1. You are viewing our forum as a guest. For full access please Register. WindowsBBS.com is completely free, paid for by advertisers and donations.

Solved Programs won't load or very slow

Discussion in 'Malware and Virus Removal Archive' started by chinaclipper, 2013/05/16.

  1. 2013/05/16
    chinaclipper

    chinaclipper Well-Known Member Thread Starter

    Joined:
    2010/01/20
    Messages:
    96
    Likes Received:
    0
    [Resolved] Programs won't load or very slow

    I am using Windows XP. My programs have been getting more and more difficult to load. I click on the program (Firefox, Quicken, Explorer, Picassa etc) and the hourglass goes for like two seconds, then nothing. It won't open. If I shut down, the computer says "Do you need to close these programs before shutting down" or something like that. Many times I have to completely reboot, then try again. Sometimes this works, but it is taking so long. If they DO load, after I am done, when I come back to the computer, they will no longer run. I have tried scanning for virii, I have tried the malware scanners. I have tried shutting down some of the programs in the MSCONFIG at startup. This is getting worse and worse.

    What can I do? Am I infected?

    Here are the logs:
    Malware:
    Malwarebytes Anti-Malware (Trial) 1.75.0.1300
    www.malwarebytes.org

    Database version: v2013.05.15.10

    Windows XP Service Pack 3 x86 NTFS (Safe Mode/Networking)
    Internet Explorer 8.0.6001.18702
    Administrator :: ALPHA [administrator]

    Protection: Disabled

    5/16/2013 8:58:53 AM
    mbam-log-2013-05-16 (08-58-53).txt

    Scan type: Quick scan
    Scan options enabled: Memory | Startup | Registry | File System | Heuristics/Extra | Heuristics/Shuriken | PUP | PUM
    Scan options disabled: P2P
    Objects scanned: 265117
    Time elapsed: 6 minute(s), 21 second(s)

    Memory Processes Detected: 0
    (No malicious items detected)

    Memory Modules Detected: 0
    (No malicious items detected)

    Registry Keys Detected: 0
    (No malicious items detected)

    Registry Values Detected: 0
    (No malicious items detected)

    Registry Data Items Detected: 0
    (No malicious items detected)

    Folders Detected: 0
    (No malicious items detected)
    **********

    MBR
    MBRCheck, version 1.2.3
    (c) 2010, AD

    Command-line:
    Windows Version: Windows XP Professional
    Windows Information: Service Pack 3 (build 2600)
    Logical Drives Mask: 0x0000007d

    Kernel Drivers (total 107):
    0x804D7000 \WINDOWS\system32\ntoskrnl.exe
    0x80700000 \WINDOWS\system32\hal.dll
    0x8A242000 \WINDOWS\system32\KDCOM.DLL
    0xF789B000 \WINDOWS\system32\BOOTVID.dll
    0xF75A8000 ACPI.sys
    0xF7987000 \WINDOWS\system32\DRIVERS\WMILIB.SYS
    0xF7597000 pci.sys
    0xF75F7000 isapnp.sys
    0xF7989000 gfibto.sys
    0xF7A4F000 pciide.sys
    0xF7707000 \WINDOWS\system32\DRIVERS\PCIIDEX.SYS
    0xF7607000 MountMgr.sys
    0xF74D8000 ftdisk.sys
    0xF798B000 dmload.sys
    0xF74B2000 dmio.sys
    0xF770F000 PartMgr.sys
    0xF7617000 VolSnap.sys
    0xF749A000 atapi.sys
    0xF7627000 disk.sys
    0xF7637000 \WINDOWS\system32\DRIVERS\CLASSPNP.SYS
    0xF747A000 fltmgr.sys
    0xF7468000 sr.sys
    0xF7647000 PxHelp20.sys
    0xF7451000 KSecDD.sys
    0xF743E000 WudfPf.sys
    0xF7B52000 Ntfs.sys
    0xF7411000 NDIS.sys
    0xF7657000 ohci1394.sys
    0xF7667000 \WINDOWS\system32\DRIVERS\1394BUS.SYS
    0xBA7E6000 Mup.sys
    0xF7717000 avgrkx86.sys
    0xBA7BC000 avglogx.sys
    0xBA7A2000 avgmfx86.sys
    0xF7677000 avgidshx.sys
    0xBA66A000 \SystemRoot\system32\DRIVERS\HDAudBus.sys
    0xF76D7000 \SystemRoot\system32\DRIVERS\l151x86.sys
    0xF775F000 \SystemRoot\system32\DRIVERS\usbuhci.sys
    0xBA646000 \SystemRoot\system32\DRIVERS\USBPORT.SYS
    0xF7767000 \SystemRoot\system32\DRIVERS\usbehci.sys
    0xF7777000 \SystemRoot\system32\DRIVERS\fdc.sys
    0xF7991000 \SystemRoot\system32\DRIVERS\ASACPI.sys
    0xF76E7000 \SystemRoot\system32\DRIVERS\i8042prt.sys
    0xF7917000 \SystemRoot\system32\DRIVERS\L8042Kbd.sys
    0xF778F000 \SystemRoot\system32\DRIVERS\kbdclass.sys
    0xF76F7000 \SystemRoot\system32\DRIVERS\imapi.sys
    0xF7587000 \SystemRoot\system32\DRIVERS\cdrom.sys
    0xF7577000 \SystemRoot\system32\DRIVERS\redbook.sys
    0xBA583000 \SystemRoot\system32\DRIVERS\ks.sys
    0xF77A7000 \SystemRoot\system32\DRIVERS\GEARAspiWDM.sys
    0xF7567000 \SystemRoot\system32\DRIVERS\rasl2tp.sys
    0xF792F000 \SystemRoot\system32\DRIVERS\ndistapi.sys
    0xBA56C000 \SystemRoot\system32\DRIVERS\ndiswan.sys
    0xF7557000 \SystemRoot\system32\DRIVERS\raspppoe.sys
    0xF7547000 \SystemRoot\system32\DRIVERS\raspptp.sys
    0xF77C7000 \SystemRoot\system32\DRIVERS\TDI.SYS
    0xBA533000 \SystemRoot\system32\DRIVERS\psched.sys
    0xF7537000 \SystemRoot\system32\DRIVERS\msgpc.sys
    0xF77D7000 \SystemRoot\system32\DRIVERS\ptilink.sys
    0xF77E7000 \SystemRoot\system32\DRIVERS\raspti.sys
    0xBA4B3000 \SystemRoot\system32\DRIVERS\rdpdr.sys
    0xF7527000 \SystemRoot\system32\DRIVERS\termdd.sys
    0xF77F7000 \SystemRoot\system32\DRIVERS\mouclass.sys
    0xF7997000 \SystemRoot\system32\DRIVERS\swenum.sys
    0xBA455000 \SystemRoot\system32\DRIVERS\update.sys
    0xBA6DA000 \SystemRoot\system32\DRIVERS\mssmbios.sys
    0xF7517000 \SystemRoot\System32\Drivers\NDProxy.SYS
    0xF7507000 \SystemRoot\system32\DRIVERS\usbhub.sys
    0xF79A1000 \SystemRoot\system32\DRIVERS\USBD.SYS
    0xF77BF000 \SystemRoot\system32\DRIVERS\flpydisk.sys
    0xF79A5000 \SystemRoot\System32\Drivers\Fs_Rec.SYS
    0xF7A9E000 \SystemRoot\System32\Drivers\Null.SYS
    0xF79A9000 \SystemRoot\System32\Drivers\Beep.SYS
    0xBA51B000 \SystemRoot\System32\drivers\vga.sys
    0xBA3D9000 \SystemRoot\System32\drivers\VIDEOPRT.SYS
    0xF79AD000 \SystemRoot\System32\DRIVERS\RDPCDD.sys
    0xBA4FB000 \SystemRoot\System32\Drivers\Msfs.SYS
    0xBA4EB000 \SystemRoot\System32\Drivers\Npfs.SYS
    0xBA6A2000 \SystemRoot\system32\DRIVERS\rasacd.sys
    0xBA3A6000 \SystemRoot\system32\DRIVERS\ipsec.sys
    0xBA34D000 \SystemRoot\system32\DRIVERS\tcpip.sys
    0xBA2FF000 \SystemRoot\system32\DRIVERS\ipnat.sys
    0xBA2D8000 \SystemRoot\system32\DRIVERS\avgtdix.sys
    0xBA2B0000 \SystemRoot\system32\DRIVERS\netbt.sys
    0xBA284000 \SystemRoot\System32\drivers\afd.sys
    0xBA792000 \SystemRoot\system32\DRIVERS\netbios.sys
    0xBA1B9000 \SystemRoot\system32\DRIVERS\rdbss.sys
    0xBA149000 \SystemRoot\system32\DRIVERS\mrxsmb.sys
    0xBA762000 \SystemRoot\System32\Drivers\Cdfs.SYS
    0xF781F000 \SystemRoot\system32\DRIVERS\USBSTOR.SYS
    0xBA69A000 \SystemRoot\system32\DRIVERS\hidusb.sys
    0xBA752000 \SystemRoot\system32\DRIVERS\HIDCLASS.SYS
    0xF776F000 \SystemRoot\system32\DRIVERS\HIDPARSE.SYS
    0xBA345000 \SystemRoot\system32\DRIVERS\mouhid.sys
    0xBA109000 \SystemRoot\System32\Drivers\dump_atapi.sys
    0xF79BF000 \SystemRoot\System32\Drivers\dump_WMILIB.SYS
    0xBF800000 \SystemRoot\System32\win32k.sys
    0xBA329000 \SystemRoot\System32\drivers\Dxapi.sys
    0xF7757000 \SystemRoot\System32\watchdog.sys
    0xBF000000 \SystemRoot\System32\drivers\dxg.sys
    0xBA2A6000 \SystemRoot\System32\drivers\dxgthk.sys
    0xBF012000 \SystemRoot\System32\ATMFD.DLL
    0xB9BC1000 \SystemRoot\system32\DRIVERS\ndisuio.sys
    0xB98C9000 \SystemRoot\system32\DRIVERS\srv.sys
    0xB982D000 \SystemRoot\System32\Drivers\Fastfat.SYS
    0xBF059000 \SystemRoot\System32\TSDDD.dll
    0xBFF50000 \SystemRoot\System32\framebuf.dll
    0x7C900000 \WINDOWS\system32\ntdll.dll

    Processes (total 23):
    0 System Idle Process
    4 System
    540 C:\WINDOWS\system32\smss.exe
    596 csrss.exe
    620 C:\WINDOWS\system32\winlogon.exe
    668 C:\WINDOWS\system32\services.exe
    680 C:\WINDOWS\system32\lsass.exe
    832 C:\WINDOWS\system32\svchost.exe
    916 svchost.exe
    1100 C:\WINDOWS\system32\svchost.exe
    1172 C:\WINDOWS\system32\svchost.exe
    1200 svchost.exe
    1444 C:\Program Files\SUPERAntiSpyware\SASCORE.EXE
    1636 C:\Program Files\Ad-Aware Antivirus\AdAwareService.exe
    1648 explorer.exe
    1692 C:\Program Files\Ad-Aware Antivirus\SBAMSvc.exe
    1004 firefox.exe
    1044 csrss.exe
    1088 C:\WINDOWS\system32\winlogon.exe
    124 C:\WINDOWS\explorer.exe
    1916 C:\Program Files\Mozilla Firefox\firefox.exe
    2904 C:\Program Files\Mozilla Firefox\plugin-container.exe
    3752 C:\Documents and Settings\Administrator\Desktop\MBRCheck.exe

    \\.\C: --> \\.\PhysicalDrive0 at offset 0x00000000`00007e00 (NTFS)

    PhysicalDrive0 Model Number: ST3500630AS, Rev: 3.AAK

    Size Device Name MBR Status
    --------------------------------------------
    465 GB \\.\PhysicalDrive0 Windows XP MBR code detected
    SHA1: DA38B874B7713D1B51CBC449F4EF809B0DEC644A


    Done!

    DDS:

    DDS (Ver_2012-11-20.01) - NTFS_x86 NETWORK
    Internet Explorer: 8.0.6001.18702 BrowserJavaVersion: 10.17.2
    Run by Administrator at 8:53:05 on 2013-05-16
    Microsoft Windows XP Professional 5.1.2600.3.1252.1.1033.18.2047.742 [GMT -5:00]
    .
    AV: AVG AntiVirus Free Edition 2013 *Enabled/Updated* {17DDD097-36FF-435F-9E1B-52D74245D6BF}
    AV: Lavasoft Ad-Aware *Disabled/Updated* {964FCE60-0B18-4D30-ADD6-EB178909041C}
    FW: Lavasoft Ad-Aware *Disabled*
    FW: ZoneAlarm Firewall *Disabled*
    .
    ============== Running Processes ================
    .
    C:\Program Files\SUPERAntiSpyware\SASCORE.EXE
    C:\Program Files\Ad-Aware Antivirus\AdAwareService.exe
    C:\WINDOWS\Explorer.EXE
    C:\Program Files\Ad-Aware Antivirus\SBAMSvc.exe
    C:\Program Files\Mozilla Firefox\firefox.exe
    C:\WINDOWS\Explorer.EXE
    C:\Program Files\Mozilla Firefox\firefox.exe
    C:\WINDOWS\system32\NOTEPAD.EXE
    C:\Program Files\Mozilla Firefox\plugin-container.exe
    C:\WINDOWS\system32\wbem\wmiprvse.exe
    C:\WINDOWS\system32\svchost.exe -k netsvcs
    C:\WINDOWS\system32\svchost.exe -k netsvcs
    C:\WINDOWS\system32\svchost.exe -k NetworkService
    .
    ============== Pseudo HJT Report ===============
    .
    uInternet Connection Wizard,ShellNext = hxxp://www.fileresearchcenter.com/whatsrunningpre.html?tag=SUPERANTISPYWARE&trial=no&activated=no&appid={388887D8-7670-4B23-A762-3B7221F98042}
    mWinlogon: Userinit = c:\windows\system32\userinit.exe
    BHO: {02478D38-C3F9-4efb-9B51-7695ECA05670} - <orphaned>
    BHO: Adobe PDF Link Helper: {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - c:\program files\common files\adobe\acrobat\activex\AcroIEHelperShim.dll
    BHO: Zonealarm Helper Object: {2A841F7A-A014-4DA5-B6D9-8B913DFB7A8C} - c:\program files\check point software technologies ltd\zonealarm\1.6.7.4\bh\zonealarm.dll
    BHO: {5C255C8A-E604-49b4-9D64-90988571CECB} - <orphaned>
    BHO: Groove GFS Browser Helper: {72853161-30C5-4D22-B7F9-0BBC1D38A37E} - c:\program files\microsoft office\office12\GrooveShellExtensions.dll
    BHO: Java(tm) Plug-In SSV Helper: {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - c:\program files\java\jre7\bin\ssv.dll
    BHO: Windows Live Sign-in Helper: {9030D464-4C02-4ABF-8ECC-5164760863C6} - c:\program files\common files\microsoft shared\windows live\WindowsLiveLogin.dll
    BHO: Java(tm) Plug-In 2 SSV Helper: {DBC80044-A445-435b-BC74-9C25C1C588A9} - c:\program files\java\jre7\bin\jp2ssv.dll
    TB: ZoneAlarm Security Toolbar: {438FAE3E-BDEF-44D3-AB8B-0C7C8350DF59} - c:\program files\check point software technologies ltd\zonealarm\1.6.7.4\zonealarmTlbr.dll
    uRun: [ctfmon.exe] c:\windows\system32\ctfmon.exe
    uRunOnce: [NeroHomeFirstStart] c:\program files\common files\ahead\lib\NMFirstStart.exe
    uRunOnce: [spchecker] "c:\program files\avg\avg10\notification\SPCheckerTE.exe "
    mRun: [NvCplDaemon] RUNDLL32.EXE c:\windows\system32\NvCpl.dll,NvStartup
    mRun: [AVG_UI] "c:\program files\avg\avg2013\avgui.exe" /TRAYONLY
    mRun: [IJNetworkScannerSelectorEX] c:\program files\canon\ij network scanner selector ex\CNMNSST.exe /FORCE
    mRun: [High Definition Audio Property Page Shortcut] HDAShCut.exe
    mRun: [Carbonite Backup] c:\program files\carbonite\carbonite backup\CarboniteUI.exe
    mRun: [Ad-Aware Browsing Protection] "c:\documents and settings\all users\application data\ad-aware browsing protection\adawarebp.exe "
    mRun: [Ad-Aware Antivirus] "c:\program files\ad-aware antivirus\AdAwareLauncher" --windows-run
    mRun: [QuickTime Task] "c:\program files\quicktime\qttask.exe" -atboottime
    mRun: [KernelFaultCheck] c:\windows\system32\dumprep 0 -k
    mRun: [MSConfig] c:\windows\pchealth\helpctr\binaries\MSCONFIG.EXE /auto
    dRunOnce: [FlashPlayerUpdate] c:\windows\system32\macromed\flash\FlashUtil32_11_6_602_180_ActiveX.exe -update activex
    uPolicies-Explorer: NoDriveTypeAutoRun = dword:145
    mPolicies-Explorer: NoDriveAutoRun = dword:67108863
    mPolicies-Explorer: NoDriveTypeAutoRun = dword:323
    mPolicies-Explorer: NoDrives = dword:0
    mPolicies-Windows\System: Allow-LogonScript-NetbiosDisabled = dword:1
    mPolicies-Explorer: NoDriveTypeAutoRun = dword:323
    mPolicies-Explorer: NoDriveAutoRun = dword:67108863
    IE: Add to Google Photos Screensa&ver - c:\windows\system32\GPhotos.scr/200
    IE: {2670000A-7350-4f3c-8081-5663EE0C6C49} - {48E73304-E1D6-4330-914C-F5F514E3486C} - c:\program files\microsoft office\office12\ONBttnIE.dll
    IE: {92780B25-18CC-41C8-B9BE-3C9C571A8263} - {FF059E31-CC5A-4E2E-BF3B-96E929D65503}
    IE: {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe
    IE: {FB5F1910-F110-11d2-BB9E-00C04F795683} - c:\program files\messenger\msmsgs.exe
    DPF: Garmin Communicator Plug-In - hxxps://static.garmincdn.com/gcp/ie/2.9.3.0/GarminAxControl.CAB
    DPF: {01113300-3E00-11D2-8470-0060089874ED} - hxxp://supportcenter.rr.com/sdccommon/download/tgctlcm.cab
    DPF: {0CCA191D-13A6-4E29-B746-314DEE697D83} - hxxp://upload.facebook.com/controls/2008.10.10_v5.5.8/FacebookPhotoUploader5.cab
    DPF: {17492023-C23A-453E-A040-C7C580BBF700} - hxxp://download.microsoft.com/download/5/b/0/5b0d4654-aa20-495c-b89f-c1c34c691085/LegitCheckControl.cab
    DPF: {33564D57-0000-0010-8000-00AA00389B71} - hxxp://download.microsoft.com/download/F/6/E/F6E491A6-77E1-4E20-9F5F-94901338C922/wmv9VCM.CAB
    DPF: {3BB1D69B-A780-4BE1-876E-F3D488877135} - hxxp://download.microsoft.com/download/3/B/E/3BE57995-8452-41F1-8297-DD75EF049853/VirtualEarth3D.cab
    DPF: {48DD0448-9209-4F81-9F6D-D83562940134} - hxxp://lads.myspace.com/upload/MySpaceUploader1006.cab
    DPF: {4F1E5B1A-2A80-42CA-8532-2D05CB959537} - hxxp://gfx1.hotmail.com/mail/w2/pr02/resources/MSNPUpld.cab
    DPF: {73ECB3AA-4717-450C-A2AB-D00DAD9EE203} - hxxp://h20270.www2.hp.com/ediags/gmn2/install/HPProductDetection2.cab
    DPF: {8100D56A-5661-482C-BEE8-AFECE305D968} - hxxp://upload.facebook.com/controls/2009.07.28_v5.5.8.1/FacebookPhotoUploader55.cab
    DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} - hxxp://java.sun.com/update/1.7.0/jinstall-1_7_0_11-windows-i586.cab
    DPF: {8FFBE65D-2C9C-4669-84BD-5829DC0B603C} - hxxp://fpdownload.macromedia.com/get/flashplayer/current/polarbear/ultrashim.cab
    DPF: {BCBC9371-595D-11D4-A96D-00105A1CEF6C} - hxxp://onlinedesigner.hgtv.com/images/app/view22rte.cab
    DPF: {CAFEEFAC-0017-0000-0011-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.7.0/jinstall-1_7_0_11-windows-i586.cab
    DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.7.0/jinstall-1_7_0_11-windows-i586.cab
    DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} - hxxp://fpdownload.macromedia.com/pub/shockwave/cabs/flash/swflash.cab
    DPF: {E2883E8F-472F-4FB0-9522-AC9BF37916A7} - hxxp://platformdl.adobe.com/NOS/getPlusPlus/1.6/gp.cab
    TCP: NameServer = 209.18.47.61 209.18.47.62
    TCP: Interfaces\{147B5A83-7A5F-47D3-9260-9F776C8C26B2} : DHCPNameServer = 209.18.47.61 209.18.47.62
    TCP: Interfaces\{3F7F1342-C3A6-497F-B824-9E5CF7AF0B1A} : DHCPNameServer = 24.94.163.100 24.94.163.101
    Handler: belarc - {6318E0AB-2E93-11D1-B8ED-00608CC9A71F} - c:\program files\belarc\advisor\system\BAVoilaX.dll
    Handler: grooveLocalGWS - {88FED34C-F0CA-4636-A375-3CB6248B04CD} - c:\program files\microsoft office\office12\GrooveSystemServices.dll
    Handler: linkscanner - {F274614C-63F8-47D5-A4D1-FBDDE494F8D1} - <orphaned>
    Notify: igfxcui - igfxdev.dll
    Notify: LBTWlgn - c:\program files\common files\logitech\bluetooth\LBTWlgn.dll
    SSODL: WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - c:\windows\system32\WPDShServiceObj.dll
    SEH: Groove GFS Stub Execution Hook - {B5A7F190-DDA6-4420-B3BA-52453494E6CD} - c:\program files\microsoft office\office12\GrooveShellExtensions.dll
    SEH: SABShellExecuteHook Class - {5AE067D3-9AFB-48E0-853A-EBB7F4A000DA} - c:\program files\superantispyware\SASSEH.DLL
    mASetup: {10880D85-AAD9-4558-ABDC-2AB1552D831F} - "c:\program files\common files\lightscribe\LSRunOnce.exe "
    .
    ================= FIREFOX ===================
    .
    FF - ProfilePath - c:\documents and settings\administrator\application data\mozilla\firefox\profiles\vbivqras.default\
    FF - plugin: c:\program files\adobe\reader 10.0\reader\air\nppdf32.dll
    FF - plugin: c:\program files\google\google earth\plugin\npgeplugin.dll
    FF - plugin: c:\program files\google\picasa3\npPicasa2.dll
    FF - plugin: c:\program files\google\picasa3\npPicasa3.dll
    FF - plugin: c:\program files\google\update\1.3.21.145\npGoogleUpdate3.dll
    FF - plugin: c:\program files\java\jre7\bin\plugin2\npjp2.dll
    FF - plugin: c:\program files\microsoft silverlight\5.1.20125.0\npctrlui.dll
    FF - plugin: c:\program files\mozilla firefox\plugins\NPcol400.dll
    FF - plugin: c:\program files\mozilla firefox\plugins\NPcol500.dll
    FF - plugin: c:\program files\mozilla firefox\plugins\npMozCouponPrinter.dll
    FF - plugin: c:\program files\mozilla firefox\plugins\npstrlnk.dll
    FF - plugin: c:\program files\tracker software\pdf viewer\npPDFXCviewNPPlugin.dll
    FF - plugin: c:\windows\system32\macromed\flash\NPSWF32_11_6_602_180.dll
    FF - plugin: c:\windows\system32\npdeployJava1.dll
    FF - plugin: c:\windows\system32\npptools.dll
    .
    ============= SERVICES / DRIVERS ===============
    .
    R0 AVGIDSHX;AVGIDSHX;c:\windows\system32\drivers\avgidshx.sys [2012-4-19 55776]
    R0 Avglogx;AVG Logging Driver;c:\windows\system32\drivers\avglogx.sys [2012-8-9 177376]
    R0 Avgmfx86;AVG Mini-Filter Resident Anti-Virus Shield;c:\windows\system32\drivers\avgmfx86.sys [2010-9-7 94048]
    R0 Avgrkx86;AVG Anti-Rootkit Driver;c:\windows\system32\drivers\avgrkx86.sys [2010-9-7 35552]
    R0 gfibto;gfibto;c:\windows\system32\drivers\gfibto.sys [2013-2-10 13560]
    R1 Avgtdix;AVG TDI Driver;c:\windows\system32\drivers\avgtdix.sys [2010-9-7 164832]
    R2 !SASCORE;SAS Core Service;c:\program files\superantispyware\SASCORE.EXE [2010-7-14 116608]
    R2 Ad-Aware Service;Ad-Aware Service;c:\program files\ad-aware antivirus\AdAwareService.exe [2012-12-14 1236968]
    R2 SBAMSvc;Ad-Aware;c:\program files\ad-aware antivirus\SBAMSvc.exe [2012-9-20 3677000]
    R3 AtcL001;NDIS Miniport Driver for Atheros L1 Gigabit Ethernet Controller;c:\windows\system32\drivers\l151x86.sys [2007-8-29 36864]
    S0 Lbd;Lbd;c:\windows\system32\drivers\lbd.sys --> c:\windows\system32\drivers\Lbd.sys [?]
    S1 AVGIDSDriver;AVGIDSDriver;c:\windows\system32\drivers\avgidsdriverx.sys [2011-12-23 179936]
    S1 AVGIDSShim;AVGIDSShim;c:\windows\system32\drivers\avgidsshimx.sys [2011-12-23 19936]
    S1 Avgldx86;AVG AVI Loader Driver;c:\windows\system32\drivers\avgldx86.sys [2010-9-7 159712]
    S1 hwinterface;hwinterface;c:\windows\system32\drivers\hwinterface.sys [2008-5-29 3026]
    S1 SASDIFSV;SASDIFSV;c:\program files\superantispyware\SASDIFSV.SYS [2010-1-5 12880]
    S1 SASKUTIL;SASKUTIL;c:\program files\superantispyware\SASKUTIL.SYS [2010-1-5 67664]
    S2 AVGIDSAgent;AVGIDSAgent;c:\program files\avg\avg2013\avgidsagent.exe [2012-11-16 5814904]
    S2 avgwd;AVG WatchDog;c:\program files\avg\avg2013\avgwdsvc.exe [2012-10-22 196664]
    S2 clr_optimization_v4.0.30319_32;Microsoft .NET Framework NGEN v4.0.30319_X86;c:\windows\microsoft.net\framework\v4.0.30319\mscorsvw.exe [2010-3-18 130384]
    S2 MBAMScheduler;MBAMScheduler;c:\program files\malwarebytes' anti-malware\mbamscheduler.exe [2013-5-10 418376]
    S2 MBAMService;MBAMService;c:\program files\malwarebytes' anti-malware\mbamservice.exe [2010-1-19 701512]
    S2 WUSB54GPv4SVC;WUSB54GPv4SVC;c:\program files\wireless-g portable usb adapter wireless network monitor\WLService.exe [2007-12-1 41025]
    S3 DCamUSBLTN;Kodak DVC325 Digital Video Camera;c:\windows\system32\drivers\dvc325.sys [1999-11-9 112836]
    S3 MBAMProtector;MBAMProtector;c:\windows\system32\drivers\mbam.sys [2010-1-19 22856]
    S3 motccgp;Motorola USB Composite Device Driver;c:\windows\system32\drivers\motccgp.sys --> c:\windows\system32\drivers\motccgp.sys [?]
    S3 motccgpfl;MotCcgpFlService;c:\windows\system32\drivers\motccgpfl.sys --> c:\windows\system32\drivers\motccgpfl.sys [?]
    S3 SASENUM;SASENUM;c:\program files\superantispyware\SASENUM.SYS [2010-1-5 12872]
    S3 WPFFontCache_v0400;Windows Presentation Foundation Font Cache 4.0.0.0;c:\windows\microsoft.net\framework\v4.0.30319\wpf\WPFFontCache_v0400.exe [2010-3-18 753504]
    S4 Garmin Core Update Service;Garmin Core Update Service;c:\program files\garmin\core update service\Garmin.Cartography.MapUpdate.CoreService.exe [2013-3-12 185688]
    S4 gupdate1c9961f125551c6;Google Update Service (gupdate1c9961f125551c6);c:\program files\google\update\GoogleUpdate.exe [2009-2-23 133104]
    S4 TivoBeacon2;TiVo Beacon Service;c:\program files\tivo\desktop\TiVoBeacon.exe [2010-8-24 1104656]
    .
    =============== Created Last 30 ================
    .
    2013-05-15 03:00:32 -------- d-----w- c:\program files\Speccy
    2013-05-10 01:53:12 -------- d-----w- c:\documents and settings\administrator\application data\Malwarebytes
    2013-05-10 01:53:12 -------- d-----w- c:\documents and settings\administrator\application data\AVG2013
    2013-05-10 00:11:29 -------- d-----w- c:\documents and settings\administrator\local settings\application data\Mozilla
    2013-05-09 22:32:27 -------- d-----w- c:\documents and settings\administrator\local settings\application data\Avg2013
    .
    ==================== Find3M ====================
    .
    2013-04-16 22:17:15 920064 ----a-w- c:\windows\system32\wininet.dll
    2013-04-16 22:17:14 43520 ----a-w- c:\windows\system32\licmgr10.dll
    2013-04-16 22:17:14 1469440 ------w- c:\windows\system32\inetcpl.cpl
    2013-04-12 23:28:55 385024 ----a-w- c:\windows\system32\html.iec
    2013-04-12 16:10:06 94112 ----a-w- c:\windows\system32\WindowsAccessBridge.dll
    2013-04-12 16:09:54 143872 ----a-w- c:\windows\system32\javacpl.cpl
    2013-04-12 16:09:51 861088 ----a-w- c:\windows\system32\npdeployJava1.dll
    2013-04-12 16:09:51 782240 ----a-w- c:\windows\system32\deployJava1.dll
    2013-04-10 01:31:19 1876352 ----a-w- c:\windows\system32\win32k.sys
    2013-04-04 19:50:32 22856 ----a-w- c:\windows\system32\drivers\mbam.sys
    2013-04-02 14:09:52 4550656 ----a-w- c:\windows\system32\GPhotos.scr
    2013-03-13 06:12:45 693976 ----a-w- c:\windows\system32\FlashPlayerApp.exe
    2013-03-13 06:12:44 73432 ----a-w- c:\windows\system32\FlashPlayerCPLApp.cpl
    2013-03-13 06:12:33 16486616 ----a-w- c:\windows\system32\FlashPlayerInstaller.exe
    2013-03-08 08:36:22 293376 ----a-w- c:\windows\system32\winsrv.dll
    2013-03-07 01:32:25 2149888 ------w- c:\windows\system32\ntoskrnl.exe
    2013-03-07 00:50:30 2028544 ------w- c:\windows\system32\ntkrnlpa.exe
    2013-02-27 07:56:51 2067456 ----a-w- c:\windows\system32\mstscax.dll
    2009-12-19 21:23:06 302 ----a-w- c:\program files\temp995.bat
    .
    =================== ROOTKIT ====================
    .
    Stealth MBR rootkit/Mebroot/Sinowal/TDL4 detector 0.4.2 by Gmer, http://www.gmer.net
    Windows 5.1.2600 Disk: ST3500630AS rev.3.AAK -> Harddisk0\DR0 -> \Device\Ide\IdeDeviceP2T0L0-17
    .
    device: opened successfully
    user: MBR read successfully
    .
    Disk trace:
    called modules: ntoskrnl.exe CLASSPNP.SYS disk.sys >>UNKNOWN [0x8A24C4B1]<<
    _asm { PUSH EBP; MOV EBP, ESP; PUSH ECX; MOV EAX, [EBP+0x8]; CMP EAX, [0x8a25393c]; MOV EAX, [0x8a253ab0]; PUSH EBX; PUSH ESI; MOV ESI, [EBP+0xc]; MOV EBX, [ESI+0x60]; PUSH EDI; JNZ 0x20; MOV [EBP+0x8], EAX; }
    1 nt!IofCallDriver[0x804E13B9] -> \Device\Harddisk0\DR0[0x8A30EAB8]
    3 CLASSPNP[0xF7637FD7] -> nt!IofCallDriver[0x804E13B9] -> [0x8A244CD0]
    \Driver\atapi[0x8A370398] -> IRP_MJ_CREATE -> 0x8A24C4B1
    error: Read A device attached to the system is not functioning.
    kernel: MBR read successfully
    _asm { XOR AX, AX; MOV SS, AX; MOV SP, 0x7c00; STI ; PUSH AX; POP ES; PUSH AX; POP DS; CLD ; MOV SI, 0x7c1b; MOV DI, 0x61b; PUSH AX; PUSH DI; MOV CX, 0x1e5; REP MOVSB ; RETF ; MOV BP, 0x7be; MOV CL, 0x4; CMP [BP+0x0], CH; JL 0x2e; JNZ 0x3a; }
    detected disk devices:
    detected hooks:
    \Driver\atapi DriverStartIo -> 0x8A24C2E2
    user & kernel MBR OK
    Warning: possible TDL3 rootkit infection !
    .
    ============= FINISH: 8:54:10.40 ===============
    .
    UNLESS SPECIFICALLY INSTRUCTED, DO NOT POST THIS LOG.
    IF REQUESTED, ZIP IT UP & ATTACH IT
    .
    DDS (Ver_2012-11-20.01)
    .
    Microsoft Windows XP Professional
    Boot Device: \Device\HarddiskVolume1
    Install Date: 10/16/2007 4:45:27 PM
    System Uptime: 5/16/2013 8:33:21 AM (0 hours ago)
    .
    Motherboard: ASUSTeK Computer INC. | | P5L-MX
    Processor: Intel(R) Pentium(R) Dual CPU E2180 @ 2.00GHz | LGA 775 | 1999/200mhz
    .
    ==== Disk Partitions =========================
    .
    A: is Removable
    C: is FIXED (NTFS) - 466 GiB total, 174.107 GiB free.
    D: is CDROM ()
    E: is CDROM ()
    F: is Removable
    G: is Removable
    .
    ==== Disabled Device Manager Items =============
    .
    ==== System Restore Points ===================
    .
    RP1054: 2/16/2013 4:16:09 AM - System Checkpoint
    RP1055: 2/17/2013 4:18:11 AM - System Checkpoint
    RP1056: 2/18/2013 5:18:11 AM - System Checkpoint
    RP1057: 2/19/2013 6:18:11 AM - System Checkpoint
    RP1058: 2/20/2013 7:18:11 AM - System Checkpoint
    RP1059: 2/21/2013 8:18:12 AM - System Checkpoint
    RP1060: 2/22/2013 8:19:23 AM - System Checkpoint
    RP1061: 2/23/2013 9:18:09 AM - System Checkpoint
    RP1062: 2/24/2013 10:18:09 AM - System Checkpoint
    RP1063: 2/25/2013 10:19:18 AM - System Checkpoint
    RP1064: 2/26/2013 11:18:11 AM - System Checkpoint
    RP1065: 2/27/2013 11:24:07 AM - System Checkpoint
    RP1066: 2/28/2013 12:24:00 PM - System Checkpoint
    RP1067: 3/1/2013 12:25:05 PM - System Checkpoint
    RP1068: 3/2/2013 1:24:03 PM - System Checkpoint
    RP1069: 3/3/2013 2:25:08 PM - System Checkpoint
    RP1070: 3/4/2013 2:57:31 PM - System Checkpoint
    RP1071: 3/5/2013 2:57:43 PM - System Checkpoint
    RP1072: 3/6/2013 3:45:46 PM - System Checkpoint
    RP1073: 3/7/2013 4:57:48 PM - System Checkpoint
    RP1074: 3/8/2013 5:45:46 PM - System Checkpoint
    RP1075: 3/9/2013 6:58:45 PM - System Checkpoint
    RP1076: 3/10/2013 7:59:55 PM - System Checkpoint
    RP1077: 3/11/2013 8:45:50 PM - System Checkpoint
    RP1078: 3/12/2013 10:00:16 PM - System Checkpoint
    RP1079: 3/13/2013 3:00:34 AM - Software Distribution Service 3.0
    RP1080: 3/14/2013 3:40:07 AM - System Checkpoint
    RP1081: 3/17/2013 9:43:57 PM - System Checkpoint
    RP1082: 3/18/2013 10:28:29 PM - System Checkpoint
    RP1083: 3/19/2013 9:55:02 AM - Garmin Express
    RP1084: 3/20/2013 10:34:22 AM - System Checkpoint
    RP1085: 3/20/2013 5:53:35 PM - Software Distribution Service 3.0
    RP1086: 3/21/2013 6:16:45 PM - System Checkpoint
    RP1087: 3/22/2013 7:04:46 PM - System Checkpoint
    RP1088: 3/23/2013 7:11:26 PM - System Checkpoint
    RP1089: 3/24/2013 8:17:19 PM - System Checkpoint
    RP1090: 3/25/2013 9:04:46 PM - System Checkpoint
    RP1091: 3/26/2013 10:17:10 PM - System Checkpoint
    RP1092: 3/27/2013 10:18:45 PM - System Checkpoint
    RP1093: 3/28/2013 11:21:53 PM - System Checkpoint
    RP1094: 3/30/2013 12:04:41 AM - System Checkpoint
    RP1095: 3/30/2013 11:41:02 AM - Installed H&R Block Deluxe + Efile + State 2012.
    RP1096: 3/30/2013 12:50:45 PM - Installed H&R Block Nebraska 2012.
    RP1097: 3/31/2013 1:14:36 PM - System Checkpoint
    RP1098: 4/1/2013 1:19:24 PM - System Checkpoint
    RP1099: 4/2/2013 2:19:21 PM - System Checkpoint
    RP1100: 4/3/2013 3:19:21 PM - System Checkpoint
    RP1101: 4/4/2013 4:19:20 PM - System Checkpoint
    RP1102: 4/5/2013 5:19:23 PM - System Checkpoint
    RP1103: 4/6/2013 6:19:21 PM - System Checkpoint
    RP1104: 4/7/2013 6:23:52 PM - System Checkpoint
    RP1105: 4/8/2013 6:58:03 PM - System Checkpoint
    RP1106: 4/9/2013 7:37:05 PM - System Checkpoint
    RP1107: 4/10/2013 8:37:03 PM - System Checkpoint
    RP1108: 4/11/2013 3:00:42 AM - Software Distribution Service 3.0
    RP1109: 4/12/2013 3:30:06 AM - System Checkpoint
    RP1110: 4/12/2013 11:09:10 AM - Removed Java 7 Update 7
    RP1111: 4/12/2013 11:09:45 AM - Installed Java 7 Update 17
    RP1112: 4/13/2013 11:30:10 AM - System Checkpoint
    RP1113: 4/14/2013 12:30:05 PM - System Checkpoint
    RP1114: 4/15/2013 1:30:08 PM - System Checkpoint
    RP1115: 4/16/2013 2:30:07 PM - System Checkpoint
    RP1116: 4/17/2013 3:30:08 PM - System Checkpoint
    RP1117: 4/18/2013 4:30:02 PM - System Checkpoint
    RP1118: 4/19/2013 5:30:00 PM - System Checkpoint
    RP1119: 4/20/2013 6:30:00 PM - System Checkpoint
    RP1120: 4/21/2013 7:30:04 PM - System Checkpoint
    RP1121: 4/22/2013 8:29:59 PM - System Checkpoint
    RP1122: 4/23/2013 8:55:08 PM - System Checkpoint
    RP1123: 4/24/2013 11:18:38 PM - System Checkpoint
    RP1124: 4/25/2013 11:39:52 PM - System Checkpoint
    RP1125: 4/27/2013 12:29:58 AM - System Checkpoint
    RP1126: 4/28/2013 1:29:57 AM - System Checkpoint
    RP1127: 4/29/2013 2:30:00 AM - System Checkpoint
    RP1128: 4/30/2013 3:29:58 AM - System Checkpoint
    RP1129: 5/1/2013 3:44:51 AM - System Checkpoint
    RP1130: 5/2/2013 3:58:51 AM - System Checkpoint
    RP1131: 5/3/2013 4:57:18 AM - System Checkpoint
    RP1132: 5/4/2013 5:44:49 AM - System Checkpoint
    RP1133: 5/5/2013 6:44:49 AM - System Checkpoint
    RP1134: 5/6/2013 7:44:58 AM - System Checkpoint
    RP1135: 5/7/2013 8:19:31 AM - System Checkpoint
    RP1136: 5/8/2013 9:19:34 AM - System Checkpoint
    RP1137: 5/9/2013 10:18:47 AM - System Checkpoint
    RP1138: 5/9/2013 8:57:25 PM - Restore Operation
    RP1139: 5/9/2013 9:02:42 PM - Restore Operation
    RP1140: 5/9/2013 9:08:29 PM - Restore Operation
    RP1141: 5/9/2013 9:13:48 PM - Restore Operation
    RP1142: 5/10/2013 9:57:44 PM - System Checkpoint
    RP1143: 5/11/2013 10:58:00 PM - System Checkpoint
    RP1144: 5/12/2013 11:30:48 PM - System Checkpoint
    RP1145: 5/13/2013 11:36:55 PM - System Checkpoint
    RP1146: 5/14/2013 4:11:28 PM - Removed Apple Software Update
    RP1147: 5/15/2013 3:00:53 AM - Software Distribution Service 3.0
    RP1148: 5/16/2013 3:17:07 AM - System Checkpoint
    .
    ==== Installed Programs ======================
    .
    Ad-Aware Antivirus
    Ad-Aware Browsing Protection
    Adobe AIR
    Adobe Download Manager
    Adobe Flash Player 11 ActiveX
    Adobe Flash Player 11 Plugin
    Adobe Media Player
    Adobe Photoshop 7.0
    Adobe Reader X (10.1.6)
    Amazon MP3 Downloader 1.0.17
    Attansic Ethernet Utility
    Attansic L1 Gigabit Ethernet Driver
    Auto FTP Manager 5.0
    AVG 2013
    AVS Audio Converter version 6.2
    AVS DVD Copy version 4.1.1
    AVS Media Player 4.1.1.60
    AVS Screen Capture version 2.0.2
    AVS Update Manager 1.0
    AVS Video Converter 6
    AVS Video Editor 6
    AVS Video Recorder 2.5
    AVS YouTube Uploader version 2.1
    AVS4YOU Software Navigator 1.4
    Belarc Advisor 8.1
    BitZipper 2010
    Bonjour
    Bonjour Print Services
    Camera Window
    Canon Camera Window for ZoomBrowser EX
    Canon CanoScan Toolbox 4.5
    Canon IJ Network Scanner Selector EX
    Canon IJ Network Tool
    Canon MX880 series MP Drivers
    Canon MX880 series User Registration
    Canon My Printer
    Canon RemoteCapture Task for ZoomBrowser EX
    Canon Utilities Easy-PhotoPrint
    Canon Utilities Easy-PhotoPrint Plus
    Canon Utilities PhotoStitch 3.1
    Canon Utilities ZoomBrowser EX
    Carbonite
    CCleaner
    CDDRV_Installer
    eIMAGE Recovery
    eIMAGE Recovery DEMO
    Elevated Installer
    Express Burn
    FileZilla Client 3.5.0
    FMS
    Garmin Communicator Plugin
    Garmin Express
    Garmin Express Tray
    Garmin Update Service
    Garmin USB Drivers
    Garmin VoiceStudio v2.10
    Garmin WebUpdater
    Google Earth
    Google Update Helper
    H&R Block Deluxe + Efile + State 2011
    H&R Block Deluxe + Efile + State 2012
    H&R Block Nebraska 2009
    H&R Block Nebraska 2010
    H&R Block Nebraska 2011
    H&R Block Nebraska 2012
    HDView for Internet Explorer
    HijackThis 2.0.2
    Hotfix for Microsoft .NET Framework 3.0 (KB932471)
    Hotfix for Microsoft .NET Framework 3.5 SP1 (KB953595)
    Hotfix for Microsoft .NET Framework 3.5 SP1 (KB958484)
    Hotfix for Windows Internet Explorer 7 (KB947864)
    Hotfix for Windows XP (KB954550-v5)
    ID Tracker
    ImgBurn
    Intel(R) Graphics Media Accelerator Driver
    iSEEK AnswerWorks English Runtime
    ISO Recorder
    Java 7 Update 17
    Java Auto Updater
    KhalInstallWrapper
    Kodak DVC325 Digital Video Camera Software Installation
    LightScribe System Software 1.10.16.1
    Logger32 Ver 3.10
    Logitech Harmony Remote Software 7
    Logitech SetPoint
    Malwarebytes Anti-Malware version 1.75.0.1300
    Microsoft .NET Framework 1.1
    Microsoft .NET Framework 1.1 Security Update (KB2698023)
    Microsoft .NET Framework 1.1 Security Update (KB2742597)
    Microsoft .NET Framework 1.1 Security Update (KB979906)
    Microsoft .NET Framework 2.0 Service Pack 2
    Microsoft .NET Framework 3.0 Service Pack 2
    Microsoft .NET Framework 3.5 SP1
    Microsoft .NET Framework 4 Client Profile
    Microsoft Application Error Reporting
    Microsoft Base Smart Card Cryptographic Service Provider Package
    Microsoft Choice Guard
    Microsoft Compression Client Pack 1.0 for Windows XP
    Microsoft IntelliPoint 5.2
    Microsoft IntelliType Pro 5.2
    Microsoft Internationalized Domain Names Mitigation APIs
    Microsoft Kernel-Mode Driver Framework Feature Pack 1.5
    Microsoft Kernel-Mode Driver Framework Feature Pack 1.7
    Microsoft National Language Support Downlevel APIs
    Microsoft Office 2007 Service Pack 3 (SP3)
    Microsoft Office Access MUI (English) 2007
    Microsoft Office Access Setup Metadata MUI (English) 2007
    Microsoft Office Converter Pack
    Microsoft Office Enterprise 2007
    Microsoft Office Excel MUI (English) 2007
    Microsoft Office Excel Viewer 2003
    Microsoft Office File Validation Add-In
    Microsoft Office Groove MUI (English) 2007
    Microsoft Office Groove Setup Metadata MUI (English) 2007
    Microsoft Office InfoPath MUI (English) 2007
    Microsoft Office OneNote MUI (English) 2007
    Microsoft Office Outlook MUI (English) 2007
    Microsoft Office PowerPoint MUI (English) 2007
    Microsoft Office PowerPoint Viewer 2003
    Microsoft Office Proof (English) 2007
    Microsoft Office Proof (French) 2007
    Microsoft Office Proof (Spanish) 2007
    Microsoft Office Proofing (English) 2007
    Microsoft Office Proofing Tools 2007 Service Pack 3 (SP3)
    Microsoft Office Publisher MUI (English) 2007
    Microsoft Office Shared MUI (English) 2007
    Microsoft Office Shared Setup Metadata MUI (English) 2007
    Microsoft Office Word MUI (English) 2007
    Microsoft Office Word Viewer 2003
    Microsoft Silverlight
    Microsoft Software Update for Web Folders (English) 12
    Microsoft User-Mode Driver Framework Feature Pack 1.0
    Microsoft Visual C++ 2005 ATL Update kb973923 - x86 8.0.50727.4053
    Microsoft Visual C++ 2005 Redistributable
    Microsoft Visual C++ 2008 Redistributable - KB2467174 - x86 9.0.30729.5570
    Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.4148
    Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.6161
    Microsoft Visual C++ 2010 x86 Redistributable - 10.0.40219
    Microsoft Windows Journal Viewer
    MotoHelper MergeModules
    Mozilla Firefox 20.0.1 (x86 en-US)
    Mozilla Maintenance Service
    MSVCRT
    MSXML 4.0 SP2 (KB954430)
    MSXML 4.0 SP2 (KB973688)
    MSXML 6.0 Parser (KB933579)
    Napster
    Napster Burn Engine
    NCH Toolbox
    Nero 7 Essentials
    NVIDIA Drivers
    OGA Notifier 2.0.0048.0
    OpenMG Limited Patch 4.7-07-14-05-01
    OpenMG Secure Module 4.7.00
    PDF-Viewer
    Pdf995 (installed by TaxCut)
    PhotoStitch
    Picasa 3
    Pixillion Image Converter
    Power Sound Editor Free
    PowerArchiver 2009
    Prism Video Converter
    Quicken 2013
    QuickTime
    RealUpgrade 1.0
    Remote Control USB Driver
    RemoteCapture Task
    Security Update for Microsoft .NET Framework 3.5 SP1 (KB2604111)
    Security Update for Microsoft .NET Framework 3.5 SP1 (KB2657424)
    Security Update for Microsoft .NET Framework 3.5 SP1 (KB2736416)
    Security Update for Microsoft .NET Framework 4 Client Profile (KB2604121)
    Security Update for Microsoft .NET Framework 4 Client Profile (KB2656351)
    Security Update for Microsoft .NET Framework 4 Client Profile (KB2656368v2)
    Security Update for Microsoft .NET Framework 4 Client Profile (KB2656405)
    Security Update for Microsoft .NET Framework 4 Client Profile (KB2686827)
    Security Update for Microsoft .NET Framework 4 Client Profile (KB2729449)
    Security Update for Microsoft .NET Framework 4 Client Profile (KB2737019)
    Security Update for Microsoft .NET Framework 4 Client Profile (KB2742595)
    Security Update for Microsoft .NET Framework 4 Client Profile (KB2789642)
    Security Update for Microsoft .NET Framework 4 Client Profile (KB2804576)
    Security Update for Microsoft Office 2007 suites (KB2596615) 32-Bit Edition
    Security Update for Microsoft Office 2007 suites (KB2596672) 32-Bit Edition
    Security Update for Microsoft Office 2007 suites (KB2596744) 32-Bit Edition
    Security Update for Microsoft Office 2007 suites (KB2596754) 32-Bit Edition
    Security Update for Microsoft Office 2007 suites (KB2596785) 32-Bit Edition
    Security Update for Microsoft Office 2007 suites (KB2596792) 32-Bit Edition
    Security Update for Microsoft Office 2007 suites (KB2596871) 32-Bit Edition
    Security Update for Microsoft Office 2007 suites (KB2597969) 32-Bit Edition
    Security Update for Microsoft Office 2007 suites (KB2687311) 32-Bit Edition
    Security Update for Microsoft Office 2007 suites (KB2687439) 32-Bit Edition
    Security Update for Microsoft Office 2007 suites (KB2687441) 32-Bit Edition
    Security Update for Microsoft Office 2007 suites (KB2687499) 32-Bit Edition
    Security Update for Microsoft Office 2007 suites (KB2760416) 32-Bit Edition
    Security Update for Microsoft Office Excel 2007 (KB2687307) 32-Bit Edition
    Security Update for Microsoft Office InfoPath 2007 (KB2687440) 32-Bit Edition
    Security Update for Microsoft Office PowerPoint 2007 (KB2596764) 32-Bit Edition
    Security Update for Microsoft Office PowerPoint 2007 (KB2596912) 32-Bit Edition
    Security Update for Microsoft Office Publisher 2007 (KB2597971) 32-Bit Edition
    Security Update for Microsoft Office Word 2007 (KB2760421) 32-Bit Edition
    Security Update for Windows Internet Explorer 7 (KB2183461)
    Security Update for Windows Internet Explorer 7 (KB938127)
    Security Update for Windows Internet Explorer 7 (KB939653)
    Security Update for Windows Internet Explorer 7 (KB942615)
    Security Update for Windows Internet Explorer 7 (KB944533)
    Security Update for Windows Internet Explorer 7 (KB950759)
    Security Update for Windows Internet Explorer 7 (KB953838)
    Security Update for Windows Internet Explorer 7 (KB956390)
    Security Update for Windows Internet Explorer 7 (KB958215)
    Security Update for Windows Internet Explorer 7 (KB960714)
    Security Update for Windows Internet Explorer 7 (KB961260)
    Security Update for Windows Internet Explorer 7 (KB963027)
    Security Update for Windows Internet Explorer 7 (KB969897)
    Security Update for Windows Internet Explorer 7 (KB972260)
    Security Update for Windows Internet Explorer 7 (KB974455)
    Security Update for Windows Internet Explorer 7 (KB976325)
    Security Update for Windows Internet Explorer 7 (KB978207)
    Security Update for Windows Internet Explorer 7 (KB982381)
    Security Update for Windows Internet Explorer 8 (KB2183461)
    Security Update for Windows Internet Explorer 8 (KB2360131)
    Security Update for Windows Internet Explorer 8 (KB2416400)
    Security Update for Windows Internet Explorer 8 (KB2482017)
    Security Update for Windows Internet Explorer 8 (KB2497640)
    Security Update for Windows Internet Explorer 8 (KB2510531)
    Security Update for Windows Internet Explorer 8 (KB2530548)
    Security Update for Windows Internet Explorer 8 (KB2544521)
    Security Update for Windows Internet Explorer 8 (KB2559049)
    Security Update for Windows Internet Explorer 8 (KB2586448)
    Security Update for Windows Internet Explorer 8 (KB2618444)
    Security Update for Windows Internet Explorer 8 (KB2647516)
    Security Update for Windows Internet Explorer 8 (KB2675157)
    Security Update for Windows Internet Explorer 8 (KB2699988)
    Security Update for Windows Internet Explorer 8 (KB2722913)
    Security Update for Windows Internet Explorer 8 (KB2744842)
    Security Update for Windows Internet Explorer 8 (KB2761465)
    Security Update for Windows Internet Explorer 8 (KB2792100)
    Security Update for Windows Internet Explorer 8 (KB2797052)
    Security Update for Windows Internet Explorer 8 (KB2799329)
    Security Update for Windows Internet Explorer 8 (KB2809289)
    Security Update for Windows Internet Explorer 8 (KB2817183)
    Security Update for Windows Internet Explorer 8 (KB2829530)
    Security Update for Windows Internet Explorer 8 (KB2847204)
    Security Update for Windows Internet Explorer 8 (KB971961)
    Security Update for Windows Internet Explorer 8 (KB981332)
    Security Update for Windows Internet Explorer 8 (KB982381)
    Security Update for Windows Media Player (KB911564)
    Security Update for Windows Media Player 6.4 (KB925398)
    Security Update for Windows Media Player 9 (KB936782)
    Security Update for Windows XP (KB2820197)
    Security Update for Windows XP (KB2829361)
    Security Update for Windows XP (KB923689)
    Segoe UI
    SIW 2011 Home Edition
    Speccy
    SUPERAntiSpyware Free Edition
    Switch Sound File Converter
    TiVo Desktop 2.8.2
    Update for 2007 Microsoft Office System (KB967642)
    Update for Microsoft .NET Framework 3.5 SP1 (KB963707)
    Update for Microsoft Office 2007 suites (KB2596620) 32-Bit Edition
    Update for Microsoft Office 2007 suites (KB2596660) 32-Bit Edition
    Update for Microsoft Office 2007 suites (KB2596802) 32-Bit Edition
    Update for Microsoft Office 2007 suites (KB2596848) 32-Bit Edition
    Update for Microsoft Office 2007 suites (KB2767916) 32-Bit Edition
    Update for Microsoft Office Outlook 2007 (KB2687404) 32-Bit Edition
    Update for Microsoft Office Outlook 2007 Junk Email Filter (KB2817359) 32-Bit Edition
    Update for Windows Internet Explorer 7 (KB976749)
    Update for Windows Internet Explorer 7 (KB980182)
    Update for Windows Internet Explorer 8 (KB976662)
    Update for Windows Internet Explorer 8 (KB982664)
    Visual C++ 2008 x86 Runtime - (v9.0.30729)
    Visual C++ 2008 x86 Runtime - v9.0.30729.01
    VLC media player 1.1.2
    WebFldrs XP
    Windows Driver Package - Garmin (grmnusb) GARMIN Devices (06/03/2009 2.3.0.0)
    Windows Genuine Advantage Notifications (KB905474)
    Windows Genuine Advantage Validation Tool (KB892130)
    Windows Imaging Component
    Windows Internet Explorer 7
    Windows Internet Explorer 8
    Windows Live Call
    Windows Live Communications Platform
    Windows Live Essentials
    Windows Live Messenger
    Windows Live Sign-in Assistant
    Windows Live Upload Tool
    Windows Media Format 11 runtime
    Windows Media Player 11
    Windows Presentation Foundation
    Windows XP Service Pack 3
    WinZip 12.0
    Wireless-G Portable USB Adapter
    XML Paper Specification Shared Components Pack 1.0
    XMLog
    YouTube Downloader 3.3
    ZoneAlarm Free Firewall
    ZoneAlarm Security Toolbar
    .
    ==== Event Viewer Messages From Past Week ========
    .
    5/9/2013 9:13:35 PM, error: DCOM [10005] - DCOM got error "%1055" attempting to start the service winmgmt with arguments " " in order to run the server: {8BC3F05E-D86B-11D0-A075-00C04FB68820}
    5/9/2013 8:26:05 PM, error: DCOM [10005] - DCOM got error "%1084" attempting to start the service EventSystem with arguments " " in order to run the server: {1BE1F766-5536-11D1-B726-00C04FB926AF}
    5/9/2013 8:24:10 PM, error: Service Control Manager [7026] - The following boot-start or system-start driver(s) failed to load: AFD AVGIDSDriver AVGIDSShim Avgldx86 Avgtdix BANTExt Fips hwinterface intelppm IPSec Lbd MRxSmb NetBIOS NetBT RasAcd Rdbss SASDIFSV SASKUTIL Tcpip
    5/9/2013 8:24:10 PM, error: Service Control Manager [7001] - The IPSEC Services service depends on the IPSEC driver service which failed to start because of the following error: A device attached to the system is not functioning.
    5/9/2013 8:24:10 PM, error: Service Control Manager [7001] - The DNS Client service depends on the TCP/IP Protocol Driver service which failed to start because of the following error: A device attached to the system is not functioning.
    5/9/2013 8:24:10 PM, error: Service Control Manager [7001] - The DHCP Client service depends on the NetBios over Tcpip service which failed to start because of the following error: A device attached to the system is not functioning.
    5/9/2013 8:24:10 PM, error: Service Control Manager [7001] - The Bonjour Service service depends on the TCP/IP Protocol Driver service which failed to start because of the following error: A device attached to the system is not functioning.
    5/9/2013 8:24:10 PM, error: Service Control Manager [7001] - The AVGIDSAgent service depends on the AVGIDSDriver service which failed to start because of the following error: A device attached to the system is not functioning.
    5/9/2013 8:24:04 PM, error: DCOM [10005] - DCOM got error "%1084" attempting to start the service netman with arguments " " in order to run the server: {BA126AE5-2166-11D1-B1D0-00805FC1270E}
    5/9/2013 8:23:58 PM, error: DCOM [10005] - DCOM got error "%1084" attempting to start the service CarboniteService with arguments " " in order to run the server: {36471C67-6A93-4434-92CC-4C614CD06666}
    5/9/2013 7:17:40 PM, error: Service Control Manager [7009] - Timeout (30000 milliseconds) waiting for the SSDP Discovery Service service to connect.
    5/9/2013 7:17:40 PM, error: Service Control Manager [7000] - The SSDP Discovery Service service failed to start due to the following error: The service did not respond to the start or control request in a timely fashion.
    5/15/2013 11:37:52 PM, error: Service Control Manager [7011] - Timeout (30000 milliseconds) waiting for a transaction response from the WUSB54GPv4SVC service.
    5/14/2013 4:15:58 PM, error: Service Control Manager [7011] - Timeout (30000 milliseconds) waiting for a transaction response from the avgwd service.
    5/13/2013 7:31:06 PM, error: Removable Storage Service [111] - RSM could not load media in drive Drive 0 of library TOSHIBA TransMemory USB Device.
    5/13/2013 6:18:00 PM, error: DCOM [10005] - DCOM got error "%1058" attempting to start the service gupdate1c9961f125551c6 with arguments "/comsvc" in order to run the server: {4EB61BAC-A3B6-4760-9581-655041EF4D69}
    5/13/2013 5:33:58 PM, error: Service Control Manager [7009] - Timeout (30000 milliseconds) waiting for the WUSB54GPv4SVC service to connect.
    5/13/2013 5:33:58 PM, error: Service Control Manager [7000] - The WUSB54GPv4SVC service failed to start due to the following error: The service did not respond to the start or control request in a timely fashion.
    5/13/2013 2:27:17 AM, error: VolSnap [14] - The shadow copy of volume C: was aborted because of an IO failure.
    5/13/2013 12:31:16 PM, error: DCOM [10005] - DCOM got error "%1084" attempting to start the service StiSvc with arguments " " in order to run the server: {A1F4E726-8CF1-11D1-BF92-0060081ED811}
    5/13/2013 12:15:38 PM, error: Service Control Manager [7009] - Timeout (30000 milliseconds) waiting for the IMAPI CD-Burning COM Service service to connect.
    5/13/2013 12:15:38 PM, error: Service Control Manager [7000] - The IMAPI CD-Burning COM Service service failed to start due to the following error: The service did not respond to the start or control request in a timely fashion.
    5/13/2013 12:15:06 PM, error: Service Control Manager [7011] - Timeout (30000 milliseconds) waiting for a transaction response from the NVSvc service.
    5/13/2013 12:14:02 PM, error: Service Control Manager [7026] - The following boot-start or system-start driver(s) failed to load: Lbd
    5/13/2013 12:13:29 PM, error: Service Control Manager [7006] - The ScRegSetValueExW call failed for FailureActions with the following error: Access is denied.
    5/12/2013 7:37:58 PM, error: VolSnap [12] - The shadow copy of volume C: became low on diff area space before it was properly installed.
    5/12/2013 12:14:06 PM, error: VolSnap [25] - The shadow copy of volume C: was aborted because the diff area file could not grow in time. Consider reducing the IO load on this system to avoid this problem in the future.
    5/10/2013 8:34:17 AM, error: Service Control Manager [7031] - The Garmin Core Update Service service terminated unexpectedly. It has done this 1 time(s). The following corrective action will be taken in 60000 milliseconds: Restart the service.
    .
    ==== End Of File ===========================
     
  2. 2013/05/16
    broni

    broni Moderator Malware Analyst

    Joined:
    2002/08/01
    Messages:
    21,701
    Likes Received:
    116
    Please, observe following rules:
    • Read all of my instructions very carefully. Your mistakes during cleaning process may have very serious consequences, like unbootable computer.
    • If you're stuck, or you're not sure about certain step, always ask before doing anything else.
    • Please refrain from running any tools, fixes or applying any changes to your computer other than those I suggest.
    • Never run more than one scan at a time.
    • Keep updating me regarding your computer behavior, good, or bad.
    • The cleaning process, once started, has to be completed. Even if your computer appears to act better, it may still be infected. Once the computer is totally clean, I'll certainly let you know.
    • If you leave the topic without explanation in the middle of a cleaning process, you may not be eligible to receive any more help in malware removal forum.
    • I close my topics if you have not replied in 5 days. If you need more time, simply let me know. If I closed your topic and you need it to be reopened, simply PM me.

    ======================================

    [​IMG] You're running two AV programs, AVG and Lavasoft Ad-Aware.
    You must uninstall one of them.
    I suggest Lavasoft goes.

    [​IMG] Download RogueKiller for 32bit or Roguekiller for 64bit to your Desktop.
    • Close all the running programs
    • Windows Vista/7 users: right click on RogueKiller.exe, click Run as Administrator
    • Otherwise just double-click on RogueKiller.exe
    • Pre-scan will start. Let it finish.
    • Click on SCAN button.
    • Wait until the Status box shows Scan Finished
    • Click on Delete.
    • Wait until the Status box shows Deleting Finished.
    • Click on Report and copy/paste the content of the Notepad into your next reply.
    • RKreport.txt could also be found on your desktop.
    • If more than one log is produced post all logs.
    • If RogueKiller has been blocked, do not hesitate to try a few times more. If really won't run, rename it to winlogon.exe (or winlogon.com) and try again

    [​IMG] Download Malwarebytes Anti-Rootkit (MBAR) from HERE
    • Unzip downloaded file.
    • Open the folder where the contents were unzipped and run mbar.exe
    • Follow the instructions in the wizard to update and allow the program to scan your computer for threats.
    • Click on the Cleanup button to remove any threats and reboot if prompted to do so.
    • Wait while the system shuts down and the cleanup process is performed.
    • Perform another scan with Malwarebytes Anti-Rootkit to verify that no threats remain. If they do, then click Cleanup once more and repeat the process.
    • When done, please post the two logs produced they will be in the MBAR folder..... mbar-log-xxxxx.txt and system-log.txt
     

  3. to hide this advert.

  4. 2013/05/16
    chinaclipper

    chinaclipper Well-Known Member Thread Starter

    Joined:
    2010/01/20
    Messages:
    96
    Likes Received:
    0
    Thanks! I will try you suggestions when I get home.
    Much appreciated....
    CC
     
  5. 2013/05/16
    chinaclipper

    chinaclipper Well-Known Member Thread Starter

    Joined:
    2010/01/20
    Messages:
    96
    Likes Received:
    0
    OK Here are the logs!!

    I deleted/uninstalled ADAWARE:

    RogueKiller V8.5.4 [Mar 18 2013] by Tigzy
    mail : tigzyRK<at>gmail<dot>com
    Feedback : http://www.geekstogo.com/forum/files/file/413-roguekiller/
    Website : http://tigzy.geekstogo.com/roguekiller.php
    Blog : http://tigzyrk.blogspot.com/

    Operating System : Windows XP (5.1.2600 Service Pack 3) 32 bits version
    Started in : Safe mode with network support
    User : Administrator [Admin rights]
    Mode : Scan -- Date : 05/16/2013 15:59:31
    | ARK || FAK || MBR |

    ¤¤¤ Bad processes : 1 ¤¤¤
    [SVCHOST] svchost.exe -- C:\WINDOWS\system32\svchost.exe [x] -> KILLED [TermProc]

    ¤¤¤ Registry Entries : 12 ¤¤¤
    [RUN][SUSP PATH] HKUS\S-1-5-21-299502267-1123561945-839522115-1003[...]\Run : TivoServer (C:\Program Files\TiVo\Desktop\TiVoServer.exe /service /registry /auto:TivoServer) [7] -> FOUND
    [RUN][SUSP PATH] HKUS\S-1-5-21-299502267-1123561945-839522115-1003[...]\Run : TivoTransfer (C:\Program Files\TiVo\Desktop\TiVoTransfer.exe) [7] -> FOUND
    [RUN][SUSP PATH] HKUS\S-1-5-21-299502267-1123561945-839522115-1003[...]\Run : TivoNotify (C:\Program Files\TiVo\Desktop\TiVoNotify.exe /service /registry /auto:TivoNotify) [7] -> FOUND
    [RUN][SUSP PATH] HKUS\S-1-5-21-299502267-1123561945-839522115-1003[...]\Run : TranscodingService (C:\Program Files\TiVo\Desktop\Plus\\TranscodingService.exe) [7] -> FOUND
    [RUN][SUSP PATH] HKCU\[...]\RunOnce : adawarebp_DATA_FOLDER (cmd.exe /c rmdir "C:\Documents and Settings\All Users\Application Data\Ad-Aware Browsing Protection" /s /q) [x] -> FOUND
    [RUN][SUSP PATH] HKCU\[...]\RunOnce : adawarebp_INSTALL_FOLDER (cmd.exe /c rmdir "C:\Documents and Settings\Administrator\Local Settings\Application Data\adawarebp" /s /q) [x] -> FOUND
    [RUN][SUSP PATH] HKUS\S-1-5-21-299502267-1123561945-839522115-500[...]\RunOnce : adawarebp_DATA_FOLDER (cmd.exe /c rmdir "C:\Documents and Settings\All Users\Application Data\Ad-Aware Browsing Protection" /s /q) [x] -> FOUND
    [RUN][SUSP PATH] HKUS\S-1-5-21-299502267-1123561945-839522115-500[...]\RunOnce : adawarebp_INSTALL_FOLDER (cmd.exe /c rmdir "C:\Documents and Settings\Administrator\Local Settings\Application Data\adawarebp" /s /q) [x] -> FOUND
    [HJPOL] HKLM\[...]\System : DisableRegistryTools (0) -> FOUND
    [HJ DESK] HKLM\[...]\NewStartPanel : {20D04FE0-3AEA-1069-A2D8-08002B30309D} (1) -> FOUND
    [SERVICES][HIDDEN KEY] HKLM\[...]\ControlSet001\Services\X () -> FOUND
    [SERVICES][HIDDEN KEY] HKLM\[...]\ControlSet003\Services\X () -> FOUND

    ¤¤¤ Particular Files / Folders: ¤¤¤

    ¤¤¤ Driver : [NOT LOADED] ¤¤¤

    ¤¤¤ HOSTS File: ¤¤¤
    --> C:\WINDOWS\system32\drivers\etc\hosts

    ÿþ1

    ¤¤¤ MBR Check: ¤¤¤

    +++++ PhysicalDrive0: +++++
    --- User ---
    [MBR] c416fba08077a49f37bd0c6428ea8f37
    [BSP] 081aecafbb0cc1f34454e73793a82f18 : Windows XP MBR Code
    Partition table:
    0 - [ACTIVE] NTFS (0x07) [VISIBLE] Offset (sectors): 63 | Size: 476929 Mo
    User = LL1 ... OK!
    User != LL2 ... KO!
    --- LL2 ---
    [MBR] 0d0e473649c0d8ceda4702e6cbeb9ef7
    [BSP] 081aecafbb0cc1f34454e73793a82f18 : Windows XP MBR Code
    Partition table:
    1 - [XXXXXX] NTFS (0x07) [VISIBLE] Offset (sectors): 63 | Size: 476929 Mo

    Finished : << RKreport[1]_S_05162013_02d1559.txt >>
    RKreport[1]_S_05162013_02d1559.txt



    RogueKiller V8.5.4 [Mar 18 2013] by Tigzy
    mail : tigzyRK<at>gmail<dot>com
    Feedback : http://www.geekstogo.com/forum/files/file/413-roguekiller/
    Website : http://tigzy.geekstogo.com/roguekiller.php
    Blog : http://tigzyrk.blogspot.com/

    Operating System : Windows XP (5.1.2600 Service Pack 3) 32 bits version
    Started in : Safe mode with network support
    User : Administrator [Admin rights]
    Mode : Remove -- Date : 05/16/2013 16:00:50
    | ARK || FAK || MBR |

    ¤¤¤ Bad processes : 1 ¤¤¤
    [SVCHOST] svchost.exe -- C:\WINDOWS\system32\svchost.exe [x] -> KILLED [TermProc]

    ¤¤¤ Registry Entries : 10 ¤¤¤
    [RUN][SUSP PATH] HKUS\S-1-5-21-299502267-1123561945-839522115-1003[...]\Run : TivoServer (C:\Program Files\TiVo\Desktop\TiVoServer.exe /service /registry /auto:TivoServer) [7] -> DELETED
    [RUN][SUSP PATH] HKUS\S-1-5-21-299502267-1123561945-839522115-1003[...]\Run : TivoTransfer (C:\Program Files\TiVo\Desktop\TiVoTransfer.exe) [7] -> DELETED
    [RUN][SUSP PATH] HKUS\S-1-5-21-299502267-1123561945-839522115-1003[...]\Run : TivoNotify (C:\Program Files\TiVo\Desktop\TiVoNotify.exe /service /registry /auto:TivoNotify) [7] -> DELETED
    [RUN][SUSP PATH] HKUS\S-1-5-21-299502267-1123561945-839522115-1003[...]\Run : TranscodingService (C:\Program Files\TiVo\Desktop\Plus\\TranscodingService.exe) [7] -> DELETED
    [RUN][SUSP PATH] HKCU\[...]\RunOnce : adawarebp_DATA_FOLDER (cmd.exe /c rmdir "C:\Documents and Settings\All Users\Application Data\Ad-Aware Browsing Protection" /s /q) [x] -> DELETED
    [RUN][SUSP PATH] HKCU\[...]\RunOnce : adawarebp_INSTALL_FOLDER (cmd.exe /c rmdir "C:\Documents and Settings\Administrator\Local Settings\Application Data\adawarebp" /s /q) [x] -> DELETED
    [HJPOL] HKLM\[...]\System : DisableRegistryTools (0) -> DELETED
    [HJ DESK] HKLM\[...]\NewStartPanel : {20D04FE0-3AEA-1069-A2D8-08002B30309D} (1) -> REPLACED (0)
    [SERVICES][HIDDEN KEY] HKLM\[...]\ControlSet001\Services\X\Start ((unknown)) -> ERROR [0x1]
    [SERVICES][HIDDEN KEY] HKLM\[...]\ControlSet003\Services\X\Start ((unknown)) -> ERROR [0x1]

    ¤¤¤ Particular Files / Folders: ¤¤¤

    ¤¤¤ Driver : [NOT LOADED] ¤¤¤

    ¤¤¤ HOSTS File: ¤¤¤
    --> C:\WINDOWS\system32\drivers\etc\hosts

    ÿþ1

    ¤¤¤ MBR Check: ¤¤¤

    +++++ PhysicalDrive0: +++++
    --- User ---
    [MBR] c416fba08077a49f37bd0c6428ea8f37
    [BSP] 081aecafbb0cc1f34454e73793a82f18 : Windows XP MBR Code
    Partition table:
    0 - [ACTIVE] NTFS (0x07) [VISIBLE] Offset (sectors): 63 | Size: 476929 Mo
    User = LL1 ... OK!
    User != LL2 ... KO!
    --- LL2 ---
    [MBR] 0d0e473649c0d8ceda4702e6cbeb9ef7
    [BSP] 081aecafbb0cc1f34454e73793a82f18 : Windows XP MBR Code
    Partition table:
    1 - [XXXXXX] NTFS (0x07) [VISIBLE] Offset (sectors): 63 | Size: 476929 Mo

    Finished : << RKreport[2]_D_05162013_02d1600.txt >>
    RKreport[1]_S_05162013_02d1559.txt ; RKreport[2]_D_05162013_02d1600.txt



    Malwarebytes Anti-Rootkit BETA 1.05.0.1001
    www.malwarebytes.org

    Database version: v2013.05.16.09

    Windows XP Service Pack 3 x86 NTFS (Safe Mode/Networking)
    Internet Explorer 8.0.6001.18702
    Administrator :: ALPHA [administrator]

    5/16/2013 4:33:23 PM
    mbar-log-2013-05-16 (16-33-23).txt

    Scan type: Quick scan
    Scan options enabled: Memory | Startup | Registry | File System | Heuristics/Extra | Heuristics/Shuriken | PUP | PUM | P2P
    Scan options disabled:
    Objects scanned: 27722
    Time elapsed: 24 minute(s), 6 second(s)

    Memory Processes Detected: 0
    (No malicious items detected)

    Memory Modules Detected: 0
    (No malicious items detected)

    Registry Keys Detected: 0
    (No malicious items detected)

    Registry Values Detected: 0
    (No malicious items detected)

    Registry Data Items Detected: 0
    (No malicious items detected)

    Folders Detected: 0
    (No malicious items detected)

    Files Detected: 7
    C:\Documents and Settings\All Users\Application Data\Malwarebytes\Malwarebytes' Anti-Malware\Bootstrap_0_0_13_infected.mbam (Rootkit.Pihar.c.MBR) -> Delete on reboot.
    C:\Documents and Settings\All Users\Application Data\Malwarebytes\Malwarebytes' Anti-Malware\MBR_0_infected.mbam (Rootkit.Pihar.c.MBR) -> Delete on reboot.
    c:\Documents and Settings\Dufresne\Local Settings\Application Data\Temp\{0C58F3F9-B17C-4767-903B-12764F63E320} (Trojan.P2P.Worm) -> Delete on reboot.
    c:\Documents and Settings\Dufresne\Local Settings\Application Data\Temp\{2AE26565-B431-44C4-ACDC-A2F353FD0C36} (Trojan.P2P.Worm) -> Delete on reboot.
    c:\Documents and Settings\Dufresne\Local Settings\Application Data\Temp\{7D8C5599-0A55-41C4-AC14-32F99E792A7E} (Trojan.P2P.Worm) -> Delete on reboot.
    c:\Documents and Settings\Dufresne\Local Settings\Application Data\Temp\{D65228CA-A391-4B90-AB00-AE3F50F99160} (Trojan.P2P.Worm) -> Delete on reboot.
    c:\Documents and Settings\Dufresne\Local Settings\Application Data\Temp\{F8C2F86F-ABB6-4927-88BD-EDBC95BC2BE1} (Trojan.P2P.Worm) -> Delete on reboot.

    (end)


    Malwarebytes Anti-Rootkit BETA 1.05.0.1001
    www.malwarebytes.org

    Database version: v2013.05.16.09

    Windows XP Service Pack 3 x86 NTFS (Safe Mode/Networking)
    Internet Explorer 8.0.6001.18702
    Administrator :: ALPHA [administrator]

    5/16/2013 5:03:03 PM
    mbar-log-2013-05-16 (17-03-03).txt

    Scan type: Quick scan
    Scan options enabled: Memory | Startup | Registry | File System | Heuristics/Extra | Heuristics/Shuriken | PUP | PUM | P2P
    Scan options disabled:
    Objects scanned: 27699
    Time elapsed: 25 minute(s), 29 second(s)

    Memory Processes Detected: 0
    (No malicious items detected)

    Memory Modules Detected: 0
    (No malicious items detected)

    Registry Keys Detected: 0
    (No malicious items detected)

    Registry Values Detected: 0
    (No malicious items detected)

    Registry Data Items Detected: 0
    (No malicious items detected)

    Folders Detected: 0
    (No malicious items detected)

    Files Detected: 0
    (No malicious items detected)

    (end)
     
    Last edited: 2013/05/16
  6. 2013/05/16
    broni

    broni Moderator Malware Analyst

    Joined:
    2002/08/01
    Messages:
    21,701
    Likes Received:
    116
    I still need system-log.txt logs.
     
  7. 2013/05/16
    chinaclipper

    chinaclipper Well-Known Member Thread Starter

    Joined:
    2010/01/20
    Messages:
    96
    Likes Received:
    0
    I'm sorry. Here is the message I got when I tried to upload system-log.txt

    "The text that you have entered is too long (237507 characters). Please shorten it to 55000 characters long. "
     
  8. 2013/05/17
    broni

    broni Moderator Malware Analyst

    Joined:
    2002/08/01
    Messages:
    21,701
    Likes Received:
    116
    Split it between couple of replies.
     
  9. 2013/05/17
    chinaclipper

    chinaclipper Well-Known Member Thread Starter

    Joined:
    2010/01/20
    Messages:
    96
    Likes Received:
    0
    Here is system-log.txt part 1

    ---------------------------------------
    Malwarebytes Anti-Rootkit BETA 1.05.0.1001

    (c) Malwarebytes Corporation 2011-2012

    OS version: 5.1.2600 Windows XP Service Pack 3 x86

    System is currently in a safe mode

    Account is Administrative

    Internet Explorer version: 8.0.6001.18702

    File system is: NTFS
    Disk drives: C:\ DRIVE_FIXED
    CPU speed: 1.999000 GHz
    Memory total: 2146545664, free: 1000919040

    ------------ Kernel report ------------
    05/16/2013 16:08:26
    ------------ Loaded modules -----------
    \WINDOWS\system32\ntoskrnl.exe
    \WINDOWS\system32\hal.dll
    \WINDOWS\system32\KDCOM.DLL
    \WINDOWS\system32\BOOTVID.dll
    ACPI.sys
    \WINDOWS\system32\DRIVERS\WMILIB.SYS
    pci.sys
    isapnp.sys
    gfibto.sys
    pciide.sys
    \WINDOWS\system32\DRIVERS\PCIIDEX.SYS
    MountMgr.sys
    ftdisk.sys
    dmload.sys
    dmio.sys
    PartMgr.sys
    VolSnap.sys
    atapi.sys
    disk.sys
    \WINDOWS\system32\DRIVERS\CLASSPNP.SYS
    fltmgr.sys
    sr.sys
    PxHelp20.sys
    KSecDD.sys
    WudfPf.sys
    Ntfs.sys
    NDIS.sys
    ohci1394.sys
    \WINDOWS\system32\DRIVERS\1394BUS.SYS
    Mup.sys
    avgrkx86.sys
    avglogx.sys
    avgmfx86.sys
    avgidshx.sys
    \SystemRoot\system32\DRIVERS\HDAudBus.sys
    \SystemRoot\system32\DRIVERS\l151x86.sys
    \SystemRoot\system32\DRIVERS\usbuhci.sys
    \SystemRoot\system32\DRIVERS\USBPORT.SYS
    \SystemRoot\system32\DRIVERS\usbehci.sys
    \SystemRoot\system32\DRIVERS\fdc.sys
    \SystemRoot\system32\DRIVERS\ASACPI.sys
    \SystemRoot\system32\DRIVERS\i8042prt.sys
    \SystemRoot\system32\DRIVERS\L8042Kbd.sys
    \SystemRoot\system32\DRIVERS\kbdclass.sys
    \SystemRoot\system32\DRIVERS\imapi.sys
    \SystemRoot\system32\DRIVERS\cdrom.sys
    \SystemRoot\system32\DRIVERS\redbook.sys
    \SystemRoot\system32\DRIVERS\ks.sys
    \SystemRoot\system32\DRIVERS\GEARAspiWDM.sys
    \SystemRoot\system32\DRIVERS\rasl2tp.sys
    \SystemRoot\system32\DRIVERS\ndistapi.sys
    \SystemRoot\system32\DRIVERS\ndiswan.sys
    \SystemRoot\system32\DRIVERS\raspppoe.sys
    \SystemRoot\system32\DRIVERS\raspptp.sys
    \SystemRoot\system32\DRIVERS\TDI.SYS
    \SystemRoot\system32\DRIVERS\psched.sys
    \SystemRoot\system32\DRIVERS\msgpc.sys
    \SystemRoot\system32\DRIVERS\ptilink.sys
    \SystemRoot\system32\DRIVERS\raspti.sys
    \SystemRoot\system32\DRIVERS\rdpdr.sys
    \SystemRoot\system32\DRIVERS\termdd.sys
    \SystemRoot\system32\DRIVERS\mouclass.sys
    \SystemRoot\system32\DRIVERS\swenum.sys
    \SystemRoot\system32\DRIVERS\update.sys
    \SystemRoot\system32\DRIVERS\mssmbios.sys
    \SystemRoot\System32\Drivers\NDProxy.SYS
    \SystemRoot\system32\DRIVERS\usbhub.sys
    \SystemRoot\system32\DRIVERS\USBD.SYS
    \SystemRoot\system32\DRIVERS\flpydisk.sys
    \SystemRoot\System32\Drivers\Fs_Rec.SYS
    \SystemRoot\System32\Drivers\Null.SYS
    \SystemRoot\System32\Drivers\Beep.SYS
    \SystemRoot\System32\drivers\vga.sys
    \SystemRoot\System32\drivers\VIDEOPRT.SYS
    \SystemRoot\System32\DRIVERS\RDPCDD.sys
    \SystemRoot\System32\Drivers\Msfs.SYS
    \SystemRoot\System32\Drivers\Npfs.SYS
    \SystemRoot\system32\DRIVERS\rasacd.sys
    \SystemRoot\system32\DRIVERS\ipsec.sys
    \SystemRoot\system32\DRIVERS\tcpip.sys
    \SystemRoot\system32\DRIVERS\ipnat.sys
    \SystemRoot\system32\DRIVERS\avgtdix.sys
    \SystemRoot\system32\DRIVERS\netbt.sys
    \SystemRoot\System32\drivers\afd.sys
    \SystemRoot\system32\DRIVERS\netbios.sys
    \SystemRoot\system32\DRIVERS\rdbss.sys
    \SystemRoot\system32\DRIVERS\mrxsmb.sys
    \SystemRoot\System32\Drivers\Cdfs.SYS
    \SystemRoot\system32\DRIVERS\USBSTOR.SYS
    \SystemRoot\system32\DRIVERS\hidusb.sys
    \SystemRoot\system32\DRIVERS\HIDCLASS.SYS
    \SystemRoot\system32\DRIVERS\HIDPARSE.SYS
    \SystemRoot\system32\DRIVERS\mouhid.sys
    \SystemRoot\System32\Drivers\dump_atapi.sys
    \SystemRoot\System32\Drivers\dump_WMILIB.SYS
    \SystemRoot\System32\win32k.sys
    \SystemRoot\System32\drivers\Dxapi.sys
    \SystemRoot\System32\watchdog.sys
    \SystemRoot\System32\drivers\dxg.sys
    \SystemRoot\System32\drivers\dxgthk.sys
    \SystemRoot\System32\ATMFD.DLL
    \SystemRoot\system32\DRIVERS\ndisuio.sys
    \SystemRoot\system32\DRIVERS\srv.sys
    \SystemRoot\System32\Drivers\Fastfat.SYS
    \SystemRoot\System32\TSDDD.dll
    \SystemRoot\System32\framebuf.dll
    \??\C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp\mbr.sys
    \??\C:\WINDOWS\system32\drivers\mbamchameleon.sys
    \??\C:\WINDOWS\system32\drivers\mbamswissarmy.sys
    \WINDOWS\system32\ntdll.dll
    ----------- End -----------
    <<<1>>>
    Upper Device Name: \Device\Harddisk2\DR3
    Upper Device Object: 0xffffffff8a063030
    Upper Device Driver Name: \Driver\Disk\
    Lower Device Name: \Device\0000007e\
    Lower Device Object: 0xffffffff8a080ea0
    Lower Device Driver Name: \Driver\USBSTOR\
    Driver name found: USBSTOR
    Initialization returned 0x0
    Load Function returned 0x0
    <<<1>>>
    Upper Device Name: \Device\Harddisk1\DR2
    Upper Device Object: 0xffffffff8a0694c8
    Upper Device Driver Name: \Driver\Disk\
    Lower Device Name: \Device\0000007d\
    Lower Device Object: 0xffffffff8a0708b0
    Lower Device Driver Name: \Driver\USBSTOR\
    Driver name found: USBSTOR
    <<<1>>>
    Upper Device Name: \Device\Harddisk0\DR0
    Upper Device Object: 0xffffffff8a30eab8
    Upper Device Driver Name: \Driver\Disk\
    Lower Device Name: Unknown
    Lower Device Object: 0xffffffff8a370d98
    Lower Device Driver Name: Unknown
    Driver name found: atapi
    Initialization returned 0x0
    Load Function returned 0x0
    Downloaded database version: v2013.05.16.09
    Downloaded database version: v2013.05.14.03
    Initializing...
    Done!
    <<<2>>>
    Device number: 0, partition: 1
    Physical Sector Size: 512
    Drive: 0, DevicePointer: 0xffffffff8a30eab8, DeviceName: \Device\Harddisk0\DR0\, DriverName: \Driver\Disk\
    --------- Disk Stack ------
    DevicePointer: 0xffffffff8a36ea00, DeviceName: Unknown, DriverName: \Driver\PartMgr\
    DevicePointer: 0xffffffff8a30eab8, DeviceName: \Device\Harddisk0\DR0\, DriverName: \Driver\Disk\
    DevicePointer: 0xffffffff8a370d98, DeviceName: Unknown, DriverName: Unknown
    ------------ End ----------
    Alternate DeviceName: \Device\Harddisk0\DR0\, DriverName: \Driver\Disk\
    Upper DeviceData: 0xffffffffe272b148, 0xffffffff8a30eab8, 0xffffffff899487c8
    Lower DeviceData: 0xffffffffe1e459a0, 0xffffffff8a370d98, 0xffffffff895dc040
    <<<3>>>
    Volume: C:
    File system type: NTFS
    SectorSize = 512, ClusterSize = 4096, MFTRecordSize = 1024, MFTIndexSize = 4096 bytes
    Scanning directory: C:\WINDOWS\system32\drivers...
    <<<2>>>
    Device number: 0, partition: 1
    <<<3>>>
    Volume: C:
    File system type: NTFS
    SectorSize = 512, ClusterSize = 4096, MFTRecordSize = 1024, MFTIndexSize = 4096 bytes
    Done!
    Drive 0
    Scanning MBR on drive 0...
    MBR buffers are not equal
    MBR is forged! [177b10df776cbf12774e7e6927767e44]
    Inspecting partition table:
    MBR Signature: 55AA
    Disk Signature: E654E654

    Partition information:

    Partition 0 type is Empty (0x0)
    Partition is ACTIVE.
    Partition starts at LBA: 13 Numsec = 0
    Partition is not bootable
    Infected: VBR on Empty active partition --> [Rootkit.Pihar.c.MBR]
    Changing partition to empty and not active. New active partition is 0 on drive 0 ...

    Partition 0 type is Primary (0x7)
    Partition is ACTIVE.
    Partition starts at LBA: 63 Numsec = 976751937
    Partition file system is NTFS
    Partition is bootable

    Partition 1 type is Empty (0x0)
    Partition is NOT ACTIVE.
    Partition starts at LBA: 0 Numsec = 0

    Partition 2 type is Empty (0x0)
    Partition is NOT ACTIVE.
    Partition starts at LBA: 0 Numsec = 0

    Partition 3 type is Empty (0x0)
    Partition is NOT ACTIVE.
    Partition starts at LBA: 0 Numsec = 0

    MBR infection found on drive 0
    Disk Size: 500107862016 bytes
    Sector size: 512 bytes

    Scanning physical sectors of unpartitioned space on drive 0 (1-12-976753168-976773168)...
    Physical Sector Size: 0
    Drive: 1, DevicePointer: 0xffffffff8a0694c8, DeviceName: \Device\Harddisk1\DR2\, DriverName: \Driver\Disk\
    --------- Disk Stack ------
    DevicePointer: 0xffffffff8a0692a0, DeviceName: Unknown, DriverName: \Driver\PartMgr\
    DevicePointer: 0xffffffff8a0694c8, DeviceName: \Device\Harddisk1\DR2\, DriverName: \Driver\Disk\
    DevicePointer: 0xffffffff8a0708b0, DeviceName: \Device\0000007d\, DriverName: \Driver\USBSTOR\
    ------------ End ----------
    Physical Sector Size: 0
    Drive: 2, DevicePointer: 0xffffffff8a063030, DeviceName: \Device\Harddisk2\DR3\, DriverName: \Driver\Disk\
    --------- Disk Stack ------
    DevicePointer: 0xffffffff8a063e08, DeviceName: Unknown, DriverName: \Driver\PartMgr\
    DevicePointer: 0xffffffff8a063030, DeviceName: \Device\Harddisk2\DR3\, DriverName: \Driver\Disk\
    DevicePointer: 0xffffffff8a080ea0, DeviceName: \Device\0000007e\, DriverName: \Driver\USBSTOR\
    ------------ End ----------
     
  10. 2013/05/17
    chinaclipper

    chinaclipper Well-Known Member Thread Starter

    Joined:
    2010/01/20
    Messages:
    96
    Likes Received:
    0
    part II

    Done!
    Performing system, memory and registry scan...
    Read File: File "c:\Documents and Settings\Administrator\Application Data\desktop.ini" is compressed (flags = 1)
    Read File: File "c:\Documents and Settings\Administrator\Application Data\Microsoft\Internet Explorer\brndlog.bak" is compressed (flags = 1)
    Read File: File "c:\Documents and Settings\Administrator\Application Data\Microsoft\Internet Explorer\brndlog.txt" is compressed (flags = 1)
    Read File: File "c:\Documents and Settings\All Users\Application Data\avg9\Cfg\erd.cfg" is compressed (flags = 1)
    Read File: File "c:\Documents and Settings\All Users\Application Data\avg9\Cfg\user.cfg" is compressed (flags = 1)
    Read File: File "c:\Documents and Settings\All Users\Application Data\avg9\CfgAll\krnlall.cfg" is compressed (flags = 1)
    Read File: File "c:\Documents and Settings\All Users\Application Data\avg9\Dumps\avgtray.exe_129041179032770000.exh" is compressed (flags = 1)
    Read File: File "c:\Documents and Settings\All Users\Application Data\avg9\scanlogs\srm.idx" is compressed (flags = 1)
    Read File: File "c:\Documents and Settings\All Users\Application Data\Real\setup\config.ini" is compressed (flags = 1)
    Read File: File "c:\Documents and Settings\All Users\Application Data\TaxCut\2007\NE.txt" is compressed (flags = 1)
    Read File: File "c:\Documents and Settings\All Users\Application Data\TaxCut\2008\NE.txt" is compressed (flags = 1)
    Read File: File "c:\Documents and Settings\All Users\Application Data\TaxCut\2008\pmWCPA.08" is compressed (flags = 1)
    Read File: File "c:\Documents and Settings\All Users\Application Data\TaxCut\2009\download.cfg" is compressed (flags = 1)
    Read File: File "c:\Documents and Settings\All Users\Application Data\TaxCut\2009\NE.txt" is compressed (flags = 1)
    Read File: File "c:\Documents and Settings\All Users\Application Data\TaxCut\2009\update.tim" is compressed (flags = 1)
    Read File: File "c:\Documents and Settings\All Users\Application Data\TaxCut\2010\download.cfg" is compressed (flags = 1)
    Read File: File "c:\Documents and Settings\All Users\Application Data\TaxCut\2010\NE.txt" is compressed (flags = 1)
    Read File: File "c:\Documents and Settings\All Users\Application Data\TaxCut\2010\update.tim" is compressed (flags = 1)
    Read File: File "c:\Documents and Settings\All Users\Application Data\TaxCut\2011\NE.txt" is compressed (flags = 1)
    Read File: File "c:\Documents and Settings\All Users\Application Data\TaxCut\2011\update.tim" is compressed (flags = 1)
    Read File: File "c:\Documents and Settings\All Users\Application Data\WinZip\WinZip.addon" is compressed (flags = 1)
    Read File: File "c:\Documents and Settings\All Users\Application Data\Malwarebytes\Malwarebytes' Anti-Malware\link.txt" is compressed (flags = 1)
    Read File: File "c:\Documents and Settings\All Users\Application Data\Malwarebytes\Malwarebytes' Anti-Malware\news.txt" is compressed (flags = 1)
    Read File: File "c:\Documents and Settings\All Users\Application Data\MFAData\SelfUpd\avg.snu" is compressed (flags = 1)
    Read File: File "c:\Documents and Settings\All Users\Application Data\MFAData\SelfUpd\avgatend.stp" is compressed (flags = 1)
    Read File: File "c:\Documents and Settings\All Users\Application Data\MFAData\SelfUpd\avgatupd.stp" is compressed (flags = 1)
    Read File: File "c:\Documents and Settings\All Users\Application Data\MFAData\SelfUpd\avgupd.sig" is compressed (flags = 1)
    Read File: File "c:\Documents and Settings\All Users\Application Data\MFAData\SelfUpd\mfavera.txt" is compressed (flags = 1)
    Read File: File "c:\Documents and Settings\All Users\Application Data\MFAData\SelfUpd\mfaconf.txt" is compressed (flags = 1)
    Read File: File "c:\Documents and Settings\All Users\Application Data\MFAData\SelfUpd\mfaverx.txt" is compressed (flags = 1)
    Read File: File "c:\Documents and Settings\All Users\Application Data\Microsoft Help\Hx.hxn" is compressed (flags = 1)
    Read File: File "c:\Documents and Settings\All Users\Application Data\Microsoft Help\Hx_1033_MValidator.Lck" is compressed (flags = 1)
    Read File: File "c:\Documents and Settings\All Users\Application Data\Microsoft Help\MS.EXCEL.12.1033.hxn" is compressed (flags = 1)
    Read File: File "c:\Documents and Settings\All Users\Application Data\Microsoft Help\MS.EXCEL.DEV.12.1033.hxn" is compressed (flags = 1)
    Read File: File "c:\Documents and Settings\All Users\Application Data\Microsoft Help\MS.GRAPH.12.1033.hxn" is compressed (flags = 1)
    Read File: File "c:\Documents and Settings\All Users\Application Data\Microsoft Help\MS.GROOVE.12.1033.hxn" is compressed (flags = 1)
    Read File: File "c:\Documents and Settings\All Users\Application Data\Microsoft Help\MS.INFOPATH.12.1033.hxn" is compressed (flags = 1)
    Read File: File "c:\Documents and Settings\All Users\Application Data\Microsoft Help\MS.INFOPATHEDITOR.12.1033.hxn" is compressed (flags = 1)
    Read File: File "c:\Documents and Settings\All Users\Application Data\Microsoft Help\MS.MSACCESS.12.1033.hxn" is compressed (flags = 1)
    Read File: File "c:\Documents and Settings\All Users\Application Data\Microsoft Help\MS.MSACCESS.12.1033_1033_MValidator.Lck" is compressed (flags = 1)
    Read File: File "c:\Documents and Settings\All Users\Application Data\Microsoft Help\MS.MSE.12.1033.hxn" is compressed (flags = 1)
    Read File: File "c:\Documents and Settings\All Users\Application Data\Microsoft Help\MS.MSPUB.12.1033.hxn" is compressed (flags = 1)
    Read File: File "c:\Documents and Settings\All Users\Application Data\Microsoft Help\MS.MSPUB.12.1033_1033_MValidator.Lck" is compressed (flags = 1)
    Read File: File "c:\Documents and Settings\All Users\Application Data\Microsoft Help\MS.MSPUB.DEV.12.1033.hxn" is compressed (flags = 1)
    Read File: File "c:\Documents and Settings\All Users\Application Data\Microsoft Help\MS.MSTORE.12.1033.hxn" is compressed (flags = 1)
    Read File: File "c:\Documents and Settings\All Users\Application Data\Microsoft Help\MS.OIS.12.1033.hxn" is compressed (flags = 1)
    Read File: File "c:\Documents and Settings\All Users\Application Data\Microsoft Help\MS.ONENOTE.12.1033.hxn" is compressed (flags = 1)
    Read File: File "c:\Documents and Settings\All Users\Application Data\Microsoft Help\MS.OUTLOOK.12.1033.hxn" is compressed (flags = 1)
    Read File: File "c:\Documents and Settings\All Users\Application Data\Microsoft Help\MS.OUTLOOK.DEV.12.1033.hxn" is compressed (flags = 1)
    Read File: File "c:\Documents and Settings\All Users\Application Data\Microsoft Help\MS.POWERPNT.12.1033.hxn" is compressed (flags = 1)
    Read File: File "c:\Documents and Settings\All Users\Application Data\Microsoft Help\MS.POWERPNT.12.1033_1033_MValidator.Lck" is compressed (flags = 1)
    Read File: File "c:\Documents and Settings\All Users\Application Data\Microsoft Help\MS.POWERPNT.DEV.12.1033.hxn" is compressed (flags = 1)
    Read File: File "c:\Documents and Settings\All Users\Application Data\Microsoft Help\MS.RIBBON.12.1033.hxn" is compressed (flags = 1)
    Read File: File "c:\Documents and Settings\All Users\Application Data\Microsoft Help\MS.SETLANG.12.1033.hxn" is compressed (flags = 1)
    Read File: File "c:\Documents and Settings\All Users\Application Data\Microsoft Help\MS.WINWORD.12.1033.hxn" is compressed (flags = 1)
    Read File: File "c:\Documents and Settings\All Users\Application Data\Microsoft Help\MS.WINWORD.DEV.12.1033.hxn" is compressed (flags = 1)
    Read File: File "c:\Documents and Settings\All Users\Application Data\Microsoft Help\MS.MSACCESS.DEV.12.1033.hxn" is compressed (flags = 1)
    Read File: File "c:\Documents and Settings\All Users\Application Data\Motorola\SUE\SUE.log" is compressed (flags = 1)
    Read File: File "c:\Documents and Settings\All Users\Application Data\Carbonite\Carbonite Backup\CarboniteRestoreHistory_19691231180000.dat" is compressed (flags = 1)
    Read File: File "c:\Documents and Settings\All Users\Application Data\Common Files\BCD8515B-1A00-42E0-EC4A-1535218FA1E2.dat" is compressed (flags = 1)
    Read File: File "c:\Documents and Settings\All Users\Application Data\GARMIN\VoiceStudio\__nv.dat" is compressed (flags = 1)
    Read File: File "c:\Documents and Settings\Default User\Application Data\Microsoft\Internet Explorer\brndlog.bak" is compressed (flags = 1)
    Read File: File "c:\Documents and Settings\Default User\Application Data\Microsoft\Internet Explorer\brndlog.txt" is compressed (flags = 1)
    Read File: File "c:\Documents and Settings\Dufresne\Application Data\setup_ldm.iss" is compressed (flags = 1)
    Read File: File "c:\Documents and Settings\Dufresne\Application Data\Ahead\NeroShowTime.bmk" is compressed (flags = 1)
    Read File: File "c:\Documents and Settings\Dufresne\Application Data\Ahead\Nero Burning ROM\NeroHistory.log" is compressed (flags = 1)
    Read File: File "c:\Documents and Settings\Dufresne\Application Data\Amazon\MP3 Downloader\amazonmp3.db" is compressed (flags = 1)
    Read File: File "c:\Documents and Settings\Dufresne\Application Data\Amazon\MP3 Downloader\DownloadQueue.amz" is compressed (flags = 1)
    Read File: File "c:\Documents and Settings\Dufresne\Application Data\AnvSoft\Any DVD Converter Professional\history2.db" is compressed (flags = 1)
    Read File: File "c:\Documents and Settings\Dufresne\Application Data\AnvSoft\Any DVD Converter Professional\vdoconv.log" is compressed (flags = 1)
    Read File: File "c:\Documents and Settings\Dufresne\Application Data\AnvSoft\Any Video Converter\history2.db" is compressed (flags = 1)
    Read File: File "c:\Documents and Settings\Dufresne\Application Data\AnvSoft\Any Video Converter\vdoconv.log" is compressed (flags = 1)
    Read File: File "c:\Documents and Settings\Dufresne\Application Data\CheckPoint\ZoneAlarm Toolbar\.version" is compressed (flags = 1)
    Read File: File "c:\Documents and Settings\Dufresne\Application Data\Microsoft\LastFlashConfig.WFC" is compressed (flags = 1)
    Read File: File "c:\Documents and Settings\Dufresne\Application Data\Microsoft\Address Book\Dufresne.wab" is compressed (flags = 1)
    Read File: File "c:\Documents and Settings\Dufresne\Application Data\Microsoft\Address Book\Dufresne.wab~" is compressed (flags = 1)
    Read File: File "c:\Documents and Settings\Dufresne\Application Data\Microsoft\Clip Organizer\mstore10.mgc" is compressed (flags = 1)
    Read File: File "c:\Documents and Settings\Dufresne\Application Data\Microsoft\Clip Organizer\Offic10.MGC" is compressed (flags = 1)
    Read File: File "c:\Documents and Settings\Dufresne\Application Data\Microsoft\HTML Help\hh.dat" is compressed (flags = 1)
    Read File: File "c:\Documents and Settings\Dufresne\Application Data\Microsoft\Internet Explorer\brndlog.bak" is compressed (flags = 1)
    Read File: File "c:\Documents and Settings\Dufresne\Application Data\Microsoft\Internet Explorer\brndlog.txt" is compressed (flags = 1)
    Read File: File "c:\Documents and Settings\Dufresne\Application Data\Microsoft\MSNLiveFav\log.xsl" is compressed (flags = 1)
    Read File: File "c:\Documents and Settings\Dufresne\Application Data\Microsoft\Office\Access12.pip" is compressed (flags = 1)
    Read File: File "c:\Documents and Settings\Dufresne\Application Data\Microsoft\Office\CLView12.pip" is compressed (flags = 1)
    Read File: File "c:\Documents and Settings\Dufresne\Application Data\Microsoft\Office\MSO1036.acl" is compressed (flags = 1)
    Read File: File "c:\Documents and Settings\Dufresne\Application Data\Microsoft\Office\MSO2057.acl" is compressed (flags = 1)
    Read File: File "c:\Documents and Settings\Dufresne\Application Data\Microsoft\Office\OIS12.pip" is compressed (flags = 1)
    Read File: File "c:\Documents and Settings\Dufresne\Application Data\Microsoft\Office\OneNot12.pip" is compressed (flags = 1)
    Read File: File "c:\Documents and Settings\Dufresne\Application Data\Microsoft\Office\OrgDB12.pip" is compressed (flags = 1)
    Read File: File "c:\Documents and Settings\Dufresne\Application Data\Microsoft\Office\PowerP12.pip" is compressed (flags = 1)
    Read File: File "c:\Documents and Settings\Dufresne\Application Data\Microsoft\Office\Publis12.pip" is compressed (flags = 1)
    Read File: File "c:\Documents and Settings\Dufresne\Application Data\Microsoft\Office\VB12.pip" is compressed (flags = 1)
    Read File: File "c:\Documents and Settings\Dufresne\Application Data\Microsoft\OIS\Toolbars.dat" is compressed (flags = 1)
    Read File: File "c:\Documents and Settings\Dufresne\Application Data\Microsoft\PowerPoint\PPT12.pcb" is compressed (flags = 1)
    Read File: File "c:\Documents and Settings\Dufresne\Application Data\Microsoft\Publisher\pubcmd12.dat" is compressed (flags = 1)
    Read File: File "c:\Documents and Settings\Dufresne\Application Data\Microsoft\Templates\Drum sheet music (OneNote 2003 Format).one.backup" is compressed (flags = 1)
    Read File: File "c:\Documents and Settings\Dufresne\Application Data\Microsoft\Templates\Drum sheet music.one" is compressed (flags = 1)
    Read File: File "c:\Documents and Settings\Dufresne\Application Data\Microsoft\Templates\My Templates.one" is compressed (flags = 1)
    Read File: File "c:\Documents and Settings\Dufresne\Application Data\Microsoft\Templates\Normal.BAK" is compressed (flags = 1)
    Read File: File "c:\Documents and Settings\Dufresne\Application Data\Microsoft\Templates\OneNote Table Of Contents.onetoc2" is compressed (flags = 1)
    Read File: File "c:\Documents and Settings\Dufresne\Application Data\Microsoft\UProof\ExcludeDictionaryEN0809.lex" is compressed (flags = 1)
    Read File: File "c:\Documents and Settings\Dufresne\Application Data\Move Networks\QMCache00\A0C97106E5B54BA28D878F37B38B4B19000004C800C8C7C90ABF1.qss" is compressed (flags = 1)
    Read File: File "c:\Documents and Settings\Dufresne\Application Data\Move Networks\QMCache00\A0C97106E5B54BA28D878F37B38B4B19000004C900C8824C0B8FB.qss" is compressed (flags = 1)
    Read File: File "c:\Documents and Settings\Dufresne\Application Data\Move Networks\QMCache00\A0C97106E5B54BA28D878F37B38B4B19000004CA00C845BF06468.qss" is compressed (flags = 1)
    Read File: File "c:\Documents and Settings\Dufresne\Application Data\Move Networks\QMCache00\A0C97106E5B54BA28D878F37B38B4B19000004CB00C81B1309048.qss" is compressed (flags = 1)
    Read File: File "c:\Documents and Settings\Dufresne\Application Data\Move Networks\QMCache00\A0C97106E5B54BA28D878F37B38B4B19000004CC00C81A630791D.qss" is compressed (flags = 1)
    Read File: File "c:\Documents and Settings\Dufresne\Application Data\Move Networks\QMCache00\A0C97106E5B54BA28D878F37B38B4B19000004CD00C8C37203866.qss" is compressed (flags = 1)
    Read File: File "c:\Documents and Settings\Dufresne\Application Data\Move Networks\QMCache00\A0C97106E5B54BA28D878F37B38B4B19000004CE00C8320F0C6E4.qss" is compressed (flags = 1)
    Read File: File "c:\Documents and Settings\Dufresne\Application Data\Move Networks\QMCache00\A0C97106E5B54BA28D878F37B38B4B19000004CF00C8343F079F6.qss" is compressed (flags = 1)
    Read File: File "c:\Documents and Settings\Dufresne\Application Data\Move Networks\QMCache00\A0C97106E5B54BA28D878F37B38B4B19000004D000C8087009ACD.qss" is compressed (flags = 1)
    Read File: File "c:\Documents and Settings\Dufresne\Application Data\Move Networks\QMCache00\A0C97106E5B54BA28D878F37B38B4B190000049400C8D8F109219.qss" is compressed (flags = 1)
    Read File: File "c:\Documents and Settings\Dufresne\Application Data\Move Networks\QMCache00\A0C97106E5B54BA28D878F37B38B4B190000049500C892DD076B8.qss" is compressed (flags = 1)
    Read File: File "c:\Documents and Settings\Dufresne\Application Data\Move Networks\QMCache00\A0C97106E5B54BA28D878F37B38B4B190000049600C896D607236.qss" is compressed (flags = 1)
    Read File: File "c:\Documents and Settings\Dufresne\Application Data\Move Networks\QMCache00\A0C97106E5B54BA28D878F37B38B4B190000049700C8253F0A9CB.qss" is compressed (flags = 1)
    Read File: File "c:\Documents and Settings\Dufresne\Application Data\Move Networks\QMCache00\A0C97106E5B54BA28D878F37B38B4B190000049800C7A4D6034E7.qss" is compressed (flags = 1)
    Read File: File "c:\Documents and Settings\Dufresne\Application Data\Move Networks\QMCache00\A0C97106E5B54BA28D878F37B38B4B190000049900C7802B04D5F.qss" is compressed (flags = 1)
    Read File: File "c:\Documents and Settings\Dufresne\Application Data\Move Networks\QMCache00\A0C97106E5B54BA28D878F37B38B4B190000049A00C7B09D058D7.qss" is compressed (flags = 1)
    Read File: File "c:\Documents and Settings\Dufresne\Application Data\Move Networks\QMCache00\A0C97106E5B54BA28D878F37B38B4B190000049B00C855A8050C7.qss" is compressed (flags = 1)
    Read File: File "c:\Documents and Settings\Dufresne\Application Data\Move Networks\QMCache00\A0C97106E5B54BA28D878F37B38B4B190000049C00C79CAD04448.qss" is compressed (flags = 1)
    Read File: File "c:\Documents and Settings\Dufresne\Application Data\Move Networks\QMCache00\A0C97106E5B54BA28D878F37B38B4B19000004D200C7EC2D09F3E.qss" is compressed (flags = 1)
    Read File: File "c:\Documents and Settings\Dufresne\Application Data\Move Networks\QMCache00\A0C97106E5B54BA28D878F37B38B4B19000004D300C7E8F909E34.qss" is compressed (flags = 1)
    Read File: File "c:\Documents and Settings\Dufresne\Application Data\Move Networks\QMCache00\A0C97106E5B54BA28D878F37B38B4B19000004D400C84F5D09FDD.qss" is compressed (flags = 1)
    Read File: File "c:\Documents and Settings\Dufresne\Application Data\Move Networks\QMCache00\A0C97106E5B54BA28D878F37B38B4B19000004D500C86CB808E2E.qss" is compressed (flags = 1)
    Read File: File "c:\Documents and Settings\Dufresne\Application Data\Move Networks\QMCache00\A0C97106E5B54BA28D878F37B38B4B19000004D600C8607109A99.qss" is compressed (flags = 1)
    Read File: File "c:\Documents and Settings\Dufresne\Application Data\Move Networks\QMCache00\A0C97106E5B54BA28D878F37B38B4B19000004D700C780410A168.qss" is compressed (flags = 1)
    Read File: File "c:\Documents and Settings\Dufresne\Application Data\Move Networks\QMCache00\A0C97106E5B54BA28D878F37B38B4B19000004D800C74B230741A.qss" is compressed (flags = 1)
    Read File: File "c:\Documents and Settings\Dufresne\Application Data\Move Networks\QMCache00\A0C97106E5B54BA28D878F37B38B4B19000004D900C6F780072E0.qss" is compressed (flags = 1)
    Read File: File "c:\Documents and Settings\Dufresne\Application Data\Move Networks\QMCache00\A0C97106E5B54BA28D878F37B38B4B19000004DA00C69BA8040AC.qss" is compressed (flags = 1)
    Read File: File "c:\Documents and Settings\Dufresne\Application Data\Move Networks\QMCache00\A0C97106E5B54BA28D878F37B38B4B19000004B200C8A5A30A1EE.qss" is compressed (flags = 1)
    Read File: File "c:\Documents and Settings\Dufresne\Application Data\Move Networks\QMCache00\A0C97106E5B54BA28D878F37B38B4B19000004B300C7BB6003EBC.qss" is compressed (flags = 1)
    Read File: File "c:\Documents and Settings\Dufresne\Application Data\Move Networks\QMCache00\A0C97106E5B54BA28D878F37B38B4B19000004B400C7AFB40230C.qss" is compressed (flags = 1)
    Read File: File "c:\Documents and Settings\Dufresne\Application Data\Move Networks\QMCache00\A0C97106E5B54BA28D878F37B38B4B19000004B500C7CA1E0562E.qss" is compressed (flags = 1)
    Read File: File "c:\Documents and Settings\Dufresne\Application Data\Move Networks\QMCache00\A0C97106E5B54BA28D878F37B38B4B19000004B600C7BD2805296.qss" is compressed (flags = 1)
    Read File: File "c:\Documents and Settings\Dufresne\Application Data\Move Networks\QMCache00\A0C97106E5B54BA28D878F37B38B4B19000004B700C7654904187.qss" is compressed (flags = 1)
    Read File: File "c:\Documents and Settings\Dufresne\Application Data\Move Networks\QMCache00\A0C97106E5B54BA28D878F37B38B4B19000004B800C7694F04ACE.qss" is compressed (flags = 1)
    Read File: File "c:\Documents and Settings\Dufresne\Application Data\Move Networks\QMCache00\A0C97106E5B54BA28D878F37B38B4B19000004B900C7CD4D04B4C.qss" is compressed (flags = 1)
    Read File: File "c:\Documents and Settings\Dufresne\Application Data\Move Networks\QMCache00\A0C97106E5B54BA28D878F37B38B4B19000004BA00C7CADE0522E.qss" is compressed (flags = 1)
    Read File: File "c:\Documents and Settings\Dufresne\Application Data\Move Networks\QMCache00\A0C97106E5B54BA28D878F37B38B4B19000004BB00C775EC05750.qss" is compressed (flags = 1)
    Read File: File "c:\Documents and Settings\Dufresne\Application Data\Move Networks\QMCache00\A0C97106E5B54BA28D878F37B38B4B19000004BC00C7C001054FB.qss" is compressed (flags = 1)
    Read File: File "c:\Documents and Settings\Dufresne\Application Data\Move Networks\QMCache00\A0C97106E5B54BA28D878F37B38B4B190000046200C74CCA02CA0.qss" is compressed (flags = 1)
    Read File: File "c:\Documents and Settings\Dufresne\Application Data\Move Networks\QMCache00\A0C97106E5B54BA28D878F37B38B4B190000046300C6D49506082.qss" is compressed (flags = 1)
    Read File: File "c:\Documents and Settings\Dufresne\Application Data\Move Networks\QMCache00\A0C97106E5B54BA28D878F37B38B4B190000046400C81FA3058B6.qss" is compressed (flags = 1)
    Read File: File "c:\Documents and Settings\Dufresne\Application Data\Move Networks\QMCache00\A0C97106E5B54BA28D878F37B38B4B190000046500C84B8B0A4EC.qss" is compressed (flags = 1)
    Read File: File "c:\Documents and Settings\Dufresne\Application Data\Move Networks\QMCache00\A0C97106E5B54BA28D878F37B38B4B190000046600C881B20A39B.qss" is compressed (flags = 1)
    Read File: File "c:\Documents and Settings\Dufresne\Application Data\Move Networks\QMCache00\A0C97106E5B54BA28D878F37B38B4B190000046700C791A70741F.qss" is compressed (flags = 1)
    Read File: File "c:\Documents and Settings\Dufresne\Application Data\Move Networks\QMCache00\A0C97106E5B54BA28D878F37B38B4B190000046800C8B0D705CA3.qss" is compressed (flags = 1)
    Read File: File "c:\Documents and Settings\Dufresne\Application Data\Move Networks\QMCache00\A0C97106E5B54BA28D878F37B38B4B190000046900C8E5220C5CD.qss" is compressed (flags = 1)
    Read File: File "c:\Documents and Settings\Dufresne\Application Data\Move Networks\QMCache00\A0C97106E5B54BA28D878F37B38B4B190000046A00C8EF110BEA3.qss" is compressed (flags = 1)
    Read File: File "c:\Documents and Settings\Dufresne\Application Data\Move Networks\QMCache00\A0C97106E5B54BA28D878F37B38B4B19000004DC00C669CE033E4.qss" is compressed (flags = 1)
    Read File: File "c:\Documents and Settings\Dufresne\Application Data\Move Networks\QMCache00\A0C97106E5B54BA28D878F37B38B4B19000004DD00C6F7F502F8A.qss" is compressed (flags = 1)
    Read File: File "c:\Documents and Settings\Dufresne\Application Data\Move Networks\QMCache00\A0C97106E5B54BA28D878F37B38B4B19000004DE00C675BC03404.qss" is compressed (flags = 1)
    Read File: File "c:\Documents and Settings\Dufresne\Application Data\Move Networks\QMCache00\A0C97106E5B54BA28D878F37B38B4B19000004DF00C683CE02D29.qss" is compressed (flags = 1)
    Read File: File "c:\Documents and Settings\Dufresne\Application Data\Move Networks\QMCache00\A0C97106E5B54BA28D878F37B38B4B19000004E000C7B4FD04274.qss" is compressed (flags = 1)
    Read File: File "c:\Documents and Settings\Dufresne\Application Data\Move Networks\QMCache00\A0C97106E5B54BA28D878F37B38B4B19000004E100C72795047A7.qss" is compressed (flags = 1)
    Read File: File "c:\Documents and Settings\Dufresne\Application Data\Move Networks\QMCache00\A0C97106E5B54BA28D878F37B38B4B19000004E200C7E44C0359F.qss" is compressed (flags = 1)
    Read File: File "c:\Documents and Settings\Dufresne\Application Data\Move Networks\QMCache00\A0C97106E5B54BA28D878F37B38B4B19000004E300C6FED5064A0.qss" is compressed (flags = 1)
    Read File: File "c:\Documents and Settings\Dufresne\Application Data\Move Networks\QMCache00\A0C97106E5B54BA28D878F37B38B4B19000004E400C7E7F603C48.qss" is compressed (flags = 1)
    Read File: File "c:\Documents and Settings\Dufresne\Application Data\Move Networks\QMCache00\A0C97106E5B54BA28D878F37B38B4B190000046C00C8C4E70B644.qss" is compressed (flags = 1)
    Read File: File "c:\Documents and Settings\Dufresne\Application Data\Move Networks\QMCache00\A0C97106E5B54BA28D878F37B38B4B190000046D00C8D84C09EA7.qss" is compressed (flags = 1)
    Read File: File "c:\Documents and Settings\Dufresne\Application Data\Move Networks\QMCache00\A0C97106E5B54BA28D878F37B38B4B190000046E00C8CA940BD5A.qss" is compressed (flags = 1)
    Read File: File "c:\Documents and Settings\Dufresne\Application Data\Move Networks\QMCache00\A0C97106E5B54BA28D878F37B38B4B190000046F00C8C9710C943.qss" is compressed (flags = 1)
    Read File: File "c:\Documents and Settings\Dufresne\Application Data\Move Networks\QMCache00\A0C97106E5B54BA28D878F37B38B4B190000047000C7507307EB1.qss" is compressed (flags = 1)
    Read File: File "c:\Documents and Settings\Dufresne\Application Data\Move Networks\QMCache00\A0C97106E5B54BA28D878F37B38B4B190000047100C7CB1F06265.qss" is compressed (flags = 1)
    Read File: File "c:\Documents and Settings\Dufresne\Application Data\Move Networks\QMCache00\A0C97106E5B54BA28D878F37B38B4B190000047200C74EE302D6A.qss" is compressed (flags = 1)
    Read File: File "c:\Documents and Settings\Dufresne\Application Data\Move Networks\QMCache00\A0C97106E5B54BA28D878F37B38B4B190000047300C735BA04C0E.qss" is compressed (flags = 1)
    Read File: File "c:\Documents and Settings\Dufresne\Application Data\Move Networks\QMCache00\A0C97106E5B54BA28D878F37B38B4B190000047400C6FD0904395.qss" is compressed (flags = 1)
    Read File: File "c:\Documents and Settings\Dufresne\Application Data\Move Networks\QMCache00\A0C97106E5B54BA28D878F37B38B4B19000004E600C84240076FD.qss" is compressed (flags = 1)
    Read File: File "c:\Documents and Settings\Dufresne\Application Data\Move Networks\QMCache00\A0C97106E5B54BA28D878F37B38B4B19000004E700C7379707356.qss" is compressed (flags = 1)
    Read File: File "c:\Documents and Settings\Dufresne\Application Data\Move Networks\QMCache00\A0C97106E5B54BA28D878F37B38B4B19000004E800C741CD03F96.qss" is compressed (flags = 1)
    Read File: File "c:\Documents and Settings\Dufresne\Application Data\Move Networks\QMCache00\A0C97106E5B54BA28D878F37B38B4B19000004E900C6E22E06EEF.qss" is compressed (flags = 1)
    Read File: File "c:\Documents and Settings\Dufresne\Application Data\Move Networks\QMCache00\A0C97106E5B54BA28D878F37B38B4B19000004EA00C6F63A03B6D.qss" is compressed (flags = 1)
    Read File: File "c:\Documents and Settings\Dufresne\Application Data\Move Networks\QMCache00\A0C97106E5B54BA28D878F37B38B4B19000004EB00C66036033B5.qss" is compressed (flags = 1)
    Read File: File "c:\Documents and Settings\Dufresne\Application Data\Move Networks\QMCache00\A0C97106E5B54BA28D878F37B38B4B19000004EC00C6D3BA044FE.qss" is compressed (flags = 1)
    Read File: File "c:\Documents and Settings\Dufresne\Application Data\Move Networks\QMCache00\A0C97106E5B54BA28D878F37B38B4B19000004ED00C7264C0454A.qss" is compressed (flags = 1)
    Read File: File "c:\Documents and Settings\Dufresne\Application Data\Move Networks\QMCache00\A0C97106E5B54BA28D878F37B38B4B19000004EE00C7462F05783.qss" is compressed (flags = 1)
    Read File: File "c:\Documents and Settings\Dufresne\Application Data\Move Networks\QMCache00\A0C97106E5B54BA28D878F37B38B4B19000004F000C7254E03BBB.qss" is compressed (flags = 1)
    Read File: File "c:\Documents and Settings\Dufresne\Application Data\Move Networks\QMCache00\A0C97106E5B54BA28D878F37B38B4B19000004F100C7477203721.qss" is compressed (flags = 1)
    Read File: File "c:\Documents and Settings\Dufresne\Application Data\Move Networks\QMCache00\A0C97106E5B54BA28D878F37B38B4B19000004F200C6BDF903B06.qss" is compressed (flags = 1)
    Read File: File "c:\Documents and Settings\Dufresne\Application Data\Move Networks\QMCache00\A0C97106E5B54BA28D878F37B38B4B19000004F300C6B9860382E.qss" is compressed (flags = 1)
    Read File: File "c:\Documents and Settings\Dufresne\Application Data\Move Networks\QMCache00\A0C97106E5B54BA28D878F37B38B4B19000004F400C6A4E20394D.qss" is compressed (flags = 1)
    Read File: File "c:\Documents and Settings\Dufresne\Application Data\Move Networks\QMCache00\A0C97106E5B54BA28D878F37B38B4B19000004F500C693A3036CC.qss" is compressed (flags = 1)
    Read File: File "c:\Documents and Settings\Dufresne\Application Data\Move Networks\QMCache00\A0C97106E5B54BA28D878F37B38B4B19000004F600C6BF6F038AE.qss" is compressed (flags = 1)
    Read File: File "c:\Documents and Settings\Dufresne\Application Data\Move Networks\QMCache00\A0C97106E5B54BA28D878F37B38B4B19000004F700C6CA1D03D8F.qss" is compressed (flags = 1)
    Read File: File "c:\Documents and Settings\Dufresne\Application Data\Move Networks\QMCache00\A0C97106E5B54BA28D878F37B38B4B19000004F800C6B9330418C.qss" is compressed (flags = 1)
    Read File: File "c:\Documents and Settings\Dufresne\Application Data\Move Networks\QMCache00\A0C97106E5B54BA28D878F37B38B4B190000050E00C627BE035B3.qss" is compressed (flags = 1)
    Read File: File "c:\Documents and Settings\Dufresne\Application Data\Move Networks\QMCache00\A0C97106E5B54BA28D878F37B38B4B190000050F00C65217036E4.qss" is compressed (flags = 1)
    Read File: File "c:\Documents and Settings\Dufresne\Application Data\Move Networks\QMCache00\A0C97106E5B54BA28D878F37B38B4B190000051000C5897703684.qss" is compressed (flags = 1)
    Read File: File "c:\Documents and Settings\Dufresne\Application Data\Move Networks\QMCache00\A0C97106E5B54BA28D878F37B38B4B190000051100C086B30085B.qss" is compressed (flags = 1)
    Read File: File "c:\Documents and Settings\Dufresne\Application Data\Move Networks\QMCache00\A0C97106E5B54BA28D878F37B38B4B190000051200C0C4FD0085B.qss" is compressed (flags = 1)
    Read File: File "c:\Documents and Settings\Dufresne\Application Data\Move Networks\QMCache00\A0C97106E5B54BA28D878F37B38B4B190000051300C122E901E2C.qss" is compressed (flags = 1)
    Read File: File "c:\Documents and Settings\Dufresne\Application Data\Move Networks\QMCache00\A0C97106E5B54BA28D878F37B38B4B190000051400C11B590195A.qss" is compressed (flags = 1)
    Read File: File "c:\Documents and Settings\Dufresne\Application Data\Move Networks\QMCache00\A0C97106E5B54BA28D878F37B38B4B190000051500C13E140348C.qss" is compressed (flags = 1)
    Read File: File "c:\Documents and Settings\Dufresne\Application Data\Move Networks\QMCache00\A0C97106E5B54BA28D878F37B38B4B190000051600C16B2B031AE.qss" is compressed (flags = 1)
    Read File: File "c:\Documents and Settings\Dufresne\Application Data\Move Networks\QMCache00\E30E776DE3C9447CBBE9CEB8A7AC0FE7000000090094C40D0423C.qss" is compressed (flags = 1)
    Read File: File "c:\Documents and Settings\Dufresne\Application Data\Move Networks\QMCache00\E30E776DE3C9447CBBE9CEB8A7AC0FE70000000A0094C8D90484F.qss" is compressed (flags = 1)
    Read File: File "c:\Documents and Settings\Dufresne\Application Data\Move Networks\QMCache00\E30E776DE3C9447CBBE9CEB8A7AC0FE70000000B00953DAA02B8C.qss" is compressed (flags = 1)
    Read File: File "c:\Documents and Settings\Dufresne\Application Data\Move Networks\QMCache00\E30E776DE3C9447CBBE9CEB8A7AC0FE70000000C009472B403307.qss" is compressed (flags = 1)
    Read File: File "c:\Documents and Settings\Dufresne\Application Data\Move Networks\QMCache00\E30E776DE3C9447CBBE9CEB8A7AC0FE70000000D00945EE703193.qss" is compressed (flags = 1)
    Read File: File "c:\Documents and Settings\Dufresne\Application Data\Move Networks\QMCache00\E30E776DE3C9447CBBE9CEB8A7AC0FE70000000E0094D45902121.qss" is compressed (flags = 1)
    Read File: File "c:\Documents and Settings\Dufresne\Application Data\Move Networks\QMCache00\E30E776DE3C9447CBBE9CEB8A7AC0FE70000000F0092B807020F7.qss" is compressed (flags = 1)
    Read File: File "c:\Documents and Settings\Dufresne\Application Data\Move Networks\QMCache00\E30E776DE3C9447CBBE9CEB8A7AC0FE7000000100090CBC802A02.qss" is compressed (flags = 1)
    Read File: File "c:\Documents and Settings\Dufresne\Application Data\Move Networks\QMCache00\A0C97106E5B54BA28D878F37B38B4B19000003E900C840040611C.qss" is compressed (flags = 1)
    Read File: File "c:\Documents and Settings\Dufresne\Application Data\Move Networks\QMCache00\A0C97106E5B54BA28D878F37B38B4B19000003F300C8622505D54.qss" is compressed (flags = 1)
    Read File: File "c:\Documents and Settings\Dufresne\Application Data\Move Networks\QMCache00\A0C97106E5B54BA28D878F37B38B4B19000004BE00C7ADC204BBB.qss" is compressed (flags = 1)
    Read File: File "c:\Documents and Settings\Dufresne\Application Data\Move Networks\QMCache00\A0C97106E5B54BA28D878F37B38B4B19000004BF00C7A71C04890.qss" is compressed (flags = 1)
    Read File: File "c:\Documents and Settings\Dufresne\Application Data\Move Networks\QMCache00\A0C97106E5B54BA28D878F37B38B4B19000004C000C7381505BA1.qss" is compressed (flags = 1)
    Read File: File "c:\Documents and Settings\Dufresne\Application Data\Move Networks\QMCache00\A0C97106E5B54BA28D878F37B38B4B19000004C100C854B307989.qss" is compressed (flags = 1)
    Read File: File "c:\Documents and Settings\Dufresne\Application Data\Move Networks\QMCache00\A0C97106E5B54BA28D878F37B38B4B19000004C200C8559907BBC.qss" is compressed (flags = 1)
    Read File: File "c:\Documents and Settings\Dufresne\Application Data\Move Networks\QMCache00\A0C97106E5B54BA28D878F37B38B4B19000004C300C87A7F05832.qss" is compressed (flags = 1)
    Read File: File "c:\Documents and Settings\Dufresne\Application Data\Move Networks\QMCache00\A0C97106E5B54BA28D878F37B38B4B19000004C400C87D4F0A2F5.qss" is compressed (flags = 1)
    Read File: File "c:\Documents and Settings\Dufresne\Application Data\Move Networks\QMCache00\A0C97106E5B54BA28D878F37B38B4B19000004C500C85FF90A352.qss" is compressed (flags = 1)
    Read File: File "c:\Documents and Settings\Dufresne\Application Data\Move Networks\QMCache00\A0C97106E5B54BA28D878F37B38B4B19000004C600C872E20837F.qss" is compressed (flags = 1)
    Read File: File "c:\Documents and Settings\Dufresne\Application Data\Move Networks\QMCache00\A0C97106E5B54BA28D878F37B38B4B19000003E700C85A2605810.qss" is compressed (flags = 1)
    Read File: File "c:\Documents and Settings\Dufresne\Application Data\Move Networks\QMCache00\A0C97106E5B54BA28D878F37B38B4B19000003E800C7CC430276F.qss" is compressed (flags = 1)
    Read File: File "c:\Documents and Settings\Dufresne\Application Data\Move Networks\QMCache00\A0C97106E5B54BA28D878F37B38B4B19000003EA00C8146905366.qss" is compressed (flags = 1)
    Read File: File "c:\Documents and Settings\Dufresne\Application Data\Move Networks\QMCache00\A0C97106E5B54BA28D878F37B38B4B19000003EB00C88D9806FCC.qss" is compressed (flags = 1)
    Read File: File "c:\Documents and Settings\Dufresne\Application Data\Move Networks\QMCache00\A0C97106E5B54BA28D878F37B38B4B19000003EC00C83F2306FD5.qss" is compressed (flags = 1)
    Read File: File "c:\Documents and Settings\Dufresne\Application Data\Move Networks\QMCache00\A0C97106E5B54BA28D878F37B38B4B19000003ED00C8604A04AF0.qss" is compressed (flags = 1)
    Read File: File "c:\Documents and Settings\Dufresne\Application Data\Move Networks\QMCache00\A0C97106E5B54BA28D878F37B38B4B19000003EE00C8710105DDC.qss" is compressed (flags = 1)
    Read File: File "c:\Documents and Settings\Dufresne\Application Data\Move Networks\QMCache00\A0C97106E5B54BA28D878F37B38B4B19000003EF00C8712F069BE.qss" is compressed (flags = 1)
    Read File: File "c:\Documents and Settings\Dufresne\Application Data\Move Networks\QMCache00\A0C97106E5B54BA28D878F37B38B4B19000003F000C7F07F0642D.qss" is compressed (flags = 1)
    Read File: File "c:\Documents and Settings\Dufresne\Application Data\Move Networks\QMCache00\A0C97106E5B54BA28D878F37B38B4B19000003F100C8747206BC3.qss" is compressed (flags = 1)
    Read File: File "c:\Documents and Settings\Dufresne\Application Data\Move Networks\QMCache00\A0C97106E5B54BA28D878F37B38B4B19000003F200C8727804E85.qss" is compressed (flags = 1)
    Read File: File "c:\Documents and Settings\Dufresne\Application Data\Move Networks\QMCache00\A0C97106E5B54BA28D878F37B38B4B19000003F400C855C006505.qss" is compressed (flags = 1)
    Read File: File "c:\Documents and Settings\Dufresne\Application Data\Move Networks\QMCache00\A0C97106E5B54BA28D878F37B38B4B19000003F500C8631801F21.qss" is compressed (flags = 1)
    Read File: File "c:\Documents and Settings\Dufresne\Application Data\Move Networks\QMCache00\A0C97106E5B54BA28D878F37B38B4B19000003F600C898CF0611A.qss" is compressed (flags = 1)
    Read File: File "c:\Documents and Settings\Dufresne\Application Data\Move Networks\QMCache00\A0C97106E5B54BA28D878F37B38B4B19000003F700C885D90AB36.qss" is compressed (flags = 1)
    Read File: File "c:\Documents and Settings\Dufresne\Application Data\Move Networks\QMCache00\A0C97106E5B54BA28D878F37B38B4B19000003F800C8C0000845E.qss" is compressed (flags = 1)
    Read File: File "c:\Documents and Settings\Dufresne\Application Data\Move Networks\QMCache00\A0C97106E5B54BA28D878F37B38B4B19000003F900C8AB0307F13.qss" is compressed (flags = 1)
    Read File: File "c:\Documents and Settings\Dufresne\Application Data\Move Networks\QMCache00\A0C97106E5B54BA28D878F37B38B4B19000003FA00C9011A0818C.qss" is compressed (flags = 1)
    Read File: File "c:\Documents and Settings\Dufresne\Application Data\Move Networks\QMCache00\A0C97106E5B54BA28D878F37B38B4B19000003FB00C8A04B0C4D7.qss" is compressed (flags = 1)
    Read File: File "c:\Documents and Settings\Dufresne\Application Data\Move Networks\QMCache00\A0C97106E5B54BA28D878F37B38B4B19000003FC00C8534009573.qss" is compressed (flags = 1)
    Read File: File "c:\Documents and Settings\Dufresne\Application Data\Move Networks\QMCache00\A0C97106E5B54BA28D878F37B38B4B19000003FE00C7A531028FB.qss" is compressed (flags = 1)
    Read File: File "c:\Documents and Settings\Dufresne\Application Data\Move Networks\QMCache00\A0C97106E5B54BA28D878F37B38B4B19000003FF00C8AF37030B8.qss" is compressed (flags = 1)
    Read File: File "c:\Documents and Settings\Dufresne\Application Data\Move Networks\QMCache00\A0C97106E5B54BA28D878F37B38B4B190000040000C825E20A621.qss" is compressed (flags = 1)
    Read File: File "c:\Documents and Settings\Dufresne\Application Data\Move Networks\QMCache00\A0C97106E5B54BA28D878F37B38B4B190000040100C8299503811.qss" is compressed (flags = 1)
    Read File: File "c:\Documents and Settings\Dufresne\Application Data\Move Networks\QMCache00\A0C97106E5B54BA28D878F37B38B4B190000040200C85711027C4.qss" is compressed (flags = 1)
    Read File: File "c:\Documents and Settings\Dufresne\Application Data\Move Networks\QMCache00\A0C97106E5B54BA28D878F37B38B4B190000040300C8141804EAA.qss" is compressed (flags = 1)
    Read File: File "c:\Documents and Settings\Dufresne\Application Data\Move Networks\QMCache00\A0C97106E5B54BA28D878F37B38B4B190000040400C8C480053C6.qss" is compressed (flags = 1)
    Read File: File "c:\Documents and Settings\Dufresne\Application Data\Move Networks\QMCache00\A0C97106E5B54BA28D878F37B38B4B190000040500C8060605450.qss" is compressed (flags = 1)
    Read File: File "c:\Documents and Settings\Dufresne\Application Data\Move Networks\QMCache00\A0C97106E5B54BA28D878F37B38B4B190000040600C7F54E052CD.qss" is compressed (flags = 1)
    Read File: File "c:\Documents and Settings\Dufresne\Application Data\Move Networks\QMCache00\A0C97106E5B54BA28D878F37B38B4B190000040800C7EFA60521E.qss" is compressed (flags = 1)
    Read File: File "c:\Documents and Settings\Dufresne\Application Data\Move Networks\QMCache00\A0C97106E5B54BA28D878F37B38B4B190000040900C8517402695.qss" is compressed (flags = 1)
    Read File: File "c:\Documents and Settings\Dufresne\Application Data\Move Networks\QMCache00\A0C97106E5B54BA28D878F37B38B4B190000040A00C844240845C.qss" is compressed (flags = 1)
    Read File: File "c:\Documents and Settings\Dufresne\Application Data\Move Networks\QMCache00\A0C97106E5B54BA28D878F37B38B4B190000040B00C846540837C.qss" is compressed (flags = 1)
     
  11. 2013/05/17
    chinaclipper

    chinaclipper Well-Known Member Thread Starter

    Joined:
    2010/01/20
    Messages:
    96
    Likes Received:
    0
    part III

    Read File: File "c:\Documents and Settings\Dufresne\Application Data\Move Networks\QMCache00\A0C97106E5B54BA28D878F37B38B4B190000040D00C83C4F05F9F.qss" is compressed (flags = 1)
    Read File: File "c:\Documents and Settings\Dufresne\Application Data\Move Networks\QMCache00\A0C97106E5B54BA28D878F37B38B4B190000040E00C823CC06021.qss" is compressed (flags = 1)
    Read File: File "c:\Documents and Settings\Dufresne\Application Data\Move Networks\QMCache00\A0C97106E5B54BA28D878F37B38B4B190000040F00C8292507088.qss" is compressed (flags = 1)
    Read File: File "c:\Documents and Settings\Dufresne\Application Data\Move Networks\QMCache00\A0C97106E5B54BA28D878F37B38B4B190000041000C852B90703B.qss" is compressed (flags = 1)
    Read File: File "c:\Documents and Settings\Dufresne\Application Data\Move Networks\QMCache00\A0C97106E5B54BA28D878F37B38B4B190000041200C8C9D409B7C.qss" is compressed (flags = 1)
    Read File: File "c:\Documents and Settings\Dufresne\Application Data\Move Networks\QMCache00\A0C97106E5B54BA28D878F37B38B4B190000041300C7737E0549D.qss" is compressed (flags = 1)
    Read File: File "c:\Documents and Settings\Dufresne\Application Data\Move Networks\QMCache00\A0C97106E5B54BA28D878F37B38B4B190000041400C80C6007290.qss" is compressed (flags = 1)
    Read File: File "c:\Documents and Settings\Dufresne\Application Data\Move Networks\QMCache00\A0C97106E5B54BA28D878F37B38B4B190000041500C8719705E92.qss" is compressed (flags = 1)
    Read File: File "c:\Documents and Settings\Dufresne\Application Data\Move Networks\QMCache00\A0C97106E5B54BA28D878F37B38B4B190000041600C2660A058EC.qss" is compressed (flags = 1)
    Read File: File "c:\Documents and Settings\Dufresne\Application Data\Move Networks\QMCache00\A0C97106E5B54BA28D878F37B38B4B190000041700C0ABCD0085B.qss" is compressed (flags = 1)
    Read File: File "c:\Documents and Settings\Dufresne\Application Data\Move Networks\QMCache00\A0C97106E5B54BA28D878F37B38B4B190000041800C7C6090085B.qss" is compressed (flags = 1)
    Read File: File "c:\Documents and Settings\Dufresne\Application Data\Move Networks\QMCache00\A0C97106E5B54BA28D878F37B38B4B190000041900C81AD8070B6.qss" is compressed (flags = 1)
    Read File: File "c:\Documents and Settings\Dufresne\Application Data\Move Networks\QMCache00\A0C97106E5B54BA28D878F37B38B4B190000041A00C7A5AA06D92.qss" is compressed (flags = 1)
    Read File: File "c:\Documents and Settings\Dufresne\Application Data\Move Networks\QMCache00\E5FE5D98E7E249DE80B3754EA2242B350000000100B5DE62006F0.qss" is compressed (flags = 1)
    Read File: File "c:\Documents and Settings\Dufresne\Application Data\Move Networks\QMCache00\E5FE5D98E7E249DE80B3754EA2242B350000000200B63C0903517.qss" is compressed (flags = 1)
    Read File: File "c:\Documents and Settings\Dufresne\Application Data\Move Networks\QMCache00\E5FE5D98E7E249DE80B3754EA2242B350000000200C733AB03EEB.qss" is compressed (flags = 1)
    Read File: File "c:\Documents and Settings\Dufresne\Application Data\Move Networks\QMCache00\E5FE5D98E7E249DE80B3754EA2242B350000000300B5B31802B7E.qss" is compressed (flags = 1)
    Read File: File "c:\Documents and Settings\Dufresne\Application Data\Move Networks\QMCache00\E5FE5D98E7E249DE80B3754EA2242B350000000300C6BAD20346E.qss" is compressed (flags = 1)
    Read File: File "c:\Documents and Settings\Dufresne\Application Data\Move Networks\QMCache00\E5FE5D98E7E249DE80B3754EA2242B350000000400B4D044020AA.qss" is compressed (flags = 1)
    Read File: File "c:\Documents and Settings\Dufresne\Application Data\Move Networks\QMCache00\E5FE5D98E7E249DE80B3754EA2242B350000000400C5AE5F02808.qss" is compressed (flags = 1)
    Read File: File "c:\Documents and Settings\Dufresne\Application Data\Move Networks\QMCache00\E5FE5D98E7E249DE80B3754EA2242B350000000500B5B4C20176C.qss" is compressed (flags = 1)
    Read File: File "c:\Documents and Settings\Dufresne\Application Data\Move Networks\QMCache00\E5FE5D98E7E249DE80B3754EA2242B350000000500C621ED01B49.qss" is compressed (flags = 1)
    Read File: File "c:\Documents and Settings\Dufresne\Application Data\Move Networks\QMCache00\E5FE5D98E7E249DE80B3754EA2242B350000000600B3059C039E1.qss" is compressed (flags = 1)
    Read File: File "c:\Documents and Settings\Dufresne\Application Data\Move Networks\QMCache00\E5FE5D98E7E249DE80B3754EA2242B350000000600C37DE404608.qss" is compressed (flags = 1)
    Read File: File "c:\Documents and Settings\Dufresne\Application Data\Move Networks\QMCache00\E5FE5D98E7E249DE80B3754EA2242B350000000700B577C503412.qss" is compressed (flags = 1)
    Read File: File "c:\Documents and Settings\Dufresne\Application Data\Move Networks\QMCache00\E5FE5D98E7E249DE80B3754EA2242B350000000700C655C903FBE.qss" is compressed (flags = 1)
    Read File: File "c:\Documents and Settings\Dufresne\Application Data\Move Networks\QMCache00\E5FE5D98E7E249DE80B3754EA2242B350000000800B3F032033CC.qss" is compressed (flags = 1)
    Read File: File "c:\Documents and Settings\Dufresne\Application Data\Move Networks\QMCache00\E5FE5D98E7E249DE80B3754EA2242B350000000800C497B903E08.qss" is compressed (flags = 1)
    Read File: File "c:\Documents and Settings\Dufresne\Application Data\Move Networks\QMCache00\A0C97106E5B54BA28D878F37B38B4B190000041C00C84A49057A6.qss" is compressed (flags = 1)
    Read File: File "c:\Documents and Settings\Dufresne\Application Data\Move Networks\QMCache00\A0C97106E5B54BA28D878F37B38B4B190000041D00C844D304A45.qss" is compressed (flags = 1)
    Read File: File "c:\Documents and Settings\Dufresne\Application Data\Move Networks\QMCache00\A0C97106E5B54BA28D878F37B38B4B190000041E00C8503607616.qss" is compressed (flags = 1)
    Read File: File "c:\Documents and Settings\Dufresne\Application Data\Move Networks\QMCache00\A0C97106E5B54BA28D878F37B38B4B190000041F00C730DC07BFA.qss" is compressed (flags = 1)
    Read File: File "c:\Documents and Settings\Dufresne\Application Data\Move Networks\QMCache00\A0C97106E5B54BA28D878F37B38B4B190000042000C7BB0C02594.qss" is compressed (flags = 1)
    Read File: File "c:\Documents and Settings\Dufresne\Application Data\Move Networks\QMCache00\A0C97106E5B54BA28D878F37B38B4B190000042100C757D605604.qss" is compressed (flags = 1)
    Read File: File "c:\Documents and Settings\Dufresne\Application Data\Move Networks\QMCache00\A0C97106E5B54BA28D878F37B38B4B190000042200C7B77F063BA.qss" is compressed (flags = 1)
    Read File: File "c:\Documents and Settings\Dufresne\Application Data\Move Networks\QMCache00\A0C97106E5B54BA28D878F37B38B4B190000042300C811F606316.qss" is compressed (flags = 1)
    Read File: File "c:\Documents and Settings\Dufresne\Application Data\Move Networks\QMCache00\A0C97106E5B54BA28D878F37B38B4B190000042400C732DB03AC3.qss" is compressed (flags = 1)
    Read File: File "c:\Documents and Settings\Dufresne\Application Data\Move Networks\QMCache00\A0C97106E5B54BA28D878F37B38B4B190000042600C75EF7095EB.qss" is compressed (flags = 1)
    Read File: File "c:\Documents and Settings\Dufresne\Application Data\Move Networks\QMCache00\A0C97106E5B54BA28D878F37B38B4B190000042700C8034C00E95.qss" is compressed (flags = 1)
    Read File: File "c:\Documents and Settings\Dufresne\Application Data\Move Networks\QMCache00\A0C97106E5B54BA28D878F37B38B4B190000042800C80F00073FD.qss" is compressed (flags = 1)
    Read File: File "c:\Documents and Settings\Dufresne\Application Data\Move Networks\QMCache00\A0C97106E5B54BA28D878F37B38B4B190000042900C5BA2708A92.qss" is compressed (flags = 1)
    Read File: File "c:\Documents and Settings\Dufresne\Application Data\Move Networks\QMCache00\A0C97106E5B54BA28D878F37B38B4B190000042A00C5F83502BFF.qss" is compressed (flags = 1)
    Read File: File "c:\Documents and Settings\Dufresne\Application Data\Move Networks\QMCache00\A0C97106E5B54BA28D878F37B38B4B190000042B00C613FB02465.qss" is compressed (flags = 1)
    Read File: File "c:\Documents and Settings\Dufresne\Application Data\Move Networks\QMCache00\A0C97106E5B54BA28D878F37B38B4B190000042C00C628AC026CA.qss" is compressed (flags = 1)
    Read File: File "c:\Documents and Settings\Dufresne\Application Data\Move Networks\QMCache00\A0C97106E5B54BA28D878F37B38B4B190000042D00C5F8A602FC8.qss" is compressed (flags = 1)
    Read File: File "c:\Documents and Settings\Dufresne\Application Data\Move Networks\QMCache00\A0C97106E5B54BA28D878F37B38B4B190000042E00C5D2BA0301D.qss" is compressed (flags = 1)
    Read File: File "c:\Documents and Settings\Dufresne\Application Data\Move Networks\QMCache00\A0C97106E5B54BA28D878F37B38B4B190000043000C5E72902D7B.qss" is compressed (flags = 1)
    Read File: File "c:\Documents and Settings\Dufresne\Application Data\Move Networks\QMCache00\A0C97106E5B54BA28D878F37B38B4B190000043100C5E53E02BF1.qss" is compressed (flags = 1)
    Read File: File "c:\Documents and Settings\Dufresne\Application Data\Move Networks\QMCache00\A0C97106E5B54BA28D878F37B38B4B190000043200C5D18C02DC0.qss" is compressed (flags = 1)
    Read File: File "c:\Documents and Settings\Dufresne\Application Data\Move Networks\QMCache00\A0C97106E5B54BA28D878F37B38B4B190000043300C5E3DC02DBF.qss" is compressed (flags = 1)
    Read File: File "c:\Documents and Settings\Dufresne\Application Data\Move Networks\QMCache00\A0C97106E5B54BA28D878F37B38B4B190000043400C5E5F802D1F.qss" is compressed (flags = 1)
    Read File: File "c:\Documents and Settings\Dufresne\Application Data\Move Networks\QMCache00\A0C97106E5B54BA28D878F37B38B4B190000043500C5E55502CCA.qss" is compressed (flags = 1)
    Read File: File "c:\Documents and Settings\Dufresne\Application Data\Move Networks\QMCache00\A0C97106E5B54BA28D878F37B38B4B190000043600C6012C02D68.qss" is compressed (flags = 1)
    Read File: File "c:\Documents and Settings\Dufresne\Application Data\Move Networks\QMCache00\A0C97106E5B54BA28D878F37B38B4B190000043700C5E63C02D71.qss" is compressed (flags = 1)
    Read File: File "c:\Documents and Settings\Dufresne\Application Data\Move Networks\QMCache00\A0C97106E5B54BA28D878F37B38B4B190000043800C68BD301A1E.qss" is compressed (flags = 1)
    Read File: File "c:\Documents and Settings\Dufresne\Application Data\Move Networks\QMCache00\A0C97106E5B54BA28D878F37B38B4B19000003FD00C8335605F91.qss" is compressed (flags = 1)
    Read File: File "c:\Documents and Settings\Dufresne\Application Data\Move Networks\QMCache00\A0C97106E5B54BA28D878F37B38B4B190000046100C5E1DD01D9C.qss" is compressed (flags = 1)
    Read File: File "c:\Documents and Settings\Dufresne\Application Data\Move Networks\QMCache00\A0C97106E5B54BA28D878F37B38B4B19000004C700C8A812055DE.qss" is compressed (flags = 1)
    Read File: File "c:\Documents and Settings\Dufresne\Application Data\Move Networks\QMCache00\A0C97106E5B54BA28D878F37B38B4B190000043A00C683D302BB2.qss" is compressed (flags = 1)
    Read File: File "c:\Documents and Settings\Dufresne\Application Data\Move Networks\QMCache00\A0C97106E5B54BA28D878F37B38B4B190000043B00C681C302B16.qss" is compressed (flags = 1)
    Read File: File "c:\Documents and Settings\Dufresne\Application Data\Move Networks\QMCache00\A0C97106E5B54BA28D878F37B38B4B190000043C00C688F302A2B.qss" is compressed (flags = 1)
    Read File: File "c:\Documents and Settings\Dufresne\Application Data\Move Networks\QMCache00\A0C97106E5B54BA28D878F37B38B4B190000043D00C6841102881.qss" is compressed (flags = 1)
    Read File: File "c:\Documents and Settings\Dufresne\Application Data\Move Networks\QMCache00\A0C97106E5B54BA28D878F37B38B4B190000043E00C5FFA7029FC.qss" is compressed (flags = 1)
    Read File: File "c:\Documents and Settings\Dufresne\Application Data\Move Networks\QMCache00\A0C97106E5B54BA28D878F37B38B4B190000043F00C5F4E402615.qss" is compressed (flags = 1)
    Read File: File "c:\Documents and Settings\Dufresne\Application Data\Move Networks\QMCache00\A0C97106E5B54BA28D878F37B38B4B190000044000C5E5BF02446.qss" is compressed (flags = 1)
    Read File: File "c:\Documents and Settings\Dufresne\Application Data\Move Networks\QMCache00\A0C97106E5B54BA28D878F37B38B4B190000044100C5EFA402727.qss" is compressed (flags = 1)
    Read File: File "c:\Documents and Settings\Dufresne\Application Data\Move Networks\QMCache00\A0C97106E5B54BA28D878F37B38B4B190000044200C5DD940264B.qss" is compressed (flags = 1)
    Read File: File "c:\Documents and Settings\Dufresne\Application Data\Move Networks\QMCache00\A0C97106E5B54BA28D878F37B38B4B190000044400C6A69A02FC8.qss" is compressed (flags = 1)
    Read File: File "c:\Documents and Settings\Dufresne\Application Data\Move Networks\QMCache00\A0C97106E5B54BA28D878F37B38B4B190000044500C693FD02D22.qss" is compressed (flags = 1)
    Read File: File "c:\Documents and Settings\Dufresne\Application Data\Move Networks\QMCache00\A0C97106E5B54BA28D878F37B38B4B190000044600C6CA0D02E6C.qss" is compressed (flags = 1)
    Read File: File "c:\Documents and Settings\Dufresne\Application Data\Move Networks\QMCache00\A0C97106E5B54BA28D878F37B38B4B190000044700C5EFBF02DD7.qss" is compressed (flags = 1)
    Read File: File "c:\Documents and Settings\Dufresne\Application Data\Move Networks\QMCache00\A0C97106E5B54BA28D878F37B38B4B190000044800C5E3CA02185.qss" is compressed (flags = 1)
    Read File: File "c:\Documents and Settings\Dufresne\Application Data\Move Networks\QMCache00\A0C97106E5B54BA28D878F37B38B4B190000044900C5F3D802441.qss" is compressed (flags = 1)
    Read File: File "c:\Documents and Settings\Dufresne\Application Data\Move Networks\QMCache00\A0C97106E5B54BA28D878F37B38B4B190000044A00C5E6A10240F.qss" is compressed (flags = 1)
    Read File: File "c:\Documents and Settings\Dufresne\Application Data\Move Networks\QMCache00\A0C97106E5B54BA28D878F37B38B4B190000044B00C5ED3E02539.qss" is compressed (flags = 1)
    Read File: File "c:\Documents and Settings\Dufresne\Application Data\Move Networks\QMCache00\A0C97106E5B54BA28D878F37B38B4B190000044C00C5E6500255F.qss" is compressed (flags = 1)
    Read File: File "c:\Documents and Settings\Dufresne\Application Data\Move Networks\QMCache00\A0C97106E5B54BA28D878F37B38B4B190000045800C5FDA502D2C.qss" is compressed (flags = 1)
    Read File: File "c:\Documents and Settings\Dufresne\Application Data\Move Networks\QMCache00\A0C97106E5B54BA28D878F37B38B4B190000045900C61ED702DF8.qss" is compressed (flags = 1)
    Read File: File "c:\Documents and Settings\Dufresne\Application Data\Move Networks\QMCache00\A0C97106E5B54BA28D878F37B38B4B190000045A00C63B9A02C2B.qss" is compressed (flags = 1)
    Read File: File "c:\Documents and Settings\Dufresne\Application Data\Move Networks\QMCache00\A0C97106E5B54BA28D878F37B38B4B190000045B00C669E10328E.qss" is compressed (flags = 1)
    Read File: File "c:\Documents and Settings\Dufresne\Application Data\Move Networks\QMCache00\A0C97106E5B54BA28D878F37B38B4B190000045C00C62BF5030DE.qss" is compressed (flags = 1)
    Read File: File "c:\Documents and Settings\Dufresne\Application Data\Move Networks\QMCache00\A0C97106E5B54BA28D878F37B38B4B190000045D00C67DBF02066.qss" is compressed (flags = 1)
    Read File: File "c:\Documents and Settings\Dufresne\Application Data\Move Networks\QMCache00\A0C97106E5B54BA28D878F37B38B4B190000045E00C66D43032F7.qss" is compressed (flags = 1)
    Read File: File "c:\Documents and Settings\Dufresne\Application Data\Move Networks\QMCache00\A0C97106E5B54BA28D878F37B38B4B190000045F00C66B6603203.qss" is compressed (flags = 1)
    Read File: File "c:\Documents and Settings\Dufresne\Application Data\Move Networks\QMCache00\A0C97106E5B54BA28D878F37B38B4B190000046000C655DF0304E.qss" is compressed (flags = 1)
    Read File: File "c:\Documents and Settings\Dufresne\Application Data\Move Networks\QMCache00\A0C97106E5B54BA28D878F37B38B4B190000047600C6D94A04E78.qss" is compressed (flags = 1)
    Read File: File "c:\Documents and Settings\Dufresne\Application Data\Move Networks\QMCache00\A0C97106E5B54BA28D878F37B38B4B190000047700C8241C05A30.qss" is compressed (flags = 1)
    Read File: File "c:\Documents and Settings\Dufresne\Application Data\Move Networks\QMCache00\A0C97106E5B54BA28D878F37B38B4B190000047800C758C904B7D.qss" is compressed (flags = 1)
    Read File: File "c:\Documents and Settings\Dufresne\Application Data\Move Networks\QMCache00\A0C97106E5B54BA28D878F37B38B4B190000047900C7BB5E04637.qss" is compressed (flags = 1)
    Read File: File "c:\Documents and Settings\Dufresne\Application Data\Move Networks\QMCache00\A0C97106E5B54BA28D878F37B38B4B190000047A00C795D605432.qss" is compressed (flags = 1)
    Read File: File "c:\Documents and Settings\Dufresne\Application Data\Move Networks\QMCache00\A0C97106E5B54BA28D878F37B38B4B190000047B00C7515A0482D.qss" is compressed (flags = 1)
    Read File: File "c:\Documents and Settings\Dufresne\Application Data\Move Networks\QMCache00\A0C97106E5B54BA28D878F37B38B4B190000047C00C787EC03C11.qss" is compressed (flags = 1)
    Read File: File "c:\Documents and Settings\Dufresne\Application Data\Move Networks\QMCache00\A0C97106E5B54BA28D878F37B38B4B190000047D00C7CB2E0605C.qss" is compressed (flags = 1)
    Read File: File "c:\Documents and Settings\Dufresne\Application Data\Move Networks\QMCache00\A0C97106E5B54BA28D878F37B38B4B190000047E00C6C40905FE9.qss" is compressed (flags = 1)
    Read File: File "c:\Documents and Settings\Dufresne\Application Data\Move Networks\QMCache00\A0C97106E5B54BA28D878F37B38B4B190000048000C6D1EC06D2F.qss" is compressed (flags = 1)
    Read File: File "c:\Documents and Settings\Dufresne\Application Data\Move Networks\QMCache00\A0C97106E5B54BA28D878F37B38B4B190000048100C8000D037EB.qss" is compressed (flags = 1)
    Read File: File "c:\Documents and Settings\Dufresne\Application Data\Move Networks\QMCache00\A0C97106E5B54BA28D878F37B38B4B190000048200C7151806C22.qss" is compressed (flags = 1)
    Read File: File "c:\Documents and Settings\Dufresne\Application Data\Move Networks\QMCache00\A0C97106E5B54BA28D878F37B38B4B190000048300C7871303DDF.qss" is compressed (flags = 1)
    Read File: File "c:\Documents and Settings\Dufresne\Application Data\Move Networks\QMCache00\A0C97106E5B54BA28D878F37B38B4B190000048400C6F5C507A6E.qss" is compressed (flags = 1)
    Read File: File "c:\Documents and Settings\Dufresne\Application Data\Move Networks\QMCache00\A0C97106E5B54BA28D878F37B38B4B190000048500C7D043036C5.qss" is compressed (flags = 1)
    Read File: File "c:\Documents and Settings\Dufresne\Application Data\Move Networks\QMCache00\A0C97106E5B54BA28D878F37B38B4B190000048600C7DB9F07096.qss" is compressed (flags = 1)
    Read File: File "c:\Documents and Settings\Dufresne\Application Data\Move Networks\QMCache00\A0C97106E5B54BA28D878F37B38B4B190000048700C79DA806D59.qss" is compressed (flags = 1)
    Read File: File "c:\Documents and Settings\Dufresne\Application Data\Move Networks\QMCache00\A0C97106E5B54BA28D878F37B38B4B190000048800C767D8063DA.qss" is compressed (flags = 1)
    Read File: File "c:\Documents and Settings\Dufresne\Application Data\Move Networks\QMCache00\A0C97106E5B54BA28D878F37B38B4B190000049E00C73F43040B5.qss" is compressed (flags = 1)
    Read File: File "c:\Documents and Settings\Dufresne\Application Data\Move Networks\QMCache00\A0C97106E5B54BA28D878F37B38B4B190000049F00C7A73D02DFE.qss" is compressed (flags = 1)
    Read File: File "c:\Documents and Settings\Dufresne\Application Data\Move Networks\QMCache00\A0C97106E5B54BA28D878F37B38B4B19000004A000C7BBF705926.qss" is compressed (flags = 1)
    Read File: File "c:\Documents and Settings\Dufresne\Application Data\Move Networks\QMCache00\A0C97106E5B54BA28D878F37B38B4B19000004A100C7BFA00594C.qss" is compressed (flags = 1)
    Read File: File "c:\Documents and Settings\Dufresne\Application Data\Move Networks\QMCache00\A0C97106E5B54BA28D878F37B38B4B19000004A200C721BC05184.qss" is compressed (flags = 1)
    Read File: File "c:\Documents and Settings\Dufresne\Application Data\Move Networks\QMCache00\A0C97106E5B54BA28D878F37B38B4B19000004A300C8E255017A3.qss" is compressed (flags = 1)
    Read File: File "c:\Documents and Settings\Dufresne\Application Data\Move Networks\QMCache00\A0C97106E5B54BA28D878F37B38B4B19000004A400C89CBA0CACF.qss" is compressed (flags = 1)
    Read File: File "c:\Documents and Settings\Dufresne\Application Data\Move Networks\QMCache00\A0C97106E5B54BA28D878F37B38B4B19000004A500C7D8EB054DB.qss" is compressed (flags = 1)
    Read File: File "c:\Documents and Settings\Dufresne\Application Data\Move Networks\QMCache00\A0C97106E5B54BA28D878F37B38B4B19000004A600C7938A0599E.qss" is compressed (flags = 1)
    Read File: File "c:\Documents and Settings\Dufresne\Application Data\Move Networks\QMCache00\E30E776DE3C9447CBBE9CEB8A7AC0FE7000000010094B1BF003CD.qss" is compressed (flags = 1)
    Read File: File "c:\Documents and Settings\Dufresne\Application Data\Move Networks\QMCache00\E30E776DE3C9447CBBE9CEB8A7AC0FE70000000200947781039A1.qss" is compressed (flags = 1)
    Read File: File "c:\Documents and Settings\Dufresne\Application Data\Move Networks\QMCache00\E30E776DE3C9447CBBE9CEB8A7AC0FE7000000030093A88C02DFD.qss" is compressed (flags = 1)
    Read File: File "c:\Documents and Settings\Dufresne\Application Data\Move Networks\QMCache00\E30E776DE3C9447CBBE9CEB8A7AC0FE7000000040094C3A1029A8.qss" is compressed (flags = 1)
    Read File: File "c:\Documents and Settings\Dufresne\Application Data\Move Networks\QMCache00\E30E776DE3C9447CBBE9CEB8A7AC0FE7000000050094539403959.qss" is compressed (flags = 1)
    Read File: File "c:\Documents and Settings\Dufresne\Application Data\Move Networks\QMCache00\E30E776DE3C9447CBBE9CEB8A7AC0FE70000000600955F7701460.qss" is compressed (flags = 1)
    Read File: File "c:\Documents and Settings\Dufresne\Application Data\Move Networks\QMCache00\E30E776DE3C9447CBBE9CEB8A7AC0FE70000000700955176017A3.qss" is compressed (flags = 1)
    Read File: File "c:\Documents and Settings\Dufresne\Application Data\Move Networks\QMCache00\A0C97106E5B54BA28D878F37B38B4B190000048A00C780B8057E6.qss" is compressed (flags = 1)
    Read File: File "c:\Documents and Settings\Dufresne\Application Data\Move Networks\QMCache00\A0C97106E5B54BA28D878F37B38B4B190000048B00C8AA3E038B6.qss" is compressed (flags = 1)
    Read File: File "c:\Documents and Settings\Dufresne\Application Data\Move Networks\QMCache00\A0C97106E5B54BA28D878F37B38B4B190000048C00C82461085C7.qss" is compressed (flags = 1)
    Read File: File "c:\Documents and Settings\Dufresne\Application Data\Move Networks\QMCache00\A0C97106E5B54BA28D878F37B38B4B190000048D00C82C9606FD6.qss" is compressed (flags = 1)
    Read File: File "c:\Documents and Settings\Dufresne\Application Data\Move Networks\QMCache00\A0C97106E5B54BA28D878F37B38B4B190000048E00C7F2BA06891.qss" is compressed (flags = 1)
    Read File: File "c:\Documents and Settings\Dufresne\Application Data\Move Networks\QMCache00\A0C97106E5B54BA28D878F37B38B4B190000048F00C7ADB1070AD.qss" is compressed (flags = 1)
    Read File: File "c:\Documents and Settings\Dufresne\Application Data\Move Networks\QMCache00\A0C97106E5B54BA28D878F37B38B4B190000049000C866E305274.qss" is compressed (flags = 1)
    Read File: File "c:\Documents and Settings\Dufresne\Application Data\Move Networks\QMCache00\A0C97106E5B54BA28D878F37B38B4B190000049100C81D1604D50.qss" is compressed (flags = 1)
    Read File: File "c:\Documents and Settings\Dufresne\Application Data\Move Networks\QMCache00\A0C97106E5B54BA28D878F37B38B4B190000049200C7694F0582A.qss" is compressed (flags = 1)
    Read File: File "c:\Documents and Settings\Dufresne\Application Data\Move Networks\QMCache00\A0C97106E5B54BA28D878F37B38B4B190000046B00C8F2DB0B65A.qss" is compressed (flags = 1)
    Read File: File "c:\Documents and Settings\Dufresne\Application Data\Move Networks\QMCache00\A0C97106E5B54BA28D878F37B38B4B190000047500C796F90601A.qss" is compressed (flags = 1)
    Read File: File "c:\Documents and Settings\Dufresne\Application Data\Move Networks\QMCache00\A0C97106E5B54BA28D878F37B38B4B190000047F00C7CD81037DD.qss" is compressed (flags = 1)
    Read File: File "c:\Documents and Settings\Dufresne\Application Data\Move Networks\QMCache00\A0C97106E5B54BA28D878F37B38B4B190000048900C734B705D97.qss" is compressed (flags = 1)
    Read File: File "c:\Documents and Settings\Dufresne\Application Data\Move Networks\QMCache00\A0C97106E5B54BA28D878F37B38B4B190000049300C8BA9608EE9.qss" is compressed (flags = 1)
    Read File: File "c:\Documents and Settings\Dufresne\Application Data\Move Networks\QMCache00\A0C97106E5B54BA28D878F37B38B4B190000049D00C6FDD504E76.qss" is compressed (flags = 1)
    Read File: File "c:\Documents and Settings\Dufresne\Application Data\Move Networks\QMCache00\A0C97106E5B54BA28D878F37B38B4B19000004A700C7967B05326.qss" is compressed (flags = 1)
    Read File: File "c:\Documents and Settings\Dufresne\Application Data\Move Networks\QMCache00\A0C97106E5B54BA28D878F37B38B4B19000004B100C778660474B.qss" is compressed (flags = 1)
    Read File: File "c:\Documents and Settings\Dufresne\Application Data\Move Networks\QMCache00\A0C97106E5B54BA28D878F37B38B4B19000004BD00C7D74A0546C.qss" is compressed (flags = 1)
    Read File: File "c:\Documents and Settings\Dufresne\Application Data\Move Networks\QMCache00\A0C97106E5B54BA28D878F37B38B4B19000004A800C799C0052C3.qss" is compressed (flags = 1)
    Read File: File "c:\Documents and Settings\Dufresne\Application Data\Move Networks\QMCache00\A0C97106E5B54BA28D878F37B38B4B19000004A900C7D403059A4.qss" is compressed (flags = 1)
    Read File: File "c:\Documents and Settings\Dufresne\Application Data\Move Networks\QMCache00\A0C97106E5B54BA28D878F37B38B4B19000004AA00C7F45905A1D.qss" is compressed (flags = 1)
    Read File: File "c:\Documents and Settings\Dufresne\Application Data\Move Networks\QMCache00\A0C97106E5B54BA28D878F37B38B4B19000004AB00C7AF4605CEA.qss" is compressed (flags = 1)
    Read File: File "c:\Documents and Settings\Dufresne\Application Data\Move Networks\QMCache00\A0C97106E5B54BA28D878F37B38B4B19000004AC00C7A3C004C51.qss" is compressed (flags = 1)
    Read File: File "c:\Documents and Settings\Dufresne\Application Data\Move Networks\QMCache00\A0C97106E5B54BA28D878F37B38B4B19000004AD00C75CC604BD8.qss" is compressed (flags = 1)
    Read File: File "c:\Documents and Settings\Dufresne\Application Data\Move Networks\QMCache00\A0C97106E5B54BA28D878F37B38B4B19000004AE00C799A6058CF.qss" is compressed (flags = 1)
    Read File: File "c:\Documents and Settings\Dufresne\Application Data\Move Networks\QMCache00\A0C97106E5B54BA28D878F37B38B4B19000004AF00C7916805934.qss" is compressed (flags = 1)
    Read File: File "c:\Documents and Settings\Dufresne\Application Data\Move Networks\QMCache00\A0C97106E5B54BA28D878F37B38B4B19000004B000C7EEA205127.qss" is compressed (flags = 1)
    Read File: File "c:\Documents and Settings\Dufresne\Application Data\Move Networks\QMCache00\A0C97106E5B54BA28D878F37B38B4B19000004FA00C6A45C045F3.qss" is compressed (flags = 1)
    Read File: File "c:\Documents and Settings\Dufresne\Application Data\Move Networks\QMCache00\A0C97106E5B54BA28D878F37B38B4B19000004FB00C6A47504554.qss" is compressed (flags = 1)
    Read File: File "c:\Documents and Settings\Dufresne\Application Data\Move Networks\QMCache00\A0C97106E5B54BA28D878F37B38B4B19000004FC00C69EC204471.qss" is compressed (flags = 1)
    Read File: File "c:\Documents and Settings\Dufresne\Application Data\Move Networks\QMCache00\A0C97106E5B54BA28D878F37B38B4B19000004FD00C6AE450427D.qss" is compressed (flags = 1)
    Read File: File "c:\Documents and Settings\Dufresne\Application Data\Move Networks\QMCache00\A0C97106E5B54BA28D878F37B38B4B19000004FE00C6A27704367.qss" is compressed (flags = 1)
    Read File: File "c:\Documents and Settings\Dufresne\Application Data\Move Networks\QMCache00\A0C97106E5B54BA28D878F37B38B4B19000004FF00C6C96E043D9.qss" is compressed (flags = 1)
    Read File: File "c:\Documents and Settings\Dufresne\Application Data\Move Networks\QMCache00\A0C97106E5B54BA28D878F37B38B4B190000050000C6E1CB042E5.qss" is compressed (flags = 1)
    Read File: File "c:\Documents and Settings\Dufresne\Application Data\Move Networks\QMCache00\A0C97106E5B54BA28D878F37B38B4B190000050100C6AC68045BF.qss" is compressed (flags = 1)
    Read File: File "c:\Documents and Settings\Dufresne\Application Data\Move Networks\QMCache00\A0C97106E5B54BA28D878F37B38B4B190000050200C6B0A404340.qss" is compressed (flags = 1)
    Read File: File "c:\Documents and Settings\Dufresne\Application Data\Move Networks\QMCache00\A0C97106E5B54BA28D878F37B38B4B190000050400C6B31B04287.qss" is compressed (flags = 1)
    Read File: File "c:\Documents and Settings\Dufresne\Application Data\Move Networks\QMCache00\A0C97106E5B54BA28D878F37B38B4B190000050500C6D7150400C.qss" is compressed (flags = 1)
    Read File: File "c:\Documents and Settings\Dufresne\Application Data\Move Networks\QMCache00\A0C97106E5B54BA28D878F37B38B4B190000050600C6D58E040AA.qss" is compressed (flags = 1)
    Read File: File "c:\Documents and Settings\Dufresne\Application Data\Move Networks\QMCache00\A0C97106E5B54BA28D878F37B38B4B190000050700C6C18804165.qss" is compressed (flags = 1)
    Read File: File "c:\Documents and Settings\Dufresne\Application Data\Move Networks\QMCache00\A0C97106E5B54BA28D878F37B38B4B190000050800C6923004452.qss" is compressed (flags = 1)
    Read File: File "c:\Documents and Settings\Dufresne\Application Data\Move Networks\QMCache00\A0C97106E5B54BA28D878F37B38B4B190000050900C694B704453.qss" is compressed (flags = 1)
    Read File: File "c:\Documents and Settings\Dufresne\Application Data\Move Networks\QMCache00\A0C97106E5B54BA28D878F37B38B4B190000050A00C6DC9A0437B.qss" is compressed (flags = 1)
    Read File: File "c:\Documents and Settings\Dufresne\Application Data\Move Networks\QMCache00\A0C97106E5B54BA28D878F37B38B4B190000050B00C655F2040B9.qss" is compressed (flags = 1)
    Read File: File "c:\Documents and Settings\Dufresne\Application Data\Move Networks\QMCache00\A0C97106E5B54BA28D878F37B38B4B190000050C00C6369F035C0.qss" is compressed (flags = 1)
    Read File: File "c:\Documents and Settings\Dufresne\Application Data\Move Networks\QMCache00\A0C97106E5B54BA28D878F37B38B4B190000040700C80E880532B.qss" is compressed (flags = 1)
    Read File: File "c:\Documents and Settings\Dufresne\Application Data\Move Networks\QMCache00\A0C97106E5B54BA28D878F37B38B4B190000041100C8C34E03FAC.qss" is compressed (flags = 1)
    Read File: File "c:\Documents and Settings\Dufresne\Application Data\Move Networks\QMCache00\A0C97106E5B54BA28D878F37B38B4B190000041B00C77992077C1.qss" is compressed (flags = 1)
    Read File: File "c:\Documents and Settings\Dufresne\Application Data\Move Networks\QMCache00\A0C97106E5B54BA28D878F37B38B4B190000042500C6C660045AE.qss" is compressed (flags = 1)
    Read File: File "c:\Documents and Settings\Dufresne\Application Data\Move Networks\QMCache00\A0C97106E5B54BA28D878F37B38B4B190000042F00C5E19B02F92.qss" is compressed (flags = 1)
    Read File: File "c:\Documents and Settings\Dufresne\Application Data\Move Networks\QMCache00\A0C97106E5B54BA28D878F37B38B4B190000043900C6806002BA9.qss" is compressed (flags = 1)
    Read File: File "c:\Documents and Settings\Dufresne\Application Data\Move Networks\QMCache00\A0C97106E5B54BA28D878F37B38B4B190000044300C62C1002252.qss" is compressed (flags = 1)
    Read File: File "c:\Documents and Settings\Dufresne\Application Data\Move Networks\QMCache00\A0C97106E5B54BA28D878F37B38B4B190000044D00C5E96B026B5.qss" is compressed (flags = 1)
    Read File: File "c:\Documents and Settings\Dufresne\Application Data\Move Networks\QMCache00\A0C97106E5B54BA28D878F37B38B4B190000045700C617010319F.qss" is compressed (flags = 1)
    Read File: File "c:\Documents and Settings\Dufresne\Application Data\Move Networks\QMCache00\A0C97106E5B54BA28D878F37B38B4B19000004D100C74A9906546.qss" is compressed (flags = 1)
    Read File: File "c:\Documents and Settings\Dufresne\Application Data\Move Networks\QMCache00\A0C97106E5B54BA28D878F37B38B4B19000004DB00C6716C032BF.qss" is compressed (flags = 1)
    Read File: File "c:\Documents and Settings\Dufresne\Application Data\Move Networks\QMCache00\A0C97106E5B54BA28D878F37B38B4B19000004E500C8024207238.qss" is compressed (flags = 1)
    Read File: File "c:\Documents and Settings\Dufresne\Application Data\Move Networks\QMCache00\A0C97106E5B54BA28D878F37B38B4B19000004EF00C6F409045E1.qss" is compressed (flags = 1)
    Read File: File "c:\Documents and Settings\Dufresne\Application Data\Move Networks\QMCache00\A0C97106E5B54BA28D878F37B38B4B19000004F900C6BE60043E5.qss" is compressed (flags = 1)
    Read File: File "c:\Documents and Settings\Dufresne\Application Data\Move Networks\QMCache00\A0C97106E5B54BA28D878F37B38B4B190000050300C6C716042EF.qss" is compressed (flags = 1)
    Read File: File "c:\Documents and Settings\Dufresne\Application Data\Move Networks\QMCache00\A0C97106E5B54BA28D878F37B38B4B190000050D00C645E703546.qss" is compressed (flags = 1)
    Read File: File "c:\Documents and Settings\Dufresne\Application Data\Move Networks\QMCache00\A0C97106E5B54BA28D878F37B38B4B190000051700C174690482F.qss" is compressed (flags = 1)
    Read File: File "c:\Documents and Settings\Dufresne\Application Data\Move Networks\QMCache00\E30E776DE3C9447CBBE9CEB8A7AC0FE7000000080094EBC003191.qss" is compressed (flags = 1)
    Read File: File "c:\Documents and Settings\Dufresne\Application Data\Move Networks\QMCache00\A0C97106E5B54BA28D878F37B38B4B190000044E00C5EADC02789.qss" is compressed (flags = 1)
    Read File: File "c:\Documents and Settings\Dufresne\Application Data\Move Networks\QMCache00\A0C97106E5B54BA28D878F37B38B4B190000044F00C643DD0277A.qss" is compressed (flags = 1)
    Read File: File "c:\Documents and Settings\Dufresne\Application Data\Move Networks\QMCache00\A0C97106E5B54BA28D878F37B38B4B190000045000C5E885028FA.qss" is compressed (flags = 1)
    Read File: File "c:\Documents and Settings\Dufresne\Application Data\Move Networks\QMCache00\A0C97106E5B54BA28D878F37B38B4B190000045100C73E1006155.qss" is compressed (flags = 1)
    Read File: File "c:\Documents and Settings\Dufresne\Application Data\Move Networks\QMCache00\A0C97106E5B54BA28D878F37B38B4B190000045200C6CC6603B2C.qss" is compressed (flags = 1)
    Read File: File "c:\Documents and Settings\Dufresne\Application Data\Move Networks\QMCache00\A0C97106E5B54BA28D878F37B38B4B190000045300C6C79D027C3.qss" is compressed (flags = 1)
    Read File: File "c:\Documents and Settings\Dufresne\Application Data\Move Networks\QMCache00\A0C97106E5B54BA28D878F37B38B4B190000045400C62F3F02FAB.qss" is compressed (flags = 1)
    Read File: File "c:\Documents and Settings\Dufresne\Application Data\Move Networks\QMCache00\A0C97106E5B54BA28D878F37B38B4B190000045500C63E2902392.qss" is compressed (flags = 1)
    Read File: File "c:\Documents and Settings\Dufresne\Application Data\Move Networks\QMCache00\A0C97106E5B54BA28D878F37B38B4B190000045600C5F75702B61.qss" is compressed (flags = 1)
    Read File: File "c:\Documents and Settings\Dufresne\Application Data\Move Networks\QMCache00\A0C97106E5B54BA28D878F37B38B4B190000051800C166F302C40.qss" is compressed (flags = 1)
    Read File: File "c:\Documents and Settings\Dufresne\Application Data\Move Networks\QMCache00\A0C97106E5B54BA28D878F37B38B4B190000051900C15DCB047EC.qss" is compressed (flags = 1)
    Read File: File "c:\Documents and Settings\Dufresne\Application Data\Move Networks\QMCache00\A0C97106E5B54BA28D878F37B38B4B190000051A00C10A1802589.qss" is compressed (flags = 1)
    Read File: File "c:\Documents and Settings\Dufresne\Application Data\Move Networks\QMCache00\A0C97106E5B54BA28D878F37B38B4B190000051B00C1BED50192D.qss" is compressed (flags = 1)
    Read File: File "c:\Documents and Settings\Dufresne\Application Data\Move Networks\QMCache00\A0C97106E5B54BA28D878F37B38B4B190000051C00C27F790889D.qss" is compressed (flags = 1)
    Read File: File "c:\Documents and Settings\Dufresne\Application Data\Move Networks\QMCache00\A0C97106E5B54BA28D878F37B38B4B190000051D00C212D605543.qss" is compressed (flags = 1)
    Read File: File "c:\Documents and Settings\Dufresne\Application Data\Move Networks\QMCache00\A0C97106E5B54BA28D878F37B38B4B190000051E00C24FEC06E62.qss" is compressed (flags = 1)
    Read File: File "c:\Documents and Settings\Dufresne\Application Data\Move Networks\QMCache00\A0C97106E5B54BA28D878F37B38B4B190000051F00C243E307378.qss" is compressed (flags = 1)
    Read File: File "c:\Documents and Settings\Dufresne\Application Data\Move Networks\QMCache00\A0C97106E5B54BA28D878F37B38B4B190000052000C21BCA06904.qss" is compressed (flags = 1)
    Read File: File "c:\Documents and Settings\Dufresne\Application Data\Move Networks\QMCache00\A0C97106E5B54BA28D878F37B38B4B190000052100C2C8C60BE6A.qss" is compressed (flags = 1)
    Read File: File "c:\Documents and Settings\Dufresne\Application Data\Move Networks\QMCache00\A0C97106E5B54BA28D878F37B38B4B190000052200C16FE605AEA.qss" is compressed (flags = 1)
    Read File: File "c:\Documents and Settings\Dufresne\Application Data\Move Networks\QMCache00\A0C97106E5B54BA28D878F37B38B4B190000052300C16E7B05AEA.qss" is compressed (flags = 1)
    Read File: File "c:\Documents and Settings\Dufresne\Application Data\Move Networks\QMCache00\A0C97106E5B54BA28D878F37B38B4B190000052400C7356106D7D.qss" is compressed (flags = 1)
    Read File: File "c:\Documents and Settings\Dufresne\Application Data\Move Networks\QMCache00\A0C97106E5B54BA28D878F37B38B4B190000052500C4D3D2045D6.qss" is compressed (flags = 1)
    Read File: File "c:\Documents and Settings\Dufresne\Application Data\Move Networks\QMCache00\A0C97106E5B54BA28D878F37B38B4B190000052600C76B4C00CFC.qss" is compressed (flags = 1)
    Read File: File "c:\Documents and Settings\Dufresne\Application Data\Move Networks\QMCache00\A0C97106E5B54BA28D878F37B38B4B190000052700C074050085B.qss" is compressed (flags = 1)
     
  12. 2013/05/17
    chinaclipper

    chinaclipper Well-Known Member Thread Starter

    Joined:
    2010/01/20
    Messages:
    96
    Likes Received:
    0
    Part IV

    Read File: File "c:\Documents and Settings\Dufresne\Application Data\Mozilla\Firefox\pluginreg.dat" is compressed (flags = 1)
    Read File: File "c:\Documents and Settings\Dufresne\Application Data\pdf995\temp.ps" is compressed (flags = 1)
    Read File: File "c:\Documents and Settings\Dufresne\Application Data\Power Sound Editor Free\Favorite7.8.5.dat" is compressed (flags = 1)
    Read File: File "c:\Documents and Settings\Dufresne\Application Data\Power Sound Editor Free\MRUList.dat" is compressed (flags = 1)
    Read File: File "c:\Documents and Settings\Dufresne\Application Data\Power Sound Editor Free\Shortcut7.8.5.dat" is compressed (flags = 1)
    Read File: File "c:\Documents and Settings\Dufresne\Application Data\Power Sound Editor Free\system.dat" is compressed (flags = 1)
    Read File: File "c:\Documents and Settings\Dufresne\Application Data\Real\RealMediaSDK\c0a80100.txt" is compressed (flags = 1)
    Read File: File "c:\Documents and Settings\Dufresne\Application Data\Real\Update\Update-log.txt" is compressed (flags = 1)
    Read File: File "c:\Documents and Settings\Dufresne\Application Data\Roxio\CDDB\cddb.db" is compressed (flags = 1)
    Read File: File "c:\Documents and Settings\Dufresne\Application Data\Roxio\Sidewinder\Sidewinder.log" is compressed (flags = 1)
    Read File: File "c:\Documents and Settings\Dufresne\Application Data\Droppix\Droppix Recorder\DxLM.log" is compressed (flags = 1)
    Read File: File "c:\Documents and Settings\Dufresne\Application Data\dvdcss\$1.anv" is compressed (flags = 1)
    Read File: File "c:\Documents and Settings\Dufresne\Application Data\dvdcss\CACHEDIR.TAG" is compressed (flags = 1)
    Read File: File "c:\Documents and Settings\Dufresne\Application Data\FileZilla\queue.sqlite3" is compressed (flags = 1)
    Read File: File "c:\Documents and Settings\Dufresne\Application Data\GARMIN\Maps\79de0af9-afe6-4b8b-9a76-181dd2b2d140.gma" is compressed (flags = 1)
    Read File: File "c:\Documents and Settings\Dufresne\Application Data\ImgBurn\Graph Data Files\CDWRITER_IDE5224_S028_SATURDAY-AUGUST-21-2010_17-16_97m15s17f_MAX.ibg" is compressed (flags = 1)
    Read File: File "c:\Documents and Settings\Dufresne\Application Data\ImgBurn\Graph Data Files\TSSTcorp_CD-DVDW_SH-S162L_TS05_SATURDAY-AUGUST-21-2010_17-28_97m15s17f_MAX.ibg" is compressed (flags = 1)
    Read File: File "c:\Documents and Settings\Dufresne\Application Data\SmartDraw\accent.tlx" is compressed (flags = 1)
    Read File: File "c:\Documents and Settings\Dufresne\Application Data\SmartDraw\correct.tlx" is compressed (flags = 1)
    Read File: File "c:\Documents and Settings\Dufresne\Application Data\SmartDraw\html.tlx" is compressed (flags = 1)
    Read File: File "c:\Documents and Settings\Dufresne\Application Data\SmartDraw\SMARTD8.OPT" is compressed (flags = 1)
    Read File: File "c:\Documents and Settings\Dufresne\Application Data\SmartDraw\tech.tlx" is compressed (flags = 1)
    Read File: File "c:\Documents and Settings\Dufresne\Application Data\SmartDraw\userdic.tlx" is compressed (flags = 1)
    Read File: File "c:\Documents and Settings\Dufresne\Application Data\Sony Corporation\SonicStage\appimport.log" is compressed (flags = 1)
    Read File: File "c:\Documents and Settings\Dufresne\Application Data\Sony Corporation\SonicStage\SonicStage.log" is compressed (flags = 1)
    Read File: File "c:\Documents and Settings\Dufresne\Application Data\SUPERAntiSpyware.com\SUPERAntiSpyware\PROCESSLIST.ZIP" is compressed (flags = 1)
    Read File: File "c:\Documents and Settings\Dufresne\Application Data\SUPERAntiSpyware.com\SUPERAntiSpyware\PROCESSLISTRELATED.DB" is compressed (flags = 1)
    Read File: File "c:\Documents and Settings\Dufresne\Application Data\SUPERAntiSpyware.com\SUPERAntiSpyware\PROCESSLISTRELATED.ZIP" is compressed (flags = 1)
    Read File: File "c:\Documents and Settings\Dufresne\Application Data\TaxCut\2007\alert.cfg" is compressed (flags = 1)
    Read File: File "c:\Documents and Settings\Dufresne\Application Data\TaxCut\2007\alert.txt" is compressed (flags = 1)
    Read File: File "c:\Documents and Settings\Dufresne\Application Data\TaxCut\2007\centrallog.log" is compressed (flags = 1)
    Read File: File "c:\Documents and Settings\Dufresne\Application Data\TaxCut\2007\htmlBuilder.log" is compressed (flags = 1)
    Read File: File "c:\Documents and Settings\Dufresne\Application Data\TaxCut\2007\taxcut_pdf995_setup.log" is compressed (flags = 1)
    Read File: File "c:\Documents and Settings\Dufresne\Application Data\TaxCut\2007\tc07.cfg" is compressed (flags = 1)
    Read File: File "c:\Documents and Settings\Dufresne\Application Data\TaxCut\2008\alert.cfg" is compressed (flags = 1)
    Read File: File "c:\Documents and Settings\Dufresne\Application Data\TaxCut\2008\alert.txt" is compressed (flags = 1)
    Read File: File "c:\Documents and Settings\Dufresne\Application Data\TaxCut\2008\EFileResponse.txt" is compressed (flags = 1)
    Read File: File "c:\Documents and Settings\Dufresne\Application Data\TaxCut\2008\htmlBuilder.log" is compressed (flags = 1)
    Read File: File "c:\Documents and Settings\Dufresne\Application Data\TaxCut\2008\tc08.cfg" is compressed (flags = 1)
    Read File: File "c:\Documents and Settings\Dufresne\Application Data\TaxCut\2009\alert.cfg" is compressed (flags = 1)
    Read File: File "c:\Documents and Settings\Dufresne\Application Data\TaxCut\2009\alert.txt" is compressed (flags = 1)
    Read File: File "c:\Documents and Settings\Dufresne\Application Data\TaxCut\2009\htmlBuilder.log" is compressed (flags = 1)
    Read File: File "c:\Documents and Settings\Dufresne\Application Data\TaxCut\2009\tc09.cfg" is compressed (flags = 1)
    Read File: File "c:\Documents and Settings\Dufresne\Application Data\TaxCut\2010\alert.cfg" is compressed (flags = 1)
    Read File: File "c:\Documents and Settings\Dufresne\Application Data\TaxCut\2010\alert.txt" is compressed (flags = 1)
    Read File: File "c:\Documents and Settings\Dufresne\Application Data\TaxCut\2010\htmlBuilder.log" is compressed (flags = 1)
    Read File: File "c:\Documents and Settings\Dufresne\Application Data\TaxCut\2010\tc10.cfg" is compressed (flags = 1)
    Read File: File "c:\Documents and Settings\Dufresne\Application Data\TaxCut\2011\alert.cfg" is compressed (flags = 1)
    Read File: File "c:\Documents and Settings\Dufresne\Application Data\TaxCut\2011\htmlBuilder.log" is compressed (flags = 1)
    Read File: File "c:\Documents and Settings\Dufresne\Application Data\TaxCut\2011\tc11.cfg" is compressed (flags = 1)
    Read File: File "c:\Documents and Settings\Dufresne\Application Data\TaxCut\2011\usalert.txt" is compressed (flags = 1)
    Read File: File "c:\Documents and Settings\Dufresne\Application Data\Uniblue\SpeedUpMyPC\error.log" is compressed (flags = 1)
    Read File: File "c:\Documents and Settings\Dufresne\Application Data\Uniblue\SpeedUpMyPC\settings.dat" is compressed (flags = 1)
    Read File: File "c:\Documents and Settings\Dufresne\Application Data\Uniblue\SpeedUpMyPC\state.sqlite" is compressed (flags = 1)
    Read File: File "c:\Documents and Settings\Dufresne\Application Data\Uniblue\SpeedUpMyPC\track_installs.txt" is compressed (flags = 1)
    Read File: File "c:\Documents and Settings\Dufresne\Application Data\vlc\74fc38f77c06519e77f3a2fec1e82051-i686.cache-2" is compressed (flags = 1)
    Read File: File "c:\Documents and Settings\Dufresne\Application Data\vlc\ef9c9ad8cc5857eb63cb3660bc8bd202-i686.cache-2" is compressed (flags = 1)
    Read File: File "c:\Documents and Settings\Dufresne\Application Data\Xtranormal\Output\State.err" is compressed (flags = 1)
    Read File: File "c:\Documents and Settings\Dufresne\Application Data\Xtranormal\State\License.dat" is compressed (flags = 1)
    Read File: File "c:\Documents and Settings\Dufresne\Application Data\Yahoo!\Companion\inq_data.inq" is compressed (flags = 1)
    Read File: File "c:\Documents and Settings\Dufresne\Application Data\Yahoo!\Companion\resources.inq" is compressed (flags = 1)
    Read File: File "c:\WINDOWS\system32\config\systemprofile\Application Data\Microsoft\Internet Explorer\brndlog.bak" is compressed (flags = 1)
    Read File: File "c:\WINDOWS\system32\config\systemprofile\Application Data\Microsoft\Internet Explorer\brndlog.txt" is compressed (flags = 1)
    Read File: File "c:\Documents and Settings\Dufresne\Desktop\Thumbs.db" is compressed (flags = 1)
    Read File: File "c:\Documents and Settings\Dufresne\Desktop\nvideaHTPC.nvp" is compressed (flags = 1)
    Read File: File "c:\Documents and Settings\Dufresne\Desktop\ZbThumbnail.info" is compressed (flags = 1)
    Read File: File "c:\Program Files\Outlook Express\msoe.txt" is compressed (flags = 1)
    Read File: File "c:\Program Files\Windows Media Player\npdrmv2.zip" is compressed (flags = 1)
    Read File: File "c:\Documents and Settings\Default User\Start Menu\Programs\Startup\desktop.ini" is compressed (flags = 1)
    Read File: File "c:\WINDOWS\system32\config\systemprofile\Start Menu\Programs\Startup\desktop.ini" is compressed (flags = 1)
    Read File: File "c:\WINDOWS\system32\omginstlog.txt" is compressed (flags = 1)
    Read File: File "c:\WINDOWS\system32\dsound.vxd" is compressed (flags = 1)
    Read File: File "c:\WINDOWS\system32\l_except.nls" is compressed (flags = 1)
    Read File: File "c:\WINDOWS\system32\perfwci.h" is compressed (flags = 1)
    Read File: File "c:\WINDOWS\system32\cmos.ram" is compressed (flags = 1)
    Read File: File "c:\WINDOWS\system32\pscript.sep" is compressed (flags = 1)
    Read File: File "c:\WINDOWS\system32\lMMLDeleteUserData42107612FX.tmp" is compressed (flags = 1)
    Read File: File "c:\WINDOWS\system32\login.cmd" is compressed (flags = 1)
    Read File: File "c:\WINDOWS\system32\pcl.sep" is compressed (flags = 1)
    Read File: File "c:\WINDOWS\system32\perfci.h" is compressed (flags = 1)
    Read File: File "c:\WINDOWS\system32\perffilt.h" is compressed (flags = 1)
    Read File: File "c:\WINDOWS\system32\spupdwxp.log" is compressed (flags = 1)
    Read File: File "c:\WINDOWS\system32\results.txt" is compressed (flags = 1)
    Read File: File "c:\WINDOWS\system32\nvModes.dat" is compressed (flags = 1)
    Read File: File "c:\WINDOWS\system32\View Channels.scf" is compressed (flags = 1)
    Read File: File "c:\WINDOWS\system32\config\systemprofile\Start Menu\Programs\Startup\desktop.ini" is compressed (flags = 1)
    Read File: File "c:\WINDOWS\system32\drivers\etc\networks" is compressed (flags = 1)
    Read File: File "c:\WINDOWS\system32\oobe\migip.dun" is compressed (flags = 1)
    Read File: File "c:\WINDOWS\system32\oobe\migrate.isp" is compressed (flags = 1)
    Read File: File "c:\WINDOWS\system32\oobe\msobe.isp" is compressed (flags = 1)
    Read File: File "c:\WINDOWS\system32\oobe\obeip.dun" is compressed (flags = 1)
    Read File: File "c:\WINDOWS\system32\oobe\reg.isp" is compressed (flags = 1)
    Read File: File "c:\WINDOWS\system32\wbem\wmiclivalueformat.xsl" is compressed (flags = 1)
    Read File: File "c:\Documents and Settings\Dufresne\.jupload.properties" is compressed (flags = 1)
    Read File: File "c:\Documents and Settings\Dufresne\.recently-used.xbel" is compressed (flags = 1)
    Read File: File "c:\Documents and Settings\Dufresne\DPro.log" is compressed (flags = 1)
    Read File: File "c:\Documents and Settings\Administrator\Local Settings\desktop.ini" is compressed (flags = 1)
    Read File: File "c:\Documents and Settings\Default User\Local Settings\desktop.ini" is compressed (flags = 1)
    Read File: File "c:\Documents and Settings\Dufresne\Local Settings\Application Data\dt.dat" is compressed (flags = 1)
    Read File: File "c:\Documents and Settings\Dufresne\Local Settings\Application Data\fusioncache.dat" is compressed (flags = 1)
    Read File: File "c:\Documents and Settings\Dufresne\Local Settings\Application Data\GDIPFONTCACHEV1.DAT" is compressed (flags = 1)
    Read File: File "c:\Documents and Settings\Dufresne\Local Settings\Application Data\Microsoft\Internet Explorer\brndlog.bak" is compressed (flags = 1)
    Read File: File "c:\Documents and Settings\Dufresne\Local Settings\Application Data\Microsoft\Internet Explorer\brndlog.txt" is compressed (flags = 1)
    Read File: File "c:\Documents and Settings\Dufresne\Local Settings\Application Data\Microsoft\Internet Explorer\MSIMGSIZ.DAT" is compressed (flags = 1)
    Read File: File "c:\WINDOWS\Permissions Syntax.txt" is compressed (flags = 1)
    Read File: File "c:\WINDOWS\UNNeroShowTime.cfg" is compressed (flags = 1)
    Read File: File "c:\WINDOWS\explorer.scf" is compressed (flags = 1)
    Read File: File "c:\WINDOWS\DVDShrink.txt" is compressed (flags = 1)
    Read File: File "c:\WINDOWS\assembly\GAC\System.Web.Mobile\1.0.5000.0__b03f5f7f11d50a3a\__AssemblyInfo__.ini" is compressed (flags = 1)
    Read File: File "c:\WINDOWS\Help\ciadmin.htm" is compressed (flags = 1)
    Read File: File "c:\WINDOWS\Help\conf.cnt" is compressed (flags = 1)
    Read File: File "c:\WINDOWS\Help\connect.cnt" is compressed (flags = 1)
    Read File: File "c:\WINDOWS\Help\ratings.cnt" is compressed (flags = 1)
    Read File: File "c:\WINDOWS\Help\mshearts.cnt" is compressed (flags = 1)
    Read File: File "c:\WINDOWS\Help\msnauth.cnt" is compressed (flags = 1)
    Read File: File "c:\WINDOWS\Help\nocontnt.cnt" is compressed (flags = 1)
    Read File: File "c:\WINDOWS\Help\update.cnt" is compressed (flags = 1)
    Read File: File "c:\WINDOWS\Help\windows.cnt" is compressed (flags = 1)
    Read File: File "c:\WINDOWS\Help\winhlp32.cnt" is compressed (flags = 1)
    Read File: File "c:\WINDOWS\Microsoft.NET\Framework\v1.0.3705\regsvcs.exe.rtm.config" is compressed (flags = 1)
    Read File: File "c:\WINDOWS\Microsoft.NET\Framework\v1.1.4322\aspnet.mof.uninstall" is compressed (flags = 1)
    Read File: File "c:\WINDOWS\Microsoft.NET\Framework\v1.1.4322\ieexec.exe.config" is compressed (flags = 1)
    Read File: File "c:\WINDOWS\Microsoft.NET\Framework\v1.1.4322\ilasm.exe.config" is compressed (flags = 1)
    Read File: File "c:\WINDOWS\Microsoft.NET\Framework\v1.1.4322\csc.exe.config" is compressed (flags = 1)
    Read File: File "c:\WINDOWS\Microsoft.NET\Framework\v1.1.4322\cvtres.exe.config" is compressed (flags = 1)
    Read File: File "c:\WINDOWS\Microsoft.NET\Framework\v1.1.4322\jsc.exe.config" is compressed (flags = 1)
    Read File: File "c:\WINDOWS\Microsoft.NET\Framework\v1.1.4322\l_except.nlp" is compressed (flags = 1)
    Read File: File "c:\WINDOWS\Microsoft.NET\Framework\v1.1.4322\vbc.exe.config" is compressed (flags = 1)
    Read File: File "c:\WINDOWS\Microsoft.NET\Framework\v1.1.4322\XPThemes.manifest" is compressed (flags = 1)
    Read File: File "c:\WINDOWS\Microsoft.NET\Framework\v1.1.4322\caspol.exe.config" is compressed (flags = 1)
    Read File: File "c:\WINDOWS\Microsoft.NET\Framework\v1.1.4322\ConfigWizards.exe.config" is compressed (flags = 1)
    Read File: File "c:\WINDOWS\Microsoft.NET\Framework\v1.1.4322\regasm.exe.config" is compressed (flags = 1)
    Read File: File "c:\WINDOWS\Microsoft.NET\Framework\v1.1.4322\1033\SetupENU1.txt" is compressed (flags = 1)
    Read File: File "c:\WINDOWS\Microsoft.NET\Framework\v1.1.4322\1033\SetupENU2.txt" is compressed (flags = 1)
    Read File: File "c:\WINDOWS\Microsoft.NET\Framework\v1.1.4322\ASP.NETClientFiles\SmartNav.htm" is compressed (flags = 1)
    Read File: File "c:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\caspol.exe.config" is compressed (flags = 1)
    Read File: File "c:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\aspnet.mof.uninstall" is compressed (flags = 1)
    Read File: File "c:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\ilasm.exe.config" is compressed (flags = 1)
    Read File: File "c:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\jsc.exe.config" is compressed (flags = 1)
    Read File: File "c:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\regasm.exe.config" is compressed (flags = 1)
    Read File: File "c:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\ASP.NETWebAdminFiles\webAdminNoNavBar.master" is compressed (flags = 1)
    Read File: File "c:\WINDOWS\Microsoft.NET\Framework\v3.5\AddInProcess.exe.config" is compressed (flags = 1)
    Read File: File "c:\WINDOWS\Microsoft.NET\Framework\v3.5\AddInProcess32.exe.config" is compressed (flags = 1)
    Read File: File "c:\WINDOWS\Microsoft.NET\Framework\v3.5\AddInUtil.exe.config" is compressed (flags = 1)
    Read File: File "c:\WINDOWS\Microsoft.NET\Framework\v3.5\csc.exe.config" is compressed (flags = 1)
    Read File: File "c:\WINDOWS\Microsoft.NET\Framework\v3.5\DataSvcUtil.exe.config" is compressed (flags = 1)
    Read File: File "c:\WINDOWS\Microsoft.NET\Framework\v3.5\default.win32manifest" is compressed (flags = 1)
    Read File: File "c:\WINDOWS\Microsoft.NET\Framework\v3.5\EdmGen.exe.config" is compressed (flags = 1)
    Read File: File "c:\WINDOWS\Microsoft.NET\Framework\v3.5\vbc.exe.config" is compressed (flags = 1)
    Read File: File "c:\WINDOWS\Microsoft.NET\Framework\v4.0.30319\AddInProcess.exe.config" is compressed (flags = 1)
    Read File: File "c:\WINDOWS\Microsoft.NET\Framework\v4.0.30319\AddInProcess32.exe.config" is compressed (flags = 1)
    Read File: File "c:\WINDOWS\Microsoft.NET\Framework\v4.0.30319\AddInUtil.exe.config" is compressed (flags = 1)
    Read File: File "c:\WINDOWS\Microsoft.NET\Framework\v4.0.30319\applaunch.exe.config" is compressed (flags = 1)
    Read File: File "c:\WINDOWS\Microsoft.NET\Framework\v4.0.30319\caspol.exe.config" is compressed (flags = 1)
    Read File: File "c:\WINDOWS\Microsoft.NET\Framework\v4.0.30319\InstallUtil.exe.config" is compressed (flags = 1)
    Read File: File "c:\WINDOWS\Microsoft.NET\Framework\v4.0.30319\jsc.exe.config" is compressed (flags = 1)
    Read File: File "c:\WINDOWS\Microsoft.NET\Framework\v4.0.30319\regasm.exe.config" is compressed (flags = 1)
    Read File: File "c:\WINDOWS\Microsoft.NET\Framework\v4.0.30319\regsvcs.exe.config" is compressed (flags = 1)
    Read File: File "c:\WINDOWS\Microsoft.NET\Framework\v4.0.30319\vbc.exe.config" is compressed (flags = 1)
    Read File: File "c:\WINDOWS\Web\bullet.gif" is compressed (flags = 1)
    Read File: File "c:\Documents and Settings\Administrator\Local Settings\desktop.ini" is compressed (flags = 1)
    Read File: File "c:\Documents and Settings\Administrator\Local Settings\History\History.IE5\desktop.ini" is compressed (flags = 1)
    Read File: File "c:\Documents and Settings\Administrator\Local Settings\History\History.IE5\index.dat" is compressed (flags = 1)
    Read File: File "c:\Documents and Settings\Default User\Local Settings\desktop.ini" is compressed (flags = 1)
    Read File: File "c:\Documents and Settings\Default User\Local Settings\History\desktop.ini" is compressed (flags = 1)
    Read File: File "c:\Documents and Settings\Dufresne\Local Settings\Application Data\dt.dat" is compressed (flags = 1)
    Read File: File "c:\Documents and Settings\Dufresne\Local Settings\Application Data\fusioncache.dat" is compressed (flags = 1)
    Read File: File "c:\Documents and Settings\Dufresne\Local Settings\Application Data\GDIPFONTCACHEV1.DAT" is compressed (flags = 1)
    Infected: c:\Documents and Settings\Dufresne\Local Settings\Application Data\Temp\{0C58F3F9-B17C-4767-903B-12764F63E320} --> [Trojan.P2P.Worm]
    Infected: c:\Documents and Settings\Dufresne\Local Settings\Application Data\Temp\{2AE26565-B431-44C4-ACDC-A2F353FD0C36} --> [Trojan.P2P.Worm]
    Infected: c:\Documents and Settings\Dufresne\Local Settings\Application Data\Temp\{7D8C5599-0A55-41C4-AC14-32F99E792A7E} --> [Trojan.P2P.Worm]
    Infected: c:\Documents and Settings\Dufresne\Local Settings\Application Data\Temp\{D65228CA-A391-4B90-AB00-AE3F50F99160} --> [Trojan.P2P.Worm]
    Infected: c:\Documents and Settings\Dufresne\Local Settings\Application Data\Temp\{F8C2F86F-ABB6-4927-88BD-EDBC95BC2BE1} --> [Trojan.P2P.Worm]
    Read File: File "c:\Documents and Settings\NetworkService\Local Settings\History\History.IE5\index.dat" is compressed (flags = 1)
    Read File: File "c:\Documents and Settings\Dufresne\Local Settings\Application Data\dt.dat" is compressed (flags = 1)
    Read File: File "c:\Documents and Settings\Dufresne\Local Settings\Application Data\fusioncache.dat" is compressed (flags = 1)
    Read File: File "c:\Documents and Settings\Dufresne\Local Settings\Application Data\GDIPFONTCACHEV1.DAT" is compressed (flags = 1)
    Read File: File "c:\Documents and Settings\Dufresne\Local Settings\Application Data\Adobe\Color\ACECache6.lst" is compressed (flags = 1)
    Read File: File "c:\Documents and Settings\Dufresne\Local Settings\Application Data\Adobe\Fonts\AdobeFnt11.lst" is compressed (flags = 1)
    Read File: File "c:\Documents and Settings\Dufresne\Local Settings\Application Data\Adobe\TypeSpt\AdobeFnt11.lst" is compressed (flags = 1)
    Read File: File "c:\Documents and Settings\Dufresne\Local Settings\Application Data\Adobe\Updater5\acrobatPI.log" is compressed (flags = 1)
    Read File: File "c:\Documents and Settings\Dufresne\Local Settings\Application Data\Adobe\Updater5\aum.log" is compressed (flags = 1)
    Read File: File "c:\Documents and Settings\Dufresne\Local Settings\Application Data\Adobe\Updater5\aumLib.log" is compressed (flags = 1)
    Read File: File "c:\Documents and Settings\Dufresne\Local Settings\Application Data\Adobe\Updater5\AUTrans.xml.0" is compressed (flags = 1)
    Read File: File "c:\Documents and Settings\Dufresne\Local Settings\Application Data\Ahead\Nero Home\bl.db" is compressed (flags = 1)
    Read File: File "c:\Documents and Settings\Dufresne\Local Settings\Application Data\Ahead\Nero Home\crawlercfg.dat" is compressed (flags = 1)
    Read File: File "c:\Documents and Settings\Dufresne\Local Settings\Application Data\Ahead\Nero Home\is2.db" is compressed (flags = 1)
    Read File: File "c:\Documents and Settings\Dufresne\Local Settings\Application Data\Ahead\Nero Home\SID.db" is compressed (flags = 1)
    Read File: File "c:\Documents and Settings\Dufresne\Local Settings\Application Data\Ahead\Nero Home\SII.db" is compressed (flags = 1)
    Read File: File "c:\Documents and Settings\Dufresne\Local Settings\Application Data\Avg2013\log\avgpostinst.log" is compressed (flags = 1)
    Read File: File "c:\Documents and Settings\Dufresne\Local Settings\Application Data\Avg2013\log\avgual.2012-09-30.log" is compressed (flags = 1)
    Read File: File "c:\Documents and Settings\Dufresne\Local Settings\Application Data\Avg2013\log\avgual.2012-12-20.log" is compressed (flags = 1)
    Read File: File "c:\Documents and Settings\Dufresne\Local Settings\Application Data\Avg2013\log\avgual.2013-03-26.log" is compressed (flags = 1)
    Read File: File "c:\Documents and Settings\Dufresne\Local Settings\Application Data\Avg2013\log\avgual.2013-03-28.log" is compressed (flags = 1)
    Read File: File "c:\Documents and Settings\Dufresne\Local Settings\Application Data\Avg2013\log\avgual.2013-03-30.log" is compressed (flags = 1)
    Read File: File "c:\Documents and Settings\Dufresne\Local Settings\Application Data\Avg2013\log\avgual.2013-04-01.log" is compressed (flags = 1)
    Read File: File "c:\Documents and Settings\Dufresne\Local Settings\Application Data\Avg2013\log\avgual.2013-04-03.log" is compressed (flags = 1)
    Read File: File "c:\Documents and Settings\Dufresne\Local Settings\Application Data\Google\GBScreensaver\network.log" is compressed (flags = 1)
    Read File: File "c:\Documents and Settings\Dufresne\Local Settings\Application Data\Google\GoogleEarth\dbCache1.dat.index" is compressed (flags = 1)
    Read File: File "c:\Documents and Settings\Dufresne\Local Settings\Application Data\Google\GoogleEarth\dbCache2.dat" is compressed (flags = 1)
    Read File: File "c:\Documents and Settings\Dufresne\Local Settings\Application Data\Google\GoogleEarth\dbCache2.dat.index" is compressed (flags = 1)
    Read File: File "c:\Documents and Settings\Dufresne\Local Settings\Application Data\Google\GoogleEarth\dbCache3.dat" is compressed (flags = 1)
    Read File: File "c:\Documents and Settings\Dufresne\Local Settings\Application Data\Google\GoogleEarth\dbCache3.dat.index" is compressed (flags = 1)
    Read File: File "c:\Documents and Settings\Dufresne\Local Settings\Application Data\Google\GoogleEarth\dbCache4.dat" is compressed (flags = 1)
    Read File: File "c:\Documents and Settings\Dufresne\Local Settings\Application Data\Google\GoogleEarth\dbCache4.dat.index" is compressed (flags = 1)
    Read File: File "c:\Documents and Settings\Dufresne\Local Settings\Application Data\Google\Picasa2\overlay.kml" is compressed (flags = 1)
    Read File: File "c:\Documents and Settings\Dufresne\Local Settings\Application Data\Google\Picasa2\picasa.kml" is compressed (flags = 1)
    Read File: File "c:\Documents and Settings\Dufresne\Local Settings\Application Data\MFAData\logs\msi-20120928-015458.log" is compressed (flags = 1)
    Read File: File "c:\Documents and Settings\Dufresne\Local Settings\Application Data\MFAData\logs\msi-20120930-174631.log" is compressed (flags = 1)
    Read File: File "c:\Documents and Settings\Dufresne\Local Settings\Application Data\MFAData\logs\r86-20120930-174838.log" is compressed (flags = 1)
    Read File: File "c:\Documents and Settings\Dufresne\Local Settings\Application Data\Microsoft\Office\PowerPoint.qat" is compressed (flags = 1)
    Read File: File "c:\Documents and Settings\Dufresne\Local Settings\Application Data\Microsoft\FORMS\FRMCACHE.DAT" is compressed (flags = 1)
    Read File: File "c:\Documents and Settings\Dufresne\Local Settings\Application Data\Microsoft\HelpCtr\HelpSessionHistory.dat" is compressed (flags = 1)
    Read File: File "c:\Documents and Settings\Dufresne\Local Settings\Application Data\Microsoft\Internet Explorer\brndlog.bak" is compressed (flags = 1)
    Read File: File "c:\Documents and Settings\Dufresne\Local Settings\Application Data\Microsoft\Internet Explorer\brndlog.txt" is compressed (flags = 1)
    Read File: File "c:\Documents and Settings\Dufresne\Local Settings\Application Data\Microsoft\Internet Explorer\MSIMGSIZ.DAT" is compressed (flags = 1)
    Read File: File "c:\Documents and Settings\Dufresne\Local Settings\Application Data\Microsoft\Media Player\CorruptDatabase_360.wmdb" is compressed (flags = 1)
    Read File: File "c:\Documents and Settings\Dufresne\Local Settings\Application Data\Microsoft\Media Player\CurrentDatabase_59R.wmdb" is compressed (flags = 1)
    Read File: File "c:\Documents and Settings\Dufresne\Local Settings\Application Data\Microsoft\Media Player\D- _0.wmdb" is compressed (flags = 1)
    Read File: File "c:\Documents and Settings\Dufresne\Local Settings\Application Data\Microsoft\Media Player\D- _1.wmdb" is compressed (flags = 1)
    Read File: File "c:\Documents and Settings\Dufresne\Local Settings\Application Data\Microsoft\Media Player\D- _2.wmdb" is compressed (flags = 1)
    Read File: File "c:\Documents and Settings\Dufresne\Local Settings\Application Data\Microsoft\Media Player\D- _3.wmdb" is compressed (flags = 1)
    Read File: File "c:\Documents and Settings\Dufresne\Local Settings\Application Data\Microsoft\Media Player\D- _4.wmdb" is compressed (flags = 1)
    Read File: File "c:\Documents and Settings\Dufresne\Local Settings\Application Data\Microsoft\Media Player\D- _5.wmdb" is compressed (flags = 1)
    Read File: File "c:\Documents and Settings\Dufresne\Local Settings\Application Data\Microsoft\Media Player\E- _0.wmdb" is compressed (flags = 1)
    Read File: File "c:\Documents and Settings\Dufresne\Local Settings\Application Data\Microsoft\Media Player\E- _1.wmdb" is compressed (flags = 1)
    Read File: File "c:\Documents and Settings\Dufresne\Local Settings\Application Data\Microsoft\Media Player\E- _2.wmdb" is compressed (flags = 1)
    Read File: File "c:\Documents and Settings\Dufresne\Local Settings\Application Data\Microsoft\Media Player\E- _3.wmdb" is compressed (flags = 1)
    Read File: File "c:\Documents and Settings\Dufresne\Local Settings\Application Data\Microsoft\Media Player\E- _4.wmdb" is compressed (flags = 1)
    Read File: File "c:\Documents and Settings\Dufresne\Local Settings\Application Data\Microsoft\Media Player\E- _5.wmdb" is compressed (flags = 1)
    Read File: File "c:\Documents and Settings\Dufresne\Local Settings\Application Data\Microsoft\Messenger\activesharingfolder.dat" is compressed (flags = 1)
    Read File: File "c:\Documents and Settings\Dufresne\Local Settings\Application Data\Microsoft\Messenger\ContactsLog.txt" is compressed (flags = 1)
    Read File: File "c:\Documents and Settings\Dufresne\Local Settings\Application Data\Microsoft\Movie Maker\MEDIATAB0.DAT" is compressed (flags = 1)
    Read File: File "c:\Documents and Settings\Dufresne\Local Settings\Application Data\Microsoft\Outlook\Outltdufres@Hotmail.com-00000002.pst" is compressed (flags = 1)
    Read File: File "c:\Documents and Settings\Dufresne\Local Settings\Application Data\Microsoft\Outlook\Outltdufres@hotmail.com-00000003.pst" is compressed (flags = 1)
    Read File: File "c:\Documents and Settings\Dufresne\Desktop\Thumbs.db" is compressed (flags = 1)
    Read File: File "c:\Documents and Settings\Dufresne\Desktop\nvideaHTPC.nvp" is compressed (flags = 1)
    Read File: File "c:\Documents and Settings\Dufresne\Desktop\ZbThumbnail.info" is compressed (flags = 1)
    Read File: File "c:\Documents and Settings\Dufresne\Desktop\Personal Mailing List\FIELDS.LST" is compressed (flags = 1)
    Read File: File "c:\Documents and Settings\Dufresne\Desktop\Personal Mailing List\INSTALL.LOG" is compressed (flags = 1)
    Read File: File "c:\Documents and Settings\Dufresne\Desktop\Personal Mailing List\PML.GID" is compressed (flags = 1)
    Read File: File "c:\Documents and Settings\Dufresne\Desktop\Personal Mailing List\Pml.tpl" is compressed (flags = 1)
    Read File: File "c:\Documents and Settings\Dufresne\Desktop\Personal Mailing List\DATA\Add0001.CDX" is compressed (flags = 1)
    Read File: File "c:\Documents and Settings\Dufresne\Desktop\Personal Mailing List\DATA\Add0001.DBF" is compressed (flags = 1)
    Read File: File "c:\Documents and Settings\Dufresne\Desktop\Personal Mailing List\Labels\Christmas 2011.lbl" is compressed (flags = 1)
    Read File: File "c:\Documents and Settings\Dufresne\Desktop\Personal Mailing List\Labels\Return Address.lbl" is compressed (flags = 1)
    Read File: File "c:\Documents and Settings\Dufresne\Desktop\Personal Mailing List\Labels\Sample Label #1.lbl" is compressed (flags = 1)
    Read File: File "c:\Documents and Settings\Dufresne\Desktop\quicken backups\quicken1_19-20Jan2010.QDF-backup" is compressed (flags = 1)
    Read File: File "c:\Documents and Settings\Dufresne\Desktop\quicken backups\quicken1_19.QDF" is compressed (flags = 1)
    Read File: File "c:\Documents and Settings\Dufresne\Desktop\quicken backups\quicken1_19OFXLOG.DAT" is compressed (flags = 1)
    Read File: File "c:\Documents and Settings\Dufresne\Desktop\quicken backups\stupid.QDF" is compressed (flags = 1)
    Read File: File "c:\Documents and Settings\Dufresne\Desktop\quicken backups\stupid.QEL" is compressed (flags = 1)
    Read File: File "c:\Documents and Settings\Dufresne\Desktop\quicken backups\stupid.QPH" is compressed (flags = 1)
    Read File: File "c:\Documents and Settings\Dufresne\Desktop\quicken backups\stupid.QTX" is compressed (flags = 1)
    Read File: File "c:\Documents and Settings\Dufresne\Desktop\quicken backups\stupidOFXLOG.DAT" is compressed (flags = 1)
    Read File: File "c:\Documents and Settings\Dufresne\Desktop\quicken backups\test.QDF" is compressed (flags = 1)
    Read File: File "c:\Documents and Settings\Dufresne\Desktop\quicken backups\testOFXLOG.DAT" is compressed (flags = 1)
    Read File: File "c:\Documents and Settings\Dufresne\Desktop\quicken backups\today-2010-01-27.PM06.49.QDF-backup" is compressed (flags = 1)
    Read File: File "c:\Documents and Settings\Dufresne\Desktop\quicken backups\today-20Jan2010.QDF-backup" is compressed (flags = 1)
    Read File: File "c:\Documents and Settings\Dufresne\Desktop\quicken backups\todayOFXOLD.DAT" is compressed (flags = 1)
    Read File: File "c:\Documents and Settings\Dufresne\Desktop\quicken backups\BACKUP\today-2012-02-16.PM10.06.QDF-backup" is compressed (flags = 1)
    Read File: File "c:\Documents and Settings\Dufresne\Desktop\quicken backups\BACKUP\today-2012-03-14.PM10.00.QDF-backup" is compressed (flags = 1)
    Read File: File "c:\Documents and Settings\Dufresne\Desktop\quicken backups\BACKUP\today-2012-04-17.PM08.24.QDF-backup" is compressed (flags = 1)
    Read File: File "c:\Documents and Settings\Dufresne\Desktop\quicken backups\BACKUP\today-2012-08-22.PM08.53.QDF-backup" is compressed (flags = 1)
    Read File: File "c:\Documents and Settings\Dufresne\Desktop\quicken backups\BACKUP\today-2012-09-30.PM01.20.QDF-backup" is compressed (flags = 1)
    Read File: File "c:\Documents and Settings\Dufresne\Desktop\school stuff\Thumbs.db" is compressed (flags = 1)
    Read File: File "c:\Documents and Settings\Dufresne\Desktop\school stuff\ZbThumbnail.info" is compressed (flags = 1)
    Read File: File "c:\Documents and Settings\Dufresne\Desktop\school stuff\Jeopardy 2012\pacman_dies_y.wav" is compressed (flags = 1)
    Read File: File "c:\Documents and Settings\Dufresne\Desktop\school stuff\Jeopardy 2012\ShortDoDo.wav" is compressed (flags = 1)
    Read File: File "c:\Documents and Settings\Dufresne\Desktop\school stuff\jeopardy2011\pacman_dies_y.wav" is compressed (flags = 1)
    Read File: File "c:\Documents and Settings\Dufresne\Desktop\school stuff\jeopardy2011\ShortDoDo.wav" is compressed (flags = 1)
    Read File: File "c:\Documents and Settings\Dufresne\Desktop\Aishas videos\Thumbs.db" is compressed (flags = 1)
    Read File: File "c:\Documents and Settings\Dufresne\Desktop\Aishas videos\VID 00003.3GP" is compressed (flags = 1)
    Read File: File "c:\Documents and Settings\Dufresne\Desktop\Aishas videos\VID 00004.3GP" is compressed (flags = 1)
    Read File: File "c:\Documents and Settings\Dufresne\Desktop\Aishas videos\VID 00005.3GP" is compressed (flags = 1)
    Read File: File "c:\Documents and Settings\Dufresne\Desktop\Aishas videos\VID 00006.3GP" is compressed (flags = 1)
    Read File: File "c:\Documents and Settings\Dufresne\Desktop\Aishas videos\ZbThumbnail.info" is compressed (flags = 1)
    Read File: File "c:\Documents and Settings\Dufresne\Desktop\Big Pink Beaver\Thumbs.db" is compressed (flags = 1)
    Read File: File "c:\Documents and Settings\Dufresne\Desktop\Big Pink Beaver\ZbThumbnail.info" is compressed (flags = 1)
    Read File: File "c:\Documents and Settings\Dufresne\Desktop\Big Pink Beaver\Beaver_MistyFjords.ai" is compressed (flags = 1)
    Read File: File "c:\Documents and Settings\Dufresne\Desktop\Big Pink Beaver\beaver_poster_test1.pub" is compressed (flags = 1)
    Read File: File "c:\Documents and Settings\Dufresne\Desktop\Big Pink Beaver\beaver_test_2.pub" is compressed (flags = 1)
    Done!
     
  13. 2013/05/17
    chinaclipper

    chinaclipper Well-Known Member Thread Starter

    Joined:
    2010/01/20
    Messages:
    96
    Likes Received:
    0
    Part V

    Scan finished
    Creating System Restore point...
    Could not create restore point...
    Scheduling clean up...
    <<<2>>>
    Device number: 0, partition: 1
    <<<3>>>
    Volume: C:
    File system type: NTFS
    SectorSize = 512, ClusterSize = 4096, MFTRecordSize = 1024, MFTIndexSize = 4096 bytes
    Removal scheduling successful. System shutdown needed.
    System shutdown occurred
    =======================================


    ---------------------------------------
    Malwarebytes Anti-Rootkit BETA 1.05.0.1001

    (c) Malwarebytes Corporation 2011-2012

    OS version: 5.1.2600 Windows XP Service Pack 3 x86

    System is currently in a safe mode

    Account is Administrative

    Internet Explorer version: 8.0.6001.18702

    File system is: NTFS
    Disk drives: C:\ DRIVE_FIXED
    CPU speed: 1.999000 GHz
    Memory total: 2146545664, free: 1826762752

    ------------ Kernel report ------------
    05/16/2013 16:37:22
    ------------ Loaded modules -----------
    \WINDOWS\system32\ntoskrnl.exe
    \WINDOWS\system32\hal.dll
    \WINDOWS\system32\KDCOM.DLL
    \WINDOWS\system32\BOOTVID.dll
    imofugc.sys
    ACPI.sys
    \WINDOWS\system32\DRIVERS\WMILIB.SYS
    pci.sys
    isapnp.sys
    gfibto.sys
    pciide.sys
    \WINDOWS\system32\DRIVERS\PCIIDEX.SYS
    MountMgr.sys
    ftdisk.sys
    dmload.sys
    dmio.sys
    PartMgr.sys
    VolSnap.sys
    atapi.sys
    disk.sys
    \WINDOWS\system32\DRIVERS\CLASSPNP.SYS
    fltmgr.sys
    sr.sys
    PxHelp20.sys
    KSecDD.sys
    WudfPf.sys
    Ntfs.sys
    NDIS.sys
    Mup.sys
    avgrkx86.sys
    avglogx.sys
    avgmfx86.sys
    avgidshx.sys
    \SystemRoot\system32\DRIVERS\HDAudBus.sys
    \SystemRoot\system32\DRIVERS\l151x86.sys
    \SystemRoot\system32\DRIVERS\usbuhci.sys
    \SystemRoot\system32\DRIVERS\USBPORT.SYS
    \SystemRoot\system32\DRIVERS\usbehci.sys
    \SystemRoot\system32\DRIVERS\fdc.sys
    \SystemRoot\system32\DRIVERS\ASACPI.sys
    \SystemRoot\system32\DRIVERS\i8042prt.sys
    \SystemRoot\system32\DRIVERS\L8042Kbd.sys
    \SystemRoot\system32\DRIVERS\kbdclass.sys
    \SystemRoot\system32\DRIVERS\imapi.sys
    \SystemRoot\system32\DRIVERS\cdrom.sys
    \SystemRoot\system32\DRIVERS\redbook.sys
    \SystemRoot\system32\DRIVERS\ks.sys
    \SystemRoot\system32\DRIVERS\GEARAspiWDM.sys
    \SystemRoot\system32\DRIVERS\rasl2tp.sys
    \SystemRoot\system32\DRIVERS\ndistapi.sys
    \SystemRoot\system32\DRIVERS\ndiswan.sys
    \SystemRoot\system32\DRIVERS\raspppoe.sys
    \SystemRoot\system32\DRIVERS\raspptp.sys
    \SystemRoot\system32\DRIVERS\TDI.SYS
    \SystemRoot\system32\DRIVERS\psched.sys
    \SystemRoot\system32\DRIVERS\msgpc.sys
    \SystemRoot\system32\DRIVERS\ptilink.sys
    \SystemRoot\system32\DRIVERS\raspti.sys
    \SystemRoot\system32\DRIVERS\rdpdr.sys
    \SystemRoot\system32\DRIVERS\termdd.sys
    \SystemRoot\system32\DRIVERS\mouclass.sys
    \SystemRoot\system32\DRIVERS\swenum.sys
    \SystemRoot\system32\DRIVERS\update.sys
    \SystemRoot\system32\DRIVERS\mssmbios.sys
    \SystemRoot\System32\Drivers\NDProxy.SYS
    \SystemRoot\system32\DRIVERS\usbhub.sys
    \SystemRoot\system32\DRIVERS\USBD.SYS
    \SystemRoot\system32\DRIVERS\flpydisk.sys
    \SystemRoot\System32\Drivers\Fs_Rec.SYS
    \SystemRoot\System32\Drivers\Null.SYS
    \SystemRoot\System32\Drivers\Beep.SYS
    \SystemRoot\System32\drivers\vga.sys
    \SystemRoot\System32\drivers\VIDEOPRT.SYS
    \SystemRoot\System32\DRIVERS\RDPCDD.sys
    \SystemRoot\System32\Drivers\Msfs.SYS
    \SystemRoot\System32\Drivers\Npfs.SYS
    \SystemRoot\system32\DRIVERS\rasacd.sys
    \SystemRoot\system32\DRIVERS\ipsec.sys
    \SystemRoot\system32\DRIVERS\tcpip.sys
    \SystemRoot\system32\DRIVERS\avgtdix.sys
    \SystemRoot\system32\DRIVERS\ipnat.sys
    \SystemRoot\system32\DRIVERS\netbt.sys
    \SystemRoot\System32\drivers\afd.sys
    \SystemRoot\system32\DRIVERS\netbios.sys
    \SystemRoot\system32\DRIVERS\rdbss.sys
    \SystemRoot\system32\DRIVERS\mrxsmb.sys
    \SystemRoot\system32\DRIVERS\USBSTOR.SYS
    \SystemRoot\System32\Drivers\Cdfs.SYS
    \SystemRoot\system32\DRIVERS\hidusb.sys
    \SystemRoot\system32\DRIVERS\HIDCLASS.SYS
    \SystemRoot\system32\DRIVERS\HIDPARSE.SYS
    \SystemRoot\system32\DRIVERS\mouhid.sys
    \SystemRoot\System32\Drivers\dump_atapi.sys
    \SystemRoot\System32\Drivers\dump_WMILIB.SYS
    \SystemRoot\System32\win32k.sys
    \SystemRoot\System32\drivers\Dxapi.sys
    \SystemRoot\System32\watchdog.sys
    \SystemRoot\System32\drivers\dxg.sys
    \SystemRoot\System32\drivers\dxgthk.sys
    \SystemRoot\System32\framebuf.dll
    \SystemRoot\System32\ATMFD.DLL
    \SystemRoot\system32\DRIVERS\ndisuio.sys
    \SystemRoot\system32\DRIVERS\srv.sys
    \SystemRoot\System32\Drivers\Fastfat.SYS
    \??\C:\WINDOWS\system32\drivers\mbamchameleon.sys
    \??\C:\WINDOWS\system32\drivers\mbamswissarmy.sys
    \WINDOWS\system32\ntdll.dll
    ----------- End -----------
    <<<1>>>
    Upper Device Name: \Device\Harddisk2\DR3
    Upper Device Object: 0xffffffff8a0cd9c0
    Upper Device Driver Name: \Driver\Disk\
    Lower Device Name: \Device\0000007d\
    Lower Device Object: 0xffffffff8a0b9ea0
    Lower Device Driver Name: \Driver\USBSTOR\
    Driver name found: USBSTOR
    Initialization returned 0x0
    Load Function returned 0x0
    <<<1>>>
    Upper Device Name: \Device\Harddisk1\DR2
    Upper Device Object: 0xffffffff8a0bd030
    Upper Device Driver Name: \Driver\Disk\
    Lower Device Name: \Device\0000007c\
    Lower Device Object: 0xffffffff8a0c5030
    Lower Device Driver Name: \Driver\USBSTOR\
    Driver name found: USBSTOR
    <<<1>>>
    Upper Device Name: \Device\Harddisk0\DR0
    Upper Device Object: 0xffffffff8a321ab8
    Upper Device Driver Name: \Driver\Disk\
    Lower Device Name: \Device\Ide\IdeDeviceP2T0L0-17\
    Lower Device Object: 0xffffffff8a369d98
    Lower Device Driver Name: \Driver\atapi\
    Driver name found: atapi
    Initialization returned 0x0
    Load Function returned 0x0
    Initializing...
    Done!
    <<<2>>>
    Device number: 0, partition: 1
    Physical Sector Size: 512
    Drive: 0, DevicePointer: 0xffffffff8a321ab8, DeviceName: \Device\Harddisk0\DR0\, DriverName: \Driver\Disk\
    --------- Disk Stack ------
    DevicePointer: 0xffffffff8a364e08, DeviceName: Unknown, DriverName: \Driver\PartMgr\
    DevicePointer: 0xffffffff8a321ab8, DeviceName: \Device\Harddisk0\DR0\, DriverName: \Driver\Disk\
    DevicePointer: 0xffffffff8a369d98, DeviceName: \Device\Ide\IdeDeviceP2T0L0-17\, DriverName: \Driver\atapi\
    ------------ End ----------
    Alternate DeviceName: \Device\Harddisk0\DR0\, DriverName: \Driver\Disk\
    Upper DeviceData: 0xffffffffe2009b08, 0xffffffff8a321ab8, 0xffffffff89e32720
    Lower DeviceData: 0xffffffffe21deea0, 0xffffffff8a369d98, 0xffffffff89e36ab0
    <<<3>>>
    Volume: C:
    File system type: NTFS
    SectorSize = 512, ClusterSize = 4096, MFTRecordSize = 1024, MFTIndexSize = 4096 bytes
    Scanning directory: C:\WINDOWS\system32\drivers...
    <<<2>>>
    Device number: 0, partition: 1
    <<<3>>>
    Volume: C:
    File system type: NTFS
    SectorSize = 512, ClusterSize = 4096, MFTRecordSize = 1024, MFTIndexSize = 4096 bytes
    Done!
    Drive 0
    Scanning MBR on drive 0...
    Inspecting partition table:
    MBR Signature: 55AA
    Disk Signature: E654E654

    Partition information:

    Partition 0 type is Primary (0x7)
    Partition is ACTIVE.
    Partition starts at LBA: 63 Numsec = 976751937
    Partition file system is NTFS
    Partition is bootable

    Partition 1 type is Empty (0x0)
    Partition is NOT ACTIVE.
    Partition starts at LBA: 0 Numsec = 0

    Partition 2 type is Empty (0x0)
    Partition is NOT ACTIVE.
    Partition starts at LBA: 0 Numsec = 0

    Partition 3 type is Empty (0x0)
    Partition is NOT ACTIVE.
    Partition starts at LBA: 0 Numsec = 0

    Disk Size: 500107862016 bytes
    Sector size: 512 bytes

    Scanning physical sectors of unpartitioned space on drive 0 (1-62-976753168-976773168)...
    Physical Sector Size: 0
    Drive: 1, DevicePointer: 0xffffffff8a0bd030, DeviceName: \Device\Harddisk1\DR2\, DriverName: \Driver\Disk\
    --------- Disk Stack ------
    DevicePointer: 0xffffffff8a0bd6b0, DeviceName: Unknown, DriverName: \Driver\PartMgr\
    DevicePointer: 0xffffffff8a0bd030, DeviceName: \Device\Harddisk1\DR2\, DriverName: \Driver\Disk\
    DevicePointer: 0xffffffff8a0c5030, DeviceName: \Device\0000007c\, DriverName: \Driver\USBSTOR\
    ------------ End ----------
    Physical Sector Size: 0
    Drive: 2, DevicePointer: 0xffffffff8a0cd9c0, DeviceName: \Device\Harddisk2\DR3\, DriverName: \Driver\Disk\
    --------- Disk Stack ------
    DevicePointer: 0xffffffff8a0cd798, DeviceName: Unknown, DriverName: \Driver\PartMgr\
    DevicePointer: 0xffffffff8a0cd9c0, DeviceName: \Device\Harddisk2\DR3\, DriverName: \Driver\Disk\
    DevicePointer: 0xffffffff8a0b9ea0, DeviceName: \Device\0000007d\, DriverName: \Driver\USBSTOR\
    ------------ End ----------
     
  14. 2013/05/17
    chinaclipper

    chinaclipper Well-Known Member Thread Starter

    Joined:
    2010/01/20
    Messages:
    96
    Likes Received:
    0
    Part VI

    Done!
    Performing system, memory and registry scan...
    Read File: File "c:\Documents and Settings\Administrator\Application Data\desktop.ini" is compressed (flags = 1)
    Read File: File "c:\Documents and Settings\Administrator\Application Data\Microsoft\Internet Explorer\brndlog.bak" is compressed (flags = 1)
    Read File: File "c:\Documents and Settings\Administrator\Application Data\Microsoft\Internet Explorer\brndlog.txt" is compressed (flags = 1)
    Read File: File "c:\Documents and Settings\All Users\Application Data\avg9\Cfg\erd.cfg" is compressed (flags = 1)
    Read File: File "c:\Documents and Settings\All Users\Application Data\avg9\Cfg\user.cfg" is compressed (flags = 1)
    Read File: File "c:\Documents and Settings\All Users\Application Data\avg9\CfgAll\krnlall.cfg" is compressed (flags = 1)
    Read File: File "c:\Documents and Settings\All Users\Application Data\avg9\Dumps\avgtray.exe_129041179032770000.exh" is compressed (flags = 1)
    Read File: File "c:\Documents and Settings\All Users\Application Data\avg9\scanlogs\srm.idx" is compressed (flags = 1)
    Read File: File "c:\Documents and Settings\All Users\Application Data\Real\setup\config.ini" is compressed (flags = 1)
    Read File: File "c:\Documents and Settings\All Users\Application Data\TaxCut\2007\NE.txt" is compressed (flags = 1)
    Read File: File "c:\Documents and Settings\All Users\Application Data\TaxCut\2008\NE.txt" is compressed (flags = 1)
    Read File: File "c:\Documents and Settings\All Users\Application Data\TaxCut\2008\pmWCPA.08" is compressed (flags = 1)
    Read File: File "c:\Documents and Settings\All Users\Application Data\TaxCut\2009\download.cfg" is compressed (flags = 1)
    Read File: File "c:\Documents and Settings\All Users\Application Data\TaxCut\2009\NE.txt" is compressed (flags = 1)
    Read File: File "c:\Documents and Settings\All Users\Application Data\TaxCut\2009\update.tim" is compressed (flags = 1)
    Read File: File "c:\Documents and Settings\All Users\Application Data\TaxCut\2010\download.cfg" is compressed (flags = 1)
    Read File: File "c:\Documents and Settings\All Users\Application Data\TaxCut\2010\NE.txt" is compressed (flags = 1)
    Read File: File "c:\Documents and Settings\All Users\Application Data\TaxCut\2010\update.tim" is compressed (flags = 1)
    Read File: File "c:\Documents and Settings\All Users\Application Data\TaxCut\2011\NE.txt" is compressed (flags = 1)
    Read File: File "c:\Documents and Settings\All Users\Application Data\TaxCut\2011\update.tim" is compressed (flags = 1)
    Read File: File "c:\Documents and Settings\All Users\Application Data\WinZip\WinZip.addon" is compressed (flags = 1)
    Read File: File "c:\Documents and Settings\All Users\Application Data\Malwarebytes\Malwarebytes' Anti-Malware\link.txt" is compressed (flags = 1)
    Read File: File "c:\Documents and Settings\All Users\Application Data\Malwarebytes\Malwarebytes' Anti-Malware\news.txt" is compressed (flags = 1)
    Read File: File "c:\Documents and Settings\All Users\Application Data\MFAData\SelfUpd\avg.snu" is compressed (flags = 1)
    Read File: File "c:\Documents and Settings\All Users\Application Data\MFAData\SelfUpd\avgatend.stp" is compressed (flags = 1)
    Read File: File "c:\Documents and Settings\All Users\Application Data\MFAData\SelfUpd\avgatupd.stp" is compressed (flags = 1)
    Read File: File "c:\Documents and Settings\All Users\Application Data\MFAData\SelfUpd\avgupd.sig" is compressed (flags = 1)
    Read File: File "c:\Documents and Settings\All Users\Application Data\MFAData\SelfUpd\mfavera.txt" is compressed (flags = 1)
    Read File: File "c:\Documents and Settings\All Users\Application Data\MFAData\SelfUpd\mfaconf.txt" is compressed (flags = 1)
    Read File: File "c:\Documents and Settings\All Users\Application Data\MFAData\SelfUpd\mfaverx.txt" is compressed (flags = 1)
    Read File: File "c:\Documents and Settings\All Users\Application Data\Microsoft Help\Hx.hxn" is compressed (flags = 1)
    Read File: File "c:\Documents and Settings\All Users\Application Data\Microsoft Help\Hx_1033_MValidator.Lck" is compressed (flags = 1)
    Read File: File "c:\Documents and Settings\All Users\Application Data\Microsoft Help\MS.EXCEL.12.1033.hxn" is compressed (flags = 1)
    Read File: File "c:\Documents and Settings\All Users\Application Data\Microsoft Help\MS.EXCEL.DEV.12.1033.hxn" is compressed (flags = 1)
    Read File: File "c:\Documents and Settings\All Users\Application Data\Microsoft Help\MS.GRAPH.12.1033.hxn" is compressed (flags = 1)
    Read File: File "c:\Documents and Settings\All Users\Application Data\Microsoft Help\MS.GROOVE.12.1033.hxn" is compressed (flags = 1)
    Read File: File "c:\Documents and Settings\All Users\Application Data\Microsoft Help\MS.INFOPATH.12.1033.hxn" is compressed (flags = 1)
    Read File: File "c:\Documents and Settings\All Users\Application Data\Microsoft Help\MS.INFOPATHEDITOR.12.1033.hxn" is compressed (flags = 1)
    Read File: File "c:\Documents and Settings\All Users\Application Data\Microsoft Help\MS.MSACCESS.12.1033.hxn" is compressed (flags = 1)
    Read File: File "c:\Documents and Settings\All Users\Application Data\Microsoft Help\MS.MSACCESS.12.1033_1033_MValidator.Lck" is compressed (flags = 1)
    Read File: File "c:\Documents and Settings\All Users\Application Data\Microsoft Help\MS.MSE.12.1033.hxn" is compressed (flags = 1)
    Read File: File "c:\Documents and Settings\All Users\Application Data\Microsoft Help\MS.MSPUB.12.1033.hxn" is compressed (flags = 1)
    Read File: File "c:\Documents and Settings\All Users\Application Data\Microsoft Help\MS.MSPUB.12.1033_1033_MValidator.Lck" is compressed (flags = 1)
    Read File: File "c:\Documents and Settings\All Users\Application Data\Microsoft Help\MS.MSPUB.DEV.12.1033.hxn" is compressed (flags = 1)
    Read File: File "c:\Documents and Settings\All Users\Application Data\Microsoft Help\MS.MSTORE.12.1033.hxn" is compressed (flags = 1)
    Read File: File "c:\Documents and Settings\All Users\Application Data\Microsoft Help\MS.OIS.12.1033.hxn" is compressed (flags = 1)
    Read File: File "c:\Documents and Settings\All Users\Application Data\Microsoft Help\MS.ONENOTE.12.1033.hxn" is compressed (flags = 1)
    Read File: File "c:\Documents and Settings\All Users\Application Data\Microsoft Help\MS.OUTLOOK.12.1033.hxn" is compressed (flags = 1)
    Read File: File "c:\Documents and Settings\All Users\Application Data\Microsoft Help\MS.OUTLOOK.DEV.12.1033.hxn" is compressed (flags = 1)
    Read File: File "c:\Documents and Settings\All Users\Application Data\Microsoft Help\MS.POWERPNT.12.1033.hxn" is compressed (flags = 1)
    Read File: File "c:\Documents and Settings\All Users\Application Data\Microsoft Help\MS.POWERPNT.12.1033_1033_MValidator.Lck" is compressed (flags = 1)
    Read File: File "c:\Documents and Settings\All Users\Application Data\Microsoft Help\MS.POWERPNT.DEV.12.1033.hxn" is compressed (flags = 1)
    Read File: File "c:\Documents and Settings\All Users\Application Data\Microsoft Help\MS.RIBBON.12.1033.hxn" is compressed (flags = 1)
    Read File: File "c:\Documents and Settings\All Users\Application Data\Microsoft Help\MS.SETLANG.12.1033.hxn" is compressed (flags = 1)
    Read File: File "c:\Documents and Settings\All Users\Application Data\Microsoft Help\MS.WINWORD.12.1033.hxn" is compressed (flags = 1)
    Read File: File "c:\Documents and Settings\All Users\Application Data\Microsoft Help\MS.WINWORD.DEV.12.1033.hxn" is compressed (flags = 1)
    Read File: File "c:\Documents and Settings\All Users\Application Data\Microsoft Help\MS.MSACCESS.DEV.12.1033.hxn" is compressed (flags = 1)
    Read File: File "c:\Documents and Settings\All Users\Application Data\Motorola\SUE\SUE.log" is compressed (flags = 1)
    Read File: File "c:\Documents and Settings\All Users\Application Data\Carbonite\Carbonite Backup\CarboniteRestoreHistory_19691231180000.dat" is compressed (flags = 1)
    Read File: File "c:\Documents and Settings\All Users\Application Data\Common Files\BCD8515B-1A00-42E0-EC4A-1535218FA1E2.dat" is compressed (flags = 1)
    Read File: File "c:\Documents and Settings\All Users\Application Data\GARMIN\VoiceStudio\__nv.dat" is compressed (flags = 1)
    Read File: File "c:\Documents and Settings\Default User\Application Data\Microsoft\Internet Explorer\brndlog.bak" is compressed (flags = 1)
    Read File: File "c:\Documents and Settings\Default User\Application Data\Microsoft\Internet Explorer\brndlog.txt" is compressed (flags = 1)
    Read File: File "c:\Documents and Settings\Dufresne\Application Data\setup_ldm.iss" is compressed (flags = 1)
    Read File: File "c:\Documents and Settings\Dufresne\Application Data\Ahead\NeroShowTime.bmk" is compressed (flags = 1)
    Read File: File "c:\Documents and Settings\Dufresne\Application Data\Ahead\Nero Burning ROM\NeroHistory.log" is compressed (flags = 1)
    Read File: File "c:\Documents and Settings\Dufresne\Application Data\Amazon\MP3 Downloader\amazonmp3.db" is compressed (flags = 1)
    Read File: File "c:\Documents and Settings\Dufresne\Application Data\Amazon\MP3 Downloader\DownloadQueue.amz" is compressed (flags = 1)
    Read File: File "c:\Documents and Settings\Dufresne\Application Data\AnvSoft\Any DVD Converter Professional\history2.db" is compressed (flags = 1)
    Read File: File "c:\Documents and Settings\Dufresne\Application Data\AnvSoft\Any DVD Converter Professional\vdoconv.log" is compressed (flags = 1)
    Read File: File "c:\Documents and Settings\Dufresne\Application Data\AnvSoft\Any Video Converter\history2.db" is compressed (flags = 1)
    Read File: File "c:\Documents and Settings\Dufresne\Application Data\AnvSoft\Any Video Converter\vdoconv.log" is compressed (flags = 1)
    Read File: File "c:\Documents and Settings\Dufresne\Application Data\CheckPoint\ZoneAlarm Toolbar\.version" is compressed (flags = 1)
    Read File: File "c:\Documents and Settings\Dufresne\Application Data\Microsoft\LastFlashConfig.WFC" is compressed (flags = 1)
    Read File: File "c:\Documents and Settings\Dufresne\Application Data\Microsoft\Address Book\Dufresne.wab" is compressed (flags = 1)
    Read File: File "c:\Documents and Settings\Dufresne\Application Data\Microsoft\Address Book\Dufresne.wab~" is compressed (flags = 1)
    Read File: File "c:\Documents and Settings\Dufresne\Application Data\Microsoft\Clip Organizer\mstore10.mgc" is compressed (flags = 1)
    Read File: File "c:\Documents and Settings\Dufresne\Application Data\Microsoft\Clip Organizer\Offic10.MGC" is compressed (flags = 1)
    Read File: File "c:\Documents and Settings\Dufresne\Application Data\Microsoft\HTML Help\hh.dat" is compressed (flags = 1)
    Read File: File "c:\Documents and Settings\Dufresne\Application Data\Microsoft\Internet Explorer\brndlog.bak" is compressed (flags = 1)
    Read File: File "c:\Documents and Settings\Dufresne\Application Data\Microsoft\Internet Explorer\brndlog.txt" is compressed (flags = 1)
    Read File: File "c:\Documents and Settings\Dufresne\Application Data\Microsoft\MSNLiveFav\log.xsl" is compressed (flags = 1)
    Read File: File "c:\Documents and Settings\Dufresne\Application Data\Microsoft\Office\Access12.pip" is compressed (flags = 1)
    Read File: File "c:\Documents and Settings\Dufresne\Application Data\Microsoft\Office\CLView12.pip" is compressed (flags = 1)
    Read File: File "c:\Documents and Settings\Dufresne\Application Data\Microsoft\Office\MSO1036.acl" is compressed (flags = 1)
    Read File: File "c:\Documents and Settings\Dufresne\Application Data\Microsoft\Office\MSO2057.acl" is compressed (flags = 1)
    Read File: File "c:\Documents and Settings\Dufresne\Application Data\Microsoft\Office\OIS12.pip" is compressed (flags = 1)
    Read File: File "c:\Documents and Settings\Dufresne\Application Data\Microsoft\Office\OneNot12.pip" is compressed (flags = 1)
    Read File: File "c:\Documents and Settings\Dufresne\Application Data\Microsoft\Office\OrgDB12.pip" is compressed (flags = 1)
    Read File: File "c:\Documents and Settings\Dufresne\Application Data\Microsoft\Office\PowerP12.pip" is compressed (flags = 1)
    Read File: File "c:\Documents and Settings\Dufresne\Application Data\Microsoft\Office\Publis12.pip" is compressed (flags = 1)
    Read File: File "c:\Documents and Settings\Dufresne\Application Data\Microsoft\Office\VB12.pip" is compressed (flags = 1)
    Read File: File "c:\Documents and Settings\Dufresne\Application Data\Microsoft\OIS\Toolbars.dat" is compressed (flags = 1)
    Read File: File "c:\Documents and Settings\Dufresne\Application Data\Microsoft\PowerPoint\PPT12.pcb" is compressed (flags = 1)
    Read File: File "c:\Documents and Settings\Dufresne\Application Data\Microsoft\Publisher\pubcmd12.dat" is compressed (flags = 1)
    Read File: File "c:\Documents and Settings\Dufresne\Application Data\Microsoft\Templates\Drum sheet music (OneNote 2003 Format).one.backup" is compressed (flags = 1)
    Read File: File "c:\Documents and Settings\Dufresne\Application Data\Microsoft\Templates\Drum sheet music.one" is compressed (flags = 1)
    Read File: File "c:\Documents and Settings\Dufresne\Application Data\Microsoft\Templates\My Templates.one" is compressed (flags = 1)
    Read File: File "c:\Documents and Settings\Dufresne\Application Data\Microsoft\Templates\Normal.BAK" is compressed (flags = 1)
    Read File: File "c:\Documents and Settings\Dufresne\Application Data\Microsoft\Templates\OneNote Table Of Contents.onetoc2" is compressed (flags = 1)
    Read File: File "c:\Documents and Settings\Dufresne\Application Data\Microsoft\UProof\ExcludeDictionaryEN0809.lex" is compressed (flags = 1)
    Read File: File "c:\Documents and Settings\Dufresne\Application Data\Move Networks\QMCache00\A0C97106E5B54BA28D878F37B38B4B19000004C800C8C7C90ABF1.qss" is compressed (flags = 1)
    Read File: File "c:\Documents and Settings\Dufresne\Application Data\Move Networks\QMCache00\A0C97106E5B54BA28D878F37B38B4B19000004C900C8824C0B8FB.qss" is compressed (flags = 1)
    Read File: File "c:\Documents and Settings\Dufresne\Application Data\Move Networks\QMCache00\A0C97106E5B54BA28D878F37B38B4B19000004CA00C845BF06468.qss" is compressed (flags = 1)
    Read File: File "c:\Documents and Settings\Dufresne\Application Data\Move Networks\QMCache00\A0C97106E5B54BA28D878F37B38B4B19000004CB00C81B1309048.qss" is compressed (flags = 1)
    Read File: File "c:\Documents and Settings\Dufresne\Application Data\Move Networks\QMCache00\A0C97106E5B54BA28D878F37B38B4B19000004CC00C81A630791D.qss" is compressed (flags = 1)
    Read File: File "c:\Documents and Settings\Dufresne\Application Data\Move Networks\QMCache00\A0C97106E5B54BA28D878F37B38B4B19000004CD00C8C37203866.qss" is compressed (flags = 1)
    Read File: File "c:\Documents and Settings\Dufresne\Application Data\Move Networks\QMCache00\A0C97106E5B54BA28D878F37B38B4B19000004CE00C8320F0C6E4.qss" is compressed (flags = 1)
    Read File: File "c:\Documents and Settings\Dufresne\Application Data\Move Networks\QMCache00\A0C97106E5B54BA28D878F37B38B4B19000004CF00C8343F079F6.qss" is compressed (flags = 1)
    Read File: File "c:\Documents and Settings\Dufresne\Application Data\Move Networks\QMCache00\A0C97106E5B54BA28D878F37B38B4B19000004D000C8087009ACD.qss" is compressed (flags = 1)
    Read File: File "c:\Documents and Settings\Dufresne\Application Data\Move Networks\QMCache00\A0C97106E5B54BA28D878F37B38B4B190000049400C8D8F109219.qss" is compressed (flags = 1)
    Read File: File "c:\Documents and Settings\Dufresne\Application Data\Move Networks\QMCache00\A0C97106E5B54BA28D878F37B38B4B190000049500C892DD076B8.qss" is compressed (flags = 1)
    Read File: File "c:\Documents and Settings\Dufresne\Application Data\Move Networks\QMCache00\A0C97106E5B54BA28D878F37B38B4B190000049600C896D607236.qss" is compressed (flags = 1)
    Read File: File "c:\Documents and Settings\Dufresne\Application Data\Move Networks\QMCache00\A0C97106E5B54BA28D878F37B38B4B190000049700C8253F0A9CB.qss" is compressed (flags = 1)
    Read File: File "c:\Documents and Settings\Dufresne\Application Data\Move Networks\QMCache00\A0C97106E5B54BA28D878F37B38B4B190000049800C7A4D6034E7.qss" is compressed (flags = 1)
    Read File: File "c:\Documents and Settings\Dufresne\Application Data\Move Networks\QMCache00\A0C97106E5B54BA28D878F37B38B4B190000049900C7802B04D5F.qss" is compressed (flags = 1)
    Read File: File "c:\Documents and Settings\Dufresne\Application Data\Move Networks\QMCache00\A0C97106E5B54BA28D878F37B38B4B190000049A00C7B09D058D7.qss" is compressed (flags = 1)
    Read File: File "c:\Documents and Settings\Dufresne\Application Data\Move Networks\QMCache00\A0C97106E5B54BA28D878F37B38B4B190000049B00C855A8050C7.qss" is compressed (flags = 1)
    Read File: File "c:\Documents and Settings\Dufresne\Application Data\Move Networks\QMCache00\A0C97106E5B54BA28D878F37B38B4B190000049C00C79CAD04448.qss" is compressed (flags = 1)
    Read File: File "c:\Documents and Settings\Dufresne\Application Data\Move Networks\QMCache00\A0C97106E5B54BA28D878F37B38B4B19000004D200C7EC2D09F3E.qss" is compressed (flags = 1)
    Read File: File "c:\Documents and Settings\Dufresne\Application Data\Move Networks\QMCache00\A0C97106E5B54BA28D878F37B38B4B19000004D300C7E8F909E34.qss" is compressed (flags = 1)
    Read File: File "c:\Documents and Settings\Dufresne\Application Data\Move Networks\QMCache00\A0C97106E5B54BA28D878F37B38B4B19000004D400C84F5D09FDD.qss" is compressed (flags = 1)
    Read File: File "c:\Documents and Settings\Dufresne\Application Data\Move Networks\QMCache00\A0C97106E5B54BA28D878F37B38B4B19000004D500C86CB808E2E.qss" is compressed (flags = 1)
    Read File: File "c:\Documents and Settings\Dufresne\Application Data\Move Networks\QMCache00\A0C97106E5B54BA28D878F37B38B4B19000004D600C8607109A99.qss" is compressed (flags = 1)
    Read File: File "c:\Documents and Settings\Dufresne\Application Data\Move Networks\QMCache00\A0C97106E5B54BA28D878F37B38B4B19000004D700C780410A168.qss" is compressed (flags = 1)
    Read File: File "c:\Documents and Settings\Dufresne\Application Data\Move Networks\QMCache00\A0C97106E5B54BA28D878F37B38B4B19000004D800C74B230741A.qss" is compressed (flags = 1)
    Read File: File "c:\Documents and Settings\Dufresne\Application Data\Move Networks\QMCache00\A0C97106E5B54BA28D878F37B38B4B19000004D900C6F780072E0.qss" is compressed (flags = 1)
    Read File: File "c:\Documents and Settings\Dufresne\Application Data\Move Networks\QMCache00\A0C97106E5B54BA28D878F37B38B4B19000004DA00C69BA8040AC.qss" is compressed (flags = 1)
    Read File: File "c:\Documents and Settings\Dufresne\Application Data\Move Networks\QMCache00\A0C97106E5B54BA28D878F37B38B4B19000004B200C8A5A30A1EE.qss" is compressed (flags = 1)
    Read File: File "c:\Documents and Settings\Dufresne\Application Data\Move Networks\QMCache00\A0C97106E5B54BA28D878F37B38B4B19000004B300C7BB6003EBC.qss" is compressed (flags = 1)
    Read File: File "c:\Documents and Settings\Dufresne\Application Data\Move Networks\QMCache00\A0C97106E5B54BA28D878F37B38B4B19000004B400C7AFB40230C.qss" is compressed (flags = 1)
    Read File: File "c:\Documents and Settings\Dufresne\Application Data\Move Networks\QMCache00\A0C97106E5B54BA28D878F37B38B4B19000004B500C7CA1E0562E.qss" is compressed (flags = 1)
    Read File: File "c:\Documents and Settings\Dufresne\Application Data\Move Networks\QMCache00\A0C97106E5B54BA28D878F37B38B4B19000004B600C7BD2805296.qss" is compressed (flags = 1)
    Read File: File "c:\Documents and Settings\Dufresne\Application Data\Move Networks\QMCache00\A0C97106E5B54BA28D878F37B38B4B19000004B700C7654904187.qss" is compressed (flags = 1)
    Read File: File "c:\Documents and Settings\Dufresne\Application Data\Move Networks\QMCache00\A0C97106E5B54BA28D878F37B38B4B19000004B800C7694F04ACE.qss" is compressed (flags = 1)
    Read File: File "c:\Documents and Settings\Dufresne\Application Data\Move Networks\QMCache00\A0C97106E5B54BA28D878F37B38B4B19000004B900C7CD4D04B4C.qss" is compressed (flags = 1)
    Read File: File "c:\Documents and Settings\Dufresne\Application Data\Move Networks\QMCache00\A0C97106E5B54BA28D878F37B38B4B19000004BA00C7CADE0522E.qss" is compressed (flags = 1)
    Read File: File "c:\Documents and Settings\Dufresne\Application Data\Move Networks\QMCache00\A0C97106E5B54BA28D878F37B38B4B19000004BB00C775EC05750.qss" is compressed (flags = 1)
    Read File: File "c:\Documents and Settings\Dufresne\Application Data\Move Networks\QMCache00\A0C97106E5B54BA28D878F37B38B4B19000004BC00C7C001054FB.qss" is compressed (flags = 1)
    Read File: File "c:\Documents and Settings\Dufresne\Application Data\Move Networks\QMCache00\A0C97106E5B54BA28D878F37B38B4B190000046200C74CCA02CA0.qss" is compressed (flags = 1)
    Read File: File "c:\Documents and Settings\Dufresne\Application Data\Move Networks\QMCache00\A0C97106E5B54BA28D878F37B38B4B190000046300C6D49506082.qss" is compressed (flags = 1)
    Read File: File "c:\Documents and Settings\Dufresne\Application Data\Move Networks\QMCache00\A0C97106E5B54BA28D878F37B38B4B190000046400C81FA3058B6.qss" is compressed (flags = 1)
    Read File: File "c:\Documents and Settings\Dufresne\Application Data\Move Networks\QMCache00\A0C97106E5B54BA28D878F37B38B4B190000046500C84B8B0A4EC.qss" is compressed (flags = 1)
    Read File: File "c:\Documents and Settings\Dufresne\Application Data\Move Networks\QMCache00\A0C97106E5B54BA28D878F37B38B4B190000046600C881B20A39B.qss" is compressed (flags = 1)
    Read File: File "c:\Documents and Settings\Dufresne\Application Data\Move Networks\QMCache00\A0C97106E5B54BA28D878F37B38B4B190000046700C791A70741F.qss" is compressed (flags = 1)
    Read File: File "c:\Documents and Settings\Dufresne\Application Data\Move Networks\QMCache00\A0C97106E5B54BA28D878F37B38B4B190000046800C8B0D705CA3.qss" is compressed (flags = 1)
    Read File: File "c:\Documents and Settings\Dufresne\Application Data\Move Networks\QMCache00\A0C97106E5B54BA28D878F37B38B4B190000046900C8E5220C5CD.qss" is compressed (flags = 1)
    Read File: File "c:\Documents and Settings\Dufresne\Application Data\Move Networks\QMCache00\A0C97106E5B54BA28D878F37B38B4B190000046A00C8EF110BEA3.qss" is compressed (flags = 1)
    Read File: File "c:\Documents and Settings\Dufresne\Application Data\Move Networks\QMCache00\A0C97106E5B54BA28D878F37B38B4B19000004DC00C669CE033E4.qss" is compressed (flags = 1)
    Read File: File "c:\Documents and Settings\Dufresne\Application Data\Move Networks\QMCache00\A0C97106E5B54BA28D878F37B38B4B19000004DD00C6F7F502F8A.qss" is compressed (flags = 1)
    Read File: File "c:\Documents and Settings\Dufresne\Application Data\Move Networks\QMCache00\A0C97106E5B54BA28D878F37B38B4B19000004DE00C675BC03404.qss" is compressed (flags = 1)
    Read File: File "c:\Documents and Settings\Dufresne\Application Data\Move Networks\QMCache00\A0C97106E5B54BA28D878F37B38B4B19000004DF00C683CE02D29.qss" is compressed (flags = 1)
    Read File: File "c:\Documents and Settings\Dufresne\Application Data\Move Networks\QMCache00\A0C97106E5B54BA28D878F37B38B4B19000004E000C7B4FD04274.qss" is compressed (flags = 1)
    Read File: File "c:\Documents and Settings\Dufresne\Application Data\Move Networks\QMCache00\A0C97106E5B54BA28D878F37B38B4B19000004E100C72795047A7.qss" is compressed (flags = 1)
    Read File: File "c:\Documents and Settings\Dufresne\Application Data\Move Networks\QMCache00\A0C97106E5B54BA28D878F37B38B4B19000004E200C7E44C0359F.qss" is compressed (flags = 1)
    Read File: File "c:\Documents and Settings\Dufresne\Application Data\Move Networks\QMCache00\A0C97106E5B54BA28D878F37B38B4B19000004E300C6FED5064A0.qss" is compressed (flags = 1)
    Read File: File "c:\Documents and Settings\Dufresne\Application Data\Move Networks\QMCache00\A0C97106E5B54BA28D878F37B38B4B19000004E400C7E7F603C48.qss" is compressed (flags = 1)
    Read File: File "c:\Documents and Settings\Dufresne\Application Data\Move Networks\QMCache00\A0C97106E5B54BA28D878F37B38B4B190000046C00C8C4E70B644.qss" is compressed (flags = 1)
    Read File: File "c:\Documents and Settings\Dufresne\Application Data\Move Networks\QMCache00\A0C97106E5B54BA28D878F37B38B4B190000046D00C8D84C09EA7.qss" is compressed (flags = 1)
    Read File: File "c:\Documents and Settings\Dufresne\Application Data\Move Networks\QMCache00\A0C97106E5B54BA28D878F37B38B4B190000046E00C8CA940BD5A.qss" is compressed (flags = 1)
    Read File: File "c:\Documents and Settings\Dufresne\Application Data\Move Networks\QMCache00\A0C97106E5B54BA28D878F37B38B4B190000046F00C8C9710C943.qss" is compressed (flags = 1)
    Read File: File "c:\Documents and Settings\Dufresne\Application Data\Move Networks\QMCache00\A0C97106E5B54BA28D878F37B38B4B190000047000C7507307EB1.qss" is compressed (flags = 1)
    Read File: File "c:\Documents and Settings\Dufresne\Application Data\Move Networks\QMCache00\A0C97106E5B54BA28D878F37B38B4B190000047100C7CB1F06265.qss" is compressed (flags = 1)
    Read File: File "c:\Documents and Settings\Dufresne\Application Data\Move Networks\QMCache00\A0C97106E5B54BA28D878F37B38B4B190000047200C74EE302D6A.qss" is compressed (flags = 1)
    Read File: File "c:\Documents and Settings\Dufresne\Application Data\Move Networks\QMCache00\A0C97106E5B54BA28D878F37B38B4B190000047300C735BA04C0E.qss" is compressed (flags = 1)
    Read File: File "c:\Documents and Settings\Dufresne\Application Data\Move Networks\QMCache00\A0C97106E5B54BA28D878F37B38B4B190000047400C6FD0904395.qss" is compressed (flags = 1)
    Read File: File "c:\Documents and Settings\Dufresne\Application Data\Move Networks\QMCache00\A0C97106E5B54BA28D878F37B38B4B19000004E600C84240076FD.qss" is compressed (flags = 1)
    Read File: File "c:\Documents and Settings\Dufresne\Application Data\Move Networks\QMCache00\A0C97106E5B54BA28D878F37B38B4B19000004E700C7379707356.qss" is compressed (flags = 1)
    Read File: File "c:\Documents and Settings\Dufresne\Application Data\Move Networks\QMCache00\A0C97106E5B54BA28D878F37B38B4B19000004E800C741CD03F96.qss" is compressed (flags = 1)
    Read File: File "c:\Documents and Settings\Dufresne\Application Data\Move Networks\QMCache00\A0C97106E5B54BA28D878F37B38B4B19000004E900C6E22E06EEF.qss" is compressed (flags = 1)
    Read File: File "c:\Documents and Settings\Dufresne\Application Data\Move Networks\QMCache00\A0C97106E5B54BA28D878F37B38B4B19000004EA00C6F63A03B6D.qss" is compressed (flags = 1)
    Read File: File "c:\Documents and Settings\Dufresne\Application Data\Move Networks\QMCache00\A0C97106E5B54BA28D878F37B38B4B19000004EB00C66036033B5.qss" is compressed (flags = 1)
    Read File: File "c:\Documents and Settings\Dufresne\Application Data\Move Networks\QMCache00\A0C97106E5B54BA28D878F37B38B4B19000004EC00C6D3BA044FE.qss" is compressed (flags = 1)
    Read File: File "c:\Documents and Settings\Dufresne\Application Data\Move Networks\QMCache00\A0C97106E5B54BA28D878F37B38B4B19000004ED00C7264C0454A.qss" is compressed (flags = 1)
    Read File: File "c:\Documents and Settings\Dufresne\Application Data\Move Networks\QMCache00\A0C97106E5B54BA28D878F37B38B4B19000004EE00C7462F05783.qss" is compressed (flags = 1)
    Read File: File "c:\Documents and Settings\Dufresne\Application Data\Move Networks\QMCache00\A0C97106E5B54BA28D878F37B38B4B19000004F000C7254E03BBB.qss" is compressed (flags = 1)
    Read File: File "c:\Documents and Settings\Dufresne\Application Data\Move Networks\QMCache00\A0C97106E5B54BA28D878F37B38B4B19000004F100C7477203721.qss" is compressed (flags = 1)
    Read File: File "c:\Documents and Settings\Dufresne\Application Data\Move Networks\QMCache00\A0C97106E5B54BA28D878F37B38B4B19000004F200C6BDF903B06.qss" is compressed (flags = 1)
    Read File: File "c:\Documents and Settings\Dufresne\Application Data\Move Networks\QMCache00\A0C97106E5B54BA28D878F37B38B4B19000004F300C6B9860382E.qss" is compressed (flags = 1)
    Read File: File "c:\Documents and Settings\Dufresne\Application Data\Move Networks\QMCache00\A0C97106E5B54BA28D878F37B38B4B19000004F400C6A4E20394D.qss" is compressed (flags = 1)
    Read File: File "c:\Documents and Settings\Dufresne\Application Data\Move Networks\QMCache00\A0C97106E5B54BA28D878F37B38B4B19000004F500C693A3036CC.qss" is compressed (flags = 1)
    Read File: File "c:\Documents and Settings\Dufresne\Application Data\Move Networks\QMCache00\A0C97106E5B54BA28D878F37B38B4B19000004F600C6BF6F038AE.qss" is compressed (flags = 1)
    Read File: File "c:\Documents and Settings\Dufresne\Application Data\Move Networks\QMCache00\A0C97106E5B54BA28D878F37B38B4B19000004F700C6CA1D03D8F.qss" is compressed (flags = 1)
    Read File: File "c:\Documents and Settings\Dufresne\Application Data\Move Networks\QMCache00\A0C97106E5B54BA28D878F37B38B4B19000004F800C6B9330418C.qss" is compressed (flags = 1)
    Read File: File "c:\Documents and Settings\Dufresne\Application Data\Move Networks\QMCache00\A0C97106E5B54BA28D878F37B38B4B190000050E00C627BE035B3.qss" is compressed (flags = 1)
    Read File: File "c:\Documents and Settings\Dufresne\Application Data\Move Networks\QMCache00\A0C97106E5B54BA28D878F37B38B4B190000050F00C65217036E4.qss" is compressed (flags = 1)
    Read File: File "c:\Documents and Settings\Dufresne\Application Data\Move Networks\QMCache00\A0C97106E5B54BA28D878F37B38B4B190000051000C5897703684.qss" is compressed (flags = 1)
    Read File: File "c:\Documents and Settings\Dufresne\Application Data\Move Networks\QMCache00\A0C97106E5B54BA28D878F37B38B4B190000051100C086B30085B.qss" is compressed (flags = 1)
    Read File: File "c:\Documents and Settings\Dufresne\Application Data\Move Networks\QMCache00\A0C97106E5B54BA28D878F37B38B4B190000051200C0C4FD0085B.qss" is compressed (flags = 1)
    Read File: File "c:\Documents and Settings\Dufresne\Application Data\Move Networks\QMCache00\A0C97106E5B54BA28D878F37B38B4B190000051300C122E901E2C.qss" is compressed (flags = 1)
    Read File: File "c:\Documents and Settings\Dufresne\Application Data\Move Networks\QMCache00\A0C97106E5B54BA28D878F37B38B4B190000051400C11B590195A.qss" is compressed (flags = 1)
    Read File: File "c:\Documents and Settings\Dufresne\Application Data\Move Networks\QMCache00\A0C97106E5B54BA28D878F37B38B4B190000051500C13E140348C.qss" is compressed (flags = 1)
    Read File: File "c:\Documents and Settings\Dufresne\Application Data\Move Networks\QMCache00\A0C97106E5B54BA28D878F37B38B4B190000051600C16B2B031AE.qss" is compressed (flags = 1)
    Read File: File "c:\Documents and Settings\Dufresne\Application Data\Move Networks\QMCache00\E30E776DE3C9447CBBE9CEB8A7AC0FE7000000090094C40D0423C.qss" is compressed (flags = 1)
    Read File: File "c:\Documents and Settings\Dufresne\Application Data\Move Networks\QMCache00\E30E776DE3C9447CBBE9CEB8A7AC0FE70000000A0094C8D90484F.qss" is compressed (flags = 1)
    Read File: File "c:\Documents and Settings\Dufresne\Application Data\Move Networks\QMCache00\E30E776DE3C9447CBBE9CEB8A7AC0FE70000000B00953DAA02B8C.qss" is compressed (flags = 1)
    Read File: File "c:\Documents and Settings\Dufresne\Application Data\Move Networks\QMCache00\E30E776DE3C9447CBBE9CEB8A7AC0FE70000000C009472B403307.qss" is compressed (flags = 1)
    Read File: File "c:\Documents and Settings\Dufresne\Application Data\Move Networks\QMCache00\E30E776DE3C9447CBBE9CEB8A7AC0FE70000000D00945EE703193.qss" is compressed (flags = 1)
    Read File: File "c:\Documents and Settings\Dufresne\Application Data\Move Networks\QMCache00\E30E776DE3C9447CBBE9CEB8A7AC0FE70000000E0094D45902121.qss" is compressed (flags = 1)
    Read File: File "c:\Documents and Settings\Dufresne\Application Data\Move Networks\QMCache00\E30E776DE3C9447CBBE9CEB8A7AC0FE70000000F0092B807020F7.qss" is compressed (flags = 1)
    Read File: File "c:\Documents and Settings\Dufresne\Application Data\Move Networks\QMCache00\E30E776DE3C9447CBBE9CEB8A7AC0FE7000000100090CBC802A02.qss" is compressed (flags = 1)
    Read File: File "c:\Documents and Settings\Dufresne\Application Data\Move Networks\QMCache00\A0C97106E5B54BA28D878F37B38B4B19000003E900C840040611C.qss" is compressed (flags = 1)
    Read File: File "c:\Documents and Settings\Dufresne\Application Data\Move Networks\QMCache00\A0C97106E5B54BA28D878F37B38B4B19000003F300C8622505D54.qss" is compressed (flags = 1)
    Read File: File "c:\Documents and Settings\Dufresne\Application Data\Move Networks\QMCache00\A0C97106E5B54BA28D878F37B38B4B19000004BE00C7ADC204BBB.qss" is compressed (flags = 1)
    Read File: File "c:\Documents and Settings\Dufresne\Application Data\Move Networks\QMCache00\A0C97106E5B54BA28D878F37B38B4B19000004BF00C7A71C04890.qss" is compressed (flags = 1)
    Read File: File "c:\Documents and Settings\Dufresne\Application Data\Move Networks\QMCache00\A0C97106E5B54BA28D878F37B38B4B19000004C000C7381505BA1.qss" is compressed (flags = 1)
    Read File: File "c:\Documents and Settings\Dufresne\Application Data\Move Networks\QMCache00\A0C97106E5B54BA28D878F37B38B4B19000004C100C854B307989.qss" is compressed (flags = 1)
    Read File: File "c:\Documents and Settings\Dufresne\Application Data\Move Networks\QMCache00\A0C97106E5B54BA28D878F37B38B4B19000004C200C8559907BBC.qss" is compressed (flags = 1)
    Read File: File "c:\Documents and Settings\Dufresne\Application Data\Move Networks\QMCache00\A0C97106E5B54BA28D878F37B38B4B19000004C300C87A7F05832.qss" is compressed (flags = 1)
    Read File: File "c:\Documents and Settings\Dufresne\Application Data\Move Networks\QMCache00\A0C97106E5B54BA28D878F37B38B4B19000004C400C87D4F0A2F5.qss" is compressed (flags = 1)
    Read File: File "c:\Documents and Settings\Dufresne\Application Data\Move Networks\QMCache00\A0C97106E5B54BA28D878F37B38B4B19000004C500C85FF90A352.qss" is compressed (flags = 1)
    Read File: File "c:\Documents and Settings\Dufresne\Application Data\Move Networks\QMCache00\A0C97106E5B54BA28D878F37B38B4B19000004C600C872E20837F.qss" is compressed (flags = 1)
    Read File: File "c:\Documents and Settings\Dufresne\Application Data\Move Networks\QMCache00\A0C97106E5B54BA28D878F37B38B4B19000003E700C85A2605810.qss" is compressed (flags = 1)
    Read File: File "c:\Documents and Settings\Dufresne\Application Data\Move Networks\QMCache00\A0C97106E5B54BA28D878F37B38B4B19000003E800C7CC430276F.qss" is compressed (flags = 1)
    Read File: File "c:\Documents and Settings\Dufresne\Application Data\Move Networks\QMCache00\A0C97106E5B54BA28D878F37B38B4B19000003EA00C8146905366.qss" is compressed (flags = 1)
    Read File: File "c:\Documents and Settings\Dufresne\Application Data\Move Networks\QMCache00\A0C97106E5B54BA28D878F37B38B4B19000003EB00C88D9806FCC.qss" is compressed (flags = 1)
    Read File: File "c:\Documents and Settings\Dufresne\Application Data\Move Networks\QMCache00\A0C97106E5B54BA28D878F37B38B4B19000003EC00C83F2306FD5.qss" is compressed (flags = 1)
    Read File: File "c:\Documents and Settings\Dufresne\Application Data\Move Networks\QMCache00\A0C97106E5B54BA28D878F37B38B4B19000003ED00C8604A04AF0.qss" is compressed (flags = 1)
    Read File: File "c:\Documents and Settings\Dufresne\Application Data\Move Networks\QMCache00\A0C97106E5B54BA28D878F37B38B4B19000003EE00C8710105DDC.qss" is compressed (flags = 1)
    Read File: File "c:\Documents and Settings\Dufresne\Application Data\Move Networks\QMCache00\A0C97106E5B54BA28D878F37B38B4B19000003EF00C8712F069BE.qss" is compressed (flags = 1)
    Read File: File "c:\Documents and Settings\Dufresne\Application Data\Move Networks\QMCache00\A0C97106E5B54BA28D878F37B38B4B19000003F000C7F07F0642D.qss" is compressed (flags = 1)
    Read File: File "c:\Documents and Settings\Dufresne\Application Data\Move Networks\QMCache00\A0C97106E5B54BA28D878F37B38B4B19000003F100C8747206BC3.qss" is compressed (flags = 1)
    Read File: File "c:\Documents and Settings\Dufresne\Application Data\Move Networks\QMCache00\A0C97106E5B54BA28D878F37B38B4B19000003F200C8727804E85.qss" is compressed (flags = 1)
    Read File: File "c:\Documents and Settings\Dufresne\Application Data\Move Networks\QMCache00\A0C97106E5B54BA28D878F37B38B4B19000003F400C855C006505.qss" is compressed (flags = 1)
    Read File: File "c:\Documents and Settings\Dufresne\Application Data\Move Networks\QMCache00\A0C97106E5B54BA28D878F37B38B4B19000003F500C8631801F21.qss" is compressed (flags = 1)
    Read File: File "c:\Documents and Settings\Dufresne\Application Data\Move Networks\QMCache00\A0C97106E5B54BA28D878F37B38B4B19000003F600C898CF0611A.qss" is compressed (flags = 1)
    Read File: File "c:\Documents and Settings\Dufresne\Application Data\Move Networks\QMCache00\A0C97106E5B54BA28D878F37B38B4B19000003F700C885D90AB36.qss" is compressed (flags = 1)
    Read File: File "c:\Documents and Settings\Dufresne\Application Data\Move Networks\QMCache00\A0C97106E5B54BA28D878F37B38B4B19000003F800C8C0000845E.qss" is compressed (flags = 1)
    Read File: File "c:\Documents and Settings\Dufresne\Application Data\Move Networks\QMCache00\A0C97106E5B54BA28D878F37B38B4B19000003F900C8AB0307F13.qss" is compressed (flags = 1)
    Read File: File "c:\Documents and Settings\Dufresne\Application Data\Move Networks\QMCache00\A0C97106E5B54BA28D878F37B38B4B19000003FA00C9011A0818C.qss" is compressed (flags = 1)
    Read File: File "c:\Documents and Settings\Dufresne\Application Data\Move Networks\QMCache00\A0C97106E5B54BA28D878F37B38B4B19000003FB00C8A04B0C4D7.qss" is compressed (flags = 1)
    Read File: File "c:\Documents and Settings\Dufresne\Application Data\Move Networks\QMCache00\A0C97106E5B54BA28D878F37B38B4B19000003FC00C8534009573.qss" is compressed (flags = 1)
    Read File: File "c:\Documents and Settings\Dufresne\Application Data\Move Networks\QMCache00\A0C97106E5B54BA28D878F37B38B4B19000003FE00C7A531028FB.qss" is compressed (flags = 1)
    Read File: File "c:\Documents and Settings\Dufresne\Application Data\Move Networks\QMCache00\A0C97106E5B54BA28D878F37B38B4B19000003FF00C8AF37030B8.qss" is compressed (flags = 1)
    Read File: File "c:\Documents and Settings\Dufresne\Application Data\Move Networks\QMCache00\A0C97106E5B54BA28D878F37B38B4B190000040000C825E20A621.qss" is compressed (flags = 1)
    Read File: File "c:\Documents and Settings\Dufresne\Application Data\Move Networks\QMCache00\A0C97106E5B54BA28D878F37B38B4B190000040100C8299503811.qss" is compressed (flags = 1)
    Read File: File "c:\Documents and Settings\Dufresne\Application Data\Move Networks\QMCache00\A0C97106E5B54BA28D878F37B38B4B190000040200C85711027C4.qss" is compressed (flags = 1)
    Read File: File "c:\Documents and Settings\Dufresne\Application Data\Move Networks\QMCache00\A0C97106E5B54BA28D878F37B38B4B190000040300C8141804EAA.qss" is compressed (flags = 1)
    Read File: File "c:\Documents and Settings\Dufresne\Application Data\Move Networks\QMCache00\A0C97106E5B54BA28D878F37B38B4B190000040400C8C480053C6.qss" is compressed (flags = 1)
    Read File: File "c:\Documents and Settings\Dufresne\Application Data\Move Networks\QMCache00\A0C97106E5B54BA28D878F37B38B4B190000040500C8060605450.qss" is compressed (flags = 1)
    Read File: File "c:\Documents and Settings\Dufresne\Application Data\Move Networks\QMCache00\A0C97106E5B54BA28D878F37B38B4B190000040600C7F54E052CD.qss" is compressed (flags = 1)
    Read File: File "c:\Documents and Settings\Dufresne\Application Data\Move Networks\QMCache00\A0C97106E5B54BA28D878F37B38B4B190000040800C7EFA60521E.qss" is compressed (flags = 1)
    Read File: File "c:\Documents and Settings\Dufresne\Application Data\Move Networks\QMCache00\A0C97106E5B54BA28D878F37B38B4B190000040900C8517402695.qss" is compressed (flags = 1)
    Read File: File "c:\Documents and Settings\Dufresne\Application Data\Move Networks\QMCache00\A0C97106E5B54BA28D878F37B38B4B190000040A00C844240845C.qss" is compressed (flags = 1)
    Read File: File "c:\Documents and Settings\Dufresne\Application Data\Move Networks\QMCache00\A0C97106E5B54BA28D878F37B38B4B190000040B00C846540837C.qss" is compressed (flags = 1)
    Read File: File "c:\Documents and Settings\Dufresne\Application Data\Move Networks\QMCache00\A0C97106E5B54BA28D878F37B38B4B190000040C00C855E907150.qss" is compressed (flags = 1)
    Read File: File "c:\Documents and Settings\Dufresne\Application Data\Move Networks\QMCache00\A0C97106E5B54BA28D878F37B38B4B190000040D00C83C4F05F9F.qss" is compressed (flags = 1)
    Read File: File "c:\Documents and Settings\Dufresne\Application Data\Move Networks\QMCache00\A0C97106E5B54BA28D878F37B38B4B190000040E00C823CC06021.qss" is compressed (flags = 1)
    Read File: File "c:\Documents and Settings\Dufresne\Application Data\Move Networks\QMCache00\A0C97106E5B54BA28D878F37B38B4B190000040F00C8292507088.qss" is compressed (flags = 1)
    Read File: File "c:\Documents and Settings\Dufresne\Application Data\Move Networks\QMCache00\A0C97106E5B54BA28D878F37B38B4B190000041000C852B90703B.qss" is compressed (flags = 1)
    Read File: File "c:\Documents and Settings\Dufresne\Application Data\Move Networks\QMCache00\A0C97106E5B54BA28D878F37B38B4B190000041200C8C9D409B7C.qss" is compressed (flags = 1)
    Read File: File "c:\Documents and Settings\Dufresne\Application Data\Move Networks\QMCache00\A0C97106E5B54BA28D878F37B38B4B190000041300C7737E0549D.qss" is compressed (flags = 1)
    Read File: File "c:\Documents and Settings\Dufresne\Application Data\Move Networks\QMCache00\A0C97106E5B54BA28D878F37B38B4B190000041400C80C6007290.qss" is compressed (flags = 1)
    Read File: File "c:\Documents and Settings\Dufresne\Application Data\Move Networks\QMCache00\A0C97106E5B54BA28D878F37B38B4B190000041500C8719705E92.qss" is compressed (flags = 1)
    Read File: File "c:\Documents and Settings\Dufresne\Application Data\Move Networks\QMCache00\A0C97106E5B54BA28D878F37B38B4B190000041600C2660A058EC.qss" is compressed (flags = 1)
    Read File: File "c:\Documents and Settings\Dufresne\Application Data\Move Networks\QMCache00\A0C97106E5B54BA28D878F37B38B4B190000041700C0ABCD0085B.qss" is compressed (flags = 1)
    Read File: File "c:\Documents and Settings\Dufresne\Application Data\Move Networks\QMCache00\A0C97106E5B54BA28D878F37B38B4B190000041800C7C6090085B.qss" is compressed (flags = 1)
    Read File: File "c:\Documents and Settings\Dufresne\Application Data\Move Networks\QMCache00\A0C97106E5B54BA28D878F37B38B4B190000041900C81AD8070B6.qss" is compressed (flags = 1)
    Read File: File "c:\Documents and Settings\Dufresne\Application Data\Move Networks\QMCache00\A0C97106E5B54BA28D878F37B38B4B190000041A00C7A5AA06D92.qss" is compressed (flags = 1)
    Read File: File "c:\Documents and Settings\Dufresne\Application Data\Move Networks\QMCache00\E5FE5D98E7E249DE80B3754EA2242B350000000100B5DE62006F0.qss" is compressed (flags = 1)
    Read File: File "c:\Documents and Settings\Dufresne\Application Data\Move Networks\QMCache00\E5FE5D98E7E249DE80B3754EA2242B350000000200B63C0903517.qss" is compressed (flags = 1)
    Read File: File "c:\Documents and Settings\Dufresne\Application Data\Move Networks\QMCache00\E5FE5D98E7E249DE80B3754EA2242B350000000200C733AB03EEB.qss" is compressed (flags = 1)
    Read File: File "c:\Documents and Settings\Dufresne\Application Data\Move Networks\QMCache00\E5FE5D98E7E249DE80B3754EA2242B350000000300B5B31802B7E.qss" is compressed (flags = 1)
    Read File: File "c:\Documents and Settings\Dufresne\Application Data\Move Networks\QMCache00\E5FE5D98E7E249DE80B3754EA2242B350000000300C6BAD20346E.qss" is compressed (flags = 1)
    Read File: File "c:\Documents and Settings\Dufresne\Application Data\Move Networks\QMCache00\E5FE5D98E7E249DE80B3754EA2242B350000000400B4D044020AA.qss" is compressed (flags = 1)
    Read File: File "c:\Documents and Settings\Dufresne\Application Data\Move Networks\QMCache00\E5FE5D98E7E249DE80B3754EA2242B350000000400C5AE5F02808.qss" is compressed (flags = 1)
    Read File: File "c:\Documents and Settings\Dufresne\Application Data\Move Networks\QMCache00\E5FE5D98E7E249DE80B3754EA2242B350000000500B5B4C20176C.qss" is compressed (flags = 1)
    Read File: File "c:\Documents and Settings\Dufresne\Application Data\Move Networks\QMCache00\E5FE5D98E7E249DE80B3754EA2242B350000000500C621ED01B49.qss" is compressed (flags = 1)
    Read File: File "c:\Documents and Settings\Dufresne\Application Data\Move Networks\QMCache00\E5FE5D98E7E249DE80B3754EA2242B350000000600B3059C039E1.qss" is compressed (flags = 1)
    Read File: File "c:\Documents and Settings\Dufresne\Application Data\Move Networks\QMCache00\E5FE5D98E7E249DE80B3754EA2242B350000000600C37DE404608.qss" is compressed (flags = 1)
    Read File: File "c:\Documents and Settings\Dufresne\Application Data\Move Networks\QMCache00\E5FE5D98E7E249DE80B3754EA2242B350000000700B577C503412.qss" is compressed (flags = 1)
    Read File: File "c:\Documents and Settings\Dufresne\Application Data\Move Networks\QMCache00\E5FE5D98E7E249DE80B3754EA2242B350000000700C655C903FBE.qss" is compressed (flags = 1)
    Read File: File "c:\Documents and Settings\Dufresne\Application Data\Move Networks\QMCache00\E5FE5D98E7E249DE80B3754EA2242B350000000800B3F032033CC.qss" is compressed (flags = 1)
    Read File: File "c:\Documents and Settings\Dufresne\Application Data\Move Networks\QMCache00\E5FE5D98E7E249DE80B3754EA2242B350000000800C497B903E08.qss" is compressed (flags = 1)
    Read File: File "c:\Documents and Settings\Dufresne\Application Data\Move Networks\QMCache00\A0C97106E5B54BA28D878F37B38B4B190000041C00C84A49057A6.qss" is compressed (flags = 1)
    Read File: File "c:\Documents and Settings\Dufresne\Application Data\Move Networks\QMCache00\A0C97106E5B54BA28D878F37B38B4B190000041D00C844D304A45.qss" is compressed (flags = 1)
    Read File: File "c:\Documents and Settings\Dufresne\Application Data\Move Networks\QMCache00\A0C97106E5B54BA28D878F37B38B4B190000041E00C8503607616.qss" is compressed (flags = 1)
    Read File: File "c:\Documents and Settings\Dufresne\Application Data\Move Networks\QMCache00\A0C97106E5B54BA28D878F37B38B4B190000041F00C730DC07BFA.qss" is compressed (flags = 1)
    Read File: File "c:\Documents and Settings\Dufresne\Application Data\Move Networks\QMCache00\A0C97106E5B54BA28D878F37B38B4B190000042000C7BB0C02594.qss" is compressed (flags = 1)
    Read File: File "c:\Documents and Settings\Dufresne\Application Data\Move Networks\QMCache00\A0C97106E5B54BA28D878F37B38B4B190000042100C757D605604.qss" is compressed (flags = 1)
    Read File: File "c:\Documents and Settings\Dufresne\Application Data\Move Networks\QMCache00\A0C97106E5B54BA28D878F37B38B4B190000042200C7B77F063BA.qss" is compressed (flags = 1)
    Read File: File "c:\Documents and Settings\Dufresne\Application Data\Move Networks\QMCache00\A0C97106E5B54BA28D878F37B38B4B190000042300C811F606316.qss" is compressed (flags = 1)
    Read File: File "c:\Documents and Settings\Dufresne\Application Data\Move Networks\QMCache00\A0C97106E5B54BA28D878F37B38B4B190000042400C732DB03AC3.qss" is compressed (flags = 1)
    Read File: File "c:\Documents and Settings\Dufresne\Application Data\Move Networks\QMCache00\A0C97106E5B54BA28D878F37B38B4B190000042600C75EF7095EB.qss" is compressed (flags = 1)
    Read File: File "c:\Documents and Settings\Dufresne\Application Data\Move Networks\QMCache00\A0C97106E5B54BA28D878F37B38B4B190000042700C8034C00E95.qss" is compressed (flags = 1)
    Read File: File "c:\Documents and Settings\Dufresne\Application Data\Move Networks\QMCache00\A0C97106E5B54BA28D878F37B38B4B190000042800C80F00073FD.qss" is compressed (flags = 1)
    Read File: File "c:\Documents and Settings\Dufresne\Application Data\Move Networks\QMCache00\A0C97106E5B54BA28D878F37B38B4B190000042900C5BA2708A92.qss" is compressed (flags = 1)
    Read File: File "c:\Documents and Settings\Dufresne\Application Data\Move Networks\QMCache00\A0C97106E5B54BA28D878F37B38B4B190000042A00C5F83502BFF.qss" is compressed (flags = 1)
    Read File: File "c:\Documents and Settings\Dufresne\Application Data\Move Networks\QMCache00\A0C97106E5B54BA28D878F37B38B4B190000042B00C613FB02465.qss" is compressed (flags = 1)
    Read File: File "c:\Documents and Settings\Dufresne\Application Data\Move Networks\QMCache00\A0C97106E5B54BA28D878F37B38B4B190000042C00C628AC026CA.qss" is compressed (flags = 1)
    Read File: File "c:\Documents and Settings\Dufresne\Application Data\Move Networks\QMCache00\A0C97106E5B54BA28D878F37B38B4B190000042D00C5F8A602FC8.qss" is compressed (flags = 1)
    Read File: File "c:\Documents and Settings\Dufresne\Application Data\Move Networks\QMCache00\A0C97106E5B54BA28D878F37B38B4B190000042E00C5D2BA0301D.qss" is compressed (flags = 1)
    Read File: File "c:\Documents and Settings\Dufresne\Application Data\Move Networks\QMCache00\A0C97106E5B54BA28D878F37B38B4B190000043000C5E72902D7B.qss" is compressed (flags = 1)
    Read File: File "c:\Documents and Settings\Dufresne\Application Data\Move Networks\QMCache00\A0C97106E5B54BA28D878F37B38B4B190000043100C5E53E02BF1.qss" is compressed (flags = 1)
    Read File: File "c:\Documents and Settings\Dufresne\Application Data\Move Networks\QMCache00\A0C97106E5B54BA28D878F37B38B4B190000043200C5D18C02DC0.qss" is compressed (flags = 1)
    Read File: File "c:\Documents and Settings\Dufresne\Application Data\Move Networks\QMCache00\A0C97106E5B54BA28D878F37B38B4B190000043300C5E3DC02DBF.qss" is compressed (flags = 1)
    Read File: File "c:\Documents and Settings\Dufresne\Application Data\Move Networks\QMCache00\A0C97106E5B54BA28D878F37B38B4B190000043400C5E5F802D1F.qss" is compressed (flags = 1)
    Read File: File "c:\Documents and Settings\Dufresne\Application Data\Move Networks\QMCache00\A0C97106E5B54BA28D878F37B38B4B190000043500C5E55502CCA.qss" is compressed (flags = 1)
    Read File: File "c:\Documents and Settings\Dufresne\Application Data\Move Networks\QMCache00\A0C97106E5B54BA28D878F37B38B4B190000043600C6012C02D68.qss" is compressed (flags = 1)
    Read File: File "c:\Documents and Settings\Dufresne\Application Data\Move Networks\QMCache00\A0C97106E5B54BA28D878F37B38B4B190000043700C5E63C02D71.qss" is compressed (flags = 1)
    Read File: File "c:\Documents and Settings\Dufresne\Application Data\Move Networks\QMCache00\A0C97106E5B54BA28D878F37B38B4B190000043800C68BD301A1E.qss" is compressed (flags = 1)
    Read File: File "c:\Documents and Settings\Dufresne\Application Data\Move Networks\QMCache00\A0C97106E5B54BA28D878F37B38B4B19000003FD00C8335605F91.qss" is compressed (flags = 1)
    Read File: File "c:\Documents and Settings\Dufresne\Application Data\Move Networks\QMCache00\A0C97106E5B54BA28D878F37B38B4B190000046100C5E1DD01D9C.qss" is compressed (flags = 1)
    Read File: File "c:\Documents and Settings\Dufresne\Application Data\Move Networks\QMCache00\A0C97106E5B54BA28D878F37B38B4B19000004C700C8A812055DE.qss" is compressed (flags = 1)
    Read File: File "c:\Documents and Settings\Dufresne\Application Data\Move Networks\QMCache00\A0C97106E5B54BA28D878F37B38B4B190000043A00C683D302BB2.qss" is compressed (flags = 1)
    Read File: File "c:\Documents and Settings\Dufresne\Application Data\Move Networks\QMCache00\A0C97106E5B54BA28D878F37B38B4B190000043B00C681C302B16.qss" is compressed (flags = 1)
    Read File: File "c:\Documents and Settings\Dufresne\Application Data\Move Networks\QMCache00\A0C97106E5B54BA28D878F37B38B4B190000043C00C688F302A2B.qss" is compressed (flags = 1)
    Read File: File "c:\Documents and Settings\Dufresne\Application Data\Move Networks\QMCache00\A0C97106E5B54BA28D878F37B38B4B190000043D00C6841102881.qss" is compressed (flags = 1)
    Read File: File "c:\Documents and Settings\Dufresne\Application Data\Move Networks\QMCache00\A0C97106E5B54BA28D878F37B38B4B190000043E00C5FFA7029FC.qss" is compressed (flags = 1)
    Read File: File "c:\Documents and Settings\Dufresne\Application Data\Move Networks\QMCache00\A0C97106E5B54BA28D878F37B38B4B190000043F00C5F4E402615.qss" is compressed (flags = 1)
    Read File: File "c:\Documents and Settings\Dufresne\Application Data\Move Networks\QMCache00\A0C97106E5B54BA28D878F37B38B4B190000044000C5E5BF02446.qss" is compressed (flags = 1)
    Read File: File "c:\Documents and Settings\Dufresne\Application Data\Move Networks\QMCache00\A0C97106E5B54BA28D878F37B38B4B190000044100C5EFA402727.qss" is compressed (flags = 1)
    Read File: File "c:\Documents and Settings\Dufresne\Application Data\Move Networks\QMCache00\A0C97106E5B54BA28D878F37B38B4B190000044200C5DD940264B.qss" is compressed (flags = 1)
    Read File: File "c:\Documents and Settings\Dufresne\Application Data\Move Networks\QMCache00\A0C97106E5B54BA28D878F37B38B4B190000044400C6A69A02FC8.qss" is compressed (flags = 1)
    Read File: File "c:\Documents and Settings\Dufresne\Application Data\Move Networks\QMCache00\A0C97106E5B54BA28D878F37B38B4B190000044500C693FD02D22.qss" is compressed (flags = 1)
    Read File: File "c:\Documents and Settings\Dufresne\Application Data\Move Networks\QMCache00\A0C97106E5B54BA28D878F37B38B4B190000044600C6CA0D02E6C.qss" is compressed (flags = 1)
    Read File: File "c:\Documents and Settings\Dufresne\Application Data\Move Networks\QMCache00\A0C97106E5B54BA28D878F37B38B4B190000044700C5EFBF02DD7.qss" is compressed (flags = 1)
     
  15. 2013/05/17
    chinaclipper

    chinaclipper Well-Known Member Thread Starter

    Joined:
    2010/01/20
    Messages:
    96
    Likes Received:
    0
    Vii

    Read File: File "c:\Documents and Settings\Dufresne\Application Data\Move Networks\QMCache00\A0C97106E5B54BA28D878F37B38B4B190000044800C5E3CA02185.qss" is compressed (flags = 1)
    Read File: File "c:\Documents and Settings\Dufresne\Application Data\Move Networks\QMCache00\A0C97106E5B54BA28D878F37B38B4B190000044900C5F3D802441.qss" is compressed (flags = 1)
    Read File: File "c:\Documents and Settings\Dufresne\Application Data\Move Networks\QMCache00\A0C97106E5B54BA28D878F37B38B4B190000044A00C5E6A10240F.qss" is compressed (flags = 1)
    Read File: File "c:\Documents and Settings\Dufresne\Application Data\Move Networks\QMCache00\A0C97106E5B54BA28D878F37B38B4B190000044B00C5ED3E02539.qss" is compressed (flags = 1)
    Read File: File "c:\Documents and Settings\Dufresne\Application Data\Move Networks\QMCache00\A0C97106E5B54BA28D878F37B38B4B190000044C00C5E6500255F.qss" is compressed (flags = 1)
    Read File: File "c:\Documents and Settings\Dufresne\Application Data\Move Networks\QMCache00\A0C97106E5B54BA28D878F37B38B4B190000045800C5FDA502D2C.qss" is compressed (flags = 1)
    Read File: File "c:\Documents and Settings\Dufresne\Application Data\Move Networks\QMCache00\A0C97106E5B54BA28D878F37B38B4B190000045900C61ED702DF8.qss" is compressed (flags = 1)
    Read File: File "c:\Documents and Settings\Dufresne\Application Data\Move Networks\QMCache00\A0C97106E5B54BA28D878F37B38B4B190000045A00C63B9A02C2B.qss" is compressed (flags = 1)
    Read File: File "c:\Documents and Settings\Dufresne\Application Data\Move Networks\QMCache00\A0C97106E5B54BA28D878F37B38B4B190000045B00C669E10328E.qss" is compressed (flags = 1)
    Read File: File "c:\Documents and Settings\Dufresne\Application Data\Move Networks\QMCache00\A0C97106E5B54BA28D878F37B38B4B190000045C00C62BF5030DE.qss" is compressed (flags = 1)
    Read File: File "c:\Documents and Settings\Dufresne\Application Data\Move Networks\QMCache00\A0C97106E5B54BA28D878F37B38B4B190000045D00C67DBF02066.qss" is compressed (flags = 1)
    Read File: File "c:\Documents and Settings\Dufresne\Application Data\Move Networks\QMCache00\A0C97106E5B54BA28D878F37B38B4B190000045E00C66D43032F7.qss" is compressed (flags = 1)
    Read File: File "c:\Documents and Settings\Dufresne\Application Data\Move Networks\QMCache00\A0C97106E5B54BA28D878F37B38B4B190000045F00C66B6603203.qss" is compressed (flags = 1)
    Read File: File "c:\Documents and Settings\Dufresne\Application Data\Move Networks\QMCache00\A0C97106E5B54BA28D878F37B38B4B190000046000C655DF0304E.qss" is compressed (flags = 1)
    Read File: File "c:\Documents and Settings\Dufresne\Application Data\Move Networks\QMCache00\A0C97106E5B54BA28D878F37B38B4B190000047600C6D94A04E78.qss" is compressed (flags = 1)
    Read File: File "c:\Documents and Settings\Dufresne\Application Data\Move Networks\QMCache00\A0C97106E5B54BA28D878F37B38B4B190000047700C8241C05A30.qss" is compressed (flags = 1)
    Read File: File "c:\Documents and Settings\Dufresne\Application Data\Move Networks\QMCache00\A0C97106E5B54BA28D878F37B38B4B190000047800C758C904B7D.qss" is compressed (flags = 1)
    Read File: File "c:\Documents and Settings\Dufresne\Application Data\Move Networks\QMCache00\A0C97106E5B54BA28D878F37B38B4B190000047900C7BB5E04637.qss" is compressed (flags = 1)
    Read File: File "c:\Documents and Settings\Dufresne\Application Data\Move Networks\QMCache00\A0C97106E5B54BA28D878F37B38B4B190000047A00C795D605432.qss" is compressed (flags = 1)
    Read File: File "c:\Documents and Settings\Dufresne\Application Data\Move Networks\QMCache00\A0C97106E5B54BA28D878F37B38B4B190000047B00C7515A0482D.qss" is compressed (flags = 1)
    Read File: File "c:\Documents and Settings\Dufresne\Application Data\Move Networks\QMCache00\A0C97106E5B54BA28D878F37B38B4B190000047C00C787EC03C11.qss" is compressed (flags = 1)
    Read File: File "c:\Documents and Settings\Dufresne\Application Data\Move Networks\QMCache00\A0C97106E5B54BA28D878F37B38B4B190000047D00C7CB2E0605C.qss" is compressed (flags = 1)
    Read File: File "c:\Documents and Settings\Dufresne\Application Data\Move Networks\QMCache00\A0C97106E5B54BA28D878F37B38B4B190000047E00C6C40905FE9.qss" is compressed (flags = 1)
    Read File: File "c:\Documents and Settings\Dufresne\Application Data\Move Networks\QMCache00\A0C97106E5B54BA28D878F37B38B4B190000048000C6D1EC06D2F.qss" is compressed (flags = 1)
    Read File: File "c:\Documents and Settings\Dufresne\Application Data\Move Networks\QMCache00\A0C97106E5B54BA28D878F37B38B4B190000048100C8000D037EB.qss" is compressed (flags = 1)
    Read File: File "c:\Documents and Settings\Dufresne\Application Data\Move Networks\QMCache00\A0C97106E5B54BA28D878F37B38B4B190000048200C7151806C22.qss" is compressed (flags = 1)
    Read File: File "c:\Documents and Settings\Dufresne\Application Data\Move Networks\QMCache00\A0C97106E5B54BA28D878F37B38B4B190000048300C7871303DDF.qss" is compressed (flags = 1)
    Read File: File "c:\Documents and Settings\Dufresne\Application Data\Move Networks\QMCache00\A0C97106E5B54BA28D878F37B38B4B190000048400C6F5C507A6E.qss" is compressed (flags = 1)
    Read File: File "c:\Documents and Settings\Dufresne\Application Data\Move Networks\QMCache00\A0C97106E5B54BA28D878F37B38B4B190000048500C7D043036C5.qss" is compressed (flags = 1)
    Read File: File "c:\Documents and Settings\Dufresne\Application Data\Move Networks\QMCache00\A0C97106E5B54BA28D878F37B38B4B190000048600C7DB9F07096.qss" is compressed (flags = 1)
    Read File: File "c:\Documents and Settings\Dufresne\Application Data\Move Networks\QMCache00\A0C97106E5B54BA28D878F37B38B4B190000048700C79DA806D59.qss" is compressed (flags = 1)
    Read File: File "c:\Documents and Settings\Dufresne\Application Data\Move Networks\QMCache00\A0C97106E5B54BA28D878F37B38B4B190000048800C767D8063DA.qss" is compressed (flags = 1)
    Read File: File "c:\Documents and Settings\Dufresne\Application Data\Move Networks\QMCache00\A0C97106E5B54BA28D878F37B38B4B190000049E00C73F43040B5.qss" is compressed (flags = 1)
    Read File: File "c:\Documents and Settings\Dufresne\Application Data\Move Networks\QMCache00\A0C97106E5B54BA28D878F37B38B4B190000049F00C7A73D02DFE.qss" is compressed (flags = 1)
    Read File: File "c:\Documents and Settings\Dufresne\Application Data\Move Networks\QMCache00\A0C97106E5B54BA28D878F37B38B4B19000004A000C7BBF705926.qss" is compressed (flags = 1)
    Read File: File "c:\Documents and Settings\Dufresne\Application Data\Move Networks\QMCache00\A0C97106E5B54BA28D878F37B38B4B19000004A100C7BFA00594C.qss" is compressed (flags = 1)
    Read File: File "c:\Documents and Settings\Dufresne\Application Data\Move Networks\QMCache00\A0C97106E5B54BA28D878F37B38B4B19000004A200C721BC05184.qss" is compressed (flags = 1)
    Read File: File "c:\Documents and Settings\Dufresne\Application Data\Move Networks\QMCache00\A0C97106E5B54BA28D878F37B38B4B19000004A300C8E255017A3.qss" is compressed (flags = 1)
    Read File: File "c:\Documents and Settings\Dufresne\Application Data\Move Networks\QMCache00\A0C97106E5B54BA28D878F37B38B4B19000004A400C89CBA0CACF.qss" is compressed (flags = 1)
    Read File: File "c:\Documents and Settings\Dufresne\Application Data\Move Networks\QMCache00\A0C97106E5B54BA28D878F37B38B4B19000004A500C7D8EB054DB.qss" is compressed (flags = 1)
    Read File: File "c:\Documents and Settings\Dufresne\Application Data\Move Networks\QMCache00\A0C97106E5B54BA28D878F37B38B4B19000004A600C7938A0599E.qss" is compressed (flags = 1)
    Read File: File "c:\Documents and Settings\Dufresne\Application Data\Move Networks\QMCache00\E30E776DE3C9447CBBE9CEB8A7AC0FE7000000010094B1BF003CD.qss" is compressed (flags = 1)
    Read File: File "c:\Documents and Settings\Dufresne\Application Data\Move Networks\QMCache00\E30E776DE3C9447CBBE9CEB8A7AC0FE70000000200947781039A1.qss" is compressed (flags = 1)
    Read File: File "c:\Documents and Settings\Dufresne\Application Data\Move Networks\QMCache00\E30E776DE3C9447CBBE9CEB8A7AC0FE7000000030093A88C02DFD.qss" is compressed (flags = 1)
    Read File: File "c:\Documents and Settings\Dufresne\Application Data\Move Networks\QMCache00\E30E776DE3C9447CBBE9CEB8A7AC0FE7000000040094C3A1029A8.qss" is compressed (flags = 1)
    Read File: File "c:\Documents and Settings\Dufresne\Application Data\Move Networks\QMCache00\E30E776DE3C9447CBBE9CEB8A7AC0FE7000000050094539403959.qss" is compressed (flags = 1)
    Read File: File "c:\Documents and Settings\Dufresne\Application Data\Move Networks\QMCache00\E30E776DE3C9447CBBE9CEB8A7AC0FE70000000600955F7701460.qss" is compressed (flags = 1)
    Read File: File "c:\Documents and Settings\Dufresne\Application Data\Move Networks\QMCache00\E30E776DE3C9447CBBE9CEB8A7AC0FE70000000700955176017A3.qss" is compressed (flags = 1)
    Read File: File "c:\Documents and Settings\Dufresne\Application Data\Move Networks\QMCache00\A0C97106E5B54BA28D878F37B38B4B190000048A00C780B8057E6.qss" is compressed (flags = 1)
    Read File: File "c:\Documents and Settings\Dufresne\Application Data\Move Networks\QMCache00\A0C97106E5B54BA28D878F37B38B4B190000048B00C8AA3E038B6.qss" is compressed (flags = 1)
    Read File: File "c:\Documents and Settings\Dufresne\Application Data\Move Networks\QMCache00\A0C97106E5B54BA28D878F37B38B4B190000048C00C82461085C7.qss" is compressed (flags = 1)
    Read File: File "c:\Documents and Settings\Dufresne\Application Data\Move Networks\QMCache00\A0C97106E5B54BA28D878F37B38B4B190000048D00C82C9606FD6.qss" is compressed (flags = 1)
    Read File: File "c:\Documents and Settings\Dufresne\Application Data\Move Networks\QMCache00\A0C97106E5B54BA28D878F37B38B4B190000048E00C7F2BA06891.qss" is compressed (flags = 1)
    Read File: File "c:\Documents and Settings\Dufresne\Application Data\Move Networks\QMCache00\A0C97106E5B54BA28D878F37B38B4B190000048F00C7ADB1070AD.qss" is compressed (flags = 1)
    Read File: File "c:\Documents and Settings\Dufresne\Application Data\Move Networks\QMCache00\A0C97106E5B54BA28D878F37B38B4B190000049000C866E305274.qss" is compressed (flags = 1)
    Read File: File "c:\Documents and Settings\Dufresne\Application Data\Move Networks\QMCache00\A0C97106E5B54BA28D878F37B38B4B190000049100C81D1604D50.qss" is compressed (flags = 1)
    Read File: File "c:\Documents and Settings\Dufresne\Application Data\Move Networks\QMCache00\A0C97106E5B54BA28D878F37B38B4B190000049200C7694F0582A.qss" is compressed (flags = 1)
    Read File: File "c:\Documents and Settings\Dufresne\Application Data\Move Networks\QMCache00\A0C97106E5B54BA28D878F37B38B4B190000046B00C8F2DB0B65A.qss" is compressed (flags = 1)
    Read File: File "c:\Documents and Settings\Dufresne\Application Data\Move Networks\QMCache00\A0C97106E5B54BA28D878F37B38B4B190000047500C796F90601A.qss" is compressed (flags = 1)
    Read File: File "c:\Documents and Settings\Dufresne\Application Data\Move Networks\QMCache00\A0C97106E5B54BA28D878F37B38B4B190000047F00C7CD81037DD.qss" is compressed (flags = 1)
    Read File: File "c:\Documents and Settings\Dufresne\Application Data\Move Networks\QMCache00\A0C97106E5B54BA28D878F37B38B4B190000048900C734B705D97.qss" is compressed (flags = 1)
    Read File: File "c:\Documents and Settings\Dufresne\Application Data\Move Networks\QMCache00\A0C97106E5B54BA28D878F37B38B4B190000049300C8BA9608EE9.qss" is compressed (flags = 1)
    Read File: File "c:\Documents and Settings\Dufresne\Application Data\Move Networks\QMCache00\A0C97106E5B54BA28D878F37B38B4B190000049D00C6FDD504E76.qss" is compressed (flags = 1)
    Read File: File "c:\Documents and Settings\Dufresne\Application Data\Move Networks\QMCache00\A0C97106E5B54BA28D878F37B38B4B19000004A700C7967B05326.qss" is compressed (flags = 1)
    Read File: File "c:\Documents and Settings\Dufresne\Application Data\Move Networks\QMCache00\A0C97106E5B54BA28D878F37B38B4B19000004B100C778660474B.qss" is compressed (flags = 1)
    Read File: File "c:\Documents and Settings\Dufresne\Application Data\Move Networks\QMCache00\A0C97106E5B54BA28D878F37B38B4B19000004BD00C7D74A0546C.qss" is compressed (flags = 1)
    Read File: File "c:\Documents and Settings\Dufresne\Application Data\Move Networks\QMCache00\A0C97106E5B54BA28D878F37B38B4B19000004A800C799C0052C3.qss" is compressed (flags = 1)
    Read File: File "c:\Documents and Settings\Dufresne\Application Data\Move Networks\QMCache00\A0C97106E5B54BA28D878F37B38B4B19000004A900C7D403059A4.qss" is compressed (flags = 1)
    Read File: File "c:\Documents and Settings\Dufresne\Application Data\Move Networks\QMCache00\A0C97106E5B54BA28D878F37B38B4B19000004AA00C7F45905A1D.qss" is compressed (flags = 1)
    Read File: File "c:\Documents and Settings\Dufresne\Application Data\Move Networks\QMCache00\A0C97106E5B54BA28D878F37B38B4B19000004AB00C7AF4605CEA.qss" is compressed (flags = 1)
    Read File: File "c:\Documents and Settings\Dufresne\Application Data\Move Networks\QMCache00\A0C97106E5B54BA28D878F37B38B4B19000004AC00C7A3C004C51.qss" is compressed (flags = 1)
    Read File: File "c:\Documents and Settings\Dufresne\Application Data\Move Networks\QMCache00\A0C97106E5B54BA28D878F37B38B4B19000004AD00C75CC604BD8.qss" is compressed (flags = 1)
    Read File: File "c:\Documents and Settings\Dufresne\Application Data\Move Networks\QMCache00\A0C97106E5B54BA28D878F37B38B4B19000004AE00C799A6058CF.qss" is compressed (flags = 1)
    Read File: File "c:\Documents and Settings\Dufresne\Application Data\Move Networks\QMCache00\A0C97106E5B54BA28D878F37B38B4B19000004AF00C7916805934.qss" is compressed (flags = 1)
    Read File: File "c:\Documents and Settings\Dufresne\Application Data\Move Networks\QMCache00\A0C97106E5B54BA28D878F37B38B4B19000004B000C7EEA205127.qss" is compressed (flags = 1)
    Read File: File "c:\Documents and Settings\Dufresne\Application Data\Move Networks\QMCache00\A0C97106E5B54BA28D878F37B38B4B19000004FA00C6A45C045F3.qss" is compressed (flags = 1)
    Read File: File "c:\Documents and Settings\Dufresne\Application Data\Move Networks\QMCache00\A0C97106E5B54BA28D878F37B38B4B19000004FB00C6A47504554.qss" is compressed (flags = 1)
    Read File: File "c:\Documents and Settings\Dufresne\Application Data\Move Networks\QMCache00\A0C97106E5B54BA28D878F37B38B4B19000004FC00C69EC204471.qss" is compressed (flags = 1)
    Read File: File "c:\Documents and Settings\Dufresne\Application Data\Move Networks\QMCache00\A0C97106E5B54BA28D878F37B38B4B19000004FD00C6AE450427D.qss" is compressed (flags = 1)
    Read File: File "c:\Documents and Settings\Dufresne\Application Data\Move Networks\QMCache00\A0C97106E5B54BA28D878F37B38B4B19000004FE00C6A27704367.qss" is compressed (flags = 1)
    Read File: File "c:\Documents and Settings\Dufresne\Application Data\Move Networks\QMCache00\A0C97106E5B54BA28D878F37B38B4B19000004FF00C6C96E043D9.qss" is compressed (flags = 1)
    Read File: File "c:\Documents and Settings\Dufresne\Application Data\Move Networks\QMCache00\A0C97106E5B54BA28D878F37B38B4B190000050000C6E1CB042E5.qss" is compressed (flags = 1)
    Read File: File "c:\Documents and Settings\Dufresne\Application Data\Move Networks\QMCache00\A0C97106E5B54BA28D878F37B38B4B190000050100C6AC68045BF.qss" is compressed (flags = 1)
    Read File: File "c:\Documents and Settings\Dufresne\Application Data\Move Networks\QMCache00\A0C97106E5B54BA28D878F37B38B4B190000050200C6B0A404340.qss" is compressed (flags = 1)
    Read File: File "c:\Documents and Settings\Dufresne\Application Data\Move Networks\QMCache00\A0C97106E5B54BA28D878F37B38B4B190000050400C6B31B04287.qss" is compressed (flags = 1)
    Read File: File "c:\Documents and Settings\Dufresne\Application Data\Move Networks\QMCache00\A0C97106E5B54BA28D878F37B38B4B190000050500C6D7150400C.qss" is compressed (flags = 1)
    Read File: File "c:\Documents and Settings\Dufresne\Application Data\Move Networks\QMCache00\A0C97106E5B54BA28D878F37B38B4B190000050600C6D58E040AA.qss" is compressed (flags = 1)
    Read File: File "c:\Documents and Settings\Dufresne\Application Data\Move Networks\QMCache00\A0C97106E5B54BA28D878F37B38B4B190000050700C6C18804165.qss" is compressed (flags = 1)
    Read File: File "c:\Documents and Settings\Dufresne\Application Data\Move Networks\QMCache00\A0C97106E5B54BA28D878F37B38B4B190000050800C6923004452.qss" is compressed (flags = 1)
    Read File: File "c:\Documents and Settings\Dufresne\Application Data\Move Networks\QMCache00\A0C97106E5B54BA28D878F37B38B4B190000050900C694B704453.qss" is compressed (flags = 1)
    Read File: File "c:\Documents and Settings\Dufresne\Application Data\Move Networks\QMCache00\A0C97106E5B54BA28D878F37B38B4B190000050A00C6DC9A0437B.qss" is compressed (flags = 1)
    Read File: File "c:\Documents and Settings\Dufresne\Application Data\Move Networks\QMCache00\A0C97106E5B54BA28D878F37B38B4B190000050B00C655F2040B9.qss" is compressed (flags = 1)
    Read File: File "c:\Documents and Settings\Dufresne\Application Data\Move Networks\QMCache00\A0C97106E5B54BA28D878F37B38B4B190000050C00C6369F035C0.qss" is compressed (flags = 1)
    Read File: File "c:\Documents and Settings\Dufresne\Application Data\Move Networks\QMCache00\A0C97106E5B54BA28D878F37B38B4B190000040700C80E880532B.qss" is compressed (flags = 1)
    Read File: File "c:\Documents and Settings\Dufresne\Application Data\Move Networks\QMCache00\A0C97106E5B54BA28D878F37B38B4B190000041100C8C34E03FAC.qss" is compressed (flags = 1)
    Read File: File "c:\Documents and Settings\Dufresne\Application Data\Move Networks\QMCache00\A0C97106E5B54BA28D878F37B38B4B190000041B00C77992077C1.qss" is compressed (flags = 1)
    Read File: File "c:\Documents and Settings\Dufresne\Application Data\Move Networks\QMCache00\A0C97106E5B54BA28D878F37B38B4B190000042500C6C660045AE.qss" is compressed (flags = 1)
    Read File: File "c:\Documents and Settings\Dufresne\Application Data\Move Networks\QMCache00\A0C97106E5B54BA28D878F37B38B4B190000042F00C5E19B02F92.qss" is compressed (flags = 1)
    Read File: File "c:\Documents and Settings\Dufresne\Application Data\Move Networks\QMCache00\A0C97106E5B54BA28D878F37B38B4B190000043900C6806002BA9.qss" is compressed (flags = 1)
    Read File: File "c:\Documents and Settings\Dufresne\Application Data\Move Networks\QMCache00\A0C97106E5B54BA28D878F37B38B4B190000044300C62C1002252.qss" is compressed (flags = 1)
    Read File: File "c:\Documents and Settings\Dufresne\Application Data\Move Networks\QMCache00\A0C97106E5B54BA28D878F37B38B4B190000044D00C5E96B026B5.qss" is compressed (flags = 1)
    Read File: File "c:\Documents and Settings\Dufresne\Application Data\Move Networks\QMCache00\A0C97106E5B54BA28D878F37B38B4B190000045700C617010319F.qss" is compressed (flags = 1)
    Read File: File "c:\Documents and Settings\Dufresne\Application Data\Move Networks\QMCache00\A0C97106E5B54BA28D878F37B38B4B19000004D100C74A9906546.qss" is compressed (flags = 1)
    Read File: File "c:\Documents and Settings\Dufresne\Application Data\Move Networks\QMCache00\A0C97106E5B54BA28D878F37B38B4B19000004DB00C6716C032BF.qss" is compressed (flags = 1)
    Read File: File "c:\Documents and Settings\Dufresne\Application Data\Move Networks\QMCache00\A0C97106E5B54BA28D878F37B38B4B19000004E500C8024207238.qss" is compressed (flags = 1)
    Read File: File "c:\Documents and Settings\Dufresne\Application Data\Move Networks\QMCache00\A0C97106E5B54BA28D878F37B38B4B19000004EF00C6F409045E1.qss" is compressed (flags = 1)
    Read File: File "c:\Documents and Settings\Dufresne\Application Data\Move Networks\QMCache00\A0C97106E5B54BA28D878F37B38B4B19000004F900C6BE60043E5.qss" is compressed (flags = 1)
    Read File: File "c:\Documents and Settings\Dufresne\Application Data\Move Networks\QMCache00\A0C97106E5B54BA28D878F37B38B4B190000050300C6C716042EF.qss" is compressed (flags = 1)
    Read File: File "c:\Documents and Settings\Dufresne\Application Data\Move Networks\QMCache00\A0C97106E5B54BA28D878F37B38B4B190000050D00C645E703546.qss" is compressed (flags = 1)
    Read File: File "c:\Documents and Settings\Dufresne\Application Data\Move Networks\QMCache00\A0C97106E5B54BA28D878F37B38B4B190000051700C174690482F.qss" is compressed (flags = 1)
    Read File: File "c:\Documents and Settings\Dufresne\Application Data\Move Networks\QMCache00\E30E776DE3C9447CBBE9CEB8A7AC0FE7000000080094EBC003191.qss" is compressed (flags = 1)
    Read File: File "c:\Documents and Settings\Dufresne\Application Data\Move Networks\QMCache00\A0C97106E5B54BA28D878F37B38B4B190000044E00C5EADC02789.qss" is compressed (flags = 1)
    Read File: File "c:\Documents and Settings\Dufresne\Application Data\Move Networks\QMCache00\A0C97106E5B54BA28D878F37B38B4B190000044F00C643DD0277A.qss" is compressed (flags = 1)
    Read File: File "c:\Documents and Settings\Dufresne\Application Data\Move Networks\QMCache00\A0C97106E5B54BA28D878F37B38B4B190000045000C5E885028FA.qss" is compressed (flags = 1)
    Read File: File "c:\Documents and Settings\Dufresne\Application Data\Move Networks\QMCache00\A0C97106E5B54BA28D878F37B38B4B190000045100C73E1006155.qss" is compressed (flags = 1)
    Read File: File "c:\Documents and Settings\Dufresne\Application Data\Move Networks\QMCache00\A0C97106E5B54BA28D878F37B38B4B190000045200C6CC6603B2C.qss" is compressed (flags = 1)
    Read File: File "c:\Documents and Settings\Dufresne\Application Data\Move Networks\QMCache00\A0C97106E5B54BA28D878F37B38B4B190000045300C6C79D027C3.qss" is compressed (flags = 1)
    Read File: File "c:\Documents and Settings\Dufresne\Application Data\Move Networks\QMCache00\A0C97106E5B54BA28D878F37B38B4B190000045400C62F3F02FAB.qss" is compressed (flags = 1)
    Read File: File "c:\Documents and Settings\Dufresne\Application Data\Move Networks\QMCache00\A0C97106E5B54BA28D878F37B38B4B190000045500C63E2902392.qss" is compressed (flags = 1)
    Read File: File "c:\Documents and Settings\Dufresne\Application Data\Move Networks\QMCache00\A0C97106E5B54BA28D878F37B38B4B190000045600C5F75702B61.qss" is compressed (flags = 1)
    Read File: File "c:\Documents and Settings\Dufresne\Application Data\Move Networks\QMCache00\A0C97106E5B54BA28D878F37B38B4B190000051800C166F302C40.qss" is compressed (flags = 1)
    Read File: File "c:\Documents and Settings\Dufresne\Application Data\Move Networks\QMCache00\A0C97106E5B54BA28D878F37B38B4B190000051900C15DCB047EC.qss" is compressed (flags = 1)
    Read File: File "c:\Documents and Settings\Dufresne\Application Data\Move Networks\QMCache00\A0C97106E5B54BA28D878F37B38B4B190000051A00C10A1802589.qss" is compressed (flags = 1)
    Read File: File "c:\Documents and Settings\Dufresne\Application Data\Move Networks\QMCache00\A0C97106E5B54BA28D878F37B38B4B190000051B00C1BED50192D.qss" is compressed (flags = 1)
    Read File: File "c:\Documents and Settings\Dufresne\Application Data\Move Networks\QMCache00\A0C97106E5B54BA28D878F37B38B4B190000051C00C27F790889D.qss" is compressed (flags = 1)
    Read File: File "c:\Documents and Settings\Dufresne\Application Data\Move Networks\QMCache00\A0C97106E5B54BA28D878F37B38B4B190000051D00C212D605543.qss" is compressed (flags = 1)
    Read File: File "c:\Documents and Settings\Dufresne\Application Data\Move Networks\QMCache00\A0C97106E5B54BA28D878F37B38B4B190000051E00C24FEC06E62.qss" is compressed (flags = 1)
    Read File: File "c:\Documents and Settings\Dufresne\Application Data\Move Networks\QMCache00\A0C97106E5B54BA28D878F37B38B4B190000051F00C243E307378.qss" is compressed (flags = 1)
    Read File: File "c:\Documents and Settings\Dufresne\Application Data\Move Networks\QMCache00\A0C97106E5B54BA28D878F37B38B4B190000052000C21BCA06904.qss" is compressed (flags = 1)
    Read File: File "c:\Documents and Settings\Dufresne\Application Data\Move Networks\QMCache00\A0C97106E5B54BA28D878F37B38B4B190000052100C2C8C60BE6A.qss" is compressed (flags = 1)
    Read File: File "c:\Documents and Settings\Dufresne\Application Data\Move Networks\QMCache00\A0C97106E5B54BA28D878F37B38B4B190000052200C16FE605AEA.qss" is compressed (flags = 1)
    Read File: File "c:\Documents and Settings\Dufresne\Application Data\Move Networks\QMCache00\A0C97106E5B54BA28D878F37B38B4B190000052300C16E7B05AEA.qss" is compressed (flags = 1)
    Read File: File "c:\Documents and Settings\Dufresne\Application Data\Move Networks\QMCache00\A0C97106E5B54BA28D878F37B38B4B190000052400C7356106D7D.qss" is compressed (flags = 1)
    Read File: File "c:\Documents and Settings\Dufresne\Application Data\Move Networks\QMCache00\A0C97106E5B54BA28D878F37B38B4B190000052500C4D3D2045D6.qss" is compressed (flags = 1)
    Read File: File "c:\Documents and Settings\Dufresne\Application Data\Move Networks\QMCache00\A0C97106E5B54BA28D878F37B38B4B190000052600C76B4C00CFC.qss" is compressed (flags = 1)
    Read File: File "c:\Documents and Settings\Dufresne\Application Data\Move Networks\QMCache00\A0C97106E5B54BA28D878F37B38B4B190000052700C074050085B.qss" is compressed (flags = 1)
     
  16. 2013/05/17
    chinaclipper

    chinaclipper Well-Known Member Thread Starter

    Joined:
    2010/01/20
    Messages:
    96
    Likes Received:
    0
    Read File: File "c:\Documents and Settings\Dufresne\Application Data\Mozilla\Firefox\pluginreg.dat" is compressed (flags = 1)
    Read File: File "c:\Documents and Settings\Dufresne\Application Data\pdf995\temp.ps" is compressed (flags = 1)
    Read File: File "c:\Documents and Settings\Dufresne\Application Data\Power Sound Editor Free\Favorite7.8.5.dat" is compressed (flags = 1)
    Read File: File "c:\Documents and Settings\Dufresne\Application Data\Power Sound Editor Free\MRUList.dat" is compressed (flags = 1)
    Read File: File "c:\Documents and Settings\Dufresne\Application Data\Power Sound Editor Free\Shortcut7.8.5.dat" is compressed (flags = 1)
    Read File: File "c:\Documents and Settings\Dufresne\Application Data\Power Sound Editor Free\system.dat" is compressed (flags = 1)
    Read File: File "c:\Documents and Settings\Dufresne\Application Data\Real\RealMediaSDK\c0a80100.txt" is compressed (flags = 1)
    Read File: File "c:\Documents and Settings\Dufresne\Application Data\Real\Update\Update-log.txt" is compressed (flags = 1)
    Read File: File "c:\Documents and Settings\Dufresne\Application Data\Roxio\CDDB\cddb.db" is compressed (flags = 1)
    Read File: File "c:\Documents and Settings\Dufresne\Application Data\Roxio\Sidewinder\Sidewinder.log" is compressed (flags = 1)
    Read File: File "c:\Documents and Settings\Dufresne\Application Data\Droppix\Droppix Recorder\DxLM.log" is compressed (flags = 1)
    Read File: File "c:\Documents and Settings\Dufresne\Application Data\dvdcss\$1.anv" is compressed (flags = 1)
    Read File: File "c:\Documents and Settings\Dufresne\Application Data\dvdcss\CACHEDIR.TAG" is compressed (flags = 1)
    Read File: File "c:\Documents and Settings\Dufresne\Application Data\FileZilla\queue.sqlite3" is compressed (flags = 1)
    Read File: File "c:\Documents and Settings\Dufresne\Application Data\GARMIN\Maps\79de0af9-afe6-4b8b-9a76-181dd2b2d140.gma" is compressed (flags = 1)
    Read File: File "c:\Documents and Settings\Dufresne\Application Data\ImgBurn\Graph Data Files\CDWRITER_IDE5224_S028_SATURDAY-AUGUST-21-2010_17-16_97m15s17f_MAX.ibg" is compressed (flags = 1)
    Read File: File "c:\Documents and Settings\Dufresne\Application Data\ImgBurn\Graph Data Files\TSSTcorp_CD-DVDW_SH-S162L_TS05_SATURDAY-AUGUST-21-2010_17-28_97m15s17f_MAX.ibg" is compressed (flags = 1)
    Read File: File "c:\Documents and Settings\Dufresne\Application Data\SmartDraw\accent.tlx" is compressed (flags = 1)
    Read File: File "c:\Documents and Settings\Dufresne\Application Data\SmartDraw\correct.tlx" is compressed (flags = 1)
    Read File: File "c:\Documents and Settings\Dufresne\Application Data\SmartDraw\html.tlx" is compressed (flags = 1)
    Read File: File "c:\Documents and Settings\Dufresne\Application Data\SmartDraw\SMARTD8.OPT" is compressed (flags = 1)
    Read File: File "c:\Documents and Settings\Dufresne\Application Data\SmartDraw\tech.tlx" is compressed (flags = 1)
    Read File: File "c:\Documents and Settings\Dufresne\Application Data\SmartDraw\userdic.tlx" is compressed (flags = 1)
    Read File: File "c:\Documents and Settings\Dufresne\Application Data\Sony Corporation\SonicStage\appimport.log" is compressed (flags = 1)
    Read File: File "c:\Documents and Settings\Dufresne\Application Data\Sony Corporation\SonicStage\SonicStage.log" is compressed (flags = 1)
    Read File: File "c:\Documents and Settings\Dufresne\Application Data\SUPERAntiSpyware.com\SUPERAntiSpyware\PROCESSLIST.ZIP" is compressed (flags = 1)
    Read File: File "c:\Documents and Settings\Dufresne\Application Data\SUPERAntiSpyware.com\SUPERAntiSpyware\PROCESSLISTRELATED.DB" is compressed (flags = 1)
    Read File: File "c:\Documents and Settings\Dufresne\Application Data\SUPERAntiSpyware.com\SUPERAntiSpyware\PROCESSLISTRELATED.ZIP" is compressed (flags = 1)
    Read File: File "c:\Documents and Settings\Dufresne\Application Data\TaxCut\2007\alert.cfg" is compressed (flags = 1)
    Read File: File "c:\Documents and Settings\Dufresne\Application Data\TaxCut\2007\alert.txt" is compressed (flags = 1)
    Read File: File "c:\Documents and Settings\Dufresne\Application Data\TaxCut\2007\centrallog.log" is compressed (flags = 1)
    Read File: File "c:\Documents and Settings\Dufresne\Application Data\TaxCut\2007\htmlBuilder.log" is compressed (flags = 1)
    Read File: File "c:\Documents and Settings\Dufresne\Application Data\TaxCut\2007\taxcut_pdf995_setup.log" is compressed (flags = 1)
    Read File: File "c:\Documents and Settings\Dufresne\Application Data\TaxCut\2007\tc07.cfg" is compressed (flags = 1)
    Read File: File "c:\Documents and Settings\Dufresne\Application Data\TaxCut\2008\alert.cfg" is compressed (flags = 1)
    Read File: File "c:\Documents and Settings\Dufresne\Application Data\TaxCut\2008\alert.txt" is compressed (flags = 1)
    Read File: File "c:\Documents and Settings\Dufresne\Application Data\TaxCut\2008\EFileResponse.txt" is compressed (flags = 1)
    Read File: File "c:\Documents and Settings\Dufresne\Application Data\TaxCut\2008\htmlBuilder.log" is compressed (flags = 1)
    Read File: File "c:\Documents and Settings\Dufresne\Application Data\TaxCut\2008\tc08.cfg" is compressed (flags = 1)
    Read File: File "c:\Documents and Settings\Dufresne\Application Data\TaxCut\2009\alert.cfg" is compressed (flags = 1)
    Read File: File "c:\Documents and Settings\Dufresne\Application Data\TaxCut\2009\alert.txt" is compressed (flags = 1)
    Read File: File "c:\Documents and Settings\Dufresne\Application Data\TaxCut\2009\htmlBuilder.log" is compressed (flags = 1)
    Read File: File "c:\Documents and Settings\Dufresne\Application Data\TaxCut\2009\tc09.cfg" is compressed (flags = 1)
    Read File: File "c:\Documents and Settings\Dufresne\Application Data\TaxCut\2010\alert.cfg" is compressed (flags = 1)
    Read File: File "c:\Documents and Settings\Dufresne\Application Data\TaxCut\2010\alert.txt" is compressed (flags = 1)
    Read File: File "c:\Documents and Settings\Dufresne\Application Data\TaxCut\2010\htmlBuilder.log" is compressed (flags = 1)
    Read File: File "c:\Documents and Settings\Dufresne\Application Data\TaxCut\2010\tc10.cfg" is compressed (flags = 1)
    Read File: File "c:\Documents and Settings\Dufresne\Application Data\TaxCut\2011\alert.cfg" is compressed (flags = 1)
    Read File: File "c:\Documents and Settings\Dufresne\Application Data\TaxCut\2011\htmlBuilder.log" is compressed (flags = 1)
    Read File: File "c:\Documents and Settings\Dufresne\Application Data\TaxCut\2011\tc11.cfg" is compressed (flags = 1)
    Read File: File "c:\Documents and Settings\Dufresne\Application Data\TaxCut\2011\usalert.txt" is compressed (flags = 1)
    Read File: File "c:\Documents and Settings\Dufresne\Application Data\Uniblue\SpeedUpMyPC\error.log" is compressed (flags = 1)
    Read File: File "c:\Documents and Settings\Dufresne\Application Data\Uniblue\SpeedUpMyPC\settings.dat" is compressed (flags = 1)
    Read File: File "c:\Documents and Settings\Dufresne\Application Data\Uniblue\SpeedUpMyPC\state.sqlite" is compressed (flags = 1)
    Read File: File "c:\Documents and Settings\Dufresne\Application Data\Uniblue\SpeedUpMyPC\track_installs.txt" is compressed (flags = 1)
    Read File: File "c:\Documents and Settings\Dufresne\Application Data\vlc\74fc38f77c06519e77f3a2fec1e82051-i686.cache-2" is compressed (flags = 1)
    Read File: File "c:\Documents and Settings\Dufresne\Application Data\vlc\ef9c9ad8cc5857eb63cb3660bc8bd202-i686.cache-2" is compressed (flags = 1)
    Read File: File "c:\Documents and Settings\Dufresne\Application Data\Xtranormal\Output\State.err" is compressed (flags = 1)
    Read File: File "c:\Documents and Settings\Dufresne\Application Data\Xtranormal\State\License.dat" is compressed (flags = 1)
    Read File: File "c:\Documents and Settings\Dufresne\Application Data\Yahoo!\Companion\inq_data.inq" is compressed (flags = 1)
    Read File: File "c:\Documents and Settings\Dufresne\Application Data\Yahoo!\Companion\resources.inq" is compressed (flags = 1)
    Read File: File "c:\WINDOWS\system32\config\systemprofile\Application Data\Microsoft\Internet Explorer\brndlog.bak" is compressed (flags = 1)
    Read File: File "c:\WINDOWS\system32\config\systemprofile\Application Data\Microsoft\Internet Explorer\brndlog.txt" is compressed (flags = 1)
    Read File: File "c:\Documents and Settings\Dufresne\Desktop\Thumbs.db" is compressed (flags = 1)
    Read File: File "c:\Documents and Settings\Dufresne\Desktop\nvideaHTPC.nvp" is compressed (flags = 1)
    Read File: File "c:\Documents and Settings\Dufresne\Desktop\ZbThumbnail.info" is compressed (flags = 1)
    Read File: File "c:\Program Files\Outlook Express\msoe.txt" is compressed (flags = 1)
    Read File: File "c:\Program Files\Windows Media Player\npdrmv2.zip" is compressed (flags = 1)
    Read File: File "c:\Documents and Settings\Default User\Start Menu\Programs\Startup\desktop.ini" is compressed (flags = 1)
    Read File: File "c:\WINDOWS\system32\config\systemprofile\Start Menu\Programs\Startup\desktop.ini" is compressed (flags = 1)
    Read File: File "c:\WINDOWS\system32\omginstlog.txt" is compressed (flags = 1)
    Read File: File "c:\WINDOWS\system32\dsound.vxd" is compressed (flags = 1)
    Read File: File "c:\WINDOWS\system32\l_except.nls" is compressed (flags = 1)
    Read File: File "c:\WINDOWS\system32\perfwci.h" is compressed (flags = 1)
    Read File: File "c:\WINDOWS\system32\cmos.ram" is compressed (flags = 1)
    Read File: File "c:\WINDOWS\system32\pscript.sep" is compressed (flags = 1)
    Read File: File "c:\WINDOWS\system32\lMMLDeleteUserData42107612FX.tmp" is compressed (flags = 1)
    Read File: File "c:\WINDOWS\system32\login.cmd" is compressed (flags = 1)
    Read File: File "c:\WINDOWS\system32\pcl.sep" is compressed (flags = 1)
    Read File: File "c:\WINDOWS\system32\perfci.h" is compressed (flags = 1)
    Read File: File "c:\WINDOWS\system32\perffilt.h" is compressed (flags = 1)
    Read File: File "c:\WINDOWS\system32\spupdwxp.log" is compressed (flags = 1)
    Read File: File "c:\WINDOWS\system32\results.txt" is compressed (flags = 1)
    Read File: File "c:\WINDOWS\system32\nvModes.dat" is compressed (flags = 1)
    Read File: File "c:\WINDOWS\system32\View Channels.scf" is compressed (flags = 1)
    Read File: File "c:\WINDOWS\system32\config\systemprofile\Start Menu\Programs\Startup\desktop.ini" is compressed (flags = 1)
    Read File: File "c:\WINDOWS\system32\drivers\etc\networks" is compressed (flags = 1)
    Read File: File "c:\WINDOWS\system32\oobe\migip.dun" is compressed (flags = 1)
    Read File: File "c:\WINDOWS\system32\oobe\migrate.isp" is compressed (flags = 1)
    Read File: File "c:\WINDOWS\system32\oobe\msobe.isp" is compressed (flags = 1)
    Read File: File "c:\WINDOWS\system32\oobe\obeip.dun" is compressed (flags = 1)
    Read File: File "c:\WINDOWS\system32\oobe\reg.isp" is compressed (flags = 1)
    Read File: File "c:\WINDOWS\system32\wbem\wmiclivalueformat.xsl" is compressed (flags = 1)
    Read File: File "c:\Documents and Settings\Dufresne\.jupload.properties" is compressed (flags = 1)
    Read File: File "c:\Documents and Settings\Dufresne\.recently-used.xbel" is compressed (flags = 1)
    Read File: File "c:\Documents and Settings\Dufresne\DPro.log" is compressed (flags = 1)
    Read File: File "c:\Documents and Settings\Administrator\Local Settings\desktop.ini" is compressed (flags = 1)
    Read File: File "c:\Documents and Settings\Default User\Local Settings\desktop.ini" is compressed (flags = 1)
    Read File: File "c:\Documents and Settings\Dufresne\Local Settings\Application Data\dt.dat" is compressed (flags = 1)
    Read File: File "c:\Documents and Settings\Dufresne\Local Settings\Application Data\fusioncache.dat" is compressed (flags = 1)
    Read File: File "c:\Documents and Settings\Dufresne\Local Settings\Application Data\GDIPFONTCACHEV1.DAT" is compressed (flags = 1)
    Read File: File "c:\Documents and Settings\Dufresne\Local Settings\Application Data\Microsoft\Internet Explorer\brndlog.bak" is compressed (flags = 1)
    Read File: File "c:\Documents and Settings\Dufresne\Local Settings\Application Data\Microsoft\Internet Explorer\brndlog.txt" is compressed (flags = 1)
    Read File: File "c:\Documents and Settings\Dufresne\Local Settings\Application Data\Microsoft\Internet Explorer\MSIMGSIZ.DAT" is compressed (flags = 1)
    Read File: File "c:\WINDOWS\Permissions Syntax.txt" is compressed (flags = 1)
    Read File: File "c:\WINDOWS\UNNeroShowTime.cfg" is compressed (flags = 1)
    Read File: File "c:\WINDOWS\explorer.scf" is compressed (flags = 1)
    Read File: File "c:\WINDOWS\DVDShrink.txt" is compressed (flags = 1)
    Read File: File "c:\WINDOWS\assembly\GAC\System.Web.Mobile\1.0.5000.0__b03f5f7f11d50a3a\__AssemblyInfo__.ini" is compressed (flags = 1)
    Read File: File "c:\WINDOWS\Help\ciadmin.htm" is compressed (flags = 1)
    Read File: File "c:\WINDOWS\Help\conf.cnt" is compressed (flags = 1)
    Read File: File "c:\WINDOWS\Help\connect.cnt" is compressed (flags = 1)
    Read File: File "c:\WINDOWS\Help\ratings.cnt" is compressed (flags = 1)
    Read File: File "c:\WINDOWS\Help\mshearts.cnt" is compressed (flags = 1)
    Read File: File "c:\WINDOWS\Help\msnauth.cnt" is compressed (flags = 1)
    Read File: File "c:\WINDOWS\Help\nocontnt.cnt" is compressed (flags = 1)
    Read File: File "c:\WINDOWS\Help\update.cnt" is compressed (flags = 1)
    Read File: File "c:\WINDOWS\Help\windows.cnt" is compressed (flags = 1)
    Read File: File "c:\WINDOWS\Help\winhlp32.cnt" is compressed (flags = 1)
    Read File: File "c:\WINDOWS\Microsoft.NET\Framework\v1.0.3705\regsvcs.exe.rtm.config" is compressed (flags = 1)
    Read File: File "c:\WINDOWS\Microsoft.NET\Framework\v1.1.4322\aspnet.mof.uninstall" is compressed (flags = 1)
    Read File: File "c:\WINDOWS\Microsoft.NET\Framework\v1.1.4322\ieexec.exe.config" is compressed (flags = 1)
    Read File: File "c:\WINDOWS\Microsoft.NET\Framework\v1.1.4322\ilasm.exe.config" is compressed (flags = 1)
    Read File: File "c:\WINDOWS\Microsoft.NET\Framework\v1.1.4322\csc.exe.config" is compressed (flags = 1)
    Read File: File "c:\WINDOWS\Microsoft.NET\Framework\v1.1.4322\cvtres.exe.config" is compressed (flags = 1)
    Read File: File "c:\WINDOWS\Microsoft.NET\Framework\v1.1.4322\jsc.exe.config" is compressed (flags = 1)
    Read File: File "c:\WINDOWS\Microsoft.NET\Framework\v1.1.4322\l_except.nlp" is compressed (flags = 1)
    Read File: File "c:\WINDOWS\Microsoft.NET\Framework\v1.1.4322\vbc.exe.config" is compressed (flags = 1)
    Read File: File "c:\WINDOWS\Microsoft.NET\Framework\v1.1.4322\XPThemes.manifest" is compressed (flags = 1)
    Read File: File "c:\WINDOWS\Microsoft.NET\Framework\v1.1.4322\caspol.exe.config" is compressed (flags = 1)
    Read File: File "c:\WINDOWS\Microsoft.NET\Framework\v1.1.4322\ConfigWizards.exe.config" is compressed (flags = 1)
    Read File: File "c:\WINDOWS\Microsoft.NET\Framework\v1.1.4322\regasm.exe.config" is compressed (flags = 1)
    Read File: File "c:\WINDOWS\Microsoft.NET\Framework\v1.1.4322\1033\SetupENU1.txt" is compressed (flags = 1)
    Read File: File "c:\WINDOWS\Microsoft.NET\Framework\v1.1.4322\1033\SetupENU2.txt" is compressed (flags = 1)
    Read File: File "c:\WINDOWS\Microsoft.NET\Framework\v1.1.4322\ASP.NETClientFiles\SmartNav.htm" is compressed (flags = 1)
    Read File: File "c:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\caspol.exe.config" is compressed (flags = 1)
    Read File: File "c:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\aspnet.mof.uninstall" is compressed (flags = 1)
    Read File: File "c:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\ilasm.exe.config" is compressed (flags = 1)
    Read File: File "c:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\jsc.exe.config" is compressed (flags = 1)
    Read File: File "c:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\regasm.exe.config" is compressed (flags = 1)
    Read File: File "c:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\ASP.NETWebAdminFiles\webAdminNoNavBar.master" is compressed (flags = 1)
    Read File: File "c:\WINDOWS\Microsoft.NET\Framework\v3.5\AddInProcess.exe.config" is compressed (flags = 1)
    Read File: File "c:\WINDOWS\Microsoft.NET\Framework\v3.5\AddInProcess32.exe.config" is compressed (flags = 1)
    Read File: File "c:\WINDOWS\Microsoft.NET\Framework\v3.5\AddInUtil.exe.config" is compressed (flags = 1)
    Read File: File "c:\WINDOWS\Microsoft.NET\Framework\v3.5\csc.exe.config" is compressed (flags = 1)
    Read File: File "c:\WINDOWS\Microsoft.NET\Framework\v3.5\DataSvcUtil.exe.config" is compressed (flags = 1)
    Read File: File "c:\WINDOWS\Microsoft.NET\Framework\v3.5\default.win32manifest" is compressed (flags = 1)
    Read File: File "c:\WINDOWS\Microsoft.NET\Framework\v3.5\EdmGen.exe.config" is compressed (flags = 1)
    Read File: File "c:\WINDOWS\Microsoft.NET\Framework\v3.5\vbc.exe.config" is compressed (flags = 1)
    Read File: File "c:\WINDOWS\Microsoft.NET\Framework\v4.0.30319\AddInProcess.exe.config" is compressed (flags = 1)
    Read File: File "c:\WINDOWS\Microsoft.NET\Framework\v4.0.30319\AddInProcess32.exe.config" is compressed (flags = 1)
    Read File: File "c:\WINDOWS\Microsoft.NET\Framework\v4.0.30319\AddInUtil.exe.config" is compressed (flags = 1)
    Read File: File "c:\WINDOWS\Microsoft.NET\Framework\v4.0.30319\applaunch.exe.config" is compressed (flags = 1)
    Read File: File "c:\WINDOWS\Microsoft.NET\Framework\v4.0.30319\caspol.exe.config" is compressed (flags = 1)
    Read File: File "c:\WINDOWS\Microsoft.NET\Framework\v4.0.30319\InstallUtil.exe.config" is compressed (flags = 1)
    Read File: File "c:\WINDOWS\Microsoft.NET\Framework\v4.0.30319\jsc.exe.config" is compressed (flags = 1)
    Read File: File "c:\WINDOWS\Microsoft.NET\Framework\v4.0.30319\regasm.exe.config" is compressed (flags = 1)
    Read File: File "c:\WINDOWS\Microsoft.NET\Framework\v4.0.30319\regsvcs.exe.config" is compressed (flags = 1)
    Read File: File "c:\WINDOWS\Microsoft.NET\Framework\v4.0.30319\vbc.exe.config" is compressed (flags = 1)
    Read File: File "c:\WINDOWS\Web\bullet.gif" is compressed (flags = 1)
    Read File: File "c:\Documents and Settings\Administrator\Local Settings\desktop.ini" is compressed (flags = 1)
    Read File: File "c:\Documents and Settings\Administrator\Local Settings\History\History.IE5\desktop.ini" is compressed (flags = 1)
    Read File: File "c:\Documents and Settings\Administrator\Local Settings\History\History.IE5\index.dat" is compressed (flags = 1)
    Read File: File "c:\Documents and Settings\Default User\Local Settings\desktop.ini" is compressed (flags = 1)
    Read File: File "c:\Documents and Settings\Default User\Local Settings\History\desktop.ini" is compressed (flags = 1)
    Read File: File "c:\Documents and Settings\Dufresne\Local Settings\Application Data\dt.dat" is compressed (flags = 1)
    Read File: File "c:\Documents and Settings\Dufresne\Local Settings\Application Data\fusioncache.dat" is compressed (flags = 1)
    Read File: File "c:\Documents and Settings\Dufresne\Local Settings\Application Data\GDIPFONTCACHEV1.DAT" is compressed (flags = 1)
    Read File: File "c:\Documents and Settings\Dufresne\Local Settings\Application Data\dt.dat" is compressed (flags = 1)
    Read File: File "c:\Documents and Settings\Dufresne\Local Settings\Application Data\fusioncache.dat" is compressed (flags = 1)
    Read File: File "c:\Documents and Settings\Dufresne\Local Settings\Application Data\GDIPFONTCACHEV1.DAT" is compressed (flags = 1)
    Read File: File "c:\Documents and Settings\Dufresne\Local Settings\Application Data\Adobe\Color\ACECache6.lst" is compressed (flags = 1)
    Read File: File "c:\Documents and Settings\Dufresne\Local Settings\Application Data\Adobe\Fonts\AdobeFnt11.lst" is compressed (flags = 1)
    Read File: File "c:\Documents and Settings\Dufresne\Local Settings\Application Data\Adobe\TypeSpt\AdobeFnt11.lst" is compressed (flags = 1)
    Read File: File "c:\Documents and Settings\Dufresne\Local Settings\Application Data\Adobe\Updater5\acrobatPI.log" is compressed (flags = 1)
    Read File: File "c:\Documents and Settings\Dufresne\Local Settings\Application Data\Adobe\Updater5\aum.log" is compressed (flags = 1)
    Read File: File "c:\Documents and Settings\Dufresne\Local Settings\Application Data\Adobe\Updater5\aumLib.log" is compressed (flags = 1)
    Read File: File "c:\Documents and Settings\Dufresne\Local Settings\Application Data\Adobe\Updater5\AUTrans.xml.0" is compressed (flags = 1)
    Read File: File "c:\Documents and Settings\Dufresne\Local Settings\Application Data\Ahead\Nero Home\bl.db" is compressed (flags = 1)
    Read File: File "c:\Documents and Settings\Dufresne\Local Settings\Application Data\Ahead\Nero Home\crawlercfg.dat" is compressed (flags = 1)
    Read File: File "c:\Documents and Settings\Dufresne\Local Settings\Application Data\Ahead\Nero Home\is2.db" is compressed (flags = 1)
    Read File: File "c:\Documents and Settings\Dufresne\Local Settings\Application Data\Ahead\Nero Home\SID.db" is compressed (flags = 1)
    Read File: File "c:\Documents and Settings\Dufresne\Local Settings\Application Data\Ahead\Nero Home\SII.db" is compressed (flags = 1)
    Read File: File "c:\Documents and Settings\Dufresne\Local Settings\Application Data\Avg2013\log\avgpostinst.log" is compressed (flags = 1)
    Read File: File "c:\Documents and Settings\Dufresne\Local Settings\Application Data\Avg2013\log\avgual.2012-09-30.log" is compressed (flags = 1)
    Read File: File "c:\Documents and Settings\Dufresne\Local Settings\Application Data\Avg2013\log\avgual.2012-12-20.log" is compressed (flags = 1)
    Read File: File "c:\Documents and Settings\Dufresne\Local Settings\Application Data\Avg2013\log\avgual.2013-03-26.log" is compressed (flags = 1)
    Read File: File "c:\Documents and Settings\Dufresne\Local Settings\Application Data\Avg2013\log\avgual.2013-03-28.log" is compressed (flags = 1)
    Read File: File "c:\Documents and Settings\Dufresne\Local Settings\Application Data\Avg2013\log\avgual.2013-03-30.log" is compressed (flags = 1)
    Read File: File "c:\Documents and Settings\Dufresne\Local Settings\Application Data\Avg2013\log\avgual.2013-04-01.log" is compressed (flags = 1)
    Read File: File "c:\Documents and Settings\Dufresne\Local Settings\Application Data\Avg2013\log\avgual.2013-04-03.log" is compressed (flags = 1)
    Read File: File "c:\Documents and Settings\Dufresne\Local Settings\Application Data\Google\GBScreensaver\network.log" is compressed (flags = 1)
    Read File: File "c:\Documents and Settings\Dufresne\Local Settings\Application Data\Google\GoogleEarth\dbCache1.dat.index" is compressed (flags = 1)
    Read File: File "c:\Documents and Settings\Dufresne\Local Settings\Application Data\Google\GoogleEarth\dbCache2.dat" is compressed (flags = 1)
    Read File: File "c:\Documents and Settings\Dufresne\Local Settings\Application Data\Google\GoogleEarth\dbCache2.dat.index" is compressed (flags = 1)
    Read File: File "c:\Documents and Settings\Dufresne\Local Settings\Application Data\Google\GoogleEarth\dbCache3.dat" is compressed (flags = 1)
    Read File: File "c:\Documents and Settings\Dufresne\Local Settings\Application Data\Google\GoogleEarth\dbCache3.dat.index" is compressed (flags = 1)
    Read File: File "c:\Documents and Settings\Dufresne\Local Settings\Application Data\Google\GoogleEarth\dbCache4.dat" is compressed (flags = 1)
    Read File: File "c:\Documents and Settings\Dufresne\Local Settings\Application Data\Google\GoogleEarth\dbCache4.dat.index" is compressed (flags = 1)
    Read File: File "c:\Documents and Settings\Dufresne\Local Settings\Application Data\Google\Picasa2\overlay.kml" is compressed (flags = 1)
    Read File: File "c:\Documents and Settings\Dufresne\Local Settings\Application Data\Google\Picasa2\picasa.kml" is compressed (flags = 1)
    Read File: File "c:\Documents and Settings\Dufresne\Local Settings\Application Data\MFAData\logs\msi-20120928-015458.log" is compressed (flags = 1)
    Read File: File "c:\Documents and Settings\Dufresne\Local Settings\Application Data\MFAData\logs\msi-20120930-174631.log" is compressed (flags = 1)
    Read File: File "c:\Documents and Settings\Dufresne\Local Settings\Application Data\MFAData\logs\r86-20120930-174838.log" is compressed (flags = 1)
    Read File: File "c:\Documents and Settings\Dufresne\Local Settings\Application Data\Microsoft\Office\PowerPoint.qat" is compressed (flags = 1)
    Read File: File "c:\Documents and Settings\Dufresne\Local Settings\Application Data\Microsoft\FORMS\FRMCACHE.DAT" is compressed (flags = 1)
    Read File: File "c:\Documents and Settings\Dufresne\Local Settings\Application Data\Microsoft\HelpCtr\HelpSessionHistory.dat" is compressed (flags = 1)
    Read File: File "c:\Documents and Settings\Dufresne\Local Settings\Application Data\Microsoft\Internet Explorer\brndlog.bak" is compressed (flags = 1)
    Read File: File "c:\Documents and Settings\Dufresne\Local Settings\Application Data\Microsoft\Internet Explorer\brndlog.txt" is compressed (flags = 1)
    Read File: File "c:\Documents and Settings\Dufresne\Local Settings\Application Data\Microsoft\Internet Explorer\MSIMGSIZ.DAT" is compressed (flags = 1)
    Read File: File "c:\Documents and Settings\Dufresne\Local Settings\Application Data\Microsoft\Media Player\CorruptDatabase_360.wmdb" is compressed (flags = 1)
    Read File: File "c:\Documents and Settings\Dufresne\Local Settings\Application Data\Microsoft\Media Player\CurrentDatabase_59R.wmdb" is compressed (flags = 1)
    Read File: File "c:\Documents and Settings\Dufresne\Local Settings\Application Data\Microsoft\Media Player\D- _0.wmdb" is compressed (flags = 1)
    Read File: File "c:\Documents and Settings\Dufresne\Local Settings\Application Data\Microsoft\Media Player\D- _1.wmdb" is compressed (flags = 1)
    Read File: File "c:\Documents and Settings\Dufresne\Local Settings\Application Data\Microsoft\Media Player\D- _2.wmdb" is compressed (flags = 1)
    Read File: File "c:\Documents and Settings\Dufresne\Local Settings\Application Data\Microsoft\Media Player\D- _3.wmdb" is compressed (flags = 1)
    Read File: File "c:\Documents and Settings\Dufresne\Local Settings\Application Data\Microsoft\Media Player\D- _4.wmdb" is compressed (flags = 1)
    Read File: File "c:\Documents and Settings\Dufresne\Local Settings\Application Data\Microsoft\Media Player\D- _5.wmdb" is compressed (flags = 1)
    Read File: File "c:\Documents and Settings\Dufresne\Local Settings\Application Data\Microsoft\Media Player\E- _0.wmdb" is compressed (flags = 1)
    Read File: File "c:\Documents and Settings\Dufresne\Local Settings\Application Data\Microsoft\Media Player\E- _1.wmdb" is compressed (flags = 1)
    Read File: File "c:\Documents and Settings\Dufresne\Local Settings\Application Data\Microsoft\Media Player\E- _2.wmdb" is compressed (flags = 1)
    Read File: File "c:\Documents and Settings\Dufresne\Local Settings\Application Data\Microsoft\Media Player\E- _3.wmdb" is compressed (flags = 1)
    Read File: File "c:\Documents and Settings\Dufresne\Local Settings\Application Data\Microsoft\Media Player\E- _4.wmdb" is compressed (flags = 1)
    Read File: File "c:\Documents and Settings\Dufresne\Local Settings\Application Data\Microsoft\Media Player\E- _5.wmdb" is compressed (flags = 1)
    Read File: File "c:\Documents and Settings\Dufresne\Local Settings\Application Data\Microsoft\Messenger\activesharingfolder.dat" is compressed (flags = 1)
    Read File: File "c:\Documents and Settings\Dufresne\Local Settings\Application Data\Microsoft\Messenger\ContactsLog.txt" is compressed (flags = 1)
    Read File: File "c:\Documents and Settings\Dufresne\Local Settings\Application Data\Microsoft\Movie Maker\MEDIATAB0.DAT" is compressed (flags = 1)
    Read File: File "c:\Documents and Settings\Dufresne\Local Settings\Application Data\Microsoft\Outlook\Outltdufres@Hotmail.com-00000002.pst" is compressed (flags = 1)
    Read File: File "c:\Documents and Settings\Dufresne\Local Settings\Application Data\Microsoft\Outlook\Outltdufres@hotmail.com-00000003.pst" is compressed (flags = 1)
    Read File: File "c:\Documents and Settings\Dufresne\Desktop\Thumbs.db" is compressed (flags = 1)
    Read File: File "c:\Documents and Settings\Dufresne\Desktop\nvideaHTPC.nvp" is compressed (flags = 1)
    Read File: File "c:\Documents and Settings\Dufresne\Desktop\ZbThumbnail.info" is compressed (flags = 1)
    Read File: File "c:\Documents and Settings\Dufresne\Desktop\Personal Mailing List\FIELDS.LST" is compressed (flags = 1)
    Read File: File "c:\Documents and Settings\Dufresne\Desktop\Personal Mailing List\INSTALL.LOG" is compressed (flags = 1)
    Read File: File "c:\Documents and Settings\Dufresne\Desktop\Personal Mailing List\PML.GID" is compressed (flags = 1)
    Read File: File "c:\Documents and Settings\Dufresne\Desktop\Personal Mailing List\Pml.tpl" is compressed (flags = 1)
    Read File: File "c:\Documents and Settings\Dufresne\Desktop\Personal Mailing List\DATA\Add0001.CDX" is compressed (flags = 1)
    Read File: File "c:\Documents and Settings\Dufresne\Desktop\Personal Mailing List\DATA\Add0001.DBF" is compressed (flags = 1)
    Read File: File "c:\Documents and Settings\Dufresne\Desktop\Personal Mailing List\Labels\Christmas 2011.lbl" is compressed (flags = 1)
    Read File: File "c:\Documents and Settings\Dufresne\Desktop\Personal Mailing List\Labels\Return Address.lbl" is compressed (flags = 1)
    Read File: File "c:\Documents and Settings\Dufresne\Desktop\Personal Mailing List\Labels\Sample Label #1.lbl" is compressed (flags = 1)
    Read File: File "c:\Documents and Settings\Dufresne\Desktop\quicken backups\quicken1_19-20Jan2010.QDF-backup" is compressed (flags = 1)
    Read File: File "c:\Documents and Settings\Dufresne\Desktop\quicken backups\quicken1_19.QDF" is compressed (flags = 1)
    Read File: File "c:\Documents and Settings\Dufresne\Desktop\quicken backups\quicken1_19OFXLOG.DAT" is compressed (flags = 1)
    Read File: File "c:\Documents and Settings\Dufresne\Desktop\quicken backups\stupid.QDF" is compressed (flags = 1)
    Read File: File "c:\Documents and Settings\Dufresne\Desktop\quicken backups\stupid.QEL" is compressed (flags = 1)
    Read File: File "c:\Documents and Settings\Dufresne\Desktop\quicken backups\stupid.QPH" is compressed (flags = 1)
    Read File: File "c:\Documents and Settings\Dufresne\Desktop\quicken backups\stupid.QTX" is compressed (flags = 1)
    Read File: File "c:\Documents and Settings\Dufresne\Desktop\quicken backups\stupidOFXLOG.DAT" is compressed (flags = 1)
    Read File: File "c:\Documents and Settings\Dufresne\Desktop\quicken backups\test.QDF" is compressed (flags = 1)
    Read File: File "c:\Documents and Settings\Dufresne\Desktop\quicken backups\testOFXLOG.DAT" is compressed (flags = 1)
    Read File: File "c:\Documents and Settings\Dufresne\Desktop\quicken backups\today-2010-01-27.PM06.49.QDF-backup" is compressed (flags = 1)
    Read File: File "c:\Documents and Settings\Dufresne\Desktop\quicken backups\today-20Jan2010.QDF-backup" is compressed (flags = 1)
    Read File: File "c:\Documents and Settings\Dufresne\Desktop\quicken backups\todayOFXOLD.DAT" is compressed (flags = 1)
    Read File: File "c:\Documents and Settings\Dufresne\Desktop\quicken backups\BACKUP\today-2012-02-16.PM10.06.QDF-backup" is compressed (flags = 1)
    Read File: File "c:\Documents and Settings\Dufresne\Desktop\quicken backups\BACKUP\today-2012-03-14.PM10.00.QDF-backup" is compressed (flags = 1)
    Read File: File "c:\Documents and Settings\Dufresne\Desktop\quicken backups\BACKUP\today-2012-04-17.PM08.24.QDF-backup" is compressed (flags = 1)
    Read File: File "c:\Documents and Settings\Dufresne\Desktop\quicken backups\BACKUP\today-2012-08-22.PM08.53.QDF-backup" is compressed (flags = 1)
    Read File: File "c:\Documents and Settings\Dufresne\Desktop\quicken backups\BACKUP\today-2012-09-30.PM01.20.QDF-backup" is compressed (flags = 1)
    Read File: File "c:\Documents and Settings\Dufresne\Desktop\school stuff\Thumbs.db" is compressed (flags = 1)
    Read File: File "c:\Documents and Settings\Dufresne\Desktop\school stuff\ZbThumbnail.info" is compressed (flags = 1)
    Read File: File "c:\Documents and Settings\Dufresne\Desktop\school stuff\Jeopardy 2012\pacman_dies_y.wav" is compressed (flags = 1)
    Read File: File "c:\Documents and Settings\Dufresne\Desktop\school stuff\Jeopardy 2012\ShortDoDo.wav" is compressed (flags = 1)
    Read File: File "c:\Documents and Settings\Dufresne\Desktop\school stuff\jeopardy2011\pacman_dies_y.wav" is compressed (flags = 1)
    Read File: File "c:\Documents and Settings\Dufresne\Desktop\school stuff\jeopardy2011\ShortDoDo.wav" is compressed (flags = 1)
    Read File: File "c:\Documents and Settings\Dufresne\Desktop\Aishas videos\Thumbs.db" is compressed (flags = 1)
    Read File: File "c:\Documents and Settings\Dufresne\Desktop\Aishas videos\VID 00003.3GP" is compressed (flags = 1)
    Read File: File "c:\Documents and Settings\Dufresne\Desktop\Aishas videos\VID 00004.3GP" is compressed (flags = 1)
    Read File: File "c:\Documents and Settings\Dufresne\Desktop\Aishas videos\VID 00005.3GP" is compressed (flags = 1)
    Read File: File "c:\Documents and Settings\Dufresne\Desktop\Aishas videos\VID 00006.3GP" is compressed (flags = 1)
    Read File: File "c:\Documents and Settings\Dufresne\Desktop\Aishas videos\ZbThumbnail.info" is compressed (flags = 1)
    Read File: File "c:\Documents and Settings\Dufresne\Desktop\Big Pink Beaver\Thumbs.db" is compressed (flags = 1)
    Read File: File "c:\Documents and Settings\Dufresne\Desktop\Big Pink Beaver\ZbThumbnail.info" is compressed (flags = 1)
    Read File: File "c:\Documents and Settings\Dufresne\Desktop\Big Pink Beaver\Beaver_MistyFjords.ai" is compressed (flags = 1)
    Read File: File "c:\Documents and Settings\Dufresne\Desktop\Big Pink Beaver\beaver_poster_test1.pub" is compressed (flags = 1)
    Read File: File "c:\Documents and Settings\Dufresne\Desktop\Big Pink Beaver\beaver_test_2.pub" is compressed (flags = 1)
    Done!
    Scan finished
    =======================================
     
  17. 2013/05/17
    broni

    broni Moderator Malware Analyst

    Joined:
    2002/08/01
    Messages:
    21,701
    Likes Received:
    116
    Good :)

    [​IMG] Create new restore point before proceeding with the next step....
    How to:
    - Windows 8: http://www.vikitech.com/11302/system-restore-windows-8
    - Windows 7: http://www.howtogeek.com/howto/3195/create-a-system-restore-point-in-windows-7/
    - Vista: http://www.howtogeek.com/howto/wind...tore-point-for-windows-vistas-system-restore/
    - XP: http://support.microsoft.com/kb/948247

    [​IMG] Please download ComboFix from Here, Here or Here to your Desktop.

    **Note: In the event you already have Combofix, this is a new version that I need you to download. It is important that it is saved directly to your desktop**
    • Never rename Combofix unless instructed.
    • Close any open browsers.
    • Close/disable all anti virus and anti malware programs so they do not interfere with the running of ComboFix.
    • Very Important! Temporarily disable your anti-virus, script blocking and any anti-malware real-time protection before performing a scan. They can interfere with ComboFix or remove some of its embedded files which may cause "unpredictable results ".
    • Click on this link to see a list of programs that should be disabled. The list is not all inclusive. If yours is not listed and you don't know how to disable it, please ask.
    • Close any open browsers.
    • WARNING: Combofix will disconnect your machine from the Internet as soon as it starts
    • Please do not attempt to re-connect your machine back to the Internet until Combofix has completely finished.
    • If there is no internet connection after running Combofix, then restart your computer to restore back your connection.
      If the connection is not there use restore point you created prior to running Combofix.
    • Double click on combofix.exe & follow the prompts.

    • NOTE1. If Combofix asks you to install Recovery Console, please allow it.
      NOTE 2. If Combofix asks you to update the program, always do so.
    • When finished, it will produce a report for you.
    • Please post the "C:\ComboFix.txt"
    **Note 1: Do not mouseclick combofix's window while it's running. That may cause it to stall
    **Note 2 for AVG and CA Internet Security (Total Defense Internet Security) users: ComboFix will not run until AVG/CA Internet Security is uninstalled as a protective measure against the anti-virus. This is because AVG/CA Internet Security "falsely" detects ComboFix (or its embedded files) as a threat and may remove them resulting in the tool not working correctly which in turn can cause "unpredictable results ". Since AVG/CA Internet Security cannot be effectively disabled before running ComboFix, the author recommends you to uninstall AVG/CA Internet Security first.
    Use AppRemover to uninstall it: http://www.appremover.com/
    We can reinstall it when we're done with CF.
    **Note 3: If you receive an error "Illegal operation attempted on a registery key that has been marked for deletion ", restart computer to fix the issue.
    **Note 4: Some infections may take some significant time to be cured. As long as your computer clock is running Combofix is still working. Be patient.


    Make sure, you re-enable your security programs, when you're done with Combofix.

    ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
    ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~

    NOTE.
    If, for some reason, Combofix refuses to run, try the following...

    Delete Combofix file, download fresh one, but rename combofix.exe to your_name.exe BEFORE saving it to your desktop.
    Do NOT run it yet.
    Download Rkill (courtesy of BleepingComputer.com) to your desktop.
    There are 2 different versions. If one of them won't run then download and try to run the other one.
    You only need to get one of these to run, not all of them. You may get warnings from your antivirus about this tool, ignore them or shutdown your antivirus.

    rKill.exe: http://www.bleepingcomputer.com/download/rkill/dl/10/
    iExplore.exe (renamed rKill.exe): http://www.bleepingcomputer.com/download/rkill/dl/11/

    Restart computer in safe mode

    • Double-click on the Rkill desktop icon to run the tool.
    • If using Vista or Windows 7 right-click on it and choose Run As Administrator.
    • A black DOS box will briefly flash and then disappear. This is normal and indicates the tool ran successfully.
    • If not, delete the file, then download and use the one provided in Link 2.
    • Do not reboot until instructed.
    • If the tool does not run from any of the links provided, please let me know.

    When the scan is done Notepad will open with rKill.txt log.
    NOTE. rKill.txt log will also be present on your desktop.

    Once you've gotten one of them to run, immediately run your_name.exe by double clicking on it.

    IF you had to run rKill post BOTH logs, rKill.txt and Combofix.txt.
     
  18. 2013/05/17
    chinaclipper

    chinaclipper Well-Known Member Thread Starter

    Joined:
    2010/01/20
    Messages:
    96
    Likes Received:
    0
    Roger that. Will do it later today!
     
  19. 2013/05/17
    chinaclipper

    chinaclipper Well-Known Member Thread Starter

    Joined:
    2010/01/20
    Messages:
    96
    Likes Received:
    0
    Here is the comboFix.txt

    ComboFix 13-05-16.02 - Dufresne 05/17/2013 16:48:11.3.2 - x86
    Microsoft Windows XP Professional 5.1.2600.3.1252.1.1033.18.2047.1399 [GMT -5:00]
    Running from: c:\documents and settings\Dufresne\Desktop\ComboFix.exe
    FW: ZoneAlarm Firewall *Disabled* {829BDA32-94B3-44F4-8446-F8FCFF809F8B}
    .
    .
    ((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
    .
    .
    c:\documents and settings\All Users\Application Data\TEMP
    c:\documents and settings\Dufresne\Local Settings\Application Data\assembly\tmp
    c:\documents and settings\Dufresne\System
    c:\documents and settings\Dufresne\System\win_qs8.jqx
    c:\documents and settings\Dufresne\WINDOWS
    c:\windows\system32\drivers\hwinterface.sys
    c:\windows\system32\uptime.exe
    c:\windows\system32\URTTemp
    c:\windows\system32\URTTemp\regtlib.exe
    .
    Infected copy of c:\windows\system32\drivers\ntfs.sys was found and disinfected
    Restored copy from - c:\windows\ERDNT\cache\ntfs.sys
    .
    .
    ((((((((((((((((((((((((((((((((((((((( Drivers/Services )))))))))))))))))))))))))))))))))))))))))))))))))
    .
    .
    -------\Legacy_hwinterface
    -------\Service_hwinterface
    .
    .
    ((((((((((((((((((((((((( Files Created from 2013-04-17 to 2013-05-17 )))))))))))))))))))))))))))))))
    .
    .
    2013-05-16 21:05 . 2013-05-16 21:05 -------- d-----w- c:\documents and settings\Administrator\Application Data\BitZipper
    2013-05-15 03:00 . 2013-05-15 03:07 -------- d-----w- c:\program files\Speccy
    2013-05-13 17:19 . 2013-05-13 17:19 -------- d-----w- c:\documents and settings\Dufresne\Local Settings\Application Data\Garmin
    2013-05-10 01:53 . 2013-05-10 01:53 -------- d-----w- c:\documents and settings\Administrator\Application Data\Malwarebytes
    2013-05-10 01:53 . 2013-05-10 01:53 -------- d-----w- c:\documents and settings\Administrator\Application Data\AVG2013
    2013-05-10 00:11 . 2013-05-10 00:11 -------- d-----w- c:\documents and settings\Administrator\Local Settings\Application Data\Mozilla
    2013-05-09 22:32 . 2013-05-10 01:53 -------- d-----w- c:\documents and settings\Administrator\Local Settings\Application Data\Avg2013
    .
    .
    .
    (((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
    .
    2013-04-16 22:17 . 2006-02-28 12:00 920064 ----a-w- c:\windows\system32\wininet.dll
    2013-04-16 22:17 . 2006-02-28 12:00 43520 ----a-w- c:\windows\system32\licmgr10.dll
    2013-04-16 22:17 . 2006-02-28 12:00 1469440 ------w- c:\windows\system32\inetcpl.cpl
    2013-04-12 23:28 . 2006-02-28 12:00 385024 ----a-w- c:\windows\system32\html.iec
    2013-04-12 16:10 . 2013-04-12 16:10 94112 ----a-w- c:\windows\system32\WindowsAccessBridge.dll
    2013-04-12 16:09 . 2013-04-12 16:10 143872 ----a-w- c:\windows\system32\javacpl.cpl
    2013-04-12 16:09 . 2012-04-29 14:53 861088 ----a-w- c:\windows\system32\npdeployJava1.dll
    2013-04-12 16:09 . 2011-07-06 21:01 782240 ----a-w- c:\windows\system32\deployJava1.dll
    2013-04-10 01:31 . 2006-02-28 12:00 1876352 ----a-w- c:\windows\system32\win32k.sys
    2013-04-02 14:09 . 2013-04-02 14:09 4550656 ----a-w- c:\windows\system32\GPhotos.scr
    2013-03-13 06:12 . 2012-04-14 15:14 693976 ----a-w- c:\windows\system32\FlashPlayerApp.exe
    2013-03-13 06:12 . 2011-08-04 23:52 73432 ----a-w- c:\windows\system32\FlashPlayerCPLApp.cpl
    2013-03-13 06:12 . 2013-03-13 06:12 16486616 ----a-w- c:\windows\system32\FlashPlayerInstaller.exe
    2013-03-08 08:36 . 2006-02-28 12:00 293376 ----a-w- c:\windows\system32\winsrv.dll
    2013-03-07 01:32 . 2006-02-28 12:00 2149888 ------w- c:\windows\system32\ntoskrnl.exe
    2013-03-07 00:50 . 2004-08-03 22:59 2028544 ------w- c:\windows\system32\ntkrnlpa.exe
    2013-02-27 07:56 . 2007-10-16 21:40 2067456 ----a-w- c:\windows\system32\mstscax.dll
    2009-12-19 21:23 . 2009-12-19 21:23 302 ----a-w- c:\program files\temp995.bat
    2013-04-12 02:16 . 2013-04-12 02:15 263064 ----a-w- c:\program files\mozilla firefox\components\browsercomps.dll
    .
    .
    ((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
    .
    .
    *Note* empty entries & legit default entries are not shown
    REGEDIT4
    .
    [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\Carbonite.Green]
    @= "{95A27763-F62A-4114-9072-E81D87DE3B68} "
    [HKEY_CLASSES_ROOT\CLSID\{95A27763-F62A-4114-9072-E81D87DE3B68}]
    2012-12-05 04:23 1019976 ----a-r- c:\program files\Carbonite\Carbonite Backup\CarboniteNSE.dll
    .
    [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\Carbonite.Partial]
    @= "{E300CD91-100F-4E67-9AF3-1384A6124015} "
    [HKEY_CLASSES_ROOT\CLSID\{E300CD91-100F-4E67-9AF3-1384A6124015}]
    2012-12-05 04:23 1019976 ----a-r- c:\program files\Carbonite\Carbonite Backup\CarboniteNSE.dll
    .
    [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\Carbonite.Yellow]
    @= "{5E529433-B50E-4bef-A63B-16A6B71B071A} "
    [HKEY_CLASSES_ROOT\CLSID\{5E529433-B50E-4bef-A63B-16A6B71B071A}]
    2012-12-05 04:23 1019976 ----a-r- c:\program files\Carbonite\Carbonite Backup\CarboniteNSE.dll
    .
    [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
    "QuickenScheduledUpdates "= "c:\program files\Quicken\bagent.exe" [2013-04-10 76072]
    "GarminExpressTrayApp "= "c:\program files\Garmin\Express Tray\ExpressTray.exe" [2013-03-12 1099608]
    "ctfmon.exe "= "c:\windows\system32\ctfmon.exe" [2008-04-14 15360]
    .
    [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
    "NvCplDaemon "= "c:\windows\system32\NvCpl.dll" [2007-09-17 8491008]
    "IJNetworkScannerSelectorEX "= "c:\program files\Canon\IJ Network Scanner Selector EX\CNMNSST.exe" [2010-09-09 452016]
    "High Definition Audio Property Page Shortcut "= "HDAShCut.exe" [2004-10-27 61952]
    "Carbonite Backup "= "c:\program files\Carbonite\Carbonite Backup\CarboniteUI.exe" [2012-12-05 1065032]
    "QuickTime Task "= "c:\program files\QuickTime\qttask.exe" [2010-11-29 421888]
    .
    [HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\RunOnce]
    "FlashPlayerUpdate "= "c:\windows\system32\Macromed\Flash\FlashUtil32_11_6_602_180_ActiveX.exe" [2013-03-13 706776]
    .
    [hkey_local_machine\software\microsoft\windows\currentversion\explorer\ShellExecuteHooks]
    "{5AE067D3-9AFB-48E0-853A-EBB7F4A000DA} "= "c:\program files\SUPERAntiSpyware\SASSEH.DLL" [2011-10-16 113024]
    .
    [HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\LBTWlgn]
    2007-11-15 15:10 72208 ----a-w- c:\program files\Common Files\Logitech\Bluetooth\LBTWLgn.dll
    .
    [HKEY_LOCAL_MACHINE\system\currentcontrolset\control\session manager]
    BootExecute REG_MULTI_SZ autocheck autochk *\0c:\progra~1\AVG\AVG2013\avgrsx.exe /sync /restart
    .
    [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\!SASCORE]
    @=" "
    .
    [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\Wdf01000.sys]
    @= "Driver "
    .
    [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\WdfLoadGroup]
    @=" "
    .
    [HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Adobe Gamma Loader.exe.lnk]
    path=c:\documents and settings\All Users\Start Menu\Programs\Startup\Adobe Gamma Loader.exe.lnk
    backup=c:\windows\pss\Adobe Gamma Loader.exe.lnkCommon Startup
    .
    [HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Adobe Gamma Loader.lnk]
    path=c:\documents and settings\All Users\Start Menu\Programs\Startup\Adobe Gamma Loader.lnk
    backup=c:\windows\pss\Adobe Gamma Loader.lnkCommon Startup
    .
    [HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Logitech SetPoint.lnk]
    path=c:\documents and settings\All Users\Start Menu\Programs\Startup\Logitech SetPoint.lnk
    backup=c:\windows\pss\Logitech SetPoint.lnkCommon Startup
    .
    [HKLM\~\startupfolder\C:^Documents and Settings^Dufresne^Start Menu^Programs^Startup^OneNote 2007 Screen Clipper and Launcher.lnk]
    path=c:\documents and settings\Dufresne\Start Menu\Programs\Startup\OneNote 2007 Screen Clipper and Launcher.lnk
    backup=c:\windows\pss\OneNote 2007 Screen Clipper and Launcher.lnkStartup
    .
    [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\KernelFaultCheck]
    c:\windows\system32\dumprep 0 -k [X]
    .
    [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Adobe ARM]
    2012-12-03 07:35 946352 ----a-w- c:\program files\Common Files\Adobe\ARM\1.0\AdobeARM.exe
    .
    [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\CanonMyPrinter]
    2010-07-26 02:08 2569616 ----a-w- c:\program files\Canon\MyPrinter\BJMYPRT.EXE
    .
    [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\ctfmon.exe]
    2008-04-14 00:12 15360 ------w- c:\windows\system32\ctfmon.exe
    .
    [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Google Update]
    2011-05-31 20:25 136176 ----atw- c:\documents and settings\Dufresne\Local Settings\Application Data\Google\Update\GoogleUpdate.exe
    .
    [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\GrooveMonitor]
    2009-02-27 00:36 30040 ----a-w- c:\program files\Microsoft Office\Office12\GrooveMonitor.exe
    .
    [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\High Definition Audio Property Page Shortcut]
    2004-10-27 20:21 61952 -c----w- c:\windows\system32\HdAShCut.exe
    .
    [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\HotKeysCmds]
    2006-10-05 13:13 114688 -c--a-r- c:\windows\system32\hkcmd.exe
    .
    [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\IgfxTray]
    2006-10-05 13:11 98304 -c--a-r- c:\windows\system32\igfxtray.exe
    .
    [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\IntelliPoint]
    2004-06-03 06:50 204800 ----a-w- c:\program files\Microsoft IntelliPoint\point32.exe
    .
    [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\ISUSPM]
    2006-09-11 09:40 218032 -c--a-w- c:\program files\Common Files\InstallShield\UpdateService\ISUSPM.exe
    .
    [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Kernel and Hardware Abstraction Layer]
    2007-09-21 08:10 55824 -c--a-w- c:\windows\KHALMNPR.Exe
    .
    [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Logitech Hardware Abstraction Layer]
    2007-09-21 08:10 55824 -c--a-w- c:\windows\KHALMNPR.Exe
    .
    [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\NapsterShell]
    2010-01-19 17:48 323280 ----a-w- c:\program files\Napster\napster.exe
    .
    [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\NeroFilterCheck]
    2006-01-12 20:40 155648 -c--a-w- c:\program files\Common Files\Ahead\Lib\NeroCheck.exe
    .
    [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\NvCplDaemon]
    2007-09-17 06:07 8491008 ----a-w- c:\windows\system32\nvcpl.dll
    .
    [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\NvMediaCenter]
    2007-09-17 06:07 81920 -c--a-w- c:\windows\system32\nvmctray.dll
    .
    [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\nwiz]
    2007-09-17 06:07 1626112 ----a-w- c:\windows\system32\nwiz.exe
    .
    [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Persistence]
    2006-10-05 13:10 94208 -c--a-r- c:\windows\system32\igfxpers.exe
    .
    [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\QuickTime Task]
    2010-11-29 22:38 421888 ----a-w- c:\program files\QuickTime\QTTask.exe
    .
    [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SunJavaUpdateSched]
    2012-07-03 14:04 252848 ----a-w- c:\program files\Common Files\Java\Java Update\jusched.exe
    .
    [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\type32]
    2004-06-03 05:51 172032 ----a-w- c:\program files\Microsoft IntelliType Pro\type32.exe
    .
    [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\WUSB54GPv4]
    2004-04-19 15:19 24576 ----a-w- c:\program files\Wireless-G Portable USB Adapter Wireless Network Monitor\InvokeSvc3.exe
    .
    [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\services]
    "SharedAccess "=2 (0x2)
    "LBTServ "=3 (0x3)
    "gusvc "=3 (0x3)
    "gupdatem "=3 (0x3)
    "gupdate1c9961f125551c6 "=2 (0x2)
    "Garmin Core Update Service "=2 (0x2)
    .
    [HKEY_LOCAL_MACHINE\software\microsoft\security center]
    "AntiVirusOverride "=dword:00000001
    .
    [HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\ZoneLabsFirewall]
    "DisableMonitoring "=dword:00000001
    .
    [HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]
    "DisableNotifications "= 1 (0x1)
    .
    [HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
    "%windir%\\system32\\sessmgr.exe "=
    "c:\\Program Files\\Microsoft Office\\Office12\\OUTLOOK.EXE "=
    "c:\\Program Files\\Microsoft Office\\Office12\\GROOVE.EXE "=
    "c:\\Program Files\\Microsoft Office\\Office12\\ONENOTE.EXE "=
    "%windir%\\Network Diagnostic\\xpnetdiag.exe "=
    "c:\\WINDOWS\\system32\\dpvsetup.exe "=
    "c:\\Program Files\\Messenger\\msmsgs.exe "=
    "c:\\WINDOWS\\system32\\ftp.exe "=
    "c:\\Program Files\\WS_FTP\\WS_FTP95.exe "=
    "c:\\Program Files\\Nero\\Nero 7\\Nero ShowTime\\ShowTime.exe "=
    "c:\\Program Files\\Windows Live\\Messenger\\msnmsgr.exe "=
    "c:\\Program Files\\Logitech\\Logitech Harmony Remote Software 7\\HarmonyRemote.exe "=
    "c:\\Program Files\\Bonjour\\mDNSResponder.exe "=
    .
    R0 AVGIDSHX;AVGIDSHX;c:\windows\system32\drivers\avgidshx.sys [4/19/2012 04:50 55776]
    R0 Avglogx;AVG Logging Driver;c:\windows\system32\drivers\avglogx.sys [8/9/2012 13:56 177376]
    R0 Avgrkx86;AVG Anti-Rootkit Driver;c:\windows\system32\drivers\avgrkx86.sys [9/7/2010 03:48 35552]
    R0 gfibto;gfibto;c:\windows\system32\drivers\gfibto.sys [2/10/2013 21:03 13560]
    R1 AVGIDSDriver;AVGIDSDriver;c:\windows\system32\drivers\avgidsdriverx.sys [12/23/2011 13:32 179936]
    R1 AVGIDSShim;AVGIDSShim;c:\windows\system32\drivers\avgidsshimx.sys [12/23/2011 13:32 19936]
    R1 Avgldx86;AVG AVI Loader Driver;c:\windows\system32\drivers\avgldx86.sys [9/7/2010 03:48 159712]
    R1 Avgtdix;AVG TDI Driver;c:\windows\system32\drivers\avgtdix.sys [9/7/2010 03:49 164832]
    R1 SASDIFSV;SASDIFSV;c:\program files\SUPERAntiSpyware\SASDIFSV.SYS [1/5/2010 08:56 12880]
    R1 SASKUTIL;SASKUTIL;c:\program files\SUPERAntiSpyware\SASKUTIL.SYS [1/5/2010 08:56 67664]
    R2 !SASCORE;SAS Core Service;c:\program files\SUPERAntiSpyware\SASCORE.EXE [7/14/2010 20:44 116608]
    R2 avgwd;AVG WatchDog;c:\program files\AVG\AVG2013\avgwdsvc.exe [10/22/2012 14:05 196664]
    R2 WUSB54GPv4SVC;WUSB54GPv4SVC;c:\program files\Wireless-G Portable USB Adapter Wireless Network Monitor\WLService.exe [12/1/2007 14:44 41025]
    R3 AtcL001;NDIS Miniport Driver for Atheros L1 Gigabit Ethernet Controller;c:\windows\system32\drivers\l151x86.sys [8/29/2007 19:41 36864]
    R3 DCamUSBLTN;Kodak DVC325 Digital Video Camera;c:\windows\system32\drivers\dvc325.sys [11/9/1999 22:00 112836]
    S0 Lbd;Lbd;c:\windows\system32\DRIVERS\Lbd.sys --> c:\windows\system32\DRIVERS\Lbd.sys [?]
    S2 AVGIDSAgent;AVGIDSAgent;c:\program files\AVG\AVG2013\avgidsagent.exe [11/16/2012 00:34 5814904]
    S3 motccgp;Motorola USB Composite Device Driver;c:\windows\system32\DRIVERS\motccgp.sys --> c:\windows\system32\DRIVERS\motccgp.sys [?]
    S3 motccgpfl;MotCcgpFlService;c:\windows\system32\DRIVERS\motccgpfl.sys --> c:\windows\system32\DRIVERS\motccgpfl.sys [?]
    S3 SASENUM;SASENUM;c:\program files\SUPERAntiSpyware\SASENUM.SYS [1/5/2010 08:56 12872]
    S4 Garmin Core Update Service;Garmin Core Update Service;c:\program files\Garmin\Core Update Service\Garmin.Cartography.MapUpdate.CoreService.exe [3/12/2013 13:19 185688]
    S4 gupdate1c9961f125551c6;Google Update Service (gupdate1c9961f125551c6);c:\program files\Google\Update\GoogleUpdate.exe [2/23/2009 20:27 133104]
    S4 TivoBeacon2;TiVo Beacon Service;c:\program files\TiVo\Desktop\TiVoBeacon.exe [8/24/2010 17:02 1104656]
    .
    --- Other Services/Drivers In Memory ---
    .
    *NewlyCreated* - GTNDIS5
    *NewlyCreated* - WS2IFSL
    .
    [HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost]
    getPlusHelper REG_MULTI_SZ getPlusHelper
    .
    [HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{10880D85-AAD9-4558-ABDC-2AB1552D831F}]
    2007-09-20 02:46 451872 ----a-w- c:\program files\Common Files\LightScribe\LSRunOnce.exe
    .
    Contents of the 'Scheduled Tasks' folder
    .
    2013-05-14 c:\windows\Tasks\Adobe Flash Player Updater.job
    - c:\windows\system32\Macromed\Flash\FlashPlayerUpdateService.exe [2012-04-14 06:12]
    .
    2013-05-14 c:\windows\Tasks\GoogleUpdateTaskMachineCore.job
    - c:\program files\Google\Update\GoogleUpdate.exe [2009-02-24 01:27]
    .
    2013-05-14 c:\windows\Tasks\GoogleUpdateTaskMachineUA.job
    - c:\program files\Google\Update\GoogleUpdate.exe [2009-02-24 01:27]
    .
    2013-05-14 c:\windows\Tasks\GoogleUpdateTaskUserS-1-5-21-299502267-1123561945-839522115-1003Core.job
    - c:\documents and settings\Dufresne\Local Settings\Application Data\Google\Update\GoogleUpdate.exe [2011-07-06 20:25]
    .
    2013-05-14 c:\windows\Tasks\GoogleUpdateTaskUserS-1-5-21-299502267-1123561945-839522115-1003UA.job
    - c:\documents and settings\Dufresne\Local Settings\Application Data\Google\Update\GoogleUpdate.exe [2011-07-06 20:25]
    .
    2013-05-14 c:\windows\Tasks\pixillionDowngrade.job
    - c:\program files\NCH Software\Pixillion\pixillion.exe [2011-04-27 23:24]
    .
    2013-05-14 c:\windows\Tasks\pixillionShakeIcon.job
    - c:\program files\NCH Software\Pixillion\pixillion.exe [2011-04-27 23:24]
    .
    2013-05-14 c:\windows\Tasks\RealUpgradeLogonTaskS-1-5-21-299502267-1123561945-839522115-1003.job
    - c:\program files\Real\RealUpgrade\realupgrade.exe [2010-02-25 03:09]
    .
    2013-05-14 c:\windows\Tasks\RealUpgradeScheduledTaskS-1-5-21-299502267-1123561945-839522115-1003.job
    - c:\program files\Real\RealUpgrade\realupgrade.exe [2010-02-25 03:09]
    .
    2013-05-17 c:\windows\Tasks\User_Feed_Synchronization-{12B68F65-51FE-4A6C-B798-4F7B3692C98C}.job
    - c:\windows\system32\msfeedssync.exe [2007-08-13 09:31]
    .
    .
    ------- Supplementary Scan -------
    .
    uStart Page = hxxp://www.wnd.com/
    uInternet Settings,ProxyOverride = 192.168.*.*;*.local
    IE: Add to Google Photos Screensa&ver - c:\windows\system32\GPhotos.scr/200
    TCP: DhcpNameServer = 209.18.47.61 209.18.47.62
    DPF: Garmin Communicator Plug-In - hxxps://static.garmincdn.com/gcp/ie/2.9.3.0/GarminAxControl.CAB
    FF - ProfilePath - c:\documents and settings\Dufresne\Application Data\Mozilla\Firefox\Profiles\ps7ggpty.default\
    FF - prefs.js: browser.search.defaulturl - hxxp://search.conduit.com/ResultsExt.aspx?ctid=CT2559647&SearchSource=3&q={searchTerms}
    FF - prefs.js: browser.search.selectedEngine - Google
    FF - prefs.js: browser.startup.homepage - hxxp://worldnetdaily.com/
    FF - prefs.js: keyword.URL - hxxps://duckduckgo.com/?q=
    FF - ExtSQL: 2013-04-03 20:26; jid1-ZAdIEUB7XOzOJw@jetpack; c:\documents and settings\Dufresne\Application Data\Mozilla\Firefox\Profiles\ps7ggpty.default\extensions\jid1-ZAdIEUB7XOzOJw@jetpack.xpi
    FF - ExtSQL: !HIDDEN! 2009-09-02 03:00; {20a82645-c095-46ed-80e3-08825760534b}; c:\windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\DotNetAssistantExtension
    FF - user.js: yahoo.ytff.general.dontshowhpoffer - true);user_pref(extensions.zonealarm.autoRvrt, false
    FF - user.js: extensions.zonealarm_i.newTab - false
    FF - user.js: extensions.zonealarm.tlbrSrchUrl - hxxp://search.zonealarm.com/search?Source=ToolBar&oemCode=ZLN15433043594532-1001&toolbarId=base&affiliateId=1025&Lan={dfltLng}&utid=78525803000000000000001d6035caf7&q=
    FF - user.js: extensions.zonealarm.id - 78525803000000000000001d6035caf7
    FF - user.js: extensions.zonealarm.instlDay - 15581
    FF - user.js: extensions.zonealarm.vrsn - 1.6.7.4
    FF - user.js: extensions.zonealarm.vrsni - 1.6.7.4
    FF - user.js: extensions.zonealarm_i.vrsnTs - 1.6.7.423:22
    FF - user.js: extensions.zonealarm.prtnrId - checkpoint
    FF - user.js: extensions.zonealarm.prdct - zonealarm
    FF - user.js: extensions.zonealarm.aflt - 1025
    FF - user.js: extensions.zonealarm_i.smplGrp - none
    FF - user.js: extensions.zonealarm.tlbrId - base
    FF - user.js: extensions.zonealarm.instlRef - ZLN15433043594532-1001
    FF - user.js: extensions.zonealarm.dfltLng - en
    FF - user.js: extensions.zonealarm.excTlbr - false
    FF - user.js: extensions.zonealarm.admin - false
    .
    - - - - ORPHANS REMOVED - - - -
    .
    URLSearchHooks-{6c97a91e-4524-4019-86af-2aa2d567bf5c} - (no file)
    SafeBoot-mbamchameleon
    SafeBoot-X ???
    MSConfigStartUp-Adobe Reader Speed Launcher - c:\program files\Adobe\Reader 8.0\Reader\Reader_sl.exe
    MSConfigStartUp-Messenger (Yahoo!) - c:\program files\Yahoo!\Messenger\YahooMessenger.exe
    MSConfigStartUp-SoundMAX - c:\program files\Analog Devices\SoundMAX\Smax4.exe
    MSConfigStartUp-SoundMAXPnP - c:\program files\Analog Devices\Core\smax4pnp.exe
    MSConfigStartUp-TkBellExe - c:\program files\Common Files\Real\Update_OB\realsched.exe
    .
    .
    .
    **************************************************************************
    .
    catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
    Rootkit scan 2013-05-17 16:56
    Windows 5.1.2600 Service Pack 3 NTFS
    .
    scanning hidden processes ...
    .
    scanning hidden autostart entries ...
    .
    scanning hidden files ...
    .
    scan completed successfully
    hidden files: 0
    .
    **************************************************************************
    Binary file temp00 matches
    .
    --------------------- LOCKED REGISTRY KEYS ---------------------
    .
    [HKEY_LOCAL_MACHINE\software\Classes\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}]
    @Denied: (A 2) (Everyone)
    @= "FlashBroker "
    "LocalizedString "= "@c:\\WINDOWS\\system32\\Macromed\\Flash\\FlashUtil32_11_6_602_180_ActiveX.exe,-101 "
    .
    [HKEY_LOCAL_MACHINE\software\Classes\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}\Elevation]
    "Enabled "=dword:00000001
    .
    [HKEY_LOCAL_MACHINE\software\Classes\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}\LocalServer32]
    @= "c:\\WINDOWS\\system32\\Macromed\\Flash\\FlashUtil32_11_6_602_180_ActiveX.exe "
    .
    [HKEY_LOCAL_MACHINE\software\Classes\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}\TypeLib]
    @= "{FAB3E735-69C7-453B-A446-B6823C6DF1C9} "
    .
    [HKEY_LOCAL_MACHINE\software\Classes\Interface\{6AE38AE0-750C-11E1-B0C4-0800200C9A66}]
    @Denied: (A 2) (Everyone)
    @= "IFlashBroker5 "
    .
    [HKEY_LOCAL_MACHINE\software\Classes\Interface\{6AE38AE0-750C-11E1-B0C4-0800200C9A66}\ProxyStubClsid32]
    @= "{00020424-0000-0000-C000-000000000046} "
    .
    [HKEY_LOCAL_MACHINE\software\Classes\Interface\{6AE38AE0-750C-11E1-B0C4-0800200C9A66}\TypeLib]
    @= "{FAB3E735-69C7-453B-A446-B6823C6DF1C9} "
    "Version "= "1.0 "
    .
    [HKEY_LOCAL_MACHINE\System\ControlSet001\Control\SafeBoot\Minimal\X**0|‚*@¶·]
    @= "Driver "
    .
    [HKEY_LOCAL_MACHINE\System\ControlSet001\Control\SafeBoot\Network\X**0|‚*@¶·]
    @= "Driver "
    .
    [HKEY_LOCAL_MACHINE\System\ControlSet001\Services\X**0|‚*@¶·]
    "ImagePath "=expand: "\\??\\c:\\WINDOWS\\system32\\drivers\\X ???.sys "
    "Start "=dword:00000001
    "Type "=dword:00000001
    "ErrorControl "=dword:00000000
    .
    --------------------- DLLs Loaded Under Running Processes ---------------------
    .
    - - - - - - - > 'winlogon.exe'(948)
    c:\program files\common files\logitech\bluetooth\LBTWlgn.dll
    c:\program files\common files\logitech\bluetooth\LBTServ.dll
    .
    - - - - - - - > 'explorer.exe'(2876)
    c:\windows\system32\WININET.dll
    c:\program files\Carbonite\Carbonite Backup\CarboniteNSE.dll
    c:\windows\WinSxS\x86_Microsoft.VC80.CRT_1fc8b3b9a1e18e3b_8.0.50727.6195_x-ww_44262b86\MSVCR80.dll
    c:\windows\system32\ieframe.dll
    c:\windows\system32\webcheck.dll
    c:\windows\system32\WPDShServiceObj.dll
    c:\windows\system32\PortableDeviceTypes.dll
    c:\windows\system32\PortableDeviceApi.dll
    .
    ------------------------ Other Running Processes ------------------------
    .
    c:\program files\Bonjour\mDNSResponder.exe
    c:\program files\Carbonite\Carbonite Backup\carboniteservice.exe
    c:\program files\Java\jre7\bin\jqs.exe
    c:\program files\Common Files\LightScribe\LSSrvc.exe
    c:\windows\system32\nvsvc32.exe
    c:\program files\Wireless-G Portable USB Adapter Wireless Network Monitor\WUSB54GPv4.exe
    c:\windows\Microsoft.NET\Framework\v4.0.30319\WPF\WPFFontCache_v0400.exe
    .
    **************************************************************************
    .
    Completion time: 2013-05-17 17:02:25 - machine was rebooted
    ComboFix-quarantined-files.txt 2013-05-17 22:02
    ComboFix2.txt 2010-01-22 23:48
    .
    Pre-Run: 187,387,531,264 bytes free
    Post-Run: 187,850,997,760 bytes free
    .
    - - End Of File - - 620109DD299512008C7815486DB23833
     
  20. 2013/05/17
    broni

    broni Moderator Malware Analyst

    Joined:
    2002/08/01
    Messages:
    21,701
    Likes Received:
    116
    Looks good.

    How is computer doing?

    If you uninstalled AVG you can reinstall it now.

    [​IMG] Please download AdwCleaner by Xplode onto your desktop.
    • Close all open programs and internet browsers.
    • Double click on adwcleaner.exe to run the tool.
    • Click on Delete.
    • Confirm each time with Ok.
    • Your computer will be rebooted automatically. A text file will open after the restart.
    • Please post the contents of that logfile with your next reply.
    • You can find the logfile at C:\AdwCleaner[S1].txt as well.

    [​IMG] Please download Junkware Removal Tool to your desktop.
    • Shut down your protection software now to avoid potential conflicts.
    • Run the tool by double-clicking it. If you are using Windows Vista, 7, or 8; instead of double-clicking, right-mouse click JRT.exe and select "Run as Administrator ".
    • The tool will open and start scanning your system.
    • Please be patient as this can take a while to complete depending on your system's specifications.
    • On completion, a log (JRT.txt) is saved to your desktop and will automatically open.
    • Post the contents of JRT.txt into your next message.

    [​IMG] Download OTL to your Desktop.
    Alternate download: http://www.itxassociates.com/OT-Tools/OTL.exe
    • Double click on the icon to run it. Make sure all other windows are closed and to let it run uninterrupted.
    • Click the Scan All Users checkbox.
    • Click the Quick Scan button. Do not change any settings unless otherwise told to do so. The scan wont take long.
    • When the scan completes, it will open two notepad windows: OTL.txt and Extras.txt. These are saved in the same location as OTL.
    • Please copy (Edit->Select All, Edit->Copy) the contents of these files, one at a time, and post them back here.
     
  21. 2013/05/17
    chinaclipper

    chinaclipper Well-Known Member Thread Starter

    Joined:
    2010/01/20
    Messages:
    96
    Likes Received:
    0
    <sigh> It seems to have its moments. I say that because its STILL slow to load Firefox, but faster than before, and only half the time. GO figure....
    I reinstalled AVG, I will do the rest as requested!
     

Share This Page

  1. This site uses cookies to help personalise content, tailor your experience and to keep you logged in if you register.
    By continuing to use this site, you are consenting to our use of cookies.