[code] WinPFind35 logfile created on: 2/20/2008 6:32:59 PM WinPFind35U Version 1.0.0.0 Folder = C:\Documents and Settings\Boo Boo\Desktop\WinPFind35u Windows XP Home Edition Service Pack 2 (Version = 5.1.2600) - Type = NTWorkstation Internet Explorer (Version = 6.0.2900.2180) Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy 495.30 Mb Total Physical Memory | 103.69 Mb Available Physical Memory | 20.94% Memory free 1.13 Gb Paging File | 0.76 Gb Available in Paging File | 67.85% Paging File free Paging file location(s): C:\pagefile.sys 744 1488; %SystemDrive% = C: | %SystemRoot% = C:\WINDOWS | %ProgramFiles% = C:\Program Files Drive C: | 54.84 Gb Total Space | 12.58 Gb Free Space | 22.93% Space Free | Partition Type: NTFS Drive D: | 36.46 Gb Total Space | 1.71 Gb Free Space | 4.69% Space Free | Partition Type: NTFS E: Drive not present or media not loaded F: Drive not present or media not loaded G: Drive not present or media not loaded H: Drive not present or media not loaded I: Drive not present or media not loaded Computer Name: LISAB Current User Name: Boo Boo Logged in as Administrator. Current Boot Mode: Normal Scan Mode: Current user [Processes - Non-Microsoft Only] evteng.exe -> %ProgramFiles%\Intel\Wireless\Bin\EvtEng.exe -> Intel Corporation [Ver = 9, 0, 1, 12 | Size = 86016 bytes | Modified Date = 10/15/2004 10:22:14 AM | Attr = ] s24evmon.exe -> %ProgramFiles%\Intel\Wireless\Bin\S24EvMon.exe -> Intel Corporation [Ver = 9, 0, 1, 41 | Size = 360521 bytes | Modified Date = 10/15/2004 10:24:48 AM | Attr = ] zcfgsvc.exe -> %ProgramFiles%\Intel\Wireless\Bin\ZCfgSvc.exe -> Intel Corporation [Ver = 9, 0, 1, 51 | Size = 389120 bytes | Modified Date = 10/15/2004 10:27:38 AM | Attr = ] hcontrol.exe -> %SystemRoot%\ATK0100\HControl.exe -> [Ver = 1043, 2, 15, 48 | Size = 102400 bytes | Modified Date = 5/11/2005 11:15:14 PM | Attr = ] hkcmd.exe -> %SystemRoot%\system32\hkcmd.exe -> Intel Corporation [Ver = 3.0.0.4332 | Size = 77824 bytes | Modified Date = 6/7/2005 6:59:00 PM | Attr = ] igfxpers.exe -> %SystemRoot%\system32\igfxpers.exe -> Intel Corporation [Ver = 3.0.0.4332 | Size = 114688 bytes | Modified Date = 6/7/2005 7:03:00 PM | Attr = ] alu.exe -> %ProgramFiles%\ASUS\ASUS Live Update\ALU.exe -> [Ver = 1, 0, 0, 1 | Size = 172032 bytes | Modified Date = 9/19/2003 11:54:44 AM | Attr = ] wcourier.exe -> %ProgramFiles%\ASUS\Wireless Console\wcourier.exe -> [Ver = 1, 0, 9, 620 | Size = 57344 bytes | Modified Date = 6/20/2005 6:16:36 PM | Attr = ] syntplpr.exe -> %ProgramFiles%\Synaptics\SynTP\SynTPLpr.exe -> Synaptics, Inc. [Ver = 7.12.9 19Nov04 | Size = 98394 bytes | Modified Date = 12/21/2004 10:23:00 PM | Attr = ] syntpenh.exe -> %ProgramFiles%\Synaptics\SynTP\SynTPEnh.exe -> Synaptics, Inc. [Ver = 7.12.9 19Nov04 | Size = 688218 bytes | Modified Date = 12/21/2004 10:23:00 PM | Attr = ] soundman.exe -> %SystemRoot%\SoundMan.exe -> Realtek Semiconductor Corp. [Ver = 1, 0, 0, 14 | Size = 77824 bytes | Modified Date = 1/4/2005 11:40:24 PM | Attr = ] ifrmewrk.exe -> %ProgramFiles%\Intel\Wireless\Bin\iFrmewrk.exe -> Intel Corporation [Ver = 9, 0, 1, 19 | Size = 385024 bytes | Modified Date = 10/15/2004 10:27:56 AM | Attr = ] eouwiz.exe -> %ProgramFiles%\Intel\Wireless\Bin\EOUWiz.exe -> Intel Corporation [Ver = 9, 0, 1, 26 | Size = 356352 bytes | Modified Date = 10/15/2004 10:31:32 AM | Attr = ] acrotray.exe -> %ProgramFiles%\Adobe\Acrobat 8.0\Acrobat\acrotray.exe -> Adobe Systems Inc. [Ver = 8.1.0.2007051000 | Size = 624248 bytes | Modified Date = 5/10/2007 9:46:20 PM | Attr = ] jusched.exe -> %ProgramFiles%\Java\jre1.6.0_03\bin\jusched.exe -> Sun Microsystems, Inc. [Ver = 6.0.30.5 | Size = 132496 bytes | Modified Date = 9/25/2007 1:11:35 AM | Attr = ] ituneshelper.exe -> %ProgramFiles%\iTunes\iTunesHelper.exe -> Apple Inc. [Ver = 7.6.0.29 | Size = 267048 bytes | Modified Date = 2/4/2008 2:18:40 PM | Attr = ] avgas.exe -> %ProgramFiles%\Grisoft\AVG Anti-Spyware 7.5\avgas.exe -> GRISOFT s.r.o. [Ver = 7, 5, 1, 43 | Size = 6731312 bytes | Modified Date = 6/11/2007 1:25:42 AM | Attr = ] tosbtmng.exe -> %ProgramFiles%\Toshiba\Bluetooth Toshiba Stack\TosBtMng.exe -> TOSHIBA CORPORATION. [Ver = 3.03.5114.US | Size = 479232 bytes | Modified Date = 1/14/2005 6:54:48 PM | Attr = ] setpoint.exe -> %ProgramFiles%\SetPoint\SetPoint.exe -> Logitech Inc. [Ver = 2.40.849 | Size = 450560 bytes | Modified Date = 5/25/2005 1:40:00 AM | Attr = ] khalmnpr.exe -> %CommonProgramFiles%\Logitech\KHAL\KHALMNPR.EXE -> Logitech Inc. [Ver = 2.40.840 | Size = 28160 bytes | Modified Date = 5/25/2005 1:40:00 AM | Attr = ] atkosd.exe -> %SystemRoot%\ATK0100\ATKOSD.exe -> [Ver = 1043, 2, 15, 48 | Size = 1953792 bytes | Modified Date = 5/9/2005 6:12:22 PM | Attr = ] tosa2dp.exe -> %ProgramFiles%\Toshiba\Bluetooth Toshiba Stack\TosA2dp.exe -> TOSHIBA CORPORATION. [Ver = 3.01.4y30.US | Size = 253952 bytes | Modified Date = 11/30/2004 6:09:34 PM | Attr = ] tosbthsp.exe -> %ProgramFiles%\Toshiba\Bluetooth Toshiba Stack\TosBtHSP.exe -> TOSHIBA CORPORATION. [Ver = 2.03.3603.0 | Size = 450560 bytes | Modified Date = 10/14/2004 3:13:58 AM | Attr = ] guard.exe -> %ProgramFiles%\Grisoft\AVG Anti-Spyware 7.5\guard.exe -> GRISOFT s.r.o. [Ver = 7, 5, 1, 22 | Size = 312880 bytes | Modified Date = 5/30/2007 4:31:10 AM | Attr = ] lssrvc.exe -> %CommonProgramFiles%\LightScribe\LSSrvc.exe -> Hewlett-Packard Company [Ver = 1.4.31.1 | Size = 53248 bytes | Modified Date = 6/20/2005 10:10:30 PM | Attr = ] oprotsvc.exe -> %ProgramFiles%\Intel\Wireless\Bin\OProtSvc.exe -> Intel Corporation [Ver = 9, 0, 1, 3 | Size = 98304 bytes | Modified Date = 10/15/2004 10:30:52 AM | Attr = ] regsrvc.exe -> %ProgramFiles%\Intel\Wireless\Bin\RegSrvc.exe -> Intel Corporation [Ver = 9, 0, 1, 10 | Size = 139264 bytes | Modified Date = 10/15/2004 10:21:38 AM | Attr = ] fnplicensingservice.exe -> %CommonProgramFiles%\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe -> Macrovision Europe Ltd. [Ver = 11.03.005 | Size = 654848 bytes | Modified Date = 9/1/2007 1:51:38 PM | Attr = ] ipodservice.exe -> %ProgramFiles%\iPod\bin\iPodService.exe -> Apple Inc. [Ver = 7.6.0.29 | Size = 504104 bytes | Modified Date = 2/4/2008 2:18:32 PM | Attr = ] winpfind35u.exe -> %UserProfile%\Desktop\WinPFind35u\WinPFind35U.exe -> OldTimer Tools [Ver = 1.0.0.0 | Size = 309760 bytes | Modified Date = 2/20/2008 11:36:44 AM | Attr = ] [Win32 Services - Non-Microsoft Only] (Adobe LM Service) Adobe LM Service [Win32_Own | On_Demand | Stopped] -> %CommonProgramFiles%\Adobe Systems Shared\Service\Adobelmsvc.exe -> Adobe Systems [Ver = 2.67.010 | Size = 72704 bytes | Modified Date = 9/1/2007 1:32:41 PM | Attr = ] (AVG Anti-Spyware Guard) AVG Anti-Spyware Guard [Win32_Own | Auto | Running] -> %ProgramFiles%\Grisoft\AVG Anti-Spyware 7.5\guard.exe -> GRISOFT s.r.o. [Ver = 7, 5, 1, 22 | Size = 312880 bytes | Modified Date = 5/30/2007 4:31:10 AM | Attr = ] (dmadmin) Logical Disk Manager Administrative Service [Win32_Shared | On_Demand | Stopped] -> %SystemRoot%\system32\dmadmin.exe -> Microsoft Corp., Veritas Software [Ver = 2600.2180.503.0 | Size = 224768 bytes | Modified Date = 8/4/2004 7:00:00 PM | Attr = ] (EvtEng) EvtEng [Win32_Own | Auto | Running] -> %ProgramFiles%\Intel\Wireless\Bin\EvtEng.exe -> Intel Corporation [Ver = 9, 0, 1, 12 | Size = 86016 bytes | Modified Date = 10/15/2004 10:22:14 AM | Attr = ] (FLEXnet Licensing Service) FLEXnet Licensing Service [Win32_Own | On_Demand | Running] -> %CommonProgramFiles%\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe -> Macrovision Europe Ltd. [Ver = 11.03.005 | Size = 654848 bytes | Modified Date = 9/1/2007 1:51:38 PM | Attr = ] (iPod Service) iPod Service [Win32_Own | On_Demand | Running] -> %ProgramFiles%\iPod\bin\iPodService.exe -> Apple Inc. [Ver = 7.6.0.29 | Size = 504104 bytes | Modified Date = 2/4/2008 2:18:32 PM | Attr = ] (LightScribeService) LightScribeService Direct Disc Labeling Service [Win32_Own | Auto | Running] -> %CommonProgramFiles%\LightScribe\LSSrvc.exe -> Hewlett-Packard Company [Ver = 1.4.31.1 | Size = 53248 bytes | Modified Date = 6/20/2005 10:10:30 PM | Attr = ] (MSControlService) Microsoft cache control [Win32_Own | On_Demand | Stopped] -> -> File not found (OwnershipProtocol) OwnershipProtocol [Win32_Own | Auto | Running] -> %ProgramFiles%\Intel\Wireless\Bin\OProtSvc.exe -> Intel Corporation [Ver = 9, 0, 1, 3 | Size = 98304 bytes | Modified Date = 10/15/2004 10:30:52 AM | Attr = ] (RegSrvc) RegSrvc [Win32_Own | Auto | Running] -> %ProgramFiles%\Intel\Wireless\Bin\RegSrvc.exe -> Intel Corporation [Ver = 9, 0, 1, 10 | Size = 139264 bytes | Modified Date = 10/15/2004 10:21:38 AM | Attr = ] (S24EventMonitor) Spectrum24 Event Monitor [Win32_Own | Auto | Running] -> %ProgramFiles%\Intel\Wireless\Bin\S24EvMon.exe -> Intel Corporation [Ver = 9, 0, 1, 41 | Size = 360521 bytes | Modified Date = 10/15/2004 10:24:48 AM | Attr = ] [Driver Services - Non-Microsoft Only] (Abiosdsk) Abiosdsk [Kernel | Disabled | Stopped] -> -> File not found (abp480n5) abp480n5 [Kernel | Disabled | Stopped] -> -> File not found (adpu160m) adpu160m [Kernel | Disabled | Stopped] -> -> File not found (AegisP) AEGIS Protocol (IEEE 802.1x) v3.1.6.0 [Kernel | Auto | Running] -> %SystemRoot%\system32\drivers\AegisP.sys -> Meetinghouse Data Communications [Ver = 3.1.6.0 | Size = 17119 bytes | Modified Date = 9/1/2007 11:34:26 AM | Attr = ] (Aha154x) Aha154x [Kernel | Disabled | Stopped] -> -> File not found (aic78u2) aic78u2 [Kernel | Disabled | Stopped] -> -> File not found (aic78xx) aic78xx [Kernel | Disabled | Stopped] -> -> File not found (AliIde) AliIde [Kernel | Disabled | Stopped] -> -> File not found (amsint) amsint [Kernel | Disabled | Stopped] -> -> File not found (asc) asc [Kernel | Disabled | Stopped] -> -> File not found (asc3350p) asc3350p [Kernel | Disabled | Stopped] -> -> File not found (asc3550) asc3550 [Kernel | Disabled | Stopped] -> -> File not found (ASPI32) ASPI32 [Kernel | System | Running] -> %SystemRoot%\system32\drivers\ASPI32.SYS -> Adaptec [Ver = 4.60 (1021) | Size = 25244 bytes | Modified Date = 9/10/1999 12:06:00 PM | Attr = ] (Atdisk) Atdisk [Kernel | Disabled | Stopped] -> -> File not found (AVG Anti-Spyware Driver) AVG Anti-Spyware Driver [Kernel | System | Running] -> %ProgramFiles%\Grisoft\AVG Anti-Spyware 7.5\guard.sys -> [Ver = | Size = 11000 bytes | Modified Date = 5/30/2007 4:10:42 AM | Attr = ] (AvgAsCln) AVG Anti-Spyware Clean Driver [Kernel | System | Running] -> %SystemRoot%\system32\drivers\AvgAsCln.sys -> GRISOFT, s.r.o. [Ver = 1.0.0.14 | Size = 10872 bytes | Modified Date = 5/30/2007 4:10:42 AM | Attr = ] (Cam5603D) ASUS Mobile Vision Camera W5-A01 [Kernel | On_Demand | Running] -> %SystemRoot%\system32\drivers\BisonCam.sys -> Bison Electronics. Inc. [Ver = 6.0.0.9 | Size = 681600 bytes | Modified Date = 5/3/2005 7:03:00 PM | Attr = ] (cd20xrnt) cd20xrnt [Kernel | Disabled | Stopped] -> -> File not found (Changer) Changer [Kernel | System | Stopped] -> -> File not found (CmdIde) CmdIde [Kernel | Disabled | Stopped] -> -> File not found (Cpqarray) Cpqarray [Kernel | Disabled | Stopped] -> -> File not found (dac960nt) dac960nt [Kernel | Disabled | Stopped] -> -> File not found (dmboot) dmboot [Kernel | Disabled | Stopped] -> %SystemRoot%\system32\drivers\dmboot.sys -> Microsoft Corp., Veritas Software [Ver = 2600.2180.503.0 | Size = 799744 bytes | Modified Date = 8/4/2004 7:00:00 PM | Attr = ] (dmio) dmio [Kernel | Disabled | Stopped] -> %SystemRoot%\system32\drivers\dmio.sys -> Microsoft Corp., Veritas Software [Ver = 2600.2180.503.0 | Size = 153344 bytes | Modified Date = 8/4/2004 7:00:00 PM | Attr = ] (dmload) dmload [Kernel | Disabled | Stopped] -> %SystemRoot%\system32\drivers\dmload.sys -> Microsoft Corp., Veritas Software. [Ver = 2600.0.503.0 | Size = 5888 bytes | Modified Date = 8/4/2004 7:00:00 PM | Attr = ] (dpti2o) dpti2o [Kernel | Disabled | Stopped] -> -> File not found (GEARAspiWDM) GEARAspiWDM [Kernel | On_Demand | Running] -> %SystemRoot%\system32\drivers\GEARAspiWDM.sys -> GEAR Software Inc. [Ver = 2.0.6.1 | Size = 15664 bytes | Modified Date = 9/19/2006 2:44:04 PM | Attr = ] (HDAudBus) Microsoft UAA Bus Driver for High Definition Audio [Kernel | On_Demand | Running] -> %SystemRoot%\system32\drivers\Hdaudbus.sys -> Windows (R) Server 2003 DDK provider [Ver = 5.10.00.5011 built by: WinDDK | Size = 137728 bytes | Modified Date = 8/12/2004 4:45:54 PM | Attr = ] (hpn) hpn [Kernel | Disabled | Stopped] -> -> File not found (HSFHWAZL) HSFHWAZL [Kernel | On_Demand | Running] -> %SystemRoot%\system32\drivers\HSFHWAZL.sys -> Conexant Systems, Inc. [Ver = 7.17.00 | Size = 163328 bytes | Modified Date = 10/5/2004 7:33:06 AM | Attr = ] (HSF_DP) HSF_DP [Kernel | On_Demand | Running] -> %SystemRoot%\system32\drivers\HSF_DP.sys -> Conexant Systems, Inc. [Ver = 7.17.00 | Size = 1036928 bytes | Modified Date = 10/5/2004 7:31:54 AM | Attr = ] (i2omgmt) i2omgmt [Kernel | System | Stopped] -> -> File not found (i2omp) i2omp [Kernel | Disabled | Stopped] -> -> File not found (ialm) ialm [Kernel | On_Demand | Running] -> %SystemRoot%\system32\drivers\ialmnt5.sys -> Intel Corporation [Ver = 6.14.10.4332 | Size = 1050140 bytes | Modified Date = 6/7/2005 7:27:00 PM | Attr = ] (ini910u) ini910u [Kernel | Disabled | Stopped] -> -> File not found (IntcAzAudAddService) Service for Realtek HD Audio (WDM) [Kernel | On_Demand | Running] -> %SystemRoot%\system32\drivers\RtkHDAud.sys -> Realtek Semiconductor Corp. [Ver = 5.10.00.5109 built by: WinDDK | Size = 2510784 bytes | Modified Date = 1/16/2005 6:26:22 PM | Attr = ] (IWCA) Intel Wireless Connection Agent Miniport for Win XP [Kernel | On_Demand | Running] -> %SystemRoot%\system32\drivers\iwca.sys -> Intel Corporation [Ver = 9.00.0.17 built by: WinDDK | Size = 234496 bytes | Modified Date = 8/12/2004 7:44:04 AM | Attr = ] (L8042Kbd) Logitech SetPoint Keyboard Driver [Kernel | On_Demand | Running] -> %SystemRoot%\system32\drivers\L8042Kbd.sys -> Logitech, Inc. [Ver = 2.40.840.00 | Size = 13056 bytes | Modified Date = 5/20/2005 2:00:36 PM | Attr = ] (L8042mou) Logitech SetPoint PS/2 Mouse Filter Driver [Kernel | On_Demand | Stopped] -> %SystemRoot%\system32\drivers\L8042mou.Sys -> Logitech, Inc. [Ver = 2.40.840.00 | Size = 54528 bytes | Modified Date = 5/20/2005 2:00:48 PM | Attr = ] (lbrtfdc) lbrtfdc [Kernel | System | Stopped] -> -> File not found (LMouKE) Logitech SetPoint Mouse Filter Driver [Kernel | On_Demand | Stopped] -> %SystemRoot%\system32\drivers\LMouKE.Sys -> Logitech, Inc. [Ver = 2.40.840.00 | Size = 68352 bytes | Modified Date = 5/20/2005 2:01:26 PM | Attr = ] (mcdbus) Driver for MagicISO SCSI Host Controller [Kernel | On_Demand | Stopped] -> system32\DRIVERS\mcdbus.sys -> File not found (mdmxsdk) mdmxsdk [Kernel | Auto | Running] -> %SystemRoot%\system32\drivers\mdmxsdk.sys -> Conexant [Ver = 1.0.2.006 | Size = 13059 bytes | Modified Date = 3/16/2004 3:04:14 AM | Attr = ] (mraid35x) mraid35x [Kernel | Disabled | Stopped] -> -> File not found (MTsensor) ATK0100 ACPI UTILITY [Kernel | On_Demand | Running] -> %SystemRoot%\system32\drivers\ATKACPI.sys -> [Ver = 1043, 2, 15, 46 | Size = 5632 bytes | Modified Date = 2/17/2005 7:07:48 AM | Attr = ] (PCIDump) PCIDump [Kernel | System | Stopped] -> -> File not found (PDCOMP) PDCOMP [Kernel | On_Demand | Stopped] -> -> File not found (PDFRAME) PDFRAME [Kernel | On_Demand | Stopped] -> -> File not found (PDRELI) PDRELI [Kernel | On_Demand | Stopped] -> -> File not found (PDRFRAME) PDRFRAME [Kernel | On_Demand | Stopped] -> -> File not found (perc2) perc2 [Kernel | Disabled | Stopped] -> -> File not found (perc2hib) perc2hib [Kernel | Disabled | Stopped] -> -> File not found (Ptilink) Direct Parallel Link Driver [Kernel | On_Demand | Running] -> %SystemRoot%\system32\drivers\ptilink.sys -> Parallel Technologies, Inc. [Ver = 1.10 (XPClient.010817-1148) | Size = 17792 bytes | Modified Date = 8/4/2004 7:00:00 PM | Attr = ] (PxHelp20) PxHelp20 [Kernel | Boot | Running] -> %SystemRoot%\system32\drivers\PxHelp20.sys -> Sonic Solutions [Ver = 3.00.56a | Size = 43528 bytes | Modified Date = 3/7/2007 3:51:00 PM | Attr = ] (ql1080) ql1080 [Kernel | Disabled | Stopped] -> -> File not found (Ql10wnt) Ql10wnt [Kernel | Disabled | Stopped] -> -> File not found (ql12160) ql12160 [Kernel | Disabled | Stopped] -> -> File not found (ql1240) ql1240 [Kernel | Disabled | Stopped] -> -> File not found (ql1280) ql1280 [Kernel | Disabled | Stopped] -> -> File not found (rimsptsk) rimsptsk [Kernel | Boot | Running] -> %SystemRoot%\system32\drivers\rimsptsk.sys -> REDC [Ver = 1.00.01.05 | Size = 51328 bytes | Modified Date = 12/5/2004 11:51:00 PM | Attr = ] (risdptsk) risdptsk [Kernel | Boot | Running] -> %SystemRoot%\system32\drivers\risdptsk.sys -> REDC [Ver = 1.0.3.3 | Size = 27136 bytes | Modified Date = 4/18/2005 6:21:00 AM | Attr = ] (rismxdp) Ricoh xD-Picture Card Driver [Kernel | Boot | Running] -> %SystemRoot%\system32\drivers\rixdptsk.sys -> REDC [Ver = 1.00.01.05 | Size = 307456 bytes | Modified Date = 12/5/2004 5:57:00 AM | Attr = ] (RTL8023xp) Realtek RTL8139/810x/8169/8110 all in one NDIS XP Driver [Kernel | On_Demand | Running] -> %SystemRoot%\system32\drivers\Rtlnicxp.sys -> Realtek Semiconductor Corporation [Ver = 5.616.0809.2004 built by: WinDDK | Size = 70144 bytes | Modified Date = 9/23/2004 4:32:00 AM | Attr = ] (s24trans) WLAN Transport [Kernel | Auto | Running] -> %SystemRoot%\system32\drivers\s24trans.sys -> Intel Corporation [Ver = 9, 0, 1, 3 | Size = 11354 bytes | Modified Date = 10/15/2004 10:20:04 AM | Attr = ] (SDTHOOK) SDTHOOK [Kernel | On_Demand | Stopped] -> %SystemRoot%\system32\drivers\SDTHOOK.SYS -> Panda Software [Ver = 1.6.0.0 | Size = 44928 bytes | Modified Date = 6/5/2007 10:56:40 AM | Attr = ] (Secdrv) Secdrv [Kernel | On_Demand | Stopped] -> %SystemRoot%\system32\drivers\secdrv.sys -> Macrovision Corporation, Macrovision Europe Limited, and Macrovision Japan and Asia K.K. [Ver = 4.03.086 | Size = 20480 bytes | Modified Date = 11/13/2007 2:25:53 AM | Attr = ] (Simbad) Simbad [Kernel | Disabled | Stopped] -> -> File not found (Sparrow) Sparrow [Kernel | Disabled | Stopped] -> -> File not found (symc810) symc810 [Kernel | Disabled | Stopped] -> -> File not found (symc8xx) symc8xx [Kernel | Disabled | Stopped] -> -> File not found (sym_hi) sym_hi [Kernel | Disabled | Stopped] -> -> File not found (sym_u3) sym_u3 [Kernel | Disabled | Stopped] -> -> File not found (SynTP) Synaptics TouchPad Driver [Kernel | On_Demand | Running] -> %SystemRoot%\system32\drivers\SynTP.sys -> Synaptics, Inc. [Ver = 7.12.9 19Nov04 | Size = 186240 bytes | Modified Date = 12/21/2004 10:23:00 PM | Attr = ] (toshidpt) TOSHIBA Bluetooth HID port driver [Kernel | On_Demand | Stopped] -> %SystemRoot%\system32\drivers\Toshidpt.sys -> TOSHIBA Corporation. [Ver = Version 1.00.00 | Size = 2851 bytes | Modified Date = 10/17/2002 5:55:48 AM | Attr = ] (TosIde) TosIde [Kernel | Disabled | Stopped] -> -> File not found (tosporte) Bluetooth Port Driver from Toshiba [Kernel | On_Demand | Running] -> %SystemRoot%\system32\drivers\Tosporte.sys -> TOSHIBA Corporation [Ver = 1.02.00 | Size = 51582 bytes | Modified Date = 1/8/2005 5:15:40 PM | Attr = ] (Tosrfbd) Bluetooth RFBUS from TOSHIBA [Kernel | On_Demand | Stopped] -> %SystemRoot%\system32\drivers\TosRfbd.sys -> TOSHIBA CORPORATION [Ver = 01.03.30 | Size = 98304 bytes | Modified Date = 1/17/2005 12:13:28 PM | Attr = ] (Tosrfbnp) Bluetooth RFBNEP from TOSHIBA [Kernel | On_Demand | Stopped] -> %SystemRoot%\system32\drivers\tosrfbnp.sys -> TOSHIBA Corporation [Ver = 1.00 | Size = 36531 bytes | Modified Date = 7/9/2004 9:07:34 AM | Attr = ] (Tosrfcom) Bluetooth RFCOMM from TOSHIBA [Kernel | System | Running] -> %SystemRoot%\system32\drivers\tosrfcom.sys -> TOSHIBA Corporation [Ver = 1.02 | Size = 62799 bytes | Modified Date = 10/5/2004 2:33:02 AM | Attr = ] (Tosrfhid) Bluetooth RFHID from TOSHIBA [Kernel | On_Demand | Stopped] -> %SystemRoot%\system32\drivers\TosRfhid.sys -> TOSHIBA Corporation. [Ver = Version 1.03.13 | Size = 50048 bytes | Modified Date = 11/16/2004 2:51:54 PM | Attr = ] (tosrfnds) Bluetooth Personal Area Network from TOSHIBA [Kernel | On_Demand | Stopped] -> %SystemRoot%\system32\drivers\tosrfnds.sys -> TOSHIBA Corporation. [Ver = Version 1.00.03 | Size = 18612 bytes | Modified Date = 1/7/2005 5:42:42 AM | Attr = ] (TosRfSnd) Bluetooth Audio Device (WDM) from TOSHIBA [Kernel | On_Demand | Stopped] -> %SystemRoot%\system32\drivers\TosRfSnd.sys -> TOSHIBA Corporation [Ver = 1.0.0.0 | Size = 50048 bytes | Modified Date = 12/16/2004 9:30:14 AM | Attr = ] (Tosrfusb) Bluetooth USB Controller [Kernel | On_Demand | Stopped] -> %SystemRoot%\system32\drivers\tosrfusb.sys -> TOSHIBA CORPORATION [Ver = 02.00.11 | Size = 34816 bytes | Modified Date = 12/22/2004 3:38:12 AM | Attr = ] (ultra) ultra [Kernel | Disabled | Stopped] -> -> File not found (ViaIde) ViaIde [Kernel | Disabled | Stopped] -> -> File not found (w29n51) Intel(R) PRO/Wireless 2200BG Network Connection Driver for Windows XP [Kernel | On_Demand | Stopped] -> %SystemRoot%\system32\drivers\w29n51.sys -> Intel® Corporation [Ver = 9001-9 Driver | Size = 3222784 bytes | Modified Date = 10/29/2004 5:48:10 PM | Attr = ] (WDICA) WDICA [Kernel | On_Demand | Stopped] -> -> File not found (winachsf) winachsf [Kernel | On_Demand | Running] -> %SystemRoot%\system32\drivers\HSF_CNXT.sys -> Conexant Systems, Inc. [Ver = 7.17.00 built by: WinDDK | Size = 702592 bytes | Modified Date = 10/5/2004 7:32:30 AM | Attr = ] [Registry - Non-Microsoft Only] < Run [HKEY_LOCAL_MACHINE\] > -> HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run -> !AVG Anti-Spyware -> %ProgramFiles%\Grisoft\AVG Anti-Spyware 7.5\avgas.exe -> GRISOFT s.r.o. [Ver = 7, 5, 1, 43 | Size = 6731312 bytes | Modified Date = 6/11/2007 1:25:42 AM | Attr = ] Acrobat Assistant 8.0 -> %ProgramFiles%\Adobe\Acrobat 8.0\Acrobat\acrotray.exe -> Adobe Systems Inc. [Ver = 8.1.0.2007051000 | Size = 624248 bytes | Modified Date = 5/10/2007 9:46:20 PM | Attr = ] AlcWzrd -> %SystemRoot%\ALCWZRD.EXE -> RealTek Semicoductor Corp. [Ver = 1.1.0.16 | Size = 2750464 bytes | Modified Date = 1/4/2005 11:02:46 PM | Attr = ] ASUS Live Update -> %ProgramFiles%\ASUS\ASUS Live Update\ALU.exe -> [Ver = 1, 0, 0, 1 | Size = 172032 bytes | Modified Date = 9/19/2003 11:54:44 AM | Attr = ] EOUApp -> %ProgramFiles%\Intel\Wireless\Bin\EOUWiz.exe -> Intel Corporation [Ver = 9, 0, 1, 26 | Size = 356352 bytes | Modified Date = 10/15/2004 10:31:32 AM | Attr = ] HControl -> %SystemRoot%\ATK0100\HControl.exe -> [Ver = 1043, 2, 15, 48 | Size = 102400 bytes | Modified Date = 5/11/2005 11:15:14 PM | Attr = ] HotKeysCmds -> %SystemRoot%\system32\hkcmd.exe -> Intel Corporation [Ver = 3.0.0.4332 | Size = 77824 bytes | Modified Date = 6/7/2005 6:59:00 PM | Attr = ] IgfxTray -> %SystemRoot%\system32\igfxtray.exe -> Intel Corporation [Ver = 3.0.0.4332 | Size = 94208 bytes | Modified Date = 6/7/2005 7:02:00 PM | Attr = ] IntelWireless -> %ProgramFiles%\Intel\Wireless\Bin\iFrmewrk.exe -> Intel Corporation [Ver = 9, 0, 1, 19 | Size = 385024 bytes | Modified Date = 10/15/2004 10:27:56 AM | Attr = ] iTunesHelper -> %ProgramFiles%\iTunes\iTunesHelper.exe -> Apple Inc. [Ver = 7.6.0.29 | Size = 267048 bytes | Modified Date = 2/4/2008 2:18:40 PM | Attr = ] NeroFilterCheck -> %SystemRoot%\system32\NeroCheck.exe -> Ahead Software Gmbh [Ver = 1, 0, 0, 2 | Size = 155648 bytes | Modified Date = 7/9/2001 10:50:42 AM | Attr = ] Persistence -> %SystemRoot%\system32\igfxpers.exe -> Intel Corporation [Ver = 3.0.0.4332 | Size = 114688 bytes | Modified Date = 6/7/2005 7:03:00 PM | Attr = ] Power_Gear -> %ProgramFiles%\ASUS\Power4 Gear\BatteryLife.exe -> ASUSTeK Computer Inc. [Ver = 1043, 6, 15, 111 | Size = 81920 bytes | Modified Date = 9/21/2004 3:55:40 PM | Attr = ] QuickTime Task -> %ProgramFiles%\QuickTime\QTTask.exe -> Apple Inc. [Ver = 7.4.1 | Size = 385024 bytes | Modified Date = 1/31/2008 11:13:08 PM | Attr = ] SoundMan -> %SystemRoot%\SoundMan.exe -> Realtek Semiconductor Corp. [Ver = 1, 0, 0, 14 | Size = 77824 bytes | Modified Date = 1/4/2005 11:40:24 PM | Attr = ] SunJavaUpdateSched -> %ProgramFiles%\Java\jre1.6.0_03\bin\jusched.exe -> Sun Microsystems, Inc. [Ver = 6.0.30.5 | Size = 132496 bytes | Modified Date = 9/25/2007 1:11:35 AM | Attr = ] SynTPEnh -> %ProgramFiles%\Synaptics\SynTP\SynTPEnh.exe -> Synaptics, Inc. [Ver = 7.12.9 19Nov04 | Size = 688218 bytes | Modified Date = 12/21/2004 10:23:00 PM | Attr = ] SynTPLpr -> %ProgramFiles%\Synaptics\SynTP\SynTPLpr.exe -> Synaptics, Inc. [Ver = 7.12.9 19Nov04 | Size = 98394 bytes | Modified Date = 12/21/2004 10:23:00 PM | Attr = ] Wireless Console -> %ProgramFiles%\ASUS\Wireless Console\wcourier.exe -> [Ver = 1, 0, 9, 620 | Size = 57344 bytes | Modified Date = 6/20/2005 6:16:36 PM | Attr = ] < OptionalComponents [HKEY_LOCAL_MACHINE\] > -> HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\OptionalComponents\ -> IMAIL-> Installed = 1 -> MAPI-> Installed = 1 -> MSFS-> Installed = 1 -> < All Users Startup Folder > -> C:\Documents and Settings\All Users\Start Menu\Programs\Startup -> %AllUsersProfile%\Start Menu\Programs\Startup\Bluetooth Manager.lnk -> %ProgramFiles%\Toshiba\Bluetooth Toshiba Stack\TosBtMng1.exe -> [Ver = | Size = 45056 bytes | Modified Date = 12/22/2004 12:42:22 PM | Attr = ] %AllUsersProfile%\Start Menu\Programs\Startup\Logitech SetPoint.lnk -> %ProgramFiles%\SetPoint\SetPoint.exe -> Logitech Inc. [Ver = 2.40.849 | Size = 450560 bytes | Modified Date = 5/25/2005 1:40:00 AM | Attr = ] < Boo Boo Startup Folder > -> C:\Documents and Settings\Boo Boo\Start Menu\Programs\Startup -> %UserProfile%\Start Menu\Programs\Startup\Adobe Gamma.lnk -> %CommonProgramFiles%\Adobe\Calibration\Adobe Gamma Loader.exe -> Adobe Systems, Inc. [Ver = 1, 0, 0, 1 | Size = 113664 bytes | Modified Date = 3/16/2005 6:16:50 PM | Attr = ] < ShellExecuteHooks [HKEY_LOCAL_MACHINE] > -> HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks -> {57B86673-276A-48B2-BAE7-C6DBB3020EB8} [HKEY_LOCAL_MACHINE] -> %ProgramFiles%\Grisoft\AVG Anti-Spyware 7.5\shellexecutehook.dll [AVG Anti-Spyware 7.5] -> GRISOFT s.r.o. [Ver = 7, 5, 1, 36 | Size = 79408 bytes | Modified Date = 5/30/2007 4:29:58 AM | Attr = ] < SecurityProviders [HKEY_LOCAL_MACHINE] > -> HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SecurityProviders\\SecurityProviders -> < Winlogon settings [HKEY_LOCAL_MACHINE] > -> HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon -> < Winlogon settings [HKEY_CURRENT_USER] > -> HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon -> < Winlogon\Notify settings [HKEY_LOCAL_MACHINE] > -> HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\ -> ftprwqee -> ftprwqee.dll -> File not found igfxcui -> %SystemRoot%\system32\igfxdev.dll -> Intel Corporation [Ver = 3.0.0.4332 | Size = 131072 bytes | Modified Date = 6/7/2005 6:58:00 PM | Attr = ] IntelWireless -> %ProgramFiles%\Intel\Wireless\Bin\LgNotify.dll -> Intel Corporation [Ver = 9, 0, 1, 0 | Size = 110592 bytes | Modified Date = 10/15/2004 10:27:42 AM | Attr = ] < CurrentVersion Policy Settings [HKEY_LOCAL_MACHINE] > -> HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\ -> HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\ -> -> HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\ActiveDesktop\ -> -> HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\ -> -> HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\\NoDriveAutoRun -> 67108863 -> HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\\NoDriveTypeAutoRun -> 255 -> HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\Run\ -> -> HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\NonEnum\ -> -> HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\NonEnum\\{BDEADF00-C265-11D0-BCED-00A0C90AB50F} -> 1 -> HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\NonEnum\\{6DFD7C5C-2451-11d3-A299-00C04F8EF6AF} -> 1073741857 -> HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\NonEnum\\{0DF44EAA-FF21-4412-828E-260A8728E7F1} -> 32 -> HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\system\ -> -> HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\system\\dontdisplaylastusername -> 0 -> HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\system\\legalnoticecaption -> -> HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\system\\legalnoticetext -> -> HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\system\\shutdownwithoutlogon -> 1 -> HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\system\\undockwithoutlogon -> 1 -> HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Uninstall\ -> -> HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\WindowsUpdate\ -> -> < CurrentVersion Policy Settings [HKEY_CURRENT_USER] > -> HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\ -> HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\ -> -> HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\ActiveDesktop\ -> -> HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Associations\ -> -> HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\ -> -> HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\\NoDriveTypeAutoRun -> (binary data) -> HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\Run\ -> -> HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\system\ -> -> HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\system\\DisableRegistryTools -> 0 -> HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\WindowsUpdate\ -> -> < HOSTS File > (27 bytes) -> C:\WINDOWS\System32\drivers\etc\Hosts -> < Internet Explorer Settings [HKEY_LOCAL_MACHINE\] > -> -> HKEY_LOCAL_MACHINE\: Main\\Default_Page_URL -> http://www.asus.com -> HKEY_LOCAL_MACHINE\: Main\\Default_Search_URL -> http://www.microsoft.com/isapi/redir.dll?prd=ie&ar=iesearch -> HKEY_LOCAL_MACHINE\: Main\\Local Page -> %SystemRoot%\system32\blank.htm -> HKEY_LOCAL_MACHINE\: Main\\Search Page -> http://www.microsoft.com/isapi/redir.dll?prd=ie&ar=iesearch -> HKEY_LOCAL_MACHINE\: Main\\Start Page -> http://www.microsoft.com/isapi/redir.dll?prd={SUB_PRD}&clcid={SUB_CLSID}&pver={SUB_PVER}&ar=home -> HKEY_LOCAL_MACHINE\: Search\\CustomizeSearch -> http://ie.search.msn.com/{SUB_RFC1766}/srchasst/srchcust.htm -> HKEY_LOCAL_MACHINE\: Search\\SearchAssistant -> http://ie.search.msn.com/{SUB_RFC1766}/srchasst/srchasst.htm -> < Internet Explorer Settings [HKEY_CURRENT_USER\] > -> -> HKEY_CURRENT_USER\: Main\\Local Page -> C:\WINDOWS\system32\blank.htm -> HKEY_CURRENT_USER\: Main\\Search Page -> http://www.microsoft.com/isapi/redir.dll?prd=ie&ar=iesearch -> HKEY_CURRENT_USER\: Main\\Start Page -> http://www.canada.com/vancouversun/index.html -> HKEY_CURRENT_USER\: ProxyEnable -> 0 -> < Trusted Sites Domains [HKEY_LOCAL_MACHINE\] > -> HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Domains\ -> HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Domains\ -> [Key] 1 domain(s) found. -> 1 domain(s) and sub-domain(s) not assigned to a zone. < Trusted Sites Ranges [HKEY_LOCAL_MACHINE\] > -> HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Ranges\ -> HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Ranges\ -> [Key] 0 range(s) found. -> < Trusted Sites Domains [HKEY_CURRENT_USER\] > -> HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Domains\ -> HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Domains\ -> [Key] 0 domain(s) found. -> < Trusted Sites Ranges [HKEY_CURRENT_USER\] > -> HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Ranges\ -> HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Ranges\ -> [Key] 0 range(s) found. -> < BHO's [HKEY_LOCAL_MACHINE] > -> HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\ -> {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} [HKEY_LOCAL_MACHINE] -> %CommonProgramFiles%\Adobe\Acrobat\ActiveX\AcroIEHelper.dll [Adobe PDF Reader Link Helper] -> Adobe Systems Incorporated [Ver = 8.0.0.2006102200 | Size = 62080 bytes | Modified Date = 10/22/2006 10:08:42 PM | Attr = ] {62B66D84-19D1-400F-A249-8BA3E5A19A8A} [HKEY_LOCAL_MACHINE] -> %ProgramFiles%\MSN\fehy89104.dll [] -> [Ver = | Size = 217088 bytes | Modified Date = 2/7/2008 5:07:06 PM | Attr = ] {68F9551E-0411-48E4-9AAF-4BC42A6A46BE} [HKEY_LOCAL_MACHINE] -> %ProgramFiles%\Canon\Easy-WebPrint\EWPBrowseLoader.dll [EWPBrowseObject Class] -> [Ver = 2, 6, 4, 1 | Size = 34304 bytes | Modified Date = 6/9/2006 1:37:54 PM | Attr = ] {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} [HKEY_LOCAL_MACHINE] -> %ProgramFiles%\Java\jre1.6.0_03\bin\ssv.dll [SSVHelper Class] -> Sun Microsystems, Inc. [Ver = 6.0.30.5 | Size = 501136 bytes | Modified Date = 9/25/2007 1:11:33 AM | Attr = ] {A95B2816-1D7E-4561-A202-68C0DE02353A} [HKEY_LOCAL_MACHINE] -> %SystemRoot%\system32\ftprwqee.dll [Reg Error: Value does not exist or could not be read.] -> File not found {AE7CD045-E861-484f-8273-0445EE161910} [HKEY_LOCAL_MACHINE] -> %ProgramFiles%\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll [Adobe PDF Conversion Toolbar Helper] -> Adobe Systems Incorporated [Ver = 8.1.0.0 | Size = 321120 bytes | Modified Date = 5/10/2007 9:47:03 PM | Attr = ] {DBBC93AD-82B2-4EDC-33BD-39BD7B698D64} [HKEY_LOCAL_MACHINE] -> %ProgramFiles%\Windows Media Player\lavu.dll [Reg Error: Value does not exist or could not be read.] -> File not found < Internet Explorer Bars [HKEY_LOCAL_MACHINE\] > -> HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Explorer Bars\ -> {182EC0BE-5110-49C8-A062-BEB1D02A220B} [HKEY_LOCAL_MACHINE] -> %ProgramFiles%\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll [Adobe PDF] -> Adobe Systems Incorporated [Ver = 8.1.0.0 | Size = 321120 bytes | Modified Date = 5/10/2007 9:47:03 PM | Attr = ] < Internet Explorer ToolBars [HKEY_LOCAL_MACHINE] > -> HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\ToolBar -> {327C2873-E90D-4c37-AA9D-10AC9BABA46C} [HKEY_LOCAL_MACHINE] -> %ProgramFiles%\Canon\Easy-WebPrint\Toolband.dll [Easy-WebPrint] -> [Ver = 2, 6, 4, 1 | Size = 552960 bytes | Modified Date = 6/9/2006 1:39:38 PM | Attr = ] {47833539-D0C5-4125-9FA8-0819E2EAAC93} [HKEY_LOCAL_MACHINE] -> %ProgramFiles%\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll [Adobe PDF] -> Adobe Systems Incorporated [Ver = 8.1.0.0 | Size = 321120 bytes | Modified Date = 5/10/2007 9:47:03 PM | Attr = ] < Internet Explorer ToolBars [HKEY_CURRENT_USER\] > -> HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Toolbar\ -> ShellBrowser\\{42CDD1BF-3FFB-4238-8AD1-7859DF00B1D6} [HKEY_LOCAL_MACHINE] -> Reg Error: Key does not exist or could not be opened. [Reg Error: Key does not exist or could not be opened.] -> File not found WebBrowser\\{0B53EAC3-8D69-4B9E-9B19-A37C9A5676A7} [HKEY_LOCAL_MACHINE] -> Reg Error: Key does not exist or could not be opened. [Reg Error: Key does not exist or could not be opened.] -> File not found WebBrowser\\{47833539-D0C5-4125-9FA8-0819E2EAAC93} [HKEY_LOCAL_MACHINE] -> %ProgramFiles%\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll [Adobe PDF] -> Adobe Systems Incorporated [Ver = 8.1.0.0 | Size = 321120 bytes | Modified Date = 5/10/2007 9:47:03 PM | Attr = ] WebBrowser\\{EF99BD32-C1FB-11D2-892F-0090271D4F88} [HKEY_LOCAL_MACHINE] -> Reg Error: Key does not exist or could not be opened. [Reg Error: Key does not exist or could not be opened.] -> File not found < Internet Explorer Extensions [HKEY_LOCAL_MACHINE] > -> HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Extensions\ -> {08B0E5C0-4FCB-11CF-AAA5-00401C608501}:{CAFEEFAC-0016-0000-0003-ABCDEFFEDCBC} [HKEY_LOCAL_MACHINE] -> %ProgramFiles%\Java\jre1.6.0_03\bin\npjpi160_03.dll [Sun Java Console] -> Sun Microsystems, Inc. [Ver = 6.0.30.5 | Size = 132496 bytes | Modified Date = 9/25/2007 1:11:34 AM | Attr = ] {08B0E5C0-4FCB-11CF-AAA5-00401C608501}:{CAFEEFAC-0016-0000-0003-ABCDEFFEDCBC} [HKEY_CURRENT_USER] -> %ProgramFiles%\Java\jre1.6.0_03\bin\ssv.dll [Sun Java Console] -> Sun Microsystems, Inc. [Ver = 6.0.30.5 | Size = 501136 bytes | Modified Date = 9/25/2007 1:11:33 AM | Attr = ] < Internet Explorer Extensions [HKEY_CURRENT_USER\] > -> HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Extensions\ -> CmdMapping\\{08B0E5C0-4FCB-11CF-AAA5-00401C608501} [HKEY_LOCAL_MACHINE] -> %ProgramFiles%\Java\jre1.6.0_03\bin\npjpi160_03.dll [Sun Java Console] -> Sun Microsystems, Inc. [Ver = 6.0.30.5 | Size = 132496 bytes | Modified Date = 9/25/2007 1:11:34 AM | Attr = ] CmdMapping\\{5BAB4B5B-68BC-4B02-94D6-2FC0DE4A7897} [HKEY_LOCAL_MACHINE] -> [Reg Error: Key does not exist or could not be opened.] -> File not found < Internet Explorer Menu Extensions [HKEY_CURRENT_USER\] > -> HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\MenuExt\ -> Append to existing PDF -> %ProgramFiles%\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll -> Adobe Systems Incorporated [Ver = 8.1.0.0 | Size = 321120 bytes | Modified Date = 5/10/2007 9:47:03 PM | Attr = ] Convert link target to Adobe PDF -> %ProgramFiles%\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll -> Adobe Systems Incorporated [Ver = 8.1.0.0 | Size = 321120 bytes | Modified Date = 5/10/2007 9:47:03 PM | Attr = ] Convert link target to existing PDF -> %ProgramFiles%\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll -> Adobe Systems Incorporated [Ver = 8.1.0.0 | Size = 321120 bytes | Modified Date = 5/10/2007 9:47:03 PM | Attr = ] Convert selected links to Adobe PDF -> %ProgramFiles%\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll -> Adobe Systems Incorporated [Ver = 8.1.0.0 | Size = 321120 bytes | Modified Date = 5/10/2007 9:47:03 PM | Attr = ] Convert selected links to existing PDF -> %ProgramFiles%\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll -> Adobe Systems Incorporated [Ver = 8.1.0.0 | Size = 321120 bytes | Modified Date = 5/10/2007 9:47:03 PM | Attr = ] Convert selection to Adobe PDF -> %ProgramFiles%\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll -> Adobe Systems Incorporated [Ver = 8.1.0.0 | Size = 321120 bytes | Modified Date = 5/10/2007 9:47:03 PM | Attr = ] Convert selection to existing PDF -> %ProgramFiles%\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll -> Adobe Systems Incorporated [Ver = 8.1.0.0 | Size = 321120 bytes | Modified Date = 5/10/2007 9:47:03 PM | Attr = ] Convert to Adobe PDF -> %ProgramFiles%\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll -> Adobe Systems Incorporated [Ver = 8.1.0.0 | Size = 321120 bytes | Modified Date = 5/10/2007 9:47:03 PM | Attr = ] Easy-WebPrint Add To Print List -> %ProgramFiles%\Canon\Easy-WebPrint\Toolband.dll -> [Ver = 2, 6, 4, 1 | Size = 552960 bytes | Modified Date = 6/9/2006 1:39:38 PM | Attr = ] Easy-WebPrint High Speed Print -> %ProgramFiles%\Canon\Easy-WebPrint\Toolband.dll -> [Ver = 2, 6, 4, 1 | Size = 552960 bytes | Modified Date = 6/9/2006 1:39:38 PM | Attr = ] Easy-WebPrint Preview -> %ProgramFiles%\Canon\Easy-WebPrint\Toolband.dll -> [Ver = 2, 6, 4, 1 | Size = 552960 bytes | Modified Date = 6/9/2006 1:39:38 PM | Attr = ] Easy-WebPrint Print -> %ProgramFiles%\Canon\Easy-WebPrint\Toolband.dll -> [Ver = 2, 6, 4, 1 | Size = 552960 bytes | Modified Date = 6/9/2006 1:39:38 PM | Attr = ] < Internet Explorer Plugins [HKEY_LOCAL_MACHINE] > -> HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Plugins\ -> PluginsPageFriendlyName -> Microsoft ActiveX Gallery -> PluginsPage -> http://activex.microsoft.com/controls/find.asp?ext=%s&mime=%s -> < User Agent Post Platform [HKEY_LOCAL_MACHINE] > -> HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\User Agent\Post Platform -> SV1 -> -> < DNS Name Servers [HKEY_LOCAL_MACHINE] > -> HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Tcpip\Parameters\Adapters\ -> {0C3EBDCA-47CD-48A1-9435-3EF5548B9C8F} -> (1394 Net Adapter) -> {5D4B40EC-48BD-4292-A67D-06EE4F33BA74} -> (Realtek RTL8139/810x Family Fast Ethernet NIC) -> {A2A73A42-CABB-48C5-9B7B-D4956B07D1E0} -> () -> {DE0F4BBA-1389-4B51-A343-069663ADA761} -> (Intel(R) PRO/Wireless 2200BG Network Connection) -> {F9BD003B-BE80-4EDB-AD52-B35AA5A525E9} -> () -> < Protocol Handlers [HKEY_LOCAL_MACHINE] > -> HKEY_LOCAL_MACHINE\SOFTWARE\Classes\PROTOCOLS\Handler\ -> ipp: [HKEY_LOCAL_MACHINE] -> Reg Error: Key does not exist or could not be opened.[Reg Error: Value does not exist or could not be read.] -> File not found msdaipp: [HKEY_LOCAL_MACHINE] -> Reg Error: Key does not exist or could not be opened.[Reg Error: Value does not exist or could not be read.] -> File not found < Downloaded Program Files > -> HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Code Store Database\Distribution Units\ -> {6414512B-B978-451D-A0D8-FCFDF33E833C}[HKEY_LOCAL_MACHINE] -> http://www.update.microsoft.com/microsoftupdate/v6/V5Controls/en/x86/client/wuweb_site.cab?1203406209234[WUWebControl Class] -> {6E32070A-766D-4EE6-879C-DC1FA91D2FC3}[HKEY_LOCAL_MACHINE] -> http://www.update.microsoft.com/microsoftupdate/v6/V5Controls/en/x86/client/muweb_site.cab?1203406197046[MUWebControl Class] -> {8AD9C840-044E-11D1-B3E9-00805F499D93}[HKEY_LOCAL_MACHINE] -> http://java.sun.com/update/1.6.0/jinstall-1_6_0_03-windows-i586.cab[Java Plug-in 1.6.0_03] -> {9A9307A0-7DA4-4DAF-B042-5009F29E09E1}[HKEY_LOCAL_MACHINE] -> http://acs.pandasoftware.com/activescan/as5free/asinst.cab[ActiveScan Installer Class] -> {CAFEEFAC-0016-0000-0003-ABCDEFFEDCBA}[HKEY_LOCAL_MACHINE] -> http://java.sun.com/update/1.6.0/jinstall-1_6_0_03-windows-i586.cab[Java Plug-in 1.6.0_03] -> {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA}[HKEY_LOCAL_MACHINE] -> http://java.sun.com/update/1.6.0/jinstall-1_6_0_03-windows-i586.cab[Java Plug-in 1.6.0_03] -> {D27CDB6E-AE6D-11CF-96B8-444553540000}[HKEY_LOCAL_MACHINE] -> http://fpdownload.macromedia.com/pub/shockwave/cabs/flash/swflash.cab[Shockwave Flash Object] -> [Registry - Additional Scans - Non-Microsoft Only] < BotCheck > -> -> HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Ole\ -> -> HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Ole\\DefaultLaunchPermission -> (binary data) -> HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Ole\\MachineLaunchRestriction -> (binary data) -> HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Ole\\MachineAccessRestriction -> (binary data) -> HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Ole\\EnableDCOM -> Y -> HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Ole\AppCompat\ -> -> HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Ole\AppCompat\ActivationSecurityCheckExemptionList\ -> -> HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Ole\AppCompat\ActivationSecurityCheckExemptionList\\{A50398B8-9075-4FBF-A7A1-456BF21937AD} -> 1 -> HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Ole\AppCompat\ActivationSecurityCheckExemptionList\\{AD65A69D-3831-40D7-9629-9B0B50A93843} -> 1 -> HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Ole\AppCompat\ActivationSecurityCheckExemptionList\\{0040D221-54A1-11D1-9DE0-006097042D69} -> 1 -> HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Ole\AppCompat\ActivationSecurityCheckExemptionList\\{2A6D72F1-6E7E-4702-B99C-E40D3DED33C3} -> 1 -> HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\ -> -> HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\\FirstRunDisabled -> 1 -> HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\\AntiVirusDisableNotify -> 0 -> HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\\FirewallDisableNotify -> 0 -> HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\\UpdatesDisableNotify -> 0 -> HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\\AntiVirusOverride -> 1 -> HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\\FirewallOverride -> 0 -> HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\ -> -> HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\AhnlabAntiVirus\ -> -> HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\ComputerAssociatesAntiVirus\ -> -> HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\KasperskyAntiVirus\ -> -> HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\McAfeeAntiVirus\ -> -> HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\McAfeeFirewall\ -> -> HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\PandaAntiVirus\ -> -> HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\PandaFirewall\ -> -> HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\SophosAntiVirus\ -> -> HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\SymantecAntiVirus\ -> -> HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\SymantecFirewall\ -> -> HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\TinyFirewall\ -> -> HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\TrendAntiVirus\ -> -> HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\TrendFirewall\ -> -> HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\ZoneLabsFirewall\ -> -> Reg Error: Key HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows\WindowsUpdate\ not found. -> -> HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\WindowsFirewall\DomainProfile\ -> -> HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Lsa\ -> -> *Authentication Packages* -> HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Lsa\\Authentication Packages -> msv1_0 -> %SystemRoot%\system32\msv1_0.dll -> Microsoft Corporation [Ver = 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158) | Size = 129536 bytes | Modified Date = 8/4/2004 7:00:00 PM | Attr = ] *MultiFile Done* -> -> HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Lsa\\Bounds -> (binary data) -> *Security Packages* -> HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Lsa\\Security Packages -> kerberos -> %SystemRoot%\system32\kerberos.dll -> Microsoft Corporation [Ver = 5.1.2600.2698 (xpsp_sp2_gdr.050614-1522) | Size = 295936 bytes | Modified Date = 6/15/2005 9:49:30 AM | Attr = ] msv1_0 -> %SystemRoot%\system32\msv1_0.dll -> Microsoft Corporation [Ver = 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158) | Size = 129536 bytes | Modified Date = 8/4/2004 7:00:00 PM | Attr = ] schannel -> %SystemRoot%\system32\schannel.dll -> Microsoft Corporation [Ver = 5.1.2600.3126 (xpsp_sp2_gdr.070425-0226) | Size = 144896 bytes | Modified Date = 4/25/2007 6:21:15 AM | Attr = ] wdigest -> %SystemRoot%\system32\wdigest.dll -> Microsoft Corporation [Ver = 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158) | Size = 49152 bytes | Modified Date = 8/4/2004 7:00:00 PM | Attr = ] *MultiFile Done* -> -> HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Lsa\\ImpersonatePrivilegeUpgradeToolHasRun -> 1 -> HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Lsa\\LsaPid -> 628 -> HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Lsa\\SecureBoot -> 1 -> HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Lsa\\auditbaseobjects -> 0 -> HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Lsa\\crashonauditfail -> 0 -> HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Lsa\\disabledomaincreds -> 0 -> HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Lsa\\everyoneincludesanonymous -> 0 -> HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Lsa\\fipsalgorithmpolicy -> 0 -> HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Lsa\\forceguest -> 1 -> HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Lsa\\fullprivilegeauditing -> (binary data) -> HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Lsa\\limitblankpassworduse -> 1 -> HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Lsa\\lmcompatibilitylevel -> 0 -> HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Lsa\\nodefaultadminowner -> 1 -> HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Lsa\\nolmhash -> 0 -> HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Lsa\\restrictanonymous -> 0 -> HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Lsa\\restrictanonymoussam -> 1 -> *Notification Packages* -> HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Lsa\\Notification Packages -> scecli -> %SystemRoot%\system32\scecli.dll -> Microsoft Corporation [Ver = 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158) | Size = 180224 bytes | Modified Date = 8/4/2004 7:00:00 PM | Attr = ] *MultiFile Done* -> -> HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Lsa\\enabledcom -> y -> HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Lsa\AccessProviders\ -> -> *ProviderOrder* -> HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Lsa\AccessProviders\\ProviderOrder -> Windows NT Access Provider -> -> File not found *MultiFile Done* -> -> HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Lsa\AccessProviders\Windows NT Access Provider\ -> -> HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Lsa\AccessProviders\Windows NT Access Provider\\ProviderPath -> C:\WINDOWS\system32\ntmarta.dll [%SystemRoot%\system32\ntmarta.dll] -> Microsoft Corporation [Ver = 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158) | Size = 118784 bytes | Modified Date = 8/4/2004 7:00:00 PM | Attr = ] HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Lsa\Audit\ -> -> HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Lsa\Audit\PerUserAuditing\ -> -> HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Lsa\Audit\PerUserAuditing\System\ -> -> HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Lsa\Data\ -> -> HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Lsa\Data\\Pattern -> (binary data) -> HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Lsa\GBG\ -> -> HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Lsa\GBG\\GrafBlumGroup -> (binary data) -> HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Lsa\JD\ -> -> HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Lsa\JD\\Lookup -> (binary data) -> HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Lsa\Kerberos\ -> -> HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Lsa\Kerberos\Domains\ -> -> HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Lsa\Kerberos\SidCache\ -> -> HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Lsa\msv1_0\ -> -> HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Lsa\msv1_0\\ntlmminclientsec -> 0 -> HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Lsa\msv1_0\\ntlmminserversec -> 0 -> HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Lsa\Skew1\ -> -> HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Lsa\Skew1\\SkewMatrix -> (binary data) -> HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Lsa\SSO\ -> -> HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Lsa\SSO\Passport1.4\ -> -> HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Lsa\SSO\Passport1.4\\SSOURL -> http://www.passport.com -> HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Lsa\SspiCache\ -> -> HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Lsa\SspiCache\\Time -> (binary data) -> HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Lsa\SspiCache\digest.dll\ -> -> HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Lsa\SspiCache\digest.dll\\Name -> Digest -> HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Lsa\SspiCache\digest.dll\\Comment -> Digest SSPI Authentication Package -> HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Lsa\SspiCache\digest.dll\\Capabilities -> 16464 -> HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Lsa\SspiCache\digest.dll\\RpcId -> 65535 -> HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Lsa\SspiCache\digest.dll\\Version -> 1 -> HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Lsa\SspiCache\digest.dll\\TokenSize -> 65535 -> HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Lsa\SspiCache\digest.dll\\Time -> (binary data) -> HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Lsa\SspiCache\digest.dll\\Type -> 49 -> HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Lsa\SspiCache\msapsspc.dll\ -> -> HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Lsa\SspiCache\msapsspc.dll\\Name -> DPA -> HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Lsa\SspiCache\msapsspc.dll\\Comment -> DPA Security Package -> HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Lsa\SspiCache\msapsspc.dll\\Capabilities -> 55 -> HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Lsa\SspiCache\msapsspc.dll\\RpcId -> 17 -> HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Lsa\SspiCache\msapsspc.dll\\Version -> 1 -> HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Lsa\SspiCache\msapsspc.dll\\TokenSize -> 768 -> HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Lsa\SspiCache\msapsspc.dll\\Time -> (binary data) -> HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Lsa\SspiCache\msapsspc.dll\\Type -> 49 -> HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Lsa\SspiCache\msnsspc.dll\ -> -> HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Lsa\SspiCache\msnsspc.dll\\Name -> MSN -> HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Lsa\SspiCache\msnsspc.dll\\Comment -> MSN Security Package -> HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Lsa\SspiCache\msnsspc.dll\\Capabilities -> 55 -> HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Lsa\SspiCache\msnsspc.dll\\RpcId -> 18 -> HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Lsa\SspiCache\msnsspc.dll\\Version -> 1 -> HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Lsa\SspiCache\msnsspc.dll\\TokenSize -> 768 -> HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Lsa\SspiCache\msnsspc.dll\\Time -> (binary data) -> HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Lsa\SspiCache\msnsspc.dll\\Type -> 49 -> HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\ -> -> HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\\DependOnGroup -> -> HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\\DependOnService -> Netman;WinMgmt; -> HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\\Description -> Provides network address translation, addressing, name resolution and/or intrusion prevention services for a home or small office network. -> HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\\DisplayName -> Windows Firewall/Internet Connection Sharing (ICS) -> HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\\ErrorControl -> 1 -> HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\\ImagePath -> C:\WINDOWS\system32\svchost.exe [%SystemRoot%\System32\svchost.exe -k netsvcs] -> Microsoft Corporation [Ver = 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158) | Size = 14336 bytes | Modified Date = 8/4/2004 7:00:00 PM | Attr = ] HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\\ObjectName -> LocalSystem -> HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\\Start -> 2 -> HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\\Type -> 32 -> HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Epoch\ -> -> HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Epoch\\Epoch -> 11510 -> HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\ -> -> HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\\ServiceDll -> C:\WINDOWS\system32\ipnathlp.dll [%SystemRoot%\System32\ipnathlp.dll] -> Microsoft Corporation [Ver = 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158) | Size = 331264 bytes | Modified Date = 8/4/2004 7:00:00 PM | Attr = ] HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\ -> -> HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile\ -> -> HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile\AuthorizedApplications\ -> -> HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile\AuthorizedApplications\List\ -> -> HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\ -> -> HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\AuthorizedApplications\ -> -> HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\AuthorizedApplications\List\ -> -> HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\AuthorizedApplications\List\\C:\Program Files\MSN Messenger\msnmsgr.exe -> C:\Program Files\MSN Messenger\msnmsgr.exe [C:\Program Files\MSN Messenger\msnmsgr.exe:*:Enabled:Messenger] -> Microsoft Corporation [Ver = 8.1.0178.00 | Size = 5674352 bytes | Modified Date = 1/19/2007 11:54:56 AM | Attr = ] HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\GloballyOpenPorts\ -> -> HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\GloballyOpenPorts\List\ -> -> HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\GloballyOpenPorts\List\\139:TCP -> 139:TCP:LocalSubNet:Enabled:@xpsp2res.dll [139:TCP:LocalSubNet:Enabled:@xpsp2res.dll,-22004] -> File not found HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\GloballyOpenPorts\List\\445:TCP -> 445:TCP:LocalSubNet:Enabled:@xpsp2res.dll [445:TCP:LocalSubNet:Enabled:@xpsp2res.dll,-22005] -> File not found HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\GloballyOpenPorts\List\\137:UDP -> 137:UDP:LocalSubNet:Enabled:@xpsp2res.dll [137:UDP:LocalSubNet:Enabled:@xpsp2res.dll,-22001] -> File not found HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\GloballyOpenPorts\List\\138:UDP -> 138:UDP:LocalSubNet:Enabled:@xpsp2res.dll [138:UDP:LocalSubNet:Enabled:@xpsp2res.dll,-22002] -> File not found HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\GloballyOpenPorts\List\\1900:UDP -> 1900:UDP:LocalSubNet:Enabled:@xpsp2res.dll [1900:UDP:LocalSubNet:Enabled:@xpsp2res.dll,-22007] -> File not found HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\GloballyOpenPorts\List\\2869:TCP -> 2869:TCP:LocalSubNet:Enabled:@xpsp2res.dll [2869:TCP:LocalSubNet:Enabled:@xpsp2res.dll,-22008] -> File not found HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Setup\ -> -> HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Setup\\ServiceUpgrade -> 1 -> HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Setup\InterfacesUnfirewalledAtUpdate\ -> -> HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Setup\InterfacesUnfirewalledAtUpdate\\All -> 1 -> HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Enum\ -> -> HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Enum\\0 -> Root\LEGACY_SHAREDACCESS\0000 -> HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Enum\\Count -> 1 -> HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Enum\\NextInstance -> 1 -> HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\wuauserv\ -> -> HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\wuauserv\\Type -> 32 -> HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\wuauserv\\Start -> 2 -> HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\wuauserv\\ErrorControl -> 1 -> HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\wuauserv\\ImagePath -> C:\WINDOWS\system32\svchost.exe [%systemroot%\system32\svchost.exe -k netsvcs] -> Microsoft Corporation [Ver = 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158) | Size = 14336 bytes | Modified Date = 8/4/2004 7:00:00 PM | Attr = ] HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\wuauserv\\DisplayName -> Automatic Updates -> HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\wuauserv\\ObjectName -> LocalSystem -> HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\wuauserv\\Description -> Enables the download and installation of Windows updates. If this service is disabled, this computer will not be able to use the Automatic Updates feature or the Windows Update Web site. -> HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\wuauserv\Parameters\ -> -> HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\wuauserv\Parameters\\ServiceDll -> C:\WINDOWS\system32\wuauserv.dll [C:\WINDOWS\system32\wuauserv.dll] -> Microsoft Corporation [Ver = 5.4.3790.2180 (xpsp_sp2_rtm.040803-2158) | Size = 6656 bytes | Modified Date = 8/4/2004 7:00:00 PM | Attr = ] HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\wuauserv\Security\ -> -> HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\wuauserv\Security\\Security -> (binary data) -> HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\wuauserv\Enum\ -> -> HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\wuauserv\Enum\\0 -> Root\LEGACY_WUAUSERV\0000 -> HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\wuauserv\Enum\\Count -> 1 -> HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\wuauserv\Enum\\NextInstance -> 1 -> Reg Error: Key HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\RemoteRegistry\ not found. -> -> Reg Error: Key HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\TlntSvr\ not found. -> -> HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Hardware Profiles\Current\Software\Microsoft\windows\CurrentVersion\Internet Settings\ -> -> HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Hardware Profiles\Current\Software\Microsoft\windows\CurrentVersion\Internet Settings\\ProxyEnable -> 0 -> [Files/Folders - Created Within 30 days] Boot.bak -> %SystemDrive%\Boot.bak -> [Ver = | Size = 211 bytes | Modified Date = 9/1/2007 11:45:38 AM | Attr = ] cmdcons -> %SystemDrive%\cmdcons -> [Folder | Created Date = 2/18/2008 3:39:19 PM | Attr = ] 1000 C:\*.tmp files -> C:\*.tmp -> cmldr -> %SystemDrive%\cmldr -> [Ver = | Size = 260272 bytes | Modified Date = 8/3/2004 11:00:00 PM | Attr = ] hiberfil.sys -> %SystemDrive%\hiberfil.sys -> [Ver = | Size = 519426048 bytes | Modified Date = 2/20/2008 6:22:09 PM | Attr = HS] QooBox -> %SystemDrive%\QooBox -> [Folder | Created Date = 2/18/2008 3:30:53 PM | Attr = ] Temp -> %SystemDrive%\Temp -> [Folder | Created Date = 2/17/2008 9:32:54 PM | Attr = ] ASPI32.SYS -> %SystemRoot%\System32\drivers\ASPI32.SYS -> Adaptec [Ver = 4.60 (1021) | Size = 25244 bytes | Modified Date = 9/10/1999 12:06:00 PM | Attr = ] AvgAsCln.sys -> %SystemRoot%\System32\drivers\AvgAsCln.sys -> GRISOFT, s.r.o. [Ver = 1.0.0.14 | Size = 10872 bytes | Modified Date = 5/30/2007 4:10:42 AM | Attr = ] flfjomesxjve.sys -> %SystemRoot%\System32\drivers\flfjomesxjve.sys -> Panda Software International [Ver = 1, 0, 0, 5 | Size = 8576 bytes | Modified Date = 6/8/2007 9:44:36 AM | Attr = ] SDTHOOK.SYS -> %SystemRoot%\System32\drivers\SDTHOOK.SYS -> Panda Software [Ver = 1.6.0.0 | Size = 44928 bytes | Modified Date = 6/5/2007 10:56:40 AM | Attr = ] ActiveScan -> %SystemRoot%\System32\ActiveScan -> [Folder | Created Date = 2/18/2008 7:37:43 PM | Attr = ] 4 C:\WINDOWS\System32\*.tmp files -> C:\WINDOWS\System32\*.tmp -> asuninst.exe -> %SystemRoot%\System32\asuninst.exe -> Panda Software [Ver = 1, 0, 0, 2 | Size = 73728 bytes | Modified Date = 8/2/2006 12:39:06 PM | Attr = ] bwmedia.dll -> %SystemRoot%\System32\bwmedia.dll -> [Ver = 1.00 | Size = 150016 bytes | Modified Date = 2/7/2008 10:48:04 PM | Attr = ] bwmedia1.dll -> %SystemRoot%\System32\bwmedia1.dll -> BinaryWork Corp. [Ver = 1.0.0.0 | Size = 295424 bytes | Modified Date = 2/7/2008 10:48:04 PM | Attr = ] er2 -> %SystemRoot%\System32\er2 -> [Folder | Created Date = 2/17/2008 9:33:08 PM | Attr = ] fdsv.exe -> %SystemRoot%\System32\fdsv.exe -> Smallfrogs Studio [Ver = 1.0.0.10 | Size = 73728 bytes | Modified Date = 8/31/2000 8:00:00 AM | Attr = ] ftprwqee.dllbox -> %SystemRoot%\System32\ftprwqee.dllbox -> [Ver = | Size = 19460 bytes | Modified Date = 2/18/2008 4:27:41 PM | Attr = HS] grep.exe -> %SystemRoot%\System32\grep.exe -> [Ver = | Size = 80412 bytes | Modified Date = 8/31/2000 8:00:00 AM | Attr = ] Help.ico -> %SystemRoot%\System32\Help.ico -> [Ver = | Size = 1406 bytes | Modified Date = 2/18/2008 7:37:47 PM | Attr = ] kap8 -> %SystemRoot%\System32\kap8 -> [Folder | Created Date = 2/17/2008 9:33:08 PM | Attr = ] lp6 -> %SystemRoot%\System32\lp6 -> [Folder | Created Date = 2/17/2008 9:33:08 PM | Attr = ] pavas.ico -> %SystemRoot%\System32\pavas.ico -> [Ver = | Size = 30590 bytes | Modified Date = 2/18/2008 7:37:47 PM | Attr = ] PreInstall -> %SystemRoot%\System32\PreInstall -> [Folder | Created Date = 2/18/2008 11:35:49 PM | Attr = ] QuickTime.qts -> %SystemRoot%\System32\QuickTime.qts -> Apple Inc. [Ver = 7.4.1 | Size = 57344 bytes | Modified Date = 1/31/2008 11:13:18 PM | Attr = ] QuickTimeVR.qtx -> %SystemRoot%\System32\QuickTimeVR.qtx -> Apple Inc. [Ver = 7.4.1 | Size = 90112 bytes | Modified Date = 1/31/2008 11:13:18 PM | Attr = ] sed.exe -> %SystemRoot%\System32\sed.exe -> [Ver = | Size = 98816 bytes | Modified Date = 8/31/2000 8:00:00 AM | Attr = ] SoftwareDistribution -> %SystemRoot%\System32\SoftwareDistribution -> [Folder | Created Date = 2/18/2008 11:30:37 PM | Attr = ] swreg.exe -> %SystemRoot%\System32\swreg.exe -> SteelWerX [Ver = 3.0.0.0 | Size = 161792 bytes | Modified Date = 8/31/2000 8:00:00 AM | Attr = ] swsc.exe -> %SystemRoot%\System32\swsc.exe -> SteelWerX [Ver = 2.0.0.5 | Size = 136704 bytes | Modified Date = 8/31/2000 8:00:00 AM | Attr = ] swxcacls.exe -> %SystemRoot%\System32\swxcacls.exe -> SteelWerX [Ver = 1.0.1.1 | Size = 212480 bytes | Modified Date = 8/31/2000 8:00:00 AM | Attr = ] Uninstall.ico -> %SystemRoot%\System32\Uninstall.ico -> [Ver = | Size = 2550 bytes | Modified Date = 2/18/2008 7:37:48 PM | Attr = ] VFind.exe -> %SystemRoot%\System32\VFind.exe -> [Ver = | Size = 49152 bytes | Modified Date = 8/31/2000 8:00:00 AM | Attr = ] WNASPI32.DLL -> %SystemRoot%\System32\WNASPI32.DLL -> Adaptec [Ver = 4.60 (1021) | Size = 45056 bytes | Modified Date = 9/10/1999 12:06:00 PM | Attr = ] zip.exe -> %SystemRoot%\System32\zip.exe -> [Ver = | Size = 68096 bytes | Modified Date = 8/31/2000 8:00:00 AM | Attr = ] ZPORT4AS.dll -> %SystemRoot%\System32\ZPORT4AS.dll -> [Ver = | Size = 11776 bytes | Modified Date = 3/25/2003 6:53:50 PM | Attr = ] $hf_mig$ -> %SystemRoot%\$hf_mig$ -> [Folder | Created Date = 2/18/2008 11:35:47 PM | Attr = H ] 1 C:\WINDOWS\*.tmp files -> C:\WINDOWS\*.tmp -> $MSI31Uninstall_KB893803v2$ -> %SystemRoot%\$MSI31Uninstall_KB893803v2$ -> [Folder | Created Date = 2/18/2008 11:35:24 PM | Attr = H ] 17PHolmes572.exe -> %SystemRoot%\17PHolmes572.exe -> [Ver = 1, 0, 0, 1 | Size = 36864 bytes | Modified Date = 2/17/2008 9:38:31 PM | Attr = ] erdnt -> %SystemRoot%\erdnt -> [Folder | Created Date = 2/18/2008 3:32:39 PM | Attr = ] Nircmd.exe -> %SystemRoot%\Nircmd.exe -> NirSoft [Ver = 2.00 | Size = 51200 bytes | Modified Date = 8/31/2000 8:00:00 AM | Attr = ] olx98NT.sys -> %SystemRoot%\olx98NT.sys -> [Ver = | Size = 0 bytes | Modified Date = 2/6/2008 12:28:33 AM | Attr = ] QTFont.for -> %SystemRoot%\QTFont.for -> [Ver = | Size = 1409 bytes | Modified Date = 2/16/2008 5:53:42 PM | Attr = ] QTFont.qfn -> %SystemRoot%\QTFont.qfn -> [Ver = | Size = 54156 bytes | Modified Date = 2/20/2008 6:22:21 PM | Attr = H ] SxsCaPendDel -> %SystemRoot%\SxsCaPendDel -> [Folder | Created Date = 2/17/2008 11:06:48 PM | Attr = ] TEMP -> %SystemRoot%\TEMP -> [Folder | Created Date = 2/18/2008 4:16:43 PM | Attr = ] tk58.exe -> %SystemRoot%\tk58.exe -> [Ver = | Size = 135168 bytes | Modified Date = 2/19/2008 9:37:15 PM | Attr = ] [Files Created - Additional Folder Scans - Non-Microsoft Only] Apple Computer -> %AllUsersProfile%\Application Data\Apple Computer -> [Folder | Created Date = 2/16/2008 5:44:50 PM | Attr = ] Grisoft -> %AllUsersProfile%\Application Data\Grisoft -> [Folder | Created Date = 2/18/2008 4:50:24 PM | Attr = ] SUPERAntiSpyware.com -> %AllUsersProfile%\Application Data\SUPERAntiSpyware.com -> [Folder | Created Date = 2/18/2008 6:46:56 PM | Attr = ] Apple Computer -> %AppData%\Apple Computer -> [Folder | Created Date = 2/16/2008 5:53:34 PM | Attr = ] Grisoft -> %AppData%\Grisoft -> [Folder | Created Date = 2/18/2008 4:50:38 PM | Attr = ] SUPERAntiSpyware.com -> %AppData%\SUPERAntiSpyware.com -> [Folder | Created Date = 2/18/2008 6:46:46 PM | Attr = ] dancing.pdf -> %UserProfile%\My Documents\dancing.pdf -> [Ver = | Size = 164560 bytes | Modified Date = 2/7/2008 11:33:01 PM | Attr = ] HEART_S_RANSOM.pdf -> %UserProfile%\My Documents\HEART_S_RANSOM.pdf -> [Ver = | Size = 1676023 bytes | Modified Date = 2/7/2008 11:32:24 PM | Attr = ] Updater -> %UserProfile%\My Documents\Updater -> [Folder | Created Date = 2/5/2008 6:41:00 PM | Attr = ] 1000 C:\Documents and Settings\Boo Boo\My Documents\*.tmp files -> C:\Documents and Settings\Boo Boo\My Documents\*.tmp -> AVG Anti-Spyware.lnk -> %AllUsersProfile%\Desktop\AVG Anti-Spyware.lnk -> [Ver = | Size = 849 bytes | Modified Date = 2/18/2008 4:50:31 PM | Attr = ] iTunes.lnk -> %AllUsersProfile%\Desktop\iTunes.lnk -> [Ver = | Size = 1804 bytes | Modified Date = 2/16/2008 5:53:19 PM | Attr = ] QuickTime Player.lnk -> %AllUsersProfile%\Desktop\QuickTime Player.lnk -> [Ver = | Size = 1604 bytes | Modified Date = 2/16/2008 5:45:40 PM | Attr = ] avgas-setup-7.5.1.43-3339.exe -> %UserProfile%\Desktop\avgas-setup-7.5.1.43-3339.exe -> [Ver = | Size = 14113576 bytes | Modified Date = 2/18/2008 4:45:11 PM | Attr = ] combofix log.docx -> %UserProfile%\Desktop\combofix log.docx -> [Ver = | Size = 15312 bytes | Modified Date = 2/18/2008 4:25:01 PM | Attr = ] ComboFix.exe -> %UserProfile%\Desktop\ComboFix.exe -> [Ver = | Size = 1597661 bytes | Modified Date = 2/18/2008 3:15:35 PM | Attr = ] @Alternate Data Stream - 26 bytes -> %UserProfile%\Desktop\ComboFix.exe:Zone.Identifier Growing up in a household where my mom is a care.docx -> %UserProfile%\Desktop\Growing up in a household where my mom is a care.docx -> [Ver = | Size = 14114 bytes | Modified Date = 2/19/2008 10:06:42 PM | Attr = ] Hello My Teacher -> %UserProfile%\Desktop\Hello My Teacher -> [Folder | Created Date = 2/4/2008 5:56:33 PM | Attr = ] Help and Support Center.lnk -> %UserProfile%\Desktop\Help and Support Center.lnk -> [Ver = | Size = 1270 bytes | Modified Date = 2/18/2008 10:18:57 AM | Attr = ] HijackThis.lnk -> %UserProfile%\Desktop\HijackThis.lnk -> [Ver = | Size = 1734 bytes | Modified Date = 2/18/2008 11:48:00 PM | Attr = ] HJTInstall.exe -> %UserProfile%\Desktop\HJTInstall.exe -> Trend Micro Inc. [Ver = 2.00.2 | Size = 812344 bytes | Modified Date = 2/18/2008 11:47:17 PM | Attr = ] @Alternate Data Stream - 26 bytes -> %UserProfile%\Desktop\HJTInstall.exe:Zone.Identifier LOVE-2008.wmv -> %UserProfile%\Desktop\LOVE-2008.wmv -> [Ver = | Size = 4172597 bytes | Modified Date = 2/17/2008 12:14:37 AM | Attr = ] slowmewp.exe -> %UserProfile%\Desktop\slowmewp.exe -> [Ver = | Size = 54030 bytes | Modified Date = 2/10/2008 6:24:23 PM | Attr = ] SUPERAntiSpyware.exe -> %UserProfile%\Desktop\SUPERAntiSpyware.exe -> [Ver = | Size = 5797152 bytes | Modified Date = 2/18/2008 6:45:38 PM | Attr = ] @Alternate Data Stream - 26 bytes -> %UserProfile%\Desktop\SUPERAntiSpyware.exe:Zone.Identifier Trends_Insights2006.pdf -> %UserProfile%\Desktop\Trends_Insights2006.pdf -> [Ver = | Size = 3790594 bytes | Modified Date = 1/23/2008 6:58:19 PM | Attr = ] Windows Update.lnk -> %UserProfile%\Desktop\Windows Update.lnk -> [Ver = | Size = 1270 bytes | Modified Date = 2/18/2008 10:19:00 AM | Attr = ] WinPFind35u -> %UserProfile%\Desktop\WinPFind35u -> [Folder | Created Date = 2/20/2008 6:30:05 PM | Attr = ] WinPFind35u.exe -> %UserProfile%\Desktop\WinPFind35u.exe -> [Ver = | Size = 480944 bytes | Modified Date = 2/20/2008 6:27:51 PM | Attr = ] @Alternate Data Stream - 26 bytes -> %UserProfile%\Desktop\WinPFind35u.exe:Zone.Identifier [Files/Folders - Modified Within 30 days] boot.ini -> %SystemDrive%\boot.ini -> [Ver = | Size = 281 bytes | Modified Date = 2/18/2008 3:39:34 PM | Attr = RHS] cmdcons -> %SystemDrive%\cmdcons -> [Folder | Modified Date = 2/18/2008 3:39:31 PM | Attr = ] 1000 C:\*.tmp files -> C:\*.tmp -> hiberfil.sys -> %SystemDrive%\hiberfil.sys -> [Ver = | Size = 519426048 bytes | Modified Date = 2/20/2008 6:22:09 PM | Attr = HS] Program Files -> %ProgramFiles% -> [Folder | Modified Date = 2/19/2008 12:21:15 AM | Attr = R ] QooBox -> %SystemDrive%\QooBox -> [Folder | Modified Date = 2/18/2008 4:16:26 PM | Attr = ] Temp -> %SystemDrive%\Temp -> [Folder | Modified Date = 2/18/2008 3:50:06 PM | Attr = ] WINDOWS -> %SystemRoot% -> [Folder | Modified Date = 2/20/2008 11:01:43 AM | Attr = ] etc -> %SystemRoot%\System32\drivers\etc -> [Folder | Modified Date = 2/18/2008 4:11:46 PM | Attr = ] hosts -> %SystemRoot%\System32\drivers\etc\hosts -> [Ver = | Size = 27 bytes | Modified Date = 2/18/2008 4:11:46 PM | Attr = ] ActiveScan -> %SystemRoot%\System32\ActiveScan -> [Folder | Modified Date = 2/18/2008 8:58:59 PM | Attr = ] 4 C:\WINDOWS\System32\*.tmp files -> C:\WINDOWS\System32\*.tmp -> bwmedia.dll -> %SystemRoot%\System32\bwmedia.dll -> [Ver = 1.00 | Size = 150016 bytes | Modified Date = 2/7/2008 10:48:04 PM | Attr = ] bwmedia1.dll -> %SystemRoot%\System32\bwmedia1.dll -> BinaryWork Corp. [Ver = 1.0.0.0 | Size = 295424 bytes | Modified Date = 2/7/2008 10:48:04 PM | Attr = ] CatRoot2 -> %SystemRoot%\System32\CatRoot2 -> [Folder | Modified Date = 2/19/2008 11:00:03 PM | Attr = ] Com -> %SystemRoot%\System32\Com -> [Folder | Modified Date = 2/19/2008 12:34:49 PM | Attr = ] config -> %SystemRoot%\System32\config -> [Folder | Modified Date = 2/18/2008 8:59:27 PM | Attr = ] dllcache -> %SystemRoot%\System32\dllcache -> [Folder | Modified Date = 2/19/2008 11:01:34 PM | Attr = RHS] drivers -> %SystemRoot%\System32\drivers -> [Folder | Modified Date = 2/19/2008 12:38:47 PM | Attr = ] DRVSTORE -> %SystemRoot%\System32\DRVSTORE -> [Folder | Modified Date = 2/17/2008 11:06:18 PM | Attr = ] er2 -> %SystemRoot%\System32\er2 -> [Folder | Modified Date = 2/18/2008 6:25:25 PM | Attr = ] FNTCACHE.DAT -> %SystemRoot%\System32\FNTCACHE.DAT -> [Ver = | Size = 265416 bytes | Modified Date = 2/19/2008 9:21:19 PM | Attr = ] ftprwqee.dllbox -> %SystemRoot%\System32\ftprwqee.dllbox -> [Ver = | Size = 19460 bytes | Modified Date = 2/18/2008 4:27:41 PM | Attr = HS] Help.ico -> %SystemRoot%\System32\Help.ico -> [Ver = | Size = 1406 bytes | Modified Date = 2/18/2008 7:37:47 PM | Attr = ] kap8 -> %SystemRoot%\System32\kap8 -> [Folder | Modified Date = 2/17/2008 9:33:08 PM | Attr = ] lp6 -> %SystemRoot%\System32\lp6 -> [Folder | Modified Date = 2/17/2008 9:33:08 PM | Attr = ] pavas.ico -> %SystemRoot%\System32\pavas.ico -> [Ver = | Size = 30590 bytes | Modified Date = 2/18/2008 7:37:47 PM | Attr = ] perfc009.dat -> %SystemRoot%\System32\perfc009.dat -> [Ver = | Size = 41238 bytes | Modified Date = 2/19/2008 11:39:05 AM | Attr = ] perfh009.dat -> %SystemRoot%\System32\perfh009.dat -> [Ver = | Size = 315076 bytes | Modified Date = 2/19/2008 11:39:05 AM | Attr = ] PerfStringBackup.INI -> %SystemRoot%\System32\PerfStringBackup.INI -> [Ver = | Size = 359948 bytes | Modified Date = 2/19/2008 11:39:03 AM | Attr = ] PreInstall -> %SystemRoot%\System32\PreInstall -> [Folder | Modified Date = 2/18/2008 11:35:49 PM | Attr = ] QuickTime.qts -> %SystemRoot%\System32\QuickTime.qts -> Apple Inc. [Ver = 7.4.1 | Size = 57344 bytes | Modified Date = 1/31/2008 11:13:18 PM | Attr = ] QuickTimeVR.qtx -> %SystemRoot%\System32\QuickTimeVR.qtx -> Apple Inc. [Ver = 7.4.1 | Size = 90112 bytes | Modified Date = 1/31/2008 11:13:18 PM | Attr = ] SoftwareDistribution -> %SystemRoot%\System32\SoftwareDistribution -> [Folder | Modified Date = 2/18/2008 11:30:37 PM | Attr = ] Uninstall.ico -> %SystemRoot%\System32\Uninstall.ico -> [Ver = | Size = 2550 bytes | Modified Date = 2/18/2008 7:37:48 PM | Attr = ] wbem -> %SystemRoot%\System32\wbem -> [Folder | Modified Date = 2/18/2008 9:01:58 PM | Attr = ] $hf_mig$ -> %SystemRoot%\$hf_mig$ -> [Folder | Modified Date = 2/19/2008 11:01:18 PM | Attr = H ] 1 C:\WINDOWS\*.tmp files -> C:\WINDOWS\*.tmp -> $MSI31Uninstall_KB893803v2$ -> %SystemRoot%\$MSI31Uninstall_KB893803v2$ -> [Folder | Modified Date = 2/18/2008 11:35:26 PM | Attr = H ] 17PHolmes572.exe -> %SystemRoot%\17PHolmes572.exe -> [Ver = 1, 0, 0, 1 | Size = 36864 bytes | Modified Date = 2/17/2008 9:38:31 PM | Attr = ] AppPatch -> %SystemRoot%\AppPatch -> [Folder | Modified Date = 2/18/2008 8:53:56 PM | Attr = ] ATK0100 -> %SystemRoot%\ATK0100 -> [Folder | Modified Date = 2/18/2008 8:53:57 PM | Attr = ] bootstat.dat -> %SystemRoot%\bootstat.dat -> [Ver = | Size = 2048 bytes | Modified Date = 2/20/2008 6:22:10 PM | Attr = S] Debug -> %SystemRoot%\Debug -> [Folder | Modified Date = 2/19/2008 12:37:12 PM | Attr = ] Downloaded Program Files -> %SystemRoot%\Downloaded Program Files -> [Folder | Modified Date = 2/18/2008 11:30:15 PM | Attr = S] erdnt -> %SystemRoot%\erdnt -> [Folder | Modified Date = 2/18/2008 4:08:21 PM | Attr = ] Help -> %SystemRoot%\Help -> [Folder | Modified Date = 2/18/2008 11:30:41 PM | Attr = ] imsins.BAK -> %SystemRoot%\imsins.BAK -> [Ver = | Size = 1374 bytes | Modified Date = 2/19/2008 11:01:25 PM | Attr = ] inf -> %SystemRoot%\inf -> [Folder | Modified Date = 2/20/2008 6:22:19 PM | Attr = H ] Installer -> %SystemRoot%\Installer -> [Folder | Modified Date = 2/19/2008 11:01:11 PM | Attr = HS] msagent -> %SystemRoot%\msagent -> [Folder | Modified Date = 2/19/2008 9:21:17 PM | Attr = ] NeroDigital.ini -> %SystemRoot%\NeroDigital.ini -> [Ver = | Size = 116 bytes | Modified Date = 2/11/2008 12:23:48 AM | Attr = ] olx98NT.sys -> %SystemRoot%\olx98NT.sys -> [Ver = | Size = 0 bytes | Modified Date = 2/6/2008 12:28:33 AM | Attr = ] Prefetch -> %SystemRoot%\Prefetch -> [Folder | Modified Date = 2/20/2008 6:30:14 PM | Attr = ] QTFont.for -> %SystemRoot%\QTFont.for -> [Ver = | Size = 1409 bytes | Modified Date = 2/16/2008 5:53:42 PM | Attr = ] QTFont.qfn -> %SystemRoot%\QTFont.qfn -> [Ver = | Size = 54156 bytes | Modified Date = 2/20/2008 6:22:21 PM | Attr = H ] Registration -> %SystemRoot%\Registration -> [Folder | Modified Date = 2/17/2008 9:27:48 PM | Attr = ] SoftwareDistribution -> %SystemRoot%\SoftwareDistribution -> [Folder | Modified Date = 2/18/2008 11:31:38 PM | Attr = ] SxsCaPendDel -> %SystemRoot%\SxsCaPendDel -> [Folder | Modified Date = 2/18/2008 10:15:51 AM | Attr = ] system -> %SystemRoot%\system -> [Folder | Modified Date = 2/6/2008 12:28:38 AM | Attr = ] system.ini -> %SystemRoot%\system.ini -> [Ver = | Size = 227 bytes | Modified Date = 2/18/2008 4:13:18 PM | Attr = ] system32 -> %SystemRoot%\system32 -> [Folder | Modified Date = 2/20/2008 11:01:14 AM | Attr = ] Tasks -> %SystemRoot%\Tasks -> [Folder | Modified Date = 2/18/2008 4:05:55 PM | Attr = S] TEMP -> %SystemRoot%\TEMP -> [Folder | Modified Date = 2/20/2008 6:22:38 PM | Attr = ] tk58.exe -> %SystemRoot%\tk58.exe -> [Ver = | Size = 135168 bytes | Modified Date = 2/19/2008 9:37:15 PM | Attr = ] win.ini -> %SystemRoot%\win.ini -> [Ver = | Size = 641 bytes | Modified Date = 2/18/2008 7:47:19 PM | Attr = ] WinSxS -> %SystemRoot%\WinSxS -> [Folder | Modified Date = 2/19/2008 12:36:31 PM | Attr = ] SA.DAT -> %SystemRoot%\tasks\SA.DAT -> [Ver = | Size = 6 bytes | Modified Date = 2/20/2008 6:22:14 PM | Attr = H ] qmgr0.dat -> C:\Documents and Settings\All Users\Application Data\Microsoft\Network\Downloader\qmgr0.dat -> [Ver = | Size = 11424 bytes | Modified Date = 2/20/2008 6:23:42 PM | Attr = ] qmgr1.dat -> C:\Documents and Settings\All Users\Application Data\Microsoft\Network\Downloader\qmgr1.dat -> [Ver = | Size = 11424 bytes | Modified Date = 2/20/2008 6:23:42 PM | Attr = ] opa12.dat -> C:\Documents and Settings\All Users\Application Data\Microsoft\OFFICE\DATA\opa12.dat -> [Ver = | Size = 8206 bytes | Modified Date = 9/1/2007 12:58:23 PM | Attr = ] [Files Modified - Additional Folder Scans - Non-Microsoft Only] Apple Computer -> %AllUsersProfile%\Application Data\Apple Computer -> [Folder | Modified Date = 2/16/2008 5:52:38 PM | Attr = ] Grisoft -> %AllUsersProfile%\Application Data\Grisoft -> [Folder | Modified Date = 2/18/2008 4:50:24 PM | Attr = ] Microsoft Help -> %AllUsersProfile%\Application Data\Microsoft Help -> [Folder | Modified Date = 2/19/2008 11:01:07 PM | Attr = ] SUPERAntiSpyware.com -> %AllUsersProfile%\Application Data\SUPERAntiSpyware.com -> [Folder | Modified Date = 2/18/2008 6:46:56 PM | Attr = ] Adobe -> %AppData%\Adobe -> [Folder | Modified Date = 2/5/2008 6:41:00 PM | Attr = ] Apple Computer -> %AppData%\Apple Computer -> [Folder | Modified Date = 2/17/2008 7:46:43 PM | Attr = ] Grisoft -> %AppData%\Grisoft -> [Folder | Modified Date = 2/18/2008 4:50:38 PM | Attr = ] Microsoft -> %AppData%\Microsoft -> [Folder | Modified Date = 2/18/2008 7:32:13 PM | Attr = S] SUPERAntiSpyware.com -> %AppData%\SUPERAntiSpyware.com -> [Folder | Modified Date = 2/18/2008 7:32:29 PM | Attr = ] uTorrent -> %AppData%\uTorrent -> [Folder | Modified Date = 2/11/2008 9:26:36 PM | Attr = ] Adobe -> %UserProfile%\Local Settings\Application Data\Adobe -> [Folder | Modified Date = 2/5/2008 11:43:07 PM | Attr = ] Apple Computer -> %UserProfile%\Local Settings\Application Data\Apple Computer -> [Folder | Modified Date = 2/16/2008 5:53:34 PM | Attr = ] DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini -> %UserProfile%\Local Settings\Application Data\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini -> [Ver = | Size = 19456 bytes | Modified Date = 1/31/2008 7:31:28 PM | Attr = ] GDIPFONTCACHEV1.DAT -> %UserProfile%\Local Settings\Application Data\GDIPFONTCACHEV1.DAT -> [Ver = | Size = 69312 bytes | Modified Date = 2/17/2008 1:31:58 PM | Attr = ] IconCache.db -> %UserProfile%\Local Settings\Application Data\IconCache.db -> [Ver = | Size = 2551012 bytes | Modified Date = 2/19/2008 10:58:50 PM | Attr = H ] Microsoft -> %UserProfile%\Local Settings\Application Data\Microsoft -> [Folder | Modified Date = 1/21/2008 11:01:58 PM | Attr = ] dancing.pdf -> %UserProfile%\My Documents\dancing.pdf -> [Ver = | Size = 164560 bytes | Modified Date = 2/7/2008 11:33:01 PM | Attr = ] Downloads -> %UserProfile%\My Documents\Downloads -> [Folder | Modified Date = 1/24/2008 8:29:41 PM | Attr = ] 1000 C:\Documents and Settings\Boo Boo\My Documents\*.tmp files -> C:\Documents and Settings\Boo Boo\My Documents\*.tmp -> HEART_S_RANSOM.pdf -> %UserProfile%\My Documents\HEART_S_RANSOM.pdf -> [Ver = | Size = 1676023 bytes | Modified Date = 2/7/2008 11:32:24 PM | Attr = ] LifeFrame -> %UserProfile%\My Documents\LifeFrame -> [Folder | Modified Date = 2/11/2008 12:28:23 AM | Attr = ] My Pictures -> %UserProfile%\My Documents\My Pictures -> [Folder | Modified Date = 2/8/2008 10:35:49 PM | Attr = ] My Received Files -> %UserProfile%\My Documents\My Received Files -> [Folder | Modified Date = 2/18/2008 4:46:42 PM | Attr = ] My Sharing Folders.lnk -> %UserProfile%\My Documents\My Sharing Folders.lnk -> [Ver = | Size = 576 bytes | Modified Date = 2/20/2008 6:24:42 PM | Attr = ] Updater -> %UserProfile%\My Documents\Updater -> [Folder | Modified Date = 2/5/2008 6:41:00 PM | Attr = ] Videos -> %UserProfile%\My Documents\Videos -> [Folder | Modified Date = 2/13/2008 11:57:04 PM | Attr = ] AVG Anti-Spyware.lnk -> %AllUsersProfile%\Desktop\AVG Anti-Spyware.lnk -> [Ver = | Size = 849 bytes | Modified Date = 2/18/2008 4:50:31 PM | Attr = ] iTunes.lnk -> %AllUsersProfile%\Desktop\iTunes.lnk -> [Ver = | Size = 1804 bytes | Modified Date = 2/16/2008 5:53:19 PM | Attr = ] jetAudio.lnk -> %AllUsersProfile%\Desktop\jetAudio.lnk -> [Ver = | Size = 1496 bytes | Modified Date = 2/14/2008 12:04:26 AM | Attr = ] QuickTime Player.lnk -> %AllUsersProfile%\Desktop\QuickTime Player.lnk -> [Ver = | Size = 1604 bytes | Modified Date = 2/16/2008 5:45:40 PM | Attr = ] Winamp.lnk -> %AllUsersProfile%\Desktop\Winamp.lnk -> [Ver = | Size = 664 bytes | Modified Date = 2/10/2008 6:35:15 PM | Attr = ] avgas-setup-7.5.1.43-3339.exe -> %UserProfile%\Desktop\avgas-setup-7.5.1.43-3339.exe -> [Ver = | Size = 14113576 bytes | Modified Date = 2/18/2008 4:45:11 PM | Attr = ] combofix log.docx -> %UserProfile%\Desktop\combofix log.docx -> [Ver = | Size = 15312 bytes | Modified Date = 2/18/2008 4:25:01 PM | Attr = ] ComboFix.exe -> %UserProfile%\Desktop\ComboFix.exe -> [Ver = | Size = 1597661 bytes | Modified Date = 2/18/2008 3:15:35 PM | Attr = ] @Alternate Data Stream - 26 bytes -> %UserProfile%\Desktop\ComboFix.exe:Zone.Identifier Growing up in a household where my mom is a care.docx -> %UserProfile%\Desktop\Growing up in a household where my mom is a care.docx -> [Ver = | Size = 14114 bytes | Modified Date = 2/19/2008 10:06:42 PM | Attr = ] Hello My Teacher -> %UserProfile%\Desktop\Hello My Teacher -> [Folder | Modified Date = 2/4/2008 5:56:55 PM | Attr = ] Help and Support Center.lnk -> %UserProfile%\Desktop\Help and Support Center.lnk -> [Ver = | Size = 1270 bytes | Modified Date = 2/18/2008 10:18:57 AM | Attr = ] HijackThis.lnk -> %UserProfile%\Desktop\HijackThis.lnk -> [Ver = | Size = 1734 bytes | Modified Date = 2/18/2008 11:48:00 PM | Attr = ] HJTInstall.exe -> %UserProfile%\Desktop\HJTInstall.exe -> Trend Micro Inc. [Ver = 2.00.2 | Size = 812344 bytes | Modified Date = 2/18/2008 11:47:17 PM | Attr = ] @Alternate Data Stream - 26 bytes -> %UserProfile%\Desktop\HJTInstall.exe:Zone.Identifier LOVE-2008.wmv -> %UserProfile%\Desktop\LOVE-2008.wmv -> [Ver = | Size = 4172597 bytes | Modified Date = 2/17/2008 12:14:37 AM | Attr = ] Microsoft Office Word 2007.lnk -> %UserProfile%\Desktop\Microsoft Office Word 2007.lnk -> [Ver = | Size = 2515 bytes | Modified Date = 2/18/2008 3:41:48 PM | Attr = ] slowmewp.exe -> %UserProfile%\Desktop\slowmewp.exe -> [Ver = | Size = 54030 bytes | Modified Date = 2/10/2008 6:24:23 PM | Attr = ] SUPERAntiSpyware.exe -> %UserProfile%\Desktop\SUPERAntiSpyware.exe -> [Ver = | Size = 5797152 bytes | Modified Date = 2/18/2008 6:45:38 PM | Attr = ] @Alternate Data Stream - 26 bytes -> %UserProfile%\Desktop\SUPERAntiSpyware.exe:Zone.Identifier Trends_Insights2006.pdf -> %UserProfile%\Desktop\Trends_Insights2006.pdf -> [Ver = | Size = 3790594 bytes | Modified Date = 1/23/2008 6:58:19 PM | Attr = ] utorrent.exe -> %UserProfile%\Desktop\utorrent.exe -> [Ver = | Size = 219952 bytes | Modified Date = 1/30/2008 11:13:32 AM | Attr = ] Windows Update.lnk -> %UserProfile%\Desktop\Windows Update.lnk -> [Ver = | Size = 1270 bytes | Modified Date = 2/18/2008 10:19:00 AM | Attr = ] WinPFind35u -> %UserProfile%\Desktop\WinPFind35u -> [Folder | Modified Date = 2/20/2008 6:30:05 PM | Attr = ] WinPFind35u.exe -> %UserProfile%\Desktop\WinPFind35u.exe -> [Ver = | Size = 480944 bytes | Modified Date = 2/20/2008 6:27:51 PM | Attr = ] @Alternate Data Stream - 26 bytes -> %UserProfile%\Desktop\WinPFind35u.exe:Zone.Identifier LightScribe -> %CommonProgramFiles%\LightScribe -> [Folder | Modified Date = 2/18/2008 8:47:35 PM | Attr = ] System -> %CommonProgramFiles%\System -> [Folder | Modified Date = 2/19/2008 12:35:11 PM | Attr = ] [File - Lop Check: Additional Folder Scans - Non-Microsoft Only] C:\Documents and Settings\All Users\Application Data\ -> C:\Documents and Settings\All Users\Application Data -> [Folder | Modified Date = 2/18/2008 6:46:56 PM | Attr = RH ] Adobe -> C:\Documents and Settings\All Users\Application Data\Adobe -> [Folder | Modified Date = 9/18/2007 5:49:12 PM | Attr = ] Adobe Systems -> C:\Documents and Settings\All Users\Application Data\Adobe Systems -> [Folder | Modified Date = 9/1/2007 1:32:51 PM | Attr = ] Apple Computer -> C:\Documents and Settings\All Users\Application Data\Apple Computer -> [Folder | Modified Date = 2/16/2008 5:52:38 PM | Attr = ] CanonBJ -> C:\Documents and Settings\All Users\Application Data\CanonBJ -> [Folder | Modified Date = 9/11/2007 12:32:35 PM | Attr = H ] FLEXnet -> C:\Documents and Settings\All Users\Application Data\FLEXnet -> [Folder | Modified Date = 9/1/2007 1:53:04 PM | Attr = ] Google -> C:\Documents and Settings\All Users\Application Data\Google -> [Folder | Modified Date = 12/20/2007 10:17:02 AM | Attr = ] Grisoft -> C:\Documents and Settings\All Users\Application Data\Grisoft -> [Folder | Modified Date = 2/18/2008 4:50:24 PM | Attr = ] Intel -> C:\Documents and Settings\All Users\Application Data\Intel -> [Folder | Modified Date = 9/1/2007 11:34:14 AM | Attr = ] Microsoft -> C:\Documents and Settings\All Users\Application Data\Microsoft -> [Folder | Modified Date = 9/6/2007 12:23:33 AM | Attr = S] Microsoft Help -> C:\Documents and Settings\All Users\Application Data\Microsoft Help -> [Folder | Modified Date = 2/19/2008 11:01:07 PM | Attr = ] Real -> C:\Documents and Settings\All Users\Application Data\Real -> [Folder | Modified Date = 9/1/2007 12:33:54 PM | Attr = ] SBSI -> C:\Documents and Settings\All Users\Application Data\SBSI -> [Folder | Modified Date = 9/1/2007 11:17:20 AM | Attr = ] SUPERAntiSpyware.com -> C:\Documents and Settings\All Users\Application Data\SUPERAntiSpyware.com -> [Folder | Modified Date = 2/18/2008 6:46:56 PM | Attr = ] Symantec -> C:\Documents and Settings\All Users\Application Data\Symantec -> [Folder | Modified Date = 9/1/2007 11:57:16 AM | Attr = ] Windows Genuine Advantage -> C:\Documents and Settings\All Users\Application Data\Windows Genuine Advantage -> [Folder | Modified Date = 10/22/2007 9:48:08 PM | Attr = ] Yahoo! -> C:\Documents and Settings\All Users\Application Data\Yahoo! -> [Folder | Modified Date = 11/21/2007 10:49:14 AM | Attr = ] C:\Documents and Settings\Boo Boo\Application Data\ -> C:\Documents and Settings\Boo Boo\Application Data -> [Folder | Modified Date = 2/18/2008 6:46:46 PM | Attr = RH ] Adobe -> C:\Documents and Settings\Boo Boo\Application Data\Adobe -> [Folder | Modified Date = 2/5/2008 6:41:00 PM | Attr = ] Apple Computer -> C:\Documents and Settings\Boo Boo\Application Data\Apple Computer -> [Folder | Modified Date = 2/17/2008 7:46:43 PM | Attr = ] COWON -> C:\Documents and Settings\Boo Boo\Application Data\COWON -> [Folder | Modified Date = 9/22/2007 4:06:27 PM | Attr = ] Grisoft -> C:\Documents and Settings\Boo Boo\Application Data\Grisoft -> [Folder | Modified Date = 2/18/2008 4:50:38 PM | Attr = ] Identities -> C:\Documents and Settings\Boo Boo\Application Data\Identities -> [Folder | Modified Date = 9/1/2007 11:11:38 AM | Attr = ] Intel -> C:\Documents and Settings\Boo Boo\Application Data\Intel -> [Folder | Modified Date = 9/1/2007 11:34:42 AM | Attr = ] InterTrust -> C:\Documents and Settings\Boo Boo\Application Data\InterTrust -> [Folder | Modified Date = 9/1/2007 11:20:14 AM | Attr = ] Logitech -> C:\Documents and Settings\Boo Boo\Application Data\Logitech -> [Folder | Modified Date = 9/1/2007 11:32:12 AM | Attr = ] Macromedia -> C:\Documents and Settings\Boo Boo\Application Data\Macromedia -> [Folder | Modified Date = 9/1/2007 12:25:48 PM | Attr = ] Media Player Classic -> C:\Documents and Settings\Boo Boo\Application Data\Media Player Classic -> [Folder | Modified Date = 9/1/2007 12:35:18 PM | Attr = ] Microsoft -> C:\Documents and Settings\Boo Boo\Application Data\Microsoft -> [Folder | Modified Date = 2/18/2008 7:32:13 PM | Attr = S] Move Networks -> C:\Documents and Settings\Boo Boo\Application Data\Move Networks -> [Folder | Modified Date = 12/4/2007 9:50:37 AM | Attr = ] Mozilla -> C:\Documents and Settings\Boo Boo\Application Data\Mozilla -> [Folder | Modified Date = 12/19/2007 9:57:55 PM | Attr = ] Opera -> C:\Documents and Settings\Boo Boo\Application Data\Opera -> [Folder | Modified Date = 9/22/2007 6:01:15 PM | Attr = ] Real -> C:\Documents and Settings\Boo Boo\Application Data\Real -> [Folder | Modified Date = 12/11/2007 12:11:37 AM | Attr = ] Sun -> C:\Documents and Settings\Boo Boo\Application Data\Sun -> [Folder | Modified Date = 1/14/2008 11:37:24 PM | Attr = ] SUPERAntiSpyware.com -> C:\Documents and Settings\Boo Boo\Application Data\SUPERAntiSpyware.com -> [Folder | Modified Date = 2/18/2008 7:32:29 PM | Attr = ] Symantec -> C:\Documents and Settings\Boo Boo\Application Data\Symantec -> [Folder | Modified Date = 9/1/2007 11:28:14 AM | Attr = ] Toshiba -> C:\Documents and Settings\Boo Boo\Application Data\Toshiba -> [Folder | Modified Date = 9/1/2007 12:00:49 PM | Attr = ] uTorrent -> C:\Documents and Settings\Boo Boo\Application Data\uTorrent -> [Folder | Modified Date = 2/11/2008 9:26:36 PM | Attr = ] Yahoo! -> C:\Documents and Settings\Boo Boo\Application Data\Yahoo! -> [Folder | Modified Date = 11/21/2007 10:49:14 AM | Attr = ] C:\WINDOWS\Tasks\ -> C:\WINDOWS\Tasks -> [Folder | Modified Date = 2/18/2008 4:05:55 PM | Attr = S] desktop.ini -> C:\WINDOWS\Tasks\desktop.ini -> [Ver = | Size = 65 bytes | Modified Date = 8/4/2004 7:00:00 PM | Attr = RH ] SA.DAT -> C:\WINDOWS\Tasks\SA.DAT -> [Ver = | Size = 6 bytes | Modified Date = 2/20/2008 6:22:14 PM | Attr = H ] [File - Purity Scan: Additional Folder Scans - Non-Microsoft Only] [CatchMe Rootkit Scan by GMER] < Windows folder & sub-folders > scanning hidden processes ... scanning hidden services & system hive ... scanning hidden registry entries ... scanning hidden files ... scan completed successfully hidden processes: 0 hidden services: 0 hidden files: 0 < Document and Settings folder & sub folders > scanning hidden files ... C:\Documents and Settings\All Users\Documents\My Music\Sample Music\Thumbs.db:encryptable 0 bytes C:\Documents and Settings\All Users\Documents\My Pictures\Sample Pictures\Thumbs.db:encryptable 0 bytes C:\Documents and Settings\Boo Boo\Desktop\Guitar Scales\Thumbs.db:encryptable 0 bytes C:\Documents and Settings\Boo Boo\Local Settings\Application Data\Microsoft\Messenger\lhbui2001@hotmail.com\Sharing Folders\bui_christina@hotmail.com\Thumbs.db:encryptable 0 bytes C:\Documents and Settings\Boo Boo\Local Settings\Application Data\Microsoft\Messenger\lhbui2001@hotmail.com\SharingMetadata\bui_christina@hotmail.com\DFSR\Staging\CS{3B245131-D152-EC1A-ACEF-4D6E04C0BFBE}\00\300-{3DCFACD1-027F-45BA-8F5E-8A8FEDCA80E2}-v300-{3DCFACD1-027F-45BA-8F5E-8A8FEDCA80E2}-v300-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.rdc.1 45012 bytes hidden from API C:\Documents and Settings\Boo Boo\Local Settings\Application Data\Microsoft\Messenger\lhbui2001@hotmail.com\SharingMetadata\bui_christina@hotmail.com\DFSR\Staging\CS{3B245131-D152-EC1A-ACEF-4D6E04C0BFBE}\00\300-{3DCFACD1-027F-45BA-8F5E-8A8FEDCA80E2}-v300-{3DCFACD1-027F-45BA-8F5E-8A8FEDCA80E2}-v300-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.rdc.2 3162 bytes hidden from API C:\Documents and Settings\Boo Boo\Local Settings\Application Data\Microsoft\Messenger\lhbui2001@hotmail.com\SharingMetadata\bui_christina@hotmail.com\DFSR\Staging\CS{3B245131-D152-EC1A-ACEF-4D6E04C0BFBE}\00\300-{3DCFACD1-027F-45BA-8F5E-8A8FEDCA80E2}-v300-{3DCFACD1-027F-45BA-8F5E-8A8FEDCA80E2}-v300-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.XPRESS 5000 bytes hidden from API C:\Documents and Settings\Boo Boo\Local Settings\Application Data\Microsoft\Messenger\lhbui2001@hotmail.com\SharingMetadata\bui_christina@hotmail.com\DFSR\Staging\CS{3B245131-D152-EC1A-ACEF-4D6E04C0BFBE}\01\301-{3DCFACD1-027F-45BA-8F5E-8A8FEDCA80E2}-v301-{3DCFACD1-027F-45BA-8F5E-8A8FEDCA80E2}-v301-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.rdc.1 26310 bytes hidden from API C:\Documents and Settings\Boo Boo\Local Settings\Application Data\Microsoft\Messenger\lhbui2001@hotmail.com\SharingMetadata\bui_christina@hotmail.com\DFSR\Staging\CS{3B245131-D152-EC1A-ACEF-4D6E04C0BFBE}\01\301-{3DCFACD1-027F-45BA-8F5E-8A8FEDCA80E2}-v301-{3DCFACD1-027F-45BA-8F5E-8A8FEDCA80E2}-v301-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.rdc.2 1992 bytes hidden from API C:\Documents and Settings\Boo Boo\Local Settings\Application Data\Microsoft\Messenger\lhbui2001@hotmail.com\SharingMetadata\bui_christina@hotmail.com\DFSR\Staging\CS{3B245131-D152-EC1A-ACEF-4D6E04C0BFBE}\01\301-{3DCFACD1-027F-45BA-8F5E-8A8FEDCA80E2}-v301-{3DCFACD1-027F-45BA-8F5E-8A8FEDCA80E2}-v301-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.XPRESS 2904 bytes hidden from API C:\Documents and Settings\Boo Boo\Local Settings\Application Data\Microsoft\Messenger\lhbui2001@hotmail.com\SharingMetadata\bui_christina@hotmail.com\DFSR\Staging\CS{3B245131-D152-EC1A-ACEF-4D6E04C0BFBE}\13\313-{3DCFACD1-027F-45BA-8F5E-8A8FEDCA80E2}-v313-{3DCFACD1-027F-45BA-8F5E-8A8FEDCA80E2}-v313-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.XPRESS 8 bytes hidden from API C:\Documents and Settings\Boo Boo\Local Settings\Application Data\Microsoft\Messenger\lhbui2001@hotmail.com\SharingMetadata\bui_christina@hotmail.com\DFSR\Staging\CS{3B245131-D152-EC1A-ACEF-4D6E04C0BFBE}\15\315-{3DCFACD1-027F-45BA-8F5E-8A8FEDCA80E2}-v315-{3DCFACD1-027F-45BA-8F5E-8A8FEDCA80E2}-v315-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.rdc.1 53850 bytes hidden from API C:\Documents and Settings\Boo Boo\Local Settings\Application Data\Microsoft\Messenger\lhbui2001@hotmail.com\SharingMetadata\bui_christina@hotmail.com\DFSR\Staging\CS{3B245131-D152-EC1A-ACEF-4D6E04C0BFBE}\15\315-{3DCFACD1-027F-45BA-8F5E-8A8FEDCA80E2}-v315-{3DCFACD1-027F-45BA-8F5E-8A8FEDCA80E2}-v315-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.rdc.2 3954 bytes hidden from API C:\Documents and Settings\Boo Boo\Local Settings\Application Data\Microsoft\Messenger\lhbui2001@hotmail.com\SharingMetadata\bui_christina@hotmail.com\DFSR\Staging\CS{3B245131-D152-EC1A-ACEF-4D6E04C0BFBE}\15\315-{3DCFACD1-027F-45BA-8F5E-8A8FEDCA80E2}-v315-{3DCFACD1-027F-45BA-8F5E-8A8FEDCA80E2}-v315-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.XPRESS 5968 bytes hidden from API C:\Documents and Settings\Boo Boo\Local Settings\Application Data\Microsoft\Messenger\lhbui2001@hotmail.com\SharingMetadata\bui_christina@hotmail.com\DFSR\Staging\CS{3B245131-D152-EC1A-ACEF-4D6E04C0BFBE}\16\316-{3DCFACD1-027F-45BA-8F5E-8A8FEDCA80E2}-v316-{3DCFACD1-027F-45BA-8F5E-8A8FEDCA80E2}-v316-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.rdc.1 56280 bytes hidden from API C:\Documents and Settings\Boo Boo\Local Settings\Application Data\Microsoft\Messenger\lhbui2001@hotmail.com\SharingMetadata\bui_christina@hotmail.com\DFSR\Staging\CS{3B245131-D152-EC1A-ACEF-4D6E04C0BFBE}\16\316-{3DCFACD1-027F-45BA-8F5E-8A8FEDCA80E2}-v316-{3DCFACD1-027F-45BA-8F5E-8A8FEDCA80E2}-v316-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.rdc.2 4098 bytes hidden from API C:\Documents and Settings\Boo Boo\Local Settings\Application Data\Microsoft\Messenger\lhbui2001@hotmail.com\SharingMetadata\bui_christina@hotmail.com\DFSR\Staging\CS{3B245131-D152-EC1A-ACEF-4D6E04C0BFBE}\16\316-{3DCFACD1-027F-45BA-8F5E-8A8FEDCA80E2}-v316-{3DCFACD1-027F-45BA-8F5E-8A8FEDCA80E2}-v316-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.XPRESS 6200 bytes hidden from API C:\Documents and Settings\Boo Boo\Local Settings\Application Data\Microsoft\Messenger\lhbui2001@hotmail.com\SharingMetadata\bui_christina@hotmail.com\DFSR\Staging\CS{3B245131-D152-EC1A-ACEF-4D6E04C0BFBE}\17\317-{3DCFACD1-027F-45BA-8F5E-8A8FEDCA80E2}-v317-{3DCFACD1-027F-45BA-8F5E-8A8FEDCA80E2}-v317-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.rdc.1 66432 bytes hidden from API C:\Documents and Settings\Boo Boo\Local Settings\Application Data\Microsoft\Messenger\lhbui2001@hotmail.com\SharingMetadata\bui_christina@hotmail.com\DFSR\Staging\CS{3B245131-D152-EC1A-ACEF-4D6E04C0BFBE}\17\317-{3DCFACD1-027F-45BA-8F5E-8A8FEDCA80E2}-v317-{3DCFACD1-027F-45BA-8F5E-8A8FEDCA80E2}-v317-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.rdc.2 4818 bytes hidden from API C:\Documents and Settings\Boo Boo\Local Settings\Application Data\Microsoft\Messenger\lhbui2001@hotmail.com\SharingMetadata\bui_christina@hotmail.com\DFSR\Staging\CS{3B245131-D152-EC1A-ACEF-4D6E04C0BFBE}\17\317-{3DCFACD1-027F-45BA-8F5E-8A8FEDCA80E2}-v317-{3DCFACD1-027F-45BA-8F5E-8A8FEDCA80E2}-v317-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.XPRESS 7344 bytes hidden from API C:\Documents and Settings\Boo Boo\Local Settings\Application Data\Microsoft\Messenger\lhbui2001@hotmail.com\SharingMetadata\bui_christina@hotmail.com\DFSR\Staging\CS{3B245131-D152-EC1A-ACEF-4D6E04C0BFBE}\18\318-{3DCFACD1-027F-45BA-8F5E-8A8FEDCA80E2}-v318-{3DCFACD1-027F-45BA-8F5E-8A8FEDCA80E2}-v318-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.rdc.1 54174 bytes hidden from API C:\Documents and Settings\Boo Boo\Local Settings\Application Data\Microsoft\Messenger\lhbui2001@hotmail.com\SharingMetadata\bui_christina@hotmail.com\DFSR\Staging\CS{3B245131-D152-EC1A-ACEF-4D6E04C0BFBE}\18\318-{3DCFACD1-027F-45BA-8F5E-8A8FEDCA80E2}-v318-{3DCFACD1-027F-45BA-8F5E-8A8FEDCA80E2}-v318-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.XPRESS 6056 bytes hidden from API C:\Documents and Settings\Boo Boo\Local Settings\Application Data\Microsoft\Messenger\lhbui2001@hotmail.com\SharingMetadata\bui_christina@hotmail.com\DFSR\Staging\CS{3B245131-D152-EC1A-ACEF-4D6E04C0BFBE}\19\319-{3DCFACD1-027F-45BA-8F5E-8A8FEDCA80E2}-v319-{3DCFACD1-027F-45BA-8F5E-8A8FEDCA80E2}-v319-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.rdc.1 55236 bytes hidden from API C:\Documents and Settings\Boo Boo\Local Settings\Application Data\Microsoft\Messenger\lhbui2001@hotmail.com\SharingMetadata\bui_christina@hotmail.com\DFSR\Staging\CS{3B245131-D152-EC1A-ACEF-4D6E04C0BFBE}\19\319-{3DCFACD1-027F-45BA-8F5E-8A8FEDCA80E2}-v319-{3DCFACD1-027F-45BA-8F5E-8A8FEDCA80E2}-v319-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.XPRESS 6088 bytes hidden from API C:\Documents and Settings\Boo Boo\Local Settings\Application Data\Microsoft\Messenger\lhbui2001@hotmail.com\SharingMetadata\bui_christina@hotmail.com\DFSR\Staging\CS{3B245131-D152-EC1A-ACEF-4D6E04C0BFBE}\20\320-{3DCFACD1-027F-45BA-8F5E-8A8FEDCA80E2}-v320-{3DCFACD1-027F-45BA-8F5E-8A8FEDCA80E2}-v320-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.rdc.1 60258 bytes hidden from API C:\Documents and Settings\Boo Boo\Local Settings\Application Data\Microsoft\Messenger\lhbui2001@hotmail.com\SharingMetadata\bui_christina@hotmail.com\DFSR\Staging\CS{3B245131-D152-EC1A-ACEF-4D6E04C0BFBE}\20\320-{3DCFACD1-027F-45BA-8F5E-8A8FEDCA80E2}-v320-{3DCFACD1-027F-45BA-8F5E-8A8FEDCA80E2}-v320-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.XPRESS 6680 bytes hidden from API C:\Documents and Settings\Boo Boo\Local Settings\Application Data\Microsoft\Messenger\lhbui2001@hotmail.com\SharingMetadata\bui_christina@hotmail.com\DFSR\Staging\CS{3B245131-D152-EC1A-ACEF-4D6E04C0BFBE}\21\321-{3DCFACD1-027F-45BA-8F5E-8A8FEDCA80E2}-v321-{3DCFACD1-027F-45BA-8F5E-8A8FEDCA80E2}-v321-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.rdc.1 44292 bytes hidden from API C:\Documents and Settings\Boo Boo\Local Settings\Application Data\Microsoft\Messenger\lhbui2001@hotmail.com\SharingMetadata\bui_christina@hotmail.com\DFSR\Staging\CS{3B245131-D152-EC1A-ACEF-4D6E04C0BFBE}\21\321-{3DCFACD1-027F-45BA-8F5E-8A8FEDCA80E2}-v321-{3DCFACD1-027F-45BA-8F5E-8A8FEDCA80E2}-v321-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.XPRESS 5008 bytes hidden from API C:\Documents and Settings\Boo Boo\Local Settings\Application Data\Microsoft\Messenger\lhbui2001@hotmail.com\SharingMetadata\bui_christina@hotmail.com\DFSR\Staging\CS{3B245131-D152-EC1A-ACEF-4D6E04C0BFBE}\22\322-{3DCFACD1-027F-45BA-8F5E-8A8FEDCA80E2}-v322-{3DCFACD1-027F-45BA-8F5E-8A8FEDCA80E2}-v322-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.rdc.1 62940 bytes hidden from API C:\Documents and Settings\Boo Boo\Local Settings\Application Data\Microsoft\Messenger\lhbui2001@hotmail.com\SharingMetadata\bui_christina@hotmail.com\DFSR\Staging\CS{3B245131-D152-EC1A-ACEF-4D6E04C0BFBE}\22\322-{3DCFACD1-027F-45BA-8F5E-8A8FEDCA80E2}-v322-{3DCFACD1-027F-45BA-8F5E-8A8FEDCA80E2}-v322-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.XPRESS 7008 bytes hidden from API C:\Documents and Settings\Boo Boo\Local Settings\Application Data\Microsoft\Messenger\lhbui2001@hotmail.com\SharingMetadata\bui_christina@hotmail.com\DFSR\Staging\CS{3B245131-D152-EC1A-ACEF-4D6E04C0BFBE}\23\323-{3DCFACD1-027F-45BA-8F5E-8A8FEDCA80E2}-v323-{3DCFACD1-027F-45BA-8F5E-8A8FEDCA80E2}-v323-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.rdc.1 52662 bytes hidden from API C:\Documents and Settings\Boo Boo\Local Settings\Application Data\Microsoft\Messenger\lhbui2001@hotmail.com\SharingMetadata\bui_christina@hotmail.com\DFSR\Staging\CS{3B245131-D152-EC1A-ACEF-4D6E04C0BFBE}\23\323-{3DCFACD1-027F-45BA-8F5E-8A8FEDCA80E2}-v323-{3DCFACD1-027F-45BA-8F5E-8A8FEDCA80E2}-v323-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.XPRESS 5920 bytes hidden from API C:\Documents and Settings\Boo Boo\Local Settings\Application Data\Microsoft\Messenger\lhbui2001@hotmail.com\SharingMetadata\bui_christina@hotmail.com\DFSR\Staging\CS{3B245131-D152-EC1A-ACEF-4D6E04C0BFBE}\24\324-{3DCFACD1-027F-45BA-8F5E-8A8FEDCA80E2}-v324-{3DCFACD1-027F-45BA-8F5E-8A8FEDCA80E2}-v324-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.rdc.1 49098 bytes hidden from API C:\Documents and Settings\Boo Boo\Local Settings\Application Data\Microsoft\Messenger\lhbui2001@hotmail.com\SharingMetadata\bui_christina@hotmail.com\DFSR\Staging\CS{3B245131-D152-EC1A-ACEF-4D6E04C0BFBE}\24\324-{3DCFACD1-027F-45BA-8F5E-8A8FEDCA80E2}-v324-{3DCFACD1-027F-45BA-8F5E-8A8FEDCA80E2}-v324-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.XPRESS 5464 bytes hidden from API C:\Documents and Settings\Boo Boo\Local Settings\Application Data\Microsoft\Messenger\lhbui2001@hotmail.com\SharingMetadata\bui_christina@hotmail.com\DFSR\Staging\CS{3B245131-D152-EC1A-ACEF-4D6E04C0BFBE}\25\325-{3DCFACD1-027F-45BA-8F5E-8A8FEDCA80E2}-v325-{3DCFACD1-027F-45BA-8F5E-8A8FEDCA80E2}-v325-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.rdc.1 52554 bytes hidden from API C:\Documents and Settings\Boo Boo\Local Settings\Application Data\Microsoft\Messenger\lhbui2001@hotmail.com\SharingMetadata\bui_christina@hotmail.com\DFSR\Staging\CS{3B245131-D152-EC1A-ACEF-4D6E04C0BFBE}\25\325-{3DCFACD1-027F-45BA-8F5E-8A8FEDCA80E2}-v325-{3DCFACD1-027F-45BA-8F5E-8A8FEDCA80E2}-v325-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.XPRESS 5856 bytes hidden from API C:\Documents and Settings\Boo Boo\Local Settings\Application Data\Microsoft\Messenger\lhbui2001@hotmail.com\SharingMetadata\bui_christina@hotmail.com\DFSR\Staging\CS{3B245131-D152-EC1A-ACEF-4D6E04C0BFBE}\26\326-{3DCFACD1-027F-45BA-8F5E-8A8FEDCA80E2}-v326-{3DCFACD1-027F-45BA-8F5E-8A8FEDCA80E2}-v326-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.rdc.1 62904 bytes hidden from API C:\Documents and Settings\Boo Boo\Local Settings\Application Data\Microsoft\Messenger\lhbui2001@hotmail.com\SharingMetadata\bui_christina@hotmail.com\DFSR\Staging\CS{3B245131-D152-EC1A-ACEF-4D6E04C0BFBE}\26\326-{3DCFACD1-027F-45BA-8F5E-8A8FEDCA80E2}-v326-{3DCFACD1-027F-45BA-8F5E-8A8FEDCA80E2}-v326-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.XPRESS 7008 bytes hidden from API C:\Documents and Settings\Boo Boo\Local Settings\Application Data\Microsoft\Messenger\lhbui2001@hotmail.com\SharingMetadata\bui_christina@hotmail.com\DFSR\Staging\CS{3B245131-D152-EC1A-ACEF-4D6E04C0BFBE}\27\327-{3DCFACD1-027F-45BA-8F5E-8A8FEDCA80E2}-v327-{3DCFACD1-027F-45BA-8F5E-8A8FEDCA80E2}-v327-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.rdc.1 55920 bytes hidden from API C:\Documents and Settings\Boo Boo\Local Settings\Application Data\Microsoft\Messenger\lhbui2001@hotmail.com\SharingMetadata\bui_christina@hotmail.com\DFSR\Staging\CS{3B245131-D152-EC1A-ACEF-4D6E04C0BFBE}\27\327-{3DCFACD1-027F-45BA-8F5E-8A8FEDCA80E2}-v327-{3DCFACD1-027F-45BA-8F5E-8A8FEDCA80E2}-v327-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.XPRESS 6176 bytes hidden from API C:\Documents and Settings\Boo Boo\Local Settings\Application Data\Microsoft\Messenger\lhbui2001@hotmail.com\SharingMetadata\bui_christina@hotmail.com\DFSR\Staging\CS{3B245131-D152-EC1A-ACEF-4D6E04C0BFBE}\28\328-{3DCFACD1-027F-45BA-8F5E-8A8FEDCA80E2}-v328-{3DCFACD1-027F-45BA-8F5E-8A8FEDCA80E2}-v328-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.rdc.1 42240 bytes hidden from API C:\Documents and Settings\Boo Boo\Local Settings\Application Data\Microsoft\Messenger\lhbui2001@hotmail.com\SharingMetadata\bui_christina@hotmail.com\DFSR\Staging\CS{3B245131-D152-EC1A-ACEF-4D6E04C0BFBE}\28\328-{3DCFACD1-027F-45BA-8F5E-8A8FEDCA80E2}-v328-{3DCFACD1-027F-45BA-8F5E-8A8FEDCA80E2}-v328-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.XPRESS 4672 bytes hidden from API C:\Documents and Settings\Boo Boo\Local Settings\Application Data\Microsoft\Messenger\lhbui2001@hotmail.com\SharingMetadata\bui_christina@hotmail.com\DFSR\Staging\CS{3B245131-D152-EC1A-ACEF-4D6E04C0BFBE}\62\287-{3DCFACD1-027F-45BA-8F5E-8A8FEDCA80E2}-v262-{3DCFACD1-027F-45BA-8F5E-8A8FEDCA80E2}-v287-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.rdc.1 50754 bytes hidden from API C:\Documents and Settings\Boo Boo\Local Settings\Application Data\Microsoft\Messenger\lhbui2001@hotmail.com\SharingMetadata\bui_christina@hotmail.com\DFSR\Staging\CS{3B245131-D152-EC1A-ACEF-4D6E04C0BFBE}\62\287-{3DCFACD1-027F-45BA-8F5E-8A8FEDCA80E2}-v262-{3DCFACD1-027F-45BA-8F5E-8A8FEDCA80E2}-v287-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.rdc.2 3414 bytes hidden from API C:\Documents and Settings\Boo Boo\Local Settings\Application Data\Microsoft\Messenger\lhbui2001@hotmail.com\SharingMetadata\bui_christina@hotmail.com\DFSR\Staging\CS{3B245131-D152-EC1A-ACEF-4D6E04C0BFBE}\62\287-{3DCFACD1-027F-45BA-8F5E-8A8FEDCA80E2}-v262-{3DCFACD1-027F-45BA-8F5E-8A8FEDCA80E2}-v287-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.XPRESS 5592 bytes hidden from API C:\Documents and Settings\Boo Boo\Local Settings\Application Data\Microsoft\Messenger\lhbui2001@hotmail.com\SharingMetadata\bui_christina@hotmail.com\DFSR\Staging\CS{3B245131-D152-EC1A-ACEF-4D6E04C0BFBE}\63\275-{3DCFACD1-027F-45BA-8F5E-8A8FEDCA80E2}-v263-{3DCFACD1-027F-45BA-8F5E-8A8FEDCA80E2}-v275-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.rdc.1 46164 bytes hidden from API C:\Documents and Settings\Boo Boo\Local Settings\Application Data\Microsoft\Messenger\lhbui2001@hotmail.com\SharingMetadata\bui_christina@hotmail.com\DFSR\Staging\CS{3B245131-D152-EC1A-ACEF-4D6E04C0BFBE}\63\275-{3DCFACD1-027F-45BA-8F5E-8A8FEDCA80E2}-v263-{3DCFACD1-027F-45BA-8F5E-8A8FEDCA80E2}-v275-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.rdc.2 3378 bytes hidden from API C:\Documents and Settings\Boo Boo\Local Settings\Application Data\Microsoft\Messenger\lhbui2001@hotmail.com\SharingMetadata\bui_christina@hotmail.com\DFSR\Staging\CS{3B245131-D152-EC1A-ACEF-4D6E04C0BFBE}\63\275-{3DCFACD1-027F-45BA-8F5E-8A8FEDCA80E2}-v263-{3DCFACD1-027F-45BA-8F5E-8A8FEDCA80E2}-v275-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.XPRESS 5088 bytes hidden from API C:\Documents and Settings\Boo Boo\Local Settings\Application Data\Microsoft\Messenger\lhbui2001@hotmail.com\SharingMetadata\bui_christina@hotmail.com\DFSR\Staging\CS{3B245131-D152-EC1A-ACEF-4D6E04C0BFBE}\64\276-{3DCFACD1-027F-45BA-8F5E-8A8FEDCA80E2}-v264-{3DCFACD1-027F-45BA-8F5E-8A8FEDCA80E2}-v276-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.rdc.1 40818 bytes hidden from API C:\Documents and Settings\Boo Boo\Local Settings\Application Data\Microsoft\Messenger\lhbui2001@hotmail.com\SharingMetadata\bui_christina@hotmail.com\DFSR\Staging\CS{3B245131-D152-EC1A-ACEF-4D6E04C0BFBE}\64\276-{3DCFACD1-027F-45BA-8F5E-8A8FEDCA80E2}-v264-{3DCFACD1-027F-45BA-8F5E-8A8FEDCA80E2}-v276-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.rdc.2 2892 bytes hidden from API C:\Documents and Settings\Boo Boo\Local Settings\Application Data\Microsoft\Messenger\lhbui2001@hotmail.com\SharingMetadata\bui_christina@hotmail.com\DFSR\Staging\CS{3B245131-D152-EC1A-ACEF-4D6E04C0BFBE}\64\276-{3DCFACD1-027F-45BA-8F5E-8A8FEDCA80E2}-v264-{3DCFACD1-027F-45BA-8F5E-8A8FEDCA80E2}-v276-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.XPRESS 4544 bytes hidden from API C:\Documents and Settings\Boo Boo\Local Settings\Application Data\Microsoft\Messenger\lhbui2001@hotmail.com\SharingMetadata\bui_christina@hotmail.com\DFSR\Staging\CS{3B245131-D152-EC1A-ACEF-4D6E04C0BFBE}\65\277-{3DCFACD1-027F-45BA-8F5E-8A8FEDCA80E2}-v265-{3DCFACD1-027F-45BA-8F5E-8A8FEDCA80E2}-v277-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.rdc.1 47280 bytes hidden from API C:\Documents and Settings\Boo Boo\Local Settings\Application Data\Microsoft\Messenger\lhbui2001@hotmail.com\SharingMetadata\bui_christina@hotmail.com\DFSR\Staging\CS{3B245131-D152-EC1A-ACEF-4D6E04C0BFBE}\65\277-{3DCFACD1-027F-45BA-8F5E-8A8FEDCA80E2}-v265-{3DCFACD1-027F-45BA-8F5E-8A8FEDCA80E2}-v277-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.rdc.2 3342 bytes hidden from API C:\Documents and Settings\Boo Boo\Local Settings\Application Data\Microsoft\Messenger\lhbui2001@hotmail.com\SharingMetadata\bui_christina@hotmail.com\DFSR\Staging\CS{3B245131-D152-EC1A-ACEF-4D6E04C0BFBE}\65\277-{3DCFACD1-027F-45BA-8F5E-8A8FEDCA80E2}-v265-{3DCFACD1-027F-45BA-8F5E-8A8FEDCA80E2}-v277-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.XPRESS 5280 bytes hidden from API C:\Documents and Settings\Boo Boo\Local Settings\Application Data\Microsoft\Messenger\lhbui2001@hotmail.com\SharingMetadata\bui_christina@hotmail.com\DFSR\Staging\CS{3B245131-D152-EC1A-ACEF-4D6E04C0BFBE}\66\278-{3DCFACD1-027F-45BA-8F5E-8A8FEDCA80E2}-v266-{3DCFACD1-027F-45BA-8F5E-8A8FEDCA80E2}-v278-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.rdc.1 29838 bytes hidden from API C:\Documents and Settings\Boo Boo\Local Settings\Application Data\Microsoft\Messenger\lhbui2001@hotmail.com\SharingMetadata\bui_christina@hotmail.com\DFSR\Staging\CS{3B245131-D152-EC1A-ACEF-4D6E04C0BFBE}\66\278-{3DCFACD1-027F-45BA-8F5E-8A8FEDCA80E2}-v266-{3DCFACD1-027F-45BA-8F5E-8A8FEDCA80E2}-v278-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.rdc.2 2208 bytes hidden from API C:\Documents and Settings\Boo Boo\Local Settings\Application Data\Microsoft\Messenger\lhbui2001@hotmail.com\SharingMetadata\bui_christina@hotmail.com\DFSR\Staging\CS{3B245131-D152-EC1A-ACEF-4D6E04C0BFBE}\66\278-{3DCFACD1-027F-45BA-8F5E-8A8FEDCA80E2}-v266-{3DCFACD1-027F-45BA-8F5E-8A8FEDCA80E2}-v278-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.XPRESS 3288 bytes hidden from API C:\Documents and Settings\Boo Boo\Local Settings\Application Data\Microsoft\Messenger\lhbui2001@hotmail.com\SharingMetadata\bui_christina@hotmail.com\DFSR\Staging\CS{3B245131-D152-EC1A-ACEF-4D6E04C0BFBE}\67\279-{3DCFACD1-027F-45BA-8F5E-8A8FEDCA80E2}-v267-{3DCFACD1-027F-45BA-8F5E-8A8FEDCA80E2}-v279-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.rdc.1 48612 bytes hidden from API C:\Documents and Settings\Boo Boo\Local Settings\Application Data\Microsoft\Messenger\lhbui2001@hotmail.com\SharingMetadata\bui_christina@hotmail.com\DFSR\Staging\CS{3B245131-D152-EC1A-ACEF-4D6E04C0BFBE}\67\279-{3DCFACD1-027F-45BA-8F5E-8A8FEDCA80E2}-v267-{3DCFACD1-027F-45BA-8F5E-8A8FEDCA80E2}-v279-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.rdc.2 3396 bytes hidden from API C:\Documents and Settings\Boo Boo\Local Settings\Application Data\Microsoft\Messenger\lhbui2001@hotmail.com\SharingMetadata\bui_christina@hotmail.com\DFSR\Staging\CS{3B245131-D152-EC1A-ACEF-4D6E04C0BFBE}\67\279-{3DCFACD1-027F-45BA-8F5E-8A8FEDCA80E2}-v267-{3DCFACD1-027F-45BA-8F5E-8A8FEDCA80E2}-v279-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.XPRESS 5384 bytes hidden from API C:\Documents and Settings\Boo Boo\Local Settings\Application Data\Microsoft\Messenger\lhbui2001@hotmail.com\SharingMetadata\bui_christina@hotmail.com\DFSR\Staging\CS{3B245131-D152-EC1A-ACEF-4D6E04C0BFBE}\68\280-{3DCFACD1-027F-45BA-8F5E-8A8FEDCA80E2}-v268-{3DCFACD1-027F-45BA-8F5E-8A8FEDCA80E2}-v280-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.rdc.1 52104 bytes hidden from API C:\Documents and Settings\Boo Boo\Local Settings\Application Data\Microsoft\Messenger\lhbui2001@hotmail.com\SharingMetadata\bui_christina@hotmail.com\DFSR\Staging\CS{3B245131-D152-EC1A-ACEF-4D6E04C0BFBE}\68\280-{3DCFACD1-027F-45BA-8F5E-8A8FEDCA80E2}-v268-{3DCFACD1-027F-45BA-8F5E-8A8FEDCA80E2}-v280-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.rdc.2 3522 bytes hidden from API C:\Documents and Settings\Boo Boo\Local Settings\Application Data\Microsoft\Messenger\lhbui2001@hotmail.com\SharingMetadata\bui_christina@hotmail.com\DFSR\Staging\CS{3B245131-D152-EC1A-ACEF-4D6E04C0BFBE}\68\280-{3DCFACD1-027F-45BA-8F5E-8A8FEDCA80E2}-v268-{3DCFACD1-027F-45BA-8F5E-8A8FEDCA80E2}-v280-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.XPRESS 5832 bytes hidden from API C:\Documents and Settings\Boo Boo\Local Settings\Application Data\Microsoft\Messenger\lhbui2001@hotmail.com\SharingMetadata\bui_christina@hotmail.com\DFSR\Staging\CS{3B245131-D152-EC1A-ACEF-4D6E04C0BFBE}\69\281-{3DCFACD1-027F-45BA-8F5E-8A8FEDCA80E2}-v269-{3DCFACD1-027F-45BA-8F5E-8A8FEDCA80E2}-v281-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.rdc.1 44094 bytes hidden from API C:\Documents and Settings\Boo Boo\Local Settings\Application Data\Microsoft\Messenger\lhbui2001@hotmail.com\SharingMetadata\bui_christina@hotmail.com\DFSR\Staging\CS{3B245131-D152-EC1A-ACEF-4D6E04C0BFBE}\69\281-{3DCFACD1-027F-45BA-8F5E-8A8FEDCA80E2}-v269-{3DCFACD1-027F-45BA-8F5E-8A8FEDCA80E2}-v281-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.rdc.2 3108 bytes hidden from API C:\Documents and Settings\Boo Boo\Local Settings\Application Data\Microsoft\Messenger\lhbui2001@hotmail.com\SharingMetadata\bui_christina@hotmail.com\DFSR\Staging\CS{3B245131-D152-EC1A-ACEF-4D6E04C0BFBE}\69\281-{3DCFACD1-027F-45BA-8F5E-8A8FEDCA80E2}-v269-{3DCFACD1-027F-45BA-8F5E-8A8FEDCA80E2}-v281-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.XPRESS 4872 bytes hidden from API C:\Documents and Settings\Boo Boo\Local Settings\Application Data\Microsoft\Messenger\lhbui2001@hotmail.com\SharingMetadata\bui_christina@hotmail.com\DFSR\Staging\CS{3B245131-D152-EC1A-ACEF-4D6E04C0BFBE}\70\282-{3DCFACD1-027F-45BA-8F5E-8A8FEDCA80E2}-v270-{3DCFACD1-027F-45BA-8F5E-8A8FEDCA80E2}-v282-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.rdc.1 44454 bytes hidden from API C:\Documents and Settings\Boo Boo\Local Settings\Application Data\Microsoft\Messenger\lhbui2001@hotmail.com\SharingMetadata\bui_christina@hotmail.com\DFSR\Staging\CS{3B245131-D152-EC1A-ACEF-4D6E04C0BFBE}\70\282-{3DCFACD1-027F-45BA-8F5E-8A8FEDCA80E2}-v270-{3DCFACD1-027F-45BA-8F5E-8A8FEDCA80E2}-v282-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.rdc.2 3180 bytes hidden from API C:\Documents and Settings\Boo Boo\Local Settings\Application Data\Microsoft\Messenger\lhbui2001@hotmail.com\SharingMetadata\bui_christina@hotmail.com\DFSR\Staging\CS{3B245131-D152-EC1A-ACEF-4D6E04C0BFBE}\70\282-{3DCFACD1-027F-45BA-8F5E-8A8FEDCA80E2}-v270-{3DCFACD1-027F-45BA-8F5E-8A8FEDCA80E2}-v282-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.XPRESS 5000 bytes hidden from API C:\Documents and Settings\Boo Boo\Local Settings\Application Data\Microsoft\Messenger\lhbui2001@hotmail.com\SharingMetadata\bui_christina@hotmail.com\DFSR\Staging\CS{3B245131-D152-EC1A-ACEF-4D6E04C0BFBE}\71\283-{3DCFACD1-027F-45BA-8F5E-8A8FEDCA80E2}-v271-{3DCFACD1-027F-45BA-8F5E-8A8FEDCA80E2}-v283-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.rdc.1 53616 bytes hidden from API C:\Documents and Settings\Boo Boo\Local Settings\Application Data\Microsoft\Messenger\lhbui2001@hotmail.com\SharingMetadata\bui_christina@hotmail.com\DFSR\Staging\CS{3B245131-D152-EC1A-ACEF-4D6E04C0BFBE}\71\283-{3DCFACD1-027F-45BA-8F5E-8A8FEDCA80E2}-v271-{3DCFACD1-027F-45BA-8F5E-8A8FEDCA80E2}-v283-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.rdc.2 3720 bytes hidden from API C:\Documents and Settings\Boo Boo\Local Settings\Application Data\Microsoft\Messenger\lhbui2001@hotmail.com\SharingMetadata\bui_christina@hotmail.com\DFSR\Staging\CS{3B245131-D152-EC1A-ACEF-4D6E04C0BFBE}\71\283-{3DCFACD1-027F-45BA-8F5E-8A8FEDCA80E2}-v271-{3DCFACD1-027F-45BA-8F5E-8A8FEDCA80E2}-v283-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.XPRESS 5960 bytes hidden from API C:\Documents and Settings\Boo Boo\Local Settings\Application Data\Microsoft\Messenger\lhbui2001@hotmail.com\SharingMetadata\bui_christina@hotmail.com\DFSR\Staging\CS{3B245131-D152-EC1A-ACEF-4D6E04C0BFBE}\72\284-{3DCFACD1-027F-45BA-8F5E-8A8FEDCA80E2}-v272-{3DCFACD1-027F-45BA-8F5E-8A8FEDCA80E2}-v284-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.rdc.1 77844 bytes hidden from API C:\Documents and Settings\Boo Boo\Local Settings\Application Data\Microsoft\Messenger\lhbui2001@hotmail.com\SharingMetadata\bui_christina@hotmail.com\DFSR\Staging\CS{3B245131-D152-EC1A-ACEF-4D6E04C0BFBE}\72\284-{3DCFACD1-027F-45BA-8F5E-8A8FEDCA80E2}-v272-{3DCFACD1-027F-45BA-8F5E-8A8FEDCA80E2}-v284-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.rdc.2 5430 bytes hidden from API C:\Documents and Settings\Boo Boo\Local Settings\Application Data\Microsoft\Messenger\lhbui2001@hotmail.com\SharingMetadata\bui_christina@hotmail.com\DFSR\Staging\CS{3B245131-D152-EC1A-ACEF-4D6E04C0BFBE}\72\284-{3DCFACD1-027F-45BA-8F5E-8A8FEDCA80E2}-v272-{3DCFACD1-027F-45BA-8F5E-8A8FEDCA80E2}-v284-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.XPRESS 8664 bytes hidden from API C:\Documents and Settings\Boo Boo\Local Settings\Application Data\Microsoft\Messenger\lhbui2001@hotmail.com\SharingMetadata\bui_christina@hotmail.com\DFSR\Staging\CS{3B245131-D152-EC1A-ACEF-4D6E04C0BFBE}\73\285-{3DCFACD1-027F-45BA-8F5E-8A8FEDCA80E2}-v273-{3DCFACD1-027F-45BA-8F5E-8A8FEDCA80E2}-v285-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.rdc.1 51924 bytes hidden from API C:\Documents and Settings\Boo Boo\Local Settings\Application Data\Microsoft\Messenger\lhbui2001@hotmail.com\SharingMetadata\bui_christina@hotmail.com\DFSR\Staging\CS{3B245131-D152-EC1A-ACEF-4D6E04C0BFBE}\73\285-{3DCFACD1-027F-45BA-8F5E-8A8FEDCA80E2}-v273-{3DCFACD1-027F-45BA-8F5E-8A8FEDCA80E2}-v285-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.rdc.2 3774 bytes hidden from API C:\Documents and Settings\Boo Boo\Local Settings\Application Data\Microsoft\Messenger\lhbui2001@hotmail.com\SharingMetadata\bui_christina@hotmail.com\DFSR\Staging\CS{3B245131-D152-EC1A-ACEF-4D6E04C0BFBE}\73\285-{3DCFACD1-027F-45BA-8F5E-8A8FEDCA80E2}-v273-{3DCFACD1-027F-45BA-8F5E-8A8FEDCA80E2}-v285-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.XPRESS 5784 bytes hidden from API C:\Documents and Settings\Boo Boo\Local Settings\Application Data\Microsoft\Messenger\lhbui2001@hotmail.com\SharingMetadata\bui_christina@hotmail.com\DFSR\Staging\CS{3B245131-D152-EC1A-ACEF-4D6E04C0BFBE}\74\286-{3DCFACD1-027F-45BA-8F5E-8A8FEDCA80E2}-v274-{3DCFACD1-027F-45BA-8F5E-8A8FEDCA80E2}-v286-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.rdc.1 49890 bytes hidden from API C:\Documents and Settings\Boo Boo\Local Settings\Application Data\Microsoft\Messenger\lhbui2001@hotmail.com\SharingMetadata\bui_christina@hotmail.com\DFSR\Staging\CS{3B245131-D152-EC1A-ACEF-4D6E04C0BFBE}\74\286-{3DCFACD1-027F-45BA-8F5E-8A8FEDCA80E2}-v274-{3DCFACD1-027F-45BA-8F5E-8A8FEDCA80E2}-v286-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.rdc.2 3594 bytes hidden from API C:\Documents and Settings\Boo Boo\Local Settings\Application Data\Microsoft\Messenger\lhbui2001@hotmail.com\SharingMetadata\bui_christina@hotmail.com\DFSR\Staging\CS{3B245131-D152-EC1A-ACEF-4D6E04C0BFBE}\74\286-{3DCFACD1-027F-45BA-8F5E-8A8FEDCA80E2}-v274-{3DCFACD1-027F-45BA-8F5E-8A8FEDCA80E2}-v286-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.XPRESS 5536 bytes hidden from API C:\Documents and Settings\Boo Boo\Local Settings\Application Data\Microsoft\Messenger\lhbui2001@hotmail.com\SharingMetadata\bui_christina@hotmail.com\DFSR\Staging\CS{3B245131-D152-EC1A-ACEF-4D6E04C0BFBE}\88\288-{3DCFACD1-027F-45BA-8F5E-8A8FEDCA80E2}-v288-{3DCFACD1-027F-45BA-8F5E-8A8FEDCA80E2}-v288-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.rdc.1 57486 bytes hidden from API C:\Documents and Settings\Boo Boo\Local Settings\Application Data\Microsoft\Messenger\lhbui2001@hotmail.com\SharingMetadata\bui_christina@hotmail.com\DFSR\Staging\CS{3B245131-D152-EC1A-ACEF-4D6E04C0BFBE}\88\288-{3DCFACD1-027F-45BA-8F5E-8A8FEDCA80E2}-v288-{3DCFACD1-027F-45BA-8F5E-8A8FEDCA80E2}-v288-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.rdc.2 4080 bytes hidden from API C:\Documents and Settings\Boo Boo\Local Settings\Application Data\Microsoft\Messenger\lhbui2001@hotmail.com\SharingMetadata\bui_christina@hotmail.com\DFSR\Staging\CS{3B245131-D152-EC1A-ACEF-4D6E04C0BFBE}\88\288-{3DCFACD1-027F-45BA-8F5E-8A8FEDCA80E2}-v288-{3DCFACD1-027F-45BA-8F5E-8A8FEDCA80E2}-v288-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.XPRESS 6448 bytes hidden from API C:\Documents and Settings\Boo Boo\Local Settings\Application Data\Microsoft\Messenger\lhbui2001@hotmail.com\SharingMetadata\bui_christina@hotmail.com\DFSR\Staging\CS{3B245131-D152-EC1A-ACEF-4D6E04C0BFBE}\89\289-{3DCFACD1-027F-45BA-8F5E-8A8FEDCA80E2}-v289-{3DCFACD1-027F-45BA-8F5E-8A8FEDCA80E2}-v289-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.rdc.1 50808 bytes hidden from API C:\Documents and Settings\Boo Boo\Local Settings\Application Data\Microsoft\Messenger\lhbui2001@hotmail.com\SharingMetadata\bui_christina@hotmail.com\DFSR\Staging\CS{3B245131-D152-EC1A-ACEF-4D6E04C0BFBE}\89\289-{3DCFACD1-027F-45BA-8F5E-8A8FEDCA80E2}-v289-{3DCFACD1-027F-45BA-8F5E-8A8FEDCA80E2}-v289-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.rdc.2 3756 bytes hidden from API C:\Documents and Settings\Boo Boo\Local Settings\Application Data\Microsoft\Messenger\lhbui2001@hotmail.com\SharingMetadata\bui_christina@hotmail.com\DFSR\Staging\CS{3B245131-D152-EC1A-ACEF-4D6E04C0BFBE}\89\289-{3DCFACD1-027F-45BA-8F5E-8A8FEDCA80E2}-v289-{3DCFACD1-027F-45BA-8F5E-8A8FEDCA80E2}-v289-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.XPRESS 5664 bytes hidden from API C:\Documents and Settings\Boo Boo\Local Settings\Application Data\Microsoft\Messenger\lhbui2001@hotmail.com\SharingMetadata\bui_christina@hotmail.com\DFSR\Staging\CS{3B245131-D152-EC1A-ACEF-4D6E04C0BFBE}\90\290-{3DCFACD1-027F-45BA-8F5E-8A8FEDCA80E2}-v290-{3DCFACD1-027F-45BA-8F5E-8A8FEDCA80E2}-v290-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.rdc.1 21936 bytes hidden from API C:\Documents and Settings\Boo Boo\Local Settings\Application Data\Microsoft\Messenger\lhbui2001@hotmail.com\SharingMetadata\bui_christina@hotmail.com\DFSR\Staging\CS{3B245131-D152-EC1A-ACEF-4D6E04C0BFBE}\90\290-{3DCFACD1-027F-45BA-8F5E-8A8FEDCA80E2}-v290-{3DCFACD1-027F-45BA-8F5E-8A8FEDCA80E2}-v290-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.rdc.2 1524 bytes hidden from API C:\Documents and Settings\Boo Boo\Local Settings\Application Data\Microsoft\Messenger\lhbui2001@hotmail.com\SharingMetadata\bui_christina@hotmail.com\DFSR\Staging\CS{3B245131-D152-EC1A-ACEF-4D6E04C0BFBE}\90\290-{3DCFACD1-027F-45BA-8F5E-8A8FEDCA80E2}-v290-{3DCFACD1-027F-45BA-8F5E-8A8FEDCA80E2}-v290-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.XPRESS 2424 bytes hidden from API C:\Documents and Settings\Boo Boo\Local Settings\Application Data\Microsoft\Messenger\lhbui2001@hotmail.com\SharingMetadata\bui_christina@hotmail.com\DFSR\Staging\CS{3B245131-D152-EC1A-ACEF-4D6E04C0BFBE}\91\291-{3DCFACD1-027F-45BA-8F5E-8A8FEDCA80E2}-v291-{3DCFACD1-027F-45BA-8F5E-8A8FEDCA80E2}-v291-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.rdc.1 60780 bytes hidden from API C:\Documents and Settings\Boo Boo\Local Settings\Application Data\Microsoft\Messenger\lhbui2001@hotmail.com\SharingMetadata\bui_christina@hotmail.com\DFSR\Staging\CS{3B245131-D152-EC1A-ACEF-4D6E04C0BFBE}\91\291-{3DCFACD1-027F-45BA-8F5E-8A8FEDCA80E2}-v291-{3DCFACD1-027F-45BA-8F5E-8A8FEDCA80E2}-v291-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.rdc.2 4458 bytes hidden from API C:\Documents and Settings\Boo Boo\Local Settings\Application Data\Microsoft\Messenger\lhbui2001@hotmail.com\SharingMetadata\bui_christina@hotmail.com\DFSR\Staging\CS{3B245131-D152-EC1A-ACEF-4D6E04C0BFBE}\91\291-{3DCFACD1-027F-45BA-8F5E-8A8FEDCA80E2}-v291-{3DCFACD1-027F-45BA-8F5E-8A8FEDCA80E2}-v291-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.XPRESS 6784 bytes hidden from API C:\Documents and Settings\Boo Boo\Local Settings\Application Data\Microsoft\Messenger\lhbui2001@hotmail.com\SharingMetadata\bui_christina@hotmail.com\DFSR\Staging\CS{3B245131-D152-EC1A-ACEF-4D6E04C0BFBE}\91\91-{3DCFACD1-027F-45BA-8F5E-8A8FEDCA80E2}-v91-{3DCFACD1-027F-45BA-8F5E-8A8FEDCA80E2}-v91-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.rdc.1 39792 bytes hidden from API C:\Documents and Settings\Boo Boo\Local Settings\Application Data\Microsoft\Messenger\lhbui2001@hotmail.com\SharingMetadata\bui_christina@hotmail.com\DFSR\Staging\CS{3B245131-D152-EC1A-ACEF-4D6E04C0BFBE}\91\91-{3DCFACD1-027F-45BA-8F5E-8A8FEDCA80E2}-v91-{3DCFACD1-027F-45BA-8F5E-8A8FEDCA80E2}-v91-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.rdc.2 2838 bytes hidden from API C:\Documents and Settings\Boo Boo\Local Settings\Application Data\Microsoft\Messenger\lhbui2001@hotmail.com\SharingMetadata\bui_christina@hotmail.com\DFSR\Staging\CS{3B245131-D152-EC1A-ACEF-4D6E04C0BFBE}\91\91-{3DCFACD1-027F-45BA-8F5E-8A8FEDCA80E2}-v91-{3DCFACD1-027F-45BA-8F5E-8A8FEDCA80E2}-v91-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.XPRESS 4448 bytes hidden from API C:\Documents and Settings\Boo Boo\Local Settings\Application Data\Microsoft\Messenger\lhbui2001@hotmail.com\SharingMetadata\bui_christina@hotmail.com\DFSR\Staging\CS{3B245131-D152-EC1A-ACEF-4D6E04C0BFBE}\92\192-{3DCFACD1-027F-45BA-8F5E-8A8FEDCA80E2}-v192-{3DCFACD1-027F-45BA-8F5E-8A8FEDCA80E2}-v192-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.rdc.1 47730 bytes hidden from API C:\Documents and Settings\Boo Boo\Local Settings\Application Data\Microsoft\Messenger\lhbui2001@hotmail.com\SharingMetadata\bui_christina@hotmail.com\DFSR\Staging\CS{3B245131-D152-EC1A-ACEF-4D6E04C0BFBE}\92\192-{3DCFACD1-027F-45BA-8F5E-8A8FEDCA80E2}-v192-{3DCFACD1-027F-45BA-8F5E-8A8FEDCA80E2}-v192-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.rdc.2 3450 bytes hidden from API C:\Documents and Settings\Boo Boo\Local Settings\Application Data\Microsoft\Messenger\lhbui2001@hotmail.com\SharingMetadata\bui_christina@hotmail.com\DFSR\Staging\CS{3B245131-D152-EC1A-ACEF-4D6E04C0BFBE}\92\192-{3DCFACD1-027F-45BA-8F5E-8A8FEDCA80E2}-v192-{3DCFACD1-027F-45BA-8F5E-8A8FEDCA80E2}-v192-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.XPRESS 5320 bytes hidden from API C:\Documents and Settings\Boo Boo\Local Settings\Application Data\Microsoft\Messenger\lhbui2001@hotmail.com\SharingMetadata\bui_christina@hotmail.com\DFSR\Staging\CS{3B245131-D152-EC1A-ACEF-4D6E04C0BFBE}\92\292-{3DCFACD1-027F-45BA-8F5E-8A8FEDCA80E2}-v292-{3DCFACD1-027F-45BA-8F5E-8A8FEDCA80E2}-v292-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.rdc.1 58998 bytes hidden from API C:\Documents and Settings\Boo Boo\Local Settings\Application Data\Microsoft\Messenger\lhbui2001@hotmail.com\SharingMetadata\bui_christina@hotmail.com\DFSR\Staging\CS{3B245131-D152-EC1A-ACEF-4D6E04C0BFBE}\92\292-{3DCFACD1-027F-45BA-8F5E-8A8FEDCA80E2}-v292-{3DCFACD1-027F-45BA-8F5E-8A8FEDCA80E2}-v292-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.XPRESS 6496 bytes hidden from API C:\Documents and Settings\Boo Boo\Local Settings\Application Data\Microsoft\Messenger\lhbui2001@hotmail.com\SharingMetadata\bui_christina@hotmail.com\DFSR\Staging\CS{3B245131-D152-EC1A-ACEF-4D6E04C0BFBE}\92\92-{3DCFACD1-027F-45BA-8F5E-8A8FEDCA80E2}-v92-{3DCFACD1-027F-45BA-8F5E-8A8FEDCA80E2}-v92-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.rdc.1 54048 bytes hidden from API C:\Documents and Settings\Boo Boo\Local Settings\Application Data\Microsoft\Messenger\lhbui2001@hotmail.com\SharingMetadata\bui_christina@hotmail.com\DFSR\Staging\CS{3B245131-D152-EC1A-ACEF-4D6E04C0BFBE}\92\92-{3DCFACD1-027F-45BA-8F5E-8A8FEDCA80E2}-v92-{3DCFACD1-027F-45BA-8F5E-8A8FEDCA80E2}-v92-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.rdc.2 3846 bytes hidden from API C:\Documents and Settings\Boo Boo\Local Settings\Application Data\Microsoft\Messenger\lhbui2001@hotmail.com\SharingMetadata\bui_christina@hotmail.com\DFSR\Staging\CS{3B245131-D152-EC1A-ACEF-4D6E04C0BFBE}\92\92-{3DCFACD1-027F-45BA-8F5E-8A8FEDCA80E2}-v92-{3DCFACD1-027F-45BA-8F5E-8A8FEDCA80E2}-v92-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.XPRESS 5936 bytes hidden from API C:\Documents and Settings\Boo Boo\Local Settings\Application Data\Microsoft\Messenger\lhbui2001@hotmail.com\SharingMetadata\bui_christina@hotmail.com\DFSR\Staging\CS{3B245131-D152-EC1A-ACEF-4D6E04C0BFBE}\93\193-{3DCFACD1-027F-45BA-8F5E-8A8FEDCA80E2}-v193-{3DCFACD1-027F-45BA-8F5E-8A8FEDCA80E2}-v193-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.rdc.1 69474 bytes hidden from API C:\Documents and Settings\Boo Boo\Local Settings\Application Data\Microsoft\Messenger\lhbui2001@hotmail.com\SharingMetadata\bui_christina@hotmail.com\DFSR\Staging\CS{3B245131-D152-EC1A-ACEF-4D6E04C0BFBE}\93\193-{3DCFACD1-027F-45BA-8F5E-8A8FEDCA80E2}-v193-{3DCFACD1-027F-45BA-8F5E-8A8FEDCA80E2}-v193-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.rdc.2 4782 bytes hidden from API C:\Documents and Settings\Boo Boo\Local Settings\Application Data\Microsoft\Messenger\lhbui2001@hotmail.com\SharingMetadata\bui_christina@hotmail.com\DFSR\Staging\CS{3B245131-D152-EC1A-ACEF-4D6E04C0BFBE}\93\193-{3DCFACD1-027F-45BA-8F5E-8A8FEDCA80E2}-v193-{3DCFACD1-027F-45BA-8F5E-8A8FEDCA80E2}-v193-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.XPRESS 7696 bytes hidden from API C:\Documents and Settings\Boo Boo\Local Settings\Application Data\Microsoft\Messenger\lhbui2001@hotmail.com\SharingMetadata\bui_christina@hotmail.com\DFSR\Staging\CS{3B245131-D152-EC1A-ACEF-4D6E04C0BFBE}\93\293-{3DCFACD1-027F-45BA-8F5E-8A8FEDCA80E2}-v293-{3DCFACD1-027F-45BA-8F5E-8A8FEDCA80E2}-v293-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.rdc.1 48540 bytes hidden from API C:\Documents and Settings\Boo Boo\Local Settings\Application Data\Microsoft\Messenger\lhbui2001@hotmail.com\SharingMetadata\bui_christina@hotmail.com\DFSR\Staging\CS{3B245131-D152-EC1A-ACEF-4D6E04C0BFBE}\93\293-{3DCFACD1-027F-45BA-8F5E-8A8FEDCA80E2}-v293-{3DCFACD1-027F-45BA-8F5E-8A8FEDCA80E2}-v293-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.XPRESS 5408 bytes hidden from API C:\Documents and Settings\Boo Boo\Local Settings\Application Data\Microsoft\Messenger\lhbui2001@hotmail.com\SharingMetadata\bui_christina@hotmail.com\DFSR\Staging\CS{3B245131-D152-EC1A-ACEF-4D6E04C0BFBE}\93\93-{3DCFACD1-027F-45BA-8F5E-8A8FEDCA80E2}-v93-{3DCFACD1-027F-45BA-8F5E-8A8FEDCA80E2}-v93-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.rdc.1 49764 bytes hidden from API C:\Documents and Settings\Boo Boo\Local Settings\Application Data\Microsoft\Messenger\lhbui2001@hotmail.com\SharingMetadata\bui_christina@hotmail.com\DFSR\Staging\CS{3B245131-D152-EC1A-ACEF-4D6E04C0BFBE}\93\93-{3DCFACD1-027F-45BA-8F5E-8A8FEDCA80E2}-v93-{3DCFACD1-027F-45BA-8F5E-8A8FEDCA80E2}-v93-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.rdc.2 3540 bytes hidden from API C:\Documents and Settings\Boo Boo\Local Settings\Application Data\Microsoft\Messenger\lhbui2001@hotmail.com\SharingMetadata\bui_christina@hotmail.com\DFSR\Staging\CS{3B245131-D152-EC1A-ACEF-4D6E04C0BFBE}\93\93-{3DCFACD1-027F-45BA-8F5E-8A8FEDCA80E2}-v93-{3DCFACD1-027F-45BA-8F5E-8A8FEDCA80E2}-v93-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.XPRESS 5560 bytes hidden from API C:\Documents and Settings\Boo Boo\Local Settings\Application Data\Microsoft\Messenger\lhbui2001@hotmail.com\SharingMetadata\bui_christina@hotmail.com\DFSR\Staging\CS{3B245131-D152-EC1A-ACEF-4D6E04C0BFBE}\94\194-{3DCFACD1-027F-45BA-8F5E-8A8FEDCA80E2}-v194-{3DCFACD1-027F-45BA-8F5E-8A8FEDCA80E2}-v194-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.rdc.1 56658 bytes hidden from API C:\Documents and Settings\Boo Boo\Local Settings\Application Data\Microsoft\Messenger\lhbui2001@hotmail.com\SharingMetadata\bui_christina@hotmail.com\DFSR\Staging\CS{3B245131-D152-EC1A-ACEF-4D6E04C0BFBE}\94\194-{3DCFACD1-027F-45BA-8F5E-8A8FEDCA80E2}-v194-{3DCFACD1-027F-45BA-8F5E-8A8FEDCA80E2}-v194-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.rdc.2 4152 bytes hidden from API C:\Documents and Settings\Boo Boo\Local Settings\Application Data\Microsoft\Messenger\lhbui2001@hotmail.com\SharingMetadata\bui_christina@hotmail.com\DFSR\Staging\CS{3B245131-D152-EC1A-ACEF-4D6E04C0BFBE}\94\194-{3DCFACD1-027F-45BA-8F5E-8A8FEDCA80E2}-v194-{3DCFACD1-027F-45BA-8F5E-8A8FEDCA80E2}-v194-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.XPRESS 6352 bytes hidden from API C:\Documents and Settings\Boo Boo\Local Settings\Application Data\Microsoft\Messenger\lhbui2001@hotmail.com\SharingMetadata\bui_christina@hotmail.com\DFSR\Staging\CS{3B245131-D152-EC1A-ACEF-4D6E04C0BFBE}\94\294-{3DCFACD1-027F-45BA-8F5E-8A8FEDCA80E2}-v294-{3DCFACD1-027F-45BA-8F5E-8A8FEDCA80E2}-v294-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.rdc.1 73434 bytes hidden from API C:\Documents and Settings\Boo Boo\Local Settings\Application Data\Microsoft\Messenger\lhbui2001@hotmail.com\SharingMetadata\bui_christina@hotmail.com\DFSR\Staging\CS{3B245131-D152-EC1A-ACEF-4D6E04C0BFBE}\94\294-{3DCFACD1-027F-45BA-8F5E-8A8FEDCA80E2}-v294-{3DCFACD1-027F-45BA-8F5E-8A8FEDCA80E2}-v294-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.rdc.2 5358 bytes hidden from API C:\Documents and Settings\Boo Boo\Local Settings\Application Data\Microsoft\Messenger\lhbui2001@hotmail.com\SharingMetadata\bui_christina@hotmail.com\DFSR\Staging\CS{3B245131-D152-EC1A-ACEF-4D6E04C0BFBE}\94\294-{3DCFACD1-027F-45BA-8F5E-8A8FEDCA80E2}-v294-{3DCFACD1-027F-45BA-8F5E-8A8FEDCA80E2}-v294-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.XPRESS 8104 bytes hidden from API C:\Documents and Settings\Boo Boo\Local Settings\Application Data\Microsoft\Messenger\lhbui2001@hotmail.com\SharingMetadata\bui_christina@hotmail.com\DFSR\Staging\CS{3B245131-D152-EC1A-ACEF-4D6E04C0BFBE}\94\94-{3DCFACD1-027F-45BA-8F5E-8A8FEDCA80E2}-v94-{3DCFACD1-027F-45BA-8F5E-8A8FEDCA80E2}-v94-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.rdc.1 47352 bytes hidden from API C:\Documents and Settings\Boo Boo\Local Settings\Application Data\Microsoft\Messenger\lhbui2001@hotmail.com\SharingMetadata\bui_christina@hotmail.com\DFSR\Staging\CS{3B245131-D152-EC1A-ACEF-4D6E04C0BFBE}\94\94-{3DCFACD1-027F-45BA-8F5E-8A8FEDCA80E2}-v94-{3DCFACD1-027F-45BA-8F5E-8A8FEDCA80E2}-v94-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.rdc.2 3198 bytes hidden from API C:\Documents and Settings\Boo Boo\Local Settings\Application Data\Microsoft\Messenger\lhbui2001@hotmail.com\SharingMetadata\bui_christina@hotmail.com\DFSR\Staging\CS{3B245131-D152-EC1A-ACEF-4D6E04C0BFBE}\94\94-{3DCFACD1-027F-45BA-8F5E-8A8FEDCA80E2}-v94-{3DCFACD1-027F-45BA-8F5E-8A8FEDCA80E2}-v94-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.XPRESS 5304 bytes hidden from API C:\Documents and Settings\Boo Boo\Local Settings\Application Data\Microsoft\Messenger\lhbui2001@hotmail.com\SharingMetadata\bui_christina@hotmail.com\DFSR\Staging\CS{3B245131-D152-EC1A-ACEF-4D6E04C0BFBE}\95\195-{3DCFACD1-027F-45BA-8F5E-8A8FEDCA80E2}-v195-{3DCFACD1-027F-45BA-8F5E-8A8FEDCA80E2}-v195-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.rdc.1 63642 bytes hidden from API C:\Documents and Settings\Boo Boo\Local Settings\Application Data\Microsoft\Messenger\lhbui2001@hotmail.com\SharingMetadata\bui_christina@hotmail.com\DFSR\Staging\CS{3B245131-D152-EC1A-ACEF-4D6E04C0BFBE}\95\195-{3DCFACD1-027F-45BA-8F5E-8A8FEDCA80E2}-v195-{3DCFACD1-027F-45BA-8F5E-8A8FEDCA80E2}-v195-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.rdc.2 4638 bytes hidden from API C:\Documents and Settings\Boo Boo\Local Settings\Application Data\Microsoft\Messenger\lhbui2001@hotmail.com\SharingMetadata\bui_christina@hotmail.com\DFSR\Staging\CS{3B245131-D152-EC1A-ACEF-4D6E04C0BFBE}\95\195-{3DCFACD1-027F-45BA-8F5E-8A8FEDCA80E2}-v195-{3DCFACD1-027F-45BA-8F5E-8A8FEDCA80E2}-v195-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.XPRESS 7112 bytes hidden from API C:\Documents and Settings\Boo Boo\Local Settings\Application Data\Microsoft\Messenger\lhbui2001@hotmail.com\SharingMetadata\bui_christina@hotmail.com\DFSR\Staging\CS{3B245131-D152-EC1A-ACEF-4D6E04C0BFBE}\95\295-{3DCFACD1-027F-45BA-8F5E-8A8FEDCA80E2}-v295-{3DCFACD1-027F-45BA-8F5E-8A8FEDCA80E2}-v295-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.rdc.1 57414 bytes hidden from API C:\Documents and Settings\Boo Boo\Local Settings\Application Data\Microsoft\Messenger\lhbui2001@hotmail.com\SharingMetadata\bui_christina@hotmail.com\DFSR\Staging\CS{3B245131-D152-EC1A-ACEF-4D6E04C0BFBE}\95\295-{3DCFACD1-027F-45BA-8F5E-8A8FEDCA80E2}-v295-{3DCFACD1-027F-45BA-8F5E-8A8FEDCA80E2}-v295-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.rdc.2 3864 bytes hidden from API C:\Documents and Settings\Boo Boo\Local Settings\Application Data\Microsoft\Messenger\lhbui2001@hotmail.com\SharingMetadata\bui_christina@hotmail.com\DFSR\Staging\CS{3B245131-D152-EC1A-ACEF-4D6E04C0BFBE}\95\295-{3DCFACD1-027F-45BA-8F5E-8A8FEDCA80E2}-v295-{3DCFACD1-027F-45BA-8F5E-8A8FEDCA80E2}-v295-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.XPRESS 6368 bytes hidden from API C:\Documents and Settings\Boo Boo\Local Settings\Application Data\Microsoft\Messenger\lhbui2001@hotmail.com\SharingMetadata\bui_christina@hotmail.com\DFSR\Staging\CS{3B245131-D152-EC1A-ACEF-4D6E04C0BFBE}\95\95-{3DCFACD1-027F-45BA-8F5E-8A8FEDCA80E2}-v95-{3DCFACD1-027F-45BA-8F5E-8A8FEDCA80E2}-v95-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.rdc.1 552 bytes hidden from API C:\Documents and Settings\Boo Boo\Local Settings\Application Data\Microsoft\Messenger\lhbui2001@hotmail.com\SharingMetadata\bui_christina@hotmail.com\DFSR\Staging\CS{3B245131-D152-EC1A-ACEF-4D6E04C0BFBE}\95\95-{3DCFACD1-027F-45BA-8F5E-8A8FEDCA80E2}-v95-{3DCFACD1-027F-45BA-8F5E-8A8FEDCA80E2}-v95-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.XPRESS 72 bytes hidden from API C:\Documents and Settings\Boo Boo\Local Settings\Application Data\Microsoft\Messenger\lhbui2001@hotmail.com\SharingMetadata\bui_christina@hotmail.com\DFSR\Staging\CS{3B245131-D152-EC1A-ACEF-4D6E04C0BFBE}\96\196-{3DCFACD1-027F-45BA-8F5E-8A8FEDCA80E2}-v196-{3DCFACD1-027F-45BA-8F5E-8A8FEDCA80E2}-v196-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.rdc.1 50880 bytes hidden from API C:\Documents and Settings\Boo Boo\Local Settings\Application Data\Microsoft\Messenger\lhbui2001@hotmail.com\SharingMetadata\bui_christina@hotmail.com\DFSR\Staging\CS{3B245131-D152-EC1A-ACEF-4D6E04C0BFBE}\96\196-{3DCFACD1-027F-45BA-8F5E-8A8FEDCA80E2}-v196-{3DCFACD1-027F-45BA-8F5E-8A8FEDCA80E2}-v196-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.rdc.2 3612 bytes hidden from API C:\Documents and Settings\Boo Boo\Local Settings\Application Data\Microsoft\Messenger\lhbui2001@hotmail.com\SharingMetadata\bui_christina@hotmail.com\DFSR\Staging\CS{3B245131-D152-EC1A-ACEF-4D6E04C0BFBE}\96\196-{3DCFACD1-027F-45BA-8F5E-8A8FEDCA80E2}-v196-{3DCFACD1-027F-45BA-8F5E-8A8FEDCA80E2}-v196-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.XPRESS 5672 bytes hidden from API C:\Documents and Settings\Boo Boo\Local Settings\Application Data\Microsoft\Messenger\lhbui2001@hotmail.com\SharingMetadata\bui_christina@hotmail.com\DFSR\Staging\CS{3B245131-D152-EC1A-ACEF-4D6E04C0BFBE}\96\296-{3DCFACD1-027F-45BA-8F5E-8A8FEDCA80E2}-v296-{3DCFACD1-027F-45BA-8F5E-8A8FEDCA80E2}-v296-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.rdc.1 46920 bytes hidden from API C:\Documents and Settings\Boo Boo\Local Settings\Application Data\Microsoft\Messenger\lhbui2001@hotmail.com\SharingMetadata\bui_christina@hotmail.com\DFSR\Staging\CS{3B245131-D152-EC1A-ACEF-4D6E04C0BFBE}\96\296-{3DCFACD1-027F-45BA-8F5E-8A8FEDCA80E2}-v296-{3DCFACD1-027F-45BA-8F5E-8A8FEDCA80E2}-v296-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.rdc.2 3486 bytes hidden from API C:\Documents and Settings\Boo Boo\Local Settings\Application Data\Microsoft\Messenger\lhbui2001@hotmail.com\SharingMetadata\bui_christina@hotmail.com\DFSR\Staging\CS{3B245131-D152-EC1A-ACEF-4D6E04C0BFBE}\96\296-{3DCFACD1-027F-45BA-8F5E-8A8FEDCA80E2}-v296-{3DCFACD1-027F-45BA-8F5E-8A8FEDCA80E2}-v296-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.XPRESS 5264 bytes hidden from API C:\Documents and Settings\Boo Boo\Local Settings\Application Data\Microsoft\Messenger\lhbui2001@hotmail.com\SharingMetadata\bui_christina@hotmail.com\DFSR\Staging\CS{3B245131-D152-EC1A-ACEF-4D6E04C0BFBE}\97\197-{3DCFACD1-027F-45BA-8F5E-8A8FEDCA80E2}-v197-{3DCFACD1-027F-45BA-8F5E-8A8FEDCA80E2}-v197-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.rdc.1 71490 bytes hidden from API C:\Documents and Settings\Boo Boo\Local Settings\Application Data\Microsoft\Messenger\lhbui2001@hotmail.com\SharingMetadata\bui_christina@hotmail.com\DFSR\Staging\CS{3B245131-D152-EC1A-ACEF-4D6E04C0BFBE}\97\197-{3DCFACD1-027F-45BA-8F5E-8A8FEDCA80E2}-v197-{3DCFACD1-027F-45BA-8F5E-8A8FEDCA80E2}-v197-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.rdc.2 5124 bytes hidden from API C:\Documents and Settings\Boo Boo\Local Settings\Application Data\Microsoft\Messenger\lhbui2001@hotmail.com\SharingMetadata\bui_christina@hotmail.com\DFSR\Staging\CS{3B245131-D152-EC1A-ACEF-4D6E04C0BFBE}\97\197-{3DCFACD1-027F-45BA-8F5E-8A8FEDCA80E2}-v197-{3DCFACD1-027F-45BA-8F5E-8A8FEDCA80E2}-v197-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.XPRESS 7904 bytes hidden from API C:\Documents and Settings\Boo Boo\Local Settings\Application Data\Microsoft\Messenger\lhbui2001@hotmail.com\SharingMetadata\bui_christina@hotmail.com\DFSR\Staging\CS{3B245131-D152-EC1A-ACEF-4D6E04C0BFBE}\97\297-{3DCFACD1-027F-45BA-8F5E-8A8FEDCA80E2}-v297-{3DCFACD1-027F-45BA-8F5E-8A8FEDCA80E2}-v297-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.rdc.1 43536 bytes hidden from API C:\Documents and Settings\Boo Boo\Local Settings\Application Data\Microsoft\Messenger\lhbui2001@hotmail.com\SharingMetadata\bui_christina@hotmail.com\DFSR\Staging\CS{3B245131-D152-EC1A-ACEF-4D6E04C0BFBE}\97\297-{3DCFACD1-027F-45BA-8F5E-8A8FEDCA80E2}-v297-{3DCFACD1-027F-45BA-8F5E-8A8FEDCA80E2}-v297-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.rdc.2 3000 bytes hidden from API C:\Documents and Settings\Boo Boo\Local Settings\Application Data\Microsoft\Messenger\lhbui2001@hotmail.com\SharingMetadata\bui_christina@hotmail.com\DFSR\Staging\CS{3B245131-D152-EC1A-ACEF-4D6E04C0BFBE}\97\297-{3DCFACD1-027F-45BA-8F5E-8A8FEDCA80E2}-v297-{3DCFACD1-027F-45BA-8F5E-8A8FEDCA80E2}-v297-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.XPRESS 4856 bytes hidden from API C:\Documents and Settings\Boo Boo\Local Settings\Application Data\Microsoft\Messenger\lhbui2001@hotmail.com\SharingMetadata\bui_christina@hotmail.com\DFSR\Staging\CS{3B245131-D152-EC1A-ACEF-4D6E04C0BFBE}\98\198-{3DCFACD1-027F-45BA-8F5E-8A8FEDCA80E2}-v198-{3DCFACD1-027F-45BA-8F5E-8A8FEDCA80E2}-v198-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.rdc.1 53976 bytes hidden from API C:\Documents and Settings\Boo Boo\Local Settings\Application Data\Microsoft\Messenger\lhbui2001@hotmail.com\SharingMetadata\bui_christina@hotmail.com\DFSR\Staging\CS{3B245131-D152-EC1A-ACEF-4D6E04C0BFBE}\98\198-{3DCFACD1-027F-45BA-8F5E-8A8FEDCA80E2}-v198-{3DCFACD1-027F-45BA-8F5E-8A8FEDCA80E2}-v198-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.rdc.2 3864 bytes hidden from API C:\Documents and Settings\Boo Boo\Local Settings\Application Data\Microsoft\Messenger\lhbui2001@hotmail.com\SharingMetadata\bui_christina@hotmail.com\DFSR\Staging\CS{3B245131-D152-EC1A-ACEF-4D6E04C0BFBE}\98\198-{3DCFACD1-027F-45BA-8F5E-8A8FEDCA80E2}-v198-{3DCFACD1-027F-45BA-8F5E-8A8FEDCA80E2}-v198-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.XPRESS 5976 bytes hidden from API C:\Documents and Settings\Boo Boo\Local Settings\Application Data\Microsoft\Messenger\lhbui2001@hotmail.com\SharingMetadata\bui_christina@hotmail.com\DFSR\Staging\CS{3B245131-D152-EC1A-ACEF-4D6E04C0BFBE}\98\298-{3DCFACD1-027F-45BA-8F5E-8A8FEDCA80E2}-v298-{3DCFACD1-027F-45BA-8F5E-8A8FEDCA80E2}-v298-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.rdc.1 37452 bytes hidden from API C:\Documents and Settings\Boo Boo\Local Settings\Application Data\Microsoft\Messenger\lhbui2001@hotmail.com\SharingMetadata\bui_christina@hotmail.com\DFSR\Staging\CS{3B245131-D152-EC1A-ACEF-4D6E04C0BFBE}\98\298-{3DCFACD1-027F-45BA-8F5E-8A8FEDCA80E2}-v298-{3DCFACD1-027F-45BA-8F5E-8A8FEDCA80E2}-v298-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.rdc.2 2820 bytes hidden from API C:\Documents and Settings\Boo Boo\Local Settings\Application Data\Microsoft\Messenger\lhbui2001@hotmail.com\SharingMetadata\bui_christina@hotmail.com\DFSR\Staging\CS{3B245131-D152-EC1A-ACEF-4D6E04C0BFBE}\98\298-{3DCFACD1-027F-45BA-8F5E-8A8FEDCA80E2}-v298-{3DCFACD1-027F-45BA-8F5E-8A8FEDCA80E2}-v298-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.XPRESS 4176 bytes hidden from API C:\Documents and Settings\Boo Boo\Local Settings\Application Data\Microsoft\Messenger\lhbui2001@hotmail.com\SharingMetadata\bui_christina@hotmail.com\DFSR\Staging\CS{3B245131-D152-EC1A-ACEF-4D6E04C0BFBE}\99\199-{3DCFACD1-027F-45BA-8F5E-8A8FEDCA80E2}-v199-{3DCFACD1-027F-45BA-8F5E-8A8FEDCA80E2}-v199-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.rdc.1 64038 bytes hidden from API C:\Documents and Settings\Boo Boo\Local Settings\Application Data\Microsoft\Messenger\lhbui2001@hotmail.com\SharingMetadata\bui_christina@hotmail.com\DFSR\Staging\CS{3B245131-D152-EC1A-ACEF-4D6E04C0BFBE}\99\199-{3DCFACD1-027F-45BA-8F5E-8A8FEDCA80E2}-v199-{3DCFACD1-027F-45BA-8F5E-8A8FEDCA80E2}-v199-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.rdc.2 4602 bytes hidden from API C:\Documents and Settings\Boo Boo\Local Settings\Application Data\Microsoft\Messenger\lhbui2001@hotmail.com\SharingMetadata\bui_christina@hotmail.com\DFSR\Staging\CS{3B245131-D152-EC1A-ACEF-4D6E04C0BFBE}\99\199-{3DCFACD1-027F-45BA-8F5E-8A8FEDCA80E2}-v199-{3DCFACD1-027F-45BA-8F5E-8A8FEDCA80E2}-v199-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.XPRESS 7120 bytes hidden from API C:\Documents and Settings\Boo Boo\Local Settings\Application Data\Microsoft\Messenger\lhbui2001@hotmail.com\SharingMetadata\bui_christina@hotmail.com\DFSR\Staging\CS{3B245131-D152-EC1A-ACEF-4D6E04C0BFBE}\99\299-{3DCFACD1-027F-45BA-8F5E-8A8FEDCA80E2}-v299-{3DCFACD1-027F-45BA-8F5E-8A8FEDCA80E2}-v299-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.rdc.1 69528 bytes hidden from API C:\Documents and Settings\Boo Boo\Local Settings\Application Data\Microsoft\Messenger\lhbui2001@hotmail.com\SharingMetadata\bui_christina@hotmail.com\DFSR\Staging\CS{3B245131-D152-EC1A-ACEF-4D6E04C0BFBE}\99\299-{3DCFACD1-027F-45BA-8F5E-8A8FEDCA80E2}-v299-{3DCFACD1-027F-45BA-8F5E-8A8FEDCA80E2}-v299-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.rdc.2 5016 bytes hidden from API C:\Documents and Settings\Boo Boo\Local Settings\Application Data\Microsoft\Messenger\lhbui2001@hotmail.com\SharingMetadata\bui_christina@hotmail.com\DFSR\Staging\CS{3B245131-D152-EC1A-ACEF-4D6E04C0BFBE}\99\299-{3DCFACD1-027F-45BA-8F5E-8A8FEDCA80E2}-v299-{3DCFACD1-027F-45BA-8F5E-8A8FEDCA80E2}-v299-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.XPRESS 7728 bytes hidden from API C:\Documents and Settings\Boo Boo\Local Settings\Application Data\Microsoft\Messenger\lhbui2001@hotmail.com\SharingMetadata\tessa_do@hotmail.com\DFSR\Staging\CS{E3236E1C-9003-A644-088A-F8E10C2774E6}\01\10-{E3236E1C-9003-A644-088A-F8E10C2774E6}-v1-{3DCFACD1-027F-45BA-8F5E-8A8FEDCA80E2}-v10-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.XPRESS 8 bytes hidden from API C:\Documents and Settings\Boo Boo\Local Settings\Application Data\Microsoft\Messenger\lhbui2001@hotmail.com\SharingMetadata\tessa_do@hotmail.com\DFSR\Staging\CS{E3236E1C-9003-A644-088A-F8E10C2774E6}\11\14-{BB3C6834-71C0-4977-9B98-EB020E4DBBC7}-v11-{BB3C6834-71C0-4977-9B98-EB020E4DBBC7}-v14-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.XPRESS 3552 bytes hidden from API C:\Documents and Settings\Boo Boo\Local Settings\Application Data\Microsoft\Messenger\lhbui2001@hotmail.com\SharingMetadata\tessa_do@hotmail.com\DFSR\Staging\CS{E3236E1C-9003-A644-088A-F8E10C2774E6}\12\15-{BB3C6834-71C0-4977-9B98-EB020E4DBBC7}-v12-{BB3C6834-71C0-4977-9B98-EB020E4DBBC7}-v15-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.XPRESS 3432 bytes hidden from API C:\Documents and Settings\Boo Boo\My Documents\Downloads\Thumbs.db:encryptable 0 bytes C:\Documents and Settings\Boo Boo\My Documents\Downloads\Finished Downloads\Michael Buble Its Time\Thumbs.db:encryptable 0 bytes C:\Documents and Settings\Boo Boo\My Documents\Downloads\Finished Downloads\[XviD - Ita Mp3] GUARDAMI [tntvillage.org]\Thumbs.db:encryptable 0 bytes C:\Documents and Settings\Boo Boo\My Documents\Downloads\Finished Downloads\R & B Love Collection\Thumbs.db:encryptable 0 bytes C:\Documents and Settings\Boo Boo\My Documents\LifeFrame\Thumbs.db:encryptable 0 bytes C:\Documents and Settings\Boo Boo\My Documents\My Pictures\Thumbs.db:encryptable 0 bytes C:\Documents and Settings\Boo Boo\My Documents\My Pictures\Hair Styles\Thumbs.db:encryptable 0 bytes C:\Documents and Settings\Boo Boo\My Documents\My Received Files\Thumbs.db:encryptable 0 bytes scan completed successfully hidden files: 300 < End of report > [/code]