This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

[Resolved] I NEED HELP PLEASE- NEWBIE

13 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

Im not much of a comp wiz, as you can see…or will see, but have checked out your site and here is my log, could you please help me.




:pullhair: ____________________________________
StartupList report, 11/25/2008, 9:48:50 AM
StartupList version: 1.52.2
Started from : C:\Program Files\Hijackthis\HijackThis.EXE
Detected: Windows XP SP2 (WinNT 5.01.2600)
Detected: Internet Explorer v7.00 (7.00.6000.16735)
* Using default options
==================================================

Running processes:

C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Windows Defender\MsMpEng.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\CA\SharedComponents\HIPSEngine\UmxCfg.exe
C:\Program Files\CA\SharedComponents\HIPSEngine\UmxFwHlp.exe
C:\Program Files\CA\SharedComponents\HIPSEngine\UmxPol.exe
C:\Program Files\CA\SharedComponents\HIPSEngine\UmxAgent.exe
C:\Program Files\Common Files\AOL\ACS\AOLAcsd.exe
C:\Program Files\Common Files\AOL\TopSpeed\2.0\aoltsmon.exe
C:\Program Files\CA\CA Internet Security Suite\CA Anti-Virus\ISafe.exe
C:\WINDOWS\eHome\ehRecvr.exe
C:\WINDOWS\eHome\ehSched.exe
C:\Program Files\CA\SharedComponents\PPRT\bin\ITMRTSVC.exe
C:\Program Files\Common Files\New Boundary\PrismXL\PRISMXL.SYS
C:\WINDOWS\system32\svchost.exe
C:\Program Files\CA\CA Internet Security Suite\CA Anti-Virus\VetMsg.exe
C:\WINDOWS\system32\dllhost.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\rundll32.exe
C:\Program Files\CA\CA Internet Security Suite\CA Personal Firewall\capfsem.exe
C:\WINDOWS\ehome\ehtray.exe
C:\WINDOWS\RTHDCPL.EXE
C:\WINDOWS\eHome\ehmsas.exe
C:\WINDOWS\zHotkey.exe
C:\Program Files\HP\HP Software Update\HPWuSchd2.exe
C:\PROGRAM FILES\DELL\DELL LASER MFP 1815\PSU\Scan2Pc.exe
C:\Program Files\QuickTime\QTTask.exe
C:\Program Files\iTunes\iTunesHelper.exe
C:\Program Files\Common Files\AOL\ACS\AOLDial.exe
C:\PROGRA~1\COMMON~1\AOL\AOLSPY~1\AOLSP Scheduler.exe
C:\Program Files\CA\CA Internet Security Suite\cctray\cctray.exe
C:\Program Files\CA\CA Internet Security Suite\CA Anti-Spam\QSP-5.1.18.0\QOELoader.exe
C:\Program Files\CA\CA Internet Security Suite\CA Anti-Virus\CAVRID.exe
C:\Program Files\CA\CA Internet Security Suite\CA Personal Firewall\capfasem.exe
C:\PROGRA~1\COMMON~1\AOL\121562~1\EE\AOLHOS~1.EXE
C:\Program Files\Windows Defender\MSASCui.exe
C:\WINDOWS\system32\rundll32.exe
C:\PROGRA~1\COMMON~1\AOL\121562~1\EE\AOLServiceHost.exe
C:\Program Files\Messenger\msmsgs.exe
C:\Program Files\CA\CA Internet Security Suite\ccprovsp.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
C:\Program Files\CA\CA Internet Security Suite\CA Anti-Spyware\CAPPActiveProtection.exe
C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe
C:\Program Files\CA\CA Internet Security Suite\CA Anti-Spyware\PPCtlPriv.exe
C:\Program Files\iPod\bin\iPodService.exe
C:\Program Files\HP\Digital Imaging\bin\hpqSTE08.exe
C:\WINDOWS\system32\FBw54VXH.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLLoginProxy.exe
C:\Program Files\Hijackthis\HijackThis.exe
C:\WINDOWS\system32\HPZipm12.exe

————————————————–

Listing of startup folders:

Shell folders Common Startup:
[C:\Documents and Settings\All Users\Start Menu\Programs\Startup]
Adobe Reader Speed Launch.lnk = C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
HP Digital Imaging Monitor.lnk = C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe

————————————————–

Checking Windows NT UserInit:

[HKLM\Software\Microsoft\Windows NT\CurrentVersion\Winlogon]
UserInit = C:\WINDOWS\system32\userinit.exe,

————————————————–

Autorun entries from Registry:
HKLM\Software\Microsoft\Windows\CurrentVersion\Run

ehTray = C:\WINDOWS\ehome\ehtray.exe
RTHDCPL = RTHDCPL.EXE
Alcmtr = ALCMTR.EXE
CHotkey = zHotkey.exe
HP Software Update = C:\Program Files\HP\HP Software Update\HPWuSchd2.exe
MFP1815_S2P = C:\PROGRAM FILES\DELL\DELL LASER MFP 1815\PSU\Scan2Pc.exe
SSBkgdUpdate = "C:\Program Files\Common Files\Scansoft Shared\SSBkgdUpdate\SSBkgdupdate.exe" -Embedding -boot
PaperPort PTD = "C:\Program Files\DELL\Dell Laser MFP 1815\PaperPort\pptd40nt.exe"
IndexSearch = "C:\Program Files\DELL\Dell Laser MFP 1815\PaperPort\IndexSearch.exe"
QuickTime Task = "C:\Program Files\QuickTime\QTTask.exe" -atboottime
iTunesHelper = "C:\Program Files\iTunes\iTunesHelper.exe"
MSKDetectorExe = C:\Program Files\McAfee\SpamKiller\MSKDetct.exe /uninstall
HostManager = C:\Program Files\Common Files\AOL\1215622490\EE\AOLHostManager.exe
AOLDialer = C:\Program Files\Common Files\AOL\ACS\AOLDial.exe
AOL Spyware Protection = "C:\PROGRA~1\COMMON~1\AOL\AOLSPY~1\AOLSP Scheduler.exe"
cctray = "C:\Program Files\CA\CA Internet Security Suite\cctray\cctray.exe"
QOELOADER = "C:\Program Files\CA\CA Internet Security Suite\CA Anti-Spam\QSP-5.1.18.0\QOELoader.exe"
CAVRID = "C:\Program Files\CA\CA Internet Security Suite\CA Anti-Virus\CAVRID.exe"
cafwc = C:\Program Files\CA\CA Internet Security Suite\CA Personal Firewall\cafw.exe -cl
capfasem = C:\Program Files\CA\CA Internet Security Suite\CA Personal Firewall\capfasem.exe
(Default) =
capfupgrade = C:\Program Files\CA\CA Internet Security Suite\CA Personal Firewall\capfupgrade.exe
Windows Defender = "C:\Program Files\Windows Defender\MSASCui.exe" -hide
CPM97f4074d = Rundll32.exe "c:\windows\system32\rafaweti.dll",a
bofakidibe = Rundll32.exe "C:\WINDOWS\system32\sayadaso.dll",s
Malwarebytes Anti-Malware (reboot) = "C:\Program Files\Malwarebytes' Anti-Malware\mbam.exe" /runcleanupscript

————————————————–

Autorun entries from Registry:
HKCU\Software\Microsoft\Windows\CurrentVersion\Run

Power2GoExpress = NA
updateMgr = C:\Program Files\Adobe\Acrobat 7.0\Reader\AdobeUpdateManager.exe AcRdB7_0_9
MSMSGS = "C:\Program Files\Messenger\msmsgs.exe" /background
ctfmon.exe = C:\WINDOWS\system32\ctfmon.exe
swg = C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
DW6 = "C:\Program Files\The Weather Channel FW\Desktop\DesktopWeather.exe"

————————————————–

Load/Run keys from C:\WINDOWS\WIN.INI:

load=*INI section not found*
run=*INI section not found*

Load/Run keys from Registry:

HKLM\..\Windows NT\CurrentVersion\WinLogon: load=*Registry value not found*
HKLM\..\Windows NT\CurrentVersion\WinLogon: run=*Registry value not found*
HKLM\..\Windows\CurrentVersion\WinLogon: load=*Registry key not found*
HKLM\..\Windows\CurrentVersion\WinLogon: run=*Registry key not found*
HKCU\..\Windows NT\CurrentVersion\WinLogon: load=*Registry value not found*
HKCU\..\Windows NT\CurrentVersion\WinLogon: run=*Registry value not found*
HKCU\..\Windows\CurrentVersion\WinLogon: load=*Registry key not found*
HKCU\..\Windows\CurrentVersion\WinLogon: run=*Registry key not found*
HKCU\..\Windows NT\CurrentVersion\Windows: load=
HKCU\..\Windows NT\CurrentVersion\Windows: run=*Registry value not found*
HKLM\..\Windows NT\CurrentVersion\Windows: load=*Registry value not found*
HKLM\..\Windows NT\CurrentVersion\Windows: run=*Registry value not found*
HKLM\..\Windows NT\CurrentVersion\Windows: AppInit_DLLs=karna.dat C:\WINDOWS\system32\gejanojo.dll c:\windows\system32\rafaweti.dll

————————————————–

Shell & screensaver key from C:\WINDOWS\SYSTEM.INI:

Shell=
SCRNSAVE.EXE=C:\WINDOWS\system32\gtw_logo.scr
drivers=

Shell & screensaver key from Registry:

Shell=Explorer.exe
SCRNSAVE.EXE=C:\WINDOWS\system32\mypixdx.scr
drivers=*Registry value not found*

Policies Shell key:

HKCU\..\Policies: Shell=*Registry key not found*
HKLM\..\Policies: Shell=*Registry value not found*

————————————————–


Enumerating Browser Helper Objects:

(no name) - C:\WINDOWS\system32\nevorefa.dll (file missing) - {85e6eb01-3bfd-4265-b6e3-e81c4be4bd37}
(no name) - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll - {9030D464-4C02-4ABF-8ECC-5164760863C6}

————————————————–

Enumerating Task Scheduler jobs:

AppleSoftwareUpdate.job
At1.job
At10.job
At11.job
At12.job
At13.job
At14.job
At15.job
At16.job
At17.job
At18.job
At19.job
At2.job
At20.job
At21.job
At22.job
At23.job
At24.job
At25.job
At26.job
At27.job
At28.job
At29.job
At3.job
At30.job
At31.job
At32.job
At33.job
At34.job
At35.job
At36.job
At37.job
At38.job
At39.job
At4.job
At40.job
At41.job
At42.job
At43.job
At44.job
At45.job
At46.job
At47.job
At48.job
At5.job
At6.job
At7.job
At8.job
At9.job
CAAntiSpywareScan_Daily as Owner at 8 35 AM.job
MP Scheduled Scan.job

————————————————–

Enumerating Download Program Files:

[MeadCo ScriptX]
InProcServer32 = C:\WINDOWS\system32\MCScripX.dll
CODEBASE = https://eagent.farmersinsurance.com/PLA/eAg…ctiveX/smsx.cab
OSD = C:\WINDOWS\Downloaded Program Files\smsx.osd

[Shockwave ActiveX Control]
InProcServer32 = C:\WINDOWS\system32\macromed\Director\SwDir.dll
CODEBASE = http://download.macromedia.com/pub/shockwa…director/sw.cab

[Windows Genuine Advantage Validation Tool]
InProcServer32 = C:\WINDOWS\system32\LegitCheckControl.DLL
CODEBASE = http://download.microsoft.com/download/8/b…heckControl.cab

[ImgXTwain6.ImgXTwain]
InProcServer32 = C:\WINDOWS\Downloaded Program Files\ImgXTwain61.dll
CODEBASE = https://eagent.farmersinsurance.com/PLA/eAg…ImgXTwain61.cab

[ImgXDialog6.ImgXDialog]
InProcServer32 = C:\WINDOWS\Downloaded Program Files\ImgXDialog61.dll
CODEBASE = https://eagent.farmersinsurance.com/PLA/eAg…mgXDialog61.cab

[Atalasoft ImgXCtrl6.ImgXCtrl (CAB)]
InProcServer32 = C:\WINDOWS\Downloaded Program Files\ImgXCAB61.ocx
CODEBASE = https://eagent.farmersinsurance.com/PLA/eAg…iveX/ImgX61.cab

[{8FFBE65D-2C9C-4669-84BD-5829DC0B603C}]
CODEBASE = http://fpdownload.macromedia.com/get/flash…t/ultrashim.cab

[Shockwave Flash Object]
InProcServer32 = C:\WINDOWS\system32\Macromed\Flash\Flash9f.ocx
CODEBASE = http://fpdownload.macromedia.com/get/shock…ash/swflash.cab

————————————————–

Enumerating Winsock LSP files:

Protocol #1: C:\WINDOWS\system32\VetRedir.dll
Protocol #2: C:\WINDOWS\system32\VetRedir.dll
Protocol #3: C:\WINDOWS\system32\VetRedir.dll
Protocol #21: C:\WINDOWS\system32\VetRedir.dll

————————————————–

Enumerating ShellServiceObjectDelayLoad items:

PostBootReminder: C:\WINDOWS\system32\SHELL32.dll
CDBurn: C:\WINDOWS\system32\SHELL32.dll
WebCheck: C:\WINDOWS\system32\webcheck.dll
SysTray: C:\WINDOWS\system32\stobject.dll
WPDShServiceObj: C:\WINDOWS\system32\WPDShServiceObj.dll
SSODL: c:\windows\system32\rafaweti.dll

————————————————–
End of report, 11,926 bytes
Report generated in 0.250 seconds

Command line options:
/verbose - to add additional info on each section
/complete - to include empty sections and unsuspicious data
/full - to include several rarely-important sections
/force9x - to include Win9x-only startups even if running on WinNT
/forcent - to include WinNT-only startups even if running on Win9x
/forceall - to include all Win9x and WinNT startups, regardless of platform
/history - to list version history only
Hi dejaylos welcome to the forum.

Please be advised, as I'm still in training, all my replies will have to be approved by a teacher or expert before I can post them. This may cause some delays, but I will do my best to keep them as short as possible.

To make cleaning this machine easier
  • Please do not uninstall/install any programs unless asked to
    It is more difficult when files/programs are appearing in/disappearing from the logs.
  • Please do not run any scans other than those requested
  • Please follow all instructions in the order posted
  • If you have problems with or do not understand the instructions, Please ask before continuing.
I will post back soon with additional instructions.

Thanks
I understand and will not do anything to this machine, unless advised to do so. Thanks for your time and I will be patient during this process.
Hi dejaylos,

If you haven't all ready done so, please reboot your computer to let MalwareBytes AntiMalware finish. A log will be saved automatically by MBAM and can be viewed by clicking the Logs tab in MBAM.
Copy&Paste the entire report in your next reply.

Please download and save to your desktop Double-click ATF-Cleaner.exe to run the program.
  • Under Main choose: Select All
  • Click the Empty Selected button.
If you use Firefox browser
  • Click Firefox at the top and choose: Select All
  • Click the Empty Selected button.
NOTE: If you would like to keep your saved passwords, please click No at the prompt.

If you use Opera browser
  • Click Opera at the top and choose: Select All
  • Click the Empty Selected button.
NOTE: If you would like to keep your saved passwords, please click No at the prompt.

Click Exit on the Main menu to close the program.

Note your computer may boot a little slower the first couple of times.

Double click on RSIT.exe to run RSIT.
  • Click Continue at the disclaimer screen.
  • Once it has finished, two logs will open. Please post the contents of both log.txt (will be maximized) and info.txt (will be minimized)
Please tell me how your computer is at the moment.

Please include in your next reply, the MBAM log (if pesent) and both Rsit logs.

Thanks
Okay I have done what you said.. Thank you in advance for your help. These are the logs requested, also my anti-virus scaned and it says I have the win32/vxidl!generic virus in two files? Can you help me with these as well.

Here are the reports:


Logfile of random's system information tool 1.04 (written by random/random)
Run by [removed] at 2008-11-27 08:37:03
Microsoft Windows XP Professional Service Pack 2
System drive C: has 123 GB (84%) free of 147 GB
Total RAM: 446 MB (12% free)

Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 8:37:33 AM, on 11/27/2008
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16735)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Windows Defender\MsMpEng.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\CA\SharedComponents\HIPSEngine\UmxCfg.exe
C:\Program Files\CA\SharedComponents\HIPSEngine\UmxFwHlp.exe
C:\Program Files\CA\SharedComponents\HIPSEngine\UmxPol.exe
C:\Program Files\CA\SharedComponents\HIPSEngine\UmxAgent.exe
C:\Program Files\Common Files\AOL\ACS\AOLAcsd.exe
C:\Program Files\Common Files\AOL\TopSpeed\2.0\aoltsmon.exe
C:\Program Files\CA\CA Internet Security Suite\CA Anti-Virus\ISafe.exe
C:\WINDOWS\eHome\ehRecvr.exe
C:\WINDOWS\eHome\ehSched.exe
C:\Program Files\CA\SharedComponents\PPRT\bin\ITMRTSVC.exe
C:\Program Files\Common Files\New Boundary\PrismXL\PRISMXL.SYS
C:\WINDOWS\system32\svchost.exe
C:\Program Files\CA\CA Internet Security Suite\CA Anti-Virus\VetMsg.exe
C:\WINDOWS\system32\dllhost.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\CA\CA Internet Security Suite\CA Personal Firewall\capfsem.exe
C:\WINDOWS\ehome\ehtray.exe
C:\WINDOWS\RTHDCPL.EXE
C:\WINDOWS\eHome\ehmsas.exe
C:\WINDOWS\zHotkey.exe
C:\Program Files\HP\HP Software Update\HPWuSchd2.exe
C:\PROGRAM FILES\DELL\DELL LASER MFP 1815\PSU\Scan2Pc.exe
C:\Program Files\QuickTime\QTTask.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\iTunes\iTunesHelper.exe
C:\Program Files\Common Files\AOL\ACS\AOLDial.exe
C:\PROGRA~1\COMMON~1\AOL\AOLSPY~1\AOLSP Scheduler.exe
C:\Program Files\CA\CA Internet Security Suite\cctray\cctray.exe
C:\Program Files\CA\CA Internet Security Suite\CA Anti-Spam\QSP-5.1.18.0\QOELoader.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\CA\CA Internet Security Suite\CA Anti-Virus\CAVRID.exe
C:\PROGRA~1\COMMON~1\AOL\121562~1\EE\AOLHOS~1.EXE
C:\Program Files\CA\CA Internet Security Suite\CA Personal Firewall\capfasem.exe
C:\Program Files\Windows Defender\MSASCui.exe
C:\Program Files\CA\CA Internet Security Suite\ccprovsp.exe
C:\Program Files\Messenger\msmsgs.exe
C:\Program Files\CA\CA Internet Security Suite\CA Anti-Spyware\CAPPActiveProtection.exe
C:\PROGRA~1\COMMON~1\AOL\121562~1\EE\AOLServiceHost.exe
C:\Program Files\CA\CA Internet Security Suite\CA Anti-Spyware\PPCtlPriv.exe
C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLLoginProxy.exe
C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe
C:\Program Files\iPod\bin\iPodService.exe
C:\Program Files\HP\Digital Imaging\bin\hpqSTE08.exe
C:\Program Files\iTunes\iTunes.exe
C:\WINDOWS\system32\FBw54VXH.exe
C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
C:\Documents and Settings\Owner.LOPEZINSURANCE\Desktop\RSIT.exe
C:\Program Files\trend micro\Owner.exe

R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
O2 - BHO: (no name) - {85e6eb01-3bfd-4265-b6e3-e81c4be4bd37} - C:\WINDOWS\system32\nevorefa.dll (file missing)
O2 - BHO: Windows Live Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
O3 - Toolbar: AOL Toolbar - {4982D40A-C53B-4615-B15B-B5B5E98D167C} - C:\Program Files\AOL Toolbar\toolbar.dll
O3 - Toolbar: &Google; - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar1.dll
O4 - HKLM\..\Run: [ehTray] C:\WINDOWS\ehome\ehtray.exe
O4 - HKLM\..\Run: [RTHDCPL] RTHDCPL.EXE
O4 - HKLM\..\Run: [Alcmtr] ALCMTR.EXE
O4 - HKLM\..\Run: [CHotkey] zHotkey.exe
O4 - HKLM\..\Run: [Recguard] %WINDIR%\SMINST\RECGUARD.EXE
O4 - HKLM\..\Run: [HP Software Update] C:\Program Files\HP\HP Software Update\HPWuSchd2.exe
O4 - HKLM\..\Run: [MFP1815_S2P] C:\PROGRAM FILES\DELL\DELL LASER MFP 1815\PSU\Scan2Pc.exe
O4 - HKLM\..\Run: [SSBkgdUpdate] "C:\Program Files\Common Files\Scansoft Shared\SSBkgdUpdate\SSBkgdupdate.exe" -Embedding -boot
O4 - HKLM\..\Run: [PaperPort PTD] "C:\Program Files\DELL\Dell Laser MFP 1815\PaperPort\pptd40nt.exe"
O4 - HKLM\..\Run: [IndexSearch] "C:\Program Files\DELL\Dell Laser MFP 1815\PaperPort\IndexSearch.exe"
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\QTTask.exe" -atboottime
O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
O4 - HKLM\..\Run: [MSKDetectorExe] C:\Program Files\McAfee\SpamKiller\MSKDetct.exe /uninstall
O4 - HKLM\..\Run: [HostManager] C:\Program Files\Common Files\AOL\1215622490\EE\AOLHostManager.exe
O4 - HKLM\..\Run: [AOLDialer] C:\Program Files\Common Files\AOL\ACS\AOLDial.exe
O4 - HKLM\..\Run: [AOL Spyware Protection] "C:\PROGRA~1\COMMON~1\AOL\AOLSPY~1\AOLSP Scheduler.exe"
O4 - HKLM\..\Run: [cctray] "C:\Program Files\CA\CA Internet Security Suite\cctray\cctray.exe"
O4 - HKLM\..\Run: [QOELOADER] "C:\Program Files\CA\CA Internet Security Suite\CA Anti-Spam\QSP-5.1.18.0\QOELoader.exe"
O4 - HKLM\..\Run: [CAVRID] "C:\Program Files\CA\CA Internet Security Suite\CA Anti-Virus\CAVRID.exe"
O4 - HKLM\..\Run: [cafwc] C:\Program Files\CA\CA Internet Security Suite\CA Personal Firewall\cafw.exe -cl
O4 - HKLM\..\Run: [capfasem] C:\Program Files\CA\CA Internet Security Suite\CA Personal Firewall\capfasem.exe
O4 - HKLM\..\Run: [capfupgrade] C:\Program Files\CA\CA Internet Security Suite\CA Personal Firewall\capfupgrade.exe
O4 - HKLM\..\Run: [Windows Defender] "C:\Program Files\Windows Defender\MSASCui.exe" -hide
O4 - HKCU\..\Run: [Power2GoExpress] NA
O4 - HKCU\..\Run: [updateMgr] C:\Program Files\Adobe\Acrobat 7.0\Reader\AdobeUpdateManager.exe AcRdB7_0_9
O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [swg] C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
O4 - HKCU\..\Run: [DW6] "C:\Program Files\The Weather Channel FW\Desktop\DesktopWeather.exe"
O4 - HKUS\S-1-5-19\..\Run: [bofakidibe] Rundll32.exe "C:\WINDOWS\system32\sayadaso.dll",s (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-20\..\Run: [bofakidibe] Rundll32.exe "C:\WINDOWS\system32\sayadaso.dll",s (User 'NETWORK SERVICE')
O4 - Global Startup: Adobe Reader Speed Launch.lnk = C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
O4 - Global Startup: HP Digital Imaging Monitor.lnk = C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe
O8 - Extra context menu item: &AOL; Toolbar search - res://C:\Program Files\AOL Toolbar\toolbar.dll/SEARCH.HTML
O8 - Extra context menu item: E&xport; to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
O9 - Extra button: AOL Toolbar - {4982D40A-C53B-4615-B15B-B5B5E98D167C} - C:\Program Files\AOL Toolbar\toolbar.dll
O9 - Extra 'Tools' menuitem: AOL Toolbar - {4982D40A-C53B-4615-B15B-B5B5E98D167C} - C:\Program Files\AOL Toolbar\toolbar.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL
O9 - Extra button: Real.com - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - C:\WINDOWS\system32\Shdocvw.dll
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O16 - DPF: {1663ed61-23eb-11d2-b92f-008048fdd814} (MeadCo ScriptX Advanced) - https://eagent.farmersinsurance.com/PLA/eAg…ctiveX/smsx.cab
O16 - DPF: {354D91A8-E3C9-491F-BB89-0FB27DEEED86} (ImgXTwain6.ImgXTwain) - https://eagent.farmersinsurance.com/PLA/eAg…ImgXTwain61.cab
O16 - DPF: {45EEDB84-57BC-4FBD-8065-7AB8E971B545} (ImgXDialog6.ImgXDialog) - https://eagent.farmersinsurance.com/PLA/eAg…mgXDialog61.cab
O16 - DPF: {7E8DC73D-69CD-4F67-99B1-8DC6E42F6246} (Atalasoft ImgXCtrl6.ImgXCtrl (CAB)) - https://eagent.farmersinsurance.com/PLA/eAg…iveX/ImgX61.cab
O20 - AppInit_DLLs: karna.dat ,C:\WINDOWS\system32\gejanojo.dll
O23 - Service: AOL Connectivity Service (AOL ACS) - America Online - C:\Program Files\Common Files\AOL\ACS\AOLAcsd.exe
O23 - Service: AOL TopSpeed Monitor (AOL TopSpeedMonitor) - America Online, Inc - C:\Program Files\Common Files\AOL\TopSpeed\2.0\aoltsmon.exe
O23 - Service: AOL Spyware Protection Service (AOLService) - Unknown owner - C:\PROGRA~1\COMMON~1\AOL\AOLSPY~1\\aolserv.exe
O23 - Service: Ati HotKey Poller - ATI Technologies Inc. - C:\WINDOWS\system32\Ati2evxx.exe
O23 - Service: ATI Smart - Unknown owner - C:\WINDOWS\system32\ati2sgag.exe
O23 - Service: CaCCProvSP - CA, Inc. - C:\Program Files\CA\CA Internet Security Suite\ccprovsp.exe
O23 - Service: CAISafe - Computer Associates International, Inc. - C:\Program Files\CA\CA Internet Security Suite\CA Anti-Virus\ISafe.exe
O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: iPod Service - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: CA Pest Patrol Realtime Protection Service (ITMRTSVC) - CA, Inc. - C:\Program Files\CA\SharedComponents\PPRT\bin\ITMRTSVC.exe
O23 - Service: Pml Driver HPZ12 - HP - C:\WINDOWS\system32\HPZipm12.exe
O23 - Service: PPCtlPriv - CA, Inc. - C:\Program Files\CA\CA Internet Security Suite\CA Anti-Spyware\PPCtlPriv.exe
O23 - Service: PrismXL - New Boundary Technologies, Inc. - C:\Program Files\Common Files\New Boundary\PrismXL\PRISMXL.SYS
O23 - Service: HIPS Event Manager (UmxAgent) - CA - C:\Program Files\CA\SharedComponents\HIPSEngine\UmxAgent.exe
O23 - Service: HIPS Configuration Interpreter (UmxCfg) - CA - C:\Program Files\CA\SharedComponents\HIPSEngine\UmxCfg.exe
O23 - Service: HIPS Firewall Helper (UmxFwHlp) - CA - C:\Program Files\CA\SharedComponents\HIPSEngine\UmxFwHlp.exe
O23 - Service: HIPS Policy Manager (UmxPol) - CA - C:\Program Files\CA\SharedComponents\HIPSEngine\UmxPol.exe
O23 - Service: VET Message Service (VETMSGNT) - CA, Inc. - C:\Program Files\CA\CA Internet Security Suite\CA Anti-Virus\VetMsg.exe

–
End of file - 10830 bytes

======Scheduled tasks folder======

C:\WINDOWS\tasks\AppleSoftwareUpdate.job
C:\WINDOWS\tasks\At1.job
C:\WINDOWS\tasks\At10.job
C:\WINDOWS\tasks\At11.job
C:\WINDOWS\tasks\At12.job
C:\WINDOWS\tasks\At13.job
C:\WINDOWS\tasks\At14.job
C:\WINDOWS\tasks\At15.job
C:\WINDOWS\tasks\At16.job
C:\WINDOWS\tasks\At17.job
C:\WINDOWS\tasks\At18.job
C:\WINDOWS\tasks\At19.job
C:\WINDOWS\tasks\At2.job
C:\WINDOWS\tasks\At20.job
C:\WINDOWS\tasks\At21.job
C:\WINDOWS\tasks\At22.job
C:\WINDOWS\tasks\At23.job
C:\WINDOWS\tasks\At24.job
C:\WINDOWS\tasks\At25.job
C:\WINDOWS\tasks\At26.job
C:\WINDOWS\tasks\At27.job
C:\WINDOWS\tasks\At28.job
C:\WINDOWS\tasks\At29.job
C:\WINDOWS\tasks\At3.job
C:\WINDOWS\tasks\At30.job
C:\WINDOWS\tasks\At31.job
C:\WINDOWS\tasks\At32.job
C:\WINDOWS\tasks\At33.job
C:\WINDOWS\tasks\At34.job
C:\WINDOWS\tasks\At35.job
C:\WINDOWS\tasks\At36.job
C:\WINDOWS\tasks\At37.job
C:\WINDOWS\tasks\At38.job
C:\WINDOWS\tasks\At39.job
C:\WINDOWS\tasks\At4.job
C:\WINDOWS\tasks\At40.job
C:\WINDOWS\tasks\At41.job
C:\WINDOWS\tasks\At42.job
C:\WINDOWS\tasks\At43.job
C:\WINDOWS\tasks\At44.job
C:\WINDOWS\tasks\At45.job
C:\WINDOWS\tasks\At46.job
C:\WINDOWS\tasks\At47.job
C:\WINDOWS\tasks\At48.job
C:\WINDOWS\tasks\At5.job
C:\WINDOWS\tasks\At6.job
C:\WINDOWS\tasks\At7.job
C:\WINDOWS\tasks\At8.job
C:\WINDOWS\tasks\At9.job
C:\WINDOWS\tasks\CAAntiSpywareScan_Daily as Owner at 8 35 AM.job
C:\WINDOWS\tasks\MP Scheduled Scan.job

======Registry dump======

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{85e6eb01-3bfd-4265-b6e3-e81c4be4bd37}]
C:\WINDOWS\system32\nevorefa.dll []

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{9030D464-4C02-4ABF-8ECC-5164760863C6}]
Windows Live Sign-in Helper - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll [2007-09-20 328752]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar]
{4982D40A-C53B-4615-B15B-B5B5E98D167C} - AOL Toolbar - C:\Program Files\AOL Toolbar\toolbar.dll [2005-04-20 472744]
{2318C2B1-4965-11d4-9B18-009027A5CD4F} - &Google; - c:\program files\google\googletoolbar1.dll [2008-09-19 2403392]

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
"ehTray"=C:\WINDOWS\ehome\ehtray.exe [2005-08-05 64512]
"RTHDCPL"=C:\WINDOWS\RTHDCPL.EXE [2006-04-16 16143872]
"Alcmtr"=C:\WINDOWS\ALCMTR.EXE [2005-05-03 69632]
"CHotkey"=C:\WINDOWS\zHotkey.exe [2004-12-08 550912]
"Recguard"=C:\WINDOWS\SMINST\RECGUARD.EXE [2002-09-13 212992]
"HP Software Update"=C:\Program Files\HP\HP Software Update\HPWuSchd2.exe [2005-12-15 49152]
"MFP1815_S2P"=C:\PROGRAM FILES\DELL\DELL LASER MFP 1815\PSU\Scan2Pc.exe [2006-12-22 258952]
"SSBkgdUpdate"=C:\Program Files\Common Files\Scansoft Shared\SSBkgdUpdate\SSBkgdupdate.exe [2003-10-14 155648]
"PaperPort PTD"=C:\Program Files\DELL\Dell Laser MFP 1815\PaperPort\pptd40nt.exe [2006-02-20 36864]
"IndexSearch"=C:\Program Files\DELL\Dell Laser MFP 1815\PaperPort\IndexSearch.exe [2006-02-20 40960]
"QuickTime Task"=C:\Program Files\QuickTime\QTTask.exe [2007-06-29 286720]
"iTunesHelper"=C:\Program Files\iTunes\iTunesHelper.exe [2007-07-10 270648]
"MSKDetectorExe"=C:\Program Files\McAfee\SpamKiller\MSKDetct.exe [2006-11-07 1121280]
"HostManager"=C:\Program Files\Common Files\AOL\1215622490\EE\AOLHostManager.exe [2004-11-03 125528]
"AOLDialer"=C:\Program Files\Common Files\AOL\ACS\AOLDial.exe [2004-10-20 34904]
"AOL Spyware Protection"=C:\PROGRA~1\COMMON~1\AOL\AOLSPY~1\AOLSP Scheduler.exe [2004-10-18 79448]
"cctray"=C:\Program Files\CA\CA Internet Security Suite\cctray\cctray.exe [2007-08-16 177416]
"QOELOADER"=C:\Program Files\CA\CA Internet Security Suite\CA Anti-Spam\QSP-5.1.18.0\QOELoader.exe [2008-11-13 14088]
"CAVRID"=C:\Program Files\CA\CA Internet Security Suite\CA Anti-Virus\CAVRID.exe [2007-08-20 230664]
"cafwc"=C:\Program Files\CA\CA Internet Security Suite\CA Personal Firewall\cafw.exe [2008-11-13 1193200]
"capfasem"=C:\Program Files\CA\CA Internet Security Suite\CA Personal Firewall\capfasem.exe [2008-11-13 173296]
""= []
"capfupgrade"=C:\Program Files\CA\CA Internet Security Suite\CA Personal Firewall\capfupgrade.exe [2008-11-13 259312]
"Windows Defender"=C:\Program Files\Windows Defender\MSASCui.exe [2006-11-03 866584]

[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run]
"Power2GoExpress"=NA []
"updateMgr"=C:\Program Files\Adobe\Acrobat 7.0\Reader\AdobeUpdateManager.exe [2006-03-30 313472]
"MSMSGS"=C:\Program Files\Messenger\msmsgs.exe [2004-10-13 1694208]
"ctfmon.exe"=C:\WINDOWS\system32\ctfmon.exe [2004-08-10 15360]
"swg"=C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe [2008-10-01 68856]
"DW6"=C:\Program Files\The Weather Channel FW\Desktop\DesktopWeather.exe [2008-09-26 789616]

C:\Documents and Settings\All Users\Start Menu\Programs\Startup
Adobe Reader Speed Launch.lnk - C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
HP Digital Imaging Monitor.lnk - C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows]
"AppInit_DLLS"="karna.dat ,C:\WINDOWS\system32\gejanojo.dll"

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\AtiExtEvent]
C:\WINDOWS\system32\Ati2evxx.dll [2006-01-14 61440]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\PFW]
C:\WINDOWS\system32\UmxWnp.Dll [2007-05-18 79368]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad]
WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - C:\WINDOWS\system32\WPDShServiceObj.dll [2006-10-18 133632]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks]
"{091EB208-39DD-417D-A5DD-7E2C2D8FB9CB}"=C:\PROGRA~1\WIFD1F~1\MpShHook.dll [2006-11-03 83224]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Lsa]
"notification packages"=scecli
C:\WINDOWS\system32\gejanojo.dll

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\WinDefend]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\WinDefend]

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\System]
"dontdisplaylastusername"=0
"legalnoticecaption"=
"legalnoticetext"=
"shutdownwithoutlogon"=1
"undockwithoutlogon"=1
"InstallVisualStyle"=C:\WINDOWS\Resources\Themes\Royale\Royale.msstyles
"InstallTheme"=C:\WINDOWS\Resources\Themes\Royale.theme

[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\explorer]
"NoDriveTypeAutoRun"=149
"ForceClassicControlPanel"=1

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\standardprofile\authorizedapplications\list]
"%windir%\system32\sessmgr.exe"="%windir%\system32\sessmgr.exe:*:enabled:@xpsp2res.dll,-22019"
"C:\Program Files\Common Files\AOL\Loader\aolload.exe"="C:\Program Files\Common Files\AOL\Loader\aolload.exe:*:Enabled:AOL Application Loader"
"C:\Program Files\Common Files\AOL\ACS\AOLDial.exe"="C:\Program Files\Common Files\AOL\ACS\AOLDial.exe:*:Enabled:AOL"
"C:\Program Files\Common Files\AOL\ACS\AOLacsd.exe"="C:\Program Files\Common Files\AOL\ACS\AOLacsd.exe:*:Enabled:AOL"
"C:\Program Files\America Online 9.0\waol.exe"="C:\Program Files\America Online 9.0\waol.exe:*:Enabled:AOL"
"C:\Program Files\Common Files\AOL\TopSpeed\2.0\aoltsmon.exe"="C:\Program Files\Common Files\AOL\TopSpeed\2.0\aoltsmon.exe:*:Enabled:AOLTsMon"
"C:\Program Files\Common Files\AOL\TopSpeed\2.0\aoltpspd.exe"="C:\Program Files\Common Files\AOL\TopSpeed\2.0\aoltpspd.exe:*:Enabled:AOLTopSpeed"
"C:\Program Files\Common Files\AOL\1159911348\EE\AOLServiceHost.exe"="C:\Program Files\Common Files\AOL\1159911348\EE\AOLServiceHost.exe:*:Enabled:AOL"
"C:\Program Files\Common Files\AOL\System Information\sinf.exe"="C:\Program Files\Common Files\AOL\System Information\sinf.exe:*:Enabled:AOL"
"C:\Program Files\Common Files\AOL\AOL Spyware Protection\AOLSP Scheduler.exe"="C:\Program Files\Common Files\AOL\AOL Spyware Protection\AOLSP Scheduler.exe:*:Enabled:AOL"
"C:\Program Files\Common Files\AOL\AOL Spyware Protection\asp.exe"="C:\Program Files\Common Files\AOL\AOL Spyware Protection\asp.exe:*:Enabled:AOL"
"C:\Program Files\Common Files\AolCoach\en_en\player\AOLNySEV.exe"="C:\Program Files\Common Files\AolCoach\en_en\player\AOLNySEV.exe:*:Enabled:AOL"
"C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe"="C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe:*:Enabled:hpqtra08.exe"
"C:\Program Files\HP\Digital Imaging\bin\hpqste08.exe"="C:\Program Files\HP\Digital Imaging\bin\hpqste08.exe:*:Enabled:hpqste08.exe"
"C:\Program Files\HP\Digital Imaging\bin\hpofxm08.exe"="C:\Program Files\HP\Digital Imaging\bin\hpofxm08.exe:*:Enabled:hpofxm08.exe"
"C:\Program Files\HP\Digital Imaging\bin\hposfx08.exe"="C:\Program Files\HP\Digital Imaging\bin\hposfx08.exe:*:Enabled:hposfx08.exe"
"C:\Program Files\HP\Digital Imaging\bin\hposid01.exe"="C:\Program Files\HP\Digital Imaging\bin\hposid01.exe:*:Enabled:hposid01.exe"
"C:\Program Files\HP\Digital Imaging\bin\hpqscnvw.exe"="C:\Program Files\HP\Digital Imaging\bin\hpqscnvw.exe:*:Enabled:hpqscnvw.exe"
"C:\Program Files\HP\Digital Imaging\bin\hpqkygrp.exe"="C:\Program Files\HP\Digital Imaging\bin\hpqkygrp.exe:*:Enabled:hpqkygrp.exe"
"C:\Program Files\HP\Digital Imaging\bin\hpqCopy.exe"="C:\Program Files\HP\Digital Imaging\bin\hpqCopy.exe:*:Enabled:hpqcopy.exe"
"C:\Program Files\HP\Digital Imaging\bin\hpfccopy.exe"="C:\Program Files\HP\Digital Imaging\bin\hpfccopy.exe:*:Enabled:hpfccopy.exe"
"C:\Program Files\HP\Digital Imaging\bin\hpzwiz01.exe"="C:\Program Files\HP\Digital Imaging\bin\hpzwiz01.exe:*:Enabled:hpzwiz01.exe"
"C:\Program Files\HP\Digital Imaging\Unload\HpqPhUnl.exe"="C:\Program Files\HP\Digital Imaging\Unload\HpqPhUnl.exe:*:Enabled:hpqphunl.exe"
"C:\Program Files\HP\Digital Imaging\Unload\HpqDIA.exe"="C:\Program Files\HP\Digital Imaging\Unload\HpqDIA.exe:*:Enabled:hpqdia.exe"
"C:\Program Files\HP\Digital Imaging\bin\hpoews01.exe"="C:\Program Files\HP\Digital Imaging\bin\hpoews01.exe:*:Enabled:hpoews01.exe"
"C:\Program Files\HP\Digital Imaging\bin\hpqnrs08.exe"="C:\Program Files\HP\Digital Imaging\bin\hpqnrs08.exe:*:Enabled:hpqnrs08.exe"
"%windir%\Network Diagnostic\xpnetdiag.exe"="%windir%\Network Diagnostic\xpnetdiag.exe:*:Enabled:@xpsp3res.dll,-20000"
"C:\Program Files\Messenger\msmsgs.exe"="C:\Program Files\Messenger\msmsgs.exe:*:Enabled:Windows Messenger"
"C:\Program Files\iTunes\iTunes.exe"="C:\Program Files\iTunes\iTunes.exe:*:Enabled:iTunes"
"C:\Program Files\Common Files\AOL\1215622490\EE\AOLServiceHost.exe"="C:\Program Files\Common Files\AOL\1215622490\EE\AOLServiceHost.exe:*:Enabled:AOL"
"C:\WINDOWS\system32\FBw54VXH.exe"="C:\WINDOWS\system32\FBw54VXH.exe:*:Enabled:FBw54VXH"
"C:\WINDOWS\system32\winlogon.exe"="C:\WINDOWS\system32\winlogon.exe:*:Enabled:winlogon"

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\domainprofile\authorizedapplications\list]
"%windir%\system32\sessmgr.exe"="%windir%\system32\sessmgr.exe:*:enabled:@xpsp2res.dll,-22019"
"%windir%\Network Diagnostic\xpnetdiag.exe"="%windir%\Network Diagnostic\xpnetdiag.exe:*:Enabled:@xpsp3res.dll,-20000"

[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{935b3331-5323-11db-8b52-806d6172696f}]
shell\AutoRun\command - C:\WINDOWS\system32\RunDLL32.EXE Shell32.DLL,ShellExec_RunDLL Info.exe folder.htt 480 480


======List of files/folders created in the last 1 months======

2008-11-27 08:37:08 —-D—- C:\Program Files\trend micro
2008-11-27 08:37:02 —-D—- C:\rsit
2008-11-25 09:44:03 —-D—- C:\Program Files\Hijackthis
2008-11-25 09:21:54 —-D—- C:\VundoFix Backups
2008-11-25 09:21:54 —-A—- C:\VundoFix.txt
2008-11-25 08:47:39 —-A—- C:\bgeyvyqx.txt
2008-11-25 08:44:51 —-D—- C:\Program Files\Exterminate It!
2008-11-24 14:46:53 —-D—- C:\Program Files\Windows Defender
2008-11-22 22:12:27 —-D—- C:\Documents and Settings\Owner.LOPEZINSURANCE\Application Data\Malwarebytes
2008-11-22 22:12:05 —-D—- C:\Program Files\Malwarebytes' Anti-Malware
2008-11-22 22:12:05 —-D—- C:\Documents and Settings\All Users\Application Data\Malwarebytes
2008-11-22 18:31:53 —-A—- C:\WINDOWS\system32\muweb.dll
2008-11-22 18:31:53 —-A—- C:\WINDOWS\system32\mucltui.dll.mui
2008-11-22 18:31:53 —-A—- C:\WINDOWS\system32\mucltui.dll
2008-11-22 18:31:01 —-SHDC—- C:\Program Files\Common Files\WindowsLiveInstaller
2008-11-22 18:30:28 —-D—- C:\Program Files\Windows Live
2008-11-22 18:29:00 —-D—- C:\Documents and Settings\All Users\Application Data\WLInstaller
2008-11-13 18:20:46 —-A—- C:\WINDOWS\cdplayer.ini
2008-11-13 08:47:28 —-D—- C:\WINDOWS\CAVTemp
2008-11-13 08:36:05 —-A—- C:\WINDOWS\system32\vetredir.dll
2008-11-13 08:36:05 —-A—- C:\WINDOWS\system32\isafprod.dll
2008-11-13 08:36:05 —-A—- C:\WINDOWS\system32\isafeif.dll
2008-11-13 08:36:01 —-A—- C:\caavsetupLog.txt
2008-11-13 08:35:34 —-D—- C:\Program Files\Common Files\Scanner
2008-11-13 08:35:16 —-D—- C:\Documents and Settings\All Users\Application Data\CA
2008-11-13 08:35:15 —-D—- C:\Program Files\CA
2008-11-13 08:33:02 —-A—- C:\caisslog.txt
2008-11-12 15:31:57 —-A—- C:\WINDOWS\system32\odopeci.bat
2008-11-12 15:31:57 —-A—- C:\WINDOWS\gukugu.bat
2008-11-12 15:31:57 —-A—- C:\Documents and Settings\All Users\Application Data\lyjysezivi.bat
2008-11-12 10:04:49 —-HDC—- C:\WINDOWS\$NtUninstallKB957097$
2008-11-12 10:04:39 —-HDC—- C:\WINDOWS\$NtUninstallKB955069$
2008-11-03 08:19:36 —-HDC—- C:\WINDOWS\$NtUninstallKB939683$
2008-11-02 13:14:07 —-A—- C:\WINDOWS\system32\FBw54VXH.exe_
2008-11-02 13:14:07 —-A—- C:\WINDOWS\system32\FBw54VXH.exe
2008-11-01 12:36:03 —-A—- C:\WINDOWS\system32\VIbh1Sv1.exe

======List of files/folders modified in the last 1 months======

2008-11-27 08:37:16 —-D—- C:\WINDOWS\Prefetch
2008-11-27 08:37:08 —-D—- C:\Program Files
2008-11-27 08:37:00 —-D—- C:\WINDOWS\Temp
2008-11-27 08:30:33 —-D—- C:\WINDOWS\system32
2008-11-27 08:15:14 —-D—- C:\WINDOWS\system32\CatRoot2
2008-11-27 07:24:05 —-D—- C:\WINDOWS
2008-11-27 07:19:13 —-SD—- C:\WINDOWS\Tasks
2008-11-27 07:17:58 —-A—- C:\WINDOWS\ModemLog_PCI Soft Data Fax Modem with SmartCP.txt
2008-11-27 07:16:42 —-D—- C:\WINDOWS\Registration
2008-11-26 14:33:13 —-A—- C:\WINDOWS\SchedLgU.Txt
2008-11-25 11:43:37 —-SHD—- C:\WINDOWS\Installer
2008-11-25 11:43:35 —-HD—- C:\Config.Msi
2008-11-25 10:31:17 —-D—- C:\WINDOWS\system32\drivers
2008-11-25 07:44:57 —-N—- C:\WINDOWS\system32\rafaweti.dll
2008-11-24 19:12:42 —-D—- C:\Program Files\Common Files
2008-11-24 14:46:55 —-HD—- C:\WINDOWS\inf
2008-11-24 14:46:53 —-SD—- C:\Documents and Settings\All Users\Application Data\Microsoft
2008-11-24 14:44:27 —-SD—- C:\WINDOWS\Downloaded Program Files
2008-11-22 19:41:01 —-D—- C:\WINDOWS\system32\CatRoot_bak
2008-11-22 19:41:01 —-D—- C:\WINDOWS\system32\CatRoot
2008-11-22 18:32:03 —-D—- C:\Program Files\Common Files\Microsoft Shared
2008-11-20 23:00:22 —-D—- C:\WINDOWS\network diagnostic
2008-11-18 15:05:53 —-A—- C:\WINDOWS\win.ini
2008-11-13 08:40:57 —-RSHDC—- C:\WINDOWS\system32\dllcache
2008-11-13 08:32:46 —-D—- C:\Documents and Settings
2008-11-12 10:04:49 —-HD—- C:\WINDOWS\$hf_mig$
2008-11-12 10:04:46 —-A—- C:\WINDOWS\imsins.BAK
2008-11-12 10:04:02 —-D—- C:\WINDOWS\WinSxS
2008-11-06 15:44:11 —-D—- C:\Documents and Settings\Owner.LOPEZINSURANCE\Application Data\PDF reDirect
2008-11-02 12:41:38 —-A—- C:\WINDOWS\system32\PerfStringBackup.INI

======List of drivers (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======

R1 Cdr4_xp;Cdr4_xp; C:\WINDOWS\system32\drivers\Cdr4_xp.sys [2004-11-10 44288]
R1 Cdralw2k;Cdralw2k; C:\WINDOWS\system32\drivers\Cdralw2k.sys [2004-11-10 24832]
R1 intelppm;Intel Processor Driver; C:\WINDOWS\system32\DRIVERS\intelppm.sys [2004-08-10 36096]
R1 KmxAgent;KmxAgent; C:\WINDOWS\System32\DRIVERS\kmxagent.sys [2008-06-24 63504]
R1 KmxFile;KmxFile; C:\WINDOWS\System32\DRIVERS\KmxFile.sys [2008-06-24 45584]
R1 KmxFw;KmxFw; C:\WINDOWS\System32\DRIVERS\kmxfw.sys [2008-06-24 115216]
R1 VETEFILE;VET File Scan Engine; C:\WINDOWS\system32\drivers\VETEFILE.sys [2008-11-13 880560]
R1 VETFDDNT;VET Floppy Boot Sector Monitor; C:\WINDOWS\system32\drivers\VETFDDNT.sys [2007-08-20 21512]
R1 VET-FILT;VET File System Filter; C:\WINDOWS\system32\drivers\VET-FILT.sys [2007-08-20 26376]
R1 VETMONNT;VET File Monitor; C:\WINDOWS\system32\drivers\VETMONNT.sys [2007-08-20 32264]
R1 VET-REC;VET File System Recognizer; C:\WINDOWS\system32\drivers\VET-REC.sys [2007-08-20 21128]
R2 ASCTRM;ASCTRM; C:\WINDOWS\system32\drivers\ASCTRM.sys [2006-10-03 8552]
R2 KmxCF;KmxCF; C:\WINDOWS\System32\DRIVERS\KmxCF.sys [2008-06-24 134648]
R2 KmxSbx;KmxSbx; C:\WINDOWS\System32\DRIVERS\KmxSbx.sys [2008-06-24 66576]
R2 mdmxsdk;mdmxsdk; C:\WINDOWS\system32\DRIVERS\mdmxsdk.sys [2006-06-18 12672]
R3 ati2mtag;ati2mtag; C:\WINDOWS\system32\DRIVERS\ati2mtag.sys [2006-01-14 1477632]
R3 GEARAspiWDM;GEARAspiWDM; C:\WINDOWS\System32\Drivers\GEARAspiWDM.sys [2006-09-19 15664]
R3 HDAudBus;Microsoft UAA Bus Driver for High Definition Audio; C:\WINDOWS\system32\DRIVERS\HDAudBus.sys [2005-01-07 138752]
R3 HSF_DPV;HSF_DPV; C:\WINDOWS\system32\DRIVERS\HSF_DPV.sys [2006-07-17 990592]
R3 HSFHWBS2;HSFHWBS2; C:\WINDOWS\system32\DRIVERS\HSFHWBS2.sys [2006-07-17 256128]
R3 IntcAzAudAddService;Service for Realtek HD Audio (WDM); C:\WINDOWS\system32\drivers\RtkHDAud.sys [2006-04-17 4262912]
R3 KmxCfg;KmxCfg; C:\WINDOWS\System32\DRIVERS\kmxcfg.sys [2008-06-24 88816]
R3 RTL8023xp;Realtek 10/100/1000 NIC Family all in one NDIS XP Driver; C:\WINDOWS\system32\DRIVERS\Rtnicxp.sys [2006-01-18 80512]
R3 usbccgp;Microsoft USB Generic Parent Driver; C:\WINDOWS\system32\DRIVERS\usbccgp.sys [2004-08-04 31616]
R3 usbehci;Microsoft USB 2.0 Enhanced Host Controller Miniport Driver; C:\WINDOWS\system32\DRIVERS\usbehci.sys [2004-08-10 26624]
R3 usbhub;USB2 Enabled Hub; C:\WINDOWS\system32\DRIVERS\usbhub.sys [2004-08-10 57600]
R3 usbohci;Microsoft USB Open Host Controller Miniport Driver; C:\WINDOWS\system32\DRIVERS\usbohci.sys [2004-08-03 17024]
R3 usbprint;Microsoft USB PRINTER Class; C:\WINDOWS\system32\DRIVERS\usbprint.sys [2004-08-03 25856]
R3 usbscan;USB Scanner Driver; C:\WINDOWS\system32\DRIVERS\usbscan.sys [2004-08-03 15104]
R3 usbstor;USB Mass Storage Driver; C:\WINDOWS\system32\DRIVERS\USBSTOR.SYS [2004-08-03 26496]
R3 VETEBOOT;VET Boot Scan Engine; C:\WINDOWS\system32\drivers\VETEBOOT.sys [2008-11-13 108368]
R3 wanatw;WAN Miniport (ATW); C:\WINDOWS\system32\DRIVERS\wanatw4.sys [2003-01-10 33588]
R3 winachsf;winachsf; C:\WINDOWS\system32\DRIVERS\HSF_CNXT.sys [2006-07-17 728192]
S1 kbdhid;Keyboard HID Driver; C:\WINDOWS\system32\DRIVERS\kbdhid.sys [2004-08-04 14848]
S2 DgiVecp;DgiVecp; \??\C:\WINDOWS\system32\Drivers\DgiVecp.sys []
S2 MCSTRM;MCSTRM; C:\WINDOWS\system32\drivers\MCSTRM.sys []
S2 SSPORT;SSPORT; \??\C:\WINDOWS\system32\Drivers\SSPORT.sys []
S3 Arp1394;1394 ARP Client Protocol; C:\WINDOWS\system32\DRIVERS\arp1394.sys [2004-08-10 60800]
S3 CCDECODE;Closed Caption Decoder; C:\WINDOWS\system32\DRIVERS\CCDECODE.sys [2004-08-03 17024]
S3 CmBatt;Microsoft ACPI Control Method Battery Driver; C:\WINDOWS\system32\DRIVERS\CmBatt.sys [2004-08-03 14080]
S3 HidUsb;Microsoft HID Class Driver; C:\WINDOWS\system32\DRIVERS\hidusb.sys [2001-08-17 9600]
S3 HPZid412;IEEE-1284.4 Driver HPZid412; C:\WINDOWS\system32\DRIVERS\HPZid412.sys [2005-10-27 49664]
S3 HPZipr12;Print Class Driver for IEEE-1284.4 HPZipr12; C:\WINDOWS\system32\DRIVERS\HPZipr12.sys [2005-10-27 16496]
S3 HPZius12;USB to IEEE-1284.4 Translation Driver HPZius12; C:\WINDOWS\system32\DRIVERS\HPZius12.sys [2005-10-27 21568]
S3 MHNDRV;MHN driver; C:\WINDOWS\system32\DRIVERS\mhndrv.sys [2004-08-10 11008]
S3 mouhid;Mouse HID Driver; C:\WINDOWS\system32\DRIVERS\mouhid.sys [2001-08-17 12160]
S3 MSTEE;Microsoft Streaming Tee/Sink-to-Sink Converter; C:\WINDOWS\system32\drivers\MSTEE.sys [2004-08-03 5504]
S3 NABTSFEC;NABTS/FEC VBI Codec; C:\WINDOWS\system32\DRIVERS\NABTSFEC.sys [2004-08-03 85376]
S3 NdisIP;Microsoft TV/Video Connection; C:\WINDOWS\system32\DRIVERS\NdisIP.sys [2004-08-03 10880]
S3 NIC1394;1394 Net Driver; C:\WINDOWS\system32\DRIVERS\nic1394.sys [2004-08-10 61824]
S3 RimSerPort;RIM Virtual Serial Port; C:\WINDOWS\system32\DRIVERS\RimSerial.sys [2005-08-16 18432]
S3 RimUsb;BlackBerry Device; C:\WINDOWS\System32\Drivers\RimUsb.sys []
S3 ROOTMODEM;Microsoft Legacy Modem Driver; C:\WINDOWS\System32\Drivers\RootMdm.sys [2004-08-10 5888]
S3 rtl8139;Realtek RTL8139(A/B/C)-based PCI Fast Ethernet Adapter NT Driver; C:\WINDOWS\system32\DRIVERS\RTL8139.SYS [2004-08-03 20992]
S3 sdbus;sdbus; C:\WINDOWS\system32\DRIVERS\sdbus.sys [2004-08-10 67584]
S3 SLIP;BDA Slip De-Framer; C:\WINDOWS\system32\DRIVERS\SLIP.sys [2004-08-03 11136]
S3 SQTECH905C;DB CIF Cam; C:\WINDOWS\System32\Drivers\Capt905c.sys [2006-01-26 34686]
S3 streamip;BDA IPSink; C:\WINDOWS\system32\DRIVERS\StreamIP.sys [2004-08-03 15360]
S3 usbuhci;Microsoft USB Universal Host Controller Miniport Driver; C:\WINDOWS\system32\DRIVERS\usbuhci.sys [2004-08-10 20480]
S3 WSTCODEC;World Standard Teletext Codec; C:\WINDOWS\system32\DRIVERS\WSTCODEC.SYS [2004-08-03 19328]
S3 WudfPf;Windows Driver Foundation - User-mode Driver Framework Platform Driver; C:\WINDOWS\system32\DRIVERS\WudfPf.sys [2006-09-28 77568]
S3 WudfRd;Windows Driver Foundation - User-mode Driver Framework Reflector; C:\WINDOWS\system32\DRIVERS\wudfrd.sys [2006-09-28 82944]

======List of services (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======

R2 AOL ACS;AOL Connectivity Service; C:\Program Files\Common Files\AOL\ACS\AOLAcsd.exe [2004-10-20 10328]
R2 AOL TopSpeedMonitor;AOL TopSpeed Monitor; C:\Program Files\Common Files\AOL\TopSpeed\2.0\aoltsmon.exe [2004-10-15 100016]
R2 Ati HotKey Poller;Ati HotKey Poller; C:\WINDOWS\system32\Ati2evxx.exe [2006-01-14 405504]
R2 CAISafe;CAISafe; C:\Program Files\CA\CA Internet Security Suite\CA Anti-Virus\ISafe.exe [2007-08-20 144960]
R2 ehRecvr;Media Center Receiver Service; C:\WINDOWS\eHome\ehRecvr.exe [2006-10-09 237568]
R2 ehSched;Media Center Scheduler Service; C:\WINDOWS\eHome\ehSched.exe [2005-08-05 102912]
R2 ITMRTSVC;CA Pest Patrol Realtime Protection Service; C:\Program Files\CA\SharedComponents\PPRT\bin\ITMRTSVC.exe [2007-01-04 280080]
R2 McrdSvc;Media Center Extender Service; C:\WINDOWS\ehome\mcrdsvc.exe [2005-08-05 99328]
R2 PrismXL;PrismXL; C:\Program Files\Common Files\New Boundary\PrismXL\PRISMXL.SYS [2006-10-03 172032]
R2 UmxAgent;HIPS Event Manager; C:\Program Files\CA\SharedComponents\HIPSEngine\UmxAgent.exe [2007-10-18 1010192]
R2 UmxCfg;HIPS Configuration Interpreter; C:\Program Files\CA\SharedComponents\HIPSEngine\UmxCfg.exe [2007-10-18 801296]
R2 UmxFwHlp;HIPS Firewall Helper; C:\Program Files\CA\SharedComponents\HIPSEngine\UmxFwHlp.exe [2007-10-18 145936]
R2 UmxPol;HIPS Policy Manager; C:\Program Files\CA\SharedComponents\HIPSEngine\UmxPol.exe [2008-06-24 281104]
R2 VETMSGNT;VET Message Service; C:\Program Files\CA\CA Internet Security Suite\CA Anti-Virus\VetMsg.exe [2007-08-20 242952]
R2 WinDefend;Windows Defender; C:\Program Files\Windows Defender\MsMpEng.exe [2006-11-03 13592]
R3 CaCCProvSP;CaCCProvSP; C:\Program Files\CA\CA Internet Security Suite\ccprovsp.exe [2007-08-16 214280]
R3 iPod Service;iPod Service; C:\Program Files\iPod\bin\iPodService.exe [2007-07-10 501048]
R3 PPCtlPriv;PPCtlPriv; C:\Program Files\CA\CA Internet Security Suite\CA Anti-Spyware\PPCtlPriv.exe [2007-08-16 189704]
S2 AOLService;AOL Spyware Protection Service; C:\PROGRA~1\COMMON~1\AOL\AOLSPY~1\\aolserv.exe [2004-06-29 184373]
S2 ATI Smart;ATI Smart; C:\WINDOWS\system32\ati2sgag.exe [2006-01-26 520192]
S2 Fax;Fax; C:\WINDOWS\system32\fxssvc.exe [2004-08-10 267776]
S2 Pml Driver HPZ12;Pml Driver HPZ12; C:\WINDOWS\system32\HPZipm12.exe [2005-03-14 69632]
S3 aspnet_state;ASP.NET State Service; C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\aspnet_state.exe [2007-04-13 33632]
S3 clr_optimization_v2.0.50727_32;.NET Runtime Optimization Service v2.0.50727_X86; C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\mscorsvw.exe [2007-04-13 68952]
S3 gusvc;Google Updater Service; C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe [2008-09-19 138168]
S3 IDriverT;InstallDriver Table Manager; C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe [2005-04-03 69632]
S3 MHN;MHN; C:\WINDOWS\System32\svchost.exe [2004-08-10 14336]
S3 ose;Office Source Engine; C:\Program Files\Common Files\Microsoft Shared\Source Engine\OSE.EXE [2003-07-28 89136]
S3 WLSetupSvc;Windows Live Setup Service; C:\Program Files\Windows Live\installer\WLSetupSvc.exe [2007-10-25 266240]
S3 WMPNetworkSvc;Windows Media Player Network Sharing Service; C:\Program Files\Windows Media Player\WMPNetwk.exe [2006-10-18 913408]
S3 WudfSvc;Windows Driver Foundation - User-mode Driver Framework; C:\WINDOWS\system32\svchost.exe [2004-08-10 14336]

—————–EOF—————–


info.txt logfile of random's system information tool 1.04 2008-11-27 08:37:40

======Uninstall list======

–>RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\engine\6\INTEL3~1\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{4804B98A-77A1-493D-869E-3844A2A362D5}\Setup.exe" -l0x9
–>RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\engine\6\INTEL3~1\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{54C41CCD-8AF5-4295-88BC-F7FEB1EB2A21}\Setup.exe" -l0x9 /L9 remove
–>rundll32.exe setupapi.dll,InstallHinfSection DefaultUninstall 132 C:\WINDOWS\INF\PCHealth.inf
Adobe Flash Player 9 ActiveX–>C:\WINDOWS\system32\Macromed\Flash\FlashUtil9b.exe -uninstallDelete
Adobe Flash Player ActiveX–>C:\WINDOWS\system32\Macromed\Flash\uninstall_activeX.exe
Adobe Reader 7.0.9–>MsiExec.exe /I{AC76BA86-7AD7-1033-7B44-A70900000002}
Adobe Shockwave Player–>C:\WINDOWS\system32\Macromed\SHOCKW~1\UNWISE.EXE C:\WINDOWS\system32\Macromed\SHOCKW~1\Install.log
America Online (Choose which version to remove)–>C:\Program Files\Common Files\aolshare\aolunins_us.exe
AOL Coach Version 2.0(Build:20041026.5 en)–>C:\Program Files\Common Files\AolCoach\en_en\AolCInUn.exe -lang=en_en -ext=UDP
AOL Connectivity Services–>"C:\Program Files\Common Files\AOL\ACS\AcsUninstall.exe" /c
AOL Deskbar–>"C:\Program Files\AOL Deskbar\UNWISE.EXE" /u "C:\Program Files\AOL Deskbar\INSTALL.LOG"
AOL Spyware Protection–>C:\PROGRA~1\COMMON~1\AOL\AOLSPY~1\UNWISE.EXE C:\PROGRA~1\COMMON~1\AOL\AOLSPY~1\INSTALL.LOG
AOL Toolbar–>"C:\Program Files\AOL Toolbar\UNWISE.EXE" /u "C:\Program Files\AOL Toolbar\INSTALL.LOG"
AOL You've Got Pictures Screensaver–>C:\Program Files\Common Files\AOL\Screensaver\uninst_ygpss.exe
Apple Software Update–>MsiExec.exe /I{74EC78BC-B379-4E29-9006-8F161DCAABA6}
ATI Display Driver–>rundll32 C:\WINDOWS\system32\atiiiexx.dll,_InfEngUnInstallINFFile_RunDLL@16 -force_restart -flags:0x2010001 -inf_class:DISPLAY -clean
Bejeweled 2 Deluxe–>"C:\Program Files\Gateway Games\Bejeweled 2 Deluxe\Uninstall.exe"
Blackhawk Striker 2–>"C:\Program Files\Gateway Games\Blackhawk Striker 2\Uninstall.exe"
Blasterball 2 Revolution–>"C:\Program Files\Gateway Games\Blasterball 2 Revolution\Uninstall.exe"
Browser Address Error Redirector–>regsvr32 /u /s "c:\windows\system32\BAE.dll"
CA Internet Security Suite–>"C:\Program Files\CA\CA Internet Security Suite\caunst.exe" /u
Cyberchase Carnival Chaos–>C:\WINDOWS\TLCUninstall.exe -f "C:\Program Files\The Learning Company\Cyberchase\Cyberchase Carnival Chaos\Uninstall.xml"
Dell Laser MFP 1815 Software Uninstall–>C:\Program Files\DELL\Dell Laser MFP 1815\Install\setup.exe /Uninstall
Diner Dash–>"C:\Program Files\Gateway Games\Diner Dash\Uninstall.exe"
Disney's Winnie the Pooh Kindergarten–>C:\WINDOWS\IsUninst.exe -fC:\PROGRA~1\DISNEY~2\WINNIE~1\DeIsL1.isu -c"C:\Program Files\Disney Interactive\Winnie the Pooh Kindergarten\Code\Saved Games\Uninst.dll
Docudesk GPL Ghostscript 8.15–>"C:\Program Files\Docudesk\GPL Ghostscript\unins000.exe"
DVD Solution–>RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\engine\6\INTEL3~1\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{1FBF6C24-C1FD-4101-A42B-0C564F9E8E79}\setup.exe" -uninstall
Edmark - Zap–>C:\WINDOWS\unvise32.exe C:\Program Files\Edmark\Zap\uninstal.log
Exterminate It!–>C:\Program Files\Exterminate It!\ExterminateIt_Uninst.exe
FATE–>"C:\Program Files\Gateway Games\FATE\Uninstall.exe"
Gateway Game Console–>"C:\Program Files\WildTangent\Apps\Gateway Game Console\Uninstall.exe"
Google Toolbar for Internet Explorer–>MsiExec.exe /I{DBEA1034-5882-4A88-8033-81C4EF0CFA29}
Google Toolbar for Internet Explorer–>regsvr32 /u /s "c:\program files\google\googletoolbar1.dll"
High Definition Audio Driver Package - KB888111–>"C:\WINDOWS\$NtUninstallKB888111WXPSP2$\spuninst\spuninst.exe"
Hijackthis 1.99.1–>"C:\Program Files\Hijackthis\unins000.exe"
HijackThis 2.0.2–>"C:\Program Files\trend micro\HijackThis.exe" /uninstall
Hotfix for Windows Media Format 11 SDK (KB929399)–>"C:\WINDOWS\$NtUninstallKB929399$\spuninst\spuninst.exe"
Hotfix for Windows Media Player 10 (KB903157)–>"C:\WINDOWS\$NtUninstallKB903157$\spuninst\spuninst.exe"
Hotfix for Windows Media Player 11 (KB939683)–>"C:\WINDOWS\$NtUninstallKB939683$\spuninst\spuninst.exe"
Hotfix for Windows XP (KB888795)–>"C:\WINDOWS\$NtUninstallKB888795$\spuninst\spuninst.exe"
Hotfix for Windows XP (KB891593)–>"C:\WINDOWS\$NtUninstallKB891593$\spuninst\spuninst.exe"
Hotfix for Windows XP (KB895961)–>"C:\WINDOWS\$NtUninstallKB895961$\spuninst\spuninst.exe"
Hotfix for Windows XP (KB896256)–>"C:\WINDOWS\$NtUninstallKB896256$\spuninst\spuninst.exe"
Hotfix for Windows XP (KB899337)–>"C:\WINDOWS\$NtUninstallKB899337$\spuninst\spuninst.exe"
Hotfix for Windows XP (KB899510)–>"C:\WINDOWS\$NtUninstallKB899510$\spuninst\spuninst.exe"
Hotfix for Windows XP (KB902841)–>"C:\WINDOWS\$NtUninstallKB902841$\spuninst\spuninst.exe"
Hotfix for Windows XP (KB906569)–>"C:\WINDOWS\$NtUninstallKB906569$\spuninst\spuninst.exe"
Hotfix for Windows XP (KB909095)–>"C:\WINDOWS\$NtUninstallKB909095$\spuninst\spuninst.exe"
Hotfix for Windows XP (KB910728)–>"C:\WINDOWS\$NtUninstallKB910728$\spuninst\spuninst.exe"
Hotfix for Windows XP (KB912024)–>"C:\WINDOWS\$NtUninstallKB912024$\spuninst\spuninst.exe"
Hotfix for Windows XP (KB914440)–>"C:\WINDOWS\$NtUninstallKB914440$\spuninst\spuninst.exe"
Hotfix for Windows XP (KB914906)–>"C:\WINDOWS\$NtUninstallKB914906$\spuninst\spuninst.exe"
Hotfix for Windows XP (KB915865)–>"C:\WINDOWS\$NtUninstallKB915865$\spuninst\spuninst.exe"
Hotfix for Windows XP (KB926239)–>"C:\WINDOWS\$NtUninstallKB926239$\spuninst\spuninst.exe"
Hotfix for Windows XP (KB935448)–>"C:\WINDOWS\$NtUninstallKB935448$\spuninst\spuninst.exe"
Hotfix for Windows XP (KB952287)–>"C:\WINDOWS\$NtUninstallKB952287$\spuninst\spuninst.exe"
HP Extended Capabilities 6.1–>C:\Program Files\HP\Digital Imaging\ExtCapUninstall\hpzscr01.exe -datfile hpqhsc01.dat
HP Imaging Device Functions 6.1–>C:\Program Files\HP\Digital Imaging\DigitalImagingMonitor\hpzscr01.exe -datfile hpqbud01.dat
HP Photosmart Essential–>MsiExec.exe /X{D7CAE58E-26DE-49B7-A75D-EAEDF76726BE}
HP PSC & OfficeJet 6.1.A–>"C:\Program Files\HP\Digital Imaging\{E5A8DDAB-AE80-48C6-A75B-D0FAB83B299D}\setup\hpzscr01.exe" -datfile hposcr08.dat
HP Software Update–>MsiExec.exe /X{ECFDD6BD-E0C0-41CC-A171-E6D6AF4C0E93}
HP Solution Center and Imaging Support Tools 6.1–>C:\Program Files\HP\Digital Imaging\eSupport\hpzscr01.exe -datfile hpqbud05.dat
iTunes–>MsiExec.exe /I{9357AE3A-B2ED-4138-BB9B-0564352C3F0A}
J2SE Runtime Environment 5.0 Update 2–>MsiExec.exe /I{3248F0A8-6813-11D6-A77B-00B0D0150020}
Malwarebytes' Anti-Malware–>"C:\Program Files\Malwarebytes' Anti-Malware\unins000.exe"
Memorex exPressit Label Design Studio–>C:\WINDOWS\mvuninst\App1\mvuninst.exe "Memorex exPressit Label Design Studio"
Microsoft .NET Framework 1.0 Hotfix (KB887998)–>"C:\WINDOWS\$NtUninstallKB887998$\spuninst\spuninst.exe"
Microsoft .NET Framework 1.0 Hotfix (KB930494)–>"C:\WINDOWS\$NtUninstallKB930494$\spuninst\spuninst.exe"
Microsoft .NET Framework 1.1 Hotfix (KB928366)–>"C:\WINDOWS\Microsoft.NET\Framework\v1.1.4322\Updates\hotfix.exe" "C:\WINDOWS\Microsoft.NET\Framework\v1.1.4322\Updates\M928366\M928366Uninstall.msp"
Microsoft .NET Framework 1.1–>msiexec.exe /X {CB2F7EDD-9D1F-43C1-90FC-4F52EAE172A1}
Microsoft .NET Framework 1.1–>MsiExec.exe /X{CB2F7EDD-9D1F-43C1-90FC-4F52EAE172A1}
Microsoft .NET Framework 2.0–>C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\Microsoft .NET Framework 2.0\install.exe
Microsoft Compression Client Pack 1.0 for Windows XP–>"C:\WINDOWS\$NtUninstallMSCompPackV1$\spuninst\spuninst.exe"
Microsoft Digital Image Starter Edition 2006–>"C:\Program Files\Common Files\Microsoft Shared\Picture It!\RmvSuite.exe" ADDREMOVE=1 SKU=TRIAL VERSION=11
Microsoft Internationalized Domain Names Mitigation APIs–>"C:\WINDOWS\$NtServicePackUninstallIDNMitigationAPIs$\spuninst\spuninst.exe"
Microsoft Money 2006–>"C:\Program Files\Microsoft Money 2006\MNYCoreFiles\Setup\uninst.exe" /s:120
Microsoft National Language Support Downlevel APIs–>"C:\WINDOWS\$NtServicePackUninstallNLSDownlevelMapping$\spuninst\spuninst.exe"
Microsoft Office Professional Edition 2003–>MsiExec.exe /I{91E30409-6000-11D3-8CFE-0150048383C9}
Microsoft Office Standard Edition 2003–>MsiExec.exe /I{91120409-6000-11D3-8CFE-0150048383C9}
Microsoft User-Mode Driver Framework Feature Pack 1.0–>"C:\WINDOWS\$NtUninstallWudf01000$\spuninst\spuninst.exe"
Microsoft Works–>MsiExec.exe /I{6D52C408-B09A-4520-9B18-475B81D393F1}
Mighty Math Number Heroes–>C:\Program Files\Common Files\InstallShield\Driver\8\Intel 32\IDriver.exe /M{60859BF2-5151-473C-8F76-7F3A232CF7E7}
Minigolf Space–>C:\PROGRA~1\COMMON~1\INSTAL~1\Driver\11\INTEL3~1\IDriver.exe /M{A2F6B63B-01BA-4D18-BBE2-31743427D8A3}
MSN–>C:\Program Files\MSN\MsnInstaller\msninst.exe /Action:ARP
MSXML 4.0 SP2 (KB927978)–>MsiExec.exe /I{37477865-A3F1-4772-AD43-AAFC6BCFF99F}
MSXML 4.0 SP2 (KB936181)–>MsiExec.exe /I{C04E32E0-0416-434D-AFB9-6969D703A9EF}
MSXML 4.0 SP2 (KB954430)–>MsiExec.exe /I{86493ADD-824D-4B8E-BD72-8C5DCDC52A71}
Multimedia Keyboard Driver–>RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\engine\6\INTEL3~1\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{6E66ECBD-FCA7-4AE1-A8C5-1CA78BEEB057}\Setup.exe" -l0x9
Napster Burn Engine–>MsiExec.exe /I{8DCE550C-CA43-4E82-92DF-FFC4A48F5BE1}
Napster–>RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\PROFES~1\RunTime\09\01\Intel32\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{BBBCAE4B-B416-4182-A6F2-438180894A81}\setup.exe" -l0x9
Penguins!–>"C:\Program Files\Gateway Games\Penguins!\Uninstall.exe"
Polar Bowler–>"C:\Program Files\Gateway Games\Polar Bowler\Uninstall.exe"
Polar Golfer–>"C:\Program Files\Gateway Games\Polar Golfer\Uninstall.exe"
Power2Go 4.0–>RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\engine\6\INTEL3~1\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{40BF1E83-20EB-11D8-97C5-0009C5020658}\setup.exe" -uninstall
PowerDVD–>RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\engine\6\INTEL3~1\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{6811CAA0-BF12-11D4-9EA1-0050BAE317E1}\setup.exe" -uninstall
QuickTime–>MsiExec.exe /I{95A890AA-B3B1-44B6-9C18-A8F7AB3EE7FC}
Reader Rabbit Personalized Preschool–>C:\WINDOWS\IsUninst.exe -f"C:\Program Files\The Learning Company\Reader Rabbit Personalized Preschool\Uninst.isu"
Reader Rabbit® I Can Read! With Phonics–>C:\Program Files\The Learning Company\Reader Rabbit® I Can Read! With Phonics\uninstall.exe
RealArcade–>C:\Program Files\Real\RealArcade\Update\rnuninst.exe RealNetworks|RealArcade|1.2
RealPlayer Basic–>C:\Program Files\Common Files\Real\Update\\rnuninst.exe RealNetworks|RealPlayer|6.0
REALTEK GbE & FE Ethernet PCI NIC Driver–>RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\PROFES~1\RunTime\11\00\Intel32\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{ACCA20B0-C4D1-4BF5-BF21-0A0EB5EF9730}\setup.exe" -l0x9 -removeonly
Realtek High Definition Audio Driver–>RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\PROFES~1\RunTime\11\00\Intel32\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{F132AF7F-7BCA-4EDE-8A7C-958108FE7DBC}\Setup.exe" -l0x9 -removeonly
Rhapsody Player Engine–>MsiExec.exe /I{2DFF31F9-7893-4922-AF66-C9A1EB4EBB31}
Rhapsody–>C:\PROGRA~1\Rhapsody\Unwise32.exe /A C:\PROGRA~1\Rhapsody\install.log
ScanSoft PaperPort 10–>MsiExec.exe /I{9B51B3C0-3A9E-4B2D-A4DA-6348F6F5DC0B}
SCRABBLE–>"C:\Program Files\Gateway Games\SCRABBLE\Uninstall.exe"
Security Update for Microsoft .NET Framework 2.0 (KB928365)–>C:\WINDOWS\system32\msiexec.exe /promptrestart /uninstall {8056AC9E-49C5-4375-9ADE-B2F862C9DF51} /package {7131646D-CD3C-40F4-97B9-CD9E4E6262EF}
Security Update for Windows Internet Explorer 7 (KB928090)–>"C:\WINDOWS\ie7updates\KB928090-IE7\spuninst\spuninst.exe"
Security Update for Windows Internet Explorer 7 (KB929969)–>"C:\WINDOWS\ie7updates\KB929969\spuninst\spuninst.exe"
Security Update for Windows Internet Explorer 7 (KB931768)–>"C:\WINDOWS\ie7updates\KB931768-IE7\spuninst\spuninst.exe"
Security Update for Windows Internet Explorer 7 (KB933566)–>"C:\WINDOWS\ie7updates\KB933566-IE7\spuninst\spuninst.exe"
Security Update for Windows Internet Explorer 7 (KB937143)–>"C:\WINDOWS\ie7updates\KB937143-IE7\spuninst\spuninst.exe"
Security Update for Windows Internet Explorer 7 (KB938127)–>"C:\WINDOWS\ie7updates\KB938127-IE7\spuninst\spuninst.exe"
Security Update for Windows Internet Explorer 7 (KB939653)–>"C:\WINDOWS\ie7updates\KB939653-IE7\spuninst\spuninst.exe"
Security Update for Windows Internet Explorer 7 (KB953838)–>"C:\WINDOWS\ie7updates\KB953838-IE7\spuninst\spuninst.exe"
Security Update for Windows Internet Explorer 7 (KB956390)–>"C:\WINDOWS\ie7updates\KB956390-IE7\spuninst\spuninst.exe"
Security Update for Windows Media Player (KB911564)–>"C:\WINDOWS\$NtUninstallKB911564$\spuninst\spuninst.exe"
Security Update for Windows Media Player 10 (KB911565)–>"C:\WINDOWS\$NtUninstallKB911565$\spuninst\spuninst.exe"
Security Update for Windows Media Player 10 (KB917734)–>"C:\WINDOWS\$NtUninstallKB917734_WMP10$\spuninst\spuninst.exe"
Security Update for Windows Media Player 10 (KB936782)–>"C:\WINDOWS\$NtUninstallKB936782_WMP10$\spuninst\spuninst.exe"
Security Update for Windows Media Player 11 (KB936782)–>"C:\WINDOWS\$NtUninstallKB936782_WMP11$\spuninst\spuninst.exe"
Security Update for Windows Media Player 11 (KB954154)–>"C:\WINDOWS\$NtUninstallKB954154_WM11$\spuninst\spuninst.exe"
Security Update for Windows Media Player 6.4 (KB925398)–>"C:\WINDOWS\$NtUninstallKB925398_WMP64$\spuninst\spuninst.exe"
Security Update for Windows XP (KB896358)–>"C:\WINDOWS\$NtUninstallKB896358$\spuninst\spuninst.exe"
Security Update for Windows XP (KB896423)–>"C:\WINDOWS\$NtUninstallKB896423$\spuninst\spuninst.exe"
Security Update for Windows XP (KB896424)–>"C:\WINDOWS\$NtUninstallKB896424$\spuninst\spuninst.exe"
Security Update for Windows XP (KB896688)–>"C:\WINDOWS\$NtUninstallKB896688$\spuninst\spuninst.exe"
Security Update for Windows XP (KB899589)–>"C:\WINDOWS\$NtUninstallKB899589$\spuninst\spuninst.exe"
Security Update for Windows XP (KB900725)–>"C:\WINDOWS\$NtUninstallKB900725$\spuninst\spuninst.exe"
Security Update for Windows XP (KB901017)–>"C:\WINDOWS\$NtUninstallKB901017$\spuninst\spuninst.exe"
Security Update for Windows XP (KB902400)–>"C:\WINDOWS\$NtUninstallKB902400$\spuninst\spuninst.exe"
Security Update for Windows XP (KB904706)–>"C:\WINDOWS\$NtUninstallKB904706$\spuninst\spuninst.exe"
Security Update for Windows XP (KB905414)–>"C:\WINDOWS\$NtUninstallKB905414$\spuninst\spuninst.exe"
Security Update for Windows XP (KB905749)–>"C:\WINDOWS\$NtUninstallKB905749$\spuninst\spuninst.exe"
Security Update for Windows XP (KB905915)–>"C:\WINDOWS\$NtUninstallKB905915$\spuninst\spuninst.exe"
Security Update for Windows XP (KB908519)–>"C:\WINDOWS\$NtUninstallKB908519$\spuninst\spuninst.exe"
Security Update for Windows XP (KB908531)–>"C:\WINDOWS\$NtUninstallKB908531$\spuninst\spuninst.exe"
Security Update for Windows XP (KB911280)–>"C:\WINDOWS\$NtUninstallKB911280$\spuninst\spuninst.exe"
Security Update for Windows XP (KB911562)–>"C:\WINDOWS\$NtUninstallKB911562$\spuninst\spuninst.exe"
Security Update for Windows XP (KB911567)–>"C:\WINDOWS\$NtUninstallKB911567$\spuninst\spuninst.exe"
Security Update for Windows XP (KB911927)–>"C:\WINDOWS\$NtUninstallKB911927$\spuninst\spuninst.exe"
Security Update for Windows XP (KB912812)–>"C:\WINDOWS\$NtUninstallKB912812$\spuninst\spuninst.exe"
Security Update for Windows XP (KB912919)–>"C:\WINDOWS\$NtUninstallKB912919$\spuninst\spuninst.exe"
Security Update for Windows XP (KB913433)–>C:\WINDOWS\system32\MacroMed\Flash\genuinst.exe C:\WINDOWS\system32\MacroMed\Flash\KB913433.inf
Security Update for Windows XP (KB913580)–>"C:\WINDOWS\$NtUninstallKB913580$\spuninst\spuninst.exe"
Security Update for Windows XP (KB914388)–>"C:\WINDOWS\$NtUninstallKB914388$\spuninst\spuninst.exe"
Security Update for Windows XP (KB914389)–>"C:\WINDOWS\$NtUninstallKB914389$\spuninst\spuninst.exe"
Security Update for Windows XP (KB916281)–>"C:\WINDOWS\$NtUninstallKB916281$\spuninst\spuninst.exe"
Security Update for Windows XP (KB917159)–>"C:\WINDOWS\$NtUninstallKB917159$\spuninst\spuninst.exe"
Security Update for Windows XP (KB917344)–>"C:\WINDOWS\$NtUninstallKB917344$\spuninst\spuninst.exe"
Security Update for Windows XP (KB917422)–>"C:\WINDOWS\$NtUninstallKB917422$\spuninst\spuninst.exe"
Security Update for Windows XP (KB917537)–>"C:\WINDOWS\$NtUninstallKB917537$\spuninst\spuninst.exe"
Security Update for Windows XP (KB917953)–>"C:\WINDOWS\$NtUninstallKB917953$\spuninst\spuninst.exe"
Security Update for Windows XP (KB918118)–>"C:\WINDOWS\$NtUninstallKB918118$\spuninst\spuninst.exe"
Security Update for Windows XP (KB918439)–>"C:\WINDOWS\$NtUninstallKB918439$\spuninst\spuninst.exe"
Security Update for Windows XP (KB919007)–>"C:\WINDOWS\$NtUninstallKB919007$\spuninst\spuninst.exe"
Security Update for Windows XP (KB920213)–>"C:\WINDOWS\$NtUninstallKB920213$\spuninst\spuninst.exe"
Security Update for Windows XP (KB920670)–>"C:\WINDOWS\$NtUninstallKB920670$\spuninst\spuninst.exe"
Security Update for Windows XP (KB920683)–>"C:\WINDOWS\$NtUninstallKB920683$\spuninst\spuninst.exe"
Security Update for Windows XP (KB920685)–>"C:\WINDOWS\$NtUninstallKB920685$\spuninst\spuninst.exe"
Security Update for Windows XP (KB921398)–>"C:\WINDOWS\$NtUninstallKB921398$\spuninst\spuninst.exe"
Security Update for Windows XP (KB921503)–>"C:\WINDOWS\$NtUninstallKB921503$\spuninst\spuninst.exe"
Security Update for Windows XP (KB922616)–>"C:\WINDOWS\$NtUninstallKB922616$\spuninst\spuninst.exe"
Security Update for Windows XP (KB922819)–>"C:\WINDOWS\$NtUninstallKB922819$\spuninst\spuninst.exe"
Security Update for Windows XP (KB923191)–>"C:\WINDOWS\$NtUninstallKB923191$\spuninst\spuninst.exe"
Security Update for Windows XP (KB923414)–>"C:\WINDOWS\$NtUninstallKB923414$\spuninst\spuninst.exe"
Security Update for Windows XP (KB923689)–>"C:\WINDOWS\$NtUninstallKB923689$\spuninst\spuninst.exe"
Security Update for Windows XP (KB923694)–>"C:\WINDOWS\$NtUninstallKB923694$\spuninst\spuninst.exe"
Security Update for Windows XP (KB923980)–>"C:\WINDOWS\$NtUninstallKB923980$\spuninst\spuninst.exe"
Security Update for Windows XP (KB924191)–>"C:\WINDOWS\$NtUninstallKB924191$\spuninst\spuninst.exe"
Security Update for Windows XP (KB924270)–>"C:\WINDOWS\$NtUninstallKB924270$\spuninst\spuninst.exe"
Security Update for Windows XP (KB924667)–>"C:\WINDOWS\$NtUninstallKB924667$\spuninst\spuninst.exe"
Security Update for Windows XP (KB925902)–>"C:\WINDOWS\$NtUninstallKB925902$\spuninst\spuninst.exe"
Security Update for Windows XP (KB926255)–>"C:\WINDOWS\$NtUninstallKB926255$\spuninst\spuninst.exe"
Security Update for Windows XP (KB926436)–>"C:\WINDOWS\$NtUninstallKB926436$\spuninst\spuninst.exe"
Security Update for Windows XP (KB927779)–>"C:\WINDOWS\$NtUninstallKB927779$\spuninst\spuninst.exe"
Security Update for Windows XP (KB927802)–>"C:\WINDOWS\$NtUninstallKB927802$\spuninst\spuninst.exe"
Security Update for Windows XP (KB928255)–>"C:\WINDOWS\$NtUninstallKB928255$\spuninst\spuninst.exe"
Security Update for Windows XP (KB928843)–>"C:\WINDOWS\$NtUninstallKB928843$\spuninst\spuninst.exe"
Security Update for Windows XP (KB929123)–>"C:\WINDOWS\$NtUninstallKB929123$\spuninst\spuninst.exe"
Security Update for Windows XP (KB930178)–>"C:\WINDOWS\$NtUninstallKB930178$\spuninst\spuninst.exe"
Security Update for Windows XP (KB931261)–>"C:\WINDOWS\$NtUninstallKB931261$\spuninst\spuninst.exe"
Security Update for Windows XP (KB931784)–>"C:\WINDOWS\$NtUninstallKB931784$\spuninst\spuninst.exe"
Security Update for Windows XP (KB932168)–>"C:\WINDOWS\$NtUninstallKB932168$\spuninst\spuninst.exe"
Security Update for Windows XP (KB933729)–>"C:\WINDOWS\$NtUninstallKB933729$\spuninst\spuninst.exe"
Security Update for Windows XP (KB935839)–>"C:\WINDOWS\$NtUninstallKB935839$\spuninst\spuninst.exe"
Security Update for Windows XP (KB935840)–>"C:\WINDOWS\$NtUninstallKB935840$\spuninst\spuninst.exe"
Security Update for Windows XP (KB936021)–>"C:\WINDOWS\$NtUninstallKB936021$\spuninst\spuninst.exe"
Security Update for Windows XP (KB938464)–>"C:\WINDOWS\$NtUninstallKB938464$\spuninst\spuninst.exe"
Security Update for Windows XP (KB938829)–>"C:\WINDOWS\$NtUninstallKB938829$\spuninst\spuninst.exe"
Security Update for Windows XP (KB941202)–>"C:\WINDOWS\$NtUninstallKB941202$\spuninst\spuninst.exe"
Security Update for Windows XP (KB941569)–>"C:\WINDOWS\$NtUninstallKB941569$\spuninst\spuninst.exe"
Security Update for Windows XP (KB944653)–>"C:\WINDOWS\$NtUninstallKB944653$\spuninst\spuninst.exe"
Security Update for Windows XP (KB946648)–>"C:\WINDOWS\$NtUninstallKB946648$\spuninst\spuninst.exe"
Security Update for Windows XP (KB950749)–>"C:\WINDOWS\$NtUninstallKB950749$\spuninst\spuninst.exe"
Security Update for Windows XP (KB950762)–>"C:\WINDOWS\$NtUninstallKB950762$\spuninst\spuninst.exe"
Security Update for Windows XP (KB950974)–>"C:\WINDOWS\$NtUninstallKB950974$\spuninst\spuninst.exe"
Security Update for Windows XP (KB951066)–>"C:\WINDOWS\$NtUninstallKB951066$\spuninst\spuninst.exe"
Security Update for Windows XP (KB951376-v2)–>"C:\WINDOWS\$NtUninstallKB951376-v2$\spuninst\spuninst.exe"
Security Update for Windows XP (KB951698)–>"C:\WINDOWS\$NtUninstallKB951698$\spuninst\spuninst.exe"
Security Update for Windows XP (KB951748)–>"C:\WINDOWS\$NtUninstallKB951748$\spuninst\spuninst.exe"
Security Update for Windows XP (KB952954)–>"C:\WINDOWS\$NtUninstallKB952954$\spuninst\spuninst.exe"
Security Update for Windows XP (KB953839)–>"C:\WINDOWS\$NtUninstallKB953839$\spuninst\spuninst.exe"
Security Update for Windows XP (KB954211)–>"C:\WINDOWS\$NtUninstallKB954211$\spuninst\spuninst.exe"
Security Update for Windows XP (KB955069)–>"C:\WINDOWS\$NtUninstallKB955069$\spuninst\spuninst.exe"
Security Update for Windows XP (KB956391)–>"C:\WINDOWS\$NtUninstallKB956391$\spuninst\spuninst.exe"
Security Update for Windows XP (KB956803)–>"C:\WINDOWS\$NtUninstallKB956803$\spuninst\spuninst.exe"
Security Update for Windows XP (KB956841)–>"C:\WINDOWS\$NtUninstallKB956841$\spuninst\spuninst.exe"
Security Update for Windows XP (KB957095)–>"C:\WINDOWS\$NtUninstallKB957095$\spuninst\spuninst.exe"
Security Update for Windows XP (KB957097)–>"C:\WINDOWS\$NtUninstallKB957097$\spuninst\spuninst.exe"
Security Update for Windows XP (KB958644)–>"C:\WINDOWS\$NtUninstallKB958644$\spuninst\spuninst.exe"
Soft Data Fax Modem with SmartCP–>C:\Program Files\CONEXANT\CNXT_MODEM_PCI_VEN_14F1&DEV;_2F40&SUBSYS;_200014F1\HXFSETUP.EXE -U -IPDBRYCM5K.inf
Sonic Encoders–>MsiExec.exe /I{9941F0AA-B903-4AF4-A055-83A9815CC011}
SpongeBob SquarePants Typing–>C:\WINDOWS\TLCUninstall.exe -f "C:\Program Files\The Learning Company\SpongeBob SquarePants Typing\Uninstall.xml"
Tradewinds–>"C:\Program Files\Gateway Games\Tradewinds\Uninstall.exe"
Uninstall Dell PC Fax–>RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\engine\6\INTEL3~1\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{11A80E40-621F-489C-A626-58886B60FEAC}\Setup.exe" -l0x9 -remove_all
Update for Windows Media Player 10 (KB910393)–>"C:\WINDOWS\$NtUninstallKB910393$\spuninst\spuninst.exe"
Update for Windows Media Player 10 (KB913800)–>"C:\WINDOWS\$NtUninstallKB913800$\spuninst\spuninst.exe"
Update for Windows Media Player 10 (KB926251)–>"C:\WINDOWS\$NtUninstallKB926251$\spuninst\spuninst.exe"
Update for Windows XP (KB898461)–>"C:\WINDOWS\$NtUninstallKB898461$\spuninst\spuninst.exe"
Update for Windows XP (KB900485)–>"C:\WINDOWS\$NtUninstallKB900485$\spuninst\spuninst.exe"
Update for Windows XP (KB904942)–>"C:\WINDOWS\$NtUninstallKB904942$\spuninst\spuninst.exe"
Update for Windows XP (KB910437)–>"C:\WINDOWS\$NtUninstallKB910437$\spuninst\spuninst.exe"
Update for Windows XP (KB912945)–>"C:\WINDOWS\$NtUninstallKB912945$\spuninst\spuninst.exe"
Update for Windows XP (KB916595)–>"C:\WINDOWS\$NtUninstallKB916595$\spuninst\spuninst.exe"
Update for Windows XP (KB920872)–>"C:\WINDOWS\$NtUninstallKB920872$\spuninst\spuninst.exe"
Update for Windows XP (KB922582)–>"C:\WINDOWS\$NtUninstallKB922582$\spuninst\spuninst.exe"
Update for Windows XP (KB927891)–>"C:\WINDOWS\$NtUninstallKB927891$\spuninst\spuninst.exe"
Update for Windows XP (KB929338)–>"C:\WINDOWS\$NtUninstallKB929338$\spuninst\spuninst.exe"
Update for Windows XP (KB930916)–>"C:\WINDOWS\$NtUninstallKB930916$\spuninst\spuninst.exe"
Update for Windows XP (KB931836)–>"C:\WINDOWS\$NtUninstallKB931836$\spuninst\spuninst.exe"
Update for Windows XP (KB932823-v3)–>"C:\WINDOWS\$NtUninstallKB932823-v3$\spuninst\spuninst.exe"
Update for Windows XP (KB933360)–>"C:\WINDOWS\$NtUninstallKB933360$\spuninst\spuninst.exe"
Update for Windows XP (KB936357)–>"C:\WINDOWS\$NtUninstallKB936357$\spuninst\spuninst.exe"
Update for Windows XP (KB938828)–>"C:\WINDOWS\$NtUninstallKB938828$\spuninst\spuninst.exe"
Update for Windows XP (KB951072-v2)–>"C:\WINDOWS\$NtUninstallKB951072-v2$\spuninst\spuninst.exe"
Update Rollup 2 for Windows XP Media Center Edition 2005–>C:\WINDOWS\$NtUninstallKB900325$\spuninst\spuninst.exe
Viewpoint Media Player–>C:\Program Files\Viewpoint\Viewpoint Experience Technology\mtsAxInstaller.exe /u
WildTangent Web Driver–>C:\Program Files\WildTangent\Apps\CDA\CDAUninstall.exe
Windows Defender–>MsiExec.exe /I{A06275F4-324B-4E85-95E6-87B2CD729401}
Windows Internet Explorer 7–>"C:\WINDOWS\ie7\spuninst\spuninst.exe"
Windows Live installer–>MsiExec.exe /X{A7E4ECCA-4A8E-4258-8EC8-2DCCF5B11320}
Windows Live Sign-in Assistant–>MsiExec.exe /I{AFA4E5FD-ED70-4D92-99D0-162FD56DC986}
Windows Media Format 11 runtime–>"C:\Program Files\Windows Media Player\wmsetsdk.exe" /UninstallAll
Windows Media Format 11 runtime–>"C:\WINDOWS\$NtUninstallWMFDist11$\spuninst\spuninst.exe"
Windows Media Player 11–>"C:\Program Files\Windows Media Player\Setup_wm.exe" /Uninstall
Windows Media Player 11–>"C:\WINDOWS\$NtUninstallwmp11$\spuninst\spuninst.exe"
Windows XP Hotfix - KB886185–>C:\WINDOWS\$NtUninstallKB886185$\spuninst\spuninst.exe
Windows XP Media Center Edition 2005 KB925766–>"C:\WINDOWS\$NtUninstallKB925766$\spuninst\spuninst.exe"

======Security center information======

AV: CA Anti-Virus
FW: CA Personal Firewall

======Environment variables======

"ComSpec"=%SystemRoot%\system32\cmd.exe
"Path"=%SystemRoot%\system32;%SystemRoot%;%SystemRoot%\System32\Wbem;C:\Program Files\QuickTime\QTSystem\
"windir"=%SystemRoot%
"FP_NO_HOST_CHECK"=NO
"OS"=Windows_NT
"PROCESSOR_ARCHITECTURE"=x86
"PROCESSOR_LEVEL"=15
"PROCESSOR_IDENTIFIER"=x86 Family 15 Model 4 Stepping 7, GenuineIntel
"PROCESSOR_REVISION"=0407
"NUMBER_OF_PROCESSORS"=2
"PATHEXT"=.COM;.EXE;.BAT;.CMD;.VBS;.VBE;.JS;.JSE;.WSF;.WSH
"TEMP"=%SystemRoot%\TEMP
"TMP"=%SystemRoot%\TEMP
"CLASSPATH"=.;C:\Program Files\Java\jre1.5.0_02\lib\ext\QTJava.zip
"QTJAVA"=C:\Program Files\Java\jre1.5.0_02\lib\ext\QTJava.zip

—————–EOF—————–
And my Malawarebytes log:



Malwarebytes' Anti-Malware 1.30
Database version: 1417
Windows 5.1.2600 Service Pack 2

11/27/2008 8:30:34 AM
mbam-log-2008-11-27 (08-30-34).txt

Scan type: Quick Scan
Objects scanned: 82538
Time elapsed: 26 minute(s), 34 second(s)

Memory Processes Infected: 0
Memory Modules Infected: 0
Registry Keys Infected: 0
Registry Values Infected: 1
Registry Data Items Infected: 0
Folders Infected: 0
Files Infected: 1

Memory Processes Infected:
(No malicious items detected)

Memory Modules Infected:
(No malicious items detected)

Registry Keys Infected:
(No malicious items detected)

Registry Values Infected:
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\bofakidibe (Trojan.Agent) -> Quarantined and deleted successfully.

Registry Data Items Infected:
(No malicious items detected)

Folders Infected:
(No malicious items detected)

Files Infected:
C:\WINDOWS\system32\FBw54VXH.exe.a_a (Trojan.Agent) -> Quarantined and deleted successfully
Hi dejaylos,

We will use Combofix for the next part of the cleaning.

Please visit this webpage for download links, and instructions for running the tool and installing the recovery console:

http://www.bleepingcomputer.com/combofix/how-to-use-combofix

* Ensure you have disabled all anti virus and anti malware programs so they do not interfere with the running of ComboFix. If you are unsure of how to disable these programs, please refer to this page for details.

Please note you have Service pack 2 installed.

In your case the programs to disable are:

1. WINDOWS DEFENDER
  • Click Start > Programs > Windows Defender or launch from the system tray icon.
  • Click on Tools & Settings > Options.
  • Under Real-time protection options, uncheck the "Real-time protection" check box.
  • Click Save.
  • Go to Start > Control Panel > Security > Windows Defender, at the bottom of the Window Defenders page uncheck under Administrator Options "use Windows Defender" and then Save.
  • (When we are done, you can re-enable Defender using the same steps but this time place a check next to "Turn on real-time protection" check box.)

2. CA antivirus
Click on Start–> Run–> type in services.msc, hit enter
  • In the list of services try to Stop the CAISafe service.
  • When you try to stop this service, it will ask you to stop VET messaging service also. So stop that service also. This will disables the Realtime protection feature of CA AntiVirus.

3. CA Personal Firewall
Please navigate to the system tray on the bottom right hand corner and look for the following [external image: Posted Image] sign.
  • Right click it-> hover (mouse-over) over CA Personal Firewall menue option. A sub-menu will popup.
  • Please chose "Disable CA Personal Firewall"
  • Unfortunately the system tray icon does not change, so if you want to double-check whether or not you successfully disabled the Firewall, do the above steps again and look for "Enable CA Personal Firewall." If this is the case, then you succesfully disabled the CA Personal Firewall Guard.

After you have finished with Combofix, open HJT (hijackthis), click "Do a system scan and save a logfile". When the scan is complete a notepad will open, Please post the notepad's contents and the combofix log in your next reply.

Thanks.
Hello,

Attached are the logs requested:

Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 6:49:49 PM, on 11/28/2008
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16735)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Windows Defender\MsMpEng.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\CA\SharedComponents\HIPSEngine\UmxCfg.exe
C:\Program Files\CA\SharedComponents\HIPSEngine\UmxFwHlp.exe
C:\Program Files\CA\SharedComponents\HIPSEngine\UmxPol.exe
C:\Program Files\CA\SharedComponents\HIPSEngine\UmxAgent.exe
C:\Program Files\Common Files\AOL\ACS\AOLAcsd.exe
C:\Program Files\Common Files\AOL\TopSpeed\2.0\aoltsmon.exe
C:\Program Files\CA\CA Internet Security Suite\CA Anti-Virus\ISafe.exe
C:\WINDOWS\eHome\ehRecvr.exe
C:\WINDOWS\eHome\ehSched.exe
C:\Program Files\CA\SharedComponents\PPRT\bin\ITMRTSVC.exe
C:\Program Files\Common Files\New Boundary\PrismXL\PRISMXL.SYS
C:\WINDOWS\system32\svchost.exe
C:\Program Files\CA\CA Internet Security Suite\CA Anti-Virus\VetMsg.exe
C:\WINDOWS\system32\dllhost.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\Program Files\CA\CA Internet Security Suite\CA Personal Firewall\capfsem.exe
C:\WINDOWS\ehome\ehtray.exe
C:\WINDOWS\RTHDCPL.EXE
C:\WINDOWS\zHotkey.exe
C:\WINDOWS\eHome\ehmsas.exe
C:\Program Files\HP\HP Software Update\HPWuSchd2.exe
C:\PROGRAM FILES\DELL\DELL LASER MFP 1815\PSU\Scan2Pc.exe
C:\Program Files\QuickTime\QTTask.exe
C:\Program Files\iTunes\iTunesHelper.exe
C:\Program Files\Common Files\AOL\ACS\AOLDial.exe
C:\PROGRA~1\COMMON~1\AOL\AOLSPY~1\AOLSP Scheduler.exe
C:\Program Files\CA\CA Internet Security Suite\CA Anti-Spam\QSP-5.1.18.0\QOELoader.exe
C:\Program Files\CA\CA Internet Security Suite\CA Anti-Virus\CAVRID.exe
C:\Program Files\CA\CA Internet Security Suite\CA Personal Firewall\capfasem.exe
C:\Program Files\Messenger\msmsgs.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe
C:\WINDOWS\system32\wuauclt.exe
C:\PROGRA~1\COMMON~1\AOL\121562~1\EE\AOLHOS~1.EXE
C:\Program Files\iPod\bin\iPodService.exe
C:\PROGRA~1\COMMON~1\AOL\121562~1\EE\AOLServiceHost.exe
C:\Program Files\HP\Digital Imaging\bin\hpqSTE08.exe
C:\Program Files\CA\CA Internet Security Suite\CA Anti-Spyware\CAPPActiveProtection.exe
C:\Program Files\CA\CA Internet Security Suite\CA Anti-Spyware\PPCtlPriv.exe
C:\WINDOWS\system32\msiexec.exe
C:\Program Files\CA\CA Internet Security Suite\ccprovsp.exe
C:\Program Files\Common Files\Microsoft Shared\Source Engine\OSE.EXE
C:\WINDOWS\explorer.exe
C:\Program Files\Internet Explorer\IEXPLORE.EXE
C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLLoginProxy.exe
C:\WINDOWS\system32\wuauclt.exe
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe
C:\WINDOWS\system32\MsiExec.exe

R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
O2 - BHO: Windows Live Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
O3 - Toolbar: AOL Toolbar - {4982D40A-C53B-4615-B15B-B5B5E98D167C} - C:\Program Files\AOL Toolbar\toolbar.dll
O3 - Toolbar: &Google; - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar1.dll
O4 - HKLM\..\Run: [ehTray] C:\WINDOWS\ehome\ehtray.exe
O4 - HKLM\..\Run: [RTHDCPL] RTHDCPL.EXE
O4 - HKLM\..\Run: [CHotkey] zHotkey.exe
O4 - HKLM\..\Run: [Recguard] %WINDIR%\SMINST\RECGUARD.EXE
O4 - HKLM\..\Run: [HP Software Update] C:\Program Files\HP\HP Software Update\HPWuSchd2.exe
O4 - HKLM\..\Run: [MFP1815_S2P] C:\PROGRAM FILES\DELL\DELL LASER MFP 1815\PSU\Scan2Pc.exe
O4 - HKLM\..\Run: [SSBkgdUpdate] "C:\Program Files\Common Files\Scansoft Shared\SSBkgdUpdate\SSBkgdupdate.exe" -Embedding -boot
O4 - HKLM\..\Run: [PaperPort PTD] "C:\Program Files\DELL\Dell Laser MFP 1815\PaperPort\pptd40nt.exe"
O4 - HKLM\..\Run: [IndexSearch] "C:\Program Files\DELL\Dell Laser MFP 1815\PaperPort\IndexSearch.exe"
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\QTTask.exe" -atboottime
O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
O4 - HKLM\..\Run: [MSKDetectorExe] C:\Program Files\McAfee\SpamKiller\MSKDetct.exe /uninstall
O4 - HKLM\..\Run: [HostManager] C:\Program Files\Common Files\AOL\1215622490\EE\AOLHostManager.exe
O4 - HKLM\..\Run: [AOLDialer] C:\Program Files\Common Files\AOL\ACS\AOLDial.exe
O4 - HKLM\..\Run: [AOL Spyware Protection] "C:\PROGRA~1\COMMON~1\AOL\AOLSPY~1\AOLSP Scheduler.exe"
O4 - HKLM\..\Run: [cctray] "C:\Program Files\CA\CA Internet Security Suite\cctray\cctray.exe"
O4 - HKLM\..\Run: [QOELOADER] "C:\Program Files\CA\CA Internet Security Suite\CA Anti-Spam\QSP-5.1.18.0\QOELoader.exe"
O4 - HKLM\..\Run: [CAVRID] "C:\Program Files\CA\CA Internet Security Suite\CA Anti-Virus\CAVRID.exe"
O4 - HKLM\..\Run: [cafwc] C:\Program Files\CA\CA Internet Security Suite\CA Personal Firewall\cafw.exe -cl
O4 - HKLM\..\Run: [capfasem] C:\Program Files\CA\CA Internet Security Suite\CA Personal Firewall\capfasem.exe
O4 - HKLM\..\Run: [capfupgrade] C:\Program Files\CA\CA Internet Security Suite\CA Personal Firewall\capfupgrade.exe
O4 - HKCU\..\Run: [Power2GoExpress] NA
O4 - HKCU\..\Run: [updateMgr] C:\Program Files\Adobe\Acrobat 7.0\Reader\AdobeUpdateManager.exe AcRdB7_0_9
O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [swg] C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
O4 - HKCU\..\Run: [DW6] "C:\Program Files\The Weather Channel FW\Desktop\DesktopWeather.exe"
O4 - Global Startup: Adobe Reader Speed Launch.lnk = C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
O4 - Global Startup: HP Digital Imaging Monitor.lnk = C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe
O8 - Extra context menu item: &AOL; Toolbar search - res://C:\Program Files\AOL Toolbar\toolbar.dll/SEARCH.HTML
O8 - Extra context menu item: E&xport; to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
O9 - Extra button: AOL Toolbar - {4982D40A-C53B-4615-B15B-B5B5E98D167C} - C:\Program Files\AOL Toolbar\toolbar.dll
O9 - Extra 'Tools' menuitem: AOL Toolbar - {4982D40A-C53B-4615-B15B-B5B5E98D167C} - C:\Program Files\AOL Toolbar\toolbar.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL
O9 - Extra button: Real.com - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - C:\WINDOWS\system32\Shdocvw.dll
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O16 - DPF: {1663ed61-23eb-11d2-b92f-008048fdd814} (MeadCo ScriptX Advanced) - https://eagent.farmersinsurance.com/PLA/eAg…ctiveX/smsx.cab
O16 - DPF: {354D91A8-E3C9-491F-BB89-0FB27DEEED86} (ImgXTwain6.ImgXTwain) - https://eagent.farmersinsurance.com/PLA/eAg…ImgXTwain61.cab
O16 - DPF: {45EEDB84-57BC-4FBD-8065-7AB8E971B545} (ImgXDialog6.ImgXDialog) - https://eagent.farmersinsurance.com/PLA/eAg…mgXDialog61.cab
O16 - DPF: {7E8DC73D-69CD-4F67-99B1-8DC6E42F6246} (Atalasoft ImgXCtrl6.ImgXCtrl (CAB)) - https://eagent.farmersinsurance.com/PLA/eAg…iveX/ImgX61.cab
O23 - Service: AOL Connectivity Service (AOL ACS) - America Online - C:\Program Files\Common Files\AOL\ACS\AOLAcsd.exe
O23 - Service: AOL TopSpeed Monitor (AOL TopSpeedMonitor) - America Online, Inc - C:\Program Files\Common Files\AOL\TopSpeed\2.0\aoltsmon.exe
O23 - Service: AOL Spyware Protection Service (AOLService) - Unknown owner - C:\PROGRA~1\COMMON~1\AOL\AOLSPY~1\\aolserv.exe
O23 - Service: Ati HotKey Poller - ATI Technologies Inc. - C:\WINDOWS\system32\Ati2evxx.exe
O23 - Service: ATI Smart - Unknown owner - C:\WINDOWS\system32\ati2sgag.exe
O23 - Service: CaCCProvSP - CA, Inc. - C:\Program Files\CA\CA Internet Security Suite\ccprovsp.exe
O23 - Service: CAISafe - Computer Associates International, Inc. - C:\Program Files\CA\CA Internet Security Suite\CA Anti-Virus\ISafe.exe
O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: iPod Service - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: CA Pest Patrol Realtime Protection Service (ITMRTSVC) - CA, Inc. - C:\Program Files\CA\SharedComponents\PPRT\bin\ITMRTSVC.exe
O23 - Service: Pml Driver HPZ12 - HP - C:\WINDOWS\system32\HPZipm12.exe
O23 - Service: PPCtlPriv - CA, Inc. - C:\Program Files\CA\CA Internet Security Suite\CA Anti-Spyware\PPCtlPriv.exe
O23 - Service: PrismXL - New Boundary Technologies, Inc. - C:\Program Files\Common Files\New Boundary\PrismXL\PRISMXL.SYS
O23 - Service: HIPS Event Manager (UmxAgent) - CA - C:\Program Files\CA\SharedComponents\HIPSEngine\UmxAgent.exe
O23 - Service: HIPS Configuration Interpreter (UmxCfg) - CA - C:\Program Files\CA\SharedComponents\HIPSEngine\UmxCfg.exe
O23 - Service: HIPS Firewall Helper (UmxFwHlp) - CA - C:\Program Files\CA\SharedComponents\HIPSEngine\UmxFwHlp.exe
O23 - Service: HIPS Policy Manager (UmxPol) - CA - C:\Program Files\CA\SharedComponents\HIPSEngine\UmxPol.exe
O23 - Service: VET Message Service (VETMSGNT) - CA, Inc. - C:\Program Files\CA\CA Internet Security Suite\CA Anti-Virus\VetMsg.exe

–
End of file - 10491 bytes
__________________________________________________________________________

And Combo Fix:


ComboFix 08-11-28.02 - Owner 2008-11-28 17:59:54.1 - NTFSx86
Microsoft Windows XP Professional 5.1.2600.2.1252.1.1033.18.112 [GMT -8:00]
Running from: c:\documents and settings\[removed]\Desktop\ComboFix.exe
Command switches used :: c:\documents and settings\Owner.LOPEZINSURANCE\Desktop\WindowsXP-KB310994-SP2-Home-BootDisk-ENU.exe
* Created a new restore point
.

((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.

C:\bold.log
c:\documents and settings\Owner.LOPEZINSURANCE\Local Settings\Temporary Internet Files\jocyne.vbs
c:\documents and settings\Owner.LOPEZINSURANCE\Local Settings\Temporary Internet Files\urukime.bat
c:\windows\Downloaded Program Files\setup.inf
c:\windows\system32\FBw54VXH.exe.a_a
c:\windows\system32\HDy21XAJ.dll
H:\Autorun.inf

.
((((((((((((((((((((((((( Files Created from 2008-10-28 to 2008-11-29 )))))))))))))))))))))))))))))))
.

2008-11-27 08:37 . 2008-11-27 08:37 d——– C:\rsit
2008-11-27 08:37 . 2008-11-27 08:42 d——– c:\program files\trend micro
2008-11-25 09:21 . 2008-11-25 09:21 d——– C:\VundoFix Backups
2008-11-25 08:44 . 2008-11-25 09:05 d——– c:\program files\Exterminate It!
2008-11-24 14:46 . 2008-11-24 14:46 d——– c:\program files\Windows Defender
2008-11-22 22:12 . 2008-11-22 22:12 d——– c:\program files\Malwarebytes' Anti-Malware
2008-11-22 22:12 . 2008-11-22 22:12 d——– c:\documents and settings\Owner.LOPEZINSURANCE\Application Data\Malwarebytes
2008-11-22 22:12 . 2008-11-22 22:12 d——– c:\documents and settings\All Users\Application Data\Malwarebytes
2008-11-22 22:12 . 2008-10-22 16:10 38,496 –a—— c:\windows\system32\drivers\mbamswissarmy.sys
2008-11-22 22:12 . 2008-10-22 16:10 15,504 –a—— c:\windows\system32\drivers\mbam.sys
2008-11-22 18:31 . 2008-11-22 18:31 d–hsc— c:\program files\Common Files\WindowsLiveInstaller
2008-11-22 18:31 . 2008-07-18 22:07 270,880 –a—— c:\windows\system32\mucltui.dll
2008-11-22 18:31 . 2008-07-18 22:07 210,976 –a—— c:\windows\system32\muweb.dll
2008-11-22 18:31 . 2008-07-18 22:07 29,728 –a—— c:\windows\system32\mucltui.dll.mui
2008-11-22 18:30 . 2008-11-22 18:30 d——– c:\program files\Windows Live
2008-11-22 18:29 . 2008-11-22 18:30 d——– c:\documents and settings\All Users\Application Data\WLInstaller
2008-11-13 18:20 . 2008-11-13 18:20 152 –a—— c:\windows\cdplayer.ini
2008-11-13 09:00 . 2008-11-28 18:16 45,522 –a—— c:\windows\system32\drivers\kmxcfg.u2k0
2008-11-13 09:00 . 2008-11-28 18:16 64 –a—— c:\windows\system32\drivers\kmxcfg.u2k7
2008-11-13 09:00 . 2008-11-28 18:16 64 –a—— c:\windows\system32\drivers\kmxcfg.u2k6
2008-11-13 09:00 . 2008-11-28 18:16 64 –a—— c:\windows\system32\drivers\kmxcfg.u2k5
2008-11-13 09:00 . 2008-11-28 18:16 64 –a—— c:\windows\system32\drivers\kmxcfg.u2k4
2008-11-13 09:00 . 2008-11-28 18:16 64 –a—— c:\windows\system32\drivers\kmxcfg.u2k3
2008-11-13 09:00 . 2008-11-28 18:16 64 –a—— c:\windows\system32\drivers\kmxcfg.u2k2
2008-11-13 09:00 . 2008-11-28 18:16 64 –a—— c:\windows\system32\drivers\kmxcfg.u2k1
2008-11-13 08:47 . 2008-11-28 18:25 d——– c:\windows\CAVTemp
2008-11-13 08:37 . 2008-11-13 08:37 880,560 –a—— c:\windows\system32\drivers\vetefile.sys
2008-11-13 08:37 . 2008-11-13 08:37 108,368 –a—— c:\windows\system32\drivers\veteboot.sys
2008-11-13 08:36 . 2007-08-20 13:37 99,592 –a—— c:\windows\system32\isafeif.dll
2008-11-13 08:36 . 2007-08-20 13:26 79,424 –a—— c:\windows\system32\vetredir.dll
2008-11-13 08:36 . 2007-08-20 13:37 75,016 –a—— c:\windows\system32\isafprod.dll
2008-11-13 08:36 . 2007-08-20 13:38 32,264 –a—— c:\windows\system32\drivers\vetmonnt.sys
2008-11-13 08:36 . 2007-08-20 13:38 26,376 –a—— c:\windows\system32\drivers\vet-filt.sys
2008-11-13 08:36 . 2007-08-20 13:38 21,512 –a—— c:\windows\system32\drivers\vetfddnt.sys
2008-11-13 08:36 . 2007-08-20 13:38 21,128 –a—— c:\windows\system32\drivers\vet-rec.sys
2008-11-13 08:35 . 2008-11-13 08:35 d——– c:\program files\Common Files\Scanner
2008-11-13 08:35 . 2008-11-13 08:35 d——– c:\program files\CA
2008-11-13 08:35 . 2008-11-13 08:45 d——– c:\documents and settings\All Users\Application Data\CA
2008-11-13 08:32 . 2008-11-13 08:32 d——– c:\documents and settings\OWNER~1~LOP\LOCALS~1
2008-11-13 08:32 . 2008-11-13 08:32 d——– c:\documents and settings\OWNER~1~LOP
2008-11-12 15:31 . 2008-11-12 15:31 19,853 –a—— c:\windows\mefaxysic._sy
2008-11-12 15:31 . 2008-11-12 15:31 18,743 –a—— c:\windows\gukugu.bat
2008-11-12 15:31 . 2008-11-12 15:31 17,187 –a—— c:\windows\system32\odopeci.bat
2008-11-12 15:31 . 2008-11-12 15:31 16,638 –a—— c:\windows\vehakyg.pif
2008-11-12 15:31 . 2008-11-12 15:31 12,822 –a—— c:\windows\yfisy.db
2008-11-12 15:31 . 2008-11-12 15:31 12,427 –a—— c:\documents and settings\All Users\Application Data\lyjysezivi.bat
2008-11-12 15:31 . 2008-11-12 15:31 12,214 –a—— c:\windows\ebamoz.db
2008-11-12 15:27 . 2004-08-10 11:00 4,224 –a–c— c:\windows\system32\dllcache\beep.sys
2008-11-12 08:53 . 2008-10-24 03:10 453,632 —–c— c:\windows\system32\dllcache\mrxsmb.sys
2008-11-11 20:17 . 2008-11-11 20:17 d——– c:\documents and settings\NetworkService\Application Data\AdobeUM
2008-11-02 13:14 . 2008-11-27 08:14 41,474 –a—— c:\windows\system32\FBw54VXH.exe_
2008-11-02 13:14 . 2008-11-27 10:14 41,474 –a—— c:\windows\system32\FBw54VXH.exe
2008-11-01 12:36 . 2008-11-01 12:35 31,744 –a—— c:\windows\system32\VIbh1Sv1.exe

.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2008-11-25 15:44 93,236 ——w c:\windows\system32\rafaweti.dll
2008-11-06 23:44 ——— d—–w c:\documents and settings\Owner.LOPEZINSURANCE\Application Data\PDF reDirect
2008-10-24 11:10 453,632 —-a-w c:\windows\system32\drivers\mrxsmb.sys
2008-10-18 23:25 ——— d—–w c:\program files\Rhapsody
2008-10-18 23:21 ——— d—–w c:\program files\Real
2008-10-18 17:03 ——— d—–w c:\program files\Windows Media Connect 2
2008-10-17 15:25 330 —-a-w c:\documents and settings\Owner.LOPEZINSURANCE\Application Data\wklnhst.dat
2008-10-15 16:26 ——— d—–w c:\documents and settings\Owner.LOPEZINSURANCE\Application Data\Template
2008-10-07 00:09 ——— d—–w c:\program files\The Weather Channel FW
2008-10-01 00:43 1,286,152 —-a-w c:\windows\system32\msxml4.dll
2008-09-15 11:57 1,846,016 —-a-w c:\windows\system32\win32k.sys
2008-09-04 16:42 1,106,944 —-a-w c:\windows\system32\msxml3.dll
2007-09-08 02:22 774,144 —-a-w c:\program files\RngInterstitial.dll
.

((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Power2GoExpress"="NA" [X]
"updateMgr"="c:\program files\Adobe\Acrobat 7.0\Reader\AdobeUpdateManager.exe" [2006-03-30 313472]
"MSMSGS"="c:\program files\Messenger\msmsgs.exe" [2004-10-13 1694208]
"ctfmon.exe"="c:\windows\system32\ctfmon.exe" [2004-08-10 15360]
"swg"="c:\program files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe" [2008-10-01 68856]
"DW6"="c:\program files\The Weather Channel FW\Desktop\DesktopWeather.exe" [2008-09-26 789616]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ehTray"="c:\windows\ehome\ehtray.exe" [2005-08-05 64512]
"Recguard"="c:\windows\SMINST\RECGUARD.EXE" [2002-09-13 212992]
"HP Software Update"="c:\program files\HP\HP Software Update\HPWuSchd2.exe" [2005-12-15 49152]
"MFP1815_S2P"="c:\program files\DELL\DELL LASER MFP 1815\PSU\Scan2Pc.exe" [2006-12-22 258952]
"SSBkgdUpdate"="c:\program files\Common Files\Scansoft Shared\SSBkgdUpdate\SSBkgdupdate.exe" [2003-10-14 155648]
"PaperPort PTD"="c:\program files\DELL\Dell Laser MFP 1815\PaperPort\pptd40nt.exe" [2006-02-20 36864]
"IndexSearch"="c:\program files\DELL\Dell Laser MFP 1815\PaperPort\IndexSearch.exe" [2006-02-20 40960]
"QuickTime Task"="c:\program files\QuickTime\QTTask.exe" [2007-06-29 286720]
"iTunesHelper"="c:\program files\iTunes\iTunesHelper.exe" [2007-07-10 270648]
"MSKDetectorExe"="c:\program files\McAfee\SpamKiller\MSKDetct.exe" [2006-11-07 1121280]
"HostManager"="c:\program files\Common Files\AOL\1215622490\EE\AOLHostManager.exe" [2004-11-03 125528]
"AOLDialer"="c:\program files\Common Files\AOL\ACS\AOLDial.exe" [2004-10-20 34904]
"AOL Spyware Protection"="c:\progra~1\COMMON~1\AOL\AOLSPY~1\AOLSP Scheduler.exe" [2004-10-18 79448]
"cctray"="c:\program files\CA\CA Internet Security Suite\cctray\cctray.exe" [2007-08-16 177416]
"QOELOADER"="c:\program files\CA\CA Internet Security Suite\CA Anti-Spam\QSP-5.1.18.0\QOELoader.exe" [2008-11-13 14088]
"CAVRID"="c:\program files\CA\CA Internet Security Suite\CA Anti-Virus\CAVRID.exe" [2007-08-20 230664]
"cafwc"="c:\program files\CA\CA Internet Security Suite\CA Personal Firewall\cafw.exe" [2008-11-13 1193200]
"capfasem"="c:\program files\CA\CA Internet Security Suite\CA Personal Firewall\capfasem.exe" [2008-11-13 173296]
"capfupgrade"="c:\program files\CA\CA Internet Security Suite\CA Personal Firewall\capfupgrade.exe" [2008-11-13 259312]
"RTHDCPL"="RTHDCPL.EXE" [2006-04-16 c:\windows\RTHDCPL.exe]
"CHotkey"="zHotkey.exe" [2004-12-08 c:\windows\zHotkey.exe]

c:\documents and settings\All Users\Start Menu\Programs\Startup\
Adobe Reader Speed Launch.lnk - c:\program files\Adobe\Acrobat 7.0\Reader\reader_sl.exe [2005-09-23 29696]
HP Digital Imaging Monitor.lnk - c:\program files\HP\Digital Imaging\bin\hpqtra08.exe [2005-12-15 282624]

[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\policies\explorer]
"ForceClassicControlPanel"= 1 (0x1)

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\PFW]
2007-05-18 13:30 79368 c:\windows\system32\UmxWNP.dll

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\drivers32]
"msacm.clmp3enc"= c:\progra~1\CYBERL~1\Power2Go\CLMP3Enc.ACM

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]
"EnableFirewall"= 0 (0x0)

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"c:\\Program Files\\Common Files\\AOL\\Loader\\aolload.exe"=
"c:\\Program Files\\Common Files\\AOL\\ACS\\AOLDial.exe"=
"c:\\Program Files\\Common Files\\AOL\\ACS\\AOLacsd.exe"=
"c:\\Program Files\\America Online 9.0\\waol.exe"=
"c:\\Program Files\\Common Files\\AOL\\TopSpeed\\2.0\\aoltsmon.exe"=
"c:\\Program Files\\Common Files\\AOL\\TopSpeed\\2.0\\aoltpspd.exe"=
"c:\\Program Files\\Common Files\\AOL\\System Information\\sinf.exe"=
"c:\\Program Files\\Common Files\\AOL\\AOL Spyware Protection\\AOLSP Scheduler.exe"=
"c:\\Program Files\\Common Files\\AOL\\AOL Spyware Protection\\asp.exe"=
"c:\\Program Files\\Common Files\\AolCoach\\en_en\\player\\AOLNySEV.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpqtra08.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpqste08.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpofxm08.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hposfx08.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hposid01.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpqscnvw.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpqkygrp.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpqCopy.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpfccopy.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpzwiz01.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\Unload\\HpqPhUnl.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\Unload\\HpqDIA.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpoews01.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpqnrs08.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"c:\\Program Files\\Messenger\\msmsgs.exe"=
"c:\\Program Files\\iTunes\\iTunes.exe"=
"c:\\Program Files\\Common Files\\AOL\\1215622490\\EE\\AOLServiceHost.exe"=
"c:\\WINDOWS\\system32\\FBw54VXH.exe"=

R0 KmxStart;KmxStart;c:\windows\system32\DRIVERS\kmxstart.sys [2008-06-24 93712]
R1 KmxAgent;KmxAgent;c:\windows\system32\DRIVERS\kmxagent.sys [2008-06-24 63504]
R1 KmxFile;KmxFile;c:\windows\system32\DRIVERS\KmxFile.sys [2008-06-24 45584]
R1 KmxFw;KmxFw;c:\windows\system32\DRIVERS\kmxfw.sys [2008-06-24 115216]
R2 KmxCF;KmxCF;c:\windows\system32\DRIVERS\KmxCF.sys [2008-06-24 134648]
R2 KmxSbx;KmxSbx;c:\windows\system32\DRIVERS\KmxSbx.sys [2008-06-24 66576]
R2 UmxAgent;HIPS Event Manager;"c:\program files\CA\SharedComponents\HIPSEngine\UmxAgent.exe" [2007-10-18 1010192]
R2 UmxCfg;HIPS Configuration Interpreter;"c:\program files\CA\SharedComponents\HIPSEngine\UmxCfg.exe" [2007-10-18 801296]
R2 UmxPol;HIPS Policy Manager;"c:\program files\CA\SharedComponents\HIPSEngine\UmxPol.exe" [2008-06-24 281104]
R3 KmxCfg;KmxCfg;c:\windows\system32\DRIVERS\kmxcfg.sys [2008-06-24 88816]
R3 PPCtlPriv;PPCtlPriv;"c:\program files\CA\CA Internet Security Suite\CA Anti-Spyware\PPCtlPriv.exe" [2007-08-16 189704]
S2 SSPORT;SSPORT;\??\c:\windows\system32\Drivers\SSPORT.sys []
S3 RimSerPort;RIM Virtual Serial Port;c:\windows\system32\DRIVERS\RimSerial.sys [2007-04-25 18432]

[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{935b3331-5323-11db-8b52-806d6172696f}]
\Shell\AutoRun\command - c:\windows\system32\RunDLL32.EXE Shell32.DLL,ShellExec_RunDLL Info.exe folder.htt 480 480
.
Contents of the 'Scheduled Tasks' folder

2008-11-26 c:\windows\Tasks\AppleSoftwareUpdate.job
- c:\program files\Apple Software Update\SoftwareUpdate.exe [2007-06-03 12:42]

2008-11-01 c:\windows\Tasks\At1.job
- c:\windows\system32\VIbh1Sv1.exe [2008-11-01 12:35]

2008-11-26 c:\windows\Tasks\At10.job
- c:\windows\system32\VIbh1Sv1.exe [2008-11-01 12:35]

2008-11-27 c:\windows\Tasks\At11.job
- c:\windows\system32\VIbh1Sv1.exe [2008-11-01 12:35]

2008-11-25 c:\windows\Tasks\At12.job
- c:\windows\system32\VIbh1Sv1.exe [2008-11-01 12:35]

2008-11-25 c:\windows\Tasks\At13.job
- c:\windows\system32\VIbh1Sv1.exe [2008-11-01 12:35]

2008-11-26 c:\windows\Tasks\At14.job
- c:\windows\system32\VIbh1Sv1.exe [2008-11-01 12:35]

2008-11-26 c:\windows\Tasks\At15.job
- c:\windows\system32\VIbh1Sv1.exe [2008-11-01 12:35]

2008-11-25 c:\windows\Tasks\At16.job
- c:\windows\system32\VIbh1Sv1.exe [2008-11-01 12:35]

2008-11-26 c:\windows\Tasks\At17.job
- c:\windows\system32\VIbh1Sv1.exe [2008-11-01 12:35]

2008-11-25 c:\windows\Tasks\At18.job
- c:\windows\system32\VIbh1Sv1.exe [2008-11-01 12:35]

2008-11-23 c:\windows\Tasks\At19.job
- c:\windows\system32\VIbh1Sv1.exe [2008-11-01 12:35]

2008-11-01 c:\windows\Tasks\At2.job
- c:\windows\system32\VIbh1Sv1.exe [2008-11-01 12:35]

2008-11-23 c:\windows\Tasks\At20.job
- c:\windows\system32\VIbh1Sv1.exe [2008-11-01 12:35]

2008-11-25 c:\windows\Tasks\At21.job
- c:\windows\system32\VIbh1Sv1.exe [2008-11-01 12:35]

2008-11-25 c:\windows\Tasks\At22.job
- c:\windows\system32\VIbh1Sv1.exe [2008-11-01 12:35]

2008-11-25 c:\windows\Tasks\At23.job
- c:\windows\system32\VIbh1Sv1.exe [2008-11-01 12:35]

2008-11-21 c:\windows\Tasks\At24.job
- c:\windows\system32\VIbh1Sv1.exe [2008-11-01 12:35]

2008-11-02 c:\windows\Tasks\At25.job
- c:\windows\system32\FBw54VXH.exe [2008-11-27 10:14]

2008-11-02 c:\windows\Tasks\At26.job
- c:\windows\system32\FBw54VXH.exe [2008-11-27 10:14]

2008-11-02 c:\windows\Tasks\At27.job
- c:\windows\system32\FBw54VXH.exe [2008-11-27 10:14]

2008-11-02 c:\windows\Tasks\At28.job
- c:\windows\system32\FBw54VXH.exe [2008-11-27 10:14]

2008-11-02 c:\windows\Tasks\At29.job
- c:\windows\system32\FBw54VXH.exe [2008-11-27 10:14]

2008-11-01 c:\windows\Tasks\At3.job
- c:\windows\system32\VIbh1Sv1.exe [2008-11-01 12:35]

2008-11-02 c:\windows\Tasks\At30.job
- c:\windows\system32\FBw54VXH.exe [2008-11-27 10:14]

2008-11-02 c:\windows\Tasks\At31.job
- c:\windows\system32\FBw54VXH.exe [2008-11-27 10:14]

2008-11-06 c:\windows\Tasks\At32.job
- c:\windows\system32\FBw54VXH.exe [2008-11-27 10:14]

2008-11-27 c:\windows\Tasks\At33.job
- c:\windows\system32\FBw54VXH.exe [2008-11-27 10:14]

2008-11-26 c:\windows\Tasks\At34.job
- c:\windows\system32\FBw54VXH.exe [2008-11-27 10:14]

2008-11-28 c:\windows\Tasks\At35.job
- c:\windows\system32\FBw54VXH.exe [2008-11-27 10:14]

2008-11-25 c:\windows\Tasks\At36.job
- c:\windows\system32\FBw54VXH.exe [2008-11-27 10:14]

2008-11-25 c:\windows\Tasks\At37.job
- c:\windows\system32\FBw54VXH.exe [2008-11-27 10:14]

2008-11-26 c:\windows\Tasks\At38.job
- c:\windows\system32\FBw54VXH.exe [2008-11-27 10:14]

2008-11-27 c:\windows\Tasks\At39.job
- c:\windows\system32\FBw54VXH.exe [2008-11-27 10:14]

2008-11-01 c:\windows\Tasks\At4.job
- c:\windows\system32\VIbh1Sv1.exe [2008-11-01 12:35]

2008-11-26 c:\windows\Tasks\At40.job
- c:\windows\system32\FBw54VXH.exe [2008-11-27 10:14]

2008-11-26 c:\windows\Tasks\At41.job
- c:\windows\system32\FBw54VXH.exe [2008-11-27 10:14]

2008-11-25 c:\windows\Tasks\At42.job
- c:\windows\system32\FBw54VXH.exe [2008-11-27 10:14]

2008-11-23 c:\windows\Tasks\At43.job
- c:\windows\system32\FBw54VXH.exe [2008-11-27 10:14]

2008-11-23 c:\windows\Tasks\At44.job
- c:\windows\system32\FBw54VXH.exe [2008-11-27 10:14]

2008-11-25 c:\windows\Tasks\At45.job
- c:\windows\system32\FBw54VXH.exe [2008-11-27 10:14]

2008-11-25 c:\windows\Tasks\At46.job
- c:\windows\system32\FBw54VXH.exe [2008-11-27 10:14]

2008-11-25 c:\windows\Tasks\At47.job
- c:\windows\system32\FBw54VXH.exe [2008-11-27 10:14]

2008-11-21 c:\windows\Tasks\At48.job
- c:\windows\system32\FBw54VXH.exe [2008-11-27 10:14]

2008-11-01 c:\windows\Tasks\At5.job
- c:\windows\system32\VIbh1Sv1.exe [2008-11-01 12:35]

2008-11-01 c:\windows\Tasks\At6.job
- c:\windows\system32\VIbh1Sv1.exe [2008-11-01 12:35]

2008-11-01 c:\windows\Tasks\At7.job
- c:\windows\system32\VIbh1Sv1.exe [2008-11-01 12:35]

2008-11-06 c:\windows\Tasks\At8.job
- c:\windows\system32\VIbh1Sv1.exe [2008-11-01 12:35]

2008-11-27 c:\windows\Tasks\At9.job
- c:\windows\system32\VIbh1Sv1.exe [2008-11-01 12:35]

2008-11-13 c:\windows\Tasks\CAAntiSpywareScan_Daily as Owner at 8 35 AM.job
- c:\program files\CA\CA Internet Security Suite\CA Anti-Spyware\CAAntiSpyware.exe [2007-08-16 21:10]

2008-11-29 c:\windows\Tasks\MP Scheduled Scan.job
- c:\program files\Windows Defender\MpCmdRun.exe [2006-11-03 19:20]
.
- - - - ORPHANS REMOVED - - - -

BHO-{85e6eb01-3bfd-4265-b6e3-e81c4be4bd37} - c:\windows\system32\nevorefa.dll



**************************************************************************

catchme 0.3.1367 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2008-11-28 18:18:59
Windows 5.1.2600 Service Pack 2 NTFS

scanning hidden processes …

scanning hidden autostart entries …

scanning hidden files …

scan completed successfully
hidden files: 0

**************************************************************************
.
——————— DLLs Loaded Under Running Processes ———————

- - - - - - - > 'winlogon.exe'(600)
c:\windows\system32\Ati2evxx.dll
c:\windows\system32\UmxWnp.Dll
c:\program files\CA\SharedComponents\PPRT\bin\CACheck.dll
c:\program files\CA\SharedComponents\PPRT\bin\CAHook.dll
c:\program files\CA\SharedComponents\PPRT\bin\CAServer.dll

- - - - - - - > 'lsass.exe'(848)
c:\windows\system32\VetRedir.dll
c:\windows\system32\ISafeIf.dll

- - - - - - - > 'explorer.exe'(1100)
c:\program files\CA\SharedComponents\PPRT\bin\CACheck.dll
c:\program files\CA\SharedComponents\PPRT\bin\CAHook.dll
c:\program files\CA\SharedComponents\PPRT\bin\CAServer.dll
c:\program files\Common Files\AOL\ACS\WLHook.dll
.
———————— Other Running Processes ————————
.
c:\windows\system32\ati2evxx.exe
c:\program files\Windows Defender\MsMpEng.exe
c:\program files\CA\SharedComponents\HIPSEngine\UmxFwHlp.exe
c:\program files\Common Files\AOL\ACS\AOLacsd.exe
c:\program files\Common Files\AOL\TopSpeed\2.0\aoltsmon.exe
c:\program files\Common Files\AOL\TopSpeed\2.0\aoltpspd.exe
c:\program files\CA\CA Internet Security Suite\CA Anti-Virus\isafe.exe
c:\windows\ehome\ehrecvr.exe
c:\windows\ehome\ehSched.exe
c:\program files\CA\SharedComponents\PPRT\bin\ITMRTSVC.exe
c:\program files\Common Files\New Boundary\PrismXL\PRISMXL.SYS
c:\program files\CA\CA Internet Security Suite\CA Anti-Virus\vetmsg.exe
c:\windows\ehome\mcrdsvc.exe
c:\windows\system32\dllhost.exe
c:\windows\system32\ati2evxx.exe
c:\program files\CA\CA Internet Security Suite\CA Personal Firewall\capfsem.exe
c:\windows\ehome\ehmsas.exe
c:\program files\iPod\bin\iPodService.exe
c:\progra~1\COMMON~1\AOL\121562~1\EE\AOLServiceHost.exe
c:\program files\HP\Digital Imaging\bin\hpqste08.exe
c:\program files\CA\CA Internet Security Suite\CA Anti-Spyware\CAPPActiveProtection.exe
c:\windows\system32\msiexec.exe
c:\program files\CA\CA Internet Security Suite\ccprovsp.exe
c:\program files\Common Files\Microsoft Shared\Source Engine\OSE.EXE
c:\windows\system32\msiexec.exe
c:\windows\system32\verclsid.exe
c:\windows\system32\drwtsn32.exe
.
**************************************************************************
.
Completion time: 2008-11-28 18:36:20 - machine was rebooted
ComboFix-quarantined-files.txt 2008-11-29 02:35:12

Pre-Run: 128,675,848,192 bytes free
Post-Run: 131,707,629,568 bytes free

WindowsXP-KB310994-SP2-Home-BootDisk-ENU.exe
[boot loader]
timeout=2
default=multi(0)disk(0)rdisk(0)partition(1)\WINDOWS
[operating systems]
c:\cmdcons\BOOTSECT.DAT="Microsoft Windows Recovery Console" /cmdcons
multi(0)disk(0)rdisk(0)partition(1)\WINDOWS="Windows XP Media Center Edition" /noexecute=optin /fastdetect

356 — E O F — 2008-11-12 18:04:54
Hi dejaylos,

We need to look at some files so it's important that you do these steps in the order posted.

  • Right click the attached file look.zip, click Save Target as
    📎look.zip
  • Set the save in box to Desktop
  • Click Save
On your Desktop, please locate look.zip
  • Right click on it, select Extract here
  • A file look.cmd, with a gear icon will now be on your desktop, please double click it
    📎cmd.jpg
  • When it's finished running, a notepad called Lookresult.txt will popup
  • Save it to your desktop, you will need to copy and paste it's contents in your next reply
note:If you misplace it, a copy can be found on your harddrive at C:\

We will be using Combofix again.

Please follow all previous instructions regarding security programs.

Open a new Notepad session
  • Click the Start button, click run
  • in the run box type notepad
  • click ok
  • In the notepad, Click "Format" and be certain that Word Wrap is not checked.
  • Copy and paste all the text in the code box below into the Notepad.

KillAll::

File::
c:\windows\Tasks\At1.job
c:\windows\Tasks\At10.job
c:\windows\Tasks\At11.job
c:\windows\Tasks\At12.job
c:\windows\Tasks\At13.job
c:\windows\Tasks\At14.job
c:\windows\Tasks\At15.job
c:\windows\Tasks\At16.job
c:\windows\Tasks\At17.job
c:\windows\Tasks\At18.job
c:\windows\Tasks\At19.job
c:\windows\Tasks\At2.job
c:\windows\Tasks\At20.job
c:\windows\Tasks\At21.job
c:\windows\Tasks\At22.job
c:\windows\Tasks\At23.job
c:\windows\Tasks\At24.job
c:\windows\Tasks\At25.job
c:\windows\Tasks\At26.job
c:\windows\Tasks\At27.job
c:\windows\Tasks\At28.job
c:\windows\Tasks\At29.job
c:\windows\Tasks\At3.job
c:\windows\Tasks\At30.job
c:\windows\Tasks\At31.job
c:\windows\Tasks\At32.job
c:\windows\Tasks\At33.job
c:\windows\Tasks\At34.job
c:\windows\Tasks\At35.job
c:\windows\Tasks\At36.job
c:\windows\Tasks\At37.job
c:\windows\Tasks\At38.job
c:\windows\Tasks\At39.job
c:\windows\Tasks\At4.job
c:\windows\Tasks\At40.job
c:\windows\Tasks\At41.job
c:\windows\Tasks\At42.job
c:\windows\Tasks\At43.job
c:\windows\Tasks\At44.job
c:\windows\Tasks\At45.job
c:\windows\Tasks\At46.job
c:\windows\Tasks\At47.job
c:\windows\Tasks\At48.job
c:\windows\Tasks\At5.job
c:\windows\Tasks\At6.job
c:\windows\Tasks\At7.job
c:\windows\Tasks\At8.job
c:\windows\Tasks\At9.job
c:\windows\mefaxysic._sy
c:\windows\gukugu.bat
c:\windows\system32\odopeci.bat
c:\windows\vehakyg.pif
c:\windows\yfisy.db
c:\documents and settings\All Users\Application Data\lyjysezivi.bat
c:\windows\ebamoz.db
c:\windows\system32\FBw54VXH.exe_
c:\windows\system32\FBw54VXH.exe
c:\windows\system32\VIbh1Sv1.exe
c:\windows\system32\rafaweti.dll

Registry::
[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\standardprofile\authorizedapplications\list]
"C:\WINDOWS\system32\FBw54VXH.exe"=-

In the notepad
  • Click File, Save as…, and set the Save in to your Desktop
  • In the filename box, type (including quotation marks) as the filename: "CFScript.txt"
  • Click save
Using your mouse left button, drag the new file CFscript.txt and drop it on the ComboFix.exe icon as shown below.

This will start ComboFix again.Close all browser/windows first.

**Note: Do not mouseclick combofix's window while it's running. That may cause it to stall**

[external image: Posted Image]

After reboot, (in case it asks to reboot), post the contents of Combofix.txt in your next reply together with a new HJT log and the contents of Lookresult.txt.

How's your computer now?

Thanks.
Hey Old Man, Just wanted to see if Im doing something wrong, because when I try to run the combo fix with the script, it starts it and it will get to start the fix, but then it freezes, and does nothing for a very long time. It went down to case #50 and stayed there for about an hour. so my computer fell asleep and I restarted it. Can you please help
Hi dejaylos,

No, I don't think you are doing anything wrong, this happens sometimes.

We'll use a different tool. But first, please ensure that you followed the instructions for downloading and running look.zip . This has to be the first step.

Here's the instructions again, please follow them if you have not all ready done this part.

  • Right click the attached file look.zip, click Save Target as
    📎look.zip
  • Set the save in box to Desktop
  • Click Save
On your Desktop, please locate look.zip
  • Right click on it, select Extract here
  • A file look.cmd, with a gear icon will now be on your desktop, please double click it
    📎cmd.jpg
  • When it's finished running, a notepad called Lookresult.txt will popup
  • Save it to your desktop, you will need to copy and paste it's contents in your next reply
note:If you misplace it, a copy can be found on your harddrive at C:\

Please download the OTMoveIt3 by OldTimer.
  • Save it to your desktop.
  • Please double-click OTMoveIt3.exe to run it. (Note: If you are running on Vista, right-click on the file and choose Run As Administrator).
  • Copy the lines in the codebox below to the clipboard by highlighting ALL of them and pressing CTRL + C (or, after highlighting, right-click and choose Copy):

    :Processes
    explorer.exe
    
    :Reg
    [HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\standardprofile\authorizedapplications\list]
    "C:\WINDOWS\system32\FBw54VXH.exe"=-
    
    :Files
    c:\windows\Tasks\At*.job
    c:\windows\mefaxysic._sy
    c:\windows\gukugu.bat
    c:\windows\system32\odopeci.bat
    c:\windows\vehakyg.pif
    c:\windows\yfisy.db
    c:\documents and settings\All Users\Application Data\lyjysezivi.bat
    c:\windows\ebamoz.db
    c:\windows\system32\FBw54VXH.exe_
    c:\windows\system32\FBw54VXH.exe
    c:\windows\system32\VIbh1Sv1.exe
    c:\windows\system32\rafaweti.dll
    
    :Commands
    [EmptyTemp]
    [Start Explorer]
    [Reboot]
  • Return to OTMoveIt3, right click in the "Paste Instructions for Items to be Moved" window (under the yellow bar) and choose Paste.
  • Click the red Moveit! button.
  • Copy everything in the Results window (under the green bar) to the clipboard by highlighting ALL of them and pressing CTRL + C (or, after highlighting, right-click and choose copy), and paste it in your next reply.
  • Close OTMoveIt3
Note: If a file or folder cannot be moved immediately you may be asked to reboot the machine to finish the move process. If you are asked to reboot the machine choose Yes. In this case, after the reboot, open Notepad (Start->All Programs->Accessories->Notepad), click File->Open, in the File Name box enter *.log and press the Enter key, navigate to the C:\_OTMoveIt\MovedFiles folder, and open the newest .log file present, and copy/paste the contents of that document back here in your next post.

Now try running Combofix without the CFScript. Just double click the Combofix.exe icon on your desktop. It shouldn't take more than 20-30 minutes tops.

Please post the post the contents of Combofix.txt in your next reply together with a new HJT log and the contents of Lookresult.txt plus the OTMOVEIT3 results.

Thanks
Hi oldtimer:

Here are the logs you requested, I hope they were done right, as the look result txt looks wierd in its verbage. Also wanted to mention that as combo fix was done, my antivirus said the following:

C:/combofix/temp00
Virus: bangsoft.a
result: quartantined

then:

C:/combofix/temp00
Virus: bangsoft.a
result: infected

Not sure what this means but here are the logs starting with OTMOVEIT3:

Error: Unable to interpret in the current context!
Error: Unable to interpret in the current context!
========== REGISTRY ==========
Registry value HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\standardprofile\authorizedapplications\list\\C:\WINDOWS\system32\FBw54VXH.exe deleted successfully.
========== FILES ==========
c:\windows\Tasks\At1.job moved successfully.
c:\windows\Tasks\At10.job moved successfully.
c:\windows\Tasks\At11.job moved successfully.
c:\windows\Tasks\At12.job moved successfully.
c:\windows\Tasks\At13.job moved successfully.
c:\windows\Tasks\At14.job moved successfully.
c:\windows\Tasks\At15.job moved successfully.
c:\windows\Tasks\At16.job moved successfully.
c:\windows\Tasks\At17.job moved successfully.
c:\windows\Tasks\At18.job moved successfully.
c:\windows\Tasks\At19.job moved successfully.
c:\windows\Tasks\At2.job moved successfully.
c:\windows\Tasks\At20.job moved successfully.
c:\windows\Tasks\At21.job moved successfully.
c:\windows\Tasks\At22.job moved successfully.
c:\windows\Tasks\At23.job moved successfully.
c:\windows\Tasks\At24.job moved successfully.
c:\windows\Tasks\At25.job moved successfully.
c:\windows\Tasks\At26.job moved successfully.
c:\windows\Tasks\At27.job moved successfully.
c:\windows\Tasks\At28.job moved successfully.
c:\windows\Tasks\At29.job moved successfully.
c:\windows\Tasks\At3.job moved successfully.
c:\windows\Tasks\At30.job moved successfully.
c:\windows\Tasks\At31.job moved successfully.
c:\windows\Tasks\At32.job moved successfully.
c:\windows\Tasks\At33.job moved successfully.
c:\windows\Tasks\At34.job moved successfully.
c:\windows\Tasks\At35.job moved successfully.
c:\windows\Tasks\At36.job moved successfully.
c:\windows\Tasks\At37.job moved successfully.
c:\windows\Tasks\At38.job moved successfully.
c:\windows\Tasks\At39.job moved successfully.
c:\windows\Tasks\At4.job moved successfully.
c:\windows\Tasks\At40.job moved successfully.
c:\windows\Tasks\At41.job moved successfully.
c:\windows\Tasks\At42.job moved successfully.
c:\windows\Tasks\At43.job moved successfully.
c:\windows\Tasks\At44.job moved successfully.
c:\windows\Tasks\At45.job moved successfully.
c:\windows\Tasks\At46.job moved successfully.
c:\windows\Tasks\At47.job moved successfully.
c:\windows\Tasks\At48.job moved successfully.
c:\windows\Tasks\At5.job moved successfully.
c:\windows\Tasks\At6.job moved successfully.
c:\windows\Tasks\At7.job moved successfully.
c:\windows\Tasks\At8.job moved successfully.
c:\windows\Tasks\At9.job moved successfully.
c:\windows\mefaxysic._sy moved successfully.
c:\windows\gukugu.bat moved successfully.
c:\windows\system32\odopeci.bat moved successfully.
c:\windows\vehakyg.pif moved successfully.
c:\windows\yfisy.db moved successfully.
c:\documents and settings\All Users\Application Data\lyjysezivi.bat moved successfully.
c:\windows\ebamoz.db moved successfully.
c:\windows\system32\FBw54VXH.exe_ moved successfully.
c:\windows\system32\FBw54VXH.exe moved successfully.
c:\windows\system32\VIbh1Sv1.exe moved successfully.
LoadLibrary failed for c:\windows\system32\rafaweti.dll
c:\windows\system32\rafaweti.dll NOT unregistered.
c:\windows\system32\rafaweti.dll moved successfully.
========== COMMANDS ==========
File delete failed. C:\DOCUME~1\OWNER~1.LOP\LOCALS~1\Temp\hpodvd09.log scheduled to be deleted on reboot.
File delete failed. C:\DOCUME~1\OWNER~1.LOP\LOCALS~1\Temp\~DF11BB.tmp scheduled to be deleted on reboot.
File delete failed. C:\DOCUME~1\OWNER~1.LOP\LOCALS~1\Temp\~DF2E6D.tmp scheduled to be deleted on reboot.
File delete failed. C:\DOCUME~1\OWNER~1.LOP\LOCALS~1\Temp\~DF5038.tmp scheduled to be deleted on reboot.
File delete failed. C:\DOCUME~1\OWNER~1.LOP\LOCALS~1\Temp\~DF7C5B.tmp scheduled to be deleted on reboot.
File delete failed. C:\DOCUME~1\OWNER~1.LOP\LOCALS~1\Temp\~DF9E88.tmp scheduled to be deleted on reboot.
File delete failed. C:\DOCUME~1\OWNER~1.LOP\LOCALS~1\Temp\~DFE3DF.tmp scheduled to be deleted on reboot.
User's Temp folder emptied.
User's Temporary Internet Files folder emptied.
User's Internet Explorer cache folder emptied.
File delete failed. C:\Documents and Settings\LocalService\Local Settings\Temp\Temporary Internet Files\Content.IE5\index.dat scheduled to be deleted on reboot.
File delete failed. C:\Documents and Settings\LocalService\Local Settings\Temp\History\History.IE5\index.dat scheduled to be deleted on reboot.
File delete failed. C:\Documents and Settings\LocalService\Local Settings\Temp\Cookies\index.dat scheduled to be deleted on reboot.
Local Service Temp folder emptied.
Local Service Temporary Internet Files folder emptied.
Windows Temp folder emptied.
Temp folders emptied.
Explorer started successfully

OTMoveIt3 by OldTimer - Version 1.0.7.1 log created on 11302008_191848

Files moved on Reboot…
File move failed. C:\DOCUME~1\OWNER~1.LOP\LOCALS~1\Temp\hpodvd09.log scheduled to be moved on reboot.
File move failed. C:\DOCUME~1\OWNER~1.LOP\LOCALS~1\Temp\~DF11BB.tmp scheduled to be moved on reboot.
File move failed. C:\DOCUME~1\OWNER~1.LOP\LOCALS~1\Temp\~DF2E6D.tmp scheduled to be moved on reboot.
File move failed. C:\DOCUME~1\OWNER~1.LOP\LOCALS~1\Temp\~DF5038.tmp scheduled to be moved on reboot.
File move failed. C:\DOCUME~1\OWNER~1.LOP\LOCALS~1\Temp\~DF7C5B.tmp scheduled to be moved on reboot.
File move failed. C:\DOCUME~1\OWNER~1.LOP\LOCALS~1\Temp\~DF9E88.tmp scheduled to be moved on reboot.
File move failed. C:\DOCUME~1\OWNER~1.LOP\LOCALS~1\Temp\~DFE3DF.tmp scheduled to be moved on reboot.
File move failed. C:\Documents and Settings\LocalService\Local Settings\Temp\Temporary Internet Files\Content.IE5\index.dat scheduled to be moved on reboot.
File move failed. C:\Documents and Settings\LocalService\Local Settings\Temp\History\History.IE5\index.dat scheduled to be moved on reboot.
File move failed. C:\Documents and Settings\LocalService\Local Settings\Temp\Cookies\index.dat scheduled to be moved on reboot.


Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 8:14:34 PM, on 11/30/2008
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16735)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Windows Defender\MsMpEng.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\CA\SharedComponents\HIPSEngine\UmxCfg.exe
C:\Program Files\CA\SharedComponents\HIPSEngine\UmxFwHlp.exe
C:\Program Files\CA\SharedComponents\HIPSEngine\UmxPol.exe
C:\Program Files\CA\SharedComponents\HIPSEngine\UmxAgent.exe
C:\Program Files\Common Files\AOL\ACS\AOLAcsd.exe
C:\Program Files\Common Files\AOL\TopSpeed\2.0\aoltsmon.exe
C:\Program Files\CA\CA Internet Security Suite\CA Anti-Virus\ISafe.exe
C:\WINDOWS\eHome\ehRecvr.exe
C:\WINDOWS\eHome\ehSched.exe
C:\Program Files\CA\SharedComponents\PPRT\bin\ITMRTSVC.exe
C:\Program Files\Common Files\New Boundary\PrismXL\PRISMXL.SYS
C:\WINDOWS\system32\svchost.exe
C:\Program Files\CA\CA Internet Security Suite\CA Anti-Virus\VetMsg.exe
C:\WINDOWS\system32\dllhost.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\CA\CA Internet Security Suite\CA Personal Firewall\capfsem.exe
C:\WINDOWS\ehome\ehtray.exe
C:\WINDOWS\RTHDCPL.EXE
C:\WINDOWS\eHome\ehmsas.exe
C:\WINDOWS\zHotkey.exe
C:\Program Files\HP\HP Software Update\HPWuSchd2.exe
C:\PROGRAM FILES\DELL\DELL LASER MFP 1815\PSU\Scan2Pc.exe
C:\Program Files\QuickTime\QTTask.exe
C:\Program Files\iTunes\iTunesHelper.exe
C:\Program Files\Common Files\AOL\ACS\AOLDial.exe
C:\PROGRA~1\COMMON~1\AOL\AOLSPY~1\AOLSP Scheduler.exe
C:\Program Files\CA\CA Internet Security Suite\cctray\cctray.exe
C:\Program Files\CA\CA Internet Security Suite\CA Anti-Spam\QSP-5.1.18.0\QOELoader.exe
C:\Program Files\CA\CA Internet Security Suite\CA Anti-Virus\CAVRID.exe
C:\PROGRA~1\COMMON~1\AOL\121562~1\EE\AOLHOS~1.EXE
C:\Program Files\CA\CA Internet Security Suite\CA Personal Firewall\capfasem.exe
C:\Program Files\Messenger\msmsgs.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
C:\Program Files\CA\CA Internet Security Suite\ccprovsp.exe
C:\PROGRA~1\COMMON~1\AOL\121562~1\EE\AOLServiceHost.exe
C:\Program Files\CA\CA Internet Security Suite\CA Anti-Spyware\CAPPActiveProtection.exe
C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe
C:\WINDOWS\system32\wuauclt.exe
C:\Program Files\CA\CA Internet Security Suite\CA Anti-Spyware\PPCtlPriv.exe
C:\Program Files\iPod\bin\iPodService.exe
C:\Program Files\HP\Digital Imaging\bin\hpqSTE08.exe
C:\Program Files\Internet Explorer\IEXPLORE.EXE
C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLLoginProxy.exe
C:\Program Files\trend micro\HijackThis\HijackThis.exe

R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
O2 - BHO: Windows Live Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
O3 - Toolbar: AOL Toolbar - {4982D40A-C53B-4615-B15B-B5B5E98D167C} - C:\Program Files\AOL Toolbar\toolbar.dll
O3 - Toolbar: &Google; - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar1.dll
O4 - HKLM\..\Run: [ehTray] C:\WINDOWS\ehome\ehtray.exe
O4 - HKLM\..\Run: [RTHDCPL] RTHDCPL.EXE
O4 - HKLM\..\Run: [CHotkey] zHotkey.exe
O4 - HKLM\..\Run: [Recguard] %WINDIR%\SMINST\RECGUARD.EXE
O4 - HKLM\..\Run: [HP Software Update] C:\Program Files\HP\HP Software Update\HPWuSchd2.exe
O4 - HKLM\..\Run: [MFP1815_S2P] C:\PROGRAM FILES\DELL\DELL LASER MFP 1815\PSU\Scan2Pc.exe
O4 - HKLM\..\Run: [SSBkgdUpdate] "C:\Program Files\Common Files\Scansoft Shared\SSBkgdUpdate\SSBkgdupdate.exe" -Embedding -boot
O4 - HKLM\..\Run: [PaperPort PTD] "C:\Program Files\DELL\Dell Laser MFP 1815\PaperPort\pptd40nt.exe"
O4 - HKLM\..\Run: [IndexSearch] "C:\Program Files\DELL\Dell Laser MFP 1815\PaperPort\IndexSearch.exe"
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\QTTask.exe" -atboottime
O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
O4 - HKLM\..\Run: [MSKDetectorExe] C:\Program Files\McAfee\SpamKiller\MSKDetct.exe /uninstall
O4 - HKLM\..\Run: [HostManager] C:\Program Files\Common Files\AOL\1215622490\EE\AOLHostManager.exe
O4 - HKLM\..\Run: [AOLDialer] C:\Program Files\Common Files\AOL\ACS\AOLDial.exe
O4 - HKLM\..\Run: [AOL Spyware Protection] "C:\PROGRA~1\COMMON~1\AOL\AOLSPY~1\AOLSP Scheduler.exe"
O4 - HKLM\..\Run: [cctray] "C:\Program Files\CA\CA Internet Security Suite\cctray\cctray.exe"
O4 - HKLM\..\Run: [QOELOADER] "C:\Program Files\CA\CA Internet Security Suite\CA Anti-Spam\QSP-5.1.18.0\QOELoader.exe"
O4 - HKLM\..\Run: [CAVRID] "C:\Program Files\CA\CA Internet Security Suite\CA Anti-Virus\CAVRID.exe"
O4 - HKLM\..\Run: [cafwc] C:\Program Files\CA\CA Internet Security Suite\CA Personal Firewall\cafw.exe -cl
O4 - HKLM\..\Run: [capfasem] C:\Program Files\CA\CA Internet Security Suite\CA Personal Firewall\capfasem.exe
O4 - HKLM\..\Run: [capfupgrade] C:\Program Files\CA\CA Internet Security Suite\CA Personal Firewall\capfupgrade.exe
O4 - HKCU\..\Run: [Power2GoExpress] NA
O4 - HKCU\..\Run: [updateMgr] C:\Program Files\Adobe\Acrobat 7.0\Reader\AdobeUpdateManager.exe AcRdB7_0_9
O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [swg] C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
O4 - HKCU\..\Run: [DW6] "C:\Program Files\The Weather Channel FW\Desktop\DesktopWeather.exe"
O4 - Global Startup: Adobe Reader Speed Launch.lnk = C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
O4 - Global Startup: HP Digital Imaging Monitor.lnk = C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe
O8 - Extra context menu item: &AOL; Toolbar search - res://C:\Program Files\AOL Toolbar\toolbar.dll/SEARCH.HTML
O8 - Extra context menu item: E&xport; to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
O9 - Extra button: AOL Toolbar - {4982D40A-C53B-4615-B15B-B5B5E98D167C} - C:\Program Files\AOL Toolbar\toolbar.dll
O9 - Extra 'Tools' menuitem: AOL Toolbar - {4982D40A-C53B-4615-B15B-B5B5E98D167C} - C:\Program Files\AOL Toolbar\toolbar.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL
O9 - Extra button: Real.com - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - C:\WINDOWS\system32\Shdocvw.dll
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O16 - DPF: {1663ed61-23eb-11d2-b92f-008048fdd814} (MeadCo ScriptX Advanced) - https://eagent.farmersinsurance.com/PLA/eAg…ctiveX/smsx.cab
O16 - DPF: {354D91A8-E3C9-491F-BB89-0FB27DEEED86} (ImgXTwain6.ImgXTwain) - https://eagent.farmersinsurance.com/PLA/eAg…ImgXTwain61.cab
O16 - DPF: {45EEDB84-57BC-4FBD-8065-7AB8E971B545} (ImgXDialog6.ImgXDialog) - https://eagent.farmersinsurance.com/PLA/eAg…mgXDialog61.cab
O16 - DPF: {7E8DC73D-69CD-4F67-99B1-8DC6E42F6246} (Atalasoft ImgXCtrl6.ImgXCtrl (CAB)) - https://eagent.farmersinsurance.com/PLA/eAg…iveX/ImgX61.cab
O23 - Service: AOL Connectivity Service (AOL ACS) - America Online - C:\Program Files\Common Files\AOL\ACS\AOLAcsd.exe
O23 - Service: AOL TopSpeed Monitor (AOL TopSpeedMonitor) - America Online, Inc - C:\Program Files\Common Files\AOL\TopSpeed\2.0\aoltsmon.exe
O23 - Service: AOL Spyware Protection Service (AOLService) - Unknown owner - C:\PROGRA~1\COMMON~1\AOL\AOLSPY~1\\aolserv.exe
O23 - Service: Ati HotKey Poller - ATI Technologies Inc. - C:\WINDOWS\system32\Ati2evxx.exe
O23 - Service: ATI Smart - Unknown owner - C:\WINDOWS\system32\ati2sgag.exe
O23 - Service: CaCCProvSP - CA, Inc. - C:\Program Files\CA\CA Internet Security Suite\ccprovsp.exe
O23 - Service: CAISafe - Computer Associates International, Inc. - C:\Program Files\CA\CA Internet Security Suite\CA Anti-Virus\ISafe.exe
O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: iPod Service - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: CA Pest Patrol Realtime Protection Service (ITMRTSVC) - CA, Inc. - C:\Program Files\CA\SharedComponents\PPRT\bin\ITMRTSVC.exe
O23 - Service: Pml Driver HPZ12 - HP - C:\WINDOWS\system32\HPZipm12.exe
O23 - Service: PPCtlPriv - CA, Inc. - C:\Program Files\CA\CA Internet Security Suite\CA Anti-Spyware\PPCtlPriv.exe
O23 - Service: PrismXL - New Boundary Technologies, Inc. - C:\Program Files\Common Files\New Boundary\PrismXL\PRISMXL.SYS
O23 - Service: HIPS Event Manager (UmxAgent) - CA - C:\Program Files\CA\SharedComponents\HIPSEngine\UmxAgent.exe
O23 - Service: HIPS Configuration Interpreter (UmxCfg) - CA - C:\Program Files\CA\SharedComponents\HIPSEngine\UmxCfg.exe
O23 - Service: HIPS Firewall Helper (UmxFwHlp) - CA - C:\Program Files\CA\SharedComponents\HIPSEngine\UmxFwHlp.exe
O23 - Service: HIPS Policy Manager (UmxPol) - CA - C:\Program Files\CA\SharedComponents\HIPSEngine\UmxPol.exe
O23 - Service: VET Message Service (VETMSGNT) - CA, Inc. - C:\Program Files\CA\CA Internet Security Suite\CA Anti-Virus\VetMsg.exe

–
End of file - 10388 bytes



File: Look.cmd
Run at: 19:14:12.78
On 2008-11-30

Run from C:\Documents and Settings\Owner.LOPEZINSURANCE\Desktop\look



~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~Contents of C:\Windows\gukugu.bat~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~



  


 ##'*-
$,4/
+'
@?D4=" '&>='$0I7N8K:'VVd$MO?>eX#41trH-Qu[VH7 sO
W`C‹~0…XqG!ex?`[vs›–1Œ3d'lU RD0Ÿ­h„< k›
¢ª7¶¸±”s¯_%57z+@€@¼qi"a[;Çt3^~¬:K `Dx 9&h;Ÿ«í%p[¥„}É ÉtnøÞ% ïà¿îHË
=üÊóêÇ^Þ568@O§F:aÃ22‚ ,yÌØfí µn‹^0v°|Îp#/µsp8ì†CâÕ< 1¿L#®_&m;^0S
Pµ ÔZO_5èJ‰4$H 9BTZR‹ €ÂŽ";w;Bu¯ý(>ÁÌ Z`ªn9[æ!bJ¥Ð!Þ‹D^:Âì ho®C“@`4Ð{‡wP
cž­C—ížÌ]B¢kjtÊÔÏ)s>>€ )’ö×1¾p°
@‹.5OË£>ñ
äR[4‹8 Ò6‘EsxèA•€b—êžTËgd©ió¿ÑWk¿ˆ–;è…šÈJ«Ul
@››×9RcE¸7ÎòÇþ^ñð¡¤Å-×–x)=©Ç9xÌ}v¼ û2ÿÕàpêL‰TÇŒØN:R%£•¶áýA·ÃºŒð lïSI2¨ýYªå5ëUS•8Koᐹ «°VEA}q)'0õSÛ_2²¬R®9µí`‰m€8Ž9$†‹Y F‚oåÛÓwñ Ž„Y÷c›÷±NŠÏAçª1š¯Í­Å÷§¦AêÌùæÑ»a
·¬ò]A6Ìs6ƒbÇóTÖ7½S¼4nhh&ÿGSLá{ìë¼ÿ@“asìž&Kl;²œ8LÂcõ`c 4å
Qa<ÎQ}6ŽŸ£_^ªžì)µ¸êR)çïéOo<®Ã.³ôÀ1ú|î÷l2 ¿ý&±+U“b
;£
Ò<Žùpdˆ§.¶™ÒÄ'Ã+ÄD̿ة°Wá|C¾Ûœ
öŒ>iÑÈ`\g ·MDÑÆ»\³e†oÅ*Ø7{Cå*»Ò‰NrM{‰LMj‹ÖGñU
ˆ2’N?mím^’`±lGšèÚ 6DA‡ˆŒ– (¨ªC¾ëL9Í—ÆLÙpyx€ØýöWõ‹ýnÿs9Ûªá:Q+M…(’´ÄU âµâÜ#ò÷~!_Aª™b31ûYG™a¨A©ŠÿÉ@NøÈÎG 0ÅD_%z;ÉG1¤gþoñQ,QXkʦ‚“a1ÒkÀLJFn“µÒ€ Á”’Ä«OK
,*ªÉ¦¶ÿøÝĺ¬Ïc3_–Q{ï¬?bž°_ÑÈ\Š¿g£Br¨É²%Æú¾þ4ìî*#)ðˆåP€Sfua@–µKÜ–Î¥>- øngž|ê&¹v!}À¿.Æ""¾©5Yv^ŠjÓî,&¤²†:F»k"…n*3¿¾*b¥¼¥Éàë§Áz8l )SBDŽ9qÑYíÙ»‹•Ô×’6ì'dP°I% á“‘ò¾&Ù^öù³®¿ QCåN‡fÑnœbíôwx뱑}Vz¢³ˆ[o÷3R@Š÷*'ÁŒƒ+r®¬ º;h‰«±àÇYôLxT”ÇFxÍ
ë’œRg·—üŒ—+f‘AÓK…Ú×1аv…šP†^û÷Í÷û(·‚k|$¥{ù
*Õ¬×_.'øfkŸùâ-Ã,ÖçUú"¦òÝ›ƒSþ–áØHK‚&Çñ#|T·|´oÀ§š64OÓx¶ä* ÐÙ‘ó“lñú F¨•‘·ÿõ‹”²Ì©«÷u‘kÅP÷Ò‚ÆÝLàÚ
ÜÖ¯ÛЮwØ–2eH†2 ûQ:ŽÁ<·Û|Ü‹˜'W‹»¬’€ñ›_Fg”¾•? ÚL]ã…ÔæÊàξbîñòÓFÆIÈÐu€Æ°?ù8BÏÑÎs;:d%zSä7¯iŸKf˜*[e‚Ä\œ½$C`ùáƒÛ£7ÙÁýŠ»PqíSôéÀ€LµØéÊyi(Á˜ä t˙朄:C†–¶™f)Rÿ-Éîûo»F´¶ú4EÏƒÏ ücFeÂU€|ÁéуNĤ:h^€P¤iÀÙ>\×:÷Q(; {‘2S@YO<0 'ÔI8v½ä3 ªÞ9úŽzåµ,Ñ'•ÃÞWIÛÙ3„KªíÀ›u‚Jwˆ
7ƒâQɨGjä2°¤‰kn¨\¢œ}Ѹ܏²òXƒŽÆ/Æ´›œsŽ)F´ªy¹ãÂQàºêåçÝÇò²'ÿ’ó¡gÉ;OVñ}¯ûu’x ýÃ=ÍÖ—ÙÐzZW-ÓÕúMtÅ{w«k÷ï]—z4©¼©BÓE#
×ÙÌxôŽÝ{El<,ª|;øŽtæb&¢9õN£@ËoeÔ~ ¤k„ÖˆÔ)w>¢~}pVdB–Ý•.U꿌p—cSÊçôš5ª—§A×㉷œ§‡~'»­h'ök!è ý®c:³yP$J¶-¹äH KA®Ùz3d( (ĐßåžÑÖØ+dwb Yç¼ÖDŽ®Ç¢»Ó¶òà§ ›%oÉ›Æ§EŸöÚ“ E®Œ >.Îõ/ŠL_*B:ÑÉ?@ ønnÀ(­€¾.ÓXÍ&h;„=`¶¬ˆÇ)õ¹Š ;0é´Û¦Á4S(rÝ_»šf¬¿;„8•÷5¿I½Õƒ‘U­Ó´…ÌiñM%3TémÆYóà7(V¯p["u²U+¼·lŸh~2‹˜®Á`wEÒÐ48VF|ˆp_:ol[Ÿ—ÿý4c½¹^«ÖÝõôZJîп¾¯N¡·g×}×M•IÀô*Î6n5|òå/÷v1“H†ƒ…ØóÇÁm‹/ÅçWH&9Ø
£u|MÝáTÛ…7’UIv6Ô/¿¯ w×ôÒÒKt>òEüXå^: ÑñwhºÕõx¢iørdó60º›e«‚+ãgyõ¿BªvFÚÞ`¥D7 6éU¥><)ßim„â7¹~Ä¡>5PêMüú5‘‰YG|„ÐÙ/ÃŒnuŒ|]pc{¿`ãYÞ]â±ÜÍMGbìlPsì= "²>͇ÙKJUQ
}ýÍ?-‚Ïëä’ÖÑÀ°V>¿öÏ^V}-+pð]ó †q
}‰‡wZ=1ã~e‰9q³sWx¢2Å}À q ÈHQ.þ1ëÐyÍàJ³'Sï–_¹a½§Æuc*åpøå³/°F°ê
íâ/h6œœ3óg­ëÞW8}ÉšxÏJcY؁†˜±e¶´¦>ù~ŽÉª‚vCˆ’žþ*çZ¾3¿XfaOÞ„‚\ª†S{rvUS¹‰ÿàÀ
­+]V¾Bn‰ùªÀþå9Ööëíæ¹þÛ(®;õŒe²sŸ[ÁE”aÂ1«ì|ß7_˝ÝQ:>/½Á‹9=%X 1\Ë= ÝÁaI|ñå×ÿ óëBœä«×²+t­å‚qcbfö|4ŸxÕ«ó
tŠÁé¯Ä>¢šû´IÒµáTdFÌFt£Jé—´*Ý`ðôu.Ÿg¯´½E¯P´ŒãÌBî9€™ö’7¹å/_,oß4hö Ÿ5°ïBôx7aÄÅ@£Hÿªi¿“7‚’…jµ‹ÚÎE&ÀO]Ÿ¢¢;rš¸‰>#ÖVt/â+_ æH
¶š-;VW,7l6f%0¡/°Ï»þõAçd\Ç—$¦r»$2²[ú‹J’Ný©J„'ïn+šˆsàLDr~Í­Ú^–o ý»ôi1B7•'ÌÄëÅ5@4(‰v–qKŽ“Ê¸‡ä¥Ä¡Ð¦*j…0Ô -(ÙwôàÔW|FCAF¥Ú^mùË@`ÐìõœÜIÉ­ÍÏvÉ UÿAGø.øÈŸÒ¢fT”Ú¬D:fV×D÷W±“<€†çÈ|^­–æ<œ¦ì©,š‘á¯›ì1+<9ë¯Íš×DÔ’îN.íZÊîÏYiÅ×¥0!EÛ?…–…A`W^¿ñˆl5Êl‘Cªi¯ÌУR|pþ—sfˆ×UÑ¡ƒ¬çFþí~y3_x”ð5€0'Ѩ×V2qXje;êz– Ç‹ôµ~qÍ×;ü ŽÙrQ~N™ÝWP¯ëš‡‹)ý¡pg°Ø8ïÞ~ïq„õfn|. ˆß9&°9ÜÚž8ì½H6ÏŸ¢]iC¢à½9ž5
×ï¼d’rçM´Ä
©äsd38k%{óª ÁÌ }uñ ˆèø¨ÈUÅ%ôZ~–pÜl{N eµÀ1hs«úDç«>ÒiRúQ*ÙtDèé1âo
¡2aþj#/üˆ@U·dR“ÿ
½¹®½£Pzï²7¼+h³¨åg©„ú‘ÚRAµ•?¿|µF«g~Û‹lÓ [a>>ËgkçùµÅ`¬EÿZÝè­©N‚-©Óú_N½èµä rä@÷b#|^ÜtŠªsö¹éÍQØ™­›ÓÀ϶òwK:þå)*cYõѬaµ( ԝ%~Ÿ!ºÜ{dº¬ðì¯þ n@6H¼(-ÀÌc\»t\!Q¾ÅI½g±ÂtÿÈa;lÒK(´ÕÿÂâÐŒwŽ3"¸³oÙ© ›³saèÈXs•øp„NýPùÛ¢6£%sX¶-ÂwJ( ÂÀŒÌ!ãÊ&3þ½öEÔÔCœ ôË4⻃RNÅ5Pæßì$ÀÙ[Ó:ʱA¸á±3ÂáA‹°ýT/׸íÇÀç—sL˜gp†@²0ZŵoA©ô²–WøÆlnäV¤¥û»Òy Ö³e¢Mé.ºñII«
-e3Vö­Ó!ïm?æE>ƒ…‚¯èH6\Ú¯ i…”ª¼•uvq Œ=ÎB?‚£éƒvUAõêPoÜ\ƒ 1MÅ‹¸?dw’FJ±¤™æ
Fh wõîéKšå„Ü)€HîSCz#ü¬Ù¬Ü5X®³Ä[iè<•ùÁWñC#N¨
uMžß¦'ñX3™Ê¨üËÔMʝÖû¹XH/ÏÄt™ä¬ï†¨Þüf q¸Pÿo|`êIQo9'ŸÇÖƒî+ãt›wn›„8­´çlJ™’Ãdi
…¿ºÓ‚D¹»ŽJ‹÷G”ŽH …má/´5g‘»^w±Õ°»‘@ »¾¿f°±ÓK_±Üòòüöâ,2…,tT?«ùl§†„[]©+E¿ÕA1Õ±ÞÀw"t¦”*
#Ëm’ÃZò ±ÜGTK)9g
’-D¹Sèíø‹4*(CÕ«x‰Î€ríñsÙ‹ü ÈæI?ñ Vú`WégZQ_ ;ÍÙa÷åV?}õ$Žel¿Þ€âŒ-tZG‘ïºxp$É-Í<Ðí®3%CÞdï<'` ý+Š˜¦@©9>UÇ8À%6þBAIE…³mxüU›×>"ÿË—€øÕœp
«¸RäL5>OŠ}È£=’] #Š[M!?PVc&<º\ÇÑ Ä=é6;ùjÛôûPÖèÊ÷¶rQ˜>«¨`góo§èUÁ¯­›³MÑd`)L‡Æ_R-:õz\€³A¬ôRV‘_Z‚mFVühˆ—m«Dð+ÝÏa¯Jð±Ý±å Ô0ʃf: `º)
½¼k„ø~wp 𚢠Ä×w°
˜¬úm&d;´e,€ È{ƲseWLRT6cѰŽrƒ |ɶ¶Þ[ì&òÚ¾³¿Ï@jÆ!8k_Vé|_n­Ñ`5Ï¢i˜Þ×§:°÷$&ø™{ƳE(Øq£¬=_[*ÜøaÕÓu§Óô¾Ç*TÊè·fUmˆéÜÆñI•+­mÖº¦7æ¡¨Öþ˜¶cUÃI›Þ4[Ætß
§wØ`üÅą<âõž~’#Tó“Qež¿­!va1©ÐQHýùåØÑáRBsÞN; ) £"*±S*&—¶u•5 nM¥áv
ø €ìm=šáOq“¹L-ºyöQÖYïê¦9¾Tœˆé”ÛÀ£f
¡¸èêo…1C°»–é+$b鲿Oõ9†nßìÕmbžW !Ž;Û+÷à¾Z¢E‘c@#Úʇ[ŠpæxN@ÈxZèÄr"NhIФŠè”dh»·ƒ^AVÈý­6¸D±¤’¹X:‚ºÌN“² ·ÄS,~-¨õiÙ?Õ–`Ê#_Â
-³EQA%Q Cýó@²¥+ÊäŨ“cˆâ«Š
³•ùok4ÁšÝøŽ¤Ô˜>_á™Òz±¹.áÅdæ&¾|ðú~¢u^­£e@·±³›S&>rŸ`euÙËðÅ §w‰ž ÐQk»€‰Ažc”ïâ¬F1PO¹J!ò–ш'©zû4¯wXÞµ¸>yöÊV5²¦ e‹ÒFŠì
zje_›Î¦š%¥‘
eÇ ÎÉ*ð
ºñ@¿üÛ{.ôyú¯­×›}Å7.†ë# EÜpÞ§ÆÞ­^aWƒ”¹—òá¥mæ`ëà"IH¤‘‚¸v”B/Ǹ
¶±+à·Þ*]¡Žƒ›ûº2ê'ˆƒêÞàuðýPŸ,û-¢ÒÛ_ž­Áè’VA &¤ÂƒB‰v¤ã3×óG½éPÞè¡p)là|šÁVƒÿ0µ¸þ°lÏϱ)&^N'RúB‘jiYT…ö“¡ñ Û¢» 5
ÿ'GRÓÀNñÀލƝçŸ
ÇÙŸò‘Ä£1Šóá"%Þh9M AlX]y/§ZøæÅ"(ïKØ'ë¥QZ³á¬£ú|>œ`{èÄéî '¥b [ÛÆ£|\äf¥;
¨¢&aÂ4Êâpê/‡C–/qØ=ê—°WéÇ„4otëeZÖøãª×?튗
ð`-L•µ(݃¸,*s]ÈoòžõN°¶­Í
v$mœÜâ†ðáÀÒr>\ÞÏìñ ¥ßà¾;ö†)ªÌ¨ÍñóÍ™—Sön ÜØ—ìK%…ý|™uŠi Rk29üSÇ'J¢„£E…ÉÈ5÷3A5y£Ç=Öu¡*G\£µ9Ã>JO
˜‡÷!ðpÝÅ͍šc½ˆ%£›'a=+‘‡ÝžJ“u8ùc"˜O»^¸õ!a´ÿîãAðN²ËR*÷🣦³kÞö‚GjUSi'3óiN:ëñýäa7;
6Î,Ò
Aïrü&L;§Ø8ð ñD rDc¶ªctiÝèÞoÈ‹-Æ Jò«òSäâF¦’aëpRí]´×DÆ`)ugËàNú=ª¢DáƒØ”h°…´@
Û­¹v'ïùýÝnKߪhFՏßg°©ÂÇÐ\|‰&ÞÄîºÍM
`v+}d€…U HJ‚T0ÑóŒ!¯µ†Y%Q°¸¹–ÔJìñ}.`sJÅ`ð_éÈ—Sx i<¶]„:¤­®¬Dź`˜‰†¤Îaíši-Ñ š0¯cmw× < éɱõ¦è³¥g¨*3>¦7«rákj^…¥¦
CÝÑ¥êÁvµVÅ〓ÝL™iiL0èøZ*;üKþÜó2Ö=,K†CC嘘}°ôä¼ë!§A“% «Û¤Mã=û¡í>>;c4ÆçhTü¾èråÐmQLr’"–Ô Aäöx¥
=øÊ IhCõ²øOå:š0Sà£VþÂÿþm= XV&—™ƒuÏ‘“òœôƒË7å³R‡E¨¤¶Í¶È™ ½#=޹ápÂ|8 ::‚'dƒ:ÝD
h/=Éæñ‚&ŸhÙ–›*€22oÏ@ùïbi7o,†AWñø3„Ž.¾äÉ*– ÓsG«’îs æ‡ Ãæ¢
BõüHÕͺ9Šýw/u—vØ)‘}¨›´|blOƒé|I=ö&@ý´¬¦6·¢ê†à!1.OB
M`ðÓ¡„[
?2 ±^é®0ôTÒï¬ë¬ñ?Õ—â À‹·²ïWÍÓY½”_yl%>¯ÜŒ|²BÁÈžR´•i¢¼ O
Úö|™³éO|X—ö†¦$IÃü‹GÉ̈5”ÁÖÏe„òg8¿÷BÕ /üüi"~Õ;Töb=ÀúGi·sä­D¶u¡Â5gwk‘<·ÅGMˆ
¿£)ùîI<[ÕÏ¡§NiÛGñõYøò—x.,"_YúWcíq­&X;Ý•Uy»ƒkB~qÛø}=-Ù5ökí“íhxðÖ µ)!b«{ÈÇL­ƒ˜Ùˆ ¼òàQð×NÇDV³6ÉxI{ì&š*dÚ?ɏñœÿ|wŒœ¤¿ò]l‡ö“ɵ °†B|K—"@ ®ØÞƒ! fF8š‹ \ísM·æ·¦2ö¥íbü}ÌcÕçd„¾§àÌZ‰wC ÁÇnj/¢]§«C-¾P%Ó^'…ËㆊrD¦¢eø·s’³Ã·Í0axPXüÚ‰³¤QçÆ#$tQ¶FôEýBñ"ì?Û“/®a‘ÅϽඬƒ¤«Û n#Ç5 >PŠâÞ^’n«›K9e©J#q¾µ[ &ªQíZ{ÚÖÆ ÅJ“K‰µ¶ðÎKl®ØÞɇ\3Kb[9jù¨*:Püßžúˆù¼;n'Ýè!ý]‘ÿ± 4׈€‹“¢Îv“>­5´ëÇÝ·&]aé•&q;ŸaÝå5›<Á¯žðgYâz6u{üÆÁŸãq¯ÓlÁÏö `.æpï|‹º·cîÞyDÈó÷b´ïÝë´ÆÝ¢2?kRÒý§U|‹³,¡NnÃGìö{“ÂùUžªŠ¿þÃnëAòmõÇÙÅ
˜[åÒ§žØG ÂQ)Ð(íßjðlÇÈ~íËöÅ×äBÖHO7·‹Ë£êG ˆ©’_Ç™Ûü‹¯3Ûô®üÎæ+2Èéè£d±Ø‘ÁòÍô¿4)\欶*“wѤhðVa¢SÅ“”fQʉ
ò”;ØÝ}ÿöˤi("Þ6™ ºosH¬~aÏːTp}Ëô?ÚM&Eq¹–Þ}ó§I`MX~ÿËï{¥eZ?1TsP²&î nM¨ü!z[;Kºš£Œ=$Á*|»ØS,ø&ös%¦IãKµ¦M)yw©ìñ‡ †ÐܦŸ•’óÂŒyMiÍhñÕÀ6¥ùn»qqïyq-ëká,.‚Ü,Çê
o˜t“cÜQÈN5#ÈpŠæö²Á|–ÚP ÃÓÐù‘jš7»áºÕ’,åœ"ÅÓñ1§TV’AØïXåk|š¹ðƒ3®`ÈŠ+>"'–ä¹Â†…GÁÚí·ñï». Šª¦‡Hbã[àÖtÂÜ^^ÚÙrž[×!ÇùG¶
±Ö•úRäç³ÛžÁ¦YN?½OÙ®ù#ðrCÍÍaRå\E‡` Êðjh.'žñŸk MÒÇ$ñj¢aá#´Q}„-Ö¸X.¡÷2Ni>ÞBFÑácnÏD&´3]7æA¯ð?b¬D á}G&§ÂZaȲ†j*0Э}¡œØ^À=а¸ëÐðªÈ_4àS^…•oçÓ:˜ê…¹Vù²&|ŽÂíãBô³‹äu!Ì]ò\Öže´Í‚À@±/Ñ ƒ
ßÀýÒ»6€ü_‡1’#.¯Œ‘%zÂ|¿yôS·…™n™ÓËÿ·dŠëge­¢;‚óêK"WÈqÏ0‹›QŒò M‚wU^B¬Ø`ÎßÎöûz;l—t¿¾
ú܉¢d],̍w0Q¦€Áö-¢½®ë€L™ˆ%j»Ë4…øF¡c¹)€[üòÜçŒÅ¼ÔX®Ì3ø`9z 8Žè꽩ò÷i5:«õô.”P·¨LÿˆÐ=;Q
âV±,ÃlL5é¨[ìLǽ®:T|”º'ɐ#R™—â³ƒ×a‰d‰ØFEþëõ†‹º?È,Âmê§”¸·ÆjRfj«-”ZéÊ­‘—¾ðv<Úa§\1¶€„“¯¸Ç$¥#Ì XÊ^©{”ò~»9½f˜Ê„‹½qSǸ×67 [
&‚
3·íAÕíÄJJ‚­ÔP ;s)»Ä«¦&U;[ê~x߃ü2âa͸ª’rTòñÇAÞš e+/D:¹ìw¥þyFz–nø"ì)úEü >¡À‡"ÖØ×EB‹·eÐ[ç‰VÆë÷x`Û¢o K޾Xü™6gÛ ¯žB¤`/ª6™¢—œ‹Ê]·Æz¤Êó^dµrËïŸEò3h
~%3€W!MA7—õé|p~È7{à…'ŒúºKyðÔ©¹•ƒeƒÇš{÷0ù¼Ë 3¹ÏPáà aر
øÆ€ëžñÐú3¨¯»Q›\ i*]µ‡ã8þΛ’D’!3“žõÃãL”ä¢흅)%S»Ì×=“þü.4@ðN¼Ñ¹/v(tõ‚%^QžÏœÊ9 ÛJ®Úc„ÓÜ#]È, K¡EÉ—kjù» øÅ ÿGYcG0pZ\w{U…h9 0S}X1×>Ãýœz2¬-zH.ÝÃ5Ø’“(ý!d¤½X Kv¬fÉ€‚C³†`¸£x0´» ÐÐ_#“}ØzÂÞb™Qx.êÚì)ï$ßä¼ãÐÖ¥bAæL4Kòõ×çÔib¯¦Ô;SöÖ3:Í
óÖ}~ ÷ýdŒ{–¶˜Xá¢À¡iiÜp³ŸA~§ùfDÅå©H„ w;œ
fú519´F’6ñue² ægfêAÐþDy.A²Ü¹‚()Á^Jg·n]yF?gty5'ó>ØŒp·ù4„"Ë»öËôµdô›è"?^u ‘v(‰K,ýtݐÌ1ö¥DØäTrL‰K,*’â1fô}š_õKÅÜåÂk’û÷óhø¦7\{w}ÂjJ 3û;¬TÖ üW®‘êOü ¶CîµÃ³ˆW«¶7-!}á[ Ýãc†é/úlx^kö´ì?èÆë7ã"‘J §jΦèÇÑM–“ïÿ üëBÄxm¿ÝȼYúj€|£ÝŽ×¤ðîÈ3E‘@„uºl3tãµ{=³#j]ÇÉÕ»Ä8TcKE<›Þz^ÊPhƒSÓ[1A¸)ð)K›×z9‰ Wõ÷h–Ù¹Á⁢ÇðÜ¡¬óž6Á™EÀ^oQÅ9 )*Oò¶9)¿ÂSJ¶$?5QëÍõ
›Žï2‚°·b•‹ú­¿)ûA#mjöfÚ*ƒˆN)x–¾Ÿqèx?W,ѹVbö…K
PýÄ?ðF¸–ýÛôÑü<ô “ßÚ/xîäȇG2]jAd2©X·¸€nÞȳç¨C§hø ¨®Ûׇe^m­NP¶mŸ«º¨–O«wì{œ#~#’I€”;/èKªÿ—]Œ‰ÏÓ¡ˆñGš¤#Ý÷ÿ¾4àÚ}‰½eÚ«Z)£à~;Ô¸¬„9p>]ÿÿ@8Ý[Ås2ç’UÕ«‰lî l
N×;5Çpÿ´¼;·’Ú'Þ½R¾QšÈÀ[õÃ;I1fHÿI9"BìÞ°¿¬ÚÎ ÇŸ'JŤÇûŒ‡5£ØvýoÖ©74:Î>%"—[5 †a¬Ì½àíPªc=hó",Me,\@z÷Héç§é=C<«]åv볉WŠ6•Tƒ&ñ€‘‘Ÿ¨¯gQ¾Ð
f2§„VåÑ:^@rƒ/óñ?ln0 © ¼†ƒ­}!à:Èv/ORuYw•À©UƵ IxŒ±ñ*¼ŒNÒ)8·`€8[%ïå
¾Í£uÔŠí¹ÄöÌõÓÎJË\„ÿÛs¦t%¿Wjº[ŒQa9ðm X0»Oê:/,[{^ïÖ?Ú?Pú`ª*öŸ¼Ší:/lÞ ”Võ{@k€bцü.­ù›3‰9¼Øƒ}Bãêäv
ï¹ÐŸï}š@µ^D|°°ëZ•z"_Ý¢TÙËd¿Þž
Vô¥&B;ñ²ª¬©ŽÄ Å_ÈLjÙ/TSƒVþÖêÖóSº'=ß!¤9F-a:½á
R!Ï÷ûPBûå_Ê#ó!FÃêÔ,ŒÌaIçõÀ…] æ”ÈVψ?J…4¸2c¼»Â‰QôÁ8ý[~`ñŸÝM¡Nö•Çli
Ÿyƒ÷*âyä
Xw¿
>†³áæ1:Þ×x¡™ XìžwËDˆŒN¨¶ç#óøˆX ŠÑƒÄ Îe¬™SO¹e‹ÛfÝóö†z‚¯êŠì{Ã8ÝòKx ÷»5Îk©[­*ûi7>wiÛä¼K¨@xg¨í¥¦¡y
èR¬,öÁ“U-/Ãr®èDÁ 
'ö©o9‰Áæ•0N˜À
Ðÿro¡Ž;_Ñ0>çŸw.•/Ozæë[5JÑrª¾Š²à]kµ”a™7|pL—á.CLXŸ}Á8“ñUœû4ʯ¸à«5ËáðÆ4•¶¼R vi
Œ¯íY>} c˜Eç›Á¥ú`Ò,¸LÅ]'…Nc±Eð ÀÌýêÌšÉéÕ<Ï>Çñ¦âäj«÷2ë,ëw©P×x‚­$‹··­’Îio å§¾D­f“—'ØË³\Q¿ŠÍÏÇyø¸ë ö»›‡Òl¿PÉLd¹SX‰À\ (Â`&án%X£F–ãĉ'jD²d ‹©³Jq,2òŽ ÀæçozZ€´ ÈŒËY½€‡Ÿ™ÿÝ¡x¦8òÁøJ‹âs A‹b€m÷º ÚÒhTÊÉëFF¬GéCãåöpöÐÔô¶9•ªGnû1Ð­>Øw¾uP5«Éù–zÜ埤ݦ.hMÀŽ3Y«ïÒUËF`ÊEÿ@{«²0¥7ÄÑSÒÊ*†ðá§ÌéU¢k±f$^½_Ÿie–l]È—mã‰^¡ÒúÏÒ…Î÷x´Qã[¦h€d9xpút¿Ýs%!®tà¸=´{–, ù¼h*{_S26ÊZ¨«ãrÂÇ%øu÷ܬ÷8K‹:V3˜øö -vº1RýD·9c¢AÞ÷•îâ9X†W ›ÆÈ¡)É˜Š¼‰aDð…à—/•¯t\ý@Ó“4A€mN?.þ•Q0¡n„ígêL0{ãö"9ôÿ0nYôf£´z[ À- f.éÓç+±H¶¼E…i%‘+wµä˜2z€Î®LûæÓeH•¿†9[œ%¦f<­Q5Šã• ¿üWä1ýdˆ?²deÿV£e%¡ùH#DP{Û£ê^‘‰¬Œ¬}ÑžLÎ3
pùfÿÕ)å§Ý>.Ä ]ÁÞsb†Ø£ÀëéxS‚¯æð&ˆ” ý¤Ú&Í>§sX
ä8Çí½}Á·|H¯h”ûBO®0x˜Øw>ø¤ ›fá̾³æ¥†Z$,šúýñÓGœe3ÌÃÕ"à[_>ï—ŠÞ `ì
w=IpŽˆ—¢‡ofŠ »ôŽ@2Bûj–6H¯§QÏÀAu6Å 2/ڝòÃ+}èº_üÇ~ÜÌsÿz…œ) e·ýáJㆥïLNZå*io0(¹æT8W«’A’ÞŽ¯ð—ü2,
,Ñž¨ˆü¦Þ…r·½cè )ÝfìZzï”A6#¶u÷ýI*ÍQê´êÃA½„MQÇÏÜZͱúdJÙòW5éE’*”:2ÓE…"t½¨·ëÜøñÔPÔ¸×Ò°üö®¿¬­êÚT•âe^0l臮ªâN¯4ɬ8­QÃÜ»ájçÅ£Ÿ6"ôõ}ǝ¬¹ÁQ,~FϤÅ`ÈÊ›¯i…i3¡;ã¢=$/Vm¶@`ëðê]¢]ÇB
MZ{¥ä÷To3çG!Bc%SW£4ƒÝòÜ_ˆð°À¦Ø¿\"LOêýWþ001xU'IGgÚ^`Úêß¡˜á(©&S;Ô€¿ŽŒ{þëÊ’§·%\FÚIŠ•qŒn„/'¬nÓ¦¦ìl°wfKvÊß}šô!„®Î©ö´Îú†_L†oȽOQŒ€vZ®ËÊ©Xiá•þ&ðpÛÆnéà֞!`2EpÆ‘ßÓ?¤¥ñÝ_h3ہo˜ÝHéw⇵½+¸ùñæ-!>L!ó&Ûý9ÿ>¹&#þØ{sdèlÚ`Á¥3×;/·àŽ+€Å[!߃išYzò†wA›póv¥GÔÃM÷惌@ J:º‘xöIEù]ÂQm>xÖц(Çr¾°[|›^(#8@5A³üM>?5š\x ÊèÖu%?p,Â
IšãTå*óÜjóñߌeá,S7[½
&‡`1ñˆÝW³ˆ|ÕÄ'›×“»Ÿ7­„å@¿R
D~¯¬«¯çÞ$)ÒÍš£: 'GüSV¾ÅÀöâì%9ºÀvóbÛ@›Š•)~UÉü/ghIª!”“Fàj½Q>á“èæˆÒ%žoÙMÄí6°ßjûúöa¸Ù3êt‰ÖI™‰1¦Ü»h̆¹ |~Ö¾gª»Å©è[(ûFezëO6À¿:˜gY
ê¤s‘Bóû"*mùç`tÌÒ+¡ö‘ \ðÂý›|摵s°‰8÷ƒO¾«t°cYSâ\ùØ>‚‘]ÆŒÄC×ëùRAK’ÐeÉàýÀÅ]oÍׯõÙÕÝÍk³G†Ùê6Õ:±«pÔצM'õ>U,\áòd¼
¿UpÃ4/Wt‡§´¯:³W‡L'—(Ú’~ß Çð!ˆbeUºtôi?†Dä³6÷!ÓÕ¸éýƝL0|QjmÅm<€rÒS:šN¨=-®fûÑj^ǺPŠÿh³)õ)&½i*ZO›Ú¿]˹+D#6…(ù°Íº¶‰4©ÂJÔ¼W[M\Oífñº“$ºœçRÐ
ÞrÌD{дPÓü)‹¹É\Sÿ•ÿÅ;©ŸÈŸpFd\!õðN´Ÿ¦Žuô騒"è'¥|Z À^ÒÛ'RÑÊ£8š^|ì£vì"pÇ)ɁêB~ïS"›­~˜ Ò€ƒtñjª¼¤å¥tÌ®¸³YÁ0ôðšæv½3‰[F%aŒTJm´¶3ìï„
æ‚b¬–¦öiì]0ÑGè˜ÈT÷”¨þ§áœځäÇñ¤¡ê5Ynç¼(¶£ìÄT
#m…AÅ¥8ßðUæðk ¸ÝÞ]+ž#Gý¿óæÆ·üòöOöæuüQÜ{D¥æë´ Uãs?ßFû:Llm‚ᝊTPÉŽ(äOÙ¡ÕÛ…¿ùÞœ‹ùa•B~–(IˆÅÇ%ëøÑòÚG©ìjPîùñ<”Ÿ—אCƳf¬V9kwЍÏÀw˜íÅ‘û]Ûå.¾³æ†E4cκ±Ç­4Û:ímÐ?”evÊK1±ˆWßcùº?C#ô§Í—¯ºT «qÊk­ßÿ4¥{Cå•-'}À!-c&ÏŸ‘Í10Ü»´Êò®_
™>–j‹FòâbŽ£RÇûa¡ó†ÜcsoÄã5'iÌBÁa‰<ÐÕ/‘^MÐ%Ž/j¬ÄÌ_xê°43mÒ!.ã¬S•®J˜¾í/3ÜÉïSGÛI3Û…Ÿ•{Þ­å °!™øvH-S›~Œ†K·z#YÍŽ”²/ÍŸºÁ±²·ÍÓpæ5ªQèsD¬ ø°/r‹Cµ~æR+šÇpŠU¶]1„lƒqç‘L”i"Wœß€M‘l
•$¼S3ȰƒdÍœÝÚ‡'¨®âpÙiôj'º-‘AÖ«îî9ãI¬L‹þÙÚßH„#e</àK}r Ûü§WPg ®×M‚‡!3ºïi²ËàÕvÂÔ8zSMº´Ø&¾?:MìßH¦ e/;X} M'®TO‘„¼eå JGÜÛ‚SP†ƒ˜äò{›Û’n æjD%¡%Ÿf¶¢-¤%!GÒ;§»nŒ[Z ©‘«x<5~’³™iwL"Ý0ŸŽq’OB¯TgJ$YU
Õª'2AÕNl¶‰yËÔ¶2èÐ.(¤èͦ-
þv2X¢Ûõ)yAT3°¼&¶Ù¶¨ÓUóÂÀ¿pÅn -qÓŽÌï¼e#$ <•^FjŽ3¾Úí:IÀ ºlX±¬¦¥ìåÎ{Æ­31{ï2/ïQ;z1ÌWe5‹8j#ú<?;¸þ‚ÿ;½{]ìd(^´Š” ‹w¨Ó¤–ûz:Á¿ïö$mrZËHm,nÊ‹_åú Åe 9ümX‚ÆöQ)øêé›Õ“¾”–˜hO‘Èí×ÏWîN¿B/X§ˆ)…Òß!ƾdÜF€+±vº™vŠ[u¼Ô-w8v×ÎÁzë(Ë Ú€1·r*“\#jH‡ŒT6à|m£;¯Vš÷š”qÃêTzhPÈž/cRû™– ~GžÂ­:MZÝÎÇäÇsÜNt—ùðçI=;A¨ba-«àŠz× f9à=*V@/‡¢sÎ<¤aä0Ý@\EÀÎiTÕp˜Hnò™2|ÚÇ”›žKàŽŽøê·U‡E›øòëHðI*`„ƒ{R½©é¿AÊpñäÎ<éd /öº,q TÑÚP½mœ™Oe/pÑ{ŠW°oàHÿ\£´¹eٍ«¬ÑÛdEj
„fBI„B<ìú.Æc”¨s©C­¥
JZŽ!W"Ž­ ¯Ý ñLÚ×wçÀ6aÉU´Å"¯¬Ç¢Êv¾FڐVÇÈ(æ*ïþ‚•=ΞVÔÇfXçBž^Fِ÷ÒÂöe/„+.>\^ƒ²y
sL®£h`J% ›í¥§aˆSœiG¤ŒÓµšRÇh
1ì$üc·K*ŸúÆJËÑ ›ì¿Ó=ºYaÂhPŒ&ÄðÛ&=b p—>ë[–N‘eѐ?ç‰Rï ®°z¡EÉèAj€#1+è…‰4’|Ÿ…G,¿j1Ð|˜áפÛxH¸ü‚1„z=Fx.@óׄ‹ÊÜhÓÆ©®ZÉWg²¹œÎ0Œ
œ&‘E µ4%HÎÈŠmú˜¤Ç+<¸“eíBG˜¦Þë7DˆN-†ÑøÜ-µÜÃEë¨KÕ—}Q´0,þIHíðÄ®·×òG-FÝCR†i y‚R ÞæªÍ]—ͤI…òµvÝòòå¸_zÅK”1sl^3ü&V;ó—˳vÛ°ÆÈÚæ ëKÔ*Ë!ú2Y˜I×[«=Û®±‹Ç%fêOœz @ҏ_#¡E«e‹›DA®°Ì Ej©\:CìõÞIÄGØx“ @qíä s­0²¾Ÿ5ÇB²À áØëé®ÝaJò•+¤GTÿ=Õlwã£â+ îv>®‘ãe’³A^ ËýâÕC¯õ Éu(ãòr;JôèxDJdÓºB«¾ËóÌé]}"Ä ?¹gE'<^BqP‰C¨¶WKÃú¯K§[>“K§pô>ðˆ”ôtuCï4é‰ÔNèm‡XÄøU;aõ€‚”Õ¬
†öo?
Ì]0|ÒUæ Ŧ2ÅÌEôÂÙvÇÍ\Àï­DÉ
°GF*jzTñ›üj2/Ó9Å™:P! N‚
Ne,6É“—¼çô6E&n;—›‡þÆ›ˆ¶|Ÿ´3D7¼¼¯PäD.…Åá“[¯$™°}—öÓ`¹YÓâKÒšîêàŸE’ £ØL–OKÙÄ_•=êûQä ź¿ÊÆB­N]RñzºâÉ,hL£Ý…Zû Ùg?‚[„îÒÏŒuŸÔ«D#¯H5ô»ÄD°p|ƒ½¥ŒÕÂ[•ýÆ3ß)ûŠÔ>Þ*MJ|ꍷiØPnò-²,ôX"üz”ÁôÇŒ¥^ðe
§Æh¦âm£§ï-ÞÛ«þ焜Â\€9ÅÅóCÑá.@–'Kº<óU£Þ‰Aµè蝹Ëìð YSÙ-Ã6t…;5¸w €!õÁE:"! î¼àYzIÍdÇøfAǶbëL8к¡£ 䥃Ñhî¬^\ ÞÖú Ï
i
¢®]BŠ”Š4EöJõO;¦Ìó_<[à¿Fð½\ž_ù˜oõÉ`öGµÂêä-cSr´¦©%7n0éqFîÎ$Ô‡bûrYˁ#àÕœL΄¨
¾’Éš!”»ƒ.¦+ÈvÂw`ï· ·±wïô½8 ÚKÿ
<·È¶L”¥Ï ïwj3é#‘% —øÆ;ça}LœÐ
¤¢Jwó#šõXà4Äs:*­SMýQ¡ñ\“Ç`˰îa®ŽªùÐÒù§†:{Cf—@Êþ«vÉõZÄsvËË#õT\õzS/ªEb䠝n €«¦[ä` ‚ÂÚ€õŸö¶ õMOfr NŽòn¹4TË!
Æ_ýü€#îݦd£‰fBõ’cz(ü-Þû›Ìç8‘œ”âã#O)*)<Ù¡·#6Û:½ÿÚ6ɤÄÇNB׫Û%¤†èÆälMø¡¥|ƒÃŸ¶*O’ó¹†f_ÃuƒP—SÔ-ÒëüN€ï¤Ä{CšÈÇØpáb©Ýªwžª%‰{ÞZí*ðÖàh³„¨D¯æEì foE•5Ó„I†ç½"øzöhZ×–ÖÉ^ ß66Í6€·ƒgòh÷þ+–ÂW êÜ(¢ú›q4w1&NU;@<-’–NŠ4|Èê7¤{0òIw™0î#h¨¸æx‡5ÅíêyiTÖKÔçªN×"@½êlKEœOIòÊš.›†‰‰—Ѓ9[ [x;Ï]Dh¸}݆9­©?×
Þ öb‹¿º?]lªJU9Dÿsø¤=£Ä [˜îØqüᭁ¨Ø4àt*
" ‹µä˜§É{3áìûlFìœÊq-‡½uQ½™ÆB䨈wYÕ2öåN¸Ã÷׆ËãvßÄ;Ç–RÃzâÄVdÅ|ÔâÑË?`ª˜8›0ÂdoØË¼NÒ—Vî¤Q¿1ÆšÛÕÏf=ylõ¡ù¡ýuQágÕF"®g§ ‰ÓÁQìˆø#XiÆÍ´õû‰UU^´ÃÚ?Šõ„ñö†va2msÔbˆVٝråf¦ …µÄØpD´Î+,À›Ãâ[ðš¢ñ¥è3Œ¯o lI«æó¡V…_5'îoÊz@ˆTŒ4’¸‚ŸÑÈ åÌ2qâØnÿM®÷OMÔÄÎ6ÈÐ¥Ã(ζŸÞHB½~&'晑ȵ7$FÀ%T i®ìh³&Zx;+:uÙ8ºÓVA½Mg?9ä–§ïæÌó ÿŸÚ0#ԐýDnrͲÝ‚&Ò4õ|öfä“Éd&D;å ¤×sùOHç±|L7ج¸wlg'¶±ŠÐÅá ˜`ù«Í"4¶Ûïž‹˜˜7ûVHÚµVxbd>ÖWûœÑÀÅ´ÛOéLrTr”r±ü!°ž ¹º ÎFòZNbÄ„Éy¦†7W‹çã´ë9~1ó j8̤{x•GÀÌð¹÷–EV°4õU¥>•;øDÌ…>ð’O¿U'§ÎµrUœ¶?ýtóL#zå^ÌœŽÃªñŸNôjëhÒ.„\a앺?Û¾aKV’0Y'$9›Ö
‹ê©±^Û¿n·8A 2n_–…óYg-Y7Ym£¼ñ*"fÝÁ6p›ü8ÿ®u»ÁTæV5Ñòn:F<¾Y#‚¸Pý$§ íŌգ’04…€×ÓÑç¼–8è Ý
JžÁ–A½YDݽi¶G¿§²JYlâý m3
6äÃß„{«Àããij>®. *IË÷¸Ër!¾½¤^] 6šŒ ê-2ý /ÙW^îZ+\jxÅJš0öªâÒ»™Õnž£áÛÜ|güod86ß鷏1 +ÀÝ´ƒ¹"|§M[çœÏ_=\Çœ«‚a“͹döÖ”Çè§h#_²(!jJ|“=ÓÍüÒö²>`¤QLúÞ$´4¹.çç>Ôô5ÅêÛSÅÿ^Ý`]Žº,¥t»T@b›®._ÿ\{fXêôgÀŒ¶Ó"ïìekb`ØÞ€qpXœüýDÚmþА¯ß¬±ú°
bòÎãñÉ®(þ,) 7B:N!ßÅš&Óe‘Ý2ˆ&ÎۍgÔ]zô®ì¾D©h_ZN©Ùq
BæÔ¯ Æ Ã:õéŽV[*&³B~À0hïmêÁ)„HƒuôÀt3Ãÿw=È(u1ì13aÈWø]Žƒ†›0Ɛ#j0+pܘ
’VfsxÑP/xô>´£^î
fF”¥Îž›/šîC'LÕ#-VÄÇø‹jå°**cÊw­JÎ+zÒÙ%ГÃ8ß)™XÜZyà’¬u‘pŸT£på0b…Ó+q]<Ôßùkb{(Ì”‚5²'ã\¿ŠYEtÉNÀÙäæ´£ì¨ÊsÜr2;GŸ žÑA¨âï¡7pnD§ÉTÊb¤èׂ°F%Á¤að>
`á0Ñ•²áUŸuëÿ›k|×:Ìò¸ýD­˜‹¥fÏÛ·¶lFG
x¤îköö8p©”®áŽc|D¦Xd2íñV/äÖKÑjæ|ª×ÞZâ´¬U50}>ïÂòOÔf¥5]aÍ>£ ]´„ú,6sÄø8{
­7¨E¦S…UL‰5í$¢Õj
NVøŠ{šu[ 3ãvU>¢îc Ld¶€Ç;*9^ô3m¯þŒ³Õ<˜óšß$ž¡È+ÕÃÓ›/óKÑ”!EØ’¢çRŠ¥ÔR
ÿ€ýëIJ¤ vò;ƒøhví±¨$RCô?Åêè”(›6*fbðéˆÝ”‘˜I–ÚV}I‡¯ÝöE[Mž!o;çèÎ1UâíÙªÑ¦è …˜zy‘AìÂý4¤q|!zfOÏÄõUŒH?ŽøþW/>&Ÿ6_Ì N(üt„‡ûHÓ/?Ì&ñ ! «‰ùrÂÚÅØðò’‡½wÑ}ã•ÿ
0DßéñQ¸“¢nçìャ
Ë:º‹‚ö ¢ÝîÈ'^ú¬?v5òÒÛp)G@‹½·v i&3X2h•n˜°ö
<ˆ¨(dïW>6²°•H&ˆ’RM!P—jèOgÆ:¹
÷ªÜb4;?Ît}á"H§:JÀ·SLåõáMz{Š„ô}5>{ú6߆5´Vî“ï*hÖ,œ¼?& `ü¨ãœ£°}‹]
RúDÄ­ª{<ú]þwóp| /eÞŠÁK
¼-IÜ>¯=ú‘סŸ^¦iúUøøö2BÄÂMì
k£]â^‡A¦j1µ˜ú‚„8á€ÂØCú¤Ç.ØnPÙ°'¢æÔÄÕ«®þéé†ë–”pa{Ķ!†bè†Ø:uÓª
¬Ÿ-ÍÈ
™¬Ü8rúé¹%#v´Å˜ŒÌ_¾¹^\ž6׌‰n}r\±2}Y½@Ps ê·ihpúÞþÕ8*¬ YØÏMÄ­´ºý—ùh°¤å™á©«ÅöÕ=RAY¸ìk¼ÄsY²çþ׺$
º oäÇèžHÊrvÏN+R8ë„Ú¦1T“³täM(xŽŒ2a½§ë³£8ó£É  M㔈k#b ea—ä8ØÙçÞ‡¦Þ馪#ó!^#FðŸ.\ ²½]‹eŸr«5ÂÕrLñoRú­÷&e-nu;
30÷‰N:¾ ~¬ WE+”Æ0æ
Ý Þ!.ËÏOÕÞ_ÅiW(…‡Qx€ ^¼Þõ:8óÖó…(ôÒCZõ\¡¦=^É蚊•äZ<â§Ü>âTË>ªHmu‰¿Ú\ HŽÿBN3e+ìí‰3rÎ!錮ÝD­bIWI‹ZW4hH„/K-%4¹†׆ø¶ä
;䃀·©oyÄ,q[îÂÐù@eP` àôH á DÉCØÒ$¥²sç [é`ê
ƒ–ÞŸ%™0à7Þ dݻ܋¿±èä€Þ:¶™žyPntòNÏ 8î-Ùz—BîL r†Â¿\BÕzkžÀ‰ñbb1ùöíî–áÝYv¶#r.@ÔíT»Ê‚þÌx…I ö÷pɨûÏ=i;ßhŽh•¬÷ˆÿj¡§ó׌ÇÎæ2ß.êúöšM¬€e
e5ia“ç»%„AY?=Þnܼ—[¡#¯”æe.Ð#3ÆŒPÓ–âÏûS¾è:‚Œ­ØEWH6™DsqRÈ ƒ?OÓí®X_ßÁè Ô'Ó-„^‰µÃÓ0%|ŽHI»X¢EäÒW©-8£ w&*÷ŸR j'o¦,òO±±·œÒ¼ÿ¬„Ì–vDî3ubŒúÔZ/Í
<¢‹c,ƒµ×´
³iǝþ#"FÞ&ì¸Ã((réflyÐiÒÅG »Óe¸0›¹³AbAÏ*ºwW.m®Ùê–)Áͦ¼î†/6t[ûÝY:ð"S÷Ð(Êa!Kgaêá$Kâ¦VxÃ×Ùý8¥fødÒ7q:Ohj,Ôn:PÍÛÙÌK­?N–´:¥oS1ÀàÅ(D’t
’åùW0#ž>ì%ôãâxt$˜ž;¶Ðr ø×8‘Sþ?ÇïÎŽ°0ñ¯_ɇØdE~Y~w1..0¿jÀMf­Öf}äåôh\DÉ‚þM üÑ$þûí­O¨¦ITš =ñµÍ¿bèîók˜™¶ØŒù¦ASßsÌ0„úÞ<†®î©k_X™™,¸Þ:›–è8b1^¾úíQ:M^ fIé,á³ÙJA¸ÕØ=ý¬wHØSî3 þj
EÔà ÓÀª\1À{­Õ%°¾7É.C%¡ÙÙd~Þìÿ*nˆù†-nCà‹vQ)òï@,nãUÍÿ‹ädO‚Z¦-a/¨r½¼ËPhBy`Ū]Žë³m‘JájlƒuÜR„ÝŒD<$‘¬ÉDEµïÁ¢}~ŒîD°É@tžXQDÏÒ)¡n×ômiC—áë/:)™øòsž#¹A¯\çøƒ9û/d#s$é™6gÙê¶P+ÿ‡åø ®á~f



~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~Contents of C:\Windows\System32\odopeci.bat~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~



  
  
  !(*$#+2$(! *)#4)5" 4%#

JR- XB X;_Y
@]@
o8HrP[7e;Qn p6'W 
x-yP]\€F[|kV^ˆ`z`N4Y6jd f} b9U”¨>Žh+€=u›6+W¡¡6µ|7`SZ¼fH—7Œ¡¿ nFÏw¢q³r±« i^ð>2Ôç~O±© ÐÅ…$² Ê™䢕+
Z–@û±FzDïåk-zZnÑH§Ø÷×â0w¥øÛ!:— ¼' ½,øA
ƒ B4÷8ºVÂÒ°É
Ú8å÷·£™V‡/&™ý0<Êaí„  mHH5[PÉÅQÆa”æMF¿i !99 ¨µ¯g-üë`02ß«=Í>Gtr$Iü]%Uïg
OÂc/º¨÷¡Q|r Þ‡o`qáák€©gbÐY:B«sZdër¤K°Bñp¨KÂ2n›}g4®¾G´°$b ñ)ÃŒ•³ÀS5|hŠ“²EImm.¯ýVD·ØÂ!‰ÈP%ÈÕuJ]u¯giêî+G2˜}lÅÏc{ÿÒnrIk‹îX
c!µòV\Ëñ³vó[L.(! º bÔ³±ê·DeŽõa}Úmëm¶%X¯ȰåõÉ"O¡®|¸EROÀ»ñ¸Sž‰®…?»‡i\ˆ ¯myÿd?«6»,Ô*Þ &œ¶)3ß%µcUHQu¶[ïßö7«*Ä•!‚ÉBB;X9_„z;¹vfì€'n˜ÔÞ/€Ró?8û
݉H(’ª¹Pý·:%Á7&_h*C‚‘o <ƒÀÚ/€ TõÞçË,Fm3&u÷7Þ'ÊëgìBuнÞ–P0[€¬9i¸gÁ¦/B­o[Þ壓ˆ.QÞ¯¦¶;½–ÎE9„ZIᏰ$b}Vb0éLrs‹ 6,&y;z!ÛÜE+¤h0ÎT|Áo´é¿é"6÷ÍpߪK{o x*¡ÔD$bñÆÊ9 |š^<¨°39Áœ©šœ\
soÿÃéü/·¤%‹ _æ&âJ7ç,Œ›’DÄ-‘^TŸ¢‘¬êl„N]ñÔ…“WZ…#yl{ŸtCëPçDd¡,eŸ;­ð“Ä ?Z¢Ê9Ë›µÉeA\ ÝƒÔºã¢¹úÕŠËÙàéàzKãÌ«º·6É= r™«o´Ì* + ÑB¹„ñ#Æ0Ë:¿Ùv]~€·aµ¡O6–ÄõÿŸc]—ùk%Ä2
È&I;ÜÅ» ßÜ}
›Á¿x
Âaåë[VäìF°e´"f5œ.ÉøÕ~ž×{[/öŒ B›t‰p;>•Tè(fß7& ˜-% 5qÒam]ù‡0h‰Ò z¸"k .G§Ç­bûEÊÒ®{ e¦Š$š2*áÎÞHf,0Ãv’C\Oÿ‘xóVž 615´nKè+¡~×ÌÍ'ÅxÔý0}.jXòEâ*²h¥Ðeæ@Ö
°¹ìv28>$±Ç_+ßä(øäXòˆlA?°ä΍k´‡à%x/v*ŽEöwÂPh‰ñóL¥ÿ{ êÊ.¡&‡>GÄDÀ9iB°Èû÷ õГŸg¹ Øj×íkì´ºÝ0*üQ÷+¨bXñ™úã#Ÿò‡Âg­ŸÈ÷WE2ˆ2QÖ9-¾ä¡VG‹Mï¹½?eí¾ã5èñ^‘(ÒÄnæC«:7§Ÿÿ
I –% ‘n²2ºÄkù+%¯ø(ºj·ƒûŽæXdh“j2¾ÑPˆÒÿÒQ›÷:I™j!W™D€6e0ÎД`Sijþí¢ˆ¯ œÈ;·SklǡȐzA‘Û!Þæ"’‰§¹úgN˜–ƒ±}ê˜y ÎÀ6·ëÄ×’Od8±!$–
†fRìïl‘D$’CÕ8
OFJ\êk°ÀÞå t¡w
Að7ÎÛpztEi/m €4ß4Þ¤qÁ¥›×@v¤„‰¸ºÑ´Q7{@d‚Y§
¸87ÝŽµO¹‡ÌyR±t!苦†í؏ŸŽ'æGgÊ _ÅKÛ4ê_ÿQû~
-H|lfΉvøÇ¿$s ¾¤N À Œz¦‰Nàø~T1?4(qPÇè_ˆp¿pÚ (춆~¸ c9 _5`{ÉËz*Z¸ÁWÑ:¬û÷·âÈüÍÊs³Îˆì®:äî²±'hDgÔh¹½÷ECÄXØW(%å«&GX;ï»V ¢¯)Ø ÀÛf$Í€ ûq쩳µýä1Q°¢–öÓþ ð¡q†È
Øv$Œ§t½4À—hÜ gÄ å ñWSÄ D€È”™36O‚Tp®Â”{1š˜<ð¦]˜KÊKÉsÜÊ&Z;ØPz>Ș?,ÕrCÚ‚jí˜PôÙ.íN¾at×B+š²š?oKî¶tÌb†!Éc9‚òs;Џ~}íæ1e)m.þ-ñ3ÁÂ2‚ŸÌÂð=† ÏÐ"=‡Žžû;Ÿ‡•û;š@8RùŒÝÆd!ú¯Iæ<¸JÞ³*ëøÌ¹%5‡bv3‹.¿mj{ÑèTª*ˆ.Ä£©ÉOBõbæÕò¸¬ûFÔIßbÙ¯QƳނ›¥E?GP;Ú¡]jF³[Háøî÷dµÈþˆö
ZGN™8ŏ­¸/ï
à:wW«}ž\ÂßåME¶tËiˆû֣ĈÒéì~%!DÈN›&Ž &ŒÑÇÒv£¸¦¥ó΃fòŸ`+Ø~Ý
ŠÓÎã"ѰØ<éx×Ör°ÕÆ‚í –\g*ÌPÍÙý Œ…!xø¯H0ZWÔÓMk†Ó…{Yô‹>‡Ÿz”_qGë ë’Ðô¥sY⇖FLº(ÿp[VmU\:iÖ˜à4r# zGtQîD)
÷ÿ‡9_RšQr/ág wdˆñ 7°âݯ݀ƒ&tJq;Á
ƒ½9ïmy!–”~¥’¹œœÜl?QW$˜[ÐFsŽgWÔ%h=œ¥+¶ç@RYû
p3cŸ6.ÝõÇô³Vöó‡Rœ˜¤z4uy†ò®]*ÉŸŒ¯ÀkcÞù~ØðØ?n–Ê£ÿ´ŽÄnÆçNS=B™‹NsñË~¾ÚÄ›à³êâ&\-Nžp¬Û—ŒÃV:w4~°C1œÈé5 D+Üéjú&ºë×—ôf0ž pZ<ƒÆ]$šg)OŽ’ÿ_ä}Œq&É£r‡aÝiu„ǻَJ,9‚žX‡šƒžÞëÑ™K,Ö„¡ŠƒIJ9BvP¾KÊ… ‰Aëîé’7ÆÁÍSä—ºÏO¬.¦
ß‚G’ ÂbÝ–I®T¼®/3~‡·×ÉÀë =úuÁË>ËÇc– X?)œèÅ€)(þ‘óp+RÍV«åq¨æþ Ç{µf¸ûöIòO6ߢùœ¾|ÚÞÃóè‘¶.F lγ¾V#»ö¥ÛÿÆœ¢Iü]Ú
kÝx‹Gˆœ¡AœÚ_m¾DølKÊ÷ü `ý–«”9ã6³á:¶<€Ü•ðaÜX±å& £O©€Ë"Ý=ʤ?¨ƒV (ZŠ|ÃFÀRc&îznò*»K0$nÊdžlnâ ‡v^»‚³ç‚ø’
qäŠçSü¶_Ïë³áºìÓˆ‘äšÍiG§A_üà³§¼³Â¦‹“±Ò ^a·jŒ'ðºOmO'êTJ3’5þ“†á]ÎHÕ jœÅ)£Qßkø—Ùi>iÈäç߿ˠz— ›[²>5žl˜a l12mØ´Ã "kû°.ü N“ÀŸ?MfñPã&V;£l¾ÎµUÙÅdRf£]½€ªoàOXÕ+– ¢<@eHià"ê h»@ò§ù¾Sã÷|VN¼Èëu+N€/°6˜µ”Ñ)‡ Ú ’¶ù¡møƒ6|:Ô0¬Ê=0ì/
ÞMöv“¦ ­Sþd F™¼üGWCûOþ€sÜpÙÝ¡öow¢ÔL‹ÜÀ
ÅgDǘ`Én/„“#8€4¤ ¨¯©ÕÀø
’ Ñ®wé:·ÒsÄ``ÉÍ)ðF‹ÅÊ'2^+÷eè ^jŠõãù¯ðDp¼«ž(³ó°1:ñ‘Š”LÆ
&Ãÿ+”‹”8c÷ÍSìY{ûìE€jBÛ£@û/ÝzTƒ)NcûüN7˜ÍâyüÆ`O”¯“ð2ºçÛž«¥½Ž©rÇêÜ(•Š>£T°±}¿ÿl-Þ¯|ÍZÜ×B ö«¦Æ…(×±#ö¸–Xw¨TA¶mKâ¶ÑÅþmfeÛ
â@–Ñ@Lx2”Я†=ì’ÃJ $Dyb^W¾*æÛËoDNUÓ[àžÝ%¨ Ñ”ÚÖÏcÙÿa{|¡¢±NBÆÚkCfëÎcÕ€ÒßÀŒ?2HMDP—ÉóýG.×P¿/“Ù”ƇŠ7$:ºèÈõù˜îjm ±©?ÀóÚ(£¿FVýä¶®½ÑVíJÊŠ´áL™txVÖJNãï(ͱ'Æb9°Vð9V!64öOYŠÛO•by'éázkxÒmøZ€»Í¿„y s@ zë˜ö®Ìæ×QvPíY€ °{X‘ŸPN‰!1cüäcÕ±®fÄQx÷(p”3©Ð©™$Ø@
~‘9‡ÐâU&ÇcŽQþ|‘ÐÔÄ‚‡´""öLì Ô!!Vᘓ¼€} @íÀÇ^!x(æ· +¬ô_¨:€Rás×+¸rÚ*M׉=šÃË&7¾UÁÙ–·¼w6—•Ê)
ôbãîèÊÎ7´m{6ÿ¥Jg#Âø¢ëkθ»O–¨0ï‘Zd@¬”gyžîÍéx™çž­¿m؈%8Gš¤ø5—vR‡y·qãÍÈzé°Uxµ¶)uh$.S2ÔE6ë† ãb `8iôCGGhŒ2L™˜1âÒfT¿TýN0-›%›ñE!BýÔ:/ÿ丅•DµÃ›­Ý0˃™7‚0‘ʧœlˆco NTR~<ÆŒgfìx
Ï*¶³Yc€2 B0Æ£ŠXÔÍÞÀ˜ÍxC•NŽäuLÞàæÍ¯ÍðÞLНR¸ šĪ—-/ÝkDÒä€å‘n^eÎÑkíxÙš}þòk‡3eœ8öœÜnÉ%À¸Ínf2'Ì­:È]@Rf¯%”q#áô؍89•‰óÑ8Û²q´âÓ2‹4ï;)ˆä)+""R,<2.¡æ,*ø}¸V` lÒûÕ&;%°ÿ‹c½åøõIƒGÓêc 9–}U¨Þ—W¤ë_ &þ-.û™Þæ×L›tÜÜn
Æœ%"D…œUàßì§à쾺"Úbó…B›\0©'ßUM¤Š®£ŽR¡ 3zh.ƒZŽ/wk­¯6ÁšRKeßTi¢<ˆÿ?hÁ»ëSþèd–
ÊÑt°ZÄCB¼þrŒ€Ž†.'iKŠQþýêŠß‡gæ¬âĸÝqŽt½wN .P~ £]Üc¼
®0@˜ˆ®’|© T-øñ<–Z“$y¸ [å]ìÕ£æÿźñÅAPf{å mwÖ¿-À¼øµ¦²tß\lW|"š#®º`pE!›Ïl]tî€=4\xsË ¬a9+닉¹9e-‚4ÍUó~ðh\> ر˜mðkF ÈFÙ|U
l;+ç‹ÛxÜúÇŠoŒÍÉŽ/œßçà{s‚æ51 !QpÅݺ)Ük¤š”aewÕ¬ÙµzXt” M†‘UR m9?øHBXÑ¡ W8ËžC … n·%Û½Ìåúú´Ð†
ÿSPæ…Ö¬ŠìwTô–ÐSù«æ,Ï\_°ÕÊj|½k;lj[HŸ¾Šû'aïsŽkxOœÖ§)¨¿mxU¢
!‡-û‹¡ßú”QIªÞÝ$m‘Âéÿ|Z/¶—;
unôµ*‰N´$9gÍ}DëY¿&•\p‡í*à ‰-&UðèRƹÑÙÅ™Q®UኦݡqF:ðð$Oû˜ð¹•¨Å³„Ö®ÄGÇ›ÆL(؉Œ|Gðk
p{5‹j‰ÂÙ:Ìܤ‘™¤WÌ|1¨CR½ò¥ClblÕ´*`&¿ðŸ—f²æið”*rhwˆ®„ÌgØ›¡.ußc¡´²_¢Öõu2SWxt”V/èq;ço6Ìš›T뀃à†ßt"‹·n%
ä ôߺ/ƒ5°1Q9C“ˆËÎ޲t½:å
+ÆÔ™[¼Ëˆ°íø[µApُåLÊÓ±÷=9Ñ ]…¼VJáµÙ!uBƒºŸ0¸6ä!Ÿ
$ãŸ*¢¡ŠÁj__(yäûÌ< Œˆÿ,LÀ˜5€w|uèàÝ/æÖ
¿Ä=¤á¤òd~Ðý0€ûdk +0û^8@Kvœ:øÚH!Ü0r+¬Ùm0Æ]OIÁRå`0–¿£SÖ
™ñŪÔù%Jnãf•¥´Ú¨‡/&ʱ|hÅsšc*ååÝ—àda[“¿2KÕ (IQ*<ý
ßEa¾`l†ìMB!ÖÔ“ 4…´FŒžLý‡zt*(ó}Ý ‘ÔÛpÕ¡EÕU¦j<>Jm4Y°¥‹&]>¡x5‡0¹
œpv(þÿÆ$»ÞñâŽñ€†z ø¬y6œt¶‚SY*˜`(ÞºhˆÉD½‚"‹ÍwÛýÒ(¸ò¾o h¸ µÑ2鑉2Mè¤Qã,¡¶’HÌRñ;$ðBÀˆ:…ðûØgyGo&æ–?ã\úB#°†7b “¹Å«TE¢Õd›(Ž%Fý&¦A/¥ËÇVKÁÂ0ƒ ^ékŒî}žÓÐ_ÆSÿÛâüYŠ=W7RåCûÝ>ˆÿa¸á÷¾+'òÔ%y"}(ú=LNæõRŸÓ6l½ëKrÔØKóSÜè½-
WÞE“à ٟԸä_§‹•«êf'¨+(Hstoš/\ÎÙüö0w9È­ÝÐU›û,rÔ
hí1DAO½ÁdøE4¶½ýj«fkwn‘ºÄë¤ÕGË.}1
,®‚XÑ—YŽû!AdŒ™¸³LÕãs/Èèý3’JرÀ…8U!î ¯ƒ@ô£*^Xm¢ >3;£Ñò{ŠÙÂé|øÖÏNy„à,†ËÅò'–o©*+-g4`¹c¶‘@†•_“í©Oz}oÙ§øE†Ñs´ÿLp³âí89­
.:ø>(¡-ƒ V³yŸÍ/k‚¤48žqUÑòw6 ñäW0îÿŸ´õß‰‹.C5-b^z‰DÿX†s½ÿù×ÐÀ•Iß‘T¨oh~ê1 V0ˆ]t^2”XÒÇ E?
Z´³O%½­ ¤5+ÕÏ{xÐ^VC—~l{Ét}¯ßсC7báþŸØ¡L*òDÇÝø™f]"%ŽJµBalFTøýŠ_\Ü%{“`þr!ìÝl'A_¬Qõ/ $¾á&›ýz*tH¿àÑP}ഝ{ÈÆó~‹v5Š‹"Á ûñj§¾ rŒÌBÅøŠ9£™
¦)3Ð Ÿ±YÂWmÍIXK€¶P>öŒjJ/}¬ÊòqÇ ¢Gý;‰=r}PÎÄ+Ïpšž åøvãù¸Ódˆ±&öfÉl– „߁µ¹ÖÏ.òFMz¾‘ÿøãí€æ{õm¼¬X˜b³:†ÄvüÉÓ)Â}nKY{´:‘cŠÝá› ý04×¢ö+`9+ŸªŽJGf¦:)ÅË(HÐ6ÿ
ª â{„¥îѰ!õzÎ[«Áu¾™ù¶ÉŽ|ýLtm8m Ä.1¹C7»CôÇvr¶áÍ . t£LØ/|îNÜ~yåW/Z‰»$¿‚â?ÏokÕReÊø
B(
Qà°™´*)3,Yz{8ÛŽKÀ(YíêË„hŠï®çÃo©Ú«3¡KÓr¢¦ƒ`Û-c v“Q8¤§‰jaú˫ǝD[Xt÷„C*î²èÂ7”¢Ûš—¾f1òÏ—§¼õhL´uËÛa SÚô1t‡mÝ ¶ ¯ùYñîi2•½a©’…А¢…ŸÛμÚȸ‚ª"CÒ¥[t´ïÅ Ñp—Gv7^°q¹ħˆÍ’ºã-J¾¿²slÂÞxéÀH¢ƒ#ææ'Û͹¿2BÐë‹•û#¼"¹ËÿÇbå5«_HÝA]MŠIõ]zІÆÞž3›M/–í/¤È Vrk+,ç*Uoæ:•MN§ÝQ÷0nøck4?%Ý¢ÉéŒB ã,O3ˆžy™9¯¬ØÉ6Jä¯By¡64/+ƒ·2ã‚9û‰F“}'ü,j›ˆÊ2ÝNð·áÿ㢗ïℼ1±ÊÛ B­äUÇ/øtÇ,ôbèF–4HïöBˆ1½¦^ӌȥŽùLÛƒªçôcqx&·þ›)_\ŽA¾GY†û·ÙJ'jrÅà˜&Öx"›5‰Ùb.8ƒzßQæGùÇsÂQé|‡‡ô·\Û=m
Ò¼‹ò›ƒù¬£¦>¹¯q‘w˜ŒÌÿ^p _Æb18Û#â»­; \më. ØOhb@ø}:* ð‰âMŒ)€UÜçÙr¨WÅÐD[òŸ€I˜iýŠÊç*-߀ï…ªðÉpî‡ Uâ?„âu&·VÈc¹lç]æS=³öÚ:oQ­Z(ùn\ì`upiÁhnE¼Q9¶Íƒ¸Î/m š„‹K?,sø³¸ -¸¯BDè#¶!Ù5ïH~î„VìTôÆ‹$Æç«6ŒÀWÍëÎÿc—øÌÄ_éºa’Ý)Šñ¬BAç™5ÔÒ¼=S<”4ܶWP-ˆã-:â^DãŸ@À<ΠHõëŒÛ(;JÀ6PÔ+¡‡Ý<ù`ýŠdÓ8 Îìb꒍mb׎‡KüÀè–Öô
5/˜´x$€\]8×jý`
‰ÜÐ
Œ¢T›òT@\0Ø…v{¡/ˆÁ8†âšîÚ=¾^\DÈ&¬}N^Ý/å¡G¿ƒî÷®§£d1ÊÚý´R¤6·ýϳfžŠL†‘TV½+ÙŽŽô(ë£R?ÿÄãè#!—ýdþS5Öºoþñ;„(ÈÚÉš 6G©‘Cq”liú]¯ô14âÜ
àBšäWÐhÄ$è[þo)¥ëÈ^«®A9ùw$2n{Æäv3û(…áa­ vó@óúE¡kCM `³G`2~YoÓ¯c}
÷êj)añ¢ôÑÑÁÓB"2„Êw½ÎÄ×/ë93Ê€6{3å §Š0ÌœÏ0.V¼v<ÄÚz'B¶Ùªâ½ø€) @ɲ¨fRnƒcñ…rþKtîÛ6ùu^žð^2ìfè›±f
ÿ€ôSuY† ð°mP9–ÿƒUd=™ŒàÔË9Û2Ý(½41àKiJ7Žðéi õeeI©>œ€P .3zâô}¢d^‡C˜üÅ/’“‘Lš~ò‚€XüøìÑ0Ð?f"`¿´‹êáçµq2z¤¯^Frã’|›çžkyv:A-O¤œ³zúug•°#Aœ&7å›¶ü½qßú{Öí
‰S‹›æ#ü+üèk Q*ÈTš.V…i±ë,&c;çëž°íÁûa»xBp@cÂc€^#èI–h8ýî?6ß<=›™lõbNãȃþ.v®A3Ÿ’t|59h¨v|žlŒžlÙß E-{\¸©ÔØ[¡ƒÔ¥Ò¨”^ýcèJ­Õ#  «^+%59(?PxºÓD‘fqL"v…t*Î'ýÁ‹¨Õ)U–9ì{õI…<§_,]z‡®·
Q–> ¤½ ƒÑ^\ãvʃÔ˜àA—{6K“_É×D[9 ÚŸ|Ò‚ðUìŠÍ9 á¼ý3éK£¼ào½I\\ÛÑáDE㏊«ÚC€ ÌÓFã N7ˆöÊuYo('&È‚´¼97õ%/pù&’Ùh/ÿÃC°¦Qk$
#Á 5›ÔÐR‹º¦Záøþ}ÄJBŒ¨41WIŸ+|'¹€8çÅ(”›tá`Ë™Ê: |™š€Ö ìá
â9«ä?æ"ëœk¦räÍåFË~E¼=È\0ð];—¢¥Ú„Ú.^Luk
’¥*¨«ÄWHe«AÈáLo”5`ºÈÒˆW©×ÎQ7ÑX YdÜ¢LÑòm{ÍÚ’j‰¸!Rˆ ÿ¥b^eã
vJ™}÷7õÃþ\«LÑ´z—¼æ÷Ëç
X÷œ7#vû¯íàñ rfB\Hž29è°&›†îT—L<=‰Ì4 ”1é„ËôŽJŒ_×þqJ–çþJT¿îC"é—F¼IvtÃj&Òrlì+Ó#6
A0ý $(“K›U·õüxý–êÁοßãz‡û®£Ýpã¹Þ¾Džá«oùý'~P¨r¹h/‹¼:¯ð|°r°
6vÖ'» ÇœàlÂÇî¹rÁ僬²F”*‡þœâ“a%´Bîû%˜ãkwÇõö†L߁PxH§7æ;uF‘ãòõlt/Å¡ Þy.
V\jÖ¨Ë µæ³Ûñ=i
>^oF3s|] î­ªmö4åÐ:ÏP³Ä±¾°Â[¤-ªCã4¡Û’ͯLêÊ&ªn4¯L¥q\WKþ~Ý®ÏвÑÄ¥%¾ µsp ù*˜Gþ8’œÜ”§–uKQî·å4V›±@ m‡@a_ûm-Ëì† eÃ*3§?Â<ž°ºŒï¦X°¿B©Þ©À²;èÙ°£9MkÕ ù[ª¶»ßˆ®¼,y‰[¹Šâvc%éyjÜØÝª²XXŐ†fºç^„0½»˜iÝ|BéÖbÿw­~Œjªˆ6ïÑé†ÏrNËP–ˆ2ßg˜C¸¬8³ß7ãHVW‹l†`npõŸY-•Jké/´hü[M´A‰ÿñÓåðÌ#Ζ’rfCÂeî&õC„u}¼{;tMVÐŒÜãa>‡öÊ'¼M²BDÄ®‚Ä=-ܼc
SãEï•jXöAV‚×4!-f¿õЦ½dò˺‹e—E›d™Ûm¨ÕJ댰‰ïoœžƒPsÜûŠÊò Áë†4©ØÛ)YL’Ž„1ª¤ [üÇpº—¶,ä)Š-°¯ïü°ƒr‰žÇýLÅ4«ÂZ\B S\ÈõðA( ¥ð šmþryÜ~XÁ™‘šh›?”’d.ïϰ€•o³!
·J0Aâ qýG5¥*~y›“¹Ç¼–ÑÕ©æ,¼å%V[+T2~ëÚfoëž<¥=L^’jM“‚î—ñU>8EÀ€<$áo´n@/ôÆÖ–—äãþJpíÿZ¤”±±™Ú„gV^Ò4ƒ´ÍŽ»`¹yîŠ+¨Môb¡œ>¸5A.í­U@]úCÎ;LåÙ¹†.Úò^x‰4âã訄]"(†ò$ã-nKh:?2RlÃŽãæÀ”r ”®%¯,ëxsžÆWªµË“ÆYºvF9²ÁäÁôØJ]|Lí=ÕÙ>¬ö\°¬½~§Òùß<:Øó%&Å‹)!J,6ˆŠÔ`//Ztð6’, ‡ð-e¹2sC¾¯^er3Hi6°ç€|`ÖJ™oqf»œÖ¦R›Šì@¤0×^¡¼=Ll8sv²˜§:ˆ½ÉÍí'*裺y ~¡‘ Ò_Ñ äð±+#µqÿë†}$ÌÒ[eÛ¯§Å &C4;úà Œ²gÓ¥—<Šx1`5±…dC,ŽðH*µEZuU9G­2—¹Öíž[óòEUµÍЗMÕâè6nÖ騁T_¾×®7Q–]^WDÎØ5Þ:™7
›ÏaúnëBÅ‚dºC^Yÿ“p¯LäÖ Î–ÆâÍ¿Ž=£Åó.ò8K`U[£‚÷Sû¡7"‡kr ´ªƒR¨:óKÍh•Kö1Ô.ƒŒª­Y¦k
ÛÇä¼ßTªÀ¶;ÕmÉgáÇ¥°áTKäðPŸì¾ “¡S„øEœ¤6Iß*Ü{ %ª£÷‡ Mƾ¿âY9sóž¹z–{¼“d1íQMCkÀ-œ`*ë7õLÀ4ÈïÜŠN-{€{vÉ‹‘ü”Oô&ç$ó‚ÀÒé„[Ô^H$?w—Éò%A̧Q½D$dú]>ä ƒþgõÃä¹8€ÉÙOžèˆüdÁ}pü–á>%­[]$‡I"Ε«Y÷¿íTYåÁ´ö1hýªï*ë
Hµîu‘b SJMMYíɦÞB“ó£{´4‚?·îìwC,ôÈ?LŽâ7ÊKû`ò³ÛÎûÒ¯.3ÌyáÝèÕÀ$ÀrG_kTþ=m]‰zMC „kV„h5Ÿ
µ³¢(I˜$?^´Ðe(zÞ«”ÀŸyùçw6N/Éø
k5 ºí§Œª`0#—-Gðf¸ƒH
:º®¼êx Î
ý0¸º}hw1µô7¨¤‡ ñ$+åwà
¸Ê󇳍köGP‹Ø”/Up¿ìõﵪ²§ef¹i ©¸žíf…4nU¿<`¿ÀXƒÍ!j4ˆ¶-ÐÝWÝiôWtI&鶁i}¢Õ¹fd±qE¥Ý{=çoÔ8Qðf•зø^Ťõ{¿r;ðË‘4/RüÎÄ–Ðh
ãsoÖ+»tXcYï½gPâ±LµÛúÂG·—¡¬¯÷[ŽK ¨Z‘du¥ñŒwÀ©ƒùÑè±·5ÚÓp€ž…ñ£îL¦£ßŠVȽç
ïô2TÉžàÏ¡lƳ@Ë-hÝßô-à³ÌÞ1,2Yç}uHéC é WP'Žÿ•Ô^.¢?­Eˆ¬ÒXúÅâ©NÐÞ8šEË3
Y||¡Ø Z±¼X1}òd«';
Þ§Ò4oÆÀÎ
„´t±çñ¬†ŸãXl€oii +…S ‰ûvÓÓ÷ûŠ#ÀëѲŽýs”y µ –3+ ·˜÷Óèwð˜¨|H]ïô´Ì¢=p@šýýÿ•% r|„yûH+£·ÊÅ$¤½µëß~m˜ñl×ËFb#q èŒ?0ñßûoÍʇkt=,ºg×QÍ9OQ4TUf©dÎÛ8A¹u1$ÜÏ­ÞŸP²N•’'AÇ*#½´Ø¸Öxc[EØY&W;§ý6™#ä»ÙÚ¡w0l¶Vþ†•kœ;†›Ë‰K!•,ƒ­žu³ªÂìé>ÖñÊ:7K]íǯ.E P¡UuˆaÛs:F@òkh˜é Voi{›ÅÊ¢þªÄU“ñ£¶
¥Ü—ZåŒR‡àñ½í·K“~?mRíVÔ0«´ç¨Š:A,Ѷˉù55듺*m^¬¹OJÐ “3BÚ6’Ï ôá›õž-ðÈì? à+\¶ úxðgWϐYªpª¢–šënæÖÓYêÜq³ÁðX.“‘\“¸wƒ9£7G:û,3ˆ± }á>$G~˜#»Tð¾ËÖÞÛ|òŽI~$SÚɐ‘œ˜q\.K€”1ÀpE#æÏñ“X÷ 7›¤Â0^÷2”P"‡>xØy¬ä¢ BcÈQ'(3v#B6.’!,ë8ÛÓ·š|"\úó~‘[G¤î-–§‘ɇƒíRÜ3µè%,Ø–áæå(M=-|cad‹Àí>^ÈÃèCy, è}?'ÎãŸò« ÒyýâTd_}®•ä¶}ÐX%ï'âè©B1:A=|dPpÿ;cbÜ¿¶kg4!z²&‘WÒ&Ò9MÇ÷b†Dà#|³Tq0ÿÚc•H
޳̐`-k”\öÕ-þx¨
­ÛÀƒe]› §\’wwß? ®@6’j…éG—J<Ì?)!Boåº]yæç³·'ÿÝ<^„ÒÈÌfµ@ØðOÃ@6°Xâc)æ/Ç¿³+°µK\é "rםT3á=pƸ‚)  ÙZÁÉmee%X
àt×¶˜¯T¥Ñɲë"[0‰”œÚ­7ª›ÇŠB2ó†%@— $hz¾ÖdJÒ€°TjJbDÓNÖ4)´ZdZÉî­)Q’°ž¨É$xlbºšb¥†’Ü‚ÕÔÕuºÌO6HÊ
˜ÙaVÒ˜Ì}1fc•¶ÒˆCÿè‘éí–ÐŽ×EÒ¦èÿ»toGþŽ«|+WB_†¶\ƒ"ñ띵^Ñ©F—°ëŔ EY¯ˆAF—®psU–*Ðx¦2!Ïç®:
¹H†èÖ¡%¯3Fgœõ_X ‘]ô´˜‡ÐH)Ï„í–Â[í:;”ÛßâõK%ýU¸ ¦­h"êÓÒ MÇøŽ“óufÍf- Ñ_3%j)xYþ Cæ¢lBNzaÍ1V†L£‡ì"5Dz@RóÔ•PXG³N›|üKÝöUðʺö‹y|¢a›ÎLí¥„E 0%«„áТ³NT(ƒžß½íUJà]9!7~ƒØUj8˜þè‚qË£
»rkó S ´Ÿz‰Ê“§!÷ÃȲ¢ÕVŠ}D çIϯº³ï¨T+Û«ù%¦=*õ4ÁÊC)S‘üyl_¿;‰Zmˏé8íÍ`•ÚS1,øÊî.=ŽkãpÃÛØF
ûÂisB²TÒ8OæGhï‘ÔÚ8L1š¼jü3á©
5T—òŒ‡¢þÍ}bE©û—µøòäC†_O:…‡8E®p}Y«?䵊Ÿ¹Î»9²€
(R³geü¢Ô™RG‰tô|Õiت¿©Ÿy+:Ó†EaÐôíæ+ÊÐG7¼Ï»Ó
äóË*46#»R x°µÝjÒÁn UJþÈZ¼$ªkõ5œî¶¥³á¢ ÎçæŸÝ–2aꯀ„
Ái´…Œ$Úúa’®{ƒ\#^ÜøåügS¼w?O)¸K—²Óøó Â&¤s_D
}.~€ÛÏMøOæ²­[ÚÀyÝf$Ô:ë7OÔ@ÆdO#&73‡mÐÑ»FÆÏ@{7 ymZ6LU™ù.oЧ&ü¸Hª}øRsø-ó÷0ÙÉFMÙ'ejeÀt ‡Ýp\9ËôÒ€©¶±†®#ÈxzÇ Ä½$Ç…ÁÝµ$‘ÝZ="|¸eÝÄ•/ù©’Adœ‰&o;æȁ¿ nb›*“[´üûÑk&ÈHa’ lV2­ì†½Øq `0/Ãî>µ]ÞÜÜPÀNb§kw G¤Ú£ºpH3»zƒÐ/C®\Ñݐ‹2!@”p“<+6rw?í‚¶b–-èD¿1À œäCÅÄzSßñB“£Y!‘j¥²ÉPúí9iâîãYsèzÞ©‹ñë_™gÂÖÀ‰Ý4Ãqñ0ͤ‡Ô£} SfS7%Ó[ÞWK˜uªV¤l§FŠ^#>*(Šä_Å,ò?Sö ”½÷×±k§FvØ’˜*¥~ü‚‹{ڪĢÏ*·šrf5nÖWôòܦ[9aKæ#³ªŸ/Òn"Y-ÌçãüìdŸ&N;:ôÈqô6n!áv`˜2Ì´h0ÿh¬-òìÓ[tìÒzß :/7ÍÜ}Ÿ¨‹e««7¹ pÖ`ujêìyªV´Y+I›á½,ÎO GRýò•Þ¨‡rzmŽF]ˆ÷»Ú™á(9ÆÍl'(dgú™÷ª&p;˜ÆûÒ˜z2g".ÃÑ2ý7Z
ÛÅ`B»Ò}€o¹1ÚuÄ
iOx2
`ú®Œ¥ÇÖµ€z\ëI²r“¹Ö›0˜â§05[£™4ô®ësß­¾mÓ6E<6ç{{37²o*wf‘K¨Ð€ù£ôô
9Á•êéDø’q ( &õ/Úƒ Ë?”¦SɓӨ$ªÈëyÙ¥þÍÙÐhbþ„ˆÖ?å¡¶Œ0K,íZ&¥óÏîNÿœ¬L«—“j=»÷/¹éÃÛÓcó¥»ò웕bŪSA‹¦ Ϗ5º(Í2éÈZå+ÿJvî3ã×Y–NØFØ@Yÿ`dg…6è–F}q3ŸÐ¯‹­ž¨‘×+Š,zðžï¼Ãec—lô1íGç«RâBó{éÏ5ë‡ð}¥Ë@D¯tÓÆÄøŽç¥éCú
é«1 Œ²KÁgwì¢5…4Õ`í»V<ªq-Ìexó\×¢2ài!1új<Ê'©¥@xDj"ÍûMÂwš1äиiwŸŠ1šÌ`_¯)ûÑ
šáÿ]"]›Éò˜bÛñá6vŽK޳­1?©&誢(ô¦Ù>7‚]÷ƒ“Ô;»{ÝŸe¢¡Ü‰MóVÃ%„“éÇ\J%sHÕ&(æ{E&ÍÈ¿~VÕz¼hJ¹59-` Ú!Žm†W–xÜ´^.4leo›„Þy†nzVÆ·üfÏÿßv +
"™‡8J°(tƒËtGN¼Ÿ”†¥ÿwã
JbAÑG–þ" ÑÐé…@ÎА=ÿ#»Ür§N‡Ð;<‘¼PÙg%°™ÓêÌ+b¨Nä#.NšDë6Ž•‡Á“¤¦…áa[€Ãþ¦\ë´¼8Dâìe•F³Áì!ˆwYÿfDû}"ñÀ«VzÈÐK.â‘H`+ÖµÇz‹}]“øw«¶êÒn]U;Ëã6~›t—ÏüÁ¬ºhˆéFñ®Ð1’íRÔR>Œd¯á<ß…[ÇĘ9
;O¶Ê×CI¿ÉW#ͯ©ÌAA™ÉÛ»¦ ù>Y|x‘…˜äFjI}r•>›\^vóŽƒîÙõ˜%U\ŠËÊq¿q&Éu€º‘ø¬úƒ|CvåÏ÷EÒRYH‰×†R5˜gÖQj¹¿D.Ëe[õd€{5ªƒýzŒWOÿO(¢§½)Võ`!3 žk±,í‡E3*&O;úæô5S×syI×§p¼V)KQïÖ5å0ß¾p±ÓTD–!ü™¨iÆ[qhÛÀšÛÍ÷{²JŽŒÜ°?gꔀ٠µßÀ;×,#T`ö°M< Ò‹»•ò(Æ:¿‡èÓú¯]„
@) “}"bWŸ”`+ ÒŽÔÜã$Ù]j;ªløs:< X=†$F|Py<„ïÞtÒ¥iÎÑöÅ_B’™¹¼Ò*!Ô¼„pÅ)"o”y;õw…Aú½6‚ÑQ
…ië¯Ä5»Û/Y… æ½Ð›Üð‰ž\~ÜÑØÜ67"B*´A…#¶€.
®kucÏ©\Ë‹¥ûKi)ëËÇ*è9Ä}…7Ô¿.„µá‹µføm ƒdv½äû`¹\ERÂkaà 7 Q„tý¨ë+u"º®` er<ýsþýáßòÝÏ‚£¹1ö ÍdQVᅯ͡3V¿ìVVÚ•4¤yP° V—¬©qß}ÅœJÄ%õ®½ïÊU)1CÆqåöSls|€à%ùÒÿzÕ¦™[,ª[®ŽÎ#ÄË:ƒE>Wïã nœû~{\®×™óSægƒŽ‚guy\ƒ­ä4ë¿ÿ¶ƒGÒé"‹¨ñ^ühJy«fu¼/EO4±f“î§SÓ§ÀYz–¾:¡M
4(
ÔÊêH(,žq¢7о2+.Y…ZV®¹œ¾ŽKýmU_zVpn^O|¬›^Í!,ÜÂ)ÑN*Oï¹’þŸ°B}è Hº‡kÞT9…©ïoÕ ‡b/Ť†ÁúÙƒjx¾mÿ
ÐMSùðdé½÷ÑxÜ&‘¬4K
-…=]ÈóƒƒGÖ,Â@ÉéÝä&ˆ!+zühØçZ¹x=NÚ'öbeŒ$ûøl|…í;Cí¾@ÚüÏt›÷}TõÁ‹«€ÏÝ¢ØP/Ly¥½cky÷<8ôš­-y&I;ž„l=¼‹Î¸Æ"îqŠ Ì…TÛ¢È|îjJn©E¶²4pÛ~ýÝTqÌç/ïÙДk•\)1^\W/ÔUÅM}ØuYlnî¢{šòŸAm1_ý1PWÜOÓªAñŽh`/žB‡;¿zÝ’xž­ÑèQßÂnË\ǤÝóìÖ‡¥/Wy>8¿—<‹T.&jH; üEX ÷Ő3»ç@lkb
}£zSÄ»¾ŸÈù~gž½Éçp9gˆº4£ê$
v“¸ö¸¬¸†ØC"V½Tî°^½
ø×¡Ðnqø·ÍŠ.ùÚd]yºuK\‡˜ÆÃ(=".ÒÝSÒðEž*mv5§ß Fî p‰HÚÁ…U)ÛhèÁë Õ0ÿ:YÌæØóßð+ Ý?²ÜxquŽó±Ð¥;(gDƺÁu—(­óåÁ'÷þ{ìvÓì!§°`¹¿‚ 5}»ò`Næ/Ù¹ B8ÜGܾ„ا4m÷ÒÆ1ô–+FæFÊãY¬w®e¿§Ú[/Y-ãñVk35c5ÐÔÀ§õ—Umà¨T²Ë`ð8ýâÆyˆÅÙëk€å¢vÃJ…‡'ChŽWÌ·tÏ’j¾‰'+ÑÅínÿ«fäìe@ÎU˜Oõ³îk{J`ZÅûof{öö‡&S;¼
A ð†×Ž9Ô“Œ(2àò¿›½”20Ÿpóäžy>oÅå°è×ˆøl±W-’Yº 0¢ j‘`´ež›ÈÝHË¥—»=A6—Çs¿jHï ß¿Ÿ*$ΐ•÷:à.™5ÃѺ«? j’èÇLî1ð$xú²œ¤MáH6½÷åYÔö…!R3`À9B"µê
ÕWáÞ2Lø™ó‡*¬§lfÙ¿i5Tr€žçwj“ÓܺÄ%âñ
®ÒÌR«3×bÿØ`ò¢E#Î_,wÁ¡Mg£¦tÚØ÷cZ³/8«µvéÆÿ)¨J`¶€cE@wP%†ów¹Ø¿û)‘v”`Í«§8%µc@â[4ÀŸ¤â=A“­nžÒhÞõüܾ×K Vz뜣 ‹˜9?x}­ÏRïuzÊmâo+¢ 5 Ü¹r%gä+»€?„.³ÿÂ&®“Êkx”e™s/‚š¤+휕Œ
›C)Ç9¬Àt{ƒzþ]ä˜yªx@€6ìo~ÿ¾t0€¶§BmæÚ*Ô'Ø€·ä ù»`éÔ1b3®`“åÂßFDA˜„áOnR¤ÿ¡T5Æ ¾_TÑÀÀ®t3±Í±“¼ÉÆó^…ôÒ „¤×’ŽVûT}÷ÒŽýh K˜»®„¯ØÛPW1.JeÀ¶ç@t­ãVù•)Kw#€sâ"¤«‹˜Ü;Þ(‘h6ßrŽAŸƒy¦M‘ûŸj+&ùé¼ýIÍ4{-¡¤bÌ÷ýlEÁú‚Ó]—
iÐÞíauv»÷Í´Ìø+Ä*°7@ê®ü¨ej¸¾á:æêE  ×»9p;Rbr5A~#èܬ¹4ˆ ² ܤzÙ© ‘‡à_MIcr¨+—#4B“ISù„îƒ HvT0$Î% zÐýpҧҝ—è[°_ :F½Ïü w9줠»hú oé-ñ¤³gŽIáîZêŸ JÝÄÚ’—}¹ðXAj /×s=)÷ݺ³~y>ŽÀ— ‡³ÐÀ
ÉX0ë Tm“ýº¦Â­í’•y’IK¢Œg2™zaZäÒ»Uc.°BëÃO§iː"b3_vã"ä~—?6¿9q<Þ ;ô.Äb‚·‹›œš.‹ûòŸãD¯L¿$ÊòÌøÕ­ †¾÷¶ä SÚáõ?åË}ØØ3Sñ[«Ñ„Çá U¨²ã÷¸4ŸüÛ°`ʵHŲQ³¾¬X¥‘“ó}5“9ªòGò‰fÚýíÚÊúº



~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~Contents of c:\documents and settings\All Users\Application Data\lyjysezivi.bat~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~



    
  &./ 6/:>1A=$1-6:*7E?P$"JJB
X 715„Ç7³?Û%Ó.d/W;Wh…B†\^ΐx¢KÖzG4ÚT·D©š!J^Þ>óüº&&S;¢5‚¤ÉJ^í×hd">«ãm®”KH/z M s/Ó4\¶2ƒOt­6~,YMÅrCfn:f¦ZY%·MÞÆÌê0}áOIª'UÌeD@,l™B¤Ëe¨©âéü¤“©F¨=…Û»Äôò‚l6˜lK‡·G{Y{Œ’MÝÜA¿vr
‹„Gì=“‡¶ B“K7í1$tòÛ mбk"-8¾óÞ  Gš¬DßóUtëŠVc8ÖÈåïŠU ävOükC"'U5=BÕÈaP4.™!×ñ]è(3r™ T R÷ö]Ó¼^Fuz¡ñ`;µf³>¼K—|{ 4Yå
zJN„=öò›TGör½”yH©]:䉐®ÅrK+¸¶@¯TTC©°HöŸï5pˆ?nd~ˆ8€.箸Üñ'¾Cûß%2ùŸ`¼oãi#h·.R™è©òÓÀXþÖm´§RÊZý®ïSFÕþh‰Æ0¿zyÑ0ñgÚg™@탒Ø3©Và jD©teBM@`A¹z¼ÿ:ò±‚µÌ˜”²Î"ÝÕb}LzpWÄÜ žUC‰ŒŒ³…ûÜʇlvØg¸AEÛ~øáõn =+GRO#fíœHN‘@.h ¢ÆBb]vð¨™Jüzw#D%Ân¤ðØvK>LB\/ÅM6sЬˆ@‰í_T¶&@)Fú™úÃ&›~a¸ 'ŸŸ& m¹-;Z˜æÍ6«AfºÈ˃© †=ŒŽôâŸ?Ð
â£Î–Ë|† öõµ¤eòõ,ÉîR† ;ßzÇ’NU³ƒ½ÀóŽ åï.ŸB‘£\öÃÐ; ÒYYfúûú –ï¡Ë3ƒÂÄŽ}p‘,!ß>-Ž'ôX>˜EA" $¥ù`
w‡ûz ×…ìÃŒ$x)]Sd53ãH
ÜY·ÉÅ!ßp¿¯î{[îj#ŽÆåF8þU±MšBÐ
´ØNWËQ¥¢¼Œ94T ŠhŽà¤Ã ÒÚþv'¼à}ºbl«°Ï*¤˜VêVŽh:Yz_§e×!TA’”ŸöÁ
4Ça9äãôûÊcÜÿüSfIՖ¯¨N7¿©3ÚöÊâÛþÎn…HAºW– “5€©4ʽœ¿¤^$)¥ÍbxEÝ0öiMMiæošBÍ(ü®fXžàW 8ì"ÏÜø«àBóĽàÂ`»Ç<P|àGrüÞHÔOÓ:˜|æ3#J³*ñ¯N×͓έs¸”µ   b: Ü€äü¹6ásžK1˜ T°k…ültðˆäƒXs›£Ì#PDa‹H Úzî&£gò¹:—w;ægy•6À·&þjÆ^‚’žä$šÍÿ?Â?5”
Þ/€±*>f!
Ë ƒ„[Ýí>¶ýBZÙÑü"RãÕ È¬>c¹}Ý
Šòc¦ B/Œ D7—bÊ®· ¤$ýÂhÓŠ¢•21ùqEÚQ3Dô=uJÞŸÖ#šb²ú"¢³ï‹¦§.ÿL>žßq¨o½°+ð ç" ¾eb=ÂÍ—_bÚ>ÿ^=hÄÇt,^PC)”@gkS)«#MñǺׂâøÛbŠúÎú˜ôHõâC“|Žì:)?¬NÝÚÁ0»ŠðD«wáG /¬ªt¤Kߌ~@o§)¤^Š*œØ!RÐx-``? ~Ó„ŠÆî<á \{?®¡×þG 3%‚Ãbƒ‚)¨ž%m…ßÈÙ1¼(Ý{[ö*)ý4›j†oåe™òÀþ`a]RH·À¶X³Ü‚­šj–8
,Þ¥Ýwa‡½Þ§R•V`“E<[¨gNanȲ¢?Asú;µ>z@;è·Oì5&XC-;ÿP÷².•#m½=)#Wr
íyP¥Å³a%R¬™ÍÍ~š‰:
]1¿—A$?.Œ4fŠÚ3 W÷ÿÚ=é­±BgYVft@êú²]:߯”›”J¾Ùœ{È Ì@_Zʧ©¹”ÙgÍ_;=‚‰u>Lzúy&#¬‰8ÚiúùÕ×~ÛK±O~+@c/šøþÑÌ ªýVZïNõ.‰9@úwÑÞÙK¨6wk'%Îö×?Ö¨æ6tÎí¨Ú[xé½ãÐ!1¼sºZÿ(¾O÷Æ\O1º™×.ßu‹sϾV¼}Þ / é
ƒ ¸6Ú£ÿåе|ËÏyn! qi«YXñ9Þ%8µ­S ‹SÈèÂûO*¦¦“á³mR/â¢
Åõ’j‡ˆ¹BÜ'd)fEëŠ\äEÑT^TÅB‡K‚z52`‡&ćj}Ga8‡Î³ãÑ7ÖY,5õUk¥ˆÌ¾ÇÓex¡-épbÝkþþP’½š¿ókV @éjœ~š nÿ­C3/­T'7…Éè¸TÅü㹌äfËr«&]#g8J™Ž]dN`)\aNþJ°¶ä¬Ô2×·ÿ©tš?Çœm'oƒ¯·„–'9ì¯VDáŸ\”Âðò6 "7TY!û´É2ÐŒ”*¯a({ü›d^Z¯(Cð„,.¸@¢µä¶mÍ)̃¥ˆ¬ùrƒfêºSL=€„2€ûL]:}‘\jS¼…v‡ Þ}/GÙje'¯¨zyµrv­_¿±§Ç=¹ßøM_†•ð©bµèìH:PÂ/…¿ë÷¦¹èÑaú{âÎ×{´Ü ”h{kµT'w•u¸×áKn+ÜÎw*ø
LîþNÿÿ(­ARYB;mßõi¿Ô¸ãLlxÁƒØ\øXߟåP—5HÿÒôV4…he¬1É 7È)v®¾f5_;QÆU‰-ÓÉÚײþ¢O”×åÖ†§ ¼Më¥e"W;3·9ó83+Zd7·é<1–žü¸ÔIGOÇlz„›)J~E;“‘S/ÿýAòâ2Jü´Doét¦±k¤‘$¾t >Õ.÷qlÉ ·bè2aVPøÅ1vÀÔÃÀg±èôJvè2^E?ÿßàAøï@™ïßm5@\!ñŒ¼~pÀZFf8o
âäò"üx–ÝiÅ”‰HUxÎ ¹@~g]pß$DŠãzÎUR¿¸¾;®fЈw÷~1J:xÌ1˼¯—kU@ú\a9èDè5Y¼¿?"Þ'$¹ºuáö*øýªO@S­ª==§ã*Ø#zìF,}(Í
„ìƒqó¯2÷Qx´ß`>¯rcâI/rŸ° ½Þ¾Ú9]qv²![‡‹£Å›B>íGXØ~è<¯Õ›UŸbÈǸm¸tàYÉ?ûw¦@²SJÁ§sa«õüh^{Õ¶p¡†bONÈ„ Þ;Ó–;肏–Z7"¸ú[oðÐ]Æ]!^ÄQFò`†hníÄ$¤;X¦¤áµûé¦Ju ÝlvÐi/û–IãYÏ)·rSræÀE”0´”)ã<ÕXÍLÖ×/¼7¢°º‚.e•OXR÷€„ÖöAf(ªh·$i5Ð4óÍgÂzŠ×ä ¤ŸFÒ¶›‡>_TqIxøvÅÖ’38"”gJÃ)SUlÅßÝw‘˜Š²sŒ™>rÕXç±vCvprx-*a5‹D°e ³EÏ»âÿªw!ÄP’Pe{‹BÐbüŠWÒq˜0~É)¿Ð_69‘³œ°¾»hËæÍ§¶-ÚšYb
ë(ô2ª¥Pz?ä%®&F;²wa¿ª72SEOðëGúŒÌÄB Ûjòèk«EøfãœU$ž9ïPZE…ëV‘‹š[ت’枥N;Gãp‰øñ†CÎÙ¸kÙ¬ÈØïœYËþ£–æäòökWVê.`JN]î0^-¸Éxý ²Š?üÒÖìƒÀ“flxL& |—D–9Èw &Î_%L€U]Ð_8dÌc´%/ÍbìÇtãJLꃈ´ nú"|6·^rNòg~à®À—è¼ÛE^è[Ù¾+0‡›fþ*:…lÃÏlÞ8Ì쪞‹²g˜‹BÊÑ;³â£ˆü âès WWlØØaCõ—Tõf¼;ÊøQO®7†ƒU¿ê”ûLpØËÙÇ4ªnÚ˘Ñ߈”w'¨ÀàfºÑ¼ÏˆgŠ#ÖOÿCI4Â"Ó]w>}y.WÞ¢ðt±ÊÄ;oÓ½QùIÜY7¢dÙ¾ûMOxDÇ xýI'…ÿjH2%¢³6lçµ#Ö†ºî÷Þ`kºËR-÷Pt†ŸŽüƐ„F$þD #"õÊBj@øiHgM’a©žp/½#=ËÞ6D õcnÓ„jzmD5¢ËUó÷i)0—X'E‡ln֐š#bl¸½|]³îÝnßm aá†Ð61- [q[>å Ô·%Äbò6ìâƒûCÄy;wdÖz ×¼‘o±+‘¶e$Éd3fÍÔïTAÃ!¶7wÍä£Ç‡Üƒ’—Ä.S7,E¼\.¦MIÀAeýÒ,í÷GåÝLÿüuñ§ÐÖÛð–›,ìÊÈÚ©èž³YqÌásŒw ü*¡ËQ‡íùcà >µÝ{4/ Y"‹°#¤=O7‹K^U\Â9jlˆ'AÛ¼…¯0÷Bo¹ˆì㥫ÒW‚©Zv.4}OH§úšòÞRjF
~n«iPIF0Sd÷Ó3ÉÉhg%®—Bðï17ܾµÀ°”6èÆÃCGgÁ\BåUEyĬAG”Þ¥s ²br“%œðÀf
6«²>.ô2! —W
úÛÔÀeê~nïè?>˜¹? 9Û\¹B*‚Ý–µ~+iÒ_ãùÓc³sÌÝ9¬\~È8Ñ0w¬ xº* Éwz³\V ÔAY3Ùc„T¤‹¶!uˆ¶²Ï®ü)l) âÑÊøÀ™B]¡iØb3°•µ‡yôM¿BÜiM')э¶ Yå¥RN¾°‘žWë+ÌœdFi‰ûÀ"Š›v§ñWþÉ?)®4¯_°œ`Ì1º*ý9TUa¥L!|–x+æ+:Þ·Ç—Õ;Ì=yÙ!z÷B^}ýûÓT[}9w&N;Å[•û5÷#©%)kK
ÈÅhÂ,Uìû×_û%#l¥ ?gxaò ðŒÄ0Ʀ°4aŸÂBo¶V,†.(_q„ ×ÃùñXVáßRжفJ°I$³ˆ £ÐÊ!qá>++˜Î‘ØdWV¢¦þc©r h¶{c€„]«÷‡Œ 憶‚ÙW!¨òqIH芔À­ ¨òcN¯›c³ÊŠâãíu|\:äù™7Ë}²bá M]ÞKa¤µ29ŒàÇŸ{X©óšÜÇx¶DÑJ1¤L•Üù¦-.F{¾¬²»wiúá÷•}·óÑú'±ØFFu­
€¨&ýeó4(Ù"dïW ‹ß3ˆà†ælþ[¿J»ýT´íÃv)ó¶áU=©k§¡ÑáQˆÜªš·‹»Ñ§¡-SÝóþ2 =ÅÜ]Éc888WAò}—Êœ›V÷Ý?,.—äÃ!ö‡7¬[û¯ÐCM_¥[›jÓ$¹¸$ƒ8
"Fsù5XC5³¹Å2sŽ{ã¦Éaߢ: Ú“šUÌ£]MZŽÈòþ/uÜ@êâÃØH렝ÚHî0V"’†Âåç~Bz£Fú|‰É‹t»
ê!ŠŸkk{ScçÈÍýr•)Á(?QÚ2«é#ÒŇïsÛG±D
³Ú­‘³"ú¸b:Z*ftY?BKþå — X7Ù ‹&4Îî“nlX2"@8‰èÌm{¯4ÿi+©#]e uŒòöò’y¡·¿ì õ[á^«ö…¦2 bcëöLÙ³3¡^n5«N½w…´/8`Ç’G+,Ûæ ½/žsý¶Y!ˆ ÛÚ`aèëÕoÜñ_êê_TÓm“HZ ŽIéà£áÓù—›ÑU£Š6zàË»>R
)N>æIwiª·©h¹Q⠁qeÔ¼sÃ
ÿ¦Z,‰Ù ’«úòKÚ 5>Ù熌TpB´ìŒ($^ª­"I= º›.A¢ä‘š7¥]Øœ`–%Ó|¢!ÙéÏ4j
 l¸o5S¼ôŽb­é˜xêVÅŽ¥€A´ëÃîÝ¿«§k‰¯=7b•uþF|nס]ÁrÂ8î =Xø³škûÈ5pÜV# “[^•ÈC¦ ßÖ‚
~*­€½ˆ¨
ÚE¡ÝÃK™Ÿòü–ƒî‘õACd¢§7 "gçÍ j™0DH`阯±,%ö7Aºk¢ÞY‹†¨L8ò‰x,mÆÝ$nÁ6YÔøœôil°µÏÒqÀÔg“ΐ¶Ý9´dÞZ
©Ë~jH’B“^Zt§;k÷î¸pzÁ*1áqøï:²æwEL(Ÿ¿˜ÉW:ò*Šl.
‘Ú“Õóû+ª96ÈÐ8h}Ç뀁´¦ˆ ¸[Äòõú‹½U`yëìh9ƒxÓ‹S¢çÆñƒñie3°äÑ”B)B8s`¹›ö Ô+ö.¶vÜ!2îƒ i1ÃD”E
4ÿ;Da)ùcKÃFaJʦÒ,ûwÛÐãpY ØTc];8]ãG
ñ“[¬Ö!ôÚC*ہÐ6Z ªÏx 7˜¤V›<‘vå,æ-Àà’Þþ=Æ+ѺTp¨•‡.06)ü)WÒ@&[¬@\f÷ÍÁ!/|EžAƒÃ“mh@üÃï\†F|
EGQ=­Ù@þ&
øs–ž„•ØŽJ¸W2z8ý[ÁßiÃӻ턚òB—^èÜsúW"ãÓÖ[©qþˆm?­?¤»áO~Ãï éú…0¼cÄÇB€ÈÛ”f¿ÐÆ™4:;Ô‰5ÞD&®/\c ÖîŒT†Ê÷–Êæ£RVHÉ7)pc7{;â¹á}áZÕI±ú.pb¸ÓfÈbüHó_ÓÇ¢Mx¼g¿8*†æI)ü”+tË ö5»Å@¶I*9sL«Á[Œ´ÂÜìpîªnã8‹ó^'ùeÓÔÏL(û¹º<4á#ŸÇß™&—C!G((—
5Óœ7LˆêÂB7í·'S‡ñgBùÎaKŠÊ¢£ÀäJ–ãu¬‘z.n—{„clrøÄâhuáuÔ,é £Æ&k;\±Í,¦Ko³öÔ.Ì:]
©ÓÁÉ–|ª3Þ“Us»oØNWŸJ„x‘•®ýô34ÿG¹ú ±;"¯„O¤¶¯!¬9ÍÐnáþ©×þ.؝p°lØqÛoÇ\ªxÙúVX¸è¾¯­ñŒð‘é…T±ûßÿrÂJ–†¼rìWô‹ ;Ä8UnŽÕ„<‘wan7§>…®Ä“m,£"ý “R=å+LUrbD ¥uïÛHkQäxÌ¿Çy¿v·7ÆËœÏf Qe¥5‡†áR¸E¹"2}XF^óPlZ„ ]wŸK“•§´^êèÕ™Ðð^ÿg~1pîÁÈXĉ•ƒÜ:½él…¿Ð*X__)1'‹¹X‹wàí}L2çÓVéGíùn 1/›Ú´ …ƒØhŽwnìºLM0Ê;%׳̠we:…¤­@ÛՏء[ɹ\^6Ñ! ä/pêr2Cu(De˜W$ok ¨QËÞyúaßi)Q«¤%lrW!Kð£¡Ñ
û
øºkª§!ìDFHLô'A|¼.½„´W‘zCŽû¯[Ò=D /Z.l†Ö.mƒ`—áÛ!5[NP7ƒK"|Æt–7
dsÑ–2†¦(Ø/½‡zŸ²áüÓPѝÆÌ0M¶¯›CÕ±‚ӝJ៻RÇzíãLƧÞa3PLfâW)ÆôOãHñO0¬d3FØ_ßs”Õeç¾ m«X˜pe€šá)CÕ9ð!—´†Ó­BÍéô£²”ÿTd¾[ÀЫL)3ûk H
7pΫ
æñ’…ØÒªAÝIsd ð\l.zFïòÉœkôJP8ùå}3 4õ͇z‹N
²ŽŒ%Ix=A¾:›|â©`uË¿K•Þ¥ð9IMv_¤˜Åž2Ñš-tÂù¨Ž¸a À©Åt1x9‚ùÊ7
ù?D5 Ukª{Nˆ;Èü™yž
ÌñfSäi<”×(
~)шà2¹1š³ô Õu°”‚¶jð1Õ$—ÿ} gg1„Ó£bµê½:y@¤ÎwõÆ·†È¢”¼5p|ê*!ð]:i/׿·p&±Uѽú‘Úð]°aXþ:Ïü‡ x€ÃÓ)2—/¦¡³G”ãÕJ5ÈG~ÆHnDß§uöî„}ÍsÈLVJ3žNbÅê>%·
R¥ÊUKÛ\•=ª\÷pB ¿yNzË=ŒX³£½÷÷üÒ˜¥ •£´ïæ>—˯Ö{ü½Ý ”£´›8œ”Â%Ä'0›4 $™íá³s¡?×ùˆâ St~³ XÙ»Wš É.;†È 6Ø!=Êê:“ÕÊ ( Ú(17¡tõ`±DHÌíz†6¢ñ{zq'ò!Ý/Ð÷e™«Î{áÐy
•ÀzF|;„CpŠDØö½O‹¯Ñ/UgbŠÌ½©¡ªÊâå˜;qq
srêˆ*qŽ(K¢™s:,˜¡í1ÄMˆ4øØõDgúKaGâÈ»7h
d Sԁ›&Êýmï)X;ζÞã­ ws)„‰5ÑmiÔ¼“Éòšd­à"Ù¦´5„Ë/“~ŵÂýÄ¿WÃð!_Dê^LJ=Ž…?᯵’­8Aœý%f Ö9/#îԡõˆÁ‹WÝ` ƒ1×>Kò'unqjïèÕ6Ï^€4I^ÌHù¾z˜Êéú·%‰G·…kÅt´—^·&Ab;ûè¿ÀdæÄïOûL$²!ß @[ÈìÐËü|
‰Â`ï4?ÝéêõANV±g ½+ t^EÎÍe;ƒü=2’&D;Ššq@±° Ó¿â/üb{`è{êФ£I¿”Û4ßÖ2mY øþkÖߍŸy±9tp?O{µ?9E­Bɸ…_ªüñ‹`vY“
_GñEí Ãø'Éé‰[@8 G¤ôº¶­l1+‰
ñ³ìº±äèïUÅøDƒe.ÄFÎý‡ÇëˬYê!
É©äÉÕ鬪®,~\Kј˯`®+IfS¡Ûò´Š§É+c‡Ŷå B=ß2aGøäày•hCø×ÕÞ6w´m®ùçæÀÁö $FßµUށ²±rì‡ö”P8lòY†ñªdÑÑÜëÞŽÌT̼8 è§ÿ¿{ÁÌ×RþáßX bvŽ™Uoñ‰VfB¯å=à=ù¼g¯Ìéhèzþü€=ôÓÁrðKtµmÂ9Ð0ç’)Ž·†Æ1³GPiXãö™jŒ“ÅÏÇ
†Å€Ù}àÊëÄ.SAóyÉGxÍR¢åµ~{ã¼»XŽé ËÃ.@,.&f;ÁüÛ¬«˜@’ô°•8Ð>ÃÖŒ’+#ÐD&c;üú*,6«‡íÌñÔ‹šlw6é$V£œ!QOèHèŠ_N$T­*Yݙ ¼LPŒ¿£/‰}˜æùÚ˜îoj¤—÷GˆàÆs© x ²ûËp5aÔ03Iߏj¬RJ=£qþ¿,²ã¯RËv[c¨}ú´Î& KäênI“/1ÄFËJ‘ÞoM]¡áaÊÄg ”e`§’ôà”ú¡R ƒsÊ2@¦‘œ .Þù•à
w–0UîSE;½ƒC{^ß%īߵ"X¨‹~öÓ<&¦ (SpÿZ†L‡
ÜÔ¢ÜvˆªöËüo93oƒrpmV]äÖ³•ºv¥òPˆ=fz•J¥½¶±MBB¾>’¹Ž…a#”r®TÈӁ¹][2-3—¶ëÓ‘ÞFäàŽ"÷­t q Mg· I}`¦²ß:[-|=9aP@Þ»˜_>Fa8Ìî4›:â4Tgó(‡m±æ®EžGv-÷ßnIɯïÛ~ÆçbÆ„ö.ŽMbžPbqÑÉ™5ïL.qÙÿKf5¾ÿ4·Éë‡6­=—¨u’“£`@yó ÀÂØÄš¢´òhAÈÑžÊWpx³bXÚˆÃÓÁ&Û¹·h[{K„…J–X¤ð=èû¨¢å¬6eÿ-Íá‚e?֏†O
Î÷[Ø,"ž
.Ϭœútm±í•ˆžsy¹ÿX þMr‹¼L<ú)“§ý÷YïF"€èËt ‘g4LÅàç5¿tUW¥4„öÝ—îUJøÿ ªØùûtÍ0’
j‰dp+ºm‡ÎfGþÌ”kÞl&‚n±`èô¡Ã:Bˆ:EÁ|_“‡ šm ¹Ý º3hÒôNl2í†Éí)ël&èw{4»ŠEãé ÜÜÜ—ÕŠS6r !O’Éñ-ð4JÓp¨ù(ô«ò
–­OoÖ¾ÓŽˆ2gXËÞh.彨W+†ŠùöÇg,ëà €àÿ÷B.Ÿë.ÉUšP—ÕÿV^©n–z£rÊ¥%åiÀCŸh5ÀÂ*¿1©ohk¤aç¡'8 ÿÎpå/ø [yLç˜ö#´d­þ»ËÅw#ßâQ—&ëóz¾äû%ߺ˜¬:/,0Uã$•_c¬ÌÙîóÓ®Ñï°ïPîÀÓÊÒ„—Tö×Ð-Eäö%w½&f;Ѓ­ÚAs·X¹?ý\i:ûl ¹®jœðº{}Où‹ôhø”ë3Ÿ‘O5ÜJÊ…Ìf•.Œ—IÌ)Þ NªÁ?…ïvsãÃÈø­‹ðns{‡Ç^:êTÿþá†ù†ªÎ±GížQý‹Ð÷SÝtÓаÿ{6Ç”·KUißT@­%• :BŽÉ™˜÷VA$IIZ|\‘vîH8F•Ÿv”µryV/¾'Ú ×L·Ù7lèÝe4RaÍ«UÇuêöáFØêµRµÙ³¡×ÜÅ´EG$p¾Áç–¨‰b ‰²
2möj`û':ož$1(øÇre(Ž©¹ùH„XàÆí$1ÁÄ19·ùåÕ&c;·1ÄY™ù ”hãzö(QÓÊ1]ùõ—Þ¦ö
¥¯øàË@vù—íµ¡HNÿê|87ÙD\NBН~‰Å ×p¢ù=í%BŠkÌIZ6˜O¹œ#Ô®¥é–¨w^|¦R–D<‘_Žù¾6Ø@Âñ#1W÷)µV4ð~Éìu¿*!BAm

öáê=≻Éé‡
Ç‚AK‘M'+ó‰Ç
§úµÌÙF¨äÆÜõöûG]qíúý5NñNÇE\‹NÒ!¢²6˜Ánmß<çÎÉû‘U'Ulbé0Ãk}Üñ\Sb@š›ò²Ÿ”Üîš@û#’$jeIÇø J[>­¶…¤$Lå:\× ºðåºxä§›fM ©)÷Û¡¼ôâC¸ÿæ
oPŽäœH´}ë‘-Ÿ¯— ùÒCÔ&'+]É¥‘Ä£`‹I‘ÄYåÄÍÂ*[¦ 뎷‡ÝÍ©‰Jr`{)޹þM¨rL ©‘Ї-G¼(üUØcH ÚçB ž[T>»¶ÃÂÇÖ8bÈOÕ>:Q pìœ#?݈ÕÁ„hâj9"âÕß…N„ôà›¸ârq Vns#jTÃÊ=9³Äb‘~‘¿‘oaßæ2?TÏr©ã¨XxÜÛ ÌG«|¸ô×®X³G*a‹?®1Ú„ÃDê.#7Q”ZÔlx”ºÊf¯Ðƒ¹räµ›ú¾F>ȾÒD}šZTîìë]yæ‹]Ì7DñL˜UÃÐT@M²Œ„ b@§¼ÿ{ DÜÁ „XãÈÉ©þØòP!:áºhj àùî„NB©; Úde raIÈðÂýƒéåÛo6rÐdMFê ®-WµcÀô®”ã­Q›»Þ×lˆ­Ê µ*ÓšÏ;™Ò%ÛMŒ'÷9ýWWYb c,Ó\&31]z³3 í¿±Ö6·x¼ð-pÐZÛ~ Z²niÚ ‡¬Sã99lâ^R-e…¿^»Od˜ëZûÅÄHŒ?Ð àÚüØX¬;JpÂ
ê•$ûŽÏõ]ÿC
• 8ºÈÛó9óXÌVÏ®²«œ{š_–Kk÷IõÔPraÑ.
4Œ@5÷Fž)ùt´è¼ÙœØ«& ÈDã4ë¢×óÜ
v,R3Ñ š=ÞëB°~Àñ#„I{Ò¿ `æùˆCŠ u¡ÿþjQÌC Ùù‹î·ª@
P½ÌªQÜt͆Þ`ð¶ÖWÿi´;ìi[lh3¿MÊ©^i0Y#¼úZ¦õÿ¼8ˆÿ@†JûŠ­
ü¹C3å˜l˜>V6Hz§ ³!—ákÙU}Ÿ‰8’±Ê¬ÎÄÑ“=‘˜M¦Š byë~^{ݸ¹¨j¿!‡<Ï]û{”ð¶½Ðñ¢„XEcåÁ ¾l(³0µ·ŽV!ôÍŸ`°‚ãf1ýv$*Âè¦þšYþÞWÑÃç6F¨¸­‚¾¹˜¼‰Ï«—8&ЦC쌡°¤:rÔM•9m0enÆ‘pݪœ„ÿ€sÀä1»ÂYÍ&t²p„ÓÉϝ\¡Ö,=9‚ASñ­ŸëšfWa’ÂmâziÕLŒ ~“:°Òx—øW¥Œè¯…zϲ1¡€±ÿ a P” }ƒbµ®4P0²MøÁl!áèΏčœ|ÆÆ‚=êkj
˜ä¨Ç²ºfÇ=3 |ÿÎbò™‘•^H1Þ™wÞŽ¹{5Y%ù<¬ô#¤•ç_x)Øü#bÄCÁüt¾Þ>~¡º[º<½vß•x„†Gc*Ÿni™y®°¿QQÛä«RKï5“¶ª7OJºU[03í-þΗèÖc™@Qä0Nè.¼3ÊðK2ÈgĘî­,¢šOsý‘IÅ@+7iŽáujÝ*éYNžNTBg2j¯ƒár‰¾ÙÉhºQ.¶æghZ‘2
tµnÛ_ª‰šNRhöAGçt%IyN°î $¾lè ®½æ¶% yÆ]Pæç‹k/í¿¨@ÎǬõнïڐÉwì)-–ÑŠ=qŒÌÃ~10û¬ñ=MßC›â³S¬ÉûÞy%⦃”çŽøª¥:b~; ç4ÄfŸ™÷û‘jmynÄ5“YðæôWU\(¹øžPxÉ`–Wš;·à±oõaÆ¢Aß±gÕé‡Ç•RS8È,Å*帘íö%Ñ&ÅeFd_ôÂÊñõa˧3‚+ÖØÔÄѐôñôY÷b%Y° _&À¶éòÜ࿲«Ý3TÄâÛ“— ö”Þ!8ê€ËzAz¥F|³µ•¾‹WIÁ‚˜¡gŽùs¥OAÛÊ«vÛºÙªtš¤åìã8ªÏÐ!ÛÂ~–pSØñÙTÛ̾ú¡¨3óúodì/Çqy Nì¨Ì]n~«i¨zì;m-' ziÔLÄ9+7KnOÞVHíÀÿ Á!;ÛFnÚÆEjX¦èÜŽ¯2_‘×a PÕ<:b
VÖ¨wW¨Þ1ÞǸ'MY
˜)s-äÙaW ’~å.[ù5¡iâ]}„ÏxHϤç"ïþš/>ŸÙ EP8bi{ÿ£T»ÎJ¯ÿe¨õ£1q#–a—ìi¨“f³¹ÂYwFa¹Êj(~‚ v^7ß‘"Ùä»*xjð–„!Éò6ä*J¾(Ëôž¾°wjýÐÈZÖA²¨ûe*ýt¥ò%/ê~Ç7AŒÑ,x£ p¥šÁæ¨.r:–Œï6÷ñA§‹´ú¤N[’X‹°…!\Ÿ UˍÅuq³LŸÒ—Ç=c·÷˜4üìˆmËS‡f¤šå읻BïtlrÕDÿ!Ž8Ö7%ü{
A}SJd¿X2ÒTJ#7öû×—YĸéÎ+‡N®7XjÞI¨PËuFA±ÁÏG’î]åEÇÆ1ù—jdZ¸ ¿Va÷ kÍ!ü‡º©!ù0rWö]3v£¡3N”.Õ_<>^å³Û¬Yt-¨cDäZEõá ‚÷° ±ùúùÖ(çÔƒûßÁD¿:NP™°ˆT£${ýLr…Ë2º C1è¢oÝ-ssÜBX Â²µÚRˆ:ÈÿF£Gd>VWYW F†æØ·ÙÄ&G;x¹Ç¡‰¬EÓí‰ZYjù((ÌwñÆg100œ{A9•°iv}€’ä”"%‘ƾ䬑ËÃè–»¹µ”;¯\c_àC
rYvA Ef”i÷MÖ±n áPú
饭OÚ}¬"¢Bìw]´ÐCGlÒ†9´¸îœI,ή¦ÐnÔ*½ÁŒ¾>/rÕS•ÃÐRU± ko8~”!À¨G ´ø Ùv+\‚RG±‘“¯z௃#ž°þØò4ü³þg›hñëñ‡q„¦
°ÑWÚܯy0ŠáßÎŽçª>Âëô±‚^£ƒw,-*ÙжÆ¦` eÉœ+ÎOý+I°È?Zm_¼ŠŠH½Œ*A‚õÏ)£¡Ÿe]jˆ”.!õ ‡AÁ8 ©W´ÃÎt[P‚P;ªÔã¾»¾¹æBpu¶Ê
I}^¿ö¾Àè´/LÃðç4Ž5 °ÊÆi¨ã©MTY&ðM°Óq
ö®vh'Ä©‰¤,•%4†¦h阢ÒNã²)1„r·Ÿ*Î bEÁp,)?[Óî Þ°5²Ç3¾ÊzA:‚çÇÓxJÎ+-§*|ÙO¶û˜íÉYb¾>“ Ľ@ÿF»Íciªûˆ«Bêh¸æ£ !œ9ŽÀdʲÁ…èoÆOgn7ƒcâÞá'Æoüô ‚¿‰´ž ¿þà&í™ô==ä¯Îá´’SV­ólôüÉÔ„#Ð*íq¸p¥½/iÝYúëê 2qhÛ]*uıë0§€my’ðAüÕ$]ŒBú%úБ²¤áå=
¢ä¢Ö¬I€JäÀ /BvæÿIJޙ#˜¨[¶/îŸãìñ3‚ÏM½Mô'SbN82Û³ïS³Ï
ЯÓ!¡[óg}PæÏô’k”Ì"‹ð$ ìfT=SÏ7¾­€~ò oaå${rxÂ>ޝ·=^ìK¶«ƒÓ+šcCÖN-3êQ<¶þ_Á˜£ñÝ0£ê5Ò'8<˜>ÅSVa(Ê ´ÙÆ=ñqŸÚÉY`ËЏtb±Íb©µÝ !ÎÍŠØ«žæ:|)!b<•–åTy¢À’ÁÍbñŸk¾"ÒÓH ú
!* #™q딨"p
€îà@¨á–å³4¢ð ù>üOöF=‘©~DÄx_ÑÛF‘¤êz¤É_nèÂvºIa'ô7ËÎ÷MDœ8†1gÁþpIãVðZ¯qAÏšø ÚPïÕü\ä•x޹»ü‹
nŸ)Ÿ



ComboFix 08-11-29.03 - Owner 2008-11-30 19:32:11.3 - NTFSx86
Microsoft Windows XP Professional 5.1.2600.2.1252.1.1033.18.121 [GMT -8:00]
Running from: c:\documents and settings\[removed]\Desktop\ComboFix.exe
.

((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.

C:\bold.log
C:\mimic.log
c:\windows\system32\FBw54VXH.exe.a_a
c:\windows\system32\HDy21XAJ.dll
.
—- Previous Run ——-
.
C:\bold.log
C:\mimic.log
c:\windows\system32\FBw54VXH.exe.a_a
c:\windows\system32\HDy21XAJ.dll

.
((((((((((((((((((((((((( Files Created from 2008-11-01 to 2008-12-01 )))))))))))))))))))))))))))))))
.

2008-11-30 19:18 . 2008-11-30 19:18

d——– C:\_OTMoveIt
2008-11-30 13:56 . 2008-11-30 19:25 54,156 –ah—– c:\windows\QTFont.qfn
2008-11-30 13:56 . 2008-11-30 13:56 1,409 –a—— c:\windows\QTFont.for
2008-11-27 08:37 . 2008-11-27 08:37 d——– C:\rsit
2008-11-27 08:37 . 2008-11-28 18:49 d——– c:\program files\trend micro
2008-11-25 09:21 . 2008-11-25 09:21 d——– C:\VundoFix Backups
2008-11-25 08:44 . 2008-11-25 09:05 d——– c:\program files\Exterminate It!
2008-11-24 14:46 . 2008-11-24 14:46 d——– c:\program files\Windows Defender
2008-11-22 22:12 . 2008-11-22 22:12 d——– c:\program files\Malwarebytes' Anti-Malware
2008-11-22 22:12 . 2008-11-22 22:12 d——– c:\documents and settings\Owner.LOPEZINSURANCE\Application Data\Malwarebytes
2008-11-22 22:12 . 2008-11-22 22:12 d——– c:\documents and settings\All Users\Application Data\Malwarebytes
2008-11-22 22:12 . 2008-10-22 16:10 38,496 –a—— c:\windows\system32\drivers\mbamswissarmy.sys
2008-11-22 22:12 . 2008-10-22 16:10 15,504 –a—— c:\windows\system32\drivers\mbam.sys
2008-11-22 18:31 . 2008-11-22 18:31 d–hsc— c:\program files\Common Files\WindowsLiveInstaller
2008-11-22 18:31 . 2008-07-18 22:07 270,880 –a—— c:\windows\system32\mucltui.dll
2008-11-22 18:31 . 2008-07-18 22:07 210,976 –a—— c:\windows\system32\muweb.dll
2008-11-22 18:31 . 2008-07-18 22:07 29,728 –a—— c:\windows\system32\mucltui.dll.mui
2008-11-22 18:30 . 2008-11-22 18:30 d——– c:\program files\Windows Live
2008-11-22 18:29 . 2008-11-22 18:30 d——– c:\documents and settings\All Users\Application Data\WLInstaller
2008-11-13 18:20 . 2008-11-13 18:20 152 –a—— c:\windows\cdplayer.ini
2008-11-13 09:00 . 2008-11-30 19:22 45,522 –a—— c:\windows\system32\drivers\kmxcfg.u2k0
2008-11-13 09:00 . 2008-11-30 19:22 64 –a—— c:\windows\system32\drivers\kmxcfg.u2k7
2008-11-13 09:00 . 2008-11-30 19:22 64 –a—— c:\windows\system32\drivers\kmxcfg.u2k6
2008-11-13 09:00 . 2008-11-30 19:22 64 –a—— c:\windows\system32\drivers\kmxcfg.u2k5
2008-11-13 09:00 . 2008-11-30 19:22 64 –a—— c:\windows\system32\drivers\kmxcfg.u2k4
2008-11-13 09:00 . 2008-11-30 19:22 64 –a—— c:\windows\system32\drivers\kmxcfg.u2k3
2008-11-13 09:00 . 2008-11-30 19:22 64 –a—— c:\windows\system32\drivers\kmxcfg.u2k2
2008-11-13 09:00 . 2008-11-30 19:22 64 –a—— c:\windows\system32\drivers\kmxcfg.u2k1
2008-11-13 08:47 . 2008-11-30 19:32 d——– c:\windows\CAVTemp
2008-11-13 08:37 . 2008-11-13 08:37 880,560 –a—— c:\windows\system32\drivers\vetefile.sys
2008-11-13 08:37 . 2008-11-13 08:37 108,368 –a—— c:\windows\system32\drivers\veteboot.sys
2008-11-13 08:36 . 2007-08-20 13:37 99,592 –a—— c:\windows\system32\isafeif.dll
2008-11-13 08:36 . 2007-08-20 13:26 79,424 –a—— c:\windows\system32\vetredir.dll
2008-11-13 08:36 . 2007-08-20 13:37 75,016 –a—— c:\windows\system32\isafprod.dll
2008-11-13 08:36 . 2007-08-20 13:38 32,264 –a—— c:\windows\system32\drivers\vetmonnt.sys
2008-11-13 08:36 . 2007-08-20 13:38 26,376 –a—— c:\windows\system32\drivers\vet-filt.sys
2008-11-13 08:36 . 2007-08-20 13:38 21,512 –a—— c:\windows\system32\drivers\vetfddnt.sys
2008-11-13 08:36 . 2007-08-20 13:38 21,128 –a—— c:\windows\system32\drivers\vet-rec.sys
2008-11-13 08:35 . 2008-11-13 08:35 d——– c:\program files\Common Files\Scanner
2008-11-13 08:35 . 2008-11-13 08:35 d——– c:\program files\CA
2008-11-13 08:35 . 2008-11-13 08:45 d——– c:\documents and settings\All Users\Application Data\CA
2008-11-13 08:32 . 2008-11-13 08:32 d——– c:\documents and settings\OWNER~1~LOP\LOCALS~1
2008-11-13 08:32 . 2008-11-13 08:32 d——– c:\documents and settings\OWNER~1~LOP
2008-11-12 15:27 . 2004-08-10 11:00 4,224 –a–c— c:\windows\system32\dllcache\beep.sys
2008-11-12 08:53 . 2008-10-24 03:10 453,632 —–c— c:\windows\system32\dllcache\mrxsmb.sys
2008-11-11 20:17 . 2008-11-11 20:17 d——– c:\documents and settings\NetworkService\Application Data\AdobeUM

.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2008-11-29 02:28 ——— d—–w c:\program files\Microsoft Works
2008-11-06 23:44 ——— d—–w c:\documents and settings\Owner.LOPEZINSURANCE\Application Data\PDF reDirect
2008-10-24 11:10 453,632 —-a-w c:\windows\system32\drivers\mrxsmb.sys
2008-10-18 23:25 ——— d—–w c:\program files\Rhapsody
2008-10-18 23:21 ——— d—–w c:\program files\Real
2008-10-18 17:03 ——— d—–w c:\program files\Windows Media Connect 2
2008-10-17 15:25 330 —-a-w c:\documents and settings\Owner.LOPEZINSURANCE\Application Data\wklnhst.dat
2008-10-15 16:26 ——— d—–w c:\documents and settings\Owner.LOPEZINSURANCE\Application Data\Template
2008-10-07 00:09 ——— d—–w c:\program files\The Weather Channel FW
2008-10-01 00:43 1,286,152 —-a-w c:\windows\system32\msxml4.dll
2008-09-15 11:57 1,846,016 —-a-w c:\windows\system32\win32k.sys
2008-09-04 16:42 1,106,944 —-a-w c:\windows\system32\msxml3.dll
2007-09-08 02:22 774,144 —-a-w c:\program files\RngInterstitial.dll
.

((((((((((((((((((((((((((((( snapshot@2008-11-28_18.31.06.45 )))))))))))))))))))))))))))))))))))))))))
.
+ 2008-11-29 02:40:03 91,488 —-a-w c:\windows\assembly\GAC\Microsoft.Office.Interop.InfoPath.Xml\11.0.0.0__71e9bce111e9429c\Microsoft.Office.Interop.InfoPath.Xml.dll
+ 2008-11-29 02:40:02 103,776 —-a-w c:\windows\assembly\GAC\Microsoft.Office.Interop.InfoPath\11.0.0.0__71e9bce111e9429c\Microsoft.Office.Interop.InfoPath.dll
- 2006-10-03 21:24:50 64,088 —-a-w c:\windows\assembly\GAC\Microsoft.Vbe.Interop\11.0.0.0__71e9bce111e9429c\Microsoft.Vbe.Interop.dll
+ 2008-11-29 02:38:26 66,936 —-a-w c:\windows\assembly\GAC\Microsoft.Vbe.Interop\11.0.0.0__71e9bce111e9429c\Microsoft.Vbe.Interop.dll
- 2006-10-03 21:24:49 223,800 —-a-w c:\windows\assembly\GAC\office\11.0.0.0__71e9bce111e9429c\OFFICE.DLL
+ 2008-11-29 02:38:05 226,656 —-a-w c:\windows\assembly\GAC\office\11.0.0.0__71e9bce111e9429c\OFFICE.DLL
+ 2004-08-03 16:57:00 1,712,128 —-a-r c:\windows\Installer\$PatchCache$\Managed\804C25D6A90B0254B98174B5183D391F\8.5.818\F20954_gdiplus.dll
+ 2005-08-17 19:11:30 225,280 —-a-r c:\windows\Installer\$PatchCache$\Managed\804C25D6A90B0254B98174B5183D391F\8.5.818\F20963_wkssole.dll
+ 2005-08-17 19:36:00 2,023,424 —-a-r c:\windows\Installer\$PatchCache$\Managed\804C25D6A90B0254B98174B5183D391F\8.5.818\F22194_wksssdb.dll
+ 2007-03-23 03:07:56 91,488 —-a-r c:\windows\Installer\$PatchCache$\Managed\9040211900063D11C8EF10054038389C\11.0.8173\ADDRPARS.DLL
+ 2007-04-19 22:10:18 45,920 —-a-r c:\windows\Installer\$PatchCache$\Managed\9040211900063D11C8EF10054038389C\11.0.8173\AUTHZAX.DLL
+ 2007-03-23 03:29:56 99,160 —-a-r c:\windows\Installer\$PatchCache$\Managed\9040211900063D11C8EF10054038389C\11.0.8173\AW.DLL
+ 2007-03-23 03:06:08 355,168 —-a-r c:\windows\Installer\$PatchCache$\Managed\9040211900063D11C8EF10054038389C\11.0.8173\CDLMSO.DLL
+ 2007-04-19 21:55:16 53,088 —-a-r c:\windows\Installer\$PatchCache$\Managed\9040211900063D11C8EF10054038389C\11.0.8173\DFUICOM.EXE
+ 2007-03-23 03:07:54 80,224 —-a-r c:\windows\Installer\$PatchCache$\Managed\9040211900063D11C8EF10054038389C\11.0.8173\DLGSETP.DLL
+ 2007-03-23 03:23:32 19,800 —-a-r c:\windows\Installer\$PatchCache$\Managed\9040211900063D11C8EF10054038389C\11.0.8173\DSITF.DLL
+ 2007-05-10 21:44:02 121,688 —-a-r c:\windows\Installer\$PatchCache$\Managed\9040211900063D11C8EF10054038389C\11.0.8173\DSSM.EXE
+ 2007-03-23 03:29:28 43,360 —-a-r c:\windows\Installer\$PatchCache$\Managed\9040211900063D11C8EF10054038389C\11.0.8173\DWDCW20.DLL
+ 2007-03-23 03:29:28 39,264 —-a-r c:\windows\Installer\$PatchCache$\Managed\9040211900063D11C8EF10054038389C\11.0.8173\DWTRIG20.EXE
+ 2007-04-19 21:53:52 137,568 —-a-r c:\windows\Installer\$PatchCache$\Managed\9040211900063D11C8EF10054038389C\11.0.8173\ENVELOPE.DLL
+ 2007-05-31 21:41:06 10,352,472 —-a-r c:\windows\Installer\$PatchCache$\Managed\9040211900063D11C8EF10054038389C\11.0.8173\EXCEL.EXE
+ 2007-03-23 03:06:34 17,248 —-a-r c:\windows\Installer\$PatchCache$\Managed\9040211900063D11C8EF10054038389C\11.0.8173\FINDER.EXE
+ 2007-06-06 18:53:34 1,195,888 —-a-r c:\windows\Installer\$PatchCache$\Managed\9040211900063D11C8EF10054038389C\11.0.8173\FM20.DLL
+ 2007-06-06 20:46:12 1,961,312 —-a-r c:\windows\Installer\$PatchCache$\Managed\9040211900063D11C8EF10054038389C\11.0.8173\FPCUTL.DLL
+ 2007-04-19 22:15:26 192,344 —-a-r c:\windows\Installer\$PatchCache$\Managed\9040211900063D11C8EF10054038389C\11.0.8173\FPDTC.DLL
+ 2007-04-19 21:47:40 186,208 —-a-r c:\windows\Installer\$PatchCache$\Managed\9040211900063D11C8EF10054038389C\11.0.8173\FPERSON.DLL
+ 2007-04-19 21:47:40 171,872 —-a-r c:\windows\Installer\$PatchCache$\Managed\9040211900063D11C8EF10054038389C\11.0.8173\FPLACE.DLL
+ 2007-05-31 21:50:10 1,168,736 —-a-r c:\windows\Installer\$PatchCache$\Managed\9040211900063D11C8EF10054038389C\11.0.8173\FPSRVUTL.DLL
+ 2007-04-19 22:16:14 807,256 —-a-r c:\windows\Installer\$PatchCache$\Managed\9040211900063D11C8EF10054038389C\11.0.8173\FPWEC.DLL
+ 2007-04-19 21:57:32 2,152,792 —-a-r c:\windows\Installer\$PatchCache$\Managed\9040211900063D11C8EF10054038389C\11.0.8173\GRAPH.EXE
+ 2007-04-19 22:10:30 116,576 —-a-r c:\windows\Installer\$PatchCache$\Managed\9040211900063D11C8EF10054038389C\11.0.8173\IEAWSDC.DLL
+ 2007-04-19 22:09:30 167,256 —-a-r c:\windows\Installer\$PatchCache$\Managed\9040211900063D11C8EF10054038389C\11.0.8173\IETAG.DLL
+ 2007-04-19 21:53:52 127,328 —-a-r c:\windows\Installer\$PatchCache$\Managed\9040211900063D11C8EF10054038389C\11.0.8173\IMPMAIL.DLL
+ 2007-04-09 21:24:04 758,664 —-a-r c:\windows\Installer\$PatchCache$\Managed\9040211900063D11C8EF10054038389C\11.0.8173\MDIGRAPH.DLL
+ 2007-04-09 21:23:58 231,816 —-a-r c:\windows\Installer\$PatchCache$\Managed\9040211900063D11C8EF10054038389C\11.0.8173\MDIINK.DLL
+ 2007-04-09 21:23:54 28,040 —-a-r c:\windows\Installer\$PatchCache$\Managed\9040211900063D11C8EF10054038389C\11.0.8173\MDIMON.DLL
+ 2007-04-09 21:23:54 28,552 —-a-r c:\windows\Installer\$PatchCache$\Managed\9040211900063D11C8EF10054038389C\11.0.8173\MDIPPR.DLL
+ 2007-04-09 21:23:58 46,472 —-a-r c:\windows\Installer\$PatchCache$\Managed\9040211900063D11C8EF10054038389C\11.0.8173\MDIUI.DLL
+ 2007-04-09 21:24:04 453,512 —-a-r c:\windows\Installer\$PatchCache$\Managed\9040211900063D11C8EF10054038389C\11.0.8173\MDIVWCTL.DLL
+ 2007-04-19 21:54:04 183,136 —-a-r c:\windows\Installer\$PatchCache$\Managed\9040211900063D11C8EF10054038389C\11.0.8173\MIMEDIR.DLL
+ 2007-04-19 22:01:52 238,424 —-a-r c:\windows\Installer\$PatchCache$\Managed\9040211900063D11C8EF10054038389C\11.0.8173\MSCDM.DLL
+ 2007-05-10 22:35:40 120,160 —-a-r c:\windows\Installer\$PatchCache$\Managed\9040211900063D11C8EF10054038389C\11.0.8173\MSCONV97.DLL
+ 2005-05-04 07:06:28 465,640 —-a-r c:\windows\Installer\$PatchCache$\Managed\9040211900063D11C8EF10054038389C\11.0.8173\MSDMENG.DLL
+ 2005-05-04 07:06:32 1,411,816 —-a-r c:\windows\Installer\$PatchCache$\Managed\9040211900063D11C8EF10054038389C\11.0.8173\MSDMINE.DLL
+ 2007-04-30 23:11:38 89,440 —-a-r c:\windows\Installer\$PatchCache$\Managed\9040211900063D11C8EF10054038389C\11.0.8173\MSENCODE.DLL
+ 2005-05-04 07:06:26 199,408 —-a-r c:\windows\Installer\$PatchCache$\Managed\9040211900063D11C8EF10054038389C\11.0.8173\MSMDUN80.DLL
+ 2007-03-23 03:29:16 20,824 —-a-r c:\windows\Installer\$PatchCache$\Managed\9040211900063D11C8EF10054038389C\11.0.8173\MSMH.DLL
+ 2007-06-19 01:16:32 12,259,160 —-a-r c:\windows\Installer\$PatchCache$\Managed\9040211900063D11C8EF10054038389C\11.0.8173\MSO.DLL
+ 2007-04-19 22:10:34 127,840 —-a-r c:\windows\Installer\$PatchCache$\Managed\9040211900063D11C8EF10054038389C\11.0.8173\MSOAUTH.DLL
+ 2007-03-23 03:04:52 109,912 —-a-r c:\windows\Installer\$PatchCache$\Managed\9040211900063D11C8EF10054038389C\11.0.8173\MSOCF.DLL
+ 2007-03-23 03:04:52 130,912 —-a-r c:\windows\Installer\$PatchCache$\Managed\9040211900063D11C8EF10054038389C\11.0.8173\MSOCFU.DLL
+ 2007-03-23 03:29:22 31,072 —-a-r c:\windows\Installer\$PatchCache$\Managed\9040211900063D11C8EF10054038389C\11.0.8173\MSODCW.DLL
+ 2007-04-19 21:56:58 29,024 —-a-r c:\windows\Installer\$PatchCache$\Managed\9040211900063D11C8EF10054038389C\11.0.8173\MSOEURO.DLL
+ 2007-04-19 22:07:38 61,280 —-a-r c:\windows\Installer\$PatchCache$\Managed\9040211900063D11C8EF10054038389C\11.0.8173\MSOHTMED.EXE
+ 2007-05-02 21:45:26 2,123,104 —-a-r c:\windows\Installer\$PatchCache$\Managed\9040211900063D11C8EF10054038389C\11.0.8173\MSOLAP80.DLL
+ 2005-09-20 20:33:08 1,293,008 —-a-r c:\windows\Installer\$PatchCache$\Managed\9040211900063D11C8EF10054038389C\11.0.8173\MSONSEXT.DLL
+ 2007-04-19 21:49:28 383,328 —-a-r c:\windows\Installer\$PatchCache$\Managed\9040211900063D11C8EF10054038389C\11.0.8173\MSORUN.DLL
+ 2007-04-19 22:07:24 36,192 —-a-r c:\windows\Installer\$PatchCache$\Managed\9040211900063D11C8EF10054038389C\11.0.8173\MSOSTYLE.DLL
+ 2007-03-23 03:29:24 39,256 —-a-r c:\windows\Installer\$PatchCache$\Managed\9040211900063D11C8EF10054038389C\11.0.8173\MSOSV.DLL
+ 2007-04-19 22:07:32 45,408 —-a-r c:\windows\Installer\$PatchCache$\Managed\9040211900063D11C8EF10054038389C\11.0.8173\MSOSVFBR.DLL
+ 2007-03-23 03:13:38 45,408 —-a-r c:\windows\Installer\$PatchCache$\Managed\9040211900063D11C8EF10054038389C\11.0.8173\MSOXEV.DLL
+ 2007-03-23 03:13:38 58,720 —-a-r c:\windows\Installer\$PatchCache$\Managed\9040211900063D11C8EF10054038389C\11.0.8173\MSOXMLED.EXE
+ 2007-04-19 21:57:40 46,432 —-a-r c:\windows\Installer\$PatchCache$\Managed\9040211900063D11C8EF10054038389C\11.0.8173\MSOXMLMF.DLL
+ 2007-04-09 21:24:06 1,025,416 —-a-r c:\windows\Installer\$PatchCache$\Managed\9040211900063D11C8EF10054038389C\11.0.8173\MSPCORE.DLL
+ 2007-04-09 21:23:52 25,992 —-a-r c:\windows\Installer\$PatchCache$\Managed\9040211900063D11C8EF10054038389C\11.0.8173\MSPGIMME.DLL
+ 2007-04-09 21:24:00 367,496 —-a-r c:\windows\Installer\$PatchCache$\Managed\9040211900063D11C8EF10054038389C\11.0.8173\MSPVIEW.EXE
+ 2007-03-23 03:29:32 44,888 —-a-r c:\windows\Installer\$PatchCache$\Managed\9040211900063D11C8EF10054038389C\11.0.8173\MSSH.DLL
+ 2007-04-19 22:00:30 637,792 —-a-r c:\windows\Installer\$PatchCache$\Managed\9040211900063D11C8EF10054038389C\11.0.8173\MSTORDB.EXE
+ 2007-04-19 22:00:22 130,912 —-a-r c:\windows\Installer\$PatchCache$\Managed\9040211900063D11C8EF10054038389C\11.0.8173\MSTORE.EXE
+ 2007-04-19 22:00:30 489,824 —-a-r c:\windows\Installer\$PatchCache$\Managed\9040211900063D11C8EF10054038389C\11.0.8173\MSTORES.DLL
+ 2007-04-19 22:09:02 157,024 —-a-r c:\windows\Installer\$PatchCache$\Managed\9040211900063D11C8EF10054038389C\11.0.8173\MSWEBCAP.DLL
+ 2007-04-19 22:10:26 80,216 —-a-r c:\windows\Installer\$PatchCache$\Managed\9040211900063D11C8EF10054038389C\11.0.8173\NAME.DLL
+ 2007-03-23 03:23:30 17,248 —-a-r c:\windows\Installer\$PatchCache$\Managed\9040211900063D11C8EF10054038389C\11.0.8173\NPOFFICE.DLL
+ 2007-03-23 03:06:22 287,576 —-a-r c:\windows\Installer\$PatchCache$\Managed\9040211900063D11C8EF10054038389C\11.0.8173\OIS.EXE
+ 2007-04-19 21:50:52 837,472 —-a-r c:\windows\Installer\$PatchCache$\Managed\9040211900063D11C8EF10054038389C\11.0.8173\OISAPP.DLL
+ 2007-03-23 03:06:08 46,432 —-a-r c:\windows\Installer\$PatchCache$\Managed\9040211900063D11C8EF10054038389C\11.0.8173\OISCTRL.DLL
+ 2007-03-23 03:06:22 245,600 —-a-r c:\windows\Installer\$PatchCache$\Managed\9040211900063D11C8EF10054038389C\11.0.8173\OISGRAPH.DLL
+ 2007-04-19 22:09:46 1,061,720 —-a-r c:\windows\Installer\$PatchCache$\Managed\9040211900063D11C8EF10054038389C\11.0.8173\OMFC.DLL
+ 2007-04-19 21:52:16 30,560 —-a-r c:\windows\Installer\$PatchCache$\Managed\9040211900063D11C8EF10054038389C\11.0.8173\OUTLACCT.DLL
+ 2007-04-19 21:53:48 109,408 —-a-r c:\windows\Installer\$PatchCache$\Managed\9040211900063D11C8EF10054038389C\11.0.8173\OUTLCTL.DLL
+ 2007-05-31 21:43:46 7,613,280 —-a-r c:\windows\Installer\$PatchCache$\Managed\9040211900063D11C8EF10054038389C\11.0.8173\OUTLLIB.DLL
+ 2007-04-19 21:53:44 106,336 —-a-r c:\windows\Installer\$PatchCache$\Managed\9040211900063D11C8EF10054038389C\11.0.8173\OUTLMIME.DLL
+ 2007-05-31 21:42:14 200,032 —-a-r c:\windows\Installer\$PatchCache$\Managed\9040211900063D11C8EF10054038389C\11.0.8173\OUTLOOK.EXE
+ 2007-04-19 21:53:56 149,856 —-a-r c:\windows\Installer\$PatchCache$\Managed\9040211900063D11C8EF10054038389C\11.0.8173\OUTLPH.DLL
+ 2007-04-19 21:53:24 69,984 —-a-r c:\windows\Installer\$PatchCache$\Managed\9040211900063D11C8EF10054038389C\11.0.8173\OUTLRPC.DLL
+ 2007-03-23 03:07:28 52,576 —-a-r c:\windows\Installer\$PatchCache$\Managed\9040211900063D11C8EF10054038389C\11.0.8173\OUTLWAB.DLL
+ 2007-05-10 21:45:34 8,069,464 —-a-r c:\windows\Installer\$PatchCache$\Managed\9040211900063D11C8EF10054038389C\11.0.8173\OWC11.DLL
+ 2007-05-31 21:35:22 6,420,320 —-a-r c:\windows\Installer\$PatchCache$\Managed\9040211900063D11C8EF10054038389C\11.0.8173\POWERPNT.EXE
+ 2007-03-23 03:05:34 434,016 —-a-r c:\windows\Installer\$PatchCache$\Managed\9040211900063D11C8EF10054038389C\11.0.8173\PP4X322.DLL
+ 2007-03-23 03:05:22 97,632 —-a-r c:\windows\Installer\$PatchCache$\Managed\9040211900063D11C8EF10054038389C\11.0.8173\PP7X32.DLL
+ 2007-04-19 21:49:56 1,661,280 —-a-r c:\windows\Installer\$PatchCache$\Managed\9040211900063D11C8EF10054038389C\11.0.8173\PPTVIEW.EXE
+ 2007-03-23 03:07:10 41,824 —-a-r c:\windows\Installer\$PatchCache$\Managed\9040211900063D11C8EF10054038389C\11.0.8173\RECALL.DLL
+ 2007-06-06 20:07:40 100,192 —-a-r c:\windows\Installer\$PatchCache$\Managed\9040211900063D11C8EF10054038389C\11.0.8173\REFEDIT.DLL
+ 2007-04-19 22:10:18 63,840 —-a-r c:\windows\Installer\$PatchCache$\Managed\9040211900063D11C8EF10054038389C\11.0.8173\REFIEBAR.DLL
+ 2007-03-23 03:07:54 78,168 —-a-r c:\windows\Installer\$PatchCache$\Managed\9040211900063D11C8EF10054038389C\11.0.8173\RM.DLL
+ 2007-03-23 03:09:02 394,080 —-a-r c:\windows\Installer\$PatchCache$\Managed\9040211900063D11C8EF10054038389C\11.0.8173\RTFHTML.DLL
+ 2007-03-23 03:07:40 69,984 —-a-r c:\windows\Installer\$PatchCache$\Managed\9040211900063D11C8EF10054038389C\11.0.8173\SENDTO.DLL
+ 2007-04-19 22:10:20 65,888 —-a-r c:\windows\Installer\$PatchCache$\Managed\9040211900063D11C8EF10054038389C\11.0.8173\SEQCHK10.DLL
+ 2007-03-23 03:29:16 14,704 —-a-r c:\windows\Installer\$PatchCache$\Managed\9040211900063D11C8EF10054038389C\11.0.8173\SMARTTAGINSTALL.EXE
+ 2007-05-10 21:42:52 2,839,904 —-a-r c:\windows\Installer\$PatchCache$\Managed\9040211900063D11C8EF10054038389C\11.0.8173\STSLIST.DLL
+ 2007-03-23 03:22:02 103,264 —-a-r c:\windows\Installer\$PatchCache$\Managed\9040211900063D11C8EF10054038389C\11.0.8173\TRANSMGR.DLL
+ 2007-05-10 01:19:48 2,585,936 —-a-r c:\windows\Installer\$PatchCache$\Managed\9040211900063D11C8EF10054038389C\11.0.8173\VBE6.DLL
+ 2007-05-31 21:37:40 12,310,368 —-a-r c:\windows\Installer\$PatchCache$\Managed\9040211900063D11C8EF10054038389C\11.0.8173\WINWORD.EXE
+ 2003-07-15 10:13:58 166,456 —-a-r c:\windows\Installer\$PatchCache$\Managed\90403E1900063D11C8EF10054038389C\11.0.5614\ACCWIZ.DLL
+ 2003-07-15 05:57:34 38,968 —-a-r c:\windows\Installer\$PatchCache$\Managed\90403E1900063D11C8EF10054038389C\11.0.5614\AUTHZAX.DLL
+ 2003-07-15 05:53:06 94,768 —-a-r c:\windows\Installer\$PatchCache$\Managed\90403E1900063D11C8EF10054038389C\11.0.5614\AW.DLL
+ 2003-07-15 05:56:54 14,904 —-a-r c:\windows\Installer\$PatchCache$\Managed\90403E1900063D11C8EF10054038389C\11.0.5614\DSITF.DLL
+ 2003-07-15 05:57:14 98,360 —-a-r c:\windows\Installer\$PatchCache$\Managed\90403E1900063D11C8EF10054038389C\11.0.5614\DSSM.EXE
+ 2003-07-15 05:41:44 13,368 —-a-r c:\windows\Installer\$PatchCache$\Managed\90403E1900063D11C8EF10054038389C\11.0.5614\FINDER.EXE
+ 2003-07-15 05:40:12 179,768 —-a-r c:\windows\Installer\$PatchCache$\Managed\90403E1900063D11C8EF10054038389C\11.0.5614\FPERSON.DLL
+ 2003-07-15 05:40:12 165,944 —-a-r c:\windows\Installer\$PatchCache$\Managed\90403E1900063D11C8EF10054038389C\11.0.5614\FPLACE.DLL
+ 2003-08-01 22:07:36 4,815,424 —-a-r c:\windows\Installer\$PatchCache$\Managed\90403E1900063D11C8EF10054038389C\11.0.5614\INFOPATH.EXE
+ 2003-07-15 05:45:14 58,944 —-a-r c:\windows\Installer\$PatchCache$\Managed\90403E1900063D11C8EF10054038389C\11.0.5614\INLAUNCH.DLL
+ 2003-06-19 00:31:10 252,928 —-a-r c:\windows\Installer\$PatchCache$\Managed\90403E1900063D11C8EF10054038389C\11.0.5614\MDIINK.DLL
+ 2003-07-15 05:46:08 176,696 —-a-r c:\windows\Installer\$PatchCache$\Managed\90403E1900063D11C8EF10054038389C\11.0.5614\MIMEDIR.DLL
+ 2003-08-15 07:54:08 6,627,392 —-a-r c:\windows\Installer\$PatchCache$\Managed\90403E1900063D11C8EF10054038389C\11.0.5614\MSACCESS.EXE
+ 2003-07-15 10:13:58 130,112 —-a-r c:\windows\Installer\$PatchCache$\Managed\90403E1900063D11C8EF10054038389C\11.0.5614\MSAEXP30.DLL
+ 2003-07-15 05:51:44 87,104 —-a-r c:\windows\Installer\$PatchCache$\Managed\90403E1900063D11C8EF10054038389C\11.0.5614\MSENCODE.DLL
+ 2003-07-15 10:14:00 139,328 —-a-r c:\windows\Installer\$PatchCache$\Managed\90403E1900063D11C8EF10054038389C\11.0.5614\MSJSPP40.DLL
+ 2003-07-15 05:52:52 17,464 —-a-r c:\windows\Installer\$PatchCache$\Managed\90403E1900063D11C8EF10054038389C\11.0.5614\MSMH.DLL
+ 2003-07-15 05:57:16 120,888 —-a-r c:\windows\Installer\$PatchCache$\Managed\90403E1900063D11C8EF10054038389C\11.0.5614\MSOAUTH.DLL
+ 2003-07-15 05:52:52 27,704 —-a-r c:\windows\Installer\$PatchCache$\Managed\90403E1900063D11C8EF10054038389C\11.0.5614\MSODCW.DLL
+ 2003-07-15 05:44:06 25,144 —-a-r c:\windows\Installer\$PatchCache$\Managed\90403E1900063D11C8EF10054038389C\11.0.5614\MSOEURO.DLL
+ 2003-07-15 05:52:56 55,360 —-a-r c:\windows\Installer\$PatchCache$\Managed\90403E1900063D11C8EF10054038389C\11.0.5614\MSOHTMED.EXE
+ 2003-07-11 09:15:48 1,292,872 —-a-r c:\windows\Installer\$PatchCache$\Managed\90403E1900063D11C8EF10054038389C\11.0.5614\MSONSEXT.DLL
+ 2003-07-15 10:18:52 376,888 —-a-r c:\windows\Installer\$PatchCache$\Managed\90403E1900063D11C8EF10054038389C\11.0.5614\MSORUN.DLL
+ 2003-07-15 05:52:54 28,224 —-a-r c:\windows\Installer\$PatchCache$\Managed\90403E1900063D11C8EF10054038389C\11.0.5614\MSOSTYLE.DLL
+ 2003-07-15 05:52:52 35,896 —-a-r c:\windows\Installer\$PatchCache$\Managed\90403E1900063D11C8EF10054038389C\11.0.5614\MSOSV.DLL
+ 2003-07-15 05:53:20 39,488 —-a-r c:\windows\Installer\$PatchCache$\Managed\90403E1900063D11C8EF10054038389C\11.0.5614\MSOSVFBR.DLL
+ 2003-07-15 05:46:16 42,040 —-a-r c:\windows\Installer\$PatchCache$\Managed\90403E1900063D11C8EF10054038389C\11.0.5614\MSOXEV.DLL
+ 2003-07-15 05:45:12 55,360 —-a-r c:\windows\Installer\$PatchCache$\Managed\90403E1900063D11C8EF10054038389C\11.0.5614\MSOXMLED.EXE
+ 2003-07-15 05:45:12 39,488 —-a-r c:\windows\Installer\$PatchCache$\Managed\90403E1900063D11C8EF10054038389C\11.0.5614\MSOXMLMF.DLL
+ 2003-06-19 00:31:50 16,384 —-a-r c:\windows\Installer\$PatchCache$\Managed\90403E1900063D11C8EF10054038389C\11.0.5614\MSPGIMME.DLL
+ 2003-07-28 19:24:40 5,677,112 —-a-r c:\windows\Installer\$PatchCache$\Managed\90403E1900063D11C8EF10054038389C\11.0.5614\MSPUB.EXE
+ 2003-06-19 23:05:50 364,648 —-a-r c:\windows\Installer\$PatchCache$\Managed\90403E1900063D11C8EF10054038389C\11.0.5614\MSPVIEW.EXE
+ 2003-07-15 05:52:58 41,528 —-a-r c:\windows\Installer\$PatchCache$\Managed\90403E1900063D11C8EF10054038389C\11.0.5614\MSSH.DLL
+ 2003-07-15 06:00:54 145,984 —-a-r c:\windows\Installer\$PatchCache$\Managed\90403E1900063D11C8EF10054038389C\11.0.5614\MSWEBCAP.DLL
+ 2003-07-15 05:57:10 56,888 —-a-r c:\windows\Installer\$PatchCache$\Managed\90403E1900063D11C8EF10054038389C\11.0.5614\NAME.DLL
+ 2003-07-15 05:56:52 13,888 —-a-r c:\windows\Installer\$PatchCache$\Managed\90403E1900063D11C8EF10054038389C\11.0.5614\NPOFFICE.DLL
+ 2006-10-03 21:24:49 223,800 —-a-r c:\windows\Installer\$PatchCache$\Managed\90403E1900063D11C8EF10054038389C\11.0.5614\OFFICE.DLL
+ 2003-07-15 10:14:26 242,240 —-a-r c:\windows\Installer\$PatchCache$\Managed\90403E1900063D11C8EF10054038389C\11.0.5614\OISGRAPH.DLL
+ 2003-07-15 06:05:24 1,054,264 —-a-r c:\windows\Installer\$PatchCache$\Managed\90403E1900063D11C8EF10054038389C\11.0.5614\OMFC.DLL
+ 2003-07-15 05:44:34 102,968 —-a-r c:\windows\Installer\$PatchCache$\Managed\90403E1900063D11C8EF10054038389C\11.0.5614\OUTLCTL.DLL
+ 2003-07-07 20:36:00 2,058,343 —-a-r c:\windows\Installer\$PatchCache$\Managed\90403E1900063D11C8EF10054038389C\11.0.5614\OUTLFLTR.DAT
+ 2003-07-08 18:48:00 115,288 —-a-r c:\windows\Installer\$PatchCache$\Managed\90403E1900063D11C8EF10054038389C\11.0.5614\OUTLFLTR.DLL
+ 2003-07-15 05:43:16 49,208 —-a-r c:\windows\Installer\$PatchCache$\Managed\90403E1900063D11C8EF10054038389C\11.0.5614\OUTLWAB.DLL
+ 2003-08-04 20:19:34 7,330,360 —-a-r c:\windows\Installer\$PatchCache$\Managed\90403E1900063D11C8EF10054038389C\11.0.5614\OWC10.DLL
+ 2003-07-15 10:18:44 93,752 —-a-r c:\windows\Installer\$PatchCache$\Managed\90403E1900063D11C8EF10054038389C\11.0.5614\PP7X32.DLL
+ 2003-07-15 05:40:26 130,104 —-a-r c:\windows\Installer\$PatchCache$\Managed\90403E1900063D11C8EF10054038389C\11.0.5614\PRTF9.DLL
+ 2003-07-15 05:51:12 604,728 —-a-r c:\windows\Installer\$PatchCache$\Managed\90403E1900063D11C8EF10054038389C\11.0.5614\PTXT9.DLL
+ 2003-07-15 05:50:26 551,480 —-a-r c:\windows\Installer\$PatchCache$\Managed\90403E1900063D11C8EF10054038389C\11.0.5614\PUBCONV.DLL
+ 2003-07-15 05:40:16 51,256 —-a-r c:\windows\Installer\$PatchCache$\Managed\90403E1900063D11C8EF10054038389C\11.0.5614\PUBTRAP.DLL
+ 2003-07-15 05:42:26 37,432 —-a-r c:\windows\Installer\$PatchCache$\Managed\90403E1900063D11C8EF10054038389C\11.0.5614\RECALL.DLL
+ 2003-05-09 04:54:00 77,824 —-a-r c:\windows\Installer\$PatchCache$\Managed\90403E1900063D11C8EF10054038389C\11.0.5614\REFEDIT.DLL
+ 2003-07-15 05:57:08 40,512 —-a-r c:\windows\Installer\$PatchCache$\Managed\90403E1900063D11C8EF10054038389C\11.0.5614\REFIEBAR.DLL
+ 2003-07-21 18:46:38 390,712 —-a-r c:\windows\Installer\$PatchCache$\Managed\90403E1900063D11C8EF10054038389C\11.0.5614\RTFHTML.DLL
+ 2003-07-15 05:44:16 66,616 —-a-r c:\windows\Installer\$PatchCache$\Managed\90403E1900063D11C8EF10054038389C\11.0.5614\SENDTO.DLL
+ 2003-07-15 05:57:08 58,944 —-a-r c:\windows\Installer\$PatchCache$\Managed\90403E1900063D11C8EF10054038389C\11.0.5614\SEQCHK10.DLL
+ 2003-07-15 05:53:14 11,848 —-a-r c:\windows\Installer\$PatchCache$\Managed\90403E1900063D11C8EF10054038389C\11.0.5614\SMARTTAGINSTALL.EXE
+ 2003-08-06 20:26:18 445,488 —-a-r c:\windows\Installer\$PatchCache$\Managed\90403E1900063D11C8EF10054038389C\11.0.5614\SOA.DLL
+ 2006-10-03 21:24:50 64,088 —-a-r c:\windows\Installer\$PatchCache$\Managed\90403E1900063D11C8EF10054038389C\11.0.5614\VBIDEPIA.DLL
+ 2007-03-23 03:07:56 91,488 —-a-r c:\windows\Installer\$PatchCache$\Managed\90403E1900063D11C8EF10054038389C\11.0.8173\ADDRPARS.DLL
+ 2007-03-23 03:07:54 80,224 —-a-r c:\windows\Installer\$PatchCache$\Managed\90403E1900063D11C8EF10054038389C\11.0.8173\DLGSETP.DLL
+ 2007-04-19 21:53:52 137,568 —-a-r c:\windows\Installer\$PatchCache$\Managed\90403E1900063D11C8EF10054038389C\11.0.8173\ENVELOPE.DLL
+ 2007-05-31 21:41:06 10,352,472 —-a-r c:\windows\Installer\$PatchCache$\Managed\90403E1900063D11C8EF10054038389C\11.0.8173\EXCEL.EXE
+ 2007-04-19 22:09:30 167,256 —-a-r c:\windows\Installer\$PatchCache$\Managed\90403E1900063D11C8EF10054038389C\11.0.8173\IETAG.DLL
+ 2007-04-19 21:53:52 127,328 —-a-r c:\windows\Installer\$PatchCache$\Managed\90403E1900063D11C8EF10054038389C\11.0.8173\IMPMAIL.DLL
+ 2007-04-19 21:54:04 183,136 —-a-r c:\windows\Installer\$PatchCache$\Managed\90403E1900063D11C8EF10054038389C\11.0.8173\MIMEDIR.DLL
+ 2005-05-04 07:06:28 465,640 —-a-r c:\windows\Installer\$PatchCache$\Managed\90403E1900063D11C8EF10054038389C\11.0.8173\MSDMENG.DLL
+ 2005-05-04 07:06:32 1,411,816 —-a-r c:\windows\Installer\$PatchCache$\Managed\90403E1900063D11C8EF10054038389C\11.0.8173\MSDMINE.DLL
+ 2005-05-04 07:06:26 199,408 —-a-r c:\windows\Installer\$PatchCache$\Managed\90403E1900063D11C8EF10054038389C\11.0.8173\MSMDUN80.DLL
+ 2007-06-19 01:16:32 12,259,160 —-a-r c:\windows\Installer\$PatchCache$\Managed\90403E1900063D11C8EF10054038389C\11.0.8173\MSO.DLL
+ 2007-05-10 21:35:04 6,747,480 —-a-r c:\windows\Installer\$PatchCache$\Managed\90403E1900063D11C8EF10054038389C\11.0.8173\MSPUB.EXE
+ 2007-05-31 21:43:46 7,613,280 —-a-r c:\windows\Installer\$PatchCache$\Managed\90403E1900063D11C8EF10054038389C\11.0.8173\OUTLLIB.DLL
+ 2007-04-19 21:53:44 106,336 —-a-r c:\windows\Installer\$PatchCache$\Managed\90403E1900063D11C8EF10054038389C\11.0.8173\OUTLMIME.DLL
+ 2007-05-31 21:42:14 200,032 —-a-r c:\windows\Installer\$PatchCache$\Managed\90403E1900063D11C8EF10054038389C\11.0.8173\OUTLOOK.EXE
+ 2007-04-19 21:53:56 149,856 —-a-r c:\windows\Installer\$PatchCache$\Managed\90403E1900063D11C8EF10054038389C\11.0.8173\OUTLPH.DLL
+ 2007-04-19 21:53:24 69,984 —-a-r c:\windows\Installer\$PatchCache$\Managed\90403E1900063D11C8EF10054038389C\11.0.8173\OUTLRPC.DLL
+ 2007-05-31 21:35:22 6,420,320 —-a-r c:\windows\Installer\$PatchCache$\Managed\90403E1900063D11C8EF10054038389C\11.0.8173\POWERPNT.EXE
+ 2007-05-31 21:35:46 133,976 —-a-r c:\windows\Installer\$PatchCache$\Managed\90403E1900063D11C8EF10054038389C\11.0.8173\PRTF9.DLL
+ 2007-05-31 21:36:08 612,184 —-a-r c:\windows\Installer\$PatchCache$\Managed\90403E1900063D11C8EF10054038389C\11.0.8173\PTXT9.DLL
+ 2007-05-10 21:34:48 562,528 —-a-r c:\windows\Installer\$PatchCache$\Managed\90403E1900063D11C8EF10054038389C\11.0.8173\PUBCONV.DLL
+ 2007-03-23 03:07:10 41,824 —-a-r c:\windows\Installer\$PatchCache$\Managed\90403E1900063D11C8EF10054038389C\11.0.8173\RECALL.DLL
+ 2007-03-23 03:07:54 78,168 —-a-r c:\windows\Installer\$PatchCache$\Managed\90403E1900063D11C8EF10054038389C\11.0.8173\RM.DLL
+ 2007-03-23 03:22:02 103,264 —-a-r c:\windows\Installer\$PatchCache$\Managed\90403E1900063D11C8EF10054038389C\11.0.8173\TRANSMGR.DLL
+ 2007-05-10 01:19:48 2,585,936 —-a-r c:\windows\Installer\$PatchCache$\Managed\90403E1900063D11C8EF10054038389C\11.0.8173\VBE6.DLL
+ 2007-05-31 21:37:40 12,310,368 —-a-r c:\windows\Installer\$PatchCache$\Managed\90403E1900063D11C8EF10054038389C\11.0.8173\WINWORD.EXE
- 2006-10-03 21:35:22 65,536 —-a-r c:\windows\Installer\{6D52C408-B09A-4520-9B18-475B81D393F1}\_4E403E143BE9_4CD1_B8DF_8012EBBE9E82.exe
+ 2008-11-29 02:29:05 65,536 —-a-r c:\windows\Installer\{6D52C408-B09A-4520-9B18-475B81D393F1}\_4E403E143BE9_4CD1_B8DF_8012EBBE9E82.exe
- 2006-10-03 21:35:22 65,536 —-a-r c:\windows\Installer\{6D52C408-B09A-4520-9B18-475B81D393F1}\_630CEEA9B210_4765_A2B1_FC24596048D7.exe
+ 2008-11-29 02:29:04 65,536 —-a-r c:\windows\Installer\{6D52C408-B09A-4520-9B18-475B81D393F1}\_630CEEA9B210_4765_A2B1_FC24596048D7.exe
- 2006-10-03 21:35:22 184,320 —-a-r c:\windows\Installer\{6D52C408-B09A-4520-9B18-475B81D393F1}\_9FA356B1395F_4530_8CB3_946ED0B3291E.exe
+ 2008-11-29 02:29:04 184,320 —-a-r c:\windows\Installer\{6D52C408-B09A-4520-9B18-475B81D393F1}\_9FA356B1395F_4530_8CB3_946ED0B3291E.exe
- 2006-10-03 21:35:22 65,536 —-a-r c:\windows\Installer\{6D52C408-B09A-4520-9B18-475B81D393F1}\_B8B1511D9331_467C_9B1B_E8204012E95B.exe
+ 2008-11-29 02:29:04 65,536 —-a-r c:\windows\Installer\{6D52C408-B09A-4520-9B18-475B81D393F1}\_B8B1511D9331_467C_9B1B_E8204012E95B.exe
- 2006-10-03 21:35:22 17,534 —-a-r c:\windows\Installer\{6D52C408-B09A-4520-9B18-475B81D393F1}\gtngstrtd.exe
+ 2008-11-29 02:29:04 17,534 —-a-r c:\windows\Installer\{6D52C408-B09A-4520-9B18-475B81D393F1}\gtngstrtd.exe
- 2006-10-03 21:35:22 4,710 —-a-r c:\windows\Installer\{6D52C408-B09A-4520-9B18-475B81D393F1}\Win2Kico.exe
+ 2008-11-29 02:29:04 4,710 —-a-r c:\windows\Installer\{6D52C408-B09A-4520-9B18-475B81D393F1}\Win2Kico.exe
- 2006-10-03 21:35:22 4,710 —-a-r c:\windows\Installer\{6D52C408-B09A-4520-9B18-475B81D393F1}\WSBico.exe
+ 2008-11-29 02:29:05 4,710 —-a-r c:\windows\Installer\{6D52C408-B09A-4520-9B18-475B81D393F1}\WSBico.exe
- 2006-10-03 21:43:42 12,288 —-a-r c:\windows\Installer\{91120409-6000-11D3-8CFE-0150048383C9}\cagicon.exe
+ 2008-11-29 16:10:33 12,288 —-a-r c:\windows\Installer\{91120409-6000-11D3-8CFE-0150048383C9}\cagicon.exe
- 2006-10-03 21:43:42 135,168 —-a-r c:\windows\Installer\{91120409-6000-11D3-8CFE-0150048383C9}\misc.exe
+ 2008-11-29 16:10:33 135,168 —-a-r c:\windows\Installer\{91120409-6000-11D3-8CFE-0150048383C9}\misc.exe
- 2006-10-03 21:43:42 11,264 —-a-r c:\windows\Installer\{91120409-6000-11D3-8CFE-0150048383C9}\mspicons.exe
+ 2008-11-29 16:10:33 11,264 —-a-r c:\windows\Installer\{91120409-6000-11D3-8CFE-0150048383C9}\mspicons.exe
- 2006-10-03 21:43:42 27,136 —-a-r c:\windows\Installer\{91120409-6000-11D3-8CFE-0150048383C9}\oisicon.exe
+ 2008-11-29 16:10:33 27,136 —-a-r c:\windows\Installer\{91120409-6000-11D3-8CFE-0150048383C9}\oisicon.exe
- 2006-10-03 21:43:42 4,096 —-a-r c:\windows\Installer\{91120409-6000-11D3-8CFE-0150048383C9}\opwicon.exe
+ 2008-11-29 16:10:33 4,096 —-a-r c:\windows\Installer\{91120409-6000-11D3-8CFE-0150048383C9}\opwicon.exe
- 2006-10-03 21:43:42 794,624 —-a-r c:\windows\Installer\{91120409-6000-11D3-8CFE-0150048383C9}\outicon.exe
+ 2008-11-29 16:10:33 794,624 —-a-r c:\windows\Installer\{91120409-6000-11D3-8CFE-0150048383C9}\outicon.exe
- 2006-10-03 21:43:42 249,856 —-a-r c:\windows\Installer\{91120409-6000-11D3-8CFE-0150048383C9}\pptico.exe
+ 2008-11-29 16:10:33 249,856 —-a-r c:\windows\Installer\{91120409-6000-11D3-8CFE-0150048383C9}\pptico.exe
- 2006-10-03 21:43:42 23,040 —-a-r c:\windows\Installer\{91120409-6000-11D3-8CFE-0150048383C9}\unbndico.exe
+ 2008-11-29 16:10:33 23,040 —-a-r c:\windows\Installer\{91120409-6000-11D3-8CFE-0150048383C9}\unbndico.exe
- 2006-10-03 21:43:42 286,720 —-a-r c:\windows\Installer\{91120409-6000-11D3-8CFE-0150048383C9}\wordicon.exe
+ 2008-11-29 16:10:32 286,720 —-a-r c:\windows\Installer\{91120409-6000-11D3-8CFE-0150048383C9}\wordicon.exe
- 2006-10-03 21:43:41 409,600 —-a-r c:\windows\Installer\{91120409-6000-11D3-8CFE-0150048383C9}\xlicons.exe
+ 2008-11-29 16:10:32 409,600 —-a-r c:\windows\Installer\{91120409-6000-11D3-8CFE-0150048383C9}\xlicons.exe
- 2007-04-03 22:05:36 593,920 —-a-r c:\windows\Installer\{91E30409-6000-11D3-8CFE-0150048383C9}\accicons.exe
+ 2008-11-29 16:09:21 593,920 —-a-r c:\windows\Installer\{91E30409-6000-11D3-8CFE-0150048383C9}\accicons.exe
- 2007-04-03 22:05:36 12,288 —-a-r c:\windows\Installer\{91E30409-6000-11D3-8CFE-0150048383C9}\cagicon.exe
+ 2008-11-29 16:09:22 12,288 —-a-r c:\windows\Installer\{91E30409-6000-11D3-8CFE-0150048383C9}\cagicon.exe
- 2007-04-03 22:05:36 86,016 —-a-r c:\windows\Installer\{91E30409-6000-11D3-8CFE-0150048383C9}\inficon.exe
+ 2008-11-29 16:09:22 86,016 —-a-r c:\windows\Installer\{91E30409-6000-11D3-8CFE-0150048383C9}\inficon.exe
- 2007-04-03 22:05:36 135,168 —-a-r c:\windows\Installer\{91E30409-6000-11D3-8CFE-0150048383C9}\misc.exe
+ 2008-11-29 16:09:21 135,168 —-a-r c:\windows\Installer\{91E30409-6000-11D3-8CFE-0150048383C9}\misc.exe
- 2007-04-03 22:05:37 11,264 —-a-r c:\windows\Installer\{91E30409-6000-11D3-8CFE-0150048383C9}\mspicons.exe
+ 2008-11-29 16:09:22 11,264 —-a-r c:\windows\Installer\{91E30409-6000-11D3-8CFE-0150048383C9}\mspicons.exe
- 2007-04-03 22:05:37 27,136 —-a-r c:\windows\Installer\{91E30409-6000-11D3-8CFE-0150048383C9}\oisicon.exe
+ 2008-11-29 16:09:22 27,136 —-a-r c:\windows\Installer\{91E30409-6000-11D3-8CFE-0150048383C9}\oisicon.exe
- 2007-04-03 22:05:37 4,096 —-a-r c:\windows\Installer\{91E30409-6000-11D3-8CFE-0150048383C9}\opwicon.exe
+ 2008-11-29 16:09:22 4,096 —-a-r c:\windows\Installer\{91E30409-6000-11D3-8CFE-0150048383C9}\opwicon.exe
- 2007-04-03 22:05:37 794,624 —-a-r c:\windows\Installer\{91E30409-6000-11D3-8CFE-0150048383C9}\outicon.exe
+ 2008-11-29 16:09:22 794,624 —-a-r c:\windows\Installer\{91E30409-6000-11D3-8CFE-0150048383C9}\outicon.exe
- 2007-04-03 22:05:36 249,856 —-a-r c:\windows\Installer\{91E30409-6000-11D3-8CFE-0150048383C9}\pptico.exe
+ 2008-11-29 16:09:21 249,856 —-a-r c:\windows\Installer\{91E30409-6000-11D3-8CFE-0150048383C9}\pptico.exe
- 2007-04-03 22:05:36 61,440 —-a-r c:\windows\Installer\{91E30409-6000-11D3-8CFE-0150048383C9}\pubs.exe
+ 2008-11-29 16:09:21 61,440 —-a-r c:\windows\Installer\{91E30409-6000-11D3-8CFE-0150048383C9}\pubs.exe
- 2007-04-03 22:05:37 23,040 —-a-r c:\windows\Installer\{91E30409-6000-11D3-8CFE-0150048383C9}\unbndico.exe
+ 2008-11-29 16:09:22 23,040 —-a-r c:\windows\Installer\{91E30409-6000-11D3-8CFE-0150048383C9}\unbndico.exe
- 2007-04-03 22:05:36 286,720 —-a-r c:\windows\Installer\{91E30409-6000-11D3-8CFE-0150048383C9}\wordicon.exe
+ 2008-11-29 16:09:21 286,720 —-a-r c:\windows\Installer\{91E30409-6000-11D3-8CFE-0150048383C9}\wordicon.exe
- 2007-04-03 22:05:36 409,600 —-a-r c:\windows\Installer\{91E30409-6000-11D3-8CFE-0150048383C9}\xlicons.exe
+ 2008-11-29 16:09:21 409,600 —-a-r c:\windows\Installer\{91E30409-6000-11D3-8CFE-0150048383C9}\xlicons.exe
- 2005-03-17 21:39:58 1,146,320 —-a-w c:\windows\system32\FM20.DLL
+ 2007-06-06 18:53:34 1,195,888 —-a-w c:\windows\system32\FM20.DLL
- 2003-07-15 05:57:04 32,584 —-a-w c:\windows\system32\FM20ENU.DLL
+ 2007-03-23 03:17:04 35,440 —-a-w c:\windows\system32\FM20ENU.DLL
- 2008-10-16 00:48:48 250,288 —-a-w c:\windows\system32\FNTCACHE.DAT
+ 2008-12-01 03:23:13 250,288 —-a-w c:\windows\system32\FNTCACHE.DAT
+ 2003-09-04 22:14:28 94,208 —-a-w c:\windows\system32\Macromed\Flash\GetFlash.exe
- 2004-03-22 22:17:06 24,816 —-a-w c:\windows\system32\mdimon.dll
+ 2007-04-09 21:23:54 28,040 —-a-w c:\windows\system32\mdimon.dll
- 2004-03-22 22:17:04 765,680 —-a-w c:\windows\system32\spool\drivers\w32x86\3\mdigraph.dll
+ 2007-04-09 21:24:04 758,664 —-a-w c:\windows\system32\spool\drivers\w32x86\3\mdigraph.dll
- 2004-03-22 22:17:10 42,224 —-a-w c:\windows\system32\spool\drivers\w32x86\3\mdiui.dll
+ 2007-04-09 21:23:58 46,472 —-a-w c:\windows\system32\spool\drivers\w32x86\3\mdiui.dll
- 2004-03-22 22:17:04 765,680 —-a-w c:\windows\system32\spool\drivers\w32x86\mdigraph.dll
+ 2007-04-09 21:24:04 758,664 —-a-w c:\windows\system32\spool\drivers\w32x86\mdigraph.dll
- 2004-03-22 22:17:10 42,224 —-a-w c:\windows\system32\spool\drivers\w32x86\mdiui.dll
+ 2007-04-09 21:23:58 46,472 —-a-w c:\windows\system32\spool\drivers\w32x86\mdiui.dll
- 2004-03-22 22:17:08 25,840 —-a-w c:\windows\system32\spool\prtprocs\w32x86\mdippr.dll
+ 2007-04-09 21:23:54 28,552 —-a-w c:\windows\system32\spool\prtprocs\w32x86\mdippr.dll
.
– Snapshot reset to current date –
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Power2GoExpress"="NA" [X]
"updateMgr"="c:\program files\Adobe\Acrobat 7.0\Reader\AdobeUpdateManager.exe" [2006-03-30 313472]
"MSMSGS"="c:\program files\Messenger\msmsgs.exe" [2004-10-13 1694208]
"ctfmon.exe"="c:\windows\system32\ctfmon.exe" [2004-08-10 15360]
"swg"="c:\program files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe" [2008-10-01 68856]
"DW6"="c:\program files\The Weather Channel FW\Desktop\DesktopWeather.exe" [2008-09-26 789616]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ehTray"="c:\windows\ehome\ehtray.exe" [2005-08-05 64512]
"Recguard"="c:\windows\SMINST\RECGUARD.EXE" [2002-09-13 212992]
"HP Software Update"="c:\program files\HP\HP Software Update\HPWuSchd2.exe" [2005-12-15 49152]
"MFP1815_S2P"="c:\program files\DELL\DELL LASER MFP 1815\PSU\Scan2Pc.exe" [2006-12-22 258952]
"SSBkgdUpdate"="c:\program files\Common Files\Scansoft Shared\SSBkgdUpdate\SSBkgdupdate.exe" [2003-10-14 155648]
"PaperPort PTD"="c:\program files\DELL\Dell Laser MFP 1815\PaperPort\pptd40nt.exe" [2006-02-20 36864]
"IndexSearch"="c:\program files\DELL\Dell Laser MFP 1815\PaperPort\IndexSearch.exe" [2006-02-20 40960]
"QuickTime Task"="c:\program files\QuickTime\QTTask.exe" [2007-06-29 286720]
"iTunesHelper"="c:\program files\iTunes\iTunesHelper.exe" [2007-07-10 270648]
"MSKDetectorExe"="c:\program files\McAfee\SpamKiller\MSKDetct.exe" [2006-11-07 1121280]
"HostManager"="c:\program files\Common Files\AOL\1215622490\EE\AOLHostManager.exe" [2004-11-03 125528]
"AOLDialer"="c:\program files\Common Files\AOL\ACS\AOLDial.exe" [2004-10-20 34904]
"AOL Spyware Protection"="c:\progra~1\COMMON~1\AOL\AOLSPY~1\AOLSP Scheduler.exe" [2004-10-18 79448]
"cctray"="c:\program files\CA\CA Internet Security Suite\cctray\cctray.exe" [2007-08-16 177416]
"QOELOADER"="c:\program files\CA\CA Internet Security Suite\CA Anti-Spam\QSP-5.1.18.0\QOELoader.exe" [2008-11-13 14088]
"CAVRID"="c:\program files\CA\CA Internet Security Suite\CA Anti-Virus\CAVRID.exe" [2007-08-20 230664]
"cafwc"="c:\program files\CA\CA Internet Security Suite\CA Personal Firewall\cafw.exe" [2008-11-13 1193200]
"capfasem"="c:\program files\CA\CA Internet Security Suite\CA Personal Firewall\capfasem.exe" [2008-11-13 173296]
"capfupgrade"="c:\program files\CA\CA Internet Security Suite\CA Personal Firewall\capfupgrade.exe" [2008-11-13 259312]
"RTHDCPL"="RTHDCPL.EXE" [2006-04-16 c:\windows\RTHDCPL.exe]
"CHotkey"="zHotkey.exe" [2004-12-08 c:\windows\zHotkey.exe]

c:\documents and settings\All Users\Start Menu\Programs\Startup\
Adobe Reader Speed Launch.lnk - c:\program files\Adobe\Acrobat 7.0\Reader\reader_sl.exe [2005-09-23 29696]
HP Digital Imaging Monitor.lnk - c:\program files\HP\Digital Imaging\bin\hpqtra08.exe [2005-12-15 282624]

[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\policies\explorer]
"ForceClassicControlPanel"= 1 (0x1)

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\PFW]
2007-05-18 13:30 79368 c:\windows\system32\UmxWNP.dll

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\drivers32]
"msacm.clmp3enc"= c:\progra~1\CYBERL~1\Power2Go\CLMP3Enc.ACM

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]
"EnableFirewall"= 0 (0x0)

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"c:\\Program Files\\Common Files\\AOL\\Loader\\aolload.exe"=
"c:\\Program Files\\Common Files\\AOL\\ACS\\AOLDial.exe"=
"c:\\Program Files\\Common Files\\AOL\\ACS\\AOLacsd.exe"=
"c:\\Program Files\\America Online 9.0\\waol.exe"=
"c:\\Program Files\\Common Files\\AOL\\TopSpeed\\2.0\\aoltsmon.exe"=
"c:\\Program Files\\Common Files\\AOL\\TopSpeed\\2.0\\aoltpspd.exe"=
"c:\\Program Files\\Common Files\\AOL\\System Information\\sinf.exe"=
"c:\\Program Files\\Common Files\\AOL\\AOL Spyware Protection\\AOLSP Scheduler.exe"=
"c:\\Program Files\\Common Files\\AOL\\AOL Spyware Protection\\asp.exe"=
"c:\\Program Files\\Common Files\\AolCoach\\en_en\\player\\AOLNySEV.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpqtra08.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpqste08.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpofxm08.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hposfx08.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hposid01.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpqscnvw.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpqkygrp.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpqCopy.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpfccopy.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpzwiz01.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\Unload\\HpqPhUnl.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\Unload\\HpqDIA.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpoews01.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpqnrs08.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"c:\\Program Files\\Messenger\\msmsgs.exe"=
"c:\\Program Files\\iTunes\\iTunes.exe"=
"c:\\Program Files\\Common Files\\AOL\\1215622490\\EE\\AOLServiceHost.exe"=

R0 KmxStart;KmxStart;c:\windows\system32\DRIVERS\kmxstart.sys [2008-06-24 93712]
R1 KmxAgent;KmxAgent;c:\windows\system32\DRIVERS\kmxagent.sys [2008-06-24 63504]
R1 KmxFile;KmxFile;c:\windows\system32\DRIVERS\KmxFile.sys [2008-06-24 45584]
R1 KmxFw;KmxFw;c:\windows\system32\DRIVERS\kmxfw.sys [2008-06-24 115216]
R2 KmxCF;KmxCF;c:\windows\system32\DRIVERS\KmxCF.sys [2008-06-24 134648]
R2 KmxSbx;KmxSbx;c:\windows\system32\DRIVERS\KmxSbx.sys [2008-06-24 66576]
R2 UmxAgent;HIPS Event Manager;"c:\program files\CA\SharedComponents\HIPSEngine\UmxAgent.exe" [2007-10-18 1010192]
R2 UmxCfg;HIPS Configuration Interpreter;"c:\program files\CA\SharedComponents\HIPSEngine\UmxCfg.exe" [2007-10-18 801296]
R2 UmxPol;HIPS Policy Manager;"c:\program files\CA\SharedComponents\HIPSEngine\UmxPol.exe" [2008-06-24 281104]
R3 KmxCfg;KmxCfg;c:\windows\system32\DRIVERS\kmxcfg.sys [2008-06-24 88816]
R3 PPCtlPriv;PPCtlPriv;"c:\program files\CA\CA Internet Security Suite\CA Anti-Spyware\PPCtlPriv.exe" [2007-08-16 189704]
S2 SSPORT;SSPORT;\??\c:\windows\system32\Drivers\SSPORT.sys []
S3 RimSerPort;RIM Virtual Serial Port;c:\windows\system32\DRIVERS\RimSerial.sys [2007-04-25 18432]

[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{935b3331-5323-11db-8b52-806d6172696f}]
\Shell\AutoRun\command - c:\windows\system32\RunDLL32.EXE Shell32.DLL,ShellExec_RunDLL Info.exe folder.htt 480 480
.
Contents of the 'Scheduled Tasks' folder

2008-11-26 c:\windows\Tasks\AppleSoftwareUpdate.job
- c:\program files\Apple Software Update\SoftwareUpdate.exe [2007-06-03 12:42]

2008-11-13 c:\windows\Tasks\CAAntiSpywareScan_Daily as Owner at 8 35 AM.job
- c:\program files\CA\CA Internet Security Suite\CA Anti-Spyware\CAAntiSpyware.exe [2007-08-16 21:10]

2008-12-01 c:\windows\Tasks\MP Scheduled Scan.job
- c:\program files\Windows Defender\MpCmdRun.exe [2006-11-03 19:20]
.

**************************************************************************

catchme 0.3.1367 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2008-11-30 19:47:30
Windows 5.1.2600 Service Pack 2 NTFS

scanning hidden processes …

scanning hidden autostart entries …

scanning hidden files …

scan completed successfully
hidden files: 0

**************************************************************************
.
——————— DLLs Loaded Under Running Processes ———————

- - - - - - - > 'winlogon.exe'(1324)
c:\windows\system32\Ati2evxx.dll
c:\windows\system32\UmxWnp.Dll
c:\program files\CA\SharedComponents\PPRT\bin\CACheck.dll
c:\program files\CA\SharedComponents\PPRT\bin\CAHook.dll
c:\program files\CA\SharedComponents\PPRT\bin\CAServer.dll

- - - - - - - > 'lsass.exe'(1560)
c:\windows\system32\VetRedir.dll
c:\windows\system32\ISafeIf.dll
.
Completion time: 2008-11-30 19:54:22
ComboFix-quarantined-files.txt 2008-12-01 03:53:59
ComboFix2.txt 2008-11-29 02:36:34

Pre-Run: 131,030,822,912 bytes free
Post-Run: 131,025,653,760 bytes free

480 — E O F — 2008-11-29 16:10:35
Hi dejaylos,

You're confusing me with OldTimer, the author of OTMOVEIT3 and other tools. He writes them, I just get to use them. ;)

My fault on the detections. I forgot to remind you to disable your security programs as you did before.

This is looking better. Let's see if anything is left.

Go here to run an online scannner from ESET:
http://www.eset.eu/online-scanner

(Note: You must use Internet Explorer for this scan.)

  • Tick the box next to YES, I accept the Terms of Use.
  • Click Start
  • When asked, allow the activex control to install
  • Disable your Antivirus software. You can usually do this with its Notfication Tray icon near the clock
  • Click Start
  • Make sure that the option "Remove found threats" is Unchecked, and the option "Scan unwanted applications" is Checked.
  • Click Scan.
  • Wait for the scan to finish.
  • Re-enable your Antivirus software.
  • A logfile is created and located at C:\Program Files\EsetOnlineScanner\log.txt. We will need this later.
Please post back with the ESET log and a new HJT log.

How's your computer?

Thanks.
Hey Oldman, Sorry about the oldtimer stuff I was confusing myself! :blush:

Any how here are the logs you requested, my pc seems normal now…but only you would know so I appreciate all your help!!

# version=4
# OnlineScanner.ocx=[removed]
# OnlineScannerDLLA.dll=1, 0, 0, 51
# OnlineScannerDLLW.dll=1, 0, 0, 51
# OnlineScannerUninstaller.exe=1, 0, 0, 49
# vers_standard_module=3653 (20081201)
# vers_arch_module=1.064 (20080214)
# vers_adv_heur_module=1.066 (20070917)
# EOSSerial=bab29a5867230b40b5f0f6d8834e95a1
# end=finished
# remove_checked=false
# unwanted_checked=true
# utc_time=2008-12-01 04:49:33
# local_time=2008-12-01 08:49:33 (-0800, Pacific Standard Time)
# country="United States"
# osver=5.1.2600 NT Service Pack 2
# scanned=437935
# found=4
# scan_time=9367
C:\Qoobox\Quarantine\C\WINDOWS\system32\HDy21XAJ.dll.vir probably a variant of Win32/TrojanClicker.Agent.NEB trojan 2A34D5A130B3DBEA1EBBC49A148C70DA
C:\_OTMoveIt\MovedFiles\11302008_191848\windows\system32\FBw54VXH.exe Win32/TrojanClicker.Agent.NEB trojan 10DC2325BFBF560D474253E783F9C8BB
C:\_OTMoveIt\MovedFiles\11302008_191848\windows\system32\FBw54VXH.exe_ Win32/TrojanClicker.Agent.NEB trojan 10DC2325BFBF560D474253E783F9C8BB
C:\_OTMoveIt\MovedFiles\11302008_191848\windows\system32\VIbh1Sv1.exe probably a variant of Win32/TrojanDownloader.Firu trojan 92708452F7AFFB4AD15D2DC8241784C2


And HJT:

Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 2:45:40 PM, on 12/1/2008
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16735)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Windows Defender\MsMpEng.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\CA\SharedComponents\HIPSEngine\UmxCfg.exe
C:\Program Files\CA\SharedComponents\HIPSEngine\UmxFwHlp.exe
C:\Program Files\CA\SharedComponents\HIPSEngine\UmxPol.exe
C:\Program Files\CA\SharedComponents\HIPSEngine\UmxAgent.exe
C:\Program Files\Common Files\AOL\ACS\AOLAcsd.exe
C:\Program Files\Common Files\AOL\TopSpeed\2.0\aoltsmon.exe
C:\Program Files\CA\CA Internet Security Suite\CA Anti-Virus\ISafe.exe
C:\WINDOWS\eHome\ehRecvr.exe
C:\WINDOWS\eHome\ehSched.exe
C:\Program Files\CA\SharedComponents\PPRT\bin\ITMRTSVC.exe
C:\Program Files\Common Files\New Boundary\PrismXL\PRISMXL.SYS
C:\WINDOWS\system32\svchost.exe
C:\Program Files\CA\CA Internet Security Suite\CA Anti-Virus\VetMsg.exe
C:\WINDOWS\system32\dllhost.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\CA\CA Internet Security Suite\CA Personal Firewall\capfsem.exe
C:\WINDOWS\ehome\ehtray.exe
C:\WINDOWS\RTHDCPL.EXE
C:\WINDOWS\zHotkey.exe
C:\WINDOWS\eHome\ehmsas.exe
C:\Program Files\HP\HP Software Update\HPWuSchd2.exe
C:\PROGRAM FILES\DELL\DELL LASER MFP 1815\PSU\Scan2Pc.exe
C:\Program Files\QuickTime\QTTask.exe
C:\Program Files\iTunes\iTunesHelper.exe
C:\Program Files\Common Files\AOL\ACS\AOLDial.exe
C:\PROGRA~1\COMMON~1\AOL\AOLSPY~1\AOLSP Scheduler.exe
C:\Program Files\CA\CA Internet Security Suite\cctray\cctray.exe
C:\Program Files\CA\CA Internet Security Suite\CA Anti-Spam\QSP-5.1.18.0\QOELoader.exe
C:\Program Files\CA\CA Internet Security Suite\CA Anti-Virus\CAVRID.exe
C:\Program Files\CA\CA Internet Security Suite\CA Personal Firewall\capfasem.exe
C:\PROGRA~1\COMMON~1\AOL\121562~1\EE\AOLHOS~1.EXE
C:\Program Files\Messenger\msmsgs.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
C:\PROGRA~1\COMMON~1\AOL\121562~1\EE\AOLServiceHost.exe
C:\Program Files\CA\CA Internet Security Suite\ccprovsp.exe
C:\Program Files\CA\CA Internet Security Suite\CA Anti-Spyware\CAPPActiveProtection.exe
C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe
C:\Program Files\CA\CA Internet Security Suite\CA Anti-Spyware\PPCtlPriv.exe
C:\Program Files\iPod\bin\iPodService.exe
C:\Program Files\HP\Digital Imaging\bin\hpqSTE08.exe
C:\Program Files\Internet Explorer\IEXPLORE.EXE
C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLLoginProxy.exe
C:\WINDOWS\system32\wscntfy.exe
C:\WINDOWS\system32\wuauclt.exe
C:\Program Files\trend micro\HijackThis\HijackThis.exe

R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
O2 - BHO: Windows Live Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
O3 - Toolbar: AOL Toolbar - {4982D40A-C53B-4615-B15B-B5B5E98D167C} - C:\Program Files\AOL Toolbar\toolbar.dll
O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar1.dll
O4 - HKLM\..\Run: [ehTray] C:\WINDOWS\ehome\ehtray.exe
O4 - HKLM\..\Run: [RTHDCPL] RTHDCPL.EXE
O4 - HKLM\..\Run: [CHotkey] zHotkey.exe
O4 - HKLM\..\Run: [Recguard] %WINDIR%\SMINST\RECGUARD.EXE
O4 - HKLM\..\Run: [HP Software Update] C:\Program Files\HP\HP Software Update\HPWuSchd2.exe
O4 - HKLM\..\Run: [MFP1815_S2P] C:\PROGRAM FILES\DELL\DELL LASER MFP 1815\PSU\Scan2Pc.exe
O4 - HKLM\..\Run: [SSBkgdUpdate] "C:\Program Files\Common Files\Scansoft Shared\SSBkgdUpdate\SSBkgdupdate.exe" -Embedding -boot
O4 - HKLM\..\Run: [PaperPort PTD] "C:\Program Files\DELL\Dell Laser MFP 1815\PaperPort\pptd40nt.exe"
O4 - HKLM\..\Run: [IndexSearch] "C:\Program Files\DELL\Dell Laser MFP 1815\PaperPort\IndexSearch.exe"
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\QTTask.exe" -atboottime
O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
O4 - HKLM\..\Run: [MSKDetectorExe] C:\Program Files\McAfee\SpamKiller\MSKDetct.exe /uninstall
O4 - HKLM\..\Run: [HostManager] C:\Program Files\Common Files\AOL\1215622490\EE\AOLHostManager.exe
O4 - HKLM\..\Run: [AOLDialer] C:\Program Files\Common Files\AOL\ACS\AOLDial.exe
O4 - HKLM\..\Run: [AOL Spyware Protection] "C:\PROGRA~1\COMMON~1\AOL\AOLSPY~1\AOLSP Scheduler.exe"
O4 - HKLM\..\Run: [cctray] "C:\Program Files\CA\CA Internet Security Suite\cctray\cctray.exe"
O4 - HKLM\..\Run: [QOELOADER] "C:\Program Files\CA\CA Internet Security Suite\CA Anti-Spam\QSP-5.1.18.0\QOELoader.exe"
O4 - HKLM\..\Run: [CAVRID] "C:\Program Files\CA\CA Internet Security Suite\CA Anti-Virus\CAVRID.exe"
O4 - HKLM\..\Run: [cafwc] C:\Program Files\CA\CA Internet Security Suite\CA Personal Firewall\cafw.exe -cl
O4 - HKLM\..\Run: [capfasem] C:\Program Files\CA\CA Internet Security Suite\CA Personal Firewall\capfasem.exe
O4 - HKLM\..\Run: [capfupgrade] C:\Program Files\CA\CA Internet Security Suite\CA Personal Firewall\capfupgrade.exe
O4 - HKCU\..\Run: [Power2GoExpress] NA
O4 - HKCU\..\Run: [updateMgr] C:\Program Files\Adobe\Acrobat 7.0\Reader\AdobeUpdateManager.exe AcRdB7_0_9
O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [swg] C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
O4 - HKCU\..\Run: [DW6] "C:\Program Files\The Weather Channel FW\Desktop\DesktopWeather.exe"
O4 - Global Startup: Adobe Reader Speed Launch.lnk = C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
O4 - Global Startup: HP Digital Imaging Monitor.lnk = C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe
O8 - Extra context menu item: &AOL Toolbar search - res://C:\Program Files\AOL Toolbar\toolbar.dll/SEARCH.HTML
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
O9 - Extra button: AOL Toolbar - {4982D40A-C53B-4615-B15B-B5B5E98D167C} - C:\Program Files\AOL Toolbar\toolbar.dll
O9 - Extra 'Tools' menuitem: AOL Toolbar - {4982D40A-C53B-4615-B15B-B5B5E98D167C} - C:\Program Files\AOL Toolbar\toolbar.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL
O9 - Extra button: Real.com - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - C:\WINDOWS\system32\Shdocvw.dll
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O16 - DPF: {1663ed61-23eb-11d2-b92f-008048fdd814} (MeadCo ScriptX Advanced) - https://eagent.farmersinsurance.com/PLA/eAg…ctiveX/smsx.cab
O16 - DPF: {354D91A8-E3C9-491F-BB89-0FB27DEEED86} (ImgXTwain6.ImgXTwain) - https://eagent.farmersinsurance.com/PLA/eAg…ImgXTwain61.cab
O16 - DPF: {45EEDB84-57BC-4FBD-8065-7AB8E971B545} (ImgXDialog6.ImgXDialog) - https://eagent.farmersinsurance.com/PLA/eAg…mgXDialog61.cab
O16 - DPF: {56762DEC-6B0D-4AB4-A8AD-989993B5D08B} (OnlineScanner Control) - http://www.eset.eu/OnlineScanner.cab
O16 - DPF: {7E8DC73D-69CD-4F67-99B1-8DC6E42F6246} (Atalasoft ImgXCtrl6.ImgXCtrl (CAB)) - https://eagent.farmersinsurance.com/PLA/eAg…iveX/ImgX61.cab
O23 - Service: AOL Connectivity Service (AOL ACS) - America Online - C:\Program Files\Common Files\AOL\ACS\AOLAcsd.exe
O23 - Service: AOL TopSpeed Monitor (AOL TopSpeedMonitor) - America Online, Inc - C:\Program Files\Common Files\AOL\TopSpeed\2.0\aoltsmon.exe
O23 - Service: AOL Spyware Protection Service (AOLService) - Unknown owner - C:\PROGRA~1\COMMON~1\AOL\AOLSPY~1\\aolserv.exe
O23 - Service: Ati HotKey Poller - ATI Technologies Inc. - C:\WINDOWS\system32\Ati2evxx.exe
O23 - Service: ATI Smart - Unknown owner - C:\WINDOWS\system32\ati2sgag.exe
O23 - Service: CaCCProvSP - CA, Inc. - C:\Program Files\CA\CA Internet Security Suite\ccprovsp.exe
O23 - Service: CAISafe - Computer Associates International, Inc. - C:\Program Files\CA\CA Internet Security Suite\CA Anti-Virus\ISafe.exe
O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: iPod Service - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: CA Pest Patrol Realtime Protection Service (ITMRTSVC) - CA, Inc. - C:\Program Files\CA\SharedComponents\PPRT\bin\ITMRTSVC.exe
O23 - Service: Pml Driver HPZ12 - HP - C:\WINDOWS\system32\HPZipm12.exe
O23 - Service: PPCtlPriv - CA, Inc. - C:\Program Files\CA\CA Internet Security Suite\CA Anti-Spyware\PPCtlPriv.exe
O23 - Service: PrismXL - New Boundary Technologies, Inc. - C:\Program Files\Common Files\New Boundary\PrismXL\PRISMXL.SYS
O23 - Service: HIPS Event Manager (UmxAgent) - CA - C:\Program Files\CA\SharedComponents\HIPSEngine\UmxAgent.exe
O23 - Service: HIPS Configuration Interpreter (UmxCfg) - CA - C:\Program Files\CA\SharedComponents\HIPSEngine\UmxCfg.exe
O23 - Service: HIPS Firewall Helper (UmxFwHlp) - CA - C:\Program Files\CA\SharedComponents\HIPSEngine\UmxFwHlp.exe
O23 - Service: HIPS Policy Manager (UmxPol) - CA - C:\Program Files\CA\SharedComponents\HIPSEngine\UmxPol.exe
O23 - Service: VET Message Service (VETMSGNT) - CA, Inc. - C:\Program Files\CA\CA Internet Security Suite\CA Anti-Virus\VetMsg.exe

–
End of file - 10534 bytes
Hi dejaylos,

This looks fine. We can clean up the tools you used and I'll give you some tips to keep clean.

From your desktop, please delete
  • RSIT.exe
  • look.zip
  • look.cmd
  • Lookresult.txt
Next, click the Start button, click Run. Copy and paste the following line into the run box and click OK
Combofix /u

Open OTMOVEIT3 then click the Clean Up button. You may get prompted by your firewall that OTMoveIt wants to contact the internet - allow this. A cleanup.txt will be downloaded, a message dialog will ask you if you want to proceed with the cleanup process, click Yes. This will delete all the tools you have downloaded plus itself.

In windows explorer, delete these
  • C:\Lookresult.txt
  • C:\RSIT
ESET online scanner can be removed via add/remove programs if you wish.

I suggest you keep ATF and MBAM. Keep MBAM updated and use it as an on demand scanner.

You have a program Exterminate IT, unless it's a paid for version, will not remove anything. If you wish, it can be uninstalled via add/remove programs.

Now that your system has been cleaned, we'll remove all old infected System Restore points.

Turn OFF System Restore.
  • On the Desktop, right-click My Computer.
  • Click Properties.
  • Click the System Restore tab.
  • Check Turn off System Restore.
  • Click Apply, and then click OK.
Restart your computer.

Turn ON System Restore.
  • On the Desktop, right-click My Computer.
  • Click Properties.
  • Click the System Restore tab.
  • UN-Check Turn off System Restore.
  • Click Apply, and then click OK.
System Restore will now be active again.

* Updates and Upgrades

You have old vulnerable java installed.
  • Go to http://java.sun.com/javase/downloads/index.jsp
  • Scroll down to "Java Runtime Environment (JRE) 6 Update 10…allows end-users to run Java applications".
  • Click the download button on the right.
If Information Bar pop-ups up, right-click on it and say it's OK to display the blocked content.
  • Select the platform (Windows, in your case), mutli language.
  • Accept the license agreement, click continue.
You do not have to install the Java Web Start ActiveX Control
  • Scroll down and click on Windows Offline Installation,
  • Save the file jre-6u10-windows-i586-p.exe to your desktop;
Do not select Run . Do not install it yet.

When the download is complete, close your browser.

Open Control Panel > Add/Remove Programs:
  • Uninstall the old versions of Sun Java, Java JRE, or similar.
  • Do not uninstall Java TM 6 Update 10 if found! :yeah:
Reboot your computer.

  • Double-click on the saved file to install the update.
  • Delete the downloaded installation file after completing the above procedure and reboot if not prompted to do so.

* If you are running Microsoft Office, or any portion thereof, go to the Microsoft's Office Update site and make sure you have at least all the cirtical updates installed (Free) Microsoft Office Update

Some Recommendations and prevention tips

You should also use Spyware Blaster to help immunize your computer.

- SpywareBlaster will add a large list of programs and sites into your Internet Explorer
settings that will protect you from running and downloading known malicious programs.

OR

A guide to understanding and using the hosts file.

Learn how your Hosts file can protect you and how you can protect it.
Besides the Hosts file information, there are links to a very good updated hosts file, a host file manager. and some programs that can protect your hosts file.
HOSTS

Please read the info on disabling the DNS Client before installing a custom hosts file.

-Secure your Internet Explorer

From within Internet Explorer click on the Tools menu and then click on Options.
  • Click once on the Security tab
  • Click once on the Internet icon so it becomes highlighted.
  • Click once on the Custom Level button.
  • Change the Download signed ActiveX controls to Prompt
  • Change the Download unsigned ActiveX controls to Disable
  • Change the Initialize and script ActiveX controls not marked as safe to Disable
  • Change the Installation of desktop items to Prompt
  • Change the Launching programs and files in an IFRAME to Prompt
  • Change the Navigate sub-frames across different domains to Prompt
When all these settings have been made, click on the OK button.

If it prompts you as to whether or not you want to save the settings, press the Yes button.

Next press the Apply button and then the OK to exit the Internet Properties page.

- Ensure that Automatic Update is turned on so you get all the latest patches.
Click start, control panel, click Security Center.

- Keep your antivirus program updated, as well as any other security programs you have.

- You may also want to read this article By Tony Klein
http://www.freedomlist.com/forum/viewtopic.php?t=22879

This thread will be keep open for a few days. If you have any problems, please post in this thread.

:adios:
Hey oldman, I just wanted to thank you in helping me. As Im sure you could tell, I have no clue about Pc's at all. So thank you once again for your assistance. :unsure: A question that I have for you is this, and forgive me for my ignorance in this area, but in your last post I have followed every step that you have directed me in, however, when you say I have a vulnarable java installed and to uninstall it in the add/remove programs I didnt see any javas in there, that said sun java, java JRE. The only thing I did see was J2SE Runtime environment 5.0. Is this it?? I already saved the new version to the desk top, but havent installed, and i didnt want to make any mistakes. Thanks again!!

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI