Malwarebytes' Anti-Malware 1.40
Database version: 2769
Windows 5.1.2600 Service Pack 2
9/9/2009 10:09:08 PM
mbam-log-2009-09-09 (22-09-08).txt
Scan type: Quick Scan
Objects scanned: 105789
Time elapsed: 10 minute(s), 0 second(s)
Memory Processes Infected: 0
Memory Modules Infected: 0
Registry Keys Infected: 0
Registry Values Infected: 0
Registry Data Items Infected: 0
Folders Infected: 0
Files Infected: 0
Memory Processes Infected:
(No malicious items detected)
Memory Modules Infected:
(No malicious items detected)
Registry Keys Infected:
(No malicious items detected)
Registry Values Infected:
(No malicious items detected)
Registry Data Items Infected:
(No malicious items detected)
Folders Infected:
(No malicious items detected)
Files Infected:
(No malicious items detected)
——————————————————————————–
KASPERSKY ONLINE SCANNER 7.0: scan report
Thursday, September 10, 2009
Operating system: Microsoft Windows XP Professional Service Pack 2 (build 2600)
Kaspersky Online Scanner version: 7.0.26.13
Last database update: Thursday, September 10, 2009 03:23:28
Records in database: 2768520
——————————————————————————–
Scan settings:
scan using the following database: extended
Scan archives: yes
Scan e-mail databases: yes
Scan area - My Computer:
C:\
D:\
E:\
Scan statistics:
Objects scanned: 74928
Threats found: 3
Infected objects found: 6
Suspicious objects found: 0
Scan duration: 03:17:03
File name / Threat / Threats count
C:\Documents and Settings\All Users\Application Data\Symantec\Symantec Endpoint Protection\Quarantine\0FB00000.VBN Infected: Trojan.Win32.Tdss.ajeo 1
C:\Documents and Settings\All Users\Application Data\Symantec\Symantec Endpoint Protection\Quarantine\0FB00001.VBN Infected: Trojan.Win32.Tdss.anrc 1
C:\Qoobox\Quarantine\C\WINDOWS\system32\UACbdqvxrgilt.dll.vir Infected: Packed.Win32.TDSS.y 1
C:\Qoobox\Quarantine\C\WINDOWS\system32\UACsdjdwnrvkk.dll.vir Infected: Packed.Win32.TDSS.y 1
C:\Qoobox\Quarantine\C\WINDOWS\system32\UACwbuoxbqjnk.dll.vir Infected: Packed.Win32.TDSS.y 1
C:\Qoobox\Quarantine\C\WINDOWS\system32\wscsvc32.exe.vir Infected: Packed.Win32.TDSS.y 1
Selected area has been scanned.
DDS (Ver_09-06-26.01) - NTFSx86
Run by [removed] at 2:10:43.05 on Thu 09/10/2009
Internet Explorer: 7.0.5730.13 BrowserJavaVersion: 1.6.0_16
Microsoft Windows XP Professional 5.1.2600.2.1252.1.1033.18.502.182 [GMT -4:00]
AV: Symantec Endpoint Protection *On-access scanning enabled* (Updated) {FB06448E-52B8-493A-90F3-E43226D3305C}
============== Running Processes ===============
C:\WINDOWS\system32\svchost -k DcomLaunch
svchost.exe
C:\WINDOWS\System32\svchost.exe -k netsvcs
C:\WINDOWS\system32\svchost.exe -k WudfServiceGroup
C:\Program Files\Symantec\Symantec Endpoint Protection\Smc.exe
svchost.exe
svchost.exe
C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe
C:\WINDOWS\System32\WLTRYSVC.EXE
C:\WINDOWS\System32\bcmwltry.exe
C:\WINDOWS\system32\spoolsv.exe
svchost.exe
C:\Program Files\Common Files\Creative Labs Shared\Service\CreativeLicensing.exe
C:\WINDOWS\eHome\ehRecvr.exe
C:\WINDOWS\eHome\ehSched.exe
C:\Program Files\Common Files\LogiShrd\LVCOMSER\LVComSer.exe
C:\Program Files\Common Files\LogiShrd\LVMVFM\LVPrcSrv.exe
C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE
C:\Program Files\Microsoft SQL Server\MSSQL$MICROSOFTSMLBIZ\Binn\sqlservr.exe
svchost.exe
C:\WINDOWS\system32\svchost.exe -k imgsvc
C:\Program Files\Symantec\Symantec Endpoint Protection\Rtvscan.exe
C:\Program Files\Canon\CAL\CALMAIN.exe
C:\WINDOWS\system32\dllhost.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Common Files\LogiShrd\LVCOMSER\LVComSer.exe
C:\Program Files\Symantec\Symantec Endpoint Protection\SmcGui.exe
C:\WINDOWS\ehome\ehtray.exe
C:\WINDOWS\system32\igfxpers.exe
C:\WINDOWS\system32\igfxsrvc.exe
C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
C:\WINDOWS\system32\WLTRAY.exe
C:\WINDOWS\stsystra.exe
C:\Program Files\Dell\Media Experience\DMXLauncher.exe
C:\WINDOWS\eHome\ehmsas.exe
C:\Program Files\Creative\Mixer\CTSVolFE.exe
C:\Program Files\Common Files\InstallShield\UpdateService\issch.exe
C:\WINDOWS\System32\DLA\DLACTRLW.EXE
C:\Program Files\Common Files\Real\Update_OB\realsched.exe
C:\Program Files\Common Files\LogiShrd\LComMgr\Communications_Helper.exe
C:\Program Files\Logitech\QuickCam\Quickcam.exe
C:\Program Files\Messenger\msmsgs.exe
C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
C:\Program Files\Digital Line Detect\DLG.exe
C:\Program Files\Hewlett-Packard\Digital Imaging\bin\hpohmr08.exe
C:\Program Files\Hewlett-Packard\Digital Imaging\bin\hpotdd01.exe
C:\Program Files\Logitech\Desktop Messenger\8876480\Program\LogitechDesktopMessenger.exe
C:\Program Files\Microsoft SQL Server\80\Tools\Binn\sqlmangr.exe
C:\Program Files\Hewlett-Packard\Digital Imaging\bin\hpoevm08.exe
C:\Program Files\Hewlett-Packard\Digital Imaging\Bin\hpoSTS08.exe
C:\Program Files\Common Files\Logishrd\LQCVFX\COCIManager.exe
C:\WINDOWS\System32\svchost.exe -k HTTPFilter
C:\WINDOWS\system32\wuauclt.exe
C:\Program Files\Mozilla Firefox\firefox.exe
c:\program files\logitech\quickcam\lu\lulnchr.exe
c:\program files\logitech\quickcam\lu\LogitechUpdate.exe
C:\Program Files\Java\jre6\bin\jqs.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Java\jre6\bin\java.exe
C:\Documents and Settings\Jamie\Local Settings\temp\jkos-Jamie\binaries\ScanningProcess.exe
C:\Documents and Settings\Jamie\Desktop\dds.scr
============== Pseudo HJT Report ===============
uStart Page =
https://home.nyu.edu/
uSearchMigratedDefaultURL = hxxp://www.google.com/search?q={searchTerms}&sourceid=ie7&rls=com.microsoft:en-US&ie=utf8&oe=utf8
uInternet Connection Wizard,ShellNext = iexplore
uSearchURL,(Default) = hxxp://www.google.com/search?q=%s
BHO: Adobe PDF Reader Link Helper: {06849e9f-c8d7-4d59-b87d-784b7d6be0b3} - c:\program files\adobe\acrobat 7.0\activex\AcroIEHelper.dll
BHO: DriveLetterAccess: {5ca3d70e-1895-11cf-8e15-001234567890} - c:\windows\system32\dla\DLASHX_W.DLL
BHO: Google Toolbar Helper: {aa58ed58-01dd-4d91-8333-cf10577473f7} - c:\program files\google\google toolbar\GoogleToolbar.dll
BHO: Google Toolbar Notifier BHO: {af69de43-7d58-4638-b6fa-ce66b5ad205d} - c:\program files\google\googletoolbarnotifier\5.1.1309.15642\swg.dll
BHO: Google Dictionary Compression sdch: {c84d72fe-e17d-4195-bb24-76c02e2e7c4e} - c:\program files\google\google toolbar\component\fastsearch_A8904FB862BD9564.dll
BHO: CBrowserHelperObject Object: {ca6319c0-31b7-401e-a518-a07c3db8f777} - c:\program files\bae\BAE.dll
BHO: Java™ Plug-In 2 SSV Helper: {dbc80044-a445-435b-bc74-9c25c1c588a9} - c:\program files\java\jre6\bin\jp2ssv.dll
BHO: JQSIEStartDetectorImpl Class: {e7e6f031-17ce-4c07-bc86-eabfe594f69c} - c:\program files\java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll
TB: Google Toolbar: {2318c2b1-4965-11d4-9b18-009027a5cd4f} - c:\program files\google\google toolbar\GoogleToolbar.dll
uRun: [MSMSGS] "c:\program files\messenger\msmsgs.exe" /background
uRun: [swg] c:\program files\google\googletoolbarnotifier\GoogleToolbarNotifier.exe
mRun: [ehTray] c:\windows\ehome\ehtray.exe
mRun: [igfxtray] c:\windows\system32\igfxtray.exe
mRun: [igfxhkcmd] c:\windows\system32\hkcmd.exe
mRun: [igfxpers] c:\windows\system32\igfxpers.exe
mRun: [SynTPEnh] c:\program files\synaptics\syntp\SynTPEnh.exe
mRun: [Broadcom Wireless Manager UI] c:\windows\system32\WLTRAY.exe
mRun: [SigmatelSysTrayApp] stsystra.exe
mRun: [DMXLauncher] c:\program files\dell\media experience\DMXLauncher.exe
mRun: [CTSVolFE.exe] "c:\program files\creative\mixer\CTSVolFE.exe" /r
mRun: [ISUSPM Startup] "c:\program files\common files\installshield\updateservice\isuspm.exe" -startup
mRun: [ISUSScheduler] "c:\program files\common files\installshield\updateservice\issch.exe" -start
mRun: [DLA] c:\windows\system32\dla\DLACTRLW.EXE
mRun: [MSKDetectorExe] c:\program files\mcafee\spamkiller\MSKDetct.exe /uninstall
mRun: [TkBellExe] "c:\program files\common files\real\update_ob\realsched.exe" -osboot
mRun: [LogitechCommunicationsManager] "c:\program files\common files\logishrd\lcommgr\Communications_Helper.exe"
mRun: [LogitechQuickCamRibbon] "c:\program files\logitech\quickcam\Quickcam.exe" /hide
mRun: [ccApp] "c:\program files\common files\symantec shared\ccApp.exe"
mRun: [SunJavaUpdateSched] "c:\program files\java\jre6\bin\jusched.exe"
mRunOnce: [Malwarebytes' Anti-Malware] c:\program files\malwarebytes' anti-malware\mbamgui.exe /install /silent
StartupFolder: c:\docume~1\alluse~1\startm~1\programs\startup\adober~1.lnk - c:\program files\adobe\acrobat 7.0\reader\reader_sl.exe
StartupFolder: c:\docume~1\alluse~1\startm~1\programs\startup\digita~1.lnk - c:\program files\digital line detect\DLG.exe
StartupFolder: c:\docume~1\alluse~1\startm~1\programs\startup\hppsc1~1.lnk - c:\program files\hewlett-packard\digital imaging\bin\hpohmr08.exe
StartupFolder: c:\docume~1\alluse~1\startm~1\programs\startup\hpoddt~1.lnk - c:\program files\hewlett-packard\digital imaging\bin\hpotdd01.exe
StartupFolder: c:\docume~1\alluse~1\startm~1\programs\startup\logite~1.lnk - c:\program files\logitech\desktop messenger\8876480\program\LogitechDesktopMessenger.exe
StartupFolder: c:\docume~1\alluse~1\startm~1\programs\startup\micros~1.lnk - c:\program files\microsoft office\office\OSA9.EXE
StartupFolder: c:\docume~1\alluse~1\startm~1\programs\startup\servic~1.lnk - c:\program files\microsoft sql server\80\tools\binn\sqlmangr.exe
IE: E&xport to Microsoft Excel - c:\progra~1\mi1933~1\office11\EXCEL.EXE/3000
IE: {FB5F1910-F110-11d2-BB9E-00C04F795683} - c:\program files\messenger\msmsgs.exe
IE: {92780B25-18CC-41C8-B9BE-3C9C571A8263} - {FF059E31-CC5A-4E2E-BF3B-96E929D65503} - c:\progra~1\mi1933~1\office11\REFIEBAR.DLL
IE: {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - {FE54FA40-D68C-11d2-98FA-00C0F0318AFE} - c:\windows\system32\Shdocvw.dll
Trusted Zone: musicmatch.com\online
DPF: {1239CC52-59EF-4DFA-8C61-90FFA846DF7E} - hxxp://www.musicnotes.com/download/mnviewer.cab
DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_16-windows-i586.cab
DPF: {8FFBE65D-2C9C-4669-84BD-5829DC0B603C} - hxxp://fpdownload.macromedia.com/get/flashplayer/current/ultrashim.cab
DPF: {CAFEEFAC-0016-0000-0014-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_14-windows-i586.cab
DPF: {CAFEEFAC-0016-0000-0016-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_16-windows-i586.cab
DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_16-windows-i586.cab
Filter: x-sdch - {B1759355-3EEC-4C1E-B0F1-B719FE26E377} - c:\program files\google\google toolbar\component\fastsearch_A8904FB862BD9564.dll
Handler: bwfile-8876480 - {9462A756-7B47-47BC-8C80-C34B9B80B32B} - c:\program files\logitech\desktop messenger\8876480\program\GAPlugProtocol-8876480.dll
Handler: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - c:\progra~1\common~1\skype\SKYPE4~1.DLL
Notify: igfxcui - igfxdev.dll
SSODL: WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - c:\windows\system32\WPDShServiceObj.dll
================= FIREFOX ===================
FF - ProfilePath - c:\docume~1\jamie\applic~1\mozilla\firefox\profiles\skixw25y.default\
FF - prefs.js: browser.search.defaulturl - hxxp://slirsredirect.search.aol.com/slirs_http/sredir?sredir=2706&invocationType=tb50fftrie7&query=
FF - prefs.js: browser.search.selectedEngine - Google
FF - prefs.js: browser.startup.homepage - hxxp://home.nyu.edu/
FF - prefs.js: keyword.URL - hxxp://slirsredirect.search.aol.com/slirs_http/sredir?sredir=2706&invocationType=tb50fftrab&query=
FF - plugin: c:\documents and settings\jamie\application data\move networks\plugins\npqmp071500000347.dll
FF - plugin: c:\program files\mozilla firefox\plugins\npGoogleGadgetPluginFirefoxWin.dll
FF - plugin: c:\program files\mozilla firefox\plugins\npunagi2.dll
FF - HiddenExtension: Java Console: No Registry Reference - c:\program files\mozilla firefox\extensions\{CAFEEFAC-0016-0000-0014-ABCDEFFEDCBA}
FF - HiddenExtension: Java Console: No Registry Reference - c:\program files\mozilla firefox\extensions\{CAFEEFAC-0016-0000-0016-ABCDEFFEDCBA}
—- FIREFOX POLICIES —-
FF - user.js: general.useragent.extra.zencast -
============= SERVICES / DRIVERS ===============
R2 BCMWLNPF;Broadcom Netgroup Packet Filter;c:\windows\system32\drivers\BCMWLNPF.SYS [2006-9-8 33664]
R3 EraserUtilRebootDrv;EraserUtilRebootDrv;c:\program files\common files\symantec shared\eengine\EraserUtilRebootDrv.sys [2009-9-8 102448]
R3 NAVENG;NAVENG;c:\progra~1\common~1\symant~1\virusd~1\20090908.032\NAVENG.SYS [2009-9-8 84912]
R3 NAVEX15;NAVEX15;c:\progra~1\common~1\symant~1\virusd~1\20090908.032\NAVEX15.SYS [2009-9-8 1323568]
=============== Created Last 30 ================
2009-09-09 21:56 –d—– c:\docume~1\jamie\applic~1\Malwarebytes
2009-09-09 21:56 38,160 a——- c:\windows\system32\drivers\mbamswissarmy.sys
2009-09-09 21:56 19,096 a——- c:\windows\system32\drivers\mbam.sys
2009-09-09 21:56 –d—– c:\program files\Malwarebytes' Anti-Malware
2009-09-09 21:56 –d—– c:\docume~1\alluse~1\applic~1\Malwarebytes
2009-09-09 21:50 411,368 a——- c:\windows\system32\deploytk.dll
2009-09-09 21:50 73,728 a——- c:\windows\system32\javacpl.cpl
2009-09-09 10:29 a-dshr– C:\cmdcons
2009-09-09 10:27 230,912 a——- c:\windows\PEV.exe
2009-09-09 10:27 161,792 a——- c:\windows\SWREG.exe
2009-09-09 10:27 98,816 a——- c:\windows\sed.exe
2009-09-09 00:03 197 a——- c:\windows\system32\MRT.INI
2009-09-08 22:50 153,088 ——– c:\windows\system32\dllcache\triedit.dll
2009-09-07 17:05 123,952 a——- c:\windows\system32\drivers\SYMEVENT.SYS
2009-09-07 17:05 60,800 a——- c:\windows\system32\S32EVNT1.DLL
2009-09-07 17:05 10,563 a——- c:\windows\system32\drivers\SYMEVENT.CAT
2009-09-07 17:05 805 a——- c:\windows\system32\drivers\SYMEVENT.INF
2009-09-07 11:45 102,664 a——- c:\windows\system32\drivers\tmcomm.sys
2009-09-07 11:29 –d—– c:\documents and settings\jamie\.housecall6.6
2009-08-12 09:42 128,512 ——– c:\windows\system32\dllcache\dhtmled.ocx
==================== Find3M ====================
2009-08-24 22:15 0 ac—— c:\windows\system32\drivers\lvuvc.hs
2009-08-24 22:15 0 ac—— c:\windows\system32\drivers\logiflt.iad
2009-08-13 11:16 512,000 a——- c:\windows\system32\dllcache\jscript.dll
2009-08-07 17:05 107,848 a——- c:\windows\system32\SymVPN.dll
2009-08-07 17:05 89,088 a——- c:\windows\system32\atl71.dll
2009-08-07 17:05 49,480 a——- c:\windows\system32\FwsVpn.dll
2009-08-07 17:05 319,920 a——- c:\windows\system32\drivers\srtspl.sys
2009-08-07 17:05 280,112 a——- c:\windows\system32\drivers\srtsp.sys
2009-08-07 17:05 43,824 a——- c:\windows\system32\drivers\srtspx.sys
2009-08-07 17:05 7,372 a——- c:\windows\system32\drivers\srtspl.cat
2009-08-07 17:05 7,368 a——- c:\windows\system32\drivers\srtsp.cat
2009-08-07 17:05 7,359 a——- c:\windows\system32\drivers\srtspx.cat
2009-08-07 17:05 1,431 a——- c:\windows\system32\drivers\srtspl.inf
2009-08-07 17:05 1,422 a——- c:\windows\system32\drivers\srtspx.inf
2009-08-07 17:05 1,416 a——- c:\windows\system32\drivers\srtsp.inf
2009-08-07 17:04 23,888 a——- c:\windows\system32\drivers\COH_Mon.sys
2009-08-07 17:04 10,537 a——- c:\windows\system32\drivers\coh_mon.cat
2009-08-07 17:04 706 a——- c:\windows\system32\drivers\COH_Mon.inf
2009-08-05 05:11 204,800 a——- c:\windows\system32\mswebdvd.dll
2009-08-05 05:11 204,800 a——- c:\windows\system32\dllcache\mswebdvd.dll
2009-07-19 09:33 3,597,824 a——- c:\windows\system32\dllcache\mshtml.dll
2009-07-19 09:32 6,067,200 ——– c:\windows\system32\dllcache\ieframe.dll
2009-07-17 14:55 58,880 a——- c:\windows\system32\atl.dll
2009-07-17 14:55 58,880 ——– c:\windows\system32\dllcache\atl.dll
2009-07-13 10:08 286,720 a——- c:\windows\system32\wmpdxm.dll
2009-07-13 10:08 286,720 ——– c:\windows\system32\dllcache\wmpdxm.dll
2009-07-13 10:08 5,537,792 ——– c:\windows\system32\dllcache\wmp.dll
2009-07-10 09:42 1,315,328 a——- c:\windows\system32\dllcache\msoe.dll
2009-07-02 19:32 3,766 a–sh— c:\windows\system32\KGyGaAvL.sys
2009-06-29 07:07 13,824 ——– c:\windows\system32\dllcache\ieudinit.exe
2009-06-29 07:07 70,656 ——– c:\windows\system32\dllcache\ie4uinit.exe
2009-06-29 04:35 634,632 ——– c:\windows\system32\dllcache\iexplore.exe
2009-06-29 04:33 2,452,872 ——– c:\windows\system32\dllcache\ieapfltr.dat
2009-06-29 04:33 161,792 ——– c:\windows\system32\dllcache\ieakui.dll
2009-06-25 04:17 729,600 a——- c:\windows\system32\lsasrv.dll
2009-06-25 04:17 301,568 a——- c:\windows\system32\kerberos.dll
2009-06-25 04:17 168,448 a——- c:\windows\system32\schannel.dll
2009-06-25 04:17 136,192 a——- c:\windows\system32\msv1_0.dll
2009-06-25 04:17 59,392 a——- c:\windows\system32\wdigest.dll
2009-06-25 04:17 56,320 a——- c:\windows\system32\secur32.dll
2009-06-25 04:17 729,600 ——– c:\windows\system32\dllcache\lsasrv.dll
2009-06-25 04:17 301,568 ——– c:\windows\system32\dllcache\kerberos.dll
2009-06-25 04:17 168,448 ——– c:\windows\system32\dllcache\schannel.dll
2009-06-25 04:17 136,192 ——– c:\windows\system32\dllcache\msv1_0.dll
2009-06-25 04:17 59,392 ——– c:\windows\system32\dllcache\wdigest.dll
2009-06-25 04:17 56,320 ——– c:\windows\system32\dllcache\secur32.dll
2009-06-22 07:49 117,248 a——- c:\windows\system32\mqtgsvc.exe
2009-06-22 07:49 117,248 a——- c:\windows\system32\dllcache\mqtgsvc.exe
2009-06-22 07:49 19,968 a——- c:\windows\system32\mqbkup.exe
2009-06-22 07:49 19,968 a——- c:\windows\system32\dllcache\mqbkup.exe
2009-06-22 07:49 4,608 a——- c:\windows\system32\mqsvc.exe
2009-06-22 07:49 4,608 ——– c:\windows\system32\dllcache\mqsvc.exe
2009-06-22 07:48 91,776 a——- c:\windows\system32\dllcache\mqac.sys
2009-06-22 07:35 92,544 ——– c:\windows\system32\dllcache\ksecdd.sys
2009-06-16 10:55 119,808 a——- c:\windows\system32\t2embed.dll
2009-06-16 10:55 82,432 a——- c:\windows\system32\fontsub.dll
2009-06-16 10:55 82,432 a——- c:\windows\system32\dllcache\fontsub.dll
2009-06-16 10:55 119,808 ——– c:\windows\system32\dllcache\t2embed.dll
2009-06-12 07:50 80,896 a——- c:\windows\system32\tlntsess.exe
2009-06-12 07:50 80,896 a——- c:\windows\system32\dllcache\tlntsess.exe
2009-06-12 07:50 76,288 a——- c:\windows\system32\telnet.exe
2009-06-12 07:50 76,288 a——- c:\windows\system32\dllcache\telnet.exe
2006-09-15 21:03 0 ac—— c:\docume~1\jamie\applic~1\wklnhst.dat
2008-12-21 23:46 32,768 ac-sh— c:\windows\system32\config\systemprofile\local settings\history\history.ie5\mshist012008122120081222\index.dat
============= FINISH: 2:11:50.85 ===============