Here is DSS:
Deckard's System Scanner v20071014.68
Run by BAMF3000 on 2008-05-31 18:57:10
Computer is in Normal Mode.
--------------------------------------------------------------------------------
-- HijackThis (run as BAMF3000.exe) --------------------------------------------
Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 6:57:12 PM, on 5/31/2008
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16640)
Boot mode: Normal
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Avira\AntiVir PersonalEdition Classic\sched.exe
C:\WINDOWS\ehome\ehtray.exe
C:\WINDOWS\system32\RUNDLL32.EXE
C:\WINDOWS\SOUNDMAN.EXE
C:\Program Files\Avira\AntiVir PersonalEdition Classic\avgnt.exe
C:\Program Files\iTunes\iTunesHelper.exe
C:\Program Files\Java\jre1.6.0_06\bin\jusched.exe
C:\Program Files\Windows Live\Messenger\MsnMsgr.Exe
C:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe
C:\Program Files\Avira\AntiVir PersonalEdition Classic\avguard.exe
C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
C:\WINDOWS\eHome\ehRecvr.exe
C:\WINDOWS\eHome\ehSched.exe
C:\WINDOWS\system32\nvsvc32.exe
C:\Program Files\iPod\bin\iPodService.exe
C:\WINDOWS\system32\dllhost.exe
C:\WINDOWS\eHome\ehmsas.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\Documents and Settings\BAMF3000\Desktop\dss.exe
C:\PROGRA~1\TRENDM~1\HIJACK~1\BAMF3000.exe
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page =
http://www.yahoo.com/R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL =
http://go.microsoft....k/?LinkId=69157R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL =
http://go.microsoft....k/?LinkId=54896R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page =
http://go.microsoft....k/?LinkId=54896R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page =
http://go.microsoft....k/?LinkId=69157O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_06\bin\ssv.dll
O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - (no file)
O2 - BHO: Windows Live Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
O4 - HKLM\..\Run: [ehTray] C:\WINDOWS\ehome\ehtray.exe
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [nwiz] nwiz.exe /install
O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\WINDOWS\system32\NvMcTray.dll,NvTaskbarInit
O4 - HKLM\..\Run: [SoundMan] SOUNDMAN.EXE
O4 - HKLM\..\Run: [avgnt] "C:\Program Files\Avira\AntiVir PersonalEdition Classic\avgnt.exe" /min
O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_06\bin\jusched.exe"
O4 - HKLM\..\Run: [KernelFaultCheck] %systemroot%\system32\dumprep 0 -k
O4 - HKCU\..\Run: [MsnMsgr] "C:\Program Files\Windows Live\Messenger\MsnMsgr.Exe" /background
O4 - HKCU\..\Run: [SUPERAntiSpyware] C:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_06\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_06\bin\ssv.dll
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O16 - DPF: {0EB0E74A-2A76-4AB3-A7FB-9BD8C29F7F75} (CKAVWebScan Object) -
http://www.kaspersky...can_unicode.cabO16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} (Java Runtime Environment 1.6.0) -
http://sdlc-esd.sun....ows-i586-jc.cabO20 - Winlogon Notify: !SASWinLogon - C:\Program Files\SUPERAntiSpyware\SASWINLO.dll
O23 - Service: Avira AntiVir Personal – Free Antivirus Scheduler (AntiVirScheduler) - Avira GmbH - C:\Program Files\Avira\AntiVir PersonalEdition Classic\sched.exe
O23 - Service: Avira AntiVir Personal – Free Antivirus Guard (AntiVirService) - Avira GmbH - C:\Program Files\Avira\AntiVir PersonalEdition Classic\avguard.exe
O23 - Service: Apple Mobile Device - Apple, Inc. - C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
O23 - Service: iPod Service - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe
--
End of file - 5050 bytes
-- Files created between 2008-04-30 and 2008-05-31 -----------------------------
2008-05-31 14:05:13 0 d-------- C:\WINDOWS\system32\Kaspersky Lab
2008-05-31 14:05:13 0 d-------- C:\Documents and Settings\All Users\Application Data\Kaspersky Lab
2008-05-31 14:05:12 0 d-------- C:\WINDOWS\LastGood
2008-05-27 14:34:32 0 dr-h----- C:\Documents and Settings\BAMF3000\Recent
2008-05-27 14:28:54 0 d-------- C:\Program Files\CCleaner
2008-05-27 14:26:16 0 d-------- C:\WINDOWS\setup.pss
2008-05-27 14:26:02 0 d-------- C:\WINDOWS\setupupd
2008-05-27 02:48:06 0 d-------- C:\Documents and Settings\LocalService\Application Data\Adobe
2008-05-27 01:25:49 0 d-------- C:\Documents and Settings\All Users\Application Data\SUPERAntiSpyware.com
2008-05-27 01:25:11 0 d-------- C:\Program Files\SUPERAntiSpyware
2008-05-27 01:25:11 0 d-------- C:\Documents and Settings\BAMF3000\Application Data\SUPERAntiSpyware.com
2008-05-27 01:24:51 0 d-------- C:\Program Files\Common Files\Wise Installation Wizard
2008-05-27 01:00:07 0 d-------- C:\Documents and Settings\BAMF3000\Application Data\Malwarebytes
2008-05-27 01:00:03 0 d-------- C:\Program Files\Malwarebytes' Anti-Malware
2008-05-27 01:00:03 0 d-------- C:\Documents and Settings\All Users\Application Data\Malwarebytes
2008-05-27 00:59:41 0 d-------- C:\Program Files\Common Files\Download Manager
2008-05-27 00:55:32 0 d-------- C:\Program Files\Trend Micro
2008-05-27 00:46:49 0 d-------- C:\Documents and Settings\BAMF3000\Application Data\Uniblue
2008-05-27 00:12:00 0 d-------- C:\WINDOWS\Sun
2008-05-27 00:12:00 0 d-------- C:\Documents and Settings\BAMF3000\Application Data\Sun
2008-05-27 00:11:29 0 d-------- C:\Program Files\Java
2008-05-27 00:11:09 0 d-------- C:\Program Files\Common Files\Java
2008-05-26 23:27:18 0 d-------- C:\Documents and Settings\BAMF3000\Contacts
2008-05-23 12:33:54 2568 --a------ C:\WINDOWS\mozver.dat
2008-05-22 23:52:07 0 --a------ C:\WINDOWS\nsreg.dat
2008-05-22 00:50:00 0 d-------- C:\Documents and Settings\BAMF3000\Application Data\Mozilla
2008-05-21 18:01:07 0 d-------- C:\unzipped
2008-05-21 17:54:23 3548 --a------ C:\WINDOWS\system32\drivers\WinFlash.sys
2008-05-21 17:54:10 42487 --a------ C:\WINDOWS\system32\FlashMenu.sys
2008-05-18 23:33:18 29293 --a------ C:\WINDOWS\scunin.dat
2008-05-18 23:33:17 967 --a------ C:\WINDOWS\ScUnin.pif
2008-05-18 23:33:17 70656 --a------ C:\WINDOWS\ScUnin.exe <Not Verified; Blizzard Entertainment; Starcraft Uninstaller>
2008-05-11 03:42:07 0 d-------- C:\Documents and Settings\BAMF3000\Application Data\Apple Computer
2008-05-11 03:41:26 0 d-------- C:\Program Files\QuickTime
2008-05-11 03:36:21 0 d-------- C:\Program Files\iPod
2008-05-11 03:36:17 0 d-------- C:\Program Files\iTunes
2008-05-11 03:36:17 0 d-------- C:\Documents and Settings\All Users\Application Data\Apple Computer
2008-05-11 03:35:49 0 d-------- C:\Program Files\Apple Software Update
2008-05-11 03:35:47 0 d------c- C:\WINDOWS\system32\DRVSTORE
2008-05-11 03:35:40 0 d-------- C:\Program Files\Common Files\Apple
2008-05-11 03:35:39 0 d-------- C:\Documents and Settings\All Users\Application Data\Apple
2008-05-11 03:32:30 0 d--hs--c- C:\Program Files\Common Files\WindowsLiveInstaller
2008-05-11 03:32:25 0 d-------- C:\Program Files\Windows Live
2008-05-11 03:32:20 0 d-------- C:\Documents and Settings\All Users\Application Data\WLInstaller
2008-05-11 03:28:08 0 d-------- C:\Program Files\Avira
2008-05-11 03:28:08 0 d-------- C:\Documents and Settings\All Users\Application Data\Avira
2008-05-11 03:22:00 0 d-------- C:\WINDOWS\system32\PreInstall
2008-05-11 03:15:30 40960 -ra------ C:\WINDOWS\system32\ChCfg.exe
2008-05-11 03:15:10 0 d-------- C:\Program Files\Realtek Sound Manager
2008-05-11 03:15:10 0 d-------- C:\Program Files\Realtek Audio
2008-05-11 03:15:07 0 d-------- C:\Program Files\Realtek AC97
2008-05-11 03:15:04 307200 -ra------ C:\WINDOWS\alcupd.exe <Not Verified; Realtek Semiconductor Corp.; Realtek AC'97 Update driver Tool>
2008-05-11 03:15:04 212992 -ra------ C:\WINDOWS\alcrmv.exe <Not Verified; Realtek Semiconductor Corp.; Realtek AC'97 Removing driver Tool>
2008-05-11 03:14:12 0 d-------- C:\WINDOWS\system32\SoftwareDistribution
2008-05-11 03:04:03 0 d-------- C:\WINDOWS\nview
2008-05-11 03:01:47 0 d-------- C:\Program Files\Nvidia Driver
2008-05-11 02:57:44 0 d-------- C:\Documents and Settings\BAMF3000\Application Data\Adobe
2008-05-11 02:57:36 0 d-------- C:\Documents and Settings\BAMF3000\Application Data\Macromedia
2008-05-11 02:39:51 0 d-------- C:\WINDOWS\system32\ReinstallBackups
2008-05-11 02:38:36 7296 -----n--- C:\WINDOWS\system32\drivers\Wbhwdoct.sys <Not Verified; Winbond Electronics Corp.; Winbond Hardware Doctor>
2008-05-11 02:38:36 0 d--h----- C:\Program Files\InstallShield Installation Information
2008-05-11 02:38:36 0 d-------- C:\Program Files\ABIT
2008-05-11 02:38:22 0 d-------- C:\Program Files\Common Files\InstallShield
2008-05-11 02:35:47 0 d-------- C:\Documents and Settings\BAMF3000\Application Data\Identities
2008-05-11 02:33:58 0 d-------- C:\WINDOWS\system32\URTTemp
2008-05-11 02:33:37 0 d-------- C:\Program Files\RGB
2008-05-11 02:28:00 0 d--h----- C:\Documents and Settings\BAMF3000\Templates
2008-05-11 02:28:00 0 dr------- C:\Documents and Settings\BAMF3000\Start Menu
2008-05-11 02:28:00 0 dr-h----- C:\Documents and Settings\BAMF3000\SendTo
2008-05-11 02:28:00 0 d--h----- C:\Documents and Settings\BAMF3000\PrintHood
2008-05-11 02:28:00 2097152 --ah----- C:\Documents and Settings\BAMF3000\NTUSER.DAT
2008-05-11 02:28:00 0 d--h----- C:\Documents and Settings\BAMF3000\NetHood
2008-05-11 02:28:00 0 dr------- C:\Documents and Settings\BAMF3000\My Documents
2008-05-11 02:28:00 0 d--h----- C:\Documents and Settings\BAMF3000\Local Settings
2008-05-11 02:28:00 0 dr------- C:\Documents and Settings\BAMF3000\Favorites
2008-05-11 02:28:00 0 d-------- C:\Documents and Settings\BAMF3000\Desktop
2008-05-11 02:28:00 0 d--hs---- C:\Documents and Settings\BAMF3000\Cookies
2008-05-11 02:28:00 0 dr-h----- C:\Documents and Settings\BAMF3000\Application Data
2008-05-11 02:27:02 0 d-------- C:\WINDOWS\SoftwareDistribution
2008-05-11 02:26:59 0 d-------- C:\WINDOWS\Prefetch
2008-05-11 02:26:58 0 d---s---- C:\WINDOWS\system32\Microsoft
2008-05-11 02:26:57 262144 --ah----- C:\Documents and Settings\LocalService\NTUSER.DAT
2008-05-11 02:26:57 0 d--h----- C:\Documents and Settings\LocalService\Local Settings
2008-05-11 02:26:57 0 d--hs---- C:\Documents and Settings\LocalService\Cookies
2008-05-11 02:26:57 0 d-------- C:\Documents and Settings\LocalService\Application Data
2008-05-11 02:26:57 0 d---s---- C:\Documents and Settings\LocalService\Application Data\Microsoft
2008-05-11 02:26:21 0 d--h----- C:\Documents and Settings\NetworkService\Local Settings
2008-05-11 02:26:21 0 d--hs---- C:\Documents and Settings\NetworkService\Cookies
2008-05-11 02:26:21 0 d-------- C:\Documents and Settings\NetworkService\Application Data
2008-05-11 02:26:21 0 d---s---- C:\Documents and Settings\NetworkService\Application Data\Microsoft
2008-05-11 02:26:20 229376 --ah----- C:\Documents and Settings\NetworkService\NTUSER.DAT
2008-05-11 02:23:19 0 d-------- C:\WINDOWS\system32\xircom
2008-05-11 02:23:19 0 d-------- C:\Program Files\microsoft frontpage
2008-05-11 02:22:51 229376 ---h----- C:\Documents and Settings\Default User\NTUSER.DAT
2008-05-11 02:22:51 0 d-------- C:\DELL
2008-05-11 02:22:37 0 d--h----- C:\WINDOWS\$hf_mig$
2008-05-11 02:22:23 0 -rahs---- C:\MSDOS.SYS
2008-05-11 02:22:23 0 -rahs---- C:\IO.SYS
2008-05-11 02:22:23 0 --a------ C:\CONFIG.SYS
2008-05-11 02:22:23 0 --a------ C:\AUTOEXEC.BAT
2008-05-11 02:21:08 0 d--hs---- C:\Documents and Settings\All Users\DRM
2008-05-11 02:21:00 0 dr------- C:\WINDOWS\Offline Web Pages
2008-05-11 02:21:00 0 d---s---- C:\WINDOWS\Downloaded Program Files
2008-05-11 02:20:50 0 d--h----- C:\Program Files\WindowsUpdate
2008-05-11 02:20:36 0 d-------- C:\WINDOWS\system32\DirectX
2008-05-11 02:20:19 12288 --a------ C:\WINDOWS\system32\nmevtmsg.dll <Not Verified; Microsoft Corporation; Windows® NetMeeting®>
2008-05-11 02:20:16 0 d---s---- C:\WINDOWS\Tasks
2008-05-11 02:20:16 0 d-------- C:\Program Files\Common Files\MSSoap
2008-05-11 02:20:14 0 d-------- C:\WINDOWS\srchasst
2008-05-11 02:20:13 0 d-------- C:\WINDOWS\system32\Macromed
2008-05-11 02:20:03 0 d-------- C:\WINDOWS\system32\Restore
2008-05-11 02:20:02 28672 --a------ C:\WINDOWS\system32\nmmkcert.dll <Not Verified; Microsoft Corporation; Windows® NetMeeting®>
2008-05-11 02:19:02 21640 --a------ C:\WINDOWS\system32\emptyregdb.dat
2008-05-11 02:18:46 0 d-------- C:\WINDOWS\Registration
2008-05-11 02:18:14 0 d-------- C:\Program Files\Windows Plus
2008-05-11 02:18:06 0 d-------- C:\Program Files\Movie Maker
2008-05-11 02:17:34 0 d-------- C:\Program Files\Messenger
2008-05-11 02:17:30 0 d-------- C:\Program Files\MSN Gaming Zone
2008-05-11 02:17:20 16896 --a------ C:\WINDOWS\system32\qappsrv.exe <Not Verified; Microsoft Corporation; Microsoft® Windows® Operating System>
2008-05-11 02:17:10 0 d-------- C:\Program Files\Windows NT
2008-05-11 02:17:08 0 d-------- C:\WINDOWS\system32\MsDtc
2008-05-11 02:17:07 0 d-------- C:\WINDOWS\system32\Com
2008-05-10 20:12:50 0 d--hs---- C:\WINDOWS\Installer
2008-05-10 20:12:49 0 d-------- C:\Program Files\Common Files\ODBC
2008-05-10 20:12:47 0 dr------- C:\Program Files
2008-05-10 20:12:47 0 d-------- C:\Program Files\Common Files
2008-05-10 20:12:47 0 d-------- C:\Program Files\Common Files\SpeechEngines
2008-05-10 20:12:28 0 d--h----- C:\Documents and Settings\Default User\Templates
2008-05-10 20:12:28 0 dr------- C:\Documents and Settings\Default User\Start Menu
2008-05-10 20:12:28 0 dr-h----- C:\Documents and Settings\Default User\SendTo
2008-05-10 20:12:28 0 d--h----- C:\Documents and Settings\Default User\Recent
2008-05-10 20:12:28 0 d--h----- C:\Documents and Settings\Default User\PrintHood
2008-05-10 20:12:28 0 d--h----- C:\Documents and Settings\Default User\NetHood
2008-05-10 20:12:28 0 d-------- C:\Documents and Settings\Default User\My Documents
2008-05-10 20:12:28 0 dr-h----- C:\Documents and Settings\Default User\Local Settings
2008-05-10 20:12:28 0 d-------- C:\Documents and Settings\Default User\Favorites
2008-05-10 20:12:28 0 d-------- C:\Documents and Settings\Default User\Desktop
2008-05-10 20:12:28 0 d---s---- C:\Documents and Settings\Default User\Cookies
2008-05-10 20:12:28 0 d--h----- C:\Documents and Settings\All Users\Templates
2008-05-10 20:12:28 0 dr------- C:\Documents and Settings\All Users\Start Menu
2008-05-10 20:12:28 0 d-------- C:\Documents and Settings\All Users\Favorites
2008-05-10 20:12:28 0 dr------- C:\Documents and Settings\All Users\Documents
2008-05-10 20:12:28 0 d-------- C:\Documents and Settings\All Users\Desktop
2008-05-10 20:10:39 0 d-------- C:\WINDOWS\system32\CatRoot2
2008-05-10 20:10:39 0 d-------- C:\WINDOWS\system32\CatRoot
2008-05-10 20:10:34 0 dr-h----- C:\Documents and Settings\Default User\Application Data
2008-05-10 20:10:34 0 d---s---- C:\Documents and Settings\Default User\Application Data\Microsoft
2008-05-10 20:10:33 0 dr-h----- C:\Documents and Settings\All Users\Application Data
2008-05-10 20:10:33 0 d---s---- C:\Documents and Settings\All Users\Application Data\Microsoft
2008-05-10 20:10:15 0 d-------- C:\Documents and Settings
2008-05-10 20:10:14 0 d--hs---- C:\System Volume Information
2008-05-10 20:04:27 0 d-------- C:\WINDOWS
2008-05-10 20:04:27 0 d-------- C:\WINDOWS\WinSxS
2008-05-10 20:04:27 0 dr------- C:\WINDOWS\Web
2008-05-10 20:04:27 0 d-------- C:\WINDOWS\twain_32
2008-05-10 20:04:27 0 d-------- C:\WINDOWS\system32
2008-05-10 20:04:27 0 d-------- C:\WINDOWS\system32\wins
2008-05-10 20:04:27 0 d-------- C:\WINDOWS\system32\wbem
2008-05-10 20:04:27 0 d-------- C:\WINDOWS\system32\usmt
2008-05-10 20:04:27 0 d-------- C:\WINDOWS\system32\spool
2008-05-10 20:04:27 0 d-------- C:\WINDOWS\system32\ShellExt
2008-05-10 20:04:27 0 d-------- C:\WINDOWS\system32\Setup
2008-05-10 20:04:27 0 d-------- C:\WINDOWS\system32\ras
2008-05-10 20:04:27 0 d-------- C:\WINDOWS\system32\oobe
2008-05-10 20:04:27 0 d-------- C:\WINDOWS\system32\npp
2008-05-10 20:04:27 0 d-------- C:\WINDOWS\system32\mui
2008-05-10 20:04:27 0 d-------- C:\WINDOWS\system32\inetsrv
2008-05-10 20:04:27 0 d-------- C:\WINDOWS\system32\IME
2008-05-10 20:04:27 0 d-------- C:\WINDOWS\system32\icsxml
2008-05-10 20:04:27 0 d-------- C:\WINDOWS\system32\ias
2008-05-10 20:04:27 0 d-------- C:\WINDOWS\system32\export
2008-05-10 20:04:27 0 d-------- C:\WINDOWS\system32\drivers
2008-05-10 20:04:27 0 d-------- C:\WINDOWS\system32\drivers\etc
2008-05-10 20:04:27 0 d-------- C:\WINDOWS\system32\drivers\disdn
2008-05-10 20:04:27 0 dr-hs--c- C:\WINDOWS\system32\dllcache
2008-05-10 20:04:27 0 d-------- C:\WINDOWS\system32\dhcp
2008-05-10 20:04:27 0 d-------- C:\WINDOWS\system32\config
2008-05-10 20:04:27 0 d-------- C:\WINDOWS\system32\3com_dmi
2008-05-10 20:04:27 0 d-------- C:\WINDOWS\system32\3076
2008-05-10 20:04:27 0 d-------- C:\WINDOWS\system32\2052
2008-05-10 20:04:27 0 d-------- C:\WINDOWS\system32\1054
2008-05-10 20:04:27 0 d-------- C:\WINDOWS\system32\1042
2008-05-10 20:04:27 0 d-------- C:\WINDOWS\system32\1041
2008-05-10 20:04:27 0 d-------- C:\WINDOWS\system32\1037
2008-05-10 20:04:27 0 d-------- C:\WINDOWS\system32\1033
2008-05-10 20:04:27 0 d-------- C:\WINDOWS\system32\1031
2008-05-10 20:04:27 0 d-------- C:\WINDOWS\system32\1028
2008-05-10 20:04:27 0 d-------- C:\WINDOWS\system32\1025
2008-05-10 20:04:27 0 d-------- C:\WINDOWS\system
2008-05-10 20:04:27 0 d-------- C:\WINDOWS\security
2008-05-10 20:04:27 0 d-------- C:\WINDOWS\Resources
2008-05-10 20:04:27 0 d-------- C:\WINDOWS\repair
2008-05-10 20:04:27 0 d-------- C:\WINDOWS\Provisioning
2008-05-10 20:04:27 0 d-------- C:\WINDOWS\PeerNet
2008-05-10 20:04:27 0 d-------- C:\WINDOWS\pchealth
2008-05-10 20:04:27 0 d-------- C:\WINDOWS\mui
2008-05-10 20:04:27 0 d-------- C:\WINDOWS\msapps
2008-05-10 20:04:27 0 d-------- C:\WINDOWS\msagent
2008-05-10 20:04:27 0 d-------- C:\WINDOWS\Media
2008-05-10 20:04:27 0 d-------- C:\WINDOWS\java
2008-05-10 20:04:27 0 d--h----- C:\WINDOWS\inf
2008-05-10 20:04:27 0 d-------- C:\WINDOWS\ime
2008-05-10 20:04:27 0 d-------- C:\WINDOWS\Help
2008-05-10 20:04:27 0 dr--s---- C:\WINDOWS\Fonts
2008-05-10 20:04:27 0 d-------- C:\WINDOWS\ehome
2008-05-10 20:04:27 0 d-------- C:\WINDOWS\Driver Cache
2008-05-10 20:04:27 0 d-------- C:\WINDOWS\dell
2008-05-10 20:04:27 0 d-------- C:\WINDOWS\Debug
2008-05-10 20:04:27 0 d-------- C:\WINDOWS\Cursors
2008-05-10 20:04:27 0 d-------- C:\WINDOWS\Connection Wizard
2008-05-10 20:04:27 0 d-------- C:\WINDOWS\Config
2008-05-10 20:04:27 0 d-------- C:\WINDOWS\AppPatch
2008-05-10 20:04:27 0 d-------- C:\WINDOWS\addins
-- Find3M Report ---------------------------------------------------------------
2008-05-10 20:12:28 62 --ahs---- C:\Documents and Settings\BAMF3000\Application Data\desktop.ini
-- Registry Dump ---------------------------------------------------------------
*Note* empty entries & legit default entries are not shown
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ehTray"="C:\WINDOWS\ehome\ehtray.exe" [08/10/2004 04:04 AM]
"NvCplDaemon"="C:\WINDOWS\system32\NvCpl.dll" [12/05/2007 01:41 AM]
"nwiz"="nwiz.exe" [12/05/2007 01:41 AM C:\WINDOWS\system32\nwiz.exe]
"NvMediaCenter"="C:\WINDOWS\system32\NvMcTray.dll" [12/05/2007 01:41 AM]
"SoundMan"="SOUNDMAN.EXE" [08/17/2005 06:39 PM C:\WINDOWS\soundman.exe]
"avgnt"="C:\Program Files\Avira\AntiVir PersonalEdition Classic\avgnt.exe" [02/12/2008 10:06 AM]
"iTunesHelper"="C:\Program Files\iTunes\iTunesHelper.exe" [03/30/2008 10:36 AM]
"QuickTime Task"="C:\Program Files\QuickTime\qttask.exe" [03/28/2008 11:37 PM]
"SunJavaUpdateSched"="C:\Program Files\Java\jre1.6.0_06\bin\jusched.exe" [03/25/2008 04:28 AM]
"KernelFaultCheck"="C:\WINDOWS\system32\dumprep 0 -k" []
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"MsnMsgr"="C:\Program Files\Windows Live\Messenger\MsnMsgr.exe" [10/18/2007 11:34 AM]
"SUPERAntiSpyware"="C:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe" [05/13/2008 12:43 PM]
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"InstallVisualStyle"=C:\WINDOWS\Resources\Themes\Royale\Royale.msstyles
"InstallTheme"=C:\WINDOWS\Resources\Themes\Royale.theme
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks]
"{5AE067D3-9AFB-48E0-853A-EBB7F4A000DA}"= C:\Program Files\SUPERAntiSpyware\SASSEH.DLL [05/13/2008 10:13 AM 77824]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\!SASWinLogon]
C:\Program Files\SUPERAntiSpyware\SASWINLO.dll 04/19/2007 01:41 PM 294912 C:\Program Files\SUPERAntiSpyware\SASWINLO.dll
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{15f4b981-1efa-11dd-b1d4-806d6172696f}]
AutoRun\command- F:\setup.exe
-- End of Deckard's System Scanner: finished at 2008-05-31 18:57:49 ------------
Here is Kaspersky:
-------------------------------------------------------------------------------
KASPERSKY ONLINE SCANNER REPORT
Saturday, May 31, 2008 6:42:30 PM
Operating System: Microsoft Windows XP Professional, Service Pack 2 (Build 2600)
Kaspersky Online Scanner version: 5.0.98.0
Kaspersky Anti-Virus database last update: 31/05/2008
Kaspersky Anti-Virus database records: 818915
-------------------------------------------------------------------------------
Scan Settings:
Scan using the following antivirus database: extended
Scan Archives: true
Scan Mail Bases: true
Scan Target - My Computer:
A:\
C:\
D:\
E:\
F:\
G:\
Scan Statistics:
Total number of scanned objects: 43322
Number of viruses found: 0
Number of infected objects: 0
Number of suspicious objects: 0
Duration of the scan process: 00:39:22
Infected Object Name / Virus Name / Last Action
C:\Documents and Settings\All Users\Application Data\Microsoft\eHome\logs\ehRecvr.log Object is locked skipped
C:\Documents and Settings\BAMF3000\Application Data\Mozilla\Firefox\Profiles\rpn2dq14.default\cert8.db Object is locked skipped
C:\Documents and Settings\BAMF3000\Application Data\Mozilla\Firefox\Profiles\rpn2dq14.default\history.dat Object is locked skipped
C:\Documents and Settings\BAMF3000\Application Data\Mozilla\Firefox\Profiles\rpn2dq14.default\key3.db Object is locked skipped
C:\Documents and Settings\BAMF3000\Application Data\Mozilla\Firefox\Profiles\rpn2dq14.default\parent.lock Object is locked skipped
C:\Documents and Settings\BAMF3000\Application Data\Mozilla\Firefox\Profiles\rpn2dq14.default\search.sqlite Object is locked skipped
C:\Documents and Settings\BAMF3000\Application Data\Mozilla\Firefox\Profiles\rpn2dq14.default\urlclassifier2.sqlite Object is locked skipped
C:\Documents and Settings\BAMF3000\Application Data\SUPERAntiSpyware.com\SUPERAntiSpyware\AppLogs\SUPERANTISPYWARE-5-31-2008( 7-4-55 ).LOG Object is locked skipped
C:\Documents and Settings\BAMF3000\Cookies\index.dat Object is locked skipped
C:\Documents and Settings\BAMF3000\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat Object is locked skipped
C:\Documents and Settings\BAMF3000\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat.LOG Object is locked skipped
C:\Documents and Settings\BAMF3000\Local Settings\Application Data\Mozilla\Firefox\Profiles\rpn2dq14.default\Cache\_CACHE_001_ Object is locked skipped
C:\Documents and Settings\BAMF3000\Local Settings\Application Data\Mozilla\Firefox\Profiles\rpn2dq14.default\Cache\_CACHE_002_ Object is locked skipped
C:\Documents and Settings\BAMF3000\Local Settings\Application Data\Mozilla\Firefox\Profiles\rpn2dq14.default\Cache\_CACHE_003_ Object is locked skipped
C:\Documents and Settings\BAMF3000\Local Settings\Application Data\Mozilla\Firefox\Profiles\rpn2dq14.default\Cache\_CACHE_MAP_ Object is locked skipped
C:\Documents and Settings\BAMF3000\Local Settings\History\History.IE5\index.dat Object is locked skipped
C:\Documents and Settings\BAMF3000\Local Settings\Temporary Internet Files\AntiPhishing\B3BB5BBA-E7D5-40AB-A041-A5B1C0B26C8F.dat Object is locked skipped
C:\Documents and Settings\BAMF3000\Local Settings\Temporary Internet Files\Content.IE5\index.dat Object is locked skipped
C:\Documents and Settings\BAMF3000\NTUSER.DAT Object is locked skipped
C:\Documents and Settings\BAMF3000\ntuser.dat.LOG Object is locked skipped
C:\Documents and Settings\LocalService\Cookies\index.dat Object is locked skipped
C:\Documents and Settings\LocalService\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat Object is locked skipped
C:\Documents and Settings\LocalService\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat.LOG Object is locked skipped
C:\Documents and Settings\LocalService\Local Settings\History\History.IE5\index.dat Object is locked skipped
C:\Documents and Settings\LocalService\Local Settings\Temporary Internet Files\Content.IE5\index.dat Object is locked skipped
C:\Documents and Settings\LocalService\NTUSER.DAT Object is locked skipped
C:\Documents and Settings\LocalService\ntuser.dat.LOG Object is locked skipped
C:\Documents and Settings\NetworkService\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat Object is locked skipped
C:\Documents and Settings\NetworkService\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat.LOG Object is locked skipped
C:\Documents and Settings\NetworkService\NTUSER.DAT Object is locked skipped
C:\Documents and Settings\NetworkService\ntuser.dat.LOG Object is locked skipped
C:\System Volume Information\MountPointManagerRemoteDatabase Object is locked skipped
C:\System Volume Information\_restore{5C960178-C3DB-4942-9A15-2DBC73BAF0CB}\RP43\change.log Object is locked skipped
C:\WINDOWS\Debug\PASSWD.LOG Object is locked skipped
C:\WINDOWS\Registration\{02D4B3F1-FD88-11D1-960D-00805FC79235}.{07E1B2EB-FA4D-4800-BE72-4ED0D05EA9E5}.crmlog Object is locked skipped
C:\WINDOWS\SchedLgU.Txt Object is locked skipped
C:\WINDOWS\SoftwareDistribution\ReportingEvents.log Object is locked skipped
C:\WINDOWS\Sti_Trace.log Object is locked skipped
C:\WINDOWS\system32\CatRoot2\edb.log Object is locked skipped
C:\WINDOWS\system32\CatRoot2\tmp.edb Object is locked skipped
C:\WINDOWS\system32\config\AppEvent.Evt Object is locked skipped
C:\WINDOWS\system32\config\default Object is locked skipped
C:\WINDOWS\system32\config\default.LOG Object is locked skipped
C:\WINDOWS\system32\config\Internet.evt Object is locked skipped
C:\WINDOWS\system32\config\Media Ce.evt Object is locked skipped
C:\WINDOWS\system32\config\SAM Object is locked skipped
C:\WINDOWS\system32\config\SAM.LOG Object is locked skipped
C:\WINDOWS\system32\config\SecEvent.Evt Object is locked skipped
C:\WINDOWS\system32\config\SECURITY Object is locked skipped
C:\WINDOWS\system32\config\SECURITY.LOG Object is locked skipped
C:\WINDOWS\system32\config\software Object is locked skipped
C:\WINDOWS\system32\config\software.LOG Object is locked skipped
C:\WINDOWS\system32\config\SysEvent.Evt Object is locked skipped
C:\WINDOWS\system32\config\system Object is locked skipped
C:\WINDOWS\system32\config\system.LOG Object is locked skipped
C:\WINDOWS\system32\h323log.txt Object is locked skipped
C:\WINDOWS\system32\wbem\Repository\FS\INDEX.BTR Object is locked skipped
C:\WINDOWS\system32\wbem\Repository\FS\INDEX.MAP Object is locked skipped
C:\WINDOWS\system32\wbem\Repository\FS\MAPPING.VER Object is locked skipped
C:\WINDOWS\system32\wbem\Repository\FS\MAPPING1.MAP Object is locked skipped
C:\WINDOWS\system32\wbem\Repository\FS\MAPPING2.MAP Object is locked skipped
C:\WINDOWS\system32\wbem\Repository\FS\OBJECTS.DATA Object is locked skipped
C:\WINDOWS\system32\wbem\Repository\FS\OBJECTS.MAP Object is locked skipped
C:\WINDOWS\wiadebug.log Object is locked skipped
C:\WINDOWS\wiaservc.log Object is locked skipped
C:\WINDOWS\WindowsUpdate.log Object is locked skipped
D:\System Volume Information\MountPointManagerRemoteDatabase Object is locked skipped
D:\System Volume Information\_restore{5C960178-C3DB-4942-9A15-2DBC73BAF0CB}\RP43\change.log Object is locked skipped
E:\RECYCLER\S-1-5-21-1757981266-1284227242-725345543-1004\De4\%temp%dd_msxml_retMSI.txt Object is locked skipped
E:\System Volume Information\MountPointManagerRemoteDatabase Object is locked skipped
E:\System Volume Information\_restore{5C960178-C3DB-4942-9A15-2DBC73BAF0CB}\RP43\change.log Object is locked skipped
Scan process completed.
Here is Rootalyzer
// info: Rootkit removal help file
// copyright: © 2008 Safer Networking Ltd. All rights reserved.
:: RootAlyzer Results
File:"Unknown ADS","E:\Videos\TT Videos\SkyonFire.bmp:Q30lsldxJoudresxAaaqpcawXc:$DATA"
File:"Unknown ADS","E:\My Pictures\My Pictures- family- irreplaceable\dec 03 - feb 04\DSCF0001.JPG:Q30lsldxJoudresxAaaqpcawXc:$DATA"
File:"Unknown ADS","E:\My Pictures\My Pictures- family- irreplaceable\dec 03 - feb 04\DSCF0006.JPG:Q30lsldxJoudresxAaaqpcawXc:$DATA"
File:"Unknown ADS","E:\My Pictures\My Pictures- family- irreplaceable\dec 03 - feb 04\DSCF0007.JPG:Q30lsldxJoudresxAaaqpcawXc:$DATA"
File:"Unknown ADS","E:\My Pictures\My Pictures- family- irreplaceable\dec 03 - feb 04\DSCF0011.JPG:Q30lsldxJoudresxAaaqpcawXc:$DATA"
File:"Unknown ADS","E:\My Pictures\My Pictures- family- irreplaceable\dec 03 - feb 04\DSCF0012.JPG:Q30lsldxJoudresxAaaqpcawXc:$DATA"
File:"Unknown ADS","E:\My Pictures\My Pictures- family- irreplaceable\dec 03 - feb 04\DSCF0013.JPG:Q30lsldxJoudresxAaaqpcawXc:$DATA"
File:"Unknown ADS","E:\My Pictures\My Pictures- family- irreplaceable\dec 03 - feb 04\DSCF0014.JPG:Q30lsldxJoudresxAaaqpcawXc:$DATA"
File:"Unknown ADS","E:\My Pictures\My Pictures- family- irreplaceable\dec 03 - feb 04\DSCF0015.JPG:Q30lsldxJoudresxAaaqpcawXc:$DATA"
File:"Unknown ADS","E:\My Pictures\My Pictures- family- irreplaceable\dec 03 - feb 04\DSCF0016.JPG:Q30lsldxJoudresxAaaqpcawXc:$DATA"
File:"Unknown ADS","E:\My Pictures\My Pictures- family- irreplaceable\dec 03 - feb 04\DSCF0017.JPG:Q30lsldxJoudresxAaaqpcawXc:$DATA"
File:"Unknown ADS","E:\My Pictures\My Pictures- family- irreplaceable\dec 03 - feb 04\DSCF0018.JPG:Q30lsldxJoudresxAaaqpcawXc:$DATA"
File:"Unknown ADS","E:\My Pictures\My Pictures- family- irreplaceable\dec 03 - feb 04\DSCF0019.JPG:Q30lsldxJoudresxAaaqpcawXc:$DATA"
File:"Unknown ADS","E:\My Pictures\My Pictures- family- irreplaceable\dec 03 - feb 04\DSCF0020.JPG:Q30lsldxJoudresxAaaqpcawXc:$DATA"
File:"Unknown ADS","E:\My Pictures\My Pictures- family- irreplaceable\dec 03 - feb 04\DSCF0021.JPG:Q30lsldxJoudresxAaaqpcawXc:$DATA"
File:"Unknown ADS","E:\My Pictures\My Pictures- family- irreplaceable\dec 03 - feb 04\DSCF0022.JPG:Q30lsldxJoudresxAaaqpcawXc:$DATA"
File:"Unknown ADS","E:\My Pictures\My Pictures- family- irreplaceable\dec 03 - feb 04\DSCF0023.JPG:Q30lsldxJoudresxAaaqpcawXc:$DATA"
File:"Unknown ADS","E:\My Pictures\My Pictures- family- irreplaceable\dec 03 - feb 04\DSCF0024.JPG:Q30lsldxJoudresxAaaqpcawXc:$DATA"
File:"Unknown ADS","E:\My Pictures\My Pictures- family- irreplaceable\dec 03 - feb 04\DSCF0025.JPG:Q30lsldxJoudresxAaaqpcawXc:$DATA"
File:"Unknown ADS","E:\My Pictures\My Pictures- family- irreplaceable\dec 03 - feb 04\DSCF0026.JPG:Q30lsldxJoudresxAaaqpcawXc:$DATA"
File:"Unknown ADS","E:\My Pictures\My Pictures- family- irreplaceable\dec 03 - feb 04\DSCF0027.JPG:Q30lsldxJoudresxAaaqpcawXc:$DATA"
File:"Unknown ADS","E:\My Pictures\My Pictures- family- irreplaceable\dec 03 - feb 04\DSCF0028.JPG:Q30lsldxJoudresxAaaqpcawXc:$DATA"
File:"Unknown ADS","E:\My Pictures\My Pictures- family- irreplaceable\dec 03 - feb 04\DSCF0029.JPG:Q30lsldxJoudresxAaaqpcawXc:$DATA"
File:"Unknown ADS","E:\My Pictures\My Pictures- family- irreplaceable\dec 03 - feb 04\DSCF0030.JPG:Q30lsldxJoudresxAaaqpcawXc:$DATA"
File:"Unknown ADS","E:\My Pictures\My Pictures- family- irreplaceable\dec 03 - feb 04\DSCF0031.JPG:Q30lsldxJoudresxAaaqpcawXc:$DATA"
File:"Unknown ADS","E:\My Pictures\My Pictures- family- irreplaceable\dec 03 - feb 04\DSCF0032.JPG:Q30lsldxJoudresxAaaqpcawXc:$DATA"
File:"Unknown ADS","E:\My Pictures\My Pictures- family- irreplaceable\dec 03 - feb 04\DSCF0033.JPG:Q30lsldxJoudresxAaaqpcawXc:$DATA"
File:"Unknown ADS","E:\My Pictures\My Pictures- family- irreplaceable\dec 03 - feb 04\DSCF0034.JPG:Q30lsldxJoudresxAaaqpcawXc:$DATA"
File:"Unknown ADS","E:\My Pictures\My Pictures- family- irreplaceable\dec 03 - feb 04\DSCF0035.JPG:Q30lsldxJoudresxAaaqpcawXc:$DATA"
File:"Unknown ADS","E:\My Pictures\My Pictures- family- irreplaceable\dec 03 - feb 04\DSCF0036.JPG:Q30lsldxJoudresxAaaqpcawXc:$DATA"
File:"Unknown ADS","E:\My Pictures\My Pictures- family- irreplaceable\dec 03 - feb 04\DSCF0037.JPG:Q30lsldxJoudresxAaaqpcawXc:$DATA"
File:"Unknown ADS","C:\Documents and Settings\BAMF3000\My Documents\My Pictures\My Pictures- family- irreplaceable\dec 03 - feb 04\DSCF0001.JPG:Q30lsldxJoudresxAaaqpcawXc:$DATA"
File:"Unknown ADS","C:\Documents and Settings\BAMF3000\My Documents\My Pictures\My Pictures- family- irreplaceable\dec 03 - feb 04\DSCF0006.JPG:Q30lsldxJoudresxAaaqpcawXc:$DATA"
File:"Unknown ADS","C:\Documents and Settings\BAMF3000\My Documents\My Pictures\My Pictures- family- irreplaceable\dec 03 - feb 04\DSCF0007.JPG:Q30lsldxJoudresxAaaqpcawXc:$DATA"
File:"Unknown ADS","C:\Documents and Settings\BAMF3000\My Documents\My Pictures\My Pictures- family- irreplaceable\dec 03 - feb 04\DSCF0011.JPG:Q30lsldxJoudresxAaaqpcawXc:$DATA"
File:"Unknown ADS","C:\Documents and Settings\BAMF3000\My Documents\My Pictures\My Pictures- family- irreplaceable\dec 03 - feb 04\DSCF0012.JPG:Q30lsldxJoudresxAaaqpcawXc:$DATA"
File:"Unknown ADS","C:\Documents and Settings\BAMF3000\My Documents\My Pictures\My Pictures- family- irreplaceable\dec 03 - feb 04\DSCF0013.JPG:Q30lsldxJoudresxAaaqpcawXc:$DATA"
File:"Unknown ADS","C:\Documents and Settings\BAMF3000\My Documents\My Pictures\My Pictures- family- irreplaceable\dec 03 - feb 04\DSCF0014.JPG:Q30lsldxJoudresxAaaqpcawXc:$DATA"
File:"Unknown ADS","C:\Documents and Settings\BAMF3000\My Documents\My Pictures\My Pictures- family- irreplaceable\dec 03 - feb 04\DSCF0015.JPG:Q30lsldxJoudresxAaaqpcawXc:$DATA"
File:"Unknown ADS","C:\Documents and Settings\BAMF3000\My Documents\My Pictures\My Pictures- family- irreplaceable\dec 03 - feb 04\DSCF0016.JPG:Q30lsldxJoudresxAaaqpcawXc:$DATA"
File:"Unknown ADS","C:\Documents and Settings\BAMF3000\My Documents\My Pictures\My Pictures- family- irreplaceable\dec 03 - feb 04\DSCF0017.JPG:Q30lsldxJoudresxAaaqpcawXc:$DATA"
File:"Unknown ADS","C:\Documents and Settings\BAMF3000\My Documents\My Pictures\My Pictures- family- irreplaceable\dec 03 - feb 04\DSCF0018.JPG:Q30lsldxJoudresxAaaqpcawXc:$DATA"
File:"Unknown ADS","C:\Documents and Settings\BAMF3000\My Documents\My Pictures\My Pictures- family- irreplaceable\dec 03 - feb 04\DSCF0019.JPG:Q30lsldxJoudresxAaaqpcawXc:$DATA"
File:"Unknown ADS","C:\Documents and Settings\BAMF3000\My Documents\My Pictures\My Pictures- family- irreplaceable\dec 03 - feb 04\DSCF0020.JPG:Q30lsldxJoudresxAaaqpcawXc:$DATA"
File:"Unknown ADS","C:\Documents and Settings\BAMF3000\My Documents\My Pictures\My Pictures- family- irreplaceable\dec 03 - feb 04\DSCF0021.JPG:Q30lsldxJoudresxAaaqpcawXc:$DATA"
File:"Unknown ADS","C:\Documents and Settings\BAMF3000\My Documents\My Pictures\My Pictures- family- irreplaceable\dec 03 - feb 04\DSCF0022.JPG:Q30lsldxJoudresxAaaqpcawXc:$DATA"
File:"Unknown ADS","C:\Documents and Settings\BAMF3000\My Documents\My Pictures\My Pictures- family- irreplaceable\dec 03 - feb 04\DSCF0023.JPG:Q30lsldxJoudresxAaaqpcawXc:$DATA"
File:"Unknown ADS","C:\Documents and Settings\BAMF3000\My Documents\My Pictures\My Pictures- family- irreplaceable\dec 03 - feb 04\DSCF0024.JPG:Q30lsldxJoudresxAaaqpcawXc:$DATA"
File:"Unknown ADS","C:\Documents and Settings\BAMF3000\My Documents\My Pictures\My Pictures- family- irreplaceable\dec 03 - feb 04\DSCF0025.JPG:Q30lsldxJoudresxAaaqpcawXc:$DATA"
File:"Unknown ADS","C:\Documents and Settings\BAMF3000\My Documents\My Pictures\My Pictures- family- irreplaceable\dec 03 - feb 04\DSCF0026.JPG:Q30lsldxJoudresxAaaqpcawXc:$DATA"
File:"Unknown ADS","C:\Documents and Settings\BAMF3000\My Documents\My Pictures\My Pictures- family- irreplaceable\dec 03 - feb 04\DSCF0027.JPG:Q30lsldxJoudresxAaaqpcawXc:$DATA"
File:"Unknown ADS","C:\Documents and Settings\BAMF3000\My Documents\My Pictures\My Pictures- family- irreplaceable\dec 03 - feb 04\DSCF0028.JPG:Q30lsldxJoudresxAaaqpcawXc:$DATA"
File:"Unknown ADS","C:\Documents and Settings\BAMF3000\My Documents\My Pictures\My Pictures- family- irreplaceable\dec 03 - feb 04\DSCF0029.JPG:Q30lsldxJoudresxAaaqpcawXc:$DATA"
File:"Unknown ADS","C:\Documents and Settings\BAMF3000\My Documents\My Pictures\My Pictures- family- irreplaceable\dec 03 - feb 04\DSCF0030.JPG:Q30lsldxJoudresxAaaqpcawXc:$DATA"
File:"Unknown ADS","C:\Documents and Settings\BAMF3000\My Documents\My Pictures\My Pictures- family- irreplaceable\dec 03 - feb 04\DSCF0031.JPG:Q30lsldxJoudresxAaaqpcawXc:$DATA"
File:"Unknown ADS","C:\Documents and Settings\BAMF3000\My Documents\My Pictures\My Pictures- family- irreplaceable\dec 03 - feb 04\DSCF0032.JPG:Q30lsldxJoudresxAaaqpcawXc:$DATA"
File:"Unknown ADS","C:\Documents and Settings\BAMF3000\My Documents\My Pictures\My Pictures- family- irreplaceable\dec 03 - feb 04\DSCF0033.JPG:Q30lsldxJoudresxAaaqpcawXc:$DATA"
File:"Unknown ADS","C:\Documents and Settings\BAMF3000\My Documents\My Pictures\My Pictures- family- irreplaceable\dec 03 - feb 04\DSCF0034.JPG:Q30lsldxJoudresxAaaqpcawXc:$DATA"
File:"Unknown ADS","C:\Documents and Settings\BAMF3000\My Documents\My Pictures\My Pictures- family- irreplaceable\dec 03 - feb 04\DSCF0035.JPG:Q30lsldxJoudresxAaaqpcawXc:$DATA"
File:"Unknown ADS","C:\Documents and Settings\BAMF3000\My Documents\My Pictures\My Pictures- family- irreplaceable\dec 03 - feb 04\DSCF0036.JPG:Q30lsldxJoudresxAaaqpcawXc:$DATA"
File:"Unknown ADS","C:\Documents and Settings\BAMF3000\My Documents\My Pictures\My Pictures- family- irreplaceable\dec 03 - feb 04\DSCF0037.JPG:Q30lsldxJoudresxAaaqpcawXc:$DATA"