dirtyboy103us
Posts: 25 +0
4 of 4
[2010/09/05 01:41:24 | 000,000,209 | ---- | C] () -- C:\Boot.bak
[2010/09/05 01:41:21 | 000,260,272 | RHS- | C] () -- C:\cmldr
[2010/09/05 01:38:24 | 000,256,512 | ---- | C] () -- C:\WINDOWS\PEV.exe
[2010/09/05 01:38:24 | 000,098,816 | ---- | C] () -- C:\WINDOWS\sed.exe
[2010/09/05 01:38:24 | 000,080,412 | ---- | C] () -- C:\WINDOWS\grep.exe
[2010/09/05 01:38:24 | 000,077,312 | ---- | C] () -- C:\WINDOWS\MBR.exe
[2010/09/05 01:38:24 | 000,068,096 | ---- | C] () -- C:\WINDOWS\zip.exe
[2010/09/05 01:31:27 | 003,837,097 | R--- | C] () -- C:\Documents and Settings\Owner\Desktop\ComboFix.exe
[2010/09/05 01:29:19 | 000,080,384 | ---- | C] () -- C:\Documents and Settings\Owner\Desktop\MBRCheck.exe
[2010/09/04 15:24:18 | 000,293,376 | ---- | C] () -- C:\Documents and Settings\Owner\Desktop\nn3dfywv.exe
[2010/09/04 01:13:10 | 001,188,006 | ---- | C] () -- C:\Documents and Settings\Owner\Desktop\tdsskiller.zip
[2010/09/02 23:05:39 | 000,525,824 | ---- | C] () -- C:\Documents and Settings\Owner\Desktop\dds.scr
[2010/09/02 12:49:21 | 000,465,298 | ---- | C] () -- C:\Documents and Settings\Owner\Desktop\RootRepeal.rar
[2010/09/02 10:16:34 | 000,000,765 | ---- | C] () -- C:\Documents and Settings\Owner\Application Data\Microsoft\Internet Explorer\Quick Launch\Malwarebytes' Anti-Malware.lnk
[2010/09/02 10:16:34 | 000,000,747 | ---- | C] () -- C:\Documents and Settings\All Users\Desktop\Malwarebytes' Anti-Malware.lnk
[2010/09/02 07:58:28 | 000,001,753 | ---- | C] () -- C:\Documents and Settings\All Users\Desktop\Avira AntiVir Control Center.lnk
[2010/09/02 07:55:18 | 044,092,504 | ---- | C] () -- C:\Documents and Settings\Owner\Desktop\avira_antivir_personal_en.exe
[2010/09/01 17:33:36 | 000,002,607 | ---- | C] () -- C:\TIMSLINE.p10
[2010/08/28 06:38:39 | 000,429,909 | ---- | C] () -- C:\Documents and Settings\Owner\My Documents\mortons floor 7.a.1
[2010/08/27 19:02:20 | 000,062,335 | ---- | C] () -- C:\Documents and Settings\Owner\My Documents\mortons floor 7.a.2.jpg
[2010/08/27 19:00:58 | 000,465,619 | ---- | C] () -- C:\Documents and Settings\Owner\My Documents\mortons floor 7.a.1.png
[2010/08/27 19:00:40 | 000,074,918 | ---- | C] () -- C:\Documents and Settings\Owner\My Documents\mortons floor 7.a.1.odg
[2010/08/27 18:56:02 | 000,227,179 | ---- | C] () -- C:\Documents and Settings\Owner\My Documents\mortons floor 7.a.png
[2010/08/27 18:52:52 | 000,074,996 | ---- | C] () -- C:\Documents and Settings\Owner\My Documents\mortons floor 7.a.odg
[2010/08/27 18:42:13 | 000,039,544 | ---- | C] () -- C:\Documents and Settings\Owner\My Documents\mortons floor 7.JPG
[2010/08/27 18:31:32 | 000,247,359 | ---- | C] () -- C:\Documents and Settings\Owner\My Documents\mortons floor 6.a.png
[2010/08/27 18:26:59 | 000,092,920 | ---- | C] () -- C:\Documents and Settings\Owner\My Documents\mortons floor 6.a.odg
[2010/08/24 19:27:37 | 000,023,135 | ---- | C] () -- C:\Documents and Settings\Owner\My Documents\company.CSV
[2010/08/20 12:57:48 | 040,038,634 | ---- | C] () -- C:\Documents and Settings\Owner\Desktop\Boxload.zip
[2010/08/20 10:17:43 | 000,041,899 | ---- | C] () -- C:\Documents and Settings\Owner\My Documents\mortons floor 6.JPG
[2010/08/20 10:03:56 | 000,041,389 | ---- | C] () -- C:\Documents and Settings\Owner\My Documents\mortons floor 5.JPG
[2010/08/18 19:35:58 | 000,039,402 | ---- | C] () -- C:\Documents and Settings\Owner\My Documents\mortons floor 4.JPG
[2010/08/18 19:11:34 | 000,034,495 | ---- | C] () -- C:\Documents and Settings\Owner\My Documents\mortons floor 3.JPG
[2010/08/08 10:49:45 | 000,000,256 | ---- | C] () -- C:\WINDOWS\tasks\Malwarebytes' Anti-Malware.job
[2010/07/22 08:58:09 | 009,160,917 | ---- | C] () -- C:\Documents and Settings\Owner\My Documents\B_Model_Single_Evaporator_sm.pdf
[2010/06/25 07:53:59 | 003,682,611 | ---- | C] () -- C:\Documents and Settings\Owner\Desktop\50A Installation.pdf
[2010/06/25 07:52:30 | 003,630,788 | ---- | C] () -- C:\Documents and Settings\Owner\Desktop\Mortons carrier.zip
[2010/06/25 06:44:51 | 001,710,113 | ---- | C] () -- C:\Documents and Settings\Owner\Desktop\20-10_062009 sporlan distibutors.pdf
[2010/06/25 04:49:05 | 000,069,632 | ---- | C] () -- C:\Documents and Settings\Owner\Desktop\Proposal mortons plaza.doc
[2010/06/25 04:46:09 | 000,069,632 | ---- | C] () -- C:\Documents and Settings\Owner\Desktop\Proposal.doc
[2010/06/17 14:17:52 | 000,135,483 | ---- | C] () -- C:\Documents and Settings\Owner\Desktop\Morton's Market Rev. 2 Proposal.docx
[2010/06/17 07:11:14 | 000,100,864 | ---- | C] () -- C:\Documents and Settings\Owner\Desktop\whitemountainrepair50tc05061610.doc
[2010/04/04 17:28:36 | 000,000,158 | ---- | C] () -- C:\Documents and Settings\Owner\Application Data\BBMS_EXCEPTION.txt
[2010/02/10 09:10:40 | 000,000,192 | ---- | C] () -- C:\WINDOWS\System32\MRT.INI
[2009/09/01 15:17:52 | 000,000,688 | ---- | C] () -- C:\WINDOWS\cdplayer.ini
[2009/06/29 23:02:04 | 000,000,047 | ---- | C] () -- C:\WINDOWS\NeroDigital.ini
[2008/11/01 11:17:55 | 000,000,353 | ---- | C] () -- C:\WINDOWS\Com_CoilSelection.ini
[2008/10/30 13:35:35 | 000,000,209 | ---- | C] () -- C:\WINDOWS\pdf2word.INI
[2008/10/30 13:17:54 | 000,176,235 | ---- | C] () -- C:\WINDOWS\System32\Primomonnt.dll
[2008/10/29 12:23:50 | 000,307,200 | ---- | C] () -- C:\WINDOWS\System32\EXPORTMODELLER.DLL
[2008/10/29 12:23:50 | 000,049,223 | ---- | C] () -- C:\WINDOWS\System32\CRTSLV.DLL
[2008/10/29 12:23:49 | 000,100,352 | ---- | C] () -- C:\WINDOWS\System32\PG32CONV.DLL
[2008/02/27 11:12:37 | 000,000,150 | ---- | C] () -- C:\WINDOWS\System32\CT_SUPPORT.INI
[2007/07/05 11:34:24 | 000,000,000 | ---- | C] () -- C:\WINDOWS\USLAUNCH.INI
[2007/04/09 17:02:07 | 000,000,017 | ---- | C] () -- C:\WINDOWS\MovingPicture.ini
[2007/04/09 15:57:52 | 000,194,248 | ---- | C] () -- C:\WINDOWS\System32\LTRFD13n.DLL
[2007/04/09 15:47:54 | 000,138,752 | ---- | C] () -- C:\WINDOWS\System32\mase32.dll
[2007/04/09 15:47:54 | 000,000,359 | ---- | C] () -- C:\WINDOWS\VFO.INI
[2007/04/09 15:47:53 | 000,196,096 | ---- | C] () -- C:\WINDOWS\System32\macd32.dll
[2007/04/09 15:47:53 | 000,136,192 | ---- | C] () -- C:\WINDOWS\System32\mamc32.dll
[2007/04/09 15:47:53 | 000,057,856 | ---- | C] () -- C:\WINDOWS\System32\masd32.dll
[2007/04/09 15:47:53 | 000,027,648 | ---- | C] () -- C:\WINDOWS\System32\ma32.dll
[2007/03/07 08:06:55 | 000,000,067 | ---- | C] () -- C:\WINDOWS\swupdate.INI
[2007/03/03 20:52:26 | 000,000,020 | ---- | C] () -- C:\WINDOWS\Hposcv07.INI
[2007/02/24 05:24:03 | 000,000,048 | ---- | C] () -- C:\WINDOWS\CRW.INI
[2007/02/24 05:18:53 | 000,003,584 | ---- | C] () -- C:\WINDOWS\System32\drivers\DLPORTIO.sys
[2007/02/24 05:18:45 | 000,460,800 | ---- | C] () -- C:\WINDOWS\System32\WCT32D.DLL
[2007/02/23 21:35:09 | 000,177,664 | ---- | C] () -- C:\Documents and Settings\Owner\Local Settings\Application Data\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2007/02/21 06:19:58 | 000,001,188 | ---- | C] () -- C:\Documents and Settings\Owner\Application Data\wklnhst.dat
[2007/02/09 17:21:25 | 000,000,128 | ---- | C] () -- C:\Documents and Settings\Owner\Local Settings\Application Data\fusioncache.dat
[2007/02/09 16:44:19 | 000,000,061 | ---- | C] () -- C:\WINDOWS\smscfg.ini
[2006/05/13 18:56:11 | 000,000,004 | ---- | C] () -- C:\WINDOWS\msoffice.ini
[2006/02/25 00:28:54 | 000,045,056 | ---- | C] () -- C:\WINDOWS\System32\TDispVol.dll
[2006/02/16 11:07:58 | 000,000,012 | ---- | C] () -- C:\WINDOWS\dirsaver.ini
[2006/02/16 05:50:52 | 000,000,222 | ---- | C] () -- C:\WINDOWS\wininit.ini
[2006/02/16 05:25:21 | 000,204,800 | ---- | C] () -- C:\WINDOWS\System32\IVIresizeW7.dll
[2006/02/16 05:25:21 | 000,200,704 | ---- | C] () -- C:\WINDOWS\System32\IVIresizeA6.dll
[2006/02/16 05:25:21 | 000,192,512 | ---- | C] () -- C:\WINDOWS\System32\IVIresizeP6.dll
[2006/02/16 05:25:21 | 000,192,512 | ---- | C] () -- C:\WINDOWS\System32\IVIresizeM6.dll
[2006/02/16 05:25:21 | 000,188,416 | ---- | C] () -- C:\WINDOWS\System32\IVIresizePX.dll
[2006/02/16 05:25:21 | 000,020,480 | ---- | C] () -- C:\WINDOWS\System32\IVIresize.dll
[2006/02/15 12:41:53 | 000,036,736 | ---- | C] () -- C:\WINDOWS\System32\drivers\CSIIDecoder_kern_i386.sys
[2006/02/15 12:41:53 | 000,029,184 | ---- | C] () -- C:\WINDOWS\System32\drivers\TSXT_kern_i386.sys
[2006/02/15 12:40:07 | 000,000,000 | ---- | C] () -- C:\WINDOWS\NDSTray.INI
[2006/02/15 12:28:50 | 000,128,113 | ---- | C] () -- C:\WINDOWS\System32\csellang.ini
[2006/02/15 12:28:50 | 000,045,056 | ---- | C] () -- C:\WINDOWS\System32\csellang.dll
[2006/02/15 12:28:50 | 000,010,165 | ---- | C] () -- C:\WINDOWS\System32\tosmreg.ini
[2006/02/15 12:28:50 | 000,007,671 | ---- | C] () -- C:\WINDOWS\System32\cseltbl.ini
[2006/02/15 12:25:00 | 000,118,784 | ---- | C] () -- C:\WINDOWS\System32\TCtrlIO.dll
[2006/02/15 12:21:53 | 000,135,168 | ---- | C] () -- C:\WINDOWS\System32\RtlCPAPI.dll
[2006/02/15 11:44:19 | 000,000,376 | ---- | C] () -- C:\WINDOWS\ODBC.INI
[2006/02/15 11:34:07 | 000,001,793 | ---- | C] () -- C:\WINDOWS\System32\fxsperf.ini
[2006/02/15 10:09:00 | 000,000,341 | ---- | C] () -- C:\WINDOWS\System32\OEMINFO.INI
[2005/11/29 00:33:56 | 000,000,000 | ---- | C] () -- C:\WINDOWS\System32\px.ini
[2005/09/02 18:44:08 | 000,110,592 | ---- | C] () -- C:\WINDOWS\System32\TosBtAcc.dll
[2005/08/24 19:20:28 | 000,009,472 | ---- | C] () -- C:\WINDOWS\System32\drivers\tbiosdrv.sys
[2005/08/05 18:01:54 | 000,235,008 | ---- | C] () -- C:\WINDOWS\System32\psisdecd.dll
[2005/07/23 01:30:20 | 000,065,536 | ---- | C] () -- C:\WINDOWS\System32\TosCommAPI.dll
[2004/07/20 21:04:02 | 000,094,208 | ---- | C] () -- C:\WINDOWS\System32\TosBtHcrpAPI.dll
[2004/01/15 18:43:28 | 000,114,688 | ---- | C] () -- C:\WINDOWS\System32\TBTMonUI.dll
[2003/01/07 19:05:08 | 000,002,695 | ---- | C] () -- C:\WINDOWS\System32\OUTLPERF.INI
========== LOP Check ==========
[2010/09/02 07:19:40 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\Alwil Software
[2007/02/12 13:07:26 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\COMMON FILES
[2006/02/17 05:57:21 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\DIGStream
[2008/11/05 13:05:06 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\EPSON
[2008/02/15 10:12:49 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\MSScanAppDataDir
[2010/05/16 20:33:34 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\Oberon Media
[2007/04/09 15:58:42 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\Pinnacle
[2007/04/09 15:59:18 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\Pinnacle Studio
[2010/04/04 07:27:42 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\Research In Motion
[2007/04/09 15:49:37 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\SmartSound Software Inc
[2010/09/02 07:10:54 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\TEMP
[2007/05/25 20:49:43 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\Viewpoint
[2007/02/25 17:18:09 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\WildTangent
[2006/05/13 19:35:32 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\YAHOO
[2010/09/01 18:40:09 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Owner\Application Data\ElevatedDiagnostics
[2009/03/28 14:54:26 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Owner\Application Data\GetRightToGo
[2008/06/01 20:14:58 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Owner\Application Data\ieSpell
[2007/12/24 20:49:08 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Owner\Application Data\InterVideo
[2010/07/18 04:45:20 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Owner\Application Data\iWin
[2009/10/01 15:33:34 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Owner\Application Data\licenses
[2007/12/02 10:09:04 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Owner\Application Data\LimeWire
[2009/10/01 15:36:01 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Owner\Application Data\PCMM2009
[2007/04/09 18:16:38 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Owner\Application Data\Pinnacle Systems
[2010/09/05 13:53:02 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Owner\Application Data\PriceGong
[2010/04/04 07:25:53 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Owner\Application Data\Research In Motion
[2009/05/31 11:39:44 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Owner\Application Data\Sensory
[2007/02/21 06:20:00 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Owner\Application Data\Template
[2009/05/20 12:52:43 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Owner\Application Data\toshiba
[2010/07/24 20:30:46 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Owner\Application Data\Unity
[2007/05/25 20:49:45 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Owner\Application Data\Viewpoint
[2010/09/02 07:06:20 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Owner\Application Data\WebbIE
[2007/02/25 17:18:09 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Owner\Application Data\WildTangent
========== Purity Check ==========
========== Custom Scans ==========
< %SYSTEMDRIVE%\*.* >
[2009/01/08 12:51:11 | 000,015,242 | ---- | M] () -- C:\aaw7boot.log
[2009/09/01 13:06:45 | 000,000,040 | ---- | M] () -- C:\Auth.prof
[2007/04/09 15:47:54 | 000,000,095 | ---- | M] () -- C:\AUTOEXEC.BAT
[2010/03/03 13:17:55 | 000,000,209 | ---- | M] () -- C:\Boot.bak
[2010/09/05 01:41:25 | 000,000,325 | RHS- | M] () -- C:\boot.ini
[2004/08/03 23:00:00 | 000,260,272 | RHS- | M] () -- C:\cmldr
[2009/08/19 13:37:02 | 000,001,195 | ---- | M] () -- C:\Coefficients.csv
[2010/09/05 13:10:20 | 000,028,848 | ---- | M] () -- C:\ComboFix.txt
[2006/02/15 11:38:58 | 000,000,000 | ---- | M] () -- C:\CONFIG.SYS
[2005/08/21 17:32:50 | 000,219,780 | ---- | M] () -- C:\EULA.pdf
[2006/02/15 11:38:58 | 000,000,000 | RHS- | M] () -- C:\IO.SYS
[2006/05/13 19:31:25 | 000,002,384 | -H-- | M] () -- C:\IPH.PH
[2006/02/15 11:38:58 | 000,000,000 | RHS- | M] () -- C:\MSDOS.SYS
[2004/08/10 08:00:00 | 000,047,564 | RHS- | M] () -- C:\NTDETECT.COM
[2009/03/31 08:25:31 | 000,250,048 | RHS- | M] () -- C:\ntldr
[2010/09/05 12:49:34 | 2145,386,496 | -HS- | M] () -- C:\pagefile.sys
[2010/08/20 13:08:38 | 000,017,408 | ---- | M] (Microsoft Corporation) -- C:\psapi.dll
[2010/01/24 11:25:41 | 000,001,982 | ---- | M] () -- C:\rapport.txt
[2006/09/14 18:15:18 | 000,001,670 | ---- | M] () -- C:\sysprep
[2010/09/04 01:15:55 | 000,049,368 | ---- | M] () -- C:\TDSSKiller.2.4.2.0_04.09.2010_01.14.44_log.txt
[2010/09/01 17:33:36 | 000,002,607 | ---- | M] () -- C:\TIMSLINE.p10
[2008/02/16 22:12:31 | 000,000,152 | ---- | M] () -- C:\YServer.txt
< %systemroot%\system32\Spool\prtprocs\w32x86\*.dll >
[2008/07/06 08:06:10 | 000,089,088 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\system32\spool\prtprocs\w32x86\filterpipelineprintproc.dll
[2003/06/18 21:31:48 | 000,018,944 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\system32\spool\prtprocs\w32x86\mdippr.dll
< %systemroot%\system32\*.wt >
< %systemroot%\system32\*.ruy >
< %systemroot%\Fonts\*.com >
[2006/04/18 15:39:28 | 000,026,040 | ---- | M] () -- C:\WINDOWS\Fonts\GlobalMonospace.CompositeFont
[2006/06/29 14:53:56 | 000,026,489 | ---- | M] () -- C:\WINDOWS\Fonts\GlobalSansSerif.CompositeFont
[2006/04/18 15:39:28 | 000,029,779 | ---- | M] () -- C:\WINDOWS\Fonts\GlobalSerif.CompositeFont
[2006/06/29 14:58:52 | 000,030,808 | ---- | M] () -- C:\WINDOWS\Fonts\GlobalUserInterface.CompositeFont
< %systemroot%\Fonts\*.dll >
< %systemroot%\system32\spool\prtprocs\w32x86\*.tmp >
< %systemroot%\*. /mp /s >
< %systemroot%\system32\*.dll /lockedfiles >
[2008/04/14 05:41:52 | 001,267,200 | ---- | M] (Microsoft Corporation) Unable to obtain MD5 -- C:\WINDOWS\system32\comsvcs.dll
< %systemroot%\Tasks\*.job /lockedfiles >
< %systemroot%\System32\config\*.sav >
[2006/02/15 03:28:58 | 000,094,208 | ---- | M] () -- C:\WINDOWS\system32\config\default.sav
[2006/02/15 03:28:58 | 000,659,456 | ---- | M] () -- C:\WINDOWS\system32\config\software.sav
[2006/02/15 03:28:57 | 000,897,024 | ---- | M] () -- C:\WINDOWS\system32\config\system.sav
< %systemroot%\system32\user32.dll /md5 >
[2008/04/14 05:42:10 | 000,578,560 | ---- | M] (Microsoft Corporation) MD5=B26B135FF1B9F60C9388B4A7D16F600B -- C:\WINDOWS\system32\user32.dll
< %systemroot%\system32\ws2_32.dll /md5 >
[2008/04/14 05:42:12 | 000,082,432 | ---- | M] (Microsoft Corporation) MD5=2CCC474EB85CEAA3E1FA1726580A3E5A -- C:\WINDOWS\system32\ws2_32.dll
< %systemroot%\system32\ws2help.dll /md5 >
[2008/04/14 05:42:12 | 000,019,968 | ---- | M] (Microsoft Corporation) MD5=9789E95E1D88EEB4B922BF3EA7779C28 -- C:\WINDOWS\system32\ws2help.dll
< HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows\WindowsUpdate\AU >
< HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\WindowsUpdate\ Auto Update\Results\Install|LastSuccessTime /rs >
========== Alternate Data Streams ==========
@Alternate Data Stream - 128 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:288A91F8
@Alternate Data Stream - 126 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:81F83028
@Alternate Data Stream - 116 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP
1B5B4F1
@Alternate Data Stream - 104 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP
FC5A2B2
< End of report >
[2010/09/05 01:41:24 | 000,000,209 | ---- | C] () -- C:\Boot.bak
[2010/09/05 01:41:21 | 000,260,272 | RHS- | C] () -- C:\cmldr
[2010/09/05 01:38:24 | 000,256,512 | ---- | C] () -- C:\WINDOWS\PEV.exe
[2010/09/05 01:38:24 | 000,098,816 | ---- | C] () -- C:\WINDOWS\sed.exe
[2010/09/05 01:38:24 | 000,080,412 | ---- | C] () -- C:\WINDOWS\grep.exe
[2010/09/05 01:38:24 | 000,077,312 | ---- | C] () -- C:\WINDOWS\MBR.exe
[2010/09/05 01:38:24 | 000,068,096 | ---- | C] () -- C:\WINDOWS\zip.exe
[2010/09/05 01:31:27 | 003,837,097 | R--- | C] () -- C:\Documents and Settings\Owner\Desktop\ComboFix.exe
[2010/09/05 01:29:19 | 000,080,384 | ---- | C] () -- C:\Documents and Settings\Owner\Desktop\MBRCheck.exe
[2010/09/04 15:24:18 | 000,293,376 | ---- | C] () -- C:\Documents and Settings\Owner\Desktop\nn3dfywv.exe
[2010/09/04 01:13:10 | 001,188,006 | ---- | C] () -- C:\Documents and Settings\Owner\Desktop\tdsskiller.zip
[2010/09/02 23:05:39 | 000,525,824 | ---- | C] () -- C:\Documents and Settings\Owner\Desktop\dds.scr
[2010/09/02 12:49:21 | 000,465,298 | ---- | C] () -- C:\Documents and Settings\Owner\Desktop\RootRepeal.rar
[2010/09/02 10:16:34 | 000,000,765 | ---- | C] () -- C:\Documents and Settings\Owner\Application Data\Microsoft\Internet Explorer\Quick Launch\Malwarebytes' Anti-Malware.lnk
[2010/09/02 10:16:34 | 000,000,747 | ---- | C] () -- C:\Documents and Settings\All Users\Desktop\Malwarebytes' Anti-Malware.lnk
[2010/09/02 07:58:28 | 000,001,753 | ---- | C] () -- C:\Documents and Settings\All Users\Desktop\Avira AntiVir Control Center.lnk
[2010/09/02 07:55:18 | 044,092,504 | ---- | C] () -- C:\Documents and Settings\Owner\Desktop\avira_antivir_personal_en.exe
[2010/09/01 17:33:36 | 000,002,607 | ---- | C] () -- C:\TIMSLINE.p10
[2010/08/28 06:38:39 | 000,429,909 | ---- | C] () -- C:\Documents and Settings\Owner\My Documents\mortons floor 7.a.1
[2010/08/27 19:02:20 | 000,062,335 | ---- | C] () -- C:\Documents and Settings\Owner\My Documents\mortons floor 7.a.2.jpg
[2010/08/27 19:00:58 | 000,465,619 | ---- | C] () -- C:\Documents and Settings\Owner\My Documents\mortons floor 7.a.1.png
[2010/08/27 19:00:40 | 000,074,918 | ---- | C] () -- C:\Documents and Settings\Owner\My Documents\mortons floor 7.a.1.odg
[2010/08/27 18:56:02 | 000,227,179 | ---- | C] () -- C:\Documents and Settings\Owner\My Documents\mortons floor 7.a.png
[2010/08/27 18:52:52 | 000,074,996 | ---- | C] () -- C:\Documents and Settings\Owner\My Documents\mortons floor 7.a.odg
[2010/08/27 18:42:13 | 000,039,544 | ---- | C] () -- C:\Documents and Settings\Owner\My Documents\mortons floor 7.JPG
[2010/08/27 18:31:32 | 000,247,359 | ---- | C] () -- C:\Documents and Settings\Owner\My Documents\mortons floor 6.a.png
[2010/08/27 18:26:59 | 000,092,920 | ---- | C] () -- C:\Documents and Settings\Owner\My Documents\mortons floor 6.a.odg
[2010/08/24 19:27:37 | 000,023,135 | ---- | C] () -- C:\Documents and Settings\Owner\My Documents\company.CSV
[2010/08/20 12:57:48 | 040,038,634 | ---- | C] () -- C:\Documents and Settings\Owner\Desktop\Boxload.zip
[2010/08/20 10:17:43 | 000,041,899 | ---- | C] () -- C:\Documents and Settings\Owner\My Documents\mortons floor 6.JPG
[2010/08/20 10:03:56 | 000,041,389 | ---- | C] () -- C:\Documents and Settings\Owner\My Documents\mortons floor 5.JPG
[2010/08/18 19:35:58 | 000,039,402 | ---- | C] () -- C:\Documents and Settings\Owner\My Documents\mortons floor 4.JPG
[2010/08/18 19:11:34 | 000,034,495 | ---- | C] () -- C:\Documents and Settings\Owner\My Documents\mortons floor 3.JPG
[2010/08/08 10:49:45 | 000,000,256 | ---- | C] () -- C:\WINDOWS\tasks\Malwarebytes' Anti-Malware.job
[2010/07/22 08:58:09 | 009,160,917 | ---- | C] () -- C:\Documents and Settings\Owner\My Documents\B_Model_Single_Evaporator_sm.pdf
[2010/06/25 07:53:59 | 003,682,611 | ---- | C] () -- C:\Documents and Settings\Owner\Desktop\50A Installation.pdf
[2010/06/25 07:52:30 | 003,630,788 | ---- | C] () -- C:\Documents and Settings\Owner\Desktop\Mortons carrier.zip
[2010/06/25 06:44:51 | 001,710,113 | ---- | C] () -- C:\Documents and Settings\Owner\Desktop\20-10_062009 sporlan distibutors.pdf
[2010/06/25 04:49:05 | 000,069,632 | ---- | C] () -- C:\Documents and Settings\Owner\Desktop\Proposal mortons plaza.doc
[2010/06/25 04:46:09 | 000,069,632 | ---- | C] () -- C:\Documents and Settings\Owner\Desktop\Proposal.doc
[2010/06/17 14:17:52 | 000,135,483 | ---- | C] () -- C:\Documents and Settings\Owner\Desktop\Morton's Market Rev. 2 Proposal.docx
[2010/06/17 07:11:14 | 000,100,864 | ---- | C] () -- C:\Documents and Settings\Owner\Desktop\whitemountainrepair50tc05061610.doc
[2010/04/04 17:28:36 | 000,000,158 | ---- | C] () -- C:\Documents and Settings\Owner\Application Data\BBMS_EXCEPTION.txt
[2010/02/10 09:10:40 | 000,000,192 | ---- | C] () -- C:\WINDOWS\System32\MRT.INI
[2009/09/01 15:17:52 | 000,000,688 | ---- | C] () -- C:\WINDOWS\cdplayer.ini
[2009/06/29 23:02:04 | 000,000,047 | ---- | C] () -- C:\WINDOWS\NeroDigital.ini
[2008/11/01 11:17:55 | 000,000,353 | ---- | C] () -- C:\WINDOWS\Com_CoilSelection.ini
[2008/10/30 13:35:35 | 000,000,209 | ---- | C] () -- C:\WINDOWS\pdf2word.INI
[2008/10/30 13:17:54 | 000,176,235 | ---- | C] () -- C:\WINDOWS\System32\Primomonnt.dll
[2008/10/29 12:23:50 | 000,307,200 | ---- | C] () -- C:\WINDOWS\System32\EXPORTMODELLER.DLL
[2008/10/29 12:23:50 | 000,049,223 | ---- | C] () -- C:\WINDOWS\System32\CRTSLV.DLL
[2008/10/29 12:23:49 | 000,100,352 | ---- | C] () -- C:\WINDOWS\System32\PG32CONV.DLL
[2008/02/27 11:12:37 | 000,000,150 | ---- | C] () -- C:\WINDOWS\System32\CT_SUPPORT.INI
[2007/07/05 11:34:24 | 000,000,000 | ---- | C] () -- C:\WINDOWS\USLAUNCH.INI
[2007/04/09 17:02:07 | 000,000,017 | ---- | C] () -- C:\WINDOWS\MovingPicture.ini
[2007/04/09 15:57:52 | 000,194,248 | ---- | C] () -- C:\WINDOWS\System32\LTRFD13n.DLL
[2007/04/09 15:47:54 | 000,138,752 | ---- | C] () -- C:\WINDOWS\System32\mase32.dll
[2007/04/09 15:47:54 | 000,000,359 | ---- | C] () -- C:\WINDOWS\VFO.INI
[2007/04/09 15:47:53 | 000,196,096 | ---- | C] () -- C:\WINDOWS\System32\macd32.dll
[2007/04/09 15:47:53 | 000,136,192 | ---- | C] () -- C:\WINDOWS\System32\mamc32.dll
[2007/04/09 15:47:53 | 000,057,856 | ---- | C] () -- C:\WINDOWS\System32\masd32.dll
[2007/04/09 15:47:53 | 000,027,648 | ---- | C] () -- C:\WINDOWS\System32\ma32.dll
[2007/03/07 08:06:55 | 000,000,067 | ---- | C] () -- C:\WINDOWS\swupdate.INI
[2007/03/03 20:52:26 | 000,000,020 | ---- | C] () -- C:\WINDOWS\Hposcv07.INI
[2007/02/24 05:24:03 | 000,000,048 | ---- | C] () -- C:\WINDOWS\CRW.INI
[2007/02/24 05:18:53 | 000,003,584 | ---- | C] () -- C:\WINDOWS\System32\drivers\DLPORTIO.sys
[2007/02/24 05:18:45 | 000,460,800 | ---- | C] () -- C:\WINDOWS\System32\WCT32D.DLL
[2007/02/23 21:35:09 | 000,177,664 | ---- | C] () -- C:\Documents and Settings\Owner\Local Settings\Application Data\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2007/02/21 06:19:58 | 000,001,188 | ---- | C] () -- C:\Documents and Settings\Owner\Application Data\wklnhst.dat
[2007/02/09 17:21:25 | 000,000,128 | ---- | C] () -- C:\Documents and Settings\Owner\Local Settings\Application Data\fusioncache.dat
[2007/02/09 16:44:19 | 000,000,061 | ---- | C] () -- C:\WINDOWS\smscfg.ini
[2006/05/13 18:56:11 | 000,000,004 | ---- | C] () -- C:\WINDOWS\msoffice.ini
[2006/02/25 00:28:54 | 000,045,056 | ---- | C] () -- C:\WINDOWS\System32\TDispVol.dll
[2006/02/16 11:07:58 | 000,000,012 | ---- | C] () -- C:\WINDOWS\dirsaver.ini
[2006/02/16 05:50:52 | 000,000,222 | ---- | C] () -- C:\WINDOWS\wininit.ini
[2006/02/16 05:25:21 | 000,204,800 | ---- | C] () -- C:\WINDOWS\System32\IVIresizeW7.dll
[2006/02/16 05:25:21 | 000,200,704 | ---- | C] () -- C:\WINDOWS\System32\IVIresizeA6.dll
[2006/02/16 05:25:21 | 000,192,512 | ---- | C] () -- C:\WINDOWS\System32\IVIresizeP6.dll
[2006/02/16 05:25:21 | 000,192,512 | ---- | C] () -- C:\WINDOWS\System32\IVIresizeM6.dll
[2006/02/16 05:25:21 | 000,188,416 | ---- | C] () -- C:\WINDOWS\System32\IVIresizePX.dll
[2006/02/16 05:25:21 | 000,020,480 | ---- | C] () -- C:\WINDOWS\System32\IVIresize.dll
[2006/02/15 12:41:53 | 000,036,736 | ---- | C] () -- C:\WINDOWS\System32\drivers\CSIIDecoder_kern_i386.sys
[2006/02/15 12:41:53 | 000,029,184 | ---- | C] () -- C:\WINDOWS\System32\drivers\TSXT_kern_i386.sys
[2006/02/15 12:40:07 | 000,000,000 | ---- | C] () -- C:\WINDOWS\NDSTray.INI
[2006/02/15 12:28:50 | 000,128,113 | ---- | C] () -- C:\WINDOWS\System32\csellang.ini
[2006/02/15 12:28:50 | 000,045,056 | ---- | C] () -- C:\WINDOWS\System32\csellang.dll
[2006/02/15 12:28:50 | 000,010,165 | ---- | C] () -- C:\WINDOWS\System32\tosmreg.ini
[2006/02/15 12:28:50 | 000,007,671 | ---- | C] () -- C:\WINDOWS\System32\cseltbl.ini
[2006/02/15 12:25:00 | 000,118,784 | ---- | C] () -- C:\WINDOWS\System32\TCtrlIO.dll
[2006/02/15 12:21:53 | 000,135,168 | ---- | C] () -- C:\WINDOWS\System32\RtlCPAPI.dll
[2006/02/15 11:44:19 | 000,000,376 | ---- | C] () -- C:\WINDOWS\ODBC.INI
[2006/02/15 11:34:07 | 000,001,793 | ---- | C] () -- C:\WINDOWS\System32\fxsperf.ini
[2006/02/15 10:09:00 | 000,000,341 | ---- | C] () -- C:\WINDOWS\System32\OEMINFO.INI
[2005/11/29 00:33:56 | 000,000,000 | ---- | C] () -- C:\WINDOWS\System32\px.ini
[2005/09/02 18:44:08 | 000,110,592 | ---- | C] () -- C:\WINDOWS\System32\TosBtAcc.dll
[2005/08/24 19:20:28 | 000,009,472 | ---- | C] () -- C:\WINDOWS\System32\drivers\tbiosdrv.sys
[2005/08/05 18:01:54 | 000,235,008 | ---- | C] () -- C:\WINDOWS\System32\psisdecd.dll
[2005/07/23 01:30:20 | 000,065,536 | ---- | C] () -- C:\WINDOWS\System32\TosCommAPI.dll
[2004/07/20 21:04:02 | 000,094,208 | ---- | C] () -- C:\WINDOWS\System32\TosBtHcrpAPI.dll
[2004/01/15 18:43:28 | 000,114,688 | ---- | C] () -- C:\WINDOWS\System32\TBTMonUI.dll
[2003/01/07 19:05:08 | 000,002,695 | ---- | C] () -- C:\WINDOWS\System32\OUTLPERF.INI
========== LOP Check ==========
[2010/09/02 07:19:40 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\Alwil Software
[2007/02/12 13:07:26 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\COMMON FILES
[2006/02/17 05:57:21 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\DIGStream
[2008/11/05 13:05:06 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\EPSON
[2008/02/15 10:12:49 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\MSScanAppDataDir
[2010/05/16 20:33:34 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\Oberon Media
[2007/04/09 15:58:42 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\Pinnacle
[2007/04/09 15:59:18 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\Pinnacle Studio
[2010/04/04 07:27:42 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\Research In Motion
[2007/04/09 15:49:37 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\SmartSound Software Inc
[2010/09/02 07:10:54 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\TEMP
[2007/05/25 20:49:43 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\Viewpoint
[2007/02/25 17:18:09 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\WildTangent
[2006/05/13 19:35:32 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\YAHOO
[2010/09/01 18:40:09 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Owner\Application Data\ElevatedDiagnostics
[2009/03/28 14:54:26 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Owner\Application Data\GetRightToGo
[2008/06/01 20:14:58 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Owner\Application Data\ieSpell
[2007/12/24 20:49:08 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Owner\Application Data\InterVideo
[2010/07/18 04:45:20 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Owner\Application Data\iWin
[2009/10/01 15:33:34 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Owner\Application Data\licenses
[2007/12/02 10:09:04 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Owner\Application Data\LimeWire
[2009/10/01 15:36:01 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Owner\Application Data\PCMM2009
[2007/04/09 18:16:38 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Owner\Application Data\Pinnacle Systems
[2010/09/05 13:53:02 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Owner\Application Data\PriceGong
[2010/04/04 07:25:53 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Owner\Application Data\Research In Motion
[2009/05/31 11:39:44 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Owner\Application Data\Sensory
[2007/02/21 06:20:00 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Owner\Application Data\Template
[2009/05/20 12:52:43 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Owner\Application Data\toshiba
[2010/07/24 20:30:46 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Owner\Application Data\Unity
[2007/05/25 20:49:45 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Owner\Application Data\Viewpoint
[2010/09/02 07:06:20 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Owner\Application Data\WebbIE
[2007/02/25 17:18:09 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Owner\Application Data\WildTangent
========== Purity Check ==========
========== Custom Scans ==========
< %SYSTEMDRIVE%\*.* >
[2009/01/08 12:51:11 | 000,015,242 | ---- | M] () -- C:\aaw7boot.log
[2009/09/01 13:06:45 | 000,000,040 | ---- | M] () -- C:\Auth.prof
[2007/04/09 15:47:54 | 000,000,095 | ---- | M] () -- C:\AUTOEXEC.BAT
[2010/03/03 13:17:55 | 000,000,209 | ---- | M] () -- C:\Boot.bak
[2010/09/05 01:41:25 | 000,000,325 | RHS- | M] () -- C:\boot.ini
[2004/08/03 23:00:00 | 000,260,272 | RHS- | M] () -- C:\cmldr
[2009/08/19 13:37:02 | 000,001,195 | ---- | M] () -- C:\Coefficients.csv
[2010/09/05 13:10:20 | 000,028,848 | ---- | M] () -- C:\ComboFix.txt
[2006/02/15 11:38:58 | 000,000,000 | ---- | M] () -- C:\CONFIG.SYS
[2005/08/21 17:32:50 | 000,219,780 | ---- | M] () -- C:\EULA.pdf
[2006/02/15 11:38:58 | 000,000,000 | RHS- | M] () -- C:\IO.SYS
[2006/05/13 19:31:25 | 000,002,384 | -H-- | M] () -- C:\IPH.PH
[2006/02/15 11:38:58 | 000,000,000 | RHS- | M] () -- C:\MSDOS.SYS
[2004/08/10 08:00:00 | 000,047,564 | RHS- | M] () -- C:\NTDETECT.COM
[2009/03/31 08:25:31 | 000,250,048 | RHS- | M] () -- C:\ntldr
[2010/09/05 12:49:34 | 2145,386,496 | -HS- | M] () -- C:\pagefile.sys
[2010/08/20 13:08:38 | 000,017,408 | ---- | M] (Microsoft Corporation) -- C:\psapi.dll
[2010/01/24 11:25:41 | 000,001,982 | ---- | M] () -- C:\rapport.txt
[2006/09/14 18:15:18 | 000,001,670 | ---- | M] () -- C:\sysprep
[2010/09/04 01:15:55 | 000,049,368 | ---- | M] () -- C:\TDSSKiller.2.4.2.0_04.09.2010_01.14.44_log.txt
[2010/09/01 17:33:36 | 000,002,607 | ---- | M] () -- C:\TIMSLINE.p10
[2008/02/16 22:12:31 | 000,000,152 | ---- | M] () -- C:\YServer.txt
< %systemroot%\system32\Spool\prtprocs\w32x86\*.dll >
[2008/07/06 08:06:10 | 000,089,088 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\system32\spool\prtprocs\w32x86\filterpipelineprintproc.dll
[2003/06/18 21:31:48 | 000,018,944 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\system32\spool\prtprocs\w32x86\mdippr.dll
< %systemroot%\system32\*.wt >
< %systemroot%\system32\*.ruy >
< %systemroot%\Fonts\*.com >
[2006/04/18 15:39:28 | 000,026,040 | ---- | M] () -- C:\WINDOWS\Fonts\GlobalMonospace.CompositeFont
[2006/06/29 14:53:56 | 000,026,489 | ---- | M] () -- C:\WINDOWS\Fonts\GlobalSansSerif.CompositeFont
[2006/04/18 15:39:28 | 000,029,779 | ---- | M] () -- C:\WINDOWS\Fonts\GlobalSerif.CompositeFont
[2006/06/29 14:58:52 | 000,030,808 | ---- | M] () -- C:\WINDOWS\Fonts\GlobalUserInterface.CompositeFont
< %systemroot%\Fonts\*.dll >
< %systemroot%\system32\spool\prtprocs\w32x86\*.tmp >
< %systemroot%\*. /mp /s >
< %systemroot%\system32\*.dll /lockedfiles >
[2008/04/14 05:41:52 | 001,267,200 | ---- | M] (Microsoft Corporation) Unable to obtain MD5 -- C:\WINDOWS\system32\comsvcs.dll
< %systemroot%\Tasks\*.job /lockedfiles >
< %systemroot%\System32\config\*.sav >
[2006/02/15 03:28:58 | 000,094,208 | ---- | M] () -- C:\WINDOWS\system32\config\default.sav
[2006/02/15 03:28:58 | 000,659,456 | ---- | M] () -- C:\WINDOWS\system32\config\software.sav
[2006/02/15 03:28:57 | 000,897,024 | ---- | M] () -- C:\WINDOWS\system32\config\system.sav
< %systemroot%\system32\user32.dll /md5 >
[2008/04/14 05:42:10 | 000,578,560 | ---- | M] (Microsoft Corporation) MD5=B26B135FF1B9F60C9388B4A7D16F600B -- C:\WINDOWS\system32\user32.dll
< %systemroot%\system32\ws2_32.dll /md5 >
[2008/04/14 05:42:12 | 000,082,432 | ---- | M] (Microsoft Corporation) MD5=2CCC474EB85CEAA3E1FA1726580A3E5A -- C:\WINDOWS\system32\ws2_32.dll
< %systemroot%\system32\ws2help.dll /md5 >
[2008/04/14 05:42:12 | 000,019,968 | ---- | M] (Microsoft Corporation) MD5=9789E95E1D88EEB4B922BF3EA7779C28 -- C:\WINDOWS\system32\ws2help.dll
< HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows\WindowsUpdate\AU >
< HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\WindowsUpdate\ Auto Update\Results\Install|LastSuccessTime /rs >
========== Alternate Data Streams ==========
@Alternate Data Stream - 128 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:288A91F8
@Alternate Data Stream - 126 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:81F83028
@Alternate Data Stream - 116 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP
@Alternate Data Stream - 104 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP
< End of report >