skullsuga
Topic Starter
TomK was helping me, but closed the topic this morning, which is fine. I've been getting killed at work for two weeks, and haven't had time to run the scans he requested.
previous topic is/was this - http://forums.whatthetech.com/slow_compute…ser_t99074.html -
requested scans in the last instruction post -
JavaRa log -
JavaRa 1.13 Removal Log.
Report follows after line.
————————————
The JavaRa removal process was started on Fri Feb 06 23:00:30 2009
Found and removed: C:\Program Files\Java\j2re1.4.2_01
Found and removed: C:\Program Files\Java\j2re1.4.2_03
Found and removed: C:\Program Files\Java\jre1.5.0_06
Found and removed: C:\Program Files\Java\jre1.5.0_07
Found and removed: C:\Windows\Installer\{7148F0A8-6813-11D6-A77B-00B0D0142010}
Found and removed: C:\Windows\Installer\{7148F0A8-6813-11D6-A77B-00B0D0142030}
Found and removed: SOFTWARE\JavaSoft\Java Runtime Environment\1.4
Found and removed: Software\JavaSoft\Java2D\1.5.0_07
Found and removed: SOFTWARE\Classes\CLSID\{CAFEEFAC-0015-0000-0006-ABCDEFFEDCBA}
Found and removed: SOFTWARE\Classes\CLSID\{CAFEEFAC-0015-0000-0007-ABCDEFFEDCBA}
Found and removed: SOFTWARE\Classes\Installer\Features\8A0F842331866D117AB7000B0D510006
Found and removed: SOFTWARE\Classes\Installer\Features\8A0F842331866D117AB7000B0D510007
Found and removed: SOFTWARE\Classes\Installer\Products\8A0F842331866D117AB7000B0D510006
Found and removed: SOFTWARE\Classes\Installer\Products\8A0F842331866D117AB7000B0D510007
Found and removed: SOFTWARE\Classes\Installer\UpgradeCodes\7A0F842331866D117AB7000B0D510006
Found and removed: SOFTWARE\Classes\Installer\UpgradeCodes\7A0F842331866D117AB7000B0D510007
Found and removed: SOFTWARE\Classes\JavaPlugin.150_06
Found and removed: SOFTWARE\Classes\JavaPlugin.150_07
Found and removed: SOFTWARE\Classes\JavaWebStart.isInstalled.1.5.0.0
Found and removed: SOFTWARE\JavaSoft\Java Plug-in\1.5.0_06
Found and removed: SOFTWARE\JavaSoft\Java Plug-in\1.5.0_07
Found and removed: SOFTWARE\JavaSoft\Java Runtime Environment\1.5
Found and removed: SOFTWARE\JavaSoft\Java Runtime Environment\1.5.0_06
Found and removed: SOFTWARE\JavaSoft\Java Runtime Environment\1.5.0_07
Found and removed: SOFTWARE\Microsoft\Code Store Database\Distribution Units\{CAFEEFAC-0015-0000-0006-ABCDEFFEDCBA}
Found and removed: SOFTWARE\Microsoft\Code Store Database\Distribution Units\{CAFEEFAC-0015-0000-0007-ABCDEFFEDCBA}
Found and removed: SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\ACBB9B2318A96D117A58000B0D510006
Found and removed: SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\ACBB9B2318A96D117A58000B0D510007
Found and removed: SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\8A0F842331866D117AB7000B0D510006
Found and removed: SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\8A0F842331866D117AB7000B0D510007
Found and removed: SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{3248F0A8-6813-11D6-A77B-00B0D0150060}
Found and removed: SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{3248F0A8-6813-11D6-A77B-00B0D0150070}
Found and removed: SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{7148F0A8-6813-11D6-A77B-00B0D0142010}
Found and removed: SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{7148F0A8-6813-11D6-A77B-00B0D0142030}
Found and removed: SOFTWARE\Classes\CLSID\{CAFEEFAC-0014-0002-0001-ABCDEFFEDCBA}
Found and removed: SOFTWARE\Classes\CLSID\{CAFEEFAC-0014-0002-0003-ABCDEFFEDCBA}
Found and removed: SOFTWARE\Classes\CLSID\{CAFEEFAC-0014-0002-0001-ABCDEFFEDCBB}
Found and removed: SOFTWARE\Classes\CLSID\{CAFEEFAC-0014-0002-0003-ABCDEFFEDCBB}
Found and removed: SOFTWARE\Classes\Installer\Products\8A0F841731866D117AB7000B0D410201
Found and removed: SOFTWARE\Classes\Installer\Products\8A0F841731866D117AB7000B0D410203
Found and removed: SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\8A0F841731866D117AB7000B0D410201
Found and removed: SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\8A0F841731866D117AB7000B0D410203
Found and removed: SOFTWARE\Classes\JavaPlugin.142_01
Found and removed: SOFTWARE\Classes\JavaPlugin.142_03
Found and removed: SOFTWARE\JavaSoft\Java Plug-in\1.4.2_01
Found and removed: SOFTWARE\JavaSoft\Java Plug-in\1.4.2_03
Found and removed: SOFTWARE\JavaSoft\Java Runtime Environment\1.4.2_01
Found and removed: SOFTWARE\JavaSoft\Java Runtime Environment\1.4.2_03
Found and removed: SOFTWARE\JavaSoft\Java Web Start\1.4.2_01
Found and removed: SOFTWARE\JavaSoft\Java Web Start\1.4.2_03
Found and removed: SOFTWARE\JavaSoft\Java Web Start\1.5.0_06
Found and removed: SOFTWARE\JavaSoft\Java Web Start\1.5.0_07
Found and removed: SOFTWARE\Microsoft\Code Store Database\Distribution Units\{CAFEEFAC-0014-0002-0001-ABCDEFFEDCBA}
Found and removed: SOFTWARE\Microsoft\Code Store Database\Distribution Units\{CAFEEFAC-0014-0002-0003-ABCDEFFEDCBA}
Found and removed: Software\Classes\JavaPlugin.142_01
Found and removed: Software\Classes\JavaPlugin.142_03
Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0000-0003-ABCDEFFEDCBA}
Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0000-0004-ABCDEFFEDCBA}
Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0000-0005-ABCDEFFEDCBA}
Found and removed: SOFTWARE\JavaSoft\Java Web Start\1.0.1
Found and removed: SOFTWARE\JavaSoft\Java Web Start\1.0.1_02
Found and removed: SOFTWARE\JavaSoft\Java Web Start\1.0.1_03
Found and removed: SOFTWARE\JavaSoft\Java Web Start\1.0.1_04
Found and removed: SOFTWARE\JavaSoft\Java Web Start\1.2
Found and removed: SOFTWARE\JavaSoft\Java Web Start\1.2.0_01
Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0000-ABCDEFFEDCBA}
Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0001-ABCDEFFEDCBA}
Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0001-ABCDEFFEDCBB}
Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0002-ABCDEFFEDCBA}
Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0002-ABCDEFFEDCBB}
Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0003-ABCDEFFEDCBA}
Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0003-ABCDEFFEDCBB}
Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0004-ABCDEFFEDCBA}
Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0004-ABCDEFFEDCBB}
Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0005-ABCDEFFEDCBA}
Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0005-ABCDEFFEDCBB}
Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0006-ABCDEFFEDCBA}
Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0006-ABCDEFFEDCBB}
Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0007-ABCDEFFEDCBA}
Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0007-ABCDEFFEDCBB}
Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0008-ABCDEFFEDCBA}
Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0008-ABCDEFFEDCBB}
Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0009-ABCDEFFEDCBA}
Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0009-ABCDEFFEDCBB}
Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0010-ABCDEFFEDCBA}
Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0010-ABCDEFFEDCBB}
Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0011-ABCDEFFEDCBA}
Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0011-ABCDEFFEDCBB}
Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0012-ABCDEFFEDCBA}
Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0012-ABCDEFFEDCBB}
Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0013-ABCDEFFEDCBA}
Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0013-ABCDEFFEDCBB}
Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0014-ABCDEFFEDCBA}
Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0014-ABCDEFFEDCBB}
Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0015-ABCDEFFEDCBA}
Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0015-ABCDEFFEDCBB}
Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0016-ABCDEFFEDCBA}
Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0016-ABCDEFFEDCBB}
Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0017-ABCDEFFEDCBA}
Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0017-ABCDEFFEDCBB}
Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0018-ABCDEFFEDCBA}
Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0018-ABCDEFFEDCBB}
Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0019-ABCDEFFEDCBA}
Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0019-ABCDEFFEDCBB}
Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0020-ABCDEFFEDCBA}
Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0020-ABCDEFFEDCBB}
Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0021-ABCDEFFEDCBA}
Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0021-ABCDEFFEDCBB}
Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0022-ABCDEFFEDCBA}
Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0022-ABCDEFFEDCBB}
Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0023-ABCDEFFEDCBA}
Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0023-ABCDEFFEDCBB}
Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0024-ABCDEFFEDCBA}
Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0024-ABCDEFFEDCBB}
Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0025-ABCDEFFEDCBA}
Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0025-ABCDEFFEDCBB}
Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0026-ABCDEFFEDCBA}
Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0026-ABCDEFFEDCBB}
Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0027-ABCDEFFEDCBA}
Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0027-ABCDEFFEDCBB}
Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0028-ABCDEFFEDCBA}
Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0028-ABCDEFFEDCBB}
Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0029-ABCDEFFEDCBA}
Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0029-ABCDEFFEDCBB}
Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0030-ABCDEFFEDCBA}
Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0030-ABCDEFFEDCBB}
Found and removed: SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\Folders\\C:\Program Files\Common Files\Java\Update\Base Images\jre1.5.0.b64\
Found and removed: SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\Folders\\C:\Program Files\Java\jre1.5.0_06\
Found and removed: SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\Folders\\C:\Program Files\Java\jre1.5.0_07\
Found and removed: SOFTWARE\Microsoft\Windows\CurrentVersion\SharedDlls\C:\Program Files\Common Files\Java\Update\Base Images\jre1.5.0.b64\core1.zip
Found and removed: SOFTWARE\Microsoft\Windows\CurrentVersion\SharedDlls\C:\Program Files\Common Files\Java\Update\Base Images\jre1.5.0.b64\core2.zip
Found and removed: SOFTWARE\Microsoft\Windows\CurrentVersion\SharedDlls\C:\Program Files\Common Files\Java\Update\Base Images\jre1.5.0.b64\core3.zip
————————————
Finished reporting.
ComboFix log -
ComboFix 09-02-06.01 - Andy 2009-02-06 23:04:43.2 - NTFSx86
Microsoft Windows XP Professional 5.1.2600.2.1252.1.1033.18.3071.2515 [GMT -5:00]
Running from: c:\documents and settings\[removed]\Desktop\ComboFix.exe
Command switches used :: c:\documents and settings\Andy\Desktop\CFScript.txt
FW: Trend Micro OfficeScan Enterprise Client Firewall *disabled*
* Created a new restore point
FILE ::
c:\docume~1\Jessica\LOCALS~1\Temp\asbp2poa.sys
f:\documents and settings\Andrew\Desktop\Old C drive\WINDOWS\Desktop\laptop.zip
f:\documents and settings\Andrew\Desktop\Old C drive\WINDOWS\Desktop\old folder folder\old hdd\signage\eds labels\Pfeifferlabel.jpg
f:\old c drive\WINDOWS\Desktop\laptop.zip
f:\old c drive\WINDOWS\Desktop\old folder folder\old hdd\signage\eds labels\Pfeifferlabel.jpg
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
c:\documents and settings\Jessica\Application Data\Sun\Java\Deployment\cache\javapi\v1.0
c:\documents and settings\Jessica\Application Data\Sun\Java\Deployment\cache\javapi\v1.0\file\2galaxy.jpg-647ce554-2102c78d.idx
c:\documents and settings\Jessica\Application Data\Sun\Java\Deployment\cache\javapi\v1.0\file\2galaxy.jpg-647ce554-2102c78d.jpg
c:\documents and settings\Jessica\Application Data\Sun\Java\Deployment\cache\javapi\v1.0\file\2sam.jpg-20a1d3af-15547c87.idx
c:\documents and settings\Jessica\Application Data\Sun\Java\Deployment\cache\javapi\v1.0\file\2sam.jpg-20a1d3af-15547c87.jpg
c:\documents and settings\Jessica\Application Data\Sun\Java\Deployment\cache\javapi\v1.0\file\a_ws_theme_2.au-13d1aae-759c6000.au
c:\documents and settings\Jessica\Application Data\Sun\Java\Deployment\cache\javapi\v1.0\file\a_ws_theme_2.au-13d1aae-759c6000.idx
c:\documents and settings\Jessica\Application Data\Sun\Java\Deployment\cache\javapi\v1.0\file\applet.gif-1074eacd-481cfce6.gif
c:\documents and settings\Jessica\Application Data\Sun\Java\Deployment\cache\javapi\v1.0\file\applet.gif-1074eacd-481cfce6.idx
c:\documents and settings\Jessica\Application Data\Sun\Java\Deployment\cache\javapi\v1.0\file\apXPDropDown.class-35d6b28c-2f342c6f.class
c:\documents and settings\Jessica\Application Data\Sun\Java\Deployment\cache\javapi\v1.0\file\apXPDropDown.class-35d6b28c-2f342c6f.idx
c:\documents and settings\Jessica\Application Data\Sun\Java\Deployment\cache\javapi\v1.0\file\ARROW.AU-1efbb99-69b0c4d9.AU
c:\documents and settings\Jessica\Application Data\Sun\Java\Deployment\cache\javapi\v1.0\file\ARROW.AU-1efbb99-69b0c4d9.idx
c:\documents and settings\Jessica\Application Data\Sun\Java\Deployment\cache\javapi\v1.0\file\audioplayer.class-21de4a59-5642f114.class
c:\documents and settings\Jessica\Application Data\Sun\Java\Deployment\cache\javapi\v1.0\file\audioplayer.class-21de4a59-5642f114.idx
c:\documents and settings\Jessica\Application Data\Sun\Java\Deployment\cache\javapi\v1.0\file\audiopreloader.class-35af017a-106c44d5.class
c:\documents and settings\Jessica\Application Data\Sun\Java\Deployment\cache\javapi\v1.0\file\audiopreloader.class-35af017a-106c44d5.idx
c:\documents and settings\Jessica\Application Data\Sun\Java\Deployment\cache\javapi\v1.0\file\bien-2.au-53b41fd3-7a7b7884.au
c:\documents and settings\Jessica\Application Data\Sun\Java\Deployment\cache\javapi\v1.0\file\bien-2.au-53b41fd3-7a7b7884.idx
c:\documents and settings\Jessica\Application Data\Sun\Java\Deployment\cache\javapi\v1.0\file\bien-3.au-53b49432-6152f879.au
c:\documents and settings\Jessica\Application Data\Sun\Java\Deployment\cache\javapi\v1.0\file\bien-3.au-53b49432-6152f879.idx
c:\documents and settings\Jessica\Application Data\Sun\Java\Deployment\cache\javapi\v1.0\file\bien-4.au-53b50891-56bc7b43.au
c:\documents and settings\Jessica\Application Data\Sun\Java\Deployment\cache\javapi\v1.0\file\bien-4.au-53b50891-56bc7b43.idx
c:\documents and settings\Jessica\Application Data\Sun\Java\Deployment\cache\javapi\v1.0\file\click-3.au-388dd7b5-54380161.au
c:\documents and settings\Jessica\Application Data\Sun\Java\Deployment\cache\javapi\v1.0\file\click-3.au-388dd7b5-54380161.idx
c:\documents and settings\Jessica\Application Data\Sun\Java\Deployment\cache\javapi\v1.0\file\clrbook.gif-495dfc90-6f4551a7.gif
c:\documents and settings\Jessica\Application Data\Sun\Java\Deployment\cache\javapi\v1.0\file\clrbook.gif-495dfc90-6f4551a7.idx
c:\documents and settings\Jessica\Application Data\Sun\Java\Deployment\cache\javapi\v1.0\file\color_friends.gif-69c9023a-6afeb2a9.gif
c:\documents and settings\Jessica\Application Data\Sun\Java\Deployment\cache\javapi\v1.0\file\color_friends.gif-69c9023a-6afeb2a9.idx
c:\documents and settings\Jessica\Application Data\Sun\Java\Deployment\cache\javapi\v1.0\file\color_jorge.gif-2b41a1d0-55b9a0d4.gif
c:\documents and settings\Jessica\Application Data\Sun\Java\Deployment\cache\javapi\v1.0\file\color_jorge.gif-2b41a1d0-55b9a0d4.idx
c:\documents and settings\Jessica\Application Data\Sun\Java\Deployment\cache\javapi\v1.0\file\color_puppy.gif-3acc4639-27457b2d.gif
c:\documents and settings\Jessica\Application Data\Sun\Java\Deployment\cache\javapi\v1.0\file\color_puppy.gif-3acc4639-27457b2d.idx
c:\documents and settings\Jessica\Application Data\Sun\Java\Deployment\cache\javapi\v1.0\file\count.au-7cc44774-21adfba0.au
c:\documents and settings\Jessica\Application Data\Sun\Java\Deployment\cache\javapi\v1.0\file\count.au-7cc44774-21adfba0.idx
c:\documents and settings\Jessica\Application Data\Sun\Java\Deployment\cache\javapi\v1.0\file\earth.jpg-6be9dddc-43a1a5e4.idx
c:\documents and settings\Jessica\Application Data\Sun\Java\Deployment\cache\javapi\v1.0\file\earth.jpg-6be9dddc-43a1a5e4.jpg
c:\documents and settings\Jessica\Application Data\Sun\Java\Deployment\cache\javapi\v1.0\file\entryway_450.jpg-f78ec34-7c5821c2.idx
c:\documents and settings\Jessica\Application Data\Sun\Java\Deployment\cache\javapi\v1.0\file\entryway_450.jpg-f78ec34-7c5821c2.jpg
c:\documents and settings\Jessica\Application Data\Sun\Java\Deployment\cache\javapi\v1.0\file\esquela.au-706d4a1c-1b517d4d.au
c:\documents and settings\Jessica\Application Data\Sun\Java\Deployment\cache\javapi\v1.0\file\esquela.au-706d4a1c-1b517d4d.idx
c:\documents and settings\Jessica\Application Data\Sun\Java\Deployment\cache\javapi\v1.0\file\finish-3.au-d8cc390-2ea71c66.au
c:\documents and settings\Jessica\Application Data\Sun\Java\Deployment\cache\javapi\v1.0\file\finish-3.au-d8cc390-2ea71c66.idx
c:\documents and settings\Jessica\Application Data\Sun\Java\Deployment\cache\javapi\v1.0\file\getDoubles.class-3727b7fc-767abb9a.class
c:\documents and settings\Jessica\Application Data\Sun\Java\Deployment\cache\javapi\v1.0\file\getDoubles.class-3727b7fc-767abb9a.idx
c:\documents and settings\Jessica\Application Data\Sun\Java\Deployment\cache\javapi\v1.0\file\hola-4.au-18b34e85-359bfccd.au
c:\documents and settings\Jessica\Application Data\Sun\Java\Deployment\cache\javapi\v1.0\file\hola-4.au-18b34e85-359bfccd.idx
c:\documents and settings\Jessica\Application Data\Sun\Java\Deployment\cache\javapi\v1.0\file\hola-5.au-18b3c2e4-7bd52bf7.au
c:\documents and settings\Jessica\Application Data\Sun\Java\Deployment\cache\javapi\v1.0\file\hola-5.au-18b3c2e4-7bd52bf7.idx
c:\documents and settings\Jessica\Application Data\Sun\Java\Deployment\cache\javapi\v1.0\file\hola-6.au-18b43743-448ae503.au
c:\documents and settings\Jessica\Application Data\Sun\Java\Deployment\cache\javapi\v1.0\file\hola-6.au-18b43743-448ae503.idx
c:\documents and settings\Jessica\Application Data\Sun\Java\Deployment\cache\javapi\v1.0\file\Honor.gif-5e314986-2de5371c.gif
c:\documents and settings\Jessica\Application Data\Sun\Java\Deployment\cache\javapi\v1.0\file\Honor.gif-5e314986-2de5371c.idx
c:\documents and settings\Jessica\Application Data\Sun\Java\Deployment\cache\javapi\v1.0\file\jumpstrp.gif-568c3105-1d2e9201.gif
c:\documents and settings\Jessica\Application Data\Sun\Java\Deployment\cache\javapi\v1.0\file\jumpstrp.gif-568c3105-1d2e9201.idx
c:\documents and settings\Jessica\Application Data\Sun\Java\Deployment\cache\javapi\v1.0\file\JVMDetect.class-71e1c178-2368d752.class
c:\documents and settings\Jessica\Application Data\Sun\Java\Deployment\cache\javapi\v1.0\file\JVMDetect.class-71e1c178-2368d752.idx
c:\documents and settings\Jessica\Application Data\Sun\Java\Deployment\cache\javapi\v1.0\file\kitchen1_450.jpg-5788a404-19fb755e.idx
c:\documents and settings\Jessica\Application Data\Sun\Java\Deployment\cache\javapi\v1.0\file\kitchen1_450.jpg-5788a404-19fb755e.jpg
c:\documents and settings\Jessica\Application Data\Sun\Java\Deployment\cache\javapi\v1.0\file\labor.au-5adbdf89-59c57a88.au
c:\documents and settings\Jessica\Application Data\Sun\Java\Deployment\cache\javapi\v1.0\file\labor.au-5adbdf89-59c57a88.idx
c:\documents and settings\Jessica\Application Data\Sun\Java\Deployment\cache\javapi\v1.0\file\livingroom1_450.jpg-26ea5021-4be85370.idx
c:\documents and settings\Jessica\Application Data\Sun\Java\Deployment\cache\javapi\v1.0\file\livingroom1_450.jpg-26ea5021-4be85370.jpg
c:\documents and settings\Jessica\Application Data\Sun\Java\Deployment\cache\javapi\v1.0\file\livingroom1_450.jpg-3cee146a-1a5025fd.idx
c:\documents and settings\Jessica\Application Data\Sun\Java\Deployment\cache\javapi\v1.0\file\livingroom1_450.jpg-3cee146a-1a5025fd.jpg
c:\documents and settings\Jessica\Application Data\Sun\Java\Deployment\cache\javapi\v1.0\file\LoadingPano.gif-4154700e-4320c640.gif
c:\documents and settings\Jessica\Application Data\Sun\Java\Deployment\cache\javapi\v1.0\file\LoadingPano.gif-4154700e-4320c640.idx
c:\documents and settings\Jessica\Application Data\Sun\Java\Deployment\cache\javapi\v1.0\file\look-schoolyard.au-36c29308-6a1e64d4.au
c:\documents and settings\Jessica\Application Data\Sun\Java\Deployment\cache\javapi\v1.0\file\look-schoolyard.au-36c29308-6a1e64d4.idx
c:\documents and settings\Jessica\Application Data\Sun\Java\Deployment\cache\javapi\v1.0\file\masterbedroom1_450.jpg-2ad94e6e-5ee619f3.idx
c:\documents and settings\Jessica\Application Data\Sun\Java\Deployment\cache\javapi\v1.0\file\masterbedroom1_450.jpg-2ad94e6e-5ee619f3.jpg
c:\documents and settings\Jessica\Application Data\Sun\Java\Deployment\cache\javapi\v1.0\file\MENUSEL.AU-5cb8a129-311d9524.AU
c:\documents and settings\Jessica\Application Data\Sun\Java\Deployment\cache\javapi\v1.0\file\MENUSEL.AU-5cb8a129-311d9524.idx
c:\documents and settings\Jessica\Application Data\Sun\Java\Deployment\cache\javapi\v1.0\file\MultiAudioClipPlayer.class-3d2a0e1f-2b0d8872.class
c:\documents and settings\Jessica\Application Data\Sun\Java\Deployment\cache\javapi\v1.0\file\MultiAudioClipPlayer.class-3d2a0e1f-2b0d8872.idx
c:\documents and settings\Jessica\Application Data\Sun\Java\Deployment\cache\javapi\v1.0\file\MultiAudioClipPlayer.class-8329380-47e3895a.class
c:\documents and settings\Jessica\Application Data\Sun\Java\Deployment\cache\javapi\v1.0\file\MultiAudioClipPlayer.class-8329380-47e3895a.idx
c:\documents and settings\Jessica\Application Data\Sun\Java\Deployment\cache\javapi\v1.0\file\newsflash.class-482b776a-338f826b.class
c:\documents and settings\Jessica\Application Data\Sun\Java\Deployment\cache\javapi\v1.0\file\newsflash.class-482b776a-338f826b.idx
c:\documents and settings\Jessica\Application Data\Sun\Java\Deployment\cache\javapi\v1.0\file\nextgame.gif-206554fb-5cf76fe6.gif
c:\documents and settings\Jessica\Application Data\Sun\Java\Deployment\cache\javapi\v1.0\file\nextgame.gif-206554fb-5cf76fe6.idx
c:\documents and settings\Jessica\Application Data\Sun\Java\Deployment\cache\javapi\v1.0\file\nextgame.gif-227974dd-2be4fe4c.gif
c:\documents and settings\Jessica\Application Data\Sun\Java\Deployment\cache\javapi\v1.0\file\nextgame.gif-227974dd-2be4fe4c.idx
c:\documents and settings\Jessica\Application Data\Sun\Java\Deployment\cache\javapi\v1.0\file\nina.au-75f1bdda-1a324153.au
c:\documents and settings\Jessica\Application Data\Sun\Java\Deployment\cache\javapi\v1.0\file\nina.au-75f1bdda-1a324153.idx
c:\documents and settings\Jessica\Application Data\Sun\Java\Deployment\cache\javapi\v1.0\file\no.au-41fb4067-4db569ad.au
c:\documents and settings\Jessica\Application Data\Sun\Java\Deployment\cache\javapi\v1.0\file\no.au-41fb4067-4db569ad.idx
c:\documents and settings\Jessica\Application Data\Sun\Java\Deployment\cache\javapi\v1.0\file\number-1.au-692f4ddc-1aaa28d5.au
c:\documents and settings\Jessica\Application Data\Sun\Java\Deployment\cache\javapi\v1.0\file\number-1.au-692f4ddc-1aaa28d5.idx
c:\documents and settings\Jessica\Application Data\Sun\Java\Deployment\cache\javapi\v1.0\file\number-2.au-692fc23b-47d56764.au
c:\documents and settings\Jessica\Application Data\Sun\Java\Deployment\cache\javapi\v1.0\file\number-2.au-692fc23b-47d56764.idx
c:\documents and settings\Jessica\Application Data\Sun\Java\Deployment\cache\javapi\v1.0\file\number-3.au-6930369a-3bdb297c.au
c:\documents and settings\Jessica\Application Data\Sun\Java\Deployment\cache\javapi\v1.0\file\number-3.au-6930369a-3bdb297c.idx
c:\documents and settings\Jessica\Application Data\Sun\Java\Deployment\cache\javapi\v1.0\file\numberofday.au-454202e7-643e7c74.au
c:\documents and settings\Jessica\Application Data\Sun\Java\Deployment\cache\javapi\v1.0\file\numberofday.au-454202e7-643e7c74.idx
c:\documents and settings\Jessica\Application Data\Sun\Java\Deployment\cache\javapi\v1.0\file\organ.au-61674f32-675f1133.au
c:\documents and settings\Jessica\Application Data\Sun\Java\Deployment\cache\javapi\v1.0\file\organ.au-61674f32-675f1133.idx
c:\documents and settings\Jessica\Application Data\Sun\Java\Deployment\cache\javapi\v1.0\file\paint01c.gif-522c957a-49efb17a.gif
c:\documents and settings\Jessica\Application Data\Sun\Java\Deployment\cache\javapi\v1.0\file\paint01c.gif-522c957a-49efb17a.idx
c:\documents and settings\Jessica\Application Data\Sun\Java\Deployment\cache\javapi\v1.0\file\paintbox.class-42113c78-7b3f82e6.class
c:\documents and settings\Jessica\Application Data\Sun\Java\Deployment\cache\javapi\v1.0\file\paintbox.class-42113c78-7b3f82e6.idx
c:\documents and settings\Jessica\Application Data\Sun\Java\Deployment\cache\javapi\v1.0\file\palcup.gif-90fb59-573be683.gif
c:\documents and settings\Jessica\Application Data\Sun\Java\Deployment\cache\javapi\v1.0\file\palcup.gif-90fb59-573be683.idx
c:\documents and settings\Jessica\Application Data\Sun\Java\Deployment\cache\javapi\v1.0\file\pano1.jpg-22f2f56d-29d47ba7.idx
c:\documents and settings\Jessica\Application Data\Sun\Java\Deployment\cache\javapi\v1.0\file\pano1.jpg-22f2f56d-29d47ba7.jpg
c:\documents and settings\Jessica\Application Data\Sun\Java\Deployment\cache\javapi\v1.0\file\pano2.jpg-23010cee-3d060f10.idx
c:\documents and settings\Jessica\Application Data\Sun\Java\Deployment\cache\javapi\v1.0\file\pano2.jpg-23010cee-3d060f10.jpg
c:\documents and settings\Jessica\Application Data\Sun\Java\Deployment\cache\javapi\v1.0\file\pano3.jpg-230f246f-714f7d22.idx
c:\documents and settings\Jessica\Application Data\Sun\Java\Deployment\cache\javapi\v1.0\file\pano3.jpg-230f246f-714f7d22.jpg
c:\documents and settings\Jessica\Application Data\Sun\Java\Deployment\cache\javapi\v1.0\file\panohead.jpg-7a79bc1e-326a1ab8.idx
c:\documents and settings\Jessica\Application Data\Sun\Java\Deployment\cache\javapi\v1.0\file\panohead.jpg-7a79bc1e-326a1ab8.jpg
c:\documents and settings\Jessica\Application Data\Sun\Java\Deployment\cache\javapi\v1.0\file\payoff-3.au-574d54dc-48325748.au
c:\documents and settings\Jessica\Application Data\Sun\Java\Deployment\cache\javapi\v1.0\file\payoff-3.au-574d54dc-48325748.idx
c:\documents and settings\Jessica\Application Data\Sun\Java\Deployment\cache\javapi\v1.0\file\payoff.au-5e5752b8-2cefcb7b.au
c:\documents and settings\Jessica\Application Data\Sun\Java\Deployment\cache\javapi\v1.0\file\payoff.au-5e5752b8-2cefcb7b.idx
c:\documents and settings\Jessica\Application Data\Sun\Java\Deployment\cache\javapi\v1.0\file\pdr-tlogo.gif-d3b9ebe-401d4468.gif
c:\documents and settings\Jessica\Application Data\Sun\Java\Deployment\cache\javapi\v1.0\file\pdr-tlogo.gif-d3b9ebe-401d4468.idx
c:\documents and settings\Jessica\Application Data\Sun\Java\Deployment\cache\javapi\v1.0\file\PERC.AU-144cef64-46c8e381.AU
c:\documents and settings\Jessica\Application Data\Sun\Java\Deployment\cache\javapi\v1.0\file\PERC.AU-144cef64-46c8e381.idx
c:\documents and settings\Jessica\Application Data\Sun\Java\Deployment\cache\javapi\v1.0\file\play-1.au-6641a5f0-288af849.au
c:\documents and settings\Jessica\Application Data\Sun\Java\Deployment\cache\javapi\v1.0\file\play-1.au-6641a5f0-288af849.idx
c:\documents and settings\Jessica\Application Data\Sun\Java\Deployment\cache\javapi\v1.0\file\play-2.au-66421a4f-534a8f7a.au
c:\documents and settings\Jessica\Application Data\Sun\Java\Deployment\cache\javapi\v1.0\file\play-2.au-66421a4f-534a8f7a.idx
c:\documents and settings\Jessica\Application Data\Sun\Java\Deployment\cache\javapi\v1.0\file\play-3.au-66428eae-228d1a60.au
c:\documents and settings\Jessica\Application Data\Sun\Java\Deployment\cache\javapi\v1.0\file\play-3.au-66428eae-228d1a60.idx
c:\documents and settings\Jessica\Application Data\Sun\Java\Deployment\cache\javapi\v1.0\file\PlayFour.class-10b4be2c-1728af65.class
c:\documents and settings\Jessica\Application Data\Sun\Java\Deployment\cache\javapi\v1.0\file\PlayFour.class-10b4be2c-1728af65.idx
c:\documents and settings\Jessica\Application Data\Sun\Java\Deployment\cache\javapi\v1.0\file\pots.gif-4e49f9d4-18c0b39a.gif
c:\documents and settings\Jessica\Application Data\Sun\Java\Deployment\cache\javapi\v1.0\file\pots.gif-4e49f9d4-18c0b39a.idx
c:\documents and settings\Jessica\Application Data\Sun\Java\Deployment\cache\javapi\v1.0\file\RESET.AU-39594493-7253c211.AU
c:\documents and settings\Jessica\Application Data\Sun\Java\Deployment\cache\javapi\v1.0\file\RESET.AU-39594493-7253c211.idx
c:\documents and settings\Jessica\Application Data\Sun\Java\Deployment\cache\javapi\v1.0\file\right.au-65c30253-22de09ff.au
c:\documents and settings\Jessica\Application Data\Sun\Java\Deployment\cache\javapi\v1.0\file\right.au-65c30253-22de09ff.idx
c:\documents and settings\Jessica\Application Data\Sun\Java\Deployment\cache\javapi\v1.0\file\right.au-67be7511-47564268.au
c:\documents and settings\Jessica\Application Data\Sun\Java\Deployment\cache\javapi\v1.0\file\right.au-67be7511-47564268.idx
c:\documents and settings\Jessica\Application Data\Sun\Java\Deployment\cache\javapi\v1.0\file\ring.gif-55c0c246-4127abc5.gif
c:\documents and settings\Jessica\Application Data\Sun\Java\Deployment\cache\javapi\v1.0\file\ring.gif-55c0c246-4127abc5.idx
c:\documents and settings\Jessica\Application Data\Sun\Java\Deployment\cache\javapi\v1.0\file\skip2.gif-7bd5d76f-4009de1d.gif
c:\documents and settings\Jessica\Application Data\Sun\Java\Deployment\cache\javapi\v1.0\file\skip2.gif-7bd5d76f-4009de1d.idx
c:\documents and settings\Jessica\Application Data\Sun\Java\Deployment\cache\javapi\v1.0\file\sol.au-78745e94-5eed3346.au
c:\documents and settings\Jessica\Application Data\Sun\Java\Deployment\cache\javapi\v1.0\file\sol.au-78745e94-5eed3346.idx
c:\documents and settings\Jessica\Application Data\Sun\Java\Deployment\cache\javapi\v1.0\file\SQUISH.AU-47a30a63-484b397a.AU
c:\documents and settings\Jessica\Application Data\Sun\Java\Deployment\cache\javapi\v1.0\file\SQUISH.AU-47a30a63-484b397a.idx
c:\documents and settings\Jessica\Application Data\Sun\Java\Deployment\cache\javapi\v1.0\file\STOP.AU-239fefa6-515972fd.AU
c:\documents and settings\Jessica\Application Data\Sun\Java\Deployment\cache\javapi\v1.0\file\STOP.AU-239fefa6-515972fd.idx
c:\documents and settings\Jessica\Application Data\Sun\Java\Deployment\cache\javapi\v1.0\file\STOP.AU-4c73f4c8-39025284.AU
c:\documents and settings\Jessica\Application Data\Sun\Java\Deployment\cache\javapi\v1.0\file\STOP.AU-4c73f4c8-39025284.idx
c:\documents and settings\Jessica\Application Data\Sun\Java\Deployment\cache\javapi\v1.0\file\strip0.gif-190c011e-144f6745.gif
c:\documents and settings\Jessica\Application Data\Sun\Java\Deployment\cache\javapi\v1.0\file\strip0.gif-190c011e-144f6745.idx
c:\documents and settings\Jessica\Application Data\Sun\Java\Deployment\cache\javapi\v1.0\file\strip1.gif-191a189f-119fea0f.gif
c:\documents and settings\Jessica\Application Data\Sun\Java\Deployment\cache\javapi\v1.0\file\strip1.gif-191a189f-119fea0f.idx
c:\documents and settings\Jessica\Application Data\Sun\Java\Deployment\cache\javapi\v1.0\file\strip2.gif-19283020-3954693c.gif
c:\documents and settings\Jessica\Application Data\Sun\Java\Deployment\cache\javapi\v1.0\file\strip2.gif-19283020-3954693c.idx
c:\documents and settings\Jessica\Application Data\Sun\Java\Deployment\cache\javapi\v1.0\file\strip3.gif-193647a1-74ad6391.gif
c:\documents and settings\Jessica\Application Data\Sun\Java\Deployment\cache\javapi\v1.0\file\strip3.gif-193647a1-74ad6391.idx
c:\documents and settings\Jessica\Application Data\Sun\Java\Deployment\cache\javapi\v1.0\file\sun.jpg-409eccde-2edefd31.idx
c:\documents and settings\Jessica\Application Data\Sun\Java\Deployment\cache\javapi\v1.0\file\sun.jpg-409eccde-2edefd31.jpg
c:\documents and settings\Jessica\Application Data\Sun\Java\Deployment\cache\javapi\v1.0\file\thunder.au-3c0f203f-23b674e9.au
c:\documents and settings\Jessica\Application Data\Sun\Java\Deployment\cache\javapi\v1.0\file\thunder.au-3c0f203f-23b674e9.idx
c:\documents and settings\Jessica\Application Data\Sun\Java\Deployment\cache\javapi\v1.0\file\tiger.jpg-7c0573d1-111d8cdd.idx
c:\documents and settings\Jessica\Application Data\Sun\Java\Deployment\cache\javapi\v1.0\file\tiger.jpg-7c0573d1-111d8cdd.jpg
c:\documents and settings\Jessica\Application Data\Sun\Java\Deployment\cache\javapi\v1.0\file\TinyAudioPlayer.class-13f0595e-7b3af7b2.class
c:\documents and settings\Jessica\Application Data\Sun\Java\Deployment\cache\javapi\v1.0\file\TinyAudioPlayer.class-13f0595e-7b3af7b2.idx
c:\documents and settings\Jessica\Application Data\Sun\Java\Deployment\cache\javapi\v1.0\file\tocountthem.au-2297f393-33c83475.au
c:\documents and settings\Jessica\Application Data\Sun\Java\Deployment\cache\javapi\v1.0\file\tocountthem.au-2297f393-33c83475.idx
c:\documents and settings\Jessica\Application Data\Sun\Java\Deployment\cache\javapi\v1.0\file\topback.gif-a74798-414eed41.gif
c:\documents and settings\Jessica\Application Data\Sun\Java\Deployment\cache\javapi\v1.0\file\topback.gif-a74798-414eed41.idx
c:\documents and settings\Jessica\Application Data\Sun\Java\Deployment\cache\javapi\v1.0\file\TotRwdPieChart.class-5e53fa88-14239f03.class
c:\documents and settings\Jessica\Application Data\Sun\Java\Deployment\cache\javapi\v1.0\file\TotRwdPieChart.class-5e53fa88-14239f03.idx
c:\documents and settings\Jessica\Application Data\Sun\Java\Deployment\cache\javapi\v1.0\file\turn.au-23a45b00-52b586db.au
c:\documents and settings\Jessica\Application Data\Sun\Java\Deployment\cache\javapi\v1.0\file\turn.au-23a45b00-52b586db.idx
c:\documents and settings\Jessica\Application Data\Sun\Java\Deployment\cache\javapi\v1.0\file\ULTRA%20DeepFields.jpg-51dbfbfe-6ad883b2.idx
c:\documents and settings\Jessica\Application Data\Sun\Java\Deployment\cache\javapi\v1.0\file\ULTRA%20DeepFields.jpg-51dbfbfe-6ad883b2.jpg
c:\documents and settings\Jessica\Application Data\Sun\Java\Deployment\cache\javapi\v1.0\file\v51.class-66fadd81-2a11d97d.class
c:\documents and settings\Jessica\Application Data\Sun\Java\Deployment\cache\javapi\v1.0\file\v51.class-66fadd81-2a11d97d.idx
c:\documents and settings\Jessica\Application Data\Sun\Java\Deployment\cache\javapi\v1.0\file\v51Sleep.class-7e9ad752-3f8a5869.class
c:\documents and settings\Jessica\Application Data\Sun\Java\Deployment\cache\javapi\v1.0\file\v51Sleep.class-7e9ad752-3f8a5869.idx
c:\documents and settings\Jessica\Application Data\Sun\Java\Deployment\cache\javapi\v1.0\file\woolly.jpg-306fdfc4-213a95cc.idx
c:\documents and settings\Jessica\Application Data\Sun\Java\Deployment\cache\javapi\v1.0\file\woolly.jpg-306fdfc4-213a95cc.jpg
c:\documents and settings\Jessica\Application Data\Sun\Java\Deployment\cache\javapi\v1.0\file\WRNGPLC.AU-3ebac4cf-7851578c.AU
c:\documents and settings\Jessica\Application Data\Sun\Java\Deployment\cache\javapi\v1.0\file\WRNGPLC.AU-3ebac4cf-7851578c.idx
c:\documents and settings\Jessica\Application Data\Sun\Java\Deployment\cache\javapi\v1.0\file\wrong.au-57366122-4691a1fc.au
c:\documents and settings\Jessica\Application Data\Sun\Java\Deployment\cache\javapi\v1.0\file\wrong.au-57366122-4691a1fc.idx
c:\documents and settings\Jessica\Application Data\Sun\Java\Deployment\cache\javapi\v1.0\file\wrong.au-5931d3e0-5907970a.au
c:\documents and settings\Jessica\Application Data\Sun\Java\Deployment\cache\javapi\v1.0\file\wrong.au-5931d3e0-5907970a.idx
c:\documents and settings\Jessica\Application Data\Sun\Java\Deployment\cache\javapi\v1.0\jar\ColoringBook.zip-f16ee8e-312265a6.idx
c:\documents and settings\Jessica\Application Data\Sun\Java\Deployment\cache\javapi\v1.0\jar\ColoringBook.zip-f16ee8e-312265a6.zip
c:\documents and settings\Jessica\Application Data\Sun\Java\Deployment\cache\javapi\v1.0\jar\cryptojN.jar-187ce279-7fa66dd0.idx
c:\documents and settings\Jessica\Application Data\Sun\Java\Deployment\cache\javapi\v1.0\jar\cryptojN.jar-187ce279-7fa66dd0.zip
c:\documents and settings\Jessica\Application Data\Sun\Java\Deployment\cache\javapi\v1.0\jar\DuriusWaterPic.jar-6f87cc62-6796c951.idx
c:\documents and settings\Jessica\Application Data\Sun\Java\Deployment\cache\javapi\v1.0\jar\DuriusWaterPic.jar-6f87cc62-6796c951.zip
c:\documents and settings\Jessica\Application Data\Sun\Java\Deployment\cache\javapi\v1.0\jar\elmo.jar-3009a466-2aff9083.idx
c:\documents and settings\Jessica\Application Data\Sun\Java\Deployment\cache\javapi\v1.0\jar\elmo.jar-3009a466-2aff9083.zip
c:\documents and settings\Jessica\Application Data\Sun\Java\Deployment\cache\javapi\v1.0\jar\FacebookPhotoUploader.jar-2cce3b73-7d01c276.idx
c:\documents and settings\Jessica\Application Data\Sun\Java\Deployment\cache\javapi\v1.0\jar\FacebookPhotoUploader.jar-2cce3b73-7d01c276.zip
c:\documents and settings\Jessica\Application Data\Sun\Java\Deployment\cache\javapi\v1.0\jar\FacebookPhotoUploader5.jar-62950ace-30d1398c.idx
c:\documents and settings\Jessica\Application Data\Sun\Java\Deployment\cache\javapi\v1.0\jar\FacebookPhotoUploader5.jar-62950ace-30d1398c.zip
c:\documents and settings\Jessica\Application Data\Sun\Java\Deployment\cache\javapi\v1.0\jar\HeroGuyPaint.jar-49bdd52b-13f1a601.idx
c:\documents and settings\Jessica\Application Data\Sun\Java\Deployment\cache\javapi\v1.0\jar\HeroGuyPaint.jar-49bdd52b-13f1a601.zip
c:\documents and settings\Jessica\Application Data\Sun\Java\Deployment\cache\javapi\v1.0\jar\ImageUploader2.jar-7fc79664-1d300cdd.idx
c:\documents and settings\Jessica\Application Data\Sun\Java\Deployment\cache\javapi\v1.0\jar\ImageUploader2.jar-7fc79664-1d300cdd.zip
c:\documents and settings\Jessica\Application Data\Sun\Java\Deployment\cache\javapi\v1.0\jar\ImageUploader2_vs44.jar-1fa2518e-1df63325.idx
c:\documents and settings\Jessica\Application Data\Sun\Java\Deployment\cache\javapi\v1.0\jar\ImageUploader2_vs44.jar-1fa2518e-1df63325.zip
c:\documents and settings\Jessica\Application Data\Sun\Java\Deployment\cache\javapi\v1.0\jar\JICA-configN.jar-3db89030-366af76f.idx
c:\documents and settings\Jessica\Application Data\Sun\Java\Deployment\cache\javapi\v1.0\jar\JICA-configN.jar-3db89030-366af76f.zip
c:\documents and settings\Jessica\Application Data\Sun\Java\Deployment\cache\javapi\v1.0\jar\JICA-coreN.jar-5f250533-21351a51.idx
c:\documents and settings\Jessica\Application Data\Sun\Java\Deployment\cache\javapi\v1.0\jar\JICA-coreN.jar-5f250533-21351a51.zip
c:\documents and settings\Jessica\Application Data\Sun\Java\Deployment\cache\javapi\v1.0\jar\JICA-printerN.jar-31001d5e-3565a2db.idx
c:\documents and settings\Jessica\Application Data\Sun\Java\Deployment\cache\javapi\v1.0\jar\JICA-printerN.jar-31001d5e-3565a2db.zip
c:\documents and settings\Jessica\Application Data\Sun\Java\Deployment\cache\javapi\v1.0\jar\JICA-seamlessN.jar-7aee40bb-6b8014af.idx
c:\documents and settings\Jessica\Application Data\Sun\Java\Deployment\cache\javapi\v1.0\jar\JICA-seamlessN.jar-7aee40bb-6b8014af.zip
c:\documents and settings\Jessica\Application Data\Sun\Java\Deployment\cache\javapi\v1.0\jar\JICA-sicaN.jar-13d40cbe-395fd938.idx
c:\documents and settings\Jessica\Application Data\Sun\Java\Deployment\cache\javapi\v1.0\jar\JICA-sicaN.jar-13d40cbe-395fd938.zip
c:\documents and settings\Jessica\Application Data\Sun\Java\Deployment\cache\javapi\v1.0\jar\jvmimpro.jar-5efd1945-42d8ffc2.idx
c:\documents and settings\Jessica\Application Data\Sun\Java\Deployment\cache\javapi\v1.0\jar\jvmimpro.jar-5efd1945-42d8ffc2.zip
c:\documents and settings\Jessica\Application Data\Sun\Java\Deployment\cache\javapi\v1.0\jar\newsday01.jar-4ff640f-672b1727.idx
c:\documents and settings\Jessica\Application Data\Sun\Java\Deployment\cache\javapi\v1.0\jar\newsday01.jar-4ff640f-672b1727.zip
c:\documents and settings\Jessica\Application Data\Sun\Java\Deployment\cache\javapi\v1.0\jar\npatjava.jar-209bde28-272bbc6d.idx
c:\documents and settings\Jessica\Application Data\Sun\Java\Deployment\cache\javapi\v1.0\jar\npatjava.jar-209bde28-272bbc6d.zip
c:\documents and settings\Jessica\Application Data\Sun\Java\Deployment\cache\javapi\v1.0\jar\ptviewer.jar-32a40a4a-7d35f353.idx
c:\documents and settings\Jessica\Application Data\Sun\Java\Deployment\cache\javapi\v1.0\jar\ptviewer.jar-32a40a4a-7d35f353.zip
c:\documents and settings\Jessica\Application Data\Sun\Java\Deployment\cache\javapi\v1.0\jar\ptviewer.jar-38493d1c-40d6dae9.idx
c:\documents and settings\Jessica\Application Data\Sun\Java\Deployment\cache\javapi\v1.0\jar\ptviewer.jar-38493d1c-40d6dae9.zip
c:\documents and settings\Jessica\Application Data\Sun\Java\Deployment\cache\javapi\v1.0\jar\ptviewer.jar-4966f37a-30296c09.idx
c:\documents and settings\Jessica\Application Data\Sun\Java\Deployment\cache\javapi\v1.0\jar\ptviewer.jar-4966f37a-30296c09.zip
c:\documents and settings\Jessica\Application Data\Sun\Java\Deployment\cache\javapi\v1.0\jar\ScrollDisp2.jar-610753b1-2dd5b88d.idx
c:\documents and settings\Jessica\Application Data\Sun\Java\Deployment\cache\javapi\v1.0\jar\ScrollDisp2.jar-610753b1-2dd5b88d.zip
c:\documents and settings\Jessica\Application Data\Sun\Java\Deployment\cache\javapi\v1.0\jar\TmapCube.jar-39ee6059-6e8cbbbb.idx
c:\documents and settings\Jessica\Application Data\Sun\Java\Deployment\cache\javapi\v1.0\jar\TmapCube.jar-39ee6059-6e8cbbbb.zip
c:\documents and settings\Jessica\Application Data\Sun\Java\Deployment\cache\javapi\v1.0\jar\twviewer.jar-22e66139-37cce2dd.idx
c:\documents and settings\Jessica\Application Data\Sun\Java\Deployment\cache\javapi\v1.0\jar\twviewer.jar-22e66139-37cce2dd.zip
c:\documents and settings\Jessica\Application Data\Sun\Java\Deployment\cache\javapi\v1.0\jar\ZoeGame.jar-23d68ebc-1fc73ca0.idx
c:\documents and settings\Jessica\Application Data\Sun\Java\Deployment\cache\javapi\v1.0\jar\ZoeGame.jar-23d68ebc-1fc73ca0.zip
c:\program files\Trend Micro\OfficeScan Client\SUSPECT
c:\program files\Trend Micro\OfficeScan Client\SUSPECT\{0024342E-7423-4BA4-BD7C-EB58003DCE8C}.exe
c:\program files\Trend Micro\OfficeScan Client\SUSPECT\{0076B20E-2B2D-43B2-8D92-12F818CF8C5F}.exe
c:\program files\Trend Micro\OfficeScan Client\SUSPECT\{0103A7E3-331E-43DF-BC20-6146A4F3E35B}.exe
c:\program files\Trend Micro\OfficeScan Client\SUSPECT\{03D080E6-A39F-4C5A-BC3E-8C024E61053D}.exe
c:\program files\Trend Micro\OfficeScan Client\SUSPECT\{03F612EB-5FB3-4578-A052-82D3098569F7}.exe
c:\program files\Trend Micro\OfficeScan Client\SUSPECT\{057C2EDB-3CE8-4620-AA41-D2C870100969}.exe
c:\program files\Trend Micro\OfficeScan Client\SUSPECT\{05853678-A615-4488-B4FA-3687B2D3400A}.exe
c:\program files\Trend Micro\OfficeScan Client\SUSPECT\{059F5891-012C-484C-9C5D-90437A2E2E60}.exe
c:\program files\Trend Micro\OfficeScan Client\SUSPECT\{05E72921-E09C-4963-8E02-09F72C5DD0E9}.exe
c:\program files\Trend Micro\OfficeScan Client\SUSPECT\{07D13CDA-74EE-4EF7-8FF0-83F1E7A053D2}.exe
c:\program files\Trend Micro\OfficeScan Client\SUSPECT\{08071625-BD2E-476F-9AD2-04DD1C3136C3}.exe
c:\program files\Trend Micro\OfficeScan Client\SUSPECT\{085F8FA7-C829-429B-903B-73748B15C341}.exe
c:\program files\Trend Micro\OfficeScan Client\SUSPECT\{08EB46B1-9960-4831-B698-BBECE673AA0C}.exe
c:\program files\Trend Micro\OfficeScan Client\SUSPECT\{095783EC-9BEF-46D9-9F21-606B68360702}.exe
c:\program files\Trend Micro\OfficeScan Client\SUSPECT\{09A79FA0-72F6-4DF0-814B-78DA4EBE39D9}.exe
c:\program files\Trend Micro\OfficeScan Client\SUSPECT\{0AC797A2-AB3A-418E-951F-FA57D8EF3EAD}.exe
c:\program files\Trend Micro\OfficeScan Client\SUSPECT\{0C682116-97AC-4A52-9D7D-D1A580533D75}.exe
c:\program files\Trend Micro\OfficeScan Client\SUSPECT\{0F618AF7-9F20-49F8-AAAF-FEEE20F15BB8}.exe
c:\program files\Trend Micro\OfficeScan Client\SUSPECT\{0FD9CBBF-679A-4B21-829B-8B8B6CEB7998}.exe
c:\program files\Trend Micro\OfficeScan Client\SUSPECT\{102641DA-94BF-42AF-B1A2-154B94DA446E}.exe
c:\program files\Trend Micro\OfficeScan Client\SUSPECT\{10B1E11D-4774-4EB9-AF8C-BAA303D5602F}.exe
c:\program files\Trend Micro\OfficeScan Client\SUSPECT\{10FCCEBF-4845-4D80-A712-5F1DDF4745A3}.exe
c:\program files\Trend Micro\OfficeScan Client\SUSPECT\{11E78EC3-3505-4C28-9C5B-2AEB07479041}.exe
c:\program files\Trend Micro\OfficeScan Client\SUSPECT\{1341D77C-733A-4316-B42C-54900C00E0C1}.exe
c:\program files\Trend Micro\OfficeScan Client\SUSPECT\{14FA0A95-4703-4BB2-BCC7-3D11CFF987C6}.exe
c:\program files\Trend Micro\OfficeScan Client\SUSPECT\{15412139-E5C2-42EC-8205-358D7579045C}.exe
c:\program files\Trend Micro\OfficeScan Client\SUSPECT\{162B86B1-ED2A-4D86-BCE5-04C62C171DFF}.exe
c:\program files\Trend Micro\OfficeScan Client\SUSPECT\{169DB33A-5FBD-44FA-A9DC-8A73E357EE9E}.exe
c:\program files\Trend Micro\OfficeScan Client\SUSPECT\{16C7533A-125E-4237-B4DF-026001654557}.exe
c:\program files\Trend Micro\OfficeScan Client\SUSPECT\{17E0F41E-BC16-4386-9721-8FA23C984130}.exe
c:\program files\Trend Micro\OfficeScan Client\SUSPECT\{18077D85-12F4-46DD-BBA8-8FDE1C280CE9}.exe
c:\program files\Trend Micro\OfficeScan Client\SUSPECT\{183FA186-E42E-4187-8280-C8EC4B7985D2}.exe
c:\program files\Trend Micro\OfficeScan Client\SUSPECT\{1ABBB395-5DFB-4D0B-A958-982A75488948}.exe
c:\program files\Trend Micro\OfficeScan Client\SUSPECT\{1AD1D8EF-72F3-4826-A144-A4CDCD649C83}.exe
c:\program files\Trend Micro\OfficeScan Client\SUSPECT\{1ADB0666-2BED-4335-BD08-1CB62200B390}.exe
c:\program files\Trend Micro\OfficeScan Client\SUSPECT\{1B9549EE-B0F9-4066-B4C3-8F97D93479D2}.exe
c:\program files\Trend Micro\OfficeScan Client\SUSPECT\{1BB202BE-BB29-45A6-B222-962BFDDF48D1}.exe
c:\program files\Trend Micro\OfficeScan Client\SUSPECT\{1C398595-28ED-4BA5-A473-81303576233F}.exe
c:\program files\Trend Micro\OfficeScan Client\SUSPECT\{1DB62F99-7F1C-41F6-B15D-D6CDD1E6E8D3}.exe
c:\program files\Trend Micro\OfficeScan Client\SUSPECT\{1DC15094-CC01-4ADF-88C0-4622C1A696D1}.exe
c:\program files\Trend Micro\OfficeScan Client\SUSPECT\{1EB2E6A1-9B28-4526-A168-63587682BDFF}.exe
c:\program files\Trend Micro\OfficeScan Client\SUSPECT\{1FE09F07-85EF-4C15-806B-B9BF957AAE91}.exe
c:\program files\Trend Micro\OfficeScan Client\SUSPECT\{1FE41E89-974C-4F0D-A533-C54C1B930E32}.exe
c:\program files\Trend Micro\OfficeScan Client\SUSPECT\{23122034-FD1E-425F-B5B0-93EFF63FC099}.exe
c:\program files\Trend Micro\OfficeScan Client\SUSPECT\{23813485-882E-406A-A2DF-B2EEF70CA7B8}.exe
c:\program files\Trend Micro\OfficeScan Client\SUSPECT\{23CF0435-E605-4129-8DB7-A3C30AECE66B}.exe
c:\program files\Trend Micro\OfficeScan Client\SUSPECT\{2517402A-C43E-4465-AD04-4658FBE610F4}.exe
c:\program files\Trend Micro\OfficeScan Client\SUSPECT\{255EFD54-26D5-412A-AD84-E52B00AE70B7}.exe
c:\program files\Trend Micro\OfficeScan Client\SUSPECT\{25DEB6ED-5905-4E92-A61F-B6F587E6290D}.exe
c:\program files\Trend Micro\OfficeScan Client\SUSPECT\{2609F02A-8EBF-4B79-87CE-17516C932AA2}.exe
c:\program files\Trend Micro\OfficeScan Client\SUSPECT\{263B22AC-AFF0-4862-8BD2-8B83486EDF8A}.exe
c:\program files\Trend Micro\OfficeScan Client\SUSPECT\{26F7316A-E0F7-47FC-8F50-627D8B499AB2}.exe
c:\program files\Trend Micro\OfficeScan Client\SUSPECT\{28E56AF9-07ED-4253-95DA-9E72DFF0B8B2}.exe
c:\program files\Trend Micro\OfficeScan Client\SUSPECT\{295935D3-E1B3-40DF-9B04-45BC7CC7E2C8}.exe
c:\program files\Trend Micro\OfficeScan Client\SUSPECT\{2B05CB97-E170-4AC6-9AB7-2815A7DC03FF}.exe
c:\program files\Trend Micro\OfficeScan Client\SUSPECT\{2BA5CE9F-ED1C-497E-9D5E-969505FE078D}.exe
c:\program files\Trend Micro\OfficeScan Client\SUSPECT\{2CAF9C19-C942-444F-8CFB-EB668AF27066}.exe
c:\program files\Trend Micro\OfficeScan Client\SUSPECT\{2DE52A28-0C24-4287-B099-1B373807DD37}.exe
c:\program files\Trend Micro\OfficeScan Client\SUSPECT\{2F400998-3A11-48E2-B2CC-2D8AB21E8D0F}.exe
c:\program files\Trend Micro\OfficeScan Client\SUSPECT\{3143BEC7-C74B-45E8-8526-9DFAFDF0E707}.exe
c:\program files\Trend Micro\OfficeScan Client\SUSPECT\{31E583AA-DACD-4E21-88CB-8DAF7E26FD6C}.exe
c:\program files\Trend Micro\OfficeScan Client\SUSPECT\{320BF4FC-F93C-4A25-9951-343F3C847A1A}.exe
c:\program files\Trend Micro\OfficeScan Client\SUSPECT\{32585BAE-C0E4-4E6D-B4AA-0B02CF300953}.exe
c:\program files\Trend Micro\OfficeScan Client\SUSPECT\{32851801-43B4-44F4-AE90-52D035AC9B00}.exe
c:\program files\Trend Micro\OfficeScan Client\SUSPECT\{32930834-6828-4E5A-B467-795145AF668E}.exe
c:\program files\Trend Micro\OfficeScan Client\SUSPECT\{344255D4-FD99-4843-B6B0-DC81BB7A8E51}.exe
c:\program files\Trend Micro\OfficeScan Client\SUSPECT\{357996F7-09C0-40EB-9A27-7A69FF8D65D6}.exe
c:\program files\Trend Micro\OfficeScan Client\SUSPECT\{36350E7F-AA40-43EE-9DE4-D8326B57A119}.exe
c:\program files\Trend Micro\OfficeScan Client\SUSPECT\{37810C34-4ECB-47B2-8E22-9F3738A01A74}.exe
c:\program files\Trend Micro\OfficeScan Client\SUSPECT\{39E68A5B-903B-4468-9FF7-9A994F44205E}.exe
c:\program files\Trend Micro\OfficeScan Client\SUSPECT\{3B6D0B4D-49B9-41F8-A8C3-619E3DAF6E78}.exe
c:\program files\Trend Micro\OfficeScan Client\SUSPECT\{3B7C1B9B-99B6-4260-A713-38F7AE508A02}.exe
c:\program files\Trend Micro\OfficeScan Client\SUSPECT\{3BA5A7C7-1739-4C0B-9ACB-B7D6172BA270}.exe
c:\program files\Trend Micro\OfficeScan Client\SUSPECT\{3C249B75-831B-48D6-BB00-FBA47FACBC01}.exe
c:\program files\Trend Micro\OfficeScan Client\SUSPECT\{3DA7C2F2-0E15-4DD7-81CB-D8F189410202}.exe
c:\program files\Trend Micro\OfficeScan Client\SUSPECT\{41FE21CE-01CE-4BE6-A2AC-38700AD24955}.exe
c:\program files\Trend Micro\OfficeScan Client\SUSPECT\{4376106A-B592-4712-B4A2-FCAAFEADB14A}.exe
c:\program files\Trend Micro\OfficeScan Client\SUSPECT\{43D52C3B-8BFB-4F29-BD54-CA87DC3C8D68}.exe
c:\program files\Trend Micro\OfficeScan Client\SUSPECT\{441D8E8B-2DDF-40F9-B2BE-478BEA30EA62}.exe
c:\program files\Trend Micro\OfficeScan Client\SUSPECT\{44589375-CA7D-484E-AE02-6F32517BEB6D}.exe
c:\program files\Trend Micro\OfficeScan Client\SUSPECT\{44C93E27-2C59-4530-B97B-4A681D1340F2}.exe
c:\program files\Trend Micro\OfficeScan Client\SUSPECT\{44F57523-02B7-4009-B596-868F9D0D6DF2}.exe
c:\program files\Trend Micro\OfficeScan Client\SUSPECT\{4581BB35-5088-47BD-B7D5-0D27A6E61D49}.exe
c:\program files\Trend Micro\OfficeScan Client\SUSPECT\{462F5201-51AE-4128-BBB7-1571D80D7A8B}.exe
c:\program files\Trend Micro\OfficeScan Client\SUSPECT\{4683801B-3E5C-46E1-87F1-F802C3E61B2E}.exe
c:\program files\Trend Micro\OfficeScan Client\SUSPECT\{46B69603-D3EB-4D54-AEBB-597D429AFC73}.exe
c:\program files\Trend Micro\OfficeScan Client\SUSPECT\{47464CE8-E700-44F4-AB65-8E6400C0D829}.exe
c:\program files\Trend Micro\OfficeScan Client\SUSPECT\{47DA9AC5-5086-4397-A6C9-9D7A90A7F3B6}.exe
c:\program files\Trend Micro\OfficeScan Client\SUSPECT\{48F16835-EA6F-4E07-A36E-A1F4A5B5142E}.exe
c:\program files\Trend Micro\OfficeScan Client\SUSPECT\{49F527DA-87AC-4B8C-ADAA-C5F8C015B657}.exe
c:\program files\Trend Micro\OfficeScan Client\SUSPECT\{4A2C9B90-B633-487D-840D-24BC24F794B9}.exe
c:\program files\Trend Micro\OfficeScan Client\SUSPECT\{4C2AB9C7-4B17-4381-9AE4-6335AD8A0B03}.exe
c:\program files\Trend Micro\OfficeScan Client\SUSPECT\{4E6E5600-FA9F-40EF-9C07-96185586E9C6}.exe
c:\program files\Trend Micro\OfficeScan Client\SUSPECT\{4F83089E-D371-4AD2-B2ED-091C192F6065}.exe
c:\program files\Trend Micro\OfficeScan Client\SUSPECT\{5005A9D2-74EB-4C02-B9D8-6459AD1BD1E8}.exe
c:\program files\Trend Micro\OfficeScan Client\SUSPECT\{5277B0CD-F808-4B97-9C4F-CD6F5D750647}.exe
c:\program files\Trend Micro\OfficeScan Client\SUSPECT\{540D031A-0118-48E2-A164-E53866824D04}.exe
c:\program files\Trend Micro\OfficeScan Client\SUSPECT\{545A8743-77D9-4B42-838B-B18AA8A9F8A2}.exe
c:\program files\Trend Micro\OfficeScan Client\SUSPECT\{54733545-3B0E-4433-A916-B8B5537AA74F}.exe
c:\program files\Trend Micro\OfficeScan Client\SUSPECT\{560FEAB2-91D6-4373-A703-D3285B16E7BC}.exe
c:\program files\Trend Micro\OfficeScan Client\SUSPECT\{57153D05-EC35-48CB-9204-95D96D752CA3}.exe
c:\program files\Trend Micro\OfficeScan Client\SUSPECT\{57A71CE6-E698-4398-982F-3790CD39DB9B}.exe
c:\program files\Trend Micro\OfficeScan Client\SUSPECT\{58485ADF-1F0E-4D3A-A1EB-CB0AC84CAE91}.exe
c:\program files\Trend Micro\OfficeScan Client\SUSPECT\{58490BF1-B7FB-45BC-BED8-BEAEB8F011D1}.exe
c:\program files\Trend Micro\OfficeScan Client\SUSPECT\{5A7A809D-A3D9-459D-AD36-26E9CFA5437A}.exe
c:\program files\Trend Micro\OfficeScan Client\SUSPECT\{5AA6EF84-5A53-48A8-AB45-C063BCEBCEFC}.exe
c:\program files\Trend Micro\OfficeScan Client\SUSPECT\{5AB38E84-C722-42F5-BEAA-06D0E0CD3CA9}.exe
c:\program files\Trend Micro\OfficeScan Client\SUSPECT\{5AF067F4-53D1-4361-B87C-65D06E0DF48D}.exe
c:\program files\Trend Micro\OfficeScan Client\SUSPECT\{5BE765FF-61D8-4F2B-BB68-3270F5FEC10C}.exe
c:\program files\Trend Micro\OfficeScan Client\SUSPECT\{5C1A3C20-B3B3-4E9C-93AD-DA6FBAF9751E}.exe
c:\program files\Trend Micro\OfficeScan Client\SUSPECT\{5CFBBC0B-0EB6-4A92-A0F4-2843C3A11C04}.exe
c:\program files\Trend Micro\OfficeScan Client\SUSPECT\{5D02AC3D-0E58-4134-BA5C-ED6CC905D179}.exe
c:\program files\Trend Micro\OfficeScan Client\SUSPECT\{5DBC209A-ECF3-4571-9A71-72B786B7014A}.exe
c:\program files\Trend Micro\OfficeScan Client\SUSPECT\{5F5099CE-D663-46D9-A1EA-D0F3F088B1C0}.exe
c:\program files\Trend Micro\OfficeScan Client\SUSPECT\{5FAD44E3-369E-4703-9C99-00B7A00E7030}.exe
c:\program files\Trend Micro\OfficeScan Client\SUSPECT\{60489031-220A-4987-B61E-E8919C2D0252}.exe
c:\program files\Trend Micro\OfficeScan Client\SUSPECT\{610B1E35-0189-4CC1-B254-09BC8273AEED}.exe
c:\program files\Trend Micro\OfficeScan Client\SUSPECT\{61E7BD1E-7383-4B81-B70D-DF06A363093C}.exe
c:\program files\Trend Micro\OfficeScan Client\SUSPECT\{62CFCCCD-E362-42D3-9121-543106B01B33}.exe
c:\program files\Trend Micro\OfficeScan Client\SUSPECT\{6363D2C0-AC03-41F0-8EED-BBF788C9EB12}.exe
c:\program files\Trend Micro\OfficeScan Client\SUSPECT\{63E640A4-D83C-41F8-A97A-6C8F5BB3E17F}.exe
c:\program files\Trend Micro\OfficeScan Client\SUSPECT\{6499024C-C30F-4092-9466-4D5A9F8AB2DA}.exe
c:\program files\Trend Micro\OfficeScan Client\SUSPECT\{6838FE89-4CA6-4817-8C3A-B29BAF9A7985}.exe
c:\program files\Trend Micro\OfficeScan Client\SUSPECT\{6AAF7086-911E-4067-A51A-7981566821CF}.exe
c:\program files\Trend Micro\OfficeScan Client\SUSPECT\{6C06D5CF-7735-442F-A1EE-8D327F20C1D0}.exe
c:\program files\Trend Micro\OfficeScan Client\SUSPECT\{6CAF9E8D-843F-420C-9CE9-433D9C8E4170}.exe
c:\program files\Trend Micro\OfficeScan Client\SUSPECT\{6E2C9EE4-C36E-4848-8F61-30041C3A734B}.exe
c:\program files\Trend Micro\OfficeScan Client\SUSPECT\{6EC40D33-F4A7-48F3-9ABC-C43D00548D89}.exe
c:\program files\Trend Micro\OfficeScan Client\SUSPECT\{6FBE9113-0280-436A-BA8A-9141F9C8F792}.exe
c:\program files\Trend Micro\OfficeScan Client\SUSPECT\{6FEE0D0F-DB88-412A-A121-F296F1BBFE4A}.exe
c:\program files\Trend Micro\OfficeScan Client\SUSPECT\{71DE9F00-CD2F-403A-B93C-01EB781E6C45}.exe
c:\program files\Trend Micro\OfficeScan Client\SUSPECT\{72DA0E53-F80D-44D9-B650-D5B3341214BB}.exe
c:\program files\Trend Micro\OfficeScan Client\SUSPECT\{72ECEB4A-8A8A-4C3F-B415-245E8EFD0AB8}.exe
c:\program files\Trend Micro\OfficeScan Client\SUSPECT\{73810376-C12E-4B66-96AF-DB503519371E}.exe
c:\program files\Trend Micro\OfficeScan Client\SUSPECT\{74453308-5B4C-4BE8-AACD-A59A1DA8C6F3}.exe
c:\program files\Trend Micro\OfficeScan Client\SUSPECT\{7573A29C-491A-4C80-B37B-86652F5CB953}.exe
c:\program files\Trend Micro\OfficeScan Client\SUSPECT\{76A190CA-31C6-4C26-978A-6498D2A59990}.exe
c:\program files\Trend Micro\OfficeScan Client\SUSPECT\{7702CDE2-5145-4A8E-8325-3F5C0B0346E8}.exe
c:\program files\Trend Micro\OfficeScan Client\SUSPECT\{77927923-A14A-4C7E-897D-A42FA472C647}.exe
c:\program files\Trend Micro\OfficeScan Client\SUSPECT\{7A6D43C3-9CB5-4B03-B905-A9E32B599547}.exe
c:\program files\Trend Micro\OfficeScan Client\SUSPECT\{7B464784-0735-4DD4-9388-80B13FE1E034}.exe
c:\program files\Trend Micro\OfficeScan Client\SUSPECT\{7B80E44F-057F-4E6F-BED3-C4292AB3B4AA}.exe
c:\program files\Trend Micro\OfficeScan Client\SUSPECT\{7BDAD998-708D-4E9F-A69C-824A45C058A4}.exe
c:\program files\Trend Micro\OfficeScan Client\SUSPECT\{7D69BFBF-42F7-4286-8F1B-014F01DC7AD0}.exe
c:\program files\Trend Micro\OfficeScan Client\SUSPECT\{7DA07259-69E6-4CCE-9A3E-28A445D5EA7F}.exe
c:\program files\Trend Micro\OfficeScan Client\SUSPECT\{7E6C048D-9B2E-462B-97DE-04BE84F17F3D}.exe
c:\program files\Trend Micro\OfficeScan Client\SUSPECT\{8097BB81-738E-4D07-8222-E3A28EA2C719}.exe
c:\program files\Trend Micro\OfficeScan Client\SUSPECT\{8208D703-DC3A-40CF-97B2-C70BE3615395}.exe
c:\program files\Trend Micro\OfficeScan Client\SUSPECT\{82CA9FCE-1894-4E5D-9C5B-22D2BDF20504}.exe
c:\program files\Trend Micro\OfficeScan Client\SUSPECT\{831A788B-8BBE-4593-B96F-28E0A27B0569}.exe
c:\program files\Trend Micro\OfficeScan Client\SUSPECT\{83896F41-FB20-4A79-AEC4-19BF3043DD93}.exe
c:\program files\Trend Micro\OfficeScan Client\SUSPECT\{84D0BEC9-B212-483A-A3D0-88EBD0E6956F}.exe
c:\program files\Trend Micro\OfficeScan Client\SUSPECT\{85C9B207-BACB-44C5-90BB-6A2C8F27399F}.exe
c:\program files\Trend Micro\OfficeScan Client\SUSPECT\{86594A18-149C-4A7D-9B89-DE8F5E08FAD0}.exe
c:\program files\Trend Micro\OfficeScan Client\SUSPECT\{87A37CC9-0698-4F47-AE8F-E87DA36321E3}.exe
c:\program files\Trend Micro\OfficeScan Client\SUSPECT\{87D3974B-928F-4DC5-AB68-E332BEF822F3}.exe
c:\program files\Trend Micro\OfficeScan Client\SUSPECT\{88715687-1872-40D2-BE44-89029F7778A7}.exe
c:\program files\Trend Micro\OfficeScan Client\SUSPECT\{89DFA45A-DA51-4956-A1CC-CF3FA1EDA94C}.exe
c:\program files\Trend Micro\OfficeScan Client\SUSPECT\{8CEF8505-E475-4111-8089-432D8365A534}.exe
c:\program files\Trend Micro\OfficeScan Client\SUSPECT\{8DC4C7B8-D2C7-44E3-8557-7B530C0D4EE1}.exe
c:\program files\Trend Micro\OfficeScan Client\SUSPECT\{8DE73611-F901-4809-B1D9-1F9E241AF9AB}.exe
c:\program files\Trend Micro\OfficeScan Client\SUSPECT\{8FA942E6-6992-4076-A4DD-4CD27283AA13}.exe
c:\program files\Trend Micro\OfficeScan Client\SUSPECT\{92BE637B-FB3E-49AD-82CC-BC4F2DD28CE8}.exe
c:\program files\Trend Micro\OfficeScan Client\SUSPECT\{9373AC90-5B69-40CA-967C-688688BC46A3}.exe
c:\program files\Trend Micro\OfficeScan Client\SUSPECT\{93F0C5B0-BD91-4519-AF65-E5DD25AAE56E}.exe
c:\program files\Trend Micro\OfficeScan Client\SUSPECT\{953CB1C5-EE3B-4E3B-9BCC-25F6CC5A68A6}.exe
c:\program files\Trend Micro\OfficeScan Client\SUSPECT\{95E99EE6-AB63-4C1C-BC3C-E732129B8A99}.exe
c:\program files\Trend Micro\OfficeScan Client\SUSPECT\{97293E2B-E564-415C-8B49-F7F26B3DEFD2}.exe
c:\program files\Trend Micro\OfficeScan Client\SUSPECT\{97D7968F-A07E-4EF7-8329-A2DA36105C49}.exe
c:\program files\Trend Micro\OfficeScan Client\SUSPECT\{97DA8B1D-2B2A-4760-A1E7-0185B0FEE913}.exe
c:\program files\Trend Micro\OfficeScan Client\SUSPECT\{98085EB6-4E8E-4BFE-9237-ABEAD7A99895}.exe
c:\program files\Trend Micro\OfficeScan Client\SUSPECT\{9B34C141-FB71-4FA2-BACC-33C01E9BD70D}.exe
c:\program files\Trend Micro\OfficeScan Client\SUSPECT\{9B656264-F98C-4997-84D1-BAB83DA74D4C}.exe
c:\program files\Trend Micro\OfficeScan Client\SUSPECT\{9BC739BE-1966-49FC-810C-3DAC5D8E299A}.exe
c:\program files\Trend Micro\OfficeScan Client\SUSPECT\{9C00FAE9-A2CD-4E70-9165-32B0984C4F71}.exe
c:\program files\Trend Micro\OfficeScan Client\SUSPECT\{9C905909-9EC8-42DD-B706-3EB7A8402B3F}.exe
c:\program files\Trend Micro\OfficeScan Client\SUSPECT\{9D392E52-D962-4C59-A335-D75B693837EC}.exe
c:\program files\Trend Micro\OfficeScan Client\SUSPECT\{9D684C95-F9C7-42EA-A768-33C64C56AE9B}.exe
c:\program files\Trend Micro\OfficeScan Client\SUSPECT\{9E190037-AE8E-43FA-ADC4-92B5A6E6A9D5}.exe
c:\program files\Trend Micro\OfficeScan Client\SUSPECT\{9E4686C2-1DF0-4022-B48F-7DAC4F45B6A3}.exe
c:\program files\Trend Micro\OfficeScan Client\SUSPECT\{A06765BC-20E0-4ACE-B057-40CB48532A99}.exe
c:\program files\Trend Micro\OfficeScan Client\SUSPECT\{A27CE282-7E93-49DC-A27E-61DC39E26F5F}.exe
c:\program files\Trend Micro\OfficeScan Client\SUSPECT\{A3100213-F198-4CBE-BD6F-573777A35775}.exe
c:\program files\Trend Micro\OfficeScan Client\SUSPECT\{A3F76C03-6C94-4CE8-9130-6DA1B32352E8}.exe
c:\program files\Trend Micro\OfficeScan Client\SUSPECT\{A4589012-EC3C-483F-85EE-A3CDA7269BF4}.exe
c:\program files\Trend Micro\OfficeScan Client\SUSPECT\{A73CEE44-711D-4B19-9EBA-685A2B267E6D}.exe
c:\program files\Trend Micro\OfficeScan Client\SUSPECT\{AA1146A0-B10E-4662-A39D-58D043341925}.exe
c:\program files\Trend Micro\OfficeScan Client\SUSPECT\{AE6861EA-F04B-4C35-90C0-B5C25775FAAB}.exe
c:\program files\Trend Micro\OfficeScan Client\SUSPECT\{AEC7F004-92F9-4BA0-9BE6-5EF1626EF127}.exe
c:\program files\Trend Micro\OfficeScan Client\SUSPECT\{AF9FA9F6-34EB-4780-907A-96DFDB20DA81}.exe
c:\program files\Trend Micro\OfficeScan Client\SUSPECT\{B1828260-D025-40A2-8047-F37E58BE45AD}.exe
c:\program files\Trend Micro\OfficeScan Client\SUSPECT\{B1A2F6C9-70EB-4083-9EAC-8ABACDCF5496}.exe
c:\program files\Trend Micro\OfficeScan Client\SUSPECT\{B1DEC13B-1C69-4175-9922-3D5EFE6D6322}.exe
c:\program files\Trend Micro\OfficeScan Client\SUSPECT\{B2657BDF-92FB-429A-86B9-F7EEFAB2B519}.exe
c:\program files\Trend Micro\OfficeScan Client\SUSPECT\{B4CE5FA3-A89F-4ABD-8481-98FB3703AEAA}.exe
c:\program files\Trend Micro\OfficeScan Client\SUSPECT\{B4F8F29F-DD76-4E3B-8C2C-6E7D45865167}.exe
c:\program files\Trend Micro\OfficeScan Client\SUSPECT\{B5568457-4560-4F32-B15D-398870345155}.exe
c:\program files\Trend Micro\OfficeScan Client\SUSPECT\{B57634A8-E985-4B8F-AAEA-CDD0202BAB54}.exe
c:\program files\Trend Micro\OfficeScan Client\SUSPECT\{B6D407B7-0802-47B6-BFF8-9C33642BC99C}.exe
c:\program files\Trend Micro\OfficeScan Client\SUSPECT\{B718FA50-F761-45FE-84CB-F4CB9F8DE254}.exe
c:\program files\Trend Micro\OfficeScan Client\SUSPECT\{B77BFBAF-35F9-49E4-9C9C-9CED93F5AAD1}.exe
c:\program files\Trend Micro\OfficeScan Client\SUSPECT\{B839EEE5-3314-469D-A65E-6BBAA0E587C3}.exe
c:\program files\Trend Micro\OfficeScan Client\SUSPECT\{B8986C5F-3CDB-4483-B6C7-1247FE378C6B}.exe
c:\program files\Trend Micro\OfficeScan Client\SUSPECT\{B89A4388-96B6-4D7A-95DC-076EC65923E1}.exe
c:\program files\Trend Micro\OfficeScan Client\SUSPECT\{B932A9EF-B227-4882-89FB-08534A12910D}.exe
c:\program files\Trend Micro\OfficeScan Client\SUSPECT\{BBC92E50-6B43-4990-89B0-8A1FC48D01D9}.exe
c:\program files\Trend Micro\OfficeScan Client\SUSPECT\{BC015DE5-739F-45E7-8D88-2C4D94CF5F40}.exe
c:\program files\Trend Micro\OfficeScan Client\SUSPECT\{BD944332-32E4-4D45-BCE7-911DBD7506FE}.exe
c:\program files\Trend Micro\OfficeScan Client\SUSPECT\{BE06FFA6-F66D-4B51-A0B7-89FAF53DE6E8}.exe
c:\program files\Trend Micro\OfficeScan Client\SUSPECT\{BE1E4969-84B3-4D0A-BC87-F0066EF9B788}.exe
c:\program files\Trend Micro\OfficeScan Client\SUSPECT\{BE20749D-88E2-4A76-BAC3-BF6FDA978A27}.exe
c:\program files\Trend Micro\OfficeScan Client\SUSPECT\{BE4DA4BD-D020-45BE-8A5D-325772FA04A0}.exe
c:\program files\Trend Micro\OfficeScan Client\SUSPECT\{BEE1CD58-36FA-4822-A3BE-93C6C6478505}.exe
c:\program files\Trend Micro\OfficeScan Client\SUSPECT\{C0A762C5-3A38-4F5D-A817-473C0ECE2B11}.exe
c:\program files\Trend Micro\OfficeScan Client\SUSPECT\{C1AA3733-D4E4-4C5E-B3A7-EF5B8F6A66B0}.exe
c:\program files\Trend Micro\OfficeScan Client\SUSPECT\{C3B066DF-44E4-4AFA-9C33-72596AAF8D49}.exe
c:\program files\Trend Micro\OfficeScan Client\SUSPECT\{C3C6F046-6C63-40FE-9103-74D32C2B0969}.exe
c:\program files\Trend Micro\OfficeScan Client\SUSPECT\{C680606C-A50B-46E6-A61B-2B092213F1B4}.exe
c:\program files\Trend Micro\OfficeScan Client\SUSPECT\{C6D3C978-3F1E-4A87-ABE1-D0BEE6A9FCEA}.exe
c:\program files\Trend Micro\OfficeScan Client\SUSPECT\{C76A473A-D438-4EF0-9922-19B725C372DC}.exe
c:\program files\Trend Micro\OfficeScan Client\SUSPECT\{C9910FA5-F1BB-4FCD-9CFF-2342DFD8A29B}.exe
c:\program files\Trend Micro\OfficeScan Client\SUSPECT\{C994CD21-08B4-496D-96ED-63B49C1E9120}.exe
c:\program files\Trend Micro\OfficeScan Client\SUSPECT\{C9BBD0F8-EBFC-42BB-9167-AB717B20A530}.exe
c:\program files\Trend Micro\OfficeScan Client\SUSPECT\{CACB2384-9E12-4B0D-9AD3-7104CBFB7AF2}.exe
c:\program files\Trend Micro\OfficeScan Client\SUSPECT\{CC73360B-162A-4C46-B632-E5DE679F561D}.exe
c:\program files\Trend Micro\OfficeScan Client\SUSPECT\{CCCCF789-69D6-48E4-ACEF-840A198DF6FE}.exe
c:\program files\Trend Micro\OfficeScan Client\SUSPECT\{CDB5BA49-6AD3-4C10-AFC3-375ED856609C}.exe
c:\program files\Trend Micro\OfficeScan Client\SUSPECT\{CEE6D2FB-4DCC-46BF-9708-47059CC1E2D8}.exe
c:\program files\Trend Micro\OfficeScan Client\SUSPECT\{CF185AA3-667E-42DB-ACCB-9FA56F191614}.exe
c:\program files\Trend Micro\OfficeScan Client\SUSPECT\{CFFC831B-44D2-4427-8AE4-CDDC61F5F10F}.exe
c:\program files\Trend Micro\OfficeScan Client\SUSPECT\{D053AB84-CDE3-44CC-8EC1-3C45B39796BA}.exe
c:\program files\Trend Micro\OfficeScan Client\SUSPECT\{D13F4E9F-53CA-43CD-9A98-92F1B638818F}.exe
c:\program files\Trend Micro\OfficeScan Client\SUSPECT\{D33E9539-C426-4525-9A3D-D59FA88D9888}.exe
c:\program files\Trend Micro\OfficeScan Client\SUSPECT\{D56CE563-B497-475C-BFEF-890F49E85EB2}.exe
c:\program files\Trend Micro\OfficeScan Client\SUSPECT\{D59E01A1-14D3-4681-94B0-479F097AB3CC}.exe
c:\program files\Trend Micro\OfficeScan Client\SUSPECT\{D63D6D36-2BEF-4F42-B77D-9F3A6DD3D19F}.exe
c:\program files\Trend Micro\OfficeScan Client\SUSPECT\{D771E0E9-1CCA-4CBE-BAB6-FD45B316423E}.exe
c:\program files\Trend Micro\OfficeScan Client\SUSPECT\{D7A56B9C-8367-46A6-981F-A64643DD85DA}.exe
c:\program files\Trend Micro\OfficeScan Client\SUSPECT\{DD4F8AB9-14A7-48D6-A962-14A2CF027676}.exe
c:\program files\Trend Micro\OfficeScan Client\SUSPECT\{DE4A5CEA-7091-4600-8B27-23D9DC386241}.exe
c:\program files\Trend Micro\OfficeScan Client\SUSPECT\{E01E9265-72DC-4A87-95A2-9FD181AAFF34}.exe
c:\program files\Trend Micro\OfficeScan Client\SUSPECT\{E203D50C-0502-445C-ACF2-A9852ACCBF6C}.exe
c:\program files\Trend Micro\OfficeScan Client\SUSPECT\{E2A05F51-DB73-42EA-B265-C762877B5369}.exe
c:\program files\Trend Micro\OfficeScan Client\SUSPECT\{E2DED314-4906-4465-BF0E-FE3C58001563}.exe
c:\program files\Trend Micro\OfficeScan Client\SUSPECT\{E3DB7C2D-8474-4A0B-B53B-A7E715A8D25D}.exe
c:\program files\Trend Micro\OfficeScan Client\SUSPECT\{E69C65A4-565C-4CF0-907E-17F21750D3D8}.exe
c:\program files\Trend Micro\OfficeScan Client\SUSPECT\{E791D2CC-85E1-4603-8102-DC1EF1AD8177}.exe
c:\program files\Trend Micro\OfficeScan Client\SUSPECT\{E8CD60FA-EA05-469D-AD82-BAEB4ECDFFA9}.exe
c:\program files\Trend Micro\OfficeScan Client\SUSPECT\{E8DED8BF-BCBC-4E40-B341-815F1578AC6A}.exe
c:\program files\Trend Micro\OfficeScan Client\SUSPECT\{E8F31391-A0C3-45D7-8AB1-52E3B6E026C9}.exe
c:\program files\Trend Micro\OfficeScan Client\SUSPECT\{EA5AFF68-1172-45EF-BE89-2553AA39D420}.exe
c:\program files\Trend Micro\OfficeScan Client\SUSPECT\{EA5FE5DD-0037-4B93-8F0E-962B311D4506}.exe
c:\program files\Trend Micro\OfficeScan Client\SUSPECT\{EA64D614-9BD8-475F-A71D-441A3565D686}.exe
c:\program files\Trend Micro\OfficeScan Client\SUSPECT\{EAB93EA9-6DA9-4CE5-A9C8-4DB910FA10B6}.exe
c:\program files\Trend Micro\OfficeScan Client\SUSPECT\{EAE02ADB-76C7-4981-A917-4E6EC020046F}.exe
c:\program files\Trend Micro\OfficeScan Client\SUSPECT\{EC1EB546-D842-4867-AA06-F4BD2C1FF005}.exe
c:\program files\Trend Micro\OfficeScan Client\SUSPECT\{ED22610E-B08C-4815-ABE9-B0438B53E834}.exe
c:\program files\Trend Micro\OfficeScan Client\SUSPECT\{EDD8AFF3-0474-4A38-8505-979822C1FC80}.exe
c:\program files\Trend Micro\OfficeScan Client\SUSPECT\{EDD8F870-7FF5-4CA0-BAFC-845904D1349E}.exe
c:\program files\Trend Micro\OfficeScan Client\SUSPECT\{EE601938-DF3A-44F2-A05D-DDBEADA19538}.exe
c:\program files\Trend Micro\OfficeScan Client\SUSPECT\{EE89912D-35D4-4F2E-9FCE-0A465959903A}.exe
c:\program files\Trend Micro\OfficeScan Client\SUSPECT\{EEFB34E8-845E-4F91-88C9-661D9F3AB26F}.exe
c:\program files\Trend Micro\OfficeScan Client\SUSPECT\{EF231512-C4E2-4C97-A36E-4714E1AE4948}.exe
c:\program files\Trend Micro\OfficeScan Client\SUSPECT\{EFE424D0-F1C0-4EAE-B927-733FE716847A}.exe
c:\program files\Trend Micro\OfficeScan Client\SUSPECT\{F2C69D9A-0BC2-4DDE-B63C-C9B5758E4B28}.exe
c:\program files\Trend Micro\OfficeScan Client\SUSPECT\{F2EFE5D9-3EFD-409C-AB72-468FA3E52017}.exe
c:\program files\Trend Micro\OfficeScan Client\SUSPECT\{F3482F38-F496-47D5-93A2-9B88F7D98EBB}.exe
c:\program files\Trend Micro\OfficeScan Client\SUSPECT\{F3547DF7-FA6F-4703-9594-8CFDE2984A40}.exe
c:\program files\Trend Micro\OfficeScan Client\SUSPECT\{F3AB0DF4-44AD-48BF-9B2B-690F45BE12F9}.exe
c:\program files\Trend Micro\OfficeScan Client\SUSPECT\{F3B01B3C-5427-4864-982E-F525DB1D75D0}.exe
c:\program files\Trend Micro\OfficeScan Client\SUSPECT\{F3D483B8-87C2-4E33-931C-9D545C705672}.exe
c:\program files\Trend Micro\OfficeScan Client\SUSPECT\{F7744241-6255-4F16-879A-AAABC9965A25}.exe
c:\program files\Trend Micro\OfficeScan Client\SUSPECT\{F940746C-AF57-49F6-ADB1-6A2551827053}.exe
c:\program files\Trend Micro\OfficeScan Client\SUSPECT\{F970F258-C058-4115-931B-0140497FF190}.exe
c:\program files\Trend Micro\OfficeScan Client\SUSPECT\{F9A39964-F4CD-4E05-9F45-1F2008C024BE}.exe
c:\program files\Trend Micro\OfficeScan Client\SUSPECT\{FB445BDB-8CCB-42A5-B2C6-98808737738B}.exe
c:\program files\Trend Micro\OfficeScan Client\SUSPECT\{FB68A0BC-37D2-450C-B31C-3F58AAC111D6}.exe
c:\program files\Trend Micro\OfficeScan Client\SUSPECT\{FC60983B-E449-4B6A-8062-6B98DA1345E3}.exe
c:\program files\Trend Micro\OfficeScan Client\SUSPECT\{FDD52332-88DF-444A-999C-939221C639CD}.exe
c:\program files\Trend Micro\OfficeScan Client\SUSPECT\{FF9ACEC9-AD98-4A2C-9BD7-3ED86E52CA24}.exe
c:\program files\Trend Micro\OfficeScan Client\SUSPECT\18532
c:\program files\Trend Micro\OfficeScan Client\SUSPECT\9s4tqo8k.exe
c:\program files\Trend Micro\OfficeScan Client\SUSPECT\C72D424Cd01
c:\program files\Trend Micro\OfficeScan Client\SUSPECT\d5c08qo9.exe
c:\program files\Trend Micro\OfficeScan Client\SUSPECT\FF21D759d01
c:\program files\Trend Micro\OfficeScan Client\SUSPECT\FF21D759d01_614.VIR
c:\program files\Trend Micro\OfficeScan Client\SUSPECT\googletalk-setup.exe
f:\documents and settings\Andrew\Desktop\Old C drive\WINDOWS\Desktop\laptop.zip
f:\documents and settings\Andrew\Desktop\Old C drive\WINDOWS\Desktop\old folder folder\old hdd\signage\eds labels\Pfeifferlabel.jpg
f:\old c drive\WINDOWS\Desktop\laptop.zip
f:\old c drive\WINDOWS\Desktop\old folder folder\old hdd\signage\eds labels\Pfeifferlabel.jpg
.
((((((((((((((((((((((((((((((((((((((( Drivers/Services )))))))))))))))))))))))))))))))))))))))))))))))))
.
——-\Legacy_ASBP2POA
——-\Service_asbp2poa
((((((((((((((((((((((((( Files Created from 2009-01-07 to 2009-02-07 )))))))))))))))))))))))))))))))
.
2009-01-23 00:27 . 2009-01-23 00:28 d——– C:\Rooter$
2009-01-22 21:45 . 2009-01-22 21:45 d——– c:\program files\Malwarebytes' Anti-Malware
2009-01-22 21:45 . 2009-01-22 21:45 d——– c:\documents and settings\Andy\Application Data\Malwarebytes
2009-01-22 21:45 . 2009-01-22 21:45 d——– c:\documents and settings\All Users\Application Data\Malwarebytes
2009-01-22 21:45 . 2009-01-14 16:11 38,496 –a—— c:\windows\system32\drivers\mbamswissarmy.sys
2009-01-22 21:45 . 2009-01-14 16:11 15,504 –a—— c:\windows\system32\drivers\mbam.sys
2009-01-21 22:30 . 2009-01-21 22:30 54,156 –ah—– c:\windows\QTFont.qfn
2009-01-21 22:30 . 2009-01-21 22:30 1,409 –a—— c:\windows\QTFont.for
2009-01-21 20:57 . 2009-01-21 20:57 410,984 –a—— c:\windows\system32\deploytk.dll
2009-01-21 20:57 . 2009-01-21 20:57 73,728 –a—— c:\windows\system32\javacpl.cpl
2009-01-17 13:41 . 2009-01-17 13:41 d——– c:\documents and settings\All Users\Application Data\Blizzard
2009-01-15 23:17 . 2009-01-15 23:20 d——– c:\program files\ERUNT
2009-01-07 23:59 . 2009-01-07 23:59 d——– c:\program files\CD Wave
2009-01-07 23:59 . 2005-07-01 16:32 258,352 –a—— c:\windows\system32\unicows.dll
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2009-02-07 04:00 ——— d—–w c:\program files\Java
2009-02-01 01:31 ——— d—–w c:\program files\World of Warcraft
2009-01-17 15:30 ——— d—–w c:\documents and settings\Andy\Application Data\Juniper Networks
2009-01-17 15:30 ——— d—–w c:\documents and settings\All Users\Application Data\Juniper Networks
2009-01-16 05:13 ——— d—–w c:\program files\EverQuest
2009-01-16 03:55 ——— d—–w c:\program files\Trend Micro
2009-01-05 05:28 ——— d—–w c:\documents and settings\Andy\Application Data\Roxio
2009-01-05 05:25 ——— d—–w c:\documents and settings\Andy\Application Data\vlc
2009-01-05 04:59 ——— d—–w c:\program files\VideoLAN
2009-01-05 04:44 ——— d—–w c:\program files\DVD Decrypter
2009-01-05 04:04 ——— d—–w c:\program files\DivX
2008-12-28 20:12 ——— d—–w c:\documents and settings\Andy\Application Data\uTorrent
2008-12-19 12:09 0 —ha-w c:\windows\system32\drivers\MsftWdf_Kernel_01005_Coinstaller_Critical.Wdf
2008-12-19 12:09 0 —ha-w c:\windows\system32\drivers\Msft_Kernel_xusb21_01005.Wdf
2008-12-11 11:57 333,184 —-a-w c:\windows\system32\drivers\srv.sys
2007-10-08 01:10 53,248 —-a-w c:\documents and settings\Andy\Jessica HoweAddItConfig.dll
2007-10-08 01:10 40,960 —-a-w c:\documents and settings\Andy\Jessica HoweAddItTaskProc.exe
2007-10-08 01:10 4 —-a-w c:\documents and settings\Andy\Jessica HoweTransDB.bin
2007-10-08 01:10 192,512 —-a-w c:\documents and settings\Andy\Jessica HoweAddItManager.exe
2007-10-08 01:10 102,400 —-a-w c:\documents and settings\Andy\Jessica HoweAddItConduit.dll
2007-07-17 11:52 154,120 —-a-w c:\documents and settings\Jessica\Application Data\GDIPFONTCACHEV1.DAT
2007-01-04 00:33 154,120 —-a-w c:\documents and settings\Andy\Application Data\GDIPFONTCACHEV1.DAT
2005-01-24 17:09 3,518,464 ——w c:\documents and settings\Andy\testeqgame.exe
2005-01-24 17:09 2,035,712 ——w c:\documents and settings\Andy\EQGraphicsDX9.dll
2005-01-06 21:04 913,408 ——w c:\documents and settings\Andy\eqmain.dll
2005-01-06 21:04 901,120 ——w c:\documents and settings\Andy\EQGfx_Dx8.dll
2005-01-06 21:04 81,920 ——w c:\documents and settings\Andy\eaxman.dll
2005-01-06 21:04 349,696 ——w c:\documents and settings\Andy\mss32.dll
2005-01-06 21:04 282,624 ——w c:\documents and settings\Andy\OptionsEditor.exe
2005-01-06 21:04 159,744 ——w c:\documents and settings\Andy\dpvs.dll
2004-12-17 09:57 3,514,368 ——w c:\documents and settings\Andy\eqgame.exe
2004-08-09 23:31 1,409,024 ——w c:\documents and settings\Andy\BetaEverQuest.exe
2003-07-15 17:02 81,920 ——w c:\documents and settings\Andy\Win32Bitmap.dll
2002-07-24 05:28 1,296 ——w c:\documents and settings\Andy\load2_switches.dat
2002-04-01 14:11 249,856 ——w c:\documents and settings\Andy\installerconfig.exe
1999-01-25 22:40 95,232 ——w c:\documents and settings\Andy\smackw32.dll
2008-10-20 14:51 27,976 —-a-w c:\program files\mozilla firefox\plugins\atgpcdec.dll
2008-10-20 14:51 125,848 —-a-w c:\program files\mozilla firefox\plugins\atgpcext.dll
2008-02-08 01:46 13,624 —-a-w c:\program files\mozilla firefox\plugins\cgpcfg.dll
2008-02-08 01:46 87,360 —-a-w c:\program files\mozilla firefox\plugins\CgpCore.dll
2008-02-08 01:46 91,448 —-a-w c:\program files\mozilla firefox\plugins\confmgr.dll
2008-02-08 01:46 21,824 —-a-w c:\program files\mozilla firefox\plugins\ctxlogging.dll
2008-02-08 01:46 206,136 —-a-w c:\program files\mozilla firefox\plugins\ctxmui.dll
2008-02-08 01:46 31,544 —-a-w c:\program files\mozilla firefox\plugins\icafile.dll
2008-02-08 01:46 40,248 —-a-w c:\program files\mozilla firefox\plugins\icalogon.dll
2008-10-20 14:52 98,712 —-a-w c:\program files\mozilla firefox\plugins\ieatgpc.dll
2007-03-16 21:27 479,232 —-a-w c:\program files\mozilla firefox\plugins\msvcm80.dll
2007-03-16 21:27 548,864 —-a-w c:\program files\mozilla firefox\plugins\msvcp80.dll
2007-03-16 21:27 626,688 —-a-w c:\program files\mozilla firefox\plugins\msvcr80.dll
2007-07-20 16:47 981,170 —-a-w c:\program files\mozilla firefox\plugins\sslsdk_b.dll
2008-02-08 01:46 24,384 —-a-w c:\program files\mozilla firefox\plugins\TcpPServ.dll
2005-09-15 23:26 44,153 —-a-w c:\program files\mozilla firefox\components\inspector.dll
2008-12-19 12:07 67,688 —-a-w c:\program files\mozilla firefox\components\jar50.dll
2008-12-19 12:07 54,368 —-a-w c:\program files\mozilla firefox\components\jsd3250.dll
2008-12-19 12:07 34,944 —-a-w c:\program files\mozilla firefox\components\myspell.dll
2008-12-19 12:07 46,712 —-a-w c:\program files\mozilla firefox\components\spellchk.dll
2008-12-19 12:07 172,136 —-a-w c:\program files\mozilla firefox\components\xpinstal.dll
.
((((((((((((((((((((((((((((( snapshot@2009-02-01_19.15.21.89 )))))))))))))))))))))))))))))))))))))))))
.
- 2005-10-20 12:02:28 163,328 —-a-w c:\windows\ERDNT\Hiv-backup\ERDNT.EXE
+ 2005-10-21 01:02:28 163,328 —-a-w c:\windows\ERDNT\Hiv-backup\ERDNT.EXE
+ 2005-10-21 01:02:28 163,328 —-a-w c:\windows\ERDNT\subs\ERDNT.EXE
- 2000-08-31 13:00:00 286,720 —-a-w c:\windows\SWREG.exe
+ 2000-08-31 13:00:00 161,792 —-a-w c:\windows\SWREG.exe
+ 2009-02-05 23:31:03 53,248 —-a-w c:\windows\system32\Macromed\Shockwave 10\PostUpdate.exe
+ 2004-07-07 01:07:14 172,099 —-a-w c:\windows\Temp\KTC63D.EXE
+ 2009-02-07 04:15:29 16,384 —-atw c:\windows\Temp\Perflib_Perfdata_138.dat
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ctfmon.exe"="c:\windows\system32\ctfmon.exe" [2004-08-04 15360]
"googletalk"="c:\program files\Google\Google Talk\googletalk.exe" [2007-01-01 3739648]
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\RunOnce]
"CTStartup"="c:\program files\Creative\Splash Screen\CTEaxSpl.EXE" [2002-09-13 49152]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"CTStartup"="c:\program files\Creative\Splash Screen\CTEaxSpl.EXE" [2002-09-13 49152]
"OfficeScanNT Monitor"="c:\program files\Trend Micro\OfficeScan Client\pccntmon.exe" [2004-07-06 335872]
"googletalk"="c:\program files\Google\Google Talk\googletalk.exe" [2007-01-01 3739648]
"TkBellExe"="c:\program files\Common Files\Real\Update_OB\realsched.exe" [2008-10-28 185872]
"SunJavaUpdateSched"="c:\program files\Java\jre6\bin\jusched.exe" [2009-01-21 136600]
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"DWQueuedReporting"="c:\progra~1\COMMON~1\MICROS~1\DW\dwtrig20.exe" [2007-03-13 39264]
c:\documents and settings\Jessica\Start Menu\Programs\Startup\
Cyber-shot Viewer Media Check Tool.lnk - c:\program files\Sony\Sony Picture Utility\VolumeWatcher\SPUVolumeWatcher.exe [2007-01-15 155648]
[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Adobe Gamma Loader.exe.lnk]
path=c:\documents and settings\All Users\Start Menu\Programs\Startup\Adobe Gamma Loader.exe.lnk
backup=c:\windows\pss\Adobe Gamma Loader.exe.lnkCommon Startup
[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^APC UPS Status.lnk]
path=c:\documents and settings\All Users\Start Menu\Programs\Startup\APC UPS Status.lnk
backup=c:\windows\pss\APC UPS Status.lnkCommon Startup
[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^HOTSYNCSHORTCUTNAME.lnk]
path=c:\documents and settings\All Users\Start Menu\Programs\Startup\HOTSYNCSHORTCUTNAME.lnk
backup=c:\windows\pss\HOTSYNCSHORTCUTNAME.lnkCommon Startup
[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^HP Digital Imaging Monitor.lnk]
path=c:\documents and settings\All Users\Start Menu\Programs\Startup\HP Digital Imaging Monitor.lnk
backup=c:\windows\pss\HP Digital Imaging Monitor.lnkCommon Startup
[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Microsoft Office.lnk]
path=c:\documents and settings\All Users\Start Menu\Programs\Startup\Microsoft Office.lnk
backup=c:\windows\pss\Microsoft Office.lnkCommon Startup
[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^PixCert.lnk]
path=c:\documents and settings\All Users\Start Menu\Programs\Startup\PixCert.lnk
backup=c:\windows\pss\PixCert.lnkCommon Startup
[HKLM\~\startupfolder\C:^Documents and Settings^Andy^Start Menu^Programs^Startup^LifeDrive™ Manager.lnk]
path=c:\documents and settings\Andy\Start Menu\Programs\Startup\LifeDrive™ Manager.lnk
backup=c:\windows\pss\LifeDrive™ Manager.lnkStartup
[HKLM\~\startupfolder\C:^Documents and Settings^Andy^Start Menu^Programs^Startup^PdaReach Desktop.lnk]
path=c:\documents and settings\Andy\Start Menu\Programs\Startup\PdaReach Desktop.lnk
backup=c:\windows\pss\PdaReach Desktop.lnkStartup
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Adobe Reader Speed Launcher]
–a—— 2008-06-12 01:38 34672 c:\program files\Adobe\Reader 9.0\Reader\reader_sl.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\CTDVDDet]
–a—— 2002-09-30 01:00 45056 c:\program files\Creative\SBAudigy2\DVDAudio\CTDVDDET.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\CTRegRun]
——— 1999-10-10 20:00 41984 c:\windows\Ctregrun.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\CTSysVol]
–a—— 2002-10-29 09:18 49152 c:\program files\Creative\SBAudigy2\Surround Mixer\CTSysVol.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\H/PC Connection Agent]
–a—— 2006-11-13 12:39 1289000 c:\program files\Microsoft ActiveSync\wcescomm.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\HostManager]
–a—— 2004-11-03 16:03 125528 c:\program files\Common Files\AOL\1151501207\EE\AOLHostManager.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\HP Software Update]
–a—— 2006-12-10 20:52 49152 c:\program files\Hewlett-Packard\HP Software Update\hpwuSchd2.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\HPDJ Taskbar Utility]
–a—— 2006-01-06 14:07 188416 c:\windows\system32\spool\drivers\w32x86\3\hpztsb07.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\HPHmon04]
–a—— 2006-01-06 14:07 348160 c:\windows\system32\hphmon04.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\MSMSGS]
–a—— 2004-10-13 11:24 1694208 c:\program files\Messenger\msmsgs.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\QuickTime Task]
–a—— 2006-06-28 08:28 98304 c:\program files\QuickTime\qttask.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\RealTray]
–a—— 2008-10-28 21:38 214536 c:\program files\Real\RealPlayer\realplay.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\RoxioDragToDisc]
–a—— 2005-10-20 19:47 1687552 c:\program files\Roxio\Easy Media Creator 8\Drag to Disc\DrgToDsc.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\RoxWatchTray]
–a—— 2005-10-21 14:13 163840 c:\program files\Common Files\Roxio Shared\SharedCOM8\RoxWatchTray.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SansaDispatch]
–a—— 2007-10-22 11:52 75584 c:\program files\SanDisk\Sansa Updater\SansaDispatch.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SBDrvDet]
–a—— 2002-12-03 18:06 45056 c:\program files\Creative\SB Drive Det\SBDrvDet.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Share-to-Web Namespace Daemon]
–a—— 2002-04-17 10:42 69632 c:\program files\Hewlett-Packard\HP Share-to-Web\hpgs2wnd.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\StartCCC]
–a—— 2006-11-10 12:35 90112 c:\program files\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\TkBellExe]
–a—— 2008-10-28 21:38 185872 c:\program files\Common Files\Real\Update_OB\realsched.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\UpdReg]
——— 2000-05-11 01:00 90112 c:\windows\Updreg.EXE
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\AsioReg]
–a—— 2006-08-11 14:45 74752 c:\windows\system32\CTASIO.DLL
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\CTHelper]
–a—— 2002-12-19 01:59 28672 c:\windows\system32\CTHELPER.EXE
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\CTxfiHlp]
–a—— 2006-08-11 14:56 18944 c:\windows\system32\CTXFIHLP.EXE
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\TrendFirewall]
"DisableMonitoring"=dword:00000001
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"c:\\Program Files\\World of Warcraft\\BackgroundDownloader.exe"=
"c:\\Program Files\\World of Warcraft\\WoW-1.10.2.5302-to-1.11.0.5428-enUS-downloader.exe"=
"c:\\Program Files\\Mozilla Firefox\\firefox.exe"=
"c:\\Program Files\\Common Files\\AOL\\Loader\\aolload.exe"=
"c:\\Program Files\\America Online 9.0\\waol.exe"=
"c:\\Program Files\\Common Files\\AOL\\TopSpeed\\2.0\\aoltsmon.exe"=
"c:\\Program Files\\Common Files\\AOL\\TopSpeed\\2.0\\aoltpspd.exe"=
"c:\\Program Files\\Common Files\\AOL\\1151501207\\EE\\AOLServiceHost.exe"=
"c:\\Program Files\\Common Files\\AOL\\System Information\\sinf.exe"=
"c:\\Program Files\\World of Warcraft\\WoW-1.11.1.5462-to-1.11.2.5464-enUS-downloader.exe"=
"c:\\Program Files\\Google\\Google Talk\\googletalk.exe"=
"c:\\Program Files\\Windows Media Player\\wmplayer.exe"=
"c:\\Program Files\\palmOne\\Hotsync.exe"=
"c:\\Program Files\\Bullfrog\\Dungeon Keeper 2\\DKII.icd"=
"c:\\Program Files\\World of Warcraft\\WoW-1.12.x-to-2.0.1-enUS-patch-downloader.exe"=
"c:\\Program Files\\World of Warcraft\\WoW-2.0.3-enUS-downloader.exe"=
"c:\\Program Files\\World of Warcraft\\WoW-2.0.4.6314-to-2.0.5.6320-enUS-downloader.exe"=
"c:\\Program Files\\World of Warcraft\\WoW-2.0.3.6299-to-2.0.5.6320-enUS-downloader.exe"=
"c:\\Program Files\\World of Warcraft\\WoW-2.0.5.6320-to-2.0.6.6337-enUS-downloader.exe"=
"c:\\Program Files\\World of Warcraft\\WoW-2.0.6.6337-to-2.0.7.6383-enUS-downloader.exe"=
"c:\\Program Files\\World of Warcraft\\WoW-2.0.7.6383-to-2.0.8.6403-enUS-downloader.exe"=
"c:\\Program Files\\World of Warcraft\\WoW-2.0.8.6403-to-2.0.10.6448-enUS-downloader.exe"=
"c:\\Program Files\\Real\\RealPlayer\\realplay.exe"=
"c:\\Program Files\\World of Warcraft\\WoW-2.0.10.6448-to-2.0.12.6546-enUS-downloader.exe"=
"c:\\pfs\\callatl\\rteng9.exe"=
"c:\\Program Files\\Roxio\\Easy Media Creator 8\\Digital Home\\RoxUpnpServer.exe"=
"c:\\Program Files\\uTorrent\\uTorrent.exe"=
"c:\\Program Files\\Aspyr\\Guitar Hero III\\GH3.exe"=
"c:\\Program Files\\Juniper Networks\\Secure Application Manager\\dsSamProxy.exe"=
"c:\\Documents and Settings\\Andy\\Application Data\\Juniper Networks\\Juniper Terminal Services Client\\dsTermServ.exe"=
"c:\program files\Microsoft ActiveSync\rapimgr.exe"= c:\program files\Microsoft ActiveSync\rapimgr.exe:169.254.2.0/255.255.255.0:Enabled:ActiveSync RAPI Manager
"c:\program files\Microsoft ActiveSync\wcescomm.exe"= c:\program files\Microsoft ActiveSync\wcescomm.exe:169.254.2.0/255.255.255.0:Enabled:ActiveSync Connection Manager
"c:\program files\Microsoft ActiveSync\WCESMgr.exe"= c:\program files\Microsoft ActiveSync\WCESMgr.exe:169.254.2.0/255.255.255.0:Enabled:ActiveSync Application
"c:\\Program Files\\Hewlett-Packard\\Digital Imaging\\Bin\\hpqtra08.exe"=
"c:\\Program Files\\Hewlett-Packard\\Digital Imaging\\Bin\\hpqste08.exe"=
"c:\\Program Files\\Hewlett-Packard\\Digital Imaging\\Bin\\hpofxm08.exe"=
"c:\\Program Files\\Hewlett-Packard\\Digital Imaging\\Bin\\hposfx08.exe"=
"c:\\Program Files\\Hewlett-Packard\\Digital Imaging\\Bin\\hposid01.exe"=
"c:\\Program Files\\Hewlett-Packard\\Digital Imaging\\Bin\\hpqscnvw.exe"=
"c:\\Program Files\\Hewlett-Packard\\Digital Imaging\\Bin\\hpqkygrp.exe"=
"c:\\Program Files\\Hewlett-Packard\\Digital Imaging\\Bin\\hpqcopy.exe"=
"c:\\Program Files\\Hewlett-Packard\\Digital Imaging\\Bin\\hpzwiz01.exe"=
"c:\\Program Files\\Hewlett-Packard\\Digital Imaging\\Bin\\hpoews01.exe"=
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List]
"26675:TCP"= 26675:TCP:169.254.2.0/255.255.255.0:Enabled:ActiveSync Service
R1 NEOFLTR_550_11711;Juniper Networks TDI Filter Driver (NEOFLTR_550_11711);c:\windows\system32\drivers\NEOFLTR_550_11711.sys [2007-04-10 63264]
R2 TmFilter;Trend Micro Filter;c:\program files\Trend Micro\OfficeScan Client\tmxpflt.sys [2004-03-30 205328]
R2 TmPreFilter;Trend Micro PreFilter;c:\program files\Trend Micro\OfficeScan Client\tmpreflt.sys [2004-03-30 36368]
R2 WinDefend;Windows Defender;c:\program files\Windows Defender\MsMpEng.exe [2006-11-03 13592]
R3 ctgame;Game Port;c:\windows\system32\drivers\ctgame.sys [2003-12-14 12160]
S3 merger;merger;c:\program files\Microsoft Application Compatibility Toolkit\Application Analyzer\merger.exe [2005-09-27 49152]
— Other Services/Drivers In Memory —
*NewlyCreated* - MDM
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost]
HPZ12 REG_MULTI_SZ Pml Driver HPZ12 Net Driver HPZ12
HPService REG_MULTI_SZ HPSLPSVC
hpdevmgmt REG_MULTI_SZ hpqcxs08 hpqddsvc
.
Contents of the 'Scheduled Tasks' folder
2009-02-07 c:\windows\Tasks\MP Scheduled Scan.job
- c:\program files\Windows Defender\MpCmdRun.exe [2006-11-03 18:20]
.
- - - - ORPHANS REMOVED - - - -
MSConfigStartUp-SunJavaUpdateSched - c:\program files\Java\jre1.5.0_07\bin\jusched.exe
.
——- Supplementary Scan ——-
.
IE: E&xport to Microsoft Excel - c:\progra~1\MICROS~3\OFFICE10\EXCEL.EXE/3000
IE: {{55ED1415-06D3-41D0-9FC4-BCCBF334F865} - {1565EDCF-7E2D-4777-B08D-9845EA53C39A} - c:\windows\system32\mscoree.DLL
Trusted Zone: aol.com\free
Trusted Zone: turbotax.com
DPF: ActiveGS.cab - hxxp://www.virtualapple.com/activegs.cab
DPF: Microsoft XML Parser for Java - file://c:\windows\Java\classes\xmldso.cab
DPF: {2B1AA38D-2D12-11D5-AAD0-00C04FA03D78} - hxxp://portal.uga.edu/nps/portal/gadgets/com.novell.nps.gadgets.shortcut.ShortcutGadget/LocalExec.CAB
DPF: {B3872502-F9FD-4E96-93FF-0D37298F0689} - hxxp://everquest2.station.sony.com/beta_reg/soesysinfo.cab
FF - ProfilePath - c:\documents and settings\Andy\Application Data\Mozilla\Firefox\Profiles\2uva4pts.default\
FF - prefs.js: browser.search.selectedEngine - Google
FF - prefs.js: browser.startup.homepage - hxxp://www.google.com
FF - component: c:\program files\Mozilla Firefox\components\xpinstal.dll
.
**************************************************************************
catchme 0.3.1367 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2009-02-06 23:16:23
Windows 5.1.2600 Service Pack 2 NTFS
scanning hidden processes …
scanning hidden autostart entries …
HKLM\Software\Microsoft\Windows\CurrentVersion\Run
CTStartup = "c:\program files\Creative\Splash Screen\CTEaxSpl.EXE" /run?Z?A~d???*?A~?????????M??????h?@?x?????B~D??????sx??s????????y??w????@@@????|D@@?????>??w?????:2?H??????|???|???????|L(?s?:2??????/?s????????D???????????????????,????????????+?s@@@?D???`|?w??????@
HKCU\Software\Microsoft\Windows\CurrentVersion\RunOnce
CTStartup = "c:\program files\Creative\Splash Screen\CTEaxSpl.EXE" /play??A~d???*?A~?????????M??????h?@?x?????B~D??????sx??s????????y??w????@@@????|D@@?????>??w?????:2?H??????|???|???????|L(?s?:2??????/?s????????D???????????????????,????????????+?s@@@?D???`|?w??????@
scanning hidden files …
c:\windows\TEMP\TMP0000001E24001E91587BABFC 524288 bytes executable
scan completed successfully
hidden files: 1
**************************************************************************
.
——————— DLLs Loaded Under Running Processes ———————
- - - - - - - > 'winlogon.exe'(728)
c:\windows\system32\Ati2evxx.dll
.
———————— Other Running Processes ————————
.
c:\windows\system32\ati2evxx.exe
c:\windows\system32\ati2evxx.exe
c:\program files\Common Files\AOL\TopSpeed\2.0\aoltsmon.exe
c:\program files\APC\APC PowerChute Personal Edition\mainserv.exe
c:\program files\Common Files\AOL\TopSpeed\2.0\aoltpspd.exe
c:\windows\system32\CTSVCCDA.EXE
c:\program files\Java\jre6\bin\jqs.exe
c:\program files\Common Files\Microsoft Shared\VS7Debug\mdm.exe
c:\program files\Trend Micro\OfficeScan Client\NTRtScan.exe
c:\program files\Trend Micro\OfficeScan Client\OfcPfwSvc.exe
c:\program files\Common Files\Roxio Shared\SharedCOM8\RoxMediaDB.exe
c:\program files\Common Files\Roxio Shared\SharedCOM8\RoxWatch.exe
c:\program files\Trend Micro\OfficeScan Client\TmListen.exe
c:\windows\system32\MsPMSPSv.exe
c:\windows\Temp\KTC63D.EXE
c:\windows\system32\logonui.exe
c:\program files\Trend Micro\OfficeScan Client\PccNTUpd.exe
.
**************************************************************************
.
Completion time: 2009-02-07 0:07:16 - machine was rebooted
ComboFix-quarantined-files.txt 2009-02-07 05:07:11
ComboFix2.txt 2009-02-02 00:18:41
Pre-Run: 26,619,179,008 bytes free
Post-Run: 26,511,622,144 bytes free
854 — E O F — 2009-02-05 15:18:30
MBAM log -
Malwarebytes' Anti-Malware 1.33
Database version: 1682
Windows 5.1.2600 Service Pack 2
2/7/2009 7:00:13 AM
mbam-log-2009-02-07 (07-00-13).txt
Scan type: Quick Scan
Objects scanned: 64944
Time elapsed: 6 minute(s), 6 second(s)
Memory Processes Infected: 0
Memory Modules Infected: 0
Registry Keys Infected: 0
Registry Values Infected: 0
Registry Data Items Infected: 0
Folders Infected: 0
Files Infected: 0
Memory Processes Infected:
(No malicious items detected)
Memory Modules Infected:
(No malicious items detected)
Registry Keys Infected:
(No malicious items detected)
Registry Values Infected:
(No malicious items detected)
Registry Data Items Infected:
(No malicious items detected)
Folders Infected:
(No malicious items detected)
Files Infected:
(No malicious items detected)
HJT log -
Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 3:11:54 PM, on 2/7/2009
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16762)
Boot mode: Normal
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Windows Defender\MsMpEng.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Common Files\AOL\TopSpeed\2.0\aoltsmon.exe
C:\Program Files\APC\APC PowerChute Personal Edition\mainserv.exe
C:\WINDOWS\System32\CTsvcCDA.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Java\jre6\bin\jqs.exe
C:\Program Files\Common Files\Microsoft Shared\VS7Debug\mdm.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Trend Micro\OfficeScan Client\ntrtscan.exe
C:\Program Files\Trend Micro\OfficeScan Client\OfcPfwSvc.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Common Files\Roxio Shared\SharedCOM8\RoxMediaDB.exe
C:\Program Files\Common Files\Roxio Shared\SharedCOM8\RoxWatch.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Trend Micro\OfficeScan Client\tmlisten.exe
C:\WINDOWS\System32\MsPMSPSv.exe
C:\WINDOWS\TEMP\KTC63D.EXE
C:\Program Files\Trend Micro\OfficeScan Client\pccntmon.exe
C:\Program Files\Google\Google Talk\googletalk.exe
C:\Program Files\Common Files\Real\Update_OB\realsched.exe
C:\Program Files\Java\jre6\bin\jusched.exe
C:\WINDOWS\system32\ctfmon.exe
C:\WINDOWS\explorer.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\Program Files\Malwarebytes' Anti-Malware\mbam.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\system32\wuauclt.exe
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
O2 - BHO: AcroIEHelperStub - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll
O2 - BHO: Java™ Plug-In SSV Helper - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre6\bin\ssv.dll
O2 - BHO: Java™ Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll
O2 - BHO: JQSIEStartDetectorImpl - {E7E6F031-17CE-4C07-BC86-EABFE594F69C} - C:\Program Files\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll
O4 - HKLM\..\Run: [CTStartup] "C:\Program Files\Creative\Splash Screen\CTEaxSpl.EXE" /run
O4 - HKLM\..\Run: [OfficeScanNT Monitor] "C:\Program Files\Trend Micro\OfficeScan Client\pccntmon.exe" -HideWindow
O4 - HKLM\..\Run: [googletalk] C:\Program Files\Google\Google Talk\googletalk.exe /autostart
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre6\bin\jusched.exe"
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [googletalk] "C:\Program Files\Google\Google Talk\googletalk.exe" /autostart
O4 - HKUS\S-1-5-21-1935655697-1993962763-725345543-1005\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe (User 'Jessica')
O4 - HKUS\S-1-5-21-1935655697-1993962763-725345543-1005\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background (User 'Jessica')
O4 - HKUS\S-1-5-21-1935655697-1993962763-725345543-1005\..\Run: [H/PC Connection Agent] "C:\PROGRA~1\MI3AA1~1\wcescomm.exe" (User 'Jessica')
O4 - HKUS\S-1-5-18\..\Run: [DWQueuedReporting] "C:\PROGRA~1\COMMON~1\MICROS~1\DW\dwtrig20.exe" -t (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [DWQueuedReporting] "C:\PROGRA~1\COMMON~1\MICROS~1\DW\dwtrig20.exe" -t (User 'Default user')
O4 - S-1-5-21-1935655697-1993962763-725345543-1005 Startup: Cyber-shot Viewer Media Check Tool.lnk = C:\Program Files\Sony\Sony Picture Utility\VolumeWatcher\SPUVolumeWatcher.exe (User 'Jessica')
O4 - S-1-5-21-1935655697-1993962763-725345543-1005 User Startup: Cyber-shot Viewer Media Check Tool.lnk = C:\Program Files\Sony\Sony Picture Utility\VolumeWatcher\SPUVolumeWatcher.exe (User 'Jessica')
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~3\OFFICE10\EXCEL.EXE/3000
O9 - Extra button: Create Mobile Favorite - {2EAF5BB1-070F-11D3-9307-00C04FAE2D4F} - C:\PROGRA~1\MI3AA1~1\INetRepl.dll
O9 - Extra button: (no name) - {2EAF5BB2-070F-11D3-9307-00C04FAE2D4F} - C:\PROGRA~1\MI3AA1~1\INetRepl.dll
O9 - Extra 'Tools' menuitem: Create Mobile Favorite… - {2EAF5BB2-070F-11D3-9307-00C04FAE2D4F} - C:\PROGRA~1\MI3AA1~1\INetRepl.dll
O9 - Extra button: Capture with PixCert - {55ED1415-06D3-41D0-9FC4-BCCBF334F865} - C:\WINDOWS\system32\mscoree.DLL
O9 - Extra button: Real.com - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - C:\WINDOWS\system32\Shdocvw.dll
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O12 - Plugin for .spop: C:\Program Files\Internet Explorer\Plugins\NPDocBox.dll
O16 - DPF: ActiveGS.cab - http://www.virtualapple.com/activegs.cab
O16 - DPF: {0A5FD7C5-A45C-49FC-ADB5-9952547D5715} (Creative Software AutoUpdate) - http://www.creative.com/su/ocx/15031/CTSUEng.cab
O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) - http://go.microsoft.com/fwlink/?linkid=39204
O16 - DPF: {2B1AA38D-2D12-11D5-AAD0-00C04FA03D78} (LocalExec Control) - http://portal.uga.edu/nps/portal/gadgets/c…t/LocalExec.CAB
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://update.microsoft.com/windowsupdate/…b?1150243977734
O16 - DPF: {6E5A37BF-FD42-463A-877C-4EB7002E68AE} (Trend Micro ActiveX Scan Agent 6.5) - http://housecall65.trendmicro.com/housecal…ivex/hcImpl.cab
O16 - DPF: {A90A5822-F108-45AD-8482-9BC8B12DD539} (Crucial cpcScan) - http://www.crucial.com/controls/cpcScanner.cab
O16 - DPF: {B3872502-F9FD-4E96-93FF-0D37298F0689} (SOESysInfo Control) - http://everquest2.station.sony.com/beta_reg/soesysinfo.cab
O16 - DPF: {E5F5D008-DD2C-4D32-977D-1A0ADF03058B} (JuniperSetupSP1 Control) - https://ive1.primerica.com/dana-cached/setu…perSetupSP1.cab
O16 - DPF: {EB387D2F-E27B-4D36-979E-847D1036C65D} (QDiagHUpdateObj Class) - http://h30043.www3.hp.com/sj/en/check/qdiagh.cab?312
O16 - DPF: {F6ACF75C-C32C-447B-9BEF-46B766368D29} (Creative Software AutoUpdate Support Package) - http://www.creative.com/su/ocx/15033/CTPID.cab
O23 - Service: AOL TopSpeed Monitor (AOL TopSpeedMonitor) - America Online, Inc - C:\Program Files\Common Files\AOL\TopSpeed\2.0\aoltsmon.exe
O23 - Service: APC UPS Service - American Power Conversion Corporation - C:\Program Files\APC\APC PowerChute Personal Edition\mainserv.exe
O23 - Service: Ati HotKey Poller - ATI Technologies Inc. - C:\WINDOWS\system32\Ati2evxx.exe
O23 - Service: ATI Smart - Unknown owner - C:\WINDOWS\system32\ati2sgag.exe
O23 - Service: Creative Service for CDROM Access - Creative Technology Ltd - C:\WINDOWS\System32\CTsvcCDA.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: Imapi Helper - Alex Feinman - C:\Program Files\Alex Feinman\ISO Recorder\ImapiHelper.exe
O23 - Service: Java Quick Starter (JavaQuickStarterService) - Sun Microsystems, Inc. - C:\Program Files\Java\jre6\bin\jqs.exe
O23 - Service: OfficeScanNT RealTime Scan (ntrtscan) - Trend Micro Inc. - C:\Program Files\Trend Micro\OfficeScan Client\ntrtscan.exe
O23 - Service: OfficeScanNT Personal Firewall (OfcPfwSvc) - Trend Micro Inc. - C:\Program Files\Trend Micro\OfficeScan Client\OfcPfwSvc.exe
O23 - Service: PictureTaker - LANovation - C:\WINDOWS\System32\PCTKRNT.SYS
O23 - Service: Pml Driver HPH11 - HP - C:\WINDOWS\system32\HPHipm11.exe
O23 - Service: LiveShare P2P Server (RoxLiveShare) - Sonic Solutions - C:\Program Files\Common Files\Roxio Shared\SharedCOM8\RoxLiveShare.exe
O23 - Service: RoxMediaDB - Sonic Solutions - C:\Program Files\Common Files\Roxio Shared\SharedCOM8\RoxMediaDB.exe
O23 - Service: RoxUpnpRenderer (RoxUPnPRenderer) - Sonic Solutions - C:\Program Files\Common Files\Roxio Shared\SharedCom\RoxUpnpRenderer.exe
O23 - Service: RoxUpnpServer - Sonic Solutions - C:\Program Files\Roxio\Easy Media Creator 8\Digital Home\RoxUpnpServer.exe
O23 - Service: Roxio Hard Drive Watcher (RoxWatch) - Sonic Solutions - C:\Program Files\Common Files\Roxio Shared\SharedCOM8\RoxWatch.exe
O23 - Service: OfficeScanNT Listener (tmlisten) - Trend Micro Inc. - C:\Program Files\Trend Micro\OfficeScan Client\tmlisten.exe
–
End of file - 9383 bytes
previous topic is/was this - http://forums.whatthetech.com/slow_compute…ser_t99074.html -
requested scans in the last instruction post -
JavaRa log -
JavaRa 1.13 Removal Log.
Report follows after line.
————————————
The JavaRa removal process was started on Fri Feb 06 23:00:30 2009
Found and removed: C:\Program Files\Java\j2re1.4.2_01
Found and removed: C:\Program Files\Java\j2re1.4.2_03
Found and removed: C:\Program Files\Java\jre1.5.0_06
Found and removed: C:\Program Files\Java\jre1.5.0_07
Found and removed: C:\Windows\Installer\{7148F0A8-6813-11D6-A77B-00B0D0142010}
Found and removed: C:\Windows\Installer\{7148F0A8-6813-11D6-A77B-00B0D0142030}
Found and removed: SOFTWARE\JavaSoft\Java Runtime Environment\1.4
Found and removed: Software\JavaSoft\Java2D\1.5.0_07
Found and removed: SOFTWARE\Classes\CLSID\{CAFEEFAC-0015-0000-0006-ABCDEFFEDCBA}
Found and removed: SOFTWARE\Classes\CLSID\{CAFEEFAC-0015-0000-0007-ABCDEFFEDCBA}
Found and removed: SOFTWARE\Classes\Installer\Features\8A0F842331866D117AB7000B0D510006
Found and removed: SOFTWARE\Classes\Installer\Features\8A0F842331866D117AB7000B0D510007
Found and removed: SOFTWARE\Classes\Installer\Products\8A0F842331866D117AB7000B0D510006
Found and removed: SOFTWARE\Classes\Installer\Products\8A0F842331866D117AB7000B0D510007
Found and removed: SOFTWARE\Classes\Installer\UpgradeCodes\7A0F842331866D117AB7000B0D510006
Found and removed: SOFTWARE\Classes\Installer\UpgradeCodes\7A0F842331866D117AB7000B0D510007
Found and removed: SOFTWARE\Classes\JavaPlugin.150_06
Found and removed: SOFTWARE\Classes\JavaPlugin.150_07
Found and removed: SOFTWARE\Classes\JavaWebStart.isInstalled.1.5.0.0
Found and removed: SOFTWARE\JavaSoft\Java Plug-in\1.5.0_06
Found and removed: SOFTWARE\JavaSoft\Java Plug-in\1.5.0_07
Found and removed: SOFTWARE\JavaSoft\Java Runtime Environment\1.5
Found and removed: SOFTWARE\JavaSoft\Java Runtime Environment\1.5.0_06
Found and removed: SOFTWARE\JavaSoft\Java Runtime Environment\1.5.0_07
Found and removed: SOFTWARE\Microsoft\Code Store Database\Distribution Units\{CAFEEFAC-0015-0000-0006-ABCDEFFEDCBA}
Found and removed: SOFTWARE\Microsoft\Code Store Database\Distribution Units\{CAFEEFAC-0015-0000-0007-ABCDEFFEDCBA}
Found and removed: SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\ACBB9B2318A96D117A58000B0D510006
Found and removed: SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\ACBB9B2318A96D117A58000B0D510007
Found and removed: SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\8A0F842331866D117AB7000B0D510006
Found and removed: SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\8A0F842331866D117AB7000B0D510007
Found and removed: SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{3248F0A8-6813-11D6-A77B-00B0D0150060}
Found and removed: SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{3248F0A8-6813-11D6-A77B-00B0D0150070}
Found and removed: SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{7148F0A8-6813-11D6-A77B-00B0D0142010}
Found and removed: SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{7148F0A8-6813-11D6-A77B-00B0D0142030}
Found and removed: SOFTWARE\Classes\CLSID\{CAFEEFAC-0014-0002-0001-ABCDEFFEDCBA}
Found and removed: SOFTWARE\Classes\CLSID\{CAFEEFAC-0014-0002-0003-ABCDEFFEDCBA}
Found and removed: SOFTWARE\Classes\CLSID\{CAFEEFAC-0014-0002-0001-ABCDEFFEDCBB}
Found and removed: SOFTWARE\Classes\CLSID\{CAFEEFAC-0014-0002-0003-ABCDEFFEDCBB}
Found and removed: SOFTWARE\Classes\Installer\Products\8A0F841731866D117AB7000B0D410201
Found and removed: SOFTWARE\Classes\Installer\Products\8A0F841731866D117AB7000B0D410203
Found and removed: SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\8A0F841731866D117AB7000B0D410201
Found and removed: SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\8A0F841731866D117AB7000B0D410203
Found and removed: SOFTWARE\Classes\JavaPlugin.142_01
Found and removed: SOFTWARE\Classes\JavaPlugin.142_03
Found and removed: SOFTWARE\JavaSoft\Java Plug-in\1.4.2_01
Found and removed: SOFTWARE\JavaSoft\Java Plug-in\1.4.2_03
Found and removed: SOFTWARE\JavaSoft\Java Runtime Environment\1.4.2_01
Found and removed: SOFTWARE\JavaSoft\Java Runtime Environment\1.4.2_03
Found and removed: SOFTWARE\JavaSoft\Java Web Start\1.4.2_01
Found and removed: SOFTWARE\JavaSoft\Java Web Start\1.4.2_03
Found and removed: SOFTWARE\JavaSoft\Java Web Start\1.5.0_06
Found and removed: SOFTWARE\JavaSoft\Java Web Start\1.5.0_07
Found and removed: SOFTWARE\Microsoft\Code Store Database\Distribution Units\{CAFEEFAC-0014-0002-0001-ABCDEFFEDCBA}
Found and removed: SOFTWARE\Microsoft\Code Store Database\Distribution Units\{CAFEEFAC-0014-0002-0003-ABCDEFFEDCBA}
Found and removed: Software\Classes\JavaPlugin.142_01
Found and removed: Software\Classes\JavaPlugin.142_03
Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0000-0003-ABCDEFFEDCBA}
Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0000-0004-ABCDEFFEDCBA}
Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0000-0005-ABCDEFFEDCBA}
Found and removed: SOFTWARE\JavaSoft\Java Web Start\1.0.1
Found and removed: SOFTWARE\JavaSoft\Java Web Start\1.0.1_02
Found and removed: SOFTWARE\JavaSoft\Java Web Start\1.0.1_03
Found and removed: SOFTWARE\JavaSoft\Java Web Start\1.0.1_04
Found and removed: SOFTWARE\JavaSoft\Java Web Start\1.2
Found and removed: SOFTWARE\JavaSoft\Java Web Start\1.2.0_01
Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0000-ABCDEFFEDCBA}
Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0001-ABCDEFFEDCBA}
Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0001-ABCDEFFEDCBB}
Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0002-ABCDEFFEDCBA}
Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0002-ABCDEFFEDCBB}
Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0003-ABCDEFFEDCBA}
Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0003-ABCDEFFEDCBB}
Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0004-ABCDEFFEDCBA}
Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0004-ABCDEFFEDCBB}
Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0005-ABCDEFFEDCBA}
Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0005-ABCDEFFEDCBB}
Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0006-ABCDEFFEDCBA}
Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0006-ABCDEFFEDCBB}
Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0007-ABCDEFFEDCBA}
Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0007-ABCDEFFEDCBB}
Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0008-ABCDEFFEDCBA}
Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0008-ABCDEFFEDCBB}
Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0009-ABCDEFFEDCBA}
Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0009-ABCDEFFEDCBB}
Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0010-ABCDEFFEDCBA}
Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0010-ABCDEFFEDCBB}
Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0011-ABCDEFFEDCBA}
Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0011-ABCDEFFEDCBB}
Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0012-ABCDEFFEDCBA}
Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0012-ABCDEFFEDCBB}
Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0013-ABCDEFFEDCBA}
Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0013-ABCDEFFEDCBB}
Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0014-ABCDEFFEDCBA}
Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0014-ABCDEFFEDCBB}
Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0015-ABCDEFFEDCBA}
Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0015-ABCDEFFEDCBB}
Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0016-ABCDEFFEDCBA}
Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0016-ABCDEFFEDCBB}
Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0017-ABCDEFFEDCBA}
Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0017-ABCDEFFEDCBB}
Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0018-ABCDEFFEDCBA}
Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0018-ABCDEFFEDCBB}
Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0019-ABCDEFFEDCBA}
Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0019-ABCDEFFEDCBB}
Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0020-ABCDEFFEDCBA}
Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0020-ABCDEFFEDCBB}
Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0021-ABCDEFFEDCBA}
Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0021-ABCDEFFEDCBB}
Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0022-ABCDEFFEDCBA}
Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0022-ABCDEFFEDCBB}
Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0023-ABCDEFFEDCBA}
Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0023-ABCDEFFEDCBB}
Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0024-ABCDEFFEDCBA}
Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0024-ABCDEFFEDCBB}
Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0025-ABCDEFFEDCBA}
Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0025-ABCDEFFEDCBB}
Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0026-ABCDEFFEDCBA}
Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0026-ABCDEFFEDCBB}
Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0027-ABCDEFFEDCBA}
Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0027-ABCDEFFEDCBB}
Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0028-ABCDEFFEDCBA}
Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0028-ABCDEFFEDCBB}
Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0029-ABCDEFFEDCBA}
Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0029-ABCDEFFEDCBB}
Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0030-ABCDEFFEDCBA}
Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0030-ABCDEFFEDCBB}
Found and removed: SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\Folders\\C:\Program Files\Common Files\Java\Update\Base Images\jre1.5.0.b64\
Found and removed: SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\Folders\\C:\Program Files\Java\jre1.5.0_06\
Found and removed: SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\Folders\\C:\Program Files\Java\jre1.5.0_07\
Found and removed: SOFTWARE\Microsoft\Windows\CurrentVersion\SharedDlls\C:\Program Files\Common Files\Java\Update\Base Images\jre1.5.0.b64\core1.zip
Found and removed: SOFTWARE\Microsoft\Windows\CurrentVersion\SharedDlls\C:\Program Files\Common Files\Java\Update\Base Images\jre1.5.0.b64\core2.zip
Found and removed: SOFTWARE\Microsoft\Windows\CurrentVersion\SharedDlls\C:\Program Files\Common Files\Java\Update\Base Images\jre1.5.0.b64\core3.zip
————————————
Finished reporting.
ComboFix log -
ComboFix 09-02-06.01 - Andy 2009-02-06 23:04:43.2 - NTFSx86
Microsoft Windows XP Professional 5.1.2600.2.1252.1.1033.18.3071.2515 [GMT -5:00]
Running from: c:\documents and settings\[removed]\Desktop\ComboFix.exe
Command switches used :: c:\documents and settings\Andy\Desktop\CFScript.txt
FW: Trend Micro OfficeScan Enterprise Client Firewall *disabled*
* Created a new restore point
FILE ::
c:\docume~1\Jessica\LOCALS~1\Temp\asbp2poa.sys
f:\documents and settings\Andrew\Desktop\Old C drive\WINDOWS\Desktop\laptop.zip
f:\documents and settings\Andrew\Desktop\Old C drive\WINDOWS\Desktop\old folder folder\old hdd\signage\eds labels\Pfeifferlabel.jpg
f:\old c drive\WINDOWS\Desktop\laptop.zip
f:\old c drive\WINDOWS\Desktop\old folder folder\old hdd\signage\eds labels\Pfeifferlabel.jpg
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
c:\documents and settings\Jessica\Application Data\Sun\Java\Deployment\cache\javapi\v1.0
c:\documents and settings\Jessica\Application Data\Sun\Java\Deployment\cache\javapi\v1.0\file\2galaxy.jpg-647ce554-2102c78d.idx
c:\documents and settings\Jessica\Application Data\Sun\Java\Deployment\cache\javapi\v1.0\file\2galaxy.jpg-647ce554-2102c78d.jpg
c:\documents and settings\Jessica\Application Data\Sun\Java\Deployment\cache\javapi\v1.0\file\2sam.jpg-20a1d3af-15547c87.idx
c:\documents and settings\Jessica\Application Data\Sun\Java\Deployment\cache\javapi\v1.0\file\2sam.jpg-20a1d3af-15547c87.jpg
c:\documents and settings\Jessica\Application Data\Sun\Java\Deployment\cache\javapi\v1.0\file\a_ws_theme_2.au-13d1aae-759c6000.au
c:\documents and settings\Jessica\Application Data\Sun\Java\Deployment\cache\javapi\v1.0\file\a_ws_theme_2.au-13d1aae-759c6000.idx
c:\documents and settings\Jessica\Application Data\Sun\Java\Deployment\cache\javapi\v1.0\file\applet.gif-1074eacd-481cfce6.gif
c:\documents and settings\Jessica\Application Data\Sun\Java\Deployment\cache\javapi\v1.0\file\applet.gif-1074eacd-481cfce6.idx
c:\documents and settings\Jessica\Application Data\Sun\Java\Deployment\cache\javapi\v1.0\file\apXPDropDown.class-35d6b28c-2f342c6f.class
c:\documents and settings\Jessica\Application Data\Sun\Java\Deployment\cache\javapi\v1.0\file\apXPDropDown.class-35d6b28c-2f342c6f.idx
c:\documents and settings\Jessica\Application Data\Sun\Java\Deployment\cache\javapi\v1.0\file\ARROW.AU-1efbb99-69b0c4d9.AU
c:\documents and settings\Jessica\Application Data\Sun\Java\Deployment\cache\javapi\v1.0\file\ARROW.AU-1efbb99-69b0c4d9.idx
c:\documents and settings\Jessica\Application Data\Sun\Java\Deployment\cache\javapi\v1.0\file\audioplayer.class-21de4a59-5642f114.class
c:\documents and settings\Jessica\Application Data\Sun\Java\Deployment\cache\javapi\v1.0\file\audioplayer.class-21de4a59-5642f114.idx
c:\documents and settings\Jessica\Application Data\Sun\Java\Deployment\cache\javapi\v1.0\file\audiopreloader.class-35af017a-106c44d5.class
c:\documents and settings\Jessica\Application Data\Sun\Java\Deployment\cache\javapi\v1.0\file\audiopreloader.class-35af017a-106c44d5.idx
c:\documents and settings\Jessica\Application Data\Sun\Java\Deployment\cache\javapi\v1.0\file\bien-2.au-53b41fd3-7a7b7884.au
c:\documents and settings\Jessica\Application Data\Sun\Java\Deployment\cache\javapi\v1.0\file\bien-2.au-53b41fd3-7a7b7884.idx
c:\documents and settings\Jessica\Application Data\Sun\Java\Deployment\cache\javapi\v1.0\file\bien-3.au-53b49432-6152f879.au
c:\documents and settings\Jessica\Application Data\Sun\Java\Deployment\cache\javapi\v1.0\file\bien-3.au-53b49432-6152f879.idx
c:\documents and settings\Jessica\Application Data\Sun\Java\Deployment\cache\javapi\v1.0\file\bien-4.au-53b50891-56bc7b43.au
c:\documents and settings\Jessica\Application Data\Sun\Java\Deployment\cache\javapi\v1.0\file\bien-4.au-53b50891-56bc7b43.idx
c:\documents and settings\Jessica\Application Data\Sun\Java\Deployment\cache\javapi\v1.0\file\click-3.au-388dd7b5-54380161.au
c:\documents and settings\Jessica\Application Data\Sun\Java\Deployment\cache\javapi\v1.0\file\click-3.au-388dd7b5-54380161.idx
c:\documents and settings\Jessica\Application Data\Sun\Java\Deployment\cache\javapi\v1.0\file\clrbook.gif-495dfc90-6f4551a7.gif
c:\documents and settings\Jessica\Application Data\Sun\Java\Deployment\cache\javapi\v1.0\file\clrbook.gif-495dfc90-6f4551a7.idx
c:\documents and settings\Jessica\Application Data\Sun\Java\Deployment\cache\javapi\v1.0\file\color_friends.gif-69c9023a-6afeb2a9.gif
c:\documents and settings\Jessica\Application Data\Sun\Java\Deployment\cache\javapi\v1.0\file\color_friends.gif-69c9023a-6afeb2a9.idx
c:\documents and settings\Jessica\Application Data\Sun\Java\Deployment\cache\javapi\v1.0\file\color_jorge.gif-2b41a1d0-55b9a0d4.gif
c:\documents and settings\Jessica\Application Data\Sun\Java\Deployment\cache\javapi\v1.0\file\color_jorge.gif-2b41a1d0-55b9a0d4.idx
c:\documents and settings\Jessica\Application Data\Sun\Java\Deployment\cache\javapi\v1.0\file\color_puppy.gif-3acc4639-27457b2d.gif
c:\documents and settings\Jessica\Application Data\Sun\Java\Deployment\cache\javapi\v1.0\file\color_puppy.gif-3acc4639-27457b2d.idx
c:\documents and settings\Jessica\Application Data\Sun\Java\Deployment\cache\javapi\v1.0\file\count.au-7cc44774-21adfba0.au
c:\documents and settings\Jessica\Application Data\Sun\Java\Deployment\cache\javapi\v1.0\file\count.au-7cc44774-21adfba0.idx
c:\documents and settings\Jessica\Application Data\Sun\Java\Deployment\cache\javapi\v1.0\file\earth.jpg-6be9dddc-43a1a5e4.idx
c:\documents and settings\Jessica\Application Data\Sun\Java\Deployment\cache\javapi\v1.0\file\earth.jpg-6be9dddc-43a1a5e4.jpg
c:\documents and settings\Jessica\Application Data\Sun\Java\Deployment\cache\javapi\v1.0\file\entryway_450.jpg-f78ec34-7c5821c2.idx
c:\documents and settings\Jessica\Application Data\Sun\Java\Deployment\cache\javapi\v1.0\file\entryway_450.jpg-f78ec34-7c5821c2.jpg
c:\documents and settings\Jessica\Application Data\Sun\Java\Deployment\cache\javapi\v1.0\file\esquela.au-706d4a1c-1b517d4d.au
c:\documents and settings\Jessica\Application Data\Sun\Java\Deployment\cache\javapi\v1.0\file\esquela.au-706d4a1c-1b517d4d.idx
c:\documents and settings\Jessica\Application Data\Sun\Java\Deployment\cache\javapi\v1.0\file\finish-3.au-d8cc390-2ea71c66.au
c:\documents and settings\Jessica\Application Data\Sun\Java\Deployment\cache\javapi\v1.0\file\finish-3.au-d8cc390-2ea71c66.idx
c:\documents and settings\Jessica\Application Data\Sun\Java\Deployment\cache\javapi\v1.0\file\getDoubles.class-3727b7fc-767abb9a.class
c:\documents and settings\Jessica\Application Data\Sun\Java\Deployment\cache\javapi\v1.0\file\getDoubles.class-3727b7fc-767abb9a.idx
c:\documents and settings\Jessica\Application Data\Sun\Java\Deployment\cache\javapi\v1.0\file\hola-4.au-18b34e85-359bfccd.au
c:\documents and settings\Jessica\Application Data\Sun\Java\Deployment\cache\javapi\v1.0\file\hola-4.au-18b34e85-359bfccd.idx
c:\documents and settings\Jessica\Application Data\Sun\Java\Deployment\cache\javapi\v1.0\file\hola-5.au-18b3c2e4-7bd52bf7.au
c:\documents and settings\Jessica\Application Data\Sun\Java\Deployment\cache\javapi\v1.0\file\hola-5.au-18b3c2e4-7bd52bf7.idx
c:\documents and settings\Jessica\Application Data\Sun\Java\Deployment\cache\javapi\v1.0\file\hola-6.au-18b43743-448ae503.au
c:\documents and settings\Jessica\Application Data\Sun\Java\Deployment\cache\javapi\v1.0\file\hola-6.au-18b43743-448ae503.idx
c:\documents and settings\Jessica\Application Data\Sun\Java\Deployment\cache\javapi\v1.0\file\Honor.gif-5e314986-2de5371c.gif
c:\documents and settings\Jessica\Application Data\Sun\Java\Deployment\cache\javapi\v1.0\file\Honor.gif-5e314986-2de5371c.idx
c:\documents and settings\Jessica\Application Data\Sun\Java\Deployment\cache\javapi\v1.0\file\jumpstrp.gif-568c3105-1d2e9201.gif
c:\documents and settings\Jessica\Application Data\Sun\Java\Deployment\cache\javapi\v1.0\file\jumpstrp.gif-568c3105-1d2e9201.idx
c:\documents and settings\Jessica\Application Data\Sun\Java\Deployment\cache\javapi\v1.0\file\JVMDetect.class-71e1c178-2368d752.class
c:\documents and settings\Jessica\Application Data\Sun\Java\Deployment\cache\javapi\v1.0\file\JVMDetect.class-71e1c178-2368d752.idx
c:\documents and settings\Jessica\Application Data\Sun\Java\Deployment\cache\javapi\v1.0\file\kitchen1_450.jpg-5788a404-19fb755e.idx
c:\documents and settings\Jessica\Application Data\Sun\Java\Deployment\cache\javapi\v1.0\file\kitchen1_450.jpg-5788a404-19fb755e.jpg
c:\documents and settings\Jessica\Application Data\Sun\Java\Deployment\cache\javapi\v1.0\file\labor.au-5adbdf89-59c57a88.au
c:\documents and settings\Jessica\Application Data\Sun\Java\Deployment\cache\javapi\v1.0\file\labor.au-5adbdf89-59c57a88.idx
c:\documents and settings\Jessica\Application Data\Sun\Java\Deployment\cache\javapi\v1.0\file\livingroom1_450.jpg-26ea5021-4be85370.idx
c:\documents and settings\Jessica\Application Data\Sun\Java\Deployment\cache\javapi\v1.0\file\livingroom1_450.jpg-26ea5021-4be85370.jpg
c:\documents and settings\Jessica\Application Data\Sun\Java\Deployment\cache\javapi\v1.0\file\livingroom1_450.jpg-3cee146a-1a5025fd.idx
c:\documents and settings\Jessica\Application Data\Sun\Java\Deployment\cache\javapi\v1.0\file\livingroom1_450.jpg-3cee146a-1a5025fd.jpg
c:\documents and settings\Jessica\Application Data\Sun\Java\Deployment\cache\javapi\v1.0\file\LoadingPano.gif-4154700e-4320c640.gif
c:\documents and settings\Jessica\Application Data\Sun\Java\Deployment\cache\javapi\v1.0\file\LoadingPano.gif-4154700e-4320c640.idx
c:\documents and settings\Jessica\Application Data\Sun\Java\Deployment\cache\javapi\v1.0\file\look-schoolyard.au-36c29308-6a1e64d4.au
c:\documents and settings\Jessica\Application Data\Sun\Java\Deployment\cache\javapi\v1.0\file\look-schoolyard.au-36c29308-6a1e64d4.idx
c:\documents and settings\Jessica\Application Data\Sun\Java\Deployment\cache\javapi\v1.0\file\masterbedroom1_450.jpg-2ad94e6e-5ee619f3.idx
c:\documents and settings\Jessica\Application Data\Sun\Java\Deployment\cache\javapi\v1.0\file\masterbedroom1_450.jpg-2ad94e6e-5ee619f3.jpg
c:\documents and settings\Jessica\Application Data\Sun\Java\Deployment\cache\javapi\v1.0\file\MENUSEL.AU-5cb8a129-311d9524.AU
c:\documents and settings\Jessica\Application Data\Sun\Java\Deployment\cache\javapi\v1.0\file\MENUSEL.AU-5cb8a129-311d9524.idx
c:\documents and settings\Jessica\Application Data\Sun\Java\Deployment\cache\javapi\v1.0\file\MultiAudioClipPlayer.class-3d2a0e1f-2b0d8872.class
c:\documents and settings\Jessica\Application Data\Sun\Java\Deployment\cache\javapi\v1.0\file\MultiAudioClipPlayer.class-3d2a0e1f-2b0d8872.idx
c:\documents and settings\Jessica\Application Data\Sun\Java\Deployment\cache\javapi\v1.0\file\MultiAudioClipPlayer.class-8329380-47e3895a.class
c:\documents and settings\Jessica\Application Data\Sun\Java\Deployment\cache\javapi\v1.0\file\MultiAudioClipPlayer.class-8329380-47e3895a.idx
c:\documents and settings\Jessica\Application Data\Sun\Java\Deployment\cache\javapi\v1.0\file\newsflash.class-482b776a-338f826b.class
c:\documents and settings\Jessica\Application Data\Sun\Java\Deployment\cache\javapi\v1.0\file\newsflash.class-482b776a-338f826b.idx
c:\documents and settings\Jessica\Application Data\Sun\Java\Deployment\cache\javapi\v1.0\file\nextgame.gif-206554fb-5cf76fe6.gif
c:\documents and settings\Jessica\Application Data\Sun\Java\Deployment\cache\javapi\v1.0\file\nextgame.gif-206554fb-5cf76fe6.idx
c:\documents and settings\Jessica\Application Data\Sun\Java\Deployment\cache\javapi\v1.0\file\nextgame.gif-227974dd-2be4fe4c.gif
c:\documents and settings\Jessica\Application Data\Sun\Java\Deployment\cache\javapi\v1.0\file\nextgame.gif-227974dd-2be4fe4c.idx
c:\documents and settings\Jessica\Application Data\Sun\Java\Deployment\cache\javapi\v1.0\file\nina.au-75f1bdda-1a324153.au
c:\documents and settings\Jessica\Application Data\Sun\Java\Deployment\cache\javapi\v1.0\file\nina.au-75f1bdda-1a324153.idx
c:\documents and settings\Jessica\Application Data\Sun\Java\Deployment\cache\javapi\v1.0\file\no.au-41fb4067-4db569ad.au
c:\documents and settings\Jessica\Application Data\Sun\Java\Deployment\cache\javapi\v1.0\file\no.au-41fb4067-4db569ad.idx
c:\documents and settings\Jessica\Application Data\Sun\Java\Deployment\cache\javapi\v1.0\file\number-1.au-692f4ddc-1aaa28d5.au
c:\documents and settings\Jessica\Application Data\Sun\Java\Deployment\cache\javapi\v1.0\file\number-1.au-692f4ddc-1aaa28d5.idx
c:\documents and settings\Jessica\Application Data\Sun\Java\Deployment\cache\javapi\v1.0\file\number-2.au-692fc23b-47d56764.au
c:\documents and settings\Jessica\Application Data\Sun\Java\Deployment\cache\javapi\v1.0\file\number-2.au-692fc23b-47d56764.idx
c:\documents and settings\Jessica\Application Data\Sun\Java\Deployment\cache\javapi\v1.0\file\number-3.au-6930369a-3bdb297c.au
c:\documents and settings\Jessica\Application Data\Sun\Java\Deployment\cache\javapi\v1.0\file\number-3.au-6930369a-3bdb297c.idx
c:\documents and settings\Jessica\Application Data\Sun\Java\Deployment\cache\javapi\v1.0\file\numberofday.au-454202e7-643e7c74.au
c:\documents and settings\Jessica\Application Data\Sun\Java\Deployment\cache\javapi\v1.0\file\numberofday.au-454202e7-643e7c74.idx
c:\documents and settings\Jessica\Application Data\Sun\Java\Deployment\cache\javapi\v1.0\file\organ.au-61674f32-675f1133.au
c:\documents and settings\Jessica\Application Data\Sun\Java\Deployment\cache\javapi\v1.0\file\organ.au-61674f32-675f1133.idx
c:\documents and settings\Jessica\Application Data\Sun\Java\Deployment\cache\javapi\v1.0\file\paint01c.gif-522c957a-49efb17a.gif
c:\documents and settings\Jessica\Application Data\Sun\Java\Deployment\cache\javapi\v1.0\file\paint01c.gif-522c957a-49efb17a.idx
c:\documents and settings\Jessica\Application Data\Sun\Java\Deployment\cache\javapi\v1.0\file\paintbox.class-42113c78-7b3f82e6.class
c:\documents and settings\Jessica\Application Data\Sun\Java\Deployment\cache\javapi\v1.0\file\paintbox.class-42113c78-7b3f82e6.idx
c:\documents and settings\Jessica\Application Data\Sun\Java\Deployment\cache\javapi\v1.0\file\palcup.gif-90fb59-573be683.gif
c:\documents and settings\Jessica\Application Data\Sun\Java\Deployment\cache\javapi\v1.0\file\palcup.gif-90fb59-573be683.idx
c:\documents and settings\Jessica\Application Data\Sun\Java\Deployment\cache\javapi\v1.0\file\pano1.jpg-22f2f56d-29d47ba7.idx
c:\documents and settings\Jessica\Application Data\Sun\Java\Deployment\cache\javapi\v1.0\file\pano1.jpg-22f2f56d-29d47ba7.jpg
c:\documents and settings\Jessica\Application Data\Sun\Java\Deployment\cache\javapi\v1.0\file\pano2.jpg-23010cee-3d060f10.idx
c:\documents and settings\Jessica\Application Data\Sun\Java\Deployment\cache\javapi\v1.0\file\pano2.jpg-23010cee-3d060f10.jpg
c:\documents and settings\Jessica\Application Data\Sun\Java\Deployment\cache\javapi\v1.0\file\pano3.jpg-230f246f-714f7d22.idx
c:\documents and settings\Jessica\Application Data\Sun\Java\Deployment\cache\javapi\v1.0\file\pano3.jpg-230f246f-714f7d22.jpg
c:\documents and settings\Jessica\Application Data\Sun\Java\Deployment\cache\javapi\v1.0\file\panohead.jpg-7a79bc1e-326a1ab8.idx
c:\documents and settings\Jessica\Application Data\Sun\Java\Deployment\cache\javapi\v1.0\file\panohead.jpg-7a79bc1e-326a1ab8.jpg
c:\documents and settings\Jessica\Application Data\Sun\Java\Deployment\cache\javapi\v1.0\file\payoff-3.au-574d54dc-48325748.au
c:\documents and settings\Jessica\Application Data\Sun\Java\Deployment\cache\javapi\v1.0\file\payoff-3.au-574d54dc-48325748.idx
c:\documents and settings\Jessica\Application Data\Sun\Java\Deployment\cache\javapi\v1.0\file\payoff.au-5e5752b8-2cefcb7b.au
c:\documents and settings\Jessica\Application Data\Sun\Java\Deployment\cache\javapi\v1.0\file\payoff.au-5e5752b8-2cefcb7b.idx
c:\documents and settings\Jessica\Application Data\Sun\Java\Deployment\cache\javapi\v1.0\file\pdr-tlogo.gif-d3b9ebe-401d4468.gif
c:\documents and settings\Jessica\Application Data\Sun\Java\Deployment\cache\javapi\v1.0\file\pdr-tlogo.gif-d3b9ebe-401d4468.idx
c:\documents and settings\Jessica\Application Data\Sun\Java\Deployment\cache\javapi\v1.0\file\PERC.AU-144cef64-46c8e381.AU
c:\documents and settings\Jessica\Application Data\Sun\Java\Deployment\cache\javapi\v1.0\file\PERC.AU-144cef64-46c8e381.idx
c:\documents and settings\Jessica\Application Data\Sun\Java\Deployment\cache\javapi\v1.0\file\play-1.au-6641a5f0-288af849.au
c:\documents and settings\Jessica\Application Data\Sun\Java\Deployment\cache\javapi\v1.0\file\play-1.au-6641a5f0-288af849.idx
c:\documents and settings\Jessica\Application Data\Sun\Java\Deployment\cache\javapi\v1.0\file\play-2.au-66421a4f-534a8f7a.au
c:\documents and settings\Jessica\Application Data\Sun\Java\Deployment\cache\javapi\v1.0\file\play-2.au-66421a4f-534a8f7a.idx
c:\documents and settings\Jessica\Application Data\Sun\Java\Deployment\cache\javapi\v1.0\file\play-3.au-66428eae-228d1a60.au
c:\documents and settings\Jessica\Application Data\Sun\Java\Deployment\cache\javapi\v1.0\file\play-3.au-66428eae-228d1a60.idx
c:\documents and settings\Jessica\Application Data\Sun\Java\Deployment\cache\javapi\v1.0\file\PlayFour.class-10b4be2c-1728af65.class
c:\documents and settings\Jessica\Application Data\Sun\Java\Deployment\cache\javapi\v1.0\file\PlayFour.class-10b4be2c-1728af65.idx
c:\documents and settings\Jessica\Application Data\Sun\Java\Deployment\cache\javapi\v1.0\file\pots.gif-4e49f9d4-18c0b39a.gif
c:\documents and settings\Jessica\Application Data\Sun\Java\Deployment\cache\javapi\v1.0\file\pots.gif-4e49f9d4-18c0b39a.idx
c:\documents and settings\Jessica\Application Data\Sun\Java\Deployment\cache\javapi\v1.0\file\RESET.AU-39594493-7253c211.AU
c:\documents and settings\Jessica\Application Data\Sun\Java\Deployment\cache\javapi\v1.0\file\RESET.AU-39594493-7253c211.idx
c:\documents and settings\Jessica\Application Data\Sun\Java\Deployment\cache\javapi\v1.0\file\right.au-65c30253-22de09ff.au
c:\documents and settings\Jessica\Application Data\Sun\Java\Deployment\cache\javapi\v1.0\file\right.au-65c30253-22de09ff.idx
c:\documents and settings\Jessica\Application Data\Sun\Java\Deployment\cache\javapi\v1.0\file\right.au-67be7511-47564268.au
c:\documents and settings\Jessica\Application Data\Sun\Java\Deployment\cache\javapi\v1.0\file\right.au-67be7511-47564268.idx
c:\documents and settings\Jessica\Application Data\Sun\Java\Deployment\cache\javapi\v1.0\file\ring.gif-55c0c246-4127abc5.gif
c:\documents and settings\Jessica\Application Data\Sun\Java\Deployment\cache\javapi\v1.0\file\ring.gif-55c0c246-4127abc5.idx
c:\documents and settings\Jessica\Application Data\Sun\Java\Deployment\cache\javapi\v1.0\file\skip2.gif-7bd5d76f-4009de1d.gif
c:\documents and settings\Jessica\Application Data\Sun\Java\Deployment\cache\javapi\v1.0\file\skip2.gif-7bd5d76f-4009de1d.idx
c:\documents and settings\Jessica\Application Data\Sun\Java\Deployment\cache\javapi\v1.0\file\sol.au-78745e94-5eed3346.au
c:\documents and settings\Jessica\Application Data\Sun\Java\Deployment\cache\javapi\v1.0\file\sol.au-78745e94-5eed3346.idx
c:\documents and settings\Jessica\Application Data\Sun\Java\Deployment\cache\javapi\v1.0\file\SQUISH.AU-47a30a63-484b397a.AU
c:\documents and settings\Jessica\Application Data\Sun\Java\Deployment\cache\javapi\v1.0\file\SQUISH.AU-47a30a63-484b397a.idx
c:\documents and settings\Jessica\Application Data\Sun\Java\Deployment\cache\javapi\v1.0\file\STOP.AU-239fefa6-515972fd.AU
c:\documents and settings\Jessica\Application Data\Sun\Java\Deployment\cache\javapi\v1.0\file\STOP.AU-239fefa6-515972fd.idx
c:\documents and settings\Jessica\Application Data\Sun\Java\Deployment\cache\javapi\v1.0\file\STOP.AU-4c73f4c8-39025284.AU
c:\documents and settings\Jessica\Application Data\Sun\Java\Deployment\cache\javapi\v1.0\file\STOP.AU-4c73f4c8-39025284.idx
c:\documents and settings\Jessica\Application Data\Sun\Java\Deployment\cache\javapi\v1.0\file\strip0.gif-190c011e-144f6745.gif
c:\documents and settings\Jessica\Application Data\Sun\Java\Deployment\cache\javapi\v1.0\file\strip0.gif-190c011e-144f6745.idx
c:\documents and settings\Jessica\Application Data\Sun\Java\Deployment\cache\javapi\v1.0\file\strip1.gif-191a189f-119fea0f.gif
c:\documents and settings\Jessica\Application Data\Sun\Java\Deployment\cache\javapi\v1.0\file\strip1.gif-191a189f-119fea0f.idx
c:\documents and settings\Jessica\Application Data\Sun\Java\Deployment\cache\javapi\v1.0\file\strip2.gif-19283020-3954693c.gif
c:\documents and settings\Jessica\Application Data\Sun\Java\Deployment\cache\javapi\v1.0\file\strip2.gif-19283020-3954693c.idx
c:\documents and settings\Jessica\Application Data\Sun\Java\Deployment\cache\javapi\v1.0\file\strip3.gif-193647a1-74ad6391.gif
c:\documents and settings\Jessica\Application Data\Sun\Java\Deployment\cache\javapi\v1.0\file\strip3.gif-193647a1-74ad6391.idx
c:\documents and settings\Jessica\Application Data\Sun\Java\Deployment\cache\javapi\v1.0\file\sun.jpg-409eccde-2edefd31.idx
c:\documents and settings\Jessica\Application Data\Sun\Java\Deployment\cache\javapi\v1.0\file\sun.jpg-409eccde-2edefd31.jpg
c:\documents and settings\Jessica\Application Data\Sun\Java\Deployment\cache\javapi\v1.0\file\thunder.au-3c0f203f-23b674e9.au
c:\documents and settings\Jessica\Application Data\Sun\Java\Deployment\cache\javapi\v1.0\file\thunder.au-3c0f203f-23b674e9.idx
c:\documents and settings\Jessica\Application Data\Sun\Java\Deployment\cache\javapi\v1.0\file\tiger.jpg-7c0573d1-111d8cdd.idx
c:\documents and settings\Jessica\Application Data\Sun\Java\Deployment\cache\javapi\v1.0\file\tiger.jpg-7c0573d1-111d8cdd.jpg
c:\documents and settings\Jessica\Application Data\Sun\Java\Deployment\cache\javapi\v1.0\file\TinyAudioPlayer.class-13f0595e-7b3af7b2.class
c:\documents and settings\Jessica\Application Data\Sun\Java\Deployment\cache\javapi\v1.0\file\TinyAudioPlayer.class-13f0595e-7b3af7b2.idx
c:\documents and settings\Jessica\Application Data\Sun\Java\Deployment\cache\javapi\v1.0\file\tocountthem.au-2297f393-33c83475.au
c:\documents and settings\Jessica\Application Data\Sun\Java\Deployment\cache\javapi\v1.0\file\tocountthem.au-2297f393-33c83475.idx
c:\documents and settings\Jessica\Application Data\Sun\Java\Deployment\cache\javapi\v1.0\file\topback.gif-a74798-414eed41.gif
c:\documents and settings\Jessica\Application Data\Sun\Java\Deployment\cache\javapi\v1.0\file\topback.gif-a74798-414eed41.idx
c:\documents and settings\Jessica\Application Data\Sun\Java\Deployment\cache\javapi\v1.0\file\TotRwdPieChart.class-5e53fa88-14239f03.class
c:\documents and settings\Jessica\Application Data\Sun\Java\Deployment\cache\javapi\v1.0\file\TotRwdPieChart.class-5e53fa88-14239f03.idx
c:\documents and settings\Jessica\Application Data\Sun\Java\Deployment\cache\javapi\v1.0\file\turn.au-23a45b00-52b586db.au
c:\documents and settings\Jessica\Application Data\Sun\Java\Deployment\cache\javapi\v1.0\file\turn.au-23a45b00-52b586db.idx
c:\documents and settings\Jessica\Application Data\Sun\Java\Deployment\cache\javapi\v1.0\file\ULTRA%20DeepFields.jpg-51dbfbfe-6ad883b2.idx
c:\documents and settings\Jessica\Application Data\Sun\Java\Deployment\cache\javapi\v1.0\file\ULTRA%20DeepFields.jpg-51dbfbfe-6ad883b2.jpg
c:\documents and settings\Jessica\Application Data\Sun\Java\Deployment\cache\javapi\v1.0\file\v51.class-66fadd81-2a11d97d.class
c:\documents and settings\Jessica\Application Data\Sun\Java\Deployment\cache\javapi\v1.0\file\v51.class-66fadd81-2a11d97d.idx
c:\documents and settings\Jessica\Application Data\Sun\Java\Deployment\cache\javapi\v1.0\file\v51Sleep.class-7e9ad752-3f8a5869.class
c:\documents and settings\Jessica\Application Data\Sun\Java\Deployment\cache\javapi\v1.0\file\v51Sleep.class-7e9ad752-3f8a5869.idx
c:\documents and settings\Jessica\Application Data\Sun\Java\Deployment\cache\javapi\v1.0\file\woolly.jpg-306fdfc4-213a95cc.idx
c:\documents and settings\Jessica\Application Data\Sun\Java\Deployment\cache\javapi\v1.0\file\woolly.jpg-306fdfc4-213a95cc.jpg
c:\documents and settings\Jessica\Application Data\Sun\Java\Deployment\cache\javapi\v1.0\file\WRNGPLC.AU-3ebac4cf-7851578c.AU
c:\documents and settings\Jessica\Application Data\Sun\Java\Deployment\cache\javapi\v1.0\file\WRNGPLC.AU-3ebac4cf-7851578c.idx
c:\documents and settings\Jessica\Application Data\Sun\Java\Deployment\cache\javapi\v1.0\file\wrong.au-57366122-4691a1fc.au
c:\documents and settings\Jessica\Application Data\Sun\Java\Deployment\cache\javapi\v1.0\file\wrong.au-57366122-4691a1fc.idx
c:\documents and settings\Jessica\Application Data\Sun\Java\Deployment\cache\javapi\v1.0\file\wrong.au-5931d3e0-5907970a.au
c:\documents and settings\Jessica\Application Data\Sun\Java\Deployment\cache\javapi\v1.0\file\wrong.au-5931d3e0-5907970a.idx
c:\documents and settings\Jessica\Application Data\Sun\Java\Deployment\cache\javapi\v1.0\jar\ColoringBook.zip-f16ee8e-312265a6.idx
c:\documents and settings\Jessica\Application Data\Sun\Java\Deployment\cache\javapi\v1.0\jar\ColoringBook.zip-f16ee8e-312265a6.zip
c:\documents and settings\Jessica\Application Data\Sun\Java\Deployment\cache\javapi\v1.0\jar\cryptojN.jar-187ce279-7fa66dd0.idx
c:\documents and settings\Jessica\Application Data\Sun\Java\Deployment\cache\javapi\v1.0\jar\cryptojN.jar-187ce279-7fa66dd0.zip
c:\documents and settings\Jessica\Application Data\Sun\Java\Deployment\cache\javapi\v1.0\jar\DuriusWaterPic.jar-6f87cc62-6796c951.idx
c:\documents and settings\Jessica\Application Data\Sun\Java\Deployment\cache\javapi\v1.0\jar\DuriusWaterPic.jar-6f87cc62-6796c951.zip
c:\documents and settings\Jessica\Application Data\Sun\Java\Deployment\cache\javapi\v1.0\jar\elmo.jar-3009a466-2aff9083.idx
c:\documents and settings\Jessica\Application Data\Sun\Java\Deployment\cache\javapi\v1.0\jar\elmo.jar-3009a466-2aff9083.zip
c:\documents and settings\Jessica\Application Data\Sun\Java\Deployment\cache\javapi\v1.0\jar\FacebookPhotoUploader.jar-2cce3b73-7d01c276.idx
c:\documents and settings\Jessica\Application Data\Sun\Java\Deployment\cache\javapi\v1.0\jar\FacebookPhotoUploader.jar-2cce3b73-7d01c276.zip
c:\documents and settings\Jessica\Application Data\Sun\Java\Deployment\cache\javapi\v1.0\jar\FacebookPhotoUploader5.jar-62950ace-30d1398c.idx
c:\documents and settings\Jessica\Application Data\Sun\Java\Deployment\cache\javapi\v1.0\jar\FacebookPhotoUploader5.jar-62950ace-30d1398c.zip
c:\documents and settings\Jessica\Application Data\Sun\Java\Deployment\cache\javapi\v1.0\jar\HeroGuyPaint.jar-49bdd52b-13f1a601.idx
c:\documents and settings\Jessica\Application Data\Sun\Java\Deployment\cache\javapi\v1.0\jar\HeroGuyPaint.jar-49bdd52b-13f1a601.zip
c:\documents and settings\Jessica\Application Data\Sun\Java\Deployment\cache\javapi\v1.0\jar\ImageUploader2.jar-7fc79664-1d300cdd.idx
c:\documents and settings\Jessica\Application Data\Sun\Java\Deployment\cache\javapi\v1.0\jar\ImageUploader2.jar-7fc79664-1d300cdd.zip
c:\documents and settings\Jessica\Application Data\Sun\Java\Deployment\cache\javapi\v1.0\jar\ImageUploader2_vs44.jar-1fa2518e-1df63325.idx
c:\documents and settings\Jessica\Application Data\Sun\Java\Deployment\cache\javapi\v1.0\jar\ImageUploader2_vs44.jar-1fa2518e-1df63325.zip
c:\documents and settings\Jessica\Application Data\Sun\Java\Deployment\cache\javapi\v1.0\jar\JICA-configN.jar-3db89030-366af76f.idx
c:\documents and settings\Jessica\Application Data\Sun\Java\Deployment\cache\javapi\v1.0\jar\JICA-configN.jar-3db89030-366af76f.zip
c:\documents and settings\Jessica\Application Data\Sun\Java\Deployment\cache\javapi\v1.0\jar\JICA-coreN.jar-5f250533-21351a51.idx
c:\documents and settings\Jessica\Application Data\Sun\Java\Deployment\cache\javapi\v1.0\jar\JICA-coreN.jar-5f250533-21351a51.zip
c:\documents and settings\Jessica\Application Data\Sun\Java\Deployment\cache\javapi\v1.0\jar\JICA-printerN.jar-31001d5e-3565a2db.idx
c:\documents and settings\Jessica\Application Data\Sun\Java\Deployment\cache\javapi\v1.0\jar\JICA-printerN.jar-31001d5e-3565a2db.zip
c:\documents and settings\Jessica\Application Data\Sun\Java\Deployment\cache\javapi\v1.0\jar\JICA-seamlessN.jar-7aee40bb-6b8014af.idx
c:\documents and settings\Jessica\Application Data\Sun\Java\Deployment\cache\javapi\v1.0\jar\JICA-seamlessN.jar-7aee40bb-6b8014af.zip
c:\documents and settings\Jessica\Application Data\Sun\Java\Deployment\cache\javapi\v1.0\jar\JICA-sicaN.jar-13d40cbe-395fd938.idx
c:\documents and settings\Jessica\Application Data\Sun\Java\Deployment\cache\javapi\v1.0\jar\JICA-sicaN.jar-13d40cbe-395fd938.zip
c:\documents and settings\Jessica\Application Data\Sun\Java\Deployment\cache\javapi\v1.0\jar\jvmimpro.jar-5efd1945-42d8ffc2.idx
c:\documents and settings\Jessica\Application Data\Sun\Java\Deployment\cache\javapi\v1.0\jar\jvmimpro.jar-5efd1945-42d8ffc2.zip
c:\documents and settings\Jessica\Application Data\Sun\Java\Deployment\cache\javapi\v1.0\jar\newsday01.jar-4ff640f-672b1727.idx
c:\documents and settings\Jessica\Application Data\Sun\Java\Deployment\cache\javapi\v1.0\jar\newsday01.jar-4ff640f-672b1727.zip
c:\documents and settings\Jessica\Application Data\Sun\Java\Deployment\cache\javapi\v1.0\jar\npatjava.jar-209bde28-272bbc6d.idx
c:\documents and settings\Jessica\Application Data\Sun\Java\Deployment\cache\javapi\v1.0\jar\npatjava.jar-209bde28-272bbc6d.zip
c:\documents and settings\Jessica\Application Data\Sun\Java\Deployment\cache\javapi\v1.0\jar\ptviewer.jar-32a40a4a-7d35f353.idx
c:\documents and settings\Jessica\Application Data\Sun\Java\Deployment\cache\javapi\v1.0\jar\ptviewer.jar-32a40a4a-7d35f353.zip
c:\documents and settings\Jessica\Application Data\Sun\Java\Deployment\cache\javapi\v1.0\jar\ptviewer.jar-38493d1c-40d6dae9.idx
c:\documents and settings\Jessica\Application Data\Sun\Java\Deployment\cache\javapi\v1.0\jar\ptviewer.jar-38493d1c-40d6dae9.zip
c:\documents and settings\Jessica\Application Data\Sun\Java\Deployment\cache\javapi\v1.0\jar\ptviewer.jar-4966f37a-30296c09.idx
c:\documents and settings\Jessica\Application Data\Sun\Java\Deployment\cache\javapi\v1.0\jar\ptviewer.jar-4966f37a-30296c09.zip
c:\documents and settings\Jessica\Application Data\Sun\Java\Deployment\cache\javapi\v1.0\jar\ScrollDisp2.jar-610753b1-2dd5b88d.idx
c:\documents and settings\Jessica\Application Data\Sun\Java\Deployment\cache\javapi\v1.0\jar\ScrollDisp2.jar-610753b1-2dd5b88d.zip
c:\documents and settings\Jessica\Application Data\Sun\Java\Deployment\cache\javapi\v1.0\jar\TmapCube.jar-39ee6059-6e8cbbbb.idx
c:\documents and settings\Jessica\Application Data\Sun\Java\Deployment\cache\javapi\v1.0\jar\TmapCube.jar-39ee6059-6e8cbbbb.zip
c:\documents and settings\Jessica\Application Data\Sun\Java\Deployment\cache\javapi\v1.0\jar\twviewer.jar-22e66139-37cce2dd.idx
c:\documents and settings\Jessica\Application Data\Sun\Java\Deployment\cache\javapi\v1.0\jar\twviewer.jar-22e66139-37cce2dd.zip
c:\documents and settings\Jessica\Application Data\Sun\Java\Deployment\cache\javapi\v1.0\jar\ZoeGame.jar-23d68ebc-1fc73ca0.idx
c:\documents and settings\Jessica\Application Data\Sun\Java\Deployment\cache\javapi\v1.0\jar\ZoeGame.jar-23d68ebc-1fc73ca0.zip
c:\program files\Trend Micro\OfficeScan Client\SUSPECT
c:\program files\Trend Micro\OfficeScan Client\SUSPECT\{0024342E-7423-4BA4-BD7C-EB58003DCE8C}.exe
c:\program files\Trend Micro\OfficeScan Client\SUSPECT\{0076B20E-2B2D-43B2-8D92-12F818CF8C5F}.exe
c:\program files\Trend Micro\OfficeScan Client\SUSPECT\{0103A7E3-331E-43DF-BC20-6146A4F3E35B}.exe
c:\program files\Trend Micro\OfficeScan Client\SUSPECT\{03D080E6-A39F-4C5A-BC3E-8C024E61053D}.exe
c:\program files\Trend Micro\OfficeScan Client\SUSPECT\{03F612EB-5FB3-4578-A052-82D3098569F7}.exe
c:\program files\Trend Micro\OfficeScan Client\SUSPECT\{057C2EDB-3CE8-4620-AA41-D2C870100969}.exe
c:\program files\Trend Micro\OfficeScan Client\SUSPECT\{05853678-A615-4488-B4FA-3687B2D3400A}.exe
c:\program files\Trend Micro\OfficeScan Client\SUSPECT\{059F5891-012C-484C-9C5D-90437A2E2E60}.exe
c:\program files\Trend Micro\OfficeScan Client\SUSPECT\{05E72921-E09C-4963-8E02-09F72C5DD0E9}.exe
c:\program files\Trend Micro\OfficeScan Client\SUSPECT\{07D13CDA-74EE-4EF7-8FF0-83F1E7A053D2}.exe
c:\program files\Trend Micro\OfficeScan Client\SUSPECT\{08071625-BD2E-476F-9AD2-04DD1C3136C3}.exe
c:\program files\Trend Micro\OfficeScan Client\SUSPECT\{085F8FA7-C829-429B-903B-73748B15C341}.exe
c:\program files\Trend Micro\OfficeScan Client\SUSPECT\{08EB46B1-9960-4831-B698-BBECE673AA0C}.exe
c:\program files\Trend Micro\OfficeScan Client\SUSPECT\{095783EC-9BEF-46D9-9F21-606B68360702}.exe
c:\program files\Trend Micro\OfficeScan Client\SUSPECT\{09A79FA0-72F6-4DF0-814B-78DA4EBE39D9}.exe
c:\program files\Trend Micro\OfficeScan Client\SUSPECT\{0AC797A2-AB3A-418E-951F-FA57D8EF3EAD}.exe
c:\program files\Trend Micro\OfficeScan Client\SUSPECT\{0C682116-97AC-4A52-9D7D-D1A580533D75}.exe
c:\program files\Trend Micro\OfficeScan Client\SUSPECT\{0F618AF7-9F20-49F8-AAAF-FEEE20F15BB8}.exe
c:\program files\Trend Micro\OfficeScan Client\SUSPECT\{0FD9CBBF-679A-4B21-829B-8B8B6CEB7998}.exe
c:\program files\Trend Micro\OfficeScan Client\SUSPECT\{102641DA-94BF-42AF-B1A2-154B94DA446E}.exe
c:\program files\Trend Micro\OfficeScan Client\SUSPECT\{10B1E11D-4774-4EB9-AF8C-BAA303D5602F}.exe
c:\program files\Trend Micro\OfficeScan Client\SUSPECT\{10FCCEBF-4845-4D80-A712-5F1DDF4745A3}.exe
c:\program files\Trend Micro\OfficeScan Client\SUSPECT\{11E78EC3-3505-4C28-9C5B-2AEB07479041}.exe
c:\program files\Trend Micro\OfficeScan Client\SUSPECT\{1341D77C-733A-4316-B42C-54900C00E0C1}.exe
c:\program files\Trend Micro\OfficeScan Client\SUSPECT\{14FA0A95-4703-4BB2-BCC7-3D11CFF987C6}.exe
c:\program files\Trend Micro\OfficeScan Client\SUSPECT\{15412139-E5C2-42EC-8205-358D7579045C}.exe
c:\program files\Trend Micro\OfficeScan Client\SUSPECT\{162B86B1-ED2A-4D86-BCE5-04C62C171DFF}.exe
c:\program files\Trend Micro\OfficeScan Client\SUSPECT\{169DB33A-5FBD-44FA-A9DC-8A73E357EE9E}.exe
c:\program files\Trend Micro\OfficeScan Client\SUSPECT\{16C7533A-125E-4237-B4DF-026001654557}.exe
c:\program files\Trend Micro\OfficeScan Client\SUSPECT\{17E0F41E-BC16-4386-9721-8FA23C984130}.exe
c:\program files\Trend Micro\OfficeScan Client\SUSPECT\{18077D85-12F4-46DD-BBA8-8FDE1C280CE9}.exe
c:\program files\Trend Micro\OfficeScan Client\SUSPECT\{183FA186-E42E-4187-8280-C8EC4B7985D2}.exe
c:\program files\Trend Micro\OfficeScan Client\SUSPECT\{1ABBB395-5DFB-4D0B-A958-982A75488948}.exe
c:\program files\Trend Micro\OfficeScan Client\SUSPECT\{1AD1D8EF-72F3-4826-A144-A4CDCD649C83}.exe
c:\program files\Trend Micro\OfficeScan Client\SUSPECT\{1ADB0666-2BED-4335-BD08-1CB62200B390}.exe
c:\program files\Trend Micro\OfficeScan Client\SUSPECT\{1B9549EE-B0F9-4066-B4C3-8F97D93479D2}.exe
c:\program files\Trend Micro\OfficeScan Client\SUSPECT\{1BB202BE-BB29-45A6-B222-962BFDDF48D1}.exe
c:\program files\Trend Micro\OfficeScan Client\SUSPECT\{1C398595-28ED-4BA5-A473-81303576233F}.exe
c:\program files\Trend Micro\OfficeScan Client\SUSPECT\{1DB62F99-7F1C-41F6-B15D-D6CDD1E6E8D3}.exe
c:\program files\Trend Micro\OfficeScan Client\SUSPECT\{1DC15094-CC01-4ADF-88C0-4622C1A696D1}.exe
c:\program files\Trend Micro\OfficeScan Client\SUSPECT\{1EB2E6A1-9B28-4526-A168-63587682BDFF}.exe
c:\program files\Trend Micro\OfficeScan Client\SUSPECT\{1FE09F07-85EF-4C15-806B-B9BF957AAE91}.exe
c:\program files\Trend Micro\OfficeScan Client\SUSPECT\{1FE41E89-974C-4F0D-A533-C54C1B930E32}.exe
c:\program files\Trend Micro\OfficeScan Client\SUSPECT\{23122034-FD1E-425F-B5B0-93EFF63FC099}.exe
c:\program files\Trend Micro\OfficeScan Client\SUSPECT\{23813485-882E-406A-A2DF-B2EEF70CA7B8}.exe
c:\program files\Trend Micro\OfficeScan Client\SUSPECT\{23CF0435-E605-4129-8DB7-A3C30AECE66B}.exe
c:\program files\Trend Micro\OfficeScan Client\SUSPECT\{2517402A-C43E-4465-AD04-4658FBE610F4}.exe
c:\program files\Trend Micro\OfficeScan Client\SUSPECT\{255EFD54-26D5-412A-AD84-E52B00AE70B7}.exe
c:\program files\Trend Micro\OfficeScan Client\SUSPECT\{25DEB6ED-5905-4E92-A61F-B6F587E6290D}.exe
c:\program files\Trend Micro\OfficeScan Client\SUSPECT\{2609F02A-8EBF-4B79-87CE-17516C932AA2}.exe
c:\program files\Trend Micro\OfficeScan Client\SUSPECT\{263B22AC-AFF0-4862-8BD2-8B83486EDF8A}.exe
c:\program files\Trend Micro\OfficeScan Client\SUSPECT\{26F7316A-E0F7-47FC-8F50-627D8B499AB2}.exe
c:\program files\Trend Micro\OfficeScan Client\SUSPECT\{28E56AF9-07ED-4253-95DA-9E72DFF0B8B2}.exe
c:\program files\Trend Micro\OfficeScan Client\SUSPECT\{295935D3-E1B3-40DF-9B04-45BC7CC7E2C8}.exe
c:\program files\Trend Micro\OfficeScan Client\SUSPECT\{2B05CB97-E170-4AC6-9AB7-2815A7DC03FF}.exe
c:\program files\Trend Micro\OfficeScan Client\SUSPECT\{2BA5CE9F-ED1C-497E-9D5E-969505FE078D}.exe
c:\program files\Trend Micro\OfficeScan Client\SUSPECT\{2CAF9C19-C942-444F-8CFB-EB668AF27066}.exe
c:\program files\Trend Micro\OfficeScan Client\SUSPECT\{2DE52A28-0C24-4287-B099-1B373807DD37}.exe
c:\program files\Trend Micro\OfficeScan Client\SUSPECT\{2F400998-3A11-48E2-B2CC-2D8AB21E8D0F}.exe
c:\program files\Trend Micro\OfficeScan Client\SUSPECT\{3143BEC7-C74B-45E8-8526-9DFAFDF0E707}.exe
c:\program files\Trend Micro\OfficeScan Client\SUSPECT\{31E583AA-DACD-4E21-88CB-8DAF7E26FD6C}.exe
c:\program files\Trend Micro\OfficeScan Client\SUSPECT\{320BF4FC-F93C-4A25-9951-343F3C847A1A}.exe
c:\program files\Trend Micro\OfficeScan Client\SUSPECT\{32585BAE-C0E4-4E6D-B4AA-0B02CF300953}.exe
c:\program files\Trend Micro\OfficeScan Client\SUSPECT\{32851801-43B4-44F4-AE90-52D035AC9B00}.exe
c:\program files\Trend Micro\OfficeScan Client\SUSPECT\{32930834-6828-4E5A-B467-795145AF668E}.exe
c:\program files\Trend Micro\OfficeScan Client\SUSPECT\{344255D4-FD99-4843-B6B0-DC81BB7A8E51}.exe
c:\program files\Trend Micro\OfficeScan Client\SUSPECT\{357996F7-09C0-40EB-9A27-7A69FF8D65D6}.exe
c:\program files\Trend Micro\OfficeScan Client\SUSPECT\{36350E7F-AA40-43EE-9DE4-D8326B57A119}.exe
c:\program files\Trend Micro\OfficeScan Client\SUSPECT\{37810C34-4ECB-47B2-8E22-9F3738A01A74}.exe
c:\program files\Trend Micro\OfficeScan Client\SUSPECT\{39E68A5B-903B-4468-9FF7-9A994F44205E}.exe
c:\program files\Trend Micro\OfficeScan Client\SUSPECT\{3B6D0B4D-49B9-41F8-A8C3-619E3DAF6E78}.exe
c:\program files\Trend Micro\OfficeScan Client\SUSPECT\{3B7C1B9B-99B6-4260-A713-38F7AE508A02}.exe
c:\program files\Trend Micro\OfficeScan Client\SUSPECT\{3BA5A7C7-1739-4C0B-9ACB-B7D6172BA270}.exe
c:\program files\Trend Micro\OfficeScan Client\SUSPECT\{3C249B75-831B-48D6-BB00-FBA47FACBC01}.exe
c:\program files\Trend Micro\OfficeScan Client\SUSPECT\{3DA7C2F2-0E15-4DD7-81CB-D8F189410202}.exe
c:\program files\Trend Micro\OfficeScan Client\SUSPECT\{41FE21CE-01CE-4BE6-A2AC-38700AD24955}.exe
c:\program files\Trend Micro\OfficeScan Client\SUSPECT\{4376106A-B592-4712-B4A2-FCAAFEADB14A}.exe
c:\program files\Trend Micro\OfficeScan Client\SUSPECT\{43D52C3B-8BFB-4F29-BD54-CA87DC3C8D68}.exe
c:\program files\Trend Micro\OfficeScan Client\SUSPECT\{441D8E8B-2DDF-40F9-B2BE-478BEA30EA62}.exe
c:\program files\Trend Micro\OfficeScan Client\SUSPECT\{44589375-CA7D-484E-AE02-6F32517BEB6D}.exe
c:\program files\Trend Micro\OfficeScan Client\SUSPECT\{44C93E27-2C59-4530-B97B-4A681D1340F2}.exe
c:\program files\Trend Micro\OfficeScan Client\SUSPECT\{44F57523-02B7-4009-B596-868F9D0D6DF2}.exe
c:\program files\Trend Micro\OfficeScan Client\SUSPECT\{4581BB35-5088-47BD-B7D5-0D27A6E61D49}.exe
c:\program files\Trend Micro\OfficeScan Client\SUSPECT\{462F5201-51AE-4128-BBB7-1571D80D7A8B}.exe
c:\program files\Trend Micro\OfficeScan Client\SUSPECT\{4683801B-3E5C-46E1-87F1-F802C3E61B2E}.exe
c:\program files\Trend Micro\OfficeScan Client\SUSPECT\{46B69603-D3EB-4D54-AEBB-597D429AFC73}.exe
c:\program files\Trend Micro\OfficeScan Client\SUSPECT\{47464CE8-E700-44F4-AB65-8E6400C0D829}.exe
c:\program files\Trend Micro\OfficeScan Client\SUSPECT\{47DA9AC5-5086-4397-A6C9-9D7A90A7F3B6}.exe
c:\program files\Trend Micro\OfficeScan Client\SUSPECT\{48F16835-EA6F-4E07-A36E-A1F4A5B5142E}.exe
c:\program files\Trend Micro\OfficeScan Client\SUSPECT\{49F527DA-87AC-4B8C-ADAA-C5F8C015B657}.exe
c:\program files\Trend Micro\OfficeScan Client\SUSPECT\{4A2C9B90-B633-487D-840D-24BC24F794B9}.exe
c:\program files\Trend Micro\OfficeScan Client\SUSPECT\{4C2AB9C7-4B17-4381-9AE4-6335AD8A0B03}.exe
c:\program files\Trend Micro\OfficeScan Client\SUSPECT\{4E6E5600-FA9F-40EF-9C07-96185586E9C6}.exe
c:\program files\Trend Micro\OfficeScan Client\SUSPECT\{4F83089E-D371-4AD2-B2ED-091C192F6065}.exe
c:\program files\Trend Micro\OfficeScan Client\SUSPECT\{5005A9D2-74EB-4C02-B9D8-6459AD1BD1E8}.exe
c:\program files\Trend Micro\OfficeScan Client\SUSPECT\{5277B0CD-F808-4B97-9C4F-CD6F5D750647}.exe
c:\program files\Trend Micro\OfficeScan Client\SUSPECT\{540D031A-0118-48E2-A164-E53866824D04}.exe
c:\program files\Trend Micro\OfficeScan Client\SUSPECT\{545A8743-77D9-4B42-838B-B18AA8A9F8A2}.exe
c:\program files\Trend Micro\OfficeScan Client\SUSPECT\{54733545-3B0E-4433-A916-B8B5537AA74F}.exe
c:\program files\Trend Micro\OfficeScan Client\SUSPECT\{560FEAB2-91D6-4373-A703-D3285B16E7BC}.exe
c:\program files\Trend Micro\OfficeScan Client\SUSPECT\{57153D05-EC35-48CB-9204-95D96D752CA3}.exe
c:\program files\Trend Micro\OfficeScan Client\SUSPECT\{57A71CE6-E698-4398-982F-3790CD39DB9B}.exe
c:\program files\Trend Micro\OfficeScan Client\SUSPECT\{58485ADF-1F0E-4D3A-A1EB-CB0AC84CAE91}.exe
c:\program files\Trend Micro\OfficeScan Client\SUSPECT\{58490BF1-B7FB-45BC-BED8-BEAEB8F011D1}.exe
c:\program files\Trend Micro\OfficeScan Client\SUSPECT\{5A7A809D-A3D9-459D-AD36-26E9CFA5437A}.exe
c:\program files\Trend Micro\OfficeScan Client\SUSPECT\{5AA6EF84-5A53-48A8-AB45-C063BCEBCEFC}.exe
c:\program files\Trend Micro\OfficeScan Client\SUSPECT\{5AB38E84-C722-42F5-BEAA-06D0E0CD3CA9}.exe
c:\program files\Trend Micro\OfficeScan Client\SUSPECT\{5AF067F4-53D1-4361-B87C-65D06E0DF48D}.exe
c:\program files\Trend Micro\OfficeScan Client\SUSPECT\{5BE765FF-61D8-4F2B-BB68-3270F5FEC10C}.exe
c:\program files\Trend Micro\OfficeScan Client\SUSPECT\{5C1A3C20-B3B3-4E9C-93AD-DA6FBAF9751E}.exe
c:\program files\Trend Micro\OfficeScan Client\SUSPECT\{5CFBBC0B-0EB6-4A92-A0F4-2843C3A11C04}.exe
c:\program files\Trend Micro\OfficeScan Client\SUSPECT\{5D02AC3D-0E58-4134-BA5C-ED6CC905D179}.exe
c:\program files\Trend Micro\OfficeScan Client\SUSPECT\{5DBC209A-ECF3-4571-9A71-72B786B7014A}.exe
c:\program files\Trend Micro\OfficeScan Client\SUSPECT\{5F5099CE-D663-46D9-A1EA-D0F3F088B1C0}.exe
c:\program files\Trend Micro\OfficeScan Client\SUSPECT\{5FAD44E3-369E-4703-9C99-00B7A00E7030}.exe
c:\program files\Trend Micro\OfficeScan Client\SUSPECT\{60489031-220A-4987-B61E-E8919C2D0252}.exe
c:\program files\Trend Micro\OfficeScan Client\SUSPECT\{610B1E35-0189-4CC1-B254-09BC8273AEED}.exe
c:\program files\Trend Micro\OfficeScan Client\SUSPECT\{61E7BD1E-7383-4B81-B70D-DF06A363093C}.exe
c:\program files\Trend Micro\OfficeScan Client\SUSPECT\{62CFCCCD-E362-42D3-9121-543106B01B33}.exe
c:\program files\Trend Micro\OfficeScan Client\SUSPECT\{6363D2C0-AC03-41F0-8EED-BBF788C9EB12}.exe
c:\program files\Trend Micro\OfficeScan Client\SUSPECT\{63E640A4-D83C-41F8-A97A-6C8F5BB3E17F}.exe
c:\program files\Trend Micro\OfficeScan Client\SUSPECT\{6499024C-C30F-4092-9466-4D5A9F8AB2DA}.exe
c:\program files\Trend Micro\OfficeScan Client\SUSPECT\{6838FE89-4CA6-4817-8C3A-B29BAF9A7985}.exe
c:\program files\Trend Micro\OfficeScan Client\SUSPECT\{6AAF7086-911E-4067-A51A-7981566821CF}.exe
c:\program files\Trend Micro\OfficeScan Client\SUSPECT\{6C06D5CF-7735-442F-A1EE-8D327F20C1D0}.exe
c:\program files\Trend Micro\OfficeScan Client\SUSPECT\{6CAF9E8D-843F-420C-9CE9-433D9C8E4170}.exe
c:\program files\Trend Micro\OfficeScan Client\SUSPECT\{6E2C9EE4-C36E-4848-8F61-30041C3A734B}.exe
c:\program files\Trend Micro\OfficeScan Client\SUSPECT\{6EC40D33-F4A7-48F3-9ABC-C43D00548D89}.exe
c:\program files\Trend Micro\OfficeScan Client\SUSPECT\{6FBE9113-0280-436A-BA8A-9141F9C8F792}.exe
c:\program files\Trend Micro\OfficeScan Client\SUSPECT\{6FEE0D0F-DB88-412A-A121-F296F1BBFE4A}.exe
c:\program files\Trend Micro\OfficeScan Client\SUSPECT\{71DE9F00-CD2F-403A-B93C-01EB781E6C45}.exe
c:\program files\Trend Micro\OfficeScan Client\SUSPECT\{72DA0E53-F80D-44D9-B650-D5B3341214BB}.exe
c:\program files\Trend Micro\OfficeScan Client\SUSPECT\{72ECEB4A-8A8A-4C3F-B415-245E8EFD0AB8}.exe
c:\program files\Trend Micro\OfficeScan Client\SUSPECT\{73810376-C12E-4B66-96AF-DB503519371E}.exe
c:\program files\Trend Micro\OfficeScan Client\SUSPECT\{74453308-5B4C-4BE8-AACD-A59A1DA8C6F3}.exe
c:\program files\Trend Micro\OfficeScan Client\SUSPECT\{7573A29C-491A-4C80-B37B-86652F5CB953}.exe
c:\program files\Trend Micro\OfficeScan Client\SUSPECT\{76A190CA-31C6-4C26-978A-6498D2A59990}.exe
c:\program files\Trend Micro\OfficeScan Client\SUSPECT\{7702CDE2-5145-4A8E-8325-3F5C0B0346E8}.exe
c:\program files\Trend Micro\OfficeScan Client\SUSPECT\{77927923-A14A-4C7E-897D-A42FA472C647}.exe
c:\program files\Trend Micro\OfficeScan Client\SUSPECT\{7A6D43C3-9CB5-4B03-B905-A9E32B599547}.exe
c:\program files\Trend Micro\OfficeScan Client\SUSPECT\{7B464784-0735-4DD4-9388-80B13FE1E034}.exe
c:\program files\Trend Micro\OfficeScan Client\SUSPECT\{7B80E44F-057F-4E6F-BED3-C4292AB3B4AA}.exe
c:\program files\Trend Micro\OfficeScan Client\SUSPECT\{7BDAD998-708D-4E9F-A69C-824A45C058A4}.exe
c:\program files\Trend Micro\OfficeScan Client\SUSPECT\{7D69BFBF-42F7-4286-8F1B-014F01DC7AD0}.exe
c:\program files\Trend Micro\OfficeScan Client\SUSPECT\{7DA07259-69E6-4CCE-9A3E-28A445D5EA7F}.exe
c:\program files\Trend Micro\OfficeScan Client\SUSPECT\{7E6C048D-9B2E-462B-97DE-04BE84F17F3D}.exe
c:\program files\Trend Micro\OfficeScan Client\SUSPECT\{8097BB81-738E-4D07-8222-E3A28EA2C719}.exe
c:\program files\Trend Micro\OfficeScan Client\SUSPECT\{8208D703-DC3A-40CF-97B2-C70BE3615395}.exe
c:\program files\Trend Micro\OfficeScan Client\SUSPECT\{82CA9FCE-1894-4E5D-9C5B-22D2BDF20504}.exe
c:\program files\Trend Micro\OfficeScan Client\SUSPECT\{831A788B-8BBE-4593-B96F-28E0A27B0569}.exe
c:\program files\Trend Micro\OfficeScan Client\SUSPECT\{83896F41-FB20-4A79-AEC4-19BF3043DD93}.exe
c:\program files\Trend Micro\OfficeScan Client\SUSPECT\{84D0BEC9-B212-483A-A3D0-88EBD0E6956F}.exe
c:\program files\Trend Micro\OfficeScan Client\SUSPECT\{85C9B207-BACB-44C5-90BB-6A2C8F27399F}.exe
c:\program files\Trend Micro\OfficeScan Client\SUSPECT\{86594A18-149C-4A7D-9B89-DE8F5E08FAD0}.exe
c:\program files\Trend Micro\OfficeScan Client\SUSPECT\{87A37CC9-0698-4F47-AE8F-E87DA36321E3}.exe
c:\program files\Trend Micro\OfficeScan Client\SUSPECT\{87D3974B-928F-4DC5-AB68-E332BEF822F3}.exe
c:\program files\Trend Micro\OfficeScan Client\SUSPECT\{88715687-1872-40D2-BE44-89029F7778A7}.exe
c:\program files\Trend Micro\OfficeScan Client\SUSPECT\{89DFA45A-DA51-4956-A1CC-CF3FA1EDA94C}.exe
c:\program files\Trend Micro\OfficeScan Client\SUSPECT\{8CEF8505-E475-4111-8089-432D8365A534}.exe
c:\program files\Trend Micro\OfficeScan Client\SUSPECT\{8DC4C7B8-D2C7-44E3-8557-7B530C0D4EE1}.exe
c:\program files\Trend Micro\OfficeScan Client\SUSPECT\{8DE73611-F901-4809-B1D9-1F9E241AF9AB}.exe
c:\program files\Trend Micro\OfficeScan Client\SUSPECT\{8FA942E6-6992-4076-A4DD-4CD27283AA13}.exe
c:\program files\Trend Micro\OfficeScan Client\SUSPECT\{92BE637B-FB3E-49AD-82CC-BC4F2DD28CE8}.exe
c:\program files\Trend Micro\OfficeScan Client\SUSPECT\{9373AC90-5B69-40CA-967C-688688BC46A3}.exe
c:\program files\Trend Micro\OfficeScan Client\SUSPECT\{93F0C5B0-BD91-4519-AF65-E5DD25AAE56E}.exe
c:\program files\Trend Micro\OfficeScan Client\SUSPECT\{953CB1C5-EE3B-4E3B-9BCC-25F6CC5A68A6}.exe
c:\program files\Trend Micro\OfficeScan Client\SUSPECT\{95E99EE6-AB63-4C1C-BC3C-E732129B8A99}.exe
c:\program files\Trend Micro\OfficeScan Client\SUSPECT\{97293E2B-E564-415C-8B49-F7F26B3DEFD2}.exe
c:\program files\Trend Micro\OfficeScan Client\SUSPECT\{97D7968F-A07E-4EF7-8329-A2DA36105C49}.exe
c:\program files\Trend Micro\OfficeScan Client\SUSPECT\{97DA8B1D-2B2A-4760-A1E7-0185B0FEE913}.exe
c:\program files\Trend Micro\OfficeScan Client\SUSPECT\{98085EB6-4E8E-4BFE-9237-ABEAD7A99895}.exe
c:\program files\Trend Micro\OfficeScan Client\SUSPECT\{9B34C141-FB71-4FA2-BACC-33C01E9BD70D}.exe
c:\program files\Trend Micro\OfficeScan Client\SUSPECT\{9B656264-F98C-4997-84D1-BAB83DA74D4C}.exe
c:\program files\Trend Micro\OfficeScan Client\SUSPECT\{9BC739BE-1966-49FC-810C-3DAC5D8E299A}.exe
c:\program files\Trend Micro\OfficeScan Client\SUSPECT\{9C00FAE9-A2CD-4E70-9165-32B0984C4F71}.exe
c:\program files\Trend Micro\OfficeScan Client\SUSPECT\{9C905909-9EC8-42DD-B706-3EB7A8402B3F}.exe
c:\program files\Trend Micro\OfficeScan Client\SUSPECT\{9D392E52-D962-4C59-A335-D75B693837EC}.exe
c:\program files\Trend Micro\OfficeScan Client\SUSPECT\{9D684C95-F9C7-42EA-A768-33C64C56AE9B}.exe
c:\program files\Trend Micro\OfficeScan Client\SUSPECT\{9E190037-AE8E-43FA-ADC4-92B5A6E6A9D5}.exe
c:\program files\Trend Micro\OfficeScan Client\SUSPECT\{9E4686C2-1DF0-4022-B48F-7DAC4F45B6A3}.exe
c:\program files\Trend Micro\OfficeScan Client\SUSPECT\{A06765BC-20E0-4ACE-B057-40CB48532A99}.exe
c:\program files\Trend Micro\OfficeScan Client\SUSPECT\{A27CE282-7E93-49DC-A27E-61DC39E26F5F}.exe
c:\program files\Trend Micro\OfficeScan Client\SUSPECT\{A3100213-F198-4CBE-BD6F-573777A35775}.exe
c:\program files\Trend Micro\OfficeScan Client\SUSPECT\{A3F76C03-6C94-4CE8-9130-6DA1B32352E8}.exe
c:\program files\Trend Micro\OfficeScan Client\SUSPECT\{A4589012-EC3C-483F-85EE-A3CDA7269BF4}.exe
c:\program files\Trend Micro\OfficeScan Client\SUSPECT\{A73CEE44-711D-4B19-9EBA-685A2B267E6D}.exe
c:\program files\Trend Micro\OfficeScan Client\SUSPECT\{AA1146A0-B10E-4662-A39D-58D043341925}.exe
c:\program files\Trend Micro\OfficeScan Client\SUSPECT\{AE6861EA-F04B-4C35-90C0-B5C25775FAAB}.exe
c:\program files\Trend Micro\OfficeScan Client\SUSPECT\{AEC7F004-92F9-4BA0-9BE6-5EF1626EF127}.exe
c:\program files\Trend Micro\OfficeScan Client\SUSPECT\{AF9FA9F6-34EB-4780-907A-96DFDB20DA81}.exe
c:\program files\Trend Micro\OfficeScan Client\SUSPECT\{B1828260-D025-40A2-8047-F37E58BE45AD}.exe
c:\program files\Trend Micro\OfficeScan Client\SUSPECT\{B1A2F6C9-70EB-4083-9EAC-8ABACDCF5496}.exe
c:\program files\Trend Micro\OfficeScan Client\SUSPECT\{B1DEC13B-1C69-4175-9922-3D5EFE6D6322}.exe
c:\program files\Trend Micro\OfficeScan Client\SUSPECT\{B2657BDF-92FB-429A-86B9-F7EEFAB2B519}.exe
c:\program files\Trend Micro\OfficeScan Client\SUSPECT\{B4CE5FA3-A89F-4ABD-8481-98FB3703AEAA}.exe
c:\program files\Trend Micro\OfficeScan Client\SUSPECT\{B4F8F29F-DD76-4E3B-8C2C-6E7D45865167}.exe
c:\program files\Trend Micro\OfficeScan Client\SUSPECT\{B5568457-4560-4F32-B15D-398870345155}.exe
c:\program files\Trend Micro\OfficeScan Client\SUSPECT\{B57634A8-E985-4B8F-AAEA-CDD0202BAB54}.exe
c:\program files\Trend Micro\OfficeScan Client\SUSPECT\{B6D407B7-0802-47B6-BFF8-9C33642BC99C}.exe
c:\program files\Trend Micro\OfficeScan Client\SUSPECT\{B718FA50-F761-45FE-84CB-F4CB9F8DE254}.exe
c:\program files\Trend Micro\OfficeScan Client\SUSPECT\{B77BFBAF-35F9-49E4-9C9C-9CED93F5AAD1}.exe
c:\program files\Trend Micro\OfficeScan Client\SUSPECT\{B839EEE5-3314-469D-A65E-6BBAA0E587C3}.exe
c:\program files\Trend Micro\OfficeScan Client\SUSPECT\{B8986C5F-3CDB-4483-B6C7-1247FE378C6B}.exe
c:\program files\Trend Micro\OfficeScan Client\SUSPECT\{B89A4388-96B6-4D7A-95DC-076EC65923E1}.exe
c:\program files\Trend Micro\OfficeScan Client\SUSPECT\{B932A9EF-B227-4882-89FB-08534A12910D}.exe
c:\program files\Trend Micro\OfficeScan Client\SUSPECT\{BBC92E50-6B43-4990-89B0-8A1FC48D01D9}.exe
c:\program files\Trend Micro\OfficeScan Client\SUSPECT\{BC015DE5-739F-45E7-8D88-2C4D94CF5F40}.exe
c:\program files\Trend Micro\OfficeScan Client\SUSPECT\{BD944332-32E4-4D45-BCE7-911DBD7506FE}.exe
c:\program files\Trend Micro\OfficeScan Client\SUSPECT\{BE06FFA6-F66D-4B51-A0B7-89FAF53DE6E8}.exe
c:\program files\Trend Micro\OfficeScan Client\SUSPECT\{BE1E4969-84B3-4D0A-BC87-F0066EF9B788}.exe
c:\program files\Trend Micro\OfficeScan Client\SUSPECT\{BE20749D-88E2-4A76-BAC3-BF6FDA978A27}.exe
c:\program files\Trend Micro\OfficeScan Client\SUSPECT\{BE4DA4BD-D020-45BE-8A5D-325772FA04A0}.exe
c:\program files\Trend Micro\OfficeScan Client\SUSPECT\{BEE1CD58-36FA-4822-A3BE-93C6C6478505}.exe
c:\program files\Trend Micro\OfficeScan Client\SUSPECT\{C0A762C5-3A38-4F5D-A817-473C0ECE2B11}.exe
c:\program files\Trend Micro\OfficeScan Client\SUSPECT\{C1AA3733-D4E4-4C5E-B3A7-EF5B8F6A66B0}.exe
c:\program files\Trend Micro\OfficeScan Client\SUSPECT\{C3B066DF-44E4-4AFA-9C33-72596AAF8D49}.exe
c:\program files\Trend Micro\OfficeScan Client\SUSPECT\{C3C6F046-6C63-40FE-9103-74D32C2B0969}.exe
c:\program files\Trend Micro\OfficeScan Client\SUSPECT\{C680606C-A50B-46E6-A61B-2B092213F1B4}.exe
c:\program files\Trend Micro\OfficeScan Client\SUSPECT\{C6D3C978-3F1E-4A87-ABE1-D0BEE6A9FCEA}.exe
c:\program files\Trend Micro\OfficeScan Client\SUSPECT\{C76A473A-D438-4EF0-9922-19B725C372DC}.exe
c:\program files\Trend Micro\OfficeScan Client\SUSPECT\{C9910FA5-F1BB-4FCD-9CFF-2342DFD8A29B}.exe
c:\program files\Trend Micro\OfficeScan Client\SUSPECT\{C994CD21-08B4-496D-96ED-63B49C1E9120}.exe
c:\program files\Trend Micro\OfficeScan Client\SUSPECT\{C9BBD0F8-EBFC-42BB-9167-AB717B20A530}.exe
c:\program files\Trend Micro\OfficeScan Client\SUSPECT\{CACB2384-9E12-4B0D-9AD3-7104CBFB7AF2}.exe
c:\program files\Trend Micro\OfficeScan Client\SUSPECT\{CC73360B-162A-4C46-B632-E5DE679F561D}.exe
c:\program files\Trend Micro\OfficeScan Client\SUSPECT\{CCCCF789-69D6-48E4-ACEF-840A198DF6FE}.exe
c:\program files\Trend Micro\OfficeScan Client\SUSPECT\{CDB5BA49-6AD3-4C10-AFC3-375ED856609C}.exe
c:\program files\Trend Micro\OfficeScan Client\SUSPECT\{CEE6D2FB-4DCC-46BF-9708-47059CC1E2D8}.exe
c:\program files\Trend Micro\OfficeScan Client\SUSPECT\{CF185AA3-667E-42DB-ACCB-9FA56F191614}.exe
c:\program files\Trend Micro\OfficeScan Client\SUSPECT\{CFFC831B-44D2-4427-8AE4-CDDC61F5F10F}.exe
c:\program files\Trend Micro\OfficeScan Client\SUSPECT\{D053AB84-CDE3-44CC-8EC1-3C45B39796BA}.exe
c:\program files\Trend Micro\OfficeScan Client\SUSPECT\{D13F4E9F-53CA-43CD-9A98-92F1B638818F}.exe
c:\program files\Trend Micro\OfficeScan Client\SUSPECT\{D33E9539-C426-4525-9A3D-D59FA88D9888}.exe
c:\program files\Trend Micro\OfficeScan Client\SUSPECT\{D56CE563-B497-475C-BFEF-890F49E85EB2}.exe
c:\program files\Trend Micro\OfficeScan Client\SUSPECT\{D59E01A1-14D3-4681-94B0-479F097AB3CC}.exe
c:\program files\Trend Micro\OfficeScan Client\SUSPECT\{D63D6D36-2BEF-4F42-B77D-9F3A6DD3D19F}.exe
c:\program files\Trend Micro\OfficeScan Client\SUSPECT\{D771E0E9-1CCA-4CBE-BAB6-FD45B316423E}.exe
c:\program files\Trend Micro\OfficeScan Client\SUSPECT\{D7A56B9C-8367-46A6-981F-A64643DD85DA}.exe
c:\program files\Trend Micro\OfficeScan Client\SUSPECT\{DD4F8AB9-14A7-48D6-A962-14A2CF027676}.exe
c:\program files\Trend Micro\OfficeScan Client\SUSPECT\{DE4A5CEA-7091-4600-8B27-23D9DC386241}.exe
c:\program files\Trend Micro\OfficeScan Client\SUSPECT\{E01E9265-72DC-4A87-95A2-9FD181AAFF34}.exe
c:\program files\Trend Micro\OfficeScan Client\SUSPECT\{E203D50C-0502-445C-ACF2-A9852ACCBF6C}.exe
c:\program files\Trend Micro\OfficeScan Client\SUSPECT\{E2A05F51-DB73-42EA-B265-C762877B5369}.exe
c:\program files\Trend Micro\OfficeScan Client\SUSPECT\{E2DED314-4906-4465-BF0E-FE3C58001563}.exe
c:\program files\Trend Micro\OfficeScan Client\SUSPECT\{E3DB7C2D-8474-4A0B-B53B-A7E715A8D25D}.exe
c:\program files\Trend Micro\OfficeScan Client\SUSPECT\{E69C65A4-565C-4CF0-907E-17F21750D3D8}.exe
c:\program files\Trend Micro\OfficeScan Client\SUSPECT\{E791D2CC-85E1-4603-8102-DC1EF1AD8177}.exe
c:\program files\Trend Micro\OfficeScan Client\SUSPECT\{E8CD60FA-EA05-469D-AD82-BAEB4ECDFFA9}.exe
c:\program files\Trend Micro\OfficeScan Client\SUSPECT\{E8DED8BF-BCBC-4E40-B341-815F1578AC6A}.exe
c:\program files\Trend Micro\OfficeScan Client\SUSPECT\{E8F31391-A0C3-45D7-8AB1-52E3B6E026C9}.exe
c:\program files\Trend Micro\OfficeScan Client\SUSPECT\{EA5AFF68-1172-45EF-BE89-2553AA39D420}.exe
c:\program files\Trend Micro\OfficeScan Client\SUSPECT\{EA5FE5DD-0037-4B93-8F0E-962B311D4506}.exe
c:\program files\Trend Micro\OfficeScan Client\SUSPECT\{EA64D614-9BD8-475F-A71D-441A3565D686}.exe
c:\program files\Trend Micro\OfficeScan Client\SUSPECT\{EAB93EA9-6DA9-4CE5-A9C8-4DB910FA10B6}.exe
c:\program files\Trend Micro\OfficeScan Client\SUSPECT\{EAE02ADB-76C7-4981-A917-4E6EC020046F}.exe
c:\program files\Trend Micro\OfficeScan Client\SUSPECT\{EC1EB546-D842-4867-AA06-F4BD2C1FF005}.exe
c:\program files\Trend Micro\OfficeScan Client\SUSPECT\{ED22610E-B08C-4815-ABE9-B0438B53E834}.exe
c:\program files\Trend Micro\OfficeScan Client\SUSPECT\{EDD8AFF3-0474-4A38-8505-979822C1FC80}.exe
c:\program files\Trend Micro\OfficeScan Client\SUSPECT\{EDD8F870-7FF5-4CA0-BAFC-845904D1349E}.exe
c:\program files\Trend Micro\OfficeScan Client\SUSPECT\{EE601938-DF3A-44F2-A05D-DDBEADA19538}.exe
c:\program files\Trend Micro\OfficeScan Client\SUSPECT\{EE89912D-35D4-4F2E-9FCE-0A465959903A}.exe
c:\program files\Trend Micro\OfficeScan Client\SUSPECT\{EEFB34E8-845E-4F91-88C9-661D9F3AB26F}.exe
c:\program files\Trend Micro\OfficeScan Client\SUSPECT\{EF231512-C4E2-4C97-A36E-4714E1AE4948}.exe
c:\program files\Trend Micro\OfficeScan Client\SUSPECT\{EFE424D0-F1C0-4EAE-B927-733FE716847A}.exe
c:\program files\Trend Micro\OfficeScan Client\SUSPECT\{F2C69D9A-0BC2-4DDE-B63C-C9B5758E4B28}.exe
c:\program files\Trend Micro\OfficeScan Client\SUSPECT\{F2EFE5D9-3EFD-409C-AB72-468FA3E52017}.exe
c:\program files\Trend Micro\OfficeScan Client\SUSPECT\{F3482F38-F496-47D5-93A2-9B88F7D98EBB}.exe
c:\program files\Trend Micro\OfficeScan Client\SUSPECT\{F3547DF7-FA6F-4703-9594-8CFDE2984A40}.exe
c:\program files\Trend Micro\OfficeScan Client\SUSPECT\{F3AB0DF4-44AD-48BF-9B2B-690F45BE12F9}.exe
c:\program files\Trend Micro\OfficeScan Client\SUSPECT\{F3B01B3C-5427-4864-982E-F525DB1D75D0}.exe
c:\program files\Trend Micro\OfficeScan Client\SUSPECT\{F3D483B8-87C2-4E33-931C-9D545C705672}.exe
c:\program files\Trend Micro\OfficeScan Client\SUSPECT\{F7744241-6255-4F16-879A-AAABC9965A25}.exe
c:\program files\Trend Micro\OfficeScan Client\SUSPECT\{F940746C-AF57-49F6-ADB1-6A2551827053}.exe
c:\program files\Trend Micro\OfficeScan Client\SUSPECT\{F970F258-C058-4115-931B-0140497FF190}.exe
c:\program files\Trend Micro\OfficeScan Client\SUSPECT\{F9A39964-F4CD-4E05-9F45-1F2008C024BE}.exe
c:\program files\Trend Micro\OfficeScan Client\SUSPECT\{FB445BDB-8CCB-42A5-B2C6-98808737738B}.exe
c:\program files\Trend Micro\OfficeScan Client\SUSPECT\{FB68A0BC-37D2-450C-B31C-3F58AAC111D6}.exe
c:\program files\Trend Micro\OfficeScan Client\SUSPECT\{FC60983B-E449-4B6A-8062-6B98DA1345E3}.exe
c:\program files\Trend Micro\OfficeScan Client\SUSPECT\{FDD52332-88DF-444A-999C-939221C639CD}.exe
c:\program files\Trend Micro\OfficeScan Client\SUSPECT\{FF9ACEC9-AD98-4A2C-9BD7-3ED86E52CA24}.exe
c:\program files\Trend Micro\OfficeScan Client\SUSPECT\18532
c:\program files\Trend Micro\OfficeScan Client\SUSPECT\9s4tqo8k.exe
c:\program files\Trend Micro\OfficeScan Client\SUSPECT\C72D424Cd01
c:\program files\Trend Micro\OfficeScan Client\SUSPECT\d5c08qo9.exe
c:\program files\Trend Micro\OfficeScan Client\SUSPECT\FF21D759d01
c:\program files\Trend Micro\OfficeScan Client\SUSPECT\FF21D759d01_614.VIR
c:\program files\Trend Micro\OfficeScan Client\SUSPECT\googletalk-setup.exe
f:\documents and settings\Andrew\Desktop\Old C drive\WINDOWS\Desktop\laptop.zip
f:\documents and settings\Andrew\Desktop\Old C drive\WINDOWS\Desktop\old folder folder\old hdd\signage\eds labels\Pfeifferlabel.jpg
f:\old c drive\WINDOWS\Desktop\laptop.zip
f:\old c drive\WINDOWS\Desktop\old folder folder\old hdd\signage\eds labels\Pfeifferlabel.jpg
.
((((((((((((((((((((((((((((((((((((((( Drivers/Services )))))))))))))))))))))))))))))))))))))))))))))))))
.
——-\Legacy_ASBP2POA
——-\Service_asbp2poa
((((((((((((((((((((((((( Files Created from 2009-01-07 to 2009-02-07 )))))))))))))))))))))))))))))))
.
2009-01-23 00:27 . 2009-01-23 00:28 d——– C:\Rooter$
2009-01-22 21:45 . 2009-01-22 21:45 d——– c:\program files\Malwarebytes' Anti-Malware
2009-01-22 21:45 . 2009-01-22 21:45 d——– c:\documents and settings\Andy\Application Data\Malwarebytes
2009-01-22 21:45 . 2009-01-22 21:45 d——– c:\documents and settings\All Users\Application Data\Malwarebytes
2009-01-22 21:45 . 2009-01-14 16:11 38,496 –a—— c:\windows\system32\drivers\mbamswissarmy.sys
2009-01-22 21:45 . 2009-01-14 16:11 15,504 –a—— c:\windows\system32\drivers\mbam.sys
2009-01-21 22:30 . 2009-01-21 22:30 54,156 –ah—– c:\windows\QTFont.qfn
2009-01-21 22:30 . 2009-01-21 22:30 1,409 –a—— c:\windows\QTFont.for
2009-01-21 20:57 . 2009-01-21 20:57 410,984 –a—— c:\windows\system32\deploytk.dll
2009-01-21 20:57 . 2009-01-21 20:57 73,728 –a—— c:\windows\system32\javacpl.cpl
2009-01-17 13:41 . 2009-01-17 13:41 d——– c:\documents and settings\All Users\Application Data\Blizzard
2009-01-15 23:17 . 2009-01-15 23:20 d——– c:\program files\ERUNT
2009-01-07 23:59 . 2009-01-07 23:59 d——– c:\program files\CD Wave
2009-01-07 23:59 . 2005-07-01 16:32 258,352 –a—— c:\windows\system32\unicows.dll
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2009-02-07 04:00 ——— d—–w c:\program files\Java
2009-02-01 01:31 ——— d—–w c:\program files\World of Warcraft
2009-01-17 15:30 ——— d—–w c:\documents and settings\Andy\Application Data\Juniper Networks
2009-01-17 15:30 ——— d—–w c:\documents and settings\All Users\Application Data\Juniper Networks
2009-01-16 05:13 ——— d—–w c:\program files\EverQuest
2009-01-16 03:55 ——— d—–w c:\program files\Trend Micro
2009-01-05 05:28 ——— d—–w c:\documents and settings\Andy\Application Data\Roxio
2009-01-05 05:25 ——— d—–w c:\documents and settings\Andy\Application Data\vlc
2009-01-05 04:59 ——— d—–w c:\program files\VideoLAN
2009-01-05 04:44 ——— d—–w c:\program files\DVD Decrypter
2009-01-05 04:04 ——— d—–w c:\program files\DivX
2008-12-28 20:12 ——— d—–w c:\documents and settings\Andy\Application Data\uTorrent
2008-12-19 12:09 0 —ha-w c:\windows\system32\drivers\MsftWdf_Kernel_01005_Coinstaller_Critical.Wdf
2008-12-19 12:09 0 —ha-w c:\windows\system32\drivers\Msft_Kernel_xusb21_01005.Wdf
2008-12-11 11:57 333,184 —-a-w c:\windows\system32\drivers\srv.sys
2007-10-08 01:10 53,248 —-a-w c:\documents and settings\Andy\Jessica HoweAddItConfig.dll
2007-10-08 01:10 40,960 —-a-w c:\documents and settings\Andy\Jessica HoweAddItTaskProc.exe
2007-10-08 01:10 4 —-a-w c:\documents and settings\Andy\Jessica HoweTransDB.bin
2007-10-08 01:10 192,512 —-a-w c:\documents and settings\Andy\Jessica HoweAddItManager.exe
2007-10-08 01:10 102,400 —-a-w c:\documents and settings\Andy\Jessica HoweAddItConduit.dll
2007-07-17 11:52 154,120 —-a-w c:\documents and settings\Jessica\Application Data\GDIPFONTCACHEV1.DAT
2007-01-04 00:33 154,120 —-a-w c:\documents and settings\Andy\Application Data\GDIPFONTCACHEV1.DAT
2005-01-24 17:09 3,518,464 ——w c:\documents and settings\Andy\testeqgame.exe
2005-01-24 17:09 2,035,712 ——w c:\documents and settings\Andy\EQGraphicsDX9.dll
2005-01-06 21:04 913,408 ——w c:\documents and settings\Andy\eqmain.dll
2005-01-06 21:04 901,120 ——w c:\documents and settings\Andy\EQGfx_Dx8.dll
2005-01-06 21:04 81,920 ——w c:\documents and settings\Andy\eaxman.dll
2005-01-06 21:04 349,696 ——w c:\documents and settings\Andy\mss32.dll
2005-01-06 21:04 282,624 ——w c:\documents and settings\Andy\OptionsEditor.exe
2005-01-06 21:04 159,744 ——w c:\documents and settings\Andy\dpvs.dll
2004-12-17 09:57 3,514,368 ——w c:\documents and settings\Andy\eqgame.exe
2004-08-09 23:31 1,409,024 ——w c:\documents and settings\Andy\BetaEverQuest.exe
2003-07-15 17:02 81,920 ——w c:\documents and settings\Andy\Win32Bitmap.dll
2002-07-24 05:28 1,296 ——w c:\documents and settings\Andy\load2_switches.dat
2002-04-01 14:11 249,856 ——w c:\documents and settings\Andy\installerconfig.exe
1999-01-25 22:40 95,232 ——w c:\documents and settings\Andy\smackw32.dll
2008-10-20 14:51 27,976 —-a-w c:\program files\mozilla firefox\plugins\atgpcdec.dll
2008-10-20 14:51 125,848 —-a-w c:\program files\mozilla firefox\plugins\atgpcext.dll
2008-02-08 01:46 13,624 —-a-w c:\program files\mozilla firefox\plugins\cgpcfg.dll
2008-02-08 01:46 87,360 —-a-w c:\program files\mozilla firefox\plugins\CgpCore.dll
2008-02-08 01:46 91,448 —-a-w c:\program files\mozilla firefox\plugins\confmgr.dll
2008-02-08 01:46 21,824 —-a-w c:\program files\mozilla firefox\plugins\ctxlogging.dll
2008-02-08 01:46 206,136 —-a-w c:\program files\mozilla firefox\plugins\ctxmui.dll
2008-02-08 01:46 31,544 —-a-w c:\program files\mozilla firefox\plugins\icafile.dll
2008-02-08 01:46 40,248 —-a-w c:\program files\mozilla firefox\plugins\icalogon.dll
2008-10-20 14:52 98,712 —-a-w c:\program files\mozilla firefox\plugins\ieatgpc.dll
2007-03-16 21:27 479,232 —-a-w c:\program files\mozilla firefox\plugins\msvcm80.dll
2007-03-16 21:27 548,864 —-a-w c:\program files\mozilla firefox\plugins\msvcp80.dll
2007-03-16 21:27 626,688 —-a-w c:\program files\mozilla firefox\plugins\msvcr80.dll
2007-07-20 16:47 981,170 —-a-w c:\program files\mozilla firefox\plugins\sslsdk_b.dll
2008-02-08 01:46 24,384 —-a-w c:\program files\mozilla firefox\plugins\TcpPServ.dll
2005-09-15 23:26 44,153 —-a-w c:\program files\mozilla firefox\components\inspector.dll
2008-12-19 12:07 67,688 —-a-w c:\program files\mozilla firefox\components\jar50.dll
2008-12-19 12:07 54,368 —-a-w c:\program files\mozilla firefox\components\jsd3250.dll
2008-12-19 12:07 34,944 —-a-w c:\program files\mozilla firefox\components\myspell.dll
2008-12-19 12:07 46,712 —-a-w c:\program files\mozilla firefox\components\spellchk.dll
2008-12-19 12:07 172,136 —-a-w c:\program files\mozilla firefox\components\xpinstal.dll
.
((((((((((((((((((((((((((((( snapshot@2009-02-01_19.15.21.89 )))))))))))))))))))))))))))))))))))))))))
.
- 2005-10-20 12:02:28 163,328 —-a-w c:\windows\ERDNT\Hiv-backup\ERDNT.EXE
+ 2005-10-21 01:02:28 163,328 —-a-w c:\windows\ERDNT\Hiv-backup\ERDNT.EXE
+ 2005-10-21 01:02:28 163,328 —-a-w c:\windows\ERDNT\subs\ERDNT.EXE
- 2000-08-31 13:00:00 286,720 —-a-w c:\windows\SWREG.exe
+ 2000-08-31 13:00:00 161,792 —-a-w c:\windows\SWREG.exe
+ 2009-02-05 23:31:03 53,248 —-a-w c:\windows\system32\Macromed\Shockwave 10\PostUpdate.exe
+ 2004-07-07 01:07:14 172,099 —-a-w c:\windows\Temp\KTC63D.EXE
+ 2009-02-07 04:15:29 16,384 —-atw c:\windows\Temp\Perflib_Perfdata_138.dat
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ctfmon.exe"="c:\windows\system32\ctfmon.exe" [2004-08-04 15360]
"googletalk"="c:\program files\Google\Google Talk\googletalk.exe" [2007-01-01 3739648]
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\RunOnce]
"CTStartup"="c:\program files\Creative\Splash Screen\CTEaxSpl.EXE" [2002-09-13 49152]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"CTStartup"="c:\program files\Creative\Splash Screen\CTEaxSpl.EXE" [2002-09-13 49152]
"OfficeScanNT Monitor"="c:\program files\Trend Micro\OfficeScan Client\pccntmon.exe" [2004-07-06 335872]
"googletalk"="c:\program files\Google\Google Talk\googletalk.exe" [2007-01-01 3739648]
"TkBellExe"="c:\program files\Common Files\Real\Update_OB\realsched.exe" [2008-10-28 185872]
"SunJavaUpdateSched"="c:\program files\Java\jre6\bin\jusched.exe" [2009-01-21 136600]
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"DWQueuedReporting"="c:\progra~1\COMMON~1\MICROS~1\DW\dwtrig20.exe" [2007-03-13 39264]
c:\documents and settings\Jessica\Start Menu\Programs\Startup\
Cyber-shot Viewer Media Check Tool.lnk - c:\program files\Sony\Sony Picture Utility\VolumeWatcher\SPUVolumeWatcher.exe [2007-01-15 155648]
[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Adobe Gamma Loader.exe.lnk]
path=c:\documents and settings\All Users\Start Menu\Programs\Startup\Adobe Gamma Loader.exe.lnk
backup=c:\windows\pss\Adobe Gamma Loader.exe.lnkCommon Startup
[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^APC UPS Status.lnk]
path=c:\documents and settings\All Users\Start Menu\Programs\Startup\APC UPS Status.lnk
backup=c:\windows\pss\APC UPS Status.lnkCommon Startup
[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^HOTSYNCSHORTCUTNAME.lnk]
path=c:\documents and settings\All Users\Start Menu\Programs\Startup\HOTSYNCSHORTCUTNAME.lnk
backup=c:\windows\pss\HOTSYNCSHORTCUTNAME.lnkCommon Startup
[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^HP Digital Imaging Monitor.lnk]
path=c:\documents and settings\All Users\Start Menu\Programs\Startup\HP Digital Imaging Monitor.lnk
backup=c:\windows\pss\HP Digital Imaging Monitor.lnkCommon Startup
[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Microsoft Office.lnk]
path=c:\documents and settings\All Users\Start Menu\Programs\Startup\Microsoft Office.lnk
backup=c:\windows\pss\Microsoft Office.lnkCommon Startup
[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^PixCert.lnk]
path=c:\documents and settings\All Users\Start Menu\Programs\Startup\PixCert.lnk
backup=c:\windows\pss\PixCert.lnkCommon Startup
[HKLM\~\startupfolder\C:^Documents and Settings^Andy^Start Menu^Programs^Startup^LifeDrive™ Manager.lnk]
path=c:\documents and settings\Andy\Start Menu\Programs\Startup\LifeDrive™ Manager.lnk
backup=c:\windows\pss\LifeDrive™ Manager.lnkStartup
[HKLM\~\startupfolder\C:^Documents and Settings^Andy^Start Menu^Programs^Startup^PdaReach Desktop.lnk]
path=c:\documents and settings\Andy\Start Menu\Programs\Startup\PdaReach Desktop.lnk
backup=c:\windows\pss\PdaReach Desktop.lnkStartup
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Adobe Reader Speed Launcher]
–a—— 2008-06-12 01:38 34672 c:\program files\Adobe\Reader 9.0\Reader\reader_sl.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\CTDVDDet]
–a—— 2002-09-30 01:00 45056 c:\program files\Creative\SBAudigy2\DVDAudio\CTDVDDET.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\CTRegRun]
——— 1999-10-10 20:00 41984 c:\windows\Ctregrun.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\CTSysVol]
–a—— 2002-10-29 09:18 49152 c:\program files\Creative\SBAudigy2\Surround Mixer\CTSysVol.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\H/PC Connection Agent]
–a—— 2006-11-13 12:39 1289000 c:\program files\Microsoft ActiveSync\wcescomm.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\HostManager]
–a—— 2004-11-03 16:03 125528 c:\program files\Common Files\AOL\1151501207\EE\AOLHostManager.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\HP Software Update]
–a—— 2006-12-10 20:52 49152 c:\program files\Hewlett-Packard\HP Software Update\hpwuSchd2.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\HPDJ Taskbar Utility]
–a—— 2006-01-06 14:07 188416 c:\windows\system32\spool\drivers\w32x86\3\hpztsb07.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\HPHmon04]
–a—— 2006-01-06 14:07 348160 c:\windows\system32\hphmon04.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\MSMSGS]
–a—— 2004-10-13 11:24 1694208 c:\program files\Messenger\msmsgs.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\QuickTime Task]
–a—— 2006-06-28 08:28 98304 c:\program files\QuickTime\qttask.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\RealTray]
–a—— 2008-10-28 21:38 214536 c:\program files\Real\RealPlayer\realplay.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\RoxioDragToDisc]
–a—— 2005-10-20 19:47 1687552 c:\program files\Roxio\Easy Media Creator 8\Drag to Disc\DrgToDsc.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\RoxWatchTray]
–a—— 2005-10-21 14:13 163840 c:\program files\Common Files\Roxio Shared\SharedCOM8\RoxWatchTray.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SansaDispatch]
–a—— 2007-10-22 11:52 75584 c:\program files\SanDisk\Sansa Updater\SansaDispatch.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SBDrvDet]
–a—— 2002-12-03 18:06 45056 c:\program files\Creative\SB Drive Det\SBDrvDet.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Share-to-Web Namespace Daemon]
–a—— 2002-04-17 10:42 69632 c:\program files\Hewlett-Packard\HP Share-to-Web\hpgs2wnd.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\StartCCC]
–a—— 2006-11-10 12:35 90112 c:\program files\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\TkBellExe]
–a—— 2008-10-28 21:38 185872 c:\program files\Common Files\Real\Update_OB\realsched.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\UpdReg]
——— 2000-05-11 01:00 90112 c:\windows\Updreg.EXE
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\AsioReg]
–a—— 2006-08-11 14:45 74752 c:\windows\system32\CTASIO.DLL
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\CTHelper]
–a—— 2002-12-19 01:59 28672 c:\windows\system32\CTHELPER.EXE
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\CTxfiHlp]
–a—— 2006-08-11 14:56 18944 c:\windows\system32\CTXFIHLP.EXE
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\TrendFirewall]
"DisableMonitoring"=dword:00000001
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"c:\\Program Files\\World of Warcraft\\BackgroundDownloader.exe"=
"c:\\Program Files\\World of Warcraft\\WoW-1.10.2.5302-to-1.11.0.5428-enUS-downloader.exe"=
"c:\\Program Files\\Mozilla Firefox\\firefox.exe"=
"c:\\Program Files\\Common Files\\AOL\\Loader\\aolload.exe"=
"c:\\Program Files\\America Online 9.0\\waol.exe"=
"c:\\Program Files\\Common Files\\AOL\\TopSpeed\\2.0\\aoltsmon.exe"=
"c:\\Program Files\\Common Files\\AOL\\TopSpeed\\2.0\\aoltpspd.exe"=
"c:\\Program Files\\Common Files\\AOL\\1151501207\\EE\\AOLServiceHost.exe"=
"c:\\Program Files\\Common Files\\AOL\\System Information\\sinf.exe"=
"c:\\Program Files\\World of Warcraft\\WoW-1.11.1.5462-to-1.11.2.5464-enUS-downloader.exe"=
"c:\\Program Files\\Google\\Google Talk\\googletalk.exe"=
"c:\\Program Files\\Windows Media Player\\wmplayer.exe"=
"c:\\Program Files\\palmOne\\Hotsync.exe"=
"c:\\Program Files\\Bullfrog\\Dungeon Keeper 2\\DKII.icd"=
"c:\\Program Files\\World of Warcraft\\WoW-1.12.x-to-2.0.1-enUS-patch-downloader.exe"=
"c:\\Program Files\\World of Warcraft\\WoW-2.0.3-enUS-downloader.exe"=
"c:\\Program Files\\World of Warcraft\\WoW-2.0.4.6314-to-2.0.5.6320-enUS-downloader.exe"=
"c:\\Program Files\\World of Warcraft\\WoW-2.0.3.6299-to-2.0.5.6320-enUS-downloader.exe"=
"c:\\Program Files\\World of Warcraft\\WoW-2.0.5.6320-to-2.0.6.6337-enUS-downloader.exe"=
"c:\\Program Files\\World of Warcraft\\WoW-2.0.6.6337-to-2.0.7.6383-enUS-downloader.exe"=
"c:\\Program Files\\World of Warcraft\\WoW-2.0.7.6383-to-2.0.8.6403-enUS-downloader.exe"=
"c:\\Program Files\\World of Warcraft\\WoW-2.0.8.6403-to-2.0.10.6448-enUS-downloader.exe"=
"c:\\Program Files\\Real\\RealPlayer\\realplay.exe"=
"c:\\Program Files\\World of Warcraft\\WoW-2.0.10.6448-to-2.0.12.6546-enUS-downloader.exe"=
"c:\\pfs\\callatl\\rteng9.exe"=
"c:\\Program Files\\Roxio\\Easy Media Creator 8\\Digital Home\\RoxUpnpServer.exe"=
"c:\\Program Files\\uTorrent\\uTorrent.exe"=
"c:\\Program Files\\Aspyr\\Guitar Hero III\\GH3.exe"=
"c:\\Program Files\\Juniper Networks\\Secure Application Manager\\dsSamProxy.exe"=
"c:\\Documents and Settings\\Andy\\Application Data\\Juniper Networks\\Juniper Terminal Services Client\\dsTermServ.exe"=
"c:\program files\Microsoft ActiveSync\rapimgr.exe"= c:\program files\Microsoft ActiveSync\rapimgr.exe:169.254.2.0/255.255.255.0:Enabled:ActiveSync RAPI Manager
"c:\program files\Microsoft ActiveSync\wcescomm.exe"= c:\program files\Microsoft ActiveSync\wcescomm.exe:169.254.2.0/255.255.255.0:Enabled:ActiveSync Connection Manager
"c:\program files\Microsoft ActiveSync\WCESMgr.exe"= c:\program files\Microsoft ActiveSync\WCESMgr.exe:169.254.2.0/255.255.255.0:Enabled:ActiveSync Application
"c:\\Program Files\\Hewlett-Packard\\Digital Imaging\\Bin\\hpqtra08.exe"=
"c:\\Program Files\\Hewlett-Packard\\Digital Imaging\\Bin\\hpqste08.exe"=
"c:\\Program Files\\Hewlett-Packard\\Digital Imaging\\Bin\\hpofxm08.exe"=
"c:\\Program Files\\Hewlett-Packard\\Digital Imaging\\Bin\\hposfx08.exe"=
"c:\\Program Files\\Hewlett-Packard\\Digital Imaging\\Bin\\hposid01.exe"=
"c:\\Program Files\\Hewlett-Packard\\Digital Imaging\\Bin\\hpqscnvw.exe"=
"c:\\Program Files\\Hewlett-Packard\\Digital Imaging\\Bin\\hpqkygrp.exe"=
"c:\\Program Files\\Hewlett-Packard\\Digital Imaging\\Bin\\hpqcopy.exe"=
"c:\\Program Files\\Hewlett-Packard\\Digital Imaging\\Bin\\hpzwiz01.exe"=
"c:\\Program Files\\Hewlett-Packard\\Digital Imaging\\Bin\\hpoews01.exe"=
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List]
"26675:TCP"= 26675:TCP:169.254.2.0/255.255.255.0:Enabled:ActiveSync Service
R1 NEOFLTR_550_11711;Juniper Networks TDI Filter Driver (NEOFLTR_550_11711);c:\windows\system32\drivers\NEOFLTR_550_11711.sys [2007-04-10 63264]
R2 TmFilter;Trend Micro Filter;c:\program files\Trend Micro\OfficeScan Client\tmxpflt.sys [2004-03-30 205328]
R2 TmPreFilter;Trend Micro PreFilter;c:\program files\Trend Micro\OfficeScan Client\tmpreflt.sys [2004-03-30 36368]
R2 WinDefend;Windows Defender;c:\program files\Windows Defender\MsMpEng.exe [2006-11-03 13592]
R3 ctgame;Game Port;c:\windows\system32\drivers\ctgame.sys [2003-12-14 12160]
S3 merger;merger;c:\program files\Microsoft Application Compatibility Toolkit\Application Analyzer\merger.exe [2005-09-27 49152]
— Other Services/Drivers In Memory —
*NewlyCreated* - MDM
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost]
HPZ12 REG_MULTI_SZ Pml Driver HPZ12 Net Driver HPZ12
HPService REG_MULTI_SZ HPSLPSVC
hpdevmgmt REG_MULTI_SZ hpqcxs08 hpqddsvc
.
Contents of the 'Scheduled Tasks' folder
2009-02-07 c:\windows\Tasks\MP Scheduled Scan.job
- c:\program files\Windows Defender\MpCmdRun.exe [2006-11-03 18:20]
.
- - - - ORPHANS REMOVED - - - -
MSConfigStartUp-SunJavaUpdateSched - c:\program files\Java\jre1.5.0_07\bin\jusched.exe
.
——- Supplementary Scan ——-
.
IE: E&xport to Microsoft Excel - c:\progra~1\MICROS~3\OFFICE10\EXCEL.EXE/3000
IE: {{55ED1415-06D3-41D0-9FC4-BCCBF334F865} - {1565EDCF-7E2D-4777-B08D-9845EA53C39A} - c:\windows\system32\mscoree.DLL
Trusted Zone: aol.com\free
Trusted Zone: turbotax.com
DPF: ActiveGS.cab - hxxp://www.virtualapple.com/activegs.cab
DPF: Microsoft XML Parser for Java - file://c:\windows\Java\classes\xmldso.cab
DPF: {2B1AA38D-2D12-11D5-AAD0-00C04FA03D78} - hxxp://portal.uga.edu/nps/portal/gadgets/com.novell.nps.gadgets.shortcut.ShortcutGadget/LocalExec.CAB
DPF: {B3872502-F9FD-4E96-93FF-0D37298F0689} - hxxp://everquest2.station.sony.com/beta_reg/soesysinfo.cab
FF - ProfilePath - c:\documents and settings\Andy\Application Data\Mozilla\Firefox\Profiles\2uva4pts.default\
FF - prefs.js: browser.search.selectedEngine - Google
FF - prefs.js: browser.startup.homepage - hxxp://www.google.com
FF - component: c:\program files\Mozilla Firefox\components\xpinstal.dll
.
**************************************************************************
catchme 0.3.1367 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2009-02-06 23:16:23
Windows 5.1.2600 Service Pack 2 NTFS
scanning hidden processes …
scanning hidden autostart entries …
HKLM\Software\Microsoft\Windows\CurrentVersion\Run
CTStartup = "c:\program files\Creative\Splash Screen\CTEaxSpl.EXE" /run?Z?A~d???*?A~?????????M??????h?@?x?????B~D??????sx??s????????y??w????@@@????|D@@?????>??w?????:2?H??????|???|???????|L(?s?:2??????/?s????????D???????????????????,????????????+?s@@@?D???`|?w??????@
HKCU\Software\Microsoft\Windows\CurrentVersion\RunOnce
CTStartup = "c:\program files\Creative\Splash Screen\CTEaxSpl.EXE" /play??A~d???*?A~?????????M??????h?@?x?????B~D??????sx??s????????y??w????@@@????|D@@?????>??w?????:2?H??????|???|???????|L(?s?:2??????/?s????????D???????????????????,????????????+?s@@@?D???`|?w??????@
scanning hidden files …
c:\windows\TEMP\TMP0000001E24001E91587BABFC 524288 bytes executable
scan completed successfully
hidden files: 1
**************************************************************************
.
——————— DLLs Loaded Under Running Processes ———————
- - - - - - - > 'winlogon.exe'(728)
c:\windows\system32\Ati2evxx.dll
.
———————— Other Running Processes ————————
.
c:\windows\system32\ati2evxx.exe
c:\windows\system32\ati2evxx.exe
c:\program files\Common Files\AOL\TopSpeed\2.0\aoltsmon.exe
c:\program files\APC\APC PowerChute Personal Edition\mainserv.exe
c:\program files\Common Files\AOL\TopSpeed\2.0\aoltpspd.exe
c:\windows\system32\CTSVCCDA.EXE
c:\program files\Java\jre6\bin\jqs.exe
c:\program files\Common Files\Microsoft Shared\VS7Debug\mdm.exe
c:\program files\Trend Micro\OfficeScan Client\NTRtScan.exe
c:\program files\Trend Micro\OfficeScan Client\OfcPfwSvc.exe
c:\program files\Common Files\Roxio Shared\SharedCOM8\RoxMediaDB.exe
c:\program files\Common Files\Roxio Shared\SharedCOM8\RoxWatch.exe
c:\program files\Trend Micro\OfficeScan Client\TmListen.exe
c:\windows\system32\MsPMSPSv.exe
c:\windows\Temp\KTC63D.EXE
c:\windows\system32\logonui.exe
c:\program files\Trend Micro\OfficeScan Client\PccNTUpd.exe
.
**************************************************************************
.
Completion time: 2009-02-07 0:07:16 - machine was rebooted
ComboFix-quarantined-files.txt 2009-02-07 05:07:11
ComboFix2.txt 2009-02-02 00:18:41
Pre-Run: 26,619,179,008 bytes free
Post-Run: 26,511,622,144 bytes free
854 — E O F — 2009-02-05 15:18:30
MBAM log -
Malwarebytes' Anti-Malware 1.33
Database version: 1682
Windows 5.1.2600 Service Pack 2
2/7/2009 7:00:13 AM
mbam-log-2009-02-07 (07-00-13).txt
Scan type: Quick Scan
Objects scanned: 64944
Time elapsed: 6 minute(s), 6 second(s)
Memory Processes Infected: 0
Memory Modules Infected: 0
Registry Keys Infected: 0
Registry Values Infected: 0
Registry Data Items Infected: 0
Folders Infected: 0
Files Infected: 0
Memory Processes Infected:
(No malicious items detected)
Memory Modules Infected:
(No malicious items detected)
Registry Keys Infected:
(No malicious items detected)
Registry Values Infected:
(No malicious items detected)
Registry Data Items Infected:
(No malicious items detected)
Folders Infected:
(No malicious items detected)
Files Infected:
(No malicious items detected)
HJT log -
Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 3:11:54 PM, on 2/7/2009
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16762)
Boot mode: Normal
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Windows Defender\MsMpEng.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Common Files\AOL\TopSpeed\2.0\aoltsmon.exe
C:\Program Files\APC\APC PowerChute Personal Edition\mainserv.exe
C:\WINDOWS\System32\CTsvcCDA.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Java\jre6\bin\jqs.exe
C:\Program Files\Common Files\Microsoft Shared\VS7Debug\mdm.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Trend Micro\OfficeScan Client\ntrtscan.exe
C:\Program Files\Trend Micro\OfficeScan Client\OfcPfwSvc.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Common Files\Roxio Shared\SharedCOM8\RoxMediaDB.exe
C:\Program Files\Common Files\Roxio Shared\SharedCOM8\RoxWatch.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Trend Micro\OfficeScan Client\tmlisten.exe
C:\WINDOWS\System32\MsPMSPSv.exe
C:\WINDOWS\TEMP\KTC63D.EXE
C:\Program Files\Trend Micro\OfficeScan Client\pccntmon.exe
C:\Program Files\Google\Google Talk\googletalk.exe
C:\Program Files\Common Files\Real\Update_OB\realsched.exe
C:\Program Files\Java\jre6\bin\jusched.exe
C:\WINDOWS\system32\ctfmon.exe
C:\WINDOWS\explorer.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\Program Files\Malwarebytes' Anti-Malware\mbam.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\system32\wuauclt.exe
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
O2 - BHO: AcroIEHelperStub - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll
O2 - BHO: Java™ Plug-In SSV Helper - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre6\bin\ssv.dll
O2 - BHO: Java™ Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll
O2 - BHO: JQSIEStartDetectorImpl - {E7E6F031-17CE-4C07-BC86-EABFE594F69C} - C:\Program Files\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll
O4 - HKLM\..\Run: [CTStartup] "C:\Program Files\Creative\Splash Screen\CTEaxSpl.EXE" /run
O4 - HKLM\..\Run: [OfficeScanNT Monitor] "C:\Program Files\Trend Micro\OfficeScan Client\pccntmon.exe" -HideWindow
O4 - HKLM\..\Run: [googletalk] C:\Program Files\Google\Google Talk\googletalk.exe /autostart
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre6\bin\jusched.exe"
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [googletalk] "C:\Program Files\Google\Google Talk\googletalk.exe" /autostart
O4 - HKUS\S-1-5-21-1935655697-1993962763-725345543-1005\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe (User 'Jessica')
O4 - HKUS\S-1-5-21-1935655697-1993962763-725345543-1005\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background (User 'Jessica')
O4 - HKUS\S-1-5-21-1935655697-1993962763-725345543-1005\..\Run: [H/PC Connection Agent] "C:\PROGRA~1\MI3AA1~1\wcescomm.exe" (User 'Jessica')
O4 - HKUS\S-1-5-18\..\Run: [DWQueuedReporting] "C:\PROGRA~1\COMMON~1\MICROS~1\DW\dwtrig20.exe" -t (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [DWQueuedReporting] "C:\PROGRA~1\COMMON~1\MICROS~1\DW\dwtrig20.exe" -t (User 'Default user')
O4 - S-1-5-21-1935655697-1993962763-725345543-1005 Startup: Cyber-shot Viewer Media Check Tool.lnk = C:\Program Files\Sony\Sony Picture Utility\VolumeWatcher\SPUVolumeWatcher.exe (User 'Jessica')
O4 - S-1-5-21-1935655697-1993962763-725345543-1005 User Startup: Cyber-shot Viewer Media Check Tool.lnk = C:\Program Files\Sony\Sony Picture Utility\VolumeWatcher\SPUVolumeWatcher.exe (User 'Jessica')
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~3\OFFICE10\EXCEL.EXE/3000
O9 - Extra button: Create Mobile Favorite - {2EAF5BB1-070F-11D3-9307-00C04FAE2D4F} - C:\PROGRA~1\MI3AA1~1\INetRepl.dll
O9 - Extra button: (no name) - {2EAF5BB2-070F-11D3-9307-00C04FAE2D4F} - C:\PROGRA~1\MI3AA1~1\INetRepl.dll
O9 - Extra 'Tools' menuitem: Create Mobile Favorite… - {2EAF5BB2-070F-11D3-9307-00C04FAE2D4F} - C:\PROGRA~1\MI3AA1~1\INetRepl.dll
O9 - Extra button: Capture with PixCert - {55ED1415-06D3-41D0-9FC4-BCCBF334F865} - C:\WINDOWS\system32\mscoree.DLL
O9 - Extra button: Real.com - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - C:\WINDOWS\system32\Shdocvw.dll
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O12 - Plugin for .spop: C:\Program Files\Internet Explorer\Plugins\NPDocBox.dll
O16 - DPF: ActiveGS.cab - http://www.virtualapple.com/activegs.cab
O16 - DPF: {0A5FD7C5-A45C-49FC-ADB5-9952547D5715} (Creative Software AutoUpdate) - http://www.creative.com/su/ocx/15031/CTSUEng.cab
O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) - http://go.microsoft.com/fwlink/?linkid=39204
O16 - DPF: {2B1AA38D-2D12-11D5-AAD0-00C04FA03D78} (LocalExec Control) - http://portal.uga.edu/nps/portal/gadgets/c…t/LocalExec.CAB
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://update.microsoft.com/windowsupdate/…b?1150243977734
O16 - DPF: {6E5A37BF-FD42-463A-877C-4EB7002E68AE} (Trend Micro ActiveX Scan Agent 6.5) - http://housecall65.trendmicro.com/housecal…ivex/hcImpl.cab
O16 - DPF: {A90A5822-F108-45AD-8482-9BC8B12DD539} (Crucial cpcScan) - http://www.crucial.com/controls/cpcScanner.cab
O16 - DPF: {B3872502-F9FD-4E96-93FF-0D37298F0689} (SOESysInfo Control) - http://everquest2.station.sony.com/beta_reg/soesysinfo.cab
O16 - DPF: {E5F5D008-DD2C-4D32-977D-1A0ADF03058B} (JuniperSetupSP1 Control) - https://ive1.primerica.com/dana-cached/setu…perSetupSP1.cab
O16 - DPF: {EB387D2F-E27B-4D36-979E-847D1036C65D} (QDiagHUpdateObj Class) - http://h30043.www3.hp.com/sj/en/check/qdiagh.cab?312
O16 - DPF: {F6ACF75C-C32C-447B-9BEF-46B766368D29} (Creative Software AutoUpdate Support Package) - http://www.creative.com/su/ocx/15033/CTPID.cab
O23 - Service: AOL TopSpeed Monitor (AOL TopSpeedMonitor) - America Online, Inc - C:\Program Files\Common Files\AOL\TopSpeed\2.0\aoltsmon.exe
O23 - Service: APC UPS Service - American Power Conversion Corporation - C:\Program Files\APC\APC PowerChute Personal Edition\mainserv.exe
O23 - Service: Ati HotKey Poller - ATI Technologies Inc. - C:\WINDOWS\system32\Ati2evxx.exe
O23 - Service: ATI Smart - Unknown owner - C:\WINDOWS\system32\ati2sgag.exe
O23 - Service: Creative Service for CDROM Access - Creative Technology Ltd - C:\WINDOWS\System32\CTsvcCDA.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: Imapi Helper - Alex Feinman - C:\Program Files\Alex Feinman\ISO Recorder\ImapiHelper.exe
O23 - Service: Java Quick Starter (JavaQuickStarterService) - Sun Microsystems, Inc. - C:\Program Files\Java\jre6\bin\jqs.exe
O23 - Service: OfficeScanNT RealTime Scan (ntrtscan) - Trend Micro Inc. - C:\Program Files\Trend Micro\OfficeScan Client\ntrtscan.exe
O23 - Service: OfficeScanNT Personal Firewall (OfcPfwSvc) - Trend Micro Inc. - C:\Program Files\Trend Micro\OfficeScan Client\OfcPfwSvc.exe
O23 - Service: PictureTaker - LANovation - C:\WINDOWS\System32\PCTKRNT.SYS
O23 - Service: Pml Driver HPH11 - HP - C:\WINDOWS\system32\HPHipm11.exe
O23 - Service: LiveShare P2P Server (RoxLiveShare) - Sonic Solutions - C:\Program Files\Common Files\Roxio Shared\SharedCOM8\RoxLiveShare.exe
O23 - Service: RoxMediaDB - Sonic Solutions - C:\Program Files\Common Files\Roxio Shared\SharedCOM8\RoxMediaDB.exe
O23 - Service: RoxUpnpRenderer (RoxUPnPRenderer) - Sonic Solutions - C:\Program Files\Common Files\Roxio Shared\SharedCom\RoxUpnpRenderer.exe
O23 - Service: RoxUpnpServer - Sonic Solutions - C:\Program Files\Roxio\Easy Media Creator 8\Digital Home\RoxUpnpServer.exe
O23 - Service: Roxio Hard Drive Watcher (RoxWatch) - Sonic Solutions - C:\Program Files\Common Files\Roxio Shared\SharedCOM8\RoxWatch.exe
O23 - Service: OfficeScanNT Listener (tmlisten) - Trend Micro Inc. - C:\Program Files\Trend Micro\OfficeScan Client\tmlisten.exe
–
End of file - 9383 bytes