\Content.IE5\
c:\windows\TEMP\Temporary Internet Files\Content.IE5\Y 7372800 bytes
c:\windows\TEMP\Temporary Internet Files\Content.IE5\k 5406720 bytes
c:\windows\TEMP\Temporary Internet Files\Content.IE5\s 2981888 bytes
c:\windows\TEMP\Temporary Internet Files\Content.IE5\0 2129920 bytes
c:\windows\TEMP\Temporary Internet Files\Content.IE5\p 3178496 bytes
c:\windows\TEMP\Temporary Internet Files\Content.IE5\8 3637248 bytes
c:\windows\TEMP\Temporary Internet Files\Content.IE5\F 3244032 bytes
c:\windows\TEMP\Temporary Internet Files\Content.IE5\c 3440640 bytes
c:\windows\TEMP\Temporary Internet Files\Content.IE5\0 4489216 bytes
c:\windows\TEMP\Temporary Internet Files\Content.IE5\k 2850816 bytes
c:\windows\TEMP\Temporary Internet Files\Content.IE5\c 884736 bytes
c:\windows\TEMP\Temporary Internet Files\Content.IE5\
c:\windows\TEMP\Temporary Internet Files\Content.IE5\y 7110656 bytes
c:\windows\TEMP\Temporary Internet Files\Content.IE5\6 5406720 bytes
c:\windows\TEMP\Temporary Internet Files\Content.IE5\s 2981888 bytes
c:\windows\TEMP\Temporary Internet Files\Content.IE5\0 2129920 bytes
c:\windows\TEMP\Temporary Internet Files\Content.IE5\p 3178496 bytes
c:\windows\TEMP\Temporary Internet Files\Content.IE5\8 3637248 bytes
c:\windows\TEMP\Temporary Internet Files\Content.IE5\F 3244032 bytes
c:\windows\TEMP\Temporary Internet Files\Content.IE5\c 3440640 bytes
c:\windows\TEMP\Temporary Internet Files\Content.IE5\0 4423680 bytes
c:\windows\TEMP\Temporary Internet Files\Content.IE5\I 6979584 bytes
c:\windows\TEMP\Temporary Internet Files\Content.IE5\w 884736 bytes
c:\windows\TEMP\Temporary Internet Files\Content.IE5\
c:\windows\TEMP\Temporary Internet Files\Content.IE5\e 5472256 bytes
c:\windows\TEMP\Temporary Internet Files\Content.IE5\I 5406720 bytes
c:\windows\TEMP\Temporary Internet Files\Content.IE5\s 2981888 bytes
c:\windows\TEMP\Temporary Internet Files\Content.IE5\0 2129920 bytes
c:\windows\TEMP\Temporary Internet Files\Content.IE5\p 3178496 bytes
c:\windows\TEMP\Temporary Internet Files\Content.IE5\8 3637248 bytes
c:\windows\TEMP\Temporary Internet Files\Content.IE5\F 3244032 bytes
c:\windows\TEMP\Temporary Internet Files\Content.IE5\c 3440640 bytes
c:\windows\TEMP\Temporary Internet Files\Content.IE5\0 4292608 bytes
c:\windows\TEMP\Temporary Internet Files\Content.IE5\q 4358144 bytes
c:\windows\TEMP\Temporary Internet Files\Content.IE5\i 884736 bytes
c:\windows\TEMP\Temporary Internet Files\Content.IE5\
c:\windows\TEMP\Temporary Internet Files\Content.IE5\M 7307264 bytes
c:\windows\TEMP\Temporary Internet Files\Content.IE5\b 5406720 bytes
c:\windows\TEMP\Temporary Internet Files\Content.IE5\s 2981888 bytes
c:\windows\TEMP\Temporary Internet Files\Content.IE5\0 2129920 bytes
c:\windows\TEMP\Temporary Internet Files\Content.IE5\p 3178496 bytes
c:\windows\TEMP\Temporary Internet Files\Content.IE5\8 3637248 bytes
c:\windows\TEMP\Temporary Internet Files\Content.IE5\F 3244032 bytes
c:\windows\TEMP\Temporary Internet Files\Content.IE5\c 3440640 bytes
c:\windows\TEMP\Temporary Internet Files\Content.IE5\0 4358144 bytes
c:\windows\TEMP\Temporary Internet Files\Content.IE5\w 4423680 bytes
c:\windows\TEMP\Temporary Internet Files\Content.IE5\l 884736 bytes
c:\windows\TEMP\Temporary Internet Files\Content.IE5\
c:\windows\TEMP\Temporary Internet Files\Content.IE5\n 5603328 bytes
c:\windows\TEMP\Temporary Internet Files\Content.IE5\s 2981888 bytes
c:\windows\TEMP\Temporary Internet Files\Content.IE5\0 2129920 bytes
c:\windows\TEMP\Temporary Internet Files\Content.IE5\p 3178496 bytes
c:\windows\TEMP\Temporary Internet Files\Content.IE5\8 3637248 bytes
c:\windows\TEMP\Temporary Internet Files\Content.IE5\F 3244032 bytes
c:\windows\TEMP\Temporary Internet Files\Content.IE5\c 3440640 bytes
c:\windows\TEMP\Temporary Internet Files\Content.IE5\0 4358144 bytes
c:\windows\TEMP\Temporary Internet Files\Content.IE5\t 5406720 bytes
c:\windows\TEMP\Temporary Internet Files\Content.IE5\i 884736 bytes
c:\windows\TEMP\Temporary Internet Files\Content.IE5\
c:\windows\TEMP\Temporary Internet Files\Content.IE5\e 5406720 bytes
c:\windows\TEMP\Temporary Internet Files\Content.IE5\s 2981888 bytes
c:\windows\TEMP\Temporary Internet Files\Content.IE5\0 2129920 bytes
c:\windows\TEMP\Temporary Internet Files\Content.IE5\p 3178496 bytes
c:\windows\TEMP\Temporary Internet Files\Content.IE5\8 3637248 bytes
c:\windows\TEMP\Temporary Internet Files\Content.IE5\F 3244032 bytes
c:\windows\TEMP\Temporary Internet Files\Content.IE5\c 3440640 bytes
c:\windows\TEMP\Temporary Internet Files\Content.IE5\0 4358144 bytes
c:\windows\TEMP\Temporary Internet Files\Content.IE5\U 7045120 bytes
c:\windows\TEMP\Temporary Internet Files\Content.IE5\e 884736 bytes
c:\windows\TEMP\Temporary Internet Files\Content.IE5\
c:\windows\TEMP\Temporary Internet Files\Content.IE5\e 5472256 bytes
c:\windows\TEMP\Temporary Internet Files\Content.IE5\I 5406720 bytes
c:\windows\TEMP\Temporary Internet Files\Content.IE5\s 2981888 bytes
c:\windows\TEMP\Temporary Internet Files\Content.IE5\0 2129920 bytes
c:\windows\TEMP\Temporary Internet Files\Content.IE5\p 3178496 bytes
c:\windows\TEMP\Temporary Internet Files\Content.IE5\8 3637248 bytes
c:\windows\TEMP\Temporary Internet Files\Content.IE5\F 3244032 bytes
c:\windows\TEMP\Temporary Internet Files\Content.IE5\c 3440640 bytes
c:\windows\TEMP\Temporary Internet Files\Content.IE5\0 4489216 bytes
c:\windows\TEMP\Temporary Internet Files\Content.IE5\k 2850816 bytes
c:\windows\TEMP\Temporary Internet Files\Content.IE5\c 884736 bytes
c:\windows\TEMP\Temporary Internet Files\Content.IE5\
c:\windows\TEMP\Temporary Internet Files\Content.IE5\M 7307264 bytes
c:\windows\TEMP\Temporary Internet Files\Content.IE5\b 5406720 bytes
c:\windows\TEMP\Temporary Internet Files\Content.IE5\s 2981888 bytes
c:\windows\TEMP\Temporary Internet Files\Content.IE5\0 2129920 bytes
c:\windows\TEMP\Temporary Internet Files\Content.IE5\p 3178496 bytes
c:\windows\TEMP\Temporary Internet Files\Content.IE5\8 3637248 bytes
c:\windows\TEMP\Temporary Internet Files\Content.IE5\F 3244032 bytes
c:\windows\TEMP\Temporary Internet Files\Content.IE5\c 3440640 bytes
c:\windows\TEMP\Temporary Internet Files\Content.IE5\0 4423680 bytes
c:\windows\TEMP\Temporary Internet Files\Content.IE5\I 6979584 bytes
c:\windows\TEMP\Temporary Internet Files\Content.IE5\w 884736 bytes
c:\windows\TEMP\Temporary Internet Files\Content.IE5\
c:\windows\TEMP\Temporary Internet Files\Content.IE5\e 5472256 bytes
c:\windows\TEMP\Temporary Internet Files\Content.IE5\I 5406720 bytes
c:\windows\TEMP\Temporary Internet Files\Content.IE5\s 2981888 bytes
c:\windows\TEMP\Temporary Internet Files\Content.IE5\0 2129920 bytes
c:\windows\TEMP\Temporary Internet Files\Content.IE5\p 3178496 bytes
c:\windows\TEMP\Temporary Internet Files\Content.IE5\8 3637248 bytes
c:\windows\TEMP\Temporary Internet Files\Content.IE5\F 3244032 bytes
c:\windows\TEMP\Temporary Internet Files\Content.IE5\c 3440640 bytes
c:\windows\TEMP\Temporary Internet Files\Content.IE5\0 4489216 bytes
c:\windows\TEMP\Temporary Internet Files\Content.IE5\Z 6651904 bytes
c:\windows\TEMP\Temporary Internet Files\Content.IE5\n 884736 bytes
c:\windows\TEMP\Temporary Internet Files\Content.IE5\
c:\windows\TEMP\Temporary Internet Files\Content.IE5\z 7700480 bytes
c:\windows\TEMP\Temporary Internet Files\Content.IE5\l 5406720 bytes
c:\windows\TEMP\Temporary Internet Files\Content.IE5\s 2981888 bytes
c:\windows\TEMP\Temporary Internet Files\Content.IE5\0 2129920 bytes
c:\windows\TEMP\Temporary Internet Files\Content.IE5\p 3178496 bytes
c:\windows\TEMP\Temporary Internet Files\Content.IE5\8 3637248 bytes
c:\windows\TEMP\Temporary Internet Files\Content.IE5\F 3244032 bytes
c:\windows\TEMP\Temporary Internet Files\Content.IE5\c 3440640 bytes
c:\windows\TEMP\Temporary Internet Files\Content.IE5\0 4358144 bytes
c:\windows\TEMP\Temporary Internet Files\Content.IE5\w 4423680 bytes
c:\windows\TEMP\Temporary Internet Files\Content.IE5\l 884736 bytes
c:\windows\TEMP\Temporary Internet Files\Content.IE5\
c:\windows\TEMP\Temporary Internet Files\Content.IE5\s 2981888 bytes
c:\windows\TEMP\Temporary Internet Files\Content.IE5\0 2129920 bytes
c:\windows\TEMP\Temporary Internet Files\Content.IE5\p 3178496 bytes
c:\windows\TEMP\Temporary Internet Files\Content.IE5\8 3637248 bytes
c:\windows\TEMP\Temporary Internet Files\Content.IE5\F 3244032 bytes
c:\windows\TEMP\Temporary Internet Files\Content.IE5\c 3440640 bytes
c:\windows\TEMP\Temporary Internet Files\Content.IE5\0 4358144 bytes
c:\windows\TEMP\Temporary Internet Files\Content.IE5\O 4358144 bytes
c:\windows\TEMP\Temporary Internet Files\Content.IE5\X 884736 bytes
c:\windows\TEMP\Temporary Internet Files\Content.IE5\
c:\windows\TEMP\Temporary Internet Files\Content.IE5\z 5210112 bytes
c:\windows\TEMP\Temporary Internet Files\Content.IE5\n 5406720 bytes
c:\windows\TEMP\Temporary Internet Files\Content.IE5\s 2981888 bytes
c:\windows\TEMP\Temporary Internet Files\Content.IE5\0 2129920 bytes
c:\windows\TEMP\Temporary Internet Files\Content.IE5\p 3178496 bytes
c:\windows\TEMP\Temporary Internet Files\Content.IE5\8 3637248 bytes
c:\windows\TEMP\Temporary Internet Files\Content.IE5\F 3244032 bytes
c:\windows\TEMP\Temporary Internet Files\Content.IE5\c 3440640 bytes
c:\windows\TEMP\Temporary Internet Files\Content.IE5\0 4489216 bytes
c:\windows\TEMP\Temporary Internet Files\Content.IE5\Z 6651904 bytes
c:\windows\TEMP\Temporary Internet Files\Content.IE5\n 884736 bytes
c:\windows\TEMP\Temporary Internet Files\Content.IE5\
c:\windows\TEMP\Temporary Internet Files\Content.IE5\M 7307264 bytes
c:\windows\TEMP\Temporary Internet Files\Content.IE5\b 5406720 bytes
c:\windows\TEMP\Temporary Internet Files\Content.IE5\s 2981888 bytes
c:\windows\TEMP\Temporary Internet Files\Content.IE5\0 2129920 bytes
c:\windows\TEMP\Temporary Internet Files\Content.IE5\p 3178496 bytes
c:\windows\TEMP\Temporary Internet Files\Content.IE5\8 3637248 bytes
c:\windows\TEMP\Temporary Internet Files\Content.IE5\F 3244032 bytes
c:\windows\TEMP\Temporary Internet Files\Content.IE5\c 3440640 bytes
c:\windows\TEMP\Temporary Internet Files\Content.IE5\0 4292608 bytes
c:\windows\TEMP\Temporary Internet Files\Content.IE5\q 4358144 bytes
c:\windows\TEMP\Temporary Internet Files\Content.IE5\i 884736 bytes
c:\windows\TEMP\Temporary Internet Files\Content.IE5\
c:\windows\TEMP\Temporary Internet Files\Content.IE5\M 7307264 bytes
c:\windows\TEMP\Temporary Internet Files\Content.IE5\b 5406720 bytes
c:\windows\TEMP\Temporary Internet Files\Content.IE5\s 2981888 bytes
c:\windows\TEMP\Temporary Internet Files\Content.IE5\0 2129920 bytes
c:\windows\TEMP\Temporary Internet Files\Content.IE5\p 3178496 bytes
c:\windows\TEMP\Temporary Internet Files\Content.IE5\8 3637248 bytes
c:\windows\TEMP\Temporary Internet Files\Content.IE5\F 3244032 bytes
c:\windows\TEMP\Temporary Internet Files\Content.IE5\c 3440640 bytes
c:\windows\TEMP\Temporary Internet Files\Content.IE5\0 4489216 bytes
c:\windows\TEMP\Temporary Internet Files\Content.IE5\M 5931008 bytes
c:\windows\TEMP\Temporary Internet Files\Content.IE5\e 884736 bytes
 
c:\windows\TEMP\Temporary Internet Files\Content.IE5\
c:\windows\TEMP\Temporary Internet Files\Content.IE5\z 7700480 bytes
c:\windows\TEMP\Temporary Internet Files\Content.IE5\l 5406720 bytes
c:\windows\TEMP\Temporary Internet Files\Content.IE5\s 2981888 bytes
c:\windows\TEMP\Temporary Internet Files\Content.IE5\0 2129920 bytes
c:\windows\TEMP\Temporary Internet Files\Content.IE5\p 3178496 bytes
c:\windows\TEMP\Temporary Internet Files\Content.IE5\8 3637248 bytes
c:\windows\TEMP\Temporary Internet Files\Content.IE5\F 3244032 bytes
c:\windows\TEMP\Temporary Internet Files\Content.IE5\c 3440640 bytes
c:\windows\TEMP\Temporary Internet Files\Content.IE5\0 4358144 bytes
c:\windows\TEMP\Temporary Internet Files\Content.IE5\U 7045120 bytes
c:\windows\TEMP\Temporary Internet Files\Content.IE5\e 884736 bytes
c:\windows\TEMP\Temporary Internet Files\Content.IE5\
c:\windows\TEMP\Temporary Internet Files\Content.IE5\x 3702784 bytes
c:\windows\TEMP\Temporary Internet Files\Content.IE5\6 5406720 bytes
c:\windows\TEMP\Temporary Internet Files\Content.IE5\s 2981888 bytes
c:\windows\TEMP\Temporary Internet Files\Content.IE5\0 2129920 bytes
c:\windows\TEMP\Temporary Internet Files\Content.IE5\p 3178496 bytes
c:\windows\TEMP\Temporary Internet Files\Content.IE5\8 3637248 bytes
c:\windows\TEMP\Temporary Internet Files\Content.IE5\F 3244032 bytes
c:\windows\TEMP\Temporary Internet Files\Content.IE5\c 3440640 bytes
c:\windows\TEMP\Temporary Internet Files\Content.IE5\0 4292608 bytes
c:\windows\TEMP\Temporary Internet Files\Content.IE5\8 3637248 bytes
c:\windows\TEMP\Temporary Internet Files\Content.IE5\T 884736 bytes
c:\windows\TEMP\Temporary Internet Files\Content.IE5\
c:\windows\TEMP\Temporary Internet Files\Content.IE5\z 5210112 bytes
c:\windows\TEMP\Temporary Internet Files\Content.IE5\n 5406720 bytes
c:\windows\TEMP\Temporary Internet Files\Content.IE5\s 2981888 bytes
c:\windows\TEMP\Temporary Internet Files\Content.IE5\0 2129920 bytes
c:\windows\TEMP\Temporary Internet Files\Content.IE5\p 3178496 bytes
c:\windows\TEMP\Temporary Internet Files\Content.IE5\8 3637248 bytes
c:\windows\TEMP\Temporary Internet Files\Content.IE5\F 3244032 bytes
c:\windows\TEMP\Temporary Internet Files\Content.IE5\c 3440640 bytes
c:\windows\TEMP\Temporary Internet Files\Content.IE5\0 4358144 bytes
c:\windows\TEMP\Temporary Internet Files\Content.IE5\t 5406720 bytes
c:\windows\TEMP\Temporary Internet Files\Content.IE5\i 884736 bytes
c:\windows\TEMP\Temporary Internet Files\Content.IE5\
c:\windows\TEMP\Temporary Internet Files\Content.IE5\P 4358144 bytes
c:\windows\TEMP\Temporary Internet Files\Content.IE5\m 5406720 bytes
c:\windows\TEMP\Temporary Internet Files\Content.IE5\s 2981888 bytes
c:\windows\TEMP\Temporary Internet Files\Content.IE5\0 2129920 bytes
c:\windows\TEMP\Temporary Internet Files\Content.IE5\p 3178496 bytes
c:\windows\TEMP\Temporary Internet Files\Content.IE5\8 3637248 bytes
c:\windows\TEMP\Temporary Internet Files\Content.IE5\F 3244032 bytes
c:\windows\TEMP\Temporary Internet Files\Content.IE5\c 3440640 bytes
c:\windows\TEMP\Temporary Internet Files\Content.IE5\0 4292608 bytes
c:\windows\TEMP\Temporary Internet Files\Content.IE5\u 7045120 bytes
c:\windows\TEMP\Temporary Internet Files\Content.IE5\i 884736 bytes
c:\windows\TEMP\Temporary Internet Files\Content.IE5\
c:\windows\TEMP\Temporary Internet Files\Content.IE5\e 5406720 bytes
c:\windows\TEMP\Temporary Internet Files\Content.IE5\s 2981888 bytes
c:\windows\TEMP\Temporary Internet Files\Content.IE5\0 2129920 bytes
c:\windows\TEMP\Temporary Internet Files\Content.IE5\p 3178496 bytes
c:\windows\TEMP\Temporary Internet Files\Content.IE5\8 3637248 bytes
c:\windows\TEMP\Temporary Internet Files\Content.IE5\F 3244032 bytes
c:\windows\TEMP\Temporary Internet Files\Content.IE5\c 3440640 bytes
c:\windows\TEMP\Temporary Internet Files\Content.IE5\0 4358144 bytes
c:\windows\TEMP\Temporary Internet Files\Content.IE5\t 5406720 bytes
c:\windows\TEMP\Temporary Internet Files\Content.IE5\i 884736 bytes
c:\windows\TEMP\Temporary Internet Files\Content.IE5\
c:\windows\TEMP\Temporary Internet Files\Content.IE5\y 7110656 bytes
c:\windows\TEMP\Temporary Internet Files\Content.IE5\6 5406720 bytes
c:\windows\TEMP\Temporary Internet Files\Content.IE5\s 2981888 bytes
c:\windows\TEMP\Temporary Internet Files\Content.IE5\0 2129920 bytes
c:\windows\TEMP\Temporary Internet Files\Content.IE5\p 3178496 bytes
c:\windows\TEMP\Temporary Internet Files\Content.IE5\8 3637248 bytes
c:\windows\TEMP\Temporary Internet Files\Content.IE5\F 3244032 bytes
c:\windows\TEMP\Temporary Internet Files\Content.IE5\c 3440640 bytes
c:\windows\TEMP\Temporary Internet Files\Content.IE5\0 4489216 bytes
c:\windows\TEMP\Temporary Internet Files\Content.IE5\Z 6651904 bytes
c:\windows\TEMP\Temporary Internet Files\Content.IE5\n 884736 bytes
c:\windows\TEMP\Temporary Internet Files\Content.IE5\
c:\windows\TEMP\Temporary Internet Files\Content.IE5\z 5210112 bytes
c:\windows\TEMP\Temporary Internet Files\Content.IE5\n 5406720 bytes
c:\windows\TEMP\Temporary Internet Files\Content.IE5\s 2981888 bytes
c:\windows\TEMP\Temporary Internet Files\Content.IE5\0 2129920 bytes
c:\windows\TEMP\Temporary Internet Files\Content.IE5\p 3178496 bytes
c:\windows\TEMP\Temporary Internet Files\Content.IE5\8 3637248 bytes
c:\windows\TEMP\Temporary Internet Files\Content.IE5\F 3244032 bytes
c:\windows\TEMP\Temporary Internet Files\Content.IE5\c 3440640 bytes
c:\windows\TEMP\Temporary Internet Files\Content.IE5\0 4358144 bytes
c:\windows\TEMP\Temporary Internet Files\Content.IE5\O 4358144 bytes
c:\windows\TEMP\Temporary Internet Files\Content.IE5\X 884736 bytes
c:\windows\TEMP\Temporary Internet Files\Content.IE5\
c:\windows\TEMP\Temporary Internet Files\Content.IE5\Y 7372800 bytes
c:\windows\TEMP\Temporary Internet Files\Content.IE5\k 5406720 bytes
c:\windows\TEMP\Temporary Internet Files\Content.IE5\s 2981888 bytes
c:\windows\TEMP\Temporary Internet Files\Content.IE5\0 2129920 bytes
c:\windows\TEMP\Temporary Internet Files\Content.IE5\p 3178496 bytes
c:\windows\TEMP\Temporary Internet Files\Content.IE5\8 3637248 bytes
c:\windows\TEMP\Temporary Internet Files\Content.IE5\F 3244032 bytes
c:\windows\TEMP\Temporary Internet Files\Content.IE5\c 3440640 bytes
c:\windows\TEMP\Temporary Internet Files\Content.IE5\0 4292608 bytes
c:\windows\TEMP\Temporary Internet Files\Content.IE5\L 3768320 bytes
c:\windows\TEMP\Temporary Internet Files\Content.IE5\0 884736 bytes
c:\windows\TEMP\Temporary Internet Files\Content.IE5\
c:\windows\TEMP\Temporary Internet Files\Content.IE5\Y 7372800 bytes
c:\windows\TEMP\Temporary Internet Files\Content.IE5\k 5406720 bytes
c:\windows\TEMP\Temporary Internet Files\Content.IE5\s 2981888 bytes
c:\windows\TEMP\Temporary Internet Files\Content.IE5\0 2129920 bytes
c:\windows\TEMP\Temporary Internet Files\Content.IE5\p 3178496 bytes
c:\windows\TEMP\Temporary Internet Files\Content.IE5\8 3637248 bytes
c:\windows\TEMP\Temporary Internet Files\Content.IE5\F 3244032 bytes
c:\windows\TEMP\Temporary Internet Files\Content.IE5\c 3440640 bytes
c:\windows\TEMP\Temporary Internet Files\Content.IE5\0 4292608 bytes
c:\windows\TEMP\Temporary Internet Files\Content.IE5\q 4358144 bytes
c:\windows\TEMP\Temporary Internet Files\Content.IE5\i 884736 bytes
c:\windows\TEMP\Temporary Internet Files\Content.IE5\
c:\windows\TEMP\Temporary Internet Files\Content.IE5\e 5406720 bytes
c:\windows\TEMP\Temporary Internet Files\Content.IE5\s 2981888 bytes
c:\windows\TEMP\Temporary Internet Files\Content.IE5\0 2129920 bytes
c:\windows\TEMP\Temporary Internet Files\Content.IE5\p 3178496 bytes
c:\windows\TEMP\Temporary Internet Files\Content.IE5\8 3637248 bytes
c:\windows\TEMP\Temporary Internet Files\Content.IE5\F 3244032 bytes
c:\windows\TEMP\Temporary Internet Files\Content.IE5\c 3440640 bytes
c:\windows\TEMP\Temporary Internet Files\Content.IE5\0 4292608 bytes
c:\windows\TEMP\Temporary Internet Files\Content.IE5\u 7045120 bytes
c:\windows\TEMP\Temporary Internet Files\Content.IE5\i 884736 bytes
c:\windows\TEMP\Temporary Internet Files\Content.IE5\
c:\windows\TEMP\Temporary Internet Files\Content.IE5\4 3768320 bytes
c:\windows\TEMP\Temporary Internet Files\Content.IE5\N 5406720 bytes
c:\windows\TEMP\Temporary Internet Files\Content.IE5\s 2981888 bytes
c:\windows\TEMP\Temporary Internet Files\Content.IE5\0 2129920 bytes
c:\windows\TEMP\Temporary Internet Files\Content.IE5\p 3178496 bytes
c:\windows\TEMP\Temporary Internet Files\Content.IE5\8 3637248 bytes
c:\windows\TEMP\Temporary Internet Files\Content.IE5\F 3244032 bytes
c:\windows\TEMP\Temporary Internet Files\Content.IE5\c 3440640 bytes
c:\windows\TEMP\Temporary Internet Files\Content.IE5\0 4358144 bytes
c:\windows\TEMP\Temporary Internet Files\Content.IE5\O 4358144 bytes
c:\windows\TEMP\Temporary Internet Files\Content.IE5\X 884736 bytes
c:\windows\TEMP\Temporary Internet Files\Content.IE5\
c:\windows\TEMP\Temporary Internet Files\Content.IE5\O 4947968 bytes
c:\windows\TEMP\Temporary Internet Files\Content.IE5\s 2981888 bytes
c:\windows\TEMP\Temporary Internet Files\Content.IE5\0 2129920 bytes
c:\windows\TEMP\Temporary Internet Files\Content.IE5\p 3178496 bytes
c:\windows\TEMP\Temporary Internet Files\Content.IE5\8 3637248 bytes
c:\windows\TEMP\Temporary Internet Files\Content.IE5\F 3244032 bytes
c:\windows\TEMP\Temporary Internet Files\Content.IE5\c 3440640 bytes
c:\windows\TEMP\Temporary Internet Files\Content.IE5\0 4489216 bytes
c:\windows\TEMP\Temporary Internet Files\Content.IE5\M 5931008 bytes
c:\windows\TEMP\Temporary Internet Files\Content.IE5\e 884736 bytes
c:\windows\TEMP\Temporary Internet Files\Content.IE5\
c:\windows\TEMP\Temporary Internet Files\Content.IE5\n 5603328 bytes
c:\windows\TEMP\Temporary Internet Files\Content.IE5\s 2981888 bytes
c:\windows\TEMP\Temporary Internet Files\Content.IE5\0 2129920 bytes
c:\windows\TEMP\Temporary Internet Files\Content.IE5\p 3178496 bytes
c:\windows\TEMP\Temporary Internet Files\Content.IE5\8 3637248 bytes
c:\windows\TEMP\Temporary Internet Files\Content.IE5\F 3244032 bytes
c:\windows\TEMP\Temporary Internet Files\Content.IE5\c 3440640 bytes
c:\windows\TEMP\Temporary Internet Files\Content.IE5\0 4292608 bytes
c:\windows\TEMP\Temporary Internet Files\Content.IE5\q 4358144 bytes
c:\windows\TEMP\Temporary Internet Files\Content.IE5\i 884736 bytes
c:\windows\TEMP\Temporary Internet Files\Content.IE5\
c:\windows\TEMP\Temporary Internet Files\Content.IE5\Y 7372800 bytes
c:\windows\TEMP\Temporary Internet Files\Content.IE5\k 5406720 bytes
c:\windows\TEMP\Temporary Internet Files\Content.IE5\s 2981888 bytes
c:\windows\TEMP\Temporary Internet Files\Content.IE5\0 2129920 bytes
c:\windows\TEMP\Temporary Internet Files\Content.IE5\p 3178496 bytes
c:\windows\TEMP\Temporary Internet Files\Content.IE5\8 3637248 bytes
c:\windows\TEMP\Temporary Internet Files\Content.IE5\F 3244032 bytes
c:\windows\TEMP\Temporary Internet Files\Content.IE5\c 3440640 bytes
c:\windows\TEMP\Temporary Internet Files\Content.IE5\0 4423680 bytes
c:\windows\TEMP\Temporary Internet Files\Content.IE5\y 3506176 bytes
c:\windows\TEMP\Temporary Internet Files\Content.IE5\E 884736 bytes
c:\windows\TEMP\Temporary Internet Files\Content.IE5\
c:\windows\TEMP\Temporary Internet Files\Content.IE5\x 7766016 bytes
c:\windows\TEMP\Temporary Internet Files\Content.IE5\s 2981888 bytes
c:\windows\TEMP\Temporary Internet Files\Content.IE5\0 2129920 bytes
c:\windows\TEMP\Temporary Internet Files\Content.IE5\p 3178496 bytes
c:\windows\TEMP\Temporary Internet Files\Content.IE5\8 3637248 bytes
c:\windows\TEMP\Temporary Internet Files\Content.IE5\F 3244032 bytes
c:\windows\TEMP\Temporary Internet Files\Content.IE5\c 3440640 bytes
c:\windows\TEMP\Temporary Internet Files\Content.IE5\0 4358144 bytes
c:\windows\TEMP\Temporary Internet Files\Content.IE5\w 4423680 bytes
c:\windows\TEMP\Temporary Internet Files\Content.IE5\l 884736 bytes
c:\windows\TEMP\Temporary Internet Files\Content.IE5\
c:\windows\TEMP\Temporary Internet Files\Content.IE5\Y 7372800 bytes
c:\windows\TEMP\Temporary Internet Files\Content.IE5\k 5406720 bytes
c:\windows\TEMP\Temporary Internet Files\Content.IE5\s 2981888 bytes
c:\windows\TEMP\Temporary Internet Files\Content.IE5\0 2129920 bytes
c:\windows\TEMP\Temporary Internet Files\Content.IE5\p 3178496 bytes
c:\windows\TEMP\Temporary Internet Files\Content.IE5\8 3637248 bytes
c:\windows\TEMP\Temporary Internet Files\Content.IE5\F 3244032 bytes
c:\windows\TEMP\Temporary Internet Files\Content.IE5\c 3440640 bytes
c:\windows\TEMP\Temporary Internet Files\Content.IE5\0 4292608 bytes
c:\windows\TEMP\Temporary Internet Files\Content.IE5\8 3637248 bytes
c:\windows\TEMP\Temporary Internet Files\Content.IE5\T 884736 bytes
c:\windows\TEMP\Temporary Internet Files\Content.IE5\
c:\windows\TEMP\Temporary Internet Files\Content.IE5\P 4358144 bytes
c:\windows\TEMP\Temporary Internet Files\Content.IE5\m 5406720 bytes
c:\windows\TEMP\Temporary Internet Files\Content.IE5\s 2981888 bytes
c:\windows\TEMP\Temporary Internet Files\Content.IE5\0 2129920 bytes
c:\windows\TEMP\Temporary Internet Files\Content.IE5\p 3178496 bytes
c:\windows\TEMP\Temporary Internet Files\Content.IE5\8 3637248 bytes
c:\windows\TEMP\Temporary Internet Files\Content.IE5\F 3244032 bytes
c:\windows\TEMP\Temporary Internet Files\Content.IE5\c 3440640 bytes
c:\windows\TEMP\Temporary Internet Files\Content.IE5\0 4423680 bytes
c:\windows\TEMP\Temporary Internet Files\Content.IE5\y 5144576 bytes
c:\windows\TEMP\Temporary Internet Files\Content.IE5\B 884736 bytes
c:\windows\TEMP\Temporary Internet Files\Content.IE5\
c:\windows\TEMP\Temporary Internet Files\Content.IE5\M 7307264 bytes
c:\windows\TEMP\Temporary Internet Files\Content.IE5\b 5406720 bytes
c:\windows\TEMP\Temporary Internet Files\Content.IE5\s 2981888 bytes
c:\windows\TEMP\Temporary Internet Files\Content.IE5\0 2129920 bytes
c:\windows\TEMP\Temporary Internet Files\Content.IE5\p 3178496 bytes
c:\windows\TEMP\Temporary Internet Files\Content.IE5\8 3637248 bytes
c:\windows\TEMP\Temporary Internet Files\Content.IE5\F 3244032 bytes
c:\windows\TEMP\Temporary Internet Files\Content.IE5\c 3440640 bytes
c:\windows\TEMP\Temporary Internet Files\Content.IE5\0 4358144 bytes
c:\windows\TEMP\Temporary Internet Files\Content.IE5\t 5406720 bytes
c:\windows\TEMP\Temporary Internet Files\Content.IE5\i 884736 bytes
c:\windows\TEMP\Temporary Internet Files\Content.IE5\
c:\windows\TEMP\Temporary Internet Files\Content.IE5\4 3768320 bytes
c:\windows\TEMP\Temporary Internet Files\Content.IE5\N 5406720 bytes
c:\windows\TEMP\Temporary Internet Files\Content.IE5\s 2981888 bytes
c:\windows\TEMP\Temporary Internet Files\Content.IE5\0 2129920 bytes
c:\windows\TEMP\Temporary Internet Files\Content.IE5\p 3178496 bytes
c:\windows\TEMP\Temporary Internet Files\Content.IE5\8 3637248 bytes
c:\windows\TEMP\Temporary Internet Files\Content.IE5\F 3244032 bytes
c:\windows\TEMP\Temporary Internet Files\Content.IE5\c 3440640 bytes
c:\windows\TEMP\Temporary Internet Files\Content.IE5\0 4292608 bytes
c:\windows\TEMP\Temporary Internet Files\Content.IE5\L 3768320 bytes
c:\windows\TEMP\Temporary Internet Files\Content.IE5\0 884736 bytes
c:\windows\TEMP\Temporary Internet Files\Content.IE5\
c:\windows\TEMP\Temporary Internet Files\Content.IE5\4 3768320 bytes
c:\windows\TEMP\Temporary Internet Files\Content.IE5\N 5406720 bytes
c:\windows\TEMP\Temporary Internet Files\Content.IE5\s 2981888 bytes
c:\windows\TEMP\Temporary Internet Files\Content.IE5\0 2129920 bytes
c:\windows\TEMP\Temporary Internet Files\Content.IE5\p 3178496 bytes
c:\windows\TEMP\Temporary Internet Files\Content.IE5\8 3637248 bytes
c:\windows\TEMP\Temporary Internet Files\Content.IE5\F 3244032 bytes
c:\windows\TEMP\Temporary Internet Files\Content.IE5\c 3440640 bytes
c:\windows\TEMP\Temporary Internet Files\Content.IE5\0 4358144 bytes
c:\windows\TEMP\Temporary Internet Files\Content.IE5\U 7045120 bytes
c:\windows\TEMP\Temporary Internet Files\Content.IE5\e 884736 bytes
c:\windows\TEMP\Temporary Internet Files\Content.IE5\
c:\windows\TEMP\Temporary Internet Files\Content.IE5\W 3637248 bytes
c:\windows\TEMP\Temporary Internet Files\Content.IE5\n 5406720 bytes
c:\windows\TEMP\Temporary Internet Files\Content.IE5\s 2981888 bytes
c:\windows\TEMP\Temporary Internet Files\Content.IE5\0 2129920 bytes
c:\windows\TEMP\Temporary Internet Files\Content.IE5\p 3178496 bytes
c:\windows\TEMP\Temporary Internet Files\Content.IE5\8 3637248 bytes
c:\windows\TEMP\Temporary Internet Files\Content.IE5\F 3244032 bytes
c:\windows\TEMP\Temporary Internet Files\Content.IE5\c 3440640 bytes
c:\windows\TEMP\Temporary Internet Files\Content.IE5\0 4489216 bytes
c:\windows\TEMP\Temporary Internet Files\Content.IE5\k 2850816 bytes
c:\windows\TEMP\Temporary Internet Files\Content.IE5\c 884736 bytes
c:\windows\TEMP\Temporary Internet Files\Content.IE5\
c:\windows\TEMP\Temporary Internet Files\Content.IE5\z 7700480 bytes
c:\windows\TEMP\Temporary Internet Files\Content.IE5\l 5406720 bytes
c:\windows\TEMP\Temporary Internet Files\Content.IE5\s 2981888 bytes
c:\windows\TEMP\Temporary Internet Files\Content.IE5\0 2129920 bytes
c:\windows\TEMP\Temporary Internet Files\Content.IE5\p 3178496 bytes
c:\windows\TEMP\Temporary Internet Files\Content.IE5\8 3637248 bytes
c:\windows\TEMP\Temporary Internet Files\Content.IE5\F 3244032 bytes
c:\windows\TEMP\Temporary Internet Files\Content.IE5\c 3440640 bytes
c:\windows\TEMP\Temporary Internet Files\Content.IE5\0 4358144 bytes
c:\windows\TEMP\Temporary Internet Files\Content.IE5\U 7045120 bytes
c:\windows\TEMP\Temporary Internet Files\Content.IE5\e 884736 bytes
c:\windows\TEMP\Temporary Internet Files\Content.IE5\
c:\windows\TEMP\Temporary Internet Files\Content.IE5\y 7110656 bytes
c:\windows\TEMP\Temporary Internet Files\Content.IE5\6 5406720 bytes
c:\windows\TEMP\Temporary Internet Files\Content.IE5\s 2981888 bytes
c:\windows\TEMP\Temporary Internet Files\Content.IE5\0 2129920 bytes
c:\windows\TEMP\Temporary Internet Files\Content.IE5\p 3178496 bytes
c:\windows\TEMP\Temporary Internet Files\Content.IE5\8 3637248 bytes
c:\windows\TEMP\Temporary Internet Files\Content.IE5\F 3244032 bytes
c:\windows\TEMP\Temporary Internet Files\Content.IE5\c 3440640 bytes
c:\windows\TEMP\Temporary Internet Files\Content.IE5\0 4358144 bytes
c:\windows\TEMP\Temporary Internet Files\Content.IE5\U 7045120 bytes
c:\windows\TEMP\Temporary Internet Files\Content.IE5\e 884736 bytes
c:\windows\TEMP\Temporary Internet Files\Content.IE5\
c:\windows\TEMP\Temporary Internet Files\Content.IE5\s 2981888 bytes
c:\windows\TEMP\Temporary Internet Files\Content.IE5\0 2129920 bytes
c:\windows\TEMP\Temporary Internet Files\Content.IE5\p 3178496 bytes
c:\windows\TEMP\Temporary Internet Files\Content.IE5\8 3637248 bytes
c:\windows\TEMP\Temporary Internet Files\Content.IE5\F 3244032 bytes
c:\windows\TEMP\Temporary Internet Files\Content.IE5\c 3440640 bytes
c:\windows\TEMP\Temporary Internet Files\Content.IE5\0 4358144 bytes
c:\windows\TEMP\Temporary Internet Files\Content.IE5\U 7045120 bytes
c:\windows\TEMP\Temporary Internet Files\Content.IE5\e 884736 bytes
c:\windows\TEMP\Temporary Internet Files\Content.IE5\
c:\windows\TEMP\Temporary Internet Files\Content.IE5\P 4358144 bytes
c:\windows\TEMP\Temporary Internet Files\Content.IE5\m 5406720 bytes
c:\windows\TEMP\Temporary Internet Files\Content.IE5\s 2981888 bytes
c:\windows\TEMP\Temporary Internet Files\Content.IE5\0 2129920 bytes
c:\windows\TEMP\Temporary Internet Files\Content.IE5\p 3178496 bytes
c:\windows\TEMP\Temporary Internet Files\Content.IE5\8 3637248 bytes
c:\windows\TEMP\Temporary Internet Files\Content.IE5\F 3244032 bytes
c:\windows\TEMP\Temporary Internet Files\Content.IE5\c 3440640 bytes
c:\windows\TEMP\Temporary Internet Files\Content.IE5\0 4423680 bytes
c:\windows\TEMP\Temporary Internet Files\Content.IE5\I 6979584 bytes
c:\windows\TEMP\Temporary Internet Files\Content.IE5\w 884736 bytes
c:\windows\TEMP\Temporary Internet Files\Content.IE5\
c:\windows\TEMP\Temporary Internet Files\Content.IE5\e 5472256 bytes
c:\windows\TEMP\Temporary Internet Files\Content.IE5\I 5406720 bytes
c:\windows\TEMP\Temporary Internet Files\Content.IE5\s 2981888 bytes
c:\windows\TEMP\Temporary Internet Files\Content.IE5\0 2129920 bytes
c:\windows\TEMP\Temporary Internet Files\Content.IE5\p 3178496 bytes
c:\windows\TEMP\Temporary Internet Files\Content.IE5\8 3637248 bytes
c:\windows\TEMP\Temporary Internet Files\Content.IE5\F 3244032 bytes
c:\windows\TEMP\Temporary Internet Files\Content.IE5\c 3440640 bytes
c:\windows\TEMP\Temporary Internet Files\Content.IE5\0 4489216 bytes
c:\windows\TEMP\Temporary Internet Files\Content.IE5\/ 6717440 bytes
c:\windows\TEMP\Temporary Internet Files\Content.IE5\6 884736 bytes
c:\windows\TEMP\Temporary Internet Files\Content.IE5\
c:\windows\TEMP\Temporary Internet Files\Content.IE5\s 2981888 bytes
c:\windows\TEMP\Temporary Internet Files\Content.IE5\0 2129920 bytes
c:\windows\TEMP\Temporary Internet Files\Content.IE5\p 3178496 bytes
c:\windows\TEMP\Temporary Internet Files\Content.IE5\8 3637248 bytes
c:\windows\TEMP\Temporary Internet Files\Content.IE5\F 3244032 bytes
c:\windows\TEMP\Temporary Internet Files\Content.IE5\c 3440640 bytes
c:\windows\TEMP\Temporary Internet Files\Content.IE5\0 4292608 bytes
c:\windows\TEMP\Temporary Internet Files\Content.IE5\u 7045120 bytes
c:\windows\TEMP\Temporary Internet Files\Content.IE5\i 884736 bytes
c:\windows\TEMP\Temporary Internet Files\Content.IE5\
c:\windows\TEMP\Temporary Internet Files\Content.IE5\Y 7372800 bytes
c:\windows\TEMP\Temporary Internet Files\Content.IE5\k 5406720 bytes
c:\windows\TEMP\Temporary Internet Files\Content.IE5\s 2981888 bytes
c:\windows\TEMP\Temporary Internet Files\Content.IE5\0 2129920 bytes
c:\windows\TEMP\Temporary Internet Files\Content.IE5\p 3178496 bytes
c:\windows\TEMP\Temporary Internet Files\Content.IE5\8 3637248 bytes
c:\windows\TEMP\Temporary Internet Files\Content.IE5\F 3244032 bytes
c:\windows\TEMP\Temporary Internet Files\Content.IE5\c 3440640 bytes
c:\windows\TEMP\Temporary Internet Files\Content.IE5\0 4489216 bytes
c:\windows\TEMP\Temporary Internet Files\Content.IE5\Z 6651904 bytes
c:\windows\TEMP\Temporary Internet Files\Content.IE5\n 884736 bytes
c:\windows\TEMP\Temporary Internet Files\Content.IE5\
c:\windows\TEMP\Temporary Internet Files\Content.IE5\s 2981888 bytes
c:\windows\TEMP\Temporary Internet Files\Content.IE5\0 2129920 bytes
c:\windows\TEMP\Temporary Internet Files\Content.IE5\p 3178496 bytes
c:\windows\TEMP\Temporary Internet Files\Content.IE5\8 3637248 bytes
c:\windows\TEMP\Temporary Internet Files\Content.IE5\F 3244032 bytes
c:\windows\TEMP\Temporary Internet Files\Content.IE5\c 3440640 bytes
c:\windows\TEMP\Temporary Internet Files\Content.IE5\0 4358144 bytes
c:\windows\TEMP\Temporary Internet Files\Content.IE5\U 7045120 bytes
c:\windows\TEMP\Temporary Internet Files\Content.IE5\e 884736 bytes
c:\windows\TEMP\Temporary Internet Files\Content.IE5\
c:\windows\TEMP\Temporary Internet Files\Content.IE5\e 5406720 bytes
c:\windows\TEMP\Temporary Internet Files\Content.IE5\s 2981888 bytes
c:\windows\TEMP\Temporary Internet Files\Content.IE5\0 2129920 bytes
c:\windows\TEMP\Temporary Internet Files\Content.IE5\p 3178496 bytes
c:\windows\TEMP\Temporary Internet Files\Content.IE5\8 3637248 bytes
c:\windows\TEMP\Temporary Internet Files\Content.IE5\F 3244032 bytes
c:\windows\TEMP\Temporary Internet Files\Content.IE5\c 3440640 bytes
c:\windows\TEMP\Temporary Internet Files\Content.IE5\0 4489216 bytes
c:\windows\TEMP\Temporary Internet Files\Content.IE5\k 2850816 bytes
c:\windows\TEMP\Temporary Internet Files\Content.IE5\c 884736 bytes
c:\windows\TEMP\Temporary Internet Files\Content.IE5\
c:\windows\TEMP\Temporary Internet Files\Content.IE5\x 7766016 bytes
c:\windows\TEMP\Temporary Internet Files\Content.IE5\s 2981888 bytes
c:\windows\TEMP\Temporary Internet Files\Content.IE5\0 2129920 bytes
c:\windows\TEMP\Temporary Internet Files\Content.IE5\p 3178496 bytes
c:\windows\TEMP\Temporary Internet Files\Content.IE5\8 3637248 bytes
c:\windows\TEMP\Temporary Internet Files\Content.IE5\F 3244032 bytes
c:\windows\TEMP\Temporary Internet Files\Content.IE5\c 3440640 bytes
c:\windows\TEMP\Temporary Internet Files\Content.IE5\0 4358144 bytes
c:\windows\TEMP\Temporary Internet Files\Content.IE5\U 7045120 bytes
c:\windows\TEMP\Temporary Internet Files\Content.IE5\e 884736 bytes
c:\windows\TEMP\Temporary Internet Files\Content.IE5\
c:\windows\TEMP\Temporary Internet Files\Content.IE5\e 5472256 bytes
c:\windows\TEMP\Temporary Internet Files\Content.IE5\I 5406720 bytes
c:\windows\TEMP\Temporary Internet Files\Content.IE5\s 2981888 bytes
c:\windows\TEMP\Temporary Internet Files\Content.IE5\0 2129920 bytes
c:\windows\TEMP\Temporary Internet Files\Content.IE5\p 3178496 bytes
c:\windows\TEMP\Temporary Internet Files\Content.IE5\8 3637248 bytes
c:\windows\TEMP\Temporary Internet Files\Content.IE5\F 3244032 bytes
c:\windows\TEMP\Temporary Internet Files\Content.IE5\c 3440640 bytes
c:\windows\TEMP\Temporary Internet Files\Content.IE5\0 4423680 bytes
c:\windows\TEMP\Temporary Internet Files\Content.IE5\I 6979584 bytes
c:\windows\TEMP\Temporary Internet Files\Content.IE5\w 884736 bytes
c:\windows\TEMP\Temporary Internet Files\Content.IE5\
c:\windows\TEMP\Temporary Internet Files\Content.IE5\s 2981888 bytes
c:\windows\TEMP\Temporary Internet Files\Content.IE5\0 2129920 bytes
c:\windows\TEMP\Temporary Internet Files\Content.IE5\p 3178496 bytes
c:\windows\TEMP\Temporary Internet Files\Content.IE5\8 3637248 bytes
c:\windows\TEMP\Temporary Internet Files\Content.IE5\F 3244032 bytes
c:\windows\TEMP\Temporary Internet Files\Content.IE5\c 3440640 bytes
c:\windows\TEMP\Temporary Internet Files\Content.IE5\0 4358144 bytes
c:\windows\TEMP\Temporary Internet Files\Content.IE5\t 5406720 bytes
c:\windows\TEMP\Temporary Internet Files\Content.IE5\i 884736 bytes
c:\windows\TEMP\Temporary Internet Files\Content.IE5\
c:\windows\TEMP\Temporary Internet Files\Content.IE5\O 4947968 bytes
c:\windows\TEMP\Temporary Internet Files\Content.IE5\s 2981888 bytes
c:\windows\TEMP\Temporary Internet Files\Content.IE5\0 2129920 bytes
c:\windows\TEMP\Temporary Internet Files\Content.IE5\p 3178496 bytes
c:\windows\TEMP\Temporary Internet Files\Content.IE5\8 3637248 bytes
c:\windows\TEMP\Temporary Internet Files\Content.IE5\F 3244032 bytes
c:\windows\TEMP\Temporary Internet Files\Content.IE5\c 3440640 bytes
c:\windows\TEMP\Temporary Internet Files\Content.IE5\0 4489216 bytes
c:\windows\TEMP\Temporary Internet Files\Content.IE5\/ 6717440 bytes
c:\windows\TEMP\Temporary Internet Files\Content.IE5\6 884736 bytes
c:\windows\TEMP\Temporary Internet Files\Content.IE5\
c:\windows\TEMP\Temporary Internet Files\Content.IE5\4 3768320 bytes
c:\windows\TEMP\Temporary Internet Files\Content.IE5\N 5406720 bytes
c:\windows\TEMP\Temporary Internet Files\Content.IE5\s 2981888 bytes
c:\windows\TEMP\Temporary Internet Files\Content.IE5\0 2129920 bytes
c:\windows\TEMP\Temporary Internet Files\Content.IE5\p 3178496 bytes
c:\windows\TEMP\Temporary Internet Files\Content.IE5\8 3637248 bytes
c:\windows\TEMP\Temporary Internet Files\Content.IE5\F 3244032 bytes
c:\windows\TEMP\Temporary Internet Files\Content.IE5\c 3440640 bytes
c:\windows\TEMP\Temporary Internet Files\Content.IE5\0 4292608 bytes
c:\windows\TEMP\Temporary Internet Files\Content.IE5\8 3637248 bytes
c:\windows\TEMP\Temporary Internet Files\Content.IE5\T 884736 bytes
c:\windows\TEMP\Temporary Internet Files\Content.IE5\
c:\windows\TEMP\Temporary Internet Files\Content.IE5\p 8028160 bytes
c:\windows\TEMP\Temporary Internet Files\Content.IE5\8 5406720 bytes
c:\windows\TEMP\Temporary Internet Files\Content.IE5\s 2981888 bytes
c:\windows\TEMP\Temporary Internet Files\Content.IE5\0 2129920 bytes
c:\windows\TEMP\Temporary Internet Files\Content.IE5\p 3178496 bytes
c:\windows\TEMP\Temporary Internet Files\Content.IE5\8 3637248 bytes
c:\windows\TEMP\Temporary Internet Files\Content.IE5\F 3244032 bytes
c:\windows\TEMP\Temporary Internet Files\Content.IE5\c 3440640 bytes
c:\windows\TEMP\Temporary Internet Files\Content.IE5\0 4358144 bytes
c:\windows\TEMP\Temporary Internet Files\Content.IE5\w 4423680 bytes
c:\windows\TEMP\Temporary Internet Files\Content.IE5\l 884736 bytes
c:\windows\TEMP\Temporary Internet Files\Content.IE5\
c:\windows\TEMP\Temporary Internet Files\Content.IE5\O 4947968 bytes
c:\windows\TEMP\Temporary Internet Files\Content.IE5\s 2981888 bytes
c:\windows\TEMP\Temporary Internet Files\Content.IE5\0 2129920 bytes
c:\windows\TEMP\Temporary Internet Files\Content.IE5\p 3178496 bytes
c:\windows\TEMP\Temporary Internet Files\Content.IE5\8 3637248 bytes
c:\windows\TEMP\Temporary Internet Files\Content.IE5\F 3244032 bytes
c:\windows\TEMP\Temporary Internet Files\Content.IE5\c 3440640 bytes
c:\windows\TEMP\Temporary Internet Files\Content.IE5\0 4292608 bytes
c:\windows\TEMP\Temporary Internet Files\Content.IE5\L 3768320 bytes
c:\windows\TEMP\Temporary Internet Files\Content.IE5\0 884736 bytes
c:\windows\TEMP\Temporary Internet Files\Content.IE5\
c:\windows\TEMP\Temporary Internet Files\Content.IE5\e 5406720 bytes
c:\windows\TEMP\Temporary Internet Files\Content.IE5\s 2981888 bytes
c:\windows\TEMP\Temporary Internet Files\Content.IE5\0 2129920 bytes
c:\windows\TEMP\Temporary Internet Files\Content.IE5\p 3178496 bytes
c:\windows\TEMP\Temporary Internet Files\Content.IE5\8 3637248 bytes
c:\windows\TEMP\Temporary Internet Files\Content.IE5\F 3244032 bytes
c:\windows\TEMP\Temporary Internet Files\Content.IE5\c 3440640 bytes
c:\windows\TEMP\Temporary Internet Files\Content.IE5\0 4358144 bytes
c:\windows\TEMP\Temporary Internet Files\Content.IE5\t 5406720 bytes
c:\windows\TEMP\Temporary Internet Files\Content.IE5\i 884736 bytes
c:\windows\TEMP\Temporary Internet Files\Content.IE5\
c:\windows\TEMP\Temporary Internet Files\Content.IE5\P 4358144 bytes
c:\windows\TEMP\Temporary Internet Files\Content.IE5\m 5406720 bytes
c:\windows\TEMP\Temporary Internet Files\Content.IE5\s 2981888 bytes
c:\windows\TEMP\Temporary Internet Files\Content.IE5\0 2129920 bytes
c:\windows\TEMP\Temporary Internet Files\Content.IE5\p 3178496 bytes
c:\windows\TEMP\Temporary Internet Files\Content.IE5\8 3637248 bytes
c:\windows\TEMP\Temporary Internet Files\Content.IE5\F 3244032 bytes
c:\windows\TEMP\Temporary Internet Files\Content.IE5\c 3440640 bytes
c:\windows\TEMP\Temporary Internet Files\Content.IE5\0 4292608 bytes
c:\windows\TEMP\Temporary Internet Files\Content.IE5\u 7045120 bytes
c:\windows\TEMP\Temporary Internet Files\Content.IE5\i 884736 bytes
c:\windows\TEMP\Temporary Internet Files\Content.IE5\
c:\windows\TEMP\Temporary Internet Files\Content.IE5\z 7700480 bytes
c:\windows\TEMP\Temporary Internet Files\Content.IE5\l 5406720 bytes
c:\windows\TEMP\Temporary Internet Files\Content.IE5\s 2981888 bytes
c:\windows\TEMP\Temporary Internet Files\Content.IE5\0 2129920 bytes
c:\windows\TEMP\Temporary Internet Files\Content.IE5\p 3178496 bytes
c:\windows\TEMP\Temporary Internet Files\Content.IE5\8 3637248 bytes
c:\windows\TEMP\Temporary Internet Files\Content.IE5\F 3244032 bytes
c:\windows\TEMP\Temporary Internet Files\Content.IE5\c 3440640 bytes
c:\windows\TEMP\Temporary Internet Files\Content.IE5\0 4489216 bytes
c:\windows\TEMP\Temporary Internet Files\Content.IE5\Z 6651904 bytes
c:\windows\TEMP\Temporary Internet Files\Content.IE5\n 884736 bytes
c:\windows\TEMP\Temporary Internet Files\Content.IE5\
c:\windows\TEMP\Temporary Internet Files\Content.IE5\z 7700480 bytes
c:\windows\TEMP\Temporary Internet Files\Content.IE5\l 5406720 bytes
c:\windows\TEMP\Temporary Internet Files\Content.IE5\s 2981888 bytes
c:\windows\TEMP\Temporary Internet Files\Content.IE5\0 2129920 bytes
c:\windows\TEMP\Temporary Internet Files\Content.IE5\p 3178496 bytes
c:\windows\TEMP\Temporary Internet Files\Content.IE5\8 3637248 bytes
c:\windows\TEMP\Temporary Internet Files\Content.IE5\F 3244032 bytes
c:\windows\TEMP\Temporary Internet Files\Content.IE5\c 3440640 bytes
c:\windows\TEMP\Temporary Internet Files\Content.IE5\0 4489216 bytes
c:\windows\TEMP\Temporary Internet Files\Content.IE5\M 5931008 bytes
c:\windows\TEMP\Temporary Internet Files\Content.IE5\e 884736 bytes
c:\windows\TEMP\Temporary Internet Files\Content.IE5\
c:\windows\TEMP\Temporary Internet Files\Content.IE5\y 7110656 bytes
c:\windows\TEMP\Temporary Internet Files\Content.IE5\6 5406720 bytes
c:\windows\TEMP\Temporary Internet Files\Content.IE5\s 2981888 bytes
c:\windows\TEMP\Temporary Internet Files\Content.IE5\0 2129920 bytes
c:\windows\TEMP\Temporary Internet Files\Content.IE5\p 3178496 bytes
c:\windows\TEMP\Temporary Internet Files\Content.IE5\8 3637248 bytes
c:\windows\TEMP\Temporary Internet Files\Content.IE5\F 3244032 bytes
c:\windows\TEMP\Temporary Internet Files\Content.IE5\c 3440640 bytes
c:\windows\TEMP\Temporary Internet Files\Content.IE5\0 4358144 bytes
c:\windows\TEMP\Temporary Internet Files\Content.IE5\w 4423680 bytes
c:\windows\TEMP\Temporary Internet Files\Content.IE5\l 884736 bytes
c:\windows\TEMP\Temporary Internet Files\Content.IE5\
c:\windows\TEMP\Temporary Internet Files\Content.IE5\z 5210112 bytes
c:\windows\TEMP\Temporary Internet Files\Content.IE5\n 5406720 bytes
c:\windows\TEMP\Temporary Internet Files\Content.IE5\s 2981888 bytes
c:\windows\TEMP\Temporary Internet Files\Content.IE5\0 2129920 bytes
c:\windows\TEMP\Temporary Internet Files\Content.IE5\p 3178496 bytes
c:\windows\TEMP\Temporary Internet Files\Content.IE5\8 3637248 bytes
c:\windows\TEMP\Temporary Internet Files\Content.IE5\F 3244032 bytes
c:\windows\TEMP\Temporary Internet Files\Content.IE5\c 3440640 bytes
c:\windows\TEMP\Temporary Internet Files\Content.IE5\0 4489216 bytes
c:\windows\TEMP\Temporary Internet Files\Content.IE5\M 5931008 bytes
c:\windows\TEMP\Temporary Internet Files\Content.IE5\e 884736 bytes
c:\windows\TEMP\Temporary Internet Files\Content.IE5\
c:\windows\TEMP\Temporary Internet Files\Content.IE5\4 3768320 bytes
c:\windows\TEMP\Temporary Internet Files\Content.IE5\N 5406720 bytes
c:\windows\TEMP\Temporary Internet Files\Content.IE5\s 2981888 bytes
c:\windows\TEMP\Temporary Internet Files\Content.IE5\0 2129920 bytes
c:\windows\TEMP\Temporary Internet Files\Content.IE5\p 3178496 bytes
c:\windows\TEMP\Temporary Internet Files\Content.IE5\8 3637248 bytes
c:\windows\TEMP\Temporary Internet Files\Content.IE5\F 3244032 bytes
c:\windows\TEMP\Temporary Internet Files\Content.IE5\c 3440640 bytes
c:\windows\TEMP\Temporary Internet Files\Content.IE5\0 4292608 bytes
c:\windows\TEMP\Temporary Internet Files\Content.IE5\u 7045120 bytes
c:\windows\TEMP\Temporary Internet Files\Content.IE5\i 884736 bytes
c:\windows\TEMP\Temporary Internet Files\Content.IE5\
c:\windows\TEMP\Temporary Internet Files\Content.IE5\Y 7372800 bytes
c:\windows\TEMP\Temporary Internet Files\Content.IE5\k 5406720 bytes
c:\windows\TEMP\Temporary Internet Files\Content.IE5\s 2981888 bytes
c:\windows\TEMP\Temporary Internet Files\Content.IE5\0 2129920 bytes
c:\windows\TEMP\Temporary Internet Files\Content.IE5\p 3178496 bytes
c:\windows\TEMP\Temporary Internet Files\Content.IE5\8 3637248 bytes
c:\windows\TEMP\Temporary Internet Files\Content.IE5\F 3244032 bytes
c:\windows\TEMP\Temporary Internet Files\Content.IE5\c 3440640 bytes
c:\windows\TEMP\Temporary Internet Files\Content.IE5\0 4423680 bytes
c:\windows\TEMP\Temporary Internet Files\Content.IE5\I 6979584 bytes
c:\windows\TEMP\Temporary Internet Files\Content.IE5\w 884736 bytes
c:\windows\TEMP\Temporary Internet Files\Content.IE5\
c:\windows\TEMP\Temporary Internet Files\Content.IE5\e 5406720 bytes
c:\windows\TEMP\Temporary Internet Files\Content.IE5\s 2981888 bytes
c:\windows\TEMP\Temporary Internet Files\Content.IE5\0 2129920 bytes
c:\windows\TEMP\Temporary Internet Files\Content.IE5\p 3178496 bytes
c:\windows\TEMP\Temporary Internet Files\Content.IE5\8 3637248 bytes
c:\windows\TEMP\Temporary Internet Files\Content.IE5\F 3244032 bytes
c:\windows\TEMP\Temporary Internet Files\Content.IE5\c 3440640 bytes
c:\windows\TEMP\Temporary Internet Files\Content.IE5\0 4489216 bytes
c:\windows\TEMP\Temporary Internet Files\Content.IE5\k 2850816 bytes
c:\windows\TEMP\Temporary Internet Files\Content.IE5\c 884736 bytes
c:\windows\TEMP\Temporary Internet Files\Content.IE5\
c:\windows\TEMP\Temporary Internet Files\Content.IE5\z 7700480 bytes
c:\windows\TEMP\Temporary Internet Files\Content.IE5\l 5406720 bytes
c:\windows\TEMP\Temporary Internet Files\Content.IE5\s 2981888 bytes
c:\windows\TEMP\Temporary Internet Files\Content.IE5\0 2129920 bytes
c:\windows\TEMP\Temporary Internet Files\Content.IE5\p 3178496 bytes
c:\windows\TEMP\Temporary Internet Files\Content.IE5\8 3637248 bytes
c:\windows\TEMP\Temporary Internet Files\Content.IE5\F 3244032 bytes
c:\windows\TEMP\Temporary Internet Files\Content.IE5\c 3440640 bytes
c:\windows\TEMP\Temporary Internet Files\Content.IE5\0 4292608 bytes
c:\windows\TEMP\Temporary Internet Files\Content.IE5\8 3637248 bytes
c:\windows\TEMP\Temporary Internet Files\Content.IE5\T 884736 bytes
c:\windows\TEMP\Temporary Internet Files\Content.IE5\
c:\windows\TEMP\Temporary Internet Files\Content.IE5\n 5603328 bytes
c:\windows\TEMP\Temporary Internet Files\Content.IE5\s 2981888 bytes
c:\windows\TEMP\Temporary Internet Files\Content.IE5\0 2129920 bytes
c:\windows\TEMP\Temporary Internet Files\Content.IE5\p 3178496 bytes
c:\windows\TEMP\Temporary Internet Files\Content.IE5\8 3637248 bytes
c:\windows\TEMP\Temporary Internet Files\Content.IE5\F 3244032 bytes
c:\windows\TEMP\Temporary Internet Files\Content.IE5\c 3440640 bytes
c:\windows\TEMP\Temporary Internet Files\Content.IE5\0 4358144 bytes
c:\windows\TEMP\Temporary Internet Files\Content.IE5\O 4358144 bytes
c:\windows\TEMP\Temporary Internet Files\Content.IE5\X 884736 bytes
c:\windows\TEMP\Temporary Internet Files\Content.IE5\
c:\windows\TEMP\Temporary Internet Files\Content.IE5\n 5603328 bytes
c:\windows\TEMP\Temporary Internet Files\Content.IE5\s 2981888 bytes
c:\windows\TEMP\Temporary Internet Files\Content.IE5\0 2129920 bytes
c:\windows\TEMP\Temporary Internet Files\Content.IE5\p 3178496 bytes
c:\windows\TEMP\Temporary Internet Files\Content.IE5\8 3637248 bytes
c:\windows\TEMP\Temporary Internet Files\Content.IE5\F 3244032 bytes
c:\windows\TEMP\Temporary Internet Files\Content.IE5\c 3440640 bytes
c:\windows\TEMP\Temporary Internet Files\Content.IE5\0 4358144 bytes
c:\windows\TEMP\Temporary Internet Files\Content.IE5\O 4358144 bytes
c:\windows\TEMP\Temporary Internet Files\Content.IE5\X 884736 bytes
c:\windows\TEMP\Temporary Internet Files\Content.IE5\
c:\windows\TEMP\Temporary Internet Files\Content.IE5\x 7766016 bytes
c:\windows\TEMP\Temporary Internet Files\Content.IE5\s 2981888 bytes
c:\windows\TEMP\Temporary Internet Files\Content.IE5\0 2129920 bytes
c:\windows\TEMP\Temporary Internet Files\Content.IE5\p 3178496 bytes
c:\windows\TEMP\Temporary Internet Files\Content.IE5\8 3637248 bytes
c:\windows\TEMP\Temporary Internet Files\Content.IE5\F 3244032 bytes
c:\windows\TEMP\Temporary Internet Files\Content.IE5\c 3440640 bytes
c:\windows\TEMP\Temporary Internet Files\Content.IE5\0 4423680 bytes
c:\windows\TEMP\Temporary Internet Files\Content.IE5\I 6979584 bytes
c:\windows\TEMP\Temporary Internet Files\Content.IE5\w 884736 bytes
c:\windows\TEMP\Temporary Internet Files\Content.IE5\
c:\windows\TEMP\Temporary Internet Files\Content.IE5\P 4358144 bytes
c:\windows\TEMP\Temporary Internet Files\Content.IE5\m 5406720 bytes
c:\windows\TEMP\Temporary Internet Files\Content.IE5\s 2981888 bytes
c:\windows\TEMP\Temporary Internet Files\Content.IE5\0 2129920 bytes
c:\windows\TEMP\Temporary Internet Files\Content.IE5\p 3178496 bytes
c:\windows\TEMP\Temporary Internet Files\Content.IE5\8 3637248 bytes
c:\windows\TEMP\Temporary Internet Files\Content.IE5\F 3244032 bytes
c:\windows\TEMP\Temporary Internet Files\Content.IE5\c 3440640 bytes
c:\windows\TEMP\Temporary Internet Files\Content.IE5\0 4358144 bytes
c:\windows\TEMP\Temporary Internet Files\Content.IE5\w 4423680 bytes
c:\windows\TEMP\Temporary Internet Files\Content.IE5\l 884736 bytes
c:\windows\TEMP\Temporary Internet Files\Content.IE5\
c:\windows\TEMP\Temporary Internet Files\Content.IE5\s 2981888 bytes
c:\windows\TEMP\Temporary Internet Files\Content.IE5\0 2129920 bytes
c:\windows\TEMP\Temporary Internet Files\Content.IE5\p 3178496 bytes
c:\windows\TEMP\Temporary Internet Files\Content.IE5\8 3637248 bytes
c:\windows\TEMP\Temporary Internet Files\Content.IE5\F 3244032 bytes
c:\windows\TEMP\Temporary Internet Files\Content.IE5\c 3440640 bytes
c:\windows\TEMP\Temporary Internet Files\Content.IE5\0 4292608 bytes
c:\windows\TEMP\Temporary Internet Files\Content.IE5\q 4358144 bytes
c:\windows\TEMP\Temporary Internet Files\Content.IE5\i 884736 bytes
c:\windows\TEMP\Temporary Internet Files\Content.IE5\
c:\windows\TEMP\Temporary Internet Files\Content.IE5\M 7307264 bytes
c:\windows\TEMP\Temporary Internet Files\Content.IE5\b 5406720 bytes
c:\windows\TEMP\Temporary Internet Files\Content.IE5\s 2981888 bytes
c:\windows\TEMP\Temporary Internet Files\Content.IE5\0 2129920 bytes
c:\windows\TEMP\Temporary Internet Files\Content.IE5\p 3178496 bytes
c:\windows\TEMP\Temporary Internet Files\Content.IE5\8 3637248 bytes
c:\windows\TEMP\Temporary Internet Files\Content.IE5\F 3244032 bytes
c:\windows\TEMP\Temporary Internet Files\Content.IE5\c 3440640 bytes
c:\windows\TEMP\Temporary Internet Files\Content.IE5\0 4358144 bytes
c:\windows\TEMP\Temporary Internet Files\Content.IE5\U 7045120 bytes
c:\windows\TEMP\Temporary Internet Files\Content.IE5\e 884736 bytes
 
Back
Top