Author Topic: [Resolved] AVG found Trojan Horse Crypt.ASHD  (Read 4668 times)

0 Members and 1 Guest are viewing this topic.

Offline kcrawhorn

  • Bronze Member
  • Posts: 126
[Resolved] AVG found Trojan Horse Crypt.ASHD
« on: March 27, 2012, 03:43:42 PM »
This computer has been running slowly. The wifi is not working very fast either. An AVG scan ran March 24th found "";"C:\Program Files\Jasc Software Inc\Paint Shop Pro Studio\Paint Shop Pro Studio.exe";"Trojan horse Crypt.ASHD";"Moved to Virus Vault"

Here are the DDS logs:

.
DDS (Ver_2011-08-26.01) - NTFSx86
Internet Explorer: 8.0.6001.18702  BrowserJavaVersion: 1.6.0_30
Run by customer1 at 16:36:54 on 2012-03-27
Microsoft Windows XP Home Edition  5.1.2600.3.1252.1.1033.18.2047.1392 [GMT -5:00]
.
AV: AVG Anti-Virus Free Edition 2012 *Enabled/Updated* {17DDD097-36FF-435F-9E1B-52D74245D6BF}
.
============== Running Processes ===============
.
C:\PROGRA~1\AVG\AVG2012\avgrsx.exe
C:\Program Files\AVG\AVG2012\avgcsrvx.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\system32\svchost -k DcomLaunch
svchost.exe
C:\WINDOWS\System32\svchost.exe -k netsvcs
C:\WINDOWS\system32\svchost.exe -k WudfServiceGroup
svchost.exe
svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\Program Files\AVG\AVG PC Tuneup\BoostSpeed.exe
C:\WINDOWS\Explorer.EXE
svchost.exe
C:\Program Files\AVG\AVG2012\avgwdsvc.exe
C:\Program Files\Bonjour\mDNSResponder.exe
C:\WINDOWS\system32\dlcxcoms.exe
C:\Program Files\Java\jre6\bin\jqs.exe
C:\Program Files\ATI Technologies\ATI.ACE\cli.exe
C:\Program Files\Common Files\Java\Java Update\jusched.exe
C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE
C:\Program Files\Dell Photo AIO Printer 926\dlcxmon.exe
C:\Program Files\Dell Photo AIO Printer 926\memcard.exe
C:\Program Files\Common Files\InstallShield\UpdateService\issch.exe
C:\Program Files\Dell Photo AIO Printer 924\dlccmon.exe
C:\Program Files\Analog Devices\SoundMAX\SMax4PNP.exe
C:\Program Files\Analog Devices\SoundMAX\Smax4.exe
C:\Program Files\AVG\AVG2012\avgtray.exe
C:\Program Files\AVG Secure Search\vprot.exe
C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
C:\WINDOWS\system32\tcpsvcs.exe
C:\WINDOWS\System32\snmp.exe
C:\Program Files\Analog Devices\SoundMAX\SMAgent.exe
C:\WINDOWS\system32\svchost.exe -k imgsvc
C:\Program Files\AVG\AVG2012\avgnsx.exe
C:\WINDOWS\system32\UTSCSI.EXE
C:\Program Files\Common Files\AVG Secure Search\vToolbarUpdater\10.2.0\ToolbarUpdater.exe
C:\Program Files\AVG\AVG2012\AVGIDSAgent.exe
C:\WINDOWS\system32\dlcccoms.exe
C:\WINDOWS\System32\svchost.exe -k HTTPFilter
C:\Program Files\ATI Technologies\ATI.ACE\cli.exe
C:\program files\real\realplayer\update\realsched.exe
C:\Program Files\AVG\AVG2012\avgui.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\Internet Explorer\iexplore.exe
.
============== Pseudo HJT Report ===============
.
uStart Page = hxxp://www.google.com/
uSearch Page = hxxp://www.google.com
uInternet Settings,ProxyOverride = *.local
BHO: Adobe PDF Reader Link Helper: {06849e9f-c8d7-4d59-b87d-784b7d6be0b3} - c:\program files\common files\adobe\acrobat\activex\AcroIEHelper.dll
BHO: RealPlayer Download and Record Plugin for Internet Explorer: {3049c3e9-b461-4bc5-8870-4c09146192ca} - c:\documents and settings\all users\application data\real\realplayer\browserrecordplugin\ie\rpbrowserrecordplugin.dll
BHO: AVG Safe Search: {3ca2f312-6f6e-4b53-a66e-4e65e497c8c0} - c:\program files\avg\avg2012\avgssie.dll
BHO: Spybot-S&D IE Protection: {53707962-6f74-2d53-2644-206d7942484f} - c:\progra~1\spybot~1\SDHelper.dll
BHO: Java(tm) Plug-In SSV Helper: {761497bb-d6f0-462c-b6eb-d4daf1d92d43} - c:\program files\java\jre6\bin\ssv.dll
BHO: AVG Security Toolbar: {95b7759c-8c7f-4bf1-b163-73684a933233} - c:\program files\avg secure search\10.2.0.3\AVG Secure Search_toolbar.dll
BHO: Java(tm) Plug-In 2 SSV Helper: {dbc80044-a445-435b-bc74-9c25c1c588a9} - c:\program files\java\jre6\bin\jp2ssv.dll
BHO: AL2Spy Class: {dc200356-0864-4f66-8964-5d43a19300f5} - c:\windows\autolo~1\AL2DLL.dll
BHO: JQSIEStartDetectorImpl Class: {e7e6f031-17ce-4c07-bc86-eabfe594f69c} - c:\program files\java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll
TB: AVG Security Toolbar: {95b7759c-8c7f-4bf1-b163-73684a933233} - c:\program files\avg secure search\10.2.0.3\AVG Secure Search_toolbar.dll
{e7df6bff-55a5-4eb7-a673-4ed3e9456d39}
uRun: [SpybotSD TeaTimer] c:\program files\spybot - search & destroy\TeaTimer.exe
mRun: [ATICCC] "c:\program files\ati technologies\ati.ace\cli.exe" runtime -Delay
mRun: [SunJavaUpdateSched] "c:\program files\common files\java\java update\jusched.exe"
mRun: [FaxCenterServer] "c:\program files\dell pc fax\fm3032.exe" /s
mRun: [dlcxmon.exe] "c:\program files\dell photo aio printer 926\dlcxmon.exe"
mRun: [MemoryCardManager] "c:\program files\dell photo aio printer 926\memcard.exe"
mRun: [ISUSScheduler] "c:\program files\common files\installshield\updateservice\issch.exe" -start
mRun: [Adobe Reader Speed Launcher] "c:\program files\adobe\reader 8.0\reader\Reader_sl.exe"
mRun: [dlccmon.exe] "c:\program files\dell photo aio printer 924\dlccmon.exe"
mRun: [DLCCCATS] rundll32 c:\windows\system32\spool\drivers\w32x86\3\DLCCtime.dll,_RunDLLEntry@16
mRun: [DLCXCATS] rundll32 c:\windows\system32\spool\drivers\w32x86\3\DLCXtime.dll,_RunDLLEntry@16
mRun: [SoundMAXPnP] c:\program files\analog devices\soundmax\SMax4PNP.exe
mRun: [SoundMAX] "c:\program files\analog devices\soundmax\Smax4.exe" /tray
mRun: [QuickTime Task] "c:\program files\quicktime\qttask.exe" -atboottime
mRun: [AVG_TRAY] "c:\program files\avg\avg2012\avgtray.exe"
mRun: [vProt] "c:\program files\avg secure search\vprot.exe"
mRun: [TkBellExe] "c:\program files\real\realplayer\update\realsched.exe"  -osboot
mRun: [ROC_roc_dec12] "c:\program files\avg secure search\ROC_roc_dec12.exe" /PROMPT /CMPID=roc_dec12
IE: E&xport to Microsoft Excel - c:\progra~1\micros~2\office11\EXCEL.EXE/3000
IE: {85d1f590-48f4-11d9-9669-0800200c9a66} - %windir%\bdoscandel.exe
IE: {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe
IE: {FB5F1910-F110-11d2-BB9E-00C04F795683} - c:\program files\messenger\msmsgs.exe
IE: {92780B25-18CC-41C8-B9BE-3C9C571A8263} - {FF059E31-CC5A-4E2E-BF3B-96E929D65503} - c:\progra~1\micros~2\office11\REFIEBAR.DLL
IE: {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - {53707962-6F74-2D53-2644-206D7942484F} - c:\progra~1\spybot~1\SDHelper.dll
DPF: {149E45D8-163E-4189-86FC-45022AB2B6C9} - file:///C:/Program%20Files/Mahjong%20Escape%20-%20Ancient%20Japan/Images/stg_drm.ocx
DPF: {166B1BCA-3F9C-11CF-8075-444553540000} - hxxp://fpdownload.macromedia.com/get/shockwave/cabs/director/sw.cab
DPF: {17492023-C23A-453E-A040-C7C580BBF700} - hxxp://download.microsoft.com/download/3/9/8/398422c0-8d3e-40e1-a617-af65a72a0465/LegitCheckControl.cab
DPF: {38AB6A6C-CC4C-4F9E-A3DD-3C5681EF18A1} - hxxp://www.freerealms.com/gamedata/FreeRealmsInstaller.cab
DPF: {4B54A9DE-EF1C-4EBE-A328-7C28EA3B433A} - hxxp://quickscan.bitdefender.com/qsax/qsax.cab
DPF: {4F1E5B1A-2A80-42CA-8532-2D05CB959537} - hxxp://gfx1.hotmail.com/mail/w3/resources/MSNPUpld.cab
DPF: {5D86DDB5-BDF9-441B-9E9E-D4730F4EE499} - hxxp://download.bitdefender.com/resources/scan8/oscan8.cab
DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} - hxxp://update.microsoft.com/windowsupdate/v6/V5Controls/en/x86/client/wuweb_site.cab?1160522783484
DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} - hxxp://update.microsoft.com/microsoftupdate/v6/V5Controls/en/x86/client/muweb_site.cab?1155655455656
DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_30-windows-i586.cab
DPF: {8FFBE65D-2C9C-4669-84BD-5829DC0B603C} - hxxp://fpdownload.macromedia.com/get/flashplayer/current/ultrashim.cab
DPF: {CAFEEFAC-0016-0000-0001-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_01-windows-i586.cab
DPF: {CAFEEFAC-0016-0000-0003-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_03-windows-i586.cab
DPF: {CAFEEFAC-0016-0000-0005-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_05-windows-i586.cab
DPF: {CAFEEFAC-0016-0000-0007-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_07-windows-i586.cab
DPF: {CAFEEFAC-0016-0000-0030-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_30-windows-i586.cab
DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_30-windows-i586.cab
DPF: {CC450D71-CC90-424C-8638-1F2DBAC87A54} - file:///C:/Program%20Files/SCRABBLE/Images/armhelper.ocx
DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} - hxxp://fpdownload.macromedia.com/get/flashplayer/current/swflash.cab
DPF: {DE22A7AB-A739-4C58-AD52-21F9CD6306B7} - hxxp://download.microsoft.com/download/7/E/6/7E6A8567-DFE4-4624-87C3-163549BE2704/clearadj.cab
TCP: DhcpNameServer = 192.168.2.1
TCP: Interfaces\{3A17128A-31C1-494A-B8F5-0761BE95C120} : DhcpNameServer = 66.38.1.91 66.38.0.240 66.38.0.241
TCP: Interfaces\{6151B8D1-1250-49F0-A78C-282061E09E38} : DhcpNameServer = 192.168.2.1
TCP: Interfaces\{8AD25AF2-6805-4F2F-B834-8F6890B2EDCB} : DhcpNameServer = 192.168.1.1
TCP: Interfaces\{FAA11E2B-BF70-4753-AC88-0B28DAA776B1} : DhcpNameServer = 192.168.1.1
Handler: linkscanner - {F274614C-63F8-47D5-A4D1-FBDDE494F8D1} - c:\program files\avg\avg2012\avgpp.dll
Handler: viprotocol - {B658800C-F66E-4EF3-AB85-6C0C227862A9} - c:\program files\common files\avg secure search\viprotocolinstaller\10.2.0\ViProtocol.dll
Notify: AtiExtEvent - Ati2evxx.dll
SSODL: WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - c:\windows\system32\WPDShServiceObj.dll
Hosts: 127.0.0.1   www.spywareinfo.com
.
================= FIREFOX ===================
.
FF - ProfilePath - c:\documents and settings\customer1\application data\mozilla\firefox\profiles\gygvqas6.default\
FF - prefs.js: browser.search.selectedEngine - Yahoo
FF - prefs.js: keyword.URL - hxxp://isearch.avg.com/search?cid=%7B9b5491a7-5335-4be7-ac85-02b376fd61ba%7D&mid=394e44f4630a47d18da8d15e776005a6-87d0ec190e4c69a23e608e916e5c08d08c9e9e6c&ds=AVG&v=9.0.0.23&lang=en&pr=pr&d=2011-12-22%2017%3A52%3A00&sap=ku&q=
FF - component: c:\documents and settings\all users\application data\real\realplayer\browserrecordplugin\firefox\ext\components\nprpffbrowserrecordext.dll
FF - component: c:\documents and settings\all users\application data\real\realplayer\browserrecordplugin\firefox\ext\components\nprpffbrowserrecordlegacyext.dll
FF - plugin: c:\documents and settings\all users\application data\real\realplayer\browserrecordplugin\mozillaplugins\nprpchromebrowserrecordext.dll
FF - plugin: c:\documents and settings\all users\application data\real\realplayer\browserrecordplugin\mozillaplugins\nprphtml5videoshim.dll
FF - plugin: c:\progra~1\sonyon~1\npsoe.dll
FF - plugin: c:\progra~1\sonyon~1\npsoeact.dll
FF - plugin: c:\program files\java\jre6\bin\new_plugin\npdeployJava1.dll
FF - plugin: c:\program files\microsoft silverlight\4.1.10111.0\npctrlui.dll
FF - plugin: c:\program files\mozilla firefox\plugins\npdeployJava1.dll
.
============= SERVICES / DRIVERS ===============
.
R0 AVGIDSEH;AVGIDSEH;c:\windows\system32\drivers\AVGIDSEH.sys [2011-7-11 23120]
R0 Avgrkx86;AVG Anti-Rootkit Driver;c:\windows\system32\drivers\avgrkx86.sys [2011-9-13 32592]
R1 Avgldx86;AVG AVI Loader Driver;c:\windows\system32\drivers\avgldx86.sys [2011-10-7 230608]
R1 Avgmfx86;AVG Mini-Filter Resident Anti-Virus Shield;c:\windows\system32\drivers\avgmfx86.sys [2011-8-8 40016]
R1 Avgtdix;AVG TDI Driver;c:\windows\system32\drivers\avgtdix.sys [2011-7-11 295248]
R2 AVGIDSAgent;AVGIDSAgent;c:\program files\avg\avg2012\AVGIDSAgent.exe [2011-10-12 4433248]
R2 avgwd;AVG WatchDog;c:\program files\avg\avg2012\avgwdsvc.exe [2011-8-2 192776]
R2 dlcx_device;dlcx_device;c:\windows\system32\dlcxcoms.exe -service --> c:\windows\system32\dlcxcoms.exe -service [?]
R2 Iprip;RIP Listener;c:\windows\system32\svchost.exe -k netsvcs [2004-8-4 14336]
R2 vToolbarUpdater10.2.0;vToolbarUpdater10.2.0;c:\program files\common files\avg secure search\vtoolbarupdater\10.2.0\ToolbarUpdater.exe [2012-3-12 918880]
R3 AVGIDSDriver;AVGIDSDriver;c:\windows\system32\drivers\AVGIDSDriver.sys [2011-7-11 134608]
R3 AVGIDSFilter;AVGIDSFilter;c:\windows\system32\drivers\AVGIDSFilter.sys [2011-7-11 24272]
R3 AVGIDSShim;AVGIDSShim;c:\windows\system32\drivers\AVGIDSShim.sys [2011-10-4 16720]
S3 IPN2220;802.11g Wireless LAN Card Driver;c:\windows\system32\drivers\i2220ntx.sys [2006-10-16 140288]
S3 SetupNTGLM7X;SetupNTGLM7X;\??\d:\ntglm7x.sys --> d:\NTGLM7X.sys [?]
.
=============== Created Last 30 ================
.
.
==================== Find3M  ====================
.
2012-03-24 17:58:10   414368   ----a-w-   c:\windows\system32\FlashPlayerCPLApp.cpl
2012-02-03 09:22:18   1860096   ----a-w-   c:\windows\system32\win32k.sys
2012-01-15 03:25:37   499712   ----a-w-   c:\windows\system32\msvcp71.dll
2012-01-15 03:25:37   348160   ----a-w-   c:\windows\system32\msvcr71.dll
2012-01-11 19:06:47   3072   ------w-   c:\windows\system32\iacenc.dll
2012-01-09 16:20:25   139784   ----a-w-   c:\windows\system32\drivers\rdpwd.sys
.
============= FINISH: 16:38:04.42 ===============



.
UNLESS SPECIFICALLY INSTRUCTED, DO NOT POST THIS LOG.
IF REQUESTED, ZIP IT UP & ATTACH IT
.
DDS (Ver_2011-08-26.01)
.
Microsoft Windows XP Home Edition
Boot Device: \Device\HarddiskVolume1
Install Date: 1/16/2009 11:13:35 AM
System Uptime: 3/26/2012 2:45:56 PM (26 hours ago)
.
Motherboard: ASUSTeK Computer INC. |  | A8S-X
Processor: AMD Athlon(tm) 64 Processor 3200+ | Socket 939 | 2000/200mhz
.
==== Disk Partitions =========================
.
A: is Removable
C: is FIXED (NTFS) - 149 GiB total, 131.067 GiB free.
D: is CDROM ()
.
==== Disabled Device Manager Items =============
.
Class GUID: {4D36E97E-E325-11CE-BFC1-08002BE10318}
Description:
Device ID: ACPI\ATK0110\1010110
Manufacturer:
Name:
PNP Device ID: ACPI\ATK0110\1010110
Service:
.
==== System Restore Points ===================
.
No restore point in system.
.
==== Installed Programs ======================
.
Adobe Acrobat and Reader 8.1.2 Security Update 1 (KB403742)
Adobe Flash Player 10 Plugin
Adobe Flash Player 11 ActiveX
Adobe Reader 8.1.2
Adobe Shockwave Player
Athlon 64 Processor Driver
ATI - Software Uninstall Utility
ATI Catalyst Control Center
ATI Display Driver
ATI HYDRAVISION
ATI Parental Control & Encoder
AVG 2012
AVG PC Tuneup
Bonjour
Compatibility Pack for the 2007 Office system
Dell PC Fax
Dell Photo AIO Printer 924
Dell Photo AIO Printer 926
Free Realms Installer
InterActual Player
Jasc Paint Shop Photo Album 5
Jasc Paint Shop Pro Studio, Dell Editon
Java Auto Updater
Java(TM) 6 Update 3
Java(TM) 6 Update 30
Java(TM) 6 Update 5
Java(TM) 6 Update 7
Java(TM) SE Runtime Environment 6 Update 1
Malwarebytes Anti-Malware version 1.60.1.1000
Microsoft .NET Framework 1.1
Microsoft .NET Framework 1.1 Security Update (KB2656353)
Microsoft Internationalized Domain Names Mitigation APIs
Microsoft Managed DirectX (1126)
Microsoft National Language Support Downlevel APIs
Microsoft Office File Validation Add-In
Microsoft Office Live Image Uploader
Microsoft Office Professional Edition 2003
Microsoft Silverlight
Microsoft Visual C++ 2005 ATL Update kb973923 - x86 8.0.50727.4053
Microsoft Visual C++ 2005 Redistributable
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.4148
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.6161
Move Networks Media Player for Internet Explorer
Mozilla Firefox 11.0 (x86 en-US)
MSN Music Assistant
MSXML 4.0 SP2 (KB936181)
MSXML 4.0 SP2 (KB954430)
MSXML 4.0 SP2 (KB973688)
Nero 7 Ultra Edition
NVIDIA Drivers
PowerDVD
Quicken 2007
QuickTime
RCA Video Converter
RealNetworks - Microsoft Visual C++ 2008 Runtime
RealPlayer
RealUpgrade 1.1
Rhapsody Player Engine
SCRABBLE PLUS
Security Update for Windows Internet Explorer 7 (KB938127-v2)
Security Update for Windows Internet Explorer 7 (KB956390)
Security Update for Windows Internet Explorer 7 (KB958215)
Security Update for Windows Internet Explorer 7 (KB960714)
Security Update for Windows Internet Explorer 7 (KB961260)
Security Update for Windows Internet Explorer 7 (KB963027)
Security Update for Windows Internet Explorer 7 (KB969897)
Security Update for Windows Internet Explorer 8 (KB2510531)
Security Update for Windows Internet Explorer 8 (KB2544521)
Security Update for Windows Internet Explorer 8 (KB2618444)
Security Update for Windows Internet Explorer 8 (KB2647516)
Security Update for Windows Internet Explorer 8 (KB969897)
Security Update for Windows Internet Explorer 8 (KB972260)
Security Update for Windows XP (KB2621440)
Security Update for Windows XP (KB2641653)
Security Update for Windows XP (KB2647518)
Security Update for Windows XP (KB923789)
Skype™ 5.5
SoundMAX
Spybot - Search & Destroy
Update for Windows Internet Explorer 8 (KB972636)
WebFldrs XP
Winamp
Windows Internet Explorer 7
Windows Internet Explorer 8
Windows Media Format 11 runtime
Windows Media Format Runtime
Windows Media Player 10
Windows Media Player 11
Windows XP Service Pack 3
.
==== Event Viewer Messages From Past Week ========
.
3/24/2012 12:57:03 PM, error: Service Control Manager [7026]  - The following boot-start or system-start driver(s) failed to load:  sfsync02
3/20/2012 4:30:24 AM, error: Dhcp [1002]  - The IP address lease 192.168.2.2 for the Network Card with network address 00173184EC55 has been denied by the DHCP server 0.0.0.0 (The DHCP Server sent a DHCPNACK message).
.
==== End Of File ===========================
« Last Edit: April 07, 2012, 01:27:28 PM by Bear »



Offline Bear

  • Malware Removal Mentors
  • Global Moderator
  • Gold Member
  • Posts: 2141
Re: [In Progress B]AVG found Trojan Horse Crypt.ASHD
« Reply #1 on: March 27, 2012, 04:31:30 PM »
Hello, welcome to SpywareHammer.

I go by Bear, and I will be helping you with your problem. I understand that having malware on your system is disruptive, annoying and can even be frightening.  I also understand the urgency of getting your computer functioning again.  Working as a team, you and I will be able to confront this problem and hopefully bring it to a successful conclusion.  But you need to do a few things to help me understand your situation.

First, tell me everything and anything that you have already tried to fix this problem. 

Second, tell me the symptoms that of infection that you are seeing in your computer and when you first notice them.  If the symptoms were progressive, let me know that.

Third, please only use one forum to help resolve your problem. Posting on more than one forum or trying other things in between our procedures will confuse and lengthen the process and may even make a positive solution impossible.

Fourth, please follow my instructions exactly.   If you cannot follow them or don't understand something, let me know immediately and do NOTHING until you hear from me.  If for any reason you have deviated from my instructions, PLEASE let me know at once.

Fifth, Understand that malware gets into your computer system very easily but can be very, very difficult to remove.  It could take a while and we may have to try several processes to fix the problem.  So please "keep the faith".   I will do all I can to get your computer operating properly, and if I can't fix it we have many very bright individuals here at SpywareHammer who will help us.

Sixth, do not send anything to me as an attachment unless I specifically ask for it.  Please copy and paste all of your responses to me by replying to my post on this forum.  If the response is too long (the forum has size limits), please send it in portions, sequentially.

Seventh let me know of any software you have running that encrypts your hard drive, such as Windows BitLocker or any others.

Eighth If your PC is set to automatically update, DISABLE, this function and do not update until we have disinfected your PC.

And lastly, before we do anything else, please back up you data, if possible on an external media such as DVD's, CD's, memory sticks or external hard drives.

I will analyze your data and post instructions back to you. 



Never interrupt your enemy when he is making a mistake.
- Napoleon Bonaparte

Offline Bear

  • Malware Removal Mentors
  • Global Moderator
  • Gold Member
  • Posts: 2141
Re: [In Progress B]AVG found Trojan Horse Crypt.ASHD
« Reply #2 on: March 27, 2012, 06:06:51 PM »
Hi KC

Let’s get to work on your PC.

1.  Please go to start/control panel/add or remove programs and completely uninstall this program:
Spybot - Search & Destroy

Reboot your PC.

2.  Open Notepad, then copy the code in the code box below and paste it into the Notepad window.  Save the file as Hosts.txt and save it to the following location: c:\windows\system32\drivers\etc .

Code: [Select]
# Copyright (c) 1993-1999 Microsoft Corp.
#
# This is a sample HOSTS file used by Microsoft TCP/IP for Windows.
#
# This file contains the mappings of IP addresses to host names. Each
# entry should be kept on an individual line. The IP address should
# be placed in the first column followed by the corresponding host name.
# The IP address and the host name should be separated by at least one
# space.
#
# Additionally, comments (such as these) may be inserted on individual
# lines or following the machine name denoted by a '#' symbol.
#
# For example:
#
# 102.54.94.97 rhino.acme.com # source server
# 38.25.63.10 x.acme.com # x client host

127.0.0.1 localhost

3.  Now open Notepad again, then copy the code in the code box below and paste it into the Notepad window.  Name the file fixhosts.bat and save it to your desktop.

Code: [Select]
reg delete "HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings" /v  "ProxyOverride"
attrib -r -a -s -h "c:\windows\system32\drivers\etc\Hosts"
del /q /f  "c:\windows\system32\drivers\etc\Hosts"
rename c:\windows\system32\drivers\etc\Hosts.txt Hosts
c:\windows\system32\drivers\etc\Hosts > "c:\%userprofile%\desktop\HostsLog.txt" | notepad
attrib +r +s +h "c:\windows\system32\drivers\etc\Hosts"

Double Click on fixhosts.bat.

Reboot your PC again.

Please read carefully and follow these steps:


4.  Download Combofix from any of the links below, and save it to your desktop. For information regarding this download, please visit this webpage: Combofix use

Link 1
Link 2
Link 3

**Note: It is important that it is saved directly to your desktop**

Close all open browsers.

5.  Disable all of your Anti-Virus, Anti-Spyware programs.  If you need help to disable them go to Disable Anti Malware, be sure to re-enable them before posting your reply.

6.  Double click combofix.exe.  For XP, if ComboFix offers to install a Recovery Console, you must permit it to do so. It is very dangerous to permit ComboFix to run unless the Recovery Console is installed.

When finished, it will produce a report for you at C:\ComboFix.txt.

Please always check to be sure Word Wrap is NOT turned on in any Notepad files you post.  This is done by opening the Notepad file and clicking on Format to be sure Word Wrap is not checked.

Note:  This site has size limits on posts.  Please be sure to check that all the data you entered was posted.  If not, use multiple posts.

Now please post the following to me as a reply to this post:
HostsLog.txt
ComboFix.txt
Let me know how your computer is operating
If you have any questions or problems, let me know that as well

Never interrupt your enemy when he is making a mistake.
- Napoleon Bonaparte

Offline kcrawhorn

  • Bronze Member
  • Posts: 126
Re: [In Progress B]AVG found Trojan Horse Crypt.ASHD
« Reply #3 on: March 28, 2012, 03:15:54 PM »
When I double-clicked fixhosts on the desktop, a box popped up that said C:\WINDOWS\system32\cmd.exe.  A line said, "Delete the registry value ProxyOverride <Y/N>?  I didn't know what to select, so I didn't select anything.  I'm now going to reboot and follow the rest of the directions in your second post.

So many people have worked on this problem that I don't know what all has been tried.  This is actually my mother's computer.  I know we have ran Malware Bytes, AVG, defragmented the computer, and I'm not sure what else. 

The symptoms have been going on for a long, long time.  We thought perhaps the problems were the router.  She's mainly having problems with the speed of her wireless system.  For example, Netflix won't work on the blu-ray player.  Videos won't load or load slowly.  Also, about a month ago, she clicked on a link in Facebook that caused a lot of popups.  Someone came along and uninstalled a bunch of stuff from the computer.  I'm not sure what all.

I have disabled automatic updates.

Offline Bear

  • Malware Removal Mentors
  • Global Moderator
  • Gold Member
  • Posts: 2141
Re: [In Progress B]AVG found Trojan Horse Crypt.ASHD
« Reply #4 on: March 28, 2012, 03:37:16 PM »
Hi KC
Click yes.  You don't want an internet proxy, if one is on your machine it is probably placed there by malware.  Your hosts file has definitely been hijacked and needs to be reset.
Never interrupt your enemy when he is making a mistake.
- Napoleon Bonaparte

Offline Bear

  • Malware Removal Mentors
  • Global Moderator
  • Gold Member
  • Posts: 2141
Re: [In Progress B]AVG found Trojan Horse Crypt.ASHD
« Reply #5 on: March 28, 2012, 03:40:19 PM »
KC
Have you tried resetting the router to defaults?  You have to do that within the router firmware.  You will need to look up your particular router online to find out how to access it.
Never interrupt your enemy when he is making a mistake.
- Napoleon Bonaparte

Offline kcrawhorn

  • Bronze Member
  • Posts: 126
Re: [In Progress B]AVG found Trojan Horse Crypt.ASHD
« Reply #6 on: March 28, 2012, 03:41:47 PM »
Here is the Combo Fix log.  I didn't click yes on the fixhosts file until after I ran combofix.  Do you think I need to do the whole thing over?

ComboFix 12-03-28.02 - customer1 03/28/2012  16:30:32.1.1 - x86
Microsoft Windows XP Home Edition  5.1.2600.3.1252.1.1033.18.2047.1598 [GMT -5:00]
Running from: c:\documents and settings\customer1\Desktop\ComboFix.exe
AV: AVG Anti-Virus Free Edition 2012 *Disabled/Updated* {17DDD097-36FF-435F-9E1B-52D74245D6BF}
.
.
(((((((((((((((((((((((((((((((((((((((   Other Deletions   )))))))))))))))))))))))))))))))))))))))))))))))))
.
.
c:\documents and settings\All Users\Application Data\TEMP
c:\documents and settings\All Users\Application Data\TEMP\DFC5A2B2.TMP
c:\documents and settings\All Users\SPLFA.tmp
c:\documents and settings\customer1\SendTo\RemoveOnReboot.exe
c:\documents and settings\customer1\WINDOWS
c:\windows\system32\Cache
c:\windows\system32\Cache\272512937d9e61a4.fb
c:\windows\system32\Cache\287204568329e189.fb
c:\windows\system32\Cache\28bc8f716fd76a47.fb
c:\windows\system32\Cache\2c53092c95605355.fb
c:\windows\system32\Cache\2d4433759e523ba4.fb
c:\windows\system32\Cache\3917078cb68ec657.fb
c:\windows\system32\Cache\590ba23ce359fd0c.fb
c:\windows\system32\Cache\610289e025a3ee9a.fb
c:\windows\system32\Cache\651c5d3cdbfb8bd1.fb
c:\windows\system32\Cache\6c59ac5e7e7a3ad0.fb
c:\windows\system32\Cache\747dab09c1038a3f.fb
c:\windows\system32\Cache\a8556537add6dfc5.fb
c:\windows\system32\Cache\ad10a52aff5e038d.fb
c:\windows\system32\Cache\c4d28dca2e7648be.fb
c:\windows\system32\Cache\d201ef9910cd39de.fb
c:\windows\system32\Cache\d2e94710a5708128.fb
c:\windows\system32\Cache\d79b9dfe81484ec4.fb
c:\windows\system32\Cache\e0de16f883bea794.fb
c:\windows\system32\Cache\e13dedcd67cb6319.fb
c:\windows\system32\drivers\etc\hosts.txt
c:\windows\system32\SET83.tmp
c:\windows\system32\SET8F.tmp
c:\windows\system32\SETD6.tmp
.
.
(((((((((((((((((((((((((   Files Created from 2012-02-28 to 2012-03-28  )))))))))))))))))))))))))))))))
.
.
2012-02-29 10:12 . 2012-02-29 10:12   --------   d-----w-   c:\documents and settings\customer1\Application Data\Malwarebytes
.
.
.
((((((((((((((((((((((((((((((((((((((((   Find3M Report   ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2012-03-24 17:58 . 2011-12-23 02:22   414368   ----a-w-   c:\windows\system32\FlashPlayerCPLApp.cpl
2012-02-03 09:22 . 2004-08-04 12:00   1860096   ----a-w-   c:\windows\system32\win32k.sys
2012-01-15 03:25 . 2006-07-19 01:16   499712   ----a-w-   c:\windows\system32\msvcp71.dll
2012-01-15 03:25 . 2003-02-21 09:42   348160   ----a-w-   c:\windows\system32\msvcr71.dll
2012-01-11 19:06 . 2012-02-15 06:19   3072   ------w-   c:\windows\system32\iacenc.dll
2012-01-09 16:20 . 2006-07-18 22:42   139784   ----a-w-   c:\windows\system32\drivers\rdpwd.sys
2012-03-13 04:39 . 2012-03-24 18:21   97208   ----a-w-   c:\program files\mozilla firefox\components\browsercomps.dll
.
.
(((((((((((((((((((((((((((((((((((((   Reg Loading Points   ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
.
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{95B7759C-8C7F-4BF1-B163-73684A933233}]
2012-03-12 13:03   1869152   ----a-w-   c:\program files\AVG Secure Search\10.2.0.3\AVG Secure Search_toolbar.dll
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar]
"{95B7759C-8C7F-4BF1-B163-73684A933233}"= "c:\program files\AVG Secure Search\10.2.0.3\AVG Secure Search_toolbar.dll" [2012-03-12 1869152]
.
[HKEY_CLASSES_ROOT\clsid\{95b7759c-8c7f-4bf1-b163-73684a933233}]
[HKEY_CLASSES_ROOT\AVG Secure Search.PugiObj.1]
[HKEY_CLASSES_ROOT\AVG Secure Search.PugiObj]
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ATICCC"="c:\program files\ATI Technologies\ATI.ACE\cli.exe" [2006-01-02 45056]
"SunJavaUpdateSched"="c:\program files\Common Files\Java\Java Update\jusched.exe" [2011-06-09 254696]
"FaxCenterServer"="c:\program files\Dell PC Fax\fm3032.exe" [2006-11-03 312200]
"dlcxmon.exe"="c:\program files\Dell Photo AIO Printer 926\dlcxmon.exe" [2007-01-12 292336]
"MemoryCardManager"="c:\program files\Dell Photo AIO Printer 926\memcard.exe" [2006-11-03 304008]
"ISUSScheduler"="c:\program files\Common Files\InstallShield\UpdateService\issch.exe" [2005-06-10 81920]
"Adobe Reader Speed Launcher"="c:\program files\Adobe\Reader 8.0\Reader\Reader_sl.exe" [2008-01-12 39792]
"dlccmon.exe"="c:\program files\Dell Photo AIO Printer 924\dlccmon.exe" [2005-07-22 425984]
"DLCCCATS"="c:\windows\System32\spool\DRIVERS\W32X86\3\DLCCtime.dll" [2005-06-07 69632]
"DLCXCATS"="c:\windows\System32\spool\DRIVERS\W32X86\3\DLCXtime.dll" [2006-10-16 106496]
"SoundMAXPnP"="c:\program files\Analog Devices\SoundMAX\SMax4PNP.exe" [2004-10-14 1388544]
"QuickTime Task"="c:\program files\QuickTime\qttask.exe" [2009-05-26 413696]
"AVG_TRAY"="c:\program files\AVG\AVG2012\avgtray.exe" [2012-01-24 2416480]
"vProt"="c:\program files\AVG Secure Search\vprot.exe" [2012-03-12 982880]
"TkBellExe"="c:\program files\real\realplayer\update\realsched.exe" [2012-01-15 296056]
"ROC_roc_dec12"="c:\program files\AVG Secure Search\ROC_roc_dec12.exe" [2012-01-30 928096]
.
[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\session manager]
BootExecute   REG_MULTI_SZ      autocheck autochk *\0c:\progra~1\AVG\AVG2012\avgrsx.exe /sync /restart
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\DLCCCATS]
2005-06-07 18:38   69632   ----a-w-   c:\windows\system32\spool\drivers\w32x86\3\dlcctime.dll
.
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"c:\\WINDOWS\\system32\\mmc.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"c:\\Program Files\\Messenger\\msmsgs.exe"=
"c:\\Program Files\\Real\\RealPlayer\\realplay.exe"=
"c:\\WINDOWS\\system32\\dlcxcoms.exe"=
"c:\\WINDOWS\\system32\\dlcccoms.exe"=
"c:\\WINDOWS\\system32\\spool\\drivers\\w32x86\\3\\dlccPSWX.EXE"=
"c:\\Program Files\\Bonjour\\mDNSResponder.exe"=
"c:\\Program Files\\AVG\\AVG2012\\avgmfapx.exe"=
"c:\\Program Files\\Skype\\Phone\\Skype.exe"=
"c:\\Program Files\\AVG\\AVG2012\\avgnsx.exe"=
"c:\\Program Files\\AVG\\AVG2012\\avgdiagex.exe"=
"c:\\Program Files\\AVG\\AVG2012\\avgemcx.exe"=
.
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List]
"3587:TCP"= 3587:TCP:Windows Peer-to-Peer Grouping
"3540:UDP"= 3540:UDP:Peer Name Resolution Protocol (PNRP)
"135:TCP"= 135:TCP:TCP Port 135
"5000:TCP"= 5000:TCP:TCP Port 5000
"5001:TCP"= 5001:TCP:TCP Port 5001
"5002:TCP"= 5002:TCP:TCP Port 5002
"5003:TCP"= 5003:TCP:TCP Port 5003
"5004:TCP"= 5004:TCP:TCP Port 5004
"5005:TCP"= 5005:TCP:TCP Port 5005
"5006:TCP"= 5006:TCP:TCP Port 5006
"5007:TCP"= 5007:TCP:TCP Port 5007
"5008:TCP"= 5008:TCP:TCP Port 5008
"5009:TCP"= 5009:TCP:TCP Port 5009
"5010:TCP"= 5010:TCP:TCP Port 5010
"5011:TCP"= 5011:TCP:TCP Port 5011
"5012:TCP"= 5012:TCP:TCP Port 5012
"5013:TCP"= 5013:TCP:TCP Port 5013
"5014:TCP"= 5014:TCP:TCP Port 5014
"5015:TCP"= 5015:TCP:TCP Port 5015
"5016:TCP"= 5016:TCP:TCP Port 5016
"5017:TCP"= 5017:TCP:TCP Port 5017
"5018:TCP"= 5018:TCP:TCP Port 5018
"5019:TCP"= 5019:TCP:TCP Port 5019
"5020:TCP"= 5020:TCP:TCP Port 5020
.
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\IcmpSettings]
"AllowInboundEchoRequest"= 1 (0x1)
.
R0 AVGIDSEH;AVGIDSEH;c:\windows\system32\drivers\AVGIDSEH.sys [7/11/2011 2:14 AM 23120]
R0 Avgrkx86;AVG Anti-Rootkit Driver;c:\windows\system32\drivers\avgrkx86.sys [9/13/2011 7:30 AM 32592]
R1 Avgldx86;AVG AVI Loader Driver;c:\windows\system32\drivers\avgldx86.sys [10/7/2011 7:23 AM 230608]
R1 Avgtdix;AVG TDI Driver;c:\windows\system32\drivers\avgtdix.sys [7/11/2011 2:14 AM 295248]
R2 avgwd;AVG WatchDog;c:\program files\AVG\AVG2012\avgwdsvc.exe [8/2/2011 7:09 AM 192776]
R2 dlcx_device;dlcx_device;c:\windows\system32\dlcxcoms.exe -service --> c:\windows\system32\dlcxcoms.exe -service [?]
R2 Iprip;RIP Listener;c:\windows\System32\svchost.exe -k netsvcs [8/4/2004 7:00 AM 14336]
R2 vToolbarUpdater10.2.0;vToolbarUpdater10.2.0;c:\program files\Common Files\AVG Secure Search\vToolbarUpdater\10.2.0\ToolbarUpdater.exe [3/12/2012 8:03 AM 918880]
R3 AVGIDSDriver;AVGIDSDriver;c:\windows\system32\drivers\AVGIDSDriver.sys [7/11/2011 2:14 AM 134608]
R3 AVGIDSFilter;AVGIDSFilter;c:\windows\system32\drivers\AVGIDSFilter.sys [7/11/2011 2:14 AM 24272]
R3 AVGIDSShim;AVGIDSShim;c:\windows\system32\drivers\AVGIDSShim.sys [10/4/2011 7:21 AM 16720]
S3 AVGIDSAgent;AVGIDSAgent;c:\program files\AVG\AVG2012\AVGIDSAgent.exe [10/12/2011 7:25 AM 4433248]
S3 IPN2220;802.11g Wireless LAN Card Driver;c:\windows\system32\drivers\i2220ntx.sys [10/16/2006 7:52 PM 140288]
S3 SetupNTGLM7X;SetupNTGLM7X;\??\d:\ntglm7x.sys --> d:\NTGLM7X.sys [?]
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost]
p2psvc   REG_MULTI_SZ      p2psvc p2pimsvc p2pgasvc PNRPSvc
.
Contents of the 'Scheduled Tasks' folder
.
2012-03-28 c:\windows\Tasks\AVG PC Tuneup Integrator Start On customer1 Logon.job
- c:\program files\AVG\AVG PC Tuneup\BoostSpeed.exe [2012-02-25 23:20]
.
2012-03-28 c:\windows\Tasks\RealUpgradeLogonTaskS-1-5-21-73586283-842925246-725345543-1004.job
- c:\program files\Real\RealUpgrade\realupgrade.exe [2011-11-29 22:02]
.
2012-03-22 c:\windows\Tasks\RealUpgradeScheduledTaskS-1-5-21-73586283-842925246-725345543-1004.job
- c:\program files\Real\RealUpgrade\realupgrade.exe [2011-11-29 22:02]
.
.
------- Supplementary Scan -------
.
uStart Page = hxxp://www.google.com/
uInternet Settings,ProxyOverride = *.local
IE: E&xport to Microsoft Excel - c:\progra~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
TCP: DhcpNameServer = 192.168.2.1
Handler: viprotocol - {B658800C-F66E-4EF3-AB85-6C0C227862A9} - c:\program files\Common Files\AVG Secure Search\ViProtocolInstaller\10.2.0\ViProtocol.dll
FF - ProfilePath - c:\documents and settings\customer1\Application Data\Mozilla\Firefox\Profiles\gygvqas6.default\
FF - prefs.js: browser.search.selectedEngine - Yahoo
FF - prefs.js: keyword.URL - hxxp://isearch.avg.com/search?cid=%7B9b5491a7-5335-4be7-ac85-02b376fd61ba%7D&mid=394e44f4630a47d18da8d15e776005a6-87d0ec190e4c69a23e608e916e5c08d08c9e9e6c&ds=AVG&v=9.0.0.23&lang=en&pr=pr&d=2011-12-22%2017%3A52%3A00&sap=ku&q=
.
- - - - ORPHANS REMOVED - - - -
.
WebBrowser-{E7DF6BFF-55A5-4EB7-A673-4ED3E9456D39} - (no file)
AddRemove-Move Networks Player - IE - c:\documents and settings\customer1\Application Data\Move Networks\ie_bin\Uninst.exe
.
.
.
**************************************************************************
.
catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2012-03-28 16:34
Windows 5.1.2600 Service Pack 3 NTFS
.
scanning hidden processes ... 
.
scanning hidden autostart entries ...
.
HKLM\Software\Microsoft\Windows\CurrentVersion\Run
  DLCCCATS = rundll32 c:\windows\System32\spool\DRIVERS\W32X86\3\DLCCtime.dll,_RunDLLEntry@16???????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????
  DLCXCATS = rundll32 c:\windows\System32\spool\DRIVERS\W32X86\3\DLCXtime.dll,_RunDLLEntry@16???????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????
.
scanning hidden files ... 
.
scan completed successfully
hidden files: 0
.
**************************************************************************
.
--------------------- DLLs Loaded Under Running Processes ---------------------
.
- - - - - - - > 'winlogon.exe'(920)
c:\windows\system32\Ati2evxx.dll
.
Completion time: 2012-03-28  16:36:36
ComboFix-quarantined-files.txt  2012-03-28 21:36
.
Pre-Run: 140,736,991,232 bytes free
Post-Run: 140,725,993,472 bytes free
.
WindowsXP-KB310994-SP2-Home-BootDisk-ENU.exe
[boot loader]
timeout=2
default=multi(0)disk(0)rdisk(0)partition(1)\WINDOWS
[operating systems]
c:\cmdcons\BOOTSECT.DAT="Microsoft Windows Recovery Console" /cmdcons
UnsupportedDebug="do not select this" /debug
multi(0)disk(0)rdisk(0)partition(1)\WINDOWS="Microsoft Windows XP Home Edition" /noexecute=optin /fastdetect
.
- - End Of File - - 2D48A7E79B7AC0AC2B92A443A62FF981

Offline Bear

  • Malware Removal Mentors
  • Global Moderator
  • Gold Member
  • Posts: 2141
Re: [In Progress B]AVG found Trojan Horse Crypt.ASHD
« Reply #7 on: March 28, 2012, 04:15:56 PM »
Hi KC

Be sure to run the HOSTS repair script that I sent you last post.  Then:

1.  Disable all Anti-virus, Anti-spyware programs as instructed earlier.  Do not forget to re-enable them before you reply to this post.

2.  I'd like you to run ComboFix again with some changes.  Open Notepad, click on Format and be sure Word Wrap is NOT checked.  Then copy the text in the code box below and paste it into the Notepad window.  Now name this file CFScript.txt and save it to your Desktop.

Code: [Select]

KILLALL::

ClearJavaCache::

RegLock::

RegLockDel::

File::

Folder::

Registry::

Driver::

Firefox::

dirlook::
C:\Program Files\Jasc Software Inc\Paint Shop Pro Studio
c:\documents and settings\customer1

FCopy::

DDS::


2. Close all open browsers.



3. Referring to the picture above, drag CFScript.txt onto the ComboFix.exe icon.  ComboFix will run and produce a report.  This report will be saved at C:\ComboFix.txt.
Note: Do not mouseclick combofix's window while it is running. That may cause it to stall.  Reboot your computer.

Remember to be sure Word Wrap is NOT turned on in any Notepad files you post and to be sure and check that all the data you entered was posted. 

Now please post the following to me as a reply to this post:
ComboFix.txt
Let me know how your computer and browser are operating
If you have any other questions or problems, let me know that as well

Never interrupt your enemy when he is making a mistake.
- Napoleon Bonaparte

Offline kcrawhorn

  • Bronze Member
  • Posts: 126
Re: [In Progress B]AVG found Trojan Horse Crypt.ASHD
« Reply #8 on: March 29, 2012, 03:30:06 PM »
After all of yesterday's steps, the computer got even worse.  When I try to go to the spywarehammer.com, it says the page cannot be found.  It took me to a Google page.  After I clicked on it, it finally came to this site.  I have followed the latest set of directions and getting ready to post the log.  It shut the computer down when I followed those steps.  It hung on shut down, so I finally held the power button in to turn it off.  When it came back on, it finished the scan and the log came up.

Offline kcrawhorn

  • Bronze Member
  • Posts: 126
Re: [In Progress B]AVG found Trojan Horse Crypt.ASHD
« Reply #9 on: March 29, 2012, 03:45:41 PM »
ComboFix 12-03-28.02 - customer1 03/29/2012  16:09:22.2.1 - x86
Running from: c:\documents and settings\customer1\Desktop\ComboFix.exe
Command switches used :: c:\documents and settings\customer1\Desktop\CFScript.txt
.
.
(((((((((((((((((((((((((   Files Created from 2012-02-28 to 2012-03-29  )))))))))))))))))))))))))))))))
.
.
2012-02-29 10:12 . 2012-02-29 10:12   --------   d-----w-   c:\documents and settings\customer1\Application Data\Malwarebytes
.
.
.
((((((((((((((((((((((((((((((((((((((((   Find3M Report   ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2012-03-24 17:58 . 2011-12-23 02:22   414368   ----a-w-   c:\windows\system32\FlashPlayerCPLApp.cpl
2012-02-03 09:22 . 2004-08-04 12:00   1860096   ----a-w-   c:\windows\system32\win32k.sys
2012-01-15 03:25 . 2006-07-19 01:16   499712   ----a-w-   c:\windows\system32\msvcp71.dll
2012-01-15 03:25 . 2003-02-21 09:42   348160   ----a-w-   c:\windows\system32\msvcr71.dll
2012-01-11 19:06 . 2012-02-15 06:19   3072   ------w-   c:\windows\system32\iacenc.dll
2012-01-09 16:20 . 2006-07-18 22:42   139784   ----a-w-   c:\windows\system32\drivers\rdpwd.sys
2012-03-13 04:39 . 2012-03-24 18:21   97208   ----a-w-   c:\program files\mozilla firefox\components\browsercomps.dll
.
.
((((((((((((((((((((((((((((((((((((((((((((   Look   )))))))))))))))))))))))))))))))))))))))))))))))))))))))))
.
---- Directory of c:\documents and settings\customer1 ----
.
2012-03-29 21:23 . 2012-03-29 21:23   16384   ----atw-   c:\documents and settings\customer1\Local Settings\temp\Perflib_Perfdata_a40.dat
2012-03-29 21:22 . 2012-03-29 21:22   16384   ----atw-   c:\documents and settings\customer1\Local Settings\temp\Perflib_Perfdata_c30.dat
2012-03-29 21:22 . 2012-03-29 21:22   0   ----a-w-   c:\documents and settings\customer1\Local Settings\temp\ichcop
2012-03-29 21:21 . 2012-03-29 21:22   26292   ----a-w-   c:\documents and settings\customer1\Local Settings\temp\toolbar_log.txt
2012-03-29 21:21 . 2012-03-29 21:21   79   ----a-w-   c:\documents and settings\customer1\Local Settings\temp\jusched.log
2012-03-29 21:21 . 2012-03-29 21:21   67   --sh--w-   c:\documents and settings\customer1\Local Settings\Temporary Internet Files\Content.IE5\4FX1CDSC\desktop.ini
2012-03-29 21:21 . 2012-03-29 21:21   67   --sh--w-   c:\documents and settings\customer1\Local Settings\Temporary Internet Files\Content.IE5\DBM0BY9Q\desktop.ini
2012-03-29 21:21 . 2012-03-29 21:21   67   --sh--w-   c:\documents and settings\customer1\Local Settings\Temporary Internet Files\Content.IE5\OECUT2CT\desktop.ini
2012-03-29 21:21 . 2012-03-29 21:21   67   --sh--w-   c:\documents and settings\customer1\Local Settings\Temporary Internet Files\Content.IE5\R94RAPBX\desktop.ini
2012-03-29 21:21 . 2012-03-29 21:22   32768   --sha-w-   c:\documents and settings\customer1\Local Settings\Temporary Internet Files\Content.IE5\index.dat
2012-03-29 21:21 . 2012-03-29 21:21   67   --sh--w-   c:\documents and settings\customer1\Local Settings\Temporary Internet Files\Content.IE5\desktop.ini
2012-03-29 21:05 . 2012-03-29 21:05   487   ----a-w-   c:\documents and settings\customer1\Application Data\Macromedia\Flash Player\macromedia.com\support\flashplayer\sys\settings.sol
2012-03-29 21:05 . 2012-03-29 21:05   495   ----a-w-   c:\documents and settings\customer1\Recent\CFScript.lnk
2012-03-29 20:51 . 2012-03-29 21:05   32768   --sha-w-   c:\documents and settings\customer1\Local Settings\History\History.IE5\MSHist012012032920120330\index.dat
2012-03-29 20:22 . 2012-03-29 20:22   252   ----a-w-   c:\documents and settings\customer1\Cookies\B4UN779F.txt
2012-03-29 14:11 . 2012-03-29 14:11   367   ----a-w-   c:\documents and settings\customer1\Cookies\FFS010N4.txt
2012-03-29 13:46 . 2012-03-29 13:46   277   ----a-w-   c:\documents and settings\customer1\Cookies\SFVSQR1K.txt
2012-03-28 22:02 . 2012-03-28 22:02   252   ----a-w-   c:\documents and settings\customer1\Cookies\VE2PS91W.txt
2012-03-28 22:01 . 2012-03-28 22:01   205   ----a-w-   c:\documents and settings\customer1\Cookies\W2W3ZEP1.txt
2012-03-28 21:35 . 2012-03-28 21:35   6375   ----a-w-   c:\documents and settings\customer1\Application Data\Mozilla\Firefox\Profiles\gygvqas6.default\prefs.js.BAK
2012-03-28 21:20 . 2012-03-28 21:20   4448457   ------r-   c:\documents and settings\customer1\Desktop\ComboFix.exe
2012-03-28 21:07 . 2012-03-29 20:55   417   ----a-w-   c:\documents and settings\customer1\Desktop\fixhosts.bat
2012-03-28 21:06 . 2012-03-29 20:55   627   ----a-w-   c:\documents and settings\customer1\Recent\etc.lnk
2012-03-28 21:06 . 2012-03-29 20:55   787   ----a-w-   c:\documents and settings\customer1\Recent\Hosts.lnk
2012-03-27 18:16 . 2012-03-27 18:16   269   ----a-w-   c:\documents and settings\customer1\Cookies\L90SY94R.txt
2012-03-27 18:15 . 2012-03-27 18:15   351   ----a-w-   c:\documents and settings\customer1\Cookies\2MQXJFWJ.txt
2012-03-26 18:40 . 2012-03-26 18:40   86   ----a-w-   c:\documents and settings\customer1\Cookies\UZ6F70BE.txt

Offline kcrawhorn

  • Bronze Member
  • Posts: 126
Re: [In Progress B]AVG found Trojan Horse Crypt.ASHD
« Reply #10 on: March 29, 2012, 03:48:25 PM »

2012-03-26 18:10 . 2012-03-26 18:10   1687   ----a-w-   c:\documents and settings\customer1\Cookies\CWQT8QH5.txt
2012-03-25 00:43 . 2012-03-25 00:43   2924   ----a-w-   c:\documents and settings\customer1\Application Data\Mozilla\Firefox\Profiles\gygvqas6.default\localstore.rdf
2012-03-25 00:42 . 2012-03-25 00:43   2952   ----a-w-   c:\documents and settings\customer1\Application Data\Mozilla\Firefox\Profiles\gygvqas6.default\sessionstore.js
2012-03-25 00:42 . 2012-03-25 00:43   3103448   ----a-w-   c:\documents and settings\customer1\Local Settings\Application Data\Mozilla\Firefox\Profiles\gygvqas6.default\Cache\5\FA\B1B1Bd01
2012-03-25 00:42 . 2012-03-25 00:42   95823   ----a-w-   c:\documents and settings\customer1\Local Settings\Application Data\Mozilla\Firefox\Profiles\gygvqas6.default\Cache\D\DA\5DE04d01
2012-03-25 00:42 . 2012-03-25 00:42   75261   ----a-w-   c:\documents and settings\customer1\Local Settings\Application Data\Mozilla\Firefox\Profiles\gygvqas6.default\Cache\9\F8\11A90d01
2012-03-24 23:26 . 2012-03-28 21:35   6369   ----a-w-   c:\documents and settings\customer1\Application Data\Mozilla\Firefox\Profiles\gygvqas6.default\prefs.js
2012-03-24 23:26 . 2012-03-24 23:26   40427   ----a-w-   c:\documents and settings\customer1\Local Settings\Application Data\Mozilla\Firefox\Profiles\gygvqas6.default\Cache\2\A0\48E42d01
2012-03-24 23:26 . 2012-03-24 23:26   29962   ----a-w-   c:\documents and settings\customer1\Local Settings\Application Data\Mozilla\Firefox\Profiles\gygvqas6.default\Cache\1\8C\1F8B5d01
2012-03-24 23:26 . 2012-03-24 23:26   29538   ----a-w-   c:\documents and settings\customer1\Local Settings\Application Data\Mozilla\Firefox\Profiles\gygvqas6.default\Cache\5\40\B0914d01
2012-03-24 23:26 . 2012-03-24 23:26   51688   ----a-w-   c:\documents and settings\customer1\Local Settings\Application Data\Mozilla\Firefox\Profiles\gygvqas6.default\Cache\D\FF\4C88Dd01
2012-03-24 23:26 . 2012-03-24 23:26   18380   ----a-w-   c:\documents and settings\customer1\Local Settings\Application Data\Mozilla\Firefox\Profiles\gygvqas6.default\Cache\D\81\BE1B5d01
2012-03-24 23:26 . 2012-03-24 23:26   50413   ----a-w-   c:\documents and settings\customer1\Local Settings\Application Data\Mozilla\Firefox\Profiles\gygvqas6.default\Cache\3\D5\36D1Cd01
2012-03-24 23:25 . 2012-03-24 23:25   16772   ----a-w-   c:\documents and settings\customer1\Local Settings\Application Data\Mozilla\Firefox\Profiles\gygvqas6.default\Cache\9\D1\21623d01
2012-03-24 23:25 . 2012-03-24 23:26   137180   ----a-w-   c:\documents and settings\customer1\Local Settings\Application Data\Mozilla\Firefox\Profiles\gygvqas6.default\Cache\B\64\DFBE9d01
2012-03-24 23:25 . 2012-03-24 23:25   30991   ----a-w-   c:\documents and settings\customer1\Local Settings\Application Data\Mozilla\Firefox\Profiles\gygvqas6.default\Cache\F\52\DDA24d01
2012-03-24 23:25 . 2012-03-24 23:25   17076   ----a-w-   c:\documents and settings\customer1\Local Settings\Application Data\Mozilla\Firefox\Profiles\gygvqas6.default\Cache\8\DA\A23B0d01
2012-03-24 23:25 . 2012-03-24 23:25   16593   ----a-w-   c:\documents and settings\customer1\Local Settings\Application Data\Mozilla\Firefox\Profiles\gygvqas6.default\Cache\1\F6\5AE4Fd01
2012-03-24 23:25 . 2012-03-24 23:25   21823   ----a-w-   c:\documents and settings\customer1\Local Settings\Application Data\Mozilla\Firefox\Profiles\gygvqas6.default\Cache\6\0D\AC2C8d01
2012-03-24 23:25 . 2012-03-24 23:25   22633   ----a-w-   c:\documents and settings\customer1\Local Settings\Application Data\Mozilla\Firefox\Profiles\gygvqas6.default\Cache\5\E0\34FF6d01
2012-03-24 23:25 . 2012-03-24 23:25   25059   ----a-w-   c:\documents and settings\customer1\Local Settings\Application Data\Mozilla\Firefox\Profiles\gygvqas6.default\Cache\6\D1\9B9E1d01
2012-03-24 23:25 . 2012-03-24 23:25   25099   ----a-w-   c:\documents and settings\customer1\Local Settings\Application Data\Mozilla\Firefox\Profiles\gygvqas6.default\Cache\A\3B\D2A88d01
2012-03-24 23:25 . 2012-03-24 23:25   31349   ----a-w-   c:\documents and settings\customer1\Local Settings\Application Data\Mozilla\Firefox\Profiles\gygvqas6.default\Cache\8\AF\BBD93d01
2012-03-24 23:25 . 2012-03-24 23:25   40394   ----a-w-   c:\documents and settings\customer1\Local Settings\Application Data\Mozilla\Firefox\Profiles\gygvqas6.default\Cache\E\59\EF37Fd01
2012-03-24 23:25 . 2012-03-24 23:25   23175   ----a-w-   c:\documents and settings\customer1\Local Settings\Application Data\Mozilla\Firefox\Profiles\gygvqas6.default\Cache\C\6A\89193d01
2012-03-24 23:10 . 2012-03-24 23:10   17841   ----a-w-   c:\documents and settings\customer1\Local Settings\Application Data\Mozilla\Firefox\Profiles\gygvqas6.default\Cache\A\42\E0273d01
2012-03-24 23:10 . 2012-03-24 23:10   28377   ----a-w-   c:\documents and settings\customer1\Local Settings\Application Data\Mozilla\Firefox\Profiles\gygvqas6.default\Cache\5\37\260CAd01
2012-03-24 23:10 . 2012-03-24 23:10   17394   ----a-w-   c:\documents and settings\customer1\Local Settings\Application Data\Mozilla\Firefox\Profiles\gygvqas6.default\Cache\3\63\23C93d01
2012-03-24 23:10 . 2012-03-24 23:10   20012   ----a-w-   c:\documents and settings\customer1\Local Settings\Application Data\Mozilla\Firefox\Profiles\gygvqas6.default\Cache\C\79\7122Bd01
2012-03-24 23:10 . 2012-03-24 23:10   59629   ----a-w-   c:\documents and settings\customer1\Local Settings\Application Data\Mozilla\Firefox\Profiles\gygvqas6.default\Cache\F\C8\42B1Bd01
2012-03-24 23:10 . 2012-03-24 23:10   39733   ----a-w-   c:\documents and settings\customer1\Local Settings\Application Data\Mozilla\Firefox\Profiles\gygvqas6.default\Cache\2\66\DFC80d01
2012-03-24 23:10 . 2012-03-24 23:10   294476   ----a-w-   c:\documents and settings\customer1\Local Settings\Application Data\Mozilla\Firefox\Profiles\gygvqas6.default\Cache\9\57\5DAEFd01
2012-03-24 23:10 . 2012-03-24 23:10   17394   ----a-w-   c:\documents and settings\customer1\Local Settings\Application Data\Mozilla\Firefox\Profiles\gygvqas6.default\Cache\E\67\D84ADd01
2012-03-24 23:10 . 2012-03-24 23:10   19916   ----a-w-   c:\documents and settings\customer1\Local Settings\Application Data\Mozilla\Firefox\Profiles\gygvqas6.default\Cache\C\42\BB37Cd01
2012-03-24 23:09 . 2012-03-24 23:09   17394   ----a-w-   c:\documents and settings\customer1\Local Settings\Application Data\Mozilla\Firefox\Profiles\gygvqas6.default\Cache\8\9D\02440d01
2012-03-24 23:09 . 2012-03-24 23:09   18000   ----a-w-   c:\documents and settings\customer1\Local Settings\Application Data\Mozilla\Firefox\Profiles\gygvqas6.default\Cache\6\5C\0FDC1d01
2012-03-24 23:09 . 2012-03-24 23:09   22255   ----a-w-   c:\documents and settings\customer1\Local Settings\Application Data\Mozilla\Firefox\Profiles\gygvqas6.default\Cache\9\EA\CC0DEd01
2012-03-24 23:09 . 2012-03-24 23:09   1050501   ----a-w-   c:\documents and settings\customer1\Local Settings\Application Data\Mozilla\Firefox\Profiles\gygvqas6.default\Cache\F\95\DCDFBd01
2012-03-24 23:09 . 2012-03-24 23:09   20981   ----a-w-   c:\documents and settings\customer1\Local Settings\Application Data\Mozilla\Firefox\Profiles\gygvqas6.default\Cache\7\7D\5414Bd01
2012-03-24 23:09 . 2012-03-24 23:09   27313   ----a-w-   c:\documents and settings\customer1\Local Settings\Application Data\Mozilla\Firefox\Profiles\gygvqas6.default\Cache\A\54\80A30d01
2012-03-24 23:08 . 2012-03-24 23:09   109388   ----a-w-   c:\documents and settings\customer1\Local Settings\Application Data\Mozilla\Firefox\Profiles\gygvqas6.default\Cache\C\7A\706E5d01
2012-03-24 23:08 . 2012-03-24 23:09   108645   ----a-w-   c:\documents and settings\customer1\Local Settings\Application Data\Mozilla\Firefox\Profiles\gygvqas6.default\Cache\7\94\8B17Ad01
2012-03-24 23:08 . 2012-03-24 23:08   21022   ----a-w-   c:\documents and settings\customer1\Local Settings\Application Data\Mozilla\Firefox\Profiles\gygvqas6.default\Cache\4\02\EFFE0d01
2012-03-24 23:08 . 2012-03-24 23:08   18880   ----a-w-   c:\documents and settings\customer1\Local Settings\Application Data\Mozilla\Firefox\Profiles\gygvqas6.default\Cache\6\1D\F94DFd01
2012-03-24 23:08 . 2012-03-24 23:09   633580   ----a-w-   c:\documents and settings\customer1\Local Settings\Application Data\Mozilla\Firefox\Profiles\gygvqas6.default\Cache\6\5B\4B0E2d01
2012-03-24 23:08 . 2012-03-24 23:08   393814   ----a-w-   c:\documents and settings\customer1\Local Settings\Application Data\Mozilla\Firefox\Profiles\gygvqas6.default\Cache\8\E6\B2008d01
2012-03-24 23:08 . 2012-03-24 23:08   25030   ----a-w-   c:\documents and settings\customer1\Local Settings\Application Data\Mozilla\Firefox\Profiles\gygvqas6.default\Cache\7\B0\2483Cd01
2012-03-24 23:08 . 2012-03-24 23:09   1425182   ----a-w-   c:\documents and settings\customer1\Local Settings\Application Data\Mozilla\Firefox\Profiles\gygvqas6.default\Cache\2\56\F74A4d01
2012-03-24 23:08 . 2012-03-24 23:08   489488   ----a-w-   c:\documents and settings\customer1\Local Settings\Application Data\Mozilla\Firefox\Profiles\gygvqas6.default\Cache\F\FE\243CFd01
2012-03-24 23:08 . 2012-03-24 23:08   183725   ----a-w-   c:\documents and settings\customer1\Local Settings\Application Data\Mozilla\Firefox\Profiles\gygvqas6.default\Cache\9\D8\B9B5Fd01
2012-03-24 23:08 . 2012-03-24 23:09   1326608   ----a-w-   c:\documents and settings\customer1\Local Settings\Application Data\Mozilla\Firefox\Profiles\gygvqas6.default\Cache\0\CF\3BF27d01
2012-03-24 23:08 . 2012-03-24 23:08   17986   ----a-w-   c:\documents and settings\customer1\Local Settings\Application Data\Mozilla\Firefox\Profiles\gygvqas6.default\Cache\0\B0\5D861d01
2012-03-24 23:08 . 2012-03-24 23:08   30194   ----a-w-   c:\documents and settings\customer1\Local Settings\Application Data\Mozilla\Firefox\Profiles\gygvqas6.default\Cache\2\2D\7C45Fd01
2012-03-24 23:08 . 2012-03-24 23:08   19917   ----a-w-   c:\documents and settings\customer1\Local Settings\Application Data\Mozilla\Firefox\Profiles\gygvqas6.default\Cache\E\71\BC477d01
2012-03-24 23:08 . 2012-03-24 23:08   18287   ----a-w-   c:\documents and settings\customer1\Local Settings\Application Data\Mozilla\Firefox\Profiles\gygvqas6.default\Cache\F\C7\EC131d01
2012-03-24 23:07 . 2012-03-24 23:07   20681   ----a-w-   c:\documents and settings\customer1\Local Settings\Application Data\Mozilla\Firefox\Profiles\gygvqas6.default\Cache\A\2D\660D6d01
2012-03-24 23:07 . 2012-03-24 23:07   19406   ----a-w-   c:\documents and settings\customer1\Local Settings\Application Data\Mozilla\Firefox\Profiles\gygvqas6.default\Cache\7\B0\5562Ad01
2012-03-24 23:07 . 2012-03-24 23:07   24145   ----a-w-   c:\documents and settings\customer1\Local Settings\Application Data\Mozilla\Firefox\Profiles\gygvqas6.default\Cache\8\2C\3DA0Dd01
2012-03-24 23:07 . 2012-03-24 23:07   19406   ----a-w-   c:\documents and settings\customer1\Local Settings\Application Data\Mozilla\Firefox\Profiles\gygvqas6.default\Cache\3\23\23386d01
2012-03-24 23:07 . 2012-03-24 23:07   22047   ----a-w-   c:\documents and settings\customer1\Local Settings\Application Data\Mozilla\Firefox\Profiles\gygvqas6.default\Cache\D\12\8769Bd01
2012-03-24 23:07 . 2012-03-24 23:07   21214   ----a-w-   c:\documents and settings\customer1\Local Settings\Application Data\Mozilla\Firefox\Profiles\gygvqas6.default\Cache\F\7F\273C0d01
2012-03-24 23:07 . 2012-03-24 23:07   18396   ----a-w-   c:\documents and settings\customer1\Local Settings\Application Data\Mozilla\Firefox\Profiles\gygvqas6.default\Cache\1\0F\69BA3d01
2012-03-24 23:07 . 2012-03-24 23:07   19074   ----a-w-   c:\documents and settings\customer1\Local Settings\Application Data\Mozilla\Firefox\Profiles\gygvqas6.default\Cache\0\4D\365D6d01
2012-03-24 23:07 . 2012-03-24 23:07   26112   ----a-w-   c:\documents and settings\customer1\Local Settings\Application Data\Mozilla\Firefox\Profiles\gygvqas6.default\Cache\7\0A\8A17Cd01
2012-03-24 23:07 . 2012-03-24 23:07   19948   ----a-w-   c:\documents and settings\customer1\Local Settings\Application Data\Mozilla\Firefox\Profiles\gygvqas6.default\Cache\5\9B\F95EFd01
2012-03-24 23:07 . 2012-03-24 23:07   27868   ----a-w-   c:\documents and settings\customer1\Local Settings\Application Data\Mozilla\Firefox\Profiles\gygvqas6.default\Cache\0\97\313AAd01
2012-03-24 23:07 . 2012-03-24 23:07   211536   ----a-w-   c:\documents and settings\customer1\Local Settings\Application Data\Mozilla\Firefox\Profiles\gygvqas6.default\Cache\E\5F\DBA5Cd01
2012-03-24 23:07 . 2012-03-24 23:07   19837   ----a-w-   c:\documents and settings\customer1\Local Settings\Application Data\Mozilla\Firefox\Profiles\gygvqas6.default\Cache\6\24\C739Bd01
2012-03-24 23:07 . 2012-03-24 23:07   16897   ----a-w-   c:\documents and settings\customer1\Local Settings\Application Data\Mozilla\Firefox\Profiles\gygvqas6.default\Cache\5\65\63701d01
2012-03-24 23:07 . 2012-03-24 23:07   31012   ----a-w-   c:\documents and settings\customer1\Local Settings\Application Data\Mozilla\Firefox\Profiles\gygvqas6.default\Cache\3\4E\2A15Cd01
2012-03-24 23:07 . 2012-03-24 23:07   24636   ----a-w-   c:\documents and settings\customer1\Local Settings\Application Data\Mozilla\Firefox\Profiles\gygvqas6.default\Cache\C\22\57105d01
2012-03-24 23:07 . 2012-03-24 23:07   43715   ----a-w-   c:\documents and settings\customer1\Local Settings\Application Data\Mozilla\Firefox\Profiles\gygvqas6.default\Cache\9\C0\DCFF6d01
2012-03-24 23:07 . 2012-03-24 23:07   23863   ----a-w-   c:\documents and settings\customer1\Local Settings\Application Data\Mozilla\Firefox\Profiles\gygvqas6.default\Cache\6\38\BFA98d01
2012-03-24 23:07 . 2012-03-24 23:07   25024   ----a-w-   c:\documents and settings\customer1\Local Settings\Application Data\Mozilla\Firefox\Profiles\gygvqas6.default\Cache\6\42\D38E4d01
2012-03-24 23:07 . 2012-03-24 23:07   125098   ----a-w-   c:\documents and settings\customer1\Local Settings\Application Data\Mozilla\Firefox\Profiles\gygvqas6.default\Cache\F\5A\D0DC4d01
2012-03-24 23:07 . 2012-03-24 23:07   20648   ----a-w-   c:\documents and settings\customer1\Local Settings\Application Data\Mozilla\Firefox\Profiles\gygvqas6.default\Cache\A\6A\5702Cd01
2012-03-24 23:07 . 2012-03-24 23:07   28693   ----a-w-   c:\documents and settings\customer1\Local Settings\Application Data\Mozilla\Firefox\Profiles\gygvqas6.default\Cache\B\5D\44ADFd01
2012-03-24 23:07 . 2012-03-24 23:07   58814   ----a-w-   c:\documents and settings\customer1\Local Settings\Application Data\Mozilla\Firefox\Profiles\gygvqas6.default\Cache\4\67\A4532d01
2012-03-24 22:37 . 2012-03-24 23:08   864304   ----a-w-   c:\documents and settings\customer1\Local Settings\Application Data\Mozilla\Firefox\Profiles\gygvqas6.default\startupCache\startupCache.4.little
2012-03-24 22:34 . 2012-03-24 22:34   276   ----a-w-   c:\documents and settings\customer1\Application Data\Mozilla\Firefox\Profiles\gygvqas6.default\extensions.ini
2012-03-24 22:34 . 2012-03-24 23:26   484522   ----a-w-   c:\documents and settings\customer1\Application Data\Mozilla\Firefox\Profiles\gygvqas6.default\sessionstore.bak
2012-03-24 22:01 . 2012-03-24 22:01   368   ----a-w-   c:\documents and settings\customer1\Cookies\C97P26DM.txt
2012-03-24 22:00 . 2012-03-24 22:00   24547   ----a-w-   c:\documents and settings\customer1\Local Settings\Application Data\Mozilla\Firefox\Profiles\gygvqas6.default\Cache\8\4B\43F26d01
2012-03-24 21:59 . 2012-03-24 21:59   1048576   ----a-w-   c:\documents and settings\customer1\Local Settings\Application Data\Mozilla\Firefox\Profiles\gygvqas6.default\Cache\5\DD\DA402d01
2012-03-24 21:58 . 2012-03-24 21:58   33387   ----a-w-   c:\documents and settings\customer1\Local Settings\Application Data\Mozilla\Firefox\Profiles\gygvqas6.default\Cache\4\AA\47C52d01
2012-03-24 21:58 . 2012-03-24 21:58   17100   ----a-w-   c:\documents and settings\customer1\Local Settings\Application Data\Mozilla\Firefox\Profiles\gygvqas6.default\Cache\9\3D\131B2d01
2012-03-24 21:58 . 2012-03-24 21:58   25616   ----a-w-   c:\documents and settings\customer1\Local Settings\Application Data\Mozilla\Firefox\Profiles\gygvqas6.default\Cache\D\41\E4F39d01
2012-03-24 21:57 . 2012-03-24 21:57   16852   ----a-w-   c:\documents and settings\customer1\Local Settings\Application Data\Mozilla\Firefox\Profiles\gygvqas6.default\Cache\C\7E\66F26d01
2012-03-24 21:57 . 2012-03-24 21:57   63169   ----a-w-   c:\documents and settings\customer1\Local Settings\Application Data\Mozilla\Firefox\Profiles\gygvqas6.default\Cache\6\C9\931C8d01
2012-03-24 21:57 . 2012-03-24 21:57   19681   ----a-w-   c:\documents and settings\customer1\Local Settings\Application Data\Mozilla\Firefox\Profiles\gygvqas6.default\Cache\F\8D\6C9EEd01
2012-03-24 21:57 . 2012-03-24 21:57   21530   ----a-w-   c:\documents and settings\customer1\Local Settings\Application Data\Mozilla\Firefox\Profiles\gygvqas6.default\Cache\E\7D\AB69Dd01
2012-03-24 21:56 . 2012-03-24 21:56   45914   ----a-w-   c:\documents and settings\customer1\Local Settings\Application Data\Mozilla\Firefox\Profiles\gygvqas6.default\Cache\C\F3\6E4DFd01
2012-03-24 21:56 . 2012-03-24 21:56   20540   ----a-w-   c:\documents and settings\customer1\Local Settings\Application Data\Mozilla\Firefox\Profiles\gygvqas6.default\Cache\8\D6\4F027d01
2012-03-24 21:56 . 2012-03-24 21:56   28586   ----a-w-   c:\documents and settings\customer1\Local Settings\Application Data\Mozilla\Firefox\Profiles\gygvqas6.default\Cache\8\5E\553CEd01
2012-03-24 21:56 . 2012-03-24 21:56   20021   ----a-w-   c:\documents and settings\customer1\Local Settings\Application Data\Mozilla\Firefox\Profiles\gygvqas6.default\Cache\9\2F\ACF3Dd01
2012-03-24 21:54 . 2012-03-24 21:54   22748   ----a-w-   c:\documents and settings\customer1\Local Settings\Application Data\Mozilla\Firefox\Profiles\gygvqas6.default\Cache\B\04\45CAAd01
2012-03-24 21:54 . 2012-03-24 21:54   22656   ----a-w-   c:\documents and settings\customer1\Local Settings\Application Data\Mozilla\Firefox\Profiles\gygvqas6.default\Cache\4\5E\66992d01
2012-03-24 21:54 . 2012-03-24 21:54   28881   ----a-w-   c:\documents and settings\customer1\Local Settings\Application Data\Mozilla\Firefox\Profiles\gygvqas6.default\Cache\1\B5\1F753d01
2012-03-24 21:54 . 2012-03-24 21:54   25163   ----a-w-   c:\documents and settings\customer1\Local Settings\Application Data\Mozilla\Firefox\Profiles\gygvqas6.default\Cache\4\F3\FDC3Ad01
2012-03-24 21:54 . 2012-03-24 21:54   27734   ----a-w-   c:\documents and settings\customer1\Local Settings\Application Data\Mozilla\Firefox\Profiles\gygvqas6.default\Cache\C\90\01F22d01
2012-03-24 21:54 . 2012-03-24 21:54   25645   ----a-w-   c:\documents and settings\customer1\Local Settings\Application Data\Mozilla\Firefox\Profiles\gygvqas6.default\Cache\8\06\9861Fd01
2012-03-24 21:54 . 2012-03-24 21:54   28104   ----a-w-   c:\documents and settings\customer1\Local Settings\Application Data\Mozilla\Firefox\Profiles\gygvqas6.default\Cache\B\D2\B1F6Fd01
2012-03-24 21:51 . 2012-03-24 21:51   62076   ----a-w-   c:\documents and settings\customer1\Local Settings\Application Data\Mozilla\Firefox\Profiles\gygvqas6.default\Cache\0\E1\893E3d01
2012-03-24 21:51 . 2012-03-24 21:51   29957   ----a-w-   c:\documents and settings\customer1\Local Settings\Application Data\Mozilla\Firefox\Profiles\gygvqas6.default\Cache\5\B7\708FFd01
2012-03-24 21:51 . 2012-03-24 21:51   18394   ----a-w-   c:\documents and settings\customer1\Local Settings\Application Data\Mozilla\Firefox\Profiles\gygvqas6.default\Cache\3\78\A481Bd01
2012-03-24 21:51 . 2012-03-24 21:51   18674   ----a-w-   c:\documents and settings\customer1\Local Settings\Application Data\Mozilla\Firefox\Profiles\gygvqas6.default\Cache\2\28\0F969d01
2012-03-24 21:51 . 2012-03-24 21:51   19475   ----a-w-   c:\documents and settings\customer1\Local Settings\Application Data\Mozilla\Firefox\Profiles\gygvqas6.default\Cache\1\26\1ED1Bd01
2012-03-24 21:51 . 2012-03-24 21:51   17459   ----a-w-   c:\documents and settings\customer1\Local Settings\Application Data\Mozilla\Firefox\Profiles\gygvqas6.default\Cache\C\42\36F0Bd01
2012-03-24 21:50 . 2012-03-24 21:50   20128   ----a-w-   c:\documents and settings\customer1\Local Settings\Application Data\Mozilla\Firefox\Profiles\gygvqas6.default\Cache\4\42\52970d01
2012-03-24 21:50 . 2012-03-24 21:50   32794   ----a-w-   c:\documents and settings\customer1\Local Settings\Application Data\Mozilla\Firefox\Profiles\gygvqas6.default\Cache\1\04\B4E47d01
2012-03-24 21:50 . 2012-03-24 21:50   19108   ----a-w-   c:\documents and settings\customer1\Local Settings\Application Data\Mozilla\Firefox\Profiles\gygvqas6.default\Cache\4\B2\BF2BCd01
2012-03-24 21:50 . 2012-03-24 21:50   19296   ----a-w-   c:\documents and settings\customer1\Local Settings\Application Data\Mozilla\Firefox\Profiles\gygvqas6.default\Cache\5\2E\3E853d01
2012-03-24 21:50 . 2012-03-24 21:50   17831   ----a-w-   c:\documents and settings\customer1\Local Settings\Application Data\Mozilla\Firefox\Profiles\gygvqas6.default\Cache\3\85\C3633d01
2012-03-24 21:50 . 2012-03-24 21:50   85434   ----a-w-   c:\documents and settings\customer1\Local Settings\Application Data\Mozilla\Firefox\Profiles\gygvqas6.default\Cache\D\59\57123d01
2012-03-24 21:50 . 2012-03-24 21:50   48156   ----a-w-   c:\documents and settings\customer1\Local Settings\Application Data\Mozilla\Firefox\Profiles\gygvqas6.default\Cache\A\90\A3E76d01
2012-03-24 21:50 . 2012-03-24 21:50   39769   ----a-w-   c:\documents and settings\customer1\Local Settings\Application Data\Mozilla\Firefox\Profiles\gygvqas6.default\Cache\3\B7\4A533d01
2012-03-24 21:50 . 2012-03-24 21:50   57339   ----a-w-   c:\documents and settings\customer1\Local Settings\Application Data\Mozilla\Firefox\Profiles\gygvqas6.default\Cache\0\7E\DEEF2d01
2012-03-24 21:50 . 2012-03-24 21:50   65509   ----a-w-   c:\documents and settings\customer1\Local Settings\Application Data\Mozilla\Firefox\Profiles\gygvqas6.default\Cache\9\F2\61DA0d01
2012-03-24 21:50 . 2012-03-24 21:50   19986   ----a-w-   c:\documents and settings\customer1\Local Settings\Application Data\Mozilla\Firefox\Profiles\gygvqas6.default\Cache\1\69\06895d01
2012-03-24 21:50 . 2012-03-24 21:50   24991   ----a-w-   c:\documents and settings\customer1\Local Settings\Application Data\Mozilla\Firefox\Profiles\gygvqas6.default\Cache\1\0B\43B0Ad01
2012-03-24 21:50 . 2012-03-24 21:50   20555   ----a-w-   c:\documents and settings\customer1\Local Settings\Application Data\Mozilla\Firefox\Profiles\gygvqas6.default\Cache\5\EE\2D45Ed01
2012-03-24 21:50 . 2012-03-24 21:50   19613   ----a-w-   c:\documents and settings\customer1\Local Settings\Application Data\Mozilla\Firefox\Profiles\gygvqas6.default\Cache\1\C7\FBE58d01
2012-03-24 21:50 . 2012-03-24 21:50   19828   ----a-w-   c:\documents and settings\customer1\Local Settings\Application Data\Mozilla\Firefox\Profiles\gygvqas6.default\Cache\0\FF\1E3CFd01
2012-03-24 21:50 . 2012-03-24 21:50   57202   ----a-w-   c:\documents and settings\customer1\Local Settings\Application Data\Mozilla\Firefox\Profiles\gygvqas6.default\Cache\6\03\6BF7Ad01
2012-03-24 21:50 . 2012-03-24 21:50   24553   ----a-w-   c:\documents and settings\customer1\Local Settings\Application Data\Mozilla\Firefox\Profiles\gygvqas6.default\Cache\B\01\5473Fd01
2012-03-24 21:50 . 2012-03-24 21:50   90776   ----a-w-   c:\documents and settings\customer1\Local Settings\Application Data\Mozilla\Firefox\Profiles\gygvqas6.default\Cache\3\C3\B5D50d01
2012-03-24 21:50 . 2012-03-24 21:50   24605   ----a-w-   c:\documents and settings\customer1\Local Settings\Application Data\Mozilla\Firefox\Profiles\gygvqas6.default\Cache\C\E6\E2E3Ad01
2012-03-24 21:38 . 2012-03-24 21:38   56933   ----a-w-   c:\documents and settings\customer1\Local Settings\Application Data\Mozilla\Firefox\Profiles\gygvqas6.default\Cache\4\B3\404ACd01
2012-03-24 21:38 . 2012-03-24 21:38   60538   ----a-w-   c:\documents and settings\customer1\Local Settings\Application Data\Mozilla\Firefox\Profiles\gygvqas6.default\Cache\1\04\39931d01
2012-03-24 21:38 . 2012-03-24 21:38   20247   ----a-w-   c:\documents and settings\customer1\Local Settings\Application Data\Mozilla\Firefox\Profiles\gygvqas6.default\Cache\D\4B\D487Cd01
2012-03-24 21:37 . 2012-03-24 21:37   49348   ----a-w-   c:\documents and settings\customer1\Local Settings\Application Data\Mozilla\Firefox\Profiles\gygvqas6.default\Cache\F\B1\048CFd01
2012-03-24 21:37 . 2012-03-24 21:37   19104   ----a-w-   c:\documents and settings\customer1\Local Settings\Application Data\Mozilla\Firefox\Profiles\gygvqas6.default\Cache\D\D7\4692Ed01
2012-03-24 21:36 . 2012-03-24 21:36   17853   ----a-w-   c:\documents and settings\customer1\Local Settings\Application Data\Mozilla\Firefox\Profiles\gygvqas6.default\Cache\F\FA\2C1E0d01
2012-03-24 21:36 . 2012-03-24 21:36   23306   ----a-w-   c:\documents and settings\customer1\Local Settings\Application Data\Mozilla\Firefox\Profiles\gygvqas6.default\Cache\D\2B\4FD3Bd01
2012-03-24 21:36 . 2012-03-24 21:36   41471   ----a-w-   c:\documents and settings\customer1\Local Settings\Application Data\Mozilla\Firefox\Profiles\gygvqas6.default\Cache\B\C9\646C3d01
2012-03-24 21:36 . 2012-03-24 21:36   22206   ----a-w-   c:\documents and settings\customer1\Local Settings\Application Data\Mozilla\Firefox\Profiles\gygvqas6.default\Cache\5\42\717DFd01
2012-03-24 21:36 . 2012-03-24 21:36   19045   ----a-w-   c:\documents and settings\customer1\Local Settings\Application Data\Mozilla\Firefox\Profiles\gygvqas6.default\Cache\3\A5\4EE1Ad01
2012-03-24 21:36 . 2012-03-24 21:36   27035   ----a-w-   c:\documents and settings\customer1\Local Settings\Application Data\Mozilla\Firefox\Profiles\gygvqas6.default\Cache\E\8C\6F89Ed01
2012-03-24 21:36 . 2012-03-24 21:36   41874   ----a-w-   c:\documents and settings\customer1\Local Settings\Application Data\Mozilla\Firefox\Profiles\gygvqas6.default\Cache\5\28\EE132d01
2012-03-24 21:35 . 2012-03-24 21:35   65033   ----a-w-   c:\documents and settings\customer1\Local Settings\Application Data\Mozilla\Firefox\Profiles\gygvqas6.default\Cache\F\5F\C3F3Dd01
2012-03-24 21:35 . 2012-03-24 21:35   46531   ----a-w-   c:\documents and settings\customer1\Local Settings\Application Data\Mozilla\Firefox\Profiles\gygvqas6.default\Cache\9\DD\6EB14d01
2012-03-24 21:35 . 2012-03-24 21:35   29603   ----a-w-   c:\documents and settings\customer1\Local Settings\Application Data\Mozilla\Firefox\Profiles\gygvqas6.default\Cache\0\95\2E9D7d01
2012-03-24 21:35 . 2012-03-24 21:35   33184   ----a-w-   c:\documents and settings\customer1\Local Settings\Application Data\Mozilla\Firefox\Profiles\gygvqas6.default\Cache\8\6B\48755d01
2012-03-24 21:35 . 2012-03-24 21:35   18704   ----a-w-   c:\documents and settings\customer1\Local Settings\Application Data\Mozilla\Firefox\Profiles\gygvqas6.default\Cache\3\24\66CADd01
2012-03-24 21:35 . 2012-03-24 21:35   16544   ----a-w-   c:\documents and settings\customer1\Local Settings\Application Data\Mozilla\Firefox\Profiles\gygvqas6.default\Cache\E\9D\35BFEd01
2012-03-24 21:35 . 2012-03-24 21:35   58326   ----a-w-   c:\documents and settings\customer1\Local Settings\Application Data\Mozilla\Firefox\Profiles\gygvqas6.default\Cache\1\71\EE4A2d01
2012-03-24 21:35 . 2012-03-24 21:35   25562   ----a-w-   c:\documents and settings\customer1\Local Settings\Application Data\Mozilla\Firefox\Profiles\gygvqas6.default\Cache\0\42\E05C3d01
2012-03-24 21:35 . 2012-03-24 21:35   20606   ----a-w-   c:\documents and settings\customer1\Local Settings\Application Data\Mozilla\Firefox\Profiles\gygvqas6.default\Cache\F\52\FBE63d01
2012-03-24 21:35 . 2012-03-24 21:35   91768   ----a-w-   c:\documents and settings\customer1\Local Settings\Application Data\Mozilla\Firefox\Profiles\gygvqas6.default\Cache\4\12\B1002d01
2012-03-24 21:35 . 2012-03-24 21:35   24296   ----a-w-   c:\documents and settings\customer1\Local Settings\Application Data\Mozilla\Firefox\Profiles\gygvqas6.default\Cache\E\50\1E799d01
2012-03-24 21:35 . 2012-03-24 21:35   21231   ----a-w-   c:\documents and settings\customer1\Local Settings\Application Data\Mozilla\Firefox\Profiles\gygvqas6.default\Cache\5\65\5DA31d01
2012-03-24 21:35 . 2012-03-24 21:35   35568   ----a-w-   c:\documents and settings\customer1\Local Settings\Application Data\Mozilla\Firefox\Profiles\gygvqas6.default\Cache\C\C3\33402d01
2012-03-24 21:35 . 2012-03-24 21:35   21547   ----a-w-   c:\documents and settings\customer1\Local Settings\Application Data\Mozilla\Firefox\Profiles\gygvqas6.default\Cache\F\1D\9FCF8d01
2012-03-24 21:35 . 2012-03-24 21:35   26679   ----a-w-   c:\documents and settings\customer1\Local Settings\Application Data\Mozilla\Firefox\Profiles\gygvqas6.default\Cache\9\84\E8D5Ad01
2012-03-24 21:35 . 2012-03-24 21:35   20794   ----a-w-   c:\documents and settings\customer1\Local Settings\Application Data\Mozilla\Firefox\Profiles\gygvqas6.default\Cache\4\C8\8F946d01
2012-03-24 21:35 . 2012-03-24 21:35   17248   ----a-w-   c:\documents and settings\customer1\Local Settings\Application Data\Mozilla\Firefox\Profiles\gygvqas6.default\Cache\C\4F\182A1d01
2012-03-24 21:35 . 2012-03-24 21:35   57272   ----a-w-   c:\documents and settings\customer1\Local Settings\Application Data\Mozilla\Firefox\Profiles\gygvqas6.default\Cache\7\9C\2156Ed01
2012-03-24 21:35 . 2012-03-24 21:35   36838   ----a-w-   c:\documents and settings\customer1\Local Settings\Application Data\Mozilla\Firefox\Profiles\gygvqas6.default\Cache\7\AC\BB7C3d01
2012-03-24 21:35 . 2012-03-24 21:35   25440   ----a-w-   c:\documents and settings\customer1\Local Settings\Application Data\Mozilla\Firefox\Profiles\gygvqas6.default\Cache\B\8D\473D0d01
2012-03-24 21:35 . 2012-03-24 21:35   34729   ----a-w-   c:\documents and settings\customer1\Local Settings\Application Data\Mozilla\Firefox\Profiles\gygvqas6.default\Cache\A\02\3945Cd01
2012-03-24 21:35 . 2012-03-24 21:35   26992   ----a-w-   c:\documents and settings\customer1\Local Settings\Application Data\Mozilla\Firefox\Profiles\gygvqas6.default\Cache\9\CC\0DD22d01
2012-03-24 21:35 . 2012-03-24 21:35   109173   ----a-w-   c:\documents and settings\customer1\Local Settings\Application Data\Mozilla\Firefox\Profiles\gygvqas6.default\Cache\B\D8\5EC99d01
2012-03-24 21:34 . 2012-03-24 21:34   17970   ----a-w-   c:\documents and settings\customer1\Local Settings\Application Data\Mozilla\Firefox\Profiles\gygvqas6.default\Cache\6\29\6C002d01
2012-03-24 21:34 . 2012-03-24 21:34   16922   ----a-w-   c:\documents and settings\customer1\Local Settings\Application Data\Mozilla\Firefox\Profiles\gygvqas6.default\Cache\A\EA\63AC8d01
2012-03-24 21:34 . 2012-03-24 21:34   21491   ----a-w-   c:\documents and settings\customer1\Local Settings\Application Data\Mozilla\Firefox\Profiles\gygvqas6.default\Cache\F\69\D1A94d01
2012-03-24 21:34 . 2012-03-24 21:34   18283   ----a-w-   c:\documents and settings\customer1\Local Settings\Application Data\Mozilla\Firefox\Profiles\gygvqas6.default\Cache\1\A4\5B4C3d01
2012-03-24 21:33 . 2012-03-24 21:33   29570   ----a-w-   c:\documents and settings\customer1\Local Settings\Application Data\Mozilla\Firefox\Profiles\gygvqas6.default\Cache\8\A1\D3459d01
2012-03-24 21:33 . 2012-03-24 21:33   22988   ----a-w-   c:\documents and settings\customer1\Local Settings\Application Data\Mozilla\Firefox\Profiles\gygvqas6.default\Cache\3\18\8A1C5d01
2012-03-24 21:32 . 2012-03-24 21:32   38881   ----a-w-   c:\documents and settings\customer1\Local Settings\Application Data\Mozilla\Firefox\Profiles\gygvqas6.default\Cache\5\BE\474B5d01
2012-03-24 21:32 . 2012-03-24 21:32   36527   ----a-w-   c:\documents and settings\customer1\Local Settings\Application Data\Mozilla\Firefox\Profiles\gygvqas6.default\Cache\B\D4\A4FAFd01
2012-03-24 21:32 . 2012-03-24 21:32   22946   ----a-w-   c:\documents and settings\customer1\Local Settings\Application Data\Mozilla\Firefox\Profiles\gygvqas6.default\Cache\6\3D\5AC27d01
2012-03-24 21:31 . 2012-03-24 21:31   24321   ----a-w-   c:\documents and settings\customer1\Local Settings\Application Data\Mozilla\Firefox\Profiles\gygvqas6.default\Cache\9\37\47A64d01
2012-03-24 21:31 . 2012-03-24 21:31   23214   ----a-w-   c:\documents and settings\customer1\Local Settings\Application Data\Mozilla\Firefox\Profiles\gygvqas6.default\Cache\6\C2\EFA31d01
2012-03-24 21:30 . 2012-03-24 21:30   23796   ----a-w-   c:\documents and settings\customer1\Local Settings\Application Data\Mozilla\Firefox\Profiles\gygvqas6.default\Cache\B\10\26240d01
2012-03-24 21:30 . 2012-03-24 21:30   39431   ----a-w-   c:\documents and settings\customer1\Local Settings\Application Data\Mozilla\Firefox\Profiles\gygvqas6.default\Cache\2\8B\F13DBd01
2012-03-24 21:30 . 2012-03-24 21:30   27528   ----a-w-   c:\documents and settings\customer1\Local Settings\Application Data\Mozilla\Firefox\Profiles\gygvqas6.default\Cache\F\E5\2A3F1d01
2012-03-24 21:30 . 2012-03-24 21:30   32154   ----a-w-   c:\documents and settings\customer1\Local Settings\Application Data\Mozilla\Firefox\Profiles\gygvqas6.default\Cache\A\4A\AD02Fd01
2012-03-24 21:30 . 2012-03-24 21:30   69793   ----a-w-   c:\documents and settings\customer1\Local Settings\Application Data\Mozilla\Firefox\Profiles\gygvqas6.default\Cache\0\8D\D3497d01
2012-03-24 21:30 . 2012-03-24 21:30   32472   ----a-w-   c:\documents and settings\customer1\Local Settings\Application Data\Mozilla\Firefox\Profiles\gygvqas6.default\Cache\8\13\A10A9d01
2012-03-24 21:30 . 2012-03-24 21:30   450938   ----a-w-   c:\documents and settings\customer1\Local Settings\Application Data\Mozilla\Firefox\Profiles\gygvqas6.default\Cache\1\06\9323Cd01
2012-03-24 21:30 . 2012-03-24 21:30   74323   ----a-w-   c:\documents and settings\customer1\Local Settings\Application Data\Mozilla\Firefox\Profiles\gygvqas6.default\Cache\F\DB\E0019d01
2012-03-24 21:30 . 2012-03-24 21:30   32472   ----a-w-   c:\documents and settings\customer1\Local Settings\Application Data\Mozilla\Firefox\Profiles\gygvqas6.default\Cache\F\AE\893BEd01
2012-03-24 21:30 . 2012-03-24 21:30   73507   ----a-w-   c:\documents and settings\customer1\Local Settings\Application Data\Mozilla\Firefox\Profiles\gygvqas6.default\Cache\5\79\2407Fd01
2012-03-24 21:30 . 2012-03-24 21:30   53109   ----a-w-   c:\documents and settings\customer1\Local Settings\Application Data\Mozilla\Firefox\Profiles\gygvqas6.default\Cache\E\4C\B88B8d01
2012-03-24 21:29 . 2012-03-24 21:29   34146   ----a-w-   c:\documents and settings\customer1\Local Settings\Application Data\Mozilla\Firefox\Profiles\gygvqas6.default\Cache\4\14\3C689d01
2012-03-24 21:29 . 2012-03-24 21:29   27052   ----a-w-   c:\documents and settings\customer1\Local Settings\Application Data\Mozilla\Firefox\Profiles\gygvqas6.default\Cache\D\85\7EEC4d01
2012-03-24 21:29 . 2012-03-24 21:29   42164   ----a-w-   c:\documents and settings\customer1\Local Settings\Application Data\Mozilla\Firefox\Profiles\gygvqas6.default\Cache\B\EA\13926d01
2012-03-24 21:28 . 2012-03-24 21:29   58432   ----a-w-   c:\documents and settings\customer1\Local Settings\Application Data\Mozilla\Firefox\Profiles\gygvqas6.default\Cache\A\05\001CEd01
2012-03-24 21:28 . 2012-03-24 21:28   21337   ----a-w-   c:\documents and settings\customer1\Local Settings\Application Data\Mozilla\Firefox\Profiles\gygvqas6.default\Cache\8\C1\1D7CFd01
2012-03-24 21:28 . 2012-03-24 21:28   18027   ----a-w-   c:\documents and settings\customer1\Local Settings\Application Data\Mozilla\Firefox\Profiles\gygvqas6.default\Cache\1\66\2D4BBd01
2012-03-24 21:28 . 2012-03-24 21:28   19580   ----a-w-   c:\documents and settings\customer1\Local Settings\Application Data\Mozilla\Firefox\Profiles\gygvqas6.default\Cache\3\9F\490F1d01
2012-03-24 21:28 . 2012-03-24 21:28   18876   ----a-w-   c:\documents and settings\customer1\Local Settings\Application Data\Mozilla\Firefox\Profiles\gygvqas6.default\Cache\A\C5\414ACd01
2012-03-24 20:58 . 2012-03-24 20:58   11828   ----a-w-   c:\documents and settings\customer1\Application Data\Mozilla\Firefox\Profiles\gygvqas6.default\bookmarkbackups\bookmarks-2012-03-24.json
2012-03-24 20:40 . 2012-03-24 20:40   65324   ----a-w-   c:\documents and settings\customer1\Local Settings\Application Data\Mozilla\Firefox\Profiles\gygvqas6.default\Cache\F\14\C0E85d01
2012-03-24 20:40 . 2012-03-24 20:43   8600439   ----a-w-   c:\documents and settings\customer1\Local Settings\Application Data\Mozilla\Firefox\Profiles\gygvqas6.default\Cache\7\A9\CF892d01
2012-03-24 20:40 . 2012-03-25 00:42   28322   ----a-w-   c:\documents and settings\customer1\Local Settings\Application Data\Mozilla\Firefox\Profiles\gygvqas6.default\Cache\4\29\7633Dd01
2012-03-24 20:38 . 2012-03-24 20:40   7118450   ----a-w-   c:\documents and settings\customer1\Local Settings\Application Data\Mozilla\Firefox\Profiles\gygvqas6.default\Cache\C\D4\9CA0Ad01
2012-03-24 20:35 . 2012-03-24 20:35   38498   ----a-w-   c:\documents and settings\customer1\Local Settings\Application Data\Mozilla\Firefox\Profiles\gygvqas6.default\Cache\C\5E\9F874d01
2012-03-24 20:35 . 2012-03-24 20:35   58449   ----a-w-   c:\documents and settings\customer1\Local Settings\Application Data\Mozilla\Firefox\Profiles\gygvqas6.default\Cache\E\41\4C47Ed01
2012-03-24 20:35 . 2012-03-24 20:35   21657   ----a-w-   c:\documents and settings\customer1\Local Settings\Application Data\Mozilla\Firefox\Profiles\gygvqas6.default\Cache\8\AD\2FB46d01
2012-03-24 20:34 . 2012-03-24 20:34   18717   ----a-w-   c:\documents and settings\customer1\Local Settings\Application Data\Mozilla\Firefox\Profiles\gygvqas6.default\Cache\D\68\90F50d01
2012-03-24 20:34 . 2012-03-24 20:41   7791510   ----a-w-   c:\documents and settings\customer1\Local Settings\Application Data\Mozilla\Firefox\Profiles\gygvqas6.default\Cache\4\D4\C861Cd01
2012-03-24 20:34 . 2012-03-24 20:34   44756   ----a-w-   c:\documents and settings\customer1\Local Settings\Application Data\Mozilla\Firefox\Profiles\gygvqas6.default\Cache\2\E4\958CCd01
2012-03-24 20:34 . 2012-03-24 20:34   19280   ----a-w-   c:\documents and settings\customer1\Local Settings\Application Data\Mozilla\Firefox\Profiles\gygvqas6.default\Cache\C\83\0F3B7d01
2012-03-24 20:34 . 2012-03-24 20:34   1048576   ----a-w-   c:\documents and settings\customer1\Local Settings\Application Data\Mozilla\Firefox\Profiles\gygvqas6.default\Cache\B\F7\6CA71d01
2012-03-24 20:34 . 2012-03-24 20:34   80465   ----a-w-   c:\documents and settings\customer1\Local Settings\Application Data\Mozilla\Firefox\Profiles\gygvqas6.default\Cache\6\D8\DB661d01
2012-03-24 20:34 . 2012-03-24 20:34   54994   ----a-w-   c:\documents and settings\customer1\Local Settings\Application Data\Mozilla\Firefox\Profiles\gygvqas6.default\Cache\7\5F\73298d01
2012-03-24 20:34 . 2012-03-24 20:34   251746   ----a-w-   c:\documents and settings\customer1\Local Settings\Application Data\Mozilla\Firefox\Profiles\gygvqas6.default\Cache\4\B5\C03FBd01

Offline kcrawhorn

  • Bronze Member
  • Posts: 126
Re: [In Progress B]AVG found Trojan Horse Crypt.ASHD
« Reply #11 on: March 29, 2012, 03:49:23 PM »
2012-03-24 20:34 . 2012-03-24 20:34   23557   ----a-w-   c:\documents and settings\customer1\Local Settings\Application Data\Mozilla\Firefox\Profiles\gygvqas6.default\Cache\A\59\99762d01
2012-03-24 20:34 . 2012-03-24 20:34   27104   ----a-w-   c:\documents and settings\customer1\Local Settings\Application Data\Mozilla\Firefox\Profiles\gygvqas6.default\Cache\9\59\24332d01
2012-03-24 20:34 . 2012-03-24 20:34   73762   ----a-w-   c:\documents and settings\customer1\Local Settings\Application Data\Mozilla\Firefox\Profiles\gygvqas6.default\Cache\3\CD\80C3Bd01
2012-03-24 20:34 . 2012-03-24 20:34   58206   ----a-w-   c:\documents and settings\customer1\Local Settings\Application Data\Mozilla\Firefox\Profiles\gygvqas6.default\Cache\B\CD\F8AEBd01
2012-03-24 20:34 . 2012-03-24 20:34   138462   ----a-w-   c:\documents and settings\customer1\Local Settings\Application Data\Mozilla\Firefox\Profiles\gygvqas6.default\Cache\4\B1\DDA14d01
2012-03-24 20:34 . 2012-03-24 20:34   17172   ----a-w-   c:\documents and settings\customer1\Local Settings\Application Data\Mozilla\Firefox\Profiles\gygvqas6.default\Cache\C\C5\12417d01
2012-03-24 20:34 . 2012-03-24 20:34   57757   ----a-w-   c:\documents and settings\customer1\Local Settings\Application Data\Mozilla\Firefox\Profiles\gygvqas6.default\Cache\8\68\EDBF4d01
2012-03-24 20:34 . 2012-03-24 20:34   19542   ----a-w-   c:\documents and settings\customer1\Local Settings\Application Data\Mozilla\Firefox\Profiles\gygvqas6.default\Cache\A\F3\57FA6d01
2012-03-24 20:34 . 2012-03-24 20:34   254066   ----a-w-   c:\documents and settings\customer1\Local Settings\Application Data\Mozilla\Firefox\Profiles\gygvqas6.default\Cache\5\57\44FC1d01
2012-03-24 20:34 . 2012-03-24 20:34   27400   ----a-w-   c:\documents and settings\customer1\Local Settings\Application Data\Mozilla\Firefox\Profiles\gygvqas6.default\Cache\6\B3\D98DCd01
2012-03-24 20:32 . 2012-03-24 20:32   17232   ----a-w-   c:\documents and settings\customer1\Local Settings\Application Data\Mozilla\Firefox\Profiles\gygvqas6.default\Cache\7\0D\C7A51d01
2012-03-24 20:32 . 2012-03-24 20:32   26987   ----a-w-   c:\documents and settings\customer1\Local Settings\Application Data\Mozilla\Firefox\Profiles\gygvqas6.default\Cache\E\B2\D7BA2d01
2012-03-24 20:32 . 2012-03-24 20:32   35081   ----a-w-   c:\documents and settings\customer1\Local Settings\Application Data\Mozilla\Firefox\Profiles\gygvqas6.default\Cache\D\4F\46B2Fd01
2012-03-24 20:32 . 2012-03-24 20:32   46564   ----a-w-   c:\documents and settings\customer1\Local Settings\Application Data\Mozilla\Firefox\Profiles\gygvqas6.default\Cache\4\06\ED7CFd01
2012-03-24 20:32 . 2012-03-24 20:32   43755   ----a-w-   c:\documents and settings\customer1\Local Settings\Application Data\Mozilla\Firefox\Profiles\gygvqas6.default\Cache\5\46\30E38d01
2012-03-24 20:32 . 2012-03-24 20:32   16416   ----a-w-   c:\documents and settings\customer1\Local Settings\Application Data\Mozilla\Firefox\Profiles\gygvqas6.default\Cache\3\5C\B3CA3d01
2012-03-24 20:32 . 2012-03-24 20:32   75957   ----a-w-   c:\documents and settings\customer1\Local Settings\Application Data\Mozilla\Firefox\Profiles\gygvqas6.default\Cache\6\53\692D3d01
2012-03-24 20:32 . 2012-03-24 20:32   17394   ----a-w-   c:\documents and settings\customer1\Local Settings\Application Data\Mozilla\Firefox\Profiles\gygvqas6.default\Cache\F\B2\8DC3Ad01
2012-03-24 20:32 . 2012-03-24 20:32   23661   ----a-w-   c:\documents and settings\customer1\Local Settings\Application Data\Mozilla\Firefox\Profiles\gygvqas6.default\Cache\3\82\30DC4d01
2012-03-24 20:32 . 2012-03-24 20:32   23524   ----a-w-   c:\documents and settings\customer1\Local Settings\Application Data\Mozilla\Firefox\Profiles\gygvqas6.default\Cache\9\A2\D02B9d01
2012-03-24 20:31 . 2012-03-24 20:31   50071   ----a-w-   c:\documents and settings\customer1\Local Settings\Application Data\Mozilla\Firefox\Profiles\gygvqas6.default\Cache\4\20\0926Cd01
2012-03-24 20:31 . 2012-03-24 20:31   22059   ----a-w-   c:\documents and settings\customer1\Local Settings\Application Data\Mozilla\Firefox\Profiles\gygvqas6.default\Cache\1\CE\009C9d01
2012-03-24 20:31 . 2012-03-24 20:31   97849   ----a-w-   c:\documents and settings\customer1\Local Settings\Application Data\Mozilla\Firefox\Profiles\gygvqas6.default\Cache\D\91\11F75d01
2012-03-24 20:31 . 2012-03-24 20:31   30173   ----a-w-   c:\documents and settings\customer1\Local Settings\Application Data\Mozilla\Firefox\Profiles\gygvqas6.default\Cache\4\34\AC5FAd01
2012-03-24 20:31 . 2012-03-24 20:31   27810   ----a-w-   c:\documents and settings\customer1\Local Settings\Application Data\Mozilla\Firefox\Profiles\gygvqas6.default\Cache\2\8A\EBB3Ed01
2012-03-24 20:31 . 2012-03-24 20:31   30173   ----a-w-   c:\documents and settings\customer1\Local Settings\Application Data\Mozilla\Firefox\Profiles\gygvqas6.default\Cache\F\3B\3D633d01
2012-03-24 20:30 . 2012-03-24 20:30   17394   ----a-w-   c:\documents and settings\customer1\Local Settings\Application Data\Mozilla\Firefox\Profiles\gygvqas6.default\Cache\1\06\B78EBd01
2012-03-24 20:30 . 2012-03-24 20:30   25180   ----a-w-   c:\documents and settings\customer1\Local Settings\Application Data\Mozilla\Firefox\Profiles\gygvqas6.default\Cache\9\FC\264A3d01
2012-03-24 20:30 . 2012-03-24 20:30   34491   ----a-w-   c:\documents and settings\customer1\Local Settings\Application Data\Mozilla\Firefox\Profiles\gygvqas6.default\Cache\0\9F\5FE40d01
2012-03-24 20:30 . 2012-03-24 20:30   50749   ----a-w-   c:\documents and settings\customer1\Local Settings\Application Data\Mozilla\Firefox\Profiles\gygvqas6.default\Cache\6\7A\C341Ed01
2012-03-24 20:30 . 2012-03-24 20:30   53958   ----a-w-   c:\documents and settings\customer1\Local Settings\Application Data\Mozilla\Firefox\Profiles\gygvqas6.default\Cache\7\60\990B2d01
2012-03-24 20:30 . 2012-03-24 20:30   23870   ----a-w-   c:\documents and settings\customer1\Local Settings\Application Data\Mozilla\Firefox\Profiles\gygvqas6.default\Cache\E\BD\7DF0Cd01
2012-03-24 20:30 . 2012-03-24 20:30   27291   ----a-w-   c:\documents and settings\customer1\Local Settings\Application Data\Mozilla\Firefox\Profiles\gygvqas6.default\Cache\F\B9\AF820d01
2012-03-24 20:30 . 2012-03-24 20:30   27291   ----a-w-   c:\documents and settings\customer1\Local Settings\Application Data\Mozilla\Firefox\Profiles\gygvqas6.default\Cache\9\2F\E9690d01
2012-03-24 20:30 . 2012-03-24 20:30   32111   ----a-w-   c:\documents and settings\customer1\Local Settings\Application Data\Mozilla\Firefox\Profiles\gygvqas6.default\Cache\6\C3\18724d01
2012-03-24 20:29 . 2012-03-24 20:30   410254   ----a-w-   c:\documents and settings\customer1\Local Settings\Application Data\Mozilla\Firefox\Profiles\gygvqas6.default\Cache\5\67\E521Cd01
2012-03-24 20:29 . 2012-03-24 20:30   56223   ----a-w-   c:\documents and settings\customer1\Local Settings\Application Data\Mozilla\Firefox\Profiles\gygvqas6.default\Cache\3\A1\A37D7d01
2012-03-24 20:29 . 2012-03-24 20:29   43526   ----a-w-   c:\documents and settings\customer1\Local Settings\Application Data\Mozilla\Firefox\Profiles\gygvqas6.default\Cache\8\48\F2765d01
2012-03-24 20:29 . 2012-03-24 20:29   20983   ----a-w-   c:\documents and settings\customer1\Local Settings\Application Data\Mozilla\Firefox\Profiles\gygvqas6.default\Cache\4\ED\CED04d01
2012-03-24 20:29 . 2012-03-24 20:29   78554   ----a-w-   c:\documents and settings\customer1\Local Settings\Application Data\Mozilla\Firefox\Profiles\gygvqas6.default\Cache\0\B0\CC995d01
2012-03-24 20:29 . 2012-03-24 22:00   191612   ----a-w-   c:\documents and settings\customer1\Local Settings\Application Data\Mozilla\Firefox\Profiles\gygvqas6.default\Cache\2\31\87467d01
2012-03-24 20:29 . 2012-03-24 20:29   25774   ----a-w-   c:\documents and settings\customer1\Local Settings\Application Data\Mozilla\Firefox\Profiles\gygvqas6.default\Cache\D\54\E3C65d01
2012-03-24 20:29 . 2012-03-24 20:29   22946   ----a-w-   c:\documents and settings\customer1\Local Settings\Application Data\Mozilla\Firefox\Profiles\gygvqas6.default\Cache\B\88\F0DA4d01
2012-03-24 20:29 . 2012-03-24 20:29   29096   ----a-w-   c:\documents and settings\customer1\Local Settings\Application Data\Mozilla\Firefox\Profiles\gygvqas6.default\Cache\4\92\3CE61d01
2012-03-24 20:29 . 2012-03-24 20:29   26524   ----a-w-   c:\documents and settings\customer1\Local Settings\Application Data\Mozilla\Firefox\Profiles\gygvqas6.default\Cache\9\CA\1C6C6d01
2012-03-24 20:29 . 2012-03-24 20:29   22293   ----a-w-   c:\documents and settings\customer1\Local Settings\Application Data\Mozilla\Firefox\Profiles\gygvqas6.default\Cache\0\69\9F748d01
2012-03-24 20:29 . 2012-03-25 00:32   1236866   ----a-w-   c:\documents and settings\customer1\Local Settings\Application Data\Mozilla\Firefox\Profiles\gygvqas6.default\urlclassifier.pset
2012-03-24 20:29 . 2012-03-25 00:43   131072   ----a-w-   c:\documents and settings\customer1\Application Data\Mozilla\Firefox\Profiles\gygvqas6.default\chromeappsstore.sqlite
2012-03-24 19:23 . 2012-03-24 19:23   1888   ----a-w-   c:\documents and settings\customer1\Application Data\Malwarebytes\Malwarebytes' Anti-Malware\Logs\mbam-log-2012-03-24 (13-10-03).txt
2012-03-24 18:22 . 2012-03-25 00:43   1307497   ----a-w-   c:\documents and settings\customer1\Local Settings\Application Data\Mozilla\Firefox\Profiles\gygvqas6.default\Cache\_CACHE_002_
2012-03-24 18:22 . 2012-03-25 00:43   4047762   ----a-w-   c:\documents and settings\customer1\Local Settings\Application Data\Mozilla\Firefox\Profiles\gygvqas6.default\Cache\_CACHE_003_
2012-03-24 18:22 . 2012-03-25 00:43   1037354   ----a-w-   c:\documents and settings\customer1\Local Settings\Application Data\Mozilla\Firefox\Profiles\gygvqas6.default\Cache\_CACHE_001_
2012-03-24 18:22 . 2012-03-25 00:43   65812   ----a-w-   c:\documents and settings\customer1\Local Settings\Application Data\Mozilla\Firefox\Profiles\gygvqas6.default\Cache\_CACHE_MAP_
2012-03-24 18:22 . 2012-03-24 18:22   15447   ----a-w-   c:\documents and settings\customer1\Application Data\Mozilla\Firefox\Profiles\gygvqas6.default\pluginreg.dat
2012-03-24 18:22 . 2012-03-24 18:22   425984   ----a-w-   c:\documents and settings\customer1\Application Data\Mozilla\Firefox\Profiles\gygvqas6.default\addons.sqlite
2012-03-24 18:22 . 2012-03-24 22:34   425984   ----a-w-   c:\documents and settings\customer1\Application Data\Mozilla\Firefox\Profiles\gygvqas6.default\extensions.sqlite
2012-03-24 18:22 . 2012-03-24 18:22   10   ----a-w-   c:\documents and settings\customer1\Application Data\Mozilla\Firefox\Crash Reports\InstallTime20120312181643
2012-03-24 18:21 . 2012-03-24 18:21   742   ----a-w-   c:\documents and settings\customer1\Application Data\Microsoft\Internet Explorer\Quick Launch\Mozilla Firefox.lnk
2012-03-24 18:19 . 2012-03-24 18:19   94113   --s-a-w-   c:\documents and settings\customer1\Application Data\Microsoft\CryptnetUrlCache\Content\12236C41CDDF9E40BA5606CDF086B821
2012-03-24 18:19 . 2012-03-24 18:19   114   --s-a-w-   c:\documents and settings\customer1\Application Data\Microsoft\CryptnetUrlCache\MetaData\12236C41CDDF9E40BA5606CDF086B821
2012-03-24 18:19 . 2012-03-24 18:19   500   --s-a-w-   c:\documents and settings\customer1\Application Data\Microsoft\CryptnetUrlCache\Content\8EDCF682921FE94F4A02A43CD1A28E6B
2012-03-24 18:19 . 2012-03-24 18:19   100   --s-a-w-   c:\documents and settings\customer1\Application Data\Microsoft\CryptnetUrlCache\MetaData\8EDCF682921FE94F4A02A43CD1A28E6B
2012-03-24 18:15 . 2012-03-24 18:15   16157992   ----a-w-   c:\documents and settings\customer1\My Documents\Firefox Setup 11.0.exe
2012-03-24 18:07 . 2012-03-24 18:07   802   ----a-w-   c:\documents and settings\customer1\Application Data\Microsoft\Internet Explorer\Quick Launch\Malwarebytes Anti-Malware.lnk
2012-03-24 17:48 . 2012-03-24 17:48   1447   ----a-w-   c:\documents and settings\customer1\Local Settings\Application Data\Apple Computer\QuickTime\downloads\06\08\68ccf1f2-edb0f1ea-277ddf93-6d60cbdb.qtch
2012-03-24 17:48 . 2012-03-24 17:49   3223541   ----a-w-   c:\documents and settings\customer1\Local Settings\Application Data\Apple Computer\QuickTime\downloads\06\07\67b0d4ea-e51d5749-137c19a0-f1546acb.qtch
2012-03-24 17:48 . 2012-03-24 17:48   133   ----a-w-   c:\documents and settings\customer1\Cookies\P02WMEST.txt
2012-03-24 17:46 . 2012-03-24 17:46   333   ----a-w-   c:\documents and settings\customer1\Cookies\XGZLEN2R.txt
2012-03-24 04:42 . 2012-03-24 04:42   10631   ----a-w-   c:\documents and settings\customer1\Application Data\Mozilla\Firefox\Profiles\gygvqas6.default\bookmarkbackups\bookmarks-2012-03-23.json
2012-03-24 03:33 . 2012-03-24 03:33   350   ----a-w-   c:\documents and settings\customer1\Cookies\TOZABF48.txt
2012-03-23 20:01 . 2012-03-23 20:01   294804   ----a-w-   c:\documents and settings\customer1\Local Settings\Temporary Internet Files\AntiPhishing\2CEDBFBC-DBA8-43AA-B1FD-CC8E6316E3E2.dat
2012-03-23 00:04 . 2012-03-23 00:04   1184   --s-a-w-   c:\documents and settings\customer1\Application Data\Microsoft\CryptnetUrlCache\Content\373AA1E44F5B933F81294FE7DF9AE44E
2012-03-23 00:04 . 2012-03-23 00:04   106   --s-a-w-   c:\documents and settings\customer1\Application Data\Microsoft\CryptnetUrlCache\MetaData\373AA1E44F5B933F81294FE7DF9AE44E
2012-03-22 22:45 . 2012-03-22 22:45   996   ----a-w-   c:\documents and settings\customer1\Cookies\LI43DP61.txt
2012-03-22 22:28 . 2012-03-22 22:28   133   ----a-w-   c:\documents and settings\customer1\Cookies\89TLA6SD.txt
2012-03-22 22:28 . 2012-03-22 22:28   348   ----a-w-   c:\documents and settings\customer1\Cookies\OKCXA7RO.txt
2012-03-19 14:58 . 2012-03-19 14:58   84   ----a-w-   c:\documents and settings\customer1\Cookies\OP52URPM.txt
2012-03-17 05:25 . 2012-03-17 05:25   12134   --sh--w-   c:\documents and settings\customer1\My Documents\My Music\Hollywood Undead\Swan Songs [Clean]\AlbumArt_{6098F471-DDDE-4BC2-9F2B-CA508A3BA642}_Large.jpg
2012-03-17 05:25 . 2012-03-17 05:25   12134   --sh--w-   c:\documents and settings\customer1\My Documents\My Music\Hollywood Undead\Swan Songs [Clean]\Folder.jpg
2012-03-17 05:25 . 2012-03-17 05:25   2887   --sh--w-   c:\documents and settings\customer1\My Documents\My Music\Hollywood Undead\Swan Songs [Clean]\AlbumArtSmall.jpg
2012-03-17 05:25 . 2012-03-17 05:25   2887   --sh--w-   c:\documents and settings\customer1\My Documents\My Music\Hollywood Undead\Swan Songs [Clean]\AlbumArt_{6098F471-DDDE-4BC2-9F2B-CA508A3BA642}_Small.jpg
2012-03-17 05:25 . 2012-03-17 05:25   359   --sh--w-   c:\documents and settings\customer1\My Documents\My Music\Hollywood Undead\desktop.ini
2012-03-17 05:25 . 2012-03-17 05:25   358   --sh--w-   c:\documents and settings\customer1\My Documents\My Music\Hollywood Undead\Swan Songs [Clean]\desktop.ini
2012-03-17 05:20 . 2012-03-17 05:25   6650   ----a-w-   c:\documents and settings\customer1\Application Data\Real\RealPlayer\WatchFolders\C__Documents and Settings_customer1_My Documents_My Music_scan.log
2012-03-17 05:20 . 2012-03-17 05:21   6740   ----a-w-   c:\documents and settings\customer1\Application Data\Real\RealPlayer\WatchFolders\C__Documents and Settings_customer1_My Documents_My Music_scan2.log
2012-03-17 05:20 . 2012-03-17 05:20   8275   --sh--w-   c:\documents and settings\customer1\My Documents\Songs burnt to cd\AlbumArt_{01FDAE7E-FAA6-41D6-AF9B-4B23CB304581}_Large.jpg
2012-03-17 05:20 . 2012-03-17 05:20   2268   --sh--w-   c:\documents and settings\customer1\My Documents\Songs burnt to cd\AlbumArt_{01FDAE7E-FAA6-41D6-AF9B-4B23CB304581}_Small.jpg
2012-03-17 05:20 . 2012-03-17 05:20   12180   --sh--w-   c:\documents and settings\customer1\My Documents\My Music\Fall Out Boy\Believers Never Die- The Greatest Hits Disc 1\AlbumArt_{A4F50E3D-ABCA-4A25-AE82-3C59E4698091}_Large.jpg
2012-03-17 05:20 . 2012-03-17 05:20   2587   --sh--w-   c:\documents and settings\customer1\My Documents\My Music\Fall Out Boy\Believers Never Die- The Greatest Hits Disc 1\AlbumArtSmall.jpg
2012-03-17 05:20 . 2012-03-17 05:20   2587   --sh--w-   c:\documents and settings\customer1\My Documents\My Music\Fall Out Boy\Believers Never Die- The Greatest Hits Disc 1\AlbumArt_{A4F50E3D-ABCA-4A25-AE82-3C59E4698091}_Small.jpg
2012-03-17 05:20 . 2012-03-17 05:20   12180   --sh--w-   c:\documents and settings\customer1\My Documents\My Music\Fall Out Boy\Believers Never Die- The Greatest Hits Disc 1\Folder.jpg
2012-03-17 05:20 . 2012-03-17 05:20   383   --sh--w-   c:\documents and settings\customer1\My Documents\My Music\Fall Out Boy\desktop.ini
2012-03-17 05:20 . 2012-03-17 05:20   382   --sh--w-   c:\documents and settings\customer1\My Documents\My Music\Fall Out Boy\Believers Never Die- The Greatest Hits Disc 1\desktop.ini
2012-03-17 05:20 . 2012-03-17 05:20   361   --sh--w-   c:\documents and settings\customer1\My Documents\My Music\Unknown Artist\Unknown Album (1-26-2010 3-16-17 PM)\desktop.ini
2012-03-17 05:20 . 2012-03-17 05:20   9569   --sh--w-   c:\documents and settings\customer1\My Documents\My Music\Unknown Artist\Unknown Album (1-26-2010 3-16-17 PM)\AlbumArt_{8434C6BC-AD8C-478E-8C5A-F34669574864}_Large.jpg
2012-03-17 05:20 . 2012-03-17 05:20   9569   --sh--w-   c:\documents and settings\customer1\My Documents\My Music\Unknown Artist\Unknown Album (1-26-2010 3-16-17 PM)\Folder.jpg
2012-03-17 05:20 . 2012-03-17 05:20   2439   --sh--w-   c:\documents and settings\customer1\My Documents\My Music\Unknown Artist\Unknown Album (1-26-2010 3-16-17 PM)\AlbumArt_{8434C6BC-AD8C-478E-8C5A-F34669574864}_Small.jpg
2012-03-17 05:20 . 2012-03-17 05:20   2439   --sh--w-   c:\documents and settings\customer1\My Documents\My Music\Unknown Artist\Unknown Album (1-26-2010 3-16-17 PM)\AlbumArtSmall.jpg
2012-03-17 05:18 . 2012-03-17 05:18   146   ----a-w-   c:\documents and settings\customer1\Cookies\QEH0VGO1.txt
2012-03-17 05:17 . 2012-03-17 05:17   371   ----a-w-   c:\documents and settings\customer1\Cookies\AIGYCGZT.txt
2012-03-17 02:27 . 2012-03-17 02:27   34972   ----a-w-   c:\documents and settings\customer1\Local Settings\Temporary Internet Files\Sqm\iesqmdata0.sqm
2012-03-17 02:15 . 2012-03-18 10:27   18009   ----a-w-   c:\documents and settings\customer1\Application Data\Macromedia\Shockwave Player\Shockwave Log
2012-03-17 01:49 . 2012-03-17 20:32   237   ----a-w-   c:\documents and settings\customer1\Local Settings\Application Data\Microsoft\Internet Explorer\DOMStore\1GD0ODTH\apps.facebook[1].xml
2012-03-13 20:11 . 2012-03-13 21:09   1544   ----a-w-   c:\documents and settings\customer1\Application Data\Skype\temp-xThTGw8BuZWcvBtLfgBLSL6l
2012-03-13 14:30 . 2012-03-13 14:30   10631   ----a-w-   c:\documents and settings\customer1\Application Data\Mozilla\Firefox\Profiles\gygvqas6.default\bookmarkbackups\bookmarks-2012-03-13.json
2012-03-13 13:18 . 2012-03-13 13:18   350   ----a-w-   c:\documents and settings\customer1\Cookies\SWRSWHJR.txt
2012-03-13 13:18 . 2012-03-13 13:18   106   ----a-w-   c:\documents and settings\customer1\Cookies\E6MU7N51.txt
2012-03-13 13:18 . 2012-03-13 13:18   363   ----a-w-   c:\documents and settings\customer1\Cookies\ZQE4EAQN.txt
2012-03-13 13:06 . 2012-03-13 13:06   492   ----a-w-   c:\documents and settings\customer1\Cookies\H6HRIT83.txt
2012-03-13 13:02 . 2012-03-13 13:02   95   ----a-w-   c:\documents and settings\customer1\Cookies\UIZ1LR3U.txt
2012-03-12 03:35 . 2012-03-26 18:10   84   ----a-w-   c:\documents and settings\customer1\Local Settings\Application Data\Microsoft\Internet Explorer\DOMStore\6FGOOPS5\movies.netflix[1].xml
2012-03-12 03:34 . 2012-03-12 03:34   13   ----a-w-   c:\documents and settings\customer1\Local Settings\Application Data\Microsoft\Internet Explorer\DOMStore\JA83JMQC\signup.netflix[1].xml
2012-03-11 14:27 . 2012-03-11 14:27   82   ----a-w-   c:\documents and settings\customer1\Cookies\V6B13668.txt
2012-03-10 17:33 . 2012-03-22 22:28   95   ----a-w-   c:\documents and settings\customer1\Local Settings\Application Data\Microsoft\Internet Explorer\DOMStore\1GD0ODTH\www.cattle[1].xml
2012-03-09 17:24 . 2012-03-09 17:24   176   ----a-w-   c:\documents and settings\customer1\Favorites\Links\Games - Sesame Street (2).url
2012-03-09 13:43 . 2012-03-09 13:43   13   ----a-w-   c:\documents and settings\customer1\Local Settings\Application Data\Microsoft\Internet Explorer\DOMStore\6FGOOPS5\icanbe.barbie[1].xml
2012-03-09 13:16 . 2012-03-09 13:16   48   ----a-w-   c:\documents and settings\customer1\Application Data\Microsoft\Office\Recent\www.google.com (2).url
2012-03-09 13:16 . 2012-03-09 13:16   59   ---h--w-   c:\documents and settings\customer1\Application Data\Microsoft\Office\Recent\index.dat
2012-03-09 13:16 . 2012-03-09 13:16   0   ----a-w-   c:\documents and settings\customer1\Local Settings\Temporary Internet Files\JZ0WINWP\3F3N73LN\Offline\e\00000039
2012-03-09 13:16 . 2012-03-09 13:16   500000   ----a-w-   c:\documents and settings\customer1\Local Settings\Temporary Internet Files\JZ0WINWP\3F3N73LN\Offline\0x00000003_R
2012-03-09 13:16 . 2012-03-09 13:16   100000   ----a-w-   c:\documents and settings\customer1\Local Settings\Temporary Internet Files\JZ0WINWP\3F3N73LN\Offline\0x00000001_R
2012-03-09 13:16 . 2012-03-09 13:16   102412   ----a-w-   c:\documents and settings\customer1\Local Settings\Temporary Internet Files\JZ0WINWP\3F3N73LN\Offline\HashFile.dat
2012-03-09 02:36 . 2012-03-09 02:36   13   ----a-w-   c:\documents and settings\customer1\Local Settings\Application Data\Microsoft\Internet Explorer\DOMStore\FFCO4NDM\www.facebook[1].xml
2012-03-09 01:48 . 2012-03-09 01:48   13   ----a-w-   c:\documents and settings\customer1\Local Settings\Application Data\Microsoft\Internet Explorer\DOMStore\1GD0ODTH\maps.google[1].xml
2012-03-09 01:32 . 2012-03-09 14:09   159   ----a-w-   c:\documents and settings\customer1\Local Settings\Application Data\Microsoft\Internet Explorer\DOMStore\JA83JMQC\www.google[1].xml
2012-03-09 01:23 . 2012-03-09 01:24   1544   ----a-w-   c:\documents and settings\customer1\Application Data\Skype\temp-Fd3LsbgPbHxy6r5g2ZC6e8ti
2012-03-09 01:23 . 2012-03-09 01:24   7168   ----a-w-   c:\documents and settings\customer1\Application Data\Skype\temp-H1L8b1QOZFtlCujzAlvb8RoS
2012-03-09 01:18 . 2012-03-09 01:18   67   --sh--w-   c:\documents and settings\customer1\Local Settings\Temporary Internet Files\desktop.ini
2012-03-07 11:41 . 2012-03-07 11:41   1124   --s-a-w-   c:\documents and settings\customer1\Application Data\Microsoft\CryptnetUrlCache\Content\ED7CF8F6DA57321AAC9580C26058483A
2012-03-07 11:41 . 2012-03-07 11:41   148   --s-a-w-   c:\documents and settings\customer1\Application Data\Microsoft\CryptnetUrlCache\MetaData\ED7CF8F6DA57321AAC9580C26058483A
2012-03-07 11:41 . 2012-03-09 01:22   7168   ----a-w-   c:\documents and settings\customer1\Application Data\Skype\temp-0qMmxUCt8zzLGEEuvHX3Q2bK
2012-03-07 11:41 . 2012-03-09 01:22   1544   ----a-w-   c:\documents and settings\customer1\Application Data\Skype\temp-wKgfVnbwZbeAMhWVKa6TdZAL
2012-03-05 16:56 . 2012-03-07 11:38   1544   ----a-w-   c:\documents and settings\customer1\Application Data\Skype\temp-XMPvXvtofjgkihFUR3IVu4Mc
2012-03-05 15:54 . 2012-03-05 15:54   9   ----a-w-   c:\documents and settings\customer1\Application Data\Winamp\Winamp.m3u
2012-03-05 15:54 . 2012-03-05 15:54   12   ----a-w-   c:\documents and settings\customer1\Application Data\Winamp\Winamp.m3u8
2012-03-02 23:25 . 2012-03-05 16:52   1544   ----a-w-   c:\documents and settings\customer1\Application Data\Skype\temp-JXQsCalmxW6PAMbq28hKs8y7
2012-03-02 00:58 . 2012-03-02 22:49   1544   ----a-w-   c:\documents and settings\customer1\Application Data\Skype\temp-8zSneJw3GhOhYYwAfWQZGxpf
2012-03-01 00:13 . 2012-03-01 00:13   555   ----a-w-   c:\documents and settings\customer1\Recent\RA_Whse_2011_Workout.lnk
2012-02-29 23:47 . 2012-03-02 00:55   1544   ----a-w-   c:\documents and settings\customer1\Application Data\Skype\temp-Xnl7FArgm4U01ZWy2Kqh0CIJ
2012-02-27 20:24 . 2012-02-27 20:24   1520   --s-a-w-   c:\documents and settings\customer1\Application Data\Microsoft\CryptnetUrlCache\Content\D1D88DE21ADA9AD70F84C0C44CF3BFE4
2012-02-27 20:24 . 2012-02-27 20:24   134   --s-a-w-   c:\documents and settings\customer1\Application Data\Microsoft\CryptnetUrlCache\MetaData\D1D88DE21ADA9AD70F84C0C44CF3BFE4
2012-02-25 14:17 . 2012-02-25 14:17   864   ----a-w-   c:\documents and settings\customer1\Recent\sam.lnk
2012-02-25 14:17 . 2012-02-25 14:17   888   ----a-w-   c:\documents and settings\customer1\Recent\brown31.lnk
2012-02-25 14:16 . 2012-02-25 14:16   888   ----a-w-   c:\documents and settings\customer1\Recent\brown30.lnk
2012-02-25 14:15 . 2012-02-25 14:15   888   ----a-w-   c:\documents and settings\customer1\Recent\brown29.lnk
2012-02-25 14:15 . 2012-02-25 14:15   888   ----a-w-   c:\documents and settings\customer1\Recent\brown28.lnk
2012-02-25 14:15 . 2012-02-25 14:15   888   ----a-w-   c:\documents and settings\customer1\Recent\brown27.lnk
2012-02-25 14:15 . 2012-02-25 14:15   888   ----a-w-   c:\documents and settings\customer1\Recent\brown26.lnk
2012-02-25 14:14 . 2012-02-25 14:14   888   ----a-w-   c:\documents and settings\customer1\Recent\brown25.lnk
2012-02-25 14:14 . 2012-02-25 14:14   888   ----a-w-   c:\documents and settings\customer1\Recent\brown24.lnk
2012-02-25 14:14 . 2012-02-25 14:14   888   ----a-w-   c:\documents and settings\customer1\Recent\brown23.lnk
2012-02-25 14:14 . 2012-02-25 14:14   888   ----a-w-   c:\documents and settings\customer1\Recent\brown22.lnk
2012-02-25 14:13 . 2012-02-25 14:13   888   ----a-w-   c:\documents and settings\customer1\Recent\brown21.lnk
2012-02-25 14:13 . 2012-02-25 14:17   246   ----a-w-   c:\documents and settings\customer1\Local Settings\Application Data\Microsoft\OIS\OIScatalog.cag
2012-02-25 14:13 . 2012-02-25 14:17   620   ----a-w-   c:\documents and settings\customer1\Recent\Sam Brown Pictures.lnk
2012-02-25 05:55 . 2012-02-29 23:44   1544   ----a-w-   c:\documents and settings\customer1\Application Data\Skype\temp-LALP4YmpaMJmLocYiaC62g9T
2012-02-25 05:42 . 2012-02-25 05:53   1544   ----a-w-   c:\documents and settings\customer1\Application Data\Skype\temp-EjTIgOtjO6qVtEi3TFPdDsZ9
2012-02-25 05:37 . 2012-02-25 05:37   1590   ----a-w-   c:\documents and settings\customer1\Application Data\AVG\Rescue\Program Manager\120224233739406.rsc
2012-02-25 05:36 . 2012-02-25 05:37   253896   ----a-w-   c:\documents and settings\customer1\Application Data\AVG\PC Tuneup\Logs\UninstallManager.log
2012-02-25 05:35 . 2012-02-25 05:35   727   ----a-w-   c:\documents and settings\customer1\Application Data\AVG\Rescue\Strartup Manager\120224233550890.rsc
2012-02-25 05:35 . 2012-02-25 05:35   789   ----a-w-   c:\documents and settings\customer1\Application Data\AVG\Rescue\Strartup Manager\120224233549953.rsc
2012-02-25 05:35 . 2012-02-25 05:36   12566   ----a-w-   c:\documents and settings\customer1\Application Data\AVG\PC Tuneup\Logs\StartupManager.log
2012-02-25 05:33 . 2012-02-25 05:33   20231   ----a-w-   c:\documents and settings\customer1\Application Data\AVG\Disk Defrag\Reports\Disk_Defrag_Report.html
2012-02-25 05:33 . 2012-02-25 05:33   13445   ----a-w-   c:\documents and settings\customer1\Application Data\AVG\Disk Defrag\Reports\Disk_Defrag_Report.xml
2012-02-25 05:32 . 2012-02-25 05:32   660   ----a-w-   c:\documents and settings\customer1\Application Data\AVG\Rescue\Tweak Manager\120224233237312.rsc
2012-02-25 05:32 . 2012-02-25 05:32   35308   ----a-w-   c:\documents and settings\customer1\Application Data\AVG\PC Tuneup\Logs\TweakManager.log
2012-02-25 04:48 . 2012-02-25 04:48   653   ----a-w-   c:\documents and settings\customer1\Application Data\AVG\Rescue\PC Tuneup 2011\120224224842015.rsc
2012-02-25 04:48 . 2012-02-25 04:48   629   ----a-w-   c:\documents and settings\customer1\Application Data\AVG\Rescue\PC Tuneup 2011\120224224837687.rsc
2012-02-25 04:33 . 2012-02-25 04:35   296155493   ----a-w-   c:\documents and settings\customer1\Application Data\AVG\Rescue\PC Tuneup 2011\120224223314562.rsc
2012-02-25 04:33 . 2012-02-25 04:33   70963   ----a-w-   c:\documents and settings\customer1\Application Data\AVG\Rescue\PC Tuneup 2011\120224223307656.rsc
2012-02-25 04:32 . 2012-03-29 21:22   181258   ----a-w-   c:\documents and settings\customer1\Application Data\AVG\PC Tuneup\Logs\PC Tuneup_SN.log
2012-02-25 04:32 . 2012-03-29 21:22   151   ----a-w-   c:\documents and settings\customer1\Application Data\Real\RealPlayer\WatchFolders\C__Documents and Settings_customer1_Desktop_scan.log
2012-02-25 04:32 . 2012-03-29 21:06   151   ----a-w-   c:\documents and settings\customer1\Application Data\Real\RealPlayer\WatchFolders\C__Documents and Settings_customer1_Desktop_scan2.log
2012-02-25 04:31 . 2012-02-25 04:31   813   ----a-w-   c:\documents and settings\customer1\Application Data\Microsoft\Internet Explorer\Quick Launch\AVG PC Tuneup 2011.lnk
2012-02-25 04:28 . 2012-03-24 18:15   53043   ----a-w-   c:\documents and settings\customer1\Application Data\Real\RealPlayer\WatchFolders\C__Documents and Settings_customer1_My Documents_scan.log
2012-02-25 04:28 . 2012-03-24 18:10   53043   ----a-w-   c:\documents and settings\customer1\Application Data\Real\RealPlayer\WatchFolders\C__Documents and Settings_customer1_My Documents_scan2.log
2012-02-25 04:27 . 2012-02-25 04:30   8351056   ----a-w-   c:\documents and settings\customer1\My Documents\Downloads\avg_pct_stf_all_10_27_c5.exe
2012-02-25 04:27 . 2012-03-24 20:29   2048   ----a-w-   c:\documents and settings\customer1\Application Data\Mozilla\Firefox\Profiles\gygvqas6.default\downloads.sqlite
2012-02-25 04:24 . 2012-02-25 05:40   1544   ----a-w-   c:\documents and settings\customer1\Application Data\Skype\temp-GO9NLc5SKynSjANasqQgHQ29
2012-02-25 03:47 . 2012-02-25 03:47   67   --sh--w-   c:\documents and settings\customer1\Local Settings\Application Data\Microsoft\Feeds Cache\desktop.ini
2012-02-25 03:40 . 2012-02-25 03:40   150   --sha-w-   c:\documents and settings\customer1\Recent\Desktop.ini
2012-02-25 03:39 . 2012-03-29 21:00   16384   --sha-w-   c:\documents and settings\customer1\Local Settings\Application Data\Microsoft\Feeds Cache\index.dat
2012-02-25 03:35 . 2012-02-25 03:35   10631   ----a-w-   c:\documents and settings\customer1\Application Data\Mozilla\Firefox\Profiles\gygvqas6.default\bookmarkbackups\bookmarks-2012-02-24.json
2012-02-24 04:59 . 2012-02-25 04:21   1544   ----a-w-   c:\documents and settings\customer1\Application Data\Skype\temp-LGtWde5uU6bbzCCP7XUdaFlk
2012-02-22 02:29 . 2012-02-22 02:29   10631   ----a-w-   c:\documents and settings\customer1\Application Data\Mozilla\Firefox\Profiles\gygvqas6.default\bookmarkbackups\bookmarks-2012-02-21.json
2012-02-19 19:30 . 2012-02-19 19:41   3027   ----a-w-   c:\documents and settings\customer1\Application Data\Skype\bmurphy1954\chatsync\b1\b1ea65c7d68bcaae.dat
2012-02-19 18:18 . 2012-02-19 19:30   3290   ----a-w-   c:\documents and settings\customer1\Application Data\Skype\bmurphy1954\chatsync\bf\bf78efed89ff476c.dat
2012-02-18 21:56 . 2012-02-18 21:56   993   --s-a-w-   c:\documents and settings\customer1\Application Data\Microsoft\CryptnetUrlCache\Content\A4CB310CBB8B8F7A3CFBDD2D9868F1BE
2012-02-18 21:56 . 2012-02-18 21:56   178   --s-a-w-   c:\documents and settings\customer1\Application Data\Microsoft\CryptnetUrlCache\MetaData\A4CB310CBB8B8F7A3CFBDD2D9868F1BE
2012-02-18 14:00 . 2012-02-18 14:00   10631   ----a-w-   c:\documents and settings\customer1\Application Data\Mozilla\Firefox\Profiles\gygvqas6.default\bookmarkbackups\bookmarks-2012-02-18.json
2012-02-14 08:12 . 2012-02-14 08:12   785033   ----a-w-   c:\documents and settings\customer1\Local Settings\Application Data\Microsoft\Silverlight\is\pw0mce0s.wyw\3u0zi4ly.vv5\1\s\v2b3wvdzfyecgh2hqj51l4tlxbhr2vxbwm30slwtjdjujnapo0aaagca\f\MahjongedBackgrounds4.xap
2012-02-14 02:22 . 2012-02-14 02:22   10631   ----a-w-   c:\documents and settings\customer1\Application Data\Mozilla\Firefox\Profiles\gygvqas6.default\bookmarkbackups\bookmarks-2012-02-13.json
2012-02-14 00:23 . 2012-02-14 00:23   1069083   ----a-w-   c:\documents and settings\customer1\Local Settings\Application Data\Microsoft\Silverlight\is\pw0mce0s.wyw\3u0zi4ly.vv5\1\s\v2b3wvdzfyecgh2hqj51l4tlxbhr2vxbwm30slwtjdjujnapo0aaagca\f\MahjongedBackgrounds3.xap
2012-02-13 20:01 . 2012-02-13 20:01   967814   ----a-w-   c:\documents and settings\customer1\Local Settings\Application Data\Microsoft\Silverlight\is\pw0mce0s.wyw\3u0zi4ly.vv5\1\s\v2b3wvdzfyecgh2hqj51l4tlxbhr2vxbwm30slwtjdjujnapo0aaagca\f\MahjongedBackgrounds2.xap
2012-02-13 19:00 . 2012-02-13 19:00   1341751   ----a-w-   c:\documents and settings\customer1\Local Settings\Application Data\Microsoft\Silverlight\is\pw0mce0s.wyw\3u0zi4ly.vv5\1\s\v2b3wvdzfyecgh2hqj51l4tlxbhr2vxbwm30slwtjdjujnapo0aaagca\f\MahjongedMusic.xap
2012-02-13 18:58 . 2012-02-13 18:58   1601831   ----a-w-   c:\documents and settings\customer1\Local Settings\Application Data\Microsoft\Silverlight\is\pw0mce0s.wyw\3u0zi4ly.vv5\1\s\v2b3wvdzfyecgh2hqj51l4tlxbhr2vxbwm30slwtjdjujnapo0aaagca\f\MahjongedHelp.xap
2012-02-13 17:37 . 2012-02-13 17:37   732636   ----a-w-   c:\documents and settings\customer1\Local Settings\Application Data\Microsoft\Silverlight\is\pw0mce0s.wyw\3u0zi4ly.vv5\1\s\v2b3wvdzfyecgh2hqj51l4tlxbhr2vxbwm30slwtjdjujnapo0aaagca\f\MahjongedBackgrounds1.xap
2012-02-13 16:41 . 2012-02-25 15:44   1469   ----a-w-   c:\documents and settings\customer1\Local Settings\Application Data\Microsoft\Silverlight\is\pw0mce0s.wyw\3u0zi4ly.vv5\1\s\v2b3wvdzfyecgh2hqj51l4tlxbhr2vxbwm30slwtjdjujnapo0aaagca\f\__LocalSettings
2012-02-13 16:41 . 2012-02-13 16:41   8   ----a-w-   c:\documents and settings\customer1\Local Settings\Application Data\Microsoft\Silverlight\is\pw0mce0s.wyw\3u0zi4ly.vv5\1\g\311jhywqp10p13r2pau1bhwcdyyn0uutn5hxsv4zmtkp4zr2qsaaaaga\quota.dat
2012-02-13 16:41 . 2012-02-13 16:41   8   ----a-w-   c:\documents and settings\customer1\Local Settings\Application Data\Microsoft\Silverlight\is\pw0mce0s.wyw\3u0zi4ly.vv5\1\g\311jhywqp10p13r2pau1bhwcdyyn0uutn5hxsv4zmtkp4zr2qsaaaaga\used.dat
2012-02-13 16:41 . 2012-03-08 06:15   56   ----a-w-   c:\documents and settings\customer1\Local Settings\Application Data\Microsoft\Silverlight\is\pw0mce0s.wyw\3u0zi4ly.vv5\1\s\v2b3wvdzfyecgh2hqj51l4tlxbhr2vxbwm30slwtjdjujnapo0aaagca\group.dat
2012-02-13 16:41 . 2012-02-13 16:41   48   ----a-w-   c:\documents and settings\customer1\Local Settings\Application Data\Microsoft\Silverlight\is\pw0mce0s.wyw\3u0zi4ly.vv5\1\s\v2b3wvdzfyecgh2hqj51l4tlxbhr2vxbwm30slwtjdjujnapo0aaagca\id.dat
2012-02-13 16:41 . 2012-02-13 16:41   24   ----a-w-   c:\documents and settings\customer1\Local Settings\Application Data\Microsoft\Silverlight\is\

Offline kcrawhorn

  • Bronze Member
  • Posts: 126
Re: [In Progress B]AVG found Trojan Horse Crypt.ASHD
« Reply #12 on: March 29, 2012, 03:51:51 PM »
pw0mce0s.wyw\3u0zi4ly.vv5\1\g\311jhywqp10p13r2pau1bhwcdyyn0uutn5hxsv4zmtkp4zr2qsaaaaga\id.dat
2012-02-12 05:23 . 2012-02-12 05:23   0   ----a-w-   c:\documents and settings\customer1\Application Data\Sun\Java\Deployment\SystemCache\6.0\32\6c34baa0-22ef0122
2012-02-12 05:23 . 2012-03-29 21:03   462   ----a-w-   c:\documents and settings\customer1\Application Data\Sun\Java\Deployment\SystemCache\6.0\32\6c34baa0-22ef0122.idx
2012-02-09 16:38 . 2012-02-09 16:55   166   ----a-w-   c:\documents and settings\customer1\Application Data\Real\RealPlayer\viz.ini
2012-02-09 16:35 . 2012-02-09 16:35   341   --sh--w-   c:\documents and settings\customer1\My Documents\My Music\Unknown Artist\Unknown Album (11-27-2009 3-42-06 AM)\desktop.ini
2012-02-09 16:35 . 2012-02-09 16:35   12608   --sh--w-   c:\documents and settings\customer1\My Documents\My Music\Unknown Artist\Unknown Album (11-27-2009 3-42-06 AM)\AlbumArt_{E982D37E-C8B6-4F69-977F-C3716B7B94C1}_Large.jpg
2012-02-09 16:35 . 2012-02-09 16:35   12608   --sh--w-   c:\documents and settings\customer1\My Documents\My Music\Unknown Artist\Unknown Album (11-27-2009 3-42-06 AM)\Folder.jpg
2012-02-09 16:35 . 2012-02-09 16:35   2822   --sh--w-   c:\documents and settings\customer1\My Documents\My Music\Unknown Artist\Unknown Album (11-27-2009 3-42-06 AM)\AlbumArt_{E982D37E-C8B6-4F69-977F-C3716B7B94C1}_Small.jpg
2012-02-09 16:35 . 2012-02-09 16:35   2822   --sh--w-   c:\documents and settings\customer1\My Documents\My Music\Unknown Artist\Unknown Album (11-27-2009 3-42-06 AM)\AlbumArtSmall.jpg
2012-02-06 17:23 . 2012-02-06 17:23   43   --sh--w-   c:\documents and settings\customer1\My Documents\My Music\Unknown Artist\Unknown Album (2-6-2012 11-23-24 AM)\desktop.ini
2012-02-06 17:23 . 2012-02-06 17:23   43   --sh--w-   c:\documents and settings\customer1\My Documents\My Music\Unknown Artist\Unknown Album (2-6-2012 11-23-23 AM)\desktop.ini
2012-02-06 17:23 . 2012-02-06 17:23   43   --sh--w-   c:\documents and settings\customer1\My Documents\My Music\Unknown Artist\Unknown Album (2-6-2012 11-23-22 AM)\desktop.ini
2012-02-06 17:20 . 2012-03-02 15:18   152   ----a-w-   c:\documents and settings\customer1\Local Settings\Application Data\Microsoft\Silverlight\is\pw0mce0s.wyw\3u0zi4ly.vv5\1\s\u4nll4hghcen13r3jyqlcw1e0wapukkfqd1nyqcn5uz4dmrluzaaaefa\f\SLPlayer\bwdata.json
2012-02-06 17:20 . 2012-02-06 17:20   552   --s-a-w-   c:\documents and settings\customer1\Application Data\Microsoft\CryptnetUrlCache\Content\3130B1871A126520A8C47861EFE3ED4D
2012-02-06 17:20 . 2012-02-06 17:20   132   --s-a-w-   c:\documents and settings\customer1\Application Data\Microsoft\CryptnetUrlCache\MetaData\3130B1871A126520A8C47861EFE3ED4D
2012-02-04 03:20 . 2012-02-04 03:20   5988   ----a-w-   c:\documents and settings\customer1\Application Data\Mozilla\Firefox\Profiles\gygvqas6.default\extensions.rdf
2012-02-02 22:10 . 2012-02-02 22:10   388   --sha-w-   c:\documents and settings\customer1\Application Data\Microsoft\Protect\S-1-5-21-73586283-842925246-725345543-1004\cc8f8d95-2978-4388-831d-307b3136990c
2012-01-29 19:35 . 2012-03-17 05:25   18630   ----a-w-   c:\documents and settings\customer1\Application Data\Real\RealPlayer\WatchFolders\fldrscan.out
2012-01-29 19:35 . 2012-01-29 19:35   0   ----a-w-   c:\documents and settings\customer1\Application Data\Real\RealPlayer\timecache0.ini
2012-01-29 19:35 . 2012-01-29 19:35   6144   ----a-w-   c:\documents and settings\customer1\Application Data\Real\RealPlayer\device\temp_pictures_master.db
2012-01-29 18:41 . 2012-01-29 18:41   36   ----a-w-   c:\documents and settings\customer1\Application Data\Adobe\Acrobat\8.0\TMDocs.sav
2012-01-29 18:41 . 2012-01-29 18:41   54   ----a-w-   c:\documents and settings\customer1\Application Data\Adobe\Acrobat\8.0\TMGrpPrm.sav
2012-01-29 02:10 . 2012-03-24 20:29   14744   ----a-w-   c:\documents and settings\customer1\Application Data\Mozilla\Firefox\Profiles\gygvqas6.default\search.json
2012-01-29 01:01 . 2012-01-29 01:01   22591707   ----a-w-   c:\documents and settings\customer1\Desktop\RA_Whse_2011_Workout.pdf
2012-01-28 23:54 . 2012-01-28 23:54   7790   ----a-w-   c:\documents and settings\customer1\Application Data\AVG Secure Search\cache\849681cb524c609a.fb
2012-01-28 23:54 . 2012-01-28 23:54   1256   --s-a-w-   c:\documents and settings\customer1\Application Data\Microsoft\CryptnetUrlCache\Content\44E52DC699C23D7773A11CFD31BFE848
2012-01-28 23:54 . 2012-01-28 23:54   172   --s-a-w-   c:\documents and settings\customer1\Application Data\Microsoft\CryptnetUrlCache\MetaData\44E52DC699C23D7773A11CFD31BFE848
2012-01-26 22:02 . 2012-01-26 22:02   1997   --s-a-w-   c:\documents and settings\customer1\Application Data\Microsoft\CryptnetUrlCache\Content\140B4CDED8ED877CDC65B54BA965BD39
2012-01-26 22:02 . 2012-01-26 22:02   96   --s-a-w-   c:\documents and settings\customer1\Application Data\Microsoft\CryptnetUrlCache\MetaData\140B4CDED8ED877CDC65B54BA965BD39
2012-01-24 17:01 . 2012-03-24 22:39   10240   ----a-w-   c:\documents and settings\customer1\Local Settings\Application Data\Mozilla\Firefox\Profiles\gygvqas6.default\OfflineCache\index.sqlite
2012-01-22 05:44 . 2012-01-22 05:44   410   ----a-w-   c:\documents and settings\customer1\Favorites\wikipedia - Google Search.url
2012-01-19 22:23 . 2012-01-19 22:23   75326   --s-a-w-   c:\documents and settings\customer1\Application Data\Microsoft\CryptnetUrlCache\Content\B69D763EB21649DA26F20618312DEE70
2012-01-19 22:23 . 2012-01-19 22:23   128   --s-a-w-   c:\documents and settings\customer1\Application Data\Microsoft\CryptnetUrlCache\MetaData\B69D763EB21649DA26F20618312DEE70
2012-01-17 04:20 . 2012-03-03 03:52   148   ----a-w-   c:\documents and settings\customer1\Application Data\Adobe\Flash Player\AssetCache\QKMWSUYA\1846548181EAE8A4BB86AFC74FD021D9A0F6DFA6.heu
2012-01-17 04:20 . 2012-01-17 04:20   541380   ----a-w-   c:\documents and settings\customer1\Application Data\Adobe\Flash Player\AssetCache\QKMWSUYA\1846548181EAE8A4BB86AFC74FD021D9A0F6DFA6.swz
2012-01-17 02:59 . 2012-02-24 04:56   4844452   ---ha-w-   c:\documents and settings\customer1\Local Settings\Application Data\IconCache.db
2012-01-15 16:49 . 2012-02-25 21:19   148   ----a-w-   c:\documents and settings\customer1\Application Data\Adobe\Flash Player\AssetCache\QKMWSUYA\67BA9F962EEC4D8B413432AFAD5C88BB810426B9.heu
2012-01-15 16:49 . 2012-01-15 16:49   54494   ----a-w-   c:\documents and settings\customer1\Application Data\Adobe\Flash Player\AssetCache\QKMWSUYA\67BA9F962EEC4D8B413432AFAD5C88BB810426B9.swz
2012-01-15 16:49 . 2012-02-25 21:19   148   ----a-w-   c:\documents and settings\customer1\Application Data\Adobe\Flash Player\AssetCache\QKMWSUYA\33D9983BC427DD69DF151E816FB0AB02C0B8D5CF.heu
2012-01-15 16:49 . 2012-01-15 16:49   317992   ----a-w-   c:\documents and settings\customer1\Application Data\Adobe\Flash Player\AssetCache\QKMWSUYA\33D9983BC427DD69DF151E816FB0AB02C0B8D5CF.swz
2012-01-15 16:49 . 2012-02-25 21:19   148   ----a-w-   c:\documents and settings\customer1\Application Data\Adobe\Flash Player\AssetCache\QKMWSUYA\D796AC95BD6E16151B6D3C0019A52E648CED1FE1.heu
2012-01-15 16:49 . 2012-01-15 16:49   131911   ----a-w-   c:\documents and settings\customer1\Application Data\Adobe\Flash Player\AssetCache\QKMWSUYA\D796AC95BD6E16151B6D3C0019A52E648CED1FE1.swz
2012-01-15 16:49 . 2012-02-25 21:19   148   ----a-w-   c:\documents and settings\customer1\Application Data\Adobe\Flash Player\AssetCache\QKMWSUYA\7421C71F94DB4F028E7528B2D278F3FE4DC21273.heu
2012-01-15 16:49 . 2012-01-15 16:49   156308   ----a-w-   c:\documents and settings\customer1\Application Data\Adobe\Flash Player\AssetCache\QKMWSUYA\7421C71F94DB4F028E7528B2D278F3FE4DC21273.swz
2012-01-15 16:49 . 2012-02-25 21:19   148   ----a-w-   c:\documents and settings\customer1\Application Data\Adobe\Flash Player\AssetCache\QKMWSUYA\F74FCD943BAC79E6DADBF0307B55B0697C5907E4.heu
2012-01-15 16:49 . 2012-01-15 16:49   621999   ----a-w-   c:\documents and settings\customer1\Application Data\Adobe\Flash Player\AssetCache\QKMWSUYA\F74FCD943BAC79E6DADBF0307B55B0697C5907E4.swz
2012-01-15 16:49 . 2012-02-25 21:19   148   ----a-w-   c:\documents and settings\customer1\Application Data\Adobe\Flash Player\AssetCache\QKMWSUYA\C3306B26751D6A80EB1FCB651912469AE18819AB.heu
2012-01-15 16:49 . 2012-01-15 16:49   98047   ----a-w-   c:\documents and settings\customer1\Application Data\Adobe\Flash Player\AssetCache\QKMWSUYA\C3306B26751D6A80EB1FCB651912469AE18819AB.swz
2012-01-15 03:27 . 2012-01-15 03:27   37787   ----a-w-   c:\documents and settings\customer1\Application Data\Real\RealPlayer\WatchFolders\fldrscan2.out
2012-01-15 03:27 . 2012-01-15 03:27   2450   ----a-w-   c:\documents and settings\customer1\Application Data\Real\RealPlayer\db\unifi.xml
2012-01-15 03:27 . 2012-01-15 03:27   643   ----a-w-   c:\documents and settings\customer1\Application Data\Real\RealPlayer\db\listview.dat
2012-01-15 03:27 . 2012-01-29 19:35   782   ----a-w-   c:\documents and settings\customer1\Application Data\Real\RealPlayer\DRM\rights.xml
2012-01-15 03:27 . 2012-01-29 19:35   3678   ----a-w-   c:\documents and settings\customer1\Application Data\Real\RealPlayer\library\view.xml
2012-01-15 03:27 . 2012-01-15 03:27   224   ----a-w-   c:\documents and settings\customer1\Application Data\Real\Msg\Category.dat
2012-01-15 03:27 . 2012-01-15 03:27   106   ----a-w-   c:\documents and settings\customer1\Application Data\Real\Msg\SCategory.dat
2012-01-15 03:26 . 2012-02-09 16:55   1373   ----a-w-   c:\documents and settings\customer1\Application Data\Real\RealPlayer\skins\data\normal\state.ini
2012-01-15 03:26 . 2012-01-15 03:26   28672   ----a-w-   c:\documents and settings\customer1\Application Data\Real\RealPlayer\device\device_master.db
2012-01-15 03:26 . 2012-01-29 19:35   1223943   ----a-w-   c:\documents and settings\customer1\Application Data\Real\RealPlayer\skins\data\normal\imgcache.dat
2012-01-15 03:25 . 2012-01-15 03:25   6144   ----a-w-   c:\documents and settings\customer1\Application Data\Real\RealPlayer\device\audiovideo_master.db
2012-01-15 03:25 . 2012-03-29 21:22   2532   ----a-w-   c:\documents and settings\customer1\Application Data\Real\rnadmin\rnsystem.dat
2012-01-14 04:00 . 2012-01-14 04:00   1498   ----a-w-   c:\documents and settings\customer1\Desktop\Calculator.lnk
2012-01-14 03:58 . 2012-01-14 03:58   45056   ----a-w-   c:\documents and settings\customer1\Desktop\U.S.Bank_Resume_CL_01.13.12.doc
2012-01-12 23:40 . 2012-03-02 15:18   121   ----a-w-   c:\documents and settings\customer1\Local Settings\Application Data\Microsoft\Silverlight\is\pw0mce0s.wyw\3u0zi4ly.vv5\1\s\u4nll4hghcen13r3jyqlcw1e0wapukkfqd1nyqcn5uz4dmrluzaaaefa\f\SLPlayer\userPrefs.json
2012-01-12 23:34 . 2012-01-12 23:34   512   ----a-w-   c:\documents and settings\customer1\Application Data\Real\Update\temp\~Upg1\update.spc
2012-01-12 23:31 . 2012-03-02 15:18   3025   ----a-w-   c:\documents and settings\customer1\Local Settings\Application Data\Microsoft\Silverlight\is\pw0mce0s.wyw\3u0zi4ly.vv5\1\s\u4nll4hghcen13r3jyqlcw1e0wapukkfqd1nyqcn5uz4dmrluzaaaefa\f\SLPlayer\sysData
2012-01-12 23:31 . 2012-03-02 15:14   0   ----a-w-   c:\documents and settings\customer1\Local Settings\Application Data\Microsoft\Silverlight\is\pw0mce0s.wyw\3u0zi4ly.vv5\1\s\u4nll4hghcen13r3jyqlcw1e0wapukkfqd1nyqcn5uz4dmrluzaaaefa\f\SLPlayer\applock
2012-01-12 23:31 . 2012-01-12 23:31   25   ----a-w-   c:\documents and settings\customer1\Local Settings\Application Data\Microsoft\Silverlight\is\pw0mce0s.wyw\3u0zi4ly.vv5\1\g\u4nll4hghcen13r3jyqlcw1e0wapukkfqd1nyqcn5uz4dmrluzaaaefa\id.dat
2012-01-12 23:31 . 2012-01-12 23:31   8   ----a-w-   c:\documents and settings\customer1\Local Settings\Application Data\Microsoft\Silverlight\is\pw0mce0s.wyw\3u0zi4ly.vv5\1\g\u4nll4hghcen13r3jyqlcw1e0wapukkfqd1nyqcn5uz4dmrluzaaaefa\quota.dat
2012-01-12 23:31 . 2012-01-12 23:31   8   ----a-w-   c:\documents and settings\customer1\Local Settings\Application Data\Microsoft\Silverlight\is\pw0mce0s.wyw\3u0zi4ly.vv5\1\g\u4nll4hghcen13r3jyqlcw1e0wapukkfqd1nyqcn5uz4dmrluzaaaefa\used.dat
2012-01-12 23:31 . 2012-03-02 15:18   56   ----a-w-   c:\documents and settings\customer1\Local Settings\Application Data\Microsoft\Silverlight\is\pw0mce0s.wyw\3u0zi4ly.vv5\1\s\u4nll4hghcen13r3jyqlcw1e0wapukkfqd1nyqcn5uz4dmrluzaaaefa\group.dat
2012-01-12 23:31 . 2012-01-12 23:31   25   ----a-w-   c:\documents and settings\customer1\Local Settings\Application Data\Microsoft\Silverlight\is\pw0mce0s.wyw\3u0zi4ly.vv5\1\s\u4nll4hghcen13r3jyqlcw1e0wapukkfqd1nyqcn5uz4dmrluzaaaefa\id.dat
2012-01-04 15:40 . 2012-01-04 15:50   2087   ----a-w-   c:\documents and settings\customer1\Application Data\Skype\bmurphy1954\chatsync\fe\fe07557a2e803e2d.dat
2012-01-04 02:42 . 2012-03-26 14:42   149   ----a-w-   c:\documents and settings\customer1\Application Data\Adobe\Flash Player\AssetCache\QKMWSUYA\8F903698240FE799F61EEDA8595181137B996156.heu
2012-01-04 02:42 . 2012-01-04 02:42   186404   ----a-w-   c:\documents and settings\customer1\Application Data\Adobe\Flash Player\AssetCache\QKMWSUYA\8F903698240FE799F61EEDA8595181137B996156.swz
2012-01-03 14:22 . 2012-01-03 14:22   1302   --s-a-w-   c:\documents and settings\customer1\Application Data\Microsoft\CryptnetUrlCache\Content\A92ECB803776646616CF2949CC6BAC5D
2012-01-03 14:22 . 2012-01-03 14:22   126   --s-a-w-   c:\documents and settings\customer1\Application Data\Microsoft\CryptnetUrlCache\MetaData\A92ECB803776646616CF2949CC6BAC5D
2012-01-03 14:22 . 2012-01-03 14:22   2202   --s-a-w-   c:\documents and settings\customer1\Application Data\Microsoft\CryptnetUrlCache\Content\A0F226E8ACF8E1672AF808D7CAF4AD47
2012-01-03 14:22 . 2012-01-03 14:22   194   --s-a-w-   c:\documents and settings\customer1\Application Data\Microsoft\CryptnetUrlCache\MetaData\A0F226E8ACF8E1672AF808D7CAF4AD47
2012-01-03 14:18 . 2012-03-13 21:08   12   ----a-w-   c:\documents and settings\customer1\Application Data\Skype\bmurphy1954\httpfe\cookies.dat
2012-01-03 13:48 . 2012-02-19 19:39   1806   ----a-w-   c:\documents and settings\customer1\Application Data\Skype\bmurphy1954\chatsync\2d\2d592345fc8eb024.dat
2012-01-03 13:47 . 2012-03-13 20:41   86696   ----a-w-   c:\documents and settings\customer1\Application Data\Skype\bmurphy1954\dc.db-journal
2012-01-03 13:47 . 2012-03-13 20:41   172032   ----a-w-   c:\documents and settings\customer1\Application Data\Skype\bmurphy1954\dc.db
2012-01-03 13:47 . 2012-03-13 21:08   8514   ----a-w-   c:\documents and settings\customer1\Application Data\Skype\bmurphy1954\config.xml
2012-01-03 13:47 . 2012-03-13 21:09   33344   ----a-w-   c:\documents and settings\customer1\Application Data\Skype\bmurphy1954\bistats.db-journal
2012-01-03 13:47 . 2012-03-13 21:09   61440   ----a-w-   c:\documents and settings\customer1\Application Data\Skype\bmurphy1954\bistats.db
2012-01-03 13:47 . 2012-01-03 13:47   28672   ----a-w-   c:\documents and settings\customer1\Application Data\Skype\bmurphy1954\griffin.db
2012-01-03 13:47 . 2012-01-03 13:47   12824   ----a-w-   c:\documents and settings\customer1\Application Data\Skype\bmurphy1954\griffin.db-journal
2012-01-03 13:47 . 2012-03-13 20:11   40960   ----a-w-   c:\documents and settings\customer1\Application Data\Skype\bmurphy1954\keyval.db
2012-01-03 13:47 . 2012-03-13 20:11   33344   ----a-w-   c:\documents and settings\customer1\Application Data\Skype\bmurphy1954\keyval.db-journal
2012-01-03 13:47 . 2012-03-13 21:09   368640   ----a-w-   c:\documents and settings\customer1\Application Data\Skype\bmurphy1954\main.db
2012-01-03 13:47 . 2012-03-13 21:09   131840   ----a-w-   c:\documents and settings\customer1\Application Data\Skype\bmurphy1954\main.db-journal
2012-01-03 13:47 . 2012-01-03 13:47   0   ----a-w-   c:\documents and settings\customer1\Application Data\Skype\bmurphy1954\config.lck
2012-01-03 13:47 . 2012-01-03 13:47   12824   ----a-w-   c:\documents and settings\customer1\Application Data\Skype\shared_httpfe\queue.db-journal
2012-01-03 13:47 . 2012-01-03 13:47   36864   ----a-w-   c:\documents and settings\customer1\Application Data\Skype\shared_httpfe\queue.db
2012-01-03 13:47 . 2012-01-03 13:47   0   ----a-w-   c:\documents and settings\customer1\Application Data\Skype\shared_httpfe\queue.lock
2012-01-03 13:47 . 2012-03-13 20:50   61950   ----a-w-   c:\documents and settings\customer1\Application Data\Skype\shared.xml
2012-01-03 13:47 . 2012-03-13 20:11   1032192   ----a-w-   c:\documents and settings\customer1\Application Data\Skype\shared_dynco\dc.db
2012-01-03 13:47 . 2012-03-13 20:11   800792   ----a-w-   c:\documents and settings\customer1\Application Data\Skype\shared_dynco\dc.db-journal
2012-01-03 13:47 . 2012-01-03 13:47   0   ----a-w-   c:\documents and settings\customer1\Application Data\Skype\shared_dynco\dc.lock
2012-01-03 13:47 . 2012-01-03 13:47   0   ----a-w-   c:\documents and settings\customer1\Application Data\Skype\shared.lck
2012-01-03 13:47 . 2012-01-03 13:47   1692   ----a-w-   c:\documents and settings\customer1\SendTo\Skype.lnk
2012-01-01 23:33 . 2012-01-01 23:33   512   ----a-w-   c:\documents and settings\customer1\Application Data\Real\Update\temp\~Upg0\update.spc
2011-12-31 20:16 . 2011-12-31 20:16   3562   ----a-w-   c:\documents and settings\customer1\Desktop\Massey 165 Hydraulic Pump INFO.txt
2011-12-31 15:45 . 2012-03-28 22:01   245   ----a-w-   c:\documents and settings\customer1\Favorites\Craigslist  Cities.url
2011-12-30 03:23 . 2011-12-30 03:23   528   --s-a-w-   c:\documents and settings\customer1\Application Data\Microsoft\CryptnetUrlCache\Content\E04822AD18D472EA5B582E6E6F8C6B9A
2011-12-30 03:23 . 2011-12-30 03:23   140   --s-a-w-   c:\documents and settings\customer1\Application Data\Microsoft\CryptnetUrlCache\MetaData\E04822AD18D472EA5B582E6E6F8C6B9A
2011-12-30 03:23 . 2011-12-30 03:23   561   --s-a-w-   c:\documents and settings\customer1\Application Data\Microsoft\CryptnetUrlCache\Content\B8CC409ACDBF2A2FE04C56F2875B1FD6
2011-12-30 03:23 . 2011-12-30 03:23   134   --s-a-w-   c:\documents and settings\customer1\Application Data\Microsoft\CryptnetUrlCache\MetaData\B8CC409ACDBF2A2FE04C56F2875B1FD6
2011-12-30 03:23 . 2011-12-30 03:23   576   --s-a-w-   c:\documents and settings\customer1\Application Data\Microsoft\CryptnetUrlCache\Content\1B749B72855CB97BF2F58675617C9BF9
2011-12-30 03:23 . 2011-12-30 03:23   162   --s-a-w-   c:\documents and settings\customer1\Application Data\Microsoft\CryptnetUrlCache\MetaData\1B749B72855CB97BF2F58675617C9BF9
2011-12-30 03:23 . 2011-12-30 03:24   55818   ----a-w-   c:\documents and settings\customer1\Application Data\QuickScan\Report 2011-12-29 21.23.09.txt
2011-12-30 02:52 . 2012-03-23 02:40   264   ----a-w-   c:\documents and settings\customer1\Favorites\Links\Barbie Games for Girls - Play Fun Activities, Puzzles, Makeover & Dress-Up Games, Free  Barbie.url
2011-12-30 02:51 . 2012-03-29 13:46   265   ----a-w-   c:\documents and settings\customer1\Favorites\Links\Games - Sesame Street.url
2011-12-30 02:51 . 2012-03-28 22:01   3146   ----a-w-   c:\documents and settings\customer1\Favorites\Links\Columbia - Kentucky Weather Forecasts  Maps  News - Yahoo! Weather.url
2011-12-30 02:50 . 2011-12-30 02:50   158   ----a-w-   c:\documents and settings\customer1\Favorites\Links\Welcome to Facebook - Log In, Sign Up or Learn More.url
2011-12-30 02:46 . 2012-01-10 01:43   234   ----a-w-   c:\documents and settings\customer1\Favorites\Links\Netflix - Watch TV Shows Online, Watch Movies Online.url
2011-12-29 21:38 . 2011-12-29 21:38   639   ----a-w-   c:\documents and settings\customer1\Application Data\AVG Secure Search\cache\590ba23ce359fd0c__exp__1325281139
2011-12-29 21:38 . 2011-12-29 21:38   630   ----a-w-   c:\documents and settings\customer1\Application Data\AVG Secure Search\cache\272512937d9e61a4__exp__1325281139
2011-12-29 21:38 . 2011-12-29 21:38   398   ----a-w-   c:\documents and settings\customer1\Application Data\AVG Secure Search\cache\6c59ac5e7e7a3ad0__exp__1325281139
2011-12-29 21:38 . 2011-12-29 21:38   627   ----a-w-   c:\documents and settings\customer1\Application Data\AVG Secure Search\cache\651c5d3cdbfb8bd1__exp__1325281139
2011-12-29 21:38 . 2011-12-29 21:38   1045   ----a-w-   c:\documents and settings\customer1\Application Data\AVG Secure Search\cache\d201ef9910cd39de__exp__1325281139
2011-12-29 21:38 . 2011-12-29 21:38   586   ----a-w-   c:\documents and settings\customer1\Application Data\AVG Secure Search\cache\c4d28dca2e7648be__exp__1325281139
2011-12-29 21:38 . 2011-12-29 21:38   1062   ----a-w-   c:\documents and settings\customer1\Application Data\AVG Secure Search\cache\e0de16f883bea794__exp__1325281139
2011-12-29 21:38 . 2011-12-29 21:38   366   ----a-w-   c:\documents and settings\customer1\Application Data\AVG Secure Search\cache\ad10a52aff5e038d__exp__1325281139
2011-12-29 21:38 . 2011-12-29 21:38   1291   ----a-w-   c:\documents and settings\customer1\Application Data\AVG Secure Search\cache\28bc8f716fd76a47__exp__1325281139
2011-12-29 21:38 . 2011-12-29 21:38   8520   ----a-w-   c:\documents and settings\customer1\Application Data\AVG Secure Search\cache\aa074feb4a578e80__exp__1325281139
2011-12-24 23:03 . 2011-12-24 23:03   640   ----a-w-   c:\documents and settings\customer1\Application Data\Winamp\Plugins\Gracenote\cddb.db
2011-12-24 04:24 . 2012-03-16 17:45   197   ----a-w-   c:\documents and settings\customer1\Application Data\AVG2012\cfgall\outlook.cfg
2011-12-24 04:23 . 2012-03-15 14:21   519   ----a-w-   c:\documents and settings\customer1\Local Settings\Application Data\Microsoft\Outlook\extend.dat
2011-12-24 00:53 . 2012-03-13 20:11   38890   --s-a-w-   c:\documents and settings\customer1\Application Data\Microsoft\CryptnetUrlCache\Content\62B5AF9BE9ADC1085C3C56EC07A82BF6
2011-12-24 00:53 . 2012-03-13 20:11   124   --s-a-w-   c:\documents and settings\customer1\Application Data\Microsoft\CryptnetUrlCache\MetaData\62B5AF9BE9ADC1085C3C56EC07A82BF6
2011-12-24 00:53 . 2011-12-24 00:53   533   --s-a-w-   c:\documents and settings\customer1\Application Data\Microsoft\CryptnetUrlCache\Content\8DFDF057024880D7A081AFBF6D26B92F
2011-12-24 00:53 . 2011-12-24 00:53   100   --s-a-w-   c:\documents and settings\customer1\Application Data\Microsoft\CryptnetUrlCache\MetaData\8DFDF057024880D7A081AFBF6D26B92F
2011-12-24 00:36 . 2011-12-24 00:36   1340   ----a-w-   c:\documents and settings\customer1\Application Data\Ahead\Nero BackItUp\ToolbarSettings.dat
2011-12-24 00:36 . 2011-12-24 00:36   30978   ----a-w-   c:\documents and settings\customer1\Application Data\Ahead\Nero BackItUp\Cache\NeroBackItUp.txt
2011-12-24 00:29 . 2011-12-24 00:34   306   ----a-w-   c:\documents and settings\customer1\Application Data\Ahead\Nero BackItUp\Cache\NBDBList.ini
2011-12-23 20:38 . 2011-12-23 20:38   56   ----a-w-   c:\documents and settings\customer1\Local Settings\Application Data\Microsoft\Silverlight\is\pw0mce0s.wyw\3u0zi4ly.vv5\1\s\cg1yg4fgpzcbrh3l21zvf4entslg3yktnvseib12d4oyzcr2vzaaahba\group.dat
2011-12-23 20:38 . 2011-12-23 20:38   22   ----a-w-   c:\documents and settings\customer1\Local Settings\Application Data\Microsoft\Silverlight\is\pw0mce0s.wyw\3u0zi4ly.vv5\1\s\cg1yg4fgpzcbrh3l21zvf4entslg3yktnvseib12d4oyzcr2vzaaahba\id.dat
2011-12-23 20:38 . 2011-12-23 20:38   3255   ----a-w-   c:\documents and settings\customer1\Local Settings\Application Data\Microsoft\Silverlight\is\pw0mce0s.wyw\3u0zi4ly.vv5\1\s\13pracan3sihwadxer2qeandcsbthokfr1z2q1u0qby3gofjelaaacca\f\__LocalSettings
2011-12-23 20:38 . 2011-12-23 20:38   22   ----a-w-   c:\documents and settings\customer1\Local Settings\Application Data\Microsoft\Silverlight\is\pw0mce0s.wyw\3u0zi4ly.vv5\1\g\cg1yg4fgpzcbrh3l21zvf4entslg3yktnvseib12d4oyzcr2vzaaahba\id.dat
2011-12-23 20:38 . 2011-12-23 20:38   8   ----a-w-   c:\documents and settings\customer1\Local Settings\Application Data\Microsoft\Silverlight\is\pw0mce0s.wyw\3u0zi4ly.vv5\1\g\cg1yg4fgpzcbrh3l21zvf4entslg3yktnvseib12d4oyzcr2vzaaahba\quota.dat
2011-12-23 20:38 . 2011-12-23 20:38   8   ----a-w-   c:\documents and settings\customer1\Local Settings\Application Data\Microsoft\Silverlight\is\pw0mce0s.wyw\3u0zi4ly.vv5\1\g\cg1yg4fgpzcbrh3l21zvf4entslg3yktnvseib12d4oyzcr2vzaaahba\used.dat
2011-12-23 20:38 . 2011-12-23 20:38   56   ----a-w-   c:\documents and settings\customer1\Local Settings\Application Data\Microsoft\Silverlight\is\pw0mce0s.wyw\3u0zi4ly.vv5\1\s\13pracan3sihwadxer2qeandcsbthokfr1z2q1u0qby3gofjelaaacca\group.dat
2011-12-23 20:38 . 2011-12-23 20:38   51   ----a-w-   c:\documents and settings\customer1\Local Settings\Application Data\Microsoft\Silverlight\is\pw0mce0s.wyw\3u0zi4ly.vv5\1\s\13pracan3sihwadxer2qeandcsbthokfr1z2q1u0qby3gofjelaaacca\id.dat
2011-12-23 02:36 . 2011-12-23 02:39   26927552   ----a-w-   c:\documents and settings\customer1\Application Data\Real\Update\UpgradeHelper\RealPlayer\9.01\stub_data\RealPlayer.exe
2011-12-23 02:36 . 2011-12-23 02:36   260204   ----a-w-   c:\documents and settings\customer1\Application Data\Real\Update\UpgradeHelper\RealPlayer\9.01\stub_data\nss.cab
2011-12-23 02:36 . 2011-12-23 02:36   250654   ----a-w-   c:\documents and settings\customer1\Application Data\Real\Update\UpgradeHelper\RealPlayer\9.01\stub_data\gtb.cab
2011-12-23 02:34 . 2012-01-04 14:25   25093534   ----a-w-   c:\documents and settings\customer1\Application Data\Real\Update\UpgradeHelper\RealPlayer\9.01\stub_data\chrome.cab

Offline kcrawhorn

  • Bronze Member
  • Posts: 126
Re: [In Progress B]AVG found Trojan Horse Crypt.ASHD
« Reply #13 on: March 29, 2012, 03:53:02 PM »
2011-12-23 02:34 . 2011-12-23 02:34   713472   ----a-w-   c:\documents and settings\customer1\Application Data\Real\Update\UpgradeHelper\RealPlayer\9.01\stub_exe\RealPlayer.exe
2011-12-23 02:33 . 2011-12-23 02:34   1199303   ----a-w-   c:\documents and settings\customer1\Application Data\Real\Update\UpgradeHelper\RealPlayer\9.01\stub_data\stubinst_pkg_en-us.cab
2011-12-22 23:53 . 2012-03-29 21:02   46777   ----a-w-   c:\documents and settings\customer1\Application Data\AVG2012\cfgall\userawacs.cfg
2011-12-22 23:53 . 2012-02-25 04:27   2753   ----a-w-   c:\documents and settings\customer1\Application Data\AVG2012\cfgall\usergui.cfg
2011-12-22 23:52 . 2012-01-28 23:54   630   ----a-w-   c:\documents and settings\customer1\Application Data\AVG Secure Search\cache\272512937d9e61a4.fb
2011-12-22 23:52 . 2012-01-28 23:54   639   ----a-w-   c:\documents and settings\customer1\Application Data\AVG Secure Search\cache\590ba23ce359fd0c.fb
2011-12-22 23:52 . 2012-01-28 23:54   622   ----a-w-   c:\documents and settings\customer1\Application Data\AVG Secure Search\cache\287204568329e189.fb
2011-12-22 23:52 . 2012-01-28 23:54   1291   ----a-w-   c:\documents and settings\customer1\Application Data\AVG Secure Search\cache\28bc8f716fd76a47.fb
2011-12-22 23:52 . 2012-01-28 23:54   633   ----a-w-   c:\documents and settings\customer1\Application Data\AVG Secure Search\cache\2c53092c95605355.fb
2011-12-22 23:52 . 2012-01-28 23:54   1022   ----a-w-   c:\documents and settings\customer1\Application Data\AVG Secure Search\cache\3917078cb68ec657.fb
2011-12-22 23:52 . 2012-01-28 23:54   365   ----a-w-   c:\documents and settings\customer1\Application Data\AVG Secure Search\cache\610289e025a3ee9a.fb
2011-12-22 23:52 . 2012-01-28 23:54   627   ----a-w-   c:\documents and settings\customer1\Application Data\AVG Secure Search\cache\651c5d3cdbfb8bd1.fb
2011-12-22 23:52 . 2012-01-28 23:54   398   ----a-w-   c:\documents and settings\customer1\Application Data\AVG Secure Search\cache\6c59ac5e7e7a3ad0.fb
2011-12-22 23:52 . 2011-12-22 23:51   7790   ----a-w-   c:\documents and settings\customer1\Application Data\AVG Secure Search\cache\aa074feb4a578e80.fb
2011-12-22 23:52 . 2012-01-28 23:54   366   ----a-w-   c:\documents and settings\customer1\Application Data\AVG Secure Search\cache\ad10a52aff5e038d.fb
2011-12-22 23:52 . 2012-01-28 23:54   586   ----a-w-   c:\documents and settings\customer1\Application Data\AVG Secure Search\cache\c4d28dca2e7648be.fb
2011-12-22 23:52 . 2012-01-28 23:54   1045   ----a-w-   c:\documents and settings\customer1\Application Data\AVG Secure Search\cache\d201ef9910cd39de.fb
2011-12-22 23:52 . 2012-01-28 23:54   567   ----a-w-   c:\documents and settings\customer1\Application Data\AVG Secure Search\cache\d2e94710a5708128.fb
2011-12-22 23:52 . 2012-01-28 23:54   627   ----a-w-   c:\documents and settings\customer1\Application Data\AVG Secure Search\cache\d79b9dfe81484ec4.fb
2011-12-22 23:52 . 2012-01-28 23:54   1062   ----a-w-   c:\documents and settings\customer1\Application Data\AVG Secure Search\cache\e0de16f883bea794.fb
2011-12-22 23:41 . 2012-02-25 04:31   36163   --s-a-w-   c:\documents and settings\customer1\Application Data\Microsoft\CryptnetUrlCache\Content\0797C381B2F87EB5A1D5573BD15BA4F4
2011-12-22 23:41 . 2012-02-25 04:31   132   --s-a-w-   c:\documents and settings\customer1\Application Data\Microsoft\CryptnetUrlCache\MetaData\0797C381B2F87EB5A1D5573BD15BA4F4
2011-12-22 23:40 . 2011-12-22 23:40   577169   ----a-w-   c:\documents and settings\customer1\Application Data\Sun\Java\AU\au.cab
2011-12-22 23:40 . 2011-12-22 23:40   207360   ----a-w-   c:\documents and settings\customer1\Application Data\Sun\Java\AU\au.msi
2011-12-22 23:40 . 2012-02-12 05:23   1   ----a-w-   c:\documents and settings\customer1\Application Data\Sun\Java\Deployment\SystemCache\6.0\lastAccessed
2011-12-22 23:40 . 2012-02-12 05:23   128   ----a-w-   c:\documents and settings\customer1\Application Data\Sun\Java\Deployment\SystemCache\6.0\32\6c34baa0-77654f70.idx
2011-12-22 23:35 . 2011-12-22 23:35   2280   --s-a-w-   c:\documents and settings\customer1\Application Data\Microsoft\CryptnetUrlCache\Content\135BD6A358680A7BF1CCEC7C0172393D
2011-12-22 23:35 . 2011-12-22 23:35   132   --s-a-w-   c:\documents and settings\customer1\Application Data\Microsoft\CryptnetUrlCache\MetaData\135BD6A358680A7BF1CCEC7C0172393D
2011-12-22 23:33 . 2012-01-04 14:21   12738   ----a-w-   c:\documents and settings\customer1\Application Data\Real\Update\UpgradeHelper\RealPlayer\9.01\stub_data\stubinst_config_en.xml
2011-12-22 23:33 . 2011-12-22 23:33   315512   ----a-w-   c:\documents and settings\customer1\Application Data\Real\Update\UpgradeHelper\RealPlayer\9.01\rnupgagent.exe
2011-11-06 02:57 . 2011-11-06 02:57   18212   --sh--w-   c:\documents and settings\customer1\My Documents\New limewire songs\AlbumArt_{B5FC4FDE-E275-4DA2-91E7-0CF3709667E4}_Large.jpg
2011-11-06 02:57 . 2011-11-06 02:57   3755   --sh--w-   c:\documents and settings\customer1\My Documents\New limewire songs\AlbumArtSmall.jpg
2011-11-06 02:57 . 2011-11-06 02:57   3755   --sh--w-   c:\documents and settings\customer1\My Documents\New limewire songs\AlbumArt_{B5FC4FDE-E275-4DA2-91E7-0CF3709667E4}_Small.jpg
2011-11-06 02:55 . 2012-03-17 05:20   362   --sh--w-   c:\documents and settings\customer1\My Documents\My Music\Unknown Artist\desktop.ini
2011-11-04 21:39 . 2012-03-02 20:55   2249   --s-a-w-   c:\documents and settings\customer1\Application Data\Microsoft\CryptnetUrlCache\Content\E8974A4669383843486E5AFDB09650F5
2011-11-04 21:39 . 2012-03-02 20:55   124   --s-a-w-   c:\documents and settings\customer1\Application Data\Microsoft\CryptnetUrlCache\MetaData\E8974A4669383843486E5AFDB09650F5
2011-11-04 21:39 . 2011-12-22 23:30   1310   --s-a-w-   c:\documents and settings\customer1\Application Data\Microsoft\CryptnetUrlCache\Content\C554DCF706A5AAB8B360FAD227EAB9C7
2011-11-04 21:39 . 2011-12-22 23:30   100   --s-a-w-   c:\documents and settings\customer1\Application Data\Microsoft\CryptnetUrlCache\MetaData\C554DCF706A5AAB8B360FAD227EAB9C7
2011-11-04 18:03 . 2011-11-04 18:03   388   --sha-w-   c:\documents and settings\customer1\Application Data\Microsoft\Protect\S-1-5-21-73586283-842925246-725345543-1004\ccf32877-fec7-49ae-bc4a-4ac6ce8bbffb
2011-07-03 18:03 . 2011-07-03 18:03   388   --sha-w-   c:\documents and settings\customer1\Application Data\Microsoft\Protect\S-1-5-21-73586283-842925246-725345543-1004\457775d9-6c31-4048-81ca-7e1e9d5e83f7
2011-04-01 22:33 . 2011-04-01 22:33   388   --sha-w-   c:\documents and settings\customer1\Application Data\Microsoft\Protect\S-1-5-21-73586283-842925246-725345543-1004\dfff9f05-7ed5-499f-80ff-fc67e20381ca
2010-07-23 06:04 . 2010-07-23 06:04   388   --sha-w-   c:\documents and settings\customer1\Application Data\Microsoft\Protect\S-1-5-21-73586283-842925246-725345543-1004\f3a8bb5d-bedf-46fc-a439-3ebefac7bf6f
2010-06-14 12:58 . 2010-06-14 12:58   2006900   ----a-w-   c:\documents and settings\customer1\My Documents\My Pictures\Photo Shoot\Copy of Photo Shoot 001.jpg
2010-06-13 22:02 . 2010-06-13 22:38   1858100   ----a-w-   c:\documents and settings\customer1\My Documents\My Pictures\Photo Shoot\Photo Shoot 153.jpg
2010-06-13 22:02 . 2010-06-13 22:38   1828186   ----a-w-   c:\documents and settings\customer1\My Documents\My Pictures\Photo Shoot\Photo Shoot 152.jpg
2010-06-13 22:02 . 2010-06-13 22:38   1823427   ----a-w-   c:\documents and settings\customer1\My Documents\My Pictures\Photo Shoot\Photo Shoot 151.jpg
2010-06-13 22:02 . 2010-06-13 22:38   1821052   ----a-w-   c:\documents and settings\customer1\My Documents\My Pictures\Photo Shoot\Photo Shoot 150.jpg
2010-06-13 22:01 . 2010-06-13 22:38   1753659   ----a-w-   c:\documents and settings\customer1\My Documents\My Pictures\Photo Shoot\Photo Shoot 149.jpg
2010-06-13 22:01 . 2010-06-13 22:38   1845445   ----a-w-   c:\documents and settings\customer1\My Documents\My Pictures\Photo Shoot\Photo Shoot 148.jpg
2010-06-13 22:01 . 2010-06-13 22:38   1901964   ----a-w-   c:\documents and settings\customer1\My Documents\My Pictures\Photo Shoot\Photo Shoot 147.jpg
2010-06-13 22:01 . 2010-06-13 22:38   1907079   ----a-w-   c:\documents and settings\customer1\My Documents\My Pictures\Photo Shoot\Photo Shoot 146.jpg
2010-06-13 22:01 . 2010-06-13 22:38   1946355   ----a-w-   c:\documents and settings\customer1\My Documents\My Pictures\Photo Shoot\Photo Shoot 145.jpg
2010-06-13 22:01 . 2010-06-13 22:38   1922649   ----a-w-   c:\documents and settings\customer1\My Documents\My Pictures\Photo Shoot\Photo Shoot 144.jpg
2010-06-13 22:01 . 2010-06-13 22:38   1768761   ----a-w-   c:\documents and settings\customer1\My Documents\My Pictures\Photo Shoot\Photo Shoot 143.jpg
2010-06-13 22:01 . 2010-06-13 22:38   1829201   ----a-w-   c:\documents and settings\customer1\My Documents\My Pictures\Photo Shoot\Photo Shoot 142.jpg
2010-06-13 22:01 . 2010-06-13 22:38   1817202   ----a-w-   c:\documents and settings\customer1\My Documents\My Pictures\Photo Shoot\Photo Shoot 141.jpg
2010-06-13 22:00 . 2010-06-13 22:38   1910527   ----a-w-   c:\documents and settings\customer1\My Documents\My Pictures\Photo Shoot\Photo Shoot 140.jpg
2010-06-13 22:00 . 2010-06-13 22:38   1872165   ----a-w-   c:\documents and settings\customer1\My Documents\My Pictures\Photo Shoot\Photo Shoot 139.jpg
2010-06-13 22:00 . 2010-06-13 22:38   1871216   ----a-w-   c:\documents and settings\customer1\My Documents\My Pictures\Photo Shoot\Photo Shoot 138.jpg
2010-06-13 22:00 . 2010-06-13 22:38   1898032   ----a-w-   c:\documents and settings\customer1\My Documents\My Pictures\Photo Shoot\Photo Shoot 137.jpg
2010-06-13 22:00 . 2010-06-13 22:55   1877144   ----a-w-   c:\documents and settings\customer1\My Documents\My Pictures\Photo Shoot\Photo Shoot 136.jpg
2010-06-13 22:00 . 2010-06-13 22:55   1933276   ----a-w-   c:\documents and settings\customer1\My Documents\My Pictures\Photo Shoot\Photo Shoot 135.jpg
2010-06-13 21:59 . 2010-06-13 22:38   1803111   ----a-w-   c:\documents and settings\customer1\My Documents\My Pictures\Photo Shoot\Photo Shoot 134.jpg
2010-06-13 21:59 . 2010-06-13 22:38   1862413   ----a-w-   c:\documents and settings\customer1\My Documents\My Pictures\Photo Shoot\Photo Shoot 133.jpg
2010-06-13 21:58 . 2010-06-13 22:38   1959782   ----a-w-   c:\documents and settings\customer1\My Documents\My Pictures\Photo Shoot\Photo Shoot 132.jpg
2010-06-13 21:58 . 2010-06-13 22:38   2030706   ----a-w-   c:\documents and settings\customer1\My Documents\My Pictures\Photo Shoot\Photo Shoot 131.jpg
2010-06-13 21:58 . 2010-06-13 22:55   1829271   ----a-w-   c:\documents and settings\customer1\My Documents\My Pictures\Photo Shoot\Photo Shoot 130.jpg
2010-06-13 21:58 . 2010-06-13 22:55   2036023   ----a-w-   c:\documents and settings\customer1\My Documents\My Pictures\Photo Shoot\Photo Shoot 129.jpg
2010-06-13 21:50 . 2010-06-13 22:55   2177674   ----a-w-   c:\documents and settings\customer1\My Documents\My Pictures\Photo Shoot\Photo Shoot 128.jpg
2010-06-13 21:50 . 2010-06-13 22:55   2161923   ----a-w-   c:\documents and settings\customer1\My Documents\My Pictures\Photo Shoot\Photo Shoot 127.jpg
2010-06-13 21:50 . 2010-06-13 22:55   2123000   ----a-w-   c:\documents and settings\customer1\My Documents\My Pictures\Photo Shoot\Photo Shoot 126.jpg
2010-06-13 21:50 . 2010-06-13 22:55   2137463   ----a-w-   c:\documents and settings\customer1\My Documents\My Pictures\Photo Shoot\Photo Shoot 125.jpg
2010-06-13 21:50 . 2010-06-13 22:55   2128977   ----a-w-   c:\documents and settings\customer1\My Documents\My Pictures\Photo Shoot\Photo Shoot 124.jpg
2010-06-13 21:50 . 2010-06-13 22:55   2111729   ----a-w-   c:\documents and settings\customer1\My Documents\My Pictures\Photo Shoot\Photo Shoot 123.jpg
2010-06-13 21:50 . 2010-06-13 22:55   2124514   ----a-w-   c:\documents and settings\customer1\My Documents\My Pictures\Photo Shoot\Photo Shoot 122.jpg
2010-06-13 21:50 . 2010-06-13 22:55   2082726   ----a-w-   c:\documents and settings\customer1\My Documents\My Pictures\Photo Shoot\Photo Shoot 121.jpg
2010-06-13 21:50 . 2010-06-13 22:55   2160971   ----a-w-   c:\documents and settings\customer1\My Documents\My Pictures\Photo Shoot\Photo Shoot 120.jpg
2010-06-13 21:50 . 2010-06-13 22:55   2107070   ----a-w-   c:\documents and settings\customer1\My Documents\My Pictures\Photo Shoot\Photo Shoot 119.jpg
2010-06-13 21:49 . 2010-06-13 22:55   2167744   ----a-w-   c:\documents and settings\customer1\My Documents\My Pictures\Photo Shoot\Photo Shoot 118.jpg
2010-06-13 21:47 . 2010-06-13 22:37   2149487   ----a-w-   c:\documents and settings\customer1\My Documents\My Pictures\Photo Shoot\Photo Shoot 117.jpg
2010-06-13 21:47 . 2010-06-13 22:37   2143895   ----a-w-   c:\documents and settings\customer1\My Documents\My Pictures\Photo Shoot\Photo Shoot 116.jpg
2010-06-13 21:47 . 2010-06-13 22:37   2132190   ----a-w-   c:\documents and settings\customer1\My Documents\My Pictures\Photo Shoot\Photo Shoot 115.jpg
2010-06-13 21:46 . 2010-06-13 22:37   2121959   ----a-w-   c:\documents and settings\customer1\My Documents\My Pictures\Photo Shoot\Photo Shoot 114.jpg
2010-06-13 21:46 . 2010-06-13 22:37   2124318   ----a-w-   c:\documents and settings\customer1\My Documents\My Pictures\Photo Shoot\Photo Shoot 113.jpg
2010-06-13 21:46 . 2010-06-13 22:37   2182904   ----a-w-   c:\documents and settings\customer1\My Documents\My Pictures\Photo Shoot\Photo Shoot 112.jpg
2010-06-13 21:45 . 2010-06-13 22:55   2023992   ----a-w-   c:\documents and settings\customer1\My Documents\My Pictures\Photo Shoot\Photo Shoot 111.jpg
2010-06-13 21:45 . 2010-06-13 22:55   1901548   ----a-w-   c:\documents and settings\customer1\My Documents\My Pictures\Photo Shoot\Photo Shoot 110.jpg
2010-06-13 21:45 . 2010-06-13 22:55   2067243   ----a-w-   c:\documents and settings\customer1\My Documents\My Pictures\Photo Shoot\Photo Shoot 109.jpg
2010-06-13 21:45 . 2010-06-13 22:55   1650370   ----a-w-   c:\documents and settings\customer1\My Documents\My Pictures\Photo Shoot\Photo Shoot 108.jpg
2010-06-13 21:45 . 2010-06-13 22:55   2035536   ----a-w-   c:\documents and settings\customer1\My Documents\My Pictures\Photo Shoot\Photo Shoot 107.jpg
2010-06-13 21:45 . 2010-06-13 22:55   2139647   ----a-w-   c:\documents and settings\customer1\My Documents\My Pictures\Photo Shoot\Photo Shoot 106.jpg
2010-06-13 21:45 . 2010-06-13 22:55   2086951   ----a-w-   c:\documents and settings\customer1\My Documents\My Pictures\Photo Shoot\Photo Shoot 105.jpg
2010-06-13 21:44 . 2010-06-13 22:55   1936361   ----a-w-   c:\documents and settings\customer1\My Documents\My Pictures\Photo Shoot\Photo Shoot 104.jpg
2010-06-13 21:44 . 2010-06-13 22:55   2049026   ----a-w-   c:\documents and settings\customer1\My Documents\My Pictures\Photo Shoot\Photo Shoot 103.jpg
2010-06-13 21:44 . 2010-06-13 22:55   1825570   ----a-w-   c:\documents and settings\customer1\My Documents\My Pictures\Photo Shoot\Photo Shoot 102.jpg
2010-06-13 21:44 . 2010-06-13 22:55   1835802   ----a-w-   c:\documents and settings\customer1\My Documents\My Pictures\Photo Shoot\Photo Shoot 101.jpg
2010-06-13 21:44 . 2010-06-13 22:55   2060957   ----a-w-   c:\documents and settings\customer1\My Documents\My Pictures\Photo Shoot\Photo Shoot 100.jpg
2010-06-13 21:44 . 2010-06-13 22:55   1885128   ----a-w-   c:\documents and settings\customer1\My Documents\My Pictures\Photo Shoot\Photo Shoot 099.jpg
2010-06-13 21:44 . 2010-06-13 22:55   2010066   ----a-w-   c:\documents and settings\customer1\My Documents\My Pictures\Photo Shoot\Photo Shoot 098.jpg
2010-06-13 21:44 . 2010-06-13 22:55   2223541   ----a-w-   c:\documents and settings\customer1\My Documents\My Pictures\Photo Shoot\Photo Shoot 097.jpg
2010-06-13 21:43 . 2010-06-13 22:55   2226658   ----a-w-   c:\documents and settings\customer1\My Documents\My Pictures\Photo Shoot\Photo Shoot 096.jpg
2010-06-13 21:43 . 2010-06-13 22:55   2016814   ----a-w-   c:\documents and settings\customer1\My Documents\My Pictures\Photo Shoot\Photo Shoot 095.jpg
2010-06-13 21:43 . 2010-06-13 22:55   2041400   ----a-w-   c:\documents and settings\customer1\My Documents\My Pictures\Photo Shoot\Photo Shoot 094.jpg
2010-06-13 21:42 . 2010-06-13 22:55   2143188   ----a-w-   c:\documents and settings\customer1\My Documents\My Pictures\Photo Shoot\Photo Shoot 093.jpg
2010-06-13 21:42 . 2010-06-13 22:55   2011060   ----a-w-   c:\documents and settings\customer1\My Documents\My Pictures\Photo Shoot\Photo Shoot 092.jpg
2010-06-13 21:42 . 2010-06-13 22:55   2123780   ----a-w-   c:\documents and settings\customer1\My Documents\My Pictures\Photo Shoot\Photo Shoot 091.jpg
2010-06-13 21:42 . 2010-06-13 22:55   2188079   ----a-w-   c:\documents and settings\customer1\My Documents\My Pictures\Photo Shoot\Photo Shoot 090.jpg
2010-06-13 21:42 . 2010-06-13 22:55   2175893   ----a-w-   c:\documents and settings\customer1\My Documents\My Pictures\Photo Shoot\Photo Shoot 089.jpg
2010-06-13 21:41 . 2010-06-13 22:55   2158007   ----a-w-   c:\documents and settings\customer1\My Documents\My Pictures\Photo Shoot\Photo Shoot 088.jpg
2010-06-13 21:37 . 2010-06-13 22:55   2091109   ----a-w-   c:\documents and settings\customer1\My Documents\My Pictures\Photo Shoot\Photo Shoot 087.jpg
2010-06-13 21:36 . 2010-06-13 22:55   2117087   ----a-w-   c:\documents and settings\customer1\My Documents\My Pictures\Photo Shoot\Photo Shoot 085.jpg
2010-06-13 21:35 . 2010-06-13 22:55   2033679   ----a-w-   c:\documents and settings\customer1\My Documents\My Pictures\Photo Shoot\Photo Shoot 084.jpg
2010-06-13 21:35 . 2010-06-13 22:55   2114553   ----a-w-   c:\documents and settings\customer1\My Documents\My Pictures\Photo Shoot\Photo Shoot 083.jpg
2010-06-13 21:35 . 2010-06-13 22:55   2062314   ----a-w-   c:\documents and settings\customer1\My Documents\My Pictures\Photo Shoot\Photo Shoot 082.jpg
2010-06-13 21:34 . 2010-06-13 22:55   2110521   ----a-w-   c:\documents and settings\customer1\My Documents\My Pictures\Photo Shoot\Photo Shoot 081.jpg
2010-06-13 21:34 . 2010-06-13 22:55   2145200   ----a-w-   c:\documents and settings\customer1\My Documents\My Pictures\Photo Shoot\Photo Shoot 080.jpg
2010-06-13 21:34 . 2010-06-13 22:55   2103338   ----a-w-   c:\documents and settings\customer1\My Documents\My Pictures\Photo Shoot\Photo Shoot 079.jpg
2010-06-13 21:34 . 2010-06-13 22:55   2107031   ----a-w-   c:\documents and settings\customer1\My Documents\My Pictures\Photo Shoot\Photo Shoot 078.jpg
2010-06-13 21:33 . 2010-06-13 22:55   2055864   ----a-w-   c:\documents and settings\customer1\My Documents\My Pictures\Photo Shoot\Photo Shoot 077.jpg
2010-06-13 21:33 . 2010-06-13 22:55   1950495   ----a-w-   c:\documents and settings\customer1\My Documents\My Pictures\Photo Shoot\Photo Shoot 076.jpg
2010-06-13 21:32 . 2010-06-13 22:55   2062356   ----a-w-   c:\documents and settings\customer1\My Documents\My Pictures\Photo Shoot\Photo Shoot 075.jpg
2010-06-13 21:32 . 2010-06-13 22:36   2029147   ----a-w-   c:\documents and settings\customer1\My Documents\My Pictures\Photo Shoot\Photo Shoot 074.jpg
2010-06-13 21:32 . 2010-06-13 22:36   2061081   ----a-w-   c:\documents and settings\customer1\My Documents\My Pictures\Photo Shoot\Photo Shoot 073.jpg
2010-06-13 21:30 . 2010-06-13 22:36   2021330   ----a-w-   c:\documents and settings\customer1\My Documents\My Pictures\Photo Shoot\Photo Shoot 072.jpg
2010-06-13 21:29 . 2010-06-13 22:36   1978842   ----a-w-   c:\documents and settings\customer1\My Documents\My Pictures\Photo Shoot\Photo Shoot 071.jpg
2010-06-13 21:29 . 2010-06-13 22:36   1974399   ----a-w-   c:\documents and settings\customer1\My Documents\My Pictures\Photo Shoot\Photo Shoot 070.jpg
2010-06-13 21:29 . 2010-06-13 22:36   1932300   ----a-w-   c:\documents and settings\customer1\My Documents\My Pictures\Photo Shoot\Photo Shoot 069.jpg
2010-06-13 21:29 . 2010-06-13 22:36   1995317   ----a-w-   c:\documents and settings\customer1\My Documents\My Pictures\Photo Shoot\Photo Shoot 068.jpg
2010-06-13 21:29 . 2010-06-13 22:36   1992429   ----a-w-   c:\documents and settings\customer1\My Documents\My Pictures\Photo Shoot\Photo Shoot 067.jpg
2010-06-13 21:28 . 2010-06-13 22:55   1957168   ----a-w-   c:\documents and settings\customer1\My Documents\My Pictures\Photo Shoot\Photo Shoot 066.jpg
2010-06-13 21:28 . 2010-06-13 22:55   1993272   ----a-w-   c:\documents and settings\customer1\My Documents\My Pictures\Photo Shoot\Photo Shoot 065.jpg
2010-06-13 21:28 . 2010-06-13 22:55   2055094   ----a-w-   c:\documents and settings\customer1\My Documents\My Pictures\Photo Shoot\Photo Shoot 064.jpg
2010-06-13 21:28 . 2010-06-13 22:55   2059033   ----a-w-   c:\documents and settings\customer1\My Documents\My Pictures\Photo Shoot\Photo Shoot 063.jpg
2010-06-13 21:28 . 2010-06-13 22:55   2058338   ----a-w-   c:\documents and settings\customer1\My Documents\My Pictures\Photo Shoot\Photo Shoot 062.jpg
2010-06-13 21:27 . 2010-06-13 22:55   2053014   ----a-w-   c:\documents and settings\customer1\My Documents\My Pictures\Photo Shoot\Photo Shoot 061.jpg
2010-06-13 21:27 . 2010-06-13 22:55   2048243   ----a-w-   c:\documents and settings\customer1\My Documents\My Pictures\Photo Shoot\Photo Shoot 060.jpg
2010-06-13 21:27 . 2010-06-13 22:55   2033129   ----a-w-   c:\documents and settings\customer1\My Documents\My Pictures\Photo Shoot\Photo Shoot 059.jpg
2010-06-13 21:27 . 2010-06-13 22:55   2050125   ----a-w-   c:\documents and settings\customer1\My Documents\My Pictures\Photo Shoot\Photo Shoot 058.jpg
2010-06-13 21:27 . 2010-06-13 22:55   2046397   ----a-w-   c:\documents and settings\customer1\My Documents\My Pictures\Photo Shoot\Photo Shoot 057.jpg
2010-06-13 21:27 . 2010-06-13 22:55   2050505   ----a-w-   c:\documents and settings\customer1\My Documents\My Pictures\Photo Shoot\Photo Shoot 056.jpg
2010-06-13 21:27 . 2010-06-13 22:55   2133194   ----a-w-   c:\documents and settings\customer1\My Documents\My Pictures\Photo Shoot\Photo Shoot 055.jpg
2010-06-13 21:26 . 2010-06-13 22:35   2017496   ----a-w-   c:\documents and settings\customer1\My Documents\My Pictures\Photo Shoot\Photo Shoot 054.jpg
2010-06-13 21:25 . 2010-06-13 22:35   2027605   ----a-w-   c:\documents and settings\customer1\My Documents\My Pictures\Photo Shoot\Photo Shoot 053.jpg
2010-06-13 21:25 . 2010-06-13 22:55   2057425   ----a-w-   c:\documents and settings\customer1\My Documents\My Pictures\Photo Shoot\Photo Shoot 052.jpg
2010-06-13 21:23 . 2010-06-13 22:55   2100588   ----a-w-   c:\documents and settings\customer1\My Documents\My Pictures\Photo Shoot\Photo Shoot 050.jpg
2010-06-13 21:22 . 2010-06-13 22:35   2037251   ----a-w-   c:\documents and settings\customer1\My Documents\My Pictures\Photo Shoot\Photo Shoot 049.jpg
2010-06-13 21:22 . 2010-06-13 22:55   2011779   ----a-w-   c:\documents and settings\customer1\My Documents\My Pictures\Photo Shoot\Photo Shoot 048.jpg
2010-06-13 21:22 . 2010-06-13 22:55   2138750   ----a-w-   c:\documents and settings\customer1\My Documents\My Pictures\Photo Shoot\Photo Shoot 047.jpg
2010-06-13 21:22 . 2010-06-13 22:55   1966928   ----a-w-   c:\documents and settings\customer1\My Documents\My Pictures\Photo Shoot\Photo Shoot 046.jpg
2010-06-13 21:21 . 2010-06-13 22:55   1945531   ----a-w-   c:\documents and settings\customer1\My Documents\My Pictures\Photo Shoot\Photo Shoot 045.jpg
2010-06-13 21:21 . 2010-06-13 22:55   2063434   ----a-w-   c:\documents and settings\customer1\My Documents\My Pictures\Photo Shoot\Photo Shoot 043.jpg
2010-06-13 21:07 . 2010-06-13 22:54   2184904   ----a-w-   c:\documents and settings\customer1\My Documents\My Pictures\Photo Shoot\Photo Shoot 041.jpg
2010-06-13 21:07 . 2010-06-13 22:35   2203095   ----a-w-   c:\documents and settings\customer1\My Documents\My Pictures\Photo Shoot\Photo Shoot 040.jpg
2010-06-13 21:06 . 2010-06-13 22:35   2234557   ----a-w-   c:\documents and settings\customer1\My Documents\My Pictures\Photo Shoot\Photo Shoot 039.jpg
2010-06-13 21:06 . 2010-06-13 22:54   2125634   ----a-w-   c:\documents and settings\customer1\My Documents\My Pictures\Photo Shoot\Photo Shoot 038.jpg
2010-06-13 21:06 . 2010-06-13 22:54   2078775   ----a-w-   c:\documents and settings\customer1\My Documents\My Pictures\Photo Shoot\Photo Shoot 037.jpg
2010-06-13 21:05 . 2010-06-13 22:54   2151541   ----a-w-   c:\documents and settings\customer1\My Documents\My Pictures\Photo Shoot\Photo Shoot 036.jpg
2010-06-13 21:05 . 2010-06-13 22:54   2044086   ----a-w-   c:\documents and settings\customer1\My Documents\My Pictures\Photo Shoot\Photo Shoot 035.jpg
2010-06-13 21:03 . 2010-06-13 22:54   2076632   ----a-w-   c:\documents and settings\customer1\My Documents\My Pictures\Photo Shoot\Photo Shoot 032.jpg
2010-06-13 21:03 . 2010-06-13 22:54   2180067   ----a-w-   c:\documents and settings\customer1\My Documents\My Pictures\Photo Shoot\Photo Shoot 031.jpg
2010-06-13 21:03 . 2010-06-13 22:54   2158336   ----a-w-   c:\documents and settings\customer1\My Documents\My Pictures\Photo Shoot\Photo Shoot 030.jpg
2010-06-13 21:02 . 2010-06-13 22:54   2137252   ----a-w-   c:\documents and settings\customer1\My Documents\My Pictures\Photo Shoot\Photo Shoot 029.jpg
2010-06-13 21:02 . 2010-06-13 22:54   2173388   ----a-w-   c:\documents and settings\customer1\My Documents\My Pictures\Photo Shoot\Photo Shoot 028.jpg
2010-06-13 20:46 . 2010-06-13 22:54   2100838   ----a-w-   c:\documents and settings\customer1\My Documents\My Pictures\Photo Shoot\Photo Shoot 027.jpg
2010-06-13 20:45 . 2010-06-13 22:54   2176206   ----a-w-   c:\documents and settings\customer1\My Documents\My Pictures\Photo Shoot\Photo Shoot 026.jpg
2010-06-13 20:45 . 2010-06-13 22:54   1947524   ----a-w-   c:\documents and settings\customer1\My Documents\My Pictures\Photo Shoot\Photo Shoot 025.jpg
2010-06-13 20:45 . 2010-06-13 22:54   1973911   ----a-w-   c:\documents and settings\customer1\My Documents\My Pictures\Photo Shoot\Photo Shoot 024.jpg
2010-06-13 20:44 . 2010-06-13 22:54   1987614   ----a-w-   c:\documents and settings\customer1\My Documents\My Pictures\Photo Shoot\Photo Shoot 023.jpg
2010-06-13 20:44 . 2010-06-13 22:54   1942439   ----a-w-   c:\documents and settings\customer1\My Documents\My Pictures\Photo Shoot\Photo Shoot 022.jpg
2010-06-13 20:42 . 2010-06-13 22:34   1975209   ----a-w-   c:\documents and settings\customer1\My Documents\My Pictures\Photo Shoot\Photo Shoot 021.jpg
2010-06-13 20:41 . 2010-06-13 22:34   1948657   ----a-w-   c:\documents and settings\customer1\My Documents\My Pictures\Photo Shoot\Photo Shoot 020.jpg
2010-06-13 20:41 . 2010-06-13 22:34   1992866   ----a-w-   c:\documents and settings\customer1\My Documents\My Pictures\Photo Shoot\Photo Shoot 019.jpg
2010-06-13 20:41 . 2010-06-13 22:34   1951990   ----a-w-   c:\documents and settings\customer1\My Documents\My Pictures\Photo Shoot\Photo Shoot 018.jpg
2010-06-13 20:41 . 2010-06-13 22:34   2026120   ----a-w-   c:\documents and settings\customer1\My Documents\My Pictures\Photo Shoot\Photo Shoot 017.jpg
2010-06-13 20:40 . 2010-06-13 22:34   1957199   ----a-w-   c:\documents and settings\customer1\My Documents\My Pictures\Photo Shoot\Photo Shoot 016.jpg
2010-06-13 20:40 . 2010-06-13 22:34   1966595   ----a-w-   c:\documents and settings\customer1\My Documents\My Pictures\Photo Shoot\Photo Shoot 015.jpg
2010-06-13 20:40 . 2010-06-13 22:34   1954237   ----a-w-   c:\documents and settings\customer1\My Documents\My Pictures\Photo Shoot\Photo Shoot 014.jpg
2010-06-13 20:29 . 2010-06-13 22:54   2104746   ----a-w-   c:\documents and settings\customer1\My Documents\My Pictures\Photo Shoot\Photo Shoot 013.jpg
2010-06-13 20:29 . 2010-06-13 22:54   2051647   ----a-w-   c:\documents and settings\customer1\My Documents\My Pictures\Photo Shoot\Photo Shoot 012.jpg
2010-06-13 20:29 . 2010-06-13 22:54   2077357   ----a-w-   c:\documents and settings\customer1\My Documents\My Pictures\Photo Shoot\Photo Shoot 011.jpg
2010-06-13 20:28 . 2010-06-13 22:54   1912136   ----a-w-   c:\documents and settings\customer1\My Documents\My Pictures\Photo Shoot\Photo Shoot 010.jpg
2010-06-13 20:28 . 2010-06-13 22:54   2036037   ----a-w-   c:\documents and settings\customer1\My Documents\My Pictures\Photo Shoot\Photo Shoot 009.jpg
2010-06-13 20:27 . 2010-06-13 22:54   2013202   ----a-w-   c:\documents and settings\customer1\My Documents\My Pictures\Photo Shoot\Photo Shoot 008.jpg
2010-06-13 20:26 . 2010-06-13 22:54   2134656   ----a-w-   c:\documents and settings\customer1\My Documents\My Pictures\Photo Shoot\Photo Shoot 007.jpg
2010-06-13 20:26 . 2010-06-13 22:53   2084729   ----a-w-   c:\documents and settings\customer1\My Documents\My Pictures\Photo Shoot\Photo Shoot 006.jpg
2010-06-12 15:17 . 2010-06-13 22:34   2063207   ----a-w-   c:\documents and settings\customer1\My Documents\My Pictures\Photo Shoot\Photo Shoot 005.jpg
2010-06-12 01:04 . 2010-06-13 22:33   2163840   ----a-w-   c:\documents and settings\customer1\My Documents\My Pictures\Photo Shoot\Photo Shoot 004.jpg
2010-06-12 01:04 . 2010-06-13 22:33   2039173   ----a-w-   c:\documents and settings\customer1\My Documents\My Pictures\Photo Shoot\Photo Shoot 003.jpg
2010-06-12 01:03 . 2010-06-14 13:04   1982711   ----a-w-   c:\documents and settings\customer1\My Documents\My Pictures\Photo Shoot\Photo Shoot 002.jpg
2010-06-12 00:28 . 2010-06-13 22:33   2006900   ----a-w-   c:\documents and settings\customer1\My Documents\My Pictures\Photo Shoot\Photo Shoot 001.jp

Offline kcrawhorn

  • Bronze Member
  • Posts: 126
Re: [In Progress B]AVG found Trojan Horse Crypt.ASHD
« Reply #14 on: March 29, 2012, 03:53:52 PM »
g
2010-05-07 04:12 . 2010-05-07 04:12   275   ----a-w-   c:\documents and settings\customer1\My Documents\Incomplete\downloads.dat
2010-04-17 16:21 . 2010-04-17 16:21   388   --sha-w-   c:\documents and settings\customer1\Application Data\Microsoft\Protect\S-1-5-21-73586283-842925246-725345543-1004\6e84cd37-4d59-4b9a-99de-a5357671bddc
2010-01-26 21:34 . 2012-03-17 05:21   3573259   ----a-w-   c:\documents and settings\customer1\My Documents\My Music\Fall Out Boy\Believers Never Die- The Greatest Hits Disc 1\15 Alpha Dog
  • .wma

2010-01-26 21:33 . 2012-03-17 05:21   3555331   ----a-w-   c:\documents and settings\customer1\My Documents\My Music\Fall Out Boy\Believers Never Die- The Greatest Hits Disc 1\13 America's Suitehearts.wma
2010-01-26 21:33 . 2012-03-17 05:21   3698755   ----a-w-   c:\documents and settings\customer1\My Documents\My Music\Fall Out Boy\Believers Never Die- The Greatest Hits Disc 1\11 Beat It.wma
2010-01-26 21:33 . 2012-03-17 05:21   3441787   ----a-w-   c:\documents and settings\customer1\My Documents\My Music\Fall Out Boy\Believers Never Die- The Greatest Hits Disc 1\07 This Ain't a Scene, It's an Arms Race.wma
2010-01-26 21:28 . 2012-03-17 05:25   3178793   ----a-w-   c:\documents and settings\customer1\My Documents\My Music\Hollywood Undead\Swan Songs [Clean]\10 California.wma
2010-01-26 21:27 . 2012-03-17 05:25   3166841   ----a-w-   c:\documents and settings\customer1\My Documents\My Music\Hollywood Undead\Swan Songs [Clean]\06 Young.wma
2010-01-26 21:27 . 2012-03-17 05:25   3405881   ----a-w-   c:\documents and settings\customer1\My Documents\My Music\Hollywood Undead\Swan Songs [Clean]\03 Everywhere I Go.wma
2010-01-26 21:26 . 2012-03-17 05:25   4302281   ----a-w-   c:\documents and settings\customer1\My Documents\My Music\Hollywood Undead\Swan Songs [Clean]\01 Undead.wma
2010-01-26 21:24 . 2010-01-26 21:24   2420   ----a-w-   c:\documents and settings\customer1\My Documents\My Music\My Playlists\fight M.I.R.A..wpl
2010-01-26 21:24 . 2010-01-26 21:24   2407   ----a-w-   c:\documents and settings\customer1\My Documents\My Music\My Playlists\R.wpl
2010-01-26 21:21 . 2012-03-17 05:21   3877961   ----a-w-   c:\documents and settings\customer1\My Documents\My Music\Unknown Artist\Unknown Album (1-26-2010 3-16-17 PM)\02 Track 2.wma
2010-01-26 21:20 . 2012-03-17 05:21   3023393   ----a-w-   c:\documents and settings\customer1\My Documents\My Music\Unknown Artist\Unknown Album (1-26-2010 3-16-17 PM)\01 Track 1.wma
2010-01-26 20:56 . 2010-01-26 21:32   2848   ----a-w-   c:\documents and settings\customer1\My Documents\My Music\My Playlists\fight M.I.R.A.wpl
2010-01-26 20:43 . 2012-02-06 17:23   5360109   ----a-w-   c:\documents and settings\customer1\My Documents\My Music\Unknown Artist\Unknown Album (2-6-2012 11-23-24 AM)\17 17 17 17 Track 17.wma
2010-01-26 20:43 . 2012-02-06 17:23   4021485   ----a-w-   c:\documents and settings\customer1\My Documents\My Music\Unknown Artist\Unknown Album (2-6-2012 11-23-24 AM)\15 15 15 15 Track 15.wma
2010-01-26 20:43 . 2012-02-06 17:23   4087221   ----a-w-   c:\documents and settings\customer1\My Documents\My Music\Unknown Artist\Unknown Album (2-6-2012 11-23-24 AM)\14 14 14 Track 14.wma
2010-01-26 20:42 . 2012-02-06 17:23   3382053   ----a-w-   c:\documents and settings\customer1\My Documents\My Music\Unknown Artist\Unknown Album (2-6-2012 11-23-24 AM)\12 12 12 12 Track 12.wma
2010-01-26 20:42 . 2010-01-26 20:42   3214725   ----a-w-   c:\documents and settings\customer1\My Documents\My Music\Unknown Artist\Unknown Album (1-26-2010 2-30-20 PM)\11 Track 11.wma
2010-01-26 20:42 . 2012-02-06 17:23   3746589   ----a-w-   c:\documents and settings\customer1\My Documents\My Music\Unknown Artist\Unknown Album (2-6-2012 11-23-24 AM)\10 10 10 Track 10.wma
2010-01-26 20:42 . 2012-02-06 17:23   3322293   ----a-w-   c:\documents and settings\customer1\My Documents\My Music\Unknown Artist\Unknown Album (2-6-2012 11-23-24 AM)\08 08 08 08 Track 8.wma
2010-01-26 20:42 . 2012-02-06 17:23   1684869   ----a-w-   c:\documents and settings\customer1\My Documents\My Music\Unknown Artist\Unknown Album (2-6-2012 11-23-24 AM)\07 07 07 07 Track 7.wma
2010-01-26 20:41 . 2012-02-06 17:23   3364125   ----a-w-   c:\documents and settings\customer1\My Documents\My Music\Unknown Artist\Unknown Album (2-6-2012 11-23-24 AM)\05 05 05 05 Track 5.wma
2010-01-26 20:41 . 2012-02-06 17:23   4672869   ----a-w-   c:\documents and settings\customer1\My Documents\My Music\Unknown Artist\Unknown Album (2-6-2012 11-23-24 AM)\04 04 04 Track 4.wma
2010-01-26 20:41 . 2012-02-06 17:23   3495597   ----a-w-   c:\documents and settings\customer1\My Documents\My Music\Unknown Artist\Unknown Album (2-6-2012 11-23-24 AM)\02 02 02 Track 2.wma
2010-01-26 20:40 . 2012-02-06 17:23   5342181   ----a-w-   c:\documents and settings\customer1\My Documents\My Music\Unknown Artist\Unknown Album (2-6-2012 11-23-24 AM)\01 01 01 Track 1.wma
2010-01-26 19:50 . 2012-02-06 17:23   1846145   ----a-w-   c:\documents and settings\customer1\My Documents\My Music\Unknown Artist\Unknown Album (2-6-2012 11-23-24 AM)\01 01 01 01 Track 1.wma
2010-01-26 19:50 . 2012-02-06 17:23   2802305   ----a-w-   c:\documents and settings\customer1\My Documents\My Music\Unknown Artist\Unknown Album (2-6-2012 11-23-23 AM)\14 14 14 14 Track 14.wma
2010-01-26 19:50 . 2012-02-06 17:23   4828169   ----a-w-   c:\documents and settings\customer1\My Documents\My Music\Unknown Artist\Unknown Album (2-6-2012 11-23-23 AM)\13 13 13 13 Track 13.wma
2010-01-26 19:49 . 2012-02-06 17:23   4756457   ----a-w-   c:\documents and settings\customer1\My Documents\My Music\Unknown Artist\Unknown Album (2-6-2012 11-23-23 AM)\12 12 12 Track 12.wma
2010-01-26 19:49 . 2012-02-06 17:32   2611073   ----a-w-   c:\documents and settings\customer1\My Documents\My Music\Unknown Artist\Unknown Album (1-26-2010 1-42-30 PM)\11 Track 11.wma
2010-01-26 19:48 . 2012-02-06 17:23   4571201   ----a-w-   c:\documents and settings\customer1\My Documents\My Music\Unknown Artist\Unknown Album (2-6-2012 11-23-23 AM)\10 10 10 10 Track 10.wma
2010-01-26 19:48 . 2012-02-06 17:23   4499489   ----a-w-   c:\documents and settings\customer1\My Documents\My Music\Unknown Artist\Unknown Album (2-6-2012 11-23-23 AM)\09 09 09 09 Track 9.wma
2010-01-26 19:47 . 2012-02-06 17:23   2306297   ----a-w-   c:\documents and settings\customer1\My Documents\My Music\Unknown Artist\Unknown Album (2-6-2012 11-23-23 AM)\08 08 08 08 Track 8.wma
2010-01-26 19:47 . 2012-02-06 17:23   2969633   ----a-w-   c:\documents and settings\customer1\My Documents\My Music\Unknown Artist\Unknown Album (2-6-2012 11-23-23 AM)\07 07 07 07 Track 7.wma
2010-01-26 19:47 . 2012-02-06 17:23   3848105   ----a-w-   c:\documents and settings\customer1\My Documents\My Music\Unknown Artist\Unknown Album (2-6-2012 11-23-23 AM)\06 06 06 Track 6.wma
2010-01-26 19:46 . 2012-02-06 17:23   5013425   ----a-w-   c:\documents and settings\customer1\My Documents\My Music\Unknown Artist\Unknown Album (2-6-2012 11-23-23 AM)\05 05 05 Track 5.wma
2010-01-26 19:46 . 2012-02-06 17:23   3238553   ----a-w-   c:\documents and settings\customer1\My Documents\My Music\Unknown Artist\Unknown Album (2-6-2012 11-23-23 AM)\04 04 04 Track 4.wma
2010-01-26 19:45 . 2012-02-06 17:23   3854081   ----a-w-   c:\documents and settings\customer1\My Documents\My Music\Unknown Artist\Unknown Album (2-6-2012 11-23-22 AM)\03 03 03 03 Track 3.wma
2010-01-26 19:45 . 2012-02-06 17:23   3160865   ----a-w-   c:\documents and settings\customer1\My Documents\My Music\Unknown Artist\Unknown Album (2-6-2012 11-23-22 AM)\02 02 02 02 Track 2.wma
2010-01-25 21:13 . 2010-01-25 21:25   15872   ----a-w-   c:\documents and settings\customer1\Desktop\Calorie Chart.xls
2010-01-24 21:09 . 2010-01-24 21:09   9240   ----a-w-   c:\documents and settings\customer1\My Documents\My Music\iTunes\iTunes Library.itl
2010-01-24 21:09 . 2010-01-24 21:09   100851   ----a-w-   c:\documents and settings\customer1\Application Data\Apple Computer\SyncServices\Local\schemas.adminarchive
2010-01-24 21:09 . 2010-01-24 21:09   181   ----a-w-   c:\documents and settings\customer1\Application Data\Apple Computer\SyncServices\Local\SyncingClients.plist
2010-01-24 21:09 . 2010-01-24 21:09   17   ----a-w-   c:\documents and settings\customer1\Application Data\Apple Computer\SyncServices\Local\clientdata\928ce871e31e838b84dc3874b86b384438631594\clientname.txt
2010-01-24 21:09 . 2010-01-24 21:09   12   ----a-w-   c:\documents and settings\customer1\Application Data\Apple Computer\SyncServices\Local\clientdata\ebf0f86d30f0f15eb295a85fd1c590756e81420a\clientname.txt
2010-01-24 21:09 . 2010-01-24 21:09   322   ----a-w-   c:\documents and settings\customer1\Application Data\Apple Computer\SyncServices\Local\cleanup.time
2010-01-24 21:09 . 2010-01-24 21:09   2   ----a-w-   c:\documents and settings\customer1\Application Data\Apple Computer\SyncServices\Local\data.version
2010-01-24 21:09 . 2010-01-24 21:09   24576   ----a-w-   c:\documents and settings\customer1\Application Data\Apple Computer\SyncServices\Local\admin.syncdb
2010-01-24 21:09 . 2010-01-24 21:09   77824   ----a-w-   c:\documents and settings\customer1\Application Data\Apple Computer\SyncServices\Local\data.syncdb
2010-01-24 21:09 . 2010-01-24 21:09   73   ----a-w-   c:\documents and settings\customer1\Application Data\Apple Computer\Preferences\ByHost\com.apple.syncservices.{790d4040-1683-11db-b8eb-806d6172696f}.plist
2010-01-16 19:36 . 2010-01-16 19:36   388   --sha-w-   c:\documents and settings\customer1\Application Data\Microsoft\Protect\S-1-5-21-73586283-842925246-725345543-1004\7bb3c0f7-cad4-4b55-9f82-4cb53aebfcc7
2010-01-15 21:23 . 2010-01-15 21:33   148512   ----a-w-   c:\documents and settings\customer1\Application Data\Microsoft\Clip Organizer\Offic10.MGC
2010-01-15 21:23 . 2010-01-15 21:33   197688   ----a-w-   c:\documents and settings\customer1\Application Data\Microsoft\Clip Organizer\mstore10.mgc
2009-12-25 04:52 . 2009-06-08 17:50   2604   ----a-w-   c:\documents and settings\customer1\Application Data\Scrabble Plus\modes\targetzones.xml
2009-12-25 04:52 . 2009-06-02 00:37   936   ----a-w-   c:\documents and settings\customer1\Application Data\Scrabble Plus\modes\golf\golf.xml
2009-12-25 04:52 . 2009-06-02 00:33   965   ----a-w-   c:\documents and settings\customer1\Application Data\Scrabble Plus\modes\golf\skinsplay.xml
2009-12-25 04:52 . 2009-06-02 23:27   632   ----a-w-   c:\documents and settings\customer1\Application Data\Scrabble Plus\modes\brainiac\clabbers.xml
2009-12-25 04:52 . 2009-06-13 01:20   479   ----a-w-   c:\documents and settings\customer1\Application Data\Scrabble Plus\modes\brainiac\quizzical.xml
2009-12-25 04:52 . 2009-06-02 23:27   519   ----a-w-   c:\documents and settings\customer1\Application Data\Scrabble Plus\modes\classic\classic.xml
2009-12-25 04:52 . 2009-06-02 23:27   954   ----a-w-   c:\documents and settings\customer1\Application Data\Scrabble Plus\modes\brainiac\categories.xml
2009-12-25 04:52 . 2009-06-04 22:56   1407   ----a-w-   c:\documents and settings\customer1\Application Data\Scrabble Plus\modes\battle\scrabbleterritories.xml
2009-12-25 04:52 . 2009-06-16 19:09   2571   ----a-w-   c:\documents and settings\customer1\Application Data\Scrabble Plus\modes\battle\scrabblewars.xml
2009-12-25 04:51 . 2009-12-25 04:51   144   ----a-w-   c:\documents and settings\customer1\Start Menu\Programs\GameHouse\Visit GameHouse.com.url
2009-12-25 04:51 . 2009-12-25 04:51   144   ----a-w-   c:\documents and settings\customer1\Desktop\Unused Desktop Shortcuts\More Games at GameHouse.com.url
2009-12-25 04:51 . 2007-02-10 10:56   295606   ----a-w-   c:\documents and settings\customer1\Application Data\GameHouse\gh.ico
2009-12-24 12:43 . 2010-06-18 03:26   3722   ----a-w-   c:\documents and settings\customer1\My Documents\My Music\My Playlists\war.wpl
2009-12-11 20:32 . 2010-01-15 21:33   172   ----a-w-   c:\documents and settings\customer1\Application Data\Microsoft\PowerPoint\PPT11.pcb
2009-12-02 04:22 . 2009-12-02 04:22   779   ----a-w-   c:\documents and settings\customer1\Desktop\Unused Desktop Shortcuts\InterActual Player.lnk
2009-11-29 22:58 . 2009-11-29 22:58   0   ----a-w-   c:\documents and settings\customer1\My Documents\Default.PLS
2009-11-28 20:21 . 2009-11-28 20:21   34816   ----a-w-   c:\documents and settings\customer1\Desktop\sweet potato pie.doc
2009-11-27 09:46 . 2012-02-09 16:35   4481539   ----a-w-   c:\documents and settings\customer1\My Documents\My Music\Unknown Artist\Unknown Album (11-27-2009 3-42-06 AM)\01 Track 1.wma
2009-11-27 09:45 . 2009-11-27 09:46   3698683   ----a-w-   c:\documents and settings\customer1\My Documents\My Music\Unknown Artist\Unknown Album (11-27-2009 3-42-06 AM)\03 Track 3.wma
2009-11-27 09:45 . 2012-02-09 16:36   3734539   ----a-w-   c:\documents and settings\customer1\My Documents\My Music\Unknown Artist\Unknown Album (11-27-2009 3-42-06 AM)\02 Track 2.wma
2009-11-06 22:39 . 2009-11-06 22:39   31   ----a-w-   c:\documents and settings\customer1\Application Data\DellFaxCtr\fm3032.INI
2009-11-06 22:39 . 2006-04-24 19:58   2546   ----a-w-   c:\documents and settings\customer1\Application Data\DellFaxCtr\Coverpgs\Urgent.pg
2009-11-06 22:39 . 2006-04-24 19:58   2506   ----a-w-   c:\documents and settings\customer1\Application Data\DellFaxCtr\Coverpgs\Standard.pg
2009-11-06 22:39 . 2006-04-24 19:58   1024   ----a-w-   c:\documents and settings\customer1\Application Data\DellFaxCtr\Coverpgs\faxlog32.fpt
2009-11-06 22:39 . 2006-04-24 19:58   2582   ----a-w-   c:\documents and settings\customer1\Application Data\DellFaxCtr\Coverpgs\Simple.pg
2009-11-06 22:39 . 2006-04-24 19:58   1826   ----a-w-   c:\documents and settings\customer1\Application Data\DellFaxCtr\Coverpgs\faxlog32.dbf
2009-11-06 22:39 . 2006-04-24 19:58   13824   ----a-w-   c:\documents and settings\customer1\Application Data\DellFaxCtr\Coverpgs\faxlog32.cdx
2009-11-06 22:39 . 2006-04-24 19:58   2840   ----a-w-   c:\documents and settings\customer1\Application Data\DellFaxCtr\Coverpgs\Cnfdentl.pg
2009-11-05 01:59 . 2009-11-05 01:59   2900131   ----a-w-   c:\documents and settings\customer1\My Documents\11-04-2009 07;58;55PM.rtf
2009-11-05 01:58 . 2009-11-05 01:58   2132597   ----a-w-   c:\documents and settings\customer1\My Documents\11-04-2009 07;57;53PM.rtf
2009-10-14 21:04 . 2009-10-14 21:04   388   --sha-w-   c:\documents and settings\customer1\Application Data\Microsoft\Protect\S-1-5-21-73586283-842925246-725345543-1004\7e97d3be-1851-4698-b82e-ccce7d0cb2d5
2009-09-08 01:11 . 2009-11-02 17:03   42496   ----a-w-   c:\documents and settings\customer1\My Documents\My Music\iTunes\iTunes Music Library.xml
2009-08-15 01:02 . 2009-08-15 01:03   81920   --sha-w-   c:\documents and settings\customer1\Desktop\Horse Pictures\Thumbs.db
2009-08-03 23:58 . 2009-08-03 23:59   34   ----a-w-   c:\documents and settings\customer1\jagex_runescape_preferences.dat
2009-08-03 23:58 . 2009-08-03 23:58   1068   ----a-w-   c:\documents and settings\customer1\Application Data\Sun\Java\Deployment\security\trusted.certs
2009-08-03 04:01 . 2009-08-03 04:01   14993   --sh--w-   c:\documents and settings\customer1\My Documents\Songs burnt to cd\AlbumArt_{5E9BC3D0-A692-4399-BD78-7710DB2B8078}_Large.jpg
2009-08-03 04:01 . 2009-08-03 04:01   3358   --sh--w-   c:\documents and settings\customer1\My Documents\Songs burnt to cd\AlbumArt_{5E9BC3D0-A692-4399-BD78-7710DB2B8078}_Small.jpg
2009-07-30 07:33 . 2009-07-30 07:33   1219   --s-a-w-   c:\documents and settings\customer1\Application Data\Microsoft\CryptnetUrlCache\Content\7735880A01E3F94F763761958A7A8191
2009-07-30 07:33 . 2009-07-30 07:33   132   --s-a-w-   c:\documents and settings\customer1\Application Data\Microsoft\CryptnetUrlCache\MetaData\7735880A01E3F94F763761958A7A8191
2009-07-28 13:15 . 2009-07-28 13:15   223   ----a-w-   c:\documents and settings\customer1\Favorites\Oldies 103.3 FM - Homepage.url
2009-07-26 17:17 . 2009-07-26 17:17   15291   --sh--w-   c:\documents and settings\customer1\My Documents\Songs burnt to cd\AlbumArt_{B60C0FFD-7E8F-4881-90FC-EC14FD6E1A71}_Large.jpg
2009-07-26 17:17 . 2009-07-26 17:17   3277   --sh--w-   c:\documents and settings\customer1\My Documents\Songs burnt to cd\AlbumArt_{B60C0FFD-7E8F-4881-90FC-EC14FD6E1A71}_Small.jpg
2009-07-26 17:17 . 2009-07-26 17:17   7536   --sh--w-   c:\documents and settings\customer1\My Documents\Songs burnt to cd\AlbumArt_{FC16DE9A-01DB-40D0-A5B9-2A1E8EBA13D0}_Large.jpg
2009-07-26 17:17 . 2009-07-26 17:17   1876   --sh--w-   c:\documents and settings\customer1\My Documents\Songs burnt to cd\AlbumArt_{FC16DE9A-01DB-40D0-A5B9-2A1E8EBA13D0}_Small.jpg
2009-07-26 17:16 . 2009-07-26 17:16   8837   --sh--w-   c:\documents and settings\customer1\My Documents\Songs burnt to cd\AlbumArt_{7499CE90-9A5D-43C4-A339-B00BC45E57EC}_Large.jpg
2009-07-26 17:16 . 2009-07-26 17:16   2451   --sh--w-   c:\documents and settings\customer1\My Documents\Songs burnt to cd\AlbumArt_{7499CE90-9A5D-43C4-A339-B00BC45E57EC}_Small.jpg
2009-07-26 17:16 . 2009-07-26 17:16   12003   --sh--w-   c:\documents and settings\customer1\My Documents\Songs burnt to cd\AlbumArt_{9FC3DAA7-49F1-4D36-834A-A96BED9D7207}_Large.jpg
2009-07-26 17:16 . 2009-07-26 17:16   3068   --sh--w-   c:\documents and settings\customer1\My Documents\Songs burnt to cd\AlbumArt_{9FC3DAA7-49F1-4D36-834A-A96BED9D7207}_Small.jpg
2009-07-26 17:16 . 2009-07-26 17:16   10680   --sh--w-   c:\documents and settings\customer1\My Documents\Songs burnt to cd\AlbumArt_{BDF5030E-DB6C-45EA-BBF0-09A1C83CDE88}_Large.jpg
2009-07-26 17:16 . 2009-07-26 17:16   2795   --sh--w-   c:\documents and settings\customer1\My Documents\Songs burnt to cd\AlbumArt_{BDF5030E-DB6C-45EA-BBF0-09A1C83CDE88}_Small.jpg
2009-07-26 17:16 . 2009-07-26 17:16   9349   --sh--w-   c:\documents and settings\customer1\My Documents\Songs burnt to cd\AlbumArt_{F0649410-7377-4AA6-88BD-9556A92109A1}_Large.jpg
2009-07-26 17:16 . 2009-07-26 17:16   2438   --sh--w-   c:\documents and settings\customer1\My Documents\Songs burnt to cd\AlbumArt_{F0649410-7377-4AA6-88BD-9556A92109A1}_Small.jpg
2009-07-26 17:08 . 2009-07-26 17:08   43062   ----a-w-   c:\documents and settings\customer1\My Documents\Kevin\UserImages.bmp
2009-07-25 02:53 . 2012-03-29 21:05   65536   --sha-w-   c:\documents and settings\customer1\Local Settings\Application Data\Microsoft\Internet Explorer\DOMStore\index.dat
2009-07-23 12:45 . 2012-03-29 21:05   851968   --sha-w-   c:\documents and settings\customer1\IECompatCache\index.dat
2009-07-23 12:45 . 2012-03-09 01:18   67   --sh--w-   c:\documents and settings\customer1\Cookies\desktop.ini
2009-07-23 09:52 . 2009-07-23 09:52   10   ----a-w-   c:\documents and settings\customer1\Application Data\Mozilla\Firefox\Crash Reports\InstallTime20090715094852
2009-07-22 16:30 . 2009-07-22 16:30   1150   ----a-w-   c:\documents and settings\customer1\Local Settings\Application Data\Microsoft\Internet Explorer\Services\search_{6A1806CD-94D4-4689-BA73-E35EA1EA9990}.ico
2009-07-22 16:30 . 2009-07-22 16:30   1150   ----a-w-   c:\documents and settings\customer1\Local Settings\Application Data\Microsoft\Internet Explorer\Services\search_{0633EE93-D776-472f-A0FF-E1416B8B2E3A}.ico
2009-07-22 16:30 . 2012-03-29 21:05   16187392   --sha-w-   c:\documents and settings\customer1\PrivacIE\index.dat
2009-07-22 08:10 . 2009-07-22 08:10   84   --sha-w-   c:\documents and settings\customer1\Favorites\Links\desktop.ini
2009-07-22 08:10 . 2009-07-22 08:10   134   ----a-w-   c:\documents and settings\customer1\Favorites\Microsoft Websites\Microsoft Store.url
2009-07-22 08:10 . 2012-03-29 21:22   262144   --sha-w-   c:\documents and settings\customer1\IETldCache\index.dat
2009-07-21 03:34 . 2012-03-24 04:35   10939   ----a-w-   c:\documents and settings\customer1\Application Data\Mozilla\Firefox\Profiles\gygvqas6.default\blocklist.xml
2009-07-21 01:42 . 2009-07-21 01:42   8359   --sh--w-   c:\documents and settings\customer1\My Documents\Songs burnt to cd\AlbumArt_{3FBB31B8-767F-4385-B602-8F47F0713E3B}_Large.jpg
2009-07-21 01:42 . 2009-07-21 01:42   2343   --sh--w-   c:\documents and settings\customer1\My Documents\Songs burnt to cd\AlbumArt_{3FBB31B8-767F-4385-B602-8F47F0713E3B}_Small.jpg
2009-07-21 01:41 . 2009-07-21 01:41   8392   --sh--w-   c:\documents and settings\customer1\My Documents\Songs burnt to cd\AlbumArt_{4BB37DE2-017E-4FA8-AA15-08180649E1AD}_Large.jpg
2009-07-21 01:41 . 2009-07-21 01:41   2190   --sh--w-   c:\documents and settings\customer1\My Documents\Songs burnt to cd\AlbumArt_{4BB37DE2-017E-4FA8-AA15-08180649E1AD}_Small.jpg
2009-07-21 01:41 . 2009-07-21 01:41   10893   --sh--w-   c:\documents and settings\customer1\My Documents\Songs burnt to cd\AlbumArt_{58AEF48B-701D-46BD-9B2E-2AB82DCA9AF3}_Large.jpg
2009-07-21 01:41 . 2009-07-21 01:41   2346   --sh--w-   c:\documents and settings\customer1\My Documents\Songs burnt to cd\AlbumArt_{58AEF48B-701D-46BD-9B2E-2AB82DCA9AF3}_Small.jpg
2009-07-21 01:41 . 2009-07-21 01:41   9588   --sh--w-   c:\documents and settings\customer1\My Documents\Songs burnt to cd\AlbumArt_{F51A1D46-BBF0-46C7-B4A5-82DA227D8E80}_Large.jpg
2009-07-21 01:41 . 2009-07-21 01:41   2566   --sh--w-   c:\documents and settings\customer1\My Documents\Songs burnt to cd\AlbumArt_{F51A1D46-BBF0-46C7-B4A5-82DA227D8E80}_Small.jpg
2009-07-21 01:41 . 2009-07-21 01:41   12785   --sh--w-   c:\documents and settings\customer1\My Documents\Songs burnt to cd\AlbumArt_{A772A62A-F718-43A8-9704-0334671FA145}_Large.jpg
2009-07-21 01:41 . 2009-07-21 01:41   2874   --sh--w-   c:\documents and settings\customer1\My Documents\Songs burnt to cd\AlbumArt_{A772A62A-F718-43A8-9704-0334671FA145}_Small.jpg
2009-07-21 01:41 . 2009-07-21 01:41   8765   --sh--w-   c:\documents and settings\customer1\My Documents\Songs burnt to cd\AlbumArt_{43A3D4D3-3BF2-4640-AB6A-A448F1CF8964}_Large.jpg
2009-07-21 01:41 . 2009-07-21 01:41   2296   --sh--w-   c:\documents and settings\customer1\My Documents\Songs burnt to cd\AlbumArt_{43A3D4D3-3BF2-4640-AB6A-A448F1CF8964}_Small.jpg
2009-07-21 01:41 . 2009-07-21 01:41   9334   --sh--w-   c:\documents and settings\customer1\My Documents\Songs burnt to cd\AlbumArt_{266DACBE-A138-4D34-A42A-AAA73B94D2DF}_Large.jpg
2009-07-21 01:41 . 2009-07-21 01:41   2338   --sh--w-   c:\documents and settings\customer1\My Documents\Songs burnt to cd\AlbumArt_{266DACBE-A138-4D34-A42A-AAA73B94D2DF}_Small.jpg
2009-07-21 01:41 . 2009-07-21 01:41   8457   --sh--w-   c:\documents and settings\customer1\My Documents\Songs burnt to cd\AlbumArt_{E084D519-EDDF-4A07-A888-D0DD5BF1133F}_Large.jpg
2009-07-21 01:41 . 2009-07-21 01:41   2602   --sh--w-   c:\documents and settings\customer1\My Documents\Songs burnt to cd\AlbumArt_{E084D519-EDDF-4A07-A888-D0DD5BF1133F}_Small.jpg
2009-07-21 01:41 . 2009-07-21 01:41   13332   --sh--w-   c:\documents and settings\customer1\My Documents\Songs burnt to cd\AlbumArt_{5E548BCF-A636-4761-B609-B2F430716848}_Large.jpg
2009-07-21 01:41 . 2009-07-21 01:41   3212   --sh--w-   c:\documents and settings\customer1\My Documents\Songs burnt to cd\AlbumArt_{5E548BCF-A636-4761-B609-B2F430716848}_Small.jpg
2009-07-21 01:41 . 2009-07-21 01:40   13828   --sh--w-   c:\documents and settings\customer1\My Documents\Songs burnt to cd\AlbumArt_{5E558BF3-D629-4504-9B3F-37937C1879CA}_Large.jpg
2009-07-21 01:41 . 2009-07-21 01:40   2917   --sh--w-   c:\documents and settings\customer1\My Documents\Songs burnt to cd\AlbumArt_{5E558BF3-D629-4504-9B3F-37937C1879CA}_Small.jpg
2009-07-21 01:40 . 2011-11-06 02:57   12093   --sh--w-   c:\documents and settings\customer1\My Documents\Songs burnt to cd\AlbumArt_{7DED654C-BEE4-4E25-9D8E-6C2FDE8EB518}_Large.jpg
2009-07-21 01:40 . 2011-11-06 02:57   2730   --sh--w-   c:\documents and settings\customer1\My Documents\Songs burnt to cd\AlbumArt_{7DED654C-BEE4-4E25-9D8E-6C2FDE8EB518}_Small.jpg
2009-07-21 01:40 . 2009-07-21 01:40   11177   --sh--w-   c:\documents and settings\customer1\My Documents\Songs burnt to cd\AlbumArt_{882949F7-FB55-4E86-800A-543B032F5E71}_Large.jpg
2009-07-21 01:40 . 2009-07-21 01:40   2440   --sh--w-   c:\documents and settings\customer1\My Documents\Songs burnt to cd\AlbumArt_{882949F7-FB55-4E86-800A-543B032F5E71}_Small.jpg
2009-07-21 01:40 . 2009-07-21 01:40   14491   --sh--w-   c:\documents and settings\customer1\My Documents\Songs burnt to cd\AlbumArt_{07939268-200E-4FF2-9674-D135052EE83A}_Large.jpg
2009-07-21 01:40 . 2009-07-21 01:40   3488   --sh--w-   c:\documents and settings\customer1\My Documents\Songs burnt to cd\AlbumArt_{07939268-200E-4FF2-9674-D135052EE83A}_Small.jpg
2009-07-19 04:03 . 2009-07-19 04:03   10358   --sh--w-   c:\documents and settings\customer1\My Documents\Songs burnt to cd\AlbumArt_{F2515C25-F0E5-4385-BE0B-9ED6F91F8A6F}_Large.jpg
2009-07-19 04:03 . 2009-07-19 04:03   2640   --sh--w-   c:\documents and settings\customer1\My Documents\Songs burnt to cd\AlbumArt_{F2515C25-F0E5-4385-BE0B-9ED6F91F8A6F}_Small.jpg
« Last Edit: March 29, 2012, 04:04:16 PM by kcrawhorn »