Jump to content

alexd123456

Members
  • Posts

    12
  • Joined

  • Last visited

Everything posted by alexd123456

  1. Heres the HJT log Logfile of Trend Micro HijackThis v2.0.2 Scan saved at 12:55:30 PM, on 7/6/2008 Platform: Windows XP SP2 (WinNT 5.01.2600) MSIE: Internet Explorer v7.00 (7.00.6000.16674) Boot mode: Normal Running processes: C:\WINDOWS\System32\smss.exe C:\WINDOWS\system32\winlogon.exe C:\WINDOWS\system32\services.exe C:\WINDOWS\system32\lsass.exe C:\WINDOWS\system32\Ati2evxx.exe C:\WINDOWS\system32\svchost.exe C:\WINDOWS\System32\svchost.exe C:\WINDOWS\System32\WLTRYSVC.EXE C:\WINDOWS\System32\bcmwltry.exe C:\WINDOWS\system32\spoolsv.exe C:\Program Files\Common Files\LogiShrd\LVMVFM\LVPrcSrv.exe C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe C:\Program Files\Common Files\LogiShrd\LVCOMSER\LVComSer.exe C:\Program Files\McAfee\Common Framework\FrameworkService.exe C:\Program Files\McAfee\VirusScan Enterprise\mcshield.exe C:\Program Files\McAfee\VirusScan Enterprise\vstskmgr.exe C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE C:\WINDOWS\system32\Ati2evxx.exe C:\WINDOWS\system32\svchost.exe C:\WINDOWS\Explorer.EXE C:\WINDOWS\system32\WLTRAY.exe C:\WINDOWS\stsystra.exe C:\Program Files\Synaptics\SynTP\SynTPEnh.exe C:\Program Files\ATI Technologies\ATI.ACE\cli.exe C:\Program Files\Google\Google Talk\googletalk.exe C:\Program Files\Microsoft IntelliPoint\ipoint.exe C:\Program Files\Microsoft Office\Office12\GrooveMonitor.exe C:\Program Files\PowerISO\PWRISOVM.EXE C:\Program Files\McAfee\VirusScan Enterprise\SHSTAT.EXE C:\Program Files\McAfee\Common Framework\UdaterUI.exe C:\Program Files\Common Files\LogiShrd\LComMgr\Communications_Helper.exe C:\Program Files\Logitech\QuickCam\Quickcam.exe C:\Program Files\iTunes\iTunesHelper.exe C:\Program Files\Java\jre1.6.0_06\bin\jusched.exe C:\Program Files\DAEMON Tools\daemon.exe C:\Program Files\AIM6\aim6.exe C:\WINDOWS\system32\ctfmon.exe C:\Program Files\Linksys EasyLink Advisor\LinksysAgent.exe C:\Program Files\Digital Line Detect\DLG.exe C:\Program Files\McAfee\Common Framework\McTray.exe C:\Program Files\Common Files\AOL\Loader\aolload.exe C:\Program Files\3M\PSNotes\psn.exe C:\PROGRA~1\3M\PSNotes\PSNGive.exe C:\Program Files\iPod\bin\iPodService.exe C:\Program Files\Common Files\LogiShrd\LVCOMSER\LVComSer.exe C:\Program Files\AIM6\aolsoftware.exe C:\Program Files\Common Files\Logishrd\LQCVFX\COCIManager.exe C:\Program Files\ATI Technologies\ATI.ACE\cli.exe C:\WINDOWS\System32\svchost.exe C:\Program Files\Mozilla Firefox\firefox.exe C:\Program Files\Trend Micro\HijackThis\HijackThis.exe R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157 R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896 R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896 R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157 R1 - HKLM\Software\Microsoft\Internet Explorer\Search,Default_Page_URL = www.google.com/ig/dell?hl=en&client=dell-usuk-rel&channel=us&ibd=4061226 R1 - HKCU\Software\Microsoft\Internet Connection Wizard,ShellNext = http://desktop.google.com/uninstall-feedback.html?hl=en O2 - BHO: Spybot-S&D IE Protection - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_06\bin\ssv.dll O4 - HKLM\..\Run: [broadcom Wireless Manager UI] C:\WINDOWS\system32\WLTRAY.exe O4 - HKLM\..\Run: [sigmatelSysTrayApp] stsystra.exe O4 - HKLM\..\Run: [synTPEnh] C:\Program Files\Synaptics\SynTP\SynTPEnh.exe O4 - HKLM\..\Run: [ATICCC] "C:\Program Files\ATI Technologies\ATI.ACE\cli.exe" runtime -Delay O4 - HKLM\..\Run: [iSUSScheduler] "C:\Program Files\Common Files\InstallShield\UpdateService\issch.exe" -start O4 - HKLM\..\Run: [googletalk] C:\Program Files\Google\Google Talk\googletalk.exe /autostart O4 - HKLM\..\Run: [Tweak UI] RUNDLL32.EXE TWEAKUI.CPL,TweakMeUp O4 - HKLM\..\Run: [intelliPoint] "C:\Program Files\Microsoft IntelliPoint\ipoint.exe" O4 - HKLM\..\Run: [GrooveMonitor] "C:\Program Files\Microsoft Office\Office12\GrooveMonitor.exe" O4 - HKLM\..\Run: [PWRISOVM.EXE] C:\Program Files\PowerISO\PWRISOVM.EXE O4 - HKLM\..\Run: [shStatEXE] "C:\Program Files\McAfee\VirusScan Enterprise\SHSTAT.EXE" /STANDALONE O4 - HKLM\..\Run: [McAfeeUpdaterUI] "C:\Program Files\McAfee\Common Framework\UdaterUI.exe" /StartedFromRunKey O4 - HKLM\..\Run: [LogitechCommunicationsManager] "C:\Program Files\Common Files\LogiShrd\LComMgr\Communications_Helper.exe" O4 - HKLM\..\Run: [LogitechQuickCamRibbon] "C:\Program Files\Logitech\QuickCam\Quickcam.exe" /hide O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\QTTask.exe" -atboottime O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe" O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe" O4 - HKLM\..\Run: [sunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_06\bin\jusched.exe" O4 - HKCU\..\Run: [DAEMON Tools] "C:\Program Files\DAEMON Tools\daemon.exe" -lang 1033 O4 - HKCU\..\Run: [Aim6] "C:\Program Files\AIM6\aim6.exe" /d locale=en-US ee://aol/imApp O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe O4 - HKCU\..\Run: [EasyLinkAdvisor] "C:\Program Files\Linksys EasyLink Advisor\LinksysAgent.exe" /startup O4 - S-1-5-18 Startup: OneNote 2007 Screen Clipper and Launcher.lnk = C:\Program Files\Microsoft Office\Office12\ONENOTEM.EXE (User 'SYSTEM') O4 - .DEFAULT Startup: OneNote 2007 Screen Clipper and Launcher.lnk = C:\Program Files\Microsoft Office\Office12\ONENOTEM.EXE (User 'Default user') O4 - Startup: OneNote 2007 Screen Clipper and Launcher.lnk = C:\Program Files\Microsoft Office\Office12\ONENOTEM.EXE O4 - Global Startup: AutoCAD Startup Accelerator.lnk = C:\Program Files\Common Files\Autodesk Shared\acstart16.exe O4 - Global Startup: Digital Line Detect.lnk = ? O4 - Global Startup: Post-it
  2. and last C:\\ijji\ENGLISH\HgSoundOut.exe C:\\ijji\ENGLISH\HgTool3.dll C:\\ijji\ENGLISH\HgView3.dll C:\\ijji\ENGLISH\IjjiGamePluginRemoveTool.exe C:\\ijji\ENGLISH\ijjiLauncher_PostPluginDll_02.dll C:\\ijji\ENGLISH\ijjiLauncher_PrePluginDll_01.dll C:\\ijji\ENGLISH\ijjiUninstall.exe C:\\ijji\ENGLISH\ijl15.dll C:\\ijji\ENGLISH\nb_option.dat C:\\ijji\ENGLISH\NeoBit.dll C:\\ijji\ENGLISH\PiXel.dll C:\\ijji\ENGLISH\Rounders.exe C:\\ijji\ENGLISH\rounders\Channel.hml C:\\ijji\ENGLISH\rounders\Game.hml C:\\ijji\ENGLISH\rounders\images\Background\img_Board.bmp C:\\ijji\ENGLISH\rounders\images\Background\img_JokboArrow.bmp C:\\ijji\ENGLISH\rounders\images\Button\btn_Betting0.bmp C:\\ijji\ENGLISH\rounders\images\Button\btn_Betting1.bmp C:\\ijji\ENGLISH\rounders\images\Button\btn_Betting2.bmp C:\\ijji\ENGLISH\rounders\images\Button\btn_DontShow.bmp C:\\ijji\ENGLISH\rounders\images\Button\btn_GameAway.bmp C:\\ijji\ENGLISH\rounders\images\Button\btn_GameIAmBack.bmp C:\\ijji\ENGLISH\rounders\images\Button\btn_GameLeave.bmp C:\\ijji\ENGLISH\rounders\images\Button\btn_GameOption.bmp C:\\ijji\ENGLISH\rounders\images\Button\btn_GameReBuy.bmp C:\\ijji\ENGLISH\rounders\images\Button\btn_GameSitIn.bmp C:\\ijji\ENGLISH\rounders\images\Button\btn_GameSitOut.bmp C:\\ijji\ENGLISH\rounders\images\Button\btn_PreBetting0.bmp C:\\ijji\ENGLISH\rounders\images\Button\btn_PreBetting1.bmp C:\\ijji\ENGLISH\rounders\images\Button\btn_PreBetting2.bmp C:\\ijji\ENGLISH\rounders\images\Button\btn_PreBetting3.bmp C:\\ijji\ENGLISH\rounders\images\Button\btn_PreBetting4.bmp C:\\ijji\ENGLISH\rounders\images\Button\btn_PreBetting5.bmp C:\\ijji\ENGLISH\rounders\images\Button\btn_ShowCard.bmp C:\\ijji\ENGLISH\rounders\images\Button\btn_TitleCapture.bmp C:\\ijji\ENGLISH\rounders\images\Button\btn_TitleExitRoom.bmp C:\\ijji\ENGLISH\rounders\images\Button\btn_TitleFullMode.bmp C:\\ijji\ENGLISH\rounders\images\Button\btn_TitleMinimize.bmp C:\\ijji\ENGLISH\rounders\images\Button\btn_TitleWndMode.bmp C:\\ijji\ENGLISH\rounders\images\Button\img_BettingGaugeBack.bmp C:\\ijji\ENGLISH\rounders\images\Button\img_BettingGaugeBar.bmp C:\\ijji\ENGLISH\rounders\images\Button\img_PreBettingCheck.bmp C:\\ijji\ENGLISH\rounders\images\BuyInDlg\btn_BuyInDlgCancel.bmp C:\\ijji\ENGLISH\rounders\images\BuyInDlg\btn_BuyInDlgDeposit.bmp C:\\ijji\ENGLISH\rounders\images\BuyInDlg\btn_BuyInDlgLeave.bmp C:\\ijji\ENGLISH\rounders\images\BuyInDlg\btn_BuyInDlgOk.bmp C:\\ijji\ENGLISH\rounders\images\BuyInDlg\btn_BuyInDlgRefill.bmp C:\\ijji\ENGLISH\rounders\images\BuyInDlg\btn_BuyInDlgUseMax.bmp C:\\ijji\ENGLISH\rounders\images\BuyInDlg\img_BuyInDlgBack.bmp C:\\ijji\ENGLISH\rounders\images\BuyInDlg\Thumbs.db C:\\ijji\ENGLISH\rounders\images\Card\img_BigCardBack.bmp C:\\ijji\ENGLISH\rounders\images\Card\tile_BigCard.bmp C:\\ijji\ENGLISH\rounders\images\Card\tile_SmallCard.bmp C:\\ijji\ENGLISH\rounders\images\Card\tile_SmallCardBack0.bmp C:\\ijji\ENGLISH\rounders\images\Card\tile_SmallCardBack1.bmp C:\\ijji\ENGLISH\rounders\images\Card\tile_SmallCardBack2.bmp C:\\ijji\ENGLISH\rounders\images\Card\tile_SmallCardBack3.bmp C:\\ijji\ENGLISH\rounders\images\Card\tile_SmallCardBack4.bmp C:\\ijji\ENGLISH\rounders\images\Card\tile_SmallCardBack5.bmp C:\\ijji\ENGLISH\rounders\images\Card\tile_SmallCardBack6.bmp C:\\ijji\ENGLISH\rounders\images\Card\tile_SmallCardBack7.bmp C:\\ijji\ENGLISH\rounders\images\Card\tile_SmallCardBack8.bmp C:\\ijji\ENGLISH\rounders\images\Card\tile_SmallCardBack9.bmp C:\\ijji\ENGLISH\rounders\images\Card\tile_SmallCardBackCommon.bmp C:\\ijji\ENGLISH\rounders\images\Channel\_AdLogo1.bmp C:\\ijji\ENGLISH\rounders\images\Channel\_AdLogo2.bmp C:\\ijji\ENGLISH\rounders\images\Channel\_AdLogo3.bmp C:\\ijji\ENGLISH\rounders\images\Channel\_AdLogo4.bmp C:\\ijji\ENGLISH\rounders\images\Channel\_ChangeChannelBtn.him C:\\ijji\ENGLISH\rounders\images\Channel\_ChannelInfoBg.him C:\\ijji\ENGLISH\rounders\images\Channel\_ChnlGrl_AdBg1.him C:\\ijji\ENGLISH\rounders\images\Channel\_ChnlGrl_AdBg2.him C:\\ijji\ENGLISH\rounders\images\Channel\_ChnlGrl_AdBg3.him C:\\ijji\ENGLISH\rounders\images\Channel\_ChnlGrl_AdBg4.him C:\\ijji\ENGLISH\rounders\images\Channel\_ChnlGrp_ChannelListCtrlBg.him C:\\ijji\ENGLISH\rounders\images\Channel\_ChnlGrp_InfoBg.him C:\\ijji\ENGLISH\rounders\images\Channel\_ChnlGrp_JoinBtn.him C:\\ijji\ENGLISH\rounders\images\Channel\_ChnlGrp_ListCtrlBg.him C:\\ijji\ENGLISH\rounders\images\Channel\_ChnlGrp_RefreshBtn.him C:\\ijji\ENGLISH\rounders\images\Channel\_ChnlGrp_RoomGrpTitle.him C:\\ijji\ENGLISH\rounders\images\Channel\_ChnlGrp_RoomListTitle.him C:\\ijji\ENGLISH\rounders\images\Channel\_ChnlGrp_TextInfoBg.him C:\\ijji\ENGLISH\rounders\images\Channel\_Chnlst_ChnlGrpListCornerBottom.him C:\\ijji\ENGLISH\rounders\images\Channel\_Chnlst_ChnlGrpListCornerTop.him C:\\ijji\ENGLISH\rounders\images\Channel\_ComboboxArrowBtn.him C:\\ijji\ENGLISH\rounders\images\Channel\_CreateATableBtn.him C:\\ijji\ENGLISH\rounders\images\Channel\_GMark.him C:\\ijji\ENGLISH\rounders\images\Channel\_HowToPlayBtn.him C:\\ijji\ENGLISH\rounders\images\Channel\_MainframeAuctionBtn.him C:\\ijji\ENGLISH\rounders\images\Channel\_MainframeBorderBottom.him C:\\ijji\ENGLISH\rounders\images\Channel\_MainframeBorderSide.him C:\\ijji\ENGLISH\rounders\images\Channel\_MainframeCaption.him C:\\ijji\ENGLISH\rounders\images\Channel\_MainFrameCornerBottom.him C:\\ijji\ENGLISH\rounders\images\Channel\_MainframeExitBtn.him C:\\ijji\ENGLISH\rounders\images\Channel\_MainFrameMaximizeBtn.him C:\\ijji\ENGLISH\rounders\images\Channel\_MainFrameMinimizeBtn.him C:\\ijji\ENGLISH\rounders\images\Channel\_MyInfoBg.him C:\\ijji\ENGLISH\rounders\images\Channel\_PlayNowBtn.him C:\\ijji\ENGLISH\rounders\images\Channel\_PlayNowBtn_HoverAni.him C:\\ijji\ENGLISH\rounders\images\Channel\_Popup_BorderBottom.him C:\\ijji\ENGLISH\rounders\images\Channel\_Popup_BorderSide.him C:\\ijji\ENGLISH\rounders\images\Channel\_Popup_BorderTop.him C:\\ijji\ENGLISH\rounders\images\Channel\_Popup_CancelBtn.him C:\\ijji\ENGLISH\rounders\images\Channel\_Popup_CaptionIcon.him C:\\ijji\ENGLISH\rounders\images\Channel\_Popup_CornerBottom.him C:\\ijji\ENGLISH\rounders\images\Channel\_Popup_CornerTop.him C:\\ijji\ENGLISH\rounders\images\Channel\_Popup_OKBtn.him C:\\ijji\ENGLISH\rounders\images\Channel\_Popup_Title_Ad.him C:\\ijji\ENGLISH\rounders\images\Channel\_Popup_Title_Auctions.him C:\\ijji\ENGLISH\rounders\images\Channel\_RoomJoinBtn.him C:\\ijji\ENGLISH\rounders\images\Channel\_RoomListCornerBottom.him C:\\ijji\ENGLISH\rounders\images\Channel\_RoomListCornerTop.him C:\\ijji\ENGLISH\rounders\images\Channel\_RoundersGameTitle.bmp C:\\ijji\ENGLISH\rounders\images\Channel\_TabBtnNotice.him C:\\ijji\ENGLISH\rounders\images\Channel\_TableImage_AA.him C:\\ijji\ENGLISH\rounders\images\Channel\AuctionNotifyBg.him C:\\ijji\ENGLISH\rounders\images\Channel\btn_DlgCancel.bmp C:\\ijji\ENGLISH\rounders\images\Channel\btn_DlgCheck.bmp C:\\ijji\ENGLISH\rounders\images\Channel\btn_DlgFold.bmp C:\\ijji\ENGLISH\rounders\images\Channel\btn_DlgLeave.bmp C:\\ijji\ENGLISH\rounders\images\Channel\btn_DlgOk.bmp C:\\ijji\ENGLISH\rounders\images\Channel\btn_TnmBuyInDlgPrizePage.bmp C:\\ijji\ENGLISH\rounders\images\Channel\btn_TnmBuyInDlgRefill.bmp C:\\ijji\ENGLISH\rounders\images\Channel\btn_TnmWinInfoDlgContinue.bmp C:\\ijji\ENGLISH\rounders\images\Channel\btn_TnmWinInfoDlgStop.bmp C:\\ijji\ENGLISH\rounders\images\Channel\img_TnmBuyInDlgAlreadyFinalWin.bmp C:\\ijji\ENGLISH\rounders\images\Channel\img_TnmBuyInDlgBack.bmp C:\\ijji\ENGLISH\rounders\images\Channel\img_TnmBuyInDlgEnterTournament.bmp C:\\ijji\ENGLISH\rounders\images\Channel\img_TnmBuyInDlgNotEnoughMoney.bmp C:\\ijji\ENGLISH\rounders\images\Channel\img_TnmWinInfoDlgBack.bmp C:\\ijji\ENGLISH\rounders\images\Channel\img_UserInfoArrow.bmp C:\\ijji\ENGLISH\rounders\images\Channel\img_UserInfoLine.bmp C:\\ijji\ENGLISH\rounders\images\Character\img_Chr0.bmp C:\\ijji\ENGLISH\rounders\images\Character\img_Chr1.bmp C:\\ijji\ENGLISH\rounders\images\Character\img_Chr2.bmp C:\\ijji\ENGLISH\rounders\images\Character\img_Chr3.bmp C:\\ijji\ENGLISH\rounders\images\Character\img_Chr4.bmp C:\\ijji\ENGLISH\rounders\images\Character\img_Chr5.bmp C:\\ijji\ENGLISH\rounders\images\Character\img_Chr6.bmp C:\\ijji\ENGLISH\rounders\images\Character\img_Chr7.bmp C:\\ijji\ENGLISH\rounders\images\Character\img_Chr8.bmp C:\\ijji\ENGLISH\rounders\images\Character\img_Chr9.bmp C:\\ijji\ENGLISH\rounders\images\Chat\btn_ChatScrollCenter.bmp C:\\ijji\ENGLISH\rounders\images\Chat\btn_ChatScrollDown.bmp C:\\ijji\ENGLISH\rounders\images\Chat\btn_ChatScrollUp.bmp C:\\ijji\ENGLISH\rounders\images\Chat\img_ChatScroll.bmp C:\\ijji\ENGLISH\rounders\images\Chat\img_ChatWindow.bmp C:\\ijji\ENGLISH\rounders\images\Chip\img_DealerChip.bmp C:\\ijji\ENGLISH\rounders\images\Chip\tile_ChipA.bmp C:\\ijji\ENGLISH\rounders\images\Chip\tile_ChipB.bmp C:\\ijji\ENGLISH\rounders\images\Chip\tile_ChipShadow.bmp C:\\ijji\ENGLISH\rounders\images\GameOption\btn_GameOptCancel.bmp C:\\ijji\ENGLISH\rounders\images\GameOption\btn_GameOptOk.bmp C:\\ijji\ENGLISH\rounders\images\GameOption\img_GameOptBack.bmp C:\\ijji\ENGLISH\rounders\images\GameOption\img_GameOptCheckBox.bmp C:\\ijji\ENGLISH\rounders\images\Player\AwayMark.bmp C:\\ijji\ENGLISH\rounders\images\Player\spr_AllinEffect.hgs C:\\ijji\ENGLISH\rounders\images\Player\spr_BettingTextAllin.hgs C:\\ijji\ENGLISH\rounders\images\Player\spr_BettingTextBet.hgs C:\\ijji\ENGLISH\rounders\images\Player\spr_BettingTextCall.hgs C:\\ijji\ENGLISH\rounders\images\Player\spr_BettingTextCheck.hgs C:\\ijji\ENGLISH\rounders\images\Player\spr_BettingTextFold.hgs C:\\ijji\ENGLISH\rounders\images\Player\spr_BettingTextRaise.hgs C:\\ijji\ENGLISH\rounders\images\Player\tile_Grade.bmp C:\\ijji\ENGLISH\rounders\images\Player\tile_UserInfoBar0.bmp C:\\ijji\ENGLISH\rounders\images\Player\tile_UserInfoBar1.bmp C:\\ijji\ENGLISH\rounders\images\Player\tile_UserInfoBar2.bmp C:\\ijji\ENGLISH\rounders\images\Player\tile_UserInfoBar3.bmp C:\\ijji\ENGLISH\rounders\images\Player\tile_UserInfoBar4.bmp C:\\ijji\ENGLISH\rounders\images\Player\tile_UserInfoBar5.bmp C:\\ijji\ENGLISH\rounders\images\Player\tile_UserInfoBar6.bmp C:\\ijji\ENGLISH\rounders\images\Player\tile_UserInfoBar7.bmp C:\\ijji\ENGLISH\rounders\images\Player\tile_UserInfoBar8.bmp C:\\ijji\ENGLISH\rounders\images\Player\tile_UserInfoBar9.bmp C:\\ijji\ENGLISH\rounders\images\TimeGauge\img_TimeGaugeBack.bmp C:\\ijji\ENGLISH\rounders\images\TimeGauge\img_TimeGaugeBar.bmp C:\\ijji\ENGLISH\rounders\sounds\effect\Bgm_GameStart1.ogg C:\\ijji\ENGLISH\rounders\sounds\effect\Bgm_GameStart2.ogg C:\\ijji\ENGLISH\rounders\sounds\effect\Bgm_GameStart3.ogg C:\\ijji\ENGLISH\rounders\sounds\effect\Bgm_GameStart4.ogg C:\\ijji\ENGLISH\rounders\sounds\effect\Bgm_GameStart5.ogg C:\\ijji\ENGLISH\rounders\sounds\effect\Bgm_Lobby.ogg C:\\ijji\ENGLISH\rounders\sounds\effect\Eff_BettingBetBig1.ogg C:\\ijji\ENGLISH\rounders\sounds\effect\Eff_BettingBetBig2.ogg C:\\ijji\ENGLISH\rounders\sounds\effect\Eff_BettingBetBig3.ogg C:\\ijji\ENGLISH\rounders\sounds\effect\Eff_BettingBetMedium1.ogg C:\\ijji\ENGLISH\rounders\sounds\effect\Eff_BettingBetMedium2.ogg C:\\ijji\ENGLISH\rounders\sounds\effect\Eff_BettingBetMedium3.ogg C:\\ijji\ENGLISH\rounders\sounds\effect\Eff_BettingBetSmall1.ogg C:\\ijji\ENGLISH\rounders\sounds\effect\Eff_BettingBetSmall2.ogg C:\\ijji\ENGLISH\rounders\sounds\effect\Eff_BettingBetSmall3.ogg C:\\ijji\ENGLISH\rounders\sounds\effect\Eff_BettingBetSmall4.ogg C:\\ijji\ENGLISH\rounders\sounds\effect\Eff_BettingCheck.ogg C:\\ijji\ENGLISH\rounders\sounds\effect\Eff_BettingFold.ogg C:\\ijji\ENGLISH\rounders\sounds\effect\Eff_Buyin.ogg C:\\ijji\ENGLISH\rounders\sounds\effect\Eff_ChipToPlayer.ogg C:\\ijji\ENGLISH\rounders\sounds\effect\Eff_ChipToTable.ogg C:\\ijji\ENGLISH\rounders\sounds\effect\Eff_DealPlayerCard.ogg C:\\ijji\ENGLISH\rounders\sounds\effect\Eff_DealPlayers.ogg C:\\ijji\ENGLISH\rounders\sounds\effect\Eff_DoorClose.ogg C:\\ijji\ENGLISH\rounders\sounds\effect\Eff_DoorOpen.ogg C:\\ijji\ENGLISH\rounders\sounds\effect\Eff_MouseClickBtn.ogg C:\\ijji\ENGLISH\rounders\sounds\effect\Eff_MouseClickPreBettingBtn.ogg C:\\ijji\ENGLISH\rounders\sounds\effect\Eff_MouseOverBtn.ogg C:\\ijji\ENGLISH\rounders\sounds\effect\Eff_MyTurn.ogg C:\\ijji\ENGLISH\rounders\sounds\effect\Eff_OpenTableCard.ogg C:\\ijji\ENGLISH\rounders\sounds\effect\Eff_SitdownChair.ogg C:\\ijji\ENGLISH\rounders\sounds\effect\Eff_Timer.ogg C:\\ijji\ENGLISH\rounders\sounds\effect\Eff_Win.ogg C:\\ijji\ENGLISH\rounders\sounds\effect\Eff_WinBigpot.ogg C:\\ijji\ENGLISH\rounders\sounds\effect\Eff_WinBigpotMe.ogg C:\\ijji\ENGLISH\rounders\sounds\effect\Eff_WinMe.ogg C:\\ijji\ENGLISH\rounders\VideoObject3\cache\data\chess_170_170\chess_170_170.png C:\\ijji\ENGLISH\rounders\VideoObject3\cache\data\chess_170_170\df.dat C:\\ijji\ENGLISH\rounders\VideoObject3\cache\data\ijji_120_240\df.dat C:\\ijji\ENGLISH\rounders\VideoObject3\cache\data\ijji_120_240\ijji_120_240.jpg C:\\ijji\ENGLISH\rounders\VideoObject3\cache\data\ijji_728_90\df.dat C:\\ijji\ENGLISH\rounders\VideoObject3\cache\data\ijji_728_90\ijji_728_90.jpg C:\\ijji\ENGLISH\rounders\VideoObject3\cache\data\ijji_banner_300_250\df.dat C:\\ijji\ENGLISH\rounders\VideoObject3\cache\data\ijji_banner_300_250\ijji_banner_300_250.swf C:\\ijji\ENGLISH\rounders\VideoObject3\cache\Objects.dfo C:\\ijji\ENGLISH\rounders\VideoObject3\Engine.Var C:\\ijji\ENGLISH\roundershgc.hsp C:\\ijji\ENGLISH\SwitcheRooUS.ini C:\\ijji\ENGLISH\sysfiles\MFC71.dll C:\\ijji\ENGLISH\sysfiles\msvcp71.dll C:\\ijji\ENGLISH\sysfiles\msvcr71.dll C:\\ijji\ENGLISH\u_dcity.agt C:\\ijji\ENGLISH\u_gbound.exe C:\\ijji\ENGLISH\u_skid.exe C:\\ijji\ENGLISH\u_skid\dbghelp.dll C:\\ijji\ENGLISH\u_skid\DSETUP.dll C:\\ijji\ENGLISH\u_skid\HanAuthForClient.dll C:\\ijji\ENGLISH\u_skid\HanReportForClient.dll C:\\ijji\ENGLISH\u_skid\u_dcity.exe C:\\ijji\ENGLISH\u_skid_fordownloader.exe C:\\ijji\ENGLISH\urlhgb3.cfg C:\\ijji\ENGLISH\urlhgc3.cfg C:\\ijji\ENGLISH\USAAniChannelWnd.dll C:\\ijji\ENGLISH\UsaBase.dll C:\\ijji\ENGLISH\USABASE.hvr C:\\ijji\ENGLISH\UsaBaseExt.dll C:\\ijji\ENGLISH\XDebug.dll C:\\ijji\ENGLISH\XFire\xfire_installer_27409.driftcity.exe C:\\ijji\ENGLISH\XInNetwork.dll C:\\ijji\ENGLISH\XPlatform.dll C:\\ijji\ENGLISH\XStream.dll C:\\ijji\ENGLISH\XSystem.dll C:\Documents and Settings\AlexDong\Application Data\dvdcss C:\Documents and Settings\AlexDong\Application Data\dvdcss\CACHEDIR.TAG C:\Documents and Settings\AlexDong\Application Data\dvdcss\THE_WIZARD_OF_OZ-2005081516371200-2b36e4e9d7\0000019893 C:\Documents and Settings\AlexDong\Application Data\dvdcss\THE_WIZARD_OF_OZ-2005081516371200-2b36e4e9d7\000002038e C:\Documents and Settings\AlexDong\Local Settings\Temporary Internet Files\ijjistarter2FxB.exe C:\Documents and Settings\All Users\Application Data\Symantec C:\Documents and Settings\All Users\Application Data\Symantec\LiveUpdate\Product.Inventory.LiveUpdate C:\Documents and Settings\All Users\Application Data\Symantec\LiveUpdate\Settings.LiveUpdate C:\Documents and Settings\All Users\Application Data\Symantec\rmt.dat C:\Documents and Settings\All Users\Application Data\Symantec\Shared\QBackup\{6264B4CC-4FA2-4731-9E10-0558B109FCDF}.qbi C:\Documents and Settings\All Users\Application Data\Symantec\Shared\QBackup\{6264B4CC-4FA2-4731-9E10-0558B109FCDF}\{3B178E35-4454-4DBD-AAFC-10FDA0760093}.qbd C:\Documents and Settings\All Users\Application Data\Symantec\Shared\QBackup\{6264B4CC-4FA2-4731-9E10-0558B109FCDF}\{3B178E35-4454-4DBD-AAFC-10FDA0760093}.qbi C:\Documents and Settings\All Users\Application Data\Symantec\Shared\QBackup\{6264B4CC-4FA2-4731-9E10-0558B109FCDF}\{3E9DAB77-A08C-43ED-9208-BBFA2663FE25}.qbd C:\Documents and Settings\All Users\Application Data\Symantec\Shared\QBackup\{6264B4CC-4FA2-4731-9E10-0558B109FCDF}\{3E9DAB77-A08C-43ED-9208-BBFA2663FE25}.qbi C:\Documents and Settings\All Users\Application Data\Symantec\Shared\QBackup\{6264B4CC-4FA2-4731-9E10-0558B109FCDF}\{43090295-8F23-4899-BEB9-553617D0BFC9}.qbd C:\Documents and Settings\All Users\Application Data\Symantec\Shared\QBackup\{6264B4CC-4FA2-4731-9E10-0558B109FCDF}\{43090295-8F23-4899-BEB9-553617D0BFC9}.qbi C:\Documents and Settings\All Users\Application Data\Symantec\Shared\QBackup\{6264B4CC-4FA2-4731-9E10-0558B109FCDF}\{690F8E8D-BDE6-45D2-9FCE-E44C869886D5}.qbd C:\Documents and Settings\All Users\Application Data\Symantec\Shared\QBackup\{6264B4CC-4FA2-4731-9E10-0558B109FCDF}\{690F8E8D-BDE6-45D2-9FCE-E44C869886D5}.qbi C:\Documents and Settings\All Users\Application Data\Symantec\Shared\QBackup\{6264B4CC-4FA2-4731-9E10-0558B109FCDF}\{7734629D-4A43-42D9-BFEA-E3D4A58C9E5F}.qbd C:\Documents and Settings\All Users\Application Data\Symantec\Shared\QBackup\{6264B4CC-4FA2-4731-9E10-0558B109FCDF}\{7734629D-4A43-42D9-BFEA-E3D4A58C9E5F}.qbi C:\Documents and Settings\All Users\Application Data\Symantec\Shared\QBackup\{6264B4CC-4FA2-4731-9E10-0558B109FCDF}\{CA435F40-E562-4F7D-9225-CF7671884D1E}.qbd C:\Documents and Settings\All Users\Application Data\Symantec\Shared\QBackup\{6264B4CC-4FA2-4731-9E10-0558B109FCDF}\{CA435F40-E562-4F7D-9225-CF7671884D1E}.qbi C:\Documents and Settings\All Users\Application Data\Symantec\Shared\QBackup\{6264B4CC-4FA2-4731-9E10-0558B109FCDF}\{E26713BF-57D3-40A9-8328-96C008F05B88}.qbd C:\Documents and Settings\All Users\Application Data\Symantec\Shared\QBackup\{6264B4CC-4FA2-4731-9E10-0558B109FCDF}\{E26713BF-57D3-40A9-8328-96C008F05B88}.qbi C:\Documents and Settings\All Users\Application Data\Symantec\Shared\QBackup\{6264B4CC-4FA2-4731-9E10-0558B109FCDF}\{EE35A479-29A5-4D4A-8D28-FD83102FB8E8}.qbd C:\Documents and Settings\All Users\Application Data\Symantec\Shared\QBackup\{6264B4CC-4FA2-4731-9E10-0558B109FCDF}\{EE35A479-29A5-4D4A-8D28-FD83102FB8E8}.qbi C:\Documents and Settings\All Users\Application Data\Symantec\wds.dat C:\PROGRA~1\COMMON~1\SYMANT~1\CCPD-LC\symlcsvc.exe\ C:\Program Files\Common Files\Symantec Shared C:\Program Files\Common Files\Symantec Shared\CCPD-LC\ez_log.htm C:\Program Files\Common Files\Symantec Shared\CCPD-LC\symlcnet.dll C:\Program Files\Common Files\Symantec Shared\CCPD-LC\symlcrst.dll C:\Program Files\Common Files\Symantec Shared\CCPD-LC\symlcsvc.exe C:\Program Files\Common Files\Symantec Shared\CCPD-LC\symlctnk.dll C:\Program Files\Common Files\Symantec Shared\COH\coh.cache C:\Program Files\Common Files\Symantec Shared\COH\COH32.exe C:\Program Files\Common Files\Symantec Shared\COH\COH64.exe C:\Program Files\Common Files\Symantec Shared\COH\COHClean.dll C:\Program Files\Common Files\Symantec Shared\COH\sH0000.dll C:\Program Files\Common Files\Symantec Shared\EENGINE\eeCtrl.sys C:\Program Files\Common Files\Symantec Shared\SPManifests\eraser.grd C:\Program Files\Common Files\Symantec Shared\SPManifests\eraser.sig C:\Program Files\Common Files\Symantec Shared\SPManifests\eraser.spm C:\Program Files\Common Files\Symantec Shared\SPManifests\symcleng.grd C:\Program Files\Common Files\Symantec Shared\SPManifests\symcleng.sig C:\Program Files\Common Files\Symantec Shared\SPManifests\symcleng.spm C:\Program Files\Common Files\Symantec Shared\VirusDefs\20070327.019\CATALOG.DAT C:\Program Files\Common Files\Symantec Shared\VirusDefs\20070327.019\CCERASER.DLL C:\Program Files\Common Files\Symantec Shared\VirusDefs\20070327.019\ECBOOTIL.VXD C:\Program Files\Common Files\Symantec Shared\VirusDefs\20070327.019\ECMSVR32.DLL C:\Program Files\Common Files\Symantec Shared\VirusDefs\20070327.019\EECTRL.SYS C:\Program Files\Common Files\Symantec Shared\VirusDefs\20070327.019\ERASER.GRD C:\Program Files\Common Files\Symantec Shared\VirusDefs\20070327.019\ERASER.SIG C:\Program Files\Common Files\Symantec Shared\VirusDefs\20070327.019\ERASER.SPM C:\Program Files\Common Files\Symantec Shared\VirusDefs\20070327.019\ERASER.SYS C:\Program Files\Common Files\Symantec Shared\VirusDefs\20070327.019\ESRDEF.BIN C:\Program Files\Common Files\Symantec Shared\VirusDefs\20070327.019\HH C:\Program Files\Common Files\Symantec Shared\VirusDefs\20070327.019\NAVENG.EXP C:\Program Files\Common Files\Symantec Shared\VirusDefs\20070327.019\NAVENG.SYS C:\Program Files\Common Files\Symantec Shared\VirusDefs\20070327.019\NAVENG.VXD C:\Program Files\Common Files\Symantec Shared\VirusDefs\20070327.019\NAVENG32.DLL C:\Program Files\Common Files\Symantec Shared\VirusDefs\20070327.019\NAVEX15.EXP C:\Program Files\Common Files\Symantec Shared\VirusDefs\20070327.019\NAVEX15.SYS C:\Program Files\Common Files\Symantec Shared\VirusDefs\20070327.019\NAVEX15.VXD C:\Program Files\Common Files\Symantec Shared\VirusDefs\20070327.019\NAVEX32A.DLL C:\Program Files\Common Files\Symantec Shared\VirusDefs\20070327.019\NCSACERT.TXT C:\Program Files\Common Files\Symantec Shared\VirusDefs\20070327.019\SCRAUTH.DAT C:\Program Files\Common Files\Symantec Shared\VirusDefs\20070327.019\SYMAVENG.CAT C:\Program Files\Common Files\Symantec Shared\VirusDefs\20070327.019\SYMAVENG.INF C:\Program Files\Common Files\Symantec Shared\VirusDefs\20070327.019\SYMERASE.CAT C:\Program Files\Common Files\Symantec Shared\VirusDefs\20070327.019\SYMERASE.INF C:\Program Files\Common Files\Symantec Shared\VirusDefs\20070327.019\TCDEFS.DAT C:\Program Files\Common Files\Symantec Shared\VirusDefs\20070327.019\TCSCAN7.DAT C:\Program Files\Common Files\Symantec Shared\VirusDefs\20070327.019\TCSCAN8.DAT C:\Program Files\Common Files\Symantec Shared\VirusDefs\20070327.019\TCSCAN9.DAT C:\Program Files\Common Files\Symantec Shared\VirusDefs\20070327.019\TECHNOTE.TXT C:\Program Files\Common Files\Symantec Shared\VirusDefs\20070327.019\TINF.DAT C:\Program Files\Common Files\Symantec Shared\VirusDefs\20070327.019\TINFIDX.DAT C:\Program Files\Common Files\Symantec Shared\VirusDefs\20070327.019\TINFL.DAT C:\Program Files\Common Files\Symantec Shared\VirusDefs\20070327.019\TSCAN1.DAT C:\Program Files\Common Files\Symantec Shared\VirusDefs\20070327.019\TSCAN1HD.DAT C:\Program Files\Common Files\Symantec Shared\VirusDefs\20070327.019\UPDATE.TXT C:\Program Files\Common Files\Symantec Shared\VirusDefs\20070327.019\V.GRD C:\Program Files\Common Files\Symantec Shared\VirusDefs\20070327.019\V.SIG C:\Program Files\Common Files\Symantec Shared\VirusDefs\20070327.019\VIRSCAN.INF C:\Program Files\Common Files\Symantec Shared\VirusDefs\20070327.019\VIRSCAN1.DAT C:\Program Files\Common Files\Symantec Shared\VirusDefs\20070327.019\VIRSCAN2.DAT C:\Program Files\Common Files\Symantec Shared\VirusDefs\20070327.019\VIRSCAN3.DAT C:\Program Files\Common Files\Symantec Shared\VirusDefs\20070327.019\VIRSCAN4.DAT C:\Program Files\Common Files\Symantec Shared\VirusDefs\20070327.019\VIRSCAN5.DAT C:\Program Files\Common Files\Symantec Shared\VirusDefs\20070327.019\VIRSCAN6.DAT C:\Program Files\Common Files\Symantec Shared\VirusDefs\20070327.019\VIRSCAN7.DAT C:\Program Files\Common Files\Symantec Shared\VirusDefs\20070327.019\VIRSCAN8.DAT C:\Program Files\Common Files\Symantec Shared\VirusDefs\20070327.019\VIRSCAN9.DAT C:\Program Files\Common Files\Symantec Shared\VirusDefs\20070327.019\VIRSCANT.DAT C:\Program Files\Common Files\Symantec Shared\VirusDefs\20070327.019\WHATSNEW.TXT C:\Program Files\Common Files\Symantec Shared\VirusDefs\20070327.019\ZDONE.DAT C:\Program Files\Common Files\Symantec Shared\VirusDefs\20071029.008\CATALOG.DAT C:\Program Files\Common Files\Symantec Shared\VirusDefs\20071029.008\CCERASER.DLL C:\Program Files\Common Files\Symantec Shared\VirusDefs\20071029.008\ECBOOTIL.VXD C:\Program Files\Common Files\Symantec Shared\VirusDefs\20071029.008\ECMSVR32.DLL C:\Program Files\Common Files\Symantec Shared\VirusDefs\20071029.008\EECTRL.SYS C:\Program Files\Common Files\Symantec Shared\VirusDefs\20071029.008\ERASER.GRD C:\Program Files\Common Files\Symantec Shared\VirusDefs\20071029.008\ERASER.SIG C:\Program Files\Common Files\Symantec Shared\VirusDefs\20071029.008\ERASER.SPM C:\Program Files\Common Files\Symantec Shared\VirusDefs\20071029.008\ERASER.SYS C:\Program Files\Common Files\Symantec Shared\VirusDefs\20071029.008\ESRDEF.BIN C:\Program Files\Common Files\Symantec Shared\VirusDefs\20071029.008\HH C:\Program Files\Common Files\Symantec Shared\VirusDefs\20071029.008\NAVENG.EXP C:\Program Files\Common Files\Symantec Shared\VirusDefs\20071029.008\NAVENG.SYS C:\Program Files\Common Files\Symantec Shared\VirusDefs\20071029.008\NAVENG.VXD C:\Program Files\Common Files\Symantec Shared\VirusDefs\20071029.008\NAVENG32.DLL C:\Program Files\Common Files\Symantec Shared\VirusDefs\20071029.008\NAVEX15.EXP C:\Program Files\Common Files\Symantec Shared\VirusDefs\20071029.008\NAVEX15.SYS C:\Program Files\Common Files\Symantec Shared\VirusDefs\20071029.008\NAVEX15.VXD C:\Program Files\Common Files\Symantec Shared\VirusDefs\20071029.008\NAVEX32A.DLL C:\Program Files\Common Files\Symantec Shared\VirusDefs\20071029.008\NCSACERT.TXT C:\Program Files\Common Files\Symantec Shared\VirusDefs\20071029.008\SCRAUTH.DAT C:\Program Files\Common Files\Symantec Shared\VirusDefs\20071029.008\SYMAVENG.CAT C:\Program Files\Common Files\Symantec Shared\VirusDefs\20071029.008\SYMAVENG.INF C:\Program Files\Common Files\Symantec Shared\VirusDefs\20071029.008\SYMERASE.CAT C:\Program Files\Common Files\Symantec Shared\VirusDefs\20071029.008\SYMERASE.INF C:\Program Files\Common Files\Symantec Shared\VirusDefs\20071029.008\TCDEFS.DAT C:\Program Files\Common Files\Symantec Shared\VirusDefs\20071029.008\TCSCAN7.DAT C:\Program Files\Common Files\Symantec Shared\VirusDefs\20071029.008\TCSCAN8.DAT C:\Program Files\Common Files\Symantec Shared\VirusDefs\20071029.008\TCSCAN9.DAT C:\Program Files\Common Files\Symantec Shared\VirusDefs\20071029.008\TECHNOTE.TXT C:\Program Files\Common Files\Symantec Shared\VirusDefs\20071029.008\TINF.DAT C:\Program Files\Common Files\Symantec Shared\VirusDefs\20071029.008\TINFIDX.DAT C:\Program Files\Common Files\Symantec Shared\VirusDefs\20071029.008\TINFL.DAT C:\Program Files\Common Files\Symantec Shared\VirusDefs\20071029.008\TSCAN1.DAT C:\Program Files\Common Files\Symantec Shared\VirusDefs\20071029.008\TSCAN1HD.DAT C:\Program Files\Common Files\Symantec Shared\VirusDefs\20071029.008\UPDATE.TXT C:\Program Files\Common Files\Symantec Shared\VirusDefs\20071029.008\V.GRD C:\Program Files\Common Files\Symantec Shared\VirusDefs\20071029.008\V.SIG C:\Program Files\Common Files\Symantec Shared\VirusDefs\20071029.008\VIRSCAN.INF C:\Program Files\Common Files\Symantec Shared\VirusDefs\20071029.008\VIRSCAN1.DAT C:\Program Files\Common Files\Symantec Shared\VirusDefs\20071029.008\VIRSCAN2.DAT C:\Program Files\Common Files\Symantec Shared\VirusDefs\20071029.008\VIRSCAN3.DAT C:\Program Files\Common Files\Symantec Shared\VirusDefs\20071029.008\VIRSCAN4.DAT C:\Program Files\Common Files\Symantec Shared\VirusDefs\20071029.008\VIRSCAN5.DAT C:\Program Files\Common Files\Symantec Shared\VirusDefs\20071029.008\VIRSCAN6.DAT C:\Program Files\Common Files\Symantec Shared\VirusDefs\20071029.008\VIRSCAN7.DAT C:\Program Files\Common Files\Symantec Shared\VirusDefs\20071029.008\VIRSCAN8.DAT C:\Program Files\Common Files\Symantec Shared\VirusDefs\20071029.008\VIRSCAN9.DAT C:\Program Files\Common Files\Symantec Shared\VirusDefs\20071029.008\VIRSCANT.DAT C:\Program Files\Common Files\Symantec Shared\VirusDefs\20071029.008\WHATSNEW.TXT C:\Program Files\Common Files\Symantec Shared\VirusDefs\20071029.008\ZDONE.DAT C:\Program Files\Common Files\Symantec Shared\VirusDefs\20071102.016\CATALOG.DAT C:\Program Files\Common Files\Symantec Shared\VirusDefs\20071102.016\CCERASER.DLL C:\Program Files\Common Files\Symantec Shared\VirusDefs\20071102.016\ECBOOTIL.VXD C:\Program Files\Common Files\Symantec Shared\VirusDefs\20071102.016\ECMSVR32.DLL C:\Program Files\Common Files\Symantec Shared\VirusDefs\20071102.016\EECTRL.SYS C:\Program Files\Common Files\Symantec Shared\VirusDefs\20071102.016\ERASER.GRD C:\Program Files\Common Files\Symantec Shared\VirusDefs\20071102.016\ERASER.SIG C:\Program Files\Common Files\Symantec Shared\VirusDefs\20071102.016\ERASER.SPM C:\Program Files\Common Files\Symantec Shared\VirusDefs\20071102.016\ERASER.SYS C:\Program Files\Common Files\Symantec Shared\VirusDefs\20071102.016\ESRDEF.BIN C:\Program Files\Common Files\Symantec Shared\VirusDefs\20071102.016\HH C:\Program Files\Common Files\Symantec Shared\VirusDefs\20071102.016\NAVENG.EXP C:\Program Files\Common Files\Symantec Shared\VirusDefs\20071102.016\NAVENG.SYS C:\Program Files\Common Files\Symantec Shared\VirusDefs\20071102.016\NAVENG.VXD C:\Program Files\Common Files\Symantec Shared\VirusDefs\20071102.016\NAVENG32.DLL C:\Program Files\Common Files\Symantec Shared\VirusDefs\20071102.016\NAVEX15.EXP C:\Program Files\Common Files\Symantec Shared\VirusDefs\20071102.016\NAVEX15.SYS C:\Program Files\Common Files\Symantec Shared\VirusDefs\20071102.016\NAVEX15.VXD C:\Program Files\Common Files\Symantec Shared\VirusDefs\20071102.016\NAVEX32A.DLL C:\Program Files\Common Files\Symantec Shared\VirusDefs\20071102.016\NCSACERT.TXT C:\Program Files\Common Files\Symantec Shared\VirusDefs\20071102.016\SCRAUTH.DAT C:\Program Files\Common Files\Symantec Shared\VirusDefs\20071102.016\SYMAVENG.CAT C:\Program Files\Common Files\Symantec Shared\VirusDefs\20071102.016\SYMAVENG.INF C:\Program Files\Common Files\Symantec Shared\VirusDefs\20071102.016\SYMERASE.CAT C:\Program Files\Common Files\Symantec Shared\VirusDefs\20071102.016\SYMERASE.INF C:\Program Files\Common Files\Symantec Shared\VirusDefs\20071102.016\TCDEFS.DAT C:\Program Files\Common Files\Symantec Shared\VirusDefs\20071102.016\TCSCAN7.DAT C:\Program Files\Common Files\Symantec Shared\VirusDefs\20071102.016\TCSCAN8.DAT C:\Program Files\Common Files\Symantec Shared\VirusDefs\20071102.016\TCSCAN9.DAT C:\Program Files\Common Files\Symantec Shared\VirusDefs\20071102.016\TECHNOTE.TXT C:\Program Files\Common Files\Symantec Shared\VirusDefs\20071102.016\TINF.DAT C:\Program Files\Common Files\Symantec Shared\VirusDefs\20071102.016\TINFIDX.DAT C:\Program Files\Common Files\Symantec Shared\VirusDefs\20071102.016\TINFL.DAT C:\Program Files\Common Files\Symantec Shared\VirusDefs\20071102.016\TSCAN1.DAT C:\Program Files\Common Files\Symantec Shared\VirusDefs\20071102.016\TSCAN1HD.DAT C:\Program Files\Common Files\Symantec Shared\VirusDefs\20071102.016\UPDATE.TXT C:\Program Files\Common Files\Symantec Shared\VirusDefs\20071102.016\V.GRD C:\Program Files\Common Files\Symantec Shared\VirusDefs\20071102.016\V.SIG C:\Program Files\Common Files\Symantec Shared\VirusDefs\20071102.016\VIRSCAN.INF C:\Program Files\Common Files\Symantec Shared\VirusDefs\20071102.016\VIRSCAN1.DAT C:\Program Files\Common Files\Symantec Shared\VirusDefs\20071102.016\VIRSCAN2.DAT C:\Program Files\Common Files\Symantec Shared\VirusDefs\20071102.016\VIRSCAN3.DAT C:\Program Files\Common Files\Symantec Shared\VirusDefs\20071102.016\VIRSCAN4.DAT C:\Program Files\Common Files\Symantec Shared\VirusDefs\20071102.016\VIRSCAN5.DAT C:\Program Files\Common Files\Symantec Shared\VirusDefs\20071102.016\VIRSCAN6.DAT C:\Program Files\Common Files\Symantec Shared\VirusDefs\20071102.016\VIRSCAN7.DAT C:\Program Files\Common Files\Symantec Shared\VirusDefs\20071102.016\VIRSCAN8.DAT C:\Program Files\Common Files\Symantec Shared\VirusDefs\20071102.016\VIRSCAN9.DAT C:\Program Files\Common Files\Symantec Shared\VirusDefs\20071102.016\VIRSCANT.DAT C:\Program Files\Common Files\Symantec Shared\VirusDefs\20071102.016\vscanmsx.dat C:\Program Files\Common Files\Symantec Shared\VirusDefs\20071102.016\WHATSNEW.TXT C:\Program Files\Common Files\Symantec Shared\VirusDefs\20071102.016\ZDONE.DAT C:\Program Files\Common Files\Symantec Shared\VirusDefs\20071103.005\CATALOG.DAT C:\Program Files\Common Files\Symantec Shared\VirusDefs\20071103.005\CCERASER.DLL C:\Program Files\Common Files\Symantec Shared\VirusDefs\20071103.005\ECBOOTIL.VXD C:\Program Files\Common Files\Symantec Shared\VirusDefs\20071103.005\ECMSVR32.DLL C:\Program Files\Common Files\Symantec Shared\VirusDefs\20071103.005\EECTRL.SYS C:\Program Files\Common Files\Symantec Shared\VirusDefs\20071103.005\ERASER.GRD C:\Program Files\Common Files\Symantec Shared\VirusDefs\20071103.005\ERASER.SIG C:\Program Files\Common Files\Symantec Shared\VirusDefs\20071103.005\ERASER.SPM C:\Program Files\Common Files\Symantec Shared\VirusDefs\20071103.005\ERASER.SYS C:\Program Files\Common Files\Symantec Shared\VirusDefs\20071103.005\ESRDEF.BIN C:\Program Files\Common Files\Symantec Shared\VirusDefs\20071103.005\HH C:\Program Files\Common Files\Symantec Shared\VirusDefs\20071103.005\NAVENG.EXP C:\Program Files\Common Files\Symantec Shared\VirusDefs\20071103.005\NAVENG.SYS C:\Program Files\Common Files\Symantec Shared\VirusDefs\20071103.005\NAVENG.VXD C:\Program Files\Common Files\Symantec Shared\VirusDefs\20071103.005\NAVENG32.DLL C:\Program Files\Common Files\Symantec Shared\VirusDefs\20071103.005\NAVEX15.EXP C:\Program Files\Common Files\Symantec Shared\VirusDefs\20071103.005\NAVEX15.SYS C:\Program Files\Common Files\Symantec Shared\VirusDefs\20071103.005\NAVEX15.VXD C:\Program Files\Common Files\Symantec Shared\VirusDefs\20071103.005\NAVEX32A.DLL C:\Program Files\Common Files\Symantec Shared\VirusDefs\20071103.005\NCSACERT.TXT C:\Program Files\Common Files\Symantec Shared\VirusDefs\20071103.005\SCRAUTH.DAT C:\Program Files\Common Files\Symantec Shared\VirusDefs\20071103.005\SYMAVENG.CAT C:\Program Files\Common Files\Symantec Shared\VirusDefs\20071103.005\SYMAVENG.INF C:\Program Files\Common Files\Symantec Shared\VirusDefs\20071103.005\SYMERASE.CAT C:\Program Files\Common Files\Symantec Shared\VirusDefs\20071103.005\SYMERASE.INF C:\Program Files\Common Files\Symantec Shared\VirusDefs\20071103.005\TCDEFS.DAT C:\Program Files\Common Files\Symantec Shared\VirusDefs\20071103.005\TCSCAN7.DAT C:\Program Files\Common Files\Symantec Shared\VirusDefs\20071103.005\TCSCAN8.DAT C:\Program Files\Common Files\Symantec Shared\VirusDefs\20071103.005\TCSCAN9.DAT C:\Program Files\Common Files\Symantec Shared\VirusDefs\20071103.005\TECHNOTE.TXT C:\Program Files\Common Files\Symantec Shared\VirusDefs\20071103.005\TINF.DAT C:\Program Files\Common Files\Symantec Shared\VirusDefs\20071103.005\TINFIDX.DAT C:\Program Files\Common Files\Symantec Shared\VirusDefs\20071103.005\TINFL.DAT C:\Program Files\Common Files\Symantec Shared\VirusDefs\20071103.005\TSCAN1.DAT C:\Program Files\Common Files\Symantec Shared\VirusDefs\20071103.005\TSCAN1HD.DAT C:\Program Files\Common Files\Symantec Shared\VirusDefs\20071103.005\UPDATE.TXT C:\Program Files\Common Files\Symantec Shared\VirusDefs\20071103.005\V.GRD C:\Program Files\Common Files\Symantec Shared\VirusDefs\20071103.005\V.SIG C:\Program Files\Common Files\Symantec Shared\VirusDefs\20071103.005\VIRSCAN.INF C:\Program Files\Common Files\Symantec Shared\VirusDefs\20071103.005\VIRSCAN1.DAT C:\Program Files\Common Files\Symantec Shared\VirusDefs\20071103.005\VIRSCAN2.DAT C:\Program Files\Common Files\Symantec Shared\VirusDefs\20071103.005\VIRSCAN3.DAT C:\Program Files\Common Files\Symantec Shared\VirusDefs\20071103.005\VIRSCAN4.DAT C:\Program Files\Common Files\Symantec Shared\VirusDefs\20071103.005\VIRSCAN5.DAT C:\Program Files\Common Files\Symantec Shared\VirusDefs\20071103.005\VIRSCAN6.DAT C:\Program Files\Common Files\Symantec Shared\VirusDefs\20071103.005\VIRSCAN7.DAT C:\Program Files\Common Files\Symantec Shared\VirusDefs\20071103.005\VIRSCAN8.DAT C:\Program Files\Common Files\Symantec Shared\VirusDefs\20071103.005\VIRSCAN9.DAT C:\Program Files\Common Files\Symantec Shared\VirusDefs\20071103.005\VIRSCANT.DAT C:\Program Files\Common Files\Symantec Shared\VirusDefs\20071103.005\WHATSNEW.TXT C:\Program Files\Common Files\Symantec Shared\VirusDefs\20071103.005\ZDONE.DAT C:\Program Files\Common Files\Symantec Shared\VirusDefs\BinHub\catalog.dat C:\Program Files\Common Files\Symantec Shared\VirusDefs\BinHub\cceraser.dll C:\Program Files\Common Files\Symantec Shared\VirusDefs\BinHub\ecbootil.vxd C:\Program Files\Common Files\Symantec Shared\VirusDefs\BinHub\ecmsvr32.dll C:\Program Files\Common Files\Symantec Shared\VirusDefs\BinHub\eeCtrl.sys C:\Program Files\Common Files\Symantec Shared\VirusDefs\BinHub\ERASER.grd C:\Program Files\Common Files\Symantec Shared\VirusDefs\BinHub\ERASER.sig C:\Program Files\Common Files\Symantec Shared\VirusDefs\BinHub\ERASER.spm C:\Program Files\Common Files\Symantec Shared\VirusDefs\BinHub\eraser.sys C:\Program Files\Common Files\Symantec Shared\VirusDefs\BinHub\esrdef.bin C:\Program Files\Common Files\Symantec Shared\VirusDefs\BinHub\hh C:\Program Files\Common Files\Symantec Shared\VirusDefs\BinHub\naveng.exp C:\Program Files\Common Files\Symantec Shared\VirusDefs\BinHub\naveng.sys C:\Program Files\Common Files\Symantec Shared\VirusDefs\BinHub\naveng.vxd C:\Program Files\Common Files\Symantec Shared\VirusDefs\BinHub\naveng32.dll C:\Program Files\Common Files\Symantec Shared\VirusDefs\BinHub\navex15.exp C:\Program Files\Common Files\Symantec Shared\VirusDefs\BinHub\navex15.sys C:\Program Files\Common Files\Symantec Shared\VirusDefs\BinHub\navex15.vxd C:\Program Files\Common Files\Symantec Shared\VirusDefs\BinHub\navex32a.dll C:\Program Files\Common Files\Symantec Shared\VirusDefs\BinHub\ncsacert.txt C:\Program Files\Common Files\Symantec Shared\VirusDefs\BinHub\scrauth.dat C:\Program Files\Common Files\Symantec Shared\VirusDefs\BinHub\symaveng.cat C:\Program Files\Common Files\Symantec Shared\VirusDefs\BinHub\symaveng.inf C:\Program Files\Common Files\Symantec Shared\VirusDefs\BinHub\SymErase.cat C:\Program Files\Common Files\Symantec Shared\VirusDefs\BinHub\SymErase.inf C:\Program Files\Common Files\Symantec Shared\VirusDefs\BinHub\tcdefs.dat C:\Program Files\Common Files\Symantec Shared\VirusDefs\BinHub\tcscan7.dat C:\Program Files\Common Files\Symantec Shared\VirusDefs\BinHub\tcscan8.dat C:\Program Files\Common Files\Symantec Shared\VirusDefs\BinHub\tcscan9.dat C:\Program Files\Common Files\Symantec Shared\VirusDefs\BinHub\technote.txt C:\Program Files\Common Files\Symantec Shared\VirusDefs\BinHub\tinf.dat C:\Program Files\Common Files\Symantec Shared\VirusDefs\BinHub\tinfidx.dat C:\Program Files\Common Files\Symantec Shared\VirusDefs\BinHub\tinfl.dat C:\Program Files\Common Files\Symantec Shared\VirusDefs\BinHub\tscan1.dat C:\Program Files\Common Files\Symantec Shared\VirusDefs\BinHub\tscan1hd.dat C:\Program Files\Common Files\Symantec Shared\VirusDefs\BinHub\v.grd C:\Program Files\Common Files\Symantec Shared\VirusDefs\BinHub\v.sig C:\Program Files\Common Files\Symantec Shared\VirusDefs\BinHub\virscan.inf C:\Program Files\Common Files\Symantec Shared\VirusDefs\BinHub\virscan1.dat C:\Program Files\Common Files\Symantec Shared\VirusDefs\BinHub\virscan2.dat C:\Program Files\Common Files\Symantec Shared\VirusDefs\BinHub\virscan3.dat C:\Program Files\Common Files\Symantec Shared\VirusDefs\BinHub\virscan4.dat C:\Program Files\Common Files\Symantec Shared\VirusDefs\BinHub\virscan5.dat C:\Program Files\Common Files\Symantec Shared\VirusDefs\BinHub\virscan6.dat C:\Program Files\Common Files\Symantec Shared\VirusDefs\BinHub\virscan7.dat C:\Program Files\Common Files\Symantec Shared\VirusDefs\BinHub\virscan8.dat C:\Program Files\Common Files\Symantec Shared\VirusDefs\BinHub\virscan9.dat C:\Program Files\Common Files\Symantec Shared\VirusDefs\BinHub\VIRSCANT.DAT C:\Program Files\Common Files\Symantec Shared\VirusDefs\BinHub\whatsnew.txt C:\Program Files\Common Files\Symantec Shared\VirusDefs\BinHub\zdone.dat C:\Program Files\Common Files\Symantec Shared\VirusDefs\definfo.dat C:\Program Files\Common Files\Symantec Shared\VirusDefs\TextHub\virscant.dat C:\Program Files\Common Files\Symantec Shared\VirusDefs\tmp163b.tmp\CATALOG.DAT C:\Program Files\Common Files\Symantec Shared\VirusDefs\tmp163b.tmp\CCERASER.DLL C:\Program Files\Common Files\Symantec Shared\VirusDefs\tmp163b.tmp\cur.scr C:\Program Files\Common Files\Symantec Shared\VirusDefs\tmp163b.tmp\ECBOOTIL.VXD C:\Program Files\Common Files\Symantec Shared\VirusDefs\tmp163b.tmp\ECMSVR32.DLL C:\Program Files\Common Files\Symantec Shared\VirusDefs\tmp163b.tmp\eeCtrl.sys C:\Program Files\Common Files\Symantec Shared\VirusDefs\tmp163b.tmp\ERASER.grd C:\Program Files\Common Files\Symantec Shared\VirusDefs\tmp163b.tmp\ERASER.sig C:\Program Files\Common Files\Symantec Shared\VirusDefs\tmp163b.tmp\ERASER.spm C:\Program Files\Common Files\Symantec Shared\VirusDefs\tmp163b.tmp\eraser.sys C:\Program Files\Common Files\Symantec Shared\VirusDefs\tmp163b.tmp\ESRDEF.999 C:\Program Files\Common Files\Symantec Shared\VirusDefs\tmp163b.tmp\ESRDEF.BIN C:\Program Files\Common Files\Symantec Shared\VirusDefs\tmp163b.tmp\HH C:\Program Files\Common Files\Symantec Shared\VirusDefs\tmp163b.tmp\hub.scr C:\Program Files\Common Files\Symantec Shared\VirusDefs\tmp163b.tmp\NAVENG.998 C:\Program Files\Common Files\Symantec Shared\VirusDefs\tmp163b.tmp\NAVENG.EXP C:\Program Files\Common Files\Symantec Shared\VirusDefs\tmp163b.tmp\NAVENG.SYS C:\Program Files\Common Files\Symantec Shared\VirusDefs\tmp163b.tmp\NAVENG.VXD C:\Program Files\Common Files\Symantec Shared\VirusDefs\tmp163b.tmp\NAVENG32.DLL C:\Program Files\Common Files\Symantec Shared\VirusDefs\tmp163b.tmp\NAVEX15.997 C:\Program Files\Common Files\Symantec Shared\VirusDefs\tmp163b.tmp\NAVEX15.EXP C:\Program Files\Common Files\Symantec Shared\VirusDefs\tmp163b.tmp\NAVEX15.SYS C:\Program Files\Common Files\Symantec Shared\VirusDefs\tmp163b.tmp\NAVEX15.VXD C:\Program Files\Common Files\Symantec Shared\VirusDefs\tmp163b.tmp\NAVEX32A.DLL C:\Program Files\Common Files\Symantec Shared\VirusDefs\tmp163b.tmp\NCSACERT.TXT C:\Program Files\Common Files\Symantec Shared\VirusDefs\tmp163b.tmp\SCRAUTH.996 C:\Program Files\Common Files\Symantec Shared\VirusDefs\tmp163b.tmp\SCRAUTH.DAT C:\Program Files\Common Files\Symantec Shared\VirusDefs\tmp163b.tmp\SYMAVENG.CAT C:\Program Files\Common Files\Symantec Shared\VirusDefs\tmp163b.tmp\SYMAVENG.INF C:\Program Files\Common Files\Symantec Shared\VirusDefs\tmp163b.tmp\SymErase.cat C:\Program Files\Common Files\Symantec Shared\VirusDefs\tmp163b.tmp\SymErase.inf C:\Program Files\Common Files\Symantec Shared\VirusDefs\tmp163b.tmp\TCDEFS.995 C:\Program Files\Common Files\Symantec Shared\VirusDefs\tmp163b.tmp\TCDEFS.DAT C:\Program Files\Common Files\Symantec Shared\VirusDefs\tmp163b.tmp\TCSCAN7.994 C:\Program Files\Common Files\Symantec Shared\VirusDefs\tmp163b.tmp\TCSCAN7.DAT C:\Program Files\Common Files\Symantec Shared\VirusDefs\tmp163b.tmp\TCSCAN8.993 C:\Program Files\Common Files\Symantec Shared\VirusDefs\tmp163b.tmp\TCSCAN8.DAT C:\Program Files\Common Files\Symantec Shared\VirusDefs\tmp163b.tmp\TCSCAN9.992 C:\Program Files\Common Files\Symantec Shared\VirusDefs\tmp163b.tmp\TCSCAN9.DAT C:\Program Files\Common Files\Symantec Shared\VirusDefs\tmp163b.tmp\TECHNOTE.TXT C:\Program Files\Common Files\Symantec Shared\VirusDefs\tmp163b.tmp\TINF.991 C:\Program Files\Common Files\Symantec Shared\VirusDefs\tmp163b.tmp\TINF.DAT C:\Program Files\Common Files\Symantec Shared\VirusDefs\tmp163b.tmp\TINFIDX.DAT C:\Program Files\Common Files\Symantec Shared\VirusDefs\tmp163b.tmp\TINFL.990 C:\Program Files\Common Files\Symantec Shared\VirusDefs\tmp163b.tmp\TINFL.DAT C:\Program Files\Common Files\Symantec Shared\VirusDefs\tmp163b.tmp\TSCAN1.989 C:\Program Files\Common Files\Symantec Shared\VirusDefs\tmp163b.tmp\TSCAN1.DAT C:\Program Files\Common Files\Symantec Shared\VirusDefs\tmp163b.tmp\TSCAN1HD.988 C:\Program Files\Common Files\Symantec Shared\VirusDefs\tmp163b.tmp\TSCAN1HD.DAT C:\Program Files\Common Files\Symantec Shared\VirusDefs\tmp163b.tmp\V.986 C:\Program Files\Common Files\Symantec Shared\VirusDefs\tmp163b.tmp\V.987 C:\Program Files\Common Files\Symantec Shared\VirusDefs\tmp163b.tmp\V.GRD C:\Program Files\Common Files\Symantec Shared\VirusDefs\tmp163b.tmp\V.SIG C:\Program Files\Common Files\Symantec Shared\VirusDefs\tmp163b.tmp\VIRSCAN.985 C:\Program Files\Common Files\Symantec Shared\VirusDefs\tmp163b.tmp\VIRSCAN.INF C:\Program Files\Common Files\Symantec Shared\VirusDefs\tmp163b.tmp\VIRSCAN1.984 C:\Program Files\Common Files\Symantec Shared\VirusDefs\tmp163b.tmp\VIRSCAN1.DAT C:\Program Files\Common Files\Symantec Shared\VirusDefs\tmp163b.tmp\VIRSCAN2.983 C:\Program Files\Common Files\Symantec Shared\VirusDefs\tmp163b.tmp\VIRSCAN2.DAT C:\Program Files\Common Files\Symantec Shared\VirusDefs\tmp163b.tmp\VIRSCAN3.982 C:\Program Files\Common Files\Symantec Shared\VirusDefs\tmp163b.tmp\VIRSCAN3.DAT C:\Program Files\Common Files\Symantec Shared\VirusDefs\tmp163b.tmp\VIRSCAN4.981 C:\Program Files\Common Files\Symantec Shared\VirusDefs\tmp163b.tmp\VIRSCAN4.DAT C:\Program Files\Common Files\Symantec Shared\VirusDefs\tmp163b.tmp\VIRSCAN5.980 C:\Program Files\Common Files\Symantec Shared\VirusDefs\tmp163b.tmp\VIRSCAN5.DAT C:\Program Files\Common Files\Symantec Shared\VirusDefs\tmp163b.tmp\VIRSCAN6.979 C:\Program Files\Common Files\Symantec Shared\VirusDefs\tmp163b.tmp\VIRSCAN6.DAT C:\Program Files\Common Files\Symantec Shared\VirusDefs\tmp163b.tmp\VIRSCAN7.978 C:\Program Files\Common Files\Symantec Shared\VirusDefs\tmp163b.tmp\VIRSCAN7.DAT C:\Program Files\Common Files\Symantec Shared\VirusDefs\tmp163b.tmp\VIRSCAN8.977 C:\Program Files\Common Files\Symantec Shared\VirusDefs\tmp163b.tmp\VIRSCAN8.DAT C:\Program Files\Common Files\Symantec Shared\VirusDefs\tmp163b.tmp\VIRSCAN9.976 C:\Program Files\Common Files\Symantec Shared\VirusDefs\tmp163b.tmp\VIRSCAN9.DAT C:\Program Files\Common Files\Symantec Shared\VirusDefs\tmp163b.tmp\VIRSCANT.975 C:\Program Files\Common Files\Symantec Shared\VirusDefs\tmp163b.tmp\VIRSCANT.DAT C:\Program Files\Common Files\Symantec Shared\VirusDefs\tmp163b.tmp\WHATSNEW.974 C:\Program Files\Common Files\Symantec Shared\VirusDefs\tmp163b.tmp\WHATSNEW.TXT C:\Program Files\Common Files\Symantec Shared\VirusDefs\tmp163b.tmp\ZDONE.DAT C:\Program Files\Common Files\Symantec Shared\VirusDefs\tmp175e.tmp\catalog.dat C:\Program Files\Common Files\Symantec Shared\VirusDefs\tmp175e.tmp\cceraser.dll C:\Program Files\Common Files\Symantec Shared\VirusDefs\tmp175e.tmp\ecbootil.vxd C:\Program Files\Common Files\Symantec Shared\VirusDefs\tmp175e.tmp\ecmsvr32.dll C:\Program Files\Common Files\Symantec Shared\VirusDefs\tmp175e.tmp\eeCtrl.sys C:\Program Files\Common Files\Symantec Shared\VirusDefs\tmp175e.tmp\ERASER.grd C:\Program Files\Common Files\Symantec Shared\VirusDefs\tmp175e.tmp\ERASER.sig C:\Program Files\Common Files\Symantec Shared\VirusDefs\tmp175e.tmp\ERASER.spm C:\Program Files\Common Files\Symantec Shared\VirusDefs\tmp175e.tmp\eraser.sys C:\Program Files\Common Files\Symantec Shared\VirusDefs\tmp175e.tmp\esrdef.bin C:\Program Files\Common Files\Symantec Shared\VirusDefs\tmp175e.tmp\hh C:\Program Files\Common Files\Symantec Shared\VirusDefs\tmp175e.tmp\naveng.exp C:\Program Files\Common Files\Symantec Shared\VirusDefs\tmp175e.tmp\naveng.sys C:\Program Files\Common Files\Symantec Shared\VirusDefs\tmp175e.tmp\naveng.vxd C:\Program Files\Common Files\Symantec Shared\VirusDefs\tmp175e.tmp\naveng32.dll C:\Program Files\Common Files\Symantec Shared\VirusDefs\tmp175e.tmp\navex15.exp C:\Program Files\Common Files\Symantec Shared\VirusDefs\tmp175e.tmp\navex15.sys C:\Program Files\Common Files\Symantec Shared\VirusDefs\tmp175e.tmp\navex15.vxd C:\Program Files\Common Files\Symantec Shared\VirusDefs\tmp175e.tmp\navex32a.dll C:\Program Files\Common Files\Symantec Shared\VirusDefs\tmp175e.tmp\ncsacert.txt C:\Program Files\Common Files\Symantec Shared\VirusDefs\tmp175e.tmp\scrauth.dat C:\Program Files\Common Files\Symantec Shared\VirusDefs\tmp175e.tmp\symaveng.cat C:\Program Files\Common Files\Symantec Shared\VirusDefs\tmp175e.tmp\symaveng.inf C:\Program Files\Common Files\Symantec Shared\VirusDefs\tmp175e.tmp\SymErase.cat C:\Program Files\Common Files\Symantec Shared\VirusDefs\tmp175e.tmp\SymErase.inf C:\Program Files\Common Files\Symantec Shared\VirusDefs\tmp175e.tmp\tcdefs.dat C:\Program Files\Common Files\Symantec Shared\VirusDefs\tmp175e.tmp\tcscan7.dat C:\Program Files\Common Files\Symantec Shared\VirusDefs\tmp175e.tmp\tcscan8.dat C:\Program Files\Common Files\Symantec Shared\VirusDefs\tmp175e.tmp\tcscan9.dat C:\Program Files\Common Files\Symantec Shared\VirusDefs\tmp175e.tmp\technote.txt C:\Program Files\Common Files\Symantec Shared\VirusDefs\tmp175e.tmp\tinf.dat C:\Program Files\Common Files\Symantec Shared\VirusDefs\tmp175e.tmp\tinfidx.dat C:\Program Files\Common Files\Symantec Shared\VirusDefs\tmp175e.tmp\tinfl.dat C:\Program Files\Common Files\Symantec Shared\VirusDefs\tmp175e.tmp\tscan1.dat C:\Program Files\Common Files\Symantec Shared\VirusDefs\tmp175e.tmp\tscan1hd.dat C:\Program Files\Common Files\Symantec Shared\VirusDefs\tmp175e.tmp\v.grd C:\Program Files\Common Files\Symantec Shared\VirusDefs\tmp175e.tmp\v.sig C:\Program Files\Common Files\Symantec Shared\VirusDefs\tmp175e.tmp\virscan1.dat C:\Program Files\Common Files\Symantec Shared\VirusDefs\tmp175e.tmp\virscan2.dat C:\Program Files\Common Files\Symantec Shared\VirusDefs\tmp175e.tmp\virscan3.dat C:\Program Files\Common Files\Symantec Shared\VirusDefs\tmp175e.tmp\virscan4.dat C:\Program Files\Common Files\Symantec Shared\VirusDefs\tmp175e.tmp\virscan5.dat C:\Program Files\Common Files\Symantec Shared\VirusDefs\tmp175e.tmp\virscan6.dat C:\Program Files\Common Files\Symantec Shared\VirusDefs\tmp175e.tmp\virscan7.dat C:\Program Files\Common Files\Symantec Shared\VirusDefs\tmp175e.tmp\virscan8.dat C:\Program Files\Common Files\Symantec Shared\VirusDefs\tmp175e.tmp\virscan9.dat C:\Program Files\Common Files\Symantec Shared\VirusDefs\tmp175e.tmp\VIRSCANT.DAT C:\Program Files\Common Files\Symantec Shared\VirusDefs\tmp175e.tmp\whatsnew.txt C:\Program Files\Common Files\Symantec Shared\VirusDefs\tmp175e.tmp\zdone.dat C:\Program Files\Common Files\Symantec Shared\VirusDefs\usage.dat C:\Program Files\LimeWire C:\Program Files\LimeWire\COPYING C:\Program Files\LimeWire\data.ser C:\Program Files\LimeWire\hs_err_pid2124.log C:\Program Files\LimeWire\hs_err_pid3060.log C:\Program Files\LimeWire\hs_err_pid3580.log C:\Program Files\LimeWire\hs_err_pid4396.log C:\Program Files\LimeWire\hs_err_pid5884.log C:\Program Files\LimeWire\hs_err_pid9548.log C:\Program Files\LimeWire\hs_err_pid9976.log C:\Program Files\LimeWire\inspection.props C:\Program Files\LimeWire\install.log C:\Program Files\LimeWire\language.prop C:\Program Files\LimeWire\lib\aopalliance.jar C:\Program Files\LimeWire\lib\clink.jar C:\Program Files\LimeWire\lib\commons-codec-1.3.jar C:\Program Files\LimeWire\lib\commons-logging.jar C:\Program Files\LimeWire\lib\commons-net.jar C:\Program Files\LimeWire\lib\daap.jar C:\Program Files\LimeWire\lib\dnsjava.jar C:\Program Files\LimeWire\lib\forms.jar C:\Program Files\LimeWire\lib\foxtrot.jar C:\Program Files\LimeWire\lib\gettext-commons.jar C:\Program Files\LimeWire\lib\guice-1.0.jar C:\Program Files\LimeWire\lib\hashes C:\Program Files\LimeWire\lib\hsqldb.jar C:\Program Files\LimeWire\lib\httpclient-4.0-alpha5-20080522.192134-5.jar C:\Program Files\LimeWire\lib\httpcore-4.0-beta2-20080510.140437-10.jar C:\Program Files\LimeWire\lib\httpcore-nio-4.0-beta2-20080510.140437-10.jar C:\Program Files\LimeWire\lib\icu4j.jar C:\Program Files\LimeWire\lib\jaudiotagger.jar C:\Program Files\LimeWire\lib\jcraft.jar C:\Program Files\LimeWire\lib\jdic.dll C:\Program Files\LimeWire\lib\jdic.jar C:\Program Files\LimeWire\lib\jdic_stub.jar C:\Program Files\LimeWire\lib\jflac.jar C:\Program Files\LimeWire\lib\jl.jar C:\Program Files\LimeWire\lib\jmdns.jar C:\Program Files\LimeWire\lib\jogg.jar C:\Program Files\LimeWire\lib\jorbis.jar C:\Program Files\LimeWire\lib\LimeWire.ico C:\Program Files\LimeWire\lib\LimeWire.jar C:\Program Files\LimeWire\lib\log4j.jar C:\Program Files\LimeWire\lib\log4j.properties C:\Program Files\LimeWire\lib\looks.jar C:\Program Files\LimeWire\lib\messages.jar C:\Program Files\LimeWire\lib\mp3spi.jar C:\Program Files\LimeWire\lib\onion-common.jar C:\Program Files\LimeWire\lib\onion-fec.jar C:\Program Files\LimeWire\lib\ProgressTabs.jar C:\Program Files\LimeWire\lib\swt.jar C:\Program Files\LimeWire\lib\SystemUtilities.dll C:\Program Files\LimeWire\lib\SystemUtilitiesA.dll C:\Program Files\LimeWire\lib\themes.jar C:\Program Files\LimeWire\lib\tray.dll C:\Program Files\LimeWire\lib\tritonus.jar C:\Program Files\LimeWire\lib\vorbisspi.jar C:\Program Files\LimeWire\LimeWire On Startup.lnk C:\Program Files\LimeWire\LimeWire.exe C:\Program Files\LimeWire\LimeWire.ico C:\Program Files\LimeWire\pmf.ico C:\Program Files\LimeWire\root\magnet10\badge.img C:\Program Files\LimeWire\root\magnet10\canHandle.img C:\Program Files\LimeWire\root\magnet10\limewire.gif C:\Program Files\LimeWire\root\magnet10\options.js C:\Program Files\LimeWire\root\magnet10\silentdetect.js C:\Program Files\LimeWire\SOURCE C:\Program Files\LimeWire\spacer.gif C:\Program Files\LimeWire\uninstall.exe C:\WINDOWS\system32\actskn43.ocx C:\WINDOWS\system32\CAD8306DFB.sys C:\WINDOWS\system32\drivers\pavboot.sys C:\WINDOWS\system32\fbfarypy.dll C:\WINDOWS\system32\nsb139.tmp C:\WINDOWS\system32\nsy138.tmp C:\WINDOWS\system32\quvfuhea.dll C:\WINDOWS\system32\vrjksxav.dll C:\WINDOWS\system32\XceedCry.dll C:\WINDOWS\system32\XceedZip.dll C:\WINDOWS\system32\yrinapqx.dll . ((((((((((((((((((((((((((((((((((((((( Drivers/Services ))))))))))))))))))))))))))))))))))))))))))))))))) . -------\Legacy_PAVBOOT -------\Service_pavboot -------\Legacy_eeCtrl -------\Service_eeCtrl ((((((((((((((((((((((((( Files Created from 2008-06-05 to 2008-07-05 ))))))))))))))))))))))))))))))) . 2008-07-05 12:57 . 2008-07-05 15:22 1,409 --a------ C:\WINDOWS\system32\Postin__.FOT 2008-07-05 00:28 . 2008-07-05 00:29 <DIR> d-------- C:\RecoveryCD 2008-07-04 23:58 . 2008-03-25 02:37 69,632 --a------ C:\WINDOWS\system32\javacpl.cpl 2008-07-04 23:56 . 2008-07-04 23:58 <DIR> d-------- C:\Program Files\Java 2008-07-04 23:56 . 2008-07-04 23:56 <DIR> d-------- C:\Program Files\Common Files\Java 2008-07-04 16:41 . 2008-07-04 16:41 <DIR> d-------- C:\Program Files\Trend Micro 2008-07-04 16:40 . 2008-07-04 16:40 <DIR> d-------- C:\Program Files\Panda Security 2008-07-04 16:35 . 2008-07-04 16:35 <DIR> d-------- C:\Program Files\Malwarebytes' Anti-Malware 2008-07-04 16:35 . 2008-07-04 16:35 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\Malwarebytes 2008-07-04 16:35 . 2008-07-04 16:35 <DIR> d-------- C:\Documents and Settings\AlexDong\Application Data\Malwarebytes 2008-07-04 16:35 . 2008-06-28 14:21 34,296 --a------ C:\WINDOWS\system32\drivers\mbamcatchme.sys 2008-07-04 16:35 . 2008-06-28 14:21 17,144 --a------ C:\WINDOWS\system32\drivers\mbam.sys 2008-07-04 15:34 . 2008-07-04 15:35 <DIR> d-------- C:\Program Files\Spybot - Search & Destroy 2008-06-30 22:13 . 2008-06-30 22:13 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\PC Tools 2008-06-18 13:52 . 2008-06-18 13:52 161,096 --a------ C:\WINDOWS\system32\DivXCodecVersionChecker.exe 2008-06-11 07:18 . 2008-06-13 09:10 272,128 --------- C:\WINDOWS\system32\drivers\bthport.sys 2008-06-11 07:18 . 2008-06-13 09:10 272,128 --------- C:\WINDOWS\system32\dllcache\bthport.sys 2008-06-10 20:07 . 2008-06-10 20:07 4,816 --a------ C:\WINDOWS\system32\divxsm.tlb 2008-06-10 20:04 . 2008-06-10 20:04 1,044,480 --a------ C:\WINDOWS\system32\libdivx.dll 2008-06-10 20:04 . 2008-06-10 20:04 200,704 --a------ C:\WINDOWS\system32\ssldivx.dll . (((((((((((((((((((((((((((((((((((((((( Find3M Report )))))))))))))))))))))))))))))))))))))))))))))))))))) . 2008-07-04 23:21 --------- d-----w C:\Program Files\Warcraft III 2008-07-04 20:30 --------- d-----w C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy 2008-07-04 02:00 --------- d-----w C:\Program Files\Common Files\Real 2008-07-04 01:55 --------- d-----w C:\Program Files\Common Files\Sonic Shared 2008-07-04 01:49 --------- d-----w C:\Program Files\DivX 2008-07-03 14:41 --------- d---a-w C:\Documents and Settings\All Users\Application Data\TEMP 2008-05-22 22:18 12,288 ----a-w C:\WINDOWS\system32\DivXWMPExtType.dll 2008-05-17 03:00 --------- d-----w C:\Program Files\Linksys EasyLink Advisor 2008-05-14 00:47 --------- d-----w C:\Documents and Settings\All Users\Application Data\Microsoft Help 2008-05-08 12:28 202,752 ----a-w C:\WINDOWS\system32\drivers\rmcast.sys 2008-05-08 12:28 202,752 ------w C:\WINDOWS\system32\dllcache\rmcast.sys 2008-05-07 05:18 1,287,680 ----a-w C:\WINDOWS\system32\quartz.dll 2008-05-07 05:18 1,287,680 ------w C:\WINDOWS\system32\dllcache\quartz.dll 2008-04-24 02:16 3,591,680 ----a-w C:\WINDOWS\system32\dllcache\mshtml.dll 2008-04-22 07:40 625,664 ------w C:\WINDOWS\system32\dllcache\iexplore.exe 2008-04-22 07:39 70,656 ------w C:\WINDOWS\system32\dllcache\ie4uinit.exe 2008-04-22 07:39 13,824 ------w C:\WINDOWS\system32\dllcache\ieudinit.exe 2008-04-20 05:07 161,792 ------w C:\WINDOWS\system32\dllcache\ieakui.dll 2007-12-08 23:53 32 ----a-w C:\Documents and Settings\All Users\Application Data\ezsid.dat 2007-01-02 22:38 2,828 --sha-w C:\WINDOWS\system32\KGyGaAvL.sys . ((((((((((((((((((((((((((((( snapshot@2008-07-05_ 1.21.45.37 ))))))))))))))))))))))))))))))))))))))))) . - 2008-07-05 05:16:45 2,048 --s-a-w C:\WINDOWS\bootstat.dat + 2008-07-05 19:19:22 2,048 --s-a-w C:\WINDOWS\bootstat.dat . ((((((((((((((((((((((((((((((((((((( Reg Loading Points )))))))))))))))))))))))))))))))))))))))))))))))))) . . *Note* empty entries & legit default entries are not shown REGEDIT4 [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] "DAEMON Tools"="C:\Program Files\DAEMON Tools\daemon.exe" [2006-11-12 06:48 157592] "Aim6"="C:\Program Files\AIM6\aim6.exe" [2008-01-03 12:15 50528] "ctfmon.exe"="C:\WINDOWS\system32\ctfmon.exe" [2004-08-04 07:00 15360] "EasyLinkAdvisor"="C:\Program Files\Linksys EasyLink Advisor\LinksysAgent.exe" [2007-03-15 18:16 454784] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] "Broadcom Wireless Manager UI"="C:\WINDOWS\system32\WLTRAY.exe" [2006-11-23 02:35 1392640] "SynTPEnh"="C:\Program Files\Synaptics\SynTP\SynTPEnh.exe" [2006-03-08 20:48 761947] "ATICCC"="C:\Program Files\ATI Technologies\ATI.ACE\cli.exe" [2006-01-02 19:41 45056] "ISUSScheduler"="C:\Program Files\Common Files\InstallShield\UpdateService\issch.exe" [2006-03-20 18:34 86960] "googletalk"="C:\Program Files\Google\Google Talk\googletalk.exe" [2007-01-01 17:22 3739648] "IntelliPoint"="C:\Program Files\Microsoft IntelliPoint\ipoint.exe" [2006-11-21 18:09 842584] "GrooveMonitor"="C:\Program Files\Microsoft Office\Office12\GrooveMonitor.exe" [2006-10-27 00:47 31016] "PWRISOVM.EXE"="C:\Program Files\PowerISO\PWRISOVM.EXE" [2007-08-06 20:05 200704] "ShStatEXE"="C:\Program Files\McAfee\VirusScan Enterprise\SHSTAT.EXE" [2006-11-30 09:50 112216] "McAfeeUpdaterUI"="C:\Program Files\McAfee\Common Framework\UdaterUI.exe" [2006-11-17 14:39 136768] "LogitechCommunicationsManager"="C:\Program Files\Common Files\LogiShrd\LComMgr\Communications_Helper.exe" [2007-07-25 17:02 563984] "LogitechQuickCamRibbon"="C:\Program Files\Logitech\QuickCam\Quickcam.exe" [2007-07-25 17:06 2027792] "QuickTime Task"="C:\Program Files\QuickTime\QTTask.exe" [2008-01-10 16:27 385024] "iTunesHelper"="C:\Program Files\iTunes\iTunesHelper.exe" [2008-01-15 04:22 267048] "Adobe Reader Speed Launcher"="C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe" [2008-01-11 23:16 39792] "SunJavaUpdateSched"="C:\Program Files\Java\jre1.6.0_06\bin\jusched.exe" [2008-03-25 04:28 144784] "SigmatelSysTrayApp"="stsystra.exe" [2006-03-25 01:30 282624 C:\WINDOWS\stsystra.exe] "Tweak UI"="TWEAKUI.CPL" [2003-03-25 06:49 106544 C:\WINDOWS\system32\tweakui.cpl] C:\Documents and Settings\AlexDong\Start Menu\Programs\Startup\ OneNote 2007 Screen Clipper and Launcher.lnk - C:\Program Files\Microsoft Office\Office12\ONENOTEM.EXE [2006-10-26 20:24:54 98632] C:\Documents and Settings\All Users\Start Menu\Programs\Startup\ AutoCAD Startup Accelerator.lnk - C:\Program Files\Common Files\Autodesk Shared\acstart16.exe [2006-09-23 09:21:54 10872] Digital Line Detect.lnk - C:\Program Files\Digital Line Detect\DLG.exe [2006-12-26 13:32:26 24576] Post-itr Software Notes.lnk - C:\Program Files\3M\PSNotes\psn.exe [2003-10-10 15:53:20 675840] [HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\drivers32] "msacm.iac2"= C:\PROGRA~1\ACEMEG~1\SystemS\Intel\iac25_32.ax "msacm.sl_anet"= C:\PROGRA~1\ACEMEG~1\SystemS\sl_anet.acm "msacm.msaudio1"= C:\PROGRA~1\ACEMEG~1\SystemS\MICROS~1\msaud32.acm [HKEY_LOCAL_MACHINE\software\microsoft\security center] "AntiVirusDisableNotify"=dword:00000001 [HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring] "DisableMonitoring"=dword:00000001 [HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecAntiVirus] "DisableMonitoring"=dword:00000001 [HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecFirewall] "DisableMonitoring"=dword:00000001 [HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List] "%windir%\\system32\\sessmgr.exe"= "C:\\Program Files\\Google\\Google Talk\\googletalk.exe"= "%windir%\\Network Diagnostic\\xpnetdiag.exe"= "C:\\Program Files\\Common Files\\AOL\\Loader\\aolload.exe"= "C:\\Program Files\\Microsoft Office\\Office12\\OUTLOOK.EXE"= "C:\\Program Files\\Microsoft Office\\Office12\\GROOVE.EXE"= "C:\\Program Files\\Microsoft Office\\Office12\\ONENOTE.EXE"= "C:\\Program Files\\Logitech\\Desktop Messenger\\8876480\\Program\\LogitechDesktopMessenger.exe"= "C:\\Program Files\\McAfee\\Common Framework\\FrameworkService.exe"= "C:\\Program Files\\AIM6\\aim6.exe"= "C:\\Program Files\\Steam\\steamapps\\azndevourer2417@yahoo.com\\counter-strike\\hl.exe"= "C:\\Program Files\\iTunes\\iTunes.exe"= S3 fd_dbus;FutureDial USB Composite Device driver (WDM);C:\WINDOWS\system32\DRIVERS\fd_dbus.sys [2005-01-17 21:46] S3 fd_dmdfl;FutureDial USB Modem Filter;C:\WINDOWS\system32\DRIVERS\fd_dmdfl.sys [2005-01-17 21:46] S3 fd_dmdm;FutureDial USB Modem Drivers;C:\WINDOWS\system32\DRIVERS\fd_dmdm.sys [2005-01-17 21:46] S3 lgatserd;LG CDMA USB Modem Diagnostic Serial Port Drivers (WDM);C:\WINDOWS\system32\DRIVERS\lgatserd.sys [2005-01-17 21:46] [HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{4b2ed31e-c15e-11dc-b62d-0019b94d2f87}] \Shell\AutoRun\command - G:\LaunchU3.exe -a [HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{8e1da9f3-f19c-11db-b5a9-0019b94d2f87}] \Shell\AutoRun\command - G:\USBNB.exe . Contents of the 'Scheduled Tasks' folder "2008-07-03 23:15:04 C:\WINDOWS\Tasks\AppleSoftwareUpdate.job" - C:\Program Files\Apple Software Update\SoftwareUpdate.exe "2008-06-11 09:00:01 C:\WINDOWS\Tasks\SpyHunter Scanner.job" - C:\Program Files\Enigma Software Group\SpyHunter\SpyHunter3.exe . ************************************************************************** catchme 0.3.1361 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net Rootkit scan 2008-07-05 15:20:25 Windows 5.1.2600 Service Pack 2 NTFS scanning hidden processes ... scanning hidden autostart entries ... scanning hidden files ... scan completed successfully hidden files: 0 ************************************************************************** . ------------------------ Other Running Processes ------------------------ . C:\WINDOWS\system32\ati2evxx.exe C:\WINDOWS\system32\WLTRYSVC.EXE C:\WINDOWS\system32\BCMWLTRY.EXE C:\Program Files\Common Files\LogiShrd\LVMVFM\LVPrcSrv.exe C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe C:\Program Files\Common Files\LogiShrd\LVCOMSER\LVComSer.exe C:\Program Files\McAfee\Common Framework\FrameworkService.exe C:\Program Files\McAfee\VirusScan Enterprise\mcshield.exe C:\Program Files\McAfee\VirusScan Enterprise\vstskmgr.exe C:\WINDOWS\system32\ati2evxx.exe C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE C:\Program Files\McAfee\Common Framework\naPrdMgr.exe C:\Program Files\Common Files\LogiShrd\LVCOMSER\LVComSer.exe C:\Program Files\McAfee\Common Framework\Mctray.exe C:\Program Files\3M\PSNotes\PSNGive.exe C:\Program Files\Common Files\AOL\Loader\aolload.exe C:\Program Files\iPod\bin\iPodService.exe C:\WINDOWS\system32\wbem\wmiapsrv.exe C:\Program Files\Common Files\LogiShrd\LQCVFX\COCIManager.exe C:\Program Files\AIM6\aolsoftware.exe . ************************************************************************** . Completion time: 2008-07-05 15:26:05 - machine was rebooted [AlexDong] ComboFix-quarantined-files.txt 2008-07-05 19:26:00 ComboFix2.txt 2008-07-05 05:22:00 Pre-Run: 42,571,423,744 bytes free Post-Run: 42,474,409,984 bytes free 2188 --- E O F --- 2008-06-21 01:04:01
  3. 4 C:\\ijji\ENGLISH\common\images\k6\k6007.gif C:\\ijji\ENGLISH\common\images\k6\k600b.gif C:\\ijji\ENGLISH\common\images\k6\k600c.gif C:\\ijji\ENGLISH\common\images\k6\k600d.gif C:\\ijji\ENGLISH\common\images\k6\k600e.gif C:\\ijji\ENGLISH\common\images\k9\k9001.gif C:\\ijji\ENGLISH\common\images\k9\k9002.gif C:\\ijji\ENGLISH\common\images\k9\k9003.gif C:\\ijji\ENGLISH\common\images\k9\k9004.gif C:\\ijji\ENGLISH\common\images\k9\k9005.gif C:\\ijji\ENGLISH\common\images\k9\k9007.gif C:\\ijji\ENGLISH\common\images\k9\k900b.gif C:\\ijji\ENGLISH\common\images\k9\k900c.gif C:\\ijji\ENGLISH\common\images\k9\k900e.gif C:\\ijji\ENGLISH\common\images\k9\k900g.gif C:\\ijji\ENGLISH\common\images\k9\k900i.gif C:\\ijji\ENGLISH\common\images\k9\k900j.gif C:\\ijji\ENGLISH\common\images\k9\k900k.gif C:\\ijji\ENGLISH\common\images\k9\k900m.gif C:\\ijji\ENGLISH\common\images\k9\k900n.gif C:\\ijji\ENGLISH\common\images\LastGame.hgs C:\\ijji\ENGLISH\common\images\LastGame.him C:\\ijji\ENGLISH\common\images\mkcount.him C:\\ijji\ENGLISH\common\images\mkdraw.him C:\\ijji\ENGLISH\common\images\mkendcount.him C:\\ijji\ENGLISH\common\images\mkundo.him C:\\ijji\ENGLISH\common\images\newhgb2005.ico C:\\ijji\ENGLISH\common\images\newhgc2005.ico C:\\ijji\ENGLISH\common\images\popup_background.him C:\\ijji\ENGLISH\common\images\popup_background_b.him C:\\ijji\ENGLISH\common\images\seedmoneyoption.him C:\\ijji\ENGLISH\common\images\table\StreakCount_01.him C:\\ijji\ENGLISH\common\images\table\StreakCount_02.him C:\\ijji\ENGLISH\common\images\table\StreakCount_03.him C:\\ijji\ENGLISH\common\images\table\StreakCount_04.him C:\\ijji\ENGLISH\common\images\table\StreakCount_05.him C:\\ijji\ENGLISH\common\images\table\StreakCount_06.him C:\\ijji\ENGLISH\common\images\table\StreakCount_07.him C:\\ijji\ENGLISH\common\images\table\StreakCount_08.him C:\\ijji\ENGLISH\common\images\table\StreakCount_09.him C:\\ijji\ENGLISH\common\images\table\StreakCount_10.him C:\\ijji\ENGLISH\common\images\table\StreakCount_11.him C:\\ijji\ENGLISH\common\images\table\StreakCount_12.him C:\\ijji\ENGLISH\common\images\table\StreakCount_13.him C:\\ijji\ENGLISH\common\images\table\StreakCount_14.him C:\\ijji\ENGLISH\common\images\table\StreakCount_15.him C:\\ijji\ENGLISH\common\images\table\StreakCount_16.him C:\\ijji\ENGLISH\common\images\table\StreakCount_17.him C:\\ijji\ENGLISH\common\images\table\StreakCount_18.him C:\\ijji\ENGLISH\common\images\table\StreakCount_19.him C:\\ijji\ENGLISH\common\images\table\StreakCount_20.him C:\\ijji\ENGLISH\common\images\table\StreakCount_21.him C:\\ijji\ENGLISH\common\images\table\StreakCount_22.him C:\\ijji\ENGLISH\common\images\table\StreakCount_23.him C:\\ijji\ENGLISH\common\images\table\StreakCount_24.him C:\\ijji\ENGLISH\common\images\table\StreakCount_25.him C:\\ijji\ENGLISH\common\images\table\StreakCount_26.him C:\\ijji\ENGLISH\common\images\table\StreakCount_27.him C:\\ijji\ENGLISH\common\images\table\StreakCount_28.him C:\\ijji\ENGLISH\common\images\table\StreakCount_29.him C:\\ijji\ENGLISH\common\images\table\StreakCount_30.him C:\\ijji\ENGLISH\common\images\table\StreakCount_31.him C:\\ijji\ENGLISH\common\images\table\StreakCount_32.him C:\\ijji\ENGLISH\common\images\table\StreakCount_33.him C:\\ijji\ENGLISH\common\images\table\StreakCount_34.him C:\\ijji\ENGLISH\common\images\table\StreakCount_35.him C:\\ijji\ENGLISH\common\images\table\StreakCount_36.him C:\\ijji\ENGLISH\common\images\table\StreakCount_37.him C:\\ijji\ENGLISH\common\images\table\StreakCount_38.him C:\\ijji\ENGLISH\common\images\table\StreakCount_39.him C:\\ijji\ENGLISH\common\images\table\StreakCount_40.him C:\\ijji\ENGLISH\common\images\table\StreakCount_41.him C:\\ijji\ENGLISH\common\images\table\StreakCount_42.him C:\\ijji\ENGLISH\common\images\table\StreakCount_43.him C:\\ijji\ENGLISH\common\images\table\StreakCount_44.him C:\\ijji\ENGLISH\common\images\table\StreakCount_45.him C:\\ijji\ENGLISH\common\images\table\StreakCount_46.him C:\\ijji\ENGLISH\common\images\table\StreakCount_47.him C:\\ijji\ENGLISH\common\images\table\StreakCount_48.him C:\\ijji\ENGLISH\common\images\table\StreakCount_49.him C:\\ijji\ENGLISH\common\images\table\StreakCount_50.him C:\\ijji\ENGLISH\common\images\table\StreakCount_51.him C:\\ijji\ENGLISH\common\images\table\StreakCount_52.him C:\\ijji\ENGLISH\common\images\table\StreakCount_53.him C:\\ijji\ENGLISH\common\images\table\StreakCount_54.him C:\\ijji\ENGLISH\common\images\table\StreakCount_55.him C:\\ijji\ENGLISH\common\images\table\StreakCount_56.him C:\\ijji\ENGLISH\common\images\table\StreakCount_57.him C:\\ijji\ENGLISH\common\images\table\StreakCount_58.him C:\\ijji\ENGLISH\common\images\table\StreakCount_59.him C:\\ijji\ENGLISH\common\images\table\StreakCount_60.him C:\\ijji\ENGLISH\common\images\table\StreakCount_61.him C:\\ijji\ENGLISH\common\images\table\StreakCount_62.him C:\\ijji\ENGLISH\common\images\table\StreakCount_63.him C:\\ijji\ENGLISH\common\images\table\StreakCount_64.him C:\\ijji\ENGLISH\common\images\table\StreakCount_65.him C:\\ijji\ENGLISH\common\images\table\StreakCount_66.him C:\\ijji\ENGLISH\common\images\table\StreakCount_67.him C:\\ijji\ENGLISH\common\images\table\StreakCount_68.him C:\\ijji\ENGLISH\common\images\table\StreakCount_69.him C:\\ijji\ENGLISH\common\images\table\StreakCount_70.him C:\\ijji\ENGLISH\common\images\table\StreakCount_71.him C:\\ijji\ENGLISH\common\images\table\StreakCount_72.him C:\\ijji\ENGLISH\common\images\table\StreakCount_73.him C:\\ijji\ENGLISH\common\images\table\StreakCount_74.him C:\\ijji\ENGLISH\common\images\table\StreakCount_75.him C:\\ijji\ENGLISH\common\images\table\StreakCount_76.him C:\\ijji\ENGLISH\common\images\table\StreakCount_77.him C:\\ijji\ENGLISH\common\images\table\StreakCount_78.him C:\\ijji\ENGLISH\common\images\table\StreakCount_79.him C:\\ijji\ENGLISH\common\images\table\StreakCount_80.him C:\\ijji\ENGLISH\common\images\table\StreakCount_81.him C:\\ijji\ENGLISH\common\images\table\StreakCount_82.him C:\\ijji\ENGLISH\common\images\table\StreakCount_83.him C:\\ijji\ENGLISH\common\images\table\StreakCount_84.him C:\\ijji\ENGLISH\common\images\table\StreakCount_85.him C:\\ijji\ENGLISH\common\images\table\StreakCount_86.him C:\\ijji\ENGLISH\common\images\table\StreakCount_87.him C:\\ijji\ENGLISH\common\images\table\StreakCount_88.him C:\\ijji\ENGLISH\common\images\table\StreakCount_89.him C:\\ijji\ENGLISH\common\images\table\StreakCount_90.him C:\\ijji\ENGLISH\common\images\table\StreakCount_91.him C:\\ijji\ENGLISH\common\images\table\StreakCount_92.him C:\\ijji\ENGLISH\common\images\table\StreakCount_93.him C:\\ijji\ENGLISH\common\images\table\StreakCount_94.him C:\\ijji\ENGLISH\common\images\table\StreakCount_95.him C:\\ijji\ENGLISH\common\images\table\StreakCount_96.him C:\\ijji\ENGLISH\common\images\table\StreakCount_97.him C:\\ijji\ENGLISH\common\images\table\StreakCount_98.him C:\\ijji\ENGLISH\common\images\table\StreakCount_99.him C:\\ijji\ENGLISH\common\images\Table_back.him C:\\ijji\ENGLISH\common\images\Table_bg.him C:\\ijji\ENGLISH\common\images\Table_btn_TeamGreen.him C:\\ijji\ENGLISH\common\images\Table_btn_TeamYellow.him C:\\ijji\ENGLISH\common\images\Table_btnChatSend.him C:\\ijji\ENGLISH\common\images\Table_btnexit.him C:\\ijji\ENGLISH\common\images\Table_btninvite.him C:\\ijji\ENGLISH\common\images\Table_btnpractice.him C:\\ijji\ENGLISH\common\images\Table_btnReady.him C:\\ijji\ENGLISH\common\images\Table_btnstart.hgs C:\\ijji\ENGLISH\common\images\Table_btnstart.him C:\\ijji\ENGLISH\common\images\Table_btnstartcancel.him C:\\ijji\ENGLISH\common\images\Table_CharacterClear.hgs C:\\ijji\ENGLISH\common\images\Table_ChatBalloon.him C:\\ijji\ENGLISH\common\images\Table_Gemble_arrow.him C:\\ijji\ENGLISH\common\images\Table_Gemble_back.him C:\\ijji\ENGLISH\common\images\Table_Individual_host.him C:\\ijji\ENGLISH\common\images\Table_Individual_MyBack.him C:\\ijji\ENGLISH\common\images\Table_Individual_playerback.him C:\\ijji\ENGLISH\common\images\Table_Individual_Title.him C:\\ijji\ENGLISH\common\images\Table_JackpotNumber.him C:\\ijji\ENGLISH\common\images\Table_JackpotWinner_my.him C:\\ijji\ENGLISH\common\images\Table_JackpotWinner_peer.him C:\\ijji\ENGLISH\common\images\Table_LevelUp.him C:\\ijji\ENGLISH\common\images\Table_MyAvtrBack.him C:\\ijji\ENGLISH\common\images\Table_PlayerInfoBack.him C:\\ijji\ENGLISH\common\images\Table_playerNumber.him C:\\ijji\ENGLISH\common\images\Table_Ready.him C:\\ijji\ENGLISH\common\images\Table_RoomInfo_back.him C:\\ijji\ENGLISH\common\images\Table_RoomNumber_back.him C:\\ijji\ENGLISH\common\images\Table_Streak_Back.him C:\\ijji\ENGLISH\common\images\Table_tbtnMax.him C:\\ijji\ENGLISH\common\images\Table_tbtnRestore.him C:\\ijji\ENGLISH\common\images\Table_Team_backgreen.him C:\\ijji\ENGLISH\common\images\Table_Team_backyellow.him C:\\ijji\ENGLISH\common\images\Table_Team_host.him C:\\ijji\ENGLISH\common\images\Table_Team_MyBack.him C:\\ijji\ENGLISH\common\images\Table_Team_playerback.him C:\\ijji\ENGLISH\common\images\Table_Team_RoomInfo_back.him C:\\ijji\ENGLISH\common\images\Table_Team_RoomNumber_back.him C:\\ijji\ENGLISH\common\images\Table_Team_Title.him C:\\ijji\ENGLISH\common\images\Table_Team_vs.him C:\\ijji\ENGLISH\common\images\Table_TeamPlayerInfoBack.him C:\\ijji\ENGLISH\common\images\Table_Winner.him C:\\ijji\ENGLISH\common\images\TableScrollBar.him C:\\ijji\ENGLISH\common\images\TableScrollDn.him C:\\ijji\ENGLISH\common\images\TableScrollUp.him C:\\ijji\ENGLISH\common\images\wf\wfa0061.gif C:\\ijji\ENGLISH\common\images\wf\wfa0062.gif C:\\ijji\ENGLISH\common\images\wf\wfa00f1.gif C:\\ijji\ENGLISH\common\images\wf\wfa00f2.gif C:\\ijji\ENGLISH\common\images\wf\wfa01f1.gif C:\\ijji\ENGLISH\common\images\wf\wfa01f2.gif C:\\ijji\ENGLISH\common\images\wf\wfa01h1.gif C:\\ijji\ENGLISH\common\images\wf\wfa01h2.gif C:\\ijji\ENGLISH\common\images\wf\wfa0251.gif C:\\ijji\ENGLISH\common\images\wf\wfa0252.gif C:\\ijji\ENGLISH\common\images\wf\wfa0291.gif C:\\ijji\ENGLISH\common\images\wf\wfa0292.gif C:\\ijji\ENGLISH\common\images\wf\wfa02w1.gif C:\\ijji\ENGLISH\common\images\wf\wfa02w2.gif C:\\ijji\ENGLISH\common\images\wf\wfa0341.gif C:\\ijji\ENGLISH\common\images\wf\wfa0342.gif C:\\ijji\ENGLISH\common\images\wf\wfa03o1.gif C:\\ijji\ENGLISH\common\images\wf\wfa03o2.gif C:\\ijji\ENGLISH\common\images\wf\wfb00e1.gif C:\\ijji\ENGLISH\common\images\wf\wfb00e2.gif C:\\ijji\ENGLISH\common\images\wf\wfb00f1.gif C:\\ijji\ENGLISH\common\images\wf\wfb00f2.gif C:\\ijji\ENGLISH\common\images\wf\wfb00q1.gif C:\\ijji\ENGLISH\common\images\wf\wfb00q2.gif C:\\ijji\ENGLISH\common\images\wf\wfb01i1.gif C:\\ijji\ENGLISH\common\images\wf\wfb01i2.gif C:\\ijji\ENGLISH\common\images\wf\wfb01l1.gif C:\\ijji\ENGLISH\common\images\wf\wfb01l2.gif C:\\ijji\ENGLISH\common\images\wf\wfb01v1.gif C:\\ijji\ENGLISH\common\images\wf\wfb01v2.gif C:\\ijji\ENGLISH\common\images\wf\wfb01z1.gif C:\\ijji\ENGLISH\common\images\wf\wfb01z2.gif C:\\ijji\ENGLISH\common\images\wf\wfb0221.gif C:\\ijji\ENGLISH\common\images\wf\wfb0222.gif C:\\ijji\ENGLISH\common\images\wf\wfb0241.gif C:\\ijji\ENGLISH\common\images\wf\wfb0341.gif C:\\ijji\ENGLISH\common\images\wf\wfb0342.gif C:\\ijji\ENGLISH\common\images\wf\wfc0061.gif C:\\ijji\ENGLISH\common\images\wf\wfc0062.gif C:\\ijji\ENGLISH\common\images\wf\wfc00q1.gif C:\\ijji\ENGLISH\common\images\wf\wfc00q2.gif C:\\ijji\ENGLISH\common\images\wf\wfc0191.gif C:\\ijji\ENGLISH\common\images\wf\wfc0192.gif C:\\ijji\ENGLISH\common\images\wf\wfc01d1.gif C:\\ijji\ENGLISH\common\images\wf\wfc01d2.gif C:\\ijji\ENGLISH\common\images\wf\wfc01f1.gif C:\\ijji\ENGLISH\common\images\wf\wfc01f2.gif C:\\ijji\ENGLISH\common\images\wf\wfc0281.gif C:\\ijji\ENGLISH\common\images\wf\wfc0282.gif C:\\ijji\ENGLISH\common\images\wf\wfd01l1.gif C:\\ijji\ENGLISH\common\images\wf\wfd01l2.gif C:\\ijji\ENGLISH\common\images\wf\wfd01q1.gif C:\\ijji\ENGLISH\common\images\wf\wfd01q2.gif C:\\ijji\ENGLISH\common\images\wf\wfd0201.gif C:\\ijji\ENGLISH\common\images\wf\wfd0202.gif C:\\ijji\ENGLISH\common\images\wm\wma0131.gif C:\\ijji\ENGLISH\common\images\wm\wma0132.gif C:\\ijji\ENGLISH\common\images\wm\wma01e1.gif C:\\ijji\ENGLISH\common\images\wm\wma01e2.gif C:\\ijji\ENGLISH\common\images\wm\wma01g1.gif C:\\ijji\ENGLISH\common\images\wm\wma01g2.gif C:\\ijji\ENGLISH\common\images\wm\wma01i1.gif C:\\ijji\ENGLISH\common\images\wm\wma01i2.gif C:\\ijji\ENGLISH\common\images\wm\wma01k1.gif C:\\ijji\ENGLISH\common\images\wm\wma01k2.gif C:\\ijji\ENGLISH\common\images\wm\wma01l1.gif C:\\ijji\ENGLISH\common\images\wm\wma01l2.gif C:\\ijji\ENGLISH\common\images\wm\wma01y1.gif C:\\ijji\ENGLISH\common\images\wm\wma01y2.gif C:\\ijji\ENGLISH\common\images\wm\wma02b1.gif C:\\ijji\ENGLISH\common\images\wm\wma02b2.gif C:\\ijji\ENGLISH\common\images\wm\wma02j1.gif C:\\ijji\ENGLISH\common\images\wm\wma02j2.gif C:\\ijji\ENGLISH\common\images\wm\wma02u1.gif C:\\ijji\ENGLISH\common\images\wm\wma02u2.gif C:\\ijji\ENGLISH\common\images\wm\wma0321.gif C:\\ijji\ENGLISH\common\images\wm\wma0322.gif C:\\ijji\ENGLISH\common\images\wm\wma0361.gif C:\\ijji\ENGLISH\common\images\wm\wma0362.gif C:\\ijji\ENGLISH\common\images\wm\wma0371.gif C:\\ijji\ENGLISH\common\images\wm\wma0372.gif C:\\ijji\ENGLISH\common\images\wm\wma0391.gif C:\\ijji\ENGLISH\common\images\wm\wma0392.gif C:\\ijji\ENGLISH\common\images\wm\wmb0071.gif C:\\ijji\ENGLISH\common\images\wm\wmb0072.gif C:\\ijji\ENGLISH\common\images\wm\wmb00j1.gif C:\\ijji\ENGLISH\common\images\wm\wmb00j2.gif C:\\ijji\ENGLISH\common\images\wm\wmb00x1.gif C:\\ijji\ENGLISH\common\images\wm\wmb00x2.gif C:\\ijji\ENGLISH\common\images\wm\wmb0101.gif C:\\ijji\ENGLISH\common\images\wm\wmb0102.gif C:\\ijji\ENGLISH\common\images\wm\wmb0111.gif C:\\ijji\ENGLISH\common\images\wm\wmb0112.gif C:\\ijji\ENGLISH\common\images\wm\wmb0121.gif C:\\ijji\ENGLISH\common\images\wm\wmb0122.gif C:\\ijji\ENGLISH\common\images\wm\wmb01b1.gif C:\\ijji\ENGLISH\common\images\wm\wmb01b2.gif C:\\ijji\ENGLISH\common\images\wm\wmb01g1.gif C:\\ijji\ENGLISH\common\images\wm\wmb01g2.gif C:\\ijji\ENGLISH\common\images\wm\wmb01j1.gif C:\\ijji\ENGLISH\common\images\wm\wmb01j2.gif C:\\ijji\ENGLISH\common\images\wm\wmb01l1.gif C:\\ijji\ENGLISH\common\images\wm\wmb01l2.gif C:\\ijji\ENGLISH\common\images\wm\wmb01m1.gif C:\\ijji\ENGLISH\common\images\wm\wmb01m2.gif C:\\ijji\ENGLISH\common\images\wm\wmb01r1.gif C:\\ijji\ENGLISH\common\images\wm\wmb01r2.gif C:\\ijji\ENGLISH\common\images\wm\wmb01v1.gif C:\\ijji\ENGLISH\common\images\wm\wmb01v2.gif C:\\ijji\ENGLISH\common\images\wm\wmb0231.gif C:\\ijji\ENGLISH\common\images\wm\wmb0232.gif C:\\ijji\ENGLISH\common\images\wm\wmb0261.gif C:\\ijji\ENGLISH\common\images\wm\wmb0262.gif C:\\ijji\ENGLISH\common\images\wm\wmb0271.gif C:\\ijji\ENGLISH\common\images\wm\wmb0272.gif C:\\ijji\ENGLISH\common\images\wm\wmb02a1.gif C:\\ijji\ENGLISH\common\images\wm\wmb02a2.gif C:\\ijji\ENGLISH\common\images\wm\wmb02i1.gif C:\\ijji\ENGLISH\common\images\wm\wmb02i2.gif C:\\ijji\ENGLISH\common\images\wm\wmb02z1.gif C:\\ijji\ENGLISH\common\images\wm\wmb02z2.gif C:\\ijji\ENGLISH\common\images\wm\wmb0321.gif C:\\ijji\ENGLISH\common\images\wm\wmb0322.gif C:\\ijji\ENGLISH\common\images\wm\wmb0361.gif C:\\ijji\ENGLISH\common\images\wm\wmb0362.gif C:\\ijji\ENGLISH\common\images\wm\wmc0071.gif C:\\ijji\ENGLISH\common\images\wm\wmc0072.gif C:\\ijji\ENGLISH\common\images\wm\wmc00h1.gif C:\\ijji\ENGLISH\common\images\wm\wmc00h2.gif C:\\ijji\ENGLISH\common\images\wm\wmc00s1.gif C:\\ijji\ENGLISH\common\images\wm\wmc00s2.gif C:\\ijji\ENGLISH\common\images\wm\wmc0101.gif C:\\ijji\ENGLISH\common\images\wm\wmc0102.gif C:\\ijji\ENGLISH\common\images\wm\wmc0161.gif C:\\ijji\ENGLISH\common\images\wm\wmc01d1.gif C:\\ijji\ENGLISH\common\images\wm\wmc01d2.gif C:\\ijji\ENGLISH\common\images\wm\wmc01e1.gif C:\\ijji\ENGLISH\common\images\wm\wmc01e2.gif C:\\ijji\ENGLISH\common\images\wm\wmc01m1.gif C:\\ijji\ENGLISH\common\images\wm\wmc01m2.gif C:\\ijji\ENGLISH\common\images\wm\wmc01v1.gif C:\\ijji\ENGLISH\common\images\wm\wmc01v2.gif C:\\ijji\ENGLISH\common\images\wm\wmc0201.gif C:\\ijji\ENGLISH\common\images\wm\wmc0202.gif C:\\ijji\ENGLISH\common\images\wm\wmc02g1.gif C:\\ijji\ENGLISH\common\images\wm\wmc02g2.gif C:\\ijji\ENGLISH\common\images\wm\wmc02h1.gif C:\\ijji\ENGLISH\common\images\wm\wmc02h2.gif C:\\ijji\ENGLISH\common\images\wm\wmc02y1.gif C:\\ijji\ENGLISH\common\images\wm\wmc02y2.gif C:\\ijji\ENGLISH\common\images\wm\wmc0361.gif C:\\ijji\ENGLISH\common\images\wm\wmc0362.gif C:\\ijji\ENGLISH\common\images\wm\wmc0391.gif C:\\ijji\ENGLISH\common\images\wm\wmc0392.gif C:\\ijji\ENGLISH\common\images\wm\wmd0051.gif C:\\ijji\ENGLISH\common\images\wm\wmd0052.gif C:\\ijji\ENGLISH\common\images\wm\wmd0111.gif C:\\ijji\ENGLISH\common\images\wm\wmd0112.gif C:\\ijji\ENGLISH\common\images\wm\wmd0121.gif C:\\ijji\ENGLISH\common\images\wm\wmd0122.gif C:\\ijji\ENGLISH\common\images\wm\wmd0161.gif C:\\ijji\ENGLISH\common\images\wm\wmd0162.gif C:\\ijji\ENGLISH\common\images\wm\wmd01e1.gif C:\\ijji\ENGLISH\common\images\wm\wmd01e2.gif C:\\ijji\ENGLISH\common\images\wm\wmd01j1.gif C:\\ijji\ENGLISH\common\images\wm\wmd01j2.gif C:\\ijji\ENGLISH\common\images\wm\wmd01m1.gif C:\\ijji\ENGLISH\common\images\wm\wmd01m2.gif C:\\ijji\ENGLISH\common\images\wm\wmd01z1.gif C:\\ijji\ENGLISH\common\images\wm\wmd01z2.gif C:\\ijji\ENGLISH\common\images\wm\wmd0241.gif C:\\ijji\ENGLISH\common\images\wm\wmd0242.gif C:\\ijji\ENGLISH\common\images\wm\wmd02g1.gif C:\\ijji\ENGLISH\common\images\wm\wmd02g2.gif C:\\ijji\ENGLISH\common\sounds\base_jiksaw_n.hso C:\\ijji\ENGLISH\common\sounds\base_jiksaw_s.hso C:\\ijji\ENGLISH\common\sounds\prv0f.hso C:\\ijji\ENGLISH\common\sounds\prv0m.hso C:\\ijji\ENGLISH\common\sounds\prv1f.hso C:\\ijji\ENGLISH\common\sounds\prv1m.hso C:\\ijji\ENGLISH\common\sounds\prv2f.hso C:\\ijji\ENGLISH\common\sounds\prv2m.hso C:\\ijji\ENGLISH\common\sounds\prv3f.hso C:\\ijji\ENGLISH\common\sounds\prv3m.hso C:\\ijji\ENGLISH\common\sounds\prv4f.hso C:\\ijji\ENGLISH\common\sounds\prv4m.hso C:\\ijji\ENGLISH\common\sounds\prv5f.hso C:\\ijji\ENGLISH\common\sounds\prv5m.hso C:\\ijji\ENGLISH\common\sounds\prv6f.hso C:\\ijji\ENGLISH\common\sounds\prv6m.hso C:\\ijji\ENGLISH\common\sounds\prv7f.hso C:\\ijji\ENGLISH\common\sounds\prv7m.hso C:\\ijji\ENGLISH\dbghelp.dll C:\\ijji\ENGLISH\DFEngine.dll C:\\ijji\ENGLISH\dsound.dll C:\\ijji\ENGLISH\fmod.dll C:\\ijji\ENGLISH\GameGuard.des C:\\ijji\ENGLISH\GdiPlus.dll C:\\ijji\ENGLISH\Gunbound Revolution\GameGuard\GameGuard.des C:\\ijji\ENGLISH\Gunbound Revolution\GameGuard\GameGuard.ver C:\\ijji\ENGLISH\Gunbound Revolution\GameGuard\GameMon.des C:\\ijji\ENGLISH\Gunbound Revolution\GameGuard\ggscan.des C:\\ijji\ENGLISH\Gunbound Revolution\GameGuard\GunBoundUS.ini C:\\ijji\ENGLISH\Gunbound Revolution\GameGuard\npgg.erl C:\\ijji\ENGLISH\Gunbound Revolution\GameGuard\npgg9x.des C:\\ijji\ENGLISH\Gunbound Revolution\GameGuard\npggNT.des C:\\ijji\ENGLISH\Gunbound Revolution\GameGuard\npgl.erl C:\\ijji\ENGLISH\Gunbound Revolution\GameGuard\npgm.erl C:\\ijji\ENGLISH\Gunbound Revolution\GameGuard\npgmup.des C:\\ijji\ENGLISH\Gunbound Revolution\GameGuard\npgmup.des.new C:\\ijji\ENGLISH\Gunbound Revolution\GameGuard\npgmup.erl C:\\ijji\ENGLISH\Gunbound Revolution\GameGuard\npsc.des C:\\ijji\ENGLISH\Gunbound Revolution\GameGuard\npsc.erl C:\\ijji\ENGLISH\Gunbound Revolution\GameGuard\NPSCAN.DES C:\\ijji\ENGLISH\Gunbound Revolution\Gunbound.erl C:\\ijji\ENGLISH\Gunbound Revolution\GunBound.log C:\\ijji\ENGLISH\Gunbound Revolution\GunBound0000001.bmp C:\\ijji\ENGLISH\Gunbound Revolution\GunBound0000002.bmp C:\\ijji\ENGLISH\Gunbound Revolution\GunBound0000003.bmp C:\\ijji\ENGLISH\Gunbound Revolution\GunBound0000004.bmp C:\\ijji\ENGLISH\Gunbound Revolution\GunBound0000005.bmp C:\\ijji\ENGLISH\Gunbound Revolution\GunBound0000006.bmp C:\\ijji\ENGLISH\Gunbound Revolution\GunBound0000007.bmp C:\\ijji\ENGLISH\Gunbound Revolution\GunBound0000008.bmp C:\\ijji\ENGLISH\Gunbound Revolution\GunBound0000009.bmp C:\\ijji\ENGLISH\Gunbound Revolution\GunBound0000010.bmp C:\\ijji\ENGLISH\Gunbound Revolution\GunBound0000011.bmp C:\\ijji\ENGLISH\Gunbound Revolution\GunBound0000012.bmp C:\\ijji\ENGLISH\Gunbound Revolution\GunBound0000013.bmp C:\\ijji\ENGLISH\Gunbound Revolution\GunBound0000014.bmp C:\\ijji\ENGLISH\Gunbound Revolution\GunBound0000015.bmp C:\\ijji\ENGLISH\Gunbound Revolution\GunBound0000016.bmp C:\\ijji\ENGLISH\Gunbound Revolution\GunBound0000017.bmp C:\\ijji\ENGLISH\Gunbound Revolution\GunBound0000018.bmp C:\\ijji\ENGLISH\Gunbound Revolution\GunBound0000019.bmp C:\\ijji\ENGLISH\Gunbound Revolution\GunBound0000020.bmp C:\\ijji\ENGLISH\Gunbound Revolution\GunBound0000021.bmp C:\\ijji\ENGLISH\Gunbound Revolution\GunBound0000022.bmp C:\\ijji\ENGLISH\Gunbound Revolution\GunBound0000023.bmp C:\\ijji\ENGLISH\Gunbound Revolution\GunBound0000024.bmp C:\\ijji\ENGLISH\Gunbound Revolution\GunBound0000025.bmp C:\\ijji\ENGLISH\Gunbound Revolution\GunBound0000026.bmp C:\\ijji\ENGLISH\Gunbound Revolution\GunBound0000027.bmp C:\\ijji\ENGLISH\Gunbound Revolution\GunBound0000028.bmp C:\\ijji\ENGLISH\Gunbound Revolution\GunBound0000029.bmp C:\\ijji\ENGLISH\Gunbound Revolution\GunBound0000030.bmp C:\\ijji\ENGLISH\Gunbound Revolution\GunBound0000031.bmp C:\\ijji\ENGLISH\Gunbound Revolution\HanAuthForClient.dll C:\\ijji\ENGLISH\Gunbound Revolution\HanPollForClient.dll C:\\ijji\ENGLISH\Gunbound Revolution\Img\Thumbs.db C:\\ijji\ENGLISH\Gunbound Revolution\msvcr71.dll C:\\ijji\ENGLISH\Gunbound Revolution\NyxLauncher.exe C:\\ijji\ENGLISH\HanAuthForClient.dll C:\\ijji\ENGLISH\HanReportForClient.dll C:\\ijji\ENGLISH\HanUninstall.ini C:\\ijji\ENGLISH\HgAniGm3.dll C:\\ijji\ENGLISH\HgAniGm3_16Bit.dll C:\\ijji\ENGLISH\HgAvatar2006.dll C:\\ijji\ENGLISH\HgAvtr3.dll C:\\ijji\ENGLISH\HgBoard3.dll C:\\ijji\ENGLISH\HgClientConfig.xml C:\\ijji\ENGLISH\HgCom3.dll C:\\ijji\ENGLISH\HgCtr3.dll C:\\ijji\ENGLISH\HgDlg3.dll C:\\ijji\ENGLISH\HgDoubleFusion.dll C:\\ijji\ENGLISH\HgEng3.dll C:\\ijji\ENGLISH\HgFrm3.dll C:\\ijji\ENGLISH\HgModel3.dll C:\\ijji\ENGLISH\HgSC.dll C:\\ijji\ENGLISH\HgSock3.dll
  4. 3 C:\\ijji\ENGLISH\common\images\f2\f2b00v.gif C:\\ijji\ENGLISH\common\images\f2\f2b00y.gif C:\\ijji\ENGLISH\common\images\f2\f2b013.gif C:\\ijji\ENGLISH\common\images\f2\f2b01b.gif C:\\ijji\ENGLISH\common\images\f2\f2b01c.gif C:\\ijji\ENGLISH\common\images\f2\f2b01d.gif C:\\ijji\ENGLISH\common\images\f2\f2b01f.gif C:\\ijji\ENGLISH\common\images\f2\f2b01g.gif C:\\ijji\ENGLISH\common\images\f2\f2c001.gif C:\\ijji\ENGLISH\common\images\f2\f2c002.gif C:\\ijji\ENGLISH\common\images\f2\f2c005.gif C:\\ijji\ENGLISH\common\images\f2\f2c00b.gif C:\\ijji\ENGLISH\common\images\f2\f2c00d.gif C:\\ijji\ENGLISH\common\images\f2\f2c00j.gif C:\\ijji\ENGLISH\common\images\f2\f2c00k.gif C:\\ijji\ENGLISH\common\images\f2\f2c00l.gif C:\\ijji\ENGLISH\common\images\f2\f2c00r.gif C:\\ijji\ENGLISH\common\images\f2\f2c00t.gif C:\\ijji\ENGLISH\common\images\f2\f2c00v.gif C:\\ijji\ENGLISH\common\images\f2\f2c00y.gif C:\\ijji\ENGLISH\common\images\f2\f2c011.gif C:\\ijji\ENGLISH\common\images\f2\f2c014.gif C:\\ijji\ENGLISH\common\images\f2\f2c01b.gif C:\\ijji\ENGLISH\common\images\f2\f2c01c.gif C:\\ijji\ENGLISH\common\images\f2\f2c01d.gif C:\\ijji\ENGLISH\common\images\f2\f2d007.gif C:\\ijji\ENGLISH\common\images\f2\f2d00b.gif C:\\ijji\ENGLISH\common\images\f2\f2d00g.gif C:\\ijji\ENGLISH\common\images\f2\f2d00h.gif C:\\ijji\ENGLISH\common\images\f2\f2d00l.gif C:\\ijji\ENGLISH\common\images\f2\f2d00v.gif C:\\ijji\ENGLISH\common\images\f2\f2d01b.gif C:\\ijji\ENGLISH\common\images\f2\f2d01c.gif C:\\ijji\ENGLISH\common\images\f2\f2d01f.gif C:\\ijji\ENGLISH\common\images\f2\f2d01g.gif C:\\ijji\ENGLISH\common\images\f3\f3a009.gif C:\\ijji\ENGLISH\common\images\f3\f3a00f.gif C:\\ijji\ENGLISH\common\images\f3\f3a00g.gif C:\\ijji\ENGLISH\common\images\f3\f3a00h.gif C:\\ijji\ENGLISH\common\images\f3\f3a00q.gif C:\\ijji\ENGLISH\common\images\f3\f3a00r.gif C:\\ijji\ENGLISH\common\images\f3\f3a011.gif C:\\ijji\ENGLISH\common\images\f3\f3a013.gif C:\\ijji\ENGLISH\common\images\f3\f3a01f.gif C:\\ijji\ENGLISH\common\images\f3\f3a01t.gif C:\\ijji\ENGLISH\common\images\f3\f3a02a.gif C:\\ijji\ENGLISH\common\images\f3\f3a02b.gif C:\\ijji\ENGLISH\common\images\f3\f3a02j.gif C:\\ijji\ENGLISH\common\images\f3\f3a02m.gif C:\\ijji\ENGLISH\common\images\f3\f3a02w.gif C:\\ijji\ENGLISH\common\images\f3\f3a03j.gif C:\\ijji\ENGLISH\common\images\f3\f3b009.gif C:\\ijji\ENGLISH\common\images\f3\f3b00f.gif C:\\ijji\ENGLISH\common\images\f3\f3b00g.gif C:\\ijji\ENGLISH\common\images\f3\f3b00h.gif C:\\ijji\ENGLISH\common\images\f3\f3b00p.gif C:\\ijji\ENGLISH\common\images\f3\f3b00r.gif C:\\ijji\ENGLISH\common\images\f3\f3b00u.gif C:\\ijji\ENGLISH\common\images\f3\f3b00z.gif C:\\ijji\ENGLISH\common\images\f3\f3b013.gif C:\\ijji\ENGLISH\common\images\f3\f3b01f.gif C:\\ijji\ENGLISH\common\images\f3\f3b01t.gif C:\\ijji\ENGLISH\common\images\f3\f3b01x.gif C:\\ijji\ENGLISH\common\images\f3\f3b020.gif C:\\ijji\ENGLISH\common\images\f3\f3b025.gif C:\\ijji\ENGLISH\common\images\f3\f3b026.gif C:\\ijji\ENGLISH\common\images\f3\f3b02b.gif C:\\ijji\ENGLISH\common\images\f3\f3b02e.gif C:\\ijji\ENGLISH\common\images\f3\f3b02m.gif C:\\ijji\ENGLISH\common\images\f3\f3b02o.gif C:\\ijji\ENGLISH\common\images\f3\f3b02p.gif C:\\ijji\ENGLISH\common\images\f3\f3b02w.gif C:\\ijji\ENGLISH\common\images\f3\f3b039.gif C:\\ijji\ENGLISH\common\images\f3\f3c009.gif C:\\ijji\ENGLISH\common\images\f3\f3c00a.gif C:\\ijji\ENGLISH\common\images\f3\f3c00e.gif C:\\ijji\ENGLISH\common\images\f3\f3c00i.gif C:\\ijji\ENGLISH\common\images\f3\f3c00m.gif C:\\ijji\ENGLISH\common\images\f3\f3c00p.gif C:\\ijji\ENGLISH\common\images\f3\f3c00y.gif C:\\ijji\ENGLISH\common\images\f3\f3c00z.gif C:\\ijji\ENGLISH\common\images\f3\f3c011.gif C:\\ijji\ENGLISH\common\images\f3\f3c01f.gif C:\\ijji\ENGLISH\common\images\f3\f3c01s.gif C:\\ijji\ENGLISH\common\images\f3\f3c01t.gif C:\\ijji\ENGLISH\common\images\f3\f3c020.gif C:\\ijji\ENGLISH\common\images\f3\f3c025.gif C:\\ijji\ENGLISH\common\images\f3\f3c02a.gif C:\\ijji\ENGLISH\common\images\f3\f3c02c.gif C:\\ijji\ENGLISH\common\images\f3\f3c02m.gif C:\\ijji\ENGLISH\common\images\f3\f3d009.gif C:\\ijji\ENGLISH\common\images\f3\f3d00i.gif C:\\ijji\ENGLISH\common\images\f3\f3d00x.gif C:\\ijji\ENGLISH\common\images\f3\f3d010.gif C:\\ijji\ENGLISH\common\images\f3\f3d013.gif C:\\ijji\ENGLISH\common\images\f3\f3d016.gif C:\\ijji\ENGLISH\common\images\f3\f3d01t.gif C:\\ijji\ENGLISH\common\images\f3\f3d029.gif C:\\ijji\ENGLISH\common\images\f3\f3d02a.gif C:\\ijji\ENGLISH\common\images\f3\f3d02m.gif C:\\ijji\ENGLISH\common\images\f3\f3d02t.gif C:\\ijji\ENGLISH\common\images\f4\f4a002.gif C:\\ijji\ENGLISH\common\images\f4\f4a005.gif C:\\ijji\ENGLISH\common\images\f4\f4a006.gif C:\\ijji\ENGLISH\common\images\f4\f4a00j.gif C:\\ijji\ENGLISH\common\images\f4\f4a00w.gif C:\\ijji\ENGLISH\common\images\f4\f4a014.gif C:\\ijji\ENGLISH\common\images\f4\f4a01k.gif C:\\ijji\ENGLISH\common\images\f4\f4a01z.gif C:\\ijji\ENGLISH\common\images\f4\f4a023.gif C:\\ijji\ENGLISH\common\images\f4\f4a02g.gif C:\\ijji\ENGLISH\common\images\f4\f4a02j.gif C:\\ijji\ENGLISH\common\images\f4\f4a02l.gif C:\\ijji\ENGLISH\common\images\f4\f4b003.gif C:\\ijji\ENGLISH\common\images\f4\f4b005.gif C:\\ijji\ENGLISH\common\images\f4\f4b00j.gif C:\\ijji\ENGLISH\common\images\f4\f4b00o.gif C:\\ijji\ENGLISH\common\images\f4\f4b00p.gif C:\\ijji\ENGLISH\common\images\f4\f4b00v.gif C:\\ijji\ENGLISH\common\images\f4\f4b00z.gif C:\\ijji\ENGLISH\common\images\f4\f4b013.gif C:\\ijji\ENGLISH\common\images\f4\f4b014.gif C:\\ijji\ENGLISH\common\images\f4\f4b017.gif C:\\ijji\ENGLISH\common\images\f4\f4b01c.gif C:\\ijji\ENGLISH\common\images\f4\f4b01u.gif C:\\ijji\ENGLISH\common\images\f4\f4b01z.gif C:\\ijji\ENGLISH\common\images\f4\f4b023.gif C:\\ijji\ENGLISH\common\images\f4\f4b02i.gif C:\\ijji\ENGLISH\common\images\f4\f4b02j.gif C:\\ijji\ENGLISH\common\images\f4\f4b02l.gif C:\\ijji\ENGLISH\common\images\f4\f4b02m.gif C:\\ijji\ENGLISH\common\images\f4\f4b02n.gif C:\\ijji\ENGLISH\common\images\f4\f4c002.gif C:\\ijji\ENGLISH\common\images\f4\f4c003.gif C:\\ijji\ENGLISH\common\images\f4\f4c005.gif C:\\ijji\ENGLISH\common\images\f4\f4c006.gif C:\\ijji\ENGLISH\common\images\f4\f4c00e.gif C:\\ijji\ENGLISH\common\images\f4\f4c00j.gif C:\\ijji\ENGLISH\common\images\f4\f4c00n.gif C:\\ijji\ENGLISH\common\images\f4\f4c00o.gif C:\\ijji\ENGLISH\common\images\f4\f4c014.gif C:\\ijji\ENGLISH\common\images\f4\f4c017.gif C:\\ijji\ENGLISH\common\images\f4\f4c01a.gif C:\\ijji\ENGLISH\common\images\f4\f4c01t.gif C:\\ijji\ENGLISH\common\images\f4\f4c01u.gif C:\\ijji\ENGLISH\common\images\f4\f4c01w.gif C:\\ijji\ENGLISH\common\images\f4\f4c01y.gif C:\\ijji\ENGLISH\common\images\f4\f4c02j.gif C:\\ijji\ENGLISH\common\images\f4\f4c03j.gif C:\\ijji\ENGLISH\common\images\f4\f4d00j.gif C:\\ijji\ENGLISH\common\images\f4\f4d00z.gif C:\\ijji\ENGLISH\common\images\f4\f4d014.gif C:\\ijji\ENGLISH\common\images\f4\f4d01a.gif C:\\ijji\ENGLISH\common\images\f4\f4d01l.gif C:\\ijji\ENGLISH\common\images\f4\f4d01v.gif C:\\ijji\ENGLISH\common\images\f4\f4d01y.gif C:\\ijji\ENGLISH\common\images\f5\f5a00c.gif C:\\ijji\ENGLISH\common\images\f5\f5a014.gif C:\\ijji\ENGLISH\common\images\f5\f5a02a.gif C:\\ijji\ENGLISH\common\images\f5\f5b00j.gif C:\\ijji\ENGLISH\common\images\f6\f6a00e.gif C:\\ijji\ENGLISH\common\images\f6\f6a00n.gif C:\\ijji\ENGLISH\common\images\f6\f6a014.gif C:\\ijji\ENGLISH\common\images\f6\f6a01l.gif C:\\ijji\ENGLISH\common\images\f6\f6a01y.gif C:\\ijji\ENGLISH\common\images\f6\f6b003.gif C:\\ijji\ENGLISH\common\images\f6\f6b00z.gif C:\\ijji\ENGLISH\common\images\f6\f6b013.gif C:\\ijji\ENGLISH\common\images\f6\f6b014.gif C:\\ijji\ENGLISH\common\images\f6\f6b01k.gif C:\\ijji\ENGLISH\common\images\f6\f6b020.gif C:\\ijji\ENGLISH\common\images\f6\f6c02j.gif C:\\ijji\ENGLISH\common\images\f6\f6d00e.gif C:\\ijji\ENGLISH\common\images\f6\f6d01k.gif C:\\ijji\ENGLISH\common\images\f6\f6d01m.gif C:\\ijji\ENGLISH\common\images\f6\f6d02m.gif C:\\ijji\ENGLISH\common\images\f7\f7a021.gif C:\\ijji\ENGLISH\common\images\f7\f7b01i.gif C:\\ijji\ENGLISH\common\images\f7\f7c00f.gif C:\\ijji\ENGLISH\common\images\f7\f7d00j.gif C:\\ijji\ENGLISH\common\images\f7\f7d015.gif C:\\ijji\ENGLISH\common\images\gf\gfa00b.gif C:\\ijji\ENGLISH\common\images\gf\gfa01b.gif C:\\ijji\ENGLISH\common\images\gf\gfb004.gif C:\\ijji\ENGLISH\common\images\gf\gfb006.gif C:\\ijji\ENGLISH\common\images\gf\gfc005.gif C:\\ijji\ENGLISH\common\images\gf\gfc00b.gif C:\\ijji\ENGLISH\common\images\gm\gma004.gif C:\\ijji\ENGLISH\common\images\gm\gma006.gif C:\\ijji\ENGLISH\common\images\gm\gma00p.gif C:\\ijji\ENGLISH\common\images\gm\gmb006.gif C:\\ijji\ENGLISH\common\images\gm\gmb00e.gif C:\\ijji\ENGLISH\common\images\gm\gmb00p.gif C:\\ijji\ENGLISH\common\images\gm\gmb01j.gif C:\\ijji\ENGLISH\common\images\gm\gmc01b.gif C:\\ijji\ENGLISH\common\images\h1\h100c1.gif C:\\ijji\ENGLISH\common\images\h1\h100c2.gif C:\\ijji\ENGLISH\common\images\h1\h100d1.gif C:\\ijji\ENGLISH\common\images\h1\h100d2.gif C:\\ijji\ENGLISH\common\images\h1\h100e1.gif C:\\ijji\ENGLISH\common\images\h1\h100e2.gif C:\\ijji\ENGLISH\common\images\h1\h100f1.gif C:\\ijji\ENGLISH\common\images\h1\h100f2.gif C:\\ijji\ENGLISH\common\images\h1\h100h1.gif C:\\ijji\ENGLISH\common\images\h1\h100h2.gif C:\\ijji\ENGLISH\common\images\h1\h100m1.gif C:\\ijji\ENGLISH\common\images\h1\h100m2.gif C:\\ijji\ENGLISH\common\images\h1\h100n1.gif C:\\ijji\ENGLISH\common\images\h1\h100n2.gif C:\\ijji\ENGLISH\common\images\h1\h100o1.gif C:\\ijji\ENGLISH\common\images\h1\h100o2.gif C:\\ijji\ENGLISH\common\images\h1\h100u1.gif C:\\ijji\ENGLISH\common\images\h1\h100u2.gif C:\\ijji\ENGLISH\common\images\h1\h100v1.gif C:\\ijji\ENGLISH\common\images\h1\h100v2.gif C:\\ijji\ENGLISH\common\images\h1\h100w1.gif C:\\ijji\ENGLISH\common\images\h1\h100w2.gif C:\\ijji\ENGLISH\common\images\h1\h100y1.gif C:\\ijji\ENGLISH\common\images\h1\h100y2.gif C:\\ijji\ENGLISH\common\images\h1\h10101.gif C:\\ijji\ENGLISH\common\images\h1\h10102.gif C:\\ijji\ENGLISH\common\images\h1\h10121.gif C:\\ijji\ENGLISH\common\images\h1\h10122.gif C:\\ijji\ENGLISH\common\images\h1\h101o1.gif C:\\ijji\ENGLISH\common\images\h1\h101o2.gif C:\\ijji\ENGLISH\common\images\h1\h101p1.gif C:\\ijji\ENGLISH\common\images\h1\h101p2.gif C:\\ijji\ENGLISH\common\images\h1\h101r1.gif C:\\ijji\ENGLISH\common\images\h1\h101r2.gif C:\\ijji\ENGLISH\common\images\h1\h101s1.gif C:\\ijji\ENGLISH\common\images\h1\h101s2.gif C:\\ijji\ENGLISH\common\images\h1\h101y1.gif C:\\ijji\ENGLISH\common\images\h1\h101y2.gif C:\\ijji\ENGLISH\common\images\h1\h101z1.gif C:\\ijji\ENGLISH\common\images\h1\h101z2.gif C:\\ijji\ENGLISH\common\images\h1\h10221.gif C:\\ijji\ENGLISH\common\images\h1\h10222.gif C:\\ijji\ENGLISH\common\images\h1\h10241.gif C:\\ijji\ENGLISH\common\images\h1\h10242.gif C:\\ijji\ENGLISH\common\images\h1\h10251.gif C:\\ijji\ENGLISH\common\images\h1\h10252.gif C:\\ijji\ENGLISH\common\images\h1\h10261.gif C:\\ijji\ENGLISH\common\images\h1\h10262.gif C:\\ijji\ENGLISH\common\images\h1\h10271.gif C:\\ijji\ENGLISH\common\images\h1\h10272.gif C:\\ijji\ENGLISH\common\images\h1\h10291.gif C:\\ijji\ENGLISH\common\images\h1\h10292.gif C:\\ijji\ENGLISH\common\images\h1\h102e1.gif C:\\ijji\ENGLISH\common\images\h1\h102e2.gif C:\\ijji\ENGLISH\common\images\h1\h102i1.gif C:\\ijji\ENGLISH\common\images\h1\h102i2.gif C:\\ijji\ENGLISH\common\images\h1\h102k1.gif C:\\ijji\ENGLISH\common\images\h1\h102k2.gif C:\\ijji\ENGLISH\common\images\h1\h102u1.gif C:\\ijji\ENGLISH\common\images\h1\h102u2.gif C:\\ijji\ENGLISH\common\images\h1\h102y1.gif C:\\ijji\ENGLISH\common\images\h1\h102y2.gif C:\\ijji\ENGLISH\common\images\h1\h103c1.gif C:\\ijji\ENGLISH\common\images\h1\h103c2.gif C:\\ijji\ENGLISH\common\images\h1\h103g1.gif C:\\ijji\ENGLISH\common\images\h1\h103g2.gif C:\\ijji\ENGLISH\common\images\h1\h103o1.gif C:\\ijji\ENGLISH\common\images\h1\h103o2.gif C:\\ijji\ENGLISH\common\images\h1\h103p1.gif C:\\ijji\ENGLISH\common\images\h1\h103p2.gif C:\\ijji\ENGLISH\common\images\h1\h103v1.gif C:\\ijji\ENGLISH\common\images\h1\h103v2.gif C:\\ijji\ENGLISH\common\images\h1\h104c1.gif C:\\ijji\ENGLISH\common\images\h1\h104c2.gif C:\\ijji\ENGLISH\common\images\h1\h104q1.gif C:\\ijji\ENGLISH\common\images\h1\h104q2.gif C:\\ijji\ENGLISH\common\images\h1\h104w1.gif C:\\ijji\ENGLISH\common\images\h1\h104w2.gif C:\\ijji\ENGLISH\common\images\h1\h104x1.gif C:\\ijji\ENGLISH\common\images\h1\h104x2.gif C:\\ijji\ENGLISH\common\images\h1\h105f1.gif C:\\ijji\ENGLISH\common\images\h1\h105f2.gif C:\\ijji\ENGLISH\common\images\h2\h20061.gif C:\\ijji\ENGLISH\common\images\h2\h20062.gif C:\\ijji\ENGLISH\common\images\h2\h200v1.gif C:\\ijji\ENGLISH\common\images\h2\h200v2.gif C:\\ijji\ENGLISH\common\images\h2\h200x1.gif C:\\ijji\ENGLISH\common\images\h2\h200x2.gif C:\\ijji\ENGLISH\common\images\h2\h20131.gif C:\\ijji\ENGLISH\common\images\h2\h20132.gif C:\\ijji\ENGLISH\common\images\h2\h201r1.gif C:\\ijji\ENGLISH\common\images\h2\h201r2.gif C:\\ijji\ENGLISH\common\images\h2\h202b1.gif C:\\ijji\ENGLISH\common\images\h2\h202b2.gif C:\\ijji\ENGLISH\common\images\h2\h202d1.gif C:\\ijji\ENGLISH\common\images\h2\h202d2.gif C:\\ijji\ENGLISH\common\images\h2\h203m1.gif C:\\ijji\ENGLISH\common\images\h2\h203m2.gif C:\\ijji\ENGLISH\common\images\h2\h203o1.gif C:\\ijji\ENGLISH\common\images\h2\h203o2.gif C:\\ijji\ENGLISH\common\images\h2\h203s1.gif C:\\ijji\ENGLISH\common\images\h2\h203s2.gif C:\\ijji\ENGLISH\common\images\h2\h203x1.gif C:\\ijji\ENGLISH\common\images\h2\h203x2.gif C:\\ijji\ENGLISH\common\images\h2\h204f1.gif C:\\ijji\ENGLISH\common\images\h2\h204f2.gif C:\\ijji\ENGLISH\common\images\h3\h300j1.gif C:\\ijji\ENGLISH\common\images\h3\h300j2.gif C:\\ijji\ENGLISH\common\images\h3\h300l1.gif C:\\ijji\ENGLISH\common\images\h3\h300l2.gif C:\\ijji\ENGLISH\common\images\h4\h40021.gif C:\\ijji\ENGLISH\common\images\h4\h40022.gif C:\\ijji\ENGLISH\common\images\h4\h400c1.gif C:\\ijji\ENGLISH\common\images\h4\h400c2.gif C:\\ijji\ENGLISH\common\images\h4\h400f1.gif C:\\ijji\ENGLISH\common\images\h4\h400f2.gif C:\\ijji\ENGLISH\common\images\h4\h400g1.gif C:\\ijji\ENGLISH\common\images\h4\h400g2.gif C:\\ijji\ENGLISH\common\images\h4\h400h1.gif C:\\ijji\ENGLISH\common\images\h4\h400h2.gif C:\\ijji\ENGLISH\common\images\h4\h400j1.gif C:\\ijji\ENGLISH\common\images\h4\h400j2.gif C:\\ijji\ENGLISH\common\images\h4\h400s1.gif C:\\ijji\ENGLISH\common\images\h4\h400s2.gif C:\\ijji\ENGLISH\common\images\h4\h400v1.gif C:\\ijji\ENGLISH\common\images\h4\h400v2.gif C:\\ijji\ENGLISH\common\images\h4\h400w1.gif C:\\ijji\ENGLISH\common\images\h4\h400w2.gif C:\\ijji\ENGLISH\common\images\h4\h401s1.gif C:\\ijji\ENGLISH\common\images\h4\h401s2.gif C:\\ijji\ENGLISH\common\images\h4\h40291.gif C:\\ijji\ENGLISH\common\images\h4\h40292.gif C:\\ijji\ENGLISH\common\images\h4\h402j1.gif C:\\ijji\ENGLISH\common\images\h4\h402j2.gif C:\\ijji\ENGLISH\common\images\h4\h402w1.gif C:\\ijji\ENGLISH\common\images\h4\h402w2.gif C:\\ijji\ENGLISH\common\images\h4\h40311.gif C:\\ijji\ENGLISH\common\images\h4\h40312.gif C:\\ijji\ENGLISH\common\images\h4\h40371.gif C:\\ijji\ENGLISH\common\images\h4\h40372.gif C:\\ijji\ENGLISH\common\images\h4\h403g1.gif C:\\ijji\ENGLISH\common\images\h4\h403g2.gif C:\\ijji\ENGLISH\common\images\h4\h403o1.gif C:\\ijji\ENGLISH\common\images\h4\h403o2.gif C:\\ijji\ENGLISH\common\images\h4\h405f1.gif C:\\ijji\ENGLISH\common\images\h4\h405f2.gif C:\\ijji\ENGLISH\common\images\hgb2008.ico C:\\ijji\ENGLISH\common\images\hgc2008.ico C:\\ijji\ENGLISH\common\images\hostmark.him C:\\ijji\ENGLISH\common\images\img_channel_seedmoney.him C:\\ijji\ENGLISH\common\images\JackpotScoreBoardNumber.him C:\\ijji\ENGLISH\common\images\jiksocheckbtn.him C:\\ijji\ENGLISH\common\images\k2\k2001.gif C:\\ijji\ENGLISH\common\images\k2\k2002.gif C:\\ijji\ENGLISH\common\images\k2\k2003.gif C:\\ijji\ENGLISH\common\images\k3\k3003.gif C:\\ijji\ENGLISH\common\images\k3\k3007.gif C:\\ijji\ENGLISH\common\images\k4\k4005.gif C:\\ijji\ENGLISH\common\images\k5\k5002.gif C:\\ijji\ENGLISH\common\images\k5\k5003.gif C:\\ijji\ENGLISH\common\images\k5\k5006.gif C:\\ijji\ENGLISH\common\images\k5\k500c.gif C:\\ijji\ENGLISH\common\images\k5\k500d.gif C:\\ijji\ENGLISH\common\images\k5\k500e.gif C:\\ijji\ENGLISH\common\images\k5\k500f.gif C:\\ijji\ENGLISH\common\images\k5\k500g.gif C:\\ijji\ENGLISH\common\images\k5\k500h.gif C:\\ijji\ENGLISH\common\images\k5\k500j.gif C:\\ijji\ENGLISH\common\images\k5\k500k.gif C:\\ijji\ENGLISH\common\images\k5\k500l.gif C:\\ijji\ENGLISH\common\images\k6\k6001.gif C:\\ijji\ENGLISH\common\images\k6\k6002.gif C:\\ijji\ENGLISH\common\images\k6\k6004.gif C:\\ijji\ENGLISH\common\images\k6\k6006.gif
  5. part 2 C:\\ijji\ENGLISH\common\images\a1\a1001.gif C:\\ijji\ENGLISH\common\images\a1\a1002.gif C:\\ijji\ENGLISH\common\images\a1\a1003.gif C:\\ijji\ENGLISH\common\images\a1\a1005.gif C:\\ijji\ENGLISH\common\images\a1\a1006.gif C:\\ijji\ENGLISH\common\images\a1\a1008.gif C:\\ijji\ENGLISH\common\images\a1\a1009.gif C:\\ijji\ENGLISH\common\images\a1\a100a.gif C:\\ijji\ENGLISH\common\images\a2\a2002.gif C:\\ijji\ENGLISH\common\images\a2\a2003.gif C:\\ijji\ENGLISH\common\images\a3\a3004.gif C:\\ijji\ENGLISH\common\images\a3\a3006.gif C:\\ijji\ENGLISH\common\images\a4\a4002.gif C:\\ijji\ENGLISH\common\images\arrow_gray.him C:\\ijji\ENGLISH\common\images\bar_line.him C:\\ijji\ENGLISH\common\images\btn_kickuser.him C:\\ijji\ENGLISH\common\images\btn_opengdiary.him C:\\ijji\ENGLISH\common\images\btn_reportabuse.him C:\\ijji\ENGLISH\common\images\btnchance.him C:\\ijji\ENGLISH\common\images\c1\c1002.gif C:\\ijji\ENGLISH\common\images\c1\c1009.gif C:\\ijji\ENGLISH\common\images\c1\c100a.gif C:\\ijji\ENGLISH\common\images\c1\c100e.gif C:\\ijji\ENGLISH\common\images\c1\c100g.gif C:\\ijji\ENGLISH\common\images\c1\c100h.gif C:\\ijji\ENGLISH\common\images\c1\c100i.gif C:\\ijji\ENGLISH\common\images\c2\c2004.gif C:\\ijji\ENGLISH\common\images\c2\c2009.gif C:\\ijji\ENGLISH\common\images\c2\c200c.gif C:\\ijji\ENGLISH\common\images\c2\c200k.gif C:\\ijji\ENGLISH\common\images\c2\c200n.gif C:\\ijji\ENGLISH\common\images\c3\c3001.gif C:\\ijji\ENGLISH\common\images\c3\c3004.gif C:\\ijji\ENGLISH\common\images\c3\c3006.gif C:\\ijji\ENGLISH\common\images\c3\c300b.gif C:\\ijji\ENGLISH\common\images\c3\c300d.gif C:\\ijji\ENGLISH\common\images\c3\c300i.gif C:\\ijji\ENGLISH\common\images\c3\c300k.gif C:\\ijji\ENGLISH\common\images\c3\c300n.gif C:\\ijji\ENGLISH\common\images\com\0\ABFA00-H101R_WF01L_F100I_F201F_F301F_F4017_D2001_K9002 C:\\ijji\ENGLISH\common\images\com\0\ABFA00-H102E_WF01V_F100C_F201F_F300R_F4017 C:\\ijji\ENGLISH\common\images\com\0\ABFA00-H203O_WF00E_F1001_F201F_F300R_F402N C:\\ijji\ENGLISH\common\images\com\0\ABMA00-H100V_WM02A_F1001_F2002_F300Z_F400J_D4006_K500J C:\\ijji\ENGLISH\common\images\com\0\ABMA00-H100V_WM02A_F100J_F200L_F300Z_F4005 C:\\ijji\ENGLISH\common\images\com\0\ABMA00-H102I_WM023_F1005_F2005_F3009_F4003 C:\\ijji\ENGLISH\common\images\com\0\ACMA00-H104C_WM036_F1002_F2002_F302M_F401U C:\\ijji\ENGLISH\common\images\com\0\AUUA00-C100G_C200C_C300D_K5003 C:\\ijji\ENGLISH\common\images\com\1\AAMA00-H1027_WM013_F100C_F201F_F3013_F600E_D2001_K6002_K900C C:\\ijji\ENGLISH\common\images\com\1\ABFA00-H100O_WF01L_F100S_F201F_F3009_F401C C:\\ijji\ENGLISH\common\images\com\1\ABMA00-H100V_WM01V_F100F_F200K_F3025_F400J C:\\ijji\ENGLISH\common\images\com\1\ABMA00-H1022_WM01B_F1001_F2002_F302B_F401U_K500D C:\\ijji\ENGLISH\common\images\com\1\ABMA00-H200V_WM01M_F100C_F2002_F3039_F4005 C:\\ijji\ENGLISH\common\images\com\1\AUUA00-C1009_C200N_C300N C:\\ijji\ENGLISH\common\images\com\10\ABFA00-A1009_H103C_WF00F_F100S_F201G_F300R_F400P_D400F_K500L_K6007_K9007 C:\\ijji\ENGLISH\common\images\com\10\ACFA00-H100H_WF01F_F100S_F201B_F300I_F401A_D400C_K500J C:\\ijji\ENGLISH\common\images\com\11\AAFA00-GF00B_K500F_K9004 C:\\ijji\ENGLISH\common\images\com\11\AAFA00-H101O_WF006_F1001_F201E_F300G_F502A_K6004 C:\\ijji\ENGLISH\common\images\com\11\ABMA00-H203M_WM012_F100J_F2013_F3013_F500J C:\\ijji\ENGLISH\common\images\com\12\AAMA00-A1002_H102Y_WM02U_F100C_F2001_F3011_F402L C:\\ijji\ENGLISH\common\images\com\12\ABMA00-H400C_WM02Z_F100I_F201F_F302P_F4014_D2002_K900E C:\\ijji\ENGLISH\common\images\com\12\ACMA00-H400W_WM02H_F1005_F2014_F3020_F403J_D400C C:\\ijji\ENGLISH\common\images\com\13\AAMA00-H104X_WM01E_F1001_F201B_F303J_F400J_D400E_K6007_K9003 C:\\ijji\ENGLISH\common\images\com\13\ACMA00-H100V_WM016_F1002_F2002_F301F_F4014_D2002 C:\\ijji\ENGLISH\common\images\com\13\ACMA00-H202D_WM01V_F100C_F2001_F3011_F401W C:\\ijji\ENGLISH\common\images\com\13\ADMA00-H103V_WM024_F100C_F200H_F3013_F401L C:\\ijji\ENGLISH\common\images\com\14\ABFA00-GF004 C:\\ijji\ENGLISH\common\images\com\14\ACFA00-H200X_WF028_F100C_F200Y_F300M_F700F C:\\ijji\ENGLISH\common\images\com\14\ADFA00-H403O_WF01L_F100C_F201B_F3010_F602M C:\\ijji\ENGLISH\common\images\com\15\AAFA00-A1005_H101R_WF01H_F100I_F201F_F300R_F4014_D400E_K500C_K6002_K9002 C:\\ijji\ENGLISH\common\images\com\15\AAMA00-H2006_WM01G_F100C_F2001_F302A_F7021 C:\\ijji\ENGLISH\common\images\com\15\AAMA00-H202B_WM01I_F100J_F201C_F3013_F601L C:\\ijji\ENGLISH\common\images\com\15\ABFA00-H1012_WF01V_F1001_F201B_F300F_F4023 C:\\ijji\ENGLISH\common\images\com\15\ABFA00-H1025_WF022_F100B_F200Y_F302W_F4013 C:\\ijji\ENGLISH\common\images\com\15\ABMA00-A1003_H100D_WM027_F1002_F2013_F301F_F400J_D400F_K2001_K500D_K9003 C:\\ijji\ENGLISH\common\images\com\15\ABMA00-H101Z_WM010_F1001_F201F_F300R_F4014_D2001 C:\\ijji\ENGLISH\common\images\com\15\ABMA00-H101Z_WM01G_F1001_F2002_F300P_F400V_K5006_K600C_K900J C:\\ijji\ENGLISH\common\images\com\15\ABMA00-H1022_WM01J_F100J_F201F_F300Z_F4005 C:\\ijji\ENGLISH\common\images\com\15\ABMA00-H400S_WM00X_F100C_F201B_F301X_F402J_D2001 C:\\ijji\ENGLISH\common\images\com\15\ADFA00-H401S_WF020_F100C_F201B_F300I_F7015 C:\\ijji\ENGLISH\common\images\com\15\AUUA00-C100E_C200C_C300D_K500J C:\\ijji\ENGLISH\common\images\com\16\AAFA00-H101R_WF02W_F1002_F201B_F300R_F4006_K5003 C:\\ijji\ENGLISH\common\images\com\16\AAMA00-A100A_H300J_WM032_F1001_F200C_F302J_F4005_K9004 C:\\ijji\ENGLISH\common\images\com\16\ABFA00-GF006 C:\\ijji\ENGLISH\common\images\com\16\ABMA00-H101Z_WM026_F1001_F2002_F300P_F400Z C:\\ijji\ENGLISH\common\images\com\16\ACFA00-GF005 C:\\ijji\ENGLISH\common\images\com\16\ACMA00-H4031_WM010_F1002_F201D_F300Y_F401U_K5003_K9004 C:\\ijji\ENGLISH\common\images\com\17\AAMA00-H400S_WM01K_F100C_F201B_F300H_F402J C:\\ijji\ENGLISH\common\images\com\17\ABMA00-H202D_WM01L_F100J_F200V_F3026_F6003 C:\\ijji\ENGLISH\common\images\com\17\AUUA00-C100I_C2009_C300I_K6002 C:\\ijji\ENGLISH\common\images\com\18\AAFA00-H400H_WF034_F100C_F201G_F3009_F5014_K500H C:\\ijji\ENGLISH\common\images\com\18\AAMA00-H100W_WM02J_F100C_F200G_F3011_F500C C:\\ijji\ENGLISH\common\images\com\18\AAMA00-H300J_WM01Y_F100J_F200F_F301T_F401K C:\\ijji\ENGLISH\common\images\com\18\ABMA00-H100E_WM011_F100J_F201B_F302M_F400O C:\\ijji\ENGLISH\common\images\com\18\ACFA00-H100M_WF006_F1001_F200J_F300E_F4017 C:\\ijji\ENGLISH\common\images\com\18\ACMA00-GM01B C:\\ijji\ENGLISH\common\images\com\18\ACMA00-H1024_WM00S_F100C_F200K_F301T_F4005 C:\\ijji\ENGLISH\common\images\com\18\ACMA00-H400V_WM02G_F1002_F200D_F300Z_F4014_D2001 C:\\ijji\ENGLISH\common\images\com\19\ACMA00-H400J_WM01E_F1002_F201B_F301T_F400J_D2001_K500H C:\\ijji\ENGLISH\common\images\com\19\AUUA00-C100A_C200K_C3001_K500C C:\\ijji\ENGLISH\common\images\com\2\AAFA00-H103O_WF00F_F100S_F201B_F300R_F4014 C:\\ijji\ENGLISH\common\images\com\2\ABFA00-H104Q_WF024_F1001_F201D_F301F_F4017 C:\\ijji\ENGLISH\common\images\com\2\ABMA00-H102Y_WM036_F1002_F200B_F3009_F400O_D2003_K500G C:\\ijji\ENGLISH\common\images\com\2\ADFA00-H101S_WF01Q_F100S_F201G_F300I_F401A C:\\ijji\ENGLISH\common\images\com\2\ADMA00-H4029_WM01J_F1005_F2007_F3029_F401Y C:\\ijji\ENGLISH\common\images\com\3\ABFA00-A1006_A2002_H1010_WF01I_F100B_F201G_F300R_F402L_D4003_K600C_K900K C:\\ijji\ENGLISH\common\images\com\3\ACMA00-H300L_WM00H_F100C_F200R_F300Z_F401T C:\\ijji\ENGLISH\common\images\com\3\ADMA00-H1029_WM005_F1002_F201C_F302M_F4014_D400E_K5002_K9005 C:\\ijji\ENGLISH\common\images\com\3\ADMA00-H4002_WM012_F100F_F201F_F3016_F400Z_K2001_K500E_K6002 C:\\ijji\ENGLISH\common\images\com\4\ABMA00-A2003_H100C_WM00J_F1005_F201B_F3009_F4017_D2001_K5002_K6002 C:\\ijji\ENGLISH\common\images\com\5\AAFA00-H400G_WF03O_F100N_F200J_F300R_F4002 C:\\ijji\ENGLISH\common\images\com\5\AAMA00-GM006_K500C C:\\ijji\ENGLISH\common\images\com\5\ABMA00-GM01J C:\\ijji\ENGLISH\common\images\com\5\ABMA00-H100F_WM01L_F1001_F201F_F302M_F4014 C:\\ijji\ENGLISH\common\images\com\5\ADMA00-H1025_WM011_F100C_F200V_F301T_F601M C:\\ijji\ENGLISH\common\images\com\6\AAMA00-H403G_WM039_F1001_F201B_F300F_F402G_K6001 C:\\ijji\ENGLISH\common\images\com\6\ABMA00-A1003_GM00P_K2002_K900E C:\\ijji\ENGLISH\common\images\com\6\ACMA00-H100V_WM00H_F1001_F200D_F3009_F400J_D2002_K500E C:\\ijji\ENGLISH\common\images\com\6\ACMA00-H400C_WM01M_F100C_F2005_F300P_F4003 C:\\ijji\ENGLISH\common\images\com\6\AUUA00-C1002_C2009_C3006_K5002 C:\\ijji\ENGLISH\common\images\com\7\AAFA00-H101R_WF025_F100C_F201B_F300R_F402L_D4003_K500H_K600E_K9005 C:\\ijji\ENGLISH\common\images\com\7\AAMA00-A1003_H400F_WM01L_F1002_F200B_F3009_F400J_K5002_K9001 C:\\ijji\ENGLISH\common\images\com\7\AAMA00-GM004 C:\\ijji\ENGLISH\common\images\com\7\AAMA00-H100V_WM02B_F100C_F200V_F300Q_F601Y C:\\ijji\ENGLISH\common\images\com\7\ABFA00-A1006_A2002_H102E_WF01V_F100B_F200D_F300G_F701I_K500L_K9002 C:\\ijji\ENGLISH\common\images\com\7\ACFA00-H102K_WF019_F100S_F200T_F301S_F4006 C:\\ijji\ENGLISH\common\images\com\7\AUUA00-A1008_A3004_C1002_C2009_C300K_K2003_K3007_K500K_K600D_K900I C:\\ijji\ENGLISH\common\images\com\7\AUUA00-C100H_C200C_C300D_K500H_K6007 C:\\ijji\ENGLISH\common\images\com\8\AAFA00-GF01B C:\\ijji\ENGLISH\common\images\com\8\AAFA00-H102K_WF029_F100C_F201G_F302W_F4023 C:\\ijji\ENGLISH\common\images\com\8\ADMA00-H403G_WM02G_F100C_F200G_F302T_F601K C:\\ijji\ENGLISH\common\images\com\9\AAMA00-GM00P C:\\ijji\ENGLISH\common\images\com\9\ABFA00-H203X_WF00Q_F100B_F200Y_F302W_F4013 C:\\ijji\ENGLISH\common\images\com\9\ABMA00-H102Y_WM007_F1001_F201C_F300U_F6014 C:\\ijji\ENGLISH\common\images\com\9\ABMA00-H105F_WM011_F1002_F201F_F3009_F400J C:\\ijji\ENGLISH\common\images\com\9\ACFA00-GF00B C:\\ijji\ENGLISH\common\images\com\9\ACFA00-H101P_WF01D_F100T_F201B_F300A_F4002 C:\\ijji\ENGLISH\common\images\com\a\ABFA00-H102E_WF01V_F100C_F200Y_F3020_F6013 C:\\ijji\ENGLISH\common\images\com\a\ABMA00-A1003_H402W_WM032_F1001_F200C_F300P_F402J_D2003_K4005_K500C_K600B C:\\ijji\ENGLISH\common\images\com\a\ABMA00-GM006 C:\\ijji\ENGLISH\common\images\com\a\ABMA00-H104W_WM007_F1005_F201B_F302P_F4017 C:\\ijji\ENGLISH\common\images\com\a\ACFA00-H100F_WF00Q_F100S_F200V_F300I_F4002 C:\\ijji\ENGLISH\common\images\com\b\ABMA00-A1008_GM00E_K3003_K900N C:\\ijji\ENGLISH\common\images\com\b\ACMA00-A4002_H402J_WM007_F1006_F201C_F301F_F402J_K500D_K900M C:\\ijji\ENGLISH\common\images\com\c\AAMA00-H100U_WM02J_F1001_F201F_F301F_F6014 C:\\ijji\ENGLISH\common\images\com\c\ABFA00-A1001_H204F_WF034_F100C_F201F_F300R_F402L_D400C_K3003_K6006 C:\\ijji\ENGLISH\common\images\com\c\ABFA00-A1002_H201R_WF01Z_F100Q_F201G_F302O_F600Z_K6002 C:\\ijji\ENGLISH\common\images\com\c\ADMA00-H100V_WM01M_F100I_F200B_F3009_F700J_D400F_K900E C:\\ijji\ENGLISH\common\images\com\c\ADMA00-H100Y_WM01Z_F100C_F200V_F3013_F600E C:\\ijji\ENGLISH\common\images\com\d\AAFA00-H203S_WF01F_F100C_F201G_F300G_F600N C:\\ijji\ENGLISH\common\images\com\d\ABMA00-H101Y_WM02I_F100J_F200G_F302E_F6020 C:\\ijji\ENGLISH\common\images\com\d\ACMA00-H100U_WM01M_F1006_F201C_F300M_F400E_D4006 C:\\ijji\ENGLISH\common\images\com\d\ADMA00-H101Y_WM01E_F100C_F201C_F300X_F400J C:\\ijji\ENGLISH\common\images\com\d\ADMA00-H2013_WM016_F100C_F200L_F302A_F401V C:\\ijji\ENGLISH\common\images\com\d\AUUA00-C1002_C200C_C3004_K900G C:\\ijji\ENGLISH\common\images\com\e\AAMA00-A1002_H100N_WM037_F1001_F201B_F302M_F400W C:\\ijji\ENGLISH\common\images\com\e\AAMA00-H405F_WM036_F1005_F201B_F3009_F402J_K500C_K900B C:\\ijji\ENGLISH\common\images\com\e\ABMA00-H400F_WM012_F100I_F201B_F302M_F401Z C:\\ijji\ENGLISH\common\images\com\e\ACMA00-A1003_A3006_H1026_WM039_F1005_F200B_F302M_F400N_K900C C:\\ijji\ENGLISH\common\images\com\e\ACMA00-H102U_WM01D_F1006_F2011_F302C_F602J C:\\ijji\ENGLISH\common\images\com\e\ACMA00-H103P_WM020_F1006_F200K_F3025_F401Y C:\\ijji\ENGLISH\common\images\com\e\ACMA00-H400F_WM02Y_F100I_F200L_F302A_F400O C:\\ijji\ENGLISH\common\images\com\e\AUUA00-A2003_C1002_C2004_C300B_K5002_K6002_K900E C:\\ijji\ENGLISH\common\images\com\f\ABMA00-H100C_WM010_F100C_F200D_F300R_F601K_D2002_K500J C:\\ijji\ENGLISH\common\images\com\f\ABMA00-H103G_WM01R_F100J_F200F_F301T_F402I C:\\ijji\ENGLISH\common\images\com\f\ABMA00-H4037_WM010_F100J_F200V_F300H_F402M_D400C C:\\ijji\ENGLISH\common\images\d2\d2001.gif C:\\ijji\ENGLISH\common\images\d2\d2002.gif C:\\ijji\ENGLISH\common\images\d2\d2003.gif C:\\ijji\ENGLISH\common\images\d4\d4003.gif C:\\ijji\ENGLISH\common\images\d4\d4006.gif C:\\ijji\ENGLISH\common\images\d4\d400c.gif C:\\ijji\ENGLISH\common\images\d4\d400e.gif C:\\ijji\ENGLISH\common\images\d4\d400f.gif C:\\ijji\ENGLISH\common\images\evtGemToWinPrize.him C:\\ijji\ENGLISH\common\images\f1\f1a001.gif C:\\ijji\ENGLISH\common\images\f1\f1a002.gif C:\\ijji\ENGLISH\common\images\f1\f1a005.gif C:\\ijji\ENGLISH\common\images\f1\f1a00c.gif C:\\ijji\ENGLISH\common\images\f1\f1a00i.gif C:\\ijji\ENGLISH\common\images\f1\f1a00j.gif C:\\ijji\ENGLISH\common\images\f1\f1a00n.gif C:\\ijji\ENGLISH\common\images\f1\f1a00s.gif C:\\ijji\ENGLISH\common\images\f1\f1b001.gif C:\\ijji\ENGLISH\common\images\f1\f1b002.gif C:\\ijji\ENGLISH\common\images\f1\f1b005.gif C:\\ijji\ENGLISH\common\images\f1\f1b00b.gif C:\\ijji\ENGLISH\common\images\f1\f1b00c.gif C:\\ijji\ENGLISH\common\images\f1\f1b00f.gif C:\\ijji\ENGLISH\common\images\f1\f1b00i.gif C:\\ijji\ENGLISH\common\images\f1\f1b00j.gif C:\\ijji\ENGLISH\common\images\f1\f1b00q.gif C:\\ijji\ENGLISH\common\images\f1\f1b00s.gif C:\\ijji\ENGLISH\common\images\f1\f1c001.gif C:\\ijji\ENGLISH\common\images\f1\f1c002.gif C:\\ijji\ENGLISH\common\images\f1\f1c005.gif C:\\ijji\ENGLISH\common\images\f1\f1c006.gif C:\\ijji\ENGLISH\common\images\f1\f1c00c.gif C:\\ijji\ENGLISH\common\images\f1\f1c00i.gif C:\\ijji\ENGLISH\common\images\f1\f1c00s.gif C:\\ijji\ENGLISH\common\images\f1\f1c00t.gif C:\\ijji\ENGLISH\common\images\f1\f1d002.gif C:\\ijji\ENGLISH\common\images\f1\f1d005.gif C:\\ijji\ENGLISH\common\images\f1\f1d00c.gif C:\\ijji\ENGLISH\common\images\f1\f1d00f.gif C:\\ijji\ENGLISH\common\images\f1\f1d00i.gif C:\\ijji\ENGLISH\common\images\f1\f1d00s.gif C:\\ijji\ENGLISH\common\images\f2\f2a001.gif C:\\ijji\ENGLISH\common\images\f2\f2a00b.gif C:\\ijji\ENGLISH\common\images\f2\f2a00c.gif C:\\ijji\ENGLISH\common\images\f2\f2a00f.gif C:\\ijji\ENGLISH\common\images\f2\f2a00g.gif C:\\ijji\ENGLISH\common\images\f2\f2a00j.gif C:\\ijji\ENGLISH\common\images\f2\f2a00v.gif C:\\ijji\ENGLISH\common\images\f2\f2a01b.gif C:\\ijji\ENGLISH\common\images\f2\f2a01c.gif C:\\ijji\ENGLISH\common\images\f2\f2a01e.gif C:\\ijji\ENGLISH\common\images\f2\f2a01f.gif C:\\ijji\ENGLISH\common\images\f2\f2a01g.gif C:\\ijji\ENGLISH\common\images\f2\f2b002.gif C:\\ijji\ENGLISH\common\images\f2\f2b005.gif C:\\ijji\ENGLISH\common\images\f2\f2b00b.gif C:\\ijji\ENGLISH\common\images\f2\f2b00c.gif C:\\ijji\ENGLISH\common\images\f2\f2b00d.gif C:\\ijji\ENGLISH\common\images\f2\f2b00f.gif C:\\ijji\ENGLISH\common\images\f2\f2b00g.gif C:\\ijji\ENGLISH\common\images\f2\f2b00k.gif C:\\ijji\ENGLISH\common\images\f2\f2b00l.gif
  6. Part 1 of the Combofix log ComboFix 08-07-04.6 - AlexDong 2008-07-05 14:39:17.3 - NTFSx86 Microsoft Windows XP Home Edition 5.1.2600.2.1252.1.1033.18.1373 [GMT -4:00] Running from: C:\Documents and Settings\AlexDong\Desktop\ComboFix.exe Command switches used :: C:\Documents and Settings\AlexDong\Desktop\CFScript.txt * Created a new restore point * Resident AV is active FILE :: C:\WINDOWS\system32\actskn43.ocx C:\WINDOWS\system32\CAD8306DFB.sys C:\WINDOWS\system32\drivers\pavboot.sys C:\WINDOWS\system32\fbfarypy.dll C:\WINDOWS\system32\nsb139.tmp C:\WINDOWS\system32\nsy138.tmp C:\WINDOWS\system32\quvfuhea.dll C:\WINDOWS\system32\vrjksxav.dll C:\WINDOWS\system32\XceedCry.dll C:\WINDOWS\system32\XceedZip.dll C:\WINDOWS\system32\yrinapqx.dll . ((((((((((((((((((((((((((((((((((((((( Other Deletions ))))))))))))))))))))))))))))))))))))))))))))))))) . C:\\ijji\ENGLISH\binkw32.dll C:\\ijji\ENGLISH\capture\ROUNDERS_wackpdp_145845.jpg C:\\ijji\ENGLISH\common\Channel.hml C:\\ijji\ENGLISH\common\GameWarpInfo.ini C:\\ijji\ENGLISH\common\hgaud.hdc C:\\ijji\ENGLISH\common\images\_AdLogo1.bmp C:\\ijji\ENGLISH\common\images\_AdLogo2.bmp C:\\ijji\ENGLISH\common\images\_AdLogo3.bmp C:\\ijji\ENGLISH\common\images\_AdLogo4.bmp C:\\ijji\ENGLISH\common\images\_ChangeChannelBtn.him C:\\ijji\ENGLISH\common\images\_ChangeViewBtn.him C:\\ijji\ENGLISH\common\images\_ChannelInfo.him C:\\ijji\ENGLISH\common\images\_ChannelInfoBg.him C:\\ijji\ENGLISH\common\images\_ChannelInfoBgL.him C:\\ijji\ENGLISH\common\images\_ChannelListCtrlBg.him C:\\ijji\ENGLISH\common\images\_ChannelListCtrlBtn.him C:\\ijji\ENGLISH\common\images\_ChnlGrl_AdBg1.him C:\\ijji\ENGLISH\common\images\_ChnlGrl_AdBg2.him C:\\ijji\ENGLISH\common\images\_ChnlGrl_AdBg3.him C:\\ijji\ENGLISH\common\images\_ChnlGrl_AdBg4.him C:\\ijji\ENGLISH\common\images\_ChnlGrp_ChannelListCtrlBg.him C:\\ijji\ENGLISH\common\images\_ChnlGrp_InfoBg.him C:\\ijji\ENGLISH\common\images\_ChnlGrp_JoinBtn.him C:\\ijji\ENGLISH\common\images\_ChnlGrp_ListCtrlBg.him C:\\ijji\ENGLISH\common\images\_ChnlGrp_RefreshBtn.him C:\\ijji\ENGLISH\common\images\_ChnlGrp_RoomGrpTitle.him C:\\ijji\ENGLISH\common\images\_ChnlGrp_RoomListTitle.him C:\\ijji\ENGLISH\common\images\_ChnlGrp_ShowEmptyChnlBtn.him C:\\ijji\ENGLISH\common\images\_ChnlGrp_SortBtn.him C:\\ijji\ENGLISH\common\images\_ChnlGrp_TextInfoBg.him C:\\ijji\ENGLISH\common\images\_ChnlGrp_ViewRoomLstBtn.him C:\\ijji\ENGLISH\common\images\_ChnlGrpListCornerBottom.him C:\\ijji\ENGLISH\common\images\_ChnlGrpListCornerTop.him C:\\ijji\ENGLISH\common\images\_ChnlGrpListCtrlBg.him C:\\ijji\ENGLISH\common\images\_Chnlst_ChnlGrpListCornerBottom.him C:\\ijji\ENGLISH\common\images\_Chnlst_ChnlGrpListCornerTop.him C:\\ijji\ENGLISH\common\images\_ChnnelJackpotScoreBoardBG.him C:\\ijji\ENGLISH\common\images\_ComboboxArrowBtn.him C:\\ijji\ENGLISH\common\images\_CreateATableBtn.him C:\\ijji\ENGLISH\common\images\_CreateRoomBtn.him C:\\ijji\ENGLISH\common\images\_DefaultAvatar.him C:\\ijji\ENGLISH\common\images\_DirectStartBtn.him C:\\ijji\ENGLISH\common\images\_DummyTabBtn.him C:\\ijji\ENGLISH\common\images\_EnterChannelBtn.him C:\\ijji\ENGLISH\common\images\_ExitBtn.him C:\\ijji\ENGLISH\common\images\_GameWndFullBtn.him C:\\ijji\ENGLISH\common\images\_GameWndRstBtn.him C:\\ijji\ENGLISH\common\images\_GemPrize_BtnWhatisThis.him C:\\ijji\ENGLISH\common\images\_GemPrize_GaugeBar.him C:\\ijji\ENGLISH\common\images\_GemPrize_GemIcon.him C:\\ijji\ENGLISH\common\images\_GemPrize_GuageBg.him C:\\ijji\ENGLISH\common\images\_GemPrize_GuageSide.him C:\\ijji\ENGLISH\common\images\_GemPrize_Play7Matches.him C:\\ijji\ENGLISH\common\images\_GemPrize_Play7Matches_.him C:\\ijji\ENGLISH\common\images\_GemPrize_PlayDescription.him C:\\ijji\ENGLISH\common\images\_GemPrize_PlayDescription_.him C:\\ijji\ENGLISH\common\images\_GemPrize_PopupDlg_Bg.him C:\\ijji\ENGLISH\common\images\_GemPrize_PopupDlg_Bg_.him C:\\ijji\ENGLISH\common\images\_GemPrize_PopupDlg_CloseBtn.him C:\\ijji\ENGLISH\common\images\_GemPrizeBg.him C:\\ijji\ENGLISH\common\images\_GemPrizeEndDlg_Bg.him C:\\ijji\ENGLISH\common\images\_GemPrizeEndDlgExitBtn.him C:\\ijji\ENGLISH\common\images\_GemPrizeEndDlgGotoGemBtn.him C:\\ijji\ENGLISH\common\images\_GemPrizeGetGemBg.him C:\\ijji\ENGLISH\common\images\_GemPrizeGotExtraGems.him C:\\ijji\ENGLISH\common\images\_GemPrizeGotExtraGems_.him C:\\ijji\ENGLISH\common\images\_GemPrizeGotGems7Matches.him C:\\ijji\ENGLISH\common\images\_GemPrizeGotGems7Matches_.him C:\\ijji\ENGLISH\common\images\_GemPrizeMark.him C:\\ijji\ENGLISH\common\images\_GemPrizeMenuBtn.him C:\\ijji\ENGLISH\common\images\_GemPrizeWhatIsJackPotBg.him C:\\ijji\ENGLISH\common\images\_GemPrizeWIJMouseOver.him C:\\ijji\ENGLISH\common\images\_GMark.him C:\\ijji\ENGLISH\common\images\_GuildMark.him C:\\ijji\ENGLISH\common\images\_Hanchat_Emoticon.him C:\\ijji\ENGLISH\common\images\_HideHanChatBtn.him C:\\ijji\ENGLISH\common\images\_HowToPlayBtn.him C:\\ijji\ENGLISH\common\images\_LevelStarMark.him C:\\ijji\ENGLISH\common\images\_MainFrameAccuseBtn.him C:\\ijji\ENGLISH\common\images\_MainframeBorderBottom.him C:\\ijji\ENGLISH\common\images\_MainframeBorderSide.him C:\\ijji\ENGLISH\common\images\_MainframeCaption.him C:\\ijji\ENGLISH\common\images\_MainFrameCornerBottom.him C:\\ijji\ENGLISH\common\images\_MainframeExitBtn.him C:\\ijji\ENGLISH\common\images\_MainframeGemPrizeBtn.him C:\\ijji\ENGLISH\common\images\_MainFrameInviteBtn.him C:\\ijji\ENGLISH\common\images\_MainframeListenMusicBtn.him C:\\ijji\ENGLISH\common\images\_MainframeLogo.him C:\\ijji\ENGLISH\common\images\_MainFrameMaximizeBtn.him C:\\ijji\ENGLISH\common\images\_MainFrameMinimizeBtn.him C:\\ijji\ENGLISH\common\images\_MainFrameOptionBtn.him C:\\ijji\ENGLISH\common\images\_MainframeSlogan.him C:\\ijji\ENGLISH\common\images\_MemberListTab_SortBtn.him C:\\ijji\ENGLISH\common\images\_MiniChnl_SortBtn.him C:\\ijji\ENGLISH\common\images\_MiniChnl_ViewRoomLstBtn.him C:\\ijji\ENGLISH\common\images\_MsgBoxIcon.him C:\\ijji\ENGLISH\common\images\_MyInfo_BuyBtn.him C:\\ijji\ENGLISH\common\images\_MyInfo_Guild.him C:\\ijji\ENGLISH\common\images\_MyInfo_ItemBtn.him C:\\ijji\ENGLISH\common\images\_MyInfo_LevelGuageBar.him C:\\ijji\ENGLISH\common\images\_MyInfo_LevelGuageBg.him C:\\ijji\ENGLISH\common\images\_MyInfo_LevelGuageSide.him C:\\ijji\ENGLISH\common\images\_MyInfo_MyHomeBtn.him C:\\ijji\ENGLISH\common\images\_MyInfo_ViewProfileBtn.him C:\\ijji\ENGLISH\common\images\_MyInfoBg.him C:\\ijji\ENGLISH\common\images\_Notice.him C:\\ijji\ENGLISH\common\images\_NoticeIcon.him C:\\ijji\ENGLISH\common\images\_Player_Class_14.him C:\\ijji\ENGLISH\common\images\_Player_Class_16.him C:\\ijji\ENGLISH\common\images\_Player_Gem.him C:\\ijji\ENGLISH\common\images\_Player_Level_14.him C:\\ijji\ENGLISH\common\images\_Player_Level_16.him C:\\ijji\ENGLISH\common\images\_Player_Level_24.him C:\\ijji\ENGLISH\common\images\_Player_Level_32.him C:\\ijji\ENGLISH\common\images\_PlayNowBtn.him C:\\ijji\ENGLISH\common\images\_PlayNowBtn_HoverAni.him C:\\ijji\ENGLISH\common\images\_Popup_AcceptBtn.him C:\\ijji\ENGLISH\common\images\_Popup_AccuseBtn.him C:\\ijji\ENGLISH\common\images\_Popup_AccuseIcon.him C:\\ijji\ENGLISH\common\images\_Popup_AddFriendBtn.him C:\\ijji\ENGLISH\common\images\_Popup_AlbumBtn.him C:\\ijji\ENGLISH\common\images\_Popup_ApplyBtn.him C:\\ijji\ENGLISH\common\images\_Popup_BanishBtn.him C:\\ijji\ENGLISH\common\images\_Popup_BorderBottom.him C:\\ijji\ENGLISH\common\images\_Popup_BorderSide.him C:\\ijji\ENGLISH\common\images\_Popup_BorderTop.him C:\\ijji\ENGLISH\common\images\_Popup_BuyAvatarBtn.him C:\\ijji\ENGLISH\common\images\_Popup_CancelBtn.him C:\\ijji\ENGLISH\common\images\_Popup_CaptionIcon.him C:\\ijji\ENGLISH\common\images\_Popup_ChallengeBtn.him C:\\ijji\ENGLISH\common\images\_Popup_CheckBtn.him C:\\ijji\ENGLISH\common\images\_Popup_CornerBottom.him C:\\ijji\ENGLISH\common\images\_Popup_CornerTop.him C:\\ijji\ENGLISH\common\images\_Popup_DetailInfoBtn.him C:\\ijji\ENGLISH\common\images\_Popup_GembleWarning_MoreInfoBtn.him C:\\ijji\ENGLISH\common\images\_Popup_GembleWarning_OKBtn.him C:\\ijji\ENGLISH\common\images\_Popup_InviteBtn.him C:\\ijji\ENGLISH\common\images\_Popup_OKBtn.him C:\\ijji\ENGLISH\common\images\_Popup_ProgressBar.him C:\\ijji\ENGLISH\common\images\_Popup_ProgressBg.him C:\\ijji\ENGLISH\common\images\_Popup_ProgressSide.him C:\\ijji\ENGLISH\common\images\_Popup_RadioBtn.him C:\\ijji\ENGLISH\common\images\_Popup_RejectBtn.him C:\\ijji\ENGLISH\common\images\_Popup_ReportBtn.him C:\\ijji\ENGLISH\common\images\_Popup_ReportCancelBtn.him C:\\ijji\ENGLISH\common\images\_Popup_SendMemoBtn.him C:\\ijji\ENGLISH\common\images\_Popup_TabStatic.him C:\\ijji\ENGLISH\common\images\_PracticeBtn.him C:\\ijji\ENGLISH\common\images\_RecommendedGameBtn.him C:\\ijji\ENGLISH\common\images\_RefreshBtn.him C:\\ijji\ENGLISH\common\images\_RoomColumnSelectArrrow.him C:\\ijji\ENGLISH\common\images\_RoomCtrlBtn.him C:\\ijji\ENGLISH\common\images\_RoomCtrlBtn_2.him C:\\ijji\ENGLISH\common\images\_RoomImg_A.him C:\\ijji\ENGLISH\common\images\_RoomImg_B.him C:\\ijji\ENGLISH\common\images\_RoomImg_C.him C:\\ijji\ENGLISH\common\images\_RoomJoinBtn.him C:\\ijji\ENGLISH\common\images\_RoomKey.him C:\\ijji\ENGLISH\common\images\_RoomListCornerBottom.him C:\\ijji\ENGLISH\common\images\_RoomListCornerTop.him C:\\ijji\ENGLISH\common\images\_RoomState.him C:\\ijji\ENGLISH\common\images\_SearchRoomBtn.him C:\\ijji\ENGLISH\common\images\_ShowEmptyChnlBtn.him C:\\ijji\ENGLISH\common\images\_ShowEmptyRoomBtn.him C:\\ijji\ENGLISH\common\images\_ShowRoomNumOrderBtn.him C:\\ijji\ENGLISH\common\images\_Splash_Bg.him C:\\ijji\ENGLISH\common\images\_Splash_bg_small.him C:\\ijji\ENGLISH\common\images\_SplashWnd_CancelBtn.him C:\\ijji\ENGLISH\common\images\_SupRoomImg_A.him C:\\ijji\ENGLISH\common\images\_SupRoomImg_B.him C:\\ijji\ENGLISH\common\images\_SupRoomImg_C.him C:\\ijji\ENGLISH\common\images\_TabBtnAll.him C:\\ijji\ENGLISH\common\images\_TabBtnFriend.him C:\\ijji\ENGLISH\common\images\_TabBtnGuild.him C:\\ijji\ENGLISH\common\images\_TabBtnMyBuddy.him C:\\ijji\ENGLISH\common\images\_TabBtnPlayers.him C:\\ijji\ENGLISH\common\images\_TabCtrlLeftBorder.him C:\\ijji\ENGLISH\common\images\_TabCtrlRightBorder.him C:\\ijji\ENGLISH\common\images\_Table_LevelGuageBar.him C:\\ijji\ENGLISH\common\images\_TableImage_A.him C:\\ijji\ENGLISH\common\images\_TableImage_AA.him C:\\ijji\ENGLISH\common\images\_TooltipBtnExit.him C:\\ijji\ENGLISH\common\images\_TooltipCornerBottom.him C:\\ijji\ENGLISH\common\images\_TooltipCornerTop.him C:\\ijji\ENGLISH\common\images\_TooltipSelectArrow.him C:\\ijji\ENGLISH\common\images\_VScrollArrow.him C:\\ijji\ENGLISH\common\images\_VScrollPage.him C:\\ijji\ENGLISH\common\images\_VScrollThumb_Long.him C:\\ijji\ENGLISH\common\images\_VScrollThumb_Member.him C:\\ijji\ENGLISH\common\images\_VScrollThumb_Room.him C:\\ijji\ENGLISH\common\images\_VScrollThumb_Small.him
  7. heres the Hijackthis log Logfile of Trend Micro HijackThis v2.0.2 Scan saved at 3:29:51 PM, on 7/5/2008 Platform: Windows XP SP2 (WinNT 5.01.2600) MSIE: Internet Explorer v7.00 (7.00.6000.16674) Boot mode: Normal Running processes: C:\WINDOWS\System32\smss.exe C:\WINDOWS\system32\winlogon.exe C:\WINDOWS\system32\services.exe C:\WINDOWS\system32\lsass.exe C:\WINDOWS\system32\Ati2evxx.exe C:\WINDOWS\system32\svchost.exe C:\WINDOWS\System32\svchost.exe C:\WINDOWS\System32\WLTRYSVC.EXE C:\WINDOWS\System32\bcmwltry.exe C:\WINDOWS\system32\spoolsv.exe C:\Program Files\Common Files\LogiShrd\LVMVFM\LVPrcSrv.exe C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe C:\Program Files\Common Files\LogiShrd\LVCOMSER\LVComSer.exe C:\Program Files\McAfee\Common Framework\FrameworkService.exe C:\Program Files\McAfee\VirusScan Enterprise\mcshield.exe C:\Program Files\McAfee\VirusScan Enterprise\vstskmgr.exe C:\WINDOWS\system32\Ati2evxx.exe C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE C:\WINDOWS\system32\svchost.exe C:\Program Files\Common Files\LogiShrd\LVCOMSER\LVComSer.exe C:\WINDOWS\system32\WLTRAY.exe C:\WINDOWS\stsystra.exe C:\Program Files\Synaptics\SynTP\SynTPEnh.exe C:\Program Files\ATI Technologies\ATI.ACE\cli.exe C:\Program Files\Google\Google Talk\googletalk.exe C:\Program Files\Microsoft IntelliPoint\ipoint.exe C:\Program Files\Microsoft Office\Office12\GrooveMonitor.exe C:\Program Files\PowerISO\PWRISOVM.EXE C:\Program Files\McAfee\VirusScan Enterprise\SHSTAT.EXE C:\Program Files\McAfee\Common Framework\UdaterUI.exe C:\Program Files\Common Files\LogiShrd\LComMgr\Communications_Helper.exe C:\Program Files\Logitech\QuickCam\Quickcam.exe C:\Program Files\McAfee\Common Framework\McTray.exe C:\Program Files\iTunes\iTunesHelper.exe C:\Program Files\Java\jre1.6.0_06\bin\jusched.exe C:\Program Files\DAEMON Tools\daemon.exe C:\Program Files\AIM6\aim6.exe C:\WINDOWS\system32\ctfmon.exe C:\Program Files\Linksys EasyLink Advisor\LinksysAgent.exe C:\Program Files\Digital Line Detect\DLG.exe C:\Program Files\3M\PSNotes\psn.exe C:\PROGRA~1\3M\PSNotes\PSNGive.exe C:\Program Files\Common Files\AOL\Loader\aolload.exe C:\Program Files\iPod\bin\iPodService.exe C:\Program Files\Common Files\Logishrd\LQCVFX\COCIManager.exe C:\Program Files\AIM6\aolsoftware.exe C:\Program Files\ATI Technologies\ATI.ACE\cli.exe C:\WINDOWS\explorer.exe C:\WINDOWS\system32\notepad.exe C:\WINDOWS\System32\svchost.exe C:\Program Files\Mozilla Firefox\firefox.exe C:\WINDOWS\system32\wuauclt.exe C:\Program Files\Trend Micro\HijackThis\HijackThis.exe R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157 R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896 R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896 R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157 R1 - HKLM\Software\Microsoft\Internet Explorer\Search,Default_Page_URL = www.google.com/ig/dell?hl=en&client=dell-usuk-rel&channel=us&ibd=4061226 R1 - HKCU\Software\Microsoft\Internet Connection Wizard,ShellNext = http://desktop.google.com/uninstall-feedback.html?hl=en O2 - BHO: Spybot-S&D IE Protection - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_06\bin\ssv.dll O4 - HKLM\..\Run: [broadcom Wireless Manager UI] C:\WINDOWS\system32\WLTRAY.exe O4 - HKLM\..\Run: [sigmatelSysTrayApp] stsystra.exe O4 - HKLM\..\Run: [synTPEnh] C:\Program Files\Synaptics\SynTP\SynTPEnh.exe O4 - HKLM\..\Run: [ATICCC] "C:\Program Files\ATI Technologies\ATI.ACE\cli.exe" runtime -Delay O4 - HKLM\..\Run: [iSUSScheduler] "C:\Program Files\Common Files\InstallShield\UpdateService\issch.exe" -start O4 - HKLM\..\Run: [googletalk] C:\Program Files\Google\Google Talk\googletalk.exe /autostart O4 - HKLM\..\Run: [Tweak UI] RUNDLL32.EXE TWEAKUI.CPL,TweakMeUp O4 - HKLM\..\Run: [intelliPoint] "C:\Program Files\Microsoft IntelliPoint\ipoint.exe" O4 - HKLM\..\Run: [GrooveMonitor] "C:\Program Files\Microsoft Office\Office12\GrooveMonitor.exe" O4 - HKLM\..\Run: [PWRISOVM.EXE] C:\Program Files\PowerISO\PWRISOVM.EXE O4 - HKLM\..\Run: [shStatEXE] "C:\Program Files\McAfee\VirusScan Enterprise\SHSTAT.EXE" /STANDALONE O4 - HKLM\..\Run: [McAfeeUpdaterUI] "C:\Program Files\McAfee\Common Framework\UdaterUI.exe" /StartedFromRunKey O4 - HKLM\..\Run: [LogitechCommunicationsManager] "C:\Program Files\Common Files\LogiShrd\LComMgr\Communications_Helper.exe" O4 - HKLM\..\Run: [LogitechQuickCamRibbon] "C:\Program Files\Logitech\QuickCam\Quickcam.exe" /hide O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\QTTask.exe" -atboottime O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe" O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe" O4 - HKLM\..\Run: [sunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_06\bin\jusched.exe" O4 - HKCU\..\Run: [DAEMON Tools] "C:\Program Files\DAEMON Tools\daemon.exe" -lang 1033 O4 - HKCU\..\Run: [Aim6] "C:\Program Files\AIM6\aim6.exe" /d locale=en-US ee://aol/imApp O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe O4 - HKCU\..\Run: [EasyLinkAdvisor] "C:\Program Files\Linksys EasyLink Advisor\LinksysAgent.exe" /startup O4 - S-1-5-18 Startup: OneNote 2007 Screen Clipper and Launcher.lnk = C:\Program Files\Microsoft Office\Office12\ONENOTEM.EXE (User 'SYSTEM') O4 - .DEFAULT Startup: OneNote 2007 Screen Clipper and Launcher.lnk = C:\Program Files\Microsoft Office\Office12\ONENOTEM.EXE (User 'Default user') O4 - Startup: OneNote 2007 Screen Clipper and Launcher.lnk = C:\Program Files\Microsoft Office\Office12\ONENOTEM.EXE O4 - Global Startup: AutoCAD Startup Accelerator.lnk = C:\Program Files\Common Files\Autodesk Shared\acstart16.exe O4 - Global Startup: Digital Line Detect.lnk = ? O4 - Global Startup: Post-it
  8. I'm having some difficulty with the CFScript.txt file and the combofix, when I place the text file onto the combofix, i get an error saying that it cannot access the file because it is already in use.
  9. I finished both the scans, Combofix ComboFix 08-07-04.2 - AlexDong 2008-07-05 1:10:58.2 - NTFSx86 Microsoft Windows XP Home Edition 5.1.2600.2.1252.1.1033.18.1445 [GMT -4:00] Running from: C:\Documents and Settings\AlexDong\Desktop\ComboFix.exe * Resident AV is active . ((((((((((((((((((((((((((((((((((((((( Other Deletions ))))))))))))))))))))))))))))))))))))))))))))))))) . C:\WINDOWS\BM5b979e79.xml . ---- Previous Run ------- . C:\WINDOWS\BM5b979e79.txt C:\WINDOWS\system32\anxunexy.dll C:\WINDOWS\system32\bhgzzj.dll C:\WINDOWS\system32\gvhbafkd.dll C:\WINDOWS\system32\ncfdygyg.ini C:\WINDOWS\system32\pilrcons.ini C:\WINDOWS\system32\pordxrjp.dll C:\WINDOWS\system32\psuDKUvw.ini C:\WINDOWS\system32\psuDKUvw.ini2 C:\WINDOWS\system32\sbcfiqoc.dll C:\WINDOWS\system32\tdocwm.dll . ((((((((((((((((((((((((( Files Created from 2008-06-05 to 2008-07-05 ))))))))))))))))))))))))))))))) . 2008-07-05 00:28 . 2008-07-05 00:29 <DIR> d-------- C:\RecoveryCD 2008-07-04 23:58 . 2008-03-25 02:37 69,632 --a------ C:\WINDOWS\system32\javacpl.cpl 2008-07-04 23:56 . 2008-07-04 23:58 <DIR> d-------- C:\Program Files\Java 2008-07-04 23:56 . 2008-07-04 23:56 <DIR> d-------- C:\Program Files\Common Files\Java 2008-07-04 16:41 . 2008-07-04 16:41 <DIR> d-------- C:\Program Files\Trend Micro 2008-07-04 16:41 . 2008-06-19 17:24 28,544 --a------ C:\WINDOWS\system32\drivers\pavboot.sys 2008-07-04 16:40 . 2008-07-04 16:40 <DIR> d-------- C:\Program Files\Panda Security 2008-07-04 16:35 . 2008-07-04 16:35 <DIR> d-------- C:\Program Files\Malwarebytes' Anti-Malware 2008-07-04 16:35 . 2008-07-04 16:35 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\Malwarebytes 2008-07-04 16:35 . 2008-07-04 16:35 <DIR> d-------- C:\Documents and Settings\AlexDong\Application Data\Malwarebytes 2008-07-04 16:35 . 2008-06-28 14:21 34,296 --a------ C:\WINDOWS\system32\drivers\mbamcatchme.sys 2008-07-04 16:35 . 2008-06-28 14:21 17,144 --a------ C:\WINDOWS\system32\drivers\mbam.sys 2008-07-04 15:34 . 2008-07-04 15:35 <DIR> d-------- C:\Program Files\Spybot - Search & Destroy 2008-07-03 10:50 . 2006-09-11 10:56 526,184 --a------ C:\WINDOWS\system32\XceedCry.dll 2008-07-03 10:50 . 2006-12-21 14:18 497,496 --a------ C:\WINDOWS\system32\XceedZip.dll 2008-07-03 10:50 . 2003-05-14 21:07 389,120 --a------ C:\WINDOWS\system32\actskn43.ocx 2008-07-02 23:15 . 2008-07-02 23:15 1,972 --a------ C:\WINDOWS\system32\quvfuhea.dll 2008-07-02 22:12 . 2008-07-02 22:12 1,972 --a------ C:\WINDOWS\system32\fbfarypy.dll 2008-07-01 14:42 . 2008-07-01 14:42 1,972 --a------ C:\WINDOWS\system32\yrinapqx.dll 2008-07-01 00:28 . 2008-07-01 00:28 1,972 --a------ C:\WINDOWS\system32\vrjksxav.dll 2008-06-30 22:13 . 2008-06-30 22:13 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\PC Tools 2008-06-18 13:52 . 2008-06-18 13:52 161,096 --a------ C:\WINDOWS\system32\DivXCodecVersionChecker.exe 2008-06-11 07:18 . 2008-06-13 09:10 272,128 --------- C:\WINDOWS\system32\drivers\bthport.sys 2008-06-11 07:18 . 2008-06-13 09:10 272,128 --------- C:\WINDOWS\system32\dllcache\bthport.sys 2008-06-10 20:07 . 2008-06-10 20:07 3,596,288 --a------ C:\WINDOWS\system32\nsy138.tmp 2008-06-10 20:07 . 2008-06-10 20:07 524,288 --a------ C:\WINDOWS\system32\nsb139.tmp 2008-06-10 20:07 . 2008-06-10 20:07 4,816 --a------ C:\WINDOWS\system32\divxsm.tlb 2008-06-10 20:04 . 2008-06-10 20:04 1,044,480 --a------ C:\WINDOWS\system32\libdivx.dll 2008-06-10 20:04 . 2008-06-10 20:04 200,704 --a------ C:\WINDOWS\system32\ssldivx.dll . (((((((((((((((((((((((((((((((((((((((( Find3M Report )))))))))))))))))))))))))))))))))))))))))))))))))))) . 2008-07-05 02:41 --------- d-----w C:\Program Files\Common Files\Symantec Shared 2008-07-05 02:41 --------- d-----w C:\Documents and Settings\All Users\Application Data\Symantec 2008-07-04 23:21 --------- d-----w C:\Program Files\Warcraft III 2008-07-04 20:30 --------- d-----w C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy 2008-07-04 20:29 --------- d-----w C:\Program Files\Enigma Software Group 2008-07-04 02:00 --------- d-----w C:\Program Files\Common Files\Real 2008-07-04 01:55 --------- d-----w C:\Program Files\Common Files\Sonic Shared 2008-07-04 01:49 --------- d-----w C:\Program Files\DivX 2008-07-03 14:41 --------- d---a-w C:\Documents and Settings\All Users\Application Data\TEMP 2008-07-01 02:35 --------- d-----w C:\Program Files\LimeWire 2008-06-18 21:57 --------- d-----w C:\Documents and Settings\AlexDong\Application Data\dvdcss 2008-05-17 03:00 --------- d-----w C:\Program Files\Linksys EasyLink Advisor 2008-05-14 00:47 --------- d-----w C:\Documents and Settings\All Users\Application Data\Microsoft Help 2008-05-08 12:28 202,752 ----a-w C:\WINDOWS\system32\drivers\rmcast.sys 2007-12-08 23:53 32 ----a-w C:\Documents and Settings\All Users\Application Data\ezsid.dat 2007-01-02 22:38 88 --sh--r C:\WINDOWS\system32\CAD8306DFB.sys 2007-01-02 22:38 2,828 --sha-w C:\WINDOWS\system32\KGyGaAvL.sys . ((((((((((((((((((((((((((((((((((((( Reg Loading Points )))))))))))))))))))))))))))))))))))))))))))))))))) . . *Note* empty entries & legit default entries are not shown REGEDIT4 [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] "DAEMON Tools"="C:\Program Files\DAEMON Tools\daemon.exe" [2006-11-12 06:48 157592] "Aim6"="C:\Program Files\AIM6\aim6.exe" [2008-01-03 12:15 50528] "ctfmon.exe"="C:\WINDOWS\system32\ctfmon.exe" [2004-08-04 07:00 15360] "EasyLinkAdvisor"="C:\Program Files\Linksys EasyLink Advisor\LinksysAgent.exe" [2007-03-15 18:16 454784] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] "Broadcom Wireless Manager UI"="C:\WINDOWS\system32\WLTRAY.exe" [2006-11-23 02:35 1392640] "SynTPEnh"="C:\Program Files\Synaptics\SynTP\SynTPEnh.exe" [2006-03-08 20:48 761947] "ATICCC"="C:\Program Files\ATI Technologies\ATI.ACE\cli.exe" [2006-01-02 19:41 45056] "ISUSScheduler"="C:\Program Files\Common Files\InstallShield\UpdateService\issch.exe" [2006-03-20 18:34 86960] "googletalk"="C:\Program Files\Google\Google Talk\googletalk.exe" [2007-01-01 17:22 3739648] "IntelliPoint"="C:\Program Files\Microsoft IntelliPoint\ipoint.exe" [2006-11-21 18:09 842584] "GrooveMonitor"="C:\Program Files\Microsoft Office\Office12\GrooveMonitor.exe" [2006-10-27 00:47 31016] "PWRISOVM.EXE"="C:\Program Files\PowerISO\PWRISOVM.EXE" [2007-08-06 20:05 200704] "ShStatEXE"="C:\Program Files\McAfee\VirusScan Enterprise\SHSTAT.EXE" [2006-11-30 09:50 112216] "McAfeeUpdaterUI"="C:\Program Files\McAfee\Common Framework\UdaterUI.exe" [2006-11-17 14:39 136768] "LogitechCommunicationsManager"="C:\Program Files\Common Files\LogiShrd\LComMgr\Communications_Helper.exe" [2007-07-25 17:02 563984] "LogitechQuickCamRibbon"="C:\Program Files\Logitech\QuickCam\Quickcam.exe" [2007-07-25 17:06 2027792] "QuickTime Task"="C:\Program Files\QuickTime\QTTask.exe" [2008-01-10 16:27 385024] "iTunesHelper"="C:\Program Files\iTunes\iTunesHelper.exe" [2008-01-15 04:22 267048] "Adobe Reader Speed Launcher"="C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe" [2008-01-11 23:16 39792] "SunJavaUpdateSched"="C:\Program Files\Java\jre1.6.0_06\bin\jusched.exe" [2008-03-25 04:28 144784] "SigmatelSysTrayApp"="stsystra.exe" [2006-03-25 01:30 282624 C:\WINDOWS\stsystra.exe] "Tweak UI"="TWEAKUI.CPL" [2003-03-25 06:49 106544 C:\WINDOWS\system32\tweakui.cpl] C:\Documents and Settings\AlexDong\Start Menu\Programs\Startup\ OneNote 2007 Screen Clipper and Launcher.lnk - C:\Program Files\Microsoft Office\Office12\ONENOTEM.EXE [2006-10-26 20:24:54 98632] C:\Documents and Settings\All Users\Start Menu\Programs\Startup\ AutoCAD Startup Accelerator.lnk - C:\Program Files\Common Files\Autodesk Shared\acstart16.exe [2006-09-23 09:21:54 10872] Digital Line Detect.lnk - C:\Program Files\Digital Line Detect\DLG.exe [2006-12-26 13:32:26 24576] Post-itr Software Notes.lnk - C:\Program Files\3M\PSNotes\psn.exe [2003-10-10 15:53:20 675840] [HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\drivers32] "msacm.iac2"= C:\PROGRA~1\ACEMEG~1\SystemS\Intel\iac25_32.ax "msacm.sl_anet"= C:\PROGRA~1\ACEMEG~1\SystemS\sl_anet.acm "msacm.msaudio1"= C:\PROGRA~1\ACEMEG~1\SystemS\MICROS~1\msaud32.acm [HKEY_LOCAL_MACHINE\software\microsoft\security center] "AntiVirusDisableNotify"=dword:00000001 [HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring] "DisableMonitoring"=dword:00000001 [HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecAntiVirus] "DisableMonitoring"=dword:00000001 [HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecFirewall] "DisableMonitoring"=dword:00000001 [HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List] "%windir%\\system32\\sessmgr.exe"= "C:\\Program Files\\Google\\Google Talk\\googletalk.exe"= "%windir%\\Network Diagnostic\\xpnetdiag.exe"= "C:\\Program Files\\Common Files\\AOL\\Loader\\aolload.exe"= "C:\\Program Files\\Microsoft Office\\Office12\\OUTLOOK.EXE"= "C:\\Program Files\\Microsoft Office\\Office12\\GROOVE.EXE"= "C:\\Program Files\\Microsoft Office\\Office12\\ONENOTE.EXE"= "C:\\Program Files\\Logitech\\Desktop Messenger\\8876480\\Program\\LogitechDesktopMessenger.exe"= "C:\\Program Files\\McAfee\\Common Framework\\FrameworkService.exe"= "C:\\Program Files\\BitTornado\\btdownloadgui.exe"= "C:\\Program Files\\DC++\\DCPlusPlus.exe"= "C:\\Program Files\\AIM6\\aim6.exe"= "C:\\ijji\\ENGLISH\\u_gbound.exe"= "C:\\Program Files\\LimeWire\\LimeWire.exe"= "C:\\Program Files\\Steam\\steamapps\\azndevourer2417@yahoo.com\\counter-strike\\hl.exe"= "C:\\ijji\\ENGLISH\\u_skid.exe"= "C:\\Program Files\\iTunes\\iTunes.exe"= R0 pavboot;pavboot;C:\WINDOWS\system32\drivers\pavboot.sys [2008-06-19 17:24] S3 fd_dbus;FutureDial USB Composite Device driver (WDM);C:\WINDOWS\system32\DRIVERS\fd_dbus.sys [2005-01-17 21:46] S3 fd_dmdfl;FutureDial USB Modem Filter;C:\WINDOWS\system32\DRIVERS\fd_dmdfl.sys [2005-01-17 21:46] S3 fd_dmdm;FutureDial USB Modem Drivers;C:\WINDOWS\system32\DRIVERS\fd_dmdm.sys [2005-01-17 21:46] S3 lgatserd;LG CDMA USB Modem Diagnostic Serial Port Drivers (WDM);C:\WINDOWS\system32\DRIVERS\lgatserd.sys [2005-01-17 21:46] [HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{4b2ed31e-c15e-11dc-b62d-0019b94d2f87}] \Shell\AutoRun\command - G:\LaunchU3.exe -a [HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{8e1da9f3-f19c-11db-b5a9-0019b94d2f87}] \Shell\AutoRun\command - G:\USBNB.exe . Contents of the 'Scheduled Tasks' folder "2008-07-03 23:15:04 C:\WINDOWS\Tasks\AppleSoftwareUpdate.job" - C:\Program Files\Apple Software Update\SoftwareUpdate.exe "2008-06-11 09:00:01 C:\WINDOWS\Tasks\SpyHunter Scanner.job" - C:\Program Files\Enigma Software Group\SpyHunter\SpyHunter3.exe . - - - - ORPHANS REMOVED - - - - HKCU-Run-msnmsgr - C:\Program Files\MSN Messenger\msnmsgr.exe HKCU-Run-Uniblue RegistryBooster 2 - C:\Program Files\Uniblue\RegistryBooster 2\RegistryBooster.exe HKCU-Run-Steam - (no file) HKLM-Run-ISUSPM Startup - C:\PROGRA~1\COMMON~1\INSTAL~1\UPDATE~1\ISUSPM.exe HKLM-Run-ISUSPM - C:\Program Files\Common Files\InstallShield\UpdateService\ISUSPM.exe HKLM-Run-Spyhunter Security Suite - C:\Program Files\Enigma Software Group\SpyHunter\SpyHunter3.exe Notify-urqQgETK - urqQgETK.dll ************************************************************************** catchme 0.3.1361 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net Rootkit scan 2008-07-05 01:17:12 Windows 5.1.2600 Service Pack 2 NTFS scanning hidden processes ... scanning hidden autostart entries ... scanning hidden files ... C:\WINDOWS\system32\Postin__.FOT 1409 bytes scan completed successfully hidden files: 1 ************************************************************************** . ------------------------ Other Running Processes ------------------------ . C:\WINDOWS\system32\ati2evxx.exe C:\WINDOWS\system32\WLTRYSVC.EXE C:\WINDOWS\system32\BCMWLTRY.EXE C:\Program Files\Common Files\LogiShrd\LVMVFM\LVPrcSrv.exe C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe C:\Program Files\Common Files\LogiShrd\LVCOMSER\LVComSer.exe C:\Program Files\McAfee\Common Framework\FrameworkService.exe C:\WINDOWS\system32\ati2evxx.exe C:\Program Files\McAfee\VirusScan Enterprise\mcshield.exe C:\Program Files\McAfee\VirusScan Enterprise\vstskmgr.exe C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE C:\Program Files\McAfee\Common Framework\naPrdMgr.exe C:\PROGRA~1\COMMON~1\SYMANT~1\CCPD-LC\symlcsvc.exe C:\Program Files\Common Files\LogiShrd\LVCOMSER\LVComSer.exe C:\Program Files\McAfee\Common Framework\Mctray.exe C:\Program Files\iPod\bin\iPodService.exe C:\Program Files\Common Files\AOL\Loader\aolload.exe C:\Program Files\3M\PSNotes\PSNGive.exe C:\Program Files\Common Files\LogiShrd\LQCVFX\COCIManager.exe C:\Program Files\AIM6\aolsoftware.exe . ************************************************************************** . Completion time: 2008-07-05 1:21:59 - machine was rebooted [AlexDong] ComboFix-quarantined-files.txt 2008-07-05 05:21:55 Pre-Run: 42,315,546,624 bytes free Post-Run: 42,349,211,648 bytes free 205 --- E O F --- 2008-06-21 01:04:01 HijackThis Logfile of Trend Micro HijackThis v2.0.2 Scan saved at 1:23:00 AM, on 7/5/2008 Platform: Windows XP SP2 (WinNT 5.01.2600) MSIE: Internet Explorer v7.00 (7.00.6000.16674) Boot mode: Normal Running processes: C:\WINDOWS\System32\smss.exe C:\WINDOWS\system32\winlogon.exe C:\WINDOWS\system32\services.exe C:\WINDOWS\system32\lsass.exe C:\WINDOWS\system32\Ati2evxx.exe C:\WINDOWS\system32\svchost.exe C:\WINDOWS\System32\svchost.exe C:\WINDOWS\System32\WLTRYSVC.EXE C:\WINDOWS\System32\bcmwltry.exe C:\WINDOWS\system32\spoolsv.exe C:\Program Files\Common Files\LogiShrd\LVMVFM\LVPrcSrv.exe C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe C:\Program Files\Common Files\LogiShrd\LVCOMSER\LVComSer.exe C:\Program Files\McAfee\Common Framework\FrameworkService.exe C:\WINDOWS\system32\Ati2evxx.exe C:\Program Files\McAfee\VirusScan Enterprise\mcshield.exe C:\Program Files\McAfee\VirusScan Enterprise\vstskmgr.exe C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE C:\WINDOWS\system32\svchost.exe C:\PROGRA~1\COMMON~1\SYMANT~1\CCPD-LC\symlcsvc.exe C:\Program Files\Common Files\LogiShrd\LVCOMSER\LVComSer.exe C:\WINDOWS\system32\wuauclt.exe C:\WINDOWS\system32\WLTRAY.exe C:\WINDOWS\stsystra.exe C:\Program Files\Synaptics\SynTP\SynTPEnh.exe C:\Program Files\ATI Technologies\ATI.ACE\cli.exe C:\Program Files\Google\Google Talk\googletalk.exe C:\Program Files\Microsoft IntelliPoint\ipoint.exe C:\Program Files\Microsoft Office\Office12\GrooveMonitor.exe C:\Program Files\PowerISO\PWRISOVM.EXE C:\Program Files\McAfee\VirusScan Enterprise\SHSTAT.EXE C:\Program Files\McAfee\Common Framework\UdaterUI.exe C:\Program Files\Common Files\LogiShrd\LComMgr\Communications_Helper.exe C:\WINDOWS\system32\ctfmon.exe C:\Program Files\McAfee\Common Framework\McTray.exe C:\Program Files\Logitech\QuickCam\Quickcam.exe C:\Program Files\iTunes\iTunesHelper.exe C:\Program Files\Java\jre1.6.0_06\bin\jusched.exe C:\Program Files\DAEMON Tools\daemon.exe C:\Program Files\AIM6\aim6.exe C:\Program Files\Linksys EasyLink Advisor\LinksysAgent.exe C:\Program Files\iPod\bin\iPodService.exe C:\Program Files\Common Files\AOL\Loader\aolload.exe C:\Program Files\Digital Line Detect\DLG.exe C:\Program Files\3M\PSNotes\psn.exe C:\PROGRA~1\3M\PSNotes\PSNGive.exe C:\Program Files\Common Files\Logishrd\LQCVFX\COCIManager.exe C:\Program Files\AIM6\aolsoftware.exe C:\Program Files\ATI Technologies\ATI.ACE\cli.exe C:\WINDOWS\explorer.exe C:\WINDOWS\system32\notepad.exe C:\Program Files\Trend Micro\HijackThis\HijackThis.exe R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157 R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896 R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896 R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157 R1 - HKLM\Software\Microsoft\Internet Explorer\Search,Default_Page_URL = www.google.com/ig/dell?hl=en&client=dell-usuk-rel&channel=us&ibd=4061226 R1 - HKCU\Software\Microsoft\Internet Connection Wizard,ShellNext = http://desktop.google.com/uninstall-feedback.html?hl=en O2 - BHO: Spybot-S&D IE Protection - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_06\bin\ssv.dll O3 - Toolbar: ZoneAlarm Spy Blocker - {F0D4B239-DA4B-4daf-81E4-DFEE4931A4AA} - C:\Program Files\ZoneAlarmSB\bar\1.bin\SPYBLOCK.DLL (file missing) O4 - HKLM\..\Run: [broadcom Wireless Manager UI] C:\WINDOWS\system32\WLTRAY.exe O4 - HKLM\..\Run: [sigmatelSysTrayApp] stsystra.exe O4 - HKLM\..\Run: [synTPEnh] C:\Program Files\Synaptics\SynTP\SynTPEnh.exe O4 - HKLM\..\Run: [ATICCC] "C:\Program Files\ATI Technologies\ATI.ACE\cli.exe" runtime -Delay O4 - HKLM\..\Run: [iSUSScheduler] "C:\Program Files\Common Files\InstallShield\UpdateService\issch.exe" -start O4 - HKLM\..\Run: [googletalk] C:\Program Files\Google\Google Talk\googletalk.exe /autostart O4 - HKLM\..\Run: [Tweak UI] RUNDLL32.EXE TWEAKUI.CPL,TweakMeUp O4 - HKLM\..\Run: [intelliPoint] "C:\Program Files\Microsoft IntelliPoint\ipoint.exe" O4 - HKLM\..\Run: [GrooveMonitor] "C:\Program Files\Microsoft Office\Office12\GrooveMonitor.exe" O4 - HKLM\..\Run: [PWRISOVM.EXE] C:\Program Files\PowerISO\PWRISOVM.EXE O4 - HKLM\..\Run: [shStatEXE] "C:\Program Files\McAfee\VirusScan Enterprise\SHSTAT.EXE" /STANDALONE O4 - HKLM\..\Run: [McAfeeUpdaterUI] "C:\Program Files\McAfee\Common Framework\UdaterUI.exe" /StartedFromRunKey O4 - HKLM\..\Run: [LogitechCommunicationsManager] "C:\Program Files\Common Files\LogiShrd\LComMgr\Communications_Helper.exe" O4 - HKLM\..\Run: [LogitechQuickCamRibbon] "C:\Program Files\Logitech\QuickCam\Quickcam.exe" /hide O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\QTTask.exe" -atboottime O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe" O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe" O4 - HKLM\..\Run: [sunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_06\bin\jusched.exe" O4 - HKCU\..\Run: [DAEMON Tools] "C:\Program Files\DAEMON Tools\daemon.exe" -lang 1033 O4 - HKCU\..\Run: [Aim6] "C:\Program Files\AIM6\aim6.exe" /d locale=en-US ee://aol/imApp O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe O4 - HKCU\..\Run: [EasyLinkAdvisor] "C:\Program Files\Linksys EasyLink Advisor\LinksysAgent.exe" /startup O4 - S-1-5-18 Startup: OneNote 2007 Screen Clipper and Launcher.lnk = C:\Program Files\Microsoft Office\Office12\ONENOTEM.EXE (User 'SYSTEM') O4 - .DEFAULT Startup: OneNote 2007 Screen Clipper and Launcher.lnk = C:\Program Files\Microsoft Office\Office12\ONENOTEM.EXE (User 'Default user') O4 - Startup: OneNote 2007 Screen Clipper and Launcher.lnk = C:\Program Files\Microsoft Office\Office12\ONENOTEM.EXE O4 - Global Startup: AutoCAD Startup Accelerator.lnk = C:\Program Files\Common Files\Autodesk Shared\acstart16.exe O4 - Global Startup: Digital Line Detect.lnk = ? O4 - Global Startup: Post-it
  10. Nevermind I uninstalled it, I feel stupid And still working on the rest
  11. For my symantec file, it only contains the Live Update folder within it, I had uninstalled it long ago and when I tried to Uninstall it now it didnt work. Any suggestions? Thanks
  12. Hi, I'm new to this forum and I have been having trouble with accessing some sites. I followed the Pre-HJT post and and scanned everything. After scanning the MBAM, the sites previously not working have began to work again, I just wanted to post the logs to see what else I can do about the rest of the things found on Activescan. Here are the logs: From Active Scan ;******************************************************************************* ******************************************************************************** * ******************* ANALYSIS: 2008-07-04 17:44:03 PROTECTIONS: 1 MALWARE: 11 SUSPECTS: 1 ;******************************************************************************* ******************************************************************************** * ******************* PROTECTIONS Description Version Active Updated ;=============================================================================== ================================================================================ = =================== McAfee VirusScan Enterprise 8.5.0.781 No Yes ;=============================================================================== ================================================================================ = =================== MALWARE Id Description Type Active Severity Disinfectable Disinfected Location ;=============================================================================== ================================================================================ = =================== 00139064 Cookie/Atlas DMT TrackingCookie No 0 Yes No C:\Documents and Settings\AlexDong\Cookies\alexdong@atdmt[1].txt 00167642 Cookie/Com.com TrackingCookie No 0 Yes No C:\Documents and Settings\AlexDong\Cookies\alexdong@com[1].txt 00169190 Cookie/Advertising TrackingCookie No 0 Yes No C:\Documents and Settings\AlexDong\Cookies\alexdong@advertising[2].txt 00286738 Cookie/Cgi-bin TrackingCookie No 0 Yes No C:\Documents and Settings\AlexDong\Cookies\alexdong@www1.addfreestats[1].txt 02235691 Generic Malware Virus/Trojan No 0 Yes No C:\WINDOWS\Downloaded Program Files\HGStart9USA.exe 03184554 Generic Trojan Virus/Trojan No 0 Yes No C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP574\A0109733.dll 03194486 Trj/Monder.T Virus/Trojan No 0 Yes No C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP574\A0109735.dll 03194486 Trj/Monder.T Virus/Trojan No 0 Yes No C:\Documents and Settings\AlexDong\Local Settings\Temporary Internet Files\Content.IE5\0726U0JK\kb671231[1] 03194486 Trj/Monder.T Virus/Trojan No 0 Yes No C:\WINDOWS\system32\gvhbafkd.dll 03204797 Adware/IntCodec Adware No 0 Yes No C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP562\A0105129.dll 03204986 Spyware/Virtumonde Spyware No 1 Yes No C:\Documents and Settings\AlexDong\Local Settings\Temporary Internet Files\Content.IE5\SGQBO6ZZ\kb767887[1] 03204986 Spyware/Virtumonde Spyware No 1 Yes No C:\WINDOWS\system32\anxunexy.dll 03205080 Spyware/Virtumonde Spyware No 1 Yes No C:\WINDOWS\system32\bhgzzj.dll 03205080 Spyware/Virtumonde Spyware No 1 Yes No C:\WINDOWS\system32\tdocwm.dll 03205080 Spyware/Virtumonde Spyware No 1 Yes No C:\Documents and Settings\AlexDong\Local Settings\Temporary Internet Files\Content.IE5\P9L7GPGJ\kb767887[1] 03205080 Spyware/Virtumonde Spyware No 1 Yes No C:\WINDOWS\system32\pordxrjp.dll 03205080 Spyware/Virtumonde Spyware No 1 Yes No C:\WINDOWS\system32\sbcfiqoc.dll 03205136 Spyware/Virtumonde Spyware No 1 Yes No C:\Documents and Settings\AlexDong\Local Settings\Temporary Internet Files\Content.IE5\SGQBO6ZZ\kb456456[1] ;=============================================================================== ================================================================================ = =================== SUSPECTS Sent Location $ ;=============================================================================== ================================================================================ = =================== No C:\Documents and Settings\AlexDong\Local Settings\Temp\Div12D.tmp\DivXInstaller.exe[
Back to top
×
×
  • Create New...

Important Information

This site uses cookies - We have placed cookies on your device to help make this website better. You can adjust your cookie settings, otherwise we'll assume you're okay to continue.