Help infected wit blood hound

Status
Not open for further replies.

KoRn

In the zone
help gus im infected wit bloodhound .exploit.6 and nav 2005 cant remove it please help me what should i do i even downloaded the latest virus definitions but nahi chalta hai ofcourse ma pc's runnin perfectly but still man i wanna be virus free. :shock: :x :(
 

enoonmai

Cyborg Agent
Norton AntiVirus can detect unknown viruses of various types using a heuristics search called "Bloodhound" which was developed by Symantec. When Bloodhound detects an unknown virus, it reports the file name as one of many possible vulnerabilities. The best thing to do is to download and run HijackThis from here:

*www.spywareinfo.com/~merijn/downloads.html

so that we may take a look at what "exploit" is currently being detected by Norton that its unable to detect properly. Run HJT and post the log file it generates back here so we can take a look at it.
 
OP
KoRn

KoRn

In the zone
please talk in a simpler way i can undrstand and is dis hijackthis thingee another anti virus cuz i jus wabt nav dats it dude.
 

bharathbala2003

why need title?
@chwamki.. jus download wat enoonmai said.. and jus run in.. select the option scan and save log file.. jus copy and paste that log file here...
 

swatkat

Technomancer
Download the Outlook Express Patch for the exploit here....
*www.microsoft.com/technet/security/bulletin/ms04-013.mspx

Aftert this, get CCleaner and CleanUp!, and run them both....
*www.ccleaner.com/
*cleanup.stevengould.org/

Learn how to use HijackThis here...
*www.thinkdigit.com/forum/viewtopic.php?t=15729

after that post the Log file content...
 
OP
KoRn

KoRn

In the zone
Heres wat was displayed in notepad after i scaned pc.


Logfile of HijackThis v1.99.1
Scan saved at 2:13:07 PM, on 3/13/2005
Platform: Windows XP (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 (6.00.2600.0000)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Common Files\Symantec Shared\ccProxy.exe
C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe
C:\Program Files\Norton Internet Security\ISSVC.exe
C:\Program Files\Common Files\Symantec Shared\SNDSrvc.exe
C:\Program Files\Common Files\Symantec Shared\SPBBC\SPBBCSvc.exe
C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
C:\WINDOWS\System32\imapi.exe
C:\Program Files\Norton Internet Security\Norton AntiVirus\navapsvc.exe
C:\WINDOWS\System32\nvsvc32.exe
C:\WINDOWS\system32\pctspk.exe
C:\Program Files\Common Files\Symantec Shared\CCPD-LC\symlcsvc.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\Mixer.exe
C:\WINDOWS\System32\RUNDLL32.EXE
C:\WINDOWS\System32\SK2690DM.EXE
C:\Program Files\Winamp\winampa.exe
C:\Program Files\Common Files\Symantec Shared\ccApp.exe
C:\Program Files\Microsoft AntiSpyware\gcasServ.exe
C:\Program Files\Microsoft AntiSpyware\gcasDtServ.exe
C:\Program Files\Winamp\winamp.exe
C:\Program Files\Common Files\Symantec Shared\AdBlocking\NSMdtr.exe
C:\Program Files\Internet Explorer\iexplore.exe
D:\Program Files\Yahoo!\Messenger\ypager.exe
C:\WINDOWS\System32\rundll32.exe
D:\PROGRA~1\DAP\DAP.EXE
D:\Program Files\ht\HijackThis.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = www.mail.yahoo.com
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = www.mail.yahoo.com
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Local Page =
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page =
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = *hot-searches.com*;*lender-search.com*
O1 - Hosts file is located at: C:\WINDOWS\nsdb\hosts
O1 - Hosts: 82.179.166.164 lender-search.com
O1 - Hosts: 82.179.166.165 hot-searches.com
O2 - BHO: Norton Internet Security - {9ECB9560-04F9-4bbc-943D-298DDF1699E1} - C:\Program Files\Common Files\Symantec Shared\AdBlocking\NISShExt.dll
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar1.dll
O2 - BHO: NAV Helper - {BDF3E430-B101-42AD-A544-FADC6B084872} - C:\Program Files\Norton Internet Security\Norton AntiVirus\NavShExt.dll
O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINDOWS\System32\msdxm.ocx
O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar1.dll
O3 - Toolbar: DAP Bar - {62999427-33FC-4baf-9C9C-BCE6BD127F08} - D:\Program Files\DAP\DAPIEBar.dll
O3 - Toolbar: Norton Internet Security - {0B53EAC3-8D69-4b9e-9B19-A37C9A5676A7} - C:\Program Files\Common Files\Symantec Shared\AdBlocking\NISShExt.dll
O3 - Toolbar: Norton AntiVirus - {42CDD1BF-3FFB-4238-8AD1-7859DF00B1D6} - C:\Program Files\Norton Internet Security\Norton AntiVirus\NavShExt.dll
O4 - HKLM\..\Run: [SystemTray] SysTray.Exe
O4 - HKLM\..\Run: [C-Media Mixer] Mixer.exe /startup
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\System32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [nwiz] nwiz.exe /install
O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\WINDOWS\System32\NvMcTray.dll,NvTaskbarInit
O4 - HKLM\..\Run: [HPDJ Taskbar Utility] C:\WINDOWS\System32\spool\drivers\w32x86\3\hpztsb03.exe
O4 - HKLM\..\Run: [Hot Key Kbd 2690 Daemon] SK2690DM.EXE
O4 - HKLM\..\Run: [WinampAgent] C:\Program Files\Winamp\winampa.exe
O4 - HKLM\..\Run: [ccApp] "C:\Program Files\Common Files\Symantec Shared\ccApp.exe"
O4 - HKLM\..\Run: [SSC_UserPrompt] C:\Program Files\Common Files\Symantec Shared\Security Center\UsrPrmpt.exe
O4 - HKLM\..\Run: [gcasServ] "C:\Program Files\Microsoft AntiSpyware\gcasServ.exe"
O4 - HKLM\..\Run: [Symantec NetDriver Monitor] C:\PROGRA~1\SYMNET~1\SNDMon.exe
O4 - HKCU\..\Run: [Yahoo! Pager] D:\Program Files\Yahoo!\Messenger\ypager.exe -quiet
O4 - HKCU\..\Run: [Windows Registry Repair Pro] d:\Program Files\3B Software\Windows Registry Repair Pro\RegistryRepairPro.exe 4
O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office\OSA9.EXE
O8 - Extra context menu item: &Download with &DAP - D:\PROGRA~1\DAP\dapextie.htm
O8 - Extra context menu item: &Google Search - res://C:\Program Files\Google\GoogleToolbar1.dll/cmsearch.html
O8 - Extra context menu item: Backward Links - res://C:\Program Files\Google\GoogleToolbar1.dll/cmbacklinks.html
O8 - Extra context menu item: Cached Snapshot of Page - res://C:\Program Files\Google\GoogleToolbar1.dll/cmcache.html
O8 - Extra context menu item: Download &all with DAP - D:\PROGRA~1\DAP\dapextie2.htm
O8 - Extra context menu item: Similar Pages - res://C:\Program Files\Google\GoogleToolbar1.dll/cmsimilar.html
O8 - Extra context menu item: Translate into English - res://C:\Program Files\Google\GoogleToolbar1.dll/cmtrans.html
O9 - Extra button: Messenger - {4528BBE0-4E08-11D5-AD55-00010333D0AD} - D:\Program Files\Yahoo!\Messenger\yhexbmes0521.dll
O9 - Extra 'Tools' menuitem: Yahoo! Messenger - {4528BBE0-4E08-11D5-AD55-00010333D0AD} - D:\Program Files\Yahoo!\Messenger\yhexbmes0521.dll
O9 - Extra button: Run DAP - {669695BC-A811-4A9D-8CDF-BA8C795F261C} - D:\PROGRA~1\DAP\DAP.EXE
O9 - Extra button: Related - {c95fe080-8f5d-11d2-a20b-00aa003c157a} - C:\WINDOWS\web\related.htm
O9 - Extra 'Tools' menuitem: Show &Related Links - {c95fe080-8f5d-11d2-a20b-00aa003c157a} - C:\WINDOWS\web\related.htm
O17 - HKLM\System\CCS\Services\Tcpip\..\{5DDED4B0-7DD8-47F4-8A03-0D18BAACD731}: NameServer = 210.212.12.3,210.212.12.5
O17 - HKLM\System\CS1\Services\Tcpip\..\{5DDED4B0-7DD8-47F4-8A03-0D18BAACD731}: NameServer = 210.212.12.3,210.212.12.5
O17 - HKLM\System\CS2\Services\Tcpip\..\{5DDED4B0-7DD8-47F4-8A03-0D18BAACD731}: NameServer = 210.212.12.3,210.212.12.5
O23 - Service: Symantec Event Manager (ccEvtMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
O23 - Service: Symantec Network Proxy (ccProxy) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccProxy.exe
O23 - Service: Symantec Password Validation (ccPwdSvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccPwdSvc.exe
O23 - Service: Symantec Settings Manager (ccSetMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe
O23 - Service: ISSvc (ISSVC) - Symantec Corporation - C:\Program Files\Norton Internet Security\ISSVC.exe
O23 - Service: Norton AntiVirus Auto-Protect Service (navapsvc) - Symantec Corporation - C:\Program Files\Norton Internet Security\Norton AntiVirus\navapsvc.exe
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\System32\nvsvc32.exe
O23 - Service: PCTEL Speaker Phone (Pctspk) - PCtel, Inc. - C:\WINDOWS\system32\pctspk.exe
O23 - Service: SAVScan - Symantec Corporation - C:\Program Files\Norton Internet Security\Norton AntiVirus\SAVScan.exe
O23 - Service: ScriptBlocking Service (SBService) - Symantec Corporation - C:\PROGRA~1\COMMON~1\SYMANT~1\SCRIPT~1\SBServ.exe
O23 - Service: Symantec Network Drivers Service (SNDSrvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\SNDSrvc.exe
O23 - Service: Symantec SPBBCSvc (SPBBCSvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\SPBBC\SPBBCSvc.exe
O23 - Service: Symantec Core LC - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\CCPD-LC\symlcsvc.exe
 

swatkat

Technomancer
chwamiki said:
Heres wat was displayed in notepad after i scaned pc.


Logfile of HijackThis v1.99.1
Scan saved at 2:13:07 PM, on 3/13/2005
Platform: Windows XP (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 (6.00.2600.0000)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Common Files\Symantec Shared\ccProxy.exe
C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe
C:\Program Files\Norton Internet Security\ISSVC.exe
C:\Program Files\Common Files\Symantec Shared\SNDSrvc.exe
C:\Program Files\Common Files\Symantec Shared\SPBBC\SPBBCSvc.exe
C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
C:\WINDOWS\System32\imapi.exe
C:\Program Files\Norton Internet Security\Norton AntiVirus\navapsvc.exe
C:\WINDOWS\System32\nvsvc32.exe
C:\WINDOWS\system32\pctspk.exe
C:\Program Files\Common Files\Symantec Shared\CCPD-LC\symlcsvc.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\Mixer.exe
C:\WINDOWS\System32\RUNDLL32.EXE
C:\WINDOWS\System32\SK2690DM.EXE
C:\Program Files\Winamp\winampa.exe
C:\Program Files\Common Files\Symantec Shared\ccApp.exe
C:\Program Files\Microsoft AntiSpyware\gcasServ.exe
C:\Program Files\Microsoft AntiSpyware\gcasDtServ.exe
C:\Program Files\Winamp\winamp.exe
C:\Program Files\Common Files\Symantec Shared\AdBlocking\NSMdtr.exe
C:\Program Files\Internet Explorer\iexplore.exe
D:\Program Files\Yahoo!\Messenger\ypager.exe
C:\WINDOWS\System32\rundll32.exe
D:\PROGRA~1\DAP\DAP.EXE
D:\Program Files\ht\HijackThis.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = www.mail.yahoo.com
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = www.mail.yahoo.com
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Local Page =
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page =
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = *hot-searches.com*;*lender-search.com*
O1 - Hosts file is located at: C:\WINDOWS\nsdb\hosts
O1 - Hosts: 82.179.166.164 lender-search.com
O1 - Hosts: 82.179.166.165 hot-searches.com

O2 - BHO: Norton Internet Security - {9ECB9560-04F9-4bbc-943D-298DDF1699E1} - C:\Program Files\Common Files\Symantec Shared\AdBlocking\NISShExt.dll
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar1.dll
O2 - BHO: NAV Helper - {BDF3E430-B101-42AD-A544-FADC6B084872} - C:\Program Files\Norton Internet Security\Norton AntiVirus\NavShExt.dll
O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINDOWS\System32\msdxm.ocx
O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar1.dll
O3 - Toolbar: DAP Bar - {62999427-33FC-4baf-9C9C-BCE6BD127F08} - D:\Program Files\DAP\DAPIEBar.dll
O3 - Toolbar: Norton Internet Security - {0B53EAC3-8D69-4b9e-9B19-A37C9A5676A7} - C:\Program Files\Common Files\Symantec Shared\AdBlocking\NISShExt.dll
O3 - Toolbar: Norton AntiVirus - {42CDD1BF-3FFB-4238-8AD1-7859DF00B1D6} - C:\Program Files\Norton Internet Security\Norton AntiVirus\NavShExt.dll
O4 - HKLM\..\Run: [SystemTray] SysTray.Exe
O4 - HKLM\..\Run: [C-Media Mixer] Mixer.exe /startup
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\System32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [nwiz] nwiz.exe /install
O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\WINDOWS\System32\NvMcTray.dll,NvTaskbarInit
O4 - HKLM\..\Run: [HPDJ Taskbar Utility] C:\WINDOWS\System32\spool\drivers\w32x86\3\hpztsb03.exe
O4 - HKLM\..\Run: [Hot Key Kbd 2690 Daemon] SK2690DM.EXE
O4 - HKLM\..\Run: [WinampAgent] C:\Program Files\Winamp\winampa.exe
O4 - HKLM\..\Run: [ccApp] "C:\Program Files\Common Files\Symantec Shared\ccApp.exe"
O4 - HKLM\..\Run: [SSC_UserPrompt] C:\Program Files\Common Files\Symantec Shared\Security Center\UsrPrmpt.exe
O4 - HKLM\..\Run: [gcasServ] "C:\Program Files\Microsoft AntiSpyware\gcasServ.exe"
O4 - HKLM\..\Run: [Symantec NetDriver Monitor] C:\PROGRA~1\SYMNET~1\SNDMon.exe
O4 - HKCU\..\Run: [Yahoo! Pager] D:\Program Files\Yahoo!\Messenger\ypager.exe -quiet
O4 - HKCU\..\Run: [Windows Registry Repair Pro] d:\Program Files\3B Software\Windows Registry Repair Pro\RegistryRepairPro.exe 4
O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office\OSA9.EXE
O8 - Extra context menu item: &Download with &DAP - D:\PROGRA~1\DAP\dapextie.htm
O8 - Extra context menu item: &Google Search - res://C:\Program Files\Google\GoogleToolbar1.dll/cmsearch.html
O8 - Extra context menu item: Backward Links - res://C:\Program Files\Google\GoogleToolbar1.dll/cmbacklinks.html
O8 - Extra context menu item: Cached Snapshot of Page - res://C:\Program Files\Google\GoogleToolbar1.dll/cmcache.html
O8 - Extra context menu item: Download &all with DAP - D:\PROGRA~1\DAP\dapextie2.htm
O8 - Extra context menu item: Similar Pages - res://C:\Program Files\Google\GoogleToolbar1.dll/cmsimilar.html
O8 - Extra context menu item: Translate into English - res://C:\Program Files\Google\GoogleToolbar1.dll/cmtrans.html
O9 - Extra button: Messenger - {4528BBE0-4E08-11D5-AD55-00010333D0AD} - D:\Program Files\Yahoo!\Messenger\yhexbmes0521.dll
O9 - Extra 'Tools' menuitem: Yahoo! Messenger - {4528BBE0-4E08-11D5-AD55-00010333D0AD} - D:\Program Files\Yahoo!\Messenger\yhexbmes0521.dll
O9 - Extra button: Run DAP - {669695BC-A811-4A9D-8CDF-BA8C795F261C} - D:\PROGRA~1\DAP\DAP.EXE
O9 - Extra button: Related - {c95fe080-8f5d-11d2-a20b-00aa003c157a} - C:\WINDOWS\web\related.htm
O9 - Extra 'Tools' menuitem: Show &Related Links - {c95fe080-8f5d-11d2-a20b-00aa003c157a} - C:\WINDOWS\web\related.htm

O17 - HKLM\System\CCS\Services\Tcpip\..\{5DDED4B0-7DD8-47F4-8A03-0D18BAACD731}: NameServer = 210.212.12.3,210.212.12.5
O17 - HKLM\System\CS1\Services\Tcpip\..\{5DDED4B0-7DD8-47F4-8A03-0D18BAACD731}: NameServer = 210.212.12.3,210.212.12.5
O17 - HKLM\System\CS2\Services\Tcpip\..\{5DDED4B0-7DD8-47F4-8A03-0D18BAACD731}: NameServer = 210.212.12.3,210.212.12.5
O23 - Service: Symantec Event Manager (ccEvtMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
O23 - Service: Symantec Network Proxy (ccProxy) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccProxy.exe
O23 - Service: Symantec Password Validation (ccPwdSvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccPwdSvc.exe
O23 - Service: Symantec Settings Manager (ccSetMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe
O23 - Service: ISSvc (ISSVC) - Symantec Corporation - C:\Program Files\Norton Internet Security\ISSVC.exe
O23 - Service: Norton AntiVirus Auto-Protect Service (navapsvc) - Symantec Corporation - C:\Program Files\Norton Internet Security\Norton AntiVirus\navapsvc.exe
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\System32\nvsvc32.exe
O23 - Service: PCTEL Speaker Phone (Pctspk) - PCtel, Inc. - C:\WINDOWS\system32\pctspk.exe
O23 - Service: SAVScan - Symantec Corporation - C:\Program Files\Norton Internet Security\Norton AntiVirus\SAVScan.exe
O23 - Service: ScriptBlocking Service (SBService) - Symantec Corporation - C:\PROGRA~1\COMMON~1\SYMANT~1\SCRIPT~1\SBServ.exe
O23 - Service: Symantec Network Drivers Service (SNDSrvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\SNDSrvc.exe
O23 - Service: Symantec SPBBCSvc (SPBBCSvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\SPBBC\SPBBCSvc.exe
O23 - Service: Symantec Core LC - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\CCPD-LC\symlcsvc.exe

Reboot in SAFE Mode.
Then run HijackThis and click the button "Do a System scan only".
After this select (put a check mark) for the entries that are made red above, and clikc "Fix".

After this run CCleaner and CleanUp! and Reboot to Normal mode.

Then post a FRESH log file...
 

bharathbala2003

why need title?
chwamiki said:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Common Files\Symantec Shared\ccProxy.exe
C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe
C:\Program Files\Norton Internet Security\ISSVC.exe
C:\Program Files\Common Files\Symantec Shared\SNDSrvc.exe
C:\Program Files\Common Files\Symantec Shared\SPBBC\SPBBCSvc.exe
C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
C:\WINDOWS\System32\imapi.exe
C:\Program Files\Norton Internet Security\Norton AntiVirus\navapsvc.exe
C:\WINDOWS\System32\nvsvc32.exe
C:\WINDOWS\system32\pctspk.exe
C:\Program Files\Common Files\Symantec Shared\CCPD-LC\symlcsvc.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\Mixer.exe
C:\WINDOWS\System32\RUNDLL32.EXE
C:\WINDOWS\System32\SK2690DM.EXE
C:\Program Files\Winamp\winampa.exe
C:\Program Files\Common Files\Symantec Shared\ccApp.exe
C:\Program Files\Microsoft AntiSpyware\gcasServ.exe
C:\Program Files\Microsoft AntiSpyware\gcasDtServ.exe
C:\Program Files\Winamp\winamp.exe
C:\Program Files\Common Files\Symantec Shared\AdBlocking\NSMdtr.exe
C:\Program Files\Internet Explorer\iexplore.exe
D:\Program Files\Yahoo!\Messenger\ypager.exe
C:\WINDOWS\System32\rundll32.exe
D:\PROGRA~1\DAP\DAP.EXE
D:\Program Files\ht\HijackThis.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = www.mail.yahoo.com
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = www.mail.yahoo.com
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Local Page =
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page =
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = *hot-searches.com*;*lender-search.com*
O1 - Hosts file is located at: C:\WINDOWS\nsdb\hosts
O1 - Hosts: 82.179.166.164 lender-search.com
O1 - Hosts: 82.179.166.165 hot-searches.com
O2 - BHO: Norton Internet Security - {9ECB9560-04F9-4bbc-943D-298DDF1699E1} - C:\Program Files\Common Files\Symantec Shared\AdBlocking\NISShExt.dll
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar1.dll
O2 - BHO: NAV Helper - {BDF3E430-B101-42AD-A544-FADC6B084872} - C:\Program Files\Norton Internet Security\Norton AntiVirus\NavShExt.dll
O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINDOWS\System32\msdxm.ocx
O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar1.dll
O3 - Toolbar: DAP Bar - {62999427-33FC-4baf-9C9C-BCE6BD127F08} - D:\Program Files\DAP\DAPIEBar.dll
O3 - Toolbar: Norton Internet Security - {0B53EAC3-8D69-4b9e-9B19-A37C9A5676A7} - C:\Program Files\Common Files\Symantec Shared\AdBlocking\NISShExt.dll
O3 - Toolbar: Norton AntiVirus - {42CDD1BF-3FFB-4238-8AD1-7859DF00B1D6} - C:\Program Files\Norton Internet Security\Norton AntiVirus\NavShExt.dll
O4 - HKLM\..\Run: [SystemTray] SysTray.Exe
O4 - HKLM\..\Run: [C-Media Mixer] Mixer.exe /startup
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\System32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [nwiz] nwiz.exe /install
O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\WINDOWS\System32\NvMcTray.dll,NvTaskbarInit
O4 - HKLM\..\Run: [HPDJ Taskbar Utility] C:\WINDOWS\System32\spool\drivers\w32x86\3\hpztsb03.exe
O4 - HKLM\..\Run: [Hot Key Kbd 2690 Daemon] SK2690DM.EXE
O4 - HKLM\..\Run: [WinampAgent] C:\Program Files\Winamp\winampa.exe
O4 - HKLM\..\Run: [ccApp] "C:\Program Files\Common Files\Symantec Shared\ccApp.exe"
O4 - HKLM\..\Run: [SSC_UserPrompt] C:\Program Files\Common Files\Symantec Shared\Security Center\UsrPrmpt.exe
O4 - HKLM\..\Run: [gcasServ] "C:\Program Files\Microsoft AntiSpyware\gcasServ.exe"
O4 - HKLM\..\Run: [Symantec NetDriver Monitor] C:\PROGRA~1\SYMNET~1\SNDMon.exe
O4 - HKCU\..\Run: [Yahoo! Pager] D:\Program Files\Yahoo!\Messenger\ypager.exe -quiet
O4 - HKCU\..\Run: [Windows Registry Repair Pro] d:\Program Files\3B Software\Windows Registry Repair Pro\RegistryRepairPro.exe 4
O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office\OSA9.EXE
O8 - Extra context menu item: &Download with &DAP - D:\PROGRA~1\DAP\dapextie.htm
O8 - Extra context menu item: &Google Search - res://C:\Program Files\Google\GoogleToolbar1.dll/cmsearch.html
O8 - Extra context menu item: Backward Links - res://C:\Program Files\Google\GoogleToolbar1.dll/cmbacklinks.html
O8 - Extra context menu item: Cached Snapshot of Page - res://C:\Program Files\Google\GoogleToolbar1.dll/cmcache.html
O8 - Extra context menu item: Download &all with DAP - D:\PROGRA~1\DAP\dapextie2.htm
O8 - Extra context menu item: Similar Pages - res://C:\Program Files\Google\GoogleToolbar1.dll/cmsimilar.html
O8 - Extra context menu item: Translate into English - res://C:\Program Files\Google\GoogleToolbar1.dll/cmtrans.html
O9 - Extra button: Messenger - {4528BBE0-4E08-11D5-AD55-00010333D0AD} - D:\Program Files\Yahoo!\Messenger\yhexbmes0521.dll
O9 - Extra 'Tools' menuitem: Yahoo! Messenger - {4528BBE0-4E08-11D5-AD55-00010333D0AD} - D:\Program Files\Yahoo!\Messenger\yhexbmes0521.dll
O9 - Extra button: Run DAP - {669695BC-A811-4A9D-8CDF-BA8C795F261C} - D:\PROGRA~1\DAP\DAP.EXE
O9 - Extra button: Related - {c95fe080-8f5d-11d2-a20b-00aa003c157a} - C:\WINDOWS\web\related.htm
O9 - Extra 'Tools' menuitem: Show &Related Links - {c95fe080-8f5d-11d2-a20b-00aa003c157a} - C:\WINDOWS\web\related.htm
O17 - HKLM\System\CCS\Services\Tcpip\..\{5DDED4B0-7DD8-47F4-8A03-0D18BAACD731}: NameServer = 210.212.12.3,210.212.12.5
O17 - HKLM\System\CS1\Services\Tcpip\..\{5DDED4B0-7DD8-47F4-8A03-0D18BAACD731}: NameServer = 210.212.12.3,210.212.12.5
O17 - HKLM\System\CS2\Services\Tcpip\..\{5DDED4B0-7DD8-47F4-8A03-0D18BAACD731}: NameServer = 210.212.12.3,210.212.12.5
O23 - Service: Symantec Event Manager (ccEvtMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
O23 - Service: Symantec Network Proxy (ccProxy) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccProxy.exe
O23 - Service: Symantec Password Validation (ccPwdSvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccPwdSvc.exe
O23 - Service: Symantec Settings Manager (ccSetMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe
O23 - Service: ISSvc (ISSVC) - Symantec Corporation - C:\Program Files\Norton Internet Security\ISSVC.exe
O23 - Service: Norton AntiVirus Auto-Protect Service (navapsvc) - Symantec Corporation - C:\Program Files\Norton Internet Security\Norton AntiVirus\navapsvc.exe
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\System32\nvsvc32.exe
O23 - Service: PCTEL Speaker Phone (Pctspk) - PCtel, Inc. - C:\WINDOWS\system32\pctspk.exe
O23 - Service: SAVScan - Symantec Corporation - C:\Program Files\Norton Internet Security\Norton AntiVirus\SAVScan.exe
O23 - Service: ScriptBlocking Service (SBService) - Symantec Corporation - C:\PROGRA~1\COMMON~1\SYMANT~1\SCRIPT~1\SBServ.exe
O23 - Service: Symantec Network Drivers Service (SNDSrvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\SNDSrvc.exe
O23 - Service: Symantec SPBBCSvc (SPBBCSvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\SPBBC\SPBBCSvc.exe
O23 - Service: Symantec Core LC - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\CCPD-LC\symlcsvc.exe

log into safe mode and fix the ones in red.. then restart the system and run the AV..
 
OP
KoRn

KoRn

In the zone
hey swatkat could u explain that in a simpler way i mean the part about running CCleaner and clean up for wat man i hav 2 downmload that to fow wat and wat is a FRESH log file dude.please xplain in a easier way.
 

bharathbala2003

why need title?
@chwamki..

get CCleaner and CleanUp!, and run them both....
*www.ccleaner.com/
*cleanup.stevengould.org/

as for fresh log.. after u clean the system with ccleaner.. then similarly run HIJACK THIS and post the log file..
 

swatkat

Technomancer
Download the softwares ClenUp! and CCleaner and install them.
Then run them, and simply click "Clean" in CleanUp! or "Run Cleaner" in CCleaner.

Fresh log means, after removing the bad things using HijackThis, you have to scan the system again using HijackThis and post the Log file again (as u did earlier!).
Dont forget to close ALL applications while fixing using HijackThis and also dont forget to boot in SAFE mode....

@bharathbala2003, those IP addresses r related to BSNL, and SK2690DM.EXE is the multimedia KeyBoard application, and Mixer.exe is the C-Media Onboard Sound Chip Configuration application....Dont Remove them....
 
OP
KoRn

KoRn

In the zone
uhhhhh kk kk ill download and after i do i will try to do the process.it kinda looks hard cuz im tooo young to do that stuff and besides im not a pc nerd
 

bharathbala2003

why need title?
lol u needn b a nerd to do this.. jus click on the given link n download the stuffs.. jus run it.. its jus a virus remover :D after u run it again run the hijack this and paste the log file.. simple m8..
 
OP
KoRn

KoRn

In the zone
heres wat i got after i ran ccleaner kk.ill post wat igot from the other software after sometime.

ANALYSIS COMPLETE - (15.121 secs)
------------------------------------------------------------------------------------------
580.5MB to be removed. (Approximate size)


Details of files to be deleted (Note: No files have been deleted yet)
------------------------------------------------------------------------------------------
C:\Documents and Settings\Chwamiki\Application Data\Mozilla\Firefox\profiles\scakil5e.default\history.dat 329 bytes
C:\Documents and Settings\Chwamiki\Application Data\Mozilla\Firefox\profiles\scakil5e.default\cache\_CACHE_003_ 4.00KB
C:\Documents and Settings\Chwamiki\Application Data\Mozilla\Firefox\profiles\scakil5e.default\cache\_CACHE_002_ 4.00KB
C:\Documents and Settings\Chwamiki\Application Data\Mozilla\Firefox\profiles\scakil5e.default\cache\_CACHE_001_ 4.00KB
C:\Documents and Settings\Chwamiki\Application Data\Mozilla\Firefox\profiles\scakil5e.default\cache\_CACHE_MAP_ 0.13MB
C:\WINDOWS\Debug\UserMode\userenv.log 0.12MB
C:\WINDOWS\Debug\oakley.log 0 bytes
C:\WINDOWS\Debug\mrt.log 234 bytes
C:\WINDOWS\Debug\NetSetup.LOG 2.47KB
C:\Documents and Settings\All Users\Application Data\Microsoft\Dr Watson\user.dmp 48.90KB
C:\Documents and Settings\All Users\Application Data\Microsoft\Dr Watson\drwtsn32.log 1.18MB
C:\WINDOWS\setuplog.txt 0.65MB
C:\WINDOWS\NDISLOG.TXT 0 bytes
C:\WINDOWS\SchedLog.Txt 31.78KB
C:\WINDOWS\brndlog.txt 8.84KB
C:\WINDOWS\OEWABLog.txt 1.26KB
C:\WINDOWS\brndlog.bak 237 bytes
C:\WINDOWS\WININIT.BAK 110 bytes
C:\WINDOWS\imsins.BAK 1.34KB
C:\WINDOWS\Windows Update.log 2.74KB
C:\WINDOWS\sessmgr.setup.log 1.03KB
C:\WINDOWS\DtcInstall.log 128 bytes
C:\WINDOWS\wiadebug.log 216 bytes
C:\WINDOWS\wiaservc.log 49 bytes
C:\WINDOWS\Sti_Trace.log 0 bytes
C:\WINDOWS\ocmsn.log 5.70KB
C:\WINDOWS\msgsocm.log 7.10KB
C:\WINDOWS\msmqinst.log 48.93KB
C:\WINDOWS\tsoc.log 67.68KB
C:\WINDOWS\ntdtcsetup.log 32.99KB
C:\WINDOWS\comsetup.log 57.04KB
C:\WINDOWS\iis6.log 0.20MB
C:\WINDOWS\ocgen.log 63.38KB
C:\WINDOWS\regopt.log 1.48KB
C:\WINDOWS\commigrate.log 403 bytes
C:\WINDOWS\mqw9xmig.log 328 bytes
C:\WINDOWS\FaxSetup.log 0.14MB
C:\WINDOWS\setuperr.log 81 bytes
C:\WINDOWS\setupact.log 0.17MB
C:\WINDOWS\wsdu.log 148 bytes
C:\WINDOWS\WINNT32.LOG 10.30KB
C:\WINDOWS\KB834707-IE6-20040929.115007.log 20.62KB
C:\WINDOWS\KB828741.log 36.68KB
C:\WINDOWS\KB835732.log 31.21KB
C:\WINDOWS\Q329834.log 24.69KB
C:\WINDOWS\KB823559.log 31.58KB
C:\WINDOWS\Q329048.log 24.22KB
C:\WINDOWS\Q810577.log 21.72KB
C:\WINDOWS\KB833987.log 16.21KB
C:\WINDOWS\setupapi.log 0.13MB
C:\WINDOWS\vminst.log 2.01KB
C:\WINDOWS\Q811630.log 15.00KB
C:\WINDOWS\Q329441.log 11.88KB
C:\WINDOWS\Q817606.log 11.60KB
C:\WINDOWS\Q329170.log 8.86KB
C:\WINDOWS\Q329115.log 1.54KB
C:\WINDOWS\Q329390.log 1.19KB
C:\WINDOWS\xpsp1hfm.log 31.80KB
C:\WINDOWS\Q810833.log 18.21KB
C:\WINDOWS\Q323255.log 923 bytes
C:\WINDOWS\svcpack.log 3.50KB
C:\WINDOWS\SYMEVENT.LOG 7.74KB
C:\WINDOWS\LUINSTALL.LOG 21.53KB
C:\WINDOWS\KB841356.log 16.05KB
C:\WINDOWS\WindowsUpdate.log 0.46MB
C:\WINDOWS\KB841533.log 13.97KB
C:\WINDOWS\wmsetup.log 10.24KB
C:\WINDOWS\KB840987.log 33.11KB
C:\WINDOWS\imsins.log 1.34KB
C:\WINDOWS\KB873376.log 17.52KB
C:\WINDOWS\DirectX.log 0.14MB
C:\WINDOWS\KB842773.log 5.89KB
C:\WINDOWS\KB887822.log 13.72KB
C:\WINDOWS\0.log 0 bytes
C:\WINDOWS\system32\wbem\Logs\wbemess.lo_ 64.03KB
C:\WINDOWS\system32\wbem\Logs\wbemess.log 15.78KB
C:\WINDOWS\system32\wbem\Logs\NTEVT.log 2 bytes
C:\WINDOWS\system32\wbem\Logs\WBEMSNMP.log 2 bytes
C:\WINDOWS\system32\wbem\Logs\WinMgmt.log 4.85KB
C:\WINDOWS\system32\wbem\Logs\wmiadap.log 181 bytes
C:\WINDOWS\system32\wbem\Logs\wmiprov.log 54.51KB
C:\WINDOWS\system32\wbem\Logs\wbemcore.log 119 bytes
C:\WINDOWS\system32\wbem\Logs\mofcomp.log 10.80KB
C:\WINDOWS\system32\wbem\Logs\setup.log 4.75KB
C:\WINDOWS\system32\wbem\Logs\FrameWork.log 54.20KB
C:\Documents and Settings\Chwamiki\Local Settings\Temp\control.xml 12.86KB
C:\Documents and Settings\Chwamiki\Local Settings\Temp\~DF3951.tmp 32.00KB
C:\Documents and Settings\Chwamiki\Local Settings\Temp\~DF1CD7.tmp 32.00KB
C:\Documents and Settings\Chwamiki\Local Settings\Temp\~DFBB8B.tmp 32.00KB
C:\Documents and Settings\Chwamiki\Local Settings\Temp\~DF3B87.tmp 32.00KB
C:\Documents and Settings\Chwamiki\Local Settings\Temp\~DF60C9.tmp 32.00KB
C:\Documents and Settings\Chwamiki\Local Settings\Temp\~DF5052.tmp 32.00KB
C:\Documents and Settings\Chwamiki\Local Settings\Temp\~DFD948.tmp 32.00KB
C:\Documents and Settings\Chwamiki\Local Settings\Temp\~DFDDBF.tmp 32.00KB
C:\Documents and Settings\Chwamiki\Local Settings\Temp\~DFC97C.tmp 32.00KB
C:\Documents and Settings\Chwamiki\Local Settings\Temp\~DF6A80.tmp 32.00KB
C:\Documents and Settings\Chwamiki\Local Settings\Temp\~DF5A3E.tmp 32.00KB
C:\Documents and Settings\Chwamiki\Local Settings\Temp\robots.bmp 7.93KB
C:\Documents and Settings\Chwamiki\Local Settings\Temp\contender.bmp 7.93KB
C:\Documents and Settings\Chwamiki\Local Settings\Temp\~DFC9.tmp 32.00KB
C:\Documents and Settings\Chwamiki\Local Settings\Temp\~DFE9A5.tmp 32.00KB
C:\Documents and Settings\Chwamiki\Local Settings\Temp\hpilog06.txt 4.56KB
C:\Documents and Settings\Chwamiki\Local Settings\Temp\hpilog05.txt 80.30KB
C:\Documents and Settings\Chwamiki\Local Settings\Temp\hpfiui.exe 0.31MB
C:\Documents and Settings\Chwamiki\Local Settings\Temp\setup.hpi 63.15KB
C:\Documents and Settings\Chwamiki\Local Settings\Temp\hpfback.exe 0.13MB
C:\Documents and Settings\Chwamiki\Local Settings\Temp\apps2.hpi 11.36KB
C:\Documents and Settings\Chwamiki\Local Settings\Temp\wowdemo.bmp 26.21KB
C:\Documents and Settings\Chwamiki\Local Settings\Temp\congrats.hpi 426 bytes
C:\Documents and Settings\Chwamiki\Local Settings\Temp\congrat.bmp 25.58KB
C:\Documents and Settings\Chwamiki\Local Settings\Temp\ereg.hpi 15.39KB
C:\Documents and Settings\Chwamiki\Local Settings\Temp\license.bmp 25.58KB
C:\Documents and Settings\Chwamiki\Local Settings\Temp\restart.bmp 26.21KB
C:\Documents and Settings\Chwamiki\Local Settings\Temp\inline.bmp 25.58KB
C:\Documents and Settings\Chwamiki\Local Settings\Temp\usb.bmp 26.21KB
C:\Documents and Settings\Chwamiki\Local Settings\Temp\apps.hpi 43.64KB
C:\Documents and Settings\Chwamiki\Local Settings\Temp\master.hpi 46.68KB
C:\Documents and Settings\Chwamiki\Local Settings\Temp\status.bmp 26.21KB
C:\Documents and Settings\Chwamiki\Local Settings\Temp\port.bmp 13.32KB
C:\Documents and Settings\Chwamiki\Local Settings\Temp\intro.bmp 25.58KB
C:\Documents and Settings\Chwamiki\Local Settings\Temp\hpfmicm.exe 36.00KB
C:\Documents and Settings\Chwamiki\Local Settings\Temp\hpfaicm.exe 36.00KB
C:\Documents and Settings\Chwamiki\Local Settings\Temp\install.hpi 2.84KB
C:\Documents and Settings\Chwamiki\Local Settings\Temp\inc.hpi 63.04KB
C:\Documents and Settings\Chwamiki\Local Settings\Temp\license.txt 3.26KB
C:\Documents and Settings\Chwamiki\Local Settings\Temp\hpfinstx.exe 68.00KB
C:\Documents and Settings\Chwamiki\Local Settings\Temp\hpfinst.dll 0.26MB
C:\Documents and Settings\Chwamiki\Local Settings\Temp\hpilog04.txt 34.42KB
C:\Documents and Settings\Chwamiki\Local Settings\Temp\hpistr.hpi 1.87KB
C:\Documents and Settings\Chwamiki\Local Settings\Temp\~DFD73.tmp 32.00KB
C:\Documents and Settings\Chwamiki\Local Settings\Temp\~DFEE88.tmp 32.00KB
C:\Documents and Settings\Chwamiki\Local Settings\Temp\hpzghoul02.log 392 bytes
C:\Documents and Settings\Chwamiki\Local Settings\Temp\hpzscrub00.log 186 bytes
C:\Documents and Settings\Chwamiki\Local Settings\Temp\hpzghoul01.log 756 bytes
C:\Documents and Settings\Chwamiki\Local Settings\Temp\hpzglue00.log 2.64KB
C:\Documents and Settings\Chwamiki\Local Settings\Temp\hpilog03.txt 0.21MB
C:\Documents and Settings\Chwamiki\Local Settings\Temp\~DF5E02.tmp 32.00KB
C:\Documents and Settings\Chwamiki\Local Settings\Temp\~DF4E01.tmp 32.00KB
C:\Documents and Settings\Chwamiki\Local Settings\Temp\~DF7739.tmp 32.00KB
C:\Documents and Settings\Chwamiki\Local Settings\Temp\~DF5A77.tmp 32.00KB
C:\Documents and Settings\Chwamiki\Local Settings\Temp\MSI4a0ff.LOG 89.81KB
C:\Documents and Settings\Chwamiki\Local Settings\Temp\~DF6F8D.tmp 32.00KB
C:\Documents and Settings\Chwamiki\Local Settings\Temp\~DF55A1.tmp 32.00KB
C:\Documents and Settings\Chwamiki\Local Settings\Temp\_ISTMP1.DIR\_ISTMP0.DIR\_isres.dll 0.12MB
C:\Documents and Settings\Chwamiki\Local Settings\Temp\_ISTMP1.DIR\_ISTMP0.DIR\IsUninst.Exe 0.29MB
C:\Documents and Settings\Chwamiki\Local Settings\Temp\_ISTMP1.DIR\_ISTMP0.DIR\Ctl3d32.dll 26.50KB
C:\Documents and Settings\Chwamiki\Local Settings\Temp\_ISTMP1.DIR\_ISTMP0.DIR\Corecomp.ini 27.63KB
C:\Documents and Settings\Chwamiki\Local Settings\Temp\pft15~tmp\_sys1.cab 0.17MB
C:\Documents and Settings\Chwamiki\Local Settings\Temp\pft15~tmp\_ISDel.exe 27.00KB
C:\Documents and Settings\Chwamiki\Local Settings\Temp\MSIdcb45.LOG 294 bytes
C:\Documents and Settings\Chwamiki\Local Settings\Temp\~DF3CE6.tmp 32.00KB
C:\Documents and Settings\Chwamiki\Local Settings\Temp\~DF29A4.tmp 32.00KB
C:\Documents and Settings\Chwamiki\Local Settings\Temp\~DFF5C0.tmp 32.00KB
C:\Documents and Settings\Chwamiki\Local Settings\Temp\maybelline.bmp 7.93KB
C:\Documents and Settings\Chwamiki\Local Settings\Temp\~DFE1DD.tmp 32.00KB
C:\Documents and Settings\Chwamiki\Local Settings\Temp\~DF5F1C.tmp 32.00KB
C:\Documents and Settings\Chwamiki\Local Settings\Temp\~DF4E8E.tmp 32.00KB
C:\Documents and Settings\Chwamiki\Local Settings\Temp\~DF7366.tmp 32.00KB
C:\Documents and Settings\Chwamiki\Local Settings\Temp\~DF526A.tmp 32.00KB
C:\Documents and Settings\Chwamiki\Local Settings\Temp\sweetvalley.bmp 7.93KB
C:\Documents and Settings\Chwamiki\Local Settings\Temp\loreal.bmp 7.93KB
C:\Documents and Settings\Chwamiki\Local Settings\Temp\~DF1F2C.tmp 32.00KB
C:\Documents and Settings\Chwamiki\Local Settings\Temp\~DFF678.tmp 32.00KB
C:\Documents and Settings\Chwamiki\Local Settings\Temp\~DF8322.tmp 32.00KB
C:\Documents and Settings\Chwamiki\Local Settings\Temp\~DF4D90.tmp 32.00KB
C:\Documents and Settings\Chwamiki\Local Settings\Temp\~DF3D3A.tmp 32.00KB
C:\Documents and Settings\Chwamiki\Local Settings\Temp\~DF24A3.tmp 32.00KB
C:\Documents and Settings\Chwamiki\Local Settings\Temp\_isB.tmp 0.22MB
C:\Documents and Settings\Chwamiki\Local Settings\Temp\WERC.tmp.dir00\appcompat.txt 5.02KB
C:\Documents and Settings\Chwamiki\Local Settings\Temp\WERC.tmp 0 bytes
C:\Documents and Settings\Chwamiki\Local Settings\Temp\~DF6FDC.tmp 32.00KB
C:\Documents and Settings\Chwamiki\Local Settings\Temp\~DF5C9E.tmp 32.00KB
C:\Documents and Settings\Chwamiki\Local Settings\Temp\~DF6E96.tmp 32.00KB
C:\Documents and Settings\Chwamiki\Local Settings\Temp\~DF5C88.tmp 32.00KB
C:\Documents and Settings\Chwamiki\Local Settings\Temp\~DFCAFB.tmp 32.00KB
C:\Documents and Settings\Chwamiki\Local Settings\Temp\SNDUpdater544I.log 0.29MB
C:\Documents and Settings\Chwamiki\Local Settings\Temp\SNDSetup544.log 3.52KB
C:\Documents and Settings\Chwamiki\Local Settings\Temp\_is4.tmp 0.22MB
C:\Documents and Settings\Chwamiki\Local Settings\Temp\~DF5921.tmp 32.00KB
C:\Documents and Settings\Chwamiki\Local Settings\Temp\~DF30B7.tmp 32.00KB
C:\Documents and Settings\Chwamiki\Local Settings\Temp\~DF957C.tmp 32.00KB
C:\Documents and Settings\Chwamiki\Local Settings\Temp\~DF7799.tmp 32.00KB
C:\Documents and Settings\Chwamiki\Local Settings\Temp\~DF90E8.tmp 32.00KB
C:\Documents and Settings\Chwamiki\Local Settings\Temp\~DF56F5.tmp 32.00KB
C:\Documents and Settings\Chwamiki\Local Settings\Temp\~DF65E5.tmp 32.00KB
C:\Documents and Settings\Chwamiki\Local Settings\Temp\~DF4212.tmp 32.00KB
C:\Documents and Settings\Chwamiki\Local Settings\Temp\~DF149C.tmp 32.00KB
C:\Documents and Settings\Chwamiki\Local Settings\Temp\~DF1F4.tmp 32.00KB
C:\Documents and Settings\Chwamiki\Local Settings\Temp\~DF8342.tmp 32.00KB
C:\Documents and Settings\Chwamiki\Local Settings\Temp\~DF4A40.tmp 32.00KB
C:\Documents and Settings\Chwamiki\Local Settings\Temp\~DF904D.tmp 32.00KB
C:\Documents and Settings\Chwamiki\Local Settings\Temp\~DF7967.tmp 32.00KB
C:\Documents and Settings\Chwamiki\Local Settings\Temp\crazygood.bmp 20.68KB
C:\Documents and Settings\Chwamiki\Local Settings\Temp\~DFE40F.tmp 32.00KB
C:\Documents and Settings\Chwamiki\Local Settings\Temp\~DFC78F.tmp 32.00KB
C:\Documents and Settings\Chwamiki\Local Settings\Temp\~DF355.tmp 0.17MB
C:\Documents and Settings\Chwamiki\Local Settings\Temp\~DFCDA8.tmp 0.17MB
C:\Documents and Settings\Chwamiki\Local Settings\Temp\~DF340C.tmp 0.19MB
C:\Documents and Settings\Chwamiki\Local Settings\Temp\~DFF7B1.tmp 32.00KB
C:\Documents and Settings\Chwamiki\Local Settings\Temp\Norton Internet Security 2-20-2005 15h3m45s.log 5.91MB
C:\Documents and Settings\Chwamiki\Local Settings\Temp\AVRES_OPTRF_LiveUpdate.dat 172 bytes
C:\Documents and Settings\Chwamiki\Local Settings\Temp\~DF31E7.tmp 32.00KB
C:\Documents and Settings\Chwamiki\Local Settings\Temp\WER84.tmp.dir00\appcompat.txt 31.61KB
C:\Documents and Settings\Chwamiki\Local Settings\Temp\Norton AntiVirus 2005 2-20-2005 14h52m27s.log 2.42MB
C:\Documents and Settings\Chwamiki\Local Settings\Temp\WERF.tmp.dir00\appcompat.txt 17.72KB
C:\Documents and Settings\Chwamiki\Local Settings\Temp\SymSCLiveUpdate.dat 556 bytes
C:\Documents and Settings\Chwamiki\Local Settings\Temp\~DFDADD.tmp 32.00KB
C:\Documents and Settings\Chwamiki\Local Settings\Temp\travelocity.bmp 20.68KB
C:\Documents and Settings\Chwamiki\Local Settings\Temp\WER23F.tmp.dir00\appcompat.txt 17.72KB
C:\Documents and Settings\Chwamiki\Local Settings\Temp\SSALiveUpdate.dat 172 bytes
C:\Documents and Settings\Chwamiki\Local Settings\Temp\~DFCF87.tmp 32.00KB
C:\Documents and Settings\Chwamiki\Local Settings\Temp\WER84.tmp 0 bytes
C:\Documents and Settings\Chwamiki\Local Settings\Temp\Norton AntiVirus 2005 2-18-2005 16h31m54s.log 2.96MB
C:\Documents and Settings\Chwamiki\Local Settings\Temp\doritosdd.bmp 7.93KB
C:\Documents and Settings\Chwamiki\Local Settings\Temp\WERF.tmp 0 bytes
C:\Documents and Settings\Chwamiki\Local Settings\Temp\gatorade.bmp 20.68KB
C:\Documents and Settings\Chwamiki\Local Settings\Temp\WER7.tmp.dir00\appcompat.txt 17.72KB
C:\Documents and Settings\Chwamiki\Local Settings\Temp\WER6.tmp.dir00\appcompat.txt 17.72KB
C:\Documents and Settings\Chwamiki\Local Settings\Temp\WERA.tmp.dir00\appcompat.txt 14.38KB
C:\Documents and Settings\Chwamiki\Local Settings\Temp\symcprop.dat 0.18MB
C:\Documents and Settings\Chwamiki\Local Settings\Temp\AVSTELiveUpdate.dat 172 bytes
C:\Documents and Settings\Chwamiki\Local Settings\Temp\WER23F.tmp 0 bytes
C:\Documents and Settings\Chwamiki\Local Settings\Temp\LSInstall.log 6.23KB
C:\Documents and Settings\Chwamiki\Local Settings\Temp\WER7.tmp 0 bytes
C:\Documents and Settings\Chwamiki\Local Settings\Temp\WER6.tmp 0 bytes
C:\Documents and Settings\Chwamiki\Local Settings\Temp\WERA.tmp 0 bytes
C:\Documents and Settings\Chwamiki\Local Settings\Temp\Norton AntiVirus 2005 2-7-2005 17h38m33s.log 2.96MB
C:\Documents and Settings\Chwamiki\Local Settings\Temp\WER9.tmp.dir00\appcompat.txt 8.03KB
C:\Documents and Settings\Chwamiki\Local Settings\Temp\WER8.tmp.dir00\appcompat.txt 5.00KB
C:\Documents and Settings\Chwamiki\Local Settings\Temp\ReadMe\pt-pt_readme.txt 11.50KB
C:\Documents and Settings\Chwamiki\Local Settings\Temp\ReadMe\nl_readme.txt 11.80KB
C:\Documents and Settings\Chwamiki\Local Settings\Temp\ReadMe\ko_readme.txt 12.33KB
C:\Documents and Settings\Chwamiki\Local Settings\Temp\ReadMe\it_readme.txt 11.72KB
C:\Documents and Settings\Chwamiki\Local Settings\Temp\ReadMe\fr-fr_readme.txt 12.38KB
C:\Documents and Settings\Chwamiki\Local Settings\Temp\ReadMe\es_readme.txt 11.66KB
C:\Documents and Settings\Chwamiki\Local Settings\Temp\ReadMe\en-us_readme.txt 10.66KB
C:\Documents and Settings\Chwamiki\Local Settings\Temp\ReadMe\en-uk_readme.txt 10.66KB
C:\Documents and Settings\Chwamiki\Local Settings\Temp\ReadMe\de_readme.txt 11.88KB
C:\Documents and Settings\Chwamiki\Local Settings\Temp\AutoRun\autorun.cfg 1.04KB
C:\Documents and Settings\Chwamiki\Local Settings\Temp\AutoRun\AutoRun.bmp 73.24KB
C:\Documents and Settings\Chwamiki\Local Settings\Temp\PreScan.log 362 bytes
C:\Documents and Settings\Chwamiki\Local Settings\Temp\data\zdata_18.big 12.00KB
C:\Documents and Settings\Chwamiki\Local Settings\Temp\data\zdata_18.bh 1.50KB
C:\Documents and Settings\Chwamiki\Local Settings\Temp\data\zdata_16.big 4.88MB
C:\Documents and Settings\Chwamiki\Local Settings\Temp\data\zdata_16.bh 3.92KB
C:\Documents and Settings\Chwamiki\Local Settings\Temp\data\zdata_15.big 0.25MB
C:\Documents and Settings\Chwamiki\Local Settings\Temp\data\zdata_15.bh 3.92KB
C:\Documents and Settings\Chwamiki\Local Settings\Temp\data\zdata_14.big 83.99KB
C:\Documents and Settings\Chwamiki\Local Settings\Temp\data\zdata_14.bh 3.92KB
C:\Documents and Settings\Chwamiki\Local Settings\Temp\data\zdata_13.big 59.36KB
C:\Documents and Settings\Chwamiki\Local Settings\Temp\data\zdata_13.bh 3.92KB
C:\Documents and Settings\Chwamiki\Local Settings\Temp\data\zdata_07.big 0.10MB
C:\Documents and Settings\Chwamiki\Local Settings\Temp\data\zdata_07.bh 3.92KB
C:\Documents and Settings\Chwamiki\Local Settings\Temp\data\zdata_06.big 0.11MB
C:\Documents and Settings\Chwamiki\Local Settings\Temp\data\zdata_06.bh 3.92KB
C:\Documents and Settings\Chwamiki\Local Settings\Temp\data\zdata_05.big 71.17KB
C:\Documents and Settings\Chwamiki\Local Settings\Temp\data\zdata_05.bh 3.92KB
C:\Documents and Settings\Chwamiki\Local Settings\Temp\data\zdata_04.big 1.46MB
C:\Documents and Settings\Chwamiki\Local Settings\Temp\data\zdata_04.bh 3.92KB
C:\Documents and Settings\Chwamiki\Local Settings\Temp\data\zdata_03.big 0.27MB
C:\Documents and Settings\Chwamiki\Local Settings\Temp\data\zdata_03.bh 3.92KB
C:\Documents and Settings\Chwamiki\Local Settings\Temp\data\zdata_02.big 1.13MB
C:\Documents and Settings\Chwamiki\Local Settings\Temp\data\zdata_02.bh 3.92KB
C:\Documents and Settings\Chwamiki\Local Settings\Temp\data\zdata_01.big 12.88KB
C:\Documents and Settings\Chwamiki\Local Settings\Temp\data\zdata_01.bh 3.92KB
C:\Documents and Settings\Chwamiki\Local Settings\Temp\data\gui\teammgmt\12a_s11.big 9.00KB
C:\Documents and Settings\Chwamiki\Local Settings\Temp\data\gui\playnow\11_xtras.big 1.51KB
C:\Documents and Settings\Chwamiki\Local Settings\Temp\data\gui\playnow\04_2tm.big 14.70KB
C:\Documents and Settings\Chwamiki\Local Settings\Temp\data\gui\playnow\03_offl.big 14.16KB
C:\Documents and Settings\Chwamiki\Local Settings\Temp\data\gui\playnow\02_teams.big 9.14KB
C:\Documents and Settings\Chwamiki\Local Settings\Temp\data\gui\pause\85_post.big 1.69KB
C:\Documents and Settings\Chwamiki\Local Settings\Temp\data\gui\pause\83_repl.big 62.55KB
C:\Documents and Settings\Chwamiki\Local Settings\Temp\data\gui\pause\82_cam.big 3.73KB
C:\Documents and Settings\Chwamiki\Local Settings\Temp\data\gui\pause\81_mf.big 5.07KB
C:\Documents and Settings\Chwamiki\Local Settings\Temp\data\gui\pause\81b_scor.big 6.25KB
C:\Documents and Settings\Chwamiki\Local Settings\Temp\data\gui\pause\81a_book.big 12.71KB
C:\Documents and Settings\Chwamiki\Local Settings\Temp\data\gui\pause\80_pause.big 4.79KB
C:\Documents and Settings\Chwamiki\Local Settings\Temp\data\gui\pause\05a_opt.big 5.31KB
C:\Documents and Settings\Chwamiki\Local Settings\Temp\data\gui\menu\01_main.big 7.00KB
C:\Documents and Settings\Chwamiki\Local Settings\Temp\data\gui\mainbe.big 30.39KB
C:\Documents and Settings\Chwamiki\Local Settings\Temp\data\gui\main.big 71.91KB
C:\Documents and Settings\Chwamiki\Local Settings\Temp\data\gui\loading\sell.big 0.80MB
C:\Documents and Settings\Chwamiki\Local Settings\Temp\data\gui\loading\onsplash.big 0.80MB
C:\Documents and Settings\Chwamiki\Local Settings\Temp\data\gui\loading\mfsplash.big 0.80MB
C:\Documents and Settings\Chwamiki\Local Settings\Temp\data\gui\loading\load0.big 0.80MB
C:\Documents and Settings\Chwamiki\Local Settings\Temp\data\gui\loading\gmsplash.big 0.80MB
C:\Documents and Settings\Chwamiki\Local Settings\Temp\data\gui\loading\gfsplash.big 0.80MB
C:\Documents and Settings\Chwamiki\Local Settings\Temp\data\gui\loading\dnotice.big 49.47KB
C:\Documents and Settings\Chwamiki\Local Settings\Temp\data\gui\icons\x.big 2.67KB
C:\Documents and Settings\Chwamiki\Local Settings\Temp\data\gui\icons\t.big 2.66KB
C:\Documents and Settings\Chwamiki\Local Settings\Temp\data\gui\icons\r1.big 2.66KB
C:\Documents and Settings\Chwamiki\Local Settings\Temp\data\gui\icons\l1.big 2.65KB
C:\Documents and Settings\Chwamiki\Local Settings\Temp\data\gui\gameLib\toggle.big 5.57KB
C:\Documents and Settings\Chwamiki\Local Settings\Temp\data\gui\gameLib\teamsel.big 7.78KB
C:\Documents and Settings\Chwamiki\Local Settings\Temp\data\gui\gameLib\stars.big 5.21KB
C:\Documents and Settings\Chwamiki\Local Settings\Temp\data\gui\gameLib\scrlbar.big 4.30KB
C:\Documents and Settings\Chwamiki\Local Settings\Temp\data\gui\gameLib\plyrpanl.big 4.30KB
C:\Documents and Settings\Chwamiki\Local Settings\Temp\data\gui\gameLib\pitch.big 62.18KB
C:\Documents and Settings\Chwamiki\Local Settings\Temp\data\gui\gameLib\overlay.big 4.72KB
C:\Documents and Settings\Chwamiki\Local Settings\Temp\data\gui\gameLib\optBar.big 1.74KB
C:\Documents and Settings\Chwamiki\Local Settings\Temp\data\gui\gameLib\MsgBox.big 8.08KB
C:\Documents and Settings\Chwamiki\Local Settings\Temp\data\gui\gameLib\menubox.big 8.65KB
C:\Documents and Settings\Chwamiki\Local Settings\Temp\data\gui\gameLib\imgscrol.big 8.71KB
C:\Documents and Settings\Chwamiki\Local Settings\Temp\data\gui\gameLib\fifaHelp.big 14.90KB
C:\Documents and Settings\Chwamiki\Local Settings\Temp\data\gui\gameLib\fifaElem.big 8.46KB
C:\Documents and Settings\Chwamiki\Local Settings\Temp\data\gui\gameLib\ea_trax.big 17.59KB
C:\Documents and Settings\Chwamiki\Local Settings\Temp\data\gui\gameLib\comboItm.big 7.24KB
C:\Documents and Settings\Chwamiki\Local Settings\Temp\data\gui\gameLib\clipctrl.big 1.24KB
C:\Documents and Settings\Chwamiki\Local Settings\Temp\data\gui\gameLib\be_pitch.big 57.94KB
C:\Documents and Settings\Chwamiki\Local Settings\Temp\data\gui\gameLib\bargraph.big 4.71KB
C:\Documents and Settings\Chwamiki\Local Settings\Temp\data\gui\gameLib\ascroll.big 3.14KB
C:\Documents and Settings\Chwamiki\Local Settings\Temp\data\gui\elements\weather.big 25.70KB
C:\Documents and Settings\Chwamiki\Local Settings\Temp\data\gui\elements\r_arrow2.big 3.87KB
C:\Documents and Settings\Chwamiki\Local Settings\Temp\data\gui\elements\r_arrow.big 3.85KB
C:\Documents and Settings\Chwamiki\Local Settings\Temp\data\gui\elements\p_anim.big 431 bytes
C:\Documents and Settings\Chwamiki\Local Settings\Temp\data\gui\elements\pad.big 30.96KB
C:\Documents and Settings\Chwamiki\Local Settings\Temp\data\gui\elements\l_arrow2.big 3.88KB
C:\Documents and Settings\Chwamiki\Local Settings\Temp\data\gui\elements\l_arrow.big 3.85KB
C:\Documents and Settings\Chwamiki\Local Settings\Temp\data\gui\elements\length.big 12.80KB
C:\Documents and Settings\Chwamiki\Local Settings\Temp\data\gui\elements\keyboard.big 28.73KB
C:\Documents and Settings\Chwamiki\Local Settings\Temp\data\gui\elements\injury.big 5.59KB
C:\Documents and Settings\Chwamiki\Local Settings\Temp\data\gui\elements\halfplyr.big 5.43KB
C:\Documents and Settings\Chwamiki\Local Settings\Temp\data\gui\elements\fullplyr.big 6.20KB
C:\Documents and Settings\Chwamiki\Local Settings\Temp\data\gui\elements\diffic.big 9.15KB
C:\Documents and Settings\Chwamiki\Local Settings\Temp\data\gui\elements\cards.big 5.87KB
C:\Documents and Settings\Chwamiki\Local Settings\Temp\data\gui\elements\a_3.big 0.43MB
C:\Documents and Settings\Chwamiki\Local Settings\Temp\data\gui\elements\a_2.big 0.12MB
C:\Documents and Settings\Chwamiki\Local Settings\Temp\data\gui\ea05_tit.ttf 44.21KB
C:\Documents and Settings\Chwamiki\Local Settings\Temp\data\gui\ea05_bod.ttf 40.57KB
C:\Documents and Settings\Chwamiki\Local Settings\Temp\data\gui\cafeLib\stdVirKB.big 43.31KB
C:\Documents and Settings\Chwamiki\Local Settings\Temp\data\gui\cafeLib\stdCntrl.big 23.01KB
C:\Documents and Settings\Chwamiki\Local Settings\Temp\data\gui\cafeLib\stdBhvr.big 6.13KB
C:\Documents and Settings\Chwamiki\Local Settings\Temp\data\gui\cafeLib\stdArt.big 9.06KB
C:\Documents and Settings\Chwamiki\Local Settings\Temp\data\gui\cafeLib\icons\x_ps2.big 3.35KB
C:\Documents and Settings\Chwamiki\Local Settings\Temp\data\gui\cafeLib\icons\t_ps2.big 3.35KB
C:\Documents and Settings\Chwamiki\Local Settings\Temp\data\gui\cafeLib\icons\s_ps2.big 3.30KB
C:\Documents and Settings\Chwamiki\Local Settings\Temp\data\gui\cafeLib\icons\str_ps2.big 3.12KB
C:\Documents and Settings\Chwamiki\Local Settings\Temp\data\gui\cafeLib\icons\r2_ps2.big 3.62KB
C:\Documents and Settings\Chwamiki\Local Settings\Temp\data\gui\cafeLib\icons\l2_ps2.big 3.56KB
C:\Documents and Settings\Chwamiki\Local Settings\Temp\data\gui\cafeLib\icons\c_ps2.big 3.27KB
C:\Documents and Settings\Chwamiki\Local Settings\Temp\data\gui\but_x.big 2.39KB
C:\Documents and Settings\Chwamiki\Local Settings\Temp\data\gui\boot\mc_boot.big 2.06KB
C:\Documents and Settings\Chwamiki\Local Settings\Temp\data\gui\boot\flags.big 61.71KB
C:\Documents and Settings\Chwamiki\Local Settings\Temp\data\gui\boot\fe_init.big 943 bytes
C:\Documents and Settings\Chwamiki\Local Settings\Temp\data\gui\boot\53_title.big 0.12MB
C:\Documents and Settings\Chwamiki\Local Settings\Temp\data\gui\boot\47_legal.big 0.21MB
C:\Documents and Settings\Chwamiki\Local Settings\Temp\data\gui\boot\35_lang.big 3.16KB
C:\Documents and Settings\Chwamiki\Local Settings\Temp\data\gui\assets\logos\t47.big 14.58KB
C:\Documents and Settings\Chwamiki\Local Settings\Temp\data\gui\assets\logos\t1.big 21.61KB
C:\Documents and Settings\Chwamiki\Local Settings\Temp\data\gui\assets\logos\l31.big 9.27KB
C:\Documents and Settings\Chwamiki\Local Settings\Temp\data\gui\assets\logos\l13.big 12.65KB
C:\Documents and Settings\Chwamiki\Local Settings\Temp\data\gui\assets\kits\j1_00047.big 24.72KB
C:\Documents and Settings\Chwamiki\Local Settings\Temp\data\gui\assets\kits\j1_00001.big 27.52KB
C:\Documents and Settings\Chwamiki\Local Settings\Temp\data\gui\assets\kits\j0_00047.big 27.43KB
C:\Documents and Settings\Chwamiki\Local Settings\Temp\data\gui\assets\kits\j0_00001.big 30.87KB
C:\Documents and Settings\Chwamiki\Local Settings\Temp\data\gui\assets\heads\s_805.big 12.11KB
C:\Documents and Settings\Chwamiki\Local Settings\Temp\data\gui\assets\heads\s_7763.big 12.85KB
C:\Documents and Settings\Chwamiki\Local Settings\Temp\data\gui\assets\heads\s_7554.big 11.20KB
C:\Documents and Settings\Chwamiki\Local Settings\Temp\data\gui\assets\heads\s_7512.big 12.71KB
C:\Documents and Settings\Chwamiki\Local Settings\Temp\data\gui\assets\heads\s_6975.big 11.64KB
C:\Documents and Settings\Chwamiki\Local Settings\Temp\data\gui\assets\heads\s_5740.big 12.23KB
C:\Documents and Settings\Chwamiki\Local Settings\Temp\data\gui\assets\heads\s_5003.big 12.03KB
C:\Documents and Settings\Chwamiki\Local Settings\Temp\data\gui\assets\heads\s_47390.big 11.17KB
C:\Documents and Settings\Chwamiki\Local Settings\Temp\data\gui\assets\heads\s_44900.big 12.25KB
C:\Documents and Settings\Chwamiki\Local Settings\Temp\data\gui\assets\heads\s_4202.big 12.48KB
C:\Documents and Settings\Chwamiki\Local Settings\Temp\data\gui\assets\heads\s_4000.big 12.36KB
C:\Documents and Settings\Chwamiki\Local Settings\Temp\data\gui\assets\heads\s_388.big 11.31KB
C:\Documents and Settings\Chwamiki\Local Settings\Temp\data\gui\assets\heads\s_3712.big 11.39KB
C:\Documents and Settings\Chwamiki\Local Settings\Temp\data\gui\assets\heads\s_34079.big 11.54KB
C:\Documents and Settings\Chwamiki\Local Settings\Temp\data\gui\assets\heads\s_1625.big 11.10KB
C:\Documents and Settings\Chwamiki\Local Settings\Temp\data\gui\assets\heads\s_1605.big 12.29KB
C:\Documents and Settings\Chwamiki\Local Settings\Temp\data\gui\assets\heads\s_1419.big 11.35KB
C:\Documents and Settings\Chwamiki\Local Settings\Temp\data\gui\assets\heads\s_13128.big 12.50KB
C:\Documents and Settings\Chwamiki\Local Settings\Temp\data\gui\assets\heads\s_1256.big 11.66KB
C:\Documents and Settings\Chwamiki\Local Settings\Temp\data\gui\assets\heads\s_123463.big 12.33KB
C:\Documents and Settings\Chwamiki\Local Settings\Temp\data\gui\assets\heads\s_111093.big 12.70KB
C:\Documents and Settings\Chwamiki\Local Settings\Temp\data\gui\assets\heads\s_1109.big 11.38KB
C:\Documents and Settings\Chwamiki\Local Settings\Temp\data\gui\assets\heads\s_1088.big 12.62KB
C:\Documents and Settings\Chwamiki\Local Settings\Temp\data\gui\assets\heads\s_1025.big 12.03KB
C:\Documents and Settings\Chwamiki\Local Settings\Temp\data\gui\assets\heads\g_211211.big 11.88KB
C:\Documents and Settings\Chwamiki\Local Settings\Temp\data\gui\assets\heads\g_160631.big 11.39KB
C:\Documents and Settings\Chwamiki\Local Settings\Temp\data\gui\assets\heads\g_061742.big 12.34KB
C:\Documents and Settings\Chwamiki\Local Settings\Temp\data\gui\assets\heads\g_031814.big 13.03KB
C:\Documents and Settings\Chwamiki\Local Settings\Temp\data\gui\assets\heads\g_031813.big 12.98KB
C:\Documents and Settings\Chwamiki\Local Settings\Temp\data\gui\assets\heads\g_031711.big 12.02KB
C:\Documents and Settings\Chwamiki\Local Settings\Temp\data\gui\assets\heads\g_021112.big 11.77KB
C:\Documents and Settings\Chwamiki\Local Settings\Temp\data\gui\assets\heads\g_011752.big 12.35KB
C:\Documents and Settings\Chwamiki\Local Settings\Temp\data\gui\assets\back\l_6.big 1.06MB
C:\Documents and Settings\Chwamiki\Local Settings\Temp\data\gui\assets\back\bg00.big 1.92KB
C:\Documents and Settings\Chwamiki\Local Settings\Temp\data\gui\assets\back\bg0.big 1.20MB
C:\Documents and Settings\Chwamiki\Local Settings\Temp\data\gui\assets\back\b1.big 1.20MB
C:\Documents and Settings\Chwamiki\Local Settings\Temp\data\gui\arial_kr.pfr 0.23MB
C:\Documents and Settings\Chwamiki\Local Settings\Temp\data\fifa.fat 0.17MB
C:\Documents and Settings\Chwamiki\Local Settings\Temp\data\eaglrm.big 0.17MB
C:\Documents and Settings\Chwamiki\Local Settings\Temp\data\cmn\meta.db 11.29KB
C:\Documents and Settings\Chwamiki\Local Settings\Temp\data\cmn\ini_pc.big 4.70KB
C:\Documents and Settings\Chwamiki\Local Settings\Temp\data\cmn\ini.big 27.57KB
C:\Documents and Settings\Chwamiki\Local Settings\Temp\data\cmn\fifa.db 93.90KB
C:\Documents and Settings\Chwamiki\Local Settings\Temp\data\cmn\fe\spa.db 0.15MB
C:\Documents and Settings\Chwamiki\Local Settings\Temp\data\cmn\fe\por.db 0.15MB
C:\Documents and Settings\Chwamiki\Local Settings\Temp\data\cmn\fe\kor.db 0.15MB
C:\Documents and Settings\Chwamiki\Local Settings\Temp\data\cmn\fe\ita.db 0.15MB
C:\Documents and Settings\Chwamiki\Local Settings\Temp\data\cmn\fe\ger.db 0.15MB
C:\Documents and Settings\Chwamiki\Local Settings\Temp\data\cmn\fe\fre.db 0.15MB
C:\Documents and Settings\Chwamiki\Local Settings\Temp\data\cmn\fe\eng.db 0.14MB
C:\Documents and Settings\Chwamiki\Local Settings\Temp\data\cmn\fe\dut.db 0.14MB
C:\Documents and Settings\Chwamiki\Local Settings\Temp\data\cmn\cfg_pc_m.ini 2.38KB
C:\Documents and Settings\Chwamiki\Local Settings\Temp\data\cmn\cfg_pc_h.ini 2.13KB
C:\Documents and Settings\Chwamiki\Local Settings\Temp\data\cmn\be\tidbghom.bin 88 bytes
C:\Documents and Settings\Chwamiki\Local Settings\Temp\data\cmn\be\tidbgawy.bin 104 bytes
C:\Documents and Settings\Chwamiki\Local Settings\Temp\data\cmn\be\sim.bin 2.87KB
C:\Documents and Settings\Chwamiki\Local Settings\Temp\data\cmn\be\sicndata.bin 4.38KB
C:\Documents and Settings\Chwamiki\Local Settings\Temp\data\cmn\be\script.bin 8.74KB
C:\Documents and Settings\Chwamiki\Local Settings\Temp\data\cmn\be\replayz.bin 24.32KB
C:\Documents and Settings\Chwamiki\Local Settings\Temp\data\cmn\be\replayd.bin 26.50KB
C:\Documents and Settings\Chwamiki\Local Settings\Temp\data\cmn\be\motion.big 10.8MB
C:\Documents and Settings\Chwamiki\Local Settings\Temp\data\cmn\be\micndata.bin 30.61KB
C:\Documents and Settings\Chwamiki\Local Settings\Temp\data\cmn\be\iconrela.bin 392 bytes
C:\Documents and Settings\Chwamiki\Local Settings\Temp\data\cmn\be\iconperm.bin 316 bytes
C:\Documents and Settings\Chwamiki\Local Settings\Temp\data\cmn\be\flag.ebo 11.89KB
C:\Documents and Settings\Chwamiki\Local Settings\Temp\data\cl.bin 16 bytes
C:\Documents and Settings\Chwamiki\Local Settings\Temp\data\bescene.cs 0.88MB
C:\Documents and Settings\Chwamiki\Local Settings\Temp\data\audio\music\songlist.bin 148 bytes
C:\Documents and Settings\Chwamiki\Local Settings\Temp\data\audio\music\PaulOak.asf 1.11MB
C:\Documents and Settings\Chwamiki\Local Settings\Temp\data\audio\mix_mot.ini 2.93KB
C:\Documents and Settings\Chwamiki\Local Settings\Temp\data\audio\chants.bin 2.15KB
C:\Documents and Settings\Chwamiki\Local Settings\Temp\data\audio\chants.big 18.7MB
C:\Documents and Settings\Chwamiki\Local Settings\Temp\data\audio\aemsstrm.big 34.6MB
C:\Documents and Settings\Chwamiki\Local Settings\Temp\data\audio\aemsbank.big 4.27MB
C:\Documents and Settings\Chwamiki\Local Settings\Temp\alocale\eal_span.mad 1.72MB
C:\Documents and Settings\Chwamiki\Local Settings\Temp\alocale\eal_porn.mad 1.72MB
C:\Documents and Settings\Chwamiki\Local Settings\Temp\alocale\eal_korn.mad 1.83MB
C:\Documents and Settings\Chwamiki\Local Settings\Temp\alocale\eal_itan.mad 1.72MB
C:\Documents and Settings\Chwamiki\Local Settings\Temp\alocale\eal_gern.mad 1.72MB
C:\Documents and Settings\Chwamiki\Local Settings\Temp\alocale\eal_fren.mad 1.69MB
C:\Documents and Settings\Chwamiki\Local Settings\Temp\alocale\eal_engn.mad 1.72MB
C:\Documents and Settings\Chwamiki\Local Settings\Temp\alocale\eal_dutn.mad 1.71MB
C:\Documents and Settings\Chwamiki\Local Settings\Temp\setup.exe 0.11MB
C:\Documents and Settings\Chwamiki\Local Settings\Temp\fifapc.ico 23.01KB
C:\Documents and Settings\Chwamiki\Local Settings\Temp\fifa2005_demo.exe 3.71MB
C:\Documents and Settings\Chwamiki\Local Settings\Temp\config.dat 20.26KB
C:\Documents and Settings\Chwamiki\Local Settings\Temp\common_filelist.txt 6.10KB
C:\Documents and Settings\Chwamiki\Local Settings\Temp\Support\lisezmoi.txt 12.38KB
C:\Documents and Settings\Chwamiki\Local Settings\Temp\Support\leeme.txt 11.66KB
C:\Documents and Settings\Chwamiki\Local Settings\Temp\swtmp.htm 117 bytes
C:\Documents and Settings\Chwamiki\Local Settings\Temp\autorun.inf 95 bytes
C:\Documents and Settings\Chwamiki\Local Settings\Temp\hpzcoi17.log 665 bytes
C:\Documents and Settings\Chwamiki\Local Settings\Temp\hpzcoi16.log 596 bytes
C:\Documents and Settings\Chwamiki\Local Settings\Temp\hpzcoi15.log 665 bytes
C:\Documents and Settings\Chwamiki\Local Settings\Temp\hpzcoi14.log 596 bytes
C:\Documents and Settings\Chwamiki\Local Settings\Temp\hpzcoi13.log 665 bytes
C:\Documents and Settings\Chwamiki\Local Settings\Temp\hpzcoi12.log 596 bytes
C:\Documents and Settings\Chwamiki\Local Settings\Temp\hpzcoi11.log 665 bytes
C:\Documents and Settings\Chwamiki\Local Settings\Temp\hpzcoi10.log 596 bytes
C:\Documents and Settings\Chwamiki\Local Settings\Temp\hpzcoi09.log 665 bytes
C:\Documents and Settings\Chwamiki\Local Settings\Temp\hpzcoi08.log 596 bytes
C:\Documents and Settings\Chwamiki\Local Settings\Temp\wahtmltmp00.htm 304 bytes
C:\Documents and Settings\Chwamiki\Local Settings\Temp\hpzcoi07.log 665 bytes
C:\Documents and Settings\Chwamiki\Local Settings\Temp\History\History.IE5\desktop.ini 113 bytes
C:\Documents and Settings\Chwamiki\Local Settings\Temp\History\History.IE5\index.dat 32.00KB
C:\Documents and Settings\Chwamiki\Local Settings\Temp\Temporary Internet Files\Content.IE5\IQJYSE1W\desktop.ini 67 bytes
C:\Documents and Settings\Chwamiki\Local Settings\Temp\Temporary Internet Files\Content.IE5\KBKV0X4F\desktop.ini 67 bytes
C:\Documents and Settings\Chwamiki\Local Settings\Temp\Temporary Internet Files\Content.IE5\414RWDWT\desktop.ini 67 bytes
C:\Documents and Settings\Chwamiki\Local Settings\Temp\Temporary Internet Files\Content.IE5\WJYLIN2P\desktop.ini 67 bytes
C:\Documents and Settings\Chwamiki\Local Settings\Temp\Temporary Internet Files\Content.IE5\desktop.ini 67 bytes
C:\Documents and Settings\Chwamiki\Local Settings\Temp\Temporary Internet Files\Content.IE5\index.dat 32.00KB
C:\Documents and Settings\Chwamiki\Local Settings\Temp\GLFF.tmp 9.50KB
C:\Documents and Settings\Chwamiki\Local Settings\Temp\cabex.dll 80.00KB
C:\Documents and Settings\Chwamiki\Local Settings\Temp\hpzcoi06.log 596 bytes
C:\Documents and Settings\Chwamiki\Local Settings\Temp\personals2.bmp 7.93KB
C:\Documents and Settings\Chwamiki\Local Settings\Temp\shoppingxl.bmp 7.93KB
C:\Documents and Settings\Chwamiki\Local Settings\Temp\Norton AntiVirus 2005 2-10-2005 17h36m22s.log 2.42MB
C:\Documents and Settings\Chwamiki\Local Settings\Temp\hpzcoi05.log 665 bytes
C:\Documents and Settings\Chwamiki\Local Settings\Temp\SNDUpdater54U.log 0.26MB
C:\Documents and Settings\Chwamiki\Local Settings\Temp\WER9.tmp 0 bytes
C:\Documents and Settings\Chwamiki\Local Settings\Temp\WER8.tmp 0 bytes
C:\Documents and Settings\Chwamiki\Local Settings\Temp\~DFA580.tmp 32.00KB
C:\Documents and Settings\Chwamiki\Local Settings\Temp\~DFBEAC.tmp 32.00KB
C:\Documents and Settings\Chwamiki\Local Settings\Temp\hpilog02.txt 46.40KB
C:\Documents and Settings\Chwamiki\Local Settings\Temp\hpilog01.txt 1.36KB
C:\Documents and Settings\Chwamiki\Local Settings\Temp\hpzcoi04.log 596 bytes
C:\Documents and Settings\Chwamiki\Local Settings\Temp\_is7\Wings of War DEMO.msi 3.19MB
C:\Documents and Settings\Chwamiki\Local Settings\Temp\_is7\0x0409.ini 4.01KB
C:\Documents and Settings\Chwamiki\Local Settings\Temp\_is7\_ISMSIDEL.INI 133 bytes
C:\Documents and Settings\Chwamiki\Local Settings\Temp\_is7\Setup.INI 1.17KB
C:\Documents and Settings\Chwamiki\Local Settings\Temp\hpilog00.txt 80.14KB
C:\Documents and Settings\Chwamiki\Local Settings\Temp\Cookies\index.dat 32.00KB
C:\Documents and Settings\Chwamiki\Local Settings\Temp\_is3\Wings of War DEMO.msi 140.2MB
C:\Documents and Settings\Chwamiki\Local Settings\Temp\_is3\0x0409.ini 4.01KB
C:\Documents and Settings\Chwamiki\Local Settings\Temp\_is3\_ISMSIDEL.INI 133 bytes
C:\Documents and Settings\Chwamiki\Local Settings\Temp\_is3\Setup.INI 1.17KB
C:\Documents and Settings\Chwamiki\Local Settings\Temp\eauninstall.exe 0.31MB
C:\Documents and Settings\Chwamiki\Local Settings\Temp\~e5d141.tmp 45.00KB
C:\Documents and Settings\Chwamiki\Local Settings\Temp\filelist.txt 56 bytes
C:\Documents and Settings\Chwamiki\Local Settings\Temp\finishline.bmp 7.93KB
C:\Documents and Settings\Chwamiki\Local Settings\Temp\lunchables.bmp 7.93KB
C:\Documents and Settings\Chwamiki\Local Settings\Temp\srvinst.cab 0.33MB
C:\Documents and Settings\Chwamiki\Local Settings\Temp\AutoRunGUI.dll 0.55MB
C:\Documents and Settings\Chwamiki\Local Settings\Temp\AutoRun.exe 0.63MB
C:\Documents and Settings\Chwamiki\Local Settings\Temp\pepsiaa.bmp 7.93KB
C:\Documents and Settings\Chwamiki\Local Settings\Temp\ns_temp\xpcom.ns\bin\nspr4.dll 0.15MB
C:\Documents and Settings\Chwamiki\Local Settings\Temp\ns_temp\xpcom.ns\bin\plds4.dll 24.10KB
C:\Documents and Settings\Chwamiki\Local Settings\Temp\ns_temp\xpcom.ns\bin\plc4.dll 28.10KB
C:\Documents and Settings\Chwamiki\Local Settings\Temp\ns_temp\xpcom.ns\bin\js3250.dll 0.31MB
C:\Documents and Settings\Chwamiki\Local Settings\Temp\ns_temp\xpcom.ns\bin\xpcom_compat.dll 66.60KB
C:\Documents and Settings\Chwamiki\Local Settings\Temp\ns_temp\xpcom.ns\bin\components\xpinstal.dll 0.15MB
C:\Documents and Settings\Chwamiki\Local Settings\Temp\ns_temp\xpcom.ns\bin\components\jar50.dll 40.60KB
C:\Documents and Settings\Chwamiki\Local Settings\Temp\ns_temp\xpcom.ns\bin\xpcom.dll 0.36MB
C:\Documents and Settings\Chwamiki\Local Settings\Temp\wotw.bmp 20.68KB
C:\Documents and Settings\Chwamiki\Local Settings\Temp\hp3dvd.bmp 7.93KB
C:\Documents and Settings\Chwamiki\Local Settings\Temp\HP Configure - 2_8_2005 18_12_14.txt 458 bytes
C:\Documents and Settings\Chwamiki\Local Settings\Temp\hpzghoul00.log 372 bytes
C:\Documents and Settings\Chwamiki\Local Settings\Temp\offcln9.log 30.87KB
C:\Documents and Settings\Chwamiki\Local Settings\Temp\~DFBAB8.tmp 32.00KB
C:\Documents and Settings\Chwamiki\Local Settings\Temp\~E3.tmp 0 bytes
C:\Documents and Settings\Chwamiki\Local Settings\Temp\hpzpin00.log 487 bytes
C:\Documents and Settings\Chwamiki\Local Settings\Temp\hpzcoi03.log 2.28KB
C:\Documents and Settings\Chwamiki\Local Settings\Temp\hpzcoi02.log 596 bytes
C:\Documents and Settings\Chwamiki\Local Settings\Temp\hpzcoi01.log 596 bytes
C:\Documents and Settings\Chwamiki\Local Settings\Temp\Setup Log File.Log 336 bytes
C:\Documents and Settings\Chwamiki\Local Settings\Temp\Microsoft Office 2003 Setup(0002)_Task(0001).txt 6.70MB
C:\Documents and Settings\Chwamiki\Local Settings\Temp\Office 2000 Premium Setup(0002)_MsiExec.txt 0.26MB
C:\Documents and Settings\Chwamiki\Local Settings\Temp\Office 2000 Premium Setup(0002).txt 1.64KB
C:\Documents and Settings\Chwamiki\Local Settings\Temp\DW234.tmp 1.40KB
C:\Documents and Settings\Chwamiki\Local Settings\Temp\Microsoft Office 2003 Setup(0002).txt 9.74KB
C:\Documents and Settings\Chwamiki\Local Settings\Temp\offcln11.log 67.86KB
C:\Documents and Settings\Chwamiki\Local Settings\Temp\dw.log 77 bytes
C:\Documents and Settings\Chwamiki\Local Settings\Temp\Microsoft Office 2003 Setup(0001)_Task(0001).txt 0.61MB
C:\Documents and Settings\Chwamiki\Local Settings\Temp\Microsoft Office 2003 Setup(0001).txt 9.70KB
C:\Documents and Settings\Chwamiki\Local Settings\Temp\SNDunin.log 1.36KB
C:\Documents and Settings\Chwamiki\Local Settings\Temp\hpzcoi00.log 596 bytes
C:\Documents and Settings\Chwamiki\Local Settings\Temp\FCCADD4F.TMP 21 bytes
C:\Documents and Settings\Chwamiki\Local Settings\Temp\IDSinst.LOG 8.93KB
C:\DOCUME~1\Chwamiki\LOCALS~1\Temp\control.xml 12.86KB
C:\DOCUME~1\Chwamiki\LOCALS~1\Temp\~DF3951.tmp 32.00KB
C:\DOCUME~1\Chwamiki\LOCALS~1\Temp\~DF1CD7.tmp 32.00KB
C:\DOCUME~1\Chwamiki\LOCALS~1\Temp\~DFBB8B.tmp 32.00KB
C:\DOCUME~1\Chwamiki\LOCALS~1\Temp\~DF3B87.tmp 32.00KB
C:\DOCUME~1\Chwamiki\LOCALS~1\Temp\~DF60C9.tmp 32.00KB
C:\DOCUME~1\Chwamiki\LOCALS~1\Temp\~DF5052.tmp 32.00KB
C:\DOCUME~1\Chwamiki\LOCALS~1\Temp\~DFD948.tmp 32.00KB
C:\DOCUME~1\Chwamiki\LOCALS~1\Temp\~DFDDBF.tmp 32.00KB
C:\DOCUME~1\Chwamiki\LOCALS~1\Temp\~DFC97C.tmp 32.00KB
C:\DOCUME~1\Chwamiki\LOCALS~1\Temp\~DF6A80.tmp 32.00KB
C:\DOCUME~1\Chwamiki\LOCALS~1\Temp\~DF5A3E.tmp 32.00KB
C:\DOCUME~1\Chwamiki\LOCALS~1\Temp\robots.bmp 7.93KB
C:\DOCUME~1\Chwamiki\LOCALS~1\Temp\contender.bmp 7.93KB
C:\DOCUME~1\Chwamiki\LOCALS~1\Temp\~DFC9.tmp 32.00KB
C:\DOCUME~1\Chwamiki\LOCALS~1\Temp\~DFE9A5.tmp 32.00KB
C:\DOCUME~1\Chwamiki\LOCALS~1\Temp\hpilog06.txt 4.56KB
C:\DOCUME~1\Chwamiki\LOCALS~1\Temp\hpilog05.txt 80.30KB
C:\DOCUME~1\Chwamiki\LOCALS~1\Temp\hpfiui.exe 0.31MB
C:\DOCUME~1\Chwamiki\LOCALS~1\Temp\setup.hpi 63.15KB
C:\DOCUME~1\Chwamiki\LOCALS~1\Temp\hpfback.exe 0.13MB
C:\DOCUME~1\Chwamiki\LOCALS~1\Temp\apps2.hpi 11.36KB
C:\DOCUME~1\Chwamiki\LOCALS~1\Temp\wowdemo.bmp 26.21KB
C:\DOCUME~1\Chwamiki\LOCALS~1\Temp\congrats.hpi 426 bytes
C:\DOCUME~1\Chwamiki\LOCALS~1\Temp\congrat.bmp 25.58KB
C:\DOCUME~1\Chwamiki\LOCALS~1\Temp\ereg.hpi 15.39KB
C:\DOCUME~1\Chwamiki\LOCALS~1\Temp\license.bmp 25.58KB
C:\DOCUME~1\Chwamiki\LOCALS~1\Temp\restart.bmp 26.21KB
C:\DOCUME~1\Chwamiki\LOCALS~1\Temp\inline.bmp 25.58KB
C:\DOCUME~1\Chwamiki\LOCALS~1\Temp\usb.bmp 26.21KB
C:\DOCUME~1\Chwamiki\LOCALS~1\Temp\apps.hpi 43.64KB
C:\DOCUME~1\Chwamiki\LOCALS~1\Temp\master.hpi 46.68KB
C:\DOCUME~1\Chwamiki\LOCALS~1\Temp\status.bmp 26.21KB
C:\DOCUME~1\Chwamiki\LOCALS~1\Temp\port.bmp 13.32KB
C:\DOCUME~1\Chwamiki\LOCALS~1\Temp\intro.bmp 25.58KB
C:\DOCUME~1\Chwamiki\LOCALS~1\Temp\hpfmicm.exe 36.00KB
C:\DOCUME~1\Chwamiki\LOCALS~1\Temp\hpfaicm.exe 36.00KB
C:\DOCUME~1\Chwamiki\LOCALS~1\Temp\install.hpi 2.84KB
C:\DOCUME~1\Chwamiki\LOCALS~1\Temp\inc.hpi 63.04KB
C:\DOCUME~1\Chwamiki\LOCALS~1\Temp\license.txt 3.26KB
C:\DOCUME~1\Chwamiki\LOCALS~1\Temp\hpfinstx.exe 68.00KB
C:\DOCUME~1\Chwamiki\LOCALS~1\Temp\hpfinst.dll 0.26MB
C:\DOCUME~1\Chwamiki\LOCALS~1\Temp\hpilog04.txt 34.42KB
C:\DOCUME~1\Chwamiki\LOCALS~1\Temp\hpistr.hpi 1.87KB
C:\DOCUME~1\Chwamiki\LOCALS~1\Temp\~DFD73.tmp 32.00KB
C:\DOCUME~1\Chwamiki\LOCALS~1\Temp\~DFEE88.tmp 32.00KB
C:\DOCUME~1\Chwamiki\LOCALS~1\Temp\hpzghoul02.log 392 bytes
C:\DOCUME~1\Chwamiki\LOCALS~1\Temp\hpzscrub00.log 186 bytes
C:\DOCUME~1\Chwamiki\LOCALS~1\Temp\hpzghoul01.log 756 bytes
C:\DOCUME~1\Chwamiki\LOCALS~1\Temp\hpzglue00.log 2.64KB
C:\DOCUME~1\Chwamiki\LOCALS~1\Temp\hpilog03.txt 0.21MB
C:\DOCUME~1\Chwamiki\LOCALS~1\Temp\~DF5E02.tmp 32.00KB
C:\DOCUME~1\Chwamiki\LOCALS~1\Temp\~DF4E01.tmp 32.00KB
C:\DOCUME~1\Chwamiki\LOCALS~1\Temp\~DF7739.tmp 32.00KB
C:\DOCUME~1\Chwamiki\LOCALS~1\Temp\~DF5A77.tmp 32.00KB
C:\DOCUME~1\Chwamiki\LOCALS~1\Temp\MSI4a0ff.LOG 89.81KB
C:\DOCUME~1\Chwamiki\LOCALS~1\Temp\~DF6F8D.tmp 32.00KB
C:\DOCUME~1\Chwamiki\LOCALS~1\Temp\~DF55A1.tmp 32.00KB
C:\DOCUME~1\Chwamiki\LOCALS~1\Temp\_ISTMP1.DIR\_ISTMP0.DIR\_isres.dll 0.12MB
C:\DOCUME~1\Chwamiki\LOCALS~1\Temp\_ISTMP1.DIR\_ISTMP0.DIR\IsUninst.Exe 0.29MB
C:\DOCUME~1\Chwamiki\LOCALS~1\Temp\_ISTMP1.DIR\_ISTMP0.DIR\Ctl3d32.dll 26.50KB
C:\DOCUME~1\Chwamiki\LOCALS~1\Temp\_ISTMP1.DIR\_ISTMP0.DIR\Corecomp.ini 27.63KB
C:\DOCUME~1\Chwamiki\LOCALS~1\Temp\pft15~tmp\_sys1.cab 0.17MB
C:\DOCUME~1\Chwamiki\LOCALS~1\Temp\pft15~tmp\_ISDel.exe 27.00KB
C:\DOCUME~1\Chwamiki\LOCALS~1\Temp\MSIdcb45.LOG 294 bytes
C:\DOCUME~1\Chwamiki\LOCALS~1\Temp\~DF3CE6.tmp 32.00KB
C:\DOCUME~1\Chwamiki\LOCALS~1\Temp\~DF29A4.tmp 32.00KB
C:\DOCUME~1\Chwamiki\LOCALS~1\Temp\~DFF5C0.tmp 32.00KB
C:\DOCUME~1\Chwamiki\LOCALS~1\Temp\maybelline.bmp 7.93KB
C:\DOCUME~1\Chwamiki\LOCALS~1\Temp\~DFE1DD.tmp 32.00KB
C:\DOCUME~1\Chwamiki\LOCALS~1\Temp\~DF5F1C.tmp 32.00KB
C:\DOCUME~1\Chwamiki\LOCALS~1\Temp\~DF4E8E.tmp 32.00KB
C:\DOCUME~1\Chwamiki\LOCALS~1\Temp\~DF7366.tmp 32.00KB
C:\DOCUME~1\Chwamiki\LOCALS~1\Temp\~DF526A.tmp 32.00KB
C:\DOCUME~1\Chwamiki\LOCALS~1\Temp\sweetvalley.bmp 7.93KB
C:\DOCUME~1\Chwamiki\LOCALS~1\Temp\loreal.bmp 7.93KB
C:\DOCUME~1\Chwamiki\LOCALS~1\Temp\~DF1F2C.tmp 32.00KB
C:\DOCUME~1\Chwamiki\LOCALS~1\Temp\~DFF678.tmp 32.00KB
C:\DOCUME~1\Chwamiki\LOCALS~1\Temp\~DF8322.tmp 32.00KB
C:\DOCUME~1\Chwamiki\LOCALS~1\Temp\~DF4D90.tmp 32.00KB
C:\DOCUME~1\Chwamiki\LOCALS~1\Temp\~DF3D3A.tmp 32.00KB
C:\DOCUME~1\Chwamiki\LOCALS~1\Temp\~DF24A3.tmp 32.00KB
C:\DOCUME~1\Chwamiki\LOCALS~1\Temp\_isB.tmp 0.22MB
C:\DOCUME~1\Chwamiki\LOCALS~1\Temp\WERC.tmp.dir00\appcompat.txt 5.02KB
C:\DOCUME~1\Chwamiki\LOCALS~1\Temp\WERC.tmp 0 bytes
C:\DOCUME~1\Chwamiki\LOCALS~1\Temp\~DF6FDC.tmp 32.00KB
C:\DOCUME~1\Chwamiki\LOCALS~1\Temp\~DF5C9E.tmp 32.00KB
C:\DOCUME~1\Chwamiki\LOCALS~1\Temp\~DF6E96.tmp 32.00KB
C:\DOCUME~1\Chwamiki\LOCALS~1\Temp\~DF5C88.tmp 32.00KB
C:\DOCUME~1\Chwamiki\LOCALS~1\Temp\~DFCAFB.tmp 32.00KB
C:\DOCUME~1\Chwamiki\LOCALS~1\Temp\SNDUpdater544I.log 0.29MB
C:\DOCUME~1\Chwamiki\LOCALS~1\Temp\SNDSetup544.log 3.52KB
C:\DOCUME~1\Chwamiki\LOCALS~1\Temp\_is4.tmp 0.22MB
C:\DOCUME~1\Chwamiki\LOCALS~1\Temp\~DF5921.tmp 32.00KB
C:\DOCUME~1\Chwamiki\LOCALS~1\Temp\~DF30B7.tmp 32.00KB
C:\DOCUME~1\Chwamiki\LOCALS~1\Temp\~DF957C.tmp 32.00KB
C:\DOCUME~1\Chwamiki\LOCALS~1\Temp\~DF7799.tmp 32.00KB
C:\DOCUME~1\Chwamiki\LOCALS~1\Temp\~DF90E8.tmp 32.00KB
C:\DOCUME~1\Chwamiki\LOCALS~1\Temp\~DF56F5.tmp 32.00KB
C:\DOCUME~1\Chwamiki\LOCALS~1\Temp\~DF65E5.tmp 32.00KB
C:\DOCUME~1\Chwamiki\LOCALS~1\Temp\~DF4212.tmp 32.00KB
C:\DOCUME~1\Chwamiki\LOCALS~1\Temp\~DF149C.tmp 32.00KB
C:\DOCUME~1\Chwamiki\LOCALS~1\Temp\~DF1F4.tmp 32.00KB
C:\DOCUME~1\Chwamiki\LOCALS~1\Temp\~DF8342.tmp 32.00KB
C:\DOCUME~1\Chwamiki\LOCALS~1\Temp\~DF4A40.tmp 32.00KB
C:\DOCUME~1\Chwamiki\LOCALS~1\Temp\~DF904D.tmp 32.00KB
C:\DOCUME~1\Chwamiki\LOCALS~1\Temp\~DF7967.tmp 32.00KB
C:\DOCUME~1\Chwamiki\LOCALS~1\Temp\crazygood.bmp 20.68KB
C:\DOCUME~1\Chwamiki\LOCALS~1\Temp\~DFE40F.tmp 32.00KB
C:\DOCUME~1\Chwamiki\LOCALS~1\Temp\~DFC78F.tmp 32.00KB
C:\DOCUME~1\Chwamiki\LOCALS~1\Temp\~DF355.tmp 0.17MB
C:\DOCUME~1\Chwamiki\LOCALS~1\Temp\~DFCDA8.tmp 0.17MB
C:\DOCUME~1\Chwamiki\LOCALS~1\Temp\~DF340C.tmp 0.19MB
C:\DOCUME~1\Chwamiki\LOCALS~1\Temp\~DFF7B1.tmp 32.00KB
C:\DOCUME~1\Chwamiki\LOCALS~1\Temp\Norton Internet Security 2-20-2005 15h3m45s.log 5.91MB
C:\DOCUME~1\Chwamiki\LOCALS~1\Temp\AVRES_OPTRF_LiveUpdate.dat 172 bytes
C:\DOCUME~1\Chwamiki\LOCALS~1\Temp\~DF31E7.tmp 32.00KB
C:\DOCUME~1\Chwamiki\LOCALS~1\Temp\WER84.tmp.dir00\appcompat.txt 31.61KB
C:\DOCUME~1\Chwamiki\LOCALS~1\Temp\Norton AntiVirus 2005 2-20-2005 14h52m27s.log 2.42MB
C:\DOCUME~1\Chwamiki\LOCALS~1\Temp\WERF.tmp.dir00\appcompat.txt 17.72KB
C:\DOCUME~1\Chwamiki\LOCALS~1\Temp\SymSCLiveUpdate.dat 556 bytes
C:\DOCUME~1\Chwamiki\LOCALS~1\Temp\~DFDADD.tmp 32.00KB
C:\DOCUME~1\Chwamiki\LOCALS~1\Temp\travelocity.bmp 20.68KB
C:\DOCUME~1\Chwamiki\LOCALS~1\Temp\WER23F.tmp.dir00\appcompat.txt 17.72KB
C:\DOCUME~1\Chwamiki\LOCALS~1\Temp\SSALiveUpdate.dat 172 bytes
C:\DOCUME~1\Chwamiki\LOCALS~1\Temp\~DFCF87.tmp 32.00KB
C:\DOCUME~1\Chwamiki\LOCALS~1\Temp\WER84.tmp 0 bytes
C:\DOCUME~1\Chwamiki\LOCALS~1\Temp\Norton AntiVirus 2005 2-18-2005 16h31m54s.log 2.96MB
C:\DOCUME~1\Chwamiki\LOCALS~1\Temp\doritosdd.bmp 7.93KB
C:\DOCUME~1\Chwamiki\LOCALS~1\Temp\WERF.tmp 0 bytes
C:\DOCUME~1\Chwamiki\LOCALS~1\Temp\gatorade.bmp 20.68KB
C:\DOCUME~1\Chwamiki\LOCALS~1\Temp\WER7.tmp.dir00\appcompat.txt 17.72KB
C:\DOCUME~1\Chwamiki\LOCALS~1\Temp\WER6.tmp.dir00\appcompat.txt 17.72KB
C:\DOCUME~1\Chwamiki\LOCALS~1\Temp\WERA.tmp.dir00\appcompat.txt 14.38KB
C:\DOCUME~1\Chwamiki\LOCALS~1\Temp\symcprop.dat 0.18MB
C:\DOCUME~1\Chwamiki\LOCALS~1\Temp\AVSTELiveUpdate.dat 172 bytes
C:\DOCUME~1\Chwamiki\LOCALS~1\Temp\WER23F.tmp 0 bytes
C:\DOCUME~1\Chwamiki\LOCALS~1\Temp\LSInstall.log 6.23KB
C:\DOCUME~1\Chwamiki\LOCALS~1\Temp\WER7.tmp 0 bytes
C:\DOCUME~1\Chwamiki\LOCALS~1\Temp\WER6.tmp 0 bytes
C:\DOCUME~1\Chwamiki\LOCALS~1\Temp\WERA.tmp 0 bytes
C:\DOCUME~1\Chwamiki\LOCALS~1\Temp\Norton AntiVirus 2005 2-7-2005 17h38m33s.log 2.96MB
C:\DOCUME~1\Chwamiki\LOCALS~1\Temp\WER9.tmp.dir00\appcompat.txt 8.03KB
C:\DOCUME~1\Chwamiki\LOCALS~1\Temp\WER8.tmp.dir00\appcompat.txt 5.00KB
C:\DOCUME~1\Chwamiki\LOCALS~1\Temp\ReadMe\pt-pt_readme.txt 11.50KB
C:\DOCUME~1\Chwamiki\LOCALS~1\Temp\ReadMe\nl_readme.txt 11.80KB
C:\DOCUME~1\Chwamiki\LOCALS~1\Temp\ReadMe\ko_readme.txt 12.33KB
C:\DOCUME~1\Chwamiki\LOCALS~1\Temp\ReadMe\it_readme.txt 11.72KB
C:\DOCUME~1\Chwamiki\LOCALS~1\Temp\ReadMe\fr-fr_readme.txt 12.38KB
C:\DOCUME~1\Chwamiki\LOCALS~1\Temp\ReadMe\es_readme.txt 11.66KB
C:\DOCUME~1\Chwamiki\LOCALS~1\Temp\ReadMe\en-us_readme.txt 10.66KB
C:\DOCUME~1\Chwamiki\LOCALS~1\Temp\ReadMe\en-uk_readme.txt 10.66KB
C:\DOCUME~1\Chwamiki\LOCALS~1\Temp\ReadMe\de_readme.txt 11.88KB
C:\DOCUME~1\Chwamiki\LOCALS~1\Temp\AutoRun\autorun.cfg 1.04KB
C:\DOCUME~1\Chwamiki\LOCALS~1\Temp\AutoRun\AutoRun.bmp 73.24KB
C:\DOCUME~1\Chwamiki\LOCALS~1\Temp\PreScan.log 362 bytes
C:\DOCUME~1\Chwamiki\LOCALS~1\Temp\data\zdata_18.big 12.00KB
C:\DOCUME~1\Chwamiki\LOCALS~1\Temp\data\zdata_18.bh 1.50KB
C:\DOCUME~1\Chwamiki\LOCALS~1\Temp\data\zdata_16.big 4.88MB
C:\DOCUME~1\Chwamiki\LOCALS~1\Temp\data\zdata_16.bh 3.92KB
C:\DOCUME~1\Chwamiki\LOCALS~1\Temp\data\zdata_15.big 0.25MB
C:\DOCUME~1\Chwamiki\LOCALS~1\Temp\data\zdata_15.bh 3.92KB
C:\DOCUME~1\Chwamiki\LOCALS~1\Temp\data\zdata_14.big 83.99KB
C:\DOCUME~1\Chwamiki\LOCALS~1\Temp\data\zdata_14.bh 3.92KB
C:\DOCUME~1\Chwamiki\LOCALS~1\Temp\data\zdata_13.big 59.36KB
C:\DOCUME~1\Chwamiki\LOCALS~1\Temp\data\zdata_13.bh 3.92KB
C:\DOCUME~1\Chwamiki\LOCALS~1\Temp\data\zdata_07.big 0.10MB
C:\DOCUME~1\Chwamiki\LOCALS~1\Temp\data\zdata_07.bh 3.92KB
C:\DOCUME~1\Chwamiki\LOCALS~1\Temp\data\zdata_06.big 0.11MB
C:\DOCUME~1\Chwamiki\LOCALS~1\Temp\data\zdata_06.bh 3.92KB
C:\DOCUME~1\Chwamiki\LOCALS~1\Temp\data\zdata_05.big 71.17KB
C:\DOCUME~1\Chwamiki\LOCALS~1\Temp\data\zdata_05.bh 3.92KB
C:\DOCUME~1\Chwamiki\LOCALS~1\Temp\data\zdata_04.big 1.46MB
C:\DOCUME~1\Chwamiki\LOCALS~1\Temp\data\zdata_04.bh 3.92KB
C:\DOCUME~1\Chwamiki\LOCALS~1\Temp\data\zdata_03.big 0.27MB
C:\DOCUME~1\Chwamiki\LOCALS~1\Temp\data\zdata_03.bh 3.92KB
C:\DOCUME~1\Chwamiki\LOCALS~1\Temp\data\zdata_02.big 1.13MB
C:\DOCUME~1\Chwamiki\LOCALS~1\Temp\data\zdata_02.bh 3.92KB
C:\DOCUME~1\Chwamiki\LOCALS~1\Temp\data\zdata_01.big 12.88KB
C:\DOCUME~1\Chwamiki\LOCALS~1\Temp\data\zdata_01.bh 3.92KB
C:\DOCUME~1\Chwamiki\LOCALS~1\Temp\data\gui\teammgmt\12a_s11.big 9.00KB
C:\DOCUME~1\Chwamiki\LOCALS~1\Temp\data\gui\playnow\11_xtras.big 1.51KB
C:\DOCUME~1\Chwamiki\LOCALS~1\Temp\data\gui\playnow\04_2tm.big 14.70KB
C:\DOCUME~1\Chwamiki\LOCALS~1\Temp\data\gui\playnow\03_offl.big 14.16KB
C:\DOCUME~1\Chwamiki\LOCALS~1\Temp\data\gui\playnow\02_teams.big 9.14KB
C:\DOCUME~1\Chwamiki\LOCALS~1\Temp\data\gui\pause\85_post.big 1.69KB
C:\DOCUME~1\Chwamiki\LOCALS~1\Temp\data\gui\pause\83_repl.big 62.55KB
C:\DOCUME~1\Chwamiki\LOCALS~1\Temp\data\gui\pause\82_cam.big 3.73KB
C:\DOCUME~1\Chwamiki\LOCALS~1\Temp\data\gui\pause\81_mf.big 5.07KB
C:\DOCUME~1\Chwamiki\LOCALS~1\Temp\data\gui\pause\81b_scor.big 6.25KB
C:\DOCUME~1\Chwamiki\LOCALS~1\Temp\data\gui\pause\81a_book.big 12.71KB
C:\DOCUME~1\Chwamiki\LOCALS~1\Temp\data\gui\pause\80_pause.big 4.79KB
C:\DOCUME~1\Chwamiki\LOCALS~1\Temp\data\gui\pause\05a_opt.big 5.31KB
C:\DOCUME~1\Chwamiki\LOCALS~1\Temp\data\gui\menu\01_main.big 7.00KB
C:\DOCUME~1\Chwamiki\LOCALS~1\Temp\data\gui\mainbe.big 30.39KB
C:\DOCUME~1\Chwamiki\LOCALS~1\Temp\data\gui\main.big 71.91KB
C:\DOCUME~1\Chwamiki\LOCALS~1\Temp\data\gui\loading\sell.big 0.80MB
C:\DOCUME~1\Chwamiki\LOCALS~1\Temp\data\gui\loading\onsplash.big 0.80MB
C:\DOCUME~1\Chwamiki\LOCALS~1\Temp\data\gui\loading\mfsplash.big 0.80MB
C:\DOCUME~1\Chwamiki\LOCALS~1\Temp\data\gui\loading\load0.big 0.80MB
C:\DOCUME~1\Chwamiki\LOCALS~1\Temp\data\gui\loading\gmsplash.big 0.80MB
C:\DOCUME~1\Chwamiki\LOCALS~1\Temp\data\gui\loading\gfsplash.big 0.80MB
C:\DOCUME~1\Chwamiki\LOCALS~1\Temp\data\gui\loading\dnotice.big 49.47KB
C:\DOCUME~1\Chwamiki\LOCALS~1\Temp\data\gui\icons\x.big 2.67KB
C:\DOCUME~1\Chwamiki\LOCALS~1\Temp\data\gui\icons\t.big 2.66KB
C:\DOCUME~1\Chwamiki\LOCALS~1\Temp\data\gui\icons\r1.big 2.66KB
C:\DOCUME~1\Chwamiki\LOCALS~1\Temp\data\gui\icons\l1.big 2.65KB
C:\DOCUME~1\Chwamiki\LOCALS~1\Temp\data\gui\gameLib\toggle.big 5.57KB
C:\DOCUME~1\Chwamiki\LOCALS~1\Temp\data\gui\gameLib\teamsel.big 7.78KB
C:\DOCUME~1\Chwamiki\LOCALS~1\Temp\data\gui\gameLib\stars.big 5.21KB
C:\DOCUME~1\Chwamiki\LOCALS~1\Temp\data\gui\gameLib\scrlbar.big 4.30KB
C:\DOCUME~1\Chwamiki\LOCALS~1\Temp\data\gui\gameLib\plyrpanl.big 4.30KB
C:\DOCUME~1\Chwamiki\LOCALS~1\Temp\data\gui\gameLib\pitch.big 62.18KB
C:\DOCUME~1\Chwamiki\LOCALS~1\Temp\data\gui\gameLib\overlay.big 4.72KB
C:\DOCUME~1\Chwamiki\LOCALS~1\Temp\data\gui\gameLib\optBar.big 1.74KB
C:\DOCUME~1\Chwamiki\LOCALS~1\Temp\data\gui\gameLib\MsgBox.big 8.08KB
C:\DOCUME~1\Chwamiki\LOCALS~1\Temp\data\gui\gameLib\menubox.big 8.65KB
C:\DOCUME~1\Chwamiki\LOCALS~1\Temp\data\gui\gameLib\imgscrol.big 8.71KB
C:\DOCUME~1\Chwamiki\LOCALS~1\Temp\data\gui\gameLib\fifaHelp.big 14.90KB
C:\DOCUME~1\Chwamiki\LOCALS~1\Temp\data\gui\gameLib\fifaElem.big 8.46KB
C:\DOCUME~1\Chwamiki\LOCALS~1\Temp\data\gui\gameLib\ea_trax.big 17.59KB
C:\DOCUME~1\Chwamiki\LOCALS~1\Temp\data\gui\gameLib\comboItm.big 7.24KB
C:\DOCUME~1\Chwamiki\LOCALS~1\Temp\data\gui\gameLib\clipctrl.big 1.24KB
C:\DOCUME~1\Chwamiki\LOCALS~1\Temp\data\gui\gameLib\be_pitch.big 57.94KB
C:\DOCUME~1\Chwamiki\LOCALS~1\Temp\data\gui\gameLib\bargraph.big 4.71KB
C:\DOCUME~1\Chwamiki\LOCALS~1\Temp\data\gui\gameLib\ascroll.big 3.14KB
C:\DOCUME~1\Chwamiki\LOCALS~1\Temp\data\gui\elements\weather.big 25.70KB
C:\DOCUME~1\Chwamiki\LOCALS~1\Temp\data\gui\elements\r_arrow2.big 3.87KB
C:\DOCUME~1\Chwamiki\LOCALS~1\Temp\data\gui\elements\r_arrow.big 3.85KB
C:\DOCUME~1\Chwamiki\LOCALS~1\Temp\data\gui\elements\p_anim.big 431 bytes
C:\DOCUME~1\Chwamiki\LOCALS~1\Temp\data\gui\elements\pad.big 30.96KB
C:\DOCUME~1\Chwamiki\LOCALS~1\Temp\data\gui\elements\l_arrow2.big 3.88KB
C:\DOCUME~1\Chwamiki\LOCALS~1\Temp\data\gui\elements\l_arrow.big 3.85KB
C:\DOCUME~1\Chwamiki\LOCALS~1\Temp\data\gui\elements\length.big 12.80KB
C:\DOCUME~1\Chwamiki\LOCALS~1\Temp\data\gui\elements\keyboard.big 28.73KB
C:\DOCUME~1\Chwamiki\LOCALS~1\Temp\data\gui\elements\injury.big 5.59KB
C:\DOCUME~1\Chwamiki\LOCALS~1\Temp\data\gui\elements\halfplyr.big 5.43KB
C:\DOCUME~1\Chwamiki\LOCALS~1\Temp\data\gui\elements\fullplyr.big 6.20KB
C:\DOCUME~1\Chwamiki\LOCALS~1\Temp\data\gui\elements\diffic.big 9.15KB
C:\DOCUME~1\Chwamiki\LOCALS~1\Temp\data\gui\elements\cards.big 5.87KB
C:\DOCUME~1\Chwamiki\LOCALS~1\Temp\data\gui\elements\a_3.big 0.43MB
C:\DOCUME~1\Chwamiki\LOCALS~1\Temp\data\gui\elements\a_2.big 0.12MB
C:\DOCUME~1\Chwamiki\LOCALS~1\Temp\data\gui\ea05_tit.ttf 44.21KB
C:\DOCUME~1\Chwamiki\LOCALS~1\Temp\data\gui\ea05_bod.ttf 40.57KB
C:\DOCUME~1\Chwamiki\LOCALS~1\Temp\data\gui\cafeLib\stdVirKB.big 43.31KB
C:\DOCUME~1\Chwamiki\LOCALS~1\Temp\data\gui\cafeLib\stdCntrl.big 23.01KB
C:\DOCUME~1\Chwamiki\LOCALS~1\Temp\data\gui\cafeLib\stdBhvr.big 6.13KB
C:\DOCUME~1\Chwamiki\LOCALS~1\Temp\data\gui\cafeLib\stdArt.big 9.06KB
C:\DOCUME~1\Chwamiki\LOCALS~1\Temp\data\gui\cafeLib\icons\x_ps2.big 3.35KB
C:\DOCUME~1\Chwamiki\LOCALS~1\Temp\data\gui\cafeLib\icons\t_ps2.big 3.35KB
C:\DOCUME~1\Chwamiki\LOCALS~1\Temp\data\gui\cafeLib\icons\s_ps2.big 3.30KB
C:\DOCUME~1\Chwamiki\LOCALS~1\Temp\data\gui\cafeLib\icons\str_ps2.big 3.12KB
C:\DOCUME~1\Chwamiki\LOCALS~1\Temp\data\gui\cafeLib\icons\r2_ps2.big 3.62KB
C:\DOCUME~1\Chwamiki\LOCALS~1\Temp\data\gui\cafeLib\icons\l2_ps2.big 3.56KB
C:\DOCUME~1\Chwamiki\LOCALS~1\Temp\data\gui\cafeLib\icons\c_ps2.big 3.27KB
C:\DOCUME~1\Chwamiki\LOCALS~1\Temp\data\gui\but_x.big 2.39KB
C:\DOCUME~1\Chwamiki\LOCALS~1\Temp\data\gui\boot\mc_boot.big 2.06KB
C:\DOCUME~1\Chwamiki\LOCALS~1\Temp\data\gui\boot\flags.big 61.71KB
C:\DOCUME~1\Chwamiki\LOCALS~1\Temp\data\gui\boot\fe_init.big 943 bytes
C:\DOCUME~1\Chwamiki\LOCALS~1\Temp\data\gui\boot\53_title.big 0.12MB
C:\DOCUME~1\Chwamiki\LOCALS~1\Temp\data\gui\boot\47_legal.big 0.21MB
C:\DOCUME~1\Chwamiki\LOCALS~1\Temp\data\gui\boot\35_lang.big 3.16KB
C:\DOCUME~1\Chwamiki\LOCALS~1\Temp\data\gui\assets\logos\t47.big 14.58KB
C:\DOCUME~1\Chwamiki\LOCALS~1\Temp\data\gui\assets\logos\t1.big 21.61KB
C:\DOCUME~1\Chwamiki\LOCALS~1\Temp\data\gui\assets\logos\l31.big 9.27KB
C:\DOCUME~1\Chwamiki\LOCALS~1\Temp\data\gui\assets\logos\l13.big 12.65KB
C:\DOCUME~1\Chwamiki\LOCALS~1\Temp\data\gui\assets\kits\j1_00047.big 24.72KB
C:\DOCUME~1\Chwamiki\LOCALS~1\Temp\data\gui\assets\kits\j1_00001.big 27.52KB
C:\DOCUME~1\Chwamiki\LOCALS~1\Temp\data\gui\assets\kits\j0_00047.big 27.43KB
C:\DOCUME~1\Chwamiki\LOCALS~1\Temp\data\gui\assets\kits\j0_00001.big 30.87KB
C:\DOCUME~1\Chwamiki\LOCALS~1\Temp\data\gui\assets\heads\s_805.big 12.11KB
C:\DOCUME~1\Chwamiki\LOCALS~1\Temp\data\gui\assets\heads\s_7763.big 12.85KB
C:\DOCUME~1\Chwamiki\LOCALS~1\Temp\data\gui\assets\heads\s_7554.big 11.20KB
C:\DOCUME~1\Chwamiki\LOCALS~1\Temp\data\gui\assets\heads\s_7512.big 12.71KB
C:\DOCUME~1\Chwamiki\LOCALS~1\Temp\data\gui\assets\heads\s_6975.big 11.64KB
C:\DOCUME~1\Chwamiki\LOCALS~1\Temp\data\gui\assets\heads\s_5740.big 12.23KB
C:\DOCUME~1\Chwamiki\LOCALS~1\Temp\data\gui\assets\heads\s_5003.big 12.03KB
C:\DOCUME~1\Chwamiki\LOCALS~1\Temp\data\gui\assets\heads\s_47390.big 11.17KB
C:\DOCUME~1\Chwamiki\LOCALS~1\Temp\data\gui\assets\heads\s_44900.big 12.25KB
C:\DOCUME~1\Chwamiki\LOCALS~1\Temp\data\gui\assets\heads\s_4202.big 12.48KB
C:\DOCUME~1\Chwamiki\LOCALS~1\Temp\data\gui\assets\heads\s_4000.big 12.36KB
C:\DOCUME~1\Chwamiki\LOCALS~1\Temp\data\gui\assets\heads\s_388.big 11.31KB
C:\DOCUME~1\Chwamiki\LOCALS~1\Temp\data\gui\assets\heads\s_3712.big 11.39KB
C:\DOCUME~1\Chwamiki\LOCALS~1\Temp\data\gui\assets\heads\s_34079.big 11.54KB
C:\DOCUME~1\Chwamiki\LOCALS~1\Temp\data\gui\assets\heads\s_1625.big 11.10KB
C:\DOCUME~1\Chwamiki\LOCALS~1\Temp\data\gui\assets\heads\s_1605.big 12.29KB
C:\DOCUME~1\Chwamiki\LOCALS~1\Temp\data\gui\assets\heads\s_1419.big 11.35KB
C:\DOCUME~1\Chwamiki\LOCALS~1\Temp\data\gui\assets\heads\s_13128.big 12.50KB
C:\DOCUME~1\Chwamiki\LOCALS~1\Temp\data\gui\assets\heads\s_1256.big 11.66KB
C:\DOCUME~1\Chwamiki\LOCALS~1\Temp\data\gui\assets\heads\s_123463.big 12.33KB
C:\DOCUME~1\Chwamiki\LOCALS~1\Temp\data\gui\assets\heads\s_111093.big 12.70KB
C:\DOCUME~1\Chwamiki\LOCALS~1\Temp\data\gui\assets\heads\s_1109.big 11.38KB
C:\DOCUME~1\Chwamiki\LOCALS~1\Temp\data\gui\assets\heads\s_1088.big 12.62KB
C:\DOCUME~1\Chwamiki\LOCALS~1\Temp\data\gui\assets\heads\s_1025.big 12.03KB
C:\DOCUME~1\Chwamiki\LOCALS~1\Temp\data\gui\assets\heads\g_211211.big 11.88KB
C:\DOCUME~1\Chwamiki\LOCALS~1\Temp\data\gui\assets\heads\g_160631.big 11.39KB
C:\DOCUME~1\Chwamiki\LOCALS~1\Temp\data\gui\assets\heads\g_061742.big 12.34KB
C:\DOCUME~1\Chwamiki\LOCALS~1\Temp\data\gui\assets\heads\g_031814.big 13.03KB
C:\DOCUME~1\Chwamiki\LOCALS~1\Temp\data\gui\assets\heads\g_031813.big 12.98KB
C:\DOCUME~1\Chwamiki\LOCALS~1\Temp\data\gui\assets\heads\g_031711.big 12.02KB
C:\DOCUME~1\Chwamiki\LOCALS~1\Temp\data\gui\assets\heads\g_021112.big 11.77KB
C:\DOCUME~1\Chwamiki\LOCALS~1\Temp\data\gui\assets\heads\g_011752.big 12.35KB
C:\DOCUME~1\Chwamiki\LOCALS~1\Temp\data\gui\assets\back\l_6.big 1.06MB
C:\DOCUME~1\Chwamiki\LOCALS~1\Temp\data\gui\assets\back\bg00.big 1.92KB
C:\DOCUME~1\Chwamiki\LOCALS~1\Temp\data\gui\assets\back\bg0.big 1.20MB
C:\DOCUME~1\Chwamiki\LOCALS~1\Temp\data\gui\assets\back\b1.big 1.20MB
C:\DOCUME~1\Chwamiki\LOCALS~1\Temp\data\gui\arial_kr.pfr 0.23MB
C:\DOCUME~1\Chwamiki\LOCALS~1\Temp\data\fifa.fat 0.17MB
C:\DOCUME~1\Chwamiki\LOCALS~1\Temp\data\eaglrm.big 0.17MB
C:\DOCUME~1\Chwamiki\LOCALS~1\Temp\data\cmn\meta.db 11.29KB
C:\DOCUME~1\Chwamiki\LOCALS~1\Temp\data\cmn\ini_pc.big 4.70KB
C:\DOCUME~1\Chwamiki\LOCALS~1\Temp\data\cmn\ini.big 27.57KB
C:\DOCUME~1\Chwamiki\LOCALS~1\Temp\data\cmn\fifa.db 93.90KB
C:\DOCUME~1\Chwamiki\LOCALS~1\Temp\data\cmn\fe\spa.db 0.15MB
C:\DOCUME~1\Chwamiki\LOCALS~1\Temp\data\cmn\fe\por.db 0.15MB
C:\DOCUME~1\Chwamiki\LOCALS~1\Temp\data\cmn\fe\kor.db 0.15MB
C:\DOCUME~1\Chwamiki\LOCALS~1\Temp\data\cmn\fe\ita.db 0.15MB
C:\DOCUME~1\Chwamiki\LOCALS~1\Temp\data\cmn\fe\ger.db 0.15MB
C:\DOCUME~1\Chwamiki\LOCALS~1\Temp\data\cmn\fe\fre.db 0.15MB
C:\DOCUME~1\Chwamiki\LOCALS~1\Temp\data\cmn\fe\eng.db 0.14MB
C:\DOCUME~1\Chwamiki\LOCALS~1\Temp\data\cmn\fe\dut.db 0.14MB
C:\DOCUME~1\Chwamiki\LOCALS~1\Temp\data\cmn\cfg_pc_m.ini 2.38KB
C:\DOCUME~1\Chwamiki\LOCALS~1\Temp\data\cmn\cfg_pc_h.ini 2.13KB
C:\DOCUME~1\Chwamiki\LOCALS~1\Temp\data\cmn\be\tidbghom.bin 88 bytes
C:\DOCUME~1\Chwamiki\LOCALS~1\Temp\data\cmn\be\tidbgawy.bin 104 bytes
C:\DOCUME~1\Chwamiki\LOCALS~1\Temp\data\cmn\be\sim.bin 2.87KB
C:\DOCUME~1\Chwamiki\LOCALS~1\Temp\data\cmn\be\sicndata.bin 4.38KB
C:\DOCUME~1\Chwamiki\LOCALS~1\Temp\data\cmn\be\script.bin 8.74KB
C:\DOCUME~1\Chwamiki\LOCALS~1\Temp\data\cmn\be\replayz.bin 24.32KB
C:\DOCUME~1\Chwamiki\LOCALS~1\Temp\data\cmn\be\replayd.bin 26.50KB
C:\DOCUME~1\Chwamiki\LOCALS~1\Temp\data\cmn\be\motion.big 10.8MB
C:\DOCUME~1\Chwamiki\LOCALS~1\Temp\data\cmn\be\micndata.bin 30.61KB
C:\DOCUME~1\Chwamiki\LOCALS~1\Temp\data\cmn\be\iconrela.bin 392 bytes
C:\DOCUME~1\Chwamiki\LOCALS~1\Temp\data\cmn\be\iconperm.bin 316 bytes
C:\DOCUME~1\Chwamiki\LOCALS~1\Temp\data\cmn\be\flag.ebo 11.89KB
C:\DOCUME~1\Chwamiki\LOCALS~1\Temp\data\cl.bin 16 bytes
C:\DOCUME~1\Chwamiki\LOCALS~1\Temp\data\bescene.cs 0.88MB
C:\DOCUME~1\Chwamiki\LOCALS~1\Temp\data\audio\music\songlist.bin 148 bytes
C:\DOCUME~1\Chwamiki\LOCALS~1\Temp\data\audio\music\PaulOak.asf 1.11MB
C:\DOCUME~1\Chwamiki\LOCALS~1\Temp\data\audio\mix_mot.ini 2.93KB
C:\DOCUME~1\Chwamiki\LOCALS~1\Temp\data\audio\chants.bin 2.15KB
C:\DOCUME~1\Chwamiki\LOCALS~1\Temp\data\audio\chants.big 18.7MB
C:\DOCUME~1\Chwamiki\LOCALS~1\Temp\data\audio\aemsstrm.big 34.6MB
C:\DOCUME~1\Chwamiki\LOCALS~1\Temp\data\audio\aemsbank.big 4.27MB
C:\DOCUME~1\Chwamiki\LOCALS~1\Temp\alocale\eal_span.mad 1.72MB
C:\DOCUME~1\Chwamiki\LOCALS~1\Temp\alocale\eal_porn.mad 1.72MB
C:\DOCUME~1\Chwamiki\LOCALS~1\Temp\alocale\eal_korn.mad 1.83MB
C:\DOCUME~1\Chwamiki\LOCALS~1\Temp\alocale\eal_itan.mad 1.72MB
C:\DOCUME~1\Chwamiki\LOCALS~1\Temp\alocale\eal_gern.mad 1.72MB
C:\DOCUME~1\Chwamiki\LOCALS~1\Temp\alocale\eal_fren.mad 1.69MB
C:\DOCUME~1\Chwamiki\LOCALS~1\Temp\alocale\eal_engn.mad 1.72MB
C:\DOCUME~1\Chwamiki\LOCALS~1\Temp\alocale\eal_dutn.mad 1.71MB
C:\DOCUME~1\Chwamiki\LOCALS~1\Temp\setup.exe 0.11MB
C:\DOCUME~1\Chwamiki\LOCALS~1\Temp\fifapc.ico 23.01KB
C:\DOCUME~1\Chwamiki\LOCALS~1\Temp\fifa2005_demo.exe 3.71MB
C:\DOCUME~1\Chwamiki\LOCALS~1\Temp\config.dat 20.26KB
C:\DOCUME~1\Chwamiki\LOCALS~1\Temp\common_filelist.txt 6.10KB
C:\DOCUME~1\Chwamiki\LOCALS~1\Temp\Support\lisezmoi.txt 12.38KB
C:\DOCUME~1\Chwamiki\LOCALS~1\Temp\Support\leeme.txt 11.66KB
C:\DOCUME~1\Chwamiki\LOCALS~1\Temp\swtm
 

swatkat

Technomancer
whoa.....the log of CCleaner is not essential...anyway these are the JUNK in your System, i think you have clicked "Analyze" and not "Run Cleaner", click "Run Cleaner" button in CCLeaner, to remove this junk!

have fixed the badies in HijackThis?
 
OP
KoRn

KoRn

In the zone
i cant donload the other cleaner the donload links do not exist so now i hav 2 cleaners hijak dis and ccleaner wat do i do next cuz ive posted both the log files.hurry up dudes.
 

swatkat

Technomancer
u have posted only CCLeaner log file, and not HijackThis log file, CCLeaner log is not essential!, but HijakcThis log is needed.....
 
OP
KoRn

KoRn

In the zone
heres the hijack this log file.hhhhhh

Logfile of HijackThis v1.99.1
Scan saved at 3:14:36 PM, on 3/13/2005
Platform: Windows XP (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 (6.00.2600.0000)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Common Files\Symantec Shared\ccProxy.exe
C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe
C:\Program Files\Norton Internet Security\ISSVC.exe
C:\Program Files\Common Files\Symantec Shared\SNDSrvc.exe
C:\Program Files\Common Files\Symantec Shared\SPBBC\SPBBCSvc.exe
C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
C:\WINDOWS\System32\imapi.exe
C:\Program Files\Norton Internet Security\Norton AntiVirus\navapsvc.exe
C:\WINDOWS\System32\nvsvc32.exe
C:\WINDOWS\system32\pctspk.exe
C:\Program Files\Common Files\Symantec Shared\CCPD-LC\symlcsvc.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\Mixer.exe
C:\WINDOWS\System32\RUNDLL32.EXE
C:\WINDOWS\System32\SK2690DM.EXE
C:\Program Files\Winamp\winampa.exe
C:\Program Files\Common Files\Symantec Shared\ccApp.exe
C:\Program Files\Microsoft AntiSpyware\gcasServ.exe
C:\Program Files\Microsoft AntiSpyware\gcasDtServ.exe
C:\Program Files\Common Files\Symantec Shared\AdBlocking\NSMdtr.exe
C:\Program Files\Internet Explorer\iexplore.exe
D:\Program Files\Yahoo!\Messenger\ypager.exe
C:\WINDOWS\System32\rundll32.exe
D:\PROGRA~1\DAP\DAP.EXE
D:\Program Files\ht\HijackThis.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = www.mail.yahoo.com
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = www.mail.yahoo.com
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Local Page =
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page =
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = *hot-searches.com*;*lender-search.com*
O1 - Hosts file is located at: C:\WINDOWS\nsdb\hosts
O1 - Hosts: 82.179.166.164 lender-search.com
O1 - Hosts: 82.179.166.165 hot-searches.com
O2 - BHO: Norton Internet Security - {9ECB9560-04F9-4bbc-943D-298DDF1699E1} - C:\Program Files\Common Files\Symantec Shared\AdBlocking\NISShExt.dll
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar1.dll
O2 - BHO: NAV Helper - {BDF3E430-B101-42AD-A544-FADC6B084872} - C:\Program Files\Norton Internet Security\Norton AntiVirus\NavShExt.dll
O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINDOWS\System32\msdxm.ocx
O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar1.dll
O3 - Toolbar: DAP Bar - {62999427-33FC-4baf-9C9C-BCE6BD127F08} - D:\Program Files\DAP\DAPIEBar.dll
O3 - Toolbar: Norton Internet Security - {0B53EAC3-8D69-4b9e-9B19-A37C9A5676A7} - C:\Program Files\Common Files\Symantec Shared\AdBlocking\NISShExt.dll
O3 - Toolbar: Norton AntiVirus - {42CDD1BF-3FFB-4238-8AD1-7859DF00B1D6} - C:\Program Files\Norton Internet Security\Norton AntiVirus\NavShExt.dll
O4 - HKLM\..\Run: [SystemTray] SysTray.Exe
O4 - HKLM\..\Run: [C-Media Mixer] Mixer.exe /startup
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\System32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [nwiz] nwiz.exe /install
O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\WINDOWS\System32\NvMcTray.dll,NvTaskbarInit
O4 - HKLM\..\Run: [HPDJ Taskbar Utility] C:\WINDOWS\System32\spool\drivers\w32x86\3\hpztsb03.exe
O4 - HKLM\..\Run: [Hot Key Kbd 2690 Daemon] SK2690DM.EXE
O4 - HKLM\..\Run: [WinampAgent] C:\Program Files\Winamp\winampa.exe
O4 - HKLM\..\Run: [ccApp] "C:\Program Files\Common Files\Symantec Shared\ccApp.exe"
O4 - HKLM\..\Run: [SSC_UserPrompt] C:\Program Files\Common Files\Symantec Shared\Security Center\UsrPrmpt.exe
O4 - HKLM\..\Run: [gcasServ] "C:\Program Files\Microsoft AntiSpyware\gcasServ.exe"
O4 - HKLM\..\Run: [Symantec NetDriver Monitor] C:\PROGRA~1\SYMNET~1\SNDMon.exe
O4 - HKCU\..\Run: [Yahoo! Pager] D:\Program Files\Yahoo!\Messenger\ypager.exe -quiet
O4 - HKCU\..\Run: [Windows Registry Repair Pro] d:\Program Files\3B Software\Windows Registry Repair Pro\RegistryRepairPro.exe 4
O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office\OSA9.EXE
O8 - Extra context menu item: &Download with &DAP - D:\PROGRA~1\DAP\dapextie.htm
O8 - Extra context menu item: &Google Search - res://C:\Program Files\Google\GoogleToolbar1.dll/cmsearch.html
O8 - Extra context menu item: Backward Links - res://C:\Program Files\Google\GoogleToolbar1.dll/cmbacklinks.html
O8 - Extra context menu item: Cached Snapshot of Page - res://C:\Program Files\Google\GoogleToolbar1.dll/cmcache.html
O8 - Extra context menu item: Download &all with DAP - D:\PROGRA~1\DAP\dapextie2.htm
O8 - Extra context menu item: Similar Pages - res://C:\Program Files\Google\GoogleToolbar1.dll/cmsimilar.html
O8 - Extra context menu item: Translate into English - res://C:\Program Files\Google\GoogleToolbar1.dll/cmtrans.html
O9 - Extra button: Messenger - {4528BBE0-4E08-11D5-AD55-00010333D0AD} - D:\Program Files\Yahoo!\Messenger\yhexbmes0521.dll
O9 - Extra 'Tools' menuitem: Yahoo! Messenger - {4528BBE0-4E08-11D5-AD55-00010333D0AD} - D:\Program Files\Yahoo!\Messenger\yhexbmes0521.dll
O9 - Extra button: Run DAP - {669695BC-A811-4A9D-8CDF-BA8C795F261C} - D:\PROGRA~1\DAP\DAP.EXE
O9 - Extra button: Related - {c95fe080-8f5d-11d2-a20b-00aa003c157a} - C:\WINDOWS\web\related.htm
O9 - Extra 'Tools' menuitem: Show &Related Links - {c95fe080-8f5d-11d2-a20b-00aa003c157a} - C:\WINDOWS\web\related.htm
O17 - HKLM\System\CCS\Services\Tcpip\..\{5DDED4B0-7DD8-47F4-8A03-0D18BAACD731}: NameServer = 210.212.12.3,210.212.12.5
O17 - HKLM\System\CS1\Services\Tcpip\..\{5DDED4B0-7DD8-47F4-8A03-0D18BAACD731}: NameServer = 210.212.12.3,210.212.12.5
O17 - HKLM\System\CS2\Services\Tcpip\..\{5DDED4B0-7DD8-47F4-8A03-0D18BAACD731}: NameServer = 210.212.12.3,210.212.12.5
O23 - Service: Symantec Event Manager (ccEvtMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
O23 - Service: Symantec Network Proxy (ccProxy) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccProxy.exe
O23 - Service: Symantec Password Validation (ccPwdSvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccPwdSvc.exe
O23 - Service: Symantec Settings Manager (ccSetMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe
O23 - Service: ISSvc (ISSVC) - Symantec Corporation - C:\Program Files\Norton Internet Security\ISSVC.exe
O23 - Service: Norton AntiVirus Auto-Protect Service (navapsvc) - Symantec Corporation - C:\Program Files\Norton Internet Security\Norton AntiVirus\navapsvc.exe
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\System32\nvsvc32.exe
O23 - Service: PCTEL Speaker Phone (Pctspk) - PCtel, Inc. - C:\WINDOWS\system32\pctspk.exe
O23 - Service: SAVScan - Symantec Corporation - C:\Program Files\Norton Internet Security\Norton AntiVirus\SAVScan.exe
O23 - Service: ScriptBlocking Service (SBService) - Symantec Corporation - C:\PROGRA~1\COMMON~1\SYMANT~1\SCRIPT~1\SBServ.exe
O23 - Service: Symantec Network Drivers Service (SNDSrvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\SNDSrvc.exe
O23 - Service: Symantec SPBBCSvc (SPBBCSvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\SPBBC\SPBBCSvc.exe
O23 - Service: Symantec Core LC - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\CCPD-LC\symlcsvc.exe
 
Status
Not open for further replies.
Top Bottom