# Solved: ultimate cleaner and ultimate defender keep popping out



## cpuanswers (Sep 25, 2007)

both of these things keep popping out and there is a big red screen that says "YOUR PRIVACY IS IN DANGER DOWNLOAD PROTECTION SOFTWARE NOW" also my cpu is running slow and i NEED HELP!


----------



## MFDnNC (Sep 7, 2004)

*Click here* to download *HJTInstall.exe*

Save *HJTInstall.exe* to your desktop.
Doubleclick on the *HJTInstall.exe* icon on your desktop.
By default it will install to *C:\Program Files\Trend Micro\HijackThis* . 
Click on *Install*.
It will create a HijackThis icon on the desktop.
Once installed, it will launch *Hijackthis*.
Click on the *Do a system scan and save a logfile* button. It will scan and the log should open in notepad.
Click on "Edit > Select All" then click on "Edit > Copy" to copy the entire contents of the log.
Come back here to this thread and Paste the log in your next reply.
*DO NOT* have Hijackthis fix anything yet. Most of what it finds will be harmless or even required.


----------



## cpuanswers (Sep 25, 2007)

Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 3:05:08 PM, on 9/25/2007
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Yahoo!\Antivirus\ISafe.exe
C:\WINDOWS\system32\HPZipm12.exe
C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe
C:\Program Files\Digital Media Reader\readericon45G.exe
C:\WINDOWS\RTHDCPL.EXE
C:\Program Files\Common Files\New Boundary\PrismXL\PRISMXL.SYS
C:\Program Files\HP\HP Software Update\HPWuSchd2.exe
C:\PROGRA~1\Yahoo!\browser\ybrwicon.exe
C:\WINDOWS\system32\svchost.exe
C:\PROGRA~1\SBCLIG~1\SMARTB~1\MotiveSB.exe
C:\Program Files\QuickTime\qttask.exe
C:\PROGRA~1\Yahoo!\YOP\yop.exe
C:\Program Files\Common Files\WinAntiSpyware 2007\uwas7cw.exe
C:\Program Files\Yahoo!\Antivirus\CAVTray.exe
C:\Program Files\Yahoo!\Antivirus\CAVRID.exe
C:\Program Files\Yahoo!\Search Protection\SearchProtection.exe
C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
C:\PROGRA~1\Yahoo!\browser\ycommon.exe
C:\Program Files\Messenger\msmsgs.exe
C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe
C:\Program Files\Nikon\PictureProject\NkbMonitor.exe
C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe
C:\Program Files\Yahoo!\Yahoo! Music Jukebox\ymetray.exe
C:\WINDOWS\system32\VirtualExpander\VirtualExpander.exe
C:\Program Files\Yahoo!\Messenger\ymsgr_tray.exe
C:\WINDOWS\system32\wuauclt.exe
C:\WINDOWS\system32\wuauclt.exe
C:\Program Files\HP\Digital Imaging\bin\hpqSTE08.exe
C:\Program Files\Yahoo!\Antivirus\VetMsg.exe
C:\Program Files\Internet Explorer\IEXPLORE.EXE
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://softwarereferral.com/jump.php?wmid=6010&mid=MjI6Ojg5&lid=2
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.gateway.com/g/startpage.html?Ch=Retail&Br=EM&Loc=ENG_US&Sys=DTP&M=T3508
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar = http://red.clientapps.yahoo.com/cus.../sbcydsl/*http://www.yahoo.com/search/ie.html
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://red.clientapps.yahoo.com/customize/ie/defaults/sp/sbcydsl/*http://www.yahoo.com
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.gateway.com/g/startpage.html?Ch=Retail&Br=EM&Loc=ENG_US&Sys=DTP&M=T3508
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = 127.0.0.1;<local>
R3 - URLSearchHook: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn1\yt.dll
O2 - BHO: &Yahoo! Toolbar Helper - {02478D38-C3F9-4EFB-9B51-7695ECA05670} - C:\Program Files\Yahoo!\Companion\Installs\cpn1\yt.dll
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
O2 - BHO: (no name) - {0C9D3A87-7FEF-462E-ADB8-C94DFF4D6B9B} - C:\Program Files\Internet Explorer\meqosadil83122.dll (file missing)
O2 - BHO: MSVPS System - {31CBB13B-244D-4C44-AED5-DCAD70F66281} - C:\WINDOWS\nsduo.dll
O2 - BHO: (no name) - {3964D8D6-86D0-493A-B460-A805B5401114} - C:\WINDOWS\system32\ljjgdax.dll (file missing)
O2 - BHO: Yahoo! IE Services Button - {5BAB4B5B-68BC-4B02-94D6-2FC0DE4A7897} - C:\PROGRA~1\Yahoo!\common\yiesrvc.dll
O2 - BHO: (no name) - {68867113-056C-43A4-807A-9C0B0C0A57F8} - C:\WINDOWS\system32\vtsqo.dll (file missing)
O2 - BHO: 0 - {69F4671A-1407-4D07-D485-5DA6C85BCFAB} - C:\Program Files\Online Services\qucam.dll (file missing)
O2 - BHO: (no name) - {76394256-0838-46B1-A319-D59FFC795843} - \
O2 - BHO: (no name) - {7D8ED76A-B6E6-4345-8AC8-47B1349DFCDC} - \
O2 - BHO: (no name) - {8941F9B8-6EC9-4BAE-A30F-BC3764FBBA3B} - \
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar2.dll
O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\2.0.301.7164\swg.dll
O2 - BHO: (no name) - {C6039E6C-BDE9-4de5-BB40-768CAA584FDC} - C:\WINDOWS\system32\wtmfmill.dll (file missing)
O2 - BHO: (no name) - {C6907F56-4510-401B-BCB0-06118FC61C8D} - \
O2 - BHO: CBrowserHelperObject Object - {CA6319C0-31B7-401E-A518-A07C3DB8F777} - c:\windows\system32\BAE.dll
O2 - BHO: SidebarAutoLaunch Class - {F2AA9440-6328-4933-B7C9-A6CCDF9CBF6D} - C:\Program Files\Yahoo!\browser\YSidebarIEBHO.dll
O2 - BHO: Flash8.ocx - {F52A94F5-A3CC-40DA-BCD7-222282E01406} - C:\WINDOWS\system32\driver\inf\mshtm.dll
O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar2.dll
O3 - Toolbar: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn1\yt.dll
O4 - HKLM\..\Run: [Google Desktop Search] "C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe" /startup
O4 - HKLM\..\Run: [readericon] C:\Program Files\Digital Media Reader\readericon45G.exe
O4 - HKLM\..\Run: [RTHDCPL] RTHDCPL.EXE
O4 - HKLM\..\Run: [Alcmtr] ALCMTR.EXE
O4 - HKLM\..\Run: [Recguard] %WINDIR%\SMINST\RECGUARD.EXE
O4 - HKLM\..\Run: [HP Software Update] C:\Program Files\HP\HP Software Update\HPWuSchd2.exe
O4 - HKLM\..\Run: [YBrowser] C:\PROGRA~1\Yahoo!\browser\ybrwicon.exe
O4 - HKLM\..\Run: [Motive SmartBridge] C:\PROGRA~1\SBCLIG~1\SMARTB~1\MotiveSB.exe
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [YOP] C:\PROGRA~1\Yahoo!\YOP\yop.exe /autostart
O4 - HKLM\..\Run: [{ZN}] C:\WINDOWS\TISKY009.exe SKY009
O4 - HKLM\..\Run: [uwas7cw] "C:\Program Files\Common Files\WinAntiSpyware 2007\uwas7cw.exe" -c
O4 - HKLM\..\Run: [CaAvTray] "C:\Program Files\Yahoo!\Antivirus\CAVTray.exe"
O4 - HKLM\..\Run: [CAVRID] "C:\Program Files\Yahoo!\Antivirus\CAVRID.exe"
O4 - HKLM\..\Run: [YSearchProtection] "C:\Program Files\Yahoo!\Search Protection\SearchProtection.exe"
O4 - HKCU\..\Run: [swg] C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
O4 - HKCU\..\Run: [Yahoo! Pager] "C:\Program Files\Yahoo!\Messenger\YahooMessenger.exe" -quiet
O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
O4 - HKCU\..\Run: [AROReminder] C:\Program Files\Advanced Registry Optimizer\aro.exe -rem
O4 - HKCU\..\Run: [Regscan] C:\WINDOWS\system32\regscan.exe
O4 - HKCU\..\Run: [YSearchProtection] C:\Program Files\Yahoo!\Search Protection\SearchProtection.exe
O4 - HKUS\S-1-5-18\..\Run: [Power2GoExpress] NA (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [Power2GoExpress] NA (User 'Default user')
O4 - Startup: .protected
O4 - Startup: TA_Start.lnk = C:\WINDOWS\TISKY009.exe
O4 - Startup: VirtualExpander.lnk = C:\WINDOWS\system32\VirtualExpander\VirtualExpander.exe
O4 - Global Startup: .protected
O4 - Global Startup: HP Digital Imaging Monitor.lnk = C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe
O4 - Global Startup: NkbMonitor.exe.lnk = C:\Program Files\Nikon\PictureProject\NkbMonitor.exe
O4 - Global Startup: ymetray.lnk = C:\Program Files\Yahoo!\Yahoo! Music Jukebox\ymetray.exe
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
O9 - Extra button: AT&T Yahoo! Services - {5BAB4B5B-68BC-4B02-94D6-2FC0DE4A7897} - C:\PROGRA~1\Yahoo!\common\yiesrvc.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL
O9 - Extra button: Real.com - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - C:\WINDOWS\system32\Shdocvw.dll
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O16 - DPF: {30528230-99f7-4bb4-88d8-fa1d4f56a2ab} (Installation Support) - C:\Program Files\Yahoo!\Common\Yinsthelper2007261.dll
O16 - DPF: {77E32299-629F-43C6-AB77-6A1E6D7663F6} (Groove Control) - http://www.nick.com/common/groove/gx/GrooveAX27.cab
O16 - DPF: {8A0DCBDB-6E20-489C-9041-C1E8A0352E75} (Mirar_Dummy_ATS1 Class) - http://awbeta.net-nucleus.com/FIX/WinATS.cab
O16 - DPF: {BB383206-6DA1-4E80-B62A-3DF950FCC697} (Create & Print ActiveX Plug-in) - http://ak.imgag.com/imgag/cp/install/AxCtp2.cab
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - https://fpdownload.macromedia.com/pub/shockwave/cabs/flash/swflash.cab
O20 - AppInit_DLLs: C:\PROGRA~1\Google\GOOGLE~1\GOEC62~1.DLL
O20 - Winlogon Notify: ljjgdax - ljjgdax.dll (file missing)
O20 - Winlogon Notify: vtsqo - C:\WINDOWS\system32\vtsqo.dll (file missing)
O21 - SSODL: msmhost - {CB689321-0BC3-4D6D-9ECA-2BF7CB7B9B8B} - C:\WINDOWS\msmhost.dll
O21 - SSODL: msmdev - {0A1E3A93-4AB0-4D9B-9113-D8FBEAE70899} - C:\WINDOWS\msmdev.dll
O23 - Service: Ati HotKey Poller - ATI Technologies Inc. - C:\WINDOWS\system32\Ati2evxx.exe
O23 - Service: ATI Smart - Unknown owner - C:\WINDOWS\system32\ati2sgag.exe
O23 - Service: CAISafe - Computer Associates International, Inc. - C:\Program Files\Yahoo!\Antivirus\ISafe.exe
O23 - Service: GoogleDesktopManager - Google - C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe
O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: Pml Driver HPZ12 - HP - C:\WINDOWS\system32\HPZipm12.exe
O23 - Service: PrismXL - New Boundary Technologies, Inc. - C:\Program Files\Common Files\New Boundary\PrismXL\PRISMXL.SYS
O23 - Service: VET Message Service (VETMSGNT) - Computer Associates International, Inc. - C:\Program Files\Yahoo!\Antivirus\VetMsg.exe
O23 - Service: YPCService - Yahoo! Inc. - C:\WINDOWS\system32\YPCSER~1.EXE
O24 - Desktop Component 0: (no name) - C:\Program Files\Online Services\rteleb.html
O24 - Desktop Component 1: Privacy Protection - file:///C:\WINDOWS\privacy_danger\index.htm

--
End of file - 10561 bytes


----------



## MFDnNC (Sep 7, 2004)

You have multiple problems - do ALL of the following

Download http://downloads.andymanchesta.com/RemovalTools/SDFix.exe and save it to your Desktop.

Double click SDFix.exe and it will extract the files to %systemdrive%
(Drive that contains the Windows Directory, typically *C:\SDFix)*

Please then reboot your computer in Safe Mode by doing the following :
·	Restart your computer
·	After hearing your computer beep once during startup, but before the Windows icon appears, tap the F8 key continually;
·	Instead of Windows loading as normal, the Advanced Options Menu should appear;
·	Select the first option, to run Windows in Safe Mode, then press Enter.
·	Choose your usual account.
·	Open the *extracted SDFix folder* and double click RunThis.bat to start the script.
·	Type Y to begin the cleanup process.
·	It will remove any Trojan Services and Registry Entries that it finds then prompt you to press any key to Reboot.
·	Press any Key and it will restart the PC.
·	When the PC restarts the Fixtool will run again and complete the removal process then display Finished, press any key to end the script and load your desktop icons.
·	Once the desktop icons load the SDFix report will open on screen and also save into the SDFix folder as Report.txt
(Report.txt will also be copied to Clipboard ready for posting back on the forum).
·	Finally paste the contents of the Report.txt back on the forum with a new HijackThis log
================
*NOTE: If you have downloaded ComboFix previously please delete that version and download it again!*

Download this file :

http://download.bleepingcomputer.com/sUBs/Beta/ComboFix.exe

Double click combofix.exe & follow the prompts.
When finished, it shall produce a log for you. *Post that log* 

Note: 
Do not mouseclick combofix's window while its running. That may cause it to stall

=====================
Download Superantispyware (SAS) free home version

http://www.superantispyware.com/superantispywarefreevspro.html

Install it and double-click the icon on your desktop to run it.
·	It will ask if you want to update the program definitions, click Yes.
·	Under Configuration and Preferences, click the Preferences button.
·	Click the Scanning Control tab.
·	Under Scanner Options make sure the following are checked:
o	Close browsers before scanning
o	Scan for tracking cookies
o	Terminate memory threats before quarantining.
o	Please leave the others as they were.
o	Click the Close button to leave the control center screen.
·	On the main screen, under Scan for Harmful Software click Scan your computer.
·	On the left check C:\Fixed Drive.
·	On the right, under Complete Scan, choose Perform Complete Scan.
·	Click Next to start the scan. Please be patient while it scans your computer.
·	After the scan is complete a summary box will appear. Click OK.
·	Make sure everything in the white box has a check next to it, then click Next.
·	It will quarantine what it found and if it asks if you want to reboot, click Yes.
·	To retrieve the removal information for me please do the following:
o	After reboot, double-click the SUPERAntispyware icon on your desktop.
o	Click Preferences. Click the Statistics/Logs tab.
o	Under Scanner Logs, double-click SUPERAntiSpyware Scan Log.
o	It will open in your default text editor (such as Notepad/Wordpad).
o	Please highlight everything in the notepad, then right-click and choose copy.
·	Click close and close again to exit the program.
·	*Please paste that information here for me regardless of what it finds with a new HijackThis log*.

This will take some time!!!!!!!!


----------



## cpuanswers (Sep 25, 2007)

SDFix: Version 1.107

Run by Owner_Emachine on Tue 09/25/2007 at 04:25 PM

Microsoft Windows XP [Version 5.1.2600]

Running From: C:\SDFix

Safe Mode:
Checking Services:

Restoring Windows Registry Values
Restoring Windows Default Hosts File
Restoring Default HomePage Value
Restoring Default Desktop Components Value

Rebooting...

Normal Mode:
Checking Files:

Trojan Files Found:

C:\Documents and Settings\Owner_Emachine\Desktop\Error Cleaner.url - Deleted
C:\Documents and Settings\Owner_Emachine\Favorites\Error Cleaner.url - Deleted
C:\Documents and Settings\Owner_Emachine\Desktop\Privacy Protector.url - Deleted
C:\Documents and Settings\Owner_Emachine\Favorites\Privacy Protector.url - Deleted
C:\Documents and Settings\Owner_Emachine\Desktop\Spyware&Malware Protection.url - Deleted
C:\Documents and Settings\Owner_Emachine\Favorites\Spyware&Malware Protection.url - Deleted
C:\WINDOWS\privacy_danger\index.htm - Deleted
C:\WINDOWS\privacy_danger\images\capt.gif - Deleted
C:\WINDOWS\privacy_danger\images\danger.jpg - Deleted
C:\WINDOWS\privacy_danger\images\down.gif - Deleted
C:\WINDOWS\privacy_danger\images\spacer.gif - Deleted
C:\Documents and Settings\Owner_Emachine\Start Menu\Programs\Startup\TA_Start.lnk - Deleted
C:\Program Files\VideoAccessCodec\install.ico - Deleted
C:\Program Files\VideoAccessCodec\Uninstall.exe - Deleted
C:\Program Files\VideoAccessCodec\VideoAccessCodec.ocx - Deleted
C:\WINDOWS\b122.exe - Deleted
C:\WINDOWS\dat.txt - Deleted
C:\WINDOWS\Downloaded Program Files\UWA7P_0001_N91M0809NetInstaller.exe - Deleted
C:\WINDOWS\msmdev.dll - Deleted
C:\WINDOWS\msmhost.dll - Deleted
C:\WINDOWS\nsduo.dll - Deleted
C:\WINDOWS\rs.txt - Deleted
C:\WINDOWS\search_res.txt - Deleted
C:\WINDOWS\TISKY009.exe - Deleted

Folder C:\Program Files\VideoAccessCodec - Removed
Folder C:\Temp\brr - Removed
Folder C:\Temp\fse - Removed
Folder C:\WINDOWS\privacy_danger - Removed
Folder C:\WINDOWS\system32\b02FdUe - Removed

Removing Temp Files...

ADS Check:

C:\WINDOWS
No streams found.

C:\WINDOWS\system32
No streams found.

C:\WINDOWS\system32\svchost.exe
No streams found.

C:\WINDOWS\system32\ntoskrnl.exe
No streams found.

Final Check:

Remaining Services:
------------------

Authorized Application Key Export:

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\standardprofile\authorizedapplications\list]
"%windir%\\system32\\sessmgr.exe"="%windir%\\system32\\sessmgr.exe:*:enabledxpsp2res.dll,-22019"
"C:\\Program Files\\Common Files\\AOL\\Loader\\aolload.exe"="C:\\Program Files\\Common Files\\AOL\\Loader\\aolload.exe:*:Enabled:AOL Application Loader"
"C:\\Program Files\\Common Files\\AOL\\ACS\\AOLDial.exe"="C:\\Program Files\\Common Files\\AOL\\ACS\\AOLDial.exe:*:Enabled:AOL"
"C:\\Program Files\\Common Files\\AOL\\ACS\\AOLacsd.exe"="C:\\Program Files\\Common Files\\AOL\\ACS\\AOLacsd.exe:*:Enabled:AOL"
"C:\\Program Files\\America Online 9.0\\waol.exe"="C:\\Program Files\\America Online 9.0\\waol.exe:*:Enabled:AOL"
"C:\\Program Files\\Common Files\\AOL\\TopSpeed\\2.0\\aoltsmon.exe"="C:\\Program Files\\Common Files\\AOL\\TopSpeed\\2.0\\aoltsmon.exe:*:Enabled:AOLTsMon"
"C:\\Program Files\\Common Files\\AOL\\TopSpeed\\2.0\\aoltpspd.exe"="C:\\Program Files\\Common Files\\AOL\\TopSpeed\\2.0\\aoltpspd.exe:*:Enabled:AOLTopSpeed"
"C:\\Program Files\\Common Files\\AOL\\1147794822\\EE\\AOLServiceHost.exe"="C:\\Program Files\\Common Files\\AOL\\1147794822\\EE\\AOLServiceHost.exe:*:Enabled:AOL"
"C:\\Program Files\\Common Files\\AOL\\System Information\\sinf.exe"="C:\\Program Files\\Common Files\\AOL\\System Information\\sinf.exe:*:Enabled:AOL"
"C:\\Program Files\\Common Files\\AOL\\AOL Spyware Protection\\AOLSP Scheduler.exe"="C:\\Program Files\\Common Files\\AOL\\AOL Spyware Protection\\AOLSP Scheduler.exe:*:Enabled:AOL"
"C:\\Program Files\\Common Files\\AOL\\AOL Spyware Protection\\asp.exe"="C:\\Program Files\\Common Files\\AOL\\AOL Spyware Protection\\asp.exe:*:Enabled:AOL"
"C:\\Program Files\\Common Files\\AolCoach\\en_en\\player\\AOLNySEV.exe"="C:\\Program Files\\Common Files\\AolCoach\\en_en\\player\\AOLNySEV.exe:*:Enabled:AOL"
"C:\\Program Files\\Yahoo!\\Messenger\\YPager.exe"="C:\\Program Files\\Yahoo!\\Messenger\\YPager.exe:*:Enabled:Yahoo! Messenger"
"C:\\Program Files\\Yahoo!\\Messenger\\YServer.exe"="C:\\Program Files\\Yahoo!\\Messenger\\YServer.exe:*:Enabled:Yahoo! FT Server"
"C:\\Program Files\\Yahoo!\\Yahoo! Music Jukebox\\YahooMusicEngine.exe"="C:\\Program Files\\Yahoo!\\Yahoo! Music Jukebox\\YahooMusicEngine.exe:*:Enabled:AT&T Yahoo! Music Jukebox"
"C:\\Program Files\\Yahoo!\\Messenger\\YahooMessenger.exe"="C:\\Program Files\\Yahoo!\\Messenger\\YahooMessenger.exe:*:Enabled:Yahoo! Messenger"
"C:\\Program Files\\LimeWire\\LimeWire.exe"="C:\\Program Files\\LimeWire\\LimeWire.exe:*:Enabled:LimeWire"

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\domainprofile\authorizedapplications\list]
"%windir%\\system32\\sessmgr.exe"="%windir%\\system32\\sessmgr.exe:*:enabledxpsp2res.dll,-22019"

Remaining Files:
---------------

File Backups: - C:\SDFix\backups\backups.zip

Files with Hidden Attributes:

Tue 31 Jul 2007 6,507 ..SH. --- "C:\WINDOWS\system32\oqstv.bak1"
Wed 1 Aug 2007 1,730,139 ..SH. --- "C:\WINDOWS\system32\oqstv.bak2"
Wed 18 Jul 2007 4,348 ..SH. --- "C:\Documents and Settings\All Users\DRM\DRMv1.bak"
Fri 27 Jul 2007 72 A..H. --- "C:\Program Files\InterActual\InterActual Player\iti241.tmp"
Wed 18 Jul 2007 4,348 ...H. --- "C:\Documents and Settings\Owner_Emachine\My Documents\My Music\License Backup\drmv1key.bak"
Sat 18 Aug 2007 20 A..H. --- "C:\Documents and Settings\Owner_Emachine\My Documents\My Music\License Backup\drmv1lic.bak"
Wed 18 Jul 2007 9,656 A.SH. --- "C:\Documents and Settings\Owner_Emachine\My Documents\My Music\License Backup\drmv2key.bak"

Finished! 
Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 5:01:08 PM, on 9/25/2007
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Yahoo!\Antivirus\ISafe.exe
C:\WINDOWS\system32\HPZipm12.exe
C:\Program Files\Common Files\New Boundary\PrismXL\PRISMXL.SYS
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe
C:\Program Files\Digital Media Reader\readericon45G.exe
C:\WINDOWS\RTHDCPL.EXE
C:\Program Files\HP\HP Software Update\HPWuSchd2.exe
C:\PROGRA~1\Yahoo!\browser\ybrwicon.exe
C:\PROGRA~1\SBCLIG~1\SMARTB~1\MotiveSB.exe
C:\Program Files\QuickTime\qttask.exe
C:\PROGRA~1\Yahoo!\YOP\yop.exe
C:\Program Files\Common Files\WinAntiSpyware 2007\uwas7cw.exe
C:\Program Files\Yahoo!\Antivirus\CAVTray.exe
C:\Program Files\Yahoo!\Antivirus\CAVRID.exe
C:\Program Files\Yahoo!\Search Protection\SearchProtection.exe
C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
C:\PROGRA~1\Yahoo!\browser\ycommon.exe
C:\Program Files\Messenger\msmsgs.exe
C:\WINDOWS\system32\wuauclt.exe
C:\Program Files\Internet Explorer\IEXPLORE.EXE
C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe
C:\Program Files\Nikon\PictureProject\NkbMonitor.exe
C:\Program Files\Yahoo!\Yahoo! Music Jukebox\ymetray.exe
C:\WINDOWS\system32\VirtualExpander\VirtualExpander.exe
C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe
C:\Program Files\Yahoo!\Messenger\ymsgr_tray.exe
C:\Program Files\HP\Digital Imaging\bin\hpqSTE08.exe
C:\Program Files\Yahoo!\Antivirus\VetMsg.exe
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe
C:\PROGRA~1\Yahoo!\YUM\yum.exe

R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.gateway.com/g/startpage.html?Ch=Retail&Br=EM&Loc=ENG_US&Sys=DTP&M=T3508
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar = http://red.clientapps.yahoo.com/cus.../sbcydsl/*http://www.yahoo.com/search/ie.html
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://red.clientapps.yahoo.com/customize/ie/defaults/sp/sbcydsl/*http://www.yahoo.com
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.gateway.com/g/startpage.html?Ch=Retail&Br=EM&Loc=ENG_US&Sys=DTP&M=T3508
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = 127.0.0.1;<local>
R3 - URLSearchHook: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn1\yt.dll
O2 - BHO: &Yahoo! Toolbar Helper - {02478D38-C3F9-4EFB-9B51-7695ECA05670} - C:\Program Files\Yahoo!\Companion\Installs\cpn1\yt.dll
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
O2 - BHO: (no name) - {0C9D3A87-7FEF-462E-ADB8-C94DFF4D6B9B} - C:\Program Files\Internet Explorer\meqosadil83122.dll (file missing)
O2 - BHO: (no name) - {3964D8D6-86D0-493A-B460-A805B5401114} - C:\WINDOWS\system32\ljjgdax.dll (file missing)
O2 - BHO: Yahoo! IE Services Button - {5BAB4B5B-68BC-4B02-94D6-2FC0DE4A7897} - C:\PROGRA~1\Yahoo!\common\yiesrvc.dll
O2 - BHO: (no name) - {68867113-056C-43A4-807A-9C0B0C0A57F8} - C:\WINDOWS\system32\vtsqo.dll (file missing)
O2 - BHO: 0 - {69F4671A-1407-4D07-D485-5DA6C85BCFAB} - C:\Program Files\Online Services\qucam.dll (file missing)
O2 - BHO: (no name) - {76394256-0838-46B1-A319-D59FFC795843} - \
O2 - BHO: (no name) - {7D8ED76A-B6E6-4345-8AC8-47B1349DFCDC} - \
O2 - BHO: (no name) - {8941F9B8-6EC9-4BAE-A30F-BC3764FBBA3B} - \
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar2.dll
O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\2.0.301.7164\swg.dll
O2 - BHO: (no name) - {C6039E6C-BDE9-4de5-BB40-768CAA584FDC} - C:\WINDOWS\system32\wtmfmill.dll (file missing)
O2 - BHO: (no name) - {C6907F56-4510-401B-BCB0-06118FC61C8D} - \
O2 - BHO: CBrowserHelperObject Object - {CA6319C0-31B7-401E-A518-A07C3DB8F777} - c:\windows\system32\BAE.dll
O2 - BHO: SidebarAutoLaunch Class - {F2AA9440-6328-4933-B7C9-A6CCDF9CBF6D} - C:\Program Files\Yahoo!\browser\YSidebarIEBHO.dll
O2 - BHO: Flash8.ocx - {F52A94F5-A3CC-40DA-BCD7-222282E01406} - C:\WINDOWS\system32\driver\inf\mshtm.dll
O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar2.dll
O3 - Toolbar: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn1\yt.dll
O4 - HKLM\..\Run: [Google Desktop Search] "C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe" /startup
O4 - HKLM\..\Run: [readericon] C:\Program Files\Digital Media Reader\readericon45G.exe
O4 - HKLM\..\Run: [RTHDCPL] RTHDCPL.EXE
O4 - HKLM\..\Run: [Alcmtr] ALCMTR.EXE
O4 - HKLM\..\Run: [Recguard] %WINDIR%\SMINST\RECGUARD.EXE
O4 - HKLM\..\Run: [HP Software Update] C:\Program Files\HP\HP Software Update\HPWuSchd2.exe
O4 - HKLM\..\Run: [YBrowser] C:\PROGRA~1\Yahoo!\browser\ybrwicon.exe
O4 - HKLM\..\Run: [Motive SmartBridge] C:\PROGRA~1\SBCLIG~1\SMARTB~1\MotiveSB.exe
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [YOP] C:\PROGRA~1\Yahoo!\YOP\yop.exe /autostart
O4 - HKLM\..\Run: [{ZN}] C:\WINDOWS\TISKY009.exe SKY009
O4 - HKLM\..\Run: [uwas7cw] "C:\Program Files\Common Files\WinAntiSpyware 2007\uwas7cw.exe" -c
O4 - HKLM\..\Run: [CaAvTray] "C:\Program Files\Yahoo!\Antivirus\CAVTray.exe"
O4 - HKLM\..\Run: [CAVRID] "C:\Program Files\Yahoo!\Antivirus\CAVRID.exe"
O4 - HKLM\..\Run: [YSearchProtection] "C:\Program Files\Yahoo!\Search Protection\SearchProtection.exe"
O4 - HKCU\..\Run: [swg] C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
O4 - HKCU\..\Run: [Yahoo! Pager] "C:\Program Files\Yahoo!\Messenger\YahooMessenger.exe" -quiet
O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
O4 - HKCU\..\Run: [AROReminder] C:\Program Files\Advanced Registry Optimizer\aro.exe -rem
O4 - HKCU\..\Run: [YSearchProtection] C:\Program Files\Yahoo!\Search Protection\SearchProtection.exe
O4 - HKUS\S-1-5-18\..\Run: [Power2GoExpress] NA (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [Power2GoExpress] NA (User 'Default user')
O4 - Startup: .protected
O4 - Startup: VirtualExpander.lnk = C:\WINDOWS\system32\VirtualExpander\VirtualExpander.exe
O4 - Global Startup: .protected
O4 - Global Startup: HP Digital Imaging Monitor.lnk = C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe
O4 - Global Startup: NkbMonitor.exe.lnk = C:\Program Files\Nikon\PictureProject\NkbMonitor.exe
O4 - Global Startup: ymetray.lnk = C:\Program Files\Yahoo!\Yahoo! Music Jukebox\ymetray.exe
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
O9 - Extra button: AT&T Yahoo! Services - {5BAB4B5B-68BC-4B02-94D6-2FC0DE4A7897} - C:\PROGRA~1\Yahoo!\common\yiesrvc.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL
O9 - Extra button: Real.com - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - C:\WINDOWS\system32\Shdocvw.dll
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O16 - DPF: {30528230-99f7-4bb4-88d8-fa1d4f56a2ab} (Installation Support) - C:\Program Files\Yahoo!\Common\Yinsthelper2007261.dll
O16 - DPF: {77E32299-629F-43C6-AB77-6A1E6D7663F6} (Groove Control) - http://www.nick.com/common/groove/gx/GrooveAX27.cab
O16 - DPF: {8A0DCBDB-6E20-489C-9041-C1E8A0352E75} (Mirar_Dummy_ATS1 Class) - http://awbeta.net-nucleus.com/FIX/WinATS.cab
O16 - DPF: {BB383206-6DA1-4E80-B62A-3DF950FCC697} (Create & Print ActiveX Plug-in) - http://ak.imgag.com/imgag/cp/install/AxCtp2.cab
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - https://fpdownload.macromedia.com/pub/shockwave/cabs/flash/swflash.cab
O20 - AppInit_DLLs: C:\PROGRA~1\Google\GOOGLE~1\GOEC62~1.DLL
O20 - Winlogon Notify: ljjgdax - ljjgdax.dll (file missing)
O20 - Winlogon Notify: vtsqo - C:\WINDOWS\system32\vtsqo.dll (file missing)
O23 - Service: Ati HotKey Poller - ATI Technologies Inc. - C:\WINDOWS\system32\Ati2evxx.exe
O23 - Service: ATI Smart - Unknown owner - C:\WINDOWS\system32\ati2sgag.exe
O23 - Service: CAISafe - Computer Associates International, Inc. - C:\Program Files\Yahoo!\Antivirus\ISafe.exe
O23 - Service: GoogleDesktopManager - Google - C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe
O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: Pml Driver HPZ12 - HP - C:\WINDOWS\system32\HPZipm12.exe
O23 - Service: PrismXL - New Boundary Technologies, Inc. - C:\Program Files\Common Files\New Boundary\PrismXL\PRISMXL.SYS
O23 - Service: VET Message Service (VETMSGNT) - Computer Associates International, Inc. - C:\Program Files\Yahoo!\Antivirus\VetMsg.exe
O23 - Service: YPCService - Yahoo! Inc. - C:\WINDOWS\system32\YPCSER~1.EXE

--
End of file - 9873 bytes


----------



## MFDnNC (Sep 7, 2004)

Keep going - DO ALL of what I posted


----------



## cpuanswers (Sep 25, 2007)

the one for the combofix is too long it says it is 146658 characters long


----------



## MFDnNC (Sep 7, 2004)

POST A REPLY - scroll down to manage attachments - attach the file


----------



## cpuanswers (Sep 25, 2007)

ComboFix 07-09-26 - Owner_Emachine 2007-09-25 17:05:24.1 - NTFSx86 
Microsoft Windows XP Home Edition 5.1.2600.2.1252.1.1033.18.107 [GMT -7:00]
Running from: C:\Documents and Settings\Owner_Emachine\Desktop\ComboFix.exe
* Created a new restore point
.

((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.

C:\.protected
C:\Documents and Settings\All Users\Application Data.\salesmonitor
C:\Documents and Settings\All Users\Application Data.\winantispyware 2007
C:\Documents and Settings\All Users\Application Data.\winantispyware 2007\Data\Abbr
C:\Documents and Settings\All Users\Application Data.\winantispyware 2007\Data\ProductCode
C:\Documents and Settings\All Users\Application Data\WinAntiSpyware 2007\Data\Abbr
C:\Documents and Settings\All Users\Application Data\WinAntiSpyware 2007\Data\ProductCode
C:\Documents and Settings\All Users\Start Menu\Programs\Startup\.protected
C:\Documents and Settings\Owner_Emachine\Application Data\WinAntiSpyware 2007
C:\Documents and Settings\Owner_Emachine\Application Data\WinAntiSpyware 2007 Free
C:\Documents and Settings\Owner_Emachine\Application Data\WinAntiSpyware 2007 Free\DownloadUWAS7.url
C:\Documents and Settings\Owner_Emachine\Application Data\WinAntiSpyware 2007\Logs\update.log
C:\Documents and Settings\Owner_Emachine\err.log
C:\Documents and Settings\Owner_Emachine\Start Menu\Programs\Startup\.protected
C:\Program Files\Common Files\ssembl~1
C:\Program Files\Common Files\winantispyware 2007
C:\Program Files\Common Files\winantispyware 2007\err.log
C:\Program Files\Common Files\winantispyware 2007\uwas7cw.exe
C:\Program Files\FunWebProducts
C:\Program Files\Ultimate Defender
C:\temp\0c2
C:\temp\0c2\tmpFF.log
C:\Temp\1cb
C:\Temp\1cb\syscheck.log
C:\WINDOWS\.protected
C:\WINDOWS\~tmp0.exe
C:\WINDOWS\~tmp100.exe
C:\WINDOWS\~tmp1000.exe
C:\WINDOWS\~tmp1001.exe
C:\WINDOWS\~tmp1002.exe
C:\WINDOWS\~tmp1004.exe
C:\WINDOWS\~tmp1005.exe
C:\WINDOWS\~tmp1006.exe
C:\WINDOWS\~tmp1007.exe
C:\WINDOWS\~tmp1009.exe
C:\WINDOWS\~tmp1010.exe
C:\WINDOWS\~tmp1012.exe
C:\WINDOWS\~tmp1014.exe
C:\WINDOWS\~tmp1015.exe
C:\WINDOWS\~tmp1017.exe
C:\WINDOWS\~tmp1019.exe
C:\WINDOWS\~tmp1020.exe
C:\WINDOWS\~tmp1021.exe
C:\WINDOWS\~tmp1024.exe
C:\WINDOWS\~tmp1025.exe
C:\WINDOWS\~tmp1026.exe
C:\WINDOWS\~tmp1029.exe
C:\WINDOWS\~tmp103.exe
C:\WINDOWS\~tmp1030.exe
C:\WINDOWS\~tmp1031.exe
C:\WINDOWS\~tmp1032.exe
C:\WINDOWS\~tmp1035.exe
C:\WINDOWS\~tmp1037.exe
C:\WINDOWS\~tmp1038.exe
C:\WINDOWS\~tmp1039.exe
C:\WINDOWS\~tmp104.exe
C:\WINDOWS\~tmp1041.exe
C:\WINDOWS\~tmp1042.exe
C:\WINDOWS\~tmp1043.exe
C:\WINDOWS\~tmp1044.exe
C:\WINDOWS\~tmp1045.exe
C:\WINDOWS\~tmp1046.exe
C:\WINDOWS\~tmp1048.exe
C:\WINDOWS\~tmp105.exe
C:\WINDOWS\~tmp1050.exe
C:\WINDOWS\~tmp1051.exe
C:\WINDOWS\~tmp1056.exe
C:\WINDOWS\~tmp1057.exe
C:\WINDOWS\~tmp1058.exe
C:\WINDOWS\~tmp1059.exe
C:\WINDOWS\~tmp106.exe
C:\WINDOWS\~tmp1060.exe
C:\WINDOWS\~tmp1063.exe
C:\WINDOWS\~tmp1064.exe
C:\WINDOWS\~tmp1066.exe
C:\WINDOWS\~tmp1067.exe
C:\WINDOWS\~tmp1068.exe
C:\WINDOWS\~tmp1069.exe
C:\WINDOWS\~tmp107.exe
C:\WINDOWS\~tmp1070.exe
C:\WINDOWS\~tmp1071.exe
C:\WINDOWS\~tmp1073.exe
C:\WINDOWS\~tmp1075.exe
C:\WINDOWS\~tmp1076.exe
C:\WINDOWS\~tmp1078.exe
C:\WINDOWS\~tmp1079.exe
C:\WINDOWS\~tmp1080.exe
C:\WINDOWS\~tmp1082.exe
C:\WINDOWS\~tmp1084.exe
C:\WINDOWS\~tmp1088.exe
C:\WINDOWS\~tmp1089.exe
C:\WINDOWS\~tmp109.exe
C:\WINDOWS\~tmp1090.exe
C:\WINDOWS\~tmp1091.exe
C:\WINDOWS\~tmp1094.exe
C:\WINDOWS\~tmp1095.exe
C:\WINDOWS\~tmp1096.exe
C:\WINDOWS\~tmp1097.exe
C:\WINDOWS\~tmp1099.exe
C:\WINDOWS\~tmp11.exe
C:\WINDOWS\~tmp1100.exe
C:\WINDOWS\~tmp1102.exe
C:\WINDOWS\~tmp1103.exe
C:\WINDOWS\~tmp1104.exe
C:\WINDOWS\~tmp1105.exe
C:\WINDOWS\~tmp1106.exe
C:\WINDOWS\~tmp1109.exe
C:\WINDOWS\~tmp111.exe
C:\WINDOWS\~tmp1111.exe
C:\WINDOWS\~tmp1114.exe
C:\WINDOWS\~tmp1116.exe
C:\WINDOWS\~tmp1118.exe
C:\WINDOWS\~tmp1120.exe
C:\WINDOWS\~tmp1121.exe
C:\WINDOWS\~tmp1122.exe
C:\WINDOWS\~tmp1124.exe
C:\WINDOWS\~tmp1126.exe
C:\WINDOWS\~tmp113.exe
C:\WINDOWS\~tmp1130.exe
C:\WINDOWS\~tmp1133.exe
C:\WINDOWS\~tmp1134.exe
C:\WINDOWS\~tmp1139.exe
C:\WINDOWS\~tmp114.exe
C:\WINDOWS\~tmp1140.exe
C:\WINDOWS\~tmp1146.exe
C:\WINDOWS\~tmp1147.exe
C:\WINDOWS\~tmp1148.exe
C:\WINDOWS\~tmp1150.exe
C:\WINDOWS\~tmp1153.exe
C:\WINDOWS\~tmp1154.exe
C:\WINDOWS\~tmp1158.exe
C:\WINDOWS\~tmp1159.exe
C:\WINDOWS\~tmp1163.exe
C:\WINDOWS\~tmp1164.exe
C:\WINDOWS\~tmp1165.exe
C:\WINDOWS\~tmp1166.exe
C:\WINDOWS\~tmp1168.exe
C:\WINDOWS\~tmp1170.exe
C:\WINDOWS\~tmp1174.exe
C:\WINDOWS\~tmp1177.exe
C:\WINDOWS\~tmp1178.exe
C:\WINDOWS\~tmp118.exe
C:\WINDOWS\~tmp1180.exe
C:\WINDOWS\~tmp1181.exe
C:\WINDOWS\~tmp1183.exe
C:\WINDOWS\~tmp1184.exe
C:\WINDOWS\~tmp1188.exe
C:\WINDOWS\~tmp1189.exe
C:\WINDOWS\~tmp119.exe
C:\WINDOWS\~tmp1191.exe
C:\WINDOWS\~tmp1192.exe
C:\WINDOWS\~tmp1193.exe
C:\WINDOWS\~tmp1194.exe
C:\WINDOWS\~tmp1195.exe
C:\WINDOWS\~tmp1197.exe
C:\WINDOWS\~tmp120.exe
C:\WINDOWS\~tmp1200.exe
C:\WINDOWS\~tmp1202.exe
C:\WINDOWS\~tmp1205.exe
C:\WINDOWS\~tmp1206.exe
C:\WINDOWS\~tmp1207.exe
C:\WINDOWS\~tmp1212.exe
C:\WINDOWS\~tmp1213.exe
C:\WINDOWS\~tmp1214.exe
C:\WINDOWS\~tmp1215.exe
C:\WINDOWS\~tmp1216.exe
C:\WINDOWS\~tmp1217.exe
C:\WINDOWS\~tmp1218.exe
C:\WINDOWS\~tmp1219.exe
C:\WINDOWS\~tmp1221.exe
C:\WINDOWS\~tmp1222.exe
C:\WINDOWS\~tmp1223.exe
C:\WINDOWS\~tmp1224.exe
C:\WINDOWS\~tmp1226.exe
C:\WINDOWS\~tmp1227.exe
C:\WINDOWS\~tmp1228.exe
C:\WINDOWS\~tmp123.exe
C:\WINDOWS\~tmp1233.exe
C:\WINDOWS\~tmp1235.exe
C:\WINDOWS\~tmp1236.exe
C:\WINDOWS\~tmp1238.exe
C:\WINDOWS\~tmp1239.exe
C:\WINDOWS\~tmp124.exe
C:\WINDOWS\~tmp1240.exe
C:\WINDOWS\~tmp1242.exe
C:\WINDOWS\~tmp1243.exe
C:\WINDOWS\~tmp1245.exe
C:\WINDOWS\~tmp1246.exe
C:\WINDOWS\~tmp1247.exe
C:\WINDOWS\~tmp1248.exe
C:\WINDOWS\~tmp1250.exe
C:\WINDOWS\~tmp1252.exe
C:\WINDOWS\~tmp1253.exe
C:\WINDOWS\~tmp1256.exe
C:\WINDOWS\~tmp1258.exe
C:\WINDOWS\~tmp1259.exe
C:\WINDOWS\~tmp126.exe
C:\WINDOWS\~tmp1260.exe
C:\WINDOWS\~tmp1262.exe
C:\WINDOWS\~tmp1263.exe
C:\WINDOWS\~tmp1264.exe
C:\WINDOWS\~tmp1266.exe
C:\WINDOWS\~tmp127.exe
C:\WINDOWS\~tmp1272.exe
C:\WINDOWS\~tmp1273.exe
C:\WINDOWS\~tmp1277.exe
C:\WINDOWS\~tmp1278.exe
C:\WINDOWS\~tmp1279.exe
C:\WINDOWS\~tmp1281.exe
C:\WINDOWS\~tmp1286.exe
C:\WINDOWS\~tmp1288.exe
C:\WINDOWS\~tmp1289.exe
C:\WINDOWS\~tmp1290.exe
C:\WINDOWS\~tmp1293.exe
C:\WINDOWS\~tmp1295.exe
C:\WINDOWS\~tmp1296.exe
C:\WINDOWS\~tmp1300.exe
C:\WINDOWS\~tmp1304.exe
C:\WINDOWS\~tmp1306.exe
C:\WINDOWS\~tmp1308.exe
C:\WINDOWS\~tmp131.exe
C:\WINDOWS\~tmp1310.exe
C:\WINDOWS\~tmp1314.exe
C:\WINDOWS\~tmp1315.exe
C:\WINDOWS\~tmp1317.exe
C:\WINDOWS\~tmp1319.exe
C:\WINDOWS\~tmp132.exe
C:\WINDOWS\~tmp1320.exe
C:\WINDOWS\~tmp1324.exe
C:\WINDOWS\~tmp1325.exe
C:\WINDOWS\~tmp1326.exe
C:\WINDOWS\~tmp1329.exe
C:\WINDOWS\~tmp1334.exe
C:\WINDOWS\~tmp1337.exe
C:\WINDOWS\~tmp1340.exe
C:\WINDOWS\~tmp1341.exe
C:\WINDOWS\~tmp1342.exe
C:\WINDOWS\~tmp1344.exe
C:\WINDOWS\~tmp1346.exe
C:\WINDOWS\~tmp1348.exe
C:\WINDOWS\~tmp135.exe
C:\WINDOWS\~tmp1351.exe
C:\WINDOWS\~tmp1352.exe
C:\WINDOWS\~tmp1353.exe
C:\WINDOWS\~tmp1355.exe
C:\WINDOWS\~tmp1356.exe
C:\WINDOWS\~tmp1357.exe
C:\WINDOWS\~tmp1361.exe
C:\WINDOWS\~tmp1362.exe
C:\WINDOWS\~tmp1363.exe
C:\WINDOWS\~tmp1364.exe
C:\WINDOWS\~tmp1365.exe
C:\WINDOWS\~tmp1366.exe
C:\WINDOWS\~tmp1371.exe
C:\WINDOWS\~tmp1375.exe
C:\WINDOWS\~tmp1377.exe
C:\WINDOWS\~tmp1383.exe
C:\WINDOWS\~tmp1384.exe
C:\WINDOWS\~tmp1386.exe
C:\WINDOWS\~tmp1393.exe
C:\WINDOWS\~tmp1395.exe
C:\WINDOWS\~tmp1396.exe
C:\WINDOWS\~tmp1398.exe
C:\WINDOWS\~tmp14.exe
C:\WINDOWS\~tmp1406.exe
C:\WINDOWS\~tmp1407.exe
C:\WINDOWS\~tmp1408.exe
C:\WINDOWS\~tmp1409.exe
C:\WINDOWS\~tmp1410.exe
C:\WINDOWS\~tmp1411.exe
C:\WINDOWS\~tmp1412.exe
C:\WINDOWS\~tmp1415.exe
C:\WINDOWS\~tmp1416.exe
C:\WINDOWS\~tmp142.exe
C:\WINDOWS\~tmp1421.exe
C:\WINDOWS\~tmp1422.exe
C:\WINDOWS\~tmp1423.exe
C:\WINDOWS\~tmp1426.exe
C:\WINDOWS\~tmp1430.exe
C:\WINDOWS\~tmp1431.exe
C:\WINDOWS\~tmp1432.exe
C:\WINDOWS\~tmp1433.exe
C:\WINDOWS\~tmp1434.exe
C:\WINDOWS\~tmp1435.exe
C:\WINDOWS\~tmp1436.exe
C:\WINDOWS\~tmp1437.exe
C:\WINDOWS\~tmp1438.exe
C:\WINDOWS\~tmp1439.exe
C:\WINDOWS\~tmp1440.exe
C:\WINDOWS\~tmp1441.exe
C:\WINDOWS\~tmp1442.exe
C:\WINDOWS\~tmp1444.exe
C:\WINDOWS\~tmp1445.exe
C:\WINDOWS\~tmp1448.exe
C:\WINDOWS\~tmp1452.exe
C:\WINDOWS\~tmp1454.exe
C:\WINDOWS\~tmp1455.exe
C:\WINDOWS\~tmp1456.exe
C:\WINDOWS\~tmp1457.exe
C:\WINDOWS\~tmp146.exe
C:\WINDOWS\~tmp1462.exe
C:\WINDOWS\~tmp1463.exe
C:\WINDOWS\~tmp1464.exe
C:\WINDOWS\~tmp1465.exe
C:\WINDOWS\~tmp1466.exe
C:\WINDOWS\~tmp1467.exe
C:\WINDOWS\~tmp147.exe
C:\WINDOWS\~tmp1470.exe
C:\WINDOWS\~tmp1471.exe
C:\WINDOWS\~tmp1472.exe
C:\WINDOWS\~tmp1473.exe
C:\WINDOWS\~tmp1474.exe
C:\WINDOWS\~tmp1476.exe
C:\WINDOWS\~tmp1477.exe
C:\WINDOWS\~tmp1478.exe
C:\WINDOWS\~tmp1479.exe
C:\WINDOWS\~tmp1480.exe
C:\WINDOWS\~tmp1485.exe
C:\WINDOWS\~tmp1487.exe
C:\WINDOWS\~tmp1489.exe
C:\WINDOWS\~tmp1490.exe
C:\WINDOWS\~tmp1491.exe
C:\WINDOWS\~tmp1492.exe
C:\WINDOWS\~tmp1493.exe
C:\WINDOWS\~tmp1494.exe
C:\WINDOWS\~tmp1499.exe
C:\WINDOWS\~tmp150.exe
C:\WINDOWS\~tmp1500.exe
C:\WINDOWS\~tmp1501.exe
C:\WINDOWS\~tmp1503.exe
C:\WINDOWS\~tmp1504.exe
C:\WINDOWS\~tmp1505.exe
C:\WINDOWS\~tmp1506.exe
C:\WINDOWS\~tmp1507.exe
C:\WINDOWS\~tmp1508.exe
C:\WINDOWS\~tmp151.exe
C:\WINDOWS\~tmp1510.exe
C:\WINDOWS\~tmp1514.exe
C:\WINDOWS\~tmp1516.exe
C:\WINDOWS\~tmp1517.exe
C:\WINDOWS\~tmp1518.exe
C:\WINDOWS\~tmp152.exe
C:\WINDOWS\~tmp1520.exe
C:\WINDOWS\~tmp1521.exe
C:\WINDOWS\~tmp1522.exe
C:\WINDOWS\~tmp1523.exe
C:\WINDOWS\~tmp1524.exe
C:\WINDOWS\~tmp1525.exe
C:\WINDOWS\~tmp1526.exe
C:\WINDOWS\~tmp1530.exe
C:\WINDOWS\~tmp1531.exe
C:\WINDOWS\~tmp1532.exe
C:\WINDOWS\~tmp1533.exe
C:\WINDOWS\~tmp1535.exe
C:\WINDOWS\~tmp1536.exe
C:\WINDOWS\~tmp1539.exe
C:\WINDOWS\~tmp1542.exe
C:\WINDOWS\~tmp1543.exe
C:\WINDOWS\~tmp1545.exe
C:\WINDOWS\~tmp1546.exe
C:\WINDOWS\~tmp1547.exe
C:\WINDOWS\~tmp155.exe
C:\WINDOWS\~tmp1552.exe
C:\WINDOWS\~tmp1553.exe
C:\WINDOWS\~tmp1557.exe
C:\WINDOWS\~tmp1562.exe
C:\WINDOWS\~tmp1563.exe
C:\WINDOWS\~tmp1564.exe
C:\WINDOWS\~tmp1566.exe
C:\WINDOWS\~tmp1567.exe
C:\WINDOWS\~tmp1573.exe
C:\WINDOWS\~tmp1576.exe
C:\WINDOWS\~tmp1577.exe
C:\WINDOWS\~tmp158.exe
C:\WINDOWS\~tmp1580.exe
C:\WINDOWS\~tmp1581.exe
C:\WINDOWS\~tmp1582.exe
C:\WINDOWS\~tmp1583.exe
C:\WINDOWS\~tmp1585.exe
C:\WINDOWS\~tmp1586.exe
C:\WINDOWS\~tmp1588.exe
C:\WINDOWS\~tmp159.exe
C:\WINDOWS\~tmp1590.exe
C:\WINDOWS\~tmp1592.exe
C:\WINDOWS\~tmp1593.exe
C:\WINDOWS\~tmp1595.exe
C:\WINDOWS\~tmp1597.exe
C:\WINDOWS\~tmp16.exe
C:\WINDOWS\~tmp1600.exe
C:\WINDOWS\~tmp1601.exe
C:\WINDOWS\~tmp1602.exe
C:\WINDOWS\~tmp1604.exe
C:\WINDOWS\~tmp1605.exe
C:\WINDOWS\~tmp1607.exe
C:\WINDOWS\~tmp1608.exe
C:\WINDOWS\~tmp1610.exe
C:\WINDOWS\~tmp1611.exe
C:\WINDOWS\~tmp1613.exe
C:\WINDOWS\~tmp1615.exe
C:\WINDOWS\~tmp1617.exe
C:\WINDOWS\~tmp1618.exe
C:\WINDOWS\~tmp1619.exe
C:\WINDOWS\~tmp162.exe
C:\WINDOWS\~tmp1620.exe
C:\WINDOWS\~tmp1621.exe
C:\WINDOWS\~tmp1622.exe
C:\WINDOWS\~tmp1624.exe
C:\WINDOWS\~tmp1626.exe
C:\WINDOWS\~tmp1627.exe
C:\WINDOWS\~tmp1628.exe
C:\WINDOWS\~tmp1629.exe
C:\WINDOWS\~tmp163.exe
C:\WINDOWS\~tmp1630.exe
C:\WINDOWS\~tmp1631.exe
C:\WINDOWS\~tmp1633.exe
C:\WINDOWS\~tmp1634.exe
C:\WINDOWS\~tmp1635.exe
C:\WINDOWS\~tmp1636.exe
C:\WINDOWS\~tmp1639.exe
C:\WINDOWS\~tmp164.exe
C:\WINDOWS\~tmp1642.exe
C:\WINDOWS\~tmp1643.exe
C:\WINDOWS\~tmp1648.exe
C:\WINDOWS\~tmp165.exe
C:\WINDOWS\~tmp1652.exe
C:\WINDOWS\~tmp1654.exe
C:\WINDOWS\~tmp1657.exe
C:\WINDOWS\~tmp1658.exe
C:\WINDOWS\~tmp1660.exe
C:\WINDOWS\~tmp1661.exe
C:\WINDOWS\~tmp1662.exe
C:\WINDOWS\~tmp1663.exe
C:\WINDOWS\~tmp1668.exe
C:\WINDOWS\~tmp1669.exe
C:\WINDOWS\~tmp1672.exe
C:\WINDOWS\~tmp1675.exe
C:\WINDOWS\~tmp1677.exe
C:\WINDOWS\~tmp1678.exe
C:\WINDOWS\~tmp1679.exe
C:\WINDOWS\~tmp1680.exe
C:\WINDOWS\~tmp1682.exe
C:\WINDOWS\~tmp1683.exe
C:\WINDOWS\~tmp1685.exe
C:\WINDOWS\~tmp1686.exe
C:\WINDOWS\~tmp1687.exe
C:\WINDOWS\~tmp1688.exe
C:\WINDOWS\~tmp1689.exe
C:\WINDOWS\~tmp1690.exe
C:\WINDOWS\~tmp1698.exe
C:\WINDOWS\~tmp1699.exe
C:\WINDOWS\~tmp17.exe
C:\WINDOWS\~tmp170.exe
C:\WINDOWS\~tmp1700.exe
C:\WINDOWS\~tmp1702.exe
C:\WINDOWS\~tmp1703.exe
C:\WINDOWS\~tmp1705.exe
C:\WINDOWS\~tmp1706.exe
C:\WINDOWS\~tmp1708.exe
C:\WINDOWS\~tmp171.exe
C:\WINDOWS\~tmp1710.exe
C:\WINDOWS\~tmp1712.exe
C:\WINDOWS\~tmp1714.exe
C:\WINDOWS\~tmp1715.exe
C:\WINDOWS\~tmp1716.exe
C:\WINDOWS\~tmp1718.exe
C:\WINDOWS\~tmp1720.exe
C:\WINDOWS\~tmp1721.exe
C:\WINDOWS\~tmp1722.exe
C:\WINDOWS\~tmp1724.exe
C:\WINDOWS\~tmp1725.exe
C:\WINDOWS\~tmp1726.exe
C:\WINDOWS\~tmp1729.exe
C:\WINDOWS\~tmp173.exe
C:\WINDOWS\~tmp1731.exe
C:\WINDOWS\~tmp1732.exe
C:\WINDOWS\~tmp1735.exe
C:\WINDOWS\~tmp1736.exe
C:\WINDOWS\~tmp1737.exe
C:\WINDOWS\~tmp1738.exe
C:\WINDOWS\~tmp1739.exe
C:\WINDOWS\~tmp1740.exe
C:\WINDOWS\~tmp1741.exe
C:\WINDOWS\~tmp1742.exe
C:\WINDOWS\~tmp1745.exe
C:\WINDOWS\~tmp1746.exe
C:\WINDOWS\~tmp1747.exe
C:\WINDOWS\~tmp1748.exe
C:\WINDOWS\~tmp1749.exe
C:\WINDOWS\~tmp1750.exe
C:\WINDOWS\~tmp1756.exe
C:\WINDOWS\~tmp1757.exe
C:\WINDOWS\~tmp1758.exe
C:\WINDOWS\~tmp1759.exe
C:\WINDOWS\~tmp176.exe
C:\WINDOWS\~tmp1760.exe
C:\WINDOWS\~tmp1761.exe
C:\WINDOWS\~tmp1763.exe
C:\WINDOWS\~tmp1766.exe
C:\WINDOWS\~tmp1768.exe
C:\WINDOWS\~tmp1770.exe
C:\WINDOWS\~tmp1772.exe
C:\WINDOWS\~tmp1773.exe
C:\WINDOWS\~tmp1774.exe
C:\WINDOWS\~tmp1775.exe
C:\WINDOWS\~tmp1776.exe
C:\WINDOWS\~tmp1777.exe
C:\WINDOWS\~tmp1779.exe
C:\WINDOWS\~tmp1782.exe
C:\WINDOWS\~tmp1785.exe
C:\WINDOWS\~tmp1788.exe
C:\WINDOWS\~tmp179.exe
C:\WINDOWS\~tmp1790.exe
C:\WINDOWS\~tmp1791.exe
C:\WINDOWS\~tmp1794.exe
C:\WINDOWS\~tmp1798.exe
C:\WINDOWS\~tmp180.exe
C:\WINDOWS\~tmp1802.exe
C:\WINDOWS\~tmp1803.exe
C:\WINDOWS\~tmp1804.exe
C:\WINDOWS\~tmp1805.exe
C:\WINDOWS\~tmp1806.exe
C:\WINDOWS\~tmp1807.exe
C:\WINDOWS\~tmp1810.exe
C:\WINDOWS\~tmp1811.exe
C:\WINDOWS\~tmp1812.exe
C:\WINDOWS\~tmp1813.exe
C:\WINDOWS\~tmp1814.exe
C:\WINDOWS\~tmp1819.exe
C:\WINDOWS\~tmp1820.exe
C:\WINDOWS\~tmp1823.exe
C:\WINDOWS\~tmp1825.exe
C:\WINDOWS\~tmp1827.exe
C:\WINDOWS\~tmp1828.exe
C:\WINDOWS\~tmp1829.exe
C:\WINDOWS\~tmp183.exe
C:\WINDOWS\~tmp1832.exe
C:\WINDOWS\~tmp1834.exe
C:\WINDOWS\~tmp1836.exe
C:\WINDOWS\~tmp1837.exe
C:\WINDOWS\~tmp1838.exe
C:\WINDOWS\~tmp184.exe
C:\WINDOWS\~tmp1840.exe
C:\WINDOWS\~tmp1842.exe
C:\WINDOWS\~tmp1843.exe
C:\WINDOWS\~tmp1844.exe
C:\WINDOWS\~tmp1846.exe
C:\WINDOWS\~tmp1847.exe
C:\WINDOWS\~tmp1848.exe
C:\WINDOWS\~tmp1849.exe
C:\WINDOWS\~tmp1852.exe
C:\WINDOWS\~tmp1853.exe
C:\WINDOWS\~tmp1856.exe
C:\WINDOWS\~tmp1857.exe
C:\WINDOWS\~tmp186.exe
C:\WINDOWS\~tmp1860.exe
C:\WINDOWS\~tmp187.exe
C:\WINDOWS\~tmp1870.exe
C:\WINDOWS\~tmp1873.exe
C:\WINDOWS\~tmp1875.exe
C:\WINDOWS\~tmp1877.exe
C:\WINDOWS\~tmp1879.exe
C:\WINDOWS\~tmp1880.exe
C:\WINDOWS\~tmp1881.exe
C:\WINDOWS\~tmp1882.exe
C:\WINDOWS\~tmp1888.exe
C:\WINDOWS\~tmp1889.exe
C:\WINDOWS\~tmp1890.exe
C:\WINDOWS\~tmp1891.exe
C:\WINDOWS\~tmp1895.exe
C:\WINDOWS\~tmp1899.exe
C:\WINDOWS\~tmp19.exe
C:\WINDOWS\~tmp190.exe
C:\WINDOWS\~tmp1902.exe
C:\WINDOWS\~tmp1911.exe
C:\WINDOWS\~tmp1914.exe
C:\WINDOWS\~tmp1915.exe
C:\WINDOWS\~tmp1916.exe
C:\WINDOWS\~tmp1918.exe
C:\WINDOWS\~tmp192.exe
C:\WINDOWS\~tmp1920.exe
C:\WINDOWS\~tmp1924.exe
C:\WINDOWS\~tmp1925.exe
C:\WINDOWS\~tmp1927.exe
C:\WINDOWS\~tmp1929.exe
C:\WINDOWS\~tmp193.exe
C:\WINDOWS\~tmp1930.exe
C:\WINDOWS\~tmp1931.exe
C:\WINDOWS\~tmp1932.exe
C:\WINDOWS\~tmp1933.exe
C:\WINDOWS\~tmp1936.exe
C:\WINDOWS\~tmp1937.exe
C:\WINDOWS\~tmp1938.exe
C:\WINDOWS\~tmp1939.exe
C:\WINDOWS\~tmp194.exe
C:\WINDOWS\~tmp1940.exe
C:\WINDOWS\~tmp1942.exe
C:\WINDOWS\~tmp1945.exe
C:\WINDOWS\~tmp1946.exe
C:\WINDOWS\~tmp1947.exe
C:\WINDOWS\~tmp1949.exe
C:\WINDOWS\~tmp1950.exe
C:\WINDOWS\~tmp1952.exe
C:\WINDOWS\~tmp1954.exe
C:\WINDOWS\~tmp1955.exe
C:\WINDOWS\~tmp1956.exe
C:\WINDOWS\~tmp1957.exe
C:\WINDOWS\~tmp1958.exe
C:\WINDOWS\~tmp1963.exe
C:\WINDOWS\~tmp1964.exe
C:\WINDOWS\~tmp1965.exe
C:\WINDOWS\~tmp1970.exe
C:\WINDOWS\~tmp1971.exe
C:\WINDOWS\~tmp1972.exe
C:\WINDOWS\~tmp1975.exe
C:\WINDOWS\~tmp1976.exe
C:\WINDOWS\~tmp1978.exe
C:\WINDOWS\~tmp1980.exe
C:\WINDOWS\~tmp1981.exe
C:\WINDOWS\~tmp1984.exe
C:\WINDOWS\~tmp1986.exe
C:\WINDOWS\~tmp1988.exe
C:\WINDOWS\~tmp1989.exe
C:\WINDOWS\~tmp199.exe
C:\WINDOWS\~tmp1992.exe
C:\WINDOWS\~tmp1993.exe
C:\WINDOWS\~tmp1994.exe
C:\WINDOWS\~tmp1995.exe
C:\WINDOWS\~tmp1996.exe
C:\WINDOWS\~tmp1997.exe
C:\WINDOWS\~tmp1998.exe
C:\WINDOWS\~tmp1999.exe
C:\WINDOWS\~tmp20.exe
C:\WINDOWS\~tmp2002.exe
C:\WINDOWS\~tmp2003.exe
C:\WINDOWS\~tmp2004.exe
C:\WINDOWS\~tmp2005.exe
C:\WINDOWS\~tmp2007.exe
C:\WINDOWS\~tmp2009.exe
C:\WINDOWS\~tmp2013.exe
C:\WINDOWS\~tmp2014.exe
C:\WINDOWS\~tmp2015.exe
C:\WINDOWS\~tmp2017.exe
C:\WINDOWS\~tmp2025.exe
C:\WINDOWS\~tmp2028.exe
C:\WINDOWS\~tmp2029.exe
C:\WINDOWS\~tmp203.exe
C:\WINDOWS\~tmp2031.exe
C:\WINDOWS\~tmp2032.exe
C:\WINDOWS\~tmp2036.exe
C:\WINDOWS\~tmp2038.exe
C:\WINDOWS\~tmp2039.exe
C:\WINDOWS\~tmp204.exe
C:\WINDOWS\~tmp2041.exe
C:\WINDOWS\~tmp2047.exe
C:\WINDOWS\~tmp2048.exe
C:\WINDOWS\~tmp205.exe
C:\WINDOWS\~tmp2050.exe
C:\WINDOWS\~tmp2051.exe
C:\WINDOWS\~tmp2054.exe
C:\WINDOWS\~tmp2055.exe
C:\WINDOWS\~tmp2056.exe
C:\WINDOWS\~tmp2057.exe
C:\WINDOWS\~tmp206.exe
C:\WINDOWS\~tmp2063.exe
C:\WINDOWS\~tmp2065.exe
C:\WINDOWS\~tmp2067.exe
C:\WINDOWS\~tmp2068.exe
C:\WINDOWS\~tmp2069.exe
C:\WINDOWS\~tmp2074.exe
C:\WINDOWS\~tmp2076.exe
C:\WINDOWS\~tmp2077.exe
C:\WINDOWS\~tmp2080.exe
C:\WINDOWS\~tmp2082.exe
C:\WINDOWS\~tmp2084.exe
C:\WINDOWS\~tmp2086.exe
C:\WINDOWS\~tmp2088.exe
C:\WINDOWS\~tmp2089.exe
C:\WINDOWS\~tmp209.exe
C:\WINDOWS\~tmp2090.exe
C:\WINDOWS\~tmp2091.exe
C:\WINDOWS\~tmp2096.exe
C:\WINDOWS\~tmp210.exe
C:\WINDOWS\~tmp2100.exe
C:\WINDOWS\~tmp2103.exe
C:\WINDOWS\~tmp2104.exe
C:\WINDOWS\~tmp2105.exe
C:\WINDOWS\~tmp2106.exe
C:\WINDOWS\~tmp2109.exe
C:\WINDOWS\~tmp211.exe
C:\WINDOWS\~tmp2112.exe
C:\WINDOWS\~tmp2114.exe
C:\WINDOWS\~tmp2115.exe
C:\WINDOWS\~tmp2117.exe
C:\WINDOWS\~tmp2118.exe
C:\WINDOWS\~tmp2119.exe
C:\WINDOWS\~tmp212.exe
C:\WINDOWS\~tmp2120.exe
C:\WINDOWS\~tmp2121.exe
C:\WINDOWS\~tmp2123.exe
C:\WINDOWS\~tmp2125.exe
C:\WINDOWS\~tmp2126.exe
C:\WINDOWS\~tmp2127.exe
C:\WINDOWS\~tmp2128.exe
C:\WINDOWS\~tmp2129.exe
C:\WINDOWS\~tmp213.exe
C:\WINDOWS\~tmp2130.exe
C:\WINDOWS\~tmp2131.exe
C:\WINDOWS\~tmp2132.exe
C:\WINDOWS\~tmp2134.exe
C:\WINDOWS\~tmp2139.exe
C:\WINDOWS\~tmp214.exe
C:\WINDOWS\~tmp2141.exe
C:\WINDOWS\~tmp2142.exe
C:\WINDOWS\~tmp2145.exe
C:\WINDOWS\~tmp2146.exe
C:\WINDOWS\~tmp2147.exe
C:\WINDOWS\~tmp2148.exe
C:\WINDOWS\~tmp215.exe
C:\WINDOWS\~tmp2151.exe
C:\WINDOWS\~tmp2152.exe
C:\WINDOWS\~tmp2153.exe
C:\WINDOWS\~tmp2155.exe
C:\WINDOWS\~tmp2157.exe
C:\WINDOWS\~tmp2158.exe
C:\WINDOWS\~tmp216.exe
C:\WINDOWS\~tmp2160.exe
C:\WINDOWS\~tmp2162.exe
C:\WINDOWS\~tmp2165.exe
C:\WINDOWS\~tmp2167.exe
C:\WINDOWS\~tmp217.exe
C:\WINDOWS\~tmp2170.exe
C:\WINDOWS\~tmp2171.exe
C:\WINDOWS\~tmp2172.exe
C:\WINDOWS\~tmp2173.exe
C:\WINDOWS\~tmp2177.exe
C:\WINDOWS\~tmp2178.exe
C:\WINDOWS\~tmp218.exe
C:\WINDOWS\~tmp2180.exe
C:\WINDOWS\~tmp2183.exe
C:\WINDOWS\~tmp2184.exe
C:\WINDOWS\~tmp2187.exe
C:\WINDOWS\~tmp2188.exe
C:\WINDOWS\~tmp2189.exe
C:\WINDOWS\~tmp219.exe
C:\WINDOWS\~tmp2190.exe
C:\WINDOWS\~tmp2191.exe
C:\WINDOWS\~tmp2192.exe
C:\WINDOWS\~tmp2193.exe
C:\WINDOWS\~tmp2196.exe
C:\WINDOWS\~tmp2197.exe
C:\WINDOWS\~tmp2198.exe
C:\WINDOWS\~tmp2199.exe
C:\WINDOWS\~tmp22.exe
C:\WINDOWS\~tmp220.exe
C:\WINDOWS\~tmp2200.exe
C:\WINDOWS\~tmp2201.exe
C:\WINDOWS\~tmp2202.exe
C:\WINDOWS\~tmp2204.exe
C:\WINDOWS\~tmp2205.exe
C:\WINDOWS\~tmp2207.exe
C:\WINDOWS\~tmp2208.exe
C:\WINDOWS\~tmp2209.exe
C:\WINDOWS\~tmp221.exe
C:\WINDOWS\~tmp2210.exe
C:\WINDOWS\~tmp2211.exe
C:\WINDOWS\~tmp2217.exe
C:\WINDOWS\~tmp2220.exe
C:\WINDOWS\~tmp2221.exe
C:\WINDOWS\~tmp2223.exe
C:\WINDOWS\~tmp2225.exe
C:\WINDOWS\~tmp2226.exe
C:\WINDOWS\~tmp2227.exe
C:\WINDOWS\~tmp223.exe
C:\WINDOWS\~tmp2230.exe
C:\WINDOWS\~tmp2232.exe
C:\WINDOWS\~tmp2234.exe
C:\WINDOWS\~tmp2236.exe
C:\WINDOWS\~tmp2237.exe
C:\WINDOWS\~tmp2239.exe
C:\WINDOWS\~tmp2241.exe
C:\WINDOWS\~tmp2243.exe
C:\WINDOWS\~tmp2246.exe
C:\WINDOWS\~tmp2248.exe
C:\WINDOWS\~tmp2249.exe
C:\WINDOWS\~tmp2250.exe
C:\WINDOWS\~tmp2252.exe
C:\WINDOWS\~tmp2254.exe
C:\WINDOWS\~tmp2255.exe
C:\WINDOWS\~tmp2256.exe
C:\WINDOWS\~tmp2259.exe
C:\WINDOWS\~tmp226.exe
C:\WINDOWS\~tmp2262.exe
C:\WINDOWS\~tmp2263.exe
C:\WINDOWS\~tmp2264.exe
C:\WINDOWS\~tmp2267.exe
C:\WINDOWS\~tmp2269.exe
C:\WINDOWS\~tmp2270.exe
C:\WINDOWS\~tmp2274.exe
C:\WINDOWS\~tmp2276.exe
C:\WINDOWS\~tmp2277.exe
C:\WINDOWS\~tmp2279.exe
C:\WINDOWS\~tmp2281.exe
C:\WINDOWS\~tmp2282.exe
C:\WINDOWS\~tmp2287.exe


----------



## cpuanswers (Sep 25, 2007)

other piece of combofix

ComboFix 07-09-26 - Owner_Emachine 2007-09-25 17:05:24.1 - NTFSx86 
Microsoft Windows XP Home Edition 5.1.2600.2.1252.1.1033.18.107 [GMT -7:00]
Running from: C:\Documents and Settings\Owner_Emachine\Desktop\ComboFix.exe
* Created a new restore point
.

((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.

C:\.protected
C:\Documents and Settings\All Users\Application Data.\salesmonitor
C:\Documents and Settings\All Users\Application Data.\winantispyware 2007
C:\Documents and Settings\All Users\Application Data.\winantispyware 2007\Data\Abbr
C:\Documents and Settings\All Users\Application Data.\winantispyware 2007\Data\ProductCode
C:\Documents and Settings\All Users\Application Data\WinAntiSpyware 2007\Data\Abbr
C:\Documents and Settings\All Users\Application Data\WinAntiSpyware 2007\Data\ProductCode
C:\Documents and Settings\All Users\Start Menu\Programs\Startup\.protected
C:\Documents and Settings\Owner_Emachine\Application Data\WinAntiSpyware 2007
C:\Documents and Settings\Owner_Emachine\Application Data\WinAntiSpyware 2007 Free
C:\Documents and Settings\Owner_Emachine\Application Data\WinAntiSpyware 2007 Free\DownloadUWAS7.url
C:\Documents and Settings\Owner_Emachine\Application Data\WinAntiSpyware 2007\Logs\update.log
C:\Documents and Settings\Owner_Emachine\err.log
C:\Documents and Settings\Owner_Emachine\Start Menu\Programs\Startup\.protected
C:\Program Files\Common Files\ssembl~1
C:\Program Files\Common Files\winantispyware 2007
C:\Program Files\Common Files\winantispyware 2007\err.log
C:\Program Files\Common Files\winantispyware 2007\uwas7cw.exe
C:\Program Files\FunWebProducts
C:\Program Files\Ultimate Defender
C:\temp\0c2
C:\temp\0c2\tmpFF.log
C:\Temp\1cb
C:\Temp\1cb\syscheck.log
C:\WINDOWS\.protected
C:\WINDOWS\~tmp0.exe
C:\WINDOWS\~tmp100.exe
C:\WINDOWS\~tmp1000.exe
C:\WINDOWS\~tmp1001.exe
C:\WINDOWS\~tmp1002.exe
C:\WINDOWS\~tmp1004.exe
C:\WINDOWS\~tmp1005.exe
C:\WINDOWS\~tmp1006.exe
C:\WINDOWS\~tmp1007.exe
C:\WINDOWS\~tmp1009.exe
C:\WINDOWS\~tmp1010.exe
C:\WINDOWS\~tmp1012.exe
C:\WINDOWS\~tmp1014.exe
C:\WINDOWS\~tmp1015.exe
C:\WINDOWS\~tmp1017.exe
C:\WINDOWS\~tmp1019.exe
C:\WINDOWS\~tmp1020.exe
C:\WINDOWS\~tmp1021.exe
C:\WINDOWS\~tmp1024.exe
C:\WINDOWS\~tmp1025.exe
C:\WINDOWS\~tmp1026.exe
C:\WINDOWS\~tmp1029.exe
C:\WINDOWS\~tmp103.exe
C:\WINDOWS\~tmp1030.exe
C:\WINDOWS\~tmp1031.exe
C:\WINDOWS\~tmp1032.exe
C:\WINDOWS\~tmp1035.exe
C:\WINDOWS\~tmp1037.exe
C:\WINDOWS\~tmp1038.exe
C:\WINDOWS\~tmp1039.exe
C:\WINDOWS\~tmp104.exe
C:\WINDOWS\~tmp1041.exe
C:\WINDOWS\~tmp1042.exe
C:\WINDOWS\~tmp1043.exe
C:\WINDOWS\~tmp1044.exe
C:\WINDOWS\~tmp1045.exe
C:\WINDOWS\~tmp1046.exe
C:\WINDOWS\~tmp1048.exe
C:\WINDOWS\~tmp105.exe
C:\WINDOWS\~tmp1050.exe
C:\WINDOWS\~tmp1051.exe
C:\WINDOWS\~tmp1056.exe
C:\WINDOWS\~tmp1057.exe
C:\WINDOWS\~tmp1058.exe
C:\WINDOWS\~tmp1059.exe
C:\WINDOWS\~tmp106.exe
C:\WINDOWS\~tmp1060.exe
C:\WINDOWS\~tmp1063.exe
C:\WINDOWS\~tmp1064.exe
C:\WINDOWS\~tmp1066.exe
C:\WINDOWS\~tmp1067.exe
C:\WINDOWS\~tmp1068.exe
C:\WINDOWS\~tmp1069.exe
C:\WINDOWS\~tmp107.exe
C:\WINDOWS\~tmp1070.exe
C:\WINDOWS\~tmp1071.exe
C:\WINDOWS\~tmp1073.exe
C:\WINDOWS\~tmp1075.exe
C:\WINDOWS\~tmp1076.exe
C:\WINDOWS\~tmp1078.exe
C:\WINDOWS\~tmp1079.exe
C:\WINDOWS\~tmp1080.exe
C:\WINDOWS\~tmp1082.exe
C:\WINDOWS\~tmp1084.exe
C:\WINDOWS\~tmp1088.exe
C:\WINDOWS\~tmp1089.exe
C:\WINDOWS\~tmp109.exe
C:\WINDOWS\~tmp1090.exe
C:\WINDOWS\~tmp1091.exe
C:\WINDOWS\~tmp1094.exe
C:\WINDOWS\~tmp1095.exe
C:\WINDOWS\~tmp1096.exe
C:\WINDOWS\~tmp1097.exe
C:\WINDOWS\~tmp1099.exe
C:\WINDOWS\~tmp11.exe
C:\WINDOWS\~tmp1100.exe
C:\WINDOWS\~tmp1102.exe
C:\WINDOWS\~tmp1103.exe
C:\WINDOWS\~tmp1104.exe
C:\WINDOWS\~tmp1105.exe
C:\WINDOWS\~tmp1106.exe
C:\WINDOWS\~tmp1109.exe
C:\WINDOWS\~tmp111.exe
C:\WINDOWS\~tmp1111.exe
C:\WINDOWS\~tmp1114.exe
C:\WINDOWS\~tmp1116.exe
C:\WINDOWS\~tmp1118.exe
C:\WINDOWS\~tmp1120.exe
C:\WINDOWS\~tmp1121.exe
C:\WINDOWS\~tmp1122.exe
C:\WINDOWS\~tmp1124.exe
C:\WINDOWS\~tmp1126.exe
C:\WINDOWS\~tmp113.exe
C:\WINDOWS\~tmp1130.exe
C:\WINDOWS\~tmp1133.exe
C:\WINDOWS\~tmp1134.exe
C:\WINDOWS\~tmp1139.exe
C:\WINDOWS\~tmp114.exe
C:\WINDOWS\~tmp1140.exe
C:\WINDOWS\~tmp1146.exe
C:\WINDOWS\~tmp1147.exe
C:\WINDOWS\~tmp1148.exe
C:\WINDOWS\~tmp1150.exe
C:\WINDOWS\~tmp1153.exe
C:\WINDOWS\~tmp1154.exe
C:\WINDOWS\~tmp1158.exe
C:\WINDOWS\~tmp1159.exe
C:\WINDOWS\~tmp1163.exe
C:\WINDOWS\~tmp1164.exe
C:\WINDOWS\~tmp1165.exe
C:\WINDOWS\~tmp1166.exe
C:\WINDOWS\~tmp1168.exe
C:\WINDOWS\~tmp1170.exe
C:\WINDOWS\~tmp1174.exe
C:\WINDOWS\~tmp1177.exe
C:\WINDOWS\~tmp1178.exe
C:\WINDOWS\~tmp118.exe
C:\WINDOWS\~tmp1180.exe
C:\WINDOWS\~tmp1181.exe
C:\WINDOWS\~tmp1183.exe
C:\WINDOWS\~tmp1184.exe
C:\WINDOWS\~tmp1188.exe
C:\WINDOWS\~tmp1189.exe
C:\WINDOWS\~tmp119.exe
C:\WINDOWS\~tmp1191.exe
C:\WINDOWS\~tmp1192.exe
C:\WINDOWS\~tmp1193.exe
C:\WINDOWS\~tmp1194.exe
C:\WINDOWS\~tmp1195.exe
C:\WINDOWS\~tmp1197.exe
C:\WINDOWS\~tmp120.exe
C:\WINDOWS\~tmp1200.exe
C:\WINDOWS\~tmp1202.exe
C:\WINDOWS\~tmp1205.exe
C:\WINDOWS\~tmp1206.exe
C:\WINDOWS\~tmp1207.exe
C:\WINDOWS\~tmp1212.exe
C:\WINDOWS\~tmp1213.exe
C:\WINDOWS\~tmp1214.exe
C:\WINDOWS\~tmp1215.exe
C:\WINDOWS\~tmp1216.exe
C:\WINDOWS\~tmp1217.exe
C:\WINDOWS\~tmp1218.exe
C:\WINDOWS\~tmp1219.exe
C:\WINDOWS\~tmp1221.exe
C:\WINDOWS\~tmp1222.exe
C:\WINDOWS\~tmp1223.exe
C:\WINDOWS\~tmp1224.exe
C:\WINDOWS\~tmp1226.exe
C:\WINDOWS\~tmp1227.exe
C:\WINDOWS\~tmp1228.exe
C:\WINDOWS\~tmp123.exe
C:\WINDOWS\~tmp1233.exe
C:\WINDOWS\~tmp1235.exe
C:\WINDOWS\~tmp1236.exe
C:\WINDOWS\~tmp1238.exe
C:\WINDOWS\~tmp1239.exe
C:\WINDOWS\~tmp124.exe
C:\WINDOWS\~tmp1240.exe
C:\WINDOWS\~tmp1242.exe
C:\WINDOWS\~tmp1243.exe
C:\WINDOWS\~tmp1245.exe
C:\WINDOWS\~tmp1246.exe
C:\WINDOWS\~tmp1247.exe
C:\WINDOWS\~tmp1248.exe
C:\WINDOWS\~tmp1250.exe
C:\WINDOWS\~tmp1252.exe
C:\WINDOWS\~tmp1253.exe
C:\WINDOWS\~tmp1256.exe
C:\WINDOWS\~tmp1258.exe
C:\WINDOWS\~tmp1259.exe
C:\WINDOWS\~tmp126.exe
C:\WINDOWS\~tmp1260.exe
C:\WINDOWS\~tmp1262.exe
C:\WINDOWS\~tmp1263.exe
C:\WINDOWS\~tmp1264.exe
C:\WINDOWS\~tmp1266.exe
C:\WINDOWS\~tmp127.exe
C:\WINDOWS\~tmp1272.exe
C:\WINDOWS\~tmp1273.exe
C:\WINDOWS\~tmp1277.exe
C:\WINDOWS\~tmp1278.exe
C:\WINDOWS\~tmp1279.exe
C:\WINDOWS\~tmp1281.exe
C:\WINDOWS\~tmp1286.exe
C:\WINDOWS\~tmp1288.exe
C:\WINDOWS\~tmp1289.exe
C:\WINDOWS\~tmp1290.exe
C:\WINDOWS\~tmp1293.exe
C:\WINDOWS\~tmp1295.exe
C:\WINDOWS\~tmp1296.exe
C:\WINDOWS\~tmp1300.exe
C:\WINDOWS\~tmp1304.exe
C:\WINDOWS\~tmp1306.exe
C:\WINDOWS\~tmp1308.exe
C:\WINDOWS\~tmp131.exe
C:\WINDOWS\~tmp1310.exe
C:\WINDOWS\~tmp1314.exe
C:\WINDOWS\~tmp1315.exe
C:\WINDOWS\~tmp1317.exe
C:\WINDOWS\~tmp1319.exe
C:\WINDOWS\~tmp132.exe
C:\WINDOWS\~tmp1320.exe
C:\WINDOWS\~tmp1324.exe
C:\WINDOWS\~tmp1325.exe
C:\WINDOWS\~tmp1326.exe
C:\WINDOWS\~tmp1329.exe
C:\WINDOWS\~tmp1334.exe
C:\WINDOWS\~tmp1337.exe
C:\WINDOWS\~tmp1340.exe
C:\WINDOWS\~tmp1341.exe
C:\WINDOWS\~tmp1342.exe
C:\WINDOWS\~tmp1344.exe
C:\WINDOWS\~tmp1346.exe
C:\WINDOWS\~tmp1348.exe
C:\WINDOWS\~tmp135.exe
C:\WINDOWS\~tmp1351.exe
C:\WINDOWS\~tmp1352.exe
C:\WINDOWS\~tmp1353.exe
C:\WINDOWS\~tmp1355.exe
C:\WINDOWS\~tmp1356.exe
C:\WINDOWS\~tmp1357.exe
C:\WINDOWS\~tmp1361.exe
C:\WINDOWS\~tmp1362.exe
C:\WINDOWS\~tmp1363.exe
C:\WINDOWS\~tmp1364.exe
C:\WINDOWS\~tmp1365.exe
C:\WINDOWS\~tmp1366.exe
C:\WINDOWS\~tmp1371.exe
C:\WINDOWS\~tmp1375.exe
C:\WINDOWS\~tmp1377.exe
C:\WINDOWS\~tmp1383.exe
C:\WINDOWS\~tmp1384.exe
C:\WINDOWS\~tmp1386.exe
C:\WINDOWS\~tmp1393.exe
C:\WINDOWS\~tmp1395.exe
C:\WINDOWS\~tmp1396.exe
C:\WINDOWS\~tmp1398.exe
C:\WINDOWS\~tmp14.exe
C:\WINDOWS\~tmp1406.exe
C:\WINDOWS\~tmp1407.exe
C:\WINDOWS\~tmp1408.exe
C:\WINDOWS\~tmp1409.exe
C:\WINDOWS\~tmp1410.exe
C:\WINDOWS\~tmp1411.exe
C:\WINDOWS\~tmp1412.exe
C:\WINDOWS\~tmp1415.exe
C:\WINDOWS\~tmp1416.exe
C:\WINDOWS\~tmp142.exe
C:\WINDOWS\~tmp1421.exe
C:\WINDOWS\~tmp1422.exe
C:\WINDOWS\~tmp1423.exe
C:\WINDOWS\~tmp1426.exe
C:\WINDOWS\~tmp1430.exe
C:\WINDOWS\~tmp1431.exe
C:\WINDOWS\~tmp1432.exe
C:\WINDOWS\~tmp1433.exe
C:\WINDOWS\~tmp1434.exe
C:\WINDOWS\~tmp1435.exe
C:\WINDOWS\~tmp1436.exe
C:\WINDOWS\~tmp1437.exe
C:\WINDOWS\~tmp1438.exe
C:\WINDOWS\~tmp1439.exe
C:\WINDOWS\~tmp1440.exe
C:\WINDOWS\~tmp1441.exe
C:\WINDOWS\~tmp1442.exe
C:\WINDOWS\~tmp1444.exe
C:\WINDOWS\~tmp1445.exe
C:\WINDOWS\~tmp1448.exe
C:\WINDOWS\~tmp1452.exe
C:\WINDOWS\~tmp1454.exe
C:\WINDOWS\~tmp1455.exe
C:\WINDOWS\~tmp1456.exe
C:\WINDOWS\~tmp1457.exe
C:\WINDOWS\~tmp146.exe
C:\WINDOWS\~tmp1462.exe
C:\WINDOWS\~tmp1463.exe
C:\WINDOWS\~tmp1464.exe
C:\WINDOWS\~tmp1465.exe
C:\WINDOWS\~tmp1466.exe
C:\WINDOWS\~tmp1467.exe
C:\WINDOWS\~tmp147.exe
C:\WINDOWS\~tmp1470.exe
C:\WINDOWS\~tmp1471.exe
C:\WINDOWS\~tmp1472.exe
C:\WINDOWS\~tmp1473.exe
C:\WINDOWS\~tmp1474.exe
C:\WINDOWS\~tmp1476.exe
C:\WINDOWS\~tmp1477.exe
C:\WINDOWS\~tmp1478.exe
C:\WINDOWS\~tmp1479.exe
C:\WINDOWS\~tmp1480.exe
C:\WINDOWS\~tmp1485.exe
C:\WINDOWS\~tmp1487.exe
C:\WINDOWS\~tmp1489.exe
C:\WINDOWS\~tmp1490.exe
C:\WINDOWS\~tmp1491.exe
C:\WINDOWS\~tmp1492.exe
C:\WINDOWS\~tmp1493.exe
C:\WINDOWS\~tmp1494.exe
C:\WINDOWS\~tmp1499.exe
C:\WINDOWS\~tmp150.exe
C:\WINDOWS\~tmp1500.exe
C:\WINDOWS\~tmp1501.exe
C:\WINDOWS\~tmp1503.exe
C:\WINDOWS\~tmp1504.exe
C:\WINDOWS\~tmp1505.exe
C:\WINDOWS\~tmp1506.exe
C:\WINDOWS\~tmp1507.exe
C:\WINDOWS\~tmp1508.exe
C:\WINDOWS\~tmp151.exe
C:\WINDOWS\~tmp1510.exe
C:\WINDOWS\~tmp1514.exe
C:\WINDOWS\~tmp1516.exe
C:\WINDOWS\~tmp1517.exe
C:\WINDOWS\~tmp1518.exe
C:\WINDOWS\~tmp152.exe
C:\WINDOWS\~tmp1520.exe
C:\WINDOWS\~tmp1521.exe
C:\WINDOWS\~tmp1522.exe
C:\WINDOWS\~tmp1523.exe
C:\WINDOWS\~tmp1524.exe
C:\WINDOWS\~tmp1525.exe
C:\WINDOWS\~tmp1526.exe
C:\WINDOWS\~tmp1530.exe
C:\WINDOWS\~tmp1531.exe
C:\WINDOWS\~tmp1532.exe
C:\WINDOWS\~tmp1533.exe
C:\WINDOWS\~tmp1535.exe
C:\WINDOWS\~tmp1536.exe
C:\WINDOWS\~tmp1539.exe
C:\WINDOWS\~tmp1542.exe
C:\WINDOWS\~tmp1543.exe
C:\WINDOWS\~tmp1545.exe
C:\WINDOWS\~tmp1546.exe
C:\WINDOWS\~tmp1547.exe
C:\WINDOWS\~tmp155.exe
C:\WINDOWS\~tmp1552.exe
C:\WINDOWS\~tmp1553.exe
C:\WINDOWS\~tmp1557.exe
C:\WINDOWS\~tmp1562.exe
C:\WINDOWS\~tmp1563.exe
C:\WINDOWS\~tmp1564.exe
C:\WINDOWS\~tmp1566.exe
C:\WINDOWS\~tmp1567.exe
C:\WINDOWS\~tmp1573.exe
C:\WINDOWS\~tmp1576.exe
C:\WINDOWS\~tmp1577.exe
C:\WINDOWS\~tmp158.exe
C:\WINDOWS\~tmp1580.exe
C:\WINDOWS\~tmp1581.exe
C:\WINDOWS\~tmp1582.exe
C:\WINDOWS\~tmp1583.exe
C:\WINDOWS\~tmp1585.exe
C:\WINDOWS\~tmp1586.exe
C:\WINDOWS\~tmp1588.exe
C:\WINDOWS\~tmp159.exe
C:\WINDOWS\~tmp1590.exe
C:\WINDOWS\~tmp1592.exe
C:\WINDOWS\~tmp1593.exe
C:\WINDOWS\~tmp1595.exe
C:\WINDOWS\~tmp1597.exe
C:\WINDOWS\~tmp16.exe
C:\WINDOWS\~tmp1600.exe
C:\WINDOWS\~tmp1601.exe
C:\WINDOWS\~tmp1602.exe
C:\WINDOWS\~tmp1604.exe
C:\WINDOWS\~tmp1605.exe
C:\WINDOWS\~tmp1607.exe
C:\WINDOWS\~tmp1608.exe
C:\WINDOWS\~tmp1610.exe
C:\WINDOWS\~tmp1611.exe
C:\WINDOWS\~tmp1613.exe
C:\WINDOWS\~tmp1615.exe
C:\WINDOWS\~tmp1617.exe
C:\WINDOWS\~tmp1618.exe
C:\WINDOWS\~tmp1619.exe
C:\WINDOWS\~tmp162.exe
C:\WINDOWS\~tmp1620.exe
C:\WINDOWS\~tmp1621.exe
C:\WINDOWS\~tmp1622.exe
C:\WINDOWS\~tmp1624.exe
C:\WINDOWS\~tmp1626.exe
C:\WINDOWS\~tmp1627.exe
C:\WINDOWS\~tmp1628.exe
C:\WINDOWS\~tmp1629.exe
C:\WINDOWS\~tmp163.exe
C:\WINDOWS\~tmp1630.exe
C:\WINDOWS\~tmp1631.exe
C:\WINDOWS\~tmp1633.exe
C:\WINDOWS\~tmp1634.exe
C:\WINDOWS\~tmp1635.exe
C:\WINDOWS\~tmp1636.exe
C:\WINDOWS\~tmp1639.exe
C:\WINDOWS\~tmp164.exe
C:\WINDOWS\~tmp1642.exe
C:\WINDOWS\~tmp1643.exe
C:\WINDOWS\~tmp1648.exe
C:\WINDOWS\~tmp165.exe
C:\WINDOWS\~tmp1652.exe
C:\WINDOWS\~tmp1654.exe
C:\WINDOWS\~tmp1657.exe
C:\WINDOWS\~tmp1658.exe
C:\WINDOWS\~tmp1660.exe
C:\WINDOWS\~tmp1661.exe
C:\WINDOWS\~tmp1662.exe
C:\WINDOWS\~tmp1663.exe
C:\WINDOWS\~tmp1668.exe
C:\WINDOWS\~tmp1669.exe
C:\WINDOWS\~tmp1672.exe
C:\WINDOWS\~tmp1675.exe
C:\WINDOWS\~tmp1677.exe
C:\WINDOWS\~tmp1678.exe
C:\WINDOWS\~tmp1679.exe
C:\WINDOWS\~tmp1680.exe
C:\WINDOWS\~tmp1682.exe
C:\WINDOWS\~tmp1683.exe
C:\WINDOWS\~tmp1685.exe
C:\WINDOWS\~tmp1686.exe
C:\WINDOWS\~tmp1687.exe
C:\WINDOWS\~tmp1688.exe
C:\WINDOWS\~tmp1689.exe
C:\WINDOWS\~tmp1690.exe
C:\WINDOWS\~tmp1698.exe
C:\WINDOWS\~tmp1699.exe
C:\WINDOWS\~tmp17.exe
C:\WINDOWS\~tmp170.exe
C:\WINDOWS\~tmp1700.exe
C:\WINDOWS\~tmp1702.exe
C:\WINDOWS\~tmp1703.exe
C:\WINDOWS\~tmp1705.exe
C:\WINDOWS\~tmp1706.exe
C:\WINDOWS\~tmp1708.exe
C:\WINDOWS\~tmp171.exe
C:\WINDOWS\~tmp1710.exe
C:\WINDOWS\~tmp1712.exe
C:\WINDOWS\~tmp1714.exe
C:\WINDOWS\~tmp1715.exe
C:\WINDOWS\~tmp1716.exe
C:\WINDOWS\~tmp1718.exe
C:\WINDOWS\~tmp1720.exe
C:\WINDOWS\~tmp1721.exe
C:\WINDOWS\~tmp1722.exe
C:\WINDOWS\~tmp1724.exe
C:\WINDOWS\~tmp1725.exe
C:\WINDOWS\~tmp1726.exe
C:\WINDOWS\~tmp1729.exe
C:\WINDOWS\~tmp173.exe
C:\WINDOWS\~tmp1731.exe
C:\WINDOWS\~tmp1732.exe
C:\WINDOWS\~tmp1735.exe
C:\WINDOWS\~tmp1736.exe
C:\WINDOWS\~tmp1737.exe
C:\WINDOWS\~tmp1738.exe
C:\WINDOWS\~tmp1739.exe
C:\WINDOWS\~tmp1740.exe
C:\WINDOWS\~tmp1741.exe
C:\WINDOWS\~tmp1742.exe
C:\WINDOWS\~tmp1745.exe
C:\WINDOWS\~tmp1746.exe
C:\WINDOWS\~tmp1747.exe
C:\WINDOWS\~tmp1748.exe
C:\WINDOWS\~tmp1749.exe
C:\WINDOWS\~tmp1750.exe
C:\WINDOWS\~tmp1756.exe
C:\WINDOWS\~tmp1757.exe
C:\WINDOWS\~tmp1758.exe
C:\WINDOWS\~tmp1759.exe
C:\WINDOWS\~tmp176.exe
C:\WINDOWS\~tmp1760.exe
C:\WINDOWS\~tmp1761.exe
C:\WINDOWS\~tmp1763.exe
C:\WINDOWS\~tmp1766.exe
C:\WINDOWS\~tmp1768.exe
C:\WINDOWS\~tmp1770.exe
C:\WINDOWS\~tmp1772.exe
C:\WINDOWS\~tmp1773.exe
C:\WINDOWS\~tmp1774.exe
C:\WINDOWS\~tmp1775.exe
C:\WINDOWS\~tmp1776.exe
C:\WINDOWS\~tmp1777.exe
C:\WINDOWS\~tmp1779.exe
C:\WINDOWS\~tmp1782.exe
C:\WINDOWS\~tmp1785.exe
C:\WINDOWS\~tmp1788.exe
C:\WINDOWS\~tmp179.exe
C:\WINDOWS\~tmp1790.exe
C:\WINDOWS\~tmp1791.exe
C:\WINDOWS\~tmp1794.exe
C:\WINDOWS\~tmp1798.exe
C:\WINDOWS\~tmp180.exe
C:\WINDOWS\~tmp1802.exe
C:\WINDOWS\~tmp1803.exe
C:\WINDOWS\~tmp1804.exe
C:\WINDOWS\~tmp1805.exe
C:\WINDOWS\~tmp1806.exe
C:\WINDOWS\~tmp1807.exe
C:\WINDOWS\~tmp1810.exe
C:\WINDOWS\~tmp1811.exe
C:\WINDOWS\~tmp1812.exe
C:\WINDOWS\~tmp1813.exe
C:\WINDOWS\~tmp1814.exe
C:\WINDOWS\~tmp1819.exe
C:\WINDOWS\~tmp1820.exe
C:\WINDOWS\~tmp1823.exe
C:\WINDOWS\~tmp1825.exe
C:\WINDOWS\~tmp1827.exe
C:\WINDOWS\~tmp1828.exe
C:\WINDOWS\~tmp1829.exe
C:\WINDOWS\~tmp183.exe
C:\WINDOWS\~tmp1832.exe
C:\WINDOWS\~tmp1834.exe
C:\WINDOWS\~tmp1836.exe
C:\WINDOWS\~tmp1837.exe
C:\WINDOWS\~tmp1838.exe
C:\WINDOWS\~tmp184.exe
C:\WINDOWS\~tmp1840.exe
C:\WINDOWS\~tmp1842.exe
C:\WINDOWS\~tmp1843.exe
C:\WINDOWS\~tmp1844.exe
C:\WINDOWS\~tmp1846.exe
C:\WINDOWS\~tmp1847.exe
C:\WINDOWS\~tmp1848.exe
C:\WINDOWS\~tmp1849.exe
C:\WINDOWS\~tmp1852.exe
C:\WINDOWS\~tmp1853.exe
C:\WINDOWS\~tmp1856.exe
C:\WINDOWS\~tmp1857.exe
C:\WINDOWS\~tmp186.exe
C:\WINDOWS\~tmp1860.exe
C:\WINDOWS\~tmp187.exe
C:\WINDOWS\~tmp1870.exe
C:\WINDOWS\~tmp1873.exe
C:\WINDOWS\~tmp1875.exe
C:\WINDOWS\~tmp1877.exe
C:\WINDOWS\~tmp1879.exe
C:\WINDOWS\~tmp1880.exe
C:\WINDOWS\~tmp1881.exe
C:\WINDOWS\~tmp1882.exe
C:\WINDOWS\~tmp1888.exe
C:\WINDOWS\~tmp1889.exe
C:\WINDOWS\~tmp1890.exe
C:\WINDOWS\~tmp1891.exe
C:\WINDOWS\~tmp1895.exe
C:\WINDOWS\~tmp1899.exe
C:\WINDOWS\~tmp19.exe
C:\WINDOWS\~tmp190.exe
C:\WINDOWS\~tmp1902.exe
C:\WINDOWS\~tmp1911.exe
C:\WINDOWS\~tmp1914.exe
C:\WINDOWS\~tmp1915.exe
C:\WINDOWS\~tmp1916.exe
C:\WINDOWS\~tmp1918.exe
C:\WINDOWS\~tmp192.exe
C:\WINDOWS\~tmp1920.exe
C:\WINDOWS\~tmp1924.exe
C:\WINDOWS\~tmp1925.exe
C:\WINDOWS\~tmp1927.exe
C:\WINDOWS\~tmp1929.exe
C:\WINDOWS\~tmp193.exe
C:\WINDOWS\~tmp1930.exe
C:\WINDOWS\~tmp1931.exe
C:\WINDOWS\~tmp1932.exe
C:\WINDOWS\~tmp1933.exe
C:\WINDOWS\~tmp1936.exe
C:\WINDOWS\~tmp1937.exe
C:\WINDOWS\~tmp1938.exe
C:\WINDOWS\~tmp1939.exe
C:\WINDOWS\~tmp194.exe
C:\WINDOWS\~tmp1940.exe
C:\WINDOWS\~tmp1942.exe
C:\WINDOWS\~tmp1945.exe
C:\WINDOWS\~tmp1946.exe
C:\WINDOWS\~tmp1947.exe
C:\WINDOWS\~tmp1949.exe
C:\WINDOWS\~tmp1950.exe
C:\WINDOWS\~tmp1952.exe
C:\WINDOWS\~tmp1954.exe
C:\WINDOWS\~tmp1955.exe
C:\WINDOWS\~tmp1956.exe
C:\WINDOWS\~tmp1957.exe
C:\WINDOWS\~tmp1958.exe
C:\WINDOWS\~tmp1963.exe
C:\WINDOWS\~tmp1964.exe
C:\WINDOWS\~tmp1965.exe
C:\WINDOWS\~tmp1970.exe
C:\WINDOWS\~tmp1971.exe
C:\WINDOWS\~tmp1972.exe
C:\WINDOWS\~tmp1975.exe
C:\WINDOWS\~tmp1976.exe
C:\WINDOWS\~tmp1978.exe
C:\WINDOWS\~tmp1980.exe
C:\WINDOWS\~tmp1981.exe
C:\WINDOWS\~tmp1984.exe
C:\WINDOWS\~tmp1986.exe
C:\WINDOWS\~tmp1988.exe
C:\WINDOWS\~tmp1989.exe
C:\WINDOWS\~tmp199.exe
C:\WINDOWS\~tmp1992.exe
C:\WINDOWS\~tmp1993.exe
C:\WINDOWS\~tmp1994.exe
C:\WINDOWS\~tmp1995.exe
C:\WINDOWS\~tmp1996.exe
C:\WINDOWS\~tmp1997.exe
C:\WINDOWS\~tmp1998.exe
C:\WINDOWS\~tmp1999.exe
C:\WINDOWS\~tmp20.exe
C:\WINDOWS\~tmp2002.exe
C:\WINDOWS\~tmp2003.exe
C:\WINDOWS\~tmp2004.exe
C:\WINDOWS\~tmp2005.exe
C:\WINDOWS\~tmp2007.exe
C:\WINDOWS\~tmp2009.exe
C:\WINDOWS\~tmp2013.exe
C:\WINDOWS\~tmp2014.exe
C:\WINDOWS\~tmp2015.exe
C:\WINDOWS\~tmp2017.exe
C:\WINDOWS\~tmp2025.exe
C:\WINDOWS\~tmp2028.exe
C:\WINDOWS\~tmp2029.exe
C:\WINDOWS\~tmp203.exe
C:\WINDOWS\~tmp2031.exe
C:\WINDOWS\~tmp2032.exe
C:\WINDOWS\~tmp2036.exe
C:\WINDOWS\~tmp2038.exe
C:\WINDOWS\~tmp2039.exe
C:\WINDOWS\~tmp204.exe
C:\WINDOWS\~tmp2041.exe
C:\WINDOWS\~tmp2047.exe
C:\WINDOWS\~tmp2048.exe
C:\WINDOWS\~tmp205.exe
C:\WINDOWS\~tmp2050.exe
C:\WINDOWS\~tmp2051.exe
C:\WINDOWS\~tmp2054.exe
C:\WINDOWS\~tmp2055.exe
C:\WINDOWS\~tmp2056.exe
C:\WINDOWS\~tmp2057.exe
C:\WINDOWS\~tmp206.exe
C:\WINDOWS\~tmp2063.exe
C:\WINDOWS\~tmp2065.exe
C:\WINDOWS\~tmp2067.exe
C:\WINDOWS\~tmp2068.exe
C:\WINDOWS\~tmp2069.exe
C:\WINDOWS\~tmp2074.exe
C:\WINDOWS\~tmp2076.exe
C:\WINDOWS\~tmp2077.exe
C:\WINDOWS\~tmp2080.exe
C:\WINDOWS\~tmp2082.exe
C:\WINDOWS\~tmp2084.exe
C:\WINDOWS\~tmp2086.exe
C:\WINDOWS\~tmp2088.exe
C:\WINDOWS\~tmp2089.exe
C:\WINDOWS\~tmp209.exe
C:\WINDOWS\~tmp2090.exe
C:\WINDOWS\~tmp2091.exe
C:\WINDOWS\~tmp2096.exe
C:\WINDOWS\~tmp210.exe
C:\WINDOWS\~tmp2100.exe
C:\WINDOWS\~tmp2103.exe
C:\WINDOWS\~tmp2104.exe
C:\WINDOWS\~tmp2105.exe
C:\WINDOWS\~tmp2106.exe
C:\WINDOWS\~tmp2109.exe
C:\WINDOWS\~tmp211.exe
C:\WINDOWS\~tmp2112.exe
C:\WINDOWS\~tmp2114.exe
C:\WINDOWS\~tmp2115.exe
C:\WINDOWS\~tmp2117.exe
C:\WINDOWS\~tmp2118.exe
C:\WINDOWS\~tmp2119.exe
C:\WINDOWS\~tmp212.exe
C:\WINDOWS\~tmp2120.exe
C:\WINDOWS\~tmp2121.exe
C:\WINDOWS\~tmp2123.exe
C:\WINDOWS\~tmp2125.exe
C:\WINDOWS\~tmp2126.exe
C:\WINDOWS\~tmp2127.exe
C:\WINDOWS\~tmp2128.exe
C:\WINDOWS\~tmp2129.exe
C:\WINDOWS\~tmp213.exe
C:\WINDOWS\~tmp2130.exe
C:\WINDOWS\~tmp2131.exe
C:\WINDOWS\~tmp2132.exe
C:\WINDOWS\~tmp2134.exe
C:\WINDOWS\~tmp2139.exe
C:\WINDOWS\~tmp214.exe
C:\WINDOWS\~tmp2141.exe
C:\WINDOWS\~tmp2142.exe
C:\WINDOWS\~tmp2145.exe
C:\WINDOWS\~tmp2146.exe
C:\WINDOWS\~tmp2147.exe
C:\WINDOWS\~tmp2148.exe
C:\WINDOWS\~tmp215.exe
C:\WINDOWS\~tmp2151.exe
C:\WINDOWS\~tmp2152.exe
C:\WINDOWS\~tmp2153.exe
C:\WINDOWS\~tmp2155.exe
C:\WINDOWS\~tmp2157.exe
C:\WINDOWS\~tmp2158.exe
C:\WINDOWS\~tmp216.exe
C:\WINDOWS\~tmp2160.exe
C:\WINDOWS\~tmp2162.exe
C:\WINDOWS\~tmp2165.exe
C:\WINDOWS\~tmp2167.exe
C:\WINDOWS\~tmp217.exe
C:\WINDOWS\~tmp2170.exe
C:\WINDOWS\~tmp2171.exe
C:\WINDOWS\~tmp2172.exe
C:\WINDOWS\~tmp2173.exe
C:\WINDOWS\~tmp2177.exe
C:\WINDOWS\~tmp2178.exe
C:\WINDOWS\~tmp218.exe
C:\WINDOWS\~tmp2180.exe
C:\WINDOWS\~tmp2183.exe
C:\WINDOWS\~tmp2184.exe
C:\WINDOWS\~tmp2187.exe
C:\WINDOWS\~tmp2188.exe
C:\WINDOWS\~tmp2189.exe
C:\WINDOWS\~tmp219.exe
C:\WINDOWS\~tmp2190.exe
C:\WINDOWS\~tmp2191.exe
C:\WINDOWS\~tmp2192.exe
C:\WINDOWS\~tmp2193.exe
C:\WINDOWS\~tmp2196.exe
C:\WINDOWS\~tmp2197.exe
C:\WINDOWS\~tmp2198.exe
C:\WINDOWS\~tmp2199.exe
C:\WINDOWS\~tmp22.exe
C:\WINDOWS\~tmp220.exe
C:\WINDOWS\~tmp2200.exe
C:\WINDOWS\~tmp2201.exe
C:\WINDOWS\~tmp2202.exe
C:\WINDOWS\~tmp2204.exe
C:\WINDOWS\~tmp2205.exe
C:\WINDOWS\~tmp2207.exe
C:\WINDOWS\~tmp2208.exe
C:\WINDOWS\~tmp2209.exe
C:\WINDOWS\~tmp221.exe
C:\WINDOWS\~tmp2210.exe
C:\WINDOWS\~tmp2211.exe
C:\WINDOWS\~tmp2217.exe
C:\WINDOWS\~tmp2220.exe
C:\WINDOWS\~tmp2221.exe
C:\WINDOWS\~tmp2223.exe
C:\WINDOWS\~tmp2225.exe
C:\WINDOWS\~tmp2226.exe
C:\WINDOWS\~tmp2227.exe
C:\WINDOWS\~tmp223.exe
C:\WINDOWS\~tmp2230.exe
C:\WINDOWS\~tmp2232.exe
C:\WINDOWS\~tmp2234.exe
C:\WINDOWS\~tmp2236.exe
C:\WINDOWS\~tmp2237.exe
C:\WINDOWS\~tmp2239.exe
C:\WINDOWS\~tmp2241.exe
C:\WINDOWS\~tmp2243.exe
C:\WINDOWS\~tmp2246.exe
C:\WINDOWS\~tmp2248.exe
C:\WINDOWS\~tmp2249.exe
C:\WINDOWS\~tmp2250.exe
C:\WINDOWS\~tmp2252.exe
C:\WINDOWS\~tmp2254.exe
C:\WINDOWS\~tmp2255.exe
C:\WINDOWS\~tmp2256.exe
C:\WINDOWS\~tmp2259.exe
C:\WINDOWS\~tmp226.exe
C:\WINDOWS\~tmp2262.exe
C:\WINDOWS\~tmp2263.exe
C:\WINDOWS\~tmp2264.exe
C:\WINDOWS\~tmp2267.exe
C:\WINDOWS\~tmp2269.exe
C:\WINDOWS\~tmp2270.exe
C:\WINDOWS\~tmp2274.exe
C:\WINDOWS\~tmp2276.exe
C:\WINDOWS\~tmp2277.exe
C:\WINDOWS\~tmp2279.exe
C:\WINDOWS\~tmp2281.exe
C:\WINDOWS\~tmp2282.exe
C:\WINDOWS\~tmp2287.exe


----------



## MFDnNC (Sep 7, 2004)

You posted the first half twice - attach as I posted earlier


----------



## cpuanswers (Sep 25, 2007)

and another piece of combofix

C:
C:\WINDOWS\~tmp2277.exe
C:\WINDOWS\~tmp2279.exe
C:\WINDOWS\~tmp2281.exe
C:\WINDOWS\~tmp2282.exe
C:\WINDOWS\~tmp2287.exe


----------



## cpuanswers (Sep 25, 2007)

almost all of it...


C:\WINDOWS\~tmp2288.exe
C:\WINDOWS\~tmp229.exe
C:\WINDOWS\~tmp2290.exe
C:\WINDOWS\~tmp2291.exe
C:\WINDOWS\~tmp2293.exe
C:\WINDOWS\~tmp2294.exe
C:\WINDOWS\~tmp2296.exe
C:\WINDOWS\~tmp2297.exe
C:\WINDOWS\~tmp2299.exe
C:\WINDOWS\~tmp2301.exe
C:\WINDOWS\~tmp2304.exe
C:\WINDOWS\~tmp2305.exe
C:\WINDOWS\~tmp2309.exe
C:\WINDOWS\~tmp2310.exe
C:\WINDOWS\~tmp2313.exe
C:\WINDOWS\~tmp2314.exe
C:\WINDOWS\~tmp2316.exe
C:\WINDOWS\~tmp2318.exe
C:\WINDOWS\~tmp232.exe
C:\WINDOWS\~tmp2320.exe
C:\WINDOWS\~tmp2321.exe
C:\WINDOWS\~tmp2322.exe
C:\WINDOWS\~tmp2324.exe
C:\WINDOWS\~tmp2329.exe
C:\WINDOWS\~tmp233.exe
C:\WINDOWS\~tmp2330.exe
C:\WINDOWS\~tmp2333.exe
C:\WINDOWS\~tmp2335.exe
C:\WINDOWS\~tmp2338.exe
C:\WINDOWS\~tmp234.exe
C:\WINDOWS\~tmp2340.exe
C:\WINDOWS\~tmp2341.exe
C:\WINDOWS\~tmp2342.exe
C:\WINDOWS\~tmp2348.exe
C:\WINDOWS\~tmp2349.exe
C:\WINDOWS\~tmp235.exe
C:\WINDOWS\~tmp2356.exe
C:\WINDOWS\~tmp2357.exe
C:\WINDOWS\~tmp2362.exe
C:\WINDOWS\~tmp2363.exe
C:\WINDOWS\~tmp2365.exe
C:\WINDOWS\~tmp2367.exe
C:\WINDOWS\~tmp2368.exe
C:\WINDOWS\~tmp237.exe
C:\WINDOWS\~tmp2370.exe
C:\WINDOWS\~tmp2372.exe
C:\WINDOWS\~tmp2373.exe
C:\WINDOWS\~tmp2374.exe
C:\WINDOWS\~tmp2378.exe
C:\WINDOWS\~tmp2379.exe
C:\WINDOWS\~tmp238.exe
C:\WINDOWS\~tmp2381.exe
C:\WINDOWS\~tmp2390.exe
C:\WINDOWS\~tmp2391.exe
C:\WINDOWS\~tmp2392.exe
C:\WINDOWS\~tmp2395.exe
C:\WINDOWS\~tmp2398.exe
C:\WINDOWS\~tmp24.exe
C:\WINDOWS\~tmp240.exe
C:\WINDOWS\~tmp2402.exe
C:\WINDOWS\~tmp2404.exe
C:\WINDOWS\~tmp2407.exe
C:\WINDOWS\~tmp2409.exe
C:\WINDOWS\~tmp241.exe
C:\WINDOWS\~tmp2412.exe
C:\WINDOWS\~tmp2414.exe
C:\WINDOWS\~tmp2416.exe
C:\WINDOWS\~tmp2417.exe
C:\WINDOWS\~tmp2418.exe
C:\WINDOWS\~tmp2419.exe
C:\WINDOWS\~tmp2421.exe
C:\WINDOWS\~tmp2423.exe
C:\WINDOWS\~tmp2424.exe
C:\WINDOWS\~tmp2425.exe
C:\WINDOWS\~tmp2426.exe
C:\WINDOWS\~tmp2427.exe
C:\WINDOWS\~tmp2429.exe
C:\WINDOWS\~tmp2434.exe
C:\WINDOWS\~tmp2436.exe
C:\WINDOWS\~tmp2437.exe
C:\WINDOWS\~tmp2439.exe
C:\WINDOWS\~tmp2441.exe
C:\WINDOWS\~tmp2442.exe
C:\WINDOWS\~tmp2443.exe
C:\WINDOWS\~tmp2445.exe
C:\WINDOWS\~tmp2447.exe
C:\WINDOWS\~tmp2449.exe
C:\WINDOWS\~tmp245.exe
C:\WINDOWS\~tmp2451.exe
C:\WINDOWS\~tmp2455.exe
C:\WINDOWS\~tmp2458.exe
C:\WINDOWS\~tmp2461.exe
C:\WINDOWS\~tmp2465.exe
C:\WINDOWS\~tmp2467.exe
C:\WINDOWS\~tmp247.exe
C:\WINDOWS\~tmp2472.exe
C:\WINDOWS\~tmp2473.exe
C:\WINDOWS\~tmp2474.exe
C:\WINDOWS\~tmp2475.exe
C:\WINDOWS\~tmp2476.exe
C:\WINDOWS\~tmp2478.exe
C:\WINDOWS\~tmp2479.exe
C:\WINDOWS\~tmp248.exe
C:\WINDOWS\~tmp2484.exe
C:\WINDOWS\~tmp2485.exe
C:\WINDOWS\~tmp2488.exe
C:\WINDOWS\~tmp2489.exe
C:\WINDOWS\~tmp249.exe
C:\WINDOWS\~tmp2490.exe
C:\WINDOWS\~tmp2491.exe
C:\WINDOWS\~tmp2492.exe
C:\WINDOWS\~tmp2493.exe
C:\WINDOWS\~tmp2494.exe
C:\WINDOWS\~tmp2499.exe
C:\WINDOWS\~tmp25.exe
C:\WINDOWS\~tmp2500.exe
C:\WINDOWS\~tmp2501.exe
C:\WINDOWS\~tmp2502.exe
C:\WINDOWS\~tmp2505.exe
C:\WINDOWS\~tmp2506.exe
C:\WINDOWS\~tmp2507.exe
C:\WINDOWS\~tmp2508.exe
C:\WINDOWS\~tmp251.exe
C:\WINDOWS\~tmp2512.exe
C:\WINDOWS\~tmp2517.exe
C:\WINDOWS\~tmp2519.exe
C:\WINDOWS\~tmp252.exe
C:\WINDOWS\~tmp2520.exe
C:\WINDOWS\~tmp2522.exe
C:\WINDOWS\~tmp2523.exe
C:\WINDOWS\~tmp2524.exe
C:\WINDOWS\~tmp2525.exe
C:\WINDOWS\~tmp2526.exe
C:\WINDOWS\~tmp2527.exe
C:\WINDOWS\~tmp2528.exe
C:\WINDOWS\~tmp2529.exe
C:\WINDOWS\~tmp253.exe
C:\WINDOWS\~tmp2530.exe
C:\WINDOWS\~tmp2533.exe
C:\WINDOWS\~tmp2534.exe
C:\WINDOWS\~tmp2540.exe
C:\WINDOWS\~tmp2541.exe
C:\WINDOWS\~tmp2542.exe
C:\WINDOWS\~tmp2544.exe
C:\WINDOWS\~tmp2545.exe
C:\WINDOWS\~tmp2547.exe
C:\WINDOWS\~tmp2550.exe
C:\WINDOWS\~tmp2553.exe
C:\WINDOWS\~tmp2556.exe
C:\WINDOWS\~tmp2557.exe
C:\WINDOWS\~tmp2558.exe
C:\WINDOWS\~tmp256.exe
C:\WINDOWS\~tmp2561.exe
C:\WINDOWS\~tmp2562.exe
C:\WINDOWS\~tmp2564.exe
C:\WINDOWS\~tmp2565.exe
C:\WINDOWS\~tmp2567.exe
C:\WINDOWS\~tmp257.exe
C:\WINDOWS\~tmp2571.exe
C:\WINDOWS\~tmp2574.exe
C:\WINDOWS\~tmp2575.exe
C:\WINDOWS\~tmp2577.exe
C:\WINDOWS\~tmp2578.exe
C:\WINDOWS\~tmp2581.exe
C:\WINDOWS\~tmp2589.exe
C:\WINDOWS\~tmp259.exe
C:\WINDOWS\~tmp2590.exe
C:\WINDOWS\~tmp2593.exe
C:\WINDOWS\~tmp2596.exe
C:\WINDOWS\~tmp2597.exe
C:\WINDOWS\~tmp260.exe
C:\WINDOWS\~tmp2600.exe
C:\WINDOWS\~tmp2601.exe
C:\WINDOWS\~tmp2602.exe
C:\WINDOWS\~tmp2604.exe
C:\WINDOWS\~tmp2606.exe
C:\WINDOWS\~tmp2609.exe
C:\WINDOWS\~tmp2613.exe
C:\WINDOWS\~tmp2615.exe
C:\WINDOWS\~tmp2616.exe
C:\WINDOWS\~tmp2617.exe
C:\WINDOWS\~tmp2618.exe
C:\WINDOWS\~tmp2622.exe
C:\WINDOWS\~tmp2623.exe
C:\WINDOWS\~tmp2624.exe
C:\WINDOWS\~tmp2627.exe
C:\WINDOWS\~tmp2628.exe
C:\WINDOWS\~tmp263.exe
C:\WINDOWS\~tmp2630.exe
C:\WINDOWS\~tmp2631.exe
C:\WINDOWS\~tmp2632.exe
C:\WINDOWS\~tmp2634.exe
C:\WINDOWS\~tmp2638.exe
C:\WINDOWS\~tmp2642.exe
C:\WINDOWS\~tmp2643.exe
C:\WINDOWS\~tmp2645.exe
C:\WINDOWS\~tmp2646.exe
C:\WINDOWS\~tmp2647.exe
C:\WINDOWS\~tmp2648.exe
C:\WINDOWS\~tmp2649.exe
C:\WINDOWS\~tmp2650.exe
C:\WINDOWS\~tmp2651.exe
C:\WINDOWS\~tmp2655.exe
C:\WINDOWS\~tmp2656.exe
C:\WINDOWS\~tmp2657.exe
C:\WINDOWS\~tmp266.exe
C:\WINDOWS\~tmp2660.exe
C:\WINDOWS\~tmp2662.exe
C:\WINDOWS\~tmp2663.exe
C:\WINDOWS\~tmp2664.exe
C:\WINDOWS\~tmp2666.exe
C:\WINDOWS\~tmp2670.exe
C:\WINDOWS\~tmp2671.exe
C:\WINDOWS\~tmp2674.exe
C:\WINDOWS\~tmp2678.exe
C:\WINDOWS\~tmp268.exe
C:\WINDOWS\~tmp2680.exe
C:\WINDOWS\~tmp2688.exe
C:\WINDOWS\~tmp2689.exe
C:\WINDOWS\~tmp269.exe
C:\WINDOWS\~tmp2691.exe
C:\WINDOWS\~tmp2692.exe
C:\WINDOWS\~tmp2693.exe
C:\WINDOWS\~tmp2695.exe
C:\WINDOWS\~tmp2696.exe
C:\WINDOWS\~tmp2699.exe
C:\WINDOWS\~tmp27.exe
C:\WINDOWS\~tmp2701.exe
C:\WINDOWS\~tmp2703.exe
C:\WINDOWS\~tmp2704.exe
C:\WINDOWS\~tmp2706.exe
C:\WINDOWS\~tmp2708.exe
C:\WINDOWS\~tmp2709.exe
C:\WINDOWS\~tmp271.exe
C:\WINDOWS\~tmp2711.exe
C:\WINDOWS\~tmp2713.exe
C:\WINDOWS\~tmp2714.exe
C:\WINDOWS\~tmp2718.exe
C:\WINDOWS\~tmp2719.exe
C:\WINDOWS\~tmp272.exe
C:\WINDOWS\~tmp2720.exe
C:\WINDOWS\~tmp2721.exe
C:\WINDOWS\~tmp2722.exe
C:\WINDOWS\~tmp2725.exe
C:\WINDOWS\~tmp2727.exe
C:\WINDOWS\~tmp2728.exe
C:\WINDOWS\~tmp2729.exe
C:\WINDOWS\~tmp2731.exe
C:\WINDOWS\~tmp2732.exe
C:\WINDOWS\~tmp2737.exe
C:\WINDOWS\~tmp274.exe
C:\WINDOWS\~tmp2740.exe
C:\WINDOWS\~tmp2741.exe
C:\WINDOWS\~tmp2742.exe
C:\WINDOWS\~tmp2744.exe
C:\WINDOWS\~tmp2746.exe
C:\WINDOWS\~tmp2747.exe
C:\WINDOWS\~tmp2749.exe
C:\WINDOWS\~tmp275.exe
C:\WINDOWS\~tmp2750.exe
C:\WINDOWS\~tmp2753.exe
C:\WINDOWS\~tmp2757.exe
C:\WINDOWS\~tmp2759.exe
C:\WINDOWS\~tmp276.exe
C:\WINDOWS\~tmp2760.exe
C:\WINDOWS\~tmp2761.exe
C:\WINDOWS\~tmp2763.exe
C:\WINDOWS\~tmp2764.exe
C:\WINDOWS\~tmp2765.exe
C:\WINDOWS\~tmp2766.exe
C:\WINDOWS\~tmp2770.exe
C:\WINDOWS\~tmp2771.exe
C:\WINDOWS\~tmp2772.exe
C:\WINDOWS\~tmp2773.exe
C:\WINDOWS\~tmp2776.exe
C:\WINDOWS\~tmp2777.exe
C:\WINDOWS\~tmp2780.exe
C:\WINDOWS\~tmp2781.exe
C:\WINDOWS\~tmp2782.exe
C:\WINDOWS\~tmp2783.exe
C:\WINDOWS\~tmp2786.exe
C:\WINDOWS\~tmp2787.exe
C:\WINDOWS\~tmp2789.exe
C:\WINDOWS\~tmp279.exe
C:\WINDOWS\~tmp2791.exe
C:\WINDOWS\~tmp2792.exe
C:\WINDOWS\~tmp2793.exe
C:\WINDOWS\~tmp2794.exe
C:\WINDOWS\~tmp2796.exe
C:\WINDOWS\~tmp2797.exe
C:\WINDOWS\~tmp2799.exe
C:\WINDOWS\~tmp280.exe
C:\WINDOWS\~tmp2800.exe
C:\WINDOWS\~tmp2801.exe
C:\WINDOWS\~tmp2802.exe
C:\WINDOWS\~tmp2803.exe
C:\WINDOWS\~tmp2804.exe
C:\WINDOWS\~tmp2805.exe
C:\WINDOWS\~tmp2806.exe
C:\WINDOWS\~tmp2807.exe
C:\WINDOWS\~tmp2808.exe
C:\WINDOWS\~tmp281.exe
C:\WINDOWS\~tmp2810.exe
C:\WINDOWS\~tmp2811.exe
C:\WINDOWS\~tmp2812.exe
C:\WINDOWS\~tmp2813.exe
C:\WINDOWS\~tmp2814.exe
C:\WINDOWS\~tmp2815.exe
C:\WINDOWS\~tmp2816.exe
C:\WINDOWS\~tmp2817.exe
C:\WINDOWS\~tmp2818.exe
C:\WINDOWS\~tmp2820.exe
C:\WINDOWS\~tmp2822.exe
C:\WINDOWS\~tmp2826.exe
C:\WINDOWS\~tmp2827.exe
C:\WINDOWS\~tmp2831.exe
C:\WINDOWS\~tmp2832.exe
C:\WINDOWS\~tmp2833.exe
C:\WINDOWS\~tmp2836.exe
C:\WINDOWS\~tmp2837.exe
C:\WINDOWS\~tmp2839.exe
C:\WINDOWS\~tmp284.exe
C:\WINDOWS\~tmp2840.exe
C:\WINDOWS\~tmp2841.exe
C:\WINDOWS\~tmp2843.exe
C:\WINDOWS\~tmp2847.exe
C:\WINDOWS\~tmp2851.exe
C:\WINDOWS\~tmp2858.exe
C:\WINDOWS\~tmp2859.exe
C:\WINDOWS\~tmp286.exe
C:\WINDOWS\~tmp2861.exe
C:\WINDOWS\~tmp2862.exe
C:\WINDOWS\~tmp2866.exe
C:\WINDOWS\~tmp2868.exe
C:\WINDOWS\~tmp2872.exe
C:\WINDOWS\~tmp2873.exe
C:\WINDOWS\~tmp2874.exe
C:\WINDOWS\~tmp2875.exe
C:\WINDOWS\~tmp2877.exe
C:\WINDOWS\~tmp2878.exe
C:\WINDOWS\~tmp288.exe
C:\WINDOWS\~tmp2881.exe
C:\WINDOWS\~tmp2882.exe
C:\WINDOWS\~tmp2883.exe
C:\WINDOWS\~tmp2884.exe
C:\WINDOWS\~tmp2885.exe
C:\WINDOWS\~tmp2886.exe
C:\WINDOWS\~tmp2888.exe
C:\WINDOWS\~tmp289.exe
C:\WINDOWS\~tmp2890.exe
C:\WINDOWS\~tmp2891.exe
C:\WINDOWS\~tmp2893.exe
C:\WINDOWS\~tmp2894.exe
C:\WINDOWS\~tmp2895.exe
C:\WINDOWS\~tmp2897.exe
C:\WINDOWS\~tmp29.exe
C:\WINDOWS\~tmp290.exe
C:\WINDOWS\~tmp2902.exe
C:\WINDOWS\~tmp2904.exe
C:\WINDOWS\~tmp2906.exe
C:\WINDOWS\~tmp2907.exe
C:\WINDOWS\~tmp2908.exe
C:\WINDOWS\~tmp2909.exe
C:\WINDOWS\~tmp291.exe
C:\WINDOWS\~tmp2911.exe
C:\WINDOWS\~tmp2913.exe
C:\WINDOWS\~tmp2915.exe
C:\WINDOWS\~tmp2917.exe
C:\WINDOWS\~tmp2919.exe
C:\WINDOWS\~tmp2921.exe
C:\WINDOWS\~tmp2922.exe
C:\WINDOWS\~tmp2923.exe
C:\WINDOWS\~tmp2924.exe
C:\WINDOWS\~tmp2925.exe
C:\WINDOWS\~tmp2926.exe
C:\WINDOWS\~tmp2927.exe
C:\WINDOWS\~tmp2929.exe
C:\WINDOWS\~tmp293.exe
C:\WINDOWS\~tmp2931.exe
C:\WINDOWS\~tmp2932.exe
C:\WINDOWS\~tmp2933.exe
C:\WINDOWS\~tmp2934.exe
C:\WINDOWS\~tmp2937.exe
C:\WINDOWS\~tmp2939.exe
C:\WINDOWS\~tmp2943.exe
C:\WINDOWS\~tmp2944.exe
C:\WINDOWS\~tmp2945.exe
C:\WINDOWS\~tmp2949.exe
C:\WINDOWS\~tmp2950.exe
C:\WINDOWS\~tmp2953.exe
C:\WINDOWS\~tmp2954.exe
C:\WINDOWS\~tmp2956.exe
C:\WINDOWS\~tmp2957.exe
C:\WINDOWS\~tmp2958.exe
C:\WINDOWS\~tmp2959.exe
C:\WINDOWS\~tmp296.exe
C:\WINDOWS\~tmp2960.exe
C:\WINDOWS\~tmp2961.exe
C:\WINDOWS\~tmp2962.exe
C:\WINDOWS\~tmp2965.exe
C:\WINDOWS\~tmp2969.exe
C:\WINDOWS\~tmp297.exe
C:\WINDOWS\~tmp2970.exe
C:\WINDOWS\~tmp2971.exe
C:\WINDOWS\~tmp2972.exe
C:\WINDOWS\~tmp2975.exe
C:\WINDOWS\~tmp2977.exe
C:\WINDOWS\~tmp2978.exe
C:\WINDOWS\~tmp2979.exe
C:\WINDOWS\~tmp298.exe
C:\WINDOWS\~tmp2980.exe
C:\WINDOWS\~tmp2982.exe
C:\WINDOWS\~tmp2983.exe
C:\WINDOWS\~tmp2985.exe
C:\WINDOWS\~tmp2987.exe
C:\WINDOWS\~tmp2988.exe
C:\WINDOWS\~tmp2989.exe
C:\WINDOWS\~tmp2991.exe
C:\WINDOWS\~tmp2992.exe
C:\WINDOWS\~tmp2996.exe
C:\WINDOWS\~tmp2997.exe
C:\WINDOWS\~tmp2999.exe
C:\WINDOWS\~tmp3.exe
C:\WINDOWS\~tmp3001.exe
C:\WINDOWS\~tmp3002.exe
C:\WINDOWS\~tmp3003.exe
C:\WINDOWS\~tmp3005.exe
C:\WINDOWS\~tmp3006.exe
C:\WINDOWS\~tmp3008.exe
C:\WINDOWS\~tmp3010.exe
C:\WINDOWS\~tmp3012.exe
C:\WINDOWS\~tmp3013.exe
C:\WINDOWS\~tmp3015.exe
C:\WINDOWS\~tmp3018.exe
C:\WINDOWS\~tmp3023.exe
C:\WINDOWS\~tmp3025.exe
C:\WINDOWS\~tmp3026.exe
C:\WINDOWS\~tmp3029.exe
C:\WINDOWS\~tmp303.exe
C:\WINDOWS\~tmp3030.exe
C:\WINDOWS\~tmp3032.exe
C:\WINDOWS\~tmp3033.exe
C:\WINDOWS\~tmp3034.exe
C:\WINDOWS\~tmp3035.exe
C:\WINDOWS\~tmp3037.exe
C:\WINDOWS\~tmp3039.exe
C:\WINDOWS\~tmp304.exe
C:\WINDOWS\~tmp3040.exe
C:\WINDOWS\~tmp3041.exe
C:\WINDOWS\~tmp3042.exe
C:\WINDOWS\~tmp3043.exe
C:\WINDOWS\~tmp3044.exe
C:\WINDOWS\~tmp3046.exe
C:\WINDOWS\~tmp3048.exe
C:\WINDOWS\~tmp3049.exe
C:\WINDOWS\~tmp305.exe
C:\WINDOWS\~tmp3050.exe
C:\WINDOWS\~tmp3051.exe
C:\WINDOWS\~tmp3052.exe
C:\WINDOWS\~tmp3053.exe
C:\WINDOWS\~tmp3055.exe
C:\WINDOWS\~tmp3057.exe
C:\WINDOWS\~tmp3059.exe
C:\WINDOWS\~tmp3060.exe
C:\WINDOWS\~tmp3062.exe
C:\WINDOWS\~tmp3064.exe
C:\WINDOWS\~tmp3066.exe
C:\WINDOWS\~tmp3067.exe
C:\WINDOWS\~tmp3068.exe
C:\WINDOWS\~tmp3069.exe
C:\WINDOWS\~tmp3070.exe
C:\WINDOWS\~tmp3071.exe
C:\WINDOWS\~tmp3073.exe
C:\WINDOWS\~tmp3074.exe
C:\WINDOWS\~tmp3075.exe
C:\WINDOWS\~tmp3076.exe
C:\WINDOWS\~tmp3078.exe
C:\WINDOWS\~tmp3079.exe
C:\WINDOWS\~tmp308.exe
C:\WINDOWS\~tmp3080.exe
C:\WINDOWS\~tmp3087.exe
C:\WINDOWS\~tmp3089.exe
C:\WINDOWS\~tmp309.exe
C:\WINDOWS\~tmp3092.exe
C:\WINDOWS\~tmp3093.exe
C:\WINDOWS\~tmp3095.exe
C:\WINDOWS\~tmp3097.exe
C:\WINDOWS\~tmp3098.exe
C:\WINDOWS\~tmp31.exe
C:\WINDOWS\~tmp3103.exe
C:\WINDOWS\~tmp3106.exe
C:\WINDOWS\~tmp3108.exe
C:\WINDOWS\~tmp3110.exe
C:\WINDOWS\~tmp3111.exe
C:\WINDOWS\~tmp3113.exe
C:\WINDOWS\~tmp3114.exe
C:\WINDOWS\~tmp3115.exe
C:\WINDOWS\~tmp3116.exe
C:\WINDOWS\~tmp312.exe
C:\WINDOWS\~tmp3120.exe
C:\WINDOWS\~tmp3123.exe
C:\WINDOWS\~tmp3124.exe
C:\WINDOWS\~tmp3126.exe
C:\WINDOWS\~tmp3129.exe
C:\WINDOWS\~tmp3130.exe
C:\WINDOWS\~tmp3132.exe
C:\WINDOWS\~tmp3133.exe
C:\WINDOWS\~tmp3135.exe
C:\WINDOWS\~tmp3136.exe
C:\WINDOWS\~tmp3138.exe
C:\WINDOWS\~tmp314.exe
C:\WINDOWS\~tmp3140.exe
C:\WINDOWS\~tmp3143.exe
C:\WINDOWS\~tmp3145.exe
C:\WINDOWS\~tmp3148.exe
C:\WINDOWS\~tmp3149.exe
C:\WINDOWS\~tmp315.exe
C:\WINDOWS\~tmp3150.exe
C:\WINDOWS\~tmp3151.exe
C:\WINDOWS\~tmp3153.exe
C:\WINDOWS\~tmp3154.exe
C:\WINDOWS\~tmp3155.exe
C:\WINDOWS\~tmp3156.exe
C:\WINDOWS\~tmp3157.exe
C:\WINDOWS\~tmp3158.exe
C:\WINDOWS\~tmp3159.exe
C:\WINDOWS\~tmp3160.exe
C:\WINDOWS\~tmp3162.exe
C:\WINDOWS\~tmp3163.exe
C:\WINDOWS\~tmp3164.exe
C:\WINDOWS\~tmp3165.exe
C:\WINDOWS\~tmp3166.exe
C:\WINDOWS\~tmp3167.exe
C:\WINDOWS\~tmp3170.exe
C:\WINDOWS\~tmp3172.exe
C:\WINDOWS\~tmp3173.exe
C:\WINDOWS\~tmp3174.exe
C:\WINDOWS\~tmp3176.exe
C:\WINDOWS\~tmp3178.exe
C:\WINDOWS\~tmp318.exe
C:\WINDOWS\~tmp3184.exe
C:\WINDOWS\~tmp3185.exe
C:\WINDOWS\~tmp3186.exe
C:\WINDOWS\~tmp3188.exe
C:\WINDOWS\~tmp319.exe
C:\WINDOWS\~tmp3190.exe
C:\WINDOWS\~tmp3193.exe
C:\WINDOWS\~tmp3195.exe
C:\WINDOWS\~tmp3198.exe
C:\WINDOWS\~tmp32.exe
C:\WINDOWS\~tmp320.exe
C:\WINDOWS\~tmp3200.exe
C:\WINDOWS\~tmp3201.exe
C:\WINDOWS\~tmp3202.exe
C:\WINDOWS\~tmp3203.exe
C:\WINDOWS\~tmp3205.exe
C:\WINDOWS\~tmp3209.exe
C:\WINDOWS\~tmp321.exe
C:\WINDOWS\~tmp3210.exe
C:\WINDOWS\~tmp3211.exe
C:\WINDOWS\~tmp3212.exe
C:\WINDOWS\~tmp3213.exe
C:\WINDOWS\~tmp3215.exe
C:\WINDOWS\~tmp3216.exe
C:\WINDOWS\~tmp3217.exe
C:\WINDOWS\~tmp3218.exe
C:\WINDOWS\~tmp322.exe
C:\WINDOWS\~tmp3225.exe
C:\WINDOWS\~tmp3227.exe
C:\WINDOWS\~tmp3229.exe
C:\WINDOWS\~tmp323.exe
C:\WINDOWS\~tmp3231.exe
C:\WINDOWS\~tmp3234.exe
C:\WINDOWS\~tmp3235.exe
C:\WINDOWS\~tmp3238.exe
C:\WINDOWS\~tmp324.exe
C:\WINDOWS\~tmp3241.exe
C:\WINDOWS\~tmp3242.exe
C:\WINDOWS\~tmp3248.exe
C:\WINDOWS\~tmp3249.exe
C:\WINDOWS\~tmp3251.exe
C:\WINDOWS\~tmp3252.exe
C:\WINDOWS\~tmp3253.exe
C:\WINDOWS\~tmp3255.exe
C:\WINDOWS\~tmp3256.exe
C:\WINDOWS\~tmp3257.exe
C:\WINDOWS\~tmp3258.exe
C:\WINDOWS\~tmp3261.exe
C:\WINDOWS\~tmp3262.exe
C:\WINDOWS\~tmp3265.exe
C:\WINDOWS\~tmp3268.exe
C:\WINDOWS\~tmp3269.exe
C:\WINDOWS\~tmp327.exe
C:\WINDOWS\~tmp3270.exe
C:\WINDOWS\~tmp3271.exe
C:\WINDOWS\~tmp3273.exe
C:\WINDOWS\~tmp3275.exe
C:\WINDOWS\~tmp3276.exe
C:\WINDOWS\~tmp3277.exe
C:\WINDOWS\~tmp3278.exe
C:\WINDOWS\~tmp3282.exe
C:\WINDOWS\~tmp3283.exe
C:\WINDOWS\~tmp3287.exe
C:\WINDOWS\~tmp329.exe
C:\WINDOWS\~tmp3291.exe
C:\WINDOWS\~tmp3296.exe
C:\WINDOWS\~tmp3299.exe
C:\WINDOWS\~tmp3303.exe
C:\WINDOWS\~tmp3304.exe
C:\WINDOWS\~tmp3305.exe
C:\WINDOWS\~tmp3306.exe
C:\WINDOWS\~tmp3308.exe
C:\WINDOWS\~tmp3309.exe
C:\WINDOWS\~tmp3310.exe
C:\WINDOWS\~tmp3311.exe
C:\WINDOWS\~tmp3312.exe
C:\WINDOWS\~tmp3313.exe
C:\WINDOWS\~tmp3315.exe
C:\WINDOWS\~tmp3317.exe
C:\WINDOWS\~tmp3321.exe
C:\WINDOWS\~tmp3325.exe
C:\WINDOWS\~tmp3328.exe
C:\WINDOWS\~tmp3329.exe
C:\WINDOWS\~tmp3331.exe
C:\WINDOWS\~tmp3332.exe
C:\WINDOWS\~tmp3333.exe
C:\WINDOWS\~tmp3335.exe
C:\WINDOWS\~tmp3336.exe
C:\WINDOWS\~tmp3337.exe
C:\WINDOWS\~tmp3341.exe
C:\WINDOWS\~tmp3342.exe
C:\WINDOWS\~tmp3343.exe
C:\WINDOWS\~tmp3344.exe
C:\WINDOWS\~tmp3345.exe
C:\WINDOWS\~tmp3346.exe
C:\WINDOWS\~tmp335.exe
C:\WINDOWS\~tmp3350.exe
C:\WINDOWS\~tmp3351.exe
C:\WINDOWS\~tmp3352.exe
C:\WINDOWS\~tmp3353.exe
C:\WINDOWS\~tmp3358.exe
C:\WINDOWS\~tmp3359.exe
C:\WINDOWS\~tmp336.exe
C:\WINDOWS\~tmp3361.exe
C:\WINDOWS\~tmp3362.exe
C:\WINDOWS\~tmp3363.exe
C:\WINDOWS\~tmp3364.exe
C:\WINDOWS\~tmp3365.exe
C:\WINDOWS\~tmp3366.exe
C:\WINDOWS\~tmp3368.exe
C:\WINDOWS\~tmp3369.exe
C:\WINDOWS\~tmp3371.exe
C:\WINDOWS\~tmp3372.exe
C:\WINDOWS\~tmp3373.exe
C:\WINDOWS\~tmp3374.exe
C:\WINDOWS\~tmp3375.exe
C:\WINDOWS\~tmp3377.exe
C:\WINDOWS\~tmp3379.exe
C:\WINDOWS\~tmp338.exe
C:\WINDOWS\~tmp3381.exe
C:\WINDOWS\~tmp3388.exe
C:\WINDOWS\~tmp3389.exe
C:\WINDOWS\~tmp339.exe
C:\WINDOWS\~tmp3392.exe
C:\WINDOWS\~tmp3393.exe
C:\WINDOWS\~tmp3394.exe
C:\WINDOWS\~tmp3398.exe
C:\WINDOWS\~tmp3399.exe
C:\WINDOWS\~tmp340.exe
C:\WINDOWS\~tmp3400.exe
C:\WINDOWS\~tmp3402.exe
C:\WINDOWS\~tmp3404.exe
C:\WINDOWS\~tmp3405.exe
C:\WINDOWS\~tmp341.exe
C:\WINDOWS\~tmp3410.exe
C:\WINDOWS\~tmp3411.exe
C:\WINDOWS\~tmp3413.exe
C:\WINDOWS\~tmp3416.exe
C:\WINDOWS\~tmp3417.exe
C:\WINDOWS\~tmp3419.exe
C:\WINDOWS\~tmp342.exe
C:\WINDOWS\~tmp3420.exe
C:\WINDOWS\~tmp3422.exe
C:\WINDOWS\~tmp3424.exe
C:\WINDOWS\~tmp3425.exe
C:\WINDOWS\~tmp3426.exe
C:\WINDOWS\~tmp3427.exe
C:\WINDOWS\~tmp3428.exe
C:\WINDOWS\~tmp343.exe
C:\WINDOWS\~tmp3432.exe
C:\WINDOWS\~tmp3433.exe
C:\WINDOWS\~tmp3434.exe
C:\WINDOWS\~tmp3435.exe
C:\WINDOWS\~tmp3436.exe
C:\WINDOWS\~tmp3437.exe
C:\WINDOWS\~tmp3438.exe
C:\WINDOWS\~tmp344.exe
C:\WINDOWS\~tmp3442.exe
C:\WINDOWS\~tmp3443.exe
C:\WINDOWS\~tmp3444.exe
C:\WINDOWS\~tmp3445.exe
C:\WINDOWS\~tmp3449.exe
C:\WINDOWS\~tmp345.exe
C:\WINDOWS\~tmp3453.exe
C:\WINDOWS\~tmp3454.exe
C:\WINDOWS\~tmp346.exe
C:\WINDOWS\~tmp3460.exe
C:\WINDOWS\~tmp3464.exe
C:\WINDOWS\~tmp3468.exe
C:\WINDOWS\~tmp347.exe
C:\WINDOWS\~tmp3471.exe
C:\WINDOWS\~tmp3472.exe
C:\WINDOWS\~tmp3473.exe
C:\WINDOWS\~tmp3474.exe
C:\WINDOWS\~tmp3475.exe
C:\WINDOWS\~tmp3476.exe
C:\WINDOWS\~tmp3477.exe
C:\WINDOWS\~tmp3478.exe
C:\WINDOWS\~tmp3481.exe
C:\WINDOWS\~tmp3483.exe
C:\WINDOWS\~tmp3485.exe
C:\WINDOWS\~tmp3486.exe
C:\WINDOWS\~tmp3487.exe
C:\WINDOWS\~tmp3488.exe
C:\WINDOWS\~tmp349.exe
C:\WINDOWS\~tmp3490.exe
C:\WINDOWS\~tmp3491.exe
C:\WINDOWS\~tmp3492.exe
C:\WINDOWS\~tmp3493.exe
C:\WINDOWS\~tmp3494.exe
C:\WINDOWS\~tmp3496.exe
C:\WINDOWS\~tmp3497.exe
C:\WINDOWS\~tmp3499.exe
C:\WINDOWS\~tmp35.exe
C:\WINDOWS\~tmp350.exe
C:\WINDOWS\~tmp3501.exe
C:\WINDOWS\~tmp3502.exe
C:\WINDOWS\~tmp3503.exe
C:\WINDOWS\~tmp3504.exe
C:\WINDOWS\~tmp3505.exe
C:\WINDOWS\~tmp3507.exe
C:\WINDOWS\~tmp3508.exe
C:\WINDOWS\~tmp3509.exe
C:\WINDOWS\~tmp3511.exe
C:\WINDOWS\~tmp3512.exe
C:\WINDOWS\~tmp3515.exe
C:\WINDOWS\~tmp3519.exe
C:\WINDOWS\~tmp352.exe
C:\WINDOWS\~tmp3520.exe
C:\WINDOWS\~tmp3521.exe
C:\WINDOWS\~tmp3523.exe
C:\WINDOWS\~tmp3524.exe
C:\WINDOWS\~tmp3525.exe
C:\WINDOWS\~tmp3527.exe
C:\WINDOWS\~tmp353.exe
C:\WINDOWS\~tmp3532.exe
C:\WINDOWS\~tmp3533.exe
C:\WINDOWS\~tmp3534.exe
C:\WINDOWS\~tmp3535.exe
C:\WINDOWS\~tmp3536.exe
C:\WINDOWS\~tmp3538.exe
C:\WINDOWS\~tmp3539.exe
C:\WINDOWS\~tmp354.exe
C:\WINDOWS\~tmp3540.exe
C:\WINDOWS\~tmp3542.exe
C:\WINDOWS\~tmp3547.exe
C:\WINDOWS\~tmp3550.exe
C:\WINDOWS\~tmp3551.exe
C:\WINDOWS\~tmp3552.exe
C:\WINDOWS\~tmp3556.exe
C:\WINDOWS\~tmp3560.exe
C:\WINDOWS\~tmp3561.exe
C:\WINDOWS\~tmp3563.exe
C:\WINDOWS\~tmp3564.exe
C:\WINDOWS\~tmp3565.exe
C:\WINDOWS\~tmp3566.exe
C:\WINDOWS\~tmp3567.exe
C:\WINDOWS\~tmp3568.exe
C:\WINDOWS\~tmp3569.exe
C:\WINDOWS\~tmp3570.exe
C:\WINDOWS\~tmp3571.exe
C:\WINDOWS\~tmp3572.exe
C:\WINDOWS\~tmp3573.exe
C:\WINDOWS\~tmp3574.exe
C:\WINDOWS\~tmp3575.exe
C:\WINDOWS\~tmp3581.exe
C:\WINDOWS\~tmp3582.exe
C:\WINDOWS\~tmp3584.exe
C:\WINDOWS\~tmp3585.exe
C:\WINDOWS\~tmp3586.exe
C:\WINDOWS\~tmp3587.exe
C:\WINDOWS\~tmp3588.exe
C:\WINDOWS\~tmp359.exe
C:\WINDOWS\~tmp3590.exe
C:\WINDOWS\~tmp3591.exe
C:\WINDOWS\~tmp3593.exe
C:\WINDOWS\~tmp3594.exe
C:\WINDOWS\~tmp3595.exe
C:\WINDOWS\~tmp3596.exe
C:\WINDOWS\~tmp3598.exe
C:\WINDOWS\~tmp3601.exe
C:\WINDOWS\~tmp3602.exe
C:\WINDOWS\~tmp3606.exe
C:\WINDOWS\~tmp3607.exe
C:\WINDOWS\~tmp3610.exe
C:\WINDOWS\~tmp3613.exe
C:\WINDOWS\~tmp3616.exe
C:\WINDOWS\~tmp362.exe
C:\WINDOWS\~tmp3621.exe
C:\WINDOWS\~tmp3625.exe
C:\WINDOWS\~tmp3627.exe
C:\WINDOWS\~tmp3628.exe
C:\WINDOWS\~tmp3631.exe
C:\WINDOWS\~tmp3632.exe
C:\WINDOWS\~tmp3633.exe
C:\WINDOWS\~tmp3635.exe
C:\WINDOWS\~tmp3636.exe
C:\WINDOWS\~tmp3637.exe
C:\WINDOWS\~tmp3638.exe
C:\WINDOWS\~tmp364.exe
C:\WINDOWS\~tmp3640.exe
C:\WINDOWS\~tmp3642.exe
C:\WINDOWS\~tmp3643.exe
C:\WINDOWS\~tmp3644.exe
C:\WINDOWS\~tmp3646.exe
C:\WINDOWS\~tmp3647.exe
C:\WINDOWS\~tmp3648.exe
C:\WINDOWS\~tmp3649.exe
C:\WINDOWS\~tmp3655.exe
C:\WINDOWS\~tmp3658.exe
C:\WINDOWS\~tmp3659.exe
C:\WINDOWS\~tmp366.exe
C:\WINDOWS\~tmp3661.exe
C:\WINDOWS\~tmp3662.exe
C:\WINDOWS\~tmp3664.exe
C:\WINDOWS\~tmp3665.exe
C:\WINDOWS\~tmp3666.exe
C:\WINDOWS\~tmp3667.exe
C:\WINDOWS\~tmp3669.exe
C:\WINDOWS\~tmp3671.exe
C:\WINDOWS\~tmp3672.exe
C:\WINDOWS\~tmp3673.exe
C:\WINDOWS\~tmp3674.exe
C:\WINDOWS\~tmp3675.exe
C:\WINDOWS\~tmp3676.exe
C:\WINDOWS\~tmp3679.exe
C:\WINDOWS\~tmp3680.exe
C:\WINDOWS\~tmp3681.exe
C:\WINDOWS\~tmp3682.exe
C:\WINDOWS\~tmp3686.exe
C:\WINDOWS\~tmp3687.exe
C:\WINDOWS\~tmp3688.exe
C:\WINDOWS\~tmp3689.exe
C:\WINDOWS\~tmp3690.exe
C:\WINDOWS\~tmp3691.exe
C:\WINDOWS\~tmp3693.exe
C:\WINDOWS\~tmp3694.exe
C:\WINDOWS\~tmp3695.exe
C:\WINDOWS\~tmp3696.exe
C:\WINDOWS\~tmp3699.exe
C:\WINDOWS\~tmp37.exe
C:\WINDOWS\~tmp3700.exe
C:\WINDOWS\~tmp3702.exe
C:\WINDOWS\~tmp3705.exe
C:\WINDOWS\~tmp3707.exe
C:\WINDOWS\~tmp3708.exe
C:\WINDOWS\~tmp3709.exe
C:\WINDOWS\~tmp3711.exe
C:\WINDOWS\~tmp3712.exe
C:\WINDOWS\~tmp3715.exe
C:\WINDOWS\~tmp3717.exe
C:\WINDOWS\~tmp3719.exe
C:\WINDOWS\~tmp3723.exe
C:\WINDOWS\~tmp3725.exe
C:\WINDOWS\~tmp3728.exe
C:\WINDOWS\~tmp373.exe
C:\WINDOWS\~tmp3731.exe
C:\WINDOWS\~tmp3734.exe
C:\WINDOWS\~tmp3737.exe
C:\WINDOWS\~tmp3739.exe
C:\WINDOWS\~tmp3740.exe
C:\WINDOWS\~tmp3741.exe
C:\WINDOWS\~tmp3742.exe
C:\WINDOWS\~tmp3743.exe
C:\WINDOWS\~tmp3744.exe
C:\WINDOWS\~tmp3746.exe
C:\WINDOWS\~tmp3748.exe
C:\WINDOWS\~tmp3749.exe
C:\WINDOWS\~tmp3752.exe
C:\WINDOWS\~tmp3754.exe
C:\WINDOWS\~tmp3757.exe
C:\WINDOWS\~tmp3759.exe
C:\WINDOWS\~tmp3763.exe
C:\WINDOWS\~tmp3764.exe
C:\WINDOWS\~tmp3765.exe
C:\WINDOWS\~tmp3766.exe
C:\WINDOWS\~tmp3769.exe
C:\WINDOWS\~tmp3770.exe
C:\WINDOWS\~tmp3771.exe
C:\WINDOWS\~tmp3773.exe
C:\WINDOWS\~tmp3774.exe
C:\WINDOWS\~tmp3775.exe
C:\WINDOWS\~tmp3776.exe
C:\WINDOWS\~tmp3777.exe
C:\WINDOWS\~tmp3778.exe
C:\WINDOWS\~tmp3780.exe
C:\WINDOWS\~tmp3782.exe
C:\WINDOWS\~tmp3784.exe
C:\WINDOWS\~tmp3785.exe
C:\WINDOWS\~tmp3786.exe
C:\WINDOWS\~tmp3787.exe
C:\WINDOWS\~tmp3790.exe
C:\WINDOWS\~tmp3791.exe
C:\WINDOWS\~tmp3792.exe
C:\WINDOWS\~tmp3795.exe
C:\WINDOWS\~tmp3798.exe
C:\WINDOWS\~tmp3799.exe
C:\WINDOWS\~tmp380.exe
C:\WINDOWS\~tmp3803.exe
C:\WINDOWS\~tmp3805.exe
C:\WINDOWS\~tmp3806.exe
C:\WINDOWS\~tmp3809.exe
C:\WINDOWS\~tmp3810.exe
C:\WINDOWS\~tmp3814.exe
C:\WINDOWS\~tmp3818.exe
C:\WINDOWS\~tmp382.exe
C:\WINDOWS\~tmp3820.exe
C:\WINDOWS\~tmp3821.exe
C:\WINDOWS\~tmp3826.exe
C:\WINDOWS\~tmp3827.exe
C:\WINDOWS\~tmp383.exe
C:\WINDOWS\~tmp3830.exe
C:\WINDOWS\~tmp3831.exe
C:\WINDOWS\~tmp3839.exe
C:\WINDOWS\~tmp3840.exe
C:\WINDOWS\~tmp3841.exe
C:\WINDOWS\~tmp3842.exe
C:\WINDOWS\~tmp3844.exe
C:\WINDOWS\~tmp3845.exe
C:\WINDOWS\~tmp3847.exe
C:\WINDOWS\~tmp3849.exe
C:\WINDOWS\~tmp3854.exe
C:\WINDOWS\~tmp3855.exe
C:\WINDOWS\~tmp3856.exe
C:\WINDOWS\~tmp3858.exe
C:\WINDOWS\~tmp3860.exe
C:\WINDOWS\~tmp3861.exe
C:\WINDOWS\~tmp3862.exe
C:\WINDOWS\~tmp3863.exe
C:\WINDOWS\~tmp3864.exe
C:\WINDOWS\~tmp3865.exe
C:\WINDOWS\~tmp3868.exe
C:\WINDOWS\~tmp3869.exe
C:\WINDOWS\~tmp3870.exe
C:\WINDOWS\~tmp3871.exe
C:\WINDOWS\~tmp3878.exe
C:\WINDOWS\~tmp3879.exe
C:\WINDOWS\~tmp3880.exe
C:\WINDOWS\~tmp3881.exe
C:\WINDOWS\~tmp3882.exe
C:\WINDOWS\~tmp3883.exe
C:\WINDOWS\~tmp3884.exe
C:\WINDOWS\~tmp389.exe
C:\WINDOWS\~tmp3891.exe
C:\WINDOWS\~tmp3893.exe
C:\WINDOWS\~tmp3896.exe
C:\WINDOWS\~tmp3898.exe
C:\WINDOWS\~tmp39.exe
C:\WINDOWS\~tmp390.exe
C:\WINDOWS\~tmp3900.exe
C:\WINDOWS\~tmp3901.exe
C:\WINDOWS\~tmp3902.exe
C:\WINDOWS\~tmp3903.exe
C:\WINDOWS\~tmp3905.exe
C:\WINDOWS\~tmp3907.exe
C:\WINDOWS\~tmp3908.exe
C:\WINDOWS\~tmp391.exe
C:\WINDOWS\~tmp3910.exe
C:\WINDOWS\~tmp3911.exe
C:\WINDOWS\~tmp3914.exe
C:\WINDOWS\~tmp3915.exe
C:\WINDOWS\~tmp3916.exe
C:\WINDOWS\~tmp3919.exe
C:\WINDOWS\~tmp3921.exe
C:\WINDOWS\~tmp3922.exe
C:\WINDOWS\~tmp3926.exe
C:\WINDOWS\~tmp3927.exe
C:\WINDOWS\~tmp3929.exe
C:\WINDOWS\~tmp3933.exe
C:\WINDOWS\~tmp3936.exe
C:\WINDOWS\~tmp3937.exe
C:\WINDOWS\~tmp3938.exe
C:\WINDOWS\~tmp3939.exe
C:\WINDOWS\~tmp3940.exe
C:\WINDOWS\~tmp3942.exe
C:\WINDOWS\~tmp3946.exe
C:\WINDOWS\~tmp3954.exe
C:\WINDOWS\~tmp3955.exe
C:\WINDOWS\~tmp3956.exe
C:\WINDOWS\~tmp3957.exe
C:\WINDOWS\~tmp3958.exe
C:\WINDOWS\~tmp396.exe
C:\WINDOWS\~tmp3960.exe
C:\WINDOWS\~tmp3962.exe
C:\WINDOWS\~tmp3963.exe
C:\WINDOWS\~tmp3970.exe
C:\WINDOWS\~tmp3972.exe
C:\WINDOWS\~tmp3973.exe
C:\WINDOWS\~tmp3974.exe
C:\WINDOWS\~tmp3975.exe
C:\WINDOWS\~tmp3976.exe
C:\WINDOWS\~tmp3978.exe
C:\WINDOWS\~tmp3979.exe
C:\WINDOWS\~tmp398.exe
C:\WINDOWS\~tmp3980.exe
C:\WINDOWS\~tmp3984.exe
C:\WINDOWS\~tmp3986.exe
C:\WINDOWS\~tmp3987.exe
C:\WINDOWS\~tmp3989.exe
C:\WINDOWS\~tmp3994.exe
C:\WINDOWS\~tmp3999.exe
C:\WINDOWS\~tmp4.exe
C:\WINDOWS\~tmp400.exe
C:\WINDOWS\~tmp4004.exe
C:\WINDOWS\~tmp4007.exe
C:\WINDOWS\~tmp4012.exe
C:\WINDOWS\~tmp4016.exe
C:\WINDOWS\~tmp4018.exe
C:\WINDOWS\~tmp4020.exe
C:\WINDOWS\~tmp4021.exe
C:\WINDOWS\~tmp4023.exe
C:\WINDOWS\~tmp4025.exe
C:\WINDOWS\~tmp4030.exe
C:\WINDOWS\~tmp4031.exe
C:\WINDOWS\~tmp4032.exe
C:\WINDOWS\~tmp4034.exe
C:\WINDOWS\~tmp4035.exe
C:\WINDOWS\~tmp4036.exe
C:\WINDOWS\~tmp404.exe
C:\WINDOWS\~tmp4040.exe
C:\WINDOWS\~tmp4041.exe
C:\WINDOWS\~tmp4044.exe
C:\WINDOWS\~tmp4046.exe
C:\WINDOWS\~tmp4048.exe
C:\WINDOWS\~tmp4050.exe
C:\WINDOWS\~tmp4051.exe
C:\WINDOWS\~tmp4055.exe
C:\WINDOWS\~tmp4056.exe
C:\WINDOWS\~tmp4057.exe
C:\WINDOWS\~tmp4062.exe
C:\WINDOWS\~tmp4063.exe
C:\WINDOWS\~tmp4064.exe
C:\WINDOWS\~tmp4068.exe
C:\WINDOWS\~tmp4072.exe
C:\WINDOWS\~tmp4073.exe
C:\WINDOWS\~tmp4074.exe
C:\WINDOWS\~tmp4075.exe
C:\WINDOWS\~tmp4076.exe
C:\WINDOWS\~tmp4077.exe
C:\WINDOWS\~tmp4078.exe
C:\WINDOWS\~tmp4079.exe
C:\WINDOWS\~tmp408.exe
C:\WINDOWS\~tmp4082.exe
C:\WINDOWS\~tmp4085.exe
C:\WINDOWS\~tmp4087.exe
C:\WINDOWS\~tmp4088.exe
C:\WINDOWS\~tmp4089.exe
C:\WINDOWS\~tmp409.exe
C:\WINDOWS\~tmp4090.exe
C:\WINDOWS\~tmp4091.exe
C:\WINDOWS\~tmp4094.exe
C:\WINDOWS\~tmp4095.exe
C:\WINDOWS\~tmp4096.exe
C:\WINDOWS\~tmp41.exe
C:\WINDOWS\~tmp4100.exe
C:\WINDOWS\~tmp4101.exe
C:\WINDOWS\~tmp4104.exe
C:\WINDOWS\~tmp4105.exe
C:\WINDOWS\~tmp4106.exe
C:\WINDOWS\~tmp4108.exe
C:\WINDOWS\~tmp4112.exe
C:\WINDOWS\~tmp4113.exe
C:\WINDOWS\~tmp4115.exe
C:\WINDOWS\~tmp4117.exe
C:\WINDOWS\~tmp4118.exe
C:\WINDOWS\~tmp4119.exe
C:\WINDOWS\~tmp412.exe
C:\WINDOWS\~tmp4120.exe
C:\WINDOWS\~tmp4122.exe
C:\WINDOWS\~tmp4125.exe
C:\WINDOWS\~tmp4127.exe
C:\WINDOWS\~tmp4128.exe
C:\WINDOWS\~tmp4130.exe
C:\WINDOWS\~tmp4131.exe
C:\WINDOWS\~tmp4132.exe
C:\WINDOWS\~tmp4136.exe
C:\WINDOWS\~tmp4137.exe
C:\WINDOWS\~tmp4138.exe
C:\WINDOWS\~tmp4139.exe
C:\WINDOWS\~tmp414.exe
C:\WINDOWS\~tmp4140.exe
C:\WINDOWS\~tmp4142.exe
C:\WINDOWS\~tmp4144.exe
C:\WINDOWS\~tmp4145.exe
C:\WINDOWS\~tmp4146.exe
C:\WINDOWS\~tmp4147.exe
C:\WINDOWS\~tmp4149.exe
C:\WINDOWS\~tmp4152.exe
C:\WINDOWS\~tmp4154.exe
C:\WINDOWS\~tmp4156.exe
C:\WINDOWS\~tmp4159.exe
C:\WINDOWS\~tmp4160.exe
C:\WINDOWS\~tmp4161.exe
C:\WINDOWS\~tmp4162.exe
C:\WINDOWS\~tmp4164.exe
C:\WINDOWS\~tmp4165.exe
C:\WINDOWS\~tmp4166.exe
C:\WINDOWS\~tmp4167.exe
C:\WINDOWS\~tmp4168.exe
C:\WINDOWS\~tmp417.exe
C:\WINDOWS\~tmp4170.exe
C:\WINDOWS\~tmp4172.exe
C:\WINDOWS\~tmp4174.exe
C:\WINDOWS\~tmp4175.exe
C:\WINDOWS\~tmp4177.exe
C:\WINDOWS\~tmp4178.exe
C:\WINDOWS\~tmp4181.exe
C:\WINDOWS\~tmp4185.exe
C:\WINDOWS\~tmp4189.exe
C:\WINDOWS\~tmp4192.exe
C:\WINDOWS\~tmp4195.exe
C:\WINDOWS\~tmp4197.exe
C:\WINDOWS\~tmp42.exe
C:\WINDOWS\~tmp4203.exe
C:\WINDOWS\~tmp4204.exe
C:\WINDOWS\~tmp4206.exe
C:\WINDOWS\~tmp4207.exe
C:\WINDOWS\~tmp4208.exe
C:\WINDOWS\~tmp4209.exe
C:\WINDOWS\~tmp4215.exe
C:\WINDOWS\~tmp4216.exe
C:\WINDOWS\~tmp4218.exe
C:\WINDOWS\~tmp4220.exe
C:\WINDOWS\~tmp4221.exe
C:\WINDOWS\~tmp4223.exe
C:\WINDOWS\~tmp4229.exe
C:\WINDOWS\~tmp4230.exe
C:\WINDOWS\~tmp4233.exe
C:\WINDOWS\~tmp4234.exe
C:\WINDOWS\~tmp4235.exe
C:\WINDOWS\~tmp4236.exe
C:\WINDOWS\~tmp4238.exe
C:\WINDOWS\~tmp4239.exe
C:\WINDOWS\~tmp4241.exe
C:\WINDOWS\~tmp4242.exe
C:\WINDOWS\~tmp4243.exe
C:\WINDOWS\~tmp4244.exe
C:\WINDOWS\~tmp4246.exe
C:\WINDOWS\~tmp4249.exe
C:\WINDOWS\~tmp425.exe
C:\WINDOWS\~tmp4250.exe
C:\WINDOWS\~tmp4251.exe
C:\WINDOWS\~tmp4252.exe
C:\WINDOWS\~tmp4253.exe
C:\WINDOWS\~tmp4254.exe
C:\WINDOWS\~tmp4256.exe
C:\WINDOWS\~tmp4258.exe
C:\WINDOWS\~tmp4259.exe
C:\WINDOWS\~tmp4260.exe
C:\WINDOWS\~tmp4263.exe
C:\WINDOWS\~tmp4264.exe
C:\WINDOWS\~tmp4265.exe
C:\WINDOWS\~tmp4266.exe
C:\WINDOWS\~tmp4269.exe
C:\WINDOWS\~tmp427.exe
C:\WINDOWS\~tmp4270.exe
C:\WINDOWS\~tmp4273.exe
C:\WINDOWS\~tmp4275.exe
C:\WINDOWS\~tmp4276.exe
C:\WINDOWS\~tmp4277.exe
C:\WINDOWS\~tmp4279.exe
C:\WINDOWS\~tmp428.exe
C:\WINDOWS\~tmp4281.exe
C:\WINDOWS\~tmp4284.exe
C:\WINDOWS\~tmp4286.exe
C:\WINDOWS\~tmp4287.exe
C:\WINDOWS\~tmp429.exe
C:\WINDOWS\~tmp4290.exe
C:\WINDOWS\~tmp4292.exe
C:\WINDOWS\~tmp4293.exe
C:\WINDOWS\~tmp4294.exe
C:\WINDOWS\~tmp4295.exe
C:\WINDOWS\~tmp4297.exe
C:\WINDOWS\~tmp4300.exe
C:\WINDOWS\~tmp4301.exe
C:\WINDOWS\~tmp4302.exe
C:\WINDOWS\~tmp4304.exe
C:\WINDOWS\~tmp4305.exe
C:\WINDOWS\~tmp4306.exe
C:\WINDOWS\~tmp4307.exe
C:\WINDOWS\~tmp4308.exe
C:\WINDOWS\~tmp4311.exe


----------



## cpuanswers (Sep 25, 2007)

C:\WINDOWS\~tmp4312.exe
C:\WINDOWS\~tmp4313.exe
C:\WINDOWS\~tmp4314.exe
C:\WINDOWS\~tmp4315.exe
C:\WINDOWS\~tmp4316.exe
C:\WINDOWS\~tmp4319.exe
C:\WINDOWS\~tmp432.exe
C:\WINDOWS\~tmp4322.exe
C:\WINDOWS\~tmp4323.exe
C:\WINDOWS\~tmp4324.exe
C:\WINDOWS\~tmp4325.exe
C:\WINDOWS\~tmp4326.exe
C:\WINDOWS\~tmp4328.exe
C:\WINDOWS\~tmp4329.exe
C:\WINDOWS\~tmp4330.exe
C:\WINDOWS\~tmp4331.exe
C:\WINDOWS\~tmp4332.exe
C:\WINDOWS\~tmp4333.exe
C:\WINDOWS\~tmp4334.exe
C:\WINDOWS\~tmp4335.exe
C:\WINDOWS\~tmp4337.exe
C:\WINDOWS\~tmp4339.exe
C:\WINDOWS\~tmp4340.exe
C:\WINDOWS\~tmp4342.exe
C:\WINDOWS\~tmp4343.exe
C:\WINDOWS\~tmp4344.exe
C:\WINDOWS\~tmp4345.exe
C:\WINDOWS\~tmp4347.exe
C:\WINDOWS\~tmp4349.exe
C:\WINDOWS\~tmp435.exe
C:\WINDOWS\~tmp4351.exe
C:\WINDOWS\~tmp4352.exe
C:\WINDOWS\~tmp4353.exe
C:\WINDOWS\~tmp4355.exe
C:\WINDOWS\~tmp4356.exe
C:\WINDOWS\~tmp4357.exe
C:\WINDOWS\~tmp4358.exe
C:\WINDOWS\~tmp4359.exe
C:\WINDOWS\~tmp436.exe
C:\WINDOWS\~tmp4361.exe
C:\WINDOWS\~tmp4364.exe
C:\WINDOWS\~tmp4366.exe
C:\WINDOWS\~tmp4367.exe
C:\WINDOWS\~tmp4368.exe
C:\WINDOWS\~tmp437.exe
C:\WINDOWS\~tmp4371.exe
C:\WINDOWS\~tmp4372.exe
C:\WINDOWS\~tmp4373.exe
C:\WINDOWS\~tmp4375.exe
C:\WINDOWS\~tmp4377.exe
C:\WINDOWS\~tmp4378.exe
C:\WINDOWS\~tmp438.exe
C:\WINDOWS\~tmp4381.exe
C:\WINDOWS\~tmp4382.exe
C:\WINDOWS\~tmp4383.exe
C:\WINDOWS\~tmp4384.exe
C:\WINDOWS\~tmp4385.exe
C:\WINDOWS\~tmp4386.exe
C:\WINDOWS\~tmp4387.exe
C:\WINDOWS\~tmp4389.exe
C:\WINDOWS\~tmp439.exe
C:\WINDOWS\~tmp4390.exe
C:\WINDOWS\~tmp4391.exe
C:\WINDOWS\~tmp4394.exe
C:\WINDOWS\~tmp4396.exe
C:\WINDOWS\~tmp4397.exe
C:\WINDOWS\~tmp44.exe
C:\WINDOWS\~tmp440.exe
C:\WINDOWS\~tmp4400.exe
C:\WINDOWS\~tmp4401.exe
C:\WINDOWS\~tmp4402.exe
C:\WINDOWS\~tmp4404.exe
C:\WINDOWS\~tmp4405.exe
C:\WINDOWS\~tmp4406.exe
C:\WINDOWS\~tmp4407.exe
C:\WINDOWS\~tmp4408.exe
C:\WINDOWS\~tmp441.exe
C:\WINDOWS\~tmp4411.exe
C:\WINDOWS\~tmp4412.exe
C:\WINDOWS\~tmp4413.exe
C:\WINDOWS\~tmp4414.exe
C:\WINDOWS\~tmp4417.exe
C:\WINDOWS\~tmp4418.exe
C:\WINDOWS\~tmp4419.exe
C:\WINDOWS\~tmp442.exe
C:\WINDOWS\~tmp4425.exe
C:\WINDOWS\~tmp4426.exe
C:\WINDOWS\~tmp4430.exe
C:\WINDOWS\~tmp4431.exe
C:\WINDOWS\~tmp4432.exe
C:\WINDOWS\~tmp4435.exe
C:\WINDOWS\~tmp4436.exe
C:\WINDOWS\~tmp4437.exe
C:\WINDOWS\~tmp4438.exe
C:\WINDOWS\~tmp4439.exe
C:\WINDOWS\~tmp444.exe
C:\WINDOWS\~tmp4440.exe
C:\WINDOWS\~tmp4441.exe
C:\WINDOWS\~tmp4444.exe
C:\WINDOWS\~tmp4445.exe
C:\WINDOWS\~tmp4447.exe
C:\WINDOWS\~tmp4449.exe
C:\WINDOWS\~tmp4450.exe
C:\WINDOWS\~tmp4451.exe
C:\WINDOWS\~tmp4453.exe
C:\WINDOWS\~tmp4454.exe
C:\WINDOWS\~tmp4456.exe
C:\WINDOWS\~tmp4459.exe
C:\WINDOWS\~tmp4460.exe
C:\WINDOWS\~tmp4462.exe
C:\WINDOWS\~tmp4466.exe
C:\WINDOWS\~tmp447.exe
C:\WINDOWS\~tmp4470.exe
C:\WINDOWS\~tmp4474.exe
C:\WINDOWS\~tmp4475.exe
C:\WINDOWS\~tmp4476.exe
C:\WINDOWS\~tmp4477.exe
C:\WINDOWS\~tmp4478.exe
C:\WINDOWS\~tmp4479.exe
C:\WINDOWS\~tmp448.exe
C:\WINDOWS\~tmp4480.exe
C:\WINDOWS\~tmp4481.exe
C:\WINDOWS\~tmp4483.exe
C:\WINDOWS\~tmp4484.exe
C:\WINDOWS\~tmp4485.exe
C:\WINDOWS\~tmp4487.exe
C:\WINDOWS\~tmp4488.exe
C:\WINDOWS\~tmp4489.exe
C:\WINDOWS\~tmp449.exe
C:\WINDOWS\~tmp4491.exe
C:\WINDOWS\~tmp4493.exe
C:\WINDOWS\~tmp4494.exe
C:\WINDOWS\~tmp4495.exe
C:\WINDOWS\~tmp4496.exe
C:\WINDOWS\~tmp4497.exe
C:\WINDOWS\~tmp4499.exe
C:\WINDOWS\~tmp45.exe
C:\WINDOWS\~tmp450.exe
C:\WINDOWS\~tmp4501.exe
C:\WINDOWS\~tmp4502.exe
C:\WINDOWS\~tmp4503.exe
C:\WINDOWS\~tmp4504.exe
C:\WINDOWS\~tmp4505.exe
C:\WINDOWS\~tmp4507.exe
C:\WINDOWS\~tmp4509.exe
C:\WINDOWS\~tmp451.exe
C:\WINDOWS\~tmp4510.exe
C:\WINDOWS\~tmp4512.exe
C:\WINDOWS\~tmp4513.exe
C:\WINDOWS\~tmp4514.exe
C:\WINDOWS\~tmp4515.exe
C:\WINDOWS\~tmp4517.exe
C:\WINDOWS\~tmp4518.exe
C:\WINDOWS\~tmp4519.exe
C:\WINDOWS\~tmp452.exe
C:\WINDOWS\~tmp4523.exe
C:\WINDOWS\~tmp4524.exe
C:\WINDOWS\~tmp4526.exe
C:\WINDOWS\~tmp4528.exe
C:\WINDOWS\~tmp4531.exe
C:\WINDOWS\~tmp4532.exe
C:\WINDOWS\~tmp4533.exe
C:\WINDOWS\~tmp4534.exe
C:\WINDOWS\~tmp4535.exe
C:\WINDOWS\~tmp4536.exe
C:\WINDOWS\~tmp4538.exe
C:\WINDOWS\~tmp454.exe
C:\WINDOWS\~tmp4540.exe
C:\WINDOWS\~tmp4541.exe
C:\WINDOWS\~tmp4544.exe
C:\WINDOWS\~tmp4545.exe
C:\WINDOWS\~tmp4547.exe
C:\WINDOWS\~tmp4548.exe
C:\WINDOWS\~tmp4549.exe
C:\WINDOWS\~tmp455.exe
C:\WINDOWS\~tmp4550.exe
C:\WINDOWS\~tmp4551.exe
C:\WINDOWS\~tmp4552.exe
C:\WINDOWS\~tmp4553.exe
C:\WINDOWS\~tmp4554.exe
C:\WINDOWS\~tmp4555.exe
C:\WINDOWS\~tmp4557.exe
C:\WINDOWS\~tmp4558.exe
C:\WINDOWS\~tmp4559.exe
C:\WINDOWS\~tmp456.exe
C:\WINDOWS\~tmp4561.exe
C:\WINDOWS\~tmp4562.exe
C:\WINDOWS\~tmp4563.exe
C:\WINDOWS\~tmp4566.exe
C:\WINDOWS\~tmp4568.exe
C:\WINDOWS\~tmp457.exe
C:\WINDOWS\~tmp4571.exe
C:\WINDOWS\~tmp4573.exe
C:\WINDOWS\~tmp4575.exe
C:\WINDOWS\~tmp4577.exe
C:\WINDOWS\~tmp458.exe
C:\WINDOWS\~tmp4580.exe
C:\WINDOWS\~tmp4581.exe
C:\WINDOWS\~tmp4582.exe
C:\WINDOWS\~tmp4583.exe
C:\WINDOWS\~tmp4584.exe
C:\WINDOWS\~tmp4585.exe
C:\WINDOWS\~tmp4586.exe
C:\WINDOWS\~tmp4587.exe
C:\WINDOWS\~tmp4588.exe
C:\WINDOWS\~tmp4589.exe
C:\WINDOWS\~tmp4592.exe
C:\WINDOWS\~tmp4593.exe
C:\WINDOWS\~tmp4594.exe
C:\WINDOWS\~tmp4597.exe
C:\WINDOWS\~tmp46.exe
C:\WINDOWS\~tmp460.exe
C:\WINDOWS\~tmp4600.exe
C:\WINDOWS\~tmp4603.exe
C:\WINDOWS\~tmp4604.exe
C:\WINDOWS\~tmp4605.exe
C:\WINDOWS\~tmp4607.exe
C:\WINDOWS\~tmp4609.exe
C:\WINDOWS\~tmp461.exe
C:\WINDOWS\~tmp4610.exe
C:\WINDOWS\~tmp4611.exe
C:\WINDOWS\~tmp4612.exe
C:\WINDOWS\~tmp4616.exe
C:\WINDOWS\~tmp4617.exe
C:\WINDOWS\~tmp4619.exe
C:\WINDOWS\~tmp4622.exe
C:\WINDOWS\~tmp4623.exe
C:\WINDOWS\~tmp4624.exe
C:\WINDOWS\~tmp4625.exe
C:\WINDOWS\~tmp4626.exe
C:\WINDOWS\~tmp4627.exe
C:\WINDOWS\~tmp4629.exe
C:\WINDOWS\~tmp463.exe
C:\WINDOWS\~tmp4632.exe
C:\WINDOWS\~tmp4633.exe
C:\WINDOWS\~tmp4637.exe
C:\WINDOWS\~tmp4638.exe
C:\WINDOWS\~tmp4639.exe
C:\WINDOWS\~tmp464.exe
C:\WINDOWS\~tmp4640.exe
C:\WINDOWS\~tmp4641.exe
C:\WINDOWS\~tmp4642.exe
C:\WINDOWS\~tmp4643.exe
C:\WINDOWS\~tmp4644.exe
C:\WINDOWS\~tmp4648.exe
C:\WINDOWS\~tmp4649.exe
C:\WINDOWS\~tmp465.exe
C:\WINDOWS\~tmp4651.exe
C:\WINDOWS\~tmp4652.exe
C:\WINDOWS\~tmp4658.exe
C:\WINDOWS\~tmp4664.exe
C:\WINDOWS\~tmp4665.exe
C:\WINDOWS\~tmp4666.exe
C:\WINDOWS\~tmp4668.exe
C:\WINDOWS\~tmp4669.exe
C:\WINDOWS\~tmp4672.exe
C:\WINDOWS\~tmp4673.exe
C:\WINDOWS\~tmp4674.exe
C:\WINDOWS\~tmp4675.exe
C:\WINDOWS\~tmp4676.exe
C:\WINDOWS\~tmp4678.exe
C:\WINDOWS\~tmp4679.exe
C:\WINDOWS\~tmp4681.exe
C:\WINDOWS\~tmp4685.exe
C:\WINDOWS\~tmp4687.exe
C:\WINDOWS\~tmp469.exe
C:\WINDOWS\~tmp4691.exe
C:\WINDOWS\~tmp4694.exe
C:\WINDOWS\~tmp4695.exe
C:\WINDOWS\~tmp4696.exe
C:\WINDOWS\~tmp4697.exe
C:\WINDOWS\~tmp4698.exe
C:\WINDOWS\~tmp4699.exe
C:\WINDOWS\~tmp470.exe
C:\WINDOWS\~tmp4700.exe
C:\WINDOWS\~tmp4701.exe
C:\WINDOWS\~tmp4702.exe
C:\WINDOWS\~tmp4703.exe
C:\WINDOWS\~tmp4705.exe
C:\WINDOWS\~tmp4706.exe
C:\WINDOWS\~tmp4708.exe
C:\WINDOWS\~tmp471.exe
C:\WINDOWS\~tmp4713.exe
C:\WINDOWS\~tmp4714.exe
C:\WINDOWS\~tmp4716.exe
C:\WINDOWS\~tmp4718.exe
C:\WINDOWS\~tmp4722.exe
C:\WINDOWS\~tmp4724.exe
C:\WINDOWS\~tmp4726.exe
C:\WINDOWS\~tmp4727.exe
C:\WINDOWS\~tmp4728.exe
C:\WINDOWS\~tmp4730.exe
C:\WINDOWS\~tmp4732.exe
C:\WINDOWS\~tmp4733.exe
C:\WINDOWS\~tmp4734.exe
C:\WINDOWS\~tmp4735.exe
C:\WINDOWS\~tmp4737.exe
C:\WINDOWS\~tmp4738.exe
C:\WINDOWS\~tmp474.exe
C:\WINDOWS\~tmp4740.exe
C:\WINDOWS\~tmp4743.exe
C:\WINDOWS\~tmp4745.exe
C:\WINDOWS\~tmp4746.exe
C:\WINDOWS\~tmp4747.exe
C:\WINDOWS\~tmp4748.exe
C:\WINDOWS\~tmp4749.exe
C:\WINDOWS\~tmp4751.exe
C:\WINDOWS\~tmp4752.exe
C:\WINDOWS\~tmp4753.exe
C:\WINDOWS\~tmp4754.exe
C:\WINDOWS\~tmp4756.exe
C:\WINDOWS\~tmp4758.exe
C:\WINDOWS\~tmp476.exe
C:\WINDOWS\~tmp4761.exe
C:\WINDOWS\~tmp4763.exe
C:\WINDOWS\~tmp4764.exe
C:\WINDOWS\~tmp4765.exe
C:\WINDOWS\~tmp4768.exe
C:\WINDOWS\~tmp4769.exe
C:\WINDOWS\~tmp477.exe
C:\WINDOWS\~tmp4775.exe
C:\WINDOWS\~tmp4776.exe
C:\WINDOWS\~tmp4778.exe
C:\WINDOWS\~tmp4779.exe
C:\WINDOWS\~tmp478.exe
C:\WINDOWS\~tmp4780.exe
C:\WINDOWS\~tmp4781.exe
C:\WINDOWS\~tmp4785.exe
C:\WINDOWS\~tmp4791.exe
C:\WINDOWS\~tmp4792.exe
C:\WINDOWS\~tmp4793.exe
C:\WINDOWS\~tmp4794.exe
C:\WINDOWS\~tmp4796.exe
C:\WINDOWS\~tmp4797.exe
C:\WINDOWS\~tmp4799.exe
C:\WINDOWS\~tmp48.exe
C:\WINDOWS\~tmp480.exe
C:\WINDOWS\~tmp4801.exe
C:\WINDOWS\~tmp4804.exe
C:\WINDOWS\~tmp4806.exe
C:\WINDOWS\~tmp4808.exe
C:\WINDOWS\~tmp4809.exe
C:\WINDOWS\~tmp4811.exe
C:\WINDOWS\~tmp4812.exe
C:\WINDOWS\~tmp4814.exe
C:\WINDOWS\~tmp4824.exe
C:\WINDOWS\~tmp4825.exe
C:\WINDOWS\~tmp4826.exe
C:\WINDOWS\~tmp4829.exe
C:\WINDOWS\~tmp4832.exe
C:\WINDOWS\~tmp4835.exe
C:\WINDOWS\~tmp4836.exe
C:\WINDOWS\~tmp4839.exe
C:\WINDOWS\~tmp484.exe
C:\WINDOWS\~tmp4840.exe
C:\WINDOWS\~tmp4842.exe
C:\WINDOWS\~tmp4843.exe
C:\WINDOWS\~tmp4845.exe
C:\WINDOWS\~tmp4846.exe
C:\WINDOWS\~tmp4847.exe
C:\WINDOWS\~tmp4848.exe
C:\WINDOWS\~tmp4850.exe
C:\WINDOWS\~tmp4854.exe
C:\WINDOWS\~tmp4855.exe
C:\WINDOWS\~tmp4856.exe
C:\WINDOWS\~tmp4857.exe
C:\WINDOWS\~tmp4859.exe
C:\WINDOWS\~tmp4865.exe
C:\WINDOWS\~tmp4866.exe
C:\WINDOWS\~tmp4867.exe
C:\WINDOWS\~tmp4869.exe
C:\WINDOWS\~tmp487.exe
C:\WINDOWS\~tmp4870.exe
C:\WINDOWS\~tmp4871.exe
C:\WINDOWS\~tmp4872.exe
C:\WINDOWS\~tmp4873.exe
C:\WINDOWS\~tmp4875.exe
C:\WINDOWS\~tmp4876.exe
C:\WINDOWS\~tmp4877.exe
C:\WINDOWS\~tmp4880.exe
C:\WINDOWS\~tmp4881.exe
C:\WINDOWS\~tmp4882.exe
C:\WINDOWS\~tmp4884.exe
C:\WINDOWS\~tmp4887.exe
C:\WINDOWS\~tmp489.exe
C:\WINDOWS\~tmp4890.exe
C:\WINDOWS\~tmp4893.exe
C:\WINDOWS\~tmp4895.exe
C:\WINDOWS\~tmp4896.exe
C:\WINDOWS\~tmp4898.exe
C:\WINDOWS\~tmp4899.exe
C:\WINDOWS\~tmp49.exe
C:\WINDOWS\~tmp4900.exe
C:\WINDOWS\~tmp4901.exe
C:\WINDOWS\~tmp4903.exe
C:\WINDOWS\~tmp4904.exe
C:\WINDOWS\~tmp4905.exe
C:\WINDOWS\~tmp491.exe
C:\WINDOWS\~tmp4910.exe
C:\WINDOWS\~tmp4913.exe
C:\WINDOWS\~tmp4914.exe
C:\WINDOWS\~tmp4915.exe
C:\WINDOWS\~tmp4917.exe
C:\WINDOWS\~tmp4921.exe
C:\WINDOWS\~tmp4922.exe
C:\WINDOWS\~tmp4926.exe
C:\WINDOWS\~tmp4927.exe
C:\WINDOWS\~tmp4929.exe
C:\WINDOWS\~tmp493.exe
C:\WINDOWS\~tmp4931.exe
C:\WINDOWS\~tmp4933.exe
C:\WINDOWS\~tmp4935.exe
C:\WINDOWS\~tmp4936.exe
C:\WINDOWS\~tmp4937.exe
C:\WINDOWS\~tmp4941.exe
C:\WINDOWS\~tmp4943.exe
C:\WINDOWS\~tmp4945.exe
C:\WINDOWS\~tmp4946.exe
C:\WINDOWS\~tmp4949.exe
C:\WINDOWS\~tmp495.exe
C:\WINDOWS\~tmp4951.exe
C:\WINDOWS\~tmp4953.exe
C:\WINDOWS\~tmp4955.exe
C:\WINDOWS\~tmp4957.exe
C:\WINDOWS\~tmp4959.exe
C:\WINDOWS\~tmp496.exe
C:\WINDOWS\~tmp4960.exe
C:\WINDOWS\~tmp4962.exe
C:\WINDOWS\~tmp4963.exe
C:\WINDOWS\~tmp4964.exe
C:\WINDOWS\~tmp4966.exe
C:\WINDOWS\~tmp4969.exe
C:\WINDOWS\~tmp497.exe
C:\WINDOWS\~tmp4970.exe
C:\WINDOWS\~tmp4972.exe
C:\WINDOWS\~tmp4975.exe
C:\WINDOWS\~tmp4979.exe
C:\WINDOWS\~tmp4980.exe
C:\WINDOWS\~tmp4982.exe
C:\WINDOWS\~tmp4983.exe
C:\WINDOWS\~tmp4986.exe
C:\WINDOWS\~tmp4987.exe
C:\WINDOWS\~tmp4989.exe
C:\WINDOWS\~tmp499.exe
C:\WINDOWS\~tmp4990.exe
C:\WINDOWS\~tmp4991.exe
C:\WINDOWS\~tmp4992.exe
C:\WINDOWS\~tmp4993.exe
C:\WINDOWS\~tmp4995.exe
C:\WINDOWS\~tmp4996.exe
C:\WINDOWS\~tmp50.exe
C:\WINDOWS\~tmp5000.exe
C:\WINDOWS\~tmp5001.exe
C:\WINDOWS\~tmp5004.exe
C:\WINDOWS\~tmp5005.exe
C:\WINDOWS\~tmp5008.exe
C:\WINDOWS\~tmp501.exe
C:\WINDOWS\~tmp5011.exe
C:\WINDOWS\~tmp5012.exe
C:\WINDOWS\~tmp5013.exe
C:\WINDOWS\~tmp5014.exe
C:\WINDOWS\~tmp5016.exe
C:\WINDOWS\~tmp5017.exe
C:\WINDOWS\~tmp5018.exe
C:\WINDOWS\~tmp5019.exe
C:\WINDOWS\~tmp502.exe
C:\WINDOWS\~tmp5020.exe
C:\WINDOWS\~tmp5023.exe
C:\WINDOWS\~tmp5024.exe
C:\WINDOWS\~tmp5025.exe
C:\WINDOWS\~tmp5027.exe
C:\WINDOWS\~tmp5028.exe
C:\WINDOWS\~tmp5030.exe
C:\WINDOWS\~tmp5033.exe
C:\WINDOWS\~tmp5034.exe
C:\WINDOWS\~tmp5036.exe
C:\WINDOWS\~tmp5037.exe
C:\WINDOWS\~tmp5042.exe
C:\WINDOWS\~tmp5043.exe
C:\WINDOWS\~tmp5044.exe
C:\WINDOWS\~tmp5045.exe
C:\WINDOWS\~tmp5052.exe
C:\WINDOWS\~tmp5055.exe
C:\WINDOWS\~tmp5056.exe
C:\WINDOWS\~tmp5057.exe
C:\WINDOWS\~tmp506.exe
C:\WINDOWS\~tmp5063.exe
C:\WINDOWS\~tmp5064.exe
C:\WINDOWS\~tmp5065.exe
C:\WINDOWS\~tmp5067.exe
C:\WINDOWS\~tmp5068.exe
C:\WINDOWS\~tmp5069.exe
C:\WINDOWS\~tmp507.exe
C:\WINDOWS\~tmp5072.exe
C:\WINDOWS\~tmp5078.exe
C:\WINDOWS\~tmp5082.exe
C:\WINDOWS\~tmp5085.exe
C:\WINDOWS\~tmp5086.exe
C:\WINDOWS\~tmp5088.exe
C:\WINDOWS\~tmp5089.exe
C:\WINDOWS\~tmp509.exe
C:\WINDOWS\~tmp5090.exe
C:\WINDOWS\~tmp5095.exe
C:\WINDOWS\~tmp5096.exe
C:\WINDOWS\~tmp5097.exe
C:\WINDOWS\~tmp5098.exe
C:\WINDOWS\~tmp5099.exe
C:\WINDOWS\~tmp51.exe
C:\WINDOWS\~tmp510.exe
C:\WINDOWS\~tmp5100.exe
C:\WINDOWS\~tmp5101.exe
C:\WINDOWS\~tmp5102.exe
C:\WINDOWS\~tmp5103.exe
C:\WINDOWS\~tmp5105.exe
C:\WINDOWS\~tmp5106.exe
C:\WINDOWS\~tmp5107.exe
C:\WINDOWS\~tmp5109.exe
C:\WINDOWS\~tmp5112.exe
C:\WINDOWS\~tmp5113.exe
C:\WINDOWS\~tmp5116.exe
C:\WINDOWS\~tmp5118.exe
C:\WINDOWS\~tmp5119.exe
C:\WINDOWS\~tmp5123.exe
C:\WINDOWS\~tmp5126.exe
C:\WINDOWS\~tmp5127.exe
C:\WINDOWS\~tmp5128.exe
C:\WINDOWS\~tmp5131.exe
C:\WINDOWS\~tmp5133.exe
C:\WINDOWS\~tmp5135.exe
C:\WINDOWS\~tmp5136.exe
C:\WINDOWS\~tmp5137.exe
C:\WINDOWS\~tmp5139.exe
C:\WINDOWS\~tmp5142.exe
C:\WINDOWS\~tmp5143.exe
C:\WINDOWS\~tmp5145.exe
C:\WINDOWS\~tmp515.exe
C:\WINDOWS\~tmp5151.exe
C:\WINDOWS\~tmp5154.exe
C:\WINDOWS\~tmp5155.exe
C:\WINDOWS\~tmp5158.exe
C:\WINDOWS\~tmp5159.exe
C:\WINDOWS\~tmp5160.exe
C:\WINDOWS\~tmp5163.exe
C:\WINDOWS\~tmp5164.exe
C:\WINDOWS\~tmp5165.exe
C:\WINDOWS\~tmp5166.exe
C:\WINDOWS\~tmp5169.exe
C:\WINDOWS\~tmp517.exe
C:\WINDOWS\~tmp5172.exe
C:\WINDOWS\~tmp5173.exe
C:\WINDOWS\~tmp5174.exe
C:\WINDOWS\~tmp5176.exe
C:\WINDOWS\~tmp5179.exe
C:\WINDOWS\~tmp518.exe
C:\WINDOWS\~tmp5180.exe
C:\WINDOWS\~tmp5184.exe
C:\WINDOWS\~tmp5186.exe
C:\WINDOWS\~tmp5194.exe
C:\WINDOWS\~tmp5196.exe
C:\WINDOWS\~tmp5198.exe
C:\WINDOWS\~tmp520.exe
C:\WINDOWS\~tmp5201.exe
C:\WINDOWS\~tmp5202.exe
C:\WINDOWS\~tmp5203.exe
C:\WINDOWS\~tmp5205.exe
C:\WINDOWS\~tmp5206.exe
C:\WINDOWS\~tmp5207.exe
C:\WINDOWS\~tmp521.exe
C:\WINDOWS\~tmp5211.exe
C:\WINDOWS\~tmp5213.exe
C:\WINDOWS\~tmp5217.exe
C:\WINDOWS\~tmp522.exe
C:\WINDOWS\~tmp5220.exe
C:\WINDOWS\~tmp5221.exe
C:\WINDOWS\~tmp5223.exe
C:\WINDOWS\~tmp5224.exe
C:\WINDOWS\~tmp5225.exe
C:\WINDOWS\~tmp5227.exe
C:\WINDOWS\~tmp5229.exe
C:\WINDOWS\~tmp5230.exe
C:\WINDOWS\~tmp5231.exe
C:\WINDOWS\~tmp5233.exe
C:\WINDOWS\~tmp5234.exe
C:\WINDOWS\~tmp5235.exe
C:\WINDOWS\~tmp5237.exe
C:\WINDOWS\~tmp5240.exe
C:\WINDOWS\~tmp5243.exe
C:\WINDOWS\~tmp5244.exe
C:\WINDOWS\~tmp5245.exe
C:\WINDOWS\~tmp5246.exe
C:\WINDOWS\~tmp525.exe
C:\WINDOWS\~tmp5250.exe
C:\WINDOWS\~tmp5253.exe
C:\WINDOWS\~tmp5257.exe
C:\WINDOWS\~tmp5259.exe
C:\WINDOWS\~tmp5260.exe
C:\WINDOWS\~tmp5261.exe
C:\WINDOWS\~tmp5263.exe
C:\WINDOWS\~tmp5264.exe
C:\WINDOWS\~tmp5265.exe
C:\WINDOWS\~tmp5267.exe
C:\WINDOWS\~tmp5269.exe
C:\WINDOWS\~tmp527.exe
C:\WINDOWS\~tmp5271.exe
C:\WINDOWS\~tmp5273.exe
C:\WINDOWS\~tmp5275.exe
C:\WINDOWS\~tmp5276.exe
C:\WINDOWS\~tmp5277.exe
C:\WINDOWS\~tmp5278.exe
C:\WINDOWS\~tmp5279.exe
C:\WINDOWS\~tmp5280.exe
C:\WINDOWS\~tmp5282.exe
C:\WINDOWS\~tmp5284.exe
C:\WINDOWS\~tmp5286.exe
C:\WINDOWS\~tmp5288.exe
C:\WINDOWS\~tmp5290.exe
C:\WINDOWS\~tmp5291.exe
C:\WINDOWS\~tmp5293.exe
C:\WINDOWS\~tmp5296.exe
C:\WINDOWS\~tmp5297.exe
C:\WINDOWS\~tmp5298.exe
C:\WINDOWS\~tmp5299.exe
C:\WINDOWS\~tmp530.exe
C:\WINDOWS\~tmp5300.exe
C:\WINDOWS\~tmp5301.exe
C:\WINDOWS\~tmp5302.exe
C:\WINDOWS\~tmp5304.exe
C:\WINDOWS\~tmp5307.exe
C:\WINDOWS\~tmp531.exe
C:\WINDOWS\~tmp5310.exe
C:\WINDOWS\~tmp5311.exe
C:\WINDOWS\~tmp5312.exe
C:\WINDOWS\~tmp5316.exe
C:\WINDOWS\~tmp5317.exe
C:\WINDOWS\~tmp5318.exe
C:\WINDOWS\~tmp5319.exe
C:\WINDOWS\~tmp5320.exe
C:\WINDOWS\~tmp5321.exe
C:\WINDOWS\~tmp5323.exe
C:\WINDOWS\~tmp5327.exe
C:\WINDOWS\~tmp5328.exe
C:\WINDOWS\~tmp5337.exe
C:\WINDOWS\~tmp5338.exe
C:\WINDOWS\~tmp534.exe
C:\WINDOWS\~tmp5343.exe
C:\WINDOWS\~tmp5344.exe
C:\WINDOWS\~tmp5346.exe
C:\WINDOWS\~tmp5349.exe
C:\WINDOWS\~tmp5351.exe
C:\WINDOWS\~tmp5357.exe
C:\WINDOWS\~tmp5358.exe
C:\WINDOWS\~tmp5360.exe
C:\WINDOWS\~tmp5361.exe
C:\WINDOWS\~tmp5362.exe
C:\WINDOWS\~tmp5363.exe
C:\WINDOWS\~tmp5365.exe
C:\WINDOWS\~tmp5366.exe
C:\WINDOWS\~tmp5369.exe
C:\WINDOWS\~tmp5371.exe
C:\WINDOWS\~tmp5372.exe
C:\WINDOWS\~tmp5373.exe
C:\WINDOWS\~tmp5374.exe
C:\WINDOWS\~tmp5375.exe
C:\WINDOWS\~tmp5379.exe
C:\WINDOWS\~tmp5385.exe
C:\WINDOWS\~tmp5386.exe
C:\WINDOWS\~tmp5388.exe
C:\WINDOWS\~tmp5389.exe
C:\WINDOWS\~tmp5390.exe
C:\WINDOWS\~tmp5395.exe
C:\WINDOWS\~tmp5398.exe
C:\WINDOWS\~tmp54.exe
C:\WINDOWS\~tmp540.exe
C:\WINDOWS\~tmp5400.exe
C:\WINDOWS\~tmp5401.exe
C:\WINDOWS\~tmp5402.exe
C:\WINDOWS\~tmp5403.exe
C:\WINDOWS\~tmp5404.exe
C:\WINDOWS\~tmp5405.exe
C:\WINDOWS\~tmp5407.exe
C:\WINDOWS\~tmp5408.exe
C:\WINDOWS\~tmp5410.exe
C:\WINDOWS\~tmp5412.exe
C:\WINDOWS\~tmp5413.exe
C:\WINDOWS\~tmp5414.exe
C:\WINDOWS\~tmp5415.exe
C:\WINDOWS\~tmp5416.exe
C:\WINDOWS\~tmp5417.exe
C:\WINDOWS\~tmp5418.exe
C:\WINDOWS\~tmp5419.exe
C:\WINDOWS\~tmp5420.exe
C:\WINDOWS\~tmp5422.exe
C:\WINDOWS\~tmp5423.exe
C:\WINDOWS\~tmp5425.exe
C:\WINDOWS\~tmp5426.exe
C:\WINDOWS\~tmp5427.exe
C:\WINDOWS\~tmp5429.exe
C:\WINDOWS\~tmp5430.exe
C:\WINDOWS\~tmp5438.exe
C:\WINDOWS\~tmp5439.exe
C:\WINDOWS\~tmp5440.exe
C:\WINDOWS\~tmp5442.exe
C:\WINDOWS\~tmp5443.exe
C:\WINDOWS\~tmp5445.exe
C:\WINDOWS\~tmp5446.exe
C:\WINDOWS\~tmp5448.exe
C:\WINDOWS\~tmp5449.exe
C:\WINDOWS\~tmp5451.exe
C:\WINDOWS\~tmp5454.exe
C:\WINDOWS\~tmp5457.exe
C:\WINDOWS\~tmp5458.exe
C:\WINDOWS\~tmp546.exe
C:\WINDOWS\~tmp5462.exe
C:\WINDOWS\~tmp5463.exe
C:\WINDOWS\~tmp5468.exe
C:\WINDOWS\~tmp5470.exe
C:\WINDOWS\~tmp5471.exe
C:\WINDOWS\~tmp5473.exe
C:\WINDOWS\~tmp5475.exe
C:\WINDOWS\~tmp5476.exe
C:\WINDOWS\~tmp5477.exe
C:\WINDOWS\~tmp5478.exe
C:\WINDOWS\~tmp5479.exe
C:\WINDOWS\~tmp5481.exe
C:\WINDOWS\~tmp5482.exe
C:\WINDOWS\~tmp5483.exe
C:\WINDOWS\~tmp5485.exe
C:\WINDOWS\~tmp5486.exe
C:\WINDOWS\~tmp5487.exe
C:\WINDOWS\~tmp5488.exe
C:\WINDOWS\~tmp5489.exe
C:\WINDOWS\~tmp549.exe
C:\WINDOWS\~tmp5491.exe
C:\WINDOWS\~tmp5495.exe
C:\WINDOWS\~tmp5497.exe
C:\WINDOWS\~tmp5499.exe
C:\WINDOWS\~tmp55.exe
C:\WINDOWS\~tmp5500.exe
C:\WINDOWS\~tmp5501.exe
C:\WINDOWS\~tmp5503.exe
C:\WINDOWS\~tmp5504.exe
C:\WINDOWS\~tmp5505.exe
C:\WINDOWS\~tmp5506.exe
C:\WINDOWS\~tmp5509.exe
C:\WINDOWS\~tmp551.exe
C:\WINDOWS\~tmp5512.exe
C:\WINDOWS\~tmp5513.exe
C:\WINDOWS\~tmp5514.exe
C:\WINDOWS\~tmp5517.exe
C:\WINDOWS\~tmp5518.exe
C:\WINDOWS\~tmp5519.exe
C:\WINDOWS\~tmp5521.exe
C:\WINDOWS\~tmp5523.exe
C:\WINDOWS\~tmp5525.exe
C:\WINDOWS\~tmp5526.exe
C:\WINDOWS\~tmp5527.exe
C:\WINDOWS\~tmp5528.exe
C:\WINDOWS\~tmp5529.exe
C:\WINDOWS\~tmp553.exe
C:\WINDOWS\~tmp5534.exe
C:\WINDOWS\~tmp5538.exe
C:\WINDOWS\~tmp5539.exe
C:\WINDOWS\~tmp5540.exe
C:\WINDOWS\~tmp5541.exe
C:\WINDOWS\~tmp5542.exe
C:\WINDOWS\~tmp5545.exe
C:\WINDOWS\~tmp5548.exe
C:\WINDOWS\~tmp555.exe
C:\WINDOWS\~tmp5551.exe
C:\WINDOWS\~tmp5553.exe
C:\WINDOWS\~tmp5554.exe
C:\WINDOWS\~tmp5556.exe
C:\WINDOWS\~tmp5559.exe
C:\WINDOWS\~tmp556.exe
C:\WINDOWS\~tmp5562.exe
C:\WINDOWS\~tmp5563.exe
C:\WINDOWS\~tmp5565.exe
C:\WINDOWS\~tmp5567.exe
C:\WINDOWS\~tmp557.exe
C:\WINDOWS\~tmp5573.exe
C:\WINDOWS\~tmp5575.exe
C:\WINDOWS\~tmp5576.exe
C:\WINDOWS\~tmp5578.exe
C:\WINDOWS\~tmp5579.exe
C:\WINDOWS\~tmp5581.exe
C:\WINDOWS\~tmp5582.exe
C:\WINDOWS\~tmp5584.exe
C:\WINDOWS\~tmp5589.exe
C:\WINDOWS\~tmp559.exe
C:\WINDOWS\~tmp5590.exe
C:\WINDOWS\~tmp5593.exe
C:\WINDOWS\~tmp5594.exe
C:\WINDOWS\~tmp5596.exe
C:\WINDOWS\~tmp5597.exe
C:\WINDOWS\~tmp5599.exe
C:\WINDOWS\~tmp560.exe
C:\WINDOWS\~tmp5600.exe
C:\WINDOWS\~tmp5602.exe
C:\WINDOWS\~tmp5604.exe
C:\WINDOWS\~tmp5605.exe
C:\WINDOWS\~tmp5606.exe
C:\WINDOWS\~tmp5607.exe
C:\WINDOWS\~tmp5608.exe
C:\WINDOWS\~tmp561.exe
C:\WINDOWS\~tmp5610.exe
C:\WINDOWS\~tmp5612.exe
C:\WINDOWS\~tmp5616.exe
C:\WINDOWS\~tmp5618.exe
C:\WINDOWS\~tmp5622.exe
C:\WINDOWS\~tmp5623.exe
C:\WINDOWS\~tmp5624.exe
C:\WINDOWS\~tmp5625.exe
C:\WINDOWS\~tmp5626.exe
C:\WINDOWS\~tmp5627.exe
C:\WINDOWS\~tmp5629.exe
C:\WINDOWS\~tmp563.exe
C:\WINDOWS\~tmp5631.exe
C:\WINDOWS\~tmp5633.exe
C:\WINDOWS\~tmp5634.exe
C:\WINDOWS\~tmp5635.exe
C:\WINDOWS\~tmp5636.exe
C:\WINDOWS\~tmp5641.exe
C:\WINDOWS\~tmp5644.exe
C:\WINDOWS\~tmp5645.exe
C:\WINDOWS\~tmp5646.exe
C:\WINDOWS\~tmp5651.exe
C:\WINDOWS\~tmp5652.exe
C:\WINDOWS\~tmp5653.exe
C:\WINDOWS\~tmp5655.exe
C:\WINDOWS\~tmp5656.exe
C:\WINDOWS\~tmp5658.exe
C:\WINDOWS\~tmp566.exe
C:\WINDOWS\~tmp5661.exe
C:\WINDOWS\~tmp5662.exe
C:\WINDOWS\~tmp5663.exe
C:\WINDOWS\~tmp5665.exe
C:\WINDOWS\~tmp5666.exe
C:\WINDOWS\~tmp5667.exe
C:\WINDOWS\~tmp5668.exe
C:\WINDOWS\~tmp5669.exe
C:\WINDOWS\~tmp567.exe
C:\WINDOWS\~tmp5670.exe
C:\WINDOWS\~tmp5672.exe
C:\WINDOWS\~tmp5674.exe
C:\WINDOWS\~tmp5676.exe
C:\WINDOWS\~tmp5677.exe
C:\WINDOWS\~tmp5680.exe
C:\WINDOWS\~tmp5683.exe
C:\WINDOWS\~tmp5684.exe
C:\WINDOWS\~tmp5685.exe
C:\WINDOWS\~tmp5688.exe
C:\WINDOWS\~tmp5689.exe
C:\WINDOWS\~tmp5691.exe
C:\WINDOWS\~tmp5692.exe
C:\WINDOWS\~tmp5694.exe
C:\WINDOWS\~tmp5696.exe
C:\WINDOWS\~tmp5697.exe
C:\WINDOWS\~tmp5698.exe
C:\WINDOWS\~tmp57.exe
C:\WINDOWS\~tmp570.exe
C:\WINDOWS\~tmp5701.exe
C:\WINDOWS\~tmp5703.exe
C:\WINDOWS\~tmp5705.exe
C:\WINDOWS\~tmp5709.exe
C:\WINDOWS\~tmp5711.exe
C:\WINDOWS\~tmp5712.exe
C:\WINDOWS\~tmp5713.exe
C:\WINDOWS\~tmp5714.exe
C:\WINDOWS\~tmp572.exe
C:\WINDOWS\~tmp5720.exe
C:\WINDOWS\~tmp5722.exe
C:\WINDOWS\~tmp5723.exe
C:\WINDOWS\~tmp5725.exe
C:\WINDOWS\~tmp5729.exe
C:\WINDOWS\~tmp5734.exe
C:\WINDOWS\~tmp5735.exe
C:\WINDOWS\~tmp5736.exe
C:\WINDOWS\~tmp5737.exe
C:\WINDOWS\~tmp5739.exe
C:\WINDOWS\~tmp574.exe
C:\WINDOWS\~tmp5741.exe
C:\WINDOWS\~tmp5742.exe
C:\WINDOWS\~tmp5744.exe
C:\WINDOWS\~tmp5746.exe
C:\WINDOWS\~tmp5748.exe
C:\WINDOWS\~tmp575.exe
C:\WINDOWS\~tmp5750.exe
C:\WINDOWS\~tmp5752.exe
C:\WINDOWS\~tmp5754.exe
C:\WINDOWS\~tmp5755.exe
C:\WINDOWS\~tmp5756.exe
C:\WINDOWS\~tmp5757.exe
C:\WINDOWS\~tmp5759.exe
C:\WINDOWS\~tmp576.exe
C:\WINDOWS\~tmp5760.exe
C:\WINDOWS\~tmp5762.exe
C:\WINDOWS\~tmp5763.exe
C:\WINDOWS\~tmp5767.exe
C:\WINDOWS\~tmp577.exe
C:\WINDOWS\~tmp5770.exe
C:\WINDOWS\~tmp5771.exe
C:\WINDOWS\~tmp5772.exe
C:\WINDOWS\~tmp5774.exe
C:\WINDOWS\~tmp5775.exe
C:\WINDOWS\~tmp5778.exe
C:\WINDOWS\~tmp5779.exe
C:\WINDOWS\~tmp578.exe
C:\WINDOWS\~tmp5781.exe
C:\WINDOWS\~tmp5782.exe
C:\WINDOWS\~tmp5783.exe
C:\WINDOWS\~tmp5785.exe
C:\WINDOWS\~tmp5786.exe
C:\WINDOWS\~tmp5788.exe
C:\WINDOWS\~tmp579.exe
C:\WINDOWS\~tmp5793.exe
C:\WINDOWS\~tmp5797.exe
C:\WINDOWS\~tmp5798.exe
C:\WINDOWS\~tmp5799.exe
C:\WINDOWS\~tmp58.exe
C:\WINDOWS\~tmp580.exe
C:\WINDOWS\~tmp5809.exe
C:\WINDOWS\~tmp581.exe
C:\WINDOWS\~tmp5810.exe
C:\WINDOWS\~tmp5811.exe
C:\WINDOWS\~tmp5813.exe
C:\WINDOWS\~tmp5817.exe
C:\WINDOWS\~tmp5822.exe


----------



## cpuanswers (Sep 25, 2007)

C:\WINDOWS\~tmp5823.exe
C:\WINDOWS\~tmp5826.exe
C:\WINDOWS\~tmp5828.exe
C:\WINDOWS\~tmp5829.exe
C:\WINDOWS\~tmp5830.exe
C:\WINDOWS\~tmp5831.exe
C:\WINDOWS\~tmp5833.exe
C:\WINDOWS\~tmp5834.exe
C:\WINDOWS\~tmp5835.exe
C:\WINDOWS\~tmp5837.exe
C:\WINDOWS\~tmp584.exe
C:\WINDOWS\~tmp5841.exe
C:\WINDOWS\~tmp5842.exe
C:\WINDOWS\~tmp5843.exe
C:\WINDOWS\~tmp5845.exe
C:\WINDOWS\~tmp5846.exe
C:\WINDOWS\~tmp5847.exe
C:\WINDOWS\~tmp5849.exe
C:\WINDOWS\~tmp585.exe
C:\WINDOWS\~tmp5850.exe
C:\WINDOWS\~tmp5851.exe
C:\WINDOWS\~tmp5852.exe
C:\WINDOWS\~tmp5853.exe
C:\WINDOWS\~tmp5854.exe
C:\WINDOWS\~tmp5856.exe
C:\WINDOWS\~tmp5860.exe
C:\WINDOWS\~tmp5862.exe
C:\WINDOWS\~tmp5865.exe
C:\WINDOWS\~tmp5867.exe
C:\WINDOWS\~tmp5870.exe
C:\WINDOWS\~tmp5877.exe
C:\WINDOWS\~tmp5882.exe
C:\WINDOWS\~tmp5883.exe
C:\WINDOWS\~tmp5886.exe
C:\WINDOWS\~tmp5887.exe
C:\WINDOWS\~tmp5889.exe
C:\WINDOWS\~tmp589.exe
C:\WINDOWS\~tmp5890.exe
C:\WINDOWS\~tmp5891.exe
C:\WINDOWS\~tmp5894.exe
C:\WINDOWS\~tmp5895.exe
C:\WINDOWS\~tmp5899.exe
C:\WINDOWS\~tmp590.exe
C:\WINDOWS\~tmp5900.exe
C:\WINDOWS\~tmp5902.exe
C:\WINDOWS\~tmp5904.exe
C:\WINDOWS\~tmp5906.exe
C:\WINDOWS\~tmp5908.exe
C:\WINDOWS\~tmp5912.exe
C:\WINDOWS\~tmp5914.exe
C:\WINDOWS\~tmp5915.exe
C:\WINDOWS\~tmp5916.exe
C:\WINDOWS\~tmp5918.exe
C:\WINDOWS\~tmp5919.exe
C:\WINDOWS\~tmp592.exe
C:\WINDOWS\~tmp5921.exe
C:\WINDOWS\~tmp5924.exe
C:\WINDOWS\~tmp5926.exe
C:\WINDOWS\~tmp5927.exe
C:\WINDOWS\~tmp5928.exe
C:\WINDOWS\~tmp593.exe
C:\WINDOWS\~tmp5931.exe
C:\WINDOWS\~tmp5932.exe
C:\WINDOWS\~tmp5936.exe
C:\WINDOWS\~tmp5939.exe
C:\WINDOWS\~tmp594.exe
C:\WINDOWS\~tmp5940.exe
C:\WINDOWS\~tmp5941.exe
C:\WINDOWS\~tmp5943.exe
C:\WINDOWS\~tmp5944.exe
C:\WINDOWS\~tmp5945.exe
C:\WINDOWS\~tmp5951.exe
C:\WINDOWS\~tmp5952.exe
C:\WINDOWS\~tmp5953.exe
C:\WINDOWS\~tmp5955.exe
C:\WINDOWS\~tmp5957.exe
C:\WINDOWS\~tmp596.exe
C:\WINDOWS\~tmp5960.exe
C:\WINDOWS\~tmp5962.exe
C:\WINDOWS\~tmp5964.exe
C:\WINDOWS\~tmp5967.exe
C:\WINDOWS\~tmp5969.exe
C:\WINDOWS\~tmp597.exe
C:\WINDOWS\~tmp5970.exe
C:\WINDOWS\~tmp5971.exe
C:\WINDOWS\~tmp5972.exe
C:\WINDOWS\~tmp5975.exe
C:\WINDOWS\~tmp598.exe
C:\WINDOWS\~tmp5981.exe
C:\WINDOWS\~tmp5982.exe
C:\WINDOWS\~tmp5984.exe
C:\WINDOWS\~tmp5985.exe
C:\WINDOWS\~tmp5988.exe
C:\WINDOWS\~tmp5989.exe
C:\WINDOWS\~tmp599.exe
C:\WINDOWS\~tmp5990.exe
C:\WINDOWS\~tmp5991.exe
C:\WINDOWS\~tmp5993.exe
C:\WINDOWS\~tmp5994.exe
C:\WINDOWS\~tmp5995.exe
C:\WINDOWS\~tmp5996.exe
C:\WINDOWS\~tmp5997.exe
C:\WINDOWS\~tmp5998.exe
C:\WINDOWS\~tmp5999.exe
C:\WINDOWS\~tmp6.exe
C:\WINDOWS\~tmp600.exe
C:\WINDOWS\~tmp6006.exe
C:\WINDOWS\~tmp6007.exe
C:\WINDOWS\~tmp6012.exe
C:\WINDOWS\~tmp6014.exe
C:\WINDOWS\~tmp6015.exe
C:\WINDOWS\~tmp6017.exe
C:\WINDOWS\~tmp6019.exe
C:\WINDOWS\~tmp6022.exe
C:\WINDOWS\~tmp6026.exe
C:\WINDOWS\~tmp6028.exe
C:\WINDOWS\~tmp603.exe
C:\WINDOWS\~tmp6031.exe
C:\WINDOWS\~tmp6033.exe
C:\WINDOWS\~tmp6035.exe
C:\WINDOWS\~tmp6036.exe
C:\WINDOWS\~tmp6037.exe
C:\WINDOWS\~tmp6038.exe
C:\WINDOWS\~tmp6039.exe
C:\WINDOWS\~tmp604.exe
C:\WINDOWS\~tmp6040.exe
C:\WINDOWS\~tmp6042.exe
C:\WINDOWS\~tmp6046.exe
C:\WINDOWS\~tmp6049.exe
C:\WINDOWS\~tmp6050.exe
C:\WINDOWS\~tmp6054.exe
C:\WINDOWS\~tmp6058.exe
C:\WINDOWS\~tmp6062.exe
C:\WINDOWS\~tmp6063.exe
C:\WINDOWS\~tmp6064.exe
C:\WINDOWS\~tmp6065.exe
C:\WINDOWS\~tmp6066.exe
C:\WINDOWS\~tmp6069.exe
C:\WINDOWS\~tmp607.exe
C:\WINDOWS\~tmp6070.exe
C:\WINDOWS\~tmp6071.exe
C:\WINDOWS\~tmp6072.exe
C:\WINDOWS\~tmp6077.exe
C:\WINDOWS\~tmp6080.exe
C:\WINDOWS\~tmp6083.exe
C:\WINDOWS\~tmp6084.exe
C:\WINDOWS\~tmp6085.exe
C:\WINDOWS\~tmp6086.exe
C:\WINDOWS\~tmp6087.exe
C:\WINDOWS\~tmp609.exe
C:\WINDOWS\~tmp6090.exe
C:\WINDOWS\~tmp6091.exe
C:\WINDOWS\~tmp6093.exe
C:\WINDOWS\~tmp6096.exe
C:\WINDOWS\~tmp6097.exe
C:\WINDOWS\~tmp6098.exe
C:\WINDOWS\~tmp6099.exe
C:\WINDOWS\~tmp61.exe
C:\WINDOWS\~tmp6101.exe
C:\WINDOWS\~tmp6102.exe
C:\WINDOWS\~tmp6103.exe
C:\WINDOWS\~tmp6105.exe
C:\WINDOWS\~tmp6106.exe
C:\WINDOWS\~tmp6109.exe
C:\WINDOWS\~tmp6111.exe
C:\WINDOWS\~tmp6112.exe
C:\WINDOWS\~tmp6116.exe
C:\WINDOWS\~tmp6118.exe
C:\WINDOWS\~tmp612.exe
C:\WINDOWS\~tmp6121.exe
C:\WINDOWS\~tmp6123.exe
C:\WINDOWS\~tmp6124.exe
C:\WINDOWS\~tmp6125.exe
C:\WINDOWS\~tmp6127.exe
C:\WINDOWS\~tmp6129.exe
C:\WINDOWS\~tmp613.exe
C:\WINDOWS\~tmp6131.exe
C:\WINDOWS\~tmp6132.exe
C:\WINDOWS\~tmp6134.exe
C:\WINDOWS\~tmp6137.exe
C:\WINDOWS\~tmp6138.exe
C:\WINDOWS\~tmp6139.exe
C:\WINDOWS\~tmp614.exe
C:\WINDOWS\~tmp6142.exe
C:\WINDOWS\~tmp6144.exe
C:\WINDOWS\~tmp6146.exe
C:\WINDOWS\~tmp6148.exe
C:\WINDOWS\~tmp615.exe
C:\WINDOWS\~tmp6150.exe
C:\WINDOWS\~tmp6151.exe
C:\WINDOWS\~tmp6153.exe
C:\WINDOWS\~tmp6155.exe
C:\WINDOWS\~tmp6157.exe
C:\WINDOWS\~tmp6159.exe
C:\WINDOWS\~tmp616.exe
C:\WINDOWS\~tmp6162.exe
C:\WINDOWS\~tmp6163.exe
C:\WINDOWS\~tmp6165.exe
C:\WINDOWS\~tmp6168.exe
C:\WINDOWS\~tmp6170.exe
C:\WINDOWS\~tmp6171.exe
C:\WINDOWS\~tmp6172.exe
C:\WINDOWS\~tmp6174.exe
C:\WINDOWS\~tmp6175.exe
C:\WINDOWS\~tmp6177.exe
C:\WINDOWS\~tmp6178.exe
C:\WINDOWS\~tmp6179.exe
C:\WINDOWS\~tmp6180.exe
C:\WINDOWS\~tmp6181.exe
C:\WINDOWS\~tmp6182.exe
C:\WINDOWS\~tmp6183.exe
C:\WINDOWS\~tmp6184.exe
C:\WINDOWS\~tmp6186.exe
C:\WINDOWS\~tmp619.exe
C:\WINDOWS\~tmp6190.exe
C:\WINDOWS\~tmp6193.exe
C:\WINDOWS\~tmp6194.exe
C:\WINDOWS\~tmp6195.exe
C:\WINDOWS\~tmp6196.exe
C:\WINDOWS\~tmp6199.exe
C:\WINDOWS\~tmp6200.exe
C:\WINDOWS\~tmp6201.exe
C:\WINDOWS\~tmp6203.exe
C:\WINDOWS\~tmp6205.exe
C:\WINDOWS\~tmp6210.exe
C:\WINDOWS\~tmp6211.exe
C:\WINDOWS\~tmp6213.exe
C:\WINDOWS\~tmp6214.exe
C:\WINDOWS\~tmp6217.exe
C:\WINDOWS\~tmp6218.exe
C:\WINDOWS\~tmp622.exe
C:\WINDOWS\~tmp6220.exe
C:\WINDOWS\~tmp6221.exe
C:\WINDOWS\~tmp6222.exe
C:\WINDOWS\~tmp6223.exe
C:\WINDOWS\~tmp6224.exe
C:\WINDOWS\~tmp6225.exe
C:\WINDOWS\~tmp6226.exe
C:\WINDOWS\~tmp6227.exe
C:\WINDOWS\~tmp6228.exe
C:\WINDOWS\~tmp6229.exe
C:\WINDOWS\~tmp623.exe
C:\WINDOWS\~tmp6230.exe
C:\WINDOWS\~tmp6231.exe
C:\WINDOWS\~tmp6232.exe
C:\WINDOWS\~tmp6234.exe
C:\WINDOWS\~tmp6235.exe
C:\WINDOWS\~tmp6236.exe
C:\WINDOWS\~tmp6237.exe
C:\WINDOWS\~tmp6238.exe
C:\WINDOWS\~tmp6239.exe
C:\WINDOWS\~tmp6243.exe
C:\WINDOWS\~tmp6244.exe
C:\WINDOWS\~tmp6248.exe
C:\WINDOWS\~tmp625.exe
C:\WINDOWS\~tmp6250.exe
C:\WINDOWS\~tmp6251.exe
C:\WINDOWS\~tmp6253.exe
C:\WINDOWS\~tmp6254.exe
C:\WINDOWS\~tmp6256.exe
C:\WINDOWS\~tmp6258.exe
C:\WINDOWS\~tmp6259.exe
C:\WINDOWS\~tmp626.exe
C:\WINDOWS\~tmp6261.exe
C:\WINDOWS\~tmp6262.exe
C:\WINDOWS\~tmp6264.exe
C:\WINDOWS\~tmp6265.exe
C:\WINDOWS\~tmp6266.exe
C:\WINDOWS\~tmp6267.exe
C:\WINDOWS\~tmp627.exe
C:\WINDOWS\~tmp6270.exe
C:\WINDOWS\~tmp6271.exe
C:\WINDOWS\~tmp6273.exe
C:\WINDOWS\~tmp6274.exe
C:\WINDOWS\~tmp6275.exe
C:\WINDOWS\~tmp6279.exe
C:\WINDOWS\~tmp628.exe
C:\WINDOWS\~tmp6280.exe
C:\WINDOWS\~tmp6282.exe
C:\WINDOWS\~tmp6283.exe
C:\WINDOWS\~tmp6285.exe
C:\WINDOWS\~tmp6286.exe
C:\WINDOWS\~tmp6288.exe
C:\WINDOWS\~tmp6289.exe
C:\WINDOWS\~tmp6291.exe
C:\WINDOWS\~tmp6296.exe
C:\WINDOWS\~tmp6298.exe
C:\WINDOWS\~tmp63.exe
C:\WINDOWS\~tmp630.exe
C:\WINDOWS\~tmp6300.exe
C:\WINDOWS\~tmp6302.exe
C:\WINDOWS\~tmp6303.exe
C:\WINDOWS\~tmp6304.exe
C:\WINDOWS\~tmp6305.exe
C:\WINDOWS\~tmp6307.exe
C:\WINDOWS\~tmp6309.exe
C:\WINDOWS\~tmp631.exe
C:\WINDOWS\~tmp6310.exe
C:\WINDOWS\~tmp6311.exe
C:\WINDOWS\~tmp6312.exe
C:\WINDOWS\~tmp6316.exe
C:\WINDOWS\~tmp6317.exe
C:\WINDOWS\~tmp6318.exe
C:\WINDOWS\~tmp632.exe
C:\WINDOWS\~tmp6320.exe
C:\WINDOWS\~tmp6322.exe
C:\WINDOWS\~tmp6325.exe
C:\WINDOWS\~tmp6326.exe
C:\WINDOWS\~tmp6327.exe
C:\WINDOWS\~tmp6328.exe
C:\WINDOWS\~tmp633.exe
C:\WINDOWS\~tmp6330.exe
C:\WINDOWS\~tmp6331.exe
C:\WINDOWS\~tmp6332.exe
C:\WINDOWS\~tmp6335.exe
C:\WINDOWS\~tmp6336.exe
C:\WINDOWS\~tmp6337.exe
C:\WINDOWS\~tmp6344.exe
C:\WINDOWS\~tmp6345.exe
C:\WINDOWS\~tmp6346.exe
C:\WINDOWS\~tmp6352.exe
C:\WINDOWS\~tmp6355.exe
C:\WINDOWS\~tmp6357.exe
C:\WINDOWS\~tmp6358.exe
C:\WINDOWS\~tmp6359.exe
C:\WINDOWS\~tmp636.exe
C:\WINDOWS\~tmp6360.exe
C:\WINDOWS\~tmp6362.exe
C:\WINDOWS\~tmp6365.exe
C:\WINDOWS\~tmp6366.exe
C:\WINDOWS\~tmp6367.exe
C:\WINDOWS\~tmp637.exe
C:\WINDOWS\~tmp6371.exe
C:\WINDOWS\~tmp6372.exe
C:\WINDOWS\~tmp6373.exe
C:\WINDOWS\~tmp6375.exe
C:\WINDOWS\~tmp6378.exe
C:\WINDOWS\~tmp6379.exe
C:\WINDOWS\~tmp6380.exe
C:\WINDOWS\~tmp6381.exe
C:\WINDOWS\~tmp6382.exe
C:\WINDOWS\~tmp6383.exe
C:\WINDOWS\~tmp6384.exe
C:\WINDOWS\~tmp6386.exe
C:\WINDOWS\~tmp6387.exe
C:\WINDOWS\~tmp6388.exe
C:\WINDOWS\~tmp6389.exe
C:\WINDOWS\~tmp6390.exe
C:\WINDOWS\~tmp6391.exe
C:\WINDOWS\~tmp6392.exe
C:\WINDOWS\~tmp6394.exe
C:\WINDOWS\~tmp6396.exe
C:\WINDOWS\~tmp6397.exe
C:\WINDOWS\~tmp6398.exe
C:\WINDOWS\~tmp640.exe
C:\WINDOWS\~tmp6402.exe
C:\WINDOWS\~tmp6404.exe
C:\WINDOWS\~tmp6406.exe
C:\WINDOWS\~tmp6407.exe
C:\WINDOWS\~tmp6408.exe
C:\WINDOWS\~tmp6409.exe
C:\WINDOWS\~tmp6410.exe
C:\WINDOWS\~tmp6411.exe
C:\WINDOWS\~tmp6413.exe
C:\WINDOWS\~tmp6414.exe
C:\WINDOWS\~tmp6415.exe
C:\WINDOWS\~tmp6417.exe
C:\WINDOWS\~tmp642.exe
C:\WINDOWS\~tmp6423.exe
C:\WINDOWS\~tmp6426.exe
C:\WINDOWS\~tmp6427.exe
C:\WINDOWS\~tmp6428.exe
C:\WINDOWS\~tmp6429.exe
C:\WINDOWS\~tmp643.exe
C:\WINDOWS\~tmp6430.exe
C:\WINDOWS\~tmp6433.exe
C:\WINDOWS\~tmp6435.exe
C:\WINDOWS\~tmp6436.exe
C:\WINDOWS\~tmp6437.exe
C:\WINDOWS\~tmp6438.exe
C:\WINDOWS\~tmp644.exe
C:\WINDOWS\~tmp6440.exe
C:\WINDOWS\~tmp6442.exe
C:\WINDOWS\~tmp6444.exe
C:\WINDOWS\~tmp6446.exe
C:\WINDOWS\~tmp6447.exe
C:\WINDOWS\~tmp6448.exe
C:\WINDOWS\~tmp6451.exe
C:\WINDOWS\~tmp6453.exe
C:\WINDOWS\~tmp6455.exe
C:\WINDOWS\~tmp6457.exe
C:\WINDOWS\~tmp6459.exe
C:\WINDOWS\~tmp6460.exe
C:\WINDOWS\~tmp6461.exe
C:\WINDOWS\~tmp6463.exe
C:\WINDOWS\~tmp6464.exe
C:\WINDOWS\~tmp6465.exe
C:\WINDOWS\~tmp647.exe
C:\WINDOWS\~tmp6471.exe
C:\WINDOWS\~tmp6474.exe
C:\WINDOWS\~tmp6477.exe
C:\WINDOWS\~tmp6478.exe
C:\WINDOWS\~tmp6480.exe
C:\WINDOWS\~tmp6481.exe
C:\WINDOWS\~tmp6484.exe
C:\WINDOWS\~tmp6485.exe
C:\WINDOWS\~tmp6486.exe
C:\WINDOWS\~tmp6487.exe
C:\WINDOWS\~tmp649.exe
C:\WINDOWS\~tmp6490.exe
C:\WINDOWS\~tmp6491.exe
C:\WINDOWS\~tmp6492.exe
C:\WINDOWS\~tmp6493.exe
C:\WINDOWS\~tmp6494.exe
C:\WINDOWS\~tmp6495.exe
C:\WINDOWS\~tmp6498.exe
C:\WINDOWS\~tmp6499.exe
C:\WINDOWS\~tmp650.exe
C:\WINDOWS\~tmp6502.exe
C:\WINDOWS\~tmp6503.exe
C:\WINDOWS\~tmp6505.exe
C:\WINDOWS\~tmp6506.exe
C:\WINDOWS\~tmp6508.exe
C:\WINDOWS\~tmp6509.exe
C:\WINDOWS\~tmp651.exe
C:\WINDOWS\~tmp6510.exe
C:\WINDOWS\~tmp6511.exe
C:\WINDOWS\~tmp6514.exe
C:\WINDOWS\~tmp6515.exe
C:\WINDOWS\~tmp6516.exe
C:\WINDOWS\~tmp6519.exe
C:\WINDOWS\~tmp652.exe
C:\WINDOWS\~tmp6524.exe
C:\WINDOWS\~tmp6526.exe
C:\WINDOWS\~tmp6528.exe
C:\WINDOWS\~tmp6529.exe
C:\WINDOWS\~tmp653.exe
C:\WINDOWS\~tmp6530.exe
C:\WINDOWS\~tmp6532.exe
C:\WINDOWS\~tmp6533.exe
C:\WINDOWS\~tmp6534.exe
C:\WINDOWS\~tmp6535.exe
C:\WINDOWS\~tmp6537.exe
C:\WINDOWS\~tmp6543.exe
C:\WINDOWS\~tmp6544.exe
C:\WINDOWS\~tmp6546.exe
C:\WINDOWS\~tmp6549.exe
C:\WINDOWS\~tmp6554.exe
C:\WINDOWS\~tmp6555.exe
C:\WINDOWS\~tmp6557.exe
C:\WINDOWS\~tmp6559.exe
C:\WINDOWS\~tmp656.exe
C:\WINDOWS\~tmp6560.exe
C:\WINDOWS\~tmp6561.exe
C:\WINDOWS\~tmp6562.exe
C:\WINDOWS\~tmp6564.exe
C:\WINDOWS\~tmp6566.exe
C:\WINDOWS\~tmp6569.exe
C:\WINDOWS\~tmp657.exe
C:\WINDOWS\~tmp6570.exe
C:\WINDOWS\~tmp6571.exe
C:\WINDOWS\~tmp6573.exe
C:\WINDOWS\~tmp6577.exe
C:\WINDOWS\~tmp6578.exe
C:\WINDOWS\~tmp658.exe
C:\WINDOWS\~tmp6583.exe
C:\WINDOWS\~tmp6584.exe
C:\WINDOWS\~tmp6585.exe
C:\WINDOWS\~tmp6586.exe
C:\WINDOWS\~tmp6591.exe
C:\WINDOWS\~tmp6592.exe
C:\WINDOWS\~tmp6594.exe
C:\WINDOWS\~tmp6595.exe
C:\WINDOWS\~tmp6596.exe
C:\WINDOWS\~tmp6597.exe
C:\WINDOWS\~tmp660.exe
C:\WINDOWS\~tmp6600.exe
C:\WINDOWS\~tmp6601.exe
C:\WINDOWS\~tmp6602.exe
C:\WINDOWS\~tmp6603.exe
C:\WINDOWS\~tmp6604.exe
C:\WINDOWS\~tmp6606.exe
C:\WINDOWS\~tmp6607.exe
C:\WINDOWS\~tmp661.exe
C:\WINDOWS\~tmp6611.exe
C:\WINDOWS\~tmp6612.exe
C:\WINDOWS\~tmp6613.exe
C:\WINDOWS\~tmp6614.exe
C:\WINDOWS\~tmp6615.exe
C:\WINDOWS\~tmp6616.exe
C:\WINDOWS\~tmp6617.exe
C:\WINDOWS\~tmp6618.exe
C:\WINDOWS\~tmp6619.exe
C:\WINDOWS\~tmp6620.exe
C:\WINDOWS\~tmp6622.exe
C:\WINDOWS\~tmp6626.exe
C:\WINDOWS\~tmp6628.exe
C:\WINDOWS\~tmp6630.exe
C:\WINDOWS\~tmp6634.exe
C:\WINDOWS\~tmp6637.exe
C:\WINDOWS\~tmp6639.exe
C:\WINDOWS\~tmp6640.exe
C:\WINDOWS\~tmp6641.exe
C:\WINDOWS\~tmp6645.exe
C:\WINDOWS\~tmp6646.exe
C:\WINDOWS\~tmp665.exe
C:\WINDOWS\~tmp6652.exe
C:\WINDOWS\~tmp6653.exe
C:\WINDOWS\~tmp6654.exe
C:\WINDOWS\~tmp6655.exe
C:\WINDOWS\~tmp6656.exe
C:\WINDOWS\~tmp6657.exe
C:\WINDOWS\~tmp666.exe
C:\WINDOWS\~tmp6660.exe
C:\WINDOWS\~tmp6661.exe
C:\WINDOWS\~tmp6663.exe
C:\WINDOWS\~tmp6664.exe
C:\WINDOWS\~tmp6665.exe
C:\WINDOWS\~tmp6667.exe
C:\WINDOWS\~tmp6668.exe
C:\WINDOWS\~tmp667.exe
C:\WINDOWS\~tmp6670.exe
C:\WINDOWS\~tmp6671.exe
C:\WINDOWS\~tmp6672.exe
C:\WINDOWS\~tmp6673.exe
C:\WINDOWS\~tmp6675.exe
C:\WINDOWS\~tmp6676.exe
C:\WINDOWS\~tmp6677.exe
C:\WINDOWS\~tmp6680.exe
C:\WINDOWS\~tmp6681.exe
C:\WINDOWS\~tmp6682.exe
C:\WINDOWS\~tmp6683.exe
C:\WINDOWS\~tmp6685.exe
C:\WINDOWS\~tmp6686.exe
C:\WINDOWS\~tmp6687.exe
C:\WINDOWS\~tmp6688.exe
C:\WINDOWS\~tmp6689.exe
C:\WINDOWS\~tmp669.exe
C:\WINDOWS\~tmp6690.exe
C:\WINDOWS\~tmp6694.exe
C:\WINDOWS\~tmp6698.exe
C:\WINDOWS\~tmp67.exe
C:\WINDOWS\~tmp670.exe
C:\WINDOWS\~tmp6700.exe
C:\WINDOWS\~tmp6701.exe
C:\WINDOWS\~tmp6702.exe
C:\WINDOWS\~tmp6703.exe
C:\WINDOWS\~tmp6704.exe
C:\WINDOWS\~tmp6705.exe
C:\WINDOWS\~tmp6706.exe
C:\WINDOWS\~tmp6707.exe
C:\WINDOWS\~tmp6710.exe
C:\WINDOWS\~tmp6711.exe
C:\WINDOWS\~tmp6712.exe
C:\WINDOWS\~tmp6714.exe
C:\WINDOWS\~tmp6717.exe
C:\WINDOWS\~tmp672.exe
C:\WINDOWS\~tmp6722.exe
C:\WINDOWS\~tmp6728.exe
C:\WINDOWS\~tmp6729.exe
C:\WINDOWS\~tmp673.exe
C:\WINDOWS\~tmp6732.exe
C:\WINDOWS\~tmp6733.exe
C:\WINDOWS\~tmp6735.exe
C:\WINDOWS\~tmp6736.exe
C:\WINDOWS\~tmp6737.exe
C:\WINDOWS\~tmp674.exe
C:\WINDOWS\~tmp6741.exe
C:\WINDOWS\~tmp6742.exe
C:\WINDOWS\~tmp6744.exe
C:\WINDOWS\~tmp6745.exe
C:\WINDOWS\~tmp675.exe
C:\WINDOWS\~tmp6751.exe
C:\WINDOWS\~tmp6752.exe
C:\WINDOWS\~tmp6759.exe
C:\WINDOWS\~tmp6762.exe
C:\WINDOWS\~tmp6763.exe
C:\WINDOWS\~tmp6764.exe
C:\WINDOWS\~tmp6766.exe
C:\WINDOWS\~tmp6767.exe
C:\WINDOWS\~tmp6770.exe
C:\WINDOWS\~tmp6771.exe
C:\WINDOWS\~tmp6772.exe
C:\WINDOWS\~tmp6774.exe
C:\WINDOWS\~tmp6775.exe
C:\WINDOWS\~tmp6777.exe
C:\WINDOWS\~tmp6778.exe
C:\WINDOWS\~tmp6779.exe
C:\WINDOWS\~tmp6780.exe
C:\WINDOWS\~tmp6781.exe
C:\WINDOWS\~tmp6782.exe
C:\WINDOWS\~tmp6783.exe
C:\WINDOWS\~tmp6784.exe
C:\WINDOWS\~tmp6785.exe
C:\WINDOWS\~tmp6786.exe
C:\WINDOWS\~tmp6788.exe
C:\WINDOWS\~tmp6789.exe
C:\WINDOWS\~tmp679.exe
C:\WINDOWS\~tmp6791.exe
C:\WINDOWS\~tmp6792.exe
C:\WINDOWS\~tmp6794.exe
C:\WINDOWS\~tmp6796.exe
C:\WINDOWS\~tmp68.exe
C:\WINDOWS\~tmp680.exe
C:\WINDOWS\~tmp6800.exe
C:\WINDOWS\~tmp6801.exe
C:\WINDOWS\~tmp6805.exe
C:\WINDOWS\~tmp6806.exe
C:\WINDOWS\~tmp6807.exe
C:\WINDOWS\~tmp6808.exe
C:\WINDOWS\~tmp681.exe
C:\WINDOWS\~tmp6812.exe
C:\WINDOWS\~tmp6813.exe
C:\WINDOWS\~tmp6816.exe
C:\WINDOWS\~tmp6817.exe
C:\WINDOWS\~tmp6818.exe
C:\WINDOWS\~tmp6819.exe
C:\WINDOWS\~tmp682.exe
C:\WINDOWS\~tmp6820.exe
C:\WINDOWS\~tmp6821.exe
C:\WINDOWS\~tmp6822.exe
C:\WINDOWS\~tmp6824.exe
C:\WINDOWS\~tmp6833.exe
C:\WINDOWS\~tmp6834.exe
C:\WINDOWS\~tmp6839.exe
C:\WINDOWS\~tmp684.exe
C:\WINDOWS\~tmp6840.exe
C:\WINDOWS\~tmp6841.exe
C:\WINDOWS\~tmp6842.exe
C:\WINDOWS\~tmp6846.exe
C:\WINDOWS\~tmp6847.exe
C:\WINDOWS\~tmp6849.exe
C:\WINDOWS\~tmp685.exe
C:\WINDOWS\~tmp6850.exe
C:\WINDOWS\~tmp6851.exe
C:\WINDOWS\~tmp6852.exe
C:\WINDOWS\~tmp6853.exe
C:\WINDOWS\~tmp6857.exe
C:\WINDOWS\~tmp686.exe
C:\WINDOWS\~tmp6860.exe
C:\WINDOWS\~tmp6861.exe
C:\WINDOWS\~tmp6862.exe
C:\WINDOWS\~tmp6863.exe
C:\WINDOWS\~tmp6864.exe
C:\WINDOWS\~tmp6865.exe
C:\WINDOWS\~tmp6866.exe
C:\WINDOWS\~tmp6867.exe
C:\WINDOWS\~tmp687.exe
C:\WINDOWS\~tmp6870.exe
C:\WINDOWS\~tmp6873.exe
C:\WINDOWS\~tmp6874.exe
C:\WINDOWS\~tmp6876.exe
C:\WINDOWS\~tmp6879.exe
C:\WINDOWS\~tmp6883.exe
C:\WINDOWS\~tmp6886.exe
C:\WINDOWS\~tmp6887.exe
C:\WINDOWS\~tmp6888.exe
C:\WINDOWS\~tmp6892.exe
C:\WINDOWS\~tmp6893.exe
C:\WINDOWS\~tmp6894.exe
C:\WINDOWS\~tmp6895.exe
C:\WINDOWS\~tmp6897.exe
C:\WINDOWS\~tmp6899.exe
C:\WINDOWS\~tmp69.exe
C:\WINDOWS\~tmp6902.exe
C:\WINDOWS\~tmp6904.exe
C:\WINDOWS\~tmp6907.exe
C:\WINDOWS\~tmp6909.exe
C:\WINDOWS\~tmp691.exe
C:\WINDOWS\~tmp6910.exe
C:\WINDOWS\~tmp6911.exe
C:\WINDOWS\~tmp6913.exe
C:\WINDOWS\~tmp6917.exe
C:\WINDOWS\~tmp6920.exe
C:\WINDOWS\~tmp6921.exe
C:\WINDOWS\~tmp6923.exe
C:\WINDOWS\~tmp6926.exe
C:\WINDOWS\~tmp6928.exe
C:\WINDOWS\~tmp6930.exe
C:\WINDOWS\~tmp6933.exe
C:\WINDOWS\~tmp6934.exe
C:\WINDOWS\~tmp6935.exe
C:\WINDOWS\~tmp6937.exe
C:\WINDOWS\~tmp6938.exe
C:\WINDOWS\~tmp6939.exe
C:\WINDOWS\~tmp694.exe
C:\WINDOWS\~tmp6940.exe
C:\WINDOWS\~tmp6941.exe
C:\WINDOWS\~tmp6942.exe
C:\WINDOWS\~tmp6945.exe
C:\WINDOWS\~tmp6946.exe
C:\WINDOWS\~tmp6949.exe
C:\WINDOWS\~tmp695.exe
C:\WINDOWS\~tmp6950.exe
C:\WINDOWS\~tmp6954.exe
C:\WINDOWS\~tmp6955.exe
C:\WINDOWS\~tmp6956.exe
C:\WINDOWS\~tmp6957.exe
C:\WINDOWS\~tmp6958.exe
C:\WINDOWS\~tmp6960.exe
C:\WINDOWS\~tmp6961.exe
C:\WINDOWS\~tmp6962.exe
C:\WINDOWS\~tmp6963.exe
C:\WINDOWS\~tmp6965.exe
C:\WINDOWS\~tmp6971.exe
C:\WINDOWS\~tmp6974.exe
C:\WINDOWS\~tmp6976.exe
C:\WINDOWS\~tmp6977.exe
C:\WINDOWS\~tmp6978.exe
C:\WINDOWS\~tmp698.exe
C:\WINDOWS\~tmp6981.exe
C:\WINDOWS\~tmp6982.exe
C:\WINDOWS\~tmp6984.exe
C:\WINDOWS\~tmp6985.exe
C:\WINDOWS\~tmp6986.exe
C:\WINDOWS\~tmp6987.exe
C:\WINDOWS\~tmp6993.exe
C:\WINDOWS\~tmp6994.exe
C:\WINDOWS\~tmp6995.exe
C:\WINDOWS\~tmp6996.exe
C:\WINDOWS\~tmp7.exe
C:\WINDOWS\~tmp7000.exe
C:\WINDOWS\~tmp7001.exe
C:\WINDOWS\~tmp7002.exe
C:\WINDOWS\~tmp7003.exe
C:\WINDOWS\~tmp7006.exe
C:\WINDOWS\~tmp7008.exe
C:\WINDOWS\~tmp7009.exe
C:\WINDOWS\~tmp7010.exe
C:\WINDOWS\~tmp7012.exe
C:\WINDOWS\~tmp7014.exe
C:\WINDOWS\~tmp7015.exe
C:\WINDOWS\~tmp7020.exe
C:\WINDOWS\~tmp7022.exe
C:\WINDOWS\~tmp7023.exe
C:\WINDOWS\~tmp7024.exe
C:\WINDOWS\~tmp7025.exe
C:\WINDOWS\~tmp7026.exe
C:\WINDOWS\~tmp703.exe
C:\WINDOWS\~tmp7030.exe
C:\WINDOWS\~tmp7032.exe
C:\WINDOWS\~tmp7036.exe
C:\WINDOWS\~tmp7037.exe
C:\WINDOWS\~tmp7038.exe
C:\WINDOWS\~tmp7041.exe
C:\WINDOWS\~tmp7042.exe
C:\WINDOWS\~tmp7043.exe
C:\WINDOWS\~tmp7044.exe
C:\WINDOWS\~tmp7047.exe
C:\WINDOWS\~tmp7048.exe
C:\WINDOWS\~tmp7049.exe
C:\WINDOWS\~tmp7050.exe
C:\WINDOWS\~tmp7051.exe
C:\WINDOWS\~tmp7052.exe
C:\WINDOWS\~tmp7053.exe
C:\WINDOWS\~tmp7056.exe
C:\WINDOWS\~tmp7057.exe
C:\WINDOWS\~tmp7058.exe
C:\WINDOWS\~tmp706.exe
C:\WINDOWS\~tmp7061.exe
C:\WINDOWS\~tmp7064.exe
C:\WINDOWS\~tmp7065.exe
C:\WINDOWS\~tmp7066.exe
C:\WINDOWS\~tmp7067.exe
C:\WINDOWS\~tmp7072.exe
C:\WINDOWS\~tmp7073.exe
C:\WINDOWS\~tmp7078.exe
C:\WINDOWS\~tmp708.exe
C:\WINDOWS\~tmp7080.exe
C:\WINDOWS\~tmp7083.exe
C:\WINDOWS\~tmp7084.exe
C:\WINDOWS\~tmp7086.exe
C:\WINDOWS\~tmp7087.exe
C:\WINDOWS\~tmp7088.exe
C:\WINDOWS\~tmp709.exe
C:\WINDOWS\~tmp7090.exe
C:\WINDOWS\~tmp7091.exe
C:\WINDOWS\~tmp7092.exe
C:\WINDOWS\~tmp7095.exe
C:\WINDOWS\~tmp7096.exe
C:\WINDOWS\~tmp7098.exe
C:\WINDOWS\~tmp71.exe
C:\WINDOWS\~tmp7102.exe
C:\WINDOWS\~tmp7104.exe
C:\WINDOWS\~tmp7105.exe
C:\WINDOWS\~tmp7106.exe
C:\WINDOWS\~tmp7107.exe
C:\WINDOWS\~tmp7109.exe
C:\WINDOWS\~tmp711.exe
C:\WINDOWS\~tmp7110.exe
C:\WINDOWS\~tmp7111.exe
C:\WINDOWS\~tmp7114.exe
C:\WINDOWS\~tmp7117.exe
C:\WINDOWS\~tmp7118.exe
C:\WINDOWS\~tmp712.exe
C:\WINDOWS\~tmp7122.exe
C:\WINDOWS\~tmp7125.exe
C:\WINDOWS\~tmp7127.exe
C:\WINDOWS\~tmp713.exe
C:\WINDOWS\~tmp7131.exe
C:\WINDOWS\~tmp7132.exe
C:\WINDOWS\~tmp7136.exe
C:\WINDOWS\~tmp7137.exe
C:\WINDOWS\~tmp7141.exe
C:\WINDOWS\~tmp7142.exe
C:\WINDOWS\~tmp7143.exe
C:\WINDOWS\~tmp7147.exe
C:\WINDOWS\~tmp7148.exe
C:\WINDOWS\~tmp715.exe
C:\WINDOWS\~tmp7150.exe
C:\WINDOWS\~tmp7151.exe
C:\WINDOWS\~tmp7152.exe
C:\WINDOWS\~tmp7153.exe
C:\WINDOWS\~tmp7154.exe
C:\WINDOWS\~tmp7157.exe
C:\WINDOWS\~tmp7158.exe
C:\WINDOWS\~tmp716.exe
C:\WINDOWS\~tmp7160.exe
C:\WINDOWS\~tmp7163.exe
C:\WINDOWS\~tmp717.exe
C:\WINDOWS\~tmp7170.exe
C:\WINDOWS\~tmp7172.exe
C:\WINDOWS\~tmp7174.exe
C:\WINDOWS\~tmp7175.exe
C:\WINDOWS\~tmp7176.exe
C:\WINDOWS\~tmp7177.exe
C:\WINDOWS\~tmp7178.exe
C:\WINDOWS\~tmp7179.exe
C:\WINDOWS\~tmp7186.exe
C:\WINDOWS\~tmp7187.exe
C:\WINDOWS\~tmp7188.exe
C:\WINDOWS\~tmp7189.exe
C:\WINDOWS\~tmp7191.exe
C:\WINDOWS\~tmp7192.exe
C:\WINDOWS\~tmp7193.exe
C:\WINDOWS\~tmp7194.exe
C:\WINDOWS\~tmp7195.exe
C:\WINDOWS\~tmp7197.exe
C:\WINDOWS\~tmp7198.exe
C:\WINDOWS\~tmp72.exe
C:\WINDOWS\~tmp7201.exe
C:\WINDOWS\~tmp7202.exe
C:\WINDOWS\~tmp7206.exe
C:\WINDOWS\~tmp7207.exe
C:\WINDOWS\~tmp7208.exe
C:\WINDOWS\~tmp7209.exe
C:\WINDOWS\~tmp721.exe
C:\WINDOWS\~tmp7212.exe
C:\WINDOWS\~tmp7214.exe
C:\WINDOWS\~tmp7216.exe
C:\WINDOWS\~tmp7217.exe
C:\WINDOWS\~tmp7218.exe
C:\WINDOWS\~tmp7219.exe
C:\WINDOWS\~tmp722.exe
C:\WINDOWS\~tmp7222.exe
C:\WINDOWS\~tmp7224.exe
C:\WINDOWS\~tmp7225.exe
C:\WINDOWS\~tmp7227.exe
C:\WINDOWS\~tmp7228.exe
C:\WINDOWS\~tmp723.exe
C:\WINDOWS\~tmp7230.exe
C:\WINDOWS\~tmp7231.exe
C:\WINDOWS\~tmp7232.exe
C:\WINDOWS\~tmp7233.exe
C:\WINDOWS\~tmp7238.exe
C:\WINDOWS\~tmp7239.exe
C:\WINDOWS\~tmp724.exe
C:\WINDOWS\~tmp7243.exe
C:\WINDOWS\~tmp7245.exe
C:\WINDOWS\~tmp7246.exe
C:\WINDOWS\~tmp7249.exe
C:\WINDOWS\~tmp7250.exe
C:\WINDOWS\~tmp7252.exe
C:\WINDOWS\~tmp7254.exe
C:\WINDOWS\~tmp7257.exe
C:\WINDOWS\~tmp7258.exe
C:\WINDOWS\~tmp7259.exe
C:\WINDOWS\~tmp7261.exe
C:\WINDOWS\~tmp7262.exe
C:\WINDOWS\~tmp7263.exe
C:\WINDOWS\~tmp7264.exe
C:\WINDOWS\~tmp7266.exe
C:\WINDOWS\~tmp7269.exe
C:\WINDOWS\~tmp727.exe
C:\WINDOWS\~tmp7270.exe
C:\WINDOWS\~tmp7271.exe
C:\WINDOWS\~tmp7273.exe
C:\WINDOWS\~tmp7279.exe
C:\WINDOWS\~tmp7280.exe
C:\WINDOWS\~tmp7283.exe
C:\WINDOWS\~tmp7284.exe
C:\WINDOWS\~tmp7285.exe
C:\WINDOWS\~tmp7287.exe
C:\WINDOWS\~tmp7288.exe
C:\WINDOWS\~tmp729.exe
C:\WINDOWS\~tmp7290.exe
C:\WINDOWS\~tmp7291.exe
C:\WINDOWS\~tmp7293.exe
C:\WINDOWS\~tmp7294.exe
C:\WINDOWS\~tmp7297.exe
C:\WINDOWS\~tmp730.exe
C:\WINDOWS\~tmp7300.exe
C:\WINDOWS\~tmp7305.exe
C:\WINDOWS\~tmp7308.exe
C:\WINDOWS\~tmp7309.exe
C:\WINDOWS\~tmp7310.exe
C:\WINDOWS\~tmp7312.exe
C:\WINDOWS\~tmp7313.exe
C:\WINDOWS\~tmp7315.exe
C:\WINDOWS\~tmp7317.exe
C:\WINDOWS\~tmp7320.exe
C:\WINDOWS\~tmp7321.exe
C:\WINDOWS\~tmp7327.exe
C:\WINDOWS\~tmp7328.exe
C:\WINDOWS\~tmp7329.exe
C:\WINDOWS\~tmp733.exe
C:\WINDOWS\~tmp7330.exe
C:\WINDOWS\~tmp7331.exe
C:\WINDOWS\~tmp7332.exe
C:\WINDOWS\~tmp7334.exe
C:\WINDOWS\~tmp7335.exe
C:\WINDOWS\~tmp7337.exe
C:\WINDOWS\~tmp7338.exe
C:\WINDOWS\~tmp7339.exe
C:\WINDOWS\~tmp7340.exe
C:\WINDOWS\~tmp7345.exe
C:\WINDOWS\~tmp7346.exe
C:\WINDOWS\~tmp7347.exe
C:\WINDOWS\~tmp7348.exe
C:\WINDOWS\~tmp7349.exe
C:\WINDOWS\~tmp735.exe
C:\WINDOWS\~tmp7354.exe
C:\WINDOWS\~tmp7356.exe
C:\WINDOWS\~tmp7357.exe
C:\WINDOWS\~tmp7358.exe
C:\WINDOWS\~tmp7359.exe
C:\WINDOWS\~tmp7361.exe
C:\WINDOWS\~tmp7362.exe
C:\WINDOWS\~tmp7366.exe
C:\WINDOWS\~tmp7367.exe
C:\WINDOWS\~tmp7369.exe
C:\WINDOWS\~tmp737.exe
C:\WINDOWS\~tmp7370.exe
C:\WINDOWS\~tmp7371.exe
C:\WINDOWS\~tmp7375.exe
C:\WINDOWS\~tmp7376.exe
C:\WINDOWS\~tmp7378.exe
C:\WINDOWS\~tmp738.exe
C:\WINDOWS\~tmp7380.exe
C:\WINDOWS\~tmp7381.exe
C:\WINDOWS\~tmp7384.exe
C:\WINDOWS\~tmp7385.exe
C:\WINDOWS\~tmp7386.exe
C:\WINDOWS\~tmp7388.exe
C:\WINDOWS\~tmp7389.exe
C:\WINDOWS\~tmp739.exe
C:\WINDOWS\~tmp7390.exe
C:\WINDOWS\~tmp7393.exe
C:\WINDOWS\~tmp7394.exe
C:\WINDOWS\~tmp74.exe
C:\WINDOWS\~tmp740.exe
C:\WINDOWS\~tmp7405.exe
C:\WINDOWS\~tmp7406.exe
C:\WINDOWS\~tmp7407.exe
C:\WINDOWS\~tmp7408.exe
C:\WINDOWS\~tmp7410.exe
C:\WINDOWS\~tmp7412.exe
C:\WINDOWS\~tmp7413.exe
C:\WINDOWS\~tmp7414.exe
C:\WINDOWS\~tmp7415.exe
C:\WINDOWS\~tmp7418.exe
C:\WINDOWS\~tmp742.exe
C:\WINDOWS\~tmp7420.exe
C:\WINDOWS\~tmp7421.exe
C:\WINDOWS\~tmp7423.exe
C:\WINDOWS\~tmp7425.exe
C:\WINDOWS\~tmp7426.exe
C:\WINDOWS\~tmp743.exe
C:\WINDOWS\~tmp7430.exe
C:\WINDOWS\~tmp7432.exe
C:\WINDOWS\~tmp7433.exe
C:\WINDOWS\~tmp7434.exe
C:\WINDOWS\~tmp7435.exe
C:\WINDOWS\~tmp7436.exe
C:\WINDOWS\~tmp7437.exe
C:\WINDOWS\~tmp7439.exe
C:\WINDOWS\~tmp744.exe
C:\WINDOWS\~tmp7440.exe
C:\WINDOWS\~tmp7441.exe
C:\WINDOWS\~tmp7446.exe
C:\WINDOWS\~tmp7447.exe
C:\WINDOWS\~tmp7449.exe
C:\WINDOWS\~tmp7450.exe
C:\WINDOWS\~tmp7452.exe
C:\WINDOWS\~tmp7453.exe
C:\WINDOWS\~tmp7458.exe
C:\WINDOWS\~tmp746.exe
C:\WINDOWS\~tmp7460.exe
C:\WINDOWS\~tmp7461.exe
C:\WINDOWS\~tmp7462.exe
C:\WINDOWS\~tmp7463.exe
C:\WINDOWS\~tmp7468.exe
C:\WINDOWS\~tmp7471.exe
C:\WINDOWS\~tmp7472.exe
C:\WINDOWS\~tmp7473.exe
C:\WINDOWS\~tmp7474.exe
C:\WINDOWS\~tmp7475.exe
C:\WINDOWS\~tmp7476.exe
C:\WINDOWS\~tmp7477.exe
C:\WINDOWS\~tmp7480.exe
C:\WINDOWS\~tmp7482.exe
C:\WINDOWS\~tmp7483.exe
C:\WINDOWS\~tmp7484.exe
C:\WINDOWS\~tmp7485.exe
C:\WINDOWS\~tmp7486.exe
C:\WINDOWS\~tmp7487.exe
C:\WINDOWS\~tmp7488.exe
C:\WINDOWS\~tmp7489.exe
C:\WINDOWS\~tmp749.exe
C:\WINDOWS\~tmp7490.exe
C:\WINDOWS\~tmp7493.exe
C:\WINDOWS\~tmp7496.exe
C:\WINDOWS\~tmp7497.exe
C:\WINDOWS\~tmp7498.exe
C:\WINDOWS\~tmp75.exe
C:\WINDOWS\~tmp7500.exe
C:\WINDOWS\~tmp7502.exe
C:\WINDOWS\~tmp7503.exe
C:\WINDOWS\~tmp7504.exe
C:\WINDOWS\~tmp7505.exe
C:\WINDOWS\~tmp7508.exe
C:\WINDOWS\~tmp7509.exe
C:\WINDOWS\~tmp7510.exe
C:\WINDOWS\~tmp7511.exe
C:\WINDOWS\~tmp7515.exe
C:\WINDOWS\~tmp7517.exe
C:\WINDOWS\~tmp7521.exe
C:\WINDOWS\~tmp7522.exe
C:\WINDOWS\~tmp7524.exe
C:\WINDOWS\~tmp7525.exe
C:\WINDOWS\~tmp7526.exe
C:\WINDOWS\~tmp7530.exe
C:\WINDOWS\~tmp7534.exe
C:\WINDOWS\~tmp7535.exe
C:\WINDOWS\~tmp7537.exe
C:\WINDOWS\~tmp7539.exe
C:\WINDOWS\~tmp754.exe
C:\WINDOWS\~tmp7543.exe
C:\WINDOWS\~tmp7548.exe
C:\WINDOWS\~tmp7549.exe
C:\WINDOWS\~tmp755.exe
C:\WINDOWS\~tmp7551.exe
C:\WINDOWS\~tmp7552.exe
C:\WINDOWS\~tmp7553.exe
C:\WINDOWS\~tmp7554.exe
C:\WINDOWS\~tmp756.exe
C:\WINDOWS\~tmp7560.exe
C:\WINDOWS\~tmp7563.exe
C:\WINDOWS\~tmp7565.exe
C:\WINDOWS\~tmp7566.exe
C:\WINDOWS\~tmp7567.exe
C:\WINDOWS\~tmp757.exe
C:\WINDOWS\~tmp7570.exe
C:\WINDOWS\~tmp7574.exe
C:\WINDOWS\~tmp7575.exe
C:\WINDOWS\~tmp7576.exe
C:\WINDOWS\~tmp7577.exe
C:\WINDOWS\~tmp7579.exe
C:\WINDOWS\~tmp7580.exe
C:\WINDOWS\~tmp7582.exe
C:\WINDOWS\~tmp7583.exe
C:\WINDOWS\~tmp7584.exe
C:\WINDOWS\~tmp7585.exe
C:\WINDOWS\~tmp7586.exe
C:\WINDOWS\~tmp7588.exe
C:\WINDOWS\~tmp7590.exe
C:\WINDOWS\~tmp76.exe
C:\WINDOWS\~tmp7600.exe
C:\WINDOWS\~tmp7602.exe
C:\WINDOWS\~tmp7603.exe
C:\WINDOWS\~tmp7605.exe
C:\WINDOWS\~tmp7606.exe
C:\WINDOWS\~tmp7607.exe
C:\WINDOWS\~tmp7609.exe
C:\WINDOWS\~tmp7611.exe
C:\WINDOWS\~tmp7612.exe
C:\WINDOWS\~tmp7613.exe
C:\WINDOWS\~tmp7615.exe
C:\WINDOWS\~tmp7616.exe
C:\WINDOWS\~tmp762.exe
C:\WINDOWS\~tmp7621.exe
C:\WINDOWS\~tmp7622.exe
C:\WINDOWS\~tmp7623.exe
C:\WINDOWS\~tmp7626.exe
C:\WINDOWS\~tmp7627.exe
C:\WINDOWS\~tmp763.exe
C:\WINDOWS\~tmp7632.exe
C:\WINDOWS\~tmp7633.exe
C:\WINDOWS\~tmp7635.exe
C:\WINDOWS\~tmp764.exe
C:\WINDOWS\~tmp7640.exe
C:\WINDOWS\~tmp7644.exe
C:\WINDOWS\~tmp7646.exe
C:\WINDOWS\~tmp7647.exe
C:\WINDOWS\~tmp7649.exe
C:\WINDOWS\~tmp765.exe
C:\WINDOWS\~tmp7654.exe
C:\WINDOWS\~tmp7655.exe
C:\WINDOWS\~tmp7657.exe
C:\WINDOWS\~tmp7659.exe
C:\WINDOWS\~tmp7661.exe
C:\WINDOWS\~tmp7662.exe
C:\WINDOWS\~tmp7663.exe
C:\WINDOWS\~tmp7665.exe
C:\WINDOWS\~tmp7667.exe
C:\WINDOWS\~tmp7669.exe
C:\WINDOWS\~tmp767.exe
C:\WINDOWS\~tmp7670.exe
C:\WINDOWS\~tmp7672.exe
C:\WINDOWS\~tmp7673.exe
C:\WINDOWS\~tmp7675.exe
C:\WINDOWS\~tmp7677.exe
C:\WINDOWS\~tmp7678.exe
C:\WINDOWS\~tmp7679.exe
C:\WINDOWS\~tmp768.exe
C:\WINDOWS\~tmp7683.exe
C:\WINDOWS\~tmp7684.exe
C:\WINDOWS\~tmp7685.exe
C:\WINDOWS\~tmp7687.exe
C:\WINDOWS\~tmp769.exe
C:\WINDOWS\~tmp7690.exe
C:\WINDOWS\~tmp7691.exe
C:\WINDOWS\~tmp7692.exe
C:\WINDOWS\~tmp7696.exe
C:\WINDOWS\~tmp7697.exe
C:\WINDOWS\~tmp7698.exe
C:\WINDOWS\~tmp7699.exe
C:\WINDOWS\~tmp77.exe
C:\WINDOWS\~tmp770.exe
C:\WINDOWS\~tmp7700.exe
C:\WINDOWS\~tmp7702.exe
C:\WINDOWS\~tmp7707.exe
C:\WINDOWS\~tmp7709.exe
C:\WINDOWS\~tmp771.exe
C:\WINDOWS\~tmp7710.exe
C:\WINDOWS\~tmp7713.exe
C:\WINDOWS\~tmp7714.exe
C:\WINDOWS\~tmp7715.exe
C:\WINDOWS\~tmp7716.exe
C:\WINDOWS\~tmp7717.exe
C:\WINDOWS\~tmp7718.exe
C:\WINDOWS\~tmp7719.exe
C:\WINDOWS\~tmp772.exe
C:\WINDOWS\~tmp7720.exe
C:\WINDOWS\~tmp7721.exe
C:\WINDOWS\~tmp7722.exe
C:\WINDOWS\~tmp7724.exe
C:\WINDOWS\~tmp7725.exe
C:\WINDOWS\~tmp7726.exe
C:\WINDOWS\~tmp7727.exe
C:\WINDOWS\~tmp7729.exe
C:\WINDOWS\~tmp773.exe
C:\WINDOWS\~tmp7730.exe
C:\WINDOWS\~tmp7731.exe
C:\WINDOWS\~tmp7732.exe
C:\WINDOWS\~tmp7734.exe


----------



## cpuanswers (Sep 25, 2007)

last one

C:\WINDOWS\~tmp5823.exe
C:\WINDOWS\~tmp5826.exe
C:\WINDOWS\~tmp5828.exe
C:\WINDOWS\~tmp5829.exe
C:\WINDOWS\~tmp5830.exe
C:\WINDOWS\~tmp5831.exe
C:\WINDOWS\~tmp5833.exe
C:\WINDOWS\~tmp5834.exe
C:\WINDOWS\~tmp5835.exe
C:\WINDOWS\~tmp5837.exe
C:\WINDOWS\~tmp584.exe
C:\WINDOWS\~tmp5841.exe
C:\WINDOWS\~tmp5842.exe
C:\WINDOWS\~tmp5843.exe
C:\WINDOWS\~tmp5845.exe
C:\WINDOWS\~tmp5846.exe
C:\WINDOWS\~tmp5847.exe
C:\WINDOWS\~tmp5849.exe
C:\WINDOWS\~tmp585.exe
C:\WINDOWS\~tmp5850.exe
C:\WINDOWS\~tmp5851.exe
C:\WINDOWS\~tmp5852.exe
C:\WINDOWS\~tmp5853.exe
C:\WINDOWS\~tmp5854.exe
C:\WINDOWS\~tmp5856.exe
C:\WINDOWS\~tmp5860.exe
C:\WINDOWS\~tmp5862.exe
C:\WINDOWS\~tmp5865.exe
C:\WINDOWS\~tmp5867.exe
C:\WINDOWS\~tmp5870.exe
C:\WINDOWS\~tmp5877.exe
C:\WINDOWS\~tmp5882.exe
C:\WINDOWS\~tmp5883.exe
C:\WINDOWS\~tmp5886.exe
C:\WINDOWS\~tmp5887.exe
C:\WINDOWS\~tmp5889.exe
C:\WINDOWS\~tmp589.exe
C:\WINDOWS\~tmp5890.exe
C:\WINDOWS\~tmp5891.exe
C:\WINDOWS\~tmp5894.exe
C:\WINDOWS\~tmp5895.exe
C:\WINDOWS\~tmp5899.exe
C:\WINDOWS\~tmp590.exe
C:\WINDOWS\~tmp5900.exe
C:\WINDOWS\~tmp5902.exe
C:\WINDOWS\~tmp5904.exe
C:\WINDOWS\~tmp5906.exe
C:\WINDOWS\~tmp5908.exe
C:\WINDOWS\~tmp5912.exe
C:\WINDOWS\~tmp5914.exe
C:\WINDOWS\~tmp5915.exe
C:\WINDOWS\~tmp5916.exe
C:\WINDOWS\~tmp5918.exe
C:\WINDOWS\~tmp5919.exe
C:\WINDOWS\~tmp592.exe
C:\WINDOWS\~tmp5921.exe
C:\WINDOWS\~tmp5924.exe
C:\WINDOWS\~tmp5926.exe
C:\WINDOWS\~tmp5927.exe
C:\WINDOWS\~tmp5928.exe
C:\WINDOWS\~tmp593.exe
C:\WINDOWS\~tmp5931.exe
C:\WINDOWS\~tmp5932.exe
C:\WINDOWS\~tmp5936.exe
C:\WINDOWS\~tmp5939.exe
C:\WINDOWS\~tmp594.exe
C:\WINDOWS\~tmp5940.exe
C:\WINDOWS\~tmp5941.exe
C:\WINDOWS\~tmp5943.exe
C:\WINDOWS\~tmp5944.exe
C:\WINDOWS\~tmp5945.exe
C:\WINDOWS\~tmp5951.exe
C:\WINDOWS\~tmp5952.exe
C:\WINDOWS\~tmp5953.exe
C:\WINDOWS\~tmp5955.exe
C:\WINDOWS\~tmp5957.exe
C:\WINDOWS\~tmp596.exe
C:\WINDOWS\~tmp5960.exe
C:\WINDOWS\~tmp5962.exe
C:\WINDOWS\~tmp5964.exe
C:\WINDOWS\~tmp5967.exe
C:\WINDOWS\~tmp5969.exe
C:\WINDOWS\~tmp597.exe
C:\WINDOWS\~tmp5970.exe
C:\WINDOWS\~tmp5971.exe
C:\WINDOWS\~tmp5972.exe
C:\WINDOWS\~tmp5975.exe
C:\WINDOWS\~tmp598.exe
C:\WINDOWS\~tmp5981.exe
C:\WINDOWS\~tmp5982.exe
C:\WINDOWS\~tmp5984.exe
C:\WINDOWS\~tmp5985.exe
C:\WINDOWS\~tmp5988.exe
C:\WINDOWS\~tmp5989.exe
C:\WINDOWS\~tmp599.exe
C:\WINDOWS\~tmp5990.exe
C:\WINDOWS\~tmp5991.exe
C:\WINDOWS\~tmp5993.exe
C:\WINDOWS\~tmp5994.exe
C:\WINDOWS\~tmp5995.exe
C:\WINDOWS\~tmp5996.exe
C:\WINDOWS\~tmp5997.exe
C:\WINDOWS\~tmp5998.exe
C:\WINDOWS\~tmp5999.exe
C:\WINDOWS\~tmp6.exe
C:\WINDOWS\~tmp600.exe
C:\WINDOWS\~tmp6006.exe
C:\WINDOWS\~tmp6007.exe
C:\WINDOWS\~tmp6012.exe
C:\WINDOWS\~tmp6014.exe
C:\WINDOWS\~tmp6015.exe
C:\WINDOWS\~tmp6017.exe
C:\WINDOWS\~tmp6019.exe
C:\WINDOWS\~tmp6022.exe
C:\WINDOWS\~tmp6026.exe
C:\WINDOWS\~tmp6028.exe
C:\WINDOWS\~tmp603.exe
C:\WINDOWS\~tmp6031.exe
C:\WINDOWS\~tmp6033.exe
C:\WINDOWS\~tmp6035.exe
C:\WINDOWS\~tmp6036.exe
C:\WINDOWS\~tmp6037.exe
C:\WINDOWS\~tmp6038.exe
C:\WINDOWS\~tmp6039.exe
C:\WINDOWS\~tmp604.exe
C:\WINDOWS\~tmp6040.exe
C:\WINDOWS\~tmp6042.exe
C:\WINDOWS\~tmp6046.exe
C:\WINDOWS\~tmp6049.exe
C:\WINDOWS\~tmp6050.exe
C:\WINDOWS\~tmp6054.exe
C:\WINDOWS\~tmp6058.exe
C:\WINDOWS\~tmp6062.exe
C:\WINDOWS\~tmp6063.exe
C:\WINDOWS\~tmp6064.exe
C:\WINDOWS\~tmp6065.exe
C:\WINDOWS\~tmp6066.exe
C:\WINDOWS\~tmp6069.exe
C:\WINDOWS\~tmp607.exe
C:\WINDOWS\~tmp6070.exe
C:\WINDOWS\~tmp6071.exe
C:\WINDOWS\~tmp6072.exe
C:\WINDOWS\~tmp6077.exe
C:\WINDOWS\~tmp6080.exe
C:\WINDOWS\~tmp6083.exe
C:\WINDOWS\~tmp6084.exe
C:\WINDOWS\~tmp6085.exe
C:\WINDOWS\~tmp6086.exe
C:\WINDOWS\~tmp6087.exe
C:\WINDOWS\~tmp609.exe
C:\WINDOWS\~tmp6090.exe
C:\WINDOWS\~tmp6091.exe
C:\WINDOWS\~tmp6093.exe
C:\WINDOWS\~tmp6096.exe
C:\WINDOWS\~tmp6097.exe
C:\WINDOWS\~tmp6098.exe
C:\WINDOWS\~tmp6099.exe
C:\WINDOWS\~tmp61.exe
C:\WINDOWS\~tmp6101.exe
C:\WINDOWS\~tmp6102.exe
C:\WINDOWS\~tmp6103.exe
C:\WINDOWS\~tmp6105.exe
C:\WINDOWS\~tmp6106.exe
C:\WINDOWS\~tmp6109.exe
C:\WINDOWS\~tmp6111.exe
C:\WINDOWS\~tmp6112.exe
C:\WINDOWS\~tmp6116.exe
C:\WINDOWS\~tmp6118.exe
C:\WINDOWS\~tmp612.exe
C:\WINDOWS\~tmp6121.exe
C:\WINDOWS\~tmp6123.exe
C:\WINDOWS\~tmp6124.exe
C:\WINDOWS\~tmp6125.exe
C:\WINDOWS\~tmp6127.exe
C:\WINDOWS\~tmp6129.exe
C:\WINDOWS\~tmp613.exe
C:\WINDOWS\~tmp6131.exe
C:\WINDOWS\~tmp6132.exe
C:\WINDOWS\~tmp6134.exe
C:\WINDOWS\~tmp6137.exe
C:\WINDOWS\~tmp6138.exe
C:\WINDOWS\~tmp6139.exe
C:\WINDOWS\~tmp614.exe
C:\WINDOWS\~tmp6142.exe
C:\WINDOWS\~tmp6144.exe
C:\WINDOWS\~tmp6146.exe
C:\WINDOWS\~tmp6148.exe
C:\WINDOWS\~tmp615.exe
C:\WINDOWS\~tmp6150.exe
C:\WINDOWS\~tmp6151.exe
C:\WINDOWS\~tmp6153.exe
C:\WINDOWS\~tmp6155.exe
C:\WINDOWS\~tmp6157.exe
C:\WINDOWS\~tmp6159.exe
C:\WINDOWS\~tmp616.exe
C:\WINDOWS\~tmp6162.exe
C:\WINDOWS\~tmp6163.exe
C:\WINDOWS\~tmp6165.exe
C:\WINDOWS\~tmp6168.exe
C:\WINDOWS\~tmp6170.exe
C:\WINDOWS\~tmp6171.exe
C:\WINDOWS\~tmp6172.exe
C:\WINDOWS\~tmp6174.exe
C:\WINDOWS\~tmp6175.exe
C:\WINDOWS\~tmp6177.exe
C:\WINDOWS\~tmp6178.exe
C:\WINDOWS\~tmp6179.exe
C:\WINDOWS\~tmp6180.exe
C:\WINDOWS\~tmp6181.exe
C:\WINDOWS\~tmp6182.exe
C:\WINDOWS\~tmp6183.exe
C:\WINDOWS\~tmp6184.exe
C:\WINDOWS\~tmp6186.exe
C:\WINDOWS\~tmp619.exe
C:\WINDOWS\~tmp6190.exe
C:\WINDOWS\~tmp6193.exe
C:\WINDOWS\~tmp6194.exe
C:\WINDOWS\~tmp6195.exe
C:\WINDOWS\~tmp6196.exe
C:\WINDOWS\~tmp6199.exe
C:\WINDOWS\~tmp6200.exe
C:\WINDOWS\~tmp6201.exe
C:\WINDOWS\~tmp6203.exe
C:\WINDOWS\~tmp6205.exe
C:\WINDOWS\~tmp6210.exe
C:\WINDOWS\~tmp6211.exe
C:\WINDOWS\~tmp6213.exe
C:\WINDOWS\~tmp6214.exe
C:\WINDOWS\~tmp6217.exe
C:\WINDOWS\~tmp6218.exe
C:\WINDOWS\~tmp622.exe
C:\WINDOWS\~tmp6220.exe
C:\WINDOWS\~tmp6221.exe
C:\WINDOWS\~tmp6222.exe
C:\WINDOWS\~tmp6223.exe
C:\WINDOWS\~tmp6224.exe
C:\WINDOWS\~tmp6225.exe
C:\WINDOWS\~tmp6226.exe
C:\WINDOWS\~tmp6227.exe
C:\WINDOWS\~tmp6228.exe
C:\WINDOWS\~tmp6229.exe
C:\WINDOWS\~tmp623.exe
C:\WINDOWS\~tmp6230.exe
C:\WINDOWS\~tmp6231.exe
C:\WINDOWS\~tmp6232.exe
C:\WINDOWS\~tmp6234.exe
C:\WINDOWS\~tmp6235.exe
C:\WINDOWS\~tmp6236.exe
C:\WINDOWS\~tmp6237.exe
C:\WINDOWS\~tmp6238.exe
C:\WINDOWS\~tmp6239.exe
C:\WINDOWS\~tmp6243.exe
C:\WINDOWS\~tmp6244.exe
C:\WINDOWS\~tmp6248.exe
C:\WINDOWS\~tmp625.exe
C:\WINDOWS\~tmp6250.exe
C:\WINDOWS\~tmp6251.exe
C:\WINDOWS\~tmp6253.exe
C:\WINDOWS\~tmp6254.exe
C:\WINDOWS\~tmp6256.exe
C:\WINDOWS\~tmp6258.exe
C:\WINDOWS\~tmp6259.exe
C:\WINDOWS\~tmp626.exe
C:\WINDOWS\~tmp6261.exe
C:\WINDOWS\~tmp6262.exe
C:\WINDOWS\~tmp6264.exe
C:\WINDOWS\~tmp6265.exe
C:\WINDOWS\~tmp6266.exe
C:\WINDOWS\~tmp6267.exe
C:\WINDOWS\~tmp627.exe
C:\WINDOWS\~tmp6270.exe
C:\WINDOWS\~tmp6271.exe
C:\WINDOWS\~tmp6273.exe
C:\WINDOWS\~tmp6274.exe
C:\WINDOWS\~tmp6275.exe
C:\WINDOWS\~tmp6279.exe
C:\WINDOWS\~tmp628.exe
C:\WINDOWS\~tmp6280.exe
C:\WINDOWS\~tmp6282.exe
C:\WINDOWS\~tmp6283.exe
C:\WINDOWS\~tmp6285.exe
C:\WINDOWS\~tmp6286.exe
C:\WINDOWS\~tmp6288.exe
C:\WINDOWS\~tmp6289.exe
C:\WINDOWS\~tmp6291.exe
C:\WINDOWS\~tmp6296.exe
C:\WINDOWS\~tmp6298.exe
C:\WINDOWS\~tmp63.exe
C:\WINDOWS\~tmp630.exe
C:\WINDOWS\~tmp6300.exe
C:\WINDOWS\~tmp6302.exe
C:\WINDOWS\~tmp6303.exe
C:\WINDOWS\~tmp6304.exe
C:\WINDOWS\~tmp6305.exe
C:\WINDOWS\~tmp6307.exe
C:\WINDOWS\~tmp6309.exe
C:\WINDOWS\~tmp631.exe
C:\WINDOWS\~tmp6310.exe
C:\WINDOWS\~tmp6311.exe
C:\WINDOWS\~tmp6312.exe
C:\WINDOWS\~tmp6316.exe
C:\WINDOWS\~tmp6317.exe
C:\WINDOWS\~tmp6318.exe
C:\WINDOWS\~tmp632.exe
C:\WINDOWS\~tmp6320.exe
C:\WINDOWS\~tmp6322.exe
C:\WINDOWS\~tmp6325.exe
C:\WINDOWS\~tmp6326.exe
C:\WINDOWS\~tmp6327.exe
C:\WINDOWS\~tmp6328.exe
C:\WINDOWS\~tmp633.exe
C:\WINDOWS\~tmp6330.exe
C:\WINDOWS\~tmp6331.exe
C:\WINDOWS\~tmp6332.exe
C:\WINDOWS\~tmp6335.exe
C:\WINDOWS\~tmp6336.exe
C:\WINDOWS\~tmp6337.exe
C:\WINDOWS\~tmp6344.exe
C:\WINDOWS\~tmp6345.exe
C:\WINDOWS\~tmp6346.exe
C:\WINDOWS\~tmp6352.exe
C:\WINDOWS\~tmp6355.exe
C:\WINDOWS\~tmp6357.exe
C:\WINDOWS\~tmp6358.exe
C:\WINDOWS\~tmp6359.exe
C:\WINDOWS\~tmp636.exe
C:\WINDOWS\~tmp6360.exe
C:\WINDOWS\~tmp6362.exe
C:\WINDOWS\~tmp6365.exe
C:\WINDOWS\~tmp6366.exe
C:\WINDOWS\~tmp6367.exe
C:\WINDOWS\~tmp637.exe
C:\WINDOWS\~tmp6371.exe
C:\WINDOWS\~tmp6372.exe
C:\WINDOWS\~tmp6373.exe
C:\WINDOWS\~tmp6375.exe
C:\WINDOWS\~tmp6378.exe
C:\WINDOWS\~tmp6379.exe
C:\WINDOWS\~tmp6380.exe
C:\WINDOWS\~tmp6381.exe
C:\WINDOWS\~tmp6382.exe
C:\WINDOWS\~tmp6383.exe
C:\WINDOWS\~tmp6384.exe
C:\WINDOWS\~tmp6386.exe
C:\WINDOWS\~tmp6387.exe
C:\WINDOWS\~tmp6388.exe
C:\WINDOWS\~tmp6389.exe
C:\WINDOWS\~tmp6390.exe
C:\WINDOWS\~tmp6391.exe
C:\WINDOWS\~tmp6392.exe
C:\WINDOWS\~tmp6394.exe
C:\WINDOWS\~tmp6396.exe
C:\WINDOWS\~tmp6397.exe
C:\WINDOWS\~tmp6398.exe
C:\WINDOWS\~tmp640.exe
C:\WINDOWS\~tmp6402.exe
C:\WINDOWS\~tmp6404.exe
C:\WINDOWS\~tmp6406.exe
C:\WINDOWS\~tmp6407.exe
C:\WINDOWS\~tmp6408.exe
C:\WINDOWS\~tmp6409.exe
C:\WINDOWS\~tmp6410.exe
C:\WINDOWS\~tmp6411.exe
C:\WINDOWS\~tmp6413.exe
C:\WINDOWS\~tmp6414.exe
C:\WINDOWS\~tmp6415.exe
C:\WINDOWS\~tmp6417.exe
C:\WINDOWS\~tmp642.exe
C:\WINDOWS\~tmp6423.exe
C:\WINDOWS\~tmp6426.exe
C:\WINDOWS\~tmp6427.exe
C:\WINDOWS\~tmp6428.exe
C:\WINDOWS\~tmp6429.exe
C:\WINDOWS\~tmp643.exe
C:\WINDOWS\~tmp6430.exe
C:\WINDOWS\~tmp6433.exe
C:\WINDOWS\~tmp6435.exe
C:\WINDOWS\~tmp6436.exe
C:\WINDOWS\~tmp6437.exe
C:\WINDOWS\~tmp6438.exe
C:\WINDOWS\~tmp644.exe
C:\WINDOWS\~tmp6440.exe
C:\WINDOWS\~tmp6442.exe
C:\WINDOWS\~tmp6444.exe
C:\WINDOWS\~tmp6446.exe
C:\WINDOWS\~tmp6447.exe
C:\WINDOWS\~tmp6448.exe
C:\WINDOWS\~tmp6451.exe
C:\WINDOWS\~tmp6453.exe
C:\WINDOWS\~tmp6455.exe
C:\WINDOWS\~tmp6457.exe
C:\WINDOWS\~tmp6459.exe
C:\WINDOWS\~tmp6460.exe
C:\WINDOWS\~tmp6461.exe
C:\WINDOWS\~tmp6463.exe
C:\WINDOWS\~tmp6464.exe
C:\WINDOWS\~tmp6465.exe
C:\WINDOWS\~tmp647.exe
C:\WINDOWS\~tmp6471.exe
C:\WINDOWS\~tmp6474.exe
C:\WINDOWS\~tmp6477.exe
C:\WINDOWS\~tmp6478.exe
C:\WINDOWS\~tmp6480.exe
C:\WINDOWS\~tmp6481.exe
C:\WINDOWS\~tmp6484.exe
C:\WINDOWS\~tmp6485.exe
C:\WINDOWS\~tmp6486.exe
C:\WINDOWS\~tmp6487.exe
C:\WINDOWS\~tmp649.exe
C:\WINDOWS\~tmp6490.exe
C:\WINDOWS\~tmp6491.exe
C:\WINDOWS\~tmp6492.exe
C:\WINDOWS\~tmp6493.exe
C:\WINDOWS\~tmp6494.exe
C:\WINDOWS\~tmp6495.exe
C:\WINDOWS\~tmp6498.exe
C:\WINDOWS\~tmp6499.exe
C:\WINDOWS\~tmp650.exe
C:\WINDOWS\~tmp6502.exe
C:\WINDOWS\~tmp6503.exe
C:\WINDOWS\~tmp6505.exe
C:\WINDOWS\~tmp6506.exe
C:\WINDOWS\~tmp6508.exe
C:\WINDOWS\~tmp6509.exe
C:\WINDOWS\~tmp651.exe
C:\WINDOWS\~tmp6510.exe
C:\WINDOWS\~tmp6511.exe
C:\WINDOWS\~tmp6514.exe
C:\WINDOWS\~tmp6515.exe
C:\WINDOWS\~tmp6516.exe
C:\WINDOWS\~tmp6519.exe
C:\WINDOWS\~tmp652.exe
C:\WINDOWS\~tmp6524.exe
C:\WINDOWS\~tmp6526.exe
C:\WINDOWS\~tmp6528.exe
C:\WINDOWS\~tmp6529.exe
C:\WINDOWS\~tmp653.exe
C:\WINDOWS\~tmp6530.exe
C:\WINDOWS\~tmp6532.exe
C:\WINDOWS\~tmp6533.exe
C:\WINDOWS\~tmp6534.exe
C:\WINDOWS\~tmp6535.exe
C:\WINDOWS\~tmp6537.exe
C:\WINDOWS\~tmp6543.exe
C:\WINDOWS\~tmp6544.exe
C:\WINDOWS\~tmp6546.exe
C:\WINDOWS\~tmp6549.exe
C:\WINDOWS\~tmp6554.exe
C:\WINDOWS\~tmp6555.exe
C:\WINDOWS\~tmp6557.exe
C:\WINDOWS\~tmp6559.exe
C:\WINDOWS\~tmp656.exe
C:\WINDOWS\~tmp6560.exe
C:\WINDOWS\~tmp6561.exe
C:\WINDOWS\~tmp6562.exe
C:\WINDOWS\~tmp6564.exe
C:\WINDOWS\~tmp6566.exe
C:\WINDOWS\~tmp6569.exe
C:\WINDOWS\~tmp657.exe
C:\WINDOWS\~tmp6570.exe
C:\WINDOWS\~tmp6571.exe
C:\WINDOWS\~tmp6573.exe
C:\WINDOWS\~tmp6577.exe
C:\WINDOWS\~tmp6578.exe
C:\WINDOWS\~tmp658.exe
C:\WINDOWS\~tmp6583.exe
C:\WINDOWS\~tmp6584.exe
C:\WINDOWS\~tmp6585.exe
C:\WINDOWS\~tmp6586.exe
C:\WINDOWS\~tmp6591.exe
C:\WINDOWS\~tmp6592.exe
C:\WINDOWS\~tmp6594.exe
C:\WINDOWS\~tmp6595.exe
C:\WINDOWS\~tmp6596.exe
C:\WINDOWS\~tmp6597.exe
C:\WINDOWS\~tmp660.exe
C:\WINDOWS\~tmp6600.exe
C:\WINDOWS\~tmp6601.exe
C:\WINDOWS\~tmp6602.exe
C:\WINDOWS\~tmp6603.exe
C:\WINDOWS\~tmp6604.exe
C:\WINDOWS\~tmp6606.exe
C:\WINDOWS\~tmp6607.exe
C:\WINDOWS\~tmp661.exe
C:\WINDOWS\~tmp6611.exe
C:\WINDOWS\~tmp6612.exe
C:\WINDOWS\~tmp6613.exe
C:\WINDOWS\~tmp6614.exe
C:\WINDOWS\~tmp6615.exe
C:\WINDOWS\~tmp6616.exe
C:\WINDOWS\~tmp6617.exe
C:\WINDOWS\~tmp6618.exe
C:\WINDOWS\~tmp6619.exe
C:\WINDOWS\~tmp6620.exe
C:\WINDOWS\~tmp6622.exe
C:\WINDOWS\~tmp6626.exe
C:\WINDOWS\~tmp6628.exe
C:\WINDOWS\~tmp6630.exe
C:\WINDOWS\~tmp6634.exe
C:\WINDOWS\~tmp6637.exe
C:\WINDOWS\~tmp6639.exe
C:\WINDOWS\~tmp6640.exe
C:\WINDOWS\~tmp6641.exe
C:\WINDOWS\~tmp6645.exe
C:\WINDOWS\~tmp6646.exe
C:\WINDOWS\~tmp665.exe
C:\WINDOWS\~tmp6652.exe
C:\WINDOWS\~tmp6653.exe
C:\WINDOWS\~tmp6654.exe
C:\WINDOWS\~tmp6655.exe
C:\WINDOWS\~tmp6656.exe
C:\WINDOWS\~tmp6657.exe
C:\WINDOWS\~tmp666.exe
C:\WINDOWS\~tmp6660.exe
C:\WINDOWS\~tmp6661.exe
C:\WINDOWS\~tmp6663.exe
C:\WINDOWS\~tmp6664.exe
C:\WINDOWS\~tmp6665.exe
C:\WINDOWS\~tmp6667.exe
C:\WINDOWS\~tmp6668.exe
C:\WINDOWS\~tmp667.exe
C:\WINDOWS\~tmp6670.exe
C:\WINDOWS\~tmp6671.exe
C:\WINDOWS\~tmp6672.exe
C:\WINDOWS\~tmp6673.exe
C:\WINDOWS\~tmp6675.exe
C:\WINDOWS\~tmp6676.exe
C:\WINDOWS\~tmp6677.exe
C:\WINDOWS\~tmp6680.exe
C:\WINDOWS\~tmp6681.exe
C:\WINDOWS\~tmp6682.exe
C:\WINDOWS\~tmp6683.exe
C:\WINDOWS\~tmp6685.exe
C:\WINDOWS\~tmp6686.exe
C:\WINDOWS\~tmp6687.exe
C:\WINDOWS\~tmp6688.exe
C:\WINDOWS\~tmp6689.exe
C:\WINDOWS\~tmp669.exe
C:\WINDOWS\~tmp6690.exe
C:\WINDOWS\~tmp6694.exe
C:\WINDOWS\~tmp6698.exe
C:\WINDOWS\~tmp67.exe
C:\WINDOWS\~tmp670.exe
C:\WINDOWS\~tmp6700.exe
C:\WINDOWS\~tmp6701.exe
C:\WINDOWS\~tmp6702.exe
C:\WINDOWS\~tmp6703.exe
C:\WINDOWS\~tmp6704.exe
C:\WINDOWS\~tmp6705.exe
C:\WINDOWS\~tmp6706.exe
C:\WINDOWS\~tmp6707.exe
C:\WINDOWS\~tmp6710.exe
C:\WINDOWS\~tmp6711.exe
C:\WINDOWS\~tmp6712.exe
C:\WINDOWS\~tmp6714.exe
C:\WINDOWS\~tmp6717.exe
C:\WINDOWS\~tmp672.exe
C:\WINDOWS\~tmp6722.exe
C:\WINDOWS\~tmp6728.exe
C:\WINDOWS\~tmp6729.exe
C:\WINDOWS\~tmp673.exe
C:\WINDOWS\~tmp6732.exe
C:\WINDOWS\~tmp6733.exe
C:\WINDOWS\~tmp6735.exe
C:\WINDOWS\~tmp6736.exe
C:\WINDOWS\~tmp6737.exe
C:\WINDOWS\~tmp674.exe
C:\WINDOWS\~tmp6741.exe
C:\WINDOWS\~tmp6742.exe
C:\WINDOWS\~tmp6744.exe
C:\WINDOWS\~tmp6745.exe
C:\WINDOWS\~tmp675.exe
C:\WINDOWS\~tmp6751.exe
C:\WINDOWS\~tmp6752.exe
C:\WINDOWS\~tmp6759.exe
C:\WINDOWS\~tmp6762.exe
C:\WINDOWS\~tmp6763.exe
C:\WINDOWS\~tmp6764.exe
C:\WINDOWS\~tmp6766.exe
C:\WINDOWS\~tmp6767.exe
C:\WINDOWS\~tmp6770.exe
C:\WINDOWS\~tmp6771.exe
C:\WINDOWS\~tmp6772.exe
C:\WINDOWS\~tmp6774.exe
C:\WINDOWS\~tmp6775.exe
C:\WINDOWS\~tmp6777.exe
C:\WINDOWS\~tmp6778.exe
C:\WINDOWS\~tmp6779.exe
C:\WINDOWS\~tmp6780.exe
C:\WINDOWS\~tmp6781.exe
C:\WINDOWS\~tmp6782.exe
C:\WINDOWS\~tmp6783.exe
C:\WINDOWS\~tmp6784.exe
C:\WINDOWS\~tmp6785.exe
C:\WINDOWS\~tmp6786.exe
C:\WINDOWS\~tmp6788.exe
C:\WINDOWS\~tmp6789.exe
C:\WINDOWS\~tmp679.exe
C:\WINDOWS\~tmp6791.exe
C:\WINDOWS\~tmp6792.exe
C:\WINDOWS\~tmp6794.exe
C:\WINDOWS\~tmp6796.exe
C:\WINDOWS\~tmp68.exe
C:\WINDOWS\~tmp680.exe
C:\WINDOWS\~tmp6800.exe
C:\WINDOWS\~tmp6801.exe
C:\WINDOWS\~tmp6805.exe
C:\WINDOWS\~tmp6806.exe
C:\WINDOWS\~tmp6807.exe
C:\WINDOWS\~tmp6808.exe
C:\WINDOWS\~tmp681.exe
C:\WINDOWS\~tmp6812.exe
C:\WINDOWS\~tmp6813.exe
C:\WINDOWS\~tmp6816.exe
C:\WINDOWS\~tmp6817.exe
C:\WINDOWS\~tmp6818.exe
C:\WINDOWS\~tmp6819.exe
C:\WINDOWS\~tmp682.exe
C:\WINDOWS\~tmp6820.exe
C:\WINDOWS\~tmp6821.exe
C:\WINDOWS\~tmp6822.exe
C:\WINDOWS\~tmp6824.exe
C:\WINDOWS\~tmp6833.exe
C:\WINDOWS\~tmp6834.exe
C:\WINDOWS\~tmp6839.exe
C:\WINDOWS\~tmp684.exe
C:\WINDOWS\~tmp6840.exe
C:\WINDOWS\~tmp6841.exe
C:\WINDOWS\~tmp6842.exe
C:\WINDOWS\~tmp6846.exe
C:\WINDOWS\~tmp6847.exe
C:\WINDOWS\~tmp6849.exe
C:\WINDOWS\~tmp685.exe
C:\WINDOWS\~tmp6850.exe
C:\WINDOWS\~tmp6851.exe
C:\WINDOWS\~tmp6852.exe
C:\WINDOWS\~tmp6853.exe
C:\WINDOWS\~tmp6857.exe
C:\WINDOWS\~tmp686.exe
C:\WINDOWS\~tmp6860.exe
C:\WINDOWS\~tmp6861.exe
C:\WINDOWS\~tmp6862.exe
C:\WINDOWS\~tmp6863.exe
C:\WINDOWS\~tmp6864.exe
C:\WINDOWS\~tmp6865.exe
C:\WINDOWS\~tmp6866.exe
C:\WINDOWS\~tmp6867.exe
C:\WINDOWS\~tmp687.exe
C:\WINDOWS\~tmp6870.exe
C:\WINDOWS\~tmp6873.exe
C:\WINDOWS\~tmp6874.exe
C:\WINDOWS\~tmp6876.exe
C:\WINDOWS\~tmp6879.exe
C:\WINDOWS\~tmp6883.exe
C:\WINDOWS\~tmp6886.exe
C:\WINDOWS\~tmp6887.exe
C:\WINDOWS\~tmp6888.exe
C:\WINDOWS\~tmp6892.exe
C:\WINDOWS\~tmp6893.exe
C:\WINDOWS\~tmp6894.exe
C:\WINDOWS\~tmp6895.exe
C:\WINDOWS\~tmp6897.exe
C:\WINDOWS\~tmp6899.exe
C:\WINDOWS\~tmp69.exe
C:\WINDOWS\~tmp6902.exe
C:\WINDOWS\~tmp6904.exe
C:\WINDOWS\~tmp6907.exe
C:\WINDOWS\~tmp6909.exe
C:\WINDOWS\~tmp691.exe
C:\WINDOWS\~tmp6910.exe
C:\WINDOWS\~tmp6911.exe
C:\WINDOWS\~tmp6913.exe
C:\WINDOWS\~tmp6917.exe
C:\WINDOWS\~tmp6920.exe
C:\WINDOWS\~tmp6921.exe
C:\WINDOWS\~tmp6923.exe
C:\WINDOWS\~tmp6926.exe
C:\WINDOWS\~tmp6928.exe
C:\WINDOWS\~tmp6930.exe
C:\WINDOWS\~tmp6933.exe
C:\WINDOWS\~tmp6934.exe
C:\WINDOWS\~tmp6935.exe
C:\WINDOWS\~tmp6937.exe
C:\WINDOWS\~tmp6938.exe
C:\WINDOWS\~tmp6939.exe
C:\WINDOWS\~tmp694.exe
C:\WINDOWS\~tmp6940.exe
C:\WINDOWS\~tmp6941.exe
C:\WINDOWS\~tmp6942.exe
C:\WINDOWS\~tmp6945.exe
C:\WINDOWS\~tmp6946.exe
C:\WINDOWS\~tmp6949.exe
C:\WINDOWS\~tmp695.exe
C:\WINDOWS\~tmp6950.exe
C:\WINDOWS\~tmp6954.exe
C:\WINDOWS\~tmp6955.exe
C:\WINDOWS\~tmp6956.exe
C:\WINDOWS\~tmp6957.exe
C:\WINDOWS\~tmp6958.exe
C:\WINDOWS\~tmp6960.exe
C:\WINDOWS\~tmp6961.exe
C:\WINDOWS\~tmp6962.exe
C:\WINDOWS\~tmp6963.exe
C:\WINDOWS\~tmp6965.exe
C:\WINDOWS\~tmp6971.exe
C:\WINDOWS\~tmp6974.exe
C:\WINDOWS\~tmp6976.exe
C:\WINDOWS\~tmp6977.exe
C:\WINDOWS\~tmp6978.exe
C:\WINDOWS\~tmp698.exe
C:\WINDOWS\~tmp6981.exe
C:\WINDOWS\~tmp6982.exe
C:\WINDOWS\~tmp6984.exe
C:\WINDOWS\~tmp6985.exe
C:\WINDOWS\~tmp6986.exe
C:\WINDOWS\~tmp6987.exe
C:\WINDOWS\~tmp6993.exe
C:\WINDOWS\~tmp6994.exe
C:\WINDOWS\~tmp6995.exe
C:\WINDOWS\~tmp6996.exe
C:\WINDOWS\~tmp7.exe
C:\WINDOWS\~tmp7000.exe
C:\WINDOWS\~tmp7001.exe
C:\WINDOWS\~tmp7002.exe
C:\WINDOWS\~tmp7003.exe
C:\WINDOWS\~tmp7006.exe
C:\WINDOWS\~tmp7008.exe
C:\WINDOWS\~tmp7009.exe
C:\WINDOWS\~tmp7010.exe
C:\WINDOWS\~tmp7012.exe
C:\WINDOWS\~tmp7014.exe
C:\WINDOWS\~tmp7015.exe
C:\WINDOWS\~tmp7020.exe
C:\WINDOWS\~tmp7022.exe
C:\WINDOWS\~tmp7023.exe
C:\WINDOWS\~tmp7024.exe
C:\WINDOWS\~tmp7025.exe
C:\WINDOWS\~tmp7026.exe
C:\WINDOWS\~tmp703.exe
C:\WINDOWS\~tmp7030.exe
C:\WINDOWS\~tmp7032.exe
C:\WINDOWS\~tmp7036.exe
C:\WINDOWS\~tmp7037.exe
C:\WINDOWS\~tmp7038.exe
C:\WINDOWS\~tmp7041.exe
C:\WINDOWS\~tmp7042.exe
C:\WINDOWS\~tmp7043.exe
C:\WINDOWS\~tmp7044.exe
C:\WINDOWS\~tmp7047.exe
C:\WINDOWS\~tmp7048.exe
C:\WINDOWS\~tmp7049.exe
C:\WINDOWS\~tmp7050.exe
C:\WINDOWS\~tmp7051.exe
C:\WINDOWS\~tmp7052.exe
C:\WINDOWS\~tmp7053.exe
C:\WINDOWS\~tmp7056.exe
C:\WINDOWS\~tmp7057.exe
C:\WINDOWS\~tmp7058.exe
C:\WINDOWS\~tmp706.exe
C:\WINDOWS\~tmp7061.exe
C:\WINDOWS\~tmp7064.exe
C:\WINDOWS\~tmp7065.exe
C:\WINDOWS\~tmp7066.exe
C:\WINDOWS\~tmp7067.exe
C:\WINDOWS\~tmp7072.exe
C:\WINDOWS\~tmp7073.exe
C:\WINDOWS\~tmp7078.exe
C:\WINDOWS\~tmp708.exe
C:\WINDOWS\~tmp7080.exe
C:\WINDOWS\~tmp7083.exe
C:\WINDOWS\~tmp7084.exe
C:\WINDOWS\~tmp7086.exe
C:\WINDOWS\~tmp7087.exe
C:\WINDOWS\~tmp7088.exe
C:\WINDOWS\~tmp709.exe
C:\WINDOWS\~tmp7090.exe
C:\WINDOWS\~tmp7091.exe
C:\WINDOWS\~tmp7092.exe
C:\WINDOWS\~tmp7095.exe
C:\WINDOWS\~tmp7096.exe
C:\WINDOWS\~tmp7098.exe
C:\WINDOWS\~tmp71.exe
C:\WINDOWS\~tmp7102.exe
C:\WINDOWS\~tmp7104.exe
C:\WINDOWS\~tmp7105.exe
C:\WINDOWS\~tmp7106.exe
C:\WINDOWS\~tmp7107.exe
C:\WINDOWS\~tmp7109.exe
C:\WINDOWS\~tmp711.exe
C:\WINDOWS\~tmp7110.exe
C:\WINDOWS\~tmp7111.exe
C:\WINDOWS\~tmp7114.exe
C:\WINDOWS\~tmp7117.exe
C:\WINDOWS\~tmp7118.exe
C:\WINDOWS\~tmp712.exe
C:\WINDOWS\~tmp7122.exe
C:\WINDOWS\~tmp7125.exe
C:\WINDOWS\~tmp7127.exe
C:\WINDOWS\~tmp713.exe
C:\WINDOWS\~tmp7131.exe
C:\WINDOWS\~tmp7132.exe
C:\WINDOWS\~tmp7136.exe
C:\WINDOWS\~tmp7137.exe
C:\WINDOWS\~tmp7141.exe
C:\WINDOWS\~tmp7142.exe
C:\WINDOWS\~tmp7143.exe
C:\WINDOWS\~tmp7147.exe
C:\WINDOWS\~tmp7148.exe
C:\WINDOWS\~tmp715.exe
C:\WINDOWS\~tmp7150.exe
C:\WINDOWS\~tmp7151.exe
C:\WINDOWS\~tmp7152.exe
C:\WINDOWS\~tmp7153.exe
C:\WINDOWS\~tmp7154.exe
C:\WINDOWS\~tmp7157.exe
C:\WINDOWS\~tmp7158.exe
C:\WINDOWS\~tmp716.exe
C:\WINDOWS\~tmp7160.exe
C:\WINDOWS\~tmp7163.exe
C:\WINDOWS\~tmp717.exe
C:\WINDOWS\~tmp7170.exe
C:\WINDOWS\~tmp7172.exe
C:\WINDOWS\~tmp7174.exe
C:\WINDOWS\~tmp7175.exe
C:\WINDOWS\~tmp7176.exe
C:\WINDOWS\~tmp7177.exe
C:\WINDOWS\~tmp7178.exe
C:\WINDOWS\~tmp7179.exe
C:\WINDOWS\~tmp7186.exe
C:\WINDOWS\~tmp7187.exe
C:\WINDOWS\~tmp7188.exe
C:\WINDOWS\~tmp7189.exe
C:\WINDOWS\~tmp7191.exe
C:\WINDOWS\~tmp7192.exe
C:\WINDOWS\~tmp7193.exe
C:\WINDOWS\~tmp7194.exe
C:\WINDOWS\~tmp7195.exe
C:\WINDOWS\~tmp7197.exe
C:\WINDOWS\~tmp7198.exe
C:\WINDOWS\~tmp72.exe
C:\WINDOWS\~tmp7201.exe
C:\WINDOWS\~tmp7202.exe
C:\WINDOWS\~tmp7206.exe
C:\WINDOWS\~tmp7207.exe
C:\WINDOWS\~tmp7208.exe
C:\WINDOWS\~tmp7209.exe
C:\WINDOWS\~tmp721.exe
C:\WINDOWS\~tmp7212.exe
C:\WINDOWS\~tmp7214.exe
C:\WINDOWS\~tmp7216.exe
C:\WINDOWS\~tmp7217.exe
C:\WINDOWS\~tmp7218.exe
C:\WINDOWS\~tmp7219.exe
C:\WINDOWS\~tmp722.exe
C:\WINDOWS\~tmp7222.exe
C:\WINDOWS\~tmp7224.exe
C:\WINDOWS\~tmp7225.exe
C:\WINDOWS\~tmp7227.exe
C:\WINDOWS\~tmp7228.exe
C:\WINDOWS\~tmp723.exe
C:\WINDOWS\~tmp7230.exe
C:\WINDOWS\~tmp7231.exe
C:\WINDOWS\~tmp7232.exe
C:\WINDOWS\~tmp7233.exe
C:\WINDOWS\~tmp7238.exe
C:\WINDOWS\~tmp7239.exe
C:\WINDOWS\~tmp724.exe
C:\WINDOWS\~tmp7243.exe
C:\WINDOWS\~tmp7245.exe
C:\WINDOWS\~tmp7246.exe
C:\WINDOWS\~tmp7249.exe
C:\WINDOWS\~tmp7250.exe
C:\WINDOWS\~tmp7252.exe
C:\WINDOWS\~tmp7254.exe
C:\WINDOWS\~tmp7257.exe
C:\WINDOWS\~tmp7258.exe
C:\WINDOWS\~tmp7259.exe
C:\WINDOWS\~tmp7261.exe
C:\WINDOWS\~tmp7262.exe
C:\WINDOWS\~tmp7263.exe
C:\WINDOWS\~tmp7264.exe
C:\WINDOWS\~tmp7266.exe
C:\WINDOWS\~tmp7269.exe
C:\WINDOWS\~tmp727.exe
C:\WINDOWS\~tmp7270.exe
C:\WINDOWS\~tmp7271.exe
C:\WINDOWS\~tmp7273.exe
C:\WINDOWS\~tmp7279.exe
C:\WINDOWS\~tmp7280.exe
C:\WINDOWS\~tmp7283.exe
C:\WINDOWS\~tmp7284.exe
C:\WINDOWS\~tmp7285.exe
C:\WINDOWS\~tmp7287.exe
C:\WINDOWS\~tmp7288.exe
C:\WINDOWS\~tmp729.exe
C:\WINDOWS\~tmp7290.exe
C:\WINDOWS\~tmp7291.exe
C:\WINDOWS\~tmp7293.exe
C:\WINDOWS\~tmp7294.exe
C:\WINDOWS\~tmp7297.exe
C:\WINDOWS\~tmp730.exe
C:\WINDOWS\~tmp7300.exe
C:\WINDOWS\~tmp7305.exe
C:\WINDOWS\~tmp7308.exe
C:\WINDOWS\~tmp7309.exe
C:\WINDOWS\~tmp7310.exe
C:\WINDOWS\~tmp7312.exe
C:\WINDOWS\~tmp7313.exe
C:\WINDOWS\~tmp7315.exe
C:\WINDOWS\~tmp7317.exe
C:\WINDOWS\~tmp7320.exe
C:\WINDOWS\~tmp7321.exe
C:\WINDOWS\~tmp7327.exe
C:\WINDOWS\~tmp7328.exe
C:\WINDOWS\~tmp7329.exe
C:\WINDOWS\~tmp733.exe
C:\WINDOWS\~tmp7330.exe
C:\WINDOWS\~tmp7331.exe
C:\WINDOWS\~tmp7332.exe
C:\WINDOWS\~tmp7334.exe
C:\WINDOWS\~tmp7335.exe
C:\WINDOWS\~tmp7337.exe
C:\WINDOWS\~tmp7338.exe
C:\WINDOWS\~tmp7339.exe
C:\WINDOWS\~tmp7340.exe
C:\WINDOWS\~tmp7345.exe
C:\WINDOWS\~tmp7346.exe
C:\WINDOWS\~tmp7347.exe
C:\WINDOWS\~tmp7348.exe
C:\WINDOWS\~tmp7349.exe
C:\WINDOWS\~tmp735.exe
C:\WINDOWS\~tmp7354.exe
C:\WINDOWS\~tmp7356.exe
C:\WINDOWS\~tmp7357.exe
C:\WINDOWS\~tmp7358.exe
C:\WINDOWS\~tmp7359.exe
C:\WINDOWS\~tmp7361.exe
C:\WINDOWS\~tmp7362.exe
C:\WINDOWS\~tmp7366.exe
C:\WINDOWS\~tmp7367.exe
C:\WINDOWS\~tmp7369.exe
C:\WINDOWS\~tmp737.exe
C:\WINDOWS\~tmp7370.exe
C:\WINDOWS\~tmp7371.exe
C:\WINDOWS\~tmp7375.exe
C:\WINDOWS\~tmp7376.exe
C:\WINDOWS\~tmp7378.exe
C:\WINDOWS\~tmp738.exe
C:\WINDOWS\~tmp7380.exe
C:\WINDOWS\~tmp7381.exe
C:\WINDOWS\~tmp7384.exe
C:\WINDOWS\~tmp7385.exe
C:\WINDOWS\~tmp7386.exe
C:\WINDOWS\~tmp7388.exe
C:\WINDOWS\~tmp7389.exe
C:\WINDOWS\~tmp739.exe
C:\WINDOWS\~tmp7390.exe
C:\WINDOWS\~tmp7393.exe
C:\WINDOWS\~tmp7394.exe
C:\WINDOWS\~tmp74.exe
C:\WINDOWS\~tmp740.exe
C:\WINDOWS\~tmp7405.exe
C:\WINDOWS\~tmp7406.exe
C:\WINDOWS\~tmp7407.exe
C:\WINDOWS\~tmp7408.exe
C:\WINDOWS\~tmp7410.exe
C:\WINDOWS\~tmp7412.exe
C:\WINDOWS\~tmp7413.exe
C:\WINDOWS\~tmp7414.exe
C:\WINDOWS\~tmp7415.exe
C:\WINDOWS\~tmp7418.exe
C:\WINDOWS\~tmp742.exe
C:\WINDOWS\~tmp7420.exe
C:\WINDOWS\~tmp7421.exe
C:\WINDOWS\~tmp7423.exe
C:\WINDOWS\~tmp7425.exe
C:\WINDOWS\~tmp7426.exe
C:\WINDOWS\~tmp743.exe
C:\WINDOWS\~tmp7430.exe
C:\WINDOWS\~tmp7432.exe
C:\WINDOWS\~tmp7433.exe
C:\WINDOWS\~tmp7434.exe
C:\WINDOWS\~tmp7435.exe
C:\WINDOWS\~tmp7436.exe
C:\WINDOWS\~tmp7437.exe
C:\WINDOWS\~tmp7439.exe
C:\WINDOWS\~tmp744.exe
C:\WINDOWS\~tmp7440.exe
C:\WINDOWS\~tmp7441.exe
C:\WINDOWS\~tmp7446.exe
C:\WINDOWS\~tmp7447.exe
C:\WINDOWS\~tmp7449.exe
C:\WINDOWS\~tmp7450.exe
C:\WINDOWS\~tmp7452.exe
C:\WINDOWS\~tmp7453.exe
C:\WINDOWS\~tmp7458.exe
C:\WINDOWS\~tmp746.exe
C:\WINDOWS\~tmp7460.exe
C:\WINDOWS\~tmp7461.exe
C:\WINDOWS\~tmp7462.exe
C:\WINDOWS\~tmp7463.exe
C:\WINDOWS\~tmp7468.exe
C:\WINDOWS\~tmp7471.exe
C:\WINDOWS\~tmp7472.exe
C:\WINDOWS\~tmp7473.exe
C:\WINDOWS\~tmp7474.exe
C:\WINDOWS\~tmp7475.exe
C:\WINDOWS\~tmp7476.exe
C:\WINDOWS\~tmp7477.exe
C:\WINDOWS\~tmp7480.exe
C:\WINDOWS\~tmp7482.exe
C:\WINDOWS\~tmp7483.exe
C:\WINDOWS\~tmp7484.exe
C:\WINDOWS\~tmp7485.exe
C:\WINDOWS\~tmp7486.exe
C:\WINDOWS\~tmp7487.exe
C:\WINDOWS\~tmp7488.exe
C:\WINDOWS\~tmp7489.exe
C:\WINDOWS\~tmp749.exe
C:\WINDOWS\~tmp7490.exe
C:\WINDOWS\~tmp7493.exe
C:\WINDOWS\~tmp7496.exe
C:\WINDOWS\~tmp7497.exe
C:\WINDOWS\~tmp7498.exe
C:\WINDOWS\~tmp75.exe
C:\WINDOWS\~tmp7500.exe
C:\WINDOWS\~tmp7502.exe
C:\WINDOWS\~tmp7503.exe
C:\WINDOWS\~tmp7504.exe
C:\WINDOWS\~tmp7505.exe
C:\WINDOWS\~tmp7508.exe
C:\WINDOWS\~tmp7509.exe
C:\WINDOWS\~tmp7510.exe
C:\WINDOWS\~tmp7511.exe
C:\WINDOWS\~tmp7515.exe
C:\WINDOWS\~tmp7517.exe
C:\WINDOWS\~tmp7521.exe
C:\WINDOWS\~tmp7522.exe
C:\WINDOWS\~tmp7524.exe
C:\WINDOWS\~tmp7525.exe
C:\WINDOWS\~tmp7526.exe
C:\WINDOWS\~tmp7530.exe
C:\WINDOWS\~tmp7534.exe
C:\WINDOWS\~tmp7535.exe
C:\WINDOWS\~tmp7537.exe
C:\WINDOWS\~tmp7539.exe
C:\WINDOWS\~tmp754.exe
C:\WINDOWS\~tmp7543.exe
C:\WINDOWS\~tmp7548.exe
C:\WINDOWS\~tmp7549.exe
C:\WINDOWS\~tmp755.exe
C:\WINDOWS\~tmp7551.exe
C:\WINDOWS\~tmp7552.exe
C:\WINDOWS\~tmp7553.exe
C:\WINDOWS\~tmp7554.exe
C:\WINDOWS\~tmp756.exe
C:\WINDOWS\~tmp7560.exe
C:\WINDOWS\~tmp7563.exe
C:\WINDOWS\~tmp7565.exe
C:\WINDOWS\~tmp7566.exe
C:\WINDOWS\~tmp7567.exe
C:\WINDOWS\~tmp757.exe
C:\WINDOWS\~tmp7570.exe
C:\WINDOWS\~tmp7574.exe
C:\WINDOWS\~tmp7575.exe
C:\WINDOWS\~tmp7576.exe
C:\WINDOWS\~tmp7577.exe
C:\WINDOWS\~tmp7579.exe
C:\WINDOWS\~tmp7580.exe
C:\WINDOWS\~tmp7582.exe
C:\WINDOWS\~tmp7583.exe
C:\WINDOWS\~tmp7584.exe
C:\WINDOWS\~tmp7585.exe
C:\WINDOWS\~tmp7586.exe
C:\WINDOWS\~tmp7588.exe
C:\WINDOWS\~tmp7590.exe
C:\WINDOWS\~tmp76.exe
C:\WINDOWS\~tmp7600.exe
C:\WINDOWS\~tmp7602.exe
C:\WINDOWS\~tmp7603.exe
C:\WINDOWS\~tmp7605.exe
C:\WINDOWS\~tmp7606.exe
C:\WINDOWS\~tmp7607.exe
C:\WINDOWS\~tmp7609.exe
C:\WINDOWS\~tmp7611.exe
C:\WINDOWS\~tmp7612.exe
C:\WINDOWS\~tmp7613.exe
C:\WINDOWS\~tmp7615.exe
C:\WINDOWS\~tmp7616.exe
C:\WINDOWS\~tmp762.exe
C:\WINDOWS\~tmp7621.exe
C:\WINDOWS\~tmp7622.exe
C:\WINDOWS\~tmp7623.exe
C:\WINDOWS\~tmp7626.exe
C:\WINDOWS\~tmp7627.exe
C:\WINDOWS\~tmp763.exe
C:\WINDOWS\~tmp7632.exe
C:\WINDOWS\~tmp7633.exe
C:\WINDOWS\~tmp7635.exe
C:\WINDOWS\~tmp764.exe
C:\WINDOWS\~tmp7640.exe
C:\WINDOWS\~tmp7644.exe
C:\WINDOWS\~tmp7646.exe
C:\WINDOWS\~tmp7647.exe
C:\WINDOWS\~tmp7649.exe
C:\WINDOWS\~tmp765.exe
C:\WINDOWS\~tmp7654.exe
C:\WINDOWS\~tmp7655.exe
C:\WINDOWS\~tmp7657.exe
C:\WINDOWS\~tmp7659.exe
C:\WINDOWS\~tmp7661.exe
C:\WINDOWS\~tmp7662.exe
C:\WINDOWS\~tmp7663.exe
C:\WINDOWS\~tmp7665.exe
C:\WINDOWS\~tmp7667.exe
C:\WINDOWS\~tmp7669.exe
C:\WINDOWS\~tmp767.exe
C:\WINDOWS\~tmp7670.exe
C:\WINDOWS\~tmp7672.exe
C:\WINDOWS\~tmp7673.exe
C:\WINDOWS\~tmp7675.exe
C:\WINDOWS\~tmp7677.exe
C:\WINDOWS\~tmp7678.exe
C:\WINDOWS\~tmp7679.exe
C:\WINDOWS\~tmp768.exe
C:\WINDOWS\~tmp7683.exe
C:\WINDOWS\~tmp7684.exe
C:\WINDOWS\~tmp7685.exe
C:\WINDOWS\~tmp7687.exe
C:\WINDOWS\~tmp769.exe
C:\WINDOWS\~tmp7690.exe
C:\WINDOWS\~tmp7691.exe
C:\WINDOWS\~tmp7692.exe
C:\WINDOWS\~tmp7696.exe
C:\WINDOWS\~tmp7697.exe
C:\WINDOWS\~tmp7698.exe
C:\WINDOWS\~tmp7699.exe
C:\WINDOWS\~tmp77.exe
C:\WINDOWS\~tmp770.exe
C:\WINDOWS\~tmp7700.exe
C:\WINDOWS\~tmp7702.exe
C:\WINDOWS\~tmp7707.exe
C:\WINDOWS\~tmp7709.exe
C:\WINDOWS\~tmp771.exe
C:\WINDOWS\~tmp7710.exe
C:\WINDOWS\~tmp7713.exe
C:\WINDOWS\~tmp7714.exe
C:\WINDOWS\~tmp7715.exe
C:\WINDOWS\~tmp7716.exe
C:\WINDOWS\~tmp7717.exe
C:\WINDOWS\~tmp7718.exe
C:\WINDOWS\~tmp7719.exe
C:\WINDOWS\~tmp772.exe
C:\WINDOWS\~tmp7720.exe
C:\WINDOWS\~tmp7721.exe
C:\WINDOWS\~tmp7722.exe
C:\WINDOWS\~tmp7724.exe
C:\WINDOWS\~tmp7725.exe
C:\WINDOWS\~tmp7726.exe
C:\WINDOWS\~tmp7727.exe
C:\WINDOWS\~tmp7729.exe
C:\WINDOWS\~tmp773.exe
C:\WINDOWS\~tmp7730.exe
C:\WINDOWS\~tmp7731.exe
C:\WINDOWS\~tmp7732.exe
C:\WINDOWS\~tmp7734.exe


----------



## cpuanswers (Sep 25, 2007)

whew i had a lot in combofix


----------



## cpuanswers (Sep 25, 2007)

now for the last step


----------



## MFDnNC (Sep 7, 2004)

Run combo fix again as you did not post a lot of the necessary stuff


----------



## cpuanswers (Sep 25, 2007)

ok i guess ill try combo fix again


----------



## cpuanswers (Sep 25, 2007)

ComboFix 07-09-26 - Owner_Emachine 2007-09-25 19:15:14.3 - NTFSx86 
Microsoft Windows XP Home Edition 5.1.2600.2.1252.1.1033.18.84 [GMT -7:00]
Running from: C:\Documents and Settings\Owner_Emachine\Desktop\ComboFix.exe
.

((((((((((((((((((((((((( Files Created from 2007-08-26 to 2007-09-26 )))))))))))))))))))))))))))))))
.

2007-09-25 18:48 d--------	C:\Program Files\SUPERAntiSpyware
2007-09-25 18:48 d--------	C:\Documents and Settings\Owner_Emachine\Application Data\SUPERAntiSpyware.com
2007-09-25 18:48 d--------	C:\Documents and Settings\All Users\Application Data\SUPERAntiSpyware.com
2007-09-25 18:47 d--------	C:\Program Files\Common Files\Wise Installation Wizard
2007-09-25 17:04	51,200	--a------	C:\WINDOWS\NirCmd.exe
2007-09-25 16:23 d--------	C:\WINDOWS\ERUNT
2007-09-24 19:22 d--------	C:\Program Files\Trend Micro
2007-09-22 09:11	425,480	--a------	C:\sysmkoz.exe
2007-09-21 13:30	425,480	--a------	C:\sysbmpr.exe
2007-09-20 17:26	425,480	--a------	C:\sysnlve.exe
2007-09-18 18:18	425,480	--a------	C:\syswrcx.exe
2007-09-18 18:18	425,480	--a------	C:\sysvcfi.exe
2007-09-18 16:57	425,480	--a------	C:\sysutrb.exe

.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2007-09-23 19:47	---------	d--------	C:\Program Files\LimeWire
2007-09-21 13:30	---------	d--------	C:\Documents and Settings\Owner_Emachine\Application Data\LimeWire
2007-08-04 19:53	---------	d--------	C:\Program Files\Common Files\Ahead
2007-08-04 19:53	---------	d--------	C:\Program Files\Ahead
2007-08-01 17:00	26787	--a------	C:\WINDOWS\system32\drivers\vetmonnt.sys
2007-08-01 17:00	---------	d--------	C:\Documents and Settings\All Users\Application Data\CA
2007-08-01 16:59	879832	--a------	C:\WINDOWS\system32\drivers\VetEFile.sys
2007-08-01 16:59	108360	--a------	C:\WINDOWS\system32\drivers\VetEBoot.sys
2007-08-01 16:47	---------	d--------	C:\Documents and Settings\All Users\Application Data\yahoo!
2007-08-01 16:45	74864	--a------	C:\WINDOWS\system32\VetRedir.dll
2007-08-01 16:45	21031	--a------	C:\WINDOWS\system32\drivers\Vet-Filt.sys
2007-08-01 16:45	15735	--a------	C:\WINDOWS\system32\drivers\VetFDDNT.sys
2007-08-01 16:45	15478	--a------	C:\WINDOWS\system32\drivers\Vet-Rec.sys
2007-08-01 16:45	115824	--a------	C:\WINDOWS\UnVet32.exe
2007-08-01 16:45	111728	--a------	C:\WINDOWS\AVShlExt.dll
2007-08-01 16:45	---------	d--------	C:\Program Files\Yahoo!
2007-08-01 14:37	1730139	---hs----	C:\WINDOWS\system32\oqstv.bak2
2007-07-31 18:21	---------	d--------	C:\Program Files\Advanced Registry Optimizer
2007-07-31 18:09	---------	d--------	C:\Program Files\Common Files\Scanner
2007-07-31 18:07	---------	d--------	C:\Documents and Settings\Owner_Emachine\Application Data\Yahoo!
2007-07-31 18:07	---------	d--------	C:\Documents and Settings\All Users\Application Data\Yahoo! Companion
2007-07-31 17:26	6507	---hs----	C:\WINDOWS\system32\oqstv.bak1
2007-07-28 02:06	135	--a------	C:\Program Files\page.html
2007-07-27 13:53	---------	d--------	C:\Program Files\InterActual
.

((((((((((((((((((((((((((((( snapshot_2007-09-25_181424.60 )))))))))))))))))))))))))))))))))))))))))
.
----a-r 29,696 2007-09-26 01:48:13 C:\WINDOWS\Installer\{CDDCBBF1-2703-46BC-938B-BCC81A1EEAAA}\IconCDDCBBF11.exe
----a-r 18,944 2007-09-26 01:48:13 C:\WINDOWS\Installer\{CDDCBBF1-2703-46BC-938B-BCC81A1EEAAA}\IconCDDCBBF13.exe
----a-r 65,024 2007-09-26 01:48:13 C:\WINDOWS\Installer\{CDDCBBF1-2703-46BC-938B-BCC81A1EEAAA}\IconCDDCBBF15.exe
.
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.

*Note* empty entries & legit default entries are not shown

[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{0C9D3A87-7FEF-462E-ADB8-C94DFF4D6B9B}]
C:\Program Files\Internet Explorer\meqosadil83122.dll

[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{68867113-056C-43A4-807A-9C0B0C0A57F8}]
 C:\WINDOWS\SYSTEM32\VTSQO.DLL

[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{69F4671A-1407-4D07-D485-5DA6C85BCFAB}]
C:\Program Files\Online Services\qucam.dll

[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{76394256-0838-46B1-A319-D59FFC795843}]

[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{7D8ED76A-B6E6-4345-8AC8-47B1349DFCDC}]

[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{8941F9B8-6EC9-4BAE-A30F-BC3764FBBA3B}]

[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{C6907F56-4510-401B-BCB0-06118FC61C8D}]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Google Desktop Search"="C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe" [2007-09-06 09:34]
"readericon"="C:\Program Files\Digital Media Reader\readericon45G.exe" [2005-12-09 18:44]
"RTHDCPL"="RTHDCPL.EXE" [2006-04-04 02:44 C:\WINDOWS\RTHDCPL.exe]
"Recguard"="%WINDIR%\SMINST\RECGUARD.EXE" []
"HP Software Update"="C:\Program Files\HP\HP Software Update\HPWuSchd2.exe" [2006-02-19 03:41]
"YBrowser"="C:\PROGRA~1\Yahoo!\browser\ybrwicon.exe" [2006-07-21 16:19]
"Motive SmartBridge"="C:\PROGRA~1\SBCLIG~1\SMARTB~1\MotiveSB.exe" [2003-12-10 05:52]
"QuickTime Task"="C:\Program Files\QuickTime\qttask.exe" [2007-05-06 12:09]
"YOP"="C:\PROGRA~1\Yahoo!\YOP\yop.exe" [2006-07-21 10:43]
"CaAvTray"="C:\Program Files\Yahoo!\Antivirus\CAVTray.exe" [2007-08-01 16:45]
"CAVRID"="C:\Program Files\Yahoo!\Antivirus\CAVRID.exe" [2007-08-01 16:45]
"YSearchProtection"="C:\Program Files\Yahoo!\Search Protection\SearchProtection.exe" [2007-06-08 07:59]

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"swg"="C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe" [2007-06-09 08:15]
"Yahoo! Pager"="C:\PROGRA~1\Yahoo!\MESSEN~1\YAHOOM~1.exe" [2007-03-01 18:11]
"MSMSGS"="C:\Program Files\Messenger\msmsgs.exe" [2004-08-04 08:06]
"AROReminder"="C:\Program Files\Advanced Registry Optimizer\aro.exe" [2007-07-23 09:34]
"YSearchProtection"="C:\Program Files\Yahoo!\Search Protection\SearchProtection.exe" [2007-06-08 07:59]
"SUPERAntiSpyware"="C:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe" [2007-06-21 14:06]

[HKEY_USERS\.default\software\microsoft\windows\currentversion\run]
"Power2GoExpress"=NA

C:\Documents and Settings\All Users\Start Menu\Programs\Startup\
HP Digital Imaging Monitor.lnk - C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe [2006-02-19 05:21:22]
NkbMonitor.exe.lnk - C:\Program Files\Nikon\PictureProject\NkbMonitor.exe [2007-05-06 12:10:58]
ymetray.lnk - C:\Program Files\Yahoo!\Yahoo! Music Jukebox\ymetray.exe [2006-10-03 11:04:38]

C:\Documents and Settings\Owner_Emachine\Start Menu\Programs\Startup\
VirtualExpander.lnk - C:\WINDOWS\system32\VirtualExpander\VirtualExpander.exe [2007-07-04 15:58:31]

C:\Documents and Settings\All Users\Start Menu\Programs\Startup\
HP Digital Imaging Monitor.lnk - C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe [2006-02-19 05:21:22]
NkbMonitor.exe.lnk - C:\Program Files\Nikon\PictureProject\NkbMonitor.exe [2007-05-06 12:10:58]
ymetray.lnk - C:\Program Files\Yahoo!\Yahoo! Music Jukebox\ymetray.exe [2006-10-03 11:04:38]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks]
"{5AE067D3-9AFB-48E0-853A-EBB7F4A000DA}"= C:\Program Files\SUPERAntiSpyware\SASSEH.DLL [2006-12-20 13:55 77824]

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\!SASWinLogon] 
C:\Program Files\SUPERAntiSpyware\SASWINLO.dll 2007-04-19 13:41 294912 C:\Program Files\SUPERAntiSpyware\SASWINLO.dll

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\ljjgdax] 
ljjgdax.dll

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\vtsqo] 
C:\WINDOWS\system32\vtsqo.dll

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\windows]
"appinit_dlls"=C:\PROGRA~1\Google\GOOGLE~1\GOEC62~1.DLL

[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\F]
AutoRun\command- F:\LaunchU3.exe -a

*Newly Created Service* - SASDIFSV
*Newly Created Service* - SASENUM
*Newly Created Service* - SASKUTIL
.
Contents of the 'Scheduled Tasks' folder
"2007-09-23 07:00:00 C:\WINDOWS\Tasks\At1.job"
"2007-09-23 16:00:06 C:\WINDOWS\Tasks\At10.job"
- C:\WINDOWS\system32\MH2hQ12l.exe
"2007-09-23 17:00:00 C:\WINDOWS\Tasks\At11.job"
"2007-09-23 18:00:00 C:\WINDOWS\Tasks\At12.job"
- C:\WINDOWS\system32\MH2hQ12l.exe
"2007-09-23 19:00:01 C:\WINDOWS\Tasks\At13.job"
- C:\WINDOWS\system32\MH2hQ12l.exe
"2007-09-23 20:00:00 C:\WINDOWS\Tasks\At14.job"
- C:\WINDOWS\system32\MH2hQ12l.exe
"2007-09-24 21:00:00 C:\WINDOWS\Tasks\At15.job"
- C:\WINDOWS\system32\MH2hQ12l.exe
"2007-09-25 22:00:01 C:\WINDOWS\Tasks\At16.job"
- C:\WINDOWS\system32\MH2hQ12l.exe
"2007-09-23 23:00:00 C:\WINDOWS\Tasks\At17.job"
- C:\WINDOWS\system32\MH2hQ12l.exe
"2007-09-26 00:00:00 C:\WINDOWS\Tasks\At18.job"
- C:\WINDOWS\system32\MH2hQ12l.exe
"2007-09-26 01:00:00 C:\WINDOWS\Tasks\At19.job"
- C:\WINDOWS\system32\MH2hQ12l.exe
"2007-09-23 08:00:00 C:\WINDOWS\Tasks\At2.job"
- C:\WINDOWS\system32\MH2hQ12l.exe
"2007-09-26 02:00:01 C:\WINDOWS\Tasks\At20.job"
- C:\WINDOWS\system32\MH2hQ12l.exe
"2007-09-25 03:00:00 C:\WINDOWS\Tasks\At21.job"
- C:\WINDOWS\system32\MH2hQ12l.exe
"2007-09-23 04:00:00 C:\WINDOWS\Tasks\At22.job"
- C:\WINDOWS\system32\MH2hQ12l.exe
"2007-09-23 05:00:00 C:\WINDOWS\Tasks\At23.job"
- C:\WINDOWS\system32\MH2hQ12l.exe
"2007-09-23 06:00:00 C:\WINDOWS\Tasks\At24.job"
- C:\WINDOWS\system32\MH2hQ12l.exe
"2007-05-16 15:34:45 C:\WINDOWS\Tasks\At3.job"
- C:\WINDOWS\system32\MH2hQ12l.exe
"2007-05-16 15:34:45 C:\WINDOWS\Tasks\At4.job"
"2007-05-16 15:34:45 C:\WINDOWS\Tasks\At5.job"
- C:\WINDOWS\system32\MH2hQ12l.exe
"2007-05-16 15:34:45 C:\WINDOWS\Tasks\At6.job"
- C:\WINDOWS\system32\MH2hQ12l.exe
"2007-05-16 15:34:45 C:\WINDOWS\Tasks\At7.job"
- C:\WINDOWS\system32\MH2hQ12l.exe
"2007-09-01 14:00:00 C:\WINDOWS\Tasks\At8.job"
- C:\WINDOWS\system32\MH2hQ12l.exe
"2007-09-23 15:00:00 C:\WINDOWS\Tasks\At9.job"
- C:\WINDOWS\system32\MH2hQ12l.exe
.
**************************************************************************

catchme 0.3.1061 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2007-09-25 19:17:41
Windows 5.1.2600 Service Pack 2 NTFS

scanning hidden processes ...

scanning hidden autostart entries ...

scanning hidden files ...

scan completed successfully
hidden files: 0

**************************************************************************
.
Completion time: 2007-09-25 19:19:51
C:\ComboFix-quarantined-files.txt ... 2007-09-25 19:19
C:\ComboFix2.txt ... 2007-09-25 19:14
C:\ComboFix3.txt ... 2007-09-25 18:16
.
--- E O F ---

this is all that came out do i hav to delete the other combofix and get a new one


----------



## cpuanswers (Sep 25, 2007)

i did everything all i hav to do now is scan the computer with the superantispyware or is there a little bit more


----------



## cpuanswers (Sep 25, 2007)

ok here is my final hijackthis log pad

Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 9:28:47 PM, on 9/25/2007
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe
C:\Program Files\Digital Media Reader\readericon45G.exe
C:\WINDOWS\RTHDCPL.EXE
C:\Program Files\Yahoo!\Antivirus\ISafe.exe
C:\Program Files\HP\HP Software Update\HPWuSchd2.exe
C:\PROGRA~1\Yahoo!\browser\ybrwicon.exe
C:\PROGRA~1\SBCLIG~1\SMARTB~1\MotiveSB.exe
C:\Program Files\QuickTime\qttask.exe
C:\WINDOWS\system32\HPZipm12.exe
C:\PROGRA~1\Yahoo!\YOP\yop.exe
C:\Program Files\Yahoo!\Antivirus\CAVTray.exe
C:\Program Files\Common Files\New Boundary\PrismXL\PRISMXL.SYS
C:\Program Files\Yahoo!\Antivirus\CAVRID.exe
C:\Program Files\Yahoo!\Search Protection\SearchProtection.exe
C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
C:\WINDOWS\system32\svchost.exe
C:\PROGRA~1\Yahoo!\browser\ycommon.exe
C:\Program Files\Messenger\msmsgs.exe
C:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe
C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe
C:\Program Files\Nikon\PictureProject\NkbMonitor.exe
C:\Program Files\Yahoo!\Yahoo! Music Jukebox\ymetray.exe
C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe
C:\Program Files\Yahoo!\Antivirus\VetMsg.exe
C:\Program Files\Yahoo!\Messenger\ymsgr_tray.exe
C:\WINDOWS\system32\VirtualExpander\VirtualExpander.exe
C:\WINDOWS\system32\wuauclt.exe
C:\Program Files\HP\Digital Imaging\bin\hpqSTE08.exe
C:\Program Files\Internet Explorer\IEXPLORE.EXE
C:\WINDOWS\system32\wuauclt.exe
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe

R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.gateway.com/g/startpage.html?Ch=Retail&Br=EM&Loc=ENG_US&Sys=DTP&M=T3508
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar = http://red.clientapps.yahoo.com/cus.../sbcydsl/*http://www.yahoo.com/search/ie.html
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://red.clientapps.yahoo.com/customize/ie/defaults/sp/sbcydsl/*http://www.yahoo.com
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.gateway.com/g/startpage.html?Ch=Retail&Br=EM&Loc=ENG_US&Sys=DTP&M=T3508
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = 127.0.0.1;<local>
R3 - URLSearchHook: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn1\yt.dll
O2 - BHO: &Yahoo! Toolbar Helper - {02478D38-C3F9-4EFB-9B51-7695ECA05670} - C:\Program Files\Yahoo!\Companion\Installs\cpn1\yt.dll
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
O2 - BHO: (no name) - {0C9D3A87-7FEF-462E-ADB8-C94DFF4D6B9B} - C:\Program Files\Internet Explorer\meqosadil83122.dll (file missing)
O2 - BHO: Yahoo! IE Services Button - {5BAB4B5B-68BC-4B02-94D6-2FC0DE4A7897} - C:\PROGRA~1\Yahoo!\common\yiesrvc.dll
O2 - BHO: 0 - {69F4671A-1407-4D07-D485-5DA6C85BCFAB} - C:\Program Files\Online Services\qucam.dll (file missing)
O2 - BHO: (no name) - {76394256-0838-46B1-A319-D59FFC795843} - \
O2 - BHO: (no name) - {7D8ED76A-B6E6-4345-8AC8-47B1349DFCDC} - \
O2 - BHO: (no name) - {8941F9B8-6EC9-4BAE-A30F-BC3764FBBA3B} - \
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar2.dll
O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\2.0.301.7164\swg.dll
O2 - BHO: (no name) - {C6907F56-4510-401B-BCB0-06118FC61C8D} - \
O2 - BHO: CBrowserHelperObject Object - {CA6319C0-31B7-401E-A518-A07C3DB8F777} - c:\windows\system32\BAE.dll
O2 - BHO: SidebarAutoLaunch Class - {F2AA9440-6328-4933-B7C9-A6CCDF9CBF6D} - C:\Program Files\Yahoo!\browser\YSidebarIEBHO.dll
O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar2.dll
O3 - Toolbar: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn1\yt.dll
O4 - HKLM\..\Run: [Google Desktop Search] "C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe" /startup
O4 - HKLM\..\Run: [readericon] C:\Program Files\Digital Media Reader\readericon45G.exe
O4 - HKLM\..\Run: [RTHDCPL] RTHDCPL.EXE
O4 - HKLM\..\Run: [Recguard] %WINDIR%\SMINST\RECGUARD.EXE
O4 - HKLM\..\Run: [HP Software Update] C:\Program Files\HP\HP Software Update\HPWuSchd2.exe
O4 - HKLM\..\Run: [YBrowser] C:\PROGRA~1\Yahoo!\browser\ybrwicon.exe
O4 - HKLM\..\Run: [Motive SmartBridge] C:\PROGRA~1\SBCLIG~1\SMARTB~1\MotiveSB.exe
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [YOP] C:\PROGRA~1\Yahoo!\YOP\yop.exe /autostart
O4 - HKLM\..\Run: [CaAvTray] "C:\Program Files\Yahoo!\Antivirus\CAVTray.exe"
O4 - HKLM\..\Run: [CAVRID] "C:\Program Files\Yahoo!\Antivirus\CAVRID.exe"
O4 - HKLM\..\Run: [YSearchProtection] "C:\Program Files\Yahoo!\Search Protection\SearchProtection.exe"
O4 - HKCU\..\Run: [swg] C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
O4 - HKCU\..\Run: [Yahoo! Pager] "C:\Program Files\Yahoo!\Messenger\YahooMessenger.exe" -quiet
O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
O4 - HKCU\..\Run: [AROReminder] C:\Program Files\Advanced Registry Optimizer\aro.exe -rem
O4 - HKCU\..\Run: [YSearchProtection] C:\Program Files\Yahoo!\Search Protection\SearchProtection.exe
O4 - HKCU\..\Run: [SUPERAntiSpyware] C:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe
O4 - HKUS\S-1-5-18\..\Run: [Power2GoExpress] NA (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [Power2GoExpress] NA (User 'Default user')
O4 - Startup: VirtualExpander.lnk = C:\WINDOWS\system32\VirtualExpander\VirtualExpander.exe
O4 - Global Startup: HP Digital Imaging Monitor.lnk = C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe
O4 - Global Startup: NkbMonitor.exe.lnk = C:\Program Files\Nikon\PictureProject\NkbMonitor.exe
O4 - Global Startup: ymetray.lnk = C:\Program Files\Yahoo!\Yahoo! Music Jukebox\ymetray.exe
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
O9 - Extra button: AT&T Yahoo! Services - {5BAB4B5B-68BC-4B02-94D6-2FC0DE4A7897} - C:\PROGRA~1\Yahoo!\common\yiesrvc.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL
O9 - Extra button: Real.com - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - C:\WINDOWS\system32\Shdocvw.dll
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O16 - DPF: {30528230-99f7-4bb4-88d8-fa1d4f56a2ab} (Installation Support) - C:\Program Files\Yahoo!\Common\Yinsthelper2007261.dll
O16 - DPF: {77E32299-629F-43C6-AB77-6A1E6D7663F6} (Groove Control) - http://www.nick.com/common/groove/gx/GrooveAX27.cab
O16 - DPF: {BB383206-6DA1-4E80-B62A-3DF950FCC697} (Create & Print ActiveX Plug-in) - http://ak.imgag.com/imgag/cp/install/AxCtp2.cab
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - https://fpdownload.macromedia.com/pub/shockwave/cabs/flash/swflash.cab
O20 - AppInit_DLLs: C:\PROGRA~1\Google\GOOGLE~1\GOEC62~1.DLL
O20 - Winlogon Notify: !SASWinLogon - C:\Program Files\SUPERAntiSpyware\SASWINLO.dll
O20 - Winlogon Notify: ljjgdax - ljjgdax.dll (file missing)
O20 - Winlogon Notify: vtsqo - C:\WINDOWS\system32\vtsqo.dll (file missing)
O23 - Service: Ati HotKey Poller - ATI Technologies Inc. - C:\WINDOWS\system32\Ati2evxx.exe
O23 - Service: ATI Smart - Unknown owner - C:\WINDOWS\system32\ati2sgag.exe
O23 - Service: CAISafe - Computer Associates International, Inc. - C:\Program Files\Yahoo!\Antivirus\ISafe.exe
O23 - Service: GoogleDesktopManager - Google - C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe
O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: Pml Driver HPZ12 - HP - C:\WINDOWS\system32\HPZipm12.exe
O23 - Service: PrismXL - New Boundary Technologies, Inc. - C:\Program Files\Common Files\New Boundary\PrismXL\PRISMXL.SYS
O23 - Service: VET Message Service (VETMSGNT) - Computer Associates International, Inc. - C:\Program Files\Yahoo!\Antivirus\VetMsg.exe
O23 - Service: YPCService - Yahoo! Inc. - C:\WINDOWS\system32\YPCSER~1.EXE

--
End of file - 9234 bytes

tell me if there is any problem with it


----------



## MFDnNC (Sep 7, 2004)

Where is the log from SUPERAntiSpyware

START  RUN  CMD  enter
DEL C:\WINDOWS\Tasks\At*.job  enter

==========================

You may want to print this or save it to notepad as we will go to safe mode.

Fix these with HiJackThis  mark them, close IE, click fix checked

O2 - BHO: (no name) - {0C9D3A87-7FEF-462E-ADB8-C94DFF4D6B9B} - C:\Program Files\Internet Explorer\meqosadil83122.dll (file missing)

O2 - BHO: 0 - {69F4671A-1407-4D07-D485-5DA6C85BCFAB} - C:\Program Files\Online Services\qucam.dll (file missing)

O2 - BHO: (no name) - {76394256-0838-46B1-A319-D59FFC795843} - \

O2 - BHO: (no name) - {7D8ED76A-B6E6-4345-8AC8-47B1349DFCDC} - \

O2 - BHO: (no name) - {8941F9B8-6EC9-4BAE-A30F-BC3764FBBA3B} - \

O2 - BHO: (no name) - {C6907F56-4510-401B-BCB0-06118FC61C8D} - \

O20 - Winlogon Notify: ljjgdax - ljjgdax.dll (file missing)

O20 - Winlogon Notify: vtsqo - C:\WINDOWS\system32\vtsqo.dll (file missing)

DownLoad http://www.downloads.subratam.org/KillBox.zip or
http://www.thespykiller.co.uk/files/killbox.exe

Restart your computer into safe mode now. (Tapping F8 at the first black screen) Perform the following steps in safe mode:

Double-click on Killbox.exe to run it. Now put a tick by Standard File Kill. In the "Full Path of File to Delete" box, copy and paste each of the following line(s) one at a time then click on the button that has the red circle with the X in the middle after you enter each file. It will ask for confimation to delete the file. Click Yes. Continue with that same procedure until you have copied and pasted all of these in the "Paste Full Path of File to Delete" box. 
* Be sure to note the EXACT spelling of the file *

C:\WINDOWS\system32\MH2hQ12l.exe

Note: It is possible that Killbox will tell you that one or more files do not exist. If that happens, just continue on with all the files. Be sure you don't miss any.

START  RUN  type in %temp% - OK - Edit  Select all  File  Delete

Delete everything in the C:\Windows\Temp folder or C:\WINNT\temp

Not all temp files will delete and that is normal
Empty the recycle bin
Boot and post a new hijack log from normal NOT safe mode

* How are things on the PC??????????? *


----------



## cpuanswers (Sep 25, 2007)

Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 4:10:21 PM, on 9/26/2007
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Yahoo!\Antivirus\ISafe.exe
C:\WINDOWS\system32\HPZipm12.exe
C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe
C:\Program Files\Digital Media Reader\readericon45G.exe
C:\WINDOWS\RTHDCPL.EXE
C:\Program Files\Common Files\New Boundary\PrismXL\PRISMXL.SYS
C:\Program Files\HP\HP Software Update\HPWuSchd2.exe
C:\PROGRA~1\Yahoo!\browser\ybrwicon.exe
C:\PROGRA~1\SBCLIG~1\SMARTB~1\MotiveSB.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\QuickTime\qttask.exe
C:\PROGRA~1\Yahoo!\YOP\yop.exe
C:\Program Files\Yahoo!\Antivirus\CAVTray.exe
C:\Program Files\Yahoo!\Antivirus\CAVRID.exe
C:\Program Files\Yahoo!\Search Protection\SearchProtection.exe
C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
C:\Program Files\Messenger\msmsgs.exe
C:\PROGRA~1\Yahoo!\browser\ycommon.exe
C:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe
C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe
C:\Program Files\Nikon\PictureProject\NkbMonitor.exe
C:\Program Files\Yahoo!\Yahoo! Music Jukebox\ymetray.exe
C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe
C:\Program Files\Yahoo!\Messenger\ymsgr_tray.exe
C:\WINDOWS\system32\VirtualExpander\VirtualExpander.exe
C:\Program Files\HP\Digital Imaging\bin\hpqSTE08.exe
C:\WINDOWS\system32\wuauclt.exe
C:\Program Files\Yahoo!\Antivirus\VetMsg.exe
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe

R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.gateway.com/g/startpage.html?Ch=Retail&Br=EM&Loc=ENG_US&Sys=DTP&M=T3508
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar = http://red.clientapps.yahoo.com/cus.../sbcydsl/*http://www.yahoo.com/search/ie.html
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://red.clientapps.yahoo.com/customize/ie/defaults/sp/sbcydsl/*http://www.yahoo.com
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.gateway.com/g/startpage.html?Ch=Retail&Br=EM&Loc=ENG_US&Sys=DTP&M=T3508
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = 127.0.0.1;<local>
R3 - URLSearchHook: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn1\yt.dll
O2 - BHO: &Yahoo! Toolbar Helper - {02478D38-C3F9-4EFB-9B51-7695ECA05670} - C:\Program Files\Yahoo!\Companion\Installs\cpn1\yt.dll
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
O2 - BHO: Yahoo! IE Services Button - {5BAB4B5B-68BC-4B02-94D6-2FC0DE4A7897} - C:\PROGRA~1\Yahoo!\common\yiesrvc.dll
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar2.dll
O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\2.0.301.7164\swg.dll
O2 - BHO: CBrowserHelperObject Object - {CA6319C0-31B7-401E-A518-A07C3DB8F777} - c:\windows\system32\BAE.dll
O2 - BHO: SidebarAutoLaunch Class - {F2AA9440-6328-4933-B7C9-A6CCDF9CBF6D} - C:\Program Files\Yahoo!\browser\YSidebarIEBHO.dll
O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar2.dll
O3 - Toolbar: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn1\yt.dll
O4 - HKLM\..\Run: [Google Desktop Search] "C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe" /startup
O4 - HKLM\..\Run: [readericon] C:\Program Files\Digital Media Reader\readericon45G.exe
O4 - HKLM\..\Run: [RTHDCPL] RTHDCPL.EXE
O4 - HKLM\..\Run: [Recguard] %WINDIR%\SMINST\RECGUARD.EXE
O4 - HKLM\..\Run: [HP Software Update] C:\Program Files\HP\HP Software Update\HPWuSchd2.exe
O4 - HKLM\..\Run: [YBrowser] C:\PROGRA~1\Yahoo!\browser\ybrwicon.exe
O4 - HKLM\..\Run: [Motive SmartBridge] C:\PROGRA~1\SBCLIG~1\SMARTB~1\MotiveSB.exe
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [YOP] C:\PROGRA~1\Yahoo!\YOP\yop.exe /autostart
O4 - HKLM\..\Run: [CaAvTray] "C:\Program Files\Yahoo!\Antivirus\CAVTray.exe"
O4 - HKLM\..\Run: [CAVRID] "C:\Program Files\Yahoo!\Antivirus\CAVRID.exe"
O4 - HKLM\..\Run: [YSearchProtection] "C:\Program Files\Yahoo!\Search Protection\SearchProtection.exe"
O4 - HKCU\..\Run: [swg] C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
O4 - HKCU\..\Run: [Yahoo! Pager] "C:\Program Files\Yahoo!\Messenger\YahooMessenger.exe" -quiet
O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
O4 - HKCU\..\Run: [AROReminder] C:\Program Files\Advanced Registry Optimizer\aro.exe -rem
O4 - HKCU\..\Run: [YSearchProtection] C:\Program Files\Yahoo!\Search Protection\SearchProtection.exe
O4 - HKCU\..\Run: [SUPERAntiSpyware] C:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe
O4 - HKUS\S-1-5-18\..\Run: [Power2GoExpress] NA (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [Power2GoExpress] NA (User 'Default user')
O4 - Startup: VirtualExpander.lnk = C:\WINDOWS\system32\VirtualExpander\VirtualExpander.exe
O4 - Global Startup: HP Digital Imaging Monitor.lnk = C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe
O4 - Global Startup: NkbMonitor.exe.lnk = C:\Program Files\Nikon\PictureProject\NkbMonitor.exe
O4 - Global Startup: ymetray.lnk = C:\Program Files\Yahoo!\Yahoo! Music Jukebox\ymetray.exe
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
O9 - Extra button: AT&T Yahoo! Services - {5BAB4B5B-68BC-4B02-94D6-2FC0DE4A7897} - C:\PROGRA~1\Yahoo!\common\yiesrvc.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL
O9 - Extra button: Real.com - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - C:\WINDOWS\system32\Shdocvw.dll
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O16 - DPF: {30528230-99f7-4bb4-88d8-fa1d4f56a2ab} (Installation Support) - C:\Program Files\Yahoo!\Common\Yinsthelper2007261.dll
O16 - DPF: {77E32299-629F-43C6-AB77-6A1E6D7663F6} (Groove Control) - http://www.nick.com/common/groove/gx/GrooveAX27.cab
O16 - DPF: {BB383206-6DA1-4E80-B62A-3DF950FCC697} (Create & Print ActiveX Plug-in) - http://ak.imgag.com/imgag/cp/install/AxCtp2.cab
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - https://fpdownload.macromedia.com/pub/shockwave/cabs/flash/swflash.cab
O20 - AppInit_DLLs: C:\PROGRA~1\Google\GOOGLE~1\GOEC62~1.DLL
O20 - Winlogon Notify: !SASWinLogon - C:\Program Files\SUPERAntiSpyware\SASWINLO.dll
O23 - Service: Ati HotKey Poller - ATI Technologies Inc. - C:\WINDOWS\system32\Ati2evxx.exe
O23 - Service: ATI Smart - Unknown owner - C:\WINDOWS\system32\ati2sgag.exe
O23 - Service: CAISafe - Computer Associates International, Inc. - C:\Program Files\Yahoo!\Antivirus\ISafe.exe
O23 - Service: GoogleDesktopManager - Google - C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe
O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: Pml Driver HPZ12 - HP - C:\WINDOWS\system32\HPZipm12.exe
O23 - Service: PrismXL - New Boundary Technologies, Inc. - C:\Program Files\Common Files\New Boundary\PrismXL\PRISMXL.SYS
O23 - Service: VET Message Service (VETMSGNT) - Computer Associates International, Inc. - C:\Program Files\Yahoo!\Antivirus\VetMsg.exe
O23 - Service: YPCService - Yahoo! Inc. - C:\WINDOWS\system32\YPCSER~1.EXE

--
End of file - 8503 bytes


----------



## MFDnNC (Sep 7, 2004)

Where is the log from SUPERAntiSpyware


----------



## cpuanswers (Sep 25, 2007)

superanitspyware di not give me a log


----------



## cpuanswers (Sep 25, 2007)

oh wait I found it


----------



## cpuanswers (Sep 25, 2007)

SUPERAntiSpyware Scan Log
http://www.superantispyware.com

Generated 09/25/2007 at 07:11 PM

Application Version : 3.9.1008

Core Rules Database Version : 3313
Trace Rules Database Version: 1316

Scan type : Complete Scan
Total Scan Time : 00:19:55

Memory items scanned : 424
Memory threats detected : 0
Registry items scanned : 5669
Registry threats detected : 53
File items scanned : 3739
File threats detected : 360

Adware.Vundo Variant
HKLM\Software\Classes\CLSID\{68867113-056C-43A4-807A-9C0B0C0A57F8}
HKCR\CLSID\{68867113-056C-43A4-807A-9C0B0C0A57F8}
HKCR\CLSID\{68867113-056C-43A4-807A-9C0B0C0A57F8}\InprocServer32
HKCR\CLSID\{68867113-056C-43A4-807A-9C0B0C0A57F8}\InprocServer32#ThreadingModel
C:\WINDOWS\SYSTEM32\VTSQO.DLL
HKLM\Software\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{68867113-056C-43A4-807A-9C0B0C0A57F8}

Adware.Mirar/NetNucleus
HKLM\Software\Classes\CLSID\{9A9C9B68-F908-4AAB-8D0C-10EA8997F37E}
HKCR\CLSID\{9A9C9B68-F908-4AAB-8D0C-10EA8997F37E}
HKCR\CLSID\{9A9C9B68-F908-4AAB-8D0C-10EA8997F37E}\Properties
HKCR\CLSID\{9A9C9B68-F908-4AAB-8D0C-10EA8997F37E}\Properties#Ticket
HKCR\Interface\{1037B06C-84B7-4240-8D80-485810A0497D}
HKCR\Interface\{1037B06C-84B7-4240-8D80-485810A0497D}\ProxyStubClsid
HKCR\Interface\{1037B06C-84B7-4240-8D80-485810A0497D}\ProxyStubClsid32
HKCR\Interface\{1037B06C-84B7-4240-8D80-485810A0497D}\TypeLib
HKCR\Interface\{1037B06C-84B7-4240-8D80-485810A0497D}\TypeLib#Version
HKCR\Interface\{54B287F9-FD90-4457-B65E-CB91560C021D}
HKCR\Interface\{54B287F9-FD90-4457-B65E-CB91560C021D}\ProxyStubClsid
HKCR\Interface\{54B287F9-FD90-4457-B65E-CB91560C021D}\ProxyStubClsid32
HKCR\Interface\{54B287F9-FD90-4457-B65E-CB91560C021D}\TypeLib
HKCR\Interface\{54B287F9-FD90-4457-B65E-CB91560C021D}\TypeLib#Version
HKCR\Interface\{6E4C7AFC-9915-4036-B7F9-8B3F1710788F}
HKCR\Interface\{6E4C7AFC-9915-4036-B7F9-8B3F1710788F}\ProxyStubClsid
HKCR\Interface\{6E4C7AFC-9915-4036-B7F9-8B3F1710788F}\ProxyStubClsid32
HKCR\Interface\{6E4C7AFC-9915-4036-B7F9-8B3F1710788F}\TypeLib
HKCR\Interface\{6E4C7AFC-9915-4036-B7F9-8B3F1710788F}\TypeLib#Version
HKCR\Mirar_Dummy_ATS.Mirar_Dummy_ATS1
HKCR\Mirar_Dummy_ATS.Mirar_Dummy_ATS1\CLSID
HKCR\Mirar_Dummy_ATS.Mirar_Dummy_ATS1\CurVer
HKCR\Mirar_Dummy_ATS.Mirar_Dummy_ATS1.1
HKCR\Mirar_Dummy_ATS.Mirar_Dummy_ATS1.1\CLSID
HKCR\TypeLib\{566DEDE9-9ED8-45DA-9BE6-9B2EEAB17F49}
HKCR\TypeLib\{566DEDE9-9ED8-45DA-9BE6-9B2EEAB17F49}\1.0
HKCR\TypeLib\{566DEDE9-9ED8-45DA-9BE6-9B2EEAB17F49}\1.0\0
HKCR\TypeLib\{566DEDE9-9ED8-45DA-9BE6-9B2EEAB17F49}\1.0\0\win32
HKCR\TypeLib\{566DEDE9-9ED8-45DA-9BE6-9B2EEAB17F49}\1.0\FLAGS
HKCR\TypeLib\{566DEDE9-9ED8-45DA-9BE6-9B2EEAB17F49}\1.0\HELPDIR
HKCR\CLSID\{8A0DCBDB-6E20-489C-9041-C1E8A0352E75}
HKCR\CLSID\{8A0DCBDB-6E20-489C-9041-C1E8A0352E75}\InprocServer32
HKCR\CLSID\{8A0DCBDB-6E20-489C-9041-C1E8A0352E75}\InprocServer32#ThreadingModel
HKCR\CLSID\{8A0DCBDB-6E20-489C-9041-C1E8A0352E75}\ProgID
HKCR\CLSID\{8A0DCBDB-6E20-489C-9041-C1E8A0352E75}\Programmable
HKCR\CLSID\{8A0DCBDB-6E20-489C-9041-C1E8A0352E75}\TypeLib
HKCR\CLSID\{8A0DCBDB-6E20-489C-9041-C1E8A0352E75}\VersionIndependentProgID
HKLM\SOFTWARE\Microsoft\Code Store Database\Distribution Units\{8A0DCBDB-6E20-489C-9041-C1E8A0352E75}
HKLM\SOFTWARE\Microsoft\Code Store Database\Distribution Units\{8A0DCBDB-6E20-489C-9041-C1E8A0352E75}#SystemComponent
HKLM\SOFTWARE\Microsoft\Code Store Database\Distribution Units\{8A0DCBDB-6E20-489C-9041-C1E8A0352E75}#Installer
HKLM\SOFTWARE\Microsoft\Code Store Database\Distribution Units\{8A0DCBDB-6E20-489C-9041-C1E8A0352E75}\Contains
HKLM\SOFTWARE\Microsoft\Code Store Database\Distribution Units\{8A0DCBDB-6E20-489C-9041-C1E8A0352E75}\Contains\Files
HKLM\SOFTWARE\Microsoft\Code Store Database\Distribution Units\{8A0DCBDB-6E20-489C-9041-C1E8A0352E75}\Contains\Files#C:\WINDOWS\system32\WinATS.dll
HKLM\SOFTWARE\Microsoft\Code Store Database\Distribution Units\{8A0DCBDB-6E20-489C-9041-C1E8A0352E75}\DownloadInformation
HKLM\SOFTWARE\Microsoft\Code Store Database\Distribution Units\{8A0DCBDB-6E20-489C-9041-C1E8A0352E75}\DownloadInformation#CODEBASE
HKLM\SOFTWARE\Microsoft\Code Store Database\Distribution Units\{8A0DCBDB-6E20-489C-9041-C1E8A0352E75}\DownloadInformation#INF
HKLM\SOFTWARE\Microsoft\Code Store Database\Distribution Units\{8A0DCBDB-6E20-489C-9041-C1E8A0352E75}\InstalledVersion
HKLM\SOFTWARE\Microsoft\Code Store Database\Distribution Units\{8A0DCBDB-6E20-489C-9041-C1E8A0352E75}\InstalledVersion#LastModified
C:\WINDOWS\Downloaded Program Files\WinATS.inf

Adware.Tracking Cookie
C:\Documents and Settings\Owner_Emachine\Cookies\[email protected][1].txt
C:\Documents and Settings\Owner_Emachine\Cookies\[email protected][2].txt
C:\Documents and Settings\Owner_Emachine\Cookies\[email protected][2].txt
C:\Documents and Settings\Owner_Emachine\Cookies\[email protected][2].txt
C:\Documents and Settings\Owner_Emachine\Cookies\[email protected][2].txt
C:\Documents and Settings\Owner_Emachine\Cookies\[email protected][2].txt
C:\Documents and Settings\Owner_Emachine\Cookies\[email protected][1].txt
C:\Documents and Settings\Owner_Emachine\Cookies\[email protected][1].txt
C:\Documents and Settings\Owner_Emachine\Cookies\[email protected][2].txt
C:\Documents and Settings\Owner_Emachine\Cookies\[email protected][1].txt
C:\Documents and Settings\Owner_Emachine\Cookies\[email protected][2].txt
C:\Documents and Settings\Owner_Emachine\Cookies\[email protected][2].txt
C:\Documents and Settings\Owner_Emachine\Cookies\[email protected][1].txt
C:\Documents and Settings\Owner_Emachine\Cookies\[email protected][2].txt
C:\Documents and Settings\Owner_Emachine\Cookies\[email protected][2].txt
C:\Documents and Settings\Owner_Emachine\Cookies\[email protected][2].txt
C:\Documents and Settings\Owner_Emachine\Cookies\[email protected][1].txt
C:\Documents and Settings\Owner_Emachine\Cookies\[email protected][1].txt
C:\Documents and Settings\Owner_Emachine\Cookies\[email protected][1].txt
C:\Documents and Settings\Owner_Emachine\Cookies\[email protected][2].txt
C:\Documents and Settings\Owner_Emachine\Cookies\[email protected][1].txt
C:\Documents and Settings\Owner_Emachine\Cookies\[email protected][2].txt
C:\Documents and Settings\Owner_Emachine\Cookies\[email protected][1].txt
C:\Documents and Settings\Owner_Emachine\Cookies\[email protected][2].txt
C:\Documents and Settings\Owner_Emachine\Cookies\[email protected][2].txt
C:\Documents and Settings\Owner_Emachine\Cookies\[email protected][2].txt
C:\Documents and Settings\Owner_Emachine\Cookies\[email protected]server[2].txt
C:\Documents and Settings\Owner_Emachine\Cookies\[email protected][1].txt
C:\Documents and Settings\Owner_Emachine\Cookies\[email protected][2].txt
C:\Documents and Settings\Owner_Emachine\Cookies\[email protected][1].txt
C:\Documents and Settings\Owner_Emachine\Cookies\[email protected][1].txt
C:\Documents and Settings\Owner_Emachine\Cookies\[email protected][1].txt
C:\Documents and Settings\Owner_Emachine\Cookies\[email protected][1].txt
C:\Documents and Settings\Owner_Emachine\Cookies\[email protected][1].txt
C:\Documents and Settings\Owner_Emachine\Cookies\[email protected][1].txt
C:\Documents and Settings\Owner_Emachine\Cookies\[email protected][1].txt
C:\Documents and Settings\Owner_Emachine\Cookies\[email protected][3].txt
C:\Documents and Settings\Owner_Emachine\Cookies\[email protected][1].txt
C:\Documents and Settings\Owner_Emachine\Cookies\[email protected][2].txt
C:\Documents and Settings\Owner_Emachine\Cookies\[email protected]getrack[2].txt
C:\Documents and Settings\Owner_Emachine\Cookies\[email protected]b.hitbox[1].txt
C:\Documents and Settings\Owner_Emachine\Cookies\[email protected]ycom.122.2o7[1].txt
C:\Documents and Settings\Owner_Emachine\Cookies\[email protected][1].txt
C:\Documents and Settings\Owner_Emachine\Cookies\[email protected][1].txt
C:\Documents and Settings\Owner_Emachine\Cookies\[email protected][1].txt
C:\Documents and Settings\Owner_Emachine\Cookies\[email protected][1].txt
C:\Documents and Settings\Owner_Emachine\Cookies\[email protected][1].txt
C:\Documents and Settings\Owner_Emachine\Cookies\[email protected][1].txt
C:\Documents and Settings\Owner_Emachine\Cookies\[email protected][1].txt
C:\Documents and Settings\Owner_Emachine\Cookies\[email protected][3].txt
C:\Documents and Settings\Owner_Emachine\Cookies\[email protected][1].txt
C:\Documents and Settings\Owner_Emachine\Cookies\[email protected][2].txt
C:\Documents and Settings\Owner_Emachine\Cookies\[email protected][1].txt
C:\Documents and Settings\Owner_Emachine\Cookies\[email protected][2].txt
C:\Documents and Settings\Owner_Emachine\Cookies\[email protected][1].txt
C:\Documents and Settings\Owner_Emachine\Cookies\[email protected][2].txt
C:\Documents and Settings\Owner_Emachine\Cookies\[email protected][2].txt
C:\Documents and Settings\Owner_Emachine\Cookies\[email protected][1].txt
C:\Documents and Settings\Owner_Emachine\Cookies\[email protected][2].txt
C:\Documents and Settings\Owner_Emachine\Cookies\[email protected][2].txt
C:\Documents and Settings\Owner_Emachine\Cookies\[email protected][1].txt
C:\Documents and Settings\Owner_Emachine\Cookies\[email protected][1].txt
C:\Documents and Settings\Owner_Emachine\Cookies\[email protected][1].txt
C:\Documents and Settings\Owner_Emachine\Cookies\[email protected][2].txt
C:\Documents and Settings\Owner_Emachine\Cookies\[email protected][1].txt
C:\Documents and Settings\Owner_Emachine\Cookies\[email protected][2].txt
C:\Documents and Settings\Owner_Emachine\Cookies\[email protected][2].txt
C:\Documents and Settings\Owner_Emachine\Cookies\[email protected][1].txt
C:\Documents and Settings\Owner_Emachine\Cookies\[email protected][2].txt
C:\Documents and Settings\Owner_Emachine\Cookies\[email protected][1].txt
C:\Documents and Settings\Owner_Emachine\Cookies\[email protected][2].txt
C:\Documents and Settings\Owner_Emachine\Cookies\[email protected][2].txt
C:\Documents and Settings\Owner_Emachine\Cookies\[email protected][1].txt
C:\Documents and Settings\Owner_Emachine\Cookies\[email protected][1].txt
C:\Documents and Settings\Owner_Emachine\Cookies\[email protected][1].txt
C:\Documents and Settings\Owner_Emachine\Cookies\[email protected][1].txt
C:\Documents and Settings\Owner_Emachine\Cookies\[email protected][2].txt
C:\Documents and Settings\Owner_Emachine\Cookies\[email protected][1].txt
C:\Documents and Settings\Owner_Emachine\Cookies\[email protected][2].txt
C:\Documents and Settings\Owner_Emachine\Cookies\[email protected][1].txt
C:\Documents and Settings\Owner_Emachine\Cookies\[email protected][1].txt
C:\Documents and Settings\Owner_Emachine\Cookies\[email protected][2].txt
C:\Documents and Settings\Owner_Emachine\Cookies\[email protected][1].txt
C:\Documents and Settings\Owner_Emachine\Cookies\[email protected][1].txt
C:\Documents and Settings\Owner_Emachine\Cookies\[email protected][2].txt
C:\Documents and Settings\Owner_Emachine\Cookies\[email protected][1].txt
C:\Documents and Settings\Owner_Emachine\Cookies\[email protected]hg-groupernetworks.hitbox[2].txt
C:\Documents and Settings\Owner_Emachine\Cookies\[email protected][1].txt
C:\Documents and Settings\Owner_Emachine\Cookies\[email protected][1].txt
C:\Documents and Settings\Owner_Emachine\Cookies\[email protected][1].txt
C:\Documents and Settings\Owner_Emachine\Cookies\[email protected][2].txt
C:\Documents and Settings\Owner_Emachine\Cookies\[email protected][6].txt
C:\Documents and Settings\Owner_Emachine\Cookies\[email protected][2].txt
C:\Documents and Settings\Owner_Emachine\Cookies\[email protected][2].txt
C:\Documents and Settings\Owner_Emachine\Cookies\[email protected][2].txt
C:\Documents and Settings\Owner_Emachine\Cookies\[email protected][2].txt
C:\Documents and Settings\Owner_Emachine\Cookies\[email protected][1].txt
C:\Documents and Settings\Owner_Emachine\Cookies\[email protected][2].txt
C:\Documents and Settings\Owner_Emachine\Cookies\[email protected][1].txt
C:\Documents and Settings\Owner_Emachine\Cookies\[email protected][1].txt
C:\Documents and Settings\Owner_Emachine\Cookies\[email protected][2].txt
C:\Documents and Settings\Owner_Emachine\Cookies\[email protected][1].txt
C:\Documents and Settings\Owner_Emachine\Cookies\[email protected][1].txt
C:\Documents and Settings\Owner_Emachine\Cookies\[email protected][1].txt
C:\Documents and Settings\Owner_Emachine\Cookies\[email protected][1].txt
C:\Documents and Settings\Owner_Emachine\Cookies\[email protected][1].txt
C:\Documents and Settings\Owner_Emachine\Cookies\[email protected][1].txt
C:\Documents and Settings\Owner_Emachine\Cookies\[email protected][1].txt
C:\Documents and Settings\Owner_Emachine\Cookies\[email protected][1].txt
C:\Documents and Settings\Owner_Emachine\Cookies\[email protected][1].txt
C:\Documents and Settings\Owner_Emachine\Cookies\[email protected][1].txt
C:\Documents and Settings\Owner_Emachine\Cookies\[email protected][2].txt
C:\Documents and Settings\Owner_Emachine\Cookies\[email protected][2].txt
C:\Documents and Settings\Owner_Emachine\Cookies\[email protected][1].txt
C:\Documents and Settings\Owner_Emachine\Cookies\[email protected][1].txt
C:\Documents and Settings\Owner_Emachine\Cookies\[email protected][3].txt
C:\Documents and Settings\Owner_Emachine\Cookies\[email protected][2].txt
C:\Documents and Settings\Owner_Emachine\Cookies\[email protected][1].txt
C:\Documents and Settings\Owner_Emachine\Cookies\[email protected][1].txt
C:\Documents and Settings\Owner_Emachine\Cookies\[email protected][2].txt
C:\Documents and Settings\Owner_Emachine\Cookies\[email protected][2].txt
C:\Documents and Settings\Owner_Emachine\Cookies\[email protected][1].txt
C:\Documents and Settings\Owner_Emachine\Cookies\[email protected][1].txt
C:\Documents and Settings\Owner_Emachine\Cookies\[email protected][1].txt
C:\Documents and Settings\Owner_Emachine\Cookies\[email protected][1].txt
C:\Documents and Settings\Owner_Emachine\Cookies\[email protected][2].txt
C:\Documents and Settings\Owner_Emachine\Cookies\[email protected][1].txt

here is half of super anti spyware scan


----------



## cpuanswers (Sep 25, 2007)

C:\Documents and Settings\Owner_Emachine\Cookies\[email protected][1].txt
C:\Documents and Settings\Owner_Emachine\Cookies\[email protected][3].txt
C:\Documents and Settings\Owner_Emachine\Cookies\[email protected][2].txt
C:\Documents and Settings\Owner_Emachine\Cookies\[email protected][1].txt
C:\Documents and Settings\Owner_Emachine\Cookies\[email protected][2].txt
C:\Documents and Settings\Owner_Emachine\Cookies\[email protected][1].txt
C:\Documents and Settings\Owner_Emachine\Cookies\[email protected][1].txt
C:\Documents and Settings\Owner_Emachine\Cookies\[email protected][2].txt
C:\Documents and Settings\Owner_Emachine\Cookies\[email protected][2].txt
C:\Documents and Settings\Owner_Emachine\Cookies\[email protected][1].txt
C:\Documents and Settings\Owner_Emachine\Cookies\[email protected][1].txt
C:\Documents and Settings\Owner_Emachine\Cookies\[email protected][1].txt
C:\Documents and Settings\Owner_Emachine\Cookies\[email protected][1].txt
C:\Documents and Settings\Owner_Emachine\Cookies\[email protected][1].txt
C:\Documents and Settings\Owner_Emachine\Cookies\[email protected][1].txt
C:\Documents and Settings\Owner_Emachine\Cookies\[email protected][1].txt
C:\Documents and Settings\Owner_Emachine\Cookies\[email protected][2].txt
C:\Documents and Settings\Owner_Emachine\Cookies\[email protected][2].txt
C:\Documents and Settings\Owner_Emachine\Cookies\[email protected]=0_[3].txt
C:\Documents and Settings\Owner_Emachine\Cookies\[email protected][1].txt
C:\Documents and Settings\Owner_Emachine\Cookies\[email protected][1].txt
C:\Documents and Settings\Owner_Emachine\Cookies\[email protected][2].txt
C:\Documents and Settings\Owner_Emachine\Cookies\[email protected][1].txt
C:\Documents and Settings\Owner_Emachine\Cookies\[email protected][1].txt
C:\Documents and Settings\Owner_Emachine\Cookies\[email protected][2].txt
C:\Documents and Settings\Owner_Emachine\Cookies\[email protected][1].txt
C:\Documents and Settings\Owner_Emachine\Cookies\[email protected][2].txt
C:\Documents and Settings\Owner_Emachine\Cookies\[email protected][2].txt
C:\Documents and Settings\Owner_Emachine\Cookies\[email protected][1].txt
C:\Documents and Settings\Owner_Emachine\Cookies\[email protected][1].txt
C:\Documents and Settings\Owner_Emachine\Cookies\[email protected][1].txt
C:\Documents and Settings\Owner_Emachine\Cookies\[email protected][2].txt
C:\Documents and Settings\Owner_Emachine\Cookies\[email protected][1].txt
C:\Documents and Settings\Owner_Emachine\Cookies\[email protected][2].txt
C:\Documents and Settings\Owner_Emachine\Cookies\[email protected][2].txt
C:\Documents and Settings\Owner_Emachine\Cookies\[email protected][2].txt
C:\Documents and Settings\Owner_Emachine\Cookies\[email protected][2].txt
C:\Documents and Settings\Owner_Emachine\Cookies\[email protected][1].txt
C:\Documents and Settings\Owner_Emachine\Cookies\[email protected][2].txt
C:\Documents and Settings\Owner_Emachine\Cookies\[email protected][2].txt
C:\Documents and Settings\Owner_Emachine\Cookies\[email protected]_6l6d[1].txt
C:\Documents and Settings\Owner_Emachine\Cookies\[email protected];page=ecards[1].txt
C:\Documents and Settings\Owner_Emachine\Cookies\[email protected][2].txt
C:\Documents and Settings\Owner_Emachine\Cookies\[email protected][2].txt
C:\Documents and Settings\Owner_Emachine\Cookies\[email protected][3].txt
C:\Documents and Settings\Owner_Emachine\Cookies\[email protected][1].txt
C:\Documents and Settings\Owner_Emachine\Cookies\[email protected][1].txt
C:\Documents and Settings\Owner_Emachine\Cookies\[email protected][1].txt
C:\Documents and Settings\Owner_Emachine\Cookies\[email protected];page=ecards[1].txt
C:\Documents and Settings\Owner_Emachine\Cookies\[email protected][2].txt
C:\Documents and Settings\Owner_Emachine\Cookies\[email protected][1].txt
C:\Documents and Settings\Owner_Emachine\Cookies\[email protected][2].txt
C:\Documents and Settings\Owner_Emachine\Cookies\[email protected][3].txt
C:\Documents and Settings\Owner_Emachine\Cookies\[email protected][2].txt
C:\Documents and Settings\Owner_Emachine\Cookies\[email protected][2].txt
C:\Documents and Settings\Owner_Emachine\Cookies\[email protected][2].txt
C:\Documents and Settings\Owner_Emachine\Cookies\[email protected][1].txt
C:\Documents and Settings\Owner_Emachine\Cookies\[email protected][1].txt
C:\Documents and Settings\Owner_Emachine\Cookies\[email protected][1].txt
C:\Documents and Settings\Owner_Emachine\Cookies\[email protected][1].txt
C:\Documents and Settings\Owner_Emachine\Cookies\[email protected][1].txt
C:\Documents and Settings\Owner_Emachine\Cookies\[email protected][2].txt
C:\Documents and Settings\Owner_Emachine\Cookies\[email protected][2].txt
C:\Documents and Settings\Owner_Emachine\Cookies\[email protected][1].txt
C:\Documents and Settings\Owner_Emachine\Cookies\[email protected][2].txt
C:\Documents and Settings\Owner_Emachine\Cookies\[email protected][1].txt
C:\Documents and Settings\Owner_Emachine\Cookies\[email protected][1].txt
C:\Documents and Settings\Owner_Emachine\Cookies\[email protected][1].txt
C:\Documents and Settings\Owner_Emachine\Cookies\[email protected][1].txt
C:\Documents and Settings\Owner_Emachine\Cookies\[email protected][1].txt
C:\Documents and Settings\Owner_Emachine\Cookies\[email protected][2].txt
C:\Documents and Settings\Owner_Emachine\Cookies\[email protected][1].txt
C:\Documents and Settings\Owner_Emachine\Cookies\[email protected][1].txt
C:\Documents and Settings\Owner_Emachine\Cookies\[email protected][2].txt
C:\Documents and Settings\Owner_Emachine\Cookies\[email protected][1].txt
C:\Documents and Settings\Owner_Emachine\Cookies\[email protected][1].txt
C:\Documents and Settings\Owner_Emachine\Cookies\[email protected][1].txt
C:\Documents and Settings\Owner_Emachine\Cookies\[email protected][1].txt
C:\Documents and Settings\Owner_Emachine\Cookies\[email protected][1].txt
C:\Documents and Settings\Owner_Emachine\Cookies\[email protected][2].txt
C:\Documents and Settings\Owner_Emachine\Cookies\[email protected][2].txt
C:\Documents and Settings\Owner_Emachine\Cookies\[email protected][1].txt
C:\Documents and Settings\Owner_Emachine\Cookies\[email protected][2].txt
C:\Documents and Settings\Owner_Emachine\Cookies\[email protected][2].txt
C:\Documents and Settings\Owner_Emachine\Cookies\[email protected][1].txt
C:\Documents and Settings\Owner_Emachine\Cookies\[email protected][1].txt
C:\Documents and Settings\Owner_Emachine\Cookies\[email protected]=0[1].txt
C:\Documents and Settings\Owner_Emachine\Cookies\[email protected][1].txt
C:\Documents and Settings\Owner_Emachine\Cookies\[email protected][2].txt
C:\Documents and Settings\Owner_Emachine\Cookies\[email protected][1].txt
C:\Documents and Settings\Owner_Emachine\Cookies\[email protected][1].txt
C:\Documents and Settings\Owner_Emachine\Cookies\[email protected][1].txt
C:\Documents and Settings\Owner_Emachine\Cookies\[email protected][4].txt
C:\Documents and Settings\Owner_Emachine\Cookies\[email protected][1].txt
C:\Documents and Settings\Owner_Emachine\Cookies\[email protected][1].txt
C:\Documents and Settings\Owner_Emachine\Cookies\[email protected][1].txt
C:\Documents and Settings\Owner_Emachine\Cookies\[email protected][1].txt
C:\Documents and Settings\Owner_Emachine\Cookies\[email protected][2].txt
C:\Documents and Settings\Owner_Emachine\Cookies\[email protected][2].txt
C:\Documents and Settings\Owner_Emachine\Cookies\[email protected][1].txt
C:\Documents and Settings\Owner_Emachine\Cookies\[email protected][1].txt
C:\Documents and Settings\Owner_Emachine\Cookies\[email protected][2].txt
C:\Documents and Settings\Owner_Emachine\Cookies\[email protected][1].txt
C:\Documents and Settings\Owner_Emachine\Cookies\[email protected][1].txt
C:\Documents and Settings\Owner_Emachine\Cookies\[email protected][2].txt
C:\Documents and Settings\Owner_Emachine\Cookies\[email protected][1].txt
C:\Documents and Settings\Owner_Emachine\Cookies\[email protected][1].txt
C:\Documents and Settings\Owner_Emachine\Cookies\[email protected][2].txt
C:\Documents and Settings\Owner_Emachine\Cookies\[email protected][1].txt
C:\Documents and Settings\Owner_Emachine\Cookies\[email protected][1].txt
C:\Documents and Settings\Owner_Emachine\Cookies\[email protected][1].txt
C:\Documents and Settings\Owner_Emachine\Cookies\[email protected][1].txt
C:\Documents and Settings\Owner_Emachine\Cookies\[email protected][2].txt
C:\Documents and Settings\Owner_Emachine\Cookies\[email protected][2].txt
C:\Documents and Settings\Owner_Emachine\Cookies\[email protected][2].txt
C:\Documents and Settings\Owner_Emachine\Cookies\[email protected][2].txt
C:\Documents and Settings\Owner_Emachine\Cookies\[email protected][1].txt
C:\Documents and Settings\Owner_Emachine\Cookies\[email protected][1].txt
C:\Documents and Settings\Owner_Emachine\Cookies\[email protected][1].txt
C:\Documents and Settings\Owner_Emachine\Cookies\[email protected][1].txt
C:\Documents and Settings\Owner_Emachine\Cookies\[email protected][2].txt
C:\Documents and Settings\Owner_Emachine\Cookies\[email protected][1].txt
C:\Documents and Settings\Owner_Emachine\Cookies\[email protected][1].txt
C:\Documents and Settings\Owner_Emachine\Cookies\[email protected][2].txt
C:\Documents and Settings\Owner_Emachine\Cookies\[email protected][1].txt
C:\Documents and Settings\Owner_Emachine\Cookies\[email protected][1].txt
C:\Documents and Settings\Owner_Emachine\Cookies\[email protected][1].txt
C:\Documents and Settings\Owner_Emachine\Cookies\[email protected][1].txt
C:\Documents and Settings\Owner_Emachine\Cookies\[email protected][2].txt
C:\Documents and Settings\Owner_Emachine\Cookies\[email protected][1].txt
C:\Documents and Settings\Owner_Emachine\Cookies\[email protected][2].txt
C:\Documents and Settings\Owner_Emachine\Cookies\[email protected][2].txt
C:\Documents and Settings\Owner_Emachine\Cookies\[email protected][1].txt
C:\Documents and Settings\Owner_Emachine\Cookies\[email protected][1].txt
C:\Documents and Settings\Owner_Emachine\Cookies\[email protected][2].txt
C:\Documents and Settings\Owner_Emachine\Cookies\[email protected][1].txt
C:\Documents and Settings\Owner_Emachine\Cookies\[email protected][1].txt
C:\Documents and Settings\Owner_Emachine\Cookies\[email protected][2].txt
C:\Documents and Settings\Owner_Emachine\Cookies\[email protected][1].txt
C:\Documents and Settings\Owner_Emachine\Cookies\[email protected]=0_[2].txt
C:\Documents and Settings\Owner_Emachine\Cookies\[email protected][1].txt
C:\Documents and Settings\Owner_Emachine\Cookies\[email protected][1].txt
C:\Documents and Settings\Owner_Emachine\Cookies\[email protected][2].txt
C:\Documents and Settings\Owner_Emachine\Cookies\[email protected][2].txt
C:\Documents and Settings\Owner_Emachine\Cookies\[email protected][1].txt
C:\Documents and Settings\Owner_Emachine\Cookies\[email protected][1].txt
C:\Documents and Settings\Owner_Emachine\Cookies\[email protected][1].txt
C:\Documents and Settings\Owner_Emachine\Cookies\[email protected][2].txt
C:\Documents and Settings\Owner_Emachine\Cookies\[email protected][2].txt
C:\Documents and Settings\Owner_Emachine\Cookies\[email protected][1].txt
C:\Documents and Settings\Owner_Emachine\Cookies\[email protected][2].txt
C:\Documents and Settings\Owner_Emachine\Cookies\[email protected][1].txt
C:\Documents and Settings\Owner_Emachine\Cookies\[email protected][1].txt
C:\Documents and Settings\Owner_Emachine\Cookies\[email protected][1].txt
C:\Documents and Settings\Owner_Emachine\Cookies\[email protected][1].txt
C:\Documents and Settings\Owner_Emachine\Cookies\[email protected][2].txt
C:\Documents and Settings\Owner_Emachine\Cookies\[email protected][1].txt
C:\Documents and Settings\Owner_Emachine\Cookies\[email protected][2].txt
C:\Documents and Settings\Owner_Emachine\Cookies\[email protected][1].txt
C:\Documents and Settings\Owner_Emachine\Cookies\[email protected]exsearchcom[1].txt
C:\Documents and Settings\Owner_Emachine\Cookies\[email protected][1].txt
C:\Documents and Settings\Owner_Emachine\Cookies\[email protected][2].txt
C:\Documents and Settings\Owner_Emachine\Cookies\[email protected][1].txt
C:\Documents and Settings\Owner_Emachine\Cookies\[email protected][2].txt
C:\Documents and Settings\Owner_Emachine\Cookies\[email protected][2].txt
C:\Documents and Settings\Owner_Emachine\Cookies\[email protected][2].txt
C:\Documents and Settings\Owner_Emachine\Cookies\[email protected][2].txt
C:\Documents and Settings\Owner_Emachine\Cookies\[email protected][1].txt
C:\Documents and Settings\Owner_Emachine\Cookies\[email protected][2].txt
C:\Documents and Settings\Owner_Emachine\Cookies\[email protected][2].txt
C:\Documents and Settings\Owner_Emachine\Cookies\[email protected][2].txt
C:\Documents and Settings\Owner_Emachine\Cookies\[email protected][2].txt
C:\Documents and Settings\Owner_Emachine\Cookies\[email protected][1].txt
C:\Documents and Settings\Owner_Emachine\Cookies\[email protected][1].txt
C:\Documents and Settings\Owner_Emachine\Cookies\[email protected][1].txt
C:\Documents and Settings\Owner_Emachine\Cookies\[email protected][1].txt
C:\Documents and Settings\Owner_Emachine\Cookies\[email protected][1].txt
C:\Documents and Settings\Owner_Emachine\Cookies\[email protected][1].txt
C:\Documents and Settings\Owner_Emachine\Cookies\[email protected][2].txt
C:\Documents and Settings\Owner_Emachine\Cookies\[email protected][1].txt
C:\Documents and Settings\Owner_Emachine\Cookies\[email protected][2].txt
C:\Documents and Settings\Owner_Emachine\Cookies\[email protected][2].txt
C:\Documents and Settings\Owner_Emachine\Cookies\[email protected][1].txt
C:\Documents and Settings\Owner_Emachine\Cookies\[email protected][1].txt
C:\Documents and Settings\Owner_Emachine\Cookies\[email protected][2].txt
C:\Documents and Settings\Owner_Emachine\Cookies\[email protected][1].txt
C:\Documents and Settings\Owner_Emachine\Cookies\[email protected][8].txt
C:\Documents and Settings\Owner_Emachine\Cookies\[email protected][6].txt
C:\Documents and Settings\Owner_Emachine\Cookies\[email protected][1].txt
C:\Documents and Settings\Owner_Emachine\Cookies\[email protected][2].txt
C:\Documents and Settings\Owner_Emachine\Cookies\[email protected][2].txt
C:\Documents and Settings\Owner_Emachine\Cookies\[email protected][1].txt
C:\Documents and Settings\Owner_Emachine\Cookies\[email protected][1].txt
C:\Documents and Settings\Owner_Emachine\Cookies\[email protected][1].txt
C:\Documents and Settings\Owner_Emachine\Cookies\[email protected]3342[1].txt
C:\Documents and Settings\Owner_Emachine\Cookies\[email protected]tertainment.hitbox[2].txt
C:\Documents and Settings\Owner_Emachine\Cookies\[email protected][1].txt
C:\Documents and Settings\Owner_Emachine\Cookies\[email protected][1].txt
C:\Documents and Settings\Owner_Emachine\Cookies\[email protected][1].txt
C:\Documents and Settings\Owner_Emachine\Cookies\[email protected]=1_[3].txt
C:\Documents and Settings\Owner_Emachine\Cookies\[email protected][1].txt
C:\Documents and Settings\Owner_Emachine\Cookies\[email protected][1].txt
C:\Documents and Settings\Owner_Emachine\Cookies\[email protected][2].txt
C:\Documents and Settings\Owner_Emachine\Cookies\[email protected][2].txt
C:\Documents and Settings\Owner_Emachine\Cookies\[email protected][1].txt
C:\Documents and Settings\Owner_Emachine\Cookies\[email protected][7].txt
C:\Documents and Settings\Owner_Emachine\Cookies\[email protected][2].txt
C:\Documents and Settings\Owner_Emachine\Cookies\[email protected][1].txt
C:\Documents and Settings\Owner_Emachine\Cookies\[email protected][2].txt
C:\Documents and Settings\Owner_Emachine\Cookies\[email protected][1].txt
C:\Documents and Settings\Owner_Emachine\Cookies\[email protected][2].txt
C:\Documents and Settings\Owner_Emachine\Cookies\[email protected][2].txt
C:\Documents and Settings\Owner_Emachine\Cookies\[email protected][3].txt
C:\Documents and Settings\Owner_Emachine\Cookies\[email protected][2].txt
C:\Documents and Settings\Owner_Emachine\Cookies\[email protected][4].txt
C:\Documents and Settings\Owner_Emachine\Cookies\[email protected][1].txt
C:\Documents and Settings\Owner_Emachine\Cookies\[email protected][1].txt
C:\Documents and Settings\Owner_Emachine\Cookies\[email protected][1].txt
C:\Documents and Settings\Owner_Emachine\Cookies\[email protected][2].txt
C:\Documents and Settings\Owner_Emachine\Cookies\[email protected][2].txt
C:\Documents and Settings\Owner_Emachine\Cookies\[email protected][1].txt
C:\Documents and Settings\Owner_Emachine\Cookies\[email protected][1].txt
C:\Documents and Settings\Owner_Emachine\Cookies\[email protected][2].txt
C:\Documents and Settings\Owner_Emachine\Cookies\[email protected][2].txt
C:\Documents and Settings\Owner_Emachine\Cookies\[email protected][1].txt
C:\Documents and Settings\Owner_Emachine\Cookies\[email protected][3].txt
C:\Documents and Settings\Owner_Emachine\Cookies\[email protected][1].txt
C:\Documents and Settings\Owner_Emachine\Cookies\[email protected][3].txt
C:\Documents and Settings\Owner_Emachine\Cookies\[email protected][2].txt
C:\Documents and Settings\Owner_Emachine\Cookies\[email protected][3].txt
C:\Documents and Settings\Owner_Emachine\Cookies\[email protected][1].txt

and the other half


----------



## cpuanswers (Sep 25, 2007)

now I already did the killbox thing in safe mode but it said c:\windows\system32\MH2hQ12l.exe didnt exist but c:\WINNT\temp did work and got deleted just as it was supposed to now do I do the final hijack scan?


----------



## MFDnNC (Sep 7, 2004)

Yes hijack log pls


----------



## cpuanswers (Sep 25, 2007)

Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 5:14:58 PM, on 9/26/2007
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Yahoo!\Antivirus\ISafe.exe
C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe
C:\WINDOWS\system32\HPZipm12.exe
C:\Program Files\Digital Media Reader\readericon45G.exe
C:\WINDOWS\RTHDCPL.EXE
C:\Program Files\HP\HP Software Update\HPWuSchd2.exe
C:\PROGRA~1\Yahoo!\browser\ybrwicon.exe
C:\Program Files\Common Files\New Boundary\PrismXL\PRISMXL.SYS
C:\PROGRA~1\SBCLIG~1\SMARTB~1\MotiveSB.exe
C:\Program Files\QuickTime\qttask.exe
C:\PROGRA~1\Yahoo!\YOP\yop.exe
C:\Program Files\Yahoo!\Antivirus\CAVTray.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Yahoo!\Antivirus\CAVRID.exe
C:\Program Files\Yahoo!\Search Protection\SearchProtection.exe
C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
C:\Program Files\Messenger\msmsgs.exe
C:\PROGRA~1\Yahoo!\browser\ycommon.exe
C:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe
C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe
C:\Program Files\Nikon\PictureProject\NkbMonitor.exe
C:\Program Files\Yahoo!\Antivirus\VetMsg.exe
C:\Program Files\Yahoo!\Yahoo! Music Jukebox\ymetray.exe
C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe
C:\WINDOWS\system32\VirtualExpander\VirtualExpander.exe
C:\Program Files\HP\Digital Imaging\bin\hpqSTE08.exe
C:\WINDOWS\system32\wuauclt.exe
C:\PROGRA~1\Yahoo!\MESSEN~1\YAHOOM~1.EXE
C:\Program Files\Internet Explorer\IEXPLORE.EXE
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe

R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.gateway.com/g/startpage.html?Ch=Retail&Br=EM&Loc=ENG_US&Sys=DTP&M=T3508
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar = http://red.clientapps.yahoo.com/cus.../sbcydsl/*http://www.yahoo.com/search/ie.html
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://red.clientapps.yahoo.com/customize/ie/defaults/sp/sbcydsl/*http://www.yahoo.com
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.gateway.com/g/startpage.html?Ch=Retail&Br=EM&Loc=ENG_US&Sys=DTP&M=T3508
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = 127.0.0.1;<local>
R3 - URLSearchHook: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn1\yt.dll
O2 - BHO: &Yahoo! Toolbar Helper - {02478D38-C3F9-4EFB-9B51-7695ECA05670} - C:\Program Files\Yahoo!\Companion\Installs\cpn1\yt.dll
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
O2 - BHO: Yahoo! IE Services Button - {5BAB4B5B-68BC-4B02-94D6-2FC0DE4A7897} - C:\PROGRA~1\Yahoo!\common\yiesrvc.dll
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar2.dll
O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\2.0.301.7164\swg.dll
O2 - BHO: CBrowserHelperObject Object - {CA6319C0-31B7-401E-A518-A07C3DB8F777} - c:\windows\system32\BAE.dll
O2 - BHO: SidebarAutoLaunch Class - {F2AA9440-6328-4933-B7C9-A6CCDF9CBF6D} - C:\Program Files\Yahoo!\browser\YSidebarIEBHO.dll
O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar2.dll
O3 - Toolbar: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn1\yt.dll
O4 - HKLM\..\Run: [Google Desktop Search] "C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe" /startup
O4 - HKLM\..\Run: [readericon] C:\Program Files\Digital Media Reader\readericon45G.exe
O4 - HKLM\..\Run: [RTHDCPL] RTHDCPL.EXE
O4 - HKLM\..\Run: [Recguard] %WINDIR%\SMINST\RECGUARD.EXE
O4 - HKLM\..\Run: [HP Software Update] C:\Program Files\HP\HP Software Update\HPWuSchd2.exe
O4 - HKLM\..\Run: [YBrowser] C:\PROGRA~1\Yahoo!\browser\ybrwicon.exe
O4 - HKLM\..\Run: [Motive SmartBridge] C:\PROGRA~1\SBCLIG~1\SMARTB~1\MotiveSB.exe
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [YOP] C:\PROGRA~1\Yahoo!\YOP\yop.exe /autostart
O4 - HKLM\..\Run: [CaAvTray] "C:\Program Files\Yahoo!\Antivirus\CAVTray.exe"
O4 - HKLM\..\Run: [CAVRID] "C:\Program Files\Yahoo!\Antivirus\CAVRID.exe"
O4 - HKLM\..\Run: [YSearchProtection] "C:\Program Files\Yahoo!\Search Protection\SearchProtection.exe"
O4 - HKCU\..\Run: [swg] C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
O4 - HKCU\..\Run: [Yahoo! Pager] "C:\PROGRA~1\Yahoo!\MESSEN~1\YAHOOM~1.EXE" -quiet
O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
O4 - HKCU\..\Run: [AROReminder] C:\Program Files\Advanced Registry Optimizer\aro.exe -rem
O4 - HKCU\..\Run: [YSearchProtection] C:\Program Files\Yahoo!\Search Protection\SearchProtection.exe
O4 - HKCU\..\Run: [SUPERAntiSpyware] C:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe
O4 - HKUS\S-1-5-18\..\Run: [Power2GoExpress] NA (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [Power2GoExpress] NA (User 'Default user')
O4 - Startup: VirtualExpander.lnk = C:\WINDOWS\system32\VirtualExpander\VirtualExpander.exe
O4 - Global Startup: HP Digital Imaging Monitor.lnk = C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe
O4 - Global Startup: NkbMonitor.exe.lnk = C:\Program Files\Nikon\PictureProject\NkbMonitor.exe
O4 - Global Startup: ymetray.lnk = C:\Program Files\Yahoo!\Yahoo! Music Jukebox\ymetray.exe
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
O9 - Extra button: AT&T Yahoo! Services - {5BAB4B5B-68BC-4B02-94D6-2FC0DE4A7897} - C:\PROGRA~1\Yahoo!\common\yiesrvc.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL
O9 - Extra button: Real.com - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - C:\WINDOWS\system32\Shdocvw.dll
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O16 - DPF: {30528230-99f7-4bb4-88d8-fa1d4f56a2ab} (Installation Support) - C:\Program Files\Yahoo!\Common\Yinsthelper2007261.dll
O16 - DPF: {77E32299-629F-43C6-AB77-6A1E6D7663F6} (Groove Control) - http://www.nick.com/common/groove/gx/GrooveAX27.cab
O16 - DPF: {BB383206-6DA1-4E80-B62A-3DF950FCC697} (Create & Print ActiveX Plug-in) - http://ak.imgag.com/imgag/cp/install/AxCtp2.cab
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - https://fpdownload.macromedia.com/pub/shockwave/cabs/flash/swflash.cab
O20 - AppInit_DLLs: C:\PROGRA~1\Google\GOOGLE~1\GOEC62~1.DLL
O20 - Winlogon Notify: !SASWinLogon - C:\Program Files\SUPERAntiSpyware\SASWINLO.dll
O20 - Winlogon Notify: vtsqo - C:\WINDOWS\
O23 - Service: Ati HotKey Poller - ATI Technologies Inc. - C:\WINDOWS\system32\Ati2evxx.exe
O23 - Service: ATI Smart - Unknown owner - C:\WINDOWS\system32\ati2sgag.exe
O23 - Service: CAISafe - Computer Associates International, Inc. - C:\Program Files\Yahoo!\Antivirus\ISafe.exe
O23 - Service: GoogleDesktopManager - Google - C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe
O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: Pml Driver HPZ12 - HP - C:\WINDOWS\system32\HPZipm12.exe
O23 - Service: PrismXL - New Boundary Technologies, Inc. - C:\Program Files\Common Files\New Boundary\PrismXL\PRISMXL.SYS
O23 - Service: VET Message Service (VETMSGNT) - Computer Associates International, Inc. - C:\Program Files\Yahoo!\Antivirus\VetMsg.exe
O23 - Service: YPCService - Yahoo! Inc. - C:\WINDOWS\system32\YPCSER~1.EXE

--
End of file - 8576 bytes

ok here is the hijack this log


----------



## MFDnNC (Sep 7, 2004)

Fix this with hijack

O20 - Winlogon Notify: vtsqo - C:\WINDOWS\

How are things now??


----------



## cpuanswers (Sep 25, 2007)

my cpu is going faster now and ok ill fix that


----------



## cpuanswers (Sep 25, 2007)

ok here is the Logfile of hijack this
Trend Micro HijackThis v2.0.2
Scan saved at 5:24:05 PM, on 9/26/2007
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe
C:\Program Files\Digital Media Reader\readericon45G.exe
C:\WINDOWS\RTHDCPL.EXE
C:\Program Files\Yahoo!\Antivirus\ISafe.exe
C:\Program Files\HP\HP Software Update\HPWuSchd2.exe
C:\PROGRA~1\Yahoo!\browser\ybrwicon.exe
C:\PROGRA~1\SBCLIG~1\SMARTB~1\MotiveSB.exe
C:\Program Files\QuickTime\qttask.exe
C:\PROGRA~1\Yahoo!\YOP\yop.exe
C:\WINDOWS\system32\HPZipm12.exe
C:\Program Files\Yahoo!\Antivirus\CAVTray.exe
C:\Program Files\Yahoo!\Antivirus\CAVRID.exe
C:\Program Files\Common Files\New Boundary\PrismXL\PRISMXL.SYS
C:\Program Files\Yahoo!\Search Protection\SearchProtection.exe
C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
C:\Program Files\Messenger\msmsgs.exe
C:\PROGRA~1\Yahoo!\browser\ycommon.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe
C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe
C:\Program Files\Nikon\PictureProject\NkbMonitor.exe
C:\Program Files\Yahoo!\Yahoo! Music Jukebox\ymetray.exe
C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe
C:\Program Files\Yahoo!\Antivirus\VetMsg.exe
C:\PROGRA~1\Yahoo!\MESSEN~1\ymsgr_tray.exe
C:\WINDOWS\system32\VirtualExpander\VirtualExpander.exe
C:\Program Files\HP\Digital Imaging\bin\hpqSTE08.exe
C:\WINDOWS\system32\wuauclt.exe
C:\WINDOWS\system32\wuauclt.exe
C:\Program Files\Internet Explorer\IEXPLORE.EXE
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe

R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.gateway.com/g/startpage.html?Ch=Retail&Br=EM&Loc=ENG_US&Sys=DTP&M=T3508
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar = http://red.clientapps.yahoo.com/cus.../sbcydsl/*http://www.yahoo.com/search/ie.html
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://red.clientapps.yahoo.com/customize/ie/defaults/sp/sbcydsl/*http://www.yahoo.com
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.gateway.com/g/startpage.html?Ch=Retail&Br=EM&Loc=ENG_US&Sys=DTP&M=T3508
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = 127.0.0.1;<local>
R3 - URLSearchHook: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn1\yt.dll
O2 - BHO: &Yahoo! Toolbar Helper - {02478D38-C3F9-4EFB-9B51-7695ECA05670} - C:\Program Files\Yahoo!\Companion\Installs\cpn1\yt.dll
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
O2 - BHO: Yahoo! IE Services Button - {5BAB4B5B-68BC-4B02-94D6-2FC0DE4A7897} - C:\PROGRA~1\Yahoo!\common\yiesrvc.dll
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar2.dll
O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\2.0.301.7164\swg.dll
O2 - BHO: CBrowserHelperObject Object - {CA6319C0-31B7-401E-A518-A07C3DB8F777} - c:\windows\system32\BAE.dll
O2 - BHO: SidebarAutoLaunch Class - {F2AA9440-6328-4933-B7C9-A6CCDF9CBF6D} - C:\Program Files\Yahoo!\browser\YSidebarIEBHO.dll
O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar2.dll
O3 - Toolbar: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn1\yt.dll
O4 - HKLM\..\Run: [Google Desktop Search] "C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe" /startup
O4 - HKLM\..\Run: [readericon] C:\Program Files\Digital Media Reader\readericon45G.exe
O4 - HKLM\..\Run: [RTHDCPL] RTHDCPL.EXE
O4 - HKLM\..\Run: [Recguard] %WINDIR%\SMINST\RECGUARD.EXE
O4 - HKLM\..\Run: [HP Software Update] C:\Program Files\HP\HP Software Update\HPWuSchd2.exe
O4 - HKLM\..\Run: [YBrowser] C:\PROGRA~1\Yahoo!\browser\ybrwicon.exe
O4 - HKLM\..\Run: [Motive SmartBridge] C:\PROGRA~1\SBCLIG~1\SMARTB~1\MotiveSB.exe
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [YOP] C:\PROGRA~1\Yahoo!\YOP\yop.exe /autostart
O4 - HKLM\..\Run: [CaAvTray] "C:\Program Files\Yahoo!\Antivirus\CAVTray.exe"
O4 - HKLM\..\Run: [CAVRID] "C:\Program Files\Yahoo!\Antivirus\CAVRID.exe"
O4 - HKLM\..\Run: [YSearchProtection] "C:\Program Files\Yahoo!\Search Protection\SearchProtection.exe"
O4 - HKCU\..\Run: [swg] C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
O4 - HKCU\..\Run: [Yahoo! Pager] "C:\PROGRA~1\Yahoo!\MESSEN~1\YAHOOM~1.EXE" -quiet
O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
O4 - HKCU\..\Run: [AROReminder] C:\Program Files\Advanced Registry Optimizer\aro.exe -rem
O4 - HKCU\..\Run: [YSearchProtection] C:\Program Files\Yahoo!\Search Protection\SearchProtection.exe
O4 - HKCU\..\Run: [SUPERAntiSpyware] C:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe
O4 - HKUS\S-1-5-18\..\Run: [Power2GoExpress] NA (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [Power2GoExpress] NA (User 'Default user')
O4 - Startup: VirtualExpander.lnk = C:\WINDOWS\system32\VirtualExpander\VirtualExpander.exe
O4 - Global Startup: HP Digital Imaging Monitor.lnk = C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe
O4 - Global Startup: NkbMonitor.exe.lnk = C:\Program Files\Nikon\PictureProject\NkbMonitor.exe
O4 - Global Startup: ymetray.lnk = C:\Program Files\Yahoo!\Yahoo! Music Jukebox\ymetray.exe
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
O9 - Extra button: AT&T Yahoo! Services - {5BAB4B5B-68BC-4B02-94D6-2FC0DE4A7897} - C:\PROGRA~1\Yahoo!\common\yiesrvc.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL
O9 - Extra button: Real.com - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - C:\WINDOWS\system32\Shdocvw.dll
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O16 - DPF: {30528230-99f7-4bb4-88d8-fa1d4f56a2ab} (Installation Support) - C:\Program Files\Yahoo!\Common\Yinsthelper2007261.dll
O16 - DPF: {77E32299-629F-43C6-AB77-6A1E6D7663F6} (Groove Control) - http://www.nick.com/common/groove/gx/GrooveAX27.cab
O16 - DPF: {BB383206-6DA1-4E80-B62A-3DF950FCC697} (Create & Print ActiveX Plug-in) - http://ak.imgag.com/imgag/cp/install/AxCtp2.cab
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - https://fpdownload.macromedia.com/pub/shockwave/cabs/flash/swflash.cab
O20 - AppInit_DLLs: C:\PROGRA~1\Google\GOOGLE~1\GOEC62~1.DLL
O20 - Winlogon Notify: !SASWinLogon - C:\Program Files\SUPERAntiSpyware\SASWINLO.dll
O23 - Service: Ati HotKey Poller - ATI Technologies Inc. - C:\WINDOWS\system32\Ati2evxx.exe
O23 - Service: ATI Smart - Unknown owner - C:\WINDOWS\system32\ati2sgag.exe
O23 - Service: CAISafe - Computer Associates International, Inc. - C:\Program Files\Yahoo!\Antivirus\ISafe.exe
O23 - Service: GoogleDesktopManager - Google - C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe
O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: Pml Driver HPZ12 - HP - C:\WINDOWS\system32\HPZipm12.exe
O23 - Service: PrismXL - New Boundary Technologies, Inc. - C:\Program Files\Common Files\New Boundary\PrismXL\PRISMXL.SYS
O23 - Service: VET Message Service (VETMSGNT) - Computer Associates International, Inc. - C:\Program Files\Yahoo!\Antivirus\VetMsg.exe
O23 - Service: YPCService - Yahoo! Inc. - C:\WINDOWS\system32\YPCSER~1.EXE

--
End of file - 8567 bytes
log


----------



## MFDnNC (Sep 7, 2004)

Clean








If you feel its is fixed mark it solved via Thread Tools above

Clear restore points  heres how

http://service1.symantec.com/SUPPOR...2001111912274039?OpenDocument&src=sec_doc_nam

You will turn them off  boot  turn them on

This clears infected restore points and sets a new, clean one.


----------



## cpuanswers (Sep 25, 2007)

thank you for all the help I really appreciate it


----------

