[code] OTScanIt2 logfile created on: 19/12/2008 15:55:26 - Run 1 OTScanIt2 by OldTimer - Version 1.0.3.1 Folder = C:\Documents and Settings\user\Desktop\OTScanIt2 Windows XP Professional Edition Service Pack 2 (Version = 5.1.2600) - Type = NTWorkstation Internet Explorer (Version = 7.0.5730.13) Locale: 00000809 | Country: United Kingdom | Language: ENG | Date Format: dd/MM/yyyy 2.00 Gb Total Physical Memory | 1.21 Gb Available Physical Memory | 60.61% Memory free 3.35 Gb Paging File | 2.65 Gb Available in Paging File | 79.14% Paging File free Paging file location(s): C:\pagefile.sys 1536 3072; %SystemDrive% = C: | %SystemRoot% = C:\WINDOWS | %ProgramFiles% = C:\Program Files Drive C: | 149.05 Gb Total Space | 26.29 Gb Free Space | 17.64% Space Free | Partition Type: NTFS D: Drive not present or media not loaded Drive E: | 3.84 Mb Total Space | 0.00 Mb Free Space | 0.00% Space Free | Partition Type: CDFS F: Drive not present or media not loaded Drive G: | 971.51 Mb Total Space | 197.68 Mb Free Space | 20.35% Space Free | Partition Type: FAT32 H: Drive not present or media not loaded I: Drive not present or media not loaded Computer Name: AMD64 Current User Name: user Logged in as Administrator. Current Boot Mode: Normal Scan Mode: Current user Whitelist: On File Age = 30 Days [Processes - Safe List] aawservice.exe -> %ProgramFiles%\Lavasoft\Ad-Aware\aawservice.exe -> [2008/09/10 13:01:28 | 00,611,664 | ---- | M] (Lavasoft) anydvdtray.exe -> %ProgramFiles%\SlySoft\AnyDVD\AnyDVDtray.exe -> [2008/03/07 04:26:20 | 01,694,656 | ---- | M] (SlySoft, Inc.) avgamsvr.exe -> %ProgramFiles%\Grisoft\AVG Free\avgamsvr.exe -> [2007/10/27 12:04:30 | 00,418,816 | ---- | M] (GRISOFT, s.r.o.) avgcc.exe -> %ProgramFiles%\Grisoft\AVG Free\avgcc.exe -> [2008/10/16 18:31:23 | 00,590,848 | ---- | M] (GRISOFT, s.r.o.) avgemc.exe -> %ProgramFiles%\Grisoft\AVG Free\avgemc.exe -> [2008/01/12 10:21:56 | 00,406,528 | ---- | M] (GRISOFT, s.r.o.) avgupsvc.exe -> %ProgramFiles%\Grisoft\AVG Free\avgupsvc.exe -> [2007/09/01 13:34:13 | 00,049,664 | ---- | M] (GRISOFT, s.r.o.) cfp.exe -> %ProgramFiles%\COMODO\COMODO Internet Security\cfp.exe -> [2008/12/11 10:59:18 | 01,797,880 | ---- | M] () cmdagent.exe -> %ProgramFiles%\COMODO\COMODO Internet Security\cmdagent.exe -> [2008/12/11 10:59:20 | 00,618,232 | ---- | M] () cssurf.exe -> %ProgramFiles%\COMODO\SafeSurf\cssurf.exe -> [2008/12/11 11:00:16 | 00,278,264 | ---- | M] (COMODO) firefox.exe -> %ProgramFiles%\Mozilla Firefox\firefox.exe -> [2008/11/14 15:11:28 | 00,307,712 | ---- | M] (Mozilla Corporation) frameworkservice.exe -> %ProgramFiles%\Network Associates\Common Framework\FrameworkService.exe -> [2003/02/25 11:00:00 | 00,106,586 | ---- | M] (Network Associates, Inc.) gnotify.exe -> %ProgramFiles%\Google\Gmail Notifier\gnotify.exe -> [2005/07/15 21:48:33 | 00,479,232 | ---- | M] (Google Inc.) googletoolbarnotifier.exe -> %ProgramFiles%\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe -> [2007/09/01 12:14:09 | 00,068,856 | ---- | M] (Google Inc.) googleupdate.exe -> %UserProfile%\Local Settings\Application Data\Google\Update\GoogleUpdate.exe -> [2008/09/05 09:22:30 | 00,133,104 | ---- | M] (Google Inc.) idman.exe -> %ProgramFiles%\Internet Download Manager\IDMan.exe -> [2007/09/15 02:31:26 | 01,360,304 | ---- | M] (Tonec Inc.) ioctlsvc.exe -> %SystemRoot%\system32\IoctlSvc.exe -> [2006/12/19 09:30:26 | 00,081,920 | ---- | M] (Prolific Technology Inc.) ipodservice.exe -> %ProgramFiles%\iPod\bin\iPodService.exe -> [2008/11/20 13:20:44 | 00,536,872 | ---- | M] (Apple Inc.) ituneshelper.exe -> %ProgramFiles%\iTunes\iTunesHelper.exe -> [2008/11/20 13:20:54 | 00,290,088 | ---- | M] (Apple Inc.) jqs.exe -> %ProgramFiles%\Java\jre6\bin\jqs.exe -> [2008/10/26 18:18:13 | 00,147,456 | ---- | M] (Sun Microsystems, Inc.) jusched.exe -> %ProgramFiles%\Java\jre6\bin\jusched.exe -> [2008/10/26 18:18:23 | 00,144,792 | ---- | M] (Sun Microsystems, Inc.) mcshield.exe -> %ProgramFiles%\Network Associates\VirusScan\mcshield.exe -> [2003/03/06 07:00:00 | 00,233,595 | ---- | M] (Network Associates, Inc.) naprdmgr.exe -> %ProgramFiles%\Network Associates\Common Framework\naPrdMgr.exe -> [2003/02/25 11:00:00 | 00,127,058 | ---- | M] (Network Associates, Inc.) nbservice.exe -> %ProgramFiles%\Nero\Nero8\Nero BackItUp\NBService.exe -> [2008/02/18 16:29:12 | 00,877,864 | ---- | M] (Nero AG) nvsvc32.exe -> %SystemRoot%\system32\nvsvc32.exe -> [2005/10/10 21:49:00 | 00,131,139 | ---- | M] (NVIDIA Corporation) otscanit2.exe -> %UserProfile%\Desktop\OTScanIt2\OTScanIt2.exe -> [2008/12/12 09:24:20 | 00,477,184 | ---- | M] (OldTimer Tools) qttask.exe -> %ProgramFiles%\QuickTime\QTTask.exe -> [2008/09/06 15:09:14 | 00,413,696 | ---- | M] (Apple Inc.) ulcdrsvr.exe -> %CommonProgramFiles%\Ulead Systems\DVD\ULCDRSvr.exe -> [2003/11/12 04:48:20 | 00,049,152 | ---- | M] (Ulead Systems, Inc.) vstskmgr.exe -> %ProgramFiles%\Network Associates\VirusScan\vstskmgr.exe -> [2003/03/06 07:00:00 | 00,127,050 | ---- | M] (Network Associates, Inc.) winlogin.exe -> %UserProfile%\Local Settings\Temp\winlogin.exe -> [2008/12/05 16:39:53 | 00,015,000 | ---- | M] () wmpnetwk.exe -> %ProgramFiles%\Windows Media Player\wmpnetwk.exe -> [2006/10/18 19:05:24 | 00,913,408 | ---- | M] (Microsoft Corporation) wmpnscfg.exe -> %ProgramFiles%\Windows Media Player\wmpnscfg.exe -> [2006/10/18 19:05:26 | 00,204,288 | ---- | M] (Microsoft Corporation) wscntfy.exe -> %SystemRoot%\system32\wscntfy.exe -> [2004/08/04 00:56:58 | 00,013,824 | ---- | M] (Microsoft Corporation) wuauclt.exe -> %SystemRoot%\system32\wuauclt.exe -> [2008/10/16 14:09:44 | 00,051,224 | ---- | M] (Microsoft Corporation) [Win32 Services - Safe List] (aawservice) Lavasoft Ad-Aware Service [Win32_Own | Auto | Running] -> %ProgramFiles%\Lavasoft\Ad-Aware\aawservice.exe -> [2008/09/10 13:01:28 | 00,611,664 | ---- | M] (Lavasoft) (Adobe LM Service) Adobe LM Service [Win32_Own | On_Demand | Stopped] -> %CommonProgramFiles%\Adobe Systems Shared\Service\Adobelmsvc.exe -> [2007/09/12 12:16:39 | 00,072,704 | ---- | M] (Adobe Systems) (aspnet_state) ASP.NET State Service [Win32_Own | On_Demand | Stopped] -> %SystemRoot%\Microsoft.NET\Framework\v2.0.50727\aspnet_state.exe -> [2007/10/24 01:47:22 | 00,033,800 | ---- | M] (Microsoft Corporation) (Avg7Alrt) AVG7 Alert Manager Server [Win32_Own | Auto | Running] -> %ProgramFiles%\Grisoft\AVG Free\avgamsvr.exe -> [2007/10/27 12:04:30 | 00,418,816 | ---- | M] (GRISOFT, s.r.o.) (Avg7UpdSvc) AVG7 Update Service [Win32_Own | Auto | Running] -> %ProgramFiles%\Grisoft\AVG Free\avgupsvc.exe -> [2007/09/01 13:34:13 | 00,049,664 | ---- | M] (GRISOFT, s.r.o.) (AVGEMS) AVG E-mail Scanner [Win32_Own | Auto | Running] -> %ProgramFiles%\Grisoft\AVG Free\avgemc.exe -> [2008/01/12 10:21:56 | 00,406,528 | ---- | M] (GRISOFT, s.r.o.) (clr_optimization_v2.0.50727_32) .NET Runtime Optimization Service v2.0.50727_X86 [Win32_Own | On_Demand | Stopped] -> %SystemRoot%\Microsoft.NET\Framework\v2.0.50727\mscorsvw.exe -> [2007/10/24 01:47:40 | 00,070,144 | ---- | M] (Microsoft Corporation) (cmdAgent) COMODO Internet Security Helper Service [Win32_Own | Auto | Running] -> %ProgramFiles%\COMODO\COMODO Internet Security\cmdagent.exe -> [2008/12/11 10:59:20 | 00,618,232 | ---- | M] () (FontCache3.0.0.0) Windows Presentation Foundation Font Cache 3.0.0.0 [Win32_Own | On_Demand | Stopped] -> %SystemRoot%\Microsoft.NET\Framework\v3.0\WPF\PresentationFontCache.exe -> [2007/10/09 12:58:12 | 00,036,864 | ---- | M] (Microsoft Corporation) (gusvc) Google Updater Service [Win32_Own | On_Demand | Stopped] -> %ProgramFiles%\Google\Common\Google Updater\GoogleUpdaterService.exe -> [2007/09/01 11:57:57 | 00,138,168 | ---- | M] (Google) (helpsvc) Help and Support [Win32_Shared | Auto | Running] -> %SystemRoot%\pchealth\helpctr\binaries\pchsvc.dll -> [2004/08/04 00:56:46 | 00,038,912 | ---- | M] (Microsoft Corporation) (IDriverT) InstallDriver Table Manager [Win32_Own | On_Demand | Stopped] -> %CommonProgramFiles%\InstallShield\Driver\1150\Intel 32\IDriverT.exe -> [2005/11/14 00:06:04 | 00,069,632 | ---- | M] (Macrovision Corporation) (idsvc) Windows CardSpace [Win32_Shared | Unknown | Stopped] -> %SystemRoot%\Microsoft.NET\Framework\v3.0\Windows Communication Foundation\infocard.exe -> [2007/10/11 09:55:10 | 00,864,256 | ---- | M] (Microsoft Corporation) (iPod Service) iPod Service [Win32_Own | On_Demand | Running] -> %ProgramFiles%\iPod\bin\iPodService.exe -> [2008/11/20 13:20:44 | 00,536,872 | ---- | M] (Apple Inc.) (JavaQuickStarterService) Java Quick Starter [Win32_Own | Auto | Running] -> %ProgramFiles%\Java\jre6\bin\jqs.exe -> [2008/10/26 18:18:13 | 00,147,456 | ---- | M] (Sun Microsystems, Inc.) (KService) KService [Win32_Own | Auto | Stopped] -> %ProgramFiles%\Kontiki\KService.exe -> [2007/04/23 10:22:00 | 03,068,352 | ---- | M] (Kontiki Inc.) (McAfeeFramework) McAfee Framework Service [Win32_Own | Auto | Running] -> %ProgramFiles%\Network Associates\Common Framework\FrameworkService.exe -> [2003/02/25 11:00:00 | 00,106,586 | ---- | M] (Network Associates, Inc.) (McShield) Network Associates McShield [Win32_Own | Auto | Running] -> %ProgramFiles%\Network Associates\VirusScan\mcshield.exe -> [2003/03/06 07:00:00 | 00,233,595 | ---- | M] (Network Associates, Inc.) (McTaskManager) Network Associates Task Manager [Win32_Own | Auto | Running] -> %ProgramFiles%\Network Associates\VirusScan\vstskmgr.exe -> [2003/03/06 07:00:00 | 00,127,050 | ---- | M] (Network Associates, Inc.) (MSSQL$SONY_MEDIAMGR) MSSQL$SONY_MEDIAMGR [Win32_Own | On_Demand | Stopped] -> %ProgramFiles%\Sony\Shared Plug-Ins\Media Manager\MSSQL$SONY_MEDIAMGR\Binn\sqlservr.exe -> [2002/12/17 16:26:22 | 07,520,337 | ---- | M] (Microsoft Corporation) (MSSQLServerADHelper) MSSQLServerADHelper [Win32_Own | On_Demand | Stopped] -> %ProgramFiles%\Microsoft SQL Server\80\Tools\Binn\sqladhlp.exe -> [2002/12/17 16:23:30 | 00,066,112 | ---- | M] (Microsoft Corporation) (Nero BackItUp Scheduler 3) Nero BackItUp Scheduler 3 [Win32_Own | Auto | Running] -> %ProgramFiles%\Nero\Nero8\Nero BackItUp\NBService.exe -> [2008/02/18 16:29:12 | 00,877,864 | ---- | M] (Nero AG) (NetTcpPortSharing) Net.Tcp Port Sharing Service [Win32_Shared | Disabled | Stopped] -> %SystemRoot%\Microsoft.NET\Framework\v3.0\Windows Communication Foundation\SMSvcHost.exe -> [2007/10/11 09:55:14 | 00,122,880 | ---- | M] (Microsoft Corporation) (NMIndexingService) NMIndexingService [Win32_Own | On_Demand | Stopped] -> %CommonProgramFiles%\Nero\Lib\NMIndexingService.exe -> [2008/02/28 17:07:48 | 00,529,704 | ---- | M] (Nero AG) (NVSvc) NVIDIA Display Driver Service [Win32_Own | Auto | Running] -> %SystemRoot%\system32\nvsvc32.exe -> [2005/10/10 21:49:00 | 00,131,139 | ---- | M] (NVIDIA Corporation) (PLFlash DeviceIoControl Service) PLFlash DeviceIoControl Service [Win32_Own | Auto | Running] -> %SystemRoot%\system32\IoctlSvc.exe -> [2006/12/19 09:30:26 | 00,081,920 | ---- | M] (Prolific Technology Inc.) (SQLAgent$SONY_MEDIAMGR) SQLAgent$SONY_MEDIAMGR [Win32_Own | On_Demand | Stopped] -> %ProgramFiles%\Sony\Shared Plug-Ins\Media Manager\MSSQL$SONY_MEDIAMGR\Binn\sqlagent.EXE -> [2002/12/17 16:23:30 | 00,311,872 | ---- | M] (Microsoft Corporation) (TVersityMediaServer) TVersityMediaServer [Win32_Own | On_Demand | Stopped] -> %ProgramFiles%\TVersity\Media Server\MediaServer.exe -> [2008/07/22 16:59:42 | 00,794,624 | ---- | M] () (UleadBurningHelper) Ulead Burning Helper [Win32_Own | Auto | Running] -> %CommonProgramFiles%\Ulead Systems\DVD\ULCDRSvr.exe -> [2003/11/12 04:48:20 | 00,049,152 | ---- | M] (Ulead Systems, Inc.) (WMPNetworkSvc) Windows Media Player Network Sharing Service [Win32_Own | Auto | Running] -> %ProgramFiles%\Windows Media Player\wmpnetwk.exe -> [2006/10/18 19:05:24 | 00,913,408 | ---- | M] (Microsoft Corporation) (WudfSvc) Windows Driver Foundation - User-mode Driver Framework [Win32_Shared | Auto | Running] -> %SystemRoot%\system32\WudfSvc.dll -> [2006/09/28 17:56:14 | 00,055,808 | ---- | M] (Microsoft Corporation) [Driver Services - Safe List] (Ad-Watch Connect Filter) Ad-Watch Connect Kernel Filter [Kernel | On_Demand | Stopped] -> %SystemRoot%\system32\drivers\NSDriver.sys -> [2008/04/29 10:20:00 | 00,015,648 | ---- | M] (Lavasoft AB) (ALCXWDM) Service for Realtek AC97 Audio (WDM) [Kernel | On_Demand | Stopped] -> %SystemRoot%\system32\drivers\ALCXWDM.SYS -> [2004/11/17 11:05:38 | 02,297,664 | R--- | M] (Realtek Semiconductor Corp.) (AmdK8) AMD Processor Driver [Kernel | System | Running] -> %SystemRoot%\system32\drivers\AmdK8.sys -> [2005/03/09 15:53:00 | 00,036,352 | ---- | M] (Advanced Micro Devices) (AnyDVD) AnyDVD [Kernel | On_Demand | Running] -> %SystemRoot%\system32\drivers\AnyDVD.sys -> [2008/03/07 13:24:27 | 00,097,216 | ---- | M] (SlySoft, Inc.) (ASPI32) ASPI32 [Kernel | Auto | Running] -> %SystemRoot%\system32\drivers\aspi32.sys -> [2005/11/21 05:48:21 | 00,016,512 | ---- | M] (Adaptec) (Avg7Core) AVG7 Kernel [Kernel | System | Running] -> %SystemRoot%\system32\drivers\avg7core.sys -> [2007/10/27 12:04:27 | 00,821,856 | ---- | M] (GRISOFT, s.r.o.) (Avg7RsW) AVG7 Wrap Driver [Kernel | System | Running] -> %SystemRoot%\system32\drivers\avg7rsw.sys -> [2007/09/01 13:34:22 | 00,004,224 | ---- | M] (GRISOFT, s.r.o.) (Avg7RsXP) AVG7 Resident Driver XP [Kernel | System | Running] -> %SystemRoot%\system32\drivers\avg7rsxp.sys -> [2007/09/01 13:34:22 | 00,027,776 | ---- | M] (GRISOFT, s.r.o.) (AvgClean) AVG Clean Driver [Kernel | System | Running] -> %SystemRoot%\system32\drivers\avgclean.sys -> [2008/01/12 10:21:57 | 00,010,760 | ---- | M] (GRISOFT, s.r.o.) (AvgTdi) AVG Network Redirector [Kernel | Auto | Running] -> %SystemRoot%\system32\drivers\avgtdi.sys -> [2007/09/01 13:34:15 | 00,004,960 | ---- | M] (GRISOFT, s.r.o.) (BANTExt) Belarc SMBios Access [Kernel | System | Running] -> %SystemRoot%\system32\drivers\BANTExt.sys -> [2008/02/27 12:49:00 | 00,003,840 | ---- | M] () (cmdGuard) COMODO Internet Security Sandbox Driver [File_System | System | Running] -> %SystemRoot%\system32\drivers\cmdguard.sys -> [2008/12/11 10:59:21 | 00,101,776 | ---- | M] (COMODO) (cmdHlp) COMODO Internet Security Helper Driver [Kernel | System | Running] -> %SystemRoot%\system32\drivers\cmdhlp.sys -> [2008/12/11 10:59:21 | 00,031,504 | ---- | M] (COMODO) (DSDrv4) DSDrv4 [Kernel | On_Demand | Stopped] -> %ProgramFiles%\DScaler\DSDrv4.sys -> [2005/12/18 19:42:12 | 00,008,801 | ---- | M] () (ElbyCDIO) ElbyCDIO Driver [Kernel | System | Running] -> %SystemRoot%\system32\drivers\ElbyCDIO.sys -> [2007/08/07 19:48:33 | 00,025,160 | ---- | M] (Elaborate Bytes AG) (ElbyDelay) ElbyDelay [Kernel | On_Demand | Running] -> %SystemRoot%\system32\drivers\ElbyDelay.sys -> [2007/02/16 00:56:49 | 00,011,984 | ---- | M] (Elaborate Bytes AG) (gameenum) Game Port Enumerator [Kernel | On_Demand | Stopped] -> %SystemRoot%\system32\drivers\gameenum.sys -> [2004/08/03 23:08:22 | 00,010,624 | ---- | M] (Microsoft Corporation) (GEARAspiWDM) GEAR ASPI Filter Driver [Kernel | On_Demand | Running] -> %SystemRoot%\system32\drivers\GEARAspiWDM.sys -> [2008/04/17 13:12:54 | 00,015,464 | ---- | M] (GEAR Software Inc.) (ggflt) SEMC USB Flash Driver Filter [Kernel | On_Demand | Stopped] -> %SystemRoot%\system32\drivers\ggflt.sys -> [2008/02/07 17:29:10 | 00,013,352 | ---- | M] (Sony Ericsson Mobile Communications) (ggsemc) SEMC USB Flash Driver [Kernel | On_Demand | Stopped] -> %SystemRoot%\system32\drivers\ggsemc.sys -> [2008/02/07 17:29:10 | 00,020,520 | ---- | M] (Sony Ericsson Mobile Communications) (HDAudBus) Microsoft UAA Bus Driver for High Definition Audio [Kernel | On_Demand | Running] -> %SystemRoot%\system32\drivers\Hdaudbus.sys -> [2005/01/07 17:07:18 | 00,138,752 | ---- | M] (Windows (R) Server 2003 DDK provider) (Inspect) COMODO Internet Security Firewall Driver [Kernel | Boot | Running] -> %SystemRoot%\system32\drivers\inspect.sys -> [2008/12/11 10:59:21 | 00,079,504 | ---- | M] (COMODO) (IntcAzAudAddService) Service for Realtek HD Audio (WDM) [Kernel | On_Demand | Running] -> %SystemRoot%\system32\drivers\RtkHDAud.sys -> [2007/07/10 01:56:00 | 04,449,280 | R--- | M] (Realtek Semiconductor Corp.) (k750bus) Sony Ericsson 750 driver (WDM) [Kernel | On_Demand | Stopped] -> %SystemRoot%\system32\drivers\k750bus.sys -> [2005/02/11 10:19:20 | 00,055,216 | ---- | M] (MCCI) (kbdhid) Keyboard HID Driver [Kernel | System | Running] -> %SystemRoot%\system32\drivers\kbdhid.sys -> [2004/08/03 21:58:36 | 00,014,848 | ---- | M] (Microsoft Corporation) (ms_mpu401) Microsoft MPU-401 MIDI UART Driver [Kernel | On_Demand | Stopped] -> %SystemRoot%\system32\drivers\msmpu401.sys -> [2001/08/17 14:00:04 | 00,002,944 | ---- | M] (Microsoft Corporation) (MTsensor) ATK0110 ACPI UTILITY [Kernel | On_Demand | Stopped] -> %SystemRoot%\system32\drivers\ASACPI.sys -> [2004/08/13 02:56:20 | 00,005,810 | R--- | M] () (NaiAvFilter1) NaiAvFilter1 [File_System | On_Demand | Running] -> %SystemRoot%\system32\drivers\naiavf5x.sys -> [2003/03/06 07:00:00 | 00,084,448 | ---- | M] (Network Associates, Inc.) (nv) nv [Kernel | On_Demand | Running] -> %SystemRoot%\system32\drivers\nv4_mini.sys -> [2005/10/10 21:49:00 | 03,530,432 | ---- | M] (NVIDIA Corporation) (nvata) nvata [Kernel | Boot | Running] -> %SystemRoot%\system32\drivers\nvata.sys -> [2006/06/28 09:38:56 | 00,105,088 | R--- | M] (NVIDIA Corporation) (nvax) Service for NVIDIA(R) nForce(TM) Audio Enumerator [Kernel | On_Demand | Stopped] -> %SystemRoot%\system32\drivers\nvax.sys -> [2005/04/13 12:32:42 | 00,053,376 | ---- | M] (NVIDIA Corporation) (NVENETFD) NVIDIA nForce Networking Controller Driver [Kernel | On_Demand | Running] -> %SystemRoot%\system32\drivers\NVENETFD.sys -> [2006/11/27 08:33:50 | 00,058,368 | R--- | M] (NVIDIA Corporation) (nvnetbus) NVIDIA Network Bus Enumerator [Kernel | On_Demand | Running] -> %SystemRoot%\system32\drivers\nvnetbus.sys -> [2006/11/27 08:33:54 | 00,019,968 | R--- | M] (NVIDIA Corporation) (nvnforce) Service for NVIDIA(R) nForce(TM) Audio [Kernel | On_Demand | Stopped] -> %SystemRoot%\system32\drivers\nvapu.sys -> [2005/04/13 12:34:02 | 00,414,464 | ---- | M] (NVIDIA Corporation) (pgfilter) pgfilter [Kernel | On_Demand | Stopped] -> %ProgramFiles%\PeerGuardian2\pgfilter.sys -> [2005/09/18 17:02:52 | 00,005,632 | ---- | M] () (Ptilink) Direct Parallel Link Driver [Kernel | On_Demand | Running] -> %SystemRoot%\system32\drivers\ptilink.sys -> [2001/08/23 12:00:00 | 00,017,792 | ---- | M] (Parallel Technologies, Inc.) (PxHelp20) PxHelp20 [Kernel | Boot | Running] -> %SystemRoot%\system32\drivers\pxhelp20.sys -> [2007/03/29 02:00:00 | 00,043,528 | ---- | M] (Sonic Solutions) (s117bus) Sony Ericsson Device 117 driver (WDM) [Kernel | On_Demand | Stopped] -> %SystemRoot%\system32\drivers\s117bus.sys -> [2007/06/25 09:43:22 | 00,082,984 | ---- | M] (MCCI Corporation) (s117mdfl) Sony Ericsson Device 117 USB WMC Modem Filter [Kernel | On_Demand | Stopped] -> %SystemRoot%\system32\drivers\s117mdfl.sys -> [2007/06/25 09:43:26 | 00,014,888 | ---- | M] (MCCI Corporation) (s117mdm) Sony Ericsson Device 117 USB WMC Modem Driver [Kernel | On_Demand | Stopped] -> %SystemRoot%\system32\drivers\s117mdm.sys -> [2007/06/25 09:43:36 | 00,108,456 | ---- | M] (MCCI Corporation) (s117mgmt) Sony Ericsson Device 117 USB WMC Device Management Drivers (WDM) [Kernel | On_Demand | Stopped] -> %SystemRoot%\system32\drivers\s117mgmt.sys -> [2007/06/25 09:43:36 | 00,100,264 | ---- | M] (MCCI Corporation) (s117nd5) Sony Ericsson Device 117 USB Ethernet Emulation SEMC117 (NDIS) [Kernel | On_Demand | Stopped] -> %SystemRoot%\system32\drivers\s117nd5.sys -> [2007/06/25 09:43:36 | 00,022,952 | ---- | M] (MCCI Corporation) (s117obex) Sony Ericsson Device 117 USB WMC OBEX Interface [Kernel | On_Demand | Stopped] -> %SystemRoot%\system32\drivers\s117obex.sys -> [2007/06/25 09:43:38 | 00,098,344 | ---- | M] (MCCI Corporation) (s117unic) Sony Ericsson Device 117 USB Ethernet Emulation SEMC117 (WDM) [Kernel | On_Demand | Stopped] -> %SystemRoot%\system32\drivers\s117unic.sys -> [2007/06/25 09:43:36 | 00,098,856 | ---- | M] (MCCI Corporation) (Secdrv) Secdrv [Kernel | On_Demand | Stopped] -> %SystemRoot%\system32\drivers\secdrv.sys -> [2007/11/13 10:25:53 | 00,020,480 | ---- | M] (Macrovision Corporation, Macrovision Europe Limited, and Macrovision Japan and Asia K.K.) (sfdrv01) StarForce Protection Environment Driver (version 1.x) [Kernel | Boot | Running] -> %SystemRoot%\system32\drivers\sfdrv01.sys -> [2005/03/03 17:53:57 | 00,048,640 | ---- | M] (Protection Technology) (sfhlp02) StarForce Protection Helper Driver (version 2.x) [Kernel | Boot | Running] -> %SystemRoot%\system32\drivers\sfhlp02.sys -> [2005/02/23 15:59:54 | 00,006,656 | ---- | M] (Protection Technology) (sfsync02) StarForce Protection Synchronization Driver (version 2.x) [Kernel | Boot | Running] -> %SystemRoot%\system32\drivers\sfsync02.sys -> [2004/12/03 10:20:41 | 00,020,544 | ---- | M] (Protection Technology) (sptd) sptd [Kernel | Boot | Running] -> %SystemRoot%\system32\drivers\sptd.sys -> [2008/02/04 20:19:23 | 00,715,248 | ---- | M] () (wanatw) WAN Miniport (ATW) [Kernel | On_Demand | Running] -> %SystemRoot%\system32\drivers\wanatw4.sys -> [2003/01/10 21:13:04 | 00,033,588 | ---- | M] (America Online, Inc.) (Wdf01000) Wdf01000 [Kernel | On_Demand | Running] -> %SystemRoot%\system32\drivers\wdf01000.sys -> [2006/11/02 07:22:54 | 00,492,000 | ---- | M] (Microsoft Corporation) (WF23880) WinFast TV2000/DV2000 WDM Video Capture. [Kernel | Auto | Running] -> %SystemRoot%\system32\drivers\wf88vcap.sys -> [2004/11/22 04:34:56 | 00,208,851 | R--- | M] (Copyright @2000-2006 Leadtek Research Inc.) (WF88XBAR) WinFast TV2000/DV2000 WDM Crossbar. [Kernel | Auto | Running] -> %SystemRoot%\system32\drivers\WF88XBAR.sys -> [2004/11/22 04:34:56 | 00,010,324 | R--- | M] (Copyright @2000-2006 Leadtek Research Inc.) (WFIOCTL) WFIOCTL [Kernel | On_Demand | Stopped] -> %ProgramFiles%\WinFast\WFTVFM\WFIOCTL.sys -> [2003/09/10 09:53:08 | 00,009,510 | ---- | M] (Leadtek Research Inc.) (WFTUNE) WinFast TV2000/DV2000 WDM Tuner. [Kernel | Auto | Running] -> %SystemRoot%\system32\drivers\wf88tune.sys -> [2004/11/22 04:34:56 | 00,034,789 | R--- | M] (Copyright @2000-2006 Leadtek Research Inc.) (zumbus) Zune Bus Enumerator Driver [Kernel | Auto | Running] -> %SystemRoot%\system32\drivers\zumbus.sys -> [2008/01/11 16:39:34 | 00,040,832 | ---- | M] (Microsoft Corporation) [Registry - Safe List] < Internet Explorer Settings [HKEY_LOCAL_MACHINE\] > -> -> HKEY_LOCAL_MACHINE\: Main\\"Default_Page_URL" -> http://go.microsoft.com/fwlink/?LinkId=69157 -> HKEY_LOCAL_MACHINE\: Main\\"Default_Search_URL" -> http://go.microsoft.com/fwlink/?LinkId=54896 -> HKEY_LOCAL_MACHINE\: Main\\"Default_Secondary_Page_URL" -> -> HKEY_LOCAL_MACHINE\: Main\\"Extensions Off Page" -> about:NoAdd-ons -> HKEY_LOCAL_MACHINE\: Main\\"Local Page" -> %SystemRoot%\system32\blank.htm -> HKEY_LOCAL_MACHINE\: Main\\"Search Page" -> http://go.microsoft.com/fwlink/?LinkId=54896 -> HKEY_LOCAL_MACHINE\: Main\\"Security Risk Page" -> about:SecurityRisk -> HKEY_LOCAL_MACHINE\: Main\\"Start Page" -> http://go.microsoft.com/fwlink/?LinkId=69157 -> HKEY_LOCAL_MACHINE\: Search\\"CustomizeSearch" -> http://ie.search.msn.com/{SUB_RFC1766}/srchasst/srchcust.htm -> HKEY_LOCAL_MACHINE\: Search\\"Default_Search_URL" -> http://www.google.com/ie -> HKEY_LOCAL_MACHINE\: Search\\"SearchAssistant" -> http://www.google.com/ie -> < Internet Explorer Settings [HKEY_CURRENT_USER\] > -> -> HKEY_CURRENT_USER\: Main\\"Local Page" -> C:\WINDOWS\system32\blank.htm -> HKEY_CURRENT_USER\: Main\\"Search Page" -> http://www.google.com -> HKEY_CURRENT_USER\: Main\\"SearchMigratedDefaultName" -> Google -> HKEY_CURRENT_USER\: Main\\"SearchMigratedDefaultURL" -> http://www.google.com/search?q={searchTerms}&sourceid=ie7&rls=com.microsoft:en-US&ie=utf8&oe=utf8 -> HKEY_CURRENT_USER\: Main\\"Start Page" -> http://www.ask-yoda.com/ -> HKEY_CURRENT_USER\: Search\\"SearchAssistant" -> http://www.google.com/ie -> HKEY_CURRENT_USER\: SearchURL\\"" -> http://search.aol.co.uk/web?isinit=true&query=%s -> HKEY_CURRENT_USER\: URLSearchHooks\\"{EF99BD32-C1FB-11D2-892F-0090271D4F88}" [HKLM] -> Reg Error: Key does not exist or could not be opened. [Yahoo! Toolbar] -> File not found HKEY_CURRENT_USER\: "ProxyEnable" -> 0 -> < FireFox Settings [Default Profile] > -> C:\Documents and Settings\user\Application Data\Mozilla\FireFox\Profiles\gmbvlz4g.default\prefs.js -> browser.startup.homepage -> "www.google.co.uk/ig" -> browser.startup.homepage_override.mstone -> "rv:1.9.0.4" -> extensions.enabledItems -> bettergmail2@ginatrapani.org:0.7.1 -> extensions.enabledItems -> en-GB@dictionaries.addons.mozilla.org:1.19 -> extensions.enabledItems -> {b9db16a4-6edc-47ec-a1f4-b86292ed211d}:3.4 -> extensions.enabledItems -> max@subfighter.com:1.0.2 -> extensions.enabledItems -> {19503e42-ca3c-4c27-b1e2-9cdb2170ee34}:1.1.4 -> extensions.enabledItems -> {B9C8BE50-7105-4ec6-8FB4-4935C0671648}:0.5.97 -> extensions.enabledItems -> mozilla_cc@internetdownloadmanager.com:4.0 -> extensions.enabledItems -> jqs@sun.com:1.0 -> extensions.enabledItems -> {ada4b710-8346-4b82-8199-5de2b400a6ae}:1.8 -> extensions.enabledItems -> undoclosedtabsbutton@supernova00.biz:3.0.3 -> extensions.enabledItems -> {89f8dde0-010a-11da-8cd6-0800200c9a66}:1.0.0.15 -> extensions.enabledItems -> {E9A1DEE0-C623-4439-8932-001E7D17607D}:2.1.0.3 -> extensions.enabledItems -> {972ce4c6-7e08-4474-a285-3208198ce6fd}:3.0.4 -> extensions.enabledItems -> {07b2a769-ed19-4483-87ce-c643914c81bb}:2.0.0.46 -> < HOSTS File > (824 bytes and 22 lines) -> C:\WINDOWS\System32\drivers\etc\Hosts -> 127.0.0.1 localhost < BHO's [HKEY_LOCAL_MACHINE] > -> HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\ -> {C5BF49A2-94F3-42BD-F434-3604812C897D} [HKLM] -> %SystemRoot%\system32\jsdf8j3dgf.dll [C:\WINDOWS\system32\jsdf8j3dgf.dll] -> [2008/12/05 16:39:53 | 00,015,000 | ---- | M] () < Internet Explorer ToolBars [HKEY_LOCAL_MACHINE] > -> HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\ToolBar -> "{2318C2B1-4965-11d4-9B18-009027A5CD4F}" [HKLM] -> %ProgramFiles%\Google\GoogleToolbar2.dll [&Google] -> [2007/01/19 22:55:32 | 02,403,392 | R--- | M] (Google Inc.) "{3041d03e-fd4b-44e0-b742-2d9b88305f98}" [HKLM] -> %ProgramFiles%\AskBarDis\bar\bin\askBar.dll [Ask Toolbar] -> [2008/08/06 15:20:04 | 00,279,944 | ---- | M] (Ask.com) "{759BF46C-E39F-402A-906A-D4367B45C070}" [HKLM] -> %SystemRoot%\system32\winpm77.dll [Mirar] -> [2008/11/21 20:15:46 | 00,401,408 | ---- | M] () "{A057A204-BACC-4D26-B2F2-48F8CCAB3ED4}" [HKLM] -> %ProgramFiles%\prodegetoolbar660\prodegetoolbar660.dll [WWE Toolbar] -> [2008/06/16 14:58:02 | 01,964,544 | ---- | M] ([[[COMPANYNAME]]]----------------------------) "{D0943516-5076-4020-A3B5-AEFAF26AB263}" [HKLM] -> %ProgramFiles%\Veoh Networks\Veoh\Plugins\reg\VeohToolbar.dll [Veoh Browser Plug-in] -> [2008/05/15 14:59:54 | 00,352,256 | ---- | M] (Veoh Networks Inc) "{D2D11E4C-5E0B-4830-80F3-78B143801A91}" [HKLM] -> %SystemRoot%\system32\windi77.dll [Mirar] -> [2008/11/21 20:15:46 | 00,401,408 | ---- | M] () < Internet Explorer ToolBars [HKEY_CURRENT_USER\] > -> HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Toolbar\ -> WebBrowser\\"{2318C2B1-4965-11D4-9B18-009027A5CD4F}" [HKLM] -> %ProgramFiles%\Google\GoogleToolbar2.dll [&Google] -> [2007/01/19 22:55:32 | 02,403,392 | R--- | M] (Google Inc.) WebBrowser\\"{4982D40A-C53B-4615-B15B-B5B5E98D167C}" [HKLM] -> Reg Error: Key does not exist or could not be opened. [Reg Error: Key does not exist or could not be opened.] -> File not found WebBrowser\\"{759BF46C-E39F-402A-906A-D4367B45C070}" [HKLM] -> %SystemRoot%\system32\winpm77.dll [Mirar] -> [2008/11/21 20:15:46 | 00,401,408 | ---- | M] () WebBrowser\\"{A057A204-BACC-4D26-B2F2-48F8CCAB3ED4}" [HKLM] -> %ProgramFiles%\prodegetoolbar660\prodegetoolbar660.dll [WWE Toolbar] -> [2008/06/16 14:58:02 | 01,964,544 | ---- | M] ([[[COMPANYNAME]]]----------------------------) WebBrowser\\"{D2D11E4C-5E0B-4830-80F3-78B143801A91}" [HKLM] -> %SystemRoot%\system32\windi77.dll [Mirar] -> [2008/11/21 20:15:46 | 00,401,408 | ---- | M] () < Run [HKEY_LOCAL_MACHINE\] > -> HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run -> "{0228e555-4f9c-4e35-a3ec-b109a192b4c2}" -> %ProgramFiles%\Google\Gmail Notifier\gnotify.exe [C:\Program Files\Google\Gmail Notifier\gnotify.exe] -> [2005/07/15 21:48:33 | 00,479,232 | ---- | M] (Google Inc.) "AVG7_CC" -> [C:\PROGRA~1\Grisoft\AVGFRE~1\avgcc.exe /STARTUP] -> File not found "COMODO Internet Security" -> %ProgramFiles%\COMODO\COMODO Internet Security\cfp.exe ["C:\Program Files\COMODO\COMODO Internet Security\cfp.exe" -h] -> [2008/12/11 10:59:18 | 01,797,880 | ---- | M] () "COMODO SafeSurf" -> %ProgramFiles%\COMODO\SafeSurf\cssurf.exe ["C:\Program Files\COMODO\SafeSurf\cssurf.exe" -s] -> [2008/12/11 11:00:16 | 00,278,264 | ---- | M] (COMODO) "iTunesHelper" -> %ProgramFiles%\iTunes\iTunesHelper.exe ["C:\Program Files\iTunes\iTunesHelper.exe"] -> [2008/11/20 13:20:54 | 00,290,088 | ---- | M] (Apple Inc.) "kdx" -> %ProgramFiles%\Kontiki\KHost.exe ["C:\Program Files\Kontiki\KHost.exe" -all] -> [2007/04/23 10:23:00 | 01,032,640 | ---- | M] (Kontiki Inc.) "NI.GSCNS" -> %SystemDrive%\DOCUME~1\user\LOCALS~1\Temp\winvsnet.tmp ["C:\DOCUME~1\user\LOCALS~1\Temp\winvsnet.tmp"] -> File not found "NvCplDaemon" -> %SystemRoot%\system32\nvcpl.dll [RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup] -> [2005/10/10 21:49:00 | 07,286,784 | ---- | M] (NVIDIA Corporation) "NvMediaCenter" -> %SystemRoot%\system32\nvmctray.dll [RUNDLL32.EXE C:\WINDOWS\system32\NvMcTray.dll,NvTaskbarInit] -> [2005/10/10 21:49:00 | 00,086,016 | ---- | M] (NVIDIA Corporation) "NVMixerTray" -> %ProgramFiles%\NVIDIA Corporation\NvMixer\NvMixerTray.exe ["C:\Program Files\NVIDIA Corporation\NvMixer\NVMixerTray.exe"] -> [2004/12/20 17:12:36 | 00,131,072 | ---- | M] (NVIDIA Corporation) "prunnet" -> %SystemRoot%\system32\prunnet.exe ["C:\WINDOWS\system32\prunnet.exe"] -> File not found "QuickTime Task" -> %ProgramFiles%\QuickTime\QTTask.exe ["C:\Program Files\QuickTime\QTTask.exe" -atboottime] -> [2008/09/06 15:09:14 | 00,413,696 | ---- | M] (Apple Inc.) "SunJavaUpdateSched" -> %ProgramFiles%\Java\jre6\bin\jusched.exe ["C:\Program Files\Java\jre6\bin\jusched.exe"] -> [2008/10/26 18:18:23 | 00,144,792 | ---- | M] (Sun Microsystems, Inc.) "ugkhnqocbiql" -> %SystemRoot%\system32\ssjqssuucuthmxpyh.dll [C:\WINDOWS\System32\regsvr32.exe /s "C:\WINDOWS\system32\ssjqssuucuthmxpyh.dll"] -> File not found "xsjfn83jkemfofght" -> %UserProfile%\Local Settings\Temp\winlogin.exe [C:\DOCUME~1\user\LOCALS~1\Temp\winlogin.exe] -> [2008/12/05 16:39:53 | 00,015,000 | ---- | M] () < RunOnceEx [HKEY_LOCAL_MACHINE\] > -> HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\RunOnceEx -> "Flag" -> [] -> File not found < Run [HKEY_CURRENT_USER\] > -> HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run -> "AnyDVD" -> %ProgramFiles%\SlySoft\AnyDVD\AnyDVDtray.exe [C:\Program Files\SlySoft\AnyDVD\AnyDVDtray.exe] -> [2008/03/07 04:26:20 | 01,694,656 | ---- | M] (SlySoft, Inc.) "gadcom" -> %AppData%\gadcom\gadcom.exe ["C:\Documents and Settings\user\Application Data\gadcom\gadcom.exe" 61A847B5BBF728173599284503996897C881250221C8670836AC4FA7C8833201749139] -> File not found "Google Update" -> %UserProfile%\Local Settings\Application Data\Google\Update\GoogleUpdate.exe ["C:\Documents and Settings\user\Local Settings\Application Data\Google\Update\GoogleUpdate.exe" /c] -> [2008/09/05 09:22:30 | 00,133,104 | ---- | M] (Google Inc.) "Jnskdfmf9eldfd" -> %SystemDrive%\DOCUME~1\user\LOCALS~1\Temp\csrssc.exe [C:\DOCUME~1\user\LOCALS~1\Temp\csrssc.exe] -> File not found "kdx" -> %ProgramFiles%\Kontiki\KHost.exe [C:\Program Files\Kontiki\KHost.exe -all] -> [2007/04/23 10:23:00 | 01,032,640 | ---- | M] (Kontiki Inc.) "prunnet" -> %SystemRoot%\system32\prunnet.exe ["C:\WINDOWS\system32\prunnet.exe"] -> File not found "swg" -> %ProgramFiles%\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe [C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe] -> [2007/09/01 12:14:09 | 00,068,856 | ---- | M] (Google Inc.) "WMPNSCFG" -> %ProgramFiles%\Windows Media Player\wmpnscfg.exe [C:\Program Files\Windows Media Player\WMPNSCFG.exe] -> [2006/10/18 19:05:26 | 00,204,288 | ---- | M] (Microsoft Corporation) "xsjfn83jkemfofght" -> %UserProfile%\Local Settings\Temp\winlogin.exe [C:\DOCUME~1\user\LOCALS~1\Temp\winlogin.exe] -> [2008/12/05 16:39:53 | 00,015,000 | ---- | M] () < All Users Startup Folder > -> C:\Documents and Settings\All Users\Start Menu\Programs\Startup -> < user Startup Folder > -> C:\Documents and Settings\user\Start Menu\Programs\Startup -> %UserProfile%\Start Menu\Programs\Startup\csti.lnk -> %SystemRoot%\system32\setup.exe -> [2004/08/04 00:56:58 | 00,023,040 | ---- | M] (Microsoft Corporation) < Software Policy Settings [HKEY_LOCAL_MACHINE] > -> HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Internet Explorer -> HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Internet Explorer\Infodelivery\Restrictions \Infodelivery\Restrictions\\"NoUpdateCheck" -> [1] -> File not found < CurrentVersion Policy Settings - Explorer [HKEY_LOCAL_MACHINE] > -> HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer -> HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer \\"LinkResolveIgnoreLinkInfo" -> [0] -> File not found \\"NoResolveSearch" -> [1] -> File not found < CurrentVersion Policy Settings - System [HKEY_LOCAL_MACHINE] > -> HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System -> HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System \\"dontdisplaylastusername" -> [0] -> File not found \\"legalnoticecaption" -> [] -> File not found \\"legalnoticetext" -> [] -> File not found \\"shutdownwithoutlogon" -> [1] -> File not found \\"undockwithoutlogon" -> [1] -> File not found < CurrentVersion Policy Settings - Explorer [HKEY_CURRENT_USER] > -> HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer -> HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer \\"NoDriveTypeAutoRun" -> [145] -> File not found \\"LinkResolveIgnoreLinkInfo" -> [0] -> File not found \\"NoFolderOptions" -> [1] -> File not found < CurrentVersion Policy Settings - System [HKEY_CURRENT_USER] > -> HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System -> HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System \\"DisableRegistryTools" -> [1] -> File not found < Internet Explorer Menu Extensions [HKEY_CURRENT_USER\] > -> HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\MenuExt\ -> &AOL Toolbar search -> %ProgramFiles%\AOL Toolbar\toolbar.dll [res://C:\Program Files\AOL Toolbar\toolbar.dll/SEARCH.HTML] -> File not found Download All Links with IDM -> %ProgramFiles%\Internet Download Manager\IEGetAll.htm [C:\Program Files\Internet Download Manager\IEGetAll.htm] -> [2003/10/20 10:13:13 | 00,000,283 | ---- | M] () Download FLV video content with IDM -> %ProgramFiles%\Internet Download Manager\IEGetVL.htm [C:\Program Files\Internet Download Manager\IEGetVL.htm] -> [2007/07/02 06:19:10 | 00,000,278 | ---- | M] () Download with IDM -> %ProgramFiles%\Internet Download Manager\IEExt.htm [C:\Program Files\Internet Download Manager\IEExt.htm] -> [2004/12/02 16:31:09 | 00,000,277 | ---- | M] () E&xport to Microsoft Excel -> %ProgramFiles%\Microsoft Office\Office10\EXCEL.EXE [res://C:\PROGRA~1\MICROS~3\Office10\EXCEL.EXE/3000] -> [2003/12/03 17:04:40 | 09,189,896 | R--- | M] (Microsoft Corporation) < Internet Explorer Extensions [HKEY_LOCAL_MACHINE] > -> HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Extensions\ -> {e2e2dd38-d088-4134-82b7-f2ba38496583}:Exec [HKLM] -> %SystemRoot%\network diagnostic\xpnetdiag.exe [Menu: @xpsp3res.dll,-20001] -> [2006/10/10 12:44:50 | 00,557,568 | ---- | M] (Microsoft Corporation) {FB5F1910-F110-11d2-BB9E-00C04F795683}:Exec [HKLM] -> %ProgramFiles%\Messenger\msmsgs.exe [Button: Messenger] -> [2004/10/13 16:24:37 | 01,694,208 | ---- | M] (Microsoft Corporation) {FB5F1910-F110-11d2-BB9E-00C04F795683}:Exec [HKLM] -> %ProgramFiles%\Messenger\msmsgs.exe [Menu: Windows Messenger] -> [2004/10/13 16:24:37 | 01,694,208 | ---- | M] (Microsoft Corporation) < Internet Explorer Extensions [HKEY_CURRENT_USER\] > -> HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Extensions\ -> CmdMapping\\"{08B0E5C0-4FCB-11CF-AAA5-00401C608501}" [HKLM] -> [Reg Error: Value does not exist or could not be read.] -> File not found CmdMapping\\"{4982D40A-C53B-4615-B15B-B5B5E98D167C}" [HKLM] -> [Reg Error: Key does not exist or could not be opened.] -> File not found CmdMapping\\"{FB5F1910-F110-11d2-BB9E-00C04F795683}" [HKLM] -> %ProgramFiles%\Messenger\msmsgs.exe [Messenger] -> [2004/10/13 16:24:37 | 01,694,208 | ---- | M] (Microsoft Corporation) < Internet Explorer Plugins [HKEY_LOCAL_MACHINE] > -> HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Plugins\ -> PluginsPageFriendlyName -> Microsoft ActiveX Gallery -> PluginsPage -> http://activex.microsoft.com/controls/find.asp?ext=%s&mime=%s -> < Default Prefix > -> HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\URL\DefaultPrefix "" -> http:// < Trusted Sites Domains [HKEY_LOCAL_MACHINE\] > -> HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Domains\ -> HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Domains\ -> [Key] 1 domain(s) found. -> 1 domain(s) and sub-domain(s) not assigned to a zone. < Trusted Sites Ranges [HKEY_LOCAL_MACHINE\] > -> HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Ranges\ -> HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Ranges\ -> [Key] 0 range(s) found. -> < Trusted Sites Domains [HKEY_CURRENT_USER\] > -> HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Domains\ -> HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Domains\ -> [Key] 1572 domain(s) found. -> objects_aol.com [*] -> Out of zone range - ( 5 ) -> 9 domain(s) and sub-domain(s) not assigned to a zone. < Trusted Sites Ranges [HKEY_CURRENT_USER\] > -> HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Ranges\ -> HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Ranges\ -> [Key] 0 range(s) found. -> < Downloaded Program Files > -> HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Code Store Database\Distribution Units\ -> {0CCA191D-13A6-4E29-B746-314DEE697D83} [HKLM] -> http://upload.facebook.com/controls/FacebookPhotoUploader5.cab[Facebook Photo Uploader 5] -> {17492023-C23A-453E-A040-C7C580BBF700} [HKLM] -> http://go.microsoft.com/fwlink/?linkid=39204[Windows Genuine Advantage Validation Tool] -> {3E68E405-C6DE-49FF-83AE-41EE9F4C36CE} [HKLM] -> http://office.microsoft.com/officeupdate/content/opuc3.cab[Office Update Installation Engine] -> {4F1E5B1A-2A80-42CA-8532-2D05CB959537} [HKLM] -> http://gfx1.hotmail.com/mail/w2/resources/MSNPUpld.cab[MSN Photo Upload Tool] -> {8AD9C840-044E-11D1-B3E9-00805F499D93} [HKLM] -> http://java.sun.com/update/1.6.0/jinstall-1_6_0_10-windows-i586.cab[Java Plug-in 1.6.0_10] -> {8FFBE65D-2C9C-4669-84BD-5829DC0B603C} [HKLM] -> http://fpdownload.macromedia.com/get/flashplayer/current/ultrashim.cab[Reg Error: Key does not exist or could not be opened.] -> {C3F79A2B-B9B4-4A66-B012-3EE46475B072} [HKLM] -> http://messenger.zone.msn.com/binary/MessengerStatsPAClient.cab56907.cab[MessengerStatsClient Class] -> {C5E28B9D-0A68-4B50-94E9-E8F6B4697514} [HKLM] -> http://www.nullsoft.com/nsv/embed/nsvplayx_vp3_mp3.cab[NsvPlayX Control] -> {CAFEEFAC-0014-0002-0004-ABCDEFFEDCBA} [HKLM] -> http://java.sun.com/products/plugin/autodl/jinstall-142-windows-i586.cab[Java Plug-in 1.4.2_04] -> {CAFEEFAC-0015-0000-0003-ABCDEFFEDCBA} [HKLM] -> http://java.sun.com/update/1.5.0/jinstall-1_5_0_03-windows-i586.cab[Java Plug-in 1.5.0_03] -> {CAFEEFAC-0016-0000-0010-ABCDEFFEDCBA} [HKLM] -> http://java.sun.com/update/1.6.0/jinstall-1_6_0_10-windows-i586.cab[Java Plug-in 1.6.0_10] -> {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} [HKLM] -> http://java.sun.com/update/1.6.0/jinstall-1_6_0_10-windows-i586.cab[Java Plug-in 1.6.0_10] -> {DF780F87-FF2B-4DF8-92D0-73DB16A1543A} [HKLM] -> http://www.shockwave.com/content/bejeweled2/sis/popcaploader_v10.cab[PopCapLoader Object] -> < DNS Name Servers [HKEY_LOCAL_MACHINE] > -> HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Tcpip\Parameters\Adapters\ -> {17F15DC3-14F1-4195-8A82-7E189D6593D6} -> () -> {2C8B32FF-3197-466E-85DB-9AD0CE097027} -> (NVIDIA nForce Networking Controller) -> {4D8C3587-0223-40F2-B57C-4E7CAA2D1359} -> (1394 Net Adapter) -> {5E7F4125-E74C-47C3-AB89-AEA4B7F0975F} -> (Sony Ericsson Device 117 USB Ethernet Emulation (NDIS 5)) -> {750C60EB-7782-4371-B727-21285C251832} -> (Sony Ericsson Device 117 USB Ethernet Emulation (NDIS 5)) -> {85D63DD0-1AC7-436A-BB69-7375B6399316} -> () -> {9AC9482B-7269-44DA-B67E-CF240E4FFDFD} -> (Sony Ericsson Device 117 USB Ethernet Emulation (NDIS 5)) -> {F3C75F6E-72D8-457C-B2DA-8AFE872A13EB} -> (Sony Ericsson Device 117 USB Ethernet Emulation (NDIS 5)) -> < AppInit_DLLs [HKEY_LOCAL_MACHINE] > -> HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows\\AppInit_DLLs -> *AppInit_DLLs* -> HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows\\AppInit_Dlls -> C:\WINDOWS\system32\guard32.dll -> %SystemRoot%\system32\guard32.dll -> [2008/12/11 10:59:21 | 00,147,192 | ---- | M] () C:\WINDOWS\system32\cssdll32.dll -> %SystemRoot%\system32\cssdll32.dll -> [2008/12/11 11:00:16 | 00,249,592 | ---- | M] (COMODO) *MultiFile Done* -> -> < Winlogon settings [HKEY_LOCAL_MACHINE] > -> HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon -> *UserInit* -> HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\\UserInit -> C:\WINDOWS\system32\twext.exe -> %SystemRoot%\system32\twext.exe -> File not found *MultiFile Done* -> -> < SharedTaskScheduler [HKEY_LOCAL_MACHINE] > -> HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\SharedTaskScheduler -> "{C5BF49A2-94F3-42BD-F434-3604812C897D}" [HKLM] -> %SystemRoot%\system32\jsdf8j3dgf.dll [mcb7uehuj3n8weuhejsw] -> [2008/12/05 16:39:53 | 00,015,000 | ---- | M] () < ShellExecuteHooks [HKEY_LOCAL_MACHINE] > -> HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks -> "{9EF34FF2-3396-4527-9D27-04C8C1C67806}" [HKLM] -> %ProgramFiles%\Microsoft AntiSpyware\shellextension.dll [Microsoft AntiSpyware Service Hook] -> [2005/06/24 15:24:20 | 00,101,080 | ---- | M] (Microsoft Corporation) < Domain Profile Authorized Applications List > -> HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile\AuthorizedApplications\List -> "%windir%\Network Diagnostic\xpnetdiag.exe" -> C:\WINDOWS\network diagnostic\xpnetdiag.exe [%windir%\Network Diagnostic\xpnetdiag.exe:*:Enabled:@xpsp3res.dll,-20000] -> [2006/10/10 12:44:50 | 00,557,568 | ---- | M] (Microsoft Corporation) "%windir%\system32\sessmgr.exe" -> C:\WINDOWS\system32\sessmgr.exe [%windir%\system32\sessmgr.exe:*:enabled:@xpsp2res.dll,-22019] -> [2004/08/04 00:56:58 | 00,140,800 | ---- | M] (Microsoft Corporation) "C:\Program Files\AOL 9.0\waol.exe" -> C:\Program Files\AOL 9.0\waol.exe [C:\Program Files\AOL 9.0\waol.exe:*:Enabled:AOL 9.0] -> [2007/09/19 11:31:20 | 00,259,632 | ---- | M] (America Online, Inc.) "C:\Program Files\Common Files\AOL\ACS\AOLacsd.exe" -> C:\Program Files\Common Files\AOL\ACS\AOLacsd.exe [C:\Program Files\Common Files\AOL\ACS\AOLacsd.exe:*:Enabled:AOL] -> [2004/11/09 23:22:16 | 01,140,312 | ---- | M] (America Online, Inc.) "C:\Program Files\Common Files\AOL\ACS\AOLDial.exe" -> C:\Program Files\Common Files\AOL\ACS\AOLDial.exe [C:\Program Files\Common Files\AOL\ACS\AOLDial.exe:*:Enabled:AOL] -> [2004/11/09 23:22:17 | 00,497,240 | ---- | M] (America Online, Inc) "C:\Program Files\FlashFXP\FlashFXP.exe" -> C:\Program Files\FlashFXP\FlashFXP.exe [C:\Program Files\FlashFXP\FlashFXP.exe:*:Enabled:FlashFXP v3] -> [2008/02/20 10:52:20 | 03,068,360 | ---- | M] (IniCom Networks, Inc.) "C:\Program Files\MSN Messenger\livecall.exe" -> C:\Program Files\MSN Messenger\livecall.exe [C:\Program Files\MSN Messenger\livecall.exe:*:Enabled:Windows Live Messenger 8.1 (Phone)] -> File not found "C:\Program Files\Windows Live\Messenger\msnmsgr.exe" -> C:\Program Files\Windows Live\Messenger\msnmsgr.exe [C:\Program Files\Windows Live\Messenger\msnmsgr.exe:*:Enabled:Windows Live Messenger] -> [2008/09/08 23:02:40 | 03,513,344 | ---- | M] (Microsoft Corporation) "C:\Program Files\Windows Live\Messenger\wlcsdk.exe" -> C:\Program Files\Windows Live\Messenger\wlcsdk.exe [C:\Program Files\Windows Live\Messenger\wlcsdk.exe:*:Enabled:Windows Live Call] -> [2008/09/02 20:02:16 | 00,582,664 | ---- | M] (Microsoft Corporation) < Standard Profile Authorized Applications List > -> HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\AuthorizedApplications\List -> "%windir%\Network Diagnostic\xpnetdiag.exe" -> C:\WINDOWS\network diagnostic\xpnetdiag.exe [%windir%\Network Diagnostic\xpnetdiag.exe:*:Enabled:@xpsp3res.dll,-20000] -> [2006/10/10 12:44:50 | 00,557,568 | ---- | M] (Microsoft Corporation) "%windir%\system32\sessmgr.exe" -> C:\WINDOWS\system32\sessmgr.exe [%windir%\system32\sessmgr.exe:*:enabled:@xpsp2res.dll,-22019] -> [2004/08/04 00:56:58 | 00,140,800 | ---- | M] (Microsoft Corporation) "C:\Documents and Settings\user\Desktop\utorrent.exe" -> C:\Documents and Settings\user\Desktop\utorrent.exe [C:\Documents and Settings\user\Desktop\utorrent.exe:*:Enabled:µTorrent] -> File not found "C:\Documents and Settings\user\My Documents\uTorrent.exe" -> C:\Documents and Settings\user\My Documents\uTorrent.exe [C:\Documents and Settings\user\My Documents\uTorrent.exe:*:Enabled:µTorrent] -> [2008/10/13 15:33:42 | 00,270,128 | ---- | M] (BitTorrent, Inc.) "C:\Program Files\AOL 9.0\waol.exe" -> C:\Program Files\AOL 9.0\waol.exe [C:\Program Files\AOL 9.0\waol.exe:*:Enabled:AOL 9.0] -> [2007/09/19 11:31:20 | 00,259,632 | ---- | M] (America Online, Inc.) "C:\Program Files\Common Files\AOL\ACS\AOLacsd.exe" -> C:\Program Files\Common Files\AOL\ACS\AOLacsd.exe [C:\Program Files\Common Files\AOL\ACS\AOLacsd.exe:*:Enabled:AOL] -> [2004/11/09 23:22:16 | 01,140,312 | ---- | M] (America Online, Inc.) "C:\Program Files\Common Files\AOL\ACS\AOLDial.exe" -> C:\Program Files\Common Files\AOL\ACS\AOLDial.exe [C:\Program Files\Common Files\AOL\ACS\AOLDial.exe:*:Enabled:AOL] -> [2004/11/09 23:22:17 | 00,497,240 | ---- | M] (America Online, Inc) "C:\Program Files\FlashFXP\FlashFXP.exe" -> C:\Program Files\FlashFXP\FlashFXP.exe [C:\Program Files\FlashFXP\FlashFXP.exe:*:Enabled:FlashFXP v3] -> [2008/02/20 10:52:20 | 03,068,360 | ---- | M] (IniCom Networks, Inc.) "C:\Program Files\Grisoft\AVG Free\avgemc.exe" -> C:\Program Files\Grisoft\AVG Free\avgemc.exe [C:\Program Files\Grisoft\AVG Free\avgemc.exe:*:Enabled:avgemc.exe] -> [2008/01/12 10:21:56 | 00,406,528 | ---- | M] (GRISOFT, s.r.o.) "C:\Program Files\Grisoft\AVG Free\avginet.exe" -> C:\Program Files\Grisoft\AVG Free\avginet.exe [C:\Program Files\Grisoft\AVG Free\avginet.exe:*:Enabled:avginet.exe] -> [2008/10/16 18:31:24 | 00,514,560 | ---- | M] (GRISOFT, s.r.o.) "C:\Program Files\iTunes\iTunes.exe" -> C:\Program Files\iTunes\iTunes.exe [C:\Program Files\iTunes\iTunes.exe:*:Enabled:iTunes] -> [2008/11/20 13:20:48 | 14,294,824 | ---- | M] (Apple Inc.) "C:\Program Files\Kodak\Kodak EasyShare software\bin\EasyShare.exe" -> C:\Program Files\Kodak\Kodak EasyShare software\bin\EasyShare.exe [C:\Program Files\Kodak\Kodak EasyShare software\bin\EasyShare.exe:*:Enabled:EasyShare] -> [2008/07/07 12:14:40 | 00,282,624 | ---- | M] (Eastman Kodak Company) "C:\Program Files\Kontiki\KService.exe" -> C:\Program Files\Kontiki\KService.exe [C:\Program Files\Kontiki\KService.exe:*:Enabled:Delivery Manager Service] -> [2007/04/23 10:22:00 | 03,068,352 | ---- | M] (Kontiki Inc.) "C:\Program Files\KService\KService.exe" -> C:\Program Files\KService\KService.exe [C:\Program Files\KService\KService.exe:*:Enabled:Delivery Manager Service] -> File not found "C:\Program Files\LimeWire\LimeWire.exe" -> C:\Program Files\LimeWire\LimeWire.exe [C:\Program Files\LimeWire\LimeWire.exe:*:Enabled:LimeWire] -> File not found "C:\Program Files\MSN Messenger\livecall.exe" -> C:\Program Files\MSN Messenger\livecall.exe [C:\Program Files\MSN Messenger\livecall.exe:*:Enabled:Windows Live Messenger 8.1 (Phone)] -> File not found "C:\Program Files\Sony Ericsson\Sony Ericsson Media Manager 1.0\MediaManager.exe" -> C:\Program Files\Sony Ericsson\Sony Ericsson Media Manager 1.0\MediaManager.exe [C:\Program Files\Sony Ericsson\Sony Ericsson Media Manager 1.0\MediaManager.exe:*:Enabled:Sony Ericsson Media Manager 1.0] -> [2007/07/27 12:59:42 | 01,275,136 | ---- | M] (Sony Creative Software Inc.) "C:\Program Files\Spotify\spotify.exe" -> C:\Program Files\Spotify\spotify.exe [C:\Program Files\Spotify\spotify.exe:*:Enabled:Spotify] -> [2008/12/18 17:12:59 | 01,431,312 | ---- | M] (Spotify AB) "C:\Program Files\TVersity\Media Server\MediaServer.exe" -> C:\Program Files\TVersity\Media Server\MediaServer.exe [C:\Program Files\TVersity\Media Server\MediaServer.exe:*:Enabled:TVersity Media Server] -> [2008/07/22 16:59:42 | 00,794,624 | ---- | M] () "C:\Program Files\Windows Live\Messenger\msnmsgr.exe" -> C:\Program Files\Windows Live\Messenger\msnmsgr.exe [C:\Program Files\Windows Live\Messenger\msnmsgr.exe:*:Enabled:Windows Live Messenger] -> [2008/09/08 23:02:40 | 03,513,344 | ---- | M] (Microsoft Corporation) "C:\Program Files\Windows Live\Messenger\wlcsdk.exe" -> C:\Program Files\Windows Live\Messenger\wlcsdk.exe [C:\Program Files\Windows Live\Messenger\wlcsdk.exe:*:Enabled:Windows Live Call] -> [2008/09/02 20:02:16 | 00,582,664 | ---- | M] (Microsoft Corporation) "C:\Program Files\Yahoo!\Messenger\YahooMessenger.exe" -> C:\Program Files\Yahoo!\Messenger\YahooMessenger.exe [C:\Program Files\Yahoo!\Messenger\YahooMessenger.exe:*:Enabled:Yahoo! Messenger] -> [2008/11/05 21:59:00 | 04,347,120 | ---- | M] (Yahoo! Inc.) "C:\WINDOWS\kdx\KHost.exe" -> C:\WINDOWS\kdx\KHost.exe [C:\WINDOWS\kdx\KHost.exe:*:Enabled:Delivery Manager] -> File not found < SafeBoot AlternateShell [HKEY_LOCAL_MACHINE] > -> HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot -> "AlternateShell" -> cmd.exe -> < CDROM Autorun Setting [HKEY_LOCAL_MACHINE]> -> HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Cdrom -> "AutoRun" -> 1 -> "DisplayName" -> CD-ROM Driver -> "ImagePath" -> %SystemRoot%\system32\drivers\cdrom.sys [system32\DRIVERS\cdrom.sys] -> [2004/08/03 22:59:54 | 00,049,536 | ---- | M] (Microsoft Corporation) < Drives with AutoRun files > -> -> E:\autorun.inf [[AutoRun] | open=LaunchU3.exe | icon=LaunchU3.exe,0 | | [Definitions] | Launchpad=LaunchPad.exe | | [CopyFiles] | FileNumber=1 | File1=LaunchPad.zip | ] -> E:\autorun.inf [ CDFS ] -> [2005/06/27 13:16:56 | 00,000,145 | R--- | M] () < MountPoints2 [HKEY_CURRENT_USER] > -> HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2 -> \{09659242-4fd9-11da-8680-806d6172696f} HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{09659242-4fd9-11da-8680-806d6172696f}\Shell \{09659242-4fd9-11da-8680-806d6172696f}\Shell\\"" -> [AutoRun] -> File not found HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{09659242-4fd9-11da-8680-806d6172696f}\Shell\AutoRun \{09659242-4fd9-11da-8680-806d6172696f}\Shell\AutoRun\\"" -> [Auto&Play] -> File not found HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{09659242-4fd9-11da-8680-806d6172696f}\Shell\AutoRun\command \{09659242-4fd9-11da-8680-806d6172696f}\Shell\AutoRun\command\\"" -> D:\ASUSACPI.exe [D:\ASUSACPI.exe] -> File not found \{3d17baf3-588a-11dc-8e02-0013d4f58c41} HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{3d17baf3-588a-11dc-8e02-0013d4f58c41}\Shell \{3d17baf3-588a-11dc-8e02-0013d4f58c41}\Shell\\"" -> [AutoRun] -> File not found HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{3d17baf3-588a-11dc-8e02-0013d4f58c41}\Shell\AutoRun \{3d17baf3-588a-11dc-8e02-0013d4f58c41}\Shell\AutoRun\\"" -> [Auto&Play] -> File not found HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{3d17baf3-588a-11dc-8e02-0013d4f58c41}\Shell\AutoRun\command \{3d17baf3-588a-11dc-8e02-0013d4f58c41}\Shell\AutoRun\command\\"" -> E:\LaunchU3.exe [E:\LaunchU3.exe] -> [2005/10/11 11:58:51 | 00,921,600 | R--- | M] () [Files/Folders - Created Within 30 Days] OTScanIt2 -> %UserProfile%\Desktop\OTScanIt2 -> [2008/12/19 15:53:31 | 00,000,000 | ---D | C] OTScanIt2.exe -> %UserProfile%\Desktop\OTScanIt2.exe -> [2008/12/19 15:53:17 | 00,647,677 | ---- | C] () HijackThis.lnk -> %UserProfile%\Desktop\HijackThis.lnk -> [2008/12/19 09:52:01 | 00,001,734 | ---- | C] () Trend Micro -> %ProgramFiles%\Trend Micro -> [2008/12/19 09:52:01 | 00,000,000 | ---D | C] sqmdata19.sqm -> %SystemDrive%\sqmdata19.sqm -> [2008/12/17 20:27:00 | 00,000,236 | ---- | C] () sqmnoopt19.sqm -> %SystemDrive%\sqmnoopt19.sqm -> [2008/12/17 20:27:00 | 00,000,200 | ---- | C] () sqmdata18.sqm -> %SystemDrive%\sqmdata18.sqm -> [2008/12/17 19:35:46 | 00,000,236 | ---- | C] () sqmnoopt18.sqm -> %SystemDrive%\sqmnoopt18.sqm -> [2008/12/17 19:35:46 | 00,000,200 | ---- | C] () Belarc Advisor.lnk -> %AllUsersProfile%\Desktop\Belarc Advisor.lnk -> [2008/12/16 11:24:42 | 00,001,748 | ---- | C] () BANTExt.sys -> %SystemRoot%\System32\drivers\BANTExt.sys -> [2008/12/16 11:24:27 | 00,003,840 | ---- | C] () Belarc -> %ProgramFiles%\Belarc -> [2008/12/16 11:24:24 | 00,000,000 | ---D | C] advisor.exe -> %UserProfile%\Desktop\advisor.exe -> [2008/12/16 11:22:58 | 01,826,312 | ---- | C] () FlashFXP.lnk -> %AllUsersProfile%\Desktop\FlashFXP.lnk -> [2008/12/14 15:25:20 | 00,000,682 | ---- | C] () FlashFXP -> %ProgramFiles%\FlashFXP -> [2008/12/14 15:25:18 | 00,000,000 | ---D | C] FlashFXP -> %AllUsersProfile%\Application Data\FlashFXP -> [2008/12/14 15:25:17 | 00,000,000 | ---D | C] sqmdata17.sqm -> %SystemDrive%\sqmdata17.sqm -> [2008/12/14 14:52:51 | 00,000,236 | ---- | C] () sqmnoopt17.sqm -> %SystemDrive%\sqmnoopt17.sqm -> [2008/12/14 14:52:51 | 00,000,200 | ---- | C] () sqmdata16.sqm -> %SystemDrive%\sqmdata16.sqm -> [2008/12/13 16:24:03 | 00,000,236 | ---- | C] () sqmnoopt16.sqm -> %SystemDrive%\sqmnoopt16.sqm -> [2008/12/13 16:24:03 | 00,000,200 | ---- | C] () Apple Software Update -> %ProgramFiles%\Apple Software Update -> [2008/12/13 15:47:14 | 00,000,000 | ---D | C] Apple -> %AllUsersProfile%\Application Data\Apple -> [2008/12/13 15:47:14 | 00,000,000 | ---D | C] iPod -> %ProgramFiles%\iPod -> [2008/12/13 15:32:56 | 00,000,000 | ---D | C] Apple -> %CommonProgramFiles%\Apple -> [2008/12/13 15:32:55 | 00,000,000 | ---D | C] iTunes -> %ProgramFiles%\iTunes -> [2008/12/13 15:32:54 | 00,000,000 | ---D | C] {3276BE95_AF08_429F_A64F_CA64CB79BCF6} -> %AllUsersProfile%\Application Data\{3276BE95_AF08_429F_A64F_CA64CB79BCF6} -> [2008/12/13 15:32:54 | 00,000,000 | ---D | C] sqmdata15.sqm -> %SystemDrive%\sqmdata15.sqm -> [2008/12/12 17:49:19 | 00,000,236 | ---- | C] () sqmnoopt15.sqm -> %SystemDrive%\sqmnoopt15.sqm -> [2008/12/12 17:49:19 | 00,000,200 | ---- | C] () COMODO Internet Security.lnk -> %AllUsersProfile%\Desktop\COMODO Internet Security.lnk -> [2008/12/11 11:03:26 | 00,000,808 | ---- | C] () cssdll32.dll -> %SystemRoot%\System32\cssdll32.dll -> [2008/12/11 11:00:17 | 00,249,592 | ---- | C] (COMODO) AskBarDis -> %ProgramFiles%\AskBarDis -> [2008/12/11 11:00:15 | 00,000,000 | ---D | C] guard32.dll -> %SystemRoot%\System32\guard32.dll -> [2008/12/11 10:59:23 | 00,147,192 | ---- | C] () cmdguard.sys -> %SystemRoot%\System32\drivers\cmdguard.sys -> [2008/12/11 10:59:23 | 00,101,776 | ---- | C] (COMODO) inspect.sys -> %SystemRoot%\System32\drivers\inspect.sys -> [2008/12/11 10:59:23 | 00,079,504 | ---- | C] (COMODO) cmdhlp.sys -> %SystemRoot%\System32\drivers\cmdhlp.sys -> [2008/12/11 10:59:23 | 00,031,504 | ---- | C] (COMODO) comodo -> %AllUsersProfile%\Application Data\comodo -> [2008/12/11 10:59:23 | 00,000,000 | ---D | C] COMODO -> %ProgramFiles%\COMODO -> [2008/12/11 10:59:21 | 00,000,000 | ---D | C] CIS_Setup_3.5.57173.439_XP_Vista_x32.INI -> %SystemRoot%\CIS_Setup_3.5.57173.439_XP_Vista_x32.INI -> [2008/12/11 10:54:31 | 00,000,120 | ---- | C] () Camera pictures -> %UserProfile%\My Documents\Camera pictures -> [2008/12/09 01:03:15 | 00,000,000 | ---D | C] Phone pics -> %UserProfile%\My Documents\Phone pics -> [2008/12/09 00:58:24 | 00,000,000 | ---D | C] My mvs -> %UserProfile%\My Documents\My mvs -> [2008/12/09 00:27:04 | 00,000,000 | ---D | C] sqmdata14.sqm -> %SystemDrive%\sqmdata14.sqm -> [2008/12/08 22:01:04 | 00,000,236 | ---- | C] () sqmnoopt14.sqm -> %SystemDrive%\sqmnoopt14.sqm -> [2008/12/08 22:01:04 | 00,000,200 | ---- | C] () Royale -> %UserProfile%\My Documents\Royale -> [2008/12/07 17:05:29 | 00,000,000 | ---D | C] Mjcore -> %ProgramFiles%\Mjcore -> [2008/12/06 16:17:08 | 00,000,000 | ---D | C] windi77.dll -> %SystemRoot%\System32\windi77.dll -> [2008/12/05 16:40:06 | 00,401,408 | ---- | C] () twain_32 -> %SystemRoot%\System32\twain_32 -> [2008/12/05 16:25:30 | 00,000,000 | -HSD | C] jsdf8j3dgf.dll -> %SystemRoot%\System32\jsdf8j3dgf.dll -> [2008/12/05 16:25:28 | 00,015,000 | ---- | C] () Ad-Watch.lnk -> %AllUsersProfile%\Desktop\Ad-Watch.lnk -> [2008/12/05 16:25:04 | 00,000,793 | ---- | C] () Ad-Aware.lnk -> %AllUsersProfile%\Desktop\Ad-Aware.lnk -> [2008/12/05 16:25:04 | 00,000,793 | ---- | C] () Lavasoft -> %ProgramFiles%\Lavasoft -> [2008/12/05 16:24:57 | 00,000,000 | ---D | C] Wise Installation Wizard -> %CommonProgramFiles%\Wise Installation Wizard -> [2008/12/05 16:24:32 | 00,000,000 | ---D | C] NI.GSCNS -> %AppData%\NI.GSCNS -> [2008/12/05 16:18:49 | 00,000,000 | ---D | C] gadcom -> %AppData%\gadcom -> [2008/12/05 16:10:47 | 00,000,000 | ---D | C] akpdvjqngtifcrfm.exe -> %SystemRoot%\System32\akpdvjqngtifcrfm.exe -> [2008/12/05 16:10:37 | 00,047,599 | ---- | C] () winpm77.dll -> %SystemRoot%\System32\winpm77.dll -> [2008/12/05 16:10:34 | 00,401,408 | ---- | C] () up -> %SystemRoot%\System32\up -> [2008/12/05 16:10:34 | 00,000,000 | ---D | C] tdi -> %SystemRoot%\System32\tdi -> [2008/12/05 16:10:34 | 00,000,000 | ---D | C] ma1 -> %SystemRoot%\System32\ma1 -> [2008/12/05 16:10:34 | 00,000,000 | ---D | C] ko3 -> %SystemRoot%\System32\ko3 -> [2008/12/05 16:10:34 | 00,000,000 | ---D | C] .# -> %UserProfile%\Local Settings\Application Data\.# -> [2008/12/05 16:10:31 | 00,000,000 | -HSD | C] sqmdata13.sqm -> %SystemDrive%\sqmdata13.sqm -> [2008/11/28 12:37:27 | 00,000,236 | ---- | C] () sqmnoopt13.sqm -> %SystemDrive%\sqmnoopt13.sqm -> [2008/11/28 12:37:27 | 00,000,200 | ---- | C] () sqmdata12.sqm -> %SystemDrive%\sqmdata12.sqm -> [2008/11/27 20:36:55 | 00,000,236 | ---- | C] () sqmnoopt12.sqm -> %SystemDrive%\sqmnoopt12.sqm -> [2008/11/27 20:36:55 | 00,000,200 | ---- | C] () sqmdata11.sqm -> %SystemDrive%\sqmdata11.sqm -> [2008/11/22 19:04:25 | 00,000,236 | ---- | C] () sqmnoopt11.sqm -> %SystemDrive%\sqmnoopt11.sqm -> [2008/11/22 19:04:25 | 00,000,200 | ---- | C] () sqmdata10.sqm -> %SystemDrive%\sqmdata10.sqm -> [2008/11/21 19:23:23 | 00,000,236 | ---- | C] () sqmnoopt10.sqm -> %SystemDrive%\sqmnoopt10.sqm -> [2008/11/21 19:23:23 | 00,000,200 | ---- | C] () Spotify.lnk -> %UserProfile%\Desktop\Spotify.lnk -> [2008/11/21 11:45:50 | 00,000,666 | ---- | C] () Spotify -> %UserProfile%\Local Settings\Application Data\Spotify -> [2008/11/21 11:45:50 | 00,000,000 | ---D | C] Spotify -> %ProgramFiles%\Spotify -> [2008/11/21 11:45:50 | 00,000,000 | ---D | C] Spotify -> %AppData%\Spotify -> [2008/11/21 11:45:50 | 00,000,000 | ---D | C] Did you know.doc -> %UserProfile%\My Documents\Did you know.doc -> [2008/11/19 22:07:18 | 00,025,600 | ---- | C] () Yahoo -> %UserProfile%\Local Settings\Application Data\Yahoo -> [2008/11/19 21:51:04 | 00,000,000 | ---D | C] Yahoo! Messenger.lnk -> %AllUsersProfile%\Desktop\Yahoo! Messenger.lnk -> [2008/11/19 21:49:19 | 00,000,812 | ---- | C] () Yahoo! -> %AllUsersProfile%\Application Data\Yahoo! -> [2008/11/19 21:49:11 | 00,000,000 | ---D | C] Yahoo! -> %ProgramFiles%\Yahoo! -> [2008/11/19 21:49:07 | 00,000,000 | ---D | C] [Files/Folders - Modified Within 30 Days] 1 C:\WINDOWS\*.tmp files -> C:\WINDOWS\*.tmp -> C:\Documents and Settings\All Users\Application Data\Microsoft\Network\Downloader\ -> C:\Documents and Settings\All Users\Application Data\Microsoft\Network\Downloader -> [2005/11/07 22:18:09 | 00,000,000 | ---D | M] qmgr0.dat -> C:\Documents and Settings\All Users\Application Data\Microsoft\Network\Downloader\qmgr0.dat -> [2008/12/19 12:50:25 | 00,005,726 | ---- | M] () qmgr1.dat -> C:\Documents and Settings\All Users\Application Data\Microsoft\Network\Downloader\qmgr1.dat -> [2008/12/19 10:04:08 | 00,006,802 | ---- | M] () C:\Documents and Settings\All Users\Application Data\Microsoft\Office\Data\ -> C:\Documents and Settings\All Users\Application Data\Microsoft\Office\Data -> [2005/11/10 17:28:41 | 00,000,000 | ---D | M] data.dat -> C:\Documents and Settings\All Users\Application Data\Microsoft\Office\Data\data.dat -> [2007/09/02 21:09:50 | 00,001,372 | ---- | M] () C:\Documents and Settings\user\Local Settings\Temp\ -> C:\Documents and Settings\user\Local Settings\Temp -> [2008/12/19 15:56:12 | 00,000,000 | ---D | M] winlogin.exe -> C:\Documents and Settings\user\Local Settings\Temp\winlogin.exe -> [2008/12/05 16:39:53 | 00,015,000 | ---- | M] () 2 C:\Documents and Settings\user\Local Settings\Temp\*.tmp files -> C:\Documents and Settings\user\Local Settings\Temp\*.tmp -> C:\WINDOWS\Temp\ -> C:\WINDOWS\Temp -> [2008/12/19 15:47:15 | 00,000,000 | ---D | M] Perflib_Perfdata_518.dat -> C:\WINDOWS\Temp\Perflib_Perfdata_518.dat -> [2008/12/19 09:16:14 | 00,016,384 | ---- | M] () OTScanIt2.exe -> %UserProfile%\Desktop\OTScanIt2.exe -> [2008/12/19 15:53:18 | 00,647,677 | ---- | M] () HijackThis.lnk -> %UserProfile%\Desktop\HijackThis.lnk -> [2008/12/19 09:52:08 | 00,001,734 | ---- | M] () wpa.dbl -> %SystemRoot%\System32\wpa.dbl -> [2008/12/19 09:17:06 | 00,002,206 | ---- | M] () .zreglib -> %AllUsersProfile%\Application Data\.zreglib -> [2008/12/19 09:16:37 | 00,000,125 | -HS- | M] () nvapps.xml -> %SystemRoot%\System32\nvapps.xml -> [2008/12/19 09:16:12 | 00,000,000 | ---- | M] () SA.DAT -> %SystemRoot%\tasks\SA.DAT -> [2008/12/19 09:16:06 | 00,000,006 | -H-- | M] () bootstat.dat -> %SystemRoot%\bootstat.dat -> [2008/12/19 09:16:00 | 00,002,048 | --S- | M] () IconCache.db -> %UserProfile%\Local Settings\Application Data\IconCache.db -> [2008/12/18 23:18:20 | 84,403,926 | -H-- | M] () NeroDigital.ini -> %SystemRoot%\NeroDigital.ini -> [2008/12/18 21:34:40 | 00,000,116 | ---- | M] () randseed.rnd -> %SystemRoot%\randseed.rnd -> [2008/12/18 17:48:12 | 00,000,512 | ---- | M] () sqmdata19.sqm -> %SystemDrive%\sqmdata19.sqm -> [2008/12/17 20:27:00 | 00,000,236 | ---- | M] () sqmnoopt19.sqm -> %SystemDrive%\sqmnoopt19.sqm -> [2008/12/17 20:27:00 | 00,000,200 | ---- | M] () sqmdata18.sqm -> %SystemDrive%\sqmdata18.sqm -> [2008/12/17 19:35:46 | 00,000,236 | ---- | M] () sqmnoopt18.sqm -> %SystemDrive%\sqmnoopt18.sqm -> [2008/12/17 19:35:46 | 00,000,200 | ---- | M] () DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini -> %UserProfile%\Local Settings\Application Data\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini -> [2008/12/17 11:46:55 | 00,103,424 | ---- | M] () akpdvjqngtifcrfm.exe -> %SystemRoot%\System32\akpdvjqngtifcrfm.exe -> [2008/12/17 11:11:52 | 00,047,599 | ---- | M] () Belarc Advisor.lnk -> %AllUsersProfile%\Desktop\Belarc Advisor.lnk -> [2008/12/16 11:24:42 | 00,001,748 | ---- | M] () advisor.exe -> %UserProfile%\Desktop\advisor.exe -> [2008/12/16 11:23:45 | 01,826,312 | ---- | M] () FlashFXP.lnk -> %AllUsersProfile%\Desktop\FlashFXP.lnk -> [2008/12/14 15:25:20 | 00,000,682 | ---- | M] () sqmdata17.sqm -> %SystemDrive%\sqmdata17.sqm -> [2008/12/14 14:52:51 | 00,000,236 | ---- | M] () sqmnoopt17.sqm -> %SystemDrive%\sqmnoopt17.sqm -> [2008/12/14 14:52:51 | 00,000,200 | ---- | M] () sqmdata16.sqm -> %SystemDrive%\sqmdata16.sqm -> [2008/12/13 16:24:03 | 00,000,236 | ---- | M] () sqmnoopt16.sqm -> %SystemDrive%\sqmnoopt16.sqm -> [2008/12/13 16:24:03 | 00,000,200 | ---- | M] () mshtml.dll -> %SystemRoot%\System32\mshtml.dll -> [2008/12/13 06:40:02 | 03,593,216 | ---- | M] (Microsoft Corporation) mshtml.dll -> %SystemRoot%\System32\dllcache\mshtml.dll -> [2008/12/13 06:40:02 | 03,593,216 | ---- | M] (Microsoft Corporation) sqmdata15.sqm -> %SystemDrive%\sqmdata15.sqm -> [2008/12/12 17:49:19 | 00,000,236 | ---- | M] () sqmnoopt15.sqm -> %SystemDrive%\sqmnoopt15.sqm -> [2008/12/12 17:49:19 | 00,000,200 | ---- | M] () COMODO Internet Security.lnk -> %AllUsersProfile%\Desktop\COMODO Internet Security.lnk -> [2008/12/11 11:03:26 | 00,000,808 | ---- | M] () cssdll32.dll -> %SystemRoot%\System32\cssdll32.dll -> [2008/12/11 11:00:16 | 00,249,592 | ---- | M] (COMODO) guard32.dll -> %SystemRoot%\System32\guard32.dll -> [2008/12/11 10:59:21 | 00,147,192 | ---- | M] () cmdguard.sys -> %SystemRoot%\System32\drivers\cmdguard.sys -> [2008/12/11 10:59:21 | 00,101,776 | ---- | M] (COMODO) inspect.sys -> %SystemRoot%\System32\drivers\inspect.sys -> [2008/12/11 10:59:21 | 00,079,504 | ---- | M] (COMODO) cmdhlp.sys -> %SystemRoot%\System32\drivers\cmdhlp.sys -> [2008/12/11 10:59:21 | 00,031,504 | ---- | M] (COMODO) CIS_Setup_3.5.57173.439_XP_Vista_x32.INI -> %SystemRoot%\CIS_Setup_3.5.57173.439_XP_Vista_x32.INI -> [2008/12/11 10:54:31 | 00,000,120 | ---- | M] () sqmdata14.sqm -> %SystemDrive%\sqmdata14.sqm -> [2008/12/08 22:01:04 | 00,000,236 | ---- | M] () sqmnoopt14.sqm -> %SystemDrive%\sqmnoopt14.sqm -> [2008/12/08 22:01:04 | 00,000,200 | ---- | M] () VETlog.dmp -> %SystemDrive%\VETlog.dmp -> [2008/12/08 18:54:52 | 00,084,577 | ---- | M] () win.ini -> %SystemRoot%\win.ini -> [2008/12/08 18:54:51 | 00,000,865 | ---- | M] () jsdf8j3dgf.dll -> %SystemRoot%\System32\jsdf8j3dgf.dll -> [2008/12/05 16:39:53 | 00,015,000 | ---- | M] () Ad-Watch.lnk -> %AllUsersProfile%\Desktop\Ad-Watch.lnk -> [2008/12/05 16:25:04 | 00,000,793 | ---- | M] () Ad-Aware.lnk -> %AllUsersProfile%\Desktop\Ad-Aware.lnk -> [2008/12/05 16:25:04 | 00,000,793 | ---- | M] () Desktop.lnk -> %AllUsersProfile%\Application Data\Desktop.lnk -> [2008/12/05 16:10:54 | 00,065,552 | -HS- | M] () system.ini -> %SystemRoot%\system.ini -> [2008/11/30 12:16:31 | 00,000,227 | ---- | M] () boot.ini -> %SystemDrive%\boot.ini -> [2008/11/30 12:16:31 | 00,000,211 | -HS- | M] () sqmdata13.sqm -> %SystemDrive%\sqmdata13.sqm -> [2008/11/28 12:37:27 | 00,000,236 | ---- | M] () sqmnoopt13.sqm -> %SystemDrive%\sqmnoopt13.sqm -> [2008/11/28 12:37:27 | 00,000,200 | ---- | M] () sqmdata12.sqm -> %SystemDrive%\sqmdata12.sqm -> [2008/11/27 20:36:55 | 00,000,236 | ---- | M] () sqmnoopt12.sqm -> %SystemDrive%\sqmnoopt12.sqm -> [2008/11/27 20:36:55 | 00,000,200 | ---- | M] () sqmdata11.sqm -> %SystemDrive%\sqmdata11.sqm -> [2008/11/22 19:04:25 | 00,000,236 | ---- | M] () sqmnoopt11.sqm -> %SystemDrive%\sqmnoopt11.sqm -> [2008/11/22 19:04:25 | 00,000,200 | ---- | M] () winpm77.dll -> %SystemRoot%\System32\winpm77.dll -> [2008/11/21 20:15:46 | 00,401,408 | ---- | M] () windi77.dll -> %SystemRoot%\System32\windi77.dll -> [2008/11/21 20:15:46 | 00,401,408 | ---- | M] () sqmdata10.sqm -> %SystemDrive%\sqmdata10.sqm -> [2008/11/21 19:23:23 | 00,000,236 | ---- | M] () sqmnoopt10.sqm -> %SystemDrive%\sqmnoopt10.sqm -> [2008/11/21 19:23:23 | 00,000,200 | ---- | M] () Spotify.lnk -> %UserProfile%\Desktop\Spotify.lnk -> [2008/11/21 11:45:50 | 00,000,666 | ---- | M] () Did you know.doc -> %UserProfile%\My Documents\Did you know.doc -> [2008/11/19 22:07:18 | 00,025,600 | ---- | M] () Yahoo! Messenger.lnk -> %AllUsersProfile%\Desktop\Yahoo! Messenger.lnk -> [2008/11/19 21:49:19 | 00,000,812 | ---- | M] () [File - Lop Check] Application Data -> C:\Documents and Settings\All Users\Application Data -> [2008/12/14 15:25:17 | 00,000,000 | RH-D | M] {3276BE95_AF08_429F_A64F_CA64CB79BCF6} -> C:\Documents and Settings\All Users\Application Data\{3276BE95_AF08_429F_A64F_CA64CB79BCF6} -> [2008/12/13 15:33:34 | 00,000,000 | ---D | M] avg7 -> C:\Documents and Settings\All Users\Application Data\avg7 -> [2007/09/13 17:48:50 | 00,000,000 | ---D | M] BVRP Software -> C:\Documents and Settings\All Users\Application Data\BVRP Software -> [2008/08/15 16:27:42 | 00,000,000 | ---D | M] DVD Shrink -> C:\Documents and Settings\All Users\Application Data\DVD Shrink -> [2008/04/26 17:55:22 | 00,000,000 | ---D | M] Elaborate Bytes -> C:\Documents and Settings\All Users\Application Data\Elaborate Bytes -> [2008/02/04 20:33:27 | 00,000,000 | ---D | M] FlashFXP -> C:\Documents and Settings\All Users\Application Data\FlashFXP -> [2008/12/14 15:25:17 | 00,000,000 | ---D | M] Grisoft -> C:\Documents and Settings\All Users\Application Data\Grisoft -> [2007/09/01 13:32:53 | 00,000,000 | ---D | M] Kontiki -> C:\Documents and Settings\All Users\Application Data\Kontiki -> [2008/12/11 11:03:05 | 00,000,000 | ---D | M] Messenger Plus! -> C:\Documents and Settings\All Users\Application Data\Messenger Plus! -> [2007/09/07 22:54:20 | 00,000,000 | ---D | M] Network Associates -> C:\Documents and Settings\All Users\Application Data\Network Associates -> [2005/11/07 22:48:20 | 00,000,000 | ---D | M] PopCap -> C:\Documents and Settings\All Users\Application Data\PopCap -> [2007/12/01 12:34:18 | 00,000,000 | ---D | M] Sky -> C:\Documents and Settings\All Users\Application Data\Sky -> [2008/06/09 14:56:31 | 00,000,000 | ---D | M] SlySoft -> C:\Documents and Settings\All Users\Application Data\SlySoft -> [2008/02/04 20:41:55 | 00,000,000 | ---D | M] Sony -> C:\Documents and Settings\All Users\Application Data\Sony -> [2008/10/15 16:22:55 | 00,000,000 | ---D | M] TEMP -> C:\Documents and Settings\All Users\Application Data\TEMP -> [2008/12/10 14:19:48 | 00,000,000 | ---D | M] Ulead Systems -> C:\Documents and Settings\All Users\Application Data\Ulead Systems -> [2005/11/07 23:47:51 | 00,000,000 | ---D | M] Viewpoint -> C:\Documents and Settings\All Users\Application Data\Viewpoint -> [2008/03/24 18:35:44 | 00,000,000 | ---D | M] Application Data -> C:\Documents and Settings\user\Application Data -> [2008/12/05 16:18:49 | 00,000,000 | RH-D | M] AVG7 -> C:\Documents and Settings\user\Application Data\AVG7 -> [2008/12/19 09:55:58 | 00,000,000 | ---D | M] Axara -> C:\Documents and Settings\user\Application Data\Axara -> [2008/03/23 23:59:20 | 00,000,000 | ---D | M] DMCache -> C:\Documents and Settings\user\Application Data\DMCache -> [2008/12/19 09:56:08 | 00,000,000 | ---D | M] DVD Flick -> C:\Documents and Settings\user\Application Data\DVD Flick -> [2008/05/02 14:16:02 | 00,000,000 | ---D | M] dvdcss -> C:\Documents and Settings\user\Application Data\dvdcss -> [2008/08/27 16:37:18 | 00,000,000 | ---D | M] gadcom -> C:\Documents and Settings\user\Application Data\gadcom -> [2008/12/11 11:09:01 | 00,000,000 | ---D | M] IDM -> C:\Documents and Settings\user\Application Data\IDM -> [2008/01/19 21:56:59 | 00,000,000 | ---D | M] InterVideo -> C:\Documents and Settings\user\Application Data\InterVideo -> [2005/11/07 23:31:03 | 00,000,000 | ---D | M] Kontiki -> C:\Documents and Settings\user\Application Data\Kontiki -> [2008/02/07 16:29:40 | 00,000,000 | ---D | M] Leadertech -> C:\Documents and Settings\user\Application Data\Leadertech -> [2008/10/15 16:25:19 | 00,000,000 | ---D | M] LimeWire -> C:\Documents and Settings\user\Application Data\LimeWire -> [2008/04/24 20:34:24 | 00,000,000 | ---D | M] NI.GSCNS -> C:\Documents and Settings\user\Application Data\NI.GSCNS -> [2008/12/19 09:59:38 | 00,000,000 | ---D | M] PRODEGETOOLBAR660 -> C:\Documents and Settings\user\Application Data\PRODEGETOOLBAR660 -> [2008/08/01 14:37:00 | 00,000,000 | ---D | M] Publish Providers -> C:\Documents and Settings\user\Application Data\Publish Providers -> [2007/10/02 00:03:04 | 00,000,000 | ---D | M] Skinux -> C:\Documents and Settings\user\Application Data\Skinux -> [2008/10/19 10:53:45 | 00,000,000 | ---D | M] Sony -> C:\Documents and Settings\user\Application Data\Sony -> [2007/10/01 23:54:03 | 00,000,000 | ---D | M] Sony Setup -> C:\Documents and Settings\user\Application Data\Sony Setup -> [2007/10/01 23:46:23 | 00,000,000 | ---D | M] Spotify -> C:\Documents and Settings\user\Application Data\Spotify -> [2008/12/19 14:08:51 | 00,000,000 | ---D | M] U3 -> C:\Documents and Settings\user\Application Data\U3 -> [2008/11/29 16:43:26 | 00,000,000 | ---D | M] Ulead Systems -> C:\Documents and Settings\user\Application Data\Ulead Systems -> [2008/05/02 15:12:39 | 00,000,000 | ---D | M] URSoft -> C:\Documents and Settings\user\Application Data\URSoft -> [2007/09/01 12:54:34 | 00,000,000 | ---D | M] uTorrent -> C:\Documents and Settings\user\Application Data\uTorrent -> [2008/12/15 23:52:38 | 00,000,000 | ---D | M] Viewpoint -> C:\Documents and Settings\user\Application Data\Viewpoint -> [2008/03/24 18:35:45 | 00,000,000 | ---D | M] WNR -> C:\Documents and Settings\user\Application Data\WNR -> [2008/04/24 21:05:03 | 00,000,000 | ---D | M] You've Got Pictures Screensaver -> C:\Documents and Settings\user\Application Data\You've Got Pictures Screensaver -> [2007/09/01 12:28:53 | 00,000,000 | ---D | M] zweitgeist -> C:\Documents and Settings\user\Application Data\zweitgeist -> [2008/10/24 19:14:17 | 00,000,000 | ---D | M] C:\WINDOWS\Tasks\ -> C:\WINDOWS\Tasks -> [2008/12/13 15:47:10 | 00,000,000 | --SD | M] desktop.ini -> C:\WINDOWS\Tasks\desktop.ini -> [2001/08/23 12:00:00 | 00,000,065 | RH-- | M] () EasyShare Registration Task.job -> C:\WINDOWS\Tasks\EasyShare Registration Task.job -> [2008/11/16 11:58:48 | 00,000,434 | ---- | M] () GoogleUpdateTaskUser.job -> C:\WINDOWS\Tasks\GoogleUpdateTaskUser.job -> [2008/12/19 14:19:34 | 00,001,192 | ---- | M] () SA.DAT -> C:\WINDOWS\Tasks\SA.DAT -> [2008/12/19 09:16:06 | 00,000,006 | -H-- | M] () [File - Purity Scan] [CatchMe Rootkit Scan by GMER] < Windows folder & sub-folders > detected NTDLL code modification: ZwClose scanning hidden processes ... IPC error: 2 The system cannot find the file specified. scanning hidden services & system hive ... [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\sptd\Cfg] "s1"=dword:2df9c43f "s2"=dword:110480d0 scanning hidden registry entries ... [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\Current Version\{8AC25C6A-D4B3-FF2F-2A61-C75CA1DB6116}\Install] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\Current Version\{8AC25C6A-D4B3-FF2F-2A61-C75CA1DB6116}\Install\VxDs] "CTE_32 Name"="2454374:{301564B2-67A6-1A66-9C4E-A1FE91DE9752}" [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Install] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Install\xga-1-{73564667-633C-2E05-0016-6A50D8D3E811}] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Install\xga-1-{73564667-633C-2E05-0016-6A50D8D3E811}\Version 1.1] "dat"="806585365:{29C76C5C-5EDD-7E0A-5241-E278FCE98EFC}" [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\z\{{05FF8CB8-4942-FCF6-301D-6930181DE865}}] "DefaultSettings"="2454395:{37C8840C-72FD-B1F6-4FC1-23A6EF5B6255}" [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\{FC4E112D-8EEE-C12A-3C90-E5335FD5626B}] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\{FC4E112D-8EEE-C12A-3C90-E5335FD5626B}\Install] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\{FC4E112D-8EEE-C12A-3C90-E5335FD5626B}\Install\xga-1] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\{FC4E112D-8EEE-C12A-3C90-E5335FD5626B}\Install\xga-1\dat] "default"="516233069:{F3952BAB-E1EA-EE2C-B99B-09DA84383F21}" [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows Install VBX] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows Install VBX\Current] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows Install VBX\Current\Install] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows Install VBX\Current\Install\xga-1-{73564667-633C-2E05-0016-6A50D8D3E811}] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows Install VBX\Current\Install\xga-1-{73564667-633C-2E05-0016-6A50D8D3E811}\Version 3.x] "dat"="1767914624:{3ED60E37-1E1B-69C5-85D3-37E5ED40D8B1}" scanning hidden files ... C:\WINDOWS\Cursors\arrow_n.cur:NEDTA.DAT 6144 bytes scan completed successfully hidden processes: 0 hidden services: 0 hidden files: 1 < Document and Settings folder & sub folders > detected NTDLL code modification: ZwClose scanning hidden files ... IPC error: 2 The system cannot find the file specified. C:\Documents and Settings\All Users\Application Data\TEMP:888AFB86 110 bytes C:\Documents and Settings\All Users\Application Data\TEMP:C4252FE0 98 bytes C:\Documents and Settings\user\Favorites\Old Version of Firefox Download.url:favicon 3638 bytes C:\Documents and Settings\user\Favorites\WIN STUFF FHM.com.url:favicon 318 bytes C:\Documents and Settings\user\Local Settings\Application Data\Microsoft\Messenger\beng94@hotmail.co.uk\SharingMetadata\alex_jones_24@hotmail.com\DFSR\Staging\CS{0924F739-20EF-8C70-D9BC-FD33851A2000}\01\15-{0924F739-20EF-8C70-D9BC-FD33851A2000}-v1-{4CCD7310-0415-4B53-92A8-5821840B4842}-v15-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.XPRESS 8 bytes hidden from API C:\Documents and Settings\user\Local Settings\Application Data\Microsoft\Messenger\beng94@hotmail.co.uk\SharingMetadata\devil_child_gemz_666@msn.com\DFSR\Staging\CS{E48C3A50-1ECD-68AC-7B37-998252BF8AE8}\01\10-{E48C3A50-1ECD-68AC-7B37-998252BF8AE8}-v1-{4CCD7310-0415-4B53-92A8-5821840B4842}-v10-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.XPRESS 8 bytes hidden from API C:\Documents and Settings\user\Local Settings\Application Data\Microsoft\Messenger\beng94@hotmail.co.uk\SharingMetadata\devil_child_gemz_666@msn.com\DFSR\Staging\CS{E48C3A50-1ECD-68AC-7B37-998252BF8AE8}\01\489-{9F7BBD04-3A40-4EA7-AA6C-A228A9054F61}-v101-{29B9D68D-3441-4E85-852E-30B870698093}-v489-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.XPRESS 5304 bytes hidden from API C:\Documents and Settings\user\Local Settings\Application Data\Microsoft\Messenger\beng94@hotmail.co.uk\SharingMetadata\devil_child_gemz_666@msn.com\DFSR\Staging\CS{E48C3A50-1ECD-68AC-7B37-998252BF8AE8}\41\89-{29B9D68D-3441-4E85-852E-30B870698093}-v41-{29B9D68D-3441-4E85-852E-30B870698093}-v89-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.XPRESS 4080 bytes hidden from API C:\Documents and Settings\user\Local Settings\Application Data\Microsoft\Messenger\beng94@hotmail.co.uk\SharingMetadata\devil_child_gemz_666@msn.com\DFSR\Staging\CS{E48C3A50-1ECD-68AC-7B37-998252BF8AE8}\42\43-{29B9D68D-3441-4E85-852E-30B870698093}-v42-{9F7BBD04-3A40-4EA7-AA6C-A228A9054F61}-v43-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.XPRESS 4976 bytes hidden from API C:\Documents and Settings\user\Local Settings\Application Data\Microsoft\Messenger\beng94@hotmail.co.uk\SharingMetadata\devil_child_gemz_666@msn.com\DFSR\Staging\CS{E48C3A50-1ECD-68AC-7B37-998252BF8AE8}\52\21-{9F7BBD04-3A40-4EA7-AA6C-A228A9054F61}-v52-{D52673F4-BF6F-4C96-BB33-F322E80AE62F}-v21-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.XPRESS 6544 bytes hidden from API C:\Documents and Settings\user\Local Settings\Application Data\Microsoft\Messenger\beng94@hotmail.co.uk\SharingMetadata\devil_child_gemz_666@msn.com\DFSR\Staging\CS{E48C3A50-1ECD-68AC-7B37-998252BF8AE8}\55\108-{9F7BBD04-3A40-4EA7-AA6C-A228A9054F61}-v55-{29B9D68D-3441-4E85-852E-30B870698093}-v108-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.XPRESS 6872 bytes hidden from API C:\Documents and Settings\user\Local Settings\Application Data\Microsoft\Messenger\beng94@hotmail.co.uk\SharingMetadata\devil_child_gemz_666@msn.com\DFSR\Staging\CS{E48C3A50-1ECD-68AC-7B37-998252BF8AE8}\77\77-{29B9D68D-3441-4E85-852E-30B870698093}-v77-{29B9D68D-3441-4E85-852E-30B870698093}-v77-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.XPRESS 4272 bytes hidden from API C:\Documents and Settings\user\Local Settings\Application Data\Microsoft\Messenger\beng94@hotmail.co.uk\SharingMetadata\devil_child_gemz_666@msn.com\DFSR\Staging\CS{E48C3A50-1ECD-68AC-7B37-998252BF8AE8}\78\100-{9F7BBD04-3A40-4EA7-AA6C-A228A9054F61}-v78-{29B9D68D-3441-4E85-852E-30B870698093}-v100-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.rdc.1 33096 bytes hidden from API C:\Documents and Settings\user\Local Settings\Application Data\Microsoft\Messenger\beng94@hotmail.co.uk\SharingMetadata\devil_child_gemz_666@msn.com\DFSR\Staging\CS{E48C3A50-1ECD-68AC-7B37-998252BF8AE8}\78\100-{9F7BBD04-3A40-4EA7-AA6C-A228A9054F61}-v78-{29B9D68D-3441-4E85-852E-30B870698093}-v100-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.XPRESS 3680 bytes hidden from API C:\Documents and Settings\user\Local Settings\Application Data\Microsoft\Messenger\beng94@hotmail.co.uk\SharingMetadata\devil_child_gemz_666@msn.com\DFSR\Staging\CS{E48C3A50-1ECD-68AC-7B37-998252BF8AE8}\88\118-{29B9D68D-3441-4E85-852E-30B870698093}-v88-{29B9D68D-3441-4E85-852E-30B870698093}-v118-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.XPRESS 4144 bytes hidden from API C:\Documents and Settings\user\Local Settings\Application Data\Microsoft\Messenger\beng94@hotmail.co.uk\SharingMetadata\devil_child_gemz_666@msn.com\DFSR\Staging\CS{E48C3A50-1ECD-68AC-7B37-998252BF8AE8}\92\92-{29B9D68D-3441-4E85-852E-30B870698093}-v92-{29B9D68D-3441-4E85-852E-30B870698093}-v92-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.XPRESS 3496 bytes hidden from API C:\Documents and Settings\user\Local Settings\Application Data\Microsoft\Messenger\beng94@hotmail.co.uk\SharingMetadata\jkheadshot@hotmail.com\DFSR\Staging\CS{BC95C86C-5C41-767B-E134-DD32D57D4DC5}\01\12-{BC95C86C-5C41-767B-E134-DD32D57D4DC5}-v1-{4CCD7310-0415-4B53-92A8-5821840B4842}-v12-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.XPRESS 8 bytes hidden from API C:\Documents and Settings\user\Local Settings\Application Data\Microsoft\Messenger\beng94@hotmail.co.uk\SharingMetadata\juberislam65@hotmail.com\DFSR\Staging\CS{4DB4292E-489D-6067-9065-56782AD52AC0}\00\22-{9F7BBD04-3A40-4EA7-AA6C-A228A9054F61}-v100-{704A2292-B435-499D-8C69-2E7DDDB0BCD8}-v22-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.rdc.1 53994 bytes hidden from API C:\Documents and Settings\user\Local Settings\Application Data\Microsoft\Messenger\beng94@hotmail.co.uk\SharingMetadata\juberislam65@hotmail.com\DFSR\Staging\CS{4DB4292E-489D-6067-9065-56782AD52AC0}\00\22-{9F7BBD04-3A40-4EA7-AA6C-A228A9054F61}-v100-{704A2292-B435-499D-8C69-2E7DDDB0BCD8}-v22-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.rdc.2 3792 bytes hidden from API C:\Documents and Settings\user\Local Settings\Application Data\Microsoft\Messenger\beng94@hotmail.co.uk\SharingMetadata\juberislam65@hotmail.com\DFSR\Staging\CS{4DB4292E-489D-6067-9065-56782AD52AC0}\00\22-{9F7BBD04-3A40-4EA7-AA6C-A228A9054F61}-v100-{704A2292-B435-499D-8C69-2E7DDDB0BCD8}-v22-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.XPRESS 5944 bytes hidden from API C:\Documents and Settings\user\Local Settings\Application Data\Microsoft\Messenger\beng94@hotmail.co.uk\SharingMetadata\juberislam65@hotmail.com\DFSR\Staging\CS{4DB4292E-489D-6067-9065-56782AD52AC0}\01\16-{4DB4292E-489D-6067-9065-56782AD52AC0}-v1-{4CCD7310-0415-4B53-92A8-5821840B4842}-v16-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.XPRESS 8 bytes hidden from API C:\Documents and Settings\user\Local Settings\Application Data\Microsoft\Messenger\beng94@hotmail.co.uk\SharingMetadata\juberislam65@hotmail.com\DFSR\Staging\CS{4DB4292E-489D-6067-9065-56782AD52AC0}\03\103-{9F7BBD04-3A40-4EA7-AA6C-A228A9054F61}-v103-{9F7BBD04-3A40-4EA7-AA6C-A228A9054F61}-v103-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.rdc.1 47676 bytes hidden from API C:\Documents and Settings\user\Local Settings\Application Data\Microsoft\Messenger\beng94@hotmail.co.uk\SharingMetadata\juberislam65@hotmail.com\DFSR\Staging\CS{4DB4292E-489D-6067-9065-56782AD52AC0}\03\103-{9F7BBD04-3A40-4EA7-AA6C-A228A9054F61}-v103-{9F7BBD04-3A40-4EA7-AA6C-A228A9054F61}-v103-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.rdc.2 3216 bytes hidden from API C:\Documents and Settings\user\Local Settings\Application Data\Microsoft\Messenger\beng94@hotmail.co.uk\SharingMetadata\juberislam65@hotmail.com\DFSR\Staging\CS{4DB4292E-489D-6067-9065-56782AD52AC0}\03\103-{9F7BBD04-3A40-4EA7-AA6C-A228A9054F61}-v103-{9F7BBD04-3A40-4EA7-AA6C-A228A9054F61}-v103-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.XPRESS 5304 bytes hidden from API C:\Documents and Settings\user\Local Settings\Application Data\Microsoft\Messenger\beng94@hotmail.co.uk\SharingMetadata\juberislam65@hotmail.com\DFSR\Staging\CS{4DB4292E-489D-6067-9065-56782AD52AC0}\12\12-{CD1FC311-3236-4220-81FD-FA2A4175B22B}-v12-{CD1FC311-3236-4220-81FD-FA2A4175B22B}-v12-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.rdc.1 45948 bytes hidden from API C:\Documents and Settings\user\Local Settings\Application Data\Microsoft\Messenger\beng94@hotmail.co.uk\SharingMetadata\juberislam65@hotmail.com\DFSR\Staging\CS{4DB4292E-489D-6067-9065-56782AD52AC0}\12\12-{CD1FC311-3236-4220-81FD-FA2A4175B22B}-v12-{CD1FC311-3236-4220-81FD-FA2A4175B22B}-v12-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.rdc.2 3396 bytes hidden from API C:\Documents and Settings\user\Local Settings\Application Data\Microsoft\Messenger\beng94@hotmail.co.uk\SharingMetadata\juberislam65@hotmail.com\DFSR\Staging\CS{4DB4292E-489D-6067-9065-56782AD52AC0}\12\12-{CD1FC311-3236-4220-81FD-FA2A4175B22B}-v12-{CD1FC311-3236-4220-81FD-FA2A4175B22B}-v12-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.XPRESS 5072 bytes hidden from API C:\Documents and Settings\user\Local Settings\Application Data\Microsoft\Messenger\beng94@hotmail.co.uk\SharingMetadata\juberislam65@hotmail.com\DFSR\Staging\CS{4DB4292E-489D-6067-9065-56782AD52AC0}\17\17-{4CCD7310-0415-4B53-92A8-5821840B4842}-v17-{4CCD7310-0415-4B53-92A8-5821840B4842}-v17-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.rdc.1 33294 bytes hidden from API C:\Documents and Settings\user\Local Settings\Application Data\Microsoft\Messenger\beng94@hotmail.co.uk\SharingMetadata\juberislam65@hotmail.com\DFSR\Staging\CS{4DB4292E-489D-6067-9065-56782AD52AC0}\17\17-{4CCD7310-0415-4B53-92A8-5821840B4842}-v17-{4CCD7310-0415-4B53-92A8-5821840B4842}-v17-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.rdc.2 2388 bytes hidden from API C:\Documents and Settings\user\Local Settings\Application Data\Microsoft\Messenger\beng94@hotmail.co.uk\SharingMetadata\juberislam65@hotmail.com\DFSR\Staging\CS{4DB4292E-489D-6067-9065-56782AD52AC0}\17\17-{4CCD7310-0415-4B53-92A8-5821840B4842}-v17-{4CCD7310-0415-4B53-92A8-5821840B4842}-v17-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.XPRESS 3776 bytes hidden from API C:\Documents and Settings\user\Local Settings\Application Data\Microsoft\Messenger\beng94@hotmail.co.uk\SharingMetadata\juberislam65@hotmail.com\DFSR\Staging\CS{4DB4292E-489D-6067-9065-56782AD52AC0}\19\19-{9723354D-2E47-48FC-ABF6-D9A3170D3AE5}-v19-{9723354D-2E47-48FC-ABF6-D9A3170D3AE5}-v19-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.XPRESS 6184 bytes hidden from API C:\Documents and Settings\user\Local Settings\Application Data\Microsoft\Messenger\beng94@hotmail.co.uk\SharingMetadata\juberislam65@hotmail.com\DFSR\Staging\CS{4DB4292E-489D-6067-9065-56782AD52AC0}\81\18-{9F7BBD04-3A40-4EA7-AA6C-A228A9054F61}-v81-{9723354D-2E47-48FC-ABF6-D9A3170D3AE5}-v18-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.XPRESS 5760 bytes hidden from API C:\Documents and Settings\user\Local Settings\Application Data\Microsoft\Messenger\beng94@hotmail.co.uk\SharingMetadata\juberislam65@hotmail.com\DFSR\Staging\CS{4DB4292E-489D-6067-9065-56782AD52AC0}\84\84-{9F7BBD04-3A40-4EA7-AA6C-A228A9054F61}-v84-{9F7BBD04-3A40-4EA7-AA6C-A228A9054F61}-v84-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.rdc.1 35778 bytes hidden from API C:\Documents and Settings\user\Local Settings\Application Data\Microsoft\Messenger\beng94@hotmail.co.uk\SharingMetadata\juberislam65@hotmail.com\DFSR\Staging\CS{4DB4292E-489D-6067-9065-56782AD52AC0}\84\84-{9F7BBD04-3A40-4EA7-AA6C-A228A9054F61}-v84-{9F7BBD04-3A40-4EA7-AA6C-A228A9054F61}-v84-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.rdc.2 2640 bytes hidden from API C:\Documents and Settings\user\Local Settings\Application Data\Microsoft\Messenger\beng94@hotmail.co.uk\SharingMetadata\juberislam65@hotmail.com\DFSR\Staging\CS{4DB4292E-489D-6067-9065-56782AD52AC0}\84\84-{9F7BBD04-3A40-4EA7-AA6C-A228A9054F61}-v84-{9F7BBD04-3A40-4EA7-AA6C-A228A9054F61}-v84-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.XPRESS 3960 bytes hidden from API C:\Documents and Settings\user\Local Settings\Application Data\Microsoft\Messenger\beng94@hotmail.co.uk\SharingMetadata\juberislam65@hotmail.com\DFSR\Staging\CS{4DB4292E-489D-6067-9065-56782AD52AC0}\85\15-{9F7BBD04-3A40-4EA7-AA6C-A228A9054F61}-v85-{704A2292-B435-499D-8C69-2E7DDDB0BCD8}-v15-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.XPRESS 2832 bytes hidden from API C:\Documents and Settings\user\Local Settings\Application Data\Microsoft\Messenger\beng94@hotmail.co.uk\SharingMetadata\juberislam65@hotmail.com\DFSR\Staging\CS{4DB4292E-489D-6067-9065-56782AD52AC0}\87\16-{9F7BBD04-3A40-4EA7-AA6C-A228A9054F61}-v87-{704A2292-B435-499D-8C69-2E7DDDB0BCD8}-v16-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.XPRESS 3088 bytes hidden from API C:\Documents and Settings\user\Local Settings\Application Data\Microsoft\Messenger\beng94@hotmail.co.uk\SharingMetadata\juberislam65@hotmail.com\DFSR\Staging\CS{4DB4292E-489D-6067-9065-56782AD52AC0}\89\89-{9F7BBD04-3A40-4EA7-AA6C-A228A9054F61}-v89-{9F7BBD04-3A40-4EA7-AA6C-A228A9054F61}-v89-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.rdc.1 46794 bytes hidden from API C:\Documents and Settings\user\Local Settings\Application Data\Microsoft\Messenger\beng94@hotmail.co.uk\SharingMetadata\juberislam65@hotmail.com\DFSR\Staging\CS{4DB4292E-489D-6067-9065-56782AD52AC0}\89\89-{9F7BBD04-3A40-4EA7-AA6C-A228A9054F61}-v89-{9F7BBD04-3A40-4EA7-AA6C-A228A9054F61}-v89-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.rdc.2 3180 bytes hidden from API C:\Documents and Settings\user\Local Settings\Application Data\Microsoft\Messenger\beng94@hotmail.co.uk\SharingMetadata\juberislam65@hotmail.com\DFSR\Staging\CS{4DB4292E-489D-6067-9065-56782AD52AC0}\89\89-{9F7BBD04-3A40-4EA7-AA6C-A228A9054F61}-v89-{9F7BBD04-3A40-4EA7-AA6C-A228A9054F61}-v89-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.XPRESS 5416 bytes hidden from API C:\Documents and Settings\user\Local Settings\Application Data\Microsoft\Messenger\beng94@hotmail.co.uk\SharingMetadata\juberislam65@hotmail.com\DFSR\Staging\CS{4DB4292E-489D-6067-9065-56782AD52AC0}\90\26-{9F7BBD04-3A40-4EA7-AA6C-A228A9054F61}-v90-{704A2292-B435-499D-8C69-2E7DDDB0BCD8}-v26-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.rdc.1 37758 bytes hidden from API C:\Documents and Settings\user\Local Settings\Application Data\Microsoft\Messenger\beng94@hotmail.co.uk\SharingMetadata\juberislam65@hotmail.com\DFSR\Staging\CS{4DB4292E-489D-6067-9065-56782AD52AC0}\90\26-{9F7BBD04-3A40-4EA7-AA6C-A228A9054F61}-v90-{704A2292-B435-499D-8C69-2E7DDDB0BCD8}-v26-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.rdc.2 2694 bytes hidden from API C:\Documents and Settings\user\Local Settings\Application Data\Microsoft\Messenger\beng94@hotmail.co.uk\SharingMetadata\juberislam65@hotmail.com\DFSR\Staging\CS{4DB4292E-489D-6067-9065-56782AD52AC0}\90\26-{9F7BBD04-3A40-4EA7-AA6C-A228A9054F61}-v90-{704A2292-B435-499D-8C69-2E7DDDB0BCD8}-v26-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.XPRESS 4240 bytes hidden from API C:\Documents and Settings\user\Local Settings\Application Data\Microsoft\Messenger\beng94@hotmail.co.uk\SharingMetadata\juberislam65@hotmail.com\DFSR\Staging\CS{4DB4292E-489D-6067-9065-56782AD52AC0}\91\17-{9F7BBD04-3A40-4EA7-AA6C-A228A9054F61}-v91-{704A2292-B435-499D-8C69-2E7DDDB0BCD8}-v17-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.XPRESS 5752 bytes hidden from API C:\Documents and Settings\user\Local Settings\Application Data\Microsoft\Messenger\beng94@hotmail.co.uk\SharingMetadata\juberislam65@hotmail.com\DFSR\Staging\CS{4DB4292E-489D-6067-9065-56782AD52AC0}\92\18-{9F7BBD04-3A40-4EA7-AA6C-A228A9054F61}-v92-{704A2292-B435-499D-8C69-2E7DDDB0BCD8}-v18-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.XPRESS 5552 bytes hidden from API C:\Documents and Settings\user\Local Settings\Application Data\Microsoft\Messenger\beng94@hotmail.co.uk\SharingMetadata\juberislam65@hotmail.com\DFSR\Staging\CS{4DB4292E-489D-6067-9065-56782AD52AC0}\93\25-{9F7BBD04-3A40-4EA7-AA6C-A228A9054F61}-v93-{704A2292-B435-499D-8C69-2E7DDDB0BCD8}-v25-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.rdc.1 48756 bytes hidden from API C:\Documents and Settings\user\Local Settings\Application Data\Microsoft\Messenger\beng94@hotmail.co.uk\SharingMetadata\juberislam65@hotmail.com\DFSR\Staging\CS{4DB4292E-489D-6067-9065-56782AD52AC0}\93\25-{9F7BBD04-3A40-4EA7-AA6C-A228A9054F61}-v93-{704A2292-B435-499D-8C69-2E7DDDB0BCD8}-v25-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.rdc.2 3522 bytes hidden from API C:\Documents and Settings\user\Local Settings\Application Data\Microsoft\Messenger\beng94@hotmail.co.uk\SharingMetadata\juberislam65@hotmail.com\DFSR\Staging\CS{4DB4292E-489D-6067-9065-56782AD52AC0}\93\25-{9F7BBD04-3A40-4EA7-AA6C-A228A9054F61}-v93-{704A2292-B435-499D-8C69-2E7DDDB0BCD8}-v25-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.XPRESS 5472 bytes hidden from API C:\Documents and Settings\user\Local Settings\Application Data\Microsoft\Messenger\beng94@hotmail.co.uk\SharingMetadata\juberislam65@hotmail.com\DFSR\Staging\CS{4DB4292E-489D-6067-9065-56782AD52AC0}\94\94-{9F7BBD04-3A40-4EA7-AA6C-A228A9054F61}-v94-{9F7BBD04-3A40-4EA7-AA6C-A228A9054F61}-v94-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.rdc.1 26148 bytes hidden from API C:\Documents and Settings\user\Local Settings\Application Data\Microsoft\Messenger\beng94@hotmail.co.uk\SharingMetadata\juberislam65@hotmail.com\DFSR\Staging\CS{4DB4292E-489D-6067-9065-56782AD52AC0}\94\94-{9F7BBD04-3A40-4EA7-AA6C-A228A9054F61}-v94-{9F7BBD04-3A40-4EA7-AA6C-A228A9054F61}-v94-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.rdc.2 1920 bytes hidden from API C:\Documents and Settings\user\Local Settings\Application Data\Microsoft\Messenger\beng94@hotmail.co.uk\SharingMetadata\juberislam65@hotmail.com\DFSR\Staging\CS{4DB4292E-489D-6067-9065-56782AD52AC0}\94\94-{9F7BBD04-3A40-4EA7-AA6C-A228A9054F61}-v94-{9F7BBD04-3A40-4EA7-AA6C-A228A9054F61}-v94-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.XPRESS 2928 bytes hidden from API C:\Documents and Settings\user\Local Settings\Application Data\Microsoft\Messenger\beng94@hotmail.co.uk\SharingMetadata\juberislam65@hotmail.com\DFSR\Staging\CS{4DB4292E-489D-6067-9065-56782AD52AC0}\95\95-{9F7BBD04-3A40-4EA7-AA6C-A228A9054F61}-v95-{9F7BBD04-3A40-4EA7-AA6C-A228A9054F61}-v95-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.rdc.1 37740 bytes hidden from API C:\Documents and Settings\user\Local Settings\Application Data\Microsoft\Messenger\beng94@hotmail.co.uk\SharingMetadata\juberislam65@hotmail.com\DFSR\Staging\CS{4DB4292E-489D-6067-9065-56782AD52AC0}\95\95-{9F7BBD04-3A40-4EA7-AA6C-A228A9054F61}-v95-{9F7BBD04-3A40-4EA7-AA6C-A228A9054F61}-v95-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.rdc.2 2676 bytes hidden from API C:\Documents and Settings\user\Local Settings\Application Data\Microsoft\Messenger\beng94@hotmail.co.uk\SharingMetadata\juberislam65@hotmail.com\DFSR\Staging\CS{4DB4292E-489D-6067-9065-56782AD52AC0}\95\95-{9F7BBD04-3A40-4EA7-AA6C-A228A9054F61}-v95-{9F7BBD04-3A40-4EA7-AA6C-A228A9054F61}-v95-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.XPRESS 4144 bytes hidden from API C:\Documents and Settings\user\Local Settings\Application Data\Microsoft\Messenger\beng94@hotmail.co.uk\SharingMetadata\juberislam65@hotmail.com\DFSR\Staging\CS{4DB4292E-489D-6067-9065-56782AD52AC0}\96\19-{9F7BBD04-3A40-4EA7-AA6C-A228A9054F61}-v96-{704A2292-B435-499D-8C69-2E7DDDB0BCD8}-v19-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.XPRESS 5352 bytes hidden from API C:\Documents and Settings\user\Local Settings\Application Data\Microsoft\Messenger\beng94@hotmail.co.uk\SharingMetadata\juberislam65@hotmail.com\DFSR\Staging\CS{4DB4292E-489D-6067-9065-56782AD52AC0}\97\20-{9F7BBD04-3A40-4EA7-AA6C-A228A9054F61}-v97-{704A2292-B435-499D-8C69-2E7DDDB0BCD8}-v20-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.rdc.1 58368 bytes hidden from API C:\Documents and Settings\user\Local Settings\Application Data\Microsoft\Messenger\beng94@hotmail.co.uk\SharingMetadata\juberislam65@hotmail.com\DFSR\Staging\CS{4DB4292E-489D-6067-9065-56782AD52AC0}\97\20-{9F7BBD04-3A40-4EA7-AA6C-A228A9054F61}-v97-{704A2292-B435-499D-8C69-2E7DDDB0BCD8}-v20-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.rdc.2 4062 bytes hidden from API C:\Documents and Settings\user\Local Settings\Application Data\Microsoft\Messenger\beng94@hotmail.co.uk\SharingMetadata\juberislam65@hotmail.com\DFSR\Staging\CS{4DB4292E-489D-6067-9065-56782AD52AC0}\97\20-{9F7BBD04-3A40-4EA7-AA6C-A228A9054F61}-v97-{704A2292-B435-499D-8C69-2E7DDDB0BCD8}-v20-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.XPRESS 6944 bytes hidden from API C:\Documents and Settings\user\Local Settings\Application Data\Microsoft\Messenger\beng94@hotmail.co.uk\SharingMetadata\juberislam65@hotmail.com\DFSR\Staging\CS{4DB4292E-489D-6067-9065-56782AD52AC0}\98\98-{9F7BBD04-3A40-4EA7-AA6C-A228A9054F61}-v98-{9F7BBD04-3A40-4EA7-AA6C-A228A9054F61}-v98-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.rdc.1 68070 bytes hidden from API C:\Documents and Settings\user\Local Settings\Application Data\Microsoft\Messenger\beng94@hotmail.co.uk\SharingMetadata\juberislam65@hotmail.com\DFSR\Staging\CS{4DB4292E-489D-6067-9065-56782AD52AC0}\98\98-{9F7BBD04-3A40-4EA7-AA6C-A228A9054F61}-v98-{9F7BBD04-3A40-4EA7-AA6C-A228A9054F61}-v98-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.rdc.2 4800 bytes hidden from API C:\Documents and Settings\user\Local Settings\Application Data\Microsoft\Messenger\beng94@hotmail.co.uk\SharingMetadata\juberislam65@hotmail.com\DFSR\Staging\CS{4DB4292E-489D-6067-9065-56782AD52AC0}\98\98-{9F7BBD04-3A40-4EA7-AA6C-A228A9054F61}-v98-{9F7BBD04-3A40-4EA7-AA6C-A228A9054F61}-v98-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.XPRESS 7656 bytes hidden from API C:\Documents and Settings\user\Local Settings\Application Data\Microsoft\Messenger\beng94@hotmail.co.uk\SharingMetadata\juberislam65@hotmail.com\DFSR\Staging\CS{4DB4292E-489D-6067-9065-56782AD52AC0}\99\21-{9F7BBD04-3A40-4EA7-AA6C-A228A9054F61}-v99-{704A2292-B435-499D-8C69-2E7DDDB0BCD8}-v21-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.rdc.1 61032 bytes hidden from API C:\Documents and Settings\user\Local Settings\Application Data\Microsoft\Messenger\beng94@hotmail.co.uk\SharingMetadata\juberislam65@hotmail.com\DFSR\Staging\CS{4DB4292E-489D-6067-9065-56782AD52AC0}\99\21-{9F7BBD04-3A40-4EA7-AA6C-A228A9054F61}-v99-{704A2292-B435-499D-8C69-2E7DDDB0BCD8}-v21-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.rdc.2 4368 bytes hidden from API C:\Documents and Settings\user\Local Settings\Application Data\Microsoft\Messenger\beng94@hotmail.co.uk\SharingMetadata\juberislam65@hotmail.com\DFSR\Staging\CS{4DB4292E-489D-6067-9065-56782AD52AC0}\99\21-{9F7BBD04-3A40-4EA7-AA6C-A228A9054F61}-v99-{704A2292-B435-499D-8C69-2E7DDDB0BCD8}-v21-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.XPRESS 6832 bytes hidden from API C:\Documents and Settings\user\Local Settings\Application Data\Microsoft\Messenger\beng94@hotmail.co.uk\SharingMetadata\rob_the_cobbler@hotmail.com\DFSR\Staging\CS{3610EE36-F3E8-4E2E-80D3-BFC7AC0FB450}\01\13-{3610EE36-F3E8-4E2E-80D3-BFC7AC0FB450}-v1-{4CCD7310-0415-4B53-92A8-5821840B4842}-v13-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.XPRESS 8 bytes hidden from API C:\Documents and Settings\user\Local Settings\Application Data\Microsoft\Messenger\beng94@hotmail.co.uk\SharingMetadata\rob_the_cobbler@hotmail.com\DFSR\Staging\CS{3610EE36-F3E8-4E2E-80D3-BFC7AC0FB450}\73\71-{9F7BBD04-3A40-4EA7-AA6C-A228A9054F61}-v73-{D1424A49-C8B5-4A51-9A9E-5ED7E2D4DAC1}-v71-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.rdc.1 2226 bytes hidden from API C:\Documents and Settings\user\Local Settings\Application Data\Microsoft\Messenger\beng94@hotmail.co.uk\SharingMetadata\rob_the_cobbler@hotmail.com\DFSR\Staging\CS{3610EE36-F3E8-4E2E-80D3-BFC7AC0FB450}\73\71-{9F7BBD04-3A40-4EA7-AA6C-A228A9054F61}-v73-{D1424A49-C8B5-4A51-9A9E-5ED7E2D4DAC1}-v71-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.XPRESS 248 bytes hidden from API C:\Documents and Settings\user\Local Settings\Application Data\Microsoft\Messenger\beng94@hotmail.co.uk\SharingMetadata\simon.pike@ntlworld.com\DFSR\Staging\CS{435BAA20-08F3-EFE1-F529-9FB781A68D97}\01\11-{435BAA20-08F3-EFE1-F529-9FB781A68D97}-v1-{4CCD7310-0415-4B53-92A8-5821840B4842}-v11-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.XPRESS 8 bytes hidden from API C:\Documents and Settings\user\Local Settings\Application Data\Microsoft\Messenger\beng94@hotmail.co.uk\SharingMetadata\vanquished2k@msn.com\DFSR\Staging\CS{AB3BD19F-BF50-B2DA-2E30-B0B286654983}\01\14-{AB3BD19F-BF50-B2DA-2E30-B0B286654983}-v1-{4CCD7310-0415-4B53-92A8-5821840B4842}-v14-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.XPRESS 8 bytes hidden from API C:\Documents and Settings\user\Local Settings\Application Data\Microsoft\Messenger\beng94@hotmail.co.uk\SharingMetadata\x_bethkxox@hotmail.co.uk\DFSR\Staging\CS{0AE1F3C4-D331-AC84-08E9-3DB4BAD6CD8B}\01\20-{0AE1F3C4-D331-AC84-08E9-3DB4BAD6CD8B}-v1-{4CCD7310-0415-4B53-92A8-5821840B4842}-v20-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.XPRESS 8 bytes hidden from API C:\Documents and Settings\user\Local Settings\Application Data\Microsoft\Messenger\beng94@hotmail.co.uk\SharingMetadata\x_bethkxox@hotmail.co.uk\DFSR\Staging\CS{0AE1F3C4-D331-AC84-08E9-3DB4BAD6CD8B}\21\21-{4CCD7310-0415-4B53-92A8-5821840B4842}-v21-{4CCD7310-0415-4B53-92A8-5821840B4842}-v21-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.rdc.1 69744 bytes hidden from API C:\Documents and Settings\user\Local Settings\Application Data\Microsoft\Messenger\beng94@hotmail.co.uk\SharingMetadata\x_bethkxox@hotmail.co.uk\DFSR\Staging\CS{0AE1F3C4-D331-AC84-08E9-3DB4BAD6CD8B}\21\21-{4CCD7310-0415-4B53-92A8-5821840B4842}-v21-{4CCD7310-0415-4B53-92A8-5821840B4842}-v21-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.rdc.2 4854 bytes hidden from API C:\Documents and Settings\user\Local Settings\Application Data\Microsoft\Messenger\beng94@hotmail.co.uk\SharingMetadata\x_bethkxox@hotmail.co.uk\DFSR\Staging\CS{0AE1F3C4-D331-AC84-08E9-3DB4BAD6CD8B}\21\21-{4CCD7310-0415-4B53-92A8-5821840B4842}-v21-{4CCD7310-0415-4B53-92A8-5821840B4842}-v21-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.XPRESS 7688 bytes hidden from API C:\Documents and Settings\user\Local Settings\Application Data\Microsoft\Messenger\beng94@hotmail.co.uk\SharingMetadata\x_bethkxox@hotmail.co.uk\DFSR\Staging\CS{0AE1F3C4-D331-AC84-08E9-3DB4BAD6CD8B}\22\22-{4CCD7310-0415-4B53-92A8-5821840B4842}-v22-{4CCD7310-0415-4B53-92A8-5821840B4842}-v22-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.rdc.1 20910 bytes hidden from API C:\Documents and Settings\user\Local Settings\Application Data\Microsoft\Messenger\beng94@hotmail.co.uk\SharingMetadata\x_bethkxox@hotmail.co.uk\DFSR\Staging\CS{0AE1F3C4-D331-AC84-08E9-3DB4BAD6CD8B}\22\22-{4CCD7310-0415-4B53-92A8-5821840B4842}-v22-{4CCD7310-0415-4B53-92A8-5821840B4842}-v22-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.rdc.2 1524 bytes hidden from API C:\Documents and Settings\user\Local Settings\Application Data\Microsoft\Messenger\beng94@hotmail.co.uk\SharingMetadata\x_bethkxox@hotmail.co.uk\DFSR\Staging\CS{0AE1F3C4-D331-AC84-08E9-3DB4BAD6CD8B}\22\22-{4CCD7310-0415-4B53-92A8-5821840B4842}-v22-{4CCD7310-0415-4B53-92A8-5821840B4842}-v22-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.XPRESS 2352 bytes hidden from API C:\Documents and Settings\user\Local Settings\Application Data\Microsoft\Messenger\beng94@hotmail.co.uk\SharingMetadata\x_bethkxox@hotmail.co.uk\DFSR\Staging\CS{0AE1F3C4-D331-AC84-08E9-3DB4BAD6CD8B}\23\23-{4CCD7310-0415-4B53-92A8-5821840B4842}-v23-{4CCD7310-0415-4B53-92A8-5821840B4842}-v23-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.rdc.1 66162 bytes hidden from API C:\Documents and Settings\user\Local Settings\Application Data\Microsoft\Messenger\beng94@hotmail.co.uk\SharingMetadata\x_bethkxox@hotmail.co.uk\DFSR\Staging\CS{0AE1F3C4-D331-AC84-08E9-3DB4BAD6CD8B}\23\23-{4CCD7310-0415-4B53-92A8-5821840B4842}-v23-{4CCD7310-0415-4B53-92A8-5821840B4842}-v23-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.rdc.2 4854 bytes hidden from API C:\Documents and Settings\user\Local Settings\Application Data\Microsoft\Messenger\beng94@hotmail.co.uk\SharingMetadata\x_bethkxox@hotmail.co.uk\DFSR\Staging\CS{0AE1F3C4-D331-AC84-08E9-3DB4BAD6CD8B}\23\23-{4CCD7310-0415-4B53-92A8-5821840B4842}-v23-{4CCD7310-0415-4B53-92A8-5821840B4842}-v23-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.XPRESS 7320 bytes hidden from API C:\Documents and Settings\user\Local Settings\Application Data\Microsoft\Messenger\beng94@hotmail.co.uk\SharingMetadata\x_bethkxox@hotmail.co.uk\DFSR\Staging\CS{0AE1F3C4-D331-AC84-08E9-3DB4BAD6CD8B}\24\24-{4CCD7310-0415-4B53-92A8-5821840B4842}-v24-{4CCD7310-0415-4B53-92A8-5821840B4842}-v24-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.rdc.1 49314 bytes hidden from API C:\Documents and Settings\user\Local Settings\Application Data\Microsoft\Messenger\beng94@hotmail.co.uk\SharingMetadata\x_bethkxox@hotmail.co.uk\DFSR\Staging\CS{0AE1F3C4-D331-AC84-08E9-3DB4BAD6CD8B}\24\24-{4CCD7310-0415-4B53-92A8-5821840B4842}-v24-{4CCD7310-0415-4B53-92A8-5821840B4842}-v24-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.rdc.2 3612 bytes hidden from API C:\Documents and Settings\user\Local Settings\Application Data\Microsoft\Messenger\beng94@hotmail.co.uk\SharingMetadata\x_bethkxox@hotmail.co.uk\DFSR\Staging\CS{0AE1F3C4-D331-AC84-08E9-3DB4BAD6CD8B}\24\24-{4CCD7310-0415-4B53-92A8-5821840B4842}-v24-{4CCD7310-0415-4B53-92A8-5821840B4842}-v24-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.XPRESS 5456 bytes hidden from API C:\Documents and Settings\user\Local Settings\Application Data\Microsoft\Messenger\beng94@hotmail.co.uk\SharingMetadata\x_bethkxox@hotmail.co.uk\DFSR\Staging\CS{0AE1F3C4-D331-AC84-08E9-3DB4BAD6CD8B}\25\25-{4CCD7310-0415-4B53-92A8-5821840B4842}-v25-{4CCD7310-0415-4B53-92A8-5821840B4842}-v25-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.rdc.1 117156 bytes hidden from API C:\Documents and Settings\user\Local Settings\Application Data\Microsoft\Messenger\beng94@hotmail.co.uk\SharingMetadata\x_bethkxox@hotmail.co.uk\DFSR\Staging\CS{0AE1F3C4-D331-AC84-08E9-3DB4BAD6CD8B}\25\25-{4CCD7310-0415-4B53-92A8-5821840B4842}-v25-{4CCD7310-0415-4B53-92A8-5821840B4842}-v25-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.rdc.2 8328 bytes hidden from API C:\Documents and Settings\user\Local Settings\Application Data\Microsoft\Messenger\beng94@hotmail.co.uk\SharingMetadata\x_bethkxox@hotmail.co.uk\DFSR\Staging\CS{0AE1F3C4-D331-AC84-08E9-3DB4BAD6CD8B}\25\25-{4CCD7310-0415-4B53-92A8-5821840B4842}-v25-{4CCD7310-0415-4B53-92A8-5821840B4842}-v25-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.XPRESS 13056 bytes hidden from API C:\Documents and Settings\user\Local Settings\Application Data\Microsoft\Messenger\beng94@hotmail.co.uk\SharingMetadata\x_bethkxox@hotmail.co.uk\DFSR\Staging\CS{0AE1F3C4-D331-AC84-08E9-3DB4BAD6CD8B}\27\27-{4CCD7310-0415-4B53-92A8-5821840B4842}-v27-{4CCD7310-0415-4B53-92A8-5821840B4842}-v27-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.rdc.1 6654 bytes hidden from API C:\Documents and Settings\user\Local Settings\Application Data\Microsoft\Messenger\beng94@hotmail.co.uk\SharingMetadata\x_bethkxox@hotmail.co.uk\DFSR\Staging\CS{0AE1F3C4-D331-AC84-08E9-3DB4BAD6CD8B}\27\27-{4CCD7310-0415-4B53-92A8-5821840B4842}-v27-{4CCD7310-0415-4B53-92A8-5821840B4842}-v27-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.XPRESS 712 bytes hidden from API C:\Documents and Settings\user\Local Settings\Application Data\Microsoft\Messenger\beng94@hotmail.co.uk\SharingMetadata\x_bethkxox@hotmail.co.uk\DFSR\Staging\CS{0AE1F3C4-D331-AC84-08E9-3DB4BAD6CD8B}\28\32-{4CCD7310-0415-4B53-92A8-5821840B4842}-v28-{468A3F54-6821-43ED-838F-1F63B0123A3E}-v32-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.rdc.1 7896 bytes hidden from API C:\Documents and Settings\user\Local Settings\Application Data\Microsoft\Messenger\beng94@hotmail.co.uk\SharingMetadata\x_bethkxox@hotmail.co.uk\DFSR\Staging\CS{0AE1F3C4-D331-AC84-08E9-3DB4BAD6CD8B}\28\32-{4CCD7310-0415-4B53-92A8-5821840B4842}-v28-{468A3F54-6821-43ED-838F-1F63B0123A3E}-v32-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.XPRESS 896 bytes hidden from API C:\Documents and Settings\user\Local Settings\Application Data\Microsoft\Messenger\beng94@hotmail.co.uk\SharingMetadata\x_bethkxox@hotmail.co.uk\DFSR\Staging\CS{0AE1F3C4-D331-AC84-08E9-3DB4BAD6CD8B}\29\29-{4CCD7310-0415-4B53-92A8-5821840B4842}-v29-{4CCD7310-0415-4B53-92A8-5821840B4842}-v29-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.rdc.1 8112 bytes hidden from API C:\Documents and Settings\user\Local Settings\Application Data\Microsoft\Messenger\beng94@hotmail.co.uk\SharingMetadata\x_bethkxox@hotmail.co.uk\DFSR\Staging\CS{0AE1F3C4-D331-AC84-08E9-3DB4BAD6CD8B}\29\29-{4CCD7310-0415-4B53-92A8-5821840B4842}-v29-{4CCD7310-0415-4B53-92A8-5821840B4842}-v29-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.XPRESS 960 bytes hidden from API C:\Documents and Settings\user\Local Settings\Application Data\Microsoft\Messenger\beng94@hotmail.co.uk\SharingMetadata\x_bethkxox@hotmail.co.uk\DFSR\Staging\CS{0AE1F3C4-D331-AC84-08E9-3DB4BAD6CD8B}\31\35-{4CCD7310-0415-4B53-92A8-5821840B4842}-v31-{468A3F54-6821-43ED-838F-1F63B0123A3E}-v35-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.rdc.1 7734 bytes hidden from API C:\Documents and Settings\user\Local Settings\Application Data\Microsoft\Messenger\beng94@hotmail.co.uk\SharingMetadata\x_bethkxox@hotmail.co.uk\DFSR\Staging\CS{0AE1F3C4-D331-AC84-08E9-3DB4BAD6CD8B}\31\35-{4CCD7310-0415-4B53-92A8-5821840B4842}-v31-{468A3F54-6821-43ED-838F-1F63B0123A3E}-v35-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.XPRESS 840 bytes hidden from API C:\Documents and Settings\user\Local Settings\Application Data\Microsoft\Windows Live Mail\Hotmail.co 222\Drafts\35BD0510-00000001.eml:OEStandardProperty 1124 bytes C:\Documents and Settings\user\Local Settings\Application Data\Microsoft\Windows Live Mail\Hotmail.co 222\Inbox\008351D5-0000002D.eml:OEStandardProperty 1510 bytes C:\Documents and Settings\user\Local Settings\Application Data\Microsoft\Windows Live Mail\Hotmail.co 222\Inbox\03362756-00000017.eml:OEStandardProperty 1252 bytes C:\Documents and Settings\user\Local Settings\Application Data\Microsoft\Windows Live Mail\Hotmail.co 222\Inbox\04802D3F-0000008A.eml:OEStandardProperty 1284 bytes C:\Documents and Settings\user\Local Settings\Application Data\Microsoft\Windows Live Mail\Hotmail.co 222\Inbox\04C5783B-0000008B.eml:OEStandardProperty 1664 bytes C:\Documents and Settings\user\Local Settings\Application Data\Microsoft\Windows Live Mail\Hotmail.co 222\Inbox\057C2E4B-0000001A.eml:OEStandardProperty 1562 bytes C:\Documents and Settings\user\Local Settings\Application Data\Microsoft\Windows Live Mail\Hotmail.co 222\Inbox\05E03B15-0000000B.eml:OEStandardProperty 1340 bytes C:\Documents and Settings\user\Local Settings\Application Data\Microsoft\Windows Live Mail\Hotmail.co 222\Inbox\06622ABE-0000004E.eml:OEStandardProperty 1492 bytes C:\Documents and Settings\user\Local Settings\Application Data\Microsoft\Windows Live Mail\Hotmail.co 222\Inbox\06C32E22-0000001D.eml:OEStandardProperty 1540 bytes C:\Documents and Settings\user\Local Settings\Application Data\Microsoft\Windows Live Mail\Hotmail.co 222\Inbox\076D4F45-0000001E.eml:OEStandardProperty 1456 bytes C:\Documents and Settings\user\Local Settings\Application Data\Microsoft\Windows Live Mail\Hotmail.co 222\Inbox\08246D45-00000016.eml:OEStandardProperty 2144 bytes C:\Documents and Settings\user\Local Settings\Application Data\Microsoft\Windows Live Mail\Hotmail.co 222\Inbox\08804896-00000033.eml:OEStandardProperty 1464 bytes C:\Documents and Settings\user\Local Settings\Application Data\Microsoft\Windows Live Mail\Hotmail.co 222\Inbox\09945C00-00000022.eml:OEStandardProperty 1098 bytes C:\Documents and Settings\user\Local Settings\Application Data\Microsoft\Windows Live Mail\Hotmail.co 222\Inbox\44D411BF-0000003F.eml:OEStandardProperty 1224 bytes C:\Documents and Settings\user\Local Settings\Application Data\Microsoft\Windows Live Mail\Hotmail.co 222\Inbox\4644447B-00000014.eml:OEStandardProperty 1406 bytes C:\Documents and Settings\user\Local Settings\Application Data\Microsoft\Windows Live Mail\Hotmail.co 222\Inbox\47180090-00000068.eml:OEStandardProperty 1564 bytes C:\Documents and Settings\user\Local Settings\Application Data\Microsoft\Windows Live Mail\Hotmail.co 222\Inbox\488223EF-0000005E.eml:OEStandardProperty 1380 bytes C:\Documents and Settings\user\Local Settings\Application Data\Microsoft\Windows Live Mail\Hotmail.co 222\Inbox\49576243-0000005F.eml:OEStandardProperty 1390 bytes C:\Documents and Settings\user\Local Settings\Application Data\Microsoft\Windows Live Mail\Hotmail.co 222\Inbox\49A11BFE-00000001.eml:OEStandardProperty 1478 bytes C:\Documents and Settings\user\Local Settings\Application Data\Microsoft\Windows Live Mail\Hotmail.co 222\Inbox\4AA67FD5-00000004.eml:OEStandardProperty 1170 bytes C:\Documents and Settings\user\Local Settings\Application Data\Microsoft\Windows Live Mail\Hotmail.co 222\Inbox\4BB6516E-00000076.eml:OEStandardProperty 1336 bytes C:\Documents and Settings\user\Local Settings\Application Data\Microsoft\Windows Live Mail\Hotmail.co 222\Inbox\14F032B2-00000018.eml:OEStandardProperty 1154 bytes C:\Documents and Settings\user\Local Settings\Application Data\Microsoft\Windows Live Mail\Hotmail.co 222\Inbox\15102B17-0000008D.eml:OEStandardProperty 1314 bytes C:\Documents and Settings\user\Local Settings\Application Data\Microsoft\Windows Live Mail\Hotmail.co 222\Inbox\16C15051-0000002F.eml:OEStandardProperty 1190 bytes C:\Documents and Settings\user\Local Settings\Application Data\Microsoft\Windows Live Mail\Hotmail.co 222\Inbox\183160C8-00000011.eml:OEStandardProperty 1486 bytes C:\Documents and Settings\user\Local Settings\Application Data\Microsoft\Windows Live Mail\Hotmail.co 222\Inbox\1AFF208F-00000077.eml:OEStandardProperty 1314 bytes C:\Documents and Settings\user\Local Settings\Application Data\Microsoft\Windows Live Mail\Hotmail.co 222\Inbox\1BE838DA-00000038.eml:OEStandardProperty 1564 bytes C:\Documents and Settings\user\Local Settings\Application Data\Microsoft\Windows Live Mail\Hotmail.co 222\Inbox\1CC20087-00000040.eml:OEStandardProperty 1248 bytes C:\Documents and Settings\user\Local Settings\Application Data\Microsoft\Windows Live Mail\Hotmail.co 222\Inbox\20A4055D-00000078.eml:OEStandardProperty 1152 bytes C:\Documents and Settings\user\Local Settings\Application Data\Microsoft\Windows Live Mail\Hotmail.co 222\Inbox\238D4425-00000015.eml:OEStandardProperty 1292 bytes C:\Documents and Settings\user\Local Settings\Application Data\Microsoft\Windows Live Mail\Hotmail.co 222\Inbox\61844E3A-00000025.eml:OEStandardProperty 1302 bytes C:\Documents and Settings\user\Local Settings\Application Data\Microsoft\Windows Live Mail\Hotmail.co 222\Inbox\62E61E28-00000071.eml:OEStandardProperty 1324 bytes C:\Documents and Settings\user\Local Settings\Application Data\Microsoft\Windows Live Mail\Hotmail.co 222\Inbox\646E3F9C-00000030.eml:OEStandardProperty 1150 bytes C:\Documents and Settings\user\Local Settings\Application Data\Microsoft\Windows Live Mail\Hotmail.co 222\Inbox\65AB5535-00000003.eml:OEStandardProperty 1142 bytes C:\Documents and Settings\user\Local Settings\Application Data\Microsoft\Windows Live Mail\Hotmail.co 222\Inbox\67295E15-00000080.eml:OEStandardProperty 942 bytes C:\Documents and Settings\user\Local Settings\Application Data\Microsoft\Windows Live Mail\Hotmail.co 222\Inbox\67AA7C5F-0000004A.eml:OEStandardProperty 1248 bytes C:\Documents and Settings\user\Local Settings\Application Data\Microsoft\Windows Live Mail\Hotmail.co 222\Inbox\6B7165DE-00000028.eml:OEStandardProperty 1110 bytes C:\Documents and Settings\user\Local Settings\Application Data\Microsoft\Windows Live Mail\Hotmail.co 222\Inbox\6D4464D6-0000006E.eml:OEStandardProperty 1248 bytes C:\Documents and Settings\user\Local Settings\Application Data\Microsoft\Windows Live Mail\Hotmail.co 222\Inbox\6D522E8E-0000000E.eml:OEStandardProperty 1200 bytes C:\Documents and Settings\user\Local Settings\Application Data\Microsoft\Windows Live Mail\Hotmail.co 222\Inbox\6F2A34D0-0000006D.eml:OEStandardProperty 1246 bytes C:\Documents and Settings\user\Local Settings\Application Data\Microsoft\Windows Live Mail\Hotmail.co 222\Inbox\09F662D6-00000027.eml:OEStandardProperty 1278 bytes C:\Documents and Settings\user\Local Settings\Application Data\Microsoft\Windows Live Mail\Hotmail.co 222\Inbox\0DD420C2-00000026.eml:OEStandardProperty 1126 bytes C:\Documents and Settings\user\Local Settings\Application Data\Microsoft\Windows Live Mail\Hotmail.co 222\Inbox\0F0E33BC-0000004F.eml:OEStandardProperty 1272 bytes C:\Documents and Settings\user\Local Settings\Application Data\Microsoft\Windows Live Mail\Hotmail.co 222\Inbox\0F387E34-00000024.eml:OEStandardProperty 1062 bytes C:\Documents and Settings\user\Local Settings\Application Data\Microsoft\Windows Live Mail\Hotmail.co 222\Inbox\100802A9-00000029.eml:OEStandardProperty 1472 bytes C:\Documents and Settings\user\Local Settings\Application Data\Microsoft\Windows Live Mail\Hotmail.co 222\Inbox\133D66FB-0000002B.eml:OEStandardProperty 1254 bytes C:\Documents and Settings\user\Local Settings\Application Data\Microsoft\Windows Live Mail\Hotmail.co 222\Inbox\13967FFC-0000001B.eml:OEStandardProperty 1572 bytes C:\Documents and Settings\user\Local Settings\Application Data\Microsoft\Windows Live Mail\Hotmail.co 222\Inbox\13B5478C-0000000D.eml:OEStandardProperty 1530 bytes C:\Documents and Settings\user\Local Settings\Application Data\Microsoft\Windows Live Mail\Hotmail.co 222\Inbox\14B763D7-00000007.eml:OEStandardProperty 950 bytes C:\Documents and Settings\user\Local Settings\Application Data\Microsoft\Windows Live Mail\Hotmail.co 222\Inbox\24974805-00000062.eml:OEStandardProperty 1276 bytes C:\Documents and Settings\user\Local Settings\Application Data\Microsoft\Windows Live Mail\Hotmail.co 222\Inbox\29CA438B-00000006.eml:OEStandardProperty 1398 bytes C:\Documents and Settings\user\Local Settings\Application Data\Microsoft\Windows Live Mail\Hotmail.co 222\Inbox\2CE03769-00000005.eml:OEStandardProperty 1204 bytes C:\Documents and Settings\user\Local Settings\Application Data\Microsoft\Windows Live Mail\Hotmail.co 222\Inbox\2FDD06DA-0000000F.eml:OEStandardProperty 1492 bytes C:\Documents and Settings\user\Local Settings\Application Data\Microsoft\Windows Live Mail\Hotmail.co 222\Inbox\303554B1-00000045.eml:OEStandardProperty 1540 bytes C:\Documents and Settings\user\Local Settings\Application Data\Microsoft\Windows Live Mail\Hotmail.co 222\Inbox\3353130A-00000010.eml:OEStandardProperty 1088 bytes C:\Documents and Settings\user\Local Settings\Application Data\Microsoft\Windows Live Mail\Hotmail.co 222\Inbox\358F605C-0000002C.eml:OEStandardProperty 966 bytes C:\Documents and Settings\user\Local Settings\Application Data\Microsoft\Windows Live Mail\Hotmail.co 222\Inbox\36CC181E-00000087.eml:OEStandardProperty 1174 bytes C:\Documents and Settings\user\Local Settings\Application Data\Microsoft\Windows Live Mail\Hotmail.co 222\Inbox\3A0719F5-00000079.eml:OEStandardProperty 1198 bytes C:\Documents and Settings\user\Local Settings\Application Data\Microsoft\Windows Live Mail\Hotmail.co 222\Inbox\3A436355-00000023.eml:OEStandardProperty 1318 bytes C:\Documents and Settings\user\Local Settings\Application Data\Microsoft\Windows Live Mail\Hotmail.co 222\Inbox\3B0220AD-00000075.eml:OEStandardProperty 1308 bytes C:\Documents and Settings\user\Local Settings\Application Data\Microsoft\Windows Live Mail\Hotmail.co 222\Inbox\3C7E7220-00000020.eml:OEStandardProperty 1540 bytes C:\Documents and Settings\user\Local Settings\Application Data\Microsoft\Windows Live Mail\Hotmail.co 222\Inbox\14BB34B1-00000008.eml:OEStandardProperty 1492 bytes C:\Documents and Settings\user\Local Settings\Application Data\Microsoft\Windows Live Mail\Hotmail.co 222\Inbox\5F1A55B8-0000002A.eml:OEStandardProperty 1472 bytes C:\Documents and Settings\user\Local Settings\Application Data\Microsoft\Windows Live Mail\Hotmail.co 222\Inbox\7013736F-00000012.eml:OEStandardProperty 1322 bytes C:\Documents and Settings\user\Local Settings\Application Data\Microsoft\Windows Live Mail\Hotmail.co 222\Inbox\710C5E1E-00000069.eml:OEStandardProperty 1246 bytes C:\Documents and Settings\user\Local Settings\Application Data\Microsoft\Windows Live Mail\Hotmail.co 222\Inbox\733611B6-00000053.eml:OEStandardProperty 1300 bytes C:\Documents and Settings\user\Local Settings\Application Data\Microsoft\Windows Live Mail\Hotmail.co 222\Inbox\73A30514-0000001C.eml:OEStandardProperty 1456 bytes C:\Documents and Settings\user\Local Settings\Application Data\Microsoft\Windows Live Mail\Hotmail.co 222\Inbox\76176308-0000005B.eml:OEStandardProperty 1540 bytes C:\Documents and Settings\user\Local Settings\Application Data\Microsoft\Windows Live Mail\Hotmail.co 222\Inbox\76C454A5-0000001F.eml:OEStandardProperty 1728 bytes C:\Documents and Settings\user\Local Settings\Application Data\Microsoft\Windows Live Mail\Hotmail.co 222\Inbox\79590855-0000000C.eml:OEStandardProperty 1462 bytes C:\Documents and Settings\user\Local Settings\Application Data\Microsoft\Windows Live Mail\Hotmail.co 222\Inbox\7B496073-00000063.eml:OEStandardProperty 1270 bytes C:\Documents and Settings\user\Local Settings\Application Data\Microsoft\Windows Live Mail\Hotmail.co 222\Inbox\4E3E36D7-0000002E.eml:OEStandardProperty 1066 bytes C:\Documents and Settings\user\Local Settings\Application Data\Microsoft\Windows Live Mail\Hotmail.co 222\Inbox\504E54C9-00000013.eml:OEStandardProperty 1320 bytes C:\Documents and Settings\user\Local Settings\Application Data\Microsoft\Windows Live Mail\Hotmail.co 222\Inbox\52320CDE-00000021.eml:OEStandardProperty 1338 bytes C:\Documents and Settings\user\Local Settings\Application Data\Microsoft\Windows Live Mail\Hotmail.co 222\Inbox\54996E76-00000009.eml:OEStandardProperty 1322 bytes C:\Documents and Settings\user\Local Settings\Application Data\Microsoft\Windows Live Mail\Hotmail.co 222\Inbox\56563080-00000043.eml:OEStandardProperty 1326 bytes C:\Documents and Settings\user\Local Settings\Application Data\Microsoft\Windows Live Mail\Hotmail.co 222\Inbox\56D70A97-00000019.eml:OEStandardProperty 1274 bytes C:\Documents and Settings\user\Local Settings\Application Data\Microsoft\Windows Live Mail\Hotmail.co 222\Inbox\59690D30-00000081.eml:OEStandardProperty 1084 bytes C:\Documents and Settings\user\Local Settings\Application Data\Microsoft\Windows Live Mail\Hotmail.co 222\Inbox\5DA363B3-00000002.eml:OEStandardProperty 1440 bytes C:\Documents and Settings\user\Local Settings\Application Data\Microsoft\Windows Live Mail\Hotmail.co 222\Inbox\5DFF5530-00000058.eml:OEStandardProperty 1222 bytes C:\Documents and Settings\user\Local Settings\Application Data\Microsoft\Windows Live Mail\Hotmail.co 222\Junk e-mail\00BD6084-00000063.eml:OEStandardProperty 1296 bytes C:\Documents and Settings\user\Local Settings\Application Data\Microsoft\Windows Live Mail\Hotmail.co 222\Junk e-mail\215239A6-00000067.eml:OEStandardProperty 1318 bytes C:\Documents and Settings\user\Local Settings\Application Data\Microsoft\Windows Live Mail\Hotmail.co 222\Junk e-mail\25EF0F33-00000065.eml:OEStandardProperty 1292 bytes C:\Documents and Settings\user\Local Settings\Application Data\Microsoft\Windows Live Mail\Hotmail.co 222\Junk e-mail\27293CA6-0000006B.eml:OEStandardProperty 1394 bytes C:\Documents and Settings\user\Local Settings\Application Data\Microsoft\Windows Live Mail\Hotmail.co 222\Junk e-mail\281B7B83-00000064.eml:OEStandardProperty 1352 bytes C:\Documents and Settings\user\Local Settings\Application Data\Microsoft\Windows Live Mail\Hotmail.co 222\Junk e-mail\2CE87DAB-00000069.eml:OEStandardProperty 1354 bytes C:\Documents and Settings\user\Local Settings\Application Data\Microsoft\Windows Live Mail\Hotmail.co 222\Junk e-mail\36AB45AE-0000006E.eml:OEStandardProperty 1650 bytes C:\Documents and Settings\user\Local Settings\Application Data\Microsoft\Windows Live Mail\Hotmail.co 222\Junk e-mail\3A8F7F17-00000068.eml:OEStandardProperty 1390 bytes C:\Documents and Settings\user\Local Settings\Application Data\Microsoft\Windows Live Mail\Hotmail.co 222\Junk e-mail\3D570F3F-0000006C.eml:OEStandardProperty 1210 bytes C:\Documents and Settings\user\Local Settings\Application Data\Microsoft\Windows Live Mail\Hotmail.co 222\Junk e-mail\5680013B-00000066.eml:OEStandardProperty 1292 bytes C:\Documents and Settings\user\Local Settings\Application Data\Microsoft\Windows Live Mail\Hotmail.co 222\Junk e-mail\576E15F3-0000006A.eml:OEStandardProperty 1292 bytes C:\Documents and Settings\user\Local Settings\Application Data\Microsoft\Windows Live Mail\Hotmail.co 222\Junk e-mail\62F71826-0000006D.eml:OEStandardProperty 1716 bytes C:\Documents and Settings\user\Local Settings\Application Data\Microsoft\Windows Live Mail\Hotmail.co 222\Junk e-mail\7CB508A0-00000062.eml:OEStandardProperty 1646 bytes C:\Documents and Settings\user\Local Settings\Application Data\Microsoft\Windows Live Mail\Hotmail.co 222\Sent items\00294823-00000029.eml:OEStandardProperty 1486 bytes C:\Documents and Settings\user\Local Settings\Application Data\Microsoft\Windows Live Mail\Hotmail.co 222\Sent items\00294823-0000002E.eml:OEStandardProperty 1386 bytes C:\Documents and Settings\user\Local Settings\Application Data\Microsoft\Windows Live Mail\Hotmail.co 222\Sent items\00BF6F3F-00000027.eml:OEStandardProperty 1044 bytes C:\Documents and Settings\user\Local Settings\Application Data\Microsoft\Windows Live Mail\Hotmail.co 222\Sent items\03FD04D0-00000005.eml:OEStandardProperty 1042 bytes C:\Documents and Settings\user\Local Settings\Application Data\Microsoft\Windows Live Mail\Hotmail.co 222\Sent items\04693BE9-00000023.eml:OEStandardProperty 1114 bytes C:\Documents and Settings\user\Local Settings\Application Data\Microsoft\Windows Live Mail\Hotmail.co 222\Sent items\0A9C77DE-0000001F.eml:OEStandardProperty 1124 bytes C:\Documents and Settings\user\Local Settings\Application Data\Microsoft\Windows Live Mail\Hotmail.co 222\Sent items\0EF01887-00000019.eml:OEStandardProperty 1188 bytes C:\Documents and Settings\user\Local Settings\Application Data\Microsoft\Windows Live Mail\Hotmail.co 222\Sent items\0F140C72-0000002F.eml:OEStandardProperty 1404 bytes C:\Documents and Settings\user\Local Settings\Application Data\Microsoft\Windows Live Mail\Hotmail.co 222\Sent items\112F035B-00000010.eml:OEStandardProperty 1076 bytes C:\Documents and Settings\user\Local Settings\Application Data\Microsoft\Windows Live Mail\Hotmail.co 222\Sent items\440C2D87-0000002C.eml:OEStandardProperty 1186 bytes C:\Documents and Settings\user\Local Settings\Application Data\Microsoft\Windows Live Mail\Hotmail.co 222\Sent items\44C545C9-00000021.eml:OEStandardProperty 1112 bytes C:\Documents and Settings\user\Local Settings\Application Data\Microsoft\Windows Live Mail\Hotmail.co 222\Sent items\4BD711E7-0000000C.eml:OEStandardProperty 882 bytes C:\Documents and Settings\user\Local Settings\Application Data\Microsoft\Windows Live Mail\Hotmail.co 222\Sent items\4DCF1F80-00000018.eml:OEStandardProperty 1184 bytes C:\Documents and Settings\user\Local Settings\Application Data\Microsoft\Windows Live Mail\Hotmail.co 222\Sent items\4F3A71BB-00000030.eml:OEStandardProperty 1388 bytes C:\Documents and Settings\user\Local Settings\Application Data\Microsoft\Windows Live Mail\Hotmail.co 222\Sent items\52C25A82-0000000D.eml:OEStandardProperty 1268 bytes C:\Documents and Settings\user\Local Settings\Application Data\Microsoft\Windows Live Mail\Hotmail.co 222\Sent items\56AE2C7E-00000006.eml:OEStandardProperty 1216 bytes C:\Documents and Settings\user\Local Settings\Application Data\Microsoft\Windows Live Mail\Hotmail.co 222\Sent items\59877719-00000013.eml:OEStandardProperty 1034 bytes C:\Documents and Settings\user\Local Settings\Application Data\Microsoft\Windows Live Mail\Hotmail.co 222\Sent items\5B8B1017-00000031.eml:OEStandardProperty 1556 bytes C:\Documents and Settings\user\Local Settings\Application Data\Microsoft\Windows Live Mail\Hotmail.co 222\Sent items\64C72FE7-00000008.eml:OEStandardProperty 1268 bytes C:\Documents and Settings\user\Local Settings\Application Data\Microsoft\Windows Live Mail\Hotmail.co 222\Sent items\66681EC4-00000002.eml:OEStandardProperty 1058 bytes C:\Documents and Settings\user\Local Settings\Application Data\Microsoft\Windows Live Mail\Hotmail.co 222\Sent items\333C003E-00000001.eml:OEStandardProperty 1106 bytes C:\Documents and Settings\user\Local Settings\Application Data\Microsoft\Windows Live Mail\Hotmail.co 222\Sent items\346E23E0-00000011.eml:OEStandardProperty 1154 bytes C:\Documents and Settings\user\Local Settings\Application Data\Microsoft\Windows Live Mail\Hotmail.co 222\Sent items\35862F4F-00000016.eml:OEStandardProperty 1104 bytes C:\Documents and Settings\user\Local Settings\Application Data\Microsoft\Windows Live Mail\Hotmail.co 222\Sent items\367369A1-0000000A.eml:OEStandardProperty 1178 bytes C:\Documents and Settings\user\Local Settings\Application Data\Microsoft\Windows Live Mail\Hotmail.co 222\Sent items\37F17B9E-0000002D.eml:OEStandardProperty 1126 bytes C:\Documents and Settings\user\Local Settings\Application Data\Microsoft\Windows Live Mail\Hotmail.co 222\Sent items\38E615E0-0000001E.eml:OEStandardProperty 1084 bytes C:\Documents and Settings\user\Local Settings\Application Data\Microsoft\Windows Live Mail\Hotmail.co 222\Sent items\3B646D4C-00000017.eml:OEStandardProperty 1114 bytes C:\Documents and Settings\user\Local Settings\Application Data\Microsoft\Windows Live Mail\Hotmail.co 222\Sent items\3BF91668-00000026.eml:OEStandardProperty 930 bytes C:\Documents and Settings\user\Local Settings\Application Data\Microsoft\Windows Live Mail\Hotmail.co 222\Sent items\3CB566F2-00000022.eml:OEStandardProperty 1090 bytes C:\Documents and Settings\user\Local Settings\Application Data\Microsoft\Windows Live Mail\Hotmail.co 222\Sent items\413E0AF6-00000012.eml:OEStandardProperty 1302 bytes C:\Documents and Settings\user\Local Settings\Application Data\Microsoft\Windows Live Mail\Hotmail.co 222\Sent items\42670DCE-00000020.eml:OEStandardProperty 1042 bytes C:\Documents and Settings\user\Local Settings\Application Data\Microsoft\Windows Live Mail\Hotmail.co 222\Sent items\428E2A64-00000004.eml:OEStandardProperty 1304 bytes C:\Documents and Settings\user\Local Settings\Application Data\Microsoft\Windows Live Mail\Hotmail.co 222\Sent items\694810A8-0000000B.eml:OEStandardProperty 922 bytes C:\Documents and Settings\user\Local Settings\Application Data\Microsoft\Windows Live Mail\Hotmail.co 222\Sent items\718D2B80-0000001D.eml:OEStandardProperty 946 bytes C:\Documents and Settings\user\Local Settings\Application Data\Microsoft\Windows Live Mail\Hotmail.co 222\Sent items\745157D7-0000000F.eml:OEStandardProperty 1078 bytes C:\Documents and Settings\user\Local Settings\Application Data\Microsoft\Windows Live Mail\Hotmail.co 222\Sent items\76F875BA-0000001B.eml:OEStandardProperty 950 bytes C:\Documents and Settings\user\Local Settings\Application Data\Microsoft\Windows Live Mail\Hotmail.co 222\Sent items\786B21D3-00000024.eml:OEStandardProperty 922 bytes C:\Documents and Settings\user\Local Settings\Application Data\Microsoft\Windows Live Mail\Hotmail.co 222\Sent items\798369EE-0000001C.eml:OEStandardProperty 882 bytes C:\Documents and Settings\user\Local Settings\Application Data\Microsoft\Windows Live Mail\Hotmail.co 222\Sent items\7B1A0613-00000028.eml:OEStandardProperty 1548 bytes C:\Documents and Settings\user\Local Settings\Application Data\Microsoft\Windows Live Mail\Hotmail.co 222\Sent items\7DD22E37-00000003.eml:OEStandardProperty 1070 bytes C:\Documents and Settings\user\Local Settings\Application Data\Microsoft\Windows Live Mail\Hotmail.co 222\Sent items\19FD764C-0000000E.eml:OEStandardProperty 882 bytes C:\Documents and Settings\user\Local Settings\Application Data\Microsoft\Windows Live Mail\Hotmail.co 222\Sent items\1AD522FD-0000002B.eml:OEStandardProperty 1542 bytes C:\Documents and Settings\user\Local Settings\Application Data\Microsoft\Windows Live Mail\Hotmail.co 222\Sent items\1D401E27-00000014.eml:OEStandardProperty 1342 bytes C:\Documents and Settings\user\Local Settings\Application Data\Microsoft\Windows Live Mail\Hotmail.co 222\Sent items\23BB3B27-0000001A.eml:OEStandardProperty 1180 bytes C:\Documents and Settings\user\Local Settings\Application Data\Microsoft\Windows Live Mail\Hotmail.co 222\Sent items\28797243-0000002A.eml:OEStandardProperty 1160 bytes C:\Documents and Settings\user\Local Settings\Application Data\Microsoft\Windows Live Mail\Hotmail.co 222\Sent items\2D6C5F1F-00000009.eml:OEStandardProperty 1030 bytes C:\Documents and Settings\user\Local Settings\Application Data\Microsoft\Windows Live Mail\Hotmail.co 222\Sent items\2F812511-00000007.eml:OEStandardProperty 880 bytes C:\Documents and Settings\user\Local Settings\Application Data\Microsoft\Windows Live Mail\Hotmail.co 222\Sent items\3105289D-00000025.eml:OEStandardProperty 926 bytes C:\Documents and Settings\user\Local Settings\Application Data\Microsoft\Windows Live Mail\Hotmail.co 222\Sent items\31882497-00000015.eml:OEStandardProperty 1070 bytes C:\Documents and Settings\user\Local Settings\Application Data\Microsoft\Windows Live Mail\Storage Folders\Recovered items\12-12-2008 b08\6CE1115D-00000001.eml:OEStandardProperty 1380 bytes scan completed successfully hidden files: 856 [Alternate Data Streams] @Alternate Data Stream - 98 bytes -> %AllUsersProfile%\Application Data\TEMP:C4252FE0 @Alternate Data Stream - 110 bytes -> %AllUsersProfile%\Application Data\TEMP:888AFB86 @Alternate Data Stream - 0 bytes -> %UserProfile%\My Documents\Thumbs.db:encryptable < End of report > [/code]